v4l2-compat-ioctl32.c 28 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394959697989910010110210310410510610710810911011111211311411511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614714814915015115215315415515615715815916016116216316416516616716816917017117217317417517617717817918018118218318418518618718818919019119219319419519619719819920020120220320420520620720820921021121221321421521621721821922022122222322422522622722822923023123223323423523623723823924024124224324424524624724824925025125225325425525625725825926026126226326426526626726826927027127227327427527627727827928028128228328428528628728828929029129229329429529629729829930030130230330430530630730830931031131231331431531631731831932032132232332432532632732832933033133233333433533633733833934034134234334434534634734834935035135235335435535635735835936036136236336436536636736836937037137237337437537637737837938038138238338438538638738838939039139239339439539639739839940040140240340440540640740840941041141241341441541641741841942042142242342442542642742842943043143243343443543643743843944044144244344444544644744844945045145245345445545645745845946046146246346446546646746846947047147247347447547647747847948048148248348448548648748848949049149249349449549649749849950050150250350450550650750850951051151251351451551651751851952052152252352452552652752852953053153253353453553653753853954054154254354454554654754854955055155255355455555655755855956056156256356456556656756856957057157257357457557657757857958058158258358458558658758858959059159259359459559659759859960060160260360460560660760860961061161261361461561661761861962062162262362462562662762862963063163263363463563663763863964064164264364464564664764864965065165265365465565665765865966066166266366466566666766866967067167267367467567667767867968068168268368468568668768868969069169269369469569669769869970070170270370470570670770870971071171271371471571671771871972072172272372472572672772872973073173273373473573673773873974074174274374474574674774874975075175275375475575675775875976076176276376476576676776876977077177277377477577677777877978078178278378478578678778878979079179279379479579679779879980080180280380480580680780880981081181281381481581681781881982082182282382482582682782882983083183283383483583683783883984084184284384484584684784884985085185285385485585685785885986086186286386486586686786886987087187287387487587687787887988088188288388488588688788888989089189289389489589689789889990090190290390490590690790890991091191291391491591691791891992092192292392492592692792892993093193293393493593693793893994094194294394494594694794894995095195295395495595695795895996096196296396496596696796896997097197297397497597697797897998098198298398498598698798898999099199299399499599699799899910001001100210031004100510061007100810091010101110121013101410151016101710181019
  1. /*
  2. * ioctl32.c: Conversion between 32bit and 64bit native ioctls.
  3. * Separated from fs stuff by Arnd Bergmann <arnd@arndb.de>
  4. *
  5. * Copyright (C) 1997-2000 Jakub Jelinek (jakub@redhat.com)
  6. * Copyright (C) 1998 Eddie C. Dost (ecd@skynet.be)
  7. * Copyright (C) 2001,2002 Andi Kleen, SuSE Labs
  8. * Copyright (C) 2003 Pavel Machek (pavel@ucw.cz)
  9. * Copyright (C) 2005 Philippe De Muyter (phdm@macqel.be)
  10. * Copyright (C) 2008 Hans Verkuil <hverkuil@xs4all.nl>
  11. *
  12. * These routines maintain argument size conversion between 32bit and 64bit
  13. * ioctls.
  14. */
  15. #include <linux/compat.h>
  16. #include <linux/module.h>
  17. #include <linux/videodev2.h>
  18. #include <linux/v4l2-subdev.h>
  19. #include <media/v4l2-dev.h>
  20. #include <media/v4l2-ioctl.h>
  21. static long native_ioctl(struct file *file, unsigned int cmd, unsigned long arg)
  22. {
  23. long ret = -ENOIOCTLCMD;
  24. if (file->f_op->unlocked_ioctl)
  25. ret = file->f_op->unlocked_ioctl(file, cmd, arg);
  26. return ret;
  27. }
  28. struct v4l2_clip32 {
  29. struct v4l2_rect c;
  30. compat_caddr_t next;
  31. };
  32. struct v4l2_window32 {
  33. struct v4l2_rect w;
  34. __u32 field; /* enum v4l2_field */
  35. __u32 chromakey;
  36. compat_caddr_t clips; /* actually struct v4l2_clip32 * */
  37. __u32 clipcount;
  38. compat_caddr_t bitmap;
  39. __u8 global_alpha;
  40. };
  41. static int get_v4l2_window32(struct v4l2_window *kp, struct v4l2_window32 __user *up)
  42. {
  43. if (!access_ok(VERIFY_READ, up, sizeof(*up)) ||
  44. copy_from_user(&kp->w, &up->w, sizeof(up->w)) ||
