n_tty.c 60.9 KB
Newer Older
1
// SPDX-License-Identifier: GPL-1.0+
L
Linus Torvalds 已提交
2 3
/*
 * n_tty.c --- implements the N_TTY line discipline.
4
 *
L
Linus Torvalds 已提交
5 6 7 8 9 10 11
 * This code used to be in tty_io.c, but things are getting hairy
 * enough that it made sense to split things off.  (The N_TTY
 * processing has changed so much that it's hardly recognizable,
 * anyway...)
 *
 * Note that the open routine for N_TTY is guaranteed never to return
 * an error.  This is because Linux will fall back to setting a line
12
 * to N_TTY if it can not switch to any other line discipline.
L
Linus Torvalds 已提交
13 14
 *
 * Written by Theodore Ts'o, Copyright 1994.
15
 *
L
Linus Torvalds 已提交
16 17
 * This file also contains code originally written by Linus Torvalds,
 * Copyright 1991, 1992, 1993, and by Julian Cowley, Copyright 1994.
18
 *
L
Linus Torvalds 已提交
19 20
 * Reduced memory usage for older ARM systems  - Russell King.
 *
21
 * 2000/01/20   Fixed SMP locking on put_tty_queue using bits of
L
Linus Torvalds 已提交
22 23 24 25 26
 *		the patch by Andrew J. Kroll <ag784@freenet.buffalo.edu>
 *		who actually finally proved there really was a race.
 *
 * 2002/03/18   Implemented n_tty_wakeup to send SIGIO POLL_OUTs to
 *		waiting writing processes-Sapan Bhatia <sapan@corewars.org>.
27
 *		Also fixed a bug in BLOCKING mode where n_tty_write returns
L
Linus Torvalds 已提交
28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45
 *		EAGAIN
 */

#include <linux/types.h>
#include <linux/major.h>
#include <linux/errno.h>
#include <linux/signal.h>
#include <linux/fcntl.h>
#include <linux/sched.h>
#include <linux/interrupt.h>
#include <linux/tty.h>
#include <linux/timer.h>
#include <linux/ctype.h>
#include <linux/mm.h>
#include <linux/string.h>
#include <linux/slab.h>
#include <linux/poll.h>
#include <linux/bitops.h>
M
Miloslav Trmac 已提交
46 47
#include <linux/audit.h>
#include <linux/file.h>
A
Alan Cox 已提交
48
#include <linux/uaccess.h>
49
#include <linux/module.h>
50
#include <linux/ratelimit.h>
51
#include <linux/vmalloc.h>
L
Linus Torvalds 已提交
52 53 54 55 56 57 58 59 60 61 62


/* number of characters left in xmit buffer before select has we have room */
#define WAKEUP_CHARS 256

/*
 * This defines the low- and high-watermarks for throttling and
 * unthrottling the TTY driver.  These watermarks are used for
 * controlling the space in the read buffer.
 */
#define TTY_THRESHOLD_THROTTLE		128 /* now based on remaining room */
63
#define TTY_THRESHOLD_UNTHROTTLE	128
L
Linus Torvalds 已提交
64

65 66 67 68 69 70 71 72 73 74 75
/*
 * Special byte codes used in the echo buffer to represent operations
 * or special handling of characters.  Bytes in the echo buffer that
 * are not part of such special blocks are treated as normal character
 * codes.
 */
#define ECHO_OP_START 0xff
#define ECHO_OP_MOVE_BACK_COL 0x80
#define ECHO_OP_SET_CANON_COL 0x81
#define ECHO_OP_ERASE_TAB 0x82

P
Peter Hurley 已提交
76 77 78 79 80
#define ECHO_COMMIT_WATERMARK	256
#define ECHO_BLOCK		256
#define ECHO_DISCARD_WATERMARK	N_TTY_BUF_SIZE - (ECHO_BLOCK + 32)


81 82 83 84 85 86 87
#undef N_TTY_TRACE
#ifdef N_TTY_TRACE
# define n_tty_trace(f, args...)	trace_printk(f, ##args)
#else
# define n_tty_trace(f, args...)
#endif

J
Jiri Slaby 已提交
88
struct n_tty_data {
89 90
	/* producer-published */
	size_t read_head;
91
	size_t commit_head;
92
	size_t canon_head;
93 94
	size_t echo_head;
	size_t echo_commit;
95
	size_t echo_mark;
96
	DECLARE_BITMAP(char_map, 256);
97 98

	/* private to n_tty_receive_overrun (single-threaded) */
99 100 101
	unsigned long overrun_time;
	int num_overrun;

102 103 104
	/* non-atomic */
	bool no_room;

105
	/* must hold exclusive termios_rwsem to reset these */
106
	unsigned char lnext:1, erasing:1, raw:1, real_raw:1, icanon:1;
107
	unsigned char push:1;
108

109
	/* shared by producer and consumer */
110
	char read_buf[N_TTY_BUF_SIZE];
111
	DECLARE_BITMAP(read_flags, N_TTY_BUF_SIZE);
112
	unsigned char echo_buf[N_TTY_BUF_SIZE];
113

114 115
	/* consumer-published */
	size_t read_tail;
P
Peter Hurley 已提交
116
	size_t line_start;
117 118 119

	/* protected by output lock */
	unsigned int column;
120
	unsigned int canon_column;
121
	size_t echo_tail;
122 123 124

	struct mutex atomic_read_lock;
	struct mutex output_lock;
J
Jiri Slaby 已提交
125 126
};

127 128
#define MASK(x) ((x) & (N_TTY_BUF_SIZE - 1))

129 130
static inline size_t read_cnt(struct n_tty_data *ldata)
{
P
Peter Hurley 已提交
131
	return ldata->read_head - ldata->read_tail;
132 133
}

134 135 136 137 138 139 140 141 142 143
static inline unsigned char read_buf(struct n_tty_data *ldata, size_t i)
{
	return ldata->read_buf[i & (N_TTY_BUF_SIZE - 1)];
}

static inline unsigned char *read_buf_addr(struct n_tty_data *ldata, size_t i)
{
	return &ldata->read_buf[i & (N_TTY_BUF_SIZE - 1)];
}

144 145 146 147 148 149 150 151 152 153
static inline unsigned char echo_buf(struct n_tty_data *ldata, size_t i)
{
	return ldata->echo_buf[i & (N_TTY_BUF_SIZE - 1)];
}

static inline unsigned char *echo_buf_addr(struct n_tty_data *ldata, size_t i)
{
	return &ldata->echo_buf[i & (N_TTY_BUF_SIZE - 1)];
}

P
Peter Hurley 已提交
154 155
static int tty_copy_to_user(struct tty_struct *tty, void __user *to,
			    size_t tail, size_t n)
156 157
{
	struct n_tty_data *ldata = tty->disc_data;
P
Peter Hurley 已提交
158 159 160 161 162
	size_t size = N_TTY_BUF_SIZE - tail;
	const void *from = read_buf_addr(ldata, tail);
	int uncopied;

	if (n > size) {
163
		tty_audit_add_data(tty, from, size);
P
Peter Hurley 已提交
164 165 166 167 168 169 170
		uncopied = copy_to_user(to, from, size);
		if (uncopied)
			return uncopied;
		to += size;
		n -= size;
		from = ldata->read_buf;
	}
171

172
	tty_audit_add_data(tty, from, n);
173 174 175
	return copy_to_user(to, from, n);
}

176
/**
177
 *	n_tty_kick_worker - start input worker (if required)
178 179
 *	@tty: terminal
 *
180
 *	Re-schedules the flip buffer work if it may have stopped
181
 *
182 183 184 185
 *	Caller holds exclusive termios_rwsem
 *	   or
 *	n_tty_read()/consumer path:
 *		holds non-exclusive termios_rwsem
186 187
 */

188
static void n_tty_kick_worker(struct tty_struct *tty)
189
{
190 191
	struct n_tty_data *ldata = tty->disc_data;

192 193
	/* Did the input worker stop? Restart it */
	if (unlikely(ldata->no_room)) {
194 195
		ldata->no_room = 0;

J
Jiri Slaby 已提交
196
		WARN_RATELIMIT(tty->port->itty == NULL,
197
				"scheduling with invalid itty\n");
198 199 200 201 202 203
		/* see if ldisc has been killed - if so, this means that
		 * even though the ldisc has been halted and ->buf.work
		 * cancelled, ->buf.work is about to be rescheduled
		 */
		WARN_RATELIMIT(test_bit(TTY_LDISC_HALTED, &tty->flags),
			       "scheduling buffer work for halted ldisc\n");
P
Peter Hurley 已提交
204
		tty_buffer_restart_work(tty->port);
J
Jiri Slaby 已提交
205
	}
206 207
}

208 209 210 211 212 213
static ssize_t chars_in_buffer(struct tty_struct *tty)
{
	struct n_tty_data *ldata = tty->disc_data;
	ssize_t n = 0;

	if (!ldata->icanon)
214
		n = ldata->commit_head - ldata->read_tail;
215 216 217 218 219
	else
		n = ldata->canon_head - ldata->read_tail;
	return n;
}

220 221 222 223 224 225 226 227 228 229 230
/**
 *	n_tty_write_wakeup	-	asynchronous I/O notifier
 *	@tty: tty device
 *
 *	Required for the ptys, serial driver etc. since processes
 *	that attach themselves to the master and rely on ASYNC
 *	IO must be woken up
 */

static void n_tty_write_wakeup(struct tty_struct *tty)
{
P
Peter Hurley 已提交
231 232
	clear_bit(TTY_DO_WRITE_WAKEUP, &tty->flags);
	kill_fasync(&tty->fasync, SIGIO, POLL_OUT);
233 234
}

235
static void n_tty_check_throttle(struct tty_struct *tty)
236
{
237 238
	struct n_tty_data *ldata = tty->disc_data;

239 240 241 242 243
	/*
	 * Check the remaining room for the input canonicalization
	 * mode.  We don't want to throttle the driver if we're in
	 * canonical mode and don't have a newline yet!
	 */
244 245 246
	if (ldata->icanon && ldata->canon_head == ldata->read_tail)
		return;

247 248 249
	while (1) {
		int throttled;
		tty_set_flow_change(tty, TTY_THROTTLE_SAFE);
250
		if (N_TTY_BUF_SIZE - read_cnt(ldata) >= TTY_THRESHOLD_THROTTLE)
251 252 253 254 255 256 257 258
			break;
		throttled = tty_throttle_safe(tty);
		if (!throttled)
			break;
	}
	__tty_set_flow_change(tty, 0);
}

259
static void n_tty_check_unthrottle(struct tty_struct *tty)
260
{
261
	if (tty->driver->type == TTY_DRIVER_TYPE_PTY) {
262 263
		if (chars_in_buffer(tty) > TTY_THRESHOLD_UNTHROTTLE)
			return;
264
		n_tty_kick_worker(tty);
265
		tty_wakeup(tty->link);
266 267 268
		return;
	}

269 270 271 272 273 274 275 276 277 278 279 280 281
	/* If there is enough space in the read buffer now, let the
	 * low-level driver know. We use chars_in_buffer() to
	 * check the buffer, as it now knows about canonical mode.
	 * Otherwise, if the driver is throttled and the line is
	 * longer than TTY_THRESHOLD_UNTHROTTLE in canonical mode,
	 * we won't get any more characters.
	 */

	while (1) {
		int unthrottled;
		tty_set_flow_change(tty, TTY_UNTHROTTLE_SAFE);
		if (chars_in_buffer(tty) > TTY_THRESHOLD_UNTHROTTLE)
			break;
282
		n_tty_kick_worker(tty);
283 284 285 286 287 288 289
		unthrottled = tty_unthrottle_safe(tty);
		if (!unthrottled)
			break;
	}
	__tty_set_flow_change(tty, 0);
}

290 291 292
/**
 *	put_tty_queue		-	add character to tty
 *	@c: character
J
Jiri Slaby 已提交
293
 *	@ldata: n_tty data
294
 *
295 296 297 298
 *	Add a character to the tty read_buf queue.
 *
 *	n_tty_receive_buf()/producer path:
 *		caller holds non-exclusive termios_rwsem
299 300
 */

301
static inline void put_tty_queue(unsigned char c, struct n_tty_data *ldata)
L
Linus Torvalds 已提交
302
{
303 304
	*read_buf_addr(ldata, ldata->read_head) = c;
	ldata->read_head++;
L
Linus Torvalds 已提交
305 306 307 308 309 310
}

/**
 *	reset_buffer_flags	-	reset buffer state
 *	@tty: terminal to reset
 *
311 312
 *	Reset the read buffer counters and clear the flags.
 *	Called from n_tty_open() and n_tty_flush_buffer().
313
 *
314 315
 *	Locking: caller holds exclusive termios_rwsem
 *		 (or locking is not required)
L
Linus Torvalds 已提交
316
 */
317

318
static void reset_buffer_flags(struct n_tty_data *ldata)
L
Linus Torvalds 已提交
319
{
320
	ldata->read_head = ldata->canon_head = ldata->read_tail = 0;
P
Peter Hurley 已提交
321
	ldata->echo_head = ldata->echo_tail = ldata->echo_commit = 0;
322
	ldata->commit_head = 0;
323
	ldata->echo_mark = 0;
P
Peter Hurley 已提交
324
	ldata->line_start = 0;
325

