1457c8996SThomas Gleixner // SPDX-License-Identifier: GPL-2.0-only 27999096fSHerbert Xu #include <crypto/hash.h> 3d879cb83SAl Viro #include <linux/export.h> 42f8b5444SChristoph Hellwig #include <linux/bvec.h> 54d0e9df5SAlbert van der Linde #include <linux/fault-inject-usercopy.h> 6d879cb83SAl Viro #include <linux/uio.h> 7d879cb83SAl Viro #include <linux/pagemap.h> 828961998SIra Weiny #include <linux/highmem.h> 9d879cb83SAl Viro #include <linux/slab.h> 10d879cb83SAl Viro #include <linux/vmalloc.h> 11241699cdSAl Viro #include <linux/splice.h> 12bfdc5970SChristoph Hellwig #include <linux/compat.h> 13d879cb83SAl Viro #include <net/checksum.h> 14d05f4435SSagi Grimberg #include <linux/scatterlist.h> 15d0ef4c36SMarco Elver #include <linux/instrumented.h> 16d879cb83SAl Viro 17241699cdSAl Viro #define PIPE_PARANOIA /* for now */ 18241699cdSAl Viro 195c67aa90SAl Viro /* covers iovec and kvec alike */ 20d879cb83SAl Viro #define iterate_iovec(i, n, __v, __p, skip, STEP) { \ 21d879cb83SAl Viro size_t left; \ 22d879cb83SAl Viro size_t wanted = n; \ 237a1bcb5dSAl Viro do { \ 24d879cb83SAl Viro __v.iov_len = min(n, __p->iov_len - skip); \ 25d879cb83SAl Viro if (likely(__v.iov_len)) { \ 26d879cb83SAl Viro __v.iov_base = __p->iov_base + skip; \ 27d879cb83SAl Viro left = (STEP); \ 28d879cb83SAl Viro __v.iov_len -= left; \ 29d879cb83SAl Viro skip += __v.iov_len; \ 30d879cb83SAl Viro n -= __v.iov_len; \ 317a1bcb5dSAl Viro if (skip < __p->iov_len) \ 327a1bcb5dSAl Viro break; \ 33d879cb83SAl Viro } \ 34d879cb83SAl Viro __p++; \ 357a1bcb5dSAl Viro skip = 0; \ 367a1bcb5dSAl Viro } while (n); \ 37d879cb83SAl Viro n = wanted - n; \ 38d879cb83SAl Viro } 39d879cb83SAl Viro 40*7491a2bfSAl Viro #define iterate_bvec(i, n, __v, p, skip, STEP) { \ 41*7491a2bfSAl Viro size_t wanted = n; \ 42*7491a2bfSAl Viro while (n) { \ 43*7491a2bfSAl Viro unsigned offset = p->bv_offset + skip; \ 44*7491a2bfSAl Viro __v.bv_offset = offset % PAGE_SIZE; \ 45*7491a2bfSAl Viro __v.bv_page = p->bv_page + offset / PAGE_SIZE; \ 46*7491a2bfSAl Viro __v.bv_len = min(min(n, p->bv_len - skip), \ 47*7491a2bfSAl Viro (size_t)(PAGE_SIZE - offset % PAGE_SIZE)); \ 48d879cb83SAl Viro (void)(STEP); \ 49*7491a2bfSAl Viro skip += __v.bv_len; \ 50*7491a2bfSAl Viro if (skip == p->bv_len) { \ 51*7491a2bfSAl Viro skip = 0; \ 52*7491a2bfSAl Viro p++; \ 53d879cb83SAl Viro } \ 54*7491a2bfSAl Viro n -= __v.bv_len; \ 55*7491a2bfSAl Viro } \ 56*7491a2bfSAl Viro n = wanted - n; \ 57d879cb83SAl Viro } 58d879cb83SAl Viro 597ff50620SDavid Howells #define iterate_xarray(i, n, __v, skip, STEP) { \ 607ff50620SDavid Howells struct page *head = NULL; \ 617ff50620SDavid Howells size_t wanted = n, seg, offset; \ 627ff50620SDavid Howells loff_t start = i->xarray_start + skip; \ 637ff50620SDavid Howells pgoff_t index = start >> PAGE_SHIFT; \ 647ff50620SDavid Howells int j; \ 657ff50620SDavid Howells \ 667ff50620SDavid Howells XA_STATE(xas, i->xarray, index); \ 677ff50620SDavid Howells \ 687ff50620SDavid Howells rcu_read_lock(); \ 697ff50620SDavid Howells xas_for_each(&xas, head, ULONG_MAX) { \ 707ff50620SDavid Howells if (xas_retry(&xas, head)) \ 717ff50620SDavid Howells continue; \ 727ff50620SDavid Howells if (WARN_ON(xa_is_value(head))) \ 737ff50620SDavid Howells break; \ 747ff50620SDavid Howells if (WARN_ON(PageHuge(head))) \ 757ff50620SDavid Howells break; \ 767ff50620SDavid Howells for (j = (head->index < index) ? index - head->index : 0; \ 777ff50620SDavid Howells j < thp_nr_pages(head); j++) { \ 787ff50620SDavid Howells __v.bv_page = head + j; \ 797ff50620SDavid Howells offset = (i->xarray_start + skip) & ~PAGE_MASK; \ 807ff50620SDavid Howells seg = PAGE_SIZE - offset; \ 817ff50620SDavid Howells __v.bv_offset = offset; \ 827ff50620SDavid Howells __v.bv_len = min(n, seg); \ 837ff50620SDavid Howells (void)(STEP); \ 847ff50620SDavid Howells n -= __v.bv_len; \ 857ff50620SDavid Howells skip += __v.bv_len; \ 867ff50620SDavid Howells if (n == 0) \ 877ff50620SDavid Howells break; \ 887ff50620SDavid Howells } \ 897ff50620SDavid Howells if (n == 0) \ 907ff50620SDavid Howells break; \ 917ff50620SDavid Howells } \ 927ff50620SDavid Howells rcu_read_unlock(); \ 937ff50620SDavid Howells n = wanted - n; \ 947ff50620SDavid Howells } 957ff50620SDavid Howells 967ff50620SDavid Howells #define iterate_and_advance(i, n, v, I, B, K, X) { \ 97dd254f5aSAl Viro if (unlikely(i->count < n)) \ 98dd254f5aSAl Viro n = i->count; \ 99f5da8354SAl Viro if (likely(n)) { \ 100d879cb83SAl Viro size_t skip = i->iov_offset; \ 10128f38db7SAl Viro if (likely(iter_is_iovec(i))) { \ 1025c67aa90SAl Viro const struct iovec *iov = i->iov; \ 103d879cb83SAl Viro struct iovec v; \ 104d879cb83SAl Viro iterate_iovec(i, n, v, iov, skip, (I)) \ 105d879cb83SAl Viro i->nr_segs -= iov - i->iov; \ 106d879cb83SAl Viro i->iov = iov; \ 10728f38db7SAl Viro } else if (iov_iter_is_bvec(i)) { \ 10828f38db7SAl Viro const struct bio_vec *bvec = i->bvec; \ 10928f38db7SAl Viro struct bio_vec v; \ 110*7491a2bfSAl Viro iterate_bvec(i, n, v, bvec, skip, (B)) \ 111*7491a2bfSAl Viro i->nr_segs -= bvec - i->bvec; \ 112*7491a2bfSAl Viro i->bvec = bvec; \ 11328f38db7SAl Viro } else if (iov_iter_is_kvec(i)) { \ 1145c67aa90SAl Viro const struct kvec *kvec = i->kvec; \ 11528f38db7SAl Viro struct kvec v; \ 1165c67aa90SAl Viro iterate_iovec(i, n, v, kvec, skip, \ 1175c67aa90SAl Viro ((void)(K),0)) \ 11828f38db7SAl Viro i->nr_segs -= kvec - i->kvec; \ 11928f38db7SAl Viro i->kvec = kvec; \ 12028f38db7SAl Viro } else if (iov_iter_is_xarray(i)) { \ 12128f38db7SAl Viro struct bio_vec v; \ 12228f38db7SAl Viro iterate_xarray(i, n, v, skip, (X)) \ 123d879cb83SAl Viro } \ 124d879cb83SAl Viro i->count -= n; \ 125d879cb83SAl Viro i->iov_offset = skip; \ 126dd254f5aSAl Viro } \ 127d879cb83SAl Viro } 128d879cb83SAl Viro 12909fc68dcSAl Viro static int copyout(void __user *to, const void *from, size_t n) 13009fc68dcSAl Viro { 1314d0e9df5SAlbert van der Linde if (should_fail_usercopy()) 1324d0e9df5SAlbert van der Linde return n; 13396d4f267SLinus Torvalds if (access_ok(to, n)) { 134d0ef4c36SMarco Elver instrument_copy_to_user(to, from, n); 13509fc68dcSAl Viro n = raw_copy_to_user(to, from, n); 13609fc68dcSAl Viro } 13709fc68dcSAl Viro return n; 13809fc68dcSAl Viro } 13909fc68dcSAl Viro 14009fc68dcSAl Viro static int copyin(void *to, const void __user *from, size_t n) 14109fc68dcSAl Viro { 1424d0e9df5SAlbert van der Linde if (should_fail_usercopy()) 1434d0e9df5SAlbert van der Linde return n; 14496d4f267SLinus Torvalds if (access_ok(from, n)) { 145d0ef4c36SMarco Elver instrument_copy_from_user(to, from, n); 14609fc68dcSAl Viro n = raw_copy_from_user(to, from, n); 14709fc68dcSAl Viro } 14809fc68dcSAl Viro return n; 14909fc68dcSAl Viro } 15009fc68dcSAl Viro 151d879cb83SAl Viro static size_t copy_page_to_iter_iovec(struct page *page, size_t offset, size_t bytes, 152d879cb83SAl Viro struct iov_iter *i) 153d879cb83SAl Viro { 154d879cb83SAl Viro size_t skip, copy, left, wanted; 155d879cb83SAl Viro const struct iovec *iov; 156d879cb83SAl Viro char __user *buf; 157d879cb83SAl Viro void *kaddr, *from; 158d879cb83SAl Viro 159d879cb83SAl Viro if (unlikely(bytes > i->count)) 160d879cb83SAl Viro bytes = i->count; 161d879cb83SAl Viro 162d879cb83SAl Viro if (unlikely(!bytes)) 163d879cb83SAl Viro return 0; 164d879cb83SAl Viro 16509fc68dcSAl Viro might_fault(); 166d879cb83SAl Viro wanted = bytes; 167d879cb83SAl Viro iov = i->iov; 168d879cb83SAl Viro skip = i->iov_offset; 169d879cb83SAl Viro buf = iov->iov_base + skip; 170d879cb83SAl Viro copy = min(bytes, iov->iov_len - skip); 171d879cb83SAl Viro 1723fa6c507SMikulas Patocka if (IS_ENABLED(CONFIG_HIGHMEM) && !fault_in_pages_writeable(buf, copy)) { 173d879cb83SAl Viro kaddr = kmap_atomic(page); 174d879cb83SAl Viro from = kaddr + offset; 175d879cb83SAl Viro 176d879cb83SAl Viro /* first chunk, usually the only one */ 17709fc68dcSAl Viro left = copyout(buf, from, copy); 178d879cb83SAl Viro copy -= left; 179d879cb83SAl Viro skip += copy; 180d879cb83SAl Viro from += copy; 181d879cb83SAl Viro bytes -= copy; 182d879cb83SAl Viro 183d879cb83SAl Viro while (unlikely(!left && bytes)) { 184d879cb83SAl Viro iov++; 185d879cb83SAl Viro buf = iov->iov_base; 186d879cb83SAl Viro copy = min(bytes, iov->iov_len); 18709fc68dcSAl Viro left = copyout(buf, from, copy); 188d879cb83SAl Viro copy -= left; 189d879cb83SAl Viro skip = copy; 190d879cb83SAl Viro from += copy; 191d879cb83SAl Viro bytes -= copy; 192d879cb83SAl Viro } 193d879cb83SAl Viro if (likely(!bytes)) { 194d879cb83SAl Viro kunmap_atomic(kaddr); 195d879cb83SAl Viro goto done; 196d879cb83SAl Viro } 197d879cb83SAl Viro offset = from - kaddr; 198d879cb83SAl Viro buf += copy; 199d879cb83SAl Viro kunmap_atomic(kaddr); 200d879cb83SAl Viro copy = min(bytes, iov->iov_len - skip); 201d879cb83SAl Viro } 202d879cb83SAl Viro /* Too bad - revert to non-atomic kmap */ 2033fa6c507SMikulas Patocka 204d879cb83SAl Viro kaddr = kmap(page); 205d879cb83SAl Viro from = kaddr + offset; 20609fc68dcSAl Viro left = copyout(buf, from, copy); 207d879cb83SAl Viro copy -= left; 208d879cb83SAl Viro skip += copy; 209d879cb83SAl Viro from += copy; 210d879cb83SAl Viro bytes -= copy; 211d879cb83SAl Viro while (unlikely(!left && bytes)) { 212d879cb83SAl Viro iov++; 213d879cb83SAl Viro buf = iov->iov_base; 214d879cb83SAl Viro copy = min(bytes, iov->iov_len); 21509fc68dcSAl Viro left = copyout(buf, from, copy); 216d879cb83SAl Viro copy -= left; 217d879cb83SAl Viro skip = copy; 218d879cb83SAl Viro from += copy; 219d879cb83SAl Viro bytes -= copy; 220d879cb83SAl Viro } 221d879cb83SAl Viro kunmap(page); 2223fa6c507SMikulas Patocka 223d879cb83SAl Viro done: 224d879cb83SAl Viro if (skip == iov->iov_len) { 225d879cb83SAl Viro iov++; 226d879cb83SAl Viro skip = 0; 227d879cb83SAl Viro } 228d879cb83SAl Viro i->count -= wanted - bytes; 229d879cb83SAl Viro i->nr_segs -= iov - i->iov; 230d879cb83SAl Viro i->iov = iov; 231d879cb83SAl Viro i->iov_offset = skip; 232d879cb83SAl Viro return wanted - bytes; 233d879cb83SAl Viro } 234d879cb83SAl Viro 235d879cb83SAl Viro static size_t copy_page_from_iter_iovec(struct page *page, size_t offset, size_t bytes, 236d879cb83SAl Viro struct iov_iter *i) 237d879cb83SAl Viro { 238d879cb83SAl Viro size_t skip, copy, left, wanted; 239d879cb83SAl Viro const struct iovec *iov; 240d879cb83SAl Viro char __user *buf; 241d879cb83SAl Viro void *kaddr, *to; 242d879cb83SAl Viro 243d879cb83SAl Viro if (unlikely(bytes > i->count)) 244d879cb83SAl Viro bytes = i->count; 245d879cb83SAl Viro 246d879cb83SAl Viro if (unlikely(!bytes)) 247d879cb83SAl Viro return 0; 248d879cb83SAl Viro 24909fc68dcSAl Viro might_fault(); 250d879cb83SAl Viro wanted = bytes; 251d879cb83SAl Viro iov = i->iov; 252d879cb83SAl Viro skip = i->iov_offset; 253d879cb83SAl Viro buf = iov->iov_base + skip; 254d879cb83SAl Viro copy = min(bytes, iov->iov_len - skip); 255d879cb83SAl Viro 2563fa6c507SMikulas Patocka if (IS_ENABLED(CONFIG_HIGHMEM) && !fault_in_pages_readable(buf, copy)) { 257d879cb83SAl Viro kaddr = kmap_atomic(page); 258d879cb83SAl Viro to = kaddr + offset; 259d879cb83SAl Viro 260d879cb83SAl Viro /* first chunk, usually the only one */ 26109fc68dcSAl Viro left = copyin(to, buf, copy); 262d879cb83SAl Viro copy -= left; 263d879cb83SAl Viro skip += copy; 264d879cb83SAl Viro to += copy; 265d879cb83SAl Viro bytes -= copy; 266d879cb83SAl Viro 267d879cb83SAl Viro while (unlikely(!left && bytes)) { 268d879cb83SAl Viro iov++; 269d879cb83SAl Viro buf = iov->iov_base; 270d879cb83SAl Viro copy = min(bytes, iov->iov_len); 27109fc68dcSAl Viro left = copyin(to, buf, copy); 272d879cb83SAl Viro copy -= left; 273d879cb83SAl Viro skip = copy; 274d879cb83SAl Viro to += copy; 275d879cb83SAl Viro bytes -= copy; 276d879cb83SAl Viro } 277d879cb83SAl Viro if (likely(!bytes)) { 278d879cb83SAl Viro kunmap_atomic(kaddr); 279d879cb83SAl Viro goto done; 280d879cb83SAl Viro } 281d879cb83SAl Viro offset = to - kaddr; 282d879cb83SAl Viro buf += copy; 283d879cb83SAl Viro kunmap_atomic(kaddr); 