]> git.ipfire.org Git - thirdparty/linux.git/blame - net/compat.c
nexthops: don't modify published nexthop groups
[thirdparty/linux.git] / net / compat.c
CommitLineData
457c8996 1// SPDX-License-Identifier: GPL-2.0-only
4768fbcb 2/*
1da177e4
LT
3 * 32bit Socket syscall emulation. Based on arch/sparc64/kernel/sys_sparc32.c.
4 *
5 * Copyright (C) 2000 VA Linux Co
6 * Copyright (C) 2000 Don Dugger <n0ano@valinux.com>
7 * Copyright (C) 1999 Arun Sharma <arun.sharma@intel.com>
8 * Copyright (C) 1997,1998 Jakub Jelinek (jj@sunsite.mff.cuni.cz)
9 * Copyright (C) 1997 David S. Miller (davem@caip.rutgers.edu)
10 * Copyright (C) 2000 Hewlett-Packard Co.
11 * Copyright (C) 2000 David Mosberger-Tang <davidm@hpl.hp.com>
4768fbcb 12 * Copyright (C) 2000,2001 Andi Kleen, SuSE Labs
1da177e4
LT
13 */
14
15#include <linux/kernel.h>
5a0e3ad6 16#include <linux/gfp.h>
1da177e4 17#include <linux/fs.h>
1da177e4
LT
18#include <linux/types.h>
19#include <linux/file.h>
20#include <linux/icmpv6.h>
21#include <linux/socket.h>
22#include <linux/syscalls.h>
23#include <linux/filter.h>
24#include <linux/compat.h>
1da177e4 25#include <linux/security.h>
62bc306e 26#include <linux/audit.h>
bc3b2d7f 27#include <linux/export.h>
1da177e4
LT
28
29#include <net/scm.h>
30#include <net/sock.h>
dae50295
DS
31#include <net/ip.h>
32#include <net/ipv6.h>
7c0f6ba6 33#include <linux/uaccess.h>
1da177e4
LT
34#include <net/compat.h>
35
0a384abf
JA
36int __get_compat_msghdr(struct msghdr *kmsg,
37 struct compat_msghdr __user *umsg,
38 struct sockaddr __user **save_addr,
39 compat_uptr_t *ptr, compat_size_t *len)
1da177e4 40{
5da028a8 41 struct compat_msghdr msg;
08adb7da 42 ssize_t err;
1da177e4 43
5da028a8 44 if (copy_from_user(&msg, umsg, sizeof(*umsg)))
1da177e4 45 return -EFAULT;
91edd096 46
5da028a8
AV
47 kmsg->msg_flags = msg.msg_flags;
48 kmsg->msg_namelen = msg.msg_namelen;
49
50 if (!msg.msg_name)
91edd096
CM
51 kmsg->msg_namelen = 0;
52
53 if (kmsg->msg_namelen < 0)
54 return -EINVAL;
55
1661bf36 56 if (kmsg->msg_namelen > sizeof(struct sockaddr_storage))
db31c55a 57 kmsg->msg_namelen = sizeof(struct sockaddr_storage);
5da028a8
AV
58
59 kmsg->msg_control = compat_ptr(msg.msg_control);
60 kmsg->msg_controllen = msg.msg_controllen;
1da177e4 61
08adb7da 62 if (save_addr)
5da028a8 63 *save_addr = compat_ptr(msg.msg_name);
1da177e4 64
5da028a8 65 if (msg.msg_name && kmsg->msg_namelen) {
08adb7da 66 if (!save_addr) {
5da028a8 67 err = move_addr_to_kernel(compat_ptr(msg.msg_name),
08adb7da
AV
68 kmsg->msg_namelen,
69 kmsg->msg_name);
e71a4783 70 if (err < 0)
1da177e4
LT
71 return err;
72 }
40eea803 73 } else {
08adb7da
AV
74 kmsg->msg_name = NULL;
75 kmsg->msg_namelen = 0;
40eea803 76 }
1da177e4 77
5da028a8 78 if (msg.msg_iovlen > UIO_MAXIOV)
08449320
AV
79 return -EMSGSIZE;
80
0345f931 81 kmsg->msg_iocb = NULL;
0a384abf
JA
82 *ptr = msg.msg_iov;
83 *len = msg.msg_iovlen;
84 return 0;
85}
86
87int get_compat_msghdr(struct msghdr *kmsg,
88 struct compat_msghdr __user *umsg,
89 struct sockaddr __user **save_addr,
90 struct iovec **iov)
91{
