1457c8996SThomas Gleixner // SPDX-License-Identifier: GPL-2.0-only 27999096fSHerbert Xu #include <crypto/hash.h> 3d879cb83SAl Viro #include <linux/export.h> 42f8b5444SChristoph Hellwig #include <linux/bvec.h> 54d0e9df5SAlbert van der Linde #include <linux/fault-inject-usercopy.h> 6d879cb83SAl Viro #include <linux/uio.h> 7d879cb83SAl Viro #include <linux/pagemap.h> 828961998SIra Weiny #include <linux/highmem.h> 9d879cb83SAl Viro #include <linux/slab.h> 10d879cb83SAl Viro #include <linux/vmalloc.h> 11241699cdSAl Viro #include <linux/splice.h> 12bfdc5970SChristoph Hellwig #include <linux/compat.h> 13d879cb83SAl Viro #include <net/checksum.h> 14d05f4435SSagi Grimberg #include <linux/scatterlist.h> 15d0ef4c36SMarco Elver #include <linux/instrumented.h> 16d879cb83SAl Viro 17241699cdSAl Viro #define PIPE_PARANOIA /* for now */ 18241699cdSAl Viro 195c67aa90SAl Viro /* covers iovec and kvec alike */ 20a6e4ec7bSAl Viro #define iterate_iovec(i, n, base, len, off, __p, STEP) { \ 217baa5099SAl Viro size_t off = 0; \ 22a6e4ec7bSAl Viro size_t skip = i->iov_offset; \ 237a1bcb5dSAl Viro do { \ 247baa5099SAl Viro len = min(n, __p->iov_len - skip); \ 257baa5099SAl Viro if (likely(len)) { \ 267baa5099SAl Viro base = __p->iov_base + skip; \ 277baa5099SAl Viro len -= (STEP); \ 287baa5099SAl Viro off += len; \ 297baa5099SAl Viro skip += len; \ 307baa5099SAl Viro n -= len; \ 317a1bcb5dSAl Viro if (skip < __p->iov_len) \ 327a1bcb5dSAl Viro break; \ 33d879cb83SAl Viro } \ 34d879cb83SAl Viro __p++; \ 357a1bcb5dSAl Viro skip = 0; \ 367a1bcb5dSAl Viro } while (n); \ 37a6e4ec7bSAl Viro i->iov_offset = skip; \ 387baa5099SAl Viro n = off; \ 39d879cb83SAl Viro } 40d879cb83SAl Viro 41a6e4ec7bSAl Viro #define iterate_bvec(i, n, base, len, off, p, STEP) { \ 427baa5099SAl Viro size_t off = 0; \ 43a6e4ec7bSAl Viro unsigned skip = i->iov_offset; \ 447491a2bfSAl Viro while (n) { \ 457491a2bfSAl Viro unsigned offset = p->bv_offset + skip; \ 461b4fb5ffSAl Viro unsigned left; \ 4721b56c84SAl Viro void *kaddr = kmap_local_page(p->bv_page + \ 4821b56c84SAl Viro offset / PAGE_SIZE); \ 497baa5099SAl Viro base = kaddr + offset % PAGE_SIZE; \ 50a6e4ec7bSAl Viro len = min(min(n, (size_t)(p->bv_len - skip)), \ 517491a2bfSAl Viro (size_t)(PAGE_SIZE - offset % PAGE_SIZE)); \ 521b4fb5ffSAl Viro left = (STEP); \ 5321b56c84SAl Viro kunmap_local(kaddr); \ 547baa5099SAl Viro len -= left; \ 557baa5099SAl Viro off += len; \ 567baa5099SAl Viro skip += len; \ 577491a2bfSAl Viro if (skip == p->bv_len) { \ 587491a2bfSAl Viro skip = 0; \ 597491a2bfSAl Viro p++; \ 60d879cb83SAl Viro } \ 617baa5099SAl Viro n -= len; \ 621b4fb5ffSAl Viro if (left) \ 631b4fb5ffSAl Viro break; \ 647491a2bfSAl Viro } \ 65a6e4ec7bSAl Viro i->iov_offset = skip; \ 667baa5099SAl Viro n = off; \ 67d879cb83SAl Viro } 68d879cb83SAl Viro 69a6e4ec7bSAl Viro #define iterate_xarray(i, n, base, len, __off, STEP) { \ 701b4fb5ffSAl Viro __label__ __out; \ 71622838f3SAl Viro size_t __off = 0; \ 727ff50620SDavid Howells struct page *head = NULL; \ 73a6e4ec7bSAl Viro loff_t start = i->xarray_start + i->iov_offset; \ 744b179e9aSAl Viro unsigned offset = start % PAGE_SIZE; \ 754b179e9aSAl Viro pgoff_t index = start / PAGE_SIZE; \ 767ff50620SDavid Howells int j; \ 777ff50620SDavid Howells \ 787ff50620SDavid Howells XA_STATE(xas, i->xarray, index); \ 797ff50620SDavid Howells \ 807ff50620SDavid Howells rcu_read_lock(); \ 817ff50620SDavid Howells xas_for_each(&xas, head, ULONG_MAX) { \ 821b4fb5ffSAl Viro unsigned left; \ 837ff50620SDavid Howells if (xas_retry(&xas, head)) \ 847ff50620SDavid Howells continue; \ 857ff50620SDavid Howells if (WARN_ON(xa_is_value(head))) \ 867ff50620SDavid Howells break; \ 877ff50620SDavid Howells if (WARN_ON(PageHuge(head))) \ 887ff50620SDavid Howells break; \ 897ff50620SDavid Howells for (j = (head->index < index) ? index - head->index : 0; \ 907ff50620SDavid Howells j < thp_nr_pages(head); j++) { \ 9121b56c84SAl Viro void *kaddr = kmap_local_page(head + j); \ 927baa5099SAl Viro base = kaddr + offset; \ 937baa5099SAl Viro len = PAGE_SIZE - offset; \ 947baa5099SAl Viro len = min(n, len); \ 951b4fb5ffSAl Viro left = (STEP); \ 9621b56c84SAl Viro kunmap_local(kaddr); \ 977baa5099SAl Viro len -= left; \ 987baa5099SAl Viro __off += len; \ 997baa5099SAl Viro n -= len; \ 1001b4fb5ffSAl Viro if (left || n == 0) \ 1011b4fb5ffSAl Viro goto __out; \ 1024b179e9aSAl Viro offset = 0; \ 1037ff50620SDavid Howells } \ 1047ff50620SDavid Howells } \ 1051b4fb5ffSAl Viro __out: \ 1067ff50620SDavid Howells rcu_read_unlock(); \ 107a6e4ec7bSAl Viro i->iov_offset += __off; \ 108622838f3SAl Viro n = __off; \ 1097ff50620SDavid Howells } 1107ff50620SDavid Howells 1117baa5099SAl Viro #define __iterate_and_advance(i, n, base, len, off, I, K) { \ 112dd254f5aSAl Viro if (unlikely(i->count < n)) \ 113dd254f5aSAl Viro n = i->count; \ 114f5da8354SAl Viro if (likely(n)) { \ 11528f38db7SAl Viro if (likely(iter_is_iovec(i))) { \ 1165c67aa90SAl Viro const struct iovec *iov = i->iov; \ 1177baa5099SAl Viro void __user *base; \ 1187baa5099SAl Viro size_t len; \ 1197baa5099SAl Viro iterate_iovec(i, n, base, len, off, \ 120a6e4ec7bSAl Viro iov, (I)) \ 121d879cb83SAl Viro i->nr_segs -= iov - i->iov; \ 122d879cb83SAl Viro i->iov = iov; \ 12328f38db7SAl Viro } else if (iov_iter_is_bvec(i)) { \ 12428f38db7SAl Viro const struct bio_vec *bvec = i->bvec; \ 1257baa5099SAl Viro void *base; \ 1267baa5099SAl Viro size_t len; \ 1277baa5099SAl Viro iterate_bvec(i, n, base, len, off, \ 128a6e4ec7bSAl Viro bvec, (K)) \ 1297491a2bfSAl Viro i->nr_segs -= bvec - i->bvec; \ 1307491a2bfSAl Viro i->bvec = bvec; \ 13128f38db7SAl Viro } else if (iov_iter_is_kvec(i)) { \ 1325c67aa90SAl Viro const struct kvec *kvec = i->kvec; \ 1337baa5099SAl Viro void *base; \ 1347baa5099SAl Viro size_t len; \ 1357baa5099SAl Viro iterate_iovec(i, n, base, len, off, \ 136a6e4ec7bSAl Viro kvec, (K)) \ 13728f38db7SAl Viro i->nr_segs -= kvec - i->kvec; \ 13828f38db7SAl Viro i->kvec = kvec; \ 13928f38db7SAl Viro } else if (iov_iter_is_xarray(i)) { \ 1407baa5099SAl Viro void *base; \ 1417baa5099SAl Viro size_t len; \ 1427baa5099SAl Viro iterate_xarray(i, n, base, len, off, \ 143a6e4ec7bSAl Viro (K)) \ 144d879cb83SAl Viro } \ 145d879cb83SAl Viro i->count -= n; \ 146dd254f5aSAl Viro } \ 147d879cb83SAl Viro } 1487baa5099SAl Viro #define iterate_and_advance(i, n, base, len, off, I, K) \ 1497baa5099SAl Viro __iterate_and_advance(i, n, base, len, off, I, ((void)(K),0)) 150d879cb83SAl Viro 15109fc68dcSAl Viro static int copyout(void __user *to, const void *from, size_t n) 15209fc68dcSAl Viro { 1534d0e9df5SAlbert van der Linde if (should_fail_usercopy()) 1544d0e9df5SAlbert van der Linde return n; 15596d4f267SLinus Torvalds if (access_ok(to, n)) { 156d0ef4c36SMarco Elver instrument_copy_to_user(to, from, n); 15709fc68dcSAl Viro n = raw_copy_to_user(to, from, n); 15809fc68dcSAl Viro } 15909fc68dcSAl Viro return n; 16009fc68dcSAl Viro } 16109fc68dcSAl Viro 16209fc68dcSAl Viro static int copyin(void *to, const void __user *from, size_t n) 16309fc68dcSAl Viro { 1644d0e9df5SAlbert van der Linde if (should_fail_usercopy()) 1654d0e9df5SAlbert van der Linde return n; 16696d4f267SLinus Torvalds if (access_ok(from, n)) { 167d0ef4c36SMarco Elver instrument_copy_from_user(to, from, n); 16809fc68dcSAl Viro n = raw_copy_from_user(to, from, n); 16909fc68dcSAl Viro } 17009fc68dcSAl Viro return n; 17109fc68dcSAl Viro } 17209fc68dcSAl Viro 173d879cb83SAl Viro static size_t copy_page_to_iter_iovec(struct page *page, size_t offset, size_t bytes, 174d879cb83SAl Viro struct iov_iter *i) 175d879cb83SAl Viro { 176d879cb83SAl Viro size_t skip, copy, left, wanted; 177d879cb83SAl Viro const struct iovec *iov; 178d879cb83SAl Viro char __user *buf; 179d879cb83SAl Viro void *kaddr, *from; 180d879cb83SAl Viro 181d879cb83SAl Viro if (unlikely(bytes > i->count)) 182d879cb83SAl Viro bytes = i->count; 183d879cb83SAl Viro 184d879cb83SAl Viro if (unlikely(!bytes)) 185d879cb83SAl Viro return 0; 186d879cb83SAl Viro 18709fc68dcSAl Viro might_fault(); 188d879cb83SAl Viro wanted = bytes; 189d879cb83SAl Viro iov = i->iov; 190d879cb83SAl Viro skip = i->iov_offset; 191d879cb83SAl Viro buf = iov->iov_base + skip; 192d879cb83SAl Viro copy = min(bytes, iov->iov_len - skip); 193d879cb83SAl Viro 194*bb523b40SAndreas Gruenbacher if (IS_ENABLED(CONFIG_HIGHMEM) && !fault_in_writeable(buf, copy)) { 195d879cb83SAl Viro kaddr = kmap_atomic(page); 196d879cb83SAl Viro from = kaddr + offset; 197d879cb83SAl Viro 198d879cb83SAl Viro /* first chunk, usually the only one */ 19909fc68dcSAl Viro left = copyout(buf, from, copy); 200d879cb83SAl Viro copy -= left; 201d879cb83SAl Viro skip += copy; 202d879cb83SAl Viro from += copy; 203d879cb83SAl Viro bytes -= copy; 204d879cb83SAl Viro 205d879cb83SAl Viro while (unlikely(!left && bytes)) { 206d879cb83SAl Viro iov++; 207d879cb83SAl Viro buf = iov->iov_base; 208d879cb83SAl Viro copy = min(bytes, iov->iov_len); 20909fc68dcSAl Viro left = copyout(buf, from, copy); 210d879cb83SAl Viro copy -= left; 211d879cb83SAl Viro skip = copy; 212d879cb83SAl Viro from += copy; 213d879cb83SAl Viro bytes -= copy; 214d879cb83SAl Viro } 215d879cb83SAl Viro if (likely(!bytes)) { 216d879cb83SAl Viro kunmap_atomic(kaddr); 217d879cb83SAl Viro goto done; 218d879cb83SAl Viro } 219d879cb83SAl Viro offset = from - kaddr; 220d879cb83SAl Viro buf += copy; 221d879cb83SAl Viro kunmap_atomic(kaddr); 222d879cb83SAl Viro copy = min(bytes, iov->iov_len - skip); 223d879cb83SAl Viro } 224d879cb83SAl Viro /* Too bad - revert to non-atomic kmap */ 2253fa6c507SMikulas Patocka 226d879cb83SAl Viro kaddr = kmap(page); 227d879cb83SAl Viro from = kaddr + offset; 22809fc68dcSAl Viro left = copyout(buf, from, copy); 229d879cb83SAl Viro copy -= left; 230d879cb83SAl Viro skip += copy; 231d879cb83SAl Viro from += copy; 232d879cb83SAl Viro bytes -= copy; 233d879cb83SAl Viro while (unlikely(!left && bytes)) { 234d879cb83SAl Viro iov++; 235d879cb83SAl Viro buf = iov->iov_base; 236d879cb83SAl Viro copy = min(bytes, iov->iov_len); 23709fc68dcSAl Viro left = copyout(buf, from, copy); 238d879cb83SAl Viro copy -= left; 239d879cb83SAl Viro skip = copy; 240d879cb83SAl Viro from += copy; 241d879cb83SAl Viro bytes -= copy; 242d879cb83SAl Viro } 243d879cb83SAl Viro kunmap(page); 2443fa6c507SMikulas Patocka 245d879cb83SAl Viro done: 246d879cb83SAl Viro if (skip == iov->iov_len) { 247d879cb83SAl Viro iov++; 248d879cb83SAl Viro skip = 0; 249d879cb83SAl Viro } 250d879cb83SAl Viro i->count -= wanted - bytes; 251d879cb83SAl Viro i->nr_segs -= iov - i->iov; 252d879cb83SAl Viro i->iov = iov; 253d879cb83SAl Viro i->iov_offset = skip; 254d879cb83SAl Viro return wanted - bytes; 255d879cb83SAl Viro } 256d879cb83SAl Viro 257d879cb83SAl Viro static size_t copy_page_from_iter_iovec(struct page *page, size_t offset, size_t bytes, 258d879cb83SAl Viro struct iov_iter *i) 259d879cb83SAl Viro { 260d879cb83SAl Viro size_t skip, copy, left, wanted; 261d879cb83SAl Viro const struct iovec *iov; 262d879cb83SAl Viro char __user *buf; 263d879cb83SAl Viro void *kaddr, *to; 264d879cb83SAl Viro 265d879cb83SAl Viro if (unlikely(bytes > i->count)) 266d879cb83SAl Viro bytes = i->count; 267d879cb83SAl Viro 268d879cb83SAl Viro if (unlikely(!bytes)) 269d879cb83SAl Viro return 0; 270d879cb83SAl Viro 27109fc68dcSAl Viro might_fault(); 272d879cb83SAl Viro wanted = bytes; 273d879cb83SAl Viro iov = i->iov; 274d879cb83SAl Viro skip = i->iov_offset; 275d879cb83SAl Viro buf = iov->iov_base + skip; 276d879cb83SAl Viro copy = min(bytes, iov->iov_len - skip); 277d879cb83SAl Viro 278*bb523b40SAndreas Gruenbacher if (IS_ENABLED(CONFIG_HIGHMEM) && !fault_in_readable(buf, copy)) { 279d879cb83SAl Viro kaddr = kmap_atomic(page); 280d879cb83SAl Viro to = kaddr + offset; 281d879cb83SAl Viro 282d879cb83SAl Viro /* first chunk, usually the only one */ 28309fc68dcSAl Viro left = copyin(to, buf, copy); 284d879cb83SAl Viro copy -= left; 285d879cb83SAl Viro skip += copy; 286d879cb83SAl Viro to += copy; 287d879cb83SAl Viro bytes -= copy; 288d879cb83SAl Viro 289d879cb83SAl Viro while (unlikely(!left && bytes)) { 290d879cb83SAl Viro iov++; 291d879cb83SAl Viro buf = iov->iov_base; 292d879cb83SAl Viro copy = min(bytes, iov->iov_len); 29309fc68dcSAl Viro left = copyin(to, buf, copy); 294d879cb83SAl Viro copy -= left; 295d879cb83SAl Viro skip = copy; 296d879cb83SAl Viro to += copy; 297d879cb83SAl Viro bytes -= copy; 298d879cb83SAl Viro } 299d879cb83SAl Viro if (likely(!bytes)) { 300d879cb83SAl Viro kunmap_atomic(kaddr); 301d879cb83SAl Viro goto done; 302d879cb83SAl Viro } 303d879cb83SAl Viro offset = to - kaddr; 304d879cb83SAl Viro buf += copy; 305d879cb83SAl Viro kunmap_atomic(kaddr); 306d879cb83SAl Viro copy = min(bytes, iov->iov_len - skip); 307d879cb83SAl Viro } 308d879cb83SAl Viro /* Too bad - revert to non-atomic kmap */ 3093fa6c507SMikulas Patocka 310d879cb83SAl Viro kaddr = kmap(page); 311d879cb83SAl Viro to = kaddr + offset; 31209fc68dcSAl Viro left = copyin(to, buf, copy); 313d879cb83SAl Viro copy -= left; 314d879cb83SAl Viro skip += copy; 315d879cb83SAl Viro to += copy; 316d879cb83SAl Viro bytes -= copy; 317d879cb83SAl Viro while (unlikely(!left && bytes)) { 318d879cb83SAl Viro iov++; 319d879cb83SAl Viro buf = iov->iov_base; 320d879cb83SAl Viro copy = min(bytes, iov->iov_len); 32109fc68dcSAl Viro left = copyin(to, buf, copy); 322d879cb83SAl Viro copy -= left; 323d879cb83SAl Viro skip = copy; 324d879cb83SAl Viro to += copy; 325d879cb83SAl Viro bytes -= copy; 326d879cb83SAl Viro } 327d879cb83SAl Viro kunmap(page); 3283fa6c507SMikulas Patocka 329d879cb83SAl Viro done: 330d879cb83SAl Viro if (skip == iov->iov_len) { 331d879cb83SAl Viro iov++; 332d879cb83SAl Viro skip = 0; 333d879cb83SAl Viro } 334d879cb83SAl Viro i->count -= wanted - bytes; 335d879cb83SAl Viro i->nr_segs -= iov - i->iov; 336d879cb83SAl Viro i->iov = iov; 337d879cb83SAl Viro i->iov_offset = skip; 338d879cb83SAl Viro return wanted - bytes; 339d879cb83SAl Viro } 340d879cb83SAl Viro 341241699cdSAl Viro #ifdef PIPE_PARANOIA 342241699cdSAl Viro static bool sanity(const struct iov_iter *i) 343241699cdSAl Viro { 344241699cdSAl Viro struct pipe_inode_info *pipe = i->pipe; 3458cefc107SDavid Howells unsigned int p_head = pipe->head; 3468cefc107SDavid Howells unsigned int p_tail = pipe->tail; 3478cefc107SDavid Howells unsigned int p_mask = pipe->ring_size - 1; 3488cefc107SDavid Howells unsigned int p_occupancy = pipe_occupancy(p_head, p_tail); 3498cefc107SDavid Howells unsigned int i_head = i->head; 3508cefc107SDavid Howells unsigned int idx; 3518cefc107SDavid Howells 352241699cdSAl Viro if (i->iov_offset) { 353241699cdSAl Viro struct pipe_buffer *p; 3548cefc107SDavid Howells if (unlikely(p_occupancy == 0)) 355241699cdSAl Viro goto Bad; // pipe must be non-empty 3568cefc107SDavid Howells if (unlikely(i_head != p_head - 1)) 357241699cdSAl Viro goto Bad; // must be at the last buffer... 358241699cdSAl Viro 3598cefc107SDavid Howells p = &pipe->bufs[i_head & p_mask]; 360241699cdSAl Viro if (unlikely(p->offset + p->len != i->iov_offset)) 361241699cdSAl Viro goto Bad; // ... at the end of segment 362241699cdSAl Viro } else { 3638cefc107SDavid Howells if (i_head != p_head) 364241699cdSAl Viro goto Bad; // must be right after the last buffer 365241699cdSAl Viro } 366241699cdSAl Viro return true; 367241699cdSAl Viro Bad: 3688cefc107SDavid Howells printk(KERN_ERR "idx = %d, offset = %zd\n", i_head, i->iov_offset); 3698cefc107SDavid Howells printk(KERN_ERR "head = %d, tail = %d, buffers = %d\n", 3708cefc107SDavid Howells p_head, p_tail, pipe->ring_size); 3718cefc107SDavid Howells for (idx = 0; idx < pipe->ring_size; idx++) 372241699cdSAl Viro printk(KERN_ERR "[%p %p %d %d]\n", 373241699cdSAl Viro pipe->bufs[idx].ops, 374241699cdSAl Viro pipe->bufs[idx].page, 375241699cdSAl Viro pipe->bufs[idx].offset, 376241699cdSAl Viro pipe->bufs[idx].len); 377241699cdSAl Viro WARN_ON(1); 378241699cdSAl Viro return false; 379241699cdSAl Viro } 380241699cdSAl Viro #else 381241699cdSAl Viro #define sanity(i) true 382241699cdSAl Viro #endif 383241699cdSAl Viro 384241699cdSAl Viro static size_t copy_page_to_iter_pipe(struct page *page, size_t offset, size_t bytes, 385241699cdSAl Viro struct iov_iter *i) 386241699cdSAl Viro { 387241699cdSAl Viro struct pipe_inode_info *pipe = i->pipe; 388241699cdSAl Viro struct pipe_buffer *buf; 3898cefc107SDavid Howells unsigned int p_tail = pipe->tail; 3908cefc107SDavid Howells unsigned int p_mask = pipe->ring_size - 1; 3918cefc107SDavid Howells unsigned int i_head = i->head; 392241699cdSAl Viro size_t off; 393241699cdSAl Viro 394241699cdSAl Viro if (unlikely(bytes > i->count)) 395241699cdSAl Viro bytes = i->count; 396241699cdSAl Viro 397241699cdSAl Viro if (unlikely(!bytes)) 398241699cdSAl Viro return 0; 399241699cdSAl Viro 400241699cdSAl Viro if (!sanity(i)) 401241699cdSAl Viro return 0; 402241699cdSAl Viro 403241699cdSAl Viro off = i->iov_offset; 4048cefc107SDavid Howells buf = &pipe->bufs[i_head & p_mask]; 405241699cdSAl Viro if (off) { 406241699cdSAl Viro if (offset == off && buf->page == page) { 407241699cdSAl Viro /* merge with the last one */ 408241699cdSAl Viro buf->len += bytes; 409241699cdSAl Viro i->iov_offset += bytes; 410241699cdSAl Viro goto out; 411241699cdSAl Viro } 4128cefc107SDavid Howells i_head++; 4138cefc107SDavid Howells buf = &pipe->bufs[i_head & p_mask]; 414241699cdSAl Viro } 4156718b6f8SDavid Howells if (pipe_full(i_head, p_tail, pipe->max_usage)) 416241699cdSAl Viro return 0; 4178cefc107SDavid Howells 418241699cdSAl Viro buf->ops = &page_cache_pipe_buf_ops; 4198cefc107SDavid Howells get_page(page); 4208cefc107SDavid Howells buf->page = page; 421241699cdSAl Viro buf->offset = offset; 422241699cdSAl Viro buf->len = bytes; 4238cefc107SDavid Howells 4248cefc107SDavid Howells pipe->head = i_head + 1; 425241699cdSAl Viro i->iov_offset = offset + bytes; 4268cefc107SDavid Howells i->head = i_head; 427241699cdSAl Viro out: 428241699cdSAl Viro i->count -= bytes; 429241699cdSAl Viro return bytes; 430241699cdSAl Viro } 431241699cdSAl Viro 432d879cb83SAl Viro /* 433171a0203SAnton Altaparmakov * Fault in one or more iovecs of the given iov_iter, to a maximum length of 434171a0203SAnton Altaparmakov * bytes. For each iovec, fault in each page that constitutes the iovec. 435171a0203SAnton Altaparmakov * 436171a0203SAnton Altaparmakov * Return 0 on success, or non-zero if the memory could not be accessed (i.e. 437171a0203SAnton Altaparmakov * because it is an invalid address). 438171a0203SAnton Altaparmakov */ 4398409a0d2SAl Viro int iov_iter_fault_in_readable(const struct iov_iter *i, size_t bytes) 440171a0203SAnton Altaparmakov { 4410e8f0d67SAl Viro if (iter_is_iovec(i)) { 4428409a0d2SAl Viro const struct iovec *p; 4438409a0d2SAl Viro size_t skip; 4448409a0d2SAl Viro 4458409a0d2SAl Viro if (bytes > i->count) 4468409a0d2SAl Viro bytes = i->count; 4478409a0d2SAl Viro for (p = i->iov, skip = i->iov_offset; bytes; p++, skip = 0) { 4488409a0d2SAl Viro size_t len = min(bytes, p->iov_len - skip); 4498409a0d2SAl Viro 4508409a0d2SAl Viro if (unlikely(!len)) 4518409a0d2SAl Viro continue; 452*bb523b40SAndreas Gruenbacher if (fault_in_readable(p->iov_base + skip, len)) 453*bb523b40SAndreas Gruenbacher return -EFAULT; 4548409a0d2SAl Viro bytes -= len; 4558409a0d2SAl Viro } 456171a0203SAnton Altaparmakov } 457171a0203SAnton Altaparmakov return 0; 458171a0203SAnton Altaparmakov } 459d4690f1eSAl Viro EXPORT_SYMBOL(iov_iter_fault_in_readable); 460171a0203SAnton Altaparmakov 461aa563d7bSDavid Howells void iov_iter_init(struct iov_iter *i, unsigned int direction, 462d879cb83SAl Viro const struct iovec *iov, unsigned long nr_segs, 463d879cb83SAl Viro size_t count) 464d879cb83SAl Viro { 465aa563d7bSDavid Howells WARN_ON(direction & ~(READ | WRITE)); 4668cd54c1cSAl Viro *i = (struct iov_iter) { 4678cd54c1cSAl Viro .iter_type = ITER_IOVEC, 4688cd54c1cSAl Viro .data_source = direction, 4698cd54c1cSAl Viro .iov = iov, 4708cd54c1cSAl Viro .nr_segs = nr_segs, 4718cd54c1cSAl Viro .iov_offset = 0, 4728cd54c1cSAl Viro .count = count 4738cd54c1cSAl Viro }; 474d879cb83SAl Viro } 475d879cb83SAl Viro EXPORT_SYMBOL(iov_iter_init); 476d879cb83SAl Viro 477241699cdSAl Viro static inline bool allocated(struct pipe_buffer *buf) 478241699cdSAl Viro { 479241699cdSAl Viro return buf->ops == &default_pipe_buf_ops; 480241699cdSAl Viro } 481241699cdSAl Viro 4828cefc107SDavid Howells static inline void data_start(const struct iov_iter *i, 4838cefc107SDavid Howells unsigned int *iter_headp, size_t *offp) 484241699cdSAl Viro { 4858cefc107SDavid Howells unsigned int p_mask = i->pipe->ring_size - 1; 4868cefc107SDavid Howells unsigned int iter_head = i->head; 487241699cdSAl Viro size_t off = i->iov_offset; 4888cefc107SDavid Howells 4898cefc107SDavid Howells if (off && (!allocated(&i->pipe->bufs[iter_head & p_mask]) || 4908cefc107SDavid Howells off == PAGE_SIZE)) { 4918cefc107SDavid Howells iter_head++; 492241699cdSAl Viro off = 0; 493241699cdSAl Viro } 4948cefc107SDavid Howells *iter_headp = iter_head; 495241699cdSAl Viro *offp = off; 496241699cdSAl Viro } 497241699cdSAl Viro 498241699cdSAl Viro static size_t push_pipe(struct iov_iter *i, size_t size, 4998cefc107SDavid Howells int *iter_headp, size_t *offp) 500241699cdSAl Viro { 501241699cdSAl Viro struct pipe_inode_info *pipe = i->pipe; 5028cefc107SDavid Howells unsigned int p_tail = pipe->tail; 5038cefc107SDavid Howells unsigned int p_mask = pipe->ring_size - 1; 5048cefc107SDavid Howells unsigned int iter_head; 505241699cdSAl Viro size_t off; 506241699cdSAl Viro ssize_t left; 507241699cdSAl Viro 508241699cdSAl Viro if (unlikely(size > i->count)) 509241699cdSAl Viro size = i->count; 510241699cdSAl Viro if (unlikely(!size)) 511241699cdSAl Viro return 0; 512241699cdSAl Viro 513241699cdSAl Viro left = size; 5148cefc107SDavid Howells data_start(i, &iter_head, &off); 5158cefc107SDavid Howells *iter_headp = iter_head; 516241699cdSAl Viro *offp = off; 517241699cdSAl Viro if (off) { 518241699cdSAl Viro left -= PAGE_SIZE - off; 519241699cdSAl Viro if (left <= 0) { 5208cefc107SDavid Howells pipe->bufs[iter_head & p_mask].len += size; 521241699cdSAl Viro return size; 522241699cdSAl Viro } 5238cefc107SDavid Howells pipe->bufs[iter_head & p_mask].len = PAGE_SIZE; 5248cefc107SDavid Howells iter_head++; 525241699cdSAl Viro } 5266718b6f8SDavid Howells while (!pipe_full(iter_head, p_tail, pipe->max_usage)) { 5278cefc107SDavid Howells struct pipe_buffer *buf = &pipe->bufs[iter_head & p_mask]; 528241699cdSAl Viro struct page *page = alloc_page(GFP_USER); 529241699cdSAl Viro if (!page) 530241699cdSAl Viro break; 5318cefc107SDavid Howells 5328cefc107SDavid Howells buf->ops = &default_pipe_buf_ops; 5338cefc107SDavid Howells buf->page = page; 5348cefc107SDavid Howells buf->offset = 0; 5358cefc107SDavid Howells buf->len = min_t(ssize_t, left, PAGE_SIZE); 5368cefc107SDavid Howells left -= buf->len; 5378cefc107SDavid Howells iter_head++; 5388cefc107SDavid Howells pipe->head = iter_head; 5398cefc107SDavid Howells 5408cefc107SDavid Howells if (left == 0) 