v4l2-compat-ioctl32.c 29.2 KB
Newer Older
1 2 3 4 5 6 7
/*
 * ioctl32.c: Conversion between 32bit and 64bit native ioctls.
 *	Separated from fs stuff by Arnd Bergmann <arnd@arndb.de>
 *
 * Copyright (C) 1997-2000  Jakub Jelinek  (jakub@redhat.com)
 * Copyright (C) 1998  Eddie C. Dost  (ecd@skynet.be)
 * Copyright (C) 2001,2002  Andi Kleen, SuSE Labs
P
Pavel Machek 已提交
8
 * Copyright (C) 2003       Pavel Machek (pavel@ucw.cz)
9
 * Copyright (C) 2005       Philippe De Muyter (phdm@macqel.be)
10
 * Copyright (C) 2008       Hans Verkuil <hverkuil@xs4all.nl>
11 12 13 14 15
 *
 * These routines maintain argument size conversion between 32bit and 64bit
 * ioctls.
 */

16
#include <linux/compat.h>
17
#include <linux/module.h>
18
#include <linux/videodev2.h>
19
#include <linux/v4l2-subdev.h>
20
#include <media/v4l2-dev.h>
21
#include <media/v4l2-ioctl.h>
22

23
static long native_ioctl(struct file *file, unsigned int cmd, unsigned long arg)
24
{
25
	long ret = -ENOIOCTLCMD;
26 27 28 29 30 31 32 33

	if (file->f_op->unlocked_ioctl)
		ret = file->f_op->unlocked_ioctl(file, cmd, arg);

	return ret;
}


34
struct v4l2_clip32 {
35 36 37 38
	struct v4l2_rect        c;
	compat_caddr_t 		next;
};

39
struct v4l2_window32 {
40
	struct v4l2_rect        w;
41
	__u32		  	field;	/* enum v4l2_field */
42 43 44 45 46 47 48 49
	__u32			chromakey;
	compat_caddr_t		clips; /* actually struct v4l2_clip32 * */
	__u32			clipcount;
	compat_caddr_t		bitmap;
};

static int get_v4l2_window32(struct v4l2_window *kp, struct v4l2_window32 __user *up)
{
50 51 52 53 54 55
	if (!access_ok(VERIFY_READ, up, sizeof(struct v4l2_window32)) ||
		copy_from_user(&kp->w, &up->w, sizeof(up->w)) ||
		get_user(kp->field, &up->field) ||
		get_user(kp->chromakey, &up->chromakey) ||
		get_user(kp->clipcount, &up->clipcount))
			return -EFAULT;
56 57 58
	if (kp->clipcount > 2048)
		return -EINVAL;
	if (kp->clipcount) {
59 60
		struct v4l2_clip32 __user *uclips;
		struct v4l2_clip __user *kclips;
61
		int n = kp->clipcount;
62
		compat_caddr_t p;
63

64 65 66
		if (get_user(p, &up->clips))
			return -EFAULT;
		uclips = compat_ptr(p);
67 68 69
		kclips = compat_alloc_user_space(n * sizeof(struct v4l2_clip));
		kp->clips = kclips;
		while (--n >= 0) {
70 71 72
			if (copy_in_user(&kclips->c, &uclips->c, sizeof(uclips->c)))
				return -EFAULT;
			if (put_user(n ? kclips + 1 : NULL, &kclips->next))
73
				return -EFAULT;
74 75 76 77
			uclips += 1;
			kclips += 1;
		}
	} else
78
		kp->clips = NULL;
79 80 81 82 83
	return 0;
}

static int put_v4l2_window32(struct v4l2_window *kp, struct v4l2_window32 __user *up)
{
84
	if (copy_to_user(&up->w, &kp->w, sizeof(kp->w)) ||
85 86 87 88
		put_user(kp->field, &up->field) ||
		put_user(kp->chromakey, &up->chromakey) ||
		put_user(kp->clipcount, &up->clipcount))
			return -EFAULT;
89 90 91 92 93
	return 0;
}

static inline int get_v4l2_pix_format(struct v4l2_pix_format *kp, struct v4l2_pix_format __user *up)
{
94 95
	if (copy_from_user(kp, up, sizeof(struct v4l2_pix_format)))
		return -EFAULT;
96
	return 0;
97 98
}

99 100 101 102 103 104 105 106
static inline int get_v4l2_pix_format_mplane(struct v4l2_pix_format_mplane *kp,
				struct v4l2_pix_format_mplane __user *up)
{
	if (copy_from_user(kp, up, sizeof(struct v4l2_pix_format_mplane)))
		return -EFAULT;
	return 0;
}

107 108
static inline int put_v4l2_pix_format(struct v4l2_pix_format *kp, struct v4l2_pix_format __user *up)
{
109 110
	if (copy_to_user(up, kp, sizeof(struct v4l2_pix_format)))
		return -EFAULT;
111
	return 0;
112 113
}

114 115 116 117 118 119 120 121
static inline int put_v4l2_pix_format_mplane(struct v4l2_pix_format_mplane *kp,
				struct v4l2_pix_format_mplane __user *up)
{
	if (copy_to_user(up, kp, sizeof(struct v4l2_pix_format_mplane)))
		return -EFAULT;
	return 0;
}

122 123
static inline int get_v4l2_vbi_format(struct v4l2_vbi_format *kp, struct v4l2_vbi_format __user *up)
{
124 125
	if (copy_from_user(kp, up, sizeof(struct v4l2_vbi_format)))
		return -EFAULT;
126
	return 0;
127 128 129 130
}

static inline int put_v4l2_vbi_format(struct v4l2_vbi_format *kp, struct v4l2_vbi_format __user *up)
{
131 132
	if (copy_to_user(up, kp, sizeof(struct v4l2_vbi_format)))
		return -EFAULT;
133
	return 0;
134 135
}

