]> xenbits.xensource.com Git - people/aperard/linux.git/commitdiff
RDMA/hns: Fix uninitialized ucmd in hns_roce_create_qp_common()
authorChengchang Tang <tangchengchang@huawei.com>
Tue, 17 Oct 2023 12:52:34 +0000 (20:52 +0800)
committerLeon Romanovsky <leon@kernel.org>
Thu, 19 Oct 2023 06:49:40 +0000 (09:49 +0300)
ucmd in hns_roce_create_qp_common() are not initialized. But it works fine
until new member sdb_addr is added to struct hns_roce_ib_create_qp.

If the user-mode driver uses an old version ABI, then the value of the new
member will be undefined after ib_copy_from_udata().

This patch fixes it by initialize this variable to 0. And the default value
of the new member sdb_addr will be 0 which is invalid.

Fixes: 0425e3e6e0c7 ("RDMA/hns: Support flush cqe for hip08 in kernel space")
Signed-off-by: Chengchang Tang <tangchengchang@huawei.com>
Signed-off-by: Junxian Huang <huangjunxian6@hisilicon.com>
Link: https://lore.kernel.org/r/20231017125239.164455-3-huangjunxian6@hisilicon.com
Signed-off-by: Leon Romanovsky <leon@kernel.org>
drivers/infiniband/hw/hns/hns_roce_qp.c

index cdc1c6de43a174e25b177e6dac9de06c0163d4b4..828b58534aa976d1a84cc1133510214e9cbf3a6c 100644 (file)
@@ -1064,7 +1064,7 @@ static int hns_roce_create_qp_common(struct hns_roce_dev *hr_dev,
 {
        struct hns_roce_ib_create_qp_resp resp = {};
        struct ib_device *ibdev = &hr_dev->ib_dev;
-       struct hns_roce_ib_create_qp ucmd;
+       struct hns_roce_ib_create_qp ucmd = {};
        int ret;
 
        mutex_init(&hr_qp->mutex);