1/*
2 * comedi/comedi_compat32.c
3 * 32-bit ioctl compatibility for 64-bit comedi kernel module.
4 *
5 * Author: Ian Abbott, MEV Ltd. <abbotti@mev.co.uk>
6 * Copyright (C) 2007 MEV Ltd. <http://www.mev.co.uk/>
7 *
8 * COMEDI - Linux Control and Measurement Device Interface
9 * Copyright (C) 1997-2007 David A. Schleef <ds@schleef.org>
10 *
11 * This program is free software; you can redistribute it and/or modify
12 * it under the terms of the GNU General Public License as published by
13 * the Free Software Foundation; either version 2 of the License, or
14 * (at your option) any later version.
15 *
16 * This program is distributed in the hope that it will be useful,
17 * but WITHOUT ANY WARRANTY; without even the implied warranty of
18 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
19 * GNU General Public License for more details.
20 */
21
22#include <linux/uaccess.h>
23#include <linux/compat.h>
24#include <linux/fs.h>
25#include "comedi.h"
26#include "comedi_compat32.h"
27
28#define COMEDI32_CHANINFO _IOR(CIO, 3, struct comedi32_chaninfo_struct)
29#define COMEDI32_RANGEINFO _IOR(CIO, 8, struct comedi32_rangeinfo_struct)
30/*
31 * N.B. COMEDI32_CMD and COMEDI_CMD ought to use _IOWR, not _IOR.
32 * It's too late to change it now, but it only affects the command number.
33 */
34#define COMEDI32_CMD _IOR(CIO, 9, struct comedi32_cmd_struct)
35/*
36 * N.B. COMEDI32_CMDTEST and COMEDI_CMDTEST ought to use _IOWR, not _IOR.
37 * It's too late to change it now, but it only affects the command number.
38 */
39#define COMEDI32_CMDTEST _IOR(CIO, 10, struct comedi32_cmd_struct)
40#define COMEDI32_INSNLIST _IOR(CIO, 11, struct comedi32_insnlist_struct)
41#define COMEDI32_INSN _IOR(CIO, 12, struct comedi32_insn_struct)
42
43struct comedi32_chaninfo_struct {
44	unsigned int subdev;
45	compat_uptr_t maxdata_list;	/* 32-bit 'unsigned int *' */
46	compat_uptr_t flaglist;		/* 32-bit 'unsigned int *' */
47	compat_uptr_t rangelist;	/* 32-bit 'unsigned int *' */
48	unsigned int unused[4];
49};
50
51struct comedi32_rangeinfo_struct {
52	unsigned int range_type;
53	compat_uptr_t range_ptr;	/* 32-bit 'void *' */
54};
55
56struct comedi32_cmd_struct {
57	unsigned int subdev;
58	unsigned int flags;
59	unsigned int start_src;
60	unsigned int start_arg;
61	unsigned int scan_begin_src;
62	unsigned int scan_begin_arg;
63	unsigned int convert_src;
64	unsigned int convert_arg;
65	unsigned int scan_end_src;
66	unsigned int scan_end_arg;
67	unsigned int stop_src;
68	unsigned int stop_arg;
69	compat_uptr_t chanlist;		/* 32-bit 'unsigned int *' */
70	unsigned int chanlist_len;
71	compat_uptr_t data;		/* 32-bit 'short *' */
72	unsigned int data_len;
73};
74
75struct comedi32_insn_struct {
76	unsigned int insn;
77	unsigned int n;
78	compat_uptr_t data;		/* 32-bit 'unsigned int *' */
79	unsigned int subdev;
80	unsigned int chanspec;
81	unsigned int unused[3];
82};
83
84struct comedi32_insnlist_struct {
85	unsigned int n_insns;
86	compat_uptr_t insns;		/* 32-bit 'struct comedi_insn *' */
87};
88
