From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-ot1-f70.google.com (mail-ot1-f70.google.com [209.85.210.70]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 3A8C930E0D8 for ; Wed, 10 Dec 2025 11:13:05 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.70 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1765365188; cv=none; b=GHDEbRJwp1woQKu04DZKBNCUjwG5cxjPXhoZfUUhxry8Gep6cssvcupeH2doZBXMPsDJd/0sRfQ5tBmdeDLU9y47fgZYYQvN7FypJPoXo4/di55R0yLh4pdgGlAaUQ+/s2QAHmIM0Lm3rifKhhhG0e30SDOhQ8wzEqgZ9BWIzfU= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1765365188; c=relaxed/simple; bh=9LIv7c7BSJ8Z5gGc1uF/GBHPikZN9COFCeaq1uv1bRw=; h=MIME-Version:Date:In-Reply-To:Message-ID:Subject:From:To: Content-Type; b=f3cTSUfxblgKNT/YVK+0TvRfDH+Iz1nSZTOH6+tz+ZS8TIOL8uO8QziFKSODApaxgV7AwVp69aVHVaaxYiqPr918t7b8BF9lUlfvo8LzK11zVXzcxHhu0y2dn7PfD8acHXg8vA8ccaPj6K7Mn0l+cd9NcohRaLm4F9roKvNFv94= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=syzkaller.appspotmail.com; spf=pass smtp.mailfrom=M3KW2WVRGUFZ5GODRSRYTGD7.apphosting.bounces.google.com; arc=none smtp.client-ip=209.85.210.70 Authentication-Results: smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=syzkaller.appspotmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=M3KW2WVRGUFZ5GODRSRYTGD7.apphosting.bounces.google.com Received: by mail-ot1-f70.google.com with SMTP id 46e09a7af769-7cac9cda2d0so2495600a34.0 for ; Wed, 10 Dec 2025 03:13:05 -0800 (PST) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1765365185; x=1765969985; h=to:from:subject:message-id:in-reply-to:date:mime-version :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=DZi2bwSps/DpUwh+RYzJot/njWlHeCyWa6KdtJPw1YI=; b=o7G+HkttE8Utb6lcU+ZQxh7WUvehtfVvrQRNrCeCLJGjkxcL44jNmunDOn3dYoJ0Rn pU3XhH2AsieXSbXgyqSQHbkUoHQhDFunO0QgR/WLvkbE4j7v/VC8ZmGkKDiSENf0YCSK FXvQhK8Zc+dumyZ6Z7fT5/FNPnvUncDqsFh1TNT5yWvz5OUAAp6VTLjzzVPGB9Ou+Nep /RFHydd2LBX2HR4uMbwtUD3z2qDCDAdKsJnKV69jym5G3lQJjTgUkGjSI3bLWVai0ud1 hsIE+nrTSCVqdIE8MY/xlk7ozMPoNI+z6Xvu8CxkFbjLPIlyAM2XtFP9KttGjtPyJ8HO 8e/w== X-Forwarded-Encrypted: i=1; AJvYcCW9Tu8tRG3ipnugqKw2nuTEzAhzNeGa6TD5ACTnjgVG1hX02QdhoRfTnlFv62OWoIP+MWGQNGmiAPTo4OM=@vger.kernel.org X-Gm-Message-State: AOJu0Yxe6yLKQHIWxcXpuJppAygSoG44bngAm0kR/ZwfbpgMBdkk51er 1ZmasrfDNX0ukK/iepQ206+4oZrQwenojM0ikSBPviDUpSJ6KFjkbd1v9hy7D4x81kk22ywwG4K whsUTmryW2CjMAf3ZQ7cAXTBA//bnOeHUpoz+seXxjZDOBzxdLAhyDbbS7rA= X-Google-Smtp-Source: AGHT+IFriKEi5oiDxHLvV4sw4z7In7f3GN82iZD8ZGFkwMSkD4RsrouDi/pzLtLAfog34MYC/kkyfWJ93Cn2kxt+1l5vfnSVw27J Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Received: by 2002:a4a:e90c:0:b0:659:9a49:9016 with SMTP id 006d021491bc7-65b2ad8e0bfmr1540418eaf.67.1765365185211; Wed, 