326
	ldata->erasing = 0;
327
	bitmap_zero(ldata->read_flags, N_TTY_BUF_SIZE);
328
	ldata->push = 0;
L
Linus Torvalds 已提交
329 330
}

331 332 333 334 335
static void n_tty_packet_mode_flush(struct tty_struct *tty)
{
	unsigned long flags;

	if (tty->link->packet) {
336
		spin_lock_irqsave(&tty->ctrl_lock, flags);
337
		tty->ctrl_status |= TIOCPKT_FLUSHREAD;
338
		spin_unlock_irqrestore(&tty->ctrl_lock, flags);
339
		wake_up_interruptible(&tty->link->read_wait);
340 341 342
	}
}

L
Linus Torvalds 已提交
343 344 345 346
/**
 *	n_tty_flush_buffer	-	clean input queue
 *	@tty:	terminal device
 *
347 348 349
 *	Flush the input buffer. Called when the tty layer wants the
 *	buffer flushed (eg at hangup) or when the N_TTY line discipline
 *	internally has to clean the pending queue (for example some signals).
L
Linus Torvalds 已提交
350
 *
351 352 353 354
 *	Holds termios_rwsem to exclude producer/consumer while
 *	buffer indices are reset.
 *
 *	Locking: ctrl_lock, exclusive termios_rwsem
L
Linus Torvalds 已提交
355
 */
356 357

static void n_tty_flush_buffer(struct tty_struct *tty)
L
Linus Torvalds 已提交
358
{
359
	down_write(&tty->termios_rwsem);
360
	reset_buffer_flags(tty->disc_data);
361
	n_tty_kick_worker(tty);
362

363 364
	if (tty->link)
		n_tty_packet_mode_flush(tty);
365
	up_write(&tty->termios_rwsem);
L
Linus Torvalds 已提交
366 367 368 369 370 371 372 373 374 375
}

/**
 *	is_utf8_continuation	-	utf8 multibyte check
 *	@c: byte to check
 *
 *	Returns true if the utf8 character 'c' is a multibyte continuation
 *	character. We use this to correctly compute the on screen size
 *	of the character when printing
 */
376

L
Linus Torvalds 已提交
377 378 379 380 381 382 383 384 385 386 387 388
static inline int is_utf8_continuation(unsigned char c)
{
	return (c & 0xc0) == 0x80;
}

/**
 *	is_continuation		-	multibyte check
 *	@c: byte to check
 *
 *	Returns true if the utf8 character 'c' is a multibyte continuation
 *	character and the terminal is in unicode mode.
 */
389

L
Linus Torvalds 已提交
390 391 392 393 394 395
static inline int is_continuation(unsigned char c, struct tty_struct *tty)
{
	return I_IUTF8(tty) && is_utf8_continuation(c);
}

/**
396
 *	do_output_char			-	output one character
L
Linus Torvalds 已提交
397 398
 *	@c: character (or partial unicode symbol)
 *	@tty: terminal device
399
 *	@space: space available in tty driver write buffer
L
Linus Torvalds 已提交
400
 *
401 402
 *	This is a helper function that handles one output character
 *	(including special characters like TAB, CR, LF, etc.),
403 404
 *	doing OPOST processing and putting the results in the
 *	tty driver's write buffer.
405 406 407 408
 *
 *	Note that Linux currently ignores TABDLY, CRDLY, VTDLY, FFDLY
 *	and NLDLY.  They simply aren't relevant in the world today.
 *	If you ever need them, add them here.
L
Linus Torvalds 已提交
409
 *
410 411 412 413 414
 *	Returns the number of bytes of buffer space used or -1 if
 *	no space left.
 *
 *	Locking: should be called under the output_lock to protect
 *		 the column state and space left in the buffer
L
Linus Torvalds 已提交
415
 */
416

417
static int do_output_char(unsigned char c, struct tty_struct *tty, int space)
L
Linus Torvalds 已提交
418
{
419
	struct n_tty_data *ldata = tty->disc_data;
420
	int	spaces;
L
Linus Torvalds 已提交
421 422 423

	if (!space)
		return -1;
A
Alan Cox 已提交
424

425 426 427
	switch (c) {
	case '\n':
		if (O_ONLRET(tty))
428
			ldata->column = 0;
429 430 431
		if (O_ONLCR(tty)) {
			if (space < 2)
				return -1;
432
			ldata->canon_column = ldata->column = 0;
433
			tty->ops->write(tty, "\r\n", 2);
434 435
			return 2;
		}
436
		ldata->canon_column = ldata->column;
437 438
		break;
	case '\r':
439
		if (O_ONOCR(tty) && ldata->column == 0)
440 441 442 443
			return 0;
		if (O_OCRNL(tty)) {
			c = '\n';
			if (O_ONLRET(tty))
444
				ldata->canon_column = ldata->column = 0;
L
Linus Torvalds 已提交
445
			break;
446
		}
447
		ldata->canon_column = ldata->column = 0;
448 449
		break;
	case '\t':
450
		spaces = 8 - (ldata->column & 7);
451 452 453
		if (O_TABDLY(tty) == XTABS) {
			if (space < spaces)
				return -1;
454
			ldata->column += spaces;
455 456
			tty->ops->write(tty, "        ", spaces);
			return spaces;
L
Linus Torvalds 已提交
457
		}
458
		ldata->column += spaces;
459 460
		break;
	case '\b':
461 462
		if (ldata->column > 0)
			ldata->column--;
463 464
		break;
	default:
465 466 467 468
		if (!iscntrl(c)) {
			if (O_OLCUC(tty))
				c = toupper(c);
			if (!is_continuation(c, tty))
469
				ldata->column++;
470
		}
471
		break;
L
Linus Torvalds 已提交
472
	}
473

A
Alan Cox 已提交
474
	tty_put_char(tty, c);
475 476 477 478 479 480 481 482
	return 1;
}

/**
 *	process_output			-	output post processor
 *	@c: character (or partial unicode symbol)
 *	@tty: terminal device
 *
483 484 485
 *	Output one character with OPOST processing.
 *	Returns -1 when the output device is full and the character
 *	must be retried.
486 487 488 489 490 491 492 493
 *
 *	Locking: output_lock to protect column state and space left
 *		 (also, this is called from n_tty_write under the
 *		  tty layer write lock)
 */

static int process_output(unsigned char c, struct tty_struct *tty)
{
494
	struct n_tty_data *ldata = tty->disc_data;
495 496
	int	space, retval;

497
	mutex_lock(&ldata->output_lock);
498 499 500 501

	space = tty_write_room(tty);
	retval = do_output_char(c, tty, space);

502
	mutex_unlock(&ldata->output_lock);
503 504 505 506
	if (retval < 0)
		return -1;
	else
		return 0;
L
Linus Torvalds 已提交
507 508 509
}

/**
510
 *	process_output_block		-	block post processor
L
Linus Torvalds 已提交
511
 *	@tty: terminal device
512 513 514 515 516
 *	@buf: character buffer
 *	@nr: number of bytes to output
 *
 *	Output a block of characters with OPOST processing.
 *	Returns the number of characters output.
L
Linus Torvalds 已提交
517 518 519 520 521 522
 *
 *	This path is used to speed up block console writes, among other
 *	things when processing blocks of output data. It handles only
 *	the simple cases normally found and helps to generate blocks of
 *	symbols for the console driver and thus improve performance.
 *
523 524 525
 *	Locking: output_lock to protect column state and space left
 *		 (also, this is called from n_tty_write under the
 *		  tty layer write lock)
L
Linus Torvalds 已提交
526
 */
527

528 529
static ssize_t process_output_block(struct tty_struct *tty,
				    const unsigned char *buf, unsigned int nr)
L
Linus Torvalds 已提交
530
{
531
	struct n_tty_data *ldata = tty->disc_data;
L
Linus Torvalds 已提交
532
	int	space;
533
	int	i;
L
Linus Torvalds 已提交
534 535
	const unsigned char *cp;

536
	mutex_lock(&ldata->output_lock);
537

A
Alan Cox 已提交
538
	space = tty_write_room(tty);
A
Alan Cox 已提交
539
	if (!space) {
540
		mutex_unlock(&ldata->output_lock);
L
Linus Torvalds 已提交
541
		return 0;
542
	}
L
Linus Torvalds 已提交
543 544 545 546
	if (nr > space)
		nr = space;

	for (i = 0, cp = buf; i < nr; i++, cp++) {
547 548 549
		unsigned char c = *cp;

		switch (c) {
L
Linus Torvalds 已提交
550 551
		case '\n':
			if (O_ONLRET(tty))
552
				ldata->column = 0;
L
Linus Torvalds 已提交
553 554
			if (O_ONLCR(tty))
				goto break_out;
555
			ldata->canon_column = ldata->column;
L
Linus Torvalds 已提交
556 557
			break;
		case '\r':
558
			if (O_ONOCR(tty) && ldata->column == 0)
L
Linus Torvalds 已提交
559 560 561
				goto break_out;
			if (O_OCRNL(tty))
				goto break_out;
562
			ldata->canon_column = ldata->column = 0;
L
Linus Torvalds 已提交
563 564 565 566
			break;
		case '\t':
			goto break_out;
		case '\b':
567 568
			if (ldata->column > 0)
				ldata->column--;
L
Linus Torvalds 已提交
569 570
			break;
		default:
571 572 573 574
			if (!iscntrl(c)) {
				if (O_OLCUC(tty))
					goto break_out;
				if (!is_continuation(c, tty))
575
					ldata->column++;
576
			}
L
Linus Torvalds 已提交
577 578 579 580
			break;
		}
	}
break_out:
A
Alan Cox 已提交
581
	i = tty->ops->write(tty, buf, i);
582

583
	mutex_unlock(&ldata->output_lock);
L
Linus Torvalds 已提交
584 585 586
	return i;
}

587 588 589 590 591 592 593 594 595 596 597 598 599 600 601 602 603 604 605 606 607 608
/**
 *	process_echoes	-	write pending echo characters
 *	@tty: terminal device
 *
 *	Write previously buffered echo (and other ldisc-generated)
 *	characters to the tty.
 *
 *	Characters generated by the ldisc (including echoes) need to
 *	be buffered because the driver's write buffer can fill during
 *	heavy program output.  Echoing straight to the driver will
 *	often fail under these conditions, causing lost characters and
 *	resulting mismatches of ldisc state information.
 *
 *	Since the ldisc state must represent the characters actually sent
 *	to the driver at the time of the write, operations like certain
 *	changes in column state are also saved in the buffer and executed
 *	here.
 *
 *	A circular fifo buffer is used so that the most recent characters
 *	are prioritized.  Also, when control characters are echoed with a
 *	prefixed "^", the pair is treated atomically and thus not separated.
 *
609
 *	Locking: callers must hold output_lock
610 611
 */

612
static size_t __process_echoes(struct tty_struct *tty)
613
{
614
	struct n_tty_data *ldata = tty->disc_data;
615
	int	space, old_space;
616
	size_t tail;
617 618
	unsigned char c;

619
	old_space = space = tty_write_room(tty);
620

621
	tail = ldata->echo_tail;
622
	while (ldata->echo_commit != tail) {
623
		c = echo_buf(ldata, tail);
624 625 626 627 628 629 630 631 632
		if (c == ECHO_OP_START) {
			unsigned char op;
			int no_space_left = 0;

			/*
			 * If the buffer byte is the start of a multi-byte
			 * operation, get the next byte, which is either the
			 * op code or a control character value.
			 */
633
			op = echo_buf(ldata, tail + 1);
A
Alan Cox 已提交
634

635 636 637 638
			switch (op) {
				unsigned int num_chars, num_bs;

			case ECHO_OP_ERASE_TAB:
639
				num_chars = echo_buf(ldata, tail + 2);
640 641 642 643 644 645 646 647 648 649 650 651