541241699cdSAl Viro return size; 542241699cdSAl Viro } 543241699cdSAl Viro return size - left; 544241699cdSAl Viro } 545241699cdSAl Viro 546241699cdSAl Viro static size_t copy_pipe_to_iter(const void *addr, size_t bytes, 547241699cdSAl Viro struct iov_iter *i) 548241699cdSAl Viro { 549241699cdSAl Viro struct pipe_inode_info *pipe = i->pipe; 5508cefc107SDavid Howells unsigned int p_mask = pipe->ring_size - 1; 5518cefc107SDavid Howells unsigned int i_head; 552241699cdSAl Viro size_t n, off; 553241699cdSAl Viro 554241699cdSAl Viro if (!sanity(i)) 555241699cdSAl Viro return 0; 556241699cdSAl Viro 5578cefc107SDavid Howells bytes = n = push_pipe(i, bytes, &i_head, &off); 558241699cdSAl Viro if (unlikely(!n)) 559241699cdSAl Viro return 0; 5608cefc107SDavid Howells do { 561241699cdSAl Viro size_t chunk = min_t(size_t, n, PAGE_SIZE - off); 5628cefc107SDavid Howells memcpy_to_page(pipe->bufs[i_head & p_mask].page, off, addr, chunk); 5638cefc107SDavid Howells i->head = i_head; 564241699cdSAl Viro i->iov_offset = off + chunk; 565241699cdSAl Viro n -= chunk; 566241699cdSAl Viro addr += chunk; 5678cefc107SDavid Howells off = 0; 5688cefc107SDavid Howells i_head++; 5698cefc107SDavid Howells } while (n); 570241699cdSAl Viro i->count -= bytes; 571241699cdSAl Viro return bytes; 572241699cdSAl Viro } 573241699cdSAl Viro 574f9152895SAl Viro static __wsum csum_and_memcpy(void *to, const void *from, size_t len, 575f9152895SAl Viro __wsum sum, size_t off) 576f9152895SAl Viro { 577cc44c17bSAl Viro __wsum next = csum_partial_copy_nocheck(from, to, len); 578f9152895SAl Viro return csum_block_add(sum, next, off); 579f9152895SAl Viro } 580f9152895SAl Viro 58178e1f386SAl Viro static size_t csum_and_copy_to_pipe_iter(const void *addr, size_t bytes, 5826852df12SAl Viro struct iov_iter *i, __wsum *sump) 58378e1f386SAl Viro { 58478e1f386SAl Viro struct pipe_inode_info *pipe = i->pipe; 5858cefc107SDavid Howells unsigned int p_mask = pipe->ring_size - 1; 5866852df12SAl Viro __wsum sum = *sump; 5876852df12SAl Viro size_t off = 0; 5888cefc107SDavid Howells unsigned int i_head; 5896852df12SAl Viro size_t r; 59078e1f386SAl Viro 59178e1f386SAl Viro if (!sanity(i)) 59278e1f386SAl Viro return 0; 59378e1f386SAl Viro 5946852df12SAl Viro bytes = push_pipe(i, bytes, &i_head, &r); 5956852df12SAl Viro while (bytes) { 5966852df12SAl Viro size_t chunk = min_t(size_t, bytes, PAGE_SIZE - r); 5972495bdccSAl Viro char *p = kmap_local_page(pipe->bufs[i_head & p_mask].page); 5986852df12SAl Viro sum = csum_and_memcpy(p + r, addr + off, chunk, sum, off); 5992495bdccSAl Viro kunmap_local(p); 6008cefc107SDavid Howells i->head = i_head; 60178e1f386SAl Viro i->iov_offset = r + chunk; 6026852df12SAl Viro bytes -= chunk; 60378e1f386SAl Viro off += chunk; 6048cefc107SDavid Howells r = 0; 6058cefc107SDavid Howells i_head++; 6066852df12SAl Viro } 6076852df12SAl Viro *sump = sum; 6086852df12SAl Viro i->count -= off; 6096852df12SAl Viro return off; 61078e1f386SAl Viro } 61178e1f386SAl Viro 612aa28de27SAl Viro size_t _copy_to_iter(const void *addr, size_t bytes, struct iov_iter *i) 613d879cb83SAl Viro { 61400e23707SDavid Howells if (unlikely(iov_iter_is_pipe(i))) 615241699cdSAl Viro return copy_pipe_to_iter(addr, bytes, i); 61609fc68dcSAl Viro if (iter_is_iovec(i)) 61709fc68dcSAl Viro might_fault(); 6187baa5099SAl Viro iterate_and_advance(i, bytes, base, len, off, 6197baa5099SAl Viro copyout(base, addr + off, len), 6207baa5099SAl Viro memcpy(base, addr + off, len) 621d879cb83SAl Viro ) 622d879cb83SAl Viro 623d879cb83SAl Viro return bytes; 624d879cb83SAl Viro } 625aa28de27SAl Viro EXPORT_SYMBOL(_copy_to_iter); 626d879cb83SAl Viro 627ec6347bbSDan Williams #ifdef CONFIG_ARCH_HAS_COPY_MC 628ec6347bbSDan Williams static int copyout_mc(void __user *to, const void *from, size_t n) 6298780356eSDan Williams { 63096d4f267SLinus Torvalds if (access_ok(to, n)) { 631d0ef4c36SMarco Elver instrument_copy_to_user(to, from, n); 632ec6347bbSDan Williams n = copy_mc_to_user((__force void *) to, from, n); 6338780356eSDan Williams } 6348780356eSDan Williams return n; 6358780356eSDan Williams } 6368780356eSDan Williams 637ec6347bbSDan Williams static size_t copy_mc_pipe_to_iter(const void *addr, size_t bytes, 638ca146f6fSDan Williams struct iov_iter *i) 639ca146f6fSDan Williams { 640ca146f6fSDan Williams struct pipe_inode_info *pipe = i->pipe; 6418cefc107SDavid Howells unsigned int p_mask = pipe->ring_size - 1; 6428cefc107SDavid Howells unsigned int i_head; 643ca146f6fSDan Williams size_t n, off, xfer = 0; 644ca146f6fSDan Williams 645ca146f6fSDan Williams if (!sanity(i)) 646ca146f6fSDan Williams return 0; 647ca146f6fSDan Williams 6482a510a74SAl Viro n = push_pipe(i, bytes, &i_head, &off); 6492a510a74SAl Viro while (n) { 650ca146f6fSDan Williams size_t chunk = min_t(size_t, n, PAGE_SIZE - off); 6512a510a74SAl Viro char *p = kmap_local_page(pipe->bufs[i_head & p_mask].page); 652ca146f6fSDan Williams unsigned long rem; 6532a510a74SAl Viro rem = copy_mc_to_kernel(p + off, addr + xfer, chunk); 6542a510a74SAl Viro chunk -= rem; 6552a510a74SAl Viro kunmap_local(p); 6568cefc107SDavid Howells i->head = i_head; 6572a510a74SAl Viro i->iov_offset = off + chunk; 6582a510a74SAl Viro xfer += chunk; 659ca146f6fSDan Williams if (rem) 660ca146f6fSDan Williams break; 661ca146f6fSDan Williams n -= chunk; 6628cefc107SDavid Howells off = 0; 6638cefc107SDavid Howells i_head++; 6642a510a74SAl Viro } 665ca146f6fSDan Williams i->count -= xfer; 666ca146f6fSDan Williams return xfer; 667ca146f6fSDan Williams } 668ca146f6fSDan Williams 669bf3eeb9bSDan Williams /** 670ec6347bbSDan Williams * _copy_mc_to_iter - copy to iter with source memory error exception handling 671bf3eeb9bSDan Williams * @addr: source kernel address 672bf3eeb9bSDan Williams * @bytes: total transfer length 67344e55997SRandy Dunlap * @i: destination iterator 674bf3eeb9bSDan Williams * 675ec6347bbSDan Williams * The pmem driver deploys this for the dax operation 676ec6347bbSDan Williams * (dax_copy_to_iter()) for dax reads (bypass page-cache and the 677ec6347bbSDan Williams * block-layer). Upon #MC read(2) aborts and returns EIO or the bytes 678ec6347bbSDan Williams * successfully copied. 679bf3eeb9bSDan Williams * 680ec6347bbSDan Williams * The main differences between this and typical _copy_to_iter(). 681bf3eeb9bSDan Williams * 682bf3eeb9bSDan Williams * * Typical tail/residue handling after a fault retries the copy 683bf3eeb9bSDan Williams * byte-by-byte until the fault happens again. Re-triggering machine 684bf3eeb9bSDan Williams * checks is potentially fatal so the implementation uses source 685bf3eeb9bSDan Williams * alignment and poison alignment assumptions to avoid re-triggering 686bf3eeb9bSDan Williams * hardware exceptions. 687bf3eeb9bSDan Williams * 688bf3eeb9bSDan Williams * * ITER_KVEC, ITER_PIPE, and ITER_BVEC can return short copies. 689bf3eeb9bSDan Williams * Compare to copy_to_iter() where only ITER_IOVEC attempts might return 690bf3eeb9bSDan Williams * a short copy. 69144e55997SRandy Dunlap * 69244e55997SRandy Dunlap * Return: number of bytes copied (may be %0) 693bf3eeb9bSDan Williams */ 694ec6347bbSDan Williams size_t _copy_mc_to_iter(const void *addr, size_t bytes, struct iov_iter *i) 6958780356eSDan Williams { 69600e23707SDavid Howells if (unlikely(iov_iter_is_pipe(i))) 697ec6347bbSDan Williams return copy_mc_pipe_to_iter(addr, bytes, i); 6988780356eSDan Williams if (iter_is_iovec(i)) 6998780356eSDan Williams might_fault(); 7007baa5099SAl Viro __iterate_and_advance(i, bytes, base, len, off, 7017baa5099SAl Viro copyout_mc(base, addr + off, len), 7027baa5099SAl Viro copy_mc_to_kernel(base, addr + off, len) 7038780356eSDan Williams ) 7048780356eSDan Williams 7058780356eSDan Williams return bytes; 7068780356eSDan Williams } 707ec6347bbSDan Williams EXPORT_SYMBOL_GPL(_copy_mc_to_iter); 708ec6347bbSDan Williams #endif /* CONFIG_ARCH_HAS_COPY_MC */ 7098780356eSDan Williams 710aa28de27SAl Viro size_t _copy_from_iter(void *addr, size_t bytes, struct iov_iter *i) 711d879cb83SAl Viro { 71200e23707SDavid Howells if (unlikely(iov_iter_is_pipe(i))) { 713241699cdSAl Viro WARN_ON(1); 714241699cdSAl Viro return 0; 715241699cdSAl Viro } 71609fc68dcSAl Viro if (iter_is_iovec(i)) 71709fc68dcSAl Viro might_fault(); 7187baa5099SAl Viro iterate_and_advance(i, bytes, base, len, off, 7197baa5099SAl Viro copyin(addr + off, base, len), 7207baa5099SAl Viro memcpy(addr + off, base, len) 721d879cb83SAl Viro ) 722d879cb83SAl Viro 723d879cb83SAl Viro return bytes; 724d879cb83SAl Viro } 725aa28de27SAl Viro EXPORT_SYMBOL(_copy_from_iter); 726d879cb83SAl Viro 727aa28de27SAl Viro size_t _copy_from_iter_nocache(void *addr, size_t bytes, struct iov_iter *i) 728d879cb83SAl Viro { 72900e23707SDavid Howells if (unlikely(iov_iter_is_pipe(i))) { 730241699cdSAl Viro WARN_ON(1); 731241699cdSAl Viro return 0; 732241699cdSAl Viro } 7337baa5099SAl Viro iterate_and_advance(i, bytes, base, len, off, 7347baa5099SAl Viro __copy_from_user_inatomic_nocache(addr + off, base, len), 7357baa5099SAl Viro memcpy(addr + off, base, len) 736d879cb83SAl Viro ) 737d879cb83SAl Viro 738d879cb83SAl Viro return bytes; 739d879cb83SAl Viro } 740aa28de27SAl Viro EXPORT_SYMBOL(_copy_from_iter_nocache); 741d879cb83SAl Viro 7420aed55afSDan Williams #ifdef CONFIG_ARCH_HAS_UACCESS_FLUSHCACHE 743abd08d7dSDan Williams /** 744abd08d7dSDan Williams * _copy_from_iter_flushcache - write destination through cpu cache 745abd08d7dSDan Williams * @addr: destination kernel address 746abd08d7dSDan Williams * @bytes: total transfer length 74744e55997SRandy Dunlap * @i: source iterator 748abd08d7dSDan Williams * 749abd08d7dSDan Williams * The pmem driver arranges for filesystem-dax to use this facility via 750abd08d7dSDan Williams * dax_copy_from_iter() for ensuring that writes to persistent memory 751abd08d7dSDan Williams * are flushed through the CPU cache. It is differentiated from 752abd08d7dSDan Williams * _copy_from_iter_nocache() in that guarantees all data is flushed for 753abd08d7dSDan Williams * all iterator types. The _copy_from_iter_nocache() only attempts to 754abd08d7dSDan Williams * bypass the cache for the ITER_IOVEC case, and on some archs may use 755abd08d7dSDan Williams * instructions that strand dirty-data in the cache. 75644e55997SRandy Dunlap * 75744e55997SRandy Dunlap * Return: number of bytes copied (may be %0) 758abd08d7dSDan Williams */ 7596a37e940SLinus Torvalds size_t _copy_from_iter_flushcache(void *addr, size_t bytes, struct iov_iter *i) 7600aed55afSDan Williams { 76100e23707SDavid Howells if (unlikely(iov_iter_is_pipe(i))) { 7620aed55afSDan Williams WARN_ON(1); 7630aed55afSDan Williams return 0; 7640aed55afSDan Williams } 7657baa5099SAl Viro iterate_and_advance(i, bytes, base, len, off, 7667baa5099SAl Viro __copy_from_user_flushcache(addr + off, base, len), 7677baa5099SAl Viro memcpy_flushcache(addr + off, base, len) 7680aed55afSDan Williams ) 7690aed55afSDan Williams 7700aed55afSDan Williams return bytes; 7710aed55afSDan Williams } 7726a37e940SLinus Torvalds EXPORT_SYMBOL_GPL(_copy_from_iter_flushcache); 7730aed55afSDan Williams #endif 7740aed55afSDan Williams 77572e809edSAl Viro static inline bool page_copy_sane(struct page *page, size_t offset, size_t n) 77672e809edSAl Viro { 7776daef95bSEric Dumazet struct page *head; 7786daef95bSEric Dumazet size_t v = n + offset; 7796daef95bSEric Dumazet 7806daef95bSEric Dumazet /* 7816daef95bSEric Dumazet * The general case needs to access the page order in order 7826daef95bSEric Dumazet * to compute the page size. 7836daef95bSEric Dumazet * However, we mostly deal with order-0 pages and thus can 7846daef95bSEric Dumazet * avoid a possible cache line miss for requests that fit all 7856daef95bSEric Dumazet * page orders. 