Linux Kernel  3.7.1
 All Data Structures Namespaces Files Functions Variables Typedefs Enumerations Enumerator Macros Groups Pages
compat_ioctl.c
Go to the documentation of this file.
1 /*
2  * ioctl32.c: Conversion between 32bit and 64bit native ioctls.
3  *
4  * Copyright (C) 1997-2000 Jakub Jelinek ([email protected])
5  * Copyright (C) 1998 Eddie C. Dost ([email protected])
6  * Copyright (C) 2001,2002 Andi Kleen, SuSE Labs
7  * Copyright (C) 2003 Pavel Machek ([email protected])
8  *
9  * These routines maintain argument size conversion between 32bit and 64bit
10  * ioctls.
11  */
12 
13 #include <linux/joystick.h>
14 
15 #include <linux/types.h>
16 #include <linux/compat.h>
17 #include <linux/kernel.h>
18 #include <linux/capability.h>
19 #include <linux/compiler.h>
20 #include <linux/sched.h>
21 #include <linux/smp.h>
22 #include <linux/ioctl.h>
23 #include <linux/if.h>
24 #include <linux/if_bridge.h>
25 #include <linux/raid/md_u.h>
26 #include <linux/kd.h>
27 #include <linux/route.h>
28 #include <linux/in6.h>
29 #include <linux/ipv6_route.h>
30 #include <linux/skbuff.h>
31 #include <linux/netlink.h>
32 #include <linux/vt.h>
33 #include <linux/falloc.h>
34 #include <linux/fs.h>
35 #include <linux/file.h>
36 #include <linux/ppp_defs.h>
37 #include <linux/ppp-ioctl.h>
38 #include <linux/if_pppox.h>
39 #include <linux/mtio.h>
40 #include <linux/auto_fs.h>
41 #include <linux/auto_fs4.h>
42 #include <linux/tty.h>
43 #include <linux/vt_kern.h>
44 #include <linux/fb.h>
45 #include <linux/videodev2.h>
46 #include <linux/netdevice.h>
47 #include <linux/raw.h>
48 #include <linux/blkdev.h>
49 #include <linux/elevator.h>
50 #include <linux/rtc.h>
51 #include <linux/pci.h>
52 #include <linux/serial.h>
53 #include <linux/if_tun.h>
54 #include <linux/ctype.h>
55 #include <linux/syscalls.h>
56 #include <linux/i2c.h>
57 #include <linux/i2c-dev.h>
58 #include <linux/atalk.h>
59 #include <linux/gfp.h>
60 
62 #include <net/bluetooth/hci.h>
63 #include <net/bluetooth/rfcomm.h>
64 
65 #include <linux/capi.h>
66 #include <linux/gigaset_dev.h>
67 
68 #ifdef CONFIG_BLOCK
69 #include <linux/loop.h>
70 #include <linux/cdrom.h>
71 #include <linux/fd.h>
72 #include <scsi/scsi.h>
73 #include <scsi/scsi_ioctl.h>
74 #include <scsi/sg.h>
75 #endif
76 
77 #include <asm/uaccess.h>
78 #include <linux/ethtool.h>
79 #include <linux/mii.h>
80 #include <linux/if_bonding.h>
81 #include <linux/watchdog.h>
82 
83 #include <linux/soundcard.h>
84 #include <linux/lp.h>
85 #include <linux/ppdev.h>
86 
87 #include <linux/atm.h>
88 #include <linux/atmarp.h>
89 #include <linux/atmclip.h>
90 #include <linux/atmdev.h>
91 #include <linux/atmioc.h>
92 #include <linux/atmlec.h>
93 #include <linux/atmmpc.h>
94 #include <linux/atmsvc.h>
95 #include <linux/atm_tcp.h>
96 #include <linux/sonet.h>
97 #include <linux/atm_suni.h>
98 
99 #include <linux/usb.h>
100 #include <linux/usbdevice_fs.h>
101 #include <linux/nbd.h>
102 #include <linux/random.h>
103 #include <linux/filter.h>
104 
105 #include <linux/hiddev.h>
106 
107 #define __DVB_CORE__
108 #include <linux/dvb/audio.h>
109 #include <linux/dvb/dmx.h>
110 #include <linux/dvb/frontend.h>
111 #include <linux/dvb/video.h>
112 
113 #include <linux/sort.h>
114 
115 #ifdef CONFIG_SPARC
116 #include <asm/fbio.h>
117 #endif
118 
119 static int w_long(unsigned int fd, unsigned int cmd,
120  compat_ulong_t __user *argp)
121 {
122  mm_segment_t old_fs = get_fs();
123  int err;
124  unsigned long val;
125 
126  set_fs (KERNEL_DS);
127  err = sys_ioctl(fd, cmd, (unsigned long)&val);
128  set_fs (old_fs);
129  if (!err && put_user(val, argp))
130  return -EFAULT;
131  return err;
132 }
133 
137  union {
139  unsigned int frame_rate;
140  } u;
141 };
142 
143 static int do_video_get_event(unsigned int fd, unsigned int cmd,
144  struct compat_video_event __user *up)
145 {
146  struct video_event kevent;
147  mm_segment_t old_fs = get_fs();
148  int err;
149 
150  set_fs(KERNEL_DS);
151  err = sys_ioctl(fd, cmd, (unsigned long) &kevent);
152  set_fs(old_fs);
153 
154  if (!err) {
155  err = put_user(kevent.type, &up->type);
156  err |= put_user(kevent.timestamp, &up->timestamp);
