uaccess.h 12 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444
  1. /*
  2. * arch/arm/include/asm/uaccess.h
  3. *
  4. * This program is free software; you can redistribute it and/or modify
  5. * it under the terms of the GNU General Public License version 2 as
  6. * published by the Free Software Foundation.
  7. */
  8. #ifndef _ASMARM_UACCESS_H
  9. #define _ASMARM_UACCESS_H
  10. /*
  11. * User space memory access functions
  12. */
  13. #include <linux/sched.h>
  14. #include <asm/errno.h>
  15. #include <asm/memory.h>
  16. #include <asm/domain.h>
  17. #include <asm/system.h>
  18. #define VERIFY_READ 0
  19. #define VERIFY_WRITE 1
  20. /*
  21. * The exception table consists of pairs of addresses: the first is the
  22. * address of an instruction that is allowed to fault, and the second is
  23. * the address at which the program should continue. No registers are
  24. * modified, so it is entirely up to the continuation code to figure out
  25. * what to do.
  26. *
  27. * All the routines below use bits of fixup code that are out of line
  28. * with the main instruction path. This means when everything is well,
  29. * we don't even have to jump over them. Further, they do not intrude
  30. * on our cache or tlb entries.
  31. */
  32. struct exception_table_entry
  33. {
  34. unsigned long insn, fixup;
  35. };
  36. extern int fixup_exception(struct pt_regs *regs);
  37. /*
  38. * These two are intentionally not defined anywhere - if the kernel
  39. * code generates any references to them, that's a bug.
  40. */
  41. extern int __get_user_bad(void);
  42. extern int __put_user_bad(void);
  43. /*
  44. * Note that this is actually 0x1,0000,0000
  45. */
  46. #define KERNEL_DS 0x00000000
  47. #define get_ds() (KERNEL_DS)
  48. #ifdef CONFIG_MMU
  49. #define USER_DS TASK_SIZE
  50. #define get_fs() (current_thread_info()->addr_limit)
  51. static inline void set_fs(mm_segment_t fs)
  52. {
  53. current_thread_info()->addr_limit = fs;
  54. modify_domain(DOMAIN_KERNEL, fs ? DOMAIN_CLIENT : DOMAIN_MANAGER);
  55. }
  56. #define segment_eq(a,b) ((a) == (b))
  57. #define __addr_ok(addr) ({ \
  58. unsigned long flag; \
  59. __asm__("cmp %2, %0; movlo %0, #0" \
  60. : "=&r" (flag) \
  61. : "0" (current_thread_info()->addr_limit), "r" (addr) \
  62. : "cc"); \
  63. (flag == 0); })
  64. /* We use 33-bit arithmetic here... */
  65. #define __range_ok(addr,size) ({ \
  66. unsigned long flag, roksum; \
  67. __chk_user_ptr(addr); \
  68. __asm__("adds %1, %2, %3; sbcccs %1, %1, %0; movcc %0, #0" \
  69. : "=&r" (flag), "=&r" (roksum) \
  70. : "r" (addr), "Ir" (size), "0" (current_thread_info()->addr_limit) \
  71. : "cc"); \
  72. flag; })
  73. /*
  74. * Single-value transfer routines. They automatically use the right
  75. * size if we just have the right pointer type. Note that the functions
  76. * which read from user space (*get_*) need to take care not to leak
  77. * kernel data even if the calling code is buggy and fails to check
  78. * the return value. This means zeroing out the destination variable
  79. * or buffer on error. Normally this is done out of line by the
  80. * fixup code, but there are a few places where it intrudes on the
  81. * main code path. When we only write to user space, there is no
  82. * problem.
  83. */
  84. extern int __get_user_1(void *);
  85. extern int __get_user_2(void *);
  86. extern int __get_user_4(void *);
  87. #define __get_user_x(__r2,__p,__e,__s,__i...) \
  88. __asm__ __volatile__ ( \
  89. __asmeq("%0", "r0") __asmeq("%1", "r2") \
  90. "bl __get_user_" #__s \
  91. : "=&r" (__e), "=r" (__r2) \
  92. : "0" (__p) \
  93. : __i, "cc")
  94. #define get_user(x,p) \
  95. ({ \
  96. register const typeof(*(p)) __user *__p asm("r0") = (p);\
  97. register unsigned long __r2 asm("r2"); \
  98. register int __e asm("r0"); \
  99. switch (sizeof(*(__p))) { \
  100. case 1: \
  101. __get_user_x(__r2, __p, __e, 1, "lr"); \
  102. break; \
  103. case 2: \
  104. __get_user_x(__r2, __p, __e, 2, "r3", "lr"); \
  105. break; \
  106. case 4: \
  107. __get_user_x(__r2, __p, __e, 4, "lr"); \
  108. break; \
  109. default: __e = __get_user_bad(); break; \
  110. } \
  111. x = (typeof(*(p))) __r2; \
  112. __e; \
  113. })
  114. extern int __put_user_1(void *, unsigned int);
  115. extern int __put_user_2(void *, unsigned int);
  116. extern int __put_user_4(void *, unsigned int);
  117. extern int __put_user_8(void *, unsigned long long);
  118. #define __put_user_x(__r2,__p,__e,__s) \
  119. __asm__ __volatile__ ( \
  120. __asmeq("%0", "r0") __asmeq("%2", "r2") \
  121. "bl __put_user_" #__s \
  122. : "=&r" (__e) \
  123. : "0" (__p), "r" (__r2) \
  124. : "ip", "lr", "cc")
  125. #define put_user(x,p) \
  126. ({ \
  127. register const typeof(*(p)) __r2 asm("r2") = (x); \
  128. register const typeof(*(p)) __user *__p asm("r0") = (p);\
  129. register int __e asm("r0"); \
  130. switch (sizeof(*(__p))) { \
  131. case 1: \
  132. __put_user_x(__r2, __p, __e, 1); \
  133. break; \
  134. case 2: \
  135. __put_user_x(__r2, __p, __e, 2); \
  136. break; \
  137. case 4: \
  138. __put_user_x(__r2, __p, __e, 4); \
  139. break; \
  140. case 8: \
  141. __put_user_x(__r2, __p, __e, 8); \
  142. break; \
  143. default: __e = __put_user_bad(); break; \
  144. } \
  145. __e; \
  146. })
  147. #else /* CONFIG_MMU */
  148. /*
  149. * uClinux has only one addr space, so has simplified address limits.
  150. */
  151. #define USER_DS KERNEL_DS
  152. #define segment_eq(a,b) (1)
  153. #define __addr_ok(addr) (1)
  154. #define __range_ok(addr,size) (0)
  155. #define get_fs() (KERNEL_DS)
  156. static inline void set_fs(mm_segment_t fs)
  157. {
  158. }
  159. #define get_user(x,p) __get_user(x,p)
  160. #define put_user(x,p) __put_user(x,p)
  161. #endif /* CONFIG_MMU */
  162. #define access_ok(type,addr,size) (__range_ok(addr,size) == 0)
  163. /*
  164. * The "__xxx" versions of the user access functions do not verify the
  165. * address space - it must have been done previously with a separate
  166. * "access_ok()" call.
  167. *
  168. * The "xxx_error" versions set the third argument to EFAULT if an
  169. * error occurs, and leave it unchanged on success. Note that these
  170. * versions are void (ie, don't return a value as such).
  171. */
  172. #define __get_user(x,ptr) \
  173. ({ \
  174. long __gu_err = 0; \
  175. __get_user_err((x),(ptr),__gu_err); \
  176. __gu_err; \
  177. })
  178. #define __get_user_error(x,ptr,err) \
  179. ({ \
  180. __get_user_err((x),(ptr),err); \
  181. (void) 0; \
  182. })
  183. #define __get_user_err(x,ptr,err) \
  184. do { \
  185. unsigned long __gu_addr = (unsigned long)(ptr); \
  186. unsigned long __gu_val; \
  187. __chk_user_ptr(ptr); \
  188. switch (sizeof(*(ptr))) { \
  189. case 1: __get_user_asm_byte(__gu_val,__gu_addr,err); break; \
  190. case 2: __get_user_asm_half(__gu_val,__gu_addr,err); break; \
  191. case 4: __get_user_asm_word(__gu_val,__gu_addr,err); break; \
  192. default: (__gu_val) = __get_user_bad(); \
  193. } \
  194. (x) = (__typeof__(*(ptr)))__gu_val; \
  195. } while (0)
  196. #define __get_user_asm_byte(x,addr,err) \
  197. __asm__ __volatile__( \
  198. "1: ldrbt %1,[%2]\n" \
  199. "2:\n" \
  200. " .section .fixup,\"ax\"\n" \
  201. " .align 2\n" \
  202. "3: mov %0, %3\n" \
  203. " mov %1, #0\n" \
  204. " b 2b\n" \
  205. " .previous\n" \
  206. " .section __ex_table,\"a\"\n" \
  207. " .align 3\n" \
  208. " .long 1b, 3b\n" \
  209. " .previous" \
  210. : "+r" (err), "=&r" (x) \
  211. : "r" (addr), "i" (-EFAULT) \
  212. : "cc")
  213. #ifndef __ARMEB__
  214. #define __get_user_asm_half(x,__gu_addr,err) \
  215. ({ \
  216. unsigned long __b1, __b2; \
  217. __get_user_asm_byte(__b1, __gu_addr, err); \
  218. __get_user_asm_byte(__b2, __gu_addr + 1, err); \
  219. (x) = __b1 | (__b2 << 8); \
  220. })
  221. #else
  222. #define __get_user_asm_half(x,__gu_addr,err) \
  223. ({ \
  224. unsigned long __b1, __b2; \
  225. __get_user_asm_byte(__b1, __gu_addr, err); \
  226. __get_user_asm_byte(__b2, __gu_addr + 1, err); \
  227. (x) = (__b1 << 8) | __b2; \
  228. })
  229. #endif
  230. #define __get_user_asm_word(x,addr,err) \
  231. __asm__ __volatile__( \
  232. "1: ldrt %1,[%2]\n" \
  233. "2:\n" \
  234. " .section .fixup,\"ax\"\n" \
  235. " .align 2\n" \
  236. "3: mov %0, %3\n" \
  237. " mov %1, #0\n" \
  238. " b 2b\n" \
  239. " .previous\n" \
  240. " .section __ex_table,\"a\"\n" \
  241. " .align 3\n" \
  242. " .long 1b, 3b\n" \
  243. " .previous" \
  244. : "+r" (err), "=&r" (x) \
  245. : "r" (addr), "i" (-EFAULT) \
  246. : "cc")
  247. #define __put_user(x,ptr) \
  248. ({ \
  249. long __pu_err = 0; \
  250. __put_user_err((x),(ptr),__pu_err); \
  251. __pu_err; \
  252. })
  253. #define __put_user_error(x,ptr,err) \
  254. ({ \
  255. __put_user_err((x),(ptr),err); \
  256. (void) 0; \
  257. })
  258. #define __put_user_err(x,ptr,err) \
  259. do { \
  260. unsigned long __pu_addr = (unsigned long)(ptr); \
  261. __typeof__(*(ptr)) __pu_val = (x); \
  262. __chk_user_ptr(ptr); \
  263. switch (sizeof(*(ptr))) { \
  264. case 1: __put_user_asm_byte(__pu_val,__pu_addr,err); break; \
  265. case 2: __put_user_asm_half(__pu_val,__pu_addr,err); break; \
  266. case 4: __put_user_asm_word(__pu_val,__pu_addr,err); break; \
  267. case 8: __put_user_asm_dword(__pu_val,__pu_addr,err); break; \
  268. default: __put_user_bad(); \
  269. } \
  270. } while (0)
  271. #define __put_user_asm_byte(x,__pu_addr,err) \
  272. __asm__ __volatile__( \
  273. "1: strbt %1,[%2]\n" \
  274. "2:\n" \
  275. " .section .fixup,\"ax\"\n" \
  276. " .align 2\n" \
  277. "3: mov %0, %3\n" \
  278. " b 2b\n" \
  279. " .previous\n" \
  280. " .section __ex_table,\"a\"\n" \
  281. " .align 3\n" \
  282. " .long 1b, 3b\n" \
  283. " .previous" \
  284. : "+r" (err) \
  285. : "r" (x), "r" (__pu_addr), "i" (-EFAULT) \
  286. : "cc")
  287. #ifndef __ARMEB__
  288. #define __put_user_asm_half(x,__pu_addr,err) \
  289. ({ \
  290. unsigned long __temp = (unsigned long)(x); \
  291. __put_user_asm_byte(__temp, __pu_addr, err); \
  292. __put_user_asm_byte(__temp >> 8, __pu_addr + 1, err); \
  293. })
  294. #else
  295. #define __put_user_asm_half(x,__pu_addr,err) \
  296. ({ \
  297. unsigned long __temp = (unsigned long)(x); \
