1457c8996SThomas Gleixner // SPDX-License-Identifier: GPL-2.0-only 27999096fSHerbert Xu #include <crypto/hash.h> 3d879cb83SAl Viro #include <linux/export.h> 42f8b5444SChristoph Hellwig #include <linux/bvec.h> 54d0e9df5SAlbert van der Linde #include <linux/fault-inject-usercopy.h> 6d879cb83SAl Viro #include <linux/uio.h> 7d879cb83SAl Viro #include <linux/pagemap.h> 8d879cb83SAl Viro #include <linux/slab.h> 9d879cb83SAl Viro #include <linux/vmalloc.h> 10241699cdSAl Viro #include <linux/splice.h> 11bfdc5970SChristoph Hellwig #include <linux/compat.h> 12d879cb83SAl Viro #include <net/checksum.h> 13d05f4435SSagi Grimberg #include <linux/scatterlist.h> 14d0ef4c36SMarco Elver #include <linux/instrumented.h> 15d879cb83SAl Viro 16241699cdSAl Viro #define PIPE_PARANOIA /* for now */ 17241699cdSAl Viro 18d879cb83SAl Viro #define iterate_iovec(i, n, __v, __p, skip, STEP) { \ 19d879cb83SAl Viro size_t left; \ 20d879cb83SAl Viro size_t wanted = n; \ 21d879cb83SAl Viro __p = i->iov; \ 22d879cb83SAl Viro __v.iov_len = min(n, __p->iov_len - skip); \ 23d879cb83SAl Viro if (likely(__v.iov_len)) { \ 24d879cb83SAl Viro __v.iov_base = __p->iov_base + skip; \ 25d879cb83SAl Viro left = (STEP); \ 26d879cb83SAl Viro __v.iov_len -= left; \ 27d879cb83SAl Viro skip += __v.iov_len; \ 28d879cb83SAl Viro n -= __v.iov_len; \ 29d879cb83SAl Viro } else { \ 30d879cb83SAl Viro left = 0; \ 31d879cb83SAl Viro } \ 32d879cb83SAl Viro while (unlikely(!left && n)) { \ 33d879cb83SAl Viro __p++; \ 34d879cb83SAl Viro __v.iov_len = min(n, __p->iov_len); \ 35d879cb83SAl Viro if (unlikely(!__v.iov_len)) \ 36d879cb83SAl Viro continue; \ 37d879cb83SAl Viro __v.iov_base = __p->iov_base; \ 38d879cb83SAl Viro left = (STEP); \ 39d879cb83SAl Viro __v.iov_len -= left; \ 40d879cb83SAl Viro skip = __v.iov_len; \ 41d879cb83SAl Viro n -= __v.iov_len; \ 42d879cb83SAl Viro } \ 43d879cb83SAl Viro n = wanted - n; \ 44d879cb83SAl Viro } 45d879cb83SAl Viro 46d879cb83SAl Viro #define iterate_kvec(i, n, __v, __p, skip, STEP) { \ 47d879cb83SAl Viro size_t wanted = n; \ 48d879cb83SAl Viro __p = i->kvec; \ 49d879cb83SAl Viro __v.iov_len = min(n, __p->iov_len - skip); \ 50d879cb83SAl Viro if (likely(__v.iov_len)) { \ 51d879cb83SAl Viro __v.iov_base = __p->iov_base + skip; \ 52d879cb83SAl Viro (void)(STEP); \ 53d879cb83SAl Viro skip += __v.iov_len; \ 54d879cb83SAl Viro n -= __v.iov_len; \ 55d879cb83SAl Viro } \ 56d879cb83SAl Viro while (unlikely(n)) { \ 57d879cb83SAl Viro __p++; \ 58d879cb83SAl Viro __v.iov_len = min(n, __p->iov_len); \ 59d879cb83SAl Viro if (unlikely(!__v.iov_len)) \ 60d879cb83SAl Viro continue; \ 61d879cb83SAl Viro __v.iov_base = __p->iov_base; \ 62d879cb83SAl Viro (void)(STEP); \ 63d879cb83SAl Viro skip = __v.iov_len; \ 64d879cb83SAl Viro n -= __v.iov_len; \ 65d879cb83SAl Viro } \ 66d879cb83SAl Viro n = wanted; \ 67d879cb83SAl Viro } 68d879cb83SAl Viro 691bdc76aeSMing Lei #define iterate_bvec(i, n, __v, __bi, skip, STEP) { \ 701bdc76aeSMing Lei struct bvec_iter __start; \ 711bdc76aeSMing Lei __start.bi_size = n; \ 721bdc76aeSMing Lei __start.bi_bvec_done = skip; \ 731bdc76aeSMing Lei __start.bi_idx = 0; \ 741bdc76aeSMing Lei for_each_bvec(__v, i->bvec, __bi, __start) { \ 75d879cb83SAl Viro (void)(STEP); \ 76d879cb83SAl Viro } \ 77d879cb83SAl Viro } 78d879cb83SAl Viro 79d879cb83SAl Viro #define iterate_all_kinds(i, n, v, I, B, K) { \ 8033844e66SAl Viro if (likely(n)) { \ 81d879cb83SAl Viro size_t skip = i->iov_offset; \ 82d879cb83SAl Viro if (unlikely(i->type & ITER_BVEC)) { \ 83d879cb83SAl Viro struct bio_vec v; \ 841bdc76aeSMing Lei struct bvec_iter __bi; \ 851bdc76aeSMing Lei iterate_bvec(i, n, v, __bi, skip, (B)) \ 86d879cb83SAl Viro } else if (unlikely(i->type & ITER_KVEC)) { \ 87d879cb83SAl Viro const struct kvec *kvec; \ 88d879cb83SAl Viro struct kvec v; \ 89d879cb83SAl Viro iterate_kvec(i, n, v, kvec, skip, (K)) \ 909ea9ce04SDavid Howells } else if (unlikely(i->type & ITER_DISCARD)) { \ 91d879cb83SAl Viro } else { \ 92d879cb83SAl Viro const struct iovec *iov; \ 93d879cb83SAl Viro struct iovec v; \ 94d879cb83SAl Viro iterate_iovec(i, n, v, iov, skip, (I)) \ 95d879cb83SAl Viro } \ 9633844e66SAl Viro } \ 97d879cb83SAl Viro } 98d879cb83SAl Viro 99d879cb83SAl Viro #define iterate_and_advance(i, n, v, I, B, K) { \ 100dd254f5aSAl Viro if (unlikely(i->count < n)) \ 101dd254f5aSAl Viro n = i->count; \ 10219f18459SAl Viro if (i->count) { \ 103d879cb83SAl Viro size_t skip = i->iov_offset; \ 104d879cb83SAl Viro if (unlikely(i->type & ITER_BVEC)) { \ 1051bdc76aeSMing Lei const struct bio_vec *bvec = i->bvec; \ 106d879cb83SAl Viro struct bio_vec v; \ 1071bdc76aeSMing Lei struct bvec_iter __bi; \ 1081bdc76aeSMing Lei iterate_bvec(i, n, v, __bi, skip, (B)) \ 1091bdc76aeSMing Lei i->bvec = __bvec_iter_bvec(i->bvec, __bi); \ 1101bdc76aeSMing Lei i->nr_segs -= i->bvec - bvec; \ 1111bdc76aeSMing Lei skip = __bi.bi_bvec_done; \ 112d879cb83SAl Viro } else if (unlikely(i->type & ITER_KVEC)) { \ 113d879cb83SAl Viro const struct kvec *kvec; \ 114d879cb83SAl Viro struct kvec v; \ 115d879cb83SAl Viro iterate_kvec(i, n, v, kvec, skip, (K)) \ 116d879cb83SAl Viro if (skip == kvec->iov_len) { \ 117d879cb83SAl Viro kvec++; \ 118d879cb83SAl Viro skip = 0; \ 119d879cb83SAl Viro } \ 120d879cb83SAl Viro i->nr_segs -= kvec - i->kvec; \ 121d879cb83SAl Viro i->kvec = kvec; \ 1229ea9ce04SDavid Howells } else if (unlikely(i->type & ITER_DISCARD)) { \ 1239ea9ce04SDavid Howells skip += n; \ 124d879cb83SAl Viro } else { \ 125d879cb83SAl Viro const struct iovec *iov; \ 126d879cb83SAl Viro struct iovec v; \ 127d879cb83SAl Viro iterate_iovec(i, n, v, iov, skip, (I)) \ 128d879cb83SAl Viro if (skip == iov->iov_len) { \ 129d879cb83SAl Viro iov++; \ 130d879cb83SAl Viro skip = 0; \ 131d879cb83SAl Viro } \ 132d879cb83SAl Viro i->nr_segs -= iov - i->iov; \ 133d879cb83SAl Viro i->iov = iov; \ 134d879cb83SAl Viro } \ 135d879cb83SAl Viro i->count -= n; \ 136d879cb83SAl Viro i->iov_offset = skip; \ 137dd254f5aSAl Viro } \ 138d879cb83SAl Viro } 139d879cb83SAl Viro 14009fc68dcSAl Viro static int copyout(void __user *to, const void *from, size_t n) 14109fc68dcSAl Viro { 1424d0e9df5SAlbert van der Linde if (should_fail_usercopy()) 1434d0e9df5SAlbert van der Linde return n; 14496d4f267SLinus Torvalds if (access_ok(to, n)) { 145d0ef4c36SMarco Elver instrument_copy_to_user(to, from, n); 14609fc68dcSAl Viro n = raw_copy_to_user(to, from, n); 14709fc68dcSAl Viro } 14809fc68dcSAl Viro return n; 14909fc68dcSAl Viro } 15009fc68dcSAl Viro 15109fc68dcSAl Viro static int copyin(void *to, const void __user *from, size_t n) 15209fc68dcSAl Viro { 1534d0e9df5SAlbert van der Linde if (should_fail_usercopy()) 1544d0e9df5SAlbert van der Linde return n; 15596d4f267SLinus Torvalds if (access_ok(from, n)) { 156d0ef4c36SMarco Elver instrument_copy_from_user(to, from, n); 15709fc68dcSAl Viro n = raw_copy_from_user(to, from, n); 15809fc68dcSAl Viro } 15909fc68dcSAl Viro return n; 16009fc68dcSAl Viro } 16109fc68dcSAl Viro 162d879cb83SAl Viro static size_t copy_page_to_iter_iovec(struct page *page, size_t offset, size_t bytes, 163d879cb83SAl Viro struct iov_iter *i) 164d879cb83SAl Viro { 165d879cb83SAl Viro size_t skip, copy, left, wanted; 166d879cb83SAl Viro const struct iovec *iov; 167d879cb83SAl Viro char __user *buf; 168d879cb83SAl Viro void *kaddr, *from; 169d879cb83SAl Viro 170d879cb83SAl Viro if (unlikely(bytes > i->count)) 171d879cb83SAl Viro bytes = i->count; 172d879cb83SAl Viro 173d879cb83SAl Viro if (unlikely(!bytes)) 174d879cb83SAl Viro return 0; 175d879cb83SAl Viro 17609fc68dcSAl Viro might_fault(); 177d879cb83SAl Viro wanted = bytes; 178d879cb83SAl Viro iov = i->iov; 179d879cb83SAl Viro skip = i->iov_offset; 180d879cb83SAl Viro buf = iov->iov_base + skip; 181d879cb83SAl Viro copy = min(bytes, iov->iov_len - skip); 182d879cb83SAl Viro 1833fa6c507SMikulas Patocka if (IS_ENABLED(CONFIG_HIGHMEM) && !fault_in_pages_writeable(buf, copy)) { 184d879cb83SAl Viro kaddr = kmap_atomic(page); 185d879cb83SAl Viro from = kaddr + offset; 186d879cb83SAl Viro 187d879cb83SAl Viro /* first chunk, usually the only one */ 18809fc68dcSAl Viro left = copyout(buf, from, copy); 189d879cb83SAl Viro copy -= left; 190d879cb83SAl Viro skip += copy; 191d879cb83SAl Viro from += copy; 192d879cb83SAl Viro bytes -= copy; 193d879cb83SAl Viro 194d879cb83SAl Viro while (unlikely(!left && bytes)) { 195d879cb83SAl Viro iov++; 196d879cb83SAl Viro buf = iov->iov_base; 197d879cb83SAl Viro copy = min(bytes, iov->iov_len); 19809fc68dcSAl Viro left = copyout(buf, from, copy); 199d879cb83SAl Viro copy -= left; 200d879cb83SAl Viro skip = copy; 201d879cb83SAl Viro from += copy; 202d879cb83SAl Viro bytes -= copy; 203d879cb83SAl Viro } 204d879cb83SAl Viro if (likely(!bytes)) { 205d879cb83SAl Viro kunmap_atomic(kaddr); 206d879cb83SAl Viro goto done; 207d879cb83SAl Viro } 208d879cb83SAl Viro offset = from - kaddr; 209d879cb83SAl Viro buf += copy; 210d879cb83SAl Viro kunmap_atomic(kaddr); 211d879cb83SAl Viro copy = min(bytes, iov->iov_len - skip); 212d879cb83SAl Viro } 213d879cb83SAl Viro /* Too bad - revert to non-atomic kmap */ 2143fa6c507SMikulas Patocka 215d879cb83SAl Viro kaddr = kmap(page); 216d879cb83SAl Viro from = kaddr + offset; 21709fc68dcSAl Viro left = copyout(buf, from, copy); 218d879cb83SAl Viro copy -= left; 219d879cb83SAl Viro skip += copy; 220d879cb83SAl Viro from += copy; 221d879cb83SAl Viro bytes -= copy; 222d879cb83SAl Viro while (unlikely(!left && bytes)) { 223d879cb83SAl Viro iov++; 224d879cb83SAl Viro buf = iov->iov_base; 225d879cb83SAl Viro copy = min(bytes, iov->iov_len); 22609fc68dcSAl Viro left = copyout(buf, from, copy); 227d879cb83SAl Viro copy -= left; 228d879cb83SAl Viro skip = copy; 229d879cb83SAl Viro from += copy; 230d879cb83SAl Viro bytes -= copy; 231d879cb83SAl Viro } 232d879cb83SAl Viro kunmap(page); 2333fa6c507SMikulas Patocka 234d879cb83SAl Viro done: 235d879cb83SAl Viro if (skip == iov->iov_len) { 236d879cb83SAl Viro iov++; 237d879cb83SAl Viro skip = 0; 238d879cb83SAl Viro } 239d879cb83SAl Viro i->count -= wanted - bytes; 240d879cb83SAl Viro i->nr_segs -= iov - i->iov; 241d879cb83SAl Viro i->iov = iov; 242d879cb83SAl Viro i->iov_offset = skip; 243d879cb83SAl Viro return wanted - bytes; 244d879cb83SAl Viro } 245d879cb83SAl Viro 246d879cb83SAl Viro static size_t copy_page_from_iter_iovec(struct page *page, size_t offset, size_t bytes, 247d879cb83SAl Viro struct iov_iter *i) 248d879cb83SAl Viro { 249d879cb83SAl Viro size_t skip, copy, left, wanted; 250d879cb83SAl Viro const struct iovec *iov; 251d879cb83SAl Viro char __user *buf; 252d879cb83SAl Viro void *kaddr, *to; 253d879cb83SAl Viro 254d879cb83SAl Viro if (unlikely(bytes > i->count)) 255d879cb83SAl Viro bytes = i->count; 256d879cb83SAl Viro 257d879cb83SAl Viro if (unlikely(!bytes)) 258d879cb83SAl Viro return 0; 259d879cb83SAl Viro 26009fc68dcSAl Viro might_fault(); 261d879cb83SAl Viro wanted = bytes; 262d879cb83SAl Viro iov = i->iov; 263d879cb83SAl Viro skip = i->iov_offset; 264d879cb83SAl Viro buf = iov->iov_base + skip; 265d879cb83SAl Viro copy = min(bytes, iov->iov_len - skip); 266d879cb83SAl Viro 2673fa6c507SMikulas Patocka if (IS_ENABLED(CONFIG_HIGHMEM) && !fault_in_pages_readable(buf, copy)) { 268d879cb83SAl Viro kaddr = kmap_atomic(page); 269d879cb83SAl Viro to = kaddr + offset; 270d879cb83SAl Viro 271d879cb83SAl Viro /* first chunk, usually the only one */ 27209fc68dcSAl Viro left = copyin(to, buf, copy); 273d879cb83SAl Viro copy -= left; 274d879cb83SAl Viro skip += copy; 275d879cb83SAl Viro to += copy; 276d879cb83SAl Viro bytes -= copy; 277d879cb83SAl Viro 278d879cb83SAl Viro while (unlikely(!left && bytes)) { 279d879cb83SAl Viro iov++; 280d879cb83SAl Viro buf = iov->iov_base; 281d879cb83SAl Viro copy = min(bytes, iov->iov_len); 28209fc68dcSAl Viro left = copyin(to, buf, copy); 283d879cb83SAl Viro copy -= left; 284d879cb83SAl Viro skip = copy; 285d879cb83SAl Viro to += copy; 286d879cb83SAl Viro bytes -= copy; 287d879cb83SAl Viro } 288d879cb83SAl Viro if (likely(!bytes)) { 289d879cb83SAl Viro kunmap_atomic(kaddr); 290d879cb83SAl Viro goto done; 291d879cb83SAl Viro } 292d879cb83SAl Viro offset = to - kaddr; 293d879cb83SAl Viro buf += copy; 294d879cb83SAl Viro kunmap_atomic(kaddr); 295d879cb83SAl Viro copy = min(bytes, iov->iov_len - skip); 296d879cb83SAl Viro } 297d879cb83SAl Viro /* Too bad - revert to non-atomic kmap */ 2983fa6c507SMikulas Patocka 299d879cb83SAl Viro kaddr = kmap(page); 300d879cb83SAl Viro to = kaddr + offset; 30109fc68dcSAl Viro left = copyin(to, buf, copy); 302d879cb83SAl Viro copy -= left; 303d879cb83SAl Viro skip += copy; 304d879cb83SAl Viro to += copy; 305d879cb83SAl Viro bytes -= copy; 306d879cb83SAl Viro while (unlikely(!left && bytes)) { 307d879cb83SAl Viro iov++; 308d879cb83SAl Viro buf = iov->iov_base; 309d879cb83SAl Viro copy = min(bytes, iov->iov_len); 31009fc68dcSAl Viro left = copyin(to, buf, copy); 311d879cb83SAl Viro copy -= left; 312d879cb83SAl Viro skip = copy; 313d879cb83SAl Viro to += copy; 314d879cb83SAl Viro bytes -= copy; 315d879cb83SAl Viro } 316d879cb83SAl Viro kunmap(page); 3173fa6c507SMikulas Patocka 318d879cb83SAl Viro done: 319d879cb83SAl Viro if (skip == iov->iov_len) { 320d879cb83SAl Viro iov++; 321d879cb83SAl Viro skip = 0; 322d879cb83SAl Viro } 323d879cb83SAl Viro i->count -= wanted - bytes; 324d879cb83SAl Viro i->nr_segs -= iov - i->iov; 325d879cb83SAl Viro i->iov = iov; 326d879cb83SAl Viro i->iov_offset = skip; 327d879cb83SAl Viro return wanted - bytes; 328d879cb83SAl Viro } 329d879cb83SAl Viro 330241699cdSAl Viro #ifdef PIPE_PARANOIA 331241699cdSAl Viro static bool sanity(const struct iov_iter *i) 332241699cdSAl Viro { 333241699cdSAl Viro struct pipe_inode_info *pipe = i->pipe; 3348cefc107SDavid Howells unsigned int p_head = pipe->head; 3358cefc107SDavid Howells unsigned int p_tail = pipe->tail; 3368cefc107SDavid Howells unsigned int p_mask = pipe->ring_size - 1; 3378cefc107SDavid Howells unsigned int p_occupancy = pipe_occupancy(p_head, p_tail); 3388cefc107SDavid Howells unsigned int i_head = i->head; 3398cefc107SDavid Howells unsigned int idx; 3408cefc107SDavid Howells 341241699cdSAl Viro if (i->iov_offset) { 342241699cdSAl Viro struct pipe_buffer *p; 3438cefc107SDavid Howells if (unlikely(p_occupancy == 0)) 344241699cdSAl Viro goto Bad; // pipe must be non-empty 3458cefc107SDavid Howells if (unlikely(i_head != p_head - 1)) 346241699cdSAl Viro goto Bad; // must be at the last buffer... 347241699cdSAl Viro 3488cefc107SDavid Howells p = &pipe->bufs[i_head & p_mask]; 349241699cdSAl Viro if (unlikely(p->offset + p->len != i->iov_offset)) 350241699cdSAl Viro goto Bad; // ... at the end of segment 351241699cdSAl Viro } else { 3528cefc107SDavid Howells if (i_head != p_head) 353241699cdSAl Viro goto Bad; // must be right after the last buffer 354241699cdSAl Viro } 355241699cdSAl Viro return true; 356241699cdSAl Viro Bad: 3578cefc107SDavid Howells printk(KERN_ERR "idx = %d, offset = %zd\n", i_head, i->iov_offset); 3588cefc107SDavid Howells printk(KERN_ERR "head = %d, tail = %d, buffers = %d\n", 3598cefc107SDavid Howells p_head, p_tail, pipe->ring_size); 3608cefc107SDavid Howells for (idx = 0; idx < pipe->ring_size; idx++) 361241699cdSAl Viro printk(KERN_ERR "[%p %p %d %d]\n", 362241699cdSAl Viro pipe->bufs[idx].ops, 363241699cdSAl Viro pipe->bufs[idx].page, 364241699cdSAl Viro pipe->bufs[idx].offset, 365241699cdSAl Viro pipe->bufs[idx].len); 366241699cdSAl Viro WARN_ON(1); 367241699cdSAl Viro return false; 368241699cdSAl Viro } 369241699cdSAl Viro #else 370241699cdSAl Viro #define sanity(i) true 371241699cdSAl Viro #endif 372241699cdSAl Viro 373241699cdSAl Viro static size_t copy_page_to_iter_pipe(struct page *page, size_t offset, size_t bytes, 374241699cdSAl Viro struct iov_iter *i) 375241699cdSAl Viro { 376241699cdSAl Viro struct pipe_inode_info *pipe = i->pipe; 377241699cdSAl Viro struct pipe_buffer *buf; 3788cefc107SDavid Howells unsigned int p_tail = pipe->tail; 3798cefc107SDavid Howells unsigned int p_mask = pipe->ring_size - 1; 3808cefc107SDavid Howells unsigned int i_head = i->head; 381241699cdSAl Viro size_t off; 382241699cdSAl Viro 383241699cdSAl Viro if (unlikely(bytes > i->count)) 384241699cdSAl Viro bytes = i->count; 385241699cdSAl Viro 386241699cdSAl Viro if (unlikely(!bytes)) 387241699cdSAl Viro return 0; 388241699cdSAl Viro 389241699cdSAl Viro if (!sanity(i)) 390241699cdSAl Viro return 0; 391241699cdSAl Viro 392241699cdSAl Viro off = i->iov_offset; 3938cefc107SDavid Howells buf = &pipe->bufs[i_head & p_mask]; 394241699cdSAl Viro if (off) { 395241699cdSAl Viro if (offset == off && buf->page == page) { 396241699cdSAl Viro /* merge with the last one */ 397241699cdSAl Viro buf->len += bytes; 398241699cdSAl Viro i->iov_offset += bytes; 399241699cdSAl Viro goto out; 400241699cdSAl Viro } 4018cefc107SDavid Howells i_head++; 4028cefc107SDavid Howells buf = &pipe->bufs[i_head & p_mask]; 403241699cdSAl Viro } 4046718b6f8SDavid Howells if (pipe_full(i_head, p_tail, pipe->max_usage)) 405241699cdSAl Viro return 0; 4068cefc107SDavid Howells 407241699cdSAl Viro buf->ops = &page_cache_pipe_buf_ops; 4088cefc107SDavid Howells get_page(page); 4098cefc107SDavid Howells buf->page = page; 410241699cdSAl Viro buf->offset = offset; 411241699cdSAl Viro buf->len = bytes; 4128cefc107SDavid Howells 4138cefc107SDavid Howells pipe->head = i_head + 1; 414241699cdSAl Viro i->iov_offset = offset + bytes; 4158cefc107SDavid Howells i->head = i_head; 416241699cdSAl Viro out: 417241699cdSAl Viro i->count -= bytes; 418241699cdSAl Viro return bytes; 419241699cdSAl Viro } 420241699cdSAl Viro 421d879cb83SAl Viro /* 422171a0203SAnton Altaparmakov * Fault in one or more iovecs of the given iov_iter, to a maximum length of 423171a0203SAnton Altaparmakov * bytes. For each iovec, fault in each page that constitutes the iovec. 424171a0203SAnton Altaparmakov * 425171a0203SAnton Altaparmakov * Return 0 on success, or non-zero if the memory could not be accessed (i.e. 426171a0203SAnton Altaparmakov * because it is an invalid address). 427171a0203SAnton Altaparmakov */ 428d4690f1eSAl Viro int iov_iter_fault_in_readable(struct iov_iter *i, size_t bytes) 429171a0203SAnton Altaparmakov { 430171a0203SAnton Altaparmakov size_t skip = i->iov_offset; 431171a0203SAnton Altaparmakov const struct iovec *iov; 432171a0203SAnton Altaparmakov int err; 433171a0203SAnton Altaparmakov struct iovec v; 434171a0203SAnton Altaparmakov 435171a0203SAnton Altaparmakov if (!(i->type & (ITER_BVEC|ITER_KVEC))) { 436171a0203SAnton Altaparmakov iterate_iovec(i, bytes, v, iov, skip, ({ 4374bce9f6eSAl Viro err = fault_in_pages_readable(v.iov_base, v.iov_len); 438171a0203SAnton Altaparmakov if (unlikely(err)) 439171a0203SAnton Altaparmakov return err; 440171a0203SAnton Altaparmakov 0;})) 441171a0203SAnton Altaparmakov } 442171a0203SAnton Altaparmakov return 0; 443171a0203SAnton Altaparmakov } 444d4690f1eSAl Viro EXPORT_SYMBOL(iov_iter_fault_in_readable); 445171a0203SAnton Altaparmakov 446aa563d7bSDavid Howells void iov_iter_init(struct iov_iter *i, unsigned int direction, 447d879cb83SAl Viro const struct iovec *iov, unsigned long nr_segs, 448d879cb83SAl Viro size_t count) 449d879cb83SAl Viro { 450aa563d7bSDavid Howells WARN_ON(direction & ~(READ | WRITE)); 451aa563d7bSDavid Howells direction &= READ | WRITE; 452aa563d7bSDavid Howells 453d879cb83SAl Viro /* It will get better. Eventually... */ 454db68ce10SAl Viro if (uaccess_kernel()) { 455aa563d7bSDavid Howells i->type = ITER_KVEC | direction; 456d879cb83SAl Viro i->kvec = (struct kvec *)iov; 457d879cb83SAl Viro } else { 458aa563d7bSDavid Howells i->type = ITER_IOVEC | direction; 459d879cb83SAl Viro i->iov = iov; 460d879cb83SAl Viro } 461d879cb83SAl Viro i->nr_segs = nr_segs; 462d879cb83SAl Viro i->iov_offset = 0; 463d879cb83SAl Viro i->count = count; 464d879cb83SAl Viro } 465d879cb83SAl Viro EXPORT_SYMBOL(iov_iter_init); 466d879cb83SAl Viro 467d879cb83SAl Viro static void memcpy_from_page(char *to, struct page *page, size_t offset, size_t len) 468d879cb83SAl Viro { 469d879cb83SAl Viro char *from = kmap_atomic(page); 470d879cb83SAl Viro memcpy(to, from + offset, len); 471d879cb83SAl Viro kunmap_atomic(from); 472d879cb83SAl Viro } 473d879cb83SAl Viro 47436f7a8a4SAl Viro static void memcpy_to_page(struct page *page, size_t offset, const char *from, size_t len) 475d879cb83SAl Viro { 476d879cb83SAl Viro char *to = kmap_atomic(page); 477d879cb83SAl Viro memcpy(to + offset, from, len); 478d879cb83SAl Viro kunmap_atomic(to); 479d879cb83SAl Viro } 480d879cb83SAl Viro 481d879cb83SAl Viro static void memzero_page(struct page *page, size_t offset, size_t len) 482d879cb83SAl Viro { 483d879cb83SAl Viro char *addr = kmap_atomic(page); 484d879cb83SAl Viro memset(addr + offset, 0, len); 485d879cb83SAl Viro kunmap_atomic(addr); 486d879cb83SAl Viro } 487d879cb83SAl Viro 488241699cdSAl Viro static inline bool allocated(struct pipe_buffer *buf) 489241699cdSAl Viro { 490241699cdSAl Viro return buf->ops == &default_pipe_buf_ops; 491241699cdSAl Viro } 492241699cdSAl Viro 4938cefc107SDavid Howells static inline void data_start(const struct iov_iter *i, 4948cefc107SDavid Howells unsigned int *iter_headp, size_t *offp) 495241699cdSAl Viro { 4968cefc107SDavid Howells unsigned int p_mask = i->pipe->ring_size - 1; 4978cefc107SDavid Howells