msgutil.c 2.7 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144
  1. /*
  2. * linux/ipc/msgutil.c
  3. * Copyright (C) 1999, 2004 Manfred Spraul
  4. *
  5. * This file is released under GNU General Public Licence version 2 or
  6. * (at your option) any later version.
  7. *
  8. * See the file COPYING for more details.
  9. */
  10. #include <linux/spinlock.h>
  11. #include <linux/init.h>
  12. #include <linux/security.h>
  13. #include <linux/slab.h>
  14. #include <linux/ipc.h>
  15. #include <linux/msg.h>
  16. #include <linux/ipc_namespace.h>
  17. #include <linux/utsname.h>
  18. #include <asm/uaccess.h>
  19. #include "util.h"
  20. DEFINE_SPINLOCK(mq_lock);
  21. /*
  22. * The next 2 defines are here bc this is the only file
  23. * compiled when either CONFIG_SYSVIPC and CONFIG_POSIX_MQUEUE
  24. * and not CONFIG_IPC_NS.
  25. */
  26. struct ipc_namespace init_ipc_ns = {
  27. .count = ATOMIC_INIT(1),
  28. .user_ns = &init_user_ns,
  29. };
  30. atomic_t nr_ipc_ns = ATOMIC_INIT(1);
  31. struct msg_msgseg {
  32. struct msg_msgseg* next;
  33. /* the next part of the message follows immediately */
  34. };
  35. #define DATALEN_MSG (PAGE_SIZE-sizeof(struct msg_msg))
  36. #define DATALEN_SEG (PAGE_SIZE-sizeof(struct msg_msgseg))
  37. struct msg_msg *load_msg(const void __user *src, int len)
  38. {
  39. struct msg_msg *msg;
  40. struct msg_msgseg **pseg;
  41. int err;
  42. int alen;
  43. alen = len;
  44. if (alen > DATALEN_MSG)
  45. alen = DATALEN_MSG;
  46. msg = kmalloc(sizeof(*msg) + alen, GFP_KERNEL);
  47. if (msg == NULL)
  48. return ERR_PTR(-ENOMEM);
  49. msg->next = NULL;
  50. msg->security = NULL;
  51. if (copy_from_user(msg + 1, src, alen)) {
  52. err = -EFAULT;
  53. goto out_err;
  54. }
  55. len -= alen;
  56. src = ((char __user *)src) + alen;
  57. pseg = &msg->next;
  58. while (len > 0) {
  59. struct msg_msgseg *seg;
  60. alen = len;
  61. if (alen > DATALEN_SEG)
  62. alen = DATALEN_SEG;
  63. seg = kmalloc(sizeof(*seg) + alen,
  64. GFP_KERNEL);
  65. if (seg == NULL) {
  66. err = -ENOMEM;
  67. goto out_err;
  68. }
  69. *pseg = seg;
  70. seg->next = NULL;
  71. if (copy_from_user(seg + 1, src, alen)) {
  72. err = -EFAULT;
  73. goto out_err;
  74. }
  75. pseg = &seg->next;
  76. len -= alen;
  77. src = ((char __user *)src) + alen;
  78. }
  79. err = security_msg_msg_alloc(msg);
  80. if (err)
  81. goto out_err;
  82. return msg;
  83. out_err:
  84. free_msg(msg);
  85. return ERR_PTR(err);
  86. }
  87. int store_msg(void __user *dest, struct msg_msg *msg, int len)
  88. {
  89. int alen;
  90. struct msg_msgseg *seg;
  91. alen = len;
  92. if (alen > DATALEN_MSG)
  93. alen = DATALEN_MSG;
  94. if (copy_to_user(dest, msg + 1, alen))
  95. return -1;
  96. len -= alen;
  97. dest = ((char __user *)dest) + alen;
  98. seg = msg->next;
  99. while (len > 0) {
  100. alen = len;
  101. if (alen > DATALEN_SEG)
  102. alen = DATALEN_SEG;
  103. if (copy_to_user(dest, seg + 1, alen))
  104. return -1;
  105. len -= alen;
  106. dest = ((char __user *)dest) + alen;
  107. seg = seg->next;
  108. }
  109. return 0;
  110. }
  111. void free_msg(struct msg_msg *msg)
  112. {
  113. struct msg_msgseg *seg;
  114. security_msg_msg_free(msg);
  115. seg = msg->next;
  116. kfree(msg);
  117. while (seg != NULL) {
  118. struct msg_msgseg *tmp = seg->next;
  119. kfree(seg);
  120. seg = tmp;
  121. }
  122. }