1 /*
2  *  arch/s390x/kernel/linux32.c
3  *
4  *  S390 version
5  *    Copyright (C) 2000 IBM Deutschland Entwicklung GmbH, IBM Corporation
6  *    Author(s): Martin Schwidefsky (schwidefsky@de.ibm.com),
7  *               Gerhard Tonn (ton@de.ibm.com)
8  *
9  *  Conversion between 31bit and 64bit native syscalls.
10  *
11  * Heavily inspired by the 32-bit Sparc compat code which is
12  * Copyright (C) 1997,1998 Jakub Jelinek (jj@sunsite.mff.cuni.cz)
13  * Copyright (C) 1997 David S. Miller (davem@caip.rutgers.edu)
14  *
15  */
16 
17 
18 #include <linux/config.h>
19 #include <linux/kernel.h>
20 #include <linux/sched.h>
21 #include <linux/fs.h>
22 #include <linux/mm.h>
23 #include <linux/file.h>
24 #include <linux/signal.h>
25 #include <linux/utime.h>
26 #include <linux/resource.h>
27 #include <linux/times.h>
28 #include <linux/utsname.h>
29 #include <linux/timex.h>
30 #include <linux/smp.h>
31 #include <linux/smp_lock.h>
32 #include <linux/sem.h>
33 #include <linux/msg.h>
34 #include <linux/shm.h>
35 #include <linux/slab.h>
36 #include <linux/uio.h>
37 #include <linux/nfs_fs.h>
38 #include <linux/smb_fs.h>
39 #include <linux/smb_mount.h>
40 #include <linux/ncp_fs.h>
41 #include <linux/quota.h>
42 #include <linux/quotacompat.h>
43 #include <linux/module.h>
44 #include <linux/sunrpc/svc.h>
45 #include <linux/nfsd/nfsd.h>
46 #include <linux/nfsd/cache.h>
47 #include <linux/nfsd/xdr.h>
48 #include <linux/nfsd/syscall.h>
49 #include <linux/poll.h>
50 #include <linux/personality.h>
51 #include <linux/stat.h>
52 #include <linux/filter.h>
53 #include <linux/highmem.h>
54 #include <linux/highuid.h>
55 #include <linux/mman.h>
56 #include <linux/ipv6.h>
57 #include <linux/in.h>
58 #include <linux/icmpv6.h>
59 #include <linux/sysctl.h>
60 
61 #include <asm/types.h>
62 #include <asm/ipc.h>
63 #include <asm/uaccess.h>
64 #include <asm/semaphore.h>
65 
66 #include <net/scm.h>
67 #include <net/sock.h>
68 
69 #include "linux32.h"
70 
71 extern asmlinkage long sys_chown(const char *, uid_t,gid_t);
72 extern asmlinkage long sys_lchown(const char *, uid_t,gid_t);
73 extern asmlinkage long sys_fchown(unsigned int, uid_t,gid_t);
74 extern asmlinkage long sys_setregid(gid_t, gid_t);
75 extern asmlinkage long sys_setgid(gid_t);
76 extern asmlinkage long sys_setreuid(uid_t, uid_t);
77 extern asmlinkage long sys_setuid(uid_t);
78 extern asmlinkage long sys_setresuid(uid_t, uid_t, uid_t);
79 extern asmlinkage long sys_setresgid(gid_t, gid_t, gid_t);
80 extern asmlinkage long sys_setfsuid(uid_t);
81 extern asmlinkage long sys_setfsgid(gid_t);
82 
83 /* For this source file, we want overflow handling. */
84 
85 #undef high2lowuid
86 #undef high2lowgid
87 #undef low2highuid
88 #undef low2highgid
89 #undef SET_UID16
90 #undef SET_GID16
91 #undef NEW_TO_OLD_UID
92 #undef NEW_TO_OLD_GID
93 #undef SET_OLDSTAT_UID
94 #undef SET_OLDSTAT_GID
95 #undef SET_STAT_UID
96 #undef SET_STAT_GID
97 
98 #define high2lowuid(uid) ((uid) > 65535) ? (u16)overflowuid : (u16)(uid)
99 #define high2lowgid(gid) ((gid) > 65535) ? (u16)overflowgid : (u16)(gid)
100 #define low2highuid(uid) ((uid) == (u16)-1) ? (uid_t)-1 : (uid_t)(uid)
101 #define low2highgid(gid) ((gid) == (u16)-1) ? (gid_t)-1 : (gid_t)(gid)
102 #define SET_UID16(var, uid)	var = high2lowuid(uid)
103 #define SET_GID16(var, gid)	var = high2lowgid(gid)
104 #define NEW_TO_OLD_UID(uid)	high2lowuid(uid)
105 #define NEW_TO_OLD_GID(gid)	high2lowgid(gid)
106 #define SET_OLDSTAT_UID(stat, uid)	(stat).st_uid = high2lowuid(uid)
107 #define SET_OLDSTAT_GID(stat, gid)	(stat).st_gid = high2lowgid(gid)
108 #define SET_STAT_UID(stat, uid)		(stat).st_uid = high2lowuid(uid)
109 #define SET_STAT_GID(stat, gid)		(stat).st_gid = high2lowgid(gid)
110 
sys32_chown16(const char * filename,u16 user,u16 group)111 asmlinkage long sys32_chown16(const char * filename, u16 user, u16 group)
112 {
113 	return sys_chown(filename, low2highuid(user), low2highgid(group));
114 }
115 
sys32_lchown16(const char * filename,u16 user,u16 group)116 asmlinkage long sys32_lchown16(const char * filename, u16 user, u16 group)
117 {
118 	return sys_lchown(filename, low2highuid(user), low2highgid(group));
119 }
120 
sys32_fchown16(unsigned int fd,u16 user,u16 group)121 asmlinkage long sys32_fchown16(unsigned int fd, u16 user, u16 group)
122 {
123 	return sys_fchown(fd, low2highuid(user), low2highgid(group));
124 }
125 
sys32_setregid16(u16 rgid,u16 egid)126 asmlinkage long sys32_setregid16(u16 rgid, u16 egid)
127 {
128 	return sys_setregid(low2highgid(rgid), low2highgid(egid));
129 }
130 
sys32_setgid16(u16 gid)131 asmlinkage long sys32_setgid16(u16 gid)
132 {
133 	return sys_setgid((gid_t)gid);
134 }
135 
sys32_setreuid16(u16 ruid,u16 euid)136 asmlinkage long sys32_setreuid16(u16 ruid, u16 euid)
137 {
138 	return sys_setreuid(low2highuid(ruid), low2highuid(euid));
139 }
140 
sys32_setuid16(u16 uid)141 asmlinkage long sys32_setuid16(u16 uid)
142 {
143 	return sys_setuid((uid_t)uid);
144 }
145 
sys32_setresuid16(u16 ruid,u16 euid,u16 suid)146 asmlinkage long sys32_setresuid16(u16 ruid, u16 euid, u16 suid)
147 {
148 	return sys_setresuid(low2highuid(ruid), low2highuid(euid),
149 		low2highuid(suid));
150 }
151 
sys32_getresuid16(u16 * ruid,u16 * euid,u16 * suid)152 asmlinkage long sys32_getresuid16(u16 *ruid, u16 *euid, u16 *suid)
153 {
154 	int retval;
155 
156 	if (!(retval = put_user(high2lowuid(current->uid), ruid)) &&
157 	    !(retval = put_user(high2lowuid(current->euid), euid)))
158 		retval = put_user(high2lowuid(current->suid), suid);
159 
160 	return retval;
161 }
162 
sys32_setresgid16(u16 rgid,u16 egid,u16 sgid)163 asmlinkage long sys32_setresgid16(u16 rgid, u16 egid, u16 sgid)
164 {
165 	return sys_setresgid(low2highgid(rgid), low2highgid(egid),
166 		low2highgid(sgid));
167 }
168 
sys32_getresgid16(u16 * rgid,u16 * egid,u16 * sgid)169 asmlinkage long sys32_getresgid16(u16 *rgid, u16 *egid, u16 *sgid)
170 {
171 	int retval;
172 
173 	if (!(retval = put_user(high2lowgid(current->gid), rgid)) &&
174 	    !(retval = put_user(high2lowgid(current->egid), egid)))
175 		retval = put_user(high2lowgid(current->sgid), sgid);
176 
177 	return retval;
178 }
179 
sys32_setfsuid16(u16 uid)180 asmlinkage long sys32_setfsuid16(u16 uid)
181 {
182 	return sys_setfsuid((uid_t)uid);
183 }
184 
sys32_setfsgid16(u16 gid)185 asmlinkage long sys32_setfsgid16(u16 gid)
186 {
187 	return sys_setfsgid((gid_t)gid);
188 }
189 
sys32_getgroups16(int gidsetsize,u16 * grouplist)190 asmlinkage long sys32_getgroups16(int gidsetsize, u16 *grouplist)
191 {
192 	u16 groups[NGROUPS];
193 	int i,j;
194 
195 	if (gidsetsize < 0)
196 		return -EINVAL;
197 	i = current->ngroups;
198 	if (gidsetsize) {
199 		if (i > gidsetsize)
200 			return -EINVAL;
201 		for(j=0;j<i;j++)
202 			groups[j] = current->groups[j];
203 		if (copy_to_user(grouplist, groups, sizeof(u16)*i))
204 			return -EFAULT;
205 	}
206 	return i;
207 }
208 
sys32_setgroups16(int gidsetsize,u16 * grouplist)209 asmlinkage long sys32_setgroups16(int gidsetsize, u16 *grouplist)
210 {
211 	u16 groups[NGROUPS];
212 	int i;
213 
214 	if (!capable(CAP_SETGID))
215 		return -EPERM;
216 	if ((unsigned) gidsetsize > NGROUPS)
217 		return -EINVAL;
218 	if (copy_from_user(groups, grouplist, gidsetsize * sizeof(u16)))
219 		return -EFAULT;
220 	for (i = 0 ; i < gidsetsize ; i++)
221 		current->groups[i] = (gid_t)groups[i];
222 	current->ngroups = gidsetsize;
223 	return 0;
224 }
225 
sys32_getuid16(void)226 asmlinkage long sys32_getuid16(void)
227 {
228 	return high2lowuid(current->uid);
229 }
230 
sys32_geteuid16(void)231 asmlinkage long sys32_geteuid16(void)
232 {
233 	return high2lowuid(current->euid);
234 }
235 
sys32_getgid16(void)236 asmlinkage long sys32_getgid16(void)
237 {
238 	return high2lowgid(current->gid);
239 }
240 
sys32_getegid16(void)241 asmlinkage long sys32_getegid16(void)
242 {
243 	return high2lowgid(current->egid);
244 }
245 
246 /* 32-bit timeval and related flotsam.  */
247 
248 struct timeval32
249 {
250     int tv_sec, tv_usec;
251 };
252 
253 struct itimerval32
254 {
255     struct timeval32 it_interval;
256     struct timeval32 it_value;
257 };
258 
get_tv32(struct timeval * o,struct timeval32 * i)259 static inline long get_tv32(struct timeval *o, struct timeval32 *i)
260 {
261 	return (!access_ok(VERIFY_READ, tv32, sizeof(*tv32)) ||
262 		(__get_user(o->tv_sec, &i->tv_sec) |
263 		 __get_user(o->tv_usec, &i->tv_usec)));
264 }
265 
put_tv32(struct timeval32 * o,struct timeval * i)266 static inline long put_tv32(struct timeval32 *o, struct timeval *i)
267 {
268 	return (!access_ok(VERIFY_WRITE, o, sizeof(*o)) ||
269 		(__put_user(i->tv_sec, &o->tv_sec) |
270 		 __put_user(i->tv_usec, &o->tv_usec)));
271 }
272 
get_it32(struct itimerval * o,struct itimerval32 * i)273 static inline long get_it32(struct itimerval *o, struct itimerval32 *i)
274 {
275 	return (!access_ok(VERIFY_READ, i32, sizeof(*i32)) ||
276 		(__get_user(o->it_interval.tv_sec, &i->it_interval.tv_sec) |
277 		 __get_user(o->it_interval.tv_usec, &i->it_interval.tv_usec) |
278 		 __get_user(o->it_value.tv_sec, &i->it_value.tv_sec) |
279 		 __get_user(o->it_value.tv_usec, &i->it_value.tv_usec)));
280 }
281 
put_it32(struct itimerval32 * o,struct itimerval * i)282 static inline long put_it32(struct itimerval32 *o, struct itimerval *i)
283 {
284 	return (!access_ok(VERIFY_WRITE, i32, sizeof(*i32)) ||
285 		(__put_user(i->it_interval.tv_sec, &o->it_interval.tv_sec) |
286 		 __put_user(i->it_interval.tv_usec, &o->it_interval.tv_usec) |
287 		 __put_user(i->it_value.tv_sec, &o->it_value.tv_sec) |
288 		 __put_user(i->it_value.tv_usec, &o->it_value.tv_usec)));
289 }
290 
291 struct msgbuf32 { s32 mtype; char mtext[1]; };
292 
293 struct ipc64_perm_ds32
294 {
295         __kernel_key_t          key;
296         __kernel_uid32_t        uid;
297         __kernel_gid32_t        gid;
298         __kernel_uid32_t        cuid;
299         __kernel_gid32_t        cgid;
300         __kernel_mode_t32       mode;
301         unsigned short          __pad1;
302         unsigned short          seq;
303         unsigned short          __pad2;
304         unsigned int            __unused1;
305         unsigned int            __unused2;
306 };
307 
308 struct ipc_perm32
309 {
310 	key_t    	  key;
311         __kernel_uid_t32  uid;
312         __kernel_gid_t32  gid;
313         __kernel_uid_t32  cuid;
314         __kernel_gid_t32  cgid;
315         __kernel_mode_t32 mode;
316         unsigned short  seq;
317 };
318 
319 struct semid_ds32 {
320         struct ipc_perm32 sem_perm;               /* permissions .. see ipc.h */
321         __kernel_time_t32 sem_otime;              /* last semop time */
322         __kernel_time_t32 sem_ctime;              /* last change time */
323         u32 sem_base;              /* ptr to first semaphore in array */
324         u32 sem_pending;          /* pending operations to be processed */
325         u32 sem_pending_last;    /* last pending operation */
326         u32 undo;                  /* undo requests on this array */
327         unsigned short  sem_nsems;              /* no. of semaphores in array */
328 };
329 
330 struct semid64_ds32 {
331 	struct ipc64_perm_ds32 sem_perm;
332 	unsigned int	  __pad1;
333 	__kernel_time_t32 sem_otime;
334 	unsigned int	  __pad2;
335 	__kernel_time_t32 sem_ctime;
336 	u32 sem_nsems;
337 	u32 __unused1;
338 	u32 __unused2;
339 };
340 
341 struct msqid_ds32
342 {
343         struct ipc_perm32 msg_perm;
344         u32 msg_first;
345         u32 msg_last;
346         __kernel_time_t32 msg_stime;
347         __kernel_time_t32 msg_rtime;
348         __kernel_time_t32 msg_ctime;
349         u32 wwait;
350         u32 rwait;
351         unsigned short msg_cbytes;
352         unsigned short msg_qnum;
353         unsigned short msg_qbytes;
354         __kernel_ipc_pid_t32 msg_lspid;
355         __kernel_ipc_pid_t32 msg_lrpid;
356 };
357 
358 struct msqid64_ds32 {
359 	struct ipc64_perm_ds32 msg_perm;
360 	unsigned int   __pad1;
361 	__kernel_time_t32 msg_stime;
362 	unsigned int   __pad2;
363 	__kernel_time_t32 msg_rtime;
364 	unsigned int   __pad3;
365 	__kernel_time_t32 msg_ctime;
366 	unsigned int  msg_cbytes;
367 	unsigned int  msg_qnum;
368 	unsigned int  msg_qbytes;
369 	__kernel_pid_t32 msg_lspid;
370 	__kernel_pid_t32 msg_lrpid;
371 	unsigned int  __unused1;
372 	unsigned int  __unused2;
373 };
374 
375 
376 struct shmid_ds32 {
377 	struct ipc_perm32       shm_perm;
378 	int                     shm_segsz;
379 	__kernel_time_t32       shm_atime;
380 	__kernel_time_t32       shm_dtime;
381 	__kernel_time_t32       shm_ctime;
382 	__kernel_ipc_pid_t32    shm_cpid;
383 	__kernel_ipc_pid_t32    shm_lpid;
384 	unsigned short          shm_nattch;
385 };
386 
387 struct shmid64_ds32 {
388 	struct ipc64_perm_ds32	shm_perm;
389 	__kernel_size_t32	shm_segsz;
390 	__kernel_time_t32	shm_atime;
391 	unsigned int		__unused1;
392 	__kernel_time_t32	shm_dtime;
393 	unsigned int		__unused2;
394 	__kernel_time_t32	shm_ctime;
395 	unsigned int		__unused3;
396 	__kernel_pid_t32	shm_cpid;
397 	__kernel_pid_t32	shm_lpid;
398 	unsigned int		shm_nattch;
399 	unsigned int		__unused4;
400 	unsigned int		__unused5;
401 };
402 
403 
404 /*
405  * sys32_ipc() is the de-multiplexer for the SysV IPC calls in 32bit emulation..
406  *
407  * This is really horribly ugly.
408  */
409 #define IPCOP_MASK(__x)	(1UL << (__x))
do_sys32_semctl(int first,int second,int third,void * uptr)410 static int do_sys32_semctl(int first, int second, int third, void *uptr)
411 {
412 	union semun fourth;
413 	u32 pad;
414 	int err = -EINVAL;
415 
416 	if (!uptr)
417 		goto out;
418 	err = -EFAULT;
419 	if (get_user (pad, (u32 *)uptr))
420 		goto out;
421 	if(third == SETVAL)
422 		fourth.val = (int)pad;
423 	else
424 		fourth.__pad = (void *)A(pad);
425 	if (IPCOP_MASK (third) &
426 	    (IPCOP_MASK (IPC_INFO) | IPCOP_MASK (SEM_INFO) | IPCOP_MASK (GETVAL) |
427 	     IPCOP_MASK (GETPID) | IPCOP_MASK (GETNCNT) | IPCOP_MASK (GETZCNT) |
428 	     IPCOP_MASK (GETALL) | IPCOP_MASK (SETALL) | IPCOP_MASK (IPC_RMID))) {
429 		err = sys_semctl (first, second, third, fourth);
430 	} else if (third & IPC_64) {
431 		struct semid64_ds s;
432 		struct semid64_ds32 *usp = (struct semid64_ds32 *)A(pad);
433 		mm_segment_t old_fs;
434 		int need_back_translation;
435 
436 		if (third == (IPC_SET|IPC_64)) {
437 			err = get_user (s.sem_perm.uid, &usp->sem_perm.uid);
438 			err |= __get_user (s.sem_perm.gid, &usp->sem_perm.gid);
439 			err |= __get_user (s.sem_perm.mode, &usp->sem_perm.mode);
440 			if (err)
441 				goto out;
442 			fourth.__pad = &s;
443 		}
444 		need_back_translation =
445 			(IPCOP_MASK (third) &
446 			 (IPCOP_MASK (SEM_STAT) | IPCOP_MASK (IPC_STAT))) != 0;
447 		if (need_back_translation)
448 			fourth.__pad = &s;
449 		old_fs = get_fs ();
450 		set_fs (KERNEL_DS);
451 		err = sys_semctl (first, second, third, fourth);
452 		set_fs (old_fs);
453 		if (need_back_translation) {
454 			int err2 = put_user (s.sem_perm.key, &usp->sem_perm.key);
455 			err2 |= __put_user (high2lowuid(s.sem_perm.uid), &usp->sem_perm.uid);
456 			err2 |= __put_user (high2lowgid(s.sem_perm.gid), &usp->sem_perm.gid);
457 			err2 |= __put_user (high2lowuid(s.sem_perm.cuid), &usp->sem_perm.cuid);
458 			err2 |= __put_user (high2lowgid(s.sem_perm.cgid), &usp->sem_perm.cgid);
459 			err2 |= __put_user (s.sem_perm.mode, &usp->sem_perm.mode);
460 			err2 |= __put_user (s.sem_perm.seq, &usp->sem_perm.seq);
461 			err2 |= __put_user (s.sem_otime, &usp->sem_otime);
462 			err2 |= __put_user (s.sem_ctime, &usp->sem_ctime);
463 			err2 |= __put_user (s.sem_nsems, &usp->sem_nsems);
464 			if (err2) err = -EFAULT;
465 		}
466 	} else {
467 		struct semid_ds s;
468 		struct semid_ds32 *usp = (struct semid_ds32 *)A(pad);
469 		mm_segment_t old_fs;
470 		int need_back_translation;
471 
472 		if (third == IPC_SET) {
473 			err = get_user (s.sem_perm.uid, &usp->sem_perm.uid);
474 			err |= __get_user (s.sem_perm.gid, &usp->sem_perm.gid);
475 			err |= __get_user (s.sem_perm.mode, &usp->sem_perm.mode);
476 			if (err)
477 				goto out;
478 			fourth.__pad = &s;
479 		}
480 		need_back_translation =
481 			(IPCOP_MASK (third) &
482 			 (IPCOP_MASK (SEM_STAT) | IPCOP_MASK (IPC_STAT))) != 0;
483 		if (need_back_translation)
484 			fourth.__pad = &s;
485 		old_fs = get_fs ();
486 		set_fs (KERNEL_DS);
487 		err = sys_semctl (first, second, third, fourth);
488 		set_fs (old_fs);
489 		if (need_back_translation) {
490 			int err2 = put_user (s.sem_perm.key, &usp->sem_perm.key);
491 			err2 |= __put_user (high2lowuid(s.sem_perm.uid), &usp->sem_perm.uid);
492 			err2 |= __put_user (high2lowgid(s.sem_perm.gid), &usp->sem_perm.gid);
493 			err2 |= __put_user (high2lowuid(s.sem_perm.cuid), &usp->sem_perm.cuid);
494 			err2 |= __put_user (high2lowgid(s.sem_perm.cgid), &usp->sem_perm.cgid);
495 			err2 |= __put_user (s.sem_perm.mode, &usp->sem_perm.mode);
496 			err2 |= __put_user (s.sem_perm.seq, &usp->sem_perm.seq);
497 			err2 |= __put_user (s.sem_otime, &usp->sem_otime);
498 			err2 |= __put_user (s.sem_ctime, &usp->sem_ctime);
499 			err2 |= __put_user (s.sem_nsems, &usp->sem_nsems);
500 			if (err2) err = -EFAULT;
501 		}
502 	}
503 out:
504 	return err;
505 }
506 
do_sys32_msgsnd(int first,int second,int third,void * uptr)507 static int do_sys32_msgsnd (int first, int second, int third, void *uptr)
508 {
509 	struct msgbuf *p = kmalloc (second + sizeof (struct msgbuf), GFP_USER);
510 	struct msgbuf32 *up = (struct msgbuf32 *)uptr;
511 	mm_segment_t old_fs;
512 	int err;
513 
514 	if (!p)
515 		return -ENOMEM;
516 
517 	err = -EINVAL;
518 	if (second > MSGMAX || first < 0 || second < 0)
519 		goto out;
520 
521 	err = -EFAULT;
522 	if (!uptr)
523 		goto out;
524 	if (get_user (p->mtype, &up->mtype) ||
525 	    __copy_from_user (p->mtext, &up->mtext, second))
526 		goto out;
527 	old_fs = get_fs ();
528 	set_fs (KERNEL_DS);
529 	err = sys_msgsnd (first, p, second, third);
530 	set_fs (old_fs);
531 out:
532 	kfree (p);
533 	return err;
534 }
535 
do_sys32_msgrcv(int first,int second,int msgtyp,int third,int version,void * uptr)536 static int do_sys32_msgrcv (int first, int second, int msgtyp, int third,
537 			    int version, void *uptr)
538 {
539 	struct msgbuf32 *up;
540 	struct msgbuf *p;
541 	mm_segment_t old_fs;
542 	int err;
543 
544 	if (first < 0 || second < 0)
545 		return -EINVAL;
546 
547 	if (!version) {
548 		struct ipc_kludge_32 *uipck = (struct ipc_kludge_32 *)uptr;
549 		struct ipc_kludge_32 ipck;
550 
551 		err = -EINVAL;
552 		if (!uptr)
553 			goto out;
554 		err = -EFAULT;
555 		if (copy_from_user (&ipck, uipck, sizeof (struct ipc_kludge_32)))
556 			goto out;
557 		uptr = (void *)A(ipck.msgp);
558 		msgtyp = ipck.msgtyp;
559 	}
560 	err = -ENOMEM;
561 	p = kmalloc (second + sizeof (struct msgbuf), GFP_USER);
562 	if (!p)
563 		goto out;
564 	old_fs = get_fs ();
565 	set_fs (KERNEL_DS);
566 	err = sys_msgrcv (first, p, second, msgtyp, third);
567 	set_fs (old_fs);
568 	if (err < 0)
569 		goto free_then_out;
570 	up = (struct msgbuf32 *)uptr;
571 	if (put_user (p->mtype, &up->mtype) ||
572 	    __copy_to_user (&up->mtext, p->mtext, err))
573 		err = -EFAULT;
574 free_then_out:
575 	kfree (p);
576 out:
577 	return err;
578 }
579 
do_sys32_msgctl(int first,int second,void * uptr)580 static int do_sys32_msgctl (int first, int second, void *uptr)
581 {
582 	int err;
583 
584 	if (IPCOP_MASK (second) &
585 	    (IPCOP_MASK (IPC_INFO) | IPCOP_MASK (MSG_INFO) |
586 	     IPCOP_MASK (IPC_RMID))) {
587 		err = sys_msgctl (first, second, (struct msqid_ds *)uptr);
588 	} else if (second & IPC_64) {
589 		struct msqid64_ds m;
590 		struct msqid64_ds32 *up = (struct msqid64_ds32 *)uptr;
591 		mm_segment_t old_fs;
592 
593 		if (second == (IPC_SET|IPC_64)) {
594 			err = get_user (m.msg_perm.uid, &up->msg_perm.uid);
595 			err |= __get_user (m.msg_perm.gid, &up->msg_perm.gid);
596 			err |= __get_user (m.msg_perm.mode, &up->msg_perm.mode);
597 			err |= __get_user (m.msg_qbytes, &up->msg_qbytes);
598 			if (err)
599 				goto out;
600 		}
601 		old_fs = get_fs ();
602 		set_fs (KERNEL_DS);
603 		err = sys_msgctl (first, second, (struct msqid_ds *)&m);
604 		set_fs (old_fs);
605 		if (IPCOP_MASK (second) &