157  err |= put_user(kevent.u.size.w, &up->u.size.w);
158  err |= put_user(kevent.u.size.h, &up->u.size.h);
159  err |= put_user(kevent.u.size.aspect_ratio,
160  &up->u.size.aspect_ratio);
161  if (err)
162  err = -EFAULT;
163  }
164 
165  return err;
166 }
167 
171 };
172 
173 static int do_video_stillpicture(unsigned int fd, unsigned int cmd,
174  struct compat_video_still_picture __user *up)
175 {
176  struct video_still_picture __user *up_native;
178  int32_t size;
179  int err;
180 
181  err = get_user(fp, &up->iFrame);
182  err |= get_user(size, &up->size);
183  if (err)
184  return -EFAULT;
185 
186  up_native =
188 
189  err = put_user(compat_ptr(fp), &up_native->iFrame);
190  err |= put_user(size, &up_native->size);
191  if (err)
192  return -EFAULT;
193 
194  err = sys_ioctl(fd, cmd, (unsigned long) up_native);
195 
196  return err;
197 }
198 
200  int length;
202 };
203 
204 static int do_video_set_spu_palette(unsigned int fd, unsigned int cmd,
205  struct compat_video_spu_palette __user *up)
206 {
207  struct video_spu_palette __user *up_native;
208  compat_uptr_t palp;
209  int length, err;
210 
211  err = get_user(palp, &up->palette);
212  err |= get_user(length, &up->length);
213  if (err)
214  return -EFAULT;
215 
216  up_native = compat_alloc_user_space(sizeof(struct video_spu_palette));
217  err = put_user(compat_ptr(palp), &up_native->palette);
218  err |= put_user(length, &up_native->length);
219  if (err)
220  return -EFAULT;
221 
222  err = sys_ioctl(fd, cmd, (unsigned long) up_native);
223 
224  return err;
225 }
226 
227 #ifdef CONFIG_BLOCK
228 typedef struct sg_io_hdr32 {
229  compat_int_t interface_id; /* [i] 'S' for SCSI generic (required) */
230  compat_int_t dxfer_direction; /* [i] data transfer direction */
231  unsigned char cmd_len; /* [i] SCSI command length ( <= 16 bytes) */
232  unsigned char mx_sb_len; /* [i] max length to write to sbp */
233  unsigned short iovec_count; /* [i] 0 implies no scatter gather */
234  compat_uint_t dxfer_len; /* [i] byte count of data transfer */
235  compat_uint_t dxferp; /* [i], [*io] points to data transfer memory
236  or scatter gather list */
237  compat_uptr_t cmdp; /* [i], [*i] points to command to perform */
238  compat_uptr_t sbp; /* [i], [*o] points to sense_buffer memory */
239  compat_uint_t timeout; /* [i] MAX_UINT->no timeout (unit: millisec) */
240  compat_uint_t flags; /* [i] 0 -> default, see SG_FLAG... */
241  compat_int_t pack_id; /* [i->o] unused internally (normally) */
242  compat_uptr_t usr_ptr; /* [i->o] unused internally */
243  unsigned char status; /* [o] scsi status */
244  unsigned char masked_status; /* [o] shifted, masked scsi status */
245  unsigned char msg_status; /* [o] messaging level data (optional) */
246  unsigned char sb_len_wr; /* [o] byte count actually written to sbp */
247  unsigned short host_status; /* [o] errors from host adapter */
248  unsigned short driver_status; /* [o] errors from software driver */
249  compat_int_t resid; /* [o] dxfer_len - actual_transferred */
250  compat_uint_t duration; /* [o] time taken by cmd (unit: millisec) */
251  compat_uint_t info; /* [o] auxiliary information */
252 } sg_io_hdr32_t; /* 64 bytes long (on sparc32) */
253 
254 typedef struct sg_iovec32 {
255  compat_uint_t iov_base;
256  compat_uint_t iov_len;
257 } sg_iovec32_t;
258 
259 static int sg_build_iovec(sg_io_hdr_t __user *sgio, void __user *dxferp, u16 iovec_count)
260 {
261  sg_iovec_t __user *iov = (sg_iovec_t __user *) (sgio + 1);
262  sg_iovec32_t __user *iov32 = dxferp;
263  int i;
264 
265  for (i = 0; i < iovec_count; i++) {
266  u32 base, len;
267 
268  if (get_user(base, &iov32[i].iov_base) ||
269  get_user(len, &iov32[i].iov_len) ||
270  put_user(compat_ptr(base), &iov[i].iov_base) ||
271  put_user(len, &iov[i].iov_len))
272  return -EFAULT;
273  }
274 
275  if (put_user(iov, &sgio->dxferp))
276  return -EFAULT;
277  return 0;
278 }
279 
280 static int sg_ioctl_trans(unsigned int fd, unsigned int cmd,
281  sg_io_hdr32_t __user *sgio32)
282 {
283  sg_io_hdr_t __user *sgio;
284  u16 iovec_count;
285  u32 data;
286  void __user *dxferp;
287  int err;
288  int interface_id;
289 
290  if (get_user(interface_id, &sgio32->interface_id))
291  return -EFAULT;
292  if (interface_id != 'S')
293  return sys_ioctl(fd, cmd, (unsigned long)sgio32);
294 
295  if (get_user(iovec_count, &sgio32->iovec_count))
296  return -EFAULT;
297 
298  {
300  void __user *new = compat_alloc_user_space(sizeof(sg_io_hdr_t) +
301  (iovec_count * sizeof(sg_iovec_t)));
302  if (new > top)
303  return -EINVAL;
304 
305  sgio = new;
306  }
307 
308  /* Ok, now construct. */
309  if (copy_in_user(&sgio->interface_id, &sgio32->interface_id,
310  (2 * sizeof(int)) +
311  (2 * sizeof(unsigned char)) +
312  (1 * sizeof(unsigned short)) +
313  (1 * sizeof(unsigned int))))
314  return -EFAULT;
315 
316  if (get_user(data, &sgio32->dxferp))
317  return -EFAULT;
318  dxferp = compat_ptr(data);
319  if (iovec_count) {
320  if (sg_build_iovec(sgio, dxferp, iovec_count))
321  return -EFAULT;
322  } else {
323  if (put_user(dxferp, &sgio->dxferp))
324  return -EFAULT;
325  }
326 
327  {
328  unsigned char __user *cmdp;
329  unsigned char __user *sbp;
330 
331  if (get_user(data, &sgio32->cmdp))
332  return -EFAULT;
333  cmdp = compat_ptr(data);
334 
335  if (get_user(data, &sgio32->sbp))
336  return -EFAULT;
337  sbp = compat_ptr(data);
338 
339  if (put_user(cmdp, &sgio->cmdp) ||
340  put_user(sbp, &sgio->sbp))
341  return -EFAULT;
342  }
343 
344  if (copy_in_user(&sgio->timeout, &sgio32->timeout,
345  3 * sizeof(int)))
346  return -EFAULT;
347 
348  if (get_user(data, &sgio32->usr_ptr))
349  return -EFAULT;
350  if (put_user(compat_ptr(data), &sgio->usr_ptr))
351  return -EFAULT;
352 
353  err = sys_ioctl(fd, cmd, (unsigned long) sgio);
354 
355  if (err >= 0) {
356  void __user *datap;
357 
358  if (copy_in_user(&sgio32->pack_id, &sgio->pack_id,
359  sizeof(int)) ||
360  get_user(datap, &sgio->usr_ptr) ||
361  put_user((u32)(unsigned long)datap,
362  &sgio32->usr_ptr) ||
363  copy_in_user(&sgio32->status, &sgio->status,
364  (4 * sizeof(unsigned char)) +
365  (2 * sizeof(unsigned short)) +
366  (3 * sizeof(int))))
367  err = -EFAULT;
368  }
369 
370  return err;
371 }
372 
373 struct compat_sg_req_info { /* used by SG_GET_REQUEST_TABLE ioctl() */
374  char req_state;
375  char orphan;
376  char sg_io_owned;
377  char problem;
378  int pack_id;
379  compat_uptr_t usr_ptr;
380  unsigned int duration;
381  int unused;
382 };
383 
384 static int sg_grt_trans(unsigned int fd, unsigned int cmd, struct
385  compat_sg_req_info __user *o)
386 {
387  int err, i;
388  sg_req_info_t __user *r;
390  err = sys_ioctl(fd,cmd,(unsigned long)r);
391  if (err < 0)
392  return err;
393  for (i = 0; i < SG_MAX_QUEUE; i++) {
394  void __user *ptr;
395  int d;
396 
397  if (copy_in_user(o + i, r + i, offsetof(sg_req_info_t, usr_ptr)) ||
398  get_user(ptr, &r[i].usr_ptr) ||
399  get_user(d, &r[i].duration) ||
400  put_user((u32)(unsigned long)(ptr), &o[i].usr_ptr) ||
401  put_user(d, &o[i].duration))
402  return -EFAULT;
403  }
404  return err;
405 }
406 #endif /* CONFIG_BLOCK */
407 
408 struct sock_fprog32 {
409  unsigned short len;
411 };
412 
413 #define PPPIOCSPASS32 _IOW('t', 71, struct sock_fprog32)
414 #define PPPIOCSACTIVE32 _IOW('t', 70, struct sock_fprog32)
415 
416 static int ppp_sock_fprog_ioctl_trans(unsigned int fd, unsigned int cmd,
417  struct sock_fprog32 __user *u_fprog32)
418 {
419  struct sock_fprog __user *u_fprog64 = compat_alloc_user_space(sizeof(struct sock_fprog));
420  void __user *fptr64;
421  u32 fptr32;
422  u16 flen;
423 
424  if (get_user(flen, &u_fprog32->len) ||
425  get_user(fptr32, &u_fprog32->filter))
426  return -EFAULT;
427 
428  fptr64 = compat_ptr(fptr32);
429 
430  if (put_user(flen, &u_fprog64->len) ||
431  put_user(fptr64, &u_fprog64->filter))
432  return -EFAULT;
433 
434  if (cmd == PPPIOCSPASS32)
435  cmd = PPPIOCSPASS;
436  else
437  cmd = PPPIOCSACTIVE;
438 
439  return sys_ioctl(fd, cmd, (unsigned long) u_fprog64);
440 }
441 
446 };
447 #define PPPIOCSCOMPRESS32 _IOW('t', 77, struct ppp_option_data32)
448 
449 struct ppp_idle32 {
452 };
453 #define PPPIOCGIDLE32 _IOR('t', 63, struct ppp_idle32)
