1
#include <linux/blkdev.h>
2
#include <linux/blkpg.h>
3
#include <linux/blktrace_api.h>
4
#include <linux/cdrom.h>
5
#include <linux/compat.h>
6
#include <linux/elevator.h>
8
#include <linux/hdreg.h>
9
#include <linux/slab.h>
10
#include <linux/syscalls.h>
11
#include <linux/types.h>
12
#include <linux/uaccess.h>
14
static int compat_put_ushort(unsigned long arg, unsigned short val)
16
return put_user(val, (unsigned short __user *)compat_ptr(arg));
19
static int compat_put_int(unsigned long arg, int val)
21
return put_user(val, (compat_int_t __user *)compat_ptr(arg));
24
static int compat_put_uint(unsigned long arg, unsigned int val)
26
return put_user(val, (compat_uint_t __user *)compat_ptr(arg));
29
static int compat_put_long(unsigned long arg, long val)
31
return put_user(val, (compat_long_t __user *)compat_ptr(arg));
34
static int compat_put_ulong(unsigned long arg, compat_ulong_t val)
36
return put_user(val, (compat_ulong_t __user *)compat_ptr(arg));
39
static int compat_put_u64(unsigned long arg, u64 val)
41
return put_user(val, (compat_u64 __user *)compat_ptr(arg));
44
struct compat_hd_geometry {
46
unsigned char sectors;
47
unsigned short cylinders;
51
static int compat_hdio_getgeo(struct gendisk *disk, struct block_device *bdev,
52
struct compat_hd_geometry __user *ugeo)
54
struct hd_geometry geo;
59
if (!disk->fops->getgeo)
63
* We need to set the startsect first, the driver may
64
* want to override it.
66
geo.start = get_start_sect(bdev);
67
ret = disk->fops->getgeo(bdev, &geo);
71
ret = copy_to_user(ugeo, &geo, 4);
72
ret |= __put_user(geo.start, &ugeo->start);
79
static int compat_hdio_ioctl(struct block_device *bdev, fmode_t mode,
80
unsigned int cmd, unsigned long arg)
82
mm_segment_t old_fs = get_fs();
84
unsigned int __user *uvp;
88
error = __blkdev_driver_ioctl(bdev, mode,
89
cmd, (unsigned long)(&kval));
93
uvp = compat_ptr(arg);
94
if (put_user(kval, uvp))
100
struct compat_cdrom_read_audio {
101
union cdrom_addr addr;
103
compat_int_t nframes;
107
struct compat_cdrom_generic_command {
108
unsigned char cmd[CDROM_PACKET_SIZE];
109
compat_caddr_t buffer;
110
compat_uint_t buflen;
112
compat_caddr_t sense;
113
unsigned char data_direction;
115
compat_int_t timeout;
116
compat_caddr_t reserved[1];
119
static int compat_cdrom_read_audio(struct block_device *bdev, fmode_t mode,
120
unsigned int cmd, unsigned long arg)
122
struct cdrom_read_audio __user *cdread_audio;
123
struct compat_cdrom_read_audio __user *cdread_audio32;
127
cdread_audio = compat_alloc_user_space(sizeof(*cdread_audio));
128
cdread_audio32 = compat_ptr(arg);
130
if (copy_in_user(&cdread_audio->addr,
131
&cdread_audio32->addr,
132
(sizeof(*cdread_audio32) -
133
sizeof(compat_caddr_t))))
136
if (get_user(data, &cdread_audio32->buf))
138
datap = compat_ptr(data);
139
if (put_user(datap, &cdread_audio->buf))
142
return __blkdev_driver_ioctl(bdev, mode, cmd,
143
(unsigned long)cdread_audio);
146
static int compat_cdrom_generic_command(struct block_device *bdev, fmode_t mode,
147
unsigned int cmd, unsigned long arg)
149
struct cdrom_generic_command __user *cgc;
150