606 		    (IPCOP_MASK (MSG_STAT) | IPCOP_MASK (IPC_STAT))) {
607 			int err2 = put_user (m.msg_perm.key, &up->msg_perm.key);
608 			err2 |= __put_user (high2lowuid(m.msg_perm.uid), &up->msg_perm.uid);
609 			err2 |= __put_user (high2lowgid(m.msg_perm.gid), &up->msg_perm.gid);
610 			err2 |= __put_user (high2lowuid(m.msg_perm.cuid), &up->msg_perm.cuid);
611 			err2 |= __put_user (high2lowgid(m.msg_perm.cgid), &up->msg_perm.cgid);
612 			err2 |= __put_user (m.msg_perm.mode, &up->msg_perm.mode);
613 			err2 |= __put_user (m.msg_perm.seq, &up->msg_perm.seq);
614 			err2 |= __put_user (m.msg_stime, &up->msg_stime);
615 			err2 |= __put_user (m.msg_rtime, &up->msg_rtime);
616 			err2 |= __put_user (m.msg_ctime, &up->msg_ctime);
617 			err2 |= __put_user (m.msg_cbytes, &up->msg_cbytes);
618 			err2 |= __put_user (m.msg_qnum, &up->msg_qnum);
619 			err2 |= __put_user (m.msg_qbytes, &up->msg_qbytes);
620 			err2 |= __put_user (m.msg_lspid, &up->msg_lspid);
621 			err2 |= __put_user (m.msg_lrpid, &up->msg_lrpid);
622 			if (err2)
623 				err = -EFAULT;
624 		}
625 	} else {
626 		struct msqid_ds m;
627 		struct msqid_ds32 *up = (struct msqid_ds32 *)uptr;
628 		mm_segment_t old_fs;
629 
630 		if (second == IPC_SET) {
631 			err = get_user (m.msg_perm.uid, &up->msg_perm.uid);
632 			err |= __get_user (m.msg_perm.gid, &up->msg_perm.gid);
633 			err |= __get_user (m.msg_perm.mode, &up->msg_perm.mode);
634 			err |= __get_user (m.msg_qbytes, &up->msg_qbytes);
635 			if (err)
636 				goto out;
637 		}
638 		old_fs = get_fs ();
639 		set_fs (KERNEL_DS);
640 		err = sys_msgctl (first, second, &m);
641 		set_fs (old_fs);
642 		if (IPCOP_MASK (second) &
643 		    (IPCOP_MASK (MSG_STAT) | IPCOP_MASK (IPC_STAT))) {
644 			int err2 = put_user (m.msg_perm.key, &up->msg_perm.key);
645 			err2 |= __put_user (high2lowuid(m.msg_perm.uid), &up->msg_perm.uid);
646 			err2 |= __put_user (high2lowgid(m.msg_perm.gid), &up->msg_perm.gid);
647 			err2 |= __put_user (high2lowuid(m.msg_perm.cuid), &up->msg_perm.cuid);
648 			err2 |= __put_user (high2lowgid(m.msg_perm.cgid), &up->msg_perm.cgid);
649 			err2 |= __put_user (m.msg_perm.mode, &up->msg_perm.mode);
650 			err2 |= __put_user (m.msg_perm.seq, &up->msg_perm.seq);
651 			err2 |= __put_user (m.msg_stime, &up->msg_stime);
652 			err2 |= __put_user (m.msg_rtime, &up->msg_rtime);
653 			err2 |= __put_user (m.msg_ctime, &up->msg_ctime);
654 			err2 |= __put_user (m.msg_cbytes, &up->msg_cbytes);
655 			err2 |= __put_user (m.msg_qnum, &up->msg_qnum);
656 			err2 |= __put_user (m.msg_qbytes, &up->msg_qbytes);
657 			err2 |= __put_user (m.msg_lspid, &up->msg_lspid);
658 			err2 |= __put_user (m.msg_lrpid, &up->msg_lrpid);
659 			if (err2)
660 				err = -EFAULT;
661 		}
662 	}
663 
664 out:
665 	return err;
666 }
667 
do_sys32_shmat(int first,int second,int third,int version,void * uptr)668 static int do_sys32_shmat (int first, int second, int third, int version, void *uptr)
669 {
670 	unsigned long raddr;
671 	u32 *uaddr = (u32 *)A((u32)third);
672 	int err = -EINVAL;
673 
674 	if (version == 1)
675 		goto out;
676 	err = sys_shmat (first, uptr, second, &raddr);
677 	if (err)
678 		goto out;
679 	err = put_user (raddr, uaddr);
680 out:
681 	return err;
682 }
683 
do_sys32_shmctl(int first,int second,void * uptr)684 static int do_sys32_shmctl (int first, int second, void *uptr)
685 {
686 	int err;
687 
688 	if (IPCOP_MASK (second) &
689 	    (IPCOP_MASK (IPC_INFO) | IPCOP_MASK (SHM_LOCK) | IPCOP_MASK (SHM_UNLOCK) |
690 	     IPCOP_MASK (IPC_RMID))) {
691 		if (second == (IPC_INFO|IPC_64))
692 			second = IPC_INFO; /* So that we don't have to translate it */
693 		err = sys_shmctl (first, second, (struct shmid_ds *)uptr);
694 	} else if ((second & IPC_64) && second != (SHM_INFO|IPC_64)) {
695 		struct shmid64_ds s;
696 		struct shmid64_ds32 *up = (struct shmid64_ds32 *)uptr;
697 		mm_segment_t old_fs;
698 
699 		if (second == (IPC_SET|IPC_64)) {
700 			err = get_user (s.shm_perm.uid, &up->shm_perm.uid);
701 			err |= __get_user (s.shm_perm.gid, &up->shm_perm.gid);
702 			err |= __get_user (s.shm_perm.mode, &up->shm_perm.mode);
703 			if (err)
704 				goto out;
705 		}
706 		old_fs = get_fs ();
707 		set_fs (KERNEL_DS);
708 		err = sys_shmctl (first, second, (struct shmid_ds *)&s);
709 		set_fs (old_fs);
710 		if (err < 0)
711 			goto out;
712 
713 		/* Mask it even in this case so it becomes a CSE. */
714 		if (IPCOP_MASK (second) &
715 		    (IPCOP_MASK (SHM_STAT) | IPCOP_MASK (IPC_STAT))) {
716 			int err2 = put_user (s.shm_perm.key, &up->shm_perm.key);
717 			err2 |= __put_user (high2lowuid(s.shm_perm.uid), &up->shm_perm.uid);
718 			err2 |= __put_user (high2lowgid(s.shm_perm.gid), &up->shm_perm.gid);
719 			err2 |= __put_user (high2lowuid(s.shm_perm.cuid), &up->shm_perm.cuid);
720 			err2 |= __put_user (high2lowgid(s.shm_perm.cgid), &up->shm_perm.cgid);
721 			err2 |= __put_user (s.shm_perm.mode, &up->shm_perm.mode);
722 			err2 |= __put_user (s.shm_perm.seq, &up->shm_perm.seq);
723 			err2 |= __put_user (s.shm_atime, &up->shm_atime);
724 			err2 |= __put_user (s.shm_dtime, &up->shm_dtime);
725 			err2 |= __put_user (s.shm_ctime, &up->shm_ctime);
726 			err2 |= __put_user (s.shm_segsz, &up->shm_segsz);
727 			err2 |= __put_user (s.shm_nattch, &up->shm_nattch);
728 			err2 |= __put_user (s.shm_cpid, &up->shm_cpid);
729 			err2 |= __put_user (s.shm_lpid, &up->shm_lpid);
730 			if (err2)
731 				err = -EFAULT;
732 		}
733 	} else {
734 		struct shmid_ds s;
735 		struct shmid_ds32 *up = (struct shmid_ds32 *)uptr;
736 		mm_segment_t old_fs;
737 
738 		second &= ~IPC_64;
739 		if (second == IPC_SET) {
740 			err = get_user (s.shm_perm.uid, &up->shm_perm.uid);
741 			err |= __get_user (s.shm_perm.gid, &up->shm_perm.gid);
742 			err |= __get_user (s.shm_perm.mode, &up->shm_perm.mode);
743 			if (err)
744 				goto out;
745 		}
746 		old_fs = get_fs ();
747 		set_fs (KERNEL_DS);
748 		err = sys_shmctl (first, second, &s);
749 		set_fs (old_fs);
750 		if (err < 0)
751 			goto out;
752 
753 		/* Mask it even in this case so it becomes a CSE. */
754 		if (second == SHM_INFO) {
755 			struct shm_info32 {
756 				int used_ids;
757 				u32 shm_tot, shm_rss, shm_swp;
758 				u32 swap_attempts, swap_successes;
759 			} *uip = (struct shm_info32 *)uptr;
760 			struct shm_info *kp = (struct shm_info *)&s;
761 			int err2 = put_user (kp->used_ids, &uip->used_ids);
762 			err2 |= __put_user (kp->shm_tot, &uip->shm_tot);
763 			err2 |= __put_user (kp->shm_rss, &uip->shm_rss);
764 			err2 |= __put_user (kp->shm_swp, &uip->shm_swp);
765 			err2 |= __put_user (kp->swap_attempts, &uip->swap_attempts);
766 			err2 |= __put_user (kp->swap_successes, &uip->swap_successes);
767 			if (err2)
768 				err = -EFAULT;
769 		} else if (IPCOP_MASK (second) &
770 			   (IPCOP_MASK (SHM_STAT) | IPCOP_MASK (IPC_STAT))) {
771 			int err2 = put_user (s.shm_perm.key, &up->shm_perm.key);
772 			err2 |= __put_user (high2lowuid(s.shm_perm.uid), &up->shm_perm.uid);
773 			err2 |= __put_user (high2lowgid(s.shm_perm.gid), &up->shm_perm.gid);
774 			err2 |= __put_user (high2lowuid(s.shm_perm.cuid), &up->shm_perm.cuid);
775 			err2 |= __put_user (high2lowgid(s.shm_perm.cgid), &up->shm_perm.cgid);
776 			err2 |= __put_user (s.shm_perm.mode, &up->shm_perm.mode);
777 			err2 |= __put_user (s.shm_perm.seq, &up->shm_perm.seq);
778 			err2 |= __put_user (s.shm_atime, &up->shm_atime);
779 			err2 |= __put_user (s.shm_dtime, &up->shm_dtime);
780 			err2 |= __put_user (s.shm_ctime, &up->shm_ctime);
781 			err2 |= __put_user (s.shm_segsz, &up->shm_segsz);
782 			err2 |= __put_user (s.shm_nattch, &up->shm_nattch);
783 			err2 |= __put_user (s.shm_cpid, &up->shm_cpid);
784 			err2 |= __put_user (s.shm_lpid, &up->shm_lpid);
785 			if (err2)
786 				err = -EFAULT;
787 		}
788 	}
789 out:
790 	return err;
791 }
792 
sys32_ipc(u32 call,int first,int second,int third,u32 ptr,u32 fifth)793 asmlinkage int sys32_ipc (u32 call, int first, int second, int third, u32 ptr, u32 fifth)
794 {
795 	int version, err;
796 
797 	version = call >> 16; /* hack for backward compatibility */
798 	call &= 0xffff;
799 
800 	if(version)
801 		return -EINVAL;
802 
803 	if (call <= SEMCTL)
804 		switch (call) {
805 		case SEMOP:
806 			/* struct sembuf is the same on 32 and 64bit :)) */
807 			err = sys_semop (first, (struct sembuf *)AA(ptr), second);
808 			goto out;
809 		case SEMGET:
810 			err = sys_semget (first, second, third);
811 			goto out;
812 		case SEMCTL:
813 			err = do_sys32_semctl (first, second, third, (void *)AA(ptr));
814 			goto out;
815 		default:
816 			err = -EINVAL;
817 			goto out;
818 		};
819 	if (call <= MSGCTL)
820 		switch (call) {
821 		case MSGSND:
822 			err = do_sys32_msgsnd (first, second, third, (void *)AA(ptr));
823 			goto out;
824 		case MSGRCV:
825 			err = do_sys32_msgrcv (first, second, 0, third,
826 					       version, (void *)AA(ptr));
827 			goto out;
828 		case MSGGET:
829 			err = sys_msgget ((key_t) first, second);
830 			goto out;
831 		case MSGCTL:
832 			err = do_sys32_msgctl (first, second, (void *)AA(ptr));
833 			goto out;
834 		default:
835 			err = -EINVAL;
836 			goto out;
837 		}
838 	if (call <= SHMCTL)
839 		switch (call) {
840 		case SHMAT:
841 			err = do_sys32_shmat (first, second, third,
842 					      version, (void *)AA(ptr));
843 			goto out;
844 		case SHMDT:
845 			err = sys_shmdt ((char *)AA(ptr));
846 			goto out;
847 		case SHMGET:
848 			err = sys_shmget (first, second, third);
849 			goto out;
850 		case SHMCTL:
851 			err = do_sys32_shmctl (first, second, (void *)AA(ptr));
852 			goto out;
853 		default:
854 			err = -EINVAL;
855 			goto out;
856 		}
857 
858 	err = -EINVAL;
859 
860 out:
861 	return err;
862 }
863 
get_flock(struct flock * kfl,struct flock32 * ufl)864 static inline int get_flock(struct flock *kfl, struct flock32 *ufl)
865 {
866 	int err;
867 
868 	err = get_user(kfl->l_type, &ufl->l_type);
869 	err |= __get_user(kfl->l_whence, &ufl->l_whence);
870 	err |= __get_user(kfl->l_start, &ufl->l_start);
871 	err |= __get_user(kfl->l_len, &ufl->l_len);
872 	err |= __get_user(kfl->l_pid, &ufl->l_pid);
873 	return err;
874 }
875 
put_flock(struct flock * kfl,struct flock32 * ufl)876 static inline int put_flock(struct flock *kfl, struct flock32 *ufl)
877 {
878 	int err;
879 
880 	err = __put_user(kfl->l_type, &ufl->l_type);
881 	err |= __put_user(kfl->l_whence, &ufl->l_whence);
882 	err |= __put_user(kfl->l_start, &ufl->l_start);
883 	err |= __put_user(kfl->l_len, &ufl->l_len);
884 	err |= __put_user(kfl->l_pid, &ufl->l_pid);
885 	return err;
886 }
887 
888 extern asmlinkage long sys_fcntl(unsigned int fd, unsigned int cmd, unsigned long arg);
889 
sys32_fcntl(unsigned int fd,unsigned int cmd,unsigned long arg)890 asmlinkage long sys32_fcntl(unsigned int fd, unsigned int cmd, unsigned long arg)
891 {
892 	switch (cmd) {
893 	case F_GETLK:
894 		{
895 			struct flock f;
896 			mm_segment_t old_fs;
897 			long ret;
898 
899 			if(get_flock(&f, (struct flock32 *)A(arg)))
900 				return -EFAULT;
901 			old_fs = get_fs(); set_fs (KERNEL_DS);
902 			ret = sys_fcntl(fd, cmd, (unsigned long)&f);
903 			set_fs (old_fs);
904 			if (ret) return ret;
905 			if (f.l_start >= 0x7fffffffUL ||
906 			    f.l_start + f.l_len >= 0x7fffffffUL)
907 				return -EOVERFLOW;
908 			if(put_flock(&f, (struct flock32 *)A(arg)))
909 				return -EFAULT;
910 			return 0;
911 		}
912 	case F_SETLK:
913 	case F_SETLKW:
914 		{
915 			struct flock f;
916 			mm_segment_t old_fs;
917 			long ret;
918 
919 			if(get_flock(&f, (struct flock32 *)A(arg)))
920 				return -EFAULT;
921 			old_fs = get_fs(); set_fs (KERNEL_DS);
922 			ret = sys_fcntl(fd, cmd, (unsigned long)&f);
923 			set_fs (old_fs);
924 			if (ret) return ret;
925 			return 0;
926 		}
927 	default:
928 		return sys_fcntl(fd, cmd, (unsigned long)arg);
929 	}
930 }
931 
sys32_fcntl64(unsigned int fd,unsigned int cmd,unsigned long arg)932 asmlinkage long sys32_fcntl64(unsigned int fd, unsigned int cmd, unsigned long arg)
933 {
934 	if (cmd >= F_GETLK64 && cmd <= F_SETLKW64)
935 		return sys_fcntl(fd, cmd + F_GETLK - F_GETLK64, arg);
936 	return sys32_fcntl(fd, cmd, arg);
937 }
938 
939 struct user_dqblk32 {
940     __u32 dqb_bhardlimit;
941     __u32 dqb_bsoftlimit;
942     __u32 dqb_curblocks;
943     __u32 dqb_ihardlimit;
944     __u32 dqb_isoftlimit;
945     __u32 dqb_curinodes;
946     __kernel_time_t32 dqb_btime;
947     __kernel_time_t32 dqb_itime;
948 };
949 
950 extern asmlinkage int sys_quotactl(int cmd, const char *special, int id, caddr_t addr);
951 
sys32_quotactl(int cmd,const char * special,int id,caddr_t addr)952 asmlinkage int sys32_quotactl(int cmd, const char *special, int id, caddr_t addr)
953 {
954 	int cmds = cmd >> SUBCMDSHIFT;
955 	int err;
956 	struct v1c_mem_dqblk d;
957 	mm_segment_t old_fs;
958 	char *spec;
959 
960 	switch (cmds) {
961 	case Q_V1_GETQUOTA:
962 		break;
963 	case Q_V1_SETQUOTA:
964 	case Q_V1_SETUSE:
965 	case Q_V1_SETQLIM:
966 		if (copy_from_user(&d, addr, sizeof (struct user_dqblk32)))
967 			return -EFAULT;
968 		d.dqb_itime = ((struct user_dqblk32 *)&d)->dqb_itime;
969 		d.dqb_btime = ((struct user_dqblk32 *)&d)->dqb_btime;
970 		break;
971 	default:
972 		return sys_quotactl(cmd, special, id, addr);
973 	}
974 
975 	spec = getname(special);
976 	err = PTR_ERR(spec);
977 	if (IS_ERR(spec))
978 		return err;
979 	old_fs = get_fs();
980 	set_fs (KERNEL_DS);
981 	err = sys_quotactl(cmd, (const char *)spec, id, (caddr_t)&d);
982 	set_fs(old_fs);
983 	putname(spec);
984 	if (err)
985 		return err;
986 	if (cmds == Q_V1_GETQUOTA) {
987 		__kernel_time_t b = d.dqb_btime, i = d.dqb_itime;
988 		((struct user_dqblk32 *)&d)->dqb_itime = i;
989 		((struct user_dqblk32 *)&d)->dqb_btime = b;
990 		if (copy_to_user(addr, &d, sizeof (struct user_dqblk32)))
991 			return -EFAULT;
992 	}
993 	return 0;
994 }
995 
put_statfs(struct statfs32 * ubuf,struct statfs * kbuf)996 static inline int put_statfs (struct statfs32 *ubuf, struct statfs *kbuf)
997 {
998 	int err;
999 
1000 	err = put_user (kbuf->f_type, &ubuf->f_type);
1001 	err |= __put_user (kbuf->f_bsize, &ubuf->f_bsize);
1002 	err |= __put_user (kbuf->f_blocks, &ubuf->f_blocks);
1003 	err |= __put_user (kbuf->f_bfree, &ubuf->f_bfree);
1004 	err |= __put_user (kbuf->f_bavail, &ubuf->f_bavail);
1005 	err |= __put_user (kbuf->f_files, &ubuf->f_files);
1006 	err |= __put_user (kbuf->f_ffree, &ubuf->f_ffree);
1007 	err |= __put_user (kbuf->f_namelen, &ubuf->f_namelen);
1008 	err |= __put_user (kbuf->f_fsid.val[0], &ubuf->f_fsid.val[0]);
1009 	err |= __put_user (kbuf->f_fsid.val[1], &ubuf->f_fsid.val[1]);
1010 	return err;
1011 }
1012 
1013 extern asmlinkage int sys_statfs(const char * path, struct statfs * buf);
1014 
sys32_statfs(const char * path,struct statfs32 * buf)1015 asmlinkage int sys32_statfs(const char * path, struct statfs32 *buf)
1016 {
1017 	int ret;
1018 	struct statfs s;
1019 	mm_segment_t old_fs = get_fs();
1020 	char *pth;
1021 
1022 	pth = getname (path);
1023 	ret = PTR_ERR(pth);
1024 	if (!IS_ERR(pth)) {
1025 		set_fs (KERNEL_DS);
1026 		ret = sys_statfs((const char *)pth, &s);
1027 		set_fs (old_fs);
1028 		putname (pth);
1029 		if (put_statfs(buf, &s))
1030 			return -EFAULT;
1031 	}
1032 	return ret;
1033 }
1034 
1035 extern asmlinkage int sys_fstatfs(unsigned int fd, struct statfs * buf);
1036 
sys32_fstatfs(unsigned int fd,struct statfs32 * buf)1037 asmlinkage int sys32_fstatfs(unsigned int fd, struct statfs32 *buf)
1038 {
1039 	int ret;
1040 	struct statfs s;
1041 	mm_segment_t old_fs = get_fs();
1042 
1043 	set_fs (KERNEL_DS);
1044 	ret = sys_fstatfs(fd, &s);
1045 	set_fs (old_fs);
1046 	if (put_statfs(buf, &s))
1047 		return -EFAULT;
1048 	return ret;
1049 }
1050 
1051 extern asmlinkage long sys_truncate(const char * path, unsigned long length);
1052 extern asmlinkage long sys_ftruncate(unsigned int fd, unsigned long length);
1053 
sys32_truncate64(const char * path,unsigned long high,unsigned long low)1054 asmlinkage int sys32_truncate64(const char * path, unsigned long high, unsigned long low)
1055 {
1056 	if ((int)high < 0)
1057 		return -EINVAL;
1058 	else
1059 		return sys_truncate(path, (high << 32) | low);
1060 }
1061 
sys32_ftruncate64(unsigned int fd,unsigned long high,unsigned long low)1062 asmlinkage int sys32_ftruncate64(unsigned int fd, unsigned long high, unsigned long low)
1063 {
1064 	if ((int)high < 0)
1065 		return -EINVAL;
1066 	else
1067 		return sys_ftruncate(fd, (high << 32) | low);
1068 }
1069 
1070 extern asmlinkage int sys_utime(char * filename, struct utimbuf * times);
1071 
1072 struct utimbuf32 {
1073 	__kernel_time_t32 actime, modtime;
1074 };
1075 
sys32_utime(char * filename,struct utimbuf32 * times)1076 asmlinkage int sys32_utime(char * filename, struct utimbuf32 *times)
1077 {
1078 	struct utimbuf t;
1079 	mm_segment_t old_fs;
1080 	int ret;
1081 	char *filenam;
1082 
1083 	if (!times)
1084 		return sys_utime(filename, NULL);
1085 	if (get_user (t.actime, &times->actime) ||
1086 	    __get_user (t.modtime, &times->modtime))
1087 		return -EFAULT;
1088 	filenam = getname (filename);
1089 	ret = PTR_ERR(filenam);
1090 	if (!IS_ERR(filenam)) {
1091 		old_fs = get_fs();
1092 		set_fs (KERNEL_DS);
1093 		ret = sys_utime(filenam, &t);
1094 		set_fs (old_fs);
1095 		putname (filenam);
1096 	}
1097 	return ret;
1098 }
1099 
1100 struct iovec32 { u32 iov_base; __kernel_size_t32 iov_len; };
1101 
1102 typedef ssize_t (*io_fn_t)(struct file *, char *, size_t, loff_t *);
1103 typedef ssize_t (*iov_fn_t)(struct file *, const struct iovec *, unsigned long, loff_t *);
1104 
do_readv_writev32(int type,struct file * file,const struct iovec32 * vector,u32 count)1105 static long do_readv_writev32(int type, struct file *file,
1106 			      const struct iovec32 *vector, u32 count)
1107 {
1108 	unsigned long tot_len;
1109 	struct iovec iovstack[UIO_FASTIOV];
1110 	struct iovec *iov=iovstack, *ivp;
1111 	long retval, i;
1112 	io_fn_t fn;
1113 	iov_fn_t fnv;
1114 
1115 	/* First get the "struct iovec" from user memory and
1116 	 * verify all the pointers
1117 	 */
1118 	if (!count)
1119 		return 0;
1120 	if (verify_area(VERIFY_READ, vector, sizeof(struct iovec32)*count))
1121 		return -EFAULT;
1122 	if (count > UIO_MAXIOV)
1123 		return -EINVAL;
1124 	if (count > UIO_FASTIOV) {
1125 		iov = kmalloc(count*sizeof(struct iovec), GFP_KERNEL);
1126 		if (!iov)
1127 			return -ENOMEM;
1128 	}
1129 
1130 	tot_len = 0;
1131 	i = count;
1132 	ivp = iov;
1133 	while(i > 0) {
1134 		u32 len;
1135 		u32 buf;
1136 
1137 		__get_user(len, &vector->iov_len);
1138 		__get_user(buf, &vector->iov_base);
1139 		tot_len += len;
1140 		ivp->iov_base = (void *)A(buf);
1141 		ivp->iov_len = (__kernel_size_t) len;
1142 		vector++;
1143 		ivp++;
1144 		i--;
1145 	}
1146 
1147 	/* VERIFY_WRITE actually means a read, as we write to user space */
1148 	retval = rw_verify_area((type == VERIFY_WRITE ? READ : WRITE),
1149 				   file, &file->f_pos, tot_len);
1150 	if (retval)
1151 		goto out;
1152 
1153 	/* VERIFY_WRITE actually means a read, as we write to user space */
1154 	fnv = (type == VERIFY_WRITE ? file->f_op->readv : file->f_op->writev);
1155 	if (fnv) {
1156 		retval = fnv(file, iov, count, &file->f_pos);
1157 		goto out;
1158 	}
1159 
1160 	fn = (type == VERIFY_WRITE ? file->f_op->read :
1161 	      (io_fn_t) file->f_op->write);
1162 
1163 	ivp = iov;
1164 	while (count > 0) {
1165 		void * base;
1166 		int len, nr;
1167 
1168 		base = ivp->iov_base;
1169 		len = ivp->iov_len;
1170 		ivp++;
1171 		count--;
1172 		nr = fn(file, base, len, &file->f_pos);
1173 		if (nr < 0) {
1174 			if (!retval)
1175 				retval = nr;
1176 			break;
1177 		}
1178 		retval += nr;
1179 		if (nr != len)
1180 			break;
1181 	}
1182 out:
1183 	if (iov != iovstack)
1184 		kfree(iov);
1185 
1186 	return retval;
1187 }
1188 
sys32_readv(int fd,struct iovec32 * vector,u32 count)1189 asmlinkage long sys32_readv(int fd, struct iovec32 *vector, u32 count)
1190 {
1191 	struct file *file;
1192 	long ret = -EBADF;
1193 
1194 	file = fget(fd);
1195 	if(!file)
1196 		goto bad_file;
1197 
1198 	if (file->f_op && (file->f_mode & FMODE_READ) &&
1199 	    (file->f_op->readv || file->f_op->read))
1200 		ret = do_readv_writev32(VERIFY_WRITE, file, vector, count);