10 Dec 2025 03:13:05 -0800 (PST) Date: Wed, 10 Dec 2025 03:13:05 -0800 In-Reply-To: <0555a467-5aae-044b-908d-f501b44804b1@gmail.com> X-Google-Appengine-App-Id: s~syzkaller X-Google-Appengine-App-Id-Alias: syzkaller Message-ID: <693955c1.a70a0220.33cd7b.0005.GAE@google.com> Subject: Re: [syzbot] [btrfs?] memory leak in btrfs_read_chunk_tree From: syzbot To: hariconscious@gmail.com, linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com Content-Type: text/plain; charset="UTF-8" Hello, syzbot has tested the proposed patch but the reproducer is still triggering an issue: memory leak in btrfs_read_chunk_tree BUG: memory leak unreferenced object 0xffff88812ca1a800 (size 512): comm "syz.0.17", pid 6724, jiffies 4294946683 hex dump (first 32 bytes): 00 fe 44 da de 57 40 6a 82 41 57 ec 7d 44 12 cf ..D..W@j.AW.}D.. 00 fe 44 da de 57 40 6a 82 41 57 ec 7d 44 12 cf ..D..W@j.AW.}D.. backtrace (crc b9deaaec): kmemleak_alloc_recursive include/linux/kmemleak.h:44 [inline] slab_post_alloc_hook mm/slub.c:4953 [inline] slab_alloc_node mm/slub.c:5258 [inline] __kmalloc_cache_noprof+0x3b2/0x570 mm/slub.c:5766 kmalloc_noprof include/linux/slab.h:957 [inline] kzalloc_noprof include/linux/slab.h:1094 [inline] alloc_fs_devices+0x20/0xc0 fs/btrfs/volumes.c:381 open_seed_devices fs/btrfs/volumes.c:7125 [inline] read_one_dev fs/btrfs/volumes.c:7181 [inline] btrfs_read_chunk_tree+0xa8f/0xd20 fs/btrfs/volumes.c:7478 open_ctree+0xddd/0x23e0 fs/btrfs/disk-io.c:3443 btrfs_fill_super fs/btrfs/super.c:983 [inline] btrfs_get_tree_super fs/btrfs/super.c:1946 [inline] btrfs_get_tree_subvol fs/btrfs/super.c:2089 [inline] btrfs_get_tree+0x735/0xe00 fs/btrfs/super.c:2123 vfs_get_tree+0x31/0x120 fs/super.c:1751 fc_mount fs/namespace.c:1199 [inline] do_new_mount_fc fs/namespace.c:3636 [inline] do_new_mount fs/namespace.c:3712 [inline] path_mount+0x5b5/0x1320 fs/namespace.c:4022 do_mount fs/namespace.c:4035 [inline] __do_sys_mount fs/namespace.c:4224 [inline] __se_sys_mount fs/namespace.c:4201 [inline] __x64_sys_mount+0x1a2/0x1e0 fs/namespace.c:4201 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0xa4/0xf80 arch/x86/entry/syscall_64.c:94 entry_SYSCALL_64_after_hwframe+0x77/0x7f BUG: memory leak unreferenced object 0xffff88811a7cb400 (size 1024): comm "syz.0.17", pid 6724, jiffies 4294946683 hex dump (first 32 bytes): 90 a8 a1 2c 81 88 ff ff 90 a8 a1 2c 81 88 ff ff ...,.......,.... 10 b4 7c 1a 81 88 ff ff 10 b4 7c 1a 81 88 ff ff ..|.......