1457c8996SThomas Gleixner // SPDX-License-Identifier: GPL-2.0-only 27999096fSHerbert Xu #include <crypto/hash.h> 3d879cb83SAl Viro #include <linux/export.h> 42f8b5444SChristoph Hellwig #include <linux/bvec.h> 54d0e9df5SAlbert van der Linde #include <linux/fault-inject-usercopy.h> 6d879cb83SAl Viro #include <linux/uio.h> 7d879cb83SAl Viro #include <linux/pagemap.h> 828961998SIra Weiny #include <linux/highmem.h> 9d879cb83SAl Viro #include <linux/slab.h> 10d879cb83SAl Viro #include <linux/vmalloc.h> 11241699cdSAl Viro #include <linux/splice.h> 12bfdc5970SChristoph Hellwig #include <linux/compat.h> 13d879cb83SAl Viro #include <net/checksum.h> 14d05f4435SSagi Grimberg #include <linux/scatterlist.h> 15d0ef4c36SMarco Elver #include <linux/instrumented.h> 16d879cb83SAl Viro 17241699cdSAl Viro #define PIPE_PARANOIA /* for now */ 18241699cdSAl Viro 19d879cb83SAl Viro #define iterate_iovec(i, n, __v, __p, skip, STEP) { \ 20d879cb83SAl Viro size_t left; \ 21d879cb83SAl Viro size_t wanted = n; \ 22d879cb83SAl Viro __p = i->iov; \ 23d879cb83SAl Viro __v.iov_len = min(n, __p->iov_len - skip); \ 24d879cb83SAl Viro if (likely(__v.iov_len)) { \ 25d879cb83SAl Viro __v.iov_base = __p->iov_base + skip; \ 26d879cb83SAl Viro left = (STEP); \ 27d879cb83SAl Viro __v.iov_len -= left; \ 28d879cb83SAl Viro skip += __v.iov_len; \ 29d879cb83SAl Viro n -= __v.iov_len; \ 30d879cb83SAl Viro } else { \ 31d879cb83SAl Viro left = 0; \ 32d879cb83SAl Viro } \ 33d879cb83SAl Viro while (unlikely(!left && n)) { \ 34d879cb83SAl Viro __p++; \ 35d879cb83SAl Viro __v.iov_len = min(n, __p->iov_len); \ 36d879cb83SAl Viro if (unlikely(!__v.iov_len)) \ 37d879cb83SAl Viro continue; \ 38d879cb83SAl Viro __v.iov_base = __p->iov_base; \ 39d879cb83SAl Viro left = (STEP); \ 40d879cb83SAl Viro __v.iov_len -= left; \ 41d879cb83SAl Viro skip = __v.iov_len; \ 42d879cb83SAl Viro n -= __v.iov_len; \ 43d879cb83SAl Viro } \ 44d879cb83SAl Viro n = wanted - n; \ 45d879cb83SAl Viro } 46d879cb83SAl Viro 47d879cb83SAl Viro #define iterate_kvec(i, n, __v, __p, skip, STEP) { \ 48d879cb83SAl Viro size_t wanted = n; \ 49d879cb83SAl Viro __p = i->kvec; \ 50d879cb83SAl Viro __v.iov_len = min(n, __p->iov_len - skip); \ 51d879cb83SAl Viro if (likely(__v.iov_len)) { \ 52d879cb83SAl Viro __v.iov_base = __p->iov_base + skip; \ 53d879cb83SAl Viro (void)(STEP); \ 54d879cb83SAl Viro skip += __v.iov_len; \ 55d879cb83SAl Viro n -= __v.iov_len; \ 56d879cb83SAl Viro } \ 57d879cb83SAl Viro while (unlikely(n)) { \ 58d879cb83SAl Viro __p++; \ 59d879cb83SAl Viro __v.iov_len = min(n, __p->iov_len); \ 60d879cb83SAl Viro if (unlikely(!__v.iov_len)) \ 61d879cb83SAl Viro continue; \ 62d879cb83SAl Viro __v.iov_base = __p->iov_base; \ 63d879cb83SAl Viro (void)(STEP); \ 64d879cb83SAl Viro skip = __v.iov_len; \ 65d879cb83SAl Viro n -= __v.iov_len; \ 66d879cb83SAl Viro } \ 67d879cb83SAl Viro n = wanted; \ 68d879cb83SAl Viro } 69d879cb83SAl Viro 701bdc76aeSMing Lei #define iterate_bvec(i, n, __v, __bi, skip, STEP) { \ 711bdc76aeSMing Lei struct bvec_iter __start; \ 721bdc76aeSMing Lei __start.bi_size = n; \ 731bdc76aeSMing Lei __start.bi_bvec_done = skip; \ 741bdc76aeSMing Lei __start.bi_idx = 0; \ 751bdc76aeSMing Lei for_each_bvec(__v, i->bvec, __bi, __start) { \ 76d879cb83SAl Viro (void)(STEP); \ 77d879cb83SAl Viro } \ 78d879cb83SAl Viro } 79d879cb83SAl Viro 807ff50620SDavid Howells #define iterate_xarray(i, n, __v, skip, STEP) { \ 817ff50620SDavid Howells struct page *head = NULL; \ 827ff50620SDavid Howells size_t wanted = n, seg, offset; \ 837ff50620SDavid Howells loff_t start = i->xarray_start + skip; \ 847ff50620SDavid Howells pgoff_t index = start >> PAGE_SHIFT; \ 857ff50620SDavid Howells int j; \ 867ff50620SDavid Howells \ 877ff50620SDavid Howells XA_STATE(xas, i->xarray, index); \ 887ff50620SDavid Howells \ 897ff50620SDavid Howells rcu_read_lock(); \ 907ff50620SDavid Howells xas_for_each(&xas, head, ULONG_MAX) { \ 917ff50620SDavid Howells if (xas_retry(&xas, head)) \ 927ff50620SDavid Howells continue; \ 937ff50620SDavid Howells if (WARN_ON(xa_is_value(head))) \ 947ff50620SDavid Howells break; \ 957ff50620SDavid Howells if (WARN_ON(PageHuge(head))) \ 967ff50620SDavid Howells break; \ 977ff50620SDavid Howells for (j = (head->index < index) ? index - head->index : 0; \ 987ff50620SDavid Howells j < thp_nr_pages(head); j++) { \ 997ff50620SDavid Howells __v.bv_page = head + j; \ 1007ff50620SDavid Howells offset = (i->xarray_start + skip) & ~PAGE_MASK; \ 1017ff50620SDavid Howells seg = PAGE_SIZE - offset; \ 1027ff50620SDavid Howells __v.bv_offset = offset; \ 1037ff50620SDavid Howells __v.bv_len = min(n, seg); \ 1047ff50620SDavid Howells (void)(STEP); \ 1057ff50620SDavid Howells n -= __v.bv_len; \ 1067ff50620SDavid Howells skip += __v.bv_len; \ 1077ff50620SDavid Howells if (n == 0) \ 1087ff50620SDavid Howells break; \ 1097ff50620SDavid Howells } \ 1107ff50620SDavid Howells if (n == 0) \ 1117ff50620SDavid Howells break; \ 1127ff50620SDavid Howells } \ 1137ff50620SDavid Howells rcu_read_unlock(); \ 1147ff50620SDavid Howells n = wanted - n; \ 1157ff50620SDavid Howells } 1167ff50620SDavid Howells 1177ff50620SDavid Howells #define iterate_all_kinds(i, n, v, I, B, K, X) { \ 11833844e66SAl Viro if (likely(n)) { \ 119d879cb83SAl Viro size_t skip = i->iov_offset; \ 12028f38db7SAl Viro if (likely(iter_is_iovec(i))) { \ 121d879cb83SAl Viro const struct iovec *iov; \ 122d879cb83SAl Viro struct iovec v; \ 123d879cb83SAl Viro iterate_iovec(i, n, v, iov, skip, (I)) \ 12428f38db7SAl Viro } else if (iov_iter_is_bvec(i)) { \ 12528f38db7SAl Viro struct bio_vec v; \ 12628f38db7SAl Viro struct bvec_iter __bi; \ 12728f38db7SAl Viro iterate_bvec(i, n, v, __bi, skip, (B)) \ 12828f38db7SAl Viro } else if (iov_iter_is_kvec(i)) { \ 12928f38db7SAl Viro const struct kvec *kvec; \ 13028f38db7SAl Viro struct kvec v; \ 13128f38db7SAl Viro iterate_kvec(i, n, v, kvec, skip, (K)) \ 13228f38db7SAl Viro } else if (iov_iter_is_xarray(i)) { \ 13328f38db7SAl Viro struct bio_vec v; \ 13428f38db7SAl Viro iterate_xarray(i, n, v, skip, (X)); \ 135d879cb83SAl Viro } \ 13633844e66SAl Viro } \ 137d879cb83SAl Viro } 138d879cb83SAl Viro 1397ff50620SDavid Howells #define iterate_and_advance(i, n, v, I, B, K, X) { \ 140dd254f5aSAl Viro if (unlikely(i->count < n)) \ 141dd254f5aSAl Viro n = i->count; \ 14219f18459SAl Viro if (i->count) { \ 143d879cb83SAl Viro size_t skip = i->iov_offset; \ 14428f38db7SAl Viro if (likely(iter_is_iovec(i))) { \ 145d879cb83SAl Viro const struct iovec *iov; \ 146d879cb83SAl Viro struct iovec v; \ 147d879cb83SAl Viro iterate_iovec(i, n, v, iov, skip, (I)) \ 148d879cb83SAl Viro if (skip == iov->iov_len) { \ 149d879cb83SAl Viro iov++; \ 150d879cb83SAl Viro skip = 0; \ 151d879cb83SAl Viro } \ 152d879cb83SAl Viro i->nr_segs -= iov - i->iov; \ 153d879cb83SAl Viro i->iov = iov; \ 15428f38db7SAl Viro } else if (iov_iter_is_bvec(i)) { \ 15528f38db7SAl Viro const struct bio_vec *bvec = i->bvec; \ 15628f38db7SAl Viro struct bio_vec v; \ 15728f38db7SAl Viro struct bvec_iter __bi; \ 15828f38db7SAl Viro iterate_bvec(i, n, v, __bi, skip, (B)) \ 15928f38db7SAl Viro i->bvec = __bvec_iter_bvec(i->bvec, __bi); \ 16028f38db7SAl Viro i->nr_segs -= i->bvec - bvec; \ 16128f38db7SAl Viro skip = __bi.bi_bvec_done; \ 16228f38db7SAl Viro } else if (iov_iter_is_kvec(i)) { \ 16328f38db7SAl Viro const struct kvec *kvec; \ 16428f38db7SAl Viro struct kvec v; \ 16528f38db7SAl Viro iterate_kvec(i, n, v, kvec, skip, (K)) \ 16628f38db7SAl Viro if (skip == kvec->iov_len) { \ 16728f38db7SAl Viro kvec++; \ 16828f38db7SAl Viro skip = 0; \ 16928f38db7SAl Viro } \ 17028f38db7SAl Viro i->nr_segs -= kvec - i->kvec; \ 17128f38db7SAl Viro i->kvec = kvec; \ 17228f38db7SAl Viro } else if (iov_iter_is_xarray(i)) { \ 17328f38db7SAl Viro struct bio_vec v; \ 17428f38db7SAl Viro iterate_xarray(i, n, v, skip, (X)) \ 175d879cb83SAl Viro } \ 176d879cb83SAl Viro i->count -= n; \ 177d879cb83SAl Viro i->iov_offset = skip; \ 178dd254f5aSAl Viro } \ 179d879cb83SAl Viro } 180d879cb83SAl Viro 18109fc68dcSAl Viro static int copyout(void __user *to, const void *from, size_t n) 18209fc68dcSAl Viro { 1834d0e9df5SAlbert van der Linde if (should_fail_usercopy()) 1844d0e9df5SAlbert van der Linde return n; 18596d4f267SLinus Torvalds if (access_ok(to, n)) { 186d0ef4c36SMarco Elver instrument_copy_to_user(to, from, n); 18709fc68dcSAl Viro n = raw_copy_to_user(to, from, n); 18809fc68dcSAl Viro } 18909fc68dcSAl Viro return n; 19009fc68dcSAl Viro } 19109fc68dcSAl Viro 19209fc68dcSAl Viro static int copyin(void *to, const void __user *from, size_t n) 19309fc68dcSAl Viro { 1944d0e9df5SAlbert van der Linde if (should_fail_usercopy()) 1954d0e9df5SAlbert van der Linde return n; 19696d4f267SLinus Torvalds if (access_ok(from, n)) { 197d0ef4c36SMarco Elver instrument_copy_from_user(to, from, n); 19809fc68dcSAl Viro n = raw_copy_from_user(to, from, n); 19909fc68dcSAl Viro } 20009fc68dcSAl Viro return n; 20109fc68dcSAl Viro } 20209fc68dcSAl Viro 203d879cb83SAl Viro static size_t copy_page_to_iter_iovec(struct page *page, size_t offset, size_t bytes, 204d879cb83SAl Viro struct iov_iter *i) 205d879cb83SAl Viro { 206d879cb83SAl Viro size_t skip, copy, left, wanted; 207d879cb83SAl Viro const struct iovec *iov; 208d879cb83SAl Viro char __user *buf; 209d879cb83SAl Viro void *kaddr, *from; 210d879cb83SAl Viro 211d879cb83SAl Viro if (unlikely(bytes > i->count)) 212d879cb83SAl Viro bytes = i->count; 213d879cb83SAl Viro 214d879cb83SAl Viro if (unlikely(!bytes)) 215d879cb83SAl Viro return 0; 216d879cb83SAl Viro 21709fc68dcSAl Viro might_fault(); 218d879cb83SAl Viro wanted = bytes; 219d879cb83SAl Viro iov = i->iov; 220d879cb83SAl Viro skip = i->iov_offset; 221d879cb83SAl Viro buf = iov->iov_base + skip; 222d879cb83SAl Viro copy = min(bytes, iov->iov_len - skip); 223d879cb83SAl Viro 2243fa6c507SMikulas Patocka if (IS_ENABLED(CONFIG_HIGHMEM) && !fault_in_pages_writeable(buf, copy)) { 225d879cb83SAl Viro kaddr = kmap_atomic(page); 226d879cb83SAl Viro from = kaddr + offset; 227d879cb83SAl Viro 228d879cb83SAl Viro /* first chunk, usually the only one */ 22909fc68dcSAl Viro left = copyout(buf, from, copy); 230d879cb83SAl Viro copy -= left; 231d879cb83SAl Viro skip += copy; 232d879cb83SAl Viro from += copy; 233d879cb83SAl Viro bytes -= copy; 234d879cb83SAl Viro 235d879cb83SAl Viro while (unlikely(!left && bytes)) { 236d879cb83SAl Viro iov++; 237d879cb83SAl Viro buf = iov->iov_base; 238d879cb83SAl Viro copy = min(bytes, iov->iov_len); 23909fc68dcSAl Viro left = copyout(buf, from, copy); 240d879cb83SAl Viro copy -= left; 241d879cb83SAl Viro skip = copy; 242d879cb83SAl Viro from += copy; 243d879cb83SAl Viro bytes -= copy; 244d879cb83SAl Viro } 245d879cb83SAl Viro if (likely(!bytes)) { 246d879cb83SAl Viro kunmap_atomic(kaddr); 247d879cb83SAl Viro goto done; 248d879cb83SAl Viro } 249d879cb83SAl Viro offset = from - kaddr; 250d879cb83SAl Viro buf += copy; 251d879cb83SAl Viro kunmap_atomic(kaddr); 252d879cb83SAl Viro copy = min(bytes, iov->iov_len - skip); 253d879cb83SAl Viro } 254d879cb83SAl Viro /* Too bad - revert to non-atomic kmap */ 2553fa6c507SMikulas Patocka 256d879cb83SAl Viro kaddr = kmap(page); 257d879cb83SAl Viro from = kaddr + offset; 25809fc68dcSAl Viro left = copyout(buf, from, copy); 259d879cb83SAl Viro copy -= left; 260d879cb83SAl Viro skip += copy; 261d879cb83SAl Viro from += copy; 262d879cb83SAl Viro bytes -= copy; 263d879cb83SAl Viro while (unlikely(!left && bytes)) { 264d879cb83SAl Viro iov++; 265d879cb83SAl Viro buf = iov->iov_base; 266d879cb83SAl Viro copy = min(bytes, iov->iov_len); 26709fc68dcSAl Viro left = copyout(buf, from, copy); 268d879cb83SAl Viro copy -= left; 269d879cb83SAl Viro skip = copy; 270d879cb83SAl Viro from += copy; 271d879cb83SAl Viro bytes -= copy; 272d879cb83SAl Viro } 273d879cb83SAl Viro kunmap(page); 2743fa6c507SMikulas Patocka 275d879cb83SAl Viro done: 276d879cb83SAl Viro if (skip == iov->iov_len) { 277d879cb83SAl Viro iov++; 278d879cb83SAl Viro skip = 0; 279d879cb83SAl Viro } 280d879cb83SAl Viro i->count -= wanted - bytes; 281d879cb83SAl Viro i->nr_segs -= iov - i->iov; 282d879cb83SAl Viro i->iov = iov; 283d879cb83SAl Viro i->iov_offset = skip; 284d879cb83SAl Viro return wanted - bytes; 285d879cb83SAl