Re: [syzbot] [btrfs?] KASAN: slab-use-after-free Read in btrfs_qgroup_account_extent

From: Filipe Manana
Date: Sun Nov 05 2023 - 11:01:23 EST


On Sun, Nov 5, 2023 at 8:40 AM syzbot
<syzbot+e0b615318f8fcfc01ceb@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote:
>
> syzbot has bisected this issue to:
>
> commit dce28769a33a95425b007f00842d6e12ffa28f83
> Author: Qu Wenruo <wqu@xxxxxxxx>
> Date: Sat Sep 2 00:13:57 2023 +0000
>
> btrfs: qgroup: use qgroup_iterator_nested to in qgroup_update_refcnt()
>
> bisection log: https://syzkaller.appspot.com/x/bisect.txt?x=14f01717680000
> start commit: 90b0c2b2edd1 Merge tag 'pinctrl-v6.7-1' of git://git.kerne..
> git tree: upstream
> final oops: https://syzkaller.appspot.com/x/report.txt?x=16f01717680000
> console output: https://syzkaller.appspot.com/x/log.txt?x=12f01717680000
> kernel config: https://syzkaller.appspot.com/x/.config?x=4cc8c922092464e7
> dashboard link: https://syzkaller.appspot.com/bug?extid=e0b615318f8fcfc01ceb
> syz repro: https://syzkaller.appspot.com/x/repro.syz?x=14cae708e80000
> C reproducer: https://syzkaller.appspot.com/x/repro.c?x=1354647b680000
>
> Reported-by: syzbot+e0b615318f8fcfc01ceb@xxxxxxxxxxxxxxxxxxxxxxxxx
> Fixes: dce28769a33a ("btrfs: qgroup: use qgroup_iterator_nested to in qgroup_update_refcnt()")

#syz fix: btrfs: fix race between accounting qgroup extents and
removing a qgroup

>
> For information about bisection process see: https://goo.gl/tpsmEJ#bisection