v4l2-compat-ioctl32.c 28 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394959697989910010110210310410510610710810911011111211311411511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614714814915015115215315415515615715815916016116216316416516616716816917017117217317417517617717817918018118218318418518618718818919019119219319419519619719819920020120220320420520620720820921021121221321421521621721821922022122222322422522622722822923023123223323423523623723823924024124224324424524624724824925025125225325425525625725825926026126226326426526626726826927027127227327427527627727827928028128228328428528628728828929029129229329429529629729829930030130230330430530630730830931031131231331431531631731831932032132232332432532632732832933033133233333433533633733833934034134234334434534634734834935035135235335435535635735835936036136236336436536636736836937037137237337437537637737837938038138238338438538638738838939039139239339439539639739839940040140240340440540640740840941041141241341441541641741841942042142242342442542642742842943043143243343443543643743843944044144244344444544644744844945045145245345445545645745845946046146246346446546646746846947047147247347447547647747847948048148248348448548648748848949049149249349449549649749849950050150250350450550650750850951051151251351451551651751851952052152252352452552652752852953053153253353453553653753853954054154254354454554654754854955055155255355455555655755855956056156256356456556656756856957057157257357457557657757857958058158258358458558658758858959059159259359459559659759859960060160260360460560660760860961061161261361461561661761861962062162262362462562662762862963063163263363463563663763863964064164264364464564664764864965065165265365465565665765865966066166266366466566666766866967067167267367467567667767867968068168268368468568668768868969069169269369469569669769869970070170270370470570670770870971071171271371471571671771871972072172272372472572672772872973073173273373473573673773873974074174274374474574674774874975075175275375475575675775875976076176276376476576676776876977077177277377477577677777877978078178278378478578678778878979079179279379479579679779879980080180280380480580680780880981081181281381481581681781881982082182282382482582682782882983083183283383483583683783883984084184284384484584684784884985085185285385485585685785885986086186286386486586686786886987087187287387487587687787887988088188288388488588688788888989089189289389489589689789889990090190290390490590690790890991091191291391491591691791891992092192292392492592692792892993093193293393493593693793893994094194294394494594694794894995095195295395495595695795895996096196296396496596696796896997097197297397497597697797897998098198298398498598698798898999099199299399499599699799899910001001100210031004100510061007100810091010101110121013101410151016101710181019102010211022102310241025102610271028102910301031103210331034103510361037103810391040104110421043104410451046104710481049105010511052105310541055105610571058
  1. /*
  2. * ioctl32.c: Conversion between 32bit and 64bit native ioctls.
  3. * Separated from fs stuff by Arnd Bergmann <arnd@arndb.de>
  4. *
  5. * Copyright (C) 1997-2000 Jakub Jelinek (jakub@redhat.com)
  6. * Copyright (C) 1998 Eddie C. Dost (ecd@skynet.be)
  7. * Copyright (C) 2001,2002 Andi Kleen, SuSE Labs
  8. * Copyright (C) 2003 Pavel Machek (pavel@ucw.cz)
  9. * Copyright (C) 2005 Philippe De Muyter (phdm@macqel.be)
  10. * Copyright (C) 2008 Hans Verkuil <hverkuil@xs4all.nl>
  11. *
  12. * These routines maintain argument size conversion between 32bit and 64bit
  13. * ioctls.
  14. */
  15. #include <linux/compat.h>
  16. #include <linux/module.h>
  17. #include <linux/videodev2.h>
  18. #include <linux/v4l2-subdev.h>
  19. #include <media/v4l2-dev.h>
  20. #include <media/v4l2-fh.h>
  21. #include <media/v4l2-ctrls.h>
  22. #include <media/v4l2-ioctl.h>
  23. static long native_ioctl(struct file *file, unsigned int cmd, unsigned long arg)
  24. {
  25. long ret = -ENOIOCTLCMD;
  26. if (file->f_op->unlocked_ioctl)
  27. ret = file->f_op->unlocked_ioctl(file, cmd, arg);
  28. return ret;
  29. }
  30. struct v4l2_clip32 {
  31. struct v4l2_rect c;
  32. compat_caddr_t next;
  33. };
  34. struct v4l2_window32 {
  35. struct v4l2_rect w;
  36. __u32 field; /* enum v4l2_field */
  37. __u32 chromakey;
  38. compat_caddr_t clips; /* actually struct v4l2_clip32 * */
  39. __u32 clipcount;
  40. compat_caddr_t bitmap;
  41. __u8 global_alpha;
  42. };
  43. static int get_v4l2_window32(struct v4l2_window *kp, struct v4l2_window32 __user *up)
