[PATCH] sanitize blkdev_get() and friends
[GitHub/LineageOS/android_kernel_samsung_universal7580.git] / block / ioctl.c
CommitLineData
c59ede7b 1#include <linux/capability.h>
1da177e4
LT
2#include <linux/blkdev.h>
3#include <linux/blkpg.h>
a885c8c4 4#include <linux/hdreg.h>
1da177e4
LT
5#include <linux/backing-dev.h>
6#include <linux/buffer_head.h>
7#include <linux/smp_lock.h>
2056a782 8#include <linux/blktrace_api.h>
1da177e4
LT
9#include <asm/uaccess.h>
10
11static int blkpg_ioctl(struct block_device *bdev, struct blkpg_ioctl_arg __user *arg)
12{
13 struct block_device *bdevp;
14 struct gendisk *disk;
e71bf0d0 15 struct hd_struct *part;
1da177e4
LT
16 struct blkpg_ioctl_arg a;
17 struct blkpg_partition p;
e71bf0d0 18 struct disk_part_iter piter;
1da177e4 19 long long start, length;
cf771cb5 20 int partno;
04ebd4ae 21 int err;
1da177e4
LT
22
23 if (!capable(CAP_SYS_ADMIN))
24 return -EACCES;
25 if (copy_from_user(&a, arg, sizeof(struct blkpg_ioctl_arg)))
26 return -EFAULT;
27 if (copy_from_user(&p, a.data, sizeof(struct blkpg_partition)))
28 return -EFAULT;
29 disk = bdev->bd_disk;
30 if (bdev != bdev->bd_contains)
31 return -EINVAL;
cf771cb5 32 partno = p.pno;
540eed56 33 if (partno <= 0)
1da177e4
LT
34 return -EINVAL;
35 switch (a.op) {
36 case BLKPG_ADD_PARTITION:
37 start = p.start >> 9;
38 length = p.length >> 9;
39 /* check for fit in a hd_struct */
40 if (sizeof(sector_t) == sizeof(long) &&
41 sizeof(long long) > sizeof(long)) {
42 long pstart = start, plength = length;
43 if (pstart != start || plength != length
44 || pstart < 0 || plength < 0)
45 return -EINVAL;
46 }
88e34126 47
c039e313 48 mutex_lock(&bdev->bd_mutex);
88e34126 49
1da177e4 50 /* overlap? */
e71bf0d0
TH
51 disk_part_iter_init(&piter, disk,
52 DISK_PITER_INCL_EMPTY);
53 while ((part = disk_part_iter_next(&piter))) {
54 if (!(start + length <= part->start_sect ||
55 start >= part->start_sect + part->nr_sects)) {
56 disk_part_iter_exit(&piter);
c039e313 57 mutex_unlock(&bdev->bd_mutex);
1da177e4
LT
58 return -EBUSY;
59 }
60 }
e71bf0d0
TH
61 disk_part_iter_exit(&piter);
62
1da177e4 63 /* all seems OK */
cf771cb5
TH
64 err = add_partition(disk, partno, start, length,
65 ADDPART_FLAG_NONE);
c039e313 66 mutex_unlock(&bdev->bd_mutex);
04ebd4ae 67 return err;
1da177e4 68 case BLKPG_DEL_PARTITION:
e71bf0d0
TH
69 part = disk_get_part(disk, partno);
70 if (!part)
1da177e4 71 return -ENXIO;
e71bf0d0
TH
72
73 bdevp = bdget(part_devt(part));
74 disk_put_part(part);
1da177e4
LT
75 if (!bdevp)
76 return -ENOMEM;
e71bf0d0 77
2e7b651d 78 mutex_lock(&bdevp->bd_mutex);
1da177e4 79 if (bdevp->bd_openers) {
c039e313 80 mutex_unlock(&bdevp->bd_mutex);
1da177e4
LT
81 bdput(bdevp);
82 return -EBUSY;
83 }
84 /* all seems OK */
85 fsync_bdev(bdevp);
f98393a6 86 invalidate_bdev(bdevp);
1da177e4 87
6d740cd5 88 mutex_lock_nested(&bdev->bd_mutex, 1);
cf771cb5 89 delete_partition(disk, partno);
c039e313
AV
90 mutex_unlock(&bdev->bd_mutex);
91 mutex_unlock(&bdevp->bd_mutex);
1da177e4
LT
92 bdput(bdevp);
93
94 return 0;
95 default:
96 return -EINVAL;
97 }
98}
99
100static int blkdev_reread_part(struct block_device *bdev)
101{
102 struct gendisk *disk = bdev->bd_disk;
103 int res;
104
b5d0b9df 105 if (!disk_partitionable(disk) || bdev != bdev->bd_contains)
1da177e4
LT
106 return -EINVAL;
107 if (!capable(CAP_SYS_ADMIN))
108 return -EACCES;
c039e313 109 if (!mutex_trylock(&bdev->bd_mutex))
1da177e4
LT
110 return -EBUSY;
111 res = rescan_partitions(disk, bdev);
c039e313 112 mutex_unlock(&bdev->bd_mutex);
1da177e4
LT
113 return res;
114}
115
d30a2605
DW
116static void blk_ioc_discard_endio(struct bio *bio, int err)
117{
118 if (err) {
119 if (err == -EOPNOTSUPP)
120 set_bit(BIO_EOPNOTSUPP, &bio->bi_flags);
121 clear_bit(BIO_UPTODATE, &bio->bi_flags);
122 }
123 complete(bio->bi_private);
124}
125
126static int blk_ioctl_discard(struct block_device *bdev, uint64_t start,
127 uint64_t len)
128{
129 struct request_queue *q = bdev_get_queue(bdev);
130 int ret = 0;
131
132 if (start & 511)
133 return -EINVAL;
134 if (len & 511)
135 return -EINVAL;
136 start >>= 9;
137 len >>= 9;
138
139 if (start + len > (bdev->bd_inode->i_size >> 9))
140 return -EINVAL;
141
142 if (!q->prepare_discard_fn)
143 return -EOPNOTSUPP;
144
145 while (len && !ret) {
146 DECLARE_COMPLETION_ONSTACK(wait);
147 struct bio *bio;
148
149 bio = bio_alloc(GFP_KERNEL, 0);
150 if (!bio)
151 return -ENOMEM;
152
153 bio->bi_end_io = blk_ioc_discard_endio;
154 bio->bi_bdev = bdev;
155 bio->bi_private = &wait;
156 bio->bi_sector = start;
157
158 if (len > q->max_hw_sectors) {
159 bio->bi_size = q->max_hw_sectors << 9;
160 len -= q->max_hw_sectors;
161 start += q->max_hw_sectors;
162 } else {
163 bio->bi_size = len << 9;
164 len = 0;
165 }
e17fc0a1 166 submit_bio(DISCARD_NOBARRIER, bio);
d30a2605
DW
167
168 wait_for_completion(&wait);
169
170 if (bio_flagged(bio, BIO_EOPNOTSUPP))
171 ret = -EOPNOTSUPP;
172 else if (!bio_flagged(bio, BIO_UPTODATE))
173 ret = -EIO;
174 bio_put(bio);
175 }
176 return ret;
177}
178
1da177e4
LT
179static int put_ushort(unsigned long arg, unsigned short val)
180{
181 return put_user(val, (unsigned short __user *)arg);
182}
183
184static int put_int(unsigned long arg, int val)
185{
186 return put_user(val, (int __user *)arg);
187}
188
189static int put_long(unsigned long arg, long val)
190{
191 return put_user(val, (long __user *)arg);
192}
193
194static int put_ulong(unsigned long arg, unsigned long val)
195{
196 return put_user(val, (unsigned long __user *)arg);
197}
198
199static int put_u64(unsigned long arg, u64 val)
200{
201 return put_user(val, (u64 __user *)arg);
202}
203
bb93e3a5
AB
204static int blkdev_locked_ioctl(struct file *file, struct block_device *bdev,
205 unsigned cmd, unsigned long arg)
1da177e4 206{
1da177e4
LT
207 struct backing_dev_info *bdi;
208 int ret, n;
209
210 switch (cmd) {
211 case BLKRAGET:
212 case BLKFRAGET:
213 if (!arg)
214 return -EINVAL;
215 bdi = blk_get_backing_dev_info(bdev);
216 if (bdi == NULL)
217 return -ENOTTY;
218 return put_long(arg, (bdi->ra_pages * PAGE_CACHE_SIZE) / 512);
219 case BLKROGET:
220 return put_int(arg, bdev_read_only(bdev) != 0);
221 case BLKBSZGET: /* get the logical block size (cf. BLKSSZGET) */
222 return put_int(arg, block_size(bdev));
223 case BLKSSZGET: /* get block device hardware sector size */
224 return put_int(arg, bdev_hardsect_size(bdev));
225 case BLKSECTGET:
226 return put_ushort(arg, bdev_get_queue(bdev)->max_sectors);
227 case BLKRASET:
228 case BLKFRASET:
229 if(!capable(CAP_SYS_ADMIN))
230 return -EACCES;
231 bdi = blk_get_backing_dev_info(bdev);
232 if (bdi == NULL)
233 return -ENOTTY;
234 bdi->ra_pages = (arg * 512) / PAGE_CACHE_SIZE;
235 return 0;
236 case BLKBSZSET:
237 /* set the logical block size */
238 if (!capable(CAP_SYS_ADMIN))
239 return -EACCES;
240 if (!arg)
241 return -EINVAL;
242 if (get_user(n, (int __user *) arg))
243 return -EFAULT;
244 if (bd_claim(bdev, file) < 0)
245 return -EBUSY;
246 ret = set_blocksize(bdev, n);
247 bd_release(bdev);
248 return ret;
249 case BLKPG:
250 return blkpg_ioctl(bdev, (struct blkpg_ioctl_arg __user *) arg);
251 case BLKRRPART:
252 return blkdev_reread_part(bdev);
253 case BLKGETSIZE:
254 if ((bdev->bd_inode->i_size >> 9) > ~0UL)
255 return -EFBIG;
256 return put_ulong(arg, bdev->bd_inode->i_size >> 9);
257 case BLKGETSIZE64:
258 return put_u64(arg, bdev->bd_inode->i_size);
2056a782
JA
259 case BLKTRACESTART:
260 case BLKTRACESTOP:
261 case BLKTRACESETUP:
262 case BLKTRACETEARDOWN:
263 return blk_trace_ioctl(bdev, cmd, (char __user *) arg);
bb93e3a5
AB
264 }
265 return -ENOIOCTLCMD;
266}
267
7006f6ec
AK
268int blkdev_driver_ioctl(struct inode *inode, struct file *file,
269 struct gendisk *disk, unsigned cmd, unsigned long arg)
bb93e3a5
AB
270{
271 int ret;
d4430d62
AV
272 fmode_t mode = 0;
273 if (file) {
274 mode = file->f_mode;
275 if (file->f_flags & O_NDELAY)
276 mode |= FMODE_NDELAY_NOW;
277 }
278
d4430d62 279 return __blkdev_driver_ioctl(inode->i_bdev, mode, cmd, arg);
bb93e3a5 280}
7006f6ec 281EXPORT_SYMBOL_GPL(blkdev_driver_ioctl);
bb93e3a5 282
633a08b8
AV
283int __blkdev_driver_ioctl(struct block_device *bdev, fmode_t mode,
284 unsigned cmd, unsigned long arg)
285{
286 struct gendisk *disk = bdev->bd_disk;
287 int ret;
d4430d62
AV
288
289 if (disk->fops->ioctl)
290 return disk->fops->ioctl(bdev, mode, cmd, arg);
633a08b8 291
d4430d62 292 if (disk->fops->locked_ioctl) {
633a08b8 293 lock_kernel();
d4430d62 294 ret = disk->fops->locked_ioctl(bdev, mode, cmd, arg);
633a08b8
AV
295 unlock_kernel();
296 return ret;
297 }
298
299 return -ENOTTY;
300}
301/*
302 * For the record: _GPL here is only because somebody decided to slap it
303 * on the previous export. Sheer idiocy, since it wasn't copyrightable
304 * at all and could be open-coded without any exports by anybody who cares.
