1 /*
2  * 32 bit compatibility code for System V IPC
3  *
4  * Copyright (C) 1997,1998	Jakub Jelinek (jj@sunsite.mff.cuni.cz)
5  * Copyright (C) 1997		David S. Miller (davem@caip.rutgers.edu)
6  * Copyright (C) 1999		Arun Sharma <arun.sharma@intel.com>
7  * Copyright (C) 2000		VA Linux Co
8  * Copyright (C) 2000		Don Dugger <n0ano@valinux.com>
9  * Copyright (C) 2000           Hewlett-Packard Co.
10  * Copyright (C) 2000           David Mosberger-Tang <davidm@hpl.hp.com>
11  * Copyright (C) 2000           Gerhard Tonn (ton@de.ibm.com)
12  * Copyright (C) 2000-2002      Andi Kleen, SuSE Labs (x86-64 port)
13  * Copyright (C) 2000		Silicon Graphics, Inc.
14  * Copyright (C) 2001		IBM
15  * Copyright (C) 2004		IBM Deutschland Entwicklung GmbH, IBM Corporation
16  * Copyright (C) 2004		Arnd Bergmann (arnd@arndb.de)
17  *
18  * This code is collected from the versions for sparc64, mips64, s390x, ia64,
19  * ppc64 and x86_64, all of which are based on the original sparc64 version
20  * by Jakub Jelinek.
21  *
22  */
23 #include <linux/compat.h>
24 #include <linux/errno.h>
25 #include <linux/highuid.h>
26 #include <linux/init.h>
27 #include <linux/msg.h>
28 #include <linux/shm.h>
29 #include <linux/syscalls.h>
30 #include <linux/ptrace.h>
31 
32 #include <linux/mutex.h>
33 #include <asm/uaccess.h>
34 
35 #include "util.h"
36 
37 struct compat_msgbuf {
38 	compat_long_t mtype;
39 	char mtext[1];
40 };
41 
42 struct compat_ipc_perm {
43 	key_t key;
44 	__compat_uid_t uid;
45 	__compat_gid_t gid;
46 	__compat_uid_t cuid;
47 	__compat_gid_t cgid;
48 	compat_mode_t mode;
49 	unsigned short seq;
50 };
51 
52 struct compat_semid_ds {
53 	struct compat_ipc_perm sem_perm;
54 	compat_time_t sem_otime;
55 	compat_time_t sem_ctime;
56 	compat_uptr_t sem_base;
57 	compat_uptr_t sem_pending;
58 	compat_uptr_t sem_pending_last;
59 	compat_uptr_t undo;
60 	unsigned short sem_nsems;
61 };
62 
63 struct compat_msqid_ds {
64 	struct compat_ipc_perm msg_perm;
65 	compat_uptr_t msg_first;
66 	compat_uptr_t msg_last;
67 	compat_time_t msg_stime;
68 	compat_time_t msg_rtime;
69 	compat_time_t msg_ctime;
70 	compat_ulong_t msg_lcbytes;
71 	compat_ulong_t msg_lqbytes;
72 	unsigned short msg_cbytes;
73 	unsigned short msg_qnum;
74 	unsigned short msg_qbytes;
75 	compat_ipc_pid_t msg_lspid;
76 	compat_ipc_pid_t msg_lrpid;
77 };
78 
79 struct compat_shmid_ds {
80 	struct compat_ipc_perm shm_perm;
81 	int shm_segsz;
82 	compat_time_t shm_atime;
83 	compat_time_t shm_dtime;
84 	compat_time_t shm_ctime;
85 	compat_ipc_pid_t shm_cpid;
86 	compat_ipc_pid_t shm_lpid;
87 	unsigned short shm_nattch;
88 	unsigned short shm_unused;
89 	compat_uptr_t shm_unused2;
90 	compat_uptr_t shm_unused3;
91 };
92 
93 struct compat_ipc_kludge {
94 	compat_uptr_t msgp;
95 	compat_long_t msgtyp;
96 };
97 
98 struct compat_shminfo64 {
99 	compat_ulong_t shmmax;
100 	compat_ulong_t shmmin;
101 	compat_ulong_t shmmni;
102 	compat_ulong_t shmseg;
103 	compat_ulong_t shmall;
104 	compat_ulong_t __unused1;
105 	compat_ulong_t __unused2;