1201 	fput(file);
1202 
1203 bad_file:
1204 	return ret;
1205 }
1206 
sys32_writev(int fd,struct iovec32 * vector,u32 count)1207 asmlinkage long sys32_writev(int fd, struct iovec32 *vector, u32 count)
1208 {
1209 	struct file *file;
1210 	int ret = -EBADF;
1211 
1212 	file = fget(fd);
1213 	if(!file)
1214 		goto bad_file;
1215 	if (file->f_op && (file->f_mode & FMODE_WRITE) &&
1216 	    (file->f_op->writev || file->f_op->write))
1217 		ret = do_readv_writev32(VERIFY_READ, file, vector, count);
1218 	fput(file);
1219 
1220 bad_file:
1221 	return ret;
1222 }
1223 
1224 /* readdir & getdents */
1225 
1226 #define NAME_OFFSET(de) ((int) ((de)->d_name - (char *) (de)))
1227 #define ROUND_UP(x) (((x)+sizeof(u32)-1) & ~(sizeof(u32)-1))
1228 
1229 struct old_linux_dirent32 {
1230 	u32		d_ino;
1231 	u32		d_offset;
1232 	unsigned short	d_namlen;
1233 	char		d_name[1];
1234 };
1235 
1236 struct readdir_callback32 {
1237 	struct old_linux_dirent32 * dirent;
1238 	int count;
1239 };
1240 
fillonedir(void * __buf,const char * name,int namlen,loff_t offset,ino_t ino,unsigned int d_type)1241 static int fillonedir(void * __buf, const char * name, int namlen,
1242 		      loff_t offset, ino_t ino, unsigned int d_type)
1243 {
1244 	struct readdir_callback32 * buf = (struct readdir_callback32 *) __buf;
1245 	struct old_linux_dirent32 * dirent;
1246 
1247 	if (buf->count)
1248 		return -EINVAL;
1249 	buf->count++;
1250 	dirent = buf->dirent;
1251 	put_user(ino, &dirent->d_ino);
1252 	put_user(offset, &dirent->d_offset);
1253 	put_user(namlen, &dirent->d_namlen);
1254 	copy_to_user(dirent->d_name, name, namlen);
1255 	put_user(0, dirent->d_name + namlen);
1256 	return 0;
1257 }
1258 
old32_readdir(unsigned int fd,struct old_linux_dirent32 * dirent,unsigned int count)1259 asmlinkage int old32_readdir(unsigned int fd, struct old_linux_dirent32 *dirent, unsigned int count)
1260 {
1261 	int error = -EBADF;
1262 	struct file * file;
1263 	struct readdir_callback32 buf;
1264 
1265 	file = fget(fd);
1266 	if (!file)
1267 		goto out;
1268 
1269 	buf.count = 0;
1270 	buf.dirent = dirent;
1271 
1272 	error = vfs_readdir(file, fillonedir, &buf);
1273 	if (error < 0)
1274 		goto out_putf;
1275 	error = buf.count;
1276 
1277 out_putf:
1278 	fput(file);
1279 out:
1280 	return error;
1281 }
1282 
1283 struct linux_dirent32 {
1284 	u32		d_ino;
1285 	u32		d_off;
1286 	unsigned short	d_reclen;
1287 	char		d_name[1];
1288 };
1289 
1290 struct getdents_callback32 {
1291 	struct linux_dirent32 * current_dir;
1292 	struct linux_dirent32 * previous;
1293 	int count;
1294 	int error;
1295 };
1296 
filldir(void * __buf,const char * name,int namlen,loff_t offset,ino_t ino,unsigned int d_type)1297 static int filldir(void * __buf, const char * name, int namlen, loff_t offset, ino_t ino,
1298 		   unsigned int d_type)
1299 {
1300 	struct linux_dirent32 * dirent;
1301 	struct getdents_callback32 * buf = (struct getdents_callback32 *) __buf;
1302 	int reclen = ROUND_UP(NAME_OFFSET(dirent) + namlen + 1);
1303 
1304 	buf->error = -EINVAL;	/* only used if we fail.. */
1305 	if (reclen > buf->count)
1306 		return -EINVAL;
1307 	dirent = buf->previous;
1308 	if (dirent)
1309 		put_user(offset, &dirent->d_off);
1310 	dirent = buf->current_dir;
1311 	buf->previous = dirent;
1312 	put_user(ino, &dirent->d_ino);
1313 	put_user(reclen, &dirent->d_reclen);
1314 	copy_to_user(dirent->d_name, name, namlen);
1315 	put_user(0, dirent->d_name + namlen);
1316 	((char *) dirent) += reclen;
1317 	buf->current_dir = dirent;
1318 	buf->count -= reclen;
1319 	return 0;
1320 }
1321 
sys32_getdents(unsigned int fd,struct linux_dirent32 * dirent,unsigned int count)1322 asmlinkage int sys32_getdents(unsigned int fd, struct linux_dirent32 *dirent, unsigned int count)
1323 {
1324 	struct file * file;
1325 	struct linux_dirent32 * lastdirent;
1326 	struct getdents_callback32 buf;
1327 	int error = -EBADF;
1328 
1329 	file = fget(fd);
1330 	if (!file)
1331 		goto out;
1332 
1333 	buf.current_dir = dirent;
1334 	buf.previous = NULL;
1335 	buf.count = count;
1336 	buf.error = 0;
1337 
1338 	error = vfs_readdir(file, filldir, &buf);
1339 	if (error < 0)
1340 		goto out_putf;
1341 	lastdirent = buf.previous;
1342 	error = buf.error;
1343 	if(lastdirent) {
1344 		put_user(file->f_pos, &lastdirent->d_off);
1345 		error = count - buf.count;
1346 	}
1347 out_putf:
1348 	fput(file);
1349 out:
1350 	return error;
1351 }
1352 
1353 /* end of readdir & getdents */
1354 
1355 /*
1356  * Ooo, nasty.  We need here to frob 32-bit unsigned longs to
1357  * 64-bit unsigned longs.
1358  */
1359 
1360 static inline int
get_fd_set32(unsigned long n,unsigned long * fdset,u32 * ufdset)1361 get_fd_set32(unsigned long n, unsigned long *fdset, u32 *ufdset)
1362 {
1363 	if (ufdset) {
1364 		unsigned long odd;
1365 
1366 		if (verify_area(VERIFY_WRITE, ufdset, n*sizeof(u32)))
1367 			return -EFAULT;
1368 
1369 		odd = n & 1UL;
1370 		n &= ~1UL;
1371 		while (n) {
1372 			unsigned long h, l;
1373 			__get_user(l, ufdset);
1374 			__get_user(h, ufdset+1);
1375 			ufdset += 2;
1376 			*fdset++ = h << 32 | l;
1377 			n -= 2;
1378 		}
1379 		if (odd)
1380 			__get_user(*fdset, ufdset);
1381 	} else {
1382 		/* Tricky, must clear full unsigned long in the
1383 		 * kernel fdset at the end, this makes sure that
1384 		 * actually happens.
1385 		 */
1386 		memset(fdset, 0, ((n + 1) & ~1)*sizeof(u32));
1387 	}
1388 	return 0;
1389 }
1390 
1391 static inline void
set_fd_set32(unsigned long n,u32 * ufdset,unsigned long * fdset)1392 set_fd_set32(unsigned long n, u32 *ufdset, unsigned long *fdset)
1393 {
1394 	unsigned long odd;
1395 
1396 	if (!ufdset)
1397 		return;
1398 
1399 	odd = n & 1UL;
1400 	n &= ~1UL;
1401 	while (n) {
1402 		unsigned long h, l;
1403 		l = *fdset++;
1404 		h = l >> 32;
1405 		__put_user(l, ufdset);
1406 		__put_user(h, ufdset+1);
1407 		ufdset += 2;
1408 		n -= 2;
1409 	}
1410 	if (odd)
1411 		__put_user(*fdset, ufdset);
1412 }
1413 
1414 #define MAX_SELECT_SECONDS \
1415 	((unsigned long) (MAX_SCHEDULE_TIMEOUT / HZ)-1)
1416 
sys32_select(int n,u32 * inp,u32 * outp,u32 * exp,u32 tvp_x)1417 asmlinkage int sys32_select(int n, u32 *inp, u32 *outp, u32 *exp, u32 tvp_x)
1418 {
1419 	fd_set_bits fds;
1420 	struct timeval32 *tvp = (struct timeval32 *)AA(tvp_x);
1421 	char *bits;
1422 	unsigned long nn;
1423 	long timeout;
1424 	int ret, size;
1425 
1426 	timeout = MAX_SCHEDULE_TIMEOUT;
1427 	if (tvp) {
1428 		int sec, usec;
1429 
1430 		if ((ret = verify_area(VERIFY_READ, tvp, sizeof(*tvp)))
1431 		    || (ret = __get_user(sec, &tvp->tv_sec))
1432 		    || (ret = __get_user(usec, &tvp->tv_usec)))
1433 			goto out_nofds;
1434 
1435 		ret = -EINVAL;
1436 		if(sec < 0 || usec < 0)
1437 			goto out_nofds;
1438 
1439 		if ((unsigned long) sec < MAX_SELECT_SECONDS) {
1440 			timeout = (usec + 1000000/HZ - 1) / (1000000/HZ);
1441 			timeout += sec * (unsigned long) HZ;
1442 		}
1443 	}
1444 
1445 	ret = -EINVAL;
1446 	if (n < 0)
1447 		goto out_nofds;
1448 	if (n > current->files->max_fdset)
1449 		n = current->files->max_fdset;
1450 
1451 	/*
1452 	 * We need 6 bitmaps (in/out/ex for both incoming and outgoing),
1453 	 * since we used fdset we need to allocate memory in units of
1454 	 * long-words.
1455 	 */
1456 	ret = -ENOMEM;
1457 	size = FDS_BYTES(n);
1458 	bits = kmalloc(6 * size, GFP_KERNEL);
1459 	if (!bits)
1460 		goto out_nofds;
1461 	fds.in      = (unsigned long *)  bits;
1462 	fds.out     = (unsigned long *) (bits +   size);
1463 	fds.ex      = (unsigned long *) (bits + 2*size);
1464 	fds.res_in  = (unsigned long *) (bits + 3*size);
1465 	fds.res_out = (unsigned long *) (bits + 4*size);
1466 	fds.res_ex  = (unsigned long *) (bits + 5*size);
1467 
1468 	nn = (n + 8*sizeof(u32) - 1) / (8*sizeof(u32));
1469 	if ((ret = get_fd_set32(nn, fds.in, inp)) ||
1470 	    (ret = get_fd_set32(nn, fds.out, outp)) ||
1471 	    (ret = get_fd_set32(nn, fds.ex, exp)))
1472 		goto out;
1473 	zero_fd_set(n, fds.res_in);
1474 	zero_fd_set(n, fds.res_out);
1475 	zero_fd_set(n, fds.res_ex);
1476 
1477 	ret = do_select(n, &fds, &timeout);
1478 
1479 	if (tvp && !(current->personality & STICKY_TIMEOUTS)) {
1480 		int sec = 0, usec = 0;
1481 		if (timeout) {
1482 			sec = timeout / HZ;
1483 			usec = timeout % HZ;
1484 			usec *= (1000000/HZ);
1485 		}
1486 		put_user(sec, &tvp->tv_sec);
1487 		put_user(usec, &tvp->tv_usec);
1488 	}
1489 
1490 	if (ret < 0)
1491 		goto out;
1492 	if (!ret) {
1493 		ret = -ERESTARTNOHAND;
1494 		if (signal_pending(current))
1495 			goto out;
1496 		ret = 0;
1497 	}
1498 
1499 	set_fd_set32(nn, inp, fds.res_in);
1500 	set_fd_set32(nn, outp, fds.res_out);
1501 	set_fd_set32(nn, exp, fds.res_ex);
1502 
1503 out:
1504 	kfree(bits);
1505 out_nofds:
1506 	return ret;
1507 }
1508 
cp_new_stat32(struct inode * inode,struct stat32 * statbuf)1509 static int cp_new_stat32(struct inode *inode, struct stat32 *statbuf)
1510 {
1511 	unsigned long ino, blksize, blocks;
1512 	kdev_t dev, rdev;
1513 	umode_t mode;
1514 	nlink_t nlink;
1515 	uid_t uid;
1516 	gid_t gid;
1517 	off_t size;
1518 	time_t atime, mtime, ctime;
1519 	int err;
1520 
1521 	/* Stream the loads of inode data into the load buffer,
1522 	 * then we push it all into the store buffer below.  This
1523 	 * should give optimal cache performance.
1524 	 */
1525 	ino = inode->i_ino;
1526 	dev = inode->i_dev;
1527 	mode = inode->i_mode;
1528 	nlink = inode->i_nlink;
1529 	uid = inode->i_uid;
1530 	gid = inode->i_gid;
1531 	rdev = inode->i_rdev;
1532 	size = inode->i_size;
1533 	atime = inode->i_atime;
1534 	mtime = inode->i_mtime;
1535 	ctime = inode->i_ctime;
1536 	blksize = inode->i_blksize;
1537 	blocks = inode->i_blocks;
1538 
1539 	err  = put_user(kdev_t_to_nr(dev), &statbuf->st_dev);
1540 	err |= put_user(ino, &statbuf->st_ino);
1541 	err |= put_user(mode, &statbuf->st_mode);
1542 	err |= put_user(nlink, &statbuf->st_nlink);
1543 	err |= put_user(high2lowuid(uid), &statbuf->st_uid);
1544 	err |= put_user(high2lowgid(gid), &statbuf->st_gid);
1545 	err |= put_user(kdev_t_to_nr(rdev), &statbuf->st_rdev);
1546 	err |= put_user(size, &statbuf->st_size);
1547 	err |= put_user(atime, &statbuf->st_atime);
1548 	err |= put_user(0, &statbuf->__unused1);
1549 	err |= put_user(mtime, &statbuf->st_mtime);
1550 	err |= put_user(0, &statbuf->__unused2);
1551 	err |= put_user(ctime, &statbuf->st_ctime);
1552 	err |= put_user(0, &statbuf->__unused3);
1553 	if (blksize) {
1554 		err |= put_user(blksize, &statbuf->st_blksize);
1555 		err |= put_user(blocks, &statbuf->st_blocks);
1556 	} else {
1557 		unsigned int tmp_blocks;
1558 
1559 #define D_B   7
1560 #define I_B   (BLOCK_SIZE / sizeof(unsigned short))
1561 		tmp_blocks = (size + BLOCK_SIZE - 1) / BLOCK_SIZE;
1562 		if (tmp_blocks > D_B) {
1563 			unsigned int indirect;
1564 
1565 			indirect = (tmp_blocks - D_B + I_B - 1) / I_B;
1566 			tmp_blocks += indirect;
1567 			if (indirect > 1) {
1568 				indirect = (indirect - 1 + I_B - 1) / I_B;
1569 				tmp_blocks += indirect;
1570 				if (indirect > 1)
1571 					tmp_blocks++;
1572 			}
1573 		}
1574 		err |= put_user(BLOCK_SIZE, &statbuf->st_blksize);
1575 		err |= put_user((BLOCK_SIZE / 512) * tmp_blocks, &statbuf->st_blocks);
1576 #undef D_B
1577 #undef I_B
1578 	}
1579 /* fixme
1580 	err |= put_user(0, &statbuf->__unused4[0]);
1581 	err |= put_user(0, &statbuf->__unused4[1]);
1582 */
1583 
1584 	return err;
1585 }
1586 
1587 /* Perhaps this belongs in fs.h or similar. -DaveM */
1588 static __inline__ int
do_revalidate(struct dentry * dentry)1589 do_revalidate(struct dentry *dentry)
1590 {
1591 	struct inode * inode = dentry->d_inode;
1592 	if (inode->i_op && inode->i_op->revalidate)
1593 		return inode->i_op->revalidate(dentry);
1594 	return 0;
1595 }
1596 
sys32_newstat(char * filename,struct stat32 * statbuf)1597 asmlinkage int sys32_newstat(char * filename, struct stat32 *statbuf)
1598 {
1599 	struct nameidata nd;
1600 	int error;
1601 
1602 	error = user_path_walk(filename, &nd);
1603 	if (!error) {
1604 		error = do_revalidate(nd.dentry);
1605 		if (!error)
1606 			error = cp_new_stat32(nd.dentry->d_inode, statbuf);
1607 		path_release(&nd);
1608 	}
1609 	return error;
1610 }
1611 
sys32_newlstat(char * filename,struct stat32 * statbuf)1612 asmlinkage int sys32_newlstat(char * filename, struct stat32 *statbuf)
1613 {
1614 	struct nameidata nd;
1615 	int error;
1616 
1617 	error = user_path_walk_link(filename, &nd);
1618 	if (!error) {
1619 		error = do_revalidate(nd.dentry);
1620 		if (!error)
1621 			error = cp_new_stat32(nd.dentry->d_inode, statbuf);
1622 
1623 		path_release(&nd);
1624 	}
1625 	return error;
1626 }
1627 
sys32_newfstat(unsigned int fd,struct stat32 * statbuf)1628 asmlinkage int sys32_newfstat(unsigned int fd, struct stat32 *statbuf)
1629 {
1630 	struct file *f;
1631 	int err = -EBADF;
1632 
1633 	f = fget(fd);
1634 	if (f) {
1635 		struct dentry * dentry = f->f_dentry;
1636 
1637 		err = do_revalidate(dentry);
1638 		if (!err)
1639 			err = cp_new_stat32(dentry->d_inode, statbuf);
1640 		fput(f);
1641 	}
1642 	return err;
1643 }
1644 
1645 extern asmlinkage int sys_sysfs(int option, unsigned long arg1, unsigned long arg2);
1646 
sys32_sysfs(int option,u32 arg1,u32 arg2)1647 asmlinkage int sys32_sysfs(int option, u32 arg1, u32 arg2)
1648 {
1649 	return sys_sysfs(option, arg1, arg2);
1650 }
1651 
1652 struct ncp_mount_data32 {
1653         int version;
1654         unsigned int ncp_fd;
1655         __kernel_uid_t32 mounted_uid;
1656         __kernel_pid_t32 wdog_pid;
1657         unsigned char mounted_vol[NCP_VOLNAME_LEN + 1];
1658         unsigned int time_out;
1659         unsigned int retry_count;
1660         unsigned int flags;
1661         __kernel_uid_t32 uid;
1662         __kernel_gid_t32 gid;
1663         __kernel_mode_t32 file_mode;
1664         __kernel_mode_t32 dir_mode;
1665 };
1666 
do_ncp_super_data_conv(void * raw_data)1667 static void *do_ncp_super_data_conv(void *raw_data)
1668 {
1669 	struct ncp_mount_data *n = (struct ncp_mount_data *)raw_data;
1670 	struct ncp_mount_data32 *n32 = (struct ncp_mount_data32 *)raw_data;
1671 
1672 	n->dir_mode = n32->dir_mode;
1673 	n->file_mode = n32->file_mode;
1674 	n->gid = low2highgid(n32->gid);
1675 	n->uid = low2highuid(n32->uid);
1676 	memmove (n->mounted_vol, n32->mounted_vol, (sizeof (n32->mounted_vol) + 3 * sizeof (unsigned int)));
1677 	n->wdog_pid = n32->wdog_pid;
1678 	n->mounted_uid = low2highuid(n32->mounted_uid);
1679 	return raw_data;
1680 }
1681 
1682 struct smb_mount_data32 {
1683         int version;
1684         __kernel_uid_t32 mounted_uid;
1685         __kernel_uid_t32 uid;
1686         __kernel_gid_t32 gid;
1687         __kernel_mode_t32 file_mode;
1688         __kernel_mode_t32 dir_mode;
1689 };
1690 
do_smb_super_data_conv(void * raw_data)1691 static void *do_smb_super_data_conv(void *raw_data)
1692 {
1693 	struct smb_mount_data *s = (struct smb_mount_data *)raw_data;
1694 	struct smb_mount_data32 *s32 = (struct smb_mount_data32 *)raw_data;
1695 
1696 	s->version = s32->version;
1697 	s->mounted_uid = low2highuid(s32->mounted_uid);
1698 	s->uid = low2highuid(s32->uid);
1699 	s->gid = low2highgid(s32->gid);
1700 	s->file_mode = s32->file_mode;
1701 	s->dir_mode = s32->dir_mode;
1702 	return raw_data;
1703 }
1704 
copy_mount_stuff_to_kernel(const void * user,unsigned long * kernel)1705 static int copy_mount_stuff_to_kernel(const void *user, unsigned long *kernel)
1706 {
1707 	int i;
1708 	unsigned long page;
1709 	struct vm_area_struct *vma;
1710 
1711 	*kernel = 0;
1712 	if(!user)
1713 		return 0;
1714 	vma = find_vma(current->mm, (unsigned long)user);
1715 	if(!vma || (unsigned long)user < vma->vm_start)
1716 		return -EFAULT;
1717 	if(!(vma->vm_flags & VM_READ))
1718 		return -EFAULT;
1719 	i = vma->vm_end - (unsigned long) user;
1720 	if(PAGE_SIZE <= (unsigned long) i)
1721 		i = PAGE_SIZE - 1;
1722 	if(!(page = __get_free_page(GFP_KERNEL)))
1723 		return -ENOMEM;
1724 	if(copy_from_user((void *) page, user, i)) {
1725 		free_page(page);
1726 		return -EFAULT;
1727 	}
1728 	*kernel = page;
1729 	return 0;
1730 }
1731 
1732 #define SMBFS_NAME	"smbfs"
1733 #define NCPFS_NAME	"ncpfs"
1734 
sys32_mount(char * dev_name,char * dir_name,char * type,unsigned long new_flags,u32 data)1735 asmlinkage int sys32_mount(char *dev_name, char *dir_name, char *type, unsigned long new_flags, u32 data)
1736 {
1737 	unsigned long type_page = 0;
1738 	unsigned long data_page = 0;
1739 	unsigned long dev_page = 0;
1740 	unsigned long dir_page = 0;
1741 	int err, is_smb, is_ncp;
1742 
1743 	is_smb = is_ncp = 0;
1744 
1745 	err = copy_mount_stuff_to_kernel((const void *)type, &type_page);
1746 	if (err)
1747 		goto out;
1748 
1749 	if (!type_page) {
1750 		err = -EINVAL;
1751 		goto out;
1752 	}
1753 
1754 	is_smb = !strcmp((char *)type_page, SMBFS_NAME);
1755 	is_ncp = !strcmp((char *)type_page, NCPFS_NAME);
1756 
1757 	err = copy_mount_stuff_to_kernel((const void *)AA(data), &data_page);
1758 	if (err)
1759 		goto type_out;
1760 
1761 	err = copy_mount_stuff_to_kernel(dev_name, &dev_page);
1762 	if (err)
1763 		goto data_out;
1764 
1765 	err = copy_mount_stuff_to_kernel(dir_name, &dir_page);
1766 	if (err)
1767 		goto dev_out;
1768 
1769 	if (!is_smb && !is_ncp) {
1770 		lock_kernel();
1771 		err = do_mount((char*)dev_page, (char*)dir_page,
1772 				(char*)type_page, new_flags, (char*)data_page);
1773 		unlock_kernel();
1774 	} else {
1775 		if (is_ncp)
1776 			do_ncp_super_data_conv((void *)data_page);
1777 		else
1778 			do_smb_super_data_conv((void *)data_page);
1779 
1780 		lock_kernel();
1781 		err = do_mount((char*)dev_page, (char*)dir_page,
1782 				(char*)type_page, new_flags, (char*)data_page);
1783 		unlock_kernel();
1784 	}
1785 	free_page(dir_page);
1786 
1787 dev_out:
1788 	free_page(dev_page);
1789 
1790 data_out:
1791 	free_page(data_page);
1792 
1793 type_out:
1794 	free_page(type_page);
1795 
1796 out:
1797 	return err;
1798 }
1799 
1800 struct rusage32 {
1801         struct timeval32 ru_utime;
1802         struct timeval32 ru_stime;
1803         s32    ru_maxrss;
1804         s32    ru_ixrss;
1805         s32    ru_idrss;
1806         s32    ru_isrss;
1807         s32    ru_minflt;
1808         s32    ru_majflt;
1809         s32    ru_nswap;
1810         s32    ru_inblock;
1811         s32    ru_oublock;
1812         s32    ru_msgsnd;
1813         s32    ru_msgrcv;
1814         s32    ru_nsignals;
1815         s32    ru_nvcsw;
1816         s32    ru_nivcsw;
1817 };
1818 
put_rusage(struct rusage32 * ru,struct rusage * r)1819 static int put_rusage (struct rusage32 *ru, struct rusage *r)
1820 {
1821 	int err;
1822 
1823 	err = put_user (r->ru_utime.tv_sec, &ru->ru_utime.tv_sec);
1824 	err |= __put_user (r->ru_utime.tv_usec, &ru->ru_utime.tv_usec);
1825 	err |= __put_user (r->ru_stime.tv_sec, &ru->ru_stime.tv_sec);
1826 	err |= __put_user (r->ru_stime.tv_usec, &ru->ru_stime.tv_usec);
1827 	err |= __put_user (r->ru_maxrss, &ru->ru_maxrss);
1828 	err |= __put_user (r->ru_ixrss, &ru->ru_ixrss);
1829 	err |= __put_user (r->ru_idrss, &ru->ru_idrss);
1830 	err |= __put_user (r->ru_isrss, &ru->ru_isrss);
1831 	err |= __put_user (r->ru_minflt, &ru->ru_minflt);
1832 	err |= __put_user (r->ru_majflt, &ru->ru_majflt);
1833 	err |= __put_user (r->ru_nswap, &ru->ru_nswap);
1834 	err |= __put_user (r->ru_inblock, &ru->ru_inblock);
1835 	err |= __put_user (r->ru_oublock, &ru->ru_oublock);
1836 	err |= __put_user (r->ru_msgsnd, &ru->ru_msgsnd);
1837 	err |= __put_user (r->ru_msgrcv, &ru->ru_msgrcv);
1838 	err |= __put_user (r->ru_nsignals, &ru->ru_nsignals);
1839 	err |= __put_user (r->ru_nvcsw, &ru->ru_nvcsw);
1840 	err |= __put_user (r->ru_nivcsw, &ru->ru_nivcsw);
1841 	return err;
1842 }
1843 
sys32_wait4(__kernel_pid_t32 pid,unsigned int * stat_addr,int options,struct rusage32 * ru)1844 asmlinkage int sys32_wait4(__kernel_pid_t32 pid, unsigned int *stat_addr, int options, struct rusage32 *ru)
1845 {
1846 	if (!ru)
1847 		return sys_wait4(pid, stat_addr, options, NULL);
1848 	else {
1849 		struct rusage r;
1850 		int ret;
1851 		unsigned int status;
1852 		mm_segment_t old_fs = get_fs();
1853 
1854 		set_fs (KERNEL_DS);
1855 		ret = sys_wait4(pid, stat_addr ? &status : NULL, options, &r);
1856 		set_fs (old_fs);
