Skip to content

[bisected] File operations on a zstd:1 compressed rootfs cause BUG: unable to handle page fault for address: fffbc000 (kernel v7.2-rc3, x86_32) #1146

Description

@ernsteiswuerfel

Getting this on my Thinkpad T60 (Intel Core Duo T2400, i686) at kernel v7.2-rc3:

BUG: unable to handle page fault for address: fffbc000
#PF: supervisor read access in kernel mode
#PF: error_code(0x0000) - not-present page
*pdpt = 000000001d9dc001 *pde = 000000001d9de063 *pte = 0000000000000000 
Oops: Oops: 0000 [#1] SMP PTI
CPU: 0 UID: 0 PID: 61 Comm: kworker/u8:5 Tainted: G                 N  7.2.0-rc3-P3 #2 PREEMPTLAZY 
Tainted: [N]=TEST
Hardware name: LENOVO 2007F2G/2007F2G, BIOS 79ETE7WW (2.27 ) 03/21/2011
Workqueue: btrfs-delalloc btrfs_work_helper
EIP: ZSTD_compressStream2+0x221/0x5fc
Code: 8b 83 58 09 00 00 8b 93 5c 09 00 00 8b 4d e4 2b 4d f0 29 c2 39 ca 0f 47 d1 85 d2 74 0f 03 83 4c 09 00 00 89 d1 8b 75 f0 89 c7 <f3> a4 8b 83 58 09 00 00 31 c9 01 d0 83 7d f0 00 89 83 58 09 00 00
EAX: c28457e0 EBX: c2800000 ECX: 0001f000 EDX: 00020000
ESI: fffbc000 EDI: c28467e0 EBP: c1b73da0 ESP: c1b73d68
DS: 007b ES: 007b FS: 00d8 GS: 0000 SS: 0068 EFLAGS: 00010282
CR0: 80050033 CR2: fffbc000 CR3: 1d9e0000 CR4: 000006f0
Call Trace:
 ZSTD_compressStream+0xd/0x48
 zstd_compress_stream+0x8/0x10
 zstd_compress_bio+0x20a/0x564
 ? alloc_tagging_slab_alloc_hook+0x19/0x28
 btrfs_compress_bio+0x94/0xc0
 ? btrfs_compress_bio+0x5a/0xc0
 ? btrfs_compress_bio+0x94/0xc0
 compress_file_range+0x20a/0x380
 ? __switch_to_asm+0x6b/0xf0
 btrfs_work_helper+0xc1/0x1b4
 ? submit_uncompressed_range+0x18c/0x18c
 process_scheduled_works+0x15f/0x204
 worker_thread+0x10c/0x178
 kthread+0xe1/0xe8
 ? process_scheduled_works+0x204/0x204
 ? kthread_affine_node+0x80/0x80
 ret_from_fork+0x1d/0x14c
 ? kthread_affine_node+0x80/0x80
 ret_from_fork_asm+0x12/0x18
 entry_INT80_32+0xf0/0xf0
Modules linked in: cifs libsha512 dns_resolver nls_ucs2_utils cifs_md4 libmd5 ctr cbc aes ecb algif_skcipher af_alg iwl3945 iwlegacy af_packet mac80211 radeon drm_suballoc_helper thinkpad_acpi snd_hda_intel i2c_algo_bit cfg80211 snd_intel_dspcfg nvram snd_hda_codec drm_ttm_helper libaes sparse_keymap ttm snd_hwdep drm_exec platform_profile rfkill acpi_cpufreq snd_hda_core video drm_display_helper libarc4 cec snd_pcm battery wmi input_leds backlight thermal snd_timer led_class uhci_hcd snd ac soundcore ehci_pci ehci_hcd usbcore evdev processor joydev button usb_common pkcs8_key_parser coretemp hwmon fuse configfs
CR2: 00000000fffbc000
---[ end trace 0000000000000000 ]---
EIP: ZSTD_compressStream2+0x221/0x5fc
Code: 8b 83 58 09 00 00 8b 93 5c 09 00 00 8b 4d e4 2b 4d f0 29 c2 39 ca 0f 47 d1 85 d2 74 0f 03 83 4c 09 00 00 89 d1 8b 75 f0 89 c7 <f3> a4 8b 83 58 09 00 00 31 c9 01 d0 83 7d f0 00 89 83 58 09 00 00
EAX: c28457e0 EBX: c2800000 ECX: 0001f000 EDX: 00020000