106 	compat_ulong_t __unused3;
107 	compat_ulong_t __unused4;
108 };
109 
110 struct compat_shm_info {
111 	compat_int_t used_ids;
112 	compat_ulong_t shm_tot, shm_rss, shm_swp;
113 	compat_ulong_t swap_attempts, swap_successes;
114 };
115 
116 extern int sem_ctls[];
117 #define sc_semopm	(sem_ctls[2])
118 
compat_ipc_parse_version(int * cmd)119 static inline int compat_ipc_parse_version(int *cmd)
120 {
121 #ifdef CONFIG_ARCH_WANT_OLD_COMPAT_IPC
122 	int version = *cmd & IPC_64;
123 
124 	/* this is tricky: architectures that have support for the old
125 	 * ipc structures in 64 bit binaries need to have IPC_64 set
126 	 * in cmd, the others need to have it cleared */
127 #ifndef ipc_parse_version
128 	*cmd |= IPC_64;
129 #else
130 	*cmd &= ~IPC_64;
131 #endif
132 	return version;
133 #else
134 	/* With the asm-generic APIs, we always use the 64-bit versions. */
135 	return IPC_64;
136 #endif
137 }
138 
__get_compat_ipc64_perm(struct ipc64_perm * p64,struct compat_ipc64_perm __user * up64)139 static inline int __get_compat_ipc64_perm(struct ipc64_perm *p64,
140 					  struct compat_ipc64_perm __user *up64)
141 {
142 	int err;
143 
144 	err  = __get_user(p64->uid, &up64->uid);
145 	err |= __get_user(p64->gid, &up64->gid);
146 	err |= __get_user(p64->mode, &up64->mode);
147 	return err;
148 }
149 
__get_compat_ipc_perm(struct ipc64_perm * p,struct compat_ipc_perm __user * up)150 static inline int __get_compat_ipc_perm(struct ipc64_perm *p,
151 					struct compat_ipc_perm __user *up)
152 {
153 	int err;
154 
155 	err  = __get_user(p->uid, &up->uid);
156 	err |= __get_user(p->gid, &up->gid);
157 	err |= __get_user(p->mode, &up->mode);
158 	return err;
159 }
160 
__put_compat_ipc64_perm(struct ipc64_perm * p64,struct compat_ipc64_perm __user * up64)161 static inline int __put_compat_ipc64_perm(struct ipc64_perm *p64,
162 					  struct compat_ipc64_perm __user *up64)
163 {
164 	int err;
165 
166 	err  = __put_user(p64->key, &up64->key);
167 	err |= __put_user(p64->uid, &up64->uid);
168 	err |= __put_user(p64->gid, &up64->gid);
169 	err |= __put_user(p64->cuid, &up64->cuid);
170 	err |= __put_user(p64->cgid, &up64->cgid);
171 	err |= __put_user(p64->mode, &up64->mode);
172 	err |= __put_user(p64->seq, &up64->seq);
173 	return err;
174 }
175 
__put_compat_ipc_perm(struct ipc64_perm * p,struct compat_ipc_perm __user * up)176 static inline int __put_compat_ipc_perm(struct ipc64_perm *p,
177 					struct compat_ipc_perm __user *up)
178 {
179 	int err;
180 	__compat_uid_t u;
181 	__compat_gid_t g;
182 
183 	err  = __put_user(p->key, &up->key);
184 	SET_UID(u, p->uid);
185 	err |= __put_user(u, &up->uid);
186 	SET_GID(g, p->gid);
187 	err |= __put_user(g, &up->gid);
188 	SET_UID(u, p->cuid);
189 	err |= __put_user(u, &up->cuid);
190 	SET_GID(g, p->cgid);
191 	err |= __put_user(g, &up->cgid);
192 	err |= __put_user(p->mode, &up->mode);
193 	err |= __put_user(p->seq, &up->seq);
194 	return err;
195 }
196 
