blob: 8f2cada4f7c916d9d88fb87cbb390cf99e4b793e [file] [log] [blame]
Linus Torvalds1da177e2005-04-16 15:20:36 -07001/*
2 * include/asm-s390/uaccess.h
3 *
4 * S390 version
5 * Copyright (C) 1999,2000 IBM Deutschland Entwicklung GmbH, IBM Corporation
6 * Author(s): Hartmut Penner (hp@de.ibm.com),
7 * Martin Schwidefsky (schwidefsky@de.ibm.com)
8 *
9 * Derived from "include/asm-i386/uaccess.h"
10 */
11#ifndef __S390_UACCESS_H
12#define __S390_UACCESS_H
13
14/*
15 * User space memory access functions
16 */
17#include <linux/sched.h>
18#include <linux/errno.h>
David Howellsa0616cd2012-03-28 18:30:02 +010019#include <asm/ctl_reg.h>
Linus Torvalds1da177e2005-04-16 15:20:36 -070020
21#define VERIFY_READ 0
22#define VERIFY_WRITE 1
23
24
25/*
26 * The fs value determines whether argument validity checking should be
27 * performed or not. If get_fs() == USER_DS, checking is performed, with
28 * get_fs() == KERNEL_DS, checking is bypassed.
29 *
30 * For historical reasons, these macros are grossly misnamed.
31 */
32
33#define MAKE_MM_SEG(a) ((mm_segment_t) { (a) })
34
35
36#define KERNEL_DS MAKE_MM_SEG(0)
37#define USER_DS MAKE_MM_SEG(1)
38
39#define get_ds() (KERNEL_DS)
40#define get_fs() (current->thread.mm_segment)
41
Linus Torvalds1da177e2005-04-16 15:20:36 -070042#define set_fs(x) \
43({ \
44 unsigned long __pto; \
45 current->thread.mm_segment = (x); \
46 __pto = current->thread.mm_segment.ar4 ? \
47 S390_lowcore.user_asce : S390_lowcore.kernel_asce; \
Martin Schwidefsky94c12cc2006-09-28 16:56:43 +020048 __ctl_load(__pto, 7, 7); \
Linus Torvalds1da177e2005-04-16 15:20:36 -070049})
Linus Torvalds1da177e2005-04-16 15:20:36 -070050
51#define segment_eq(a,b) ((a).ar4 == (b).ar4)
52
Heiko Carstens7683f742011-05-26 09:48:25 +020053#define __access_ok(addr, size) \
54({ \
55 __chk_user_ptr(addr); \
56 1; \
57})
Linus Torvalds1da177e2005-04-16 15:20:36 -070058
Heiko Carstens7683f742011-05-26 09:48:25 +020059#define access_ok(type, addr, size) __access_ok(addr, size)
Linus Torvalds1da177e2005-04-16 15:20:36 -070060
Linus Torvalds1da177e2005-04-16 15:20:36 -070061/*
62 * The exception table consists of pairs of addresses: the first is the
63 * address of an instruction that is allowed to fault, and the second is
64 * the address at which the program should continue. No registers are
65 * modified, so it is entirely up to the continuation code to figure out
66 * what to do.
67 *
68 * All the routines below use bits of fixup code that are out of line
69 * with the main instruction path. This means when everything is well,
70 * we don't even have to jump over them. Further, they do not intrude
71 * on our cache or tlb entries.
