* [syzbot] [f2fs?] kernel BUG in clear_inode (5)
@ 2026-02-04 0:52 syzbot
2026-02-05 11:55 ` Forwarded: #syz test https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git f14faaf3a1fb3b9e4cf2e56269711fb85fba9458 syzbot
` (5 more replies)
0 siblings, 6 replies; 13+ messages in thread
From: syzbot @ 2026-02-04 0:52 UTC (permalink / raw)
To: chao, jaegeuk, linux-f2fs-devel, linux-kernel, syzkaller-bugs
Hello,
syzbot found the following issue on:
HEAD commit: dee65f79364c Merge tag 'lsm-pr-20260202' of git://git.kern..
git tree: upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=1639fbfa580000
kernel config: https://syzkaller.appspot.com/x/.config?x=151a39927f1e10b4
dashboard link: https://syzkaller.appspot.com/bug?extid=fc026e87558558f75c00
compiler: Debian clang version 21.1.8 (++20251221033036+2078da43e25a-1~exp1~20251221153213.50), Debian LLD 21.1.8
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=114fb322580000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=1245fc5a580000
Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/d5a48068ae28/disk-dee65f79.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/2c254f049b04/vmlinux-dee65f79.xz
kernel image: https://storage.googleapis.com/syzbot-assets/12b280dac533/bzImage-dee65f79.xz
mounted in repro: https://storage.googleapis.com/syzbot-assets/bce313ec1951/mount_0.gz
fsck result: failed (log: https://syzkaller.appspot.com/x/fsck.log?x=164fb322580000)
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+fc026e87558558f75c00@syzkaller.appspotmail.com
F2FS-fs (loop0): Wrong SSA boundary, start(3584) end(4096) blocks(3072)
F2FS-fs (loop0): Can't find valid F2FS filesystem in 1th superblock
F2FS-fs (loop0): Image doesn't support compression
F2FS-fs (loop0): invalid crc value
------------[ cut here ]------------
kernel BUG at fs/inode.c:782!
Oops: invalid opcode: 0000 [#1] SMP KASAN PTI
CPU: 1 UID: 0 PID: 6061 Comm: syz.0.17 Not tainted syzkaller #0 PREEMPT_{RT,(full)}
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/24/2026
RIP: 0010:clear_inode+0x19a/0x1c0 fs/inode.c:782
Code: 4c 89 f7 e8 08 2f eb ff e9 5a ff ff ff 44 89 f1 80 e1 07 80 c1 03 38 c1 7c a2 4c 89 f7 e8 de 2f eb ff eb 98 e8 47 c7 86 ff 90 <0f> 0b e8 3f c7 86 ff 90 0f 0b e8 37 c7 86 ff 90 0f 0b e8 2f c7 86
RSP: 0018:ffffc90003e17850 EFLAGS: 00010293
RAX: ffffffff823c6d29 RBX: ffff888057a99310 RCX: ffff88802b1edac0
RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000000
RBP: ffffc90003e179c0 R08: 0000000000000000 R09: 0000000000000000
R10: dffffc0000000000 R11: fffffbfff1e8fbef R12: dffffc0000000000
R13: 1ffff920007c2f1c R14: ffff888057a99568 R15: 0000000000000001
FS: 000055557a53e500(0000) GS:ffff8881266c9000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007fff6ffc5bbc CR3: 0000000034a72000 CR4: 00000000003526f0
Call Trace:
<TASK>
evict+0x61e/0xb10 fs/inode.c:837
f2fs_fill_super+0x54e4/0x6e30 fs/f2fs/super.c:5147
get_tree_bdev_flags+0x431/0x4f0 fs/super.c:1691
vfs_get_tree+0x92/0x2a0 fs/super.c:1751
fc_mount fs/namespace.c:1199 [inline]
do_new_mount_fc fs/namespace.c:3636 [inline]
do_new_mount+0x329/0xa50 fs/namespace.c:3712
do_mount fs/namespace.c:4035 [inline]
__do_sys_mount fs/namespace.c:4224 [inline]
__se_sys_mount+0x31d/0x420 fs/namespace.c:4201
do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
do_syscall_64+0xe2/0xf80 arch/x86/entry/syscall_64.c:94
entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7ff95c0cc14a
Code: 48 c7 c2 e8 ff ff ff f7 d8 64 89 02 b8 ff ff ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 49 89 ca b8 a5 00 00 00 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 e8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007ffd4f028d88 EFLAGS: 00000246 ORIG_RAX: 00000000000000a5
RAX: ffffffffffffffda RBX: 00007ffd4f028e10 RCX: 00007ff95c0cc14a
RDX: 0000200000000140 RSI: 00002000000001c0 RDI: 00007ffd4f028dd0
RBP: 0000200000000140 R08: 00007ffd4f028e10 R09: 0000000000000008
R10: 0000000000000008 R11: 0000000000000246 R12: 00002000000001c0
R13: 00007ffd4f028dd0 R14: 0000000000005548 R15: 0000200000000200
</TASK>
Modules linked in:
---[ end trace 0000000000000000 ]---
RIP: 0010:clear_inode+0x19a/0x1c0 fs/inode.c:782
Code: 4c 89 f7 e8 08 2f eb ff e9 5a ff ff ff 44 89 f1 80 e1 07 80 c1 03 38 c1 7c a2 4c 89 f7 e8 de 2f eb ff eb 98 e8 47 c7 86 ff 90 <0f> 0b e8 3f c7 86 ff 90 0f 0b e8 37 c7 86 ff 90 0f 0b e8 2f c7 86
RSP: 0018:ffffc90003e17850 EFLAGS: 00010293
RAX: ffffffff823c6d29 RBX: ffff888057a99310 RCX: ffff88802b1edac0
RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000000
RBP: ffffc90003e179c0 R08: 0000000000000000 R09: 0000000000000000
R10: dffffc0000000000 R11: fffffbfff1e8fbef R12: dffffc0000000000
R13: 1ffff920007c2f1c R14: ffff888057a99568 R15: 0000000000000001
FS: 000055557a53e500(0000) GS:ffff8881266c9000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007fff6ffc5bbc CR3: 0000000034a72000 CR4: 00000000003526f0
---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzkaller@googlegroups.com.
syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title
If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.