ESI: fffbc000 EDI: c28467e0 EBP: c1b73da0 ESP: c1b73d68
DS: 007b ES: 007b FS: 00d8 GS: 0000 SS: 0068 EFLAGS: 00010282
CR0: 80050033 CR2: fffbc000 CR3: 1d9e0000 CR4: 000006f0
note: kworker/u8:5[61] exited with irqs disabled
BUG: unable to handle page fault for address: fffbc000
#PF: supervisor read access in kernel mode
#PF: error_code(0x0000) - not-present page
*pdpt = 0000000004fb9001 *pde = 000000001d9de063 *pte = 0000000000000000 
Oops: Oops: 0000 [#2] SMP PTI
CPU: 0 UID: 0 PID: 56 Comm: kworker/u8:4 Tainted: G      D          N  7.2.0-rc3-P3 #2 PREEMPTLAZY 
Tainted: [D]=DIE, [N]=TEST
Hardware name: LENOVO 2007F2G/2007F2G, BIOS 79ETE7WW (2.27 ) 03/21/2011
Workqueue: btrfs-delalloc btrfs_work_helper
EIP: ZSTD_compressStream2+0x221/0x5fc
Code: 8b 83 58 09 00 00 8b 93 5c 09 00 00 8b 4d e4 2b 4d f0 29 c2 39 ca 0f 47 d1 85 d2 74 0f 03 83 4c 09 00 00 89 d1 8b 75 f0 89 c7 <f3> a4 8b 83 58 09 00 00 31 c9 01 d0 83 7d f0 00 89 83 58 09 00 00
EAX: c29c77e0 EBX: c2900000 ECX: 00003000 EDX: 00004000
ESI: fffbc000 EDI: c29c87e0 EBP: f4c0dda0 ESP: f4c0dd68
DS: 007b ES: 007b FS: 00d8 GS: 0000 SS: 0068 EFLAGS: 00010282
CR0: 80050033 CR2: fffbc000 CR3: 02ed2000 CR4: 000006f0
Call Trace:
 ZSTD_compressStream+0xd/0x48
 zstd_compress_stream+0x8/0x10
 zstd_compress_bio+0x20a/0x564
 ? alloc_tagging_slab_alloc_hook+0x19/0x28
 btrfs_compress_bio+0x94/0xc0
 ? btrfs_compress_bio+0x5a/0xc0
 ? btrfs_compress_bio+0x94/0xc0
 compress_file_range+0x20a/0x380
 btrfs_work_helper+0xc1/0x1b4
 ? submit_uncompressed_range+0x18c/0x18c
 process_scheduled_works+0x15f/0x204
 worker_thread+0x10c/0x178
 kthread+0xe1/0xe8
 ? process_scheduled_works+0x204/0x204
 ? kthread_affine_node+0x80/0x80
 ret_from_fork+0x1d/0x14c
 ? kthread_affine_node+0x80/0x80
 ret_from_fork_asm+0x12/0x18
 entry_INT80_32+0xf0/0xf0
Modules linked in: cifs libsha512 dns_resolver nls_ucs2_utils cifs_md4 libmd5 ctr cbc aes ecb algif_skcipher af_alg iwl3945 iwlegacy af_packet mac80211 radeon drm_suballoc_helper thinkpad_acpi snd_hda_intel i2c_algo_bit cfg80211 snd_intel_dspcfg nvram snd_hda_codec drm_ttm_helper libaes sparse_keymap ttm snd_hwdep drm_exec platform_profile rfkill acpi_cpufreq snd_hda_core video drm_display_helper libarc4 cec snd_pcm battery wmi input_leds backlight thermal snd_timer led_class uhci_hcd snd ac soundcore ehci_pci ehci_hcd usbcore evdev processor joydev button usb_common pkcs8_key_parser coretemp hwmon fuse configfs
CR2: 00000000fffbc000
---[ end trace 0000000000000000 ]---
EIP: ZSTD_compressStream2+0x221/0x5fc
Code: 8b 83 58 09 00 00 8b 93 5c 09 00 00 8b 4d e4 2b 4d f0 29 c2 39 ca 0f 47 d1 85 d2 74 0f 03 83 4c 09 00 00 89 d1 8b 75 f0 89 c7 <f3> a4 8b 83 58 09 00 00 31 c9 01 d0 83 7d f0 00 89 83 58 09 00 00
EAX: c28457e0 EBX: c2800000 ECX: 0001f000 EDX: 00020000
ESI: fffbc000 EDI: c28467e0 EBP: c1b73da0 ESP: c1b73d68
DS: 007b ES: 007b FS: 00d8 GS: 0000 SS: 0068 EFLAGS: 00010282