Viro } 286d879cb83SAl Viro 287d879cb83SAl Viro static size_t copy_page_from_iter_iovec(struct page *page, size_t offset, size_t bytes, 288d879cb83SAl Viro struct iov_iter *i) 289d879cb83SAl Viro { 290d879cb83SAl Viro size_t skip, copy, left, wanted; 291d879cb83SAl Viro const struct iovec *iov; 292d879cb83SAl Viro char __user *buf; 293d879cb83SAl Viro void *kaddr, *to; 294d879cb83SAl Viro 295d879cb83SAl Viro if (unlikely(bytes > i->count)) 296d879cb83SAl Viro bytes = i->count; 297d879cb83SAl Viro 298d879cb83SAl Viro if (unlikely(!bytes)) 299d879cb83SAl Viro return 0; 300d879cb83SAl Viro 30109fc68dcSAl Viro might_fault(); 302d879cb83SAl Viro wanted = bytes; 303d879cb83SAl Viro iov = i->iov; 304d879cb83SAl Viro skip = i->iov_offset; 305d879cb83SAl Viro buf = iov->iov_base + skip; 306d879cb83SAl Viro copy = min(bytes, iov->iov_len - skip); 307d879cb83SAl Viro 3083fa6c507SMikulas Patocka if (IS_ENABLED(CONFIG_HIGHMEM) && !fault_in_pages_readable(buf, copy)) { 309d879cb83SAl Viro kaddr = kmap_atomic(page); 310d879cb83SAl Viro to = kaddr + offset; 311d879cb83SAl Viro 312d879cb83SAl Viro /* first chunk, usually the only one */ 31309fc68dcSAl Viro left = copyin(to, buf, copy); 314d879cb83SAl Viro copy -= left; 315d879cb83SAl Viro skip += copy; 316d879cb83SAl Viro to += copy; 317d879cb83SAl Viro bytes -= copy; 318d879cb83SAl Viro 319d879cb83SAl Viro while (unlikely(!left && bytes)) { 320d879cb83SAl Viro iov++; 321d879cb83SAl Viro buf = iov->iov_base; 322d879cb83SAl Viro copy = min(bytes, iov->iov_len); 32309fc68dcSAl Viro left = copyin(to, buf, copy); 324d879cb83SAl Viro copy -= left; 325d879cb83SAl Viro skip = copy; 326d879cb83SAl Viro to += copy; 327d879cb83SAl Viro bytes -= copy; 328d879cb83SAl Viro } 329d879cb83SAl Viro if (likely(!bytes)) { 330d879cb83SAl Viro kunmap_atomic(kaddr); 331d879cb83SAl Viro goto done; 332d879cb83SAl Viro } 333d879cb83SAl Viro offset = to - kaddr; 334d879cb83SAl Viro buf += copy; 335d879cb83SAl Viro kunmap_atomic(kaddr); 336d879cb83SAl Viro copy = min(bytes, iov->iov_len - skip); 337d879cb83SAl Viro } 338d879cb83SAl Viro /* Too bad - revert to non-atomic kmap */ 3393fa6c507SMikulas Patocka 340d879cb83SAl Viro kaddr = kmap(page); 341d879cb83SAl Viro to = kaddr + offset; 34209fc68dcSAl Viro left = copyin(to, buf, copy); 343d879cb83SAl Viro copy -= left; 344d879cb83SAl Viro skip += copy; 345d879cb83SAl Viro to += copy; 346d879cb83SAl Viro bytes -= copy; 347d879cb83SAl Viro while (unlikely(!left && bytes)) { 348d879cb83SAl Viro iov++; 349d879cb83SAl Viro buf = iov->iov_base; 350d879cb83SAl Viro copy = min(bytes, iov->iov_len); 35109fc68dcSAl Viro left = copyin(to, buf, copy); 352d879cb83SAl Viro copy -= left; 353d879cb83SAl Viro skip = copy; 354d879cb83SAl Viro to += copy; 355d879cb83SAl Viro bytes -= copy; 356d879cb83SAl Viro } 357d879cb83SAl Viro kunmap(page); 3583fa6c507SMikulas Patocka 359d879cb83SAl Viro done: 360d879cb83SAl Viro if (skip == iov->iov_len) { 361d879cb83SAl Viro iov++; 362d879cb83SAl Viro skip = 0; 363d879cb83SAl Viro } 364d879cb83SAl Viro i->count -= wanted - bytes; 365d879cb83SAl Viro i->nr_segs -= iov - i->iov; 366d879cb83SAl Viro i->iov = iov; 367d879cb83SAl Viro i->iov_offset = skip; 368d879cb83SAl Viro return wanted - bytes; 369d879cb83SAl Viro } 370d879cb83SAl Viro 371241699cdSAl Viro #ifdef PIPE_PARANOIA 372241699cdSAl Viro static bool sanity(const struct iov_iter *i) 373241699cdSAl Viro { 374241699cdSAl Viro struct pipe_inode_info *pipe = i->pipe; 3758cefc107SDavid Howells unsigned int p_head = pipe->head; 3768cefc107SDavid Howells unsigned int p_tail = pipe->tail; 3778cefc107SDavid Howells unsigned int p_mask = pipe->ring_size - 1; 3788cefc107SDavid Howells unsigned int p_occupancy = pipe_occupancy(p_head, p_tail); 3798cefc107SDavid Howells unsigned int i_head = i->head; 3808cefc107SDavid Howells unsigned int idx; 3818cefc107SDavid Howells 382241699cdSAl Viro if (i->iov_offset) { 383241699cdSAl Viro struct pipe_buffer *p; 3848cefc107SDavid Howells if (unlikely(p_occupancy == 0)) 385241699cdSAl Viro goto Bad; // pipe must be non-empty 3868cefc107SDavid Howells if (unlikely(i_head != p_head - 1)) 387241699cdSAl Viro goto Bad; // must be at the last buffer... 388241699cdSAl Viro 3898cefc107SDavid Howells p = &pipe->bufs[i_head & p_mask]; 390241699cdSAl Viro if (unlikely(p->offset + p->len != i->iov_offset)) 391241699cdSAl Viro goto Bad; // ... at the end of segment 392241699cdSAl Viro } else { 3938cefc107SDavid Howells if (i_head != p_head) 394241699cdSAl Viro goto Bad; // must be right after the last buffer 395241699cdSAl Viro } 396241699cdSAl Viro return true; 397241699cdSAl Viro Bad: 3988cefc107SDavid Howells printk(KERN_ERR "idx = %d, offset = %zd\n", i_head, i->iov_offset); 3998cefc107SDavid Howells printk(KERN_ERR "head = %d, tail = %d, buffers = %d\n", 4008cefc107SDavid Howells p_head, p_tail, pipe->ring_size); 4018cefc107SDavid Howells for (idx = 0; idx < pipe->ring_size; idx++) 402241699cdSAl Viro printk(KERN_ERR "[%p %p %d %d]\n", 403241699cdSAl Viro pipe->bufs[idx].ops, 404241699cdSAl Viro pipe->bufs[idx].page, 405241699cdSAl Viro pipe->bufs[idx].offset, 406241699cdSAl Viro pipe->bufs[idx].len); 407241699cdSAl Viro WARN_ON(1); 408241699cdSAl Viro return false; 409241699cdSAl Viro } 410241699cdSAl Viro #else 411241699cdSAl Viro #define sanity(i) true 412241699cdSAl Viro #endif 413241699cdSAl Viro 414241699cdSAl Viro static size_t copy_page_to_iter_pipe(struct page *page, size_t offset, size_t bytes, 415241699cdSAl Viro struct iov_iter *i) 416241699cdSAl Viro { 417241699cdSAl Viro struct pipe_inode_info *pipe = i->pipe; 418241699cdSAl Viro struct pipe_buffer *buf; 4198cefc107SDavid Howells unsigned int p_tail = pipe->tail; 4208cefc107SDavid Howells unsigned int p_mask = pipe->ring_size - 1; 4218cefc107SDavid Howells unsigned int i_head = i->head; 422241699cdSAl Viro size_t off; 423241699cdSAl Viro 424241699cdSAl Viro if (unlikely(bytes > i->count)) 425241699cdSAl Viro bytes = i->count; 426241699cdSAl Viro 427241699cdSAl Viro if (unlikely(!bytes)) 428241699cdSAl Viro return 0; 429241699cdSAl Viro 430241699cdSAl Viro if (!sanity(i)) 431241699cdSAl Viro return 0; 432241699cdSAl Viro 433241699cdSAl Viro off = i->iov_offset; 4348cefc107SDavid Howells buf = &pipe->bufs[i_head & p_mask]; 435241699cdSAl Viro if (off) { 436241699cdSAl Viro if (offset == off && buf->page == page) { 437241699cdSAl Viro /* merge with the last one */ 438241699cdSAl Viro buf->len += bytes; 439241699cdSAl Viro i->iov_offset += bytes; 440241699cdSAl Viro goto out; 441241699cdSAl Viro } 4428cefc107SDavid Howells i_head++; 4438cefc107SDavid Howells buf = &pipe->bufs[i_head & p_mask]; 444241699cdSAl Viro } 4456718b6f8SDavid Howells if (pipe_full(i_head, p_tail, pipe->max_usage)) 446241699cdSAl Viro return 0; 4478cefc107SDavid Howells 448241699cdSAl Viro buf->ops = &page_cache_pipe_buf_ops; 4498cefc107SDavid Howells get_page(page); 4508cefc107SDavid Howells buf->page = page; 451241699cdSAl Viro buf->offset = offset; 452241699cdSAl Viro buf->len = bytes; 4538cefc107SDavid Howells 4548cefc107SDavid Howells pipe->head = i_head + 1; 455241699cdSAl Viro i->iov_offset = offset + bytes; 4568cefc107SDavid Howells i->head = i_head; 457241699cdSAl Viro out: 458241699cdSAl Viro i->count -= bytes; 459241699cdSAl Viro return bytes; 460241699cdSAl Viro } 461241699cdSAl Viro 462d879cb83SAl Viro /* 463171a0203SAnton Altaparmakov * Fault in one or more iovecs of the given iov_iter, to a maximum length of 464171a0203SAnton Altaparmakov * bytes. For each iovec, fault in each page that constitutes the iovec. 465171a0203SAnton Altaparmakov * 466171a0203SAnton Altaparmakov * Return 0 on success, or non-zero if the memory could not be accessed (i.e. 467171a0203SAnton Altaparmakov * because it is an invalid address). 468171a0203SAnton Altaparmakov */ 4698409a0d2SAl Viro int iov_iter_fault_in_readable(const struct iov_iter *i, size_t bytes) 470171a0203SAnton Altaparmakov { 4710e8f0d67SAl Viro if (iter_is_iovec(i)) { 4728409a0d2SAl Viro const struct iovec *p; 4738409a0d2SAl Viro size_t skip; 4748409a0d2SAl Viro 4758409a0d2SAl Viro if (bytes > i->count) 4768409a0d2SAl Viro bytes = i->count; 4778409a0d2SAl Viro for (p = i->iov, skip = i->iov_offset; bytes; p++, skip = 0) { 4788409a0d2SAl Viro size_t len = min(bytes, p->iov_len - skip); 4798409a0d2SAl Viro int err; 4808409a0d2SAl Viro 4818409a0d2SAl Viro if (unlikely(!len)) 4828409a0d2SAl Viro continue; 4838409a0d2SAl Viro err = fault_in_pages_readable(p->iov_base + skip, len); 484171a0203SAnton Altaparmakov if (unlikely(err)) 485171a0203SAnton Altaparmakov return err; 4868409a0d2SAl Viro bytes -= len; 4878409a0d2SAl Viro } 488171a0203SAnton Altaparmakov } 489171a0203SAnton Altaparmakov return 0; 490171a0203SAnton Altaparmakov } 491d4690f1eSAl Viro EXPORT_SYMBOL(iov_iter_fault_in_readable); 492171a0203SAnton Altaparmakov 493aa563d7bSDavid Howells void iov_iter_init(struct iov_iter *i, unsigned int direction, 494d879cb83SAl Viro const struct iovec *iov, unsigned long nr_segs, 495d879cb83SAl Viro size_t count) 496d879cb83SAl Viro { 497aa563d7bSDavid Howells WARN_ON(direction & ~(READ | WRITE)); 4988cd54c1cSAl Viro WARN_ON_ONCE(uaccess_kernel()); 4998cd54c1cSAl Viro *i = (struct iov_iter) { 5008cd54c1cSAl Viro .iter_type = ITER_IOVEC, 5018cd54c1cSAl Viro .data_source = direction, 5028cd54c1cSAl Viro .iov = iov, 5038cd54c1cSAl Viro .nr_segs = nr_segs, 5048cd54c1cSAl Viro .iov_offset = 0, 5058cd54c1cSAl Viro .count = count 5068cd54c1cSAl Viro }; 507d879cb83SAl Viro } 508d879cb83SAl Viro EXPORT_SYMBOL(iov_iter_init); 509d879cb83SAl Viro 510241699cdSAl Viro static inline bool allocated(struct pipe_buffer *buf) 511241699cdSAl Viro { 512241699cdSAl Viro return buf->ops == &default_pipe_buf_ops; 513241699cdSAl Viro } 514241699cdSAl Viro 5158cefc107SDavid Howells static inline void data_start(const struct iov_iter *i, 5168cefc107SDavid Howells unsigned int *iter_headp, size_t *offp) 517241699cdSAl Viro { 5188cefc107SDavid Howells unsigned int p_mask = i->pipe->ring_size - 1; 5198cefc107SDavid Howells unsigned int iter_head = i->head; 520241699cdSAl Viro size_t off = i->iov_offset; 5218cefc107SDavid Howells 5228cefc107SDavid Howells if (off && (!allocated(&i->pipe->bufs[iter_head & p_mask]) || 5238cefc107SDavid Howells off == PAGE_SIZE)) { 5248cefc107SDavid Howells iter_head++; 525241699cdSAl Viro off = 0; 526241699cdSAl Viro } 5278cefc107SDavid Howells *iter_headp = iter_head; 528241699cdSAl Viro *offp = off; 529241699cdSAl Viro } 530241699cdSAl Viro 531241699cdSAl Viro static size_t push_pipe(struct iov_iter *i, size_t size, 5328cefc107SDavid Howells int *iter_headp, size_t *offp) 533241699cdSAl Viro { 534241699cdSAl Viro struct pipe_inode_info *pipe = i->pipe; 5358cefc107SDavid Howells unsigned int p_tail = pipe->tail; 5368cefc107SDavid Howells unsigned int p_mask = pipe->ring_size - 1; 5378cefc107SDavid Howells unsigned int iter_head; 538241699cdSAl Viro size_t off; 539241699cdSAl Viro ssize_t left; 540241699cdSAl Viro 541241699cdSAl Viro if (unlikely(size > i->count)) 542241699cdSAl Viro size = i->count; 543241699cdSAl Viro if (unlikely(!size)) 544241699cdSAl Viro return 0; 545241699cdSAl Viro 546241699cdSAl Viro left = size; 5478cefc107SDavid Howells data_start(i, &iter_head, &off); 5488cefc107SDavid Howells *iter_headp = iter_head; 549241699cdSAl Viro *offp = off; 550241699cdSAl Viro if (off) { 551241699cdSAl Viro left -= PAGE_SIZE - off; 552241699cdSAl Viro if (left <= 0) { 5538cefc107SDavid Howells pipe->bufs[iter_head & p_mask].len += size; 554241699cdSAl Viro return size; 555241699cdSAl Viro } 5568cefc107SDavid Howells pipe->bufs[iter_head & p_mask].len = PAGE_SIZE; 5578cefc107SDavid Howells iter_head++; 558241699cdSAl Viro } 5596718b6f8SDavid Howells while (!pipe_full(iter_head, p_tail, pipe->max_usage)) { 5608cefc107SDavid Howells struct pipe_buffer *buf = &pipe->bufs[iter_head & p_mask]; 561241699cdSAl Viro struct page *page = alloc_page(GFP_USER); 562241699cdSAl Viro if (!page) 563241699cdSAl Viro break; 5648cefc107SDavid Howells 5658cefc107SDavid Howells buf->ops = &default_pipe_buf_ops; 5668cefc107SDavid Howells buf->page = page; 5678cefc107SDavid Howells buf->offset = 0; 