struct compat_cdrom_generic_command __user *cgc32;
155
cgc = compat_alloc_user_space(sizeof(*cgc));
156
cgc32 = compat_ptr(arg);
158
if (copy_in_user(&cgc->cmd, &cgc32->cmd, sizeof(cgc->cmd)) ||
159
get_user(data, &cgc32->buffer) ||
160
put_user(compat_ptr(data), &cgc->buffer) ||
161
copy_in_user(&cgc->buflen, &cgc32->buflen,
162
(sizeof(unsigned int) + sizeof(int))) ||
163
get_user(data, &cgc32->sense) ||
164
put_user(compat_ptr(data), &cgc->sense) ||
165
get_user(dir, &cgc32->data_direction) ||
166
put_user(dir, &cgc->data_direction) ||
167
get_user(itmp, &cgc32->quiet) ||
168
put_user(itmp, &cgc->quiet) ||
169
get_user(itmp, &cgc32->timeout) ||
170
put_user(itmp, &cgc->timeout) ||
171
get_user(data, &cgc32->reserved[0]) ||
172
put_user(compat_ptr(data), &cgc->reserved[0]))
175
return __blkdev_driver_ioctl(bdev, mode, cmd, (unsigned long)cgc);
178
struct compat_blkpg_ioctl_arg {
181
compat_int_t datalen;
185
static int compat_blkpg_ioctl(struct block_device *bdev, fmode_t mode,
186
unsigned int cmd, struct compat_blkpg_ioctl_arg __user *ua32)
188
struct blkpg_ioctl_arg __user *a = compat_alloc_user_space(sizeof(*a));
189
compat_caddr_t udata;
193
err = get_user(n, &ua32->op);
194
err |= put_user(n, &a->op);
195
err |= get_user(n, &ua32->flags);
196
err |= put_user(n, &a->flags);
197
err |= get_user(n, &ua32->datalen);
198
err |= put_user(n, &a->datalen);
199
err |= get_user(udata, &ua32->data);
200
err |= put_user(compat_ptr(udata), &a->data);
204
return blkdev_ioctl(bdev, mode, cmd, (unsigned long)a);
207
#define BLKBSZGET_32 _IOR(0x12, 112, int)
208
#define BLKBSZSET_32 _IOW(0x12, 113, int)
209
#define BLKGETSIZE64_32 _IOR(0x12, 114, int)
211
struct compat_floppy_drive_params {
213
compat_ulong_t max_dtr;
217
compat_ulong_t spinup;
218
compat_ulong_t spindown;
219
unsigned char spindown_offset;
220
unsigned char select_delay;
222
unsigned char tracks;
223
compat_ulong_t timeout;
224
unsigned char interleave_sect;
225
struct floppy_max_errors max_errors;
229
compat_int_t checkfreq;
230
compat_int_t native_format;
233
struct compat_floppy_drive_struct {
235
compat_ulong_t spinup_date;
236
compat_ulong_t select_date;
237
compat_ulong_t first_read_date;
242
compat_int_t generation;
243
compat_int_t keep_data;
245
compat_int_t fd_device;
246
compat_int_t last_checked;
247
compat_caddr_t dmabuf;
248
compat_int_t bufblocks;
251
struct compat_floppy_fdc_state {
255
unsigned char version;
257
compat_ulong_t address;
258
unsigned int rawcmd:2;
259
unsigned int reset:1;
260
unsigned int need_configure:1;
261
unsigned int perp_mode:2;
262
unsigned int has_fifo:1;
263
unsigned int driver_version;
264
unsigned char track[4];
267
struct compat_floppy_write_errors {
268
unsigned int write_errors;
269
compat_ulong_t first_error_sector;
270
compat_int_t first_error_generation;
271
compat_ulong_t last_error_sector;
272
compat_int_t last_error_generation;
273
compat_uint_t badness;
276
#define FDSETPRM32 _IOW(2, 0x42, struct compat_floppy_struct)
277
#define FDDEFPRM32 _IOW(2, 0x43, struct compat_floppy_struct)
278
#define FDSETDRVPRM32 _IOW(2, 0x90, struct compat_floppy_drive_params)