unsigned int iter_head = i->head; 498241699cdSAl Viro size_t off = i->iov_offset; 4998cefc107SDavid Howells 5008cefc107SDavid Howells if (off && (!allocated(&i->pipe->bufs[iter_head & p_mask]) || 5018cefc107SDavid Howells off == PAGE_SIZE)) { 5028cefc107SDavid Howells iter_head++; 503241699cdSAl Viro off = 0; 504241699cdSAl Viro } 5058cefc107SDavid Howells *iter_headp = iter_head; 506241699cdSAl Viro *offp = off; 507241699cdSAl Viro } 508241699cdSAl Viro 509241699cdSAl Viro static size_t push_pipe(struct iov_iter *i, size_t size, 5108cefc107SDavid Howells int *iter_headp, size_t *offp) 511241699cdSAl Viro { 512241699cdSAl Viro struct pipe_inode_info *pipe = i->pipe; 5138cefc107SDavid Howells unsigned int p_tail = pipe->tail; 5148cefc107SDavid Howells unsigned int p_mask = pipe->ring_size - 1; 5158cefc107SDavid Howells unsigned int iter_head; 516241699cdSAl Viro size_t off; 517241699cdSAl Viro ssize_t left; 518241699cdSAl Viro 519241699cdSAl Viro if (unlikely(size > i->count)) 520241699cdSAl Viro size = i->count; 521241699cdSAl Viro if (unlikely(!size)) 522241699cdSAl Viro return 0; 523241699cdSAl Viro 524241699cdSAl Viro left = size; 5258cefc107SDavid Howells data_start(i, &iter_head, &off); 5268cefc107SDavid Howells *iter_headp = iter_head; 527241699cdSAl Viro *offp = off; 528241699cdSAl Viro if (off) { 529241699cdSAl Viro left -= PAGE_SIZE - off; 530241699cdSAl Viro if (left <= 0) { 5318cefc107SDavid Howells pipe->bufs[iter_head & p_mask].len += size; 532241699cdSAl Viro return size; 533241699cdSAl Viro } 5348cefc107SDavid Howells pipe->bufs[iter_head & p_mask].len = PAGE_SIZE; 5358cefc107SDavid Howells iter_head++; 536241699cdSAl Viro } 5376718b6f8SDavid Howells while (!pipe_full(iter_head, p_tail, pipe->max_usage)) { 5388cefc107SDavid Howells struct pipe_buffer *buf = &pipe->bufs[iter_head & p_mask]; 539241699cdSAl Viro struct page *page = alloc_page(GFP_USER); 540241699cdSAl Viro if (!page) 541241699cdSAl Viro break; 5428cefc107SDavid Howells 5438cefc107SDavid Howells buf->ops = &default_pipe_buf_ops; 5448cefc107SDavid Howells buf->page = page; 5458cefc107SDavid Howells buf->offset = 0; 5468cefc107SDavid Howells buf->len = min_t(ssize_t, left, PAGE_SIZE); 5478cefc107SDavid Howells left -= buf->len; 5488cefc107SDavid Howells iter_head++; 5498cefc107SDavid Howells pipe->head = iter_head; 5508cefc107SDavid Howells 5518cefc107SDavid Howells if (left == 0) 552241699cdSAl Viro return size; 553241699cdSAl Viro } 554241699cdSAl Viro return size - left; 555241699cdSAl Viro } 556241699cdSAl Viro 557241699cdSAl Viro static size_t copy_pipe_to_iter(const void *addr, size_t bytes, 558241699cdSAl Viro struct iov_iter *i) 559241699cdSAl Viro { 560241699cdSAl Viro struct pipe_inode_info *pipe = i->pipe; 5618cefc107SDavid Howells unsigned int p_mask = pipe->ring_size - 1; 5628cefc107SDavid Howells unsigned int i_head; 563241699cdSAl Viro size_t n, off; 564241699cdSAl Viro 565241699cdSAl Viro if (!sanity(i)) 566241699cdSAl Viro return 0; 567241699cdSAl Viro 5688cefc107SDavid Howells bytes = n = push_pipe(i, bytes, &i_head, &off); 569241699cdSAl Viro if (unlikely(!n)) 570241699cdSAl Viro return 0; 5718cefc107SDavid Howells do { 572241699cdSAl Viro size_t chunk = min_t(size_t, n, PAGE_SIZE - off); 5738cefc107SDavid Howells memcpy_to_page(pipe->bufs[i_head & p_mask].page, off, addr, chunk); 5748cefc107SDavid Howells i->head = i_head; 575241699cdSAl Viro i->iov_offset = off + chunk; 576241699cdSAl Viro n -= chunk; 577241699cdSAl Viro addr += chunk; 5788cefc107SDavid Howells off = 0; 5798cefc107SDavid Howells i_head++; 5808cefc107SDavid Howells } while (n); 581241699cdSAl Viro i->count -= bytes; 582241699cdSAl Viro return bytes; 583241699cdSAl Viro } 584241699cdSAl Viro 585f9152895SAl Viro static __wsum csum_and_memcpy(void *to, const void *from, size_t len, 586f9152895SAl Viro __wsum sum, size_t off) 587f9152895SAl Viro { 588cc44c17bSAl Viro __wsum next = csum_partial_copy_nocheck(from, to, len); 589f9152895SAl Viro return csum_block_add(sum, next, off); 590f9152895SAl Viro } 591f9152895SAl Viro 59278e1f386SAl Viro static size_t csum_and_copy_to_pipe_iter(const void *addr, size_t bytes, 59378e1f386SAl Viro __wsum *csum, struct iov_iter *i) 59478e1f386SAl Viro { 59578e1f386SAl Viro struct pipe_inode_info *pipe = i->pipe; 5968cefc107SDavid Howells unsigned int p_mask = pipe->ring_size - 1; 5978cefc107SDavid Howells unsigned int i_head; 59878e1f386SAl Viro size_t n, r; 59978e1f386SAl Viro size_t off = 0; 600f9152895SAl Viro __wsum sum = *csum; 60178e1f386SAl Viro 60278e1f386SAl Viro if (!sanity(i)) 60378e1f386SAl Viro return 0; 60478e1f386SAl Viro 6058cefc107SDavid Howells bytes = n = push_pipe(i, bytes, &i_head, &r); 60678e1f386SAl Viro if (unlikely(!n)) 60778e1f386SAl Viro return 0; 6088cefc107SDavid Howells do { 60978e1f386SAl Viro size_t chunk = min_t(size_t, n, PAGE_SIZE - r); 6108cefc107SDavid Howells char *p = kmap_atomic(pipe->bufs[i_head & p_mask].page); 611f9152895SAl Viro sum = csum_and_memcpy(p + r, addr, chunk, sum, off); 61278e1f386SAl Viro kunmap_atomic(p); 6138cefc107SDavid Howells i->head = i_head; 61478e1f386SAl Viro i->iov_offset = r + chunk; 61578e1f386SAl Viro n -= chunk; 61678e1f386SAl Viro off += chunk; 61778e1f386SAl Viro addr += chunk; 6188cefc107SDavid Howells r = 0; 6198cefc107SDavid Howells i_head++; 6208cefc107SDavid Howells } while (n); 62178e1f386SAl Viro i->count -= bytes; 62278e1f386SAl Viro *csum = sum; 62378e1f386SAl Viro return bytes; 62478e1f386SAl Viro } 62578e1f386SAl Viro 626aa28de27SAl Viro size_t _copy_to_iter(const void *addr, size_t bytes, struct iov_iter *i) 627d879cb83SAl Viro { 62836f7a8a4SAl Viro const char *from = addr; 62900e23707SDavid Howells if (unlikely(iov_iter_is_pipe(i))) 630241699cdSAl Viro return copy_pipe_to_iter(addr, bytes, i); 63109fc68dcSAl Viro if (iter_is_iovec(i)) 63209fc68dcSAl Viro might_fault(); 633d879cb83SAl Viro iterate_and_advance(i, bytes, v, 63409fc68dcSAl Viro copyout(v.iov_base, (from += v.iov_len) - v.iov_len, v.iov_len), 635d879cb83SAl Viro memcpy_to_page(v.bv_page, v.bv_offset, 636d879cb83SAl Viro (from += v.bv_len) - v.bv_len, v.bv_len), 637d879cb83SAl Viro memcpy(v.iov_base, (from += v.iov_len) - v.iov_len, v.iov_len) 638d879cb83SAl Viro ) 639d879cb83SAl Viro 640d879cb83SAl Viro return bytes; 641d879cb83SAl Viro } 642aa28de27SAl Viro EXPORT_SYMBOL(_copy_to_iter); 643d879cb83SAl Viro 644ec6347bbSDan Williams #ifdef CONFIG_ARCH_HAS_COPY_MC 645ec6347bbSDan Williams static int copyout_mc(void __user *to, const void *from, size_t n) 6468780356eSDan Williams { 64796d4f267SLinus Torvalds if (access_ok(to, n)) { 648d0ef4c36SMarco Elver instrument_copy_to_user(to, from, n); 649ec6347bbSDan Williams n = copy_mc_to_user((__force void *) to, from, n); 6508780356eSDan Williams } 6518780356eSDan Williams return n; 6528780356eSDan Williams } 6538780356eSDan Williams 654ec6347bbSDan Williams static unsigned long copy_mc_to_page(struct page *page, size_t offset, 6558780356eSDan Williams const char *from, size_t len) 6568780356eSDan Williams { 6578780356eSDan Williams unsigned long ret; 6588780356eSDan Williams char *to; 6598780356eSDan Williams 6608780356eSDan Williams to = kmap_atomic(page); 661ec6347bbSDan Williams ret = copy_mc_to_kernel(to + offset, from, len); 6628780356eSDan Williams kunmap_atomic(to); 6638780356eSDan Williams 6648780356eSDan Williams return ret; 6658780356eSDan Williams } 6668780356eSDan Williams 667ec6347bbSDan Williams static size_t copy_mc_pipe_to_iter(const void *addr, size_t bytes, 668ca146f6fSDan Williams struct iov_iter *i) 669ca146f6fSDan Williams { 670ca146f6fSDan Williams struct pipe_inode_info *pipe = i->pipe; 6718cefc107SDavid Howells unsigned int p_mask = pipe->ring_size - 1; 6728cefc107SDavid Howells unsigned int i_head; 673ca146f6fSDan Williams size_t n, off, xfer = 0; 674ca146f6fSDan Williams 675ca146f6fSDan Williams if (!sanity(i)) 676ca146f6fSDan Williams return 0; 677ca146f6fSDan Williams 6788cefc107SDavid Howells bytes = n = push_pipe(i, bytes, &i_head, &off); 679ca146f6fSDan Williams if (unlikely(!n)) 680ca146f6fSDan Williams return 0; 6818cefc107SDavid Howells do { 682ca146f6fSDan Williams size_t chunk = min_t(size_t, n, PAGE_SIZE - off); 683ca146f6fSDan Williams unsigned long rem; 684ca146f6fSDan Williams 685ec6347bbSDan Williams rem = copy_mc_to_page(pipe->bufs[i_head & p_mask].page, 6868cefc107SDavid Howells off, addr, chunk); 6878cefc107SDavid Howells i->head = i_head; 688ca146f6fSDan Williams i->iov_offset = off + chunk - rem; 689ca146f6fSDan Williams xfer += chunk - rem; 690ca146f6fSDan Williams if (rem) 691ca146f6fSDan Williams break; 692ca146f6fSDan Williams n -= chunk; 693ca146f6fSDan Williams addr += chunk; 6948cefc107SDavid Howells off = 0; 6958cefc107SDavid Howells i_head++; 6968cefc107SDavid Howells } while (n); 697ca146f6fSDan Williams i->count -= xfer; 698ca146f6fSDan Williams return xfer; 699ca146f6fSDan Williams } 700ca146f6fSDan Williams 701bf3eeb9bSDan Williams /** 702ec6347bbSDan Williams * _copy_mc_to_iter - copy to iter with source memory error exception handling 703bf3eeb9bSDan Williams * @addr: source kernel address 704bf3eeb9bSDan Williams * @bytes: total transfer length 705bf3eeb9bSDan Williams * @iter: destination iterator 706bf3eeb9bSDan Williams * 707ec6347bbSDan Williams * The pmem driver deploys this for the dax operation 708ec6347bbSDan Williams * (dax_copy_to_iter()) for dax reads (bypass page-cache and the 709ec6347bbSDan Williams * block-layer). Upon #MC read(2) aborts and returns EIO or the bytes 710ec6347bbSDan Williams * successfully copied. 711bf3eeb9bSDan Williams * 712ec6347bbSDan Williams * The main differences between this and typical _copy_to_iter(). 713bf3eeb9bSDan Williams * 714bf3eeb9bSDan Williams * * Typical tail/residue handling after a fault retries the copy 715bf3eeb9bSDan Williams * byte-by-byte until the fault happens again. Re-triggering machine 716bf3eeb9bSDan Williams * checks is potentially fatal so the implementation uses source 717bf3eeb9bSDan Williams * alignment and poison alignment assumptions to avoid re-triggering 718bf3eeb9bSDan Williams * hardware exceptions. 719bf3eeb9bSDan Williams * 720bf3eeb9bSDan Williams * * ITER_KVEC, ITER_PIPE, and ITER_BVEC can return short copies. 