1 /* SPDX-License-Identifier: GPL-2.0 */
2 /*
3  * vboxguest linux pci driver, char-dev and input-device code,
4  *
5  * Copyright (C) 2006-2016 Oracle Corporation
6  */
7 
8 #include <linux/cred.h>
9 #include <linux/input.h>
10 #include <linux/kernel.h>
11 #include <linux/miscdevice.h>
12 #include <linux/module.h>
13 #include <linux/pci.h>
14 #include <linux/poll.h>
15 #include <linux/vbox_utils.h>
16 #include "vboxguest_core.h"
17 
18 /** The device name. */
19 #define DEVICE_NAME		"vboxguest"
20 /** The device name for the device node open to everyone. */
21 #define DEVICE_NAME_USER	"vboxuser"
22 /** VirtualBox PCI vendor ID. */
23 #define VBOX_VENDORID		0x80ee
24 /** VMMDev PCI card product ID. */
25 #define VMMDEV_DEVICEID		0xcafe
26 
27 /** Mutex protecting the global vbg_gdev pointer used by vbg_get/put_gdev. */
28 static DEFINE_MUTEX(vbg_gdev_mutex);
29 /** Global vbg_gdev pointer used by vbg_get/put_gdev. */
30 static struct vbg_dev *vbg_gdev;
31 
32 static u32 vbg_misc_device_requestor(struct inode *inode)
33 {
34 	u32 requestor = VMMDEV_REQUESTOR_USERMODE |
35 			VMMDEV_REQUESTOR_CON_DONT_KNOW |
36 			VMMDEV_REQUESTOR_TRUST_NOT_GIVEN;
37 
38 	if (from_kuid(current_user_ns(), current->cred->uid) == 0)
39 		requestor |= VMMDEV_REQUESTOR_USR_ROOT;
40 	else
41 		requestor |= VMMDEV_REQUESTOR_USR_USER;
42 
43 	if (in_egroup_p(inode->i_gid))
44 		requestor |= VMMDEV_REQUESTOR_GRP_VBOX;
45 
46 	return requestor;
47 }
48 
49 static int vbg_misc_device_open(struct inode *inode, struct file *filp)
50 {
51 	struct vbg_session *session;
52 	struct vbg_dev *gdev;
53 
54 	/* misc_open sets filp->private_data to our misc device */
55 	gdev = container_of(filp->private_data, struct vbg_dev, misc_device);
56 
57 	session = vbg_core_open_session(gdev, vbg_misc_device_requestor(inode));
58 	if (IS_ERR(session))
59 		return PTR_ERR(session);
60 
61 	filp->private_data = session;
62 	return 0;
63 }
64 
65 static int vbg_misc_device_user_open(struct inode *inode, struct file *filp)
66 {
67 	struct vbg_session *session;
68 	struct vbg_dev *gdev;
69 
70 	/* misc_open sets filp->private_data to our misc device */
71 	gdev = container_of(filp->private_data, struct vbg_dev,
72 			    misc_device_user);
73 
74 	session = vbg_core_open_session(gdev, vbg_misc_device_requestor(inode) |
75 					      VMMDEV_REQUESTOR_USER_DEVICE);
76 	if (IS_ERR(session))
77 		return PTR_ERR(session);
78 
79 	filp->private_data = session;
80 	return 0;
81 }
82 
83 /**
84  * Close device.
85  * Return: 0 on success, negated errno on failure.
86  * @inode:		Pointer to inode info structure.
87  * @filp:		Associated file pointer.
88  */
89 static int vbg_misc_device_close(struct inode *inode, struct file *filp)
90 {
91 	vbg_core_close_session(filp->private_data);
92 	filp->private_data = NULL;
93 	return 0;
94 }
95 
96 /**
97  * Device I/O Control entry point.
98  * Return: 0 on success, negated errno on failure.
99  * @filp:		Associated file pointer.
100  * @req:		The request specified to ioctl().
101  * @arg:		The argument specified to ioctl().