get_compat_semid64_ds(struct semid64_ds * s64,struct compat_semid64_ds __user * up64)197 static inline int get_compat_semid64_ds(struct semid64_ds *s64,
198 					struct compat_semid64_ds __user *up64)
199 {
200 	if (!access_ok (VERIFY_READ, up64, sizeof(*up64)))
201 		return -EFAULT;
202 	return __get_compat_ipc64_perm(&s64->sem_perm, &up64->sem_perm);
203 }
204 
get_compat_semid_ds(struct semid64_ds * s,struct compat_semid_ds __user * up)205 static inline int get_compat_semid_ds(struct semid64_ds *s,
206 				      struct compat_semid_ds __user *up)
207 {
208 	if (!access_ok (VERIFY_READ, up, sizeof(*up)))
209 		return -EFAULT;
210 	return __get_compat_ipc_perm(&s->sem_perm, &up->sem_perm);
211 }
212 
put_compat_semid64_ds(struct semid64_ds * s64,struct compat_semid64_ds __user * up64)213 static inline int put_compat_semid64_ds(struct semid64_ds *s64,
214 					struct compat_semid64_ds __user *up64)
215 {
216 	int err;
217 
218 	if (!access_ok (VERIFY_WRITE, up64, sizeof(*up64)))
219 		return -EFAULT;
220 	err  = __put_compat_ipc64_perm(&s64->sem_perm, &up64->sem_perm);
221 	err |= __put_user(s64->sem_otime, &up64->sem_otime);
222 	err |= __put_user(s64->sem_ctime, &up64->sem_ctime);
223 	err |= __put_user(s64->sem_nsems, &up64->sem_nsems);
224 	return err;
225 }
226 
put_compat_semid_ds(struct semid64_ds * s,struct compat_semid_ds __user * up)227 static inline int put_compat_semid_ds(struct semid64_ds *s,
228 				      struct compat_semid_ds __user *up)
229 {
230 	int err;
231 
232 	if (!access_ok (VERIFY_WRITE, up, sizeof(*up)))
233 		return -EFAULT;
234 	err  = __put_compat_ipc_perm(&s->sem_perm, &up->sem_perm);
235 	err |= __put_user(s->sem_otime, &up->sem_otime);
236 	err |= __put_user(s->sem_ctime, &up->sem_ctime);
237 	err |= __put_user(s->sem_nsems, &up->sem_nsems);
238 	return err;
239 }
240 
do_compat_semctl(int first,int second,int third,u32 pad)241 static long do_compat_semctl(int first, int second, int third, u32 pad)
242 {
243 	union semun fourth;
244 	int err, err2;
245 	struct semid64_ds s64;
246 	struct semid64_ds __user *up64;
247 	int version = compat_ipc_parse_version(&third);
248 
249 	memset(&s64, 0, sizeof(s64));
250 
251 	if ((third & (~IPC_64)) == SETVAL)
252 		fourth.val = (int) pad;
253 	else
254 		fourth.__pad = compat_ptr(pad);
255 	switch (third & (~IPC_64)) {
256 	case IPC_INFO:
257 	case IPC_RMID:
258 	case SEM_INFO:
259 	case GETVAL:
260 	case GETPID:
261 	case GETNCNT:
262 	case GETZCNT:
263 	case GETALL:
264 	case SETVAL:
265 	case SETALL:
266 		err = sys_semctl(first, second, third, fourth);
267 		break;
268 
269 	case IPC_STAT:
270 	case SEM_STAT:
271 		up64 = compat_alloc_user_space(sizeof(s64));
272 		fourth.__pad = up64;
273 		err = sys_semctl(first, second, third, fourth);
274 		if (err < 0)
275 			break;
276 		if (copy_from_user(&s64, up64, sizeof(s64)))
277 			err2 = -EFAULT;
278 		else if (version == IPC_64)
279 			err2 = put_compat_semid64_ds(&s64, compat_ptr(pad));
280 		else
281 			err2 = put_compat_semid_ds(&s64, compat_ptr(pad));
282 		if (err2)
283 			err = -EFAULT;