				/*
				 * Determine how many columns to go back
				 * in order to erase the tab.
				 * This depends on the number of columns
				 * used by other characters within the tab
				 * area.  If this (modulo 8) count is from
				 * the start of input rather than from a
				 * previous tab, we offset by canon column.
				 * Otherwise, tab spacing is normal.
				 */
				if (!(num_chars & 0x80))
652
					num_chars += ldata->canon_column;
653 654 655 656 657 658 659 660 661
				num_bs = 8 - (num_chars & 7);

				if (num_bs > space) {
					no_space_left = 1;
					break;
				}
				space -= num_bs;
				while (num_bs--) {
					tty_put_char(tty, '\b');
662 663
					if (ldata->column > 0)
						ldata->column--;
664
				}
665
				tail += 3;
666 667 668
				break;

			case ECHO_OP_SET_CANON_COL:
669
				ldata->canon_column = ldata->column;
670
				tail += 2;
671 672 673
				break;

			case ECHO_OP_MOVE_BACK_COL:
674 675
				if (ldata->column > 0)
					ldata->column--;
676
				tail += 2;
677 678 679 680 681 682 683 684 685
				break;

			case ECHO_OP_START:
				/* This is an escaped echo op start code */
				if (!space) {
					no_space_left = 1;
					break;
				}
				tty_put_char(tty, ECHO_OP_START);
686
				ldata->column++;
687
				space--;
688
				tail += 2;
689 690 691 692
				break;

			default:
				/*
693 694 695 696 697 698 699
				 * If the op is not a special byte code,
				 * it is a ctrl char tagged to be echoed
				 * as "^X" (where X is the letter
				 * representing the control char).
				 * Note that we must ensure there is
				 * enough space for the whole ctrl pair.
				 *
700
				 */
701 702 703 704 705 706
				if (space < 2) {
					no_space_left = 1;
					break;
				}
				tty_put_char(tty, '^');
				tty_put_char(tty, op ^ 0100);
707
				ldata->column += 2;
708
				space -= 2;
709
				tail += 2;
710 711 712 713 714
			}

			if (no_space_left)
				break;
		} else {
P
Peter Hurley 已提交
715
			if (O_OPOST(tty)) {
716 717 718 719 720 721 722 723 724 725
				int retval = do_output_char(c, tty, space);
				if (retval < 0)
					break;
				space -= retval;
			} else {
				if (!space)
					break;
				tty_put_char(tty, c);
				space -= 1;
			}
726
			tail += 1;
727 728 729
		}
	}

P
Peter Hurley 已提交
730 731 732 733
	/* If the echo buffer is nearly full (so that the possibility exists
	 * of echo overrun before the next commit), then discard enough
	 * data at the tail to prevent a subsequent overrun */
	while (ldata->echo_commit - tail >= ECHO_DISCARD_WATERMARK) {
734
		if (echo_buf(ldata, tail) == ECHO_OP_START) {
735
			if (echo_buf(ldata, tail + 1) == ECHO_OP_ERASE_TAB)
P
Peter Hurley 已提交
736 737 738 739 740 741 742
				tail += 3;
			else
				tail += 2;
		} else
			tail++;
	}

743
	ldata->echo_tail = tail;
744
	return old_space - space;
745 746 747 748 749
}

static void commit_echoes(struct tty_struct *tty)
{
	struct n_tty_data *ldata = tty->disc_data;
750
	size_t nr, old, echoed;
P
Peter Hurley 已提交
751 752 753
	size_t head;

	head = ldata->echo_head;
754
	ldata->echo_mark = head;
P
Peter Hurley 已提交
755 756 757 758 759 760 761 762
	old = ldata->echo_commit - ldata->echo_tail;

	/* Process committed echoes if the accumulated # of bytes
	 * is over the threshold (and try again each time another
	 * block is accumulated) */
	nr = head - ldata->echo_tail;
	if (nr < ECHO_COMMIT_WATERMARK || (nr % ECHO_BLOCK > old % ECHO_BLOCK))
		return;
763

764
	mutex_lock(&ldata->output_lock);
P
Peter Hurley 已提交
765
	ldata->echo_commit = head;
766
	echoed = __process_echoes(tty);
767
	mutex_unlock(&ldata->output_lock);
768

769
	if (echoed && tty->ops->flush_chars)
770 771 772
		tty->ops->flush_chars(tty);
}

773
static void process_echoes(struct tty_struct *tty)
P
Peter Hurley 已提交
774 775
{
	struct n_tty_data *ldata = tty->disc_data;
776
	size_t echoed;
P
Peter Hurley 已提交
777

P
Peter Hurley 已提交
778
	if (ldata->echo_mark == ldata->echo_tail)
779 780 781
		return;

	mutex_lock(&ldata->output_lock);
782
	ldata->echo_commit = ldata->echo_mark;
783
	echoed = __process_echoes(tty);
784 785
	mutex_unlock(&ldata->output_lock);

786
	if (echoed && tty->ops->flush_chars)
787
		tty->ops->flush_chars(tty);
P
Peter Hurley 已提交
788 789
}

790
/* NB: echo_mark and echo_head should be equivalent here */
P
Peter Hurley 已提交
791 792 793 794
static void flush_echoes(struct tty_struct *tty)
{
	struct n_tty_data *ldata = tty->disc_data;

P
Peter Hurley 已提交
795 796
	if ((!L_ECHO(tty) && !L_ECHONL(tty)) ||
	    ldata->echo_commit == ldata->echo_head)
P
Peter Hurley 已提交
797 798 799 800 801 802 803 804
		return;

	mutex_lock(&ldata->output_lock);
	ldata->echo_commit = ldata->echo_head;
	__process_echoes(tty);
	mutex_unlock(&ldata->output_lock);
}

805 806 807
/**
 *	add_echo_byte	-	add a byte to the echo buffer
 *	@c: unicode byte to echo
J
Jiri Slaby 已提交
808
 *	@ldata: n_tty data
809 810 811 812
 *
 *	Add a character or operation byte to the echo buffer.
 */

P
Peter Hurley 已提交
813
static inline void add_echo_byte(unsigned char c, struct n_tty_data *ldata)
814
{
815
	*echo_buf_addr(ldata, ldata->echo_head++) = c;
816 817 818 819
}

/**
 *	echo_move_back_col	-	add operation to move back a column
J
Jiri Slaby 已提交
820
 *	@ldata: n_tty data
821 822 823 824
 *
 *	Add an operation to the echo buffer to move back one column.
 */

J
Jiri Slaby 已提交
825
static void echo_move_back_col(struct n_tty_data *ldata)
826
{
J
Jiri Slaby 已提交
827 828
	add_echo_byte(ECHO_OP_START, ldata);
	add_echo_byte(ECHO_OP_MOVE_BACK_COL, ldata);
829 830 831 832
}

/**
 *	echo_set_canon_col	-	add operation to set the canon column
J
Jiri Slaby 已提交
833
 *	@ldata: n_tty data
834 835 836 837 838
 *
 *	Add an operation to the echo buffer to set the canon column
 *	to the current column.
 */

J
Jiri Slaby 已提交
839
static void echo_set_canon_col(struct n_tty_data *ldata)
840
{
J
Jiri Slaby 已提交
841 842
	add_echo_byte(ECHO_OP_START, ldata);
	add_echo_byte(ECHO_OP_SET_CANON_COL, ldata);
843 844 845 846 847 848
}

/**
 *	echo_erase_tab	-	add operation to erase a tab
 *	@num_chars: number of character columns already used
 *	@after_tab: true if num_chars starts after a previous tab
J
Jiri Slaby 已提交
849
 *	@ldata: n_tty data
850 851 852 853 854 855 856 857 858 859 860
 *
 *	Add an operation to the echo buffer to erase a tab.
 *
 *	Called by the eraser function, which knows how many character
 *	columns have been used since either a previous tab or the start
 *	of input.  This information will be used later, along with
 *	canon column (if applicable), to go back the correct number
 *	of columns.
 */

static void echo_erase_tab(unsigned int num_chars, int after_tab,
J
Jiri Slaby 已提交
861
			   struct n_tty_data *ldata)
862
{
J
Jiri Slaby 已提交
863 864
	add_echo_byte(ECHO_OP_START, ldata);
	add_echo_byte(ECHO_OP_ERASE_TAB, ldata);
865 866 867 868 869 870 871

	/* We only need to know this modulo 8 (tab spacing) */
	num_chars &= 7;

	/* Set the high bit as a flag if num_chars is after a previous tab */
	if (after_tab)
		num_chars |= 0x80;
A
Alan Cox 已提交
872

J
Jiri Slaby 已提交
873
	add_echo_byte(num_chars, ldata);
874 875 876 877 878 879 880 881 882 883 884 885 886
}

/**
 *	echo_char_raw	-	echo a character raw
 *	@c: unicode byte to echo
 *	@tty: terminal device
 *
 *	Echo user input back onto the screen. This must be called only when
 *	L_ECHO(tty) is true. Called from the driver receive_buf path.
 *
 *	This variant does not treat control characters specially.
 */

J
Jiri Slaby 已提交
887
static void echo_char_raw(unsigned char c, struct n_tty_data *ldata)
888 889
{
	if (c == ECHO_OP_START) {
J
Jiri Slaby 已提交
890 891
		add_echo_byte(ECHO_OP_START, ldata);
		add_echo_byte(ECHO_OP_START, ldata);
892
	} else {
J
Jiri Slaby 已提交
893
		add_echo_byte(c, ldata);
894 895
	}
}
L
Linus Torvalds 已提交
896 897

/**
898
 *	echo_char	-	echo a character
L
Linus Torvalds 已提交
899 900 901
 *	@c: unicode byte to echo
 *	@tty: terminal device
 *
902
 *	Echo user input back onto the screen. This must be called only when
L
Linus Torvalds 已提交
903
 *	L_ECHO(tty) is true. Called from the driver receive_buf path.
904
 *
905 906
 *	This variant tags control characters to be echoed as "^X"
 *	(where X is the letter representing the control char).
L
Linus Torvalds 已提交
907 908 909 910
 */

static void echo_char(unsigned char c, struct tty_struct *tty)
{
911 912
	struct n_tty_data *ldata = tty->disc_data;

913
	if (c == ECHO_OP_START) {
J
Jiri Slaby 已提交
914 915
		add_echo_byte(ECHO_OP_START, ldata);
		add_echo_byte(ECHO_OP_START, ldata);
916
	} else {
917
		if (L_ECHOCTL(tty) && iscntrl(c) && c != '\t')
J
Jiri Slaby 已提交
918 919
			add_echo_byte(ECHO_OP_START, ldata);
		add_echo_byte(c, ldata);
920
	}
L
Linus Torvalds 已提交
921 922
}

923
/**
924
 *	finish_erasing		-	complete erase
J
Jiri Slaby 已提交
925
 *	@ldata: n_tty data
926
 */
927

J
Jiri Slaby 已提交
928
static inline void finish_erasing(struct n_tty_data *ldata)
L
Linus Torvalds 已提交
929
{
930
	if (ldata->erasing) {
J
Jiri Slaby 已提交
931
		echo_char_raw('/', ldata);
932
		ldata->erasing = 0;
L
Linus Torvalds 已提交
933 934 935 936 937 938 939 940
	}
}

/**
 *	eraser		-	handle erase function
 *	@c: character input
 *	@tty: terminal device
 *
941
 *	Perform erase and necessary output when an erase character is
L
Linus Torvalds 已提交
942 943
 *	present in the stream from the driver layer. Handles the complexities
 *	of UTF-8 multibyte symbols.
944
 *
945 946
 *	n_tty_receive_buf()/producer path:
 *		caller holds non-exclusive termios_rwsem
L
Linus Torvalds 已提交
947
 */
948

L
Linus Torvalds 已提交
949 950
static void eraser(unsigned char c, struct tty_struct *tty)
{
951
	struct n_tty_data *ldata = tty->disc_data;
L
Linus Torvalds 已提交
952
	enum { ERASE, WERASE, KILL } kill_type;
953 954 955
	size_t head;
	size_t cnt;
	int seen_alnums;
L
Linus Torvalds 已提交
956

957
	if (ldata->read_head == ldata->canon_head) {
958
		/* process_output('\a', tty); */ /* what do you think? */
L
Linus Torvalds 已提交
959 960 961 962 963 964 965 966
		return;
	}
	if (c == ERASE_CHAR(tty))
		kill_type = ERASE;
	else if (c == WERASE_CHAR(tty))
		kill_type = WERASE;
	else {
		if (!L_ECHO(tty)) {
967
			ldata->read_head = ldata->canon_head;
L
Linus Torvalds 已提交
968 969 970
			return;
		}
		if (!L_ECHOK(tty) || !L_ECHOKE(tty) || !L_ECHOE(tty)) {
971
			ldata->read_head = ldata->canon_head;
J
Jiri Slaby 已提交
972
			finish_erasing(ldata);
L
Linus Torvalds 已提交
973 974 975
			echo_char(KILL_CHAR(tty), tty);
			/* Add a newline if ECHOK is on and ECHOKE is off. */
			if (L_ECHOK(tty))
J
Jiri Slaby 已提交
976
				echo_char_raw('\n', ldata);
L
Linus Torvalds 已提交
977 978 979 980 981 982
			return;
		}
		kill_type = KILL;
	}

	seen_alnums = 0;
983
	while (MASK(ldata->read_head) != MASK(ldata->canon_head)) {
984
		head = ldata->read_head;
L
Linus Torvalds 已提交
985 986 987

		/* erase a single possibly multibyte character */
		do {
988 989
			head--;
			c = read_buf(ldata, head);
990 991
		} while (is_continuation(c, tty) &&
			 MASK(head) != MASK(ldata->canon_head));
L
Linus Torvalds 已提交
992 993 994 995 996 997 998 999 1000 1001 1002 1003

		/* do not partially erase */
		if (is_continuation(c, tty))
			break;

		if (kill_type == WERASE) {
			/* Equivalent to BSD's ALTWERASE. */
			if (isalnum(c) || c == '_')
				seen_alnums++;
			else if (seen_alnums)
				break;
		}
1004
		cnt = ldata->read_head - head;
1005
		ldata->read_head = head;
L
Linus Torvalds 已提交
1006 1007
		if (L_ECHO(tty)) {
			if (L_ECHOPRT(tty)) {
1008
				if (!ldata->erasing) {
J
Jiri Slaby 已提交
1009
					echo_char_raw('\\', ldata);
1010
					ldata->erasing = 1;
L
Linus Torvalds 已提交
1011 1012 1013 1014
				}
				/* if cnt > 1, output a multi-byte character */
				echo_char(c, tty);
				while (--cnt > 0) {
1015 1016
					head++;
					echo_char_raw(read_buf(ldata, head), ldata);
J
Jiri Slaby 已提交
1017
					echo_move_back_col(ldata);
L
Linus Torvalds 已提交
1018 1019 1020 1021
				}
			} else if (kill_type == ERASE && !L_ECHOE(tty)) {
				echo_char(ERASE_CHAR(tty), tty);
			} else if (c == '\t') {
1022 1023
				unsigned int num_chars = 0;
				int after_tab = 0;
1024
				size_t tail = ldata->read_head;
1025 1026 1027 1028 1029 1030 1031 1032

				/*
				 * Count the columns used for characters
				 * since the start of input or after a
				 * previous tab.
				 * This info is used to go back the correct
				 * number of columns.
				 */
1033
				while (MASK(tail) != MASK(ldata->canon_head)) {
1034 1035
					tail--;
					c = read_buf(ldata, tail);
1036 1037 1038
					if (c == '\t') {
						after_tab = 1;
						break;
A
Alan Cox 已提交
1039
					} else if (iscntrl(c)) {
L
Linus Torvalds 已提交
1040
						if (L_ECHOCTL(tty))
1041 1042 1043 1044
							num_chars += 2;
					} else if (!is_continuation(c, tty)) {
						num_chars++;
					}
L
Linus Torvalds 已提交
1045
				}
J
Jiri Slaby 已提交
1046
				echo_erase_tab(num_chars, after_tab, ldata);
L
Linus Torvalds 已提交
1047 1048
			} else {
				if (iscntrl(c) && L_ECHOCTL(tty)) {
J
Jiri Slaby 已提交
1049 1050 1051
					echo_char_raw('\b', ldata);
					echo_char_raw(' ', ldata);
					echo_char_raw('\b', ldata);
L
Linus Torvalds 已提交
1052 1053
				}
				if (!iscntrl(c) || L_ECHOCTL(tty)) {
J
Jiri Slaby 已提交
1054 1055 1056
					echo_char_raw('\b', ldata);
					echo_char_raw(' ', ldata);
					echo_char_raw('\b', ldata);
L
Linus Torvalds 已提交
1057 1058 1059 1060 1061 1062
				}
			}
		}
		if (kill_type == ERASE)
			break;
	}
1063
	if (ldata->read_head == ldata->canon_head && L_ECHO(tty))
J
Jiri Slaby 已提交
1064
		finish_erasing(ldata);
L
Linus Torvalds 已提交
1065 1066 1067 1068 1069 1070 1071
}

/**
 *	isig		-	handle the ISIG optio
 *	@sig: signal
 *	@tty: terminal
 *
1072 1073
 *	Called when a signal is being sent due to terminal input.
 *	Called from the driver receive_buf path so serialized.
1074
 *
1075 1076 1077 1078
 *	Performs input and output flush if !NOFLSH. In this context, the echo
 *	buffer is 'output'. The signal is processed first to alert any current
 *	readers or writers to discontinue and exit their i/o loops.
 *
1079
 *	Locking: ctrl_lock
L
Linus Torvalds 已提交
1080
 */
1081

1082
static void __isig(int sig, struct tty_struct *tty)
L
Linus Torvalds 已提交
1083
{
1084 1085 1086 1087
	struct pid *tty_pgrp = tty_get_pgrp(tty);
	if (tty_pgrp) {
		kill_pgrp(tty_pgrp, sig, 1);
		put_pid(tty_pgrp);
L
Linus Torvalds 已提交
1088
	}
1089
}
1090

1091 1092 1093 1094 1095 1096 1097 1098 1099
static void isig(int sig, struct tty_struct *tty)
{
	struct n_tty_data *ldata = tty->disc_data;

	if (L_NOFLSH(tty)) {
		/* signal only */
		__isig(sig, tty);

	} else { /* signal and flush */
1100 1101 1102
		up_read(&tty->termios_rwsem);
		down_write(&tty->termios_rwsem);

1103 1104
		__isig(sig, tty);

1105 1106 1107 1108 1109 1110 1111 1112 1113 1114 1115 1116 1117 1118 1119 1120 1121 1122 1123
		/* clear echo buffer */
		mutex_lock(&ldata->output_lock);
		ldata->echo_head = ldata->echo_tail = 0;
		ldata->echo_mark = ldata->echo_commit = 0;
		mutex_unlock(&ldata->output_lock);

		/* clear output buffer */
		tty_driver_flush_buffer(tty);

		/* clear input buffer */
		reset_buffer_flags(tty->disc_data);

		/* notify pty master of flush */
		if (tty->link)
			n_tty_packet_mode_flush(tty);

		up_write(&tty->termios_rwsem);
		down_read(&tty->termios_rwsem);
	}
L
Linus Torvalds 已提交
1124 1125 1126 1127 1128 1129 1130 1131 1132
}

/**
 *	n_tty_receive_break	-	handle break
 *	@tty: terminal
 *
 *	An RS232 break event has been hit in the incoming bitstream. This
 *	can cause a variety of events depending upon the termios settings.
 *
1133 1134 1135 1136
 *	n_tty_receive_buf()/producer path:
 *		caller holds non-exclusive termios_rwsem
 *
 *	Note: may get exclusive termios_rwsem if flushing input buffer
L
Linus Torvalds 已提交
1137
 */
1138

1139
static void n_tty_receive_break(struct tty_struct *tty)
L
Linus Torvalds 已提交
1140
{
J
Jiri Slaby 已提交
1141 1142
	struct n_tty_data *ldata = tty->disc_data;

L
Linus Torvalds 已提交
1143 1144 1145
	if (I_IGNBRK(tty))
		return;
	if (I_BRKINT(tty)) {
1146
		isig(SIGINT, tty);
L
Linus Torvalds 已提交
1147 1148 1149
		return;
	}
	if (I_PARMRK(tty)) {
J
Jiri Slaby 已提交
1150 1151
		put_tty_queue('\377', ldata);
		put_tty_queue('\0', ldata);
L
Linus Torvalds 已提交
1152
	}
J
Jiri Slaby 已提交
1153
	put_tty_queue('\0', ldata);
L
Linus Torvalds 已提交
1154 1155 1156 1157 1158 1159 1160 1161 1162 1163 1164 1165 1166 1167
}

/**
 *	n_tty_receive_overrun	-	handle overrun reporting
 *	@tty: terminal
 *
 *	Data arrived faster than we could process it. While the tty
 *	driver has flagged this the bits that were missed are gone
 *	forever.
 *
 *	Called from the receive_buf path so single threaded. Does not
 *	need locking as num_overrun and overrun_time are function
 *	private.
 */
1168

1169
static void n_tty_receive_overrun(struct tty_struct *tty)
L
Linus Torvalds 已提交
1170
{
1171
	struct n_tty_data *ldata = tty->disc_data;
L
Linus Torvalds 已提交
1172

1173 1174 1175
	ldata->num_overrun++;
	if (time_after(jiffies, ldata->overrun_time + HZ) ||
			time_after(ldata->overrun_time, jiffies)) {
P
Peter Hurley 已提交
1176
		tty_warn(tty, "%d input overrun(s)\n", ldata->num_overrun);
1177 1178
		ldata->overrun_time = jiffies;
		ldata->num_overrun = 0;
L
Linus Torvalds 已提交
1179 1180 1181 1182 1183 1184 1185 1186 1187
	}
}

/**
 *	n_tty_receive_parity_error	-	error notifier
 *	@tty: terminal device
 *	@c: character
 *
 *	Process a parity error and queue the right data to indicate
1188 1189 1190 1191
 *	the error case if necessary.
 *
 *	n_tty_receive_buf()/producer path:
 *		caller holds non-exclusive termios_rwsem
L
Linus Torvalds 已提交
1192
 */
1193
static void n_tty_receive_parity_error(struct tty_struct *tty, unsigned char c)
L
Linus Torvalds 已提交
1194
{
J
Jiri Slaby 已提交
1195 1196
	struct n_tty_data *ldata = tty->disc_data;

P
Peter Hurley 已提交
1197 1198 1199 1200 1201 1202 1203 1204 1205 1206
	if (I_INPCK(tty)) {
		if (I_IGNPAR(tty))
			return;
		if (I_PARMRK(tty)) {
			put_tty_queue('\377', ldata);
			put_tty_queue('\0', ldata);
			put_tty_queue(c, ldata);
		} else
			put_tty_queue('\0', ldata);
	} else
J
Jiri Slaby 已提交
1207
		put_tty_queue(c, ldata);
L
Linus Torvalds 已提交
1208 1209
}

1210 1211 1212
static void
n_tty_receive_signal_char(struct tty_struct *tty, int signal, unsigned char c)
{
1213
	isig(signal, tty);
1214 1215 1216 1217 1218
	if (I_IXON(tty))
		start_tty(tty);
	if (L_ECHO(tty)) {
		echo_char(c, tty);
		commit_echoes(tty);
P
Peter Hurley 已提交
1219 1220
	} else
		process_echoes(tty);
1221 1222 1223
	return;
}

L
Linus Torvalds 已提交
1224 1225 1226 1227 1228 1229
/**
 *	n_tty_receive_char	-	perform processing
 *	@tty: terminal device
 *	@c: character
 *
 *	Process an individual character of input received from the driver.
1230
 *	This is serialized with respect to itself by the rules for the
L
Linus Torvalds 已提交
1231
 *	driver above.
1232 1233 1234 1235
 *
 *	n_tty_receive_buf()/producer path:
 *		caller holds non-exclusive termios_rwsem
 *		publishes canon_head if canonical mode is active
1236 1237
 *
 *	Returns 1 if LNEXT was received, else returns 0
L
Linus Torvalds 已提交
1238 1239
 */

1240
static int
P
Peter Hurley 已提交
1241
n_tty_receive_char_special(struct tty_struct *tty, unsigned char c)
L
Linus Torvalds 已提交
1242
{
1243
	struct n_tty_data *ldata = tty->disc_data;
L
Linus Torvalds 已提交
1244 1245 1246 1247

	if (I_IXON(tty)) {
		if (c == START_CHAR(tty)) {
			start_tty(tty);
P
Peter Hurley 已提交
1248
			process_echoes(tty);
1249
			return 0;
L
Linus Torvalds 已提交
1250 1251 1252
		}
		if (c == STOP_CHAR(tty)) {
			stop_tty(tty);
1253
			return 0;
L
Linus Torvalds 已提交
1254 1255
		}
	}
1256

L
Linus Torvalds 已提交
1257
	if (L_ISIG(tty)) {
1258 1259
		if (c == INTR_CHAR(tty)) {
			n_tty_receive_signal_char(tty, SIGINT, c);
1260
			return 0;
1261 1262
		} else if (c == QUIT_CHAR(tty)) {
			n_tty_receive_signal_char(tty, SIGQUIT, c);
1263
			return 0;
1264 1265
		} else if (c == SUSP_CHAR(tty)) {
			n_tty_receive_signal_char(tty, SIGTSTP, c);
1266
			return 0;
L
Linus Torvalds 已提交
1267 1268
		}
	}
1269

1270 1271 1272 1273 1274
	if (tty->stopped && !tty->flow_stopped && I_IXON(tty) && I_IXANY(tty)) {
		start_tty(tty);
		process_echoes(tty);
	}

1275 1276
	if (c == '\r') {
		if (I_IGNCR(tty))
1277
			return 0;
1278 1279 1280 1281 1282
		if (I_ICRNL(tty))
			c = '\n';
	} else if (c == '\n' && I_INLCR(tty))
		c = '\r';

1283
	if (ldata->icanon) {
L
Linus Torvalds 已提交
1284 1285 1286
		if (c == ERASE_CHAR(tty) || c == KILL_CHAR(tty) ||
		    (c == WERASE_CHAR(tty) && L_IEXTEN(tty))) {
			eraser(c, tty);
P
Peter Hurley 已提交
1287
			commit_echoes(tty);
1288
			return 0;
L
Linus Torvalds 已提交
1289 1290
		}
		if (c == LNEXT_CHAR(tty) && L_IEXTEN(tty)) {
1291
			ldata->lnext = 1;
L
Linus Torvalds 已提交
1292
			if (L_ECHO(tty)) {
J
Jiri Slaby 已提交
1293
				finish_erasing(ldata);
L
Linus Torvalds 已提交
1294
				if (L_ECHOCTL(tty)) {
J
Jiri Slaby 已提交
1295 1296
					echo_char_raw('^', ldata);
					echo_char_raw('\b', ldata);
P
Peter Hurley 已提交
1297
					commit_echoes(tty);
L
Linus Torvalds 已提交
1298 1299
				}
			}
1300
			return 1;
L
Linus Torvalds 已提交
1301
		}
1302
		if (c == REPRINT_CHAR(tty) && L_ECHO(tty) && L_IEXTEN(tty)) {
1303
			size_t tail = ldata->canon_head;
L
Linus Torvalds 已提交
1304

