n_tty.c 62.3 KB
Newer Older
1
// SPDX-License-Identifier: GPL-1.0+
L
Linus Torvalds 已提交
2 3
/*
 * n_tty.c --- implements the N_TTY line discipline.
4
 *
L
Linus Torvalds 已提交
5 6 7 8 9 10 11
 * This code used to be in tty_io.c, but things are getting hairy
 * enough that it made sense to split things off.  (The N_TTY
 * processing has changed so much that it's hardly recognizable,
 * anyway...)
 *
 * Note that the open routine for N_TTY is guaranteed never to return
 * an error.  This is because Linux will fall back to setting a line
12
 * to N_TTY if it can not switch to any other line discipline.
L
Linus Torvalds 已提交
13 14
 *
 * Written by Theodore Ts'o, Copyright 1994.
15
 *
L
Linus Torvalds 已提交
16 17
 * This file also contains code originally written by Linus Torvalds,
 * Copyright 1991, 1992, 1993, and by Julian Cowley, Copyright 1994.
18
 *
L
Linus Torvalds 已提交
19 20
 * Reduced memory usage for older ARM systems  - Russell King.
 *
21
 * 2000/01/20   Fixed SMP locking on put_tty_queue using bits of
L
Linus Torvalds 已提交
22 23 24 25 26
 *		the patch by Andrew J. Kroll <ag784@freenet.buffalo.edu>
 *		who actually finally proved there really was a race.
 *
 * 2002/03/18   Implemented n_tty_wakeup to send SIGIO POLL_OUTs to
 *		waiting writing processes-Sapan Bhatia <sapan@corewars.org>.
27
 *		Also fixed a bug in BLOCKING mode where n_tty_write returns
L
Linus Torvalds 已提交
28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45
 *		EAGAIN
 */

#include <linux/types.h>
#include <linux/major.h>
#include <linux/errno.h>
#include <linux/signal.h>
#include <linux/fcntl.h>
#include <linux/sched.h>
#include <linux/interrupt.h>
#include <linux/tty.h>
#include <linux/timer.h>
#include <linux/ctype.h>
#include <linux/mm.h>
#include <linux/string.h>
#include <linux/slab.h>
#include <linux/poll.h>
#include <linux/bitops.h>
M
Miloslav Trmac 已提交
46 47
#include <linux/audit.h>
#include <linux/file.h>
A
Alan Cox 已提交
48
#include <linux/uaccess.h>
49
#include <linux/module.h>
50
#include <linux/ratelimit.h>
51
#include <linux/vmalloc.h>
L
Linus Torvalds 已提交
52

53 54 55 56
/*
 * Until this number of characters is queued in the xmit buffer, select will
 * return "we have room for writes".
 */
L
Linus Torvalds 已提交
57 58 59 60 61 62 63 64
#define WAKEUP_CHARS 256

/*
 * This defines the low- and high-watermarks for throttling and
 * unthrottling the TTY driver.  These watermarks are used for
 * controlling the space in the read buffer.
 */
#define TTY_THRESHOLD_THROTTLE		128 /* now based on remaining room */
65
#define TTY_THRESHOLD_UNTHROTTLE	128
L
Linus Torvalds 已提交
66

67 68 69 70 71 72 73 74 75 76 77
/*
 * Special byte codes used in the echo buffer to represent operations
 * or special handling of characters.  Bytes in the echo buffer that
 * are not part of such special blocks are treated as normal character
 * codes.
 */
#define ECHO_OP_START 0xff
#define ECHO_OP_MOVE_BACK_COL 0x80
#define ECHO_OP_SET_CANON_COL 0x81
#define ECHO_OP_ERASE_TAB 0x82

P
Peter Hurley 已提交
78 79 80 81 82
#define ECHO_COMMIT_WATERMARK	256
#define ECHO_BLOCK		256
#define ECHO_DISCARD_WATERMARK	N_TTY_BUF_SIZE - (ECHO_BLOCK + 32)


83 84 85 86
#undef N_TTY_TRACE
#ifdef N_TTY_TRACE
# define n_tty_trace(f, args...)	trace_printk(f, ##args)
#else
87
# define n_tty_trace(f, args...)	no_printk(f, ##args)
88 89
#endif

J
Jiri Slaby 已提交
90
struct n_tty_data {
91 92
	/* producer-published */
	size_t read_head;
93
	size_t commit_head;
94
	size_t canon_head;
95 96
	size_t echo_head;
	size_t echo_commit;
97
	size_t echo_mark;
98
	DECLARE_BITMAP(char_map, 256);
99 100

	/* private to n_tty_receive_overrun (single-threaded) */
101 102 103
	unsigned long overrun_time;
	int num_overrun;

104 105 106
	/* non-atomic */
	bool no_room;

107
	/* must hold exclusive termios_rwsem to reset these */
108
	unsigned char lnext:1, erasing:1, raw:1, real_raw:1, icanon:1;
109
	unsigned char push:1;
110

111
	/* shared by producer and consumer */
112
	char read_buf[N_TTY_BUF_SIZE];
113
	DECLARE_BITMAP(read_flags, N_TTY_BUF_SIZE);
114
	unsigned char echo_buf[N_TTY_BUF_SIZE];
115

116 117
	/* consumer-published */
	size_t read_tail;
P
Peter Hurley 已提交
118
	size_t line_start;
119 120 121

	/* protected by output lock */
	unsigned int column;
122
	unsigned int canon_column;
123
	size_t echo_tail;
124 125 126

	struct mutex atomic_read_lock;
	struct mutex output_lock;
J
Jiri Slaby 已提交
127 128
};

129 130
#define MASK(x) ((x) & (N_TTY_BUF_SIZE - 1))

131 132
static inline size_t read_cnt(struct n_tty_data *ldata)
{
P
Peter Hurley 已提交
133
	return ldata->read_head - ldata->read_tail;
134 135
}

136 137 138 139 140 141 142 143 144 145
static inline unsigned char read_buf(struct n_tty_data *ldata, size_t i)
{
	return ldata->read_buf[i & (N_TTY_BUF_SIZE - 1)];
}

static inline unsigned char *read_buf_addr(struct n_tty_data *ldata, size_t i)
{
	return &ldata->read_buf[i & (N_TTY_BUF_SIZE - 1)];
}

146 147
static inline unsigned char echo_buf(struct n_tty_data *ldata, size_t i)
{
148
	smp_rmb(); /* Matches smp_wmb() in add_echo_byte(). */
149 150 151 152 153 154 155 156
	return ldata->echo_buf[i & (N_TTY_BUF_SIZE - 1)];
}

static inline unsigned char *echo_buf_addr(struct n_tty_data *ldata, size_t i)
{
	return &ldata->echo_buf[i & (N_TTY_BUF_SIZE - 1)];
}

G
Greg KH 已提交
157 158 159 160 161 162 163 164 165 166
/* If we are not echoing the data, perhaps this is a secret so erase it */
static void zero_buffer(struct tty_struct *tty, u8 *buffer, int size)
{
	bool icanon = !!L_ICANON(tty);
	bool no_echo = !L_ECHO(tty);

	if (icanon && no_echo)
		memset(buffer, 0x00, size);
}

167
static void tty_copy(struct tty_struct *tty, void *to, size_t tail, size_t n)
168 169
{
	struct n_tty_data *ldata = tty->disc_data;
P
Peter Hurley 已提交
170
	size_t size = N_TTY_BUF_SIZE - tail;
G
Greg KH 已提交
171
	void *from = read_buf_addr(ldata, tail);
P
Peter Hurley 已提交
172 173

	if (n > size) {
174
		tty_audit_add_data(tty, from, size);
175 176
		memcpy(to, from, size);
		zero_buffer(tty, from, size);
P
Peter Hurley 已提交
177 178 179 180
		to += size;
		n -= size;
		from = ldata->read_buf;
	}
181

182
	tty_audit_add_data(tty, from, n);
183 184
	memcpy(to, from, n);
	zero_buffer(tty, from, n);
185 186
}

187
/**
188
 *	n_tty_kick_worker - start input worker (if required)
189 190
 *	@tty: terminal
 *
191
 *	Re-schedules the flip buffer work if it may have stopped
192
 *
193 194 195 196
 *	Caller holds exclusive termios_rwsem
 *	   or
 *	n_tty_read()/consumer path:
 *		holds non-exclusive termios_rwsem
197 198
 */

199
static void n_tty_kick_worker(struct tty_struct *tty)
200
{
201 202
	struct n_tty_data *ldata = tty->disc_data;

203 204
	/* Did the input worker stop? Restart it */
	if (unlikely(ldata->no_room)) {
205 206
		ldata->no_room = 0;

J
Jiri Slaby 已提交
207
		WARN_RATELIMIT(tty->port->itty == NULL,
208
				"scheduling with invalid itty\n");
209 210 211 212 213 214
		/* see if ldisc has been killed - if so, this means that
		 * even though the ldisc has been halted and ->buf.work
		 * cancelled, ->buf.work is about to be rescheduled
		 */
		WARN_RATELIMIT(test_bit(TTY_LDISC_HALTED, &tty->flags),
			       "scheduling buffer work for halted ldisc\n");
P
Peter Hurley 已提交
215
		tty_buffer_restart_work(tty->port);
J
Jiri Slaby 已提交
216
	}
217 218
}

219 220 221 222 223 224
static ssize_t chars_in_buffer(struct tty_struct *tty)
{
	struct n_tty_data *ldata = tty->disc_data;
	ssize_t n = 0;

	if (!ldata->icanon)
225
		n = ldata->commit_head - ldata->read_tail;
226 227 228 229 230
	else
		n = ldata->canon_head - ldata->read_tail;
	return n;
}

231 232 233 234 235 236 237 238 239 240 241
/**
 *	n_tty_write_wakeup	-	asynchronous I/O notifier
 *	@tty: tty device
 *
 *	Required for the ptys, serial driver etc. since processes
 *	that attach themselves to the master and rely on ASYNC
 *	IO must be woken up
 */

static void n_tty_write_wakeup(struct tty_struct *tty)
{
P
Peter Hurley 已提交
242 243
	clear_bit(TTY_DO_WRITE_WAKEUP, &tty->flags);
	kill_fasync(&tty->fasync, SIGIO, POLL_OUT);
244 245
}

246
static void n_tty_check_throttle(struct tty_struct *tty)
247
{
248 249
	struct n_tty_data *ldata = tty->disc_data;

250 251 252 253 254
	/*
	 * Check the remaining room for the input canonicalization
	 * mode.  We don't want to throttle the driver if we're in
	 * canonical mode and don't have a newline yet!
	 */
255 256 257
	if (ldata->icanon && ldata->canon_head == ldata->read_tail)
		return;

258 259 260
	while (1) {
		int throttled;
		tty_set_flow_change(tty, TTY_THROTTLE_SAFE);
261
		if (N_TTY_BUF_SIZE - read_cnt(ldata) >= TTY_THRESHOLD_THROTTLE)
262 263 264 265 266 267 268 269
			break;
		throttled = tty_throttle_safe(tty);
		if (!throttled)
			break;
	}
	__tty_set_flow_change(tty, 0);
}

270
static void n_tty_check_unthrottle(struct tty_struct *tty)
271
{
272
	if (tty->driver->type == TTY_DRIVER_TYPE_PTY) {
273 274
		if (chars_in_buffer(tty) > TTY_THRESHOLD_UNTHROTTLE)
			return;
275
		n_tty_kick_worker(tty);
276
		tty_wakeup(tty->link);
277 278 279
		return;
	}

280 281 282 283 284 285 286 287 288 289 290 291 292
	/* If there is enough space in the read buffer now, let the
	 * low-level driver know. We use chars_in_buffer() to
	 * check the buffer, as it now knows about canonical mode.
	 * Otherwise, if the driver is throttled and the line is
	 * longer than TTY_THRESHOLD_UNTHROTTLE in canonical mode,
	 * we won't get any more characters.
	 */

	while (1) {
		int unthrottled;
		tty_set_flow_change(tty, TTY_UNTHROTTLE_SAFE);
		if (chars_in_buffer(tty) > TTY_THRESHOLD_UNTHROTTLE)
			break;
293
		n_tty_kick_worker(tty);
294 295 296 297 298 299 300
		unthrottled = tty_unthrottle_safe(tty);
		if (!unthrottled)
			break;
	}
	__tty_set_flow_change(tty, 0);
}

301 302 303
/**
 *	put_tty_queue		-	add character to tty
 *	@c: character
J
Jiri Slaby 已提交
304
 *	@ldata: n_tty data
305
 *
306 307 308 309
 *	Add a character to the tty read_buf queue.
 *
 *	n_tty_receive_buf()/producer path:
 *		caller holds non-exclusive termios_rwsem
310 311
 */

312
static inline void put_tty_queue(unsigned char c, struct n_tty_data *ldata)
L
Linus Torvalds 已提交
313
{
314 315
	*read_buf_addr(ldata, ldata->read_head) = c;
	ldata->read_head++;
L
Linus Torvalds 已提交
316 317 318 319
}

/**
 *	reset_buffer_flags	-	reset buffer state
J
Jiri Slaby 已提交
320
 *	@ldata: line disc data to reset
L
Linus Torvalds 已提交
321
 *
322 323
 *	Reset the read buffer counters and clear the flags.
 *	Called from n_tty_open() and n_tty_flush_buffer().
324
 *
325 326
 *	Locking: caller holds exclusive termios_rwsem
 *		 (or locking is not required)
L
Linus Torvalds 已提交
327
 */
328

