v4l2-compat-ioctl32.c 30.1 KB
Newer Older
1 2 3 4 5 6 7 8 9
/*
 * ioctl32.c: Conversion between 32bit and 64bit native ioctls.
 *	Separated from fs stuff by Arnd Bergmann <arnd@arndb.de>
 *
 * Copyright (C) 1997-2000  Jakub Jelinek  (jakub@redhat.com)
 * Copyright (C) 1998  Eddie C. Dost  (ecd@skynet.be)
 * Copyright (C) 2001,2002  Andi Kleen, SuSE Labs
 * Copyright (C) 2003       Pavel Machek (pavel@suse.cz)
 * Copyright (C) 2005       Philippe De Muyter (phdm@macqel.be)
10
 * Copyright (C) 2008       Hans Verkuil <hverkuil@xs4all.nl>
11 12 13 14 15
 *
 * These routines maintain argument size conversion between 32bit and 64bit
 * ioctls.
 */

16
#include <linux/compat.h>
17
#define __OLD_VIDIOC_ /* To allow fixing old calls*/
18
#include <linux/videodev.h>
19
#include <linux/videodev2.h>
20
#include <linux/module.h>
21
#include <linux/smp_lock.h>
22
#include <media/v4l2-ioctl.h>
23 24

#ifdef CONFIG_COMPAT
25

26
#ifdef CONFIG_VIDEO_V4L1_COMPAT
27 28 29 30 31 32 33 34 35 36
struct video_tuner32 {
	compat_int_t tuner;
	char name[32];
	compat_ulong_t rangelow, rangehigh;
	u32 flags;	/* It is really u32 in videodev.h */
	u16 mode, signal;
};

static int get_video_tuner32(struct video_tuner *kp, struct video_tuner32 __user *up)
{
37
	if (!access_ok(VERIFY_READ, up, sizeof(struct video_tuner32)) ||
38 39 40 41 42 43 44
		get_user(kp->tuner, &up->tuner) ||
		copy_from_user(kp->name, up->name, 32) ||
		get_user(kp->rangelow, &up->rangelow) ||
		get_user(kp->rangehigh, &up->rangehigh) ||
		get_user(kp->flags, &up->flags) ||
		get_user(kp->mode, &up->mode) ||
		get_user(kp->signal, &up->signal))
45 46 47 48 49 50
		return -EFAULT;
	return 0;
}

static int put_video_tuner32(struct video_tuner *kp, struct video_tuner32 __user *up)
{
51
	if (!access_ok(VERIFY_WRITE, up, sizeof(struct video_tuner32)) ||
52 53 54 55 56 57 58 59
		put_user(kp->tuner, &up->tuner) ||
		copy_to_user(up->name, kp->name, 32) ||
		put_user(kp->rangelow, &up->rangelow) ||
		put_user(kp->rangehigh, &up->rangehigh) ||
		put_user(kp->flags, &up->flags) ||
		put_user(kp->mode, &up->mode) ||
		put_user(kp->signal, &up->signal))
			return -EFAULT;
60 61 62 63 64 65 66 67 68 69 70 71
	return 0;
}

struct video_buffer32 {
	compat_caddr_t base;
	compat_int_t height, width, depth, bytesperline;
};

static int get_video_buffer32(struct video_buffer *kp, struct video_buffer32 __user *up)
{
	u32 tmp;

72 73 74 75 76 77 78
	if (!access_ok(VERIFY_READ, up, sizeof(struct video_buffer32)) ||
		get_user(tmp, &up->base) ||
		get_user(kp->height, &up->height) ||
		get_user(kp->width, &up->width) ||
		get_user(kp->depth, &up->depth) ||
		get_user(kp->bytesperline, &up->bytesperline))
			return -EFAULT;
79 80 81 82 83 84 85 86 87 88 89 90 91

	/* This is actually a physical address stored
	 * as a void pointer.
	 */
	kp->base = (void *)(unsigned long) tmp;

	return 0;
}

static int put_video_buffer32(struct video_buffer *kp, struct video_buffer32 __user *up)
{
	u32 tmp = (u32)((unsigned long)kp->base);

92
	if (!access_ok(VERIFY_WRITE, up, sizeof(struct video_buffer32)) ||
93 94 95 96 97 98
		put_user(tmp, &up->base) ||
		put_user(kp->height, &up->height) ||
		put_user(kp->width, &up->width) ||
		put_user(kp->depth, &up->depth) ||
		put_user(kp->bytesperline, &up->bytesperline))
			return -EFAULT;
99 100 101 102
	return 0;
}

struct video_clip32 {
103
	s32 x, y, width, height;	/* It's really s32 in videodev.h */
104 105 106 107 108 109 110 111 112
	compat_caddr_t next;
};

struct video_window32 {
	u32 x, y, width, height, chromakey, flags;
	compat_caddr_t clips;
	compat_int_t clipcount;
};

113
static int get_video_window32(struct video_window *kp, struct video_window32 __user *up)
114
{
115 116 117 118
	struct video_clip __user *uclips;
	struct video_clip __user *kclips;
	compat_caddr_t p;
	int nclips;
119

120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153
	if (!access_ok(VERIFY_READ, up, sizeof(struct video_window32)))
		return -EFAULT;

	if (get_user(nclips, &up->clipcount))
		return -EFAULT;

	if (!access_ok(VERIFY_READ, up, sizeof(struct video_window32)) ||
	    get_user(kp->x, &up->x) ||
	    get_user(kp->y, &up->y) ||
	    get_user(kp->width, &up->width) ||
	    get_user(kp->height, &up->height) ||
	    get_user(kp->chromakey, &up->chromakey) ||
	    get_user(kp->flags, &up->flags) ||
	    get_user(kp->clipcount, &up->clipcount))
		return -EFAULT;

	nclips = kp->clipcount;
	kp->clips = NULL;

	if (nclips == 0)
		return 0;
	if (get_user(p, &up->clips))
		return -EFAULT;
	uclips = compat_ptr(p);

	/* If nclips < 0, then it is a clipping bitmap of size
	   VIDEO_CLIPMAP_SIZE */
	if (nclips < 0) {
		if (!access_ok(VERIFY_READ, uclips, VIDEO_CLIPMAP_SIZE))
			return -EFAULT;
		kp->clips = compat_alloc_user_space(VIDEO_CLIPMAP_SIZE);
		if (copy_in_user(kp->clips, uclips, VIDEO_CLIPMAP_SIZE))
			return -EFAULT;
		return 0;
154 155
	}