721bf3eeb9bSDan Williams * Compare to copy_to_iter() where only ITER_IOVEC attempts might return 722bf3eeb9bSDan Williams * a short copy. 723bf3eeb9bSDan Williams */ 724ec6347bbSDan Williams size_t _copy_mc_to_iter(const void *addr, size_t bytes, struct iov_iter *i) 7258780356eSDan Williams { 7268780356eSDan Williams const char *from = addr; 7278780356eSDan Williams unsigned long rem, curr_addr, s_addr = (unsigned long) addr; 7288780356eSDan Williams 72900e23707SDavid Howells if (unlikely(iov_iter_is_pipe(i))) 730ec6347bbSDan Williams return copy_mc_pipe_to_iter(addr, bytes, i); 7318780356eSDan Williams if (iter_is_iovec(i)) 7328780356eSDan Williams might_fault(); 7338780356eSDan Williams iterate_and_advance(i, bytes, v, 734ec6347bbSDan Williams copyout_mc(v.iov_base, (from += v.iov_len) - v.iov_len, 735ec6347bbSDan Williams v.iov_len), 7368780356eSDan Williams ({ 737ec6347bbSDan Williams rem = copy_mc_to_page(v.bv_page, v.bv_offset, 7388780356eSDan Williams (from += v.bv_len) - v.bv_len, v.bv_len); 7398780356eSDan Williams if (rem) { 7408780356eSDan Williams curr_addr = (unsigned long) from; 7418780356eSDan Williams bytes = curr_addr - s_addr - rem; 7428780356eSDan Williams return bytes; 7438780356eSDan Williams } 7448780356eSDan Williams }), 7458780356eSDan Williams ({ 746ec6347bbSDan Williams rem = copy_mc_to_kernel(v.iov_base, (from += v.iov_len) 747ec6347bbSDan Williams - v.iov_len, v.iov_len); 7488780356eSDan Williams if (rem) { 7498780356eSDan Williams curr_addr = (unsigned long) from; 7508780356eSDan Williams bytes = curr_addr - s_addr - rem; 7518780356eSDan Williams return bytes; 7528780356eSDan Williams } 7538780356eSDan Williams }) 7548780356eSDan Williams ) 7558780356eSDan Williams 7568780356eSDan Williams return bytes; 7578780356eSDan Williams } 758ec6347bbSDan Williams EXPORT_SYMBOL_GPL(_copy_mc_to_iter); 759ec6347bbSDan Williams #endif /* CONFIG_ARCH_HAS_COPY_MC */ 7608780356eSDan Williams 761aa28de27SAl Viro size_t _copy_from_iter(void *addr, size_t bytes, struct iov_iter *i) 762d879cb83SAl Viro { 763d879cb83SAl Viro char *to = addr; 76400e23707SDavid Howells if (unlikely(iov_iter_is_pipe(i))) { 765241699cdSAl Viro WARN_ON(1); 766241699cdSAl Viro return 0; 767241699cdSAl Viro } 76809fc68dcSAl Viro if (iter_is_iovec(i)) 76909fc68dcSAl Viro might_fault(); 770d879cb83SAl Viro iterate_and_advance(i, bytes, v, 77109fc68dcSAl Viro copyin((to += v.iov_len) - v.iov_len, v.iov_base, v.iov_len), 772d879cb83SAl Viro memcpy_from_page((to += v.bv_len) - v.bv_len, v.bv_page, 773d879cb83SAl Viro v.bv_offset, v.bv_len), 774d879cb83SAl Viro memcpy((to += v.iov_len) - v.iov_len, v.iov_base, v.iov_len) 775d879cb83SAl Viro ) 776d879cb83SAl Viro 777d879cb83SAl Viro return bytes; 778d879cb83SAl Viro } 779aa28de27SAl Viro EXPORT_SYMBOL(_copy_from_iter); 780d879cb83SAl Viro 781aa28de27SAl Viro bool _copy_from_iter_full(void *addr, size_t bytes, struct iov_iter *i) 782cbbd26b8SAl Viro { 783cbbd26b8SAl Viro char *to = addr; 78400e23707SDavid Howells if (unlikely(iov_iter_is_pipe(i))) { 785cbbd26b8SAl Viro WARN_ON(1); 786cbbd26b8SAl Viro return false; 787cbbd26b8SAl Viro } 78833844e66SAl Viro if (unlikely(i->count < bytes)) 789cbbd26b8SAl Viro return false; 790cbbd26b8SAl Viro 79109fc68dcSAl Viro if (iter_is_iovec(i)) 79209fc68dcSAl Viro might_fault(); 793cbbd26b8SAl Viro iterate_all_kinds(i, bytes, v, ({ 79409fc68dcSAl Viro if (copyin((to += v.iov_len) - v.iov_len, 795cbbd26b8SAl Viro v.iov_base, v.iov_len)) 796cbbd26b8SAl Viro return false; 797cbbd26b8SAl Viro 0;}), 798cbbd26b8SAl Viro memcpy_from_page((to += v.bv_len) - v.bv_len, v.bv_page, 799cbbd26b8SAl Viro v.bv_offset, v.bv_len), 800cbbd26b8SAl Viro memcpy((to += v.iov_len) - v.iov_len, v.iov_base, v.iov_len) 801cbbd26b8SAl Viro ) 802cbbd26b8SAl Viro 803cbbd26b8SAl Viro iov_iter_advance(i, bytes); 804cbbd26b8SAl Viro return true; 805cbbd26b8SAl Viro } 806aa28de27SAl Viro EXPORT_SYMBOL(_copy_from_iter_full); 807cbbd26b8SAl Viro 808aa28de27SAl Viro size_t _copy_from_iter_nocache(void *addr, size_t bytes, struct iov_iter *i) 809d879cb83SAl Viro { 810d879cb83SAl Viro char *to = addr; 81100e23707SDavid Howells if (unlikely(iov_iter_is_pipe(i))) { 812241699cdSAl Viro WARN_ON(1); 813241699cdSAl Viro return 0; 814241699cdSAl Viro } 815d879cb83SAl Viro iterate_and_advance(i, bytes, v, 8163f763453SAl Viro __copy_from_user_inatomic_nocache((to += v.iov_len) - v.iov_len, 817d879cb83SAl Viro v.iov_base, v.iov_len), 818d879cb83SAl Viro memcpy_from_page((to += v.bv_len) - v.bv_len, v.bv_page, 819d879cb83SAl Viro v.bv_offset, v.bv_len), 820d879cb83SAl Viro memcpy((to += v.iov_len) - v.iov_len, v.iov_base, v.iov_len) 821d879cb83SAl Viro ) 822d879cb83SAl Viro 823d879cb83SAl Viro return bytes; 824d879cb83SAl Viro } 825aa28de27SAl Viro EXPORT_SYMBOL(_copy_from_iter_nocache); 826d879cb83SAl Viro 8270aed55afSDan Williams #ifdef CONFIG_ARCH_HAS_UACCESS_FLUSHCACHE 828abd08d7dSDan Williams /** 829abd08d7dSDan Williams * _copy_from_iter_flushcache - write destination through cpu cache 830abd08d7dSDan Williams * @addr: destination kernel address 831abd08d7dSDan Williams * @bytes: total transfer length 832abd08d7dSDan Williams * @iter: source iterator 833abd08d7dSDan Williams * 834abd08d7dSDan Williams * The pmem driver arranges for filesystem-dax to use this facility via 835abd08d7dSDan Williams * dax_copy_from_iter() for ensuring that writes to persistent memory 836abd08d7dSDan Williams * are flushed through the CPU cache. It is differentiated from 837abd08d7dSDan Williams * _copy_from_iter_nocache() in that guarantees all data is flushed for 838abd08d7dSDan Williams * all iterator types. The _copy_from_iter_nocache() only attempts to 839abd08d7dSDan Williams * bypass the cache for the ITER_IOVEC case, and on some archs may use 840abd08d7dSDan Williams * instructions that strand dirty-data in the cache. 841abd08d7dSDan Williams */ 8426a37e940SLinus Torvalds size_t _copy_from_iter_flushcache(void *addr, size_t bytes, struct iov_iter *i) 8430aed55afSDan Williams { 8440aed55afSDan Williams char *to = addr; 84500e23707SDavid Howells if (unlikely(iov_iter_is_pipe(i))) { 8460aed55afSDan Williams WARN_ON(1); 8470aed55afSDan Williams return 0; 8480aed55afSDan Williams } 8490aed55afSDan Williams iterate_and_advance(i, bytes, v, 8500aed55afSDan Williams __copy_from_user_flushcache((to += v.iov_len) - v.iov_len, 8510aed55afSDan Williams v.iov_base, v.iov_len), 8520aed55afSDan Williams memcpy_page_flushcache((to += v.bv_len) - v.bv_len, v.bv_page, 8530aed55afSDan Williams v.bv_offset, v.bv_len), 8540aed55afSDan Williams memcpy_flushcache((to += v.iov_len) - v.iov_len, v.iov_base, 8550aed55afSDan Williams v.iov_len) 8560aed55afSDan Williams ) 8570aed55afSDan Williams 8580aed55afSDan Williams return bytes; 8590aed55afSDan Williams } 8606a37e940SLinus Torvalds EXPORT_SYMBOL_GPL(_copy_from_iter_flushcache); 8610aed55afSDan Williams #endif 8620aed55afSDan Williams 863aa28de27SAl Viro bool _copy_from_iter_full_nocache(void *addr, size_t bytes, struct iov_iter *i) 864cbbd26b8SAl Viro { 865cbbd26b8SAl Viro char *to = addr; 86600e23707SDavid Howells if (unlikely(iov_iter_is_pipe(i))) { 867cbbd26b8SAl Viro WARN_ON(1); 868cbbd26b8SAl Viro return false; 869cbbd26b8SAl Viro } 87033844e66SAl Viro if (unlikely(i->count < bytes)) 871cbbd26b8SAl Viro return false; 872cbbd26b8SAl Viro iterate_all_kinds(i, bytes, v, ({ 8733f763453SAl Viro if (__copy_from_user_inatomic_nocache((to += v.iov_len) - v.iov_len, 874cbbd26b8SAl Viro v.iov_base, v.iov_len)) 875cbbd26b8SAl Viro return false; 876cbbd26b8SAl Viro 0;}), 877cbbd26b8SAl Viro memcpy_from_page((to += v.bv_len) - v.bv_len, v.bv_page, 878cbbd26b8SAl Viro v.bv_offset, v.bv_len), 879cbbd26b8SAl Viro memcpy((to += v.iov_len) - v.iov_len, v.iov_base, v.iov_len) 880cbbd26b8SAl Viro ) 881cbbd26b8SAl Viro 882cbbd26b8SAl Viro iov_iter_advance(i, bytes); 883cbbd26b8SAl Viro return true; 884cbbd26b8SAl Viro } 885aa28de27SAl Viro EXPORT_SYMBOL(_copy_from_iter_full_nocache); 886cbbd26b8SAl Viro 88772e809edSAl Viro static inline bool page_copy_sane(struct page *page, size_t offset, size_t n) 88872e809edSAl Viro { 8896daef95bSEric Dumazet struct page *head; 8906daef95bSEric Dumazet size_t v = n + offset; 8916daef95bSEric Dumazet 8926daef95bSEric Dumazet /* 8936daef95bSEric Dumazet * The general case needs to access the page order in order 8946daef95bSEric Dumazet * to compute the page size. 8956daef95bSEric Dumazet * However, we mostly deal with order-0 pages and thus can 8966daef95bSEric Dumazet * avoid a possible cache line miss for requests that fit all 8976daef95bSEric Dumazet * page orders. 8986daef95bSEric Dumazet */ 8996daef95bSEric Dumazet if (n <= v && v <= PAGE_SIZE) 9006daef95bSEric Dumazet return true; 9016daef95bSEric Dumazet 9026daef95bSEric Dumazet head = compound_head(page); 9036daef95bSEric Dumazet v += (page - head) << PAGE_SHIFT; 904a90bcb86SPetar Penkov 905a50b854eSMatthew Wilcox (Oracle) if (likely(n <= v && v <= (page_size(head)))) 90672e809edSAl Viro return true; 90772e809edSAl Viro WARN_ON(1); 90872e809edSAl Viro return false; 90972e809edSAl Viro } 910d879cb83SAl Viro 911d879cb83SAl Viro size_t copy_page_to_iter(struct page *page, size_t offset, size_t bytes, 912d879cb83SAl Viro struct iov_iter *i) 913d879cb83SAl Viro { 91472e809edSAl Viro if (unlikely(!page_copy_sane(page, offset, bytes))) 91572e809edSAl Viro return 0; 916d879cb83SAl Viro if (i->type & (ITER_BVEC|ITER_KVEC)) { 917d879cb83SAl Viro void *kaddr = kmap_atomic(page); 918d879cb83SAl Viro size_t wanted = copy_to_iter(kaddr + offset, bytes, i); 919d879cb83SAl Viro kunmap_atomic(kaddr); 920d879cb83SAl Viro return wanted; 9219ea9ce04SDavid Howells } else if (unlikely(iov_iter_is_discard(i))) 9229ea9ce04SDavid Howells return bytes; 9239ea9ce04SDavid Howells else if (likely(!iov_iter_is_pipe(i))) 924d879cb83SAl Viro return copy_page_to_iter_iovec(page, offset, bytes, i); 925241699cdSAl Viro else 926241699cdSAl Viro return copy_page_to_iter_pipe(page, offset, bytes, i); 927d879cb83SAl Viro } 928d879cb83SAl Viro EXPORT_SYMBOL(copy_page_to_iter); 929d879cb83SAl Viro 930d879cb83SAl Viro size_t copy_page_from_iter(struct page *page, size_t offset, size_t bytes, 931d879cb83SAl Viro struct iov_iter *i) 932d879cb83SAl Viro { 93372e809edSAl Viro if (unlikely(!page_copy_sane(page, offset, bytes))) 93472e809edSAl Viro return 0; 9359ea9ce04SDavid Howells if (unlikely(iov_iter_is_pipe(i) || iov_iter_is_discard(i))) { 936241699cdSAl Viro WARN_ON(1); 937241699cdSAl Viro return 0; 938241699cdSAl Viro } 939d879cb83SAl Viro if (i->type & (ITER_BVEC|ITER_KVEC)) { 940d879cb83SAl Viro void *kaddr = kmap_atomic(page); 941aa28de27SAl Viro size_t wanted = _copy_from_iter(kaddr + offset, bytes, i); 942d879cb83SAl Viro kunmap_atomic(kaddr); 943d879cb83SAl Viro return wanted; 944d879cb83SAl Viro } else 945d879cb83SAl Viro return copy_page_from_iter_iovec(page, offset, bytes, i); 946d879cb83SAl Viro } 947d879cb83SAl Viro EXPORT_SYMBOL(copy_page_from_iter); 948d879cb83SAl