]> git.proxmox.com Git - mirror_ubuntu-artful-kernel.git/blame - fs/read_write.c
aio_setup_vectored_rw(): switch to {compat_,}import_iovec()
[mirror_ubuntu-artful-kernel.git] / fs / read_write.c
CommitLineData
1da177e4
LT
1/*
2 * linux/fs/read_write.c
3 *
4 * Copyright (C) 1991, 1992 Linus Torvalds
5 */
6
7#include <linux/slab.h>
8#include <linux/stat.h>
9#include <linux/fcntl.h>
10#include <linux/file.h>
11#include <linux/uio.h>
0eeca283 12#include <linux/fsnotify.h>
1da177e4 13#include <linux/security.h>
630d9c47 14#include <linux/export.h>
1da177e4 15#include <linux/syscalls.h>
e28cc715 16#include <linux/pagemap.h>
d6b29d7c 17#include <linux/splice.h>
561c6731 18#include <linux/compat.h>
06ae43f3 19#include "internal.h"
1da177e4
LT
20
21#include <asm/uaccess.h>
22#include <asm/unistd.h>
23
c0bd14af
AV
24typedef ssize_t (*io_fn_t)(struct file *, char __user *, size_t, loff_t *);
25typedef ssize_t (*iov_fn_t)(struct kiocb *, const struct iovec *,
26 unsigned long, loff_t);
293bc982 27typedef ssize_t (*iter_fn_t)(struct kiocb *, struct iov_iter *);
c0bd14af 28
4b6f5d20 29const struct file_operations generic_ro_fops = {
1da177e4 30 .llseek = generic_file_llseek,
aad4f8bb
AV
31 .read = new_sync_read,
32 .read_iter = generic_file_read_iter,
1da177e4 33 .mmap = generic_file_readonly_mmap,
534f2aaa 34 .splice_read = generic_file_splice_read,
1da177e4
LT
35};
36
37EXPORT_SYMBOL(generic_ro_fops);
38
cccb5a1e 39static inline int unsigned_offsets(struct file *file)
4a3956c7 40{
cccb5a1e 41 return file->f_mode & FMODE_UNSIGNED_OFFSET;
4a3956c7
KH
42}
43
46a1c2c7
JL
44/**
45 * vfs_setpos - update the file offset for lseek
46 * @file: file structure in question
47 * @offset: file offset to seek to
48 * @maxsize: maximum file size
49 *
50 * This is a low-level filesystem helper for updating the file offset to
51 * the value specified by @offset if the given offset is valid and it is
52 * not equal to the current file offset.
53 *
54 * Return the specified offset on success and -EINVAL on invalid offset.
55 */
56loff_t vfs_setpos(struct file *file, loff_t offset, loff_t maxsize)
ef3d0fd2
AK
57{
58 if (offset < 0 && !unsigned_offsets(file))
59 return -EINVAL;
60 if (offset > maxsize)
61 return -EINVAL;
62
63 if (offset != file->f_pos) {
64 file->f_pos = offset;
65 file->f_version = 0;
66 }
67 return offset;
68}
46a1c2c7 69EXPORT_SYMBOL(vfs_setpos);
ef3d0fd2 70
3a8cff4f 71/**
5760495a 72 * generic_file_llseek_size - generic llseek implementation for regular files
3a8cff4f
CH
73 * @file: file structure to seek on
74 * @offset: file offset to seek to
965c8e59 75 * @whence: type of seek
e8b96eb5
ES
76 * @size: max size of this file in file system
77 * @eof: offset used for SEEK_END position
3a8cff4f 78 *
5760495a 79 * This is a variant of generic_file_llseek that allows passing in a custom
e8b96eb5 80 * maximum file size and a custom EOF position, for e.g. hashed directories
ef3d0fd2
AK
81 *
82 * Synchronization:
5760495a 83 * SEEK_SET and SEEK_END are unsynchronized (but atomic on 64bit platforms)
ef3d0fd2
AK
84 * SEEK_CUR is synchronized against other SEEK_CURs, but not read/writes.
85 * read/writes behave like SEEK_SET against seeks.
3a8cff4f 86 */
9465efc9 87loff_t
965c8e59 88generic_file_llseek_size(struct file *file, loff_t offset, int whence,
e8b96eb5 89 loff_t maxsize, loff_t eof)
1da177e4 90{
965c8e59 91 switch (whence) {
3a8cff4f 92 case SEEK_END:
e8b96eb5 93 offset += eof;
3a8cff4f
CH
94 break;
95 case SEEK_CUR:
5b6f1eb9
AK
96 /*
97 * Here we special-case the lseek(fd, 0, SEEK_CUR)
98 * position-querying operation. Avoid rewriting the "same"
99 * f_pos value back to the file because a concurrent read(),
100 * write() or lseek() might have altered it
101 */
102 if (offset == 0)
103 return file->f_pos;
ef3d0fd2
AK
104 /*
105 * f_lock protects against read/modify/write race with other
106 * SEEK_CURs. Note that parallel writes and reads behave
107 * like SEEK_SET.
108 */
109 spin_lock(&file->f_lock);
46a1c2c7 110 offset = vfs_setpos(file, file->f_pos + offset, maxsize);
ef3d0fd2
AK
111 spin_unlock(&file->f_lock);
112 return offset;
982d8165
JB
113 case SEEK_DATA:
114 /*
115 * In the generic case the entire file is data, so as long as
116 * offset isn't at the end of the file then the offset is data.
117 */
e8b96eb5 118 if (offset >= eof)
982d8165
JB
119 return -ENXIO;
120 break;
121 case SEEK_HOLE:
122 /*
123 * There is a virtual hole at the end of the file, so as long as
124 * offset isn't i_size or larger, return i_size.
125 */
e8b96eb5 126 if (offset >= eof)
982d8165 127 return -ENXIO;
e8b96eb5 128 offset = eof;
982d8165 129 break;
1da177e4 130 }
3a8cff4f 131
46a1c2c7 132 return vfs_setpos(file, offset, maxsize);
5760495a
AK
133}
134EXPORT_SYMBOL(generic_file_llseek_size);
135
136/**
137 * generic_file_llseek - generic llseek implementation for regular files
138 * @file: file structure to seek on
139 * @offset: file offset to seek to
965c8e59 140 * @whence: type of seek
5760495a
AK
141 *
142 * This is a generic implemenation of ->llseek useable for all normal local
143 * filesystems. It just updates the file offset to the value specified by
546ae2d2 144 * @offset and @whence.