156 157 158
	/* Otherwise it is an array of video_clip structs. */
	if (!access_ok(VERIFY_READ, uclips, nclips * sizeof(struct video_clip)))
		return -EFAULT;
159

160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176
	kp->clips = compat_alloc_user_space(nclips * sizeof(struct video_clip));
	kclips = kp->clips;
	while (nclips--) {
		int err;

		err = copy_in_user(&kclips->x, &uclips->x, sizeof(kclips->x));
		err |= copy_in_user(&kclips->y, &uclips->y, sizeof(kclips->y));
		err |= copy_in_user(&kclips->width, &uclips->width, sizeof(kclips->width));
		err |= copy_in_user(&kclips->height, &uclips->height, sizeof(kclips->height));
		kclips->next = NULL;
		if (err)
			return -EFAULT;
		kclips++;
		uclips++;
	}
	return 0;
}
177 178 179 180

/* You get back everything except the clips... */
static int put_video_window32(struct video_window *kp, struct video_window32 __user *up)
{
181
	if (!access_ok(VERIFY_WRITE, up, sizeof(struct video_window32)) ||
182 183 184 185 186 187 188 189
		put_user(kp->x, &up->x) ||
		put_user(kp->y, &up->y) ||
		put_user(kp->width, &up->width) ||
		put_user(kp->height, &up->height) ||
		put_user(kp->chromakey, &up->chromakey) ||
		put_user(kp->flags, &up->flags) ||
		put_user(kp->clipcount, &up->clipcount))
			return -EFAULT;
190 191
	return 0;
}
192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222

struct video_code32 {
	char		loadwhat[16];	/* name or tag of file being passed */
	compat_int_t	datasize;
	unsigned char	*data;
};

static int get_microcode32(struct video_code *kp, struct video_code32 __user *up)
{
	if (!access_ok(VERIFY_READ, up, sizeof(struct video_code32)) ||
		copy_from_user(kp->loadwhat, up->loadwhat, sizeof(up->loadwhat)) ||
		get_user(kp->datasize, &up->datasize) ||
		copy_from_user(kp->data, up->data, up->datasize))
			return -EFAULT;
	return 0;
}

#define VIDIOCGTUNER32		_IOWR('v', 4, struct video_tuner32)
#define VIDIOCSTUNER32		_IOW('v', 5, struct video_tuner32)
#define VIDIOCGWIN32		_IOR('v', 9, struct video_window32)
#define VIDIOCSWIN32		_IOW('v', 10, struct video_window32)
#define VIDIOCGFBUF32		_IOR('v', 11, struct video_buffer32)
#define VIDIOCSFBUF32		_IOW('v', 12, struct video_buffer32)
#define VIDIOCGFREQ32		_IOR('v', 14, u32)
#define VIDIOCSFREQ32		_IOW('v', 15, u32)
#define VIDIOCSMICROCODE32	_IOW('v', 27, struct video_code32)

#define VIDIOCCAPTURE32		_IOW('v', 8, s32)
#define VIDIOCSYNC32		_IOW('v', 18, s32)
#define VIDIOCSWRITEMODE32	_IOW('v', 25, s32)

223
#endif
224

225
static long native_ioctl(struct file *file, unsigned int cmd, unsigned long arg)
226
{
227
	long ret = -ENOIOCTLCMD;
228 229 230 231 232 233 234 235 236 237 238 239 240

	if (file->f_op->unlocked_ioctl)
		ret = file->f_op->unlocked_ioctl(file, cmd, arg);
	else if (file->f_op->ioctl) {
		lock_kernel();
		ret = file->f_op->ioctl(file->f_path.dentry->d_inode, file, cmd, arg);
		unlock_kernel();
	}

	return ret;
}


241
struct v4l2_clip32 {
242 243 244 245
	struct v4l2_rect        c;
	compat_caddr_t 		next;
};

246
struct v4l2_window32 {
247 248 249 250 251 252 253 254 255 256
	struct v4l2_rect        w;
	enum v4l2_field  	field;
	__u32			chromakey;
	compat_caddr_t		clips; /* actually struct v4l2_clip32 * */
	__u32			clipcount;
	compat_caddr_t		bitmap;
};

static int get_v4l2_window32(struct v4l2_window *kp, struct v4l2_window32 __user *up)
{
257 258 259 260 261 262
	if (!access_ok(VERIFY_READ, up, sizeof(struct v4l2_window32)) ||
		copy_from_user(&kp->w, &up->w, sizeof(up->w)) ||
		get_user(kp->field, &up->field) ||
		get_user(kp->chromakey, &up->chromakey) ||
		get_user(kp->clipcount, &up->clipcount))
			return -EFAULT;
263 264 265
	if (kp->clipcount > 2048)
		return -EINVAL;
	if (kp->clipcount) {
266 267
		struct v4l2_clip32 __user *uclips;
		struct v4l2_clip __user *kclips;
268
		int n = kp->clipcount;
269
		compat_caddr_t p;
270

271 272 273
		if (get_user(p, &up->clips))
			return -EFAULT;
		uclips = compat_ptr(p);
274 275 276
		kclips = compat_alloc_user_space(n * sizeof(struct v4l2_clip));
		kp->clips = kclips;
		while (--n >= 0) {
277 278 279
			if (copy_in_user(&kclips->c, &uclips->c, sizeof(uclips->c)))
				return -EFAULT;
			if (put_user(n ? kclips + 1 : NULL, &kclips->next))
280
				return -EFAULT;
281 282 283 284
			uclips += 1;
			kclips += 1;
		}
	} else
285
		kp->clips = NULL;
286 287 288 289 290
	return 0;
}

static int put_v4l2_window32(struct v4l2_window *kp, struct v4l2_window32 __user *up)
{
291
	if (copy_to_user(&up->w, &kp->w, sizeof(up->w)) ||
292 293 294 295
		put_user(kp->field, &up->field) ||
		put_user(kp->chromakey, &up->chromakey) ||
		put_user(kp->clipcount, &up->clipcount))
			return -EFAULT;
296 297 298 299 300
	return 0;
}

