From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-oo1-f70.google.com (mail-oo1-f70.google.com [209.85.161.70]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 24A854D77C5 for ; Thu, 8 Jan 2026 14:06:47 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.161.70 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1767881209; cv=none; b=R1GAkibB9cXT+xpQP2AZIR66Dpsn1ebQnod298vN+RFPE4xlMufSPGa5RARNYutYkJG+vrKcThOS9LVrJiCQUPUwbiWHFUP32cmCbAJiDn1PbMMkPKZBSCU6IwjVDjiZZ4QU5cOPUJBM7E77rrhFEsB3N/+Xj5GmQENYJwbd7+M= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1767881209; c=relaxed/simple; bh=81O6fELx/4KEkPbPlBOc79CGGNnQOe5rXHLTgyQZUOU=; h=MIME-Version:Date:In-Reply-To:Message-ID:Subject:From:To:Cc: Content-Type; b=GqRz7d5EWZAI6/Zny1mn0FV0DOY4qQ8zvNc3zYeRDWKFjZNRjXNgs/CT1HGDXyy5u+rjK5DxzaGAj7x5MooMvLIuAzjRsC7npn8QFr4503qDWhEwpo6CdSm/pOV3rsdVRanEXYd9EdDtzUNoP99X/m6ViYI/WYUp8RP+6qpqOrc= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=syzkaller.appspotmail.com; spf=pass smtp.mailfrom=M3KW2WVRGUFZ5GODRSRYTGD7.apphosting.bounces.google.com; arc=none smtp.client-ip=209.85.161.70 Authentication-Results: smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=syzkaller.appspotmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=M3KW2WVRGUFZ5GODRSRYTGD7.apphosting.bounces.google.com Received: by mail-oo1-f70.google.com with SMTP id 006d021491bc7-65b31ec93e7so7649566eaf.3 for ; Thu, 08 Jan 2026 06:06:47 -0800 (PST) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1767881207; x=1768486007; h=cc:to:from:subject:message-id:in-reply-to:date:mime-version :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=kuU7VxjFHP/Q2f8SCgq6oSooShd8Z9CT8vLB5H7NiEA=; b=VkVBxNlXUQDcYwoyn0EuWGvlSwqQK4EEKVs5Dd5iXpgxFQjDr9rH+Q/bmrNmCBjJfD +G8a73kMHbHFawbWCqhUMyS8pDfyMgS8b2pkjEGlO01tz3TaowYt5sg8wDLHiahyVWKg 6RK1crKBHxaZqUvSqvIVbiF8FraofNpQY6cVgrV4m3Qe1Vfizn9Li7RtcP7OTl4wpUbi YCCzSZug2KEZalGMigZaiS2XCHMV3vlweQ8J3EcCNgKVppaadpifC/iqwua25IgkEHqV NQnqLvxtAUbrsawofCcehiAFKmy++jwYFevFpmZBwvxlEdMToSiDck4+BovUcNQaIYEP wuqQ== X-Forwarded-Encrypted: i=1; AJvYcCVEBS669rnCdso5iNyTa4QR9gEkbnP77bkaNZhWko+0AsCavMDJq025sogYFoRtTMKeVlsx74ogK9l4Dgk=@vger.kernel.org X-Gm-Message-State: AOJu0YwWwe9BNt9W2qdbH9DF8Wbqxnun9V5YODmz/nXKRZjuEHn37rCl 0olN3dq0buoI0mfBirPyYwGUXKgjsh4joZihOTjSkZiZX+kkdIESGiBQfCdP32tOGm3xlR/GgOA IhOzyrwn7JZNHujXlnxBRdwujH1I/V1Kow9yYDGVi//PuWVFkdZATBAhyEaA= X-Google-Smtp-Source: AGHT+IGULEw+VtCYK6/9MZCIK7ydK+PQByNzh3TSbyRFeOojKDsWv6ntYI/lGkwuIyi1uezE3E6yQNo+DeiAOnoH6JoqxD3Naqd3 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Received: by 2002:a05:6820:160f:b0:65e:c673:777a with SMTP id 006d021491bc7-65f550982eemr2584412eaf.58.1767881207131; Thu, 08 Jan 2026 06:06:47 -0800 (PST) Date: Thu, 08 Jan 2026 06:06:47 -0800 In-Reply-To: X-Google-Appengine-App-Id: s~syzkaller X-Google-Appengine-App-Id-Alias: syzkaller Message-ID: <695fb9f7.050a0220.1c677c.03a0.GAE@google.com> Subject: Re: [PATCH v2] ocfs2: fix circular locking dependency in ocfs2_acquire_dquot From: syzbot