279
#define FDGETDRVPRM32 _IOR(2, 0x11, struct compat_floppy_drive_params)
280
#define FDGETDRVSTAT32 _IOR(2, 0x12, struct compat_floppy_drive_struct)
281
#define FDPOLLDRVSTAT32 _IOR(2, 0x13, struct compat_floppy_drive_struct)
282
#define FDGETFDCSTAT32 _IOR(2, 0x15, struct compat_floppy_fdc_state)
283
#define FDWERRORGET32 _IOR(2, 0x17, struct compat_floppy_write_errors)
288
} fd_ioctl_trans_table[] = {
289
{ FDSETPRM32, FDSETPRM },
290
{ FDDEFPRM32, FDDEFPRM },
291
{ FDGETPRM32, FDGETPRM },
292
{ FDSETDRVPRM32, FDSETDRVPRM },
293
{ FDGETDRVPRM32, FDGETDRVPRM },
294
{ FDGETDRVSTAT32, FDGETDRVSTAT },
295
{ FDPOLLDRVSTAT32, FDPOLLDRVSTAT },
296
{ FDGETFDCSTAT32, FDGETFDCSTAT },
297
{ FDWERRORGET32, FDWERRORGET }
300
#define NR_FD_IOCTL_TRANS ARRAY_SIZE(fd_ioctl_trans_table)
302
static int compat_fd_ioctl(struct block_device *bdev, fmode_t mode,
303
unsigned int cmd, unsigned long arg)
305
mm_segment_t old_fs = get_fs();
307
unsigned int kcmd = 0;
310
for (i = 0; i < NR_FD_IOCTL_TRANS; i++)
311
if (cmd == fd_ioctl_trans_table[i].cmd32) {
312
kcmd = fd_ioctl_trans_table[i].cmd;
324
struct compat_floppy_struct __user *uf;
325
struct floppy_struct *f;
327
uf = compat_ptr(arg);
328
f = karg = kmalloc(sizeof(struct floppy_struct), GFP_KERNEL);
331
if (cmd == FDGETPRM32)
333
err = __get_user(f->size, &uf->size);
334
err |= __get_user(f->sect, &uf->sect);
335
err |= __get_user(f->head, &uf->head);
336
err |= __get_user(f->track, &uf->track);
337
err |= __get_user(f->stretch, &uf->stretch);
338
err |= __get_user(f->gap, &uf->gap);
339
err |= __get_user(f->rate, &uf->rate);
340
err |= __get_user(f->spec1, &uf->spec1);
341
err |= __get_user(f->fmt_gap, &uf->fmt_gap);
342
err |= __get_user(name, &uf->name);
343
f->name = compat_ptr(name);
353
struct compat_floppy_drive_params __user *uf;
354
struct floppy_drive_params *f;
356
uf = compat_ptr(arg);
357
f = karg = kmalloc(sizeof(struct floppy_drive_params), GFP_KERNEL);
360
if (cmd == FDGETDRVPRM32)
362
err = __get_user(f->cmos, &uf->cmos);
363
err |= __get_user(f->max_dtr, &uf->max_dtr);
364
err |= __get_user(f->hlt, &uf->hlt);
365
err |= __get_user(f->hut, &uf->hut);
366
err |= __get_user(f->srt, &uf->srt);
367
err |= __get_user(f->spinup, &uf->spinup);
368
err |= __get_user(f->spindown, &uf->spindown);
369
err |= __get_user(f->spindown_offset, &uf->spindown_offset);
370
err |= __get_user(f->select_delay, &uf->select_delay);
371
err |= __get_user(f->rps, &uf->rps);
372
err |= __get_user(f->tracks, &uf->tracks);
373
err |= __get_user(f->timeout, &uf->timeout);
374
err |= __get_user(f->interleave_sect, &uf->interleave_sect);
375
err |= __copy_from_user(&f->max_errors, &uf->max_errors, sizeof(f->max_errors));
376
err |= __get_user(f->flags, &uf->flags);
377
err |= __get_user(f->read_track, &uf->read_track);
378
err |= __copy_from_user(f->autodetect, uf->autodetect, sizeof(f->autodetect));
379
err |= __get_user(f->checkfreq, &uf->checkfreq);
380
err |= __get_user(f->native_format, &uf->native_format);
388
case FDPOLLDRVSTAT32:
389
karg = kmalloc(sizeof(struct floppy_drive_struct), GFP_KERNEL);
