]> git.proxmox.com Git - mirror_ubuntu-zesty-kernel.git/blob - fs/compat_ioctl.c
[PATCH] BLOCK: Move the Ext3 device ioctl compat stuff to the Ext3 driver [try #6]
[mirror_ubuntu-zesty-kernel.git] / fs / compat_ioctl.c
1 /*
2 * ioctl32.c: Conversion between 32bit and 64bit native ioctls.
3 *
4 * Copyright (C) 1997-2000 Jakub Jelinek (jakub@redhat.com)
5 * Copyright (C) 1998 Eddie C. Dost (ecd@skynet.be)
6 * Copyright (C) 2001,2002 Andi Kleen, SuSE Labs
7 * Copyright (C) 2003 Pavel Machek (pavel@suse.cz)
8 *
9 * These routines maintain argument size conversion between 32bit and 64bit
10 * ioctls.
11 */
12
13 #include <linux/types.h>
14 #include <linux/compat.h>
15 #include <linux/kernel.h>
16 #include <linux/capability.h>
17 #include <linux/compiler.h>
18 #include <linux/sched.h>
19 #include <linux/smp.h>
20 #include <linux/smp_lock.h>
21 #include <linux/ioctl.h>
22 #include <linux/if.h>
23 #include <linux/if_bridge.h>
24 #include <linux/slab.h>
25 #include <linux/hdreg.h>
26 #include <linux/raid/md.h>
27 #include <linux/kd.h>
28 #include <linux/dirent.h>
29 #include <linux/route.h>
30 #include <linux/in6.h>
31 #include <linux/ipv6_route.h>
32 #include <linux/skbuff.h>
33 #include <linux/netlink.h>
34 #include <linux/vt.h>
35 #include <linux/fs.h>
36 #include <linux/file.h>
37 #include <linux/fd.h>
38 #include <linux/ppp_defs.h>
39 #include <linux/if_ppp.h>
40 #include <linux/if_pppox.h>
41 #include <linux/mtio.h>
42 #include <linux/cdrom.h>
43 #include <linux/auto_fs.h>
44 #include <linux/auto_fs4.h>
45 #include <linux/tty.h>
46 #include <linux/vt_kern.h>
47 #include <linux/fb.h>
48 #include <linux/videodev.h>
49 #include <linux/netdevice.h>
50 #include <linux/raw.h>
51 #include <linux/smb_fs.h>
52 #include <linux/blkpg.h>
53 #include <linux/blkdev.h>
54 #include <linux/elevator.h>
55 #include <linux/rtc.h>
56 #include <linux/pci.h>
57 #include <linux/module.h>
58 #include <linux/serial.h>
59 #include <linux/if_tun.h>
60 #include <linux/ctype.h>
61 #include <linux/ioctl32.h>
62 #include <linux/syscalls.h>
63 #include <linux/ncp_fs.h>
64 #include <linux/i2c.h>
65 #include <linux/i2c-dev.h>
66 #include <linux/wireless.h>
67 #include <linux/atalk.h>
68 #include <linux/blktrace_api.h>
69
70 #include <net/sock.h> /* siocdevprivate_ioctl */
71 #include <net/bluetooth/bluetooth.h>
72 #include <net/bluetooth/hci.h>
73 #include <net/bluetooth/rfcomm.h>
74
75 #include <linux/capi.h>
76 #include <linux/gigaset_dev.h>
77
78 #include <scsi/scsi.h>
79 #include <scsi/scsi_ioctl.h>
80 #include <scsi/sg.h>
81
82 #include <asm/uaccess.h>
83 #include <linux/ethtool.h>
84 #include <linux/mii.h>
85 #include <linux/if_bonding.h>
86 #include <linux/watchdog.h>
87 #include <linux/dm-ioctl.h>
88
89 #include <linux/soundcard.h>
90 #include <linux/lp.h>
91 #include <linux/ppdev.h>
92
93 #include <linux/atm.h>
94 #include <linux/atmarp.h>
95 #include <linux/atmclip.h>
96 #include <linux/atmdev.h>
97 #include <linux/atmioc.h>
98 #include <linux/atmlec.h>
99 #include <linux/atmmpc.h>
100 #include <linux/atmsvc.h>
101 #include <linux/atm_tcp.h>
102 #include <linux/sonet.h>
103 #include <linux/atm_suni.h>
104 #include <linux/mtd/mtd.h>
105
106 #include <linux/usb.h>
107 #include <linux/usbdevice_fs.h>
108 #include <linux/nbd.h>
109 #include <linux/random.h>
110 #include <linux/filter.h>
111 #include <linux/msdos_fs.h>
112 #include <linux/pktcdvd.h>
113
114 #include <linux/hiddev.h>
115
116 #include <linux/dvb/audio.h>
117 #include <linux/dvb/dmx.h>
118 #include <linux/dvb/frontend.h>
119 #include <linux/dvb/video.h>
120 #include <linux/lp.h>
121
122 static int do_ioctl32_pointer(unsigned int fd, unsigned int cmd,
123 unsigned long arg, struct file *f)
124 {
125 return sys_ioctl(fd, cmd, (unsigned long)compat_ptr(arg));
126 }
127
128 static int w_long(unsigned int fd, unsigned int cmd, unsigned long arg)
129 {
130 mm_segment_t old_fs = get_fs();
131 int err;
132 unsigned long val;
133
134 set_fs (KERNEL_DS);
135 err = sys_ioctl(fd, cmd, (unsigned long)&val);
136 set_fs (old_fs);
137 if (!err && put_user(val, (u32 __user *)compat_ptr(arg)))
138 return -EFAULT;
139 return err;
140 }
141
142 static int rw_long(unsigned int fd, unsigned int cmd, unsigned long arg)
143 {
144 mm_segment_t old_fs = get_fs();
145 u32 __user *argptr = compat_ptr(arg);
146 int err;
147 unsigned long val;
148
149 if(get_user(val, argptr))
150 return -EFAULT;
151 set_fs (KERNEL_DS);
152 err = sys_ioctl(fd, cmd, (unsigned long)&val);
153 set_fs (old_fs);
154 if (!err && put_user(val, argptr))
155 return -EFAULT;
156 return err;
157 }
158
159 struct compat_video_event {
160 int32_t type;
161 compat_time_t timestamp;
162 union {
163 video_size_t size;
164 unsigned int frame_rate;
165 } u;
166 };
167
168 static int do_video_get_event(unsigned int fd, unsigned int cmd, unsigned long arg)
169 {
170 struct video_event kevent;
171 mm_segment_t old_fs = get_fs();
172 int err;
173
174 set_fs(KERNEL_DS);
175 err = sys_ioctl(fd, cmd, (unsigned long) &kevent);
176 set_fs(old_fs);
177
178 if (!err) {
179 struct compat_video_event __user *up = compat_ptr(arg);
180
181 err = put_user(kevent.type, &up->type);
182 err |= put_user(kevent.timestamp, &up->timestamp);
183 err |= put_user(kevent.u.size.w, &up->u.size.w);
184 err |= put_user(kevent.u.size.h, &up->u.size.h);
185 err |= put_user(kevent.u.size.aspect_ratio,
186 &up->u.size.aspect_ratio);
187 if (err)
188 err = -EFAULT;
189 }
190
191 return err;
192 }
193
194 struct compat_video_still_picture {
195 compat_uptr_t iFrame;
196 int32_t size;
197 };
198
199 static int do_video_stillpicture(unsigned int fd, unsigned int cmd, unsigned long arg)
200 {
201 struct compat_video_still_picture __user *up;
202 struct video_still_picture __user *up_native;
203 compat_uptr_t fp;
204 int32_t size;
205 int err;
206
207 up = (struct compat_video_still_picture __user *) arg;
208 err = get_user(fp, &up->iFrame);
209 err |= get_user(size, &up->size);
210 if (err)
211 return -EFAULT;
212
213 up_native =
214 compat_alloc_user_space(sizeof(struct video_still_picture));
215
216 put_user(compat_ptr(fp), &up_native->iFrame);
217 put_user(size, &up_native->size);
218
219 err = sys_ioctl(fd, cmd, (unsigned long) up_native);
220
221 return err;
222 }
223
224 struct compat_video_spu_palette {
225 int length;
226 compat_uptr_t palette;
227 };
228
229 static int do_video_set_spu_palette(unsigned int fd, unsigned int cmd, unsigned long arg)
230 {
231 struct compat_video_spu_palette __user *up;
232 struct video_spu_palette __user *up_native;
233 compat_uptr_t palp;
234 int length, err;
235
236 up = (struct compat_video_spu_palette __user *) arg;
237 err = get_user(palp, &up->palette);
238 err |= get_user(length, &up->length);
239
240 up_native = compat_alloc_user_space(sizeof(struct video_spu_palette));
241 put_user(compat_ptr(palp), &up_native->palette);
242 put_user(length, &up_native->length);
243
244 err = sys_ioctl(fd, cmd, (unsigned long) up_native);
245
246 return err;
247 }
248
249 #ifdef CONFIG_NET
250 static int do_siocgstamp(unsigned int fd, unsigned int cmd, unsigned long arg)
251 {
252 struct compat_timeval __user *up = compat_ptr(arg);
253 struct timeval ktv;
254 mm_segment_t old_fs = get_fs();
255 int err;
256
257 set_fs(KERNEL_DS);
258 err = sys_ioctl(fd, cmd, (unsigned long)&ktv);
259 set_fs(old_fs);
260 if(!err) {
261 err = put_user(ktv.tv_sec, &up->tv_sec);
262 err |= __put_user(ktv.tv_usec, &up->tv_usec);
263 }
264 return err;
265 }
266
267 struct ifmap32 {
268 compat_ulong_t mem_start;
269 compat_ulong_t mem_end;
270 unsigned short base_addr;
271 unsigned char irq;
272 unsigned char dma;
273 unsigned char port;
274 };
275
276 struct ifreq32 {
277 #define IFHWADDRLEN 6
278 #define IFNAMSIZ 16
279 union {
280 char ifrn_name[IFNAMSIZ]; /* if name, e.g. "en0" */
281 } ifr_ifrn;
282 union {
283 struct sockaddr ifru_addr;
284 struct sockaddr ifru_dstaddr;
285 struct sockaddr ifru_broadaddr;
286 struct sockaddr ifru_netmask;
287 struct sockaddr ifru_hwaddr;
288 short ifru_flags;
289 compat_int_t ifru_ivalue;
290 compat_int_t ifru_mtu;
291 struct ifmap32 ifru_map;
292 char ifru_slave[IFNAMSIZ]; /* Just fits the size */
293 char ifru_newname[IFNAMSIZ];
294 compat_caddr_t ifru_data;
295 /* XXXX? ifru_settings should be here */
296 } ifr_ifru;
297 };
298
299 struct ifconf32 {
300 compat_int_t ifc_len; /* size of buffer */
301 compat_caddr_t ifcbuf;
302 };
303
304 static int dev_ifname32(unsigned int fd, unsigned int cmd, unsigned long arg)
305 {
306 struct net_device *dev;
307 struct ifreq32 ifr32;
308 int err;
309
310 if (copy_from_user(&ifr32, compat_ptr(arg), sizeof(ifr32)))
311 return -EFAULT;
312
313 dev = dev_get_by_index(ifr32.ifr_ifindex);
314 if (!dev)
315 return -ENODEV;
316
317 strlcpy(ifr32.ifr_name, dev->name, sizeof(ifr32.ifr_name));
318 dev_put(dev);
319
320 err = copy_to_user(compat_ptr(arg), &ifr32, sizeof(ifr32));
321 return (err ? -EFAULT : 0);
322 }
323
324 static int dev_ifconf(unsigned int fd, unsigned int cmd, unsigned long arg)
325 {
326 struct ifconf32 ifc32;
327 struct ifconf ifc;
328 struct ifconf __user *uifc;
329 struct ifreq32 __user *ifr32;
330 struct ifreq __user *ifr;
331 unsigned int i, j;
332 int err;
333
334 if (copy_from_user(&ifc32, compat_ptr(arg), sizeof(struct ifconf32)))
335 return -EFAULT;
336
337 if (ifc32.ifcbuf == 0) {
338 ifc32.ifc_len = 0;
339 ifc.ifc_len = 0;
340 ifc.ifc_req = NULL;
341 uifc = compat_alloc_user_space(sizeof(struct ifconf));
342 } else {
343 size_t len =((ifc32.ifc_len / sizeof (struct ifreq32)) + 1) *
344 sizeof (struct ifreq);
345 uifc = compat_alloc_user_space(sizeof(struct ifconf) + len);
346 ifc.ifc_len = len;
347 ifr = ifc.ifc_req = (void __user *)(uifc + 1);
348 ifr32 = compat_ptr(ifc32.ifcbuf);
349 for (i = 0; i < ifc32.ifc_len; i += sizeof (struct ifreq32)) {
350 if (copy_in_user(ifr, ifr32, sizeof(struct ifreq32)))
351 return -EFAULT;
352 ifr++;
353 ifr32++;
354 }
355 }
356 if (copy_to_user(uifc, &ifc, sizeof(struct ifconf)))
357 return -EFAULT;
358
359 err = sys_ioctl (fd, SIOCGIFCONF, (unsigned long)uifc);
360 if (err)
361 return err;
362
363 if (copy_from_user(&ifc, uifc, sizeof(struct ifconf)))
364 return -EFAULT;
365
366 ifr = ifc.ifc_req;
367 ifr32 = compat_ptr(ifc32.ifcbuf);
368 for (i = 0, j = 0;
369 i + sizeof (struct ifreq32) <= ifc32.ifc_len && j < ifc.ifc_len;
370 i += sizeof (struct ifreq32), j += sizeof (struct ifreq)) {
371 if (copy_in_user(ifr32, ifr, sizeof (struct ifreq32)))
372 return -EFAULT;
373 ifr32++;
374 ifr++;
375 }
376
377 if (ifc32.ifcbuf == 0) {
378 /* Translate from 64-bit structure multiple to
379 * a 32-bit one.