92 compat_uptr_t ptr;
93 compat_size_t len;
94 ssize_t err;
95
96 err = __get_compat_msghdr(kmsg, umsg, save_addr, &ptr, &len);
97 if (err)
98 return err;
0345f931 99
0a384abf
JA
100 err = compat_import_iovec(save_addr ? READ : WRITE, compat_ptr(ptr),
101 len, UIO_FASTIOV, iov, &kmsg->msg_iter);
87e5e6da 102 return err < 0 ? err : 0;
1da177e4
LT
103}
104
105/* Bleech... */
106#define CMSG_COMPAT_ALIGN(len) ALIGN((len), sizeof(s32))
107
108#define CMSG_COMPAT_DATA(cmsg) \
1ff8cebf 109 ((void __user *)((char __user *)(cmsg) + sizeof(struct compat_cmsghdr)))
1da177e4 110#define CMSG_COMPAT_SPACE(len) \
1ff8cebf 111 (sizeof(struct compat_cmsghdr) + CMSG_COMPAT_ALIGN(len))
1da177e4 112#define CMSG_COMPAT_LEN(len) \
1ff8cebf 113 (sizeof(struct compat_cmsghdr) + (len))
1da177e4
LT
114
115#define CMSG_COMPAT_FIRSTHDR(msg) \
116 (((msg)->msg_controllen) >= sizeof(struct compat_cmsghdr) ? \
117 (struct compat_cmsghdr __user *)((msg)->msg_control) : \
118 (struct compat_cmsghdr __user *)NULL)
119
120#define CMSG_COMPAT_OK(ucmlen, ucmsg, mhdr) \
121 ((ucmlen) >= sizeof(struct compat_cmsghdr) && \
122 (ucmlen) <= (unsigned long) \
123 ((mhdr)->msg_controllen - \
124 ((char *)(ucmsg) - (char *)(mhdr)->msg_control)))
125
126static inline struct compat_cmsghdr __user *cmsg_compat_nxthdr(struct msghdr *msg,
127 struct compat_cmsghdr __user *cmsg, int cmsg_len)
128{
129 char __user *ptr = (char __user *)cmsg + CMSG_COMPAT_ALIGN(cmsg_len);
130 if ((unsigned long)(ptr + 1 - (char __user *)msg->msg_control) >
131 msg->msg_controllen)
132 return NULL;
133 return (struct compat_cmsghdr __user *)ptr;
134}
135
136/* There is a lot of hair here because the alignment rules (and
137 * thus placement) of cmsg headers and length are different for
138 * 32-bit apps. -DaveM
139 */
8920e8f9 140int cmsghdr_from_user_compat_to_kern(struct msghdr *kmsg, struct sock *sk,
1da177e4
LT
141 unsigned char *stackbuf, int stackbuf_size)
142{
143 struct compat_cmsghdr __user *ucmsg;
144 struct cmsghdr *kcmsg, *kcmsg_base;
145 compat_size_t ucmlen;
146 __kernel_size_t kcmlen, tmp;
8920e8f9 147 int err = -EFAULT;
1da177e4 148
ac4340fc
DM
149 BUILD_BUG_ON(sizeof(struct compat_cmsghdr) !=
150 CMSG_COMPAT_ALIGN(sizeof(struct compat_cmsghdr)));
151
1da177e4
LT
152 kcmlen = 0;
153 kcmsg_base = kcmsg = (struct cmsghdr *)stackbuf;
154 ucmsg = CMSG_COMPAT_FIRSTHDR(kmsg);
e71a4783
SH
155 while (ucmsg != NULL) {
156 if (get_user(ucmlen, &ucmsg->cmsg_len))
1da177e4
LT
157 return -EFAULT;
158
159 /* Catch bogons. */
160 if (!CMSG_COMPAT_OK(ucmlen, ucmsg, kmsg))
161 return -EINVAL;
162
1ff8cebf 163 tmp = ((ucmlen - sizeof(*ucmsg)) + sizeof(struct cmsghdr));
8920e8f9 164 tmp = CMSG_ALIGN(tmp);
1da177e4
LT
165 kcmlen += tmp;
166 ucmsg = cmsg_compat_nxthdr(kmsg, ucmsg, ucmlen);
167 }
e71a4783 168 if (kcmlen == 0)
1da177e4
LT
169 return -EINVAL;
170
171 /* The kcmlen holds the 64-bit version of the control length.
172 * It may not be modified as we do not stick it into the kmsg
173 * until we have successfully copied over all of the data
174 * from the user.