89/* Handle translated ioctl. */
90static int translated_ioctl(struct file *file, unsigned int cmd,
91			    unsigned long arg)
92{
93	if (file->f_op->unlocked_ioctl)
94		return file->f_op->unlocked_ioctl(file, cmd, arg);
95
96	return -ENOTTY;
97}
98
99/* Handle 32-bit COMEDI_CHANINFO ioctl. */
100static int compat_chaninfo(struct file *file, unsigned long arg)
101{
102	struct comedi_chaninfo __user *chaninfo;
103	struct comedi32_chaninfo_struct __user *chaninfo32;
104	int err;
105	union {
106		unsigned int uint;
107		compat_uptr_t uptr;
108	} temp;
109
110	chaninfo32 = compat_ptr(arg);
111	chaninfo = compat_alloc_user_space(sizeof(*chaninfo));
112
113	/* Copy chaninfo structure.  Ignore unused members. */
114	if (!access_ok(VERIFY_READ, chaninfo32, sizeof(*chaninfo32)) ||
115	    !access_ok(VERIFY_WRITE, chaninfo, sizeof(*chaninfo)))
116		return -EFAULT;
117
118	err = 0;
119	err |= __get_user(temp.uint, &chaninfo32->subdev);
120	err |= __put_user(temp.uint, &chaninfo->subdev);
121	err |= __get_user(temp.uptr, &chaninfo32->maxdata_list);
122	err |= __put_user(compat_ptr(temp.uptr), &chaninfo->maxdata_list);
123	err |= __get_user(temp.uptr, &chaninfo32->flaglist);
124	err |= __put_user(compat_ptr(temp.uptr), &chaninfo->flaglist);
125	err |= __get_user(temp.uptr, &chaninfo32->rangelist);
126	err |= __put_user(compat_ptr(temp.uptr), &chaninfo->rangelist);
127	if (err)
128		return -EFAULT;
129
130	return translated_ioctl(file, COMEDI_CHANINFO, (unsigned long)chaninfo);
131}
132
133/* Handle 32-bit COMEDI_RANGEINFO ioctl. */
134static int compat_rangeinfo(struct file *file, unsigned long arg)
135{
136	struct comedi_rangeinfo __user *rangeinfo;
137	struct comedi32_rangeinfo_struct __user *rangeinfo32;
138	int err;
139	union {
140		unsigned int uint;
141		compat_uptr_t uptr;
142	} temp;
143
144	rangeinfo32 = compat_ptr(arg);
145	rangeinfo = compat_alloc_user_space(sizeof(*rangeinfo));
146
147	/* Copy rangeinfo structure. */
148	if (!access_ok(VERIFY_READ, rangeinfo32, sizeof(*rangeinfo32)) ||
149	    !access_ok(VERIFY_WRITE, rangeinfo, sizeof(*rangeinfo)))
150		return -EFAULT;
151
152	err = 0;
153	err |= __get_user(temp.uint, &rangeinfo32->range_type);
154	err |= __put_user(temp.uint, &rangeinfo->range_type);
155	err |= __get_user(temp.uptr, &rangeinfo32->range_ptr);
156	err |= __put_user(compat_ptr(temp.uptr), &rangeinfo->range_ptr);
157	if (err)
158		return -EFAULT;
159
160	return translated_ioctl(file, COMEDI_RANGEINFO,
161				(unsigned long)rangeinfo);
162}
163
164/* Copy 32-bit cmd structure to native cmd structure. */
165static int get_compat_cmd(struct comedi_cmd __user *cmd,
166			  struct comedi32_cmd_struct __user *cmd32)
167{
168	int err;
169	union {
170		unsigned int uint;
171		compat_uptr_t uptr;
172	} temp;
173
174	/* Copy cmd structure. */
175	if (!access_ok(VERIFY_READ, cmd32, sizeof(*cmd32)) ||
176	    !access_ok(VERIFY_WRITE, cmd, sizeof(*cmd)))
177		return -EFAULT;
178
179	err = 0;
180	err |= __get_user(temp.uint, &cmd32->subdev);
181	err |= __put_user(temp.uint, &cmd->subdev);
