1457c8996SThomas Gleixner // SPDX-License-Identifier: GPL-2.0-only 27999096fSHerbert Xu #include <crypto/hash.h> 3d879cb83SAl Viro #include <linux/export.h> 42f8b5444SChristoph Hellwig #include <linux/bvec.h> 54d0e9df5SAlbert van der Linde #include <linux/fault-inject-usercopy.h> 6d879cb83SAl Viro #include <linux/uio.h> 7d879cb83SAl Viro #include <linux/pagemap.h> 828961998SIra Weiny #include <linux/highmem.h> 9d879cb83SAl Viro #include <linux/slab.h> 10d879cb83SAl Viro #include <linux/vmalloc.h> 11241699cdSAl Viro #include <linux/splice.h> 12bfdc5970SChristoph Hellwig #include <linux/compat.h> 13d879cb83SAl Viro #include <net/checksum.h> 14d05f4435SSagi Grimberg #include <linux/scatterlist.h> 15d0ef4c36SMarco Elver #include <linux/instrumented.h> 16d879cb83SAl Viro 17241699cdSAl Viro #define PIPE_PARANOIA /* for now */ 18241699cdSAl Viro 195c67aa90SAl Viro /* covers iovec and kvec alike */ 20d879cb83SAl Viro #define iterate_iovec(i, n, __v, __p, skip, STEP) { \ 21d879cb83SAl Viro size_t left; \ 22d879cb83SAl Viro size_t wanted = n; \ 237a1bcb5dSAl Viro do { \ 24d879cb83SAl Viro __v.iov_len = min(n, __p->iov_len - skip); \ 25d879cb83SAl Viro if (likely(__v.iov_len)) { \ 26d879cb83SAl Viro __v.iov_base = __p->iov_base + skip; \ 27d879cb83SAl Viro left = (STEP); \ 28d879cb83SAl Viro __v.iov_len -= left; \ 29d879cb83SAl Viro skip += __v.iov_len; \ 30d879cb83SAl Viro n -= __v.iov_len; \ 317a1bcb5dSAl Viro if (skip < __p->iov_len) \ 327a1bcb5dSAl Viro break; \ 33d879cb83SAl Viro } \ 34d879cb83SAl Viro __p++; \ 357a1bcb5dSAl Viro skip = 0; \ 367a1bcb5dSAl Viro } while (n); \ 37d879cb83SAl Viro n = wanted - n; \ 38d879cb83SAl Viro } 39d879cb83SAl Viro 407491a2bfSAl Viro #define iterate_bvec(i, n, __v, p, skip, STEP) { \ 417491a2bfSAl Viro size_t wanted = n; \ 427491a2bfSAl Viro while (n) { \ 437491a2bfSAl Viro unsigned offset = p->bv_offset + skip; \ 441b4fb5ffSAl Viro unsigned left; \ 45*21b56c84SAl Viro void *kaddr = kmap_local_page(p->bv_page + \ 46*21b56c84SAl Viro offset / PAGE_SIZE); \ 47*21b56c84SAl Viro __v.iov_base = kaddr + offset % PAGE_SIZE; \ 48*21b56c84SAl Viro __v.iov_len = min(min(n, p->bv_len - skip), \ 497491a2bfSAl Viro (size_t)(PAGE_SIZE - offset % PAGE_SIZE)); \ 501b4fb5ffSAl Viro left = (STEP); \ 51*21b56c84SAl Viro kunmap_local(kaddr); \ 52*21b56c84SAl Viro __v.iov_len -= left; \ 53*21b56c84SAl Viro skip += __v.iov_len; \ 547491a2bfSAl Viro if (skip == p->bv_len) { \ 557491a2bfSAl Viro skip = 0; \ 567491a2bfSAl Viro p++; \ 57d879cb83SAl Viro } \ 58*21b56c84SAl Viro n -= __v.iov_len; \ 591b4fb5ffSAl Viro if (left) \ 601b4fb5ffSAl Viro break; \ 617491a2bfSAl Viro } \ 627491a2bfSAl Viro n = wanted - n; \ 63d879cb83SAl Viro } 64d879cb83SAl Viro 657ff50620SDavid Howells #define iterate_xarray(i, n, __v, skip, STEP) { \ 661b4fb5ffSAl Viro __label__ __out; \ 677ff50620SDavid Howells struct page *head = NULL; \ 687ff50620SDavid Howells size_t wanted = n, seg, offset; \ 697ff50620SDavid Howells loff_t start = i->xarray_start + skip; \ 707ff50620SDavid Howells pgoff_t index = start >> PAGE_SHIFT; \ 717ff50620SDavid Howells int j; \ 727ff50620SDavid Howells \ 737ff50620SDavid Howells XA_STATE(xas, i->xarray, index); \ 747ff50620SDavid Howells \ 757ff50620SDavid Howells rcu_read_lock(); \ 767ff50620SDavid Howells xas_for_each(&xas, head, ULONG_MAX) { \ 771b4fb5ffSAl Viro unsigned left; \ 787ff50620SDavid Howells if (xas_retry(&xas, head)) \ 797ff50620SDavid Howells continue; \ 807ff50620SDavid Howells if (WARN_ON(xa_is_value(head))) \ 817ff50620SDavid Howells break; \ 827ff50620SDavid Howells if (WARN_ON(PageHuge(head))) \ 837ff50620SDavid Howells break; \ 847ff50620SDavid Howells for (j = (head->index < index) ? index - head->index : 0; \ 857ff50620SDavid Howells j < thp_nr_pages(head); j++) { \ 86*21b56c84SAl Viro void *kaddr = kmap_local_page(head + j); \ 87*21b56c84SAl Viro offset = (i->xarray_start + skip) % PAGE_SIZE; \ 88*21b56c84SAl Viro __v.iov_base = kaddr + offset; \ 897ff50620SDavid Howells seg = PAGE_SIZE - offset; \ 90*21b56c84SAl Viro __v.iov_len = min(n, seg); \ 911b4fb5ffSAl Viro left = (STEP); \ 92*21b56c84SAl Viro kunmap_local(kaddr); \ 93*21b56c84SAl Viro __v.iov_len -= left; \ 94*21b56c84SAl Viro n -= __v.iov_len; \ 95*21b56c84SAl Viro skip += __v.iov_len; \ 961b4fb5ffSAl Viro if (left || n == 0) \ 971b4fb5ffSAl Viro goto __out; \ 987ff50620SDavid Howells } \ 997ff50620SDavid Howells } \ 1001b4fb5ffSAl Viro __out: \ 1017ff50620SDavid Howells rcu_read_unlock(); \ 1027ff50620SDavid Howells n = wanted - n; \ 1037ff50620SDavid Howells } 1047ff50620SDavid Howells 105*21b56c84SAl Viro #define __iterate_and_advance(i, n, v, I, K) { \ 106dd254f5aSAl Viro if (unlikely(i->count < n)) \ 107dd254f5aSAl Viro n = i->count; \ 108f5da8354SAl Viro if (likely(n)) { \ 109d879cb83SAl Viro size_t skip = i->iov_offset; \ 11028f38db7SAl Viro if (likely(iter_is_iovec(i))) { \ 1115c67aa90SAl Viro const struct iovec *iov = i->iov; \ 112d879cb83SAl Viro struct iovec v; \ 113d879cb83SAl Viro iterate_iovec(i, n, v, iov, skip, (I)) \ 114d879cb83SAl Viro i->nr_segs -= iov - i->iov; \ 115d879cb83SAl Viro i->iov = iov; \ 11628f38db7SAl Viro } else if (iov_iter_is_bvec(i)) { \ 11728f38db7SAl Viro const struct bio_vec *bvec = i->bvec; \ 118*21b56c84SAl Viro struct kvec v; \ 119*21b56c84SAl Viro iterate_bvec(i, n, v, bvec, skip, (K)) \ 1207491a2bfSAl Viro i->nr_segs -= bvec - i->bvec; \ 1217491a2bfSAl Viro i->bvec = bvec; \ 12228f38db7SAl Viro } else if (iov_iter_is_kvec(i)) { \ 1235c67aa90SAl Viro const struct kvec *kvec = i->kvec; \ 12428f38db7SAl Viro struct kvec v; \ 1251b4fb5ffSAl Viro iterate_iovec(i, n, v, kvec, skip, (K)) \ 12628f38db7SAl Viro i->nr_segs -= kvec - i->kvec; \ 12728f38db7SAl Viro i->kvec = kvec; \ 12828f38db7SAl Viro } else if (iov_iter_is_xarray(i)) { \ 129*21b56c84SAl Viro struct kvec v; \ 130*21b56c84SAl Viro iterate_xarray(i, n, v, skip, (K)) \ 131d879cb83SAl Viro } \ 132d879cb83SAl Viro i->count -= n; \ 133d879cb83SAl Viro i->iov_offset = skip; \ 134dd254f5aSAl Viro } \ 135d879cb83SAl Viro } 136*21b56c84SAl Viro #define iterate_and_advance(i, n, v, I, K) \ 137*21b56c84SAl Viro __iterate_and_advance(i, n, v, I, ((void)(K),0)) 138d879cb83SAl Viro 13909fc68dcSAl Viro static int copyout(void __user *to, const void *from, size_t n) 14009fc68dcSAl Viro { 1414d0e9df5SAlbert van der Linde if (should_fail_usercopy()) 1424d0e9df5SAlbert van der Linde return n; 14396d4f267SLinus Torvalds if (access_ok(to, n)) { 144d0ef4c36SMarco Elver instrument_copy_to_user(to, from, n); 14509fc68dcSAl Viro n = raw_copy_to_user(to, from, n); 14609fc68dcSAl Viro } 14709fc68dcSAl Viro return n; 14809fc68dcSAl Viro } 14909fc68dcSAl Viro 15009fc68dcSAl Viro static int copyin(void *to, const void __user *from, size_t n) 15109fc68dcSAl Viro { 1524d0e9df5SAlbert van der Linde if (should_fail_usercopy()) 1534d0e9df5SAlbert van der Linde return n; 15496d4f267SLinus Torvalds if (access_ok(from, n)) { 155d0ef4c36SMarco Elver instrument_copy_from_user(to, from, n); 15609fc68dcSAl Viro n = raw_copy_from_user(to, from, n); 15709fc68dcSAl Viro } 15809fc68dcSAl Viro return n; 15909fc68dcSAl Viro } 16009fc68dcSAl Viro 161d879cb83SAl Viro static size_t copy_page_to_iter_iovec(struct page *page, size_t offset, size_t bytes, 162d879cb83SAl Viro struct iov_iter *i) 163d879cb83SAl Viro { 164d879cb83SAl Viro size_t skip, copy, left, wanted; 165d879cb83SAl Viro const struct iovec *iov; 166d879cb83SAl Viro char __user *buf; 167d879cb83SAl Viro void *kaddr, *from; 168d879cb83SAl Viro 169d879cb83SAl Viro if (unlikely(bytes > i->count)) 170d879cb83SAl Viro bytes = i->count; 171d879cb83SAl Viro 172d879cb83SAl Viro if (unlikely(!bytes)) 173d879cb83SAl Viro return 0; 174d879cb83SAl Viro 17509fc68dcSAl Viro might_fault(); 176d879cb83SAl Viro wanted = bytes; 177d879cb83SAl Viro iov = i->iov; 178d879cb83SAl Viro skip = i->iov_offset; 179d879cb83SAl Viro buf = iov->iov_base + skip; 180d879cb83SAl Viro copy = min(bytes, iov->iov_len - skip); 181d879cb83SAl Viro 1823fa6c507SMikulas Patocka if (IS_ENABLED(CONFIG_HIGHMEM) && !fault_in_pages_writeable(buf, copy)) { 183d879cb83SAl Viro kaddr = kmap_atomic(page); 184d879cb83SAl Viro from = kaddr + offset; 185d879cb83SAl Viro 186d879cb83SAl Viro /* first chunk, usually the only one */ 18709fc68dcSAl Viro left = copyout(buf, from, copy); 188d879cb83SAl Viro copy -= left; 189d879cb83SAl Viro skip += copy; 190d879cb83SAl Viro from += copy; 191d879cb83SAl Viro bytes -= copy; 192d879cb83SAl Viro 193d879cb83SAl Viro while (unlikely(!left && bytes)) { 194d879cb83SAl Viro iov++; 195d879cb83SAl Viro buf = iov->iov_base; 196d879cb83SAl Viro copy = min(bytes, iov->iov_len); 19709fc68dcSAl Viro left = copyout(buf, from, copy); 198d879cb83SAl Viro copy -= left; 199d879cb83SAl Viro skip = copy; 200d879cb83SAl Viro from += copy; 201d879cb83SAl Viro bytes -= copy; 202d879cb83SAl Viro } 203d879cb83SAl Viro if (likely(!bytes)) { 204d879cb83SAl Viro kunmap_atomic(kaddr); 205d879cb83SAl Viro goto done; 206d879cb83SAl Viro } 207d879cb83SAl Viro offset = from - kaddr; 208d879cb83SAl Viro buf += copy; 209d879cb83SAl Viro kunmap_atomic(kaddr); 210d879cb83SAl Viro copy = min(bytes, iov->iov_len - skip); 211d879cb83SAl Viro } 212d879cb83SAl Viro /* Too bad - revert to non-atomic kmap */ 2133fa6c507SMikulas Patocka 214d879cb83SAl Viro kaddr = kmap(page); 215d879cb83SAl Viro from = kaddr + offset; 21609fc68dcSAl Viro left = copyout(buf, from, copy); 217d879cb83SAl Viro copy -= left; 218d879cb83SAl Viro skip += copy; 219d879cb83SAl Viro from += copy; 220d879cb83SAl Viro bytes -= copy; 221d879cb83SAl Viro while (unlikely(!left && bytes)) { 222d879cb83SAl Viro iov++; 223d879cb83SAl Viro buf = iov->iov_base; 224d879cb83SAl Viro copy = min(bytes, iov->iov_len); 22509fc68dcSAl Viro left = copyout(buf, from, copy); 226d879cb83SAl Viro copy -= left; 227d879cb83SAl Viro skip = copy; 228d879cb83SAl Viro from += copy; 229d879cb83SAl Viro bytes -= copy; 230d879cb83SAl Viro } 231d879cb83SAl Viro kunmap(page); 2323fa6c507SMikulas Patocka 233d879cb83SAl Viro done: 234d879cb83SAl Viro if (skip == iov->iov_len) { 235d879cb83SAl Viro iov++; 236d879cb83SAl Viro skip = 0; 237d879cb83SAl Viro } 238d879cb83SAl Viro i->count -= wanted - bytes; 239d879cb83SAl Viro i->nr_segs -= iov - i->iov; 240d879cb83SAl Viro i->iov = iov; 241d879cb83SAl Viro i->iov_offset = skip; 242d879cb83SAl Viro return wanted - bytes; 243d879cb83SAl Viro } 244d879cb83SAl Viro 245d879cb83SAl Viro static size_t copy_page_from_iter_iovec(struct page *page, size_t offset, size_t bytes, 246d879cb83SAl Viro struct iov_iter *i) 247d879cb83SAl Viro { 248d879cb83SAl Viro size_t skip, copy, left, wanted; 249d879cb83SAl Viro const struct iovec *iov; 250d879cb83SAl Viro char __user *buf; 251d879cb83SAl Viro void *kaddr, *to; 252d879cb83SAl Viro 253d879cb83SAl Viro if (unlikely(bytes > i->count)) 254d879cb83SAl Viro bytes = i->count; 255d879cb83SAl Viro 256d879cb83SAl Viro if (unlikely(!bytes)) 257d879cb83SAl Viro return 0; 258d879cb83SAl Viro 25909fc68dcSAl Viro might_fault(); 260d879cb83SAl Viro wanted = bytes; 261d879cb83SAl Viro iov = i->iov; 262d879cb83SAl Viro skip = i->iov_offset; 263d879cb83SAl Viro buf = iov->iov_base + skip; 264d879cb83SAl Viro copy = min(bytes, iov->iov_len - skip); 265d879cb83SAl Viro 2663fa6c507SMikulas Patocka if (IS_ENABLED(CONFIG_HIGHMEM) && !fault_in_pages_readable(buf, copy)) { 267d879cb83SAl Viro kaddr = kmap_atomic(page); 268d879cb83SAl Viro to = kaddr + offset; 269d879cb83SAl