Viro 949241699cdSAl Viro static size_t pipe_zero(size_t bytes, struct iov_iter *i) 950241699cdSAl Viro { 951241699cdSAl Viro struct pipe_inode_info *pipe = i->pipe; 9528cefc107SDavid Howells unsigned int p_mask = pipe->ring_size - 1; 9538cefc107SDavid Howells unsigned int i_head; 954241699cdSAl Viro size_t n, off; 955241699cdSAl Viro 956241699cdSAl Viro if (!sanity(i)) 957241699cdSAl Viro return 0; 958241699cdSAl Viro 9598cefc107SDavid Howells bytes = n = push_pipe(i, bytes, &i_head, &off); 960241699cdSAl Viro if (unlikely(!n)) 961241699cdSAl Viro return 0; 962241699cdSAl Viro 9638cefc107SDavid Howells do { 964241699cdSAl Viro size_t chunk = min_t(size_t, n, PAGE_SIZE - off); 9658cefc107SDavid Howells memzero_page(pipe->bufs[i_head & p_mask].page, off, chunk); 9668cefc107SDavid Howells i->head = i_head; 967241699cdSAl Viro i->iov_offset = off + chunk; 968241699cdSAl Viro n -= chunk; 9698cefc107SDavid Howells off = 0; 9708cefc107SDavid Howells i_head++; 9718cefc107SDavid Howells } while (n); 972241699cdSAl Viro i->count -= bytes; 973241699cdSAl Viro return bytes; 974241699cdSAl Viro } 975241699cdSAl Viro 976d879cb83SAl Viro size_t iov_iter_zero(size_t bytes, struct iov_iter *i) 977d879cb83SAl Viro { 97800e23707SDavid Howells if (unlikely(iov_iter_is_pipe(i))) 979241699cdSAl Viro return pipe_zero(bytes, i); 980d879cb83SAl Viro iterate_and_advance(i, bytes, v, 98109fc68dcSAl Viro clear_user(v.iov_base, v.iov_len), 982d879cb83SAl Viro memzero_page(v.bv_page, v.bv_offset, v.bv_len), 983d879cb83SAl Viro memset(v.iov_base, 0, v.iov_len) 984d879cb83SAl Viro ) 985d879cb83SAl Viro 986d879cb83SAl Viro return bytes; 987d879cb83SAl Viro } 988d879cb83SAl Viro EXPORT_SYMBOL(iov_iter_zero); 989d879cb83SAl Viro 990d879cb83SAl Viro size_t iov_iter_copy_from_user_atomic(struct page *page, 991d879cb83SAl Viro struct iov_iter *i, unsigned long offset, size_t bytes) 992d879cb83SAl Viro { 993d879cb83SAl Viro char *kaddr = kmap_atomic(page), *p = kaddr + offset; 99472e809edSAl Viro if (unlikely(!page_copy_sane(page, offset, bytes))) { 99572e809edSAl Viro kunmap_atomic(kaddr); 99672e809edSAl Viro return 0; 99772e809edSAl Viro } 9989ea9ce04SDavid Howells if (unlikely(iov_iter_is_pipe(i) || iov_iter_is_discard(i))) { 999241699cdSAl Viro kunmap_atomic(kaddr); 1000241699cdSAl Viro WARN_ON(1); 1001241699cdSAl Viro return 0; 1002241699cdSAl Viro } 1003d879cb83SAl Viro iterate_all_kinds(i, bytes, v, 100409fc68dcSAl Viro copyin((p += v.iov_len) - v.iov_len, v.iov_base, v.iov_len), 1005d879cb83SAl Viro memcpy_from_page((p += v.bv_len) - v.bv_len, v.bv_page, 1006d879cb83SAl Viro v.bv_offset, v.bv_len), 1007d879cb83SAl Viro memcpy((p += v.iov_len) - v.iov_len, v.iov_base, v.iov_len) 1008d879cb83SAl Viro ) 1009d879cb83SAl Viro kunmap_atomic(kaddr); 1010d879cb83SAl Viro return bytes; 1011d879cb83SAl Viro } 1012d879cb83SAl Viro EXPORT_SYMBOL(iov_iter_copy_from_user_atomic); 1013d879cb83SAl Viro 1014b9dc6f65SAl Viro static inline void pipe_truncate(struct iov_iter *i) 1015241699cdSAl Viro { 1016241699cdSAl Viro struct pipe_inode_info *pipe = i->pipe; 10178cefc107SDavid Howells unsigned int p_tail = pipe->tail; 10188cefc107SDavid Howells unsigned int p_head = pipe->head; 10198cefc107SDavid Howells unsigned int p_mask = pipe->ring_size - 1; 10208cefc107SDavid Howells 10218cefc107SDavid Howells if (!pipe_empty(p_head, p_tail)) { 10228cefc107SDavid Howells struct pipe_buffer *buf; 10238cefc107SDavid Howells unsigned int i_head = i->head; 1024b9dc6f65SAl Viro size_t off = i->iov_offset; 10258cefc107SDavid Howells 1026b9dc6f65SAl Viro if (off) { 10278cefc107SDavid Howells buf = &pipe->bufs[i_head & p_mask]; 10288cefc107SDavid Howells buf->len = off - buf->offset; 10298cefc107SDavid Howells i_head++; 1030b9dc6f65SAl Viro } 10318cefc107SDavid Howells while (p_head != i_head) { 10328cefc107SDavid Howells p_head--; 10338cefc107SDavid Howells pipe_buf_release(pipe, &pipe->bufs[p_head & p_mask]); 1034241699cdSAl Viro } 10358cefc107SDavid Howells 10368cefc107SDavid Howells pipe->head = p_head; 1037241699cdSAl Viro } 1038b9dc6f65SAl Viro } 1039b9dc6f65SAl Viro 1040b9dc6f65SAl Viro static void pipe_advance(struct iov_iter *i, size_t size) 1041b9dc6f65SAl Viro { 1042b9dc6f65SAl Viro struct pipe_inode_info *pipe = i->pipe; 1043b9dc6f65SAl Viro if (unlikely(i->count < size)) 1044b9dc6f65SAl Viro size = i->count; 1045b9dc6f65SAl Viro if (size) { 1046b9dc6f65SAl Viro struct pipe_buffer *buf; 10478cefc107SDavid Howells unsigned int p_mask = pipe->ring_size - 1; 10488cefc107SDavid Howells unsigned int i_head = i->head; 1049b9dc6f65SAl Viro size_t off = i->iov_offset, left = size; 10508cefc107SDavid Howells 1051b9dc6f65SAl Viro if (off) /* make it relative to the beginning of buffer */ 10528cefc107SDavid Howells left += off - pipe->bufs[i_head & p_mask].offset; 1053b9dc6f65SAl Viro while (1) { 10548cefc107SDavid Howells buf = &pipe->bufs[i_head & p_mask]; 1055b9dc6f65SAl Viro if (left <= buf->len) 1056b9dc6f65SAl Viro break; 1057b9dc6f65SAl Viro left -= buf->len; 10588cefc107SDavid Howells i_head++; 1059b9dc6f65SAl Viro } 10608cefc107SDavid Howells i->head = i_head; 1061b9dc6f65SAl Viro i->iov_offset = buf->offset + left; 1062b9dc6f65SAl Viro } 1063b9dc6f65SAl Viro i->count -= size; 1064b9dc6f65SAl Viro /* ... and discard everything past that point */ 1065b9dc6f65SAl Viro pipe_truncate(i); 1066241699cdSAl Viro } 1067241699cdSAl Viro 1068*54c8195bSPavel Begunkov static void iov_iter_bvec_advance(struct iov_iter *i, size_t size) 1069*54c8195bSPavel Begunkov { 1070*54c8195bSPavel Begunkov struct bvec_iter bi; 1071*54c8195bSPavel Begunkov 1072*54c8195bSPavel Begunkov bi.bi_size = i->count; 1073*54c8195bSPavel Begunkov bi.bi_bvec_done = i->iov_offset; 1074*54c8195bSPavel Begunkov bi.bi_idx = 0; 1075*54c8195bSPavel Begunkov bvec_iter_advance(i->bvec, &bi, size); 1076*54c8195bSPavel Begunkov 1077*54c8195bSPavel Begunkov i->bvec += bi.bi_idx; 1078*54c8195bSPavel Begunkov i->nr_segs -= bi.bi_idx; 1079*54c8195bSPavel Begunkov i->count = bi.bi_size; 1080*54c8195bSPavel Begunkov i->iov_offset = bi.bi_bvec_done; 1081*54c8195bSPavel Begunkov } 1082*54c8195bSPavel Begunkov 1083d879cb83SAl Viro void iov_iter_advance(struct iov_iter *i, size_t size) 1084d879cb83SAl Viro { 108500e23707SDavid Howells if (unlikely(iov_iter_is_pipe(i))) { 1086241699cdSAl Viro pipe_advance(i, size); 1087241699cdSAl Viro return; 1088241699cdSAl Viro } 10899ea9ce04SDavid Howells if (unlikely(iov_iter_is_discard(i))) { 10909ea9ce04SDavid Howells i->count -= size; 10919ea9ce04SDavid Howells return; 10929ea9ce04SDavid Howells } 1093*54c8195bSPavel Begunkov if (iov_iter_is_bvec(i)) { 1094*54c8195bSPavel Begunkov iov_iter_bvec_advance(i, size); 1095*54c8195bSPavel Begunkov return; 1096*54c8195bSPavel Begunkov } 1097d879cb83SAl Viro iterate_and_advance(i, size, v, 0, 0, 0) 1098d879cb83SAl Viro } 1099d879cb83SAl Viro EXPORT_SYMBOL(iov_iter_advance); 1100d879cb83SAl Viro 110127c0e374SAl Viro void iov_iter_revert(struct iov_iter *i, size_t unroll) 110227c0e374SAl Viro { 110327c0e374SAl Viro if (!unroll) 110427c0e374SAl Viro return; 11055b47d59aSAl Viro if (WARN_ON(unroll > MAX_RW_COUNT)) 11065b47d59aSAl Viro return; 110727c0e374SAl Viro i->count += unroll; 110800e23707SDavid Howells if (unlikely(iov_iter_is_pipe(i))) { 110927c0e374SAl Viro struct pipe_inode_info *pipe = i->pipe; 11108cefc107SDavid Howells unsigned int p_mask = pipe->ring_size - 1; 11118cefc107SDavid Howells unsigned int i_head = i->head; 111227c0e374SAl Viro size_t off = i->iov_offset; 111327c0e374SAl Viro while (1) { 11148cefc107SDavid Howells struct pipe_buffer *b = &pipe->bufs[i_head & p_mask]; 11158cefc107SDavid Howells size_t n = off - b->offset; 111627c0e374SAl Viro if (unroll < n) { 11174fa55cefSAl Viro off -= unroll; 111827c0e374SAl Viro break; 111927c0e374SAl Viro } 112027c0e374SAl Viro unroll -= n; 11218cefc107SDavid Howells if (!unroll && i_head == i->start_head) { 112227c0e374SAl Viro off = 0; 112327c0e374SAl Viro break; 112427c0e374SAl Viro } 11258cefc107SDavid Howells i_head--; 11268cefc107SDavid Howells b = &pipe->bufs[i_head & p_mask]; 11278cefc107SDavid Howells off = b->offset + b->len; 112827c0e374SAl Viro } 112927c0e374SAl Viro i->iov_offset = off; 11308cefc107SDavid Howells i->head = i_head; 113127c0e374SAl Viro pipe_truncate(i); 113227c0e374SAl Viro return; 113327c0e374SAl Viro } 11349ea9ce04SDavid Howells if (unlikely(iov_iter_is_discard(i))) 11359ea9ce04SDavid Howells return; 113627c0e374SAl Viro if (unroll <= i->iov_offset) { 113727c0e374SAl Viro i->iov_offset -= unroll; 113827c0e374SAl Viro return; 113927c0e374SAl Viro } 114027c0e374SAl Viro unroll -= i->iov_offset; 114100e23707SDavid Howells if (iov_iter_is_bvec(i)) { 114227c0e374SAl Viro const struct bio_vec *bvec = i->bvec; 114327c0e374SAl Viro while (1) { 114427c0e374SAl Viro size_t n = (--bvec)->bv_len; 114527c0e374SAl Viro i->nr_segs++; 114627c0e374SAl Viro if (unroll <= n) { 114727c0e374SAl Viro i->bvec = bvec; 114827c0e374SAl Viro i->iov_offset = n - unroll; 114927c0e374SAl Viro return; 115027c0e374SAl Viro } 115127c0e374SAl Viro unroll -= n; 115227c0e374SAl Viro } 115327c0e374SAl Viro } else { /* same logics for iovec and kvec */ 115427c0e374SAl Viro const struct iovec *iov = i->iov; 115527c0e374SAl Viro while (1) { 115627c0e374SAl Viro size_t n = (--iov)->iov_len; 115727c0e374SAl Viro i->nr_segs++; 115827c0e374SAl Viro if (unroll <= n) { 115927c0e374SAl Viro i->iov = iov; 116027c0e374SAl Viro i->iov_offset = n - unroll; 116127c0e374SAl Viro return; 116227c0e374SAl Viro } 116327c0e374SAl Viro unroll -= n; 116427c0e374SAl Viro } 116527c0e374SAl Viro } 116627c0e374SAl Viro } 116727c0e374SAl Viro EXPORT_SYMBOL(iov_iter_revert); 116827c0e374SAl Viro 1169d879cb83SAl Viro /* 1170d879cb83SAl Viro * Return the count of just the current iov_iter segment. 