136 137 138 139 140 141 142 143 144 145 146 147 148 149
static inline int get_v4l2_sliced_vbi_format(struct v4l2_sliced_vbi_format *kp, struct v4l2_sliced_vbi_format __user *up)
{
	if (copy_from_user(kp, up, sizeof(struct v4l2_sliced_vbi_format)))
		return -EFAULT;
	return 0;
}

static inline int put_v4l2_sliced_vbi_format(struct v4l2_sliced_vbi_format *kp, struct v4l2_sliced_vbi_format __user *up)
{
	if (copy_to_user(up, kp, sizeof(struct v4l2_sliced_vbi_format)))
		return -EFAULT;
	return 0;
}

150 151 152 153 154 155 156 157 158 159 160 161 162 163
static inline int get_v4l2_sdr_format(struct v4l2_sdr_format *kp, struct v4l2_sdr_format __user *up)
{
	if (copy_from_user(kp, up, sizeof(struct v4l2_sdr_format)))
		return -EFAULT;
	return 0;
}

static inline int put_v4l2_sdr_format(struct v4l2_sdr_format *kp, struct v4l2_sdr_format __user *up)
{
	if (copy_to_user(up, kp, sizeof(struct v4l2_sdr_format)))
		return -EFAULT;
	return 0;
}

164
struct v4l2_format32 {
165
	__u32	type;	/* enum v4l2_buf_type */
166
	union {
167
		struct v4l2_pix_format	pix;
168
		struct v4l2_pix_format_mplane	pix_mp;
169 170 171
		struct v4l2_window32	win;
		struct v4l2_vbi_format	vbi;
		struct v4l2_sliced_vbi_format	sliced;
172
		struct v4l2_sdr_format	sdr;
173
		__u8	raw_data[200];        /* user-defined */
174 175 176
	} fmt;
};

177 178 179 180 181 182 183 184 185
/**
 * struct v4l2_create_buffers32 - VIDIOC_CREATE_BUFS32 argument
 * @index:	on return, index of the first created buffer
 * @count:	entry: number of requested buffers,
 *		return: number of created buffers
 * @memory:	buffer memory type
 * @format:	frame format, for which buffers are requested
 * @reserved:	future extensions
 */
186
struct v4l2_create_buffers32 {
187
	__u32			index;
188
	__u32			count;
189
	__u32			memory;	/* enum v4l2_memory */
190
	struct v4l2_format32	format;
191 192 193 194
	__u32			reserved[8];
};

static int __get_v4l2_format32(struct v4l2_format *kp, struct v4l2_format32 __user *up)
195
{
196 197 198
	if (get_user(kp->type, &up->type))
		return -EFAULT;

199 200
	switch (kp->type) {
	case V4L2_BUF_TYPE_VIDEO_CAPTURE:
201
	case V4L2_BUF_TYPE_VIDEO_OUTPUT:
202
		return get_v4l2_pix_format(&kp->fmt.pix, &up->fmt.pix);
203 204 205 206
	case V4L2_BUF_TYPE_VIDEO_CAPTURE_MPLANE:
	case V4L2_BUF_TYPE_VIDEO_OUTPUT_MPLANE:
		return get_v4l2_pix_format_mplane(&kp->fmt.pix_mp,
						  &up->fmt.pix_mp);
207
	case V4L2_BUF_TYPE_VIDEO_OVERLAY:
208
	case V4L2_BUF_TYPE_VIDEO_OUTPUT_OVERLAY:
209 210
		return get_v4l2_window32(&kp->fmt.win, &up->fmt.win);
	case V4L2_BUF_TYPE_VBI_CAPTURE:
211
	case V4L2_BUF_TYPE_VBI_OUTPUT:
212
		return get_v4l2_vbi_format(&kp->fmt.vbi, &up->fmt.vbi);
213 214 215
	case V4L2_BUF_TYPE_SLICED_VBI_CAPTURE:
	case V4L2_BUF_TYPE_SLICED_VBI_OUTPUT:
		return get_v4l2_sliced_vbi_format(&kp->fmt.sliced, &up->fmt.sliced);
216
	case V4L2_BUF_TYPE_SDR_CAPTURE:
217
	case V4L2_BUF_TYPE_SDR_OUTPUT:
218
		return get_v4l2_sdr_format(&kp->fmt.sdr, &up->fmt.sdr);
219
	default:
220
		pr_info("compat_ioctl32: unexpected VIDIOC_FMT type %d\n",
221
								kp->type);
222
		return -EINVAL;
223 224 225
	}
}

226 227
static int get_v4l2_format32(struct v4l2_format *kp, struct v4l2_format32 __user *up)
{
228 229
	if (!access_ok(VERIFY_READ, up, sizeof(struct v4l2_format32)))
		return -EFAULT;
230 231 232 233 234 235
	return __get_v4l2_format32(kp, up);
}

static int get_v4l2_create32(struct v4l2_create_buffers *kp, struct v4l2_create_buffers32 __user *up)
{
	if (!access_ok(VERIFY_READ, up, sizeof(struct v4l2_create_buffers32)) ||
236 237
	    copy_from_user(kp, up, offsetof(struct v4l2_create_buffers32, format)))
		return -EFAULT;
238 239 240 241
	return __get_v4l2_format32(&kp->format, &up->format);
}

static int __put_v4l2_format32(struct v4l2_format *kp, struct v4l2_format32 __user *up)
242
{
243 244 245
	if (put_user(kp->type, &up->type))
		return -EFAULT;

