1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22#include <linux/uaccess.h>
23#include <linux/compat.h>
24#include <linux/fs.h>
25#include "comedi.h"
26#include "comedi_compat32.h"
27
28#define COMEDI32_CHANINFO _IOR(CIO, 3, struct comedi32_chaninfo_struct)
29#define COMEDI32_RANGEINFO _IOR(CIO, 8, struct comedi32_rangeinfo_struct)
30
31
32
33
34#define COMEDI32_CMD _IOR(CIO, 9, struct comedi32_cmd_struct)
35
36
37
38
39#define COMEDI32_CMDTEST _IOR(CIO, 10, struct comedi32_cmd_struct)
40#define COMEDI32_INSNLIST _IOR(CIO, 11, struct comedi32_insnlist_struct)
41#define COMEDI32_INSN _IOR(CIO, 12, struct comedi32_insn_struct)
42
43struct comedi32_chaninfo_struct {
44 unsigned int subdev;
45 compat_uptr_t maxdata_list;
46 compat_uptr_t flaglist;
47 compat_uptr_t rangelist;
48 unsigned int unused[4];
49};
50
51struct comedi32_rangeinfo_struct {
52 unsigned int range_type;
53 compat_uptr_t range_ptr;
54};
55
56struct comedi32_cmd_struct {
57 unsigned int subdev;
58 unsigned int flags;
59 unsigned int start_src;
60 unsigned int start_arg;
61 unsigned int scan_begin_src;
62 unsigned int scan_begin_arg;
63 unsigned int convert_src;
64 unsigned int convert_arg;
65 unsigned int scan_end_src;
66 unsigned int scan_end_arg;
67 unsigned int stop_src;
68 unsigned int stop_arg;
69 compat_uptr_t chanlist;
70 unsigned int chanlist_len;
71 compat_uptr_t data;
72 unsigned int data_len;
73};
74
75struct comedi32_insn_struct {
76 unsigned int insn;
77 unsigned int n;
78 compat_uptr_t data;
79 unsigned int subdev;
80 unsigned int chanspec;
81 unsigned int unused[3];
82};
83
84struct comedi32_insnlist_struct {
85 unsigned int n_insns;
86 compat_uptr_t insns;
87};
88
89
90static int translated_ioctl(struct file *file, unsigned int cmd,
91 unsigned long arg)
92{
93 if (file->f_op->unlocked_ioctl)
94 return file->f_op->unlocked_ioctl(file, cmd, arg);
95
96 return -ENOTTY;
97}
98
99
100static int compat_chaninfo(struct file *file, unsigned long arg)
101{
102 struct comedi_chaninfo __user *chaninfo;
103 struct comedi32_chaninfo_struct __user *chaninfo32;
104 int err;
105 union {
106 unsigned int uint;
107 compat_uptr_t uptr;
108 } temp;
109
110 chaninfo32 = compat_ptr(arg);
111 chaninfo = compat_alloc_user_space(sizeof(*chaninfo));
112
113
114 if (!access_ok(VERIFY_READ, chaninfo32, sizeof(*chaninfo32)) ||
115 !access_ok(VERIFY_WRITE, chaninfo, sizeof(*chaninfo)))
116 return -EFAULT;
117
118 err = 0;
119 err |= __get_user(temp.uint, &chaninfo32->subdev);
120 err |= __put_user(temp.uint, &chaninfo->subdev);
121 err |= __get_user(temp.uptr, &chaninfo32->maxdata_list);
122 err |= __put_user(compat_ptr(temp.uptr), &chaninfo->maxdata_list);
123 err |= __get_user(temp.uptr, &chaninfo32->flaglist);
124 err |= __put_user(compat_ptr(temp.uptr), &chaninfo->flaglist);
125 err |= __get_user(temp.uptr, &chaninfo32->rangelist);
126 err |= __put_user(compat_ptr(temp.uptr), &chaninfo->rangelist);
127 if (err)
128 return -EFAULT;
129
130 return translated_ioctl(file, COMEDI_CHANINFO, (unsigned long)chaninfo);
131}
132
133
134static int compat_rangeinfo(struct file *file, unsigned long arg)