102  */
103 static long vbg_misc_device_ioctl(struct file *filp, unsigned int req,
104 				  unsigned long arg)
105 {
106 	struct vbg_session *session = filp->private_data;
107 	size_t returned_size, size;
108 	struct vbg_ioctl_hdr hdr;
109 	bool is_vmmdev_req;
110 	int ret = 0;
111 	void *buf;
112 
113 	if (copy_from_user(&hdr, (void *)arg, sizeof(hdr)))
114 		return -EFAULT;
115 
116 	if (hdr.version != VBG_IOCTL_HDR_VERSION)
117 		return -EINVAL;
118 
119 	if (hdr.size_in < sizeof(hdr) ||
120 	    (hdr.size_out && hdr.size_out < sizeof(hdr)))
121 		return -EINVAL;
122 
123 	size = max(hdr.size_in, hdr.size_out);
124 	if (_IOC_SIZE(req) && _IOC_SIZE(req) != size)
125 		return -EINVAL;
126 	if (size > SZ_16M)
127 		return -E2BIG;
128 
129 	/*
130 	 * IOCTL_VMMDEV_REQUEST needs the buffer to be below 4G to avoid
131 	 * the need for a bounce-buffer and another copy later on.
132 	 */
133 	is_vmmdev_req = (req & ~IOCSIZE_MASK) == VBG_IOCTL_VMMDEV_REQUEST(0) ||
134 			 req == VBG_IOCTL_VMMDEV_REQUEST_BIG ||
135 			 req == VBG_IOCTL_VMMDEV_REQUEST_BIG_ALT;
136 
137 	if (is_vmmdev_req)
138 		buf = vbg_req_alloc(size, VBG_IOCTL_HDR_TYPE_DEFAULT,
139 				    session->requestor);
140 	else
141 		buf = kmalloc(size, GFP_KERNEL);
142 	if (!buf)
143 		return -ENOMEM;
144 
145 	*((struct vbg_ioctl_hdr *)buf) = hdr;
146 	if (copy_from_user(buf + sizeof(hdr), (void *)arg + sizeof(hdr),
147 			   hdr.size_in - sizeof(hdr))) {
148 		ret = -EFAULT;
149 		goto out;
150 	}
151 	if (hdr.size_in < size)
152 		memset(buf + hdr.size_in, 0, size -  hdr.size_in);
153 
154 	ret = vbg_core_ioctl(session, req, buf);
155 	if (ret)
156 		goto out;
157 
158 	returned_size = ((struct vbg_ioctl_hdr *)buf)->size_out;
159 	if (returned_size > size) {
160 		vbg_debug("%s: too much output data %zu > %zu\n",
161 			  __func__, returned_size, size);
162 		returned_size = size;
163 	}
164 	if (copy_to_user((void *)arg, buf, returned_size) != 0)
165 		ret = -EFAULT;
166 
167 out:
168 	if (is_vmmdev_req)
169 		vbg_req_free(buf, size);
170 	else
171 		kfree(buf);
172 
173 	return ret;
174 }
175 
176 /** The file_operations structures. */
177 static const struct file_operations vbg_misc_device_fops = {
178 	.owner			= THIS_MODULE,
179 	.open			= vbg_misc_device_open,
180 	.release		= vbg_misc_device_close,
181 	.unlocked_ioctl		= vbg_misc_device_ioctl,
182 #ifdef CONFIG_COMPAT
183 	.compat_ioctl		= vbg_misc_device_ioctl,
184 #endif
185 };
186 static const struct file_operations vbg_misc_device_user_fops = {
187 	.owner			= THIS_MODULE,
188 	.open			= vbg_misc_device_user_open,
189 	.release		= vbg_misc_device_close,
190 	.unlocked_ioctl		= vbg_misc_device_ioctl,
191 #ifdef CONFIG_COMPAT
192 	.compat_ioctl		= vbg_misc_device_ioctl,
193 #endif
194 };
195 
196 /**
197  * Called when the input device is first opened.
198  *
199  * Sets up absolute mouse reporting.