380 */
381 i = ifc.ifc_len;
382 i = ((i / sizeof(struct ifreq)) * sizeof(struct ifreq32));
383 ifc32.ifc_len = i;
384 } else {
385 ifc32.ifc_len = i;
386 }
387 if (copy_to_user(compat_ptr(arg), &ifc32, sizeof(struct ifconf32)))
388 return -EFAULT;
389
390 return 0;
391 }
392
393 static int ethtool_ioctl(unsigned int fd, unsigned int cmd, unsigned long arg)
394 {
395 struct ifreq __user *ifr;
396 struct ifreq32 __user *ifr32;
397 u32 data;
398 void __user *datap;
399
400 ifr = compat_alloc_user_space(sizeof(*ifr));
401 ifr32 = compat_ptr(arg);
402
403 if (copy_in_user(&ifr->ifr_name, &ifr32->ifr_name, IFNAMSIZ))
404 return -EFAULT;
405
406 if (get_user(data, &ifr32->ifr_ifru.ifru_data))
407 return -EFAULT;
408
409 datap = compat_ptr(data);
410 if (put_user(datap, &ifr->ifr_ifru.ifru_data))
411 return -EFAULT;
412
413 return sys_ioctl(fd, cmd, (unsigned long) ifr);
414 }
415
416 static int bond_ioctl(unsigned int fd, unsigned int cmd, unsigned long arg)
417 {
418 struct ifreq kifr;
419 struct ifreq __user *uifr;
420 struct ifreq32 __user *ifr32 = compat_ptr(arg);
421 mm_segment_t old_fs;
422 int err;
423 u32 data;
424 void __user *datap;
425
426 switch (cmd) {
427 case SIOCBONDENSLAVE:
428 case SIOCBONDRELEASE:
429 case SIOCBONDSETHWADDR:
430 case SIOCBONDCHANGEACTIVE:
431 if (copy_from_user(&kifr, ifr32, sizeof(struct ifreq32)))
432 return -EFAULT;
433
434 old_fs = get_fs();
435 set_fs (KERNEL_DS);
436 err = sys_ioctl (fd, cmd, (unsigned long)&kifr);
437 set_fs (old_fs);
438
439 return err;
440 case SIOCBONDSLAVEINFOQUERY:
441 case SIOCBONDINFOQUERY:
442 uifr = compat_alloc_user_space(sizeof(*uifr));
443 if (copy_in_user(&uifr->ifr_name, &ifr32->ifr_name, IFNAMSIZ))
444 return -EFAULT;
445
446 if (get_user(data, &ifr32->ifr_ifru.ifru_data))
447 return -EFAULT;
448
449 datap = compat_ptr(data);
450 if (put_user(datap, &uifr->ifr_ifru.ifru_data))
451 return -EFAULT;
452
453 return sys_ioctl (fd, cmd, (unsigned long)uifr);
454 default:
455 return -EINVAL;
456 };
457 }
458
459 int siocdevprivate_ioctl(unsigned int fd, unsigned int cmd, unsigned long arg)
460 {
461 struct ifreq __user *u_ifreq64;
462 struct ifreq32 __user *u_ifreq32 = compat_ptr(arg);
463 char tmp_buf[IFNAMSIZ];
464 void __user *data64;
465 u32 data32;
466
467 if (copy_from_user(&tmp_buf[0], &(u_ifreq32->ifr_ifrn.ifrn_name[0]),
468 IFNAMSIZ))
469 return -EFAULT;
470 if (__get_user(data32, &u_ifreq32->ifr_ifru.ifru_data))
471 return -EFAULT;
472 data64 = compat_ptr(data32);
473
474 u_ifreq64 = compat_alloc_user_space(sizeof(*u_ifreq64));
475
476 /* Don't check these user accesses, just let that get trapped
477 * in the ioctl handler instead.
478 */
479 if (copy_to_user(&u_ifreq64->ifr_ifrn.ifrn_name[0], &tmp_buf[0],
480 IFNAMSIZ))
481 return -EFAULT;
482 if (__put_user(data64, &u_ifreq64->ifr_ifru.ifru_data))
483 return -EFAULT;
484
485 return sys_ioctl(fd, cmd, (unsigned long) u_ifreq64);
486 }
487
488 static int dev_ifsioc(unsigned int fd, unsigned int cmd, unsigned long arg)
489 {
490 struct ifreq ifr;
491 struct ifreq32 __user *uifr32;
492 struct ifmap32 __user *uifmap32;
493 mm_segment_t old_fs;
494 int err;
495
496 uifr32 = compat_ptr(arg);
497 uifmap32 = &uifr32->ifr_ifru.ifru_map;
498 switch (cmd) {
499 case SIOCSIFMAP:
500 err = copy_from_user(&ifr, uifr32, sizeof(ifr.ifr_name));
501 err |= __get_user(ifr.ifr_map.mem_start, &uifmap32->mem_start);
502 err |= __get_user(ifr.ifr_map.mem_end, &uifmap32->mem_end);
503 err |= __get_user(ifr.ifr_map.base_addr, &uifmap32->base_addr);
504 err |= __get_user(ifr.ifr_map.irq, &uifmap32->irq);
505 err |= __get_user(ifr.ifr_map.dma, &uifmap32->dma);
506 err |= __get_user(ifr.ifr_map.port, &uifmap32->port);
507 if (err)
508 return -EFAULT;
509 break;
510 default:
511 if (copy_from_user(&ifr, uifr32, sizeof(*uifr32)))
512 return -EFAULT;
513 break;
514 }
515 old_fs = get_fs();
516 set_fs (KERNEL_DS);
517 err = sys_ioctl (fd, cmd, (unsigned long)&ifr);
518 set_fs (old_fs);
519 if (!err) {
520 switch (cmd) {
521 /* TUNSETIFF is defined as _IOW, it should be _IORW
522 * as the data is copied back to user space, but that
523 * cannot be fixed without breaking all existing apps.
524 */
525 case TUNSETIFF:
526 case SIOCGIFFLAGS:
527 case SIOCGIFMETRIC:
528 case SIOCGIFMTU:
529 case SIOCGIFMEM:
530 case SIOCGIFHWADDR:
531 case SIOCGIFINDEX:
532 case SIOCGIFADDR:
533 case SIOCGIFBRDADDR:
534 case SIOCGIFDSTADDR:
535 case SIOCGIFNETMASK:
536 case SIOCGIFTXQLEN:
537 if (copy_to_user(uifr32, &ifr, sizeof(*uifr32)))
538 return -EFAULT;
539 break;
540 case SIOCGIFMAP:
541 err = copy_to_user(uifr32, &ifr, sizeof(ifr.ifr_name));
542 err |= __put_user(ifr.ifr_map.mem_start, &uifmap32->mem_start);
543 err |= __put_user(ifr.ifr_map.mem_end, &uifmap32->mem_end);
544 err |= __put_user(ifr.ifr_map.base_addr, &uifmap32->base_addr);
545 err |= __put_user(ifr.ifr_map.irq, &uifmap32->irq);
546 err |= __put_user(ifr.ifr_map.dma, &uifmap32->dma);
547 err |= __put_user(ifr.ifr_map.port, &uifmap32->port);
548 if (err)
549 err = -EFAULT;
550 break;
551 }
552 }
553 return err;
554 }
555
556 struct rtentry32 {
557 u32 rt_pad1;
558 struct sockaddr rt_dst; /* target address */
559 struct sockaddr rt_gateway; /* gateway addr (RTF_GATEWAY) */
560 struct sockaddr rt_genmask; /* target network mask (IP) */
561 unsigned short rt_flags;
562 short rt_pad2;
563 u32 rt_pad3;
564 unsigned char rt_tos;
565 unsigned char rt_class;
566 short rt_pad4;
567 short rt_metric; /* +1 for binary compatibility! */
568 /* char * */ u32 rt_dev; /* forcing the device at add */
569 u32 rt_mtu; /* per route MTU/Window */
570 u32 rt_window; /* Window clamping */
571 unsigned short rt_irtt; /* Initial RTT */
572
573 };
574
575 struct in6_rtmsg32 {
576 struct in6_addr rtmsg_dst;
577 struct in6_addr rtmsg_src;
578 struct in6_addr rtmsg_gateway;
579 u32 rtmsg_type;
580 u16 rtmsg_dst_len;
581 u16 rtmsg_src_len;
582 u32 rtmsg_metric;
583 u32 rtmsg_info;
584 u32 rtmsg_flags;
585 s32 rtmsg_ifindex;
586 };
587
588 static int routing_ioctl(unsigned int fd, unsigned int cmd, unsigned long arg)
589 {
590 int ret;
591 void *r = NULL;
592 struct in6_rtmsg r6;
593 struct rtentry r4;
594 char devname[16];
595 u32 rtdev;
596 mm_segment_t old_fs = get_fs();
597
598 struct socket *mysock = sockfd_lookup(fd, &ret);
599
600 if (mysock && mysock->sk && mysock->sk->sk_family == AF_INET6) { /* ipv6 */
601 struct in6_rtmsg32 __user *ur6 = compat_ptr(arg);
602 ret = copy_from_user (&r6.rtmsg_dst, &(ur6->rtmsg_dst),
603 3 * sizeof(struct in6_addr));
604 ret |= __get_user (r6.rtmsg_type, &(ur6->rtmsg_type));
605 ret |= __get_user (r6.rtmsg_dst_len, &(ur6->rtmsg_dst_len));
606 ret |= __get_user (r6.rtmsg_src_len, &(ur6->rtmsg_src_len));
607 ret |= __get_user (r6.rtmsg_metric, &(ur6->rtmsg_metric));
608 ret |= __get_user (r6.rtmsg_info, &(ur6->rtmsg_info));
609 ret |= __get_user (r6.rtmsg_flags, &(ur6->rtmsg_flags));
610 ret |= __get_user (r6.rtmsg_ifindex, &(ur6->rtmsg_ifindex));
611
612 r = (void *) &r6;
613 } else { /* ipv4 */
614 struct rtentry32 __user *ur4 = compat_ptr(arg);
615 ret = copy_from_user (&r4.rt_dst, &(ur4->rt_dst),
616 3 * sizeof(struct sockaddr));
617 ret |= __get_user (r4.rt_flags, &(ur4->rt_flags));
618 ret |= __get_user (r4.rt_metric, &(ur4->rt_metric));
619 ret |= __get_user (r4.rt_mtu, &(ur4->rt_mtu));
620 ret |= __get_user (r4.rt_window, &(ur4->rt_window));
621 ret |= __get_user (r4.rt_irtt, &(ur4->rt_irtt));
622 ret |= __get_user (rtdev, &(ur4->rt_dev));
623 if (rtdev) {
624 ret |= copy_from_user (devname, compat_ptr(rtdev), 15);
625 r4.rt_dev = devname; devname[15] = 0;
626 } else
627 r4.rt_dev = NULL;
628
629 r = (void *) &r4;
630 }
631
632 if (ret) {
633 ret = -EFAULT;
634 goto out;
635 }
636
637 set_fs (KERNEL_DS);
638 ret = sys_ioctl (fd, cmd, (unsigned long) r);
639 set_fs (old_fs);
640
641 out:
642 if (mysock)
643 sockfd_put(mysock);
644
645 return ret;
646 }
647 #endif
648
649 struct hd_geometry32 {
650 unsigned char heads;
651 unsigned char sectors;
652 unsigned short cylinders;
653 u32 start;
654 };
655
656 static int hdio_getgeo(unsigned int fd, unsigned int cmd, unsigned long arg)
657 {
658 mm_segment_t old_fs = get_fs();
659 struct hd_geometry geo;
660 struct hd_geometry32 __user *ugeo;
661 int err;
662
663 set_fs (KERNEL_DS);
664 err = sys_ioctl(fd, HDIO_GETGEO, (unsigned long)&geo);
665 set_fs (old_fs);
666 ugeo = compat_ptr(arg);
667 if (!err) {
668 err = copy_to_user (ugeo, &geo, 4);
669 err |= __put_user (geo.start, &ugeo->start);
670 }
671 return err ? -EFAULT : 0;
672 }
673
674 static int hdio_ioctl_trans(unsigned int fd, unsigned int cmd, unsigned long arg)
675 {
676 mm_segment_t old_fs = get_fs();
677 unsigned long kval;
678 unsigned int __user *uvp;
679 int error;
680
681 set_fs(KERNEL_DS);
682 error = sys_ioctl(fd, cmd, (long)&kval);
683 set_fs(old_fs);
684
685 if(error == 0) {
686 uvp = compat_ptr(arg);
687 if(put_user(kval, uvp))
688 error = -EFAULT;
689 }
690 return error;
691 }
692
693
694 typedef struct sg_io_hdr32 {
695 compat_int_t interface_id; /* [i] 'S' for SCSI generic (required) */
696 compat_int_t dxfer_direction; /* [i] data transfer direction */
697 unsigned char cmd_len; /* [i] SCSI command length ( <= 16 bytes) */
698 unsigned char mx_sb_len; /* [i] max length to write to sbp */
699 unsigned short iovec_count; /* [i] 0 implies no scatter gather */
700 compat_uint_t dxfer_len; /* [i] byte count of data transfer */
701 compat_uint_t dxferp; /* [i], [*io] points to data transfer memory
702 or scatter gather list */
703 compat_uptr_t cmdp; /* [i], [*i] points to command to perform */
704 compat_uptr_t sbp; /* [i], [*o] points to sense_buffer memory */
705 compat_uint_t timeout; /* [i] MAX_UINT->no timeout (unit: millisec) */
706 compat_uint_t flags; /* [i] 0 -> default, see SG_FLAG... */
707 compat_int_t pack_id; /* [i->o] unused internally (normally) */
708 compat_uptr_t usr_ptr; /* [i->o] unused internally */
709 unsigned char status; /* [o] scsi status */
710 unsigned char masked_status; /* [o] shifted, masked scsi status */
711 unsigned char msg_status; /* [o] messaging level data (optional) */
712 unsigned char sb_len_wr; /* [o] byte count actually written to sbp */
713 unsigned short host_status; /* [o] errors from host adapter */
714 unsigned short driver_status; /* [o] errors from software driver */
715 compat_int_t resid; /* [o] dxfer_len - actual_transferred */
716 compat_uint_t duration; /* [o] time taken by cmd (unit: millisec) */
717 compat_uint_t info; /* [o] auxiliary information */
718 } sg_io_hdr32_t; /* 64 bytes long (on sparc32) */
719
720 typedef struct sg_iovec32 {
721 compat_uint_t iov_base;
722 compat_uint_t iov_len;
723 } sg_iovec32_t;
724
725 static int sg_build_iovec(sg_io_hdr_t __user *sgio, void __user *dxferp, u16 iovec_count)
726 {
727 sg_iovec_t __user *iov = (sg_iovec_t __user *) (sgio + 1);
728 sg_iovec32_t __user *iov32 = dxferp;
729 int i;
730
731 for (i = 0; i < iovec_count; i++) {
732 u32 base, len;
733
734 if (get_user(base, &iov32[i].iov_base) ||
735 get_user(len, &iov32[i].iov_len) ||
736 put_user(compat_ptr(base), &iov[i].iov_base) ||
737 put_user(len, &iov[i].iov_len))
738 return -EFAULT;
739 }
740
741 if (put_user(iov, &sgio->dxferp))
742 return -EFAULT;
743 return 0;
744 }
745
746 static int sg_ioctl_trans(unsigned int fd, unsigned int cmd, unsigned long arg)
747 {
748 sg_io_hdr_t __user *sgio;
749 sg_io_hdr32_t __user *sgio32;
750 u16 iovec_count;
751 u32 data;
752 void __user *dxferp;
753 int err;
754
755 sgio32 = compat_ptr(arg);
756 if (get_user(iovec_count, &sgio32->iovec_count))
