]> git.proxmox.com Git - mirror_ubuntu-jammy-kernel.git/blame - fs/read_write.c
vfs: pass type instead of fn to do_{loop,iter}_readv_writev()
[mirror_ubuntu-jammy-kernel.git] / fs / read_write.c
CommitLineData
1da177e4
LT
1/*
2 * linux/fs/read_write.c
3 *
4 * Copyright (C) 1991, 1992 Linus Torvalds
5 */
6
7#include <linux/slab.h>
8#include <linux/stat.h>
9#include <linux/fcntl.h>
10#include <linux/file.h>
11#include <linux/uio.h>
0eeca283 12#include <linux/fsnotify.h>
1da177e4 13#include <linux/security.h>
630d9c47 14#include <linux/export.h>
1da177e4 15#include <linux/syscalls.h>
e28cc715 16#include <linux/pagemap.h>
d6b29d7c 17#include <linux/splice.h>
561c6731 18#include <linux/compat.h>
29732938 19#include <linux/mount.h>
2feb55f8 20#include <linux/fs.h>
06ae43f3 21#include "internal.h"
1da177e4 22
7c0f6ba6 23#include <linux/uaccess.h>
1da177e4
LT
24#include <asm/unistd.h>
25
4b6f5d20 26const struct file_operations generic_ro_fops = {
1da177e4 27 .llseek = generic_file_llseek,
aad4f8bb 28 .read_iter = generic_file_read_iter,
1da177e4 29 .mmap = generic_file_readonly_mmap,
534f2aaa 30 .splice_read = generic_file_splice_read,
1da177e4
LT
31};
32
33EXPORT_SYMBOL(generic_ro_fops);
34
cccb5a1e 35static inline int unsigned_offsets(struct file *file)
4a3956c7 36{
cccb5a1e 37 return file->f_mode & FMODE_UNSIGNED_OFFSET;
4a3956c7
KH
38}
39
46a1c2c7
JL
40/**
41 * vfs_setpos - update the file offset for lseek
42 * @file: file structure in question
43 * @offset: file offset to seek to
44 * @maxsize: maximum file size
45 *
46 * This is a low-level filesystem helper for updating the file offset to
47 * the value specified by @offset if the given offset is valid and it is
48 * not equal to the current file offset.
49 *
50 * Return the specified offset on success and -EINVAL on invalid offset.
51 */
52loff_t vfs_setpos(struct file *file, loff_t offset, loff_t maxsize)
ef3d0fd2
AK
53{
54 if (offset < 0 && !unsigned_offsets(file))
55 return -EINVAL;
56 if (offset > maxsize)
57 return -EINVAL;
58
59 if (offset != file->f_pos) {
60 file->f_pos = offset;
61 file->f_version = 0;
62 }
63 return offset;
64}
46a1c2c7 65EXPORT_SYMBOL(vfs_setpos);
ef3d0fd2 66
3a8cff4f 67/**
5760495a 68 * generic_file_llseek_size - generic llseek implementation for regular files
3a8cff4f
CH
69 * @file: file structure to seek on
70 * @offset: file offset to seek to
965c8e59 71 * @whence: type of seek
e8b96eb5
ES
72 * @size: max size of this file in file system
73 * @eof: offset used for SEEK_END position
3a8cff4f 74 *
5760495a 75 * This is a variant of generic_file_llseek that allows passing in a custom
e8b96eb5 76 * maximum file size and a custom EOF position, for e.g. hashed directories
ef3d0fd2
AK
77 *
78 * Synchronization:
5760495a 79 * SEEK_SET and SEEK_END are unsynchronized (but atomic on 64bit platforms)
ef3d0fd2
AK
80 * SEEK_CUR is synchronized against other SEEK_CURs, but not read/writes.
81 * read/writes behave like SEEK_SET against seeks.
3a8cff4f 82 */
9465efc9 83loff_t
965c8e59 84generic_file_llseek_size(struct file *file, loff_t offset, int whence,
e8b96eb5 85 loff_t maxsize, loff_t eof)
1da177e4 86{
965c8e59 87 switch (whence) {
3a8cff4f 88 case SEEK_END:
e8b96eb5 89 offset += eof;
3a8cff4f
CH
90 break;
91 case SEEK_CUR:
5b6f1eb9
AK
92 /*
93 * Here we special-case the lseek(fd, 0, SEEK_CUR)
94 * position-querying operation. Avoid rewriting the "same"
95 * f_pos value back to the file because a concurrent read(),
96 * write() or lseek() might have altered it
97 */
98 if (offset == 0)
99 return file->f_pos;
ef3d0fd2
AK
100 /*
101 * f_lock protects against read/modify/write race with other
102 * SEEK_CURs. Note that parallel writes and reads behave
103 * like SEEK_SET.
104 */
105 spin_lock(&file->f_lock);
46a1c2c7 106 offset = vfs_setpos(file, file->f_pos + offset, maxsize);
ef3d0fd2
AK
107 spin_unlock(&file->f_lock);
108 return offset;
982d8165
JB
109 case SEEK_DATA:
110 /*
111 * In the generic case the entire file is data, so as long as
112 * offset isn't at the end of the file then the offset is data.
113 */
e8b96eb5 114 if (offset >= eof)
982d8165
JB
115 return -ENXIO;
116 break;
117 case SEEK_HOLE:
118 /*
119 * There is a virtual hole at the end of the file, so as long as
120 * offset isn't i_size or larger, return i_size.
121 */
e8b96eb5 122 if (offset >= eof)
982d8165 123 return -ENXIO;
e8b96eb5 124 offset = eof;
982d8165 125 break;
1da177e4 126 }
3a8cff4f 127
46a1c2c7 128 return vfs_setpos(file, offset, maxsize);
5760495a
AK
129}
130EXPORT_SYMBOL(generic_file_llseek_size);
131
132/**
133 * generic_file_llseek - generic llseek implementation for regular files
134 * @file: file structure to seek on
135 * @offset: file offset to seek to
965c8e59 136 * @whence: type of seek
5760495a
AK
137 *
138 * This is a generic implemenation of ->llseek useable for all normal local
139 * filesystems. It just updates the file offset to the value specified by
546ae2d2 140 * @offset and @whence.
5760495a 141 */
965c8e59 142loff_t generic_file_llseek(struct file *file, loff_t offset, int whence)
5760495a
AK
143{
144 struct inode *inode = file->f_mapping->host;
145
965c8e59 146 return generic_file_llseek_size(file, offset, whence,
e8b96eb5
ES
147 inode->i_sb->s_maxbytes,
148 i_size_read(inode));
1da177e4 149}
9465efc9 150EXPORT_SYMBOL(generic_file_llseek);
1da177e4 151
1bf9d14d
AV
152/**
153 * fixed_size_llseek - llseek implementation for fixed-sized devices
154 * @file: file structure to seek on
155 * @offset: file offset to seek to
156 * @whence: type of seek
157 * @size: size of the file
158 *
159 */
160loff_t fixed_size_llseek(struct file *file, loff_t offset, int whence, loff_t size)
161{
162 switch (whence) {
163 case SEEK_SET: case SEEK_CUR: case SEEK_END:
164 return generic_file_llseek_size(file, offset, whence,
165 size, size);
166 default:
167 return -EINVAL;
168 }
169}
170EXPORT_SYMBOL(fixed_size_llseek);
171
b25472f9
AV
172/**
173 * no_seek_end_llseek - llseek implementation for fixed-sized devices
174 * @file: file structure to seek on
175 * @offset: file offset to seek to
176 * @whence: type of seek
177 *
178 */
179loff_t no_seek_end_llseek(struct file *file, loff_t offset, int whence)
180{
181 switch (whence) {
182 case SEEK_SET: case SEEK_CUR:
183 return generic_file_llseek_size(file, offset, whence,
2feb55f8 184 OFFSET_MAX, 0);
b25472f9
AV
185 default:
186 return -EINVAL;
187 }
188}
189EXPORT_SYMBOL(no_seek_end_llseek);
190
191/**
192 * no_seek_end_llseek_size - llseek implementation for fixed-sized devices
193 * @file: file structure to seek on
194 * @offset: file offset to seek to
195 * @whence: type of seek
196 * @size: maximal offset allowed
197 *
198 */
199loff_t no_seek_end_llseek_size(struct file *file, loff_t offset, int whence, loff_t size)
200{
201 switch (whence) {
202 case SEEK_SET: case SEEK_CUR:
203 return generic_file_llseek_size(file, offset, whence,
204 size, 0);
205 default:
206 return -EINVAL;
207 }
208}
209EXPORT_SYMBOL(no_seek_end_llseek_size);
210
ae6afc3f
B
211/**
212 * noop_llseek - No Operation Performed llseek implementation
213 * @file: file structure to seek on
214 * @offset: file offset to seek to
965c8e59 215 * @whence: type of seek
ae6afc3f
B
216 *
217 * This is an implementation of ->llseek useable for the rare special case when
218 * userspace expects the seek to succeed but the (device) file is actually not
219 * able to perform the seek. In this case you use noop_llseek() instead of
220 * falling back to the default implementation of ->llseek.
221 */
965c8e59 222loff_t noop_llseek(struct file *file, loff_t offset, int whence)
ae6afc3f
B
223{
224 return file->f_pos;
225}
226EXPORT_SYMBOL(noop_llseek);
227
965c8e59 228loff_t no_llseek(struct file *file, loff_t offset, int whence)
1da177e4
LT
229{
230 return -ESPIPE;
231}
232EXPORT_SYMBOL(no_llseek);
233
965c8e59 234loff_t default_llseek(struct file *file, loff_t offset, int whence)
1da177e4 235{
496ad9aa 236 struct inode *inode = file_inode(file);
16abef0e 237 loff_t retval;
1da177e4 238
5955102c 239 inode_lock(inode);
965c8e59 240 switch (whence) {
7b8e8924 241 case SEEK_END:
982d8165 242 offset += i_size_read(inode);
1da177e4 243 break;
7b8e8924 244 case SEEK_CUR:
5b6f1eb9
AK
245 if (offset == 0) {
246 retval = file->f_pos;
247 goto out;
248 }
1da177e4 249 offset += file->f_pos;
982d8165
JB
250 break;
251 case SEEK_DATA:
252 /*
253 * In the generic case the entire file is data, so as
254 * long as offset isn't at the end of the file then the
255 * offset is data.