454 
455 static int ppp_gidle(unsigned int fd, unsigned int cmd,
456  struct ppp_idle32 __user *idle32)
457 {
458  struct ppp_idle __user *idle;
459  __kernel_time_t xmit, recv;
460  int err;
461 
462  idle = compat_alloc_user_space(sizeof(*idle));
463 
464  err = sys_ioctl(fd, PPPIOCGIDLE, (unsigned long) idle);
465 
466  if (!err) {
467  if (get_user(xmit, &idle->xmit_idle) ||
468  get_user(recv, &idle->recv_idle) ||
469  put_user(xmit, &idle32->xmit_idle) ||
470  put_user(recv, &idle32->recv_idle))
471  err = -EFAULT;
472  }
473  return err;
474 }
475 
476 static int ppp_scompress(unsigned int fd, unsigned int cmd,
477  struct ppp_option_data32 __user *odata32)
478 {
479  struct ppp_option_data __user *odata;
480  __u32 data;
481  void __user *datap;
482 
483  odata = compat_alloc_user_space(sizeof(*odata));
484 
485  if (get_user(data, &odata32->ptr))
486  return -EFAULT;
487 
488  datap = compat_ptr(data);
489  if (put_user(datap, &odata->ptr))
490  return -EFAULT;
491 
492  if (copy_in_user(&odata->length, &odata32->length,
493  sizeof(__u32) + sizeof(int)))
494  return -EFAULT;
495 
496  return sys_ioctl(fd, PPPIOCSCOMPRESS, (unsigned long) odata);
497 }
498 
499 #ifdef CONFIG_BLOCK
500 struct mtget32 {
501  compat_long_t mt_type;
502  compat_long_t mt_resid;
503  compat_long_t mt_dsreg;
504  compat_long_t mt_gstat;
505  compat_long_t mt_erreg;
506  compat_daddr_t mt_fileno;
507  compat_daddr_t mt_blkno;
508 };
509 #define MTIOCGET32 _IOR('m', 2, struct mtget32)
510 
511 struct mtpos32 {
512  compat_long_t mt_blkno;
513 };
514 #define MTIOCPOS32 _IOR('m', 3, struct mtpos32)
515 
516 static int mt_ioctl_trans(unsigned int fd, unsigned int cmd, void __user *argp)
517 {
518  mm_segment_t old_fs = get_fs();
519  struct mtget get;
520  struct mtget32 __user *umget32;
521  struct mtpos pos;
522  struct mtpos32 __user *upos32;
523  unsigned long kcmd;
524  void *karg;
525  int err = 0;
526 
527  switch(cmd) {
528  case MTIOCPOS32:
529  kcmd = MTIOCPOS;
530  karg = &pos;
531  break;
532  default: /* MTIOCGET32 */
533  kcmd = MTIOCGET;
534  karg = &get;
535  break;
536  }
537  set_fs (KERNEL_DS);
538  err = sys_ioctl (fd, kcmd, (unsigned long)karg);
539  set_fs (old_fs);
540  if (err)
541  return err;
542  switch (cmd) {
543  case MTIOCPOS32:
544  upos32 = argp;
545  err = __put_user(pos.mt_blkno, &upos32->mt_blkno);
546  break;
547  case MTIOCGET32:
548  umget32 = argp;
549  err = __put_user(get.mt_type, &umget32->mt_type);
550  err |= __put_user(get.mt_resid, &umget32->mt_resid);
551  err |= __put_user(get.mt_dsreg, &umget32->mt_dsreg);
552  err |= __put_user(get.mt_gstat, &umget32->mt_gstat);
553  err |= __put_user(get.mt_erreg, &umget32->mt_erreg);
554  err |= __put_user(get.mt_fileno, &umget32->mt_fileno);
555  err |= __put_user(get.mt_blkno, &umget32->mt_blkno);
556  break;
557  }
558  return err ? -EFAULT: 0;
559 }
560 
561 #endif /* CONFIG_BLOCK */
562 
563 /* Bluetooth ioctls */
564 #define HCIUARTSETPROTO _IOW('U', 200, int)
565 #define HCIUARTGETPROTO _IOR('U', 201, int)
566 #define HCIUARTGETDEVICE _IOR('U', 202, int)
567 #define HCIUARTSETFLAGS _IOW('U', 203, int)
568 #define HCIUARTGETFLAGS _IOR('U', 204, int)
569 
570 #define BNEPCONNADD _IOW('B', 200, int)
571 #define BNEPCONNDEL _IOW('B', 201, int)
572 #define BNEPGETCONNLIST _IOR('B', 210, int)
573 #define BNEPGETCONNINFO _IOR('B', 211, int)
574 
575 #define CMTPCONNADD _IOW('C', 200, int)
576 #define CMTPCONNDEL _IOW('C', 201, int)
577 #define CMTPGETCONNLIST _IOR('C', 210, int)
578 #define CMTPGETCONNINFO _IOR('C', 211, int)
579 
580 #define HIDPCONNADD _IOW('H', 200, int)
581 #define HIDPCONNDEL _IOW('H', 201, int)
582 #define HIDPGETCONNLIST _IOR('H', 210, int)
583 #define HIDPGETCONNINFO _IOR('H', 211, int)
584 
585 
595  unsigned short close_delay;
596  char io_type;
597  char reserved_char[1];
599  unsigned short closing_wait; /* time to wait before closing */
600  unsigned short closing_wait2; /* no longer used... */
602  unsigned short iomem_reg_shift;
603  unsigned int port_high;
604  /* compat_ulong_t iomap_base FIXME */
606 };
607 
608 static int serial_struct_ioctl(unsigned fd, unsigned cmd,
609  struct serial_struct32 __user *ss32)
610 {
611  typedef struct serial_struct SS;
612  typedef struct serial_struct32 SS32;
613  int err;
614  struct serial_struct ss;
615  mm_segment_t oldseg = get_fs();
616  __u32 udata;
617  unsigned int base;
618 
619  if (cmd == TIOCSSERIAL) {
620  if (!access_ok(VERIFY_READ, ss32, sizeof(SS32)))
621  return -EFAULT;
622  if (__copy_from_user(&ss, ss32, offsetof(SS32, iomem_base)))
623  return -EFAULT;
624  if (__get_user(udata, &ss32->iomem_base))
625  return -EFAULT;
626  ss.iomem_base = compat_ptr(udata);
627  if (__get_user(ss.iomem_reg_shift, &ss32->iomem_reg_shift) ||
628  __get_user(ss.port_high, &ss32->port_high))
629  return -EFAULT;
630  ss.iomap_base = 0UL;
631  }
632  set_fs(KERNEL_DS);
633  err = sys_ioctl(fd,cmd,(unsigned long)(&ss));
634  set_fs(oldseg);
635  if (cmd == TIOCGSERIAL && err >= 0) {
636  if (!access_ok(VERIFY_WRITE, ss32, sizeof(SS32)))
637  return -EFAULT;
638  if (__copy_to_user(ss32,&ss,offsetof(SS32,iomem_base)))
639  return -EFAULT;
640  base = (unsigned long)ss.iomem_base >> 32 ?
641  0xffffffff : (unsigned)(unsigned long)ss.iomem_base;
642  if (__put_user(base, &ss32->iomem_base) ||
643  __put_user(ss.iomem_reg_shift, &ss32->iomem_reg_shift) ||
644  __put_user(ss.port_high, &ss32->port_high))
645  return -EFAULT;
646  }
647  return err;
648 }
649 
650 /*
651  * I2C layer ioctls
652  */
653 
654 struct i2c_msg32 {
659 };
660 
662  compat_caddr_t msgs; /* struct i2c_msg __user *msgs */
664 };
665 
670  compat_caddr_t data; /* union i2c_smbus_data *data */
671 };
672 
675  struct i2c_msg msgs[0];
676 };
677 
678 static int do_i2c_rdwr_ioctl(unsigned int fd, unsigned int cmd,
679  struct i2c_rdwr_ioctl_data32 __user *udata)
680 {
681  struct i2c_rdwr_aligned __user *tdata;
682  struct i2c_msg __user *tmsgs;
683  struct i2c_msg32 __user *umsgs;
684  compat_caddr_t datap;
685  int nmsgs, i;
686 
687  if (get_user(nmsgs, &udata->nmsgs))
688  return -EFAULT;
689  if (nmsgs > I2C_RDRW_IOCTL_MAX_MSGS)
690  return -EINVAL;
691 
692  if (get_user(datap, &udata->msgs))
693  return -EFAULT;
694  umsgs = compat_ptr(datap);
695 
696  tdata = compat_alloc_user_space(sizeof(*tdata) +
697  nmsgs * sizeof(struct i2c_msg));
698  tmsgs = &tdata->msgs[0];
699 
700  if (put_user(nmsgs, &tdata->cmd.nmsgs) ||
701  put_user(tmsgs, &tdata->cmd.msgs))
702  return -EFAULT;
703 
704  for (i = 0; i < nmsgs; i++) {
705  if (copy_in_user(&tmsgs[i].addr, &umsgs[i].addr, 3*sizeof(u16)))
706  return -EFAULT;
707  if (get_user(datap, &umsgs[i].buf) ||
708  put_user(compat_ptr(datap), &tmsgs[i].buf))
709  return -EFAULT;
710  }
711  return sys_ioctl(fd, cmd, (unsigned long)tdata);
712 }
713 
714 static int do_i2c_smbus_ioctl(unsigned int fd, unsigned int cmd,
715  struct i2c_smbus_ioctl_data32 __user *udata)
716 {
717  struct i2c_smbus_ioctl_data __user *tdata;
718  compat_caddr_t datap;
719 
720  tdata = compat_alloc_user_space(sizeof(*tdata));
721  if (tdata == NULL)
722  return -ENOMEM;
723  if (!access_ok(VERIFY_WRITE, tdata, sizeof(*tdata)))
724  return -EFAULT;
725 
726  if (!access_ok(VERIFY_READ, udata, sizeof(*udata)))
727  return -EFAULT;
728 
729  if (__copy_in_user(&tdata->read_write, &udata->read_write, 2 * sizeof(u8)))
730  return -EFAULT;
731  if (__copy_in_user(&tdata->size, &udata->size, 2 * sizeof(u32)))
732  return -EFAULT;
733  if (__get_user(datap, &udata->data) ||
734  __put_user(compat_ptr(datap), &tdata->data))
735  return -EFAULT;
736 
737  return sys_ioctl(fd, cmd, (unsigned long)tdata);
738 }
739 
740 #define RTC_IRQP_READ32 _IOR('p', 0x0b, compat_ulong_t)
741 #define RTC_IRQP_SET32 _IOW('p', 0x0c, compat_ulong_t)
742 #define RTC_EPOCH_READ32 _IOR('p', 0x0d, compat_ulong_t)
743 #define RTC_EPOCH_SET32 _IOW('p', 0x0e, compat_ulong_t)
744 
745 static int rtc_ioctl(unsigned fd, unsigned cmd, void __user *argp)
746 {
747  mm_segment_t oldfs = get_fs();
748  compat_ulong_t val32;
749  unsigned long kval;
750  int ret;
751 
752  switch (cmd) {
753  case RTC_IRQP_READ32:
754  case RTC_EPOCH_READ32:
755  set_fs(KERNEL_DS);
756  ret = sys_ioctl(fd, (cmd == RTC_IRQP_READ32) ?