757 return -EFAULT;
758
759 {
760 void __user *top = compat_alloc_user_space(0);
761 void __user *new = compat_alloc_user_space(sizeof(sg_io_hdr_t) +
762 (iovec_count * sizeof(sg_iovec_t)));
763 if (new > top)
764 return -EINVAL;
765
766 sgio = new;
767 }
768
769 /* Ok, now construct. */
770 if (copy_in_user(&sgio->interface_id, &sgio32->interface_id,
771 (2 * sizeof(int)) +
772 (2 * sizeof(unsigned char)) +
773 (1 * sizeof(unsigned short)) +
774 (1 * sizeof(unsigned int))))
775 return -EFAULT;
776
777 if (get_user(data, &sgio32->dxferp))
778 return -EFAULT;
779 dxferp = compat_ptr(data);
780 if (iovec_count) {
781 if (sg_build_iovec(sgio, dxferp, iovec_count))
782 return -EFAULT;
783 } else {
784 if (put_user(dxferp, &sgio->dxferp))
785 return -EFAULT;
786 }
787
788 {
789 unsigned char __user *cmdp;
790 unsigned char __user *sbp;
791
792 if (get_user(data, &sgio32->cmdp))
793 return -EFAULT;
794 cmdp = compat_ptr(data);
795
796 if (get_user(data, &sgio32->sbp))
797 return -EFAULT;
798 sbp = compat_ptr(data);
799
800 if (put_user(cmdp, &sgio->cmdp) ||
801 put_user(sbp, &sgio->sbp))
802 return -EFAULT;
803 }
804
805 if (copy_in_user(&sgio->timeout, &sgio32->timeout,
806 3 * sizeof(int)))
807 return -EFAULT;
808
809 if (get_user(data, &sgio32->usr_ptr))
810 return -EFAULT;
811 if (put_user(compat_ptr(data), &sgio->usr_ptr))
812 return -EFAULT;
813
814 if (copy_in_user(&sgio->status, &sgio32->status,
815 (4 * sizeof(unsigned char)) +
816 (2 * sizeof(unsigned (short))) +
817 (3 * sizeof(int))))
818 return -EFAULT;
819
820 err = sys_ioctl(fd, cmd, (unsigned long) sgio);
821
822 if (err >= 0) {
823 void __user *datap;
824
825 if (copy_in_user(&sgio32->pack_id, &sgio->pack_id,
826 sizeof(int)) ||
827 get_user(datap, &sgio->usr_ptr) ||
828 put_user((u32)(unsigned long)datap,
829 &sgio32->usr_ptr) ||
830 copy_in_user(&sgio32->status, &sgio->status,
831 (4 * sizeof(unsigned char)) +
832 (2 * sizeof(unsigned short)) +
833 (3 * sizeof(int))))
834 err = -EFAULT;
835 }
836
837 return err;
838 }
839
840 struct compat_sg_req_info { /* used by SG_GET_REQUEST_TABLE ioctl() */
841 char req_state;
842 char orphan;
843 char sg_io_owned;
844 char problem;
845 int pack_id;
846 compat_uptr_t usr_ptr;
847 unsigned int duration;
848 int unused;
849 };
850
851 static int sg_grt_trans(unsigned int fd, unsigned int cmd, unsigned long arg)
852 {
853 int err, i;
854 sg_req_info_t __user *r;
855 struct compat_sg_req_info __user *o = (void __user *)arg;
856 r = compat_alloc_user_space(sizeof(sg_req_info_t)*SG_MAX_QUEUE);
857 err = sys_ioctl(fd,cmd,(unsigned long)r);
858 if (err < 0)
859 return err;
860 for (i = 0; i < SG_MAX_QUEUE; i++) {
861 void __user *ptr;
862 int d;
863
864 if (copy_in_user(o + i, r + i, offsetof(sg_req_info_t, usr_ptr)) ||
865 get_user(ptr, &r[i].usr_ptr) ||
866 get_user(d, &r[i].duration) ||
867 put_user((u32)(unsigned long)(ptr), &o[i].usr_ptr) ||
868 put_user(d, &o[i].duration))
869 return -EFAULT;
870 }
871 return err;
872 }
873
874 struct sock_fprog32 {
875 unsigned short len;
876 compat_caddr_t filter;
877 };
878
879 #define PPPIOCSPASS32 _IOW('t', 71, struct sock_fprog32)
880 #define PPPIOCSACTIVE32 _IOW('t', 70, struct sock_fprog32)
881
882 static int ppp_sock_fprog_ioctl_trans(unsigned int fd, unsigned int cmd, unsigned long arg)
883 {
884 struct sock_fprog32 __user *u_fprog32 = compat_ptr(arg);
885 struct sock_fprog __user *u_fprog64 = compat_alloc_user_space(sizeof(struct sock_fprog));
886 void __user *fptr64;
887 u32 fptr32;
888 u16 flen;
889
890 if (get_user(flen, &u_fprog32->len) ||
891 get_user(fptr32, &u_fprog32->filter))
892 return -EFAULT;
893
894 fptr64 = compat_ptr(fptr32);
895
896 if (put_user(flen, &u_fprog64->len) ||
897 put_user(fptr64, &u_fprog64->filter))
898 return -EFAULT;
899
900 if (cmd == PPPIOCSPASS32)
901 cmd = PPPIOCSPASS;
902 else
903 cmd = PPPIOCSACTIVE;
904
905 return sys_ioctl(fd, cmd, (unsigned long) u_fprog64);
906 }
907
908 struct ppp_option_data32 {
909 compat_caddr_t ptr;
910 u32 length;
911 compat_int_t transmit;
912 };
913 #define PPPIOCSCOMPRESS32 _IOW('t', 77, struct ppp_option_data32)
914
915 struct ppp_idle32 {
916 compat_time_t xmit_idle;
917 compat_time_t recv_idle;
918 };
919 #define PPPIOCGIDLE32 _IOR('t', 63, struct ppp_idle32)
920
921 static int ppp_gidle(unsigned int fd, unsigned int cmd, unsigned long arg)
922 {
923 struct ppp_idle __user *idle;
924 struct ppp_idle32 __user *idle32;
925 __kernel_time_t xmit, recv;
926 int err;
927
928 idle = compat_alloc_user_space(sizeof(*idle));
929 idle32 = compat_ptr(arg);
930
931 err = sys_ioctl(fd, PPPIOCGIDLE, (unsigned long) idle);
932
933 if (!err) {
934 if (get_user(xmit, &idle->xmit_idle) ||
935 get_user(recv, &idle->recv_idle) ||
936 put_user(xmit, &idle32->xmit_idle) ||
937 put_user(recv, &idle32->recv_idle))
938 err = -EFAULT;
939 }
940 return err;
941 }
942
943 static int ppp_scompress(unsigned int fd, unsigned int cmd, unsigned long arg)
944 {
945 struct ppp_option_data __user *odata;
946 struct ppp_option_data32 __user *odata32;
947 __u32 data;
948 void __user *datap;
949
950 odata = compat_alloc_user_space(sizeof(*odata));
951 odata32 = compat_ptr(arg);
952
953 if (get_user(data, &odata32->ptr))
954 return -EFAULT;
955
956 datap = compat_ptr(data);
957 if (put_user(datap, &odata->ptr))
958 return -EFAULT;
959
960 if (copy_in_user(&odata->length, &odata32->length,
961 sizeof(__u32) + sizeof(int)))
962 return -EFAULT;
963
964 return sys_ioctl(fd, PPPIOCSCOMPRESS, (unsigned long) odata);
965 }
966
967 static int ppp_ioctl_trans(unsigned int fd, unsigned int cmd, unsigned long arg)
968 {
969 int err;
970
971 switch (cmd) {
972 case PPPIOCGIDLE32:
973 err = ppp_gidle(fd, cmd, arg);
974 break;
975
976 case PPPIOCSCOMPRESS32:
977 err = ppp_scompress(fd, cmd, arg);
978 break;
979
980 default:
981 do {
982 static int count;
983 if (++count <= 20)
984 printk("ppp_ioctl: Unknown cmd fd(%d) "
985 "cmd(%08x) arg(%08x)\n",
986 (int)fd, (unsigned int)cmd, (unsigned int)arg);
987 } while(0);
988 err = -EINVAL;
989 break;
990 };
991
992 return err;
993 }
994
995
996 struct mtget32 {
997 compat_long_t mt_type;
998 compat_long_t mt_resid;
999 compat_long_t mt_dsreg;
1000 compat_long_t mt_gstat;
1001 compat_long_t mt_erreg;
1002 compat_daddr_t mt_fileno;
1003 compat_daddr_t mt_blkno;
1004 };
1005 #define MTIOCGET32 _IOR('m', 2, struct mtget32)
1006
1007 struct mtpos32 {
1008 compat_long_t mt_blkno;
1009 };
1010 #define MTIOCPOS32 _IOR('m', 3, struct mtpos32)
1011
1012 static int mt_ioctl_trans(unsigned int fd, unsigned int cmd, unsigned long arg)
1013 {
1014 mm_segment_t old_fs = get_fs();
1015 struct mtget get;
1016 struct mtget32 __user *umget32;
1017 struct mtpos pos;
1018 struct mtpos32 __user *upos32;
1019 unsigned long kcmd;
1020 void *karg;
1021 int err = 0;
1022
1023 switch(cmd) {
1024 case MTIOCPOS32:
1025 kcmd = MTIOCPOS;
1026 karg = &pos;
1027 break;
1028 case MTIOCGET32:
1029 kcmd = MTIOCGET;
1030 karg = &get;
1031 break;
1032 default:
1033 do {
1034 static int count;
1035 if (++count <= 20)
1036 printk("mt_ioctl: Unknown cmd fd(%d) "
1037 "cmd(%08x) arg(%08x)\n",
1038 (int)fd, (unsigned int)cmd, (unsigned int)arg);
1039 } while(0);
1040 return -EINVAL;
1041 }
1042 set_fs (KERNEL_DS);
1043 err = sys_ioctl (fd, kcmd, (unsigned long)karg);
1044 set_fs (old_fs);
1045 if (err)
1046 return err;
1047 switch (cmd) {
1048 case MTIOCPOS32:
1049 upos32 = compat_ptr(arg);
1050 err = __put_user(pos.mt_blkno, &upos32->mt_blkno);
1051 break;
1052 case MTIOCGET32:
1053 umget32 = compat_ptr(arg);
1054 err = __put_user(get.mt_type, &umget32->mt_type);
1055 err |= __put_user(get.mt_resid, &umget32->mt_resid);
1056 err |= __put_user(get.mt_dsreg, &umget32->mt_dsreg);
1057 err |= __put_user(get.mt_gstat, &umget32->mt_gstat);
1058 err |= __put_user(get.mt_erreg, &umget32->mt_erreg);
1059 err |= __put_user(get.mt_fileno, &umget32->mt_fileno);
1060 err |= __put_user(get.mt_blkno, &umget32->mt_blkno);
1061 break;
1062 }
1063 return err ? -EFAULT: 0;
1064 }
1065
1066 struct cdrom_read_audio32 {
1067 union cdrom_addr addr;
1068 u8 addr_format;
1069 compat_int_t nframes;
1070 compat_caddr_t buf;
1071 };
1072
1073 struct cdrom_generic_command32 {
1074 unsigned char cmd[CDROM_PACKET_SIZE];
1075 compat_caddr_t buffer;
1076 compat_uint_t buflen;
1077 compat_int_t stat;
1078 compat_caddr_t sense;
1079 unsigned char data_direction;
1080 compat_int_t quiet;
1081 compat_int_t timeout;
1082 compat_caddr_t reserved[1];
1083 };
1084
1085 static int cdrom_do_read_audio(unsigned int fd, unsigned int cmd, unsigned long arg)
1086 {
1087 struct cdrom_read_audio __user *cdread_audio;
1088 struct cdrom_read_audio32 __user *cdread_audio32;
1089 __u32 data;
1090 void __user *datap;
1091
1092 cdread_audio = compat_alloc_user_space(sizeof(*cdread_audio));
1093 cdread_audio32 = compat_ptr(arg);
1094
1095 if (copy_in_user(&cdread_audio->addr,
1096 &cdread_audio32->addr,
1097 (sizeof(*cdread_audio32) -
1098 sizeof(compat_caddr_t))))
1099 return -EFAULT;
1100
1101 if (get_user(data, &cdread_audio32->buf))
1102 return -EFAULT;
1103 datap = compat_ptr(data);
1104 if (put_user(datap, &cdread_audio->buf))
1105 return -EFAULT;
1106
1107 return sys_ioctl(fd, cmd, (unsigned long) cdread_audio);
1108 }
1109
1110 static int cdrom_do_generic_command(unsigned int fd, unsigned int cmd, unsigned long arg)
1111 {
1112 struct cdrom_generic_command __user *cgc;
1113 struct cdrom_generic_command32 __user *cgc32;
1114 u32 data;
1115 unsigned char dir;
1116 int itmp;
1117
1118 cgc = compat_alloc_user_space(sizeof(*cgc));
1119 cgc32 = compat_ptr(arg);
1120
1121 if (copy_in_user(&cgc->cmd, &cgc32->cmd, sizeof(cgc->cmd)) ||
1122 get_user(data, &cgc32->buffer) ||
1123 put_user(compat_ptr(data), &cgc->buffer) ||
1124 copy_in_user(&cgc->buflen, &cgc32->buflen,
1125 (sizeof(unsigned int) + sizeof(int))) ||
1126 get_user(data, &cgc32->sense) ||
1127 put_user(compat_ptr(data), &cgc->sense) ||
1128 get_user(dir, &cgc32->data_direction) ||
1129 put_user(dir, &cgc->data_direction) ||
1130 get_user(itmp, &cgc32->quiet) ||
1131 put_user(itmp, &cgc->quiet) ||
1132 get_user(itmp, &cgc32->timeout) ||
1133 put_user(itmp, &cgc->timeout) ||
1134 get_user(data, &cgc32->reserved[0]) ||
1135 put_user(compat_ptr(data), &cgc->reserved[0]))
1136 return -EFAULT;
1137
1138 return sys_ioctl(fd, cmd, (unsigned long) cgc);
1139 }
1140
1141 static int cdrom_ioctl_trans(unsigned int fd, unsigned int cmd, unsigned long arg)
1142 {
1143 int err;
1144
1145 switch(cmd) {
1146 case CDROMREADAUDIO:
1147 err = cdrom_do_read_audio(fd, cmd, arg);
1148 break;
1149
1150 case CDROM_SEND_PACKET:
1151 err = cdrom_do_generic_command(fd, cmd, arg);
1152 break;
1153
1154 default:
1155 do {
1156 static int count;
1157 if (++count <= 20)
1158 printk("cdrom_ioctl: Unknown cmd fd(%d) "
1159 "cmd(%08x) arg(%08x)\n",
1160 (int)fd, (unsigned int)cmd, (unsigned int)arg);
1161 } while(0);
1162 err = -EINVAL;
1163 break;
1164 };
1165
1166 return err;
1167 }
1168
1169 #ifdef CONFIG_VT
1170
1171 static int vt_check(struct file *file)
1172 {
1173 struct tty_struct *tty;
1174 struct inode *inode = file->f_dentry->d_inode;
1175
1176 if (file->f_op->ioctl != tty_ioctl)
1177 return -EINVAL;
1178
1179 tty = (struct tty_struct *)file->private_data;
1180 if (tty_paranoia_check(tty, inode, "tty_ioctl"))
1181 return -EINVAL;
1182
1183 if (tty->driver->ioctl != vt_ioctl)
1184 return -EINVAL;
1185
1186 /*
1187 * To have permissions to do most of the vt ioctls, we either have
1188 * to be the owner of the tty, or super-user.
