From nobody Fri Jul 24 05:21:21 2026 Received: from mail-oa1-f70.google.com (mail-oa1-f70.google.com [209.85.160.70]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 9950A3019A9 for ; Thu, 23 Jul 2026 02:57:33 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.160.70 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784775455; cv=none; b=RJHhsEp8yku0JuGNUICasJBwLxEVHDV7g6bgkvQ1skrH8gl74USjqX/bo8IhAJLRccZftS2WTVF9s5r4eaMJmhXA3Kjh0gnljmAwNdu+hsrY37CjlNVRdvqcXCvK+vtHERRdSo9cCGXNn+NLq1gWQ4LdZNVdsRFiAVJq/NKkZP0= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784775455; c=relaxed/simple; bh=AdhUhwxNab2j4Ys9yuCjeW8yIsSn4oAVkhB3vdn4P3k=; h=MIME-Version:Date:In-Reply-To:Message-ID:Subject:From:To: Content-Type; b=UwyNK4oySRfCPgc8SZag/KwVL11enL9u2eV6Q8FkWy+sdubgGFCuWw1ZFxIrUZFCD64DAaEo+pO7quwwsmX4BhmhXS/S2rdbwKe419aXxHryq6uloxp5J8Mod0TYHkWQAV9wDcsNfUbhTDsxjJDimzw8QbqHpCijg/21Zm3qOQw= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=syzkaller.appspotmail.com; spf=pass smtp.mailfrom=M3KW2WVRGUFZ5GODRSRYTGD7.apphosting.bounces.google.com; arc=none smtp.client-ip=209.85.160.70 Authentication-Results: smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=syzkaller.appspotmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=M3KW2WVRGUFZ5GODRSRYTGD7.apphosting.bounces.google.com Received: by mail-oa1-f70.google.com with SMTP id 586e51a60fabf-44899f99756so160962fac.2 for ; Wed, 22 Jul 2026 19:57:33 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784775452; x=1785380252; h=content-type:to:from:subject:message-id:in-reply-to:date :mime-version:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to:content-type; bh=R+EPCmUO+5/WdrpDT4n0dij/8ZqLJyVU3jz1NpDNVbg=; b=piS4pQmHRArDfN+C7yzmrR1UxED5pvIXqtDZ4wfn9B3CeTebHBcvwP3Nm9EbMJKNsH m/MQcdTD0wSncgGyEz1nopnxZhHCOvgU+JpVmaw6tWGT224S+SM3zTyCFsVD0BQalGV3 Hx/J2Wq+wSYSUCqhXWWwsUGe6BTPN/O23BuYcpUqgk153UB/0NesxFptXfxWMIffprhK BiHtCuUcEu91w8sk86XA6P8ZXKFo0MuklZ2bvsaAioG6tqn8gUG0ugbT7OEvYX+ZO5YR RA07+3/HvV9PX6DOYCEVcX87g1ecsEJtnJdixhmGDmf9zOWUOIaO5pVRb1O4R1I8319O FSNQ== X-Gm-Message-State: AOJu0YxpNM9TuHkgv0tv1qP6/n7MafYjDrIBdPtaCXX6Xu89eViZibNG aDFTIcENK2XGfiU9U3H0hZfyJfTy4lJtrbHKNzTf2Q5Hrq8ZjvtYBoUrDoFtpeFM3D2IJypMDCq g4EJDf/LsFE90wBdHO8BT5DQGslX9/k7J39AYjwXlMhhoAYL7PDl1oCjQNxM= Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Received: by 2002:a05:6820:1c9c:b0:6a1:1c1:dc84 with SMTP id 006d021491bc7-6aad3f90e0cmr544333eaf.5.1784775452541; Wed, 22 Jul 2026 19:57:32 -0700 (PDT) Date: Wed, 22 Jul 2026 19:57:32 -0700 In-Reply-To: <69c19ef0.050a0220.3bf4de.00a9.GAE@google.com> X-Google-Appengine-App-Id: s~syzkaller X-Google-Appengine-App-Id-Alias: syzkaller Message-ID: <6a61831c.16bfb6d0.3c48cb.0008.GAE@google.com> Subject: Forwarded: [PATCH] gfs2: don't add further folios to a chained bio From: syzbot To: linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" For archival purposes, forwarding an incoming command email to linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com. *** Subject: [PATCH] gfs2: don't add further folios to a chained bio Author: kmehltretter@gmail.com #syz test: git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git= master diff --git a/fs/gfs2/lops.c b/fs/gfs2/lops.c index 6dabe73ad790..a00787df2507 100644 --- a/fs/gfs2/lops.c +++ b/fs/gfs2/lops.c @@ -514,6 +514,7 @@ int gfs2_find_jhead(struct gfs2_jdesc *jd, struct gfs2_= log_header_host *head) int ret =3D 0; struct bio *bio =3D NULL; struct folio *folio =3D NULL; + bool bio_chained =3D false; bool done =3D false; errseq_t since; =20 @@ -537,7 +538,8 @@ int gfs2_find_jhead(struct gfs2_jdesc *jd, struct gfs2_= log_header_host *head) off =3D 0; } =20 - if (bio && (off || block < blocks_submitted + max_blocks)) { + if (bio && (off || (!bio_chained && + block < blocks_submitted + max_blocks))) { sector_t sector =3D dblock << sdp->sd_fsb2bb_shift; =20 if (bio_end_sector(bio) =3D=3D sector) { @@ -550,6 +552,7 @@ int gfs2_find_jhead(struct gfs2_jdesc *jd, struct gfs2_= log_header_host *head) =20 bio =3D gfs2_chain_bio(bio, blocks, sector, REQ_OP_READ); + bio_chained =3D true; goto add_block_to_new_bio; } } @@ -561,6 +564,7 @@ int gfs2_find_jhead(struct gfs2_jdesc *jd, struct gfs2_= log_header_host *head) =20 bio =3D gfs2_log_alloc_bio(sdp, dblock, gfs2_end_log_read, REQ_OP_READ); + bio_chained =3D false; add_block_to_new_bio: bio_add_folio_nofail(bio, folio, bsize, off); block_added: