1 /* 2 * linux/ipc/msgutil.c 3 * Copyright (C) 1999, 2004 Manfred Spraul 4 * 5 * This file is released under GNU General Public Licence version 2 or 6 * (at your option) any later version. 7 * 8 * See the file COPYING for more details. 9 */ 10 11 #include <linux/spinlock.h> 12 #include <linux/init.h> 13 #include <linux/security.h> 14 #include <linux/slab.h> 15 #include <linux/ipc.h> 16 #include <linux/msg.h> 17 #include <linux/ipc_namespace.h> 18 #include <linux/utsname.h> 19 #include <linux/proc_ns.h> 20 #include <linux/uaccess.h> 21 #include <linux/sched.h> 22 23 #include "util.h" 24 25 DEFINE_SPINLOCK(mq_lock); 26 27 /* 28 * The next 2 defines are here bc this is the only file 29 * compiled when either CONFIG_SYSVIPC and CONFIG_POSIX_MQUEUE 30 * and not CONFIG_IPC_NS. 31 */ 32 struct ipc_namespace init_ipc_ns = { 33 .count = REFCOUNT_INIT(1), 34 .user_ns = &init_user_ns, 35 .ns.inum = PROC_IPC_INIT_INO, 36 #ifdef CONFIG_IPC_NS 37 .ns.ops = &ipcns_operations, 38 #endif 39 }; 40 41 struct msg_msgseg { 42 struct msg_msgseg *next; 43 /* the next part of the message follows immediately */ 44 }; 45 46 #define DATALEN_MSG ((size_t)PAGE_SIZE-sizeof(struct msg_msg)) 47 #define DATALEN_SEG ((size_t)PAGE_SIZE-sizeof(struct msg_msgseg)) 48 49 50 static struct msg_msg *alloc_msg(size_t len) 51 { 52 struct msg_msg *msg; 53 struct msg_msgseg **pseg; 54 size_t alen; 55 56 alen = min(len, DATALEN_MSG); 57 msg = kmalloc(sizeof(*msg) + alen, GFP_KERNEL_ACCOUNT); 58 if (msg == NULL) 59 return NULL; 60 61 msg->next = NULL; 62 msg->security = NULL; 63 64 len -= alen; 65 pseg = &msg->next; 66 while (len > 0) { 67 struct msg_msgseg *seg; 68 69 cond_resched(); 70 71 alen = min(len, DATALEN_SEG); 72 seg = kmalloc(sizeof(*seg) + alen, GFP_KERNEL_ACCOUNT); 73 if (seg == NULL) 74 goto out_err; 75 *pseg = seg; 76 seg->next = NULL; 77 pseg = &seg->next; 78 len -= alen; 79 } 80 81 return msg; 82 83 out_err: 84 free_msg(msg); 85 return NULL; 86 } 87 88 struct msg_msg *load_msg(const void __user *src, size_t len) 89 { 90 struct msg_msg *msg; 91 struct msg_msgseg *seg; 92 int err = -EFAULT; 93 size_t alen; 94 95 msg = alloc_msg(len); 96 if (msg == NULL) 97 return ERR_PTR(-ENOMEM); 98 99 alen = min(len, DATALEN_MSG); 100 if (copy_from_user(msg + 1, src, alen)) 101 goto out_err; 102 103 for (seg = msg->next; seg != NULL; seg = seg->next) { 104 len -= alen; 105 src = (char __user *)src + alen; 106 alen = min(len, DATALEN_SEG); 107 if (copy_from_user(seg + 1, src, alen)) 108 goto out_err; 109 } 110 111 err = security_msg_msg_alloc(msg); 112 if (err) 113 goto out_err; 114 115 return msg; 116 117 out_err: 118 free_msg(msg); 119 return ERR_PTR(err); 120 } 121 #ifdef CONFIG_CHECKPOINT_RESTORE 122 struct msg_msg *copy_msg(struct msg_msg *src, struct msg_msg *dst) 123 { 124 struct msg_msgseg *dst_pseg, *src_pseg; 125 size_t len = src->m_ts; 126 size_t alen; 127 128 if (src->m_ts > dst->m_ts) 129 return ERR_PTR(-EINVAL); 130 131 alen = min(len, DATALEN_MSG); 132 memcpy(dst + 1, src + 1, alen); 133 134 for (dst_pseg = dst->next, src_pseg = src->next; 135 src_pseg != NULL; 136 dst_pseg = dst_pseg->next, src_pseg = src_pseg->next) { 137 138 len -= alen; 139 alen = min(len, DATALEN_SEG); 140 memcpy(dst_pseg + 1, src_pseg + 1, alen); 141 } 142 143 dst->m_type = src->m_type; 144 dst->m_ts = src->m_ts; 145 146 return dst; 147 } 148 #else 149 struct msg_msg *copy_msg(struct msg_msg *src, struct msg_msg *dst) 150 { 151 return ERR_PTR(-ENOSYS); 152 } 153 #endif 154 int store_msg(void __user *dest, struct msg_msg *msg, size_t len) 155 { 156 size_t alen; 157 struct msg_msgseg *seg; 158 159 alen = min(len, DATALEN_MSG); 160 if (copy_to_user(dest, msg + 1, alen)) 161 return -1; 162 163 for (seg = msg->next; seg != NULL; seg = seg->next) { 164 len -= alen; 165 dest = (char __user *)dest + alen; 166 alen = min(len, DATALEN_SEG); 167 if (copy_to_user(dest, seg + 1, alen)) 168 return -1; 169 } 170 return 0; 171 } 172 173 void free_msg(struct msg_msg *msg) 174 { 175 struct msg_msgseg *seg; 176 177 security_msg_msg_free(msg); 178 179 seg = msg->next; 180 kfree(msg); 181 while (seg != NULL) { 182 struct msg_msgseg *tmp = seg->next; 183 184 cond_resched(); 185 kfree(seg); 186 seg = tmp; 187 } 188 } 189