284 		break;
285 
286 	case IPC_SET:
287 		if (version == IPC_64) {
288 			err = get_compat_semid64_ds(&s64, compat_ptr(pad));
289 		} else {
290 			err = get_compat_semid_ds(&s64, compat_ptr(pad));
291 		}
292 		up64 = compat_alloc_user_space(sizeof(s64));
293 		if (copy_to_user(up64, &s64, sizeof(s64)))
294 			err = -EFAULT;
295 		if (err)
296 			break;
297 
298 		fourth.__pad = up64;
299 		err = sys_semctl(first, second, third, fourth);
300 		break;
301 
302 	default:
303 		err = -EINVAL;
304 		break;
305 	}
306 	return err;
307 }
308 
309 #ifdef CONFIG_ARCH_WANT_OLD_COMPAT_IPC
compat_sys_semctl(int first,int second,int third,void __user * uptr)310 long compat_sys_semctl(int first, int second, int third, void __user *uptr)
311 {
312 	u32 pad;
313 
314 	if (!uptr)
315 		return -EINVAL;
316 	if (get_user(pad, (u32 __user *) uptr))
317 		return -EFAULT;
318 	return do_compat_semctl(first, second, third, pad);
319 }
320 
compat_sys_msgsnd(int first,int second,int third,void __user * uptr)321 long compat_sys_msgsnd(int first, int second, int third, void __user *uptr)
322 {
323 	struct compat_msgbuf __user *up = uptr;
324 	long type;
325 
326 	if (first < 0)
327 		return -EINVAL;
328 	if (second < 0)
329 		return -EINVAL;
330 
331 	if (get_user(type, &up->mtype))
332 		return -EFAULT;
333 
334 	return do_msgsnd(first, type, up->mtext, second, third);
335 }
336 
compat_sys_msgrcv(int first,int second,int msgtyp,int third,int version,void __user * uptr)337 long compat_sys_msgrcv(int first, int second, int msgtyp, int third,
338 			   int version, void __user *uptr)
339 {
340 	struct compat_msgbuf __user *up;
341 	long type;
342 	int err;
343 
344 	if (first < 0)
345 		return -EINVAL;
346 	if (second < 0)
347 		return -EINVAL;
348 
349 	if (!version) {
350 		struct compat_ipc_kludge ipck;
351 		err = -EINVAL;
352 		if (!uptr)
353 			goto out;
354 		err = -EFAULT;
355 		if (copy_from_user (&ipck, uptr, sizeof(ipck)))
356 			goto out;
357 		uptr = compat_ptr(ipck.msgp);
358 		msgtyp = ipck.msgtyp;
359 	}
360 	up = uptr;
361 	err = do_msgrcv(first, &type, up->mtext, second, msgtyp, third);
362 	if (err < 0)
363 		goto out;
364 	if (put_user(type, &up->mtype))
365 		err = -EFAULT;
366 out:
367 	return err;
368 }
369 #else
compat_sys_semctl(int semid,int semnum,int cmd,int arg)370 long compat_sys_semctl(int semid, int semnum, int cmd, int arg)
371 {
372 	return do_compat_semctl(semid, semnum, cmd, arg);
373 }
374 
compat_sys_msgsnd(int msqid,struct compat_msgbuf __user * msgp,size_t msgsz,int msgflg)375 long compat_sys_msgsnd(int msqid, struct compat_msgbuf __user *msgp,
376 		       size_t msgsz, int msgflg)
377 {
378 	compat_long_t mtype;
379 
380 	if (get_user(mtype, &msgp->mtype))
381 		return -EFAULT;
382 	return do_msgsnd(msqid, mtype, msgp->mtext, msgsz, msgflg);
383 }
384 
compat_sys_msgrcv(int msqid,struct compat_msgbuf __user * msgp,size_t msgsz,long msgtyp,int msgflg)385 long compat_sys_msgrcv(int msqid, struct compat_msgbuf __user *msgp,