175 */
8920e8f9
AV
176 if (kcmlen > stackbuf_size)
177 kcmsg_base = kcmsg = sock_kmalloc(sk, kcmlen, GFP_KERNEL);
178 if (kcmsg == NULL)
1da177e4
LT
179 return -ENOBUFS;
180
181 /* Now copy them over neatly. */
182 memset(kcmsg, 0, kcmlen);
183 ucmsg = CMSG_COMPAT_FIRSTHDR(kmsg);
e71a4783 184 while (ucmsg != NULL) {
8920e8f9
AV
185 if (__get_user(ucmlen, &ucmsg->cmsg_len))
186 goto Efault;
187 if (!CMSG_COMPAT_OK(ucmlen, ucmsg, kmsg))
188 goto Einval;
1ff8cebf 189 tmp = ((ucmlen - sizeof(*ucmsg)) + sizeof(struct cmsghdr));
8920e8f9
AV
190 if ((char *)kcmsg_base + kcmlen - (char *)kcmsg < CMSG_ALIGN(tmp))
191 goto Einval;
1da177e4 192 kcmsg->cmsg_len = tmp;
8920e8f9
AV
193 tmp = CMSG_ALIGN(tmp);
194 if (__get_user(kcmsg->cmsg_level, &ucmsg->cmsg_level) ||
195 __get_user(kcmsg->cmsg_type, &ucmsg->cmsg_type) ||
196 copy_from_user(CMSG_DATA(kcmsg),
197 CMSG_COMPAT_DATA(ucmsg),
1ff8cebf 198 (ucmlen - sizeof(*ucmsg))))
8920e8f9 199 goto Efault;
1da177e4
LT
200
201 /* Advance. */
8920e8f9 202 kcmsg = (struct cmsghdr *)((char *)kcmsg + tmp);
1da177e4
LT
203 ucmsg = cmsg_compat_nxthdr(kmsg, ucmsg, ucmlen);
204 }
205
c2a64bb9
MX
206 /*
207 * check the length of messages copied in is the same as the
208 * what we get from the first loop
209 */
210 if ((char *)kcmsg - (char *)kcmsg_base != kcmlen)
211 goto Einval;
212
1da177e4
LT
213 /* Ok, looks like we made it. Hook it up and return success. */
214 kmsg->msg_control = kcmsg_base;
215 kmsg->msg_controllen = kcmlen;
216 return 0;
217
8920e8f9
AV
218Einval:
219 err = -EINVAL;
220Efault:
221 if (kcmsg_base != (struct cmsghdr *)stackbuf)
222 sock_kfree_s(sk, kcmsg_base, kcmlen);
223 return err;
1da177e4
LT
224}
225
226int put_cmsg_compat(struct msghdr *kmsg, int level, int type, int len, void *data)
227{
1da177e4
LT
228 struct compat_cmsghdr __user *cm = (struct compat_cmsghdr __user *) kmsg->msg_control;
229 struct compat_cmsghdr cmhdr;
13c6ee2a
DD
230 struct old_timeval32 ctv;
231 struct old_timespec32 cts[3];
1da177e4
LT
232 int cmlen;
233
e71a4783 234 if (cm == NULL || kmsg->msg_controllen < sizeof(*cm)) {
1da177e4
LT
235 kmsg->msg_flags |= MSG_CTRUNC;
236 return 0; /* XXX: return error? check spec. */
237 }
238
ee4fa23c 239 if (!COMPAT_USE_64BIT_TIME) {
7f1bc6e9 240 if (level == SOL_SOCKET && type == SO_TIMESTAMP_OLD) {
13c6ee2a 241 struct __kernel_old_timeval *tv = (struct __kernel_old_timeval *)data;
ee4fa23c
L
242 ctv.tv_sec = tv->tv_sec;
243 ctv.tv_usec = tv->tv_usec;
244 data = &ctv;
245 len = sizeof(ctv);
246 }
247 if (level == SOL_SOCKET &&
7f1bc6e9
DD
248 (type == SO_TIMESTAMPNS_OLD || type == SO_TIMESTAMPING_OLD)) {
249 int count = type == SO_TIMESTAMPNS_OLD ? 1 : 3;
ee4fa23c 250 int i;
df1b4ba9 251 struct __kernel_old_timespec *ts = data;
ee4fa23c
L
252 for (i = 0; i < count; i++) {
253 cts[i].tv_sec = ts[i].tv_sec;
254 cts[i].tv_nsec = ts[i].tv_nsec;
255 }
256 data = &cts;
257 len = sizeof(cts[0]) * count;
20d49473 258 }
4768fbcb
YH
259 }
260
1da177e4 261 cmlen = CMSG_COMPAT_LEN(len);
e71a4783 262 if (kmsg->msg_controllen < cmlen) {
1da177e4
LT
263 kmsg->msg_flags |= MSG_CTRUNC;
264 cmlen = kmsg->msg_controllen;
265 }
266 cmhdr.cmsg_level = level;
267 cmhdr.cmsg_type = type;
268 cmhdr.cmsg_len = cmlen;
269
e71a4783 270 if (copy_to_user(cm, &cmhdr, sizeof cmhdr))
1da177e4 271 return -EFAULT;
e71a4783 272 if (copy_to_user(CMSG_COMPAT_DATA(cm), data, cmlen - sizeof(struct compat_cmsghdr)))
1da177e4
LT
273 return -EFAULT;
274 cmlen = CMSG_COMPAT_SPACE(len);
1ac70e7a
WY
275 if (kmsg->msg_controllen < cmlen)
276 cmlen = kmsg->msg_controllen;
1da177e4
LT
277 kmsg->msg_control += cmlen;
278 kmsg->msg_controllen -= cmlen;
279 return 0;
280}
281
282void scm_detach_fds_compat(struct msghdr *kmsg, struct scm_cookie *scm)