J
Jiri Slaby 已提交
1305
			finish_erasing(ldata);
L
Linus Torvalds 已提交
1306
			echo_char(c, tty);
J
Jiri Slaby 已提交
1307
			echo_char_raw('\n', ldata);
1308
			while (MASK(tail) != MASK(ldata->read_head)) {
1309 1310
				echo_char(read_buf(ldata, tail), tty);
				tail++;
L
Linus Torvalds 已提交
1311
			}
P
Peter Hurley 已提交
1312
			commit_echoes(tty);
1313
			return 0;
L
Linus Torvalds 已提交
1314 1315
		}
		if (c == '\n') {
1316
			if (L_ECHO(tty) || L_ECHONL(tty)) {
J
Jiri Slaby 已提交
1317
				echo_char_raw('\n', ldata);
P
Peter Hurley 已提交
1318
				commit_echoes(tty);
L
Linus Torvalds 已提交
1319 1320 1321 1322 1323 1324 1325 1326 1327 1328 1329 1330 1331 1332
			}
			goto handle_newline;
		}
		if (c == EOF_CHAR(tty)) {
			c = __DISABLED_CHAR;
			goto handle_newline;
		}
		if ((c == EOL_CHAR(tty)) ||
		    (c == EOL2_CHAR(tty) && L_IEXTEN(tty))) {
			/*
			 * XXX are EOL_CHAR and EOL2_CHAR echoed?!?
			 */
			if (L_ECHO(tty)) {
				/* Record the column of first canon char. */
1333
				if (ldata->canon_head == ldata->read_head)
J
Jiri Slaby 已提交
1334
					echo_set_canon_col(ldata);
L
Linus Torvalds 已提交
1335
				echo_char(c, tty);
P
Peter Hurley 已提交
1336
				commit_echoes(tty);
L
Linus Torvalds 已提交
1337 1338 1339 1340 1341
			}
			/*
			 * XXX does PARMRK doubling happen for
			 * EOL_CHAR and EOL2_CHAR?
			 */
1342
			if (c == (unsigned char) '\377' && I_PARMRK(tty))
J
Jiri Slaby 已提交
1343
				put_tty_queue(c, ldata);
L
Linus Torvalds 已提交
1344

1345
handle_newline:
1346
			set_bit(ldata->read_head & (N_TTY_BUF_SIZE - 1), ldata->read_flags);
1347
			put_tty_queue(c, ldata);
1348
			smp_store_release(&ldata->canon_head, ldata->read_head);
L
Linus Torvalds 已提交
1349
			kill_fasync(&tty->fasync, SIGIO, POLL_IN);
1350
			wake_up_interruptible_poll(&tty->read_wait, EPOLLIN);
1351
			return 0;
L
Linus Torvalds 已提交
1352 1353
		}
	}
1354

1355
	if (L_ECHO(tty)) {
J
Jiri Slaby 已提交
1356
		finish_erasing(ldata);
L
Linus Torvalds 已提交
1357
		if (c == '\n')
J
Jiri Slaby 已提交
1358
			echo_char_raw('\n', ldata);
L
Linus Torvalds 已提交
1359 1360
		else {
			/* Record the column of first canon char. */
1361
			if (ldata->canon_head == ldata->read_head)
J
Jiri Slaby 已提交
1362
				echo_set_canon_col(ldata);
L
Linus Torvalds 已提交
1363 1364
			echo_char(c, tty);
		}
P
Peter Hurley 已提交
1365
		commit_echoes(tty);
L
Linus Torvalds 已提交
1366 1367
	}

1368 1369
	/* PARMRK doubling check */
	if (c == (unsigned char) '\377' && I_PARMRK(tty))
J
Jiri Slaby 已提交
1370
		put_tty_queue(c, ldata);
L
Linus Torvalds 已提交
1371

J
Jiri Slaby 已提交
1372
	put_tty_queue(c, ldata);
1373
	return 0;
1374
}
L
Linus Torvalds 已提交
1375

1376 1377
static inline void
n_tty_receive_char_inline(struct tty_struct *tty, unsigned char c)
P
Peter Hurley 已提交
1378 1379 1380
{
	struct n_tty_data *ldata = tty->disc_data;

1381 1382 1383 1384 1385 1386 1387 1388 1389 1390 1391
	if (tty->stopped && !tty->flow_stopped && I_IXON(tty) && I_IXANY(tty)) {
		start_tty(tty);
		process_echoes(tty);
	}
	if (L_ECHO(tty)) {
		finish_erasing(ldata);
		/* Record the column of first canon char. */
		if (ldata->canon_head == ldata->read_head)
			echo_set_canon_col(ldata);
		echo_char(c, tty);
		commit_echoes(tty);
P
Peter Hurley 已提交
1392
	}
1393 1394
	/* PARMRK doubling check */
	if (c == (unsigned char) '\377' && I_PARMRK(tty))
1395 1396 1397
		put_tty_queue(c, ldata);
	put_tty_queue(c, ldata);
}
P
Peter Hurley 已提交
1398

1399
static void n_tty_receive_char(struct tty_struct *tty, unsigned char c)
1400 1401
{
	n_tty_receive_char_inline(tty, c);
P
Peter Hurley 已提交
1402 1403
}

1404 1405 1406 1407 1408
static inline void
n_tty_receive_char_fast(struct tty_struct *tty, unsigned char c)
{
	struct n_tty_data *ldata = tty->disc_data;

1409 1410 1411
	if (tty->stopped && !tty->flow_stopped && I_IXON(tty) && I_IXANY(tty)) {
		start_tty(tty);
		process_echoes(tty);
1412
	}
1413 1414 1415 1416 1417 1418 1419 1420 1421
	if (L_ECHO(tty)) {
		finish_erasing(ldata);
		/* Record the column of first canon char. */
		if (ldata->canon_head == ldata->read_head)
			echo_set_canon_col(ldata);
		echo_char(c, tty);
		commit_echoes(tty);
	}
	put_tty_queue(c, ldata);
1422 1423
}

1424
static void n_tty_receive_char_closing(struct tty_struct *tty, unsigned char c)
1425 1426 1427 1428 1429 1430 1431 1432 1433 1434 1435 1436 1437 1438 1439 1440 1441 1442 1443
{
	if (I_ISTRIP(tty))
		c &= 0x7f;
	if (I_IUCLC(tty) && L_IEXTEN(tty))
		c = tolower(c);

	if (I_IXON(tty)) {
		if (c == STOP_CHAR(tty))
			stop_tty(tty);
		else if (c == START_CHAR(tty) ||
			 (tty->stopped && !tty->flow_stopped && I_IXANY(tty) &&
			  c != INTR_CHAR(tty) && c != QUIT_CHAR(tty) &&
			  c != SUSP_CHAR(tty))) {
			start_tty(tty);
			process_echoes(tty);
		}
	}
}

1444 1445 1446 1447 1448 1449 1450 1451 1452 1453 1454 1455 1456 1457 1458
static void
n_tty_receive_char_flagged(struct tty_struct *tty, unsigned char c, char flag)
{
	switch (flag) {
	case TTY_BREAK:
		n_tty_receive_break(tty);
		break;
	case TTY_PARITY:
	case TTY_FRAME:
		n_tty_receive_parity_error(tty, c);
		break;
	case TTY_OVERRUN:
		n_tty_receive_overrun(tty);
		break;
	default:
P
Peter Hurley 已提交
1459
		tty_err(tty, "unknown flag %d\n", flag);
1460 1461 1462 1463
		break;
	}
}

1464 1465 1466 1467 1468 1469 1470 1471 1472 1473 1474 1475 1476 1477 1478 1479
static void
n_tty_receive_char_lnext(struct tty_struct *tty, unsigned char c, char flag)
{
	struct n_tty_data *ldata = tty->disc_data;

	ldata->lnext = 0;
	if (likely(flag == TTY_NORMAL)) {
		if (I_ISTRIP(tty))
			c &= 0x7f;
		if (I_IUCLC(tty) && L_IEXTEN(tty))
			c = tolower(c);
		n_tty_receive_char(tty, c);
	} else
		n_tty_receive_char_flagged(tty, c, flag);
}

1480 1481 1482 1483 1484 1485 1486 1487
static void
n_tty_receive_buf_real_raw(struct tty_struct *tty, const unsigned char *cp,
			   char *fp, int count)
{
	struct n_tty_data *ldata = tty->disc_data;
	size_t n, head;

	head = ldata->read_head & (N_TTY_BUF_SIZE - 1);
1488
	n = min_t(size_t, count, N_TTY_BUF_SIZE - head);
1489 1490 1491 1492 1493 1494
	memcpy(read_buf_addr(ldata, head), cp, n);
	ldata->read_head += n;
	cp += n;
	count -= n;

	head = ldata->read_head & (N_TTY_BUF_SIZE - 1);
1495
	n = min_t(size_t, count, N_TTY_BUF_SIZE - head);
1496 1497 1498 1499
	memcpy(read_buf_addr(ldata, head), cp, n);
	ldata->read_head += n;
}

1500 1501 1502 1503 1504 1505 1506 1507 1508 1509 1510 1511 1512 1513 1514 1515 1516
static void
n_tty_receive_buf_raw(struct tty_struct *tty, const unsigned char *cp,
		      char *fp, int count)
{
	struct n_tty_data *ldata = tty->disc_data;
	char flag = TTY_NORMAL;

	while (count--) {
		if (fp)
			flag = *fp++;
		if (likely(flag == TTY_NORMAL))
			put_tty_queue(*cp++, ldata);
		else
			n_tty_receive_char_flagged(tty, *cp++, flag);
	}
}

1517 1518 1519 1520 1521 1522 1523 1524 1525 1526 1527 1528 1529 1530
static void
n_tty_receive_buf_closing(struct tty_struct *tty, const unsigned char *cp,
			  char *fp, int count)
{
	char flag = TTY_NORMAL;

	while (count--) {
		if (fp)
			flag = *fp++;
		if (likely(flag == TTY_NORMAL))
			n_tty_receive_char_closing(tty, *cp++);
	}
}

1531 1532
static void
n_tty_receive_buf_standard(struct tty_struct *tty, const unsigned char *cp,
1533 1534 1535 1536 1537 1538 1539 1540 1541 1542 1543 1544 1545 1546 1547 1548 1549 1550 1551
			  char *fp, int count)
{
	struct n_tty_data *ldata = tty->disc_data;
	char flag = TTY_NORMAL;

	while (count--) {
		if (fp)
			flag = *fp++;
		if (likely(flag == TTY_NORMAL)) {
			unsigned char c = *cp++;

			if (I_ISTRIP(tty))
				c &= 0x7f;
			if (I_IUCLC(tty) && L_IEXTEN(tty))
				c = tolower(c);
			if (L_EXTPROC(tty)) {
				put_tty_queue(c, ldata);
				continue;
			}
1552 1553 1554 1555 1556 1557 1558 1559
			if (!test_bit(c, ldata->char_map))
				n_tty_receive_char_inline(tty, c);
			else if (n_tty_receive_char_special(tty, c) && count) {
				if (fp)
					flag = *fp++;
				n_tty_receive_char_lnext(tty, *cp++, flag);
				count--;
			}
1560 1561 1562 1563 1564 1565 1566 1567
		} else
			n_tty_receive_char_flagged(tty, *cp++, flag);
	}
}

static void
n_tty_receive_buf_fast(struct tty_struct *tty, const unsigned char *cp,
		       char *fp, int count)
1568
{
1569
	struct n_tty_data *ldata = tty->disc_data;
1570 1571 1572 1573 1574
	char flag = TTY_NORMAL;

	while (count--) {
		if (fp)
			flag = *fp++;
1575 1576 1577 1578 1579 1580 1581 1582 1583 1584 1585 1586
		if (likely(flag == TTY_NORMAL)) {
			unsigned char c = *cp++;

			if (!test_bit(c, ldata->char_map))
				n_tty_receive_char_fast(tty, c);
			else if (n_tty_receive_char_special(tty, c) && count) {
				if (fp)
					flag = *fp++;
				n_tty_receive_char_lnext(tty, *cp++, flag);
				count--;
			}
		} else
1587 1588 1589 1590
			n_tty_receive_char_flagged(tty, *cp++, flag);
	}
}

1591 1592
static void __receive_buf(struct tty_struct *tty, const unsigned char *cp,
			  char *fp, int count)
L
Linus Torvalds 已提交
1593
{
1594
	struct n_tty_data *ldata = tty->disc_data;
1595
	bool preops = I_ISTRIP(tty) || (I_IUCLC(tty) && L_IEXTEN(tty));
L
Linus Torvalds 已提交
1596

1597 1598
	if (ldata->real_raw)
		n_tty_receive_buf_real_raw(tty, cp, fp, count);
1599
	else if (ldata->raw || (L_EXTPROC(tty) && !preops))
1600
		n_tty_receive_buf_raw(tty, cp, fp, count);
1601 1602
	else if (tty->closing && !L_EXTPROC(tty))
		n_tty_receive_buf_closing(tty, cp, fp, count);
1603
	else {
1604 1605 1606 1607 1608 1609 1610 1611 1612
		if (ldata->lnext) {
			char flag = TTY_NORMAL;

			if (fp)
				flag = *fp++;
			n_tty_receive_char_lnext(tty, *cp++, flag);
			count--;
		}