Viro 270d879cb83SAl Viro /* first chunk, usually the only one */ 27109fc68dcSAl Viro left = copyin(to, buf, copy); 272d879cb83SAl Viro copy -= left; 273d879cb83SAl Viro skip += copy; 274d879cb83SAl Viro to += copy; 275d879cb83SAl Viro bytes -= copy; 276d879cb83SAl Viro 277d879cb83SAl Viro while (unlikely(!left && bytes)) { 278d879cb83SAl Viro iov++; 279d879cb83SAl Viro buf = iov->iov_base; 280d879cb83SAl Viro copy = min(bytes, iov->iov_len); 28109fc68dcSAl Viro left = copyin(to, buf, copy); 282d879cb83SAl Viro copy -= left; 283d879cb83SAl Viro skip = copy; 284d879cb83SAl Viro to += copy; 285d879cb83SAl Viro bytes -= copy; 286d879cb83SAl Viro } 287d879cb83SAl Viro if (likely(!bytes)) { 288d879cb83SAl Viro kunmap_atomic(kaddr); 289d879cb83SAl Viro goto done; 290d879cb83SAl Viro } 291d879cb83SAl Viro offset = to - kaddr; 292d879cb83SAl Viro buf += copy; 293d879cb83SAl Viro kunmap_atomic(kaddr); 294d879cb83SAl Viro copy = min(bytes, iov->iov_len - skip); 295d879cb83SAl Viro } 296d879cb83SAl Viro /* Too bad - revert to non-atomic kmap */ 2973fa6c507SMikulas Patocka 298d879cb83SAl Viro kaddr = kmap(page); 299d879cb83SAl Viro to = kaddr + offset; 30009fc68dcSAl Viro left = copyin(to, buf, copy); 301d879cb83SAl Viro copy -= left; 302d879cb83SAl Viro skip += copy; 303d879cb83SAl Viro to += copy; 304d879cb83SAl Viro bytes -= copy; 305d879cb83SAl Viro while (unlikely(!left && bytes)) { 306d879cb83SAl Viro iov++; 307d879cb83SAl Viro buf = iov->iov_base; 308d879cb83SAl Viro copy = min(bytes, iov->iov_len); 30909fc68dcSAl Viro left = copyin(to, buf, copy); 310d879cb83SAl Viro copy -= left; 311d879cb83SAl Viro skip = copy; 312d879cb83SAl Viro to += copy; 313d879cb83SAl Viro bytes -= copy; 314d879cb83SAl Viro } 315d879cb83SAl Viro kunmap(page); 3163fa6c507SMikulas Patocka 317d879cb83SAl Viro done: 318d879cb83SAl Viro if (skip == iov->iov_len) { 319d879cb83SAl Viro iov++; 320d879cb83SAl Viro skip = 0; 321d879cb83SAl Viro } 322d879cb83SAl Viro i->count -= wanted - bytes; 323d879cb83SAl Viro i->nr_segs -= iov - i->iov; 324d879cb83SAl Viro i->iov = iov; 325d879cb83SAl Viro i->iov_offset = skip; 326d879cb83SAl Viro return wanted - bytes; 327d879cb83SAl Viro } 328d879cb83SAl Viro 329241699cdSAl Viro #ifdef PIPE_PARANOIA 330241699cdSAl Viro static bool sanity(const struct iov_iter *i) 331241699cdSAl Viro { 332241699cdSAl Viro struct pipe_inode_info *pipe = i->pipe; 3338cefc107SDavid Howells unsigned int p_head = pipe->head; 3348cefc107SDavid Howells unsigned int p_tail = pipe->tail; 3358cefc107SDavid Howells unsigned int p_mask = pipe->ring_size - 1; 3368cefc107SDavid Howells unsigned int p_occupancy = pipe_occupancy(p_head, p_tail); 3378cefc107SDavid Howells unsigned int i_head = i->head; 3388cefc107SDavid Howells unsigned int idx; 3398cefc107SDavid Howells 340241699cdSAl Viro if (i->iov_offset) { 341241699cdSAl Viro struct pipe_buffer *p; 3428cefc107SDavid Howells if (unlikely(p_occupancy == 0)) 343241699cdSAl Viro goto Bad; // pipe must be non-empty 3448cefc107SDavid Howells if (unlikely(i_head != p_head - 1)) 345241699cdSAl Viro goto Bad; // must be at the last buffer... 346241699cdSAl Viro 3478cefc107SDavid Howells p = &pipe->bufs[i_head & p_mask]; 348241699cdSAl Viro if (unlikely(p->offset + p->len != i->iov_offset)) 349241699cdSAl Viro goto Bad; // ... at the end of segment 350241699cdSAl Viro } else { 3518cefc107SDavid Howells if (i_head != p_head) 352241699cdSAl Viro goto Bad; // must be right after the last buffer 353241699cdSAl Viro } 354241699cdSAl Viro return true; 355241699cdSAl Viro Bad: 3568cefc107SDavid Howells printk(KERN_ERR "idx = %d, offset = %zd\n", i_head, i->iov_offset); 3578cefc107SDavid Howells printk(KERN_ERR "head = %d, tail = %d, buffers = %d\n", 3588cefc107SDavid Howells p_head, p_tail, pipe->ring_size); 3598cefc107SDavid Howells for (idx = 0; idx < pipe->ring_size; idx++) 360241699cdSAl Viro printk(KERN_ERR "[%p %p %d %d]\n", 361241699cdSAl Viro pipe->bufs[idx].ops, 362241699cdSAl Viro pipe->bufs[idx].page, 363241699cdSAl Viro pipe->bufs[idx].offset, 364241699cdSAl Viro pipe->bufs[idx].len); 365241699cdSAl Viro WARN_ON(1); 366241699cdSAl Viro return false; 367241699cdSAl Viro } 368241699cdSAl Viro #else 369241699cdSAl Viro #define sanity(i) true 370241699cdSAl Viro #endif 371241699cdSAl Viro 372241699cdSAl Viro static size_t copy_page_to_iter_pipe(struct page *page, size_t offset, size_t bytes, 373241699cdSAl Viro struct iov_iter *i) 374241699cdSAl Viro { 375241699cdSAl Viro struct pipe_inode_info *pipe = i->pipe; 376241699cdSAl Viro struct pipe_buffer *buf; 3778cefc107SDavid Howells unsigned int p_tail = pipe->tail; 3788cefc107SDavid Howells unsigned int p_mask = pipe->ring_size - 1; 3798cefc107SDavid Howells unsigned int i_head = i->head; 380241699cdSAl Viro size_t off; 381241699cdSAl Viro 382241699cdSAl Viro if (unlikely(bytes > i->count)) 383241699cdSAl Viro bytes = i->count; 384241699cdSAl Viro 385241699cdSAl Viro if (unlikely(!bytes)) 386241699cdSAl Viro return 0; 387241699cdSAl Viro 388241699cdSAl Viro if (!sanity(i)) 389241699cdSAl Viro return 0; 390241699cdSAl Viro 391241699cdSAl Viro off = i->iov_offset; 3928cefc107SDavid Howells buf = &pipe->bufs[i_head & p_mask]; 393241699cdSAl Viro if (off) { 394241699cdSAl Viro if (offset == off && buf->page == page) { 395241699cdSAl Viro /* merge with the last one */ 396241699cdSAl Viro buf->len += bytes; 397241699cdSAl Viro i->iov_offset += bytes; 398241699cdSAl Viro goto out; 399241699cdSAl Viro } 4008cefc107SDavid Howells i_head++; 4018cefc107SDavid Howells buf = &pipe->bufs[i_head & p_mask]; 402241699cdSAl Viro } 4036718b6f8SDavid Howells if (pipe_full(i_head, p_tail, pipe->max_usage)) 404241699cdSAl Viro return 0; 4058cefc107SDavid Howells 406241699cdSAl Viro buf->ops = &page_cache_pipe_buf_ops; 4078cefc107SDavid Howells get_page(page); 4088cefc107SDavid Howells buf->page = page; 409241699cdSAl Viro buf->offset = offset; 410241699cdSAl Viro buf->len = bytes; 4118cefc107SDavid Howells 4128cefc107SDavid Howells pipe->head = i_head + 1; 413241699cdSAl Viro i->iov_offset = offset + bytes; 4148cefc107SDavid Howells i->head = i_head; 415241699cdSAl Viro out: 416241699cdSAl Viro i->count -= bytes; 417241699cdSAl Viro return bytes; 418241699cdSAl Viro } 419241699cdSAl Viro 420d879cb83SAl Viro /* 421171a0203SAnton Altaparmakov * Fault in one or more iovecs of the given iov_iter, to a maximum length of 422171a0203SAnton Altaparmakov * bytes. For each iovec, fault in each page that constitutes the iovec. 423171a0203SAnton Altaparmakov * 424171a0203SAnton Altaparmakov * Return 0 on success, or non-zero if the memory could not be accessed (i.e. 425171a0203SAnton Altaparmakov * because it is an invalid address). 426171a0203SAnton Altaparmakov */ 4278409a0d2SAl Viro int iov_iter_fault_in_readable(const struct iov_iter *i, size_t bytes) 428171a0203SAnton Altaparmakov { 4290e8f0d67SAl Viro if (iter_is_iovec(i)) { 4308409a0d2SAl Viro const struct iovec *p; 4318409a0d2SAl Viro size_t skip; 4328409a0d2SAl Viro 4338409a0d2SAl Viro if (bytes > i->count) 4348409a0d2SAl Viro bytes = i->count; 4358409a0d2SAl Viro for (p = i->iov, skip = i->iov_offset; bytes; p++, skip = 0) { 4368409a0d2SAl Viro size_t len = min(bytes, p->iov_len - skip); 4378409a0d2SAl Viro int err; 4388409a0d2SAl Viro 4398409a0d2SAl Viro if (unlikely(!len)) 4408409a0d2SAl Viro continue; 4418409a0d2SAl Viro err = fault_in_pages_readable(p->iov_base + skip, len); 442171a0203SAnton Altaparmakov if (unlikely(err)) 443171a0203SAnton Altaparmakov return err; 4448409a0d2SAl Viro bytes -= len; 4458409a0d2SAl Viro } 446171a0203SAnton Altaparmakov } 447171a0203SAnton Altaparmakov return 0; 448171a0203SAnton Altaparmakov } 449d4690f1eSAl Viro EXPORT_SYMBOL(iov_iter_fault_in_readable); 450171a0203SAnton Altaparmakov 451aa563d7bSDavid Howells void iov_iter_init(struct iov_iter *i, unsigned int direction, 452d879cb83SAl Viro const struct iovec *iov, unsigned long nr_segs, 453d879cb83SAl Viro size_t count) 454d879cb83SAl Viro { 455aa563d7bSDavid Howells WARN_ON(direction & ~(READ | WRITE)); 4568cd54c1cSAl Viro WARN_ON_ONCE(uaccess_kernel()); 4578cd54c1cSAl Viro *i = (struct iov_iter) { 4588cd54c1cSAl Viro .iter_type = ITER_IOVEC, 4598cd54c1cSAl Viro .data_source = direction, 4608cd54c1cSAl Viro .iov = iov, 4618cd54c1cSAl Viro .nr_segs = nr_segs, 4628cd54c1cSAl Viro .iov_offset = 0, 4638cd54c1cSAl Viro .count = count 4648cd54c1cSAl Viro }; 465d879cb83SAl Viro } 466d879cb83SAl Viro EXPORT_SYMBOL(iov_iter_init); 467d879cb83SAl Viro 468241699cdSAl Viro static inline bool allocated(struct pipe_buffer *buf) 469241699cdSAl Viro { 470241699cdSAl Viro return buf->ops == &default_pipe_buf_ops; 471241699cdSAl Viro } 472241699cdSAl Viro 4738cefc107SDavid Howells static inline void data_start(const struct iov_iter *i, 4748cefc107SDavid Howells unsigned int *iter_headp, size_t *offp) 475241699cdSAl Viro { 4768cefc107SDavid Howells unsigned int p_mask = i->pipe->ring_size - 1; 4778cefc107SDavid Howells unsigned int iter_head = i->head; 478241699cdSAl Viro size_t off = i->iov_offset; 4798cefc107SDavid Howells 4808cefc107SDavid Howells if (off && (!allocated(&i->pipe->bufs[iter_head & p_mask]) || 4818cefc107SDavid Howells off == PAGE_SIZE)) { 4828cefc107SDavid Howells iter_head++; 483241699cdSAl Viro off = 0; 484241699cdSAl Viro } 4858cefc107SDavid Howells *iter_headp = iter_head; 486241699cdSAl Viro *offp = off; 487241699cdSAl Viro } 488241699cdSAl Viro 489241699cdSAl Viro static size_t push_pipe(struct iov_iter *i, size_t size, 4908cefc107SDavid Howells int *iter_headp, size_t *offp) 491241699cdSAl Viro { 492241699cdSAl Viro struct pipe_inode_info *pipe = i->pipe; 4938cefc107SDavid Howells unsigned int p_tail = pipe->tail; 4948cefc107SDavid Howells unsigned int p_mask = pipe->ring_size - 1; 4958cefc107SDavid Howells unsigned int iter_head; 496241699cdSAl Viro size_t off; 497241699cdSAl Viro ssize_t left; 498241699cdSAl Viro 499241699cdSAl Viro if (unlikely(size > i->count)) 500241699cdSAl Viro size = i->count; 501241699cdSAl Viro if (unlikely(!size)) 502241699cdSAl Viro return 0; 503241699cdSAl Viro 504241699cdSAl Viro left = size; 5058cefc107SDavid Howells data_start(i, &iter_head, &off); 5068cefc107SDavid Howells *iter_headp = iter_head; 507241699cdSAl Viro *offp = off; 508241699cdSAl Viro if (off) { 509241699cdSAl Viro left -= PAGE_SIZE - off; 510241699cdSAl Viro if (left <= 0) { 5118cefc107SDavid Howells pipe->bufs[iter_head & p_mask].len += size; 512241699cdSAl Viro return size; 513241699cdSAl Viro } 5148cefc107SDavid Howells pipe->bufs[iter_head & p_mask].len = PAGE_SIZE; 5158cefc107SDavid Howells iter_head++; 516241699cdSAl Viro } 5176718b6f8SDavid Howells while (!pipe_full(iter_head, p_tail, pipe->max_usage)) { 5188cefc107SDavid Howells struct pipe_buffer *buf = &pipe->bufs[iter_head & p_mask]; 519241699cdSAl Viro struct page *page = alloc_page(GFP_USER); 520241699cdSAl Viro if (!page) 521241699cdSAl Viro break; 5228cefc107SDavid Howells 5238cefc107SDavid Howells buf->ops = &default_pipe_buf_ops; 5248cefc107SDavid Howells buf->page = page; 5258cefc107SDavid Howells buf->offset = 0; 5268cefc107SDavid Howells buf->len = min_t(ssize_t, left, PAGE_SIZE); 5278cefc107SDavid Howells left -= buf->len; 5288cefc107SDavid Howells iter_head++; 5298cefc107SDavid Howells pipe->head = iter_head; 5308cefc107SDavid Howells 5318cefc107SDavid Howells if (left == 0) 532241699cdSAl Viro return size; 533241699cdSAl Viro } 534241699cdSAl Viro return size - left; 535241699cdSAl Viro } 536241699cdSAl Viro 537241699cdSAl Viro static size_t copy_pipe_to_iter(const void *addr, size_t bytes, 538241699cdSAl Viro struct iov_iter *i) 539241699cdSAl Viro { 540241699cdSAl Viro struct pipe_inode_info *pipe = i->pipe; 5418cefc107SDavid Howells unsigned int p_mask = pipe->ring_size - 1; 5428cefc107SDavid Howells unsigned int i_head; 543241699cdSAl Viro size_t n, off; 544241699cdSAl Viro 545241699cdSAl Viro if (!sanity(i)) 546241699cdSAl Viro return 0; 547241699cdSAl Viro 5488cefc107SDavid Howells bytes = n = push_pipe(i, bytes, &i_head, &off); 549241699cdSAl Viro if (unlikely(!n)) 550241699cdSAl Viro return 0; 5518cefc107SDavid Howells do { 552241699cdSAl Viro size_t chunk = min_t(size_t, n, PAGE_SIZE - off); 5538cefc107SDavid Howells memcpy_to_page(pipe->bufs[i_head & p_mask].page, off, addr, chunk); 5548cefc107SDavid Howells i->head = i_head; 555241699cdSAl Viro i->iov_offset = off + chunk; 556241699cdSAl Viro n -= chunk; 557241699cdSAl Viro addr += chunk; 5588cefc107SDavid Howells off = 0; 5598cefc107SDavid Howells i_head++; 5608cefc107SDavid Howells } while (n); 561241699cdSAl Viro i->count -= bytes; 562241699cdSAl Viro return bytes; 563241699cdSAl Viro } 564241699cdSAl Viro 565f9152895SAl Viro static __wsum csum_and_memcpy(void *to, const void *from, size_t len, 566f9152895SAl Viro __wsum sum, size_t off) 567f9152895SAl Viro { 568cc44c17bSAl Viro __wsum next = csum_partial_copy_nocheck(from, to, len); 569f9152895SAl Viro return csum_block_add(sum, next, off); 570f9152895SAl Viro } 571f9152895SAl Viro 57278e1f386SAl Viro static size_t csum_and_copy_to_pipe_iter(const void *addr, size_t bytes, 57352cbd23aSWillem de Bruijn struct csum_state *csstate, 57452cbd23aSWillem de Bruijn struct iov_iter *i) 57578e1f386SAl Viro { 57678e1f386SAl Viro struct pipe_inode_info *pipe = i->pipe; 5778cefc107SDavid Howells unsigned int p_mask = pipe->ring_size - 1; 57852cbd23aSWillem de Bruijn __wsum sum = csstate->csum; 57952cbd23aSWillem de Bruijn size_t off = csstate->off; 5808cefc107SDavid Howells unsigned int i_head; 58178e1f386SAl Viro size_t n, r; 58278e1f386SAl Viro 58378e1f386SAl Viro if (!sanity(i)) 58478e1f386SAl Viro return 0; 58578e1f386SAl Viro 5868cefc107SDavid Howells bytes = n = push_pipe(i, bytes, &i_head, &r); 58778e1f386SAl Viro if (unlikely(!n)) 58878e1f386SAl Viro return 0; 5898cefc107SDavid Howells do { 59078e1f386SAl Viro size_t chunk = min_t(size_t, n, PAGE_SIZE - r); 5918cefc107SDavid Howells char *p = kmap_atomic(pipe->bufs[i_head & p_mask].page); 592f9152895SAl Viro sum = csum_and_memcpy(p + r, addr, chunk, sum, off); 59378e1f386SAl Viro kunmap_atomic(p); 5948cefc107SDavid Howells i->head = i_head; 59578e1f386SAl Viro i->iov_offset = r + chunk; 59678e1f386SAl Viro n -= chunk; 59778e1f386SAl Viro off += chunk; 59878e1f386SAl Viro addr += chunk; 5998cefc107SDavid Howells r = 0; 6008cefc107SDavid Howells i_head++; 6018cefc107SDavid Howells } while (n); 60278e1f386SAl Viro i->count -= bytes; 60352cbd23aSWillem de Bruijn csstate->csum = sum; 60452cbd23aSWillem de Bruijn csstate->off = off; 60578e1f386SAl Viro return bytes; 60678e1f386SAl Viro } 60778e1f386SAl Viro 608aa28de27SAl Viro size_t _copy_to_iter(const void *addr, size_t bytes, struct iov_iter *i) 609d879cb83SAl Viro { 61036f7a8a4SAl Viro const char *from = addr; 61100e23707SDavid Howells if (unlikely(iov_iter_is_pipe(i))) 612241699cdSAl Viro return copy_pipe_to_iter(addr, bytes, i); 61309fc68dcSAl Viro if (iter_is_iovec(i)) 61409fc68dcSAl Viro might_fault(); 615d879cb83SAl Viro iterate_and_advance(i, bytes, v, 61609fc68dcSAl Viro copyout(v.iov_base, (from += v.iov_len) - v.iov_len, v.iov_len), 617*21b56c84SAl Viro memcpy(v.iov_base, (from += v.iov_len) - v.iov_len, v.iov_len) 618d879cb83SAl Viro ) 619d879cb83SAl Viro 620d879cb83SAl Viro return bytes; 621d879cb83SAl Viro } 622aa28de27SAl Viro EXPORT_SYMBOL(_copy_to_iter); 623d879cb83SAl Viro 624ec6347bbSDan Williams #ifdef CONFIG_ARCH_HAS_COPY_MC 625ec6347bbSDan Williams static int copyout_mc(void __user *to, const void *from, size_t n) 6268780356eSDan Williams { 62796d4f267SLinus Torvalds if (access_ok(to, n)) { 628d0ef4c36SMarco Elver instrument_copy_to_user(to, from, n); 629ec6347bbSDan Williams n = copy_mc_to_user((__force void *) to, from, n); 6308780356eSDan Williams } 6318780356eSDan Williams return n; 6328780356eSDan Williams } 6338780356eSDan Williams 634ec6347bbSDan Williams static unsigned long copy_mc_to_page(struct page *page, size_t offset, 6358780356eSDan Williams const char *from, size_t len) 6368780356eSDan Williams { 6378780356eSDan Williams unsigned long ret; 6388780356eSDan Williams char *to; 6398780356eSDan Williams 6408780356eSDan Williams to = kmap_atomic(page); 641ec6347bbSDan Williams ret = copy_mc_to_kernel(to + offset, from, len); 6428780356eSDan Williams kunmap_atomic(to); 6438780356eSDan Williams 6448780356eSDan Williams return ret; 6458780356eSDan Williams } 6468780356eSDan Williams 647ec6347bbSDan Williams static size_t copy_mc_pipe_to_iter(const void *addr, size_t bytes, 648ca146f6fSDan Williams struct iov_iter *i) 649ca146f6fSDan Williams { 650ca146f6fSDan Williams struct pipe_inode_info *pipe = i->pipe; 6518cefc107SDavid Howells unsigned int p_mask = pipe->ring_size - 1; 6528cefc107SDavid Howells unsigned int i_head; 653ca146f6fSDan Williams size_t n, off, xfer = 0; 654ca146f6fSDan Williams 655ca146f6fSDan Williams if (!sanity(i)) 656ca146f6fSDan Williams return 0; 657ca146f6fSDan Williams 6588cefc107SDavid Howells bytes = n = push_pipe(i, bytes, &i_head, &off); 659ca146f6fSDan Williams if (unlikely(!n)) 660ca146f6fSDan Williams return 0; 6618cefc107SDavid Howells do { 662ca146f6fSDan Williams size_t chunk = min_t(size_t, n, PAGE_SIZE - off); 663ca146f6fSDan Williams unsigned long rem; 664ca146f6fSDan Williams 665ec6347bbSDan Williams rem = copy_mc_to_page(pipe->bufs[i_head & p_mask].page, 6668cefc107SDavid Howells off, addr, chunk); 6678cefc107SDavid Howells i->head = i_head; 668ca146f6fSDan Williams i->iov_offset = off + chunk - rem; 669ca146f6fSDan Williams xfer += chunk - rem; 670ca146f6fSDan Williams if (rem) 671ca146f6fSDan Williams break; 672ca146f6fSDan Williams n -= chunk; 673ca146f6fSDan Williams addr += chunk; 6748cefc107SDavid Howells off = 0; 6758cefc107SDavid Howells i_head++; 6768cefc107SDavid Howells } while (n); 677ca146f6fSDan Williams i->count -= xfer; 678ca146f6fSDan Williams return xfer; 679ca146f6fSDan Williams } 680ca146f6fSDan Williams 681bf3eeb9bSDan Williams /** 682ec6347bbSDan Williams * _copy_mc_to_iter - copy to iter with source memory error exception handling 683bf3eeb9bSDan Williams * @addr: source kernel address 684bf3eeb9bSDan Williams * @bytes: total transfer length 685bf3eeb9bSDan Williams * @iter: destination iterator 686bf3eeb9bSDan Williams * 687ec6347bbSDan Williams * The pmem driver deploys this for the dax operation 688ec6347bbSDan Williams * (dax_copy_to_iter()) for dax reads (bypass page-cache and the 689ec6347bbSDan Williams * block-layer). Upon #MC read(2) aborts and returns EIO or the bytes 690ec6347bbSDan Williams * successfully copied. 691bf3eeb9bSDan Williams * 692ec6347bbSDan Williams * The main differences between this and typical _copy_to_iter(). 693bf3eeb9bSDan Williams * 694bf3eeb9bSDan Williams * * Typical tail/residue handling after a fault retries the copy 695bf3eeb9bSDan Williams * byte-by-byte until the fault happens again. Re-triggering machine 696bf3eeb9bSDan Williams * checks is potentially fatal so the implementation uses source 697bf3eeb9bSDan Williams * alignment and poison alignment assumptions to avoid re-triggering 698bf3eeb9bSDan Williams * hardware exceptions. 699bf3eeb9bSDan Williams * 700bf3eeb9bSDan Williams * * ITER_KVEC, ITER_PIPE, and ITER_BVEC can return short copies. 701bf3eeb9bSDan Williams * Compare to copy_to_iter() where only ITER_IOVEC attempts might return 702bf3eeb9bSDan Williams * a short copy. 703bf3eeb9bSDan Williams */ 704ec6347bbSDan Williams size_t _copy_mc_to_iter(const void *addr, size_t bytes, struct iov_iter *i) 7058780356eSDan Williams { 7068780356eSDan Williams const char *from = addr; 7078780356eSDan Williams 70800e23707SDavid Howells if (unlikely(iov_iter_is_pipe(i))) 709ec6347bbSDan Williams return copy_mc_pipe_to_iter(addr, bytes, i); 7108780356eSDan Williams if (iter_is_iovec(i)) 7118780356eSDan Williams might_fault(); 7121b4fb5ffSAl Viro __iterate_and_advance(i, bytes, v, 713ec6347bbSDan Williams copyout_mc(v.iov_base, (from += v.iov_len) - v.iov_len, 714ec6347bbSDan Williams v.iov_len), 7151b4fb5ffSAl Viro copy_mc_to_kernel(v.iov_base, (from += v.iov_len) 716*21b56c84SAl Viro - v.iov_len, v.iov_len) 7178780356eSDan Williams ) 7188780356eSDan Williams 7198780356eSDan Williams return bytes; 7208780356eSDan Williams } 721ec6347bbSDan Williams EXPORT_SYMBOL_GPL(_copy_mc_to_iter); 722ec6347bbSDan Williams #endif /* CONFIG_ARCH_HAS_COPY_MC */ 7238780356eSDan Williams 724aa28de27SAl Viro size_t _copy_from_iter(void *addr, size_t bytes, struct iov_iter *i) 725d879cb83SAl Viro { 726d879cb83SAl Viro char *to = addr; 72700e23707SDavid Howells if (unlikely(iov_iter_is_pipe(i))) { 728241699cdSAl Viro WARN_ON(1); 729241699cdSAl Viro return 0; 730241699cdSAl Viro } 73109fc68dcSAl Viro if (iter_is_iovec(i)) 73209fc68dcSAl Viro might_fault(); 733d879cb83SAl Viro iterate_and_advance(i, bytes, v, 73409fc68dcSAl Viro copyin((to += v.iov_len) - v.iov_len, v.iov_base, v.iov_len), 735*21b56c84SAl Viro memcpy((to += v.iov_len) - v.iov_len, v.iov_base, v.iov_len) 736d879cb83SAl Viro ) 737d879cb83SAl Viro 738d879cb83SAl Viro return bytes; 739d879cb83SAl Viro } 740aa28de27SAl Viro EXPORT_SYMBOL(_copy_from_iter); 741d879cb83SAl Viro 742aa28de27SAl Viro size_t _copy_from_iter_nocache(void *addr, size_t bytes, struct iov_iter *i) 743d879cb83SAl Viro { 744d879cb83SAl Viro char *to = addr; 74500e23707SDavid Howells if (unlikely(iov_iter_is_pipe(i))) { 746241699cdSAl Viro WARN_ON(1); 747241699cdSAl Viro return 0; 748241699cdSAl Viro } 749d879cb83SAl Viro iterate_and_advance(i, bytes, v, 7503f763453SAl Viro __copy_from_user_inatomic_nocache((to += v.iov_len) - v.iov_len, 751d879cb83SAl Viro v.iov_base, v.iov_len), 752*21b56c84SAl Viro memcpy((to += v.iov_len) - v.iov_len, v.iov_base, v.iov_len) 753d879cb83SAl Viro ) 754d879cb83SAl Viro 755d879cb83SAl Viro return bytes; 756d879cb83SAl Viro } 757aa28de27SAl Viro EXPORT_SYMBOL(_copy_from_iter_nocache); 758d879cb83SAl Viro 7590aed55afSDan Williams #ifdef CONFIG_ARCH_HAS_UACCESS_FLUSHCACHE 760abd08d7dSDan Williams /** 761abd08d7dSDan Williams * _copy_from_iter_flushcache - write destination through cpu cache 762abd08d7dSDan Williams * @addr: destination kernel address 763abd08d7dSDan Williams * @bytes: total transfer length 764abd08d7dSDan Williams * @iter: source iterator 765abd08d7dSDan Williams * 766abd08d7dSDan Williams * The pmem driver arranges for filesystem-dax to use this facility via 767abd08d7dSDan Williams * dax_copy_from_iter() for ensuring that writes to persistent memory 768abd08d7dSDan Williams * are flushed through the CPU cache. It is differentiated from 769abd08d7dSDan Williams * _copy_from_iter_nocache() in that guarantees all data is flushed for 770abd08d7dSDan Williams * all iterator types. The _copy_from_iter_nocache() only attempts to 771abd08d7dSDan Williams * bypass the cache for the ITER_IOVEC case, and on some archs may use 772abd08d7dSDan Williams * instructions that strand dirty-data in the cache. 773abd08d7dSDan Williams */ 7746a37e940SLinus Torvalds size_t _copy_from_iter_flushcache(void *addr, size_t bytes, struct iov_iter *i) 7750aed55afSDan Williams { 7760aed55afSDan Williams char *to = addr; 77700e23707SDavid Howells if (unlikely(iov_iter_is_pipe(i))) { 7780aed55afSDan Williams WARN_ON(1); 7790aed55afSDan Williams return 0; 7800aed55afSDan Williams } 7810aed55afSDan Williams iterate_and_advance(i, bytes, v, 7820aed55afSDan Williams __copy_from_user_flushcache((to += v.iov_len) - v.iov_len, 7830aed55afSDan Williams v.iov_base, v.iov_len), 7840aed55afSDan Williams memcpy_flushcache((to += v.iov_len) - v.iov_len, v.iov_base, 785*21b56c84SAl Viro v.iov_len) 7860aed55afSDan Williams ) 7870aed55afSDan Williams 7880aed55afSDan Williams return bytes; 7890aed55afSDan Williams } 7906a37e940SLinus Torvalds EXPORT_SYMBOL_GPL(_copy_from_iter_flushcache); 7910aed55afSDan Williams #endif 7920aed55afSDan Williams 79372e809edSAl Viro static inline bool page_copy_sane(struct page *page, size_t offset, size_t n) 79472e809edSAl Viro { 7956daef95bSEric Dumazet struct page *head; 7966daef95bSEric Dumazet size_t v = n + offset; 7976daef95bSEric Dumazet 7986daef95bSEric Dumazet /* 7996daef95bSEric Dumazet * The general case needs to access the page order in order 8006daef95bSEric Dumazet * to compute the page size. 8016daef95bSEric Dumazet * However, we mostly deal with order-0 pages and thus can 8026daef95bSEric Dumazet * avoid a possible cache line miss for requests that fit all 8036daef95bSEric Dumazet * page orders. 8046daef95bSEric Dumazet */ 8056daef95bSEric Dumazet if (n <= v && v <= PAGE_SIZE) 8066daef95bSEric Dumazet return true; 8076daef95bSEric Dumazet 8086daef95bSEric Dumazet head = compound_head(page); 8096daef95bSEric Dumazet v += (page - head) << PAGE_SHIFT; 810a90bcb86SPetar Penkov 811a50b854eSMatthew Wilcox (Oracle) if (likely(n <= v && v <= (page_size(head)))) 81272e809edSAl Viro return true; 81372e809edSAl Viro WARN_ON(1); 81472e809edSAl Viro return false; 81572e809edSAl Viro } 816cbbd26b8SAl Viro 81708aa6479SAl Viro static size_t __copy_page_to_iter(struct page *page, size_t offset, size_t bytes, 818d879cb83SAl Viro struct iov_iter *i) 819d879cb83SAl Viro { 82028f38db7SAl Viro if (likely(iter_is_iovec(i))) 82128f38db7SAl Viro return copy_page_to_iter_iovec(page, offset, bytes, i); 82228f38db7SAl Viro if (iov_iter_is_bvec(i) || iov_iter_is_kvec(i) || iov_iter_is_xarray(i)) { 823d879cb83SAl Viro void *kaddr = kmap_atomic(page); 824d879cb83SAl Viro size_t wanted = copy_to_iter(kaddr + offset, bytes, i); 825d879cb83SAl Viro kunmap_atomic(kaddr); 826d879cb83SAl Viro return wanted; 82728f38db7SAl Viro } 82828f38db7SAl Viro if (iov_iter_is_pipe(i)) 82928f38db7SAl Viro return copy_page_to_iter_pipe(page, offset, bytes, i); 83028f38db7SAl Viro if (unlikely(iov_iter_is_discard(i))) { 831a506abc7SAl Viro if (unlikely(i->count < bytes)) 832a506abc7SAl Viro bytes = i->count; 833a506abc7SAl Viro i->count -= bytes; 8349ea9ce04SDavid Howells return bytes; 83528f38db7SAl Viro } 83628f38db7SAl Viro WARN_ON(1); 83728f38db7SAl Viro return 0; 838d879cb83SAl Viro } 83908aa6479SAl Viro 84008aa6479SAl Viro size_t copy_page_to_iter(struct page *page, size_t offset, size_t bytes, 84108aa6479SAl Viro struct iov_iter *i) 84208aa6479SAl Viro { 84308aa6479SAl Viro size_t res = 0; 84408aa6479SAl Viro if (unlikely(!page_copy_sane(page, offset, bytes))) 84508aa6479SAl Viro return 0; 84608aa6479SAl Viro page += offset / PAGE_SIZE; // first subpage 84708aa6479SAl Viro offset %= PAGE_SIZE; 84808aa6479SAl Viro while (1) { 84908aa6479SAl Viro size_t n = __copy_page_to_iter(page, offset, 85008aa6479SAl Viro min(bytes, (size_t)PAGE_SIZE - offset), i); 85108aa6479SAl Viro res += n; 85208aa6479SAl Viro bytes -= n; 85308aa6479SAl Viro if (!bytes || !n) 85408aa6479SAl Viro break; 85508aa6479SAl Viro offset += n; 85608aa6479SAl Viro if (offset == PAGE_SIZE) { 85708aa6479SAl Viro page++; 85808aa6479SAl Viro offset = 0; 85908aa6479SAl Viro } 86008aa6479SAl Viro } 86108aa6479SAl Viro return res; 86208aa6479SAl Viro } 863d879cb83SAl Viro EXPORT_SYMBOL(copy_page_to_iter); 864d879cb83SAl Viro 865d879cb83SAl Viro size_t copy_page_from_iter(struct page *page, size_t offset, size_t bytes, 866d879cb83SAl Viro struct iov_iter *i) 867d879cb83SAl Viro { 86872e809edSAl Viro if (unlikely(!page_copy_sane(page, offset, bytes))) 86972e809edSAl Viro return 0; 87028f38db7SAl Viro if (likely(iter_is_iovec(i))) 87128f38db7SAl Viro return copy_page_from_iter_iovec(page, offset, bytes, i); 87228f38db7SAl Viro if (iov_iter_is_bvec(i) || iov_iter_is_kvec(i) || iov_iter_is_xarray(i)) { 873d879cb83SAl Viro void *kaddr = kmap_atomic(page); 874aa28de27SAl Viro size_t wanted = _copy_from_iter(kaddr + offset, bytes, i); 875d879cb83SAl Viro kunmap_atomic(kaddr); 876d879cb83SAl Viro return wanted; 87728f38db7SAl Viro } 87828f38db7SAl Viro WARN_ON(1); 87928f38db7SAl Viro return 0; 880d879cb83SAl Viro } 881d879cb83SAl Viro EXPORT_SYMBOL(copy_page_from_iter); 882d879cb83SAl Viro 883241699cdSAl Viro static size_t pipe_zero(size_t bytes, struct iov_iter *i) 884241699cdSAl Viro { 885241699cdSAl Viro struct pipe_inode_info *pipe = i->pipe; 8868cefc107SDavid Howells unsigned int p_mask = pipe->ring_size - 1; 8878cefc107SDavid Howells unsigned int i_head; 888241699cdSAl Viro size_t n, off; 889241699cdSAl Viro 890241699cdSAl Viro if (!sanity(i)) 891241699cdSAl Viro return 0; 892241699cdSAl Viro 8938cefc107SDavid Howells bytes = n = push_pipe(i, bytes, &i_head, &off); 894241699cdSAl Viro if (unlikely(!n)) 895241699cdSAl Viro return 0; 896241699cdSAl Viro 8978cefc107SDavid Howells do { 898241699cdSAl Viro size_t chunk = min_t(size_t, n, PAGE_SIZE - off); 8998cefc107SDavid Howells memzero_page(pipe->bufs[i_head & p_mask].page, off, chunk); 9008cefc107SDavid Howells i->head = i_head; 901241699cdSAl Viro i->iov_offset = off + chunk; 902241699cdSAl Viro n -= chunk; 9038cefc107SDavid Howells off = 0; 9048cefc107SDavid Howells i_head++; 9058cefc107SDavid Howells } while (n); 906241699cdSAl Viro i->count -= bytes; 907241699cdSAl Viro return bytes; 908241699cdSAl Viro } 909241699cdSAl Viro 910d879cb83SAl Viro size_t iov_iter_zero(size_t bytes, struct iov_iter *i) 911d879cb83SAl Viro { 91200e23707SDavid Howells if (unlikely(iov_iter_is_pipe(i))) 913241699cdSAl Viro return pipe_zero(bytes, i); 914d879cb83SAl Viro iterate_and_advance(i, bytes, v, 91509fc68dcSAl Viro clear_user(v.iov_base, v.iov_len), 916*21b56c84SAl Viro memset(v.iov_base, 0, v.iov_len) 917d879cb83SAl Viro ) 918d879cb83SAl Viro 919d879cb83SAl Viro return bytes; 920d879cb83SAl Viro } 921d879cb83SAl Viro EXPORT_SYMBOL(iov_iter_zero); 922d879cb83SAl Viro 923f0b65f39SAl Viro size_t copy_page_from_iter_atomic(struct page *page, unsigned offset, size_t bytes, 924f0b65f39SAl Viro struct iov_iter *i) 925d879cb83SAl Viro { 926d879cb83SAl Viro char *kaddr = kmap_atomic(page), *p = kaddr + offset; 92772e809edSAl Viro if (unlikely(!page_copy_sane(page, offset, bytes))) { 92872e809edSAl Viro kunmap_atomic(kaddr); 92972e809edSAl Viro return 0; 93072e809edSAl Viro } 9319ea9ce04SDavid Howells if (unlikely(iov_iter_is_pipe(i) || iov_iter_is_discard(i))) { 932241699cdSAl Viro kunmap_atomic(kaddr); 933241699cdSAl Viro WARN_ON(1); 934241699cdSAl Viro return 0; 935241699cdSAl Viro } 936f0b65f39SAl Viro iterate_and_advance(i, bytes, v, 93709fc68dcSAl Viro copyin((p += v.iov_len) - v.iov_len, v.iov_base, v.iov_len), 938*21b56c84SAl Viro memcpy((p += v.iov_len) - v.iov_len, v.iov_base, v.iov_len) 939d879cb83SAl Viro ) 940d879cb83SAl Viro kunmap_atomic(kaddr); 941d879cb83SAl Viro return bytes; 942d879cb83SAl Viro } 943f0b65f39SAl Viro EXPORT_SYMBOL(copy_page_from_iter_atomic); 944d879cb83SAl Viro 945b9dc6f65SAl Viro static inline void pipe_truncate(struct iov_iter *i) 946241699cdSAl Viro { 947241699cdSAl Viro struct pipe_inode_info *pipe = i->pipe; 9488cefc107SDavid Howells unsigned int p_tail = pipe->tail; 9498cefc107SDavid Howells unsigned int p_head = pipe->head; 9508cefc107SDavid Howells unsigned int p_mask = pipe->ring_size - 1; 9518cefc107SDavid Howells 9528cefc107SDavid Howells if (!pipe_empty(p_head, p_tail)) { 9538cefc107SDavid Howells struct pipe_buffer *buf; 9548cefc107SDavid Howells unsigned int i_head = i->head; 955b9dc6f65SAl Viro size_t off = i->iov_offset; 9568cefc107SDavid Howells 957b9dc6f65SAl Viro if (off) { 9588cefc107SDavid Howells buf = &pipe->bufs[i_head & p_mask]; 9598cefc107SDavid Howells buf->len = off - buf->offset; 9608cefc107SDavid Howells i_head++; 961b9dc6f65SAl Viro } 9628cefc107SDavid Howells while (p_head != i_head) { 9638cefc107SDavid Howells p_head--; 9648cefc107SDavid Howells pipe_buf_release(pipe, &pipe->bufs[p_head & p_mask]); 965241699cdSAl Viro } 9668cefc107SDavid Howells 9678cefc107SDavid Howells pipe->head = p_head; 968241699cdSAl Viro } 969b9dc6f65SAl Viro } 970b9dc6f65SAl Viro 971b9dc6f65SAl Viro static void pipe_advance(struct iov_iter *i, size_t size) 972b9dc6f65SAl Viro { 973b9dc6f65SAl Viro struct pipe_inode_info *pipe = i->pipe; 974b9dc6f65SAl Viro if (size) { 975b9dc6f65SAl Viro struct pipe_buffer *buf; 9768cefc107SDavid Howells unsigned int p_mask = pipe->ring_size - 1; 9778cefc107SDavid Howells unsigned int i_head = i->head; 978b9dc6f65SAl Viro size_t off = i->iov_offset, left = size; 9798cefc107SDavid Howells 980b9dc6f65SAl Viro if (off) /* make it relative to the beginning of buffer */ 9818cefc107SDavid Howells left += off - pipe->bufs[i_head & p_mask].offset; 982b9dc6f65SAl Viro while (1) { 9838cefc107SDavid Howells buf = &pipe->bufs[i_head & p_mask]; 984b9dc6f65SAl Viro if (left <= buf->len) 985b9dc6f65SAl Viro break; 986b9dc6f65SAl Viro left -= buf->len; 9878cefc107SDavid Howells i_head++; 988b9dc6f65SAl Viro } 9898cefc107SDavid Howells i->head = i_head; 990b9dc6f65SAl Viro i->iov_offset = buf->offset + left; 991b9dc6f65SAl Viro } 992b9dc6f65SAl Viro i->count -= size; 993b9dc6f65SAl Viro /* ... and discard everything past that point */ 994b9dc6f65SAl Viro pipe_truncate(i); 995241699cdSAl Viro } 996241699cdSAl Viro 99754c8195bSPavel Begunkov static void iov_iter_bvec_advance(struct iov_iter *i, size_t size) 99854c8195bSPavel Begunkov { 99954c8195bSPavel Begunkov struct bvec_iter bi; 100054c8195bSPavel Begunkov 100154c8195bSPavel Begunkov bi.bi_size = i->count; 100254c8195bSPavel Begunkov bi.bi_bvec_done = i->iov_offset; 100354c8195bSPavel Begunkov bi.bi_idx = 0; 100454c8195bSPavel Begunkov bvec_iter_advance(i->bvec, &bi, size); 100554c8195bSPavel Begunkov 100654c8195bSPavel Begunkov i->bvec += bi.bi_idx; 100754c8195bSPavel Begunkov i->nr_segs -= bi.bi_idx; 100854c8195bSPavel Begunkov i->count = bi.bi_size; 100954c8195bSPavel Begunkov i->iov_offset = bi.bi_bvec_done; 101054c8195bSPavel Begunkov } 101154c8195bSPavel Begunkov 1012185ac4d4SAl Viro static void iov_iter_iovec_advance(struct iov_iter *i, size_t size) 1013185ac4d4SAl Viro { 1014185ac4d4SAl Viro const struct iovec *iov, *end; 1015185ac4d4SAl Viro 1016185ac4d4SAl Viro if (!i->count) 1017185ac4d4SAl Viro return; 1018185ac4d4SAl Viro i->count -= size; 1019185ac4d4SAl Viro 1020185ac4d4SAl Viro size += i->iov_offset; // from beginning of current segment 1021185ac4d4SAl Viro for (iov = i->iov, end = iov + i->nr_segs; iov < end; iov++) { 1022185ac4d4SAl Viro if (likely(size < iov->iov_len)) 1023185ac4d4SAl Viro break; 1024185ac4d4SAl Viro size -= iov->iov_len; 1025185ac4d4SAl Viro } 1026185ac4d4SAl Viro i->iov_offset = size; 1027185ac4d4SAl Viro i->nr_segs -= iov - i->iov; 1028185ac4d4SAl Viro i->iov = iov; 1029185ac4d4SAl Viro } 1030185ac4d4SAl Viro 1031d879cb83SAl Viro void iov_iter_advance(struct iov_iter *i, size_t size) 1032d879cb83SAl Viro { 10333b3fc051SAl Viro if (unlikely(i->count < size)) 10343b3fc051SAl Viro size = i->count; 1035185ac4d4SAl Viro if (likely(iter_is_iovec(i) || iov_iter_is_kvec(i))) { 1036185ac4d4SAl Viro /* iovec and kvec have identical layouts */ 1037185ac4d4SAl Viro iov_iter_iovec_advance(i, size); 1038185ac4d4SAl Viro } else if (iov_iter_is_bvec(i)) { 1039185ac4d4SAl Viro iov_iter_bvec_advance(i, size); 1040185ac4d4SAl Viro } else if (iov_iter_is_pipe(i)) { 1041241699cdSAl Viro pipe_advance(i, size); 1042185ac4d4SAl Viro } else if (unlikely(iov_iter_is_xarray(i))) { 10437ff50620SDavid Howells i->iov_offset += size; 10447ff50620SDavid Howells i->count -= size; 1045185ac4d4SAl Viro } else if (iov_iter_is_discard(i)) { 1046185ac4d4SAl Viro i->count -= size; 10477ff50620SDavid Howells } 1048d879cb83SAl Viro } 1049d879cb83SAl Viro EXPORT_SYMBOL(iov_iter_advance); 1050d879cb83SAl Viro 105127c0e374SAl Viro void iov_iter_revert(struct iov_iter *i, size_t unroll) 105227c0e374SAl Viro { 105327c0e374SAl Viro if (!unroll) 105427c0e374SAl Viro return; 10555b47d59aSAl Viro if (WARN_ON(unroll > MAX_RW_COUNT)) 10565b47d59aSAl Viro return; 105727c0e374SAl Viro i->count += unroll; 105800e23707SDavid Howells if (unlikely(iov_iter_is_pipe(i))) { 105927c0e374SAl Viro struct pipe_inode_info *pipe = i->pipe; 10608cefc107SDavid Howells unsigned int p_mask = pipe->ring_size - 1; 10618cefc107SDavid Howells unsigned int i_head = i->head; 106227c0e374SAl Viro size_t off = i->iov_offset; 106327c0e374SAl Viro while (1) { 10648cefc107SDavid Howells struct pipe_buffer *b = &pipe->bufs[i_head & p_mask]; 10658cefc107SDavid Howells size_t n = off - b->offset; 106627c0e374SAl Viro if (unroll < n) { 10674fa55cefSAl Viro off -= unroll; 106827c0e374SAl Viro break; 106927c0e374SAl Viro } 107027c0e374SAl Viro unroll -= n; 10718cefc107SDavid Howells if (!unroll && i_head == i->start_head) { 107227c0e374SAl Viro off = 0; 107327c0e374SAl Viro break; 107427c0e374SAl Viro } 10758cefc107SDavid Howells i_head--; 10768cefc107SDavid Howells b = &pipe->bufs[i_head & p_mask]; 10778cefc107SDavid Howells off = b->offset + b->len; 107827c0e374SAl Viro } 107927c0e374SAl Viro i->iov_offset = off; 10808cefc107SDavid Howells i->head = i_head; 108127c0e374SAl Viro pipe_truncate(i); 108227c0e374SAl Viro return; 108327c0e374SAl Viro } 10849ea9ce04SDavid Howells if (unlikely(iov_iter_is_discard(i))) 10859ea9ce04SDavid Howells return; 108627c0e374SAl Viro if (unroll <= i->iov_offset) { 108727c0e374SAl Viro i->iov_offset -= unroll; 108827c0e374SAl Viro return; 108927c0e374SAl Viro } 109027c0e374SAl Viro unroll -= i->iov_offset; 10917ff50620SDavid Howells if (iov_iter_is_xarray(i)) { 10927ff50620SDavid Howells BUG(); /* We should never go beyond the start of the specified 10937ff50620SDavid Howells * range since we might then be straying into pages that 10947ff50620SDavid Howells * aren't pinned. 10957ff50620SDavid Howells */ 10967ff50620SDavid Howells } else if (iov_iter_is_bvec(i)) { 109727c0e374SAl Viro const struct bio_vec *bvec = i->bvec; 109827c0e374SAl Viro while (1) { 109927c0e374SAl Viro size_t n = (--bvec)->bv_len; 110027c0e374SAl Viro i->nr_segs++; 110127c0e374SAl Viro if (unroll <= n) { 110227c0e374SAl Viro i->bvec = bvec; 110327c0e374SAl Viro i->iov_offset = n - unroll; 110427c0e374SAl Viro return; 110527c0e374SAl Viro } 110627c0e374SAl Viro unroll -= n; 110727c0e374SAl Viro } 110827c0e374SAl Viro } else { /* same logics for iovec and kvec */ 110927c0e374SAl Viro const struct iovec *iov = i->iov; 111027c0e374SAl Viro while (1) { 111127c0e374SAl Viro size_t n = (--iov)->iov_len; 111227c0e374SAl Viro i->nr_segs++; 111327c0e374SAl Viro if (unroll <= n) { 111427c0e374SAl Viro i->iov = iov; 111527c0e374SAl Viro i->iov_offset = n - unroll; 111627c0e374SAl Viro return; 111727c0e374SAl Viro } 111827c0e374SAl Viro unroll -= n; 111927c0e374SAl Viro } 112027c0e374SAl Viro } 112127c0e374SAl Viro } 112227c0e374SAl Viro EXPORT_SYMBOL(iov_iter_revert); 112327c0e374SAl Viro 1124d879cb83SAl Viro /* 1125d879cb83SAl Viro * Return the count of just the current iov_iter segment. 1126d879cb83SAl Viro */ 1127d879cb83SAl Viro size_t iov_iter_single_seg_count(const struct iov_iter *i) 1128d879cb83SAl Viro { 112928f38db7SAl Viro if (i->nr_segs > 1) { 113028f38db7SAl Viro if (likely(iter_is_iovec(i) || iov_iter_is_kvec(i))) 113128f38db7SAl Viro return min(i->count, i->iov->iov_len - i->iov_offset); 11327ff50620SDavid Howells if (iov_iter_is_bvec(i)) 1133d879cb83SAl Viro return min(i->count, i->bvec->bv_len - i->iov_offset); 113428f38db7SAl Viro } 113528f38db7SAl Viro return i->count; 1136d879cb83SAl Viro } 1137d879cb83SAl Viro EXPORT_SYMBOL(iov_iter_single_seg_count); 1138d879cb83SAl Viro 1139aa563d7bSDavid Howells void iov_iter_kvec(struct iov_iter *i, unsigned int direction, 1140d879cb83SAl Viro const struct kvec *kvec, unsigned long nr_segs, 1141d879cb83SAl Viro size_t count) 1142d879cb83SAl Viro { 1143aa563d7bSDavid Howells WARN_ON(direction & ~(READ | WRITE)); 11448cd54c1cSAl Viro *i = (struct iov_iter){ 11458cd54c1cSAl Viro .iter_type = ITER_KVEC, 11468cd54c1cSAl Viro .data_source = direction, 11478cd54c1cSAl Viro .kvec = kvec, 11488cd54c1cSAl Viro .nr_segs = nr_segs, 11498cd54c1cSAl Viro .iov_offset = 0, 11508cd54c1cSAl Viro .count = count 11518cd54c1cSAl Viro }; 1152d879cb83SAl Viro } 1153d879cb83SAl Viro EXPORT_SYMBOL(iov_iter_kvec); 1154d879cb83SAl Viro 1155aa563d7bSDavid Howells void iov_iter_bvec(struct iov_iter *i, unsigned int direction, 1156d879cb83SAl Viro const struct bio_vec *bvec, unsigned long nr_segs, 1157d879cb83SAl Viro size_t count) 1158d879cb83SAl Viro { 1159aa563d7bSDavid Howells WARN_ON(direction & ~(READ | WRITE)); 11608cd54c1cSAl Viro *i = (struct iov_iter){ 11618cd54c1cSAl Viro .iter_type = ITER_BVEC, 11628cd54c1cSAl Viro .data_source = direction, 11638cd54c1cSAl Viro .bvec = bvec, 11648cd54c1cSAl Viro .nr_segs = nr_segs, 11658cd54c1cSAl Viro .iov_offset = 0, 11668cd54c1cSAl Viro .count = count 11678cd54c1cSAl Viro }; 1168d879cb83SAl Viro } 1169d879cb83SAl Viro EXPORT_SYMBOL(iov_iter_bvec); 1170d879cb83SAl Viro 1171aa563d7bSDavid Howells void iov_iter_pipe(struct iov_iter *i, unsigned int direction, 1172241699cdSAl Viro struct pipe_inode_info *pipe, 1173241699cdSAl Viro size_t count) 1174241699cdSAl Viro { 1175aa563d7bSDavid Howells BUG_ON(direction != READ); 11768cefc107SDavid Howells WARN_ON(pipe_full(pipe->head, pipe->tail, pipe->ring_size)); 11778cd54c1cSAl Viro *i = (struct iov_iter){ 11788cd54c1cSAl Viro .iter_type = ITER_PIPE, 11798cd54c1cSAl Viro .data_source = false, 11808cd54c1cSAl Viro .pipe = pipe, 11818cd54c1cSAl Viro .head = pipe->head, 11828cd54c1cSAl Viro .start_head = pipe->head, 11838cd54c1cSAl Viro .iov_offset = 0, 11848cd54c1cSAl Viro .count = count 11858cd54c1cSAl Viro }; 1186241699cdSAl Viro } 1187241699cdSAl Viro EXPORT_SYMBOL(iov_iter_pipe); 1188241699cdSAl Viro 11899ea9ce04SDavid Howells /** 11907ff50620SDavid Howells * iov_iter_xarray - Initialise an I/O iterator to use the pages in an xarray 11917ff50620SDavid Howells * @i: The iterator to initialise. 11927ff50620SDavid Howells * @direction: The direction of the transfer. 11937ff50620SDavid Howells * @xarray: The xarray to access. 11947ff50620SDavid Howells * @start: The start file position. 11957ff50620SDavid Howells * @count: The size of the I/O buffer in bytes. 11967ff50620SDavid Howells * 11977ff50620SDavid Howells * Set up an I/O iterator to either draw data out of the pages attached to an 11987ff50620SDavid Howells * inode or to inject data into those pages. The pages *must* be prevented 11997ff50620SDavid Howells * from evaporation, either by taking a ref on them or locking them by the 12007ff50620SDavid Howells * caller. 12017ff50620SDavid Howells */ 12027ff50620SDavid Howells void iov_iter_xarray(struct iov_iter *i, unsigned int direction, 12037ff50620SDavid Howells struct xarray *xarray, loff_t start, size_t count) 12047ff50620SDavid Howells { 12057ff50620SDavid Howells BUG_ON(direction & ~1); 12068cd54c1cSAl Viro *i = (struct iov_iter) { 12078cd54c1cSAl Viro .iter_type = ITER_XARRAY, 12088cd54c1cSAl Viro .data_source = direction, 12098cd54c1cSAl Viro .xarray = xarray, 12108cd54c1cSAl Viro .xarray_start = start, 12118cd54c1cSAl Viro .count = count, 12128cd54c1cSAl Viro .iov_offset = 0 12138cd54c1cSAl Viro }; 12147ff50620SDavid Howells } 12157ff50620SDavid Howells EXPORT_SYMBOL(iov_iter_xarray); 12167ff50620SDavid Howells 12177ff50620SDavid Howells /** 12189ea9ce04SDavid Howells * iov_iter_discard - Initialise an I/O iterator that discards data 12199ea9ce04SDavid Howells * @i: The iterator to initialise. 12209ea9ce04SDavid Howells * @direction: The direction of the transfer. 12219ea9ce04SDavid Howells * @count: The size of the I/O buffer in bytes. 12229ea9ce04SDavid Howells * 12239ea9ce04SDavid Howells * Set up an I/O iterator that just discards everything that's written to it. 12249ea9ce04SDavid Howells * It's only available as a READ iterator. 12259ea9ce04SDavid Howells */ 12269ea9ce04SDavid Howells void iov_iter_discard(struct iov_iter *i, unsigned int direction, size_t count) 12279ea9ce04SDavid Howells { 12289ea9ce04SDavid Howells BUG_ON(direction != READ); 12298cd54c1cSAl Viro *i = (struct iov_iter){ 12308cd54c1cSAl Viro .iter_type = ITER_DISCARD, 12318cd54c1cSAl Viro .data_source = false, 12328cd54c1cSAl Viro .count = count, 12338cd54c1cSAl Viro .iov_offset = 0 12348cd54c1cSAl Viro }; 12359ea9ce04SDavid Howells } 12369ea9ce04SDavid Howells EXPORT_SYMBOL(iov_iter_discard); 12379ea9ce04SDavid Howells 12389221d2e3SAl Viro static unsigned long iov_iter_alignment_iovec(const struct iov_iter *i) 1239d879cb83SAl Viro { 1240d879cb83SAl Viro unsigned long res = 0; 1241d879cb83SAl Viro size_t size = i->count; 12429221d2e3SAl Viro size_t skip = i->iov_offset; 12439221d2e3SAl Viro unsigned k; 1244d879cb83SAl Viro 12459221d2e3SAl Viro for (k = 0; k < i->nr_segs; k++, skip = 0) { 12469221d2e3SAl Viro size_t len = i->iov[k].iov_len - skip; 12479221d2e3SAl Viro if (len) { 12489221d2e3SAl Viro res |= (unsigned long)i->iov[k].iov_base + skip; 12499221d2e3SAl Viro if (len > size) 12509221d2e3SAl Viro len = size; 12519221d2e3SAl Viro res |= len; 12529221d2e3SAl Viro size -= len; 12539221d2e3SAl Viro if (!size) 12549221d2e3SAl Viro break; 12559221d2e3SAl Viro } 12569221d2e3SAl Viro } 12579221d2e3SAl Viro return res; 12589221d2e3SAl Viro } 12599221d2e3SAl Viro 12609221d2e3SAl Viro static unsigned long iov_iter_alignment_bvec(const struct iov_iter *i) 12619221d2e3SAl Viro { 12629221d2e3SAl Viro unsigned res = 0; 12639221d2e3SAl Viro size_t size = i->count; 12649221d2e3SAl Viro unsigned skip = i->iov_offset; 12659221d2e3SAl Viro unsigned k; 12669221d2e3SAl Viro 12679221d2e3SAl Viro for (k = 0; k < i->nr_segs; k++, skip = 0) { 12689221d2e3SAl Viro size_t len = i->bvec[k].bv_len - skip; 12699221d2e3SAl Viro res |= (unsigned long)i->bvec[k].bv_offset + skip; 12709221d2e3SAl Viro if (len > size) 12719221d2e3SAl Viro len = size; 12729221d2e3SAl Viro res |= len; 12739221d2e3SAl Viro size -= len; 12749221d2e3SAl Viro if (!size) 12759221d2e3SAl Viro break; 12769221d2e3SAl Viro } 12779221d2e3SAl Viro return res; 12789221d2e3SAl Viro } 12799221d2e3SAl Viro 12809221d2e3SAl Viro unsigned long iov_iter_alignment(const struct iov_iter *i) 12819221d2e3SAl Viro { 12829221d2e3SAl Viro /* iovec and kvec have identical layouts */ 12839221d2e3SAl Viro if (likely(iter_is_iovec(i) || iov_iter_is_kvec(i))) 12849221d2e3SAl Viro return iov_iter_alignment_iovec(i); 12859221d2e3SAl Viro 12869221d2e3SAl Viro if (iov_iter_is_bvec(i)) 12879221d2e3SAl Viro return iov_iter_alignment_bvec(i); 12889221d2e3SAl Viro 12899221d2e3SAl Viro if (iov_iter_is_pipe(i)) { 1290e0ff126eSJan Kara unsigned int p_mask = i->pipe->ring_size - 1; 12919221d2e3SAl Viro size_t size = i->count; 1292e0ff126eSJan Kara 12938cefc107SDavid Howells if (size && i->iov_offset && allocated(&i->pipe->bufs[i->head & p_mask])) 1294241699cdSAl Viro return size | i->iov_offset; 1295241699cdSAl Viro return size; 1296241699cdSAl Viro } 12979221d2e3SAl Viro 12989221d2e3SAl Viro if (iov_iter_is_xarray(i)) 12993d14ec1fSDavid Howells return (i->xarray_start + i->iov_offset) | i->count; 13009221d2e3SAl Viro 13019221d2e3SAl Viro return 0; 1302d879cb83SAl Viro } 1303d879cb83SAl Viro EXPORT_SYMBOL(iov_iter_alignment); 1304d879cb83SAl Viro 1305357f435dSAl Viro unsigned long iov_iter_gap_alignment(const struct iov_iter *i) 1306357f435dSAl Viro { 1307357f435dSAl Viro unsigned long res = 0; 1308610c7a71SAl Viro unsigned long v = 0; 1309357f435dSAl Viro size_t size = i->count; 1310610c7a71SAl Viro unsigned k; 1311357f435dSAl Viro 1312610c7a71SAl Viro if (WARN_ON(!iter_is_iovec(i))) 1313241699cdSAl Viro return ~0U; 1314241699cdSAl Viro 1315610c7a71SAl Viro for (k = 0; k < i->nr_segs; k++) { 1316610c7a71SAl Viro if (i->iov[k].iov_len) { 1317610c7a71SAl Viro unsigned long base = (unsigned long)i->iov[k].iov_base; 1318610c7a71SAl Viro if (v) // if not the first one 1319610c7a71SAl Viro res |= base | v; // this start | previous end 1320610c7a71SAl Viro v = base + i->iov[k].iov_len; 1321610c7a71SAl Viro if (size <= i->iov[k].iov_len) 1322610c7a71SAl Viro break; 1323610c7a71SAl Viro size -= i->iov[k].iov_len; 1324610c7a71SAl Viro } 1325610c7a71SAl Viro } 1326357f435dSAl Viro return res; 1327357f435dSAl Viro } 1328357f435dSAl Viro EXPORT_SYMBOL(iov_iter_gap_alignment); 1329357f435dSAl Viro 1330e76b6312SIlya Dryomov static inline ssize_t __pipe_get_pages(struct iov_iter *i, 1331241699cdSAl Viro size_t maxsize, 1332241699cdSAl Viro struct page **pages, 13338cefc107SDavid Howells int iter_head, 1334241699cdSAl Viro size_t *start) 1335241699cdSAl Viro { 1336241699cdSAl Viro struct pipe_inode_info *pipe = i->pipe; 13378cefc107SDavid Howells unsigned int p_mask = pipe->ring_size - 1; 13388cefc107SDavid Howells ssize_t n = push_pipe(i, maxsize, &iter_head, start); 1339241699cdSAl Viro if (!n) 1340241699cdSAl Viro return -EFAULT; 1341241699cdSAl Viro 1342241699cdSAl Viro maxsize = n; 1343241699cdSAl Viro n += *start; 13441689c73aSAl Viro while (n > 0) { 13458cefc107SDavid Howells get_page(*pages++ = pipe->bufs[iter_head & p_mask].page); 13468cefc107SDavid Howells iter_head++; 1347241699cdSAl Viro n -= PAGE_SIZE; 1348241699cdSAl Viro } 1349241699cdSAl Viro 1350241699cdSAl Viro return maxsize; 1351241699cdSAl Viro } 1352241699cdSAl Viro 1353241699cdSAl Viro static ssize_t pipe_get_pages(struct iov_iter *i, 1354241699cdSAl Viro struct page **pages, size_t maxsize, unsigned maxpages, 1355241699cdSAl Viro size_t *start) 1356241699cdSAl Viro { 13578cefc107SDavid Howells unsigned int iter_head, npages; 1358241699cdSAl Viro size_t capacity; 1359241699cdSAl Viro 1360241699cdSAl Viro if (!sanity(i)) 1361241699cdSAl Viro return -EFAULT; 1362241699cdSAl Viro 13638cefc107SDavid Howells data_start(i, &iter_head, start); 13648cefc107SDavid Howells /* Amount of free space: some of this one + all after this one */ 13658cefc107SDavid Howells npages = pipe_space_for_user(iter_head, i->pipe->tail, i->pipe); 1366241699cdSAl Viro capacity = min(npages, maxpages) * PAGE_SIZE - *start; 1367241699cdSAl Viro 13688cefc107SDavid Howells return __pipe_get_pages(i, min(maxsize, capacity), pages, iter_head, start); 1369241699cdSAl Viro } 1370241699cdSAl Viro 13717ff50620SDavid Howells static ssize_t iter_xarray_populate_pages(struct page **pages, struct xarray *xa, 13727ff50620SDavid Howells pgoff_t index, unsigned int nr_pages) 13737ff50620SDavid Howells { 13747ff50620SDavid Howells XA_STATE(xas, xa, index); 13757ff50620SDavid Howells struct page *page; 13767ff50620SDavid Howells unsigned int ret = 0; 13777ff50620SDavid Howells 13787ff50620SDavid Howells rcu_read_lock(); 13797ff50620SDavid Howells for (page = xas_load(&xas); page; page = xas_next(&xas)) { 13807ff50620SDavid Howells if (xas_retry(&xas, page)) 13817ff50620SDavid Howells continue; 13827ff50620SDavid Howells 13837ff50620SDavid Howells /* Has the page moved or been split? */ 13847ff50620SDavid Howells if (unlikely(page != xas_reload(&xas))) { 13857ff50620SDavid Howells xas_reset(&xas); 13867ff50620SDavid Howells continue; 13877ff50620SDavid Howells } 13887ff50620SDavid Howells 13897ff50620SDavid Howells pages[ret] = find_subpage(page, xas.xa_index); 13907ff50620SDavid Howells get_page(pages[ret]); 13917ff50620SDavid Howells if (++ret == nr_pages) 13927ff50620SDavid Howells break; 13937ff50620SDavid Howells } 13947ff50620SDavid Howells rcu_read_unlock(); 13957ff50620SDavid Howells return ret; 13967ff50620SDavid Howells } 13977ff50620SDavid Howells 13987ff50620SDavid Howells static ssize_t iter_xarray_get_pages(struct iov_iter *i, 13997ff50620SDavid Howells struct page **pages, size_t maxsize, 14007ff50620SDavid Howells unsigned maxpages, size_t *_start_offset) 14017ff50620SDavid Howells { 14027ff50620SDavid Howells unsigned nr, offset; 14037ff50620SDavid Howells pgoff_t index, count; 14047ff50620SDavid Howells size_t size = maxsize, actual; 14057ff50620SDavid Howells loff_t pos; 14067ff50620SDavid Howells 14077ff50620SDavid Howells if (!size || !maxpages) 14087ff50620SDavid Howells return 0; 14097ff50620SDavid Howells 14107ff50620SDavid Howells pos = i->xarray_start + i->iov_offset; 14117ff50620SDavid Howells index = pos >> PAGE_SHIFT; 14127ff50620SDavid Howells offset = pos & ~PAGE_MASK; 14137ff50620SDavid Howells *_start_offset = offset; 14147ff50620SDavid Howells 14157ff50620SDavid Howells count = 1; 14167ff50620SDavid Howells if (size > PAGE_SIZE - offset) { 14177ff50620SDavid Howells size -= PAGE_SIZE - offset; 14187ff50620SDavid Howells count += size >> PAGE_SHIFT; 14197ff50620SDavid Howells size &= ~PAGE_MASK; 14207ff50620SDavid Howells if (size) 14217ff50620SDavid Howells count++; 14227ff50620SDavid Howells } 14237ff50620SDavid Howells 14247ff50620SDavid Howells if (count > maxpages) 14257ff50620SDavid Howells count = maxpages; 14267ff50620SDavid Howells 14277ff50620SDavid Howells nr = iter_xarray_populate_pages(pages, i->xarray, index, count); 14287ff50620SDavid Howells if (nr == 0) 14297ff50620SDavid Howells return 0; 14307ff50620SDavid Howells 14317ff50620SDavid Howells actual = PAGE_SIZE * nr; 14327ff50620SDavid Howells actual -= offset; 14337ff50620SDavid Howells if (nr == count && size > 0) { 14347ff50620SDavid Howells unsigned last_offset = (nr > 1) ? 0 : offset; 14357ff50620SDavid Howells actual -= PAGE_SIZE - (last_offset + size); 14367ff50620SDavid Howells } 14377ff50620SDavid Howells return actual; 14387ff50620SDavid Howells } 14397ff50620SDavid Howells 14403d671ca6SAl Viro /* must be done on non-empty ITER_IOVEC one */ 14413d671ca6SAl Viro static unsigned long first_iovec_segment(const struct iov_iter *i, 14423d671ca6SAl Viro size_t *size, size_t *start, 14433d671ca6SAl Viro size_t maxsize, unsigned maxpages) 14443d671ca6SAl Viro { 14453d671ca6SAl Viro size_t skip; 14463d671ca6SAl Viro long k; 14473d671ca6SAl Viro 14483d671ca6SAl Viro for (k = 0, skip = i->iov_offset; k < i->nr_segs; k++, skip = 0) { 14493d671ca6SAl Viro unsigned long addr = (unsigned long)i->iov[k].iov_base + skip; 14503d671ca6SAl Viro size_t len = i->iov[k].iov_len - skip; 14513d671ca6SAl Viro 14523d671ca6SAl Viro if (unlikely(!len)) 14533d671ca6SAl Viro continue; 14543d671ca6SAl Viro if (len > maxsize) 14553d671ca6SAl Viro len = maxsize; 14563d671ca6SAl Viro len += (*start = addr % PAGE_SIZE); 14573d671ca6SAl Viro if (len > maxpages * PAGE_SIZE) 14583d671ca6SAl Viro len = maxpages * PAGE_SIZE; 14593d671ca6SAl Viro *size = len; 14603d671ca6SAl Viro return addr & PAGE_MASK; 14613d671ca6SAl Viro } 14623d671ca6SAl Viro BUG(); // if it had been empty, we wouldn't get called 14633d671ca6SAl Viro } 14643d671ca6SAl Viro 14653d671ca6SAl Viro /* must be done on non-empty ITER_BVEC one */ 14663d671ca6SAl Viro static struct page *first_bvec_segment(const struct iov_iter *i, 14673d671ca6SAl Viro size_t *size, size_t *start, 14683d671ca6SAl Viro size_t maxsize, unsigned maxpages) 14693d671ca6SAl Viro { 14703d671ca6SAl Viro struct page *page; 14713d671ca6SAl Viro size_t skip = i->iov_offset, len; 14723d671ca6SAl Viro 14733d671ca6SAl Viro len = i->bvec->bv_len - skip; 14743d671ca6SAl Viro if (len > maxsize) 14753d671ca6SAl Viro len = maxsize; 14763d671ca6SAl Viro skip += i->bvec->bv_offset; 14773d671ca6SAl Viro page = i->bvec->bv_page + skip / PAGE_SIZE; 14783d671ca6SAl Viro len += (*start = skip % PAGE_SIZE); 14793d671ca6SAl Viro if (len > maxpages * PAGE_SIZE) 14803d671ca6SAl Viro len = maxpages * PAGE_SIZE; 14813d671ca6SAl Viro *size = len; 14823d671ca6SAl Viro return page; 14833d671ca6SAl Viro } 14843d671ca6SAl Viro 1485d879cb83SAl Viro ssize_t iov_iter_get_pages(struct iov_iter *i, 1486d879cb83SAl Viro struct page **pages, size_t maxsize, unsigned maxpages, 1487d879cb83SAl Viro size_t *start) 1488d879cb83SAl Viro { 14893d671ca6SAl Viro size_t len; 14903d671ca6SAl Viro int n, res; 14913d671ca6SAl Viro 1492d879cb83SAl Viro if (maxsize > i->count) 1493d879cb83SAl Viro maxsize = i->count; 14943d671ca6SAl Viro if (!maxsize) 14953d671ca6SAl Viro return 0; 1496d879cb83SAl Viro 14973d671ca6SAl Viro if (likely(iter_is_iovec(i))) { 14983d671ca6SAl Viro unsigned long addr; 14999ea9ce04SDavid Howells 15003d671ca6SAl Viro addr = first_iovec_segment(i, &len, start, maxsize, maxpages); 1501d879cb83SAl Viro n = DIV_ROUND_UP(len, PAGE_SIZE); 150273b0140bSIra Weiny res = get_user_pages_fast(addr, n, 150373b0140bSIra Weiny iov_iter_rw(i) != WRITE ? FOLL_WRITE : 0, 150473b0140bSIra Weiny pages); 1505d879cb83SAl Viro if (unlikely(res < 0)) 1506d879cb83SAl Viro return res; 1507d879cb83SAl Viro return (res == n ? len : res * PAGE_SIZE) - *start; 15083d671ca6SAl Viro } 15093d671ca6SAl Viro if (iov_iter_is_bvec(i)) { 15103d671ca6SAl Viro struct page *page; 15113d671ca6SAl Viro 15123d671ca6SAl Viro page = first_bvec_segment(i, &len, start, maxsize, maxpages); 15133d671ca6SAl Viro n = DIV_ROUND_UP(len, PAGE_SIZE); 15143d671ca6SAl Viro while (n--) 15153d671ca6SAl Viro get_page(*pages++ = page++); 15163d671ca6SAl Viro return len - *start; 15173d671ca6SAl Viro } 15183d671ca6SAl Viro if (iov_iter_is_pipe(i)) 15193d671ca6SAl Viro return pipe_get_pages(i, pages, maxsize, maxpages, start); 15203d671ca6SAl Viro if (iov_iter_is_xarray(i)) 15213d671ca6SAl Viro return iter_xarray_get_pages(i, pages, maxsize, maxpages, start); 1522d879cb83SAl Viro return -EFAULT; 1523d879cb83SAl Viro } 1524d879cb83SAl Viro EXPORT_SYMBOL(iov_iter_get_pages); 1525d879cb83SAl Viro 1526d879cb83SAl Viro static struct page **get_pages_array(size_t n) 1527d879cb83SAl Viro { 1528752ade68SMichal Hocko return kvmalloc_array(n, sizeof(struct page *), GFP_KERNEL); 1529d879cb83SAl Viro } 1530d879cb83SAl Viro 1531241699cdSAl Viro static ssize_t pipe_get_pages_alloc(struct iov_iter *i, 1532241699cdSAl