758  (unsigned long)&kval);
759  set_fs(oldfs);
760  if (ret)
761  return ret;
762  val32 = kval;
763  return put_user(val32, (unsigned int __user *)argp);
764  case RTC_IRQP_SET32:
765  return sys_ioctl(fd, RTC_IRQP_SET, (unsigned long)argp);
766  case RTC_EPOCH_SET32:
767  return sys_ioctl(fd, RTC_EPOCH_SET, (unsigned long)argp);
768  }
769 
770  return -ENOIOCTLCMD;
771 }
772 
773 /* on ia32 l_start is on a 32-bit boundary */
774 #if defined(CONFIG_IA64) || defined(CONFIG_X86_64)
775 struct space_resv_32 {
776  __s16 l_type;
777  __s16 l_whence;
778  __s64 l_start __attribute__((packed));
779  /* len == 0 means until end of file */
780  __s64 l_len __attribute__((packed));
781  __s32 l_sysid;
782  __u32 l_pid;
783  __s32 l_pad[4]; /* reserve area */
784 };
785 
786 #define FS_IOC_RESVSP_32 _IOW ('X', 40, struct space_resv_32)
787 #define FS_IOC_RESVSP64_32 _IOW ('X', 42, struct space_resv_32)
788 
789 /* just account for different alignment */
790 static int compat_ioctl_preallocate(struct file *file,
791  struct space_resv_32 __user *p32)
792 {
793  struct space_resv __user *p = compat_alloc_user_space(sizeof(*p));
794 
795  if (copy_in_user(&p->l_type, &p32->l_type, sizeof(s16)) ||
796  copy_in_user(&p->l_whence, &p32->l_whence, sizeof(s16)) ||
797  copy_in_user(&p->l_start, &p32->l_start, sizeof(s64)) ||
798  copy_in_user(&p->l_len, &p32->l_len, sizeof(s64)) ||
799  copy_in_user(&p->l_sysid, &p32->l_sysid, sizeof(s32)) ||
800  copy_in_user(&p->l_pid, &p32->l_pid, sizeof(u32)) ||
801  copy_in_user(&p->l_pad, &p32->l_pad, 4*sizeof(u32)))
802  return -EFAULT;
803 
804  return ioctl_preallocate(file, p);
805 }
806 #endif
807 
808 /*
809  * simple reversible transform to make our table more evenly
810  * distributed after sorting.
811  */
812 #define XFORM(i) (((i) ^ ((i) << 27) ^ ((i) << 17)) & 0xffffffff)
813 
814 #define COMPATIBLE_IOCTL(cmd) XFORM(cmd),
815 /* ioctl should not be warned about even if it's not implemented.
816  Valid reasons to use this:
817  - It is implemented with ->compat_ioctl on some device, but programs
818  call it on others too.
819  - The ioctl is not implemented in the native kernel, but programs
820  call it commonly anyways.
821  Most other reasons are not valid. */
822 #define IGNORE_IOCTL(cmd) COMPATIBLE_IOCTL(cmd)
823 
824 static unsigned int ioctl_pointer[] = {
825 /* compatible ioctls first */
826 COMPATIBLE_IOCTL(0x4B50) /* KDGHWCLK - not in the kernel, but don't complain */
827 COMPATIBLE_IOCTL(0x4B51) /* KDSHWCLK - not in the kernel, but don't complain */
828 
829 /* Big T */
847 /* Little t */
871 #ifdef TIOCSRS485
873 #endif
874 #ifdef TIOCGRS485
876 #endif
877 #ifdef TCGETS2
882 #endif
883 /* Little f */
888 COMPATIBLE_IOCTL(FIONREAD) /* This is also TIOCINQ */
890 /* 0x00 */
893 /* 'X' - originally XFS but some now in the VFS */
913 #ifdef CONFIG_BLOCK
914 /* Big S */
923 #endif
924 /* Big V (don't complain on serial console) */
927 /* Little p (/dev/rtc, /dev/envctrl, etc.) */
942 /*
943  * These two are only for the sbus rtc driver, but
944  * hwclock tries them on every rtc device first when
945  * running on sparc. On other architectures the entries
946  * are useless but harmless.