1613
		if (!preops && !I_PARMRK(tty))
1614 1615 1616
			n_tty_receive_buf_fast(tty, cp, fp, count);
		else
			n_tty_receive_buf_standard(tty, cp, fp, count);
P
Peter Hurley 已提交
1617 1618

		flush_echoes(tty);
A
Alan Cox 已提交
1619 1620
		if (tty->ops->flush_chars)
			tty->ops->flush_chars(tty);
L
Linus Torvalds 已提交
1621 1622
	}

1623 1624 1625 1626 1627 1628
	if (ldata->icanon && !L_EXTPROC(tty))
		return;

	/* publish read_head to consumer */
	smp_store_release(&ldata->commit_head, ldata->read_head);

1629
	if (read_cnt(ldata)) {
L
Linus Torvalds 已提交
1630
		kill_fasync(&tty->fasync, SIGIO, POLL_IN);
1631
		wake_up_interruptible_poll(&tty->read_wait, EPOLLIN);
L
Linus Torvalds 已提交
1632 1633 1634
	}
}

1635 1636 1637 1638 1639 1640 1641 1642 1643 1644 1645 1646 1647 1648 1649 1650 1651 1652 1653 1654 1655 1656 1657 1658 1659 1660 1661 1662 1663 1664 1665 1666 1667
/**
 *	n_tty_receive_buf_common	-	process input
 *	@tty: device to receive input
 *	@cp: input chars
 *	@fp: flags for each char (if NULL, all chars are TTY_NORMAL)
 *	@count: number of input chars in @cp
 *
 *	Called by the terminal driver when a block of characters has
 *	been received. This function must be called from soft contexts
 *	not from interrupt context. The driver is responsible for making
 *	calls one at a time and in order (or using flush_to_ldisc)
 *
 *	Returns the # of input chars from @cp which were processed.
 *
 *	In canonical mode, the maximum line length is 4096 chars (including
 *	the line termination char); lines longer than 4096 chars are
 *	truncated. After 4095 chars, input data is still processed but
 *	not stored. Overflow processing ensures the tty can always
 *	receive more input until at least one line can be read.
 *
 *	In non-canonical mode, the read buffer will only accept 4095 chars;
 *	this provides the necessary space for a newline char if the input
 *	mode is switched to canonical.
 *
 *	Note it is possible for the read buffer to _contain_ 4096 chars
 *	in non-canonical mode: the read buffer could already contain the
 *	maximum canon line of 4096 chars when the mode is switched to
 *	non-canonical.
 *
 *	n_tty_receive_buf()/producer path:
 *		claims non-exclusive termios_rwsem
 *		publishes commit_head or canon_head
 */
P
Peter Hurley 已提交
1668 1669 1670
static int
n_tty_receive_buf_common(struct tty_struct *tty, const unsigned char *cp,
			 char *fp, int count, int flow)
1671 1672
{
	struct n_tty_data *ldata = tty->disc_data;
1673
	int room, n, rcvd = 0, overflow;
1674

1675 1676
	down_read(&tty->termios_rwsem);

1677
	while (1) {
1678
		/*
P
Peter Hurley 已提交
1679 1680
		 * When PARMRK is set, each input char may take up to 3 chars
		 * in the read buf; reduce the buffer space avail by 3x
1681 1682 1683 1684 1685 1686 1687 1688 1689 1690 1691 1692
		 *
		 * If we are doing input canonicalization, and there are no
		 * pending newlines, let characters through without limit, so
		 * that erase characters will be handled.  Other excess
		 * characters will be beeped.
		 *
		 * paired with store in *_copy_from_read_buf() -- guarantees
		 * the consumer has loaded the data in read_buf up to the new
		 * read_tail (so this producer will not overwrite unread data)
		 */
		size_t tail = smp_load_acquire(&ldata->read_tail);

1693
		room = N_TTY_BUF_SIZE - (ldata->read_head - tail);
1694
		if (I_PARMRK(tty))
1695 1696 1697 1698 1699 1700 1701 1702 1703 1704
			room = (room + 2) / 3;
		room--;
		if (room <= 0) {
			overflow = ldata->icanon && ldata->canon_head == tail;
			if (overflow && room < 0)
				ldata->read_head--;
			room = overflow;
			ldata->no_room = flow && !room;
		} else
			overflow = 0;
1705

1706
		n = min(count, room);
1707
		if (!n)
1708
			break;
1709 1710 1711 1712 1713

		/* ignore parity errors if handling overflow */
		if (!overflow || !fp || *fp != TTY_PARITY)
			__receive_buf(tty, cp, fp, n);

1714 1715 1716 1717 1718
		cp += n;
		if (fp)
			fp += n;
		count -= n;
		rcvd += n;
1719
	}
1720

1721
	tty->receive_room = room;
1722 1723 1724 1725 1726 1727 1728 1729 1730 1731 1732

	/* Unthrottle if handling overflow on pty */
	if (tty->driver->type == TTY_DRIVER_TYPE_PTY) {
		if (overflow) {
			tty_set_flow_change(tty, TTY_UNTHROTTLE_SAFE);
			tty_unthrottle_safe(tty);
			__tty_set_flow_change(tty, 0);
		}
	} else
		n_tty_check_throttle(tty);

1733 1734
	up_read(&tty->termios_rwsem);

1735
	return rcvd;
1736 1737
}

P
Peter Hurley 已提交
1738 1739 1740 1741 1742 1743 1744 1745 1746 1747 1748 1749
static void n_tty_receive_buf(struct tty_struct *tty, const unsigned char *cp,
			      char *fp, int count)
{
	n_tty_receive_buf_common(tty, cp, fp, count, 0);
}

static int n_tty_receive_buf2(struct tty_struct *tty, const unsigned char *cp,
			      char *fp, int count)
{
	return n_tty_receive_buf_common(tty, cp, fp, count, 1);
}

L
Linus Torvalds 已提交
1750 1751 1752 1753 1754 1755 1756
/**
 *	n_tty_set_termios	-	termios data changed
 *	@tty: terminal
 *	@old: previous data
 *
 *	Called by the tty layer when the user changes termios flags so
 *	that the line discipline can plan ahead. This function cannot sleep
1757
 *	and is protected from re-entry by the tty layer. The user is
L
Linus Torvalds 已提交
1758 1759
 *	guaranteed that this function will not be re-entered or in progress
 *	when the ldisc is closed.
1760
 *
1761
 *	Locking: Caller holds tty->termios_rwsem
L
Linus Torvalds 已提交
1762
 */
1763 1764

static void n_tty_set_termios(struct tty_struct *tty, struct ktermios *old)
L
Linus Torvalds 已提交
1765
{
1766
	struct n_tty_data *ldata = tty->disc_data;
1767

1768
	if (!old || (old->c_lflag ^ tty->termios.c_lflag) & (ICANON | EXTPROC)) {
1769
		bitmap_zero(ldata->read_flags, N_TTY_BUF_SIZE);
1770 1771 1772 1773 1774 1775 1776 1777 1778 1779
		ldata->line_start = ldata->read_tail;
		if (!L_ICANON(tty) || !read_cnt(ldata)) {
			ldata->canon_head = ldata->read_tail;
			ldata->push = 0;
		} else {
			set_bit((ldata->read_head - 1) & (N_TTY_BUF_SIZE - 1),
				ldata->read_flags);
			ldata->canon_head = ldata->read_head;
			ldata->push = 1;
		}
1780
		ldata->commit_head = ldata->read_head;
1781
		ldata->erasing = 0;
1782
		ldata->lnext = 0;
1783 1784
	}

1785
	ldata->icanon = (L_ICANON(tty) != 0);
P
Peter Hurley 已提交
1786

L
Linus Torvalds 已提交
1787 1788 1789 1790
	if (I_ISTRIP(tty) || I_IUCLC(tty) || I_IGNCR(tty) ||
	    I_ICRNL(tty) || I_INLCR(tty) || L_ICANON(tty) ||
	    I_IXON(tty) || L_ISIG(tty) || L_ECHO(tty) ||
	    I_PARMRK(tty)) {
1791
		bitmap_zero(ldata->char_map, 256);
L
Linus Torvalds 已提交
1792 1793

		if (I_IGNCR(tty) || I_ICRNL(tty))
1794
			set_bit('\r', ldata->char_map);
L
Linus Torvalds 已提交
1795
		if (I_INLCR(tty))
1796
			set_bit('\n', ldata->char_map);
L
Linus Torvalds 已提交
1797 1798

		if (L_ICANON(tty)) {
1799 1800 1801 1802 1803
			set_bit(ERASE_CHAR(tty), ldata->char_map);
			set_bit(KILL_CHAR(tty), ldata->char_map);
			set_bit(EOF_CHAR(tty), ldata->char_map);
			set_bit('\n', ldata->char_map);
			set_bit(EOL_CHAR(tty), ldata->char_map);
L
Linus Torvalds 已提交
1804
			if (L_IEXTEN(tty)) {
1805 1806 1807
				set_bit(WERASE_CHAR(tty), ldata->char_map);
				set_bit(LNEXT_CHAR(tty), ldata->char_map);
				set_bit(EOL2_CHAR(tty), ldata->char_map);
L
Linus Torvalds 已提交
1808 1809
				if (L_ECHO(tty))
					set_bit(REPRINT_CHAR(tty),
1810
						ldata->char_map);
L
Linus Torvalds 已提交
1811 1812 1813
			}
		}
		if (I_IXON(tty)) {
1814 1815
			set_bit(START_CHAR(tty), ldata->char_map);
			set_bit(STOP_CHAR(tty), ldata->char_map);
L
Linus Torvalds 已提交
1816 1817
		}
		if (L_ISIG(tty)) {
1818 1819 1820
			set_bit(INTR_CHAR(tty), ldata->char_map);
			set_bit(QUIT_CHAR(tty), ldata->char_map);
			set_bit(SUSP_CHAR(tty), ldata->char_map);
L
Linus Torvalds 已提交
1821
		}
1822
		clear_bit(__DISABLED_CHAR, ldata->char_map);
1823 1824
		ldata->raw = 0;
		ldata->real_raw = 0;
L
Linus Torvalds 已提交
1825
	} else {
1826
		ldata->raw = 1;
L
Linus Torvalds 已提交
1827 1828 1829
		if ((I_IGNBRK(tty) || (!I_BRKINT(tty) && !I_PARMRK(tty))) &&
		    (I_IGNPAR(tty) || !I_INPCK(tty)) &&
		    (tty->driver->flags & TTY_DRIVER_REAL_RAW))
1830
			ldata->real_raw = 1;
L
Linus Torvalds 已提交
1831
		else
1832
			ldata->real_raw = 0;
L
Linus Torvalds 已提交
1833
	}
1834 1835 1836 1837
	/*
	 * Fix tty hang when I_IXON(tty) is cleared, but the tty
	 * been stopped by STOP_CHAR(tty) before it.
	 */
P
Peter Hurley 已提交
1838
	if (!I_IXON(tty) && old && (old->c_iflag & IXON) && !tty->flow_stopped) {
1839
		start_tty(tty);
P
Peter Hurley 已提交
1840 1841
		process_echoes(tty);
	}
1842

A
Alan Cox 已提交
1843
	/* The termios change make the tty ready for I/O */
1844 1845
	wake_up_interruptible(&tty->write_wait);
	wake_up_interruptible(&tty->read_wait);
L
Linus Torvalds 已提交
1846 1847 1848 1849 1850 1851
}

/**
 *	n_tty_close		-	close the ldisc for this tty
 *	@tty: device
 *
1852 1853
 *	Called from the terminal layer when this line discipline is
 *	being shut down, either because of a close or becsuse of a
L
Linus Torvalds 已提交
1854 1855 1856
 *	discipline change. The function will not be called while other
 *	ldisc methods are in progress.
 */
1857

L
Linus Torvalds 已提交
1858 1859
static void n_tty_close(struct tty_struct *tty)
{
J
Jiri Slaby 已提交
1860 1861
	struct n_tty_data *ldata = tty->disc_data;

1862 1863 1864
	if (tty->link)
		n_tty_packet_mode_flush(tty);

1865
	vfree(ldata);
J
Jiri Slaby 已提交
1866
	tty->disc_data = NULL;
L
Linus Torvalds 已提交
1867 1868 1869 1870 1871 1872
}

/**
 *	n_tty_open		-	open an ldisc
 *	@tty: terminal to open
 *
1873
 *	Called when this line discipline is being attached to the
L
Linus Torvalds 已提交
1874 1875 1876 1877 1878 1879 1880
 *	terminal device. Can sleep. Called serialized so that no
 *	other events will occur in parallel. No further open will occur
 *	until a close.
 */

static int n_tty_open(struct tty_struct *tty)
{
J
Jiri Slaby 已提交
1881 1882
	struct n_tty_data *ldata;