Viro struct page ***pages, size_t maxsize, 1533241699cdSAl Viro size_t *start) 1534241699cdSAl Viro { 1535241699cdSAl Viro struct page **p; 15368cefc107SDavid Howells unsigned int iter_head, npages; 1537d7760d63SIlya Dryomov ssize_t n; 1538241699cdSAl Viro 1539241699cdSAl Viro if (!sanity(i)) 1540241699cdSAl Viro return -EFAULT; 1541241699cdSAl Viro 15428cefc107SDavid Howells data_start(i, &iter_head, start); 15438cefc107SDavid Howells /* Amount of free space: some of this one + all after this one */ 15448cefc107SDavid Howells npages = pipe_space_for_user(iter_head, i->pipe->tail, i->pipe); 1545241699cdSAl Viro n = npages * PAGE_SIZE - *start; 1546241699cdSAl Viro if (maxsize > n) 1547241699cdSAl Viro maxsize = n; 1548241699cdSAl Viro else 1549241699cdSAl Viro npages = DIV_ROUND_UP(maxsize + *start, PAGE_SIZE); 1550241699cdSAl Viro p = get_pages_array(npages); 1551241699cdSAl Viro if (!p) 1552241699cdSAl Viro return -ENOMEM; 15538cefc107SDavid Howells n = __pipe_get_pages(i, maxsize, p, iter_head, start); 1554241699cdSAl Viro if (n > 0) 1555241699cdSAl Viro *pages = p; 1556241699cdSAl Viro else 1557241699cdSAl Viro kvfree(p); 1558241699cdSAl Viro return n; 1559241699cdSAl Viro } 1560241699cdSAl Viro 15617ff50620SDavid Howells static ssize_t iter_xarray_get_pages_alloc(struct iov_iter *i, 15627ff50620SDavid Howells struct page ***pages, size_t maxsize, 15637ff50620SDavid Howells size_t *_start_offset) 15647ff50620SDavid Howells { 15657ff50620SDavid Howells struct page **p; 15667ff50620SDavid Howells unsigned nr, offset; 15677ff50620SDavid Howells pgoff_t index, count; 15687ff50620SDavid Howells size_t size = maxsize, actual; 15697ff50620SDavid Howells loff_t pos; 15707ff50620SDavid Howells 15717ff50620SDavid Howells if (!size) 15727ff50620SDavid Howells return 0; 15737ff50620SDavid Howells 15747ff50620SDavid Howells pos = i->xarray_start + i->iov_offset; 15757ff50620SDavid Howells index = pos >> PAGE_SHIFT; 15767ff50620SDavid Howells offset = pos & ~PAGE_MASK; 15777ff50620SDavid Howells *_start_offset = offset; 15787ff50620SDavid Howells 15797ff50620SDavid Howells count = 1; 15807ff50620SDavid Howells if (size > PAGE_SIZE - offset) { 15817ff50620SDavid Howells size -= PAGE_SIZE - offset; 15827ff50620SDavid Howells count += size >> PAGE_SHIFT; 15837ff50620SDavid Howells size &= ~PAGE_MASK; 15847ff50620SDavid Howells if (size) 15857ff50620SDavid Howells count++; 15867ff50620SDavid Howells } 15877ff50620SDavid Howells 15887ff50620SDavid Howells p = get_pages_array(count); 15897ff50620SDavid Howells if (!p) 15907ff50620SDavid Howells return -ENOMEM; 15917ff50620SDavid Howells *pages = p; 15927ff50620SDavid Howells 15937ff50620SDavid Howells nr = iter_xarray_populate_pages(p, i->xarray, index, count); 15947ff50620SDavid Howells if (nr == 0) 15957ff50620SDavid Howells return 0; 15967ff50620SDavid Howells 15977ff50620SDavid Howells actual = PAGE_SIZE * nr; 15987ff50620SDavid Howells actual -= offset; 15997ff50620SDavid Howells if (nr == count && size > 0) { 16007ff50620SDavid Howells unsigned last_offset = (nr > 1) ? 0 : offset; 16017ff50620SDavid Howells actual -= PAGE_SIZE - (last_offset + size); 16027ff50620SDavid Howells } 16037ff50620SDavid Howells return actual; 16047ff50620SDavid Howells } 16057ff50620SDavid Howells 1606d879cb83SAl Viro ssize_t iov_iter_get_pages_alloc(struct iov_iter *i, 1607d879cb83SAl Viro struct page ***pages, size_t maxsize, 1608d879cb83SAl Viro size_t *start) 1609d879cb83SAl Viro { 1610d879cb83SAl Viro struct page **p; 16113d671ca6SAl Viro size_t len; 16123d671ca6SAl Viro int n, res; 1613d879cb83SAl Viro 1614d879cb83SAl Viro if (maxsize > i->count) 1615d879cb83SAl Viro maxsize = i->count; 16163d671ca6SAl Viro if (!maxsize) 16173d671ca6SAl Viro return 0; 1618d879cb83SAl Viro 16193d671ca6SAl Viro if (likely(iter_is_iovec(i))) { 16203d671ca6SAl Viro unsigned long addr; 16219ea9ce04SDavid Howells 16223d671ca6SAl Viro addr = first_iovec_segment(i, &len, start, maxsize, ~0U); 1623d879cb83SAl Viro n = DIV_ROUND_UP(len, PAGE_SIZE); 1624d879cb83SAl Viro p = get_pages_array(n); 1625d879cb83SAl Viro if (!p) 1626d879cb83SAl Viro return -ENOMEM; 162773b0140bSIra Weiny res = get_user_pages_fast(addr, n, 162873b0140bSIra Weiny iov_iter_rw(i) != WRITE ? FOLL_WRITE : 0, p); 1629d879cb83SAl Viro if (unlikely(res < 0)) { 1630d879cb83SAl Viro kvfree(p); 1631d879cb83SAl Viro return res; 1632d879cb83SAl Viro } 1633d879cb83SAl Viro *pages = p; 1634d879cb83SAl Viro return (res == n ? len : res * PAGE_SIZE) - *start; 16353d671ca6SAl Viro } 16363d671ca6SAl Viro if (iov_iter_is_bvec(i)) { 16373d671ca6SAl Viro struct page *page; 16383d671ca6SAl Viro 16393d671ca6SAl Viro page = first_bvec_segment(i, &len, start, maxsize, ~0U); 16403d671ca6SAl Viro n = DIV_ROUND_UP(len, PAGE_SIZE); 16413d671ca6SAl Viro *pages = p = get_pages_array(n); 1642d879cb83SAl Viro if (!p) 1643d879cb83SAl Viro return -ENOMEM; 16443d671ca6SAl Viro while (n--) 16453d671ca6SAl Viro get_page(*p++ = page++); 16463d671ca6SAl Viro return len - *start; 16473d671ca6SAl Viro } 16483d671ca6SAl Viro if (iov_iter_is_pipe(i)) 16493d671ca6SAl Viro return pipe_get_pages_alloc(i, pages, maxsize, start); 16503d671ca6SAl Viro if (iov_iter_is_xarray(i)) 16513d671ca6SAl Viro return iter_xarray_get_pages_alloc(i, pages, maxsize, start); 1652d879cb83SAl Viro return -EFAULT; 1653d879cb83SAl Viro } 1654d879cb83SAl Viro EXPORT_SYMBOL(iov_iter_get_pages_alloc); 1655d879cb83SAl Viro 1656d879cb83SAl Viro size_t csum_and_copy_from_iter(void *addr, size_t bytes, __wsum *csum, 1657d879cb83SAl Viro struct iov_iter *i) 1658d879cb83SAl Viro { 1659d879cb83SAl Viro char *to = addr; 1660d879cb83SAl Viro __wsum sum, next; 1661d879cb83SAl Viro size_t off = 0; 1662d879cb83SAl Viro sum = *csum; 16639ea9ce04SDavid Howells if (unlikely(iov_iter_is_pipe(i) || iov_iter_is_discard(i))) { 1664241699cdSAl Viro WARN_ON(1); 1665241699cdSAl Viro return 0; 1666241699cdSAl Viro } 1667d879cb83SAl Viro iterate_and_advance(i, bytes, v, ({ 1668d879cb83SAl Viro next = csum_and_copy_from_user(v.iov_base, 1669d879cb83SAl Viro (to += v.iov_len) - v.iov_len, 1670c693cc46SAl Viro v.iov_len); 1671c693cc46SAl Viro if (next) { 1672d879cb83SAl Viro sum = csum_block_add(sum, next, off); 1673d879cb83SAl Viro off += v.iov_len; 1674d879cb83SAl Viro } 1675c693cc46SAl Viro next ? 0 : v.iov_len; 1676d879cb83SAl Viro }), ({ 1677f9152895SAl Viro sum = csum_and_memcpy((to += v.iov_len) - v.iov_len, 1678f9152895SAl Viro v.iov_base, v.iov_len, 1679f9152895SAl Viro sum, off); 1680d879cb83SAl Viro off += v.iov_len; 1681d879cb83SAl Viro }) 1682d879cb83SAl Viro ) 1683d879cb83SAl Viro *csum = sum; 1684d879cb83SAl Viro return bytes; 1685d879cb83SAl Viro } 1686d879cb83SAl Viro EXPORT_SYMBOL(csum_and_copy_from_iter); 1687d879cb83SAl Viro 168852cbd23aSWillem de Bruijn size_t csum_and_copy_to_iter(const void *addr, size_t bytes, void *_csstate, 1689d879cb83SAl Viro struct iov_iter *i) 1690d879cb83SAl Viro { 169152cbd23aSWillem de Bruijn struct csum_state *csstate = _csstate; 169236f7a8a4SAl Viro const char *from = addr; 1693d879cb83SAl Viro __wsum sum, next; 169452cbd23aSWillem de Bruijn size_t off; 169578e1f386SAl Viro 169678e1f386SAl Viro if (unlikely(iov_iter_is_pipe(i))) 169752cbd23aSWillem de Bruijn return csum_and_copy_to_pipe_iter(addr, bytes, _csstate, i); 169878e1f386SAl Viro 1699594e450bSAl Viro sum = csum_shift(csstate->csum, csstate->off); 1700594e450bSAl Viro off = 0; 170178e1f386SAl Viro if (unlikely(iov_iter_is_discard(i))) { 1702241699cdSAl Viro WARN_ON(1); /* for now */ 1703241699cdSAl Viro return 0; 1704241699cdSAl Viro } 1705d879cb83SAl Viro iterate_and_advance(i, bytes, v, ({ 1706d879cb83SAl Viro next = csum_and_copy_to_user((from += v.iov_len) - v.iov_len, 1707d879cb83SAl Viro v.iov_base, 1708c693cc46SAl Viro v.iov_len); 1709c693cc46SAl Viro if (next) { 1710d879cb83SAl Viro sum = csum_block_add(sum, next, off); 1711d879cb83SAl Viro off += v.iov_len; 1712d879cb83SAl Viro } 1713c693cc46SAl Viro next ? 0 : v.iov_len; 1714d879cb83SAl Viro }), ({ 1715f9152895SAl Viro sum = csum_and_memcpy(v.iov_base, 1716f9152895SAl Viro (from += v.iov_len) - v.iov_len, 1717f9152895SAl Viro v.iov_len, sum, off); 1718d879cb83SAl Viro off += v.iov_len; 1719d879cb83SAl Viro }) 1720d879cb83SAl Viro ) 1721594e450bSAl Viro csstate->csum = csum_shift(sum, csstate->off); 1722594e450bSAl Viro csstate->off += bytes; 1723d879cb83SAl Viro return bytes; 1724d879cb83SAl Viro } 1725d879cb83SAl Viro EXPORT_SYMBOL(csum_and_copy_to_iter); 1726d879cb83SAl Viro 1727d05f4435SSagi Grimberg size_t hash_and_copy_to_iter(const void *addr, size_t bytes, void *hashp, 1728d05f4435SSagi Grimberg struct iov_iter *i) 1729d05f4435SSagi Grimberg { 17307999096fSHerbert Xu #ifdef CONFIG_CRYPTO_HASH 1731d05f4435SSagi Grimberg struct ahash_request *hash = hashp; 1732d05f4435SSagi Grimberg struct scatterlist sg; 1733d05f4435SSagi Grimberg size_t copied; 1734d05f4435SSagi Grimberg 1735d05f4435SSagi Grimberg copied = copy_to_iter(addr, bytes, i); 1736d05f4435SSagi Grimberg sg_init_one(&sg, addr, copied); 1737d05f4435SSagi Grimberg ahash_request_set_crypt(hash, &sg, NULL, copied); 1738d05f4435SSagi Grimberg crypto_ahash_update(hash); 1739d05f4435SSagi Grimberg return copied; 174027fad74aSYueHaibing #else 174127fad74aSYueHaibing return 0; 174227fad74aSYueHaibing #endif 1743d05f4435SSagi Grimberg } 1744d05f4435SSagi Grimberg EXPORT_SYMBOL(hash_and_copy_to_iter); 1745d05f4435SSagi Grimberg 174666531c65SAl Viro static int iov_npages(const struct iov_iter *i, int maxpages) 1747d879cb83SAl Viro { 174866531c65SAl Viro size_t skip = i->iov_offset, size = i->count; 174966531c65SAl Viro const struct iovec *p; 1750d879cb83SAl Viro int npages = 0; 1751d879cb83SAl Viro 175266531c65SAl Viro for (p = i->iov; size; skip = 0, p++) { 175366531c65SAl Viro unsigned offs = offset_in_page(p->iov_base + skip); 175466531c65SAl Viro size_t len = min(p->iov_len - skip, size); 1755d879cb83SAl Viro 175666531c65SAl Viro if (len) { 175766531c65SAl Viro size -= len; 175866531c65SAl Viro npages += DIV_ROUND_UP(offs + len, PAGE_SIZE); 175966531c65SAl Viro if (unlikely(npages > maxpages)) 176066531c65SAl Viro return maxpages; 176166531c65SAl Viro } 176266531c65SAl Viro } 176366531c65SAl Viro return npages; 176466531c65SAl Viro } 176566531c65SAl Viro 176666531c65SAl Viro static int bvec_npages(const struct iov_iter *i, int maxpages) 176766531c65SAl Viro { 176866531c65SAl Viro size_t skip = i->iov_offset, size = i->count; 176966531c65SAl Viro const struct bio_vec *p; 177066531c65SAl Viro int npages = 0; 177166531c65SAl Viro 177266531c65SAl Viro for (p = i->bvec; size; skip = 0, p++) { 177366531c65SAl Viro unsigned offs = (p->bv_offset + skip) % PAGE_SIZE; 177466531c65SAl Viro size_t len = min(p->bv_len - skip, size); 177566531c65SAl Viro 177666531c65SAl Viro size -= len; 177766531c65SAl Viro npages += DIV_ROUND_UP(offs + len, PAGE_SIZE); 177866531c65SAl Viro if (unlikely(npages > maxpages)) 177966531c65SAl Viro return maxpages; 178066531c65SAl Viro } 178166531c65SAl Viro return npages; 178266531c65SAl Viro } 178366531c65SAl Viro 178466531c65SAl Viro int iov_iter_npages(const struct iov_iter *i, int maxpages) 178566531c65SAl Viro { 178666531c65SAl Viro if (unlikely(!i->count)) 178766531c65SAl Viro return 0; 178866531c65SAl Viro /* iovec and kvec have identical layouts */ 178966531c65SAl Viro if (likely(iter_is_iovec(i) || iov_iter_is_kvec(i))) 179066531c65SAl Viro return iov_npages(i, maxpages); 179166531c65SAl