[syzbot] kernel BUG in txUnlock

From: syzbot
Date: Sat Oct 01 2022 - 10:27:59 EST


syzbot found the following issue on:

HEAD commit: 5911b92626df Merge branch 'for-next/core' into for-kernelci
git tree: git://git.kernel.org/pub/scm/linux/kernel/git/arm64/linux.git for-kernelci
console output: https://syzkaller.appspot.com/x/log.txt?x=161da2ec880000
kernel config: https://syzkaller.appspot.com/x/.config?x=aae2d21e7dd80684
dashboard link: https://syzkaller.appspot.com/bug?extid=a63afa301d1258d09267
compiler: Debian clang version 13.0.1-++20220126092033+75e33f71c2da-1~exp1~20220126212112.63, GNU ld (GNU Binutils for Debian) 2.35.2
userspace arch: arm64

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/c50e57f66737/disk-5911b926.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/f369b7b837e3/vmlinux-5911b926.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+a63afa301d1258d09267@xxxxxxxxxxxxxxxxxxxxxxxxx

BUG at fs/jfs/jfs_txnmgr.c:926 assert(mp->nohomeok > 0)
------------[ cut here ]------------
kernel BUG at fs/jfs/jfs_txnmgr.c:926!
Internal error: Oops - BUG: 00000000f2000800 [#1] PREEMPT SMP
Modules linked in:
CPU: 1 PID: 88 Comm: jfsCommit Not tainted 6.0.0-rc7-syzkaller-18098-g5911b92626df #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 08/26/2022
pstate: 60400005 (nZCv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)
pc : txUnlock+0x6f4/0x738 fs/jfs/jfs_txnmgr.c:926
lr : txUnlock+0x6f4/0x738 fs/jfs/jfs_txnmgr.c:926
sp : ffff80000fb33d30
x29: ffff80000fb33d70 x28: ffff800012222000 x27: 0000000000000008
x26: ffff80000ef36fd0 x25: ffff80000ef37000 x24: ffff0000c289aac8
x23: ffff80000ef37000 x22: 0000000000000048 x21: ffff80000ef36f7c
x20: ffff80000ef36000 x19: 0000000000000000 x18: 0000000000000340
x17: 0000000000000000 x16: ffff80000db49158 x15: ffff0000c104cf80
x14: 0000000000000000 x13: 00000000ffffffff x12: ffff0000c104cf80
x11: ff808000081c0d5c x10: 0000000000000000 x9 : da27545727afe500
x8 : da27545727afe500 x7 : ffff800008161d1c x6 : 0000000000000000
x5 : 0000000000000080 x4 : 0000000000000001 x3 : 0000000000000000
x2 : ffff0001fefddcd0 x1 : 0000000100000000 x0 : 0000000000000037
Call trace:
txUnlock+0x6f4/0x738 fs/jfs/jfs_txnmgr.c:926
txLazyCommit fs/jfs/jfs_txnmgr.c:2677 [inline]
jfs_lazycommit+0x228/0x4c8 fs/jfs/jfs_txnmgr.c:2727
kthread+0x12c/0x158 kernel/kthread.c:376
ret_from_fork+0x10/0x20 arch/arm64/kernel/entry.S:860
Code: 9114d021 912fec63 528073c2 94c92d60 (d4210000)
---[ end trace 0000000000000000 ]---

