LKML Archive on
 help / color / Atom feed
From: Hao Sun <>
Subject: KCSAN: data-race in __jbd2_journal_file_buffer / jbd2_journal_dirty_metadata
Date: Sun, 4 Apr 2021 17:40:44 +0800
Message-ID: <> (raw)

[-- Attachment #1: Type: text/plain, Size: 1171 bytes --]


When using Healer( to fuzz
the Linux kernel, I found a data-race vulnerability in
__jbd2_journal_file_buffer / jbd2_journal_dirty_metadata.
Sorry, data-race is usually difficult to reproduce. I cannot provide
you with a reproducing program.
I hope that the call stack information in the crash log can help you
locate the problem.
Kernel config and full log can be found in the attachment.

Here is the detailed information:
commit:   3b9cdafb5358eb9f3790de2f728f765fef100731
version:   linux 5.11
git tree:    upstream
BUG: KCSAN: data-race in __jbd2_journal_file_buffer /
write to 0xffff88800af6da38 of 8 bytes by task 4822 on cpu 1:
 __jbd2_journal_file_buffer+0x18d/0x370 linux/fs/jbd2/transaction.c:2518
 __jbd2_journal_refile_buffer+0x155/0x230 linux/fs/jbd2/transaction.c:2612
 jbd2_journal_commit_transaction+0x24c6/0x3200 linux/fs/jbd2/commit.c:1084
 kjournald2+0x253/0x470 linux/fs/jbd2/journal.c:213
 kthread+0x1f0/0x220 linux/kernel/kthread.c:292
 ret_from_fork+0x1f/0x30 linux/arch/x86/entry/entry_64.S:294

[-- Attachment #2: log0 --]
[-- Type: application/octet-stream, Size: 5804 bytes --]

[-- Attachment #3: config --]
[-- Type: application/octet-stream, Size: 220871 bytes --]

             reply index

Thread overview: 7+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2021-04-04  9:40 Hao Sun [this message]
2021-04-06 12:32 ` Jan Kara
2021-04-06 13:27   ` Hao Sun
2021-04-06 14:05     ` Jan Kara
2021-04-06 15:01   ` Theodore Ts'o
2021-04-06 16:12     ` Jan Kara
2021-04-12 18:20     ` Marco Elver

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \ \ \ \ \ \ \

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link

LKML Archive on

Archives are clonable:
	git clone --mirror lkml/git/0.git
	git clone --mirror lkml/git/1.git
	git clone --mirror lkml/git/2.git
	git clone --mirror lkml/git/3.git
	git clone --mirror lkml/git/4.git
	git clone --mirror lkml/git/5.git
	git clone --mirror lkml/git/6.git
	git clone --mirror lkml/git/7.git
	git clone --mirror lkml/git/8.git
	git clone --mirror lkml/git/9.git
	git clone --mirror lkml/git/10.git

	# If you have public-inbox 1.1+ installed, you may
	# initialize and index your mirror using the following commands:
	public-inbox-init -V2 lkml lkml/ \
	public-inbox-index lkml

Example config snippet for mirrors

Newsgroup available over NNTP:

AGPL code for this site: git clone