1189 */
1190 if (current->signal->tty == tty || capable(CAP_SYS_ADMIN))
1191 return 1;
1192 return 0;
1193 }
1194
1195 struct consolefontdesc32 {
1196 unsigned short charcount; /* characters in font (256 or 512) */
1197 unsigned short charheight; /* scan lines per character (1-32) */
1198 compat_caddr_t chardata; /* font data in expanded form */
1199 };
1200
1201 static int do_fontx_ioctl(unsigned int fd, unsigned int cmd, unsigned long arg, struct file *file)
1202 {
1203 struct consolefontdesc32 __user *user_cfd = compat_ptr(arg);
1204 struct console_font_op op;
1205 compat_caddr_t data;
1206 int i, perm;
1207
1208 perm = vt_check(file);
1209 if (perm < 0) return perm;
1210
1211 switch (cmd) {
1212 case PIO_FONTX:
1213 if (!perm)
1214 return -EPERM;
1215 op.op = KD_FONT_OP_SET;
1216 op.flags = 0;
1217 op.width = 8;
1218 if (get_user(op.height, &user_cfd->charheight) ||
1219 get_user(op.charcount, &user_cfd->charcount) ||
1220 get_user(data, &user_cfd->chardata))
1221 return -EFAULT;
1222 op.data = compat_ptr(data);
1223 return con_font_op(vc_cons[fg_console].d, &op);
1224 case GIO_FONTX:
1225 op.op = KD_FONT_OP_GET;
1226 op.flags = 0;
1227 op.width = 8;
1228 if (get_user(op.height, &user_cfd->charheight) ||
1229 get_user(op.charcount, &user_cfd->charcount) ||
1230 get_user(data, &user_cfd->chardata))
1231 return -EFAULT;
1232 if (!data)
1233 return 0;
1234 op.data = compat_ptr(data);
1235 i = con_font_op(vc_cons[fg_console].d, &op);
1236 if (i)
1237 return i;
1238 if (put_user(op.height, &user_cfd->charheight) ||
1239 put_user(op.charcount, &user_cfd->charcount) ||
1240 put_user((compat_caddr_t)(unsigned long)op.data,
1241 &user_cfd->chardata))
1242 return -EFAULT;
1243 return 0;
1244 }
1245 return -EINVAL;
1246 }
1247
1248 struct console_font_op32 {
1249 compat_uint_t op; /* operation code KD_FONT_OP_* */
1250 compat_uint_t flags; /* KD_FONT_FLAG_* */
1251 compat_uint_t width, height; /* font size */
1252 compat_uint_t charcount;
1253 compat_caddr_t data; /* font data with height fixed to 32 */
1254 };
1255
1256 static int do_kdfontop_ioctl(unsigned int fd, unsigned int cmd, unsigned long arg, struct file *file)
1257 {
1258 struct console_font_op op;
1259 struct console_font_op32 __user *fontop = compat_ptr(arg);
1260 int perm = vt_check(file), i;
1261 struct vc_data *vc;
1262
1263 if (perm < 0) return perm;
1264
1265 if (copy_from_user(&op, fontop, sizeof(struct console_font_op32)))
1266 return -EFAULT;
1267 if (!perm && op.op != KD_FONT_OP_GET)
1268 return -EPERM;
1269 op.data = compat_ptr(((struct console_font_op32 *)&op)->data);
1270 op.flags |= KD_FONT_FLAG_OLD;
1271 vc = ((struct tty_struct *)file->private_data)->driver_data;
1272 i = con_font_op(vc, &op);
1273 if (i)
1274 return i;
1275 ((struct console_font_op32 *)&op)->data = (unsigned long)op.data;
1276 if (copy_to_user(fontop, &op, sizeof(struct console_font_op32)))
1277 return -EFAULT;
1278 return 0;
1279 }
1280
1281 struct unimapdesc32 {
1282 unsigned short entry_ct;
1283 compat_caddr_t entries;
1284 };
1285
1286 static int do_unimap_ioctl(unsigned int fd, unsigned int cmd, unsigned long arg, struct file *file)
1287 {
1288 struct unimapdesc32 tmp;
1289 struct unimapdesc32 __user *user_ud = compat_ptr(arg);
1290 int perm = vt_check(file);
1291
1292 if (perm < 0) return perm;
1293 if (copy_from_user(&tmp, user_ud, sizeof tmp))
1294 return -EFAULT;
1295 switch (cmd) {
1296 case PIO_UNIMAP:
1297 if (!perm) return -EPERM;
1298 return con_set_unimap(vc_cons[fg_console].d, tmp.entry_ct, compat_ptr(tmp.entries));
1299 case GIO_UNIMAP:
1300 return con_get_unimap(vc_cons[fg_console].d, tmp.entry_ct, &(user_ud->entry_ct), compat_ptr(tmp.entries));
1301 }
1302 return 0;
1303 }
1304
1305 #endif /* CONFIG_VT */
1306
1307 static int do_smb_getmountuid(unsigned int fd, unsigned int cmd, unsigned long arg)
1308 {
1309 mm_segment_t old_fs = get_fs();
1310 __kernel_uid_t kuid;
1311 int err;
1312
1313 cmd = SMB_IOC_GETMOUNTUID;
1314
1315 set_fs(KERNEL_DS);
1316 err = sys_ioctl(fd, cmd, (unsigned long)&kuid);
1317 set_fs(old_fs);
1318
1319 if (err >= 0)
1320 err = put_user(kuid, (compat_uid_t __user *)compat_ptr(arg));
1321
1322 return err;
1323 }
1324
1325 struct atmif_sioc32 {
1326 compat_int_t number;
1327 compat_int_t length;
1328 compat_caddr_t arg;
1329 };
1330
1331 struct atm_iobuf32 {
1332 compat_int_t length;
1333 compat_caddr_t buffer;
1334 };
1335
1336 #define ATM_GETLINKRATE32 _IOW('a', ATMIOC_ITF+1, struct atmif_sioc32)
1337 #define ATM_GETNAMES32 _IOW('a', ATMIOC_ITF+3, struct atm_iobuf32)
1338 #define ATM_GETTYPE32 _IOW('a', ATMIOC_ITF+4, struct atmif_sioc32)
1339 #define ATM_GETESI32 _IOW('a', ATMIOC_ITF+5, struct atmif_sioc32)
1340 #define ATM_GETADDR32 _IOW('a', ATMIOC_ITF+6, struct atmif_sioc32)
1341 #define ATM_RSTADDR32 _IOW('a', ATMIOC_ITF+7, struct atmif_sioc32)
1342 #define ATM_ADDADDR32 _IOW('a', ATMIOC_ITF+8, struct atmif_sioc32)
1343 #define ATM_DELADDR32 _IOW('a', ATMIOC_ITF+9, struct atmif_sioc32)
1344 #define ATM_GETCIRANGE32 _IOW('a', ATMIOC_ITF+10, struct atmif_sioc32)
1345 #define ATM_SETCIRANGE32 _IOW('a', ATMIOC_ITF+11, struct atmif_sioc32)
1346 #define ATM_SETESI32 _IOW('a', ATMIOC_ITF+12, struct atmif_sioc32)
1347 #define ATM_SETESIF32 _IOW('a', ATMIOC_ITF+13, struct atmif_sioc32)
1348 #define ATM_GETSTAT32 _IOW('a', ATMIOC_SARCOM+0, struct atmif_sioc32)
1349 #define ATM_GETSTATZ32 _IOW('a', ATMIOC_SARCOM+1, struct atmif_sioc32)
1350 #define ATM_GETLOOP32 _IOW('a', ATMIOC_SARCOM+2, struct atmif_sioc32)
1351 #define ATM_SETLOOP32 _IOW('a', ATMIOC_SARCOM+3, struct atmif_sioc32)
1352 #define ATM_QUERYLOOP32 _IOW('a', ATMIOC_SARCOM+4, struct atmif_sioc32)
1353
1354 static struct {
1355 unsigned int cmd32;
1356 unsigned int cmd;
1357 } atm_ioctl_map[] = {
1358 { ATM_GETLINKRATE32, ATM_GETLINKRATE },
1359 { ATM_GETNAMES32, ATM_GETNAMES },
1360 { ATM_GETTYPE32, ATM_GETTYPE },
1361 { ATM_GETESI32, ATM_GETESI },
1362 { ATM_GETADDR32, ATM_GETADDR },
1363 { ATM_RSTADDR32, ATM_RSTADDR },
1364 { ATM_ADDADDR32, ATM_ADDADDR },
1365 { ATM_DELADDR32, ATM_DELADDR },
1366 { ATM_GETCIRANGE32, ATM_GETCIRANGE },
1367 { ATM_SETCIRANGE32, ATM_SETCIRANGE },
1368 { ATM_SETESI32, ATM_SETESI },
1369 { ATM_SETESIF32, ATM_SETESIF },
1370 { ATM_GETSTAT32, ATM_GETSTAT },
1371 { ATM_GETSTATZ32, ATM_GETSTATZ },
1372 { ATM_GETLOOP32, ATM_GETLOOP },
1373 { ATM_SETLOOP32, ATM_SETLOOP },
1374 { ATM_QUERYLOOP32, ATM_QUERYLOOP }
1375 };
1376
1377 #define NR_ATM_IOCTL ARRAY_SIZE(atm_ioctl_map)
1378
1379 static int do_atm_iobuf(unsigned int fd, unsigned int cmd, unsigned long arg)
1380 {
1381 struct atm_iobuf __user *iobuf;
1382 struct atm_iobuf32 __user *iobuf32;
1383 u32 data;
1384 void __user *datap;
1385 int len, err;
1386
1387 iobuf = compat_alloc_user_space(sizeof(*iobuf));
1388 iobuf32 = compat_ptr(arg);
1389
1390 if (get_user(len, &iobuf32->length) ||
1391 get_user(data, &iobuf32->buffer))
1392 return -EFAULT;
1393 datap = compat_ptr(data);
1394 if (put_user(len, &iobuf->length) ||
1395 put_user(datap, &iobuf->buffer))
1396 return -EFAULT;
1397
1398 err = sys_ioctl(fd, cmd, (unsigned long)iobuf);
1399
1400 if (!err) {
1401 if (copy_in_user(&iobuf32->length, &iobuf->length,
1402 sizeof(int)))
1403 err = -EFAULT;
1404 }
1405
1406 return err;
1407 }
1408
1409 static int do_atmif_sioc(unsigned int fd, unsigned int cmd, unsigned long arg)
1410 {
1411 struct atmif_sioc __user *sioc;
1412 struct atmif_sioc32 __user *sioc32;
1413 u32 data;
1414 void __user *datap;
1415 int err;
1416
1417 sioc = compat_alloc_user_space(sizeof(*sioc));
1418 sioc32 = compat_ptr(arg);
1419
1420 if (copy_in_user(&sioc->number, &sioc32->number, 2 * sizeof(int)) ||
1421 get_user(data, &sioc32->arg))
1422 return -EFAULT;
1423 datap = compat_ptr(data);
1424 if (put_user(datap, &sioc->arg))
1425 return -EFAULT;
1426
1427 err = sys_ioctl(fd, cmd, (unsigned long) sioc);
1428
1429 if (!err) {
1430 if (copy_in_user(&sioc32->length, &sioc->length,
1431 sizeof(int)))
1432 err = -EFAULT;
1433 }
1434 return err;
1435 }
1436
1437 static int do_atm_ioctl(unsigned int fd, unsigned int cmd32, unsigned long arg)
1438 {
1439 int i;
1440 unsigned int cmd = 0;
1441
1442 switch (cmd32) {
1443 case SONET_GETSTAT:
1444 case SONET_GETSTATZ:
1445 case SONET_GETDIAG:
1446 case SONET_SETDIAG:
1447 case SONET_CLRDIAG:
1448 case SONET_SETFRAMING:
1449 case SONET_GETFRAMING:
1450 case SONET_GETFRSENSE:
1451 return do_atmif_sioc(fd, cmd32, arg);
1452 }
1453
1454 for (i = 0; i < NR_ATM_IOCTL; i++) {
1455 if (cmd32 == atm_ioctl_map[i].cmd32) {
1456 cmd = atm_ioctl_map[i].cmd;
1457 break;
1458 }
1459 }
1460 if (i == NR_ATM_IOCTL)
1461 return -EINVAL;
1462
1463 switch (cmd) {
1464 case ATM_GETNAMES:
1465 return do_atm_iobuf(fd, cmd, arg);
1466
1467 case ATM_GETLINKRATE:
1468 case ATM_GETTYPE:
1469 case ATM_GETESI:
1470 case ATM_GETADDR:
1471 case ATM_RSTADDR:
1472 case ATM_ADDADDR:
1473 case ATM_DELADDR:
1474 case ATM_GETCIRANGE:
1475 case ATM_SETCIRANGE:
1476 case ATM_SETESI:
1477 case ATM_SETESIF:
1478 case ATM_GETSTAT:
1479 case ATM_GETSTATZ:
1480 case ATM_GETLOOP:
1481 case ATM_SETLOOP:
1482 case ATM_QUERYLOOP:
1483 return do_atmif_sioc(fd, cmd, arg);
1484 }
1485
1486 return -EINVAL;
1487 }
1488
1489 static __attribute_used__ int
1490 ret_einval(unsigned int fd, unsigned int cmd, unsigned long arg)
1491 {
1492 return -EINVAL;
1493 }
1494
1495 static int broken_blkgetsize(unsigned int fd, unsigned int cmd, unsigned long arg)
1496 {
1497 /* The mkswap binary hard codes it to Intel value :-((( */
1498 return w_long(fd, BLKGETSIZE, arg);
1499 }
1500
1501 struct blkpg_ioctl_arg32 {
1502 compat_int_t op;
1503 compat_int_t flags;
1504 compat_int_t datalen;
1505 compat_caddr_t data;
1506 };
1507
1508 static int blkpg_ioctl_trans(unsigned int fd, unsigned int cmd, unsigned long arg)
1509 {
1510 struct blkpg_ioctl_arg32 __user *ua32 = compat_ptr(arg);
1511 struct blkpg_ioctl_arg __user *a = compat_alloc_user_space(sizeof(*a));
1512 compat_caddr_t udata;
1513 compat_int_t n;
1514 int err;
1515
1516 err = get_user(n, &ua32->op);
1517 err |= put_user(n, &a->op);
1518 err |= get_user(n, &ua32->flags);
1519 err |= put_user(n, &a->flags);
1520 err |= get_user(n, &ua32->datalen);
1521 err |= put_user(n, &a->datalen);
1522 err |= get_user(udata, &ua32->data);
1523 err |= put_user(compat_ptr(udata), &a->data);
1524 if (err)
1525 return err;
1526
1527 return sys_ioctl(fd, cmd, (unsigned long)a);
1528 }
1529
1530 static int ioc_settimeout(unsigned int fd, unsigned int cmd, unsigned long arg)
1531 {
1532 return rw_long(fd, AUTOFS_IOC_SETTIMEOUT, arg);
1533 }
1534
1535 /* Fix sizeof(sizeof()) breakage */
1536 #define BLKBSZGET_32 _IOR(0x12,112,int)
1537 #define BLKBSZSET_32 _IOW(0x12,113,int)
1538 #define BLKGETSIZE64_32 _IOR(0x12,114,int)
1539
1540 static int do_blkbszget(unsigned int fd, unsigned int cmd, unsigned long arg)
1541 {
1542 return sys_ioctl(fd, BLKBSZGET, (unsigned long)compat_ptr(arg));
1543 }
1544
1545 static int do_blkbszset(unsigned int fd, unsigned int cmd, unsigned long arg)
1546 {
1547 return sys_ioctl(fd, BLKBSZSET, (unsigned long)compat_ptr(arg));
1548 }
1549
1550 static int do_blkgetsize64(unsigned int fd, unsigned int cmd,
1551 unsigned long arg)
1552 {
1553 return sys_ioctl(fd, BLKGETSIZE64, (unsigned long)compat_ptr(arg));
1554 }
1555
1556 /* Bluetooth ioctls */
1557 #define HCIUARTSETPROTO _IOW('U', 200, int)
1558 #define HCIUARTGETPROTO _IOR('U', 201, int)
1559
1560 #define BNEPCONNADD _IOW('B', 200, int)
1561 #define BNEPCONNDEL _IOW('B', 201, int)
1562 #define BNEPGETCONNLIST _IOR('B', 210, int)
1563 #define BNEPGETCONNINFO _IOR('B', 211, int)
1564
1565 #define CMTPCONNADD _IOW('C', 200, int)
1566 #define CMTPCONNDEL _IOW('C', 201, int)
1567 #define CMTPGETCONNLIST _IOR('C', 210, int)