5688cefc107SDavid Howells buf->len = min_t(ssize_t, left, PAGE_SIZE); 5698cefc107SDavid Howells left -= buf->len; 5708cefc107SDavid Howells iter_head++; 5718cefc107SDavid Howells pipe->head = iter_head; 5728cefc107SDavid Howells 5738cefc107SDavid Howells if (left == 0) 574241699cdSAl Viro return size; 575241699cdSAl Viro } 576241699cdSAl Viro return size - left; 577241699cdSAl Viro } 578241699cdSAl Viro 579241699cdSAl Viro static size_t copy_pipe_to_iter(const void *addr, size_t bytes, 580241699cdSAl Viro struct iov_iter *i) 581241699cdSAl Viro { 582241699cdSAl Viro struct pipe_inode_info *pipe = i->pipe; 5838cefc107SDavid Howells unsigned int p_mask = pipe->ring_size - 1; 5848cefc107SDavid Howells unsigned int i_head; 585241699cdSAl Viro size_t n, off; 586241699cdSAl Viro 587241699cdSAl Viro if (!sanity(i)) 588241699cdSAl Viro return 0; 589241699cdSAl Viro 5908cefc107SDavid Howells bytes = n = push_pipe(i, bytes, &i_head, &off); 591241699cdSAl Viro if (unlikely(!n)) 592241699cdSAl Viro return 0; 5938cefc107SDavid Howells do { 594241699cdSAl Viro size_t chunk = min_t(size_t, n, PAGE_SIZE - off); 5958cefc107SDavid Howells memcpy_to_page(pipe->bufs[i_head & p_mask].page, off, addr, chunk); 5968cefc107SDavid Howells i->head = i_head; 597241699cdSAl Viro i->iov_offset = off + chunk; 598241699cdSAl Viro n -= chunk; 599241699cdSAl Viro addr += chunk; 6008cefc107SDavid Howells off = 0; 6018cefc107SDavid Howells i_head++; 6028cefc107SDavid Howells } while (n); 603241699cdSAl Viro i->count -= bytes; 604241699cdSAl Viro return bytes; 605241699cdSAl Viro } 606241699cdSAl Viro 607f9152895SAl Viro static __wsum csum_and_memcpy(void *to, const void *from, size_t len, 608f9152895SAl Viro __wsum sum, size_t off) 609f9152895SAl Viro { 610cc44c17bSAl Viro __wsum next = csum_partial_copy_nocheck(from, to, len); 611f9152895SAl Viro return csum_block_add(sum, next, off); 612f9152895SAl Viro } 613f9152895SAl Viro 61478e1f386SAl Viro static size_t csum_and_copy_to_pipe_iter(const void *addr, size_t bytes, 61552cbd23aSWillem de Bruijn struct csum_state *csstate, 61652cbd23aSWillem de Bruijn struct iov_iter *i) 61778e1f386SAl Viro { 61878e1f386SAl Viro struct pipe_inode_info *pipe = i->pipe; 6198cefc107SDavid Howells unsigned int p_mask = pipe->ring_size - 1; 62052cbd23aSWillem de Bruijn __wsum sum = csstate->csum; 62152cbd23aSWillem de Bruijn size_t off = csstate->off; 6228cefc107SDavid Howells unsigned int i_head; 62378e1f386SAl Viro size_t n, r; 62478e1f386SAl Viro 62578e1f386SAl Viro if (!sanity(i)) 62678e1f386SAl Viro return 0; 62778e1f386SAl Viro 6288cefc107SDavid Howells bytes = n = push_pipe(i, bytes, &i_head, &r); 62978e1f386SAl Viro if (unlikely(!n)) 63078e1f386SAl Viro return 0; 6318cefc107SDavid Howells do { 63278e1f386SAl Viro size_t chunk = min_t(size_t, n, PAGE_SIZE - r); 6338cefc107SDavid Howells char *p = kmap_atomic(pipe->bufs[i_head & p_mask].page); 634f9152895SAl Viro sum = csum_and_memcpy(p + r, addr, chunk, sum, off); 63578e1f386SAl Viro kunmap_atomic(p); 6368cefc107SDavid Howells i->head = i_head; 63778e1f386SAl Viro i->iov_offset = r + chunk; 63878e1f386SAl Viro n -= chunk; 63978e1f386SAl Viro off += chunk; 64078e1f386SAl Viro addr += chunk; 6418cefc107SDavid Howells r = 0; 6428cefc107SDavid Howells i_head++; 6438cefc107SDavid Howells } while (n); 64478e1f386SAl Viro i->count -= bytes; 64552cbd23aSWillem de Bruijn csstate->csum = sum; 64652cbd23aSWillem de Bruijn csstate->off = off; 64778e1f386SAl Viro return bytes; 64878e1f386SAl Viro } 64978e1f386SAl Viro 650aa28de27SAl Viro size_t _copy_to_iter(const void *addr, size_t bytes, struct iov_iter *i) 651d879cb83SAl Viro { 65236f7a8a4SAl Viro const char *from = addr; 65300e23707SDavid Howells if (unlikely(iov_iter_is_pipe(i))) 654241699cdSAl Viro return copy_pipe_to_iter(addr, bytes, i); 65509fc68dcSAl Viro if (iter_is_iovec(i)) 65609fc68dcSAl Viro might_fault(); 657d879cb83SAl Viro iterate_and_advance(i, bytes, v, 65809fc68dcSAl Viro copyout(v.iov_base, (from += v.iov_len) - v.iov_len, v.iov_len), 659d879cb83SAl Viro memcpy_to_page(v.bv_page, v.bv_offset, 660d879cb83SAl Viro (from += v.bv_len) - v.bv_len, v.bv_len), 6617ff50620SDavid Howells memcpy(v.iov_base, (from += v.iov_len) - v.iov_len, v.iov_len), 6627ff50620SDavid Howells memcpy_to_page(v.bv_page, v.bv_offset, 6637ff50620SDavid Howells (from += v.bv_len) - v.bv_len, v.bv_len) 664d879cb83SAl Viro ) 665d879cb83SAl Viro 666d879cb83SAl Viro return bytes; 667d879cb83SAl Viro } 668aa28de27SAl Viro EXPORT_SYMBOL(_copy_to_iter); 669d879cb83SAl Viro 670ec6347bbSDan Williams #ifdef CONFIG_ARCH_HAS_COPY_MC 671ec6347bbSDan Williams static int copyout_mc(void __user *to, const void *from, size_t n) 6728780356eSDan Williams { 67396d4f267SLinus Torvalds if (access_ok(to, n)) { 674d0ef4c36SMarco Elver instrument_copy_to_user(to, from, n); 675ec6347bbSDan Williams n = copy_mc_to_user((__force void *) to, from, n); 6768780356eSDan Williams } 6778780356eSDan Williams return n; 6788780356eSDan Williams } 6798780356eSDan Williams 680ec6347bbSDan Williams static unsigned long copy_mc_to_page(struct page *page, size_t offset, 6818780356eSDan Williams const char *from, size_t len) 6828780356eSDan Williams { 6838780356eSDan Williams unsigned long ret; 6848780356eSDan Williams char *to; 6858780356eSDan Williams 6868780356eSDan Williams to = kmap_atomic(page); 687ec6347bbSDan Williams ret = copy_mc_to_kernel(to + offset, from, len); 6888780356eSDan Williams kunmap_atomic(to); 6898780356eSDan Williams 6908780356eSDan Williams return ret; 6918780356eSDan Williams } 6928780356eSDan Williams 693ec6347bbSDan Williams static size_t copy_mc_pipe_to_iter(const void *addr, size_t bytes, 694ca146f6fSDan Williams struct iov_iter *i) 695ca146f6fSDan Williams { 696ca146f6fSDan Williams struct pipe_inode_info *pipe = i->pipe; 6978cefc107SDavid Howells unsigned int p_mask = pipe->ring_size - 1; 6988cefc107SDavid Howells unsigned int i_head; 699ca146f6fSDan Williams size_t n, off, xfer = 0; 700ca146f6fSDan Williams 701ca146f6fSDan Williams if (!sanity(i)) 702ca146f6fSDan Williams return 0; 703ca146f6fSDan Williams 7048cefc107SDavid Howells bytes = n = push_pipe(i, bytes, &i_head, &off); 705ca146f6fSDan Williams if (unlikely(!n)) 706ca146f6fSDan Williams return 0; 7078cefc107SDavid Howells do { 708ca146f6fSDan Williams size_t chunk = min_t(size_t, n, PAGE_SIZE - off); 709ca146f6fSDan Williams unsigned long rem; 710ca146f6fSDan Williams 711ec6347bbSDan Williams rem = copy_mc_to_page(pipe->bufs[i_head & p_mask].page, 7128cefc107SDavid Howells off, addr, chunk); 7138cefc107SDavid Howells i->head = i_head; 714ca146f6fSDan Williams i->iov_offset = off + chunk - rem; 715ca146f6fSDan Williams xfer += chunk - rem; 716ca146f6fSDan Williams if (rem) 717ca146f6fSDan Williams break; 718ca146f6fSDan Williams n -= chunk; 719ca146f6fSDan Williams addr += chunk; 7208cefc107SDavid Howells off = 0; 7218cefc107SDavid Howells i_head++; 7228cefc107SDavid Howells } while (n); 723ca146f6fSDan Williams i->count -= xfer; 724ca146f6fSDan Williams return xfer; 725ca146f6fSDan Williams } 726ca146f6fSDan Williams 727bf3eeb9bSDan Williams /** 728ec6347bbSDan Williams * _copy_mc_to_iter - copy to iter with source memory error exception handling 729bf3eeb9bSDan Williams * @addr: source kernel address 730bf3eeb9bSDan Williams * @bytes: total transfer length 731bf3eeb9bSDan Williams * @iter: destination iterator 732bf3eeb9bSDan Williams * 733ec6347bbSDan Williams * The pmem driver deploys this for the dax operation 734ec6347bbSDan Williams * (dax_copy_to_iter()) for dax reads (bypass page-cache and the 735ec6347bbSDan Williams * block-layer). Upon #MC read(2) aborts and returns EIO or the bytes 736ec6347bbSDan Williams * successfully copied. 737bf3eeb9bSDan Williams * 738ec6347bbSDan Williams * The main differences between this and typical _copy_to_iter(). 739bf3eeb9bSDan Williams * 740bf3eeb9bSDan Williams * * Typical tail/residue handling after a fault retries the copy 741bf3eeb9bSDan Williams * byte-by-byte until the fault happens again. Re-triggering machine 742bf3eeb9bSDan Williams * checks is potentially fatal so the implementation uses source 743bf3eeb9bSDan Williams * alignment and poison alignment assumptions to avoid re-triggering 744bf3eeb9bSDan Williams * hardware exceptions. 745bf3eeb9bSDan Williams * 746bf3eeb9bSDan Williams * * ITER_KVEC, ITER_PIPE, and ITER_BVEC can return short copies. 747bf3eeb9bSDan Williams * Compare to copy_to_iter() where only ITER_IOVEC attempts might return 748bf3eeb9bSDan Williams * a short copy. 749bf3eeb9bSDan Williams */ 750ec6347bbSDan Williams size_t _copy_mc_to_iter(const void *addr, size_t bytes, struct iov_iter *i) 7518780356eSDan Williams { 7528780356eSDan Williams const char *from = addr; 7538780356eSDan Williams unsigned long rem, curr_addr, s_addr = (unsigned long) addr; 7548780356eSDan Williams 75500e23707SDavid Howells if (unlikely(iov_iter_is_pipe(i))) 756ec6347bbSDan Williams return copy_mc_pipe_to_iter(addr, bytes, i); 7578780356eSDan Williams if (iter_is_iovec(i)) 7588780356eSDan Williams might_fault(); 7598780356eSDan Williams iterate_and_advance(i, bytes, v, 760ec6347bbSDan Williams copyout_mc(v.iov_base, (from += v.iov_len) - v.iov_len, 761ec6347bbSDan Williams v.iov_len), 7628780356eSDan Williams ({ 763ec6347bbSDan Williams rem = copy_mc_to_page(v.bv_page, v.bv_offset, 7648780356eSDan Williams (from += v.bv_len) - v.bv_len, v.bv_len); 7658780356eSDan Williams if (rem) { 7668780356eSDan Williams curr_addr = (unsigned long) from; 7678780356eSDan Williams bytes = curr_addr - s_addr - rem; 7688780356eSDan Williams return bytes; 7698780356eSDan Williams } 7708780356eSDan Williams }), 7718780356eSDan Williams ({ 772ec6347bbSDan Williams rem = copy_mc_to_kernel(v.iov_base, (from += v.iov_len) 773ec6347bbSDan Williams - v.iov_len, v.iov_len); 7748780356eSDan Williams if (rem) { 7758780356eSDan Williams curr_addr = (unsigned long) from; 7768780356eSDan Williams bytes = curr_addr - s_addr - rem; 7778780356eSDan Williams return bytes; 7788780356eSDan Williams } 7797ff50620SDavid Howells }), 7807ff50620SDavid Howells ({ 7817ff50620SDavid Howells rem = copy_mc_to_page(v.bv_page, v.bv_offset, 7827ff50620SDavid Howells (from += v.bv_len) - v.bv_len, v.bv_len); 7837ff50620SDavid Howells if (rem) { 7847ff50620SDavid Howells curr_addr = (unsigned long) from; 7857ff50620SDavid Howells bytes = curr_addr - s_addr - rem; 7867ff50620SDavid Howells rcu_read_unlock(); 7873d14ec1fSDavid Howells i->iov_offset += bytes; 7883d14ec1fSDavid Howells i->count -= bytes; 7897ff50620SDavid Howells return bytes; 7907ff50620SDavid Howells } 7918780356eSDan Williams }) 7928780356eSDan Williams ) 7938780356eSDan Williams 7948780356eSDan Williams return bytes; 7958780356eSDan Williams } 796ec6347bbSDan Williams EXPORT_SYMBOL_GPL(_copy_mc_to_iter); 797ec6347bbSDan Williams #endif /* CONFIG_ARCH_HAS_COPY_MC */ 7988780356eSDan Williams 799aa28de27SAl Viro size_t _copy_from_iter(void *addr, size_t bytes, struct iov_iter *i) 800d879cb83SAl Viro { 801d879cb83SAl Viro char *to = addr; 80200e23707SDavid Howells if (unlikely(iov_iter_is_pipe(i))) { 803241699cdSAl Viro WARN_ON(1); 804241699cdSAl Viro return 0; 805241699cdSAl Viro } 80609fc68dcSAl Viro if (iter_is_iovec(i)) 80709fc68dcSAl Viro might_fault(); 808d879cb83SAl Viro iterate_and_advance(i, bytes, v, 80909fc68dcSAl Viro copyin((to += v.iov_len) - v.iov_len, v.iov_base, v.iov_len), 810d879cb83SAl Viro memcpy_from_page((to += v.bv_len) - v.bv_len, v.bv_page, 811d879cb83SAl Viro v.bv_offset, v.bv_len), 8127ff50620SDavid Howells memcpy((to += v.iov_len) - v.iov_len, v.iov_base, v.iov_len), 8137ff50620SDavid Howells memcpy_from_page((to += v.bv_len) - v.bv_len, v.bv_page, 8147ff50620SDavid Howells v.bv_offset, v.bv_len) 815d879cb83SAl Viro ) 816d879cb83SAl Viro 817d879cb83SAl Viro return bytes; 818d879cb83SAl Viro } 819aa28de27SAl Viro EXPORT_SYMBOL(_copy_from_iter); 820d879cb83SAl Viro 821aa28de27SAl Viro size_t _copy_from_iter_nocache(void *addr, size_t bytes, struct iov_iter *i) 822d879cb83SAl Viro { 823d879cb83SAl Viro char *to = addr; 82400e23707SDavid Howells if (unlikely(iov_iter_is_pipe(i))) { 825241699cdSAl Viro WARN_ON(1); 826241699cdSAl Viro return 0; 827241699cdSAl Viro } 828d879cb83SAl Viro iterate_and_advance(i, bytes, v, 8293f763453SAl Viro __copy_from_user_inatomic_nocache((to += v.iov_len) - v.iov_len, 830d879cb83SAl Viro v.iov_base, v.iov_len), 831d879cb83SAl Viro memcpy_from_page((to += v.bv_len) - v.bv_len, v.bv_page, 832d879cb83SAl Viro v.bv_offset, v.bv_len), 8337ff50620SDavid Howells memcpy((to += v.iov_len) - v.iov_len, v.iov_base, v.iov_len), 8347ff50620SDavid Howells memcpy_from_page((to += v.bv_len) - v.bv_len, v.bv_page, 8357ff50620SDavid Howells v.bv_offset, v.bv_len) 836d879cb83SAl Viro ) 837d879cb83SAl Viro 838d879cb83SAl Viro return bytes; 839d879cb83SAl Viro } 840aa28de27SAl Viro EXPORT_SYMBOL(_copy_from_iter_nocache); 841d879cb83SAl Viro 8420aed55afSDan Williams #ifdef CONFIG_ARCH_HAS_UACCESS_FLUSHCACHE 843abd08d7dSDan Williams /** 844abd08d7dSDan Williams * _copy_from_iter_flushcache - write destination through cpu cache 845abd08d7dSDan Williams * @addr: destination kernel address 846abd08d7dSDan Williams * @bytes: total transfer length 847abd08d7dSDan Williams * @iter: source iterator 848abd08d7dSDan Williams * 849abd08d7dSDan Williams * The pmem driver arranges for filesystem-dax to use this facility via 850abd08d7dSDan Williams * dax_copy_from_iter() for ensuring that writes to persistent memory 851abd08d7dSDan Williams * are flushed through the CPU cache. It is differentiated from 852abd08d7dSDan Williams * _copy_from_iter_nocache() in that guarantees all data is flushed for 853abd08d7dSDan Williams * all iterator types. The _copy_from_iter_nocache() only attempts to 854abd08d7dSDan Williams * bypass the cache for the ITER_IOVEC case, and on some archs may use 855abd08d7dSDan Williams * instructions that strand dirty-data in the cache. 