1857 		if (put_rusage (ru, &r)) return -EFAULT;
1858 		if (stat_addr && put_user (status, stat_addr))
1859 			return -EFAULT;
1860 		return ret;
1861 	}
1862 }
1863 
1864 struct sysinfo32 {
1865         s32 uptime;
1866         u32 loads[3];
1867         u32 totalram;
1868         u32 freeram;
1869         u32 sharedram;
1870         u32 bufferram;
1871         u32 totalswap;
1872         u32 freeswap;
1873         unsigned short procs;
1874 	unsigned short pad;
1875 	u32 totalhigh;
1876 	u32 freehigh;
1877 	unsigned int mem_unit;
1878         char _f[8];
1879 };
1880 
1881 extern asmlinkage int sys_sysinfo(struct sysinfo *info);
1882 
sys32_sysinfo(struct sysinfo32 * info)1883 asmlinkage int sys32_sysinfo(struct sysinfo32 *info)
1884 {
1885 	struct sysinfo s;
1886 	int ret, err;
1887 	mm_segment_t old_fs = get_fs ();
1888 
1889 	set_fs (KERNEL_DS);
1890 	ret = sys_sysinfo(&s);
1891 	set_fs (old_fs);
1892 	err = put_user (s.uptime, &info->uptime);
1893 	err |= __put_user (s.loads[0], &info->loads[0]);
1894 	err |= __put_user (s.loads[1], &info->loads[1]);
1895 	err |= __put_user (s.loads[2], &info->loads[2]);
1896 	err |= __put_user (s.totalram, &info->totalram);
1897 	err |= __put_user (s.freeram, &info->freeram);
1898 	err |= __put_user (s.sharedram, &info->sharedram);
1899 	err |= __put_user (s.bufferram, &info->bufferram);
1900 	err |= __put_user (s.totalswap, &info->totalswap);
1901 	err |= __put_user (s.freeswap, &info->freeswap);
1902 	err |= __put_user (s.procs, &info->procs);
1903 	err |= __put_user (s.totalhigh, &info->totalhigh);
1904 	err |= __put_user (s.freehigh, &info->freehigh);
1905 	err |= __put_user (s.mem_unit, &info->mem_unit);
1906 	if (err)
1907 		return -EFAULT;
1908 	return ret;
1909 }
1910 
1911 struct timespec32 {
1912 	s32    tv_sec;
1913 	s32    tv_nsec;
1914 };
1915 
1916 extern asmlinkage int sys_sched_rr_get_interval(pid_t pid, struct timespec *interval);
1917 
sys32_sched_rr_get_interval(__kernel_pid_t32 pid,struct timespec32 * interval)1918 asmlinkage int sys32_sched_rr_get_interval(__kernel_pid_t32 pid, struct timespec32 *interval)
1919 {
1920 	struct timespec t;
1921 	int ret;
1922 	mm_segment_t old_fs = get_fs ();
1923 
1924 	set_fs (KERNEL_DS);
1925 	ret = sys_sched_rr_get_interval(pid, &t);
1926 	set_fs (old_fs);
1927 	if (put_user (t.tv_sec, &interval->tv_sec) ||
1928 	    __put_user (t.tv_nsec, &interval->tv_nsec))
1929 		return -EFAULT;
1930 	return ret;
1931 }
1932 
1933 extern asmlinkage int sys_nanosleep(struct timespec *rqtp, struct timespec *rmtp);
1934 
sys32_nanosleep(struct timespec32 * rqtp,struct timespec32 * rmtp)1935 asmlinkage int sys32_nanosleep(struct timespec32 *rqtp, struct timespec32 *rmtp)
1936 {
1937 	struct timespec t;
1938 	int ret;
1939 	mm_segment_t old_fs = get_fs ();
1940 
1941 	if (get_user (t.tv_sec, &rqtp->tv_sec) ||
1942 	    __get_user (t.tv_nsec, &rqtp->tv_nsec))
1943 		return -EFAULT;
1944 	set_fs (KERNEL_DS);
1945 	ret = sys_nanosleep(&t, rmtp ? &t : NULL);
1946 	set_fs (old_fs);
1947 	if (rmtp && ret == -EINTR) {
1948 		if (__put_user (t.tv_sec, &rmtp->tv_sec) ||
1949 	    	    __put_user (t.tv_nsec, &rmtp->tv_nsec))
1950 			return -EFAULT;
1951 	}
1952 	return ret;
1953 }
1954 
1955 extern asmlinkage int sys_sigprocmask(int how, old_sigset_t *set, old_sigset_t *oset);
1956 
sys32_sigprocmask(int how,old_sigset_t32 * set,old_sigset_t32 * oset)1957 asmlinkage int sys32_sigprocmask(int how, old_sigset_t32 *set, old_sigset_t32 *oset)
1958 {
1959 	old_sigset_t s;
1960 	int ret;
1961 	mm_segment_t old_fs = get_fs();
1962 
1963 	if (set && get_user (s, set)) return -EFAULT;
1964 	set_fs (KERNEL_DS);
1965 	ret = sys_sigprocmask(how, set ? &s : NULL, oset ? &s : NULL);
1966 	set_fs (old_fs);
1967 	if (ret) return ret;
1968 	if (oset && put_user (s, oset)) return -EFAULT;
1969 	return 0;
1970 }
1971 
1972 extern asmlinkage int sys_rt_sigprocmask(int how, sigset_t *set, sigset_t *oset, size_t sigsetsize);
1973 
sys32_rt_sigprocmask(int how,sigset_t32 * set,sigset_t32 * oset,__kernel_size_t32 sigsetsize)1974 asmlinkage int sys32_rt_sigprocmask(int how, sigset_t32 *set, sigset_t32 *oset, __kernel_size_t32 sigsetsize)
1975 {
1976 	sigset_t s;
1977 	sigset_t32 s32;
1978 	int ret;
1979 	mm_segment_t old_fs = get_fs();
1980 
1981 	if (set) {
1982 		if (copy_from_user (&s32, set, sizeof(sigset_t32)))
1983 			return -EFAULT;
1984 		switch (_NSIG_WORDS) {
1985 		case 4: s.sig[3] = s32.sig[6] | (((long)s32.sig[7]) << 32);
1986 		case 3: s.sig[2] = s32.sig[4] | (((long)s32.sig[5]) << 32);
1987 		case 2: s.sig[1] = s32.sig[2] | (((long)s32.sig[3]) << 32);
1988 		case 1: s.sig[0] = s32.sig[0] | (((long)s32.sig[1]) << 32);
1989 		}
1990 	}
1991 	set_fs (KERNEL_DS);
1992 	ret = sys_rt_sigprocmask(how, set ? &s : NULL, oset ? &s : NULL, sigsetsize);
1993 	set_fs (old_fs);
1994 	if (ret) return ret;
1995 	if (oset) {
1996 		switch (_NSIG_WORDS) {
1997 		case 4: s32.sig[7] = (s.sig[3] >> 32); s32.sig[6] = s.sig[3];
1998 		case 3: s32.sig[5] = (s.sig[2] >> 32); s32.sig[4] = s.sig[2];
1999 		case 2: s32.sig[3] = (s.sig[1] >> 32); s32.sig[2] = s.sig[1];
2000 		case 1: s32.sig[1] = (s.sig[0] >> 32); s32.sig[0] = s.sig[0];
2001 		}
2002 		if (copy_to_user (oset, &s32, sizeof(sigset_t32)))
2003 			return -EFAULT;
2004 	}
2005 	return 0;
2006 }
2007 
2008 extern asmlinkage int sys_sigpending(old_sigset_t *set);
2009 
sys32_sigpending(old_sigset_t32 * set)2010 asmlinkage int sys32_sigpending(old_sigset_t32 *set)
2011 {
2012 	old_sigset_t s;
2013 	int ret;
2014 	mm_segment_t old_fs = get_fs();
2015 
2016 	set_fs (KERNEL_DS);
2017 	ret = sys_sigpending(&s);
2018 	set_fs (old_fs);
2019 	if (put_user (s, set)) return -EFAULT;
2020 	return ret;
2021 }
2022 
2023 extern asmlinkage int sys_rt_sigpending(sigset_t *set, size_t sigsetsize);
2024 
sys32_rt_sigpending(sigset_t32 * set,__kernel_size_t32 sigsetsize)2025 asmlinkage int sys32_rt_sigpending(sigset_t32 *set, __kernel_size_t32 sigsetsize)
2026 {
2027 	sigset_t s;
2028 	sigset_t32 s32;
2029 	int ret;
2030 	mm_segment_t old_fs = get_fs();
2031 
2032 	set_fs (KERNEL_DS);
2033 	ret = sys_rt_sigpending(&s, sigsetsize);
2034 	set_fs (old_fs);
2035 	if (!ret) {
2036 		switch (_NSIG_WORDS) {
2037 		case 4: s32.sig[7] = (s.sig[3] >> 32); s32.sig[6] = s.sig[3];
2038 		case 3: s32.sig[5] = (s.sig[2] >> 32); s32.sig[4] = s.sig[2];
2039 		case 2: s32.sig[3] = (s.sig[1] >> 32); s32.sig[2] = s.sig[1];
2040 		case 1: s32.sig[1] = (s.sig[0] >> 32); s32.sig[0] = s.sig[0];
2041 		}
2042 		if (copy_to_user (set, &s32, sizeof(sigset_t32)))
2043 			return -EFAULT;
2044 	}
2045 	return ret;
2046 }
2047 
2048 extern int
2049 copy_siginfo_to_user32(siginfo_t32 *to, siginfo_t *from);
2050 
2051 asmlinkage int
sys32_rt_sigtimedwait(sigset_t32 * uthese,siginfo_t32 * uinfo,struct timespec32 * uts,__kernel_size_t32 sigsetsize)2052 sys32_rt_sigtimedwait(sigset_t32 *uthese, siginfo_t32 *uinfo,
2053 		      struct timespec32 *uts, __kernel_size_t32 sigsetsize)
2054 {
2055 	int ret, sig;
2056 	sigset_t these;
2057 	sigset_t32 these32;
2058 	struct timespec ts;
2059 	siginfo_t info;
2060 	long timeout = 0;
2061 
2062 	/* XXX: Don't preclude handling different sized sigset_t's.  */
2063 	if (sigsetsize != sizeof(sigset_t))
2064 		return -EINVAL;
2065 
2066 	if (copy_from_user (&these32, uthese, sizeof(sigset_t32)))
2067 		return -EFAULT;
2068 
2069 	switch (_NSIG_WORDS) {
2070 	case 4: these.sig[3] = these32.sig[6] | (((long)these32.sig[7]) << 32);
2071 	case 3: these.sig[2] = these32.sig[4] | (((long)these32.sig[5]) << 32);
2072 	case 2: these.sig[1] = these32.sig[2] | (((long)these32.sig[3]) << 32);
2073 	case 1: these.sig[0] = these32.sig[0] | (((long)these32.sig[1]) << 32);
2074 	}
2075 
2076 	/*
2077 	 * Invert the set of allowed signals to get those we
2078 	 * want to block.
2079 	 */
2080 	sigdelsetmask(&these, sigmask(SIGKILL)|sigmask(SIGSTOP));
2081 	signotset(&these);
2082 
2083 	if (uts) {
2084 		if (get_user (ts.tv_sec, &uts->tv_sec) ||
2085 		    get_user (ts.tv_nsec, &uts->tv_nsec))
2086 			return -EINVAL;
2087 		if (ts.tv_nsec >= 1000000000L || ts.tv_nsec < 0
2088 		    || ts.tv_sec < 0)
2089 			return -EINVAL;
2090 	}
2091 
2092 	spin_lock_irq(&current->sigmask_lock);
2093 	sig = dequeue_signal(&these, &info);
2094 	if (!sig) {
2095 		/* None ready -- temporarily unblock those we're interested
2096 		   in so that we'll be awakened when they arrive.  */
2097 		sigset_t oldblocked = current->blocked;
2098 		sigandsets(&current->blocked, &current->blocked, &these);
2099 		recalc_sigpending(current);
2100 		spin_unlock_irq(&current->sigmask_lock);
2101 
2102 		timeout = MAX_SCHEDULE_TIMEOUT;
2103 		if (uts)
2104 			timeout = (timespec_to_jiffies(&ts)
2105 				   + (ts.tv_sec || ts.tv_nsec));
2106 
2107 		current->state = TASK_INTERRUPTIBLE;
2108 		timeout = schedule_timeout(timeout);
2109 
2110 		spin_lock_irq(&current->sigmask_lock);
2111 		sig = dequeue_signal(&these, &info);
2112 		current->blocked = oldblocked;
2113 		recalc_sigpending(current);
2114 	}
2115 	spin_unlock_irq(&current->sigmask_lock);
2116 
2117 	if (sig) {
2118 		ret = sig;
2119 		if (uinfo) {
2120 			if (copy_siginfo_to_user32(uinfo, &info))
2121 				ret = -EFAULT;
2122 		}
2123 	} else {
2124 		ret = -EAGAIN;
2125 		if (timeout)
2126 			ret = -EINTR;
2127 	}
2128 
2129 	return ret;
2130 }
2131 
2132 extern asmlinkage int
2133 sys_rt_sigqueueinfo(int pid, int sig, siginfo_t *uinfo);
2134 
2135 asmlinkage int
sys32_rt_sigqueueinfo(int pid,int sig,siginfo_t32 * uinfo)2136 sys32_rt_sigqueueinfo(int pid, int sig, siginfo_t32 *uinfo)
2137 {
2138 	siginfo_t info;
2139 	int ret;
2140 	mm_segment_t old_fs = get_fs();
2141 
2142 	if (copy_from_user (&info, uinfo, 3*sizeof(int)) ||
2143 	    copy_from_user (info._sifields._pad, uinfo->_sifields._pad, SI_PAD_SIZE))
2144 		return -EFAULT;
2145 	set_fs (KERNEL_DS);
2146 	ret = sys_rt_sigqueueinfo(pid, sig, &info);
2147 	set_fs (old_fs);
2148 	return ret;
2149 }
2150 
2151 struct tms32 {
2152 	__kernel_clock_t32 tms_utime;
2153 	__kernel_clock_t32 tms_stime;
2154 	__kernel_clock_t32 tms_cutime;
2155 	__kernel_clock_t32 tms_cstime;
2156 };
2157 
2158 extern asmlinkage long sys_times(struct tms * tbuf);
2159 
sys32_times(struct tms32 * tbuf)2160 asmlinkage long sys32_times(struct tms32 *tbuf)
2161 {
2162 	struct tms t;
2163 	long ret;
2164 	mm_segment_t old_fs = get_fs ();
2165 	int err;
2166 
2167 	set_fs (KERNEL_DS);
2168 	ret = sys_times(tbuf ? &t : NULL);
2169 	set_fs (old_fs);
2170 	if (tbuf) {
2171 		err = put_user (t.tms_utime, &tbuf->tms_utime);
2172 		err |= __put_user (t.tms_stime, &tbuf->tms_stime);
2173 		err |= __put_user (t.tms_cutime, &tbuf->tms_cutime);
2174 		err |= __put_user (t.tms_cstime, &tbuf->tms_cstime);
2175 		if (err)
2176 			ret = -EFAULT;
2177 	}
2178 	return ret;
2179 }
2180 
2181 #define RLIM_OLD_INFINITY32	0x7fffffff
2182 #define RLIM_INFINITY32		0xffffffff
2183 #define RESOURCE32_OLD(x)	((x > RLIM_OLD_INFINITY32) ? RLIM_OLD_INFINITY32 : x)
2184 #define RESOURCE32(x) 		((x > RLIM_INFINITY32) ? RLIM_INFINITY32 : x)
2185 
2186 struct rlimit32 {
2187 	u32	rlim_cur;
2188 	u32	rlim_max;
2189 };
2190 
2191 extern asmlinkage long sys_getrlimit(unsigned int resource, struct rlimit *rlim);
2192 
sys32_old_getrlimit(unsigned int resource,struct rlimit32 * rlim)2193 asmlinkage int sys32_old_getrlimit(unsigned int resource, struct rlimit32 *rlim)
2194 {
2195 	struct rlimit r;
2196 	int ret;
2197 	mm_segment_t old_fs = get_fs ();
2198 
2199 	set_fs (KERNEL_DS);
2200 	ret = sys_getrlimit(resource, &r);
2201 	set_fs (old_fs);
2202 	if (!ret) {
2203 		ret = put_user (RESOURCE32_OLD(r.rlim_cur), &rlim->rlim_cur);
2204 		ret |= __put_user (RESOURCE32_OLD(r.rlim_max), &rlim->rlim_max);
2205 	}
2206 	return ret;
2207 }
2208 
sys32_getrlimit(unsigned int resource,struct rlimit32 * rlim)2209 asmlinkage int sys32_getrlimit(unsigned int resource, struct rlimit32 *rlim)
2210 {
2211 	struct rlimit r;
2212 	int ret;
2213 	mm_segment_t old_fs = get_fs ();
2214 
2215 	set_fs (KERNEL_DS);
2216 	ret = sys_getrlimit(resource, &r);
2217 	set_fs (old_fs);
2218 	if (!ret) {
2219 		ret = put_user (RESOURCE32(r.rlim_cur), &rlim->rlim_cur);
2220 		ret |= __put_user (RESOURCE32(r.rlim_max), &rlim->rlim_max);
2221 	}
2222 	return ret;
2223 }
2224 
2225 extern asmlinkage int sys_setrlimit(unsigned int resource, struct rlimit *rlim);
2226 
sys32_setrlimit(unsigned int resource,struct rlimit32 * rlim)2227 asmlinkage int sys32_setrlimit(unsigned int resource, struct rlimit32 *rlim)
2228 {
2229 	struct rlimit r;
2230 	int ret;
2231 	mm_segment_t old_fs = get_fs ();
2232 
2233 	if (resource >= RLIM_NLIMITS) return -EINVAL;
2234 	if (get_user (r.rlim_cur, &rlim->rlim_cur) ||
2235 	    __get_user (r.rlim_max, &rlim->rlim_max))
2236 		return -EFAULT;
2237 	if (r.rlim_cur == RLIM_INFINITY32)
2238 		r.rlim_cur = RLIM_INFINITY;
2239 	if (r.rlim_max == RLIM_INFINITY32)
2240 		r.rlim_max = RLIM_INFINITY;
2241 	set_fs (KERNEL_DS);
2242 	ret = sys_setrlimit(resource, &r);
2243 	set_fs (old_fs);
2244 	return ret;
2245 }
2246 
2247 extern asmlinkage int sys_getrusage(int who, struct rusage *ru);
2248 
sys32_getrusage(int who,struct rusage32 * ru)2249 asmlinkage int sys32_getrusage(int who, struct rusage32 *ru)
2250 {
2251 	struct rusage r;
2252 	int ret;
2253 	mm_segment_t old_fs = get_fs();
2254 
2255 	set_fs (KERNEL_DS);
2256 	ret = sys_getrusage(who, &r);
2257 	set_fs (old_fs);
2258 	if (put_rusage (ru, &r)) return -EFAULT;
2259 	return ret;
2260 }
2261 
2262 /* XXX This really belongs in some header file... -DaveM */
2263 #define MAX_SOCK_ADDR	128		/* 108 for Unix domain -
2264 					   16 for IP, 16 for IPX,
2265 					   24 for IPv6,
2266 					   about 80 for AX.25 */
2267 
2268 extern struct socket *sockfd_lookup(int fd, int *err);
2269 
2270 /* XXX This as well... */
sockfd_put(struct socket * sock)2271 extern __inline__ void sockfd_put(struct socket *sock)
2272 {
2273 	fput(sock->file);
2274 }
2275 
2276 struct msghdr32 {
2277         u32               msg_name;
2278         int               msg_namelen;
2279         u32               msg_iov;
2280         __kernel_size_t32 msg_iovlen;
2281         u32               msg_control;
2282         __kernel_size_t32 msg_controllen;
2283         unsigned          msg_flags;
2284 };
2285 
2286 struct cmsghdr32 {
2287         __kernel_size_t32 cmsg_len;
2288         int               cmsg_level;
2289         int               cmsg_type;
2290 };
2291 
2292 /* Bleech... */
2293 #define __CMSG32_NXTHDR(ctl, len, cmsg, cmsglen) __cmsg32_nxthdr((ctl),(len),(cmsg),(cmsglen))
2294 #define CMSG32_NXTHDR(mhdr, cmsg, cmsglen) cmsg32_nxthdr((mhdr), (cmsg), (cmsglen))
2295 
2296 #define CMSG32_ALIGN(len) ( ((len)+sizeof(int)-1) & ~(sizeof(int)-1) )
2297 
2298 #define CMSG32_DATA(cmsg)	((void *)((char *)(cmsg) + CMSG32_ALIGN(sizeof(struct cmsghdr32))))
2299 #define CMSG32_SPACE(len) (CMSG32_ALIGN(sizeof(struct cmsghdr32)) + CMSG32_ALIGN(len))
2300 #define CMSG32_LEN(len) (CMSG32_ALIGN(sizeof(struct cmsghdr32)) + (len))
2301 
2302 #define __CMSG32_FIRSTHDR(ctl,len) ((len) >= sizeof(struct cmsghdr32) ? \
2303 				    (struct cmsghdr32 *)(ctl) : \
2304 				    (struct cmsghdr32 *)NULL)
2305 #define CMSG32_FIRSTHDR(msg)	__CMSG32_FIRSTHDR((msg)->msg_control, (msg)->msg_controllen)
2306 #define CMSG32_OK(ucmlen, ucmsg, mhdr) \
2307 	((ucmlen) >= sizeof(struct cmsghdr32) && \
2308 	 (ucmlen) <= (unsigned long) \
2309 	 ((mhdr)->msg_controllen - \
2310 	  ((char *)(ucmsg) - (char *)(mhdr)->msg_control)))
2311 
__cmsg32_nxthdr(void * __ctl,__kernel_size_t __size,struct cmsghdr32 * __cmsg,int __cmsg_len)2312 __inline__ struct cmsghdr32 *__cmsg32_nxthdr(void *__ctl, __kernel_size_t __size,
2313 					      struct cmsghdr32 *__cmsg, int __cmsg_len)
2314 {
2315 	struct cmsghdr32 * __ptr;
2316 
2317 	__ptr = (struct cmsghdr32 *)(((unsigned char *) __cmsg) +
2318 				     CMSG32_ALIGN(__cmsg_len));
2319 	if ((unsigned long)((char*)(__ptr+1) - (char *) __ctl) > __size)
2320 		return NULL;
2321 
2322 	return __ptr;
2323 }
2324 
cmsg32_nxthdr(struct msghdr * __msg,struct cmsghdr32 * __cmsg,int __cmsg_len)2325 __inline__ struct cmsghdr32 *cmsg32_nxthdr (struct msghdr *__msg,
2326 					    struct cmsghdr32 *__cmsg,
2327 					    int __cmsg_len)
2328 {
2329 	return __cmsg32_nxthdr(__msg->msg_control, __msg->msg_controllen,
2330 			       __cmsg, __cmsg_len);
2331 }
2332 
iov_from_user32_to_kern(struct iovec * kiov,struct iovec32 * uiov32,int niov)2333 static inline int iov_from_user32_to_kern(struct iovec *kiov,
2334 					  struct iovec32 *uiov32,
2335 					  int niov)
2336 {
2337 	int tot_len = 0;
2338 
2339 	while(niov > 0) {
2340 		u32 len, buf;
2341 
2342 		if(get_user(len, &uiov32->iov_len) ||
2343 		   get_user(buf, &uiov32->iov_base)) {
2344 			tot_len = -EFAULT;
2345 			break;
2346 		}
2347 		tot_len += len;
2348 		kiov->iov_base = (void *)A(buf);
2349 		kiov->iov_len = (__kernel_size_t) len;
2350 		uiov32++;
2351 		kiov++;
2352 		niov--;
2353 	}
2354 	return tot_len;
2355 }
2356 
msghdr_from_user32_to_kern(struct msghdr * kmsg,struct msghdr32 * umsg)2357 static inline int msghdr_from_user32_to_kern(struct msghdr *kmsg,
2358 					     struct msghdr32 *umsg)
2359 {
2360 	u32 tmp1, tmp2, tmp3;
2361 	int err;
2362 
2363 	err = get_user(tmp1, &umsg->msg_name);
2364 	err |= __get_user(tmp2, &umsg->msg_iov);
2365 	err |= __get_user(tmp3, &umsg->msg_control);
2366 	if (err)
2367 		return -EFAULT;
2368 
2369 	kmsg->msg_name = (void *)A(tmp1);
2370 	kmsg->msg_iov = (struct iovec *)A(tmp2);
2371 	kmsg->msg_control = (void *)A(tmp3);
2372 
2373 	err = get_user(kmsg->msg_namelen, &umsg->msg_namelen);
2374 	err |= get_user(kmsg->msg_iovlen, &umsg->msg_iovlen);
2375 	err |= get_user(kmsg->msg_controllen, &umsg->msg_controllen);
2376 	err |= get_user(kmsg->msg_flags, &umsg->msg_flags);
2377 
2378 	return err;
2379 }
2380 
2381 /* I've named the args so it is easy to tell whose space the pointers are in. */
verify_iovec32(struct msghdr * kern_msg,struct iovec * kern_iov,char * kern_address,int mode)2382 static int verify_iovec32(struct msghdr *kern_msg, struct iovec *kern_iov,
2383 			  char *kern_address, int mode)
2384 {
2385 	int tot_len;
2386 
2387 	if(kern_msg->msg_namelen) {
2388 		if(mode==VERIFY_READ) {
2389 			int err = move_addr_to_kernel(kern_msg->msg_name,
2390 						      kern_msg->msg_namelen,
2391 						      kern_address);
2392 			if(err < 0)
2393 				return err;
2394 		}
2395 		kern_msg->msg_name = kern_address;
2396 	} else
2397 		kern_msg->msg_name = NULL;
2398 
2399 	if(kern_msg->msg_iovlen > UIO_FASTIOV) {
2400 		kern_iov = kmalloc(kern_msg->msg_iovlen * sizeof(struct iovec),
2401 				   GFP_KERNEL);
2402 		if(!kern_iov)
2403 			return -ENOMEM;
2404 	}
2405 
2406 	tot_len = iov_from_user32_to_kern(kern_iov,
2407 					  (struct iovec32 *)kern_msg->msg_iov,
2408 					  kern_msg->msg_iovlen);
2409 	if(tot_len >= 0)
2410 		kern_msg->msg_iov = kern_iov;
2411 	else if(kern_msg->msg_iovlen > UIO_FASTIOV)
2412 		kfree(kern_iov);
2413 
2414 	return tot_len;
2415 }
2416 
2417 /* There is a lot of hair here because the alignment rules (and
2418  * thus placement) of cmsg headers and length are different for
2419  * 32-bit apps.  -DaveM
2420  */
cmsghdr_from_user32_to_kern(struct msghdr * kmsg,unsigned char * stackbuf,int stackbuf_size)2421 static int cmsghdr_from_user32_to_kern(struct msghdr *kmsg,
2422 				       unsigned char *stackbuf, int stackbuf_size)
2423 {
2424 	struct cmsghdr32 *ucmsg;
2425 	struct cmsghdr *kcmsg, *kcmsg_base;
2426 	__kernel_size_t32 ucmlen;
2427 	__kernel_size_t kcmlen, tmp;
2428 	int err = -EFAULT;
2429 
2430 	kcmlen = 0;
2431 	kcmsg_base = kcmsg = (struct cmsghdr *)stackbuf;
2432 	ucmsg = CMSG32_FIRSTHDR(kmsg);
2433 	while(ucmsg != NULL) {
2434 		if (get_user(ucmlen, &ucmsg->cmsg_len))
2435 			return -EFAULT;
2436 
2437 		/* Catch bogons. */
2438 		if (!CMSG32_OK(ucmlen, ucmsg, kmsg))
2439 			return -EINVAL;
2440 
2441 		tmp = ((ucmlen - CMSG32_ALIGN(sizeof(*ucmsg))) +
2442 		       CMSG_ALIGN(sizeof(struct cmsghdr)));
2443 		tmp = CMSG_ALIGN(tmp);
2444 		kcmlen += tmp;
2445 		ucmsg = CMSG32_NXTHDR(kmsg, ucmsg, ucmlen);
2446 	}
2447 	if(kcmlen == 0)
2448 		return -EINVAL;
2449 
2450 	/* The kcmlen holds the 64-bit version of the control length.