static inline int get_v4l2_pix_format(struct v4l2_pix_format *kp, struct v4l2_pix_format __user *up)
{
301 302
	if (copy_from_user(kp, up, sizeof(struct v4l2_pix_format)))
		return -EFAULT;
303
	return 0;
304 305 306 307
}

static inline int put_v4l2_pix_format(struct v4l2_pix_format *kp, struct v4l2_pix_format __user *up)
{
308 309
	if (copy_to_user(up, kp, sizeof(struct v4l2_pix_format)))
		return -EFAULT;
310
	return 0;
311 312 313 314
}

static inline int get_v4l2_vbi_format(struct v4l2_vbi_format *kp, struct v4l2_vbi_format __user *up)
{
315 316
	if (copy_from_user(kp, up, sizeof(struct v4l2_vbi_format)))
		return -EFAULT;
317
	return 0;
318 319 320 321
}

static inline int put_v4l2_vbi_format(struct v4l2_vbi_format *kp, struct v4l2_vbi_format __user *up)
{
322 323
	if (copy_to_user(up, kp, sizeof(struct v4l2_vbi_format)))
		return -EFAULT;
324
	return 0;
325 326
}

327 328 329 330 331 332 333 334 335 336 337 338 339 340
static inline int get_v4l2_sliced_vbi_format(struct v4l2_sliced_vbi_format *kp, struct v4l2_sliced_vbi_format __user *up)
{
	if (copy_from_user(kp, up, sizeof(struct v4l2_sliced_vbi_format)))
		return -EFAULT;
	return 0;
}

static inline int put_v4l2_sliced_vbi_format(struct v4l2_sliced_vbi_format *kp, struct v4l2_sliced_vbi_format __user *up)
{
	if (copy_to_user(up, kp, sizeof(struct v4l2_sliced_vbi_format)))
		return -EFAULT;
	return 0;
}

341
struct v4l2_format32 {
342
	enum v4l2_buf_type type;
343
	union {
344 345 346 347
		struct v4l2_pix_format	pix;
		struct v4l2_window32	win;
		struct v4l2_vbi_format	vbi;
		struct v4l2_sliced_vbi_format	sliced;
348
		__u8	raw_data[200];        /* user-defined */
349 350 351 352 353
	} fmt;
};

static int get_v4l2_format32(struct v4l2_format *kp, struct v4l2_format32 __user *up)
{
354 355 356
	if (!access_ok(VERIFY_READ, up, sizeof(struct v4l2_format32)) ||
			get_user(kp->type, &up->type))
			return -EFAULT;
357 358
	switch (kp->type) {
	case V4L2_BUF_TYPE_VIDEO_CAPTURE:
359
	case V4L2_BUF_TYPE_VIDEO_OUTPUT:
360 361
		return get_v4l2_pix_format(&kp->fmt.pix, &up->fmt.pix);
	case V4L2_BUF_TYPE_VIDEO_OVERLAY:
362
	case V4L2_BUF_TYPE_VIDEO_OUTPUT_OVERLAY:
363 364
		return get_v4l2_window32(&kp->fmt.win, &up->fmt.win);
	case V4L2_BUF_TYPE_VBI_CAPTURE:
365
	case V4L2_BUF_TYPE_VBI_OUTPUT:
366
		return get_v4l2_vbi_format(&kp->fmt.vbi, &up->fmt.vbi);
367 368 369 370 371 372 373 374 375
	case V4L2_BUF_TYPE_SLICED_VBI_CAPTURE:
	case V4L2_BUF_TYPE_SLICED_VBI_OUTPUT:
		return get_v4l2_sliced_vbi_format(&kp->fmt.sliced, &up->fmt.sliced);
	case V4L2_BUF_TYPE_PRIVATE:
		if (copy_from_user(kp, up, sizeof(kp->fmt.raw_data)))
			return -EFAULT;
		return 0;
	case 0:
		return -EINVAL;
376
	default:
377
		printk(KERN_INFO "compat_ioctl32: unexpected VIDIOC_FMT type %d\n",
378
								kp->type);
379
		return -EINVAL;
380 381 382 383 384
	}
}

static int put_v4l2_format32(struct v4l2_format *kp, struct v4l2_format32 __user *up)
{
385
	if (!access_ok(VERIFY_WRITE, up, sizeof(struct v4l2_format32)) ||
386
		put_user(kp->type, &up->type))
387 388 389
		return -EFAULT;
	switch (kp->type) {
	case V4L2_BUF_TYPE_VIDEO_CAPTURE:
390
	case V4L2_BUF_TYPE_VIDEO_OUTPUT:
391 392
		return put_v4l2_pix_format(&kp->fmt.pix, &up->fmt.pix);
	case V4L2_BUF_TYPE_VIDEO_OVERLAY:
393
	case V4L2_BUF_TYPE_VIDEO_OUTPUT_OVERLAY:
394 395
		return put_v4l2_window32(&kp->fmt.win, &up->fmt.win);
	case V4L2_BUF_TYPE_VBI_CAPTURE:
396
	case V4L2_BUF_TYPE_VBI_OUTPUT:
397
		return put_v4l2_vbi_format(&kp->fmt.vbi, &up->fmt.vbi);
398 399 400 401 402 403 404 405 406
	case V4L2_BUF_TYPE_SLICED_VBI_CAPTURE:
	case V4L2_BUF_TYPE_SLICED_VBI_OUTPUT:
		return put_v4l2_sliced_vbi_format(&kp->fmt.sliced, &up->fmt.sliced);
	case V4L2_BUF_TYPE_PRIVATE:
		if (copy_to_user(up, kp, sizeof(up->fmt.raw_data)))
			return -EFAULT;
		return 0;
	case 0:
		return -EINVAL;
407
	default:
408 409 410
		printk(KERN_INFO "compat_ioctl32: unexpected VIDIOC_FMT type %d\n",
								kp->type);
		return -EINVAL;
411 412 413
	}
}

414
struct v4l2_standard32 {
415 416 417 418 419 420 421 422 423 424 425
	__u32		     index;
	__u32		     id[2]; /* __u64 would get the alignment wrong */
	__u8		     name[24];
	struct v4l2_fract    frameperiod; /* Frames, not fields */
	__u32		     framelines;
	__u32		     reserved[4];
};

static int get_v4l2_standard32(struct v4l2_standard *kp, struct v4l2_standard32 __user *up)
{
	/* other fields are not set by the user, nor used by the driver */
426 427 428 429
	if (!access_ok(VERIFY_READ, up, sizeof(struct v4l2_standard32)) ||
		get_user(kp->index, &up->index))
		return -EFAULT;
	return 0;
430 431 432 433
}

static int put_v4l2_standard32(struct v4l2_standard *kp, struct v4l2_standard32 __user *up)
{
434
	if (!access_ok(VERIFY_WRITE, up, sizeof(struct v4l2_standard32)) ||
435 436 437 438 439 440 441 442 443 444
		put_user(kp->index, &up->index) ||
		copy_to_user(up->id, &kp->id, sizeof(__u64)) ||
		copy_to_user(up->name, kp->name, 24) ||
		copy_to_user(&up->frameperiod, &kp->frameperiod, sizeof(kp->frameperiod)) ||
		put_user(kp->framelines, &up->framelines) ||
		copy_to_user(up->reserved, kp->reserved, 4 * sizeof(__u32)))
			return -EFAULT;
	return 0;
}

445
struct v4l2_buffer32 {
446 447 448 449 450 451 452 453 454 455 456 457 458 459 460 461 462 463 464 465 466 467 468
	__u32			index;
	enum v4l2_buf_type      type;
	__u32			bytesused;
	__u32			flags;
	enum v4l2_field		field;
	struct compat_timeval	timestamp;
	struct v4l2_timecode	timecode;
	__u32			sequence;

	/* memory location */
	enum v4l2_memory        memory;
	union {
		__u32           offset;
		compat_long_t   userptr;
	} m;
	__u32			length;
	__u32			input;
	__u32			reserved;
};

static int get_v4l2_buffer32(struct v4l2_buffer *kp, struct v4l2_buffer32 __user *up)
{

469 470 471 472 473 474 475
	if (!access_ok(VERIFY_READ, up, sizeof(struct v4l2_buffer32)) ||
		get_user(kp->index, &up->index) ||
		get_user(kp->type, &up->type) ||
		get_user(kp->flags, &up->flags) ||
		get_user(kp->memory, &up->memory) ||
		get_user(kp->input, &up->input))
			return -EFAULT;
476
	switch (kp->memory) {
477 478 479 480
	case V4L2_MEMORY_MMAP:
		break;
	case V4L2_MEMORY_USERPTR:
		{
481
		compat_long_t tmp;
482

483 484 485 486 487
		if (get_user(kp->length, &up->length) ||
		    get_user(tmp, &up->m.userptr))
			return -EFAULT;

		kp->m.userptr = (unsigned long)compat_ptr(tmp);
488 489 490
		}
		break;
	case V4L2_MEMORY_OVERLAY:
491
		if (get_user(kp->m.offset, &up->m.offset))
492
			return -EFAULT;
493 494 495 496 497 498 499
		break;
	}
	return 0;
}

static int put_v4l2_buffer32(struct v4l2_buffer *kp, struct v4l2_buffer32 __user *up)
{
500 501 502 503 504 505 506
	if (!access_ok(VERIFY_WRITE, up, sizeof(struct v4l2_buffer32)) ||
		put_user(kp->index, &up->index) ||
		put_user(kp->type, &up->type) ||
		put_user(kp->flags, &up->flags) ||
		put_user(kp->memory, &up->memory) ||
		put_user(kp->input, &up->input))
			return -EFAULT;
507
	switch (kp->memory) {
508
	case V4L2_MEMORY_MMAP:
509 510 511
		if (put_user(kp->length, &up->length) ||
			put_user(kp->m.offset, &up->m.offset))
			return -EFAULT;
512 513
		break;
	case V4L2_MEMORY_USERPTR:
514 515 516
		if (put_user(kp->length, &up->length) ||
			put_user(kp->m.userptr, &up->m.userptr))
			return -EFAULT;
517 518
		break;
	case V4L2_MEMORY_OVERLAY:
519 520
		if (put_user(kp->m.offset, &up->m.offset))
			return -EFAULT;
521 522
		break;
	}
523 524 525 526 527 528 529 530
	if (put_user(kp->bytesused, &up->bytesused) ||
		put_user(kp->field, &up->field) ||
		put_user(kp->timestamp.tv_sec, &up->timestamp.tv_sec) ||
		put_user(kp->timestamp.tv_usec, &up->timestamp.tv_usec) ||
		copy_to_user(&up->timecode, &kp->timecode, sizeof(struct v4l2_timecode)) ||
		put_user(kp->sequence, &up->sequence) ||
		put_user(kp->reserved, &up->reserved))
			return -EFAULT;
531 532 533
	return 0;
}

534
struct v4l2_framebuffer32 {
535 536 537 538 539 540
	__u32			capability;
	__u32			flags;
	compat_caddr_t 		base;
	struct v4l2_pix_format	fmt;
};

541 542 543 544
static int get_v4l2_framebuffer32(struct v4l2_framebuffer *kp, struct v4l2_framebuffer32 __user *up)
{
	u32 tmp;

545 546 547 548 549
	if (!access_ok(VERIFY_READ, up, sizeof(struct v4l2_framebuffer32)) ||
		get_user(tmp, &up->base) ||
		get_user(kp->capability, &up->capability) ||
		get_user(kp->flags, &up->flags))
			return -EFAULT;
550 551 552 553 554
	kp->base = compat_ptr(tmp);
	get_v4l2_pix_format(&kp->fmt, &up->fmt);
	return 0;
}

555 556 557 558
static int put_v4l2_framebuffer32(struct v4l2_framebuffer *kp, struct v4l2_framebuffer32 __user *up)
{
	u32 tmp = (u32)((unsigned long)kp->base);

559
	if (!access_ok(VERIFY_WRITE, up, sizeof(struct v4l2_framebuffer32)) ||
560 561 562 563
		put_user(tmp, &up->base) ||
		put_user(kp->capability, &up->capability) ||
		put_user(kp->flags, &up->flags))
			return -EFAULT;
564 565 566 567
	put_v4l2_pix_format(&kp->fmt, &up->fmt);
	return 0;
}

