1457c8996SThomas Gleixner // SPDX-License-Identifier: GPL-2.0-only 27999096fSHerbert Xu #include <crypto/hash.h> 3d879cb83SAl Viro #include <linux/export.h> 42f8b5444SChristoph Hellwig #include <linux/bvec.h> 54d0e9df5SAlbert van der Linde #include <linux/fault-inject-usercopy.h> 6d879cb83SAl Viro #include <linux/uio.h> 7d879cb83SAl Viro #include <linux/pagemap.h> 8d879cb83SAl Viro #include <linux/slab.h> 9d879cb83SAl Viro #include <linux/vmalloc.h> 10241699cdSAl Viro #include <linux/splice.h> 11bfdc5970SChristoph Hellwig #include <linux/compat.h> 12d879cb83SAl Viro #include <net/checksum.h> 13d05f4435SSagi Grimberg #include <linux/scatterlist.h> 14d0ef4c36SMarco Elver #include <linux/instrumented.h> 15d879cb83SAl Viro 16241699cdSAl Viro #define PIPE_PARANOIA /* for now */ 17241699cdSAl Viro 18d879cb83SAl Viro #define iterate_iovec(i, n, __v, __p, skip, STEP) { \ 19d879cb83SAl Viro size_t left; \ 20d879cb83SAl Viro size_t wanted = n; \ 21d879cb83SAl Viro __p = i->iov; \ 22d879cb83SAl Viro __v.iov_len = min(n, __p->iov_len - skip); \ 23d879cb83SAl Viro if (likely(__v.iov_len)) { \ 24d879cb83SAl Viro __v.iov_base = __p->iov_base + skip; \ 25d879cb83SAl Viro left = (STEP); \ 26d879cb83SAl Viro __v.iov_len -= left; \ 27d879cb83SAl Viro skip += __v.iov_len; \ 28d879cb83SAl Viro n -= __v.iov_len; \ 29d879cb83SAl Viro } else { \ 30d879cb83SAl Viro left = 0; \ 31d879cb83SAl Viro } \ 32d879cb83SAl Viro while (unlikely(!left && n)) { \ 33d879cb83SAl Viro __p++; \ 34d879cb83SAl Viro __v.iov_len = min(n, __p->iov_len); \ 35d879cb83SAl Viro if (unlikely(!__v.iov_len)) \ 36d879cb83SAl Viro continue; \ 37d879cb83SAl Viro __v.iov_base = __p->iov_base; \ 38d879cb83SAl Viro left = (STEP); \ 39d879cb83SAl Viro __v.iov_len -= left; \ 40d879cb83SAl Viro skip = __v.iov_len; \ 41d879cb83SAl Viro n -= __v.iov_len; \ 42d879cb83SAl Viro } \ 43d879cb83SAl Viro n = wanted - n; \ 44d879cb83SAl Viro } 45d879cb83SAl Viro 46d879cb83SAl Viro #define iterate_kvec(i, n, __v, __p, skip, STEP) { \ 47d879cb83SAl Viro size_t wanted = n; \ 48d879cb83SAl Viro __p = i->kvec; \ 49d879cb83SAl Viro __v.iov_len = min(n, __p->iov_len - skip); \ 50d879cb83SAl Viro if (likely(__v.iov_len)) { \ 51d879cb83SAl Viro __v.iov_base = __p->iov_base + skip; \ 52d879cb83SAl Viro (void)(STEP); \ 53d879cb83SAl Viro skip += __v.iov_len; \ 54d879cb83SAl Viro n -= __v.iov_len; \ 55d879cb83SAl Viro } \ 56d879cb83SAl Viro while (unlikely(n)) { \ 57d879cb83SAl Viro __p++; \ 58d879cb83SAl Viro __v.iov_len = min(n, __p->iov_len); \ 59d879cb83SAl Viro if (unlikely(!__v.iov_len)) \ 60d879cb83SAl Viro continue; \ 61d879cb83SAl Viro __v.iov_base = __p->iov_base; \ 62d879cb83SAl Viro (void)(STEP); \ 63d879cb83SAl Viro skip = __v.iov_len; \ 64d879cb83SAl Viro n -= __v.iov_len; \ 65d879cb83SAl Viro } \ 66d879cb83SAl Viro n = wanted; \ 67d879cb83SAl Viro } 68d879cb83SAl Viro 691bdc76aeSMing Lei #define iterate_bvec(i, n, __v, __bi, skip, STEP) { \ 701bdc76aeSMing Lei struct bvec_iter __start; \ 711bdc76aeSMing Lei __start.bi_size = n; \ 721bdc76aeSMing Lei __start.bi_bvec_done = skip; \ 731bdc76aeSMing Lei __start.bi_idx = 0; \ 741bdc76aeSMing Lei for_each_bvec(__v, i->bvec, __bi, __start) { \ 75d879cb83SAl Viro (void)(STEP); \ 76d879cb83SAl Viro } \ 77d879cb83SAl Viro } 78d879cb83SAl Viro 797ff50620SDavid Howells #define iterate_xarray(i, n, __v, skip, STEP) { \ 807ff50620SDavid Howells struct page *head = NULL; \ 817ff50620SDavid Howells size_t wanted = n, seg, offset; \ 827ff50620SDavid Howells loff_t start = i->xarray_start + skip; \ 837ff50620SDavid Howells pgoff_t index = start >> PAGE_SHIFT; \ 847ff50620SDavid Howells int j; \ 857ff50620SDavid Howells \ 867ff50620SDavid Howells XA_STATE(xas, i->xarray, index); \ 877ff50620SDavid Howells \ 887ff50620SDavid Howells rcu_read_lock(); \ 897ff50620SDavid Howells xas_for_each(&xas, head, ULONG_MAX) { \ 907ff50620SDavid Howells if (xas_retry(&xas, head)) \ 917ff50620SDavid Howells continue; \ 927ff50620SDavid Howells if (WARN_ON(xa_is_value(head))) \ 937ff50620SDavid Howells break; \ 947ff50620SDavid Howells if (WARN_ON(PageHuge(head))) \ 957ff50620SDavid Howells break; \ 967ff50620SDavid Howells for (j = (head->index < index) ? index - head->index : 0; \ 977ff50620SDavid Howells j < thp_nr_pages(head); j++) { \ 987ff50620SDavid Howells __v.bv_page = head + j; \ 997ff50620SDavid Howells offset = (i->xarray_start + skip) & ~PAGE_MASK; \ 1007ff50620SDavid Howells seg = PAGE_SIZE - offset; \ 1017ff50620SDavid Howells __v.bv_offset = offset; \ 1027ff50620SDavid Howells __v.bv_len = min(n, seg); \ 1037ff50620SDavid Howells (void)(STEP); \ 1047ff50620SDavid Howells n -= __v.bv_len; \ 1057ff50620SDavid Howells skip += __v.bv_len; \ 1067ff50620SDavid Howells if (n == 0) \ 1077ff50620SDavid Howells break; \ 1087ff50620SDavid Howells } \ 1097ff50620SDavid Howells if (n == 0) \ 1107ff50620SDavid Howells break; \ 1117ff50620SDavid Howells } \ 1127ff50620SDavid Howells rcu_read_unlock(); \ 1137ff50620SDavid Howells n = wanted - n; \ 1147ff50620SDavid Howells } 1157ff50620SDavid Howells 1167ff50620SDavid Howells #define iterate_all_kinds(i, n, v, I, B, K, X) { \ 11733844e66SAl Viro if (likely(n)) { \ 118d879cb83SAl Viro size_t skip = i->iov_offset; \ 119d879cb83SAl Viro if (unlikely(i->type & ITER_BVEC)) { \ 120d879cb83SAl Viro struct bio_vec v; \ 1211bdc76aeSMing Lei struct bvec_iter __bi; \ 1221bdc76aeSMing Lei iterate_bvec(i, n, v, __bi, skip, (B)) \ 123d879cb83SAl Viro } else if (unlikely(i->type & ITER_KVEC)) { \ 124d879cb83SAl Viro const struct kvec *kvec; \ 125d879cb83SAl Viro struct kvec v; \ 126d879cb83SAl Viro iterate_kvec(i, n, v, kvec, skip, (K)) \ 1279ea9ce04SDavid Howells } else if (unlikely(i->type & ITER_DISCARD)) { \ 1287ff50620SDavid Howells } else if (unlikely(i->type & ITER_XARRAY)) { \ 1297ff50620SDavid Howells struct bio_vec v; \ 1307ff50620SDavid Howells iterate_xarray(i, n, v, skip, (X)); \ 131d879cb83SAl Viro } else { \ 132d879cb83SAl Viro const struct iovec *iov; \ 133d879cb83SAl Viro struct iovec v; \ 134d879cb83SAl Viro iterate_iovec(i, n, v, iov, skip, (I)) \ 135d879cb83SAl Viro } \ 13633844e66SAl Viro } \ 137d879cb83SAl Viro } 138d879cb83SAl Viro 1397ff50620SDavid Howells #define iterate_and_advance(i, n, v, I, B, K, X) { \ 140dd254f5aSAl Viro if (unlikely(i->count < n)) \ 141dd254f5aSAl Viro n = i->count; \ 14219f18459SAl Viro if (i->count) { \ 143d879cb83SAl Viro size_t skip = i->iov_offset; \ 144d879cb83SAl Viro if (unlikely(i->type & ITER_BVEC)) { \ 1451bdc76aeSMing Lei const struct bio_vec *bvec = i->bvec; \ 146d879cb83SAl Viro struct bio_vec v; \ 1471bdc76aeSMing Lei struct bvec_iter __bi; \ 1481bdc76aeSMing Lei iterate_bvec(i, n, v, __bi, skip, (B)) \ 1491bdc76aeSMing Lei i->bvec = __bvec_iter_bvec(i->bvec, __bi); \ 1501bdc76aeSMing Lei i->nr_segs -= i->bvec - bvec; \ 1511bdc76aeSMing Lei skip = __bi.bi_bvec_done; \ 152d879cb83SAl Viro } else if (unlikely(i->type & ITER_KVEC)) { \ 153d879cb83SAl Viro const struct kvec *kvec; \ 154d879cb83SAl Viro struct kvec v; \ 155d879cb83SAl Viro iterate_kvec(i, n, v, kvec, skip, (K)) \ 156d879cb83SAl Viro if (skip == kvec->iov_len) { \ 157d879cb83SAl Viro kvec++; \ 158d879cb83SAl Viro skip = 0; \ 159d879cb83SAl Viro } \ 160d879cb83SAl Viro i->nr_segs -= kvec - i->kvec; \ 161d879cb83SAl Viro i->kvec = kvec; \ 1629ea9ce04SDavid Howells } else if (unlikely(i->type & ITER_DISCARD)) { \ 1639ea9ce04SDavid Howells skip += n; \ 1647ff50620SDavid Howells } else if (unlikely(i->type & ITER_XARRAY)) { \ 1657ff50620SDavid Howells struct bio_vec v; \ 1667ff50620SDavid Howells iterate_xarray(i, n, v, skip, (X)) \ 167d879cb83SAl Viro } else { \ 168d879cb83SAl Viro const struct iovec *iov; \ 169d879cb83SAl Viro struct iovec v; \ 170d879cb83SAl Viro iterate_iovec(i, n, v, iov, skip, (I)) \ 171d879cb83SAl Viro if (skip == iov->iov_len) { \ 172d879cb83SAl Viro iov++; \ 173d879cb83SAl Viro skip = 0; \ 174d879cb83SAl Viro } \ 175d879cb83SAl Viro i->nr_segs -= iov - i->iov; \ 176d879cb83SAl Viro i->iov = iov; \ 177d879cb83SAl Viro } \ 178d879cb83SAl Viro i->count -= n; \ 179d879cb83SAl Viro i->iov_offset = skip; \ 180dd254f5aSAl Viro } \ 181d879cb83SAl Viro } 182d879cb83SAl Viro 18309fc68dcSAl Viro static int copyout(void __user *to, const void *from, size_t n) 18409fc68dcSAl Viro { 1854d0e9df5SAlbert van der Linde if (should_fail_usercopy()) 1864d0e9df5SAlbert van der Linde return n; 18796d4f267SLinus Torvalds if (access_ok(to, n)) { 188d0ef4c36SMarco Elver instrument_copy_to_user(to, from, n); 18909fc68dcSAl Viro n = raw_copy_to_user(to, from, n); 19009fc68dcSAl Viro } 19109fc68dcSAl Viro return n; 19209fc68dcSAl Viro } 19309fc68dcSAl Viro 19409fc68dcSAl Viro static int copyin(void *to, const void __user *from, size_t n) 19509fc68dcSAl Viro { 1964d0e9df5SAlbert van der Linde if (should_fail_usercopy()) 1974d0e9df5SAlbert van der Linde return n; 19896d4f267SLinus Torvalds if (access_ok(from, n)) { 199d0ef4c36SMarco Elver instrument_copy_from_user(to, from, n); 20009fc68dcSAl Viro n = raw_copy_from_user(to, from, n); 20109fc68dcSAl Viro } 20209fc68dcSAl Viro return n; 20309fc68dcSAl Viro } 20409fc68dcSAl Viro 205d879cb83SAl Viro static size_t copy_page_to_iter_iovec(struct page *page, size_t offset, size_t bytes, 206d879cb83SAl Viro struct iov_iter *i) 207d879cb83SAl Viro { 208d879cb83SAl Viro size_t skip, copy, left, wanted; 209d879cb83SAl Viro const struct iovec *iov; 210d879cb83SAl Viro char __user *buf; 211d879cb83SAl Viro void *kaddr, *from; 212d879cb83SAl Viro 213d879cb83SAl Viro if (unlikely(bytes > i->count)) 214d879cb83SAl Viro bytes = i->count; 215d879cb83SAl Viro 216d879cb83SAl Viro if (unlikely(!bytes)) 217d879cb83SAl Viro return 0; 218d879cb83SAl Viro 21909fc68dcSAl Viro might_fault(); 220d879cb83SAl Viro wanted = bytes; 221d879cb83SAl Viro iov = i->iov; 222d879cb83SAl Viro skip = i->iov_offset; 223d879cb83SAl Viro buf = iov->iov_base + skip; 224d879cb83SAl Viro copy = min(bytes, iov->iov_len - skip); 225d879cb83SAl Viro 2263fa6c507SMikulas Patocka if (IS_ENABLED(CONFIG_HIGHMEM) && !fault_in_pages_writeable(buf, copy)) { 227d879cb83SAl Viro kaddr = kmap_atomic(page); 228d879cb83SAl Viro from = kaddr + offset; 229d879cb83SAl Viro 230d879cb83SAl Viro /* first chunk, usually the only one */ 23109fc68dcSAl Viro left = copyout(buf, from, copy); 232d879cb83SAl Viro copy -= left; 233d879cb83SAl Viro skip += copy; 234d879cb83SAl Viro from += copy; 235d879cb83SAl Viro bytes -= copy; 236d879cb83SAl Viro 237d879cb83SAl Viro while (unlikely(!left && bytes)) { 238d879cb83SAl Viro iov++; 239d879cb83SAl Viro buf = iov->iov_base; 240d879cb83SAl Viro copy = min(bytes, iov->iov_len); 24109fc68dcSAl Viro left = copyout(buf, from, copy); 242d879cb83SAl Viro copy -= left; 243d879cb83SAl Viro skip = copy; 244d879cb83SAl Viro from += copy; 245d879cb83SAl Viro bytes -= copy; 246d879cb83SAl Viro } 247d879cb83SAl Viro if (likely(!bytes)) { 248d879cb83SAl Viro kunmap_atomic(kaddr); 249d879cb83SAl Viro goto done; 250d879cb83SAl Viro } 251d879cb83SAl Viro offset = from - kaddr; 252d879cb83SAl Viro buf += copy; 253d879cb83SAl Viro kunmap_atomic(kaddr); 254d879cb83SAl Viro copy = min(bytes, iov->iov_len - skip); 255d879cb83SAl Viro } 256d879cb83SAl Viro /* Too bad - revert to non-atomic kmap */ 2573fa6c507SMikulas Patocka 258d879cb83SAl Viro kaddr = kmap(page); 259d879cb83SAl Viro from = kaddr + offset; 26009fc68dcSAl Viro left = copyout(buf, from, copy); 261d879cb83SAl Viro copy -= left; 262d879cb83SAl Viro skip += copy; 263d879cb83SAl Viro from += copy; 264d879cb83SAl Viro bytes -= copy; 265d879cb83SAl Viro while (unlikely(!left && bytes)) { 266d879cb83SAl Viro iov++; 267d879cb83SAl Viro buf = iov->iov_base; 268d879cb83SAl Viro copy = min(bytes, iov->iov_len); 26909fc68dcSAl Viro left = copyout(buf, from, copy); 270d879cb83SAl Viro copy -= left; 271d879cb83SAl Viro skip = copy; 272d879cb83SAl Viro from += copy; 273d879cb83SAl Viro bytes -= copy; 274d879cb83SAl Viro } 275d879cb83SAl Viro kunmap(page); 2763fa6c507SMikulas Patocka 277d879cb83SAl Viro done: 278d879cb83SAl Viro if (skip == iov->iov_len) { 279d879cb83SAl Viro iov++; 280d879cb83SAl Viro skip = 0; 281d879cb83SAl Viro } 282d879cb83SAl Viro i->count -= wanted - bytes; 283d879cb83SAl Viro i->nr_segs -= iov - i->iov; 284d879cb83SAl Viro i->iov = iov; 285d879cb83SAl Viro i->iov_offset = skip; 286d879cb83SAl Viro return wanted - bytes; 287d879cb83SAl Viro } 288d879cb83SAl Viro 289d879cb83SAl Viro static size_t copy_page_from_iter_iovec(struct page *page, size_t offset, size_t bytes, 290d879cb83SAl Viro struct iov_iter *i) 291d879cb83SAl Viro { 292d879cb83SAl Viro size_t skip, copy, left, wanted; 293d879cb83SAl Viro const struct iovec *iov; 294d879cb83SAl Viro char __user *buf; 295d879cb83SAl Viro void *kaddr, *to; 296d879cb83SAl Viro 297d879cb83SAl Viro if (unlikely(bytes > i->count)) 298d879cb83SAl Viro bytes = i->count; 299d879cb83SAl Viro 300d879cb83SAl Viro if (unlikely(!bytes)) 301d879cb83SAl Viro return 0; 302d879cb83SAl Viro 30309fc68dcSAl Viro might_fault(); 304d879cb83SAl Viro wanted = bytes; 305d879cb83SAl Viro iov = i->iov; 306d879cb83SAl Viro skip = i->iov_offset; 307d879cb83SAl Viro buf = iov->iov_base + skip; 308d879cb83SAl Viro copy = min(bytes, iov->iov_len - skip); 309d879cb83SAl Viro 3103fa6c507SMikulas Patocka if (IS_ENABLED(CONFIG_HIGHMEM) && !fault_in_pages_readable(buf, copy)) { 311d879cb83SAl Viro kaddr = kmap_atomic(page); 312d879cb83SAl Viro to = kaddr + offset; 313d879cb83SAl Viro 314d879cb83SAl Viro /* first chunk, usually the only one */ 31509fc68dcSAl Viro left = copyin(to, buf, copy); 316d879cb83SAl Viro copy -= left; 317d879cb83SAl Viro skip += copy; 318d879cb83SAl Viro to += copy; 319d879cb83SAl Viro bytes -= copy; 320d879cb83SAl Viro 321d879cb83SAl Viro while (unlikely(!left && bytes)) { 322d879cb83SAl Viro iov++; 323d879cb83SAl Viro buf = iov->iov_base; 324d879cb83SAl Viro copy = min(bytes, iov->iov_len); 32509fc68dcSAl Viro left = copyin(to, buf, copy); 326d879cb83SAl Viro copy -= left; 327d879cb83SAl Viro skip = copy; 328d879cb83SAl Viro to += copy; 329d879cb83SAl Viro bytes -= copy; 330d879cb83SAl Viro } 331d879cb83SAl Viro if (likely(!bytes)) { 332d879cb83SAl Viro kunmap_atomic(kaddr); 333d879cb83SAl Viro goto done; 334d879cb83SAl Viro } 335d879cb83SAl Viro offset = to - kaddr; 336d879cb83SAl Viro buf += copy; 337d879cb83SAl Viro kunmap_atomic(kaddr); 338d879cb83SAl Viro copy = min(bytes, iov->iov_len - skip); 339d879cb83SAl Viro } 340d879cb83SAl Viro /* Too bad - revert to non-atomic kmap */ 3413fa6c507SMikulas Patocka 342d879cb83SAl Viro kaddr = kmap(page); 343d879cb83SAl Viro to = kaddr + offset; 34409fc68dcSAl Viro left = copyin(to, buf, copy); 345d879cb83SAl Viro copy -= left; 346d879cb83SAl Viro skip += copy; 347d879cb83SAl Viro to += copy; 348d879cb83SAl Viro bytes -= copy; 349d879cb83SAl Viro while (unlikely(!left && bytes)) { 350d879cb83SAl Viro iov++; 351d879cb83SAl Viro buf = iov->iov_base; 352d879cb83SAl Viro copy = min(bytes, iov->iov_len); 35309fc68dcSAl Viro left = copyin(to, buf, copy); 354d879cb83SAl Viro copy -= left; 355d879cb83SAl Viro skip = copy; 356d879cb83SAl Viro to += copy; 357d879cb83SAl Viro bytes -= copy; 358d879cb83SAl Viro } 359d879cb83SAl Viro kunmap(page); 3603fa6c507SMikulas Patocka 361d879cb83SAl Viro done: 362d879cb83SAl Viro if (skip == iov->iov_len) { 363d879cb83SAl Viro iov++; 364d879cb83SAl Viro skip = 0; 365d879cb83SAl Viro } 366d879cb83SAl Viro i->count -= wanted - bytes; 367d879cb83SAl Viro i->nr_segs -= iov - i->iov; 368d879cb83SAl Viro i->iov = iov; 369d879cb83SAl Viro i->iov_offset = skip; 370d879cb83SAl Viro return wanted - bytes; 371d879cb83SAl Viro } 372d879cb83SAl Viro 373241699cdSAl Viro #ifdef PIPE_PARANOIA 374241699cdSAl Viro static bool sanity(const struct iov_iter *i) 375241699cdSAl Viro { 376241699cdSAl Viro struct pipe_inode_info *pipe = i->pipe; 3778cefc107SDavid Howells unsigned int p_head = pipe->head; 3788cefc107SDavid Howells unsigned int p_tail = pipe->tail; 3798cefc107SDavid Howells unsigned int p_mask = pipe->ring_size - 1; 3808cefc107SDavid Howells unsigned int p_occupancy = pipe_occupancy(p_head, p_tail); 3818cefc107SDavid Howells unsigned int i_head = i->head; 3828cefc107SDavid Howells unsigned int idx; 3838cefc107SDavid Howells 384241699cdSAl Viro if (i->iov_offset) { 385241699cdSAl Viro struct pipe_buffer *p; 3868cefc107SDavid Howells if (unlikely(p_occupancy == 0)) 387241699cdSAl Viro goto Bad; // pipe must be non-empty 3888cefc107SDavid Howells if (unlikely(i_head != p_head - 1)) 389241699cdSAl Viro goto Bad; // must be at the last buffer... 390241699cdSAl Viro 3918cefc107SDavid Howells p = &pipe->bufs[i_head & p_mask]; 392241699cdSAl Viro if (unlikely(p->offset + p->len != i->iov_offset)) 393241699cdSAl Viro goto Bad; // ... at the end of segment 394241699cdSAl Viro } else { 3958cefc107SDavid Howells if (i_head != p_head) 396241699cdSAl Viro goto Bad; // must be right after the last buffer 397241699cdSAl Viro } 398241699cdSAl Viro return true; 399241699cdSAl Viro Bad: 4008cefc107SDavid Howells printk(KERN_ERR "idx = %d, offset = %zd\n", i_head, i->iov_offset); 4018cefc107SDavid Howells printk(KERN_ERR "head = %d, tail = %d, buffers = %d\n", 4028cefc107SDavid Howells p_head, p_tail, pipe->ring_size); 4038cefc107SDavid Howells for (idx = 0; idx < pipe->ring_size; idx++) 404241699cdSAl Viro printk(KERN_ERR "[%p %p %d %d]\n", 405241699cdSAl Viro pipe->bufs[idx].ops, 406241699cdSAl Viro pipe->bufs[idx].page, 407241699cdSAl Viro pipe->bufs[idx].offset, 408241699cdSAl Viro pipe->bufs[idx].len); 409241699cdSAl Viro WARN_ON(1); 410241699cdSAl Viro return false; 411241699cdSAl Viro } 412241699cdSAl Viro #else 413241699cdSAl Viro #define sanity(i) true 414241699cdSAl Viro #endif 415241699cdSAl Viro 416241699cdSAl Viro static size_t copy_page_to_iter_pipe(struct page *page, size_t offset, size_t bytes, 417241699cdSAl Viro struct iov_iter *i) 418241699cdSAl Viro { 419241699cdSAl Viro struct pipe_inode_info *pipe = i->pipe; 420241699cdSAl Viro struct pipe_buffer *buf; 4218cefc107SDavid Howells unsigned int p_tail = pipe->tail; 4228cefc107SDavid Howells unsigned int p_mask = pipe->ring_size - 1; 4238cefc107SDavid Howells unsigned int i_head = i->head; 424241699cdSAl Viro size_t off; 425241699cdSAl Viro 426241699cdSAl Viro if (unlikely(bytes > i->count)) 427241699cdSAl Viro bytes = i->count; 428241699cdSAl Viro 429241699cdSAl Viro if (unlikely(!bytes)) 430241699cdSAl Viro return 0; 431241699cdSAl Viro 432241699cdSAl Viro if (!sanity(i)) 433241699cdSAl Viro return 0; 434241699cdSAl Viro 435241699cdSAl Viro off = i->iov_offset; 4368cefc107SDavid Howells buf = &pipe->bufs[i_head & p_mask]; 437241699cdSAl Viro if (off) { 438241699cdSAl Viro if (offset == off && buf->page == page) { 439241699cdSAl Viro /* merge with the last one */ 440241699cdSAl Viro buf->len += bytes; 441241699cdSAl Viro i->iov_offset += bytes; 442241699cdSAl Viro goto out; 443241699cdSAl Viro } 4448cefc107SDavid Howells i_head++; 4458cefc107SDavid Howells buf = &pipe->bufs[i_head & p_mask]; 446241699cdSAl Viro } 4476718b6f8SDavid Howells if (pipe_full(i_head, p_tail, pipe->max_usage)) 448241699cdSAl Viro return 0; 4498cefc107SDavid Howells 450241699cdSAl Viro buf->ops = &page_cache_pipe_buf_ops; 4518cefc107SDavid Howells get_page(page); 4528cefc107SDavid Howells buf->page = page; 453241699cdSAl Viro buf->offset = offset; 454241699cdSAl Viro buf->len = bytes; 4558cefc107SDavid Howells 4568cefc107SDavid Howells pipe->head = i_head + 1; 457241699cdSAl Viro i->iov_offset = offset + bytes; 4588cefc107SDavid Howells i->head = i_head; 459241699cdSAl Viro out: 460241699cdSAl Viro i->count -= bytes; 461241699cdSAl Viro return bytes; 462241699cdSAl Viro } 463241699cdSAl Viro 464d879cb83SAl Viro /* 465171a0203SAnton Altaparmakov * Fault in one or more iovecs of the given iov_iter, to a maximum length of 466171a0203SAnton Altaparmakov * bytes. For each iovec, fault in each page that constitutes the iovec. 467171a0203SAnton Altaparmakov * 468171a0203SAnton Altaparmakov * Return 0 on success, or non-zero if the memory could not be accessed (i.e. 469171a0203SAnton Altaparmakov * because it is an invalid address). 470171a0203SAnton Altaparmakov */ 471d4690f1eSAl Viro int iov_iter_fault_in_readable(struct iov_iter *i, size_t bytes) 472171a0203SAnton Altaparmakov { 473171a0203SAnton Altaparmakov size_t skip = i->iov_offset; 474171a0203SAnton Altaparmakov const struct iovec *iov; 475171a0203SAnton Altaparmakov int err; 476171a0203SAnton Altaparmakov struct iovec v; 477171a0203SAnton Altaparmakov 478171a0203SAnton Altaparmakov if (!(i->type & (ITER_BVEC|ITER_KVEC))) { 479171a0203SAnton Altaparmakov iterate_iovec(i, bytes, v, iov, skip, ({ 4804bce9f6eSAl Viro err = fault_in_pages_readable(v.iov_base, v.iov_len); 481171a0203SAnton Altaparmakov if (unlikely(err)) 482171a0203SAnton Altaparmakov return err; 483171a0203SAnton Altaparmakov 0;})) 484171a0203SAnton Altaparmakov } 485171a0203SAnton Altaparmakov return 0; 486171a0203SAnton Altaparmakov } 487d4690f1eSAl Viro EXPORT_SYMBOL(iov_iter_fault_in_readable); 488171a0203SAnton Altaparmakov 489aa563d7bSDavid Howells void iov_iter_init(struct iov_iter *i, unsigned int direction, 490d879cb83SAl Viro const struct iovec *iov, unsigned long nr_segs, 491d879cb83SAl Viro size_t count) 492d879cb83SAl Viro { 493aa563d7bSDavid Howells WARN_ON(direction & ~(READ | WRITE)); 494aa563d7bSDavid Howells direction &= READ | WRITE; 495aa563d7bSDavid Howells 496d879cb83SAl Viro /* It will get better. Eventually... */ 497db68ce10SAl Viro if (uaccess_kernel()) { 498aa563d7bSDavid Howells i->type = ITER_KVEC | direction; 499d879cb83SAl Viro i->kvec = (struct kvec *)iov; 500d879cb83SAl Viro } else { 501aa563d7bSDavid Howells i->type = ITER_IOVEC | direction; 502d879cb83SAl Viro i->iov = iov; 503d879cb83SAl Viro } 504d879cb83SAl Viro i->nr_segs = nr_segs; 505d879cb83SAl Viro i->iov_offset = 0; 506d879cb83SAl Viro i->count = count; 507d879cb83SAl Viro } 508d879cb83SAl Viro EXPORT_SYMBOL(iov_iter_init); 509d879cb83SAl Viro 510d879cb83SAl Viro static void memzero_page(struct page *page, size_t offset, size_t len) 511d879cb83SAl Viro { 512d879cb83SAl Viro char *addr = kmap_atomic(page); 513d879cb83SAl Viro memset(addr + offset, 0, len); 514d879cb83SAl Viro kunmap_atomic(addr); 515d879cb83SAl Viro } 516d879cb83SAl Viro 517241699cdSAl Viro static inline bool allocated(struct pipe_buffer *buf) 518241699cdSAl Viro { 519241699cdSAl Viro return buf->ops == &default_pipe_buf_ops; 520241699cdSAl Viro } 521241699cdSAl Viro 5228cefc107SDavid Howells static inline void data_start(const struct iov_iter *i, 5238cefc107SDavid Howells unsigned int *iter_headp, size_t *offp) 524241699cdSAl Viro { 5258cefc107SDavid Howells unsigned int p_mask = i->pipe->ring_size - 1; 5268cefc107SDavid Howells unsigned int iter_head = i->head; 527241699cdSAl Viro size_t off = i->iov_offset; 5288cefc107SDavid Howells 5298cefc107SDavid Howells if (off && (!allocated(&i->pipe->bufs[iter_head & p_mask]) || 5308cefc107SDavid Howells off == PAGE_SIZE)) { 5318cefc107SDavid Howells iter_head++; 532241699cdSAl Viro off = 0; 533241699cdSAl Viro } 5348cefc107SDavid Howells *iter_headp = iter_head; 535241699cdSAl Viro *offp = off; 536241699cdSAl Viro } 537241699cdSAl Viro 538241699cdSAl Viro static size_t push_pipe(struct iov_iter *i, size_t size, 5398cefc107SDavid Howells int *iter_headp, size_t *offp) 540241699cdSAl Viro { 541241699cdSAl Viro struct pipe_inode_info *pipe = i->pipe; 5428cefc107SDavid Howells unsigned int p_tail = pipe->tail; 5438cefc107SDavid Howells unsigned int p_mask = pipe->ring_size - 1; 5448cefc107SDavid Howells unsigned int iter_head; 545241699cdSAl Viro size_t off; 546241699cdSAl Viro ssize_t left; 547241699cdSAl Viro 548241699cdSAl Viro if (unlikely(size > i->count)) 549241699cdSAl Viro size = i->count; 550241699cdSAl Viro if (unlikely(!size)) 551241699cdSAl Viro return 0; 552241699cdSAl Viro 553241699cdSAl Viro left = size; 5548cefc107SDavid Howells data_start(i, &iter_head, &off); 5558cefc107SDavid Howells *iter_headp = iter_head; 556241699cdSAl Viro *offp = off; 557241699cdSAl Viro if (off) { 558241699cdSAl Viro left -= PAGE_SIZE - off; 559241699cdSAl Viro if (left <= 0) { 5608cefc107SDavid Howells pipe->bufs[iter_head & p_mask].len += size; 561241699cdSAl Viro return size; 562241699cdSAl Viro } 5638cefc107SDavid Howells pipe->bufs[iter_head & p_mask].len = PAGE_SIZE; 5648cefc107SDavid Howells iter_head++; 565241699cdSAl Viro } 5666718b6f8SDavid Howells while (!pipe_full(iter_head, p_tail, pipe->max_usage)) { 5678cefc107SDavid Howells struct pipe_buffer *buf = &pipe->bufs[iter_head & p_mask]; 568241699cdSAl Viro struct page *page = alloc_page(GFP_USER); 569241699cdSAl