256 */
bacb2d81
DC
257 if (offset >= inode->i_size) {
258 retval = -ENXIO;
259 goto out;
260 }
982d8165
JB
261 break;
262 case SEEK_HOLE:
263 /*
264 * There is a virtual hole at the end of the file, so
265 * as long as offset isn't i_size or larger, return
266 * i_size.
267 */
bacb2d81
DC
268 if (offset >= inode->i_size) {
269 retval = -ENXIO;
270 goto out;
271 }
982d8165
JB
272 offset = inode->i_size;
273 break;
1da177e4
LT
274 }
275 retval = -EINVAL;
cccb5a1e 276 if (offset >= 0 || unsigned_offsets(file)) {
1da177e4
LT
277 if (offset != file->f_pos) {
278 file->f_pos = offset;
279 file->f_version = 0;
280 }
281 retval = offset;
282 }
5b6f1eb9 283out:
5955102c 284 inode_unlock(inode);
1da177e4
LT
285 return retval;
286}
287EXPORT_SYMBOL(default_llseek);
288
965c8e59 289loff_t vfs_llseek(struct file *file, loff_t offset, int whence)
1da177e4
LT
290{
291 loff_t (*fn)(struct file *, loff_t, int);
292
293 fn = no_llseek;
294 if (file->f_mode & FMODE_LSEEK) {
72c2d531 295 if (file->f_op->llseek)
1da177e4
LT
296 fn = file->f_op->llseek;
297 }
965c8e59 298 return fn(file, offset, whence);
1da177e4
LT
299}
300EXPORT_SYMBOL(vfs_llseek);
301
965c8e59 302SYSCALL_DEFINE3(lseek, unsigned int, fd, off_t, offset, unsigned int, whence)
1da177e4
LT
303{
304 off_t retval;
9c225f26 305 struct fd f = fdget_pos(fd);
2903ff01
AV
306 if (!f.file)
307 return -EBADF;
1da177e4
LT
308
309 retval = -EINVAL;
965c8e59
AM
310 if (whence <= SEEK_MAX) {
311 loff_t res = vfs_llseek(f.file, offset, whence);
1da177e4
LT
312 retval = res;
313 if (res != (loff_t)retval)
314 retval = -EOVERFLOW; /* LFS: should only happen on 32 bit platforms */
315 }
9c225f26 316 fdput_pos(f);
1da177e4
LT
317 return retval;
318}
319
561c6731
AV
320#ifdef CONFIG_COMPAT
321COMPAT_SYSCALL_DEFINE3(lseek, unsigned int, fd, compat_off_t, offset, unsigned int, whence)
322{
323 return sys_lseek(fd, offset, whence);
324}
325#endif
326
1da177e4 327#ifdef __ARCH_WANT_SYS_LLSEEK
003d7ab4
HC
328SYSCALL_DEFINE5(llseek, unsigned int, fd, unsigned long, offset_high,
329 unsigned long, offset_low, loff_t __user *, result,
965c8e59 330 unsigned int, whence)
1da177e4
LT
331{
332 int retval;
d7a15f8d 333 struct fd f = fdget_pos(fd);
1da177e4 334 loff_t offset;
1da177e4 335
2903ff01
AV
336 if (!f.file)
337 return -EBADF;
1da177e4
LT
338
339 retval = -EINVAL;
965c8e59 340 if (whence > SEEK_MAX)
1da177e4
LT
341 goto out_putf;
342
2903ff01 343 offset = vfs_llseek(f.file, ((loff_t) offset_high << 32) | offset_low,
965c8e59 344 whence);
1da177e4
LT
345
346 retval = (int)offset;
347 if (offset >= 0) {
348 retval = -EFAULT;
349 if (!copy_to_user(result, &offset, sizeof(offset)))
350 retval = 0;
351 }
352out_putf:
d7a15f8d 353 fdput_pos(f);
1da177e4
LT
354 return retval;
355}
356#endif
357
dbe4e192
CH
358ssize_t vfs_iter_read(struct file *file, struct iov_iter *iter, loff_t *ppos)
359{
360 struct kiocb kiocb;
361 ssize_t ret;
362
363 if (!file->f_op->read_iter)
364 return -EINVAL;
365
366 init_sync_kiocb(&kiocb, file);
367 kiocb.ki_pos = *ppos;
dbe4e192
CH
368
369 iter->type |= READ;
370 ret = file->f_op->read_iter(&kiocb, iter);
599bd19b 371 BUG_ON(ret == -EIOCBQUEUED);
dbe4e192
CH
372 if (ret > 0)
373 *ppos = kiocb.ki_pos;
374 return ret;
375}
376EXPORT_SYMBOL(vfs_iter_read);
377
378ssize_t vfs_iter_write(struct file *file, struct iov_iter *iter, loff_t *ppos)
379{
380 struct kiocb kiocb;
381 ssize_t ret;
382
383 if (!file->f_op->write_iter)
384 return -EINVAL;
385
386 init_sync_kiocb(&kiocb, file);
387 kiocb.ki_pos = *ppos;
dbe4e192
CH
388
389 iter->type |= WRITE;
390 ret = file->f_op->write_iter(&kiocb, iter);
599bd19b 391 BUG_ON(ret == -EIOCBQUEUED);
dbe4e192
CH
392 if (ret > 0)
393 *ppos = kiocb.ki_pos;
394 return ret;
395}
396EXPORT_SYMBOL(vfs_iter_write);
397
68d70d03 398int rw_verify_area(int read_write, struct file *file, const loff_t *ppos, size_t count)
1da177e4
LT
399{
400 struct inode *inode;
401 loff_t pos;
c43e259c 402 int retval = -EINVAL;
1da177e4 403
496ad9aa 404 inode = file_inode(file);
e28cc715 405 if (unlikely((ssize_t) count < 0))
c43e259c 406 return retval;
1da177e4 407 pos = *ppos;
cccb5a1e
AV
408 if (unlikely(pos < 0)) {
409 if (!unsigned_offsets(file))
410 return retval;
411 if (count >= -pos) /* both values are in 0..LLONG_MAX */
412 return -EOVERFLOW;
413 } else if (unlikely((loff_t) (pos + count) < 0)) {
414 if (!unsigned_offsets(file))
4a3956c7
KH
415 return retval;
416 }
1da177e4 417
bd61e0a9 418 if (unlikely(inode->i_flctx && mandatory_lock(inode))) {
acc15575
CH
419 retval = locks_mandatory_area(inode, file, pos, pos + count - 1,
420 read_write == READ ? F_RDLCK : F_WRLCK);
e28cc715
LT
421 if (retval < 0)
422 return retval;
423 }
bc61384d 424 return security_file_permission(file,
c43e259c 425 read_write == READ ? MAY_READ : MAY_WRITE);
1da177e4
LT
426}
427
5d5d5689 428static ssize_t new_sync_read(struct file *filp, char __user *buf, size_t len, loff_t *ppos)
293bc982
AV
429{
430 struct iovec iov = { .iov_base = buf, .iov_len = len };
431 struct kiocb kiocb;
432 struct iov_iter iter;
433 ssize_t ret;
434
435 init_sync_kiocb(&kiocb, filp);
436 kiocb.ki_pos = *ppos;
293bc982
AV
437 iov_iter_init(&iter, READ, &iov, 1, len);
438
439 ret = filp->f_op->read_iter(&kiocb, &iter);
599bd19b 440 BUG_ON(ret == -EIOCBQUEUED);
293bc982
AV
441 *ppos = kiocb.ki_pos;
442 return ret;
443}
444
6fb5032e
DK
445ssize_t __vfs_read(struct file *file, char __user *buf, size_t count,
446 loff_t *pos)
447{
6fb5032e 448 if (file->f_op->read)
3d04c8a1 449 return file->f_op->read(file, buf, count, pos);
6fb5032e 450 else if (file->f_op->read_iter)
3d04c8a1 451 return new_sync_read(file, buf, count, pos);
6fb5032e 452 else
3d04c8a1 453 return -EINVAL;
6fb5032e 454}
3d04c8a1 455EXPORT_SYMBOL(__vfs_read);
6fb5032e 456
1da177e4
LT
457ssize_t vfs_read(struct file *file, char __user *buf, size_t count, loff_t *pos)
458{
459 ssize_t ret;
460
461 if (!(file->f_mode & FMODE_READ))
462 return -EBADF;
7f7f25e8 463 if (!(file->f_mode & FMODE_CAN_READ))
1da177e4
LT
464 return -EINVAL;
465 if (unlikely(!access_ok(VERIFY_WRITE, buf, count)))
466 return -EFAULT;
467
468 ret = rw_verify_area(READ, file, pos, count);
bc61384d
AV
469 if (!ret) {
470 if (count > MAX_RW_COUNT)
471 count = MAX_RW_COUNT;
6fb5032e 472 ret = __vfs_read(file, buf, count, pos);
c43e259c 473 if (ret > 0) {
2a12a9d7 474 fsnotify_access(file);
c43e259c 475 add_rchar(current, ret);
1da177e4 476 }
c43e259c 477 inc_syscr(current);
1da177e4
LT
478 }
479
480 return ret;
481}
482
483EXPORT_SYMBOL(vfs_read);
484
5d5d5689 485static ssize_t new_sync_write(struct file *filp, const char __user *buf, size_t len, loff_t *ppos)
293bc982
AV
486{
487 struct iovec iov = { .iov_base = (void __user *)buf, .iov_len = len };
488 struct kiocb kiocb;
489 struct iov_iter iter;
490 ssize_t ret;
491
492 init_sync_kiocb(&kiocb, filp);
493 kiocb.ki_pos = *ppos;
293bc982
AV
494 iov_iter_init(&iter, WRITE, &iov, 1, len);
495
496 ret = filp->f_op->write_iter(&kiocb, &iter);
599bd19b 497 BUG_ON(ret == -EIOCBQUEUED);
f765b134
AV
498 if (ret > 0)