284d879cb83SAl Viro copy = min(bytes, iov->iov_len - skip); 285d879cb83SAl Viro } 286d879cb83SAl Viro /* Too bad - revert to non-atomic kmap */ 2873fa6c507SMikulas Patocka 288d879cb83SAl Viro kaddr = kmap(page); 289d879cb83SAl Viro to = kaddr + offset; 29009fc68dcSAl Viro left = copyin(to, buf, copy); 291d879cb83SAl Viro copy -= left; 292d879cb83SAl Viro skip += copy; 293d879cb83SAl Viro to += copy; 294d879cb83SAl Viro bytes -= copy; 295d879cb83SAl Viro while (unlikely(!left && bytes)) { 296d879cb83SAl Viro iov++; 297d879cb83SAl Viro buf = iov->iov_base; 298d879cb83SAl Viro copy = min(bytes, iov->iov_len); 29909fc68dcSAl Viro left = copyin(to, buf, copy); 300d879cb83SAl Viro copy -= left; 301d879cb83SAl Viro skip = copy; 302d879cb83SAl Viro to += copy; 303d879cb83SAl Viro bytes -= copy; 304d879cb83SAl Viro } 305d879cb83SAl Viro kunmap(page); 3063fa6c507SMikulas Patocka 307d879cb83SAl Viro done: 308d879cb83SAl Viro if (skip == iov->iov_len) { 309d879cb83SAl Viro iov++; 310d879cb83SAl Viro skip = 0; 311d879cb83SAl Viro } 312d879cb83SAl Viro i->count -= wanted - bytes; 313d879cb83SAl Viro i->nr_segs -= iov - i->iov; 314d879cb83SAl Viro i->iov = iov; 315d879cb83SAl Viro i->iov_offset = skip; 316d879cb83SAl Viro return wanted - bytes; 317d879cb83SAl Viro } 318d879cb83SAl Viro 319241699cdSAl Viro #ifdef PIPE_PARANOIA 320241699cdSAl Viro static bool sanity(const struct iov_iter *i) 321241699cdSAl Viro { 322241699cdSAl Viro struct pipe_inode_info *pipe = i->pipe; 3238cefc107SDavid Howells unsigned int p_head = pipe->head; 3248cefc107SDavid Howells unsigned int p_tail = pipe->tail; 3258cefc107SDavid Howells unsigned int p_mask = pipe->ring_size - 1; 3268cefc107SDavid Howells unsigned int p_occupancy = pipe_occupancy(p_head, p_tail); 3278cefc107SDavid Howells unsigned int i_head = i->head; 3288cefc107SDavid Howells unsigned int idx; 3298cefc107SDavid Howells 330241699cdSAl Viro if (i->iov_offset) { 331241699cdSAl Viro struct pipe_buffer *p; 3328cefc107SDavid Howells if (unlikely(p_occupancy == 0)) 333241699cdSAl Viro goto Bad; // pipe must be non-empty 3348cefc107SDavid Howells if (unlikely(i_head != p_head - 1)) 335241699cdSAl Viro goto Bad; // must be at the last buffer... 336241699cdSAl Viro 3378cefc107SDavid Howells p = &pipe->bufs[i_head & p_mask]; 338241699cdSAl Viro if (unlikely(p->offset + p->len != i->iov_offset)) 339241699cdSAl Viro goto Bad; // ... at the end of segment 340241699cdSAl Viro } else { 3418cefc107SDavid Howells if (i_head != p_head) 342241699cdSAl Viro goto Bad; // must be right after the last buffer 343241699cdSAl Viro } 344241699cdSAl Viro return true; 345241699cdSAl Viro Bad: 3468cefc107SDavid Howells printk(KERN_ERR "idx = %d, offset = %zd\n", i_head, i->iov_offset); 3478cefc107SDavid Howells printk(KERN_ERR "head = %d, tail = %d, buffers = %d\n", 3488cefc107SDavid Howells p_head, p_tail, pipe->ring_size); 3498cefc107SDavid Howells for (idx = 0; idx < pipe->ring_size; idx++) 350241699cdSAl Viro printk(KERN_ERR "[%p %p %d %d]\n", 351241699cdSAl Viro pipe->bufs[idx].ops, 352241699cdSAl Viro pipe->bufs[idx].page, 353241699cdSAl Viro pipe->bufs[idx].offset, 354241699cdSAl Viro pipe->bufs[idx].len); 355241699cdSAl Viro WARN_ON(1); 356241699cdSAl Viro return false; 357241699cdSAl Viro } 358241699cdSAl Viro #else 359241699cdSAl Viro #define sanity(i) true 360241699cdSAl Viro #endif 361241699cdSAl Viro 362241699cdSAl Viro static size_t copy_page_to_iter_pipe(struct page *page, size_t offset, size_t bytes, 363241699cdSAl Viro struct iov_iter *i) 364241699cdSAl Viro { 365241699cdSAl Viro struct pipe_inode_info *pipe = i->pipe; 366241699cdSAl Viro struct pipe_buffer *buf; 3678cefc107SDavid Howells unsigned int p_tail = pipe->tail; 3688cefc107SDavid Howells unsigned int p_mask = pipe->ring_size - 1; 3698cefc107SDavid Howells unsigned int i_head = i->head; 370241699cdSAl Viro size_t off; 371241699cdSAl Viro 372241699cdSAl Viro if (unlikely(bytes > i->count)) 373241699cdSAl Viro bytes = i->count; 374241699cdSAl Viro 375241699cdSAl Viro if (unlikely(!bytes)) 376241699cdSAl Viro return 0; 377241699cdSAl Viro 378241699cdSAl Viro if (!sanity(i)) 379241699cdSAl Viro return 0; 380241699cdSAl Viro 381241699cdSAl Viro off = i->iov_offset; 3828cefc107SDavid Howells buf = &pipe->bufs[i_head & p_mask]; 383241699cdSAl Viro if (off) { 384241699cdSAl Viro if (offset == off && buf->page == page) { 385241699cdSAl Viro /* merge with the last one */ 386241699cdSAl Viro buf->len += bytes; 387241699cdSAl Viro i->iov_offset += bytes; 388241699cdSAl Viro goto out; 389241699cdSAl Viro } 3908cefc107SDavid Howells i_head++; 3918cefc107SDavid Howells buf = &pipe->bufs[i_head & p_mask]; 392241699cdSAl Viro } 3936718b6f8SDavid Howells if (pipe_full(i_head, p_tail, pipe->max_usage)) 394241699cdSAl Viro return 0; 3958cefc107SDavid Howells 396241699cdSAl Viro buf->ops = &page_cache_pipe_buf_ops; 3978cefc107SDavid Howells get_page(page); 3988cefc107SDavid Howells buf->page = page; 399241699cdSAl Viro buf->offset = offset; 400241699cdSAl Viro buf->len = bytes; 4018cefc107SDavid Howells 4028cefc107SDavid Howells pipe->head = i_head + 1; 403241699cdSAl Viro i->iov_offset = offset + bytes; 4048cefc107SDavid Howells i->head = i_head; 405241699cdSAl Viro out: 406241699cdSAl Viro i->count -= bytes; 407241699cdSAl Viro return bytes; 408241699cdSAl Viro } 409241699cdSAl Viro 410d879cb83SAl Viro /* 411171a0203SAnton Altaparmakov * Fault in one or more iovecs of the given iov_iter, to a maximum length of 412171a0203SAnton Altaparmakov * bytes. For each iovec, fault in each page that constitutes the iovec. 413171a0203SAnton Altaparmakov * 414171a0203SAnton Altaparmakov * Return 0 on success, or non-zero if the memory could not be accessed (i.e. 415171a0203SAnton Altaparmakov * because it is an invalid address). 416171a0203SAnton Altaparmakov */ 4178409a0d2SAl Viro int iov_iter_fault_in_readable(const struct iov_iter *i, size_t bytes) 418171a0203SAnton Altaparmakov { 4190e8f0d67SAl Viro if (iter_is_iovec(i)) { 4208409a0d2SAl Viro const struct iovec *p; 4218409a0d2SAl Viro size_t skip; 4228409a0d2SAl Viro 4238409a0d2SAl Viro if (bytes > i->count) 4248409a0d2SAl Viro bytes = i->count; 4258409a0d2SAl Viro for (p = i->iov, skip = i->iov_offset; bytes; p++, skip = 0) { 4268409a0d2SAl Viro size_t len = min(bytes, p->iov_len - skip); 4278409a0d2SAl Viro int err; 4288409a0d2SAl Viro 4298409a0d2SAl Viro if (unlikely(!len)) 4308409a0d2SAl Viro continue; 4318409a0d2SAl Viro err = fault_in_pages_readable(p->iov_base + skip, len); 432171a0203SAnton Altaparmakov if (unlikely(err)) 433171a0203SAnton Altaparmakov return err; 4348409a0d2SAl Viro bytes -= len; 4358409a0d2SAl Viro } 436171a0203SAnton Altaparmakov } 437171a0203SAnton Altaparmakov return 0; 438171a0203SAnton Altaparmakov } 439d4690f1eSAl Viro EXPORT_SYMBOL(iov_iter_fault_in_readable); 440171a0203SAnton Altaparmakov 441aa563d7bSDavid Howells void iov_iter_init(struct iov_iter *i, unsigned int direction, 442d879cb83SAl Viro const struct iovec *iov, unsigned long nr_segs, 443d879cb83SAl Viro size_t count) 444d879cb83SAl Viro { 445aa563d7bSDavid Howells WARN_ON(direction & ~(READ | WRITE)); 4468cd54c1cSAl Viro WARN_ON_ONCE(uaccess_kernel()); 4478cd54c1cSAl Viro *i = (struct iov_iter) { 4488cd54c1cSAl Viro .iter_type = ITER_IOVEC, 4498cd54c1cSAl Viro .data_source = direction, 4508cd54c1cSAl Viro .iov = iov, 4518cd54c1cSAl Viro .nr_segs = nr_segs, 4528cd54c1cSAl Viro .iov_offset = 0, 4538cd54c1cSAl Viro .count = count 4548cd54c1cSAl Viro }; 455d879cb83SAl Viro } 456d879cb83SAl Viro EXPORT_SYMBOL(iov_iter_init); 457d879cb83SAl Viro 458241699cdSAl Viro static inline bool allocated(struct pipe_buffer *buf) 459241699cdSAl Viro { 460241699cdSAl Viro return buf->ops == &default_pipe_buf_ops; 461241699cdSAl Viro } 462241699cdSAl Viro 4638cefc107SDavid Howells static inline void data_start(const struct iov_iter *i, 4648cefc107SDavid Howells unsigned int *iter_headp, size_t *offp) 465241699cdSAl Viro { 4668cefc107SDavid Howells unsigned int p_mask = i->pipe->ring_size - 1; 4678cefc107SDavid Howells unsigned int iter_head = i->head; 468241699cdSAl Viro size_t off = i->iov_offset; 4698cefc107SDavid Howells 4708cefc107SDavid Howells if (off && (!allocated(&i->pipe->bufs[iter_head & p_mask]) || 4718cefc107SDavid Howells off == PAGE_SIZE)) { 4728cefc107SDavid Howells iter_head++; 473241699cdSAl Viro off = 0; 474241699cdSAl Viro } 4758cefc107SDavid Howells *iter_headp = iter_head; 476241699cdSAl Viro *offp = off; 477241699cdSAl Viro } 478241699cdSAl Viro 479241699cdSAl Viro static size_t push_pipe(struct iov_iter *i, size_t size, 4808cefc107SDavid Howells int *iter_headp, size_t *offp) 481241699cdSAl Viro { 482241699cdSAl Viro struct pipe_inode_info *pipe = i->pipe; 4838cefc107SDavid Howells unsigned int p_tail = pipe->tail; 4848cefc107SDavid Howells unsigned int p_mask = pipe->ring_size - 1; 4858cefc107SDavid Howells unsigned int iter_head; 486241699cdSAl Viro size_t off; 487241699cdSAl Viro ssize_t left; 488241699cdSAl Viro 489241699cdSAl Viro if (unlikely(size > i->count)) 490241699cdSAl Viro size = i->count; 491241699cdSAl Viro if (unlikely(!size)) 492241699cdSAl Viro return 0; 493241699cdSAl Viro 494241699cdSAl Viro left = size; 4958cefc107SDavid Howells data_start(i, &iter_head, &off); 4968cefc107SDavid Howells *iter_headp = iter_head; 497241699cdSAl Viro *offp = off; 498241699cdSAl Viro if (off) { 499241699cdSAl Viro left -= PAGE_SIZE - off; 500241699cdSAl Viro if (left <= 0) { 5018cefc107SDavid Howells pipe->bufs[iter_head & p_mask].len += size; 502241699cdSAl Viro return size; 503241699cdSAl Viro } 5048cefc107SDavid Howells pipe->bufs[iter_head & p_mask].len = PAGE_SIZE; 5058cefc107SDavid Howells iter_head++; 506241699cdSAl Viro } 5076718b6f8SDavid Howells while (!pipe_full(iter_head, p_tail, pipe->max_usage)) { 5088cefc107SDavid Howells struct pipe_buffer *buf = &pipe->bufs[iter_head & p_mask]; 509241699cdSAl Viro struct page *page = alloc_page(GFP_USER); 510241699cdSAl Viro if (!page) 511241699cdSAl Viro break; 5128cefc107SDavid Howells 5138cefc107SDavid Howells buf->ops = &default_pipe_buf_ops; 5148cefc107SDavid Howells buf->page = page; 5158cefc107SDavid Howells buf->offset = 0; 5168cefc107SDavid Howells buf->len = min_t(ssize_t, left, PAGE_SIZE); 5178cefc107SDavid Howells left -= buf->len; 5188cefc107SDavid Howells iter_head++; 5198cefc107SDavid Howells pipe->head = iter_head; 5208cefc107SDavid Howells 5218cefc107SDavid Howells if (left == 0) 522241699cdSAl Viro return size; 523241699cdSAl Viro } 524241699cdSAl Viro return size - left; 525241699cdSAl Viro } 526241699cdSAl Viro 527241699cdSAl Viro static size_t copy_pipe_to_iter(const void *addr, size_t bytes, 528241699cdSAl Viro struct iov_iter *i) 529241699cdSAl Viro { 530241699cdSAl Viro struct pipe_inode_info *pipe = i->pipe; 5318cefc107SDavid Howells unsigned int p_mask = pipe->ring_size - 1; 5328cefc107SDavid Howells unsigned int i_head; 533241699cdSAl Viro size_t n, off; 534241699cdSAl Viro 535241699cdSAl Viro if (!sanity(i)) 536241699cdSAl Viro return 0; 537241699cdSAl Viro 5388cefc107SDavid Howells bytes = n = push_pipe(i, bytes, &i_head, &off); 539241699cdSAl Viro if (unlikely(!n)) 540241699cdSAl Viro return 0; 5418cefc107SDavid Howells do { 542241699cdSAl Viro size_t chunk = min_t(size_t, n, PAGE_SIZE - off); 5438cefc107SDavid Howells memcpy_to_page(pipe->bufs[i_head & p_mask].page, off, addr, chunk); 5448cefc107SDavid Howells i->head = i_head; 545241699cdSAl Viro i->iov_offset = off + chunk; 546241699cdSAl Viro n -= chunk; 547241699cdSAl Viro addr += chunk; 5488cefc107SDavid Howells off = 0; 5498cefc107SDavid Howells i_head++; 5508cefc107SDavid Howells } while (n); 551241699cdSAl Viro i->count -= bytes; 552241699cdSAl Viro return bytes; 553241699cdSAl Viro } 554241699cdSAl Viro 555f9152895SAl Viro static __wsum csum_and_memcpy(void *to, const void *from, size_t len, 556f9152895SAl Viro __wsum sum, size_t off) 