Skip to content

Commit bedc8f7

Browse files
metze-sambasmfrench
authored andcommitted
cifs: always initialize struct msghdr smb_msg completely
So far we were just lucky because the uninitialized members of struct msghdr are not used by default on a SOCK_STREAM tcp socket. But as new things like msg_ubuf and sg_from_iter where added recently, we should play on the safe side and avoid potention problems in future. Signed-off-by: Stefan Metzmacher <[email protected]> Cc: [email protected] Reviewed-by: Paulo Alcantara (SUSE) <[email protected]> Reviewed-by: Ronnie Sahlberg <[email protected]> Signed-off-by: Steve French <[email protected]>
1 parent 17d3df3 commit bedc8f7

File tree

2 files changed

+4
-13
lines changed

2 files changed

+4
-13
lines changed

fs/cifs/connect.c

Lines changed: 3 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -702,9 +702,6 @@ cifs_readv_from_socket(struct TCP_Server_Info *server, struct msghdr *smb_msg)
702702
int length = 0;
703703
int total_read;
704704

705-
smb_msg->msg_control = NULL;
706-
smb_msg->msg_controllen = 0;
707-
708705
for (total_read = 0; msg_data_left(smb_msg); total_read += length) {
709706
try_to_freeze();
710707

@@ -760,7 +757,7 @@ int
760757
cifs_read_from_socket(struct TCP_Server_Info *server, char *buf,
761758
unsigned int to_read)
762759
{
763-
struct msghdr smb_msg;
760+
struct msghdr smb_msg = {};
764761
struct kvec iov = {.iov_base = buf, .iov_len = to_read};
765762
iov_iter_kvec(&smb_msg.msg_iter, READ, &iov, 1, to_read);
766763

@@ -770,15 +767,13 @@ cifs_read_from_socket(struct TCP_Server_Info *server, char *buf,
770767
ssize_t
771768
cifs_discard_from_socket(struct TCP_Server_Info *server, size_t to_read)
772769
{
773-
struct msghdr smb_msg;
770+
struct msghdr smb_msg = {};
774771

775772
/*
776773
* iov_iter_discard already sets smb_msg.type and count and iov_offset
777774
* and cifs_readv_from_socket sets msg_control and msg_controllen
778775
* so little to initialize in struct msghdr
779776
*/
780-
smb_msg.msg_name = NULL;
781-
smb_msg.msg_namelen = 0;
782777
iov_iter_discard(&smb_msg.msg_iter, READ, to_read);
783778

784779
return cifs_readv_from_socket(server, &smb_msg);
@@ -788,7 +783,7 @@ int
788783
cifs_read_page_from_socket(struct TCP_Server_Info *server, struct page *page,
789784
unsigned int page_offset, unsigned int to_read)
790785
{
791-
struct msghdr smb_msg;
786+
struct msghdr smb_msg = {};
792787
struct bio_vec bv = {
793788
.bv_page = page, .bv_len = to_read, .bv_offset = page_offset};
794789
iov_iter_bvec(&smb_msg.msg_iter, READ, &bv, 1, to_read);

fs/cifs/transport.c

Lines changed: 1 addition & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -194,10 +194,6 @@ smb_send_kvec(struct TCP_Server_Info *server, struct msghdr *smb_msg,
194194

195195
*sent = 0;
196196

197-
smb_msg->msg_name = NULL;
198-
smb_msg->msg_namelen = 0;
199-
smb_msg->msg_control = NULL;
200-
smb_msg->msg_controllen = 0;
201197
if (server->noblocksnd)
202198
smb_msg->msg_flags = MSG_DONTWAIT + MSG_NOSIGNAL;
203199
else
@@ -309,7 +305,7 @@ __smb_send_rqst(struct TCP_Server_Info *server, int num_rqst,
309305
sigset_t mask, oldmask;
310306
size_t total_len = 0, sent, size;
311307
struct socket *ssocket = server->ssocket;
312-
struct msghdr smb_msg;
308+
struct msghdr smb_msg = {};
313309
__be32 rfc1002_marker;
314310

315311
if (cifs_rdma_enabled(server)) {

0 commit comments

Comments
 (0)