Re: [PATCH] nilfs2: fix BUG in nilfs_copy_dirty_pages() on dirty state mismatch
From: Ryusuke Konishi
Date: Tue Jul 28 2026 - 00:44:03 EST
On Mon, Jul 20, 2026 at 11:17 PM Ryusuke Konishi wrote:
>
> Syzbot reported a kernel BUG triggered within nilfs_copy_dirty_pages(),
> which copies dirty DAT file folios/pages to its shadow page cache. The
> BUG occurs when a retrieved dirty folio/page unexpectedly loses its
> 'dirty' status.
>
> This issue arises because, since the commit referenced below, the 'dirty'
> flag of a folio/page can be cleared asynchronously after the filesystem
> detects metadata corruption and transitions to read-only mode.
>
> Resolve the issue by returning an -EROFS error if the filesystem has
> transitioned to read-only mode. Also change the behavior to issue a
> kernel warning only once instead of triggering a kernel BUG when this
> unexpected 'dirty' state is detected while the filesystem is not in
> read-only mode.
>
> Reported-by: syzbot+8baf9a79a3ffc6271cb6@xxxxxxxxxxxxxxxxxxxxxxxxx
> Closes: https://syzkaller.appspot.com/bug?extid=8baf9a79a3ffc6271cb6
> Fixes: 8c26c4e2694a ("nilfs2: fix issue with flush kernel thread after remount in RO mode because of driver's internal error or metadata corruption")
> Signed-off-by: Ryusuke Konishi <konishi.ryusuke@xxxxxxxxx>
> ---
> Viacheslav, please apply this for the next cycle.
>
> This fixes an issue reported by syzbot where a kernel BUG could be
> triggered depending on timing after filesystem corruption is detected.
>
> Thanks,
> Ryusuke Konishi
>
> fs/nilfs2/page.c | 17 +++++++++++++++--
> 1 file changed, 15 insertions(+), 2 deletions(-)
>
> diff --git a/fs/nilfs2/page.c b/fs/nilfs2/page.c
> index a9d8aa65416f..1d00bce21c37 100644
> --- a/fs/nilfs2/page.c
> +++ b/fs/nilfs2/page.c
> @@ -243,6 +243,7 @@ static void nilfs_copy_folio(struct folio *dst, struct folio *src,
> int nilfs_copy_dirty_pages(struct address_space *dmap,
> struct address_space *smap)
> {
> + struct inode *smap_inode = smap->host;
> struct folio_batch fbatch;
> unsigned int i;
> pgoff_t index = 0;
> @@ -258,8 +259,19 @@ int nilfs_copy_dirty_pages(struct address_space *dmap,
> struct folio *folio = fbatch.folios[i], *dfolio;
>
> folio_lock(folio);
> - if (unlikely(!folio_test_dirty(folio)))
> - NILFS_FOLIO_BUG(folio, "inconsistent dirty state");
> + if (unlikely(!folio_test_dirty(folio))) {
> + if (WARN_ONCE(!sb_rdonly(smap_inode->i_sb),
> + "inconsistent dirty state\n"))
> + goto unlock_folio;
> +
> + /*
> + * If the filesystem has been forced to read-only
> + * due to metadata corruption.
> + */
> + folio_unlock(folio);
> + err = -EROFS;
> + break;
> + }
>
> dfolio = filemap_grab_folio(dmap, folio->index);
> if (IS_ERR(dfolio)) {
> @@ -277,6 +289,7 @@ int nilfs_copy_dirty_pages(struct address_space *dmap,
>
> folio_unlock(dfolio);
> folio_put(dfolio);
> +unlock_folio:
> folio_unlock(folio);
> }
> folio_batch_release(&fbatch);
> --
> 2.43.0
>
Hi Viacheslav,
Sorry for the disturbance while you are busy.
Could you please pick up the following four pending patches -
including this one - for the next cycle at your convenience?
Excluding those already applied, these are the ones submitted by me or
requested for direct pick-up since the weekend before last:
- [PATCH] nilfs2: fix slab-out-of-bounds in nilfs_direct_propagate
after truncation
- [PATCH v2] nilfs2: fix infinite loop in nilfs_clean_segments()
- [PATCH] nilfs2: prevent out-of-bounds read in super root block parsing
- [PATCH] nilfs2: fix BUG in nilfs_copy_dirty_pages() on dirty state mismatch
Thanks,
Ryusuke Konishi