557f9152895SAl Viro { 558cc44c17bSAl Viro __wsum next = csum_partial_copy_nocheck(from, to, len); 559f9152895SAl Viro return csum_block_add(sum, next, off); 560f9152895SAl Viro } 561f9152895SAl Viro 56278e1f386SAl Viro static size_t csum_and_copy_to_pipe_iter(const void *addr, size_t bytes, 56352cbd23aSWillem de Bruijn struct csum_state *csstate, 56452cbd23aSWillem de Bruijn struct iov_iter *i) 56578e1f386SAl Viro { 56678e1f386SAl Viro struct pipe_inode_info *pipe = i->pipe; 5678cefc107SDavid Howells unsigned int p_mask = pipe->ring_size - 1; 56852cbd23aSWillem de Bruijn __wsum sum = csstate->csum; 56952cbd23aSWillem de Bruijn size_t off = csstate->off; 5708cefc107SDavid Howells unsigned int i_head; 57178e1f386SAl Viro size_t n, r; 57278e1f386SAl Viro 57378e1f386SAl Viro if (!sanity(i)) 57478e1f386SAl Viro return 0; 57578e1f386SAl Viro 5768cefc107SDavid Howells bytes = n = push_pipe(i, bytes, &i_head, &r); 57778e1f386SAl Viro if (unlikely(!n)) 57878e1f386SAl Viro return 0; 5798cefc107SDavid Howells do { 58078e1f386SAl Viro size_t chunk = min_t(size_t, n, PAGE_SIZE - r); 5818cefc107SDavid Howells char *p = kmap_atomic(pipe->bufs[i_head & p_mask].page); 582f9152895SAl Viro sum = csum_and_memcpy(p + r, addr, chunk, sum, off); 58378e1f386SAl Viro kunmap_atomic(p); 5848cefc107SDavid Howells i->head = i_head; 58578e1f386SAl Viro i->iov_offset = r + chunk; 58678e1f386SAl Viro n -= chunk; 58778e1f386SAl Viro off += chunk; 58878e1f386SAl Viro addr += chunk; 5898cefc107SDavid Howells r = 0; 5908cefc107SDavid Howells i_head++; 5918cefc107SDavid Howells } while (n); 59278e1f386SAl Viro i->count -= bytes; 59352cbd23aSWillem de Bruijn csstate->csum = sum; 59452cbd23aSWillem de Bruijn csstate->off = off; 59578e1f386SAl Viro return bytes; 59678e1f386SAl Viro } 59778e1f386SAl Viro 598aa28de27SAl Viro size_t _copy_to_iter(const void *addr, size_t bytes, struct iov_iter *i) 599d879cb83SAl Viro { 60036f7a8a4SAl Viro const char *from = addr; 60100e23707SDavid Howells if (unlikely(iov_iter_is_pipe(i))) 602241699cdSAl Viro return copy_pipe_to_iter(addr, bytes, i); 60309fc68dcSAl Viro if (iter_is_iovec(i)) 60409fc68dcSAl Viro might_fault(); 605d879cb83SAl Viro iterate_and_advance(i, bytes, v, 60609fc68dcSAl Viro copyout(v.iov_base, (from += v.iov_len) - v.iov_len, v.iov_len), 607d879cb83SAl Viro memcpy_to_page(v.bv_page, v.bv_offset, 608d879cb83SAl Viro (from += v.bv_len) - v.bv_len, v.bv_len), 6097ff50620SDavid Howells memcpy(v.iov_base, (from += v.iov_len) - v.iov_len, v.iov_len), 6107ff50620SDavid Howells memcpy_to_page(v.bv_page, v.bv_offset, 6117ff50620SDavid Howells (from += v.bv_len) - v.bv_len, v.bv_len) 612d879cb83SAl Viro ) 613d879cb83SAl Viro 614d879cb83SAl Viro return bytes; 615d879cb83SAl Viro } 616aa28de27SAl Viro EXPORT_SYMBOL(_copy_to_iter); 617d879cb83SAl Viro 618ec6347bbSDan Williams #ifdef CONFIG_ARCH_HAS_COPY_MC 619ec6347bbSDan Williams static int copyout_mc(void __user *to, const void *from, size_t n) 6208780356eSDan Williams { 62196d4f267SLinus Torvalds if (access_ok(to, n)) { 622d0ef4c36SMarco Elver instrument_copy_to_user(to, from, n); 623ec6347bbSDan Williams n = copy_mc_to_user((__force void *) to, from, n); 6248780356eSDan Williams } 6258780356eSDan Williams return n; 6268780356eSDan Williams } 6278780356eSDan Williams 628ec6347bbSDan Williams static unsigned long copy_mc_to_page(struct page *page, size_t offset, 6298780356eSDan Williams const char *from, size_t len) 6308780356eSDan Williams { 6318780356eSDan Williams unsigned long ret; 6328780356eSDan Williams char *to; 6338780356eSDan Williams 6348780356eSDan Williams to = kmap_atomic(page); 635ec6347bbSDan Williams ret = copy_mc_to_kernel(to + offset, from, len); 6368780356eSDan Williams kunmap_atomic(to); 6378780356eSDan Williams 6388780356eSDan Williams return ret; 6398780356eSDan Williams } 6408780356eSDan Williams 641ec6347bbSDan Williams static size_t copy_mc_pipe_to_iter(const void *addr, size_t bytes, 642ca146f6fSDan Williams struct iov_iter *i) 643ca146f6fSDan Williams { 644ca146f6fSDan Williams struct pipe_inode_info *pipe = i->pipe; 6458cefc107SDavid Howells unsigned int p_mask = pipe->ring_size - 1; 6468cefc107SDavid Howells unsigned int i_head; 647ca146f6fSDan Williams size_t n, off, xfer = 0; 648ca146f6fSDan Williams 649ca146f6fSDan Williams if (!sanity(i)) 650ca146f6fSDan Williams return 0; 651ca146f6fSDan Williams 6528cefc107SDavid Howells bytes = n = push_pipe(i, bytes, &i_head, &off); 653ca146f6fSDan Williams if (unlikely(!n)) 654ca146f6fSDan Williams return 0; 6558cefc107SDavid Howells do { 656ca146f6fSDan Williams size_t chunk = min_t(size_t, n, PAGE_SIZE - off); 657ca146f6fSDan Williams unsigned long rem; 658ca146f6fSDan Williams 659ec6347bbSDan Williams rem = copy_mc_to_page(pipe->bufs[i_head & p_mask].page, 6608cefc107SDavid Howells off, addr, chunk); 6618cefc107SDavid Howells i->head = i_head; 662ca146f6fSDan Williams i->iov_offset = off + chunk - rem; 663ca146f6fSDan Williams xfer += chunk - rem; 664ca146f6fSDan Williams if (rem) 665ca146f6fSDan Williams break; 666ca146f6fSDan Williams n -= chunk; 667ca146f6fSDan Williams addr += chunk; 6688cefc107SDavid Howells off = 0; 6698cefc107SDavid Howells i_head++; 6708cefc107SDavid Howells } while (n); 671ca146f6fSDan Williams i->count -= xfer; 672ca146f6fSDan Williams return xfer; 673ca146f6fSDan Williams } 674ca146f6fSDan Williams 675bf3eeb9bSDan Williams /** 676ec6347bbSDan Williams * _copy_mc_to_iter - copy to iter with source memory error exception handling 677bf3eeb9bSDan Williams * @addr: source kernel address 678bf3eeb9bSDan Williams * @bytes: total transfer length 679bf3eeb9bSDan Williams * @iter: destination iterator 680bf3eeb9bSDan Williams * 681ec6347bbSDan Williams * The pmem driver deploys this for the dax operation 682ec6347bbSDan Williams * (dax_copy_to_iter()) for dax reads (bypass page-cache and the 683ec6347bbSDan Williams * block-layer). Upon #MC read(2) aborts and returns EIO or the bytes 684ec6347bbSDan Williams * successfully copied. 685bf3eeb9bSDan Williams * 686ec6347bbSDan Williams * The main differences between this and typical _copy_to_iter(). 687bf3eeb9bSDan Williams * 688bf3eeb9bSDan Williams * * Typical tail/residue handling after a fault retries the copy 689bf3eeb9bSDan Williams * byte-by-byte until the fault happens again. Re-triggering machine 690bf3eeb9bSDan Williams * checks is potentially fatal so the implementation uses source 691bf3eeb9bSDan Williams * alignment and poison alignment assumptions to avoid re-triggering 692bf3eeb9bSDan Williams * hardware exceptions. 693bf3eeb9bSDan Williams * 694bf3eeb9bSDan Williams * * ITER_KVEC, ITER_PIPE, and ITER_BVEC can return short copies. 695bf3eeb9bSDan Williams * Compare to copy_to_iter() where only ITER_IOVEC attempts might return 696bf3eeb9bSDan Williams * a short copy. 697bf3eeb9bSDan Williams */ 698ec6347bbSDan Williams size_t _copy_mc_to_iter(const void *addr, size_t bytes, struct iov_iter *i) 6998780356eSDan Williams { 7008780356eSDan Williams const char *from = addr; 7018780356eSDan Williams unsigned long rem, curr_addr, s_addr = (unsigned long) addr; 7028780356eSDan Williams 70300e23707SDavid Howells if (unlikely(iov_iter_is_pipe(i))) 704ec6347bbSDan Williams return copy_mc_pipe_to_iter(addr, bytes, i); 7058780356eSDan Williams if (iter_is_iovec(i)) 7068780356eSDan Williams might_fault(); 7078780356eSDan Williams iterate_and_advance(i, bytes, v, 708ec6347bbSDan Williams copyout_mc(v.iov_base, (from += v.iov_len) - v.iov_len, 709ec6347bbSDan Williams v.iov_len), 7108780356eSDan Williams ({ 711ec6347bbSDan Williams rem = copy_mc_to_page(v.bv_page, v.bv_offset, 7128780356eSDan Williams (from += v.bv_len) - v.bv_len, v.bv_len); 7138780356eSDan Williams if (rem) { 7148780356eSDan Williams curr_addr = (unsigned long) from; 7158780356eSDan Williams bytes = curr_addr - s_addr - rem; 7168780356eSDan Williams return bytes; 7178780356eSDan Williams } 7188780356eSDan Williams }), 7198780356eSDan Williams ({ 720ec6347bbSDan Williams rem = copy_mc_to_kernel(v.iov_base, (from += v.iov_len) 721ec6347bbSDan Williams - v.iov_len, v.iov_len); 7228780356eSDan Williams if (rem) { 7238780356eSDan Williams curr_addr = (unsigned long) from; 7248780356eSDan Williams bytes = curr_addr - s_addr - rem; 7258780356eSDan Williams return bytes; 7268780356eSDan Williams } 7277ff50620SDavid Howells }), 7287ff50620SDavid Howells ({ 7297ff50620SDavid Howells rem = copy_mc_to_page(v.bv_page, v.bv_offset, 7307ff50620SDavid Howells (from += v.bv_len) - v.bv_len, v.bv_len); 7317ff50620SDavid Howells if (rem) { 7327ff50620SDavid Howells curr_addr = (unsigned long) from; 7337ff50620SDavid Howells bytes = curr_addr - s_addr - rem; 7347ff50620SDavid Howells rcu_read_unlock(); 7353d14ec1fSDavid Howells i->iov_offset += bytes; 7363d14ec1fSDavid Howells i->count -= bytes; 7377ff50620SDavid Howells return bytes; 7387ff50620SDavid Howells } 7398780356eSDan Williams }) 7408780356eSDan Williams ) 7418780356eSDan Williams 7428780356eSDan Williams return bytes; 7438780356eSDan Williams } 744ec6347bbSDan Williams EXPORT_SYMBOL_GPL(_copy_mc_to_iter); 745ec6347bbSDan Williams #endif /* CONFIG_ARCH_HAS_COPY_MC */ 7468780356eSDan Williams 747aa28de27SAl Viro size_t _copy_from_iter(void *addr, size_t bytes, struct iov_iter *i) 748d879cb83SAl Viro { 749d879cb83SAl Viro char *to = addr; 75000e23707SDavid Howells if (unlikely(iov_iter_is_pipe(i))) { 751241699cdSAl Viro WARN_ON(1); 752241699cdSAl Viro return 0; 753241699cdSAl Viro } 75409fc68dcSAl Viro if (iter_is_iovec(i)) 75509fc68dcSAl Viro might_fault(); 756d879cb83SAl Viro iterate_and_advance(i, bytes, v, 75709fc68dcSAl Viro copyin((to += v.iov_len) - v.iov_len, v.iov_base, v.iov_len), 758d879cb83SAl Viro memcpy_from_page((to += v.bv_len) - v.bv_len, v.bv_page, 759d879cb83SAl Viro v.bv_offset, v.bv_len), 7607ff50620SDavid Howells memcpy((to += v.iov_len) - v.iov_len, v.iov_base, v.iov_len), 7617ff50620SDavid Howells memcpy_from_page((to += v.bv_len) - v.bv_len, v.bv_page, 7627ff50620SDavid Howells v.bv_offset, v.bv_len) 763d879cb83SAl Viro ) 764d879cb83SAl Viro 765d879cb83SAl Viro return bytes; 766d879cb83SAl Viro } 767aa28de27SAl Viro EXPORT_SYMBOL(_copy_from_iter); 768d879cb83SAl Viro 769aa28de27SAl Viro size_t _copy_from_iter_nocache(void *addr, size_t bytes, struct iov_iter *i) 770d879cb83SAl Viro { 771d879cb83SAl Viro char *to = addr; 77200e23707SDavid Howells if (unlikely(iov_iter_is_pipe(i))) { 773241699cdSAl Viro WARN_ON(1); 774241699cdSAl Viro return 0; 775241699cdSAl Viro } 776d879cb83SAl Viro iterate_and_advance(i, bytes, v, 7773f763453SAl Viro __copy_from_user_inatomic_nocache((to += v.iov_len) - v.iov_len, 778d879cb83SAl Viro v.iov_base, v.iov_len), 779d879cb83SAl Viro memcpy_from_page((to += v.bv_len) - v.bv_len, v.bv_page, 780d879cb83SAl Viro v.bv_offset, v.bv_len), 7817ff50620SDavid Howells memcpy((to += v.iov_len) - v.iov_len, v.iov_base, v.iov_len), 7827ff50620SDavid Howells memcpy_from_page((to += v.bv_len) - v.bv_len, v.bv_page, 7837ff50620SDavid Howells v.bv_offset, v.bv_len) 784d879cb83SAl Viro ) 785d879cb83SAl Viro 786d879cb83SAl Viro return bytes; 787d879cb83SAl Viro } 788aa28de27SAl Viro EXPORT_SYMBOL(_copy_from_iter_nocache); 789d879cb83SAl Viro 7900aed55afSDan Williams #ifdef CONFIG_ARCH_HAS_UACCESS_FLUSHCACHE 791abd08d7dSDan Williams /** 792abd08d7dSDan Williams * _copy_from_iter_flushcache - write destination through cpu cache 793abd08d7dSDan Williams * @addr: destination kernel address 794abd08d7dSDan Williams * @bytes: total transfer length 795abd08d7dSDan Williams * @iter: source iterator 796abd08d7dSDan Williams * 797abd08d7dSDan Williams * The pmem driver arranges for filesystem-dax to use this facility via 798abd08d7dSDan Williams * dax_copy_from_iter() for ensuring that writes to persistent memory 799abd08d7dSDan Williams * are flushed through the CPU cache. It is differentiated from 800abd08d7dSDan Williams * _copy_from_iter_nocache() in that guarantees all data is flushed for 801abd08d7dSDan Williams * all iterator types. The _copy_from_iter_nocache() only attempts to 802abd08d7dSDan Williams * bypass the cache for the ITER_IOVEC case, and on some archs may use 803abd08d7dSDan Williams * instructions that strand dirty-data in the cache. 