283{
284 struct compat_cmsghdr __user *cm = (struct compat_cmsghdr __user *) kmsg->msg_control;
285 int fdmax = (kmsg->msg_controllen - sizeof(struct compat_cmsghdr)) / sizeof(int);
286 int fdnum = scm->fp->count;
287 struct file **fp = scm->fp->fp;
288 int __user *cmfptr;
289 int err = 0, i;
290
291 if (fdnum < fdmax)
292 fdmax = fdnum;
293
294 for (i = 0, cmfptr = (int __user *) CMSG_COMPAT_DATA(cm); i < fdmax; i++, cmfptr++) {
295 int new_fd;
296 err = security_file_receive(fp[i]);
297 if (err)
298 break;
4a19542e
UD
299 err = get_unused_fd_flags(MSG_CMSG_CLOEXEC & kmsg->msg_flags
300 ? O_CLOEXEC : 0);
1da177e4
LT
301 if (err < 0)
302 break;
303 new_fd = err;
304 err = put_user(new_fd, cmfptr);
305 if (err) {
306 put_unused_fd(new_fd);
307 break;
308 }
309 /* Bump the usage count and install the file. */
cb0942b8 310 fd_install(new_fd, get_file(fp[i]));
1da177e4
LT
311 }
312
313 if (i > 0) {
314 int cmlen = CMSG_COMPAT_LEN(i * sizeof(int));
effee6a0 315 err = put_user(SOL_SOCKET, &cm->cmsg_level);
1da177e4
LT
316 if (!err)
317 err = put_user(SCM_RIGHTS, &cm->cmsg_type);
318 if (!err)
319 err = put_user(cmlen, &cm->cmsg_len);
320 if (!err) {
321 cmlen = CMSG_COMPAT_SPACE(i * sizeof(int));
322 kmsg->msg_control += cmlen;
323 kmsg->msg_controllen -= cmlen;
324 }
325 }
326 if (i < fdnum)
327 kmsg->msg_flags |= MSG_CTRUNC;
328
329 /*
330 * All of the files that fit in the message have had their
331 * usage counts incremented, so we just free the list.
332 */
333 __scm_destroy(scm);
334}
335
719c44d3
WB
336/* allocate a 64-bit sock_fprog on the user stack for duration of syscall. */
337struct sock_fprog __user *get_compat_bpf_fprog(char __user *optval)
1da177e4
LT
338{
339 struct compat_sock_fprog __user *fprog32 = (struct compat_sock_fprog __user *)optval;
4768fbcb 340 struct sock_fprog __user *kfprog = compat_alloc_user_space(sizeof(struct sock_fprog));
f8f8a727
AV
341 struct compat_sock_fprog f32;
342 struct sock_fprog f;
343
344 if (copy_from_user(&f32, fprog32, sizeof(*fprog32)))
345 return NULL;
346 memset(&f, 0, sizeof(f));
347 f.len = f32.len;
348 f.filter = compat_ptr(f32.filter);
349 if (copy_to_user(kfprog, &f, sizeof(struct sock_fprog)))
719c44d3
WB
350 return NULL;
351
352 return kfprog;
353}
354EXPORT_SYMBOL_GPL(get_compat_bpf_fprog);
355
356static int do_set_attach_filter(struct socket *sock, int level, int optname,
357 char __user *optval, unsigned int optlen)
358{
359 struct sock_fprog __user *kfprog;
360
361 kfprog = get_compat_bpf_fprog(optval);
362 if (!kfprog)
1da177e4
LT
363 return -EFAULT;
364
3fdadf7d 365 return sock_setsockopt(sock, level, optname, (char __user *)kfprog,
1da177e4
LT
366 sizeof(struct sock_fprog));
367}
368
3fdadf7d 369static int compat_sock_setsockopt(struct socket *sock, int level, int optname,
b7058842 370 char __user *optval, unsigned int optlen)
3fdadf7d 371{
19575988
HD
372 if (optname == SO_ATTACH_FILTER ||
373 optname == SO_ATTACH_REUSEPORT_CBPF)
3fdadf7d
DM
374 return do_set_attach_filter(sock, level, optname,
375 optval, optlen);
3fdadf7d
DM
376 return sock_setsockopt(sock, level, optname, optval, optlen);
377}
378
73ee3eaf
DB
379static int __compat_sys_setsockopt(int fd, int level, int optname,
380 char __user *optval, unsigned int optlen)
1da177e4 381{
3fdadf7d 382 int err;
52baf987 383 struct socket *sock;
3fdadf7d 384
52baf987
JH
385 if (optlen > INT_MAX)
386 return -EINVAL;
387
388 sock = sockfd_lookup(fd, &err);
c6d409cf
ED
389 if (sock) {
390 err = security_socket_setsockopt(sock, level, optname);
3fdadf7d
DM
391 if (err) {
392 sockfd_put(sock);
393 return err;
394 }
395
396 if (level == SOL_SOCKET)
397 err = compat_sock_setsockopt(sock, level,