200  */
201 static int vbg_input_open(struct input_dev *input)
202 {
203 	struct vbg_dev *gdev = input_get_drvdata(input);
204 	u32 feat = VMMDEV_MOUSE_GUEST_CAN_ABSOLUTE | VMMDEV_MOUSE_NEW_PROTOCOL;
205 	int ret;
206 
207 	ret = vbg_core_set_mouse_status(gdev, feat);
208 	if (ret)
209 		return ret;
210 
211 	return 0;
212 }
213 
214 /**
215  * Called if all open handles to the input device are closed.
216  *
217  * Disables absolute reporting.
218  */
219 static void vbg_input_close(struct input_dev *input)
220 {
221 	struct vbg_dev *gdev = input_get_drvdata(input);
222 
223 	vbg_core_set_mouse_status(gdev, 0);
224 }
225 
226 /**
227  * Creates the kernel input device.
228  *
229  * Return: 0 on success, negated errno on failure.
230  */
231 static int vbg_create_input_device(struct vbg_dev *gdev)
232 {
233 	struct input_dev *input;
234 
235 	input = devm_input_allocate_device(gdev->dev);
236 	if (!input)
237 		return -ENOMEM;
238 
239 	input->id.bustype = BUS_PCI;
240 	input->id.vendor = VBOX_VENDORID;
241 	input->id.product = VMMDEV_DEVICEID;
242 	input->open = vbg_input_open;
243 	input->close = vbg_input_close;
244 	input->dev.parent = gdev->dev;
245 	input->name = "VirtualBox mouse integration";
246 
247 	input_set_abs_params(input, ABS_X, VMMDEV_MOUSE_RANGE_MIN,
248 			     VMMDEV_MOUSE_RANGE_MAX, 0, 0);
249 	input_set_abs_params(input, ABS_Y, VMMDEV_MOUSE_RANGE_MIN,
250 			     VMMDEV_MOUSE_RANGE_MAX, 0, 0);
251 	input_set_capability(input, EV_KEY, BTN_MOUSE);
252 	input_set_drvdata(input, gdev);
253 
254 	gdev->input = input;
255 
256 	return input_register_device(gdev->input);
257 }
258 
259 static ssize_t host_version_show(struct device *dev,
260 				 struct device_attribute *attr, char *buf)
261 {
262 	struct vbg_dev *gdev = dev_get_drvdata(dev);
263 
264 	return sprintf(buf, "%s\n", gdev->host_version);
265 }
266 
267 static ssize_t host_features_show(struct device *dev,
268 				 struct device_attribute *attr, char *buf)
269 {
270 	struct vbg_dev *gdev = dev_get_drvdata(dev);
271 
272 	return sprintf(buf, "%#x\n", gdev->host_features);
273 }
274 
275 static DEVICE_ATTR_RO(host_version);
276 static DEVICE_ATTR_RO(host_features);
277 
278 /**
279  * Does the PCI detection and init of the device.
280  *
281  * Return: 0 on success, negated errno on failure.
282  */
283 static int vbg_pci_probe(struct pci_dev *pci, const struct pci_device_id *id)
284 {
285 	struct device *dev = &pci->dev;
286 	resource_size_t io, io_len, mmio, mmio_len;
287 	struct vmmdev_memory *vmmdev;
288 	struct vbg_dev *gdev;
289 	int ret;
290 
291 	gdev = devm_kzalloc(dev, sizeof(*gdev), GFP_KERNEL);
292 	if (!gdev)
293 		return -ENOMEM;
294 
295 	ret = pci_enable_device(pci);
296 	if (ret != 0) {
297 		vbg_err("vboxguest: Error enabling device: %d\n", ret);
298 		return ret;
299 	}
300 
301 	ret = -ENODEV;
302 
303 	io = pci_resource_start(pci, 0);
304 	io_len = pci_resource_len(pci, 0);
305 	if (!io || !io_len) {
306 		vbg_err("vboxguest: Error IO-port resource (0) is missing\n");