1883 1884
	/* Currently a malloc failure here can panic */
	ldata = vmalloc(sizeof(*ldata));
J
Jiri Slaby 已提交
1885 1886 1887
	if (!ldata)
		goto err;

1888
	ldata->overrun_time = jiffies;
1889 1890
	mutex_init(&ldata->atomic_read_lock);
	mutex_init(&ldata->output_lock);
1891

J
Jiri Slaby 已提交
1892
	tty->disc_data = ldata;
1893
	reset_buffer_flags(tty->disc_data);
1894
	ldata->column = 0;
1895 1896 1897 1898
	ldata->canon_column = 0;
	ldata->num_overrun = 0;
	ldata->no_room = 0;
	ldata->lnext = 0;
L
Linus Torvalds 已提交
1899
	tty->closing = 0;
1900 1901 1902 1903
	/* indicate buffer work may resume */
	clear_bit(TTY_LDISC_HALTED, &tty->flags);
	n_tty_set_termios(tty, NULL);
	tty_unthrottle(tty);
J
Jiri Slaby 已提交
1904

L
Linus Torvalds 已提交
1905
	return 0;
J
Jiri Slaby 已提交
1906
err:
1907
	return -ENOMEM;
L
Linus Torvalds 已提交
1908 1909
}

1910
static inline int input_available_p(struct tty_struct *tty, int poll)
L
Linus Torvalds 已提交
1911
{
1912
	struct n_tty_data *ldata = tty->disc_data;
1913
	int amt = poll && !TIME_CHAR(tty) && MIN_CHAR(tty) ? MIN_CHAR(tty) : 1;
1914

1915 1916 1917
	if (ldata->icanon && !L_EXTPROC(tty))
		return ldata->canon_head != ldata->read_tail;
	else
1918
		return ldata->commit_head - ldata->read_tail >= amt;
L
Linus Torvalds 已提交
1919 1920 1921
}

/**
1922
 *	copy_from_read_buf	-	copy read data directly
L
Linus Torvalds 已提交
1923 1924 1925 1926
 *	@tty: terminal device
 *	@b: user data
 *	@nr: size of data
 *
1927
 *	Helper function to speed up n_tty_read.  It is only called when
L
Linus Torvalds 已提交
1928 1929 1930 1931 1932 1933
 *	ICANON is off; it copies characters straight from the tty queue to
 *	user space directly.  It can be profitably called twice; once to
 *	drain the space from the tail pointer to the (physical) end of the
 *	buffer, and once to drain the space from the (physical) beginning of
 *	the buffer to head pointer.
 *
1934
 *	Called under the ldata->atomic_read_lock sem
L
Linus Torvalds 已提交
1935
 *
1936 1937 1938
 *	n_tty_read()/consumer path:
 *		caller holds non-exclusive termios_rwsem
 *		read_tail published
L
Linus Torvalds 已提交
1939
 */
1940

A
Alan Cox 已提交
1941
static int copy_from_read_buf(struct tty_struct *tty,
L
Linus Torvalds 已提交
1942 1943 1944 1945
				      unsigned char __user **b,
				      size_t *nr)

{
1946
	struct n_tty_data *ldata = tty->disc_data;
L
Linus Torvalds 已提交
1947 1948
	int retval;
	size_t n;
1949
	bool is_eof;
1950
	size_t head = smp_load_acquire(&ldata->commit_head);
1951
	size_t tail = ldata->read_tail & (N_TTY_BUF_SIZE - 1);
L
Linus Torvalds 已提交
1952 1953

	retval = 0;
1954
	n = min(head - ldata->read_tail, N_TTY_BUF_SIZE - tail);
L
Linus Torvalds 已提交
1955 1956
	n = min(*nr, n);
	if (n) {
P
Peter Hurley 已提交
1957 1958
		const unsigned char *from = read_buf_addr(ldata, tail);
		retval = copy_to_user(*b, from, n);
L
Linus Torvalds 已提交
1959
		n -= retval;
P
Peter Hurley 已提交
1960
		is_eof = n == 1 && *from == EOF_CHAR(tty);
1961
		tty_audit_add_data(tty, from, n);
1962
		smp_store_release(&ldata->read_tail, ldata->read_tail + n);
1963
		/* Turn single EOF into zero-length read */
1964 1965
		if (L_EXTPROC(tty) && ldata->icanon && is_eof &&
		    (head == ldata->read_tail))
1966
			n = 0;
L
Linus Torvalds 已提交
1967 1968 1969 1970 1971 1972
		*b += n;
		*nr -= n;
	}
	return retval;
}

1973
/**
1974
 *	canon_copy_from_read_buf	-	copy read data in canonical mode
1975 1976 1977 1978 1979
 *	@tty: terminal device
 *	@b: user data
 *	@nr: size of data
 *
 *	Helper function for n_tty_read.  It is only called when ICANON is on;
1980 1981
 *	it copies one line of input up to and including the line-delimiting
 *	character into the user-space buffer.
1982
 *
1983 1984 1985 1986 1987 1988
 *	NB: When termios is changed from non-canonical to canonical mode and
 *	the read buffer contains data, n_tty_set_termios() simulates an EOF
 *	push (as if C-d were input) _without_ the DISABLED_CHAR in the buffer.
 *	This causes data already processed as input to be immediately available
 *	as input although a newline has not been received.
 *
1989
 *	Called under the atomic_read_lock mutex
1990 1991 1992 1993
 *
 *	n_tty_read()/consumer path:
 *		caller holds non-exclusive termios_rwsem
 *		read_tail published
1994 1995
 */

1996 1997 1998
static int canon_copy_from_read_buf(struct tty_struct *tty,
				    unsigned char __user **b,
				    size_t *nr)
1999 2000
{
	struct n_tty_data *ldata = tty->disc_data;
2001
	size_t n, size, more, c;
2002 2003 2004
	size_t eol;
	size_t tail;
	int ret, found = 0;
2005 2006

	/* N.B. avoid overrun if nr == 0 */
2007
	if (!*nr)
2008
		return 0;
2009

2010 2011
	n = min(*nr + 1, smp_load_acquire(&ldata->canon_head) - ldata->read_tail);

2012
	tail = ldata->read_tail & (N_TTY_BUF_SIZE - 1);
2013 2014
	size = min_t(size_t, tail + n, N_TTY_BUF_SIZE);

2015
	n_tty_trace("%s: nr:%zu tail:%zu n:%zu size:%zu\n",
2016 2017 2018 2019 2020 2021 2022
		    __func__, *nr, tail, n, size);

	eol = find_next_bit(ldata->read_flags, size, tail);
	more = n - (size - tail);
	if (eol == N_TTY_BUF_SIZE && more) {
		/* scan wrapped without finding set bit */
		eol = find_next_bit(ldata->read_flags, more, 0);
2023 2024 2025
		found = eol != more;
	} else
		found = eol != size;
2026

2027
	n = eol - tail;
2028 2029
	if (n > N_TTY_BUF_SIZE)
		n += N_TTY_BUF_SIZE;
2030
	c = n + found;
2031

2032 2033 2034
	if (!found || read_buf(ldata, eol) != __DISABLED_CHAR) {
		c = min(*nr, c);
		n = c;
P
Peter Hurley 已提交
2035
	}
2036

P
Peter Hurley 已提交
2037 2038
	n_tty_trace("%s: eol:%zu found:%d n:%zu c:%zu tail:%zu more:%zu\n",
		    __func__, eol, found, n, c, tail, more);
2039

P
Peter Hurley 已提交
2040
	ret = tty_copy_to_user(tty, *b, tail, n);
2041 2042 2043 2044 2045
	if (ret)
		return -EFAULT;
	*b += n;
	*nr -= n;

2046
	if (found)
2047
		clear_bit(eol, ldata->read_flags);
2048
	smp_store_release(&ldata->read_tail, ldata->read_tail + c);
2049

P
Peter Hurley 已提交
2050
	if (found) {
2051 2052 2053 2054
		if (!ldata->push)
			ldata->line_start = ldata->read_tail;
		else
			ldata->push = 0;
2055
		tty_audit_push();
P
Peter Hurley 已提交
2056
	}
2057
	return 0;
2058 2059
}

2060
extern ssize_t redirected_tty_write(struct file *, const char __user *,
2061
							size_t, loff_t *);
L
Linus Torvalds 已提交
2062 2063 2064 2065 2066 2067 2068

/**
 *	job_control		-	check job control
 *	@tty: tty
 *	@file: file handle
 *
 *	Perform job control management checks on this file/tty descriptor
2069
 *	and if appropriate send any needed signals and return a negative
L
Linus Torvalds 已提交
2070
 *	error code if action should be taken.
A
Alan Cox 已提交
2071
 *
2072 2073 2074
 *	Locking: redirected write test is safe
 *		 current->signal->tty check is safe
 *		 ctrl_lock to safely reference tty->pgrp
L
Linus Torvalds 已提交
2075
 */
2076

L
Linus Torvalds 已提交
2077 2078 2079 2080 2081 2082 2083
static int job_control(struct tty_struct *tty, struct file *file)
{
	/* Job control check -- must be done at start and after
	   every sleep (POSIX.1 7.1.1.4). */
	/* NOTE: not yet done after every sleep pending a thorough
	   check of the logic of this change. -- jlc */
	/* don't stop on /dev/console */
2084
	if (file->f_op->write == redirected_tty_write)
2085 2086
		return 0;

2087
	return __tty_check_change(tty, SIGTTIN);
L
Linus Torvalds 已提交
2088
}
2089

L
Linus Torvalds 已提交
2090 2091

/**
2092
 *	n_tty_read		-	read function for tty
L
Linus Torvalds 已提交
2093 2094 2095 2096 2097 2098 2099 2100 2101 2102 2103
 *	@tty: tty device
 *	@file: file object
 *	@buf: userspace buffer pointer
 *	@nr: size of I/O
 *
 *	Perform reads for the line discipline. We are guaranteed that the
 *	line discipline will not be closed under us but we may get multiple
 *	parallel readers and must handle this ourselves. We may also get
 *	a hangup. Always called in user context, may sleep.
 *
 *	This code must be sure never to sleep through a hangup.
2104 2105 2106 2107
 *
 *	n_tty_read()/consumer path:
 *		claims non-exclusive termios_rwsem
 *		publishes read_tail
L
Linus Torvalds 已提交
2108
 */
2109

2110
static ssize_t n_tty_read(struct tty_struct *tty, struct file *file,
L
Linus Torvalds 已提交
2111 2112
			 unsigned char __user *buf, size_t nr)
{
2113
	struct n_tty_data *ldata = tty->disc_data;
L
Linus Torvalds 已提交
2114
	unsigned char __user *b = buf;
2115
	DEFINE_WAIT_FUNC(wait, woken_wake_function);
2116
	int c;
L
Linus Torvalds 已提交
2117 2118 2119
	int minimum, time;
	ssize_t retval = 0;
	long timeout;
A
Alan Cox 已提交
2120
	int packet;
2121
	size_t tail;
L
Linus Torvalds 已提交
2122 2123

	c = job_control(tty, file);
2124
	if (c < 0)
L
Linus Torvalds 已提交
2125
		return c;
2126

2127 2128 2129 2130 2131 2132 2133 2134 2135 2136 2137
	/*
	 *	Internal serialization of reads.
	 */
	if (file->f_flags & O_NONBLOCK) {
		if (!mutex_trylock(&ldata->atomic_read_lock))
			return -EAGAIN;
	} else {
		if (mutex_lock_interruptible(&ldata->atomic_read_lock))
			return -ERESTARTSYS;
	}

2138 2139
	down_read(&tty->termios_rwsem);

L
Linus Torvalds 已提交
2140 2141
	minimum = time = 0;
	timeout = MAX_SCHEDULE_TIMEOUT;
2142
	if (!ldata->icanon) {
L
Linus Torvalds 已提交
2143 2144
		minimum = MIN_CHAR(tty);
		if (minimum) {
2145
			time = (HZ / 10) * TIME_CHAR(tty);
L
Linus Torvalds 已提交
2146
		} else {
2147
			timeout = (HZ / 10) * TIME_CHAR(tty);
2148
			minimum = 1;
L
Linus Torvalds 已提交
2149 2150 2151
		}
	}

A
Alan Cox 已提交
2152
	packet = tty->packet;
2153
	tail = ldata->read_tail;
L
Linus Torvalds 已提交
2154 2155 2156 2157

	add_wait_queue(&tty->read_wait, &wait);
	while (nr) {
		/* First test for status change. */
A
Alan Cox 已提交
2158
		if (packet && tty->link->ctrl_status) {
L
Linus Torvalds 已提交
2159 2160 2161
			unsigned char cs;
			if (b != buf)
				break;
2162
			spin_lock_irq(&tty->link->ctrl_lock);
L
Linus Torvalds 已提交
2163 2164
			cs = tty->link->ctrl_status;
			tty->link->ctrl_status = 0;
2165
			spin_unlock_irq(&tty->link->ctrl_lock);
2166
			if (put_user(cs, b)) {
L
Linus Torvalds 已提交
2167 2168 2169
				retval = -EFAULT;
				break;
			}
2170
			b++;
L
Linus Torvalds 已提交
2171 2172 2173
			nr--;
			break;
		}
2174