  44. {
  45. struct v4l2_clip32 __user *uclips;
  46. struct v4l2_clip __user *kclips;
  47. compat_caddr_t p;
  48. u32 n;
  49. if (!access_ok(VERIFY_READ, up, sizeof(*up)) ||
  50. copy_from_user(&kp->w, &up->w, sizeof(up->w)) ||
  51. get_user(kp->field, &up->field) ||
  52. get_user(kp->chromakey, &up->chromakey) ||
  53. get_user(kp->clipcount, &up->clipcount) ||
  54. get_user(kp->global_alpha, &up->global_alpha))
  55. return -EFAULT;
  56. if (kp->clipcount > 2048)
  57. return -EINVAL;
  58. if (!kp->clipcount) {
  59. kp->clips = NULL;
  60. return 0;
  61. }
  62. n = kp->clipcount;
  63. if (get_user(p, &up->clips))
  64. return -EFAULT;
  65. uclips = compat_ptr(p);
  66. kclips = compat_alloc_user_space(n * sizeof(*kclips));
  67. kp->clips = kclips;
  68. while (n--) {
  69. if (copy_in_user(&kclips->c, &uclips->c, sizeof(uclips->c)))
  70. return -EFAULT;
  71. if (put_user(n ? kclips + 1 : NULL, &kclips->next))
  72. return -EFAULT;
  73. uclips++;
  74. kclips++;
  75. }
  76. return 0;
  77. }
  78. static int put_v4l2_window32(struct v4l2_window *kp, struct v4l2_window32 __user *up)
  79. {
  80. struct v4l2_clip __user *kclips = kp->clips;
  81. struct v4l2_clip32 __user *uclips;
  82. u32 n = kp->clipcount;
  83. compat_caddr_t p;
  84. if (copy_to_user(&up->w, &kp->w, sizeof(kp->w)) ||
  85. put_user(kp->field, &up->field) ||
  86. put_user(kp->chromakey, &up->chromakey) ||
  87. put_user(kp->clipcount, &up->clipcount) ||
  88. put_user(kp->global_alpha, &up->global_alpha))
  89. return -EFAULT;
  90. if (!kp->clipcount)
  91. return 0;
  92. if (get_user(p, &up->clips))
  93. return -EFAULT;
  94. uclips = compat_ptr(p);
  95. while (n--) {
  96. if (copy_in_user(&uclips->c, &kclips->c, sizeof(uclips->c)))
  97. return -EFAULT;
  98. uclips++;
  99. kclips++;
  100. }
  101. return 0;
  102. }
  103. struct v4l2_format32 {
  104. __u32 type; /* enum v4l2_buf_type */
  105. union {
  106. struct v4l2_pix_format pix;
  107. struct v4l2_pix_format_mplane pix_mp;
  108. struct v4l2_window32 win;
  109. struct v4l2_vbi_format vbi;
  110. struct v4l2_sliced_vbi_format sliced;
  111. struct v4l2_sdr_format sdr;
  112. struct v4l2_meta_format meta;
  113. __u8 raw_data[200]; /* user-defined */
  114. } fmt;
  115. };
  116. /**
  117. * struct v4l2_create_buffers32 - VIDIOC_CREATE_BUFS32 argument
  118. * @index: on return, index of the first created buffer
  119. * @count: entry: number of requested buffers,
  120. * return: number of created buffers
  121. * @memory: buffer memory type
  122. * @format: frame format, for which buffers are requested
  123. * @reserved: future extensions
  124. */
  125. struct v4l2_create_buffers32 {
  126. __u32 index;
  127. __u32 count;
  128. __u32 memory; /* enum v4l2_memory */
  129. struct v4l2_format32 format;
  130. __u32 reserved[8];
  131. };
  132. static int __get_v4l2_format32(struct v4l2_format *kp, struct v4l2_format32 __user *up)
  133. {
  134. if (get_user(kp->type, &up->type))
  135. return -EFAULT;
  136. switch (kp->type) {
  137. case V4L2_BUF_TYPE_VIDEO_CAPTURE:
  138. case V4L2_BUF_TYPE_VIDEO_OUTPUT:
  139. return copy_from_user(&kp->fmt.pix, &up->fmt.pix,
  140. sizeof(kp->fmt.pix)) ? -EFAULT : 0;
  141. case V4L2_BUF_TYPE_VIDEO_CAPTURE_MPLANE:
  142. case V4L2_BUF_TYPE_VIDEO_OUTPUT_MPLANE:
  143. return copy_from_user(&kp->fmt.pix_mp, &up->fmt.pix_mp,
  144. sizeof(kp->fmt.pix_mp)) ? -EFAULT : 0;
  145. case V4L2_BUF_TYPE_VIDEO_OVERLAY:
  146. case V4L2_BUF_TYPE_VIDEO_OUTPUT_OVERLAY:
  147. return get_v4l2_window32(&kp->fmt.win, &up->fmt.win);
  148. case V4L2_BUF_TYPE_VBI_CAPTURE:
  149. case V4L2_BUF_TYPE_VBI_OUTPUT:
  150. return copy_from_user(&kp->fmt.vbi, &up->fmt.vbi,
  151. sizeof(kp->fmt.vbi)) ? -EFAULT : 0;
  152. case V4L2_BUF_TYPE_SLICED_VBI_CAPTURE:
  153. case V4L2_BUF_TYPE_SLICED_VBI_OUTPUT:
  154. return copy_from_user(&kp->fmt.sliced, &up->fmt.sliced,
  155. sizeof(kp->fmt.sliced)) ? -EFAULT : 0;
  156. case V4L2_BUF_TYPE_SDR_CAPTURE:
  157. case V4L2_BUF_TYPE_SDR_OUTPUT:
  158. return copy_from_user(&kp->fmt.sdr, &up->fmt.sdr,
  159. sizeof(kp->fmt.sdr)) ? -EFAULT : 0;
  160. case V4L2_BUF_TYPE_META_CAPTURE:
  161. return copy_from_user(&kp->fmt.meta, &up->fmt.meta,
  162. sizeof(kp->fmt.meta)) ? -EFAULT : 0;
  163. default:
  164. return -EINVAL;
  165. }
  166. }
  167. static int get_v4l2_format32(struct v4l2_format *kp, struct v4l2_format32 __user *up)
  168. {
  169. if (!access_ok(VERIFY_READ, up, sizeof(*up)))
  170. return -EFAULT;
  171. return __get_v4l2_format32(kp, up);