329
static void reset_buffer_flags(struct n_tty_data *ldata)
L
Linus Torvalds 已提交
330
{
331
	ldata->read_head = ldata->canon_head = ldata->read_tail = 0;
332
	ldata->commit_head = 0;
P
Peter Hurley 已提交
333
	ldata->line_start = 0;
334

335
	ldata->erasing = 0;
336
	bitmap_zero(ldata->read_flags, N_TTY_BUF_SIZE);
337
	ldata->push = 0;
L
Linus Torvalds 已提交
338 339
}

340 341 342 343 344
static void n_tty_packet_mode_flush(struct tty_struct *tty)
{
	unsigned long flags;

	if (tty->link->packet) {
345
		spin_lock_irqsave(&tty->ctrl_lock, flags);
346
		tty->ctrl_status |= TIOCPKT_FLUSHREAD;
347
		spin_unlock_irqrestore(&tty->ctrl_lock, flags);
348
		wake_up_interruptible(&tty->link->read_wait);
349 350 351
	}
}

L
Linus Torvalds 已提交
352 353 354 355
/**
 *	n_tty_flush_buffer	-	clean input queue
 *	@tty:	terminal device
 *
356 357 358
 *	Flush the input buffer. Called when the tty layer wants the
 *	buffer flushed (eg at hangup) or when the N_TTY line discipline
 *	internally has to clean the pending queue (for example some signals).
L
Linus Torvalds 已提交
359
 *
360 361 362 363
 *	Holds termios_rwsem to exclude producer/consumer while
 *	buffer indices are reset.
 *
 *	Locking: ctrl_lock, exclusive termios_rwsem
L
Linus Torvalds 已提交
364
 */
365 366

static void n_tty_flush_buffer(struct tty_struct *tty)
L
Linus Torvalds 已提交
367
{
368
	down_write(&tty->termios_rwsem);
369
	reset_buffer_flags(tty->disc_data);
370
	n_tty_kick_worker(tty);
371

372 373
	if (tty->link)
		n_tty_packet_mode_flush(tty);
374
	up_write(&tty->termios_rwsem);
L
Linus Torvalds 已提交
375 376 377 378 379 380 381 382 383 384
}

/**
 *	is_utf8_continuation	-	utf8 multibyte check
 *	@c: byte to check
 *
 *	Returns true if the utf8 character 'c' is a multibyte continuation
 *	character. We use this to correctly compute the on screen size
 *	of the character when printing
 */
385

L
Linus Torvalds 已提交
386 387 388 389 390 391 392 393
static inline int is_utf8_continuation(unsigned char c)
{
	return (c & 0xc0) == 0x80;
}

/**
 *	is_continuation		-	multibyte check
 *	@c: byte to check
394
 *	@tty: terminal device
L
Linus Torvalds 已提交
395 396 397 398
 *
 *	Returns true if the utf8 character 'c' is a multibyte continuation
 *	character and the terminal is in unicode mode.
 */
399

L
Linus Torvalds 已提交
400 401 402 403 404 405
static inline int is_continuation(unsigned char c, struct tty_struct *tty)
{
	return I_IUTF8(tty) && is_utf8_continuation(c);
}

/**
406
 *	do_output_char			-	output one character
L
Linus Torvalds 已提交
407 408
 *	@c: character (or partial unicode symbol)
 *	@tty: terminal device
409
 *	@space: space available in tty driver write buffer
L
Linus Torvalds 已提交
410
 *
411 412
 *	This is a helper function that handles one output character
 *	(including special characters like TAB, CR, LF, etc.),
413 414
 *	doing OPOST processing and putting the results in the
 *	tty driver's write buffer.
415 416 417 418
 *
 *	Note that Linux currently ignores TABDLY, CRDLY, VTDLY, FFDLY
 *	and NLDLY.  They simply aren't relevant in the world today.
 *	If you ever need them, add them here.
L
Linus Torvalds 已提交
419
 *
420 421 422 423 424
 *	Returns the number of bytes of buffer space used or -1 if
 *	no space left.
 *
 *	Locking: should be called under the output_lock to protect
 *		 the column state and space left in the buffer
L
Linus Torvalds 已提交
425
 */
426

427
static int do_output_char(unsigned char c, struct tty_struct *tty, int space)
L
Linus Torvalds 已提交
428
{
429
	struct n_tty_data *ldata = tty->disc_data;
430
	int	spaces;
L
Linus Torvalds 已提交
431 432 433

	if (!space)
		return -1;
A
Alan Cox 已提交
434

435 436 437
	switch (c) {
	case '\n':
		if (O_ONLRET(tty))
438
			ldata->column = 0;
439 440 441
		if (O_ONLCR(tty)) {
			if (space < 2)
				return -1;
442
			ldata->canon_column = ldata->column = 0;
443
			tty->ops->write(tty, "\r\n", 2);
444 445
			return 2;
		}
446
		ldata->canon_column = ldata->column;
447 448
		break;
	case '\r':
449
		if (O_ONOCR(tty) && ldata->column == 0)
450 451 452 453
			return 0;
		if (O_OCRNL(tty)) {
			c = '\n';
			if (O_ONLRET(tty))
454
				ldata->canon_column = ldata->column = 0;
L
Linus Torvalds 已提交
455
			break;
456
		}
457
		ldata->canon_column = ldata->column = 0;
458 459
		break;
	case '\t':
460
		spaces = 8 - (ldata->column & 7);
461 462 463
		if (O_TABDLY(tty) == XTABS) {
			if (space < spaces)
				return -1;
464
			ldata->column += spaces;
465 466
			tty->ops->write(tty, "        ", spaces);
			return spaces;
L
Linus Torvalds 已提交
467
		}
468
		ldata->column += spaces;
469 470
		break;
	case '\b':
471 472
		if (ldata->column > 0)
			ldata->column--;
473 474
		break;
	default:
475 476 477 478
		if (!iscntrl(c)) {
			if (O_OLCUC(tty))
				c = toupper(c);
			if (!is_continuation(c, tty))
479
				ldata->column++;
480
		}
481
		break;
L
Linus Torvalds 已提交
482
	}
483

A
Alan Cox 已提交
484
	tty_put_char(tty, c);
485 486 487 488 489 490 491 492
	return 1;
}

/**
 *	process_output			-	output post processor
 *	@c: character (or partial unicode symbol)
 *	@tty: terminal device
 *
493 494 495
 *	Output one character with OPOST processing.
 *	Returns -1 when the output device is full and the character
 *	must be retried.
496 497 498 499 500 501 502 503
 *
 *	Locking: output_lock to protect column state and space left
 *		 (also, this is called from n_tty_write under the
 *		  tty layer write lock)
 */

static int process_output(unsigned char c, struct tty_struct *tty)
{
504
	struct n_tty_data *ldata = tty->disc_data;
505 506
	int	space, retval;

507
	mutex_lock(&ldata->output_lock);
508 509 510 511

	space = tty_write_room(tty);
	retval = do_output_char(c, tty, space);

512
	mutex_unlock(&ldata->output_lock);
513 514 515 516
	if (retval < 0)
		return -1;
	else
		return 0;
L
Linus Torvalds 已提交
517 518 519
}

/**
520
 *	process_output_block		-	block post processor
L
Linus Torvalds 已提交
521
 *	@tty: terminal device
522 523 524 525 526
 *	@buf: character buffer
 *	@nr: number of bytes to output
 *
 *	Output a block of characters with OPOST processing.
 *	Returns the number of characters output.
L
Linus Torvalds 已提交
527 528 529 530 531 532
 *
 *	This path is used to speed up block console writes, among other
 *	things when processing blocks of output data. It handles only
 *	the simple cases normally found and helps to generate blocks of
 *	symbols for the console driver and thus improve performance.
 *
533 534 535
 *	Locking: output_lock to protect column state and space left
 *		 (also, this is called from n_tty_write under the
 *		  tty layer write lock)
L
Linus Torvalds 已提交
536
 */
537

538 539
static ssize_t process_output_block(struct tty_struct *tty,
				    const unsigned char *buf, unsigned int nr)
L
Linus Torvalds 已提交
540
{
541
	struct n_tty_data *ldata = tty->disc_data;
L
Linus Torvalds 已提交
542
	int	space;
543
	int	i;
L
Linus Torvalds 已提交
544 545
	const unsigned char *cp;

546
	mutex_lock(&ldata->output_lock);
547

A
Alan Cox 已提交
548
	space = tty_write_room(tty);
549
	if (space <= 0) {
550
		mutex_unlock(&ldata->output_lock);
551
		return space;
552
	}
L
Linus Torvalds 已提交
553 554 555 556
	if (nr > space)
		nr = space;

	for (i = 0, cp = buf; i < nr; i++, cp++) {
557 558 559
		unsigned char c = *cp;

		switch (c) {
L
Linus Torvalds 已提交
560 561
		case '\n':
			if (O_ONLRET(tty))
562
				ldata->column = 0;
L
Linus Torvalds 已提交
563 564
			if (O_ONLCR(tty))
				goto break_out;
565
			ldata->canon_column = ldata->column;
L
Linus Torvalds 已提交
566 567
			break;
		case '\r':
568
			if (O_ONOCR(tty) && ldata->column == 0)
L
Linus Torvalds 已提交
569 570 571
				goto break_out;
			if (O_OCRNL(tty))
				goto break_out;
572
			ldata->canon_column = ldata->column = 0;
L
Linus Torvalds 已提交
573 574 575 576
			break;
		case '\t':
			goto break_out;
		case '\b':
577 578
			if (ldata->column > 0)
				ldata->column--;
L
Linus Torvalds 已提交
579 580
			break;
		default:
581 582 583 584
			if (!iscntrl(c)) {
				if (O_OLCUC(tty))
					goto break_out;
				if (!is_continuation(c, tty))
585
					ldata->column++;
586
			}
L
Linus Torvalds 已提交
587 588 589 590
			break;
		}
	}
break_out:
A
Alan Cox 已提交
591
	i = tty->ops->write(tty, buf, i);
592

593
	mutex_unlock(&ldata->output_lock);
L
Linus Torvalds 已提交
594 595 596
	return i;
}

597 598 599 600 601 602 603 604 605 606 607 608 609 610 611 612 613 614 615 616 617 618
/**
 *	process_echoes	-	write pending echo characters
 *	@tty: terminal device
 *
 *	Write previously buffered echo (and other ldisc-generated)
 *	characters to the tty.
 *
 *	Characters generated by the ldisc (including echoes) need to
 *	be buffered because the driver's write buffer can fill during
 *	heavy program output.  Echoing straight to the driver will
 *	often fail under these conditions, causing lost characters and
 *	resulting mismatches of ldisc state information.
 *
 *	Since the ldisc state must represent the characters actually sent
 *	to the driver at the time of the write, operations like certain
 *	changes in column state are also saved in the buffer and executed
 *	here.
 *
 *	A circular fifo buffer is used so that the most recent characters
 *	are prioritized.  Also, when control characters are echoed with a
 *	prefixed "^", the pair is treated atomically and thus not separated.
 *
619
 *	Locking: callers must hold output_lock
620 621
 */

622
static size_t __process_echoes(struct tty_struct *tty)
623
{
624
	struct n_tty_data *ldata = tty->disc_data;
625
	int	space, old_space;
626
	size_t tail;
627 628
	unsigned char c;

629
	old_space = space = tty_write_room(tty);
630

631
	tail = ldata->echo_tail;
632
	while (MASK(ldata->echo_commit) != MASK(tail)) {
633
		c = echo_buf(ldata, tail);
634 635 636 637
		if (c == ECHO_OP_START) {
			unsigned char op;
			int no_space_left = 0;

638 639 640 641 642 643 644
			/*
			 * Since add_echo_byte() is called without holding
			 * output_lock, we might see only portion of multi-byte
			 * operation.
			 */
			if (MASK(ldata->echo_commit) == MASK(tail + 1))
				goto not_yet_stored;
645 646 647 648 649
			/*
			 * If the buffer byte is the start of a multi-byte
			 * operation, get the next byte, which is either the
			 * op code or a control character value.
			 */
650
			op = echo_buf(ldata, tail + 1);
A
Alan Cox 已提交
651

652
			switch (op) {
653
			case ECHO_OP_ERASE_TAB: {
654 655
				unsigned int num_chars, num_bs;

656 657
				if (MASK(ldata->echo_commit) == MASK(tail + 2))
					goto not_yet_stored;
658
				num_chars = echo_buf(ldata, tail + 2);
659 660 661 662 663 664 665 666 667 668 669 670

				/*
				 * Determine how many columns to go back
				 * in order to erase the tab.
				 * This depends on the number of columns
				 * used by other characters within the tab
				 * area.  If this (modulo 8) count is from
				 * the start of input rather than from a
				 * previous tab, we offset by canon column.
				 * Otherwise, tab spacing is normal.
				 */
				if (!(num_chars & 0x80))
671
					num_chars += ldata->canon_column;
672 673 674 675 676 677 678 679 680
				num_bs = 8 - (num_chars & 7);

				if (num_bs > space) {
					no_space_left = 1;
					break;
				}
				space -= num_bs;
				while (num_bs--) {
					tty_put_char(tty, '\b');
681 682
					if (ldata->column > 0)
						ldata->column--;
683
				}
684
				tail += 3;
685
				break;
686
			}
687
			case ECHO_OP_SET_CANON_COL:
688
				ldata->canon_column = ldata->column;
689
				tail += 2;
690 691 692
				break;

			case ECHO_OP_MOVE_BACK_COL:
693 694
				if (ldata->column > 0)
					ldata->column--;
695
				tail += 2;
696 697 698 699 700 701 702 703 704
				break;

			case ECHO_OP_START:
				/* This is an escaped echo op start code */
				if (!space) {
					no_space_left = 1;
					break;
				}
				tty_put_char(tty, ECHO_OP_START);
705
				ldata->column++;
706
				space--;
707
				tail += 2;
708 709 710 711
				break;

			default:
				/*
712 713 714 715 716 717 718
				 * If the op is not a special byte code,
				 * it is a ctrl char tagged to be echoed
				 * as "^X" (where X is the letter
				 * representing the control char).
				 * Note that we must ensure there is
				 * enough space for the whole ctrl pair.
				 *
719
				 */
720 721 722 723 724 725
				if (space < 2) {
					no_space_left = 1;
					break;
				}
				tty_put_char(tty, '^');
				tty_put_char(tty, op ^ 0100);
726
				ldata->column += 2;
727
				space -= 2;
728
				tail += 2;
729 730 731 732 733
			}

			if (no_space_left)
				break;
		} else {
P
Peter Hurley 已提交
734
			if (O_OPOST(tty)) {
735 736 737 738 739 740 741 742 743 744
				int retval = do_output_char(c, tty, space);
				if (retval < 0)
					break;
				space -= retval;
			} else {
				if (!space)
					break;
				tty_put_char(tty, c);
				space -= 1;
			}
745
			tail += 1;
746 747 748
		}
	}

P
Peter Hurley 已提交
749 750 751
	/* If the echo buffer is nearly full (so that the possibility exists
	 * of echo overrun before the next commit), then discard enough
	 * data at the tail to prevent a subsequent overrun */
752 753
	while (ldata->echo_commit > tail &&
	       ldata->echo_commit - tail >= ECHO_DISCARD_WATERMARK) {
754
		if (echo_buf(ldata, tail) == ECHO_OP_START) {
755
			if (echo_buf(ldata, tail + 1) == ECHO_OP_ERASE_TAB)
P
Peter Hurley 已提交
756 757 758 759 760 761 762
				tail += 3;
			else
				tail += 2;
		} else
			tail++;
	}

763
 not_yet_stored:
764
	ldata->echo_tail = tail;
765
	return old_space - space;
766 767 768 769 770
}

static void commit_echoes(struct tty_struct *tty)
{
	struct n_tty_data *ldata = tty->disc_data;
771
	size_t nr, old, echoed;
P
Peter Hurley 已提交
772 773
	size_t head;

774
	mutex_lock(&ldata->output_lock);
P
Peter Hurley 已提交
775
	head = ldata->echo_head;
776
	ldata->echo_mark = head;
P
Peter Hurley 已提交
777 778 779 780 781 782
	old = ldata->echo_commit - ldata->echo_tail;

	/* Process committed echoes if the accumulated # of bytes
	 * is over the threshold (and try again each time another
	 * block is accumulated) */
	nr = head - ldata->echo_tail;
783 784 785
	if (nr < ECHO_COMMIT_WATERMARK ||
	    (nr % ECHO_BLOCK > old % ECHO_BLOCK)) {
		mutex_unlock(&ldata->output_lock);
P
Peter Hurley 已提交
786
		return;
787
	}
788

P
Peter Hurley 已提交
789
	ldata->echo_commit = head;
790
	echoed = __process_echoes(tty);
791
	mutex_unlock(&ldata->output_lock);
792

793
	if (echoed && tty->ops->flush_chars)
794 795 796
		tty->ops->flush_chars(tty);
}

797
static void process_echoes(struct tty_struct *tty)
P
Peter Hurley 已提交
798 799
{
	struct n_tty_data *ldata = tty->disc_data;
800
	size_t echoed;
P
Peter Hurley 已提交
801

P
Peter Hurley 已提交
802
	if (ldata->echo_mark == ldata->echo_tail)
803 804 805
		return;

	mutex_lock(&ldata->output_lock);
806
	ldata->echo_commit = ldata->echo_mark;
807
	echoed = __process_echoes(tty);
808 809
	mutex_unlock(&ldata->output_lock);

810
	if (echoed && tty->ops->flush_chars)
811
		tty->ops->flush_chars(tty);
P
Peter Hurley 已提交
812 813
}

814
/* NB: echo_mark and echo_head should be equivalent here */
P
Peter Hurley 已提交
815 816 817 818
static void flush_echoes(struct tty_struct *tty)
{
	struct n_tty_data *ldata = tty->disc_data;

P
Peter Hurley 已提交
819 820
	if ((!L_ECHO(tty) && !L_ECHONL(tty)) ||
	    ldata->echo_commit == ldata->echo_head)
P
Peter Hurley 已提交
821 822 823 824 825 826 827 828
		return;

	mutex_lock(&ldata->output_lock);
	ldata->echo_commit = ldata->echo_head;
	__process_echoes(tty);
	mutex_unlock(&ldata->output_lock);
}

829 830 831
/**
 *	add_echo_byte	-	add a byte to the echo buffer
 *	@c: unicode byte to echo
J
Jiri Slaby 已提交
832
 *	@ldata: n_tty data
833 834 835 836
 *
 *	Add a character or operation byte to the echo buffer.
 */

P
Peter Hurley 已提交
837
static inline void add_echo_byte(unsigned char c, struct n_tty_data *ldata)
838
{
839 840 841
	*echo_buf_addr(ldata, ldata->echo_head) = c;
	smp_wmb(); /* Matches smp_rmb() in echo_buf(). */
	ldata->echo_head++;
842 843 844 845
}

/**
 *	echo_move_back_col	-	add operation to move back a column
J
Jiri Slaby 已提交
846
 *	@ldata: n_tty data
847 848 849 850
 *
 *	Add an operation to the echo buffer to move back one column.
 */

J
Jiri Slaby 已提交
851
static void echo_move_back_col(struct n_tty_data *ldata)
852
{
J
Jiri Slaby 已提交
853 854
	add_echo_byte(ECHO_OP_START, ldata);
	add_echo_byte(ECHO_OP_MOVE_BACK_COL, ldata);
855 856 857 858
}

/**
 *	echo_set_canon_col	-	add operation to set the canon column
J
Jiri Slaby 已提交
859
 *	@ldata: n_tty data
860 861 862 863 864
 *
 *	Add an operation to the echo buffer to set the canon column
 *	to the current column.
 */

J
Jiri Slaby 已提交
865
static void echo_set_canon_col(struct n_tty_data *ldata)
866
{
J
Jiri Slaby 已提交
867 868
	add_echo_byte(ECHO_OP_START, ldata);
	add_echo_byte(ECHO_OP_SET_CANON_COL, ldata);
869 870 871 872 873 874
}

/**
 *	echo_erase_tab	-	add operation to erase a tab
 *	@num_chars: number of character columns already used
 *	@after_tab: true if num_chars starts after a previous tab
J
Jiri Slaby 已提交
875
 *	@ldata: n_tty data
876 877 878 879 880 881 882 883 884 885 886
 *
 *	Add an operation to the echo buffer to erase a tab.
 *
 *	Called by the eraser function, which knows how many character
 *	columns have been used since either a previous tab or the start
 *	of input.  This information will be used later, along with
 *	canon column (if applicable), to go back the correct number
 *	of columns.
 */

static void echo_erase_tab(unsigned int num_chars, int after_tab,
J
Jiri Slaby 已提交
887
			   struct n_tty_data *ldata)
888
{
J
Jiri Slaby 已提交
889 890
	add_echo_byte(ECHO_OP_START, ldata);
	add_echo_byte(ECHO_OP_ERASE_TAB, ldata);
891 892 893 894 895 896 897

	/* We only need to know this modulo 8 (tab spacing) */
	num_chars &= 7;

	/* Set the high bit as a flag if num_chars is after a previous tab */
	if (after_tab)
		num_chars |= 0x80;
A
Alan Cox 已提交
898

J
Jiri Slaby 已提交
899
	add_echo_byte(num_chars, ldata);
900 901 902 903 904
}

/**
 *	echo_char_raw	-	echo a character raw
 *	@c: unicode byte to echo
J
Jiri Slaby 已提交
905
 *	@ldata: line disc data
906 907 908 909 910 911 912
 *
 *	Echo user input back onto the screen. This must be called only when
 *	L_ECHO(tty) is true. Called from the driver receive_buf path.
 *
 *	This variant does not treat control characters specially.
 */

J
Jiri Slaby 已提交
913
static void echo_char_raw(unsigned char c, struct n_tty_data *ldata)
914 915
{
	if (c == ECHO_OP_START) {
J
Jiri Slaby 已提交
916 917
		add_echo_byte(ECHO_OP_START, ldata);
		add_echo_byte(ECHO_OP_START, ldata);
918
	} else {
J
Jiri Slaby 已提交
919
		add_echo_byte(c, ldata);
920 921
	}
}
L
Linus Torvalds 已提交
922 923

/**
924
 *	echo_char	-	echo a character
L
Linus Torvalds 已提交
925 926 927
 *	@c: unicode byte to echo
 *	@tty: terminal device
 *
928
 *	Echo user input back onto the screen. This must be called only when
L
Linus Torvalds 已提交
929
 *	L_ECHO(tty) is true. Called from the driver receive_buf path.
930
 *
931 932
 *	This variant tags control characters to be echoed as "^X"
 *	(where X is the letter representing the control char).
L
Linus Torvalds 已提交
933 934 935 936
 */

static void echo_char(unsigned char c, struct tty_struct *tty)
{
937 938
	struct n_tty_data *ldata = tty->disc_data;

939
	if (c == ECHO_OP_START) {
J
Jiri Slaby 已提交
940 941
		add_echo_byte(ECHO_OP_START, ldata);
		add_echo_byte(ECHO_OP_START, ldata);
942
	} else {
943
		if (L_ECHOCTL(tty) && iscntrl(c) && c != '\t')
J
Jiri Slaby 已提交
944 945
			add_echo_byte(ECHO_OP_START, ldata);
		add_echo_byte(c, ldata);
946
	}
L
Linus Torvalds 已提交
947 948
}

949
/**
950
 *	finish_erasing		-	complete erase
J
Jiri Slaby 已提交
951
 *	@ldata: n_tty data
952
 */
953

J
Jiri Slaby 已提交
954
static inline void finish_erasing(struct n_tty_data *ldata)
L
Linus Torvalds 已提交
955
{
956
	if (ldata->erasing) {
J
Jiri Slaby 已提交
957
		echo_char_raw('/', ldata);
958
		ldata->erasing = 0;
L
Linus Torvalds 已提交
959 960 961 962 963 964 965 966
	}
}

/**
 *	eraser		-	handle erase function
 *	@c: character input
 *	@tty: terminal device
 *
967
 *	Perform erase and necessary output when an erase character is
L
Linus Torvalds 已提交
968 969
 *	present in the stream from the driver layer. Handles the complexities
 *	of UTF-8 multibyte symbols.
970
 *
971 972
 *	n_tty_receive_buf()/producer path:
 *		caller holds non-exclusive termios_rwsem
L
Linus Torvalds 已提交
973
 */
974

L
Linus Torvalds 已提交
975 976
static void eraser(unsigned char c, struct tty_struct *tty)
{
977
	struct n_tty_data *ldata = tty->disc_data;
L
Linus Torvalds 已提交
978
	enum { ERASE, WERASE, KILL } kill_type;
979 980 981
	size_t head;
	size_t cnt;
	int seen_alnums;
L
Linus Torvalds 已提交
982

983
	if (ldata->read_head == ldata->canon_head) {
984
		/* process_output('\a', tty); */ /* what do you think? */
L
Linus Torvalds 已提交
985 986 987 988 989 990 991 992
		return;
	}
	if (c == ERASE_CHAR(tty))
		kill_type = ERASE;
	else if (c == WERASE_CHAR(tty))
		kill_type = WERASE;
	else {
		if (!L_ECHO(tty)) {
993
			ldata->read_head = ldata->canon_head;
L
Linus Torvalds 已提交
994 995 996
			return;
		}
		if (!L_ECHOK(tty) || !L_ECHOKE(tty) || !L_ECHOE(tty)) {
997
			ldata->read_head = ldata->canon_head;
J
Jiri Slaby 已提交
998
			finish_erasing(ldata);
L
Linus Torvalds 已提交
999 1000 1001
			echo_char(KILL_CHAR(tty), tty);
			/* Add a newline if ECHOK is on and ECHOKE is off. */
			if (L_ECHOK(tty))
J
Jiri Slaby 已提交
1002
				echo_char_raw('\n', ldata);
L
Linus Torvalds 已提交
1003 1004 1005 1006 1007 1008
			return;
		}
		kill_type = KILL;
	}

	seen_alnums = 0;
1009
	while (MASK(ldata->read_head) != MASK(ldata->canon_head)) {
1010
		head = ldata->read_head;
L
Linus Torvalds 已提交
1011 1012 1013

		/* erase a single possibly multibyte character */
		do {
1014 1015
			head--;
			c = read_buf(ldata, head);
1016 1017
		} while (is_continuation(c, tty) &&
			 MASK(head) != MASK(ldata->canon_head));
L
Linus Torvalds 已提交
1018 1019 1020 1021 1022 1023 1024 1025 1026 1027 1028 1029