135{
136 struct comedi_rangeinfo __user *rangeinfo;
137 struct comedi32_rangeinfo_struct __user *rangeinfo32;
138 int err;
139 union {
140 unsigned int uint;
141 compat_uptr_t uptr;
142 } temp;
143
144 rangeinfo32 = compat_ptr(arg);
145 rangeinfo = compat_alloc_user_space(sizeof(*rangeinfo));
146
147
148 if (!access_ok(VERIFY_READ, rangeinfo32, sizeof(*rangeinfo32)) ||
149 !access_ok(VERIFY_WRITE, rangeinfo, sizeof(*rangeinfo)))
150 return -EFAULT;
151
152 err = 0;
153 err |= __get_user(temp.uint, &rangeinfo32->range_type);
154 err |= __put_user(temp.uint, &rangeinfo->range_type);
155 err |= __get_user(temp.uptr, &rangeinfo32->range_ptr);
156 err |= __put_user(compat_ptr(temp.uptr), &rangeinfo->range_ptr);
157 if (err)
158 return -EFAULT;
159
160 return translated_ioctl(file, COMEDI_RANGEINFO,
161 (unsigned long)rangeinfo);
162}
163
164
165static int get_compat_cmd(struct comedi_cmd __user *cmd,
166 struct comedi32_cmd_struct __user *cmd32)
167{
168 int err;
169 union {
170 unsigned int uint;
171 compat_uptr_t uptr;
172 } temp;
173
174
175 if (!access_ok(VERIFY_READ, cmd32, sizeof(*cmd32)) ||
176 !access_ok(VERIFY_WRITE, cmd, sizeof(*cmd)))
177 return -EFAULT;
178
179 err = 0;
180 err |= __get_user(temp.uint, &cmd32->subdev);
181 err |= __put_user(temp.uint, &cmd->subdev);
182 err |= __get_user(temp.uint, &cmd32->flags);
183 err |= __put_user(temp.uint, &cmd->flags);
184 err |= __get_user(temp.uint, &cmd32->start_src);
185 err |= __put_user(temp.uint, &cmd->start_src);
186 err |= __get_user(temp.uint, &cmd32->start_arg);
187 err |= __put_user(temp.uint, &cmd->start_arg);
188 err |= __get_user(temp.uint, &cmd32->scan_begin_src);
189 err |= __put_user(temp.uint, &cmd->scan_begin_src);
190 err |= __get_user(temp.uint, &cmd32->scan_begin_arg);
191 err |= __put_user(temp.uint, &cmd->scan_begin_arg);
192 err |= __get_user(temp.uint, &cmd32->convert_src);
193 err |= __put_user(temp.uint, &cmd->convert_src);
194 err |= __get_user(temp.uint, &cmd32->convert_arg);
195 err |= __put_user(temp.uint, &cmd->convert_arg);
196 err |= __get_user(temp.uint, &cmd32->scan_end_src);
197 err |= __put_user(temp.uint, &cmd->scan_end_src);
198 err |= __get_user(temp.uint, &cmd32->scan_end_arg);
199 err |= __put_user(temp.uint, &cmd->scan_end_arg);
200 err |= __get_user(temp.uint, &cmd32->stop_src);
201 err |= __put_user(temp.uint, &cmd->stop_src);
202 err |= __get_user(temp.uint, &cmd32->stop_arg);
203 err |= __put_user(temp.uint, &cmd->stop_arg);
204 err |= __get_user(temp.uptr, &cmd32->chanlist);
205 err |= __put_user(compat_ptr(temp.uptr), &cmd->chanlist);
206 err |= __get_user(temp.uint, &cmd32->chanlist_len);
207 err |= __put_user(temp.uint, &cmd->chanlist_len);
208 err |= __get_user(temp.uptr, &cmd32->data);
209 err |= __put_user(compat_ptr(temp.uptr), &cmd->data);
210 err |= __get_user(temp.uint, &cmd32->data_len);
211 err |= __put_user(temp.uint, &cmd->data_len);
212 return err ? -EFAULT : 0;
213}
214
215
216static int put_compat_cmd(struct comedi32_cmd_struct __user *cmd32,
217 struct comedi_cmd __user *cmd)
218{
219 int err;
220 unsigned int temp;
221
222
223
224
225
226
227
228 if (!access_ok(VERIFY_READ, cmd, sizeof(*cmd)) ||
229 !access_ok(VERIFY_WRITE, cmd32, sizeof(*cmd32)))
230 return -EFAULT;
231
232 err = 0;
233 err |= __get_user(temp, &cmd->subdev);
234 err |= __put_user(temp, &cmd32->subdev);
235 err |= __get_user(temp, &cmd->flags);
236 err |= __put_user(temp, &cmd32->flags);
237 err |= __get_user(temp, &cmd->start_src);
238 err |= __put_user(temp, &cmd32->start_src);
239 err |= __get_user(temp, &cmd->start_arg);
240 err |= __put_user(temp, &cmd32->start_arg);
241 err |= __get_user(temp, &cmd->scan_begin_src);
242 err |= __put_user(temp, &cmd32->scan_begin_src);
243 err |= __get_user(temp, &cmd->scan_begin_arg);
244 err |= __put_user(temp, &cmd32->scan_begin_arg);
245 err |= __get_user(temp, &cmd->convert_src);
246 err |= __put_user(temp, &cmd32->convert_src);
247 err |= __get_user(temp, &cmd->convert_arg);
248 err |= __put_user(temp, &cmd32->convert_arg);
249 err |= __get_user(temp, &cmd->scan_end_src);
250 err |= __put_user(temp, &cmd32->scan_end_src);
251 err |= __get_user(temp, &cmd->scan_end_arg);
252 err |= __put_user(temp, &cmd32->scan_end_arg);
253 err |= __get_user(temp, &cmd->stop_src);
254 err |= __put_user(temp, &cmd32->stop_src);
255 err |= __get_user(temp, &cmd->stop_arg);
256 err |= __put_user(temp, &cmd32->stop_arg);
257
258 err |= __get_user(temp, &cmd->chanlist_len);
259 err |= __put_user(temp, &cmd32->chanlist_len);
260
261 err |= __get_user(temp, &cmd->data_len);
262 err |= __put_user(temp, &cmd32->data_len);
263 return err ? -EFAULT : 0;
264}
265
266
267static int compat_cmd(struct file *file, unsigned long arg)
268{
269 struct comedi_cmd __user *cmd;
270 struct comedi32_cmd_struct __user *cmd32;
271 int rc, err;
272
273 cmd32 = compat_ptr(arg);
274 cmd = compat_alloc_user_space(sizeof(*cmd));
275
276 rc = get_compat_cmd(cmd, cmd32);
277 if (rc)
278 return rc;
279
280 rc = translated_ioctl(file, COMEDI_CMD, (unsigned long)cmd);
281 if (rc == -EAGAIN) {
282
283 err = put_compat_cmd(cmd32, cmd);
284 if (err)
285 rc = err;
286 }
287
288 return rc;
289}
290
291
292static int compat_cmdtest(struct file *file, unsigned long arg)
293{
294 struct comedi_cmd __user *cmd;
295 struct comedi32_cmd_struct __user *cmd32;
296 int rc, err;
297
298 cmd32 = compat_ptr(arg);
299 cmd = compat_alloc_user_space(sizeof(*cmd));
300
301 rc = get_compat_cmd(cmd, cmd32);
302 if (rc)
303 return rc;
304
305 rc = translated_ioctl(file, COMEDI_CMDTEST, (unsigned long)cmd);
306 if (rc < 0)
307 return rc;
308
309 err = put_compat_cmd(cmd32, cmd);
310 if (err)
311 rc = err;
312
313 return rc;
314}
315
316
317static int get_compat_insn(struct comedi_insn __user *insn,
318 struct comedi32_insn_struct __user *insn32)
319{
320 int err;
321 union {
322 unsigned int uint;
323 compat_uptr_t uptr;
324 } temp;
325
326
327 err = 0;
328 if (!access_ok(VERIFY_READ, insn32, sizeof(*insn32)) ||
329 !access_ok(VERIFY_WRITE, insn, sizeof(*insn)))
330 return -EFAULT;
331
332 err |= __get_user(temp.uint, &insn32->insn);
333 err |= __put_user(temp.uint, &insn->insn);
334 err |= __get_user(temp.uint, &insn32->n);
335 err |= __put_user(temp.uint, &insn->n);