  172. }
  173. static int get_v4l2_create32(struct v4l2_create_buffers *kp, struct v4l2_create_buffers32 __user *up)
  174. {
  175. if (!access_ok(VERIFY_READ, up, sizeof(*up)) ||
  176. copy_from_user(kp, up, offsetof(struct v4l2_create_buffers32, format)))
  177. return -EFAULT;
  178. return __get_v4l2_format32(&kp->format, &up->format);
  179. }
  180. static int __put_v4l2_format32(struct v4l2_format *kp, struct v4l2_format32 __user *up)
  181. {
  182. if (put_user(kp->type, &up->type))
  183. return -EFAULT;
  184. switch (kp->type) {
  185. case V4L2_BUF_TYPE_VIDEO_CAPTURE:
  186. case V4L2_BUF_TYPE_VIDEO_OUTPUT:
  187. return copy_to_user(&up->fmt.pix, &kp->fmt.pix,
  188. sizeof(kp->fmt.pix)) ? -EFAULT : 0;
  189. case V4L2_BUF_TYPE_VIDEO_CAPTURE_MPLANE:
  190. case V4L2_BUF_TYPE_VIDEO_OUTPUT_MPLANE:
  191. return copy_to_user(&up->fmt.pix_mp, &kp->fmt.pix_mp,
  192. sizeof(kp->fmt.pix_mp)) ? -EFAULT : 0;
  193. case V4L2_BUF_TYPE_VIDEO_OVERLAY:
  194. case V4L2_BUF_TYPE_VIDEO_OUTPUT_OVERLAY:
  195. return put_v4l2_window32(&kp->fmt.win, &up->fmt.win);
  196. case V4L2_BUF_TYPE_VBI_CAPTURE:
  197. case V4L2_BUF_TYPE_VBI_OUTPUT:
  198. return copy_to_user(&up->fmt.vbi, &kp->fmt.vbi,
  199. sizeof(kp->fmt.vbi)) ? -EFAULT : 0;
  200. case V4L2_BUF_TYPE_SLICED_VBI_CAPTURE:
  201. case V4L2_BUF_TYPE_SLICED_VBI_OUTPUT:
  202. return copy_to_user(&up->fmt.sliced, &kp->fmt.sliced,
  203. sizeof(kp->fmt.sliced)) ? -EFAULT : 0;
  204. case V4L2_BUF_TYPE_SDR_CAPTURE:
  205. case V4L2_BUF_TYPE_SDR_OUTPUT:
  206. return copy_to_user(&up->fmt.sdr, &kp->fmt.sdr,
  207. sizeof(kp->fmt.sdr)) ? -EFAULT : 0;
  208. case V4L2_BUF_TYPE_META_CAPTURE:
  209. return copy_to_user(&up->fmt.meta, &kp->fmt.meta,
  210. sizeof(kp->fmt.meta)) ? -EFAULT : 0;
  211. default:
  212. return -EINVAL;
  213. }
  214. }
  215. static int put_v4l2_format32(struct v4l2_format *kp, struct v4l2_format32 __user *up)
  216. {
  217. if (!access_ok(VERIFY_WRITE, up, sizeof(*up)))
  218. return -EFAULT;
  219. return __put_v4l2_format32(kp, up);
  220. }
  221. static int put_v4l2_create32(struct v4l2_create_buffers *kp, struct v4l2_create_buffers32 __user *up)
  222. {
  223. if (!access_ok(VERIFY_WRITE, up, sizeof(*up)) ||
  224. copy_to_user(up, kp, offsetof(struct v4l2_create_buffers32, format)) ||
  225. copy_to_user(up->reserved, kp->reserved, sizeof(kp->reserved)))
  226. return -EFAULT;
  227. return __put_v4l2_format32(&kp->format, &up->format);
  228. }
  229. struct v4l2_standard32 {
  230. __u32 index;
  231. compat_u64 id;
  232. __u8 name[24];
  233. struct v4l2_fract frameperiod; /* Frames, not fields */
  234. __u32 framelines;
  235. __u32 reserved[4];
  236. };
  237. static int get_v4l2_standard32(struct v4l2_standard *kp, struct v4l2_standard32 __user *up)
  238. {
  239. /* other fields are not set by the user, nor used by the driver */
  240. if (!access_ok(VERIFY_READ, up, sizeof(*up)) ||
  241. get_user(kp->index, &up->index))
  242. return -EFAULT;
  243. return 0;
  244. }
  245. static int put_v4l2_standard32(struct v4l2_standard *kp, struct v4l2_standard32 __user *up)
  246. {
  247. if (!access_ok(VERIFY_WRITE, up, sizeof(*up)) ||
  248. put_user(kp->index, &up->index) ||
  249. put_user(kp->id, &up->id) ||
  250. copy_to_user(up->name, kp->name, sizeof(up->name)) ||
  251. copy_to_user(&up->frameperiod, &kp->frameperiod,
  252. sizeof(kp->frameperiod)) ||
  253. put_user(kp->framelines, &up->framelines) ||
  254. copy_to_user(up->reserved, kp->reserved, sizeof(kp->reserved)))
  255. return -EFAULT;
  256. return 0;
  257. }
  258. struct v4l2_plane32 {
  259. __u32 bytesused;
  260. __u32 length;
  261. union {
  262. __u32 mem_offset;
  263. compat_long_t userptr;
  264. __s32 fd;
  265. } m;
  266. __u32 data_offset;
  267. __u32 reserved[11];
  268. };
  269. struct v4l2_buffer32 {
  270. __u32 index;
  271. __u32 type; /* enum v4l2_buf_type */
  272. __u32 bytesused;
  273. __u32 flags;
  274. __u32 field; /* enum v4l2_field */
  275. struct compat_timeval timestamp;
  276. struct v4l2_timecode timecode;
  277. __u32 sequence;
  278. /* memory location */
  279. __u32 memory; /* enum v4l2_memory */
  280. union {
  281. __u32 offset;
  282. compat_long_t userptr;
  283. compat_caddr_t planes;
  284. __s32 fd;
  285. } m;
  286. __u32 length;
  287. __u32 reserved2;
  288. __u32 reserved;
  289. };
  290. static int get_v4l2_plane32(struct v4l2_plane __user *up, struct v4l2_plane32 __user *up32,
  291. enum v4l2_memory memory)
  292. {
  293. void __user *up_pln;
  294. compat_long_t p;