246 247
	switch (kp->type) {
	case V4L2_BUF_TYPE_VIDEO_CAPTURE:
248
	case V4L2_BUF_TYPE_VIDEO_OUTPUT:
249
		return put_v4l2_pix_format(&kp->fmt.pix, &up->fmt.pix);
250 251 252 253
	case V4L2_BUF_TYPE_VIDEO_CAPTURE_MPLANE:
	case V4L2_BUF_TYPE_VIDEO_OUTPUT_MPLANE:
		return put_v4l2_pix_format_mplane(&kp->fmt.pix_mp,
						  &up->fmt.pix_mp);
254
	case V4L2_BUF_TYPE_VIDEO_OVERLAY:
255
	case V4L2_BUF_TYPE_VIDEO_OUTPUT_OVERLAY:
256 257
		return put_v4l2_window32(&kp->fmt.win, &up->fmt.win);
	case V4L2_BUF_TYPE_VBI_CAPTURE:
258
	case V4L2_BUF_TYPE_VBI_OUTPUT:
259
		return put_v4l2_vbi_format(&kp->fmt.vbi, &up->fmt.vbi);
260 261 262
	case V4L2_BUF_TYPE_SLICED_VBI_CAPTURE:
	case V4L2_BUF_TYPE_SLICED_VBI_OUTPUT:
		return put_v4l2_sliced_vbi_format(&kp->fmt.sliced, &up->fmt.sliced);
263
	case V4L2_BUF_TYPE_SDR_CAPTURE:
264
	case V4L2_BUF_TYPE_SDR_OUTPUT:
265
		return put_v4l2_sdr_format(&kp->fmt.sdr, &up->fmt.sdr);
266
	default:
267
		pr_info("compat_ioctl32: unexpected VIDIOC_FMT type %d\n",
268 269
								kp->type);
		return -EINVAL;
270 271 272
	}
}

273 274
static int put_v4l2_format32(struct v4l2_format *kp, struct v4l2_format32 __user *up)
{
275
	if (!access_ok(VERIFY_WRITE, up, sizeof(struct v4l2_format32)))
276 277 278 279 280 281 282
		return -EFAULT;
	return __put_v4l2_format32(kp, up);
}

static int put_v4l2_create32(struct v4l2_create_buffers *kp, struct v4l2_create_buffers32 __user *up)
{
	if (!access_ok(VERIFY_WRITE, up, sizeof(struct v4l2_create_buffers32)) ||
283 284
	    copy_to_user(up, kp, offsetof(struct v4l2_create_buffers32, format)) ||
	    copy_to_user(up->reserved, kp->reserved, sizeof(kp->reserved)))
285
		return -EFAULT;
286 287 288
	return __put_v4l2_format32(&kp->format, &up->format);
}

289
struct v4l2_standard32 {
290
	__u32		     index;
291
	compat_u64	     id;
292 293 294 295 296 297 298 299 300
	__u8		     name[24];
	struct v4l2_fract    frameperiod; /* Frames, not fields */
	__u32		     framelines;
	__u32		     reserved[4];
};

static int get_v4l2_standard32(struct v4l2_standard *kp, struct v4l2_standard32 __user *up)
{
	/* other fields are not set by the user, nor used by the driver */
301 302 303 304
	if (!access_ok(VERIFY_READ, up, sizeof(struct v4l2_standard32)) ||
		get_user(kp->index, &up->index))
		return -EFAULT;
	return 0;
305 306 307 308
}

static int put_v4l2_standard32(struct v4l2_standard *kp, struct v4l2_standard32 __user *up)
{
309
	if (!access_ok(VERIFY_WRITE, up, sizeof(struct v4l2_standard32)) ||
310
		put_user(kp->index, &up->index) ||
311
		put_user(kp->id, &up->id) ||
312 313 314 315 316 317 318 319
		copy_to_user(up->name, kp->name, 24) ||
		copy_to_user(&up->frameperiod, &kp->frameperiod, sizeof(kp->frameperiod)) ||
		put_user(kp->framelines, &up->framelines) ||
		copy_to_user(up->reserved, kp->reserved, 4 * sizeof(__u32)))
			return -EFAULT;
	return 0;
}

320 321 322 323 324 325
struct v4l2_plane32 {
	__u32			bytesused;
	__u32			length;
	union {
		__u32		mem_offset;
		compat_long_t	userptr;
326
		__s32		fd;
327 328 329 330 331
	} m;
	__u32			data_offset;
	__u32			reserved[11];
};

332
struct v4l2_buffer32 {
333
	__u32			index;
334
	__u32			type;	/* enum v4l2_buf_type */
335 336
	__u32			bytesused;
	__u32			flags;
337
	__u32			field;	/* enum v4l2_field */
338 339 340 341 342
	struct compat_timeval	timestamp;
	struct v4l2_timecode	timecode;
	__u32			sequence;

	/* memory location */
343
	__u32			memory;	/* enum v4l2_memory */
344 345 346
	union {
		__u32           offset;
		compat_long_t   userptr;
347
		compat_caddr_t  planes;
348
		__s32		fd;
349 350
	} m;
	__u32			length;
351
	__u32			reserved2;
352 353 354
	__u32			reserved;
};

355
static int get_v4l2_plane32(struct v4l2_plane __user *up, struct v4l2_plane32 __user *up32,
356 357 358 359 360 361 362 363 364 365 366 367 368 369 370 371
				enum v4l2_memory memory)
{
	void __user *up_pln;
	compat_long_t p;

	if (copy_in_user(up, up32, 2 * sizeof(__u32)) ||
		copy_in_user(&up->data_offset, &up32->data_offset,
				sizeof(__u32)))
		return -EFAULT;

	if (memory == V4L2_MEMORY_USERPTR) {
		if (get_user(p, &up32->m.userptr))
			return -EFAULT;
		up_pln = compat_ptr(p);
		if (put_user((unsigned long)up_pln, &up->m.userptr))
			return -EFAULT;
372 373 374
	} else if (memory == V4L2_MEMORY_DMABUF) {
		if (copy_in_user(&up->m.fd, &up32->m.fd, sizeof(int)))
			return -EFAULT;
375 376 377 378 379 380 381 382 383
	} else {
		if (copy_in_user(&up->m.mem_offset, &up32->m.mem_offset,
					sizeof(__u32)))
			return -EFAULT;
	}

	return 0;
}

384
static int put_v4l2_plane32(struct v4l2_plane __user *up, struct v4l2_plane32 __user *up32,
385 386 387 388 389 390 391 392 393 394 395 396 397
				enum v4l2_memory memory)
{
	if (copy_in_user(up32, up, 2 * sizeof(__u32)) ||
		copy_in_user(&up32->data_offset, &up->data_offset,
				sizeof(__u32)))
		return -EFAULT;