Viro if (!page) 570241699cdSAl Viro break; 5718cefc107SDavid Howells 5728cefc107SDavid Howells buf->ops = &default_pipe_buf_ops; 5738cefc107SDavid Howells buf->page = page; 5748cefc107SDavid Howells buf->offset = 0; 5758cefc107SDavid Howells buf->len = min_t(ssize_t, left, PAGE_SIZE); 5768cefc107SDavid Howells left -= buf->len; 5778cefc107SDavid Howells iter_head++; 5788cefc107SDavid Howells pipe->head = iter_head; 5798cefc107SDavid Howells 5808cefc107SDavid Howells if (left == 0) 581241699cdSAl Viro return size; 582241699cdSAl Viro } 583241699cdSAl Viro return size - left; 584241699cdSAl Viro } 585241699cdSAl Viro 586241699cdSAl Viro static size_t copy_pipe_to_iter(const void *addr, size_t bytes, 587241699cdSAl Viro struct iov_iter *i) 588241699cdSAl Viro { 589241699cdSAl Viro struct pipe_inode_info *pipe = i->pipe; 5908cefc107SDavid Howells unsigned int p_mask = pipe->ring_size - 1; 5918cefc107SDavid Howells unsigned int i_head; 592241699cdSAl Viro size_t n, off; 593241699cdSAl Viro 594241699cdSAl Viro if (!sanity(i)) 595241699cdSAl Viro return 0; 596241699cdSAl Viro 5978cefc107SDavid Howells bytes = n = push_pipe(i, bytes, &i_head, &off); 598241699cdSAl Viro if (unlikely(!n)) 599241699cdSAl Viro return 0; 6008cefc107SDavid Howells do { 601241699cdSAl Viro size_t chunk = min_t(size_t, n, PAGE_SIZE - off); 6028cefc107SDavid Howells memcpy_to_page(pipe->bufs[i_head & p_mask].page, off, addr, chunk); 6038cefc107SDavid Howells i->head = i_head; 604241699cdSAl Viro i->iov_offset = off + chunk; 605241699cdSAl Viro n -= chunk; 606241699cdSAl Viro addr += chunk; 6078cefc107SDavid Howells off = 0; 6088cefc107SDavid Howells i_head++; 6098cefc107SDavid Howells } while (n); 610241699cdSAl Viro i->count -= bytes; 611241699cdSAl Viro return bytes; 612241699cdSAl Viro } 613241699cdSAl Viro 614f9152895SAl Viro static __wsum csum_and_memcpy(void *to, const void *from, size_t len, 615f9152895SAl Viro __wsum sum, size_t off) 616f9152895SAl Viro { 617cc44c17bSAl Viro __wsum next = csum_partial_copy_nocheck(from, to, len); 618f9152895SAl Viro return csum_block_add(sum, next, off); 619f9152895SAl Viro } 620f9152895SAl Viro 62178e1f386SAl Viro static size_t csum_and_copy_to_pipe_iter(const void *addr, size_t bytes, 62252cbd23aSWillem de Bruijn struct csum_state *csstate, 62352cbd23aSWillem de Bruijn struct iov_iter *i) 62478e1f386SAl Viro { 62578e1f386SAl Viro struct pipe_inode_info *pipe = i->pipe; 6268cefc107SDavid Howells unsigned int p_mask = pipe->ring_size - 1; 62752cbd23aSWillem de Bruijn __wsum sum = csstate->csum; 62852cbd23aSWillem de Bruijn size_t off = csstate->off; 6298cefc107SDavid Howells unsigned int i_head; 63078e1f386SAl Viro size_t n, r; 63178e1f386SAl Viro 63278e1f386SAl Viro if (!sanity(i)) 63378e1f386SAl Viro return 0; 63478e1f386SAl Viro 6358cefc107SDavid Howells bytes = n = push_pipe(i, bytes, &i_head, &r); 63678e1f386SAl Viro if (unlikely(!n)) 63778e1f386SAl Viro return 0; 6388cefc107SDavid Howells do { 63978e1f386SAl Viro size_t chunk = min_t(size_t, n, PAGE_SIZE - r); 6408cefc107SDavid Howells char *p = kmap_atomic(pipe->bufs[i_head & p_mask].page); 641f9152895SAl Viro sum = csum_and_memcpy(p + r, addr, chunk, sum, off); 64278e1f386SAl Viro kunmap_atomic(p); 6438cefc107SDavid Howells i->head = i_head; 64478e1f386SAl Viro i->iov_offset = r + chunk; 64578e1f386SAl Viro n -= chunk; 64678e1f386SAl Viro off += chunk; 64778e1f386SAl Viro addr += chunk; 6488cefc107SDavid Howells r = 0; 6498cefc107SDavid Howells i_head++; 6508cefc107SDavid Howells } while (n); 65178e1f386SAl Viro i->count -= bytes; 65252cbd23aSWillem de Bruijn csstate->csum = sum; 65352cbd23aSWillem de Bruijn csstate->off = off; 65478e1f386SAl Viro return bytes; 65578e1f386SAl Viro } 65678e1f386SAl Viro 657aa28de27SAl Viro size_t _copy_to_iter(const void *addr, size_t bytes, struct iov_iter *i) 658d879cb83SAl Viro { 65936f7a8a4SAl Viro const char *from = addr; 66000e23707SDavid Howells if (unlikely(iov_iter_is_pipe(i))) 661241699cdSAl Viro return copy_pipe_to_iter(addr, bytes, i); 66209fc68dcSAl Viro if (iter_is_iovec(i)) 66309fc68dcSAl Viro might_fault(); 664d879cb83SAl Viro iterate_and_advance(i, bytes, v, 66509fc68dcSAl Viro copyout(v.iov_base, (from += v.iov_len) - v.iov_len, v.iov_len), 666d879cb83SAl Viro memcpy_to_page(v.bv_page, v.bv_offset, 667d879cb83SAl Viro (from += v.bv_len) - v.bv_len, v.bv_len), 6687ff50620SDavid Howells memcpy(v.iov_base, (from += v.iov_len) - v.iov_len, v.iov_len), 6697ff50620SDavid Howells memcpy_to_page(v.bv_page, v.bv_offset, 6707ff50620SDavid Howells (from += v.bv_len) - v.bv_len, v.bv_len) 671d879cb83SAl Viro ) 672d879cb83SAl Viro 673d879cb83SAl Viro return bytes; 674d879cb83SAl Viro } 675aa28de27SAl Viro EXPORT_SYMBOL(_copy_to_iter); 676d879cb83SAl Viro 677ec6347bbSDan Williams #ifdef CONFIG_ARCH_HAS_COPY_MC 678ec6347bbSDan Williams static int copyout_mc(void __user *to, const void *from, size_t n) 6798780356eSDan Williams { 68096d4f267SLinus Torvalds if (access_ok(to, n)) { 681d0ef4c36SMarco Elver instrument_copy_to_user(to, from, n); 682ec6347bbSDan Williams n = copy_mc_to_user((__force void *) to, from, n); 6838780356eSDan Williams } 6848780356eSDan Williams return n; 6858780356eSDan Williams } 6868780356eSDan Williams 687ec6347bbSDan Williams static unsigned long copy_mc_to_page(struct page *page, size_t offset, 6888780356eSDan Williams const char *from, size_t len) 6898780356eSDan Williams { 6908780356eSDan Williams unsigned long ret; 6918780356eSDan Williams char *to; 6928780356eSDan Williams 6938780356eSDan Williams to = kmap_atomic(page); 694ec6347bbSDan Williams ret = copy_mc_to_kernel(to + offset, from, len); 6958780356eSDan Williams kunmap_atomic(to); 6968780356eSDan Williams 6978780356eSDan Williams return ret; 6988780356eSDan Williams } 6998780356eSDan Williams 700ec6347bbSDan Williams static size_t copy_mc_pipe_to_iter(const void *addr, size_t bytes, 701ca146f6fSDan Williams struct iov_iter *i) 702ca146f6fSDan Williams { 703ca146f6fSDan Williams struct pipe_inode_info *pipe = i->pipe; 7048cefc107SDavid Howells unsigned int p_mask = pipe->ring_size - 1; 7058cefc107SDavid Howells unsigned int i_head; 706ca146f6fSDan Williams size_t n, off, xfer = 0; 707ca146f6fSDan Williams 708ca146f6fSDan Williams if (!sanity(i)) 709ca146f6fSDan Williams return 0; 710ca146f6fSDan Williams 7118cefc107SDavid Howells bytes = n = push_pipe(i, bytes, &i_head, &off); 712ca146f6fSDan Williams if (unlikely(!n)) 713ca146f6fSDan Williams return 0; 7148cefc107SDavid Howells do { 715ca146f6fSDan Williams size_t chunk = min_t(size_t, n, PAGE_SIZE - off); 716ca146f6fSDan Williams unsigned long rem; 717ca146f6fSDan Williams 718ec6347bbSDan Williams rem = copy_mc_to_page(pipe->bufs[i_head & p_mask].page, 7198cefc107SDavid Howells off, addr, chunk); 7208cefc107SDavid Howells i->head = i_head; 721ca146f6fSDan Williams i->iov_offset = off + chunk - rem; 722ca146f6fSDan Williams xfer += chunk - rem; 723ca146f6fSDan Williams if (rem) 724ca146f6fSDan Williams break; 725ca146f6fSDan Williams n -= chunk; 726ca146f6fSDan Williams addr += chunk; 7278cefc107SDavid Howells off = 0; 7288cefc107SDavid Howells i_head++; 7298cefc107SDavid Howells } while (n); 730ca146f6fSDan Williams i->count -= xfer; 731ca146f6fSDan Williams return xfer; 732ca146f6fSDan Williams } 733ca146f6fSDan Williams 734bf3eeb9bSDan Williams /** 735ec6347bbSDan Williams * _copy_mc_to_iter - copy to iter with source memory error exception handling 736bf3eeb9bSDan Williams * @addr: source kernel address 737bf3eeb9bSDan Williams * @bytes: total transfer length 738bf3eeb9bSDan Williams * @iter: destination iterator 739bf3eeb9bSDan Williams * 740ec6347bbSDan Williams * The pmem driver deploys this for the dax operation 741ec6347bbSDan Williams * (dax_copy_to_iter()) for dax reads (bypass page-cache and the 742ec6347bbSDan Williams * block-layer). Upon #MC read(2) aborts and returns EIO or the bytes 743ec6347bbSDan Williams * successfully copied. 744bf3eeb9bSDan Williams * 745ec6347bbSDan Williams * The main differences between this and typical _copy_to_iter(). 746bf3eeb9bSDan Williams * 747bf3eeb9bSDan Williams * * Typical tail/residue handling after a fault retries the copy 748bf3eeb9bSDan Williams * byte-by-byte until the fault happens again. Re-triggering machine 749bf3eeb9bSDan Williams * checks is potentially fatal so the implementation uses source 750bf3eeb9bSDan Williams * alignment and poison alignment assumptions to avoid re-triggering 751bf3eeb9bSDan Williams * hardware exceptions. 752bf3eeb9bSDan Williams * 753bf3eeb9bSDan Williams * * ITER_KVEC, ITER_PIPE, and ITER_BVEC can return short copies. 754bf3eeb9bSDan Williams * Compare to copy_to_iter() where only ITER_IOVEC attempts might return 755bf3eeb9bSDan Williams * a short copy. 756bf3eeb9bSDan Williams */ 757ec6347bbSDan Williams size_t _copy_mc_to_iter(const void *addr, size_t bytes, struct iov_iter *i) 7588780356eSDan Williams { 7598780356eSDan Williams const char *from = addr; 7608780356eSDan Williams unsigned long rem, curr_addr, s_addr = (unsigned long) addr; 7618780356eSDan Williams 76200e23707SDavid Howells if (unlikely(iov_iter_is_pipe(i))) 763ec6347bbSDan Williams return copy_mc_pipe_to_iter(addr, bytes, i); 7648780356eSDan Williams if (iter_is_iovec(i)) 7658780356eSDan Williams might_fault(); 7668780356eSDan Williams iterate_and_advance(i, bytes, v, 767ec6347bbSDan Williams copyout_mc(v.iov_base, (from += v.iov_len) - v.iov_len, 768ec6347bbSDan Williams v.iov_len), 7698780356eSDan Williams ({ 770ec6347bbSDan Williams rem = copy_mc_to_page(v.bv_page, v.bv_offset, 7718780356eSDan Williams (from += v.bv_len) - v.bv_len, v.bv_len); 7728780356eSDan Williams if (rem) { 7738780356eSDan Williams curr_addr = (unsigned long) from; 7748780356eSDan Williams bytes = curr_addr - s_addr - rem; 7758780356eSDan Williams return bytes; 7768780356eSDan Williams } 7778780356eSDan Williams }), 7788780356eSDan Williams ({ 779ec6347bbSDan Williams rem = copy_mc_to_kernel(v.iov_base, (from += v.iov_len) 780ec6347bbSDan Williams - v.iov_len, v.iov_len); 7818780356eSDan Williams if (rem) { 7828780356eSDan Williams curr_addr = (unsigned long) from; 7838780356eSDan Williams bytes = curr_addr - s_addr - rem; 7848780356eSDan Williams return bytes; 7858780356eSDan Williams } 7867ff50620SDavid Howells }), 7877ff50620SDavid Howells ({ 7887ff50620SDavid Howells rem = copy_mc_to_page(v.bv_page, v.bv_offset, 7897ff50620SDavid Howells (from += v.bv_len) - v.bv_len, v.bv_len); 7907ff50620SDavid Howells if (rem) { 7917ff50620SDavid Howells curr_addr = (unsigned long) from; 7927ff50620SDavid Howells bytes = curr_addr - s_addr - rem; 7937ff50620SDavid Howells rcu_read_unlock(); 794*3d14ec1fSDavid Howells i->iov_offset += bytes; 795*3d14ec1fSDavid Howells i->count -= bytes; 7967ff50620SDavid Howells return bytes; 7977ff50620SDavid Howells } 7988780356eSDan Williams }) 7998780356eSDan Williams ) 8008780356eSDan Williams 8018780356eSDan Williams return bytes; 8028780356eSDan Williams } 803ec6347bbSDan Williams EXPORT_SYMBOL_GPL(_copy_mc_to_iter); 804ec6347bbSDan Williams #endif /* CONFIG_ARCH_HAS_COPY_MC */ 8058780356eSDan Williams 806aa28de27SAl Viro size_t _copy_from_iter(void *addr, size_t bytes, struct iov_iter *i) 807d879cb83SAl Viro { 808d879cb83SAl Viro char *to = addr; 80900e23707SDavid Howells if (unlikely(iov_iter_is_pipe(i))) { 810241699cdSAl Viro WARN_ON(1); 811241699cdSAl Viro return 0; 812241699cdSAl Viro } 81309fc68dcSAl Viro if (iter_is_iovec(i)) 81409fc68dcSAl Viro might_fault(); 815d879cb83SAl Viro iterate_and_advance(i, bytes, v, 81609fc68dcSAl Viro copyin((to += v.iov_len) - v.iov_len, v.iov_base, v.iov_len), 817d879cb83SAl Viro memcpy_from_page((to += v.bv_len) - v.bv_len, v.bv_page, 818d879cb83SAl Viro v.bv_offset, v.bv_len), 8197ff50620SDavid Howells memcpy((to += v.iov_len) - v.iov_len, v.iov_base, v.iov_len), 8207ff50620SDavid Howells memcpy_from_page((to += v.bv_len) - v.bv_len, v.bv_page, 8217ff50620SDavid Howells v.bv_offset, v.bv_len) 822d879cb83SAl Viro ) 823d879cb83SAl Viro 824d879cb83SAl Viro return bytes; 825d879cb83SAl Viro } 826aa28de27SAl Viro EXPORT_SYMBOL(_copy_from_iter); 827d879cb83SAl Viro 828aa28de27SAl Viro bool _copy_from_iter_full(void *addr, size_t bytes, struct iov_iter *i) 829cbbd26b8SAl Viro { 830cbbd26b8SAl Viro char *to = addr; 83100e23707SDavid Howells