394
karg = kmalloc(sizeof(struct floppy_fdc_state), GFP_KERNEL);
399
karg = kmalloc(sizeof(struct floppy_write_errors), GFP_KERNEL);
407
err = __blkdev_driver_ioctl(bdev, mode, kcmd, (unsigned long)karg);
414
struct floppy_struct *f = karg;
415
struct compat_floppy_struct __user *uf = compat_ptr(arg);
417
err = __put_user(f->size, &uf->size);
418
err |= __put_user(f->sect, &uf->sect);
419
err |= __put_user(f->head, &uf->head);
420
err |= __put_user(f->track, &uf->track);
421
err |= __put_user(f->stretch, &uf->stretch);
422
err |= __put_user(f->gap, &uf->gap);
423
err |= __put_user(f->rate, &uf->rate);
424
err |= __put_user(f->spec1, &uf->spec1);
425
err |= __put_user(f->fmt_gap, &uf->fmt_gap);
426
err |= __put_user((u64)f->name, (compat_caddr_t __user *)&uf->name);
431
struct compat_floppy_drive_params __user *uf;
432
struct floppy_drive_params *f = karg;
434
uf = compat_ptr(arg);
435
err = __put_user(f->cmos, &uf->cmos);
436
err |= __put_user(f->max_dtr, &uf->max_dtr);
437
err |= __put_user(f->hlt, &uf->hlt);
438
err |= __put_user(f->hut, &uf->hut);
439
err |= __put_user(f->srt, &uf->srt);
440
err |= __put_user(f->spinup, &uf->spinup);
441
err |= __put_user(f->spindown, &uf->spindown);
442
err |= __put_user(f->spindown_offset, &uf->spindown_offset);
443
err |= __put_user(f->select_delay, &uf->select_delay);
444
err |= __put_user(f->rps, &uf->rps);
445
err |= __put_user(f->tracks, &uf->tracks);
446
err |= __put_user(f->timeout, &uf->timeout);
447
err |= __put_user(f->interleave_sect, &uf->interleave_sect);
448
err |= __copy_to_user(&uf->max_errors, &f->max_errors, sizeof(f->max_errors));
449
err |= __put_user(f->flags, &uf->flags);
450
err |= __put_user(f->read_track, &uf->read_track);
451
err |= __copy_to_user(uf->autodetect, f->autodetect, sizeof(f->autodetect));
452
err |= __put_user(f->checkfreq, &uf->checkfreq);
453
err |= __put_user(f->native_format, &uf->native_format);
457
case FDPOLLDRVSTAT32:
459
struct compat_floppy_drive_struct __user *uf;
460
struct floppy_drive_struct *f = karg;
462
uf = compat_ptr(arg);
463
err = __put_user(f->flags, &uf->flags);
464
err |= __put_user(f->spinup_date, &uf->spinup_date);
465
err |= __put_user(f->select_date, &uf->select_date);
466
err |= __put_user(f->first_read_date, &uf->first_read_date);
467
err |= __put_user(f->probed_format, &uf->probed_format);
468
err |= __put_user(f->track, &uf->track);
469
err |= __put_user(f->maxblock, &uf->maxblock);
470
err |= __put_user(f->maxtrack, &uf->maxtrack);
471
err |= __put_user(f->generation, &uf->generation);
472
err |= __put_user(f->keep_data, &uf->keep_data);
473
err |= __put_user(f->fd_ref, &uf->fd_ref);
474
err |= __put_user(f->fd_device, &uf->fd_device);
475
err |= __put_user(f->last_checked, &uf->last_checked);
476
err |= __put_user((u64)f->dmabuf, &uf->dmabuf);
477
err |= __put_user((u64)f->bufblocks, &uf->bufblocks);
482
struct compat_floppy_fdc_state __user *uf;
483
struct floppy_fdc_state *f = karg;
485
uf = compat_ptr(arg);
486
err = __put_user(f->spec1, &uf->spec1);
487
err |= __put_user(f->spec2, &uf->spec2);
488
err |= __put_user(f->dtr, &uf->dtr);