1568 #define CMTPGETCONNINFO _IOR('C', 211, int)
1569
1570 #define HIDPCONNADD _IOW('H', 200, int)
1571 #define HIDPCONNDEL _IOW('H', 201, int)
1572 #define HIDPGETCONNLIST _IOR('H', 210, int)
1573 #define HIDPGETCONNINFO _IOR('H', 211, int)
1574
1575 struct floppy_struct32 {
1576 compat_uint_t size;
1577 compat_uint_t sect;
1578 compat_uint_t head;
1579 compat_uint_t track;
1580 compat_uint_t stretch;
1581 unsigned char gap;
1582 unsigned char rate;
1583 unsigned char spec1;
1584 unsigned char fmt_gap;
1585 const compat_caddr_t name;
1586 };
1587
1588 struct floppy_drive_params32 {
1589 char cmos;
1590 compat_ulong_t max_dtr;
1591 compat_ulong_t hlt;
1592 compat_ulong_t hut;
1593 compat_ulong_t srt;
1594 compat_ulong_t spinup;
1595 compat_ulong_t spindown;
1596 unsigned char spindown_offset;
1597 unsigned char select_delay;
1598 unsigned char rps;
1599 unsigned char tracks;
1600 compat_ulong_t timeout;
1601 unsigned char interleave_sect;
1602 struct floppy_max_errors max_errors;
1603 char flags;
1604 char read_track;
1605 short autodetect[8];
1606 compat_int_t checkfreq;
1607 compat_int_t native_format;
1608 };
1609
1610 struct floppy_drive_struct32 {
1611 signed char flags;
1612 compat_ulong_t spinup_date;
1613 compat_ulong_t select_date;
1614 compat_ulong_t first_read_date;
1615 short probed_format;
1616 short track;
1617 short maxblock;
1618 short maxtrack;
1619 compat_int_t generation;
1620 compat_int_t keep_data;
1621 compat_int_t fd_ref;
1622 compat_int_t fd_device;
1623 compat_int_t last_checked;
1624 compat_caddr_t dmabuf;
1625 compat_int_t bufblocks;
1626 };
1627
1628 struct floppy_fdc_state32 {
1629 compat_int_t spec1;
1630 compat_int_t spec2;
1631 compat_int_t dtr;
1632 unsigned char version;
1633 unsigned char dor;
1634 compat_ulong_t address;
1635 unsigned int rawcmd:2;
1636 unsigned int reset:1;
1637 unsigned int need_configure:1;
1638 unsigned int perp_mode:2;
1639 unsigned int has_fifo:1;
1640 unsigned int driver_version;
1641 unsigned char track[4];
1642 };
1643
1644 struct floppy_write_errors32 {
1645 unsigned int write_errors;
1646 compat_ulong_t first_error_sector;
1647 compat_int_t first_error_generation;
1648 compat_ulong_t last_error_sector;
1649 compat_int_t last_error_generation;
1650 compat_uint_t badness;
1651 };
1652
1653 #define FDSETPRM32 _IOW(2, 0x42, struct floppy_struct32)
1654 #define FDDEFPRM32 _IOW(2, 0x43, struct floppy_struct32)
1655 #define FDGETPRM32 _IOR(2, 0x04, struct floppy_struct32)
1656 #define FDSETDRVPRM32 _IOW(2, 0x90, struct floppy_drive_params32)
1657 #define FDGETDRVPRM32 _IOR(2, 0x11, struct floppy_drive_params32)
1658 #define FDGETDRVSTAT32 _IOR(2, 0x12, struct floppy_drive_struct32)
1659 #define FDPOLLDRVSTAT32 _IOR(2, 0x13, struct floppy_drive_struct32)
1660 #define FDGETFDCSTAT32 _IOR(2, 0x15, struct floppy_fdc_state32)
1661 #define FDWERRORGET32 _IOR(2, 0x17, struct floppy_write_errors32)
1662
1663 static struct {
1664 unsigned int cmd32;
1665 unsigned int cmd;
1666 } fd_ioctl_trans_table[] = {
1667 { FDSETPRM32, FDSETPRM },
1668 { FDDEFPRM32, FDDEFPRM },
1669 { FDGETPRM32, FDGETPRM },
1670 { FDSETDRVPRM32, FDSETDRVPRM },
1671 { FDGETDRVPRM32, FDGETDRVPRM },
1672 { FDGETDRVSTAT32, FDGETDRVSTAT },
1673 { FDPOLLDRVSTAT32, FDPOLLDRVSTAT },
1674 { FDGETFDCSTAT32, FDGETFDCSTAT },
1675 { FDWERRORGET32, FDWERRORGET }
1676 };
1677
1678 #define NR_FD_IOCTL_TRANS ARRAY_SIZE(fd_ioctl_trans_table)
1679
1680 static int fd_ioctl_trans(unsigned int fd, unsigned int cmd, unsigned long arg)
1681 {
1682 mm_segment_t old_fs = get_fs();
1683 void *karg = NULL;
1684 unsigned int kcmd = 0;
1685 int i, err;
1686
1687 for (i = 0; i < NR_FD_IOCTL_TRANS; i++)
1688 if (cmd == fd_ioctl_trans_table[i].cmd32) {
1689 kcmd = fd_ioctl_trans_table[i].cmd;
1690 break;
1691 }
1692 if (!kcmd)
1693 return -EINVAL;
1694
1695 switch (cmd) {
1696 case FDSETPRM32:
1697 case FDDEFPRM32:
1698 case FDGETPRM32:
1699 {
1700 compat_uptr_t name;
1701 struct floppy_struct32 __user *uf;
1702 struct floppy_struct *f;
1703
1704 uf = compat_ptr(arg);
1705 f = karg = kmalloc(sizeof(struct floppy_struct), GFP_KERNEL);
1706 if (!karg)
1707 return -ENOMEM;
1708 if (cmd == FDGETPRM32)
1709 break;
1710 err = __get_user(f->size, &uf->size);
1711 err |= __get_user(f->sect, &uf->sect);
1712 err |= __get_user(f->head, &uf->head);
1713 err |= __get_user(f->track, &uf->track);
1714 err |= __get_user(f->stretch, &uf->stretch);
1715 err |= __get_user(f->gap, &uf->gap);
1716 err |= __get_user(f->rate, &uf->rate);
1717 err |= __get_user(f->spec1, &uf->spec1);
1718 err |= __get_user(f->fmt_gap, &uf->fmt_gap);
1719 err |= __get_user(name, &uf->name);
1720 f->name = compat_ptr(name);
1721 if (err) {
1722 err = -EFAULT;
1723 goto out;
1724 }
1725 break;
1726 }
1727 case FDSETDRVPRM32:
1728 case FDGETDRVPRM32:
1729 {
1730 struct floppy_drive_params32 __user *uf;
1731 struct floppy_drive_params *f;
1732
1733 uf = compat_ptr(arg);
1734 f = karg = kmalloc(sizeof(struct floppy_drive_params), GFP_KERNEL);
1735 if (!karg)
1736 return -ENOMEM;
1737 if (cmd == FDGETDRVPRM32)
1738 break;
1739 err = __get_user(f->cmos, &uf->cmos);
1740 err |= __get_user(f->max_dtr, &uf->max_dtr);
1741 err |= __get_user(f->hlt, &uf->hlt);
1742 err |= __get_user(f->hut, &uf->hut);
1743 err |= __get_user(f->srt, &uf->srt);
1744 err |= __get_user(f->spinup, &uf->spinup);
1745 err |= __get_user(f->spindown, &uf->spindown);
1746 err |= __get_user(f->spindown_offset, &uf->spindown_offset);
1747 err |= __get_user(f->select_delay, &uf->select_delay);
1748 err |= __get_user(f->rps, &uf->rps);
1749 err |= __get_user(f->tracks, &uf->tracks);
1750 err |= __get_user(f->timeout, &uf->timeout);
1751 err |= __get_user(f->interleave_sect, &uf->interleave_sect);
1752 err |= __copy_from_user(&f->max_errors, &uf->max_errors, sizeof(f->max_errors));
1753 err |= __get_user(f->flags, &uf->flags);
1754 err |= __get_user(f->read_track, &uf->read_track);
1755 err |= __copy_from_user(f->autodetect, uf->autodetect, sizeof(f->autodetect));
1756 err |= __get_user(f->checkfreq, &uf->checkfreq);
1757 err |= __get_user(f->native_format, &uf->native_format);
1758 if (err) {
1759 err = -EFAULT;
1760 goto out;
1761 }
1762 break;
1763 }
1764 case FDGETDRVSTAT32:
1765 case FDPOLLDRVSTAT32:
1766 karg = kmalloc(sizeof(struct floppy_drive_struct), GFP_KERNEL);
1767 if (!karg)
1768 return -ENOMEM;
1769 break;
1770 case FDGETFDCSTAT32:
1771 karg = kmalloc(sizeof(struct floppy_fdc_state), GFP_KERNEL);
1772 if (!karg)
1773 return -ENOMEM;
1774 break;
1775 case FDWERRORGET32:
1776 karg = kmalloc(sizeof(struct floppy_write_errors), GFP_KERNEL);
1777 if (!karg)
1778 return -ENOMEM;
1779 break;
1780 default:
1781 return -EINVAL;
1782 }
1783 set_fs (KERNEL_DS);
1784 err = sys_ioctl (fd, kcmd, (unsigned long)karg);
1785 set_fs (old_fs);
1786 if (err)
1787 goto out;
1788 switch (cmd) {
1789 case FDGETPRM32:
1790 {
1791 struct floppy_struct *f = karg;
1792 struct floppy_struct32 __user *uf = compat_ptr(arg);
1793
1794 err = __put_user(f->size, &uf->size);
1795 err |= __put_user(f->sect, &uf->sect);
1796 err |= __put_user(f->head, &uf->head);
1797 err |= __put_user(f->track, &uf->track);
1798 err |= __put_user(f->stretch, &uf->stretch);
1799 err |= __put_user(f->gap, &uf->gap);
1800 err |= __put_user(f->rate, &uf->rate);
1801 err |= __put_user(f->spec1, &uf->spec1);
1802 err |= __put_user(f->fmt_gap, &uf->fmt_gap);
1803 err |= __put_user((u64)f->name, (compat_caddr_t __user *)&uf->name);
1804 break;
1805 }
1806 case FDGETDRVPRM32:
1807 {
1808 struct floppy_drive_params32 __user *uf;
1809 struct floppy_drive_params *f = karg;
1810
1811 uf = compat_ptr(arg);
1812 err = __put_user(f->cmos, &uf->cmos);
1813 err |= __put_user(f->max_dtr, &uf->max_dtr);
1814 err |= __put_user(f->hlt, &uf->hlt);
1815 err |= __put_user(f->hut, &uf->hut);
1816 err |= __put_user(f->srt, &uf->srt);
1817 err |= __put_user(f->spinup, &uf->spinup);
1818 err |= __put_user(f->spindown, &uf->spindown);
1819 err |= __put_user(f->spindown_offset, &uf->spindown_offset);
1820 err |= __put_user(f->select_delay, &uf->select_delay);
1821 err |= __put_user(f->rps, &uf->rps);
1822 err |= __put_user(f->tracks, &uf->tracks);
1823 err |= __put_user(f->timeout, &uf->timeout);
1824 err |= __put_user(f->interleave_sect, &uf->interleave_sect);
1825 err |= __copy_to_user(&uf->max_errors, &f->max_errors, sizeof(f->max_errors));
1826 err |= __put_user(f->flags, &uf->flags);
1827 err |= __put_user(f->read_track, &uf->read_track);
1828 err |= __copy_to_user(uf->autodetect, f->autodetect, sizeof(f->autodetect));
1829 err |= __put_user(f->checkfreq, &uf->checkfreq);
1830 err |= __put_user(f->native_format, &uf->native_format);
1831 break;
1832 }
1833 case FDGETDRVSTAT32:
1834 case FDPOLLDRVSTAT32:
1835 {
1836 struct floppy_drive_struct32 __user *uf;
1837 struct floppy_drive_struct *f = karg;
1838
1839 uf = compat_ptr(arg);
1840 err = __put_user(f->flags, &uf->flags);
1841 err |= __put_user(f->spinup_date, &uf->spinup_date);
1842 err |= __put_user(f->select_date, &uf->select_date);
1843 err |= __put_user(f->first_read_date, &uf->first_read_date);
1844 err |= __put_user(f->probed_format, &uf->probed_format);
1845 err |= __put_user(f->track, &uf->track);
1846 err |= __put_user(f->maxblock, &uf->maxblock);
1847 err |= __put_user(f->maxtrack, &uf->maxtrack);
1848 err |= __put_user(f->generation, &uf->generation);
1849 err |= __put_user(f->keep_data, &uf->keep_data);
1850 err |= __put_user(f->fd_ref, &uf->fd_ref);
1851 err |= __put_user(f->fd_device, &uf->fd_device);
1852 err |= __put_user(f->last_checked, &uf->last_checked);
1853 err |= __put_user((u64)f->dmabuf, &uf->dmabuf);
1854 err |= __put_user((u64)f->bufblocks, &uf->bufblocks);
1855 break;
1856 }
1857 case FDGETFDCSTAT32:
1858 {
1859 struct floppy_fdc_state32 __user *uf;
1860 struct floppy_fdc_state *f = karg;
1861
1862 uf = compat_ptr(arg);
1863 err = __put_user(f->spec1, &uf->spec1);
1864 err |= __put_user(f->spec2, &uf->spec2);
1865 err |= __put_user(f->dtr, &uf->dtr);
1866 err |= __put_user(f->version, &uf->version);
1867 err |= __put_user(f->dor, &uf->dor);
1868 err |= __put_user(f->address, &uf->address);
1869 err |= __copy_to_user((char __user *)&uf->address + sizeof(uf->address),
1870 (char *)&f->address + sizeof(f->address), sizeof(int));
1871 err |= __put_user(f->driver_version, &uf->driver_version);
1872 err |= __copy_to_user(uf->track, f->track, sizeof(f->track));
1873 break;
1874 }
1875 case FDWERRORGET32:
1876 {
1877 struct floppy_write_errors32 __user *uf;
1878 struct floppy_write_errors *f = karg;
1879
1880 uf = compat_ptr(arg);
1881 err = __put_user(f->write_errors, &uf->write_errors);
1882 err |= __put_user(f->first_error_sector, &uf->first_error_sector);
1883 err |= __put_user(f->first_error_generation, &uf->first_error_generation);
1884 err |= __put_user(f->last_error_sector, &uf->last_error_sector);
1885 err |= __put_user(f->last_error_generation, &uf->last_error_generation);
1886 err |= __put_user(f->badness, &uf->badness);
1887 break;
1888 }
1889 default:
1890 break;
1891 }
1892 if (err)
1893 err = -EFAULT;
1894
1895 out:
1896 kfree(karg);
1897 return err;
1898 }
1899
1900 struct mtd_oob_buf32 {
1901 u_int32_t start;
1902 u_int32_t length;
1903 compat_caddr_t ptr; /* unsigned char* */
1904 };
1905
1906 #define MEMWRITEOOB32 _IOWR('M',3,struct mtd_oob_buf32)
1907 #define MEMREADOOB32 _IOWR('M',4,struct mtd_oob_buf32)
1908
1909 static int mtd_rw_oob(unsigned int fd, unsigned int cmd, unsigned long arg)
1910 {
1911 struct mtd_oob_buf __user *buf = compat_alloc_user_space(sizeof(*buf));
1912 struct mtd_oob_buf32 __user *buf32 = compat_ptr(arg);
1913 u32 data;
1914 char __user *datap;
1915 unsigned int real_cmd;
1916 int err;
1917
1918 real_cmd = (cmd == MEMREADOOB32) ?