		/* do not partially erase */
		if (is_continuation(c, tty))
			break;

		if (kill_type == WERASE) {
			/* Equivalent to BSD's ALTWERASE. */
			if (isalnum(c) || c == '_')
				seen_alnums++;
			else if (seen_alnums)
				break;
		}
1030
		cnt = ldata->read_head - head;
1031
		ldata->read_head = head;
L
Linus Torvalds 已提交
1032 1033
		if (L_ECHO(tty)) {
			if (L_ECHOPRT(tty)) {
1034
				if (!ldata->erasing) {
J
Jiri Slaby 已提交
1035
					echo_char_raw('\\', ldata);
1036
					ldata->erasing = 1;
L
Linus Torvalds 已提交
1037 1038 1039 1040
				}
				/* if cnt > 1, output a multi-byte character */
				echo_char(c, tty);
				while (--cnt > 0) {
1041 1042
					head++;
					echo_char_raw(read_buf(ldata, head), ldata);
J
Jiri Slaby 已提交
1043
					echo_move_back_col(ldata);
L
Linus Torvalds 已提交
1044 1045 1046 1047
				}
			} else if (kill_type == ERASE && !L_ECHOE(tty)) {
				echo_char(ERASE_CHAR(tty), tty);
			} else if (c == '\t') {
1048 1049
				unsigned int num_chars = 0;
				int after_tab = 0;
1050
				size_t tail = ldata->read_head;
1051 1052 1053 1054 1055 1056 1057 1058

				/*
				 * Count the columns used for characters
				 * since the start of input or after a
				 * previous tab.
				 * This info is used to go back the correct
				 * number of columns.
				 */
1059
				while (MASK(tail) != MASK(ldata->canon_head)) {
1060 1061
					tail--;
					c = read_buf(ldata, tail);
1062 1063 1064
					if (c == '\t') {
						after_tab = 1;
						break;
A
Alan Cox 已提交
1065
					} else if (iscntrl(c)) {
L
Linus Torvalds 已提交
1066
						if (L_ECHOCTL(tty))
1067 1068 1069 1070
							num_chars += 2;
					} else if (!is_continuation(c, tty)) {
						num_chars++;
					}
L
Linus Torvalds 已提交
1071
				}
J
Jiri Slaby 已提交
1072
				echo_erase_tab(num_chars, after_tab, ldata);
L
Linus Torvalds 已提交
1073 1074
			} else {
				if (iscntrl(c) && L_ECHOCTL(tty)) {
J
Jiri Slaby 已提交
1075 1076 1077
					echo_char_raw('\b', ldata);
					echo_char_raw(' ', ldata);
					echo_char_raw('\b', ldata);
L
Linus Torvalds 已提交
1078 1079
				}
				if (!iscntrl(c) || L_ECHOCTL(tty)) {
J
Jiri Slaby 已提交
1080 1081 1082
					echo_char_raw('\b', ldata);
					echo_char_raw(' ', ldata);
					echo_char_raw('\b', ldata);
L
Linus Torvalds 已提交
1083 1084 1085 1086 1087 1088
				}
			}
		}
		if (kill_type == ERASE)
			break;
	}
1089
	if (ldata->read_head == ldata->canon_head && L_ECHO(tty))
J
Jiri Slaby 已提交
1090
		finish_erasing(ldata);
L
Linus Torvalds 已提交
1091 1092 1093 1094 1095 1096 1097
}

/**
 *	isig		-	handle the ISIG optio
 *	@sig: signal
 *	@tty: terminal
 *
1098 1099
 *	Called when a signal is being sent due to terminal input.
 *	Called from the driver receive_buf path so serialized.
1100
 *
1101 1102 1103 1104
 *	Performs input and output flush if !NOFLSH. In this context, the echo
 *	buffer is 'output'. The signal is processed first to alert any current
 *	readers or writers to discontinue and exit their i/o loops.
 *
1105
 *	Locking: ctrl_lock
L
Linus Torvalds 已提交
1106
 */
1107

1108
static void __isig(int sig, struct tty_struct *tty)
L
Linus Torvalds 已提交
1109
{
1110 1111 1112 1113
	struct pid *tty_pgrp = tty_get_pgrp(tty);
	if (tty_pgrp) {
		kill_pgrp(tty_pgrp, sig, 1);
		put_pid(tty_pgrp);
L
Linus Torvalds 已提交
1114
	}
1115
}
1116

1117 1118 1119 1120 1121 1122 1123 1124 1125
static void isig(int sig, struct tty_struct *tty)
{
	struct n_tty_data *ldata = tty->disc_data;

	if (L_NOFLSH(tty)) {
		/* signal only */
		__isig(sig, tty);

	} else { /* signal and flush */
1126 1127 1128
		up_read(&tty->termios_rwsem);
		down_write(&tty->termios_rwsem);

1129 1130
		__isig(sig, tty);

1131 1132 1133 1134 1135 1136 1137 1138 1139 1140 1141 1142 1143 1144 1145 1146 1147 1148 1149
		/* clear echo buffer */
		mutex_lock(&ldata->output_lock);
		ldata->echo_head = ldata->echo_tail = 0;
		ldata->echo_mark = ldata->echo_commit = 0;
		mutex_unlock(&ldata->output_lock);

		/* clear output buffer */
		tty_driver_flush_buffer(tty);

		/* clear input buffer */
		reset_buffer_flags(tty->disc_data);

		/* notify pty master of flush */
		if (tty->link)
			n_tty_packet_mode_flush(tty);

		up_write(&tty->termios_rwsem);
		down_read(&tty->termios_rwsem);
	}
L
Linus Torvalds 已提交
1150 1151 1152 1153 1154 1155 1156 1157 1158
}

/**
 *	n_tty_receive_break	-	handle break
 *	@tty: terminal
 *
 *	An RS232 break event has been hit in the incoming bitstream. This
 *	can cause a variety of events depending upon the termios settings.
 *
1159 1160 1161 1162
 *	n_tty_receive_buf()/producer path:
 *		caller holds non-exclusive termios_rwsem
 *
 *	Note: may get exclusive termios_rwsem if flushing input buffer
L
Linus Torvalds 已提交
1163
 */
1164

1165
static void n_tty_receive_break(struct tty_struct *tty)
L
Linus Torvalds 已提交
1166
{
J
Jiri Slaby 已提交
1167 1168
	struct n_tty_data *ldata = tty->disc_data;

L
Linus Torvalds 已提交
1169 1170 1171
	if (I_IGNBRK(tty))
		return;
	if (I_BRKINT(tty)) {
1172
		isig(SIGINT, tty);
L
Linus Torvalds 已提交
1173 1174 1175
		return;
	}
	if (I_PARMRK(tty)) {
J
Jiri Slaby 已提交
1176 1177
		put_tty_queue('\377', ldata);
		put_tty_queue('\0', ldata);
L
Linus Torvalds 已提交
1178
	}
J
Jiri Slaby 已提交
1179
	put_tty_queue('\0', ldata);
L
Linus Torvalds 已提交
1180 1181 1182 1183 1184 1185 1186 1187 1188 1189 1190 1191 1192 1193
}

/**
 *	n_tty_receive_overrun	-	handle overrun reporting
 *	@tty: terminal
 *
 *	Data arrived faster than we could process it. While the tty
 *	driver has flagged this the bits that were missed are gone
 *	forever.
 *
 *	Called from the receive_buf path so single threaded. Does not
 *	need locking as num_overrun and overrun_time are function
 *	private.
 */
1194

1195
static void n_tty_receive_overrun(struct tty_struct *tty)
L
Linus Torvalds 已提交
1196
{
1197
	struct n_tty_data *ldata = tty->disc_data;
L
Linus Torvalds 已提交
1198

1199 1200 1201
	ldata->num_overrun++;
	if (time_after(jiffies, ldata->overrun_time + HZ) ||
			time_after(ldata->overrun_time, jiffies)) {
P
Peter Hurley 已提交
1202
		tty_warn(tty, "%d input overrun(s)\n", ldata->num_overrun);
1203 1204
		ldata->overrun_time = jiffies;
		ldata->num_overrun = 0;
L
Linus Torvalds 已提交
1205 1206 1207 1208 1209 1210 1211 1212 1213
	}
}

/**
 *	n_tty_receive_parity_error	-	error notifier
 *	@tty: terminal device
 *	@c: character
 *
 *	Process a parity error and queue the right data to indicate
1214 1215 1216 1217
 *	the error case if necessary.
 *
 *	n_tty_receive_buf()/producer path:
 *		caller holds non-exclusive termios_rwsem
L
Linus Torvalds 已提交
1218
 */
1219
static void n_tty_receive_parity_error(struct tty_struct *tty, unsigned char c)
L
Linus Torvalds 已提交
1220
{
J
Jiri Slaby 已提交
1221 1222
	struct n_tty_data *ldata = tty->disc_data;

P
Peter Hurley 已提交
1223 1224 1225 1226 1227 1228 1229 1230 1231 1232
	if (I_INPCK(tty)) {
		if (I_IGNPAR(tty))
			return;
		if (I_PARMRK(tty)) {
			put_tty_queue('\377', ldata);
			put_tty_queue('\0', ldata);
			put_tty_queue(c, ldata);
		} else
			put_tty_queue('\0', ldata);
	} else
J
Jiri Slaby 已提交
1233
		put_tty_queue(c, ldata);
L
Linus Torvalds 已提交
1234 1235
}

1236 1237 1238
static void
n_tty_receive_signal_char(struct tty_struct *tty, int signal, unsigned char c)
{
1239
	isig(signal, tty);
1240 1241 1242 1243 1244
	if (I_IXON(tty))
		start_tty(tty);
	if (L_ECHO(tty)) {
		echo_char(c, tty);
		commit_echoes(tty);
P
Peter Hurley 已提交
1245 1246
	} else
		process_echoes(tty);
1247 1248 1249
	return;
}

L
Linus Torvalds 已提交
1250 1251 1252 1253 1254 1255
/**
 *	n_tty_receive_char	-	perform processing
 *	@tty: terminal device
 *	@c: character
 *
 *	Process an individual character of input received from the driver.
1256
 *	This is serialized with respect to itself by the rules for the
L
Linus Torvalds 已提交
1257
 *	driver above.
1258 1259 1260 1261
 *
 *	n_tty_receive_buf()/producer path:
 *		caller holds non-exclusive termios_rwsem
 *		publishes canon_head if canonical mode is active
1262 1263
 *
 *	Returns 1 if LNEXT was received, else returns 0
L
Linus Torvalds 已提交
1264 1265
 */

1266
static int
P
Peter Hurley 已提交
1267
n_tty_receive_char_special(struct tty_struct *tty, unsigned char c)
L
Linus Torvalds 已提交
1268
{
1269
	struct n_tty_data *ldata = tty->disc_data;
L
Linus Torvalds 已提交
1270 1271 1272 1273

	if (I_IXON(tty)) {
		if (c == START_CHAR(tty)) {
			start_tty(tty);
P
Peter Hurley 已提交
1274
			process_echoes(tty);
1275
			return 0;
L
Linus Torvalds 已提交
1276 1277 1278
		}
		if (c == STOP_CHAR(tty)) {
			stop_tty(tty);
1279
			return 0;
L
Linus Torvalds 已提交
1280 1281
		}
	}
1282

L
Linus Torvalds 已提交
1283
	if (L_ISIG(tty)) {
1284 1285
		if (c == INTR_CHAR(tty)) {
			n_tty_receive_signal_char(tty, SIGINT, c);
1286
			return 0;
1287 1288
		} else if (c == QUIT_CHAR(tty)) {
			n_tty_receive_signal_char(tty, SIGQUIT, c);
1289
			return 0;
1290 1291
		} else if (c == SUSP_CHAR(tty)) {
			n_tty_receive_signal_char(tty, SIGTSTP, c);
1292
			return 0;
L
Linus Torvalds 已提交
1293 1294
		}
	}
1295

1296 1297 1298 1299 1300
	if (tty->stopped && !tty->flow_stopped && I_IXON(tty) && I_IXANY(tty)) {
		start_tty(tty);
		process_echoes(tty);
	}

1301 1302
	if (c == '\r') {
		if (I_IGNCR(tty))
1303
			return 0;
1304 1305 1306 1307 1308
		if (I_ICRNL(tty))
			c = '\n';
	} else if (c == '\n' && I_INLCR(tty))
		c = '\r';

1309
	if (ldata->icanon) {
L
Linus Torvalds 已提交
1310 1311 1312
		if (c == ERASE_CHAR(tty) || c == KILL_CHAR(tty) ||
		    (c == WERASE_CHAR(tty) && L_IEXTEN(tty))) {
			eraser(c, tty);
P
Peter Hurley 已提交
1313
			commit_echoes(tty);
1314
			return 0;
L
Linus Torvalds 已提交
1315 1316
		}
		if (c == LNEXT_CHAR(tty) && L_IEXTEN(tty)) {
1317
			ldata->lnext = 1;
L
Linus Torvalds 已提交
1318
			if (L_ECHO(tty)) {
J
Jiri Slaby 已提交
1319
				finish_erasing(ldata);
L
Linus Torvalds 已提交
1320
				if (L_ECHOCTL(tty)) {
J
Jiri Slaby 已提交
1321 1322
					echo_char_raw('^', ldata);
					echo_char_raw('\b', ldata);
P
Peter Hurley 已提交
1323
					commit_echoes(tty);
L
Linus Torvalds 已提交
1324 1325
				}
			}
1326
			return 1;
L
Linus Torvalds 已提交
1327
		}
1328
		if (c == REPRINT_CHAR(tty) && L_ECHO(tty) && L_IEXTEN(tty)) {
1329
			size_t tail = ldata->canon_head;
L
Linus Torvalds 已提交
1330