804abd08d7dSDan Williams */ 8056a37e940SLinus Torvalds size_t _copy_from_iter_flushcache(void *addr, size_t bytes, struct iov_iter *i) 8060aed55afSDan Williams { 8070aed55afSDan Williams char *to = addr; 80800e23707SDavid Howells if (unlikely(iov_iter_is_pipe(i))) { 8090aed55afSDan Williams WARN_ON(1); 8100aed55afSDan Williams return 0; 8110aed55afSDan Williams } 8120aed55afSDan Williams iterate_and_advance(i, bytes, v, 8130aed55afSDan Williams __copy_from_user_flushcache((to += v.iov_len) - v.iov_len, 8140aed55afSDan Williams v.iov_base, v.iov_len), 8150aed55afSDan Williams memcpy_page_flushcache((to += v.bv_len) - v.bv_len, v.bv_page, 8160aed55afSDan Williams v.bv_offset, v.bv_len), 8170aed55afSDan Williams memcpy_flushcache((to += v.iov_len) - v.iov_len, v.iov_base, 8187ff50620SDavid Howells v.iov_len), 8197ff50620SDavid Howells memcpy_page_flushcache((to += v.bv_len) - v.bv_len, v.bv_page, 8207ff50620SDavid Howells v.bv_offset, v.bv_len) 8210aed55afSDan Williams ) 8220aed55afSDan Williams 8230aed55afSDan Williams return bytes; 8240aed55afSDan Williams } 8256a37e940SLinus Torvalds EXPORT_SYMBOL_GPL(_copy_from_iter_flushcache); 8260aed55afSDan Williams #endif 8270aed55afSDan Williams 82872e809edSAl Viro static inline bool page_copy_sane(struct page *page, size_t offset, size_t n) 82972e809edSAl Viro { 8306daef95bSEric Dumazet struct page *head; 8316daef95bSEric Dumazet size_t v = n + offset; 8326daef95bSEric Dumazet 8336daef95bSEric Dumazet /* 8346daef95bSEric Dumazet * The general case needs to access the page order in order 8356daef95bSEric Dumazet * to compute the page size. 8366daef95bSEric Dumazet * However, we mostly deal with order-0 pages and thus can 8376daef95bSEric Dumazet * avoid a possible cache line miss for requests that fit all 8386daef95bSEric Dumazet * page orders. 8396daef95bSEric Dumazet */ 8406daef95bSEric Dumazet if (n <= v && v <= PAGE_SIZE) 8416daef95bSEric Dumazet return true; 8426daef95bSEric Dumazet 8436daef95bSEric Dumazet head = compound_head(page); 8446daef95bSEric Dumazet v += (page - head) << PAGE_SHIFT; 845a90bcb86SPetar Penkov 846a50b854eSMatthew Wilcox (Oracle) if (likely(n <= v && v <= (page_size(head)))) 84772e809edSAl Viro return true; 84872e809edSAl Viro WARN_ON(1); 84972e809edSAl Viro return false; 85072e809edSAl Viro } 851cbbd26b8SAl Viro 85208aa6479SAl Viro static size_t __copy_page_to_iter(struct page *page, size_t offset, size_t bytes, 853d879cb83SAl Viro struct iov_iter *i) 854d879cb83SAl Viro { 85528f38db7SAl Viro if (likely(iter_is_iovec(i))) 85628f38db7SAl Viro return copy_page_to_iter_iovec(page, offset, bytes, i); 85728f38db7SAl Viro if (iov_iter_is_bvec(i) || iov_iter_is_kvec(i) || iov_iter_is_xarray(i)) { 858d879cb83SAl Viro void *kaddr = kmap_atomic(page); 859d879cb83SAl Viro size_t wanted = copy_to_iter(kaddr + offset, bytes, i); 860d879cb83SAl Viro kunmap_atomic(kaddr); 861d879cb83SAl Viro return wanted; 86228f38db7SAl Viro } 86328f38db7SAl Viro if (iov_iter_is_pipe(i)) 86428f38db7SAl Viro return copy_page_to_iter_pipe(page, offset, bytes, i); 86528f38db7SAl Viro if (unlikely(iov_iter_is_discard(i))) { 866a506abc7SAl Viro if (unlikely(i->count < bytes)) 867a506abc7SAl Viro bytes = i->count; 868a506abc7SAl Viro i->count -= bytes; 8699ea9ce04SDavid Howells return bytes; 87028f38db7SAl Viro } 87128f38db7SAl Viro WARN_ON(1); 87228f38db7SAl Viro return 0; 873d879cb83SAl Viro } 87408aa6479SAl Viro 87508aa6479SAl Viro size_t copy_page_to_iter(struct page *page, size_t offset, size_t bytes, 87608aa6479SAl Viro struct iov_iter *i) 87708aa6479SAl Viro { 87808aa6479SAl Viro size_t res = 0; 87908aa6479SAl Viro if (unlikely(!page_copy_sane(page, offset, bytes))) 88008aa6479SAl Viro return 0; 88108aa6479SAl Viro page += offset / PAGE_SIZE; // first subpage 88208aa6479SAl Viro offset %= PAGE_SIZE; 88308aa6479SAl Viro while (1) { 88408aa6479SAl Viro size_t n = __copy_page_to_iter(page, offset, 88508aa6479SAl Viro min(bytes, (size_t)PAGE_SIZE - offset), i); 88608aa6479SAl Viro res += n; 88708aa6479SAl Viro bytes -= n; 88808aa6479SAl Viro if (!bytes || !n) 88908aa6479SAl Viro break; 89008aa6479SAl Viro offset += n; 89108aa6479SAl Viro if (offset == PAGE_SIZE) { 89208aa6479SAl Viro page++; 89308aa6479SAl Viro offset = 0; 89408aa6479SAl Viro } 89508aa6479SAl Viro } 89608aa6479SAl Viro return res; 89708aa6479SAl Viro } 898d879cb83SAl Viro EXPORT_SYMBOL(copy_page_to_iter); 899d879cb83SAl Viro 900d879cb83SAl Viro size_t copy_page_from_iter(struct page *page, size_t offset, size_t bytes, 901d879cb83SAl Viro struct iov_iter *i) 902d879cb83SAl Viro { 90372e809edSAl Viro if (unlikely(!page_copy_sane(page, offset, bytes))) 90472e809edSAl Viro return 0; 90528f38db7SAl Viro if (likely(iter_is_iovec(i))) 90628f38db7SAl Viro return copy_page_from_iter_iovec(page, offset, bytes, i); 90728f38db7SAl Viro if (iov_iter_is_bvec(i) || iov_iter_is_kvec(i) || iov_iter_is_xarray(i)) { 908d879cb83SAl Viro void *kaddr = kmap_atomic(page); 909aa28de27SAl Viro size_t wanted = _copy_from_iter(kaddr + offset, bytes, i); 910d879cb83SAl Viro kunmap_atomic(kaddr); 911d879cb83SAl Viro return wanted; 91228f38db7SAl Viro } 91328f38db7SAl Viro WARN_ON(1); 91428f38db7SAl Viro return 0; 915d879cb83SAl Viro } 916d879cb83SAl Viro EXPORT_SYMBOL(copy_page_from_iter); 917d879cb83SAl Viro 918241699cdSAl Viro static size_t pipe_zero(size_t bytes, struct iov_iter *i) 919241699cdSAl Viro { 920241699cdSAl Viro struct pipe_inode_info *pipe = i->pipe; 9218cefc107SDavid Howells unsigned int p_mask = pipe->ring_size - 1; 9228cefc107SDavid Howells unsigned int i_head; 923241699cdSAl Viro size_t n, off; 924241699cdSAl Viro 925241699cdSAl Viro if (!sanity(i)) 926241699cdSAl Viro return 0; 927241699cdSAl Viro 9288cefc107SDavid Howells bytes = n = push_pipe(i, bytes, &i_head, &off); 929241699cdSAl Viro if (unlikely(!n)) 930241699cdSAl Viro return 0; 931241699cdSAl Viro 9328cefc107SDavid Howells do { 933241699cdSAl Viro size_t chunk = min_t(size_t, n, PAGE_SIZE - off); 9348cefc107SDavid Howells memzero_page(pipe->bufs[i_head & p_mask].page, off, chunk); 9358cefc107SDavid Howells i->head = i_head; 936241699cdSAl Viro i->iov_offset = off + chunk; 937241699cdSAl Viro n -= chunk; 9388cefc107SDavid Howells off = 0; 9398cefc107SDavid Howells i_head++; 9408cefc107SDavid Howells } while (n); 941241699cdSAl Viro i->count -= bytes; 942241699cdSAl Viro return bytes; 943241699cdSAl Viro } 944241699cdSAl Viro 945d879cb83SAl Viro size_t iov_iter_zero(size_t bytes, struct iov_iter *i) 946d879cb83SAl Viro { 94700e23707SDavid Howells if (unlikely(iov_iter_is_pipe(i))) 948241699cdSAl Viro return pipe_zero(bytes, i); 949d879cb83SAl Viro iterate_and_advance(i, bytes, v, 95009fc68dcSAl Viro clear_user(v.iov_base, v.iov_len), 951d879cb83SAl Viro memzero_page(v.bv_page, v.bv_offset, v.bv_len), 9527ff50620SDavid Howells memset(v.iov_base, 0, v.iov_len), 9537ff50620SDavid Howells memzero_page(v.bv_page, v.bv_offset, v.bv_len) 954d879cb83SAl Viro ) 955d879cb83SAl Viro 956d879cb83SAl Viro return bytes; 957d879cb83SAl Viro } 958d879cb83SAl Viro EXPORT_SYMBOL(iov_iter_zero); 959d879cb83SAl Viro 960f0b65f39SAl Viro size_t copy_page_from_iter_atomic(struct page *page, unsigned offset, size_t bytes, 961f0b65f39SAl Viro struct iov_iter *i) 962d879cb83SAl Viro { 963d879cb83SAl Viro char *kaddr = kmap_atomic(page), *p = kaddr + offset; 96472e809edSAl Viro if (unlikely(!page_copy_sane(page, offset, bytes))) { 96572e809edSAl Viro kunmap_atomic(kaddr); 96672e809edSAl Viro return 0; 96772e809edSAl Viro } 9689ea9ce04SDavid Howells if (unlikely(iov_iter_is_pipe(i) || iov_iter_is_discard(i))) { 969241699cdSAl Viro kunmap_atomic(kaddr); 970241699cdSAl Viro WARN_ON(1); 971241699cdSAl Viro return 0; 972241699cdSAl Viro } 973f0b65f39SAl Viro iterate_and_advance(i, bytes, v, 97409fc68dcSAl Viro copyin((p += v.iov_len) - v.iov_len, v.iov_base, v.iov_len), 975d879cb83SAl Viro memcpy_from_page((p += v.bv_len) - v.bv_len, v.bv_page, 976d879cb83SAl Viro v.bv_offset, v.bv_len), 9777ff50620SDavid Howells memcpy((p += v.iov_len) - v.iov_len, v.iov_base, v.iov_len), 9787ff50620SDavid Howells memcpy_from_page((p += v.bv_len) - v.bv_len, v.bv_page, 9797ff50620SDavid Howells v.bv_offset, v.bv_len) 980d879cb83SAl Viro ) 981d879cb83SAl Viro kunmap_atomic(kaddr); 982d879cb83SAl Viro return bytes; 983d879cb83SAl Viro } 984f0b65f39SAl Viro EXPORT_SYMBOL(copy_page_from_iter_atomic); 985d879cb83SAl Viro 986b9dc6f65SAl Viro static inline void pipe_truncate(struct iov_iter *i) 987241699cdSAl Viro { 988241699cdSAl Viro struct pipe_inode_info *pipe = i->pipe; 9898cefc107SDavid Howells unsigned int p_tail = pipe->tail; 9908cefc107SDavid Howells unsigned int p_head = pipe->head; 9918cefc107SDavid Howells unsigned int p_mask = pipe->ring_size - 1; 9928cefc107SDavid Howells 9938cefc107SDavid Howells if (!pipe_empty(p_head, p_tail)) { 9948cefc107SDavid Howells struct pipe_buffer *buf; 9958cefc107SDavid Howells unsigned int i_head = i->head; 996b9dc6f65SAl Viro size_t off = i->iov_offset; 9978cefc107SDavid Howells 998b9dc6f65SAl Viro if (off) { 9998cefc107SDavid Howells buf = &pipe->bufs[i_head & p_mask]; 10008cefc107SDavid Howells buf->len = off - buf->offset; 10018cefc107SDavid Howells i_head++; 1002b9dc6f65SAl Viro } 10038cefc107SDavid Howells while (p_head != i_head) { 10048cefc107SDavid Howells p_head--; 10058cefc107SDavid Howells pipe_buf_release(pipe, &pipe->bufs[p_head & p_mask]); 1006241699cdSAl Viro } 10078cefc107SDavid Howells 10088cefc107SDavid Howells pipe->head = p_head; 1009241699cdSAl Viro } 1010b9dc6f65SAl Viro } 1011b9dc6f65SAl Viro 1012b9dc6f65SAl Viro static void pipe_advance(struct iov_iter *i, size_t size) 1013b9dc6f65SAl Viro { 1014b9dc6f65SAl Viro struct pipe_inode_info *pipe = i->pipe; 1015b9dc6f65SAl Viro if (size) { 1016b9dc6f65SAl Viro struct pipe_buffer *buf; 10178cefc107SDavid Howells unsigned int p_mask = pipe->ring_size - 1; 10188cefc107SDavid Howells unsigned int i_head = i->head; 1019b9dc6f65SAl Viro size_t off = i->iov_offset, left = size; 10208cefc107SDavid Howells 1021b9dc6f65SAl Viro if (off) /* make it relative to the beginning of buffer */ 10228cefc107SDavid Howells left += off - pipe->bufs[i_head & p_mask].offset; 1023b9dc6f65SAl Viro while (1) { 10248cefc107SDavid Howells buf = &pipe->bufs[i_head & p_mask]; 1025b9dc6f65SAl Viro if (left <= buf->len) 1026b9dc6f65SAl Viro break; 1027b9dc6f65SAl Viro left -= buf->len; 10288cefc107SDavid Howells i_head++; 1029b9dc6f65SAl Viro } 10308cefc107SDavid Howells i->head = i_head; 1031b9dc6f65SAl Viro i->iov_offset = buf->offset + left; 1032b9dc6f65SAl Viro } 1033b9dc6f65SAl Viro i->count -= size; 1034b9dc6f65SAl Viro /* ... and discard everything past that point */ 1035b9dc6f65SAl Viro pipe_truncate(i); 1036241699cdSAl Viro } 1037241699cdSAl Viro 103854c8195bSPavel Begunkov static void iov_iter_bvec_advance(struct iov_iter *i, size_t size) 103954c8195bSPavel Begunkov { 104054c8195bSPavel Begunkov struct bvec_iter bi; 104154c8195bSPavel Begunkov 104254c8195bSPavel Begunkov bi.bi_size = i->count; 104354c8195bSPavel Begunkov bi.bi_bvec_done = i->iov_offset; 104454c8195bSPavel Begunkov bi.bi_idx = 0; 104554c8195bSPavel Begunkov bvec_iter_advance(i->bvec, &bi, size); 104654c8195bSPavel Begunkov 104754c8195bSPavel Begunkov i->bvec += bi.bi_idx; 104854c8195bSPavel Begunkov i->nr_segs -= bi.bi_idx; 104954c8195bSPavel Begunkov i->count = bi.bi_size; 105054c8195bSPavel Begunkov i->iov_offset = bi.bi_bvec_done; 105154c8195bSPavel Begunkov } 105254c8195bSPavel Begunkov 1053185ac4d4SAl Viro static void iov_iter_iovec_advance(struct iov_iter *i, size_t size) 1054185ac4d4SAl Viro { 1055185ac4d4SAl Viro const struct