499 *ppos = kiocb.ki_pos;
293bc982
AV
500 return ret;
501}
502
493c84c0
AV
503ssize_t __vfs_write(struct file *file, const char __user *p, size_t count,
504 loff_t *pos)
505{
506 if (file->f_op->write)
507 return file->f_op->write(file, p, count, pos);
493c84c0
AV
508 else if (file->f_op->write_iter)
509 return new_sync_write(file, p, count, pos);
510 else
511 return -EINVAL;
512}
513EXPORT_SYMBOL(__vfs_write);
514
06ae43f3
AV
515ssize_t __kernel_write(struct file *file, const char *buf, size_t count, loff_t *pos)
516{
517 mm_segment_t old_fs;
518 const char __user *p;
519 ssize_t ret;
520
7f7f25e8 521 if (!(file->f_mode & FMODE_CAN_WRITE))
3e84f48e
AV
522 return -EINVAL;
523
06ae43f3
AV
524 old_fs = get_fs();
525 set_fs(get_ds());
526 p = (__force const char __user *)buf;
527 if (count > MAX_RW_COUNT)
528 count = MAX_RW_COUNT;
493c84c0 529 ret = __vfs_write(file, p, count, pos);
06ae43f3
AV
530 set_fs(old_fs);
531 if (ret > 0) {
532 fsnotify_modify(file);
533 add_wchar(current, ret);
534 }
535 inc_syscw(current);
536 return ret;
537}
538
2ec3a12a
AV
539EXPORT_SYMBOL(__kernel_write);
540
1da177e4
LT
541ssize_t vfs_write(struct file *file, const char __user *buf, size_t count, loff_t *pos)
542{
543 ssize_t ret;
544
545 if (!(file->f_mode & FMODE_WRITE))
546 return -EBADF;
7f7f25e8 547 if (!(file->f_mode & FMODE_CAN_WRITE))
1da177e4
LT
548 return -EINVAL;
549 if (unlikely(!access_ok(VERIFY_READ, buf, count)))
550 return -EFAULT;
551
552 ret = rw_verify_area(WRITE, file, pos, count);
bc61384d
AV
553 if (!ret) {
554 if (count > MAX_RW_COUNT)
555 count = MAX_RW_COUNT;
03d95eb2 556 file_start_write(file);
493c84c0 557 ret = __vfs_write(file, buf, count, pos);
c43e259c 558 if (ret > 0) {
2a12a9d7 559 fsnotify_modify(file);
c43e259c 560 add_wchar(current, ret);
1da177e4 561 }
c43e259c 562 inc_syscw(current);
03d95eb2 563 file_end_write(file);
1da177e4
LT
564 }
565
566 return ret;
567}
568
569EXPORT_SYMBOL(vfs_write);
570
571static inline loff_t file_pos_read(struct file *file)
572{
573 return file->f_pos;
574}
575
576static inline void file_pos_write(struct file *file, loff_t pos)
577{
578 file->f_pos = pos;
579}
580
3cdad428 581SYSCALL_DEFINE3(read, unsigned int, fd, char __user *, buf, size_t, count)
1da177e4 582{
9c225f26 583 struct fd f = fdget_pos(fd);
1da177e4 584 ssize_t ret = -EBADF;
1da177e4 585
2903ff01
AV
586 if (f.file) {
587 loff_t pos = file_pos_read(f.file);
588 ret = vfs_read(f.file, buf, count, &pos);
5faf153e
AV
589 if (ret >= 0)
590 file_pos_write(f.file, pos);
9c225f26 591 fdput_pos(f);
1da177e4 592 }
1da177e4
LT
593 return ret;
594}
1da177e4 595
3cdad428
HC
596SYSCALL_DEFINE3(write, unsigned int, fd, const char __user *, buf,
597 size_t, count)
1da177e4 598{
9c225f26 599 struct fd f = fdget_pos(fd);
1da177e4 600 ssize_t ret = -EBADF;
1da177e4 601
2903ff01
AV
602 if (f.file) {
603 loff_t pos = file_pos_read(f.file);
604 ret = vfs_write(f.file, buf, count, &pos);
5faf153e
AV
605 if (ret >= 0)
606 file_pos_write(f.file, pos);
9c225f26 607 fdput_pos(f);
1da177e4
LT
608 }
609
610 return ret;
611}
612
4a0fd5bf
AV
613SYSCALL_DEFINE4(pread64, unsigned int, fd, char __user *, buf,
614 size_t, count, loff_t, pos)
1da177e4 615{
2903ff01 616 struct fd f;
1da177e4 617 ssize_t ret = -EBADF;
1da177e4
LT
618
619 if (pos < 0)
620 return -EINVAL;
621
2903ff01
AV
622 f = fdget(fd);
623 if (f.file) {
1da177e4 624 ret = -ESPIPE;
2903ff01
AV
625 if (f.file->f_mode & FMODE_PREAD)
626 ret = vfs_read(f.file, buf, count, &pos);
627 fdput(f);
1da177e4
LT
628 }
629
630 return ret;
631}
632
4a0fd5bf
AV
633SYSCALL_DEFINE4(pwrite64, unsigned int, fd, const char __user *, buf,
634 size_t, count, loff_t, pos)
1da177e4 635{
2903ff01 636 struct fd f;
1da177e4 637 ssize_t ret = -EBADF;
1da177e4
LT
638
639 if (pos < 0)
640 return -EINVAL;
641
2903ff01
AV
642 f = fdget(fd);
643 if (f.file) {
1da177e4 644 ret = -ESPIPE;
2903ff01
AV
645 if (f.file->f_mode & FMODE_PWRITE)
646 ret = vfs_write(f.file, buf, count, &pos);
647 fdput(f);
1da177e4
LT
648 }
649
650 return ret;
651}
652
653/*
654 * Reduce an iovec's length in-place. Return the resulting number of segments
655 */
656unsigned long iov_shorten(struct iovec *iov, unsigned long nr_segs, size_t to)
657{
658 unsigned long seg = 0;
659 size_t len = 0;
660
661 while (seg < nr_segs) {
662 seg++;
663 if (len + iov->iov_len >= to) {
664 iov->iov_len = to - len;
665 break;
666 }
667 len += iov->iov_len;
668 iov++;
669 }
670 return seg;
671}
19295529 672EXPORT_SYMBOL(iov_shorten);
1da177e4 673
ac15ac06 674static ssize_t do_iter_readv_writev(struct file *filp, struct iov_iter *iter,
0f78d06a 675 loff_t *ppos, int type, int flags)
293bc982
AV
676{
677 struct kiocb kiocb;
293bc982
AV
678 ssize_t ret;
679
e864f395 680 if (flags & ~(RWF_HIPRI | RWF_DSYNC | RWF_SYNC))
793b80ef
CH
681 return -EOPNOTSUPP;
682
293bc982 683 init_sync_kiocb(&kiocb, filp);
97be7ebe
CH
684 if (flags & RWF_HIPRI)
685 kiocb.ki_flags |= IOCB_HIPRI;
e864f395
CH
686 if (flags & RWF_DSYNC)
687 kiocb.ki_flags |= IOCB_DSYNC;
688 if (flags & RWF_SYNC)
689 kiocb.ki_flags |= (IOCB_DSYNC | IOCB_SYNC);
293bc982 690 kiocb.ki_pos = *ppos;
293bc982 691
0f78d06a
MS
692 if (type == READ)
693 ret = filp->f_op->read_iter(&kiocb, iter);
694 else
695 ret = filp->f_op->write_iter(&kiocb, iter);
599bd19b 696 BUG_ON(ret == -EIOCBQUEUED);
293bc982
AV
697 *ppos = kiocb.ki_pos;
698 return ret;
699}
700
ee0b3e67 701/* Do it by hand, with file-ops */
ac15ac06 702static ssize_t do_loop_readv_writev(struct file *filp, struct iov_iter *iter,
0f78d06a 703 loff_t *ppos, int type, int flags)
ee0b3e67 704{
ee0b3e67
BP
705 ssize_t ret = 0;
706
97be7ebe 707 if (flags & ~RWF_HIPRI)
793b80ef
CH
708 return -EOPNOTSUPP;
709
ac15ac06
AV
710 while (iov_iter_count(iter)) {
711 struct iovec iovec = iov_iter_iovec(iter);
ee0b3e67
BP
712 ssize_t nr;
713
0f78d06a
MS
714 if (type == READ) {
715 nr = filp->f_op->read(filp, iovec.iov_base,
716 iovec.iov_len, ppos);
717 } else {
718 nr = filp->f_op->write(filp, iovec.iov_base,
719 iovec.iov_len, ppos);
720 }
ee0b3e67
BP
721
722 if (nr < 0) {
723 if (!ret)
724 ret = nr;
725 break;
726 }
727 ret += nr;
ac15ac06 728 if (nr != iovec.iov_len)
ee0b3e67 729 break;
ac15ac06 730 iov_iter_advance(iter, nr);
ee0b3e67
BP
731 }
732
733 return ret;
734}
735
1da177e4
LT
736/* A write operation does a read from user space and vice versa */
737#define vrfy_dir(type) ((type) == READ ? VERIFY_WRITE : VERIFY_READ)
738
ffecee4f
VN
739/**
740 * rw_copy_check_uvector() - Copy an array of &struct iovec from userspace
741 * into the kernel and check that it is valid.
742 *
743 * @type: One of %CHECK_IOVEC_ONLY, %READ, or %WRITE.
744 * @uvector: Pointer to the userspace array.
745 * @nr_segs: Number of elements in userspace array.
746 * @fast_segs: Number of elements in @fast_pointer.
747 * @fast_pointer: Pointer to (usually small on-stack) kernel array.
748 * @ret_pointer: (output parameter) Pointer to a variable that will point to
749 * either @fast_pointer, a newly allocated kernel array, or NULL,
750 * depending on which array was used.
