]> git.ipfire.org Git - people/arne_f/kernel.git/blame - ipc/msgutil.c
iio:magnetometer:ak8975 Fix alignment and data leak issues.
[people/arne_f/kernel.git] / ipc / msgutil.c
CommitLineData
1da177e4 1/*
f30c2269 2 * linux/ipc/msgutil.c
1da177e4
LT
3 * Copyright (C) 1999, 2004 Manfred Spraul
4 *
5 * This file is released under GNU General Public Licence version 2 or
6 * (at your option) any later version.
7 *
8 * See the file COPYING for more details.
9 */
10
11#include <linux/spinlock.h>
12#include <linux/init.h>
13#include <linux/security.h>
14#include <linux/slab.h>
15#include <linux/ipc.h>
40401530 16#include <linux/msg.h>
614b84cf 17#include <linux/ipc_namespace.h>
40401530 18#include <linux/utsname.h>
0bb80f24 19#include <linux/proc_ns.h>
1e3c941c 20#include <linux/uaccess.h>
bcdabf7f 21#include <linux/sched.h>
1da177e4
LT
22
23#include "util.h"
24
7eafd7c7
SH
25DEFINE_SPINLOCK(mq_lock);
26
614b84cf
SH
27/*
28 * The next 2 defines are here bc this is the only file
29 * compiled when either CONFIG_SYSVIPC and CONFIG_POSIX_MQUEUE
30 * and not CONFIG_IPC_NS.
31 */
32struct ipc_namespace init_ipc_ns = {
a2e0602c 33 .count = REFCOUNT_INIT(1),
b515498f 34 .user_ns = &init_user_ns,
435d5f4b 35 .ns.inum = PROC_IPC_INIT_INO,
33c42940
AV
36#ifdef CONFIG_IPC_NS
37 .ns.ops = &ipcns_operations,
38#endif
614b84cf
SH
39};
40
1da177e4 41struct msg_msgseg {
1e3c941c 42 struct msg_msgseg *next;
1da177e4
LT
43 /* the next part of the message follows immediately */
44};
45
4e9b45a1
MK
46#define DATALEN_MSG ((size_t)PAGE_SIZE-sizeof(struct msg_msg))
47#define DATALEN_SEG ((size_t)PAGE_SIZE-sizeof(struct msg_msgseg))
1da177e4 48
be5f4b33 49
4e9b45a1 50static struct msg_msg *alloc_msg(size_t len)
1da177e4
LT
51{
52 struct msg_msg *msg;
53 struct msg_msgseg **pseg;
4e9b45a1 54 size_t alen;
1da177e4 55
3d8fa456 56 alen = min(len, DATALEN_MSG);
8c8d4d45 57 msg = kmalloc(sizeof(*msg) + alen, GFP_KERNEL_ACCOUNT);
1da177e4 58 if (msg == NULL)
be5f4b33 59 return NULL;
1da177e4
LT
60
61 msg->next = NULL;
62 msg->security = NULL;
63
be5f4b33
PH
64 len -= alen;
65 pseg = &msg->next;
66 while (len > 0) {
67 struct msg_msgseg *seg;
bcdabf7f
LR
68
69 cond_resched();
70
be5f4b33 71 alen = min(len, DATALEN_SEG);
8c8d4d45 72 seg = kmalloc(sizeof(*seg) + alen, GFP_KERNEL_ACCOUNT);
be5f4b33
PH
73 if (seg == NULL)
74 goto out_err;
75 *pseg = seg;
76 seg->next = NULL;
77 pseg = &seg->next;
78 len -= alen;
79 }
80
81 return msg;
82
83out_err:
84 free_msg(msg);
85 return NULL;
86}
87
4e9b45a1 88struct msg_msg *load_msg(const void __user *src, size_t len)
be5f4b33
PH
89{
90 struct msg_msg *msg;
91 struct msg_msgseg *seg;
2b3097a2 92 int err = -EFAULT;
4e9b45a1 93 size_t alen;
be5f4b33
PH
94
95 msg = alloc_msg(len);
96 if (msg == NULL)
97 return ERR_PTR(-ENOMEM);
98
99 alen = min(len, DATALEN_MSG);
2b3097a2 100 if (copy_from_user(msg + 1, src, alen))
1da177e4 101 goto out_err;
1da177e4 102
da085d45
PH
103 for (seg = msg->next; seg != NULL; seg = seg->next) {
104 len -= alen;
105 src = (char __user *)src + alen;
3d8fa456 106 alen = min(len, DATALEN_SEG);
2b3097a2 107 if (copy_from_user(seg + 1, src, alen))
1da177e4 108 goto out_err;
1da177e4
LT
109 }
110
111 err = security_msg_msg_alloc(msg);
112 if (err)
113 goto out_err;
114
115 return msg;
116
117out_err:
118 free_msg(msg);
119 return ERR_PTR(err);
120}
4a674f34
SK
121#ifdef CONFIG_CHECKPOINT_RESTORE
122struct msg_msg *copy_msg(struct msg_msg *src, struct msg_msg *dst)
123{
124 struct msg_msgseg *dst_pseg, *src_pseg;
4e9b45a1
MK
125 size_t len = src->m_ts;
126 size_t alen;
4a674f34 127
4a674f34
SK
128 if (src->m_ts > dst->m_ts)
129 return ERR_PTR(-EINVAL);
130
3d8fa456 131 alen = min(len, DATALEN_MSG);
4a674f34
SK
132 memcpy(dst + 1, src + 1, alen);
133
da085d45
PH
134 for (dst_pseg = dst->next, src_pseg = src->next;
135 src_pseg != NULL;
136 dst_pseg = dst_pseg->next, src_pseg = src_pseg->next) {
137
138 len -= alen;
3d8fa456 139 alen = min(len, DATALEN_SEG);
4a674f34 140 memcpy(dst_pseg + 1, src_pseg + 1, alen);
4a674f34
SK
141 }
142
143 dst->m_type = src->m_type;
144 dst->m_ts = src->m_ts;
145
146 return dst;
147}
51eeacaa
SK
148#else
149struct msg_msg *copy_msg(struct msg_msg *src, struct msg_msg *dst)
150{
151 return ERR_PTR(-ENOSYS);
152}
4a674f34 153#endif
4e9b45a1 154int store_msg(void __user *dest, struct msg_msg *msg, size_t len)
1da177e4 155{
4e9b45a1 156 size_t alen;
1da177e4
LT
157 struct msg_msgseg *seg;
158
3d8fa456 159 alen = min(len, DATALEN_MSG);
1da177e4
LT
160 if (copy_to_user(dest, msg + 1, alen))
161 return -1;
162
da085d45
PH
163 for (seg = msg->next; seg != NULL; seg = seg->next) {
164 len -= alen;
165 dest = (char __user *)dest + alen;
3d8fa456 166 alen = min(len, DATALEN_SEG);
1da177e4
LT
167 if (copy_to_user(dest, seg + 1, alen))
168 return -1;
1da177e4
LT
169 }
170 return 0;
171}
172
173void free_msg(struct msg_msg *msg)
174{
175 struct msg_msgseg *seg;
176
177 security_msg_msg_free(msg);
178
179 seg = msg->next;
180 kfree(msg);
181 while (seg != NULL) {
182 struct msg_msgseg *tmp = seg->next;
bcdabf7f
LR
183
184 cond_resched();
1da177e4
LT
185 kfree(seg);
186 seg = tmp;
187 }
188}