Christoph, > Metadata added by bio_integrity_prep is using plain kmalloc, which > leads to random kernel memory being written media. For PI metadata > this is limited to the app tag that isn't used by kernel generated > metadata, but for non-PI metadata the entire buffer leaks kernel > memory. We do explicitly set the app_tag to 0 for PI so it's only non-PI metadata that's affected. > Fix this by adding the __GFP_ZERO flag to allocations for writes. Reviewed-by: Martin K. Petersen <martin.petersen@xxxxxxxxxx> -- Martin K. Petersen Oracle Linux Engineering