[IA64] SN2: security hole in sn2_ptc_proc_write
[linux-2.6/linux-2.6-openrd.git] / ipc / compat_mq.c
blobd8d1e9ff4e8869ba1c9ebe6300f37dec6c62e89b
1 /*
2 * ipc/compat_mq.c
3 * 32 bit emulation for POSIX message queue system calls
5 * Copyright (C) 2004 IBM Deutschland Entwicklung GmbH, IBM Corporation
6 * Author: Arnd Bergmann <arnd@arndb.de>
7 */
9 #include <linux/compat.h>
10 #include <linux/fs.h>
11 #include <linux/kernel.h>
12 #include <linux/mqueue.h>
13 #include <linux/syscalls.h>
15 #include <asm/uaccess.h>
17 struct compat_mq_attr {
18 compat_long_t mq_flags; /* message queue flags */
19 compat_long_t mq_maxmsg; /* maximum number of messages */
20 compat_long_t mq_msgsize; /* maximum message size */
21 compat_long_t mq_curmsgs; /* number of messages currently queued */
22 compat_long_t __reserved[4]; /* ignored for input, zeroed for output */
25 static inline int get_compat_mq_attr(struct mq_attr *attr,
26 const struct compat_mq_attr __user *uattr)
28 if (!access_ok(VERIFY_READ, uattr, sizeof *uattr))
29 return -EFAULT;
31 return __get_user(attr->mq_flags, &uattr->mq_flags)
32 | __get_user(attr->mq_maxmsg, &uattr->mq_maxmsg)
33 | __get_user(attr->mq_msgsize, &uattr->mq_msgsize)
34 | __get_user(attr->mq_curmsgs, &uattr->mq_curmsgs);
37 static inline int put_compat_mq_attr(const struct mq_attr *attr,
38 struct compat_mq_attr __user *uattr)
40 if (clear_user(uattr, sizeof *uattr))
41 return -EFAULT;
43 return __put_user(attr->mq_flags, &uattr->mq_flags)
44 | __put_user(attr->mq_maxmsg, &uattr->mq_maxmsg)
45 | __put_user(attr->mq_msgsize, &uattr->mq_msgsize)
46 | __put_user(attr->mq_curmsgs, &uattr->mq_curmsgs);
49 asmlinkage long compat_sys_mq_open(const char __user *u_name,
50 int oflag, compat_mode_t mode,
51 struct compat_mq_attr __user *u_attr)
53 void __user *p = NULL;
54 if (u_attr && oflag & O_CREAT) {
55 struct mq_attr attr;
56 p = compat_alloc_user_space(sizeof(attr));
57 if (get_compat_mq_attr(&attr, u_attr) ||
58 copy_to_user(p, &attr, sizeof(attr)))
59 return -EFAULT;
61 return sys_mq_open(u_name, oflag, mode, p);
64 static int compat_prepare_timeout(struct timespec __user * *p,
65 const struct compat_timespec __user *u)
67 struct timespec ts;
68 if (!u) {
69 *p = NULL;
70 return 0;
72 *p = compat_alloc_user_space(sizeof(ts));
73 if (get_compat_timespec(&ts, u) || copy_to_user(*p, &ts, sizeof(ts)))
74 return -EFAULT;
75 return 0;
78 asmlinkage long compat_sys_mq_timedsend(mqd_t mqdes,
79 const char __user *u_msg_ptr,
80 size_t msg_len, unsigned int msg_prio,
81 const struct compat_timespec __user *u_abs_timeout)
83 struct timespec __user *u_ts;
85 if (compat_prepare_timeout(&u_ts, u_abs_timeout))
86 return -EFAULT;
88 return sys_mq_timedsend(mqdes, u_msg_ptr, msg_len,
89 msg_prio, u_ts);
92 asmlinkage ssize_t compat_sys_mq_timedreceive(mqd_t mqdes,
93 char __user *u_msg_ptr,
94 size_t msg_len, unsigned int __user *u_msg_prio,
95 const struct compat_timespec __user *u_abs_timeout)
97 struct timespec __user *u_ts;
98 if (compat_prepare_timeout(&u_ts, u_abs_timeout))
99 return -EFAULT;
101 return sys_mq_timedreceive(mqdes, u_msg_ptr, msg_len,
102 u_msg_prio, u_ts);
105 asmlinkage long compat_sys_mq_notify(mqd_t mqdes,
106 const struct compat_sigevent __user *u_notification)
108 struct sigevent __user *p = NULL;
109 if (u_notification) {
110 struct sigevent n;
111 p = compat_alloc_user_space(sizeof(*p));
112 if (get_compat_sigevent(&n, u_notification))
113 return -EFAULT;
114 if (n.sigev_notify == SIGEV_THREAD)
115 n.sigev_value.sival_ptr = compat_ptr(n.sigev_value.sival_int);
116 if (copy_to_user(p, &n, sizeof(*p)))
117 return -EFAULT;
119 return sys_mq_notify(mqdes, p);
122 asmlinkage long compat_sys_mq_getsetattr(mqd_t mqdes,
123 const struct compat_mq_attr __user *u_mqstat,
124 struct compat_mq_attr __user *u_omqstat)
126 struct mq_attr mqstat;
127 struct mq_attr __user *p = compat_alloc_user_space(2 * sizeof(*p));
128 long ret;
130 if (u_mqstat) {
131 if (get_compat_mq_attr(&mqstat, u_mqstat) ||
132 copy_to_user(p, &mqstat, sizeof(mqstat)))
133 return -EFAULT;
135 ret = sys_mq_getsetattr(mqdes,
136 u_mqstat ? p : NULL,
137 u_omqstat ? p + 1 : NULL);
138 if (ret)
139 return ret;
140 if (u_omqstat) {
141 if (copy_from_user(&mqstat, p + 1, sizeof(mqstat)) ||
142 put_compat_mq_attr(&mqstat, u_omqstat))
143 return -EFAULT;
145 return 0;