uverbs_ioctl.c 15 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562
  1. /*
  2. * Copyright (c) 2017, Mellanox Technologies inc. All rights reserved.
  3. *
  4. * This software is available to you under a choice of one of two
  5. * licenses. You may choose to be licensed under the terms of the GNU
  6. * General Public License (GPL) Version 2, available from the file
  7. * COPYING in the main directory of this source tree, or the
  8. * OpenIB.org BSD license below:
  9. *
  10. * Redistribution and use in source and binary forms, with or
  11. * without modification, are permitted provided that the following
  12. * conditions are met:
  13. *
  14. * - Redistributions of source code must retain the above
  15. * copyright notice, this list of conditions and the following
  16. * disclaimer.
  17. *
  18. * - Redistributions in binary form must reproduce the above
  19. * copyright notice, this list of conditions and the following
  20. * disclaimer in the documentation and/or other materials
  21. * provided with the distribution.
  22. *
  23. * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,
  24. * EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF
  25. * MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND
  26. * NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS
  27. * BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN
  28. * ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN
  29. * CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
  30. * SOFTWARE.
  31. */
  32. #include <rdma/rdma_user_ioctl.h>
  33. #include <rdma/uverbs_ioctl.h>
  34. #include "rdma_core.h"
  35. #include "uverbs.h"
  36. static bool uverbs_is_attr_cleared(const struct ib_uverbs_attr *uattr,
  37. u16 len)
  38. {
  39. if (uattr->len > sizeof(((struct ib_uverbs_attr *)0)->data))
  40. return ib_is_buffer_cleared(u64_to_user_ptr(uattr->data) + len,
  41. uattr->len - len);
  42. return !memchr_inv((const void *)&uattr->data + len,
  43. 0, uattr->len - len);
  44. }
  45. static int uverbs_process_attr(struct ib_uverbs_file *ufile,
  46. const struct ib_uverbs_attr *uattr,
  47. u16 attr_id,
  48. const struct uverbs_attr_spec_hash *attr_spec_bucket,
  49. struct uverbs_attr_bundle_hash *attr_bundle_h,
  50. struct uverbs_obj_attr **destroy_attr,
  51. struct ib_uverbs_attr __user *uattr_ptr)
  52. {
  53. const struct uverbs_attr_spec *spec;
  54. const struct uverbs_attr_spec *val_spec;
  55. struct uverbs_attr *e;
  56. struct uverbs_obj_attr *o_attr;
  57. struct uverbs_attr *elements = attr_bundle_h->attrs;
  58. if (attr_id >= attr_spec_bucket->num_attrs) {
  59. if (uattr->flags & UVERBS_ATTR_F_MANDATORY)
  60. return -EINVAL;
  61. else
  62. return 0;
  63. }
  64. if (test_bit(attr_id, attr_bundle_h->valid_bitmap))
  65. return -EINVAL;
  66. spec = &attr_spec_bucket->attrs[attr_id];
  67. val_spec = spec;
  68. e = &elements[attr_id];
  69. e->uattr = uattr_ptr;
  70. switch (spec->type) {
  71. case UVERBS_ATTR_TYPE_ENUM_IN:
  72. if (uattr->attr_data.enum_data.elem_id >= spec->u.enum_def.num_elems)
  73. return -EOPNOTSUPP;
  74. if (uattr->attr_data.enum_data.reserved)
  75. return -EINVAL;
  76. val_spec = &spec->u2.enum_def.ids[uattr->attr_data.enum_data.elem_id];
  77. /* Currently we only support PTR_IN based enums */
  78. if (val_spec->type != UVERBS_ATTR_TYPE_PTR_IN)
  79. return -EOPNOTSUPP;
  80. e->ptr_attr.enum_id = uattr->attr_data.enum_data.elem_id;
  81. /* fall through */
  82. case UVERBS_ATTR_TYPE_PTR_IN:
  83. /* Ensure that any data provided by userspace beyond the known
  84. * struct is zero. Userspace that knows how to use some future
  85. * longer struct will fail here if used with an old kernel and
  86. * non-zero content, making ABI compat/discovery simpler.