5760495a 145 */
965c8e59 146loff_t generic_file_llseek(struct file *file, loff_t offset, int whence)
5760495a
AK
147{
148 struct inode *inode = file->f_mapping->host;
149
965c8e59 150 return generic_file_llseek_size(file, offset, whence,
e8b96eb5
ES
151 inode->i_sb->s_maxbytes,
152 i_size_read(inode));
1da177e4 153}
9465efc9 154EXPORT_SYMBOL(generic_file_llseek);
1da177e4 155
1bf9d14d
AV
156/**
157 * fixed_size_llseek - llseek implementation for fixed-sized devices
158 * @file: file structure to seek on
159 * @offset: file offset to seek to
160 * @whence: type of seek
161 * @size: size of the file
162 *
163 */
164loff_t fixed_size_llseek(struct file *file, loff_t offset, int whence, loff_t size)
165{
166 switch (whence) {
167 case SEEK_SET: case SEEK_CUR: case SEEK_END:
168 return generic_file_llseek_size(file, offset, whence,
169 size, size);
170 default:
171 return -EINVAL;
172 }
173}
174EXPORT_SYMBOL(fixed_size_llseek);
175
ae6afc3f
B
176/**
177 * noop_llseek - No Operation Performed llseek implementation
178 * @file: file structure to seek on
179 * @offset: file offset to seek to
965c8e59 180 * @whence: type of seek
ae6afc3f
B
181 *
182 * This is an implementation of ->llseek useable for the rare special case when
183 * userspace expects the seek to succeed but the (device) file is actually not
184 * able to perform the seek. In this case you use noop_llseek() instead of
185 * falling back to the default implementation of ->llseek.
186 */
965c8e59 187loff_t noop_llseek(struct file *file, loff_t offset, int whence)
ae6afc3f
B
188{
189 return file->f_pos;
190}
191EXPORT_SYMBOL(noop_llseek);
192
965c8e59 193loff_t no_llseek(struct file *file, loff_t offset, int whence)
1da177e4
LT
194{
195 return -ESPIPE;
196}
197EXPORT_SYMBOL(no_llseek);
198
965c8e59 199loff_t default_llseek(struct file *file, loff_t offset, int whence)
1da177e4 200{
496ad9aa 201 struct inode *inode = file_inode(file);
16abef0e 202 loff_t retval;
1da177e4 203
982d8165 204 mutex_lock(&inode->i_mutex);
965c8e59 205 switch (whence) {
7b8e8924 206 case SEEK_END:
982d8165 207 offset += i_size_read(inode);
1da177e4 208 break;
7b8e8924 209 case SEEK_CUR:
5b6f1eb9
AK
210 if (offset == 0) {
211 retval = file->f_pos;
212 goto out;
213 }
1da177e4 214 offset += file->f_pos;
982d8165
JB
215 break;
216 case SEEK_DATA:
217 /*
218 * In the generic case the entire file is data, so as
219 * long as offset isn't at the end of the file then the
220 * offset is data.
221 */
bacb2d81
DC
222 if (offset >= inode->i_size) {
223 retval = -ENXIO;
224 goto out;
225 }
982d8165
JB
226 break;
227 case SEEK_HOLE:
228 /*
229 * There is a virtual hole at the end of the file, so
230 * as long as offset isn't i_size or larger, return
231 * i_size.
232 */
bacb2d81
DC
233 if (offset >= inode->i_size) {
234 retval = -ENXIO;
235 goto out;
236 }
982d8165
JB
237 offset = inode->i_size;
238 break;
1da177e4
LT
239 }
240 retval = -EINVAL;
cccb5a1e 241 if (offset >= 0 || unsigned_offsets(file)) {
1da177e4
LT
242 if (offset != file->f_pos) {
243 file->f_pos = offset;
244 file->f_version = 0;
245 }
246 retval = offset;
247 }
5b6f1eb9 248out:
982d8165 249 mutex_unlock(&inode->i_mutex);
1da177e4
LT
250 return retval;
251}
252EXPORT_SYMBOL(default_llseek);
253
965c8e59 254loff_t vfs_llseek(struct file *file, loff_t offset, int whence)
1da177e4
LT
255{
256 loff_t (*fn)(struct file *, loff_t, int);
257
258 fn = no_llseek;
259 if (file->f_mode & FMODE_LSEEK) {
72c2d531 260 if (file->f_op->llseek)
1da177e4
LT
261 fn = file->f_op->llseek;
262 }
965c8e59 263 return fn(file, offset, whence);
1da177e4
LT
264}
265EXPORT_SYMBOL(vfs_llseek);
266
9c225f26
LT
267static inline struct fd fdget_pos(int fd)
268{
bd2a31d5 269 return __to_fd(__fdget_pos(fd));
9c225f26
LT
270}
271
272static inline void fdput_pos(struct fd f)
273{
274 if (f.flags & FDPUT_POS_UNLOCK)
275 mutex_unlock(&f.file->f_pos_lock);
276 fdput(f);
277}
278
965c8e59 279SYSCALL_DEFINE3(lseek, unsigned int, fd, off_t, offset, unsigned int, whence)
1da177e4
LT
280{
281 off_t retval;
9c225f26 282 struct fd f = fdget_pos(fd);
2903ff01
AV
283 if (!f.file)
284 return -EBADF;
1da177e4
LT
285
286 retval = -EINVAL;
965c8e59
AM
287 if (whence <= SEEK_MAX) {
288 loff_t res = vfs_llseek(f.file, offset, whence);
1da177e4
LT
289 retval = res;
290 if (res != (loff_t)retval)
291 retval = -EOVERFLOW; /* LFS: should only happen on 32 bit platforms */
292 }
9c225f26 293 fdput_pos(f);
1da177e4
LT
294 return retval;
295}
296
561c6731
AV
297#ifdef CONFIG_COMPAT
298COMPAT_SYSCALL_DEFINE3(lseek, unsigned int, fd, compat_off_t, offset, unsigned int, whence)
299{
300 return sys_lseek(fd, offset, whence);
301}
302#endif
303
1da177e4 304#ifdef __ARCH_WANT_SYS_LLSEEK
003d7ab4
HC
305SYSCALL_DEFINE5(llseek, unsigned int, fd, unsigned long, offset_high,
306 unsigned long, offset_low, loff_t __user *, result,
965c8e59 307 unsigned int, whence)
1da177e4
LT
308{
309 int retval;
d7a15f8d 310 struct fd f = fdget_pos(fd);
1da177e4 311 loff_t offset;
1da177e4 312
2903ff01
AV
313 if (!f.file)
314 return -EBADF;
1da177e4
LT
315
316 retval = -EINVAL;
965c8e59 317 if (whence > SEEK_MAX)
1da177e4
LT
318 goto out_putf;
319
2903ff01 320 offset = vfs_llseek(f.file, ((loff_t) offset_high << 32) | offset_low,
965c8e59 321 whence);
1da177e4
LT
322
323 retval = (int)offset;
324 if (offset >= 0) {
325 retval = -EFAULT;
326 if (!copy_to_user(result, &offset, sizeof(offset)))
327 retval = 0;
328 }
329out_putf:
d7a15f8d 330 fdput_pos(f);
1da177e4
LT
331 return retval;
332}
333#endif
334
dbe4e192
CH
335ssize_t vfs_iter_read(struct file *file, struct iov_iter *iter, loff_t *ppos)
336{
337 struct kiocb kiocb;
338 ssize_t ret;
339
340 if (!file->f_op->read_iter)
341 return -EINVAL;
342
343 init_sync_kiocb(&kiocb, file);
344 kiocb.ki_pos = *ppos;
dbe4e192
CH
345
346 iter->type |= READ;
347 ret = file->f_op->read_iter(&kiocb, iter);
599bd19b 348 BUG_ON(ret == -EIOCBQUEUED);
dbe4e192
CH
349 if (ret > 0)
350 *ppos = kiocb.ki_pos;
351 return ret;
352}
353EXPORT_SYMBOL(vfs_iter_read);
354
355ssize_t vfs_iter_write(struct file *file, struct iov_iter *iter, loff_t *ppos)
356{
357 struct kiocb kiocb;
358 ssize_t ret;
359
360 if (!file->f_op->write_iter)
361 return -EINVAL;
362
363 init_sync_kiocb(&kiocb, file);
364 kiocb.ki_pos = *ppos;
dbe4e192
CH
365
366 iter->type |= WRITE;
367 ret = file->f_op->write_iter(&kiocb, iter);
599bd19b 368 BUG_ON(ret == -EIOCBQUEUED);
dbe4e192
CH
369 if (ret > 0)
370 *ppos = kiocb.ki_pos;
371 return ret;
372}
373EXPORT_SYMBOL(vfs_iter_write);
374
e28cc715
LT
375/*
376 * rw_verify_area doesn't like huge counts. We limit
377 * them to something that fits in "int" so that others
378 * won't have to do range checks all the time.