489
err |= __put_user(f->version, &uf->version);
490
err |= __put_user(f->dor, &uf->dor);
491
err |= __put_user(f->address, &uf->address);
492
err |= __copy_to_user((char __user *)&uf->address + sizeof(uf->address),
493
(char *)&f->address + sizeof(f->address), sizeof(int));
494
err |= __put_user(f->driver_version, &uf->driver_version);
495
err |= __copy_to_user(uf->track, f->track, sizeof(f->track));
500
struct compat_floppy_write_errors __user *uf;
501
struct floppy_write_errors *f = karg;
503
uf = compat_ptr(arg);
504
err = __put_user(f->write_errors, &uf->write_errors);
505
err |= __put_user(f->first_error_sector, &uf->first_error_sector);
506
err |= __put_user(f->first_error_generation, &uf->first_error_generation);
507
err |= __put_user(f->last_error_sector, &uf->last_error_sector);
508
err |= __put_user(f->last_error_generation, &uf->last_error_generation);
509
err |= __put_user(f->badness, &uf->badness);
523
static int compat_blkdev_driver_ioctl(struct block_device *bdev, fmode_t mode,
524
unsigned cmd, unsigned long arg)
527
case HDIO_GET_UNMASKINTR:
528
case HDIO_GET_MULTCOUNT:
529
case HDIO_GET_KEEPSETTINGS:
531
case HDIO_GET_NOWERR:
534
case HDIO_GET_WCACHE:
535
case HDIO_GET_ACOUSTIC:
536
case HDIO_GET_ADDRESS:
537
case HDIO_GET_BUSSTATE:
538
return compat_hdio_ioctl(bdev, mode, cmd, arg);
545
case FDPOLLDRVSTAT32:
548
return compat_fd_ioctl(bdev, mode, cmd, arg);
550
return compat_cdrom_read_audio(bdev, mode, cmd, arg);
551
case CDROM_SEND_PACKET:
552
return compat_cdrom_generic_command(bdev, mode, cmd, arg);
555
* No handler required for the ones below, we just need to
556
* convert arg to a 64 bit pointer.
560
* 0x03 -- HD/IDE ioctl's used by hdparm and friends.
561
* Some need translations, these do not.
563
case HDIO_GET_IDENTITY:
564
case HDIO_DRIVE_TASK:
566
/* 0x330 is reserved -- it used to be HDIO_GETGEO_BIG */
568
/* 0x02 -- Floppy ioctls */
589
case CDROMPLAYTRKIND:
590
case CDROMREADTOCHDR:
591
case CDROMREADTOCENTRY:
597
case CDROMMULTISESSION:
604
case CDROM_DISC_STATUS:
605
case CDROM_CHANGER_NSLOTS:
606
case CDROM_GET_CAPABILITY:
607
/* Ignore cdrom.h about these next 5 ioctls, they absolutely do
608
* not take a struct cdrom_read, instead they take a struct cdrom_msf
609
* which is compatible.
614
case CDROMREADCOOKED:
617
case DVD_READ_STRUCT:
618
case DVD_WRITE_STRUCT:
620
arg = (unsigned long)compat_ptr(arg);
621
/* These intepret arg as an unsigned long, not as a pointer,
622
* so we must not do compat_ptr() conversion. */
623
case HDIO_SET_MULTCOUNT:
624
case HDIO_SET_UNMASKINTR:
625
case HDIO_SET_KEEPSETTINGS:
627
case HDIO_SET_NOWERR:
629
case HDIO_SET_PIO_MODE:
631
case HDIO_SET_WCACHE:
632
case HDIO_SET_ACOUSTIC:
633
case HDIO_SET_BUSSTATE:
634
case HDIO_SET_ADDRESS:
636
case CDROM_SET_OPTIONS:
637
case CDROM_CLEAR_OPTIONS:
638
case CDROM_SELECT_SPEED:
639
case CDROM_SELECT_DISC:
640
case CDROM_MEDIA_CHANGED:
641
case CDROM_DRIVE_STATUS:
646
/* unknown ioctl number */
650
return __blkdev_driver_ioctl(bdev, mode, cmd, arg);
653
/* Most of the generic ioctls are handled in the normal fallback path.