  295. if (copy_in_user(up, up32, 2 * sizeof(__u32)) ||
  296. copy_in_user(&up->data_offset, &up32->data_offset,
  297. sizeof(up->data_offset)))
  298. return -EFAULT;
  299. switch (memory) {
  300. case V4L2_MEMORY_MMAP:
  301. case V4L2_MEMORY_OVERLAY:
  302. if (copy_in_user(&up->m.mem_offset, &up32->m.mem_offset,
  303. sizeof(up32->m.mem_offset)))
  304. return -EFAULT;
  305. break;
  306. case V4L2_MEMORY_USERPTR:
  307. if (get_user(p, &up32->m.userptr))
  308. return -EFAULT;
  309. up_pln = compat_ptr(p);
  310. if (put_user((unsigned long)up_pln, &up->m.userptr))
  311. return -EFAULT;
  312. break;
  313. case V4L2_MEMORY_DMABUF:
  314. if (copy_in_user(&up->m.fd, &up32->m.fd, sizeof(up32->m.fd)))
  315. return -EFAULT;
  316. break;
  317. }
  318. return 0;
  319. }
  320. static int put_v4l2_plane32(struct v4l2_plane __user *up, struct v4l2_plane32 __user *up32,
  321. enum v4l2_memory memory)
  322. {
  323. unsigned long p;
  324. if (copy_in_user(up32, up, 2 * sizeof(__u32)) ||
  325. copy_in_user(&up32->data_offset, &up->data_offset,
  326. sizeof(up->data_offset)))
  327. return -EFAULT;
  328. switch (memory) {
  329. case V4L2_MEMORY_MMAP:
  330. case V4L2_MEMORY_OVERLAY:
  331. if (copy_in_user(&up32->m.mem_offset, &up->m.mem_offset,
  332. sizeof(up->m.mem_offset)))
  333. return -EFAULT;
  334. break;
  335. case V4L2_MEMORY_USERPTR:
  336. if (get_user(p, &up->m.userptr) ||
  337. put_user((compat_ulong_t)ptr_to_compat((__force void *)p),
  338. &up32->m.userptr))
  339. return -EFAULT;
  340. break;
  341. case V4L2_MEMORY_DMABUF:
  342. if (copy_in_user(&up32->m.fd, &up->m.fd,
  343. sizeof(up->m.fd)))
  344. return -EFAULT;
  345. break;
  346. }
  347. return 0;
  348. }
  349. static int get_v4l2_buffer32(struct v4l2_buffer *kp, struct v4l2_buffer32 __user *up)
  350. {
  351. struct v4l2_plane32 __user *uplane32;
  352. struct v4l2_plane __user *uplane;
  353. compat_caddr_t p;
  354. int ret;
  355. if (!access_ok(VERIFY_READ, up, sizeof(*up)) ||
  356. get_user(kp->index, &up->index) ||
  357. get_user(kp->type, &up->type) ||
  358. get_user(kp->flags, &up->flags) ||
  359. get_user(kp->memory, &up->memory) ||
  360. get_user(kp->length, &up->length))
  361. return -EFAULT;
  362. if (V4L2_TYPE_IS_OUTPUT(kp->type))
  363. if (get_user(kp->bytesused, &up->bytesused) ||
  364. get_user(kp->field, &up->field) ||
  365. get_user(kp->timestamp.tv_sec, &up->timestamp.tv_sec) ||
  366. get_user(kp->timestamp.tv_usec, &up->timestamp.tv_usec))
  367. return -EFAULT;
  368. if (V4L2_TYPE_IS_MULTIPLANAR(kp->type)) {
  369. unsigned int num_planes;
  370. if (kp->length == 0) {
  371. kp->m.planes = NULL;
  372. /* num_planes == 0 is legal, e.g. when userspace doesn't
  373. * need planes array on DQBUF*/
  374. return 0;
  375. } else if (kp->length > VIDEO_MAX_PLANES) {
  376. return -EINVAL;
  377. }
  378. if (get_user(p, &up->m.planes))
  379. return -EFAULT;
  380. uplane32 = compat_ptr(p);
  381. if (!access_ok(VERIFY_READ, uplane32,
  382. kp->length * sizeof(*uplane32)))
  383. return -EFAULT;
  384. /* We don't really care if userspace decides to kill itself
  385. * by passing a very big num_planes value */
  386. uplane = compat_alloc_user_space(kp->length * sizeof(*uplane));
  387. kp->m.planes = (__force struct v4l2_plane *)uplane;
  388. for (num_planes = 0; num_planes < kp->length; num_planes++) {
  389. ret = get_v4l2_plane32(uplane, uplane32, kp->memory);
  390. if (ret)
  391. return ret;
  392. ++uplane;
  393. ++uplane32;
  394. }
  395. } else {
  396. switch (kp->memory) {
  397. case V4L2_MEMORY_MMAP:
  398. case V4L2_MEMORY_OVERLAY:
  399. if (get_user(kp->m.offset, &up->m.offset))
  400. return -EFAULT;
  401. break;
  402. case V4L2_MEMORY_USERPTR:
  403. {
  404. compat_long_t tmp;
  405. if (get_user(tmp, &up->m.userptr))
  406. return -EFAULT;
  407. kp->m.userptr = (unsigned long)compat_ptr(tmp);
  408. }
  409. break;
  410. case V4L2_MEMORY_DMABUF:
  411. if (get_user(kp->m.fd, &up->m.fd))
  412. return -EFAULT;
  413. break;
  414. }
  415. }
  416. return 0;
  417. }
  418. static int put_v4l2_buffer32(struct v4l2_buffer *kp, struct v4l2_buffer32 __user *up)
  419. {
  420. struct v4l2_plane32 __user *uplane32;
  421. struct v4l2_plane __user *uplane;
  422. compat_caddr_t p;
  423. int num_planes;
  424. int ret;
  425. if (!access_ok(VERIFY_WRITE, up, sizeof(*up)) ||
  426. put_user(kp->index, &up->index) ||
  427. put_user(kp->type, &up->type) ||
  428. put_user(kp->flags, &up->flags) ||
  429. put_user(kp->memory, &up->memory))
  430. return -EFAULT;
  431. if (put_user(kp->bytesused, &up->bytesused) ||
  432. put_user(kp->field, &up->field) ||
  433. put_user(kp->timestamp.tv_sec, &up->timestamp.tv_sec) ||
  434. put_user(kp->timestamp.tv_usec, &up->timestamp.tv_usec) ||
  435. copy_to_user(&up->timecode, &kp->timecode, sizeof(kp->timecode)) ||
  436. put_user(kp->sequence, &up->sequence) ||
  437. put_user(kp->reserved2, &up->reserved2) ||
  438. put_user(kp->reserved, &up->reserved) ||
  439. put_user(kp->length, &up->length))
  440. return -EFAULT;
  441. if (V4L2_TYPE_IS_MULTIPLANAR(kp->type)) {
  442. num_planes = kp->length;
  443. if (num_planes == 0)
  444. return 0;
  445. uplane = (__force struct v4l2_plane __user *)kp->m.planes;
  446. if (get_user(p, &up->m.planes))
  447. return -EFAULT;
  448. uplane32 = compat_ptr(p);
  449. while (--num_planes >= 0) {
  450. ret = put_v4l2_plane32(uplane, uplane32, kp->memory);
  451. if (ret)
  452. return ret;
  453. ++uplane;
  454. ++uplane32;
  455. }
  456. } else {
  457. switch (kp->memory) {
  458. case V4L2_MEMORY_MMAP:
  459. case V4L2_MEMORY_OVERLAY:
  460. if (put_user(kp->m.offset, &up->m.offset))
  461. return -EFAULT;
  462. break;
  463. case V4L2_MEMORY_USERPTR:
  464. if (put_user(kp->m.userptr, &up->m.userptr))
  465. return -EFAULT;
  466. break;
  467. case V4L2_MEMORY_DMABUF:
  468. if (put_user(kp->m.fd, &up->m.fd))
  469. return -EFAULT;
  470. break;
  471. }
  472. }
  473. return 0;
  474. }
  475. struct v4l2_framebuffer32 {
  476. __u32 capability;
  477. __u32 flags;
  478. compat_caddr_t base;
  479. struct {
  480. __u32 width;
  481. __u32 height;
  482. __u32 pixelformat;
  483. __u32 field;
  484. __u32 bytesperline;
  485. __u32 sizeimage;
  486. __u32 colorspace;
  487. __u32 priv;
  488. } fmt;
  489. };
  490. static int get_v4l2_framebuffer32(struct v4l2_framebuffer *kp, struct v4l2_framebuffer32 __user *up)
  491. {
  492. u32 tmp;
  493. if (!access_ok(VERIFY_READ, up, sizeof(*up)) ||
  494. get_user(tmp, &up->base) ||
  495. get_user(kp->capability, &up->capability) ||
  496. get_user(kp->flags, &up->flags) ||
  497. copy_from_user(&kp->fmt, &up->fmt, sizeof(up->fmt)))
  498. return -EFAULT;
  499. kp->base = (__force void *)compat_ptr(tmp);
  500. return 0;
  501. }
  502. static int put_v4l2_framebuffer32(struct v4l2_framebuffer *kp, struct v4l2_framebuffer32 __user *up)
  503. {
  504. u32 tmp = (u32)((unsigned long)kp->base);
  505. if (!access_ok(VERIFY_WRITE, up, sizeof(*up)) ||
  506. put_user(tmp, &up->base) ||
  507. put_user(kp->capability, &up->capability) ||
  508. put_user(kp->flags, &up->flags) ||
  509. copy_to_user(&up->fmt, &kp->fmt, sizeof(up->fmt)))
  510. return -EFAULT;
  511. return 0;
  512. }
  513. struct v4l2_input32 {
  514. __u32 index; /* Which input */
  515. __u8 name[32]; /* Label */
  516. __u32 type; /* Type of input */
  517. __u32 audioset; /* Associated audios (bitfield) */
  518. __u32 tuner; /* Associated tuner */
  519. compat_u64 std;
  520. __u32 status;
  521. __u32 capabilities;
  522. __u32 reserved[3];
  523. };
  524. /* The 64-bit v4l2_input struct has extra padding at the end of the struct.
  525. Otherwise it is identical to the 32-bit version. */
  526. static inline int get_v4l2_input32(struct v4l2_input *kp, struct v4l2_input32 __user *up)
  527. {
  528. if (copy_from_user(kp, up, sizeof(*up)))
  529. return -EFAULT;
  530. return 0;
  531. }
  532. static inline int put_v4l2_input32(struct v4l2_input *kp, struct v4l2_input32 __user *up)
  533. {
  534. if (copy_to_user(up, kp, sizeof(*up)))
  535. return -EFAULT;
  536. return 0;
  537. }
  538. struct v4l2_ext_controls32 {
  539. __u32 which;
  540. __u32 count;
  541. __u32 error_idx;
  542. __u32 reserved[2];
  543. compat_caddr_t controls; /* actually struct v4l2_ext_control32 * */
  544. };
  545. struct v4l2_ext_control32 {
  546. __u32 id;
  547. __u32 size;
  548. __u32 reserved2[1];
  549. union {
  550. __s32 value;
  551. __s64 value64;
  552. compat_caddr_t string; /* actually char * */
  553. };
  554. } __attribute__ ((packed));
  555. /* Return true if this control is a pointer type. */
  556. static inline bool ctrl_is_pointer(struct file *file, u32 id)
  557. {
  558. struct video_device *vdev = video_devdata(file);
  559. struct v4l2_fh *fh = NULL;
  560. struct v4l2_ctrl_handler *hdl = NULL;
  561. struct v4l2_query_ext_ctrl qec = { id };
  562. const struct v4l2_ioctl_ops *ops = vdev->ioctl_ops;
  563. if (test_bit(V4L2_FL_USES_V4L2_FH, &vdev->flags))
  564. fh = file->private_data;