If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)
If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report
If you want to undo deduplication, reply with:
#syz undup
^ permalink raw reply [flat|nested] 13+ messages in thread* Forwarded: #syz test https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git f14faaf3a1fb3b9e4cf2e56269711fb85fba9458 2026-02-04 0:52 [syzbot] [f2fs?] kernel BUG in clear_inode (5) syzbot @ 2026-02-05 11:55 ` syzbot 2026-02-24 14:44 ` Forwarded: Re: [syzbot] [f2fs?] kernel BUG in clear_inode (5) syzbot ` (4 subsequent siblings) 5 siblings, 0 replies; 13+ messages in thread From: syzbot @ 2026-02-05 11:55 UTC (permalink / raw) To: linux-kernel, syzkaller-bugs For archival purposes, forwarding an incoming command email to linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com. *** Subject: #syz test https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git f14faaf3a1fb3b9e4cf2e56269711fb85fba9458 Author: dmantipov@yandex.ru #syz test https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git f14faaf3a1fb3b9e4cf2e56269711fb85fba9458 ^ permalink raw reply [flat|nested] 13+ messages in thread
* Forwarded: Re: [syzbot] [f2fs?] kernel BUG in clear_inode (5) 2026-02-04 0:52 [syzbot] [f2fs?] kernel BUG in clear_inode (5) syzbot 2026-02-05 11:55 ` Forwarded: #syz test https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git f14faaf3a1fb3b9e4cf2e56269711fb85fba9458 syzbot @ 2026-02-24 14:44 ` syzbot 2026-02-24 14:52 ` syzbot ` (3 subsequent siblings) 5 siblings, 0 replies; 13+ messages in thread From: syzbot @ 2026-02-24 14:44 UTC (permalink / raw) To: linux-kernel, syzkaller-bugs For archival purposes, forwarding an incoming command email to linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com. *** Subject: Re: [syzbot] [f2fs?] kernel BUG in clear_inode (5) Author: kth5965@gmail.com #syz test: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git master diff --git a/fs/f2fs/inode.c b/fs/f2fs/inode.c index 38b8994bc1b2..914a0966a1c5 100644 --- a/fs/f2fs/inode.c +++ b/fs/f2fs/inode.c @@ -1001,6 +1001,13 @@ void f2fs_evict_inode(struct inode *inode) out_clear: fscrypt_put_encryption_info(inode); fsverity_cleanup_inode(inode); + /* + * Pages in inode's data mapping may have been re-added during + * eviction, e.g. by f2fs_convert_inline_inode() called from + * f2fs_truncate(). Truncate them again before clear_inode() + * which expects nrpages == 0. + */ + truncate_inode_pages_final(&inode->i_data); clear_inode(inode); } ^ permalink raw reply [flat|nested] 13+ messages in thread
* Forwarded: Re: [syzbot] [f2fs?] kernel BUG in clear_inode (5) 2026-02-04 0:52 [syzbot] [f2fs?] kernel BUG in clear_inode (5) syzbot 2026-02-05 11:55 ` Forwarded: #syz test https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git f14faaf3a1fb3b9e4cf2e56269711fb85fba9458 syzbot 2026-02-24 14:44 ` Forwarded: Re: [syzbot] [f2fs?] kernel BUG in clear_inode (5) syzbot @ 2026-02-24 14:52 ` syzbot 2026-03-28 15:41 ` Forwarded: Re: [syzbot] [f2fs?] kernel BUG in clear_inode syzbot ` (2 subsequent siblings) 5 siblings, 0 replies; 13+ messages in thread From: syzbot @ 2026-02-24 14:52 UTC (permalink / raw) To: linux-kernel, syzkaller-bugs For archival purposes, forwarding an incoming command email to linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com. *** Subject: Re: [syzbot] [f2fs?] kernel BUG in clear_inode (5) Author: kth5965@gmail.com #syz test: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git master diff --git a/fs/f2fs/inode.c b/fs/f2fs/inode.c --- a/fs/f2fs/inode.c +++ b/fs/f2fs/inode.c @@ -1007,6 +1007,13 @@ void f2fs_evict_inode(struct inode *inode) out_clear: fscrypt_put_encryption_info(inode); + /* + * Pages in inode's data mapping may have been re-added during + * eviction, e.g. by f2fs_convert_inline_inode() called from + * f2fs_truncate(). Truncate them again before clear_inode() + * which expects nrpages == 0. + */ + truncate_inode_pages_final(&inode->i_data); clear_inode(inode); } ^ permalink raw reply [flat|nested] 13+ messages in thread
