The patch below does not apply to the 4.19-stable tree. If someone wants it applied there, or to any other stable or longterm tree, then please email the backport, including the original git commit id to <stable@xxxxxxxxxxxxxxx>. Possible dependencies: cbddcc4fa344 ("btrfs: set generation before calling btrfs_clean_tree_block in btrfs_init_new_buffer") b40130b23ca4 ("btrfs: fix lockdep splat with reloc root extent buffers") 0a27a0474d14 ("btrfs: move lockdep class helpers to locking.c") b4be6aefa73c ("btrfs: do not start relocation until in progress drops are done") fdfbf020664b ("btrfs: rework async transaction committing") 54230013d41f ("btrfs: get rid of root->orphan_cleanup_state") ae5d29d4e70a ("btrfs: inline wait_current_trans_commit_start in its caller") 32cc4f8759e1 ("btrfs: sink wait_for_unblock parameter to async commit") e9306ad4ef5c ("btrfs: more graceful errors/warnings on 32bit systems when reaching limits") bc03f39ec3c1 ("btrfs: use a bit to track the existence of tree mod log users") 406808ab2f0b ("btrfs: use booleans where appropriate for the tree mod log functions") f3a84ccd28d0 ("btrfs: move the tree mod log code into its own file") dbcc7d57bffc ("btrfs: fix race when cloning extent buffer during rewind of an old root") cac06d843f25 ("btrfs: introduce the skeleton of btrfs_subpage structure") 2f96e40212d4 ("btrfs: fix possible free space tree corruption with online conversion") 1aaac38c83a2 ("btrfs: don't allow tree block to cross page boundary for subpage support") 948462294577 ("btrfs: keep sb cache_generation consistent with space_cache") 8b228324a8ce ("btrfs: clear free space tree on ro->rw remount") 8cd2908846d1 ("btrfs: clear oneshot options on mount and remount") 5011139a4718 ("btrfs: create free space tree on ro->rw remount") thanks, greg k-h ------------------ original commit in Linus's tree ------------------ >From cbddcc4fa3443fe8cfb2ff8e210deb1f6a0eea38 Mon Sep 17 00:00:00 2001 From: Tetsuo Handa <penguin-kernel@xxxxxxxxxxxxxxxxxxx> Date: Tue, 20 Sep 2022 22:43:51 +0900 Subject: [PATCH] btrfs: set generation before calling btrfs_clean_tree_block in btrfs_init_new_buffer syzbot is reporting uninit-value in btrfs_clean_tree_block() [1], for commit bc877d285ca3dba2 ("btrfs: Deduplicate extent_buffer init code") missed that btrfs_set_header_generation() in btrfs_init_new_buffer() must not be moved to after clean_tree_block() because clean_tree_block() is calling btrfs_header_generation() since commit 55c69072d6bd5be1 ("Btrfs: Fix extent_buffer usage when nodesize != leafsize"). Since memzero_extent_buffer() will reset "struct btrfs_header" part, we can't move btrfs_set_header_generation() to before memzero_extent_buffer(). Just re-add btrfs_set_header_generation() before btrfs_clean_tree_block(). Link: https://syzkaller.appspot.com/bug?extid=fba8e2116a12609b6c59 [1] Reported-by: syzbot <syzbot+fba8e2116a12609b6c59@xxxxxxxxxxxxxxxxxxxxxxxxx> Fixes: bc877d285ca3dba2 ("btrfs: Deduplicate extent_buffer init code") CC: stable@xxxxxxxxxxxxxxx # 4.19+ Signed-off-by: Tetsuo Handa <penguin-kernel@xxxxxxxxxxxxxxxxxxx> Signed-off-by: David Sterba <dsterba@xxxxxxxx> diff --git a/fs/btrfs/extent-tree.c b/fs/btrfs/extent-tree.c index ae94be318a0f..cd2d36580f1a 100644 --- a/fs/btrfs/extent-tree.c +++ b/fs/btrfs/extent-tree.c @@ -4890,6 +4890,9 @@ btrfs_init_new_buffer(struct btrfs_trans_handle *trans, struct btrfs_root *root, !test_bit(BTRFS_ROOT_RESET_LOCKDEP_CLASS, &root->state)) lockdep_owner = BTRFS_FS_TREE_OBJECTID; + /* btrfs_clean_tree_block() accesses generation field. */ + btrfs_set_header_generation(buf, trans->transid); + /* * This needs to stay, because we could allocate a freed block from an * old tree into a new tree, so we need to make sure this new block is