1171d879cb83SAl Viro */ 1172d879cb83SAl Viro size_t iov_iter_single_seg_count(const struct iov_iter *i) 1173d879cb83SAl Viro { 117400e23707SDavid Howells if (unlikely(iov_iter_is_pipe(i))) 1175241699cdSAl Viro return i->count; // it is a silly place, anyway 1176d879cb83SAl Viro if (i->nr_segs == 1) 1177d879cb83SAl Viro return i->count; 11789ea9ce04SDavid Howells if (unlikely(iov_iter_is_discard(i))) 11799ea9ce04SDavid Howells return i->count; 118000e23707SDavid Howells else if (iov_iter_is_bvec(i)) 1181d879cb83SAl Viro return min(i->count, i->bvec->bv_len - i->iov_offset); 1182d879cb83SAl Viro else 1183d879cb83SAl Viro return min(i->count, i->iov->iov_len - i->iov_offset); 1184d879cb83SAl Viro } 1185d879cb83SAl Viro EXPORT_SYMBOL(iov_iter_single_seg_count); 1186d879cb83SAl Viro 1187aa563d7bSDavid Howells void iov_iter_kvec(struct iov_iter *i, unsigned int direction, 1188d879cb83SAl Viro const struct kvec *kvec, unsigned long nr_segs, 1189d879cb83SAl Viro size_t count) 1190d879cb83SAl Viro { 1191aa563d7bSDavid Howells WARN_ON(direction & ~(READ | WRITE)); 1192aa563d7bSDavid Howells i->type = ITER_KVEC | (direction & (READ | WRITE)); 1193d879cb83SAl Viro i->kvec = kvec; 1194d879cb83SAl Viro i->nr_segs = nr_segs; 1195d879cb83SAl Viro i->iov_offset = 0; 1196d879cb83SAl Viro i->count = count; 1197d879cb83SAl Viro } 1198d879cb83SAl Viro EXPORT_SYMBOL(iov_iter_kvec); 1199d879cb83SAl Viro 1200aa563d7bSDavid Howells void iov_iter_bvec(struct iov_iter *i, unsigned int direction, 1201d879cb83SAl Viro const struct bio_vec *bvec, unsigned long nr_segs, 1202d879cb83SAl Viro size_t count) 1203d879cb83SAl Viro { 1204aa563d7bSDavid Howells WARN_ON(direction & ~(READ | WRITE)); 1205aa563d7bSDavid Howells i->type = ITER_BVEC | (direction & (READ | WRITE)); 1206d879cb83SAl Viro i->bvec = bvec; 1207d879cb83SAl Viro i->nr_segs = nr_segs; 1208d879cb83SAl Viro i->iov_offset = 0; 1209d879cb83SAl Viro i->count = count; 1210d879cb83SAl Viro } 1211d879cb83SAl Viro EXPORT_SYMBOL(iov_iter_bvec); 1212d879cb83SAl Viro 1213aa563d7bSDavid Howells void iov_iter_pipe(struct iov_iter *i, unsigned int direction, 1214241699cdSAl Viro struct pipe_inode_info *pipe, 1215241699cdSAl Viro size_t count) 1216241699cdSAl Viro { 1217aa563d7bSDavid Howells BUG_ON(direction != READ); 12188cefc107SDavid Howells WARN_ON(pipe_full(pipe->head, pipe->tail, pipe->ring_size)); 1219aa563d7bSDavid Howells i->type = ITER_PIPE | READ; 1220241699cdSAl Viro i->pipe = pipe; 12218cefc107SDavid Howells i->head = pipe->head; 1222241699cdSAl Viro i->iov_offset = 0; 1223241699cdSAl Viro i->count = count; 12248cefc107SDavid Howells i->start_head = i->head; 1225241699cdSAl Viro } 1226241699cdSAl Viro EXPORT_SYMBOL(iov_iter_pipe); 1227241699cdSAl Viro 12289ea9ce04SDavid Howells /** 12299ea9ce04SDavid Howells * iov_iter_discard - Initialise an I/O iterator that discards data 12309ea9ce04SDavid Howells * @i: The iterator to initialise. 12319ea9ce04SDavid Howells * @direction: The direction of the transfer. 12329ea9ce04SDavid Howells * @count: The size of the I/O buffer in bytes. 12339ea9ce04SDavid Howells * 12349ea9ce04SDavid Howells * Set up an I/O iterator that just discards everything that's written to it. 12359ea9ce04SDavid Howells * It's only available as a READ iterator. 12369ea9ce04SDavid Howells */ 12379ea9ce04SDavid Howells void iov_iter_discard(struct iov_iter *i, unsigned int direction, size_t count) 12389ea9ce04SDavid Howells { 12399ea9ce04SDavid Howells BUG_ON(direction != READ); 12409ea9ce04SDavid Howells i->type = ITER_DISCARD | READ; 12419ea9ce04SDavid Howells i->count = count; 12429ea9ce04SDavid Howells i->iov_offset = 0; 12439ea9ce04SDavid Howells } 12449ea9ce04SDavid Howells EXPORT_SYMBOL(iov_iter_discard); 12459ea9ce04SDavid Howells 1246d879cb83SAl Viro unsigned long iov_iter_alignment(const struct iov_iter *i) 1247d879cb83SAl Viro { 1248d879cb83SAl Viro unsigned long res = 0; 1249d879cb83SAl Viro size_t size = i->count; 1250d879cb83SAl Viro 125100e23707SDavid Howells if (unlikely(iov_iter_is_pipe(i))) { 1252e0ff126eSJan Kara unsigned int p_mask = i->pipe->ring_size - 1; 1253e0ff126eSJan Kara 12548cefc107SDavid Howells if (size && i->iov_offset && allocated(&i->pipe->bufs[i->head & p_mask])) 1255241699cdSAl Viro return size | i->iov_offset; 1256241699cdSAl Viro return size; 1257241699cdSAl Viro } 1258d879cb83SAl Viro iterate_all_kinds(i, size, v, 1259d879cb83SAl Viro (res |= (unsigned long)v.iov_base | v.iov_len, 0), 1260d879cb83SAl Viro res |= v.bv_offset | v.bv_len, 1261d879cb83SAl Viro res |= (unsigned long)v.iov_base | v.iov_len 1262d879cb83SAl Viro ) 1263d879cb83SAl Viro return res; 1264d879cb83SAl Viro } 1265d879cb83SAl Viro EXPORT_SYMBOL(iov_iter_alignment); 1266d879cb83SAl Viro 1267357f435dSAl Viro unsigned long iov_iter_gap_alignment(const struct iov_iter *i) 1268357f435dSAl Viro { 1269357f435dSAl Viro unsigned long res = 0; 1270357f435dSAl Viro size_t size = i->count; 1271357f435dSAl Viro 12729ea9ce04SDavid Howells if (unlikely(iov_iter_is_pipe(i) || iov_iter_is_discard(i))) { 1273241699cdSAl Viro WARN_ON(1); 1274241699cdSAl Viro return ~0U; 1275241699cdSAl Viro } 1276241699cdSAl Viro 1277357f435dSAl Viro iterate_all_kinds(i, size, v, 1278357f435dSAl Viro (res |= (!res ? 0 : (unsigned long)v.iov_base) | 1279357f435dSAl Viro (size != v.iov_len ? size : 0), 0), 1280357f435dSAl Viro (res |= (!res ? 0 : (unsigned long)v.bv_offset) | 1281357f435dSAl Viro (size != v.bv_len ? size : 0)), 1282357f435dSAl Viro (res |= (!res ? 0 : (unsigned long)v.iov_base) | 1283357f435dSAl Viro (size != v.iov_len ? size : 0)) 1284357f435dSAl Viro ); 1285357f435dSAl Viro return res; 1286357f435dSAl Viro } 1287357f435dSAl Viro EXPORT_SYMBOL(iov_iter_gap_alignment); 1288357f435dSAl Viro 1289e76b6312SIlya Dryomov static inline ssize_t __pipe_get_pages(struct iov_iter *i, 1290241699cdSAl Viro size_t maxsize, 1291241699cdSAl Viro struct page **pages, 12928cefc107SDavid Howells int iter_head, 1293241699cdSAl Viro size_t *start) 1294241699cdSAl Viro { 1295241699cdSAl Viro struct pipe_inode_info *pipe = i->pipe; 12968cefc107SDavid Howells unsigned int p_mask = pipe->ring_size - 1; 12978cefc107SDavid Howells ssize_t n = push_pipe(i, maxsize, &iter_head, start); 1298241699cdSAl Viro if (!n) 1299241699cdSAl Viro return -EFAULT; 1300241699cdSAl Viro 1301241699cdSAl Viro maxsize = n; 1302241699cdSAl Viro n += *start; 13031689c73aSAl Viro while (n > 0) { 13048cefc107SDavid Howells get_page(*pages++ = pipe->bufs[iter_head & p_mask].page); 13058cefc107SDavid Howells iter_head++; 1306241699cdSAl Viro n -= PAGE_SIZE; 1307241699cdSAl Viro } 1308241699cdSAl Viro 1309241699cdSAl Viro return maxsize; 1310241699cdSAl Viro } 1311241699cdSAl Viro 1312241699cdSAl Viro static ssize_t pipe_get_pages(struct iov_iter *i, 1313241699cdSAl Viro struct page **pages, size_t maxsize, unsigned maxpages, 1314241699cdSAl Viro size_t *start) 1315241699cdSAl Viro { 13168cefc107SDavid Howells unsigned int iter_head, npages; 1317241699cdSAl Viro size_t capacity; 1318241699cdSAl Viro 131933844e66SAl Viro if (!maxsize) 132033844e66SAl Viro return 0; 132133844e66SAl Viro 1322241699cdSAl Viro if (!sanity(i)) 1323241699cdSAl Viro return -EFAULT; 1324241699cdSAl Viro 13258cefc107SDavid Howells data_start(i, &iter_head, start); 13268cefc107SDavid Howells /* Amount of free space: some of this one + all after this one */ 13278cefc107SDavid Howells npages = pipe_space_for_user(iter_head, i->pipe->tail, i->pipe); 1328241699cdSAl Viro capacity = min(npages, maxpages) * PAGE_SIZE - *start; 1329241699cdSAl Viro 13308cefc107SDavid Howells return __pipe_get_pages(i, min(maxsize, capacity), pages, iter_head, start); 1331241699cdSAl Viro } 1332241699cdSAl Viro 1333d879cb83SAl Viro ssize_t iov_iter_get_pages(struct iov_iter *i, 1334d879cb83SAl Viro struct page **pages, size_t maxsize, unsigned maxpages, 1335d879cb83SAl Viro size_t *start) 1336d879cb83SAl Viro { 1337d879cb83SAl Viro if (maxsize > i->count) 1338d879cb83SAl Viro maxsize = i->count; 1339d879cb83SAl Viro 134000e23707SDavid Howells if (unlikely(iov_iter_is_pipe(i))) 1341241699cdSAl Viro return pipe_get_pages(i, pages, maxsize, maxpages, start); 13429ea9ce04SDavid Howells if (unlikely(iov_iter_is_discard(i))) 13439ea9ce04SDavid Howells return -EFAULT; 13449ea9ce04SDavid Howells 1345d879cb83SAl Viro iterate_all_kinds(i, maxsize, v, ({ 1346d879cb83SAl Viro unsigned long addr = (unsigned long)v.iov_base; 1347d879cb83SAl Viro size_t len = v.iov_len + (*start = addr & (PAGE_SIZE - 1)); 1348d879cb83SAl Viro int n; 1349d879cb83SAl Viro int res; 1350d879cb83SAl Viro 1351d879cb83SAl Viro if (len > maxpages * PAGE_SIZE) 1352d879cb83SAl Viro len = maxpages * PAGE_SIZE; 1353d879cb83SAl Viro addr &= ~(PAGE_SIZE - 1); 1354d879cb83SAl Viro n = DIV_ROUND_UP(len, PAGE_SIZE); 135573b0140bSIra Weiny res = get_user_pages_fast(addr, n, 135673b0140bSIra Weiny iov_iter_rw(i) != WRITE ? FOLL_WRITE : 0, 135773b0140bSIra Weiny pages); 1358d879cb83SAl Viro if (unlikely(res < 0)) 1359d879cb83SAl Viro return res; 1360d879cb83SAl Viro return (res == n ? len : res * PAGE_SIZE) - *start; 1361d879cb83SAl Viro 0;}),({ 1362d879cb83SAl Viro /* can't be more than PAGE_SIZE */ 1363d879cb83SAl Viro *start = v.bv_offset; 1364d879cb83SAl Viro get_page(*pages = v.bv_page); 1365d879cb83SAl Viro return v.bv_len; 1366d879cb83SAl Viro }),({ 1367d879cb83SAl Viro return -EFAULT; 1368d879cb83SAl Viro }) 1369d879cb83SAl Viro ) 1370d879cb83SAl Viro return 0; 1371d879cb83SAl Viro } 1372d879cb83SAl Viro EXPORT_SYMBOL(iov_iter_get_pages); 1373d879cb83SAl Viro 1374d879cb83SAl Viro static struct page **get_pages_array(size_t n) 1375d879cb83SAl Viro { 1376752ade68SMichal Hocko return kvmalloc_array(n, sizeof(struct page *), GFP_KERNEL); 1377d879cb83SAl Viro } 1378d879cb83SAl Viro 1379241699cdSAl Viro static ssize_t pipe_get_pages_alloc(struct iov_iter *i, 1380241699cdSAl Viro struct page ***pages, size_t maxsize, 1381241699cdSAl Viro size_t *start) 1382241699cdSAl Viro { 1383241699cdSAl Viro struct page **p; 13848cefc107SDavid Howells unsigned int iter_head, npages; 1385d7760d63SIlya Dryomov ssize_t n; 1386241699cdSAl Viro 138733844e66SAl Viro if (!maxsize) 138833844e66SAl Viro return 0; 138933844e66SAl Viro 1390241699cdSAl Viro if (!sanity(i)) 1391241699cdSAl Viro return -EFAULT; 1392241699cdSAl Viro 13938cefc107SDavid Howells data_start(i, &iter_head, start); 13948cefc107SDavid Howells /* Amount of free space: some of this one + all after this one */ 13958cefc107SDavid Howells npages = pipe_space_for_user(iter_head, i->pipe->tail, i->pipe); 1396241699cdSAl Viro n = npages * PAGE_SIZE - *start; 1397241699cdSAl Viro if (maxsize > n) 1398241699cdSAl Viro maxsize = n; 1399241699cdSAl Viro else 1400241699cdSAl Viro npages = DIV_ROUND_UP(maxsize + *start, PAGE_SIZE); 1401241699cdSAl Viro p = get_pages_array(npages); 1402241699cdSAl Viro if (!p) 1403241699cdSAl Viro return -ENOMEM; 14048cefc107SDavid Howells n = __pipe_get_pages(i, maxsize, p, iter_head, start); 1405241699cdSAl Viro if (n > 0) 1406241699cdSAl Viro *pages = p; 1407241699cdSAl Viro else 1408241699cdSAl Viro kvfree(p); 1409241699cdSAl Viro return n; 1410241699cdSAl Viro } 1411241699cdSAl Viro 1412d879cb83SAl Viro ssize_t iov_iter_get_pages_alloc(struct iov_iter *i, 1413d879cb83SAl Viro struct page ***pages, size_t maxsize, 1414d879cb83SAl Viro size_t *start) 1415d879cb83SAl Viro { 1416d879cb83SAl Viro struct page **p; 1417d879cb83SAl Viro 1418d879cb83SAl