* Forwarded: Re: [syzbot] [f2fs?] kernel BUG in clear_inode 2026-02-04 0:52 [syzbot] [f2fs?] kernel BUG in clear_inode (5) syzbot ` (2 preceding siblings ...) 2026-02-24 14:52 ` syzbot @ 2026-03-28 15:41 ` syzbot 2026-03-28 15:47 ` syzbot 2026-03-28 16:17 ` syzbot 5 siblings, 0 replies; 13+ messages in thread From: syzbot @ 2026-03-28 15:41 UTC (permalink / raw) To: linux-kernel, syzkaller-bugs For archival purposes, forwarding an incoming command email to linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com. *** Subject: Re: [syzbot] [f2fs?] kernel BUG in clear_inode Author: kth5965@gmail.com #syz test: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git master diff --git a/fs/f2fs/inline.c b/fs/f2fs/inline.c index 0a1052d5ee62..92fcadf6d2cc 100644 --- a/fs/f2fs/inline.c +++ b/fs/f2fs/inline.c @@ -53,8 +53,8 @@ bool f2fs_sanity_check_inline_data(struct inode *inode, struct folio *ifolio) if (!f2fs_has_inline_data(inode)) return false; - if (inode_has_blocks(inode, ifolio)) - return false; + if (!f2fs_exist_data(inode) && inode_has_blocks(inode, ifolio)) + return true; if (!support_inline_data(inode)) return true; @@ -142,6 +142,17 @@ int f2fs_read_inline_data(struct inode *inode, struct folio *folio) return 0; } +static void f2fs_clear_inline_inode(struct dnode_of_data *dn) +{ + f2fs_folio_wait_writeback(dn->inode_folio, NODE, true, true); + clear_inode_flag(dn->inode, FI_DATA_EXIST); + clear_inode_flag(dn->inode, FI_INLINE_DATA); + set_raw_inline(dn->inode, F2FS_INODE(dn->inode_folio)); + folio_mark_dirty(dn->inode_folio); + folio_clear_f2fs_inline(dn->inode_folio); + stat_dec_inline_inode(dn->inode); +} + int f2fs_convert_inline_folio(struct dnode_of_data *dn, struct folio *folio) { struct f2fs_io_info fio = { @@ -157,8 +168,10 @@ int f2fs_convert_inline_folio(struct dnode_of_data *dn, struct folio *folio) struct node_info ni; int dirty, err; - if (!f2fs_exist_data(dn->inode)) - goto clear_out; + if (!f2fs_exist_data(dn->inode)) { + f2fs_clear_inline_inode(dn); + goto out; + } err = f2fs_reserve_block(dn, 0); if (err) @@ -206,10 +219,8 @@ int f2fs_convert_inline_folio(struct dnode_of_data *dn, struct folio *folio) /* clear inline data and flag after data writeback */ f2fs_truncate_inline_inode(dn->inode, dn->inode_folio, 0); - folio_clear_f2fs_inline(dn->inode_folio); -clear_out: - stat_dec_inline_inode(dn->inode); - clear_inode_flag(dn->inode, FI_INLINE_DATA); + f2fs_clear_inline_inode(dn); +out: f2fs_put_dnode(dn); return 0; } @@ -232,9 +243,7 @@ int f2fs_convert_inline_inode(struct inode *inode) if (err) return err; - folio = f2fs_grab_cache_folio(inode->i_mapping, 0, false); - if (IS_ERR(folio)) - return PTR_ERR(folio); + set_new_dnode(&dn, inode, NULL, NULL, 0); f2fs_lock_op(sbi, &lc); @@ -246,14 +255,23 @@ int f2fs_convert_inline_inode(struct inode *inode) set_new_dnode(&dn, inode, ifolio, ifolio, 0); + if (f2fs_has_inline_data(inode) && f2fs_exist_data(inode)) { + folio = f2fs_grab_cache_folio(inode->i_mapping, 0, false); + if (IS_ERR(folio)) { + err = PTR_ERR(folio); + folio = NULL; + goto out; + } + } + if (f2fs_has_inline_data(inode)) err = f2fs_convert_inline_folio(&dn, folio); - f2fs_put_dnode(&dn); out: + f2fs_put_dnode(&dn); f2fs_unlock_op(sbi, &lc); - - f2fs_folio_put(folio, true); + if (folio) + f2fs_folio_put(folio, true); if (!err) f2fs_balance_fs(sbi, dn.node_changed); diff --git a/fs/f2fs/inode.c b/fs/f2fs/inode.c index e7942e6e312c..e0f850b3f0c3 100644 --- a/fs/f2fs/inode.c +++ b/fs/f2fs/inode.c @@ -1006,13 +1006,6 @@ void f2fs_evict_inode(struct inode *inode) } out_clear: fscrypt_put_encryption_info(inode); - /* - * Defensively truncate any remaining page cache, e.g. - * f2fs_convert_inline_inode() called from f2fs_truncate() - * may leave page #0 behind in the page cache when the - * inline conversion takes the clear_out success path. - */ - truncate_inode_pages_final(&inode->i_data); clear_inode(inode); } ^ permalink raw reply [flat|nested] 13+ messages in thread