751 *
752 * This function copies an array of &struct iovec of @nr_segs from
753 * userspace into the kernel and checks that each element is valid (e.g.
754 * it does not point to a kernel address or cause overflow by being too
755 * large, etc.).
756 *
757 * As an optimization, the caller may provide a pointer to a small
758 * on-stack array in @fast_pointer, typically %UIO_FASTIOV elements long
759 * (the size of this array, or 0 if unused, should be given in @fast_segs).
760 *
761 * @ret_pointer will always point to the array that was used, so the
762 * caller must take care not to call kfree() on it e.g. in case the
763 * @fast_pointer array was used and it was allocated on the stack.
764 *
765 * Return: The total number of bytes covered by the iovec array on success
766 * or a negative error code on error.
767 */
eed4e51f
BP
768ssize_t rw_copy_check_uvector(int type, const struct iovec __user * uvector,
769 unsigned long nr_segs, unsigned long fast_segs,
770 struct iovec *fast_pointer,
ac34ebb3 771 struct iovec **ret_pointer)
435f49a5 772{
eed4e51f 773 unsigned long seg;
435f49a5 774 ssize_t ret;
eed4e51f
BP
775 struct iovec *iov = fast_pointer;
776
435f49a5
LT
777 /*
778 * SuS says "The readv() function *may* fail if the iovcnt argument
779 * was less than or equal to 0, or greater than {IOV_MAX}. Linux has
780 * traditionally returned zero for zero segments, so...
781 */
eed4e51f
BP
782 if (nr_segs == 0) {
783 ret = 0;
435f49a5 784 goto out;
eed4e51f
BP
785 }
786
435f49a5
LT
787 /*
788 * First get the "struct iovec" from user memory and
789 * verify all the pointers
790 */
eed4e51f
BP
791 if (nr_segs > UIO_MAXIOV) {
792 ret = -EINVAL;
435f49a5 793 goto out;
eed4e51f
BP
794 }
795 if (nr_segs > fast_segs) {
435f49a5 796 iov = kmalloc(nr_segs*sizeof(struct iovec), GFP_KERNEL);
eed4e51f
BP
797 if (iov == NULL) {
798 ret = -ENOMEM;
435f49a5 799 goto out;
eed4e51f 800 }
435f49a5 801 }
eed4e51f
BP
802 if (copy_from_user(iov, uvector, nr_segs*sizeof(*uvector))) {
803 ret = -EFAULT;
435f49a5 804 goto out;
eed4e51f
BP
805 }
806
435f49a5 807 /*
eed4e51f
BP
808 * According to the Single Unix Specification we should return EINVAL
809 * if an element length is < 0 when cast to ssize_t or if the
810 * total length would overflow the ssize_t return value of the
811 * system call.
435f49a5
LT
812 *
813 * Linux caps all read/write calls to MAX_RW_COUNT, and avoids the
814 * overflow case.
815 */
eed4e51f 816 ret = 0;
435f49a5
LT
817 for (seg = 0; seg < nr_segs; seg++) {
818 void __user *buf = iov[seg].iov_base;
819 ssize_t len = (ssize_t)iov[seg].iov_len;
eed4e51f
BP
820
821 /* see if we we're about to use an invalid len or if
822 * it's about to overflow ssize_t */
435f49a5 823 if (len < 0) {
eed4e51f 824 ret = -EINVAL;
435f49a5 825 goto out;
eed4e51f 826 }
ac34ebb3 827 if (type >= 0
fcf63409 828 && unlikely(!access_ok(vrfy_dir(type), buf, len))) {
eed4e51f 829 ret = -EFAULT;
435f49a5
LT
830 goto out;
831 }
832 if (len > MAX_RW_COUNT - ret) {
833 len = MAX_RW_COUNT - ret;
834 iov[seg].iov_len = len;
eed4e51f 835 }
eed4e51f 836 ret += len;
435f49a5 837 }
eed4e51f
BP
838out:
839 *ret_pointer = iov;
840 return ret;
841}
842
7687a7a4
MS
843static ssize_t __do_readv_writev(int type, struct file *file,
844 struct iov_iter *iter, loff_t *pos, int flags)
1da177e4 845{
1da177e4 846 size_t tot_len;
7687a7a4 847 ssize_t ret = 0;
1da177e4 848
7687a7a4 849 tot_len = iov_iter_count(iter);
0504c074
AV
850 if (!tot_len)
851 goto out;
1da177e4 852 ret = rw_verify_area(type, file, pos, tot_len);
e28cc715 853 if (ret < 0)
411b67b4 854 goto out;
1da177e4 855
0f78d06a 856 if (type != READ)
03d95eb2 857 file_start_write(file);
1da177e4 858
0f78d06a
MS
859 if ((type == READ && file->f_op->read_iter) ||
860 (type == WRITE && file->f_op->write_iter))
861 ret = do_iter_readv_writev(file, iter, pos, type, flags);
ee0b3e67 862 else
0f78d06a 863 ret = do_loop_readv_writev(file, iter, pos, type, flags);
1da177e4 864
03d95eb2
AV
865 if (type != READ)
866 file_end_write(file);
867
1da177e4 868out:
0eeca283
RL
869 if ((ret + (type == READ)) > 0) {
870 if (type == READ)
2a12a9d7 871 fsnotify_access(file);
0eeca283 872 else
2a12a9d7 873 fsnotify_modify(file);
0eeca283 874 }
1da177e4 875 return ret;
1da177e4
LT
876}
877
7687a7a4
MS
878static ssize_t do_readv_writev(int type, struct file *file,
879 const struct iovec __user *uvector,
880 unsigned long nr_segs, loff_t *pos,
881 int flags)
882{
883 struct iovec iovstack[UIO_FASTIOV];
884 struct iovec *iov = iovstack;
885 struct iov_iter iter;
886 ssize_t ret;
887
888 ret = import_iovec(type, uvector, nr_segs,
889 ARRAY_SIZE(iovstack), &iov, &iter);
890 if (ret < 0)
891 return ret;
892
893 ret = __do_readv_writev(type, file, &iter, pos, flags);
894 kfree(iov);
895
896 return ret;
897}
898
1da177e4 899ssize_t vfs_readv(struct file *file, const struct iovec __user *vec,
793b80ef 900 unsigned long vlen, loff_t *pos, int flags)
1da177e4
LT
901{
902 if (!(file->f_mode & FMODE_READ))
903 return -EBADF;
7f7f25e8 904 if (!(file->f_mode & FMODE_CAN_READ))
1da177e4
LT
905 return -EINVAL;
906
793b80ef 907 return do_readv_writev(READ, file, vec, vlen, pos, flags);
1da177e4
LT
908}
909
910EXPORT_SYMBOL(vfs_readv);
911
912ssize_t vfs_writev(struct file *file, const struct iovec __user *vec,
793b80ef 913 unsigned long vlen, loff_t *pos, int flags)
1da177e4
LT
914{
915 if (!(file->f_mode & FMODE_WRITE))
916 return -EBADF;
7f7f25e8 917 if (!(file->f_mode & FMODE_CAN_WRITE))
1da177e4
LT
918 return -EINVAL;
919
793b80ef 920 return do_readv_writev(WRITE, file, vec, vlen, pos, flags);
1da177e4
LT
921}
922
923EXPORT_SYMBOL(vfs_writev);
924
f17d8b35
MT
925static ssize_t do_readv(unsigned long fd, const struct iovec __user *vec,
926 unsigned long vlen, int flags)
1da177e4 927{
9c225f26 928 struct fd f = fdget_pos(fd);
1da177e4 929 ssize_t ret = -EBADF;
1da177e4 930
2903ff01
AV
931 if (f.file) {
932 loff_t pos = file_pos_read(f.file);
f17d8b35 933 ret = vfs_readv(f.file, vec, vlen, &pos, flags);
5faf153e
AV
934 if (ret >= 0)
935 file_pos_write(f.file, pos);
9c225f26 936 fdput_pos(f);
1da177e4
LT
937 }
938
939 if (ret > 0)
4b98d11b
AD
940 add_rchar(current, ret);
941 inc_syscr(current);
1da177e4
LT
942 return ret;
943}
944
f17d8b35
MT
945static ssize_t do_writev(unsigned long fd, const struct iovec __user *vec,
946 unsigned long vlen, int flags)
1da177e4 947{
9c225f26 948 struct fd f = fdget_pos(fd);
1da177e4 949 ssize_t ret = -EBADF;
1da177e4 950
2903ff01
AV
951 if (f.file) {
952 loff_t pos = file_pos_read(f.file);
f17d8b35 953 ret = vfs_writev(f.file, vec, vlen, &pos, flags);
5faf153e
AV
954 if (ret >= 0)
955 file_pos_write(f.file, pos);
9c225f26 956 fdput_pos(f);
1da177e4
LT
957 }
958
959 if (ret > 0)
4b98d11b
AD
960 add_wchar(current, ret);
961 inc_syscw(current);
1da177e4
LT
962 return ret;
963}
964
601cc11d
LT
965static inline loff_t pos_from_hilo(unsigned long high, unsigned long low)
966{
967#define HALF_LONG_BITS (BITS_PER_LONG / 2)
968 return (((loff_t)high << HALF_LONG_BITS) << HALF_LONG_BITS) | low;
969}
970
f17d8b35
MT
971static ssize_t do_preadv(unsigned long fd, const struct iovec __user *vec,
972 unsigned long vlen, loff_t pos, int flags)
f3554f4b 973{
2903ff01 974 struct fd f;
f3554f4b 975 ssize_t ret = -EBADF;
f3554f4b
GH
976
977 if (pos < 0)
978 return -EINVAL;
979
2903ff01
AV
980 f = fdget(fd);
981 if (f.file) {
f3554f4b 982 ret = -ESPIPE;
