v4l2-compat-ioctl32.c 30.0 KB
Newer Older
1 2 3 4 5 6 7 8 9
/*
 * ioctl32.c: Conversion between 32bit and 64bit native ioctls.
 *	Separated from fs stuff by Arnd Bergmann <arnd@arndb.de>
 *
 * Copyright (C) 1997-2000  Jakub Jelinek  (jakub@redhat.com)
 * Copyright (C) 1998  Eddie C. Dost  (ecd@skynet.be)
 * Copyright (C) 2001,2002  Andi Kleen, SuSE Labs
 * Copyright (C) 2003       Pavel Machek (pavel@suse.cz)
 * Copyright (C) 2005       Philippe De Muyter (phdm@macqel.be)
10
 * Copyright (C) 2008       Hans Verkuil <hverkuil@xs4all.nl>
11 12 13 14 15
 *
 * These routines maintain argument size conversion between 32bit and 64bit
 * ioctls.
 */

16
#include <linux/compat.h>
17
#define __OLD_VIDIOC_ /* To allow fixing old calls*/
18
#include <linux/videodev.h>
19
#include <linux/videodev2.h>
20
#include <linux/module.h>
21
#include <linux/smp_lock.h>
22
#include <media/v4l2-ioctl.h>
23 24

#ifdef CONFIG_COMPAT
25

26
#ifdef CONFIG_VIDEO_V4L1_COMPAT
27 28 29 30 31 32 33 34 35 36
struct video_tuner32 {
	compat_int_t tuner;
	char name[32];
	compat_ulong_t rangelow, rangehigh;
	u32 flags;	/* It is really u32 in videodev.h */
	u16 mode, signal;
};

static int get_video_tuner32(struct video_tuner *kp, struct video_tuner32 __user *up)
{
37
	if (!access_ok(VERIFY_READ, up, sizeof(struct video_tuner32)) ||
38 39 40 41 42 43 44
		get_user(kp->tuner, &up->tuner) ||
		copy_from_user(kp->name, up->name, 32) ||
		get_user(kp->rangelow, &up->rangelow) ||
		get_user(kp->rangehigh, &up->rangehigh) ||
		get_user(kp->flags, &up->flags) ||
		get_user(kp->mode, &up->mode) ||
		get_user(kp->signal, &up->signal))
45 46 47 48 49 50
		return -EFAULT;
	return 0;
}

static int put_video_tuner32(struct video_tuner *kp, struct video_tuner32 __user *up)
{
51
	if (!access_ok(VERIFY_WRITE, up, sizeof(struct video_tuner32)) ||
52 53 54 55 56 57 58 59
		put_user(kp->tuner, &up->tuner) ||
		copy_to_user(up->name, kp->name, 32) ||
		put_user(kp->rangelow, &up->rangelow) ||
		put_user(kp->rangehigh, &up->rangehigh) ||
		put_user(kp->flags, &up->flags) ||
		put_user(kp->mode, &up->mode) ||
		put_user(kp->signal, &up->signal))
			return -EFAULT;
60 61 62 63 64 65 66 67 68 69 70 71
	return 0;
}

struct video_buffer32 {
	compat_caddr_t base;
	compat_int_t height, width, depth, bytesperline;
};

static int get_video_buffer32(struct video_buffer *kp, struct video_buffer32 __user *up)
{
	u32 tmp;

72 73 74 75 76 77 78
	if (!access_ok(VERIFY_READ, up, sizeof(struct video_buffer32)) ||
		get_user(tmp, &up->base) ||
		get_user(kp->height, &up->height) ||
		get_user(kp->width, &up->width) ||
		get_user(kp->depth, &up->depth) ||
		get_user(kp->bytesperline, &up->bytesperline))
			return -EFAULT;
79 80 81 82 83 84 85 86 87 88 89 90 91

	/* This is actually a physical address stored
	 * as a void pointer.
	 */
	kp->base = (void *)(unsigned long) tmp;

	return 0;
}

static int put_video_buffer32(struct video_buffer *kp, struct video_buffer32 __user *up)
{
	u32 tmp = (u32)((unsigned long)kp->base);

92
	if (!access_ok(VERIFY_WRITE, up, sizeof(struct video_buffer32)) ||
93 94 95 96 97 98
		put_user(tmp, &up->base) ||
		put_user(kp->height, &up->height) ||
		put_user(kp->width, &up->width) ||
		put_user(kp->depth, &up->depth) ||
		put_user(kp->bytesperline, &up->bytesperline))
			return -EFAULT;
99 100 101 102
	return 0;
}

struct video_clip32 {
103
	s32 x, y, width, height;	/* It's really s32 in videodev.h */
104 105 106 107 108 109 110 111 112
	compat_caddr_t next;
};

struct video_window32 {
	u32 x, y, width, height, chromakey, flags;
	compat_caddr_t clips;
	compat_int_t clipcount;
};