|..... backtrace (crc 1c3757e): kmemleak_alloc_recursive include/linux/kmemleak.h:44 [inline] slab_post_alloc_hook mm/slub.c:4953 [inline] slab_alloc_node mm/slub.c:5258 [inline] __kmalloc_cache_noprof+0x3b2/0x570 mm/slub.c:5766 kmalloc_noprof include/linux/slab.h:957 [inline] kzalloc_noprof include/linux/slab.h:1094 [inline] btrfs_alloc_device+0x5c/0x1f0 fs/btrfs/volumes.c:6860 add_missing_dev+0x4b/0xf0 fs/btrfs/volumes.c:6820 read_one_dev fs/btrfs/volumes.c:7196 [inline] btrfs_read_chunk_tree+0x7cf/0xd20 fs/btrfs/volumes.c:7478 open_ctree+0xddd/0x23e0 fs/btrfs/disk-io.c:3443 btrfs_fill_super fs/btrfs/super.c:983 [inline] btrfs_get_tree_super fs/btrfs/super.c:1946 [inline] btrfs_get_tree_subvol fs/btrfs/super.c:2089 [inline] btrfs_get_tree+0x735/0xe00 fs/btrfs/super.c:2123 vfs_get_tree+0x31/0x120 fs/super.c:1751 fc_mount fs/namespace.c:1199 [inline] do_new_mount_fc fs/namespace.c:3636 [inline] do_new_mount fs/namespace.c:3712 [inline] path_mount+0x5b5/0x1320 fs/namespace.c:4022 do_mount fs/namespace.c:4035 [inline] __do_sys_mount fs/namespace.c:4224 [inline] __se_sys_mount fs/namespace.c:4201 [inline] __x64_sys_mount+0x1a2/0x1e0 fs/namespace.c:4201 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0xa4/0xf80 arch/x86/entry/syscall_64.c:94 entry_SYSCALL_64_after_hwframe+0x77/0x7f BUG: memory leak unreferenced object 0xffff88812ca1be00 (size 512): comm "syz.0.18", pid 6765, jiffies 4294946709 hex dump (first 32 bytes): 00 fe 44 da de 57 40 6a 82 41 57 ec 7d 44 12 cf ..D..W@j.AW.}D.. 00 fe 44 da de 57 40 6a 82 41 57 ec 7d 44 12 cf ..D..W@j.AW.}D.. backtrace (crc e80f9fa6): kmemleak_alloc_recursive include/linux/kmemleak.h:44 [inline] slab_post_alloc_hook mm/slub.c:4953 [inline] slab_alloc_node mm/slub.c:5258 [inline] __kmalloc_cache_noprof+0x3b2/0x570 mm/slub.c:5766 kmalloc_noprof include/linux/slab.h:957 [inline] kzalloc_noprof include/linux/slab.h:1094 [inline] alloc_fs_devices+0x20/0xc0 fs/btrfs/volumes.c:381 open_seed_devices fs/btrfs/volumes.c:7125 [inline] read_one_dev fs/btrfs/volumes.c:7181 [inline] btrfs_read_chunk_tree+0xa8f/0xd20 fs/btrfs/volumes.c:7478 open_ctree+0xddd/0x23e0 fs/btrfs/disk-io.c:3443 btrfs_fill_super fs/btrfs/super.c:983 [inline] btrfs_get_tree_super fs/btrfs/super.c:1946 [inline] btrfs_get_tree_subvol fs/btrfs/super.c:2089 [inline] btrfs_get_tree+0x735/0xe00 fs/btrfs/super.c:2123 vfs_get_tree+0x31/0x120 fs/super.c:1751 fc_mount fs/namespace.c:1199 [inline] do_new_mount_fc fs/namespace.c:3636 [inline] do_new_mount fs/namespace.c:3712 [inline] path_mount+0x5b5/0x1320 fs/namespace.c:4022 do_mount fs/namespace.c:4035 [inline] __do_sys_mount fs/namespace.c:4224 [inline] __se_sys_mount fs/namespace.c:4201 [inline] __x64_sys_mount+0x1a2/0x1e0 fs/namespace.c:4201 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0xa4/0xf80 arch/x86/entry/syscall_64.c:94 entry_SYSCALL_64_after_hwframe+0x77/0x7f BUG: memory leak unreferenced object 0xffff88811a7c8800 (size 1024): comm "syz.0.18", pid 6765, jiffies 4294946709 hex dump (first 32 bytes): 90 be a1 2c 81 88 ff ff 90 be a1 2c 81 88 ff ff ...,.......,.... 