1919 MEMREADOOB : MEMWRITEOOB;
1920
1921 if (copy_in_user(&buf->start, &buf32->start,
1922 2 * sizeof(u32)) ||
1923 get_user(data, &buf32->ptr))
1924 return -EFAULT;
1925 datap = compat_ptr(data);
1926 if (put_user(datap, &buf->ptr))
1927 return -EFAULT;
1928
1929 err = sys_ioctl(fd, real_cmd, (unsigned long) buf);
1930
1931 if (!err) {
1932 if (copy_in_user(&buf32->start, &buf->start,
1933 2 * sizeof(u32)))
1934 err = -EFAULT;
1935 }
1936
1937 return err;
1938 }
1939
1940 #define VFAT_IOCTL_READDIR_BOTH32 _IOR('r', 1, struct compat_dirent[2])
1941 #define VFAT_IOCTL_READDIR_SHORT32 _IOR('r', 2, struct compat_dirent[2])
1942
1943 static long
1944 put_dirent32 (struct dirent *d, struct compat_dirent __user *d32)
1945 {
1946 if (!access_ok(VERIFY_WRITE, d32, sizeof(struct compat_dirent)))
1947 return -EFAULT;
1948
1949 __put_user(d->d_ino, &d32->d_ino);
1950 __put_user(d->d_off, &d32->d_off);
1951 __put_user(d->d_reclen, &d32->d_reclen);
1952 if (__copy_to_user(d32->d_name, d->d_name, d->d_reclen))
1953 return -EFAULT;
1954
1955 return 0;
1956 }
1957
1958 static int vfat_ioctl32(unsigned fd, unsigned cmd, unsigned long arg)
1959 {
1960 struct compat_dirent __user *p = compat_ptr(arg);
1961 int ret;
1962 mm_segment_t oldfs = get_fs();
1963 struct dirent d[2];
1964
1965 switch(cmd)
1966 {
1967 case VFAT_IOCTL_READDIR_BOTH32:
1968 cmd = VFAT_IOCTL_READDIR_BOTH;
1969 break;
1970 case VFAT_IOCTL_READDIR_SHORT32:
1971 cmd = VFAT_IOCTL_READDIR_SHORT;
1972 break;
1973 }
1974
1975 set_fs(KERNEL_DS);
1976 ret = sys_ioctl(fd,cmd,(unsigned long)&d);
1977 set_fs(oldfs);
1978 if (ret >= 0) {
1979 ret |= put_dirent32(&d[0], p);
1980 ret |= put_dirent32(&d[1], p + 1);
1981 }
1982 return ret;
1983 }
1984
1985 struct raw32_config_request
1986 {
1987 compat_int_t raw_minor;
1988 __u64 block_major;
1989 __u64 block_minor;
1990 } __attribute__((packed));
1991
1992 static int get_raw32_request(struct raw_config_request *req, struct raw32_config_request __user *user_req)
1993 {
1994 int ret;
1995
1996 if (!access_ok(VERIFY_READ, user_req, sizeof(struct raw32_config_request)))
1997 return -EFAULT;
1998
1999 ret = __get_user(req->raw_minor, &user_req->raw_minor);
2000 ret |= __get_user(req->block_major, &user_req->block_major);
2001 ret |= __get_user(req->block_minor, &user_req->block_minor);
2002
2003 return ret ? -EFAULT : 0;
2004 }
2005
2006 static int set_raw32_request(struct raw_config_request *req, struct raw32_config_request __user *user_req)
2007 {
2008 int ret;
2009
2010 if (!access_ok(VERIFY_WRITE, user_req, sizeof(struct raw32_config_request)))
2011 return -EFAULT;
2012
2013 ret = __put_user(req->raw_minor, &user_req->raw_minor);
2014 ret |= __put_user(req->block_major, &user_req->block_major);
2015 ret |= __put_user(req->block_minor, &user_req->block_minor);
2016
2017 return ret ? -EFAULT : 0;
2018 }
2019
2020 static int raw_ioctl(unsigned fd, unsigned cmd, unsigned long arg)
2021 {
2022 int ret;
2023
2024 switch (cmd) {
2025 case RAW_SETBIND:
2026 case RAW_GETBIND: {
2027 struct raw_config_request req;
2028 struct raw32_config_request __user *user_req = compat_ptr(arg);
2029 mm_segment_t oldfs = get_fs();
2030
2031 if ((ret = get_raw32_request(&req, user_req)))
2032 return ret;
2033
2034 set_fs(KERNEL_DS);
2035 ret = sys_ioctl(fd,cmd,(unsigned long)&req);
2036 set_fs(oldfs);
2037
2038 if ((!ret) && (cmd == RAW_GETBIND)) {
2039 ret = set_raw32_request(&req, user_req);
2040 }
2041 break;
2042 }
2043 default:
2044 ret = sys_ioctl(fd, cmd, arg);
2045 break;
2046 }
2047 return ret;
2048 }
2049
2050 struct serial_struct32 {
2051 compat_int_t type;
2052 compat_int_t line;
2053 compat_uint_t port;
2054 compat_int_t irq;
2055 compat_int_t flags;
2056 compat_int_t xmit_fifo_size;
2057 compat_int_t custom_divisor;
2058 compat_int_t baud_base;
2059 unsigned short close_delay;
2060 char io_type;
2061 char reserved_char[1];
2062 compat_int_t hub6;
2063 unsigned short closing_wait; /* time to wait before closing */
2064 unsigned short closing_wait2; /* no longer used... */
2065 compat_uint_t iomem_base;
2066 unsigned short iomem_reg_shift;
2067 unsigned int port_high;
2068 /* compat_ulong_t iomap_base FIXME */
2069 compat_int_t reserved[1];
2070 };
2071
2072 static int serial_struct_ioctl(unsigned fd, unsigned cmd, unsigned long arg)
2073 {
2074 typedef struct serial_struct SS;
2075 typedef struct serial_struct32 SS32;
2076 struct serial_struct32 __user *ss32 = compat_ptr(arg);
2077 int err;
2078 struct serial_struct ss;
2079 mm_segment_t oldseg = get_fs();
2080 __u32 udata;
2081
2082 if (cmd == TIOCSSERIAL) {
2083 if (!access_ok(VERIFY_READ, ss32, sizeof(SS32)))
2084 return -EFAULT;
2085 if (__copy_from_user(&ss, ss32, offsetof(SS32, iomem_base)))
2086 return -EFAULT;
2087 __get_user(udata, &ss32->iomem_base);
2088 ss.iomem_base = compat_ptr(udata);
2089 __get_user(ss.iomem_reg_shift, &ss32->iomem_reg_shift);
2090 __get_user(ss.port_high, &ss32->port_high);
2091 ss.iomap_base = 0UL;
2092 }
2093 set_fs(KERNEL_DS);
2094 err = sys_ioctl(fd,cmd,(unsigned long)(&ss));
2095 set_fs(oldseg);
2096 if (cmd == TIOCGSERIAL && err >= 0) {
2097 if (!access_ok(VERIFY_WRITE, ss32, sizeof(SS32)))
2098 return -EFAULT;
2099 if (__copy_to_user(ss32,&ss,offsetof(SS32,iomem_base)))
2100 return -EFAULT;
2101 __put_user((unsigned long)ss.iomem_base >> 32 ?
2102 0xffffffff : (unsigned)(unsigned long)ss.iomem_base,
2103 &ss32->iomem_base);
2104 __put_user(ss.iomem_reg_shift, &ss32->iomem_reg_shift);
2105 __put_user(ss.port_high, &ss32->port_high);
2106
2107 }
2108 return err;
2109 }
2110
2111 struct usbdevfs_ctrltransfer32 {
2112 u8 bRequestType;
2113 u8 bRequest;
2114 u16 wValue;
2115 u16 wIndex;
2116 u16 wLength;
2117 u32 timeout; /* in milliseconds */
2118 compat_caddr_t data;
2119 };
2120
2121 #define USBDEVFS_CONTROL32 _IOWR('U', 0, struct usbdevfs_ctrltransfer32)
2122
2123 static int do_usbdevfs_control(unsigned int fd, unsigned int cmd, unsigned long arg)
2124 {
2125 struct usbdevfs_ctrltransfer32 __user *p32 = compat_ptr(arg);
2126 struct usbdevfs_ctrltransfer __user *p;
2127 __u32 udata;
2128 p = compat_alloc_user_space(sizeof(*p));
2129 if (copy_in_user(p, p32, (sizeof(*p32) - sizeof(compat_caddr_t))) ||
2130 get_user(udata, &p32->data) ||
2131 put_user(compat_ptr(udata), &p->data))
2132 return -EFAULT;
2133 return sys_ioctl(fd, USBDEVFS_CONTROL, (unsigned long)p);
2134 }
2135
2136
2137 struct usbdevfs_bulktransfer32 {
2138 compat_uint_t ep;
2139 compat_uint_t len;
2140 compat_uint_t timeout; /* in milliseconds */
2141 compat_caddr_t data;
2142 };
2143
2144 #define USBDEVFS_BULK32 _IOWR('U', 2, struct usbdevfs_bulktransfer32)
2145
2146 static int do_usbdevfs_bulk(unsigned int fd, unsigned int cmd, unsigned long arg)
2147 {
2148 struct usbdevfs_bulktransfer32 __user *p32 = compat_ptr(arg);
2149 struct usbdevfs_bulktransfer __user *p;
2150 compat_uint_t n;
2151 compat_caddr_t addr;
2152
2153 p = compat_alloc_user_space(sizeof(*p));
2154
2155 if (get_user(n, &p32->ep) || put_user(n, &p->ep) ||
2156 get_user(n, &p32->len) || put_user(n, &p->len) ||
2157 get_user(n, &p32->timeout) || put_user(n, &p->timeout) ||
2158 get_user(addr, &p32->data) || put_user(compat_ptr(addr), &p->data))
2159 return -EFAULT;
2160
2161 return sys_ioctl(fd, USBDEVFS_BULK, (unsigned long)p);
2162 }
2163
2164
2165 /*
2166 * USBDEVFS_SUBMITURB, USBDEVFS_REAPURB and USBDEVFS_REAPURBNDELAY
2167 * are handled in usbdevfs core. -Christopher Li
2168 */
2169
2170 struct usbdevfs_disconnectsignal32 {
2171 compat_int_t signr;
2172 compat_caddr_t context;
2173 };
2174
2175 #define USBDEVFS_DISCSIGNAL32 _IOR('U', 14, struct usbdevfs_disconnectsignal32)
2176
2177 static int do_usbdevfs_discsignal(unsigned int fd, unsigned int cmd, unsigned long arg)
2178 {
2179 struct usbdevfs_disconnectsignal kdis;
2180 struct usbdevfs_disconnectsignal32 __user *udis;
2181 mm_segment_t old_fs;
2182 u32 uctx;
2183 int err;
2184
2185 udis = compat_ptr(arg);
2186
2187 if (get_user(kdis.signr, &udis->signr) ||
2188 __get_user(uctx, &udis->context))
2189 return -EFAULT;
2190
2191 kdis.context = compat_ptr(uctx);
2192
2193 old_fs = get_fs();
2194 set_fs(KERNEL_DS);
2195 err = sys_ioctl(fd, USBDEVFS_DISCSIGNAL, (unsigned long) &kdis);
2196 set_fs(old_fs);
2197
2198 return err;
2199 }
2200
2201 /*
2202 * I2C layer ioctls
2203 */
2204
2205 struct i2c_msg32 {
2206 u16 addr;
2207 u16 flags;
2208 u16 len;
2209 compat_caddr_t buf;
2210 };
2211
2212 struct i2c_rdwr_ioctl_data32 {
2213 compat_caddr_t msgs; /* struct i2c_msg __user *msgs */
2214 u32 nmsgs;
2215 };
2216
2217 struct i2c_smbus_ioctl_data32 {
2218 u8 read_write;
2219 u8 command;
2220 u32 size;
2221 compat_caddr_t data; /* union i2c_smbus_data *data */
2222 };
2223
2224 struct i2c_rdwr_aligned {
2225 struct i2c_rdwr_ioctl_data cmd;
2226 struct i2c_msg msgs[0];
2227 };
2228
2229 static int do_i2c_rdwr_ioctl(unsigned int fd, unsigned int cmd, unsigned long arg)
2230 {
2231 struct i2c_rdwr_ioctl_data32 __user *udata = compat_ptr(arg);
2232 struct i2c_rdwr_aligned __user *tdata;
2233 struct i2c_msg __user *tmsgs;
2234 struct i2c_msg32 __user *umsgs;
2235 compat_caddr_t datap;
2236 int nmsgs, i;
2237
2238 if (get_user(nmsgs, &udata->nmsgs))
2239 return -EFAULT;
2240 if (nmsgs > I2C_RDRW_IOCTL_MAX_MSGS)
2241 return -EINVAL;
2242
2243 if (get_user(datap, &udata->msgs))
2244 return -EFAULT;
2245 umsgs = compat_ptr(datap);
2246
2247 tdata = compat_alloc_user_space(sizeof(*tdata) +
2248 nmsgs * sizeof(struct i2c_msg));
2249 tmsgs = &tdata->msgs[0];
2250
2251 if (put_user(nmsgs, &tdata->cmd.nmsgs) ||
2252 put_user(tmsgs, &tdata->cmd.msgs))
2253 return -EFAULT;
2254
2255 for (i = 0; i < nmsgs; i++) {
2256 if (copy_in_user(&tmsgs[i].addr, &umsgs[i].addr, 3*sizeof(u16)))
2257 return -EFAULT;
2258 if (get_user(datap, &umsgs[i].buf) ||
2259 put_user(compat_ptr(datap), &tmsgs[i].buf))
2260 return -EFAULT;
2261 }
2262 return sys_ioctl(fd, cmd, (unsigned long)tdata);
2263 }
2264
2265 static int do_i2c_smbus_ioctl(unsigned int fd, unsigned int cmd, unsigned long arg)
2266 {
2267 struct i2c_smbus_ioctl_data __user *tdata;
2268 struct i2c_smbus_ioctl_data32 __user *udata;
2269 compat_caddr_t datap;
2270
2271 tdata = compat_alloc_user_space(sizeof(*tdata));
2272 if (tdata == NULL)
2273 return -ENOMEM;
2274 if (!access_ok(VERIFY_WRITE, tdata, sizeof(*tdata)))
2275 return -EFAULT;
2276
2277 udata = compat_ptr(arg);
2278 if (!access_ok(VERIFY_READ, udata, sizeof(*udata)))
2279 return -EFAULT;
2280
2281 if (__copy_in_user(&tdata->read_write, &udata->read_write, 2 * sizeof(u8)))
2282 return -EFAULT;
2283 if (__copy_in_user(&tdata->size, &udata->size, 2 * sizeof(u32)))
2284 return -EFAULT;
2285 if (__get_user(datap, &udata->data) ||
2286 __put_user(compat_ptr(datap), &tdata->data))
2287 return -EFAULT;
2288
2289 return sys_ioctl(fd, cmd, (unsigned long)tdata);
2290 }
2291
2292 struct compat_iw_point {
2293 compat_caddr_t pointer;
2294 __u16 length;
2295 __u16 flags;
2296 };
2297
2298 static int do_wireless_ioctl(unsigned int fd, unsigned int cmd, unsigned long arg)
2299 {
2300 struct iwreq __user *iwr;
2301 struct iwreq __user *iwr_u;
2302 struct iw_point __user *iwp;
2303 struct compat_iw_point __user *iwp_u;
2304 compat_caddr_t pointer;
2305 __u16 length, flags;
2306
2307 iwr_u = compat_ptr(arg);
2308 iwp_u = (struct compat_iw_point __user *) &iwr_u->u.data;
2309 iwr = compat_alloc_user_space(sizeof(*iwr));
2310 if (iwr == NULL)
2311 return -ENOMEM;
2312
2313 iwp = &iwr->u.data;
2314
2315 if (!access_ok(VERIFY_WRITE, iwr, sizeof(*iwr)))
2316 return -EFAULT;
2317
2318 if (__copy_in_user(&iwr->ifr_ifrn.ifrn_name[0],
2319 &iwr_u->ifr_ifrn.ifrn_name[0],
2320 sizeof(iwr->ifr_ifrn.ifrn_name)))
2321 return -EFAULT;
2322
2323 if (__get_user(pointer, &iwp_u->pointer) ||
2324 __get_user(length, &iwp_u->length) ||
2325 __get_user(flags, &iwp_u->flags))
2326 return -EFAULT;
2327
2328 if (__put_user(compat_ptr(pointer), &iwp->pointer) ||
2329 __put_user(length, &iwp->length) ||
2330 __put_user(flags, &iwp->flags))
2331 return -EFAULT;
2332
2333 return sys_ioctl(fd, cmd, (unsigned long) iwr);
2334 }
2335
2336 /* Since old style bridge ioctl's endup using SIOCDEVPRIVATE
2337 * for some operations; this forces use of the newer bridge-utils that
2338 * use compatiable ioctls
2339 */
2340 static int old_bridge_ioctl(unsigned int fd, unsigned int cmd, unsigned long arg)
2341 {
2342 u32 tmp;
2343
2344 if (get_user(tmp, (u32 __user *) arg))
2345 return -EFAULT;
2346 if (tmp == BRCTL_GET_VERSION)
2347 return BRCTL_VERSION + 1;
2348 return -EINVAL;
2349 }
2350
2351 #define RTC_IRQP_READ32 _IOR('p', 0x0b, compat_ulong_t)
2352 #define RTC_IRQP_SET32 _IOW('p', 0x0c, compat_ulong_t)
2353 #define RTC_EPOCH_READ32 _IOR('p', 0x0d, compat_ulong_t)
2354 #define RTC_EPOCH_SET32 _IOW('p', 0x0e, compat_ulong_t)
2355
2356 static int rtc_ioctl(unsigned fd, unsigned cmd, unsigned long arg)
2357 {
2358 mm_segment_t oldfs = get_fs();
2359 compat_ulong_t val32;
2360 unsigned long kval;
2361 int ret;
2362
2363 switch (cmd) {
2364 case RTC_IRQP_READ32:
2365 case RTC_EPOCH_READ32:
2366 set_fs(KERNEL_DS);
2367 ret = sys_ioctl(fd, (cmd == RTC_IRQP_READ32) ?
