[Bug 297976] Panic in the kern_symlinkat()->ffs_truncate()->flush_newblk_dep(): flush_newblk_dep: Bad newblk
Date: Sun, 04 Oct 2026 19:27:33 UTC
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=297976
--- Comment #6 from commit-hook@FreeBSD.org ---
A commit in branch main references this bug:
URL:
https://cgit.FreeBSD.org/src/commit/?id=a127039dd0c24bc18b3513322d22fd8fee6724eb
commit a127039dd0c24bc18b3513322d22fd8fee6724eb
Author: Maxim Sobolev <sobomax@FreeBSD.org>
AuthorDate: 2026-10-04 19:24:16 +0000
Commit: Maxim Sobolev <sobomax@FreeBSD.org>
CommitDate: 2026-10-04 19:26:41 +0000
stress2: add a reproducer for the flush_newblk_dep() "Bad newblk" panic
flush_pagedep_deps() drops the soft updates lock to obtain the vnode of
a new directory. If its MKDIR_BODY dependency completes in that window,
the lookup of the directory's first block in flush_newblk_dep() can find
a stale allocindir left behind by a previous owner of the same block,
relocated by ffs_reallocblks() and freed, and panic.
The test grows interleaved files past UFS_NDADDR to keep clusters being
relocated, while other workers create subdirectories in a parent with
IN_ENDOFF set, so that ffs_vput_pair() syncs it, and fsync() them to
complete the mkdir dependencies. The file system layout and the way
the writers put their blocks on disk are arranged so that a new
directory takes over a freed block whose dependency is still retained;
the details are in the script. With dtrace=1, the test also counts how
often this precondition is met, which works on a fixed kernel too.
PR: 297976
Reviewed by: kib, pho
Tested by: pho
Sponsored by: Sippy Software, Inc.
Differential revision: https://reviews.freebsd.org/D59356
tools/test/stress2/misc/mkdir_blkreuse.sh (new +x) | 584 +++++++++++++++++++++
1 file changed, 584 insertions(+)
--
You are receiving this mail because:
You are the assignee for the bug.