7866daef95bSEric Dumazet */ 7876daef95bSEric Dumazet if (n <= v && v <= PAGE_SIZE) 7886daef95bSEric Dumazet return true; 7896daef95bSEric Dumazet 7906daef95bSEric Dumazet head = compound_head(page); 7916daef95bSEric Dumazet v += (page - head) << PAGE_SHIFT; 792a90bcb86SPetar Penkov 793a50b854eSMatthew Wilcox (Oracle) if (likely(n <= v && v <= (page_size(head)))) 79472e809edSAl Viro return true; 79572e809edSAl Viro WARN_ON(1); 79672e809edSAl Viro return false; 79772e809edSAl Viro } 798cbbd26b8SAl Viro 79908aa6479SAl Viro static size_t __copy_page_to_iter(struct page *page, size_t offset, size_t bytes, 800d879cb83SAl Viro struct iov_iter *i) 801d879cb83SAl Viro { 80228f38db7SAl Viro if (likely(iter_is_iovec(i))) 80328f38db7SAl Viro return copy_page_to_iter_iovec(page, offset, bytes, i); 80428f38db7SAl Viro if (iov_iter_is_bvec(i) || iov_iter_is_kvec(i) || iov_iter_is_xarray(i)) { 805c1d4d6a9SAl Viro void *kaddr = kmap_local_page(page); 806c1d4d6a9SAl Viro size_t wanted = _copy_to_iter(kaddr + offset, bytes, i); 807c1d4d6a9SAl Viro kunmap_local(kaddr); 808d879cb83SAl Viro return wanted; 80928f38db7SAl Viro } 81028f38db7SAl Viro if (iov_iter_is_pipe(i)) 81128f38db7SAl Viro return copy_page_to_iter_pipe(page, offset, bytes, i); 81228f38db7SAl Viro if (unlikely(iov_iter_is_discard(i))) { 813a506abc7SAl Viro if (unlikely(i->count < bytes)) 814a506abc7SAl Viro bytes = i->count; 815a506abc7SAl Viro i->count -= bytes; 8169ea9ce04SDavid Howells return bytes; 81728f38db7SAl Viro } 81828f38db7SAl Viro WARN_ON(1); 81928f38db7SAl Viro return 0; 820d879cb83SAl Viro } 82108aa6479SAl Viro 82208aa6479SAl Viro size_t copy_page_to_iter(struct page *page, size_t offset, size_t bytes, 82308aa6479SAl Viro struct iov_iter *i) 82408aa6479SAl Viro { 82508aa6479SAl Viro size_t res = 0; 82608aa6479SAl Viro if (unlikely(!page_copy_sane(page, offset, bytes))) 82708aa6479SAl Viro return 0; 82808aa6479SAl Viro page += offset / PAGE_SIZE; // first subpage 82908aa6479SAl Viro offset %= PAGE_SIZE; 83008aa6479SAl Viro while (1) { 83108aa6479SAl Viro size_t n = __copy_page_to_iter(page, offset, 83208aa6479SAl Viro min(bytes, (size_t)PAGE_SIZE - offset), i); 83308aa6479SAl Viro res += n; 83408aa6479SAl Viro bytes -= n; 83508aa6479SAl Viro if (!bytes || !n) 83608aa6479SAl Viro break; 83708aa6479SAl Viro offset += n; 83808aa6479SAl Viro if (offset == PAGE_SIZE) { 83908aa6479SAl Viro page++; 84008aa6479SAl Viro offset = 0; 84108aa6479SAl Viro } 84208aa6479SAl Viro } 84308aa6479SAl Viro return res; 84408aa6479SAl Viro } 845d879cb83SAl Viro EXPORT_SYMBOL(copy_page_to_iter); 846d879cb83SAl Viro 847d879cb83SAl Viro size_t copy_page_from_iter(struct page *page, size_t offset, size_t bytes, 848d879cb83SAl Viro struct iov_iter *i) 849d879cb83SAl Viro { 85072e809edSAl Viro if (unlikely(!page_copy_sane(page, offset, bytes))) 85172e809edSAl Viro return 0; 85228f38db7SAl Viro if (likely(iter_is_iovec(i))) 85328f38db7SAl Viro return copy_page_from_iter_iovec(page, offset, bytes, i); 85428f38db7SAl Viro if (iov_iter_is_bvec(i) || iov_iter_is_kvec(i) || iov_iter_is_xarray(i)) { 85555ca375cSAl Viro void *kaddr = kmap_local_page(page); 856aa28de27SAl Viro size_t wanted = _copy_from_iter(kaddr + offset, bytes, i); 85755ca375cSAl Viro kunmap_local(kaddr); 858d879cb83SAl Viro return wanted; 85928f38db7SAl Viro } 86028f38db7SAl Viro WARN_ON(1); 86128f38db7SAl Viro return 0; 862d879cb83SAl Viro } 863d879cb83SAl Viro EXPORT_SYMBOL(copy_page_from_iter); 864d879cb83SAl Viro 865241699cdSAl Viro static size_t pipe_zero(size_t bytes, struct iov_iter *i) 866241699cdSAl Viro { 867241699cdSAl Viro struct pipe_inode_info *pipe = i->pipe; 8688cefc107SDavid Howells unsigned int p_mask = pipe->ring_size - 1; 8698cefc107SDavid Howells unsigned int i_head; 870241699cdSAl Viro size_t n, off; 871241699cdSAl Viro 872241699cdSAl Viro if (!sanity(i)) 873241699cdSAl Viro return 0; 874241699cdSAl Viro 8758cefc107SDavid Howells bytes = n = push_pipe(i, bytes, &i_head, &off); 876241699cdSAl Viro if (unlikely(!n)) 877241699cdSAl Viro return 0; 878241699cdSAl Viro 8798cefc107SDavid Howells do { 880241699cdSAl Viro size_t chunk = min_t(size_t, n, PAGE_SIZE - off); 881893839fdSAl Viro char *p = kmap_local_page(pipe->bufs[i_head & p_mask].page); 882893839fdSAl Viro memset(p + off, 0, chunk); 883893839fdSAl Viro kunmap_local(p); 8848cefc107SDavid Howells i->head = i_head; 885241699cdSAl Viro i->iov_offset = off + chunk; 886241699cdSAl Viro n -= chunk; 8878cefc107SDavid Howells off = 0; 8888cefc107SDavid Howells i_head++; 8898cefc107SDavid Howells } while (n); 890241699cdSAl Viro i->count -= bytes; 891241699cdSAl Viro return bytes; 892241699cdSAl Viro } 893241699cdSAl Viro 894d879cb83SAl Viro size_t iov_iter_zero(size_t bytes, struct iov_iter *i) 895d879cb83SAl Viro { 89600e23707SDavid Howells if (unlikely(iov_iter_is_pipe(i))) 897241699cdSAl Viro return pipe_zero(bytes, i); 8987baa5099SAl Viro iterate_and_advance(i, bytes, base, len, count, 8997baa5099SAl Viro clear_user(base, len), 9007baa5099SAl Viro memset(base, 0, len) 901d879cb83SAl Viro ) 902d879cb83SAl Viro 903d879cb83SAl Viro return bytes; 904d879cb83SAl Viro } 905d879cb83SAl Viro EXPORT_SYMBOL(iov_iter_zero); 906d879cb83SAl Viro 907f0b65f39SAl Viro size_t copy_page_from_iter_atomic(struct page *page, unsigned offset, size_t bytes, 908f0b65f39SAl Viro struct iov_iter *i) 909d879cb83SAl Viro { 910d879cb83SAl Viro char *kaddr = kmap_atomic(page), *p = kaddr + offset; 91172e809edSAl Viro if (unlikely(!page_copy_sane(page, offset, bytes))) { 91272e809edSAl Viro kunmap_atomic(kaddr); 91372e809edSAl Viro return 0; 91472e809edSAl Viro } 9159ea9ce04SDavid Howells if (unlikely(iov_iter_is_pipe(i) || iov_iter_is_discard(i))) { 916241699cdSAl Viro kunmap_atomic(kaddr); 917241699cdSAl Viro WARN_ON(1); 918241699cdSAl Viro return 0; 919241699cdSAl Viro } 9207baa5099SAl Viro iterate_and_advance(i, bytes, base, len, off, 9217baa5099SAl Viro copyin(p + off, base, len), 9227baa5099SAl Viro memcpy(p + off, base, len) 923d879cb83SAl Viro ) 924d879cb83SAl Viro kunmap_atomic(kaddr); 925d879cb83SAl Viro return bytes; 926d879cb83SAl Viro } 927f0b65f39SAl Viro EXPORT_SYMBOL(copy_page_from_iter_atomic); 928d879cb83SAl Viro 929b9dc6f65SAl Viro static inline void pipe_truncate(struct iov_iter *i) 930241699cdSAl Viro { 931241699cdSAl Viro struct pipe_inode_info *pipe = i->pipe; 9328cefc107SDavid Howells unsigned int p_tail = pipe->tail; 9338cefc107SDavid Howells unsigned int p_head = pipe->head; 9348cefc107SDavid Howells unsigned int p_mask = pipe->ring_size - 1; 9358cefc107SDavid Howells 9368cefc107SDavid Howells if (!pipe_empty(p_head, p_tail)) { 9378cefc107SDavid Howells struct pipe_buffer *buf; 9388cefc107SDavid Howells unsigned int i_head = i->head; 939b9dc6f65SAl Viro size_t off = i->iov_offset; 9408cefc107SDavid Howells 941b9dc6f65SAl Viro if (off) { 9428cefc107SDavid Howells buf = &pipe->bufs[i_head & p_mask]; 9438cefc107SDavid Howells buf->len = off - buf->offset; 9448cefc107SDavid Howells i_head++; 945b9dc6f65SAl Viro } 9468cefc107SDavid Howells while (p_head != i_head) { 9478cefc107SDavid Howells p_head--; 9488cefc107SDavid Howells pipe_buf_release(pipe, &pipe->bufs[p_head & p_mask]); 949241699cdSAl Viro } 9508cefc107SDavid Howells 9518cefc107SDavid Howells pipe->head = p_head; 952241699cdSAl Viro } 953b9dc6f65SAl Viro } 954b9dc6f65SAl Viro 955b9dc6f65SAl Viro static void pipe_advance(struct iov_iter *i, size_t size) 956b9dc6f65SAl Viro { 957b9dc6f65SAl Viro struct pipe_inode_info *pipe = i->pipe; 958b9dc6f65SAl Viro if (size) { 959b9dc6f65SAl Viro struct pipe_buffer *buf; 9608cefc107SDavid Howells unsigned int p_mask = pipe->ring_size - 1; 9618cefc107SDavid Howells unsigned int i_head = i->head; 962b9dc6f65SAl Viro size_t off = i->iov_offset, left = size; 9638cefc107SDavid Howells 964b9dc6f65SAl Viro if (off) /* make it relative to the beginning of buffer */ 9658cefc107SDavid Howells left += off - pipe->bufs[i_head & p_mask].offset; 966b9dc6f65SAl Viro while (1) { 9678cefc107SDavid Howells buf = &pipe->bufs[i_head & p_mask]; 968b9dc6f65SAl Viro if (left <= buf->len) 969b9dc6f65SAl Viro break; 970b9dc6f65SAl Viro left -= buf->len; 9718cefc107SDavid Howells i_head++; 972b9dc6f65SAl Viro } 9738cefc107SDavid Howells i->head = i_head; 974b9dc6f65SAl Viro i->iov_offset = buf->offset + left; 975b9dc6f65SAl Viro } 976b9dc6f65SAl Viro i->count -= size; 977b9dc6f65SAl Viro /* ... and discard everything past that point */ 978b9dc6f65SAl Viro pipe_truncate(i); 979241699cdSAl Viro } 980241699cdSAl Viro 98154c8195bSPavel Begunkov static void iov_iter_bvec_advance(struct iov_iter *i, size_t size) 98254c8195bSPavel Begunkov { 98354c8195bSPavel Begunkov struct bvec_iter bi; 98454c8195bSPavel Begunkov 98554c8195bSPavel Begunkov bi.bi_size = i->count; 98654c8195bSPavel Begunkov bi.bi_bvec_done = i->iov_offset; 98754c8195bSPavel Begunkov bi.bi_idx = 0; 98854c8195bSPavel Begunkov bvec_iter_advance(i->bvec, &bi, size); 98954c8195bSPavel Begunkov 99054c8195bSPavel Begunkov i->bvec += bi.bi_idx; 99154c8195bSPavel Begunkov i->nr_segs -= bi.bi_idx; 99254c8195bSPavel Begunkov i->count = bi.bi_size; 99354c8195bSPavel Begunkov i->iov_offset = bi.bi_bvec_done; 99454c8195bSPavel Begunkov } 99554c8195bSPavel Begunkov 996185ac4d4SAl Viro static void iov_iter_iovec_advance(struct iov_iter *i, size_t size) 997185ac4d4SAl Viro { 998185ac4d4SAl Viro const struct iovec *iov, *end; 999185ac4d4SAl Viro 1000185ac4d4SAl Viro if (!i->count) 1001185ac4d4SAl Viro return; 1002185ac4d4SAl Viro i->count -= size; 1003185ac4d4SAl Viro 1004185ac4d4SAl Viro size += i->iov_offset; // from beginning of current segment 1005185ac4d4SAl Viro for (iov = i->iov, end = iov + i->nr_segs; iov < end; iov++) { 1006185ac4d4SAl Viro if (likely(size < iov->iov_len)) 1007185ac4d4SAl Viro break; 1008185ac4d4SAl Viro size -= iov->iov_len; 1009185ac4d4SAl Viro } 1010185ac4d4SAl Viro i->iov_offset = size; 1011185ac4d4SAl Viro i->nr_segs -= iov - i->iov; 1012185ac4d4SAl Viro i->iov = iov; 1013185ac4d4SAl Viro } 1014185ac4d4SAl Viro 1015d879cb83SAl Viro void iov_iter_advance(struct iov_iter *i, size_t size) 1016d879cb83SAl Viro { 10173b3fc051SAl Viro if (unlikely(i->count < size)) 10183b3fc051SAl Viro size = i->count; 1019185ac4d4SAl Viro if (likely(iter_is_iovec(i) || iov_iter_is_kvec(i))) { 1020185ac4d4SAl Viro /* iovec and kvec have identical layouts */ 1021185ac4d4SAl Viro iov_iter_iovec_advance(i, size); 1022185ac4d4SAl Viro } else if (iov_iter_is_bvec(i)) { 1023185ac4d4SAl Viro iov_iter_bvec_advance(i, size); 1024185ac4d4SAl Viro } else if (iov_iter_is_pipe(i)) { 1025241699cdSAl Viro pipe_advance(i, size); 1026185ac4d4SAl Viro } else if (unlikely(iov_iter_is_xarray(i))) { 10277ff50620SDavid Howells i->iov_offset += size; 10287ff50620SDavid Howells i->count -= size; 1029185ac4d4SAl Viro } else if (iov_iter_is_discard(i)) { 1030185ac4d4SAl Viro i->count -= size; 10317ff50620SDavid Howells } 1032d879cb83SAl Viro } 1033d879cb83SAl Viro EXPORT_SYMBOL(iov_iter_advance); 1034d879cb83SAl Viro 103527c0e374SAl Viro void iov_iter_revert(struct iov_iter *i, size_t unroll) 103627c0e374SAl Viro { 103727c0e374SAl Viro if (!unroll) 103827c0e374SAl Viro return; 10395b47d59aSAl Viro if (WARN_ON(unroll > MAX_RW_COUNT)) 10405b47d59aSAl Viro return; 