  565. if (fh && fh->ctrl_handler)
  566. hdl = fh->ctrl_handler;
  567. else if (vdev->ctrl_handler)
  568. hdl = vdev->ctrl_handler;
  569. if (hdl) {
  570. struct v4l2_ctrl *ctrl = v4l2_ctrl_find(hdl, id);
  571. return ctrl && ctrl->is_ptr;
  572. }
  573. if (!ops->vidioc_query_ext_ctrl)
  574. return false;
  575. return !ops->vidioc_query_ext_ctrl(file, fh, &qec) &&
  576. (qec.flags & V4L2_CTRL_FLAG_HAS_PAYLOAD);
  577. }
  578. static int get_v4l2_ext_controls32(struct file *file,
  579. struct v4l2_ext_controls *kp,
  580. struct v4l2_ext_controls32 __user *up)
  581. {
  582. struct v4l2_ext_control32 __user *ucontrols;
  583. struct v4l2_ext_control __user *kcontrols;
  584. unsigned int n;
  585. compat_caddr_t p;
  586. if (!access_ok(VERIFY_READ, up, sizeof(*up)) ||
  587. get_user(kp->which, &up->which) ||
  588. get_user(kp->count, &up->count) ||
  589. get_user(kp->error_idx, &up->error_idx) ||
  590. copy_from_user(kp->reserved, up->reserved, sizeof(kp->reserved)))
  591. return -EFAULT;
  592. if (kp->count == 0) {
  593. kp->controls = NULL;
  594. return 0;
  595. } else if (kp->count > V4L2_CID_MAX_CTRLS) {
  596. return -EINVAL;
  597. }
  598. if (get_user(p, &up->controls))
  599. return -EFAULT;
  600. ucontrols = compat_ptr(p);
  601. if (!access_ok(VERIFY_READ, ucontrols, kp->count * sizeof(*ucontrols)))
  602. return -EFAULT;
  603. kcontrols = compat_alloc_user_space(kp->count * sizeof(*kcontrols));
  604. kp->controls = (__force struct v4l2_ext_control *)kcontrols;
  605. for (n = 0; n < kp->count; n++) {
  606. u32 id;
  607. if (copy_in_user(kcontrols, ucontrols, sizeof(*ucontrols)))
  608. return -EFAULT;
  609. if (get_user(id, &kcontrols->id))
  610. return -EFAULT;
  611. if (ctrl_is_pointer(file, id)) {
  612. void __user *s;
  613. if (get_user(p, &ucontrols->string))
  614. return -EFAULT;
  615. s = compat_ptr(p);
  616. if (put_user(s, &kcontrols->string))
  617. return -EFAULT;
  618. }
  619. ucontrols++;
  620. kcontrols++;
  621. }
  622. return 0;
  623. }
  624. static int put_v4l2_ext_controls32(struct file *file,
  625. struct v4l2_ext_controls *kp,
  626. struct v4l2_ext_controls32 __user *up)
  627. {
  628. struct v4l2_ext_control32 __user *ucontrols;
  629. struct v4l2_ext_control __user *kcontrols =
  630. (__force struct v4l2_ext_control __user *)kp->controls;
  631. int n = kp->count;
  632. compat_caddr_t p;
  633. if (!access_ok(VERIFY_WRITE, up, sizeof(*up)) ||
  634. put_user(kp->which, &up->which) ||
  635. put_user(kp->count, &up->count) ||
  636. put_user(kp->error_idx, &up->error_idx) ||
  637. copy_to_user(up->reserved, kp->reserved, sizeof(up->reserved)))
  638. return -EFAULT;
  639. if (!kp->count)
  640. return 0;
  641. if (get_user(p, &up->controls))
  642. return -EFAULT;
  643. ucontrols = compat_ptr(p);
  644. if (!access_ok(VERIFY_WRITE, ucontrols, n * sizeof(*ucontrols)))
  645. return -EFAULT;
  646. while (--n >= 0) {
  647. unsigned size = sizeof(*ucontrols);
  648. u32 id;
  649. if (get_user(id, &kcontrols->id))
  650. return -EFAULT;
  651. /* Do not modify the pointer when copying a pointer control.
  652. The contents of the pointer was changed, not the pointer
  653. itself. */
  654. if (ctrl_is_pointer(file, id))
  655. size -= sizeof(ucontrols->value64);
  656. if (copy_in_user(ucontrols, kcontrols, size))
  657. return -EFAULT;
  658. ucontrols++;
  659. kcontrols++;
  660. }
  661. return 0;
  662. }
  663. struct v4l2_event32 {
  664. __u32 type;
  665. union {
  666. compat_s64 value64;
  667. __u8 data[64];
  668. } u;
  669. __u32 pending;
  670. __u32 sequence;
  671. struct compat_timespec timestamp;
  672. __u32 id;
  673. __u32 reserved[8];
  674. };
  675. static int put_v4l2_event32(struct v4l2_event *kp, struct v4l2_event32 __user *up)
  676. {
  677. if (!access_ok(VERIFY_WRITE, up, sizeof(*up)) ||
  678. put_user(kp->type, &up->type) ||
  679. copy_to_user(&up->u, &kp->u, sizeof(kp->u)) ||
  680. put_user(kp->pending, &up->pending) ||
  681. put_user(kp->sequence, &up->sequence) ||
  682. put_user(kp->timestamp.tv_sec, &up->timestamp.tv_sec) ||
  683. put_user(kp->timestamp.tv_nsec, &up->timestamp.tv_nsec) ||
  684. put_user(kp->id, &up->id) ||
  685. copy_to_user(up->reserved, kp->reserved, sizeof(kp->reserved)))
  686. return -EFAULT;
  687. return 0;
  688. }
  689. struct v4l2_edid32 {
  690. __u32 pad;
  691. __u32 start_block;
  692. __u32 blocks;
  693. __u32 reserved[5];
  694. compat_caddr_t edid;
  695. };
  696. static int get_v4l2_edid32(struct v4l2_edid *kp, struct v4l2_edid32 __user *up)