  298. __put_user_asm_byte(__temp >> 8, __pu_addr, err); \
  299. __put_user_asm_byte(__temp, __pu_addr + 1, err); \
  300. })
  301. #endif
  302. #define __put_user_asm_word(x,__pu_addr,err) \
  303. __asm__ __volatile__( \
  304. "1: strt %1,[%2]\n" \
  305. "2:\n" \
  306. " .section .fixup,\"ax\"\n" \
  307. " .align 2\n" \
  308. "3: mov %0, %3\n" \
  309. " b 2b\n" \
  310. " .previous\n" \
  311. " .section __ex_table,\"a\"\n" \
  312. " .align 3\n" \
  313. " .long 1b, 3b\n" \
  314. " .previous" \
  315. : "+r" (err) \
  316. : "r" (x), "r" (__pu_addr), "i" (-EFAULT) \
  317. : "cc")
  318. #ifndef __ARMEB__
  319. #define __reg_oper0 "%R2"
  320. #define __reg_oper1 "%Q2"
  321. #else
  322. #define __reg_oper0 "%Q2"
  323. #define __reg_oper1 "%R2"
  324. #endif
  325. #define __put_user_asm_dword(x,__pu_addr,err) \
  326. __asm__ __volatile__( \
  327. "1: strt " __reg_oper1 ", [%1], #4\n" \
  328. "2: strt " __reg_oper0 ", [%1]\n" \
  329. "3:\n" \
  330. " .section .fixup,\"ax\"\n" \
  331. " .align 2\n" \
  332. "4: mov %0, %3\n" \
  333. " b 3b\n" \
  334. " .previous\n" \
  335. " .section __ex_table,\"a\"\n" \
  336. " .align 3\n" \
  337. " .long 1b, 4b\n" \
  338. " .long 2b, 4b\n" \
  339. " .previous" \
  340. : "+r" (err), "+r" (__pu_addr) \
  341. : "r" (x), "i" (-EFAULT) \
  342. : "cc")
  343. #ifdef CONFIG_MMU
  344. extern unsigned long __must_check __copy_from_user(void *to, const void __user *from, unsigned long n);
  345. extern unsigned long __must_check __copy_to_user(void __user *to, const void *from, unsigned long n);
  346. extern unsigned long __must_check __clear_user(void __user *addr, unsigned long n);
  347. #else
  348. #define __copy_from_user(to,from,n) (memcpy(to, (void __force *)from, n), 0)
  349. #define __copy_to_user(to,from,n) (memcpy((void __force *)to, from, n), 0)
  350. #define __clear_user(addr,n) (memset((void __force *)addr, 0, n), 0)
  351. #endif
  352. extern unsigned long __must_check __strncpy_from_user(char *to, const char __user *from, unsigned long count);
  353. extern unsigned long __must_check __strnlen_user(const char __user *s, long n);
  354. static inline unsigned long __must_check copy_from_user(void *to, const void __user *from, unsigned long n)
  355. {
  356. if (access_ok(VERIFY_READ, from, n))
  357. n = __copy_from_user(to, from, n);
  358. else /* security hole - plug it */
  359. memzero(to, n);
  360. return n;
  361. }
  362. static inline unsigned long __must_check copy_to_user(void __user *to, const void *from, unsigned long n)
  363. {
  364. if (access_ok(VERIFY_WRITE, to, n))
  365. n = __copy_to_user(to, from, n);
  366. return n;
  367. }
  368. #define __copy_to_user_inatomic __copy_to_user
  369. #define __copy_from_user_inatomic __copy_from_user
  370. static inline unsigned long __must_check clear_user(void __user *to, unsigned long n)
  371. {
  372. if (access_ok(VERIFY_WRITE, to, n))
  373. n = __clear_user(to, n);
  374. return n;
  375. }
  376. static inline long __must_check strncpy_from_user(char *dst, const char __user *src, long count)
  377. {
  378. long res = -EFAULT;
  379. if (access_ok(VERIFY_READ, src, 1))
  380. res = __strncpy_from_user(dst, src, count);
  381. return res;
  382. }
  383. #define strlen_user(s) strnlen_user(s, ~0UL >> 1)
  384. static inline long __must_check strnlen_user(const char __user *s, long n)
  385. {
  386. unsigned long res = 0;
  387. if (__addr_ok(s))
  388. res = __strnlen_user(s, n);
  389. return res;
  390. }
  391. #endif /* _ASMARM_UACCESS_H */