568 569 570 571 572 573 574 575 576 577 578 579 580 581
struct v4l2_input32 {
	__u32	     index;		/*  Which input */
	__u8	     name[32];		/*  Label */
	__u32	     type;		/*  Type of input */
	__u32	     audioset;		/*  Associated audios (bitfield) */
	__u32        tuner;             /*  Associated tuner */
	v4l2_std_id  std;
	__u32	     status;
	__u32	     reserved[4];
} __attribute__ ((packed));

/* The 64-bit v4l2_input struct has extra padding at the end of the struct.
   Otherwise it is identical to the 32-bit version. */
static inline int get_v4l2_input32(struct v4l2_input *kp, struct v4l2_input32 __user *up)
582
{
583
	if (copy_from_user(kp, up, sizeof(struct v4l2_input32)))
584
		return -EFAULT;
585 586 587
	return 0;
}

588
static inline int put_v4l2_input32(struct v4l2_input *kp, struct v4l2_input32 __user *up)
589
{
590
	if (copy_to_user(up, kp, sizeof(struct v4l2_input32)))
591
		return -EFAULT;
592 593 594
	return 0;
}

595 596 597 598 599 600
struct v4l2_ext_controls32 {
       __u32 ctrl_class;
       __u32 count;
       __u32 error_idx;
       __u32 reserved[2];
       compat_caddr_t controls; /* actually struct v4l2_ext_control32 * */
601 602
};

603 604 605 606 607 608 609 610 611 612 613 614 615 616 617 618 619 620 621 622 623 624 625 626 627 628
struct v4l2_ext_control32 {
	__u32 id;
	__u32 size;
	__u32 reserved2[1];
	union {
		__s32 value;
		__s64 value64;
		compat_caddr_t string; /* actually char * */
	};
} __attribute__ ((packed));

/* The following function really belong in v4l2-common, but that causes
   a circular dependency between modules. We need to think about this, but
   for now this will do. */

/* Return non-zero if this control is a pointer type. Currently only
 * type STRING is a pointer type.
 *
 * Note that there are currently no controls of this type, but at least the
 * compat32 code is in place to properly handle such controls. Please
 * remove this note once the first pointer controls are added. */
static inline int ctrl_is_pointer(u32 id)
{
	return 0;
}

629
static int get_v4l2_ext_controls32(struct v4l2_ext_controls *kp, struct v4l2_ext_controls32 __user *up)
630
{
631
	struct v4l2_ext_control32 __user *ucontrols;
632 633 634 635 636 637 638 639 640 641 642 643 644 645 646 647 648 649 650 651 652 653 654
	struct v4l2_ext_control __user *kcontrols;
	int n;
	compat_caddr_t p;

	if (!access_ok(VERIFY_READ, up, sizeof(struct v4l2_ext_controls32)) ||
		get_user(kp->ctrl_class, &up->ctrl_class) ||
		get_user(kp->count, &up->count) ||
		get_user(kp->error_idx, &up->error_idx) ||
		copy_from_user(kp->reserved, up->reserved, sizeof(kp->reserved)))
			return -EFAULT;
	n = kp->count;
	if (n == 0) {
		kp->controls = NULL;
		return 0;
	}
	if (get_user(p, &up->controls))
		return -EFAULT;
	ucontrols = compat_ptr(p);
	if (!access_ok(VERIFY_READ, ucontrols, n * sizeof(struct v4l2_ext_control)))
		return -EFAULT;
	kcontrols = compat_alloc_user_space(n * sizeof(struct v4l2_ext_control));
	kp->controls = kcontrols;
	while (--n >= 0) {
655
		if (copy_in_user(kcontrols, ucontrols, sizeof(*kcontrols)))
656
			return -EFAULT;
657 658 659 660 661 662 663 664 665
		if (ctrl_is_pointer(kcontrols->id)) {
			void __user *s;

			if (get_user(p, &ucontrols->string))
				return -EFAULT;
			s = compat_ptr(p);
			if (put_user(s, &kcontrols->string))
				return -EFAULT;
		}
666 667 668
		ucontrols++;
		kcontrols++;
	}
669 670 671
	return 0;
}

672
static int put_v4l2_ext_controls32(struct v4l2_ext_controls *kp, struct v4l2_ext_controls32 __user *up)
673
{
674
	struct v4l2_ext_control32 __user *ucontrols;
675 676 677 678 679 680 681 682 683 684 685 686
	struct v4l2_ext_control __user *kcontrols = kp->controls;
	int n = kp->count;
	compat_caddr_t p;

	if (!access_ok(VERIFY_WRITE, up, sizeof(struct v4l2_ext_controls32)) ||
		put_user(kp->ctrl_class, &up->ctrl_class) ||
		put_user(kp->count, &up->count) ||
		put_user(kp->error_idx, &up->error_idx) ||
		copy_to_user(up->reserved, kp->reserved, sizeof(up->reserved)))
			return -EFAULT;
	if (!kp->count)
		return 0;
687

688
	if (get_user(p, &up->controls))
689
		return -EFAULT;
690 691
	ucontrols = compat_ptr(p);
	if (!access_ok(VERIFY_WRITE, ucontrols, n * sizeof(struct v4l2_ext_control)))
692 693
		return -EFAULT;

694
	while (--n >= 0) {
695 696 697 698 699 700 701 702
		unsigned size = sizeof(*ucontrols);

		/* Do not modify the pointer when copying a pointer control.
		   The contents of the pointer was changed, not the pointer
		   itself. */
		if (ctrl_is_pointer(kcontrols->id))
			size -= sizeof(ucontrols->value64);
		if (copy_in_user(ucontrols, kcontrols, size))
703 704 705
			return -EFAULT;
		ucontrols++;
		kcontrols++;
706
	}
707
	return 0;
708
}
709 710 711 712 713 714 715 716 717 718 719 720 721 722 723 724

