stable.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
From: Sasha Levin <sashal@kernel.org>
To: linux-kernel@vger.kernel.org, stable@vger.kernel.org
Cc: Andrzej Pietrasiewicz <andrzej.p@collabora.com>,
	Felipe Balbi <felipe.balbi@linux.intel.com>,
	Sasha Levin <sashal@kernel.org>,
	linux-usb@vger.kernel.org
Subject: [PATCH AUTOSEL 4.9 17/45] usb: gadget: Zero ffs_io_data
Date: Fri, 19 Jul 2019 00:12:36 -0400	[thread overview]
Message-ID: <20190719041304.18849-17-sashal@kernel.org> (raw)
In-Reply-To: <20190719041304.18849-1-sashal@kernel.org>

From: Andrzej Pietrasiewicz <andrzej.p@collabora.com>

[ Upstream commit 508595515f4bcfe36246e4a565cf280937aeaade ]

In some cases the "Allocate & copy" block in ffs_epfile_io() is not
executed. Consequently, in such a case ffs_alloc_buffer() is never called
and struct ffs_io_data is not initialized properly. This in turn leads to
problems when ffs_free_buffer() is called at the end of ffs_epfile_io().

This patch uses kzalloc() instead of kmalloc() in the aio case and memset()
in non-aio case to properly initialize struct ffs_io_data.

Signed-off-by: Andrzej Pietrasiewicz <andrzej.p@collabora.com>
Signed-off-by: Felipe Balbi <felipe.balbi@linux.intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/usb/gadget/function/f_fs.c | 6 ++++--
 1 file changed, 4 insertions(+), 2 deletions(-)

diff --git a/drivers/usb/gadget/function/f_fs.c b/drivers/usb/gadget/function/f_fs.c
index 927ac0ee09b7..d1278d2d544b 100644
--- a/drivers/usb/gadget/function/f_fs.c
+++ b/drivers/usb/gadget/function/f_fs.c
@@ -1101,11 +1101,12 @@ static ssize_t ffs_epfile_write_iter(struct kiocb *kiocb, struct iov_iter *from)
 	ENTER();
 
 	if (!is_sync_kiocb(kiocb)) {
-		p = kmalloc(sizeof(io_data), GFP_KERNEL);
+		p = kzalloc(sizeof(io_data), GFP_KERNEL);
 		if (unlikely(!p))
 			return -ENOMEM;
 		p->aio = true;
 	} else {
+		memset(p, 0, sizeof(*p));
 		p->aio = false;
 	}
 
@@ -1137,11 +1138,12 @@ static ssize_t ffs_epfile_read_iter(struct kiocb *kiocb, struct iov_iter *to)
 	ENTER();
 
 	if (!is_sync_kiocb(kiocb)) {
-		p = kmalloc(sizeof(io_data), GFP_KERNEL);
+		p = kzalloc(sizeof(io_data), GFP_KERNEL);
 		if (unlikely(!p))
 			return -ENOMEM;
 		p->aio = true;
 	} else {
+		memset(p, 0, sizeof(*p));
 		p->aio = false;
 	}
 
-- 
2.20.1


  parent reply	other threads:[~2019-07-19  4:18 UTC|newest]

