lib/iov_iter: initialize "flags" in new pipe_buffer
authorMax Kellermann <max.kellermann@ionos.com>
Mon, 21 Feb 2022 10:03:13 +0000 (11:03 +0100)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Wed, 23 Feb 2022 10:56:41 +0000 (11:56 +0100)
commit 9d2231c5d74e13b2a0546fee6737ee4446017903 upstream.

The functions copy_page_to_iter_pipe() and push_pipe() can both
allocate a new pipe_buffer, but the "flags" member initializer is
missing.

Fixes: 241699cd72a8 ("new iov_iter flavour: pipe-backed")
To: Alexander Viro <viro@zeniv.linux.org.uk>
To: linux-fsdevel@vger.kernel.org
To: linux-kernel@vger.kernel.org
Cc: stable@vger.kernel.org
Signed-off-by: Max Kellermann <max.kellermann@ionos.com>
Signed-off-by: Al Viro <viro@zeniv.linux.org.uk>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
lib/iov_iter.c

index 07d735b2eccf707463b56be35e7ffd9ce30e05e8..e01bb1c51d87bea0074acf67679c629af87e18fb 100644 (file)
@@ -370,6 +370,7 @@ static size_t copy_page_to_iter_pipe(struct page *page, size_t offset, size_t by
                return 0;
        pipe->nrbufs++;
        buf->ops = &page_cache_pipe_buf_ops;
+       buf->flags = 0;
        get_page(buf->page = page);
        buf->offset = offset;
        buf->len = bytes;
@@ -494,6 +495,7 @@ static size_t push_pipe(struct iov_iter *i, size_t size,
                        break;
                pipe->nrbufs++;
                pipe->bufs[idx].ops = &default_pipe_buf_ops;
+               pipe->bufs[idx].flags = 0;
                pipe->bufs[idx].page = page;
                pipe->bufs[idx].offset = 0;
                if (left <= PAGE_SIZE) {