	/* For MMAP, driver might've set up the offset, so copy it back.
	 * USERPTR stays the same (was userspace-provided), so no copying. */
	if (memory == V4L2_MEMORY_MMAP)
		if (copy_in_user(&up32->m.mem_offset, &up->m.mem_offset,
					sizeof(__u32)))
			return -EFAULT;
398 399 400 401 402
	/* For DMABUF, driver might've set up the fd, so copy it back. */
	if (memory == V4L2_MEMORY_DMABUF)
		if (copy_in_user(&up32->m.fd, &up->m.fd,
					sizeof(int)))
			return -EFAULT;
403 404 405 406

	return 0;
}

407 408
static int get_v4l2_buffer32(struct v4l2_buffer *kp, struct v4l2_buffer32 __user *up)
{
409 410 411 412
	struct v4l2_plane32 __user *uplane32;
	struct v4l2_plane __user *uplane;
	compat_caddr_t p;
	int ret;
413

414 415 416 417
	if (!access_ok(VERIFY_READ, up, sizeof(struct v4l2_buffer32)) ||
		get_user(kp->index, &up->index) ||
		get_user(kp->type, &up->type) ||
		get_user(kp->flags, &up->flags) ||
418 419
		get_user(kp->memory, &up->memory) ||
		get_user(kp->length, &up->length))
420
			return -EFAULT;
421 422 423 424 425 426 427

	if (V4L2_TYPE_IS_OUTPUT(kp->type))
		if (get_user(kp->bytesused, &up->bytesused) ||
			get_user(kp->field, &up->field) ||
			get_user(kp->timestamp.tv_sec, &up->timestamp.tv_sec) ||
			get_user(kp->timestamp.tv_usec,
					&up->timestamp.tv_usec))
428
			return -EFAULT;
429

430
	if (V4L2_TYPE_IS_MULTIPLANAR(kp->type)) {
431 432 433
		unsigned int num_planes;

		if (kp->length == 0) {
434 435 436 437
			kp->m.planes = NULL;
			/* num_planes == 0 is legal, e.g. when userspace doesn't
			 * need planes array on DQBUF*/
			return 0;
438 439
		} else if (kp->length > VIDEO_MAX_PLANES) {
			return -EINVAL;
440
		}
441 442

		if (get_user(p, &up->m.planes))
443
			return -EFAULT;
444 445 446

		uplane32 = compat_ptr(p);
		if (!access_ok(VERIFY_READ, uplane32,
447
				kp->length * sizeof(struct v4l2_plane32)))
448 449 450 451
			return -EFAULT;

		/* We don't really care if userspace decides to kill itself
		 * by passing a very big num_planes value */
452 453
		uplane = compat_alloc_user_space(kp->length *
						 sizeof(struct v4l2_plane));
454
		kp->m.planes = (__force struct v4l2_plane *)uplane;
455

456
		for (num_planes = 0; num_planes < kp->length; num_planes++) {
457 458 459 460 461 462 463 464 465
			ret = get_v4l2_plane32(uplane, uplane32, kp->memory);
			if (ret)
				return ret;
			++uplane;
			++uplane32;
		}
	} else {
		switch (kp->memory) {
		case V4L2_MEMORY_MMAP:
466
			if (get_user(kp->m.offset, &up->m.offset))
467 468 469 470 471 472
				return -EFAULT;
			break;
		case V4L2_MEMORY_USERPTR:
			{
			compat_long_t tmp;

473
			if (get_user(tmp, &up->m.userptr))
474 475 476 477 478 479 480 481 482
				return -EFAULT;

			kp->m.userptr = (unsigned long)compat_ptr(tmp);
			}
			break;
		case V4L2_MEMORY_OVERLAY:
			if (get_user(kp->m.offset, &up->m.offset))
				return -EFAULT;
			break;
483 484 485 486
		case V4L2_MEMORY_DMABUF:
			if (get_user(kp->m.fd, &up->m.fd))
				return -EFAULT;
			break;
487
		}
488
	}
489

490 491 492 493 494
	return 0;
}

static int put_v4l2_buffer32(struct v4l2_buffer *kp, struct v4l2_buffer32 __user *up)
{
495 496 497 498 499 500
	struct v4l2_plane32 __user *uplane32;
	struct v4l2_plane __user *uplane;
	compat_caddr_t p;
	int num_planes;
	int ret;

501 502 503 504
	if (!access_ok(VERIFY_WRITE, up, sizeof(struct v4l2_buffer32)) ||
		put_user(kp->index, &up->index) ||
		put_user(kp->type, &up->type) ||
		put_user(kp->flags, &up->flags) ||
505
		put_user(kp->memory, &up->memory))
506
			return -EFAULT;
507

508 509 510 511 512 513
	if (put_user(kp->bytesused, &up->bytesused) ||
		put_user(kp->field, &up->field) ||
		put_user(kp->timestamp.tv_sec, &up->timestamp.tv_sec) ||
		put_user(kp->timestamp.tv_usec, &up->timestamp.tv_usec) ||
		copy_to_user(&up->timecode, &kp->timecode, sizeof(struct v4l2_timecode)) ||
		put_user(kp->sequence, &up->sequence) ||
514
		put_user(kp->reserved2, &up->reserved2) ||
515 516
		put_user(kp->reserved, &up->reserved) ||
		put_user(kp->length, &up->length))
517
			return -EFAULT;
518 519 520 521 522 523

	if (V4L2_TYPE_IS_MULTIPLANAR(kp->type)) {
		num_planes = kp->length;
		if (num_planes == 0)
			return 0;