Thread overview: 45+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2019-07-19  4:12 [PATCH AUTOSEL 4.9 01/45] drm/panel: simple: Fix panel_simple_dsi_probe Sasha Levin
2019-07-19  4:12 ` [PATCH AUTOSEL 4.9 02/45] usb: core: hub: Disable hub-initiated U1/U2 Sasha Levin
2019-07-19  4:12 ` [PATCH AUTOSEL 4.9 03/45] tty: max310x: Fix invalid baudrate divisors calculator Sasha Levin
2019-07-19  4:12 ` [PATCH AUTOSEL 4.9 04/45] pinctrl: rockchip: fix leaked of_node references Sasha Levin
2019-07-19  4:12 ` [PATCH AUTOSEL 4.9 05/45] tty: serial: cpm_uart - fix init when SMC is relocated Sasha Levin
2019-07-19  4:12 ` [PATCH AUTOSEL 4.9 06/45] drm/edid: Fix a missing-check bug in drm_load_edid_firmware() Sasha Levin
2019-07-19  4:12 ` [PATCH AUTOSEL 4.9 07/45] drm/bridge: tc358767: read display_props in get_modes() Sasha Levin
2019-07-19  4:12 ` [PATCH AUTOSEL 4.9 08/45] drm/bridge: sii902x: pixel clock unit is 10kHz instead of 1kHz Sasha Levin
2019-07-19  4:12 ` [PATCH AUTOSEL 4.9 09/45] memstick: Fix error cleanup path of memstick_init Sasha Levin
2019-07-19  4:12 ` [PATCH AUTOSEL 4.9 10/45] tty/serial: digicolor: Fix digicolor-usart already registered warning Sasha Levin
2019-07-19  4:12 ` [PATCH AUTOSEL 4.9 11/45] tty: serial: msm_serial: avoid system lockup condition Sasha Levin
2019-07-19  4:12 ` [PATCH AUTOSEL 4.9 12/45] serial: 8250: Fix TX interrupt handling condition Sasha Levin
2019-07-19  4:12 ` [PATCH AUTOSEL 4.9 13/45] drm/virtio: Add memory barriers for capset cache Sasha Levin
2019-07-19  4:12 ` [PATCH AUTOSEL 4.9 14/45] phy: renesas: rcar-gen2: Fix memory leak at error paths Sasha Levin
2019-07-19  4:12 ` [PATCH AUTOSEL 4.9 15/45] drm/rockchip: Properly adjust to a true clock in adjusted_mode Sasha Levin
2019-07-19  4:12 ` [PATCH AUTOSEL 4.9 16/45] tty: serial_core: Set port active bit in uart_port_activate Sasha Levin
2019-07-19  4:12 ` Sasha Levin [this message]
2019-07-19  4:12 ` [PATCH AUTOSEL 4.9 18/45] powerpc/pci/of: Fix OF flags parsing for 64bit BARs Sasha Levin
2019-07-19  4:12 ` [PATCH AUTOSEL 4.9 19/45] PCI: sysfs: Ignore lockdep for remove attribute Sasha Levin
2019-07-19  4:12 ` [PATCH AUTOSEL 4.9 20/45] iio: st_accel: fix iio_triggered_buffer_{pre,post}enable positions Sasha Levin
2019-07-19  4:12 ` [PATCH AUTOSEL 4.9 21/45] kbuild: Add -Werror=unknown-warning-option to CLANG_FLAGS Sasha Levin
2019-07-19  4:12 ` [PATCH AUTOSEL 4.9 22/45] PCI: xilinx-nwl: Fix Multi MSI data programming Sasha Levin
2019-07-19  4:12 ` [PATCH AUTOSEL 4.9 23/45] iio: iio-utils: Fix possible incorrect mask calculation Sasha Levin
2019-07-19  4:12 ` [PATCH AUTOSEL 4.9 24/45] recordmcount: Fix spurious mcount entries on powerpc Sasha Levin
2019-07-19  4:12 ` [PATCH AUTOSEL 4.9 25/45] mfd: core: Set fwnode for created devices Sasha Levin
2019-07-19  4:12 ` [PATCH AUTOSEL 4.9 26/45] mfd: arizona: Fix undefined behavior Sasha Levin
2019-07-19  4:12 ` [PATCH AUTOSEL 4.9 27/45] mfd: hi655x-pmic: Fix missing return value check for devm_regmap_init_mmio_clk Sasha Levin
2019-07-19  4:12 ` [PATCH AUTOSEL 4.9 28/45] um: Silence lockdep complaint about mmap_sem Sasha Levin
2019-07-19  4:12 ` [PATCH AUTOSEL 4.9 29/45] powerpc/4xx/uic: clear pending interrupt after irq type/pol change Sasha Levin
2019-07-19  4:12 ` [PATCH AUTOSEL 4.9 30/45] RDMA/i40iw: Set queue pair state when being queried Sasha Levin
2019-07-19  4:12 ` [PATCH AUTOSEL 4.9 31/45] serial: sh-sci: Terminate TX DMA during buffer flushing Sasha Levin
2019-07-19  4:12 ` [PATCH AUTOSEL 4.9 32/45] serial: sh-sci: Fix TX DMA buffer flushing and workqueue races Sasha Levin
2019-07-19  4:12 ` [PATCH AUTOSEL 4.9 33/45] PCI: tegra: Enable Relaxed Ordering only for Tegra20 & Tegra30 Sasha Levin
2019-07-19  4:12 ` [PATCH AUTOSEL 4.9 34/45] kallsyms: exclude kasan local symbols on s390 Sasha Levin
2019-07-19  4:12 ` [PATCH AUTOSEL 4.9 35/45] perf test mmap-thread-lookup: Initialize variable to suppress memory sanitizer warning Sasha Levin
2019-07-19  4:12 ` [PATCH AUTOSEL 4.9 36/45] RDMA/rxe: Fill in wc byte_len with IB_WC_RECV_RDMA_WITH_IMM Sasha Levin
2019-07-19  4:12 ` [PATCH AUTOSEL 4.9 37/45] powerpc/boot: add {get, put}_unaligned_be32 to xz_config.h Sasha Levin
2019-07-19  4:12 ` [PATCH AUTOSEL 4.9 38/45] f2fs: avoid out-of-range memory access Sasha Levin
2019-07-19  4:12 ` [PATCH AUTOSEL 4.9 39/45] mailbox: handle failed named mailbox channel request Sasha Levin
2019-07-19  4:12 ` [PATCH AUTOSEL 4.9 40/45] powerpc/eeh: Handle hugepages in ioremap space Sasha Levin
2019-07-19  4:13 ` [PATCH AUTOSEL 4.9 41/45] sh: prevent warnings when using iounmap Sasha Levin
2019-07-19  4:13 ` [PATCH AUTOSEL 4.9 42/45] mm/kmemleak.c: fix check for softirq context Sasha Levin
2019-07-19  4:13 ` [PATCH AUTOSEL 4.9 43/45] 9p: pass the correct prototype to read_cache_page Sasha Levin
2019-07-19  4:13 ` [PATCH AUTOSEL 4.9 44/45] mm/mmu_notifier: use hlist_add_head_rcu() Sasha Levin
2019-07-19  4:13 ` [PATCH AUTOSEL 4.9 45/45] locking/lockdep: Fix lock used or unused stats error Sasha Levin

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20190719041304.18849-17-sashal@kernel.org \
    --to=sashal@kernel.org \
    --cc=andrzej.p@collabora.com \
    --cc=felipe.balbi@linux.intel.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-usb@vger.kernel.org \
    --cc=stable@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).