386 		       size_t msgsz, long msgtyp, int msgflg)
387 {
388 	long err, mtype;
389 
390 	err =  do_msgrcv(msqid, &mtype, msgp->mtext, msgsz, msgtyp, msgflg);
391 	if (err < 0)
392 		goto out;
393 
394 	if (put_user(mtype, &msgp->mtype))
395 		err = -EFAULT;
396  out:
397 	return err;
398 }
399 #endif
400 
get_compat_msqid64(struct msqid64_ds * m64,struct compat_msqid64_ds __user * up64)401 static inline int get_compat_msqid64(struct msqid64_ds *m64,
402 				     struct compat_msqid64_ds __user *up64)
403 {
404 	int err;
405 
406 	if (!access_ok(VERIFY_READ, up64, sizeof(*up64)))
407 		return -EFAULT;
408 	err  = __get_compat_ipc64_perm(&m64->msg_perm, &up64->msg_perm);
409 	err |= __get_user(m64->msg_qbytes, &up64->msg_qbytes);
410 	return err;
411 }
412 
get_compat_msqid(struct msqid64_ds * m,struct compat_msqid_ds __user * up)413 static inline int get_compat_msqid(struct msqid64_ds *m,
414 				   struct compat_msqid_ds __user *up)
415 {
416 	int err;
417 
418 	if (!access_ok(VERIFY_READ, up, sizeof(*up)))
419 		return -EFAULT;
420 	err  = __get_compat_ipc_perm(&m->msg_perm, &up->msg_perm);
421 	err |= __get_user(m->msg_qbytes, &up->msg_qbytes);
422 	return err;
423 }
424 
put_compat_msqid64_ds(struct msqid64_ds * m64,struct compat_msqid64_ds __user * up64)425 static inline int put_compat_msqid64_ds(struct msqid64_ds *m64,
426 				 struct compat_msqid64_ds __user *up64)
427 {
428 	int err;
429 
430 	if (!access_ok(VERIFY_WRITE, up64, sizeof(*up64)))
431 		return -EFAULT;
432 	err  = __put_compat_ipc64_perm(&m64->msg_perm, &up64->msg_perm);
433 	err |= __put_user(m64->msg_stime, &up64->msg_stime);
434 	err |= __put_user(m64->msg_rtime, &up64->msg_rtime);
435 	err |= __put_user(m64->msg_ctime, &up64->msg_ctime);
436 	err |= __put_user(m64->msg_cbytes, &up64->msg_cbytes);
437 	err |= __put_user(m64->msg_qnum, &up64->msg_qnum);
438 	err |= __put_user(m64->msg_qbytes, &up64->msg_qbytes);
439 	err |= __put_user(m64->msg_lspid, &up64->msg_lspid);
440 	err |= __put_user(m64->msg_lrpid, &up64->msg_lrpid);
441 	return err;
442 }
443 
put_compat_msqid_ds(struct msqid64_ds * m,struct compat_msqid_ds __user * up)444 static inline int put_compat_msqid_ds(struct msqid64_ds *m,
445 				      struct compat_msqid_ds __user *up)
446 {
447 	int err;
448 
449 	if (!access_ok(VERIFY_WRITE, up, sizeof(*up)))
450 		return -EFAULT;
451 	err  = __put_compat_ipc_perm(&m->msg_perm, &up->msg_perm);
452 	err |= __put_user(m->msg_stime, &up->msg_stime);
453 	err |= __put_user(m->msg_rtime, &up->msg_rtime);
454 	err |= __put_user(m->msg_ctime, &up->msg_ctime);
455 	err |= __put_user(m->msg_cbytes, &up->msg_cbytes);
456 	err |= __put_user(m->msg_qnum, &up->msg_qnum);
457 	err |= __put_user(m->msg_qbytes, &up->msg_qbytes);
458 	err |= __put_user(m->msg_lspid, &up->msg_lspid);
459 	err |= __put_user(m->msg_lrpid, &up->msg_lrpid);
460 	return err;
461 }
462 
compat_sys_msgctl(int first,int second,void __user * uptr)463 long compat_sys_msgctl(int first, int second, void __user *uptr)
464 {
465 	int err, err2;