856abd08d7dSDan Williams */ 8576a37e940SLinus Torvalds size_t _copy_from_iter_flushcache(void *addr, size_t bytes, struct iov_iter *i) 8580aed55afSDan Williams { 8590aed55afSDan Williams char *to = addr; 86000e23707SDavid Howells if (unlikely(iov_iter_is_pipe(i))) { 8610aed55afSDan Williams WARN_ON(1); 8620aed55afSDan Williams return 0; 8630aed55afSDan Williams } 8640aed55afSDan Williams iterate_and_advance(i, bytes, v, 8650aed55afSDan Williams __copy_from_user_flushcache((to += v.iov_len) - v.iov_len, 8660aed55afSDan Williams v.iov_base, v.iov_len), 8670aed55afSDan Williams memcpy_page_flushcache((to += v.bv_len) - v.bv_len, v.bv_page, 8680aed55afSDan Williams v.bv_offset, v.bv_len), 8690aed55afSDan Williams memcpy_flushcache((to += v.iov_len) - v.iov_len, v.iov_base, 8707ff50620SDavid Howells v.iov_len), 8717ff50620SDavid Howells memcpy_page_flushcache((to += v.bv_len) - v.bv_len, v.bv_page, 8727ff50620SDavid Howells v.bv_offset, v.bv_len) 8730aed55afSDan Williams ) 8740aed55afSDan Williams 8750aed55afSDan Williams return bytes; 8760aed55afSDan Williams } 8776a37e940SLinus Torvalds EXPORT_SYMBOL_GPL(_copy_from_iter_flushcache); 8780aed55afSDan Williams #endif 8790aed55afSDan Williams 88072e809edSAl Viro static inline bool page_copy_sane(struct page *page, size_t offset, size_t n) 88172e809edSAl Viro { 8826daef95bSEric Dumazet struct page *head; 8836daef95bSEric Dumazet size_t v = n + offset; 8846daef95bSEric Dumazet 8856daef95bSEric Dumazet /* 8866daef95bSEric Dumazet * The general case needs to access the page order in order 8876daef95bSEric Dumazet * to compute the page size. 8886daef95bSEric Dumazet * However, we mostly deal with order-0 pages and thus can 8896daef95bSEric Dumazet * avoid a possible cache line miss for requests that fit all 8906daef95bSEric Dumazet * page orders. 8916daef95bSEric Dumazet */ 8926daef95bSEric Dumazet if (n <= v && v <= PAGE_SIZE) 8936daef95bSEric Dumazet return true; 8946daef95bSEric Dumazet 8956daef95bSEric Dumazet head = compound_head(page); 8966daef95bSEric Dumazet v += (page - head) << PAGE_SHIFT; 897a90bcb86SPetar Penkov 898a50b854eSMatthew Wilcox (Oracle) if (likely(n <= v && v <= (page_size(head)))) 89972e809edSAl Viro return true; 90072e809edSAl Viro WARN_ON(1); 90172e809edSAl Viro return false; 90272e809edSAl Viro } 903cbbd26b8SAl Viro 90408aa6479SAl Viro static size_t __copy_page_to_iter(struct page *page, size_t offset, size_t bytes, 905d879cb83SAl Viro struct iov_iter *i) 906d879cb83SAl Viro { 90728f38db7SAl Viro if (likely(iter_is_iovec(i))) 90828f38db7SAl Viro return copy_page_to_iter_iovec(page, offset, bytes, i); 90928f38db7SAl Viro if (iov_iter_is_bvec(i) || iov_iter_is_kvec(i) || iov_iter_is_xarray(i)) { 910d879cb83SAl Viro void *kaddr = kmap_atomic(page); 911d879cb83SAl Viro size_t wanted = copy_to_iter(kaddr + offset, bytes, i); 912d879cb83SAl Viro kunmap_atomic(kaddr); 913d879cb83SAl Viro return wanted; 91428f38db7SAl Viro } 91528f38db7SAl Viro if (iov_iter_is_pipe(i)) 91628f38db7SAl Viro return copy_page_to_iter_pipe(page, offset, bytes, i); 91728f38db7SAl Viro if (unlikely(iov_iter_is_discard(i))) { 918a506abc7SAl Viro if (unlikely(i->count < bytes)) 919a506abc7SAl Viro bytes = i->count; 920a506abc7SAl Viro i->count -= bytes; 9219ea9ce04SDavid Howells return bytes; 92228f38db7SAl Viro } 92328f38db7SAl Viro WARN_ON(1); 92428f38db7SAl Viro return 0; 925d879cb83SAl Viro } 92608aa6479SAl Viro 92708aa6479SAl Viro size_t copy_page_to_iter(struct page *page, size_t offset, size_t bytes, 92808aa6479SAl Viro struct iov_iter *i) 92908aa6479SAl Viro { 93008aa6479SAl Viro size_t res = 0; 93108aa6479SAl Viro if (unlikely(!page_copy_sane(page, offset, bytes))) 93208aa6479SAl Viro return 0; 93308aa6479SAl Viro page += offset / PAGE_SIZE; // first subpage 93408aa6479SAl Viro offset %= PAGE_SIZE; 93508aa6479SAl Viro while (1) { 93608aa6479SAl Viro size_t n = __copy_page_to_iter(page, offset, 93708aa6479SAl Viro min(bytes, (size_t)PAGE_SIZE - offset), i); 93808aa6479SAl Viro res += n; 93908aa6479SAl Viro bytes -= n; 94008aa6479SAl Viro if (!bytes || !n) 94108aa6479SAl Viro break; 94208aa6479SAl Viro offset += n; 94308aa6479SAl Viro if (offset == PAGE_SIZE) { 94408aa6479SAl Viro page++; 94508aa6479SAl Viro offset = 0; 94608aa6479SAl Viro } 94708aa6479SAl Viro } 94808aa6479SAl Viro return res; 94908aa6479SAl Viro } 950d879cb83SAl Viro EXPORT_SYMBOL(copy_page_to_iter); 951d879cb83SAl Viro 952d879cb83SAl Viro size_t copy_page_from_iter(struct page *page, size_t offset, size_t bytes, 953d879cb83SAl Viro struct iov_iter *i) 954d879cb83SAl Viro { 95572e809edSAl Viro if (unlikely(!page_copy_sane(page, offset, bytes))) 95672e809edSAl Viro return 0; 95728f38db7SAl Viro if (likely(iter_is_iovec(i))) 95828f38db7SAl Viro return copy_page_from_iter_iovec(page, offset, bytes, i); 95928f38db7SAl Viro if (iov_iter_is_bvec(i) || iov_iter_is_kvec(i) || iov_iter_is_xarray(i)) { 960d879cb83SAl Viro void *kaddr = kmap_atomic(page); 961aa28de27SAl Viro size_t wanted = _copy_from_iter(kaddr + offset, bytes, i); 962d879cb83SAl Viro kunmap_atomic(kaddr); 963d879cb83SAl Viro return wanted; 96428f38db7SAl Viro } 96528f38db7SAl Viro WARN_ON(1); 96628f38db7SAl Viro return 0; 967d879cb83SAl Viro } 968d879cb83SAl Viro EXPORT_SYMBOL(copy_page_from_iter); 969d879cb83SAl Viro 970241699cdSAl Viro static size_t pipe_zero(size_t bytes, struct iov_iter *i) 971241699cdSAl Viro { 972241699cdSAl Viro struct pipe_inode_info *pipe = i->pipe; 9738cefc107SDavid Howells unsigned int p_mask = pipe->ring_size - 1; 9748cefc107SDavid Howells unsigned int i_head; 975241699cdSAl Viro size_t n, off; 976241699cdSAl Viro 977241699cdSAl Viro if (!sanity(i)) 978241699cdSAl Viro return 0; 979241699cdSAl Viro 9808cefc107SDavid Howells bytes = n = push_pipe(i, bytes, &i_head, &off); 981241699cdSAl Viro if (unlikely(!n)) 982241699cdSAl Viro return 0; 983241699cdSAl Viro 9848cefc107SDavid Howells do { 985241699cdSAl Viro size_t chunk = min_t(size_t, n, PAGE_SIZE - off); 9868cefc107SDavid Howells memzero_page(pipe->bufs[i_head & p_mask].page, off, chunk); 9878cefc107SDavid Howells i->head = i_head; 988241699cdSAl Viro i->iov_offset = off + chunk; 989241699cdSAl Viro n -= chunk; 9908cefc107SDavid Howells off = 0; 9918cefc107SDavid Howells i_head++; 9928cefc107SDavid Howells } while (n); 993241699cdSAl Viro i->count -= bytes; 994241699cdSAl Viro return bytes; 995241699cdSAl Viro } 996241699cdSAl Viro 997d879cb83SAl Viro size_t iov_iter_zero(size_t bytes, struct iov_iter *i) 998d879cb83SAl Viro { 99900e23707SDavid Howells if (unlikely(iov_iter_is_pipe(i))) 1000241699cdSAl Viro return pipe_zero(bytes, i); 1001d879cb83SAl Viro iterate_and_advance(i, bytes, v, 100209fc68dcSAl Viro clear_user(v.iov_base, v.iov_len), 1003d879cb83SAl Viro memzero_page(v.bv_page, v.bv_offset, v.bv_len), 10047ff50620SDavid Howells memset(v.iov_base, 0, v.iov_len), 10057ff50620SDavid Howells memzero_page(v.bv_page, v.bv_offset, v.bv_len) 1006d879cb83SAl Viro ) 1007d879cb83SAl Viro 1008d879cb83SAl Viro return bytes; 1009d879cb83SAl Viro } 1010d879cb83SAl Viro EXPORT_SYMBOL(iov_iter_zero); 1011d879cb83SAl Viro 1012d879cb83SAl Viro size_t iov_iter_copy_from_user_atomic(struct page *page, 1013d879cb83SAl Viro struct iov_iter *i, unsigned long offset, size_t bytes) 1014d879cb83SAl Viro { 1015d879cb83SAl Viro char *kaddr = kmap_atomic(page), *p = kaddr + offset; 101672e809edSAl Viro if (unlikely(!page_copy_sane(page, offset, bytes))) { 101772e809edSAl Viro kunmap_atomic(kaddr); 101872e809edSAl Viro return 0; 101972e809edSAl Viro } 10209ea9ce04SDavid Howells if (unlikely(iov_iter_is_pipe(i) || iov_iter_is_discard(i))) { 1021241699cdSAl Viro kunmap_atomic(kaddr); 1022241699cdSAl Viro WARN_ON(1); 1023241699cdSAl Viro return 0; 1024241699cdSAl Viro } 1025d879cb83SAl Viro iterate_all_kinds(i, bytes, v, 102609fc68dcSAl Viro copyin((p += v.iov_len) - v.iov_len, v.iov_base, v.iov_len), 1027d879cb83SAl Viro memcpy_from_page((p += v.bv_len) - v.bv_len, v.bv_page, 1028d879cb83SAl Viro v.bv_offset, v.bv_len), 10297ff50620SDavid Howells memcpy((p += v.iov_len) - v.iov_len, v.iov_base, v.iov_len), 10307ff50620SDavid Howells memcpy_from_page((p += v.bv_len) - v.bv_len, v.bv_page, 10317ff50620SDavid Howells v.bv_offset, v.bv_len) 1032d879cb83SAl Viro ) 1033d879cb83SAl Viro kunmap_atomic(kaddr); 1034d879cb83SAl Viro return bytes; 1035d879cb83SAl Viro } 1036d879cb83SAl Viro EXPORT_SYMBOL(iov_iter_copy_from_user_atomic); 1037d879cb83SAl Viro 1038b9dc6f65SAl Viro static inline void pipe_truncate(struct iov_iter *i) 1039241699cdSAl Viro { 1040241699cdSAl Viro struct pipe_inode_info *pipe = i->pipe; 10418cefc107SDavid Howells unsigned int p_tail = pipe->tail; 10428cefc107SDavid Howells unsigned int p_head = pipe->head; 10438cefc107SDavid Howells unsigned int p_mask = pipe->ring_size - 1; 10448cefc107SDavid Howells 10458cefc107SDavid Howells if (!pipe_empty(p_head, p_tail)) { 10468cefc107SDavid Howells struct pipe_buffer *buf; 10478cefc107SDavid Howells unsigned int i_head = i->head; 1048b9dc6f65SAl Viro size_t off = i->iov_offset; 10498cefc107SDavid Howells 1050b9dc6f65SAl Viro if (off) { 10518cefc107SDavid Howells buf = &pipe->bufs[i_head & p_mask]; 10528cefc107SDavid Howells buf->len = off - buf->offset; 10538cefc107SDavid Howells i_head++; 1054b9dc6f65SAl Viro } 10558cefc107SDavid Howells while (p_head != i_head) { 10568cefc107SDavid Howells p_head--; 10578cefc107SDavid Howells pipe_buf_release(pipe, &pipe->bufs[p_head & p_mask]); 1058241699cdSAl Viro } 10598cefc107SDavid Howells 10608cefc107SDavid Howells pipe->head = p_head; 1061241699cdSAl Viro } 1062b9dc6f65SAl Viro } 1063b9dc6f65SAl Viro 1064b9dc6f65SAl Viro static void pipe_advance(struct iov_iter *i, size_t size) 1065b9dc6f65SAl Viro { 1066b9dc6f65SAl Viro struct pipe_inode_info *pipe = i->pipe; 1067b9dc6f65SAl Viro if (size) { 1068b9dc6f65SAl Viro struct pipe_buffer *buf; 10698cefc107SDavid Howells unsigned int p_mask = pipe->ring_size - 1; 10708cefc107SDavid Howells unsigned int i_head = i->head; 1071b9dc6f65SAl Viro size_t off = i->iov_offset, left = size; 10728cefc107SDavid Howells 1073b9dc6f65SAl Viro if (off) /* make it relative to the beginning of buffer */ 10748cefc107SDavid Howells left += off - pipe->bufs[i_head & p_mask].offset; 1075b9dc6f65SAl Viro while (1) { 10768cefc107SDavid Howells buf = &pipe->bufs[i_head & p_mask]; 1077b9dc6f65SAl Viro if (left <= buf->len) 1078b9dc6f65SAl