398 optname, optval, optlen);
399 else if (sock->ops->compat_setsockopt)
400 err = sock->ops->compat_setsockopt(sock, level,
401 optname, optval, optlen);
402 else
403 err = sock->ops->setsockopt(sock, level,
404 optname, optval, optlen);
405 sockfd_put(sock);
406 }
407 return err;
1da177e4
LT
408}
409
73ee3eaf
DB
410COMPAT_SYSCALL_DEFINE5(setsockopt, int, fd, int, level, int, optname,
411 char __user *, optval, unsigned int, optlen)
412{
413 return __compat_sys_setsockopt(fd, level, optname, optval, optlen);
414}
415
8770cf4a
DB
416static int __compat_sys_getsockopt(int fd, int level, int optname,
417 char __user *optval,
418 int __user *optlen)
3fdadf7d
DM
419{
420 int err;
c6d409cf 421 struct socket *sock = sockfd_lookup(fd, &err);
3fdadf7d 422
c6d409cf
ED
423 if (sock) {
424 err = security_socket_getsockopt(sock, level, optname);
3fdadf7d
DM
425 if (err) {
426 sockfd_put(sock);
427 return err;
428 }
429
430 if (level == SOL_SOCKET)
fe0c72f3 431 err = sock_getsockopt(sock, level,
3fdadf7d
DM
432 optname, optval, optlen);
433 else if (sock->ops->compat_getsockopt)
434 err = sock->ops->compat_getsockopt(sock, level,
435 optname, optval, optlen);
436 else
437 err = sock->ops->getsockopt(sock, level,
438 optname, optval, optlen);
439 sockfd_put(sock);
440 }
441 return err;
442}
dae50295 443
8770cf4a
DB
444COMPAT_SYSCALL_DEFINE5(getsockopt, int, fd, int, level, int, optname,
445 char __user *, optval, int __user *, optlen)
446{
447 return __compat_sys_getsockopt(fd, level, optname, optval, optlen);
448}
449
dae50295
DS
450struct compat_group_req {
451 __u32 gr_interface;
452 struct __kernel_sockaddr_storage gr_group
e099b2d9 453 __aligned(4);
bc10502d 454} __packed;
dae50295
DS
455
456struct compat_group_source_req {
457 __u32 gsr_interface;
458 struct __kernel_sockaddr_storage gsr_group
e099b2d9 459 __aligned(4);
dae50295 460 struct __kernel_sockaddr_storage gsr_source
e099b2d9 461 __aligned(4);
bc10502d 462} __packed;
dae50295
DS
463
464struct compat_group_filter {
465 __u32 gf_interface;
466 struct __kernel_sockaddr_storage gf_group
e099b2d9 467 __aligned(4);
dae50295
DS
468 __u32 gf_fmode;
469 __u32 gf_numsrc;
470 struct __kernel_sockaddr_storage gf_slist[1]
e099b2d9 471 __aligned(4);
bc10502d 472} __packed;
dae50295 473
be666e0a
DS
474#define __COMPAT_GF0_SIZE (sizeof(struct compat_group_filter) - \
475 sizeof(struct __kernel_sockaddr_storage))
476
dae50295
DS
477
478int compat_mc_setsockopt(struct sock *sock, int level, int optname,
b7058842 479 char __user *optval, unsigned int optlen,
c6d409cf 480 int (*setsockopt)(struct sock *, int, int, char __user *, unsigned int))
dae50295
DS
481{
482 char __user *koptval = optval;
483 int koptlen = optlen;
484
485 switch (optname) {
486 case MCAST_JOIN_GROUP:
487 case MCAST_LEAVE_GROUP:
488 {
46d84110 489 struct compat_group_req __user *gr32 = (void __user *)optval;
dae50295
DS
490 struct group_req __user *kgr =
491 compat_alloc_user_space(sizeof(struct group_req));
492 u32 interface;
493
96d4f267
LT
494 if (!access_ok(gr32, sizeof(*gr32)) ||
495 !access_ok(kgr, sizeof(struct group_req)) ||
dae50295
DS
496 __get_user(interface, &gr32->gr_interface) ||
497 __put_user(interface, &kgr->gr_interface) ||
498 copy_in_user(&kgr->gr_group, &gr32->gr_group,
499 sizeof(kgr->gr_group)))
500 return -EFAULT;
501 koptval = (char __user *)kgr;
502 koptlen = sizeof(struct group_req);
503 break;
504 }
505 case MCAST_JOIN_SOURCE_GROUP:
506 case MCAST_LEAVE_SOURCE_GROUP:
507 case MCAST_BLOCK_SOURCE:
508 case MCAST_UNBLOCK_SOURCE:
509 {
46d84110 510 struct compat_group_source_req __user *gsr32 = (void __user *)optval;
be666e0a 511 struct group_source_req __user *kgsr = compat_alloc_user_space(
dae50295
DS