72 */
73
74struct exception_table_entry
75{
76 unsigned long insn, fixup;
77};
78
Gerald Schaeferd02765d2006-09-20 15:59:42 +020079struct uaccess_ops {
80 size_t (*copy_from_user)(size_t, const void __user *, void *);
81 size_t (*copy_from_user_small)(size_t, const void __user *, void *);
82 size_t (*copy_to_user)(size_t, void __user *, const void *);
83 size_t (*copy_to_user_small)(size_t, void __user *, const void *);
84 size_t (*copy_in_user)(size_t, void __user *, const void __user *);
85 size_t (*clear_user)(size_t, void __user *);
86 size_t (*strnlen_user)(size_t, const char __user *);
87 size_t (*strncpy_from_user)(size_t, const char __user *, char *);
Michel Lespinasse8d7718a2011-03-10 18:50:58 -080088 int (*futex_atomic_op)(int op, u32 __user *, int oparg, int *old);
89 int (*futex_atomic_cmpxchg)(u32 *, u32 __user *, u32 old, u32 new);
Gerald Schaeferd02765d2006-09-20 15:59:42 +020090};
91
92extern struct uaccess_ops uaccess;
93extern struct uaccess_ops uaccess_std;
Gerald Schaefer6c2a9e62006-09-20 15:59:44 +020094extern struct uaccess_ops uaccess_mvcos;
Gerald Schaeferc1821c22007-02-05 21:18:17 +010095extern struct uaccess_ops uaccess_mvcos_switch;
96extern struct uaccess_ops uaccess_pt;
Gerald Schaeferd02765d2006-09-20 15:59:42 +020097
Gerald Schaefer6c1e3e72009-12-07 12:51:47 +010098extern int __handle_fault(unsigned long, unsigned long, int);
99
Gerald Schaeferd02765d2006-09-20 15:59:42 +0200100static inline int __put_user_fn(size_t size, void __user *ptr, void *x)
101{
102 size = uaccess.copy_to_user_small(size, ptr, x);
103 return size ? -EFAULT : size;
104}
105
106static inline int __get_user_fn(size_t size, const void __user *ptr, void *x)
107{
108 size = uaccess.copy_from_user_small(size, ptr, x);
109 return size ? -EFAULT : size;
110}
Linus Torvalds1da177e2005-04-16 15:20:36 -0700111
112/*
113 * These are the main single-value transfer routines. They automatically
114 * use the right size if we just have the right pointer type.
115 */
Linus Torvalds1da177e2005-04-16 15:20:36 -0700116#define __put_user(x, ptr) \
117({ \
118 __typeof__(*(ptr)) __x = (x); \
Gerald Schaeferd02765d2006-09-20 15:59:42 +0200119 int __pu_err = -EFAULT; \
Al Viro17566c32005-08-23 22:48:22 +0100120 __chk_user_ptr(ptr); \
Linus Torvalds1da177e2005-04-16 15:20:36 -0700121 switch (sizeof (*(ptr))) { \
122 case 1: \
123 case 2: \
124 case 4: \
125 case 8: \
Gerald Schaeferd02765d2006-09-20 15:59:42 +0200126 __pu_err = __put_user_fn(sizeof (*(ptr)), \
127 ptr, &__x); \
Linus Torvalds1da177e2005-04-16 15:20:36 -0700128 break; \
129 default: \
130 __put_user_bad(); \
131 break; \
132 } \
133 __pu_err; \
134})
Linus Torvalds1da177e2005-04-16 15:20:36 -0700135
136#define put_user(x, ptr) \
137({ \
Heiko Carstensdab4079d2009-06-12 10:26:32 +0200138 might_fault(); \
Linus Torvalds1da177e2005-04-16 15:20:36 -0700139 __put_user(x, ptr); \
140})
141
142
143extern int __put_user_bad(void) __attribute__((noreturn));
144
Linus Torvalds1da177e2005-04-16 15:20:36 -0700145#define __get_user(x, ptr) \
146({ \
Gerald Schaeferd02765d2006-09-20 15:59:42 +0200147 int __gu_err = -EFAULT; \
148 __chk_user_ptr(ptr); \
Linus Torvalds1da177e2005-04-16 15:20:36 -0700149 switch (sizeof(*(ptr))) { \
Martin Schwidefsky1047aa72005-11-07 00:59:11 -0800150 case 1: { \