iovec *iov, *end; 1056185ac4d4SAl Viro 1057185ac4d4SAl Viro if (!i->count) 1058185ac4d4SAl Viro return; 1059185ac4d4SAl Viro i->count -= size; 1060185ac4d4SAl Viro 1061185ac4d4SAl Viro size += i->iov_offset; // from beginning of current segment 1062185ac4d4SAl Viro for (iov = i->iov, end = iov + i->nr_segs; iov < end; iov++) { 1063185ac4d4SAl Viro if (likely(size < iov->iov_len)) 1064185ac4d4SAl Viro break; 1065185ac4d4SAl Viro size -= iov->iov_len; 1066185ac4d4SAl Viro } 1067185ac4d4SAl Viro i->iov_offset = size; 1068185ac4d4SAl Viro i->nr_segs -= iov - i->iov; 1069185ac4d4SAl Viro i->iov = iov; 1070185ac4d4SAl Viro } 1071185ac4d4SAl Viro 1072d879cb83SAl Viro void iov_iter_advance(struct iov_iter *i, size_t size) 1073d879cb83SAl Viro { 10743b3fc051SAl Viro if (unlikely(i->count < size)) 10753b3fc051SAl Viro size = i->count; 1076185ac4d4SAl Viro if (likely(iter_is_iovec(i) || iov_iter_is_kvec(i))) { 1077185ac4d4SAl Viro /* iovec and kvec have identical layouts */ 1078185ac4d4SAl Viro iov_iter_iovec_advance(i, size); 1079185ac4d4SAl Viro } else if (iov_iter_is_bvec(i)) { 1080185ac4d4SAl Viro iov_iter_bvec_advance(i, size); 1081185ac4d4SAl Viro } else if (iov_iter_is_pipe(i)) { 1082241699cdSAl Viro pipe_advance(i, size); 1083185ac4d4SAl Viro } else if (unlikely(iov_iter_is_xarray(i))) { 10847ff50620SDavid Howells i->iov_offset += size; 10857ff50620SDavid Howells i->count -= size; 1086185ac4d4SAl Viro } else if (iov_iter_is_discard(i)) { 1087185ac4d4SAl Viro i->count -= size; 10887ff50620SDavid Howells } 1089d879cb83SAl Viro } 1090d879cb83SAl Viro EXPORT_SYMBOL(iov_iter_advance); 1091d879cb83SAl Viro 109227c0e374SAl Viro void iov_iter_revert(struct iov_iter *i, size_t unroll) 109327c0e374SAl Viro { 109427c0e374SAl Viro if (!unroll) 109527c0e374SAl Viro return; 10965b47d59aSAl Viro if (WARN_ON(unroll > MAX_RW_COUNT)) 10975b47d59aSAl Viro return; 109827c0e374SAl Viro i->count += unroll; 109900e23707SDavid Howells if (unlikely(iov_iter_is_pipe(i))) { 110027c0e374SAl Viro struct pipe_inode_info *pipe = i->pipe; 11018cefc107SDavid Howells unsigned int p_mask = pipe->ring_size - 1; 11028cefc107SDavid Howells unsigned int i_head = i->head; 110327c0e374SAl Viro size_t off = i->iov_offset; 110427c0e374SAl Viro while (1) { 11058cefc107SDavid Howells struct pipe_buffer *b = &pipe->bufs[i_head & p_mask]; 11068cefc107SDavid Howells size_t n = off - b->offset; 110727c0e374SAl Viro if (unroll < n) { 11084fa55cefSAl Viro off -= unroll; 110927c0e374SAl Viro break; 111027c0e374SAl Viro } 111127c0e374SAl Viro unroll -= n; 11128cefc107SDavid Howells if (!unroll && i_head == i->start_head) { 111327c0e374SAl Viro off = 0; 111427c0e374SAl Viro break; 111527c0e374SAl Viro } 11168cefc107SDavid Howells i_head--; 11178cefc107SDavid Howells b = &pipe->bufs[i_head & p_mask]; 11188cefc107SDavid Howells off = b->offset + b->len; 111927c0e374SAl Viro } 112027c0e374SAl Viro i->iov_offset = off; 11218cefc107SDavid Howells i->head = i_head; 112227c0e374SAl Viro pipe_truncate(i); 112327c0e374SAl Viro return; 112427c0e374SAl Viro } 11259ea9ce04SDavid Howells if (unlikely(iov_iter_is_discard(i))) 11269ea9ce04SDavid Howells return; 112727c0e374SAl Viro if (unroll <= i->iov_offset) { 112827c0e374SAl Viro i->iov_offset -= unroll; 112927c0e374SAl Viro return; 113027c0e374SAl Viro } 113127c0e374SAl Viro unroll -= i->iov_offset; 11327ff50620SDavid Howells if (iov_iter_is_xarray(i)) { 11337ff50620SDavid Howells BUG(); /* We should never go beyond the start of the specified 11347ff50620SDavid Howells * range since we might then be straying into pages that 11357ff50620SDavid Howells * aren't pinned. 11367ff50620SDavid Howells */ 11377ff50620SDavid Howells } else if (iov_iter_is_bvec(i)) { 113827c0e374SAl Viro const struct bio_vec *bvec = i->bvec; 113927c0e374SAl Viro while (1) { 114027c0e374SAl Viro size_t n = (--bvec)->bv_len; 114127c0e374SAl Viro i->nr_segs++; 114227c0e374SAl Viro if (unroll <= n) { 114327c0e374SAl Viro i->bvec = bvec; 114427c0e374SAl Viro i->iov_offset = n - unroll; 114527c0e374SAl Viro return; 114627c0e374SAl Viro } 114727c0e374SAl Viro unroll -= n; 114827c0e374SAl Viro } 114927c0e374SAl Viro } else { /* same logics for iovec and kvec */ 115027c0e374SAl Viro const struct iovec *iov = i->iov; 115127c0e374SAl Viro while (1) { 115227c0e374SAl Viro size_t n = (--iov)->iov_len; 115327c0e374SAl Viro i->nr_segs++; 115427c0e374SAl Viro if (unroll <= n) { 115527c0e374SAl Viro i->iov = iov; 115627c0e374SAl Viro i->iov_offset = n - unroll; 115727c0e374SAl Viro return; 115827c0e374SAl Viro } 115927c0e374SAl Viro unroll -= n; 116027c0e374SAl Viro } 116127c0e374SAl Viro } 116227c0e374SAl Viro } 116327c0e374SAl Viro EXPORT_SYMBOL(iov_iter_revert); 116427c0e374SAl Viro 1165d879cb83SAl Viro /* 1166d879cb83SAl Viro * Return the count of just the current iov_iter segment. 1167d879cb83SAl Viro */ 1168d879cb83SAl Viro size_t iov_iter_single_seg_count(const struct iov_iter *i) 1169d879cb83SAl Viro { 117028f38db7SAl Viro if (i->nr_segs > 1) { 117128f38db7SAl Viro if (likely(iter_is_iovec(i) || iov_iter_is_kvec(i))) 117228f38db7SAl Viro return min(i->count, i->iov->iov_len - i->iov_offset); 11737ff50620SDavid Howells if (iov_iter_is_bvec(i)) 1174d879cb83SAl Viro return min(i->count, i->bvec->bv_len - i->iov_offset); 117528f38db7SAl Viro } 117628f38db7SAl Viro return i->count; 1177d879cb83SAl Viro } 1178d879cb83SAl Viro EXPORT_SYMBOL(iov_iter_single_seg_count); 1179d879cb83SAl Viro 1180aa563d7bSDavid Howells void iov_iter_kvec(struct iov_iter *i, unsigned int direction, 1181d879cb83SAl Viro const struct kvec *kvec, unsigned long nr_segs, 1182d879cb83SAl Viro size_t count) 1183d879cb83SAl Viro { 1184aa563d7bSDavid Howells WARN_ON(direction & ~(READ | WRITE)); 11858cd54c1cSAl Viro *i = (struct iov_iter){ 11868cd54c1cSAl Viro .iter_type = ITER_KVEC, 11878cd54c1cSAl Viro .data_source = direction, 11888cd54c1cSAl Viro .kvec = kvec, 11898cd54c1cSAl Viro .nr_segs = nr_segs, 11908cd54c1cSAl Viro .iov_offset = 0, 11918cd54c1cSAl Viro .count = count 11928cd54c1cSAl Viro }; 1193d879cb83SAl Viro } 1194d879cb83SAl Viro EXPORT_SYMBOL(iov_iter_kvec); 1195d879cb83SAl Viro 1196aa563d7bSDavid Howells void iov_iter_bvec(struct iov_iter *i, unsigned int direction, 1197d879cb83SAl Viro const struct bio_vec *bvec, unsigned long nr_segs, 1198d879cb83SAl Viro size_t count) 1199d879cb83SAl Viro { 1200aa563d7bSDavid Howells WARN_ON(direction & ~(READ | WRITE)); 12018cd54c1cSAl Viro *i = (struct iov_iter){ 12028cd54c1cSAl Viro .iter_type = ITER_BVEC, 12038cd54c1cSAl Viro .data_source = direction, 12048cd54c1cSAl Viro .bvec = bvec, 12058cd54c1cSAl Viro .nr_segs = nr_segs, 12068cd54c1cSAl Viro .iov_offset = 0, 12078cd54c1cSAl Viro .count = count 12088cd54c1cSAl Viro }; 1209d879cb83SAl Viro } 1210d879cb83SAl Viro EXPORT_SYMBOL(iov_iter_bvec); 1211d879cb83SAl Viro 1212aa563d7bSDavid Howells void iov_iter_pipe(struct iov_iter *i, unsigned int direction, 1213241699cdSAl Viro struct pipe_inode_info *pipe, 1214241699cdSAl Viro size_t count) 1215241699cdSAl Viro { 1216aa563d7bSDavid Howells BUG_ON(direction != READ); 12178cefc107SDavid Howells WARN_ON(pipe_full(pipe->head, pipe->tail, pipe->ring_size)); 12188cd54c1cSAl Viro *i = (struct iov_iter){ 12198cd54c1cSAl Viro .iter_type = ITER_PIPE, 12208cd54c1cSAl Viro .data_source = false, 12218cd54c1cSAl Viro .pipe = pipe, 12228cd54c1cSAl Viro .head = pipe->head, 12238cd54c1cSAl Viro .start_head = pipe->head, 12248cd54c1cSAl Viro .iov_offset = 0, 12258cd54c1cSAl Viro .count = count 12268cd54c1cSAl Viro }; 1227241699cdSAl Viro } 1228241699cdSAl Viro EXPORT_SYMBOL(iov_iter_pipe); 1229241699cdSAl Viro 12309ea9ce04SDavid Howells /** 12317ff50620SDavid Howells * iov_iter_xarray - Initialise an I/O iterator to use the pages in an xarray 12327ff50620SDavid Howells * @i: The iterator to initialise. 12337ff50620SDavid Howells * @direction: The direction of the transfer. 12347ff50620SDavid Howells * @xarray: The xarray to access. 12357ff50620SDavid Howells * @start: The start file position. 12367ff50620SDavid Howells * @count: The size of the I/O buffer in bytes. 12377ff50620SDavid Howells * 12387ff50620SDavid Howells * Set up an I/O iterator to either draw data out of the pages attached to an 12397ff50620SDavid Howells * inode or to inject data into those pages. The pages *must* be prevented 12407ff50620SDavid Howells * from evaporation, either by taking a ref on them or locking them by the 12417ff50620SDavid Howells * caller. 12427ff50620SDavid Howells */ 12437ff50620SDavid Howells void iov_iter_xarray(struct iov_iter *i, unsigned int direction, 12447ff50620SDavid Howells struct xarray *xarray, loff_t start, size_t count) 12457ff50620SDavid Howells { 12467ff50620SDavid Howells BUG_ON(direction & ~1); 12478cd54c1cSAl Viro *i = (struct iov_iter) { 12488cd54c1cSAl Viro .iter_type = ITER_XARRAY, 12498cd54c1cSAl Viro .data_source = direction, 12508cd54c1cSAl Viro .xarray = xarray, 12518cd54c1cSAl Viro .xarray_start = start, 12528cd54c1cSAl Viro .count = count, 12538cd54c1cSAl Viro .iov_offset = 0 12548cd54c1cSAl Viro }; 12557ff50620SDavid Howells } 12567ff50620SDavid Howells EXPORT_SYMBOL(iov_iter_xarray); 12577ff50620SDavid Howells 12587ff50620SDavid Howells /** 12599ea9ce04SDavid Howells * iov_iter_discard - Initialise an I/O iterator that discards data 12609ea9ce04SDavid Howells * @i: The iterator to initialise. 12619ea9ce04SDavid Howells * @direction: The direction of the transfer. 12629ea9ce04SDavid Howells * @count: The size of the I/O buffer in bytes. 12639ea9ce04SDavid Howells * 12649ea9ce04SDavid Howells * Set up an I/O iterator that just discards everything that's written to it. 12659ea9ce04SDavid Howells * It's only available as a READ iterator. 12669ea9ce04SDavid Howells */ 12679ea9ce04SDavid Howells void iov_iter_discard(struct iov_iter *i, unsigned int direction, size_t count) 12689ea9ce04SDavid Howells { 12699ea9ce04SDavid Howells BUG_ON(direction != READ); 12708cd54c1cSAl Viro *i = (struct iov_iter){ 12718cd54c1cSAl Viro .iter_type = ITER_DISCARD, 12728cd54c1cSAl Viro .data_source = false, 12738cd54c1cSAl Viro .count = count, 12748cd54c1cSAl Viro .iov_offset = 0 12758cd54c1cSAl Viro }; 12769ea9ce04SDavid Howells } 12779ea9ce04SDavid Howells EXPORT_SYMBOL(iov_iter_discard); 12789ea9ce04SDavid Howells 12799221d2e3SAl Viro static unsigned long iov_iter_alignment_iovec(const struct iov_iter *i) 1280d879cb83SAl Viro { 1281d879cb83SAl Viro unsigned long res = 0; 1282d879cb83SAl Viro size_t size = i->count; 12839221d2e3SAl Viro size_t skip = i->iov_offset; 12849221d2e3SAl Viro unsigned k; 1285d879cb83SAl Viro 12869221d2e3SAl Viro for (k = 0; k < i->nr_segs; k++, skip = 0) { 12879221d2e3SAl Viro size_t len = i->iov[k].iov_len - skip; 12889221d2e3SAl Viro if (len) { 12899221d2e3SAl Viro res |= (unsigned long)i->iov[k].iov_base + skip; 12909221d2e3SAl Viro if (len > size) 12919221d2e3SAl Viro len = size; 12929221d2e3SAl Viro res |= len; 12939221d2e3SAl Viro size -= len; 12949221d2e3SAl Viro if (!size) 12959221d2e3SAl Viro break; 12969221d2e3SAl Viro } 12979221d2e3SAl Viro } 12989221d2e3SAl Viro return res; 12999221d2e3SAl Viro } 13009221d2e3SAl Viro 13019221d2e3SAl Viro static unsigned long iov_iter_alignment_bvec(const struct iov_iter *i) 13029221d2e3SAl Viro { 13039221d2e3SAl Viro unsigned res = 0; 13049221d2e3SAl Viro size_t size = i->count; 13059221d2e3SAl Viro unsigned skip = i->iov_offset; 13069221d2e3SAl Viro unsigned k; 13079221d2e3SAl Viro 13089221d2e3SAl Viro for (k = 0; k < i->nr_segs; k++, skip = 0) { 13099221d2e3SAl Viro size_t len = i->bvec[k].bv_len - skip; 13109221d2e3SAl Viro res |= (unsigned long)i->bvec[k].bv_offset + skip; 13119221d2e3SAl Viro if (len > size) 13129221d2e3SAl Viro len = size; 13139221d2e3SAl Viro res |= len; 13149221d2e3SAl Viro size -= len; 13159221d2e3SAl Viro if (!size) 13169221d2e3SAl Viro break; 13179221d2e3SAl Viro } 13189221d2e3SAl Viro return res; 13199221d2e3SAl Viro } 13209221d2e3SAl