2903ff01 983 if (f.file->f_mode & FMODE_PREAD)
f17d8b35 984 ret = vfs_readv(f.file, vec, vlen, &pos, flags);
2903ff01 985 fdput(f);
f3554f4b
GH
986 }
987
988 if (ret > 0)
989 add_rchar(current, ret);
990 inc_syscr(current);
991 return ret;
992}
993
f17d8b35
MT
994static ssize_t do_pwritev(unsigned long fd, const struct iovec __user *vec,
995 unsigned long vlen, loff_t pos, int flags)
f3554f4b 996{
2903ff01 997 struct fd f;
f3554f4b 998 ssize_t ret = -EBADF;
f3554f4b
GH
999
1000 if (pos < 0)
1001 return -EINVAL;
1002
2903ff01
AV
1003 f = fdget(fd);
1004 if (f.file) {
f3554f4b 1005 ret = -ESPIPE;
2903ff01 1006 if (f.file->f_mode & FMODE_PWRITE)
f17d8b35 1007 ret = vfs_writev(f.file, vec, vlen, &pos, flags);
2903ff01 1008 fdput(f);
f3554f4b
GH
1009 }
1010
1011 if (ret > 0)
1012 add_wchar(current, ret);
1013 inc_syscw(current);
1014 return ret;
1015}
1016
f17d8b35
MT
1017SYSCALL_DEFINE3(readv, unsigned long, fd, const struct iovec __user *, vec,
1018 unsigned long, vlen)
1019{
1020 return do_readv(fd, vec, vlen, 0);
1021}
1022
1023SYSCALL_DEFINE3(writev, unsigned long, fd, const struct iovec __user *, vec,
1024 unsigned long, vlen)
1025{
1026 return do_writev(fd, vec, vlen, 0);
1027}
1028
1029SYSCALL_DEFINE5(preadv, unsigned long, fd, const struct iovec __user *, vec,
1030 unsigned long, vlen, unsigned long, pos_l, unsigned long, pos_h)
1031{
1032 loff_t pos = pos_from_hilo(pos_h, pos_l);
1033
1034 return do_preadv(fd, vec, vlen, pos, 0);
1035}
1036
1037SYSCALL_DEFINE6(preadv2, unsigned long, fd, const struct iovec __user *, vec,
1038 unsigned long, vlen, unsigned long, pos_l, unsigned long, pos_h,
1039 int, flags)
1040{
1041 loff_t pos = pos_from_hilo(pos_h, pos_l);
1042
1043 if (pos == -1)
1044 return do_readv(fd, vec, vlen, flags);
1045
1046 return do_preadv(fd, vec, vlen, pos, flags);
1047}
1048
1049SYSCALL_DEFINE5(pwritev, unsigned long, fd, const struct iovec __user *, vec,
1050 unsigned long, vlen, unsigned long, pos_l, unsigned long, pos_h)
1051{
1052 loff_t pos = pos_from_hilo(pos_h, pos_l);
1053
1054 return do_pwritev(fd, vec, vlen, pos, 0);
1055}
1056
1057SYSCALL_DEFINE6(pwritev2, unsigned long, fd, const struct iovec __user *, vec,
1058 unsigned long, vlen, unsigned long, pos_l, unsigned long, pos_h,
1059 int, flags)
1060{
1061 loff_t pos = pos_from_hilo(pos_h, pos_l);
1062
1063 if (pos == -1)
1064 return do_writev(fd, vec, vlen, flags);
1065
1066 return do_pwritev(fd, vec, vlen, pos, flags);
1067}
1068
72ec3516
AV
1069#ifdef CONFIG_COMPAT
1070
1071static ssize_t compat_do_readv_writev(int type, struct file *file,
1072 const struct compat_iovec __user *uvector,
793b80ef
CH
1073 unsigned long nr_segs, loff_t *pos,
1074 int flags)
72ec3516 1075{
72ec3516
AV
1076 struct iovec iovstack[UIO_FASTIOV];
1077 struct iovec *iov = iovstack;
ac15ac06 1078 struct iov_iter iter;
72ec3516 1079 ssize_t ret;
72ec3516 1080
0504c074
AV
1081 ret = compat_import_iovec(type, uvector, nr_segs,
1082 UIO_FASTIOV, &iov, &iter);
1083 if (ret < 0)
1084 return ret;
72ec3516 1085
7687a7a4 1086 ret = __do_readv_writev(type, file, &iter, pos, flags);
0504c074 1087 kfree(iov);
7687a7a4 1088
72ec3516
AV
1089 return ret;
1090}
1091
1092static size_t compat_readv(struct file *file,
1093 const struct compat_iovec __user *vec,
f17d8b35 1094 unsigned long vlen, loff_t *pos, int flags)
72ec3516
AV
1095{
1096 ssize_t ret = -EBADF;
1097
1098 if (!(file->f_mode & FMODE_READ))
1099 goto out;
1100
1101 ret = -EINVAL;
7f7f25e8 1102 if (!(file->f_mode & FMODE_CAN_READ))
72ec3516
AV
1103 goto out;
1104
f17d8b35 1105 ret = compat_do_readv_writev(READ, file, vec, vlen, pos, flags);
72ec3516
AV
1106
1107out:
1108 if (ret > 0)
1109 add_rchar(current, ret);
1110 inc_syscr(current);
1111 return ret;
1112}
1113
f17d8b35
MT
1114static size_t do_compat_readv(compat_ulong_t fd,
1115 const struct compat_iovec __user *vec,
1116 compat_ulong_t vlen, int flags)
72ec3516 1117{
9c225f26 1118 struct fd f = fdget_pos(fd);
72ec3516
AV
1119 ssize_t ret;
1120 loff_t pos;
1121
1122 if (!f.file)
1123 return -EBADF;
1124 pos = f.file->f_pos;
f17d8b35 1125 ret = compat_readv(f.file, vec, vlen, &pos, flags);
5faf153e
AV
1126 if (ret >= 0)
1127 f.file->f_pos = pos;
9c225f26 1128 fdput_pos(f);
72ec3516 1129 return ret;
f17d8b35 1130
72ec3516
AV
1131}
1132
f17d8b35
MT
1133COMPAT_SYSCALL_DEFINE3(readv, compat_ulong_t, fd,
1134 const struct compat_iovec __user *,vec,
1135 compat_ulong_t, vlen)
1136{
1137 return do_compat_readv(fd, vec, vlen, 0);
1138}
1139
1140static long do_compat_preadv64(unsigned long fd,
378a10f3 1141 const struct compat_iovec __user *vec,
f17d8b35 1142 unsigned long vlen, loff_t pos, int flags)
72ec3516
AV
1143{
1144 struct fd f;
1145 ssize_t ret;
1146
1147 if (pos < 0)
1148 return -EINVAL;
1149 f = fdget(fd);
1150 if (!f.file)
1151 return -EBADF;
1152 ret = -ESPIPE;
1153 if (f.file->f_mode & FMODE_PREAD)
f17d8b35 1154 ret = compat_readv(f.file, vec, vlen, &pos, flags);
72ec3516
AV
1155 fdput(f);
1156 return ret;
1157}
1158
378a10f3
HC
1159#ifdef __ARCH_WANT_COMPAT_SYS_PREADV64
1160COMPAT_SYSCALL_DEFINE4(preadv64, unsigned long, fd,
1161 const struct compat_iovec __user *,vec,
1162 unsigned long, vlen, loff_t, pos)
1163{
f17d8b35 1164 return do_compat_preadv64(fd, vec, vlen, pos, 0);
378a10f3
HC
1165}
1166#endif
1167
dfd948e3 1168COMPAT_SYSCALL_DEFINE5(preadv, compat_ulong_t, fd,
72ec3516 1169 const struct compat_iovec __user *,vec,
dfd948e3 1170 compat_ulong_t, vlen, u32, pos_low, u32, pos_high)
72ec3516
AV
1171{
1172 loff_t pos = ((loff_t)pos_high << 32) | pos_low;
378a10f3 1173
f17d8b35
MT
1174 return do_compat_preadv64(fd, vec, vlen, pos, 0);
1175}
1176
3ebfd81f
L
1177#ifdef __ARCH_WANT_COMPAT_SYS_PREADV64V2
1178COMPAT_SYSCALL_DEFINE5(preadv64v2, unsigned long, fd,
1179 const struct compat_iovec __user *,vec,
1180 unsigned long, vlen, loff_t, pos, int, flags)
1181{
1182 return do_compat_preadv64(fd, vec, vlen, pos, flags);
1183}
1184#endif
1185
f17d8b35
MT
1186COMPAT_SYSCALL_DEFINE6(preadv2, compat_ulong_t, fd,
1187 const struct compat_iovec __user *,vec,
1188 compat_ulong_t, vlen, u32, pos_low, u32, pos_high,
1189 int, flags)
1190{
1191 loff_t pos = ((loff_t)pos_high << 32) | pos_low;
1192
1193 if (pos == -1)
1194 return do_compat_readv(fd, vec, vlen, flags);
1195
1196 return do_compat_preadv64(fd, vec, vlen, pos, flags);
72ec3516
AV
1197}
1198
1199static size_t compat_writev(struct file *file,
1200 const struct compat_iovec __user *vec,
f17d8b35 1201 unsigned long vlen, loff_t *pos, int flags)
72ec3516
AV
1202{
1203 ssize_t ret = -EBADF;
1204
1205 if (!(file->f_mode & FMODE_WRITE))
1206 goto out;
1207
1208 ret = -EINVAL;
7f7f25e8 1209 if (!(file->f_mode & FMODE_CAN_WRITE))
72ec3516
AV
1210 goto out;
1211
793b80ef 1212 ret = compat_do_readv_writev(WRITE, file, vec, vlen, pos, 0);
72ec3516
AV
1213
1214out:
1215 if (ret > 0)
1216 add_wchar(current, ret);
1217 inc_syscw(current);
1218 return ret;
1219}
1220
f17d8b35
MT
1221static size_t do_compat_writev(compat_ulong_t fd,
1222 const struct compat_iovec __user* vec,
1223 compat_ulong_t vlen, int flags)
72ec3516 1224{
9c225f26 1225 struct fd f = fdget_pos(fd);
72ec3516
AV
1226 ssize_t ret;
1227 loff_t pos;
1228
1229 if (!f.file)
1230 return -EBADF;
1231 pos = f.file->f_pos;
f17d8b35 1232 ret = compat_writev(f.file, vec, vlen, &pos, flags);
5faf153e
AV
1233 if (ret >= 0)
1234 f.file->f_pos = pos;
9c225f26 1235 fdput_pos(f);
72ec3516
AV