Viro break; 1079b9dc6f65SAl Viro left -= buf->len; 10808cefc107SDavid Howells i_head++; 1081b9dc6f65SAl Viro } 10828cefc107SDavid Howells i->head = i_head; 1083b9dc6f65SAl Viro i->iov_offset = buf->offset + left; 1084b9dc6f65SAl Viro } 1085b9dc6f65SAl Viro i->count -= size; 1086b9dc6f65SAl Viro /* ... and discard everything past that point */ 1087b9dc6f65SAl Viro pipe_truncate(i); 1088241699cdSAl Viro } 1089241699cdSAl Viro 109054c8195bSPavel Begunkov static void iov_iter_bvec_advance(struct iov_iter *i, size_t size) 109154c8195bSPavel Begunkov { 109254c8195bSPavel Begunkov struct bvec_iter bi; 109354c8195bSPavel Begunkov 109454c8195bSPavel Begunkov bi.bi_size = i->count; 109554c8195bSPavel Begunkov bi.bi_bvec_done = i->iov_offset; 109654c8195bSPavel Begunkov bi.bi_idx = 0; 109754c8195bSPavel Begunkov bvec_iter_advance(i->bvec, &bi, size); 109854c8195bSPavel Begunkov 109954c8195bSPavel Begunkov i->bvec += bi.bi_idx; 110054c8195bSPavel Begunkov i->nr_segs -= bi.bi_idx; 110154c8195bSPavel Begunkov i->count = bi.bi_size; 110254c8195bSPavel Begunkov i->iov_offset = bi.bi_bvec_done; 110354c8195bSPavel Begunkov } 110454c8195bSPavel Begunkov 1105185ac4d4SAl Viro static void iov_iter_iovec_advance(struct iov_iter *i, size_t size) 1106185ac4d4SAl Viro { 1107185ac4d4SAl Viro const struct iovec *iov, *end; 1108185ac4d4SAl Viro 1109185ac4d4SAl Viro if (!i->count) 1110185ac4d4SAl Viro return; 1111185ac4d4SAl Viro i->count -= size; 1112185ac4d4SAl Viro 1113185ac4d4SAl Viro size += i->iov_offset; // from beginning of current segment 1114185ac4d4SAl Viro for (iov = i->iov, end = iov + i->nr_segs; iov < end; iov++) { 1115185ac4d4SAl Viro if (likely(size < iov->iov_len)) 1116185ac4d4SAl Viro break; 1117185ac4d4SAl Viro size -= iov->iov_len; 1118185ac4d4SAl Viro } 1119185ac4d4SAl Viro i->iov_offset = size; 1120185ac4d4SAl Viro i->nr_segs -= iov - i->iov; 1121185ac4d4SAl Viro i->iov = iov; 1122185ac4d4SAl Viro } 1123185ac4d4SAl Viro 1124d879cb83SAl Viro void iov_iter_advance(struct iov_iter *i, size_t size) 1125d879cb83SAl Viro { 11263b3fc051SAl Viro if (unlikely(i->count < size)) 11273b3fc051SAl Viro size = i->count; 1128185ac4d4SAl Viro if (likely(iter_is_iovec(i) || iov_iter_is_kvec(i))) { 1129185ac4d4SAl Viro /* iovec and kvec have identical layouts */ 1130185ac4d4SAl Viro iov_iter_iovec_advance(i, size); 1131185ac4d4SAl Viro } else if (iov_iter_is_bvec(i)) { 1132185ac4d4SAl Viro iov_iter_bvec_advance(i, size); 1133185ac4d4SAl Viro } else if (iov_iter_is_pipe(i)) { 1134241699cdSAl Viro pipe_advance(i, size); 1135185ac4d4SAl Viro } else if (unlikely(iov_iter_is_xarray(i))) { 11367ff50620SDavid Howells i->iov_offset += size; 11377ff50620SDavid Howells i->count -= size; 1138185ac4d4SAl Viro } else if (iov_iter_is_discard(i)) { 1139185ac4d4SAl Viro i->count -= size; 11407ff50620SDavid Howells } 1141d879cb83SAl Viro } 1142d879cb83SAl Viro EXPORT_SYMBOL(iov_iter_advance); 1143d879cb83SAl Viro 114427c0e374SAl Viro void iov_iter_revert(struct iov_iter *i, size_t unroll) 114527c0e374SAl Viro { 114627c0e374SAl Viro if (!unroll) 114727c0e374SAl Viro return; 11485b47d59aSAl Viro if (WARN_ON(unroll > MAX_RW_COUNT)) 11495b47d59aSAl Viro return; 115027c0e374SAl Viro i->count += unroll; 115100e23707SDavid Howells if (unlikely(iov_iter_is_pipe(i))) { 115227c0e374SAl Viro struct pipe_inode_info *pipe = i->pipe; 11538cefc107SDavid Howells unsigned int p_mask = pipe->ring_size - 1; 11548cefc107SDavid Howells unsigned int i_head = i->head; 115527c0e374SAl Viro size_t off = i->iov_offset; 115627c0e374SAl Viro while (1) { 11578cefc107SDavid Howells struct pipe_buffer *b = &pipe->bufs[i_head & p_mask]; 11588cefc107SDavid Howells size_t n = off - b->offset; 115927c0e374SAl Viro if (unroll < n) { 11604fa55cefSAl Viro off -= unroll; 116127c0e374SAl Viro break; 116227c0e374SAl Viro } 116327c0e374SAl Viro unroll -= n; 11648cefc107SDavid Howells if (!unroll && i_head == i->start_head) { 116527c0e374SAl Viro off = 0; 116627c0e374SAl Viro break; 116727c0e374SAl Viro } 11688cefc107SDavid Howells i_head--; 11698cefc107SDavid Howells b = &pipe->bufs[i_head & p_mask]; 11708cefc107SDavid Howells off = b->offset + b->len; 117127c0e374SAl Viro } 117227c0e374SAl Viro i->iov_offset = off; 11738cefc107SDavid Howells i->head = i_head; 117427c0e374SAl Viro pipe_truncate(i); 117527c0e374SAl Viro return; 117627c0e374SAl Viro } 11779ea9ce04SDavid Howells if (unlikely(iov_iter_is_discard(i))) 11789ea9ce04SDavid Howells return; 117927c0e374SAl Viro if (unroll <= i->iov_offset) { 118027c0e374SAl Viro i->iov_offset -= unroll; 118127c0e374SAl Viro return; 118227c0e374SAl Viro } 118327c0e374SAl Viro unroll -= i->iov_offset; 11847ff50620SDavid Howells if (iov_iter_is_xarray(i)) { 11857ff50620SDavid Howells BUG(); /* We should never go beyond the start of the specified 11867ff50620SDavid Howells * range since we might then be straying into pages that 11877ff50620SDavid Howells * aren't pinned. 11887ff50620SDavid Howells */ 11897ff50620SDavid Howells } else if (iov_iter_is_bvec(i)) { 119027c0e374SAl Viro const struct bio_vec *bvec = i->bvec; 119127c0e374SAl Viro while (1) { 119227c0e374SAl Viro size_t n = (--bvec)->bv_len; 119327c0e374SAl Viro i->nr_segs++; 119427c0e374SAl Viro if (unroll <= n) { 119527c0e374SAl Viro i->bvec = bvec; 119627c0e374SAl Viro i->iov_offset = n - unroll; 119727c0e374SAl Viro return; 119827c0e374SAl Viro } 119927c0e374SAl Viro unroll -= n; 120027c0e374SAl Viro } 120127c0e374SAl Viro } else { /* same logics for iovec and kvec */ 120227c0e374SAl Viro const struct iovec *iov = i->iov; 120327c0e374SAl Viro while (1) { 120427c0e374SAl Viro size_t n = (--iov)->iov_len; 120527c0e374SAl Viro i->nr_segs++; 120627c0e374SAl Viro if (unroll <= n) { 120727c0e374SAl Viro i->iov = iov; 120827c0e374SAl Viro i->iov_offset = n - unroll; 120927c0e374SAl Viro return; 121027c0e374SAl Viro } 121127c0e374SAl Viro unroll -= n; 121227c0e374SAl Viro } 121327c0e374SAl Viro } 121427c0e374SAl Viro } 121527c0e374SAl Viro EXPORT_SYMBOL(iov_iter_revert); 121627c0e374SAl Viro 1217d879cb83SAl Viro /* 1218d879cb83SAl Viro * Return the count of just the current iov_iter segment. 1219d879cb83SAl Viro */ 1220d879cb83SAl Viro size_t iov_iter_single_seg_count(const struct iov_iter *i) 1221d879cb83SAl Viro { 122228f38db7SAl Viro if (i->nr_segs > 1) { 122328f38db7SAl Viro if (likely(iter_is_iovec(i) || iov_iter_is_kvec(i))) 122428f38db7SAl Viro return min(i->count, i->iov->iov_len - i->iov_offset); 12257ff50620SDavid Howells if (iov_iter_is_bvec(i)) 1226d879cb83SAl Viro return min(i->count, i->bvec->bv_len - i->iov_offset); 122728f38db7SAl Viro } 122828f38db7SAl Viro return i->count; 1229d879cb83SAl Viro } 1230d879cb83SAl Viro EXPORT_SYMBOL(iov_iter_single_seg_count); 1231d879cb83SAl Viro 1232aa563d7bSDavid Howells void iov_iter_kvec(struct iov_iter *i, unsigned int direction, 1233d879cb83SAl Viro const struct kvec *kvec, unsigned long nr_segs, 1234d879cb83SAl Viro size_t count) 1235d879cb83SAl Viro { 1236aa563d7bSDavid Howells WARN_ON(direction & ~(READ | WRITE)); 12378cd54c1cSAl Viro *i = (struct iov_iter){ 12388cd54c1cSAl Viro .iter_type = ITER_KVEC, 12398cd54c1cSAl Viro .data_source = direction, 12408cd54c1cSAl Viro .kvec = kvec, 12418cd54c1cSAl Viro .nr_segs = nr_segs, 12428cd54c1cSAl Viro .iov_offset = 0, 12438cd54c1cSAl Viro .count = count 12448cd54c1cSAl Viro }; 1245d879cb83SAl Viro } 1246d879cb83SAl Viro EXPORT_SYMBOL(iov_iter_kvec); 1247d879cb83SAl Viro 1248aa563d7bSDavid Howells void iov_iter_bvec(struct iov_iter *i, unsigned int direction, 1249d879cb83SAl Viro const struct bio_vec *bvec, unsigned long nr_segs, 1250d879cb83SAl Viro size_t count) 1251d879cb83SAl Viro { 1252aa563d7bSDavid Howells WARN_ON(direction & ~(READ | WRITE)); 12538cd54c1cSAl Viro *i = (struct iov_iter){ 12548cd54c1cSAl Viro .iter_type = ITER_BVEC, 12558cd54c1cSAl Viro .data_source = direction, 12568cd54c1cSAl Viro .bvec = bvec, 12578cd54c1cSAl Viro .nr_segs = nr_segs, 12588cd54c1cSAl Viro .iov_offset = 0, 12598cd54c1cSAl Viro .count = count 12608cd54c1cSAl Viro }; 1261d879cb83SAl Viro } 1262d879cb83SAl Viro EXPORT_SYMBOL(iov_iter_bvec); 1263d879cb83SAl Viro 1264aa563d7bSDavid Howells void iov_iter_pipe(struct iov_iter *i, unsigned int direction, 1265241699cdSAl Viro struct pipe_inode_info *pipe, 1266241699cdSAl Viro size_t count) 1267241699cdSAl Viro { 1268aa563d7bSDavid Howells BUG_ON(direction != READ); 12698cefc107SDavid Howells WARN_ON(pipe_full(pipe->head, pipe->tail, pipe->ring_size)); 12708cd54c1cSAl Viro *i = (struct iov_iter){ 12718cd54c1cSAl Viro .iter_type = ITER_PIPE, 12728cd54c1cSAl Viro .data_source = false, 12738cd54c1cSAl Viro .pipe = pipe, 12748cd54c1cSAl Viro .head = pipe->head, 12758cd54c1cSAl Viro .start_head = pipe->head, 12768cd54c1cSAl Viro .iov_offset = 0, 12778cd54c1cSAl Viro .count = count 12788cd54c1cSAl Viro }; 1279241699cdSAl Viro } 1280241699cdSAl Viro EXPORT_SYMBOL(iov_iter_pipe); 1281241699cdSAl Viro 12829ea9ce04SDavid Howells /** 12837ff50620SDavid Howells * iov_iter_xarray - Initialise an I/O iterator to use the pages in an xarray 12847ff50620SDavid Howells * @i: The iterator to initialise. 12857ff50620SDavid Howells * @direction: The direction of the transfer. 12867ff50620SDavid Howells * @xarray: The xarray to access. 12877ff50620SDavid Howells * @start: The start file position. 12887ff50620SDavid Howells * @count: The size of the I/O buffer in bytes. 12897ff50620SDavid Howells * 12907ff50620SDavid Howells * Set up an I/O iterator to either draw data out of the pages attached to an 12917ff50620SDavid Howells * inode or to inject data into those pages. The pages *must* be prevented 12927ff50620SDavid Howells * from evaporation, either by taking a ref on them or locking them by the 12937ff50620SDavid Howells * caller. 12947ff50620SDavid Howells */ 12957ff50620SDavid Howells void iov_iter_xarray(struct iov_iter *i, unsigned int direction, 12967ff50620SDavid Howells struct xarray *xarray, loff_t start, size_t count) 12977ff50620SDavid Howells { 12987ff50620SDavid Howells BUG_ON(direction & ~1); 12998cd54c1cSAl Viro *i = (struct iov_iter) { 13008cd54c1cSAl Viro .iter_type = ITER_XARRAY, 13018cd54c1cSAl Viro .data_source = direction, 13028cd54c1cSAl Viro .xarray = xarray, 13038cd54c1cSAl Viro .xarray_start = start, 13048cd54c1cSAl Viro .count = count, 13058cd54c1cSAl Viro .iov_offset = 0 13068cd54c1cSAl Viro }; 13077ff50620SDavid Howells } 13087ff50620SDavid Howells EXPORT_SYMBOL(iov_iter_xarray); 13097ff50620SDavid Howells 13107ff50620SDavid Howells /** 13119ea9ce04SDavid Howells * iov_iter_discard - Initialise an I/O iterator that discards data 13129ea9ce04SDavid Howells * @i: The iterator to initialise. 13139ea9ce04SDavid Howells * @direction: The direction of the transfer. 13149ea9ce04SDavid Howells * @count: The size of the I/O buffer in bytes. 13159ea9ce04SDavid Howells * 13169ea9ce04SDavid Howells * Set up an I/O iterator that just discards everything that's written to it. 13179ea9ce04SDavid Howells * It's only available as a READ iterator. 