182	err |= __get_user(temp.uint, &cmd32->flags);
183	err |= __put_user(temp.uint, &cmd->flags);
184	err |= __get_user(temp.uint, &cmd32->start_src);
185	err |= __put_user(temp.uint, &cmd->start_src);
186	err |= __get_user(temp.uint, &cmd32->start_arg);
187	err |= __put_user(temp.uint, &cmd->start_arg);
188	err |= __get_user(temp.uint, &cmd32->scan_begin_src);
189	err |= __put_user(temp.uint, &cmd->scan_begin_src);
190	err |= __get_user(temp.uint, &cmd32->scan_begin_arg);
191	err |= __put_user(temp.uint, &cmd->scan_begin_arg);
192	err |= __get_user(temp.uint, &cmd32->convert_src);
193	err |= __put_user(temp.uint, &cmd->convert_src);
194	err |= __get_user(temp.uint, &cmd32->convert_arg);
195	err |= __put_user(temp.uint, &cmd->convert_arg);
196	err |= __get_user(temp.uint, &cmd32->scan_end_src);
197	err |= __put_user(temp.uint, &cmd->scan_end_src);
198	err |= __get_user(temp.uint, &cmd32->scan_end_arg);
199	err |= __put_user(temp.uint, &cmd->scan_end_arg);
200	err |= __get_user(temp.uint, &cmd32->stop_src);
201	err |= __put_user(temp.uint, &cmd->stop_src);
202	err |= __get_user(temp.uint, &cmd32->stop_arg);
203	err |= __put_user(temp.uint, &cmd->stop_arg);
204	err |= __get_user(temp.uptr, &cmd32->chanlist);
205	err |= __put_user(compat_ptr(temp.uptr), &cmd->chanlist);
206	err |= __get_user(temp.uint, &cmd32->chanlist_len);
207	err |= __put_user(temp.uint, &cmd->chanlist_len);
208	err |= __get_user(temp.uptr, &cmd32->data);
209	err |= __put_user(compat_ptr(temp.uptr), &cmd->data);
210	err |= __get_user(temp.uint, &cmd32->data_len);
211	err |= __put_user(temp.uint, &cmd->data_len);
212	return err ? -EFAULT : 0;
213}
214
215/* Copy native cmd structure to 32-bit cmd structure. */
216static int put_compat_cmd(struct comedi32_cmd_struct __user *cmd32,
217			  struct comedi_cmd __user *cmd)
218{
219	int err;
220	unsigned int temp;
221
222	/*
223	 * Copy back most of cmd structure.
224	 *
225	 * Assume the pointer values are already valid.
226	 * (Could use ptr_to_compat() to set them.)
227	 */
228	if (!access_ok(VERIFY_READ, cmd, sizeof(*cmd)) ||
229	    !access_ok(VERIFY_WRITE, cmd32, sizeof(*cmd32)))
230		return -EFAULT;
231
232	err = 0;
233	err |= __get_user(temp, &cmd->subdev);
234	err |= __put_user(temp, &cmd32->subdev);
235	err |= __get_user(temp, &cmd->flags);
236	err |= __put_user(temp, &cmd32->flags);
237	err |= __get_user(temp, &cmd->start_src);
238	err |= __put_user(temp, &cmd32->start_src);
239	err |= __get_user(temp, &cmd->start_arg);
240	err |= __put_user(temp, &cmd32->start_arg);
241	err |= __get_user(temp, &cmd->scan_begin_src);
242	err |= __put_user(temp, &cmd32->scan_begin_src);
243	err |= __get_user(temp, &cmd->scan_begin_arg);
244	err |= __put_user(temp, &cmd32->scan_begin_arg);
245	err |= __get_user(temp, &cmd->convert_src);
246	err |= __put_user(temp, &cmd32->convert_src);
247	err |= __get_user(temp, &cmd->convert_arg);
248	err |= __put_user(temp, &cmd32->convert_arg);
249	err |= __get_user(temp, &cmd->scan_end_src);