* Forwarded: Re: [syzbot] [f2fs?] kernel BUG in clear_inode 2026-02-04 0:52 [syzbot] [f2fs?] kernel BUG in clear_inode (5) syzbot ` (3 preceding siblings ...) 2026-03-28 15:41 ` Forwarded: Re: [syzbot] [f2fs?] kernel BUG in clear_inode syzbot @ 2026-03-28 15:47 ` syzbot 2026-03-28 16:17 ` syzbot 5 siblings, 0 replies; 13+ messages in thread From: syzbot @ 2026-03-28 15:47 UTC (permalink / raw) To: linux-kernel, syzkaller-bugs For archival purposes, forwarding an incoming command email to linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com. *** Subject: Re: [syzbot] [f2fs?] kernel BUG in clear_inode Author: kth5965@gmail.com #syz test: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git master Corrected patch: this resend excludes the local-only inode.c hunk and tests only the upstream-applicable inline.c fix. diff --git a/fs/f2fs/inline.c b/fs/f2fs/inline.c index 0a1052d5ee62..92fcadf6d2cc 100644 --- a/fs/f2fs/inline.c +++ b/fs/f2fs/inline.c @@ -53,8 +53,8 @@ bool f2fs_sanity_check_inline_data(struct inode *inode, struct folio *ifolio) if (!f2fs_has_inline_data(inode)) return false; - if (inode_has_blocks(inode, ifolio)) - return false; + if (!f2fs_exist_data(inode) && inode_has_blocks(inode, ifolio)) + return true; if (!support_inline_data(inode)) return true; @@ -142,6 +142,17 @@ int f2fs_read_inline_data(struct inode *inode, struct folio *folio) return 0; } +static void f2fs_clear_inline_inode(struct dnode_of_data *dn) +{ + f2fs_folio_wait_writeback(dn->inode_folio, NODE, true, true); + clear_inode_flag(dn->inode, FI_DATA_EXIST); + clear_inode_flag(dn->inode, FI_INLINE_DATA); + set_raw_inline(dn->inode, F2FS_INODE(dn->inode_folio)); + folio_mark_dirty(dn->inode_folio); + folio_clear_f2fs_inline(dn->inode_folio); + stat_dec_inline_inode(dn->inode); +} + int f2fs_convert_inline_folio(struct dnode_of_data *dn, struct folio *folio) { struct f2fs_io_info fio = { @@ -157,8 +168,10 @@ int f2fs_convert_inline_folio(struct dnode_of_data *dn, struct folio *folio) struct node_info ni; int dirty, err; - if (!f2fs_exist_data(dn->inode)) - goto clear_out; + if (!f2fs_exist_data(dn->inode)) { + f2fs_clear_inline_inode(dn); + goto out; + } err = f2fs_reserve_block(dn, 0); if (err) @@ -206,10 +219,8 @@ int f2fs_convert_inline_folio(struct dnode_of_data *dn, struct folio *folio) /* clear inline data and flag after data writeback */ f2fs_truncate_inline_inode(dn->inode, dn->inode_folio, 0); - folio_clear_f2fs_inline(dn->inode_folio); -clear_out: - stat_dec_inline_inode(dn->inode); - clear_inode_flag(dn->inode, FI_INLINE_DATA); + f2fs_clear_inline_inode(dn); +out: f2fs_put_dnode(dn); return 0; } @@ -232,9 +243,7 @@ int f2fs_convert_inline_inode(struct inode *inode) if (err) return err; - folio = f2fs_grab_cache_folio(inode->i_mapping, 0, false); - if (IS_ERR(folio)) - return PTR_ERR(folio); + set_new_dnode(&dn, inode, NULL, NULL, 0); f2fs_lock_op(sbi, &lc); @@ -246,14 +255,23 @@ int f2fs_convert_inline_inode(struct inode *inode) set_new_dnode(&dn, inode, ifolio, ifolio, 0); + if (f2fs_has_inline_data(inode) && f2fs_exist_data(inode)) { + folio = f2fs_grab_cache_folio(inode->i_mapping, 0, false); + if (IS_ERR(folio)) { + err = PTR_ERR(folio); + folio = NULL; + goto out; + } + } + if (f2fs_has_inline_data(inode)) err = f2fs_convert_inline_folio(&dn, folio); - f2fs_put_dnode(&dn); out: + f2fs_put_dnode(&dn); f2fs_unlock_op(sbi, &lc); - - f2fs_folio_put(folio, true); + if (folio) + f2fs_folio_put(folio, true); if (!err) f2fs_balance_fs(sbi, dn.node_changed); ^ permalink raw reply [flat|nested] 13+ messages in thread
* Forwarded: Re: [syzbot] [f2fs?] kernel BUG in clear_inode 2026-02-04 0:52 [syzbot] [f2fs?] kernel BUG in clear_inode (5) syzbot ` (4 preceding siblings ...) 2026-03-28 15:47 ` syzbot @ 2026-03-28 16:17 ` syzbot 5 siblings, 0 replies; 13+ messages in thread From: syzbot @ 2026-03-28 16:17 UTC (permalink / raw) To: linux-kernel, syzkaller-bugs For archival purposes, forwarding an incoming command email to linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com. *** Subject: Re: [syzbot] [f2fs?] kernel BUG in clear_inode Author: kth5965@gmail.com #syz test: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git master diff --git a/fs/f2fs/inline.c b/fs/f2fs/inline.c index 0a1052d5ee62..92fcadf6d2cc 100644 --- a/fs/f2fs/inline.c +++ b/fs/f2fs/inline.c @@ -53,8 +53,8 @@ bool f2fs_sanity_check_inline_data(struct inode *inode, struct folio *ifolio) if (!f2fs_has_inline_data(inode)) return false; - if (inode_has_blocks(inode, ifolio)) - return false; + if (!f2fs_exist_data(inode) && inode_has_blocks(inode, ifolio)) + return