947  */
948 COMPATIBLE_IOCTL(_IOR('p', 20, int[7])) /* RTCGET */
949 COMPATIBLE_IOCTL(_IOW('p', 21, int[7])) /* RTCSET */
950 /* Little m */
952 /* Socket level stuff */
954 #ifdef CONFIG_BLOCK
955 /* loop */
957 /* md calls this on random blockdevs */
959 /* qemu/qemu-img might call these two on plain files for probing */
961 IGNORE_IOCTL(FDGETPRM32)
962 /* SG stuff */
985 #endif
986 /* PPP stuff */
1000 /* PPPIOCSCOMPRESS is translated */
1005 /* PPPIOCSPASS is translated */
1006 /* PPPIOCSACTIVE is translated */
1007 /* PPPIOCGIDLE is translated */
1017 /* PPPOX */
1020 /* ppdev */
1042 /* Big A */
1043 /* sparc only */
1044 /* Big Q for sound/OSS */
1067 /* Big T for sound/OSS */
1076 /* Little m for sound/OSS */
1080 /* Big P for sound/OSS */
1101 /* SNDCTL_DSP_MAPINBUF, XXX needs translation */
1102 /* SNDCTL_DSP_MAPOUTBUF, XXX needs translation */
1111 /* Big C for sound/OSS */
1122 /* Big M for sound/OSS */
1149 /* SOUND_MIXER_READ_ENHANCE, same value as READ_MUTE */
1150 /* SOUND_MIXER_READ_LOUD, same value as READ_MUTE */
1182 /* SOUND_MIXER_WRITE_ENHANCE, same value as WRITE_MUTE */
1183 /* SOUND_MIXER_WRITE_LOUD, same value as WRITE_MUTE */
1198 /* Raw devices */
1201 /* Watchdog */
1210 /* Big R */
1217 /* Bluetooth */
1258 /* CAPI */
1272 /* Siemens Gigaset */
1277 /* Misc. */
1278 COMPATIBLE_IOCTL(0x41545900) /* ATYIO_CLKR */
1279 COMPATIBLE_IOCTL(0x41545901) /* ATYIO_CLKW */
1284 /* NBD */
1290 /* i2c */
1297 /* hiddev */
1314 /* dvb */
1381 
1382 /* joystick */
1387 
1388 #ifdef TIOCGLTC
1391 #endif
1392 #ifdef TIOCSTART
1393 /*
1394  * For these two we have definitions in ioctls.h and/or termios.h on
1395  * some architectures but no actual implemention. Some applications
1396  * like bash call them if they are defined in the headers, so we provide
1397  * entries here to avoid syslog message spew.
1398  */
1401 #endif
1402 
1403 /* fat 'r' ioctls. These are handled by fat with ->compat_ioctl,
1404  but we don't want warnings on other file systems. So declare
1405  them as compatible here. */
1406 #define VFAT_IOCTL_READDIR_BOTH32 _IOR('r', 1, struct compat_dirent[2])
1407 #define VFAT_IOCTL_READDIR_SHORT32 _IOR('r', 2, struct compat_dirent[2])
1408 
1411 
1412 #ifdef CONFIG_SPARC
1413 /* Sparc framebuffers, handled in sbusfb_compat_ioctl() */
1426 #endif
1427 };
1428 
1429 /*
1430  * Convert common ioctl arguments based on their command number
1431  *
1432  * Please do not add any code in here. Instead, implement
1433  * a compat_ioctl operation in the place that handleŃ• the
1434  * ioctl for the native case.
1435  */
1436 static long do_ioctl_trans(int fd, unsigned int cmd,
1437  unsigned long arg, struct file *file)
1438 {
1439  void __user *argp = compat_ptr(arg);
1440 
1441  switch (cmd) {
1442  case PPPIOCGIDLE32:
1443  return ppp_gidle(fd, cmd, argp);
1444  case PPPIOCSCOMPRESS32:
1445  return ppp_scompress(fd, cmd, argp);
1446  case PPPIOCSPASS32:
1447  case PPPIOCSACTIVE32:
1448  return ppp_sock_fprog_ioctl_trans(fd, cmd, argp);
1449 #ifdef CONFIG_BLOCK
1450  case SG_IO:
1451  return sg_ioctl_trans(fd, cmd, argp);
1452  case SG_GET_REQUEST_TABLE:
1453  return sg_grt_trans(fd, cmd, argp);
1454  case MTIOCGET32:
1455  case MTIOCPOS32:
1456  return mt_ioctl_trans(fd, cmd, argp);
1457 #endif
1458  /* Serial */
1459  case TIOCGSERIAL:
1460  case TIOCSSERIAL:
1461  return serial_struct_ioctl(fd, cmd, argp);
1462  /* i2c */
1463  case I2C_FUNCS:
1464  return w_long(fd, cmd, argp);
1465  case I2C_RDWR:
1466  return do_i2c_rdwr_ioctl(fd, cmd, argp);
1467  case I2C_SMBUS:
1468  return do_i2c_smbus_ioctl(fd, cmd, argp);
1469  /* Not implemented in the native kernel */
1470  case RTC_IRQP_READ32:
1471  case RTC_IRQP_SET32:
1472  case RTC_EPOCH_READ32:
1473  case RTC_EPOCH_SET32:
1474  return rtc_ioctl(fd, cmd, argp);
1475 
1476  /* dvb */
1477  case VIDEO_GET_EVENT:
1478  return do_video_get_event(fd, cmd, argp);
1479  case VIDEO_STILLPICTURE:
1480  return do_video_stillpicture(fd, cmd, argp);
1481  case VIDEO_SET_SPU_PALETTE:
1482  return do_video_set_spu_palette(fd, cmd, argp);
1483  }
1484 
1485  /*
1486  * These take an integer instead of a pointer as 'arg',
1487  * so we must not do a compat_ptr() translation.