654
This assumes the blkdev's low level compat_ioctl always returns
655
ENOIOCTLCMD for unknown ioctls. */
656
long compat_blkdev_ioctl(struct file *file, unsigned cmd, unsigned long arg)
658
int ret = -ENOIOCTLCMD;
659
struct inode *inode = file->f_mapping->host;
660
struct block_device *bdev = inode->i_bdev;
661
struct gendisk *disk = bdev->bd_disk;
662
fmode_t mode = file->f_mode;
663
struct backing_dev_info *bdi;
667
* O_NDELAY can be altered using fcntl(.., F_SETFL, ..), so we have
668
* to updated it before every ioctl.
670
if (file->f_flags & O_NDELAY)
671
mode |= FMODE_NDELAY;
673
mode &= ~FMODE_NDELAY;
677
return compat_hdio_getgeo(disk, bdev, compat_ptr(arg));
679
return compat_put_uint(arg, bdev_physical_block_size(bdev));
681
return compat_put_uint(arg, bdev_io_min(bdev));
683
return compat_put_uint(arg, bdev_io_opt(bdev));
685
return compat_put_int(arg, bdev_alignment_offset(bdev));
686
case BLKDISCARDZEROES:
687
return compat_put_uint(arg, bdev_discard_zeroes_data(bdev));
693
* the ones below are implemented in blkdev_locked_ioctl,
694
* but we call blkdev_ioctl, which gets the lock for us
697
return blkdev_ioctl(bdev, mode, cmd,
698
(unsigned long)compat_ptr(arg));
700
return blkdev_ioctl(bdev, mode, BLKBSZSET,
701
(unsigned long)compat_ptr(arg));
703
return compat_blkpg_ioctl(bdev, mode, cmd, compat_ptr(arg));
708
bdi = blk_get_backing_dev_info(bdev);
711
return compat_put_long(arg,
712
(bdi->ra_pages * PAGE_CACHE_SIZE) / 512);
713
case BLKROGET: /* compatible */
714
return compat_put_int(arg, bdev_read_only(bdev) != 0);
715
case BLKBSZGET_32: /* get the logical block size (cf. BLKSSZGET) */
716
return compat_put_int(arg, block_size(bdev));
717
case BLKSSZGET: /* get block device hardware sector size */
718
return compat_put_int(arg, bdev_logical_block_size(bdev));
720
return compat_put_ushort(arg,
721
queue_max_sectors(bdev_get_queue(bdev)));
722
case BLKRASET: /* compatible, but no compat_ptr (!) */
724
if (!capable(CAP_SYS_ADMIN))
726
bdi = blk_get_backing_dev_info(bdev);
729
bdi->ra_pages = (arg * 512) / PAGE_CACHE_SIZE;
732
size = i_size_read(bdev->bd_inode);
733
if ((size >> 9) > ~0UL)
735
return compat_put_ulong(arg, size >> 9);
737
case BLKGETSIZE64_32:
738
return compat_put_u64(arg, i_size_read(bdev->bd_inode));
740
case BLKTRACESETUP32:
741
case BLKTRACESTART: /* compatible */
742
case BLKTRACESTOP: /* compatible */
743
case BLKTRACETEARDOWN: /* compatible */
744
ret = blk_trace_ioctl(bdev, cmd, compat_ptr(arg));
747
if (disk->fops->compat_ioctl)
748
ret = disk->fops->compat_ioctl(bdev, mode, cmd, arg);
749
if (ret == -ENOIOCTLCMD)
750
ret = compat_blkdev_driver_ioctl(bdev, mode, cmd, arg);