10 88 7c 1a 81 88 ff ff 10 88 7c 1a 81 88 ff ff ..|.......|..... backtrace (crc 8f04a734): kmemleak_alloc_recursive include/linux/kmemleak.h:44 [inline] slab_post_alloc_hook mm/slub.c:4953 [inline] slab_alloc_node mm/slub.c:5258 [inline] __kmalloc_cache_noprof+0x3b2/0x570 mm/slub.c:5766 kmalloc_noprof include/linux/slab.h:957 [inline] kzalloc_noprof include/linux/slab.h:1094 [inline] btrfs_alloc_device+0x5c/0x1f0 fs/btrfs/volumes.c:6860 add_missing_dev+0x4b/0xf0 fs/btrfs/volumes.c:6820 read_one_dev fs/btrfs/volumes.c:7196 [inline] btrfs_read_chunk_tree+0x7cf/0xd20 fs/btrfs/volumes.c:7478 open_ctree+0xddd/0x23e0 fs/btrfs/disk-io.c:3443 btrfs_fill_super fs/btrfs/super.c:983 [inline] btrfs_get_tree_super fs/btrfs/super.c:1946 [inline] btrfs_get_tree_subvol fs/btrfs/super.c:2089 [inline] btrfs_get_tree+0x735/0xe00 fs/btrfs/super.c:2123 vfs_get_tree+0x31/0x120 fs/super.c:1751 fc_mount fs/namespace.c:1199 [inline] do_new_mount_fc fs/namespace.c:3636 [inline] do_new_mount fs/namespace.c:3712 [inline] path_mount+0x5b5/0x1320 fs/namespace.c:4022 do_mount fs/namespace.c:4035 [inline] __do_sys_mount fs/namespace.c:4224 [inline] __se_sys_mount fs/namespace.c:4201 [inline] __x64_sys_mount+0x1a2/0x1e0 fs/namespace.c:4201 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0xa4/0xf80 arch/x86/entry/syscall_64.c:94 entry_SYSCALL_64_after_hwframe+0x77/0x7f BUG: memory leak unreferenced object 0xffff888127bf8200 (size 512): comm "syz.0.19", pid 6787, jiffies 4294946730 hex dump (first 32 bytes): 00 fe 44 da de 57 40 6a 82 41 57 ec 7d 44 12 cf ..D..W@j.AW.}D.. 00 fe 44 da de 57 40 6a 82 41 57 ec 7d 44 12 cf ..D..W@j.AW.}D.. backtrace (crc abd95a3a): kmemleak_alloc_recursive include/linux/kmemleak.h:44 [inline] slab_post_alloc_hook mm/slub.c:4953 [inline] slab_alloc_node mm/slub.c:5258 [inline] __kmalloc_cache_noprof+0x3b2/0x570 mm/slub.c:5766 kmalloc_noprof include/linux/slab.h:957 [inline] kzalloc_noprof include/linux/slab.h:1094 [inline] alloc_fs_devices+0x20/0xc0 fs/btrfs/volumes.c:381 open_seed_devices fs/btrfs/volumes.c:7125 [inline] read_one_dev fs/btrfs/volumes.c:7181 [inline] btrfs_read_chunk_tree+0xa8f/0xd20 fs/btrfs/volumes.c:7478 open_ctree+0xddd/0x23e0 fs/btrfs/disk-io.c:3443 btrfs_fill_super fs/btrfs/super.c:983 [inline] btrfs_get_tree_super fs/btrfs/super.c:1946 [inline] btrfs_get_tree_subvol fs/btrfs/super.c:2089 [inline] btrfs_get_tree+0x735/0xe00 