blob: e65593742e2be5965f45929d485b54e8707f6d0d [file] [log] [blame]
rjw1f884582022-01-06 17:20:42 +08001/*
2 * linux/ipc/msgutil.c
3 * Copyright (C) 1999, 2004 Manfred Spraul
4 *
5 * This file is released under GNU General Public Licence version 2 or
6 * (at your option) any later version.
7 *
8 * See the file COPYING for more details.
9 */
10
11#include <linux/spinlock.h>
12#include <linux/init.h>
13#include <linux/security.h>
14#include <linux/slab.h>
15#include <linux/ipc.h>
16#include <linux/msg.h>
17#include <linux/ipc_namespace.h>
18#include <linux/utsname.h>
19#include <linux/proc_ns.h>
20#include <linux/uaccess.h>
21#include <linux/sched.h>
22
23#include "util.h"
24
25DEFINE_SPINLOCK(mq_lock);
26
27/*
28 * The next 2 defines are here bc this is the only file
29 * compiled when either CONFIG_SYSVIPC and CONFIG_POSIX_MQUEUE
30 * and not CONFIG_IPC_NS.
31 */
32struct ipc_namespace init_ipc_ns = {
33 .count = REFCOUNT_INIT(1),
34 .user_ns = &init_user_ns,
35 .ns.inum = PROC_IPC_INIT_INO,
36#ifdef CONFIG_IPC_NS
37 .ns.ops = &ipcns_operations,
38#endif
39};
40
41struct msg_msgseg {
42 struct msg_msgseg *next;
43 /* the next part of the message follows immediately */
44};
45
46#define DATALEN_MSG ((size_t)PAGE_SIZE-sizeof(struct msg_msg))
47#define DATALEN_SEG ((size_t)PAGE_SIZE-sizeof(struct msg_msgseg))
48
49
50static struct msg_msg *alloc_msg(size_t len)
51{
52 struct msg_msg *msg;
53 struct msg_msgseg **pseg;
54 size_t alen;
55
56 alen = min(len, DATALEN_MSG);
57 msg = kmalloc(sizeof(*msg) + alen, GFP_KERNEL_ACCOUNT);
58 if (msg == NULL)
59 return NULL;
60
61 msg->next = NULL;
62 msg->security = NULL;
63
64 len -= alen;
65 pseg = &msg->next;
66 while (len > 0) {
67 struct msg_msgseg *seg;
68
69 cond_resched();
70
71 alen = min(len, DATALEN_SEG);
72 seg = kmalloc(sizeof(*seg) + alen, GFP_KERNEL_ACCOUNT);
73 if (seg == NULL)
74 goto out_err;
75 *pseg = seg;
76 seg->next = NULL;
77 pseg = &seg->next;
78 len -= alen;
79 }
80
81 return msg;
82
83out_err:
84 free_msg(msg);
85 return NULL;
86}
87
88struct msg_msg *load_msg(const void __user *src, size_t len)
89{
90 struct msg_msg *msg;
91 struct msg_msgseg *seg;
92 int err = -EFAULT;
93 size_t alen;
94
95 msg = alloc_msg(len);
96 if (msg == NULL)
97 return ERR_PTR(-ENOMEM);
98
99 alen = min(len, DATALEN_MSG);
100 if (copy_from_user(msg + 1, src, alen))
101 goto out_err;
102
103 for (seg = msg->next; seg != NULL; seg = seg->next) {
104 len -= alen;
105 src = (char __user *)src + alen;
106 alen = min(len, DATALEN_SEG);
107 if (copy_from_user(seg + 1, src, alen))
108 goto out_err;
109 }
110
111 err = security_msg_msg_alloc(msg);
112 if (err)
113 goto out_err;
114
115 return msg;
116
117out_err:
118 free_msg(msg);
119 return ERR_PTR(err);
120}
121#ifdef CONFIG_CHECKPOINT_RESTORE
122struct msg_msg *copy_msg(struct msg_msg *src, struct msg_msg *dst)
123{
124 struct msg_msgseg *dst_pseg, *src_pseg;
125 size_t len = src->m_ts;
126 size_t alen;
127
128 if (src->m_ts > dst->m_ts)
129 return ERR_PTR(-EINVAL);
130
131 alen = min(len, DATALEN_MSG);
132 memcpy(dst + 1, src + 1, alen);
133
134 for (dst_pseg = dst->next, src_pseg = src->next;
135 src_pseg != NULL;
136 dst_pseg = dst_pseg->next, src_pseg = src_pseg->next) {
137
138 len -= alen;
139 alen = min(len, DATALEN_SEG);
140 memcpy(dst_pseg + 1, src_pseg + 1, alen);
141 }
142
143 dst->m_type = src->m_type;
144 dst->m_ts = src->m_ts;
145
146 return dst;
147}
148#else
149struct msg_msg *copy_msg(struct msg_msg *src, struct msg_msg *dst)
150{
151 return ERR_PTR(-ENOSYS);
152}
153#endif
154int store_msg(void __user *dest, struct msg_msg *msg, size_t len)
155{
156 size_t alen;
157 struct msg_msgseg *seg;
158
159 alen = min(len, DATALEN_MSG);
160 if (copy_to_user(dest, msg + 1, alen))
161 return -1;
162
163 for (seg = msg->next; seg != NULL; seg = seg->next) {
164 len -= alen;
165 dest = (char __user *)dest + alen;
166 alen = min(len, DATALEN_SEG);
167 if (copy_to_user(dest, seg + 1, alen))
168 return -1;
169 }
170 return 0;
171}
172
173void free_msg(struct msg_msg *msg)
174{
175 struct msg_msgseg *seg;
176
177 security_msg_msg_free(msg);
178
179 seg = msg->next;
180 kfree(msg);
181 while (seg != NULL) {
182 struct msg_msgseg *tmp = seg->next;
183
184 cond_resched();
185 kfree(seg);
186 seg = tmp;
187 }
188}