307 		goto err_disable_pcidev;
308 	}
309 	if (devm_request_region(dev, io, io_len, DEVICE_NAME) == NULL) {
310 		vbg_err("vboxguest: Error could not claim IO resource\n");
311 		ret = -EBUSY;
312 		goto err_disable_pcidev;
313 	}
314 
315 	mmio = pci_resource_start(pci, 1);
316 	mmio_len = pci_resource_len(pci, 1);
317 	if (!mmio || !mmio_len) {
318 		vbg_err("vboxguest: Error MMIO resource (1) is missing\n");
319 		goto err_disable_pcidev;
320 	}
321 
322 	if (devm_request_mem_region(dev, mmio, mmio_len, DEVICE_NAME) == NULL) {
323 		vbg_err("vboxguest: Error could not claim MMIO resource\n");
324 		ret = -EBUSY;
325 		goto err_disable_pcidev;
326 	}
327 
328 	vmmdev = devm_ioremap(dev, mmio, mmio_len);
329 	if (!vmmdev) {
330 		vbg_err("vboxguest: Error ioremap failed; MMIO addr=%pap size=%pap\n",
331 			&mmio, &mmio_len);
332 		goto err_disable_pcidev;
333 	}
334 
335 	/* Validate MMIO region version and size. */
336 	if (vmmdev->version != VMMDEV_MEMORY_VERSION ||
337 	    vmmdev->size < 32 || vmmdev->size > mmio_len) {
338 		vbg_err("vboxguest: Bogus VMMDev memory; version=%08x (expected %08x) size=%d (expected <= %d)\n",
339 			vmmdev->version, VMMDEV_MEMORY_VERSION,
340 			vmmdev->size, (int)mmio_len);
341 		goto err_disable_pcidev;
342 	}
343 
344 	gdev->io_port = io;
345 	gdev->mmio = vmmdev;
346 	gdev->dev = dev;
347 	gdev->misc_device.minor = MISC_DYNAMIC_MINOR;
348 	gdev->misc_device.name = DEVICE_NAME;
349 	gdev->misc_device.fops = &vbg_misc_device_fops;
350 	gdev->misc_device_user.minor = MISC_DYNAMIC_MINOR;
351 	gdev->misc_device_user.name = DEVICE_NAME_USER;
352 	gdev->misc_device_user.fops = &vbg_misc_device_user_fops;
353 
354 	ret = vbg_core_init(gdev, VMMDEV_EVENT_MOUSE_POSITION_CHANGED);
355 	if (ret)
356 		goto err_disable_pcidev;
357 
358 	ret = vbg_create_input_device(gdev);
359 	if (ret) {
360 		vbg_err("vboxguest: Error creating input device: %d\n", ret);
361 		goto err_vbg_core_exit;
362 	}
363 
364 	ret = devm_request_irq(dev, pci->irq, vbg_core_isr, IRQF_SHARED,
365 			       DEVICE_NAME, gdev);
366 	if (ret) {
367 		vbg_err("vboxguest: Error requesting irq: %d\n", ret);
368 		goto err_vbg_core_exit;
369 	}
370 
371 	ret = misc_register(&gdev->misc_device);
372 	if (ret) {
373 		vbg_err("vboxguest: Error misc_register %s failed: %d\n",
374 			DEVICE_NAME, ret);
375 		goto err_vbg_core_exit;
376 	}
377 
378 	ret = misc_register(&gdev->misc_device_user);
379 	if (ret) {
380 		vbg_err("vboxguest: Error misc_register %s failed: %d\n",
381 			DEVICE_NAME_USER, ret);
382 		goto err_unregister_misc_device;
383 	}
384 
385 	mutex_lock(&vbg_gdev_mutex);
386 	if (!vbg_gdev)
387 		vbg_gdev = gdev;
388 	else
389 		ret = -EBUSY;
390 	mutex_unlock(&vbg_gdev_mutex);
391 
392 	if (ret) {
393 		vbg_err("vboxguest: Error more then 1 vbox guest pci device\n");
394 		goto err_unregister_misc_device_user;
395 	}
396 
397 	pci_set_drvdata(pci, gdev);
398 	device_create_file(dev, &dev_attr_host_version);
399 	device_create_file(dev, &dev_attr_host_features);