151 unsigned char __x; \
Gerald Schaeferd02765d2006-09-20 15:59:42 +0200152 __gu_err = __get_user_fn(sizeof (*(ptr)), \
153 ptr, &__x); \
Al Viro97fa5a62006-02-03 20:11:52 -0500154 (x) = *(__force __typeof__(*(ptr)) *) &__x; \
Linus Torvalds1da177e2005-04-16 15:20:36 -0700155 break; \
Martin Schwidefsky1047aa72005-11-07 00:59:11 -0800156 }; \
157 case 2: { \
158 unsigned short __x; \
Gerald Schaeferd02765d2006-09-20 15:59:42 +0200159 __gu_err = __get_user_fn(sizeof (*(ptr)), \
160 ptr, &__x); \
Al Viro97fa5a62006-02-03 20:11:52 -0500161 (x) = *(__force __typeof__(*(ptr)) *) &__x; \
Martin Schwidefsky1047aa72005-11-07 00:59:11 -0800162 break; \
163 }; \
164 case 4: { \
165 unsigned int __x; \
Gerald Schaeferd02765d2006-09-20 15:59:42 +0200166 __gu_err = __get_user_fn(sizeof (*(ptr)), \
167 ptr, &__x); \
Al Viro97fa5a62006-02-03 20:11:52 -0500168 (x) = *(__force __typeof__(*(ptr)) *) &__x; \
Martin Schwidefsky1047aa72005-11-07 00:59:11 -0800169 break; \
170 }; \
171 case 8: { \
172 unsigned long long __x; \
Gerald Schaeferd02765d2006-09-20 15:59:42 +0200173 __gu_err = __get_user_fn(sizeof (*(ptr)), \
174 ptr, &__x); \
Al Viro97fa5a62006-02-03 20:11:52 -0500175 (x) = *(__force __typeof__(*(ptr)) *) &__x; \
Martin Schwidefsky1047aa72005-11-07 00:59:11 -0800176 break; \
177 }; \
Linus Torvalds1da177e2005-04-16 15:20:36 -0700178 default: \
179 __get_user_bad(); \
180 break; \
181 } \
Linus Torvalds1da177e2005-04-16 15:20:36 -0700182 __gu_err; \
183})
Linus Torvalds1da177e2005-04-16 15:20:36 -0700184
185#define get_user(x, ptr) \
186({ \
Heiko Carstensdab4079d2009-06-12 10:26:32 +0200187 might_fault(); \
Linus Torvalds1da177e2005-04-16 15:20:36 -0700188 __get_user(x, ptr); \
189})
190
191extern int __get_user_bad(void) __attribute__((noreturn));
192
193#define __put_user_unaligned __put_user
194#define __get_user_unaligned __get_user
195
Linus Torvalds1da177e2005-04-16 15:20:36 -0700196/**
197 * __copy_to_user: - Copy a block of data into user space, with less checking.
198 * @to: Destination address, in user space.
199 * @from: Source address, in kernel space.
200 * @n: Number of bytes to copy.
201 *
202 * Context: User context only. This function may sleep.
203 *
204 * Copy data from kernel space to user space. Caller must check
205 * the specified block with access_ok() before calling this function.
206 *
207 * Returns number of bytes that could not be copied.
208 * On success, this will be zero.
209 */
Heiko Carstensf7675ad2006-12-04 15:39:55 +0100210static inline unsigned long __must_check
Linus Torvalds1da177e2005-04-16 15:20:36 -0700211__copy_to_user(void __user *to, const void *from, unsigned long n)
212{
Gerald Schaeferd02765d2006-09-20 15:59:42 +0200213 if (__builtin_constant_p(n) && (n <= 256))
214 return uaccess.copy_to_user_small(n, to, from);
215 else
216 return uaccess.copy_to_user(n, to, from);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700217}
218
219#define __copy_to_user_inatomic __copy_to_user
220#define __copy_from_user_inatomic __copy_from_user
221
222/**
223 * copy_to_user: - Copy a block of data into user space.
224 * @to: Destination address, in user space.
225 * @from: Source address, in kernel space.
226 * @n: Number of bytes to copy.
227 *
228 * Context: User context only. This function may sleep.