if (unlikely(iov_iter_is_pipe(i))) { 832cbbd26b8SAl Viro WARN_ON(1); 833cbbd26b8SAl Viro return false; 834cbbd26b8SAl Viro } 83533844e66SAl Viro if (unlikely(i->count < bytes)) 836cbbd26b8SAl Viro return false; 837cbbd26b8SAl Viro 83809fc68dcSAl Viro if (iter_is_iovec(i)) 83909fc68dcSAl Viro might_fault(); 840cbbd26b8SAl Viro iterate_all_kinds(i, bytes, v, ({ 84109fc68dcSAl Viro if (copyin((to += v.iov_len) - v.iov_len, 842cbbd26b8SAl Viro v.iov_base, v.iov_len)) 843cbbd26b8SAl Viro return false; 844cbbd26b8SAl Viro 0;}), 845cbbd26b8SAl Viro memcpy_from_page((to += v.bv_len) - v.bv_len, v.bv_page, 846cbbd26b8SAl Viro v.bv_offset, v.bv_len), 8477ff50620SDavid Howells memcpy((to += v.iov_len) - v.iov_len, v.iov_base, v.iov_len), 8487ff50620SDavid Howells memcpy_from_page((to += v.bv_len) - v.bv_len, v.bv_page, 8497ff50620SDavid Howells v.bv_offset, v.bv_len) 850cbbd26b8SAl Viro ) 851cbbd26b8SAl Viro 852cbbd26b8SAl Viro iov_iter_advance(i, bytes); 853cbbd26b8SAl Viro return true; 854cbbd26b8SAl Viro } 855aa28de27SAl Viro EXPORT_SYMBOL(_copy_from_iter_full); 856cbbd26b8SAl Viro 857aa28de27SAl Viro size_t _copy_from_iter_nocache(void *addr, size_t bytes, struct iov_iter *i) 858d879cb83SAl Viro { 859d879cb83SAl Viro char *to = addr; 86000e23707SDavid Howells if (unlikely(iov_iter_is_pipe(i))) { 861241699cdSAl Viro WARN_ON(1); 862241699cdSAl Viro return 0; 863241699cdSAl Viro } 864d879cb83SAl Viro iterate_and_advance(i, bytes, v, 8653f763453SAl Viro __copy_from_user_inatomic_nocache((to += v.iov_len) - v.iov_len, 866d879cb83SAl Viro v.iov_base, v.iov_len), 867d879cb83SAl Viro memcpy_from_page((to += v.bv_len) - v.bv_len, v.bv_page, 868d879cb83SAl Viro v.bv_offset, v.bv_len), 8697ff50620SDavid Howells memcpy((to += v.iov_len) - v.iov_len, v.iov_base, v.iov_len), 8707ff50620SDavid Howells memcpy_from_page((to += v.bv_len) - v.bv_len, v.bv_page, 8717ff50620SDavid Howells v.bv_offset, v.bv_len) 872d879cb83SAl Viro ) 873d879cb83SAl Viro 874d879cb83SAl Viro return bytes; 875d879cb83SAl Viro } 876aa28de27SAl Viro EXPORT_SYMBOL(_copy_from_iter_nocache); 877d879cb83SAl Viro 8780aed55afSDan Williams #ifdef CONFIG_ARCH_HAS_UACCESS_FLUSHCACHE 879abd08d7dSDan Williams /** 880abd08d7dSDan Williams * _copy_from_iter_flushcache - write destination through cpu cache 881abd08d7dSDan Williams * @addr: destination kernel address 882abd08d7dSDan Williams * @bytes: total transfer length 883abd08d7dSDan Williams * @iter: source iterator 884abd08d7dSDan Williams * 885abd08d7dSDan Williams * The pmem driver arranges for filesystem-dax to use this facility via 886abd08d7dSDan Williams * dax_copy_from_iter() for ensuring that writes to persistent memory 887abd08d7dSDan Williams * are flushed through the CPU cache. It is differentiated from 888abd08d7dSDan Williams * _copy_from_iter_nocache() in that guarantees all data is flushed for 889abd08d7dSDan Williams * all iterator types. The _copy_from_iter_nocache() only attempts to 890abd08d7dSDan Williams * bypass the cache for the ITER_IOVEC case, and on some archs may use 891abd08d7dSDan Williams * instructions that strand dirty-data in the cache. 892abd08d7dSDan Williams */ 8936a37e940SLinus Torvalds size_t _copy_from_iter_flushcache(void *addr, size_t bytes, struct iov_iter *i) 8940aed55afSDan Williams { 8950aed55afSDan Williams char *to = addr; 89600e23707SDavid Howells if (unlikely(iov_iter_is_pipe(i))) { 8970aed55afSDan Williams WARN_ON(1); 8980aed55afSDan Williams return 0; 8990aed55afSDan Williams } 9000aed55afSDan Williams iterate_and_advance(i, bytes, v, 9010aed55afSDan Williams __copy_from_user_flushcache((to += v.iov_len) - v.iov_len, 9020aed55afSDan Williams v.iov_base, v.iov_len), 9030aed55afSDan Williams memcpy_page_flushcache((to += v.bv_len) - v.bv_len, v.bv_page, 9040aed55afSDan Williams v.bv_offset, v.bv_len), 9050aed55afSDan Williams memcpy_flushcache((to += v.iov_len) - v.iov_len, v.iov_base, 9067ff50620SDavid Howells v.iov_len), 9077ff50620SDavid Howells memcpy_page_flushcache((to += v.bv_len) - v.bv_len, v.bv_page, 9087ff50620SDavid Howells v.bv_offset, v.bv_len) 9090aed55afSDan Williams ) 9100aed55afSDan Williams 9110aed55afSDan Williams return bytes; 9120aed55afSDan Williams } 9136a37e940SLinus Torvalds EXPORT_SYMBOL_GPL(_copy_from_iter_flushcache); 9140aed55afSDan Williams #endif 9150aed55afSDan Williams 916aa28de27SAl Viro bool _copy_from_iter_full_nocache(void *addr, size_t bytes, struct iov_iter *i) 917cbbd26b8SAl Viro { 918cbbd26b8SAl Viro char *to = addr; 91900e23707SDavid Howells if (unlikely(iov_iter_is_pipe(i))) { 920cbbd26b8SAl Viro WARN_ON(1); 921cbbd26b8SAl Viro return false; 922cbbd26b8SAl Viro } 92333844e66SAl Viro if (unlikely(i->count < bytes)) 924cbbd26b8SAl Viro return false; 925cbbd26b8SAl Viro iterate_all_kinds(i, bytes, v, ({ 9263f763453SAl Viro if (__copy_from_user_inatomic_nocache((to += v.iov_len) - v.iov_len, 927cbbd26b8SAl Viro v.iov_base, v.iov_len)) 928cbbd26b8SAl Viro return false; 929cbbd26b8SAl Viro 0;}), 930cbbd26b8SAl Viro memcpy_from_page((to += v.bv_len) - v.bv_len, v.bv_page, 931cbbd26b8SAl Viro v.bv_offset, v.bv_len), 9327ff50620SDavid Howells memcpy((to += v.iov_len) - v.iov_len, v.iov_base, v.iov_len), 9337ff50620SDavid Howells memcpy_from_page((to += v.bv_len) - v.bv_len, v.bv_page, 9347ff50620SDavid Howells v.bv_offset, v.bv_len) 935cbbd26b8SAl Viro ) 936cbbd26b8SAl Viro 937cbbd26b8SAl Viro iov_iter_advance(i, bytes); 938cbbd26b8SAl Viro return true; 939cbbd26b8SAl Viro } 940aa28de27SAl Viro EXPORT_SYMBOL(_copy_from_iter_full_nocache); 941cbbd26b8SAl Viro 94272e809edSAl Viro static inline bool page_copy_sane(struct page *page, size_t offset, size_t n) 94372e809edSAl Viro { 9446daef95bSEric Dumazet struct page *head; 9456daef95bSEric Dumazet size_t v = n + offset; 9466daef95bSEric Dumazet 9476daef95bSEric Dumazet /* 9486daef95bSEric Dumazet * The general case needs to access the page order in order 9496daef95bSEric Dumazet * to compute the page size. 9506daef95bSEric Dumazet * However, we mostly deal with order-0 pages and thus can 9516daef95bSEric Dumazet * avoid a possible cache line miss for requests that fit all 9526daef95bSEric Dumazet * page orders. 9536daef95bSEric Dumazet */ 9546daef95bSEric Dumazet if (n <= v && v <= PAGE_SIZE) 9556daef95bSEric Dumazet return true; 9566daef95bSEric Dumazet 9576daef95bSEric Dumazet head = compound_head(page); 9586daef95bSEric Dumazet v += (page - head) << PAGE_SHIFT; 959a90bcb86SPetar Penkov 960a50b854eSMatthew Wilcox (Oracle) if (likely(n <= v && v <= (page_size(head)))) 96172e809edSAl Viro return true; 96272e809edSAl Viro WARN_ON(1); 96372e809edSAl Viro return false; 96472e809edSAl Viro } 965d879cb83SAl Viro 966d879cb83SAl Viro size_t copy_page_to_iter(struct page *page, size_t offset, size_t bytes, 967d879cb83SAl Viro struct iov_iter *i) 968d879cb83SAl Viro { 96972e809edSAl Viro if (unlikely(!page_copy_sane(page, offset, bytes))) 97072e809edSAl Viro return 0; 9717ff50620SDavid Howells if (i->type & (ITER_BVEC | ITER_KVEC | ITER_XARRAY)) { 972d879cb83SAl Viro void *kaddr = kmap_atomic(page); 973d879cb83SAl Viro size_t wanted = copy_to_iter(kaddr + offset, bytes, i); 974d879cb83SAl Viro kunmap_atomic(kaddr); 975d879cb83SAl Viro return wanted; 9769ea9ce04SDavid Howells } else if (unlikely(iov_iter_is_discard(i))) 9779ea9ce04SDavid Howells return bytes; 9789ea9ce04SDavid Howells else if (likely(!iov_iter_is_pipe(i))) 979d879cb83SAl Viro return copy_page_to_iter_iovec(page, offset, bytes, i); 980241699cdSAl Viro else 981241699cdSAl Viro return copy_page_to_iter_pipe(page, offset, bytes, i); 982d879cb83SAl Viro } 983d879cb83SAl Viro EXPORT_SYMBOL(copy_page_to_iter); 984d879cb83SAl Viro 985d879cb83SAl Viro size_t copy_page_from_iter(struct page *page, size_t offset, size_t bytes, 986d879cb83SAl Viro struct iov_iter *i) 987d879cb83SAl Viro { 98872e809edSAl Viro if (unlikely(!page_copy_sane(page, offset, bytes))) 98972e809edSAl Viro return 0; 9909ea9ce04SDavid Howells if (unlikely(iov_iter_is_pipe(i) || iov_iter_is_discard(i))) { 991241699cdSAl Viro WARN_ON(1); 992241699cdSAl Viro return 0; 993241699cdSAl Viro } 9947ff50620SDavid Howells if (i->type & (ITER_BVEC | ITER_KVEC | ITER_XARRAY)) { 995d879cb83SAl Viro void *kaddr = kmap_atomic(page); 996aa28de27SAl Viro size_t wanted = _copy_from_iter(kaddr + offset, bytes, i); 997d879cb83SAl Viro kunmap_atomic(kaddr); 998d879cb83SAl Viro return wanted; 999d879cb83SAl Viro } else 1000d879cb83SAl Viro return copy_page_from_iter_iovec(page, offset, bytes, i); 1001d879cb83SAl Viro } 1002d879cb83SAl Viro EXPORT_SYMBOL(copy_page_from_iter); 1003d879cb83SAl Viro 1004241699cdSAl Viro static size_t pipe_zero(size_t bytes, struct iov_iter *i) 1005241699cdSAl Viro { 1006241699cdSAl Viro struct pipe_inode_info *pipe = i->pipe; 10078cefc107SDavid Howells unsigned int p_mask = pipe->ring_size - 1; 10088cefc107SDavid Howells unsigned int i_head; 1009241699cdSAl Viro size_t n, off; 1010241699cdSAl Viro 1011241699cdSAl Viro if (!sanity(i)) 1012241699cdSAl Viro return 0; 1013241699cdSAl Viro 10148cefc107SDavid Howells bytes = n = push_pipe(i, bytes, &i_head, &off); 1015241699cdSAl Viro if (unlikely(!n)) 1016241699cdSAl Viro return 0; 1017241699cdSAl Viro 10188cefc107SDavid Howells do { 1019241699cdSAl Viro size_t chunk = min_t(size_t, n, PAGE_SIZE - off); 10208cefc107SDavid Howells memzero_page(pipe->bufs[i_head & p_mask].page, off, chunk); 10218cefc107SDavid Howells i->head = i_head; 1022241699cdSAl Viro i->iov_offset = off + chunk; 1023241699cdSAl Viro n -= chunk; 10248cefc107SDavid Howells off = 0; 10258cefc107SDavid Howells i_head++; 10268cefc107SDavid Howells } while (n); 1027241699cdSAl Viro i->count -= bytes; 1028241699cdSAl Viro return bytes; 1029241699cdSAl Viro } 1030241699cdSAl Viro 1031d879cb83SAl Viro size_t iov_iter_zero(size_t bytes, struct iov_iter *i) 1032d879cb83SAl Viro { 103300e23707SDavid Howells if (unlikely(iov_iter_is_pipe(i))) 1034241699cdSAl Viro return pipe_zero(bytes, i); 1035d879cb83SAl Viro iterate_and_advance(i, bytes, v, 103609fc68dcSAl Viro clear_user(v.iov_base, v.iov_len), 1037d879cb83SAl Viro memzero_page(v.bv_page, v.bv_offset, v.bv_len), 10387ff50620SDavid Howells memset(v.iov_base, 0, v.iov_len), 10397ff50620SDavid Howells memzero_page(v.bv_page, v.bv_offset, v.bv_len) 1040d879cb83SAl Viro ) 1041d879cb83SAl Viro 1042d879cb83SAl Viro return bytes; 1043d879cb83SAl Viro } 1044d879cb83SAl Viro EXPORT_SYMBOL(iov_iter_zero); 1045d879cb83SAl Viro 1046d879cb83SAl Viro size_t iov_iter_copy_from_user_atomic(struct page *page, 1047d879cb83SAl Viro struct iov_iter *i, unsigned long offset, size_t bytes) 1048d879cb83SAl Viro { 1049d879cb83SAl Viro char *kaddr = kmap_atomic(page), *p = kaddr + offset; 105072e809edSAl Viro if (unlikely(!page_copy_sane(page, offset, bytes))) { 105172e809edSAl Viro kunmap_atomic(kaddr); 105272e809edSAl Viro return 0; 105372e809edSAl Viro } 10549ea9ce04SDavid Howells if (unlikely(iov_iter_is_pipe(i) || iov_iter_is_discard(i))) { 1055241699cdSAl Viro kunmap_atomic(kaddr); 1056241699cdSAl Viro WARN_ON(1); 1057241699cdSAl Viro return 0; 1058241699cdSAl Viro } 1059d879cb83SAl Viro iterate_all_kinds(i, bytes, v, 106009fc68dcSAl Viro copyin((p += v.iov_len) - v.iov_len, v.iov_base, v.iov_len), 1061d879cb83SAl Viro memcpy_from_page((p += v.bv_len) - v.bv_len, v.bv_page, 1062d879cb83SAl Viro v.bv_offset, v.bv_len), 10637ff50620SDavid Howells memcpy((p += v.iov_len) - v.iov_len, v.iov_base, v.iov_len), 10647ff50620SDavid Howells memcpy_from_page((p += v.bv_len) - v.bv_len, v.bv_page, 10657ff50620SDavid Howells v.bv_offset, v.bv_len) 1066d879cb83SAl Viro ) 1067d879cb83SAl Viro kunmap_atomic(kaddr); 1068d879cb83SAl Viro return bytes; 1069d879cb83SAl Viro } 1070d879cb83SAl Viro EXPORT_SYMBOL(iov_iter_copy_from_user_atomic); 1071d879cb83SAl Viro 1072b9dc6f65SAl Viro static inline void pipe_truncate(struct iov_iter *i) 1073241699cdSAl Viro { 1074241699cdSAl Viro struct pipe_inode_info *pipe = i->pipe; 10758cefc107SDavid Howells unsigned int p_tail = pipe->tail; 10768cefc107SDavid Howells unsigned int p_head = pipe->head; 10778cefc107SDavid Howells unsigned int p_mask = pipe->ring_size - 1; 10788cefc107SDavid Howells 10798cefc107SDavid Howells if (!pipe_empty(p_head, p_tail)) { 10808cefc107SDavid Howells struct pipe_buffer *buf; 10818cefc107SDavid Howells unsigned int i_head = i->head; 1082b9dc6f65SAl