104127c0e374SAl Viro i->count += unroll; 104200e23707SDavid Howells if (unlikely(iov_iter_is_pipe(i))) { 104327c0e374SAl Viro struct pipe_inode_info *pipe = i->pipe; 10448cefc107SDavid Howells unsigned int p_mask = pipe->ring_size - 1; 10458cefc107SDavid Howells unsigned int i_head = i->head; 104627c0e374SAl Viro size_t off = i->iov_offset; 104727c0e374SAl Viro while (1) { 10488cefc107SDavid Howells struct pipe_buffer *b = &pipe->bufs[i_head & p_mask]; 10498cefc107SDavid Howells size_t n = off - b->offset; 105027c0e374SAl Viro if (unroll < n) { 10514fa55cefSAl Viro off -= unroll; 105227c0e374SAl Viro break; 105327c0e374SAl Viro } 105427c0e374SAl Viro unroll -= n; 10558cefc107SDavid Howells if (!unroll && i_head == i->start_head) { 105627c0e374SAl Viro off = 0; 105727c0e374SAl Viro break; 105827c0e374SAl Viro } 10598cefc107SDavid Howells i_head--; 10608cefc107SDavid Howells b = &pipe->bufs[i_head & p_mask]; 10618cefc107SDavid Howells off = b->offset + b->len; 106227c0e374SAl Viro } 106327c0e374SAl Viro i->iov_offset = off; 10648cefc107SDavid Howells i->head = i_head; 106527c0e374SAl Viro pipe_truncate(i); 106627c0e374SAl Viro return; 106727c0e374SAl Viro } 10689ea9ce04SDavid Howells if (unlikely(iov_iter_is_discard(i))) 10699ea9ce04SDavid Howells return; 107027c0e374SAl Viro if (unroll <= i->iov_offset) { 107127c0e374SAl Viro i->iov_offset -= unroll; 107227c0e374SAl Viro return; 107327c0e374SAl Viro } 107427c0e374SAl Viro unroll -= i->iov_offset; 10757ff50620SDavid Howells if (iov_iter_is_xarray(i)) { 10767ff50620SDavid Howells BUG(); /* We should never go beyond the start of the specified 10777ff50620SDavid Howells * range since we might then be straying into pages that 10787ff50620SDavid Howells * aren't pinned. 10797ff50620SDavid Howells */ 10807ff50620SDavid Howells } else if (iov_iter_is_bvec(i)) { 108127c0e374SAl Viro const struct bio_vec *bvec = i->bvec; 108227c0e374SAl Viro while (1) { 108327c0e374SAl Viro size_t n = (--bvec)->bv_len; 108427c0e374SAl Viro i->nr_segs++; 108527c0e374SAl Viro if (unroll <= n) { 108627c0e374SAl Viro i->bvec = bvec; 108727c0e374SAl Viro i->iov_offset = n - unroll; 108827c0e374SAl Viro return; 108927c0e374SAl Viro } 109027c0e374SAl Viro unroll -= n; 109127c0e374SAl Viro } 109227c0e374SAl Viro } else { /* same logics for iovec and kvec */ 109327c0e374SAl Viro const struct iovec *iov = i->iov; 109427c0e374SAl Viro while (1) { 109527c0e374SAl Viro size_t n = (--iov)->iov_len; 109627c0e374SAl Viro i->nr_segs++; 109727c0e374SAl Viro if (unroll <= n) { 109827c0e374SAl Viro i->iov = iov; 109927c0e374SAl Viro i->iov_offset = n - unroll; 110027c0e374SAl Viro return; 110127c0e374SAl Viro } 110227c0e374SAl Viro unroll -= n; 110327c0e374SAl Viro } 110427c0e374SAl Viro } 110527c0e374SAl Viro } 110627c0e374SAl Viro EXPORT_SYMBOL(iov_iter_revert); 110727c0e374SAl Viro 1108d879cb83SAl Viro /* 1109d879cb83SAl Viro * Return the count of just the current iov_iter segment. 1110d879cb83SAl Viro */ 1111d879cb83SAl Viro size_t iov_iter_single_seg_count(const struct iov_iter *i) 1112d879cb83SAl Viro { 111328f38db7SAl Viro if (i->nr_segs > 1) { 111428f38db7SAl Viro if (likely(iter_is_iovec(i) || iov_iter_is_kvec(i))) 111528f38db7SAl Viro return min(i->count, i->iov->iov_len - i->iov_offset); 11167ff50620SDavid Howells if (iov_iter_is_bvec(i)) 1117d879cb83SAl Viro return min(i->count, i->bvec->bv_len - i->iov_offset); 111828f38db7SAl Viro } 111928f38db7SAl Viro return i->count; 1120d879cb83SAl Viro } 1121d879cb83SAl Viro EXPORT_SYMBOL(iov_iter_single_seg_count); 1122d879cb83SAl Viro 1123aa563d7bSDavid Howells void iov_iter_kvec(struct iov_iter *i, unsigned int direction, 1124d879cb83SAl Viro const struct kvec *kvec, unsigned long nr_segs, 1125d879cb83SAl Viro size_t count) 1126d879cb83SAl Viro { 1127aa563d7bSDavid Howells WARN_ON(direction & ~(READ | WRITE)); 11288cd54c1cSAl Viro *i = (struct iov_iter){ 11298cd54c1cSAl Viro .iter_type = ITER_KVEC, 11308cd54c1cSAl Viro .data_source = direction, 11318cd54c1cSAl Viro .kvec = kvec, 11328cd54c1cSAl Viro .nr_segs = nr_segs, 11338cd54c1cSAl Viro .iov_offset = 0, 11348cd54c1cSAl Viro .count = count 11358cd54c1cSAl Viro }; 1136d879cb83SAl Viro } 1137d879cb83SAl Viro EXPORT_SYMBOL(iov_iter_kvec); 1138d879cb83SAl Viro 1139aa563d7bSDavid Howells void iov_iter_bvec(struct iov_iter *i, unsigned int direction, 1140d879cb83SAl Viro const struct bio_vec *bvec, unsigned long nr_segs, 1141d879cb83SAl Viro size_t count) 1142d879cb83SAl Viro { 1143aa563d7bSDavid Howells WARN_ON(direction & ~(READ | WRITE)); 11448cd54c1cSAl Viro *i = (struct iov_iter){ 11458cd54c1cSAl Viro .iter_type = ITER_BVEC, 11468cd54c1cSAl Viro .data_source = direction, 11478cd54c1cSAl Viro .bvec = bvec, 11488cd54c1cSAl Viro .nr_segs = nr_segs, 11498cd54c1cSAl Viro .iov_offset = 0, 11508cd54c1cSAl Viro .count = count 11518cd54c1cSAl Viro }; 1152d879cb83SAl Viro } 1153d879cb83SAl Viro EXPORT_SYMBOL(iov_iter_bvec); 1154d879cb83SAl Viro 1155aa563d7bSDavid Howells void iov_iter_pipe(struct iov_iter *i, unsigned int direction, 1156241699cdSAl Viro struct pipe_inode_info *pipe, 1157241699cdSAl Viro size_t count) 1158241699cdSAl Viro { 1159aa563d7bSDavid Howells BUG_ON(direction != READ); 11608cefc107SDavid Howells WARN_ON(pipe_full(pipe->head, pipe->tail, pipe->ring_size)); 11618cd54c1cSAl Viro *i = (struct iov_iter){ 11628cd54c1cSAl Viro .iter_type = ITER_PIPE, 11638cd54c1cSAl Viro .data_source = false, 11648cd54c1cSAl Viro .pipe = pipe, 11658cd54c1cSAl Viro .head = pipe->head, 11668cd54c1cSAl Viro .start_head = pipe->head, 11678cd54c1cSAl Viro .iov_offset = 0, 11688cd54c1cSAl Viro .count = count 11698cd54c1cSAl Viro }; 1170241699cdSAl Viro } 1171241699cdSAl Viro EXPORT_SYMBOL(iov_iter_pipe); 1172241699cdSAl Viro 11739ea9ce04SDavid Howells /** 11747ff50620SDavid Howells * iov_iter_xarray - Initialise an I/O iterator to use the pages in an xarray 11757ff50620SDavid Howells * @i: The iterator to initialise. 11767ff50620SDavid Howells * @direction: The direction of the transfer. 11777ff50620SDavid Howells * @xarray: The xarray to access. 11787ff50620SDavid Howells * @start: The start file position. 11797ff50620SDavid Howells * @count: The size of the I/O buffer in bytes. 11807ff50620SDavid Howells * 11817ff50620SDavid Howells * Set up an I/O iterator to either draw data out of the pages attached to an 11827ff50620SDavid Howells * inode or to inject data into those pages. The pages *must* be prevented 11837ff50620SDavid Howells * from evaporation, either by taking a ref on them or locking them by the 11847ff50620SDavid Howells * caller. 11857ff50620SDavid Howells */ 11867ff50620SDavid Howells void iov_iter_xarray(struct iov_iter *i, unsigned int direction, 11877ff50620SDavid Howells struct xarray *xarray, loff_t start, size_t count) 11887ff50620SDavid Howells { 11897ff50620SDavid Howells BUG_ON(direction & ~1); 11908cd54c1cSAl Viro *i = (struct iov_iter) { 11918cd54c1cSAl Viro .iter_type = ITER_XARRAY, 11928cd54c1cSAl Viro .data_source = direction, 11938cd54c1cSAl Viro .xarray = xarray, 11948cd54c1cSAl Viro .xarray_start = start, 11958cd54c1cSAl Viro .count = count, 11968cd54c1cSAl Viro .iov_offset = 0 11978cd54c1cSAl Viro }; 11987ff50620SDavid Howells } 11997ff50620SDavid Howells EXPORT_SYMBOL(iov_iter_xarray); 12007ff50620SDavid Howells 12017ff50620SDavid Howells /** 12029ea9ce04SDavid Howells * iov_iter_discard - Initialise an I/O iterator that discards data 12039ea9ce04SDavid Howells * @i: The iterator to initialise. 12049ea9ce04SDavid Howells * @direction: The direction of the transfer. 12059ea9ce04SDavid Howells * @count: The size of the I/O buffer in bytes. 12069ea9ce04SDavid Howells * 12079ea9ce04SDavid Howells * Set up an I/O iterator that just discards everything that's written to it. 12089ea9ce04SDavid Howells * It's only available as a READ iterator. 12099ea9ce04SDavid Howells */ 12109ea9ce04SDavid Howells void iov_iter_discard(struct iov_iter *i, unsigned int direction, size_t count) 12119ea9ce04SDavid Howells { 12129ea9ce04SDavid Howells BUG_ON(direction != READ); 12138cd54c1cSAl Viro *i = (struct iov_iter){ 12148cd54c1cSAl Viro .iter_type = ITER_DISCARD, 12158cd54c1cSAl Viro .data_source = false, 12168cd54c1cSAl Viro .count = count, 12178cd54c1cSAl Viro .iov_offset = 0 12188cd54c1cSAl Viro }; 12199ea9ce04SDavid Howells } 12209ea9ce04SDavid Howells EXPORT_SYMBOL(iov_iter_discard); 12219ea9ce04SDavid Howells 12229221d2e3SAl Viro static unsigned long iov_iter_alignment_iovec(const struct iov_iter *i) 1223d879cb83SAl Viro { 1224d879cb83SAl Viro unsigned long res = 0; 1225d879cb83SAl Viro size_t size = i->count; 12269221d2e3SAl Viro size_t skip = i->iov_offset; 12279221d2e3SAl Viro unsigned k; 1228d879cb83SAl Viro 12299221d2e3SAl Viro for (k = 0; k < i->nr_segs; k++, skip = 0) { 12309221d2e3SAl Viro size_t len = i->iov[k].iov_len - skip; 12319221d2e3SAl Viro if (len) { 12329221d2e3SAl Viro res |= (unsigned long)i->iov[k].iov_base + skip; 12339221d2e3SAl Viro if (len > size) 12349221d2e3SAl Viro len = size; 12359221d2e3SAl Viro res |= len; 12369221d2e3SAl Viro size -= len; 12379221d2e3SAl Viro if (!size) 12389221d2e3SAl Viro break; 12399221d2e3SAl Viro } 12409221d2e3SAl Viro } 12419221d2e3SAl Viro return res; 12429221d2e3SAl Viro } 12439221d2e3SAl Viro 12449221d2e3SAl Viro static unsigned long iov_iter_alignment_bvec(const struct iov_iter *i) 12459221d2e3SAl Viro { 12469221d2e3SAl Viro unsigned res = 0; 12479221d2e3SAl Viro size_t size = i->count; 12489221d2e3SAl Viro unsigned skip = i->iov_offset; 12499221d2e3SAl Viro unsigned k; 12509221d2e3SAl Viro 12519221d2e3SAl Viro for (k = 0; k < i->nr_segs; k++, skip = 0) { 12529221d2e3SAl Viro size_t len = i->bvec[k].bv_len - skip; 12539221d2e3SAl Viro res |= (unsigned long)i->bvec[k].bv_offset + skip; 12549221d2e3SAl Viro if (len > size) 12559221d2e3SAl Viro len = size; 12569221d2e3SAl Viro res |= len; 12579221d2e3SAl Viro size -= len; 12589221d2e3SAl Viro if (!size) 12599221d2e3SAl Viro break; 12609221d2e3SAl Viro } 12619221d2e3SAl Viro return res; 12629221d2e3SAl Viro } 12639221d2e3SAl Viro 12649221d2e3SAl Viro unsigned long iov_iter_alignment(const struct iov_iter *i) 12659221d2e3SAl Viro { 12669221d2e3SAl Viro /* iovec and kvec have identical layouts */ 12679221d2e3SAl Viro if (likely(iter_is_iovec(i) || iov_iter_is_kvec(i))) 12689221d2e3SAl Viro return iov_iter_alignment_iovec(i); 12699221d2e3SAl Viro 12709221d2e3SAl Viro if (iov_iter_is_bvec(i)) 12719221d2e3SAl Viro return iov_iter_alignment_bvec(i); 12729221d2e3SAl Viro 12739221d2e3SAl Viro if (iov_iter_is_pipe(i)) { 1274e0ff126eSJan Kara unsigned int p_mask = i->pipe->ring_size - 1; 12759221d2e3SAl Viro size_t size = i->count; 1276e0ff126eSJan Kara 12778cefc107SDavid Howells if (size && i->iov_offset && allocated(&i->pipe->bufs[i->head & p_mask])) 1278241699cdSAl Viro return size | i->iov_offset; 1279241699cdSAl Viro return size; 1280241699cdSAl Viro } 12819221d2e3SAl Viro 12829221d2e3SAl Viro if (iov_iter_is_xarray(i)) 12833d14ec1fSDavid Howells return (i->xarray_start + i->iov_offset) | i->count; 12849221d2e3SAl Viro 12859221d2e3SAl Viro return 0; 1286d879cb83SAl Viro } 1287d879cb83SAl Viro EXPORT_SYMBOL(iov_iter_alignment); 1288d879cb83SAl Viro 1289357f435dSAl Viro unsigned long iov_iter_gap_alignment(const struct iov_iter *i) 1290357f435dSAl Viro { 1291357f435dSAl Viro unsigned long res = 0; 1292610c7a71SAl Viro unsigned long v = 0; 1293357f435dSAl Viro size_t size = i->count; 1294610c7a71SAl Viro unsigned k; 1295357f435dSAl