true; if (!support_inline_data(inode)) return true; @@ -142,6 +142,17 @@ int f2fs_read_inline_data(struct inode *inode, struct folio *folio) return 0; } +static void f2fs_clear_inline_inode(struct dnode_of_data *dn) +{ + f2fs_folio_wait_writeback(dn->inode_folio, NODE, true, true); + clear_inode_flag(dn->inode, FI_DATA_EXIST); + clear_inode_flag(dn->inode, FI_INLINE_DATA); + set_raw_inline(dn->inode, F2FS_INODE(dn->inode_folio)); + folio_mark_dirty(dn->inode_folio); + folio_clear_f2fs_inline(dn->inode_folio); + stat_dec_inline_inode(dn->inode); +} + int f2fs_convert_inline_folio(struct dnode_of_data *dn, struct folio *folio) { struct f2fs_io_info fio = { @@ -157,8 +168,10 @@ int f2fs_convert_inline_folio(struct dnode_of_data *dn, struct folio *folio) struct node_info ni; int dirty, err; - if (!f2fs_exist_data(dn->inode)) - goto clear_out; + if (!f2fs_exist_data(dn->inode)) { + f2fs_clear_inline_inode(dn); + goto out; + } err = f2fs_reserve_block(dn, 0); if (err) @@ -206,10 +219,8 @@ int f2fs_convert_inline_folio(struct dnode_of_data *dn, struct folio *folio) /* clear inline data and flag after data writeback */ f2fs_truncate_inline_inode(dn->inode, dn->inode_folio, 0); - folio_clear_f2fs_inline(dn->inode_folio); -clear_out: - stat_dec_inline_inode(dn->inode); - clear_inode_flag(dn->inode, FI_INLINE_DATA); + f2fs_clear_inline_inode(dn); +out: f2fs_put_dnode(dn); return 0; } @@ -232,9 +243,7 @@ int f2fs_convert_inline_inode(struct inode *inode) if (err) return err; - folio = f2fs_grab_cache_folio(inode->i_mapping, 0, false); - if (IS_ERR(folio)) - return PTR_ERR(folio); + set_new_dnode(&dn, inode, NULL, NULL, 0); f2fs_lock_op(sbi, &lc); @@ -246,14 +255,23 @@ int f2fs_convert_inline_inode(struct inode *inode) set_new_dnode(&dn, inode, ifolio, ifolio, 0); + if (f2fs_has_inline_data(inode) && f2fs_exist_data(inode)) { + folio = f2fs_grab_cache_folio(inode->i_mapping, 0, false); + if (IS_ERR(folio)) { + err = PTR_ERR(folio); + folio = NULL; + goto out; + } + } + if (f2fs_has_inline_data(inode)) err = f2fs_convert_inline_folio(&dn, folio); - f2fs_put_dnode(&dn); out: + f2fs_put_dnode(&dn); f2fs_unlock_op(sbi, &lc); - - f2fs_folio_put(folio, true); + if (folio) + f2fs_folio_put(folio, true); if (!err) f2fs_balance_fs(sbi, dn.node_changed); ^ permalink raw reply [flat|nested] 13+ messages in thread
[parent not found: <6fa4f99a17c207019e992e70c734c88179c84ecc.camel@yandex.ru>]
* Re: [syzbot] [f2fs?] kernel BUG in clear_inode (5) [not found] <6fa4f99a17c207019e992e70c734c88179c84ecc.camel@yandex.ru> @ 2026-02-05 13:02 ` syzbot 0 siblings, 0 replies; 13+ messages in thread From: syzbot @ 2026-02-05 13:02 UTC (permalink / raw) To: dmantipov, linux-kernel, syzkaller-bugs Hello, syzbot has tested the proposed patch and the reproducer did not trigger any issue: Reported-by: syzbot+fc026e87558558f75c00@syzkaller.appspotmail.com Tested-by: syzbot+fc026e87558558f75c00@syzkaller.appspotmail.com Tested on: commit: f14faaf3 Merge tag 'tsm-fixes-for-6.19' of git://git.k.. git tree: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git console output: https://syzkaller.appspot.com/x/log.txt?x=1302c7fa580000 kernel config: https://syzkaller.appspot.com/x/.config?x=151a39927f1e10b4 dashboard link: https://syzkaller.appspot.com/bug?extid=fc026e87558558f75c00 compiler: Debian clang version 21.1.8 (++20251221033036+2078da43e25a-1~exp1~20251221153213.50), Debian LLD 21.1.8 patch: https://syzkaller.appspot.com/x/patch.diff?x=124b0a52580000 Note: testing is done by a robot and is best-effort only. ^ permalink raw reply [flat|nested] 13+ messages in thread
[parent not found: <20260224144431.447204-1-kth5965@gmail.com>]
* Re: [syzbot] [f2fs?] kernel BUG in clear_inode (5) [not found] <20260224144431.447204-1-kth5965@gmail.com> @ 2026-02-24 14:47 ` syzbot 0 siblings, 0 replies; 13+ messages in thread From: syzbot @ 2026-02-24 14:47 UTC (permalink / raw) To: kth5965, linux-kernel, syzkaller-bugs Hello, syzbot tried to test the proposed patch but the build/boot failed: failed to apply patch: checking file fs/f2fs/inode.c Hunk #1 FAILED at 1001. 1 out of 1 hunk FAILED Tested on: commit: 7dff99b3 Remove WARN_ALL_UNSEEDED_RANDOM kernel config.. git tree: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git master kernel config: https://syzkaller.appspot.com/x/.config?x=151a39927f1e10b4 dashboard link: https://syzkaller.appspot.com/bug?extid=fc026e87558558f75c00 compiler: patch: https://syzkaller.appspot.com/x/patch.diff?x=13ed355a580000 ^ permalink raw reply [flat|nested] 13+ messages in thread
