nilfs2: fix BUG in nilfs_copy_dirty_pages() on dirty state mismatch

Syzbot reported a kernel BUG triggered within nilfs_copy_dirty_pages(),
which copies dirty DAT file folios/pages to its shadow page cache.  The
BUG occurs when a retrieved dirty folio/page unexpectedly loses its
'dirty' status.

This issue arises because, since the commit referenced below, the 'dirty'
flag of a folio/page can be cleared asynchronously after the filesystem
detects metadata corruption and transitions to read-only mode.

Resolve the issue by returning an -EROFS error if the filesystem has
transitioned to read-only mode.  Also change the behavior to issue a
kernel warning only once instead of triggering a kernel BUG when this
unexpected 'dirty' state is detected while the filesystem is not in
read-only mode.

Reported-by: syzbot+8baf9a79a3ffc6271cb6@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=8baf9a79a3ffc6271cb6
Fixes: 8c26c4e269 ("nilfs2: fix issue with flush kernel thread after remount in RO mode because of driver's internal error or metadata corruption")
Signed-off-by: Ryusuke Konishi <konishi.ryusuke@gmail.com>
Signed-off-by: Viacheslav Dubeyko <slava@dubeyko.com>
This commit is contained in:
Ryusuke Konishi 2026-07-20 23:16:52 +09:00 committed by Viacheslav Dubeyko
parent 7cb2f76a6a
commit 66f4ad3ce1

View File

@ -243,6 +243,7 @@ static void nilfs_copy_folio(struct folio *dst, struct folio *src,
int nilfs_copy_dirty_pages(struct address_space *dmap,
struct address_space *smap)
{
struct inode *smap_inode = smap->host;
struct folio_batch fbatch;
unsigned int i;
pgoff_t index = 0;
@ -258,8 +259,19 @@ int nilfs_copy_dirty_pages(struct address_space *dmap,
struct folio *folio = fbatch.folios[i], *dfolio;
folio_lock(folio);
if (unlikely(!folio_test_dirty(folio)))
NILFS_FOLIO_BUG(folio, "inconsistent dirty state");
if (unlikely(!folio_test_dirty(folio))) {
if (WARN_ONCE(!sb_rdonly(smap_inode->i_sb),
"inconsistent dirty state\n"))
goto unlock_folio;
/*
* If the filesystem has been forced to read-only
* due to metadata corruption.
*/
folio_unlock(folio);
err = -EROFS;
break;
}
dfolio = filemap_grab_folio(dmap, folio->index);
if (IS_ERR(dfolio)) {
@ -277,6 +289,7 @@ int nilfs_copy_dirty_pages(struct address_space *dmap,
folio_unlock(dfolio);
folio_put(dfolio);
unlock_folio:
folio_unlock(folio);
}
folio_batch_release(&fbatch);