  697. {
  698. u32 tmp;
  699. if (!access_ok(VERIFY_READ, up, sizeof(*up)) ||
  700. get_user(kp->pad, &up->pad) ||
  701. get_user(kp->start_block, &up->start_block) ||
  702. get_user(kp->blocks, &up->blocks) ||
  703. get_user(tmp, &up->edid) ||
  704. copy_from_user(kp->reserved, up->reserved, sizeof(kp->reserved)))
  705. return -EFAULT;
  706. kp->edid = (__force u8 *)compat_ptr(tmp);
  707. return 0;
  708. }
  709. static int put_v4l2_edid32(struct v4l2_edid *kp, struct v4l2_edid32 __user *up)
  710. {
  711. u32 tmp = (u32)((unsigned long)kp->edid);
  712. if (!access_ok(VERIFY_WRITE, up, sizeof(*up)) ||
  713. put_user(kp->pad, &up->pad) ||
  714. put_user(kp->start_block, &up->start_block) ||
  715. put_user(kp->blocks, &up->blocks) ||
  716. put_user(tmp, &up->edid) ||
  717. copy_to_user(up->reserved, kp->reserved, sizeof(up->reserved)))
  718. return -EFAULT;
  719. return 0;
  720. }
  721. #define VIDIOC_G_FMT32 _IOWR('V', 4, struct v4l2_format32)
  722. #define VIDIOC_S_FMT32 _IOWR('V', 5, struct v4l2_format32)
  723. #define VIDIOC_QUERYBUF32 _IOWR('V', 9, struct v4l2_buffer32)
  724. #define VIDIOC_G_FBUF32 _IOR ('V', 10, struct v4l2_framebuffer32)
  725. #define VIDIOC_S_FBUF32 _IOW ('V', 11, struct v4l2_framebuffer32)
  726. #define VIDIOC_QBUF32 _IOWR('V', 15, struct v4l2_buffer32)
  727. #define VIDIOC_DQBUF32 _IOWR('V', 17, struct v4l2_buffer32)
  728. #define VIDIOC_ENUMSTD32 _IOWR('V', 25, struct v4l2_standard32)
  729. #define VIDIOC_ENUMINPUT32 _IOWR('V', 26, struct v4l2_input32)
  730. #define VIDIOC_G_EDID32 _IOWR('V', 40, struct v4l2_edid32)
  731. #define VIDIOC_S_EDID32 _IOWR('V', 41, struct v4l2_edid32)
  732. #define VIDIOC_TRY_FMT32 _IOWR('V', 64, struct v4l2_format32)
  733. #define VIDIOC_G_EXT_CTRLS32 _IOWR('V', 71, struct v4l2_ext_controls32)
  734. #define VIDIOC_S_EXT_CTRLS32 _IOWR('V', 72, struct v4l2_ext_controls32)
  735. #define VIDIOC_TRY_EXT_CTRLS32 _IOWR('V', 73, struct v4l2_ext_controls32)
  736. #define VIDIOC_DQEVENT32 _IOR ('V', 89, struct v4l2_event32)
  737. #define VIDIOC_CREATE_BUFS32 _IOWR('V', 92, struct v4l2_create_buffers32)
  738. #define VIDIOC_PREPARE_BUF32 _IOWR('V', 93, struct v4l2_buffer32)
  739. #define VIDIOC_OVERLAY32 _IOW ('V', 14, s32)
  740. #define VIDIOC_STREAMON32 _IOW ('V', 18, s32)
  741. #define VIDIOC_STREAMOFF32 _IOW ('V', 19, s32)
  742. #define VIDIOC_G_INPUT32 _IOR ('V', 38, s32)
  743. #define VIDIOC_S_INPUT32 _IOWR('V', 39, s32)
  744. #define VIDIOC_G_OUTPUT32 _IOR ('V', 46, s32)
  745. #define VIDIOC_S_OUTPUT32 _IOWR('V', 47, s32)
  746. static long do_video_ioctl(struct file *file, unsigned int cmd, unsigned long arg)
  747. {
  748. union {
  749. struct v4l2_format v2f;
  750. struct v4l2_buffer v2b;
  751. struct v4l2_framebuffer v2fb;
  752. struct v4l2_input v2i;
  753. struct v4l2_standard v2s;
  754. struct v4l2_ext_controls v2ecs;
  755. struct v4l2_event v2ev;
  756. struct v4l2_create_buffers v2crt;
  757. struct v4l2_edid v2edid;
  758. unsigned long vx;
  759. int vi;
  760. } karg;
  761. void __user *up = compat_ptr(arg);
  762. int compatible_arg = 1;
  763. long err = 0;
  764. /* First, convert the command. */
  765. switch (cmd) {
  766. case VIDIOC_G_FMT32: cmd = VIDIOC_G_FMT; break;
  767. case VIDIOC_S_FMT32: cmd = VIDIOC_S_FMT; break;
  768. case VIDIOC_QUERYBUF32: cmd = VIDIOC_QUERYBUF; break;
  769. case VIDIOC_G_FBUF32: cmd = VIDIOC_G_FBUF; break;
  770. case VIDIOC_S_FBUF32: cmd = VIDIOC_S_FBUF; break;
  771. case VIDIOC_QBUF32: cmd = VIDIOC_QBUF; break;
  772. case VIDIOC_DQBUF32: cmd = VIDIOC_DQBUF; break;
  773. case VIDIOC_ENUMSTD32: cmd = VIDIOC_ENUMSTD; break;
  774. case VIDIOC_ENUMINPUT32: cmd = VIDIOC_ENUMINPUT; break;
  775. case VIDIOC_TRY_FMT32: cmd = VIDIOC_TRY_FMT; break;
  776. case VIDIOC_G_EXT_CTRLS32: cmd = VIDIOC_G_EXT_CTRLS; break;
  777. case VIDIOC_S_EXT_CTRLS32: cmd = VIDIOC_S_EXT_CTRLS; break;
  778. case VIDIOC_TRY_EXT_CTRLS32: cmd = VIDIOC_TRY_EXT_CTRLS; break;
  779. case VIDIOC_DQEVENT32: cmd = VIDIOC_DQEVENT; break;
  780. case VIDIOC_OVERLAY32: cmd = VIDIOC_OVERLAY; break;
  781. case VIDIOC_STREAMON32: cmd = VIDIOC_STREAMON; break;
  782. case VIDIOC_STREAMOFF32: cmd = VIDIOC_STREAMOFF; break;
  783. case VIDIOC_G_INPUT32: cmd = VIDIOC_G_INPUT; break;
  784. case VIDIOC_S_INPUT32: cmd = VIDIOC_S_INPUT; break;
  785. case VIDIOC_G_OUTPUT32: cmd = VIDIOC_G_OUTPUT; break;
  786. case VIDIOC_S_OUTPUT32: cmd = VIDIOC_S_OUTPUT; break;
  787. case VIDIOC_CREATE_BUFS32: cmd = VIDIOC_CREATE_BUFS; break;