2368 RTC_IRQP_READ : RTC_EPOCH_READ,
2369 (unsigned long)&kval);
2370 set_fs(oldfs);
2371 if (ret)
2372 return ret;
2373 val32 = kval;
2374 return put_user(val32, (unsigned int __user *)arg);
2375 case RTC_IRQP_SET32:
2376 return sys_ioctl(fd, RTC_IRQP_SET, arg);
2377 case RTC_EPOCH_SET32:
2378 return sys_ioctl(fd, RTC_EPOCH_SET, arg);
2379 default:
2380 /* unreached */
2381 return -ENOIOCTLCMD;
2382 }
2383 }
2384
2385 #if defined(CONFIG_NCP_FS) || defined(CONFIG_NCP_FS_MODULE)
2386 struct ncp_ioctl_request_32 {
2387 u32 function;
2388 u32 size;
2389 compat_caddr_t data;
2390 };
2391
2392 struct ncp_fs_info_v2_32 {
2393 s32 version;
2394 u32 mounted_uid;
2395 u32 connection;
2396 u32 buffer_size;
2397
2398 u32 volume_number;
2399 u32 directory_id;
2400
2401 u32 dummy1;
2402 u32 dummy2;
2403 u32 dummy3;
2404 };
2405
2406 struct ncp_objectname_ioctl_32
2407 {
2408 s32 auth_type;
2409 u32 object_name_len;
2410 compat_caddr_t object_name; /* an userspace data, in most cases user name */
2411 };
2412
2413 struct ncp_privatedata_ioctl_32
2414 {
2415 u32 len;
2416 compat_caddr_t data; /* ~1000 for NDS */
2417 };
2418
2419 #define NCP_IOC_NCPREQUEST_32 _IOR('n', 1, struct ncp_ioctl_request_32)
2420 #define NCP_IOC_GETMOUNTUID2_32 _IOW('n', 2, u32)
2421 #define NCP_IOC_GET_FS_INFO_V2_32 _IOWR('n', 4, struct ncp_fs_info_v2_32)
2422 #define NCP_IOC_GETOBJECTNAME_32 _IOWR('n', 9, struct ncp_objectname_ioctl_32)
2423 #define NCP_IOC_SETOBJECTNAME_32 _IOR('n', 9, struct ncp_objectname_ioctl_32)
2424 #define NCP_IOC_GETPRIVATEDATA_32 _IOWR('n', 10, struct ncp_privatedata_ioctl_32)
2425 #define NCP_IOC_SETPRIVATEDATA_32 _IOR('n', 10, struct ncp_privatedata_ioctl_32)
2426
2427 static int do_ncp_ncprequest(unsigned int fd, unsigned int cmd, unsigned long arg)
2428 {
2429 struct ncp_ioctl_request_32 n32;
2430 struct ncp_ioctl_request __user *p = compat_alloc_user_space(sizeof(*p));
2431
2432 if (copy_from_user(&n32, compat_ptr(arg), sizeof(n32)) ||
2433 put_user(n32.function, &p->function) ||
2434 put_user(n32.size, &p->size) ||
2435 put_user(compat_ptr(n32.data), &p->data))
2436 return -EFAULT;
2437
2438 return sys_ioctl(fd, NCP_IOC_NCPREQUEST, (unsigned long)p);
2439 }
2440
2441 static int do_ncp_getmountuid2(unsigned int fd, unsigned int cmd, unsigned long arg)
2442 {
2443 mm_segment_t old_fs = get_fs();
2444 __kernel_uid_t kuid;
2445 int err;
2446
2447 cmd = NCP_IOC_GETMOUNTUID2;
2448
2449 set_fs(KERNEL_DS);
2450 err = sys_ioctl(fd, cmd, (unsigned long)&kuid);
2451 set_fs(old_fs);
2452
2453 if (!err)
2454 err = put_user(kuid,
2455 (unsigned int __user *) compat_ptr(arg));
2456
2457 return err;
2458 }
2459
2460 static int do_ncp_getfsinfo2(unsigned int fd, unsigned int cmd, unsigned long arg)
2461 {
2462 mm_segment_t old_fs = get_fs();
2463 struct ncp_fs_info_v2_32 n32;
2464 struct ncp_fs_info_v2 n;
2465 int err;
2466
2467 if (copy_from_user(&n32, compat_ptr(arg), sizeof(n32)))
2468 return -EFAULT;
2469 if (n32.version != NCP_GET_FS_INFO_VERSION_V2)
2470 return -EINVAL;
2471 n.version = NCP_GET_FS_INFO_VERSION_V2;
2472
2473 set_fs(KERNEL_DS);
2474 err = sys_ioctl(fd, NCP_IOC_GET_FS_INFO_V2, (unsigned long)&n);
2475 set_fs(old_fs);
2476
2477 if (!err) {
2478 n32.version = n.version;
2479 n32.mounted_uid = n.mounted_uid;
2480 n32.connection = n.connection;
2481 n32.buffer_size = n.buffer_size;
2482 n32.volume_number = n.volume_number;
2483 n32.directory_id = n.directory_id;
2484 n32.dummy1 = n.dummy1;
2485 n32.dummy2 = n.dummy2;
2486 n32.dummy3 = n.dummy3;
2487 err = copy_to_user(compat_ptr(arg), &n32, sizeof(n32)) ? -EFAULT : 0;
2488 }
2489 return err;
2490 }
2491
2492 static int do_ncp_getobjectname(unsigned int fd, unsigned int cmd, unsigned long arg)
2493 {
2494 struct ncp_objectname_ioctl_32 n32, __user *p32 = compat_ptr(arg);
2495 struct ncp_objectname_ioctl __user *p = compat_alloc_user_space(sizeof(*p));
2496 s32 auth_type;
2497 u32 name_len;
2498 int err;
2499
2500 if (copy_from_user(&n32, p32, sizeof(n32)) ||
2501 put_user(n32.object_name_len, &p->object_name_len) ||
2502 put_user(compat_ptr(n32.object_name), &p->object_name))
2503 return -EFAULT;
2504
2505 err = sys_ioctl(fd, NCP_IOC_GETOBJECTNAME, (unsigned long)p);
2506 if (err)
2507 return err;
2508
2509 if (get_user(auth_type, &p->auth_type) ||
2510 put_user(auth_type, &p32->auth_type) ||
2511 get_user(name_len, &p->object_name_len) ||
2512 put_user(name_len, &p32->object_name_len))
2513 return -EFAULT;
2514
2515 return 0;
2516 }
2517
2518 static int do_ncp_setobjectname(unsigned int fd, unsigned int cmd, unsigned long arg)
2519 {
2520 struct ncp_objectname_ioctl_32 n32, __user *p32 = compat_ptr(arg);
2521 struct ncp_objectname_ioctl __user *p = compat_alloc_user_space(sizeof(*p));
2522
2523 if (copy_from_user(&n32, p32, sizeof(n32)) ||
2524 put_user(n32.auth_type, &p->auth_type) ||
2525 put_user(n32.object_name_len, &p->object_name_len) ||
2526 put_user(compat_ptr(n32.object_name), &p->object_name))
2527 return -EFAULT;
2528
2529 return sys_ioctl(fd, NCP_IOC_SETOBJECTNAME, (unsigned long)p);
2530 }
2531
2532 static int do_ncp_getprivatedata(unsigned int fd, unsigned int cmd, unsigned long arg)
2533 {
2534 struct ncp_privatedata_ioctl_32 n32, __user *p32 = compat_ptr(arg);
2535 struct ncp_privatedata_ioctl __user *p =
2536 compat_alloc_user_space(sizeof(*p));
2537 u32 len;
2538 int err;
2539
2540 if (copy_from_user(&n32, p32, sizeof(n32)) ||
2541 put_user(n32.len, &p->len) ||
2542 put_user(compat_ptr(n32.data), &p->data))
2543 return -EFAULT;
2544
2545 err = sys_ioctl(fd, NCP_IOC_GETPRIVATEDATA, (unsigned long)p);
2546 if (err)
2547 return err;
2548
2549 if (get_user(len, &p->len) ||
2550 put_user(len, &p32->len))
2551 return -EFAULT;
2552
2553 return 0;
2554 }
2555
2556 static int do_ncp_setprivatedata(unsigned int fd, unsigned int cmd, unsigned long arg)
2557 {
2558 struct ncp_privatedata_ioctl_32 n32;
2559 struct ncp_privatedata_ioctl_32 __user *p32 = compat_ptr(arg);
2560 struct ncp_privatedata_ioctl __user *p =
2561 compat_alloc_user_space(sizeof(*p));
2562
2563 if (copy_from_user(&n32, p32, sizeof(n32)) ||
2564 put_user(n32.len, &p->len) ||
2565 put_user(compat_ptr(n32.data), &p->data))
2566 return -EFAULT;
2567
2568 return sys_ioctl(fd, NCP_IOC_SETPRIVATEDATA, (unsigned long)p);
2569 }
2570 #endif
2571
2572 static int
2573 lp_timeout_trans(unsigned int fd, unsigned int cmd, unsigned long arg)
2574 {
2575 struct compat_timeval __user *tc = (struct compat_timeval __user *)arg;
2576 struct timeval __user *tn = compat_alloc_user_space(sizeof(struct timeval));
2577 struct timeval ts;
2578 if (get_user(ts.tv_sec, &tc->tv_sec) ||
2579 get_user(ts.tv_usec, &tc->tv_usec) ||
2580 put_user(ts.tv_sec, &tn->tv_sec) ||
2581 put_user(ts.tv_usec, &tn->tv_usec))
2582 return -EFAULT;
2583 return sys_ioctl(fd, cmd, (unsigned long)tn);
2584 }
2585
2586 #define HANDLE_IOCTL(cmd,handler) \
2587 { (cmd), (ioctl_trans_handler_t)(handler) },
2588
2589 /* pointer to compatible structure or no argument */
2590 #define COMPATIBLE_IOCTL(cmd) \
2591 { (cmd), do_ioctl32_pointer },
2592
2593 /* argument is an unsigned long integer, not a pointer */
2594 #define ULONG_IOCTL(cmd) \
2595 { (cmd), (ioctl_trans_handler_t)sys_ioctl },
2596
2597
2598 struct ioctl_trans ioctl_start[] = {
2599 #include <linux/compat_ioctl.h>
2600 HANDLE_IOCTL(MEMREADOOB32, mtd_rw_oob)
2601 HANDLE_IOCTL(MEMWRITEOOB32, mtd_rw_oob)
2602 #ifdef CONFIG_NET
2603 HANDLE_IOCTL(SIOCGIFNAME, dev_ifname32)
2604 HANDLE_IOCTL(SIOCGIFCONF, dev_ifconf)
2605 HANDLE_IOCTL(SIOCGIFFLAGS, dev_ifsioc)
2606 HANDLE_IOCTL(SIOCSIFFLAGS, dev_ifsioc)
2607 HANDLE_IOCTL(SIOCGIFMETRIC, dev_ifsioc)
2608 HANDLE_IOCTL(SIOCSIFMETRIC, dev_ifsioc)
2609 HANDLE_IOCTL(SIOCGIFMTU, dev_ifsioc)
2610 HANDLE_IOCTL(SIOCSIFMTU, dev_ifsioc)
2611 HANDLE_IOCTL(SIOCGIFMEM, dev_ifsioc)
2612 HANDLE_IOCTL(SIOCSIFMEM, dev_ifsioc)
2613 HANDLE_IOCTL(SIOCGIFHWADDR, dev_ifsioc)
2614 HANDLE_IOCTL(SIOCSIFHWADDR, dev_ifsioc)
2615 HANDLE_IOCTL(SIOCADDMULTI, dev_ifsioc)
2616 HANDLE_IOCTL(SIOCDELMULTI, dev_ifsioc)
2617 HANDLE_IOCTL(SIOCGIFINDEX, dev_ifsioc)
2618 HANDLE_IOCTL(SIOCGIFMAP, dev_ifsioc)
2619 HANDLE_IOCTL(SIOCSIFMAP, dev_ifsioc)
2620 HANDLE_IOCTL(SIOCGIFADDR, dev_ifsioc)
2621 HANDLE_IOCTL(SIOCSIFADDR, dev_ifsioc)
2622
2623 /* ioctls used by appletalk ddp.c */
2624 HANDLE_IOCTL(SIOCATALKDIFADDR, dev_ifsioc)
2625 HANDLE_IOCTL(SIOCDIFADDR, dev_ifsioc)