CR0: 80050033 CR2: fffbc000 CR3: 02ed2000 CR4: 000006f0
note: kworker/u8:4[56] exited with irqs disabled
BUG: unable to handle page fault for address: fffbc000
#PF: supervisor read access in kernel mode
#PF: error_code(0x0000) - not-present page
*pdpt = 0000000003c5a001 *pde = 000000001d9de063 *pte = 0000000000000000 
Oops: Oops: 0000 [#3] SMP PTI
CPU: 0 UID: 0 PID: 54 Comm: kworker/u8:2 Tainted: G      D          N  7.2.0-rc3-P3 #2 PREEMPTLAZY 
Tainted: [D]=DIE, [N]=TEST
Hardware name: LENOVO 2007F2G/2007F2G, BIOS 79ETE7WW (2.27 ) 03/21/2011
Workqueue: btrfs-delalloc btrfs_work_helper
EIP: ZSTD_compressStream2+0x221/0x5fc
Code: 8b 83 58 09 00 00 8b 93 5c 09 00 00 8b 4d e4 2b 4d f0 29 c2 39 ca 0f 47 d1 85 d2 74 0f 03 83 4c 09 00 00 89 d1 8b 75 f0 89 c7 <f3> a4 8b 83 58 09 00 00 31 c9 01 d0 83 7d f0 00 89 83 58 09 00 00
EAX: c42d17e0 EBX: c4200000 ECX: 00001000 EDX: 00002000
ESI: fffbc000 EDI: c42d27e0 EBP: f4c07da0 ESP: f4c07d68
DS: 007b ES: 007b FS: 00d8 GS: 0000 SS: 0068 EFLAGS: 00010282
CR0: 80050033 CR2: fffbc000 CR3: 02ebe000 CR4: 000006f0
Call Trace:
 ZSTD_compressStream+0xd/0x48
 zstd_compress_stream+0x8/0x10
 zstd_compress_bio+0x20a/0x564
 ? alloc_tagging_slab_alloc_hook+0x19/0x28
 btrfs_compress_bio+0x94/0xc0
 ? btrfs_compress_bio+0x5a/0xc0
 ? btrfs_compress_bio+0x94/0xc0
 compress_file_range+0x20a/0x380
 btrfs_work_helper+0xc1/0x1b4
 ? submit_uncompressed_range+0x18c/0x18c
 process_scheduled_works+0x15f/0x204
 worker_thread+0x10c/0x178
 kthread+0xe1/0xe8
 ? process_scheduled_works+0x204/0x204
 ? kthread_affine_node+0x80/0x80
 ret_from_fork+0x1d/0x14c
 ? kthread_affine_node+0x80/0x80
 ret_from_fork_asm+0x12/0x18
 entry_INT80_32+0xf0/0xf0
Modules linked in: cifs libsha512 dns_resolver nls_ucs2_utils cifs_md4 libmd5 ctr cbc aes ecb algif_skcipher af_alg iwl3945 iwlegacy af_packet mac80211 radeon drm_suballoc_helper thinkpad_acpi snd_hda_intel i2c_algo_bit cfg80211 snd_intel_dspcfg nvram snd_hda_codec drm_ttm_helper libaes sparse_keymap ttm snd_hwdep drm_exec platform_profile rfkill acpi_cpufreq snd_hda_core video drm_display_helper libarc4 cec snd_pcm battery wmi input_leds backlight thermal snd_timer led_class uhci_hcd snd ac soundcore ehci_pci ehci_hcd usbcore evdev processor joydev button usb_common pkcs8_key_parser coretemp hwmon fuse configfs
CR2: 00000000fffbc000
---[ end trace 0000000000000000 ]---
EIP: ZSTD_compressStream2+0x221/0x5fc
Code: 8b 83 58 09 00 00 8b 93 5c 09 00 00 8b 4d e4 2b 4d f0 29 c2 39 ca 0f 47 d1 85 d2 74 0f 03 83 4c 09 00 00 89 d1 8b 75 f0 89 c7 <f3> a4 8b 83 58 09 00 00 31 c9 01 d0 83 7d f0 00 89 83 58 09 00 00
EAX: c28457e0 EBX: c2800000 ECX: 0001f000 EDX: 00020000
ESI: fffbc000 EDI: c28467e0 EBP: c1b73da0 ESP: c1b73d68
DS: 007b ES: 007b FS: 00d8 GS: 0000 SS: 0068 EFLAGS: 00010282
CR0: 80050033 CR2: fffbc000 CR3: 02ebe000 CR4: 000006f0
note: kworker/u8:2[54] exited with irqs disabled