Viro 13219221d2e3SAl Viro unsigned long iov_iter_alignment(const struct iov_iter *i) 13229221d2e3SAl Viro { 13239221d2e3SAl Viro /* iovec and kvec have identical layouts */ 13249221d2e3SAl Viro if (likely(iter_is_iovec(i) || iov_iter_is_kvec(i))) 13259221d2e3SAl Viro return iov_iter_alignment_iovec(i); 13269221d2e3SAl Viro 13279221d2e3SAl Viro if (iov_iter_is_bvec(i)) 13289221d2e3SAl Viro return iov_iter_alignment_bvec(i); 13299221d2e3SAl Viro 13309221d2e3SAl Viro if (iov_iter_is_pipe(i)) { 1331e0ff126eSJan Kara unsigned int p_mask = i->pipe->ring_size - 1; 13329221d2e3SAl Viro size_t size = i->count; 1333e0ff126eSJan Kara 13348cefc107SDavid Howells if (size && i->iov_offset && allocated(&i->pipe->bufs[i->head & p_mask])) 1335241699cdSAl Viro return size | i->iov_offset; 1336241699cdSAl Viro return size; 1337241699cdSAl Viro } 13389221d2e3SAl Viro 13399221d2e3SAl Viro if (iov_iter_is_xarray(i)) 13403d14ec1fSDavid Howells return (i->xarray_start + i->iov_offset) | i->count; 13419221d2e3SAl Viro 13429221d2e3SAl Viro return 0; 1343d879cb83SAl Viro } 1344d879cb83SAl Viro EXPORT_SYMBOL(iov_iter_alignment); 1345d879cb83SAl Viro 1346357f435dSAl Viro unsigned long iov_iter_gap_alignment(const struct iov_iter *i) 1347357f435dSAl Viro { 1348357f435dSAl Viro unsigned long res = 0; 1349610c7a71SAl Viro unsigned long v = 0; 1350357f435dSAl Viro size_t size = i->count; 1351610c7a71SAl Viro unsigned k; 1352357f435dSAl Viro 1353610c7a71SAl Viro if (WARN_ON(!iter_is_iovec(i))) 1354241699cdSAl Viro return ~0U; 1355241699cdSAl Viro 1356610c7a71SAl Viro for (k = 0; k < i->nr_segs; k++) { 1357610c7a71SAl Viro if (i->iov[k].iov_len) { 1358610c7a71SAl Viro unsigned long base = (unsigned long)i->iov[k].iov_base; 1359610c7a71SAl Viro if (v) // if not the first one 1360610c7a71SAl Viro res |= base | v; // this start | previous end 1361610c7a71SAl Viro v = base + i->iov[k].iov_len; 1362610c7a71SAl Viro if (size <= i->iov[k].iov_len) 1363610c7a71SAl Viro break; 1364610c7a71SAl Viro size -= i->iov[k].iov_len; 1365610c7a71SAl Viro } 1366610c7a71SAl Viro } 1367357f435dSAl Viro return res; 1368357f435dSAl Viro } 1369357f435dSAl Viro EXPORT_SYMBOL(iov_iter_gap_alignment); 1370357f435dSAl Viro 1371e76b6312SIlya Dryomov static inline ssize_t __pipe_get_pages(struct iov_iter *i, 1372241699cdSAl Viro size_t maxsize, 1373241699cdSAl Viro struct page **pages, 13748cefc107SDavid Howells int iter_head, 1375241699cdSAl Viro size_t *start) 1376241699cdSAl Viro { 1377241699cdSAl Viro struct pipe_inode_info *pipe = i->pipe; 13788cefc107SDavid Howells unsigned int p_mask = pipe->ring_size - 1; 13798cefc107SDavid Howells ssize_t n = push_pipe(i, maxsize, &iter_head, start); 1380241699cdSAl Viro if (!n) 1381241699cdSAl Viro return -EFAULT; 1382241699cdSAl Viro 1383241699cdSAl Viro maxsize = n; 1384241699cdSAl Viro n += *start; 13851689c73aSAl Viro while (n > 0) { 13868cefc107SDavid Howells get_page(*pages++ = pipe->bufs[iter_head & p_mask].page); 13878cefc107SDavid Howells iter_head++; 1388241699cdSAl Viro n -= PAGE_SIZE; 1389241699cdSAl Viro } 1390241699cdSAl Viro 1391241699cdSAl Viro return maxsize; 1392241699cdSAl Viro } 1393241699cdSAl Viro 1394241699cdSAl Viro static ssize_t pipe_get_pages(struct iov_iter *i, 1395241699cdSAl Viro struct page **pages, size_t maxsize, unsigned maxpages, 1396241699cdSAl Viro size_t *start) 1397241699cdSAl Viro { 13988cefc107SDavid Howells unsigned int iter_head, npages; 1399241699cdSAl Viro size_t capacity; 1400241699cdSAl Viro 1401241699cdSAl Viro if (!sanity(i)) 1402241699cdSAl Viro return -EFAULT; 1403241699cdSAl Viro 14048cefc107SDavid Howells data_start(i, &iter_head, start); 14058cefc107SDavid Howells /* Amount of free space: some of this one + all after this one */ 14068cefc107SDavid Howells npages = pipe_space_for_user(iter_head, i->pipe->tail, i->pipe); 1407241699cdSAl Viro capacity = min(npages, maxpages) * PAGE_SIZE - *start; 1408241699cdSAl Viro 14098cefc107SDavid Howells return __pipe_get_pages(i, min(maxsize, capacity), pages, iter_head, start); 1410241699cdSAl Viro } 1411241699cdSAl Viro 14127ff50620SDavid Howells static ssize_t iter_xarray_populate_pages(struct page **pages, struct xarray *xa, 14137ff50620SDavid Howells pgoff_t index, unsigned int nr_pages) 14147ff50620SDavid Howells { 14157ff50620SDavid Howells XA_STATE(xas, xa, index); 14167ff50620SDavid Howells struct page *page; 14177ff50620SDavid Howells unsigned int ret = 0; 14187ff50620SDavid Howells 14197ff50620SDavid Howells rcu_read_lock(); 14207ff50620SDavid Howells for (page = xas_load(&xas); page; page = xas_next(&xas)) { 14217ff50620SDavid Howells if (xas_retry(&xas, page)) 14227ff50620SDavid Howells continue; 14237ff50620SDavid Howells 14247ff50620SDavid Howells /* Has the page moved or been split? */ 14257ff50620SDavid Howells if (unlikely(page != xas_reload(&xas))) { 14267ff50620SDavid Howells xas_reset(&xas); 14277ff50620SDavid Howells continue; 14287ff50620SDavid Howells } 14297ff50620SDavid Howells 14307ff50620SDavid Howells pages[ret] = find_subpage(page, xas.xa_index); 14317ff50620SDavid Howells get_page(pages[ret]); 14327ff50620SDavid Howells if (++ret == nr_pages) 14337ff50620SDavid Howells break; 14347ff50620SDavid Howells } 14357ff50620SDavid Howells rcu_read_unlock(); 14367ff50620SDavid Howells return ret; 14377ff50620SDavid Howells } 14387ff50620SDavid Howells 14397ff50620SDavid Howells static ssize_t iter_xarray_get_pages(struct iov_iter *i, 14407ff50620SDavid Howells struct page **pages, size_t maxsize, 14417ff50620SDavid Howells unsigned maxpages, size_t *_start_offset) 14427ff50620SDavid Howells { 14437ff50620SDavid Howells unsigned nr, offset; 14447ff50620SDavid Howells pgoff_t index, count; 14457ff50620SDavid Howells size_t size = maxsize, actual; 14467ff50620SDavid Howells loff_t pos; 14477ff50620SDavid Howells 14487ff50620SDavid Howells if (!size || !maxpages) 14497ff50620SDavid Howells return 0; 14507ff50620SDavid Howells 14517ff50620SDavid Howells pos = i->xarray_start + i->iov_offset; 14527ff50620SDavid Howells index = pos >> PAGE_SHIFT; 14537ff50620SDavid Howells offset = pos & ~PAGE_MASK; 14547ff50620SDavid Howells *_start_offset = offset; 14557ff50620SDavid Howells 14567ff50620SDavid Howells count = 1; 14577ff50620SDavid Howells if (size > PAGE_SIZE - offset) { 14587ff50620SDavid Howells size -= PAGE_SIZE - offset; 14597ff50620SDavid Howells count += size >> PAGE_SHIFT; 14607ff50620SDavid Howells size &= ~PAGE_MASK; 14617ff50620SDavid Howells if (size) 14627ff50620SDavid Howells count++; 14637ff50620SDavid Howells } 14647ff50620SDavid Howells 14657ff50620SDavid Howells if (count > maxpages) 14667ff50620SDavid Howells count = maxpages; 14677ff50620SDavid Howells 14687ff50620SDavid Howells nr = iter_xarray_populate_pages(pages, i->xarray, index, count); 14697ff50620SDavid Howells if (nr == 0) 14707ff50620SDavid Howells return 0; 14717ff50620SDavid Howells 14727ff50620SDavid Howells actual = PAGE_SIZE * nr; 14737ff50620SDavid Howells actual -= offset; 14747ff50620SDavid Howells if (nr == count && size > 0) { 14757ff50620SDavid Howells unsigned last_offset = (nr > 1) ? 0 : offset; 14767ff50620SDavid Howells actual -= PAGE_SIZE - (last_offset + size); 14777ff50620SDavid Howells } 14787ff50620SDavid Howells return actual; 14797ff50620SDavid Howells } 14807ff50620SDavid Howells 14813d671ca6SAl Viro /* must be done on non-empty ITER_IOVEC one */ 14823d671ca6SAl Viro static unsigned long first_iovec_segment(const struct iov_iter *i, 14833d671ca6SAl Viro size_t *size, size_t *start, 14843d671ca6SAl Viro size_t maxsize, unsigned maxpages) 14853d671ca6SAl Viro { 14863d671ca6SAl Viro size_t skip; 14873d671ca6SAl Viro long k; 14883d671ca6SAl Viro 14893d671ca6SAl Viro for (k = 0, skip = i->iov_offset; k < i->nr_segs; k++, skip = 0) { 14903d671ca6SAl Viro unsigned long addr = (unsigned long)i->iov[k].iov_base + skip; 14913d671ca6SAl Viro size_t len = i->iov[k].iov_len - skip; 14923d671ca6SAl Viro 14933d671ca6SAl Viro if (unlikely(!len)) 14943d671ca6SAl Viro continue; 14953d671ca6SAl Viro if (len > maxsize) 14963d671ca6SAl Viro len = maxsize; 14973d671ca6SAl Viro len += (*start = addr % PAGE_SIZE); 14983d671ca6SAl Viro if (len > maxpages * PAGE_SIZE) 14993d671ca6SAl Viro len = maxpages * PAGE_SIZE; 15003d671ca6SAl Viro *size = len; 15013d671ca6SAl Viro return addr & PAGE_MASK; 15023d671ca6SAl Viro } 15033d671ca6SAl Viro BUG(); // if it had been empty, we wouldn't get called 15043d671ca6SAl Viro } 15053d671ca6SAl Viro 15063d671ca6SAl Viro /* must be done on non-empty ITER_BVEC one */ 15073d671ca6SAl Viro static struct page *first_bvec_segment(const struct iov_iter *i, 15083d671ca6SAl Viro size_t *size, size_t *start, 15093d671ca6SAl Viro size_t maxsize, unsigned maxpages) 15103d671ca6SAl Viro { 15113d671ca6SAl Viro struct page *page; 15123d671ca6SAl Viro size_t skip = i->iov_offset, len; 15133d671ca6SAl Viro 15143d671ca6SAl Viro len = i->bvec->bv_len - skip; 15153d671ca6SAl Viro if (len > maxsize) 15163d671ca6SAl Viro len = maxsize; 15173d671ca6SAl Viro skip += i->bvec->bv_offset; 15183d671ca6SAl Viro page = i->bvec->bv_page + skip / PAGE_SIZE; 15193d671ca6SAl Viro len += (*start = skip % PAGE_SIZE); 15203d671ca6SAl Viro if (len > maxpages * PAGE_SIZE) 15213d671ca6SAl Viro len = maxpages * PAGE_SIZE; 15223d671ca6SAl Viro *size = len; 15233d671ca6SAl Viro return page; 15243d671ca6SAl Viro } 15253d671ca6SAl Viro 1526d879cb83SAl Viro ssize_t iov_iter_get_pages(struct iov_iter *i, 1527d879cb83SAl Viro struct page **pages, size_t maxsize, unsigned maxpages, 1528d879cb83SAl Viro size_t *start) 1529d879cb83SAl Viro { 15303d671ca6SAl Viro size_t len; 15313d671ca6SAl Viro int n, res; 15323d671ca6SAl Viro 1533d879cb83SAl Viro if (maxsize > i->count) 1534d879cb83SAl Viro maxsize = i->count; 15353d671ca6SAl Viro if (!maxsize) 15363d671ca6SAl Viro return 0; 1537d879cb83SAl Viro 15383d671ca6SAl Viro if (likely(iter_is_iovec(i))) { 15393d671ca6SAl Viro unsigned long addr; 15409ea9ce04SDavid Howells 15413d671ca6SAl Viro addr = first_iovec_segment(i, &len, start, maxsize, maxpages); 1542d879cb83SAl Viro n = DIV_ROUND_UP(len, PAGE_SIZE); 154373b0140bSIra Weiny res = get_user_pages_fast(addr, n, 154473b0140bSIra Weiny iov_iter_rw(i) != WRITE ? FOLL_WRITE : 0, 154573b0140bSIra Weiny pages); 1546d879cb83SAl Viro if (unlikely(res < 0)) 1547d879cb83SAl Viro return res; 1548d879cb83SAl Viro return (res == n ? len : res * PAGE_SIZE) - *start; 15493d671ca6SAl Viro } 15503d671ca6SAl Viro if (iov_iter_is_bvec(i)) { 15513d671ca6SAl Viro struct page *page; 15523d671ca6SAl Viro 15533d671ca6SAl Viro page = first_bvec_segment(i, &len, start, maxsize, maxpages); 15543d671ca6SAl Viro n = DIV_ROUND_UP(len, PAGE_SIZE); 15553d671ca6SAl Viro while (n--) 15563d671ca6SAl Viro get_page(*pages++ = page++); 15573d671ca6SAl Viro return len - *start; 15583d671ca6SAl Viro } 15593d671ca6SAl Viro if (iov_iter_is_pipe(i)) 15603d671ca6SAl Viro return pipe_get_pages(i, pages, maxsize, maxpages, start); 15613d671ca6SAl Viro if (iov_iter_is_xarray(i)) 15623d671ca6SAl Viro return iter_xarray_get_pages(i, pages, maxsize, maxpages, start); 1563d879cb83SAl Viro return -EFAULT; 1564d879cb83SAl Viro } 1565d879cb83SAl Viro EXPORT_SYMBOL(iov_iter_get_pages); 1566d879cb83SAl Viro 1567d879cb83SAl Viro static struct page **get_pages_array(size_t n) 1568d879cb83SAl Viro { 1569752ade68SMichal Hocko return kvmalloc_array(n, sizeof(struct page *), GFP_KERNEL); 1570d879cb83SAl Viro } 1571d879cb83SAl Viro 1572241699cdSAl Viro static ssize_t pipe_get_pages_alloc(struct iov_iter *i, 1573241699cdSAl Viro struct page ***pages, size_t maxsize, 1574241699cdSAl Viro size_t *start) 1575241699cdSAl Viro { 1576241699cdSAl Viro struct page **p; 15778cefc107SDavid Howells unsigned int iter_head, npages; 1578d7760d63SIlya Dryomov ssize_t n; 1579241699cdSAl Viro 1580241699cdSAl Viro if (!sanity(i)) 1581241699cdSAl Viro return -EFAULT; 1582241699cdSAl Viro 15838cefc107SDavid Howells