229 *
230 * Copy data from kernel space to user space.
231 *
232 * Returns number of bytes that could not be copied.
233 * On success, this will be zero.
234 */
Heiko Carstensf7675ad2006-12-04 15:39:55 +0100235static inline unsigned long __must_check
Linus Torvalds1da177e2005-04-16 15:20:36 -0700236copy_to_user(void __user *to, const void *from, unsigned long n)
237{
Heiko Carstensdab4079d2009-06-12 10:26:32 +0200238 might_fault();
Linus Torvalds1da177e2005-04-16 15:20:36 -0700239 if (access_ok(VERIFY_WRITE, to, n))
240 n = __copy_to_user(to, from, n);
241 return n;
242}
243
Linus Torvalds1da177e2005-04-16 15:20:36 -0700244/**
245 * __copy_from_user: - Copy a block of data from user space, with less checking.
246 * @to: Destination address, in kernel space.
247 * @from: Source address, in user space.
248 * @n: Number of bytes to copy.
249 *
250 * Context: User context only. This function may sleep.
251 *
252 * Copy data from user space to kernel space. Caller must check
253 * the specified block with access_ok() before calling this function.
254 *
255 * Returns number of bytes that could not be copied.
256 * On success, this will be zero.
257 *
258 * If some data could not be copied, this function will pad the copied
259 * data to the requested size using zero bytes.
260 */
Heiko Carstensf7675ad2006-12-04 15:39:55 +0100261static inline unsigned long __must_check
Linus Torvalds1da177e2005-04-16 15:20:36 -0700262__copy_from_user(void *to, const void __user *from, unsigned long n)
263{
Gerald Schaeferd02765d2006-09-20 15:59:42 +0200264 if (__builtin_constant_p(n) && (n <= 256))
265 return uaccess.copy_from_user_small(n, from, to);
266 else
267 return uaccess.copy_from_user(n, from, to);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700268}
269
Heiko Carstens1dcec252010-02-26 22:37:22 +0100270extern void copy_from_user_overflow(void)
271#ifdef CONFIG_DEBUG_STRICT_USER_COPY_CHECKS
272__compiletime_warning("copy_from_user() buffer size is not provably correct")
273#endif
274;
275
Linus Torvalds1da177e2005-04-16 15:20:36 -0700276/**
277 * copy_from_user: - Copy a block of data from user space.
278 * @to: Destination address, in kernel space.
279 * @from: Source address, in user space.
280 * @n: Number of bytes to copy.
281 *
282 * Context: User context only. This function may sleep.
283 *
284 * Copy data from user space to kernel space.
285 *
286 * Returns number of bytes that could not be copied.
287 * On success, this will be zero.
288 *
289 * If some data could not be copied, this function will pad the copied
290 * data to the requested size using zero bytes.
291 */
Heiko Carstensf7675ad2006-12-04 15:39:55 +0100292static inline unsigned long __must_check
Linus Torvalds1da177e2005-04-16 15:20:36 -0700293copy_from_user(void *to, const void __user *from, unsigned long n)
294{
Heiko Carstens1dcec252010-02-26 22:37:22 +0100295 unsigned int sz = __compiletime_object_size(to);
296
Heiko Carstensdab4079d2009-06-12 10:26:32 +0200297 might_fault();
Heiko Carstens1dcec252010-02-26 22:37:22 +0100298 if (unlikely(sz != -1 && sz < n)) {
299 copy_from_user_overflow();
300 return n;
301 }
Linus Torvalds1da177e2005-04-16 15:20:36 -0700302 if (access_ok(VERIFY_READ, from, n))
303 n = __copy_from_user(to, from, n);
304 else
305 memset(to, 0, n);
306 return n;
307}
308
Heiko Carstensf7675ad2006-12-04 15:39:55 +0100309static inline unsigned long __must_check
Linus Torvalds1da177e2005-04-16 15:20:36 -0700310__copy_in_user(void __user *to, const void __user *from, unsigned long n)
311{
Gerald Schaeferd02765d2006-09-20 15:59:42 +0200312 return uaccess.copy_in_user(n, to, from);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700313}
314
Heiko Carstensf7675ad2006-12-04 15:39:55 +0100315static inline unsigned long __must_check
Linus Torvalds1da177e2005-04-16 15:20:36 -0700316copy_in_user(void __user *to, const void __user *from, unsigned long n)
317{
Heiko Carstensdab4079d2009-06-12 10:26:32 +0200318 might_fault();
Linus Torvalds1da177e2005-04-16 15:20:36 -0700319 if (__access_ok(from,n) && __access_ok(to,n))
Gerald Schaeferd02765d2006-09-20 15:59:42 +0200320 n = __copy_in_user(to, from, n);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700321 return n;
322}
323
324/*
325 * Copy a null terminated string from userspace.