13189ea9ce04SDavid Howells */ 13199ea9ce04SDavid Howells void iov_iter_discard(struct iov_iter *i, unsigned int direction, size_t count) 13209ea9ce04SDavid Howells { 13219ea9ce04SDavid Howells BUG_ON(direction != READ); 13228cd54c1cSAl Viro *i = (struct iov_iter){ 13238cd54c1cSAl Viro .iter_type = ITER_DISCARD, 13248cd54c1cSAl Viro .data_source = false, 13258cd54c1cSAl Viro .count = count, 13268cd54c1cSAl Viro .iov_offset = 0 13278cd54c1cSAl Viro }; 13289ea9ce04SDavid Howells } 13299ea9ce04SDavid Howells EXPORT_SYMBOL(iov_iter_discard); 13309ea9ce04SDavid Howells 13319221d2e3SAl Viro static unsigned long iov_iter_alignment_iovec(const struct iov_iter *i) 1332d879cb83SAl Viro { 1333d879cb83SAl Viro unsigned long res = 0; 1334d879cb83SAl Viro size_t size = i->count; 13359221d2e3SAl Viro size_t skip = i->iov_offset; 13369221d2e3SAl Viro unsigned k; 1337d879cb83SAl Viro 13389221d2e3SAl Viro for (k = 0; k < i->nr_segs; k++, skip = 0) { 13399221d2e3SAl Viro size_t len = i->iov[k].iov_len - skip; 13409221d2e3SAl Viro if (len) { 13419221d2e3SAl Viro res |= (unsigned long)i->iov[k].iov_base + skip; 13429221d2e3SAl Viro if (len > size) 13439221d2e3SAl Viro len = size; 13449221d2e3SAl Viro res |= len; 13459221d2e3SAl Viro size -= len; 13469221d2e3SAl Viro if (!size) 13479221d2e3SAl Viro break; 13489221d2e3SAl Viro } 13499221d2e3SAl Viro } 13509221d2e3SAl Viro return res; 13519221d2e3SAl Viro } 13529221d2e3SAl Viro 13539221d2e3SAl Viro static unsigned long iov_iter_alignment_bvec(const struct iov_iter *i) 13549221d2e3SAl Viro { 13559221d2e3SAl Viro unsigned res = 0; 13569221d2e3SAl Viro size_t size = i->count; 13579221d2e3SAl Viro unsigned skip = i->iov_offset; 13589221d2e3SAl Viro unsigned k; 13599221d2e3SAl Viro 13609221d2e3SAl Viro for (k = 0; k < i->nr_segs; k++, skip = 0) { 13619221d2e3SAl Viro size_t len = i->bvec[k].bv_len - skip; 13629221d2e3SAl Viro res |= (unsigned long)i->bvec[k].bv_offset + skip; 13639221d2e3SAl Viro if (len > size) 13649221d2e3SAl Viro len = size; 13659221d2e3SAl Viro res |= len; 13669221d2e3SAl Viro size -= len; 13679221d2e3SAl Viro if (!size) 13689221d2e3SAl Viro break; 13699221d2e3SAl Viro } 13709221d2e3SAl Viro return res; 13719221d2e3SAl Viro } 13729221d2e3SAl Viro 13739221d2e3SAl Viro unsigned long iov_iter_alignment(const struct iov_iter *i) 13749221d2e3SAl Viro { 13759221d2e3SAl Viro /* iovec and kvec have identical layouts */ 13769221d2e3SAl Viro if (likely(iter_is_iovec(i) || iov_iter_is_kvec(i))) 13779221d2e3SAl Viro return iov_iter_alignment_iovec(i); 13789221d2e3SAl Viro 13799221d2e3SAl Viro if (iov_iter_is_bvec(i)) 13809221d2e3SAl Viro return iov_iter_alignment_bvec(i); 13819221d2e3SAl Viro 13829221d2e3SAl Viro if (iov_iter_is_pipe(i)) { 1383e0ff126eSJan Kara unsigned int p_mask = i->pipe->ring_size - 1; 13849221d2e3SAl Viro size_t size = i->count; 1385e0ff126eSJan Kara 13868cefc107SDavid Howells if (size && i->iov_offset && allocated(&i->pipe->bufs[i->head & p_mask])) 1387241699cdSAl Viro return size | i->iov_offset; 1388241699cdSAl Viro return size; 1389241699cdSAl Viro } 13909221d2e3SAl Viro 13919221d2e3SAl Viro if (iov_iter_is_xarray(i)) 13923d14ec1fSDavid Howells return (i->xarray_start + i->iov_offset) | i->count; 13939221d2e3SAl Viro 13949221d2e3SAl Viro return 0; 1395d879cb83SAl Viro } 1396d879cb83SAl Viro EXPORT_SYMBOL(iov_iter_alignment); 1397d879cb83SAl Viro 1398357f435dSAl Viro unsigned long iov_iter_gap_alignment(const struct iov_iter *i) 1399357f435dSAl Viro { 1400357f435dSAl Viro unsigned long res = 0; 1401610c7a71SAl Viro unsigned long v = 0; 1402357f435dSAl Viro size_t size = i->count; 1403610c7a71SAl Viro unsigned k; 1404357f435dSAl Viro 1405610c7a71SAl Viro if (WARN_ON(!iter_is_iovec(i))) 1406241699cdSAl Viro return ~0U; 1407241699cdSAl Viro 1408610c7a71SAl Viro for (k = 0; k < i->nr_segs; k++) { 1409610c7a71SAl Viro if (i->iov[k].iov_len) { 1410610c7a71SAl Viro unsigned long base = (unsigned long)i->iov[k].iov_base; 1411610c7a71SAl Viro if (v) // if not the first one 1412610c7a71SAl Viro res |= base | v; // this start | previous end 1413610c7a71SAl Viro v = base + i->iov[k].iov_len; 1414610c7a71SAl Viro if (size <= i->iov[k].iov_len) 1415610c7a71SAl Viro break; 1416610c7a71SAl Viro size -= i->iov[k].iov_len; 1417610c7a71SAl Viro } 1418610c7a71SAl Viro } 1419357f435dSAl Viro return res; 1420357f435dSAl Viro } 1421357f435dSAl Viro EXPORT_SYMBOL(iov_iter_gap_alignment); 1422357f435dSAl Viro 1423e76b6312SIlya Dryomov static inline ssize_t __pipe_get_pages(struct iov_iter *i, 1424241699cdSAl Viro size_t maxsize, 1425241699cdSAl Viro struct page **pages, 14268cefc107SDavid Howells int iter_head, 1427241699cdSAl Viro size_t *start) 1428241699cdSAl Viro { 1429241699cdSAl Viro struct pipe_inode_info *pipe = i->pipe; 14308cefc107SDavid Howells unsigned int p_mask = pipe->ring_size - 1; 14318cefc107SDavid Howells ssize_t n = push_pipe(i, maxsize, &iter_head, start); 1432241699cdSAl Viro if (!n) 1433241699cdSAl Viro return -EFAULT; 1434241699cdSAl Viro 1435241699cdSAl Viro maxsize = n; 1436241699cdSAl Viro n += *start; 14371689c73aSAl Viro while (n > 0) { 14388cefc107SDavid Howells get_page(*pages++ = pipe->bufs[iter_head & p_mask].page); 14398cefc107SDavid Howells iter_head++; 1440241699cdSAl Viro n -= PAGE_SIZE; 1441241699cdSAl Viro } 1442241699cdSAl Viro 1443241699cdSAl Viro return maxsize; 1444241699cdSAl Viro } 1445241699cdSAl Viro 1446241699cdSAl Viro static ssize_t pipe_get_pages(struct iov_iter *i, 1447241699cdSAl Viro struct page **pages, size_t maxsize, unsigned maxpages, 1448241699cdSAl Viro size_t *start) 1449241699cdSAl Viro { 14508cefc107SDavid Howells unsigned int iter_head, npages; 1451241699cdSAl Viro size_t capacity; 1452241699cdSAl Viro 1453241699cdSAl Viro if (!sanity(i)) 1454241699cdSAl Viro return -EFAULT; 1455241699cdSAl Viro 14568cefc107SDavid Howells data_start(i, &iter_head, start); 14578cefc107SDavid Howells /* Amount of free space: some of this one + all after this one */ 14588cefc107SDavid Howells npages = pipe_space_for_user(iter_head, i->pipe->tail, i->pipe); 1459241699cdSAl Viro capacity = min(npages, maxpages) * PAGE_SIZE - *start; 1460241699cdSAl Viro 14618cefc107SDavid Howells return __pipe_get_pages(i, min(maxsize, capacity), pages, iter_head, start); 1462241699cdSAl Viro } 1463241699cdSAl Viro 14647ff50620SDavid Howells static ssize_t iter_xarray_populate_pages(struct page **pages, struct xarray *xa, 14657ff50620SDavid Howells pgoff_t index, unsigned int nr_pages) 14667ff50620SDavid Howells { 14677ff50620SDavid Howells XA_STATE(xas, xa, index); 14687ff50620SDavid Howells struct page *page; 14697ff50620SDavid Howells unsigned int ret = 0; 14707ff50620SDavid Howells 14717ff50620SDavid Howells rcu_read_lock(); 14727ff50620SDavid Howells for (page = xas_load(&xas); page; page = xas_next(&xas)) { 14737ff50620SDavid Howells if (xas_retry(&xas, page)) 14747ff50620SDavid Howells continue; 14757ff50620SDavid Howells 14767ff50620SDavid Howells /* Has the page moved or been split? */ 14777ff50620SDavid Howells if (unlikely(page != xas_reload(&xas))) { 14787ff50620SDavid Howells xas_reset(&xas); 14797ff50620SDavid Howells continue; 14807ff50620SDavid Howells } 14817ff50620SDavid Howells 14827ff50620SDavid Howells pages[ret] = find_subpage(page, xas.xa_index); 14837ff50620SDavid Howells get_page(pages[ret]); 14847ff50620SDavid Howells if (++ret == nr_pages) 14857ff50620SDavid Howells break; 14867ff50620SDavid Howells } 14877ff50620SDavid Howells rcu_read_unlock(); 14887ff50620SDavid Howells return ret; 14897ff50620SDavid Howells } 14907ff50620SDavid Howells 14917ff50620SDavid Howells static ssize_t iter_xarray_get_pages(struct iov_iter *i, 14927ff50620SDavid Howells struct page **pages, size_t maxsize, 14937ff50620SDavid Howells unsigned maxpages, size_t *_start_offset) 14947ff50620SDavid Howells { 14957ff50620SDavid Howells unsigned nr, offset; 14967ff50620SDavid Howells pgoff_t index, count; 14977ff50620SDavid Howells size_t size = maxsize, actual; 14987ff50620SDavid Howells loff_t pos; 14997ff50620SDavid Howells 15007ff50620SDavid Howells if (!size || !maxpages) 15017ff50620SDavid Howells return 0; 15027ff50620SDavid Howells 15037ff50620SDavid Howells pos = i->xarray_start + i->iov_offset; 15047ff50620SDavid Howells index = pos >> PAGE_SHIFT; 15057ff50620SDavid Howells offset = pos & ~PAGE_MASK; 15067ff50620SDavid Howells *_start_offset = offset; 15077ff50620SDavid Howells 15087ff50620SDavid Howells count = 1; 15097ff50620SDavid Howells if (size > PAGE_SIZE - offset) { 15107ff50620SDavid Howells size -= PAGE_SIZE - offset; 15117ff50620SDavid Howells count += size >> PAGE_SHIFT; 15127ff50620SDavid Howells size &= ~PAGE_MASK; 15137ff50620SDavid Howells if (size) 15147ff50620SDavid Howells count++; 15157ff50620SDavid Howells } 15167ff50620SDavid Howells 15177ff50620SDavid Howells if (count > maxpages) 15187ff50620SDavid Howells count = maxpages; 15197ff50620SDavid Howells 15207ff50620SDavid Howells nr = iter_xarray_populate_pages(pages, i->xarray, index, count); 15217ff50620SDavid Howells if (nr == 0) 15227ff50620SDavid Howells return 0; 15237ff50620SDavid Howells 15247ff50620SDavid Howells actual = PAGE_SIZE * nr; 15257ff50620SDavid Howells actual -= offset; 15267ff50620SDavid Howells if (nr == count && size > 0) { 15277ff50620SDavid Howells unsigned last_offset = (nr > 1) ? 0 : offset; 15287ff50620SDavid Howells actual -= PAGE_SIZE - (last_offset + size); 15297ff50620SDavid Howells } 15307ff50620SDavid Howells return actual; 15317ff50620SDavid Howells } 15327ff50620SDavid Howells 1533*3d671ca6SAl Viro /* must be done on non-empty ITER_IOVEC one */ 1534*3d671ca6SAl Viro static unsigned long first_iovec_segment(const struct iov_iter *i, 1535*3d671ca6SAl Viro size_t *size, size_t *start, 1536*3d671ca6SAl Viro size_t maxsize, unsigned maxpages) 1537*3d671ca6SAl Viro { 1538*3d671ca6SAl Viro size_t skip; 1539*3d671ca6SAl Viro long k; 1540*3d671ca6SAl Viro 1541*3d671ca6SAl Viro for (k = 0, skip = i->iov_offset; k < i->nr_segs; k++, skip = 0) { 1542*3d671ca6SAl Viro unsigned long addr = (unsigned long)i->iov[k].iov_base + skip; 1543*3d671ca6SAl Viro size_t len = i->iov[k].iov_len - skip; 1544*3d671ca6SAl Viro 1545*3d671ca6SAl Viro if (unlikely(!len)) 1546*3d671ca6SAl Viro continue; 1547*3d671ca6SAl Viro if (len > maxsize) 1548*3d671ca6SAl Viro len = maxsize; 1549*3d671ca6SAl Viro len += (*start = addr % PAGE_SIZE); 1550*3d671ca6SAl Viro if (len > maxpages * PAGE_SIZE) 1551*3d671ca6SAl Viro len = maxpages * PAGE_SIZE; 1552*3d671ca6SAl Viro *size = len; 1553*3d671ca6SAl Viro return addr & PAGE_MASK; 1554*3d671ca6SAl Viro } 1555*3d671ca6SAl Viro BUG(); // if it had been empty, we wouldn't get called 1556*3d671ca6SAl Viro } 1557*3d671ca6SAl Viro 1558*3d671ca6SAl Viro /* must be done on non-empty ITER_BVEC one */ 1559*3d671ca6SAl Viro static struct page *first_bvec_segment(const struct iov_iter *i, 1560*3d671ca6SAl Viro size_t *size, size_t *start, 1561*3d671ca6SAl Viro size_t maxsize, unsigned maxpages) 1562*3d671ca6SAl Viro { 1563*3d671ca6SAl Viro struct page *page; 1564*3d671ca6SAl Viro size_t skip = i->iov_offset, len; 1565*3d671ca6SAl Viro 1566*3d671ca6SAl Viro len = i->bvec->bv_len - skip; 1567*3d671ca6SAl Viro if (len > maxsize) 1568*3d671ca6SAl Viro len = maxsize; 1569*3d671ca6SAl Viro skip += i->bvec->bv_offset; 1570*3d671ca6SAl Viro page = i->bvec->bv_page + skip / PAGE_SIZE; 1571*3d671ca6SAl Viro len += (*start = skip % PAGE_SIZE); 1572*3d671ca6SAl Viro if (len > maxpages * PAGE_SIZE) 1573*3d671ca6SAl Viro len = maxpages * PAGE_SIZE; 1574*3d671ca6SAl Viro *size = len; 1575*3d671ca6SAl Viro return page; 1576*3d671ca6SAl Viro } 1577*3d671ca6SAl Viro 1578d879cb83SAl Viro ssize_t iov_iter_get_pages(struct iov_iter *i, 1579d879cb83SAl Viro struct page **pages, size_t maxsize, unsigned maxpages, 1580d879cb83SAl Viro size_t *start) 1581d879cb83SAl Viro { 1582*3d671ca6SAl Viro size_t len; 1583*3d671ca6SAl Viro int n, res; 1584*3d671ca6SAl Viro 1585d879cb83SAl Viro if (maxsize > i->count) 1586d879cb83SAl Viro maxsize = i->count; 1587*3d671ca6SAl Viro if (!maxsize) 1588*3d671ca6SAl Viro return 0; 1589d879cb83SAl Viro 1590*3d671ca6SAl Viro if (likely(iter_is_iovec(i))) { 1591*3d671ca6SAl Viro unsigned long addr; 15929ea9ce04SDavid Howells 1593*3d671ca6SAl Viro addr = first_iovec_segment(i, &len, start, maxsize, maxpages); 1594d879cb83SAl Viro n = DIV_ROUND_UP(len, PAGE_SIZE); 159573b0140bSIra Weiny res = get_user_pages_fast(addr, n, 159673b0140bSIra Weiny iov_iter_rw(i) != WRITE ? FOLL_WRITE : 0, 159773b0140bSIra Weiny pages); 1598d879cb83SAl Viro if (unlikely(res < 0)) 1599d879cb83SAl Viro return res; 1600d879cb83SAl Viro return (res == n ? len : res * PAGE_SIZE) - *start; 1601*3d671ca6SAl Viro } 1602*3d671ca6SAl Viro if (iov_iter_is_bvec(i)) { 1603*3d671ca6SAl Viro struct page *page; 1604*3d671ca6SAl Viro 1605*3d671ca6SAl Viro page = first_bvec_segment(i, &len, start, maxsize, maxpages); 1606*3d671ca6SAl Viro n = DIV_ROUND_UP(len, PAGE_SIZE); 1607*3d671ca6SAl Viro while (n--) 1608*3d671ca6SAl Viro get_page(*pages++ = page++); 1609*3d671ca6SAl Viro return len - *start; 1610*3d671ca6SAl Viro } 1611*3d671ca6SAl Viro if (iov_iter_is_pipe(i)) 1612*3d671ca6SAl Viro return pipe_get_pages(i, pages, maxsize, maxpages, start); 1613*3d671ca6SAl Viro if (iov_iter_is_xarray(i)) 1614*3d671ca6SAl Viro return