113
static int get_video_window32(struct video_window *kp, struct video_window32 __user *up)
114
{
115 116 117 118
	struct video_clip __user *uclips;
	struct video_clip __user *kclips;
	compat_caddr_t p;
	int nclips;
119

120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153
	if (!access_ok(VERIFY_READ, up, sizeof(struct video_window32)))
		return -EFAULT;

	if (get_user(nclips, &up->clipcount))
		return -EFAULT;

	if (!access_ok(VERIFY_READ, up, sizeof(struct video_window32)) ||
	    get_user(kp->x, &up->x) ||
	    get_user(kp->y, &up->y) ||
	    get_user(kp->width, &up->width) ||
	    get_user(kp->height, &up->height) ||
	    get_user(kp->chromakey, &up->chromakey) ||
	    get_user(kp->flags, &up->flags) ||
	    get_user(kp->clipcount, &up->clipcount))
		return -EFAULT;

	nclips = kp->clipcount;
	kp->clips = NULL;

	if (nclips == 0)
		return 0;
	if (get_user(p, &up->clips))
		return -EFAULT;
	uclips = compat_ptr(p);

	/* If nclips < 0, then it is a clipping bitmap of size
	   VIDEO_CLIPMAP_SIZE */
	if (nclips < 0) {
		if (!access_ok(VERIFY_READ, uclips, VIDEO_CLIPMAP_SIZE))
			return -EFAULT;
		kp->clips = compat_alloc_user_space(VIDEO_CLIPMAP_SIZE);
		if (copy_in_user(kp->clips, uclips, VIDEO_CLIPMAP_SIZE))
			return -EFAULT;
		return 0;
154 155
	}

156 157 158
	/* Otherwise it is an array of video_clip structs. */
	if (!access_ok(VERIFY_READ, uclips, nclips * sizeof(struct video_clip)))
		return -EFAULT;
159

160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176
	kp->clips = compat_alloc_user_space(nclips * sizeof(struct video_clip));
	kclips = kp->clips;
	while (nclips--) {
		int err;

		err = copy_in_user(&kclips->x, &uclips->x, sizeof(kclips->x));
		err |= copy_in_user(&kclips->y, &uclips->y, sizeof(kclips->y));
		err |= copy_in_user(&kclips->width, &uclips->width, sizeof(kclips->width));
		err |= copy_in_user(&kclips->height, &uclips->height, sizeof(kclips->height));
		kclips->next = NULL;
		if (err)
			return -EFAULT;
		kclips++;
		uclips++;
	}
	return 0;
}
177 178 179 180

/* You get back everything except the clips... */
static int put_video_window32(struct video_window *kp, struct video_window32 __user *up)
{
181
	if (!access_ok(VERIFY_WRITE, up, sizeof(struct video_window32)) ||
182 183 184 185 186 187 188 189
		put_user(kp->x, &up->x) ||
		put_user(kp->y, &up->y) ||
		put_user(kp->width, &up->width) ||
		put_user(kp->height, &up->height) ||
		put_user(kp->chromakey, &up->chromakey) ||
		put_user(kp->flags, &up->flags) ||
		put_user(kp->clipcount, &up->clipcount))
			return -EFAULT;
190 191
	return 0;
}
192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222

struct video_code32 {
	char		loadwhat[16];	/* name or tag of file being passed */
	compat_int_t	datasize;
	unsigned char	*data;
};

static int get_microcode32(struct video_code *kp, struct video_code32 __user *up)
{
	if (!access_ok(VERIFY_READ, up, sizeof(struct video_code32)) ||
		copy_from_user(kp->loadwhat, up->loadwhat, sizeof(up->loadwhat)) ||
		get_user(kp->datasize, &up->datasize) ||
		copy_from_user(kp->data, up->data, up->datasize))
			return -EFAULT;
	return 0;
}

#define VIDIOCGTUNER32		_IOWR('v', 4, struct video_tuner32)
#define VIDIOCSTUNER32		_IOW('v', 5, struct video_tuner32)
#define VIDIOCGWIN32		_IOR('v', 9, struct video_window32)
#define VIDIOCSWIN32		_IOW('v', 10, struct video_window32)
#define VIDIOCGFBUF32		_IOR('v', 11, struct video_buffer32)
#define VIDIOCSFBUF32		_IOW('v', 12, struct video_buffer32)
#define VIDIOCGFREQ32		_IOR('v', 14, u32)
#define VIDIOCSFREQ32		_IOW('v', 15, u32)
#define VIDIOCSMICROCODE32	_IOW('v', 27, struct video_code32)