512 sizeof(struct group_source_req));
513 u32 interface;
514
96d4f267
LT
515 if (!access_ok(gsr32, sizeof(*gsr32)) ||
516 !access_ok(kgsr,
dae50295
DS
517 sizeof(struct group_source_req)) ||
518 __get_user(interface, &gsr32->gsr_interface) ||
519 __put_user(interface, &kgsr->gsr_interface) ||
520 copy_in_user(&kgsr->gsr_group, &gsr32->gsr_group,
521 sizeof(kgsr->gsr_group)) ||
522 copy_in_user(&kgsr->gsr_source, &gsr32->gsr_source,
523 sizeof(kgsr->gsr_source)))
524 return -EFAULT;
525 koptval = (char __user *)kgsr;
526 koptlen = sizeof(struct group_source_req);
527 break;
528 }
529 case MCAST_MSFILTER:
530 {
46d84110 531 struct compat_group_filter __user *gf32 = (void __user *)optval;
be666e0a 532 struct group_filter __user *kgf;
dae50295
DS
533 u32 interface, fmode, numsrc;
534
96d4f267 535 if (!access_ok(gf32, __COMPAT_GF0_SIZE) ||
dae50295
DS
536 __get_user(interface, &gf32->gf_interface) ||
537 __get_user(fmode, &gf32->gf_fmode) ||
538 __get_user(numsrc, &gf32->gf_numsrc))
539 return -EFAULT;
540 koptlen = optlen + sizeof(struct group_filter) -
541 sizeof(struct compat_group_filter);
542 if (koptlen < GROUP_FILTER_SIZE(numsrc))
543 return -EINVAL;
544 kgf = compat_alloc_user_space(koptlen);
96d4f267 545 if (!access_ok(kgf, koptlen) ||
dae50295
DS
546 __put_user(interface, &kgf->gf_interface) ||
547 __put_user(fmode, &kgf->gf_fmode) ||
548 __put_user(numsrc, &kgf->gf_numsrc) ||
549 copy_in_user(&kgf->gf_group, &gf32->gf_group,
550 sizeof(kgf->gf_group)) ||
be666e0a 551 (numsrc && copy_in_user(kgf->gf_slist, gf32->gf_slist,
dae50295
DS
552 numsrc * sizeof(kgf->gf_slist[0]))))
553 return -EFAULT;
554 koptval = (char __user *)kgf;
555 break;
556 }
557
558 default:
559 break;
560 }
561 return setsockopt(sock, level, optname, koptval, koptlen);
562}
dae50295
DS
563EXPORT_SYMBOL(compat_mc_setsockopt);
564
42908c69
DS
565int compat_mc_getsockopt(struct sock *sock, int level, int optname,
566 char __user *optval, int __user *optlen,
c6d409cf 567 int (*getsockopt)(struct sock *, int, int, char __user *, int __user *))
42908c69 568{
46d84110 569 struct compat_group_filter __user *gf32 = (void __user *)optval;
42908c69
DS
570 struct group_filter __user *kgf;
571 int __user *koptlen;
572 u32 interface, fmode, numsrc;
573 int klen, ulen, err;
574
575 if (optname != MCAST_MSFILTER)
576 return getsockopt(sock, level, optname, optval, optlen);
577
578 koptlen = compat_alloc_user_space(sizeof(*koptlen));
96d4f267 579 if (!access_ok(optlen, sizeof(*optlen)) ||
42908c69
DS
580 __get_user(ulen, optlen))
581 return -EFAULT;
582
583 /* adjust len for pad */
584 klen = ulen + sizeof(*kgf) - sizeof(*gf32);
585
586 if (klen < GROUP_FILTER_SIZE(0))
587 return -EINVAL;
588
96d4f267 589 if (!access_ok(koptlen, sizeof(*koptlen)) ||
42908c69
DS
590 __put_user(klen, koptlen))
591 return -EFAULT;
592
593 /* have to allow space for previous compat_alloc_user_space, too */
594 kgf = compat_alloc_user_space(klen+sizeof(*optlen));
595
96d4f267 596 if (!access_ok(gf32, __COMPAT_GF0_SIZE) ||
42908c69
DS
597 __get_user(interface, &gf32->gf_interface) ||
598 __get_user(fmode, &gf32->gf_fmode) ||
599 __get_user(numsrc, &gf32->gf_numsrc) ||
600 __put_user(interface, &kgf->gf_interface) ||
601 __put_user(fmode, &kgf->gf_fmode) ||
602 __put_user(numsrc, &kgf->gf_numsrc) ||
c6d409cf 603 copy_in_user(&kgf->gf_group, &gf32->gf_group, sizeof(kgf->gf_group)))
42908c69
DS
604 return -EFAULT;
605
606 err = getsockopt(sock, level, optname, (char __user *)kgf, koptlen);
607 if (err)
608 return err;
609
96d4f267 610 if (!access_ok(koptlen, sizeof(*koptlen)) ||
42908c69
DS
611 __get_user(klen, koptlen))
612 return -EFAULT;
613
614 ulen = klen - (sizeof(*kgf)-sizeof(*gf32));
615