466 	struct msqid64_ds m64;
467 	int version = compat_ipc_parse_version(&second);
468 	void __user *p;
469 
470 	memset(&m64, 0, sizeof(m64));
471 
472 	switch (second & (~IPC_64)) {
473 	case IPC_INFO:
474 	case IPC_RMID:
475 	case MSG_INFO:
476 		err = sys_msgctl(first, second, uptr);
477 		break;
478 
479 	case IPC_SET:
480 		if (version == IPC_64) {
481 			err = get_compat_msqid64(&m64, uptr);
482 		} else {
483 			err = get_compat_msqid(&m64, uptr);
484 		}
485 		if (err)
486 			break;
487 		p = compat_alloc_user_space(sizeof(m64));
488 		if (copy_to_user(p, &m64, sizeof(m64)))
489 			err = -EFAULT;
490 		else
491 			err = sys_msgctl(first, second, p);
492 		break;
493 
494 	case IPC_STAT:
495 	case MSG_STAT:
496 		p = compat_alloc_user_space(sizeof(m64));
497 		err = sys_msgctl(first, second, p);
498 		if (err < 0)
499 			break;
500 		if (copy_from_user(&m64, p, sizeof(m64)))
501 			err2 = -EFAULT;
502 		else if (version == IPC_64)
503 			err2 = put_compat_msqid64_ds(&m64, uptr);
504 		else
505 			err2 = put_compat_msqid_ds(&m64, uptr);
506 		if (err2)
507 			err = -EFAULT;
508 		break;
509 
510 	default:
511 		err = -EINVAL;
512 		break;
513 	}
514 	return err;
515 }
516 
517 #ifdef CONFIG_ARCH_WANT_OLD_COMPAT_IPC
compat_sys_shmat(int first,int second,compat_uptr_t third,int version,void __user * uptr)518 long compat_sys_shmat(int first, int second, compat_uptr_t third, int version,
519 			void __user *uptr)
520 {
521 	int err;
522 	unsigned long raddr;
523 	compat_ulong_t __user *uaddr;
524 
525 	if (version == 1)
526 		return -EINVAL;
527 	err = do_shmat(first, uptr, second, &raddr);
528 	if (err < 0)
529 		return err;
530 	uaddr = compat_ptr(third);
531 	return put_user(raddr, uaddr);
532 }
533 #else
compat_sys_shmat(int shmid,compat_uptr_t shmaddr,int shmflg)534 long compat_sys_shmat(int shmid, compat_uptr_t shmaddr, int shmflg)
535 {
536 	unsigned long ret;
537 	long err;
538 
539 	err = do_shmat(shmid, compat_ptr(shmaddr), shmflg, &ret);
540 	if (err)
541 		return err;
542 	force_successful_syscall_return();
543 	return (long)ret;
544 }
545 #endif
546 
get_compat_shmid64_ds(struct shmid64_ds * s64,struct compat_shmid64_ds __user * up64)547 static inline int get_compat_shmid64_ds(struct shmid64_ds *s64,
548 					struct compat_shmid64_ds __user *up64)
549 {
550 	if (!access_ok(VERIFY_READ, up64, sizeof(*up64)))
551 		return -EFAULT;
552 	return __get_compat_ipc64_perm(&s64->shm_perm, &up64->shm_perm);
553 }
554 
get_compat_shmid_ds(struct shmid64_ds * s,struct compat_shmid_ds __user * up)555 static inline int get_compat_shmid_ds(struct shmid64_ds *s,
556 				      struct compat_shmid_ds __user *up)
557 {
558 	if (!access_ok(VERIFY_READ, up, sizeof(*up)))
559 		return -EFAULT;
560 	return __get_compat_ipc_perm(&s->shm_perm, &up->shm_perm);
561 }
562 
put_compat_shmid64_ds(struct shmid64_ds * s64,struct compat_shmid64_ds __user * up64)563 static inline int put_compat_shmid64_ds(struct shmid64_ds *s64,
564 					struct compat_shmid64_ds __user *up64)
565 {