I hit the issue not a boot, but as soon as doing some file operations on my zstd:1 compressed root and tmp filesystem. Sometimes even logging in at the console is enough to trigger the issue.

As kernel v7.1.x series is ok I was able to bisect the issue to the following commit:

 # git bisect bad
9bce95edb1b4d2802de9273b5170bfcff3090d24 is the first bad commit
commit 9bce95edb1b4d2802de9273b5170bfcff3090d24 (HEAD)
Author: Qu Wenruo <wqu@suse.com>
Date:   Fri Apr 24 10:20:25 2026 +0930

    btrfs: move large data folios out of experimental features
    
    This feature was introduced in v6.17 under experimental, and we had
    several small bugs related to or exposed by that:
    
      e9e3b22ddfa7 ("btrfs: fix beyond-EOF write handling")
      18de34daa7c6 ("btrfs: truncate ordered extent when skipping writeback past i_size")
    
    Otherwise, the feature has been frequently tested by btrfs developers.
    
    The latest fix only arrived in v6.19. After three releases, I think it's
    time to move this feature out of experimental.
    
    And since we're here, also remove the comment about the bitmap size
    limit, which is no longer relevant in the context. It will soon be
    outdated for the incoming huge folio support.
    
    Reviewed-by: Neal Gompa <neal@gompa.dev>
    Signed-off-by: Qu Wenruo <wqu@suse.com>
    Signed-off-by: David Sterba <dsterba@suse.com>

 fs/btrfs/Kconfig       |  2 +-
 fs/btrfs/btrfs_inode.h |  3 ---
 fs/btrfs/defrag.c      | 17 -----------------
 3 files changed, 1 insertion(+), 21 deletions(-)

Reverting commit 9bce95e on top of v7.2-rc3 fixes the issue.

Full dmesg, kernel .config and bisect.log attached.
netconsole_72-rc3_p3.txt
config_72-rc3_p3.txt
bisect.log

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugkernelsomething in kernel has to be done too

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions