v4l2-compat-ioctl32.c 28 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045
  1. /*
  2. * ioctl32.c: Conversion between 32bit and 64bit native ioctls.
  3. * Separated from fs stuff by Arnd Bergmann <arnd@arndb.de>
  4. *
  5. * Copyright (C) 1997-2000 Jakub Jelinek (jakub@redhat.com)
  6. * Copyright (C) 1998 Eddie C. Dost (ecd@skynet.be)
  7. * Copyright (C) 2001,2002 Andi Kleen, SuSE Labs
  8. * Copyright (C) 2003 Pavel Machek (pavel@ucw.cz)
  9. * Copyright (C) 2005 Philippe De Muyter (phdm@macqel.be)
  10. * Copyright (C) 2008 Hans Verkuil <hverkuil@xs4all.nl>
  11. *
  12. * These routines maintain argument size conversion between 32bit and 64bit
  13. * ioctls.
  14. */
  15. #include <linux/compat.h>
  16. #include <linux/module.h>
  17. #include <linux/videodev2.h>
  18. #include <media/v4l2-dev.h>
  19. #include <media/v4l2-ioctl.h>
  20. static long native_ioctl(struct file *file, unsigned int cmd, unsigned long arg)
  21. {
  22. long ret = -ENOIOCTLCMD;
  23. if (file->f_op->unlocked_ioctl)
  24. ret = file->f_op->unlocked_ioctl(file, cmd, arg);
  25. return ret;
  26. }
  27. struct v4l2_clip32 {
  28. struct v4l2_rect c;
  29. compat_caddr_t next;
  30. };
  31. struct v4l2_window32 {
  32. struct v4l2_rect w;
  33. __u32 field; /* enum v4l2_field */
  34. __u32 chromakey;
  35. compat_caddr_t clips; /* actually struct v4l2_clip32 * */
  36. __u32 clipcount;
  37. compat_caddr_t bitmap;
  38. };
  39. static int get_v4l2_window32(struct v4l2_window *kp, struct v4l2_window32 __user *up)
  40. {
  41. if (!access_ok(VERIFY_READ, up, sizeof(struct v4l2_window32)) ||
  42. copy_from_user(&kp->w, &up->w, sizeof(up->w)) ||
  43. get_user(kp->field, &up->field) ||
  44. get_user(kp->chromakey, &up->chromakey) ||
  45. get_user(kp->clipcount, &up->clipcount))
  46. return -EFAULT;
  47. if (kp->clipcount > 2048)
  48. return -EINVAL;
  49. if (kp->clipcount) {
  50. struct v4l2_clip32 __user *uclips;
  51. struct v4l2_clip __user *kclips;
  52. int n = kp->clipcount;
  53. compat_caddr_t p;
  54. if (get_user(p, &up->clips))
  55. return -EFAULT;
  56. uclips = compat_ptr(p);
  57. kclips = compat_alloc_user_space(n * sizeof(struct v4l2_clip));
  58. kp->clips = kclips;
  59. while (--n >= 0) {
  60. if (copy_in_user(&kclips->c, &uclips->c, sizeof(uclips->c)))
  61. return -EFAULT;
  62. if (put_user(n ? kclips + 1 : NULL, &kclips->next))
  63. return -EFAULT;
  64. uclips += 1;
  65. kclips += 1;
  66. }
  67. } else
  68. kp->clips = NULL;
  69. return 0;
  70. }
  71. static int put_v4l2_window32(struct v4l2_window *kp, struct v4l2_window32 __user *up)
  72. {
  73. if (copy_to_user(&up->w, &kp->w, sizeof(kp->w)) ||
  74. put_user(kp->field, &up->field) ||
  75. put_user(kp->chromakey, &up->chromakey) ||
  76. put_user(kp->clipcount, &up->clipcount))
  77. return -EFAULT;
  78. return 0;
  79. }
  80. static inline int get_v4l2_pix_format(struct v4l2_pix_format *kp, struct v4l2_pix_format __user *up)
  81. {
  82. if (copy_from_user(kp, up, sizeof(struct v4l2_pix_format)))
  83. return -EFAULT;
  84. return 0;
  85. }
  86. static inline int get_v4l2_pix_format_mplane(struct v4l2_pix_format_mplane *kp,
  87. struct v4l2_pix_format_mplane __user *up)
  88. {
  89. if (copy_from_user(kp, up, sizeof(struct v4l2_pix_format_mplane)))
  90. return -EFAULT;
  91. return 0;
  92. }
  93. static inline int put_v4l2_pix_format(struct v4l2_pix_format *kp, struct v4l2_pix_format __user *up)
  94. {
  95. if (copy_to_user(up, kp, sizeof(struct v4l2_pix_format)))
  96. return -EFAULT;
  97. return 0;
  98. }
  99. static inline int put_v4l2_pix_format_mplane(struct v4l2_pix_format_mplane *kp,
  100. struct v4l2_pix_format_mplane __user *up)
  101. {
  102. if (copy_to_user(up, kp, sizeof(struct v4l2_pix_format_mplane)))
  103. return -EFAULT;
  104. return 0;
  105. }
  106. static inline int get_v4l2_vbi_format(struct v4l2_vbi_format *kp, struct v4l2_vbi_format __user *up)
  107. {
  108. if (copy_from_user(kp, up, sizeof(struct v4l2_vbi_format)))
  109. return -EFAULT;
  110. return 0;
  111. }
  112. static inline int put_v4l2_vbi_format(struct v4l2_vbi_format *kp, struct v4l2_vbi_format __user *up)
  113. {
  114. if (copy_to_user(up, kp, sizeof(struct v4l2_vbi_format)))
  115. return -EFAULT;
  116. return 0;
  117. }
  118. static inline int get_v4l2_sliced_vbi_format(struct v4l2_sliced_vbi_format *kp, struct v4l2_sliced_vbi_format __user *up)
  119. {
  120. if (copy_from_user(kp, up, sizeof(struct v4l2_sliced_vbi_format)))
  121. return -EFAULT;
  122. return 0;
  123. }
  124. static inline int put_v4l2_sliced_vbi_format(struct v4l2_sliced_vbi_format *kp, struct v4l2_sliced_vbi_format __user *up)
  125. {
  126. if (copy_to_user(up, kp, sizeof(struct v4l2_sliced_vbi_format)))
  127. return -EFAULT;
  128. return 0;
  129. }
  130. struct v4l2_format32 {
  131. __u32 type; /* enum v4l2_buf_type */
  132. union {
  133. struct v4l2_pix_format pix;
  134. struct v4l2_pix_format_mplane pix_mp;
  135. struct v4l2_window32 win;
  136. struct v4l2_vbi_format vbi;
  137. struct v4l2_sliced_vbi_format sliced;
  138. __u8 raw_data[200]; /* user-defined */
  139. } fmt;
  140. };
  141. /**
  142. * struct v4l2_create_buffers32 - VIDIOC_CREATE_BUFS32 argument
  143. * @index: on return, index of the first created buffer
  144. * @count: entry: number of requested buffers,
  145. * return: number of created buffers
  146. * @memory: buffer memory type
  147. * @format: frame format, for which buffers are requested
  148. * @reserved: future extensions
  149. */
  150. struct v4l2_create_buffers32 {
  151. __u32 index;
  152. __u32 count;
  153. __u32 memory; /* enum v4l2_memory */
  154. struct v4l2_format32 format;
  155. __u32 reserved[8];
  156. };
  157. static int __get_v4l2_format32(struct v4l2_format *kp, struct v4l2_format32 __user *up)
  158. {
  159. switch (kp->type) {
  160. case V4L2_BUF_TYPE_VIDEO_CAPTURE:
  161. case V4L2_BUF_TYPE_VIDEO_OUTPUT:
  162. return get_v4l2_pix_format(&kp->fmt.pix, &up->fmt.pix);
  163. case V4L2_BUF_TYPE_VIDEO_CAPTURE_MPLANE:
  164. case V4L2_BUF_TYPE_VIDEO_OUTPUT_MPLANE:
  165. return get_v4l2_pix_format_mplane(&kp->fmt.pix_mp,
  166. &up->fmt.pix_mp);
  167. case V4L2_BUF_TYPE_VIDEO_OVERLAY:
  168. case V4L2_BUF_TYPE_VIDEO_OUTPUT_OVERLAY:
  169. return get_v4l2_window32(&kp->fmt.win, &up->fmt.win);
  170. case V4L2_BUF_TYPE_VBI_CAPTURE:
  171. case V4L2_BUF_TYPE_VBI_OUTPUT:
  172. return get_v4l2_vbi_format(&kp->fmt.vbi, &up->fmt.vbi);
  173. case V4L2_BUF_TYPE_SLICED_VBI_CAPTURE:
  174. case V4L2_BUF_TYPE_SLICED_VBI_OUTPUT:
  175. return get_v4l2_sliced_vbi_format(&kp->fmt.sliced, &up->fmt.sliced);
  176. case V4L2_BUF_TYPE_PRIVATE:
  177. if (copy_from_user(kp, up, sizeof(kp->fmt.raw_data)))
  178. return -EFAULT;
  179. return 0;
  180. default:
  181. printk(KERN_INFO "compat_ioctl32: unexpected VIDIOC_FMT type %d\n",
  182. kp->type);
  183. return -EINVAL;
  184. }
  185. }
  186. static int get_v4l2_format32(struct v4l2_format *kp, struct v4l2_format32 __user *up)
  187. {
  188. if (!access_ok(VERIFY_READ, up, sizeof(struct v4l2_format32)) ||
  189. get_user(kp->type, &up->type))
  190. return -EFAULT;
  191. return __get_v4l2_format32(kp, up);
  192. }
  193. static int get_v4l2_create32(struct v4l2_create_buffers *kp, struct v4l2_create_buffers32 __user *up)
  194. {
  195. if (!access_ok(VERIFY_READ, up, sizeof(struct v4l2_create_buffers32)) ||
  196. copy_from_user(kp, up, offsetof(struct v4l2_create_buffers32, format.fmt)))
  197. return -EFAULT;
  198. return __get_v4l2_format32(&kp->format, &up->format);
  199. }
  200. static int __put_v4l2_format32(struct v4l2_format *kp, struct v4l2_format32 __user *up)
  201. {
  202. switch (kp->type) {
  203. case V4L2_BUF_TYPE_VIDEO_CAPTURE:
  204. case V4L2_BUF_TYPE_VIDEO_OUTPUT:
  205. return put_v4l2_pix_format(&kp->fmt.pix, &up->fmt.pix);
  206. case V4L2_BUF_TYPE_VIDEO_CAPTURE_MPLANE:
  207. case V4L2_BUF_TYPE_VIDEO_OUTPUT_MPLANE:
  208. return put_v4l2_pix_format_mplane(&kp->fmt.pix_mp,
  209. &up->fmt.pix_mp);
  210. case V4L2_BUF_TYPE_VIDEO_OVERLAY:
  211. case V4L2_BUF_TYPE_VIDEO_OUTPUT_OVERLAY:
  212. return put_v4l2_window32(&kp->fmt.win, &up->fmt.win);
  213. case V4L2_BUF_TYPE_VBI_CAPTURE:
  214. case V4L2_BUF_TYPE_VBI_OUTPUT:
  215. return put_v4l2_vbi_format(&kp->fmt.vbi, &up->fmt.vbi);
  216. case V4L2_BUF_TYPE_SLICED_VBI_CAPTURE:
  217. case V4L2_BUF_TYPE_SLICED_VBI_OUTPUT:
  218. return put_v4l2_sliced_vbi_format(&kp->fmt.sliced, &up->fmt.sliced);
  219. case V4L2_BUF_TYPE_PRIVATE:
  220. if (copy_to_user(up, kp, sizeof(up->fmt.raw_data)))
  221. return -EFAULT;
  222. return 0;
  223. default:
  224. printk(KERN_INFO "compat_ioctl32: unexpected VIDIOC_FMT type %d\n",
  225. kp->type);
  226. return -EINVAL;
  227. }
  228. }
  229. static int put_v4l2_format32(struct v4l2_format *kp, struct v4l2_format32 __user *up)
  230. {
  231. if (!access_ok(VERIFY_WRITE, up, sizeof(struct v4l2_format32)) ||
  232. put_user(kp->type, &up->type))
  233. return -EFAULT;
  234. return __put_v4l2_format32(kp, up);
  235. }
  236. static int put_v4l2_create32(struct v4l2_create_buffers *kp, struct v4l2_create_buffers32 __user *up)
  237. {
  238. if (!access_ok(VERIFY_WRITE, up, sizeof(struct v4l2_create_buffers32)) ||
  239. copy_to_user(up, kp, offsetof(struct v4l2_create_buffers32, format.fmt)))
  240. return -EFAULT;
  241. return __put_v4l2_format32(&kp->format, &up->format);
  242. }
  243. struct v4l2_standard32 {
  244. __u32 index;
  245. __u32 id[2]; /* __u64 would get the alignment wrong */
  246. __u8 name[24];
  247. struct v4l2_fract frameperiod; /* Frames, not fields */
  248. __u32 framelines;
  249. __u32 reserved[4];
  250. };
  251. static int get_v4l2_standard32(struct v4l2_standard *kp, struct v4l2_standard32 __user *up)
  252. {
  253. /* other fields are not set by the user, nor used by the driver */
  254. if (!access_ok(VERIFY_READ, up, sizeof(struct v4l2_standard32)) ||
  255. get_user(kp->index, &up->index))
  256. return -EFAULT;
  257. return 0;
  258. }
  259. static int put_v4l2_standard32(struct v4l2_standard *kp, struct v4l2_standard32 __user *up)
  260. {
  261. if (!access_ok(VERIFY_WRITE, up, sizeof(struct v4l2_standard32)) ||
  262. put_user(kp->index, &up->index) ||
  263. copy_to_user(up->id, &kp->id, sizeof(__u64)) ||
  264. copy_to_user(up->name, kp->name, 24) ||
  265. copy_to_user(&up->frameperiod, &kp->frameperiod, sizeof(kp->frameperiod)) ||
  266. put_user(kp->framelines, &up->framelines) ||
  267. copy_to_user(up->reserved, kp->reserved, 4 * sizeof(__u32)))
  268. return -EFAULT;
  269. return 0;
  270. }
  271. struct v4l2_plane32 {
  272. __u32 bytesused;
  273. __u32 length;
  274. union {
  275. __u32 mem_offset;
  276. compat_long_t userptr;
  277. } m;
  278. __u32 data_offset;
  279. __u32 reserved[11];
  280. };
  281. struct v4l2_buffer32 {
  282. __u32 index;
  283. __u32 type; /* enum v4l2_buf_type */
  284. __u32 bytesused;
  285. __u32 flags;
  286. __u32 field; /* enum v4l2_field */
  287. struct compat_timeval timestamp;
  288. struct v4l2_timecode timecode;
  289. __u32 sequence;
  290. /* memory location */
  291. __u32 memory; /* enum v4l2_memory */
  292. union {
  293. __u32 offset;
  294. compat_long_t userptr;
  295. compat_caddr_t planes;
  296. } m;
  297. __u32 length;
  298. __u32 reserved2;
  299. __u32 reserved;
  300. };
  301. static int get_v4l2_plane32(struct v4l2_plane *up, struct v4l2_plane32 *up32,
  302. enum v4l2_memory memory)
  303. {
  304. void __user *up_pln;
  305. compat_long_t p;
  306. if (copy_in_user(up, up32, 2 * sizeof(__u32)) ||
  307. copy_in_user(&up->data_offset, &up32->data_offset,
  308. sizeof(__u32)))
  309. return -EFAULT;
  310. if (memory == V4L2_MEMORY_USERPTR) {
  311. if (get_user(p, &up32->m.userptr))
  312. return -EFAULT;
  313. up_pln = compat_ptr(p);
  314. if (put_user((unsigned long)up_pln, &up->m.userptr))
  315. return -EFAULT;
  316. } else {
  317. if (copy_in_user(&up->m.mem_offset, &up32->m.mem_offset,
  318. sizeof(__u32)))
  319. return -EFAULT;
  320. }
  321. return 0;
  322. }
  323. static int put_v4l2_plane32(struct v4l2_plane *up, struct v4l2_plane32 *up32,
  324. enum v4l2_memory memory)
  325. {
  326. if (copy_in_user(up32, up, 2 * sizeof(__u32)) ||
  327. copy_in_user(&up32->data_offset, &up->data_offset,
  328. sizeof(__u32)))
  329. return -EFAULT;
  330. /* For MMAP, driver might've set up the offset, so copy it back.
  331. * USERPTR stays the same (was userspace-provided), so no copying. */
  332. if (memory == V4L2_MEMORY_MMAP)
  333. if (copy_in_user(&up32->m.mem_offset, &up->m.mem_offset,
  334. sizeof(__u32)))
  335. return -EFAULT;
  336. return 0;
  337. }
  338. static int get_v4l2_buffer32(struct v4l2_buffer *kp, struct v4l2_buffer32 __user *up)
  339. {
  340. struct v4l2_plane32 __user *uplane32;
  341. struct v4l2_plane __user *uplane;
  342. compat_caddr_t p;
  343. int num_planes;
  344. int ret;
  345. if (!access_ok(VERIFY_READ, up, sizeof(struct v4l2_buffer32)) ||
  346. get_user(kp->index, &up->index) ||
  347. get_user(kp->type, &up->type) ||
  348. get_user(kp->flags, &up->flags) ||
  349. get_user(kp->memory, &up->memory))
  350. return -EFAULT;
  351. if (V4L2_TYPE_IS_OUTPUT(kp->type))
  352. if (get_user(kp->bytesused, &up->bytesused) ||
  353. get_user(kp->field, &up->field) ||
  354. get_user(kp->timestamp.tv_sec, &up->timestamp.tv_sec) ||
  355. get_user(kp->timestamp.tv_usec,
  356. &up->timestamp.tv_usec))
  357. return -EFAULT;
  358. if (V4L2_TYPE_IS_MULTIPLANAR(kp->type)) {
  359. if (get_user(kp->length, &up->length))
  360. return -EFAULT;
  361. num_planes = kp->length;
  362. if (num_planes == 0) {
  363. kp->m.planes = NULL;
  364. /* num_planes == 0 is legal, e.g. when userspace doesn't
  365. * need planes array on DQBUF*/
  366. return 0;
  367. }
  368. if (get_user(p, &up->m.planes))
  369. return -EFAULT;
  370. uplane32 = compat_ptr(p);
  371. if (!access_ok(VERIFY_READ, uplane32,
  372. num_planes * sizeof(struct v4l2_plane32)))
  373. return -EFAULT;
  374. /* We don't really care if userspace decides to kill itself
  375. * by passing a very big num_planes value */
  376. uplane = compat_alloc_user_space(num_planes *
  377. sizeof(struct v4l2_plane));
  378. kp->m.planes = uplane;
  379. while (--num_planes >= 0) {
  380. ret = get_v4l2_plane32(uplane, uplane32, kp->memory);
  381. if (ret)
  382. return ret;
  383. ++uplane;
  384. ++uplane32;
  385. }
  386. } else {
  387. switch (kp->memory) {
  388. case V4L2_MEMORY_MMAP:
  389. if (get_user(kp->length, &up->length) ||
  390. get_user(kp->m.offset, &up->m.offset))
  391. return -EFAULT;
  392. break;
  393. case V4L2_MEMORY_USERPTR:
  394. {
  395. compat_long_t tmp;
  396. if (get_user(kp->length, &up->length) ||
  397. get_user(tmp, &up->m.userptr))
  398. return -EFAULT;
  399. kp->m.userptr = (unsigned long)compat_ptr(tmp);
  400. }
  401. break;
  402. case V4L2_MEMORY_OVERLAY:
  403. if (get_user(kp->m.offset, &up->m.offset))
  404. return -EFAULT;
  405. break;
  406. }
  407. }
  408. return 0;
  409. }
  410. static int put_v4l2_buffer32(struct v4l2_buffer *kp, struct v4l2_buffer32 __user *up)
  411. {
  412. struct v4l2_plane32 __user *uplane32;
  413. struct v4l2_plane __user *uplane;
  414. compat_caddr_t p;
  415. int num_planes;
  416. int ret;
  417. if (!access_ok(VERIFY_WRITE, up, sizeof(struct v4l2_buffer32)) ||
  418. put_user(kp->index, &up->index) ||
  419. put_user(kp->type, &up->type) ||
  420. put_user(kp->flags, &up->flags) ||
  421. put_user(kp->memory, &up->memory))
  422. return -EFAULT;
  423. if (put_user(kp->bytesused, &up->bytesused) ||
  424. put_user(kp->field, &up->field) ||
  425. put_user(kp->timestamp.tv_sec, &up->timestamp.tv_sec) ||
  426. put_user(kp->timestamp.tv_usec, &up->timestamp.tv_usec) ||
  427. copy_to_user(&up->timecode, &kp->timecode, sizeof(struct v4l2_timecode)) ||
  428. put_user(kp->sequence, &up->sequence) ||
  429. put_user(kp->reserved2, &up->reserved2) ||
  430. put_user(kp->reserved, &up->reserved))
  431. return -EFAULT;
  432. if (V4L2_TYPE_IS_MULTIPLANAR(kp->type)) {
  433. num_planes = kp->length;
  434. if (num_planes == 0)
  435. return 0;
  436. uplane = kp->m.planes;
  437. if (get_user(p, &up->m.planes))
  438. return -EFAULT;
  439. uplane32 = compat_ptr(p);
  440. while (--num_planes >= 0) {
  441. ret = put_v4l2_plane32(uplane, uplane32, kp->memory);
  442. if (ret)
  443. return ret;
  444. ++uplane;
  445. ++uplane32;
  446. }
  447. } else {
  448. switch (kp->memory) {
  449. case V4L2_MEMORY_MMAP:
  450. if (put_user(kp->length, &up->length) ||
  451. put_user(kp->m.offset, &up->m.offset))
  452. return -EFAULT;
  453. break;
  454. case V4L2_MEMORY_USERPTR:
  455. if (put_user(kp->length, &up->length) ||
  456. put_user(kp->m.userptr, &up->m.userptr))
  457. return -EFAULT;
  458. break;
  459. case V4L2_MEMORY_OVERLAY:
  460. if (put_user(kp->m.offset, &up->m.offset))
  461. return -EFAULT;
  462. break;
  463. }
  464. }
  465. return 0;
  466. }
  467. struct v4l2_framebuffer32 {
  468. __u32 capability;
  469. __u32 flags;
  470. compat_caddr_t base;
  471. struct v4l2_pix_format fmt;
  472. };
  473. static int get_v4l2_framebuffer32(struct v4l2_framebuffer *kp, struct v4l2_framebuffer32 __user *up)
  474. {
  475. u32 tmp;
  476. if (!access_ok(VERIFY_READ, up, sizeof(struct v4l2_framebuffer32)) ||
  477. get_user(tmp, &up->base) ||
  478. get_user(kp->capability, &up->capability) ||
  479. get_user(kp->flags, &up->flags))
  480. return -EFAULT;
  481. kp->base = compat_ptr(tmp);
  482. get_v4l2_pix_format(&kp->fmt, &up->fmt);
  483. return 0;
  484. }
  485. static int put_v4l2_framebuffer32(struct v4l2_framebuffer *kp, struct v4l2_framebuffer32 __user *up)
  486. {
  487. u32 tmp = (u32)((unsigned long)kp->base);
  488. if (!access_ok(VERIFY_WRITE, up, sizeof(struct v4l2_framebuffer32)) ||
  489. put_user(tmp, &up->base) ||
  490. put_user(kp->capability, &up->capability) ||
  491. put_user(kp->flags, &up->flags))
  492. return -EFAULT;
  493. put_v4l2_pix_format(&kp->fmt, &up->fmt);
  494. return 0;
  495. }
  496. struct v4l2_input32 {
  497. __u32 index; /* Which input */
  498. __u8 name[32]; /* Label */
  499. __u32 type; /* Type of input */
  500. __u32 audioset; /* Associated audios (bitfield) */
  501. __u32 tuner; /* Associated tuner */
  502. v4l2_std_id std;
  503. __u32 status;
  504. __u32 reserved[4];
  505. } __attribute__ ((packed));
  506. /* The 64-bit v4l2_input struct has extra padding at the end of the struct.
  507. Otherwise it is identical to the 32-bit version. */
  508. static inline int get_v4l2_input32(struct v4l2_input *kp, struct v4l2_input32 __user *up)
  509. {
  510. if (copy_from_user(kp, up, sizeof(struct v4l2_input32)))
  511. return -EFAULT;
  512. return 0;
  513. }
  514. static inline int put_v4l2_input32(struct v4l2_input *kp, struct v4l2_input32 __user *up)
  515. {
  516. if (copy_to_user(up, kp, sizeof(struct v4l2_input32)))
  517. return -EFAULT;
  518. return 0;
  519. }
  520. struct v4l2_ext_controls32 {
  521. __u32 ctrl_class;
  522. __u32 count;
  523. __u32 error_idx;
  524. __u32 reserved[2];
  525. compat_caddr_t controls; /* actually struct v4l2_ext_control32 * */
  526. };
  527. struct v4l2_ext_control32 {
  528. __u32 id;
  529. __u32 size;
  530. __u32 reserved2[1];
  531. union {
  532. __s32 value;
  533. __s64 value64;
  534. compat_caddr_t string; /* actually char * */
  535. };
  536. } __attribute__ ((packed));
  537. /* The following function really belong in v4l2-common, but that causes
  538. a circular dependency between modules. We need to think about this, but
  539. for now this will do. */
  540. /* Return non-zero if this control is a pointer type. Currently only
  541. type STRING is a pointer type. */
  542. static inline int ctrl_is_pointer(u32 id)
  543. {
  544. switch (id) {
  545. case V4L2_CID_RDS_TX_PS_NAME:
  546. case V4L2_CID_RDS_TX_RADIO_TEXT:
  547. return 1;
  548. default:
  549. return 0;
  550. }
  551. }
  552. static int get_v4l2_ext_controls32(struct v4l2_ext_controls *kp, struct v4l2_ext_controls32 __user *up)
  553. {
  554. struct v4l2_ext_control32 __user *ucontrols;
  555. struct v4l2_ext_control __user *kcontrols;
  556. int n;
  557. compat_caddr_t p;
  558. if (!access_ok(VERIFY_READ, up, sizeof(struct v4l2_ext_controls32)) ||
  559. get_user(kp->ctrl_class, &up->ctrl_class) ||
  560. get_user(kp->count, &up->count) ||
  561. get_user(kp->error_idx, &up->error_idx) ||
  562. copy_from_user(kp->reserved, up->reserved, sizeof(kp->reserved)))
  563. return -EFAULT;
  564. n = kp->count;
  565. if (n == 0) {
  566. kp->controls = NULL;
  567. return 0;
  568. }
  569. if (get_user(p, &up->controls))
  570. return -EFAULT;
  571. ucontrols = compat_ptr(p);
  572. if (!access_ok(VERIFY_READ, ucontrols,
  573. n * sizeof(struct v4l2_ext_control32)))
  574. return -EFAULT;
  575. kcontrols = compat_alloc_user_space(n * sizeof(struct v4l2_ext_control));
  576. kp->controls = kcontrols;
  577. while (--n >= 0) {
  578. if (copy_in_user(kcontrols, ucontrols, sizeof(*ucontrols)))
  579. return -EFAULT;
  580. if (ctrl_is_pointer(kcontrols->id)) {
  581. void __user *s;
  582. if (get_user(p, &ucontrols->string))
  583. return -EFAULT;
  584. s = compat_ptr(p);
  585. if (put_user(s, &kcontrols->string))
  586. return -EFAULT;
  587. }
  588. ucontrols++;
  589. kcontrols++;
  590. }
  591. return 0;
  592. }
  593. static int put_v4l2_ext_controls32(struct v4l2_ext_controls *kp, struct v4l2_ext_controls32 __user *up)
  594. {
  595. struct v4l2_ext_control32 __user *ucontrols;
  596. struct v4l2_ext_control __user *kcontrols = kp->controls;
  597. int n = kp->count;
  598. compat_caddr_t p;
  599. if (!access_ok(VERIFY_WRITE, up, sizeof(struct v4l2_ext_controls32)) ||
  600. put_user(kp->ctrl_class, &up->ctrl_class) ||
  601. put_user(kp->count, &up->count) ||
  602. put_user(kp->error_idx, &up->error_idx) ||
  603. copy_to_user(up->reserved, kp->reserved, sizeof(up->reserved)))
  604. return -EFAULT;
  605. if (!kp->count)
  606. return 0;
  607. if (get_user(p, &up->controls))
  608. return -EFAULT;
  609. ucontrols = compat_ptr(p);
  610. if (!access_ok(VERIFY_WRITE, ucontrols,
  611. n * sizeof(struct v4l2_ext_control32)))
  612. return -EFAULT;
  613. while (--n >= 0) {
  614. unsigned size = sizeof(*ucontrols);
  615. /* Do not modify the pointer when copying a pointer control.
  616. The contents of the pointer was changed, not the pointer
  617. itself. */
  618. if (ctrl_is_pointer(kcontrols->id))
  619. size -= sizeof(ucontrols->value64);
  620. if (copy_in_user(ucontrols, kcontrols, size))
  621. return -EFAULT;
  622. ucontrols++;
  623. kcontrols++;
  624. }
  625. return 0;
  626. }
  627. struct v4l2_event32 {
  628. __u32 type;
  629. union {
  630. __u8 data[64];
  631. } u;
  632. __u32 pending;
  633. __u32 sequence;
  634. struct compat_timespec timestamp;
  635. __u32 id;
  636. __u32 reserved[8];
  637. };
  638. static int put_v4l2_event32(struct v4l2_event *kp, struct v4l2_event32 __user *up)
  639. {
  640. if (!access_ok(VERIFY_WRITE, up, sizeof(struct v4l2_event32)) ||
  641. put_user(kp->type, &up->type) ||
  642. copy_to_user(&up->u, &kp->u, sizeof(kp->u)) ||
  643. put_user(kp->pending, &up->pending) ||
  644. put_user(kp->sequence, &up->sequence) ||
  645. put_compat_timespec(&kp->timestamp, &up->timestamp) ||
  646. put_user(kp->id, &up->id) ||
  647. copy_to_user(up->reserved, kp->reserved, 8 * sizeof(__u32)))
  648. return -EFAULT;
  649. return 0;
  650. }
  651. #define VIDIOC_G_FMT32 _IOWR('V', 4, struct v4l2_format32)
  652. #define VIDIOC_S_FMT32 _IOWR('V', 5, struct v4l2_format32)
  653. #define VIDIOC_QUERYBUF32 _IOWR('V', 9, struct v4l2_buffer32)
  654. #define VIDIOC_G_FBUF32 _IOR ('V', 10, struct v4l2_framebuffer32)
  655. #define VIDIOC_S_FBUF32 _IOW ('V', 11, struct v4l2_framebuffer32)
  656. #define VIDIOC_QBUF32 _IOWR('V', 15, struct v4l2_buffer32)
  657. #define VIDIOC_DQBUF32 _IOWR('V', 17, struct v4l2_buffer32)
  658. #define VIDIOC_ENUMSTD32 _IOWR('V', 25, struct v4l2_standard32)
  659. #define VIDIOC_ENUMINPUT32 _IOWR('V', 26, struct v4l2_input32)
  660. #define VIDIOC_TRY_FMT32 _IOWR('V', 64, struct v4l2_format32)
  661. #define VIDIOC_G_EXT_CTRLS32 _IOWR('V', 71, struct v4l2_ext_controls32)
  662. #define VIDIOC_S_EXT_CTRLS32 _IOWR('V', 72, struct v4l2_ext_controls32)
  663. #define VIDIOC_TRY_EXT_CTRLS32 _IOWR('V', 73, struct v4l2_ext_controls32)
  664. #define VIDIOC_DQEVENT32 _IOR ('V', 89, struct v4l2_event32)
  665. #define VIDIOC_CREATE_BUFS32 _IOWR('V', 92, struct v4l2_create_buffers32)
  666. #define VIDIOC_PREPARE_BUF32 _IOWR('V', 93, struct v4l2_buffer32)
  667. #define VIDIOC_OVERLAY32 _IOW ('V', 14, s32)
  668. #define VIDIOC_STREAMON32 _IOW ('V', 18, s32)
  669. #define VIDIOC_STREAMOFF32 _IOW ('V', 19, s32)
  670. #define VIDIOC_G_INPUT32 _IOR ('V', 38, s32)
  671. #define VIDIOC_S_INPUT32 _IOWR('V', 39, s32)
  672. #define VIDIOC_G_OUTPUT32 _IOR ('V', 46, s32)
  673. #define VIDIOC_S_OUTPUT32 _IOWR('V', 47, s32)
  674. static long do_video_ioctl(struct file *file, unsigned int cmd, unsigned long arg)
  675. {
  676. union {
  677. struct v4l2_format v2f;
  678. struct v4l2_buffer v2b;
  679. struct v4l2_framebuffer v2fb;
  680. struct v4l2_input v2i;
  681. struct v4l2_standard v2s;
  682. struct v4l2_ext_controls v2ecs;
  683. struct v4l2_event v2ev;
  684. struct v4l2_create_buffers v2crt;
  685. unsigned long vx;
  686. int vi;
  687. } karg;
  688. void __user *up = compat_ptr(arg);
  689. int compatible_arg = 1;
  690. long err = 0;
  691. /* First, convert the command. */
  692. switch (cmd) {
  693. case VIDIOC_G_FMT32: cmd = VIDIOC_G_FMT; break;
  694. case VIDIOC_S_FMT32: cmd = VIDIOC_S_FMT; break;
  695. case VIDIOC_QUERYBUF32: cmd = VIDIOC_QUERYBUF; break;
  696. case VIDIOC_G_FBUF32: cmd = VIDIOC_G_FBUF; break;
  697. case VIDIOC_S_FBUF32: cmd = VIDIOC_S_FBUF; break;
  698. case VIDIOC_QBUF32: cmd = VIDIOC_QBUF; break;
  699. case VIDIOC_DQBUF32: cmd = VIDIOC_DQBUF; break;
  700. case VIDIOC_ENUMSTD32: cmd = VIDIOC_ENUMSTD; break;
  701. case VIDIOC_ENUMINPUT32: cmd = VIDIOC_ENUMINPUT; break;
  702. case VIDIOC_TRY_FMT32: cmd = VIDIOC_TRY_FMT; break;
  703. case VIDIOC_G_EXT_CTRLS32: cmd = VIDIOC_G_EXT_CTRLS; break;
  704. case VIDIOC_S_EXT_CTRLS32: cmd = VIDIOC_S_EXT_CTRLS; break;
  705. case VIDIOC_TRY_EXT_CTRLS32: cmd = VIDIOC_TRY_EXT_CTRLS; break;
  706. case VIDIOC_DQEVENT32: cmd = VIDIOC_DQEVENT; break;
  707. case VIDIOC_OVERLAY32: cmd = VIDIOC_OVERLAY; break;
  708. case VIDIOC_STREAMON32: cmd = VIDIOC_STREAMON; break;
  709. case VIDIOC_STREAMOFF32: cmd = VIDIOC_STREAMOFF; break;
  710. case VIDIOC_G_INPUT32: cmd = VIDIOC_G_INPUT; break;
  711. case VIDIOC_S_INPUT32: cmd = VIDIOC_S_INPUT; break;
  712. case VIDIOC_G_OUTPUT32: cmd = VIDIOC_G_OUTPUT; break;
  713. case VIDIOC_S_OUTPUT32: cmd = VIDIOC_S_OUTPUT; break;
  714. case VIDIOC_CREATE_BUFS32: cmd = VIDIOC_CREATE_BUFS; break;
  715. case VIDIOC_PREPARE_BUF32: cmd = VIDIOC_PREPARE_BUF; break;
  716. }
  717. switch (cmd) {
  718. case VIDIOC_OVERLAY:
  719. case VIDIOC_STREAMON:
  720. case VIDIOC_STREAMOFF:
  721. case VIDIOC_S_INPUT:
  722. case VIDIOC_S_OUTPUT:
  723. err = get_user(karg.vi, (s32 __user *)up);
  724. compatible_arg = 0;
  725. break;
  726. case VIDIOC_G_INPUT:
  727. case VIDIOC_G_OUTPUT:
  728. compatible_arg = 0;
  729. break;
  730. case VIDIOC_G_FMT:
  731. case VIDIOC_S_FMT:
  732. case VIDIOC_TRY_FMT:
  733. err = get_v4l2_format32(&karg.v2f, up);
  734. compatible_arg = 0;
  735. break;
  736. case VIDIOC_CREATE_BUFS:
  737. err = get_v4l2_create32(&karg.v2crt, up);
  738. compatible_arg = 0;
  739. break;
  740. case VIDIOC_PREPARE_BUF:
  741. case VIDIOC_QUERYBUF:
  742. case VIDIOC_QBUF:
  743. case VIDIOC_DQBUF:
  744. err = get_v4l2_buffer32(&karg.v2b, up);
  745. compatible_arg = 0;
  746. break;
  747. case VIDIOC_S_FBUF:
  748. err = get_v4l2_framebuffer32(&karg.v2fb, up);
  749. compatible_arg = 0;
  750. break;
  751. case VIDIOC_G_FBUF:
  752. compatible_arg = 0;
  753. break;
  754. case VIDIOC_ENUMSTD:
  755. err = get_v4l2_standard32(&karg.v2s, up);
  756. compatible_arg = 0;
  757. break;
  758. case VIDIOC_ENUMINPUT:
  759. err = get_v4l2_input32(&karg.v2i, up);
  760. compatible_arg = 0;
  761. break;
  762. case VIDIOC_G_EXT_CTRLS:
  763. case VIDIOC_S_EXT_CTRLS:
  764. case VIDIOC_TRY_EXT_CTRLS:
  765. err = get_v4l2_ext_controls32(&karg.v2ecs, up);
  766. compatible_arg = 0;
  767. break;
  768. case VIDIOC_DQEVENT:
  769. compatible_arg = 0;
  770. break;
  771. }
  772. if (err)
  773. return err;
  774. if (compatible_arg)
  775. err = native_ioctl(file, cmd, (unsigned long)up);
  776. else {
  777. mm_segment_t old_fs = get_fs();
  778. set_fs(KERNEL_DS);
  779. err = native_ioctl(file, cmd, (unsigned long)&karg);
  780. set_fs(old_fs);
  781. }
  782. /* Special case: even after an error we need to put the
  783. results back for these ioctls since the error_idx will
  784. contain information on which control failed. */
  785. switch (cmd) {
  786. case VIDIOC_G_EXT_CTRLS:
  787. case VIDIOC_S_EXT_CTRLS:
  788. case VIDIOC_TRY_EXT_CTRLS:
  789. if (put_v4l2_ext_controls32(&karg.v2ecs, up))
  790. err = -EFAULT;
  791. break;
  792. }
  793. if (err)
  794. return err;
  795. switch (cmd) {
  796. case VIDIOC_S_INPUT:
  797. case VIDIOC_S_OUTPUT:
  798. case VIDIOC_G_INPUT:
  799. case VIDIOC_G_OUTPUT:
  800. err = put_user(((s32)karg.vi), (s32 __user *)up);
  801. break;
  802. case VIDIOC_G_FBUF:
  803. err = put_v4l2_framebuffer32(&karg.v2fb, up);
  804. break;
  805. case VIDIOC_DQEVENT:
  806. err = put_v4l2_event32(&karg.v2ev, up);
  807. break;
  808. case VIDIOC_G_FMT:
  809. case VIDIOC_S_FMT:
  810. case VIDIOC_TRY_FMT:
  811. err = put_v4l2_format32(&karg.v2f, up);
  812. break;
  813. case VIDIOC_CREATE_BUFS:
  814. err = put_v4l2_create32(&karg.v2crt, up);
  815. break;
  816. case VIDIOC_QUERYBUF:
  817. case VIDIOC_QBUF:
  818. case VIDIOC_DQBUF:
  819. err = put_v4l2_buffer32(&karg.v2b, up);
  820. break;
  821. case VIDIOC_ENUMSTD:
  822. err = put_v4l2_standard32(&karg.v2s, up);
  823. break;
  824. case VIDIOC_ENUMINPUT:
  825. err = put_v4l2_input32(&karg.v2i, up);
  826. break;
  827. }
  828. return err;
  829. }
  830. long v4l2_compat_ioctl32(struct file *file, unsigned int cmd, unsigned long arg)
  831. {
  832. struct video_device *vdev = video_devdata(file);
  833. long ret = -ENOIOCTLCMD;
  834. if (!file->f_op->unlocked_ioctl)
  835. return ret;
  836. switch (cmd) {
  837. case VIDIOC_QUERYCAP:
  838. case VIDIOC_RESERVED:
  839. case VIDIOC_ENUM_FMT:
  840. case VIDIOC_G_FMT32:
  841. case VIDIOC_S_FMT32:
  842. case VIDIOC_REQBUFS:
  843. case VIDIOC_QUERYBUF32:
  844. case VIDIOC_G_FBUF32:
  845. case VIDIOC_S_FBUF32:
  846. case VIDIOC_OVERLAY32:
  847. case VIDIOC_QBUF32:
  848. case VIDIOC_DQBUF32:
  849. case VIDIOC_STREAMON32:
  850. case VIDIOC_STREAMOFF32:
  851. case VIDIOC_G_PARM:
  852. case VIDIOC_S_PARM:
  853. case VIDIOC_G_STD:
  854. case VIDIOC_S_STD:
  855. case VIDIOC_ENUMSTD32:
  856. case VIDIOC_ENUMINPUT32:
  857. case VIDIOC_G_CTRL:
  858. case VIDIOC_S_CTRL:
  859. case VIDIOC_G_TUNER:
  860. case VIDIOC_S_TUNER:
  861. case VIDIOC_G_AUDIO:
  862. case VIDIOC_S_AUDIO:
  863. case VIDIOC_QUERYCTRL:
  864. case VIDIOC_QUERYMENU:
  865. case VIDIOC_G_INPUT32:
  866. case VIDIOC_S_INPUT32:
  867. case VIDIOC_G_OUTPUT32:
  868. case VIDIOC_S_OUTPUT32:
  869. case VIDIOC_ENUMOUTPUT:
  870. case VIDIOC_G_AUDOUT:
  871. case VIDIOC_S_AUDOUT:
  872. case VIDIOC_G_MODULATOR:
  873. case VIDIOC_S_MODULATOR:
  874. case VIDIOC_S_FREQUENCY:
  875. case VIDIOC_G_FREQUENCY:
  876. case VIDIOC_CROPCAP:
  877. case VIDIOC_G_CROP:
  878. case VIDIOC_S_CROP:
  879. case VIDIOC_G_SELECTION:
  880. case VIDIOC_S_SELECTION:
  881. case VIDIOC_G_JPEGCOMP:
  882. case VIDIOC_S_JPEGCOMP:
  883. case VIDIOC_QUERYSTD:
  884. case VIDIOC_TRY_FMT32:
  885. case VIDIOC_ENUMAUDIO:
  886. case VIDIOC_ENUMAUDOUT:
  887. case VIDIOC_G_PRIORITY:
  888. case VIDIOC_S_PRIORITY:
  889. case VIDIOC_G_SLICED_VBI_CAP:
  890. case VIDIOC_LOG_STATUS:
  891. case VIDIOC_G_EXT_CTRLS32:
  892. case VIDIOC_S_EXT_CTRLS32:
  893. case VIDIOC_TRY_EXT_CTRLS32:
  894. case VIDIOC_ENUM_FRAMESIZES:
  895. case VIDIOC_ENUM_FRAMEINTERVALS:
  896. case VIDIOC_G_ENC_INDEX:
  897. case VIDIOC_ENCODER_CMD:
  898. case VIDIOC_TRY_ENCODER_CMD:
  899. case VIDIOC_DECODER_CMD:
  900. case VIDIOC_TRY_DECODER_CMD:
  901. case VIDIOC_DBG_S_REGISTER:
  902. case VIDIOC_DBG_G_REGISTER:
  903. case VIDIOC_DBG_G_CHIP_IDENT:
  904. case VIDIOC_S_HW_FREQ_SEEK:
  905. case VIDIOC_ENUM_DV_PRESETS:
  906. case VIDIOC_S_DV_PRESET:
  907. case VIDIOC_G_DV_PRESET:
  908. case VIDIOC_QUERY_DV_PRESET:
  909. case VIDIOC_S_DV_TIMINGS:
  910. case VIDIOC_G_DV_TIMINGS:
  911. case VIDIOC_DQEVENT:
  912. case VIDIOC_DQEVENT32:
  913. case VIDIOC_SUBSCRIBE_EVENT:
  914. case VIDIOC_UNSUBSCRIBE_EVENT:
  915. case VIDIOC_CREATE_BUFS32:
  916. case VIDIOC_PREPARE_BUF32:
  917. case VIDIOC_ENUM_DV_TIMINGS:
  918. case VIDIOC_QUERY_DV_TIMINGS:
  919. case VIDIOC_DV_TIMINGS_CAP:
  920. case VIDIOC_ENUM_FREQ_BANDS:
  921. ret = do_video_ioctl(file, cmd, arg);
  922. break;
  923. default:
  924. if (vdev->fops->compat_ioctl32)
  925. ret = vdev->fops->compat_ioctl32(file, cmd, arg);
  926. if (ret == -ENOIOCTLCMD)
  927. printk(KERN_WARNING "compat_ioctl32: "
  928. "unknown ioctl '%c', dir=%d, #%d (0x%08x)\n",
  929. _IOC_TYPE(cmd), _IOC_DIR(cmd), _IOC_NR(cmd),
  930. cmd);
  931. break;
  932. }
  933. return ret;
  934. }
  935. EXPORT_SYMBOL_GPL(v4l2_compat_ioctl32);