566 	int err;
567 
568 	if (!access_ok(VERIFY_WRITE, up64, sizeof(*up64)))
569 		return -EFAULT;
570 	err  = __put_compat_ipc64_perm(&s64->shm_perm, &up64->shm_perm);
571 	err |= __put_user(s64->shm_atime, &up64->shm_atime);
572 	err |= __put_user(s64->shm_dtime, &up64->shm_dtime);
573 	err |= __put_user(s64->shm_ctime, &up64->shm_ctime);
574 	err |= __put_user(s64->shm_segsz, &up64->shm_segsz);
575 	err |= __put_user(s64->shm_nattch, &up64->shm_nattch);
576 	err |= __put_user(s64->shm_cpid, &up64->shm_cpid);
577 	err |= __put_user(s64->shm_lpid, &up64->shm_lpid);
578 	return err;
579 }
580 
put_compat_shmid_ds(struct shmid64_ds * s,struct compat_shmid_ds __user * up)581 static inline int put_compat_shmid_ds(struct shmid64_ds *s,
582 				      struct compat_shmid_ds __user *up)
583 {
584 	int err;
585 
586 	if (!access_ok(VERIFY_WRITE, up, sizeof(*up)))
587 		return -EFAULT;
588 	err  = __put_compat_ipc_perm(&s->shm_perm, &up->shm_perm);
589 	err |= __put_user(s->shm_atime, &up->shm_atime);
590 	err |= __put_user(s->shm_dtime, &up->shm_dtime);
591 	err |= __put_user(s->shm_ctime, &up->shm_ctime);
592 	err |= __put_user(s->shm_segsz, &up->shm_segsz);
593 	err |= __put_user(s->shm_nattch, &up->shm_nattch);
594 	err |= __put_user(s->shm_cpid, &up->shm_cpid);
595 	err |= __put_user(s->shm_lpid, &up->shm_lpid);
596 	return err;
597 }
598 
put_compat_shminfo64(struct shminfo64 * smi,struct compat_shminfo64 __user * up64)599 static inline int put_compat_shminfo64(struct shminfo64 *smi,
600 				       struct compat_shminfo64 __user *up64)
601 {
602 	int err;
603 
604 	if (!access_ok(VERIFY_WRITE, up64, sizeof(*up64)))
605 		return -EFAULT;
606 	if (smi->shmmax > INT_MAX)
607 		smi->shmmax = INT_MAX;
608 	err  = __put_user(smi->shmmax, &up64->shmmax);
609 	err |= __put_user(smi->shmmin, &up64->shmmin);
610 	err |= __put_user(smi->shmmni, &up64->shmmni);
611 	err |= __put_user(smi->shmseg, &up64->shmseg);
612 	err |= __put_user(smi->shmall, &up64->shmall);
613 	return err;
614 }
615 
put_compat_shminfo(struct shminfo64 * smi,struct shminfo __user * up)616 static inline int put_compat_shminfo(struct shminfo64 *smi,
617 				     struct shminfo __user *up)
618 {
619 	int err;
620 
621 	if (!access_ok(VERIFY_WRITE, up, sizeof(*up)))
622 		return -EFAULT;
623 	if (smi->shmmax > INT_MAX)
624 		smi->shmmax = INT_MAX;
625 	err  = __put_user(smi->shmmax, &up->shmmax);
626 	err |= __put_user(smi->shmmin, &up->shmmin);
627 	err |= __put_user(smi->shmmni, &up->shmmni);
628 	err |= __put_user(smi->shmseg, &up->shmseg);
629 	err |= __put_user(smi->shmall, &up->shmall);
630 	return err;
631 }
632 
put_compat_shm_info(struct shm_info __user * ip,struct compat_shm_info __user * uip)633 static inline int put_compat_shm_info(struct shm_info __user *ip,
634 				      struct compat_shm_info __user *uip)
635 {
636 	int err;
637 	struct shm_info si;
638 
639 	if (!access_ok(VERIFY_WRITE, uip, sizeof(*uip)) ||
640 	    copy_from_user(&si, ip, sizeof(si)))
641 		return -EFAULT;
