ipc: separate msg allocation from userspace copy
[GitHub/mt8127/android_kernel_alcatel_ttab.git] / ipc / msgutil.c
CommitLineData
1da177e4 1/*
f30c2269 2 * linux/ipc/msgutil.c
1da177e4
LT
3 * Copyright (C) 1999, 2004 Manfred Spraul
4 *
5 * This file is released under GNU General Public Licence version 2 or
6 * (at your option) any later version.
7 *
8 * See the file COPYING for more details.
9 */
10
11#include <linux/spinlock.h>
12#include <linux/init.h>
13#include <linux/security.h>
14#include <linux/slab.h>
15#include <linux/ipc.h>
40401530 16#include <linux/msg.h>
614b84cf 17#include <linux/ipc_namespace.h>
40401530 18#include <linux/utsname.h>
98f842e6 19#include <linux/proc_fs.h>
1da177e4
LT
20#include <asm/uaccess.h>
21
22#include "util.h"
23
7eafd7c7
SH
24DEFINE_SPINLOCK(mq_lock);
25
614b84cf
SH
26/*
27 * The next 2 defines are here bc this is the only file
28 * compiled when either CONFIG_SYSVIPC and CONFIG_POSIX_MQUEUE
29 * and not CONFIG_IPC_NS.
30 */
31struct ipc_namespace init_ipc_ns = {
7eafd7c7 32 .count = ATOMIC_INIT(1),
b515498f 33 .user_ns = &init_user_ns,
98f842e6 34 .proc_inum = PROC_IPC_INIT_INO,
614b84cf
SH
35};
36
37atomic_t nr_ipc_ns = ATOMIC_INIT(1);
38
1da177e4
LT
39struct msg_msgseg {
40 struct msg_msgseg* next;
41 /* the next part of the message follows immediately */
42};
43
3d8fa456
PH
44#define DATALEN_MSG (int)(PAGE_SIZE-sizeof(struct msg_msg))
45#define DATALEN_SEG (int)(PAGE_SIZE-sizeof(struct msg_msgseg))
1da177e4 46
be5f4b33
PH
47
48static struct msg_msg *alloc_msg(int len)
1da177e4
LT
49{
50 struct msg_msg *msg;
51 struct msg_msgseg **pseg;
1da177e4
LT
52 int alen;
53
3d8fa456 54 alen = min(len, DATALEN_MSG);
5cbded58 55 msg = kmalloc(sizeof(*msg) + alen, GFP_KERNEL);
1da177e4 56 if (msg == NULL)
be5f4b33 57 return NULL;
1da177e4
LT
58
59 msg->next = NULL;
60 msg->security = NULL;
61
be5f4b33
PH
62 len -= alen;
63 pseg = &msg->next;
64 while (len > 0) {
65 struct msg_msgseg *seg;
66 alen = min(len, DATALEN_SEG);
67 seg = kmalloc(sizeof(*seg) + alen, GFP_KERNEL);
68 if (seg == NULL)
69 goto out_err;
70 *pseg = seg;
71 seg->next = NULL;
72 pseg = &seg->next;
73 len -= alen;
74 }
75
76 return msg;
77
78out_err:
79 free_msg(msg);
80 return NULL;
81}
82
83struct msg_msg *load_msg(const void __user *src, int len)
84{
85 struct msg_msg *msg;
86 struct msg_msgseg *seg;
87 int err;
88 int alen;
89
90 msg = alloc_msg(len);
91 if (msg == NULL)
92 return ERR_PTR(-ENOMEM);
93
94 alen = min(len, DATALEN_MSG);
1da177e4
LT
95 if (copy_from_user(msg + 1, src, alen)) {
96 err = -EFAULT;
97 goto out_err;
98 }
99
100 len -= alen;
101 src = ((char __user *)src) + alen;
be5f4b33 102 seg = msg->next;
1da177e4 103 while (len > 0) {
3d8fa456 104 alen = min(len, DATALEN_SEG);
1da177e4
LT
105 if (copy_from_user(seg + 1, src, alen)) {
106 err = -EFAULT;
107 goto out_err;
108 }
be5f4b33 109 seg = seg->next;
1da177e4
LT
110 len -= alen;
111 src = ((char __user *)src) + alen;
112 }
113
114 err = security_msg_msg_alloc(msg);
115 if (err)
116 goto out_err;
117
118 return msg;
119
120out_err:
121 free_msg(msg);
122 return ERR_PTR(err);
123}
4a674f34
SK
124#ifdef CONFIG_CHECKPOINT_RESTORE
125struct msg_msg *copy_msg(struct msg_msg *src, struct msg_msg *dst)
126{
127 struct msg_msgseg *dst_pseg, *src_pseg;
128 int len = src->m_ts;
129 int alen;
130
131 BUG_ON(dst == NULL);
132 if (src->m_ts > dst->m_ts)
133 return ERR_PTR(-EINVAL);
134
3d8fa456 135 alen = min(len, DATALEN_MSG);
4a674f34
SK
136 memcpy(dst + 1, src + 1, alen);
137
138 len -= alen;
139 dst_pseg = dst->next;
140 src_pseg = src->next;
141 while (len > 0) {
3d8fa456 142 alen = min(len, DATALEN_SEG);
4a674f34
SK
143 memcpy(dst_pseg + 1, src_pseg + 1, alen);
144 dst_pseg = dst_pseg->next;
145 len -= alen;
146 src_pseg = src_pseg->next;
147 }
148
149 dst->m_type = src->m_type;
150 dst->m_ts = src->m_ts;
151
152 return dst;
153}
51eeacaa
SK
154#else
155struct msg_msg *copy_msg(struct msg_msg *src, struct msg_msg *dst)
156{
157 return ERR_PTR(-ENOSYS);
158}
4a674f34 159#endif
1da177e4
LT
160int store_msg(void __user *dest, struct msg_msg *msg, int len)
161{
162 int alen;
163 struct msg_msgseg *seg;
164
3d8fa456 165 alen = min(len, DATALEN_MSG);
1da177e4
LT
166 if (copy_to_user(dest, msg + 1, alen))
167 return -1;
168
169 len -= alen;
170 dest = ((char __user *)dest) + alen;
171 seg = msg->next;
172 while (len > 0) {
3d8fa456 173 alen = min(len, DATALEN_SEG);
1da177e4
LT
174 if (copy_to_user(dest, seg + 1, alen))
175 return -1;
176 len -= alen;
177 dest = ((char __user *)dest) + alen;
178 seg = seg->next;
179 }
180 return 0;
181}
182
183void free_msg(struct msg_msg *msg)
184{
185 struct msg_msgseg *seg;
186
187 security_msg_msg_free(msg);
188
189 seg = msg->next;
190 kfree(msg);
191 while (seg != NULL) {
192 struct msg_msgseg *tmp = seg->next;
193 kfree(seg);
194 seg = tmp;
195 }
196}