Viro size_t off = i->iov_offset; 10838cefc107SDavid Howells 1084b9dc6f65SAl Viro if (off) { 10858cefc107SDavid Howells buf = &pipe->bufs[i_head & p_mask]; 10868cefc107SDavid Howells buf->len = off - buf->offset; 10878cefc107SDavid Howells i_head++; 1088b9dc6f65SAl Viro } 10898cefc107SDavid Howells while (p_head != i_head) { 10908cefc107SDavid Howells p_head--; 10918cefc107SDavid Howells pipe_buf_release(pipe, &pipe->bufs[p_head & p_mask]); 1092241699cdSAl Viro } 10938cefc107SDavid Howells 10948cefc107SDavid Howells pipe->head = p_head; 1095241699cdSAl Viro } 1096b9dc6f65SAl Viro } 1097b9dc6f65SAl Viro 1098b9dc6f65SAl Viro static void pipe_advance(struct iov_iter *i, size_t size) 1099b9dc6f65SAl Viro { 1100b9dc6f65SAl Viro struct pipe_inode_info *pipe = i->pipe; 1101b9dc6f65SAl Viro if (unlikely(i->count < size)) 1102b9dc6f65SAl Viro size = i->count; 1103b9dc6f65SAl Viro if (size) { 1104b9dc6f65SAl Viro struct pipe_buffer *buf; 11058cefc107SDavid Howells unsigned int p_mask = pipe->ring_size - 1; 11068cefc107SDavid Howells unsigned int i_head = i->head; 1107b9dc6f65SAl Viro size_t off = i->iov_offset, left = size; 11088cefc107SDavid Howells 1109b9dc6f65SAl Viro if (off) /* make it relative to the beginning of buffer */ 11108cefc107SDavid Howells left += off - pipe->bufs[i_head & p_mask].offset; 1111b9dc6f65SAl Viro while (1) { 11128cefc107SDavid Howells buf = &pipe->bufs[i_head & p_mask]; 1113b9dc6f65SAl Viro if (left <= buf->len) 1114b9dc6f65SAl Viro break; 1115b9dc6f65SAl Viro left -= buf->len; 11168cefc107SDavid Howells i_head++; 1117b9dc6f65SAl Viro } 11188cefc107SDavid Howells i->head = i_head; 1119b9dc6f65SAl Viro i->iov_offset = buf->offset + left; 1120b9dc6f65SAl Viro } 1121b9dc6f65SAl Viro i->count -= size; 1122b9dc6f65SAl Viro /* ... and discard everything past that point */ 1123b9dc6f65SAl Viro pipe_truncate(i); 1124241699cdSAl Viro } 1125241699cdSAl Viro 112654c8195bSPavel Begunkov static void iov_iter_bvec_advance(struct iov_iter *i, size_t size) 112754c8195bSPavel Begunkov { 112854c8195bSPavel Begunkov struct bvec_iter bi; 112954c8195bSPavel Begunkov 113054c8195bSPavel Begunkov bi.bi_size = i->count; 113154c8195bSPavel Begunkov bi.bi_bvec_done = i->iov_offset; 113254c8195bSPavel Begunkov bi.bi_idx = 0; 113354c8195bSPavel Begunkov bvec_iter_advance(i->bvec, &bi, size); 113454c8195bSPavel Begunkov 113554c8195bSPavel Begunkov i->bvec += bi.bi_idx; 113654c8195bSPavel Begunkov i->nr_segs -= bi.bi_idx; 113754c8195bSPavel Begunkov i->count = bi.bi_size; 113854c8195bSPavel Begunkov i->iov_offset = bi.bi_bvec_done; 113954c8195bSPavel Begunkov } 114054c8195bSPavel Begunkov 1141d879cb83SAl Viro void iov_iter_advance(struct iov_iter *i, size_t size) 1142d879cb83SAl Viro { 114300e23707SDavid Howells if (unlikely(iov_iter_is_pipe(i))) { 1144241699cdSAl Viro pipe_advance(i, size); 1145241699cdSAl Viro return; 1146241699cdSAl Viro } 11479ea9ce04SDavid Howells if (unlikely(iov_iter_is_discard(i))) { 11489ea9ce04SDavid Howells i->count -= size; 11499ea9ce04SDavid Howells return; 11509ea9ce04SDavid Howells } 11517ff50620SDavid Howells if (unlikely(iov_iter_is_xarray(i))) { 1152*3d14ec1fSDavid Howells size = min(size, i->count); 11537ff50620SDavid Howells i->iov_offset += size; 11547ff50620SDavid Howells i->count -= size; 11557ff50620SDavid Howells return; 11567ff50620SDavid Howells } 115754c8195bSPavel Begunkov if (iov_iter_is_bvec(i)) { 115854c8195bSPavel Begunkov iov_iter_bvec_advance(i, size); 115954c8195bSPavel Begunkov return; 116054c8195bSPavel Begunkov } 11617ff50620SDavid Howells iterate_and_advance(i, size, v, 0, 0, 0, 0) 1162d879cb83SAl Viro } 1163d879cb83SAl Viro EXPORT_SYMBOL(iov_iter_advance); 1164d879cb83SAl Viro 116527c0e374SAl Viro void iov_iter_revert(struct iov_iter *i, size_t unroll) 116627c0e374SAl Viro { 116727c0e374SAl Viro if (!unroll) 116827c0e374SAl Viro return; 11695b47d59aSAl Viro if (WARN_ON(unroll > MAX_RW_COUNT)) 11705b47d59aSAl Viro return; 117127c0e374SAl Viro i->count += unroll; 117200e23707SDavid Howells if (unlikely(iov_iter_is_pipe(i))) { 117327c0e374SAl Viro struct pipe_inode_info *pipe = i->pipe; 11748cefc107SDavid Howells unsigned int p_mask = pipe->ring_size - 1; 11758cefc107SDavid Howells unsigned int i_head = i->head; 117627c0e374SAl Viro size_t off = i->iov_offset; 117727c0e374SAl Viro while (1) { 11788cefc107SDavid Howells struct pipe_buffer *b = &pipe->bufs[i_head & p_mask]; 11798cefc107SDavid Howells size_t n = off - b->offset; 118027c0e374SAl Viro if (unroll < n) { 11814fa55cefSAl Viro off -= unroll; 118227c0e374SAl Viro break; 118327c0e374SAl Viro } 118427c0e374SAl Viro unroll -= n; 11858cefc107SDavid Howells if (!unroll && i_head == i->start_head) { 118627c0e374SAl Viro off = 0; 118727c0e374SAl Viro break; 118827c0e374SAl Viro } 11898cefc107SDavid Howells i_head--; 11908cefc107SDavid Howells b = &pipe->bufs[i_head & p_mask]; 11918cefc107SDavid Howells off = b->offset + b->len; 119227c0e374SAl Viro } 119327c0e374SAl Viro i->iov_offset = off; 11948cefc107SDavid Howells i->head = i_head; 119527c0e374SAl Viro pipe_truncate(i); 119627c0e374SAl Viro return; 119727c0e374SAl Viro } 11989ea9ce04SDavid Howells if (unlikely(iov_iter_is_discard(i))) 11999ea9ce04SDavid Howells return; 120027c0e374SAl Viro if (unroll <= i->iov_offset) { 120127c0e374SAl Viro i->iov_offset -= unroll; 120227c0e374SAl Viro return; 120327c0e374SAl Viro } 120427c0e374SAl Viro unroll -= i->iov_offset; 12057ff50620SDavid Howells if (iov_iter_is_xarray(i)) { 12067ff50620SDavid Howells BUG(); /* We should never go beyond the start of the specified 12077ff50620SDavid Howells * range since we might then be straying into pages that 12087ff50620SDavid Howells * aren't pinned. 12097ff50620SDavid Howells */ 12107ff50620SDavid Howells } else if (iov_iter_is_bvec(i)) { 121127c0e374SAl Viro const struct bio_vec *bvec = i->bvec; 121227c0e374SAl Viro while (1) { 121327c0e374SAl Viro size_t n = (--bvec)->bv_len; 121427c0e374SAl Viro i->nr_segs++; 121527c0e374SAl Viro if (unroll <= n) { 121627c0e374SAl Viro i->bvec = bvec; 121727c0e374SAl Viro i->iov_offset = n - unroll; 121827c0e374SAl Viro return; 121927c0e374SAl Viro } 122027c0e374SAl Viro unroll -= n; 122127c0e374SAl Viro } 122227c0e374SAl Viro } else { /* same logics for iovec and kvec */ 122327c0e374SAl Viro const struct iovec *iov = i->iov; 122427c0e374SAl Viro while (1) { 122527c0e374SAl Viro size_t n = (--iov)->iov_len; 122627c0e374SAl Viro i->nr_segs++; 122727c0e374SAl Viro if (unroll <= n) { 122827c0e374SAl Viro i->iov = iov; 122927c0e374SAl Viro i->iov_offset = n - unroll; 123027c0e374SAl Viro return; 123127c0e374SAl Viro } 123227c0e374SAl Viro unroll -= n; 123327c0e374SAl Viro } 123427c0e374SAl Viro } 123527c0e374SAl Viro } 123627c0e374SAl Viro EXPORT_SYMBOL(iov_iter_revert); 123727c0e374SAl Viro 1238d879cb83SAl Viro /* 1239d879cb83SAl Viro * Return the count of just the current iov_iter segment. 1240d879cb83SAl Viro */ 1241d879cb83SAl Viro size_t iov_iter_single_seg_count(const struct iov_iter *i) 1242d879cb83SAl Viro { 124300e23707SDavid Howells if (unlikely(iov_iter_is_pipe(i))) 1244241699cdSAl Viro return i->count; // it is a silly place, anyway 1245d879cb83SAl Viro if (i->nr_segs == 1) 1246d879cb83SAl Viro return i->count; 12477ff50620SDavid Howells if (unlikely(iov_iter_is_discard(i) || iov_iter_is_xarray(i))) 12489ea9ce04SDavid Howells return i->count; 12497ff50620SDavid Howells if (iov_iter_is_bvec(i)) 1250d879cb83SAl Viro return min(i->count, i->bvec->bv_len - i->iov_offset); 1251d879cb83SAl Viro else 1252d879cb83SAl Viro return min(i->count, i->iov->iov_len - i->iov_offset); 1253d879cb83SAl Viro } 1254d879cb83SAl Viro EXPORT_SYMBOL(iov_iter_single_seg_count); 1255d879cb83SAl Viro 1256aa563d7bSDavid Howells void iov_iter_kvec(struct iov_iter *i, unsigned int direction, 1257d879cb83SAl Viro const struct kvec *kvec, unsigned long nr_segs, 1258d879cb83SAl Viro size_t count) 1259d879cb83SAl Viro { 1260aa563d7bSDavid Howells WARN_ON(direction & ~(READ | WRITE)); 1261aa563d7bSDavid Howells i->type = ITER_KVEC | (direction & (READ | WRITE)); 1262d879cb83SAl Viro i->kvec = kvec; 1263d879cb83SAl Viro i->nr_segs = nr_segs; 1264d879cb83SAl Viro i->iov_offset = 0; 1265d879cb83SAl Viro i->count = count; 1266d879cb83SAl Viro } 1267d879cb83SAl Viro EXPORT_SYMBOL(iov_iter_kvec); 1268d879cb83SAl Viro 1269aa563d7bSDavid Howells void iov_iter_bvec(struct iov_iter *i, unsigned int direction, 1270d879cb83SAl Viro const struct bio_vec *bvec, unsigned long nr_segs, 1271d879cb83SAl Viro size_t count) 1272d879cb83SAl Viro { 1273aa563d7bSDavid Howells WARN_ON(direction & ~(READ | WRITE)); 1274aa563d7bSDavid Howells i->type = ITER_BVEC | (direction & (READ | WRITE)); 1275d879cb83SAl Viro i->bvec = bvec; 1276d879cb83SAl Viro i->nr_segs = nr_segs; 1277d879cb83SAl Viro i->iov_offset = 0; 1278d879cb83SAl Viro i->count = count; 1279d879cb83SAl Viro } 1280d879cb83SAl Viro EXPORT_SYMBOL(iov_iter_bvec); 1281d879cb83SAl Viro 1282aa563d7bSDavid Howells void iov_iter_pipe(struct iov_iter *i, unsigned int direction, 1283241699cdSAl Viro struct pipe_inode_info *pipe, 1284241699cdSAl Viro size_t count) 1285241699cdSAl Viro { 1286aa563d7bSDavid Howells BUG_ON(direction != READ); 12878cefc107SDavid Howells WARN_ON(pipe_full(pipe->head, pipe->tail, pipe->ring_size)); 1288aa563d7bSDavid Howells i->type = ITER_PIPE | READ; 1289241699cdSAl Viro i->pipe = pipe; 12908cefc107SDavid Howells i->head = pipe->head; 1291241699cdSAl Viro i->iov_offset = 0; 1292241699cdSAl Viro i->count = count; 12938cefc107SDavid Howells i->start_head = i->head; 1294241699cdSAl Viro } 1295241699cdSAl Viro EXPORT_SYMBOL(iov_iter_pipe); 1296241699cdSAl Viro 12979ea9ce04SDavid Howells /** 12987ff50620SDavid Howells * iov_iter_xarray - Initialise an I/O iterator to use the pages in an xarray 12997ff50620SDavid Howells * @i: The iterator to initialise. 13007ff50620SDavid Howells * @direction: The direction of the transfer. 13017ff50620SDavid Howells * @xarray: The xarray to access. 13027ff50620SDavid Howells * @start: The start file position. 13037ff50620SDavid Howells * @count: The size of the I/O buffer in bytes. 13047ff50620SDavid Howells * 13057ff50620SDavid Howells * Set up an I/O iterator to either draw data out of the pages attached to an 13067ff50620SDavid Howells * inode or to inject data into those pages. The pages *must* be prevented 13077ff50620SDavid Howells * from evaporation, either by taking a ref on them or locking them by the 13087ff50620SDavid Howells * caller. 13097ff50620SDavid Howells */ 13107ff50620SDavid Howells void iov_iter_xarray(struct iov_iter *i, unsigned int direction, 13117ff50620SDavid Howells struct xarray *xarray, loff_t start, size_t count) 13127ff50620SDavid Howells { 13137ff50620SDavid Howells BUG_ON(direction & ~1); 13147ff50620SDavid Howells i->type = ITER_XARRAY | (direction & (READ | WRITE)); 13157ff50620SDavid Howells i->xarray = xarray; 13167ff50620SDavid Howells i->xarray_start = start; 13177ff50620SDavid Howells i->count = count; 13187ff50620SDavid Howells i->iov_offset = 0; 13197ff50620SDavid Howells } 13207ff50620SDavid Howells EXPORT_SYMBOL(iov_iter_xarray); 13217ff50620SDavid Howells 13227ff50620SDavid Howells /** 13239ea9ce04SDavid Howells * iov_iter_discard - Initialise an I/O iterator that discards data 13249ea9ce04SDavid Howells * @i: The iterator to initialise. 13259ea9ce04SDavid Howells * @direction: The direction of the transfer. 13269ea9ce04SDavid Howells * @count: The size of the I/O buffer in bytes. 13279ea9ce04SDavid Howells * 13289ea9ce04SDavid Howells * Set up an I/O iterator that just discards everything that's written to it. 13299ea9ce04SDavid Howells * It's only available as a READ iterator. 