[parent not found: <20260224145250.447332-1-kth5965@gmail.com>]
* Re: [syzbot] [f2fs?] kernel BUG in clear_inode (5) [not found] <20260224145250.447332-1-kth5965@gmail.com> @ 2026-02-24 15:22 ` syzbot 0 siblings, 0 replies; 13+ messages in thread From: syzbot @ 2026-02-24 15:22 UTC (permalink / raw) To: kth5965, linux-kernel, syzkaller-bugs Hello, syzbot has tested the proposed patch and the reproducer did not trigger any issue: Reported-by: syzbot+fc026e87558558f75c00@syzkaller.appspotmail.com Tested-by: syzbot+fc026e87558558f75c00@syzkaller.appspotmail.com Tested on: commit: 7dff99b3 Remove WARN_ALL_UNSEEDED_RANDOM kernel config.. git tree: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git master console output: https://syzkaller.appspot.com/x/log.txt?x=14d8a394580000 kernel config: https://syzkaller.appspot.com/x/.config?x=96aee13764f31d12 dashboard link: https://syzkaller.appspot.com/bug?extid=fc026e87558558f75c00 compiler: Debian clang version 21.1.8 (++20251221033036+2078da43e25a-1~exp1~20251221153213.50), Debian LLD 21.1.8 patch: https://syzkaller.appspot.com/x/patch.diff?x=13c3155a580000 Note: testing is done by a robot and is best-effort only. ^ permalink raw reply [flat|nested] 13+ messages in thread
[parent not found: <69c7f6ba.170a0220.29cadc.a075@mx.google.com>]
* Re: [syzbot] [f2fs?] kernel BUG in clear_inode (5) [not found] <69c7f6ba.170a0220.29cadc.a075@mx.google.com> @ 2026-03-28 15:51 ` syzbot 0 siblings, 0 replies; 13+ messages in thread From: syzbot @ 2026-03-28 15:51 UTC (permalink / raw) To: kth5965, linux-kernel, syzkaller-bugs Hello, syzbot tried to test the proposed patch but the build/boot failed: failed to apply patch: checking file fs/f2fs/inline.c checking file fs/f2fs/inode.c Hunk #1 FAILED at 1006. 1 out of 1 hunk FAILED Tested on: commit: be762d8b Merge tag 'hwmon-for-v7.0-rc6' of git://git.k.. git tree: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git master kernel config: https://syzkaller.appspot.com/x/.config?x=151a39927f1e10b4 dashboard link: https://syzkaller.appspot.com/bug?extid=fc026e87558558f75c00 compiler: patch: https://syzkaller.appspot.com/x/patch.diff?x=14744102580000 ^ permalink raw reply [flat|nested] 13+ messages in thread
[parent not found: <69c7f817.170a0220.33e07b.a1a3@mx.google.com>]
* Re: [syzbot] [f2fs?] kernel BUG in clear_inode (5) [not found] <69c7f817.170a0220.33e07b.a1a3@mx.google.com> @ 2026-03-28 16:01 ` syzbot 0 siblings, 0 replies; 13+ messages in thread From: syzbot @ 2026-03-28 16:01 UTC (permalink / raw) To: kth5965, linux-kernel, syzkaller-bugs Hello, syzbot tried to test the proposed patch but the build/boot failed: unknown enabled syscall: syz_memcpy_off$IO_URING* syzkaller build log: go env (err=<nil>) AR='ar' CC='gcc' CGO_CFLAGS='-O2 -g' CGO_CPPFLAGS='' CGO_CXXFLAGS='-O2 -g' CGO_ENABLED='1' CGO_FFLAGS='-O2 -g' CGO_LDFLAGS='-O2 -g' CXX='g++' GCCGO='gccgo' GO111MODULE='auto' GOAMD64='v1' GOARCH='amd64' GOAUTH='netrc' GOBIN='' GOCACHE='/syzkaller/.cache/go-build' GOCACHEPROG='' GODEBUG='' GOENV='/syzkaller/.config/go/env' GOEXE='' GOEXPERIMENT='' GOFIPS140='off' GOFLAGS='' GOGCCFLAGS='-fPIC -m64 -pthread -Wl,--no-gc-sections -fmessage-length=0 -ffile-prefix-map=/tmp/go-build2642651502=/tmp/go-build -gno-record-gcc-switches' GOHOSTARCH='amd64' GOHOSTOS='linux' GOINSECURE='' GOMOD='/syzkaller/jobs-2/linux/gopath/src/github.com/google/syzkaller/go.mod' GOMODCACHE='/syzkaller/jobs-2/linux/gopath/pkg/mod' GONOPROXY='' GONOSUMDB='' GOOS='linux' GOPATH='/syzkaller/jobs-2/linux/gopath' GOPRIVATE='' GOPROXY='https://proxy.golang.org,direct' GOROOT='/usr/local/go' GOSUMDB='sum.golang.org' GOTELEMETRY='local' GOTELEMETRYDIR='/syzkaller/.config/go/telemetry' GOTMPDIR='' GOTOOLCHAIN='auto' GOTOOLDIR='/usr/local/go/pkg/tool/linux_amd64' GOVCS='' GOVERSION='go1.26.0' GOWORK='' PKG_CONFIG='pkg-config' git