2451 	 * It may not be modified as we do not stick it into the kmsg
2452 	 * until we have successfully copied over all of the data
2453 	 * from the user.
2454 	 */
2455 	if(kcmlen > stackbuf_size)
2456 		kcmsg_base = kcmsg = kmalloc(kcmlen, GFP_KERNEL);
2457 	if(kcmsg == NULL)
2458 		return -ENOBUFS;
2459 
2460 	/* Now copy them over neatly. */
2461 	memset(kcmsg, 0, kcmlen);
2462 	ucmsg = CMSG32_FIRSTHDR(kmsg);
2463 	while(ucmsg != NULL) {
2464 		if (__get_user(ucmlen, &ucmsg->cmsg_len))
2465 			goto Efault;
2466 		tmp = ((ucmlen - CMSG32_ALIGN(sizeof(*ucmsg))) +
2467 		       CMSG_ALIGN(sizeof(struct cmsghdr)));
2468 		if ((char *)kcmsg_base + kcmlen - (char *)kcmsg < CMSG_ALIGN(tmp))
2469 			goto Einval;
2470 		kcmsg->cmsg_len = tmp;
2471 		tmp = CMSG_ALIGN(tmp);
2472 		if (__get_user(kcmsg->cmsg_level, &ucmsg->cmsg_level) ||
2473 		    __get_user(kcmsg->cmsg_type, &ucmsg->cmsg_type) ||
2474 		    copy_from_user(CMSG_DATA(kcmsg),
2475 				   CMSG32_DATA(ucmsg),
2476 				   (ucmlen - CMSG32_ALIGN(sizeof(*ucmsg)))))
2477 			goto Efault;
2478 
2479 		/* Advance. */
2480 		kcmsg = (struct cmsghdr *)((char *)kcmsg + tmp);
2481 		ucmsg = CMSG32_NXTHDR(kmsg, ucmsg, ucmlen);
2482 	}
2483 
2484 	/* Ok, looks like we made it.  Hook it up and return success. */
2485 	kmsg->msg_control = kcmsg_base;
2486 	kmsg->msg_controllen = kcmlen;
2487 	return 0;
2488 
2489 Einval:
2490 	err = -EINVAL;
2491 Efault:
2492 	if (kcmsg_base != (struct cmsghdr *)stackbuf)
2493 		kfree(kcmsg_base);
2494 	return err;
2495 }
2496 
put_cmsg32(struct msghdr * kmsg,int level,int type,int len,void * data)2497 static void put_cmsg32(struct msghdr *kmsg, int level, int type,
2498 		       int len, void *data)
2499 {
2500 	struct cmsghdr32 *cm = (struct cmsghdr32 *) kmsg->msg_control;
2501 	struct cmsghdr32 cmhdr;
2502 	int cmlen = CMSG32_LEN(len);
2503 
2504 	if(cm == NULL || kmsg->msg_controllen < sizeof(*cm)) {
2505 		kmsg->msg_flags |= MSG_CTRUNC;
2506 		return;
2507 	}
2508 
2509 	if(kmsg->msg_controllen < cmlen) {
2510 		kmsg->msg_flags |= MSG_CTRUNC;
2511 		cmlen = kmsg->msg_controllen;
2512 	}
2513 	cmhdr.cmsg_level = level;
2514 	cmhdr.cmsg_type = type;
2515 	cmhdr.cmsg_len = cmlen;
2516 
2517 	if(copy_to_user(cm, &cmhdr, sizeof cmhdr))
2518 		return;
2519 	if(copy_to_user(CMSG32_DATA(cm), data, cmlen - sizeof(struct cmsghdr32)))
2520 		return;
2521 	cmlen = CMSG32_SPACE(len);
2522 	kmsg->msg_control += cmlen;
2523 	kmsg->msg_controllen -= cmlen;
2524 }
2525 
scm_detach_fds32(struct msghdr * kmsg,struct scm_cookie * scm)2526 static void scm_detach_fds32(struct msghdr *kmsg, struct scm_cookie *scm)
2527 {
2528 	struct cmsghdr32 *cm = (struct cmsghdr32 *) kmsg->msg_control;
2529 	int fdmax = (kmsg->msg_controllen - sizeof(struct cmsghdr32)) / sizeof(int);
2530 	int fdnum = scm->fp->count;
2531 	struct file **fp = scm->fp->fp;
2532 	int *cmfptr;
2533 	int err = 0, i;
2534 
2535 	if (fdnum < fdmax)
2536 		fdmax = fdnum;
2537 
2538 	for (i = 0, cmfptr = (int *) CMSG32_DATA(cm); i < fdmax; i++, cmfptr++) {
2539 		int new_fd;
2540 		err = get_unused_fd();
2541 		if (err < 0)
2542 			break;
2543 		new_fd = err;
2544 		err = put_user(new_fd, cmfptr);
2545 		if (err) {
2546 			put_unused_fd(new_fd);
2547 			break;
2548 		}
2549 		/* Bump the usage count and install the file. */
2550 		get_file(fp[i]);
2551 		fd_install(new_fd, fp[i]);
2552 	}
2553 
2554 	if (i > 0) {
2555 		int cmlen = CMSG32_LEN(i * sizeof(int));
2556 		if (!err)
2557 			err = put_user(SOL_SOCKET, &cm->cmsg_level);
2558 		if (!err)
2559 			err = put_user(SCM_RIGHTS, &cm->cmsg_type);
2560 		if (!err)
2561 			err = put_user(cmlen, &cm->cmsg_len);
2562 		if (!err) {
2563 			cmlen = CMSG32_SPACE(i * sizeof(int));
2564 			kmsg->msg_control += cmlen;
2565 			kmsg->msg_controllen -= cmlen;
2566 		}
2567 	}
2568 	if (i < fdnum)
2569 		kmsg->msg_flags |= MSG_CTRUNC;
2570 
2571 	/*
2572 	 * All of the files that fit in the message have had their
2573 	 * usage counts incremented, so we just free the list.
2574 	 */
2575 	__scm_destroy(scm);
2576 }
2577 
2578 /* In these cases we (currently) can just copy to data over verbatim
2579  * because all CMSGs created by the kernel have well defined types which
2580  * have the same layout in both the 32-bit and 64-bit API.  One must add
2581  * some special cased conversions here if we start sending control messages
2582  * with incompatible types.
2583  *
2584  * SCM_RIGHTS and SCM_CREDENTIALS are done by hand in recvmsg32 right after
2585  * we do our work.  The remaining cases are:
2586  *
2587  * SOL_IP	IP_PKTINFO	struct in_pktinfo	32-bit clean
2588  *		IP_TTL		int			32-bit clean
2589  *		IP_TOS		__u8			32-bit clean
2590  *		IP_RECVOPTS	variable length		32-bit clean
2591  *		IP_RETOPTS	variable length		32-bit clean
2592  *		(these last two are clean because the types are defined
2593  *		 by the IPv4 protocol)
2594  *		IP_RECVERR	struct sock_extended_err +
2595  *				struct sockaddr_in	32-bit clean
2596  * SOL_IPV6	IPV6_RECVERR	struct sock_extended_err +
2597  *				struct sockaddr_in6	32-bit clean
2598  *		IPV6_PKTINFO	struct in6_pktinfo	32-bit clean
2599  *		IPV6_HOPLIMIT	int			32-bit clean
2600  *		IPV6_FLOWINFO	u32			32-bit clean
2601  *		IPV6_HOPOPTS	ipv6 hop exthdr		32-bit clean
2602  *		IPV6_DSTOPTS	ipv6 dst exthdr(s)	32-bit clean
2603  *		IPV6_RTHDR	ipv6 routing exthdr	32-bit clean
2604  *		IPV6_AUTHHDR	ipv6 auth exthdr	32-bit clean
2605  */
cmsg32_recvmsg_fixup(struct msghdr * kmsg,unsigned long orig_cmsg_uptr,__kernel_size_t orig_cmsg_len)2606 static void cmsg32_recvmsg_fixup(struct msghdr *kmsg,
2607 		unsigned long orig_cmsg_uptr, __kernel_size_t orig_cmsg_len)
2608 {
2609 	unsigned char *workbuf, *wp;
2610 	unsigned long bufsz, space_avail;
2611 	struct cmsghdr *ucmsg;
2612 
2613 	bufsz = ((unsigned long)kmsg->msg_control) - orig_cmsg_uptr;
2614 	space_avail = kmsg->msg_controllen + bufsz;
2615 	wp = workbuf = kmalloc(bufsz, GFP_KERNEL);
2616 	if(workbuf == NULL)
2617 		goto fail;
2618 
2619 	/* To make this more sane we assume the kernel sends back properly
2620 	 * formatted control messages.  Because of how the kernel will truncate
2621 	 * the cmsg_len for MSG_TRUNC cases, we need not check that case either.
2622 	 */
2623 	ucmsg = (struct cmsghdr *) orig_cmsg_uptr;
2624 	while(((unsigned long)ucmsg) <=
2625 	      (((unsigned long)kmsg->msg_control) - sizeof(struct cmsghdr))) {
2626 		struct cmsghdr32 *kcmsg32 = (struct cmsghdr32 *) wp;
2627 		int clen64, clen32;
2628 
2629 		/* UCMSG is the 64-bit format CMSG entry in user-space.
2630 		 * KCMSG32 is within the kernel space temporary buffer
2631 		 * we use to convert into a 32-bit style CMSG.
2632 		 */
2633 		__get_user(kcmsg32->cmsg_len, &ucmsg->cmsg_len);
2634 		__get_user(kcmsg32->cmsg_level, &ucmsg->cmsg_level);
2635 		__get_user(kcmsg32->cmsg_type, &ucmsg->cmsg_type);
2636 
2637 		clen64 = kcmsg32->cmsg_len;
2638 		if ((clen64 < CMSG_ALIGN(sizeof(*ucmsg))) ||
2639 				(clen64 > (orig_cmsg_len + wp - workbuf)))
2640 			break;
2641 		copy_from_user(CMSG32_DATA(kcmsg32), CMSG_DATA(ucmsg),
2642 			       clen64 - CMSG_ALIGN(sizeof(*ucmsg)));
2643 		clen32 = ((clen64 - CMSG_ALIGN(sizeof(*ucmsg))) +
2644 			  CMSG32_ALIGN(sizeof(struct cmsghdr32)));
2645 		kcmsg32->cmsg_len = clen32;
2646 
2647 		switch (kcmsg32->cmsg_type) {
2648 			/*
2649 			 * The timestamp type's data needs to be converted
2650 			 * from 64-bit time values to 32-bit time values
2651 			*/
2652 		case SO_TIMESTAMP: {
2653 			__kernel_time_t32* ptr_time32 = CMSG32_DATA(kcmsg32);
2654 			__kernel_time_t*   ptr_time   = CMSG_DATA(ucmsg);
2655 			get_user(*ptr_time32, ptr_time);
2656 			get_user(*(ptr_time32+1), ptr_time+1);
2657 			kcmsg32->cmsg_len -= 2*(sizeof(__kernel_time_t) -
2658 						sizeof(__kernel_time_t32));
2659 		}
2660 		default:;
2661 		}
2662 		ucmsg = (struct cmsghdr *) (((char *)ucmsg) + CMSG_ALIGN(clen64));
2663 		wp = (((char *)kcmsg32) + CMSG32_ALIGN(kcmsg32->cmsg_len));
2664 	}
2665 
2666 	/* Copy back fixed up data, and adjust pointers. */
2667 	bufsz = (wp - workbuf);
2668 	copy_to_user((void *)orig_cmsg_uptr, workbuf, bufsz);
2669 
2670 	kmsg->msg_control = (struct cmsghdr *)
2671 		(((char *)orig_cmsg_uptr) + bufsz);
2672 	kmsg->msg_controllen = space_avail - bufsz;
2673 
2674 	kfree(workbuf);
2675 	return;
2676 
2677 fail:
2678 	/* If we leave the 64-bit format CMSG chunks in there,
2679 	 * the application could get confused and crash.  So to
2680 	 * ensure greater recovery, we report no CMSGs.
2681 	 */
2682 	kmsg->msg_controllen += bufsz;
2683 	kmsg->msg_control = (void *) orig_cmsg_uptr;
2684 }
2685 
2686 #if 0
2687 asmlinkage int sys32_sendmsg(int fd, struct msghdr32 *user_msg, unsigned user_flags)
2688 {
2689 	struct socket *sock;
2690 	char address[MAX_SOCK_ADDR];
2691 	struct iovec iov[UIO_FASTIOV];
2692 	unsigned char ctl[sizeof(struct cmsghdr) + 20];
2693 	unsigned char *ctl_buf = ctl;
2694 	struct msghdr kern_msg;
2695 	int err, total_len;
2696 
2697 	if(msghdr_from_user32_to_kern(&kern_msg, user_msg))
2698 		return -EFAULT;
2699 	if(kern_msg.msg_iovlen > UIO_MAXIOV)
2700 		return -EINVAL;
2701 	err = verify_iovec32(&kern_msg, iov, address, VERIFY_READ);
2702 	if (err < 0)
2703 		goto out;
2704 	total_len = err;
2705 
2706 	if(kern_msg.msg_controllen) {
2707 		err = cmsghdr_from_user32_to_kern(&kern_msg, ctl, sizeof(ctl));
2708 		if(err)
2709 			goto out_freeiov;
2710 		ctl_buf = kern_msg.msg_control;
2711 	}
2712 	kern_msg.msg_flags = user_flags;
2713 
2714 	sock = sockfd_lookup(fd, &err);
2715 	if (sock != NULL) {
2716 		if (sock->file->f_flags & O_NONBLOCK)
2717 			kern_msg.msg_flags |= MSG_DONTWAIT;
2718 		err = sock_sendmsg(sock, &kern_msg, total_len);
2719 		sockfd_put(sock);
2720 	}
2721 
2722 	/* N.B. Use kfree here, as kern_msg.msg_controllen might change? */
2723 	if(ctl_buf != ctl)
2724 		kfree(ctl_buf);
2725 out_freeiov:
2726 	if(kern_msg.msg_iov != iov)
2727 		kfree(kern_msg.msg_iov);
2728 out:
2729 	return err;
2730 }
2731 
2732 asmlinkage int sys32_recvmsg(int fd, struct msghdr32 *user_msg, unsigned int user_flags)
2733 {
2734 	struct iovec iovstack[UIO_FASTIOV];
2735 	struct msghdr kern_msg;
2736 	char addr[MAX_SOCK_ADDR];
2737 	struct socket *sock;
2738 	struct iovec *iov = iovstack;
2739 	struct sockaddr *uaddr;
2740 	int *uaddr_len;
2741 	unsigned long cmsg_ptr;
2742 	int err, total_len, len = 0;
2743 
2744 	if(msghdr_from_user32_to_kern(&kern_msg, user_msg))
2745 		return -EFAULT;
2746 	if(kern_msg.msg_iovlen > UIO_MAXIOV)
2747 		return -EINVAL;
2748 
2749 	uaddr = kern_msg.msg_name;
2750 	uaddr_len = &user_msg->msg_namelen;
2751 	err = verify_iovec32(&kern_msg, iov, addr, VERIFY_WRITE);
2752 	if (err < 0)
2753 		goto out;
2754 	total_len = err;
2755 
2756 	cmsg_ptr = (unsigned long) kern_msg.msg_control;
2757 	kern_msg.msg_flags = 0;
2758 
2759 	sock = sockfd_lookup(fd, &err);
2760 	if (sock != NULL) {
2761 		struct scm_cookie scm;
2762 
2763 		if (sock->file->f_flags & O_NONBLOCK)
2764 			user_flags |= MSG_DONTWAIT;
2765 		memset(&scm, 0, sizeof(scm));
2766 		err = sock->ops->recvmsg(sock, &kern_msg, total_len,
2767 					 user_flags, &scm);
2768 		if(err >= 0) {
2769 			len = err;
2770 			if(!kern_msg.msg_control) {
2771 				if(sock->passcred || scm.fp)
2772 					kern_msg.msg_flags |= MSG_CTRUNC;
2773 				if(scm.fp)
2774 					__scm_destroy(&scm);
2775 			} else {
2776 				/* If recvmsg processing itself placed some
2777 				 * control messages into user space, it's is
2778 				 * using 64-bit CMSG processing, so we need
2779 				 * to fix it up before we tack on more stuff.
2780 				 */
2781 				if((unsigned long) kern_msg.msg_control != cmsg_ptr)
2782 					cmsg32_recvmsg_fixup(&kern_msg, cmsg_ptr);
2783 
2784 				/* Wheee... */
2785 				if(sock->passcred)
2786 					put_cmsg32(&kern_msg,
2787 						   SOL_SOCKET, SCM_CREDENTIALS,
2788 						   sizeof(scm.creds), &scm.creds);
2789 				if(scm.fp != NULL)
2790 					scm_detach_fds32(&kern_msg, &scm);
2791 			}
2792 		}
2793 		sockfd_put(sock);
2794 	}
2795 
2796 	if(uaddr != NULL && err >= 0 && kern_msg.msg_namelen)
2797 		err = move_addr_to_user(addr, kern_msg.msg_namelen, uaddr, uaddr_len);
2798 	if(cmsg_ptr != 0 && err >= 0) {
2799 		unsigned long ucmsg_ptr = ((unsigned long)kern_msg.msg_control);
2800 		__kernel_size_t32 uclen = (__kernel_size_t32) (ucmsg_ptr - cmsg_ptr);
2801 		err |= __put_user(uclen, &user_msg->msg_controllen);
2802 	}
2803 	if(err >= 0)
2804 		err = __put_user(kern_msg.msg_flags, &user_msg->msg_flags);
2805 	if(kern_msg.msg_iov != iov)
2806 		kfree(kern_msg.msg_iov);
2807 out:
2808 	if(err < 0)
2809 		return err;
2810 	return len;
2811 }
2812 #endif
2813 
2814 /*
2815  *	BSD sendmsg interface
2816  */
2817 
sys32_sendmsg(int fd,struct msghdr32 * msg,unsigned flags)2818 int sys32_sendmsg(int fd, struct msghdr32 *msg, unsigned flags)
2819 {
2820 	struct socket *sock;
2821 	char address[MAX_SOCK_ADDR];
2822 	struct iovec iovstack[UIO_FASTIOV], *iov = iovstack;
2823 	unsigned char ctl[sizeof(struct cmsghdr) + 20];	/* 20 is size of ipv6_pktinfo */
2824 	unsigned char *ctl_buf = ctl;
2825 	struct msghdr msg_sys;
2826 	int err, ctl_len, iov_size, total_len;
2827 
2828 	err = -EFAULT;
2829 	if (msghdr_from_user32_to_kern(&msg_sys, msg))
2830 		goto out;
2831 
2832 	sock = sockfd_lookup(fd, &err);
2833 	if (!sock)
2834 		goto out;
2835 
2836 	/* do not move before msg_sys is valid */
2837 	err = -EINVAL;
2838 	if (msg_sys.msg_iovlen > UIO_MAXIOV)
2839 		goto out_put;
2840 
2841 	/* Check whether to allocate the iovec area*/
2842 	err = -ENOMEM;
2843 	iov_size = msg_sys.msg_iovlen * sizeof(struct iovec32);
2844 	if (msg_sys.msg_iovlen > UIO_FASTIOV) {
2845 		iov = sock_kmalloc(sock->sk, iov_size, GFP_KERNEL);
2846 		if (!iov)
2847 			goto out_put;
2848 	}
2849 
2850 	/* This will also move the address data into kernel space */
2851 	err = verify_iovec32(&msg_sys, iov, address, VERIFY_READ);
2852 	if (err < 0)
2853 		goto out_freeiov;
2854 	total_len = err;
2855 
2856 	err = -ENOBUFS;
2857 
2858 	if (msg_sys.msg_controllen > INT_MAX)
2859 		goto out_freeiov;
2860 	ctl_len = msg_sys.msg_controllen;
2861 	if (ctl_len)
2862 	{
2863 		if (ctl_len > sizeof(ctl))
2864 		{
2865 			ctl_buf = sock_kmalloc(sock->sk, ctl_len, GFP_KERNEL);
2866 			if (ctl_buf == NULL)
2867 				goto out_freeiov;
2868 		}
2869 		else if (ctl_len < sizeof(struct cmsghdr))
2870 		{
2871 			/* to get same error message as on 31 bit native */
2872 			err = EOPNOTSUPP;
2873 			goto out_freeiov;
2874 		}
2875 		err = -EFAULT;
2876 		if (cmsghdr_from_user32_to_kern(&msg_sys, ctl_buf, ctl_len))
2877 			goto out_freectl;
2878 //		msg_sys.msg_control = ctl_buf;
2879 	}
2880 	msg_sys.msg_flags = flags;
2881 
2882 	if (sock->file->f_flags & O_NONBLOCK)
2883 		msg_sys.msg_flags |= MSG_DONTWAIT;
2884 	err = sock_sendmsg(sock, &msg_sys, total_len);
2885 
2886 out_freectl:
2887 	if (ctl_buf != ctl)
2888 		sock_kfree_s(sock->sk, ctl_buf, ctl_len);
2889 out_freeiov:
2890 	if (iov != iovstack)
2891 		sock_kfree_s(sock->sk, iov, iov_size);
2892 out_put:
2893 	sockfd_put(sock);
2894 out:
2895 	return err;
2896 }
2897 
2898 static __inline__ void
scm_recv32(struct socket * sock,struct msghdr * msg,struct scm_cookie * scm,int flags,unsigned long cmsg_ptr,__kernel_size_t cmsg_len)2899 scm_recv32(struct socket *sock, struct msghdr *msg,
2900 		struct scm_cookie *scm, int flags, unsigned long cmsg_ptr,
2901 		__kernel_size_t cmsg_len)
2902 {
2903 	if(!msg->msg_control)
2904 	{
2905 		if(sock->passcred || scm->fp)
2906 			msg->msg_flags |= MSG_CTRUNC;
2907 		scm_destroy(scm);
2908 		return;
2909 	}
2910 	/* If recvmsg processing itself placed some
2911 	 * control messages into user space, it's is
2912 	 * using 64-bit CMSG processing, so we need
2913 	 * to fix it up before we tack on more stuff.
