https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=297976

--- Comment #6 from [email protected] ---
A commit in branch main references this bug:

URL:
https://cgit.FreeBSD.org/src/commit/?id=a127039dd0c24bc18b3513322d22fd8fee6724eb

commit a127039dd0c24bc18b3513322d22fd8fee6724eb
Author:     Maxim Sobolev <[email protected]>
AuthorDate: 2026-10-04 19:24:16 +0000
Commit:     Maxim Sobolev <[email protected]>
CommitDate: 2026-10-04 19:26:41 +0000

    stress2: add a reproducer for the flush_newblk_dep() "Bad newblk" panic

    flush_pagedep_deps() drops the soft updates lock to obtain the vnode of
    a new directory.  If its MKDIR_BODY dependency completes in that window,
    the lookup of the directory's first block in flush_newblk_dep() can find
    a stale allocindir left behind by a previous owner of the same block,
    relocated by ffs_reallocblks() and freed, and panic.

    The test grows interleaved files past UFS_NDADDR to keep clusters being
    relocated, while other workers create subdirectories in a parent with
    IN_ENDOFF set, so that ffs_vput_pair() syncs it, and fsync() them to
    complete the mkdir dependencies.  The file system layout and the way
    the writers put their blocks on disk are arranged so that a new
    directory takes over a freed block whose dependency is still retained;
    the details are in the script.  With dtrace=1, the test also counts how
    often this precondition is met, which works on a fixed kernel too.

    PR:             297976
    Reviewed by:    kib, pho
    Tested by:      pho
    Sponsored by:   Sippy Software, Inc.
    Differential revision:  https://reviews.freebsd.org/D59356

 tools/test/stress2/misc/mkdir_blkreuse.sh (new +x) | 584 +++++++++++++++++++++
 1 file changed, 584 insertions(+)

-- 
You are receiving this mail because:
You are the assignee for the bug.

Reply via email to