524
		uplane = (__force struct v4l2_plane __user *)kp->m.planes;
525 526 527 528 529 530 531 532 533 534 535 536 537 538
		if (get_user(p, &up->m.planes))
			return -EFAULT;
		uplane32 = compat_ptr(p);

		while (--num_planes >= 0) {
			ret = put_v4l2_plane32(uplane, uplane32, kp->memory);
			if (ret)
				return ret;
			++uplane;
			++uplane32;
		}
	} else {
		switch (kp->memory) {
		case V4L2_MEMORY_MMAP:
539
			if (put_user(kp->m.offset, &up->m.offset))
540 541 542
				return -EFAULT;
			break;
		case V4L2_MEMORY_USERPTR:
543
			if (put_user(kp->m.userptr, &up->m.userptr))
544 545 546 547 548 549
				return -EFAULT;
			break;
		case V4L2_MEMORY_OVERLAY:
			if (put_user(kp->m.offset, &up->m.offset))
				return -EFAULT;
			break;
550 551 552 553
		case V4L2_MEMORY_DMABUF:
			if (put_user(kp->m.fd, &up->m.fd))
				return -EFAULT;
			break;
554 555 556
		}
	}

557 558 559
	return 0;
}

560
struct v4l2_framebuffer32 {
561 562 563
	__u32			capability;
	__u32			flags;
	compat_caddr_t 		base;
564 565 566 567 568 569 570 571 572 573
	struct {
		__u32		width;
		__u32		height;
		__u32		pixelformat;
		__u32		field;
		__u32		bytesperline;
		__u32		sizeimage;
		__u32		colorspace;
		__u32		priv;
	} fmt;
574 575
};

576 577 578 579
static int get_v4l2_framebuffer32(struct v4l2_framebuffer *kp, struct v4l2_framebuffer32 __user *up)
{
	u32 tmp;

580 581 582
	if (!access_ok(VERIFY_READ, up, sizeof(struct v4l2_framebuffer32)) ||
		get_user(tmp, &up->base) ||
		get_user(kp->capability, &up->capability) ||
583 584
		get_user(kp->flags, &up->flags) ||
		copy_from_user(&kp->fmt, &up->fmt, sizeof(up->fmt)))
585
			return -EFAULT;
586
	kp->base = (__force void *)compat_ptr(tmp);
587 588 589
	return 0;
}

590 591 592 593
static int put_v4l2_framebuffer32(struct v4l2_framebuffer *kp, struct v4l2_framebuffer32 __user *up)
{
	u32 tmp = (u32)((unsigned long)kp->base);

594
	if (!access_ok(VERIFY_WRITE, up, sizeof(struct v4l2_framebuffer32)) ||
595 596
		put_user(tmp, &up->base) ||
		put_user(kp->capability, &up->capability) ||
597 598
		put_user(kp->flags, &up->flags) ||
		copy_to_user(&up->fmt, &kp->fmt, sizeof(up->fmt)))
599
			return -EFAULT;
600 601 602
	return 0;
}

603 604 605 606 607 608
struct v4l2_input32 {
	__u32	     index;		/*  Which input */
	__u8	     name[32];		/*  Label */
	__u32	     type;		/*  Type of input */
	__u32	     audioset;		/*  Associated audios (bitfield) */
	__u32        tuner;             /*  Associated tuner */
609
	compat_u64   std;
610 611
	__u32	     status;
	__u32	     reserved[4];
612
};
613 614 615 616

/* The 64-bit v4l2_input struct has extra padding at the end of the struct.
   Otherwise it is identical to the 32-bit version. */
static inline int get_v4l2_input32(struct v4l2_input *kp, struct v4l2_input32 __user *up)
617
{
618
	if (copy_from_user(kp, up, sizeof(struct v4l2_input32)))
619
		return -EFAULT;
620 621 622
	return 0;
}

623
static inline int put_v4l2_input32(struct v4l2_input *kp, struct v4l2_input32 __user *up)
624
{
625
	if (copy_to_user(up, kp, sizeof(struct v4l2_input32)))
626
		return -EFAULT;
627 628 629
	return 0;
}

630
struct v4l2_ext_controls32 {
631
	__u32 which;
632 633 634 635
	__u32 count;
	__u32 error_idx;
	__u32 reserved[2];
	compat_caddr_t controls; /* actually struct v4l2_ext_control32 * */
636 637
};

638 639 640 641 642 643 644 645 646 647 648 649 650 651 652 653
struct v4l2_ext_control32 {
	__u32 id;
	__u32 size;
	__u32 reserved2[1];
	union {
		__s32 value;
		__s64 value64;
		compat_caddr_t string; /* actually char * */
	};
} __attribute__ ((packed));

/* The following function really belong in v4l2-common, but that causes
   a circular dependency between modules. We need to think about this, but
   for now this will do. */

/* Return non-zero if this control is a pointer type. Currently only
654
   type STRING is a pointer type. */
655 656
static inline int ctrl_is_pointer(u32 id)
{
657 658 659 660 661 662 663
	switch (id) {
	case V4L2_CID_RDS_TX_PS_NAME:
	case V4L2_CID_RDS_TX_RADIO_TEXT:
		return 1;
	default:
		return 0;
	}
664 665
}

666
static int get_v4l2_ext_controls32(struct v4l2_ext_controls *kp, struct v4l2_ext_controls32 __user *up)
667
{
668
	struct v4l2_ext_control32 __user *ucontrols;
669
	struct v4l2_ext_control __user *kcontrols;
670
	unsigned int n;
671 672 673
	compat_caddr_t p;

	if (!access_ok(VERIFY_READ, up, sizeof(struct v4l2_ext_controls32)) ||
674
		get_user(kp->which, &up->which) ||
675 676
		get_user(kp->count, &up->count) ||
		get_user(kp->error_idx, &up->error_idx) ||
677 678
		copy_from_user(kp->reserved, up->reserved,
			       sizeof(kp->reserved)))
679
			return -EFAULT;
680
	if (kp->count == 0) {
681 682
		kp->controls = NULL;
		return 0;
683 684
	} else if (kp->count > V4L2_CID_MAX_CTRLS) {
		return -EINVAL;
685 686 687 688
	}
	if (get_user(p, &up->controls))
		return -EFAULT;
	ucontrols = compat_ptr(p);
689
	if (!access_ok(VERIFY_READ, ucontrols,
690
			kp->count * sizeof(struct v4l2_ext_control32)))
691
		return -EFAULT;
692 693
	kcontrols = compat_alloc_user_space(kp->count *
					    sizeof(struct v4l2_ext_control));
694
	kp->controls = (__force struct v4l2_ext_control *)kcontrols;
695
	for (n = 0; n < kp->count; n++) {
696 697
		u32 id;