Viro if (iov_iter_is_bvec(i)) 179266531c65SAl Viro return bvec_npages(i, maxpages); 179366531c65SAl Viro if (iov_iter_is_pipe(i)) { 17948cefc107SDavid Howells unsigned int iter_head; 179566531c65SAl Viro int npages; 1796241699cdSAl Viro size_t off; 1797241699cdSAl Viro 1798241699cdSAl Viro if (!sanity(i)) 1799241699cdSAl Viro return 0; 1800241699cdSAl Viro 18018cefc107SDavid Howells data_start(i, &iter_head, &off); 1802241699cdSAl Viro /* some of this one + all after this one */ 180366531c65SAl Viro npages = pipe_space_for_user(iter_head, i->pipe->tail, i->pipe); 180466531c65SAl Viro return min(npages, maxpages); 180566531c65SAl Viro } 180666531c65SAl Viro if (iov_iter_is_xarray(i)) { 1807e4f8df86SAl Viro unsigned offset = (i->xarray_start + i->iov_offset) % PAGE_SIZE; 1808e4f8df86SAl Viro int npages = DIV_ROUND_UP(offset + i->count, PAGE_SIZE); 180966531c65SAl Viro return min(npages, maxpages); 181066531c65SAl Viro } 181166531c65SAl Viro return 0; 1812d879cb83SAl Viro } 1813d879cb83SAl Viro EXPORT_SYMBOL(iov_iter_npages); 1814d879cb83SAl Viro 1815d879cb83SAl Viro const void *dup_iter(struct iov_iter *new, struct iov_iter *old, gfp_t flags) 1816d879cb83SAl Viro { 1817d879cb83SAl Viro *new = *old; 181800e23707SDavid Howells if (unlikely(iov_iter_is_pipe(new))) { 1819241699cdSAl Viro WARN_ON(1); 1820241699cdSAl Viro return NULL; 1821241699cdSAl Viro } 18227ff50620SDavid Howells if (unlikely(iov_iter_is_discard(new) || iov_iter_is_xarray(new))) 18239ea9ce04SDavid Howells return NULL; 182400e23707SDavid Howells if (iov_iter_is_bvec(new)) 1825d879cb83SAl Viro return new->bvec = kmemdup(new->bvec, 1826d879cb83SAl Viro new->nr_segs * sizeof(struct bio_vec), 1827d879cb83SAl Viro flags); 1828d879cb83SAl Viro else 1829d879cb83SAl Viro /* iovec and kvec have identical layout */ 1830d879cb83SAl Viro return new->iov = kmemdup(new->iov, 1831d879cb83SAl Viro new->nr_segs * sizeof(struct iovec), 1832d879cb83SAl Viro flags); 1833d879cb83SAl Viro } 1834d879cb83SAl Viro EXPORT_SYMBOL(dup_iter); 1835bc917be8SAl Viro 1836bfdc5970SChristoph Hellwig static int copy_compat_iovec_from_user(struct iovec *iov, 1837bfdc5970SChristoph Hellwig const struct iovec __user *uvec, unsigned long nr_segs) 1838bfdc5970SChristoph Hellwig { 1839bfdc5970SChristoph Hellwig const struct compat_iovec __user *uiov = 1840bfdc5970SChristoph Hellwig (const struct compat_iovec __user *)uvec; 1841bfdc5970SChristoph Hellwig int ret = -EFAULT, i; 1842bfdc5970SChristoph Hellwig 1843a959a978SChristoph Hellwig if (!user_access_begin(uiov, nr_segs * sizeof(*uiov))) 1844bfdc5970SChristoph Hellwig return -EFAULT; 1845bfdc5970SChristoph Hellwig 1846bfdc5970SChristoph Hellwig for (i = 0; i < nr_segs; i++) { 1847bfdc5970SChristoph Hellwig compat_uptr_t buf; 1848bfdc5970SChristoph Hellwig compat_ssize_t len; 1849bfdc5970SChristoph Hellwig 1850bfdc5970SChristoph Hellwig unsafe_get_user(len, &uiov[i].iov_len, uaccess_end); 1851bfdc5970SChristoph Hellwig unsafe_get_user(buf, &uiov[i].iov_base, uaccess_end); 1852bfdc5970SChristoph Hellwig 1853bfdc5970SChristoph Hellwig /* check for compat_size_t not fitting in compat_ssize_t .. */ 1854bfdc5970SChristoph Hellwig if (len < 0) { 1855bfdc5970SChristoph Hellwig ret = -EINVAL; 1856bfdc5970SChristoph Hellwig goto uaccess_end; 1857bfdc5970SChristoph Hellwig } 1858bfdc5970SChristoph Hellwig iov[i].iov_base = compat_ptr(buf); 1859bfdc5970SChristoph Hellwig iov[i].iov_len = len; 1860bfdc5970SChristoph Hellwig } 1861bfdc5970SChristoph Hellwig 1862bfdc5970SChristoph Hellwig ret = 0; 1863bfdc5970SChristoph Hellwig uaccess_end: 1864bfdc5970SChristoph Hellwig user_access_end(); 1865bfdc5970SChristoph Hellwig return ret; 1866bfdc5970SChristoph Hellwig } 1867bfdc5970SChristoph Hellwig 1868bfdc5970SChristoph Hellwig static int copy_iovec_from_user(struct iovec *iov, 1869bfdc5970SChristoph Hellwig const struct iovec __user *uvec, unsigned long nr_segs) 1870fb041b59SDavid Laight { 1871fb041b59SDavid Laight unsigned long seg; 1872bfdc5970SChristoph Hellwig 1873bfdc5970SChristoph Hellwig if (copy_from_user(iov, uvec, nr_segs * sizeof(*uvec))) 1874bfdc5970SChristoph Hellwig return -EFAULT; 1875bfdc5970SChristoph Hellwig for (seg = 0; seg < nr_segs; seg++) { 1876bfdc5970SChristoph Hellwig if ((ssize_t)iov[seg].iov_len < 0) 1877bfdc5970SChristoph Hellwig return -EINVAL; 1878bfdc5970SChristoph Hellwig } 1879bfdc5970SChristoph Hellwig 1880bfdc5970SChristoph Hellwig return 0; 1881bfdc5970SChristoph Hellwig } 1882bfdc5970SChristoph Hellwig 1883bfdc5970SChristoph Hellwig struct iovec *iovec_from_user(const struct iovec __user *uvec, 1884bfdc5970SChristoph Hellwig unsigned long nr_segs, unsigned long fast_segs, 1885bfdc5970SChristoph Hellwig struct iovec *fast_iov, bool compat) 1886bfdc5970SChristoph Hellwig { 1887bfdc5970SChristoph Hellwig struct iovec *iov = fast_iov; 1888bfdc5970SChristoph Hellwig int ret; 1889fb041b59SDavid Laight 1890fb041b59SDavid Laight /* 1891bfdc5970SChristoph Hellwig * SuS says "The readv() function *may* fail if the iovcnt argument was 1892bfdc5970SChristoph Hellwig * less than or equal to 0, or greater than {IOV_MAX}. Linux has 1893fb041b59SDavid Laight * traditionally returned zero for zero segments, so... 1894fb041b59SDavid Laight */ 1895bfdc5970SChristoph Hellwig if (nr_segs == 0) 1896bfdc5970SChristoph Hellwig return iov; 1897bfdc5970SChristoph Hellwig if (nr_segs > UIO_MAXIOV) 1898bfdc5970SChristoph Hellwig return ERR_PTR(-EINVAL); 1899fb041b59SDavid Laight if (nr_segs > fast_segs) { 1900fb041b59SDavid Laight iov = kmalloc_array(nr_segs, sizeof(struct iovec), GFP_KERNEL); 1901bfdc5970SChristoph Hellwig if (!iov) 1902bfdc5970SChristoph Hellwig return ERR_PTR(-ENOMEM); 1903fb041b59SDavid Laight } 1904bfdc5970SChristoph Hellwig 1905bfdc5970SChristoph Hellwig if (compat) 1906bfdc5970SChristoph Hellwig ret = copy_compat_iovec_from_user(iov, uvec, nr_segs); 1907bfdc5970SChristoph Hellwig else 1908bfdc5970SChristoph Hellwig ret = copy_iovec_from_user(iov, uvec, nr_segs); 1909bfdc5970SChristoph Hellwig if (ret) { 1910bfdc5970SChristoph Hellwig if (iov != fast_iov) 1911bfdc5970SChristoph Hellwig kfree(iov); 1912bfdc5970SChristoph Hellwig return ERR_PTR(ret); 1913fb041b59SDavid Laight } 1914bfdc5970SChristoph Hellwig 1915bfdc5970SChristoph Hellwig return iov; 1916bfdc5970SChristoph Hellwig } 1917bfdc5970SChristoph Hellwig 1918bfdc5970SChristoph Hellwig ssize_t __import_iovec(int type, const struct iovec __user *uvec, 1919bfdc5970SChristoph Hellwig unsigned nr_segs, unsigned fast_segs, struct iovec **iovp, 1920bfdc5970SChristoph Hellwig struct iov_iter *i, bool compat) 1921bfdc5970SChristoph Hellwig { 1922bfdc5970SChristoph Hellwig ssize_t total_len = 0; 1923bfdc5970SChristoph Hellwig unsigned long seg; 1924bfdc5970SChristoph Hellwig struct iovec *iov; 1925bfdc5970SChristoph Hellwig 1926bfdc5970SChristoph Hellwig iov = iovec_from_user(uvec, nr_segs, fast_segs, *iovp, compat); 1927bfdc5970SChristoph Hellwig if (IS_ERR(iov)) { 1928bfdc5970SChristoph Hellwig *iovp = NULL; 1929bfdc5970SChristoph Hellwig return PTR_ERR(iov); 1930fb041b59SDavid Laight } 1931fb041b59SDavid Laight 1932fb041b59SDavid Laight /* 1933bfdc5970SChristoph Hellwig * According to the Single Unix Specification we should return EINVAL if 1934bfdc5970SChristoph Hellwig * an element length is < 0 when cast to ssize_t or if the total length 1935bfdc5970SChristoph Hellwig * would overflow the ssize_t return value of the system call. 1936fb041b59SDavid Laight * 1937fb041b59SDavid Laight * Linux caps all read/write calls to MAX_RW_COUNT, and avoids the 1938fb041b59SDavid Laight * overflow case. 1939fb041b59SDavid Laight */ 1940fb041b59SDavid Laight for (seg = 0; seg < nr_segs; seg++) { 1941fb041b59SDavid Laight ssize_t len = (ssize_t)iov[seg].iov_len; 1942fb041b59SDavid Laight 1943bfdc5970SChristoph Hellwig if (!access_ok(iov[seg].iov_base, len)) { 1944bfdc5970SChristoph Hellwig if (iov != *iovp) 1945bfdc5970SChristoph Hellwig kfree(iov); 1946bfdc5970SChristoph Hellwig *iovp = NULL; 1947bfdc5970SChristoph Hellwig return -EFAULT; 1948fb041b59SDavid Laight } 1949bfdc5970SChristoph Hellwig 1950bfdc5970SChristoph Hellwig if (len > MAX_RW_COUNT - total_len) { 1951bfdc5970SChristoph Hellwig len = MAX_RW_COUNT - total_len; 1952fb041b59SDavid Laight iov[seg].iov_len = len; 1953fb041b59SDavid Laight } 1954bfdc5970SChristoph Hellwig total_len += len; 1955fb041b59SDavid Laight } 1956bfdc5970SChristoph Hellwig 1957bfdc5970SChristoph Hellwig iov_iter_init(i, type, iov, nr_segs, total_len); 1958bfdc5970SChristoph Hellwig if (iov == *iovp) 1959bfdc5970SChristoph Hellwig *iovp = NULL; 1960bfdc5970SChristoph Hellwig else 1961bfdc5970SChristoph Hellwig *iovp = iov; 1962bfdc5970SChristoph Hellwig return total_len; 1963fb041b59SDavid Laight } 1964fb041b59SDavid Laight 1965ffecee4fSVegard Nossum /** 1966ffecee4fSVegard Nossum * import_iovec() - Copy an array of &struct iovec from userspace 1967ffecee4fSVegard Nossum * into the kernel, check that it is valid, and initialize a new 1968ffecee4fSVegard Nossum * &struct iov_iter iterator to access it. 1969ffecee4fSVegard Nossum * 1970ffecee4fSVegard Nossum * @type: One of %READ or %WRITE. 1971bfdc5970SChristoph Hellwig * @uvec: Pointer to the userspace array. 1972ffecee4fSVegard Nossum * @nr_segs: Number of elements in userspace array. 1973ffecee4fSVegard Nossum * @fast_segs: Number of elements in @iov. 1974bfdc5970SChristoph Hellwig * @iovp: (input and output parameter) Pointer to pointer to (usually small 1975ffecee4fSVegard Nossum * on-stack) kernel array. 1976ffecee4fSVegard Nossum * @i: Pointer to iterator that will be initialized on success. 1977ffecee4fSVegard Nossum * 1978ffecee4fSVegard Nossum * If the array pointed to by *@iov is large enough to hold all @nr_segs, 1979ffecee4fSVegard Nossum * then this function places %NULL in *@iov on return. Otherwise, a new 1980ffecee4fSVegard Nossum * array will be allocated and the result placed in *@iov. This means that 1981ffecee4fSVegard Nossum * the caller may call kfree() on *@iov regardless of whether the small 1982ffecee4fSVegard Nossum * on-stack array was used or not (and regardless of whether this function 1983ffecee4fSVegard Nossum * returns an error or not). 1984ffecee4fSVegard Nossum * 198587e5e6daSJens Axboe * Return: Negative error code on error, bytes imported on success 1986ffecee4fSVegard Nossum */ 1987bfdc5970SChristoph Hellwig ssize_t import_iovec(int type, const struct iovec __user *uvec, 1988bc917be8SAl Viro unsigned nr_segs, unsigned fast_segs, 1989bfdc5970SChristoph Hellwig struct iovec **iovp, struct iov_iter *i) 1990bc917be8SAl Viro { 199189cd35c5SChristoph Hellwig return __import_iovec(type, uvec, nr_segs, fast_segs, iovp, i, 199289cd35c5SChristoph Hellwig in_compat_syscall()); 1993bc917be8SAl Viro } 1994bc917be8SAl Viro EXPORT_SYMBOL(import_iovec); 1995bc917be8SAl Viro 1996bc917be8SAl Viro int import_single_range(int rw, void __user *buf, size_t len, 1997bc917be8SAl Viro struct iovec *iov, struct iov_iter *i) 1998bc917be8SAl Viro { 1999bc917be8SAl Viro if (len > MAX_RW_COUNT) 2000bc917be8SAl Viro len = MAX_RW_COUNT; 200196d4f267SLinus Torvalds if (unlikely(!access_ok(buf, len))) 2002bc917be8SAl Viro return -EFAULT; 2003bc917be8SAl Viro 2004bc917be8SAl Viro iov->iov_base = buf; 2005bc917be8SAl Viro iov->iov_len = len; 2006bc917be8SAl Viro iov_iter_init(i, rw, iov, 1, len); 2007bc917be8SAl Viro return 0; 2008bc917be8SAl Viro } 2009e1267585SAl Viro EXPORT_SYMBOL(import_single_range); 2010