96d4f267 616 if (!access_ok(optlen, sizeof(*optlen)) ||
42908c69
DS
617 __put_user(ulen, optlen))
618 return -EFAULT;
619
96d4f267
LT
620 if (!access_ok(kgf, klen) ||
621 !access_ok(gf32, ulen) ||
42908c69
DS
622 __get_user(interface, &kgf->gf_interface) ||
623 __get_user(fmode, &kgf->gf_fmode) ||
624 __get_user(numsrc, &kgf->gf_numsrc) ||
625 __put_user(interface, &gf32->gf_interface) ||
626 __put_user(fmode, &gf32->gf_fmode) ||
627 __put_user(numsrc, &gf32->gf_numsrc))
628 return -EFAULT;
629 if (numsrc) {
630 int copylen;
631
632 klen -= GROUP_FILTER_SIZE(0);
633 copylen = numsrc * sizeof(gf32->gf_slist[0]);
634 if (copylen > klen)
635 copylen = klen;
c6d409cf 636 if (copy_in_user(gf32->gf_slist, kgf->gf_slist, copylen))
42908c69
DS
637 return -EFAULT;
638 }
639 return err;
640}
42908c69
DS
641EXPORT_SYMBOL(compat_mc_getsockopt);
642
dae50295 643
1da177e4
LT
644/* Argument list sizes for compat_sys_socketcall */
645#define AL(x) ((x) * sizeof(u32))
228e548e 646static unsigned char nas[21] = {
c6d409cf
ED
647 AL(0), AL(3), AL(3), AL(3), AL(2), AL(3),
648 AL(3), AL(3), AL(4), AL(4), AL(4), AL(6),
649 AL(6), AL(2), AL(5), AL(5), AL(3), AL(3),
228e548e 650 AL(4), AL(5), AL(4)
c6d409cf 651};
1da177e4
LT
652#undef AL
653
6df35465
DB
654static inline long __compat_sys_sendmsg(int fd,
655 struct compat_msghdr __user *msg,
656 unsigned int flags)
1da177e4 657{
e1834a32
DB
658 return __sys_sendmsg(fd, (struct user_msghdr __user *)msg,
659 flags | MSG_CMSG_COMPAT, false);
1da177e4
LT
660}
661
6df35465
DB
662COMPAT_SYSCALL_DEFINE3(sendmsg, int, fd, struct compat_msghdr __user *, msg,
663 unsigned int, flags)
664{
665 return __compat_sys_sendmsg(fd, msg, flags);
666}
667
668static inline long __compat_sys_sendmmsg(int fd,
669 struct compat_mmsghdr __user *mmsg,
670 unsigned int vlen, unsigned int flags)
228e548e
AB
671{
672 return __sys_sendmmsg(fd, (struct mmsghdr __user *)mmsg, vlen,
e1834a32 673 flags | MSG_CMSG_COMPAT, false);
228e548e
AB
674}
675
6df35465
DB
676COMPAT_SYSCALL_DEFINE4(sendmmsg, int, fd, struct compat_mmsghdr __user *, mmsg,
677 unsigned int, vlen, unsigned int, flags)
678{
679 return __compat_sys_sendmmsg(fd, mmsg, vlen, flags);
680}
681
682static inline long __compat_sys_recvmsg(int fd,
683 struct compat_msghdr __user *msg,
684 unsigned int flags)
1da177e4 685{
e1834a32
DB
686 return __sys_recvmsg(fd, (struct user_msghdr __user *)msg,
687 flags | MSG_CMSG_COMPAT, false);
1da177e4
LT
688}
689
6df35465
DB
690COMPAT_SYSCALL_DEFINE3(recvmsg, int, fd, struct compat_msghdr __user *, msg,
691 unsigned int, flags)
692{
693 return __compat_sys_recvmsg(fd, msg, flags);
694}
695
fd4e82f5
DB
696static inline long __compat_sys_recvfrom(int fd, void __user *buf,
697 compat_size_t len, unsigned int flags,
698 struct sockaddr __user *addr,
699 int __user *addrlen)
700{
701 return __sys_recvfrom(fd, buf, len, flags | MSG_CMSG_COMPAT, addr,
702 addrlen);
703}
704
3a49a0f7 705COMPAT_SYSCALL_DEFINE4(recv, int, fd, void __user *, buf, compat_size_t, len, unsigned int, flags)
1dacc76d 706{
fd4e82f5 707 return __compat_sys_recvfrom(fd, buf, len, flags, NULL, NULL);
1dacc76d
JB
708}
709
3a49a0f7
HC
710COMPAT_SYSCALL_DEFINE6(recvfrom, int, fd, void __user *, buf, compat_size_t, len,
711 unsigned int, flags, struct sockaddr __user *, addr,
712 int __user *, addrlen)
1dacc76d 713{
fd4e82f5 714 return __compat_sys_recvfrom(fd, buf, len, flags, addr, addrlen);
1dacc76d
JB
715}
716
e11d4284
AB
717COMPAT_SYSCALL_DEFINE5(recvmmsg_time64, int, fd, struct compat_mmsghdr __user *, mmsg,
718 unsigned int, vlen, unsigned int, flags,
719 struct __kernel_timespec __user *, timeout)
a2e27255 720{
e11d4284
AB
721 return __sys_recvmmsg(fd, (struct mmsghdr __user *)mmsg, vlen,
