syzbot has found a reproducer for the following issue on: HEAD commit: ae8373a5add4 Merge tag 'x86_urgent_for_6.4-rc4' of git://g.. git tree: upstream console+strace: https://syzkaller.appspot.com/x/log.txt?x=17b3b489280000 kernel config: https://syzkaller.appspot.com/x/.config?x=f389ffdf4e9ba3f0 dashboard link: https://syzkaller.appspot.com/bug?extid=dafbca0e20fbc5946925 compiler: gcc (Debian 10.2.1-6) 10.2.1 20210110, GNU ld (GNU Binutils for Debian) 2.35.2 syz repro: https://syzkaller.appspot.com/x/repro.syz?x=14243ef9280000 C reproducer: https://syzkaller.appspot.com/x/repro.c?x=16c06772280000 Downloadable assets: disk image: https://storage.googleapis.com/syzbot-assets/2c5ee189dd12/disk-ae8373a5.raw.xz vmlinux: https://storage.googleapis.com/syzbot-assets/63acf75623d7/vmlinux-ae8373a5.xz kernel image: https://storage.googleapis.com/syzbot-assets/29de65c99e9d/bzImage-ae8373a5.xz mounted in repro: https://storage.googleapis.com/syzbot-assets/2eac0114b435/mount_0.gz IMPORTANT: if you fix the issue, please add the following tag to the commit: Reported-by: syzbot+dafbca0e20fbc5946925@xxxxxxxxxxxxxxxxxxxxxxxxx BTRFS warning (device loop0): Skipping commit of aborted transaction. ------------[ cut here ]------------ BTRFS: Transaction aborted (error -28) WARNING: CPU: 0 PID: 41 at fs/btrfs/transaction.c:1978 cleanup_transaction fs/btrfs/transaction.c:1978 [inline] WARNING: CPU: 0 PID: 41 at fs/btrfs/transaction.c:1978 btrfs_commit_transaction+0x3223/0x3fa0 fs/btrfs/transaction.c:2565 Modules linked in: CPU: 0 PID: 41 Comm: kworker/u4:2 Not tainted 6.4.0-rc3-syzkaller-00008-gae8373a5add4 #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 04/28/2023 Workqueue: events_unbound btrfs_async_reclaim_metadata_space RIP: 0010:cleanup_transaction fs/btrfs/transaction.c:1978 [inline] RIP: 0010:btrfs_commit_transaction+0x3223/0x3fa0 fs/btrfs/transaction.c:2565 Code: c8 fe ff ff be 02 00 00 00 e8 f9 41 aa 00 e9 21 d3 ff ff e8 af 68 1b fe 8b b5 20 ff ff ff 48 c7 c7 c0 25 95 8a e8 2d 28 e3 fd <0f> 0b c7 85 00 ff ff ff 01 00 00 00 e9 97 df ff ff e8 87 68 1b fe RSP: 0018:ffffc90000b27990 EFLAGS: 00010282 RAX: 0000000000000000 RBX: 000000001f0d8001 RCX: 0000000000000000 RDX: ffff888014aa0000 RSI: ffffffff814c03e7 RDI: 0000000000000001 RBP: ffffc90000b27b00 R08: 0000000000000001 R09: 0000000000000000 R10: 0000000000000001 R11: 0000000000000001 R12: ffff88801f0d8000 R13: ffff888074df3e98 R14: ffff888074df4000 R15: ffff88801f0d8000 FS: 0000000000000000(0000) GS:ffff8880b9800000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 000055bc77452c28 CR3: 0000000072dfb000 CR4: 0000000000350ef0 Call Trace: <TASK> flush_space+0x1e0/0xde0 fs/btrfs/space-info.c:808 btrfs_async_reclaim_metadata_space+0x39e/0xa90 fs/btrfs/space-info.c:1078 process_one_work+0x99a/0x15e0 kernel/workqueue.c:2405 worker_thread+0x67d/0x10c0 kernel/workqueue.c:2552 kthread+0x344/0x440 kernel/kthread.c:379 ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:308 </TASK> --- If you want syzbot to run the reproducer, reply with: #syz test: git://repo/address.git branch-or-commit-hash If you attach or paste a git patch, syzbot will apply it before testing.