#define VIDIOC_G_FMT32		_IOWR('V',  4, struct v4l2_format32)
#define VIDIOC_S_FMT32		_IOWR('V',  5, struct v4l2_format32)
#define VIDIOC_QUERYBUF32	_IOWR('V',  9, struct v4l2_buffer32)
#define VIDIOC_G_FBUF32		_IOR ('V', 10, struct v4l2_framebuffer32)
#define VIDIOC_S_FBUF32		_IOW ('V', 11, struct v4l2_framebuffer32)
#define VIDIOC_QBUF32		_IOWR('V', 15, struct v4l2_buffer32)
#define VIDIOC_DQBUF32		_IOWR('V', 17, struct v4l2_buffer32)
#define VIDIOC_ENUMSTD32	_IOWR('V', 25, struct v4l2_standard32)
#define VIDIOC_ENUMINPUT32	_IOWR('V', 26, struct v4l2_input32)
#define VIDIOC_TRY_FMT32      	_IOWR('V', 64, struct v4l2_format32)
#define VIDIOC_G_EXT_CTRLS32    _IOWR('V', 71, struct v4l2_ext_controls32)
#define VIDIOC_S_EXT_CTRLS32    _IOWR('V', 72, struct v4l2_ext_controls32)
#define VIDIOC_TRY_EXT_CTRLS32  _IOWR('V', 73, struct v4l2_ext_controls32)

#define VIDIOC_OVERLAY32	_IOW ('V', 14, s32)
725
#ifdef __OLD_VIDIOC_
726
#define VIDIOC_OVERLAY32_OLD	_IOWR('V', 14, s32)
727
#endif
728 729 730 731 732 733
#define VIDIOC_STREAMON32	_IOW ('V', 18, s32)
#define VIDIOC_STREAMOFF32	_IOW ('V', 19, s32)
#define VIDIOC_G_INPUT32	_IOR ('V', 38, s32)
#define VIDIOC_S_INPUT32	_IOWR('V', 39, s32)
#define VIDIOC_G_OUTPUT32	_IOR ('V', 46, s32)
#define VIDIOC_S_OUTPUT32	_IOWR('V', 47, s32)
734

735
static long do_video_ioctl(struct file *file, unsigned int cmd, unsigned long arg)
736 737
{
	union {
738
#ifdef CONFIG_VIDEO_V4L1_COMPAT
739 740 741
		struct video_tuner vt;
		struct video_buffer vb;
		struct video_window vw;
742
		struct video_code vc;
743
		struct video_audio va;
744
#endif
745 746 747
		struct v4l2_format v2f;
		struct v4l2_buffer v2b;
		struct v4l2_framebuffer v2fb;
748
		struct v4l2_input v2i;
749 750
		struct v4l2_standard v2s;
		struct v4l2_ext_controls v2ecs;
751
		unsigned long vx;
752
		int vi;
753 754
	} karg;
	void __user *up = compat_ptr(arg);
755
	int compatible_arg = 1;
756
	long err = 0;
757 758

	/* First, convert the command. */
759
	switch (cmd) {
760
#ifdef CONFIG_VIDEO_V4L1_COMPAT
761 762 763 764 765 766 767 768 769
	case VIDIOCGTUNER32: cmd = VIDIOCGTUNER; break;
	case VIDIOCSTUNER32: cmd = VIDIOCSTUNER; break;
	case VIDIOCGWIN32: cmd = VIDIOCGWIN; break;
	case VIDIOCSWIN32: cmd = VIDIOCSWIN; break;
	case VIDIOCGFBUF32: cmd = VIDIOCGFBUF; break;
	case VIDIOCSFBUF32: cmd = VIDIOCSFBUF; break;
	case VIDIOCGFREQ32: cmd = VIDIOCGFREQ; break;
	case VIDIOCSFREQ32: cmd = VIDIOCSFREQ; break;
	case VIDIOCSMICROCODE32: cmd = VIDIOCSMICROCODE; break;
770
#endif
771 772 773 774 775 776 777 778 779 780 781 782 783 784
	case VIDIOC_G_FMT32: cmd = VIDIOC_G_FMT; break;
	case VIDIOC_S_FMT32: cmd = VIDIOC_S_FMT; break;
	case VIDIOC_QUERYBUF32: cmd = VIDIOC_QUERYBUF; break;
	case VIDIOC_G_FBUF32: cmd = VIDIOC_G_FBUF; break;
	case VIDIOC_S_FBUF32: cmd = VIDIOC_S_FBUF; break;
	case VIDIOC_QBUF32: cmd = VIDIOC_QBUF; break;
	case VIDIOC_DQBUF32: cmd = VIDIOC_DQBUF; break;
	case VIDIOC_ENUMSTD32: cmd = VIDIOC_ENUMSTD; break;
	case VIDIOC_ENUMINPUT32: cmd = VIDIOC_ENUMINPUT; break;
	case VIDIOC_TRY_FMT32: cmd = VIDIOC_TRY_FMT; break;
	case VIDIOC_G_EXT_CTRLS32: cmd = VIDIOC_G_EXT_CTRLS; break;
	case VIDIOC_S_EXT_CTRLS32: cmd = VIDIOC_S_EXT_CTRLS; break;
	case VIDIOC_TRY_EXT_CTRLS32: cmd = VIDIOC_TRY_EXT_CTRLS; break;
	case VIDIOC_OVERLAY32: cmd = VIDIOC_OVERLAY; break;
785
#ifdef __OLD_VIDIOC_
786
	case VIDIOC_OVERLAY32_OLD: cmd = VIDIOC_OVERLAY; break;
787
#endif
788 789 790 791 792 793 794
	case VIDIOC_STREAMON32: cmd = VIDIOC_STREAMON; break;
	case VIDIOC_STREAMOFF32: cmd = VIDIOC_STREAMOFF; break;
	case VIDIOC_G_INPUT32: cmd = VIDIOC_G_INPUT; break;
	case VIDIOC_S_INPUT32: cmd = VIDIOC_S_INPUT; break;
	case VIDIOC_G_OUTPUT32: cmd = VIDIOC_G_OUTPUT; break;
	case VIDIOC_S_OUTPUT32: cmd = VIDIOC_S_OUTPUT; break;
	}
795

796
	switch (cmd) {
797
#ifdef CONFIG_VIDEO_V4L1_COMPAT
798 799 800
	case VIDIOCSTUNER:
	case VIDIOCGTUNER:
		err = get_video_tuner32(&karg.vt, up);
801
		compatible_arg = 0;
802 803 804 805
		break;

	case VIDIOCSFBUF:
		err = get_video_buffer32(&karg.vb, up);
806
		compatible_arg = 0;
807 808
		break;

809 810 811 812 813 814 815 816 817 818 819 820 821 822 823
	case VIDIOCSWIN:
		err = get_video_window32(&karg.vw, up);
		compatible_arg = 0;
		break;

	case VIDIOCGWIN:
	case VIDIOCGFBUF:
	case VIDIOCGFREQ:
		compatible_arg = 0;
		break;

	case VIDIOCSMICROCODE:
		err = get_microcode32(&karg.vc, up);
		compatible_arg = 0;
		break;
824