326 */
Heiko Carstensf7675ad2006-12-04 15:39:55 +0100327static inline long __must_check
Linus Torvalds1da177e2005-04-16 15:20:36 -0700328strncpy_from_user(char *dst, const char __user *src, long count)
329{
330 long res = -EFAULT;
Heiko Carstensdab4079d2009-06-12 10:26:32 +0200331 might_fault();
Linus Torvalds1da177e2005-04-16 15:20:36 -0700332 if (access_ok(VERIFY_READ, src, 1))
Gerald Schaeferd02765d2006-09-20 15:59:42 +0200333 res = uaccess.strncpy_from_user(count, src, dst);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700334 return res;
335}
336
Linus Torvalds1da177e2005-04-16 15:20:36 -0700337static inline unsigned long
338strnlen_user(const char __user * src, unsigned long n)
339{
Heiko Carstensdab4079d2009-06-12 10:26:32 +0200340 might_fault();
Gerald Schaeferd02765d2006-09-20 15:59:42 +0200341 return uaccess.strnlen_user(n, src);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700342}
343
344/**
345 * strlen_user: - Get the size of a string in user space.
346 * @str: The string to measure.
347 *
348 * Context: User context only. This function may sleep.
349 *
350 * Get the size of a NUL-terminated string in user space.
351 *
352 * Returns the size of the string INCLUDING the terminating NUL.
353 * On exception, returns 0.
354 *
355 * If there is a limit on the length of a valid string, you may wish to
356 * consider using strnlen_user() instead.
357 */
358#define strlen_user(str) strnlen_user(str, ~0UL)
359
360/*
361 * Zero Userspace
362 */
363
Heiko Carstensf7675ad2006-12-04 15:39:55 +0100364static inline unsigned long __must_check
Linus Torvalds1da177e2005-04-16 15:20:36 -0700365__clear_user(void __user *to, unsigned long n)
366{
Gerald Schaeferd02765d2006-09-20 15:59:42 +0200367 return uaccess.clear_user(n, to);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700368}
369
Heiko Carstensf7675ad2006-12-04 15:39:55 +0100370static inline unsigned long __must_check
Linus Torvalds1da177e2005-04-16 15:20:36 -0700371clear_user(void __user *to, unsigned long n)
372{
Heiko Carstensdab4079d2009-06-12 10:26:32 +0200373 might_fault();
Linus Torvalds1da177e2005-04-16 15:20:36 -0700374 if (access_ok(VERIFY_WRITE, to, n))
Gerald Schaeferd02765d2006-09-20 15:59:42 +0200375 n = uaccess.clear_user(n, to);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700376 return n;
377}
378
David Howellsa0616cd2012-03-28 18:30:02 +0100379extern int memcpy_real(void *, void *, size_t);
380extern void copy_to_absolute_zero(void *dest, void *src, size_t count);
381extern int copy_to_user_real(void __user *dest, void *src, size_t count);
382extern int copy_from_user_real(void *dest, void __user *src, size_t count);
383
Linus Torvalds1da177e2005-04-16 15:20:36 -0700384#endif /* __S390_UACCESS_H */