2914 	 */
2915 	if((unsigned long) msg->msg_control != cmsg_ptr)
2916 		cmsg32_recvmsg_fixup(msg, cmsg_ptr, cmsg_len);
2917 	/* Wheee... */
2918 	if(sock->passcred)
2919 		put_cmsg32(msg,
2920 			SOL_SOCKET, SCM_CREDENTIALS,
2921 			sizeof(scm->creds), &scm->creds);
2922 	if(!scm->fp)
2923 		return;
2924 
2925 	scm_detach_fds32(msg, scm);
2926 }
2927 
2928 static int
sock_recvmsg32(struct socket * sock,struct msghdr * msg,int size,int flags,unsigned long cmsg_ptr,__kernel_size_t cmsg_len)2929 sock_recvmsg32(struct socket *sock, struct msghdr *msg, int size, int flags,
2930                unsigned long cmsg_ptr, __kernel_size_t cmsg_len)
2931 {
2932 	struct scm_cookie scm;
2933 
2934 	memset(&scm, 0, sizeof(scm));
2935 	size = sock->ops->recvmsg(sock, msg, size, flags, &scm);
2936 	if (size >= 0)
2937 		scm_recv32(sock, msg, &scm, flags, cmsg_ptr, cmsg_len);
2938 
2939 	return size;
2940 }
2941 
2942 /*
2943  *	BSD recvmsg interface
2944  */
2945 
2946 int
sys32_recvmsg(int fd,struct msghdr32 * msg,unsigned int flags)2947 sys32_recvmsg (int fd, struct msghdr32 *msg, unsigned int flags)
2948 {
2949 	struct socket *sock;
2950 	struct iovec iovstack[UIO_FASTIOV];
2951 	struct iovec *iov=iovstack;
2952 	struct msghdr msg_sys;
2953 	unsigned long cmsg_ptr;
2954 	__kernel_size_t cmsg_len;
2955 	int err, iov_size, total_len, len;
2956 
2957 	/* kernel mode address */
2958 	char addr[MAX_SOCK_ADDR];
2959 
2960 	/* user mode address pointers */
2961 	struct sockaddr *uaddr;
2962 	int *uaddr_len;
2963 
2964 	err=-EFAULT;
2965 	if (msghdr_from_user32_to_kern(&msg_sys, msg))
2966 		goto out;
2967 
2968 	sock = sockfd_lookup(fd, &err);
2969 	if (!sock)
2970 		goto out;
2971 
2972 	err = -EINVAL;
2973 	if (msg_sys.msg_iovlen > UIO_MAXIOV)
2974 		goto out_put;
2975 
2976 	/* Check whether to allocate the iovec area*/
2977 	err = -ENOMEM;
2978 	iov_size = msg_sys.msg_iovlen * sizeof(struct iovec);
2979 	if (msg_sys.msg_iovlen > UIO_FASTIOV) {
2980 		iov = sock_kmalloc(sock->sk, iov_size, GFP_KERNEL);
2981 		if (!iov)
2982 			goto out_put;
2983 	}
2984 
2985 	/*
2986 	 *	Save the user-mode address (verify_iovec will change the
2987 	 *	kernel msghdr to use the kernel address space)
2988 	 */
2989 
2990 	uaddr = msg_sys.msg_name;
2991 	uaddr_len = &msg->msg_namelen;
2992 	err = verify_iovec32(&msg_sys, iov, addr, VERIFY_WRITE);
2993 	if (err < 0)
2994 		goto out_freeiov;
2995 	total_len=err;
2996 
2997 	cmsg_ptr = (unsigned long)msg_sys.msg_control;
2998 	cmsg_len = msg_sys.msg_controllen;
2999 	msg_sys.msg_flags = 0;
3000 
3001 	if (sock->file->f_flags & O_NONBLOCK)
3002 		flags |= MSG_DONTWAIT;
3003 	err = sock_recvmsg32(sock, &msg_sys, total_len, flags, cmsg_ptr, cmsg_len);
3004 	if (err < 0)
3005 		goto out_freeiov;
3006 	len = err;
3007 
3008 	if (uaddr != NULL &&
3009 	/* in order to get same error message as on native 31 bit */
3010 		msg_sys.msg_namelen > 0) {
3011 		err = move_addr_to_user(addr, msg_sys.msg_namelen, uaddr, uaddr_len);
3012 		if (err < 0)
3013 			goto out_freeiov;
3014 	}
3015 	err = __put_user(msg_sys.msg_flags, &msg->msg_flags);
3016 	if (err)
3017 		goto out_freeiov;
3018 	err = __put_user((__kernel_size_t32) ((unsigned long)msg_sys.msg_control - cmsg_ptr), &msg->msg_controllen);
3019 	if (err)
3020 		goto out_freeiov;
3021 	err = len;
3022 
3023 out_freeiov:
3024 	if (iov != iovstack)
3025 		sock_kfree_s(sock->sk, iov, iov_size);
3026 out_put:
3027 	sockfd_put(sock);
3028 out:
3029 	return err;
3030 }
3031 
3032 extern asmlinkage int sys_setsockopt(int fd, int level, int optname,
3033 				     char *optval, int optlen);
3034 
do_set_attach_filter(int fd,int level,int optname,char * optval,int optlen)3035 static int do_set_attach_filter(int fd, int level, int optname,
3036 				char *optval, int optlen)
3037 {
3038 	struct sock_fprog32 {
3039 		__u16 len;
3040 		__u32 filter;
3041 	} *fprog32 = (struct sock_fprog32 *)optval;
3042 	struct sock_fprog kfprog;
3043 	struct sock_filter *kfilter;
3044 	unsigned int fsize;
3045 	mm_segment_t old_fs;
3046 	__u32 uptr;
3047 	int ret;
3048 
3049 	if (get_user(kfprog.len, &fprog32->len) ||
3050 	    __get_user(uptr, &fprog32->filter))
3051 		return -EFAULT;
3052 
3053 	kfprog.filter = (struct sock_filter *)A(uptr);
3054 	fsize = kfprog.len * sizeof(struct sock_filter);
3055 
3056 	kfilter = (struct sock_filter *)kmalloc(fsize, GFP_KERNEL);
3057 	if (kfilter == NULL)
3058 		return -ENOMEM;
3059 
3060 	if (copy_from_user(kfilter, kfprog.filter, fsize)) {
3061 		kfree(kfilter);
3062 		return -EFAULT;
3063 	}
3064 
3065 	kfprog.filter = kfilter;
3066 
3067 	old_fs = get_fs();
3068 	set_fs(KERNEL_DS);
3069 	ret = sys_setsockopt(fd, level, optname,
3070 			     (char *)&kfprog, sizeof(kfprog));
3071 	set_fs(old_fs);
3072 
3073 	kfree(kfilter);
3074 
3075 	return ret;
3076 }
3077 
do_set_icmpv6_filter(int fd,int level,int optname,char * optval,int optlen)3078 static int do_set_icmpv6_filter(int fd, int level, int optname,
3079 				char *optval, int optlen)
3080 {
3081 	struct icmp6_filter kfilter;
3082 	mm_segment_t old_fs;
3083 	int ret, i;
3084 
3085 	if (copy_from_user(&kfilter, optval, sizeof(kfilter)))
3086 		return -EFAULT;
3087 
3088 
3089 	for (i = 0; i < 8; i += 2) {
3090 		u32 tmp = kfilter.data[i];
3091 
3092 		kfilter.data[i] = kfilter.data[i + 1];
3093 		kfilter.data[i + 1] = tmp;
3094 	}
3095 
3096 	old_fs = get_fs();
3097 	set_fs(KERNEL_DS);
3098 	ret = sys_setsockopt(fd, level, optname,
3099 			     (char *) &kfilter, sizeof(kfilter));
3100 	set_fs(old_fs);
3101 
3102 	return ret;
3103 }
3104 
sys32_setsockopt(int fd,int level,int optname,char * optval,int optlen)3105 asmlinkage int sys32_setsockopt(int fd, int level, int optname,
3106 				char *optval, int optlen)
3107 {
3108 	if (optname == SO_ATTACH_FILTER)
3109 		return do_set_attach_filter(fd, level, optname,
3110 					    optval, optlen);
3111 	if (level == SOL_ICMPV6 && optname == ICMPV6_FILTER)
3112 		return do_set_icmpv6_filter(fd, level, optname,
3113 					    optval, optlen);
3114 	if (level == SOL_SOCKET &&
3115 	    (optname == SO_SNDTIMEO || optname == SO_RCVTIMEO)) {
3116 		long ret;
3117 		struct timeval tmp;
3118 		mm_segment_t old_fs;
3119 
3120 		if (get_tv32(&tmp, (struct timeval32 *)optval ))
3121 			return -EFAULT;
3122 		old_fs = get_fs();
3123 		set_fs(KERNEL_DS);
3124 		ret = sys_setsockopt(fd, level, optname, (char *) &tmp, sizeof(struct timeval));
3125 		set_fs(old_fs);
3126 		return ret;
3127 	}
3128 
3129 	return sys_setsockopt(fd, level, optname, optval, optlen);
3130 }
3131 
3132 extern void check_pending(int signum);
3133 
3134 /*
3135  * count32() counts the number of arguments/envelopes
3136  */
count32(u32 * argv)3137 static int count32(u32 * argv)
3138 {
3139 	int i = 0;
3140 
3141 	if (argv != NULL) {
3142 		for (;;) {
3143 			u32 p; int error;
3144 
3145 			error = get_user(p,argv);
3146 			if (error) return error;
3147 			if (!p) break;
3148 			argv++; i++;
3149 		}
3150 	}
3151 	return i;
3152 }
3153 
3154 /*
3155  * 'copy_string32()' copies argument/envelope strings from user
3156  * memory to free pages in kernel mem. These are in a format ready
3157  * to be put directly into the top of new user memory.
3158  */
copy_strings32(int argc,u32 * argv,struct linux_binprm * bprm)3159 static int copy_strings32(int argc, u32 * argv, struct linux_binprm *bprm)
3160 {
3161 	while (argc-- > 0) {
3162 		u32 str;
3163 		int len;
3164 		unsigned long pos;
3165 
3166 		if (get_user(str, argv + argc) ||
3167 		    !str ||
3168 		    !(len = strnlen_user((char *)A(str), bprm->p)))
3169 			return -EFAULT;
3170 
3171 		if (bprm->p < len)
3172 			return -E2BIG;
3173 
3174 		bprm->p -= len;
3175 
3176 		pos = bprm->p;
3177 		while (len) {
3178 			char *kaddr;
3179 			struct page *page;
3180 			int offset, bytes_to_copy, new, err;
3181 
3182 			offset = pos % PAGE_SIZE;
3183 			page = bprm->page[pos / PAGE_SIZE];
3184 			new = 0;
3185 			if (!page) {
3186 				page = alloc_page(GFP_USER);
3187 				bprm->page[pos / PAGE_SIZE] = page;
3188 				if (!page)
3189 					return -ENOMEM;
3190 				new = 1;
3191 			}
3192 			kaddr = (char *)kmap(page);
3193 
3194 			if (new && offset)
3195 				memset(kaddr, 0, offset);
3196 			bytes_to_copy = PAGE_SIZE - offset;
3197 			if (bytes_to_copy > len) {
3198 				bytes_to_copy = len;
3199 				if (new)
3200 					memset(kaddr+offset+len, 0,
3201 					       PAGE_SIZE-offset-len);
3202 			}
3203 
3204 			err = copy_from_user(kaddr + offset, (char *)A(str),
3205 					     bytes_to_copy);
3206 			flush_page_to_ram(page);
3207 			kunmap(page);
3208 
3209 			if (err)
3210 				return -EFAULT;
3211 
3212 			pos += bytes_to_copy;
3213 			str += bytes_to_copy;
3214 			len -= bytes_to_copy;
3215 		}
3216 	}
3217 	return 0;
3218 }
3219 
3220 /*
3221  * sys32_execve() executes a new program.
3222  */
3223 static inline int
do_execve32(char * filename,u32 * argv,u32 * envp,struct pt_regs * regs)3224 do_execve32(char * filename, u32 * argv, u32 * envp, struct pt_regs * regs)
3225 {
3226 	struct linux_binprm bprm;
3227 	struct file * file;
3228 	int retval;
3229 	int i;
3230 
3231 	bprm.p = PAGE_SIZE*MAX_ARG_PAGES-sizeof(void *);
3232 	memset(bprm.page, 0, MAX_ARG_PAGES * sizeof(bprm.page[0]));
3233 
3234 	file = open_exec(filename);
3235 
3236 	retval = PTR_ERR(file);
3237 	if (IS_ERR(file))
3238 		return retval;
3239 
3240 	bprm.file = file;
3241 	bprm.filename = filename;
3242 	bprm.sh_bang = 0;
3243 	bprm.loader = 0;
3244 	bprm.exec = 0;
3245 	if ((bprm.argc = count32(argv)) < 0) {
3246 		allow_write_access(file);
3247 		fput(file);
3248 		return bprm.argc;
3249 	}
3250 	if ((bprm.envc = count32(envp)) < 0) {
3251 		allow_write_access(file);
3252 		fput(file);
3253 		return bprm.envc;
3254 	}
3255 
3256 	retval = prepare_binprm(&bprm);
3257 	if (retval < 0)
3258 		goto out;
3259 
3260 	retval = copy_strings_kernel(1, &bprm.filename, &bprm);
3261 	if (retval < 0)
3262 		goto out;
3263 
3264 	bprm.exec = bprm.p;
3265 	retval = copy_strings32(bprm.envc, envp, &bprm);
3266 	if (retval < 0)
3267 		goto out;
3268 
3269 	retval = copy_strings32(bprm.argc, argv, &bprm);
3270 	if (retval < 0)
3271 		goto out;
3272 
3273 	retval = search_binary_handler(&bprm, regs);
3274 	if (retval >= 0)
3275 		/* execve success */
3276 		return retval;
3277 
3278 out:
3279 	/* Something went wrong, return the inode and free the argument pages*/
3280 	allow_write_access(bprm.file);
3281 	if (bprm.file)
3282 		fput(bprm.file);
3283 
3284 	for (i=0 ; i<MAX_ARG_PAGES ; i++)
3285 		if (bprm.page[i])
3286 			__free_page(bprm.page[i]);
3287 
3288 	return retval;
3289 }
3290 
3291 /*
3292  * sys32_execve() executes a new program after the asm stub has set
3293  * things up for us.  This should basically do what I want it to.
3294  */
3295 asmlinkage int
sys32_execve(struct pt_regs regs)3296 sys32_execve(struct pt_regs regs)
3297 {
3298         int error;
3299         char * filename;
3300 
3301         filename = getname((char *)A(regs.orig_gpr2));
3302         error = PTR_ERR(filename);
3303         if (IS_ERR(filename))
3304                 goto out;
3305         error = do_execve32(filename, (u32 *)A(regs.gprs[3]), (u32 *)A(regs.gprs[4]), &regs);
3306 	if (error == 0)
3307 	{
3308 		current->ptrace &= ~PT_DTRACE;
3309 		current->thread.fp_regs.fpc=0;
3310 		__asm__ __volatile__
3311 		        ("sr  0,0\n\t"
3312 		         "sfpc 0,0\n\t"
3313 			 : : :"0");
3314 	}
3315         putname(filename);
3316 out:
3317         return error;
3318 }
3319 
3320 
3321 #ifdef CONFIG_MODULES
3322 
3323 extern asmlinkage unsigned long sys_create_module(const char *name_user, size_t size);
3324 
sys32_create_module(const char * name_user,__kernel_size_t32 size)3325 asmlinkage unsigned long sys32_create_module(const char *name_user, __kernel_size_t32 size)
3326 {
3327 	return sys_create_module(name_user, (size_t)size);
3328 }
3329 
3330 extern asmlinkage int sys_init_module(const char *name_user, struct module *mod_user);
3331 
3332 /* Hey, when you're trying to init module, take time and prepare us a nice 64bit
3333  * module structure, even if from 32bit modutils... Why to pollute kernel... :))
3334  */
sys32_init_module(const char * name_user,struct module * mod_user)3335 asmlinkage int sys32_init_module(const char *name_user, struct module *mod_user)
3336 {
3337 	return sys_init_module(name_user, mod_user);
3338 }
3339 
3340 extern asmlinkage int sys_delete_module(const char *name_user);
3341 
sys32_delete_module(const char * name_user)3342 asmlinkage int sys32_delete_module(const char *name_user)
3343 {
3344 	return sys_delete_module(name_user);
3345 }
3346 
3347 struct module_info32 {
3348 	u32 addr;
3349 	u32 size;
3350 	u32 flags;
3351 	s32 usecount;
3352 };
3353 
3354 /* Query various bits about modules.  */
3355 
3356 static inline long
get_mod_name(const char * user_name,char ** buf)3357 get_mod_name(const char *user_name, char **buf)
3358 {
3359 	unsigned long page;
3360 	long retval;
3361 
3362 	if ((unsigned long)user_name >= TASK_SIZE
3363 	    && !segment_eq(get_fs (), KERNEL_DS))
3364 		return -EFAULT;
3365 
3366 	page = __get_free_page(GFP_KERNEL);
3367 	if (!page)
3368 		return -ENOMEM;
3369 
3370 	retval = strncpy_from_user((char *)page, user_name, PAGE_SIZE);
3371 	if (retval > 0) {
3372 		if (retval < PAGE_SIZE) {
3373 			*buf = (char *)page;
3374 			return retval;
3375 		}
3376 		retval = -ENAMETOOLONG;
3377 	} else if (!retval)
3378 		retval = -EINVAL;
3379 
3380 	free_page(page);
3381 	return retval;
3382 }
3383 
3384 static inline void
put_mod_name(char * buf)3385 put_mod_name(char *buf)
3386 {
3387 	free_page((unsigned long)buf);
3388 }
3389 
find_module(const char * name)3390 static __inline__ struct module *find_module(const char *name)
3391 {
3392 	struct module *mod;
3393 
3394 	for (mod = module_list; mod ; mod = mod->next) {
3395 		if (mod->flags & MOD_DELETED)
3396 			continue;
3397 		if (!strcmp(mod->name, name))
3398 			break;
3399 	}
3400 
3401 	return mod;
3402 }
3403 
3404 static int
qm_modules(char * buf,size_t bufsize,__kernel_size_t32 * ret)3405 qm_modules(char *buf, size_t bufsize, __kernel_size_t32 *ret)
3406 {
3407 	struct module *mod;
3408 	size_t nmod, space, len;
3409 
3410 	nmod = space = 0;
3411 
3412 	for (mod = module_list; mod->next != NULL; mod = mod->next, ++nmod) {
3413 		len = strlen(mod->name)+1;
3414 		if (len > bufsize)
3415 			goto calc_space_needed;
3416 		if (copy_to_user(buf, mod->name, len))
3417 			return -EFAULT;
3418 		buf += len;
3419 		bufsize -= len;
3420 		space += len;
3421 	}
3422 
3423 	if (put_user(nmod, ret))
3424 		return -EFAULT;
3425 	else
3426 		return 0;
3427 
3428 calc_space_needed:
3429 	space += len;
3430 	while ((mod = mod->next)->next != NULL)
3431 		space += strlen(mod->name)+1;
3432 
3433 	if (put_user(space, ret))
3434 		return -EFAULT;
3435 	else
3436 		return -ENOSPC;
3437 }
3438 
3439 static int
qm_deps(struct module * mod,char * buf,size_t bufsize,__kernel_size_t32 * ret)3440 qm_deps(struct module *mod, char *buf, size_t bufsize, __kernel_size_t32 *ret)
3441 {
3442 	size_t i, space, len;
3443 
3444 	if (mod->next == NULL)
3445 		return -EINVAL;
3446 	if (!MOD_CAN_QUERY(mod))
3447 		return put_user(0, ret);
3448 
3449 	space = 0;
3450 	for (i = 0; i < mod->ndeps; ++i) {
3451 		const char *dep_name = mod->deps[i].dep->name;
3452 
3453 		len = strlen(dep_name)+1;
3454 		if (len > bufsize)
3455 			goto calc_space_needed;
3456 		if (copy_to_user(buf, dep_name, len))
3457 			return -EFAULT;
3458 		buf += len;
3459 		bufsize -= len;
3460 		space += len;
3461 	}
3462 
3463 	return put_user(i, ret);
3464 
3465 calc_space_needed:
3466 	space += len;
3467 	while (++i < mod->ndeps)
3468 		space += strlen(mod->deps[i].dep->name)+1;
3469 
3470 	if (put_user(space, ret))
3471 		return -EFAULT;
3472 	else
3473 		return -ENOSPC;
3474 }
3475 
3476 static int
qm_refs(struct module * mod,char * buf,size_t bufsize,__kernel_size_t32 * ret)3477 qm_refs(struct module *mod, char *buf, size_t bufsize, __kernel_size_t32 *ret)