379 */
68d70d03 380int rw_verify_area(int read_write, struct file *file, const loff_t *ppos, size_t count)
1da177e4
LT
381{
382 struct inode *inode;
383 loff_t pos;
c43e259c 384 int retval = -EINVAL;
1da177e4 385
496ad9aa 386 inode = file_inode(file);
e28cc715 387 if (unlikely((ssize_t) count < 0))
c43e259c 388 return retval;
1da177e4 389 pos = *ppos;
cccb5a1e
AV
390 if (unlikely(pos < 0)) {
391 if (!unsigned_offsets(file))
392 return retval;
393 if (count >= -pos) /* both values are in 0..LLONG_MAX */
394 return -EOVERFLOW;
395 } else if (unlikely((loff_t) (pos + count) < 0)) {
396 if (!unsigned_offsets(file))
4a3956c7
KH
397 return retval;
398 }
1da177e4 399
bd61e0a9 400 if (unlikely(inode->i_flctx && mandatory_lock(inode))) {
c43e259c 401 retval = locks_mandatory_area(
e28cc715
LT
402 read_write == READ ? FLOCK_VERIFY_READ : FLOCK_VERIFY_WRITE,
403 inode, file, pos, count);
404 if (retval < 0)
405 return retval;
406 }
c43e259c
JM
407 retval = security_file_permission(file,
408 read_write == READ ? MAY_READ : MAY_WRITE);
409 if (retval)
410 return retval;
e28cc715 411 return count > MAX_RW_COUNT ? MAX_RW_COUNT : count;
1da177e4
LT
412}
413
414ssize_t do_sync_read(struct file *filp, char __user *buf, size_t len, loff_t *ppos)
415{
027445c3 416 struct iovec iov = { .iov_base = buf, .iov_len = len };
1da177e4
LT
417 struct kiocb kiocb;
418 ssize_t ret;
419
420 init_sync_kiocb(&kiocb, filp);
421 kiocb.ki_pos = *ppos;
027445c3 422
41003a7b 423 ret = filp->f_op->aio_read(&kiocb, &iov, 1, kiocb.ki_pos);
599bd19b 424 BUG_ON(ret == -EIOCBQUEUED);
1da177e4
LT
425 *ppos = kiocb.ki_pos;
426 return ret;
427}
428
429EXPORT_SYMBOL(do_sync_read);
430
293bc982
AV
431ssize_t new_sync_read(struct file *filp, char __user *buf, size_t len, loff_t *ppos)
432{
433 struct iovec iov = { .iov_base = buf, .iov_len = len };
434 struct kiocb kiocb;
435 struct iov_iter iter;
436 ssize_t ret;
437
438 init_sync_kiocb(&kiocb, filp);
439 kiocb.ki_pos = *ppos;
293bc982
AV
440 iov_iter_init(&iter, READ, &iov, 1, len);
441
442 ret = filp->f_op->read_iter(&kiocb, &iter);
599bd19b 443 BUG_ON(ret == -EIOCBQUEUED);
293bc982
AV
444 *ppos = kiocb.ki_pos;
445 return ret;
446}
447
448EXPORT_SYMBOL(new_sync_read);
449
6fb5032e
DK
450ssize_t __vfs_read(struct file *file, char __user *buf, size_t count,
451 loff_t *pos)
452{
453 ssize_t ret;
454
455 if (file->f_op->read)
456 ret = file->f_op->read(file, buf, count, pos);
457 else if (file->f_op->aio_read)
458 ret = do_sync_read(file, buf, count, pos);
459 else if (file->f_op->read_iter)
460 ret = new_sync_read(file, buf, count, pos);
461 else
462 ret = -EINVAL;
463
464 return ret;
465}
466
1da177e4
LT
467ssize_t vfs_read(struct file *file, char __user *buf, size_t count, loff_t *pos)
468{
469 ssize_t ret;
470
471 if (!(file->f_mode & FMODE_READ))
472 return -EBADF;
7f7f25e8 473 if (!(file->f_mode & FMODE_CAN_READ))
1da177e4
LT
474 return -EINVAL;
475 if (unlikely(!access_ok(VERIFY_WRITE, buf, count)))
476 return -EFAULT;
477
478 ret = rw_verify_area(READ, file, pos, count);
e28cc715
LT
479 if (ret >= 0) {
480 count = ret;
6fb5032e 481 ret = __vfs_read(file, buf, count, pos);
c43e259c 482 if (ret > 0) {
2a12a9d7 483 fsnotify_access(file);
c43e259c 484 add_rchar(current, ret);
1da177e4 485 }
c43e259c 486 inc_syscr(current);
1da177e4
LT
487 }
488
489 return ret;
490}
491
492EXPORT_SYMBOL(vfs_read);
493
494ssize_t do_sync_write(struct file *filp, const char __user *buf, size_t len, loff_t *ppos)
495{
027445c3 496 struct iovec iov = { .iov_base = (void __user *)buf, .iov_len = len };
1da177e4
LT
497 struct kiocb kiocb;
498 ssize_t ret;
499
500 init_sync_kiocb(&kiocb, filp);
501 kiocb.ki_pos = *ppos;
027445c3 502
41003a7b 503 ret = filp->f_op->aio_write(&kiocb, &iov, 1, kiocb.ki_pos);
599bd19b 504 BUG_ON(ret == -EIOCBQUEUED);
1da177e4
LT
505 *ppos = kiocb.ki_pos;
506 return ret;
507}
508
509EXPORT_SYMBOL(do_sync_write);
510
293bc982
AV
511ssize_t new_sync_write(struct file *filp, const char __user *buf, size_t len, loff_t *ppos)
512{
513 struct iovec iov = { .iov_base = (void __user *)buf, .iov_len = len };
514 struct kiocb kiocb;
515 struct iov_iter iter;
516 ssize_t ret;
517
518 init_sync_kiocb(&kiocb, filp);
519 kiocb.ki_pos = *ppos;
293bc982
AV
520 iov_iter_init(&iter, WRITE, &iov, 1, len);
521
522 ret = filp->f_op->write_iter(&kiocb, &iter);
599bd19b 523 BUG_ON(ret == -EIOCBQUEUED);
293bc982
AV
524 *ppos = kiocb.ki_pos;
525 return ret;
526}
527
528EXPORT_SYMBOL(new_sync_write);
529
06ae43f3
AV
530ssize_t __kernel_write(struct file *file, const char *buf, size_t count, loff_t *pos)
531{
532 mm_segment_t old_fs;
533 const char __user *p;
534 ssize_t ret;
535
7f7f25e8 536 if (!(file->f_mode & FMODE_CAN_WRITE))
3e84f48e
AV
537 return -EINVAL;
538
06ae43f3
AV
539 old_fs = get_fs();
540 set_fs(get_ds());
541 p = (__force const char __user *)buf;
542 if (count > MAX_RW_COUNT)
543 count = MAX_RW_COUNT;