722 flags | MSG_CMSG_COMPAT, timeout, NULL);
a2e27255
ACM
723}
724
e11d4284 725#ifdef CONFIG_COMPAT_32BIT_TIME
8dabe724 726COMPAT_SYSCALL_DEFINE5(recvmmsg_time32, int, fd, struct compat_mmsghdr __user *, mmsg,
157b334a 727 unsigned int, vlen, unsigned int, flags,
9afc5eee 728 struct old_timespec32 __user *, timeout)
157b334a 729{
e11d4284
AB
730 return __sys_recvmmsg(fd, (struct mmsghdr __user *)mmsg, vlen,
731 flags | MSG_CMSG_COMPAT, NULL, timeout);
157b334a 732}
e11d4284 733#endif
157b334a 734
361d93c4 735COMPAT_SYSCALL_DEFINE2(socketcall, int, call, u32 __user *, args)
1da177e4 736{
62bc306e
RGB
737 u32 a[AUDITSC_ARGS];
738 unsigned int len;
1da177e4 739 u32 a0, a1;
62bc306e 740 int ret;
4768fbcb 741
228e548e 742 if (call < SYS_SOCKET || call > SYS_SENDMMSG)
1da177e4 743 return -EINVAL;
62bc306e
RGB
744 len = nas[call];
745 if (len > sizeof(a))
746 return -EINVAL;
747
748 if (copy_from_user(a, args, len))
1da177e4 749 return -EFAULT;
62bc306e
RGB
750
751 ret = audit_socketcall_compat(len / sizeof(a[0]), a);
752 if (ret)
753 return ret;
754
1da177e4
LT
755 a0 = a[0];
756 a1 = a[1];
4768fbcb 757
e71a4783 758 switch (call) {
1da177e4 759 case SYS_SOCKET:
9d6a15c3 760 ret = __sys_socket(a0, a1, a[2]);
1da177e4
LT
761 break;
762 case SYS_BIND:
a87d35d8 763 ret = __sys_bind(a0, compat_ptr(a1), a[2]);
1da177e4
LT
764 break;
765 case SYS_CONNECT:
1387c2c2 766 ret = __sys_connect(a0, compat_ptr(a1), a[2]);
1da177e4
LT
767 break;
768 case SYS_LISTEN:
25e290ee 769 ret = __sys_listen(a0, a1);
1da177e4
LT
770 break;
771 case SYS_ACCEPT:
4541e805 772 ret = __sys_accept4(a0, compat_ptr(a1), compat_ptr(a[2]), 0);
1da177e4
LT
773 break;
774 case SYS_GETSOCKNAME:
8882a107 775 ret = __sys_getsockname(a0, compat_ptr(a1), compat_ptr(a[2]));
1da177e4
LT
776 break;
777 case SYS_GETPEERNAME:
b21c8f83 778 ret = __sys_getpeername(a0, compat_ptr(a1), compat_ptr(a[2]));
1da177e4
LT
779 break;
780 case SYS_SOCKETPAIR:
6debc8d8 781 ret = __sys_socketpair(a0, a1, a[2], compat_ptr(a[3]));
1da177e4
LT
782 break;
783 case SYS_SEND:
f3bf896b 784 ret = __sys_sendto(a0, compat_ptr(a1), a[2], a[3], NULL, 0);
1da177e4
LT
785 break;
786 case SYS_SENDTO:
211b634b
DB
787 ret = __sys_sendto(a0, compat_ptr(a1), a[2], a[3],
788 compat_ptr(a[4]), a[5]);
1da177e4
LT
789 break;
790 case SYS_RECV:
fd4e82f5
DB
791 ret = __compat_sys_recvfrom(a0, compat_ptr(a1), a[2], a[3],
792 NULL, NULL);
1da177e4
LT
793 break;
794 case SYS_RECVFROM:
fd4e82f5
DB
795 ret = __compat_sys_recvfrom(a0, compat_ptr(a1), a[2], a[3],
796 compat_ptr(a[4]),
797 compat_ptr(a[5]));
1da177e4
LT
798 break;
799 case SYS_SHUTDOWN:
005a1aea 800 ret = __sys_shutdown(a0, a1);
1da177e4
LT
801 break;
802 case SYS_SETSOCKOPT:
73ee3eaf
DB
803 ret = __compat_sys_setsockopt(a0, a1, a[2],
804 compat_ptr(a[3]), a[4]);
1da177e4
LT
805 break;
806 case SYS_GETSOCKOPT:
8770cf4a
DB
807 ret = __compat_sys_getsockopt(a0, a1, a[2],
808 compat_ptr(a[3]),
809 compat_ptr(a[4]));
1da177e4
LT
810 break;
811 case SYS_SENDMSG:
6df35465 812 ret = __compat_sys_sendmsg(a0, compat_ptr(a1), a[2]);
1da177e4 813 break;
228e548e 814 case SYS_SENDMMSG:
6df35465 815 ret = __compat_sys_sendmmsg(a0, compat_ptr(a1), a[2], a[3]);
228e548e 816 break;
1da177e4 817 case SYS_RECVMSG:
6df35465 818 ret = __compat_sys_recvmsg(a0, compat_ptr(a1), a[2]);
1da177e4 819 break;
a2e27255 820 case SYS_RECVMMSG:
e11d4284
AB
821 ret = __sys_recvmmsg(a0, compat_ptr(a1), a[2],
822 a[3] | MSG_CMSG_COMPAT, NULL,
823 compat_ptr(a[4]));
a2e27255 824 break;
de11defe 825 case SYS_ACCEPT4:
4541e805 826 ret = __sys_accept4(a0, compat_ptr(a1), compat_ptr(a[2]), a[3]);
aaca0bdc 827 break;
1da177e4
LT
828 default:
829 ret = -EINVAL;
830 break;
831 }
832 return ret;
833}