fs/btrfs/super.c:2123 vfs_get_tree+0x31/0x120 fs/super.c:1751 fc_mount fs/namespace.c:1199 [inline] do_new_mount_fc fs/namespace.c:3636 [inline] do_new_mount fs/namespace.c:3712 [inline] path_mount+0x5b5/0x1320 fs/namespace.c:4022 do_mount fs/namespace.c:4035 [inline] __do_sys_mount fs/namespace.c:4224 [inline] __se_sys_mount fs/namespace.c:4201 [inline] __x64_sys_mount+0x1a2/0x1e0 fs/namespace.c:4201 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0xa4/0xf80 arch/x86/entry/syscall_64.c:94 entry_SYSCALL_64_after_hwframe+0x77/0x7f BUG: memory leak unreferenced object 0xffff88810a2ff800 (size 1024): comm "syz.0.19", pid 6787, jiffies 4294946730 hex dump (first 32 bytes): 90 82 bf 27 81 88 ff ff 90 82 bf 27 81 88 ff ff ...'.......'.... 10 f8 2f 0a 81 88 ff ff 10 f8 2f 0a 81 88 ff ff ../......./..... backtrace (crc d2573d23): kmemleak_alloc_recursive include/linux/kmemleak.h:44 [inline] slab_post_alloc_hook mm/slub.c:4953 [inline] slab_alloc_node mm/slub.c:5258 [inline] __kmalloc_cache_noprof+0x3b2/0x570 mm/slub.c:5766 kmalloc_noprof include/linux/slab.h:957 [inline] kzalloc_noprof include/linux/slab.h:1094 [inline] btrfs_alloc_device+0x5c/0x1f0 fs/btrfs/volumes.c:6860 add_missing_dev+0x4b/0xf0 fs/btrfs/volumes.c:6820 read_one_dev fs/btrfs/volumes.c:7196 [inline] btrfs_read_chunk_tree+0x7cf/0xd20 fs/btrfs/volumes.c:7478 open_ctree+0xddd/0x23e0 fs/btrfs/disk-io.c:3443 btrfs_fill_super fs/btrfs/super.c:983 [inline] btrfs_get_tree_super fs/btrfs/super.c:1946 [inline] btrfs_get_tree_subvol fs/btrfs/super.c:2089 [inline] btrfs_get_tree+0x735/0xe00 fs/btrfs/super.c:2123 vfs_get_tree+0x31/0x120 fs/super.c:1751 fc_mount fs/namespace.c:1199 [inline] do_new_mount_fc fs/namespace.c:3636 [inline] do_new_mount fs/namespace.c:3712 [inline] path_mount+0x5b5/0x1320 fs/namespace.c:4022 do_mount fs/namespace.c:4035 [inline] __do_sys_mount fs/namespace.c:4224 [inline] __se_sys_mount fs/namespace.c:4201 [inline] __x64_sys_mount+0x1a2/0x1e0 fs/namespace.c:4201 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0xa4/0xf80 arch/x86/entry/syscall_64.c:94 entry_SYSCALL_64_after_hwframe+0x77/0x7f connection error: failed to recv *flatrpc.ExecutorMessageRawT: EOF Tested on: commit: 0048fbb4 Merge tag 'locking-futex-2025-12-10' of git:/.. git tree: upstream console output: https://syzkaller.appspot.com/x/log.txt?x=15a8b992580000 kernel config: https://syzkaller.appspot.com/x/.config?x=9a0268003e02068d dashboard link: https://syzkaller.appspot.com/bug?extid=eadd98df8bceb15d7fed compiler: gcc (Debian 12.2.0-14+deb12u1) 12.2.0, GNU ld (GNU Binutils for Debian) 2.40 patch: https://syzkaller.appspot.com/x/patch.diff?x=1513da1a580000