544 if (file->f_op->write)
545 ret = file->f_op->write(file, p, count, pos);
293bc982 546 else if (file->f_op->aio_write)
06ae43f3 547 ret = do_sync_write(file, p, count, pos);
293bc982
AV
548 else
549 ret = new_sync_write(file, p, count, pos);
06ae43f3
AV
550 set_fs(old_fs);
551 if (ret > 0) {
552 fsnotify_modify(file);
553 add_wchar(current, ret);
554 }
555 inc_syscw(current);
556 return ret;
557}
558
2ec3a12a
AV
559EXPORT_SYMBOL(__kernel_write);
560
1da177e4
LT
561ssize_t vfs_write(struct file *file, const char __user *buf, size_t count, loff_t *pos)
562{
563 ssize_t ret;
564
565 if (!(file->f_mode & FMODE_WRITE))
566 return -EBADF;
7f7f25e8 567 if (!(file->f_mode & FMODE_CAN_WRITE))
1da177e4
LT
568 return -EINVAL;
569 if (unlikely(!access_ok(VERIFY_READ, buf, count)))
570 return -EFAULT;
571
572 ret = rw_verify_area(WRITE, file, pos, count);
e28cc715
LT
573 if (ret >= 0) {
574 count = ret;
03d95eb2 575 file_start_write(file);
c43e259c
JM
576 if (file->f_op->write)
577 ret = file->f_op->write(file, buf, count, pos);
293bc982 578 else if (file->f_op->aio_write)
c43e259c 579 ret = do_sync_write(file, buf, count, pos);
293bc982
AV
580 else
581 ret = new_sync_write(file, buf, count, pos);
c43e259c 582 if (ret > 0) {
2a12a9d7 583 fsnotify_modify(file);
c43e259c 584 add_wchar(current, ret);
1da177e4 585 }
c43e259c 586 inc_syscw(current);
03d95eb2 587 file_end_write(file);
1da177e4
LT
588 }
589
590 return ret;
591}
592
593EXPORT_SYMBOL(vfs_write);
594
595static inline loff_t file_pos_read(struct file *file)
596{
597 return file->f_pos;
598}
599
600static inline void file_pos_write(struct file *file, loff_t pos)
601{
602 file->f_pos = pos;
603}
604
3cdad428 605SYSCALL_DEFINE3(read, unsigned int, fd, char __user *, buf, size_t, count)
1da177e4 606{
9c225f26 607 struct fd f = fdget_pos(fd);
1da177e4 608 ssize_t ret = -EBADF;
1da177e4 609
2903ff01
AV
610 if (f.file) {
611 loff_t pos = file_pos_read(f.file);
612 ret = vfs_read(f.file, buf, count, &pos);
5faf153e
AV
613 if (ret >= 0)
614 file_pos_write(f.file, pos);
9c225f26 615 fdput_pos(f);
1da177e4 616 }
1da177e4
LT
617 return ret;
618}
1da177e4 619
3cdad428
HC
620SYSCALL_DEFINE3(write, unsigned int, fd, const char __user *, buf,
621 size_t, count)
1da177e4 622{
9c225f26 623 struct fd f = fdget_pos(fd);
1da177e4 624 ssize_t ret = -EBADF;
1da177e4 625
2903ff01
AV
626 if (f.file) {
627 loff_t pos = file_pos_read(f.file);
628 ret = vfs_write(f.file, buf, count, &pos);
5faf153e
AV
629 if (ret >= 0)
630 file_pos_write(f.file, pos);
9c225f26 631 fdput_pos(f);
1da177e4
LT
632 }
633
634 return ret;
635}
636
4a0fd5bf
AV
637SYSCALL_DEFINE4(pread64, unsigned int, fd, char __user *, buf,
638 size_t, count, loff_t, pos)
1da177e4 639{
2903ff01 640 struct fd f;
1da177e4 641 ssize_t ret = -EBADF;
1da177e4
LT
642
643 if (pos < 0)
644 return -EINVAL;
645
2903ff01
AV
646 f = fdget(fd);
647 if (f.file) {
1da177e4 648 ret = -ESPIPE;
2903ff01
AV
649 if (f.file->f_mode & FMODE_PREAD)
650 ret = vfs_read(f.file, buf, count, &pos);
651 fdput(f);
1da177e4
LT
652 }
653
654 return ret;
655}
656
4a0fd5bf
AV
657SYSCALL_DEFINE4(pwrite64, unsigned int, fd, const char __user *, buf,
658 size_t, count, loff_t, pos)
1da177e4 659{
2903ff01 660 struct fd f;
1da177e4 661 ssize_t ret = -EBADF;
1da177e4
LT
662
663 if (pos < 0)
664 return -EINVAL;
665
2903ff01
AV
666 f = fdget(fd);
667 if (f.file) {
1da177e4 668 ret = -ESPIPE;
2903ff01
AV
669 if (f.file->f_mode & FMODE_PWRITE)
670 ret = vfs_write(f.file, buf, count, &pos);
671 fdput(f);
1da177e4
LT
672 }
673
674 return ret;
675}
676
677/*
678 * Reduce an iovec's length in-place. Return the resulting number of segments
679 */
680unsigned long iov_shorten(struct iovec *iov, unsigned long nr_segs, size_t to)
681{
682 unsigned long seg = 0;
683 size_t len = 0;
684
685 while (seg < nr_segs) {
686 seg++;
687 if (len + iov->iov_len >= to) {
688 iov->iov_len = to - len;
689 break;
690 }
691 len += iov->iov_len;
692 iov++;
693 }
694 return seg;
695}
19295529 696EXPORT_SYMBOL(iov_shorten);
1da177e4 697
ac15ac06
AV
698static ssize_t do_iter_readv_writev(struct file *filp, struct iov_iter *iter,
699 loff_t *ppos, iter_fn_t fn)
293bc982
AV
700{
701 struct kiocb kiocb;
293bc982
AV
702 ssize_t ret;
703
704 init_sync_kiocb(&kiocb, filp);
705 kiocb.ki_pos = *ppos;
293bc982 706
ac15ac06 707 ret = fn(&kiocb, iter);
599bd19b 708 BUG_ON(ret == -EIOCBQUEUED);
293bc982
AV
709 *ppos = kiocb.ki_pos;
710 return ret;
711}
712
ac15ac06
AV
713static ssize_t do_sync_readv_writev(struct file *filp, struct iov_iter *iter,
714 loff_t *ppos, iov_fn_t fn)
ee0b3e67
BP
715{
716 struct kiocb kiocb;
717 ssize_t ret;
718
719 init_sync_kiocb(&kiocb, filp);
720 kiocb.ki_pos = *ppos;
ee0b3e67 721
ac15ac06 722 ret = fn(&kiocb, iter->iov, iter->nr_segs, kiocb.ki_pos);
599bd19b 723 BUG_ON(ret == -EIOCBQUEUED);
ee0b3e67
BP
724 *ppos = kiocb.ki_pos;
725 return ret;
726}
727
728/* Do it by hand, with file-ops */