13309ea9ce04SDavid Howells */ 13319ea9ce04SDavid Howells void iov_iter_discard(struct iov_iter *i, unsigned int direction, size_t count) 13329ea9ce04SDavid Howells { 13339ea9ce04SDavid Howells BUG_ON(direction != READ); 13349ea9ce04SDavid Howells i->type = ITER_DISCARD | READ; 13359ea9ce04SDavid Howells i->count = count; 13369ea9ce04SDavid Howells i->iov_offset = 0; 13379ea9ce04SDavid Howells } 13389ea9ce04SDavid Howells EXPORT_SYMBOL(iov_iter_discard); 13399ea9ce04SDavid Howells 1340d879cb83SAl Viro unsigned long iov_iter_alignment(const struct iov_iter *i) 1341d879cb83SAl Viro { 1342d879cb83SAl Viro unsigned long res = 0; 1343d879cb83SAl Viro size_t size = i->count; 1344d879cb83SAl Viro 134500e23707SDavid Howells if (unlikely(iov_iter_is_pipe(i))) { 1346e0ff126eSJan Kara unsigned int p_mask = i->pipe->ring_size - 1; 1347e0ff126eSJan Kara 13488cefc107SDavid Howells if (size && i->iov_offset && allocated(&i->pipe->bufs[i->head & p_mask])) 1349241699cdSAl Viro return size | i->iov_offset; 1350241699cdSAl Viro return size; 1351241699cdSAl Viro } 1352*3d14ec1fSDavid Howells if (unlikely(iov_iter_is_xarray(i))) 1353*3d14ec1fSDavid Howells return (i->xarray_start + i->iov_offset) | i->count; 1354d879cb83SAl Viro iterate_all_kinds(i, size, v, 1355d879cb83SAl Viro (res |= (unsigned long)v.iov_base | v.iov_len, 0), 1356d879cb83SAl Viro res |= v.bv_offset | v.bv_len, 13577ff50620SDavid Howells res |= (unsigned long)v.iov_base | v.iov_len, 13587ff50620SDavid Howells res |= v.bv_offset | v.bv_len 1359d879cb83SAl Viro ) 1360d879cb83SAl Viro return res; 1361d879cb83SAl Viro } 1362d879cb83SAl Viro EXPORT_SYMBOL(iov_iter_alignment); 1363d879cb83SAl Viro 1364357f435dSAl Viro unsigned long iov_iter_gap_alignment(const struct iov_iter *i) 1365357f435dSAl Viro { 1366357f435dSAl Viro unsigned long res = 0; 1367357f435dSAl Viro size_t size = i->count; 1368357f435dSAl Viro 13699ea9ce04SDavid Howells if (unlikely(iov_iter_is_pipe(i) || iov_iter_is_discard(i))) { 1370241699cdSAl Viro WARN_ON(1); 1371241699cdSAl Viro return ~0U; 1372241699cdSAl Viro } 1373241699cdSAl Viro 1374357f435dSAl Viro iterate_all_kinds(i, size, v, 1375357f435dSAl Viro (res |= (!res ? 0 : (unsigned long)v.iov_base) | 1376357f435dSAl Viro (size != v.iov_len ? size : 0), 0), 1377357f435dSAl Viro (res |= (!res ? 0 : (unsigned long)v.bv_offset) | 1378357f435dSAl Viro (size != v.bv_len ? size : 0)), 1379357f435dSAl Viro (res |= (!res ? 0 : (unsigned long)v.iov_base) | 13807ff50620SDavid Howells (size != v.iov_len ? size : 0)), 13817ff50620SDavid Howells (res |= (!res ? 0 : (unsigned long)v.bv_offset) | 13827ff50620SDavid Howells (size != v.bv_len ? size : 0)) 1383357f435dSAl Viro ); 1384357f435dSAl Viro return res; 1385357f435dSAl Viro } 1386357f435dSAl Viro EXPORT_SYMBOL(iov_iter_gap_alignment); 1387357f435dSAl Viro 1388e76b6312SIlya Dryomov static inline ssize_t __pipe_get_pages(struct iov_iter *i, 1389241699cdSAl Viro size_t maxsize, 1390241699cdSAl Viro struct page **pages, 13918cefc107SDavid Howells int iter_head, 1392241699cdSAl Viro size_t *start) 1393241699cdSAl Viro { 1394241699cdSAl Viro struct pipe_inode_info *pipe = i->pipe; 13958cefc107SDavid Howells unsigned int p_mask = pipe->ring_size - 1; 13968cefc107SDavid Howells ssize_t n = push_pipe(i, maxsize, &iter_head, start); 1397241699cdSAl Viro if (!n) 1398241699cdSAl Viro return -EFAULT; 1399241699cdSAl Viro 1400241699cdSAl Viro maxsize = n; 1401241699cdSAl Viro n += *start; 14021689c73aSAl Viro while (n > 0) { 14038cefc107SDavid Howells get_page(*pages++ = pipe->bufs[iter_head & p_mask].page); 14048cefc107SDavid Howells iter_head++; 1405241699cdSAl Viro n -= PAGE_SIZE; 1406241699cdSAl Viro } 1407241699cdSAl Viro 1408241699cdSAl Viro return maxsize; 1409241699cdSAl Viro } 1410241699cdSAl Viro 1411241699cdSAl Viro static ssize_t pipe_get_pages(struct iov_iter *i, 1412241699cdSAl Viro struct page **pages, size_t maxsize, unsigned maxpages, 1413241699cdSAl Viro size_t *start) 1414241699cdSAl Viro { 14158cefc107SDavid Howells unsigned int iter_head, npages; 1416241699cdSAl Viro size_t capacity; 1417241699cdSAl Viro 141833844e66SAl Viro if (!maxsize) 141933844e66SAl Viro return 0; 142033844e66SAl Viro 1421241699cdSAl Viro if (!sanity(i)) 1422241699cdSAl Viro return -EFAULT; 1423241699cdSAl Viro 14248cefc107SDavid Howells data_start(i, &iter_head, start); 14258cefc107SDavid Howells /* Amount of free space: some of this one + all after this one */ 14268cefc107SDavid Howells npages = pipe_space_for_user(iter_head, i->pipe->tail, i->pipe); 1427241699cdSAl Viro capacity = min(npages, maxpages) * PAGE_SIZE - *start; 1428241699cdSAl Viro 14298cefc107SDavid Howells return __pipe_get_pages(i, min(maxsize, capacity), pages, iter_head, start); 1430241699cdSAl Viro } 1431241699cdSAl Viro 14327ff50620SDavid Howells static ssize_t iter_xarray_populate_pages(struct page **pages, struct xarray *xa, 14337ff50620SDavid Howells pgoff_t index, unsigned int nr_pages) 14347ff50620SDavid Howells { 14357ff50620SDavid Howells XA_STATE(xas, xa, index); 14367ff50620SDavid Howells struct page *page; 14377ff50620SDavid Howells unsigned int ret = 0; 14387ff50620SDavid Howells 14397ff50620SDavid Howells rcu_read_lock(); 14407ff50620SDavid Howells for (page = xas_load(&xas); page; page = xas_next(&xas)) { 14417ff50620SDavid Howells if (xas_retry(&xas, page)) 14427ff50620SDavid Howells continue; 14437ff50620SDavid Howells 14447ff50620SDavid Howells /* Has the page moved or been split? */ 14457ff50620SDavid Howells if (unlikely(page != xas_reload(&xas))) { 14467ff50620SDavid Howells xas_reset(&xas); 14477ff50620SDavid Howells continue; 14487ff50620SDavid Howells } 14497ff50620SDavid Howells 14507ff50620SDavid Howells pages[ret] = find_subpage(page, xas.xa_index); 14517ff50620SDavid Howells get_page(pages[ret]); 14527ff50620SDavid Howells if (++ret == nr_pages) 14537ff50620SDavid Howells break; 14547ff50620SDavid Howells } 14557ff50620SDavid Howells rcu_read_unlock(); 14567ff50620SDavid Howells return ret; 14577ff50620SDavid Howells } 14587ff50620SDavid Howells 14597ff50620SDavid Howells static ssize_t iter_xarray_get_pages(struct iov_iter *i, 14607ff50620SDavid Howells struct page **pages, size_t maxsize, 14617ff50620SDavid Howells unsigned maxpages, size_t *_start_offset) 14627ff50620SDavid Howells { 14637ff50620SDavid Howells unsigned nr, offset; 14647ff50620SDavid Howells pgoff_t index, count; 14657ff50620SDavid Howells size_t size = maxsize, actual; 14667ff50620SDavid Howells loff_t pos; 14677ff50620SDavid Howells 14687ff50620SDavid Howells if (!size || !maxpages) 14697ff50620SDavid Howells return 0; 14707ff50620SDavid Howells 14717ff50620SDavid Howells pos = i->xarray_start + i->iov_offset; 14727ff50620SDavid Howells index = pos >> PAGE_SHIFT; 14737ff50620SDavid Howells offset = pos & ~PAGE_MASK; 14747ff50620SDavid Howells *_start_offset = offset; 14757ff50620SDavid Howells 14767ff50620SDavid Howells count = 1; 14777ff50620SDavid Howells if (size > PAGE_SIZE - offset) { 14787ff50620SDavid Howells size -= PAGE_SIZE - offset; 14797ff50620SDavid Howells count += size >> PAGE_SHIFT; 14807ff50620SDavid Howells size &= ~PAGE_MASK; 14817ff50620SDavid Howells if (size) 14827ff50620SDavid Howells count++; 14837ff50620SDavid Howells } 14847ff50620SDavid Howells 14857ff50620SDavid Howells if (count > maxpages) 14867ff50620SDavid Howells count = maxpages; 14877ff50620SDavid Howells 14887ff50620SDavid Howells nr = iter_xarray_populate_pages(pages, i->xarray, index, count); 14897ff50620SDavid Howells if (nr == 0) 14907ff50620SDavid Howells return 0; 14917ff50620SDavid Howells 14927ff50620SDavid Howells actual = PAGE_SIZE * nr; 14937ff50620SDavid Howells actual -= offset; 14947ff50620SDavid Howells if (nr == count && size > 0) { 14957ff50620SDavid Howells unsigned last_offset = (nr > 1) ? 0 : offset; 14967ff50620SDavid Howells actual -= PAGE_SIZE - (last_offset + size); 14977ff50620SDavid Howells } 14987ff50620SDavid Howells return actual; 14997ff50620SDavid Howells } 15007ff50620SDavid Howells 1501d879cb83SAl Viro ssize_t iov_iter_get_pages(struct iov_iter *i, 1502d879cb83SAl Viro struct page **pages, size_t maxsize, unsigned maxpages, 1503d879cb83SAl Viro size_t *start) 1504d879cb83SAl Viro { 1505d879cb83SAl Viro if (maxsize > i->count) 1506d879cb83SAl Viro maxsize = i->count; 1507d879cb83SAl Viro 150800e23707SDavid Howells if (unlikely(iov_iter_is_pipe(i))) 1509241699cdSAl Viro return pipe_get_pages(i, pages, maxsize, maxpages, start); 15107ff50620SDavid Howells if (unlikely(iov_iter_is_xarray(i))) 15117ff50620SDavid Howells return iter_xarray_get_pages(i, pages, maxsize, maxpages, start); 15129ea9ce04SDavid Howells if (unlikely(iov_iter_is_discard(i))) 15139ea9ce04SDavid Howells return -EFAULT; 15149ea9ce04SDavid Howells 1515d879cb83SAl Viro iterate_all_kinds(i, maxsize, v, ({ 1516d879cb83SAl Viro unsigned long addr = (unsigned long)v.iov_base; 1517d879cb83SAl Viro size_t len = v.iov_len + (*start = addr & (PAGE_SIZE - 1)); 1518d879cb83SAl Viro int n; 1519d879cb83SAl Viro int res; 1520d879cb83SAl Viro 1521d879cb83SAl Viro if (len > maxpages * PAGE_SIZE) 1522d879cb83SAl Viro len = maxpages * PAGE_SIZE; 1523d879cb83SAl Viro addr &= ~(PAGE_SIZE - 1); 1524d879cb83SAl Viro n = DIV_ROUND_UP(len, PAGE_SIZE); 152573b0140bSIra Weiny res = get_user_pages_fast(addr, n, 152673b0140bSIra Weiny iov_iter_rw(i) != WRITE ? FOLL_WRITE : 0, 152773b0140bSIra Weiny pages); 1528d879cb83SAl Viro if (unlikely(res < 0)) 1529d879cb83SAl Viro return res; 1530d879cb83SAl Viro return (res == n ? len : res * PAGE_SIZE) - *start; 1531d879cb83SAl Viro 0;}),({ 1532d879cb83SAl Viro /* can't be more than PAGE_SIZE */ 1533d879cb83SAl Viro *start = v.bv_offset; 1534d879cb83SAl Viro get_page(*pages = v.bv_page); 1535d879cb83SAl Viro return v.bv_len; 1536d879cb83SAl Viro }),({ 1537d879cb83SAl Viro return -EFAULT; 15387ff50620SDavid Howells }), 15397ff50620SDavid Howells 0 1540d879cb83SAl Viro ) 1541d879cb83SAl Viro return 0; 1542d879cb83SAl Viro } 1543d879cb83SAl Viro EXPORT_SYMBOL(iov_iter_get_pages); 1544d879cb83SAl Viro 1545d879cb83SAl Viro static struct page **get_pages_array(size_t n) 1546d879cb83SAl Viro { 1547752ade68SMichal Hocko return kvmalloc_array(n, sizeof(struct page *), GFP_KERNEL); 1548d879cb83SAl Viro } 1549d879cb83SAl Viro 1550241699cdSAl Viro static ssize_t pipe_get_pages_alloc(struct iov_iter *i, 1551241699cdSAl Viro struct page ***pages, size_t maxsize, 1552241699cdSAl Viro size_t *start) 1553241699cdSAl Viro { 1554241699cdSAl Viro struct page **p; 15558cefc107SDavid Howells unsigned int iter_head, npages; 1556d7760d63SIlya Dryomov ssize_t n; 1557241699cdSAl Viro 155833844e66SAl Viro if (!maxsize) 155933844e66SAl Viro return 0; 156033844e66SAl Viro 1561241699cdSAl Viro if (!sanity(i)) 1562241699cdSAl Viro return -EFAULT; 1563241699cdSAl Viro 15648cefc107SDavid Howells data_start(i, &iter_head, start); 15658cefc107SDavid Howells /* Amount of free space: some of this one + all after this one */ 15668cefc107SDavid Howells npages = pipe_space_for_user(iter_head, i->pipe->tail, i->pipe); 1567241699cdSAl Viro n = npages * PAGE_SIZE - *start; 1568241699cdSAl Viro if (maxsize > n) 1569241699cdSAl Viro maxsize = n; 1570241699cdSAl Viro else 1571241699cdSAl Viro npages = DIV_ROUND_UP(maxsize + *start, PAGE_SIZE); 1572241699cdSAl Viro p = get_pages_array(npages); 1573241699cdSAl Viro if (!p) 1574241699cdSAl Viro return -ENOMEM; 15758cefc107SDavid Howells n = __pipe_get_pages(i, maxsize, p, iter_head, start); 1576241699cdSAl Viro if (n > 0) 1577241699cdSAl Viro *pages = p; 1578241699cdSAl Viro else 1579241699cdSAl Viro kvfree(p); 1580241699cdSAl Viro return n; 1581241699cdSAl Viro } 1582241699cdSAl Viro 15837ff50620SDavid Howells static ssize_t iter_xarray_get_pages_alloc(struct iov_iter *i, 15847ff50620SDavid Howells struct page ***pages, size_t maxsize, 15857ff50620SDavid Howells size_t *_start_offset) 15867ff50620SDavid Howells { 15877ff50620SDavid Howells struct page **p; 15887ff50620SDavid Howells unsigned nr, offset; 15897ff50620SDavid Howells pgoff_t index, count; 15907ff50620SDavid Howells size_t size = maxsize, actual; 15917ff50620SDavid Howells loff_t pos; 15927ff50620SDavid Howells 15937ff50620SDavid Howells if (!size) 15947ff50620SDavid Howells return 0; 15957ff50620SDavid Howells 15967ff50620SDavid Howells pos = i->xarray_start + i->iov_offset; 15977ff50620SDavid Howells index = pos >> PAGE_SHIFT; 15987ff50620SDavid Howells offset = pos & ~PAGE_MASK; 15997ff50620SDavid Howells *_start_offset = offset; 16007ff50620SDavid Howells 16017ff50620SDavid Howells count = 1; 16027ff50620SDavid Howells if (size > PAGE_SIZE - offset) { 16037ff50620SDavid Howells size -= PAGE_SIZE - offset; 16047ff50620SDavid Howells count += size >> PAGE_SHIFT; 16057ff50620SDavid Howells size &= ~PAGE_MASK; 16067ff50620SDavid Howells if (size) 16077ff50620SDavid Howells count++; 16087ff50620SDavid Howells } 16097ff50620SDavid Howells 16107ff50620SDavid Howells p = get_pages_array(count); 16117ff50620SDavid Howells if (!p) 16127ff50620SDavid Howells return -ENOMEM; 16137ff50620SDavid Howells *pages = p; 16147ff50620SDavid Howells 16157ff50620SDavid Howells nr = iter_xarray_populate_pages(p, i->xarray, index, count); 16167ff50620SDavid Howells if (nr == 0) 16177ff50620SDavid Howells return 0; 16187ff50620SDavid Howells 16197ff50620SDavid Howells actual = PAGE_SIZE * nr; 16207ff50620SDavid Howells actual -= offset; 16217ff50620SDavid Howells if (nr == count && size > 0) { 16227ff50620SDavid Howells unsigned last_offset = (nr > 1) ? 