J
Jiri Slaby 已提交
1331
			finish_erasing(ldata);
L
Linus Torvalds 已提交
1332
			echo_char(c, tty);
J
Jiri Slaby 已提交
1333
			echo_char_raw('\n', ldata);
1334
			while (MASK(tail) != MASK(ldata->read_head)) {
1335 1336
				echo_char(read_buf(ldata, tail), tty);
				tail++;
L
Linus Torvalds 已提交
1337
			}
P
Peter Hurley 已提交
1338
			commit_echoes(tty);
1339
			return 0;
L
Linus Torvalds 已提交
1340 1341
		}
		if (c == '\n') {
1342
			if (L_ECHO(tty) || L_ECHONL(tty)) {
J
Jiri Slaby 已提交
1343
				echo_char_raw('\n', ldata);
P
Peter Hurley 已提交
1344
				commit_echoes(tty);
L
Linus Torvalds 已提交
1345 1346 1347 1348 1349 1350 1351 1352 1353 1354 1355 1356 1357 1358
			}
			goto handle_newline;
		}
		if (c == EOF_CHAR(tty)) {
			c = __DISABLED_CHAR;
			goto handle_newline;
		}
		if ((c == EOL_CHAR(tty)) ||
		    (c == EOL2_CHAR(tty) && L_IEXTEN(tty))) {
			/*
			 * XXX are EOL_CHAR and EOL2_CHAR echoed?!?
			 */
			if (L_ECHO(tty)) {
				/* Record the column of first canon char. */
1359
				if (ldata->canon_head == ldata->read_head)
J
Jiri Slaby 已提交
1360
					echo_set_canon_col(ldata);
L
Linus Torvalds 已提交
1361
				echo_char(c, tty);
P
Peter Hurley 已提交
1362
				commit_echoes(tty);
L
Linus Torvalds 已提交
1363 1364 1365 1366 1367
			}
			/*
			 * XXX does PARMRK doubling happen for
			 * EOL_CHAR and EOL2_CHAR?
			 */
1368
			if (c == (unsigned char) '\377' && I_PARMRK(tty))
J
Jiri Slaby 已提交
1369
				put_tty_queue(c, ldata);
L
Linus Torvalds 已提交
1370

1371
handle_newline:
1372
			set_bit(ldata->read_head & (N_TTY_BUF_SIZE - 1), ldata->read_flags);
1373
			put_tty_queue(c, ldata);
1374
			smp_store_release(&ldata->canon_head, ldata->read_head);
L
Linus Torvalds 已提交
1375
			kill_fasync(&tty->fasync, SIGIO, POLL_IN);
1376
			wake_up_interruptible_poll(&tty->read_wait, EPOLLIN);
1377
			return 0;
L
Linus Torvalds 已提交
1378 1379
		}
	}
1380

1381
	if (L_ECHO(tty)) {
J
Jiri Slaby 已提交
1382
		finish_erasing(ldata);
L
Linus Torvalds 已提交
1383
		if (c == '\n')
J
Jiri Slaby 已提交
1384
			echo_char_raw('\n', ldata);
L
Linus Torvalds 已提交
1385 1386
		else {
			/* Record the column of first canon char. */
1387
			if (ldata->canon_head == ldata->read_head)
J
Jiri Slaby 已提交
1388
				echo_set_canon_col(ldata);
L
Linus Torvalds 已提交
1389 1390
			echo_char(c, tty);
		}
P
Peter Hurley 已提交
1391
		commit_echoes(tty);
L
Linus Torvalds 已提交
1392 1393
	}

1394 1395
	/* PARMRK doubling check */
	if (c == (unsigned char) '\377' && I_PARMRK(tty))
J
Jiri Slaby 已提交
1396
		put_tty_queue(c, ldata);
L
Linus Torvalds 已提交
1397

J
Jiri Slaby 已提交
1398
	put_tty_queue(c, ldata);
1399
	return 0;
1400
}
L
Linus Torvalds 已提交
1401

1402 1403
static inline void
n_tty_receive_char_inline(struct tty_struct *tty, unsigned char c)
P
Peter Hurley 已提交
1404 1405 1406
{
	struct n_tty_data *ldata = tty->disc_data;

1407 1408 1409 1410 1411 1412 1413 1414 1415 1416 1417
	if (tty->stopped && !tty->flow_stopped && I_IXON(tty) && I_IXANY(tty)) {
		start_tty(tty);
		process_echoes(tty);
	}
	if (L_ECHO(tty)) {
		finish_erasing(ldata);
		/* Record the column of first canon char. */
		if (ldata->canon_head == ldata->read_head)
			echo_set_canon_col(ldata);
		echo_char(c, tty);
		commit_echoes(tty);
P
Peter Hurley 已提交
1418
	}
1419 1420
	/* PARMRK doubling check */
	if (c == (unsigned char) '\377' && I_PARMRK(tty))
1421 1422 1423
		put_tty_queue(c, ldata);
	put_tty_queue(c, ldata);
}
P
Peter Hurley 已提交
1424

1425
static void n_tty_receive_char(struct tty_struct *tty, unsigned char c)
1426 1427
{
	n_tty_receive_char_inline(tty, c);
P
Peter Hurley 已提交
1428 1429
}

1430 1431 1432 1433 1434
static inline void
n_tty_receive_char_fast(struct tty_struct *tty, unsigned char c)
{
	struct n_tty_data *ldata = tty->disc_data;

1435 1436 1437
	if (tty->stopped && !tty->flow_stopped && I_IXON(tty) && I_IXANY(tty)) {
		start_tty(tty);
		process_echoes(tty);
1438
	}
1439 1440 1441 1442 1443 1444 1445 1446 1447
	if (L_ECHO(tty)) {
		finish_erasing(ldata);
		/* Record the column of first canon char. */
		if (ldata->canon_head == ldata->read_head)
			echo_set_canon_col(ldata);
		echo_char(c, tty);
		commit_echoes(tty);
	}
	put_tty_queue(c, ldata);
1448 1449
}

1450
static void n_tty_receive_char_closing(struct tty_struct *tty, unsigned char c)
1451 1452 1453 1454 1455 1456 1457 1458 1459 1460 1461 1462 1463 1464 1465 1466 1467 1468 1469
{
	if (I_ISTRIP(tty))
		c &= 0x7f;
	if (I_IUCLC(tty) && L_IEXTEN(tty))
		c = tolower(c);

	if (I_IXON(tty)) {
		if (c == STOP_CHAR(tty))
			stop_tty(tty);
		else if (c == START_CHAR(tty) ||
			 (tty->stopped && !tty->flow_stopped && I_IXANY(tty) &&
			  c != INTR_CHAR(tty) && c != QUIT_CHAR(tty) &&
			  c != SUSP_CHAR(tty))) {
			start_tty(tty);
			process_echoes(tty);
		}
	}
}

1470 1471 1472 1473 1474 1475 1476 1477 1478 1479 1480 1481 1482 1483 1484
static void
n_tty_receive_char_flagged(struct tty_struct *tty, unsigned char c, char flag)
{
	switch (flag) {
	case TTY_BREAK:
		n_tty_receive_break(tty);
		break;
	case TTY_PARITY:
	case TTY_FRAME:
		n_tty_receive_parity_error(tty, c);
		break;
	case TTY_OVERRUN:
		n_tty_receive_overrun(tty);
		break;
	default:
P
Peter Hurley 已提交
1485
		tty_err(tty, "unknown flag %d\n", flag);
1486 1487 1488 1489
		break;
	}
}

1490 1491 1492 1493 1494 1495 1496 1497 1498 1499 1500 1501 1502 1503 1504 1505
static void
n_tty_receive_char_lnext(struct tty_struct *tty, unsigned char c, char flag)
{
	struct n_tty_data *ldata = tty->disc_data;

	ldata->lnext = 0;
	if (likely(flag == TTY_NORMAL)) {
		if (I_ISTRIP(tty))
			c &= 0x7f;
		if (I_IUCLC(tty) && L_IEXTEN(tty))
			c = tolower(c);
		n_tty_receive_char(tty, c);
	} else
		n_tty_receive_char_flagged(tty, c, flag);
}

1506 1507 1508 1509 1510 1511 1512 1513
static void
n_tty_receive_buf_real_raw(struct tty_struct *tty, const unsigned char *cp,
			   char *fp, int count)
{
	struct n_tty_data *ldata = tty->disc_data;
	size_t n, head;

	head = ldata->read_head & (N_TTY_BUF_SIZE - 1);
1514
	n = min_t(size_t, count, N_TTY_BUF_SIZE - head);
1515 1516 1517 1518 1519 1520
	memcpy(read_buf_addr(ldata, head), cp, n);
	ldata->read_head += n;
	cp += n;
	count -= n;

	head = ldata->read_head & (N_TTY_BUF_SIZE - 1);
1521
	n = min_t(size_t, count, N_TTY_BUF_SIZE - head);
1522 1523 1524 1525
	memcpy(read_buf_addr(ldata, head), cp, n);
	ldata->read_head += n;
}

1526 1527 1528 1529 1530 1531 1532 1533 1534 1535 1536 1537 1538 1539 1540 1541 1542
static void
n_tty_receive_buf_raw(struct tty_struct *tty, const unsigned char *cp,
		      char *fp, int count)
{
	struct n_tty_data *ldata = tty->disc_data;
	char flag = TTY_NORMAL;

	while (count--) {
		if (fp)
			flag = *fp++;
		if (likely(flag == TTY_NORMAL))
			put_tty_queue(*cp++, ldata);
		else
			n_tty_receive_char_flagged(tty, *cp++, flag);
	}
}

1543 1544 1545 1546 1547 1548 1549 1550 1551 1552 1553 1554 1555 1556
static void
n_tty_receive_buf_closing(struct tty_struct *tty, const unsigned char *cp,
			  char *fp, int count)
{
	char flag = TTY_NORMAL;

	while (count--) {
		if (fp)
			flag = *fp++;
		if (likely(flag == TTY_NORMAL))
			n_tty_receive_char_closing(tty, *cp++);
	}
}

1557 1558
static void
n_tty_receive_buf_standard(struct tty_struct *tty, const unsigned char *cp,
1559 1560 1561 1562 1563 1564 1565 1566 1567 1568 1569 1570 1571 1572 1573 1574 1575 1576 1577
			  char *fp, int count)
{
	struct n_tty_data *ldata = tty->disc_data;
	char flag = TTY_NORMAL;

	while (count--) {
		if (fp)
			flag = *fp++;
		if (likely(flag == TTY_NORMAL)) {
			unsigned char c = *cp++;

			if (I_ISTRIP(tty))
				c &= 0x7f;
			if (I_IUCLC(tty) && L_IEXTEN(tty))
				c = tolower(c);
			if (L_EXTPROC(tty)) {
				put_tty_queue(c, ldata);
				continue;
			}
1578 1579 1580 1581 1582 1583 1584 1585
			if (!test_bit(c, ldata->char_map))
				n_tty_receive_char_inline(tty, c);
			else if (n_tty_receive_char_special(tty, c) && count) {
				if (fp)
					flag = *fp++;
				n_tty_receive_char_lnext(tty, *cp++, flag);
				count--;
			}
1586 1587 1588 1589 1590 1591 1592 1593
		} else
			n_tty_receive_char_flagged(tty, *cp++, flag);
	}
}

static void
n_tty_receive_buf_fast(struct tty_struct *tty, const unsigned char *cp,
		       char *fp, int count)
1594
{
1595
	struct n_tty_data *ldata = tty->disc_data;
1596 1597 1598 1599 1600
	char flag = TTY_NORMAL;

	while (count--) {
		if (fp)
			flag = *fp++;
1601 1602 1603 1604 1605 1606 1607 1608 1609 1610 1611 1612
		if (likely(flag == TTY_NORMAL)) {
			unsigned char c = *cp++;

			if (!test_bit(c, ldata->char_map))
				n_tty_receive_char_fast(tty, c);
			else if (n_tty_receive_char_special(tty, c) && count) {
				if (fp)
					flag = *fp++;
				n_tty_receive_char_lnext(tty, *cp++, flag);
				count--;
			}
		} else
1613 1614 1615 1616
			n_tty_receive_char_flagged(tty, *cp++, flag);
	}
}

1617 1618
static void __receive_buf(struct tty_struct *tty, const unsigned char *cp,
			  char *fp, int count)
L
Linus Torvalds 已提交
1619
{
1620
	struct n_tty_data *ldata = tty->disc_data;
1621
	bool preops = I_ISTRIP(tty) || (I_IUCLC(tty) && L_IEXTEN(tty));
L
Linus Torvalds 已提交
1622

1623 1624
	if (ldata->real_raw)
		n_tty_receive_buf_real_raw(tty, cp, fp, count);
1625
	else if (ldata->raw || (L_EXTPROC(tty) && !preops))
1626
		n_tty_receive_buf_raw(tty, cp, fp, count);
1627 1628
	else if (tty->closing && !L_EXTPROC(tty))
		n_tty_receive_buf_closing(tty, cp, fp, count);
1629
	else {
1630 1631 1632 1633 1634 1635 1636 1637 1638
		if (ldata->lnext) {
			char flag = TTY_NORMAL;

			if (fp)
				flag = *fp++;
			n_tty_receive_char_lnext(tty, *cp++, flag);
			count--;
		}

1639
		if (!preops && !I_PARMRK(tty))
1640 1641 1642
			n_tty_receive_buf_fast(tty, cp, fp, count);
		else
			n_tty_receive_buf_standard(tty, cp, fp, count);
P
Peter Hurley 已提交
1643 1644

		flush_echoes(tty);
A
Alan Cox 已提交
1645 1646
		if (tty->ops->flush_chars)
			tty->ops->flush_chars(tty);
L
Linus Torvalds 已提交
1647 1648
	}

1649 1650 1651 1652 1653 1654
	if (ldata->icanon && !L_EXTPROC(tty))
		return;

	/* publish read_head to consumer */
	smp_store_release(&ldata->commit_head, ldata->read_head);

1655
	if (read_cnt(ldata)) {
L
Linus Torvalds 已提交
1656
		kill_fasync(&tty->fasync, SIGIO, POLL_IN);
1657
		wake_up_interruptible_poll(&tty->read_wait, EPOLLIN);
L
Linus Torvalds 已提交
1658 1659 1660
	}
}

1661 1662 1663 1664 1665 1666
/**
 *	n_tty_receive_buf_common	-	process input
 *	@tty: device to receive input
 *	@cp: input chars
 *	@fp: flags for each char (if NULL, all chars are TTY_NORMAL)
 *	@count: number of input chars in @cp
1667
 *	@flow: enable flow control
1668 1669 1670 1671 1672 1673 1674 1675 1676 1677 1678 1679 1680 1681 1682 1683 1684 1685 1686 1687 1688 1689 1690 1691 1692 1693 1694
 *
 *	Called by the terminal driver when a block of characters has
 *	been received. This function must be called from soft contexts
 *	not from interrupt context. The driver is responsible for making
 *	calls one at a time and in order (or using flush_to_ldisc)
 *
 *	Returns the # of input chars from @cp which were processed.
 *
 *	In canonical mode, the maximum line length is 4096 chars (including
 *	the line termination char); lines longer than 4096 chars are
 *	truncated. After 4095 chars, input data is still processed but
 *	not stored. Overflow processing ensures the tty can always
 *	receive more input until at least one line can be read.
 *
 *	In non-canonical mode, the read buffer will only accept 4095 chars;
 *	this provides the necessary space for a newline char if the input
 *	mode is switched to canonical.
 *
 *	Note it is possible for the read buffer to _contain_ 4096 chars
 *	in non-canonical mode: the read buffer could already contain the
 *	maximum canon line of 4096 chars when the mode is switched to
 *	non-canonical.
 *
 *	n_tty_receive_buf()/producer path:
 *		claims non-exclusive termios_rwsem
 *		publishes commit_head or canon_head
 */
P
Peter Hurley 已提交
1695 1696 1697
static int
n_tty_receive_buf_common(struct tty_struct *tty, const unsigned char *cp,
			 char *fp, int count, int flow)
1698 1699
{
	struct n_tty_data *ldata = tty->disc_data;
1700
	int room, n, rcvd = 0, overflow;
1701

1702 1703
	down_read(&tty->termios_rwsem);

1704
	do {
1705
		/*
P
Peter Hurley 已提交
1706 1707
		 * When PARMRK is set, each input char may take up to 3 chars
		 * in the read buf; reduce the buffer space avail by 3x
1708 1709 1710 1711 1712 1713 1714 1715 1716 1717 1718 1719
		 *
		 * If we are doing input canonicalization, and there are no
		 * pending newlines, let characters through without limit, so
		 * that erase characters will be handled.  Other excess
		 * characters will be beeped.
		 *
		 * paired with store in *_copy_from_read_buf() -- guarantees
		 * the consumer has loaded the data in read_buf up to the new
		 * read_tail (so this producer will not overwrite unread data)
		 */
		size_t tail = smp_load_acquire(&ldata->read_tail);

1720
		room = N_TTY_BUF_SIZE - (ldata->read_head - tail);
1721
		if (I_PARMRK(tty))
1722 1723 1724 1725 1726 1727 1728 1729 1730 1731
			room = (room + 2) / 3;
		room--;
		if (room <= 0) {
			overflow = ldata->icanon && ldata->canon_head == tail;
			if (overflow && room < 0)
				ldata->read_head--;
			room = overflow;
			ldata->no_room = flow && !room;
		} else
			overflow = 0;
1732

1733
		n = min(count, room);
1734
		if (!n)
1735
			break;
1736 1737 1738 1739 1740

		/* ignore parity errors if handling overflow */
		if (!overflow || !fp || *fp != TTY_PARITY)
			__receive_buf(tty, cp, fp, n);

1741 1742 1743 1744 1745
		cp += n;
		if (fp)
			fp += n;
		count -= n;
		rcvd += n;
1746
	} while (!test_bit(TTY_LDISC_CHANGING, &tty->flags));
1747

1748
	tty->receive_room = room;
1749 1750 1751 1752 1753 1754 1755 1756 1757 1758 1759

	/* Unthrottle if handling overflow on pty */
	if (tty->driver->type == TTY_DRIVER_TYPE_PTY) {
		if (overflow) {
			tty_set_flow_change(tty, TTY_UNTHROTTLE_SAFE);
			tty_unthrottle_safe(tty);
			__tty_set_flow_change(tty, 0);
		}
	} else
		n_tty_check_throttle(tty);

1760 1761
	up_read(&tty->termios_rwsem);

1762
	return rcvd;
1763 1764
}

P
Peter Hurley 已提交
1765 1766 1767 1768 1769 1770 1771 1772 1773 1774 1775 1776
static void n_tty_receive_buf(struct tty_struct *tty, const unsigned char *cp,
			      char *fp, int count)
{
	n_tty_receive_buf_common(tty, cp, fp, count, 0);
}

static int n_tty_receive_buf2(struct tty_struct *tty, const unsigned char *cp,
			      char *fp, int count)
{
	return n_tty_receive_buf_common(tty, cp, fp, count, 1);
}

L
Linus Torvalds 已提交
1777 1778 1779 1780 1781 1782 1783
/**
 *	n_tty_set_termios	-	termios data changed
 *	@tty: terminal
 *	@old: previous data
 *
 *	Called by the tty layer when the user changes termios flags so
 *	that the line discipline can plan ahead. This function cannot sleep
1784
 *	and is protected from re-entry by the tty layer. The user is
L
Linus Torvalds 已提交
1785 1786
 *	guaranteed that this function will not be re-entered or in progress
 *	when the ldisc is closed.
1787
 *
1788
 *	Locking: Caller holds tty->termios_rwsem
L
Linus Torvalds 已提交
1789
 */
1790 1791

static void n_tty_set_termios(struct tty_struct *tty, struct ktermios *old)
L
Linus Torvalds 已提交
1792
{
1793
	struct n_tty_data *ldata = tty->disc_data;
1794

1795
	if (!old || (old->c_lflag ^ tty->termios.c_lflag) & (ICANON | EXTPROC)) {
1796
		bitmap_zero(ldata->read_flags, N_TTY_BUF_SIZE);
1797 1798 1799 1800 1801 1802 1803 1804 1805 1806
		ldata->line_start = ldata->read_tail;
		if (!L_ICANON(tty) || !read_cnt(ldata)) {
			ldata->canon_head = ldata->read_tail;
			ldata->push = 0;
		} else {
			set_bit((ldata->read_head - 1) & (N_TTY_BUF_SIZE - 1),
				ldata->read_flags);
			ldata->canon_head = ldata->read_head;
			ldata->push = 1;
		}
1807
		ldata->commit_head = ldata->read_head;
1808
		ldata->erasing = 0;
1809
		ldata->lnext = 0;
1810 1811
	}

1812
	ldata->icanon = (L_ICANON(tty) != 0);
P
Peter Hurley 已提交
1813

L
Linus Torvalds 已提交
1814 1815 1816 1817
	if (I_ISTRIP(tty) || I_IUCLC(tty) || I_IGNCR(tty) ||
	    I_ICRNL(tty) || I_INLCR(tty) || L_ICANON(tty) ||
	    I_IXON(tty) || L_ISIG(tty) || L_ECHO(tty) ||
	    I_PARMRK(tty)) {
1818
		bitmap_zero(ldata->char_map, 256);
L
Linus Torvalds 已提交
1819 1820

		if (I_IGNCR(tty) || I_ICRNL(tty))
1821
			set_bit('\r', ldata->char_map);
L
Linus Torvalds 已提交
1822
		if (I_INLCR(tty))
1823
			set_bit('\n', ldata->char_map);
L
Linus Torvalds 已提交
1824 1825

		if (L_ICANON(tty)) {
1826 1827 1828 1829 1830
			set_bit(ERASE_CHAR(tty), ldata->char_map);
			set_bit(KILL_CHAR(tty), ldata->char_map);
			set_bit(EOF_CHAR(tty), ldata->char_map);
			set_bit('\n', ldata->char_map);
			set_bit(EOL_CHAR(tty), ldata->char_map);
L
Linus Torvalds 已提交
1831
			if (L_IEXTEN(tty)) {
1832 1833 1834
				set_bit(WERASE_CHAR(tty), ldata->char_map);
				set_bit(LNEXT_CHAR(tty), ldata->char_map);
				set_bit(EOL2_CHAR(tty), ldata->char_map);
L
Linus Torvalds 已提交
1835 1836
				if (L_ECHO(tty))
					set_bit(REPRINT_CHAR(tty),
1837
						ldata->char_map);
L
Linus Torvalds 已提交
1838 1839 1840
			}
		}
		if (I_IXON(tty)) {
1841 1842
			set_bit(START_CHAR(tty), ldata->char_map);
			set_bit(STOP_CHAR(tty), ldata->char_map);
L
Linus Torvalds 已提交
1843 1844
		}
		if (L_ISIG(tty)) {
1845 1846 1847
			set_bit(INTR_CHAR(tty), ldata->char_map);
			set_bit(QUIT_CHAR(tty), ldata->char_map);
			set_bit(SUSP_CHAR(tty), ldata->char_map);
L
Linus Torvalds 已提交
1848
		}
1849
		clear_bit(__DISABLED_CHAR, ldata->char_map);
1850 1851
		ldata->raw = 0;
		ldata->real_raw = 0;
L
Linus Torvalds 已提交
1852
	} else {
1853
		ldata->raw = 1;
L
Linus Torvalds 已提交
1854 1855 1856
		if ((I_IGNBRK(tty) || (!I_BRKINT(tty) && !I_PARMRK(tty))) &&
		    (I_IGNPAR(tty) || !I_INPCK(tty)) &&
		    (tty->driver->flags & TTY_DRIVER_REAL_RAW))
1857
			ldata->real_raw = 1;
L
Linus Torvalds 已提交
1858
		else
1859
			ldata->real_raw = 0;
L
Linus Torvalds 已提交
1860
	}
1861 1862 1863 1864
	/*
	 * Fix tty hang when I_IXON(tty) is cleared, but the tty
	 * been stopped by STOP_CHAR(tty) before it.
	 */
P
Peter Hurley 已提交
1865
	if (!I_IXON(tty) && old && (old->c_iflag & IXON) && !tty->flow_stopped) {
1866
		start_tty(tty);
P
Peter Hurley 已提交
1867 1868
		process_echoes(tty);
	}
1869

A
Alan Cox 已提交
1870
	/* The termios change make the tty ready for I/O */
1871 1872
	wake_up_interruptible(&tty->write_wait);
	wake_up_interruptible(&tty->read_wait);
L
Linus Torvalds 已提交
1873 1874 1875 1876 1877 1878
}

/**
 *	n_tty_close		-	close the ldisc for this tty
 *	@tty: device
 *
1879 1880
 *	Called from the terminal layer when this line discipline is
 *	being shut down, either because of a close or becsuse of a
L
Linus Torvalds 已提交
1881 1882 1883
 *	discipline change. The function will not be called while other
 *	ldisc methods are in progress.
 */
1884

L
Linus Torvalds 已提交
1885 1886
static void n_tty_close(struct tty_struct *tty)
{
J
Jiri Slaby 已提交
1887 1888
	struct n_tty_data *ldata = tty->disc_data;

1889 1890 1891
	if (tty->link)
		n_tty_packet_mode_flush(tty);

1892
	down_write(&tty->termios_rwsem);
1893
	vfree(ldata);
J
Jiri Slaby 已提交
1894
	tty->disc_data = NULL;
1895
	up_write(&tty->termios_rwsem);
L
Linus Torvalds 已提交
1896 1897 1898 1899 1900 1901
}

/**
 *	n_tty_open		-	open an ldisc
 *	@tty: terminal to open
 *
1902
 *	Called when this line discipline is being attached to the
L
Linus Torvalds 已提交
1903 1904 1905 1906 1907 1908 1909
 *	terminal device. Can sleep. Called serialized so that no
 *	other events will occur in parallel. No further open will occur
 *	until a close.
 */

static int n_tty_open(struct tty_struct *tty)
{
J
Jiri Slaby 已提交
1910 1911
	struct n_tty_data *ldata;

1912
	/* Currently a malloc failure here can panic */
1913
	ldata = vzalloc(sizeof(*ldata));
J
Jiri Slaby 已提交
1914
	if (!ldata)
1915
		return -ENOMEM;
J
Jiri Slaby 已提交
1916