ac15ac06
AV
729static ssize_t do_loop_readv_writev(struct file *filp, struct iov_iter *iter,
730 loff_t *ppos, io_fn_t fn)
ee0b3e67 731{
ee0b3e67
BP
732 ssize_t ret = 0;
733
ac15ac06
AV
734 while (iov_iter_count(iter)) {
735 struct iovec iovec = iov_iter_iovec(iter);
ee0b3e67
BP
736 ssize_t nr;
737
ac15ac06 738 nr = fn(filp, iovec.iov_base, iovec.iov_len, ppos);
ee0b3e67
BP
739
740 if (nr < 0) {
741 if (!ret)
742 ret = nr;
743 break;
744 }
745 ret += nr;
ac15ac06 746 if (nr != iovec.iov_len)
ee0b3e67 747 break;
ac15ac06 748 iov_iter_advance(iter, nr);
ee0b3e67
BP
749 }
750
751 return ret;
752}
753
1da177e4
LT
754/* A write operation does a read from user space and vice versa */
755#define vrfy_dir(type) ((type) == READ ? VERIFY_WRITE : VERIFY_READ)
756
eed4e51f
BP
757ssize_t rw_copy_check_uvector(int type, const struct iovec __user * uvector,
758 unsigned long nr_segs, unsigned long fast_segs,
759 struct iovec *fast_pointer,
ac34ebb3 760 struct iovec **ret_pointer)
435f49a5 761{
eed4e51f 762 unsigned long seg;
435f49a5 763 ssize_t ret;
eed4e51f
BP
764 struct iovec *iov = fast_pointer;
765
435f49a5
LT
766 /*
767 * SuS says "The readv() function *may* fail if the iovcnt argument
768 * was less than or equal to 0, or greater than {IOV_MAX}. Linux has
769 * traditionally returned zero for zero segments, so...
770 */
eed4e51f
BP
771 if (nr_segs == 0) {
772 ret = 0;
435f49a5 773 goto out;
eed4e51f
BP
774 }
775
435f49a5
LT
776 /*
777 * First get the "struct iovec" from user memory and
778 * verify all the pointers
779 */
eed4e51f
BP
780 if (nr_segs > UIO_MAXIOV) {
781 ret = -EINVAL;
435f49a5 782 goto out;
eed4e51f
BP
783 }
784 if (nr_segs > fast_segs) {
435f49a5 785 iov = kmalloc(nr_segs*sizeof(struct iovec), GFP_KERNEL);
eed4e51f
BP
786 if (iov == NULL) {
787 ret = -ENOMEM;
435f49a5 788 goto out;
eed4e51f 789 }
435f49a5 790 }
eed4e51f
BP
791 if (copy_from_user(iov, uvector, nr_segs*sizeof(*uvector))) {
792 ret = -EFAULT;
435f49a5 793 goto out;
eed4e51f
BP
794 }
795
435f49a5 796 /*
eed4e51f
BP
797 * According to the Single Unix Specification we should return EINVAL
798 * if an element length is < 0 when cast to ssize_t or if the
799 * total length would overflow the ssize_t return value of the
800 * system call.
435f49a5
LT
801 *
802 * Linux caps all read/write calls to MAX_RW_COUNT, and avoids the
803 * overflow case.
804 */
eed4e51f 805 ret = 0;
435f49a5
LT
806 for (seg = 0; seg < nr_segs; seg++) {
807 void __user *buf = iov[seg].iov_base;
808 ssize_t len = (ssize_t)iov[seg].iov_len;
eed4e51f
BP
809
810 /* see if we we're about to use an invalid len or if
811 * it's about to overflow ssize_t */
435f49a5 812 if (len < 0) {
eed4e51f 813 ret = -EINVAL;
435f49a5 814 goto out;
eed4e51f 815 }
ac34ebb3 816 if (type >= 0
fcf63409 817 && unlikely(!access_ok(vrfy_dir(type), buf, len))) {
eed4e51f 818 ret = -EFAULT;
435f49a5
LT
819 goto out;
820 }
821 if (len > MAX_RW_COUNT - ret) {
822 len = MAX_RW_COUNT - ret;
823 iov[seg].iov_len = len;
eed4e51f 824 }
eed4e51f 825 ret += len;
435f49a5 826 }
eed4e51f
BP
827out:
828 *ret_pointer = iov;
829 return ret;
830}
831
1da177e4
LT
832static ssize_t do_readv_writev(int type, struct file *file,
833 const struct iovec __user * uvector,
834 unsigned long nr_segs, loff_t *pos)
835{
1da177e4
LT
836 size_t tot_len;
837 struct iovec iovstack[UIO_FASTIOV];
ee0b3e67 838 struct iovec *iov = iovstack;
ac15ac06 839 struct iov_iter iter;
1da177e4 840 ssize_t ret;
1da177e4
LT
841 io_fn_t fn;
842 iov_fn_t fnv;
293bc982 843 iter_fn_t iter_fn;
1da177e4 844
eed4e51f 845 ret = rw_copy_check_uvector(type, uvector, nr_segs,
ac34ebb3 846 ARRAY_SIZE(iovstack), iovstack, &iov);
eed4e51f 847 if (ret <= 0)
1da177e4 848 goto out;
ac15ac06 849 iov_iter_init(&iter, type, iov, nr_segs, ret);
1da177e4 850
eed4e51f 851 tot_len = ret;
1da177e4 852 ret = rw_verify_area(type, file, pos, tot_len);
e28cc715 853 if (ret < 0)
411b67b4 854 goto out;
1da177e4
LT
855
856 fnv = NULL;
857 if (type == READ) {
858 fn = file->f_op->read;
ee0b3e67 859 fnv = file->f_op->aio_read;
293bc982 860 iter_fn = file->f_op->read_iter;
1da177e4
LT
861 } else {
862 fn = (io_fn_t)file->f_op->write;
ee0b3e67 863 fnv = file->f_op->aio_write;
293bc982 864 iter_fn = file->f_op->write_iter;
03d95eb2 865 file_start_write(file);
1da177e4
LT
866 }
867
293bc982 868 if (iter_fn)
ac15ac06 869 ret = do_iter_readv_writev(file, &iter, pos, iter_fn);
293bc982 870 else if (fnv)
ac15ac06 871 ret = do_sync_readv_writev(file, &iter, pos, fnv);
ee0b3e67 872 else
ac15ac06 873 ret = do_loop_readv_writev(file, &iter, pos, fn);
1da177e4 874
03d95eb2
AV
875 if (type != READ)
876 file_end_write(file);
877
1da177e4
LT
878out:
879 if (iov != iovstack)
880 kfree(iov);
0eeca283
RL
881 if ((ret + (type == READ)) > 0) {
882 if (type == READ)
2a12a9d7 883 fsnotify_access(file);
0eeca283 884 else
2a12a9d7 885 fsnotify_modify(file);
0eeca283 886 }