0 : offset; 16237ff50620SDavid Howells actual -= PAGE_SIZE - (last_offset + size); 16247ff50620SDavid Howells } 16257ff50620SDavid Howells return actual; 16267ff50620SDavid Howells } 16277ff50620SDavid Howells 1628d879cb83SAl Viro ssize_t iov_iter_get_pages_alloc(struct iov_iter *i, 1629d879cb83SAl Viro struct page ***pages, size_t maxsize, 1630d879cb83SAl Viro size_t *start) 1631d879cb83SAl Viro { 1632d879cb83SAl Viro struct page **p; 1633d879cb83SAl Viro 1634d879cb83SAl Viro if (maxsize > i->count) 1635d879cb83SAl Viro maxsize = i->count; 1636d879cb83SAl Viro 163700e23707SDavid Howells if (unlikely(iov_iter_is_pipe(i))) 1638241699cdSAl Viro return pipe_get_pages_alloc(i, pages, maxsize, start); 16397ff50620SDavid Howells if (unlikely(iov_iter_is_xarray(i))) 16407ff50620SDavid Howells return iter_xarray_get_pages_alloc(i, pages, maxsize, start); 16419ea9ce04SDavid Howells if (unlikely(iov_iter_is_discard(i))) 16429ea9ce04SDavid Howells return -EFAULT; 16439ea9ce04SDavid Howells 1644d879cb83SAl Viro iterate_all_kinds(i, maxsize, v, ({ 1645d879cb83SAl Viro unsigned long addr = (unsigned long)v.iov_base; 1646d879cb83SAl Viro size_t len = v.iov_len + (*start = addr & (PAGE_SIZE - 1)); 1647d879cb83SAl Viro int n; 1648d879cb83SAl Viro int res; 1649d879cb83SAl Viro 1650d879cb83SAl Viro addr &= ~(PAGE_SIZE - 1); 1651d879cb83SAl Viro n = DIV_ROUND_UP(len, PAGE_SIZE); 1652d879cb83SAl Viro p = get_pages_array(n); 1653d879cb83SAl Viro if (!p) 1654d879cb83SAl Viro return -ENOMEM; 165573b0140bSIra Weiny res = get_user_pages_fast(addr, n, 165673b0140bSIra Weiny iov_iter_rw(i) != WRITE ? FOLL_WRITE : 0, p); 1657d879cb83SAl Viro if (unlikely(res < 0)) { 1658d879cb83SAl Viro kvfree(p); 1659d879cb83SAl Viro return res; 1660d879cb83SAl Viro } 1661d879cb83SAl Viro *pages = p; 1662d879cb83SAl Viro return (res == n ? len : res * PAGE_SIZE) - *start; 1663d879cb83SAl Viro 0;}),({ 1664d879cb83SAl Viro /* can't be more than PAGE_SIZE */ 1665d879cb83SAl Viro *start = v.bv_offset; 1666d879cb83SAl Viro *pages = p = get_pages_array(1); 1667d879cb83SAl Viro if (!p) 1668d879cb83SAl Viro return -ENOMEM; 1669d879cb83SAl Viro get_page(*p = v.bv_page); 1670d879cb83SAl Viro return v.bv_len; 1671d879cb83SAl Viro }),({ 1672d879cb83SAl Viro return -EFAULT; 16737ff50620SDavid Howells }), 0 1674d879cb83SAl Viro ) 1675d879cb83SAl Viro return 0; 1676d879cb83SAl Viro } 1677d879cb83SAl Viro EXPORT_SYMBOL(iov_iter_get_pages_alloc); 1678d879cb83SAl Viro 1679d879cb83SAl Viro size_t csum_and_copy_from_iter(void *addr, size_t bytes, __wsum *csum, 1680d879cb83SAl Viro struct iov_iter *i) 1681d879cb83SAl Viro { 1682d879cb83SAl Viro char *to = addr; 1683d879cb83SAl Viro __wsum sum, next; 1684d879cb83SAl Viro size_t off = 0; 1685d879cb83SAl Viro sum = *csum; 16869ea9ce04SDavid Howells if (unlikely(iov_iter_is_pipe(i) || iov_iter_is_discard(i))) { 1687241699cdSAl Viro WARN_ON(1); 1688241699cdSAl Viro return 0; 1689241699cdSAl Viro } 1690d879cb83SAl Viro iterate_and_advance(i, bytes, v, ({ 1691d879cb83SAl Viro next = csum_and_copy_from_user(v.iov_base, 1692d879cb83SAl Viro (to += v.iov_len) - v.iov_len, 1693c693cc46SAl Viro v.iov_len); 1694c693cc46SAl Viro if (next) { 1695d879cb83SAl Viro sum = csum_block_add(sum, next, off); 1696d879cb83SAl Viro off += v.iov_len; 1697d879cb83SAl Viro } 1698c693cc46SAl Viro next ? 0 : v.iov_len; 1699d879cb83SAl Viro }), ({ 1700d879cb83SAl Viro char *p = kmap_atomic(v.bv_page); 1701f9152895SAl Viro sum = csum_and_memcpy((to += v.bv_len) - v.bv_len, 1702f9152895SAl Viro p + v.bv_offset, v.bv_len, 1703f9152895SAl Viro sum, off); 1704d879cb83SAl Viro kunmap_atomic(p); 1705d879cb83SAl Viro off += v.bv_len; 1706d879cb83SAl Viro }),({ 1707f9152895SAl Viro sum = csum_and_memcpy((to += v.iov_len) - v.iov_len, 1708f9152895SAl Viro v.iov_base, v.iov_len, 1709f9152895SAl Viro sum, off); 1710d879cb83SAl Viro off += v.iov_len; 17117ff50620SDavid Howells }), ({ 17127ff50620SDavid Howells char *p = kmap_atomic(v.bv_page); 17137ff50620SDavid Howells sum = csum_and_memcpy((to += v.bv_len) - v.bv_len, 17147ff50620SDavid Howells p + v.bv_offset, v.bv_len, 17157ff50620SDavid Howells sum, off); 17167ff50620SDavid Howells kunmap_atomic(p); 17177ff50620SDavid Howells off += v.bv_len; 1718d879cb83SAl Viro }) 1719d879cb83SAl Viro ) 1720d879cb83SAl Viro *csum = sum; 1721d879cb83SAl Viro return bytes; 1722d879cb83SAl Viro } 1723d879cb83SAl Viro EXPORT_SYMBOL(csum_and_copy_from_iter); 1724d879cb83SAl Viro 1725cbbd26b8SAl Viro bool csum_and_copy_from_iter_full(void *addr, size_t bytes, __wsum *csum, 1726cbbd26b8SAl Viro struct iov_iter *i) 1727cbbd26b8SAl Viro { 1728cbbd26b8SAl Viro char *to = addr; 1729cbbd26b8SAl Viro __wsum sum, next; 1730cbbd26b8SAl Viro size_t off = 0; 1731cbbd26b8SAl Viro sum = *csum; 17329ea9ce04SDavid Howells if (unlikely(iov_iter_is_pipe(i) || iov_iter_is_discard(i))) { 1733cbbd26b8SAl Viro WARN_ON(1); 1734cbbd26b8SAl Viro return false; 1735cbbd26b8SAl Viro } 1736cbbd26b8SAl Viro if (unlikely(i->count < bytes)) 1737cbbd26b8SAl Viro return false; 1738cbbd26b8SAl Viro iterate_all_kinds(i, bytes, v, ({ 1739cbbd26b8SAl Viro next = csum_and_copy_from_user(v.iov_base, 1740cbbd26b8SAl Viro (to += v.iov_len) - v.iov_len, 1741c693cc46SAl Viro v.iov_len); 1742c693cc46SAl Viro if (!next) 1743cbbd26b8SAl Viro return false; 1744cbbd26b8SAl Viro sum = csum_block_add(sum, next, off); 1745cbbd26b8SAl Viro off += v.iov_len; 1746cbbd26b8SAl Viro 0; 1747cbbd26b8SAl Viro }), ({ 1748cbbd26b8SAl Viro char *p = kmap_atomic(v.bv_page); 1749f9152895SAl Viro sum = csum_and_memcpy((to += v.bv_len) - v.bv_len, 1750f9152895SAl Viro p + v.bv_offset, v.bv_len, 1751f9152895SAl Viro sum, off); 1752cbbd26b8SAl Viro kunmap_atomic(p); 1753cbbd26b8SAl Viro off += v.bv_len; 1754cbbd26b8SAl Viro }),({ 1755f9152895SAl Viro sum = csum_and_memcpy((to += v.iov_len) - v.iov_len, 1756f9152895SAl Viro v.iov_base, v.iov_len, 1757f9152895SAl Viro sum, off); 1758cbbd26b8SAl Viro off += v.iov_len; 17597ff50620SDavid Howells }), ({ 17607ff50620SDavid Howells char *p = kmap_atomic(v.bv_page); 17617ff50620SDavid Howells sum = csum_and_memcpy((to += v.bv_len) - v.bv_len, 17627ff50620SDavid Howells p + v.bv_offset, v.bv_len, 17637ff50620SDavid Howells sum, off); 17647ff50620SDavid Howells kunmap_atomic(p); 17657ff50620SDavid Howells off += v.bv_len; 1766cbbd26b8SAl Viro }) 1767cbbd26b8SAl Viro ) 1768cbbd26b8SAl Viro *csum = sum; 1769cbbd26b8SAl Viro iov_iter_advance(i, bytes); 1770cbbd26b8SAl Viro return true; 1771cbbd26b8SAl Viro } 1772cbbd26b8SAl Viro EXPORT_SYMBOL(csum_and_copy_from_iter_full); 1773cbbd26b8SAl Viro 177452cbd23aSWillem de Bruijn size_t csum_and_copy_to_iter(const void *addr, size_t bytes, void *_csstate, 1775d879cb83SAl Viro struct iov_iter *i) 1776d879cb83SAl Viro { 177752cbd23aSWillem de Bruijn struct csum_state *csstate = _csstate; 177836f7a8a4SAl Viro const char *from = addr; 1779d879cb83SAl Viro __wsum sum, next; 178052cbd23aSWillem de Bruijn size_t off; 178178e1f386SAl Viro 178278e1f386SAl Viro if (unlikely(iov_iter_is_pipe(i))) 178352cbd23aSWillem de Bruijn return csum_and_copy_to_pipe_iter(addr, bytes, _csstate, i); 178478e1f386SAl Viro 178552cbd23aSWillem de Bruijn sum = csstate->csum; 178652cbd23aSWillem de Bruijn off = csstate->off; 178778e1f386SAl Viro if (unlikely(iov_iter_is_discard(i))) { 1788241699cdSAl Viro WARN_ON(1); /* for now */ 1789241699cdSAl Viro return 0; 1790241699cdSAl Viro } 1791d879cb83SAl Viro iterate_and_advance(i, bytes, v, ({ 1792d879cb83SAl Viro next = csum_and_copy_to_user((from += v.iov_len) - v.iov_len, 1793d879cb83SAl Viro v.iov_base, 1794c693cc46SAl Viro v.iov_len); 1795c693cc46SAl Viro if (next) { 1796d879cb83SAl Viro sum = csum_block_add(sum, next, off); 1797d879cb83SAl Viro off += v.iov_len; 1798d879cb83SAl Viro } 1799c693cc46SAl Viro next ? 0 : v.iov_len; 1800d879cb83SAl Viro }), ({ 1801d879cb83SAl Viro char *p = kmap_atomic(v.bv_page); 1802f9152895SAl Viro sum = csum_and_memcpy(p + v.bv_offset, 1803f9152895SAl Viro (from += v.bv_len) - v.bv_len, 1804f9152895SAl Viro v.bv_len, sum, off); 1805d879cb83SAl Viro kunmap_atomic(p); 1806d879cb83SAl Viro off += v.bv_len; 1807d879cb83SAl Viro }),({ 1808f9152895SAl Viro sum = csum_and_memcpy(v.iov_base, 1809f9152895SAl Viro (from += v.iov_len) - v.iov_len, 1810f9152895SAl Viro v.iov_len, sum, off); 1811d879cb83SAl Viro off += v.iov_len; 18127ff50620SDavid Howells }), ({ 18137ff50620SDavid Howells char *p = kmap_atomic(v.bv_page); 18147ff50620SDavid Howells sum = csum_and_memcpy(p + v.bv_offset, 18157ff50620SDavid Howells (from += v.bv_len) - v.bv_len, 18167ff50620SDavid Howells v.bv_len, sum, off); 18177ff50620SDavid Howells kunmap_atomic(p); 18187ff50620SDavid Howells off += v.bv_len; 1819d879cb83SAl Viro }) 1820d879cb83SAl Viro ) 182152cbd23aSWillem de Bruijn csstate->csum = sum; 182252cbd23aSWillem de Bruijn csstate->off = off; 1823d879cb83SAl Viro return bytes; 1824d879cb83SAl Viro } 1825d879cb83SAl Viro EXPORT_SYMBOL(csum_and_copy_to_iter); 1826d879cb83SAl Viro 1827d05f4435SSagi Grimberg size_t hash_and_copy_to_iter(const void *addr, size_t bytes, void *hashp, 1828d05f4435SSagi Grimberg struct iov_iter *i) 1829d05f4435SSagi Grimberg { 18307999096fSHerbert Xu #ifdef CONFIG_CRYPTO_HASH 1831d05f4435SSagi Grimberg struct ahash_request *hash = hashp; 1832d05f4435SSagi Grimberg struct scatterlist sg; 1833d05f4435SSagi Grimberg size_t copied; 1834d05f4435SSagi Grimberg 1835d05f4435SSagi Grimberg copied = copy_to_iter(addr, bytes, i); 1836d05f4435SSagi Grimberg sg_init_one(&sg, addr, copied); 1837d05f4435SSagi Grimberg ahash_request_set_crypt(hash, &sg, NULL, copied); 1838d05f4435SSagi Grimberg crypto_ahash_update(hash); 1839d05f4435SSagi Grimberg return copied; 184027fad74aSYueHaibing #else 184127fad74aSYueHaibing return 0; 184227fad74aSYueHaibing #endif 1843d05f4435SSagi Grimberg } 1844d05f4435SSagi Grimberg EXPORT_SYMBOL(hash_and_copy_to_iter); 1845d05f4435SSagi Grimberg 1846d879cb83SAl Viro int iov_iter_npages(const struct iov_iter *i, int maxpages) 1847d879cb83SAl Viro { 1848d879cb83SAl Viro size_t size = i->count; 1849d879cb83SAl Viro int npages = 0; 1850d879cb83SAl Viro 1851d879cb83SAl Viro if (!size) 1852d879cb83SAl Viro return 0; 18539ea9ce04SDavid Howells if (unlikely(iov_iter_is_discard(i))) 18549ea9ce04SDavid Howells return 0; 1855d879cb83SAl Viro 185600e23707SDavid Howells if (unlikely(iov_iter_is_pipe(i))) { 1857241699cdSAl Viro struct pipe_inode_info *pipe = i->pipe; 18588cefc107SDavid Howells unsigned int iter_head; 1859241699cdSAl Viro size_t off; 1860241699cdSAl Viro 1861241699cdSAl Viro if (!sanity(i)) 1862241699cdSAl Viro return 0; 1863241699cdSAl Viro 18648cefc107SDavid Howells data_start(i, &iter_head, &off); 1865241699cdSAl Viro /* some of this one + all after this one */ 18668cefc107SDavid Howells npages = pipe_space_for_user(iter_head, pipe->tail, pipe); 1867241699cdSAl Viro if (npages >= maxpages) 1868241699cdSAl Viro return maxpages; 18697ff50620SDavid Howells } else if (unlikely(iov_iter_is_xarray(i))) { 18707ff50620SDavid Howells unsigned offset; 18717ff50620SDavid Howells 18727ff50620SDavid Howells offset = (i->xarray_start + i->iov_offset) & ~PAGE_MASK; 18737ff50620SDavid Howells 18747ff50620SDavid Howells npages = 1; 18757ff50620SDavid Howells if (size > PAGE_SIZE - offset) { 18767ff50620SDavid Howells size -= PAGE_SIZE - offset; 18777ff50620SDavid Howells npages += size >> PAGE_SHIFT; 18787ff50620SDavid Howells size &= ~PAGE_MASK; 18797ff50620SDavid Howells if (size) 18807ff50620SDavid Howells npages++; 18817ff50620SDavid Howells } 18827ff50620SDavid Howells if (npages >= maxpages) 18837ff50620SDavid Howells return maxpages; 1884241699cdSAl Viro } else iterate_all_kinds(i, size, v, ({ 1885d879cb83SAl Viro unsigned long p = (unsigned long)v.iov_base; 1886d879cb83SAl Viro npages += DIV_ROUND_UP(p + v.iov_len, PAGE_SIZE) 1887d879cb83SAl Viro - p / PAGE_SIZE; 1888d879cb83SAl Viro if (npages >= maxpages) 1889d879cb83SAl Viro return maxpages; 1890d879cb83SAl Viro 0;}),({ 1891d879cb83SAl Viro npages++; 1892d879cb83SAl Viro if (npages >= maxpages) 1893d879cb83SAl Viro return maxpages; 1894d879cb83SAl Viro }),({ 1895d879cb83SAl Viro unsigned long p = (unsigned long)v.iov_base; 1896d879cb83SAl Viro npages += DIV_ROUND_UP(p + v.iov_len, PAGE_SIZE) 1897d879cb83SAl Viro - p / PAGE_SIZE; 1898d879cb83SAl Viro if (npages >= maxpages) 1899d879cb83SAl Viro return maxpages; 19007ff50620SDavid Howells }), 19017ff50620SDavid Howells 0 1902d879cb83SAl Viro ) 1903d879cb83SAl Viro return npages; 1904d879cb83SAl Viro } 1905d879cb83SAl Viro EXPORT_SYMBOL(iov_iter_npages); 1906d879cb83SAl Viro 1907d879cb83SAl Viro const void *dup_iter(struct iov_iter *new, struct iov_iter *old, gfp_t flags) 1908d879cb83SAl Viro { 1909d879cb83SAl Viro *new = *old; 191000e23707SDavid Howells if (unlikely(iov_iter_is_pipe(new))) { 1911241699cdSAl Viro WARN_ON(1); 1912241699cdSAl Viro return NULL; 1913241699cdSAl Viro } 19147ff50620SDavid Howells if (unlikely(iov_iter_is_discard(new) || iov_iter_is_xarray(new))) 19159ea9ce04SDavid Howells return NULL; 191600e23707SDavid Howells if (iov_iter_is_bvec(new)) 1917d879cb83SAl Viro return new->bvec = kmemdup(new->bvec, 1918d879cb83SAl Viro new->nr_segs * sizeof(struct bio_vec), 1919d879cb83SAl Viro flags); 1920d879cb83SAl Viro else 1921d879cb83SAl Viro /* iovec and kvec have identical layout */ 1922d879cb83SAl Viro return new->iov = kmemdup(new->iov, 1923d879cb83SAl Viro new->nr_segs * sizeof(struct iovec), 1924d879cb83SAl Viro flags); 1925d879cb83SAl Viro } 1926d879cb83SAl Viro EXPORT_SYMBOL(dup_iter); 1927bc917be8SAl Viro 1928bfdc5970SChristoph Hellwig static int copy_compat_iovec_from_user(struct iovec *iov, 1929bfdc5970SChristoph Hellwig const struct iovec __user *uvec, unsigned long nr_segs) 1930bfdc5970SChristoph Hellwig { 1931bfdc5970SChristoph Hellwig const struct compat_iovec __user *uiov = 1932bfdc5970SChristoph Hellwig (const struct compat_iovec __user *)uvec; 1933bfdc5970SChristoph Hellwig int ret = -EFAULT, i; 1934bfdc5970SChristoph Hellwig 1935a959a978SChristoph Hellwig if (!user_access_begin(uiov, nr_segs * sizeof(*uiov))) 1936bfdc5970SChristoph Hellwig return -EFAULT; 1937bfdc5970SChristoph Hellwig 1938bfdc5970SChristoph Hellwig for (i = 0; i < nr_segs; i++) { 1939bfdc5970SChristoph Hellwig compat_uptr_t buf; 1940bfdc5970SChristoph Hellwig compat_ssize_t len; 1941bfdc5970SChristoph Hellwig 1942bfdc5970SChristoph Hellwig unsafe_get_user(len, &uiov[i].iov_len, uaccess_end); 1943bfdc5970SChristoph Hellwig unsafe_get_user(buf, &uiov[i].iov_base, uaccess_end); 1944bfdc5970SChristoph Hellwig 1945bfdc5970SChristoph Hellwig /* check for compat_size_t not fitting in compat_ssize_t .. */ 1946bfdc5970SChristoph Hellwig if (len < 0) { 1947bfdc5970SChristoph Hellwig ret = -EINVAL; 1948bfdc5970SChristoph Hellwig goto uaccess_end; 1949bfdc5970SChristoph Hellwig } 1950bfdc5970SChristoph Hellwig iov[i].iov_base = compat_ptr(buf); 1951bfdc5970SChristoph Hellwig iov[i].iov_len = len; 1952bfdc5970SChristoph Hellwig } 1953bfdc5970SChristoph Hellwig 1954bfdc5970SChristoph Hellwig ret = 0; 1955bfdc5970SChristoph Hellwig uaccess_end: 1956bfdc5970SChristoph Hellwig user_access_end(); 1957bfdc5970SChristoph Hellwig return ret; 1958bfdc5970SChristoph Hellwig } 1959bfdc5970SChristoph Hellwig 1960bfdc5970SChristoph Hellwig static int copy_iovec_from_user(struct iovec *iov, 1961bfdc5970SChristoph Hellwig const struct iovec __user *uvec, unsigned long nr_segs) 1962fb041b59SDavid Laight { 1963fb041b59SDavid Laight unsigned long seg; 1964bfdc5970SChristoph Hellwig 1965bfdc5970SChristoph Hellwig if (copy_from_user(iov, uvec, nr_segs * sizeof(*uvec))) 1966bfdc5970SChristoph Hellwig return -EFAULT; 1967bfdc5970SChristoph Hellwig for (seg = 0; seg < nr_segs; seg++) { 1968bfdc5970SChristoph Hellwig if ((ssize_t)iov[seg].iov_len < 0) 1969bfdc5970SChristoph Hellwig return -EINVAL; 1970bfdc5970SChristoph Hellwig } 1971bfdc5970SChristoph Hellwig 1972bfdc5970SChristoph Hellwig return 0; 1973bfdc5970SChristoph Hellwig } 1974bfdc5970SChristoph Hellwig 1975bfdc5970SChristoph Hellwig struct iovec *iovec_from_user(const struct iovec __user *uvec, 1976bfdc5970SChristoph Hellwig unsigned long nr_segs, unsigned long fast_segs, 1977bfdc5970SChristoph Hellwig struct iovec *fast_iov, bool compat) 1978bfdc5970SChristoph Hellwig { 1979bfdc5970SChristoph Hellwig struct iovec *iov = fast_iov; 1980bfdc5970SChristoph Hellwig int ret; 1981fb041b59SDavid Laight 1982fb041b59SDavid Laight /* 1983bfdc5970SChristoph Hellwig * SuS says "The readv() function *may* fail if the iovcnt argument was 1984bfdc5970SChristoph Hellwig * less than or equal to 0, or greater than {IOV_MAX}. Linux has 1985fb041b59SDavid Laight * traditionally returned zero for zero segments, so... 1986fb041b59SDavid Laight */ 1987bfdc5970SChristoph Hellwig if (nr_segs == 0) 1988bfdc5970SChristoph Hellwig return iov; 1989bfdc5970SChristoph Hellwig if (nr_segs > UIO_MAXIOV) 1990bfdc5970SChristoph Hellwig return ERR_PTR(-EINVAL); 1991fb041b59SDavid Laight if (nr_segs > fast_segs) { 1992fb041b59SDavid Laight iov = kmalloc_array(nr_segs, sizeof(struct iovec), GFP_KERNEL); 1993bfdc5970SChristoph Hellwig if (!iov) 1994bfdc5970SChristoph Hellwig return ERR_PTR(-ENOMEM); 1995fb041b59SDavid Laight } 1996bfdc5970SChristoph Hellwig 1997bfdc5970SChristoph Hellwig if (compat) 1998bfdc5970SChristoph Hellwig ret = copy_compat_iovec_from_user(iov, uvec, nr_segs); 1999bfdc5970SChristoph Hellwig else 2000bfdc5970SChristoph Hellwig ret = copy_iovec_from_user(iov, uvec, nr_segs); 2001bfdc5970SChristoph Hellwig if (ret) { 2002bfdc5970SChristoph Hellwig if (iov != fast_iov) 2003bfdc5970SChristoph Hellwig kfree(iov); 2004bfdc5970SChristoph Hellwig return ERR_PTR(ret); 2005fb041b59SDavid Laight } 2006bfdc5970SChristoph Hellwig 2007bfdc5970SChristoph Hellwig return iov; 2008bfdc5970SChristoph Hellwig } 2009bfdc5970SChristoph Hellwig 2010bfdc5970SChristoph Hellwig ssize_t __import_iovec(int type, const struct iovec __user *uvec, 2011bfdc5970SChristoph Hellwig unsigned nr_segs, unsigned fast_segs, struct iovec **iovp, 2012bfdc5970SChristoph Hellwig struct iov_iter *i, bool compat) 2013bfdc5970SChristoph Hellwig { 2014bfdc5970SChristoph Hellwig ssize_t total_len = 0; 2015bfdc5970SChristoph Hellwig unsigned long seg; 2016bfdc5970SChristoph Hellwig struct iovec *iov; 2017bfdc5970SChristoph Hellwig 2018bfdc5970SChristoph Hellwig iov = iovec_from_user(uvec, nr_segs, fast_segs, *iovp, compat); 2019bfdc5970SChristoph Hellwig if (IS_ERR(iov)) { 2020bfdc5970SChristoph Hellwig *iovp = NULL; 2021bfdc5970SChristoph Hellwig return PTR_ERR(iov); 2022fb041b59SDavid Laight } 2023fb041b59SDavid Laight 2024fb041b59SDavid Laight /* 2025bfdc5970SChristoph Hellwig * According to the Single Unix Specification we should return EINVAL if 2026bfdc5970SChristoph Hellwig * an element length is < 0 when cast to ssize_t or if the total length 2027bfdc5970SChristoph Hellwig * would overflow the ssize_t return value of the system call. 2028fb041b59SDavid Laight * 2029fb041b59SDavid Laight * Linux caps all read/write calls to MAX_RW_COUNT, and avoids the 2030fb041b59SDavid Laight * overflow case. 2031fb041b59SDavid Laight */ 2032fb041b59SDavid Laight for (seg = 0; seg < nr_segs; seg++) { 2033fb041b59SDavid Laight ssize_t len = (ssize_t)iov[seg].iov_len; 2034fb041b59SDavid Laight 2035bfdc5970SChristoph Hellwig if (!access_ok(iov[seg].iov_base, len)) { 2036bfdc5970SChristoph Hellwig if (iov != *iovp) 2037bfdc5970SChristoph Hellwig kfree(iov); 2038bfdc5970SChristoph Hellwig *iovp = NULL; 2039bfdc5970SChristoph Hellwig return -EFAULT; 2040fb041b59SDavid Laight } 2041bfdc5970SChristoph Hellwig 2042bfdc5970SChristoph Hellwig if (len > MAX_RW_COUNT - total_len) { 2043bfdc5970SChristoph Hellwig len = MAX_RW_COUNT - total_len; 2044fb041b59SDavid Laight iov[seg].iov_len = len; 2045fb041b59SDavid Laight } 2046bfdc5970SChristoph Hellwig total_len += len; 2047fb041b59SDavid Laight } 2048bfdc5970SChristoph Hellwig 2049bfdc5970SChristoph Hellwig iov_iter_init(i, type, iov, nr_segs, total_len); 2050bfdc5970SChristoph Hellwig if (iov == *iovp) 2051bfdc5970SChristoph Hellwig *iovp = NULL; 2052bfdc5970SChristoph Hellwig else 2053bfdc5970SChristoph Hellwig *iovp = iov; 2054bfdc5970SChristoph Hellwig return total_len; 2055fb041b59SDavid Laight } 2056fb041b59SDavid Laight 2057ffecee4fSVegard Nossum /** 2058ffecee4fSVegard Nossum * import_iovec() - Copy an array of &struct iovec from userspace 2059ffecee4fSVegard Nossum * into the kernel, check that it is valid, and initialize a new 2060ffecee4fSVegard Nossum * &struct iov_iter iterator to access it. 2061ffecee4fSVegard Nossum * 2062ffecee4fSVegard Nossum * @type: One of %READ or %WRITE. 2063bfdc5970SChristoph Hellwig * @uvec: Pointer to the userspace array. 2064ffecee4fSVegard Nossum * @nr_segs: Number of elements in userspace array. 2065ffecee4fSVegard Nossum * @fast_segs: Number of elements in @iov. 2066bfdc5970SChristoph Hellwig * @iovp: (input and output parameter) Pointer to pointer to (usually small 2067ffecee4fSVegard Nossum * on-stack) kernel array. 2068ffecee4fSVegard Nossum * @i: Pointer to iterator that will be initialized on success. 2069ffecee4fSVegard Nossum * 2070ffecee4fSVegard Nossum * If the array pointed to by *@iov is large enough to hold all @nr_segs, 2071ffecee4fSVegard Nossum * then this function places %NULL in *@iov on return. Otherwise, a new 2072ffecee4fSVegard Nossum * array will be allocated and the result placed in *@iov. This means that 2073ffecee4fSVegard Nossum * the caller may call kfree() on *@iov regardless of whether the small 2074ffecee4fSVegard Nossum * on-stack array was used or not (and regardless of whether this function 2075ffecee4fSVegard Nossum * returns an error or not). 2076ffecee4fSVegard Nossum * 207787e5e6daSJens Axboe * Return: Negative error code on error, bytes imported on success 2078ffecee4fSVegard Nossum */ 2079bfdc5970SChristoph Hellwig ssize_t import_iovec(int type, const struct iovec __user *uvec, 2080bc917be8SAl Viro unsigned nr_segs, unsigned fast_segs, 2081bfdc5970SChristoph Hellwig struct iovec **iovp, struct iov_iter *i) 2082bc917be8SAl Viro { 208389cd35c5SChristoph Hellwig return __import_iovec(type, uvec, nr_segs, fast_segs, iovp, i, 208489cd35c5SChristoph Hellwig in_compat_syscall()); 2085bc917be8SAl Viro } 2086bc917be8SAl Viro EXPORT_SYMBOL(import_iovec); 2087bc917be8SAl Viro 2088bc917be8SAl Viro int import_single_range(int rw, void __user *buf, size_t len, 2089bc917be8SAl Viro struct iovec *iov, struct iov_iter *i) 2090bc917be8SAl Viro { 2091bc917be8SAl Viro if (len > MAX_RW_COUNT) 2092bc917be8SAl Viro len = MAX_RW_COUNT; 209396d4f267SLinus Torvalds if (unlikely(!access_ok(buf, len))) 2094bc917be8SAl Viro return -EFAULT; 2095bc917be8SAl Viro 2096bc917be8SAl Viro iov->iov_base = buf; 2097bc917be8SAl Viro iov->iov_len = len; 2098bc917be8SAl Viro iov_iter_init(i, rw, iov, 1, len); 2099bc917be8SAl Viro return 0; 2100bc917be8SAl Viro } 2101e1267585SAl Viro EXPORT_SYMBOL(import_single_range); 210209cf698aSAl Viro 210309cf698aSAl Viro int iov_iter_for_each_range(struct iov_iter *i, size_t bytes, 210409cf698aSAl Viro int (*f)(struct kvec *vec, void *context), 210509cf698aSAl Viro void *context) 210609cf698aSAl Viro { 210709cf698aSAl Viro struct kvec w; 210809cf698aSAl Viro int err = -EINVAL; 210909cf698aSAl Viro if (!bytes) 211009cf698aSAl Viro return 0; 211109cf698aSAl Viro 211209cf698aSAl Viro iterate_all_kinds(i, bytes, v, -EINVAL, ({ 211309cf698aSAl Viro w.iov_base = kmap(v.bv_page) + v.bv_offset; 211409cf698aSAl Viro w.iov_len = v.bv_len; 211509cf698aSAl Viro err = f(&w, context); 211609cf698aSAl Viro kunmap(v.bv_page); 211709cf698aSAl Viro err;}), ({ 211809cf698aSAl Viro w = v; 21197ff50620SDavid Howells err = f(&w, context);}), ({ 21207ff50620SDavid Howells w.iov_base = kmap(v.bv_page) + v.bv_offset; 21217ff50620SDavid Howells w.iov_len = v.bv_len; 21227ff50620SDavid Howells err = f(&w, context); 21237ff50620SDavid Howells kunmap(v.bv_page); 21247ff50620SDavid Howells err;}) 212509cf698aSAl Viro ) 212609cf698aSAl Viro return err; 212709cf698aSAl Viro } 212809cf698aSAl Viro EXPORT_SYMBOL(iov_iter_for_each_range); 2129