250	err |= __put_user(temp, &cmd32->scan_end_src);
251	err |= __get_user(temp, &cmd->scan_end_arg);
252	err |= __put_user(temp, &cmd32->scan_end_arg);
253	err |= __get_user(temp, &cmd->stop_src);
254	err |= __put_user(temp, &cmd32->stop_src);
255	err |= __get_user(temp, &cmd->stop_arg);
256	err |= __put_user(temp, &cmd32->stop_arg);
257	/* Assume chanlist pointer is unchanged. */
258	err |= __get_user(temp, &cmd->chanlist_len);
259	err |= __put_user(temp, &cmd32->chanlist_len);
260	/* Assume data pointer is unchanged. */
261	err |= __get_user(temp, &cmd->data_len);
262	err |= __put_user(temp, &cmd32->data_len);
263	return err ? -EFAULT : 0;
264}
265
266/* Handle 32-bit COMEDI_CMD ioctl. */
267static int compat_cmd(struct file *file, unsigned long arg)
268{
269	struct comedi_cmd __user *cmd;
270	struct comedi32_cmd_struct __user *cmd32;
271	int rc, err;
272
273	cmd32 = compat_ptr(arg);
274	cmd = compat_alloc_user_space(sizeof(*cmd));
275
276	rc = get_compat_cmd(cmd, cmd32);
277	if (rc)
278		return rc;
279
280	rc = translated_ioctl(file, COMEDI_CMD, (unsigned long)cmd);
281	if (rc == -EAGAIN) {
282		/* Special case: copy cmd back to user. */
283		err = put_compat_cmd(cmd32, cmd);
284		if (err)
285			rc = err;
286	}
287
288	return rc;
289}
290
291/* Handle 32-bit COMEDI_CMDTEST ioctl. */
292static int compat_cmdtest(struct file *file, unsigned long arg)
293{
294	struct comedi_cmd __user *cmd;
295	struct comedi32_cmd_struct __user *cmd32;
296	int rc, err;
297
298	cmd32 = compat_ptr(arg);
299	cmd = compat_alloc_user_space(sizeof(*cmd));
300
301	rc = get_compat_cmd(cmd, cmd32);
302	if (rc)
303		return rc;
304
305	rc = translated_ioctl(file, COMEDI_CMDTEST, (unsigned long)cmd);
306	if (rc < 0)
307		return rc;
308
309	err = put_compat_cmd(cmd32, cmd);
310	if (err)
311		rc = err;
312
313	return rc;
314}
315
316/* Copy 32-bit insn structure to native insn structure. */
317static int get_compat_insn(struct comedi_insn __user *insn,
318			   struct comedi32_insn_struct __user *insn32)
319{
320	int err;
321	union {
322		unsigned int uint;
323		compat_uptr_t uptr;
324	} temp;
325
326	/* Copy insn structure.  Ignore the unused members. */
327	err = 0;
328	if (!access_ok(VERIFY_READ, insn32, sizeof(*insn32)) ||
329	    !access_ok(VERIFY_WRITE, insn, sizeof(*insn)))
330		return -EFAULT;
331
332	err |= __get_user(temp.uint, &insn32->insn);
333	err |= __put_user(temp.uint, &insn->insn);
334	err |= __get_user(temp.uint, &insn32->n);
335	err |= __put_user(temp.uint, &insn->n);
336	err |= __get_user(temp.uptr, &insn32->data);
337	err |= __put_user(compat_ptr(temp.uptr), &insn->data);
338	err |= __get_user(temp.uint, &insn32->subdev);
339	err |= __put_user(temp.uint, &insn->subdev);
340	err |= __get_user(temp.uint, &insn32->chanspec);
341	err |= __put_user(temp.uint, &insn->chanspec);
342	return err ? -EFAULT : 0;
343}
344
345/* Handle 32-bit COMEDI_INSNLIST ioctl. */
346static int compat_insnlist(struct file *file, unsigned long arg)
347{
348	struct combined_insnlist {
349		struct comedi_insnlist insnlist;