iter_xarray_get_pages(i, pages, maxsize, maxpages, start); 1615d879cb83SAl Viro return -EFAULT; 1616d879cb83SAl Viro } 1617d879cb83SAl Viro EXPORT_SYMBOL(iov_iter_get_pages); 1618d879cb83SAl Viro 1619d879cb83SAl Viro static struct page **get_pages_array(size_t n) 1620d879cb83SAl Viro { 1621752ade68SMichal Hocko return kvmalloc_array(n, sizeof(struct page *), GFP_KERNEL); 1622d879cb83SAl Viro } 1623d879cb83SAl Viro 1624241699cdSAl Viro static ssize_t pipe_get_pages_alloc(struct iov_iter *i, 1625241699cdSAl Viro struct page ***pages, size_t maxsize, 1626241699cdSAl Viro size_t *start) 1627241699cdSAl Viro { 1628241699cdSAl Viro struct page **p; 16298cefc107SDavid Howells unsigned int iter_head, npages; 1630d7760d63SIlya Dryomov ssize_t n; 1631241699cdSAl Viro 1632241699cdSAl Viro if (!sanity(i)) 1633241699cdSAl Viro return -EFAULT; 1634241699cdSAl Viro 16358cefc107SDavid Howells data_start(i, &iter_head, start); 16368cefc107SDavid Howells /* Amount of free space: some of this one + all after this one */ 16378cefc107SDavid Howells npages = pipe_space_for_user(iter_head, i->pipe->tail, i->pipe); 1638241699cdSAl Viro n = npages * PAGE_SIZE - *start; 1639241699cdSAl Viro if (maxsize > n) 1640241699cdSAl Viro maxsize = n; 1641241699cdSAl Viro else 1642241699cdSAl Viro npages = DIV_ROUND_UP(maxsize + *start, PAGE_SIZE); 1643241699cdSAl Viro p = get_pages_array(npages); 1644241699cdSAl Viro if (!p) 1645241699cdSAl Viro return -ENOMEM; 16468cefc107SDavid Howells n = __pipe_get_pages(i, maxsize, p, iter_head, start); 1647241699cdSAl Viro if (n > 0) 1648241699cdSAl Viro *pages = p; 1649241699cdSAl Viro else 1650241699cdSAl Viro kvfree(p); 1651241699cdSAl Viro return n; 1652241699cdSAl Viro } 1653241699cdSAl Viro 16547ff50620SDavid Howells static ssize_t iter_xarray_get_pages_alloc(struct iov_iter *i, 16557ff50620SDavid Howells struct page ***pages, size_t maxsize, 16567ff50620SDavid Howells size_t *_start_offset) 16577ff50620SDavid Howells { 16587ff50620SDavid Howells struct page **p; 16597ff50620SDavid Howells unsigned nr, offset; 16607ff50620SDavid Howells pgoff_t index, count; 16617ff50620SDavid Howells size_t size = maxsize, actual; 16627ff50620SDavid Howells loff_t pos; 16637ff50620SDavid Howells 16647ff50620SDavid Howells if (!size) 16657ff50620SDavid Howells return 0; 16667ff50620SDavid Howells 16677ff50620SDavid Howells pos = i->xarray_start + i->iov_offset; 16687ff50620SDavid Howells index = pos >> PAGE_SHIFT; 16697ff50620SDavid Howells offset = pos & ~PAGE_MASK; 16707ff50620SDavid Howells *_start_offset = offset; 16717ff50620SDavid Howells 16727ff50620SDavid Howells count = 1; 16737ff50620SDavid Howells if (size > PAGE_SIZE - offset) { 16747ff50620SDavid Howells size -= PAGE_SIZE - offset; 16757ff50620SDavid Howells count += size >> PAGE_SHIFT; 16767ff50620SDavid Howells size &= ~PAGE_MASK; 16777ff50620SDavid Howells if (size) 16787ff50620SDavid Howells count++; 16797ff50620SDavid Howells } 16807ff50620SDavid Howells 16817ff50620SDavid Howells p = get_pages_array(count); 16827ff50620SDavid Howells if (!p) 16837ff50620SDavid Howells return -ENOMEM; 16847ff50620SDavid Howells *pages = p; 16857ff50620SDavid Howells 16867ff50620SDavid Howells nr = iter_xarray_populate_pages(p, i->xarray, index, count); 16877ff50620SDavid Howells if (nr == 0) 16887ff50620SDavid Howells return 0; 16897ff50620SDavid Howells 16907ff50620SDavid Howells actual = PAGE_SIZE * nr; 16917ff50620SDavid Howells actual -= offset; 16927ff50620SDavid Howells if (nr == count && size > 0) { 16937ff50620SDavid Howells unsigned last_offset = (nr > 1) ? 0 : offset; 16947ff50620SDavid Howells actual -= PAGE_SIZE - (last_offset + size); 16957ff50620SDavid Howells } 16967ff50620SDavid Howells return actual; 16977ff50620SDavid Howells } 16987ff50620SDavid Howells 1699d879cb83SAl Viro ssize_t iov_iter_get_pages_alloc(struct iov_iter *i, 1700d879cb83SAl Viro struct page ***pages, size_t maxsize, 1701d879cb83SAl Viro size_t *start) 1702d879cb83SAl Viro { 1703d879cb83SAl Viro struct page **p; 1704*3d671ca6SAl Viro size_t len; 1705*3d671ca6SAl Viro int n, res; 1706d879cb83SAl Viro 1707d879cb83SAl Viro if (maxsize > i->count) 1708d879cb83SAl Viro maxsize = i->count; 1709*3d671ca6SAl Viro if (!maxsize) 1710*3d671ca6SAl Viro return 0; 1711d879cb83SAl Viro 1712*3d671ca6SAl Viro if (likely(iter_is_iovec(i))) { 1713*3d671ca6SAl Viro unsigned long addr; 17149ea9ce04SDavid Howells 1715*3d671ca6SAl Viro addr = first_iovec_segment(i, &len, start, maxsize, ~0U); 1716d879cb83SAl Viro n = DIV_ROUND_UP(len, PAGE_SIZE); 1717d879cb83SAl Viro p = get_pages_array(n); 1718d879cb83SAl Viro if (!p) 1719d879cb83SAl Viro return -ENOMEM; 172073b0140bSIra Weiny res = get_user_pages_fast(addr, n, 172173b0140bSIra Weiny iov_iter_rw(i) != WRITE ? FOLL_WRITE : 0, p); 1722d879cb83SAl Viro if (unlikely(res < 0)) { 1723d879cb83SAl Viro kvfree(p); 1724d879cb83SAl Viro return res; 1725d879cb83SAl Viro } 1726d879cb83SAl Viro *pages = p; 1727d879cb83SAl Viro return (res == n ? len : res * PAGE_SIZE) - *start; 1728*3d671ca6SAl Viro } 1729*3d671ca6SAl Viro if (iov_iter_is_bvec(i)) { 1730*3d671ca6SAl Viro struct page *page; 1731*3d671ca6SAl Viro 1732*3d671ca6SAl Viro page = first_bvec_segment(i, &len, start, maxsize, ~0U); 1733*3d671ca6SAl Viro n = DIV_ROUND_UP(len, PAGE_SIZE); 1734*3d671ca6SAl Viro *pages = p = get_pages_array(n); 1735d879cb83SAl Viro if (!p) 1736d879cb83SAl Viro return -ENOMEM; 1737*3d671ca6SAl Viro while (n--) 1738*3d671ca6SAl Viro get_page(*p++ = page++); 1739*3d671ca6SAl Viro return len - *start; 1740*3d671ca6SAl Viro } 1741*3d671ca6SAl Viro if (iov_iter_is_pipe(i)) 1742*3d671ca6SAl Viro return pipe_get_pages_alloc(i, pages, maxsize, start); 1743*3d671ca6SAl Viro if (iov_iter_is_xarray(i)) 1744*3d671ca6SAl Viro return iter_xarray_get_pages_alloc(i, pages, maxsize, start); 1745d879cb83SAl Viro return -EFAULT; 1746d879cb83SAl Viro } 1747d879cb83SAl Viro EXPORT_SYMBOL(iov_iter_get_pages_alloc); 1748d879cb83SAl Viro 1749d879cb83SAl Viro size_t csum_and_copy_from_iter(void *addr, size_t bytes, __wsum *csum, 1750d879cb83SAl Viro struct iov_iter *i) 1751d879cb83SAl Viro { 1752d879cb83SAl Viro char *to = addr; 1753d879cb83SAl Viro __wsum sum, next; 1754d879cb83SAl Viro size_t off = 0; 1755d879cb83SAl Viro sum = *csum; 17569ea9ce04SDavid Howells if (unlikely(iov_iter_is_pipe(i) || iov_iter_is_discard(i))) { 1757241699cdSAl Viro WARN_ON(1); 1758241699cdSAl Viro return 0; 1759241699cdSAl Viro } 1760d879cb83SAl Viro iterate_and_advance(i, bytes, v, ({ 1761d879cb83SAl Viro next = csum_and_copy_from_user(v.iov_base, 1762d879cb83SAl Viro (to += v.iov_len) - v.iov_len, 1763c693cc46SAl Viro v.iov_len); 1764c693cc46SAl Viro if (next) { 1765d879cb83SAl Viro sum = csum_block_add(sum, next, off); 1766d879cb83SAl Viro off += v.iov_len; 1767d879cb83SAl Viro } 1768c693cc46SAl Viro next ? 0 : v.iov_len; 1769d879cb83SAl Viro }), ({ 1770d879cb83SAl Viro char *p = kmap_atomic(v.bv_page); 1771f9152895SAl Viro sum = csum_and_memcpy((to += v.bv_len) - v.bv_len, 1772f9152895SAl Viro p + v.bv_offset, v.bv_len, 1773f9152895SAl Viro sum, off); 1774d879cb83SAl Viro kunmap_atomic(p); 1775d879cb83SAl Viro off += v.bv_len; 1776d879cb83SAl Viro }),({ 1777f9152895SAl Viro sum = csum_and_memcpy((to += v.iov_len) - v.iov_len, 1778f9152895SAl Viro v.iov_base, v.iov_len, 1779f9152895SAl Viro sum, off); 1780d879cb83SAl Viro off += v.iov_len; 17817ff50620SDavid Howells }), ({ 17827ff50620SDavid Howells char *p = kmap_atomic(v.bv_page); 17837ff50620SDavid Howells sum = csum_and_memcpy((to += v.bv_len) - v.bv_len, 17847ff50620SDavid Howells p + v.bv_offset, v.bv_len, 17857ff50620SDavid Howells sum, off); 17867ff50620SDavid Howells kunmap_atomic(p); 17877ff50620SDavid Howells off += v.bv_len; 1788d879cb83SAl Viro }) 1789d879cb83SAl Viro ) 1790d879cb83SAl Viro *csum = sum; 1791d879cb83SAl Viro return bytes; 1792d879cb83SAl Viro } 1793d879cb83SAl Viro EXPORT_SYMBOL(csum_and_copy_from_iter); 1794d879cb83SAl Viro 179552cbd23aSWillem de Bruijn size_t csum_and_copy_to_iter(const void *addr, size_t bytes, void *_csstate, 1796d879cb83SAl Viro struct iov_iter *i) 1797d879cb83SAl Viro { 179852cbd23aSWillem de Bruijn struct csum_state *csstate = _csstate; 179936f7a8a4SAl Viro const char *from = addr; 1800d879cb83SAl Viro __wsum sum, next; 180152cbd23aSWillem de Bruijn size_t off; 180278e1f386SAl Viro 180378e1f386SAl Viro if (unlikely(iov_iter_is_pipe(i))) 180452cbd23aSWillem de Bruijn return csum_and_copy_to_pipe_iter(addr, bytes, _csstate, i); 180578e1f386SAl Viro 180652cbd23aSWillem de Bruijn sum = csstate->csum; 180752cbd23aSWillem de Bruijn off = csstate->off; 180878e1f386SAl Viro if (unlikely(iov_iter_is_discard(i))) { 1809241699cdSAl Viro WARN_ON(1); /* for now */ 1810241699cdSAl Viro return 0; 1811241699cdSAl Viro } 1812d879cb83SAl Viro iterate_and_advance(i, bytes, v, ({ 1813d879cb83SAl Viro next = csum_and_copy_to_user((from += v.iov_len) - v.iov_len, 1814d879cb83SAl Viro v.iov_base, 1815c693cc46SAl Viro v.iov_len); 1816c693cc46SAl Viro if (next) { 1817d879cb83SAl Viro sum = csum_block_add(sum, next, off); 1818d879cb83SAl Viro off += v.iov_len; 1819d879cb83SAl Viro } 1820c693cc46SAl Viro next ? 0 : v.iov_len; 1821d879cb83SAl Viro }), ({ 1822d879cb83SAl Viro char *p = kmap_atomic(v.bv_page); 1823f9152895SAl Viro sum = csum_and_memcpy(p + v.bv_offset, 1824f9152895SAl Viro (from += v.bv_len) - v.bv_len, 1825f9152895SAl Viro v.bv_len, sum, off); 1826d879cb83SAl Viro kunmap_atomic(p); 1827d879cb83SAl Viro off += v.bv_len; 1828d879cb83SAl Viro }),({ 1829f9152895SAl Viro sum = csum_and_memcpy(v.iov_base, 1830f9152895SAl Viro (from += v.iov_len) - v.iov_len, 1831f9152895SAl Viro v.iov_len, sum, off); 1832d879cb83SAl Viro off += v.iov_len; 18337ff50620SDavid Howells }), ({ 18347ff50620SDavid Howells char *p = kmap_atomic(v.bv_page); 18357ff50620SDavid Howells sum = csum_and_memcpy(p + v.bv_offset, 18367ff50620SDavid Howells (from += v.bv_len) - v.bv_len, 18377ff50620SDavid Howells v.bv_len, sum, off); 18387ff50620SDavid Howells kunmap_atomic(p); 18397ff50620SDavid Howells off += v.bv_len; 1840d879cb83SAl Viro }) 1841d879cb83SAl Viro ) 184252cbd23aSWillem de Bruijn csstate->csum = sum; 184352cbd23aSWillem de Bruijn csstate->off = off; 1844d879cb83SAl Viro return bytes; 1845d879cb83SAl Viro } 1846d879cb83SAl Viro EXPORT_SYMBOL(csum_and_copy_to_iter); 1847d879cb83SAl Viro 1848d05f4435SSagi Grimberg size_t hash_and_copy_to_iter(const void *addr, size_t bytes, void *hashp, 1849d05f4435SSagi Grimberg struct iov_iter *i) 1850d05f4435SSagi Grimberg { 18517999096fSHerbert Xu #ifdef CONFIG_CRYPTO_HASH 1852d05f4435SSagi Grimberg struct ahash_request *hash = hashp; 1853d05f4435SSagi Grimberg struct scatterlist sg; 1854d05f4435SSagi Grimberg size_t copied; 1855d05f4435SSagi Grimberg 1856d05f4435SSagi Grimberg copied = copy_to_iter(addr, bytes, i); 1857d05f4435SSagi Grimberg sg_init_one(&sg, addr, copied); 1858d05f4435SSagi Grimberg ahash_request_set_crypt(hash, &sg, NULL, copied); 1859d05f4435SSagi Grimberg crypto_ahash_update(hash); 1860d05f4435SSagi Grimberg return copied; 186127fad74aSYueHaibing #else 186227fad74aSYueHaibing return 0; 186327fad74aSYueHaibing #endif 1864d05f4435SSagi Grimberg } 1865d05f4435SSagi Grimberg EXPORT_SYMBOL(hash_and_copy_to_iter); 1866d05f4435SSagi Grimberg 1867d879cb83SAl Viro int iov_iter_npages(const struct iov_iter *i, int maxpages) 1868d879cb83SAl Viro { 1869d879cb83SAl Viro size_t size = i->count; 1870d879cb83SAl Viro int npages = 0; 1871d879cb83SAl Viro 1872d879cb83SAl Viro if (!size) 1873d879cb83SAl Viro return 0; 18749ea9ce04SDavid Howells if (unlikely(iov_iter_is_discard(i))) 18759ea9ce04SDavid Howells return 0; 1876d879cb83SAl Viro 187700e23707SDavid Howells if (unlikely(iov_iter_is_pipe(i))) { 1878241699cdSAl Viro struct pipe_inode_info *pipe = i->pipe; 18798cefc107SDavid Howells unsigned int iter_head; 1880241699cdSAl Viro size_t off; 1881241699cdSAl Viro 1882241699cdSAl Viro if (!sanity(i)) 1883241699cdSAl Viro return 0; 1884241699cdSAl Viro 18858cefc107SDavid Howells data_start(i, &iter_head, &off); 1886241699cdSAl Viro /* some of this one + all after this one */ 18878cefc107SDavid Howells npages = pipe_space_for_user(iter_head, pipe->tail, pipe); 