698
		if (copy_in_user(kcontrols, ucontrols, sizeof(*ucontrols)))
699
			return -EFAULT;
700 701 702
		if (get_user(id, &kcontrols->id))
			return -EFAULT;
		if (ctrl_is_pointer(id)) {
703 704 705 706 707 708 709 710
			void __user *s;

			if (get_user(p, &ucontrols->string))
				return -EFAULT;
			s = compat_ptr(p);
			if (put_user(s, &kcontrols->string))
				return -EFAULT;
		}
711 712 713
		ucontrols++;
		kcontrols++;
	}
714 715 716
	return 0;
}

717
static int put_v4l2_ext_controls32(struct v4l2_ext_controls *kp, struct v4l2_ext_controls32 __user *up)
718
{
719
	struct v4l2_ext_control32 __user *ucontrols;
720 721
	struct v4l2_ext_control __user *kcontrols =
		(__force struct v4l2_ext_control __user *)kp->controls;
722 723 724 725
	int n = kp->count;
	compat_caddr_t p;

	if (!access_ok(VERIFY_WRITE, up, sizeof(struct v4l2_ext_controls32)) ||
726
		put_user(kp->which, &up->which) ||
727 728 729 730 731 732
		put_user(kp->count, &up->count) ||
		put_user(kp->error_idx, &up->error_idx) ||
		copy_to_user(up->reserved, kp->reserved, sizeof(up->reserved)))
			return -EFAULT;
	if (!kp->count)
		return 0;
733

734
	if (get_user(p, &up->controls))
735
		return -EFAULT;
736
	ucontrols = compat_ptr(p);
737 738
	if (!access_ok(VERIFY_WRITE, ucontrols,
			n * sizeof(struct v4l2_ext_control32)))
739 740
		return -EFAULT;

741
	while (--n >= 0) {
742
		unsigned size = sizeof(*ucontrols);
743
		u32 id;
744

745 746
		if (get_user(id, &kcontrols->id))
			return -EFAULT;
747 748 749
		/* Do not modify the pointer when copying a pointer control.
		   The contents of the pointer was changed, not the pointer
		   itself. */
750
		if (ctrl_is_pointer(id))
751 752
			size -= sizeof(ucontrols->value64);
		if (copy_in_user(ucontrols, kcontrols, size))
753 754 755
			return -EFAULT;
		ucontrols++;
		kcontrols++;
756
	}
757
	return 0;
758
}
759

760 761 762
struct v4l2_event32 {
	__u32				type;
	union {
763
		compat_s64		value64;
764 765 766 767 768 769 770 771 772 773 774 775 776 777 778 779
		__u8			data[64];
	} u;
	__u32				pending;
	__u32				sequence;
	struct compat_timespec		timestamp;
	__u32				id;
	__u32				reserved[8];
};

static int put_v4l2_event32(struct v4l2_event *kp, struct v4l2_event32 __user *up)
{
	if (!access_ok(VERIFY_WRITE, up, sizeof(struct v4l2_event32)) ||
		put_user(kp->type, &up->type) ||
		copy_to_user(&up->u, &kp->u, sizeof(kp->u)) ||
		put_user(kp->pending, &up->pending) ||
		put_user(kp->sequence, &up->sequence) ||
780
		compat_put_timespec(&kp->timestamp, &up->timestamp) ||
781 782 783 784 785 786
		put_user(kp->id, &up->id) ||
		copy_to_user(up->reserved, kp->reserved, 8 * sizeof(__u32)))
			return -EFAULT;
	return 0;
}

787
struct v4l2_edid32 {
788 789 790 791 792 793 794
	__u32 pad;
	__u32 start_block;
	__u32 blocks;
	__u32 reserved[5];
	compat_caddr_t edid;
};

795
static int get_v4l2_edid32(struct v4l2_edid *kp, struct v4l2_edid32 __user *up)
796 797 798
{
	u32 tmp;

799
	if (!access_ok(VERIFY_READ, up, sizeof(struct v4l2_edid32)) ||
800 801 802 803 804 805
		get_user(kp->pad, &up->pad) ||
		get_user(kp->start_block, &up->start_block) ||
		get_user(kp->blocks, &up->blocks) ||
		get_user(tmp, &up->edid) ||
		copy_from_user(kp->reserved, up->reserved, sizeof(kp->reserved)))
			return -EFAULT;
806
	kp->edid = (__force u8 *)compat_ptr(tmp);
807 808 809
	return 0;
}

810
static int put_v4l2_edid32(struct v4l2_edid *kp, struct v4l2_edid32 __user *up)
811 812 813
{
	u32 tmp = (u32)((unsigned long)kp->edid);

814
	if (!access_ok(VERIFY_WRITE, up, sizeof(struct v4l2_edid32)) ||
815 816 817 818
		put_user(kp->pad, &up->pad) ||
		put_user(kp->start_block, &up->start_block) ||
		put_user(kp->blocks, &up->blocks) ||
		put_user(tmp, &up->edid) ||
819
		copy_to_user(up->reserved, kp->reserved, sizeof(up->reserved)))
820 821 822 823 824
			return -EFAULT;
	return 0;
}


