[BUG] ocfs2: assertion failure in _ocfs2_free_suballoc_bits on a crafted image
From: CJ
Date: Tue Sep 22 2026 - 01:56:14 EST
Hi,
I am reporting an issue triggered by a syzkaller reproducer on Linux
7.3.0-rc2. The issue is reproducible with HEAD commit
df2908090cda368b01ff43709f51890076c56157.
The reproducer mounts a crafted ocfs2 image with commit= options and then
removes a directory, which makes ocfs2 evict the inode and release its
suballocator bits.
While freeing the bits, _ocfs2_free_suballoc_bits() reads the group
descriptor for the target group and checks that the range it is about to
clear fits within the group's declared bit count. The check fails and
BUG_ON() terminates the kernel. The call path is ocfs2_evict_inode() ->
ocfs2_wipe_inode() -> ocfs2_remove_inode() -> ocfs2_free_dinode() ->
_ocfs2_free_suballoc_bits(), reached from vfs_rmdir() in the unlinkat
syscall context.
This looks like the on-disk group descriptor and the suballocator chain
disagreeing about the size of the group, so the release range computed from
the chain falls outside it. Since the image is untrusted input, reporting
the inconsistency as a filesystem error instead of an assertion would keep
the kernel alive. I have not determined which of the two metadata sources
carries the inconsistent value.
This failure was reported earlier against the linux-6.1 longterm series at
https://syzkaller.appspot.com/bug?extid=3b664d98a77a329be77e, and the
reproducer below is the one from that report. It still reproduces on the
tested mainline kernel.
Reproducer:
syz reproducer: https://pastebin.com/raw/9vVANXgZ
console output: https://pastebin.com/raw/AZMvqBm0
kernel config: https://syzkaller.appspot.com/text?tag=KernelConfig&x=6a5cbd268406bf43
Kernel:
HEAD commit: df2908090cda368b01ff43709f51890076c56157
git tree: mainline
kernel version: 7.3.0-rc2
tested tag: v7.3-rc2 (annotated tag object 5e036ce12de91c6fd674dad33b169c6150be2a7a)
Let me know if you need more details or testing.
Best regards,
Changjian Liu