2626 HANDLE_IOCTL(SIOCSARP, dev_ifsioc)
2627 HANDLE_IOCTL(SIOCDARP, dev_ifsioc)
2628
2629 HANDLE_IOCTL(SIOCGIFBRDADDR, dev_ifsioc)
2630 HANDLE_IOCTL(SIOCSIFBRDADDR, dev_ifsioc)
2631 HANDLE_IOCTL(SIOCGIFDSTADDR, dev_ifsioc)
2632 HANDLE_IOCTL(SIOCSIFDSTADDR, dev_ifsioc)
2633 HANDLE_IOCTL(SIOCGIFNETMASK, dev_ifsioc)
2634 HANDLE_IOCTL(SIOCSIFNETMASK, dev_ifsioc)
2635 HANDLE_IOCTL(SIOCSIFPFLAGS, dev_ifsioc)
2636 HANDLE_IOCTL(SIOCGIFPFLAGS, dev_ifsioc)
2637 HANDLE_IOCTL(SIOCGIFTXQLEN, dev_ifsioc)
2638 HANDLE_IOCTL(SIOCSIFTXQLEN, dev_ifsioc)
2639 HANDLE_IOCTL(TUNSETIFF, dev_ifsioc)
2640 HANDLE_IOCTL(SIOCETHTOOL, ethtool_ioctl)
2641 HANDLE_IOCTL(SIOCBONDENSLAVE, bond_ioctl)
2642 HANDLE_IOCTL(SIOCBONDRELEASE, bond_ioctl)
2643 HANDLE_IOCTL(SIOCBONDSETHWADDR, bond_ioctl)
2644 HANDLE_IOCTL(SIOCBONDSLAVEINFOQUERY, bond_ioctl)
2645 HANDLE_IOCTL(SIOCBONDINFOQUERY, bond_ioctl)
2646 HANDLE_IOCTL(SIOCBONDCHANGEACTIVE, bond_ioctl)
2647 HANDLE_IOCTL(SIOCADDRT, routing_ioctl)
2648 HANDLE_IOCTL(SIOCDELRT, routing_ioctl)
2649 HANDLE_IOCTL(SIOCBRADDIF, dev_ifsioc)
2650 HANDLE_IOCTL(SIOCBRDELIF, dev_ifsioc)
2651 /* Note SIOCRTMSG is no longer, so this is safe and * the user would have seen just an -EINVAL anyways. */
2652 HANDLE_IOCTL(SIOCRTMSG, ret_einval)
2653 HANDLE_IOCTL(SIOCGSTAMP, do_siocgstamp)
2654 #endif
2655 HANDLE_IOCTL(HDIO_GETGEO, hdio_getgeo)
2656 HANDLE_IOCTL(BLKRAGET, w_long)
2657 HANDLE_IOCTL(BLKGETSIZE, w_long)
2658 HANDLE_IOCTL(0x1260, broken_blkgetsize)
2659 HANDLE_IOCTL(BLKFRAGET, w_long)
2660 HANDLE_IOCTL(BLKSECTGET, w_long)
2661 HANDLE_IOCTL(BLKPG, blkpg_ioctl_trans)
2662 HANDLE_IOCTL(HDIO_GET_KEEPSETTINGS, hdio_ioctl_trans)
2663 HANDLE_IOCTL(HDIO_GET_UNMASKINTR, hdio_ioctl_trans)
2664 HANDLE_IOCTL(HDIO_GET_DMA, hdio_ioctl_trans)
2665 HANDLE_IOCTL(HDIO_GET_32BIT, hdio_ioctl_trans)
2666 HANDLE_IOCTL(HDIO_GET_MULTCOUNT, hdio_ioctl_trans)
2667 HANDLE_IOCTL(HDIO_GET_NOWERR, hdio_ioctl_trans)
2668 HANDLE_IOCTL(HDIO_GET_NICE, hdio_ioctl_trans)
2669 HANDLE_IOCTL(FDSETPRM32, fd_ioctl_trans)
2670 HANDLE_IOCTL(FDDEFPRM32, fd_ioctl_trans)
2671 HANDLE_IOCTL(FDGETPRM32, fd_ioctl_trans)
2672 HANDLE_IOCTL(FDSETDRVPRM32, fd_ioctl_trans)
2673 HANDLE_IOCTL(FDGETDRVPRM32, fd_ioctl_trans)
2674 HANDLE_IOCTL(FDGETDRVSTAT32, fd_ioctl_trans)
2675 HANDLE_IOCTL(FDPOLLDRVSTAT32, fd_ioctl_trans)
2676 HANDLE_IOCTL(FDGETFDCSTAT32, fd_ioctl_trans)
2677 HANDLE_IOCTL(FDWERRORGET32, fd_ioctl_trans)
2678 HANDLE_IOCTL(SG_IO,sg_ioctl_trans)
2679 HANDLE_IOCTL(SG_GET_REQUEST_TABLE, sg_grt_trans)
2680 HANDLE_IOCTL(PPPIOCGIDLE32, ppp_ioctl_trans)
2681 HANDLE_IOCTL(PPPIOCSCOMPRESS32, ppp_ioctl_trans)
2682 HANDLE_IOCTL(PPPIOCSPASS32, ppp_sock_fprog_ioctl_trans)
2683 HANDLE_IOCTL(PPPIOCSACTIVE32, ppp_sock_fprog_ioctl_trans)
2684 HANDLE_IOCTL(MTIOCGET32, mt_ioctl_trans)
2685 HANDLE_IOCTL(MTIOCPOS32, mt_ioctl_trans)
2686 HANDLE_IOCTL(CDROMREADAUDIO, cdrom_ioctl_trans)
2687 HANDLE_IOCTL(CDROM_SEND_PACKET, cdrom_ioctl_trans)
2688 #define AUTOFS_IOC_SETTIMEOUT32 _IOWR(0x93,0x64,unsigned int)
2689 HANDLE_IOCTL(AUTOFS_IOC_SETTIMEOUT32, ioc_settimeout)
2690 #ifdef CONFIG_VT
2691 HANDLE_IOCTL(PIO_FONTX, do_fontx_ioctl)
2692 HANDLE_IOCTL(GIO_FONTX, do_fontx_ioctl)
2693 HANDLE_IOCTL(PIO_UNIMAP, do_unimap_ioctl)
2694 HANDLE_IOCTL(GIO_UNIMAP, do_unimap_ioctl)
2695 HANDLE_IOCTL(KDFONTOP, do_kdfontop_ioctl)
2696 #endif
2697 /* One SMB ioctl needs translations. */
2698 #define SMB_IOC_GETMOUNTUID_32 _IOR('u', 1, compat_uid_t)
2699 HANDLE_IOCTL(SMB_IOC_GETMOUNTUID_32, do_smb_getmountuid)
2700 HANDLE_IOCTL(ATM_GETLINKRATE32, do_atm_ioctl)
2701 HANDLE_IOCTL(ATM_GETNAMES32, do_atm_ioctl)
2702 HANDLE_IOCTL(ATM_GETTYPE32, do_atm_ioctl)
2703 HANDLE_IOCTL(ATM_GETESI32, do_atm_ioctl)
2704 HANDLE_IOCTL(ATM_GETADDR32, do_atm_ioctl)
2705 HANDLE_IOCTL(ATM_RSTADDR32, do_atm_ioctl)
2706 HANDLE_IOCTL(ATM_ADDADDR32, do_atm_ioctl)
2707 HANDLE_IOCTL(ATM_DELADDR32, do_atm_ioctl)
2708 HANDLE_IOCTL(ATM_GETCIRANGE32, do_atm_ioctl)
2709 HANDLE_IOCTL(ATM_SETCIRANGE32, do_atm_ioctl)
2710 HANDLE_IOCTL(ATM_SETESI32, do_atm_ioctl)
2711 HANDLE_IOCTL(ATM_SETESIF32, do_atm_ioctl)
2712 HANDLE_IOCTL(ATM_GETSTAT32, do_atm_ioctl)
2713 HANDLE_IOCTL(ATM_GETSTATZ32, do_atm_ioctl)
2714 HANDLE_IOCTL(ATM_GETLOOP32, do_atm_ioctl)
2715 HANDLE_IOCTL(ATM_SETLOOP32, do_atm_ioctl)
2716 HANDLE_IOCTL(ATM_QUERYLOOP32, do_atm_ioctl)
2717 HANDLE_IOCTL(SONET_GETSTAT, do_atm_ioctl)
2718 HANDLE_IOCTL(SONET_GETSTATZ, do_atm_ioctl)
2719 HANDLE_IOCTL(SONET_GETDIAG, do_atm_ioctl)
2720 HANDLE_IOCTL(SONET_SETDIAG, do_atm_ioctl)
2721 HANDLE_IOCTL(SONET_CLRDIAG, do_atm_ioctl)
2722 HANDLE_IOCTL(SONET_SETFRAMING, do_atm_ioctl)
2723 HANDLE_IOCTL(SONET_GETFRAMING, do_atm_ioctl)
2724 HANDLE_IOCTL(SONET_GETFRSENSE, do_atm_ioctl)
2725 /* block stuff */
2726 HANDLE_IOCTL(BLKBSZGET_32, do_blkbszget)
2727 HANDLE_IOCTL(BLKBSZSET_32, do_blkbszset)
2728 HANDLE_IOCTL(BLKGETSIZE64_32, do_blkgetsize64)
2729 /* vfat */
2730 HANDLE_IOCTL(VFAT_IOCTL_READDIR_BOTH32, vfat_ioctl32)
2731 HANDLE_IOCTL(VFAT_IOCTL_READDIR_SHORT32, vfat_ioctl32)
2732 /* Raw devices */
2733 HANDLE_IOCTL(RAW_SETBIND, raw_ioctl)
2734 HANDLE_IOCTL(RAW_GETBIND, raw_ioctl)
2735 /* Serial */
2736 HANDLE_IOCTL(TIOCGSERIAL, serial_struct_ioctl)
2737 HANDLE_IOCTL(TIOCSSERIAL, serial_struct_ioctl)
2738 #ifdef TIOCGLTC
2739 COMPATIBLE_IOCTL(TIOCGLTC)
2740 COMPATIBLE_IOCTL(TIOCSLTC)
2741 #endif
2742 #ifdef TIOCSTART
2743 /*
2744 * For these two we have defintions in ioctls.h and/or termios.h on
2745 * some architectures but no actual implemention. Some applications
2746 * like bash call them if they are defined in the headers, so we provide
2747 * entries here to avoid syslog message spew.
2748 */
2749 COMPATIBLE_IOCTL(TIOCSTART)
2750 COMPATIBLE_IOCTL(TIOCSTOP)
2751 #endif
2752 /* Usbdevfs */
2753 HANDLE_IOCTL(USBDEVFS_CONTROL32, do_usbdevfs_control)
2754 HANDLE_IOCTL(USBDEVFS_BULK32, do_usbdevfs_bulk)
2755 HANDLE_IOCTL(USBDEVFS_DISCSIGNAL32, do_usbdevfs_discsignal)
2756 COMPATIBLE_IOCTL(USBDEVFS_IOCTL32)
2757 /* i2c */
2758 HANDLE_IOCTL(I2C_FUNCS, w_long)
2759 HANDLE_IOCTL(I2C_RDWR, do_i2c_rdwr_ioctl)
2760 HANDLE_IOCTL(I2C_SMBUS, do_i2c_smbus_ioctl)
2761 /* wireless */
2762 HANDLE_IOCTL(SIOCGIWRANGE, do_wireless_ioctl)
2763 HANDLE_IOCTL(SIOCSIWSPY, do_wireless_ioctl)
2764 HANDLE_IOCTL(SIOCGIWSPY, do_wireless_ioctl)
2765 HANDLE_IOCTL(SIOCSIWTHRSPY, do_wireless_ioctl)
2766 HANDLE_IOCTL(SIOCGIWTHRSPY, do_wireless_ioctl)
2767 HANDLE_IOCTL(SIOCGIWAPLIST, do_wireless_ioctl)
2768 HANDLE_IOCTL(SIOCGIWSCAN, do_wireless_ioctl)
2769 HANDLE_IOCTL(SIOCSIWESSID, do_wireless_ioctl)
2770 HANDLE_IOCTL(SIOCGIWESSID, do_wireless_ioctl)
2771 HANDLE_IOCTL(SIOCSIWNICKN, do_wireless_ioctl)
2772 HANDLE_IOCTL(SIOCGIWNICKN, do_wireless_ioctl)
2773 HANDLE_IOCTL(SIOCSIWENCODE, do_wireless_ioctl)
2774 HANDLE_IOCTL(SIOCGIWENCODE, do_wireless_ioctl)
2775 HANDLE_IOCTL(SIOCSIFBR, old_bridge_ioctl)
2776 HANDLE_IOCTL(SIOCGIFBR, old_bridge_ioctl)
2777 HANDLE_IOCTL(RTC_IRQP_READ32, rtc_ioctl)
2778 HANDLE_IOCTL(RTC_IRQP_SET32, rtc_ioctl)
2779 HANDLE_IOCTL(RTC_EPOCH_READ32, rtc_ioctl)
2780 HANDLE_IOCTL(RTC_EPOCH_SET32, rtc_ioctl)
2781
2782 #if defined(CONFIG_NCP_FS) || defined(CONFIG_NCP_FS_MODULE)
2783 HANDLE_IOCTL(NCP_IOC_NCPREQUEST_32, do_ncp_ncprequest)
2784 HANDLE_IOCTL(NCP_IOC_GETMOUNTUID2_32, do_ncp_getmountuid2)
2785 HANDLE_IOCTL(NCP_IOC_GET_FS_INFO_V2_32, do_ncp_getfsinfo2)
2786 HANDLE_IOCTL(NCP_IOC_GETOBJECTNAME_32, do_ncp_getobjectname)
2787 HANDLE_IOCTL(NCP_IOC_SETOBJECTNAME_32, do_ncp_setobjectname)
2788 HANDLE_IOCTL(NCP_IOC_GETPRIVATEDATA_32, do_ncp_getprivatedata)
2789 HANDLE_IOCTL(NCP_IOC_SETPRIVATEDATA_32, do_ncp_setprivatedata)
2790 #endif
2791
2792 /* dvb */
2793 HANDLE_IOCTL(VIDEO_GET_EVENT, do_video_get_event)
2794 HANDLE_IOCTL(VIDEO_STILLPICTURE, do_video_stillpicture)
2795 HANDLE_IOCTL(VIDEO_SET_SPU_PALETTE, do_video_set_spu_palette)
2796
2797 /* parport */
2798 COMPATIBLE_IOCTL(LPTIME)
2799 COMPATIBLE_IOCTL(LPCHAR)
2800 COMPATIBLE_IOCTL(LPABORTOPEN)
2801 COMPATIBLE_IOCTL(LPCAREFUL)
2802 COMPATIBLE_IOCTL(LPWAIT)
2803 COMPATIBLE_IOCTL(LPSETIRQ)
2804 COMPATIBLE_IOCTL(LPGETSTATUS)
2805 COMPATIBLE_IOCTL(LPGETSTATUS)
2806 COMPATIBLE_IOCTL(LPRESET)
2807 /*LPGETSTATS not implemented, but no kernels seem to compile it in anyways*/
2808 COMPATIBLE_IOCTL(LPGETFLAGS)
2809 HANDLE_IOCTL(LPSETTIMEOUT, lp_timeout_trans)
2810 };
2811
2812 int ioctl_table_size = ARRAY_SIZE(ioctl_start);