Viro if (maxsize > i->count) 1419d879cb83SAl Viro maxsize = i->count; 1420d879cb83SAl Viro 142100e23707SDavid Howells if (unlikely(iov_iter_is_pipe(i))) 1422241699cdSAl Viro return pipe_get_pages_alloc(i, pages, maxsize, start); 14239ea9ce04SDavid Howells if (unlikely(iov_iter_is_discard(i))) 14249ea9ce04SDavid Howells return -EFAULT; 14259ea9ce04SDavid Howells 1426d879cb83SAl Viro iterate_all_kinds(i, maxsize, v, ({ 1427d879cb83SAl Viro unsigned long addr = (unsigned long)v.iov_base; 1428d879cb83SAl Viro size_t len = v.iov_len + (*start = addr & (PAGE_SIZE - 1)); 1429d879cb83SAl Viro int n; 1430d879cb83SAl Viro int res; 1431d879cb83SAl Viro 1432d879cb83SAl Viro addr &= ~(PAGE_SIZE - 1); 1433d879cb83SAl Viro n = DIV_ROUND_UP(len, PAGE_SIZE); 1434d879cb83SAl Viro p = get_pages_array(n); 1435d879cb83SAl Viro if (!p) 1436d879cb83SAl Viro return -ENOMEM; 143773b0140bSIra Weiny res = get_user_pages_fast(addr, n, 143873b0140bSIra Weiny iov_iter_rw(i) != WRITE ? FOLL_WRITE : 0, p); 1439d879cb83SAl Viro if (unlikely(res < 0)) { 1440d879cb83SAl Viro kvfree(p); 1441d879cb83SAl Viro return res; 1442d879cb83SAl Viro } 1443d879cb83SAl Viro *pages = p; 1444d879cb83SAl Viro return (res == n ? len : res * PAGE_SIZE) - *start; 1445d879cb83SAl Viro 0;}),({ 1446d879cb83SAl Viro /* can't be more than PAGE_SIZE */ 1447d879cb83SAl Viro *start = v.bv_offset; 1448d879cb83SAl Viro *pages = p = get_pages_array(1); 1449d879cb83SAl Viro if (!p) 1450d879cb83SAl Viro return -ENOMEM; 1451d879cb83SAl Viro get_page(*p = v.bv_page); 1452d879cb83SAl Viro return v.bv_len; 1453d879cb83SAl Viro }),({ 1454d879cb83SAl Viro return -EFAULT; 1455d879cb83SAl Viro }) 1456d879cb83SAl Viro ) 1457d879cb83SAl Viro return 0; 1458d879cb83SAl Viro } 1459d879cb83SAl Viro EXPORT_SYMBOL(iov_iter_get_pages_alloc); 1460d879cb83SAl Viro 1461d879cb83SAl Viro size_t csum_and_copy_from_iter(void *addr, size_t bytes, __wsum *csum, 1462d879cb83SAl Viro struct iov_iter *i) 1463d879cb83SAl Viro { 1464d879cb83SAl Viro char *to = addr; 1465d879cb83SAl Viro __wsum sum, next; 1466d879cb83SAl Viro size_t off = 0; 1467d879cb83SAl Viro sum = *csum; 14689ea9ce04SDavid Howells if (unlikely(iov_iter_is_pipe(i) || iov_iter_is_discard(i))) { 1469241699cdSAl Viro WARN_ON(1); 1470241699cdSAl Viro return 0; 1471241699cdSAl Viro } 1472d879cb83SAl Viro iterate_and_advance(i, bytes, v, ({ 1473d879cb83SAl Viro next = csum_and_copy_from_user(v.iov_base, 1474d879cb83SAl Viro (to += v.iov_len) - v.iov_len, 1475c693cc46SAl Viro v.iov_len); 1476c693cc46SAl Viro if (next) { 1477d879cb83SAl Viro sum = csum_block_add(sum, next, off); 1478d879cb83SAl Viro off += v.iov_len; 1479d879cb83SAl Viro } 1480c693cc46SAl Viro next ? 0 : v.iov_len; 1481d879cb83SAl Viro }), ({ 1482d879cb83SAl Viro char *p = kmap_atomic(v.bv_page); 1483f9152895SAl Viro sum = csum_and_memcpy((to += v.bv_len) - v.bv_len, 1484f9152895SAl Viro p + v.bv_offset, v.bv_len, 1485f9152895SAl Viro sum, off); 1486d879cb83SAl Viro kunmap_atomic(p); 1487d879cb83SAl Viro off += v.bv_len; 1488d879cb83SAl Viro }),({ 1489f9152895SAl Viro sum = csum_and_memcpy((to += v.iov_len) - v.iov_len, 1490f9152895SAl Viro v.iov_base, v.iov_len, 1491f9152895SAl Viro sum, off); 1492d879cb83SAl Viro off += v.iov_len; 1493d879cb83SAl Viro }) 1494d879cb83SAl Viro ) 1495d879cb83SAl Viro *csum = sum; 1496d879cb83SAl Viro return bytes; 1497d879cb83SAl Viro } 1498d879cb83SAl Viro EXPORT_SYMBOL(csum_and_copy_from_iter); 1499d879cb83SAl Viro 1500cbbd26b8SAl Viro bool csum_and_copy_from_iter_full(void *addr, size_t bytes, __wsum *csum, 1501cbbd26b8SAl Viro struct iov_iter *i) 1502cbbd26b8SAl Viro { 1503cbbd26b8SAl Viro char *to = addr; 1504cbbd26b8SAl Viro __wsum sum, next; 1505cbbd26b8SAl Viro size_t off = 0; 1506cbbd26b8SAl Viro sum = *csum; 15079ea9ce04SDavid Howells if (unlikely(iov_iter_is_pipe(i) || iov_iter_is_discard(i))) { 1508cbbd26b8SAl Viro WARN_ON(1); 1509cbbd26b8SAl Viro return false; 1510cbbd26b8SAl Viro } 1511cbbd26b8SAl Viro if (unlikely(i->count < bytes)) 1512cbbd26b8SAl Viro return false; 1513cbbd26b8SAl Viro iterate_all_kinds(i, bytes, v, ({ 1514cbbd26b8SAl Viro next = csum_and_copy_from_user(v.iov_base, 1515cbbd26b8SAl Viro (to += v.iov_len) - v.iov_len, 1516c693cc46SAl Viro v.iov_len); 1517c693cc46SAl Viro if (!next) 1518cbbd26b8SAl Viro return false; 1519cbbd26b8SAl Viro sum = csum_block_add(sum, next, off); 1520cbbd26b8SAl Viro off += v.iov_len; 1521cbbd26b8SAl Viro 0; 1522cbbd26b8SAl Viro }), ({ 1523cbbd26b8SAl Viro char *p = kmap_atomic(v.bv_page); 1524f9152895SAl Viro sum = csum_and_memcpy((to += v.bv_len) - v.bv_len, 1525f9152895SAl Viro p + v.bv_offset, v.bv_len, 1526f9152895SAl Viro sum, off); 1527cbbd26b8SAl Viro kunmap_atomic(p); 1528cbbd26b8SAl Viro off += v.bv_len; 1529cbbd26b8SAl Viro }),({ 1530f9152895SAl Viro sum = csum_and_memcpy((to += v.iov_len) - v.iov_len, 1531f9152895SAl Viro v.iov_base, v.iov_len, 1532f9152895SAl Viro sum, off); 1533cbbd26b8SAl Viro off += v.iov_len; 1534cbbd26b8SAl Viro }) 1535cbbd26b8SAl Viro ) 1536cbbd26b8SAl Viro *csum = sum; 1537cbbd26b8SAl Viro iov_iter_advance(i, bytes); 1538cbbd26b8SAl Viro return true; 1539cbbd26b8SAl Viro } 1540cbbd26b8SAl Viro EXPORT_SYMBOL(csum_and_copy_from_iter_full); 1541cbbd26b8SAl Viro 1542cb002d07SSagi Grimberg size_t csum_and_copy_to_iter(const void *addr, size_t bytes, void *csump, 1543d879cb83SAl Viro struct iov_iter *i) 1544d879cb83SAl Viro { 154536f7a8a4SAl Viro const char *from = addr; 1546cb002d07SSagi Grimberg __wsum *csum = csump; 1547d879cb83SAl Viro __wsum sum, next; 1548d879cb83SAl Viro size_t off = 0; 154978e1f386SAl Viro 155078e1f386SAl Viro if (unlikely(iov_iter_is_pipe(i))) 155178e1f386SAl Viro return csum_and_copy_to_pipe_iter(addr, bytes, csum, i); 155278e1f386SAl Viro 1553d879cb83SAl Viro sum = *csum; 155478e1f386SAl Viro if (unlikely(iov_iter_is_discard(i))) { 1555241699cdSAl Viro WARN_ON(1); /* for now */ 1556241699cdSAl Viro return 0; 1557241699cdSAl Viro } 1558d879cb83SAl Viro iterate_and_advance(i, bytes, v, ({ 1559d879cb83SAl Viro next = csum_and_copy_to_user((from += v.iov_len) - v.iov_len, 1560d879cb83SAl Viro v.iov_base, 1561c693cc46SAl Viro v.iov_len); 1562c693cc46SAl Viro if (next) { 1563d879cb83SAl Viro sum = csum_block_add(sum, next, off); 1564d879cb83SAl Viro off += v.iov_len; 1565d879cb83SAl Viro } 1566c693cc46SAl Viro next ? 0 : v.iov_len; 1567d879cb83SAl Viro }), ({ 1568d879cb83SAl Viro char *p = kmap_atomic(v.bv_page); 1569f9152895SAl Viro sum = csum_and_memcpy(p + v.bv_offset, 1570f9152895SAl Viro (from += v.bv_len) - v.bv_len, 1571f9152895SAl Viro v.bv_len, sum, off); 1572d879cb83SAl Viro kunmap_atomic(p); 1573d879cb83SAl Viro off += v.bv_len; 1574d879cb83SAl Viro }),({ 1575f9152895SAl Viro sum = csum_and_memcpy(v.iov_base, 1576f9152895SAl Viro (from += v.iov_len) - v.iov_len, 1577f9152895SAl Viro v.iov_len, sum, off); 1578d879cb83SAl Viro off += v.iov_len; 1579d879cb83SAl Viro }) 1580d879cb83SAl Viro ) 1581d879cb83SAl Viro *csum = sum; 1582d879cb83SAl Viro return bytes; 1583d879cb83SAl Viro } 1584d879cb83SAl Viro EXPORT_SYMBOL(csum_and_copy_to_iter); 1585d879cb83SAl Viro 1586d05f4435SSagi Grimberg size_t hash_and_copy_to_iter(const void *addr, size_t bytes, void *hashp, 1587d05f4435SSagi Grimberg struct iov_iter *i) 1588d05f4435SSagi Grimberg { 15897999096fSHerbert Xu #ifdef CONFIG_CRYPTO_HASH 1590d05f4435SSagi Grimberg struct ahash_request *hash = hashp; 1591d05f4435SSagi Grimberg struct scatterlist sg; 1592d05f4435SSagi Grimberg size_t copied; 1593d05f4435SSagi Grimberg 1594d05f4435SSagi Grimberg copied = copy_to_iter(addr, bytes, i); 1595d05f4435SSagi Grimberg sg_init_one(&sg, addr, copied); 1596d05f4435SSagi Grimberg ahash_request_set_crypt(hash, &sg, NULL, copied); 1597d05f4435SSagi Grimberg crypto_ahash_update(hash); 1598d05f4435SSagi Grimberg return copied; 159927fad74aSYueHaibing #else 160027fad74aSYueHaibing return 0; 160127fad74aSYueHaibing #endif 1602d05f4435SSagi Grimberg } 1603d05f4435SSagi Grimberg EXPORT_SYMBOL(hash_and_copy_to_iter); 1604d05f4435SSagi Grimberg 1605d879cb83SAl Viro int iov_iter_npages(const struct iov_iter *i, int maxpages) 1606d879cb83SAl Viro { 1607d879cb83SAl Viro size_t size = i->count; 1608d879cb83SAl Viro int npages = 0; 1609d879cb83SAl Viro 1610d879cb83SAl Viro if (!size) 1611d879cb83SAl Viro return 0; 16129ea9ce04SDavid Howells if (unlikely(iov_iter_is_discard(i))) 16139ea9ce04SDavid Howells return 0; 1614d879cb83SAl Viro 161500e23707SDavid Howells if (unlikely(iov_iter_is_pipe(i))) { 1616241699cdSAl Viro struct pipe_inode_info *pipe = i->pipe; 16178cefc107SDavid Howells unsigned int iter_head; 1618241699cdSAl Viro size_t off; 1619241699cdSAl Viro 1620241699cdSAl Viro if (!sanity(i)) 1621241699cdSAl Viro return 0; 1622241699cdSAl Viro 16238cefc107SDavid Howells data_start(i, &iter_head, &off); 1624241699cdSAl Viro /* some of this one + all after this one */ 16258cefc107SDavid Howells npages = pipe_space_for_user(iter_head, pipe->tail, pipe); 1626241699cdSAl Viro if (npages >= maxpages) 1627241699cdSAl Viro return maxpages; 1628241699cdSAl Viro } else iterate_all_kinds(i, size, v, ({ 1629d879cb83SAl Viro unsigned long p = (unsigned long)v.iov_base; 1630d879cb83SAl Viro npages += DIV_ROUND_UP(p + v.iov_len, PAGE_SIZE) 1631d879cb83SAl Viro - p / PAGE_SIZE; 1632d879cb83SAl Viro if (npages >= maxpages) 1633d879cb83SAl Viro return maxpages; 1634d879cb83SAl Viro 0;}),({ 1635d879cb83SAl Viro npages++; 1636d879cb83SAl Viro if (npages >= maxpages) 1637d879cb83SAl Viro return maxpages; 1638d879cb83SAl Viro }),({ 1639d879cb83SAl Viro unsigned long p = (unsigned long)v.iov_base; 1640d879cb83SAl Viro npages += DIV_ROUND_UP(p + v.iov_len, PAGE_SIZE) 1641d879cb83SAl Viro - p / PAGE_SIZE; 1642d879cb83SAl Viro if (npages >= maxpages) 1643d879cb83SAl Viro return maxpages; 1644d879cb83SAl Viro }) 1645d879cb83SAl Viro ) 1646d879cb83SAl Viro return npages; 1647d879cb83SAl Viro } 1648d879cb83SAl Viro EXPORT_SYMBOL(iov_iter_npages); 1649d879cb83SAl Viro 1650d879cb83SAl Viro const void *dup_iter(struct iov_iter *new, struct iov_iter *old, gfp_t flags) 1651d879cb83SAl Viro { 1652d879cb83SAl Viro *new = *old; 165300e23707SDavid Howells if (unlikely(iov_iter_is_pipe(new))) { 1654241699cdSAl Viro WARN_ON(1); 1655241699cdSAl Viro return NULL; 1656241699cdSAl Viro } 16579ea9ce04SDavid Howells if (unlikely(iov_iter_is_discard(new))) 16589ea9ce04SDavid Howells return NULL; 165900e23707SDavid Howells if (iov_iter_is_bvec(new)) 1660d879cb83SAl Viro return new->bvec = kmemdup(new->bvec, 1661d879cb83SAl Viro new->nr_segs * sizeof(struct bio_vec), 1662d879cb83SAl Viro flags); 1663d879cb83SAl Viro else 