825
	case VIDIOCSFREQ:
826 827 828 829 830 831 832
		err = get_user(karg.vx, (u32 __user *)up);
		compatible_arg = 0;
		break;

	case VIDIOCCAPTURE:
	case VIDIOCSYNC:
	case VIDIOCSWRITEMODE:
833
#endif
834
	case VIDIOC_OVERLAY:
835 836
	case VIDIOC_STREAMON:
	case VIDIOC_STREAMOFF:
837 838 839 840
	case VIDIOC_S_INPUT:
	case VIDIOC_S_OUTPUT:
		err = get_user(karg.vi, (s32 __user *)up);
		compatible_arg = 0;
841
		break;
842

843 844
	case VIDIOC_G_INPUT:
	case VIDIOC_G_OUTPUT:
845 846
		compatible_arg = 0;
		break;
847 848 849 850 851 852 853 854 855 856 857 858 859 860 861

	case VIDIOC_G_FMT:
	case VIDIOC_S_FMT:
	case VIDIOC_TRY_FMT:
		err = get_v4l2_format32(&karg.v2f, up);
		compatible_arg = 0;
		break;

	case VIDIOC_QUERYBUF:
	case VIDIOC_QBUF:
	case VIDIOC_DQBUF:
		err = get_v4l2_buffer32(&karg.v2b, up);
		compatible_arg = 0;
		break;

862 863
	case VIDIOC_S_FBUF:
		err = get_v4l2_framebuffer32(&karg.v2fb, up);
864 865 866
		compatible_arg = 0;
		break;

867
	case VIDIOC_G_FBUF:
868 869 870
		compatible_arg = 0;
		break;

871 872
	case VIDIOC_ENUMSTD:
		err = get_v4l2_standard32(&karg.v2s, up);
873 874 875
		compatible_arg = 0;
		break;

876
	case VIDIOC_ENUMINPUT:
877 878 879 880
		err = get_v4l2_input32(&karg.v2i, up);
		compatible_arg = 0;
		break;

881 882 883 884
	case VIDIOC_G_EXT_CTRLS:
	case VIDIOC_S_EXT_CTRLS:
	case VIDIOC_TRY_EXT_CTRLS:
		err = get_v4l2_ext_controls32(&karg.v2ecs, up);
885 886
		compatible_arg = 0;
		break;
887
	}
888
	if (err)
889
		return err;
890

891
	if (compatible_arg)
892
		err = native_ioctl(file, cmd, (unsigned long)up);
893 894
	else {
		mm_segment_t old_fs = get_fs();
895

896
		set_fs(KERNEL_DS);
897
		err = native_ioctl(file, cmd, (unsigned long)&karg);
898 899
		set_fs(old_fs);
	}
900 901 902 903 904 905 906 907 908 909 910 911 912 913 914 915

	/* Special case: even after an error we need to put the
	   results back for these ioctls since the error_idx will
	   contain information on which control failed. */
	switch (cmd) {
	case VIDIOC_G_EXT_CTRLS:
	case VIDIOC_S_EXT_CTRLS:
	case VIDIOC_TRY_EXT_CTRLS:
		if (put_v4l2_ext_controls32(&karg.v2ecs, up))
			err = -EFAULT;
		break;
	}
	if (err)
		return err;

	switch (cmd) {
916
#ifdef CONFIG_VIDEO_V4L1_COMPAT
917 918 919
	case VIDIOCGTUNER:
		err = put_video_tuner32(&karg.vt, up);
		break;
920

921 922 923
	case VIDIOCGWIN:
		err = put_video_window32(&karg.vw, up);
		break;
924

925 926 927
	case VIDIOCGFBUF:
		err = put_video_buffer32(&karg.vb, up);
		break;
928

929 930 931
	case VIDIOCGFREQ:
		err = put_user(((u32)karg.vx), (u32 __user *)up);
		break;
932
#endif
933 934 935 936 937 938
	case VIDIOC_S_INPUT:
	case VIDIOC_S_OUTPUT:
	case VIDIOC_G_INPUT:
	case VIDIOC_G_OUTPUT:
		err = put_user(((s32)karg.vi), (s32 __user *)up);
		break;
939

940 941 942 943 944 945 946 947 948 949 950 951 952 953 954 955 956 957 958 959 960 961 962
	case VIDIOC_G_FBUF:
		err = put_v4l2_framebuffer32(&karg.v2fb, up);
		break;

	case VIDIOC_G_FMT:
	case VIDIOC_S_FMT:
	case VIDIOC_TRY_FMT:
		err = put_v4l2_format32(&karg.v2f, up);
		break;

	case VIDIOC_QUERYBUF:
	case VIDIOC_QBUF:
	case VIDIOC_DQBUF:
		err = put_v4l2_buffer32(&karg.v2b, up);
		break;

	case VIDIOC_ENUMSTD:
		err = put_v4l2_standard32(&karg.v2s, up);
		break;

	case VIDIOC_ENUMINPUT:
		err = put_v4l2_input32(&karg.v2i, up);
		break;
963 964 965 966
	}
	return err;
}

967
long v4l2_compat_ioctl32(struct file *file, unsigned int cmd, unsigned long arg)
968
{
969
	long ret = -ENOIOCTLCMD;
970