336 err |= __get_user(temp.uptr, &insn32->data);
337 err |= __put_user(compat_ptr(temp.uptr), &insn->data);
338 err |= __get_user(temp.uint, &insn32->subdev);
339 err |= __put_user(temp.uint, &insn->subdev);
340 err |= __get_user(temp.uint, &insn32->chanspec);
341 err |= __put_user(temp.uint, &insn->chanspec);
342 return err ? -EFAULT : 0;
343}
344
345
346static int compat_insnlist(struct file *file, unsigned long arg)
347{
348 struct combined_insnlist {
349 struct comedi_insnlist insnlist;
350 struct comedi_insn insn[1];
351 } __user *s;
352 struct comedi32_insnlist_struct __user *insnlist32;
353 struct comedi32_insn_struct __user *insn32;
354 compat_uptr_t uptr;
355 unsigned int n_insns, n;
356 int err, rc;
357
358 insnlist32 = compat_ptr(arg);
359
360
361 if (!access_ok(VERIFY_READ, insnlist32, sizeof(*insnlist32)))
362 return -EFAULT;
363
364 err = 0;
365 err |= __get_user(n_insns, &insnlist32->n_insns);
366 err |= __get_user(uptr, &insnlist32->insns);
367 insn32 = compat_ptr(uptr);
368 if (err)
369 return -EFAULT;
370
371
372 s = compat_alloc_user_space(offsetof(struct combined_insnlist,
373 insn[n_insns]));
374
375
376 if (!access_ok(VERIFY_WRITE, &s->insnlist, sizeof(s->insnlist)))
377 return -EFAULT;
378
379 err |= __put_user(n_insns, &s->insnlist.n_insns);
380 err |= __put_user(&s->insn[0], &s->insnlist.insns);
381 if (err)
382 return -EFAULT;
383
384
385 for (n = 0; n < n_insns; n++) {
386 rc = get_compat_insn(&s->insn[n], &insn32[n]);
387 if (rc)
388 return rc;
389 }
390
391 return translated_ioctl(file, COMEDI_INSNLIST,
392 (unsigned long)&s->insnlist);
393}
394
395
396static int compat_insn(struct file *file, unsigned long arg)
397{
398 struct comedi_insn __user *insn;
399 struct comedi32_insn_struct __user *insn32;
400 int rc;
401
402 insn32 = compat_ptr(arg);
403 insn = compat_alloc_user_space(sizeof(*insn));
404
405 rc = get_compat_insn(insn, insn32);
406 if (rc)
407 return rc;
408
409 return translated_ioctl(file, COMEDI_INSN, (unsigned long)insn);
410}
411
412
413
414
415
416
417long comedi_compat_ioctl(struct file *file, unsigned int cmd, unsigned long arg)
418{
419 int rc;
420
421 switch (cmd) {
422 case COMEDI_DEVCONFIG:
423 case COMEDI_DEVINFO:
424 case COMEDI_SUBDINFO:
425 case COMEDI_BUFCONFIG:
426 case COMEDI_BUFINFO:
427
428 arg = (unsigned long)compat_ptr(arg);
429 rc = translated_ioctl(file, cmd, arg);
430 break;
431 case COMEDI_LOCK:
432 case COMEDI_UNLOCK:
433 case COMEDI_CANCEL:
434 case COMEDI_POLL:
435 case COMEDI_SETRSUBD:
436 case COMEDI_SETWSUBD:
437
438 rc = translated_ioctl(file, cmd, arg);
439 break;
440 case COMEDI32_CHANINFO:
441 rc = compat_chaninfo(file, arg);
442 break;
443 case COMEDI32_RANGEINFO:
444 rc = compat_rangeinfo(file, arg);
445 break;
446 case COMEDI32_CMD:
447 rc = compat_cmd(file, arg);
448 break;
449 case COMEDI32_CMDTEST:
450 rc = compat_cmdtest(file, arg);
451 break;
452 case COMEDI32_INSNLIST:
453 rc = compat_insnlist(file, arg);
454 break;
455 case COMEDI32_INSN:
456 rc = compat_insn(file, arg);
457 break;
458 default:
459 rc = -ENOIOCTLCMD;
460 break;
461 }
462 return rc;
463}
464