3478 {
3479 	size_t nrefs, space, len;
3480 	struct module_ref *ref;
3481 
3482 	if (mod->next == NULL)
3483 		return -EINVAL;
3484 	if (!MOD_CAN_QUERY(mod))
3485 		if (put_user(0, ret))
3486 			return -EFAULT;
3487 		else
3488 			return 0;
3489 
3490 	space = 0;
3491 	for (nrefs = 0, ref = mod->refs; ref ; ++nrefs, ref = ref->next_ref) {
3492 		const char *ref_name = ref->ref->name;
3493 
3494 		len = strlen(ref_name)+1;
3495 		if (len > bufsize)
3496 			goto calc_space_needed;
3497 		if (copy_to_user(buf, ref_name, len))
3498 			return -EFAULT;
3499 		buf += len;
3500 		bufsize -= len;
3501 		space += len;
3502 	}
3503 
3504 	if (put_user(nrefs, ret))
3505 		return -EFAULT;
3506 	else
3507 		return 0;
3508 
3509 calc_space_needed:
3510 	space += len;
3511 	while ((ref = ref->next_ref) != NULL)
3512 		space += strlen(ref->ref->name)+1;
3513 
3514 	if (put_user(space, ret))
3515 		return -EFAULT;
3516 	else
3517 		return -ENOSPC;
3518 }
3519 
3520 static inline int
qm_symbols(struct module * mod,char * buf,size_t bufsize,__kernel_size_t32 * ret)3521 qm_symbols(struct module *mod, char *buf, size_t bufsize, __kernel_size_t32 *ret)
3522 {
3523 	size_t i, space, len;
3524 	struct module_symbol *s;
3525 	char *strings;
3526 	unsigned *vals;
3527 
3528 	if (!MOD_CAN_QUERY(mod))
3529 		if (put_user(0, ret))
3530 			return -EFAULT;
3531 		else
3532 			return 0;
3533 
3534 	space = mod->nsyms * 2*sizeof(u32);
3535 
3536 	i = len = 0;
3537 	s = mod->syms;
3538 
3539 	if (space > bufsize)
3540 		goto calc_space_needed;
3541 
3542 	if (!access_ok(VERIFY_WRITE, buf, space))
3543 		return -EFAULT;
3544 
3545 	bufsize -= space;
3546 	vals = (unsigned *)buf;
3547 	strings = buf+space;
3548 
3549 	for (; i < mod->nsyms ; ++i, ++s, vals += 2) {
3550 		len = strlen(s->name)+1;
3551 		if (len > bufsize)
3552 			goto calc_space_needed;
3553 
3554 		if (copy_to_user(strings, s->name, len)
3555 		    || __put_user(s->value, vals+0)
3556 		    || __put_user(space, vals+1))
3557 			return -EFAULT;
3558 
3559 		strings += len;
3560 		bufsize -= len;
3561 		space += len;
3562 	}
3563 
3564 	if (put_user(i, ret))
3565 		return -EFAULT;
3566 	else
3567 		return 0;
3568 
3569 calc_space_needed:
3570 	for (; i < mod->nsyms; ++i, ++s)
3571 		space += strlen(s->name)+1;
3572 
3573 	if (put_user(space, ret))
3574 		return -EFAULT;
3575 	else
3576 		return -ENOSPC;
3577 }
3578 
3579 static inline int
qm_info(struct module * mod,char * buf,size_t bufsize,__kernel_size_t32 * ret)3580 qm_info(struct module *mod, char *buf, size_t bufsize, __kernel_size_t32 *ret)
3581 {
3582 	int error = 0;
3583 
3584 	if (mod->next == NULL)
3585 		return -EINVAL;
3586 
3587 	if (sizeof(struct module_info32) <= bufsize) {
3588 		struct module_info32 info;
3589 		info.addr = (unsigned long)mod;
3590 		info.size = mod->size;
3591 		info.flags = mod->flags;
3592 		info.usecount =
3593 			((mod_member_present(mod, can_unload)
3594 			  && mod->can_unload)
3595 			 ? -1 : atomic_read(&mod->uc.usecount));
3596 
3597 		if (copy_to_user(buf, &info, sizeof(struct module_info32)))
3598 			return -EFAULT;
3599 	} else
3600 		error = -ENOSPC;
3601 
3602 	if (put_user(sizeof(struct module_info32), ret))
3603 		return -EFAULT;
3604 
3605 	return error;
3606 }
3607 
sys32_query_module(char * name_user,int which,char * buf,__kernel_size_t32 bufsize,u32 ret)3608 asmlinkage int sys32_query_module(char *name_user, int which, char *buf, __kernel_size_t32 bufsize, u32 ret)
3609 {
3610 	struct module *mod;
3611 	int err;
3612 
3613 	lock_kernel();
3614 	if (name_user == 0) {
3615 		/* This finds "kernel_module" which is not exported. */
3616 		for(mod = module_list; mod->next != NULL; mod = mod->next)
3617 			;
3618 	} else {
3619 		long namelen;
3620 		char *name;
3621 
3622 		if ((namelen = get_mod_name(name_user, &name)) < 0) {
3623 			err = namelen;
3624 			goto out;
3625 		}
3626 		err = -ENOENT;
3627 		if (namelen == 0) {
3628 			/* This finds "kernel_module" which is not exported. */
3629 			for(mod = module_list; mod->next != NULL; mod = mod->next)
3630 				;
3631 		} else if ((mod = find_module(name)) == NULL) {
3632 			put_mod_name(name);
3633 			goto out;
3634 		}
3635 		put_mod_name(name);
3636 	}
3637 
3638 	switch (which)
3639 	{
3640 	case 0:
3641 		err = 0;
3642 		break;
3643 	case QM_MODULES:
3644 		err = qm_modules(buf, bufsize, (__kernel_size_t32 *)AA(ret));
3645 		break;
3646 	case QM_DEPS:
3647 		err = qm_deps(mod, buf, bufsize, (__kernel_size_t32 *)AA(ret));
3648 		break;
3649 	case QM_REFS:
3650 		err = qm_refs(mod, buf, bufsize, (__kernel_size_t32 *)AA(ret));
3651 		break;
3652 	case QM_SYMBOLS:
3653 		err = qm_symbols(mod, buf, bufsize, (__kernel_size_t32 *)AA(ret));
3654 		break;
3655 	case QM_INFO:
3656 		err = qm_info(mod, buf, bufsize, (__kernel_size_t32 *)AA(ret));
3657 		break;
3658 	default:
3659 		err = -EINVAL;
3660 		break;
3661 	}
3662 out:
3663 	unlock_kernel();
3664 	return err;
3665 }
3666 
3667 struct kernel_sym32 {
3668 	u32 value;
3669 	char name[60];
3670 };
3671 
3672 extern asmlinkage int sys_get_kernel_syms(struct kernel_sym *table);
3673 
sys32_get_kernel_syms(struct kernel_sym32 * table)3674 asmlinkage int sys32_get_kernel_syms(struct kernel_sym32 *table)
3675 {
3676 	int len, i;
3677 	struct kernel_sym *tbl;
3678 	mm_segment_t old_fs;
3679 
3680 	len = sys_get_kernel_syms(NULL);
3681 	if (!table) return len;
3682 	tbl = kmalloc (len * sizeof (struct kernel_sym), GFP_KERNEL);
3683 	if (!tbl) return -ENOMEM;
3684 	old_fs = get_fs();
3685 	set_fs (KERNEL_DS);
3686 	sys_get_kernel_syms(tbl);
3687 	set_fs (old_fs);
3688 	for (i = 0; i < len; i++, table += sizeof (struct kernel_sym32)) {
3689 		if (put_user (tbl[i].value, &table->value) ||
3690 		    copy_to_user (table->name, tbl[i].name, 60))
3691 			break;
3692 	}
3693 	kfree (tbl);
3694 	return i;
3695 }
3696 
3697 #else /* CONFIG_MODULES */
3698 
3699 asmlinkage unsigned long
sys32_create_module(const char * name_user,size_t size)3700 sys32_create_module(const char *name_user, size_t size)
3701 {
3702 	return -ENOSYS;
3703 }
3704 
3705 asmlinkage int
sys32_init_module(const char * name_user,struct module * mod_user)3706 sys32_init_module(const char *name_user, struct module *mod_user)
3707 {
3708 	return -ENOSYS;
3709 }
3710 
3711 asmlinkage int
sys32_delete_module(const char * name_user)3712 sys32_delete_module(const char *name_user)
3713 {
3714 	return -ENOSYS;
3715 }
3716 
3717 asmlinkage int
sys32_query_module(const char * name_user,int which,char * buf,size_t bufsize,size_t * ret)3718 sys32_query_module(const char *name_user, int which, char *buf, size_t bufsize,
3719 		 size_t *ret)
3720 {
3721 	/* Let the program know about the new interface.  Not that
3722 	   it'll do them much good.  */
3723 	if (which == 0)
3724 		return 0;
3725 
3726 	return -ENOSYS;
3727 }
3728 
3729 asmlinkage int
sys32_get_kernel_syms(struct kernel_sym * table)3730 sys32_get_kernel_syms(struct kernel_sym *table)
3731 {
3732 	return -ENOSYS;
3733 }
3734 
3735 #endif  /* CONFIG_MODULES */
3736 
3737 /* Stuff for NFS server syscalls... */
3738 struct nfsctl_svc32 {
3739 	u16			svc32_port;
3740 	s32			svc32_nthreads;
3741 };
3742 
3743 struct nfsctl_client32 {
3744 	s8			cl32_ident[NFSCLNT_IDMAX+1];
3745 	s32			cl32_naddr;
3746 	struct in_addr		cl32_addrlist[NFSCLNT_ADDRMAX];
3747 	s32			cl32_fhkeytype;
3748 	s32			cl32_fhkeylen;
3749 	u8			cl32_fhkey[NFSCLNT_KEYMAX];
3750 };
3751 
3752 struct nfsctl_export32 {
3753 	s8			ex32_client[NFSCLNT_IDMAX+1];
3754 	s8			ex32_path[NFS_MAXPATHLEN+1];
3755 	__kernel_dev_t32	ex32_dev;
3756 	__kernel_ino_t32	ex32_ino;
3757 	s32			ex32_flags;
3758 	__kernel_uid_t32	ex32_anon_uid;
3759 	__kernel_gid_t32	ex32_anon_gid;
3760 };
3761 
3762 struct nfsctl_uidmap32 {
3763 	u32			ug32_ident;   /* char * */
3764 	__kernel_uid_t32	ug32_uidbase;
3765 	s32			ug32_uidlen;
3766 	u32			ug32_udimap;  /* uid_t * */
3767 	__kernel_uid_t32	ug32_gidbase;
3768 	s32			ug32_gidlen;
3769 	u32			ug32_gdimap;  /* gid_t * */
3770 };
3771 
3772 struct nfsctl_fhparm32 {
3773 	struct sockaddr		gf32_addr;
3774 	__kernel_dev_t32	gf32_dev;
3775 	__kernel_ino_t32	gf32_ino;
3776 	s32			gf32_version;
3777 };
3778 
3779 struct nfsctl_fdparm32 {
3780 	struct sockaddr		gd32_addr;
3781 	s8			gd32_path[NFS_MAXPATHLEN+1];
3782 	s32			gd32_version;
3783 };
3784 
3785 struct nfsctl_fsparm32 {
3786 	struct sockaddr		gd32_addr;
3787 	s8			gd32_path[NFS_MAXPATHLEN+1];
3788 	s32			gd32_maxlen;
3789 };
3790 
3791 struct nfsctl_arg32 {
3792 	s32			ca32_version;	/* safeguard */
3793 	union {
3794 		struct nfsctl_svc32	u32_svc;
3795 		struct nfsctl_client32	u32_client;
3796 		struct nfsctl_export32	u32_export;
3797 		struct nfsctl_uidmap32	u32_umap;
3798 		struct nfsctl_fhparm32	u32_getfh;
3799 		struct nfsctl_fdparm32	u32_getfd;
3800 		struct nfsctl_fsparm32	u32_getfs;
3801 	} u;
3802 #define ca32_svc	u.u32_svc
3803 #define ca32_client	u.u32_client
3804 #define ca32_export	u.u32_export
3805 #define ca32_umap	u.u32_umap
3806 #define ca32_getfh	u.u32_getfh
3807 #define ca32_getfd	u.u32_getfd
3808 #define ca32_getfs	u.u32_getfs
3809 #define ca32_authd	u.u32_authd
3810 };
3811 
3812 union nfsctl_res32 {
3813 	__u8			cr32_getfh[NFS_FHSIZE];
3814 	struct knfsd_fh		cr32_getfs;
3815 };
3816 
nfs_svc32_trans(struct nfsctl_arg * karg,struct nfsctl_arg32 * arg32)3817 static int nfs_svc32_trans(struct nfsctl_arg *karg, struct nfsctl_arg32 *arg32)
3818 {
3819 	int err;
3820 
3821 	err = __get_user(karg->ca_version, &arg32->ca32_version);
3822 	err |= __get_user(karg->ca_svc.svc_port, &arg32->ca32_svc.svc32_port);
3823 	err |= __get_user(karg->ca_svc.svc_nthreads, &arg32->ca32_svc.svc32_nthreads);
3824 	return err;
3825 }
3826 
nfs_clnt32_trans(struct nfsctl_arg * karg,struct nfsctl_arg32 * arg32)3827 static int nfs_clnt32_trans(struct nfsctl_arg *karg, struct nfsctl_arg32 *arg32)
3828 {
3829 	int err;
3830 
3831 	err = __get_user(karg->ca_version, &arg32->ca32_version);
3832 	err |= copy_from_user(&karg->ca_client.cl_ident[0],
3833 			  &arg32->ca32_client.cl32_ident[0],
3834 			  NFSCLNT_IDMAX);
3835 	err |= __get_user(karg->ca_client.cl_naddr, &arg32->ca32_client.cl32_naddr);
3836 	err |= copy_from_user(&karg->ca_client.cl_addrlist[0],
3837 			  &arg32->ca32_client.cl32_addrlist[0],
3838 			  (sizeof(struct in_addr) * NFSCLNT_ADDRMAX));
3839 	err |= __get_user(karg->ca_client.cl_fhkeytype,
3840 		      &arg32->ca32_client.cl32_fhkeytype);
3841 	err |= __get_user(karg->ca_client.cl_fhkeylen,
3842 		      &arg32->ca32_client.cl32_fhkeylen);
3843 	err |= copy_from_user(&karg->ca_client.cl_fhkey[0],
3844 			  &arg32->ca32_client.cl32_fhkey[0],
3845 			  NFSCLNT_KEYMAX);
3846 	return err;
3847 }
3848 
nfs_exp32_trans(struct nfsctl_arg * karg,struct nfsctl_arg32 * arg32)3849 static int nfs_exp32_trans(struct nfsctl_arg *karg, struct nfsctl_arg32 *arg32)
3850 {
3851 	int err;
3852 
3853 	err = __get_user(karg->ca_version, &arg32->ca32_version);
3854 	err |= copy_from_user(&karg->ca_export.ex_client[0],
3855 			  &arg32->ca32_export.ex32_client[0],
3856 			  NFSCLNT_IDMAX);
3857 	err |= copy_from_user(&karg->ca_export.ex_path[0],
3858 			  &arg32->ca32_export.ex32_path[0],
3859 			  NFS_MAXPATHLEN);
3860 	err |= __get_user(karg->ca_export.ex_dev,
3861 		      &arg32->ca32_export.ex32_dev);
3862 	err |= __get_user(karg->ca_export.ex_ino,
3863 		      &arg32->ca32_export.ex32_ino);
3864 	err |= __get_user(karg->ca_export.ex_flags,
3865 		      &arg32->ca32_export.ex32_flags);
3866 	err |= __get_user(karg->ca_export.ex_anon_uid,
3867 		      &arg32->ca32_export.ex32_anon_uid);
3868 	err |= __get_user(karg->ca_export.ex_anon_gid,
3869 		      &arg32->ca32_export.ex32_anon_gid);
3870 	karg->ca_export.ex_anon_uid = high2lowuid(karg->ca_export.ex_anon_uid);
3871 	karg->ca_export.ex_anon_gid = high2lowgid(karg->ca_export.ex_anon_gid);
3872 	return err;
3873 }
3874 
nfs_uud32_trans(struct nfsctl_arg * karg,struct nfsctl_arg32 * arg32)3875 static int nfs_uud32_trans(struct nfsctl_arg *karg, struct nfsctl_arg32 *arg32)
3876 {
3877 	u32 uaddr;
3878 	int i;
3879 	int err;
3880 
3881 	memset(karg, 0, sizeof(*karg));
3882 	if(__get_user(karg->ca_version, &arg32->ca32_version))
3883 		return -EFAULT;
3884 	karg->ca_umap.ug_ident = (char *)get_free_page(GFP_USER);
3885 	if(!karg->ca_umap.ug_ident)
3886 		return -ENOMEM;
3887 	err = __get_user(uaddr, &arg32->ca32_umap.ug32_ident);
3888 	if(strncpy_from_user(karg->ca_umap.ug_ident,
3889 			     (char *)A(uaddr), PAGE_SIZE) <= 0)
3890 		return -EFAULT;
3891 	err |= __get_user(karg->ca_umap.ug_uidbase,
3892 		      &arg32->ca32_umap.ug32_uidbase);
3893 	err |= __get_user(karg->ca_umap.ug_uidlen,
3894 		      &arg32->ca32_umap.ug32_uidlen);
3895 	err |= __get_user(uaddr, &arg32->ca32_umap.ug32_udimap);
3896 	if (err)
3897 		return -EFAULT;
3898 	karg->ca_umap.ug_udimap = kmalloc((sizeof(uid_t) * karg->ca_umap.ug_uidlen),
3899 					  GFP_USER);
3900 	if(!karg->ca_umap.ug_udimap)
3901 		return -ENOMEM;
3902 	for(i = 0; i < karg->ca_umap.ug_uidlen; i++)
3903 		err |= __get_user(karg->ca_umap.ug_udimap[i],
3904 			      &(((__kernel_uid_t32 *)A(uaddr))[i]));
3905 	err |= __get_user(karg->ca_umap.ug_gidbase,
3906 		      &arg32->ca32_umap.ug32_gidbase);
3907 	err |= __get_user(karg->ca_umap.ug_uidlen,
3908 		      &arg32->ca32_umap.ug32_gidlen);
3909 	err |= __get_user(uaddr, &arg32->ca32_umap.ug32_gdimap);
3910 	if (err)
3911 		return -EFAULT;
3912 	karg->ca_umap.ug_gdimap = kmalloc((sizeof(gid_t) * karg->ca_umap.ug_uidlen),
3913 					  GFP_USER);
3914 	if(!karg->ca_umap.ug_gdimap)
3915 		return -ENOMEM;
3916 	for(i = 0; i < karg->ca_umap.ug_gidlen; i++)
3917 		err |= __get_user(karg->ca_umap.ug_gdimap[i],
3918 			      &(((__kernel_gid_t32 *)A(uaddr))[i]));
3919 
3920 	return err;
3921 }
3922 
nfs_getfh32_trans(struct nfsctl_arg * karg,struct nfsctl_arg32 * arg32)3923 static int nfs_getfh32_trans(struct nfsctl_arg *karg, struct nfsctl_arg32 *arg32)
3924 {
3925 	int err;
3926 
3927 	err = __get_user(karg->ca_version, &arg32->ca32_version);
3928 	err |= copy_from_user(&karg->ca_getfh.gf_addr,
3929 			  &arg32->ca32_getfh.gf32_addr,
3930 			  (sizeof(struct sockaddr)));
3931 	err |= __get_user(karg->ca_getfh.gf_dev,
3932 		      &arg32->ca32_getfh.gf32_dev);
3933 	err |= __get_user(karg->ca_getfh.gf_ino,
3934 		      &arg32->ca32_getfh.gf32_ino);
3935 	err |= __get_user(karg->ca_getfh.gf_version,
3936 		      &arg32->ca32_getfh.gf32_version);
3937 	return err;
3938 }
3939 
nfs_getfd32_trans(struct nfsctl_arg * karg,struct nfsctl_arg32 * arg32)3940 static int nfs_getfd32_trans(struct nfsctl_arg *karg, struct nfsctl_arg32 *arg32)
3941 {
3942 	int err;
3943 
3944 	err = __get_user(karg->ca_version, &arg32->ca32_version);
3945 	err |= copy_from_user(&karg->ca_getfd.gd_addr,
3946 			  &arg32->ca32_getfd.gd32_addr,
3947 			  (sizeof(struct sockaddr)));
3948 	err |= copy_from_user(&karg->ca_getfd.gd_path,
3949 			  &arg32->ca32_getfd.gd32_path,
3950 			  (NFS_MAXPATHLEN+1));
3951 	err |= __get_user(karg->ca_getfd.gd_version,
3952 		      &arg32->ca32_getfd.gd32_version);
3953 	return err;
3954 }
3955 
nfs_getfs32_trans(struct nfsctl_arg * karg,struct nfsctl_arg32 * arg32)3956 static int nfs_getfs32_trans(struct nfsctl_arg *karg, struct nfsctl_arg32 *arg32)
3957 {
3958 	int err;
3959 
3960 	err = __get_user(karg->ca_version, &arg32->ca32_version);
3961 	err |= copy_from_user(&karg->ca_getfs.gd_addr,
3962 			  &arg32->ca32_getfs.gd32_addr,
3963 			  (sizeof(struct sockaddr)));
3964 	err |= copy_from_user(&karg->ca_getfs.gd_path,
3965 			  &arg32->ca32_getfs.gd32_path,
3966 			  (NFS_MAXPATHLEN+1));
3967 	err |= __get_user(karg->ca_getfs.gd_maxlen,
3968 		      &arg32->ca32_getfs.gd32_maxlen);
3969 	return err;
3970 }
3971 
3972 /* This really doesn't need translations, we are only passing
3973  * back a union which contains opaque nfs file handle data.