971
	if (!file->f_op->ioctl && !file->f_op->unlocked_ioctl)
972 973 974
		return ret;

	switch (cmd) {
975
#ifdef CONFIG_VIDEO_V4L1_COMPAT
976 977 978
	case VIDIOCGCAP:
	case VIDIOCGCHAN:
	case VIDIOCSCHAN:
979 980
	case VIDIOCGTUNER32:
	case VIDIOCSTUNER32:
981 982 983
	case VIDIOCGPICT:
	case VIDIOCSPICT:
	case VIDIOCCAPTURE32:
984
	case VIDIOCGWIN32:
985
	case VIDIOCSWIN32:
986 987
	case VIDIOCGFBUF32:
	case VIDIOCSFBUF32:
988
	case VIDIOCKEY:
989
	case VIDIOCGFREQ32:
990
	case VIDIOCSFREQ32:
991 992
	case VIDIOCGAUDIO:
	case VIDIOCSAUDIO:
993 994 995 996 997 998 999 1000 1001 1002
	case VIDIOCSYNC32:
	case VIDIOCMCAPTURE:
	case VIDIOCGMBUF:
	case VIDIOCGUNIT:
	case VIDIOCGCAPTURE:
	case VIDIOCSCAPTURE:
	case VIDIOCSPLAYMODE:
	case VIDIOCSWRITEMODE32:
	case VIDIOCGPLAYINFO:
	case VIDIOCSMICROCODE32:
1003 1004
	case VIDIOCGVBIFMT:
	case VIDIOCSVBIFMT:
1005 1006 1007 1008 1009 1010 1011 1012
#endif
#ifdef __OLD_VIDIOC_
	case VIDIOC_OVERLAY32_OLD:
	case VIDIOC_S_PARM_OLD:
	case VIDIOC_S_CTRL_OLD:
	case VIDIOC_G_AUDIO_OLD:
	case VIDIOC_G_AUDOUT_OLD:
	case VIDIOC_CROPCAP_OLD:
1013
#endif
1014
	case VIDIOC_QUERYCAP:
1015
	case VIDIOC_RESERVED:
1016 1017 1018 1019 1020 1021 1022 1023 1024 1025 1026 1027 1028
	case VIDIOC_ENUM_FMT:
	case VIDIOC_G_FMT32:
	case VIDIOC_S_FMT32:
	case VIDIOC_REQBUFS:
	case VIDIOC_QUERYBUF32:
	case VIDIOC_G_FBUF32:
	case VIDIOC_S_FBUF32:
	case VIDIOC_OVERLAY32:
	case VIDIOC_QBUF32:
	case VIDIOC_DQBUF32:
	case VIDIOC_STREAMON32:
	case VIDIOC_STREAMOFF32:
	case VIDIOC_G_PARM:
1029
	case VIDIOC_S_PARM:
1030 1031 1032 1033 1034
	case VIDIOC_G_STD:
	case VIDIOC_S_STD:
	case VIDIOC_ENUMSTD32:
	case VIDIOC_ENUMINPUT32:
	case VIDIOC_G_CTRL:
1035
	case VIDIOC_S_CTRL:
1036 1037 1038 1039
	case VIDIOC_G_TUNER:
	case VIDIOC_S_TUNER:
	case VIDIOC_G_AUDIO:
	case VIDIOC_S_AUDIO:
1040
	case VIDIOC_QUERYCTRL:
1041
	case VIDIOC_QUERYMENU:
1042 1043
	case VIDIOC_G_INPUT32:
	case VIDIOC_S_INPUT32:
1044 1045 1046 1047 1048 1049 1050 1051 1052 1053 1054 1055 1056 1057 1058
	case VIDIOC_G_OUTPUT32:
	case VIDIOC_S_OUTPUT32:
	case VIDIOC_ENUMOUTPUT:
	case VIDIOC_G_AUDOUT:
	case VIDIOC_S_AUDOUT:
	case VIDIOC_G_MODULATOR:
	case VIDIOC_S_MODULATOR:
	case VIDIOC_S_FREQUENCY:
	case VIDIOC_G_FREQUENCY:
	case VIDIOC_CROPCAP:
	case VIDIOC_G_CROP:
	case VIDIOC_S_CROP:
	case VIDIOC_G_JPEGCOMP:
	case VIDIOC_S_JPEGCOMP:
	case VIDIOC_QUERYSTD:
1059
	case VIDIOC_TRY_FMT32:
1060 1061 1062 1063 1064 1065 1066 1067 1068
	case VIDIOC_ENUMAUDIO:
	case VIDIOC_ENUMAUDOUT:
	case VIDIOC_G_PRIORITY:
	case VIDIOC_S_PRIORITY:
	case VIDIOC_G_SLICED_VBI_CAP:
	case VIDIOC_LOG_STATUS:
	case VIDIOC_G_EXT_CTRLS32:
	case VIDIOC_S_EXT_CTRLS32:
	case VIDIOC_TRY_EXT_CTRLS32:
1069 1070
	case VIDIOC_ENUM_FRAMESIZES:
	case VIDIOC_ENUM_FRAMEINTERVALS:
1071 1072 1073 1074 1075
	case VIDIOC_G_ENC_INDEX:
	case VIDIOC_ENCODER_CMD:
	case VIDIOC_TRY_ENCODER_CMD:
	case VIDIOC_DBG_S_REGISTER:
	case VIDIOC_DBG_G_REGISTER:
1076
	case VIDIOC_DBG_G_CHIP_IDENT:
1077
	case VIDIOC_S_HW_FREQ_SEEK:
1078 1079 1080
		ret = do_video_ioctl(file, cmd, arg);
		break;

1081
#ifdef CONFIG_VIDEO_V4L1_COMPAT
1082 1083 1084 1085 1086 1087 1088 1089 1090 1091 1092
	/* BTTV specific... */
	case _IOW('v',  BASE_VIDIOCPRIVATE+0, char [256]):
	case _IOR('v',  BASE_VIDIOCPRIVATE+1, char [256]):
	case _IOR('v' , BASE_VIDIOCPRIVATE+2, unsigned int):
	case _IOW('v' , BASE_VIDIOCPRIVATE+3, char [16]): /* struct bttv_pll_info */
	case _IOR('v' , BASE_VIDIOCPRIVATE+4, int):
	case _IOR('v' , BASE_VIDIOCPRIVATE+5, int):
	case _IOR('v' , BASE_VIDIOCPRIVATE+6, int):
	case _IOR('v' , BASE_VIDIOCPRIVATE+7, int):
		ret = native_ioctl(file, cmd, (unsigned long)compat_ptr(arg));
		break;
1093
#endif
1094
	default:
1095 1096 1097
		printk(KERN_WARNING "compat_ioctl32: "
			"unknown ioctl '%c', dir=%d, #%d (0x%08x)\n",
			_IOC_TYPE(cmd), _IOC_DIR(cmd), _IOC_NR(cmd), cmd);
1098
		break;
1099
	}
1100
	return ret;
1101
}
1102
EXPORT_SYMBOL_GPL(v4l2_compat_ioctl32);
1103
#endif
1104 1105

MODULE_LICENSE("GPL");