1236 return ret;
1237}
1238
f17d8b35
MT
1239COMPAT_SYSCALL_DEFINE3(writev, compat_ulong_t, fd,
1240 const struct compat_iovec __user *, vec,
1241 compat_ulong_t, vlen)
1242{
1243 return do_compat_writev(fd, vec, vlen, 0);
1244}
1245
1246static long do_compat_pwritev64(unsigned long fd,
378a10f3 1247 const struct compat_iovec __user *vec,
f17d8b35 1248 unsigned long vlen, loff_t pos, int flags)
72ec3516
AV
1249{
1250 struct fd f;
1251 ssize_t ret;
1252
1253 if (pos < 0)
1254 return -EINVAL;
1255 f = fdget(fd);
1256 if (!f.file)
1257 return -EBADF;
1258 ret = -ESPIPE;
1259 if (f.file->f_mode & FMODE_PWRITE)
f17d8b35 1260 ret = compat_writev(f.file, vec, vlen, &pos, flags);
72ec3516
AV
1261 fdput(f);
1262 return ret;
1263}
1264
378a10f3
HC
1265#ifdef __ARCH_WANT_COMPAT_SYS_PWRITEV64
1266COMPAT_SYSCALL_DEFINE4(pwritev64, unsigned long, fd,
1267 const struct compat_iovec __user *,vec,
1268 unsigned long, vlen, loff_t, pos)
1269{
f17d8b35 1270 return do_compat_pwritev64(fd, vec, vlen, pos, 0);
378a10f3
HC
1271}
1272#endif
1273
dfd948e3 1274COMPAT_SYSCALL_DEFINE5(pwritev, compat_ulong_t, fd,
72ec3516 1275 const struct compat_iovec __user *,vec,
dfd948e3 1276 compat_ulong_t, vlen, u32, pos_low, u32, pos_high)
72ec3516
AV
1277{
1278 loff_t pos = ((loff_t)pos_high << 32) | pos_low;
378a10f3 1279
f17d8b35 1280 return do_compat_pwritev64(fd, vec, vlen, pos, 0);
72ec3516 1281}
f17d8b35 1282
3ebfd81f
L
1283#ifdef __ARCH_WANT_COMPAT_SYS_PWRITEV64V2
1284COMPAT_SYSCALL_DEFINE5(pwritev64v2, unsigned long, fd,
1285 const struct compat_iovec __user *,vec,
1286 unsigned long, vlen, loff_t, pos, int, flags)
1287{
1288 return do_compat_pwritev64(fd, vec, vlen, pos, flags);
1289}
1290#endif
1291
f17d8b35
MT
1292COMPAT_SYSCALL_DEFINE6(pwritev2, compat_ulong_t, fd,
1293 const struct compat_iovec __user *,vec,
1294 compat_ulong_t, vlen, u32, pos_low, u32, pos_high, int, flags)
1295{
1296 loff_t pos = ((loff_t)pos_high << 32) | pos_low;
1297
1298 if (pos == -1)
1299 return do_compat_writev(fd, vec, vlen, flags);
1300
1301 return do_compat_pwritev64(fd, vec, vlen, pos, flags);
72ec3516 1302}
f17d8b35 1303
72ec3516
AV
1304#endif
1305
19f4fc3a
AV
1306static ssize_t do_sendfile(int out_fd, int in_fd, loff_t *ppos,
1307 size_t count, loff_t max)
1da177e4 1308{
2903ff01
AV
1309 struct fd in, out;
1310 struct inode *in_inode, *out_inode;
1da177e4 1311 loff_t pos;
7995bd28 1312 loff_t out_pos;
1da177e4 1313 ssize_t retval;
2903ff01 1314 int fl;
1da177e4
LT
1315
1316 /*
1317 * Get input file, and verify that it is ok..
1318 */
1319 retval = -EBADF;
2903ff01
AV
1320 in = fdget(in_fd);
1321 if (!in.file)
1da177e4 1322 goto out;
2903ff01 1323 if (!(in.file->f_mode & FMODE_READ))
1da177e4 1324 goto fput_in;
1da177e4 1325 retval = -ESPIPE;
7995bd28
AV
1326 if (!ppos) {
1327 pos = in.file->f_pos;
1328 } else {
1329 pos = *ppos;
2903ff01 1330 if (!(in.file->f_mode & FMODE_PREAD))
1da177e4 1331 goto fput_in;
7995bd28
AV
1332 }
1333 retval = rw_verify_area(READ, in.file, &pos, count);
e28cc715 1334 if (retval < 0)
1da177e4 1335 goto fput_in;
bc61384d
AV
1336 if (count > MAX_RW_COUNT)
1337 count = MAX_RW_COUNT;
1da177e4 1338
1da177e4
LT
1339 /*
1340 * Get output file, and verify that it is ok..
1341 */
1342 retval = -EBADF;
2903ff01
AV
1343 out = fdget(out_fd);
1344 if (!out.file)
1da177e4 1345 goto fput_in;
2903ff01 1346 if (!(out.file->f_mode & FMODE_WRITE))
1da177e4
LT
1347 goto fput_out;
1348 retval = -EINVAL;
496ad9aa
AV
1349 in_inode = file_inode(in.file);
1350 out_inode = file_inode(out.file);
7995bd28
AV
1351 out_pos = out.file->f_pos;
1352 retval = rw_verify_area(WRITE, out.file, &out_pos, count);
e28cc715 1353 if (retval < 0)
1da177e4
LT
1354 goto fput_out;
1355
1da177e4
LT
1356 if (!max)
1357 max = min(in_inode->i_sb->s_maxbytes, out_inode->i_sb->s_maxbytes);
1358
1da177e4
LT
1359 if (unlikely(pos + count > max)) {
1360 retval = -EOVERFLOW;
1361 if (pos >= max)
1362 goto fput_out;
1363 count = max - pos;
1364 }
1365
d96e6e71 1366 fl = 0;
534f2aaa 1367#if 0
d96e6e71
JA
1368 /*
1369 * We need to debate whether we can enable this or not. The
1370 * man page documents EAGAIN return for the output at least,
1371 * and the application is arguably buggy if it doesn't expect
1372 * EAGAIN on a non-blocking file descriptor.
1373 */
2903ff01 1374 if (in.file->f_flags & O_NONBLOCK)
d96e6e71 1375 fl = SPLICE_F_NONBLOCK;
534f2aaa 1376#endif
50cd2c57 1377 file_start_write(out.file);
7995bd28 1378 retval = do_splice_direct(in.file, &pos, out.file, &out_pos, count, fl);
50cd2c57 1379 file_end_write(out.file);
1da177e4
LT
1380
1381 if (retval > 0) {
4b98d11b
AD
1382 add_rchar(current, retval);
1383 add_wchar(current, retval);
a68c2f12
SW
1384 fsnotify_access(in.file);
1385 fsnotify_modify(out.file);
7995bd28
AV
1386 out.file->f_pos = out_pos;
1387 if (ppos)
1388 *ppos = pos;
1389 else
1390 in.file->f_pos = pos;
1da177e4 1391 }
1da177e4 1392
4b98d11b
AD
1393 inc_syscr(current);
1394 inc_syscw(current);
7995bd28 1395 if (pos > max)
1da177e4
LT
1396 retval = -EOVERFLOW;
1397
1398fput_out:
2903ff01 1399 fdput(out);
1da177e4 1400fput_in:
2903ff01 1401 fdput(in);
1da177e4
LT
1402out:
1403 return retval;
1404}
1405
002c8976 1406SYSCALL_DEFINE4(sendfile, int, out_fd, int, in_fd, off_t __user *, offset, size_t, count)
1da177e4
LT
1407{
1408 loff_t pos;
1409 off_t off;
1410 ssize_t ret;
1411
1412 if (offset) {
1413 if (unlikely(get_user(off, offset)))
1414 return -EFAULT;
1415 pos = off;
1416 ret = do_sendfile(out_fd, in_fd, &pos, count, MAX_NON_LFS);
1417 if (unlikely(put_user(pos, offset)))
1418 return -EFAULT;
1419 return ret;
1420 }
1421
1422 return do_sendfile(out_fd, in_fd, NULL, count, 0);
1423}
1424
002c8976 1425SYSCALL_DEFINE4(sendfile64, int, out_fd, int, in_fd, loff_t __user *, offset, size_t, count)
1da177e4
LT
1426{
1427 loff_t pos;
1428 ssize_t ret;
1429
1430 if (offset) {
1431 if (unlikely(copy_from_user(&pos, offset, sizeof(loff_t))))
1432 return -EFAULT;
1433 ret = do_sendfile(out_fd, in_fd, &pos, count, 0);
1434 if (unlikely(put_user(pos, offset)))
1435 return -EFAULT;
1436 return ret;
1437 }
1438
1439 return do_sendfile(out_fd, in_fd, NULL, count, 0);
1440}
19f4fc3a
AV
1441
1442#ifdef CONFIG_COMPAT
1443COMPAT_SYSCALL_DEFINE4(sendfile, int, out_fd, int, in_fd,
1444 compat_off_t __user *, offset, compat_size_t, count)
1445{
1446 loff_t pos;
1447 off_t off;
1448 ssize_t ret;
1449
1450 if (offset) {
1451 if (unlikely(get_user(off, offset)))
1452 return -EFAULT;
1453 pos = off;
1454 ret = do_sendfile(out_fd, in_fd, &pos, count, MAX_NON_LFS);
1455 if (unlikely(put_user(pos, offset)))
1456 return -EFAULT;
1457 return ret;
1458 }
1459
1460 return do_sendfile(out_fd, in_fd, NULL, count, 0);
1461}
1462
1463COMPAT_SYSCALL_DEFINE4(sendfile64, int, out_fd, int, in_fd,
1464 compat_loff_t __user *, offset, compat_size_t, count)
1465{
1466 loff_t pos;
1467 ssize_t ret;
1468
1469 if (offset) {
1470 if (unlikely(copy_from_user(&pos, offset, sizeof(loff_t))))
1471 return -EFAULT;
1472 ret = do_sendfile(out_fd, in_fd, &pos, count, 0);
1473 if (unlikely(put_user(pos, offset)))
1474 return -EFAULT;
1475 return ret;
1476 }
1477
1478 return do_sendfile(out_fd, in_fd, NULL, count, 0);
1479}
1480#endif
29732938
ZB
1481
1482/*
1483 * copy_file_range() differs from regular file read and write in that it
1484 * specifically allows return partial success. When it does so is up to
1485 * the copy_file_range method.