  45. get_user(kp->field, &up->field) ||
  46. get_user(kp->chromakey, &up->chromakey) ||
  47. get_user(kp->clipcount, &up->clipcount) ||
  48. get_user(kp->global_alpha, &up->global_alpha))
  49. return -EFAULT;
  50. if (kp->clipcount > 2048)
  51. return -EINVAL;
  52. if (kp->clipcount) {
  53. struct v4l2_clip32 __user *uclips;
  54. struct v4l2_clip __user *kclips;
  55. int n = kp->clipcount;
  56. compat_caddr_t p;
  57. if (get_user(p, &up->clips))
  58. return -EFAULT;
  59. uclips = compat_ptr(p);
  60. kclips = compat_alloc_user_space(n * sizeof(*kclips));
  61. kp->clips = kclips;
  62. while (--n >= 0) {
  63. if (copy_in_user(&kclips->c, &uclips->c, sizeof(uclips->c)))
  64. return -EFAULT;
  65. if (put_user(n ? kclips + 1 : NULL, &kclips->next))
  66. return -EFAULT;
  67. uclips += 1;
  68. kclips += 1;
  69. }
  70. } else
  71. kp->clips = NULL;
  72. return 0;
  73. }
  74. static int put_v4l2_window32(struct v4l2_window *kp, struct v4l2_window32 __user *up)
  75. {
  76. if (copy_to_user(&up->w, &kp->w, sizeof(kp->w)) ||
  77. put_user(kp->field, &up->field) ||
  78. put_user(kp->chromakey, &up->chromakey) ||
  79. put_user(kp->clipcount, &up->clipcount) ||
  80. put_user(kp->global_alpha, &up->global_alpha))
  81. return -EFAULT;
  82. return 0;
  83. }
  84. struct v4l2_format32 {
  85. __u32 type; /* enum v4l2_buf_type */
  86. union {
  87. struct v4l2_pix_format pix;
  88. struct v4l2_pix_format_mplane pix_mp;
  89. struct v4l2_window32 win;
  90. struct v4l2_vbi_format vbi;
  91. struct v4l2_sliced_vbi_format sliced;
  92. struct v4l2_sdr_format sdr;
  93. struct v4l2_meta_format meta;
  94. __u8 raw_data[200]; /* user-defined */
  95. } fmt;
  96. };
  97. /**
  98. * struct v4l2_create_buffers32 - VIDIOC_CREATE_BUFS32 argument
  99. * @index: on return, index of the first created buffer
  100. * @count: entry: number of requested buffers,
  101. * return: number of created buffers
  102. * @memory: buffer memory type
  103. * @format: frame format, for which buffers are requested
  104. * @reserved: future extensions
  105. */
  106. struct v4l2_create_buffers32 {
  107. __u32 index;
  108. __u32 count;
  109. __u32 memory; /* enum v4l2_memory */
  110. struct v4l2_format32 format;
  111. __u32 reserved[8];
  112. };
  113. static int __get_v4l2_format32(struct v4l2_format *kp, struct v4l2_format32 __user *up)
  114. {
  115. if (get_user(kp->type, &up->type))
  116. return -EFAULT;
  117. switch (kp->type) {
  118. case V4L2_BUF_TYPE_VIDEO_CAPTURE:
  119. case V4L2_BUF_TYPE_VIDEO_OUTPUT:
  120. return copy_from_user(&kp->fmt.pix, &up->fmt.pix,
  121. sizeof(kp->fmt.pix)) ? -EFAULT : 0;
  122. case V4L2_BUF_TYPE_VIDEO_CAPTURE_MPLANE:
  123. case V4L2_BUF_TYPE_VIDEO_OUTPUT_MPLANE:
  124. return copy_from_user(&kp->fmt.pix_mp, &up->fmt.pix_mp,
  125. sizeof(kp->fmt.pix_mp)) ? -EFAULT : 0;
  126. case V4L2_BUF_TYPE_VIDEO_OVERLAY:
  127. case V4L2_BUF_TYPE_VIDEO_OUTPUT_OVERLAY:
  128. return get_v4l2_window32(&kp->fmt.win, &up->fmt.win);
  129. case V4L2_BUF_TYPE_VBI_CAPTURE:
  130. case V4L2_BUF_TYPE_VBI_OUTPUT:
  131. return copy_from_user(&kp->fmt.vbi, &up->fmt.vbi,
  132. sizeof(kp->fmt.vbi)) ? -EFAULT : 0;
  133. case V4L2_BUF_TYPE_SLICED_VBI_CAPTURE:
  134. case V4L2_BUF_TYPE_SLICED_VBI_OUTPUT:
  135. return copy_from_user(&kp->fmt.sliced, &up->fmt.sliced,
  136. sizeof(kp->fmt.sliced)) ? -EFAULT : 0;
  137. case V4L2_BUF_TYPE_SDR_CAPTURE:
  138. case V4L2_BUF_TYPE_SDR_OUTPUT:
  139. return copy_from_user(&kp->fmt.sdr, &up->fmt.sdr,
  140. sizeof(kp->fmt.sdr)) ? -EFAULT : 0;
  141. case V4L2_BUF_TYPE_META_CAPTURE:
  142. return copy_from_user(&kp->fmt.meta, &up->fmt.meta,
  143. sizeof(kp->fmt.meta)) ? -EFAULT : 0;
  144. default:
  145. pr_info("compat_ioctl32: unexpected VIDIOC_FMT type %d\n",
  146. kp->type);
  147. return -EINVAL;
  148. }
  149. }
  150. static int get_v4l2_format32(struct v4l2_format *kp, struct v4l2_format32 __user *up)
  151. {
  152. if (!access_ok(VERIFY_READ, up, sizeof(*up)))
  153. return -EFAULT;
  154. return __get_v4l2_format32(kp, up);
  155. }
  156. static int get_v4l2_create32(struct v4l2_create_buffers *kp, struct v4l2_create_buffers32 __user *up)
  157. {
  158. if (!access_ok(VERIFY_READ, up, sizeof(*up)) ||
  159. copy_from_user(kp, up, offsetof(struct v4l2_create_buffers32, format)))
  160. return -EFAULT;
  161. return __get_v4l2_format32(&kp->format, &up->format);
  162. }
  163. static int __put_v4l2_format32(struct v4l2_format *kp, struct v4l2_format32 __user *up)
  164. {
  165. if (put_user(kp->type, &up->type))
  166. return -EFAULT;
  167. switch (kp->type) {
  168. case V4L2_BUF_TYPE_VIDEO_CAPTURE:
  169. case V4L2_BUF_TYPE_VIDEO_OUTPUT:
  170. return copy_to_user(&up->fmt.pix, &kp->fmt.pix,
  171. sizeof(kp->fmt.pix)) ? -EFAULT : 0;
  172. case V4L2_BUF_TYPE_VIDEO_CAPTURE_MPLANE:
  173. case V4L2_BUF_TYPE_VIDEO_OUTPUT_MPLANE:
  174. return copy_to_user(&up->fmt.pix_mp, &kp->fmt.pix_mp,
  175. sizeof(kp->fmt.pix_mp)) ? -EFAULT : 0;
  176. case V4L2_BUF_TYPE_VIDEO_OVERLAY:
  177. case V4L2_BUF_TYPE_VIDEO_OUTPUT_OVERLAY:
  178. return put_v4l2_window32(&kp->fmt.win, &up->fmt.win);
  179. case V4L2_BUF_TYPE_VBI_CAPTURE:
  180. case V4L2_BUF_TYPE_VBI_OUTPUT:
  181. return copy_to_user(&up->fmt.vbi, &kp->fmt.vbi,
  182. sizeof(kp->fmt.vbi)) ? -EFAULT : 0;
  183. case V4L2_BUF_TYPE_SLICED_VBI_CAPTURE:
  184. case V4L2_BUF_TYPE_SLICED_VBI_OUTPUT:
  185. return copy_to_user(&up->fmt.sliced, &kp->fmt.sliced,
  186. sizeof(kp->fmt.sliced)) ? -EFAULT : 0;
  187. case V4L2_BUF_TYPE_SDR_CAPTURE:
  188. case V4L2_BUF_TYPE_SDR_OUTPUT:
  189. return copy_to_user(&up->fmt.sdr, &kp->fmt.sdr,
  190. sizeof(kp->fmt.sdr)) ? -EFAULT : 0;
  191. case V4L2_BUF_TYPE_META_CAPTURE:
  192. return copy_to_user(&up->fmt.meta, &kp->fmt.meta,
  193. sizeof(kp->fmt.meta)) ? -EFAULT : 0;
  194. default:
  195. pr_info("compat_ioctl32: unexpected VIDIOC_FMT type %d\n",
  196. kp->type);
  197. return -EINVAL;
  198. }
  199. }
  200. static int put_v4l2_format32(struct v4l2_format *kp, struct v4l2_format32 __user *up)
  201. {
  202. if (!access_ok(VERIFY_WRITE, up, sizeof(*up)))
  203. return -EFAULT;
  204. return __put_v4l2_format32(kp, up);
  205. }
  206. static int put_v4l2_create32(struct v4l2_create_buffers *kp, struct v4l2_create_buffers32 __user *up)
  207. {
  208. if (!access_ok(VERIFY_WRITE, up, sizeof(*up)) ||
  209. copy_to_user(up, kp, offsetof(struct v4l2_create_buffers32, format)) ||
  210. copy_to_user(up->reserved, kp->reserved, sizeof(kp->reserved)))
  211. return -EFAULT;
  212. return __put_v4l2_format32(&kp->format, &up->format);
  213. }
  214. struct v4l2_standard32 {
  215. __u32 index;
  216. compat_u64 id;
  217. __u8 name[24];
  218. struct v4l2_fract frameperiod; /* Frames, not fields */
  219. __u32 framelines;
  220. __u32 reserved[4];
  221. };
  222. static int get_v4l2_standard32(struct v4l2_standard *kp, struct v4l2_standard32 __user *up)
  223. {
  224. /* other fields are not set by the user, nor used by the driver */
  225. if (!access_ok(VERIFY_READ, up, sizeof(*up)) ||
  226. get_user(kp->index, &up->index))
  227. return -EFAULT;
  228. return 0;
  229. }
  230. static int put_v4l2_standard32(struct v4l2_standard *kp, struct v4l2_standard32 __user *up)
  231. {
  232. if (!access_ok(VERIFY_WRITE, up, sizeof(*up)) ||
  233. put_user(kp->index, &up->index) ||
  234. put_user(kp->id, &up->id) ||
  235. copy_to_user(up->name, kp->name, sizeof(up->name)) ||
  236. copy_to_user(&up->frameperiod, &kp->frameperiod,
  237. sizeof(kp->frameperiod)) ||
  238. put_user(kp->framelines, &up->framelines) ||
  239. copy_to_user(up->reserved, kp->reserved, sizeof(kp->reserved)))
  240. return -EFAULT;
  241. return 0;
  242. }
  243. struct v4l2_plane32 {
  244. __u32 bytesused;
  245. __u32 length;
  246. union {
  247. __u32 mem_offset;
  248. compat_long_t userptr;
  249. __s32 fd;
  250. } m;
  251. __u32 data_offset;
  252. __u32 reserved[11];
  253. };
  254. struct v4l2_buffer32 {
  255. __u32 index;
  256. __u32 type; /* enum v4l2_buf_type */
  257. __u32 bytesused;
  258. __u32 flags;
  259. __u32 field; /* enum v4l2_field */
  260. struct compat_timeval timestamp;
  261. struct v4l2_timecode timecode;
  262. __u32 sequence;
  263. /* memory location */
  264. __u32 memory; /* enum v4l2_memory */
  265. union {
  266. __u32 offset;
  267. compat_long_t userptr;
  268. compat_caddr_t planes;
  269. __s32 fd;
  270. } m;
  271. __u32 length;
  272. __u32 reserved2;
  273. __u32 reserved;
  274. };
  275. static int get_v4l2_plane32(struct v4l2_plane __user *up, struct v4l2_plane32 __user *up32,
  276. enum v4l2_memory memory)
  277. {
  278. void __user *up_pln;
  279. compat_long_t p;
  280. if (copy_in_user(up, up32, 2 * sizeof(__u32)) ||
  281. copy_in_user(&up->data_offset, &up32->data_offset,
  282. sizeof(up->data_offset)))
  283. return -EFAULT;
  284. switch (memory) {
  285. case V4L2_MEMORY_MMAP:
  286. case V4L2_MEMORY_OVERLAY:
  287. if (copy_in_user(&up->m.mem_offset, &up32->m.mem_offset,
  288. sizeof(up32->m.mem_offset)))
  289. return -EFAULT;
  290. break;
  291. case V4L2_MEMORY_USERPTR:
  292. if (get_user(p, &up32->m.userptr))
  293. return -EFAULT;
  294. up_pln = compat_ptr(p);
  295. if (put_user((unsigned long)up_pln, &up->m.userptr))
  296. return -EFAULT;
  297. break;
  298. case V4L2_MEMORY_DMABUF:
  299. if (copy_in_user(&up->m.fd, &up32->m.fd, sizeof(up32->m.fd)))
  300. return -EFAULT;
  301. break;
  302. }
  303. return 0;
  304. }
  305. static int put_v4l2_plane32(struct v4l2_plane __user *up, struct v4l2_plane32 __user *up32,
  306. enum v4l2_memory memory)
  307. {
  308. unsigned long p;
  309. if (copy_in_user(up32, up, 2 * sizeof(__u32)) ||
  310. copy_in_user(&up32->data_offset, &up->data_offset,
  311. sizeof(up->data_offset)))
  312. return -EFAULT;
  313. switch (memory) {
  314. case V4L2_MEMORY_MMAP:
  315. case V4L2_MEMORY_OVERLAY:
  316. if (copy_in_user(&up32->m.mem_offset, &up->m.mem_offset,
  317. sizeof(up->m.mem_offset)))
  318. return -EFAULT;
  319. break;
  320. case V4L2_MEMORY_USERPTR:
  321. if (get_user(p, &up->m.userptr) ||
  322. put_user((compat_ulong_t)ptr_to_compat((__force void *)p),
  323. &up32->m.userptr))
  324. return -EFAULT;
  325. break;
  326. case V4L2_MEMORY_DMABUF:
  327. if (copy_in_user(&up32->m.fd, &up->m.fd,
  328. sizeof(up->m.fd)))
  329. return -EFAULT;
  330. break;
  331. }
  332. return 0;
  333. }
  334. static int get_v4l2_buffer32(struct v4l2_buffer *kp, struct v4l2_buffer32 __user *up)
  335. {
  336. struct v4l2_plane32 __user *uplane32;
  337. struct v4l2_plane __user *uplane;
  338. compat_caddr_t p;
  339. int ret;
  340. if (!access_ok(VERIFY_READ, up, sizeof(*up)) ||
  341. get_user(kp->index, &up->index) ||
  342. get_user(kp->type, &up->type) ||
  343. get_user(kp->flags, &up->flags) ||
  344. get_user(kp->memory, &up->memory) ||
  345. get_user(kp->length, &up->length))
  346. return -EFAULT;
  347. if (V4L2_TYPE_IS_OUTPUT(kp->type))
  348. if (get_user(kp->bytesused, &up->bytesused) ||
  349. get_user(kp->field, &up->field) ||
  350. get_user(kp->timestamp.tv_sec, &up->timestamp.tv_sec) ||
  351. get_user(kp->timestamp.tv_usec, &up->timestamp.tv_usec))
  352. return -EFAULT;
  353. if (V4L2_TYPE_IS_MULTIPLANAR(kp->type)) {
  354. unsigned int num_planes;
  355. if (kp->length == 0) {
  356. kp->m.planes = NULL;
  357. /* num_planes == 0 is legal, e.g. when userspace doesn't
  358. * need planes array on DQBUF*/
  359. return 0;
  360. } else if (kp->length > VIDEO_MAX_PLANES) {
  361. return -EINVAL;
  362. }
  363. if (get_user(p, &up->m.planes))
  364. return -EFAULT;
  365. uplane32 = compat_ptr(p);
  366. if (!access_ok(VERIFY_READ, uplane32,
  367. kp->length * sizeof(*uplane32)))
  368. return -EFAULT;
  369. /* We don't really care if userspace decides to kill itself
  370. * by passing a very big num_planes value */
  371. uplane = compat_alloc_user_space(kp->length * sizeof(*uplane));
  372. kp->m.planes = (__force struct v4l2_plane *)uplane;
  373. for (num_planes = 0; num_planes < kp->length; num_planes++) {
  374. ret = get_v4l2_plane32(uplane, uplane32, kp->memory);
  375. if (ret)
  376. return ret;
  377. ++uplane;
  378. ++uplane32;
  379. }
  380. } else {
  381. switch (kp->memory) {
  382. case V4L2_MEMORY_MMAP:
  383. case V4L2_MEMORY_OVERLAY:
  384. if (get_user(kp->m.offset, &up->m.offset))
  385. return -EFAULT;
  386. break;
  387. case V4L2_MEMORY_USERPTR:
  388. {
  389. compat_long_t tmp;
  390. if (get_user(tmp, &up->m.userptr))
  391. return -EFAULT;
  392. kp->m.userptr = (unsigned long)compat_ptr(tmp);
  393. }
  394. break;
  395. case V4L2_MEMORY_DMABUF:
  396. if (get_user(kp->m.fd, &up->m.fd))
  397. return -EFAULT;
  398. break;
  399. }
  400. }
  401. return 0;
  402. }
  403. static int put_v4l2_buffer32(struct v4l2_buffer *kp, struct v4l2_buffer32 __user *up)
  404. {
  405. struct v4l2_plane32 __user *uplane32;
  406. struct v4l2_plane __user *uplane;
  407. compat_caddr_t p;
  408. int num_planes;
  409. int ret;
  410. if (!access_ok(VERIFY_WRITE, up, sizeof(*up)) ||
  411. put_user(kp->index, &up->index) ||
  412. put_user(kp->type, &up->type) ||
  413. put_user(kp->flags, &up->flags) ||
  414. put_user(kp->memory, &up->memory))
  415. return -EFAULT;
  416. if (put_user(kp->bytesused, &up->bytesused) ||
  417. put_user(kp->field, &up->field) ||
  418. put_user(kp->timestamp.tv_sec, &up->timestamp.tv_sec) ||
  419. put_user(kp->timestamp.tv_usec, &up->timestamp.tv_usec) ||
  420. copy_to_user(&up->timecode, &kp->timecode, sizeof(kp->timecode)) ||
  421. put_user(kp->sequence, &up->sequence) ||
  422. put_user(kp->reserved2, &up->reserved2) ||
  423. put_user(kp->reserved, &up->reserved) ||
  424. put_user(kp->length, &up->length))
  425. return -EFAULT;
  426. if (V4L2_TYPE_IS_MULTIPLANAR(kp->type)) {
  427. num_planes = kp->length;
  428. if (num_planes == 0)
  429. return 0;
  430. uplane = (__force struct v4l2_plane __user *)kp->m.planes;
  431. if (get_user(p, &up->m.planes))
  432. return -EFAULT;
  433. uplane32 = compat_ptr(p);
  434. while (--num_planes >= 0) {
  435. ret = put_v4l2_plane32(uplane, uplane32, kp->memory);
  436. if (ret)
  437. return ret;
  438. ++uplane;
  439. ++uplane32;
  440. }
  441. } else {
  442. switch (kp->memory) {
  443. case V4L2_MEMORY_MMAP:
  444. case V4L2_MEMORY_OVERLAY:
  445. if (put_user(kp->m.offset, &up->m.offset))
  446. return -EFAULT;
  447. break;
  448. case V4L2_MEMORY_USERPTR:
  449. if (put_user(kp->m.userptr, &up->m.userptr))
  450. return -EFAULT;
  451. break;
  452. case V4L2_MEMORY_DMABUF:
  453. if (put_user(kp->m.fd, &up->m.fd))
  454. return -EFAULT;
  455. break;
  456. }
  457. }
  458. return 0;
  459. }
  460. struct v4l2_framebuffer32 {
  461. __u32 capability;
  462. __u32 flags;
  463. compat_caddr_t base;
  464. struct {
  465. __u32 width;
  466. __u32 height;
  467. __u32 pixelformat;
  468. __u32 field;
  469. __u32 bytesperline;
  470. __u32 sizeimage;
  471. __u32 colorspace;
  472. __u32 priv;
  473. } fmt;
  474. };
  475. static int get_v4l2_framebuffer32(struct v4l2_framebuffer *kp, struct v4l2_framebuffer32 __user *up)
  476. {
  477. u32 tmp;
  478. if (!access_ok(VERIFY_READ, up, sizeof(*up)) ||
  479. get_user(tmp, &up->base) ||
  480. get_user(kp->capability, &up->capability) ||
  481. get_user(kp->flags, &up->flags) ||
  482. copy_from_user(&kp->fmt, &up->fmt, sizeof(up->fmt)))
  483. return -EFAULT;
  484. kp->base = (__force void *)compat_ptr(tmp);
  485. return 0;
  486. }
  487. static int put_v4l2_framebuffer32(struct v4l2_framebuffer *kp, struct v4l2_framebuffer32 __user *up)
  488. {
  489. u32 tmp = (u32)((unsigned long)kp->base);
  490. if (!access_ok(VERIFY_WRITE, up, sizeof(*up)) ||
  491. put_user(tmp, &up->base) ||
  492. put_user(kp->capability, &up->capability) ||
  493. put_user(kp->flags, &up->flags) ||
  494. copy_to_user(&up->fmt, &kp->fmt, sizeof(up->fmt)))
  495. return -EFAULT;
  496. return 0;
  497. }
  498. struct v4l2_input32 {
  499. __u32 index; /* Which input */
  500. __u8 name[32]; /* Label */
  501. __u32 type; /* Type of input */
  502. __u32 audioset; /* Associated audios (bitfield) */
  503. __u32 tuner; /* Associated tuner */
  504. compat_u64 std;
  505. __u32 status;
  506. __u32 capabilities;
  507. __u32 reserved[3];
  508. };
  509. /* The 64-bit v4l2_input struct has extra padding at the end of the struct.
  510. Otherwise it is identical to the 32-bit version. */
  511. static inline int get_v4l2_input32(struct v4l2_input *kp, struct v4l2_input32 __user *up)
  512. {
  513. if (copy_from_user(kp, up, sizeof(*up)))
  514. return -EFAULT;
  515. return 0;
  516. }
  517. static inline int put_v4l2_input32(struct v4l2_input *kp, struct v4l2_input32 __user *up)
  518. {
  519. if (copy_to_user(up, kp, sizeof(*up)))
  520. return -EFAULT;
  521. return 0;
  522. }
  523. struct v4l2_ext_controls32 {
  524. __u32 which;
  525. __u32 count;
  526. __u32 error_idx;
  527. __u32 reserved[2];
  528. compat_caddr_t controls; /* actually struct v4l2_ext_control32 * */
  529. };
  530. struct v4l2_ext_control32 {
  531. __u32 id;
  532. __u32 size;
  533. __u32 reserved2[1];
  534. union {
  535. __s32 value;
  536. __s64 value64;
  537. compat_caddr_t string; /* actually char * */
  538. };
  539. } __attribute__ ((packed));
  540. /* The following function really belong in v4l2-common, but that causes
  541. a circular dependency between modules. We need to think about this, but
  542. for now this will do. */
  543. /* Return non-zero if this control is a pointer type. Currently only
  544. type STRING is a pointer type. */
  545. static inline int ctrl_is_pointer(u32 id)
  546. {
  547. switch (id) {
  548. case V4L2_CID_RDS_TX_PS_NAME:
  549. case V4L2_CID_RDS_TX_RADIO_TEXT:
  550. return 1;
  551. default:
  552. return 0;
  553. }
  554. }
  555. static int get_v4l2_ext_controls32(struct v4l2_ext_controls *kp, struct v4l2_ext_controls32 __user *up)
  556. {
  557. struct v4l2_ext_control32 __user *ucontrols;
  558. struct v4l2_ext_control __user *kcontrols;
  559. unsigned int n;
  560. compat_caddr_t p;
  561. if (!access_ok(VERIFY_READ, up, sizeof(*up)) ||
  562. get_user(kp->which, &up->which) ||
  563. get_user(kp->count, &up->count) ||
  564. get_user(kp->error_idx, &up->error_idx) ||
  565. copy_from_user(kp->reserved, up->reserved, sizeof(kp->reserved)))
  566. return -EFAULT;
  567. if (kp->count == 0) {
  568. kp->controls = NULL;
  569. return 0;
  570. } else if (kp->count > V4L2_CID_MAX_CTRLS) {
  571. return -EINVAL;
  572. }
  573. if (get_user(p, &up->controls))
  574. return -EFAULT;
  575. ucontrols = compat_ptr(p);
  576. if (!access_ok(VERIFY_READ, ucontrols, kp->count * sizeof(*ucontrols)))
  577. return -EFAULT;
  578. kcontrols = compat_alloc_user_space(kp->count * sizeof(*kcontrols));
  579. kp->controls = (__force struct v4l2_ext_control *)kcontrols;
  580. for (n = 0; n < kp->count; n++) {
  581. u32 id;
  582. if (copy_in_user(kcontrols, ucontrols, sizeof(*ucontrols)))
  583. return -EFAULT;
  584. if (get_user(id, &kcontrols->id))
  585. return -EFAULT;
  586. if (ctrl_is_pointer(id)) {
  587. void __user *s;
  588. if (get_user(p, &ucontrols->string))
  589. return -EFAULT;
  590. s = compat_ptr(p);
  591. if (put_user(s, &kcontrols->string))
  592. return -EFAULT;
  593. }
  594. ucontrols++;
  595. kcontrols++;
  596. }
  597. return 0;
  598. }
  599. static int put_v4l2_ext_controls32(struct v4l2_ext_controls *kp, struct v4l2_ext_controls32 __user *up)
  600. {
  601. struct v4l2_ext_control32 __user *ucontrols;
  602. struct v4l2_ext_control __user *kcontrols =
  603. (__force struct v4l2_ext_control __user *)kp->controls;
  604. int n = kp->count;
  605. compat_caddr_t p;
  606. if (!access_ok(VERIFY_WRITE, up, sizeof(*up)) ||
  607. put_user(kp->which, &up->which) ||
  608. put_user(kp->count, &up->count) ||
  609. put_user(kp->error_idx, &up->error_idx) ||
  610. copy_to_user(up->reserved, kp->reserved, sizeof(up->reserved)))
  611. return -EFAULT;
  612. if (!kp->count)
  613. return 0;
  614. if (get_user(p, &up->controls))
  615. return -EFAULT;
  616. ucontrols = compat_ptr(p);
  617. if (!access_ok(VERIFY_WRITE, ucontrols, n * sizeof(*ucontrols)))
  618. return -EFAULT;
  619. while (--n >= 0) {
  620. unsigned size = sizeof(*ucontrols);
  621. u32 id;
  622. if (get_user(id, &kcontrols->id))
  623. return -EFAULT;
  624. /* Do not modify the pointer when copying a pointer control.
  625. The contents of the pointer was changed, not the pointer
  626. itself. */
  627. if (ctrl_is_pointer(id))
  628. size -= sizeof(ucontrols->value64);
  629. if (copy_in_user(ucontrols, kcontrols, size))
  630. return -EFAULT;
  631. ucontrols++;
  632. kcontrols++;
  633. }
  634. return 0;
  635. }
  636. struct v4l2_event32 {
  637. __u32 type;
  638. union {
  639. compat_s64 value64;
  640. __u8 data[64];
  641. } u;
  642. __u32 pending;
  643. __u32 sequence;
  644. struct compat_timespec timestamp;
  645. __u32 id;
  646. __u32 reserved[8];
  647. };
  648. static int put_v4l2_event32(struct v4l2_event *kp, struct v4l2_event32 __user *up)
  649. {
  650. if (!access_ok(VERIFY_WRITE, up, sizeof(*up)) ||
  651. put_user(kp->type, &up->type) ||
  652. copy_to_user(&up->u, &kp->u, sizeof(kp->u)) ||
  653. put_user(kp->pending, &up->pending) ||
  654. put_user(kp->sequence, &up->sequence) ||
  655. put_user(kp->timestamp.tv_sec, &up->timestamp.tv_sec) ||
  656. put_user(kp->timestamp.tv_nsec, &up->timestamp.tv_nsec) ||
  657. put_user(kp->id, &up->id) ||
  658. copy_to_user(up->reserved, kp->reserved, sizeof(kp->reserved)))
  659. return -EFAULT;
  660. return 0;
  661. }
  662. struct v4l2_edid32 {
  663. __u32 pad;
  664. __u32 start_block;
  665. __u32 blocks;
  666. __u32 reserved[5];
  667. compat_caddr_t edid;
  668. };
  669. static int get_v4l2_edid32(struct v4l2_edid *kp, struct v4l2_edid32 __user *up)
  670. {
  671. u32 tmp;
  672. if (!access_ok(VERIFY_READ, up, sizeof(*up)) ||
  673. get_user(kp->pad, &up->pad) ||
  674. get_user(kp->start_block, &up->start_block) ||
  675. get_user(kp->blocks, &up->blocks) ||
  676. get_user(tmp, &up->edid) ||
  677. copy_from_user(kp->reserved, up->reserved, sizeof(kp->reserved)))
  678. return -EFAULT;
  679. kp->edid = (__force u8 *)compat_ptr(tmp);
  680. return 0;
  681. }
  682. static int put_v4l2_edid32(struct v4l2_edid *kp, struct v4l2_edid32 __user *up)
  683. {
  684. u32 tmp = (u32)((unsigned long)kp->edid);
  685. if (!access_ok(VERIFY_WRITE, up, sizeof(*up)) ||
  686. put_user(kp->pad, &up->pad) ||
  687. put_user(kp->start_block, &up->start_block) ||
  688. put_user(kp->blocks, &up->blocks) ||
  689. put_user(tmp, &up->edid) ||
  690. copy_to_user(up->reserved, kp->reserved, sizeof(up->reserved)))
  691. return -EFAULT;
  692. return 0;
  693. }
  694. #define VIDIOC_G_FMT32 _IOWR('V', 4, struct v4l2_format32)
  695. #define VIDIOC_S_FMT32 _IOWR('V', 5, struct v4l2_format32)
  696. #define VIDIOC_QUERYBUF32 _IOWR('V', 9, struct v4l2_buffer32)
  697. #define VIDIOC_G_FBUF32 _IOR ('V', 10, struct v4l2_framebuffer32)
  698. #define VIDIOC_S_FBUF32 _IOW ('V', 11, struct v4l2_framebuffer32)
  699. #define VIDIOC_QBUF32 _IOWR('V', 15, struct v4l2_buffer32)
  700. #define VIDIOC_DQBUF32 _IOWR('V', 17, struct v4l2_buffer32)
  701. #define VIDIOC_ENUMSTD32 _IOWR('V', 25, struct v4l2_standard32)
  702. #define VIDIOC_ENUMINPUT32 _IOWR('V', 26, struct v4l2_input32)
  703. #define VIDIOC_G_EDID32 _IOWR('V', 40, struct v4l2_edid32)
  704. #define VIDIOC_S_EDID32 _IOWR('V', 41, struct v4l2_edid32)
  705. #define VIDIOC_TRY_FMT32 _IOWR('V', 64, struct v4l2_format32)
  706. #define VIDIOC_G_EXT_CTRLS32 _IOWR('V', 71, struct v4l2_ext_controls32)
  707. #define VIDIOC_S_EXT_CTRLS32 _IOWR('V', 72, struct v4l2_ext_controls32)
  708. #define VIDIOC_TRY_EXT_CTRLS32 _IOWR('V', 73, struct v4l2_ext_controls32)
  709. #define VIDIOC_DQEVENT32 _IOR ('V', 89, struct v4l2_event32)
  710. #define VIDIOC_CREATE_BUFS32 _IOWR('V', 92, struct v4l2_create_buffers32)
  711. #define VIDIOC_PREPARE_BUF32 _IOWR('V', 93, struct v4l2_buffer32)
  712. #define VIDIOC_OVERLAY32 _IOW ('V', 14, s32)
  713. #define VIDIOC_STREAMON32 _IOW ('V', 18, s32)
  714. #define VIDIOC_STREAMOFF32 _IOW ('V', 19, s32)
  715. #define VIDIOC_G_INPUT32 _IOR ('V', 38, s32)
  716. #define VIDIOC_S_INPUT32 _IOWR('V', 39, s32)
  717. #define VIDIOC_G_OUTPUT32 _IOR ('V', 46, s32)
  718. #define VIDIOC_S_OUTPUT32 _IOWR('V', 47, s32)
  719. static long do_video_ioctl(struct file *file, unsigned int cmd, unsigned long arg)
  720. {
  721. union {
  722. struct v4l2_format v2f;
  723. struct v4l2_buffer v2b;
  724. struct v4l2_framebuffer v2fb;
  725. struct v4l2_input v2i;
  726. struct v4l2_standard v2s;
  727. struct v4l2_ext_controls v2ecs;
  728. struct v4l2_event v2ev;
  729. struct v4l2_create_buffers v2crt;
  730. struct v4l2_edid v2edid;
  731. unsigned long vx;
  732. int vi;
  733. } karg;
  734. void __user *up = compat_ptr(arg);
  735. int compatible_arg = 1;
  736. long err = 0;
  737. /* First, convert the command. */
  738. switch (cmd) {
  739. case VIDIOC_G_FMT32: cmd = VIDIOC_G_FMT; break;
  740. case VIDIOC_S_FMT32: cmd = VIDIOC_S_FMT; break;
  741. case VIDIOC_QUERYBUF32: cmd = VIDIOC_QUERYBUF; break;
  742. case VIDIOC_G_FBUF32: cmd = VIDIOC_G_FBUF; break;
  743. case VIDIOC_S_FBUF32: cmd = VIDIOC_S_FBUF; break;
  744. case VIDIOC_QBUF32: cmd = VIDIOC_QBUF; break;
  745. case VIDIOC_DQBUF32: cmd = VIDIOC_DQBUF; break;
  746. case VIDIOC_ENUMSTD32: cmd = VIDIOC_ENUMSTD; break;
  747. case VIDIOC_ENUMINPUT32: cmd = VIDIOC_ENUMINPUT; break;
  748. case VIDIOC_TRY_FMT32: cmd = VIDIOC_TRY_FMT; break;
  749. case VIDIOC_G_EXT_CTRLS32: cmd = VIDIOC_G_EXT_CTRLS; break;
  750. case VIDIOC_S_EXT_CTRLS32: cmd = VIDIOC_S_EXT_CTRLS; break;
  751. case VIDIOC_TRY_EXT_CTRLS32: cmd = VIDIOC_TRY_EXT_CTRLS; break;
  752. case VIDIOC_DQEVENT32: cmd = VIDIOC_DQEVENT; break;
  753. case VIDIOC_OVERLAY32: cmd = VIDIOC_OVERLAY; break;
  754. case VIDIOC_STREAMON32: cmd = VIDIOC_STREAMON; break;
  755. case VIDIOC_STREAMOFF32: cmd = VIDIOC_STREAMOFF; break;
  756. case VIDIOC_G_INPUT32: cmd = VIDIOC_G_INPUT; break;
  757. case VIDIOC_S_INPUT32: cmd = VIDIOC_S_INPUT; break;
  758. case VIDIOC_G_OUTPUT32: cmd = VIDIOC_G_OUTPUT; break;
  759. case VIDIOC_S_OUTPUT32: cmd = VIDIOC_S_OUTPUT; break;
  760. case VIDIOC_CREATE_BUFS32: cmd = VIDIOC_CREATE_BUFS; break;
  761. case VIDIOC_PREPARE_BUF32: cmd = VIDIOC_PREPARE_BUF; break;
  762. case VIDIOC_G_EDID32: cmd = VIDIOC_G_EDID; break;
  763. case VIDIOC_S_EDID32: cmd = VIDIOC_S_EDID; break;
  764. }
  765. switch (cmd) {
  766. case VIDIOC_OVERLAY:
  767. case VIDIOC_STREAMON:
  768. case VIDIOC_STREAMOFF:
  769. case VIDIOC_S_INPUT:
  770. case VIDIOC_S_OUTPUT:
  771. err = get_user(karg.vi, (s32 __user *)up);
  772. compatible_arg = 0;
  773. break;
  774. case VIDIOC_G_INPUT:
  775. case VIDIOC_G_OUTPUT:
  776. compatible_arg = 0;
  777. break;
  778. case VIDIOC_G_EDID:
  779. case VIDIOC_S_EDID:
  780. err = get_v4l2_edid32(&karg.v2edid, up);
  781. compatible_arg = 0;
  782. break;
  783. case VIDIOC_G_FMT:
  784. case VIDIOC_S_FMT:
  785. case VIDIOC_TRY_FMT:
  786. err = get_v4l2_format32(&karg.v2f, up);
  787. compatible_arg = 0;
  788. break;
  789. case VIDIOC_CREATE_BUFS:
  790. err = get_v4l2_create32(&karg.v2crt, up);
  791. compatible_arg = 0;
  792. break;
  793. case VIDIOC_PREPARE_BUF:
  794. case VIDIOC_QUERYBUF:
  795. case VIDIOC_QBUF:
  796. case VIDIOC_DQBUF:
  797. err = get_v4l2_buffer32(&karg.v2b, up);
  798. compatible_arg = 0;
  799. break;
  800. case VIDIOC_S_FBUF:
  801. err = get_v4l2_framebuffer32(&karg.v2fb, up);
  802. compatible_arg = 0;
  803. break;
  804. case VIDIOC_G_FBUF:
  805. compatible_arg = 0;
  806. break;
  807. case VIDIOC_ENUMSTD:
  808. err = get_v4l2_standard32(&karg.v2s, up);
  809. compatible_arg = 0;
  810. break;
  811. case VIDIOC_ENUMINPUT:
  812. err = get_v4l2_input32(&karg.v2i, up);
  813. compatible_arg = 0;
  814. break;
  815. case VIDIOC_G_EXT_CTRLS:
  816. case VIDIOC_S_EXT_CTRLS:
  817. case VIDIOC_TRY_EXT_CTRLS:
  818. err = get_v4l2_ext_controls32(&karg.v2ecs, up);
  819. compatible_arg = 0;
  820. break;
  821. case VIDIOC_DQEVENT:
  822. compatible_arg = 0;
  823. break;
  824. }
  825. if (err)
  826. return err;
  827. if (compatible_arg)
  828. err = native_ioctl(file, cmd, (unsigned long)up);
  829. else {
  830. mm_segment_t old_fs = get_fs();
  831. set_fs(KERNEL_DS);
  832. err = native_ioctl(file, cmd, (unsigned long)&karg);
  833. set_fs(old_fs);
  834. }
  835. /* Special case: even after an error we need to put the
  836. results back for these ioctls since the error_idx will
  837. contain information on which control failed. */
  838. switch (cmd) {
  839. case VIDIOC_G_EXT_CTRLS:
  840. case VIDIOC_S_EXT_CTRLS:
  841. case VIDIOC_TRY_EXT_CTRLS:
  842. if (put_v4l2_ext_controls32(&karg.v2ecs, up))
  843. err = -EFAULT;
  844. break;
  845. case VIDIOC_S_EDID:
  846. if (put_v4l2_edid32(&karg.v2edid, up))
  847. err = -EFAULT;
  848. break;
  849. }
  850. if (err)
  851. return err;
  852. switch (cmd) {
  853. case VIDIOC_S_INPUT:
  854. case VIDIOC_S_OUTPUT:
  855. case VIDIOC_G_INPUT:
  856. case VIDIOC_G_OUTPUT:
  857. err = put_user(((s32)karg.vi), (s32 __user *)up);
  858. break;
  859. case VIDIOC_G_FBUF:
  860. err = put_v4l2_framebuffer32(&karg.v2fb, up);
  861. break;
  862. case VIDIOC_DQEVENT:
  863. err = put_v4l2_event32(&karg.v2ev, up);
  864. break;
  865. case VIDIOC_G_EDID:
  866. err = put_v4l2_edid32(&karg.v2edid, up);
  867. break;
  868. case VIDIOC_G_FMT:
  869. case VIDIOC_S_FMT:
  870. case VIDIOC_TRY_FMT:
  871. err = put_v4l2_format32(&karg.v2f, up);
  872. break;
  873. case VIDIOC_CREATE_BUFS:
  874. err = put_v4l2_create32(&karg.v2crt, up);
  875. break;
  876. case VIDIOC_PREPARE_BUF:
  877. case VIDIOC_QUERYBUF:
  878. case VIDIOC_QBUF:
  879. case VIDIOC_DQBUF:
  880. err = put_v4l2_buffer32(&karg.v2b, up);
  881. break;
  882. case VIDIOC_ENUMSTD:
  883. err = put_v4l2_standard32(&karg.v2s, up);
  884. break;
  885. case VIDIOC_ENUMINPUT:
  886. err = put_v4l2_input32(&karg.v2i, up);
  887. break;
  888. }
  889. return err;
  890. }
  891. long v4l2_compat_ioctl32(struct file *file, unsigned int cmd, unsigned long arg)
  892. {
  893. struct video_device *vdev = video_devdata(file);
  894. long ret = -ENOIOCTLCMD;
  895. if (!file->f_op->unlocked_ioctl)
  896. return ret;
  897. if (_IOC_TYPE(cmd) == 'V' && _IOC_NR(cmd) < BASE_VIDIOC_PRIVATE)
  898. ret = do_video_ioctl(file, cmd, arg);
  899. else if (vdev->fops->compat_ioctl32)
  900. ret = vdev->fops->compat_ioctl32(file, cmd, arg);
  901. if (ret == -ENOIOCTLCMD)
  902. pr_debug("compat_ioctl32: unknown ioctl '%c', dir=%d, #%d (0x%08x)\n",
  903. _IOC_TYPE(cmd), _IOC_DIR(cmd), _IOC_NR(cmd), cmd);
  904. return ret;
  905. }
  906. EXPORT_SYMBOL_GPL(v4l2_compat_ioctl32);