Viro 1296610c7a71SAl Viro if (WARN_ON(!iter_is_iovec(i))) 1297241699cdSAl Viro return ~0U; 1298241699cdSAl Viro 1299610c7a71SAl Viro for (k = 0; k < i->nr_segs; k++) { 1300610c7a71SAl Viro if (i->iov[k].iov_len) { 1301610c7a71SAl Viro unsigned long base = (unsigned long)i->iov[k].iov_base; 1302610c7a71SAl Viro if (v) // if not the first one 1303610c7a71SAl Viro res |= base | v; // this start | previous end 1304610c7a71SAl Viro v = base + i->iov[k].iov_len; 1305610c7a71SAl Viro if (size <= i->iov[k].iov_len) 1306610c7a71SAl Viro break; 1307610c7a71SAl Viro size -= i->iov[k].iov_len; 1308610c7a71SAl Viro } 1309610c7a71SAl Viro } 1310357f435dSAl Viro return res; 1311357f435dSAl Viro } 1312357f435dSAl Viro EXPORT_SYMBOL(iov_iter_gap_alignment); 1313357f435dSAl Viro 1314e76b6312SIlya Dryomov static inline ssize_t __pipe_get_pages(struct iov_iter *i, 1315241699cdSAl Viro size_t maxsize, 1316241699cdSAl Viro struct page **pages, 13178cefc107SDavid Howells int iter_head, 1318241699cdSAl Viro size_t *start) 1319241699cdSAl Viro { 1320241699cdSAl Viro struct pipe_inode_info *pipe = i->pipe; 13218cefc107SDavid Howells unsigned int p_mask = pipe->ring_size - 1; 13228cefc107SDavid Howells ssize_t n = push_pipe(i, maxsize, &iter_head, start); 1323241699cdSAl Viro if (!n) 1324241699cdSAl Viro return -EFAULT; 1325241699cdSAl Viro 1326241699cdSAl Viro maxsize = n; 1327241699cdSAl Viro n += *start; 13281689c73aSAl Viro while (n > 0) { 13298cefc107SDavid Howells get_page(*pages++ = pipe->bufs[iter_head & p_mask].page); 13308cefc107SDavid Howells iter_head++; 1331241699cdSAl Viro n -= PAGE_SIZE; 1332241699cdSAl Viro } 1333241699cdSAl Viro 1334241699cdSAl Viro return maxsize; 1335241699cdSAl Viro } 1336241699cdSAl Viro 1337241699cdSAl Viro static ssize_t pipe_get_pages(struct iov_iter *i, 1338241699cdSAl Viro struct page **pages, size_t maxsize, unsigned maxpages, 1339241699cdSAl Viro size_t *start) 1340241699cdSAl Viro { 13418cefc107SDavid Howells unsigned int iter_head, npages; 1342241699cdSAl Viro size_t capacity; 1343241699cdSAl Viro 1344241699cdSAl Viro if (!sanity(i)) 1345241699cdSAl Viro return -EFAULT; 1346241699cdSAl Viro 13478cefc107SDavid Howells data_start(i, &iter_head, start); 13488cefc107SDavid Howells /* Amount of free space: some of this one + all after this one */ 13498cefc107SDavid Howells npages = pipe_space_for_user(iter_head, i->pipe->tail, i->pipe); 1350241699cdSAl Viro capacity = min(npages, maxpages) * PAGE_SIZE - *start; 1351241699cdSAl Viro 13528cefc107SDavid Howells return __pipe_get_pages(i, min(maxsize, capacity), pages, iter_head, start); 1353241699cdSAl Viro } 1354241699cdSAl Viro 13557ff50620SDavid Howells static ssize_t iter_xarray_populate_pages(struct page **pages, struct xarray *xa, 13567ff50620SDavid Howells pgoff_t index, unsigned int nr_pages) 13577ff50620SDavid Howells { 13587ff50620SDavid Howells XA_STATE(xas, xa, index); 13597ff50620SDavid Howells struct page *page; 13607ff50620SDavid Howells unsigned int ret = 0; 13617ff50620SDavid Howells 13627ff50620SDavid Howells rcu_read_lock(); 13637ff50620SDavid Howells for (page = xas_load(&xas); page; page = xas_next(&xas)) { 13647ff50620SDavid Howells if (xas_retry(&xas, page)) 13657ff50620SDavid Howells continue; 13667ff50620SDavid Howells 13677ff50620SDavid Howells /* Has the page moved or been split? */ 13687ff50620SDavid Howells if (unlikely(page != xas_reload(&xas))) { 13697ff50620SDavid Howells xas_reset(&xas); 13707ff50620SDavid Howells continue; 13717ff50620SDavid Howells } 13727ff50620SDavid Howells 13737ff50620SDavid Howells pages[ret] = find_subpage(page, xas.xa_index); 13747ff50620SDavid Howells get_page(pages[ret]); 13757ff50620SDavid Howells if (++ret == nr_pages) 13767ff50620SDavid Howells break; 13777ff50620SDavid Howells } 13787ff50620SDavid Howells rcu_read_unlock(); 13797ff50620SDavid Howells return ret; 13807ff50620SDavid Howells } 13817ff50620SDavid Howells 13827ff50620SDavid Howells static ssize_t iter_xarray_get_pages(struct iov_iter *i, 13837ff50620SDavid Howells struct page **pages, size_t maxsize, 13847ff50620SDavid Howells unsigned maxpages, size_t *_start_offset) 13857ff50620SDavid Howells { 13867ff50620SDavid Howells unsigned nr, offset; 13877ff50620SDavid Howells pgoff_t index, count; 13887ff50620SDavid Howells size_t size = maxsize, actual; 13897ff50620SDavid Howells loff_t pos; 13907ff50620SDavid Howells 13917ff50620SDavid Howells if (!size || !maxpages) 13927ff50620SDavid Howells return 0; 13937ff50620SDavid Howells 13947ff50620SDavid Howells pos = i->xarray_start + i->iov_offset; 13957ff50620SDavid Howells index = pos >> PAGE_SHIFT; 13967ff50620SDavid Howells offset = pos & ~PAGE_MASK; 13977ff50620SDavid Howells *_start_offset = offset; 13987ff50620SDavid Howells 13997ff50620SDavid Howells count = 1; 14007ff50620SDavid Howells if (size > PAGE_SIZE - offset) { 14017ff50620SDavid Howells size -= PAGE_SIZE - offset; 14027ff50620SDavid Howells count += size >> PAGE_SHIFT; 14037ff50620SDavid Howells size &= ~PAGE_MASK; 14047ff50620SDavid Howells if (size) 14057ff50620SDavid Howells count++; 14067ff50620SDavid Howells } 14077ff50620SDavid Howells 14087ff50620SDavid Howells if (count > maxpages) 14097ff50620SDavid Howells count = maxpages; 14107ff50620SDavid Howells 14117ff50620SDavid Howells nr = iter_xarray_populate_pages(pages, i->xarray, index, count); 14127ff50620SDavid Howells if (nr == 0) 14137ff50620SDavid Howells return 0; 14147ff50620SDavid Howells 14157ff50620SDavid Howells actual = PAGE_SIZE * nr; 14167ff50620SDavid Howells actual -= offset; 14177ff50620SDavid Howells if (nr == count && size > 0) { 14187ff50620SDavid Howells unsigned last_offset = (nr > 1) ? 0 : offset; 14197ff50620SDavid Howells actual -= PAGE_SIZE - (last_offset + size); 14207ff50620SDavid Howells } 14217ff50620SDavid Howells return actual; 14227ff50620SDavid Howells } 14237ff50620SDavid Howells 14243d671ca6SAl Viro /* must be done on non-empty ITER_IOVEC one */ 14253d671ca6SAl Viro static unsigned long first_iovec_segment(const struct iov_iter *i, 14263d671ca6SAl Viro size_t *size, size_t *start, 14273d671ca6SAl Viro size_t maxsize, unsigned maxpages) 14283d671ca6SAl Viro { 14293d671ca6SAl Viro size_t skip; 14303d671ca6SAl Viro long k; 14313d671ca6SAl Viro 14323d671ca6SAl Viro for (k = 0, skip = i->iov_offset; k < i->nr_segs; k++, skip = 0) { 14333d671ca6SAl Viro unsigned long addr = (unsigned long)i->iov[k].iov_base + skip; 14343d671ca6SAl Viro size_t len = i->iov[k].iov_len - skip; 14353d671ca6SAl Viro 14363d671ca6SAl Viro if (unlikely(!len)) 14373d671ca6SAl Viro continue; 14383d671ca6SAl Viro if (len > maxsize) 14393d671ca6SAl Viro len = maxsize; 14403d671ca6SAl Viro len += (*start = addr % PAGE_SIZE); 14413d671ca6SAl Viro if (len > maxpages * PAGE_SIZE) 14423d671ca6SAl Viro len = maxpages * PAGE_SIZE; 14433d671ca6SAl Viro *size = len; 14443d671ca6SAl Viro return addr & PAGE_MASK; 14453d671ca6SAl Viro } 14463d671ca6SAl Viro BUG(); // if it had been empty, we wouldn't get called 14473d671ca6SAl Viro } 14483d671ca6SAl Viro 14493d671ca6SAl Viro /* must be done on non-empty ITER_BVEC one */ 14503d671ca6SAl Viro static struct page *first_bvec_segment(const struct iov_iter *i, 14513d671ca6SAl Viro size_t *size, size_t *start, 14523d671ca6SAl Viro size_t maxsize, unsigned maxpages) 14533d671ca6SAl Viro { 14543d671ca6SAl Viro struct page *page; 14553d671ca6SAl Viro size_t skip = i->iov_offset, len; 14563d671ca6SAl Viro 14573d671ca6SAl Viro len = i->bvec->bv_len - skip; 14583d671ca6SAl Viro if (len > maxsize) 14593d671ca6SAl Viro len = maxsize; 14603d671ca6SAl Viro skip += i->bvec->bv_offset; 14613d671ca6SAl Viro page = i->bvec->bv_page + skip / PAGE_SIZE; 14623d671ca6SAl Viro len += (*start = skip % PAGE_SIZE); 14633d671ca6SAl Viro if (len > maxpages * PAGE_SIZE) 14643d671ca6SAl Viro len = maxpages * PAGE_SIZE; 14653d671ca6SAl Viro *size = len; 14663d671ca6SAl Viro return page; 14673d671ca6SAl Viro } 14683d671ca6SAl Viro 1469d879cb83SAl Viro ssize_t iov_iter_get_pages(struct iov_iter *i, 1470d879cb83SAl Viro struct page **pages, size_t maxsize, unsigned maxpages, 1471d879cb83SAl Viro size_t *start) 1472d879cb83SAl Viro { 14733d671ca6SAl Viro size_t len; 14743d671ca6SAl Viro int n, res; 14753d671ca6SAl Viro 1476d879cb83SAl Viro if (maxsize > i->count) 1477d879cb83SAl Viro maxsize = i->count; 14783d671ca6SAl Viro if (!maxsize) 14793d671ca6SAl Viro return 0; 1480d879cb83SAl Viro 14813d671ca6SAl Viro if (likely(iter_is_iovec(i))) { 14823d671ca6SAl Viro unsigned long addr; 14839ea9ce04SDavid Howells 14843d671ca6SAl Viro addr = first_iovec_segment(i, &len, start, maxsize, maxpages); 1485d879cb83SAl Viro n = DIV_ROUND_UP(len, PAGE_SIZE); 148673b0140bSIra Weiny res = get_user_pages_fast(addr, n, 148773b0140bSIra Weiny iov_iter_rw(i) != WRITE ? FOLL_WRITE : 0, 148873b0140bSIra Weiny pages); 1489814a6674SAndreas Gruenbacher if (unlikely(res <= 0)) 1490d879cb83SAl Viro return res; 1491d879cb83SAl Viro return (res == n ? len : res * PAGE_SIZE) - *start; 14923d671ca6SAl Viro } 14933d671ca6SAl Viro if (iov_iter_is_bvec(i)) { 14943d671ca6SAl Viro struct page *page; 14953d671ca6SAl Viro 14963d671ca6SAl Viro page = first_bvec_segment(i, &len, start, maxsize, maxpages); 14973d671ca6SAl Viro n = DIV_ROUND_UP(len, PAGE_SIZE); 14983d671ca6SAl Viro while (n--) 14993d671ca6SAl Viro get_page(*pages++ = page++); 15003d671ca6SAl Viro return len - *start; 15013d671ca6SAl Viro } 15023d671ca6SAl Viro if (iov_iter_is_pipe(i)) 15033d671ca6SAl Viro return pipe_get_pages(i, pages, maxsize, maxpages, start); 15043d671ca6SAl Viro if (iov_iter_is_xarray(i)) 15053d671ca6SAl Viro return iter_xarray_get_pages(i, pages, maxsize, maxpages, start); 1506d879cb83SAl Viro return -EFAULT; 1507d879cb83SAl Viro } 1508d879cb83SAl Viro EXPORT_SYMBOL(iov_iter_get_pages); 1509d879cb83SAl Viro 1510d879cb83SAl Viro static struct page **get_pages_array(size_t n) 1511d879cb83SAl Viro { 1512752ade68SMichal Hocko return kvmalloc_array(n, sizeof(struct page *), GFP_KERNEL); 1513d879cb83SAl Viro } 1514d879cb83SAl Viro 1515241699cdSAl Viro static ssize_t pipe_get_pages_alloc(struct iov_iter *i, 1516241699cdSAl Viro struct page ***pages, size_t maxsize, 1517241699cdSAl Viro size_t *start) 1518241699cdSAl Viro { 1519241699cdSAl Viro struct page **p; 15208cefc107SDavid Howells unsigned int iter_head, npages; 1521d7760d63SIlya Dryomov ssize_t n; 1522241699cdSAl Viro 1523241699cdSAl Viro if (!sanity(i)) 1524241699cdSAl Viro return -EFAULT; 1525241699cdSAl Viro 15268cefc107SDavid Howells data_start(i, &iter_head, start); 15278cefc107SDavid Howells /* Amount of free space: some of this one + all after this one */ 15288cefc107SDavid Howells npages = pipe_space_for_user(iter_head, i->pipe->tail, i->pipe); 1529241699cdSAl Viro n = npages * PAGE_SIZE - *start; 1530241699cdSAl Viro if (maxsize > n) 1531241699cdSAl Viro maxsize = n; 1532241699cdSAl Viro else 1533241699cdSAl Viro npages = DIV_ROUND_UP(maxsize + *start, PAGE_SIZE); 1534241699cdSAl Viro p = get_pages_array(npages); 1535241699cdSAl Viro if (!p) 1536241699cdSAl Viro return -ENOMEM; 15378cefc107SDavid Howells n = __pipe_get_pages(i, maxsize, p, iter_head, start); 1538241699cdSAl Viro if (n > 0) 1539241699cdSAl Viro *pages = p; 1540241699cdSAl Viro else 1541241699cdSAl Viro kvfree(p); 1542241699cdSAl Viro return n; 1543241699cdSAl Viro } 1544241699cdSAl Viro 15457ff50620SDavid Howells static ssize_t iter_xarray_get_pages_alloc(struct iov_iter *i, 15467ff50620SDavid Howells struct page ***pages, size_t maxsize, 15477ff50620SDavid Howells size_t *_start_offset) 15487ff50620SDavid Howells { 15497ff50620SDavid Howells struct page **p; 15507ff50620SDavid Howells unsigned nr, offset; 15517ff50620SDavid Howells pgoff_t index, count; 15527ff50620SDavid Howells size_t size = maxsize, actual; 15537ff50620SDavid Howells loff_t pos; 15547ff50620SDavid Howells 15557ff50620SDavid Howells if (!size) 15567ff50620SDavid Howells return 0; 15577ff50620SDavid Howells 15587ff50620SDavid Howells pos = i->xarray_start + i->iov_offset; 15597ff50620SDavid Howells index = pos >> PAGE_SHIFT; 15607ff50620SDavid Howells offset = pos & ~PAGE_MASK; 15617ff50620SDavid Howells *_start_offset = offset; 15627ff50620SDavid Howells 15637ff50620SDavid Howells count = 1; 15647ff50620SDavid Howells if (size > PAGE_SIZE - offset) { 15657ff50620SDavid Howells size -= PAGE_SIZE - offset; 15667ff50620SDavid Howells count += size >> PAGE_SHIFT; 15677ff50620SDavid Howells size &= ~PAGE_MASK; 15687ff50620SDavid Howells if (size) 15697ff50620SDavid Howells count++; 15707ff50620SDavid Howells } 15717ff50620SDavid Howells 15727ff50620SDavid Howells p = get_pages_array(count); 15737ff50620SDavid Howells if (!p) 15747ff50620SDavid Howells return -ENOMEM; 15757ff50620SDavid Howells *pages = p; 15767ff50620SDavid Howells 15777ff50620SDavid Howells nr = iter_xarray_populate_pages(p, i->xarray, index, count); 15787ff50620SDavid Howells if (nr == 0) 15797ff50620SDavid Howells return 0; 15807ff50620SDavid Howells 15817ff50620SDavid Howells actual = PAGE_SIZE * nr; 15827ff50620SDavid Howells actual -= offset; 15837ff50620SDavid Howells if (nr == count && size > 0) { 15847ff50620SDavid Howells unsigned last_offset = (nr > 1) ? 0 : offset; 15857ff50620SDavid Howells actual -= PAGE_SIZE - (last_offset + size); 15867ff50620SDavid Howells } 15877ff50620SDavid Howells return actual; 15887ff50620SDavid Howells } 15897ff50620SDavid Howells 1590d879cb83SAl Viro ssize_t iov_iter_get_pages_alloc(struct iov_iter *i, 1591d879cb83SAl Viro struct page ***pages, size_t maxsize, 1592d879cb83SAl Viro size_t *start) 1593d879cb83SAl Viro { 1594d879cb83SAl Viro struct page **p; 15953d671ca6SAl Viro size_t len; 15963d671ca6SAl Viro int n, res; 1597d879cb83SAl Viro 1598d879cb83SAl Viro if (maxsize > i->count) 1599d879cb83SAl Viro maxsize = i->count; 16003d671ca6SAl Viro if (!maxsize) 16013d671ca6SAl Viro return 0; 1602d879cb83SAl Viro 16033d671ca6SAl Viro if (likely(iter_is_iovec(i))) { 16043d671ca6SAl Viro unsigned long addr; 16059ea9ce04SDavid Howells 16063d671ca6SAl Viro addr = first_iovec_segment(i, &len, start, maxsize, ~0U); 1607d879cb83SAl Viro n = DIV_ROUND_UP(len, PAGE_SIZE); 1608d879cb83SAl Viro p = get_pages_array(n); 1609d879cb83SAl Viro if (!p) 1610d879cb83SAl Viro return -ENOMEM; 161173b0140bSIra Weiny res = get_user_pages_fast(addr, n, 161273b0140bSIra Weiny iov_iter_rw(i) != WRITE ? FOLL_WRITE : 0, p); 1613814a6674SAndreas Gruenbacher if (unlikely(res <= 0)) { 1614d879cb83SAl Viro kvfree(p); 1615814a6674SAndreas Gruenbacher *pages = NULL; 1616d879cb83SAl Viro return res; 1617d879cb83SAl Viro } 1618d879cb83SAl Viro *pages = p; 1619d879cb83SAl Viro return (res == n ? len : res * PAGE_SIZE) - *start; 16203d671ca6SAl Viro } 16213d671ca6SAl Viro if (iov_iter_is_bvec(i)) { 16223d671ca6SAl Viro struct page *page; 16233d671ca6SAl Viro 16243d671ca6SAl Viro page = first_bvec_segment(i, &len, start, maxsize, ~0U); 16253d671ca6SAl Viro n = DIV_ROUND_UP(len, PAGE_SIZE); 16263d671ca6SAl Viro *pages = p = get_pages_array(n); 1627d879cb83SAl Viro if (!p) 1628d879cb83SAl Viro return -ENOMEM; 16293d671ca6SAl Viro while (n--) 16303d671ca6SAl Viro get_page(*p++ = page++); 16313d671ca6SAl Viro return len - *start; 16323d671ca6SAl Viro } 16333d671ca6SAl Viro if (iov_iter_is_pipe(i)) 16343d671ca6SAl Viro return pipe_get_pages_alloc(i, pages, maxsize, start); 16353d671ca6SAl Viro if (iov_iter_is_xarray(i)) 16363d671ca6SAl Viro return iter_xarray_get_pages_alloc(i, pages, maxsize, start); 1637d879cb83SAl Viro return -EFAULT; 1638d879cb83SAl Viro } 1639d879cb83SAl Viro EXPORT_SYMBOL(iov_iter_get_pages_alloc); 1640d879cb83SAl Viro 1641d879cb83SAl Viro size_t csum_and_copy_from_iter(void *addr, size_t bytes, __wsum *csum, 1642d879cb83SAl Viro struct iov_iter *i) 1643d879cb83SAl Viro { 1644d879cb83SAl Viro __wsum sum, next; 1645d879cb83SAl Viro sum = *csum; 16469ea9ce04SDavid Howells if (unlikely(iov_iter_is_pipe(i) || iov_iter_is_discard(i))) { 1647241699cdSAl Viro WARN_ON(1); 1648241699cdSAl Viro return 0; 1649241699cdSAl Viro } 16507baa5099SAl Viro iterate_and_advance(i, bytes, base, len, off, ({ 16517baa5099SAl Viro next = csum_and_copy_from_user(base, addr + off, len); 1652d879cb83SAl Viro sum = csum_block_add(sum, next, off); 16537baa5099SAl Viro next ? 0 : len; 1654d879cb83SAl Viro }), ({ 16557baa5099SAl Viro sum = csum_and_memcpy(addr + off, base, len, sum, off); 1656d879cb83SAl Viro }) 1657d879cb83SAl Viro ) 1658d879cb83SAl Viro *csum = sum; 1659d879cb83SAl Viro return bytes; 1660d879cb83SAl Viro } 1661d879cb83SAl Viro EXPORT_SYMBOL(csum_and_copy_from_iter); 1662d879cb83SAl Viro 166352cbd23aSWillem de Bruijn size_t csum_and_copy_to_iter(const void *addr, size_t bytes, void *_csstate, 1664d879cb83SAl Viro struct iov_iter *i) 1665d879cb83SAl Viro { 166652cbd23aSWillem de Bruijn struct csum_state *csstate = _csstate; 1667d879cb83SAl Viro __wsum sum, next; 166878e1f386SAl Viro 166978e1f386SAl Viro if (unlikely(iov_iter_is_discard(i))) { 1670241699cdSAl Viro WARN_ON(1); /* for now */ 1671241699cdSAl Viro return 0; 1672241699cdSAl Viro } 16736852df12SAl Viro 16746852df12SAl Viro sum = csum_shift(csstate->csum, csstate->off); 16756852df12SAl Viro if (unlikely(iov_iter_is_pipe(i))) 16766852df12SAl Viro bytes = csum_and_copy_to_pipe_iter(addr, bytes, i, &sum); 16776852df12SAl Viro else iterate_and_advance(i, bytes, base, len, off, ({ 16787baa5099SAl Viro next = csum_and_copy_to_user(addr + off, base, len); 1679d879cb83SAl Viro sum = csum_block_add(sum, next, off); 16807baa5099SAl Viro next ? 0 : len; 1681d879cb83SAl Viro }), ({ 16827baa5099SAl Viro sum = csum_and_memcpy(base, addr + off, len, sum, off); 1683d879cb83SAl Viro }) 1684d879cb83SAl Viro ) 1685594e450bSAl Viro csstate->csum = csum_shift(sum, csstate->off); 1686594e450bSAl Viro csstate->off += bytes; 1687d879cb83SAl Viro return bytes; 1688d879cb83SAl Viro } 1689d879cb83SAl Viro EXPORT_SYMBOL(csum_and_copy_to_iter); 1690d879cb83SAl Viro 1691d05f4435SSagi Grimberg size_t hash_and_copy_to_iter(const void *addr, size_t bytes, void *hashp, 1692d05f4435SSagi Grimberg struct iov_iter *i) 1693d05f4435SSagi Grimberg { 16947999096fSHerbert Xu #ifdef CONFIG_CRYPTO_HASH 1695d05f4435SSagi Grimberg struct ahash_request *hash = hashp; 1696d05f4435SSagi Grimberg struct scatterlist sg; 1697d05f4435SSagi Grimberg size_t copied; 1698d05f4435SSagi Grimberg 1699d05f4435SSagi Grimberg copied = copy_to_iter(addr, bytes, i); 1700d05f4435SSagi Grimberg sg_init_one(&sg, addr, copied); 1701d05f4435SSagi Grimberg ahash_request_set_crypt(hash, &sg, NULL, copied); 1702d05f4435SSagi Grimberg crypto_ahash_update(hash); 1703d05f4435SSagi Grimberg return copied; 170427fad74aSYueHaibing #else 170527fad74aSYueHaibing return 0; 170627fad74aSYueHaibing #endif 1707d05f4435SSagi Grimberg } 1708d05f4435SSagi Grimberg EXPORT_SYMBOL(hash_and_copy_to_iter); 1709d05f4435SSagi Grimberg 171066531c65SAl Viro static int iov_npages(const struct iov_iter *i, int maxpages) 1711d879cb83SAl Viro { 171266531c65SAl Viro size_t skip = i->iov_offset, size = i->count; 171366531c65SAl Viro const struct iovec *p; 1714d879cb83SAl Viro int npages = 0; 1715d879cb83SAl Viro 171666531c65SAl Viro for (p = i->iov; size; skip = 0, p++) { 171766531c65SAl Viro unsigned offs = offset_in_page(p->iov_base + skip); 171866531c65SAl Viro size_t len = min(p->iov_len - skip, size); 1719d879cb83SAl Viro 172066531c65SAl Viro if (len) { 172166531c65SAl Viro size -= len; 172266531c65SAl Viro npages += DIV_ROUND_UP(offs + len, PAGE_SIZE); 172366531c65SAl Viro if (unlikely(npages > maxpages)) 172466531c65SAl Viro return maxpages; 172566531c65SAl Viro } 172666531c65SAl Viro } 172766531c65SAl Viro return npages; 172866531c65SAl Viro } 172966531c65SAl Viro 173066531c65SAl Viro static int bvec_npages(const struct iov_iter *i, int maxpages) 173166531c65SAl Viro { 173266531c65SAl Viro size_t skip = i->iov_offset, size = i->count; 173366531c65SAl Viro const struct bio_vec *p; 173466531c65SAl Viro int npages = 0; 173566531c65SAl Viro 173666531c65SAl Viro for (p = i->bvec; size; skip = 0, p++) { 173766531c65SAl Viro unsigned offs = (p->bv_offset + skip) % PAGE_SIZE; 173866531c65SAl Viro size_t len = min(p->bv_len - skip, size); 173966531c65SAl Viro 174066531c65SAl Viro size -= len; 174166531c65SAl Viro npages += DIV_ROUND_UP(offs + len, PAGE_SIZE); 174266531c65SAl Viro if (unlikely(npages > maxpages)) 174366531c65SAl Viro return maxpages; 174466531c65SAl Viro } 174566531c65SAl Viro return npages; 174666531c65SAl Viro } 174766531c65SAl Viro 174866531c65SAl Viro int iov_iter_npages(const struct iov_iter *i, int maxpages) 174966531c65SAl Viro { 175066531c65SAl Viro if (unlikely(!i->count)) 175166531c65SAl Viro return 0; 175266531c65SAl Viro /* iovec and kvec have identical layouts */ 175366531c65SAl Viro if (likely(iter_is_iovec(i) || iov_iter_is_kvec(i))) 175466531c65SAl Viro return iov_npages(i, maxpages); 175566531c65SAl Viro if (iov_iter_is_bvec(i)) 175666531c65SAl Viro return bvec_npages(i, maxpages); 175766531c65SAl Viro if (iov_iter_is_pipe(i)) { 17588cefc107SDavid Howells unsigned int iter_head; 175966531c65SAl Viro int npages; 1760241699cdSAl Viro size_t off; 1761241699cdSAl Viro 1762241699cdSAl Viro if (!sanity(i)) 1763241699cdSAl Viro return 0; 1764241699cdSAl Viro 17658cefc107SDavid Howells data_start(i, &iter_head, &off); 1766241699cdSAl Viro /* some of this one + all after this one */ 176766531c65SAl Viro npages = pipe_space_for_user(iter_head, i->pipe->tail, i->pipe); 176866531c65SAl Viro return min(npages, maxpages); 176966531c65SAl Viro } 177066531c65SAl Viro if (iov_iter_is_xarray(i)) { 1771e4f8df86SAl Viro unsigned offset = (i->xarray_start + i->iov_offset) % PAGE_SIZE; 1772e4f8df86SAl Viro int npages = DIV_ROUND_UP(offset + i->count, PAGE_SIZE); 177366531c65SAl Viro return min(npages, maxpages); 177466531c65SAl Viro } 177566531c65SAl Viro return 0; 1776d879cb83SAl Viro } 1777d879cb83SAl Viro EXPORT_SYMBOL(iov_iter_npages); 1778d879cb83SAl Viro 1779d879cb83SAl Viro const void *dup_iter(struct iov_iter *new, struct iov_iter *old, gfp_t flags) 1780d879cb83SAl Viro { 1781d879cb83SAl Viro *new = *old; 178200e23707SDavid Howells if (unlikely(iov_iter_is_pipe(new))) { 1783241699cdSAl Viro WARN_ON(1); 1784241699cdSAl Viro return NULL; 1785241699cdSAl Viro } 17867ff50620SDavid Howells if (unlikely(iov_iter_is_discard(new) || iov_iter_is_xarray(new))) 17879ea9ce04SDavid Howells return NULL; 178800e23707SDavid Howells if (iov_iter_is_bvec(new)) 1789d879cb83SAl Viro return new->bvec = kmemdup(new->bvec, 1790d879cb83SAl Viro new->nr_segs * sizeof(struct bio_vec), 1791d879cb83SAl Viro flags); 1792d879cb83SAl Viro else 1793d879cb83SAl Viro /* iovec and kvec have identical layout */ 1794d879cb83SAl Viro return new->iov = kmemdup(new->iov, 1795d879cb83SAl Viro new->nr_segs * sizeof(struct iovec), 1796d879cb83SAl Viro flags); 1797d879cb83SAl Viro } 1798d879cb83SAl Viro EXPORT_SYMBOL(dup_iter); 1799bc917be8SAl Viro 1800bfdc5970SChristoph Hellwig static