1486 */
1487ssize_t vfs_copy_file_range(struct file *file_in, loff_t pos_in,
1488 struct file *file_out, loff_t pos_out,
1489 size_t len, unsigned int flags)
1490{
1491 struct inode *inode_in = file_inode(file_in);
1492 struct inode *inode_out = file_inode(file_out);
1493 ssize_t ret;
1494
1495 if (flags != 0)
1496 return -EINVAL;
1497
11cbfb10
AG
1498 if (S_ISDIR(inode_in->i_mode) || S_ISDIR(inode_out->i_mode))
1499 return -EISDIR;
1500 if (!S_ISREG(inode_in->i_mode) || !S_ISREG(inode_out->i_mode))
1501 return -EINVAL;
1502
29732938 1503 ret = rw_verify_area(READ, file_in, &pos_in, len);
bc61384d
AV
1504 if (unlikely(ret))
1505 return ret;
1506
1507 ret = rw_verify_area(WRITE, file_out, &pos_out, len);
1508 if (unlikely(ret))
29732938
ZB
1509 return ret;
1510
1511 if (!(file_in->f_mode & FMODE_READ) ||
1512 !(file_out->f_mode & FMODE_WRITE) ||
eac70053 1513 (file_out->f_flags & O_APPEND))
29732938
ZB
1514 return -EBADF;
1515
1516 /* this could be relaxed once a method supports cross-fs copies */
1517 if (inode_in->i_sb != inode_out->i_sb)
1518 return -EXDEV;
1519
1520 if (len == 0)
1521 return 0;
1522
bfe219d3 1523 file_start_write(file_out);
29732938 1524
a76b5b04
CH
1525 /*
1526 * Try cloning first, this is supported by more file systems, and
1527 * more efficient if both clone and copy are supported (e.g. NFS).
1528 */
1529 if (file_in->f_op->clone_file_range) {
1530 ret = file_in->f_op->clone_file_range(file_in, pos_in,
1531 file_out, pos_out, len);
1532 if (ret == 0) {
1533 ret = len;
1534 goto done;
1535 }
1536 }
1537
1538 if (file_out->f_op->copy_file_range) {
eac70053
AS
1539 ret = file_out->f_op->copy_file_range(file_in, pos_in, file_out,
1540 pos_out, len, flags);
a76b5b04
CH
1541 if (ret != -EOPNOTSUPP)
1542 goto done;
1543 }
eac70053 1544
a76b5b04
CH
1545 ret = do_splice_direct(file_in, &pos_in, file_out, &pos_out,
1546 len > MAX_RW_COUNT ? MAX_RW_COUNT : len, 0);
eac70053 1547
a76b5b04 1548done:
29732938
ZB
1549 if (ret > 0) {
1550 fsnotify_access(file_in);
1551 add_rchar(current, ret);
1552 fsnotify_modify(file_out);
1553 add_wchar(current, ret);
1554 }
a76b5b04 1555
29732938
ZB
1556 inc_syscr(current);
1557 inc_syscw(current);
1558
bfe219d3 1559 file_end_write(file_out);
29732938
ZB
1560
1561 return ret;
1562}
1563EXPORT_SYMBOL(vfs_copy_file_range);
1564
1565SYSCALL_DEFINE6(copy_file_range, int, fd_in, loff_t __user *, off_in,
1566 int, fd_out, loff_t __user *, off_out,
1567 size_t, len, unsigned int, flags)
1568{
1569 loff_t pos_in;
1570 loff_t pos_out;
1571 struct fd f_in;
1572 struct fd f_out;
1573 ssize_t ret = -EBADF;
1574
1575 f_in = fdget(fd_in);
1576 if (!f_in.file)
1577 goto out2;
1578
1579 f_out = fdget(fd_out);
1580 if (!f_out.file)
1581 goto out1;
1582
1583 ret = -EFAULT;
1584 if (off_in) {
1585 if (copy_from_user(&pos_in, off_in, sizeof(loff_t)))
1586 goto out;
1587 } else {
1588 pos_in = f_in.file->f_pos;
1589 }
1590
1591 if (off_out) {
1592 if (copy_from_user(&pos_out, off_out, sizeof(loff_t)))
1593 goto out;
1594 } else {
1595 pos_out = f_out.file->f_pos;
1596 }
1597
1598 ret = vfs_copy_file_range(f_in.file, pos_in, f_out.file, pos_out, len,
1599 flags);
1600 if (ret > 0) {
1601 pos_in += ret;
1602 pos_out += ret;
1603
1604 if (off_in) {
1605 if (copy_to_user(off_in, &pos_in, sizeof(loff_t)))
1606 ret = -EFAULT;
1607 } else {
1608 f_in.file->f_pos = pos_in;
1609 }
1610
1611 if (off_out) {
1612 if (copy_to_user(off_out, &pos_out, sizeof(loff_t)))
1613 ret = -EFAULT;
1614 } else {
1615 f_out.file->f_pos = pos_out;
1616 }
1617 }
1618
1619out:
1620 fdput(f_out);
1621out1:
1622 fdput(f_in);
1623out2:
1624 return ret;
1625}
04b38d60
CH
1626
1627static int clone_verify_area(struct file *file, loff_t pos, u64 len, bool write)
1628{
1629 struct inode *inode = file_inode(file);
1630
1631 if (unlikely(pos < 0))
1632 return -EINVAL;
1633
1634 if (unlikely((loff_t) (pos + len) < 0))
1635 return -EINVAL;
1636
1637 if (unlikely(inode->i_flctx && mandatory_lock(inode))) {
1638 loff_t end = len ? pos + len - 1 : OFFSET_MAX;
1639 int retval;
1640
1641 retval = locks_mandatory_area(inode, file, pos, end,
1642 write ? F_WRLCK : F_RDLCK);
1643 if (retval < 0)
1644 return retval;
1645 }
1646
1647 return security_file_permission(file, write ? MAY_WRITE : MAY_READ);
1648}
1649
876bec6f
DW
1650/*
1651 * Check that the two inodes are eligible for cloning, the ranges make
1652 * sense, and then flush all dirty data. Caller must ensure that the
1653 * inodes have been locked against any other modifications.
22725ce4
DW
1654 *
1655 * Returns: 0 for "nothing to clone", 1 for "something to clone", or
1656 * the usual negative error code.
876bec6f
DW
1657 */
1658int vfs_clone_file_prep_inodes(struct inode *inode_in, loff_t pos_in,
1659 struct inode *inode_out, loff_t pos_out,
1660 u64 *len, bool is_dedupe)
1661{
1662 loff_t bs = inode_out->i_sb->s_blocksize;
1663 loff_t blen;
1664 loff_t isize;
1665 bool same_inode = (inode_in == inode_out);
1666 int ret;
1667
1668 /* Don't touch certain kinds of inodes */
1669 if (IS_IMMUTABLE(inode_out))
1670 return -EPERM;
1671
1672 if (IS_SWAPFILE(inode_in) || IS_SWAPFILE(inode_out))
1673 return -ETXTBSY;
1674
1675 /* Don't reflink dirs, pipes, sockets... */
1676 if (S_ISDIR(inode_in->i_mode) || S_ISDIR(inode_out->i_mode))
1677 return -EISDIR;
1678 if (!S_ISREG(inode_in->i_mode) || !S_ISREG(inode_out->i_mode))
1679 return -EINVAL;
1680
1681 /* Are we going all the way to the end? */
1682 isize = i_size_read(inode_in);
22725ce4 1683 if (isize == 0)
876bec6f 1684 return 0;
876bec6f
DW
1685
1686 /* Zero length dedupe exits immediately; reflink goes to EOF. */
1687 if (*len == 0) {
22725ce4 1688 if (is_dedupe || pos_in == isize)
876bec6f 1689 return 0;
22725ce4
DW
1690 if (pos_in > isize)
1691 return -EINVAL;
876bec6f
DW
1692 *len = isize - pos_in;
1693 }
1694
1695 /* Ensure offsets don't wrap and the input is inside i_size */
1696 if (pos_in + *len < pos_in || pos_out + *len < pos_out ||
1697 pos_in + *len > isize)
1698 return -EINVAL;
1699
1700 /* Don't allow dedupe past EOF in the dest file */
1701 if (is_dedupe) {
1702 loff_t disize;
1703
1704 disize = i_size_read(inode_out);
1705 if (pos_out >= disize || pos_out + *len > disize)
1706 return -EINVAL;
1707 }
1708
1709 /* If we're linking to EOF, continue to the block boundary. */
1710 if (pos_in + *len == isize)
1711 blen = ALIGN(isize, bs) - pos_in;
1712 else
1713 blen = *len;
1714
1715 /* Only reflink if we're aligned to block boundaries */
1716 if (!IS_ALIGNED(pos_in, bs) || !IS_ALIGNED(pos_in + blen, bs) ||
1717 !IS_ALIGNED(pos_out, bs) || !IS_ALIGNED(pos_out + blen, bs))
1718 return -EINVAL;
1719
1720 /* Don't allow overlapped reflink within the same file */
1721 if (same_inode) {
1722 if (pos_out + blen > pos_in && pos_out < pos_in + blen)
1723 return -EINVAL;
1724 }
1725
1726 /* Wait for the completion of any pending IOs on both files */
1727 inode_dio_wait(inode_in);
1728 if (!same_inode)
1729 inode_dio_wait(inode_out);
1730
1731 ret = filemap_write_and_wait_range(inode_in->i_mapping,
1732 pos_in, pos_in + *len - 1);
1733 if (ret)
1734 return ret;
1735
1736 ret = filemap_write_and_wait_range(inode_out->i_mapping,
1737 pos_out, pos_out + *len - 1);
1738 if (ret)
1739 return ret;
1740
1741 /*
1742 * Check that the extents are the same.