  788. case VIDIOC_PREPARE_BUF32: cmd = VIDIOC_PREPARE_BUF; break;
  789. case VIDIOC_G_EDID32: cmd = VIDIOC_G_EDID; break;
  790. case VIDIOC_S_EDID32: cmd = VIDIOC_S_EDID; break;
  791. }
  792. switch (cmd) {
  793. case VIDIOC_OVERLAY:
  794. case VIDIOC_STREAMON:
  795. case VIDIOC_STREAMOFF:
  796. case VIDIOC_S_INPUT:
  797. case VIDIOC_S_OUTPUT:
  798. err = get_user(karg.vi, (s32 __user *)up);
  799. compatible_arg = 0;
  800. break;
  801. case VIDIOC_G_INPUT:
  802. case VIDIOC_G_OUTPUT:
  803. compatible_arg = 0;
  804. break;
  805. case VIDIOC_G_EDID:
  806. case VIDIOC_S_EDID:
  807. err = get_v4l2_edid32(&karg.v2edid, up);
  808. compatible_arg = 0;
  809. break;
  810. case VIDIOC_G_FMT:
  811. case VIDIOC_S_FMT:
  812. case VIDIOC_TRY_FMT:
  813. err = get_v4l2_format32(&karg.v2f, up);
  814. compatible_arg = 0;
  815. break;
  816. case VIDIOC_CREATE_BUFS:
  817. err = get_v4l2_create32(&karg.v2crt, up);
  818. compatible_arg = 0;
  819. break;
  820. case VIDIOC_PREPARE_BUF:
  821. case VIDIOC_QUERYBUF:
  822. case VIDIOC_QBUF:
  823. case VIDIOC_DQBUF:
  824. err = get_v4l2_buffer32(&karg.v2b, up);
  825. compatible_arg = 0;
  826. break;
  827. case VIDIOC_S_FBUF:
  828. err = get_v4l2_framebuffer32(&karg.v2fb, up);
  829. compatible_arg = 0;
  830. break;
  831. case VIDIOC_G_FBUF:
  832. compatible_arg = 0;
  833. break;
  834. case VIDIOC_ENUMSTD:
  835. err = get_v4l2_standard32(&karg.v2s, up);
  836. compatible_arg = 0;
  837. break;
  838. case VIDIOC_ENUMINPUT:
  839. err = get_v4l2_input32(&karg.v2i, up);
  840. compatible_arg = 0;
  841. break;
  842. case VIDIOC_G_EXT_CTRLS:
  843. case VIDIOC_S_EXT_CTRLS:
  844. case VIDIOC_TRY_EXT_CTRLS:
  845. err = get_v4l2_ext_controls32(file, &karg.v2ecs, up);
  846. compatible_arg = 0;
  847. break;
  848. case VIDIOC_DQEVENT:
  849. compatible_arg = 0;
  850. break;
  851. }
  852. if (err)
  853. return err;
  854. if (compatible_arg)
  855. err = native_ioctl(file, cmd, (unsigned long)up);
  856. else {
  857. mm_segment_t old_fs = get_fs();
  858. set_fs(KERNEL_DS);
  859. err = native_ioctl(file, cmd, (unsigned long)&karg);
  860. set_fs(old_fs);
  861. }
  862. if (err == -ENOTTY)
  863. return err;
  864. /* Special case: even after an error we need to put the
  865. results back for these ioctls since the error_idx will
  866. contain information on which control failed. */
  867. switch (cmd) {
  868. case VIDIOC_G_EXT_CTRLS:
  869. case VIDIOC_S_EXT_CTRLS:
  870. case VIDIOC_TRY_EXT_CTRLS:
  871. if (put_v4l2_ext_controls32(file, &karg.v2ecs, up))
  872. err = -EFAULT;
  873. break;
  874. case VIDIOC_S_EDID:
  875. if (put_v4l2_edid32(&karg.v2edid, up))
  876. err = -EFAULT;
  877. break;
  878. }
  879. if (err)
  880. return err;
  881. switch (cmd) {
  882. case VIDIOC_S_INPUT:
  883. case VIDIOC_S_OUTPUT:
  884. case VIDIOC_G_INPUT:
  885. case VIDIOC_G_OUTPUT:
  886. err = put_user(((s32)karg.vi), (s32 __user *)up);
  887. break;
  888. case VIDIOC_G_FBUF:
  889. err = put_v4l2_framebuffer32(&karg.v2fb, up);
  890. break;
  891. case VIDIOC_DQEVENT:
  892. err = put_v4l2_event32(&karg.v2ev, up);
  893. break;
  894. case VIDIOC_G_EDID:
  895. err = put_v4l2_edid32(&karg.v2edid, up);
  896. break;
  897. case VIDIOC_G_FMT:
  898. case VIDIOC_S_FMT:
  899. case VIDIOC_TRY_FMT:
  900. err = put_v4l2_format32(&karg.v2f, up);
  901. break;
  902. case VIDIOC_CREATE_BUFS:
  903. err = put_v4l2_create32(&karg.v2crt, up);
  904. break;
  905. case VIDIOC_PREPARE_BUF:
  906. case VIDIOC_QUERYBUF:
  907. case VIDIOC_QBUF:
  908. case VIDIOC_DQBUF:
  909. err = put_v4l2_buffer32(&karg.v2b, up);
  910. break;
  911. case VIDIOC_ENUMSTD:
  912. err = put_v4l2_standard32(&karg.v2s, up);
  913. break;
  914. case VIDIOC_ENUMINPUT:
  915. err = put_v4l2_input32(&karg.v2i, up);
  916. break;
  917. }
  918. return err;
  919. }
  920. long v4l2_compat_ioctl32(struct file *file, unsigned int cmd, unsigned long arg)
  921. {
  922. struct video_device *vdev = video_devdata(file);
  923. long ret = -ENOIOCTLCMD;
  924. if (!file->f_op->unlocked_ioctl)
  925. return ret;
  926. if (_IOC_TYPE(cmd) == 'V' && _IOC_NR(cmd) < BASE_VIDIOC_PRIVATE)
  927. ret = do_video_ioctl(file, cmd, arg);
  928. else if (vdev->fops->compat_ioctl32)
  929. ret = vdev->fops->compat_ioctl32(file, cmd, arg);
  930. if (ret == -ENOIOCTLCMD)
  931. pr_debug("compat_ioctl32: unknown ioctl '%c', dir=%d, #%d (0x%08x)\n",
  932. _IOC_TYPE(cmd), _IOC_DIR(cmd), _IOC_NR(cmd), cmd);
  933. return ret;
  934. }
  935. EXPORT_SYMBOL_GPL(v4l2_compat_ioctl32);