status (err=<nil>) HEAD detached at d78927dd8d0 nothing to commit, working tree clean tput: No value for $TERM and no -T specified tput: No value for $TERM and no -T specified Makefile:31: run command via tools/syz-env for best compatibility, see: Makefile:32: https://github.com/google/syzkaller/blob/master/docs/contributing.md#using-syz-env go list -f '{{.Stale}}' -ldflags="-s -w -X github.com/google/syzkaller/prog.GitRevision=d78927dd8d06cbe4d0dadb84bb5f977462dde1fd -X github.com/google/syzkaller/prog.gitRevisionDate=20260202-183658" ./sys/syz-sysgen | grep -q false || go install -ldflags="-s -w -X github.com/google/syzkaller/prog.GitRevision=d78927dd8d06cbe4d0dadb84bb5f977462dde1fd -X github.com/google/syzkaller/prog.gitRevisionDate=20260202-183658" ./sys/syz-sysgen make .descriptions tput: No value for $TERM and no -T specified tput: No value for $TERM and no -T specified Makefile:31: run command via tools/syz-env for best compatibility, see: Makefile:32: https://github.com/google/syzkaller/blob/master/docs/contributing.md#using-syz-env bin/syz-sysgen touch .descriptions GOOS=linux GOARCH=amd64 go build -ldflags="-s -w -X github.com/google/syzkaller/prog.GitRevision=d78927dd8d06cbe4d0dadb84bb5f977462dde1fd -X github.com/google/syzkaller/prog.gitRevisionDate=20260202-183658" -o ./bin/linux_amd64/syz-execprog github.com/google/syzkaller/tools/syz-execprog mkdir -p ./bin/linux_amd64 g++ -o ./bin/linux_amd64/syz-executor executor/executor.cc \ -m64 -O2 -pthread -Wall -Werror -Wparentheses -Wunused-const-variable -Wframe-larger-than=16384 -Wno-stringop-overflow -Wno-array-bounds -Wno-format-overflow -Wno-unused-but-set-variable -Wno-unused-command-line-argument -static-pie -std=c++17 -I. -Iexecutor/_include -DGOOS_linux=1 -DGOARCH_amd64=1 \ -DHOSTGOOS_linux=1 -DGIT_REVISION=\"d78927dd8d06cbe4d0dadb84bb5f977462dde1fd\" /usr/bin/ld: /tmp/ccGHWq3Z.o: in function `Connection::Connect(char const*, char const*)': executor.cc:(.text._ZN10Connection7ConnectEPKcS1_[_ZN10Connection7ConnectEPKcS1_]+0x386): warning: Using 'gethostbyname' in statically linked applications requires at runtime the shared libraries from the glibc version used for linking ./tools/check-syzos.sh 2>/dev/null Tested on: commit: be762d8b Merge tag 'hwmon-for-v7.0-rc6' of git://git.k.. git tree: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git master kernel config: https://syzkaller.appspot.com/x/.config?x=55412ce8dfa1f1a3 dashboard link: https://syzkaller.appspot.com/bug?extid=fc026e87558558f75c00 compiler: Debian clang version 21.1.8 (++20251221033036+2078da43e25a-1~exp1~20251221153213.50), Debian LLD 21.1.8 patch: https://syzkaller.appspot.com/x/patch.diff?x=158d9aca580000 ^ permalink raw reply [flat|nested] 13+ messages in thread
[parent not found: <69c7fefd.170a0220.361dc1.c714@mx.google.com>]
* Re: [syzbot] [f2fs?] kernel BUG in clear_inode (5) [not found] <69c7fefd.170a0220.361dc1.c714@mx.google.com> @ 2026-03-28 16:27 ` syzbot 0 siblings, 0 replies; 13+ messages in thread From: syzbot @ 2026-03-28 16:27 UTC (permalink / raw) To: kth5965, linux-kernel, syzkaller-bugs Hello, syzbot tried to test the proposed patch but the build/boot failed: unknown enabled syscall: syz_memcpy_off$IO_URING* syzkaller build log: go env (err=<nil>) AR='ar' CC='gcc' CGO_CFLAGS='-O2 -g' CGO_CPPFLAGS='' CGO_CXXFLAGS='-O2 -g' CGO_ENABLED='1' CGO_FFLAGS='-O2 -g' CGO_LDFLAGS='-O2 -g' CXX='g++' GCCGO='gccgo' GO111MODULE='auto' GOAMD64='v1' GOARCH='amd64' GOAUTH='netrc' GOBIN='' GOCACHE='/syzkaller/.cache/go-build' GOCACHEPROG='' GODEBUG='' GOENV='/syzkaller/.config/go/env' GOEXE='' GOEXPERIMENT='' GOFIPS140='off' GOFLAGS='' GOGCCFLAGS='-fPIC -m64 -pthread -Wl,--no-gc-sections -fmessage-length=0 -ffile-prefix-map=/tmp/go-build193271333=/tmp/go-build -gno-record-gcc-switches' GOHOSTARCH='amd64' GOHOSTOS='linux' GOINSECURE='' GOMOD='/syzkaller/jobs/linux/gopath/src/github.com/google/syzkaller/go.mod' GOMODCACHE='/syzkaller/jobs/linux/gopath/pkg/mod' GONOPROXY='' GONOSUMDB='' GOOS='linux' GOPATH='/syzkaller/jobs/linux/gopath' GOPRIVATE='' GOPROXY='https://proxy.golang.org,direct' GOROOT='/usr/local/go' GOSUMDB='sum.golang.org' GOTELEMETRY='local' GOTELEMETRYDIR='/syzkaller/.config/go/telemetry' GOTMPDIR='' GOTOOLCHAIN='auto' GOTOOLDIR='/usr/local/go/pkg/tool/linux_amd64' GOVCS='' GOVERSION='go1.26.0' GOWORK='' PKG_CONFIG='pkg-config' git