1da177e4 887 return ret;
1da177e4
LT
888}
889
890ssize_t vfs_readv(struct file *file, const struct iovec __user *vec,
891 unsigned long vlen, loff_t *pos)
892{
893 if (!(file->f_mode & FMODE_READ))
894 return -EBADF;
7f7f25e8 895 if (!(file->f_mode & FMODE_CAN_READ))
1da177e4
LT
896 return -EINVAL;
897
898 return do_readv_writev(READ, file, vec, vlen, pos);
899}
900
901EXPORT_SYMBOL(vfs_readv);
902
903ssize_t vfs_writev(struct file *file, const struct iovec __user *vec,
904 unsigned long vlen, loff_t *pos)
905{
906 if (!(file->f_mode & FMODE_WRITE))
907 return -EBADF;
7f7f25e8 908 if (!(file->f_mode & FMODE_CAN_WRITE))
1da177e4
LT
909 return -EINVAL;
910
911 return do_readv_writev(WRITE, file, vec, vlen, pos);
912}
913
914EXPORT_SYMBOL(vfs_writev);
915
3cdad428
HC
916SYSCALL_DEFINE3(readv, unsigned long, fd, const struct iovec __user *, vec,
917 unsigned long, vlen)
1da177e4 918{
9c225f26 919 struct fd f = fdget_pos(fd);
1da177e4 920 ssize_t ret = -EBADF;
1da177e4 921
2903ff01
AV
922 if (f.file) {
923 loff_t pos = file_pos_read(f.file);
924 ret = vfs_readv(f.file, vec, vlen, &pos);
5faf153e
AV
925 if (ret >= 0)
926 file_pos_write(f.file, pos);
9c225f26 927 fdput_pos(f);
1da177e4
LT
928 }
929
930 if (ret > 0)
4b98d11b
AD
931 add_rchar(current, ret);
932 inc_syscr(current);
1da177e4
LT
933 return ret;
934}
935
3cdad428
HC
936SYSCALL_DEFINE3(writev, unsigned long, fd, const struct iovec __user *, vec,
937 unsigned long, vlen)
1da177e4 938{
9c225f26 939 struct fd f = fdget_pos(fd);
1da177e4 940 ssize_t ret = -EBADF;
1da177e4 941
2903ff01
AV
942 if (f.file) {
943 loff_t pos = file_pos_read(f.file);
944 ret = vfs_writev(f.file, vec, vlen, &pos);
5faf153e
AV
945 if (ret >= 0)
946 file_pos_write(f.file, pos);
9c225f26 947 fdput_pos(f);
1da177e4
LT
948 }
949
950 if (ret > 0)
4b98d11b
AD
951 add_wchar(current, ret);
952 inc_syscw(current);
1da177e4
LT
953 return ret;
954}
955
601cc11d
LT
956static inline loff_t pos_from_hilo(unsigned long high, unsigned long low)
957{
958#define HALF_LONG_BITS (BITS_PER_LONG / 2)
959 return (((loff_t)high << HALF_LONG_BITS) << HALF_LONG_BITS) | low;
960}
961
f3554f4b 962SYSCALL_DEFINE5(preadv, unsigned long, fd, const struct iovec __user *, vec,
601cc11d 963 unsigned long, vlen, unsigned long, pos_l, unsigned long, pos_h)
f3554f4b 964{
601cc11d 965 loff_t pos = pos_from_hilo(pos_h, pos_l);
2903ff01 966 struct fd f;
f3554f4b 967 ssize_t ret = -EBADF;
f3554f4b
GH
968
969 if (pos < 0)
970 return -EINVAL;
971
2903ff01
AV
972 f = fdget(fd);
973 if (f.file) {
f3554f4b 974 ret = -ESPIPE;
2903ff01
AV
975 if (f.file->f_mode & FMODE_PREAD)
976 ret = vfs_readv(f.file, vec, vlen, &pos);
977 fdput(f);
f3554f4b
GH
978 }
979
980 if (ret > 0)
981 add_rchar(current, ret);
982 inc_syscr(current);
983 return ret;
984}
985
986SYSCALL_DEFINE5(pwritev, unsigned long, fd, const struct iovec __user *, vec,
601cc11d 987 unsigned long, vlen, unsigned long, pos_l, unsigned long, pos_h)
f3554f4b 988{
601cc11d 989 loff_t pos = pos_from_hilo(pos_h, pos_l);
2903ff01 990 struct fd f;
f3554f4b 991 ssize_t ret = -EBADF;
f3554f4b
GH
992
993 if (pos < 0)
994 return -EINVAL;
995
2903ff01
AV
996 f = fdget(fd);
997 if (f.file) {
f3554f4b 998 ret = -ESPIPE;
2903ff01
AV
999 if (f.file->f_mode & FMODE_PWRITE)
1000 ret = vfs_writev(f.file, vec, vlen, &pos);
1001 fdput(f);
f3554f4b
GH
1002 }
1003
1004 if (ret > 0)
1005 add_wchar(current, ret);
1006 inc_syscw(current);
1007 return ret;
1008}
1009
72ec3516
AV
1010#ifdef CONFIG_COMPAT
1011
1012static ssize_t compat_do_readv_writev(int type, struct file *file,
1013 const struct compat_iovec __user *uvector,
1014 unsigned long nr_segs, loff_t *pos)
1015{
1016 compat_ssize_t tot_len;
1017 struct iovec iovstack[UIO_FASTIOV];
1018 struct iovec *iov = iovstack;
ac15ac06 1019 struct iov_iter iter;
72ec3516
AV
1020 ssize_t ret;
1021 io_fn_t fn;
1022 iov_fn_t fnv;
293bc982 1023 iter_fn_t iter_fn;
72ec3516 1024
72ec3516
AV
1025 ret = compat_rw_copy_check_uvector(type, uvector, nr_segs,
1026 UIO_FASTIOV, iovstack, &iov);
1027 if (ret <= 0)
1028 goto out;
ac15ac06 1029 iov_iter_init(&iter, type, iov, nr_segs, ret);
72ec3516
AV
1030
1031 tot_len = ret;
1032 ret = rw_verify_area(type, file, pos, tot_len);
1033 if (ret < 0)
1034 goto out;
1035
1036 fnv = NULL;
1037 if (type == READ) {
1038 fn = file->f_op->read;
1039 fnv = file->f_op->aio_read;
293bc982 1040 iter_fn = file->f_op->read_iter;
72ec3516
AV
1041 } else {
1042 fn = (io_fn_t)file->f_op->write;
1043 fnv = file->f_op->aio_write;
293bc982 1044 iter_fn = file->f_op->write_iter;
03d95eb2 1045 file_start_write(file);
72ec3516
AV
1046 }
1047
293bc982 1048 if (iter_fn)
ac15ac06 1049 ret = do_iter_readv_writev(file, &iter, pos, iter_fn);
293bc982 1050 else if (fnv)
ac15ac06 1051 ret = do_sync_readv_writev(file, &iter, pos, fnv);
03d95eb2 1052 else
ac15ac06 1053 ret = do_loop_readv_writev(file, &iter, pos, fn);
72ec3516 1054
03d95eb2
AV