1743 */
1744 if (is_dedupe) {
1745 bool is_same = false;
1746
1747 ret = vfs_dedupe_file_range_compare(inode_in, pos_in,
1748 inode_out, pos_out, *len, &is_same);
1749 if (ret)
1750 return ret;
1751 if (!is_same)
1752 return -EBADE;
1753 }
1754
22725ce4 1755 return 1;
876bec6f
DW
1756}
1757EXPORT_SYMBOL(vfs_clone_file_prep_inodes);
1758
04b38d60
CH
1759int vfs_clone_file_range(struct file *file_in, loff_t pos_in,
1760 struct file *file_out, loff_t pos_out, u64 len)
1761{
1762 struct inode *inode_in = file_inode(file_in);
1763 struct inode *inode_out = file_inode(file_out);
1764 int ret;
1765
b335e9d9
AG
1766 if (S_ISDIR(inode_in->i_mode) || S_ISDIR(inode_out->i_mode))
1767 return -EISDIR;
1768 if (!S_ISREG(inode_in->i_mode) || !S_ISREG(inode_out->i_mode))
1769 return -EINVAL;
1770
913b86e9
AG
1771 /*
1772 * FICLONE/FICLONERANGE ioctls enforce that src and dest files are on
1773 * the same mount. Practically, they only need to be on the same file
1774 * system.
1775 */
1776 if (inode_in->i_sb != inode_out->i_sb)
04b38d60
CH
1777 return -EXDEV;
1778
04b38d60
CH
1779 if (!(file_in->f_mode & FMODE_READ) ||
1780 !(file_out->f_mode & FMODE_WRITE) ||
0fcbf996 1781 (file_out->f_flags & O_APPEND))
04b38d60
CH
1782 return -EBADF;
1783
0fcbf996
CH
1784 if (!file_in->f_op->clone_file_range)
1785 return -EOPNOTSUPP;
1786
04b38d60
CH
1787 ret = clone_verify_area(file_in, pos_in, len, false);
1788 if (ret)
1789 return ret;
1790
1791 ret = clone_verify_area(file_out, pos_out, len, true);
1792 if (ret)
1793 return ret;
1794
1795 if (pos_in + len > i_size_read(inode_in))
1796 return -EINVAL;
1797
04b38d60
CH
1798 ret = file_in->f_op->clone_file_range(file_in, pos_in,
1799 file_out, pos_out, len);
1800 if (!ret) {
1801 fsnotify_access(file_in);
1802 fsnotify_modify(file_out);
1803 }
1804
04b38d60
CH
1805 return ret;
1806}
1807EXPORT_SYMBOL(vfs_clone_file_range);
54dbc151 1808
876bec6f
DW
1809/*
1810 * Read a page's worth of file data into the page cache. Return the page
1811 * locked.
1812 */
1813static struct page *vfs_dedupe_get_page(struct inode *inode, loff_t offset)
1814{
1815 struct address_space *mapping;
1816 struct page *page;
1817 pgoff_t n;
1818
1819 n = offset >> PAGE_SHIFT;
1820 mapping = inode->i_mapping;
1821 page = read_mapping_page(mapping, n, NULL);
1822 if (IS_ERR(page))
1823 return page;
1824 if (!PageUptodate(page)) {
1825 put_page(page);
1826 return ERR_PTR(-EIO);
1827 }
1828 lock_page(page);
1829 return page;
1830}
1831
1832/*
1833 * Compare extents of two files to see if they are the same.
1834 * Caller must have locked both inodes to prevent write races.
1835 */
1836int vfs_dedupe_file_range_compare(struct inode *src, loff_t srcoff,
1837 struct inode *dest, loff_t destoff,
1838 loff_t len, bool *is_same)
1839{
1840 loff_t src_poff;
1841 loff_t dest_poff;
1842 void *src_addr;
1843 void *dest_addr;
1844 struct page *src_page;
1845 struct page *dest_page;
1846 loff_t cmp_len;
1847 bool same;
1848 int error;
1849
1850 error = -EINVAL;
1851 same = true;
1852 while (len) {
1853 src_poff = srcoff & (PAGE_SIZE - 1);
1854 dest_poff = destoff & (PAGE_SIZE - 1);
1855 cmp_len = min(PAGE_SIZE - src_poff,
1856 PAGE_SIZE - dest_poff);
1857 cmp_len = min(cmp_len, len);
1858 if (cmp_len <= 0)
1859 goto out_error;
1860
1861 src_page = vfs_dedupe_get_page(src, srcoff);
1862 if (IS_ERR(src_page)) {
1863 error = PTR_ERR(src_page);
1864 goto out_error;
1865 }
1866 dest_page = vfs_dedupe_get_page(dest, destoff);
1867 if (IS_ERR(dest_page)) {
1868 error = PTR_ERR(dest_page);
1869 unlock_page(src_page);
1870 put_page(src_page);
1871 goto out_error;
1872 }
1873 src_addr = kmap_atomic(src_page);
1874 dest_addr = kmap_atomic(dest_page);
1875
1876 flush_dcache_page(src_page);
1877 flush_dcache_page(dest_page);
1878
1879 if (memcmp(src_addr + src_poff, dest_addr + dest_poff, cmp_len))
1880 same = false;
1881
1882 kunmap_atomic(dest_addr);
1883 kunmap_atomic(src_addr);
1884 unlock_page(dest_page);
1885 unlock_page(src_page);
1886 put_page(dest_page);
1887 put_page(src_page);
1888
1889 if (!same)
1890 break;
1891
1892 srcoff += cmp_len;
1893 destoff += cmp_len;
1894 len -= cmp_len;
1895 }
1896
1897 *is_same = same;
1898 return 0;
1899
1900out_error:
1901 return error;
1902}
1903EXPORT_SYMBOL(vfs_dedupe_file_range_compare);
1904
54dbc151
DW
1905int vfs_dedupe_file_range(struct file *file, struct file_dedupe_range *same)
1906{
1907 struct file_dedupe_range_info *info;
1908 struct inode *src = file_inode(file);
1909 u64 off;
1910 u64 len;
1911 int i;
1912 int ret;
1913 bool is_admin = capable(CAP_SYS_ADMIN);
1914 u16 count = same->dest_count;
1915 struct file *dst_file;
1916 loff_t dst_off;
1917 ssize_t deduped;
1918
1919 if (!(file->f_mode & FMODE_READ))
1920 return -EINVAL;
1921
1922 if (same->reserved1 || same->reserved2)
1923 return -EINVAL;
1924
1925 off = same->src_offset;
1926 len = same->src_length;
1927
1928 ret = -EISDIR;
1929 if (S_ISDIR(src->i_mode))
1930 goto out;
1931
1932 ret = -EINVAL;
1933 if (!S_ISREG(src->i_mode))
1934 goto out;
1935
1936 ret = clone_verify_area(file, off, len, false);
1937 if (ret < 0)
1938 goto out;
1939 ret = 0;
1940
22725ce4
DW
1941 if (off + len > i_size_read(src))
1942 return -EINVAL;
1943
54dbc151
DW
1944 /* pre-format output fields to sane values */
1945 for (i = 0; i < count; i++) {
1946 same->info[i].bytes_deduped = 0ULL;
1947 same->info[i].status = FILE_DEDUPE_RANGE_SAME;
1948 }
1949
1950 for (i = 0, info = same->info; i < count; i++, info++) {
1951 struct inode *dst;
1952 struct fd dst_fd = fdget(info->dest_fd);
1953
1954 dst_file = dst_fd.file;
1955 if (!dst_file) {
1956 info->status = -EBADF;
1957 goto next_loop;
1958 }
1959 dst = file_inode(dst_file);
1960
1961 ret = mnt_want_write_file(dst_file);
1962 if (ret) {
1963 info->status = ret;
1964 goto next_loop;
1965 }
1966
1967 dst_off = info->dest_offset;
1968 ret = clone_verify_area(dst_file, dst_off, len, true);
1969 if (ret < 0) {
1970 info->status = ret;
1971 goto next_file;
1972 }
1973 ret = 0;
1974
1975 if (info->reserved) {
1976 info->status = -EINVAL;
1977 } else if (!(is_admin || (dst_file->f_mode & FMODE_WRITE))) {
1978 info->status = -EINVAL;
1979 } else if (file->f_path.mnt != dst_file->f_path.mnt) {
1980 info->status = -EXDEV;
1981 } else if (S_ISDIR(dst->i_mode)) {
1982 info->status = -EISDIR;
1983 } else if (dst_file->f_op->dedupe_file_range == NULL) {
1984 info->status = -EINVAL;
1985 } else {
1986 deduped = dst_file->f_op->dedupe_file_range(file, off,
1987 len, dst_file,
1988 info->dest_offset);
1989 if (deduped == -EBADE)
1990 info->status = FILE_DEDUPE_RANGE_DIFFERS;
1991 else if (deduped < 0)
1992 info->status = deduped;
1993 else
1994 info->bytes_deduped += deduped;
1995 }
1996
1997next_file:
1998 mnt_drop_write_file(dst_file);
1999next_loop:
2000 fdput(dst_fd);
e62e560f
DW
2001
2002 if (fatal_signal_pending(current))
2003 goto out;
54dbc151
DW
2004 }
2005
2006out:
2007 return ret;
2008}
2009EXPORT_SYMBOL(vfs_dedupe_file_range);