1917
	ldata->overrun_time = jiffies;
1918 1919
	mutex_init(&ldata->atomic_read_lock);
	mutex_init(&ldata->output_lock);
1920

J
Jiri Slaby 已提交
1921
	tty->disc_data = ldata;
L
Linus Torvalds 已提交
1922
	tty->closing = 0;
1923 1924 1925 1926
	/* indicate buffer work may resume */
	clear_bit(TTY_LDISC_HALTED, &tty->flags);
	n_tty_set_termios(tty, NULL);
	tty_unthrottle(tty);
L
Linus Torvalds 已提交
1927 1928 1929
	return 0;
}

1930
static inline int input_available_p(struct tty_struct *tty, int poll)
L
Linus Torvalds 已提交
1931
{
1932
	struct n_tty_data *ldata = tty->disc_data;
1933
	int amt = poll && !TIME_CHAR(tty) && MIN_CHAR(tty) ? MIN_CHAR(tty) : 1;
1934

1935 1936 1937
	if (ldata->icanon && !L_EXTPROC(tty))
		return ldata->canon_head != ldata->read_tail;
	else
1938
		return ldata->commit_head - ldata->read_tail >= amt;
L
Linus Torvalds 已提交
1939 1940 1941
}

/**
1942
 *	copy_from_read_buf	-	copy read data directly
L
Linus Torvalds 已提交
1943
 *	@tty: terminal device
1944
 *	@kbp: data
L
Linus Torvalds 已提交
1945 1946
 *	@nr: size of data
 *
1947
 *	Helper function to speed up n_tty_read.  It is only called when
1948
 *	ICANON is off; it copies characters straight from the tty queue.
L
Linus Torvalds 已提交
1949
 *
1950
 *	Called under the ldata->atomic_read_lock sem
L
Linus Torvalds 已提交
1951
 *
1952 1953 1954
 *	Returns true if it successfully copied data, but there is still
 *	more data to be had.
 *
1955 1956 1957
 *	n_tty_read()/consumer path:
 *		caller holds non-exclusive termios_rwsem
 *		read_tail published
L
Linus Torvalds 已提交
1958
 */
1959

1960
static bool copy_from_read_buf(struct tty_struct *tty,
1961
				      unsigned char **kbp,
L
Linus Torvalds 已提交
1962 1963 1964
				      size_t *nr)

{
1965
	struct n_tty_data *ldata = tty->disc_data;
L
Linus Torvalds 已提交
1966
	size_t n;
1967
	bool is_eof;
1968
	size_t head = smp_load_acquire(&ldata->commit_head);
1969
	size_t tail = ldata->read_tail & (N_TTY_BUF_SIZE - 1);
L
Linus Torvalds 已提交
1970

1971
	n = min(head - ldata->read_tail, N_TTY_BUF_SIZE - tail);
L
Linus Torvalds 已提交
1972 1973
	n = min(*nr, n);
	if (n) {
G
Greg KH 已提交
1974
		unsigned char *from = read_buf_addr(ldata, tail);
1975
		memcpy(*kbp, from, n);
P
Peter Hurley 已提交
1976
		is_eof = n == 1 && *from == EOF_CHAR(tty);
1977
		tty_audit_add_data(tty, from, n);
G
Greg KH 已提交
1978
		zero_buffer(tty, from, n);
1979
		smp_store_release(&ldata->read_tail, ldata->read_tail + n);
1980
		/* Turn single EOF into zero-length read */
1981 1982
		if (L_EXTPROC(tty) && ldata->icanon && is_eof &&
		    (head == ldata->read_tail))
1983
			return false;
1984
		*kbp += n;
L
Linus Torvalds 已提交
1985
		*nr -= n;
1986 1987 1988

		/* If we have more to copy, let the caller know */
		return head != ldata->read_tail;
L
Linus Torvalds 已提交
1989
	}
1990
	return false;
L
Linus Torvalds 已提交
1991 1992
}

1993
/**
1994
 *	canon_copy_from_read_buf	-	copy read data in canonical mode
1995
 *	@tty: terminal device
1996
 *	@kbp: data
1997 1998 1999
 *	@nr: size of data
 *
 *	Helper function for n_tty_read.  It is only called when ICANON is on;
2000
 *	it copies one line of input up to and including the line-delimiting
2001
 *	character into the result buffer.
2002
 *
2003 2004 2005 2006 2007 2008
 *	NB: When termios is changed from non-canonical to canonical mode and
 *	the read buffer contains data, n_tty_set_termios() simulates an EOF
 *	push (as if C-d were input) _without_ the DISABLED_CHAR in the buffer.
 *	This causes data already processed as input to be immediately available
 *	as input although a newline has not been received.
 *
2009
 *	Called under the atomic_read_lock mutex
2010 2011 2012 2013
 *
 *	n_tty_read()/consumer path:
 *		caller holds non-exclusive termios_rwsem
 *		read_tail published
2014 2015
 */

2016
static bool canon_copy_from_read_buf(struct tty_struct *tty,
2017 2018
				     unsigned char **kbp,
				     size_t *nr)
2019 2020
{
	struct n_tty_data *ldata = tty->disc_data;
2021
	size_t n, size, more, c;
2022
	size_t eol;
2023
	size_t tail, canon_head;
2024
	int found = 0;
2025 2026

	/* N.B. avoid overrun if nr == 0 */
2027
	if (!*nr)
2028
		return false;
2029

2030 2031
	canon_head = smp_load_acquire(&ldata->canon_head);
	n = min(*nr + 1, canon_head - ldata->read_tail);
2032

2033
	tail = ldata->read_tail & (N_TTY_BUF_SIZE - 1);
2034 2035
	size = min_t(size_t, tail + n, N_TTY_BUF_SIZE);

2036
	n_tty_trace("%s: nr:%zu tail:%zu n:%zu size:%zu\n",
2037 2038 2039 2040 2041 2042 2043
		    __func__, *nr, tail, n, size);

	eol = find_next_bit(ldata->read_flags, size, tail);
	more = n - (size - tail);
	if (eol == N_TTY_BUF_SIZE && more) {
		/* scan wrapped without finding set bit */
		eol = find_next_bit(ldata->read_flags, more, 0);
2044 2045 2046
		found = eol != more;
	} else
		found = eol != size;
2047

2048
	n = eol - tail;
2049 2050
	if (n > N_TTY_BUF_SIZE)
		n += N_TTY_BUF_SIZE;
2051
	c = n + found;
2052

2053 2054 2055
	if (!found || read_buf(ldata, eol) != __DISABLED_CHAR) {
		c = min(*nr, c);
		n = c;
P
Peter Hurley 已提交
2056
	}
2057

P
Peter Hurley 已提交
2058 2059
	n_tty_trace("%s: eol:%zu found:%d n:%zu c:%zu tail:%zu more:%zu\n",
		    __func__, eol, found, n, c, tail, more);
2060

2061 2062
	tty_copy(tty, *kbp, tail, n);
	*kbp += n;
2063 2064
	*nr -= n;

2065
	if (found)
2066
		clear_bit(eol, ldata->read_flags);
2067
	smp_store_release(&ldata->read_tail, ldata->read_tail + c);
2068

P
Peter Hurley 已提交
2069
	if (found) {
2070 2071 2072 2073
		if (!ldata->push)
			ldata->line_start = ldata->read_tail;
		else
			ldata->push = 0;
2074
		tty_audit_push();
2075
		return false;
P
Peter Hurley 已提交
2076
	}
2077 2078 2079

	/* No EOL found - do a continuation retry if there is more data */
	return ldata->read_tail != canon_head;
2080 2081
}

L
Linus Torvalds 已提交
2082 2083 2084 2085 2086 2087
/**
 *	job_control		-	check job control
 *	@tty: tty
 *	@file: file handle
 *
 *	Perform job control management checks on this file/tty descriptor
2088
 *	and if appropriate send any needed signals and return a negative
L
Linus Torvalds 已提交
2089
 *	error code if action should be taken.
A
Alan Cox 已提交
2090
 *
2091 2092 2093
 *	Locking: redirected write test is safe
 *		 current->signal->tty check is safe
 *		 ctrl_lock to safely reference tty->pgrp
L
Linus Torvalds 已提交
2094
 */
2095

L
Linus Torvalds 已提交
2096 2097 2098 2099 2100 2101 2102
static int job_control(struct tty_struct *tty, struct file *file)
{
	/* Job control check -- must be done at start and after
	   every sleep (POSIX.1 7.1.1.4). */
	/* NOTE: not yet done after every sleep pending a thorough
	   check of the logic of this change. -- jlc */
	/* don't stop on /dev/console */
2103
	if (file->f_op->write_iter == redirected_tty_write)
2104 2105
		return 0;

2106
	return __tty_check_change(tty, SIGTTIN);
L
Linus Torvalds 已提交
2107
}
2108

L
Linus Torvalds 已提交
2109 2110

/**
2111
 *	n_tty_read		-	read function for tty
L
Linus Torvalds 已提交
2112 2113 2114 2115 2116 2117 2118 2119 2120 2121 2122
 *	@tty: tty device
 *	@file: file object
 *	@buf: userspace buffer pointer
 *	@nr: size of I/O
 *
 *	Perform reads for the line discipline. We are guaranteed that the
 *	line discipline will not be closed under us but we may get multiple
 *	parallel readers and must handle this ourselves. We may also get
 *	a hangup. Always called in user context, may sleep.
 *
 *	This code must be sure never to sleep through a hangup.
2123 2124 2125 2126
 *
 *	n_tty_read()/consumer path:
 *		claims non-exclusive termios_rwsem
 *		publishes read_tail
L
Linus Torvalds 已提交
2127
 */
2128

2129
static ssize_t n_tty_read(struct tty_struct *tty, struct file *file,
2130 2131
			  unsigned char *kbuf, size_t nr,
			  void **cookie, unsigned long offset)
L
Linus Torvalds 已提交
2132
{
2133
	struct n_tty_data *ldata = tty->disc_data;
2134
	unsigned char *kb = kbuf;
2135
	DEFINE_WAIT_FUNC(wait, woken_wake_function);
2136
	int c;
L
Linus Torvalds 已提交
2137 2138 2139
	int minimum, time;
	ssize_t retval = 0;
	long timeout;
A
Alan Cox 已提交
2140
	int packet;
2141
	size_t tail;
L
Linus Torvalds 已提交
2142

2143 2144 2145 2146 2147 2148 2149
	/*
	 * Is this a continuation of a read started earler?
	 *
	 * If so, we still hold the atomic_read_lock and the
	 * termios_rwsem, and can just continue to copy data.
	 */
	if (*cookie) {
2150 2151 2152 2153 2154 2155 2156
		if (ldata->icanon && !L_EXTPROC(tty)) {
			if (canon_copy_from_read_buf(tty, &kb, &nr))
				return kb - kbuf;
		} else {
			if (copy_from_read_buf(tty, &kb, &nr))
				return kb - kbuf;
		}
2157 2158 2159 2160 2161 2162 2163 2164 2165 2166

		/* No more data - release locks and stop retries */
		n_tty_kick_worker(tty);
		n_tty_check_unthrottle(tty);
		up_read(&tty->termios_rwsem);
		mutex_unlock(&ldata->atomic_read_lock);
		*cookie = NULL;
		return kb - kbuf;
	}

L
Linus Torvalds 已提交
2167
	c = job_control(tty, file);
2168
	if (c < 0)
L
Linus Torvalds 已提交
2169
		return c;
2170

2171 2172 2173 2174 2175 2176 2177 2178 2179 2180 2181
	/*
	 *	Internal serialization of reads.
	 */
	if (file->f_flags & O_NONBLOCK) {
		if (!mutex_trylock(&ldata->atomic_read_lock))
			return -EAGAIN;
	} else {
		if (mutex_lock_interruptible(&ldata->atomic_read_lock))
			return -ERESTARTSYS;
	}

2182 2183
	down_read(&tty->termios_rwsem);

L
Linus Torvalds 已提交
2184 2185
	minimum = time = 0;
	timeout = MAX_SCHEDULE_TIMEOUT;
2186
	if (!ldata->icanon) {
L
Linus Torvalds 已提交
2187 2188
		minimum = MIN_CHAR(tty);
		if (minimum) {
2189
			time = (HZ / 10) * TIME_CHAR(tty);
L
Linus Torvalds 已提交
2190
		} else {
2191
			timeout = (HZ / 10) * TIME_CHAR(tty);
2192
			minimum = 1;
L
Linus Torvalds 已提交
2193 2194 2195
		}
	}

A
Alan Cox 已提交
2196
	packet = tty->packet;
2197
	tail = ldata->read_tail;
L
Linus Torvalds 已提交
2198 2199 2200 2201

	add_wait_queue(&tty->read_wait, &wait);
	while (nr) {
		/* First test for status change. */
A
Alan Cox 已提交
2202
		if (packet && tty->link->ctrl_status) {
L
Linus Torvalds 已提交
2203
			unsigned char cs;
2204
			if (kb != kbuf)
L
Linus Torvalds 已提交
2205
				break;
2206
			spin_lock_irq(&tty->link->ctrl_lock);
L
Linus Torvalds 已提交
2207 2208
			cs = tty->link->ctrl_status;
			tty->link->ctrl_status = 0;
2209
			spin_unlock_irq(&tty->link->ctrl_lock);
2210
			*kb++ = cs;
L
Linus Torvalds 已提交
2211 2212 2213
			nr--;
			break;
		}
2214