  87. */
  88. if (uattr->len > val_spec->u.ptr.len &&
  89. val_spec->zero_trailing &&
  90. !uverbs_is_attr_cleared(uattr, val_spec->u.ptr.len))
  91. return -EOPNOTSUPP;
  92. /* fall through */
  93. case UVERBS_ATTR_TYPE_PTR_OUT:
  94. if (uattr->len < val_spec->u.ptr.min_len ||
  95. (!val_spec->zero_trailing &&
  96. uattr->len > val_spec->u.ptr.len))
  97. return -EINVAL;
  98. if (spec->type != UVERBS_ATTR_TYPE_ENUM_IN &&
  99. uattr->attr_data.reserved)
  100. return -EINVAL;
  101. e->ptr_attr.len = uattr->len;
  102. e->ptr_attr.flags = uattr->flags;
  103. if (val_spec->alloc_and_copy && !uverbs_attr_ptr_is_inline(e)) {
  104. void *p;
  105. p = kvmalloc(uattr->len, GFP_KERNEL);
  106. if (!p)
  107. return -ENOMEM;
  108. e->ptr_attr.ptr = p;
  109. if (copy_from_user(p, u64_to_user_ptr(uattr->data),
  110. uattr->len)) {
  111. kvfree(p);
  112. return -EFAULT;
  113. }
  114. } else {
  115. e->ptr_attr.data = uattr->data;
  116. }
  117. break;
  118. case UVERBS_ATTR_TYPE_IDR:
  119. case UVERBS_ATTR_TYPE_FD:
  120. if (uattr->attr_data.reserved)
  121. return -EINVAL;
  122. if (uattr->len != 0)
  123. return -EINVAL;
  124. o_attr = &e->obj_attr;
  125. /* specs are allowed to have only one destroy attribute */
  126. WARN_ON(spec->u.obj.access == UVERBS_ACCESS_DESTROY &&
  127. *destroy_attr);
  128. if (spec->u.obj.access == UVERBS_ACCESS_DESTROY)
  129. *destroy_attr = o_attr;
  130. /*
  131. * The type of uattr->data is u64 for UVERBS_ATTR_TYPE_IDR and
  132. * s64 for UVERBS_ATTR_TYPE_FD. We can cast the u64 to s64
  133. * here without caring about truncation as we know that the
  134. * IDR implementation today rejects negative IDs
  135. */
  136. o_attr->uobject = uverbs_get_uobject_from_file(
  137. spec->u.obj.obj_type,
  138. ufile,
  139. spec->u.obj.access,
  140. uattr->data_s64);
  141. if (IS_ERR(o_attr->uobject))
  142. return PTR_ERR(o_attr->uobject);
  143. if (spec->u.obj.access == UVERBS_ACCESS_NEW) {
  144. s64 id = o_attr->uobject->id;
  145. /* Copy the allocated id to the user-space */
  146. if (put_user(id, &e->uattr->data)) {
  147. uverbs_finalize_object(o_attr->uobject,
  148. UVERBS_ACCESS_NEW,
  149. false);
  150. return -EFAULT;
  151. }
  152. }
  153. break;
  154. default:
  155. return -EOPNOTSUPP;
  156. }
  157. set_bit(attr_id, attr_bundle_h->valid_bitmap);
  158. return 0;
  159. }
  160. static int uverbs_finalize_attrs(struct uverbs_attr_bundle *attrs_bundle,
  161. struct uverbs_attr_spec_hash *const *spec_hash,
  162. size_t num, bool commit)
  163. {
  164. unsigned int i;
  165. int ret = 0;
  166. for (i = 0; i < num; i++) {
  167. struct uverbs_attr_bundle_hash *curr_bundle =
  168. &attrs_bundle->hash[i];
  169. const struct uverbs_attr_spec_hash *curr_spec_bucket =
  170. spec_hash[i];
  171. unsigned int j;
  172. if (!curr_spec_bucket)
  173. continue;
  174. for (j = 0; j < curr_bundle->num_attrs; j++) {
  175. struct uverbs_attr *attr;
  176. const struct uverbs_attr_spec *spec;
  177. if (!uverbs_attr_is_valid_in_hash(curr_bundle, j))
  178. continue;
  179. attr = &curr_bundle->attrs[j];
  180. spec = &curr_spec_bucket->attrs[j];
  181. if (spec->type == UVERBS_ATTR_TYPE_IDR ||
  182. spec->type == UVERBS_ATTR_TYPE_FD) {
  183. int current_ret;
  184. current_ret = uverbs_finalize_object(
  185. attr->obj_attr.uobject,
  186. spec->u.obj.access, commit);
  187. if (!ret)
  188. ret = current_ret;
  189. } else if (spec->type == UVERBS_ATTR_TYPE_PTR_IN &&
  190. spec->alloc_and_copy &&
  191. !uverbs_attr_ptr_is_inline(attr)) {
  192. kvfree(attr->ptr_attr.ptr);
  193. }
  194. }
  195. }
  196. return ret;
  197. }
  198. static int uverbs_uattrs_process(struct ib_uverbs_file *ufile,
  199. const struct ib_uverbs_attr *uattrs,
  200. size_t num_uattrs,
  201. const struct uverbs_method_spec *method,
  202. struct uverbs_attr_bundle *attr_bundle,
  203. struct uverbs_obj_attr **destroy_attr,
  204. struct ib_uverbs_attr __user *uattr_ptr)
  205. {
  206. size_t i;
  207. int ret = 0;
  208. int num_given_buckets = 0;
  209. for (i = 0; i < num_uattrs; i++) {
  210. const struct ib_uverbs_attr *uattr = &uattrs[i];
  211. u16 attr_id = uattr->attr_id;
  212. struct uverbs_attr_spec_hash *attr_spec_bucket;
  213. ret = uverbs_ns_idx(&attr_id, method->num_buckets);
  214. if (ret < 0 || !method->attr_buckets[ret]) {
  215. if (uattr->flags & UVERBS_ATTR_F_MANDATORY) {
  216. uverbs_finalize_attrs(attr_bundle,
  217. method->attr_buckets,
  218. num_given_buckets,
  219. false);
  220. return ret;
  221. }
  222. continue;
  223. }
  224. /*
  225. * ret is the found ns, so increase num_given_buckets if
  226. * necessary.
  227. */
  228. if (ret >= num_given_buckets)
  229. num_given_buckets = ret + 1;
  230. attr_spec_bucket = method->attr_buckets[ret];
  231. ret = uverbs_process_attr(ufile, uattr, attr_id,
  232. attr_spec_bucket,
  233. &attr_bundle->hash[ret], destroy_attr,
  234. uattr_ptr++);
  235. if (ret) {
  236. uverbs_finalize_attrs(attr_bundle,
  237. method->attr_buckets,
  238. num_given_buckets,
  239. false);
  240. return ret;
  241. }
  242. }
  243. return num_given_buckets;
  244. }
  245. static int uverbs_validate_kernel_mandatory(const struct uverbs_method_spec *method_spec,
  246. struct uverbs_attr_bundle *attr_bundle)
  247. {
  248. unsigned int i;
  249. for (i = 0; i < attr_bundle->num_buckets; i++) {
  250. struct uverbs_attr_spec_hash *attr_spec_bucket =
  251. method_spec->attr_buckets[i];
  252. if (!attr_spec_bucket)
  253. continue;
  254. if (!bitmap_subset(attr_spec_bucket->mandatory_attrs_bitmask,
  255. attr_bundle->hash[i].valid_bitmap,
  256. attr_spec_bucket->num_attrs))
  257. return -EINVAL;
  258. }
  259. for (; i < method_spec->num_buckets; i++) {
  260. struct uverbs_attr_spec_hash *attr_spec_bucket =
  261. method_spec->attr_buckets[i];
  262. if (!bitmap_empty(attr_spec_bucket->mandatory_attrs_bitmask,
  263. attr_spec_bucket->num_attrs))
  264. return -EINVAL;
  265. }
  266. return 0;
  267. }
  268. static int uverbs_handle_method(struct ib_uverbs_attr __user *uattr_ptr,
  269. const struct ib_uverbs_attr *uattrs,
  270. size_t num_uattrs,
  271. struct ib_device *ibdev,
  272. struct ib_uverbs_file *ufile,
  273. const struct uverbs_method_spec *method_spec,
  274. struct uverbs_attr_bundle *attr_bundle)
  275. {
  276. int ret;
  277. int finalize_ret;
  278. int num_given_buckets;
  279. struct uverbs_obj_attr *destroy_attr = NULL;
  280. num_given_buckets =
  281. uverbs_uattrs_process(ufile, uattrs, num_uattrs, method_spec,
  282. attr_bundle, &destroy_attr, uattr_ptr);
  283. if (num_given_buckets <= 0)
  284. return -EINVAL;
  285. attr_bundle->num_buckets = num_given_buckets;
  286. ret = uverbs_validate_kernel_mandatory(method_spec, attr_bundle);
  287. if (ret)
  288. goto cleanup;
  289. /*
  290. * We destroy the HW object before invoking the handler, handlers do
  291. * not get to manipulate the HW objects.
  292. */
  293. if (destroy_attr) {
  294. ret = uobj_destroy(destroy_attr->uobject);
  295. if (ret)
  296. goto cleanup;
  297. }
  298. ret = method_spec->handler(ufile, attr_bundle);
  299. if (destroy_attr) {
  300. uobj_put_destroy(destroy_attr->uobject);
  301. destroy_attr->uobject = NULL;
  302. }
  303. cleanup:
  304. finalize_ret = uverbs_finalize_attrs(attr_bundle,
  305. method_spec->attr_buckets,
  306. attr_bundle->num_buckets,
  307. !ret);
  308. return ret ? ret : finalize_ret;
  309. }
  310. #define UVERBS_OPTIMIZE_USING_STACK_SZ 256
  311. static long ib_uverbs_cmd_verbs(struct ib_device *ib_dev,
  312. struct ib_uverbs_file *file,
  313. struct ib_uverbs_ioctl_hdr *hdr,
  314. void __user *buf)
  315. {
  316. const struct uverbs_object_spec *object_spec;
  317. const struct uverbs_method_spec *method_spec;
  318. long err = 0;
  319. unsigned int i;
  320. struct {
  321. struct ib_uverbs_attr *uattrs;
  322. struct uverbs_attr_bundle *uverbs_attr_bundle;
  323. } *ctx = NULL;
  324. struct uverbs_attr *curr_attr;
  325. unsigned long *curr_bitmap;
  326. size_t ctx_size;
  327. uintptr_t data[UVERBS_OPTIMIZE_USING_STACK_SZ / sizeof(uintptr_t)];
  328. if (hdr->driver_id != ib_dev->driver_id)
  329. return -EINVAL;
  330. object_spec = uverbs_get_object(file, hdr->object_id);
  331. if (!object_spec)
  332. return -EPROTONOSUPPORT;
  333. method_spec = uverbs_get_method(object_spec, hdr->method_id);
  334. if (!method_spec)
  335. return -EPROTONOSUPPORT;
  336. ctx_size = sizeof(*ctx) +
  337. sizeof(struct uverbs_attr_bundle) +
  338. sizeof(struct uverbs_attr_bundle_hash) * method_spec->num_buckets +
  339. sizeof(*ctx->uattrs) * hdr->num_attrs +
  340. sizeof(*ctx->uverbs_attr_bundle->hash[0].attrs) *
  341. method_spec->num_child_attrs +
  342. sizeof(*ctx->uverbs_attr_bundle->hash[0].valid_bitmap) *
  343. (method_spec->num_child_attrs / BITS_PER_LONG +
  344. method_spec->num_buckets);
  345. if (ctx_size <= UVERBS_OPTIMIZE_USING_STACK_SZ)
  346. ctx = (void *)data;
  347. if (!ctx)
  348. ctx = kmalloc(ctx_size, GFP_KERNEL);
  349. if (!ctx)
  350. return -ENOMEM;
  351. ctx->uverbs_attr_bundle = (void *)ctx + sizeof(*ctx);
  352. ctx->uattrs = (void *)(ctx->uverbs_attr_bundle + 1) +
  353. (sizeof(ctx->uverbs_attr_bundle->hash[0]) *
  354. method_spec->num_buckets);
  355. curr_attr = (void *)(ctx->uattrs + hdr->num_attrs);
  356. curr_bitmap = (void *)(curr_attr + method_spec->num_child_attrs);
  357. /*
  358. * We just fill the pointers and num_attrs here. The data itself will be
  359. * filled at a later stage (uverbs_process_attr)
  360. */
  361. for (i = 0; i < method_spec->num_buckets; i++) {
  362. unsigned int curr_num_attrs;
  363. if (!method_spec->attr_buckets[i])
  364. continue;
  365. curr_num_attrs = method_spec->attr_buckets[i]->num_attrs;
  366. ctx->uverbs_attr_bundle->hash[i].attrs = curr_attr;
  367. curr_attr += curr_num_attrs;
  368. ctx->uverbs_attr_bundle->hash[i].num_attrs = curr_num_attrs;
  369. ctx->uverbs_attr_bundle->hash[i].valid_bitmap = curr_bitmap;
  370. bitmap_zero(curr_bitmap, curr_num_attrs);
  371. curr_bitmap += BITS_TO_LONGS(curr_num_attrs);
  372. }
  373. err = copy_from_user(ctx->uattrs, buf,
  374. sizeof(*ctx->uattrs) * hdr->num_attrs);
  375. if (err) {
  376. err = -EFAULT;
  377. goto out;
  378. }
  379. err = uverbs_handle_method(buf, ctx->uattrs, hdr->num_attrs, ib_dev,
  380. file, method_spec, ctx->uverbs_attr_bundle);
  381. /*
  382. * EPROTONOSUPPORT is ONLY to be returned if the ioctl framework can
  383. * not invoke the method because the request is not supported. No
  384. * other cases should return this code.
  385. */
  386. if (unlikely(err == -EPROTONOSUPPORT)) {
  387. WARN_ON_ONCE(err == -EPROTONOSUPPORT);
  388. err = -EINVAL;
  389. }
  390. out:
  391. if (ctx != (void *)data)
  392. kfree(ctx);
  393. return err;
  394. }
  395. #define IB_UVERBS_MAX_CMD_SZ 4096
  396. long ib_uverbs_ioctl(struct file *filp, unsigned int cmd, unsigned long arg)
  397. {
  398. struct ib_uverbs_file *file = filp->private_data;
  399. struct ib_uverbs_ioctl_hdr __user *user_hdr =
  400. (struct ib_uverbs_ioctl_hdr __user *)arg;
  401. struct ib_uverbs_ioctl_hdr hdr;
  402. struct ib_device *ib_dev;
  403. int srcu_key;
  404. long err;
  405. srcu_key = srcu_read_lock(&file->device->disassociate_srcu);
  406. ib_dev = srcu_dereference(file->device->ib_dev,
  407. &file->device->disassociate_srcu);
  408. if (!ib_dev) {
  409. err = -EIO;
  410. goto out;
  411. }
  412. if (cmd == RDMA_VERBS_IOCTL) {
  413. err = copy_from_user(&hdr, user_hdr, sizeof(hdr));
  414. if (err || hdr.length > IB_UVERBS_MAX_CMD_SZ ||
  415. hdr.length != sizeof(hdr) + hdr.num_attrs * sizeof(struct ib_uverbs_attr)) {
  416. err = -EINVAL;
  417. goto out;
  418. }
  419. if (hdr.reserved1 || hdr.reserved2) {
  420. err = -EPROTONOSUPPORT;
  421. goto out;
  422. }
  423. err = ib_uverbs_cmd_verbs(ib_dev, file, &hdr,
  424. (__user void *)arg + sizeof(hdr));
  425. } else {
  426. err = -ENOIOCTLCMD;
  427. }
  428. out:
  429. srcu_read_unlock(&file->device->disassociate_srcu, srcu_key);
  430. return err;
  431. }
  432. int uverbs_get_flags64(u64 *to, const struct uverbs_attr_bundle *attrs_bundle,
  433. size_t idx, u64 allowed_bits)
  434. {
  435. const struct uverbs_attr *attr;
  436. u64 flags;
  437. attr = uverbs_attr_get(attrs_bundle, idx);
  438. /* Missing attribute means 0 flags */
  439. if (IS_ERR(attr)) {
  440. *to = 0;
  441. return 0;
  442. }
  443. /*
  444. * New userspace code should use 8 bytes to pass flags, but we
  445. * transparently support old userspaces that were using 4 bytes as
  446. * well.
  447. */
  448. if (attr->ptr_attr.len == 8)
  449. flags = attr->ptr_attr.data;
  450. else if (attr->ptr_attr.len == 4)
  451. flags = *(u32 *)&attr->ptr_attr.data;
  452. else
  453. return -EINVAL;
  454. if (flags & ~allowed_bits)
  455. return -EINVAL;
  456. *to = flags;
  457. return 0;
  458. }
  459. EXPORT_SYMBOL(uverbs_get_flags64);
  460. int uverbs_get_flags32(u32 *to, const struct uverbs_attr_bundle *attrs_bundle,
  461. size_t idx, u64 allowed_bits)
  462. {
  463. u64 flags;
  464. int ret;
  465. ret = uverbs_get_flags64(&flags, attrs_bundle, idx, allowed_bits);
  466. if (ret)
  467. return ret;
  468. if (flags > U32_MAX)
  469. return -EINVAL;
  470. *to = flags;
  471. return 0;
  472. }
  473. EXPORT_SYMBOL(uverbs_get_flags32);