3974  */
nfs_getfh32_res_trans(union nfsctl_res * kres,union nfsctl_res32 * res32)3975 static int nfs_getfh32_res_trans(union nfsctl_res *kres, union nfsctl_res32 *res32)
3976 {
3977 	return copy_to_user(res32, kres, sizeof(*res32)) ? -EFAULT : 0;
3978 }
3979 
3980 /*
3981 asmlinkage long sys_ni_syscall(void);
3982 */
3983 
sys32_nfsservctl(int cmd,struct nfsctl_arg32 * arg32,union nfsctl_res32 * res32)3984 int asmlinkage sys32_nfsservctl(int cmd, struct nfsctl_arg32 *arg32, union nfsctl_res32 *res32)
3985 {
3986 	struct nfsctl_arg *karg = NULL;
3987 	union nfsctl_res *kres = NULL;
3988 	mm_segment_t oldfs;
3989 	int err;
3990 
3991 	karg = kmalloc(sizeof(*karg), GFP_USER);
3992 	if(!karg)
3993 		return -ENOMEM;
3994 	if(res32) {
3995 		kres = kmalloc(sizeof(*kres), GFP_USER);
3996 		if(!kres) {
3997 			kfree(karg);
3998 			return -ENOMEM;
3999 		}
4000 	}
4001 	switch(cmd) {
4002 	case NFSCTL_SVC:
4003 		err = nfs_svc32_trans(karg, arg32);
4004 		break;
4005 	case NFSCTL_ADDCLIENT:
4006 		err = nfs_clnt32_trans(karg, arg32);
4007 		break;
4008 	case NFSCTL_DELCLIENT:
4009 		err = nfs_clnt32_trans(karg, arg32);
4010 		break;
4011 	case NFSCTL_EXPORT:
4012 	case NFSCTL_UNEXPORT:
4013 		err = nfs_exp32_trans(karg, arg32);
4014 		break;
4015 	/* This one is unimplemented, be we're ready for it. */
4016 	case NFSCTL_UGIDUPDATE:
4017 		err = nfs_uud32_trans(karg, arg32);
4018 		break;
4019 	case NFSCTL_GETFH:
4020 		err = nfs_getfh32_trans(karg, arg32);
4021 		break;
4022 	case NFSCTL_GETFD:
4023 		err = nfs_getfd32_trans(karg, arg32);
4024 		break;
4025 	case NFSCTL_GETFS:
4026 		err = nfs_getfs32_trans(karg, arg32);
4027 		break;
4028 	default:
4029 		err = -EINVAL;
4030 		break;
4031 	}
4032 	if(err)
4033 		goto done;
4034 	oldfs = get_fs();
4035 	set_fs(KERNEL_DS);
4036 	err = sys_nfsservctl(cmd, karg, kres);
4037 	set_fs(oldfs);
4038 
4039 	if (err)
4040 		goto done;
4041 
4042 	if((cmd == NFSCTL_GETFH) ||
4043 	   (cmd == NFSCTL_GETFD) ||
4044 	   (cmd == NFSCTL_GETFS))
4045 		err = nfs_getfh32_res_trans(kres, res32);
4046 
4047 done:
4048 	if(karg) {
4049 		if(cmd == NFSCTL_UGIDUPDATE) {
4050 			if(karg->ca_umap.ug_ident)
4051 				kfree(karg->ca_umap.ug_ident);
4052 			if(karg->ca_umap.ug_udimap)
4053 				kfree(karg->ca_umap.ug_udimap);
4054 			if(karg->ca_umap.ug_gdimap)
4055 				kfree(karg->ca_umap.ug_gdimap);
4056 		}
4057 		kfree(karg);
4058 	}
4059 	if(kres)
4060 		kfree(kres);
4061 	return err;
4062 }
4063 
4064 /* Translations due to time_t size differences.  Which affects all
4065    sorts of things, like timeval and itimerval.  */
4066 
4067 extern struct timezone sys_tz;
4068 extern int do_sys_settimeofday(struct timeval *tv, struct timezone *tz);
4069 
sys32_gettimeofday(struct timeval32 * tv,struct timezone * tz)4070 asmlinkage int sys32_gettimeofday(struct timeval32 *tv, struct timezone *tz)
4071 {
4072 	if (tv) {
4073 		struct timeval ktv;
4074 		do_gettimeofday(&ktv);
4075 		if (put_tv32(tv, &ktv))
4076 			return -EFAULT;
4077 	}
4078 	if (tz) {
4079 		if (copy_to_user(tz, &sys_tz, sizeof(sys_tz)))
4080 			return -EFAULT;
4081 	}
4082 	return 0;
4083 }
4084 
sys32_settimeofday(struct timeval32 * tv,struct timezone * tz)4085 asmlinkage int sys32_settimeofday(struct timeval32 *tv, struct timezone *tz)
4086 {
4087 	struct timeval ktv;
4088 	struct timezone ktz;
4089 
4090  	if (tv) {
4091 		if (get_tv32(&ktv, tv))
4092 			return -EFAULT;
4093 	}
4094 	if (tz) {
4095 		if (copy_from_user(&ktz, tz, sizeof(ktz)))
4096 			return -EFAULT;
4097 	}
4098 
4099 	return do_sys_settimeofday(tv ? &ktv : NULL, tz ? &ktz : NULL);
4100 }
4101 
4102 extern int do_getitimer(int which, struct itimerval *value);
4103 
sys32_getitimer(int which,struct itimerval32 * it)4104 asmlinkage int sys32_getitimer(int which, struct itimerval32 *it)
4105 {
4106 	struct itimerval kit;
4107 	int error;
4108 
4109 	error = do_getitimer(which, &kit);
4110 	if (!error && put_it32(it, &kit))
4111 		error = -EFAULT;
4112 
4113 	return error;
4114 }
4115 
4116 extern int do_setitimer(int which, struct itimerval *, struct itimerval *);
4117 
sys32_setitimer(int which,struct itimerval32 * in,struct itimerval32 * out)4118 asmlinkage int sys32_setitimer(int which, struct itimerval32 *in, struct itimerval32 *out)
4119 {
4120 	struct itimerval kin, kout;
4121 	int error;
4122 
4123 	if (in) {
4124 		if (get_it32(&kin, in))
4125 			return -EFAULT;
4126 	} else
4127 		memset(&kin, 0, sizeof(kin));
4128 
4129 	error = do_setitimer(which, &kin, out ? &kout : NULL);
4130 	if (error || !out)
4131 		return error;
4132 	if (put_it32(out, &kout))
4133 		return -EFAULT;
4134 
4135 	return 0;
4136 
4137 }
4138 
4139 asmlinkage int sys_utimes(char *, struct timeval *);
4140 
sys32_utimes(char * filename,struct timeval32 * tvs)4141 asmlinkage int sys32_utimes(char *filename, struct timeval32 *tvs)
4142 {
4143 	char *kfilename;
4144 	struct timeval ktvs[2];
4145 	mm_segment_t old_fs;
4146 	int ret;
4147 
4148 	kfilename = getname(filename);
4149 	ret = PTR_ERR(kfilename);
4150 	if (!IS_ERR(kfilename)) {
4151 		if (tvs) {
4152 			if (get_tv32(&ktvs[0], tvs) ||
4153 			    get_tv32(&ktvs[1], 1+tvs))
4154 				return -EFAULT;
4155 		}
4156 
4157 		old_fs = get_fs();
4158 		set_fs(KERNEL_DS);
4159 		ret = sys_utimes(kfilename, &ktvs[0]);
4160 		set_fs(old_fs);
4161 
4162 		putname(kfilename);
4163 	}
4164 	return ret;
4165 }
4166 
4167 /* These are here just in case some old sparc32 binary calls it. */
sys32_pause(void)4168 asmlinkage int sys32_pause(void)
4169 {
4170 	current->state = TASK_INTERRUPTIBLE;
4171 	schedule();
4172 	return -ERESTARTNOHAND;
4173 }
4174 
4175 extern asmlinkage int sys_prctl(int option, unsigned long arg2, unsigned long arg3,
4176 				unsigned long arg4, unsigned long arg5);
4177 
sys32_prctl(int option,u32 arg2,u32 arg3,u32 arg4,u32 arg5)4178 asmlinkage int sys32_prctl(int option, u32 arg2, u32 arg3, u32 arg4, u32 arg5)
4179 {
4180 	return sys_prctl(option,
4181 			 (unsigned long) arg2,
4182 			 (unsigned long) arg3,
4183 			 (unsigned long) arg4,
4184 			 (unsigned long) arg5);
4185 }
4186 
4187 
4188 extern asmlinkage ssize_t sys_pread(unsigned int fd, char * buf,
4189 				    size_t count, loff_t pos);
4190 
4191 extern asmlinkage ssize_t sys_pwrite(unsigned int fd, const char * buf,
4192 				     size_t count, loff_t pos);
4193 
4194 typedef __kernel_ssize_t32 ssize_t32;
4195 
sys32_pread(unsigned int fd,char * ubuf,__kernel_size_t32 count,u32 poshi,u32 poslo)4196 asmlinkage ssize_t32 sys32_pread(unsigned int fd, char *ubuf,
4197 				 __kernel_size_t32 count, u32 poshi, u32 poslo)
4198 {
4199 	if ((ssize_t32) count < 0)
4200 		return -EINVAL;
4201 	return sys_pread(fd, ubuf, count, ((loff_t)AA(poshi) << 32) | AA(poslo));
4202 }
4203 
sys32_pwrite(unsigned int fd,char * ubuf,__kernel_size_t32 count,u32 poshi,u32 poslo)4204 asmlinkage ssize_t32 sys32_pwrite(unsigned int fd, char *ubuf,
4205 				  __kernel_size_t32 count, u32 poshi, u32 poslo)
4206 {
4207 	if ((ssize_t32) count < 0)
4208 		return -EINVAL;
4209 	return sys_pwrite(fd, ubuf, count, ((loff_t)AA(poshi) << 32) | AA(poslo));
4210 }
4211 
4212 extern asmlinkage ssize_t sys_readahead(int fd, loff_t offset, size_t count);
4213 
sys32_readahead(int fd,u32 offhi,u32 offlo,s32 count)4214 asmlinkage ssize_t32 sys32_readahead(int fd, u32 offhi, u32 offlo, s32 count)
4215 {
4216 	return sys_readahead(fd, ((loff_t)AA(offhi) << 32) | AA(offlo), count);
4217 }
4218 
4219 extern asmlinkage ssize_t sys_sendfile(int out_fd, int in_fd, off_t *offset, size_t count);
4220 
sys32_sendfile(int out_fd,int in_fd,__kernel_off_t32 * offset,s32 count)4221 asmlinkage int sys32_sendfile(int out_fd, int in_fd, __kernel_off_t32 *offset, s32 count)
4222 {
4223 	mm_segment_t old_fs = get_fs();
4224 	int ret;
4225 	off_t of;
4226 
4227 	if (offset && get_user(of, offset))
4228 		return -EFAULT;
4229 
4230 	set_fs(KERNEL_DS);
4231 	ret = sys_sendfile(out_fd, in_fd, offset ? &of : NULL, count);
4232 	set_fs(old_fs);
4233 
4234 	if (!ret && offset && put_user(of, offset))
4235 		return -EFAULT;
4236 
4237 	return ret;
4238 }
4239 
4240 /* Handle adjtimex compatability. */
4241 
4242 struct timex32 {
4243 	u32 modes;
4244 	s32 offset, freq, maxerror, esterror;
4245 	s32 status, constant, precision, tolerance;
4246 	struct timeval32 time;
4247 	s32 tick;
4248 	s32 ppsfreq, jitter, shift, stabil;
4249 	s32 jitcnt, calcnt, errcnt, stbcnt;
4250 	s32  :32; s32  :32; s32  :32; s32  :32;
4251 	s32  :32; s32  :32; s32  :32; s32  :32;
4252 	s32  :32; s32  :32; s32  :32; s32  :32;
4253 };
4254 
4255 extern int do_adjtimex(struct timex *);
4256 
sys32_adjtimex(struct timex32 * utp)4257 asmlinkage int sys32_adjtimex(struct timex32 *utp)
4258 {
4259 	struct timex txc;
4260 	int ret;
4261 
4262 	memset(&txc, 0, sizeof(struct timex));
4263 
4264 	if(get_user(txc.modes, &utp->modes) ||
4265 	   __get_user(txc.offset, &utp->offset) ||
4266 	   __get_user(txc.freq, &utp->freq) ||
4267 	   __get_user(txc.maxerror, &utp->maxerror) ||
4268 	   __get_user(txc.esterror, &utp->esterror) ||
4269 	   __get_user(txc.status, &utp->status) ||
4270 	   __get_user(txc.constant, &utp->constant) ||
4271 	   __get_user(txc.precision, &utp->precision) ||
4272 	   __get_user(txc.tolerance, &utp->tolerance) ||
4273 	   __get_user(txc.time.tv_sec, &utp->time.tv_sec) ||
4274 	   __get_user(txc.time.tv_usec, &utp->time.tv_usec) ||
4275 	   __get_user(txc.tick, &utp->tick) ||
4276 	   __get_user(txc.ppsfreq, &utp->ppsfreq) ||
4277 	   __get_user(txc.jitter, &utp->jitter) ||
4278 	   __get_user(txc.shift, &utp->shift) ||
4279 	   __get_user(txc.stabil, &utp->stabil) ||
4280 	   __get_user(txc.jitcnt, &utp->jitcnt) ||
4281 	   __get_user(txc.calcnt, &utp->calcnt) ||
4282 	   __get_user(txc.errcnt, &utp->errcnt) ||
4283 	   __get_user(txc.stbcnt, &utp->stbcnt))
4284 		return -EFAULT;
4285 
4286 	ret = do_adjtimex(&txc);
4287 
4288 	if(put_user(txc.modes, &utp->modes) ||
4289 	   __put_user(txc.offset, &utp->offset) ||
4290 	   __put_user(txc.freq, &utp->freq) ||
4291 	   __put_user(txc.maxerror, &utp->maxerror) ||
4292 	   __put_user(txc.esterror, &utp->esterror) ||
4293 	   __put_user(txc.status, &utp->status) ||
4294 	   __put_user(txc.constant, &utp->constant) ||
4295 	   __put_user(txc.precision, &utp->precision) ||
4296 	   __put_user(txc.tolerance, &utp->tolerance) ||
4297 	   __put_user(txc.time.tv_sec, &utp->time.tv_sec) ||
4298 	   __put_user(txc.time.tv_usec, &utp->time.tv_usec) ||
4299 	   __put_user(txc.tick, &utp->tick) ||
4300 	   __put_user(txc.ppsfreq, &utp->ppsfreq) ||
4301 	   __put_user(txc.jitter, &utp->jitter) ||
4302 	   __put_user(txc.shift, &utp->shift) ||
4303 	   __put_user(txc.stabil, &utp->stabil) ||
4304 	   __put_user(txc.jitcnt, &utp->jitcnt) ||
4305 	   __put_user(txc.calcnt, &utp->calcnt) ||
4306 	   __put_user(txc.errcnt, &utp->errcnt) ||
4307 	   __put_user(txc.stbcnt, &utp->stbcnt))
4308 		ret = -EFAULT;
4309 
4310 	return ret;
4311 }
4312 
4313 extern asmlinkage long sys_setpriority(int which, int who, int niceval);
4314 
sys_setpriority32(u32 which,u32 who,u32 niceval)4315 asmlinkage int sys_setpriority32(u32 which, u32 who, u32 niceval)
4316 {
4317 	return sys_setpriority((int) which,
4318 			       (int) who,
4319 			       (int) niceval);
4320 }
4321 
4322 struct __sysctl_args32 {
4323 	u32 name;
4324 	int nlen;
4325 	u32 oldval;
4326 	u32 oldlenp;
4327 	u32 newval;
4328 	u32 newlen;
4329 	u32 __unused[4];
4330 };
4331 
sys32_sysctl(struct __sysctl_args32 * args)4332 extern asmlinkage long sys32_sysctl(struct __sysctl_args32 *args)
4333 {
4334 	struct __sysctl_args32 tmp;
4335 	int error;
4336 	size_t oldlen, *oldlenp = NULL;
4337 	unsigned long addr = (((long)&args->__unused[0]) + 7) & ~7;
4338 
4339 	if (copy_from_user(&tmp, args, sizeof(tmp)))
4340 		return -EFAULT;
4341 
4342 	if (tmp.oldval && tmp.oldlenp) {
4343 		/* Duh, this is ugly and might not work if sysctl_args
4344 		   is in read-only memory, but do_sysctl does indirectly
4345 		   a lot of uaccess in both directions and we'd have to
4346 		   basically copy the whole sysctl.c here, and
4347 		   glibc's __sysctl uses rw memory for the structure
4348 		   anyway.  */
4349 		if (get_user(oldlen, (u32 *)A(tmp.oldlenp)) ||
4350 		    put_user(oldlen, (size_t *)addr))
4351 			return -EFAULT;
4352 		oldlenp = (size_t *)addr;
4353 	}
4354 
4355 	lock_kernel();
4356 	error = do_sysctl((int *)A(tmp.name), tmp.nlen, (void *)A(tmp.oldval),
4357 			  oldlenp, (void *)A(tmp.newval), tmp.newlen);
4358 	unlock_kernel();
4359 	if (oldlenp) {
4360 		if (!error) {
4361 			if (get_user(oldlen, (size_t *)addr) ||
4362 			    put_user(oldlen, (u32 *)A(tmp.oldlenp)))
4363 				error = -EFAULT;
4364 		}
4365 		copy_to_user(args->__unused, tmp.__unused, sizeof(tmp.__unused));
4366 	}
4367 	return error;
4368 }
4369 
4370 struct stat64_emu31 {
4371 	unsigned char   __pad0[6];
4372 	unsigned short  st_dev;
4373 	unsigned int    __pad1;
4374 #define STAT64_HAS_BROKEN_ST_INO        1
4375 	u32             __st_ino;
4376 	unsigned int    st_mode;
4377 	unsigned int    st_nlink;
4378 	u32             st_uid;
4379 	u32             st_gid;
4380 	unsigned char   __pad2[6];
4381 	unsigned short  st_rdev;
4382 	unsigned int    __pad3;
4383 	long            st_size;
4384 	u32             st_blksize;
4385 	unsigned char   __pad4[4];
4386 	u32             __pad5;     /* future possible st_blocks high bits */
4387 	u32             st_blocks;  /* Number 512-byte blocks allocated. */
4388 	u32             st_atime;
4389 	u32             __pad6;
4390 	u32             st_mtime;
4391 	u32             __pad7;
4392 	u32             st_ctime;
4393 	u32             __pad8;     /* will be high 32 bits of ctime someday */
4394 	unsigned long   st_ino;
4395 };
4396 
4397 static inline int
putstat64(struct stat64_emu31 * ubuf,struct stat * kbuf)4398 putstat64 (struct stat64_emu31 *ubuf, struct stat *kbuf)
4399 {
4400     struct stat64_emu31 tmp;
4401 
4402     memset(&tmp, 0, sizeof(tmp));
4403 
4404     tmp.st_dev = (unsigned short)kbuf->st_dev;
4405     tmp.st_ino = kbuf->st_ino;
4406     tmp.__st_ino = (u32)kbuf->st_ino;
4407     tmp.st_mode = kbuf->st_mode;
4408     tmp.st_nlink = (unsigned int)kbuf->st_nlink;
4409     tmp.st_uid = kbuf->st_uid;
4410     tmp.st_gid = kbuf->st_gid;
4411     tmp.st_rdev = (unsigned short)kbuf->st_rdev;
4412     tmp.st_size = kbuf->st_size;
4413     tmp.st_blksize = (u32)kbuf->st_blksize;
4414     tmp.st_blocks = (u32)kbuf->st_blocks;
4415     tmp.st_atime = (u32)kbuf->st_atime;
4416     tmp.st_mtime = (u32)kbuf->st_mtime;
4417     tmp.st_ctime = (u32)kbuf->st_ctime;
4418 
4419     return copy_to_user(ubuf,&tmp,sizeof(tmp)) ? -EFAULT : 0;
4420 }
4421 
4422 extern asmlinkage long sys_newstat(char * filename, struct stat * statbuf);
4423 
sys32_stat64(char * filename,struct stat64_emu31 * statbuf,long flags)4424 asmlinkage long sys32_stat64(char * filename, struct stat64_emu31 * statbuf, long flags)
4425 {
4426     int ret;
4427     struct stat s;
4428     char * tmp;
4429     int err;
4430     mm_segment_t old_fs = get_fs();
4431 
4432     tmp = getname(filename);
4433     err = PTR_ERR(tmp);
4434     if (IS_ERR(tmp))
4435 	    return err;
4436 
4437     set_fs (KERNEL_DS);
4438     ret = sys_newstat(tmp, &s);
4439     set_fs (old_fs);
4440     putname(tmp);
4441     if (!ret && putstat64 (statbuf, &s))
4442 	    return -EFAULT;
4443     return ret;
4444 }
4445 
4446 extern asmlinkage long sys_newlstat(char * filename, struct stat * statbuf);
4447 
sys32_lstat64(char * filename,struct stat64_emu31 * statbuf,long flags)4448 asmlinkage long sys32_lstat64(char * filename, struct stat64_emu31 * statbuf, long flags)
4449 {
4450     int ret;
4451     struct stat s;
4452     char * tmp;
4453     int err;
4454     mm_segment_t old_fs = get_fs();
4455 
4456     tmp = getname(filename);
4457     err = PTR_ERR(tmp);
4458     if (IS_ERR(tmp))
4459 	    return err;
4460 
4461     set_fs (KERNEL_DS);
4462     ret = sys_newlstat(tmp, &s);
4463     set_fs (old_fs);
4464     putname(tmp);
4465     if (!ret && putstat64 (statbuf, &s))
4466 	    return -EFAULT;
4467     return ret;
4468 }
4469 
4470 extern asmlinkage long sys_newfstat(unsigned int fd, struct stat * statbuf);
4471 
sys32_fstat64(unsigned long fd,struct stat64_emu31 * statbuf,long flags)4472 asmlinkage long sys32_fstat64(unsigned long fd, struct stat64_emu31 * statbuf, long flags)
4473 {
4474     int ret;
4475     struct stat s;
4476     mm_segment_t old_fs = get_fs();
4477 
4478     set_fs (KERNEL_DS);
4479     ret = sys_newfstat(fd, &s);
4480     set_fs (old_fs);
4481     if (!ret && putstat64 (statbuf, &s))
4482 	    return -EFAULT;
4483     return ret;
4484 }
4485 
4486 /*
4487  * Linux/i386 didn't use to be able to handle more than
4488  * 4 system call parameters, so these system calls used a memory
4489  * block for parameter passing..
4490  */
4491 
4492 struct mmap_arg_struct_emu31 {
4493 	u32	addr;
4494 	u32	len;
4495 	u32	prot;
4496 	u32	flags;
4497 	u32	fd;
4498 	u32	offset;
4499 };
4500 
4501 /* common code for old and new mmaps */
do_mmap2(unsigned long addr,unsigned long len,unsigned long prot,unsigned long flags,unsigned long fd,unsigned long pgoff)4502 static inline long do_mmap2(
4503 	unsigned long addr, unsigned long len,
4504 	unsigned long prot, unsigned long flags,
4505 	unsigned long fd, unsigned long pgoff)
4506 {
4507 	struct file * file = NULL;
4508 	unsigned long error = -EBADF;
4509 
4510 	flags &= ~(MAP_EXECUTABLE | MAP_DENYWRITE);
4511 	if (!(flags & MAP_ANONYMOUS)) {
4512 		file = fget(fd);
4513 		if (!file)
4514 			goto out;
4515 	}
4516 
4517 	down_write(&current->mm->mmap_sem);
4518 	error = do_mmap_pgoff(file, addr, len, prot, flags, pgoff);
4519 	if (!IS_ERR((void *) error) && error + len >= 0x80000000ULL) {
4520 		/* Result is out of bounds.  */
4521 		do_munmap(current->mm, error, len);
4522 		error = -ENOMEM;
4523 	}
4524 	up_write(&current->mm->mmap_sem);
4525 
4526 	if (file)
4527 		fput(file);
4528 out:
4529 	return error;
4530 }
4531 
4532 
4533 asmlinkage unsigned long
old32_mmap(struct mmap_arg_struct_emu31 * arg)4534 old32_mmap(struct mmap_arg_struct_emu31 *arg)
4535 {
4536 	struct mmap_arg_struct_emu31 a;
4537 	int error = -EFAULT;
4538 
4539 	if (copy_from_user(&a, arg, sizeof(a)))
4540 		goto out;
4541 
4542 	error = -EINVAL;
4543 	if (a.offset & ~PAGE_MASK)
4544 		goto out;
4545 
4546 	error = do_mmap2(a.addr, a.len, a.prot, a.flags, a.fd, a.offset >> PAGE_SHIFT);
4547 out:
4548 	return error;
4549 }
4550 
4551 asmlinkage long
sys32_mmap2(struct mmap_arg_struct_emu31 * arg)4552 sys32_mmap2(struct mmap_arg_struct_emu31 *arg)
4553 {
4554 	struct mmap_arg_struct_emu31 a;
4555 	int error = -EFAULT;
4556 
4557 	if (copy_from_user(&a, arg, sizeof(a)))
4558 		goto out;
4559 	error = do_mmap2(a.addr, a.len, a.prot, a.flags, a.fd, a.offset);
4560 out:
4561 	return error;
4562 }
4563 
4564 extern asmlinkage long sys_socket(int family, int type, int protocol);
4565 extern asmlinkage long sys_bind(int fd, struct sockaddr *umyaddr, int addrlen);
4566 extern asmlinkage long sys_connect(int fd, struct sockaddr *uservaddr, int addrlen);
4567 extern asmlinkage long sys_listen(int fd, int backlog);
4568 extern asmlinkage long sys_accept(int fd, struct sockaddr *upeer_sockaddr, int *upeer_addrlen);
4569 extern asmlinkage long sys_getsockname(int fd, struct sockaddr *usockaddr, int *usockaddr_len);
4570 extern asmlinkage long sys_getpeername(int fd, struct sockaddr *usockaddr, int *usockaddr_len);
4571 extern asmlinkage long sys_socketpair(int family, int type, int protocol, int usockvec[2]);
4572 extern asmlinkage long sys_send(int fd, void * buff, size_t len, unsigned flags);
4573 extern asmlinkage long sys_sendto(int fd, void * buff, size_t len, unsigned flags,
4574                            struct sockaddr *addr, int addr_len);
4575 extern asmlinkage long sys_recv(int fd, void * ubuf, size_t size, unsigned flags);
4576 extern asmlinkage long sys_recvfrom(int fd, void * ubuf, size_t size, unsigned flags,
4577                              struct sockaddr *addr, int *addr_len);
4578 extern asmlinkage long sys_shutdown(int fd, int how);
4579 extern asmlinkage long sys_getsockopt(int fd, int level, int optname, char *optval, int * optlen);
4580 
4581 /* Argument list sizes for sys_socketcall */
4582 #define AL(x) ((x) * sizeof(u32))
4583 static unsigned char nas[18] = {AL(0),AL(3),AL(3),AL(3),AL(2),AL(3),
4584                                 AL(3),AL(3),AL(4),AL(4),AL(4),AL(6),
4585                                 AL(6),AL(2),AL(5),AL(5),AL(3),AL(3)};
4586 #undef AL
4587 
sys32_socketcall(int call,u32 * args)4588 asmlinkage long sys32_socketcall(int call, u32 *args)
4589 {
4590 	int ret;
4591 	u32 a[6];
4592 
4593 	if (call < SYS_SOCKET || call > SYS_RECVMSG)
4594 		return -EINVAL;
4595 	if (copy_from_user(a, args, nas[call]))
4596 		return -EFAULT;
4597 	switch(call) {
4598 	case SYS_SOCKET:
4599 		ret = sys_socket(a[0], a[1], a[2]);
4600 		break;
4601 	case SYS_BIND:
4602 		ret = sys_bind(a[0], (struct sockaddr *) A(a[1]), a[2]);
4603 		break;
4604 	case SYS_CONNECT:
4605 		ret = sys_connect(a[0], (struct sockaddr *) A(a[1]), a[2]);
4606 		break;
4607 	case SYS_LISTEN:
4608 		ret = sys_listen(a[0], a[1]);
4609 		break;
4610 	case SYS_ACCEPT:
4611 		ret = sys_accept(a[0], (struct sockaddr *) A(a[1]),
4612 				 (int *) A(a[2]));
4613 		break;
4614 	case SYS_GETSOCKNAME:
4615 		ret = sys_getsockname(a[0], (struct sockaddr *) A(a[1]),
4616 				      (int *) A(a[2]));
4617 		break;
4618 	case SYS_GETPEERNAME:
4619 		ret = sys_getpeername(a[0], (struct sockaddr *) A(a[1]),
4620 				      (int *) A(a[2]));
4621 		break;
4622 	case SYS_SOCKETPAIR:
4623 		ret = sys_socketpair(a[0], a[1], a[2], (int *) A(a[3]));
4624 		break;
4625 	case SYS_SEND:
4626 		ret = sys_send(a[0], (void *) A(a[1]), a[2], a[3]);
4627 		break;
4628 	case SYS_SENDTO:
4629 		ret = sys_sendto(a[0], (void*) A(a[1]), a[2], a[3], (struct sockaddr *) A(a[4]), a[5]);
4630 		break;
4631 	case SYS_RECV:
4632 		ret = sys_recv(a[0], (void *) A(a[1]), a[2], a[3]);
4633 		break;
4634 	case SYS_RECVFROM:
4635 		ret = sys_recvfrom(a[0], (void *) A(a[1]), a[2], a[3], (struct sockaddr *) A(a[4]), (int *) A(a[5]) );
4636 		break;
4637 	case SYS_SHUTDOWN:
4638 		ret = sys_shutdown(a[0], a[1]);
4639 		break;
4640 	case SYS_SETSOCKOPT:
4641 		ret = sys32_setsockopt(a[0], a[1], a[2], (char *) A(a[3]),
4642 				     a[4]);
4643 		break;
4644 	case SYS_GETSOCKOPT:
4645 		ret = sys_getsockopt(a[0], a[1], a[2], (char *) A(a[3]), (int *) A(a[4]) );
4646 		break;
4647 	case SYS_SENDMSG:
4648 		ret = sys32_sendmsg(a[0], (struct msghdr32 *) A(a[1]),
4649 				    a[2]);
4650 		break;
4651 	case SYS_RECVMSG:
4652 		ret = sys32_recvmsg(a[0], (struct msghdr32 *) A(a[1]),
4653 				    a[2]);
4654 		break;
4655 	default:
4656 		ret = EINVAL;
4657 		break;
4658 	}
4659 	return ret;
4660 }
4661 
4662 asmlinkage ssize_t sys_read(unsigned int fd, char * buf, size_t count);
4663 
sys32_read(unsigned int fd,char * buf,size_t count)4664 asmlinkage ssize_t32 sys32_read(unsigned int fd, char * buf, size_t count)
4665 {
4666 	if ((ssize_t32) count < 0)
4667 		return -EINVAL;
4668 
4669 	return sys_read(fd, buf, count);
4670 }
4671 
4672 asmlinkage ssize_t sys_write(unsigned int fd, const char * buf, size_t count);
4673 
sys32_write(unsigned int fd,char * buf,size_t count)4674 asmlinkage ssize_t32 sys32_write(unsigned int fd, char * buf, size_t count)
4675 {
4676 	if ((ssize_t32) count < 0)
4677 		return -EINVAL;
4678 
4679 	return sys_write(fd, buf, count);
4680 }
4681