L
Linus Torvalds 已提交
2215
		if (!input_available_p(tty, 0)) {
2216
			up_read(&tty->termios_rwsem);
2217 2218 2219 2220 2221 2222 2223 2224 2225
			tty_buffer_flush_work(tty->port);
			down_read(&tty->termios_rwsem);
			if (!input_available_p(tty, 0)) {
				if (test_bit(TTY_OTHER_CLOSED, &tty->flags)) {
					retval = -EIO;
					break;
				}
				if (tty_hung_up_p(file))
					break;
2226 2227 2228 2229 2230 2231
				/*
				 * Abort readers for ttys which never actually
				 * get hung up.  See __tty_hangup().
				 */
				if (test_bit(TTY_HUPPING, &tty->flags))
					break;
2232 2233
				if (!timeout)
					break;
2234
				if (tty_io_nonblock(tty, file)) {
2235 2236 2237 2238 2239 2240 2241 2242
					retval = -EAGAIN;
					break;
				}
				if (signal_pending(current)) {
					retval = -ERESTARTSYS;
					break;
				}
				up_read(&tty->termios_rwsem);
2243

2244 2245
				timeout = wait_woken(&wait, TASK_INTERRUPTIBLE,
						timeout);
2246

2247 2248 2249
				down_read(&tty->termios_rwsem);
				continue;
			}
L
Linus Torvalds 已提交
2250 2251
		}

2252
		if (ldata->icanon && !L_EXTPROC(tty)) {
2253 2254
			if (canon_copy_from_read_buf(tty, &kb, &nr))
				goto more_to_be_read;
L
Linus Torvalds 已提交
2255
		} else {
2256
			/* Deal with packet mode. */
2257 2258
			if (packet && kb == kbuf) {
				*kb++ = TIOCPKT_DATA;
2259 2260 2261
				nr--;
			}

2262 2263 2264 2265 2266 2267 2268 2269 2270 2271
			/*
			 * Copy data, and if there is more to be had
			 * and we have nothing more to wait for, then
			 * let's mark us for retries.
			 *
			 * NOTE! We return here with both the termios_sem
			 * and atomic_read_lock still held, the retries
			 * will release them when done.
			 */
			if (copy_from_read_buf(tty, &kb, &nr) && kb - kbuf >= minimum) {
2272
more_to_be_read:
2273 2274 2275
				remove_wait_queue(&tty->read_wait, &wait);
				*cookie = cookie;
				return kb - kbuf;
L
Linus Torvalds 已提交
2276 2277 2278
			}
		}

2279
		n_tty_check_unthrottle(tty);
L
Linus Torvalds 已提交
2280

2281
		if (kb - kbuf >= minimum)
L
Linus Torvalds 已提交
2282 2283 2284 2285
			break;
		if (time)
			timeout = time;
	}
2286 2287
	if (tail != ldata->read_tail)
		n_tty_kick_worker(tty);
2288 2289
	up_read(&tty->termios_rwsem);

L
Linus Torvalds 已提交
2290
	remove_wait_queue(&tty->read_wait, &wait);
2291 2292
	mutex_unlock(&ldata->atomic_read_lock);

2293 2294
	if (kb - kbuf)
		retval = kb - kbuf;
L
Linus Torvalds 已提交
2295 2296 2297 2298 2299

	return retval;
}

/**
2300
 *	n_tty_write		-	write function for tty
L
Linus Torvalds 已提交
2301 2302 2303 2304 2305
 *	@tty: tty device
 *	@file: file object
 *	@buf: userspace buffer pointer
 *	@nr: size of I/O
 *
2306
 *	Write function of the terminal device.  This is serialized with
L
Linus Torvalds 已提交
2307
 *	respect to other write callers but not to termios changes, reads
2308 2309 2310 2311 2312
 *	and other such events.  Since the receive code will echo characters,
 *	thus calling driver write methods, the output_lock is used in
 *	the output processing functions called here as well as in the
 *	echo processing function to protect the column state and space
 *	left in the buffer.
L
Linus Torvalds 已提交
2313 2314
 *
 *	This code must be sure never to sleep through a hangup.
2315 2316 2317 2318
 *
 *	Locking: output_lock to protect column state and space left
 *		 (note that the process_output*() functions take this
 *		  lock themselves)
L
Linus Torvalds 已提交
2319
 */
2320

2321
static ssize_t n_tty_write(struct tty_struct *tty, struct file *file,
2322
			   const unsigned char *buf, size_t nr)
L
Linus Torvalds 已提交
2323 2324
{
	const unsigned char *b = buf;
2325
	DEFINE_WAIT_FUNC(wait, woken_wake_function);
L
Linus Torvalds 已提交
2326 2327 2328 2329
	int c;
	ssize_t retval = 0;

	/* Job control check -- must be done at start (POSIX.1 7.1.1.4). */
2330
	if (L_TOSTOP(tty) && file->f_op->write_iter != redirected_tty_write) {
L
Linus Torvalds 已提交
2331 2332 2333 2334 2335
		retval = tty_check_change(tty);
		if (retval)
			return retval;
	}

2336 2337
	down_read(&tty->termios_rwsem);

2338 2339
	/* Write out any echoed characters that are still pending */
	process_echoes(tty);
A
Alan Cox 已提交
2340

L
Linus Torvalds 已提交
2341 2342 2343 2344 2345 2346 2347 2348 2349 2350
	add_wait_queue(&tty->write_wait, &wait);
	while (1) {
		if (signal_pending(current)) {
			retval = -ERESTARTSYS;
			break;
		}
		if (tty_hung_up_p(file) || (tty->link && !tty->link->count)) {
			retval = -EIO;
			break;
		}
P
Peter Hurley 已提交
2351
		if (O_OPOST(tty)) {
L
Linus Torvalds 已提交
2352
			while (nr > 0) {
2353
				ssize_t num = process_output_block(tty, b, nr);
L
Linus Torvalds 已提交
2354 2355 2356 2357 2358 2359 2360 2361 2362 2363 2364
				if (num < 0) {
					if (num == -EAGAIN)
						break;
					retval = num;
					goto break_out;
				}
				b += num;
				nr -= num;
				if (nr == 0)
					break;
				c = *b;
2365
				if (process_output(c, tty) < 0)
L
Linus Torvalds 已提交
2366 2367 2368
					break;
				b++; nr--;
			}
A
Alan Cox 已提交
2369 2370
			if (tty->ops->flush_chars)
				tty->ops->flush_chars(tty);
L
Linus Torvalds 已提交
2371
		} else {
2372 2373
			struct n_tty_data *ldata = tty->disc_data;

R
Roman Zippel 已提交
2374
			while (nr > 0) {
2375
				mutex_lock(&ldata->output_lock);
A
Alan Cox 已提交
2376
				c = tty->ops->write(tty, b, nr);
2377
				mutex_unlock(&ldata->output_lock);
R
Roman Zippel 已提交
2378 2379 2380 2381 2382 2383 2384 2385
				if (c < 0) {
					retval = c;
					goto break_out;
				}
				if (!c)
					break;
				b += c;
				nr -= c;
L
Linus Torvalds 已提交
2386 2387 2388 2389
			}
		}
		if (!nr)
			break;
2390
		if (tty_io_nonblock(tty, file)) {
L
Linus Torvalds 已提交
2391 2392 2393
			retval = -EAGAIN;
			break;
		}
2394 2395
		up_read(&tty->termios_rwsem);

2396
		wait_woken(&wait, TASK_INTERRUPTIBLE, MAX_SCHEDULE_TIMEOUT);
2397 2398

		down_read(&tty->termios_rwsem);
L
Linus Torvalds 已提交
2399 2400 2401
	}
break_out:
	remove_wait_queue(&tty->write_wait, &wait);
P
Peter Hurley 已提交
2402
	if (nr && tty->fasync)
2403
		set_bit(TTY_DO_WRITE_WAKEUP, &tty->flags);
2404
	up_read(&tty->termios_rwsem);
L
Linus Torvalds 已提交
2405 2406 2407 2408
	return (b - buf) ? b - buf : retval;
}

/**
2409
 *	n_tty_poll		-	poll method for N_TTY
L
Linus Torvalds 已提交
2410 2411 2412 2413 2414 2415 2416 2417 2418 2419 2420
 *	@tty: terminal device
 *	@file: file accessing it
 *	@wait: poll table
 *
 *	Called when the line discipline is asked to poll() for data or
 *	for special events. This code is not serialized with respect to
 *	other events save open/close.
 *
 *	This code must be sure never to sleep through a hangup.
 *	Called without the kernel lock held - fine
 */
2421

2422
static __poll_t n_tty_poll(struct tty_struct *tty, struct file *file,
2423
							poll_table *wait)
L
Linus Torvalds 已提交
2424
{
2425
	__poll_t mask = 0;
L
Linus Torvalds 已提交
2426 2427 2428

	poll_wait(file, &tty->read_wait, wait);
	poll_wait(file, &tty->write_wait, wait);
2429
	if (input_available_p(tty, 1))
2430
		mask |= EPOLLIN | EPOLLRDNORM;
2431 2432 2433
	else {
		tty_buffer_flush_work(tty->port);
		if (input_available_p(tty, 1))
2434
			mask |= EPOLLIN | EPOLLRDNORM;
2435
	}
L
Linus Torvalds 已提交
2436
	if (tty->packet && tty->link->ctrl_status)
2437
		mask |= EPOLLPRI | EPOLLIN | EPOLLRDNORM;
2438
	if (test_bit(TTY_OTHER_CLOSED, &tty->flags))
2439
		mask |= EPOLLHUP;
L
Linus Torvalds 已提交
2440
	if (tty_hung_up_p(file))
2441
		mask |= EPOLLHUP;
A
Alan Cox 已提交
2442 2443 2444
	if (tty->ops->write && !tty_is_writelocked(tty) &&
			tty_chars_in_buffer(tty) < WAKEUP_CHARS &&
			tty_write_room(tty) > 0)
2445
		mask |= EPOLLOUT | EPOLLWRNORM;
L
Linus Torvalds 已提交
2446 2447 2448
	return mask;
}

J
Jiri Slaby 已提交
2449
static unsigned long inq_canon(struct n_tty_data *ldata)
2450
{
2451
	size_t nr, head, tail;
2452

2453
	if (ldata->canon_head == ldata->read_tail)
2454
		return 0;
2455 2456
	head = ldata->canon_head;
	tail = ldata->read_tail;
2457
	nr = head - tail;
2458
	/* Skip EOF-chars.. */
2459
	while (MASK(head) != MASK(tail)) {
2460 2461
		if (test_bit(tail & (N_TTY_BUF_SIZE - 1), ldata->read_flags) &&
		    read_buf(ldata, tail) == __DISABLED_CHAR)
2462
			nr--;
2463
		tail++;
2464 2465 2466 2467 2468 2469 2470
	}
	return nr;
}

static int n_tty_ioctl(struct tty_struct *tty, struct file *file,
		       unsigned int cmd, unsigned long arg)
{
2471
	struct n_tty_data *ldata = tty->disc_data;
2472 2473 2474 2475 2476 2477
	int retval;

	switch (cmd) {
	case TIOCOUTQ:
		return put_user(tty_chars_in_buffer(tty), (int __user *) arg);
	case TIOCINQ:
2478
		down_write(&tty->termios_rwsem);
2479
		if (L_ICANON(tty) && !L_EXTPROC(tty))
J
Jiri Slaby 已提交
2480
			retval = inq_canon(ldata);
2481 2482 2483
		else
			retval = read_cnt(ldata);
		up_write(&tty->termios_rwsem);
2484 2485 2486 2487 2488 2489
		return put_user(retval, (unsigned int __user *) arg);
	default:
		return n_tty_ioctl_helper(tty, file, cmd, arg);
	}
}

2490
static struct tty_ldisc_ops n_tty_ops = {
2491
	.owner		 = THIS_MODULE,
P
Paul Fulghum 已提交
2492 2493 2494 2495
	.name            = "n_tty",
	.open            = n_tty_open,
	.close           = n_tty_close,
	.flush_buffer    = n_tty_flush_buffer,
2496 2497
	.read            = n_tty_read,
	.write           = n_tty_write,
P
Paul Fulghum 已提交
2498 2499
	.ioctl           = n_tty_ioctl,
	.set_termios     = n_tty_set_termios,
2500
	.poll            = n_tty_poll,
P
Paul Fulghum 已提交
2501
	.receive_buf     = n_tty_receive_buf,
2502
	.write_wakeup    = n_tty_write_wakeup,
2503
	.receive_buf2	 = n_tty_receive_buf2,
L
Linus Torvalds 已提交
2504
};
2505 2506 2507 2508 2509

/**
 *	n_tty_inherit_ops	-	inherit N_TTY methods
 *	@ops: struct tty_ldisc_ops where to save N_TTY methods
 *
2510
 *	Enables a 'subclass' line discipline to 'inherit' N_TTY methods.
2511 2512 2513 2514
 */

void n_tty_inherit_ops(struct tty_ldisc_ops *ops)
{
2515
	*ops = n_tty_ops;
2516 2517 2518 2519
	ops->owner = NULL;
	ops->refcount = ops->flags = 0;
}
EXPORT_SYMBOL_GPL(n_tty_inherit_ops);
2520 2521 2522 2523 2524

void __init n_tty_init(void)
{
	tty_register_ldisc(N_TTY, &n_tty_ops);
}