400 
401 	vbg_info("vboxguest: misc device minor %d, IRQ %d, I/O port %x, MMIO at %pap (size %pap)\n",
402 		 gdev->misc_device.minor, pci->irq, gdev->io_port,
403 		 &mmio, &mmio_len);
404 
405 	return 0;
406 
407 err_unregister_misc_device_user:
408 	misc_deregister(&gdev->misc_device_user);
409 err_unregister_misc_device:
410 	misc_deregister(&gdev->misc_device);
411 err_vbg_core_exit:
412 	vbg_core_exit(gdev);
413 err_disable_pcidev:
414 	pci_disable_device(pci);
415 
416 	return ret;
417 }
418 
419 static void vbg_pci_remove(struct pci_dev *pci)
420 {
421 	struct vbg_dev *gdev = pci_get_drvdata(pci);
422 
423 	mutex_lock(&vbg_gdev_mutex);
424 	vbg_gdev = NULL;
425 	mutex_unlock(&vbg_gdev_mutex);
426 
427 	device_remove_file(gdev->dev, &dev_attr_host_features);
428 	device_remove_file(gdev->dev, &dev_attr_host_version);
429 	misc_deregister(&gdev->misc_device_user);
430 	misc_deregister(&gdev->misc_device);
431 	vbg_core_exit(gdev);
432 	pci_disable_device(pci);
433 }
434 
435 struct vbg_dev *vbg_get_gdev(void)
436 {
437 	mutex_lock(&vbg_gdev_mutex);
438 
439 	/*
440 	 * Note on success we keep the mutex locked until vbg_put_gdev(),
441 	 * this stops vbg_pci_remove from removing the device from underneath
442 	 * vboxsf. vboxsf will only hold a reference for a short while.
443 	 */
444 	if (vbg_gdev)
445 		return vbg_gdev;
446 
447 	mutex_unlock(&vbg_gdev_mutex);
448 	return ERR_PTR(-ENODEV);
449 }
450 EXPORT_SYMBOL(vbg_get_gdev);
451 
452 void vbg_put_gdev(struct vbg_dev *gdev)
453 {
454 	WARN_ON(gdev != vbg_gdev);
455 	mutex_unlock(&vbg_gdev_mutex);
456 }
457 EXPORT_SYMBOL(vbg_put_gdev);
458 
459 /**
460  * Callback for mouse events.
461  *
462  * This is called at the end of the ISR, after leaving the event spinlock, if
463  * VMMDEV_EVENT_MOUSE_POSITION_CHANGED was raised by the host.
464  *
465  * @gdev:		The device extension.
466  */
467 void vbg_linux_mouse_event(struct vbg_dev *gdev)
468 {
469 	int rc;
470 
471 	/* Report events to the kernel input device */
472 	gdev->mouse_status_req->mouse_features = 0;
473 	gdev->mouse_status_req->pointer_pos_x = 0;
474 	gdev->mouse_status_req->pointer_pos_y = 0;
475 	rc = vbg_req_perform(gdev, gdev->mouse_status_req);
476 	if (rc >= 0) {
477 		input_report_abs(gdev->input, ABS_X,
478 				 gdev->mouse_status_req->pointer_pos_x);
479 		input_report_abs(gdev->input, ABS_Y,
480 				 gdev->mouse_status_req->pointer_pos_y);
481 		input_sync(gdev->input);
482 	}
483 }
484 
485 static const struct pci_device_id vbg_pci_ids[] = {
486 	{ .vendor = VBOX_VENDORID, .device = VMMDEV_DEVICEID },
487 	{}
488 };
489 MODULE_DEVICE_TABLE(pci,  vbg_pci_ids);
490 
491 static struct pci_driver vbg_pci_driver = {
492 	.name		= DEVICE_NAME,
493 	.id_table	= vbg_pci_ids,
494 	.probe		= vbg_pci_probe,
495 	.remove		= vbg_pci_remove,
496 };
497 
498 module_pci_driver(vbg_pci_driver);
499 
500 MODULE_AUTHOR("Oracle Corporation");
501 MODULE_DESCRIPTION("Oracle VM VirtualBox Guest Additions for Linux Module");
502 MODULE_LICENSE("GPL");
503