data_start(i, &iter_head, start); 15848cefc107SDavid Howells /* Amount of free space: some of this one + all after this one */ 15858cefc107SDavid Howells npages = pipe_space_for_user(iter_head, i->pipe->tail, i->pipe); 1586241699cdSAl Viro n = npages * PAGE_SIZE - *start; 1587241699cdSAl Viro if (maxsize > n) 1588241699cdSAl Viro maxsize = n; 1589241699cdSAl Viro else 1590241699cdSAl Viro npages = DIV_ROUND_UP(maxsize + *start, PAGE_SIZE); 1591241699cdSAl Viro p = get_pages_array(npages); 1592241699cdSAl Viro if (!p) 1593241699cdSAl Viro return -ENOMEM; 15948cefc107SDavid Howells n = __pipe_get_pages(i, maxsize, p, iter_head, start); 1595241699cdSAl Viro if (n > 0) 1596241699cdSAl Viro *pages = p; 1597241699cdSAl Viro else 1598241699cdSAl Viro kvfree(p); 1599241699cdSAl Viro return n; 1600241699cdSAl Viro } 1601241699cdSAl Viro 16027ff50620SDavid Howells static ssize_t iter_xarray_get_pages_alloc(struct iov_iter *i, 16037ff50620SDavid Howells struct page ***pages, size_t maxsize, 16047ff50620SDavid Howells size_t *_start_offset) 16057ff50620SDavid Howells { 16067ff50620SDavid Howells struct page **p; 16077ff50620SDavid Howells unsigned nr, offset; 16087ff50620SDavid Howells pgoff_t index, count; 16097ff50620SDavid Howells size_t size = maxsize, actual; 16107ff50620SDavid Howells loff_t pos; 16117ff50620SDavid Howells 16127ff50620SDavid Howells if (!size) 16137ff50620SDavid Howells return 0; 16147ff50620SDavid Howells 16157ff50620SDavid Howells pos = i->xarray_start + i->iov_offset; 16167ff50620SDavid Howells index = pos >> PAGE_SHIFT; 16177ff50620SDavid Howells offset = pos & ~PAGE_MASK; 16187ff50620SDavid Howells *_start_offset = offset; 16197ff50620SDavid Howells 16207ff50620SDavid Howells count = 1; 16217ff50620SDavid Howells if (size > PAGE_SIZE - offset) { 16227ff50620SDavid Howells size -= PAGE_SIZE - offset; 16237ff50620SDavid Howells count += size >> PAGE_SHIFT; 16247ff50620SDavid Howells size &= ~PAGE_MASK; 16257ff50620SDavid Howells if (size) 16267ff50620SDavid Howells count++; 16277ff50620SDavid Howells } 16287ff50620SDavid Howells 16297ff50620SDavid Howells p = get_pages_array(count); 16307ff50620SDavid Howells if (!p) 16317ff50620SDavid Howells return -ENOMEM; 16327ff50620SDavid Howells *pages = p; 16337ff50620SDavid Howells 16347ff50620SDavid Howells nr = iter_xarray_populate_pages(p, i->xarray, index, count); 16357ff50620SDavid Howells if (nr == 0) 16367ff50620SDavid Howells return 0; 16377ff50620SDavid Howells 16387ff50620SDavid Howells actual = PAGE_SIZE * nr; 16397ff50620SDavid Howells actual -= offset; 16407ff50620SDavid Howells if (nr == count && size > 0) { 16417ff50620SDavid Howells unsigned last_offset = (nr > 1) ? 0 : offset; 16427ff50620SDavid Howells actual -= PAGE_SIZE - (last_offset + size); 16437ff50620SDavid Howells } 16447ff50620SDavid Howells return actual; 16457ff50620SDavid Howells } 16467ff50620SDavid Howells 1647d879cb83SAl Viro ssize_t iov_iter_get_pages_alloc(struct iov_iter *i, 1648d879cb83SAl Viro struct page ***pages, size_t maxsize, 1649d879cb83SAl Viro size_t *start) 1650d879cb83SAl Viro { 1651d879cb83SAl Viro struct page **p; 16523d671ca6SAl Viro size_t len; 16533d671ca6SAl Viro int n, res; 1654d879cb83SAl Viro 1655d879cb83SAl Viro if (maxsize > i->count) 1656d879cb83SAl Viro maxsize = i->count; 16573d671ca6SAl Viro if (!maxsize) 16583d671ca6SAl Viro return 0; 1659d879cb83SAl Viro 16603d671ca6SAl Viro if (likely(iter_is_iovec(i))) { 16613d671ca6SAl Viro unsigned long addr; 16629ea9ce04SDavid Howells 16633d671ca6SAl Viro addr = first_iovec_segment(i, &len, start, maxsize, ~0U); 1664d879cb83SAl Viro n = DIV_ROUND_UP(len, PAGE_SIZE); 1665d879cb83SAl Viro p = get_pages_array(n); 1666d879cb83SAl Viro if (!p) 1667d879cb83SAl Viro return -ENOMEM; 166873b0140bSIra Weiny res = get_user_pages_fast(addr, n, 166973b0140bSIra Weiny iov_iter_rw(i) != WRITE ? FOLL_WRITE : 0, p); 1670d879cb83SAl Viro if (unlikely(res < 0)) { 1671d879cb83SAl Viro kvfree(p); 1672d879cb83SAl Viro return res; 1673d879cb83SAl Viro } 1674d879cb83SAl Viro *pages = p; 1675d879cb83SAl Viro return (res == n ? len : res * PAGE_SIZE) - *start; 16763d671ca6SAl Viro } 16773d671ca6SAl Viro if (iov_iter_is_bvec(i)) { 16783d671ca6SAl Viro struct page *page; 16793d671ca6SAl Viro 16803d671ca6SAl Viro page = first_bvec_segment(i, &len, start, maxsize, ~0U); 16813d671ca6SAl Viro n = DIV_ROUND_UP(len, PAGE_SIZE); 16823d671ca6SAl Viro *pages = p = get_pages_array(n); 1683d879cb83SAl Viro if (!p) 1684d879cb83SAl Viro return -ENOMEM; 16853d671ca6SAl Viro while (n--) 16863d671ca6SAl Viro get_page(*p++ = page++); 16873d671ca6SAl Viro return len - *start; 16883d671ca6SAl Viro } 16893d671ca6SAl Viro if (iov_iter_is_pipe(i)) 16903d671ca6SAl Viro return pipe_get_pages_alloc(i, pages, maxsize, start); 16913d671ca6SAl Viro if (iov_iter_is_xarray(i)) 16923d671ca6SAl Viro return iter_xarray_get_pages_alloc(i, pages, maxsize, start); 1693d879cb83SAl Viro return -EFAULT; 1694d879cb83SAl Viro } 1695d879cb83SAl Viro EXPORT_SYMBOL(iov_iter_get_pages_alloc); 1696d879cb83SAl Viro 1697d879cb83SAl Viro size_t csum_and_copy_from_iter(void *addr, size_t bytes, __wsum *csum, 1698d879cb83SAl Viro struct iov_iter *i) 1699d879cb83SAl Viro { 1700d879cb83SAl Viro char *to = addr; 1701d879cb83SAl Viro __wsum sum, next; 1702d879cb83SAl Viro size_t off = 0; 1703d879cb83SAl Viro sum = *csum; 17049ea9ce04SDavid Howells if (unlikely(iov_iter_is_pipe(i) || iov_iter_is_discard(i))) { 1705241699cdSAl Viro WARN_ON(1); 1706241699cdSAl Viro return 0; 1707241699cdSAl Viro } 1708d879cb83SAl Viro iterate_and_advance(i, bytes, v, ({ 1709d879cb83SAl Viro next = csum_and_copy_from_user(v.iov_base, 1710d879cb83SAl Viro (to += v.iov_len) - v.iov_len, 1711c693cc46SAl Viro v.iov_len); 1712c693cc46SAl Viro if (next) { 1713d879cb83SAl Viro sum = csum_block_add(sum, next, off); 1714d879cb83SAl Viro off += v.iov_len; 1715d879cb83SAl Viro } 1716c693cc46SAl Viro next ? 0 : v.iov_len; 1717d879cb83SAl Viro }), ({ 1718d879cb83SAl Viro char *p = kmap_atomic(v.bv_page); 1719f9152895SAl Viro sum = csum_and_memcpy((to += v.bv_len) - v.bv_len, 1720f9152895SAl Viro p + v.bv_offset, v.bv_len, 1721f9152895SAl Viro sum, off); 1722d879cb83SAl Viro kunmap_atomic(p); 1723d879cb83SAl Viro off += v.bv_len; 1724d879cb83SAl Viro }),({ 1725f9152895SAl Viro sum = csum_and_memcpy((to += v.iov_len) - v.iov_len, 1726f9152895SAl Viro v.iov_base, v.iov_len, 1727f9152895SAl Viro sum, off); 1728d879cb83SAl Viro off += v.iov_len; 17297ff50620SDavid Howells }), ({ 17307ff50620SDavid Howells char *p = kmap_atomic(v.bv_page); 17317ff50620SDavid Howells sum = csum_and_memcpy((to += v.bv_len) - v.bv_len, 17327ff50620SDavid Howells p + v.bv_offset, v.bv_len, 17337ff50620SDavid Howells sum, off); 17347ff50620SDavid Howells kunmap_atomic(p); 17357ff50620SDavid Howells off += v.bv_len; 1736d879cb83SAl Viro }) 1737d879cb83SAl Viro ) 1738d879cb83SAl Viro *csum = sum; 1739d879cb83SAl Viro return bytes; 1740d879cb83SAl Viro } 1741d879cb83SAl Viro EXPORT_SYMBOL(csum_and_copy_from_iter); 1742d879cb83SAl Viro 174352cbd23aSWillem de Bruijn size_t csum_and_copy_to_iter(const void *addr, size_t bytes, void *_csstate, 1744d879cb83SAl Viro struct iov_iter *i) 1745d879cb83SAl Viro { 174652cbd23aSWillem de Bruijn struct csum_state *csstate = _csstate; 174736f7a8a4SAl Viro const char *from = addr; 1748d879cb83SAl Viro __wsum sum, next; 174952cbd23aSWillem de Bruijn size_t off; 175078e1f386SAl Viro 175178e1f386SAl Viro if (unlikely(iov_iter_is_pipe(i))) 175252cbd23aSWillem de Bruijn return csum_and_copy_to_pipe_iter(addr, bytes, _csstate, i); 175378e1f386SAl Viro 1754594e450bSAl Viro sum = csum_shift(csstate->csum, csstate->off); 1755594e450bSAl Viro off = 0; 175678e1f386SAl Viro if (unlikely(iov_iter_is_discard(i))) { 1757241699cdSAl Viro WARN_ON(1); /* for now */ 1758241699cdSAl Viro return 0; 1759241699cdSAl Viro } 1760d879cb83SAl Viro iterate_and_advance(i, bytes, v, ({ 1761d879cb83SAl Viro next = csum_and_copy_to_user((from += v.iov_len) - v.iov_len, 1762d879cb83SAl Viro v.iov_base, 1763c693cc46SAl Viro v.iov_len); 1764c693cc46SAl Viro if (next) { 1765d879cb83SAl Viro sum = csum_block_add(sum, next, off); 1766d879cb83SAl Viro off += v.iov_len; 1767d879cb83SAl Viro } 1768c693cc46SAl Viro next ? 0 : v.iov_len; 1769d879cb83SAl Viro }), ({ 1770d879cb83SAl Viro char *p = kmap_atomic(v.bv_page); 1771f9152895SAl Viro sum = csum_and_memcpy(p + v.bv_offset, 1772f9152895SAl Viro (from += v.bv_len) - v.bv_len, 1773f9152895SAl Viro v.bv_len, sum, off); 1774d879cb83SAl Viro kunmap_atomic(p); 1775d879cb83SAl Viro off += v.bv_len; 1776d879cb83SAl Viro }),({ 1777f9152895SAl Viro sum = csum_and_memcpy(v.iov_base, 1778f9152895SAl Viro (from += v.iov_len) - v.iov_len, 1779f9152895SAl Viro v.iov_len, sum, off); 1780d879cb83SAl Viro off += v.iov_len; 17817ff50620SDavid Howells }), ({ 17827ff50620SDavid Howells char *p = kmap_atomic(v.bv_page); 17837ff50620SDavid Howells sum = csum_and_memcpy(p + v.bv_offset, 17847ff50620SDavid Howells (from += v.bv_len) - v.bv_len, 17857ff50620SDavid Howells v.bv_len, sum, off); 17867ff50620SDavid Howells kunmap_atomic(p); 17877ff50620SDavid Howells off += v.bv_len; 1788d879cb83SAl Viro }) 1789d879cb83SAl Viro ) 1790594e450bSAl Viro csstate->csum = csum_shift(sum, csstate->off); 1791594e450bSAl Viro csstate->off += bytes; 1792d879cb83SAl Viro return bytes; 1793d879cb83SAl Viro } 1794d879cb83SAl Viro EXPORT_SYMBOL(csum_and_copy_to_iter); 1795d879cb83SAl Viro 1796d05f4435SSagi Grimberg size_t hash_and_copy_to_iter(const void *addr, size_t bytes, void *hashp, 1797d05f4435SSagi Grimberg struct iov_iter *i) 1798d05f4435SSagi Grimberg { 17997999096fSHerbert Xu #ifdef CONFIG_CRYPTO_HASH 1800d05f4435SSagi Grimberg struct ahash_request *hash = hashp; 1801d05f4435SSagi Grimberg struct scatterlist sg; 1802d05f4435SSagi Grimberg size_t copied; 1803d05f4435SSagi Grimberg 1804d05f4435SSagi Grimberg copied = copy_to_iter(addr, bytes, i); 1805d05f4435SSagi Grimberg sg_init_one(&sg, addr, copied); 1806d05f4435SSagi Grimberg ahash_request_set_crypt(hash, &sg, NULL, copied); 1807d05f4435SSagi Grimberg crypto_ahash_update(hash); 1808d05f4435SSagi Grimberg return copied; 180927fad74aSYueHaibing #else 181027fad74aSYueHaibing return 0; 181127fad74aSYueHaibing #endif 1812d05f4435SSagi Grimberg } 1813d05f4435SSagi Grimberg EXPORT_SYMBOL(hash_and_copy_to_iter); 1814d05f4435SSagi Grimberg 181566531c65SAl Viro static int iov_npages(const struct iov_iter *i, int maxpages) 1816d879cb83SAl Viro { 181766531c65SAl Viro size_t skip = i->iov_offset, size = i->count; 181866531c65SAl Viro const struct iovec *p; 1819d879cb83SAl Viro int npages = 0; 1820d879cb83SAl Viro 182166531c65SAl Viro for (p = i->iov; size; skip = 0, p++) { 182266531c65SAl Viro unsigned offs = offset_in_page(p->iov_base + skip); 182366531c65SAl Viro size_t len = min(p->iov_len - skip, size); 1824d879cb83SAl Viro 182566531c65SAl Viro if (len) { 182666531c65SAl Viro size -= len; 182766531c65SAl Viro npages += DIV_ROUND_UP(offs + len, PAGE_SIZE); 182866531c65SAl Viro if (unlikely(npages > maxpages)) 182966531c65SAl Viro return maxpages; 183066531c65SAl Viro } 183166531c65SAl Viro } 183266531c65SAl Viro return npages; 183366531c65SAl Viro } 183466531c65SAl Viro 183566531c65SAl Viro static int bvec_npages(const struct iov_iter *i, int maxpages) 183666531c65SAl Viro { 183766531c65SAl Viro size_t skip = i->iov_offset, size = i->count; 183866531c65SAl Viro const struct bio_vec *p; 183966531c65SAl Viro int npages = 0; 184066531c65SAl Viro 184166531c65SAl Viro for (p = i->bvec; size; skip = 0, p++) { 184266531c65SAl Viro unsigned offs = (p->bv_offset + skip) % PAGE_SIZE; 184366531c65SAl Viro size_t len = min(p->bv_len - skip, size); 184466531c65SAl Viro 184566531c65SAl Viro size -= len; 184666531c65SAl Viro npages += DIV_ROUND_UP(offs + len, PAGE_SIZE); 184766531c65SAl Viro if (unlikely(npages > maxpages)) 184866531c65SAl Viro return maxpages; 184966531c65SAl Viro } 