From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-13.8 required=3.0 tests=BAYES_00, HEADER_FROM_DIFFERENT_DOMAINS,INCLUDES_CR_TRAILER,INCLUDES_PATCH, MAILING_LIST_MULTI,NICE_REPLY_A,SPF_HELO_NONE,SPF_PASS autolearn=unavailable autolearn_force=no version=3.4.0 Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id 8D878C11F67 for ; Tue, 29 Jun 2021 08:29:53 +0000 (UTC) Received: from vger.kernel.org (vger.kernel.org [23.128.96.18]) by mail.kernel.org (Postfix) with ESMTP id 6D4C561DE3 for ; Tue, 29 Jun 2021 08:29:53 +0000 (UTC) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S232505AbhF2IcT (ORCPT ); Tue, 29 Jun 2021 04:32:19 -0400 Received: from mail.fink.org ([79.134.252.20]:33152 "EHLO mail.fink.org" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S232489AbhF2IcS (ORCPT ); Tue, 29 Jun 2021 04:32:18 -0400 X-Greylist: delayed 331 seconds by postgrey-1.27 at vger.kernel.org; Tue, 29 Jun 2021 04:32:17 EDT X-Footer: Zmluay5vcmc= Received: from progrey.fink.org ([79.134.238.40]) (authenticated user list@fink.org) by mail.fink.org (Kerio Connect 9.3.1 patch 1) with ESMTPSA (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256 bits)); Tue, 29 Jun 2021 10:23:51 +0200 Subject: Re: [PATCH net] sctp: prevent info leak in sctp_make_heartbeat() To: Dan Carpenter Cc: Vlad Yasevich , Xin Long , Neil Horman , Marcelo Ricardo Leitner , "David S. Miller" , Jakub Kicinski , linux-sctp@vger.kernel.org, netdev@vger.kernel.org, kernel-janitors@vger.kernel.org References: From: Andreas Fink Message-ID: <886e4daf-c239-c1ce-da52-4b4684449908@list.fink.org> Date: Tue, 29 Jun 2021 10:23:49 +0200 User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.16; rv:52.0) Gecko/20100101 PostboxApp/7.0.48 MIME-Version: 1.0 In-Reply-To: Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 7bit Content-Language: en-US Precedence: bulk List-ID: X-Mailing-List: netdev@vger.kernel.org Does that gcc extension work with all compilers, especially clang? Dan Carpenter wrote on 29.06.21 10:19: > The "hbinfo" struct has a 4 byte hole at the end so we have to zero it > out to prevent stack information from being disclosed. > > Fixes: fe59379b9ab7 ("sctp: do the basic send and recv for PLPMTUD probe") > Signed-off-by: Dan Carpenter > --- > Btw = {} is the newest way to initialize holes. > > In the past we have debated whether = {} will *always* zero out struct > holes and it wasn't clear from the C standard. But it turns out that > "= {}" is not part of the standard but is instead a GCC extension and it > does clear the holes. In GCC (not the C standard) then = {0}; is also > supposed to initialize holes in there was a bug in one version where it > didn't. > > So that's nice, because adding memset()s to zero everywhere was ugly. > > net/sctp/sm_make_chunk.c | 2 +- > 1 file changed, 1 insertion(+), 1 deletion(-) > > diff --git a/net/sctp/sm_make_chunk.c b/net/sctp/sm_make_chunk.c > index 587fb3cb88e2..3a290f620e96 100644 > --- a/net/sctp/sm_make_chunk.c > +++ b/net/sctp/sm_make_chunk.c > @@ -1162,7 +1162,7 @@ struct sctp_chunk *sctp_make_new_encap_port(const struct sctp_association *asoc, > struct sctp_chunk *sctp_make_heartbeat(const struct sctp_association *asoc, > const struct sctp_transport *transport) > { > - struct sctp_sender_hb_info hbinfo; > + struct sctp_sender_hb_info hbinfo = {}; > struct sctp_chunk *retval; > > retval = sctp_make_control(asoc, SCTP_CID_HEARTBEAT, 0,