642 	err  = __put_user(si.used_ids, &uip->used_ids);
643 	err |= __put_user(si.shm_tot, &uip->shm_tot);
644 	err |= __put_user(si.shm_rss, &uip->shm_rss);
645 	err |= __put_user(si.shm_swp, &uip->shm_swp);
646 	err |= __put_user(si.swap_attempts, &uip->swap_attempts);
647 	err |= __put_user(si.swap_successes, &uip->swap_successes);
648 	return err;
649 }
650 
compat_sys_shmctl(int first,int second,void __user * uptr)651 long compat_sys_shmctl(int first, int second, void __user *uptr)
652 {
653 	void __user *p;
654 	struct shmid64_ds s64;
655 	struct shminfo64 smi;
656 	int err, err2;
657 	int version = compat_ipc_parse_version(&second);
658 
659 	memset(&s64, 0, sizeof(s64));
660 
661 	switch (second & (~IPC_64)) {
662 	case IPC_RMID:
663 	case SHM_LOCK:
664 	case SHM_UNLOCK:
665 		err = sys_shmctl(first, second, uptr);
666 		break;
667 
668 	case IPC_INFO:
669 		p = compat_alloc_user_space(sizeof(smi));
670 		err = sys_shmctl(first, second, p);
671 		if (err < 0)
672 			break;
673 		if (copy_from_user(&smi, p, sizeof(smi)))
674 			err2 = -EFAULT;
675 		else if (version == IPC_64)
676 			err2 = put_compat_shminfo64(&smi, uptr);
677 		else
678 			err2 = put_compat_shminfo(&smi, uptr);
679 		if (err2)
680 			err = -EFAULT;
681 		break;
682 
683 
684 	case IPC_SET:
685 		if (version == IPC_64) {
686 			err = get_compat_shmid64_ds(&s64, uptr);
687 		} else {
688 			err = get_compat_shmid_ds(&s64, uptr);
689 		}
690 		if (err)
691 			break;
692 		p = compat_alloc_user_space(sizeof(s64));
693 		if (copy_to_user(p, &s64, sizeof(s64)))
694 			err = -EFAULT;
695 		else
696 			err = sys_shmctl(first, second, p);
697 		break;
698 
699 	case IPC_STAT:
700 	case SHM_STAT:
701 		p = compat_alloc_user_space(sizeof(s64));
702 		err = sys_shmctl(first, second, p);
703 		if (err < 0)
704 			break;
705 		if (copy_from_user(&s64, p, sizeof(s64)))
706 			err2 = -EFAULT;
707 		else if (version == IPC_64)
708 			err2 = put_compat_shmid64_ds(&s64, uptr);
709 		else
710 			err2 = put_compat_shmid_ds(&s64, uptr);
711 		if (err2)
712 			err = -EFAULT;
713 		break;
714 
715 	case SHM_INFO:
716 		p = compat_alloc_user_space(sizeof(struct shm_info));
717 		err = sys_shmctl(first, second, p);
718 		if (err < 0)
719 			break;
720 		err2 = put_compat_shm_info(p, uptr);
721 		if (err2)
722 			err = -EFAULT;
723 		break;
724 
725 	default:
726 		err = -EINVAL;
727 		break;
728 	}
729 	return err;
730 }
731 
compat_sys_semtimedop(int semid,struct sembuf __user * tsems,unsigned nsops,const struct compat_timespec __user * timeout)732 long compat_sys_semtimedop(int semid, struct sembuf __user *tsems,
733 		unsigned nsops, const struct compat_timespec __user *timeout)
734 {
735 	struct timespec __user *ts64 = NULL;
736 	if (timeout) {
737 		struct timespec ts;
738 		ts64 = compat_alloc_user_space(sizeof(*ts64));
739 		if (get_compat_timespec(&ts, timeout))
740 			return -EFAULT;
741 		if (copy_to_user(ts64, &ts, sizeof(ts)))
742 			return -EFAULT;
743 	}
744 	return sys_semtimedop(semid, tsems, nsops, ts64);
745 }
746