L
Linus Torvalds 已提交
2175
		if (!input_available_p(tty, 0)) {
2176
			up_read(&tty->termios_rwsem);
2177 2178 2179 2180 2181 2182 2183 2184 2185
			tty_buffer_flush_work(tty->port);
			down_read(&tty->termios_rwsem);
			if (!input_available_p(tty, 0)) {
				if (test_bit(TTY_OTHER_CLOSED, &tty->flags)) {
					retval = -EIO;
					break;
				}
				if (tty_hung_up_p(file))
					break;
2186 2187 2188 2189 2190 2191
				/*
				 * Abort readers for ttys which never actually
				 * get hung up.  See __tty_hangup().
				 */
				if (test_bit(TTY_HUPPING, &tty->flags))
					break;
2192 2193 2194 2195 2196 2197 2198 2199 2200 2201 2202
				if (!timeout)
					break;
				if (file->f_flags & O_NONBLOCK) {
					retval = -EAGAIN;
					break;
				}
				if (signal_pending(current)) {
					retval = -ERESTARTSYS;
					break;
				}
				up_read(&tty->termios_rwsem);
2203

2204 2205
				timeout = wait_woken(&wait, TASK_INTERRUPTIBLE,
						timeout);
2206

2207 2208 2209
				down_read(&tty->termios_rwsem);
				continue;
			}
L
Linus Torvalds 已提交
2210 2211
		}

2212
		if (ldata->icanon && !L_EXTPROC(tty)) {
2213
			retval = canon_copy_from_read_buf(tty, &b, &nr);
2214
			if (retval)
L
Linus Torvalds 已提交
2215 2216 2217
				break;
		} else {
			int uncopied;
2218 2219 2220

			/* Deal with packet mode. */
			if (packet && b == buf) {
2221
				if (put_user(TIOCPKT_DATA, b)) {
2222 2223 2224
					retval = -EFAULT;
					break;
				}
2225
				b++;
2226 2227 2228
				nr--;
			}

L
Linus Torvalds 已提交
2229 2230 2231 2232 2233 2234 2235 2236
			uncopied = copy_from_read_buf(tty, &b, &nr);
			uncopied += copy_from_read_buf(tty, &b, &nr);
			if (uncopied) {
				retval = -EFAULT;
				break;
			}
		}

2237
		n_tty_check_unthrottle(tty);
L
Linus Torvalds 已提交
2238 2239 2240 2241 2242 2243

		if (b - buf >= minimum)
			break;
		if (time)
			timeout = time;
	}
2244 2245
	if (tail != ldata->read_tail)
		n_tty_kick_worker(tty);
2246 2247
	up_read(&tty->termios_rwsem);

L
Linus Torvalds 已提交
2248
	remove_wait_queue(&tty->read_wait, &wait);
2249 2250
	mutex_unlock(&ldata->atomic_read_lock);

P
Peter Hurley 已提交
2251 2252
	if (b - buf)
		retval = b - buf;
L
Linus Torvalds 已提交
2253 2254 2255 2256 2257

	return retval;
}

/**
2258
 *	n_tty_write		-	write function for tty
L
Linus Torvalds 已提交
2259 2260 2261 2262 2263
 *	@tty: tty device
 *	@file: file object
 *	@buf: userspace buffer pointer
 *	@nr: size of I/O
 *
2264
 *	Write function of the terminal device.  This is serialized with
L
Linus Torvalds 已提交
2265
 *	respect to other write callers but not to termios changes, reads
2266 2267 2268 2269 2270
 *	and other such events.  Since the receive code will echo characters,
 *	thus calling driver write methods, the output_lock is used in
 *	the output processing functions called here as well as in the
 *	echo processing function to protect the column state and space
 *	left in the buffer.
L
Linus Torvalds 已提交
2271 2272
 *
 *	This code must be sure never to sleep through a hangup.
2273 2274 2275 2276
 *
 *	Locking: output_lock to protect column state and space left
 *		 (note that the process_output*() functions take this
 *		  lock themselves)
L
Linus Torvalds 已提交
2277
 */
2278

2279
static ssize_t n_tty_write(struct tty_struct *tty, struct file *file,
2280
			   const unsigned char *buf, size_t nr)
L
Linus Torvalds 已提交
2281 2282
{
	const unsigned char *b = buf;
2283
	DEFINE_WAIT_FUNC(wait, woken_wake_function);
L
Linus Torvalds 已提交
2284 2285 2286 2287 2288 2289 2290 2291 2292 2293
	int c;
	ssize_t retval = 0;

	/* Job control check -- must be done at start (POSIX.1 7.1.1.4). */
	if (L_TOSTOP(tty) && file->f_op->write != redirected_tty_write) {
		retval = tty_check_change(tty);
		if (retval)
			return retval;
	}

2294 2295
	down_read(&tty->termios_rwsem);

2296 2297
	/* Write out any echoed characters that are still pending */
	process_echoes(tty);
A
Alan Cox 已提交
2298

L
Linus Torvalds 已提交
2299 2300 2301 2302 2303 2304 2305 2306 2307 2308
	add_wait_queue(&tty->write_wait, &wait);
	while (1) {
		if (signal_pending(current)) {
			retval = -ERESTARTSYS;
			break;
		}
		if (tty_hung_up_p(file) || (tty->link && !tty->link->count)) {
			retval = -EIO;
			break;
		}
P
Peter Hurley 已提交
2309
		if (O_OPOST(tty)) {
L
Linus Torvalds 已提交
2310
			while (nr > 0) {
2311
				ssize_t num = process_output_block(tty, b, nr);
L
Linus Torvalds 已提交
2312 2313 2314 2315 2316 2317 2318 2319 2320 2321 2322
				if (num < 0) {
					if (num == -EAGAIN)
						break;
					retval = num;
					goto break_out;
				}
				b += num;
				nr -= num;
				if (nr == 0)
					break;
				c = *b;
2323
				if (process_output(c, tty) < 0)
L
Linus Torvalds 已提交
2324 2325 2326
					break;
				b++; nr--;
			}
A
Alan Cox 已提交
2327 2328
			if (tty->ops->flush_chars)
				tty->ops->flush_chars(tty);
L
Linus Torvalds 已提交
2329
		} else {
2330 2331
			struct n_tty_data *ldata = tty->disc_data;

R
Roman Zippel 已提交
2332
			while (nr > 0) {
2333
				mutex_lock(&ldata->output_lock);
A
Alan Cox 已提交
2334
				c = tty->ops->write(tty, b, nr);
2335
				mutex_unlock(&ldata->output_lock);
R
Roman Zippel 已提交
2336 2337 2338 2339 2340 2341 2342 2343
				if (c < 0) {
					retval = c;
					goto break_out;
				}
				if (!c)
					break;
				b += c;
				nr -= c;
L
Linus Torvalds 已提交
2344 2345 2346 2347 2348 2349 2350 2351
			}
		}
		if (!nr)
			break;
		if (file->f_flags & O_NONBLOCK) {
			retval = -EAGAIN;
			break;
		}
2352 2353
		up_read(&tty->termios_rwsem);

2354
		wait_woken(&wait, TASK_INTERRUPTIBLE, MAX_SCHEDULE_TIMEOUT);
2355 2356

		down_read(&tty->termios_rwsem);
L
Linus Torvalds 已提交
2357 2358 2359
	}
break_out:
	remove_wait_queue(&tty->write_wait, &wait);
P
Peter Hurley 已提交
2360
	if (nr && tty->fasync)
2361
		set_bit(TTY_DO_WRITE_WAKEUP, &tty->flags);
2362
	up_read(&tty->termios_rwsem);
L
Linus Torvalds 已提交
2363 2364 2365 2366
	return (b - buf) ? b - buf : retval;
}

/**
2367
 *	n_tty_poll		-	poll method for N_TTY
L
Linus Torvalds 已提交
2368 2369 2370 2371 2372 2373 2374 2375 2376 2377 2378
 *	@tty: terminal device
 *	@file: file accessing it
 *	@wait: poll table
 *
 *	Called when the line discipline is asked to poll() for data or
 *	for special events. This code is not serialized with respect to
 *	other events save open/close.
 *
 *	This code must be sure never to sleep through a hangup.
 *	Called without the kernel lock held - fine
 */
2379

2380
static __poll_t n_tty_poll(struct tty_struct *tty, struct file *file,
2381
							poll_table *wait)
L
Linus Torvalds 已提交
2382
{
2383
	__poll_t mask = 0;
L
Linus Torvalds 已提交
2384 2385 2386

	poll_wait(file, &tty->read_wait, wait);
	poll_wait(file, &tty->write_wait, wait);
2387
	if (input_available_p(tty, 1))
2388
		mask |= EPOLLIN | EPOLLRDNORM;
2389 2390 2391
	else {
		tty_buffer_flush_work(tty->port);
		if (input_available_p(tty, 1))
2392
			mask |= EPOLLIN | EPOLLRDNORM;
2393
	}
L
Linus Torvalds 已提交
2394
	if (tty->packet && tty->link->ctrl_status)
2395
		mask |= EPOLLPRI | EPOLLIN | EPOLLRDNORM;
2396
	if (test_bit(TTY_OTHER_CLOSED, &tty->flags))
2397
		mask |= EPOLLHUP;
L
Linus Torvalds 已提交
2398
	if (tty_hung_up_p(file))
2399
		mask |= EPOLLHUP;
A
Alan Cox 已提交
2400 2401 2402
	if (tty->ops->write && !tty_is_writelocked(tty) &&
			tty_chars_in_buffer(tty) < WAKEUP_CHARS &&
			tty_write_room(tty) > 0)
2403
		mask |= EPOLLOUT | EPOLLWRNORM;
L
Linus Torvalds 已提交
2404 2405 2406
	return mask;
}

J
Jiri Slaby 已提交
2407
static unsigned long inq_canon(struct n_tty_data *ldata)
2408
{
2409
	size_t nr, head, tail;
2410

2411
	if (ldata->canon_head == ldata->read_tail)
2412
		return 0;
2413 2414
	head = ldata->canon_head;
	tail = ldata->read_tail;
2415
	nr = head - tail;
2416
	/* Skip EOF-chars.. */
2417
	while (MASK(head) != MASK(tail)) {
2418 2419
		if (test_bit(tail & (N_TTY_BUF_SIZE - 1), ldata->read_flags) &&
		    read_buf(ldata, tail) == __DISABLED_CHAR)
2420
			nr--;
2421
		tail++;
2422 2423 2424 2425 2426 2427 2428
	}
	return nr;
}

static int n_tty_ioctl(struct tty_struct *tty, struct file *file,
		       unsigned int cmd, unsigned long arg)
{
2429
	struct n_tty_data *ldata = tty->disc_data;
2430 2431 2432 2433 2434 2435
	int retval;

	switch (cmd) {
	case TIOCOUTQ:
		return put_user(tty_chars_in_buffer(tty), (int __user *) arg);
	case TIOCINQ:
2436
		down_write(&tty->termios_rwsem);
2437
		if (L_ICANON(tty) && !L_EXTPROC(tty))
J
Jiri Slaby 已提交
2438
			retval = inq_canon(ldata);
2439 2440 2441
		else
			retval = read_cnt(ldata);
		up_write(&tty->termios_rwsem);
2442 2443 2444 2445 2446 2447
		return put_user(retval, (unsigned int __user *) arg);
	default:
		return n_tty_ioctl_helper(tty, file, cmd, arg);
	}
}

2448
static struct tty_ldisc_ops n_tty_ops = {
P
Paul Fulghum 已提交
2449 2450 2451 2452 2453
	.magic           = TTY_LDISC_MAGIC,
	.name            = "n_tty",
	.open            = n_tty_open,
	.close           = n_tty_close,
	.flush_buffer    = n_tty_flush_buffer,
2454 2455
	.read            = n_tty_read,
	.write           = n_tty_write,
P
Paul Fulghum 已提交
2456 2457
	.ioctl           = n_tty_ioctl,
	.set_termios     = n_tty_set_termios,
2458
	.poll            = n_tty_poll,
P
Paul Fulghum 已提交
2459
	.receive_buf     = n_tty_receive_buf,
2460
	.write_wakeup    = n_tty_write_wakeup,
2461
	.receive_buf2	 = n_tty_receive_buf2,
L
Linus Torvalds 已提交
2462
};
2463 2464 2465 2466 2467

/**
 *	n_tty_inherit_ops	-	inherit N_TTY methods
 *	@ops: struct tty_ldisc_ops where to save N_TTY methods
 *
2468
 *	Enables a 'subclass' line discipline to 'inherit' N_TTY methods.
2469 2470 2471 2472
 */

void n_tty_inherit_ops(struct tty_ldisc_ops *ops)
{
2473
	*ops = n_tty_ops;
2474 2475 2476 2477
	ops->owner = NULL;
	ops->refcount = ops->flags = 0;
}
EXPORT_SYMBOL_GPL(n_tty_inherit_ops);
2478 2479 2480 2481 2482

void __init n_tty_init(void)
{
	tty_register_ldisc(N_TTY, &n_tty_ops);
}