350		struct comedi_insn insn[1];
351	} __user *s;
352	struct comedi32_insnlist_struct __user *insnlist32;
353	struct comedi32_insn_struct __user *insn32;
354	compat_uptr_t uptr;
355	unsigned int n_insns, n;
356	int err, rc;
357
358	insnlist32 = compat_ptr(arg);
359
360	/* Get 32-bit insnlist structure.  */
361	if (!access_ok(VERIFY_READ, insnlist32, sizeof(*insnlist32)))
362		return -EFAULT;
363
364	err = 0;
365	err |= __get_user(n_insns, &insnlist32->n_insns);
366	err |= __get_user(uptr, &insnlist32->insns);
367	insn32 = compat_ptr(uptr);
368	if (err)
369		return -EFAULT;
370
371	/* Allocate user memory to copy insnlist and insns into. */
372	s = compat_alloc_user_space(offsetof(struct combined_insnlist,
373					     insn[n_insns]));
374
375	/* Set native insnlist structure. */
376	if (!access_ok(VERIFY_WRITE, &s->insnlist, sizeof(s->insnlist)))
377		return -EFAULT;
378
379	err |= __put_user(n_insns, &s->insnlist.n_insns);
380	err |= __put_user(&s->insn[0], &s->insnlist.insns);
381	if (err)
382		return -EFAULT;
383
384	/* Copy insn structures. */
385	for (n = 0; n < n_insns; n++) {
386		rc = get_compat_insn(&s->insn[n], &insn32[n]);
387		if (rc)
388			return rc;
389	}
390
391	return translated_ioctl(file, COMEDI_INSNLIST,
392				(unsigned long)&s->insnlist);
393}
394
395/* Handle 32-bit COMEDI_INSN ioctl. */
396static int compat_insn(struct file *file, unsigned long arg)
397{
398	struct comedi_insn __user *insn;
399	struct comedi32_insn_struct __user *insn32;
400	int rc;
401
402	insn32 = compat_ptr(arg);
403	insn = compat_alloc_user_space(sizeof(*insn));
404
405	rc = get_compat_insn(insn, insn32);
406	if (rc)
407		return rc;
408
409	return translated_ioctl(file, COMEDI_INSN, (unsigned long)insn);
410}
411
412/*
413 * compat_ioctl file operation.
414 *
415 * Returns -ENOIOCTLCMD for unrecognised ioctl codes.
416 */
417long comedi_compat_ioctl(struct file *file, unsigned int cmd, unsigned long arg)
418{
419	int rc;
420
421	switch (cmd) {
422	case COMEDI_DEVCONFIG:
423	case COMEDI_DEVINFO:
424	case COMEDI_SUBDINFO:
425	case COMEDI_BUFCONFIG:
426	case COMEDI_BUFINFO:
427		/* Just need to translate the pointer argument. */
428		arg = (unsigned long)compat_ptr(arg);
429		rc = translated_ioctl(file, cmd, arg);
430		break;
431	case COMEDI_LOCK:
432	case COMEDI_UNLOCK:
433	case COMEDI_CANCEL:
434	case COMEDI_POLL:
435	case COMEDI_SETRSUBD:
436	case COMEDI_SETWSUBD:
437		/* No translation needed. */
438		rc = translated_ioctl(file, cmd, arg);
439		break;
440	case COMEDI32_CHANINFO:
441		rc = compat_chaninfo(file, arg);
442		break;
443	case COMEDI32_RANGEINFO:
444		rc = compat_rangeinfo(file, arg);
445		break;
446	case COMEDI32_CMD:
447		rc = compat_cmd(file, arg);
448		break;
449	case COMEDI32_CMDTEST:
450		rc = compat_cmdtest(file, arg);
451		break;
452	case COMEDI32_INSNLIST:
453		rc = compat_insnlist(file, arg);
454		break;
455	case COMEDI32_INSN:
456		rc = compat_insn(file, arg);
457		break;
458	default:
459		rc = -ENOIOCTLCMD;
460		break;
461	}
462	return rc;
463}
464