825 826 827 828 829 830 831 832 833
#define VIDIOC_G_FMT32		_IOWR('V',  4, struct v4l2_format32)
#define VIDIOC_S_FMT32		_IOWR('V',  5, struct v4l2_format32)
#define VIDIOC_QUERYBUF32	_IOWR('V',  9, struct v4l2_buffer32)
#define VIDIOC_G_FBUF32		_IOR ('V', 10, struct v4l2_framebuffer32)
#define VIDIOC_S_FBUF32		_IOW ('V', 11, struct v4l2_framebuffer32)
#define VIDIOC_QBUF32		_IOWR('V', 15, struct v4l2_buffer32)
#define VIDIOC_DQBUF32		_IOWR('V', 17, struct v4l2_buffer32)
#define VIDIOC_ENUMSTD32	_IOWR('V', 25, struct v4l2_standard32)
#define VIDIOC_ENUMINPUT32	_IOWR('V', 26, struct v4l2_input32)
834 835
#define VIDIOC_G_EDID32		_IOWR('V', 40, struct v4l2_edid32)
#define VIDIOC_S_EDID32		_IOWR('V', 41, struct v4l2_edid32)
836 837 838 839
#define VIDIOC_TRY_FMT32      	_IOWR('V', 64, struct v4l2_format32)
#define VIDIOC_G_EXT_CTRLS32    _IOWR('V', 71, struct v4l2_ext_controls32)
#define VIDIOC_S_EXT_CTRLS32    _IOWR('V', 72, struct v4l2_ext_controls32)
#define VIDIOC_TRY_EXT_CTRLS32  _IOWR('V', 73, struct v4l2_ext_controls32)
840
#define	VIDIOC_DQEVENT32	_IOR ('V', 89, struct v4l2_event32)
841 842
#define VIDIOC_CREATE_BUFS32	_IOWR('V', 92, struct v4l2_create_buffers32)
#define VIDIOC_PREPARE_BUF32	_IOWR('V', 93, struct v4l2_buffer32)
843 844 845 846 847 848 849 850

#define VIDIOC_OVERLAY32	_IOW ('V', 14, s32)
#define VIDIOC_STREAMON32	_IOW ('V', 18, s32)
#define VIDIOC_STREAMOFF32	_IOW ('V', 19, s32)
#define VIDIOC_G_INPUT32	_IOR ('V', 38, s32)
#define VIDIOC_S_INPUT32	_IOWR('V', 39, s32)
#define VIDIOC_G_OUTPUT32	_IOR ('V', 46, s32)
#define VIDIOC_S_OUTPUT32	_IOWR('V', 47, s32)
851

852
static long do_video_ioctl(struct file *file, unsigned int cmd, unsigned long arg)
853 854
{
	union {
855 856 857
		struct v4l2_format v2f;
		struct v4l2_buffer v2b;
		struct v4l2_framebuffer v2fb;
858
		struct v4l2_input v2i;
859 860
		struct v4l2_standard v2s;
		struct v4l2_ext_controls v2ecs;
861
		struct v4l2_event v2ev;
862
		struct v4l2_create_buffers v2crt;
863
		struct v4l2_edid v2edid;
864
		unsigned long vx;
865
		int vi;
866 867
	} karg;
	void __user *up = compat_ptr(arg);
868
	int compatible_arg = 1;
869
	long err = 0;
870 871

	/* First, convert the command. */
872
	switch (cmd) {
873 874 875 876 877 878 879 880 881 882 883 884 885
	case VIDIOC_G_FMT32: cmd = VIDIOC_G_FMT; break;
	case VIDIOC_S_FMT32: cmd = VIDIOC_S_FMT; break;
	case VIDIOC_QUERYBUF32: cmd = VIDIOC_QUERYBUF; break;
	case VIDIOC_G_FBUF32: cmd = VIDIOC_G_FBUF; break;
	case VIDIOC_S_FBUF32: cmd = VIDIOC_S_FBUF; break;
	case VIDIOC_QBUF32: cmd = VIDIOC_QBUF; break;
	case VIDIOC_DQBUF32: cmd = VIDIOC_DQBUF; break;
	case VIDIOC_ENUMSTD32: cmd = VIDIOC_ENUMSTD; break;
	case VIDIOC_ENUMINPUT32: cmd = VIDIOC_ENUMINPUT; break;
	case VIDIOC_TRY_FMT32: cmd = VIDIOC_TRY_FMT; break;
	case VIDIOC_G_EXT_CTRLS32: cmd = VIDIOC_G_EXT_CTRLS; break;
	case VIDIOC_S_EXT_CTRLS32: cmd = VIDIOC_S_EXT_CTRLS; break;
	case VIDIOC_TRY_EXT_CTRLS32: cmd = VIDIOC_TRY_EXT_CTRLS; break;
886
	case VIDIOC_DQEVENT32: cmd = VIDIOC_DQEVENT; break;
887 888 889 890 891 892 893
	case VIDIOC_OVERLAY32: cmd = VIDIOC_OVERLAY; break;
	case VIDIOC_STREAMON32: cmd = VIDIOC_STREAMON; break;
	case VIDIOC_STREAMOFF32: cmd = VIDIOC_STREAMOFF; break;
	case VIDIOC_G_INPUT32: cmd = VIDIOC_G_INPUT; break;
	case VIDIOC_S_INPUT32: cmd = VIDIOC_S_INPUT; break;
	case VIDIOC_G_OUTPUT32: cmd = VIDIOC_G_OUTPUT; break;
	case VIDIOC_S_OUTPUT32: cmd = VIDIOC_S_OUTPUT; break;
894 895
	case VIDIOC_CREATE_BUFS32: cmd = VIDIOC_CREATE_BUFS; break;
	case VIDIOC_PREPARE_BUF32: cmd = VIDIOC_PREPARE_BUF; break;
896 897
	case VIDIOC_G_EDID32: cmd = VIDIOC_G_EDID; break;
	case VIDIOC_S_EDID32: cmd = VIDIOC_S_EDID; break;
898
	}
899

900
	switch (cmd) {
901
	case VIDIOC_OVERLAY:
902 903
	case VIDIOC_STREAMON:
	case VIDIOC_STREAMOFF:
904 905 906 907
	case VIDIOC_S_INPUT:
	case VIDIOC_S_OUTPUT:
		err = get_user(karg.vi, (s32 __user *)up);
		compatible_arg = 0;
908
		break;
909

910 911
	case VIDIOC_G_INPUT:
	case VIDIOC_G_OUTPUT:
912 913
		compatible_arg = 0;
		break;
914