305 */
306EXPORT_SYMBOL_GPL(__blkdev_driver_ioctl);
307
f58c4c0a
AB
308/*
309 * always keep this in sync with compat_blkdev_ioctl() and
310 * compat_blkdev_locked_ioctl()
311 */
bb93e3a5
AB
312int blkdev_ioctl(struct inode *inode, struct file *file, unsigned cmd,
313 unsigned long arg)
314{
315 struct block_device *bdev = inode->i_bdev;
316 struct gendisk *disk = bdev->bd_disk;
317 int ret, n;
318
319 switch(cmd) {
1da177e4
LT
320 case BLKFLSBUF:
321 if (!capable(CAP_SYS_ADMIN))
322 return -EACCES;
bb93e3a5
AB
323
324 ret = blkdev_driver_ioctl(inode, file, disk, cmd, arg);
325 /* -EINVAL to handle old uncorrected drivers */
326 if (ret != -EINVAL && ret != -ENOTTY)
327 return ret;
328
329 lock_kernel();
1da177e4 330 fsync_bdev(bdev);
f98393a6 331 invalidate_bdev(bdev);
bb93e3a5 332 unlock_kernel();
1da177e4 333 return 0;
bb93e3a5 334
1da177e4 335 case BLKROSET:
bb93e3a5
AB
336 ret = blkdev_driver_ioctl(inode, file, disk, cmd, arg);
337 /* -EINVAL to handle old uncorrected drivers */
338 if (ret != -EINVAL && ret != -ENOTTY)
339 return ret;
1da177e4
LT
340 if (!capable(CAP_SYS_ADMIN))
341 return -EACCES;
342 if (get_user(n, (int __user *)(arg)))
343 return -EFAULT;
bb93e3a5 344 lock_kernel();
1da177e4 345 set_device_ro(bdev, n);
bb93e3a5 346 unlock_kernel();
1da177e4 347 return 0;
d30a2605
DW
348
349 case BLKDISCARD: {
350 uint64_t range[2];
351
352 if (!(file->f_mode & FMODE_WRITE))
353 return -EBADF;
354
355 if (copy_from_user(range, (void __user *)arg, sizeof(range)))
356 return -EFAULT;
357
358 return blk_ioctl_discard(bdev, range[0], range[1]);
359 }
360
a885c8c4
CH
361 case HDIO_GETGEO: {
362 struct hd_geometry geo;
363
364 if (!arg)
365 return -EINVAL;
366 if (!disk->fops->getgeo)
367 return -ENOTTY;
368
369 /*
370 * We need to set the startsect first, the driver may
371 * want to override it.
372 */
373 geo.start = get_start_sect(bdev);
374 ret = disk->fops->getgeo(bdev, &geo);
375 if (ret)
376 return ret;
377 if (copy_to_user((struct hd_geometry __user *)arg, &geo,
378 sizeof(geo)))
379 return -EFAULT;
380 return 0;
381 }
1da177e4 382 }
bb93e3a5
AB
383
384 lock_kernel();
385 ret = blkdev_locked_ioctl(file, bdev, cmd, arg);
386 unlock_kernel();
387 if (ret != -ENOIOCTLCMD)
388 return ret;
389
390 return blkdev_driver_ioctl(inode, file, disk, cmd, arg);
1da177e4 391}
68f66feb 392EXPORT_SYMBOL_GPL(blkdev_ioctl);