1488  */
1489  switch (cmd) {
1490  /* Big T */
1491  case TCSBRKP:
1492  case TIOCMIWAIT:
1493  case TIOCSCTTY:
1494  /* RAID */
1495  case HOT_REMOVE_DISK:
1496  case HOT_ADD_DISK:
1497  case SET_DISK_FAULTY:
1498  case SET_BITMAP_FILE:
1499  /* Big K */
1500  case KDSIGACCEPT:
1501  case KIOCSOUND:
1502  case KDMKTONE:
1503  case KDSETMODE:
1504  case KDSKBMODE:
1505  case KDSKBMETA:
1506  case KDSKBLED:
1507  case KDSETLED:
1508  /* NBD */
1509  case NBD_SET_SOCK:
1510  case NBD_SET_BLKSIZE:
1511  case NBD_SET_SIZE:
1512  case NBD_SET_SIZE_BLOCKS:
1513  return do_vfs_ioctl(file, fd, cmd, arg);
1514  }
1515 
1516  return -ENOIOCTLCMD;
1517 }
1518 
1519 static int compat_ioctl_check_table(unsigned int xcmd)
1520 {
1521  int i;
1522  const int max = ARRAY_SIZE(ioctl_pointer) - 1;
1523 
1524  BUILD_BUG_ON(max >= (1 << 16));
1525 
1526  /* guess initial offset into table, assuming a
1527  normalized distribution */
1528  i = ((xcmd >> 16) * max) >> 16;
1529 
1530  /* do linear search up first, until greater or equal */
1531  while (ioctl_pointer[i] < xcmd && i < max)
1532  i++;
1533 
1534  /* then do linear search down */
1535  while (ioctl_pointer[i] > xcmd && i > 0)
1536  i--;
1537 
1538  return ioctl_pointer[i] == xcmd;
1539 }
1540 
1541 asmlinkage long compat_sys_ioctl(unsigned int fd, unsigned int cmd,
1542  unsigned long arg)
1543 {
1544  struct fd f = fdget(fd);
1545  int error = -EBADF;
1546  if (!f.file)
1547  goto out;
1548 
1549  /* RED-PEN how should LSM module know it's handling 32bit? */
1550  error = security_file_ioctl(f.file, cmd, arg);
1551  if (error)
1552  goto out_fput;
1553 
1554  /*
1555  * To allow the compat_ioctl handlers to be self contained
1556  * we need to check the common ioctls here first.
1557  * Just handle them with the standard handlers below.
1558  */
1559  switch (cmd) {
1560  case FIOCLEX:
1561  case FIONCLEX:
1562  case FIONBIO:
1563  case FIOASYNC:
1564  case FIOQSIZE:
1565  break;
1566 
1567 #if defined(CONFIG_IA64) || defined(CONFIG_X86_64)
1568  case FS_IOC_RESVSP_32:
1569  case FS_IOC_RESVSP64_32:
1570  error = compat_ioctl_preallocate(f.file, compat_ptr(arg));
1571  goto out_fput;
1572 #else
1573  case FS_IOC_RESVSP:
1574  case FS_IOC_RESVSP64:
1575  error = ioctl_preallocate(f.file, compat_ptr(arg));
1576  goto out_fput;
1577 #endif
1578 
1579  case FIBMAP:
1580  case FIGETBSZ:
1581  case FIONREAD:
1582  if (S_ISREG(f.file->f_path.dentry->d_inode->i_mode))
1583  break;
1584  /*FALL THROUGH*/
1585 
1586  default:
1587  if (f.file->f_op && f.file->f_op->compat_ioctl) {
1588  error = f.file->f_op->compat_ioctl(f.file, cmd, arg);
1589  if (error != -ENOIOCTLCMD)
1590  goto out_fput;
1591  }
1592 
1593  if (!f.file->f_op || !f.file->f_op->unlocked_ioctl)
1594  goto do_ioctl;
1595  break;
1596  }
1597 
1598  if (compat_ioctl_check_table(XFORM(cmd)))
1599  goto found_handler;
1600 
1601  error = do_ioctl_trans(fd, cmd, arg, f.file);
1602  if (error == -ENOIOCTLCMD)
1603  error = -ENOTTY;
1604 
1605  goto out_fput;
1606 
1607  found_handler:
1608  arg = (unsigned long)compat_ptr(arg);
1609  do_ioctl:
1610  error = do_vfs_ioctl(f.file, fd, cmd, arg);
1611  out_fput:
1612  fdput(f);
1613  out:
1614  return error;
1615 }
1616 
1617 static int __init init_sys32_ioctl_cmp(const void *p, const void *q)
1618 {
1619  unsigned int a, b;
1620  a = *(unsigned int *)p;
1621  b = *(unsigned int *)q;
1622  if (a > b)
1623  return 1;
1624  if (a < b)
1625  return -1;
1626  return 0;
1627 }
1628 
1629 static int __init init_sys32_ioctl(void)
1630 {
1631  sort(ioctl_pointer, ARRAY_SIZE(ioctl_pointer), sizeof(*ioctl_pointer),
1632  init_sys32_ioctl_cmp, NULL);
1633  return 0;
1634 }
1635 __initcall(init_sys32_ioctl);