To: swilczek.lx@gmail.com Cc: swilczek.lx@gmail.com, linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com Content-Type: text/plain; charset="UTF-8" > #syz test: git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git This crash does not have a reproducer. I cannot test it. > master > > diff --git a/fs/ocfs2/quota_global.c b/fs/ocfs2/quota_global.c > index e85b1ccf81be..95bb901820cf 100644 > --- a/fs/ocfs2/quota_global.c > +++ b/fs/ocfs2/quota_global.c > @@ -821,13 +821,35 @@ static int ocfs2_acquire_dquot(struct dquot *dquot) > trace_ocfs2_acquire_dquot(from_kqid(&init_user_ns, dquot->dq_id), > type); > mutex_lock(&dquot->dq_lock); > + > + /* > + * Speculatively extend quota file before acquiring any locks or > + * starting transaction to avoid lock inversion. sb_start_intwrite > + * (via ocfs2_start_trans) ranks above quota file locks. > + */ > + if (need_alloc) { > + WARN_ON(journal_current_handle()); > + status = ocfs2_extend_no_holes(gqinode, NULL, > + i_size_read(gqinode) + (need_alloc << > sb->s_blocksize_bits), > + i_size_read(gqinode)); > + if (status < 0) > + goto out; > + } > + > + handle = ocfs2_start_trans(osb, > + ocfs2_calc_global_qinit_credits(sb, type)); > + if (IS_ERR(handle)) { > + status = PTR_ERR(handle); > + goto out; > + } > + > /* > * We need an exclusive lock, because we're going to update use count > * and instantiate possibly new dquot structure > */ > status = ocfs2_lock_global_qf(info, 1); > if (status < 0) > - goto out; > + goto out_trans; > status = ocfs2_qinfo_lock(info, 0); > if (status < 0) > goto out_dq; > @@ -843,29 +865,12 @@ static int ocfs2_acquire_dquot(struct dquot *dquot) > OCFS2_DQUOT(dquot)->dq_use_count++; > OCFS2_DQUOT(dquot)->dq_origspace = dquot->dq_dqb.dqb_curspace; > OCFS2_DQUOT(dquot)->dq_originodes = dquot->dq_dqb.dqb_curinodes; > - if (!dquot->dq_off) { /* No real quota entry? */ > + if (!dquot->dq_off) /* No real quota entry? */ > ex = 1; > - /* > - * Add blocks to quota file before we start a transaction since > - * locking allocators ranks above a transaction start > - */ > - WARN_ON(journal_current_handle()); > - status = ocfs2_extend_no_holes(gqinode, NULL, > - i_size_read(gqinode) + (need_alloc << > sb->s_blocksize_bits), > - i_size_read(gqinode)); > - if (status < 0) > - goto out_dq; > - } > > - handle = ocfs2_start_trans(osb, > - ocfs2_calc_global_qinit_credits(sb, type)); > - if (IS_ERR(handle)) { > - status = PTR_ERR(handle); > - goto out_dq; > - } > status = ocfs2_qinfo_lock(info, ex); > if (status < 0) > - goto out_trans; > + goto out_dq; > status = qtree_write_dquot(&info->dqi_gi, dquot); > if (ex && info_dirty(sb_dqinfo(sb, type))) { > err = __ocfs2_global_write_info(sb, type); > @@ -873,10 +878,10 @@ static int ocfs2_acquire_dquot(struct dquot *dquot) > status = err; > } > ocfs2_qinfo_unlock(info, ex); > -out_trans: > - ocfs2_commit_trans(osb, handle); > out_dq: > ocfs2_unlock_global_qf(info, 1); > +out_trans: > + ocfs2_commit_trans(osb, handle); > if (status < 0) > goto out;