1055 if (type != READ)
1056 file_end_write(file);
1057
72ec3516
AV
1058out:
1059 if (iov != iovstack)
1060 kfree(iov);
1061 if ((ret + (type == READ)) > 0) {
1062 if (type == READ)
1063 fsnotify_access(file);
1064 else
1065 fsnotify_modify(file);
1066 }
1067 return ret;
1068}
1069
1070static size_t compat_readv(struct file *file,
1071 const struct compat_iovec __user *vec,
1072 unsigned long vlen, loff_t *pos)
1073{
1074 ssize_t ret = -EBADF;
1075
1076 if (!(file->f_mode & FMODE_READ))
1077 goto out;
1078
1079 ret = -EINVAL;
7f7f25e8 1080 if (!(file->f_mode & FMODE_CAN_READ))
72ec3516
AV
1081 goto out;
1082
1083 ret = compat_do_readv_writev(READ, file, vec, vlen, pos);
1084
1085out:
1086 if (ret > 0)
1087 add_rchar(current, ret);
1088 inc_syscr(current);
1089 return ret;
1090}
1091
dfd948e3 1092COMPAT_SYSCALL_DEFINE3(readv, compat_ulong_t, fd,
72ec3516 1093 const struct compat_iovec __user *,vec,
dfd948e3 1094 compat_ulong_t, vlen)
72ec3516 1095{
9c225f26 1096 struct fd f = fdget_pos(fd);
72ec3516
AV
1097 ssize_t ret;
1098 loff_t pos;
1099
1100 if (!f.file)
1101 return -EBADF;
1102 pos = f.file->f_pos;
1103 ret = compat_readv(f.file, vec, vlen, &pos);
5faf153e
AV
1104 if (ret >= 0)
1105 f.file->f_pos = pos;
9c225f26 1106 fdput_pos(f);
72ec3516
AV
1107 return ret;
1108}
1109
378a10f3
HC
1110static long __compat_sys_preadv64(unsigned long fd,
1111 const struct compat_iovec __user *vec,
1112 unsigned long vlen, loff_t pos)
72ec3516
AV
1113{
1114 struct fd f;
1115 ssize_t ret;
1116
1117 if (pos < 0)
1118 return -EINVAL;
1119 f = fdget(fd);
1120 if (!f.file)
1121 return -EBADF;
1122 ret = -ESPIPE;
1123 if (f.file->f_mode & FMODE_PREAD)
1124 ret = compat_readv(f.file, vec, vlen, &pos);
1125 fdput(f);
1126 return ret;
1127}
1128
378a10f3
HC
1129#ifdef __ARCH_WANT_COMPAT_SYS_PREADV64
1130COMPAT_SYSCALL_DEFINE4(preadv64, unsigned long, fd,
1131 const struct compat_iovec __user *,vec,
1132 unsigned long, vlen, loff_t, pos)
1133{
1134 return __compat_sys_preadv64(fd, vec, vlen, pos);
1135}
1136#endif
1137
dfd948e3 1138COMPAT_SYSCALL_DEFINE5(preadv, compat_ulong_t, fd,
72ec3516 1139 const struct compat_iovec __user *,vec,
dfd948e3 1140 compat_ulong_t, vlen, u32, pos_low, u32, pos_high)
72ec3516
AV
1141{
1142 loff_t pos = ((loff_t)pos_high << 32) | pos_low;
378a10f3
HC
1143
1144 return __compat_sys_preadv64(fd, vec, vlen, pos);
72ec3516
AV
1145}
1146
1147static size_t compat_writev(struct file *file,
1148 const struct compat_iovec __user *vec,
1149 unsigned long vlen, loff_t *pos)
1150{
1151 ssize_t ret = -EBADF;
1152
1153 if (!(file->f_mode & FMODE_WRITE))
1154 goto out;
1155
1156 ret = -EINVAL;
7f7f25e8 1157 if (!(file->f_mode & FMODE_CAN_WRITE))
72ec3516
AV
1158 goto out;
1159
1160 ret = compat_do_readv_writev(WRITE, file, vec, vlen, pos);
1161
1162out:
1163 if (ret > 0)
1164 add_wchar(current, ret);
1165 inc_syscw(current);
1166 return ret;
1167}
1168
dfd948e3 1169COMPAT_SYSCALL_DEFINE3(writev, compat_ulong_t, fd,
72ec3516 1170 const struct compat_iovec __user *, vec,
dfd948e3 1171 compat_ulong_t, vlen)
72ec3516 1172{
9c225f26 1173 struct fd f = fdget_pos(fd);
72ec3516
AV
1174 ssize_t ret;
1175 loff_t pos;
1176
1177 if (!f.file)
1178 return -EBADF;
1179 pos = f.file->f_pos;
1180 ret = compat_writev(f.file, vec, vlen, &pos);
5faf153e
AV
1181 if (ret >= 0)
1182 f.file->f_pos = pos;
9c225f26 1183 fdput_pos(f);
72ec3516
AV
1184 return ret;
1185}
1186
378a10f3
HC
1187static long __compat_sys_pwritev64(unsigned long fd,
1188 const struct compat_iovec __user *vec,
1189 unsigned long vlen, loff_t pos)
72ec3516
AV
1190{
1191 struct fd f;
1192 ssize_t ret;
1193
1194 if (pos < 0)
1195 return -EINVAL;
1196 f = fdget(fd);
1197 if (!f.file)
1198 return -EBADF;
1199 ret = -ESPIPE;
1200 if (f.file->f_mode & FMODE_PWRITE)
1201 ret = compat_writev(f.file, vec, vlen, &pos);
1202 fdput(f);
1203 return ret;
1204}
1205
378a10f3
HC
1206#ifdef __ARCH_WANT_COMPAT_SYS_PWRITEV64
1207COMPAT_SYSCALL_DEFINE4(pwritev64, unsigned long, fd,
1208 const struct compat_iovec __user *,vec,
1209 unsigned long, vlen, loff_t, pos)
1210{
1211 return __compat_sys_pwritev64(fd, vec, vlen, pos);
1212}
1213#endif
1214
dfd948e3 1215COMPAT_SYSCALL_DEFINE5(pwritev, compat_ulong_t, fd,
72ec3516 1216 const struct compat_iovec __user *,vec,
dfd948e3 1217 compat_ulong_t, vlen, u32, pos_low, u32, pos_high)
72ec3516
AV
1218{
1219 loff_t pos = ((loff_t)pos_high << 32) | pos_low;
378a10f3
HC
1220
1221 return __compat_sys_pwritev64(fd, vec, vlen, pos);
72ec3516
AV
1222}
1223#endif
1224
19f4fc3a
AV
1225static ssize_t do_sendfile(int out_fd, int in_fd, loff_t *ppos,
1226 size_t count, loff_t max)
1da177e4 1227{
2903ff01
AV
1228 struct fd in, out;
1229 struct inode *in_inode, *out_inode;
1da177e4 1230 loff_t pos;
7995bd28 1231 loff_t out_pos;
1da177e4 1232 ssize_t retval;
2903ff01 1233 int fl;
1da177e4
LT
1234
1235 /*
1236 * Get input file, and verify that it is ok..
