From: Jonathan Cameron <jic23@kernel.org>
To: Andy Shevchenko <andriy.shevchenko@intel.com>
Cc: linux-iio@vger.kernel.org, "Jinseob Kim" <kimjinseob88@gmail.com>,
"Joshua Crofts" <joshua.crofts1@gmail.com>,
"Sanjay Chitroda" <sanjayembeddedse@gmail.com>,
"David Lechner" <dlechner@baylibre.com>,
"Nuno Sá" <nuno.sa@analog.com>,
"Andy Shevchenko" <andy@kernel.org>,
sashiko-bot@kernel.org
Subject: Re: [PATCH v2] iio: buffer: Ensure bounce buffer used for unaligned case is zeroed.
Date: Fri, 5 Jun 2026 14:50:00 +0100 [thread overview]
Message-ID: <20260605145000.0ae0356e@jic23-huawei> (raw)
In-Reply-To: <aiFBEn_DKx5f6ekv@ashevche-desk.local>
On Thu, 4 Jun 2026 12:10:42 +0300
Andy Shevchenko <andriy.shevchenko@intel.com> wrote:
> On Thu, Jun 04, 2026 at 09:43:07AM +0100, Jonathan Cameron wrote:
> > iio_push_to_buffers_with_ts_unaligned() leaks uninitialized heap memory
> > to userspace if the data passed in is not a multiple of 8 bytes and the
> > timestamp is enabled. Use memset() to zero it after resizing.
>
> ...
>
> > indio_dev->scan_bytes, GFP_KERNEL);
> > if (!bb)
> > return -ENOMEM;
> > + memset(bb, 0, indio_dev->scan_bytes);
>
> May I suggest different approach, id est use __GFP_ZERO instead of hunting
> correct pointers?
That's a weird beast when combined with a krealloc so I was a bit
nervous about readability (and less so whether it was correct).
It should be fine in that we will either get stale data or zeros
because we always use this path to allocate the buffer so if you
think it is obviously fine then I don't mind.
The oddities are that if an object grows within a slab but doesn't need
a new one we are relying on those bits happening to be zero based on the
original allocation doing __GFP_ZERO as well (as it's the same call)
I'm nervous though as that region off the end is sometimes used for
debug objects and I really don't understand that bit of slab well enough.
If it actually does this, then seems like we'd end up with a lot of
nasty corner cases so I assume it doesn't. However, I couldn't convince
myself enough not to just force a memset of the whole thing.
>
> With Best Regards,
> Andy Shevchenko
>
>
>
next prev parent reply other threads:[~2026-06-05 13:50 UTC|newest]
Thread overview: 6+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-06-04 8:43 [PATCH v2] iio: buffer: Ensure bounce buffer used for unaligned case is zeroed Jonathan Cameron
2026-06-04 9:10 ` Andy Shevchenko
2026-06-05 13:50 ` Jonathan Cameron [this message]
2026-06-05 19:18 ` Andy Shevchenko
2026-06-08 20:00 ` Nuno Sá
2026-06-14 19:52 ` Jonathan Cameron
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260605145000.0ae0356e@jic23-huawei \
--to=jic23@kernel.org \
--cc=andriy.shevchenko@intel.com \
--cc=andy@kernel.org \
--cc=dlechner@baylibre.com \
--cc=joshua.crofts1@gmail.com \
--cc=kimjinseob88@gmail.com \
--cc=linux-iio@vger.kernel.org \
--cc=nuno.sa@analog.com \
--cc=sanjayembeddedse@gmail.com \
--cc=sashiko-bot@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.