915 916 917
	case VIDIOC_G_EDID:
	case VIDIOC_S_EDID:
		err = get_v4l2_edid32(&karg.v2edid, up);
918 919 920
		compatible_arg = 0;
		break;

921 922 923 924 925 926 927
	case VIDIOC_G_FMT:
	case VIDIOC_S_FMT:
	case VIDIOC_TRY_FMT:
		err = get_v4l2_format32(&karg.v2f, up);
		compatible_arg = 0;
		break;

928 929 930 931 932 933
	case VIDIOC_CREATE_BUFS:
		err = get_v4l2_create32(&karg.v2crt, up);
		compatible_arg = 0;
		break;

	case VIDIOC_PREPARE_BUF:
934 935 936 937 938 939 940
	case VIDIOC_QUERYBUF:
	case VIDIOC_QBUF:
	case VIDIOC_DQBUF:
		err = get_v4l2_buffer32(&karg.v2b, up);
		compatible_arg = 0;
		break;

941 942
	case VIDIOC_S_FBUF:
		err = get_v4l2_framebuffer32(&karg.v2fb, up);
943 944 945
		compatible_arg = 0;
		break;

946
	case VIDIOC_G_FBUF:
947 948 949
		compatible_arg = 0;
		break;

950 951
	case VIDIOC_ENUMSTD:
		err = get_v4l2_standard32(&karg.v2s, up);
952 953 954
		compatible_arg = 0;
		break;

955
	case VIDIOC_ENUMINPUT:
956 957 958 959
		err = get_v4l2_input32(&karg.v2i, up);
		compatible_arg = 0;
		break;

960 961 962 963
	case VIDIOC_G_EXT_CTRLS:
	case VIDIOC_S_EXT_CTRLS:
	case VIDIOC_TRY_EXT_CTRLS:
		err = get_v4l2_ext_controls32(&karg.v2ecs, up);
964 965
		compatible_arg = 0;
		break;
966 967 968
	case VIDIOC_DQEVENT:
		compatible_arg = 0;
		break;
969
	}
970
	if (err)
971
		return err;
972

973
	if (compatible_arg)
974
		err = native_ioctl(file, cmd, (unsigned long)up);
975 976
	else {
		mm_segment_t old_fs = get_fs();
977

978
		set_fs(KERNEL_DS);
979
		err = native_ioctl(file, cmd, (unsigned long)&karg);
980 981
		set_fs(old_fs);
	}
982 983 984 985 986 987 988 989 990 991 992

	/* Special case: even after an error we need to put the
	   results back for these ioctls since the error_idx will
	   contain information on which control failed. */
	switch (cmd) {
	case VIDIOC_G_EXT_CTRLS:
	case VIDIOC_S_EXT_CTRLS:
	case VIDIOC_TRY_EXT_CTRLS:
		if (put_v4l2_ext_controls32(&karg.v2ecs, up))
			err = -EFAULT;
		break;
993 994 995 996
	case VIDIOC_S_EDID:
		if (put_v4l2_edid32(&karg.v2edid, up))
			err = -EFAULT;
		break;
997 998 999 1000 1001 1002 1003 1004 1005 1006 1007
	}
	if (err)
		return err;

	switch (cmd) {
	case VIDIOC_S_INPUT:
	case VIDIOC_S_OUTPUT:
	case VIDIOC_G_INPUT:
	case VIDIOC_G_OUTPUT:
		err = put_user(((s32)karg.vi), (s32 __user *)up);
		break;
1008

1009 1010 1011 1012
	case VIDIOC_G_FBUF:
		err = put_v4l2_framebuffer32(&karg.v2fb, up);
		break;

1013 1014 1015 1016
	case VIDIOC_DQEVENT:
		err = put_v4l2_event32(&karg.v2ev, up);
		break;

1017 1018
	case VIDIOC_G_EDID:
		err = put_v4l2_edid32(&karg.v2edid, up);
1019 1020
		break;

1021 1022 1023 1024 1025 1026
	case VIDIOC_G_FMT:
	case VIDIOC_S_FMT:
	case VIDIOC_TRY_FMT:
		err = put_v4l2_format32(&karg.v2f, up);
		break;

1027 1028 1029 1030
	case VIDIOC_CREATE_BUFS:
		err = put_v4l2_create32(&karg.v2crt, up);
		break;

1031 1032 1033 1034 1035 1036 1037 1038 1039 1040 1041 1042 1043
	case VIDIOC_QUERYBUF:
	case VIDIOC_QBUF:
	case VIDIOC_DQBUF:
		err = put_v4l2_buffer32(&karg.v2b, up);
		break;

	case VIDIOC_ENUMSTD:
		err = put_v4l2_standard32(&karg.v2s, up);
		break;

	case VIDIOC_ENUMINPUT:
		err = put_v4l2_input32(&karg.v2i, up);
		break;
1044 1045 1046 1047
	}
	return err;
}

1048
long v4l2_compat_ioctl32(struct file *file, unsigned int cmd, unsigned long arg)
1049
{
1050
	struct video_device *vdev = video_devdata(file);
1051
	long ret = -ENOIOCTLCMD;
1052

1053
	if (!file->f_op->unlocked_ioctl)
1054 1055
		return ret;

1056
	if (_IOC_TYPE(cmd) == 'V' && _IOC_NR(cmd) < BASE_VIDIOC_PRIVATE)
1057
		ret = do_video_ioctl(file, cmd, arg);
1058 1059
	else if (vdev->fops->compat_ioctl32)
		ret = vdev->fops->compat_ioctl32(file, cmd, arg);
1060

1061
	if (ret == -ENOIOCTLCMD)
1062 1063
		pr_debug("compat_ioctl32: unknown ioctl '%c', dir=%d, #%d (0x%08x)\n",
			 _IOC_TYPE(cmd), _IOC_DIR(cmd), _IOC_NR(cmd), cmd);
1064
	return ret;
1065
}
1066
EXPORT_SYMBOL_GPL(v4l2_compat_ioctl32);