int copy_compat_iovec_from_user(struct iovec *iov, 1801bfdc5970SChristoph Hellwig const struct iovec __user *uvec, unsigned long nr_segs) 1802bfdc5970SChristoph Hellwig { 1803bfdc5970SChristoph Hellwig const struct compat_iovec __user *uiov = 1804bfdc5970SChristoph Hellwig (const struct compat_iovec __user *)uvec; 1805bfdc5970SChristoph Hellwig int ret = -EFAULT, i; 1806bfdc5970SChristoph Hellwig 1807a959a978SChristoph Hellwig if (!user_access_begin(uiov, nr_segs * sizeof(*uiov))) 1808bfdc5970SChristoph Hellwig return -EFAULT; 1809bfdc5970SChristoph Hellwig 1810bfdc5970SChristoph Hellwig for (i = 0; i < nr_segs; i++) { 1811bfdc5970SChristoph Hellwig compat_uptr_t buf; 1812bfdc5970SChristoph Hellwig compat_ssize_t len; 1813bfdc5970SChristoph Hellwig 1814bfdc5970SChristoph Hellwig unsafe_get_user(len, &uiov[i].iov_len, uaccess_end); 1815bfdc5970SChristoph Hellwig unsafe_get_user(buf, &uiov[i].iov_base, uaccess_end); 1816bfdc5970SChristoph Hellwig 1817bfdc5970SChristoph Hellwig /* check for compat_size_t not fitting in compat_ssize_t .. */ 1818bfdc5970SChristoph Hellwig if (len < 0) { 1819bfdc5970SChristoph Hellwig ret = -EINVAL; 1820bfdc5970SChristoph Hellwig goto uaccess_end; 1821bfdc5970SChristoph Hellwig } 1822bfdc5970SChristoph Hellwig iov[i].iov_base = compat_ptr(buf); 1823bfdc5970SChristoph Hellwig iov[i].iov_len = len; 1824bfdc5970SChristoph Hellwig } 1825bfdc5970SChristoph Hellwig 1826bfdc5970SChristoph Hellwig ret = 0; 1827bfdc5970SChristoph Hellwig uaccess_end: 1828bfdc5970SChristoph Hellwig user_access_end(); 1829bfdc5970SChristoph Hellwig return ret; 1830bfdc5970SChristoph Hellwig } 1831bfdc5970SChristoph Hellwig 1832bfdc5970SChristoph Hellwig static int copy_iovec_from_user(struct iovec *iov, 1833bfdc5970SChristoph Hellwig const struct iovec __user *uvec, unsigned long nr_segs) 1834fb041b59SDavid Laight { 1835fb041b59SDavid Laight unsigned long seg; 1836bfdc5970SChristoph Hellwig 1837bfdc5970SChristoph Hellwig if (copy_from_user(iov, uvec, nr_segs * sizeof(*uvec))) 1838bfdc5970SChristoph Hellwig return -EFAULT; 1839bfdc5970SChristoph Hellwig for (seg = 0; seg < nr_segs; seg++) { 1840bfdc5970SChristoph Hellwig if ((ssize_t)iov[seg].iov_len < 0) 1841bfdc5970SChristoph Hellwig return -EINVAL; 1842bfdc5970SChristoph Hellwig } 1843bfdc5970SChristoph Hellwig 1844bfdc5970SChristoph Hellwig return 0; 1845bfdc5970SChristoph Hellwig } 1846bfdc5970SChristoph Hellwig 1847bfdc5970SChristoph Hellwig struct iovec *iovec_from_user(const struct iovec __user *uvec, 1848bfdc5970SChristoph Hellwig unsigned long nr_segs, unsigned long fast_segs, 1849bfdc5970SChristoph Hellwig struct iovec *fast_iov, bool compat) 1850bfdc5970SChristoph Hellwig { 1851bfdc5970SChristoph Hellwig struct iovec *iov = fast_iov; 1852bfdc5970SChristoph Hellwig int ret; 1853fb041b59SDavid Laight 1854fb041b59SDavid Laight /* 1855bfdc5970SChristoph Hellwig * SuS says "The readv() function *may* fail if the iovcnt argument was 1856bfdc5970SChristoph Hellwig * less than or equal to 0, or greater than {IOV_MAX}. Linux has 1857fb041b59SDavid Laight * traditionally returned zero for zero segments, so... 1858fb041b59SDavid Laight */ 1859bfdc5970SChristoph Hellwig if (nr_segs == 0) 1860bfdc5970SChristoph Hellwig return iov; 1861bfdc5970SChristoph Hellwig if (nr_segs > UIO_MAXIOV) 1862bfdc5970SChristoph Hellwig return ERR_PTR(-EINVAL); 1863fb041b59SDavid Laight if (nr_segs > fast_segs) { 1864fb041b59SDavid Laight iov = kmalloc_array(nr_segs, sizeof(struct iovec), GFP_KERNEL); 1865bfdc5970SChristoph Hellwig if (!iov) 1866bfdc5970SChristoph Hellwig return ERR_PTR(-ENOMEM); 1867fb041b59SDavid Laight } 1868bfdc5970SChristoph Hellwig 1869bfdc5970SChristoph Hellwig if (compat) 1870bfdc5970SChristoph Hellwig ret = copy_compat_iovec_from_user(iov, uvec, nr_segs); 1871bfdc5970SChristoph Hellwig else 1872bfdc5970SChristoph Hellwig ret = copy_iovec_from_user(iov, uvec, nr_segs); 1873bfdc5970SChristoph Hellwig if (ret) { 1874bfdc5970SChristoph Hellwig if (iov != fast_iov) 1875bfdc5970SChristoph Hellwig kfree(iov); 1876bfdc5970SChristoph Hellwig return ERR_PTR(ret); 1877fb041b59SDavid Laight } 1878bfdc5970SChristoph Hellwig 1879bfdc5970SChristoph Hellwig return iov; 1880bfdc5970SChristoph Hellwig } 1881bfdc5970SChristoph Hellwig 1882bfdc5970SChristoph Hellwig ssize_t __import_iovec(int type, const struct iovec __user *uvec, 1883bfdc5970SChristoph Hellwig unsigned nr_segs, unsigned fast_segs, struct iovec **iovp, 1884bfdc5970SChristoph Hellwig struct iov_iter *i, bool compat) 1885bfdc5970SChristoph Hellwig { 1886bfdc5970SChristoph Hellwig ssize_t total_len = 0; 1887bfdc5970SChristoph Hellwig unsigned long seg; 1888bfdc5970SChristoph Hellwig struct iovec *iov; 1889bfdc5970SChristoph Hellwig 1890bfdc5970SChristoph Hellwig iov = iovec_from_user(uvec, nr_segs, fast_segs, *iovp, compat); 1891bfdc5970SChristoph Hellwig if (IS_ERR(iov)) { 1892bfdc5970SChristoph Hellwig *iovp = NULL; 1893bfdc5970SChristoph Hellwig return PTR_ERR(iov); 1894fb041b59SDavid Laight } 1895fb041b59SDavid Laight 1896fb041b59SDavid Laight /* 1897bfdc5970SChristoph Hellwig * According to the Single Unix Specification we should return EINVAL if 1898bfdc5970SChristoph Hellwig * an element length is < 0 when cast to ssize_t or if the total length 1899bfdc5970SChristoph Hellwig * would overflow the ssize_t return value of the system call. 1900fb041b59SDavid Laight * 1901fb041b59SDavid Laight * Linux caps all read/write calls to MAX_RW_COUNT, and avoids the 1902fb041b59SDavid Laight * overflow case. 1903fb041b59SDavid Laight */ 1904fb041b59SDavid Laight for (seg = 0; seg < nr_segs; seg++) { 1905fb041b59SDavid Laight ssize_t len = (ssize_t)iov[seg].iov_len; 1906fb041b59SDavid Laight 1907bfdc5970SChristoph Hellwig if (!access_ok(iov[seg].iov_base, len)) { 1908bfdc5970SChristoph Hellwig if (iov != *iovp) 1909bfdc5970SChristoph Hellwig kfree(iov); 1910bfdc5970SChristoph Hellwig *iovp = NULL; 1911bfdc5970SChristoph Hellwig return -EFAULT; 1912fb041b59SDavid Laight } 1913bfdc5970SChristoph Hellwig 1914bfdc5970SChristoph Hellwig if (len > MAX_RW_COUNT - total_len) { 1915bfdc5970SChristoph Hellwig len = MAX_RW_COUNT - total_len; 1916fb041b59SDavid Laight iov[seg].iov_len = len; 1917fb041b59SDavid Laight } 1918bfdc5970SChristoph Hellwig total_len += len; 1919fb041b59SDavid Laight } 1920bfdc5970SChristoph Hellwig 1921bfdc5970SChristoph Hellwig iov_iter_init(i, type, iov, nr_segs, total_len); 1922bfdc5970SChristoph Hellwig if (iov == *iovp) 1923bfdc5970SChristoph Hellwig *iovp = NULL; 1924bfdc5970SChristoph Hellwig else 1925bfdc5970SChristoph Hellwig *iovp = iov; 1926bfdc5970SChristoph Hellwig return total_len; 1927fb041b59SDavid Laight } 1928fb041b59SDavid Laight 1929ffecee4fSVegard Nossum /** 1930ffecee4fSVegard Nossum * import_iovec() - Copy an array of &struct iovec from userspace 1931ffecee4fSVegard Nossum * into the kernel, check that it is valid, and initialize a new 1932ffecee4fSVegard Nossum * &struct iov_iter iterator to access it. 1933ffecee4fSVegard Nossum * 1934ffecee4fSVegard Nossum * @type: One of %READ or %WRITE. 1935bfdc5970SChristoph Hellwig * @uvec: Pointer to the userspace array. 1936ffecee4fSVegard Nossum * @nr_segs: Number of elements in userspace array. 1937ffecee4fSVegard Nossum * @fast_segs: Number of elements in @iov. 1938bfdc5970SChristoph Hellwig * @iovp: (input and output parameter) Pointer to pointer to (usually small 1939ffecee4fSVegard Nossum * on-stack) kernel array. 1940ffecee4fSVegard Nossum * @i: Pointer to iterator that will be initialized on success. 1941ffecee4fSVegard Nossum * 1942ffecee4fSVegard Nossum * If the array pointed to by *@iov is large enough to hold all @nr_segs, 1943ffecee4fSVegard Nossum * then this function places %NULL in *@iov on return. Otherwise, a new 1944ffecee4fSVegard Nossum * array will be allocated and the result placed in *@iov. This means that 1945ffecee4fSVegard Nossum * the caller may call kfree() on *@iov regardless of whether the small 1946ffecee4fSVegard Nossum * on-stack array was used or not (and regardless of whether this function 1947ffecee4fSVegard Nossum * returns an error or not). 1948ffecee4fSVegard Nossum * 194987e5e6daSJens Axboe * Return: Negative error code on error, bytes imported on success 1950ffecee4fSVegard Nossum */ 1951bfdc5970SChristoph Hellwig ssize_t import_iovec(int type, const struct iovec __user *uvec, 1952bc917be8SAl Viro unsigned nr_segs, unsigned fast_segs, 1953bfdc5970SChristoph Hellwig struct iovec **iovp, struct iov_iter *i) 1954bc917be8SAl Viro { 195589cd35c5SChristoph Hellwig return __import_iovec(type, uvec, nr_segs, fast_segs, iovp, i, 195689cd35c5SChristoph Hellwig in_compat_syscall()); 1957bc917be8SAl Viro } 1958bc917be8SAl Viro EXPORT_SYMBOL(import_iovec); 1959bc917be8SAl Viro 1960bc917be8SAl Viro int import_single_range(int rw, void __user *buf, size_t len, 1961bc917be8SAl Viro struct iovec *iov, struct iov_iter *i) 1962bc917be8SAl Viro { 1963bc917be8SAl Viro if (len > MAX_RW_COUNT) 1964bc917be8SAl Viro len = MAX_RW_COUNT; 196596d4f267SLinus Torvalds if (unlikely(!access_ok(buf, len))) 1966bc917be8SAl Viro return -EFAULT; 1967bc917be8SAl Viro 1968bc917be8SAl Viro iov->iov_base = buf; 1969bc917be8SAl Viro iov->iov_len = len; 1970bc917be8SAl Viro iov_iter_init(i, rw, iov, 1, len); 1971bc917be8SAl Viro return 0; 1972bc917be8SAl Viro } 1973e1267585SAl Viro EXPORT_SYMBOL(import_single_range); 19748fb0f47aSJens Axboe 19758fb0f47aSJens Axboe /** 19768fb0f47aSJens Axboe * iov_iter_restore() - Restore a &struct iov_iter to the same state as when 19778fb0f47aSJens Axboe * iov_iter_save_state() was called. 19788fb0f47aSJens Axboe * 19798fb0f47aSJens Axboe * @i: &struct iov_iter to restore 19808fb0f47aSJens Axboe * @state: state to restore from 19818fb0f47aSJens Axboe * 19828fb0f47aSJens Axboe * Used after iov_iter_save_state() to bring restore @i, if operations may 19838fb0f47aSJens Axboe * have advanced it. 19848fb0f47aSJens Axboe * 19858fb0f47aSJens Axboe * Note: only works on ITER_IOVEC, ITER_BVEC, and ITER_KVEC 19868fb0f47aSJens Axboe */ 19878fb0f47aSJens Axboe void iov_iter_restore(struct iov_iter *i, struct iov_iter_state *state) 19888fb0f47aSJens Axboe { 19898fb0f47aSJens Axboe if (WARN_ON_ONCE(!iov_iter_is_bvec(i) && !iter_is_iovec(i)) && 19908fb0f47aSJens Axboe !iov_iter_is_kvec(i)) 19918fb0f47aSJens Axboe return; 19928fb0f47aSJens Axboe i->iov_offset = state->iov_offset; 19938fb0f47aSJens Axboe i->count = state->count; 19948fb0f47aSJens Axboe /* 19958fb0f47aSJens Axboe * For the *vec iters, nr_segs + iov is constant - if we increment 19968fb0f47aSJens Axboe * the vec, then we also decrement the nr_segs count. Hence we don't 19978fb0f47aSJens Axboe * need to track both of these, just one is enough and we can deduct 19988fb0f47aSJens Axboe * the other from that. ITER_KVEC and ITER_IOVEC are the same struct 19998fb0f47aSJens Axboe * size, so we can just increment the iov pointer as they are unionzed. 20008fb0f47aSJens Axboe * ITER_BVEC _may_ be the same size on some archs, but on others it is 20018fb0f47aSJens Axboe * not. Be safe and handle it separately. 20028fb0f47aSJens Axboe */ 20038fb0f47aSJens Axboe BUILD_BUG_ON(sizeof(struct iovec) != sizeof(struct kvec)); 20048fb0f47aSJens Axboe if (iov_iter_is_bvec(i)) 20058fb0f47aSJens Axboe i->bvec -= state->nr_segs - i->nr_segs; 20068fb0f47aSJens Axboe else 20078fb0f47aSJens Axboe i->iov -= state->nr_segs - i->nr_segs; 20088fb0f47aSJens Axboe i->nr_segs = state->nr_segs; 20098fb0f47aSJens Axboe } 2010