185066531c65SAl Viro return npages; 185166531c65SAl Viro } 185266531c65SAl Viro 185366531c65SAl Viro int iov_iter_npages(const struct iov_iter *i, int maxpages) 185466531c65SAl Viro { 185566531c65SAl Viro if (unlikely(!i->count)) 185666531c65SAl Viro return 0; 185766531c65SAl Viro /* iovec and kvec have identical layouts */ 185866531c65SAl Viro if (likely(iter_is_iovec(i) || iov_iter_is_kvec(i))) 185966531c65SAl Viro return iov_npages(i, maxpages); 186066531c65SAl Viro if (iov_iter_is_bvec(i)) 186166531c65SAl Viro return bvec_npages(i, maxpages); 186266531c65SAl Viro if (iov_iter_is_pipe(i)) { 18638cefc107SDavid Howells unsigned int iter_head; 186466531c65SAl Viro int npages; 1865241699cdSAl Viro size_t off; 1866241699cdSAl Viro 1867241699cdSAl Viro if (!sanity(i)) 1868241699cdSAl Viro return 0; 1869241699cdSAl Viro 18708cefc107SDavid Howells data_start(i, &iter_head, &off); 1871241699cdSAl Viro /* some of this one + all after this one */ 187266531c65SAl Viro npages = pipe_space_for_user(iter_head, i->pipe->tail, i->pipe); 187366531c65SAl Viro return min(npages, maxpages); 187466531c65SAl Viro } 187566531c65SAl Viro if (iov_iter_is_xarray(i)) { 1876e4f8df86SAl Viro unsigned offset = (i->xarray_start + i->iov_offset) % PAGE_SIZE; 1877e4f8df86SAl Viro int npages = DIV_ROUND_UP(offset + i->count, PAGE_SIZE); 187866531c65SAl Viro return min(npages, maxpages); 187966531c65SAl Viro } 188066531c65SAl Viro return 0; 1881d879cb83SAl Viro } 1882d879cb83SAl Viro EXPORT_SYMBOL(iov_iter_npages); 1883d879cb83SAl Viro 1884d879cb83SAl Viro const void *dup_iter(struct iov_iter *new, struct iov_iter *old, gfp_t flags) 1885d879cb83SAl Viro { 1886d879cb83SAl Viro *new = *old; 188700e23707SDavid Howells if (unlikely(iov_iter_is_pipe(new))) { 1888241699cdSAl Viro WARN_ON(1); 1889241699cdSAl Viro return NULL; 1890241699cdSAl Viro } 18917ff50620SDavid Howells if (unlikely(iov_iter_is_discard(new) || iov_iter_is_xarray(new))) 18929ea9ce04SDavid Howells return NULL; 189300e23707SDavid Howells if (iov_iter_is_bvec(new)) 1894d879cb83SAl Viro return new->bvec = kmemdup(new->bvec, 1895d879cb83SAl Viro new->nr_segs * sizeof(struct bio_vec), 1896d879cb83SAl Viro flags); 1897d879cb83SAl Viro else 1898d879cb83SAl Viro /* iovec and kvec have identical layout */ 1899d879cb83SAl Viro return new->iov = kmemdup(new->iov, 1900d879cb83SAl Viro new->nr_segs * sizeof(struct iovec), 1901d879cb83SAl Viro flags); 1902d879cb83SAl Viro } 1903d879cb83SAl Viro EXPORT_SYMBOL(dup_iter); 1904bc917be8SAl Viro 1905bfdc5970SChristoph Hellwig static int copy_compat_iovec_from_user(struct iovec *iov, 1906bfdc5970SChristoph Hellwig const struct iovec __user *uvec, unsigned long nr_segs) 1907bfdc5970SChristoph Hellwig { 1908bfdc5970SChristoph Hellwig const struct compat_iovec __user *uiov = 1909bfdc5970SChristoph Hellwig (const struct compat_iovec __user *)uvec; 1910bfdc5970SChristoph Hellwig int ret = -EFAULT, i; 1911bfdc5970SChristoph Hellwig 1912a959a978SChristoph Hellwig if (!user_access_begin(uiov, nr_segs * sizeof(*uiov))) 1913bfdc5970SChristoph Hellwig return -EFAULT; 1914bfdc5970SChristoph Hellwig 1915bfdc5970SChristoph Hellwig for (i = 0; i < nr_segs; i++) { 1916bfdc5970SChristoph Hellwig compat_uptr_t buf; 1917bfdc5970SChristoph Hellwig compat_ssize_t len; 1918bfdc5970SChristoph Hellwig 1919bfdc5970SChristoph Hellwig unsafe_get_user(len, &uiov[i].iov_len, uaccess_end); 1920bfdc5970SChristoph Hellwig unsafe_get_user(buf, &uiov[i].iov_base, uaccess_end); 1921bfdc5970SChristoph Hellwig 1922bfdc5970SChristoph Hellwig /* check for compat_size_t not fitting in compat_ssize_t .. */ 1923bfdc5970SChristoph Hellwig if (len < 0) { 1924bfdc5970SChristoph Hellwig ret = -EINVAL; 1925bfdc5970SChristoph Hellwig goto uaccess_end; 1926bfdc5970SChristoph Hellwig } 1927bfdc5970SChristoph Hellwig iov[i].iov_base = compat_ptr(buf); 1928bfdc5970SChristoph Hellwig iov[i].iov_len = len; 1929bfdc5970SChristoph Hellwig } 1930bfdc5970SChristoph Hellwig 1931bfdc5970SChristoph Hellwig ret = 0; 1932bfdc5970SChristoph Hellwig uaccess_end: 1933bfdc5970SChristoph Hellwig user_access_end(); 1934bfdc5970SChristoph Hellwig return ret; 1935bfdc5970SChristoph Hellwig } 1936bfdc5970SChristoph Hellwig 1937bfdc5970SChristoph Hellwig static int copy_iovec_from_user(struct iovec *iov, 1938bfdc5970SChristoph Hellwig const struct iovec __user *uvec, unsigned long nr_segs) 1939fb041b59SDavid Laight { 1940fb041b59SDavid Laight unsigned long seg; 1941bfdc5970SChristoph Hellwig 1942bfdc5970SChristoph Hellwig if (copy_from_user(iov, uvec, nr_segs * sizeof(*uvec))) 1943bfdc5970SChristoph Hellwig return -EFAULT; 1944bfdc5970SChristoph Hellwig for (seg = 0; seg < nr_segs; seg++) { 1945bfdc5970SChristoph Hellwig if ((ssize_t)iov[seg].iov_len < 0) 1946bfdc5970SChristoph Hellwig return -EINVAL; 1947bfdc5970SChristoph Hellwig } 1948bfdc5970SChristoph Hellwig 1949bfdc5970SChristoph Hellwig return 0; 1950bfdc5970SChristoph Hellwig } 1951bfdc5970SChristoph Hellwig 1952bfdc5970SChristoph Hellwig struct iovec *iovec_from_user(const struct iovec __user *uvec, 1953bfdc5970SChristoph Hellwig unsigned long nr_segs, unsigned long fast_segs, 1954bfdc5970SChristoph Hellwig struct iovec *fast_iov, bool compat) 1955bfdc5970SChristoph Hellwig { 1956bfdc5970SChristoph Hellwig struct iovec *iov = fast_iov; 1957bfdc5970SChristoph Hellwig int ret; 1958fb041b59SDavid Laight 1959fb041b59SDavid Laight /* 1960bfdc5970SChristoph Hellwig * SuS says "The readv() function *may* fail if the iovcnt argument was 1961bfdc5970SChristoph Hellwig * less than or equal to 0, or greater than {IOV_MAX}. Linux has 1962fb041b59SDavid Laight * traditionally returned zero for zero segments, so... 1963fb041b59SDavid Laight */ 1964bfdc5970SChristoph Hellwig if (nr_segs == 0) 1965bfdc5970SChristoph Hellwig return iov; 1966bfdc5970SChristoph Hellwig if (nr_segs > UIO_MAXIOV) 1967bfdc5970SChristoph Hellwig return ERR_PTR(-EINVAL); 1968fb041b59SDavid Laight if (nr_segs > fast_segs) { 1969fb041b59SDavid Laight iov = kmalloc_array(nr_segs, sizeof(struct iovec), GFP_KERNEL); 1970bfdc5970SChristoph Hellwig if (!iov) 1971bfdc5970SChristoph Hellwig return ERR_PTR(-ENOMEM); 1972fb041b59SDavid Laight } 1973bfdc5970SChristoph Hellwig 1974bfdc5970SChristoph Hellwig if (compat) 1975bfdc5970SChristoph Hellwig ret = copy_compat_iovec_from_user(iov, uvec, nr_segs); 1976bfdc5970SChristoph Hellwig else 1977bfdc5970SChristoph Hellwig ret = copy_iovec_from_user(iov, uvec, nr_segs); 1978bfdc5970SChristoph Hellwig if (ret) { 1979bfdc5970SChristoph Hellwig if (iov != fast_iov) 1980bfdc5970SChristoph Hellwig kfree(iov); 1981bfdc5970SChristoph Hellwig return ERR_PTR(ret); 1982fb041b59SDavid Laight } 1983bfdc5970SChristoph Hellwig 1984bfdc5970SChristoph Hellwig return iov; 1985bfdc5970SChristoph Hellwig } 1986bfdc5970SChristoph Hellwig 1987bfdc5970SChristoph Hellwig ssize_t __import_iovec(int type, const struct iovec __user *uvec, 1988bfdc5970SChristoph Hellwig unsigned nr_segs, unsigned fast_segs, struct iovec **iovp, 1989bfdc5970SChristoph Hellwig struct iov_iter *i, bool compat) 1990bfdc5970SChristoph Hellwig { 1991bfdc5970SChristoph Hellwig ssize_t total_len = 0; 1992bfdc5970SChristoph Hellwig unsigned long seg; 1993bfdc5970SChristoph Hellwig struct iovec *iov; 1994bfdc5970SChristoph Hellwig 1995bfdc5970SChristoph Hellwig iov = iovec_from_user(uvec, nr_segs, fast_segs, *iovp, compat); 1996bfdc5970SChristoph Hellwig if (IS_ERR(iov)) { 1997bfdc5970SChristoph Hellwig *iovp = NULL; 1998bfdc5970SChristoph Hellwig return PTR_ERR(iov); 1999fb041b59SDavid Laight } 2000fb041b59SDavid Laight 2001fb041b59SDavid Laight /* 2002bfdc5970SChristoph Hellwig * According to the Single Unix Specification we should return EINVAL if 2003bfdc5970SChristoph Hellwig * an element length is < 0 when cast to ssize_t or if the total length 2004bfdc5970SChristoph Hellwig * would overflow the ssize_t return value of the system call. 2005fb041b59SDavid Laight * 2006fb041b59SDavid Laight * Linux caps all read/write calls to MAX_RW_COUNT, and avoids the 2007fb041b59SDavid Laight * overflow case. 2008fb041b59SDavid Laight */ 2009fb041b59SDavid Laight for (seg = 0; seg < nr_segs; seg++) { 2010fb041b59SDavid Laight ssize_t len = (ssize_t)iov[seg].iov_len; 2011fb041b59SDavid Laight 2012bfdc5970SChristoph Hellwig if (!access_ok(iov[seg].iov_base, len)) { 2013bfdc5970SChristoph Hellwig if (iov != *iovp) 2014bfdc5970SChristoph Hellwig kfree(iov); 2015bfdc5970SChristoph Hellwig *iovp = NULL; 2016bfdc5970SChristoph Hellwig return -EFAULT; 2017fb041b59SDavid Laight } 2018bfdc5970SChristoph Hellwig 2019bfdc5970SChristoph Hellwig if (len > MAX_RW_COUNT - total_len) { 2020bfdc5970SChristoph Hellwig len = MAX_RW_COUNT - total_len; 2021fb041b59SDavid Laight iov[seg].iov_len = len; 2022fb041b59SDavid Laight } 2023bfdc5970SChristoph Hellwig total_len += len; 2024fb041b59SDavid Laight } 2025bfdc5970SChristoph Hellwig 2026bfdc5970SChristoph Hellwig iov_iter_init(i, type, iov, nr_segs, total_len); 2027bfdc5970SChristoph Hellwig if (iov == *iovp) 2028bfdc5970SChristoph Hellwig *iovp = NULL; 2029bfdc5970SChristoph Hellwig else 2030bfdc5970SChristoph Hellwig *iovp = iov; 2031bfdc5970SChristoph Hellwig return total_len; 2032fb041b59SDavid Laight } 2033fb041b59SDavid Laight 2034ffecee4fSVegard Nossum /** 2035ffecee4fSVegard Nossum * import_iovec() - Copy an array of &struct iovec from userspace 2036ffecee4fSVegard Nossum * into the kernel, check that it is valid, and initialize a new 2037ffecee4fSVegard Nossum * &struct iov_iter iterator to access it. 2038ffecee4fSVegard Nossum * 2039ffecee4fSVegard Nossum * @type: One of %READ or %WRITE. 2040bfdc5970SChristoph Hellwig * @uvec: Pointer to the userspace array. 2041ffecee4fSVegard Nossum * @nr_segs: Number of elements in userspace array. 2042ffecee4fSVegard Nossum * @fast_segs: Number of elements in @iov. 2043bfdc5970SChristoph Hellwig * @iovp: (input and output parameter) Pointer to pointer to (usually small 2044ffecee4fSVegard Nossum * on-stack) kernel array. 2045ffecee4fSVegard Nossum * @i: Pointer to iterator that will be initialized on success. 2046ffecee4fSVegard Nossum * 2047ffecee4fSVegard Nossum * If the array pointed to by *@iov is large enough to hold all @nr_segs, 2048ffecee4fSVegard Nossum * then this function places %NULL in *@iov on return. Otherwise, a new 2049ffecee4fSVegard Nossum * array will be allocated and the result placed in *@iov. This means that 2050ffecee4fSVegard Nossum * the caller may call kfree() on *@iov regardless of whether the small 2051ffecee4fSVegard Nossum * on-stack array was used or not (and regardless of whether this function 2052ffecee4fSVegard Nossum * returns an error or not). 2053ffecee4fSVegard Nossum * 205487e5e6daSJens Axboe * Return: Negative error code on error, bytes imported on success 2055ffecee4fSVegard Nossum */ 2056bfdc5970SChristoph Hellwig ssize_t import_iovec(int type, const struct iovec __user *uvec, 2057bc917be8SAl Viro unsigned nr_segs, unsigned fast_segs, 2058bfdc5970SChristoph Hellwig struct iovec **iovp, struct iov_iter *i) 2059bc917be8SAl Viro { 206089cd35c5SChristoph Hellwig return __import_iovec(type, uvec, nr_segs, fast_segs, iovp, i, 206189cd35c5SChristoph Hellwig in_compat_syscall()); 2062bc917be8SAl Viro } 2063bc917be8SAl Viro EXPORT_SYMBOL(import_iovec); 2064bc917be8SAl Viro 2065bc917be8SAl Viro int import_single_range(int rw, void __user *buf, size_t len, 2066bc917be8SAl Viro struct iovec *iov, struct iov_iter *i) 2067bc917be8SAl Viro { 2068bc917be8SAl Viro if (len > MAX_RW_COUNT) 2069bc917be8SAl Viro len = MAX_RW_COUNT; 207096d4f267SLinus Torvalds if (unlikely(!access_ok(buf, len))) 2071bc917be8SAl Viro return -EFAULT; 2072bc917be8SAl Viro 2073bc917be8SAl Viro iov->iov_base = buf; 2074bc917be8SAl Viro iov->iov_len = len; 2075bc917be8SAl Viro iov_iter_init(i, rw, iov, 1, len); 2076bc917be8SAl Viro return 0; 2077bc917be8SAl Viro } 2078e1267585SAl Viro EXPORT_SYMBOL(import_single_range); 2079