1888241699cdSAl Viro if (npages >= maxpages) 1889241699cdSAl Viro return maxpages; 18907ff50620SDavid Howells } else if (unlikely(iov_iter_is_xarray(i))) { 18917ff50620SDavid Howells unsigned offset; 18927ff50620SDavid Howells 18937ff50620SDavid Howells offset = (i->xarray_start + i->iov_offset) & ~PAGE_MASK; 18947ff50620SDavid Howells 18957ff50620SDavid Howells npages = 1; 18967ff50620SDavid Howells if (size > PAGE_SIZE - offset) { 18977ff50620SDavid Howells size -= PAGE_SIZE - offset; 18987ff50620SDavid Howells npages += size >> PAGE_SHIFT; 18997ff50620SDavid Howells size &= ~PAGE_MASK; 19007ff50620SDavid Howells if (size) 19017ff50620SDavid Howells npages++; 19027ff50620SDavid Howells } 19037ff50620SDavid Howells if (npages >= maxpages) 19047ff50620SDavid Howells return maxpages; 1905241699cdSAl Viro } else iterate_all_kinds(i, size, v, ({ 1906d879cb83SAl Viro unsigned long p = (unsigned long)v.iov_base; 1907d879cb83SAl Viro npages += DIV_ROUND_UP(p + v.iov_len, PAGE_SIZE) 1908d879cb83SAl Viro - p / PAGE_SIZE; 1909d879cb83SAl Viro if (npages >= maxpages) 1910d879cb83SAl Viro return maxpages; 1911d879cb83SAl Viro 0;}),({ 1912d879cb83SAl Viro npages++; 1913d879cb83SAl Viro if (npages >= maxpages) 1914d879cb83SAl Viro return maxpages; 1915d879cb83SAl Viro }),({ 1916d879cb83SAl Viro unsigned long p = (unsigned long)v.iov_base; 1917d879cb83SAl Viro npages += DIV_ROUND_UP(p + v.iov_len, PAGE_SIZE) 1918d879cb83SAl Viro - p / PAGE_SIZE; 1919d879cb83SAl Viro if (npages >= maxpages) 1920d879cb83SAl Viro return maxpages; 19217ff50620SDavid Howells }), 19227ff50620SDavid Howells 0 1923d879cb83SAl Viro ) 1924d879cb83SAl Viro return npages; 1925d879cb83SAl Viro } 1926d879cb83SAl Viro EXPORT_SYMBOL(iov_iter_npages); 1927d879cb83SAl Viro 1928d879cb83SAl Viro const void *dup_iter(struct iov_iter *new, struct iov_iter *old, gfp_t flags) 1929d879cb83SAl Viro { 1930d879cb83SAl Viro *new = *old; 193100e23707SDavid Howells if (unlikely(iov_iter_is_pipe(new))) { 1932241699cdSAl Viro WARN_ON(1); 1933241699cdSAl Viro return NULL; 1934241699cdSAl Viro } 19357ff50620SDavid Howells if (unlikely(iov_iter_is_discard(new) || iov_iter_is_xarray(new))) 19369ea9ce04SDavid Howells return NULL; 193700e23707SDavid Howells if (iov_iter_is_bvec(new)) 1938d879cb83SAl Viro return new->bvec = kmemdup(new->bvec, 1939d879cb83SAl Viro new->nr_segs * sizeof(struct bio_vec), 1940d879cb83SAl Viro flags); 1941d879cb83SAl Viro else 1942d879cb83SAl Viro /* iovec and kvec have identical layout */ 1943d879cb83SAl Viro return new->iov = kmemdup(new->iov, 1944d879cb83SAl Viro new->nr_segs * sizeof(struct iovec), 1945d879cb83SAl Viro flags); 1946d879cb83SAl Viro } 1947d879cb83SAl Viro EXPORT_SYMBOL(dup_iter); 1948bc917be8SAl Viro 1949bfdc5970SChristoph Hellwig static int copy_compat_iovec_from_user(struct iovec *iov, 1950bfdc5970SChristoph Hellwig const struct iovec __user *uvec, unsigned long nr_segs) 1951bfdc5970SChristoph Hellwig { 1952bfdc5970SChristoph Hellwig const struct compat_iovec __user *uiov = 1953bfdc5970SChristoph Hellwig (const struct compat_iovec __user *)uvec; 1954bfdc5970SChristoph Hellwig int ret = -EFAULT, i; 1955bfdc5970SChristoph Hellwig 1956a959a978SChristoph Hellwig if (!user_access_begin(uiov, nr_segs * sizeof(*uiov))) 1957bfdc5970SChristoph Hellwig return -EFAULT; 1958bfdc5970SChristoph Hellwig 1959bfdc5970SChristoph Hellwig for (i = 0; i < nr_segs; i++) { 1960bfdc5970SChristoph Hellwig compat_uptr_t buf; 1961bfdc5970SChristoph Hellwig compat_ssize_t len; 1962bfdc5970SChristoph Hellwig 1963bfdc5970SChristoph Hellwig unsafe_get_user(len, &uiov[i].iov_len, uaccess_end); 1964bfdc5970SChristoph Hellwig unsafe_get_user(buf, &uiov[i].iov_base, uaccess_end); 1965bfdc5970SChristoph Hellwig 1966bfdc5970SChristoph Hellwig /* check for compat_size_t not fitting in compat_ssize_t .. */ 1967bfdc5970SChristoph Hellwig if (len < 0) { 1968bfdc5970SChristoph Hellwig ret = -EINVAL; 1969bfdc5970SChristoph Hellwig goto uaccess_end; 1970bfdc5970SChristoph Hellwig } 1971bfdc5970SChristoph Hellwig iov[i].iov_base = compat_ptr(buf); 1972bfdc5970SChristoph Hellwig iov[i].iov_len = len; 1973bfdc5970SChristoph Hellwig } 1974bfdc5970SChristoph Hellwig 1975bfdc5970SChristoph Hellwig ret = 0; 1976bfdc5970SChristoph Hellwig uaccess_end: 1977bfdc5970SChristoph Hellwig user_access_end(); 1978bfdc5970SChristoph Hellwig return ret; 1979bfdc5970SChristoph Hellwig } 1980bfdc5970SChristoph Hellwig 1981bfdc5970SChristoph Hellwig static int copy_iovec_from_user(struct iovec *iov, 1982bfdc5970SChristoph Hellwig const struct iovec __user *uvec, unsigned long nr_segs) 1983fb041b59SDavid Laight { 1984fb041b59SDavid Laight unsigned long seg; 1985bfdc5970SChristoph Hellwig 1986bfdc5970SChristoph Hellwig if (copy_from_user(iov, uvec, nr_segs * sizeof(*uvec))) 1987bfdc5970SChristoph Hellwig return -EFAULT; 1988bfdc5970SChristoph Hellwig for (seg = 0; seg < nr_segs; seg++) { 1989bfdc5970SChristoph Hellwig if ((ssize_t)iov[seg].iov_len < 0) 1990bfdc5970SChristoph Hellwig return -EINVAL; 1991bfdc5970SChristoph Hellwig } 1992bfdc5970SChristoph Hellwig 1993bfdc5970SChristoph Hellwig return 0; 1994bfdc5970SChristoph Hellwig } 1995bfdc5970SChristoph Hellwig 1996bfdc5970SChristoph Hellwig struct iovec *iovec_from_user(const struct iovec __user *uvec, 1997bfdc5970SChristoph Hellwig unsigned long nr_segs, unsigned long fast_segs, 1998bfdc5970SChristoph Hellwig struct iovec *fast_iov, bool compat) 1999bfdc5970SChristoph Hellwig { 2000bfdc5970SChristoph Hellwig struct iovec *iov = fast_iov; 2001bfdc5970SChristoph Hellwig int ret; 2002fb041b59SDavid Laight 2003fb041b59SDavid Laight /* 2004bfdc5970SChristoph Hellwig * SuS says "The readv() function *may* fail if the iovcnt argument was 2005bfdc5970SChristoph Hellwig * less than or equal to 0, or greater than {IOV_MAX}. Linux has 2006fb041b59SDavid Laight * traditionally returned zero for zero segments, so... 2007fb041b59SDavid Laight */ 2008bfdc5970SChristoph Hellwig if (nr_segs == 0) 2009bfdc5970SChristoph Hellwig return iov; 2010bfdc5970SChristoph Hellwig if (nr_segs > UIO_MAXIOV) 2011bfdc5970SChristoph Hellwig return ERR_PTR(-EINVAL); 2012fb041b59SDavid Laight if (nr_segs > fast_segs) { 2013fb041b59SDavid Laight iov = kmalloc_array(nr_segs, sizeof(struct iovec), GFP_KERNEL); 2014bfdc5970SChristoph Hellwig if (!iov) 2015bfdc5970SChristoph Hellwig return ERR_PTR(-ENOMEM); 2016fb041b59SDavid Laight } 2017bfdc5970SChristoph Hellwig 2018bfdc5970SChristoph Hellwig if (compat) 2019bfdc5970SChristoph Hellwig ret = copy_compat_iovec_from_user(iov, uvec, nr_segs); 2020bfdc5970SChristoph Hellwig else 2021bfdc5970SChristoph Hellwig ret = copy_iovec_from_user(iov, uvec, nr_segs); 2022bfdc5970SChristoph Hellwig if (ret) { 2023bfdc5970SChristoph Hellwig if (iov != fast_iov) 2024bfdc5970SChristoph Hellwig kfree(iov); 2025bfdc5970SChristoph Hellwig return ERR_PTR(ret); 2026fb041b59SDavid Laight } 2027bfdc5970SChristoph Hellwig 2028bfdc5970SChristoph Hellwig return iov; 2029bfdc5970SChristoph Hellwig } 2030bfdc5970SChristoph Hellwig 2031bfdc5970SChristoph Hellwig ssize_t __import_iovec(int type, const struct iovec __user *uvec, 2032bfdc5970SChristoph Hellwig unsigned nr_segs, unsigned fast_segs, struct iovec **iovp, 2033bfdc5970SChristoph Hellwig struct iov_iter *i, bool compat) 2034bfdc5970SChristoph Hellwig { 2035bfdc5970SChristoph Hellwig ssize_t total_len = 0; 2036bfdc5970SChristoph Hellwig unsigned long seg; 2037bfdc5970SChristoph Hellwig struct iovec *iov; 2038bfdc5970SChristoph Hellwig 2039bfdc5970SChristoph Hellwig iov = iovec_from_user(uvec, nr_segs, fast_segs, *iovp, compat); 2040bfdc5970SChristoph Hellwig if (IS_ERR(iov)) { 2041bfdc5970SChristoph Hellwig *iovp = NULL; 2042bfdc5970SChristoph Hellwig return PTR_ERR(iov); 2043fb041b59SDavid Laight } 2044fb041b59SDavid Laight 2045fb041b59SDavid Laight /* 2046bfdc5970SChristoph Hellwig * According to the Single Unix Specification we should return EINVAL if 2047bfdc5970SChristoph Hellwig * an element length is < 0 when cast to ssize_t or if the total length 2048bfdc5970SChristoph Hellwig * would overflow the ssize_t return value of the system call. 2049fb041b59SDavid Laight * 2050fb041b59SDavid Laight * Linux caps all read/write calls to MAX_RW_COUNT, and avoids the 2051fb041b59SDavid Laight * overflow case. 2052fb041b59SDavid Laight */ 2053fb041b59SDavid Laight for (seg = 0; seg < nr_segs; seg++) { 2054fb041b59SDavid Laight ssize_t len = (ssize_t)iov[seg].iov_len; 2055fb041b59SDavid Laight 2056bfdc5970SChristoph Hellwig if (!access_ok(iov[seg].iov_base, len)) { 2057bfdc5970SChristoph Hellwig if (iov != *iovp) 2058bfdc5970SChristoph Hellwig kfree(iov); 2059bfdc5970SChristoph Hellwig *iovp = NULL; 2060bfdc5970SChristoph Hellwig return -EFAULT; 2061fb041b59SDavid Laight } 2062bfdc5970SChristoph Hellwig 2063bfdc5970SChristoph Hellwig if (len > MAX_RW_COUNT - total_len) { 2064bfdc5970SChristoph Hellwig len = MAX_RW_COUNT - total_len; 2065fb041b59SDavid Laight iov[seg].iov_len = len; 2066fb041b59SDavid Laight } 2067bfdc5970SChristoph Hellwig total_len += len; 2068fb041b59SDavid Laight } 2069bfdc5970SChristoph Hellwig 2070bfdc5970SChristoph Hellwig iov_iter_init(i, type, iov, nr_segs, total_len); 2071bfdc5970SChristoph Hellwig if (iov == *iovp) 2072bfdc5970SChristoph Hellwig *iovp = NULL; 2073bfdc5970SChristoph Hellwig else 2074bfdc5970SChristoph Hellwig *iovp = iov; 2075bfdc5970SChristoph Hellwig return total_len; 2076fb041b59SDavid Laight } 2077fb041b59SDavid Laight 2078ffecee4fSVegard Nossum /** 2079ffecee4fSVegard Nossum * import_iovec() - Copy an array of &struct iovec from userspace 2080ffecee4fSVegard Nossum * into the kernel, check that it is valid, and initialize a new 2081ffecee4fSVegard Nossum * &struct iov_iter iterator to access it. 2082ffecee4fSVegard Nossum * 2083ffecee4fSVegard Nossum * @type: One of %READ or %WRITE. 2084bfdc5970SChristoph Hellwig * @uvec: Pointer to the userspace array. 2085ffecee4fSVegard Nossum * @nr_segs: Number of elements in userspace array. 2086ffecee4fSVegard Nossum * @fast_segs: Number of elements in @iov. 2087bfdc5970SChristoph Hellwig * @iovp: (input and output parameter) Pointer to pointer to (usually small 2088ffecee4fSVegard Nossum * on-stack) kernel array. 2089ffecee4fSVegard Nossum * @i: Pointer to iterator that will be initialized on success. 2090ffecee4fSVegard Nossum * 2091ffecee4fSVegard Nossum * If the array pointed to by *@iov is large enough to hold all @nr_segs, 2092ffecee4fSVegard Nossum * then this function places %NULL in *@iov on return. Otherwise, a new 2093ffecee4fSVegard Nossum * array will be allocated and the result placed in *@iov. This means that 2094ffecee4fSVegard Nossum * the caller may call kfree() on *@iov regardless of whether the small 2095ffecee4fSVegard Nossum * on-stack array was used or not (and regardless of whether this function 2096ffecee4fSVegard Nossum * returns an error or not). 2097ffecee4fSVegard Nossum * 209887e5e6daSJens Axboe * Return: Negative error code on error, bytes imported on success 2099ffecee4fSVegard Nossum */ 2100bfdc5970SChristoph Hellwig ssize_t import_iovec(int type, const struct iovec __user *uvec, 2101bc917be8SAl Viro unsigned nr_segs, unsigned fast_segs, 2102bfdc5970SChristoph Hellwig struct iovec **iovp, struct iov_iter *i) 2103bc917be8SAl Viro { 210489cd35c5SChristoph Hellwig return __import_iovec(type, uvec, nr_segs, fast_segs, iovp, i, 210589cd35c5SChristoph Hellwig in_compat_syscall()); 2106bc917be8SAl Viro } 2107bc917be8SAl Viro EXPORT_SYMBOL(import_iovec); 2108bc917be8SAl Viro 2109bc917be8SAl Viro int import_single_range(int rw, void __user *buf, size_t len, 2110bc917be8SAl Viro struct iovec *iov, struct iov_iter *i) 2111bc917be8SAl Viro { 2112bc917be8SAl Viro if (len > MAX_RW_COUNT) 2113bc917be8SAl Viro len = MAX_RW_COUNT; 211496d4f267SLinus Torvalds if (unlikely(!access_ok(buf, len))) 2115bc917be8SAl Viro return -EFAULT; 2116bc917be8SAl Viro 2117bc917be8SAl Viro iov->iov_base = buf; 2118bc917be8SAl Viro iov->iov_len = len; 2119bc917be8SAl Viro iov_iter_init(i, rw, iov, 1, len); 2120bc917be8SAl Viro return 0; 2121bc917be8SAl Viro } 2122e1267585SAl Viro EXPORT_SYMBOL(import_single_range); 2123