status (err=<nil>) HEAD detached at d78927dd8d0 nothing to commit, working tree clean tput: No value for $TERM and no -T specified tput: No value for $TERM and no -T specified Makefile:31: run command via tools/syz-env for best compatibility, see: Makefile:32: https://github.com/google/syzkaller/blob/master/docs/contributing.md#using-syz-env go list -f '{{.Stale}}' -ldflags="-s -w -X github.com/google/syzkaller/prog.GitRevision=d78927dd8d06cbe4d0dadb84bb5f977462dde1fd -X github.com/google/syzkaller/prog.gitRevisionDate=20260202-183658" ./sys/syz-sysgen | grep -q false || go install -ldflags="-s -w -X github.com/google/syzkaller/prog.GitRevision=d78927dd8d06cbe4d0dadb84bb5f977462dde1fd -X github.com/google/syzkaller/prog.gitRevisionDate=20260202-183658" ./sys/syz-sysgen make .descriptions tput: No value for $TERM and no -T specified tput: No value for $TERM and no -T specified Makefile:31: run command via tools/syz-env for best compatibility, see: Makefile:32: https://github.com/google/syzkaller/blob/master/docs/contributing.md#using-syz-env bin/syz-sysgen touch .descriptions GOOS=linux GOARCH=amd64 go build -ldflags="-s -w -X github.com/google/syzkaller/prog.GitRevision=d78927dd8d06cbe4d0dadb84bb5f977462dde1fd -X github.com/google/syzkaller/prog.gitRevisionDate=20260202-183658" -o ./bin/linux_amd64/syz-execprog github.com/google/syzkaller/tools/syz-execprog mkdir -p ./bin/linux_amd64 g++ -o ./bin/linux_amd64/syz-executor executor/executor.cc \ -m64 -O2 -pthread -Wall -Werror -Wparentheses -Wunused-const-variable -Wframe-larger-than=16384 -Wno-stringop-overflow -Wno-array-bounds -Wno-format-overflow -Wno-unused-but-set-variable -Wno-unused-command-line-argument -static-pie -std=c++17 -I. -Iexecutor/_include -DGOOS_linux=1 -DGOARCH_amd64=1 \ -DHOSTGOOS_linux=1 -DGIT_REVISION=\"d78927dd8d06cbe4d0dadb84bb5f977462dde1fd\" /usr/bin/ld: /tmp/cczxGgwu.o: in function `Connection::Connect(char const*, char const*)': executor.cc:(.text._ZN10Connection7ConnectEPKcS1_[_ZN10Connection7ConnectEPKcS1_]+0x386): warning: Using 'gethostbyname' in statically linked applications requires at runtime the shared libraries from the glibc version used for linking ./tools/check-syzos.sh 2>/dev/null Tested on: commit: be762d8b Merge tag 'hwmon-for-v7.0-rc6' of git://git.k.. git tree: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git master kernel config: https://syzkaller.appspot.com/x/.config?x=55412ce8dfa1f1a3 dashboard link: https://syzkaller.appspot.com/bug?extid=fc026e87558558f75c00 compiler: Debian clang version 21.1.8 (++20251221033036+2078da43e25a-1~exp1~20251221153213.50), Debian LLD 21.1.8 patch: https://syzkaller.appspot.com/x/patch.diff?x=14b6b0d2580000 ^ permalink raw reply [flat|nested] 13+ messages in thread
end of thread, other threads:[~2026-03-28 16:27 UTC | newest]
Thread overview: 13+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-02-04 0:52 [syzbot] [f2fs?] kernel BUG in clear_inode (5) syzbot
2026-02-05 11:55 ` Forwarded: #syz test https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git f14faaf3a1fb3b9e4cf2e56269711fb85fba9458 syzbot
2026-02-24 14:44 ` Forwarded: Re: [syzbot] [f2fs?] kernel BUG in clear_inode (5) syzbot
2026-02-24 14:52 ` syzbot
2026-03-28 15:41 ` Forwarded: Re: [syzbot] [f2fs?] kernel BUG in clear_inode syzbot
2026-03-28 15:47 ` syzbot
2026-03-28 16:17 ` syzbot
[not found] <6fa4f99a17c207019e992e70c734c88179c84ecc.camel@yandex.ru>
2026-02-05 13:02 ` [syzbot] [f2fs?] kernel BUG in clear_inode (5) syzbot
[not found] <20260224144431.447204-1-kth5965@gmail.com>
2026-02-24 14:47 ` syzbot
[not found] <20260224145250.447332-1-kth5965@gmail.com>
2026-02-24 15:22 ` syzbot
[not found] <69c7f6ba.170a0220.29cadc.a075@mx.google.com>
2026-03-28 15:51 ` syzbot
[not found] <69c7f817.170a0220.33e07b.a1a3@mx.google.com>
2026-03-28 16:01 ` syzbot
[not found] <69c7fefd.170a0220.361dc1.c714@mx.google.com>
2026-03-28 16:27 ` syzbot
This is a public inbox, see mirroring instructions for how to clone and mirror all data and code used for this inbox
Powered by JetHome