1664d879cb83SAl Viro /* iovec and kvec have identical layout */ 1665d879cb83SAl Viro return new->iov = kmemdup(new->iov, 1666d879cb83SAl Viro new->nr_segs * sizeof(struct iovec), 1667d879cb83SAl Viro flags); 1668d879cb83SAl Viro } 1669d879cb83SAl Viro EXPORT_SYMBOL(dup_iter); 1670bc917be8SAl Viro 1671bfdc5970SChristoph Hellwig static int copy_compat_iovec_from_user(struct iovec *iov, 1672bfdc5970SChristoph Hellwig const struct iovec __user *uvec, unsigned long nr_segs) 1673bfdc5970SChristoph Hellwig { 1674bfdc5970SChristoph Hellwig const struct compat_iovec __user *uiov = 1675bfdc5970SChristoph Hellwig (const struct compat_iovec __user *)uvec; 1676bfdc5970SChristoph Hellwig int ret = -EFAULT, i; 1677bfdc5970SChristoph Hellwig 1678a959a978SChristoph Hellwig if (!user_access_begin(uiov, nr_segs * sizeof(*uiov))) 1679bfdc5970SChristoph Hellwig return -EFAULT; 1680bfdc5970SChristoph Hellwig 1681bfdc5970SChristoph Hellwig for (i = 0; i < nr_segs; i++) { 1682bfdc5970SChristoph Hellwig compat_uptr_t buf; 1683bfdc5970SChristoph Hellwig compat_ssize_t len; 1684bfdc5970SChristoph Hellwig 1685bfdc5970SChristoph Hellwig unsafe_get_user(len, &uiov[i].iov_len, uaccess_end); 1686bfdc5970SChristoph Hellwig unsafe_get_user(buf, &uiov[i].iov_base, uaccess_end); 1687bfdc5970SChristoph Hellwig 1688bfdc5970SChristoph Hellwig /* check for compat_size_t not fitting in compat_ssize_t .. */ 1689bfdc5970SChristoph Hellwig if (len < 0) { 1690bfdc5970SChristoph Hellwig ret = -EINVAL; 1691bfdc5970SChristoph Hellwig goto uaccess_end; 1692bfdc5970SChristoph Hellwig } 1693bfdc5970SChristoph Hellwig iov[i].iov_base = compat_ptr(buf); 1694bfdc5970SChristoph Hellwig iov[i].iov_len = len; 1695bfdc5970SChristoph Hellwig } 1696bfdc5970SChristoph Hellwig 1697bfdc5970SChristoph Hellwig ret = 0; 1698bfdc5970SChristoph Hellwig uaccess_end: 1699bfdc5970SChristoph Hellwig user_access_end(); 1700bfdc5970SChristoph Hellwig return ret; 1701bfdc5970SChristoph Hellwig } 1702bfdc5970SChristoph Hellwig 1703bfdc5970SChristoph Hellwig static int copy_iovec_from_user(struct iovec *iov, 1704bfdc5970SChristoph Hellwig const struct iovec __user *uvec, unsigned long nr_segs) 1705fb041b59SDavid Laight { 1706fb041b59SDavid Laight unsigned long seg; 1707bfdc5970SChristoph Hellwig 1708bfdc5970SChristoph Hellwig if (copy_from_user(iov, uvec, nr_segs * sizeof(*uvec))) 1709bfdc5970SChristoph Hellwig return -EFAULT; 1710bfdc5970SChristoph Hellwig for (seg = 0; seg < nr_segs; seg++) { 1711bfdc5970SChristoph Hellwig if ((ssize_t)iov[seg].iov_len < 0) 1712bfdc5970SChristoph Hellwig return -EINVAL; 1713bfdc5970SChristoph Hellwig } 1714bfdc5970SChristoph Hellwig 1715bfdc5970SChristoph Hellwig return 0; 1716bfdc5970SChristoph Hellwig } 1717bfdc5970SChristoph Hellwig 1718bfdc5970SChristoph Hellwig struct iovec *iovec_from_user(const struct iovec __user *uvec, 1719bfdc5970SChristoph Hellwig unsigned long nr_segs, unsigned long fast_segs, 1720bfdc5970SChristoph Hellwig struct iovec *fast_iov, bool compat) 1721bfdc5970SChristoph Hellwig { 1722bfdc5970SChristoph Hellwig struct iovec *iov = fast_iov; 1723bfdc5970SChristoph Hellwig int ret; 1724fb041b59SDavid Laight 1725fb041b59SDavid Laight /* 1726bfdc5970SChristoph Hellwig * SuS says "The readv() function *may* fail if the iovcnt argument was 1727bfdc5970SChristoph Hellwig * less than or equal to 0, or greater than {IOV_MAX}. Linux has 1728fb041b59SDavid Laight * traditionally returned zero for zero segments, so... 1729fb041b59SDavid Laight */ 1730bfdc5970SChristoph Hellwig if (nr_segs == 0) 1731bfdc5970SChristoph Hellwig return iov; 1732bfdc5970SChristoph Hellwig if (nr_segs > UIO_MAXIOV) 1733bfdc5970SChristoph Hellwig return ERR_PTR(-EINVAL); 1734fb041b59SDavid Laight if (nr_segs > fast_segs) { 1735fb041b59SDavid Laight iov = kmalloc_array(nr_segs, sizeof(struct iovec), GFP_KERNEL); 1736bfdc5970SChristoph Hellwig if (!iov) 1737bfdc5970SChristoph Hellwig return ERR_PTR(-ENOMEM); 1738fb041b59SDavid Laight } 1739bfdc5970SChristoph Hellwig 1740bfdc5970SChristoph Hellwig if (compat) 1741bfdc5970SChristoph Hellwig ret = copy_compat_iovec_from_user(iov, uvec, nr_segs); 1742bfdc5970SChristoph Hellwig else 1743bfdc5970SChristoph Hellwig ret = copy_iovec_from_user(iov, uvec, nr_segs); 1744bfdc5970SChristoph Hellwig if (ret) { 1745bfdc5970SChristoph Hellwig if (iov != fast_iov) 1746bfdc5970SChristoph Hellwig kfree(iov); 1747bfdc5970SChristoph Hellwig return ERR_PTR(ret); 1748fb041b59SDavid Laight } 1749bfdc5970SChristoph Hellwig 1750bfdc5970SChristoph Hellwig return iov; 1751bfdc5970SChristoph Hellwig } 1752bfdc5970SChristoph Hellwig 1753bfdc5970SChristoph Hellwig ssize_t __import_iovec(int type, const struct iovec __user *uvec, 1754bfdc5970SChristoph Hellwig unsigned nr_segs, unsigned fast_segs, struct iovec **iovp, 1755bfdc5970SChristoph Hellwig struct iov_iter *i, bool compat) 1756bfdc5970SChristoph Hellwig { 1757bfdc5970SChristoph Hellwig ssize_t total_len = 0; 1758bfdc5970SChristoph Hellwig unsigned long seg; 1759bfdc5970SChristoph Hellwig struct iovec *iov; 1760bfdc5970SChristoph Hellwig 1761bfdc5970SChristoph Hellwig iov = iovec_from_user(uvec, nr_segs, fast_segs, *iovp, compat); 1762bfdc5970SChristoph Hellwig if (IS_ERR(iov)) { 1763bfdc5970SChristoph Hellwig *iovp = NULL; 1764bfdc5970SChristoph Hellwig return PTR_ERR(iov); 1765fb041b59SDavid Laight } 1766fb041b59SDavid Laight 1767fb041b59SDavid Laight /* 1768bfdc5970SChristoph Hellwig * According to the Single Unix Specification we should return EINVAL if 1769bfdc5970SChristoph Hellwig * an element length is < 0 when cast to ssize_t or if the total length 1770bfdc5970SChristoph Hellwig * would overflow the ssize_t return value of the system call. 1771fb041b59SDavid Laight * 1772fb041b59SDavid Laight * Linux caps all read/write calls to MAX_RW_COUNT, and avoids the 1773fb041b59SDavid Laight * overflow case. 1774fb041b59SDavid Laight */ 1775fb041b59SDavid Laight for (seg = 0; seg < nr_segs; seg++) { 1776fb041b59SDavid Laight ssize_t len = (ssize_t)iov[seg].iov_len; 1777fb041b59SDavid Laight 1778bfdc5970SChristoph Hellwig if (!access_ok(iov[seg].iov_base, len)) { 1779bfdc5970SChristoph Hellwig if (iov != *iovp) 1780bfdc5970SChristoph Hellwig kfree(iov); 1781bfdc5970SChristoph Hellwig *iovp = NULL; 1782bfdc5970SChristoph Hellwig return -EFAULT; 1783fb041b59SDavid Laight } 1784bfdc5970SChristoph Hellwig 1785bfdc5970SChristoph Hellwig if (len > MAX_RW_COUNT - total_len) { 1786bfdc5970SChristoph Hellwig len = MAX_RW_COUNT - total_len; 1787fb041b59SDavid Laight iov[seg].iov_len = len; 1788fb041b59SDavid Laight } 1789bfdc5970SChristoph Hellwig total_len += len; 1790fb041b59SDavid Laight } 1791bfdc5970SChristoph Hellwig 1792bfdc5970SChristoph Hellwig iov_iter_init(i, type, iov, nr_segs, total_len); 1793bfdc5970SChristoph Hellwig if (iov == *iovp) 1794bfdc5970SChristoph Hellwig *iovp = NULL; 1795bfdc5970SChristoph Hellwig else 1796bfdc5970SChristoph Hellwig *iovp = iov; 1797bfdc5970SChristoph Hellwig return total_len; 1798fb041b59SDavid Laight } 1799fb041b59SDavid Laight 1800ffecee4fSVegard Nossum /** 1801ffecee4fSVegard Nossum * import_iovec() - Copy an array of &struct iovec from userspace 1802ffecee4fSVegard Nossum * into the kernel, check that it is valid, and initialize a new 1803ffecee4fSVegard Nossum * &struct iov_iter iterator to access it. 1804ffecee4fSVegard Nossum * 1805ffecee4fSVegard Nossum * @type: One of %READ or %WRITE. 1806bfdc5970SChristoph Hellwig * @uvec: Pointer to the userspace array. 1807ffecee4fSVegard Nossum * @nr_segs: Number of elements in userspace array. 1808ffecee4fSVegard Nossum * @fast_segs: Number of elements in @iov. 1809bfdc5970SChristoph Hellwig * @iovp: (input and output parameter) Pointer to pointer to (usually small 1810ffecee4fSVegard Nossum * on-stack) kernel array. 1811ffecee4fSVegard Nossum * @i: Pointer to iterator that will be initialized on success. 1812ffecee4fSVegard Nossum * 1813ffecee4fSVegard Nossum * If the array pointed to by *@iov is large enough to hold all @nr_segs, 1814ffecee4fSVegard Nossum * then this function places %NULL in *@iov on return. Otherwise, a new 1815ffecee4fSVegard Nossum * array will be allocated and the result placed in *@iov. This means that 1816ffecee4fSVegard Nossum * the caller may call kfree() on *@iov regardless of whether the small 1817ffecee4fSVegard Nossum * on-stack array was used or not (and regardless of whether this function 1818ffecee4fSVegard Nossum * returns an error or not). 1819ffecee4fSVegard Nossum * 182087e5e6daSJens Axboe * Return: Negative error code on error, bytes imported on success 1821ffecee4fSVegard Nossum */ 1822bfdc5970SChristoph Hellwig ssize_t import_iovec(int type, const struct iovec __user *uvec, 1823bc917be8SAl Viro unsigned nr_segs, unsigned fast_segs, 1824bfdc5970SChristoph Hellwig struct iovec **iovp, struct iov_iter *i) 1825bc917be8SAl Viro { 182689cd35c5SChristoph Hellwig return __import_iovec(type, uvec, nr_segs, fast_segs, iovp, i, 182789cd35c5SChristoph Hellwig in_compat_syscall()); 1828bc917be8SAl Viro } 1829bc917be8SAl Viro EXPORT_SYMBOL(import_iovec); 1830bc917be8SAl Viro 1831bc917be8SAl Viro int import_single_range(int rw, void __user *buf, size_t len, 1832bc917be8SAl Viro struct iovec *iov, struct iov_iter *i) 1833bc917be8SAl Viro { 1834bc917be8SAl Viro if (len > MAX_RW_COUNT) 1835bc917be8SAl Viro len = MAX_RW_COUNT; 183696d4f267SLinus Torvalds if (unlikely(!access_ok(buf, len))) 1837bc917be8SAl Viro return -EFAULT; 1838bc917be8SAl Viro 1839bc917be8SAl Viro iov->iov_base = buf; 1840bc917be8SAl Viro iov->iov_len = len; 1841bc917be8SAl Viro iov_iter_init(i, rw, iov, 1, len); 1842bc917be8SAl Viro return 0; 1843bc917be8SAl Viro } 1844e1267585SAl Viro EXPORT_SYMBOL(import_single_range); 184509cf698aSAl Viro 184609cf698aSAl Viro int iov_iter_for_each_range(struct iov_iter *i, size_t bytes, 184709cf698aSAl Viro int (*f)(struct kvec *vec, void *context), 184809cf698aSAl Viro void *context) 184909cf698aSAl Viro { 185009cf698aSAl Viro struct kvec w; 185109cf698aSAl Viro int err = -EINVAL; 185209cf698aSAl Viro if (!bytes) 185309cf698aSAl Viro return 0; 185409cf698aSAl Viro 185509cf698aSAl Viro iterate_all_kinds(i, bytes, v, -EINVAL, ({ 185609cf698aSAl Viro w.iov_base = kmap(v.bv_page) + v.bv_offset; 185709cf698aSAl Viro w.iov_len = v.bv_len; 185809cf698aSAl Viro err = f(&w, context); 185909cf698aSAl Viro kunmap(v.bv_page); 186009cf698aSAl Viro err;}), ({ 186109cf698aSAl Viro w = v; 186209cf698aSAl Viro err = f(&w, context);}) 186309cf698aSAl Viro ) 186409cf698aSAl Viro return err; 186509cf698aSAl Viro } 186609cf698aSAl Viro EXPORT_SYMBOL(iov_iter_for_each_range); 1867