1237 */
1238 retval = -EBADF;
2903ff01
AV
1239 in = fdget(in_fd);
1240 if (!in.file)
1da177e4 1241 goto out;
2903ff01 1242 if (!(in.file->f_mode & FMODE_READ))
1da177e4 1243 goto fput_in;
1da177e4 1244 retval = -ESPIPE;
7995bd28
AV
1245 if (!ppos) {
1246 pos = in.file->f_pos;
1247 } else {
1248 pos = *ppos;
2903ff01 1249 if (!(in.file->f_mode & FMODE_PREAD))
1da177e4 1250 goto fput_in;
7995bd28
AV
1251 }
1252 retval = rw_verify_area(READ, in.file, &pos, count);
e28cc715 1253 if (retval < 0)
1da177e4 1254 goto fput_in;
e28cc715 1255 count = retval;
1da177e4 1256
1da177e4
LT
1257 /*
1258 * Get output file, and verify that it is ok..
1259 */
1260 retval = -EBADF;
2903ff01
AV
1261 out = fdget(out_fd);
1262 if (!out.file)
1da177e4 1263 goto fput_in;
2903ff01 1264 if (!(out.file->f_mode & FMODE_WRITE))
1da177e4
LT
1265 goto fput_out;
1266 retval = -EINVAL;
496ad9aa
AV
1267 in_inode = file_inode(in.file);
1268 out_inode = file_inode(out.file);
7995bd28
AV
1269 out_pos = out.file->f_pos;
1270 retval = rw_verify_area(WRITE, out.file, &out_pos, count);
e28cc715 1271 if (retval < 0)
1da177e4 1272 goto fput_out;
e28cc715 1273 count = retval;
1da177e4 1274
1da177e4
LT
1275 if (!max)
1276 max = min(in_inode->i_sb->s_maxbytes, out_inode->i_sb->s_maxbytes);
1277
1da177e4
LT
1278 if (unlikely(pos + count > max)) {
1279 retval = -EOVERFLOW;
1280 if (pos >= max)
1281 goto fput_out;
1282 count = max - pos;
1283 }
1284
d96e6e71 1285 fl = 0;
534f2aaa 1286#if 0
d96e6e71
JA
1287 /*
1288 * We need to debate whether we can enable this or not. The
1289 * man page documents EAGAIN return for the output at least,
1290 * and the application is arguably buggy if it doesn't expect
1291 * EAGAIN on a non-blocking file descriptor.
1292 */
2903ff01 1293 if (in.file->f_flags & O_NONBLOCK)
d96e6e71 1294 fl = SPLICE_F_NONBLOCK;
534f2aaa 1295#endif
50cd2c57 1296 file_start_write(out.file);
7995bd28 1297 retval = do_splice_direct(in.file, &pos, out.file, &out_pos, count, fl);
50cd2c57 1298 file_end_write(out.file);
1da177e4
LT
1299
1300 if (retval > 0) {
4b98d11b
AD
1301 add_rchar(current, retval);
1302 add_wchar(current, retval);
a68c2f12
SW
1303 fsnotify_access(in.file);
1304 fsnotify_modify(out.file);
7995bd28
AV
1305 out.file->f_pos = out_pos;
1306 if (ppos)
1307 *ppos = pos;
1308 else
1309 in.file->f_pos = pos;
1da177e4 1310 }
1da177e4 1311
4b98d11b
AD
1312 inc_syscr(current);
1313 inc_syscw(current);
7995bd28 1314 if (pos > max)
1da177e4
LT
1315 retval = -EOVERFLOW;
1316
1317fput_out:
2903ff01 1318 fdput(out);
1da177e4 1319fput_in:
2903ff01 1320 fdput(in);
1da177e4
LT
1321out:
1322 return retval;
1323}
1324
002c8976 1325SYSCALL_DEFINE4(sendfile, int, out_fd, int, in_fd, off_t __user *, offset, size_t, count)
1da177e4
LT
1326{
1327 loff_t pos;
1328 off_t off;
1329 ssize_t ret;
1330
1331 if (offset) {
1332 if (unlikely(get_user(off, offset)))
1333 return -EFAULT;
1334 pos = off;
1335 ret = do_sendfile(out_fd, in_fd, &pos, count, MAX_NON_LFS);
1336 if (unlikely(put_user(pos, offset)))
1337 return -EFAULT;
1338 return ret;
1339 }
1340
1341 return do_sendfile(out_fd, in_fd, NULL, count, 0);
1342}
1343
002c8976 1344SYSCALL_DEFINE4(sendfile64, int, out_fd, int, in_fd, loff_t __user *, offset, size_t, count)
1da177e4
LT
1345{
1346 loff_t pos;
1347 ssize_t ret;
1348
1349 if (offset) {
1350 if (unlikely(copy_from_user(&pos, offset, sizeof(loff_t))))
1351 return -EFAULT;
1352 ret = do_sendfile(out_fd, in_fd, &pos, count, 0);
1353 if (unlikely(put_user(pos, offset)))
1354 return -EFAULT;
1355 return ret;
1356 }
1357
1358 return do_sendfile(out_fd, in_fd, NULL, count, 0);
1359}
19f4fc3a
AV
1360
1361#ifdef CONFIG_COMPAT
1362COMPAT_SYSCALL_DEFINE4(sendfile, int, out_fd, int, in_fd,
1363 compat_off_t __user *, offset, compat_size_t, count)
1364{
1365 loff_t pos;
1366 off_t off;
1367 ssize_t ret;
1368
1369 if (offset) {
1370 if (unlikely(get_user(off, offset)))
1371 return -EFAULT;
1372 pos = off;
1373 ret = do_sendfile(out_fd, in_fd, &pos, count, MAX_NON_LFS);
1374 if (unlikely(put_user(pos, offset)))
1375 return -EFAULT;
1376 return ret;
1377 }
1378
1379 return do_sendfile(out_fd, in_fd, NULL, count, 0);
1380}
1381
1382COMPAT_SYSCALL_DEFINE4(sendfile64, int, out_fd, int, in_fd,
1383 compat_loff_t __user *, offset, compat_size_t, count)
1384{
1385 loff_t pos;
1386 ssize_t ret;
1387
1388 if (offset) {
1389 if (unlikely(copy_from_user(&pos, offset, sizeof(loff_t))))
1390 return -EFAULT;
1391 ret = do_sendfile(out_fd, in_fd, &pos, count, 0);
1392 if (unlikely(put_user(pos, offset)))
1393 return -EFAULT;
1394 return ret;
1395 }
1396
1397 return do_sendfile(out_fd, in_fd, NULL, count, 0);
1398}
1399#endif