#define VIDIOCCAPTURE32		_IOW('v', 8, s32)
#define VIDIOCSYNC32		_IOW('v', 18, s32)
#define VIDIOCSWRITEMODE32	_IOW('v', 25, s32)

223
#endif
224

225
static long native_ioctl(struct file *file, unsigned int cmd, unsigned long arg)
226
{
227
	long ret = -ENOIOCTLCMD;
228 229 230 231 232 233 234 235 236 237 238 239 240

	if (file->f_op->unlocked_ioctl)
		ret = file->f_op->unlocked_ioctl(file, cmd, arg);
	else if (file->f_op->ioctl) {
		lock_kernel();
		ret = file->f_op->ioctl(file->f_path.dentry->d_inode, file, cmd, arg);
		unlock_kernel();
	}

	return ret;
}


241
struct v4l2_clip32 {
242 243 244 245
	struct v4l2_rect        c;
	compat_caddr_t 		next;
};

246
struct v4l2_window32 {
247 248 249 250 251 252 253 254 255 256
	struct v4l2_rect        w;
	enum v4l2_field  	field;
	__u32			chromakey;
	compat_caddr_t		clips; /* actually struct v4l2_clip32 * */
	__u32			clipcount;
	compat_caddr_t		bitmap;
};

static int get_v4l2_window32(struct v4l2_window *kp, struct v4l2_window32 __user *up)
{
257 258 259 260 261 262
	if (!access_ok(VERIFY_READ, up, sizeof(struct v4l2_window32)) ||
		copy_from_user(&kp->w, &up->w, sizeof(up->w)) ||
		get_user(kp->field, &up->field) ||
		get_user(kp->chromakey, &up->chromakey) ||
		get_user(kp->clipcount, &up->clipcount))
			return -EFAULT;
263 264 265
	if (kp->clipcount > 2048)
		return -EINVAL;
	if (kp->clipcount) {
266 267
		struct v4l2_clip32 __user *uclips;
		struct v4l2_clip __user *kclips;
268
		int n = kp->clipcount;
269
		compat_caddr_t p;
270

271 272 273
		if (get_user(p, &up->clips))
			return -EFAULT;
		uclips = compat_ptr(p);
274 275 276
		kclips = compat_alloc_user_space(n * sizeof(struct v4l2_clip));
		kp->clips = kclips;
		while (--n >= 0) {
277 278 279
			if (copy_in_user(&kclips->c, &uclips->c, sizeof(uclips->c)))
				return -EFAULT;
			if (put_user(n ? kclips + 1 : NULL, &kclips->next))
280
				return -EFAULT;
281 282 283 284
			uclips += 1;
			kclips += 1;
		}
	} else
285
		kp->clips = NULL;
286 287 288 289 290
	return 0;
}

static int put_v4l2_window32(struct v4l2_window *kp, struct v4l2_window32 __user *up)
{
291
	if (copy_to_user(&up->w, &kp->w, sizeof(up->w)) ||
292 293 294 295
		put_user(kp->field, &up->field) ||
		put_user(kp->chromakey, &up->chromakey) ||
		put_user(kp->clipcount, &up->clipcount))
			return -EFAULT;
296 297 298 299 300
	return 0;
}

static inline int get_v4l2_pix_format(struct v4l2_pix_format *kp, struct v4l2_pix_format __user *up)
{
301 302
	if (copy_from_user(kp, up, sizeof(struct v4l2_pix_format)))
		return -EFAULT;
303
	return 0;
304 305 306 307
}

static inline int put_v4l2_pix_format(struct v4l2_pix_format *kp, struct v4l2_pix_format __user *up)
{
308 309
	if (copy_to_user(up, kp, sizeof(struct v4l2_pix_format)))
		return -EFAULT;
310
	return 0;
311 312 313 314
}

static inline int get_v4l2_vbi_format(struct v4l2_vbi_format *kp, struct v4l2_vbi_format __user *up)
{
315 316
	if (copy_from_user(kp, up, sizeof(struct v4l2_vbi_format)))
		return -EFAULT;
317
	return 0;
318 319 320 321
}

static inline int put_v4l2_vbi_format(struct v4l2_vbi_format *kp, struct v4l2_vbi_format __user *up)
{
322 323
	if (copy_to_user(up, kp, sizeof(struct v4l2_vbi_format)))
		return -EFAULT;
324
	return 0;
325 326
}

327 328 329 330 331 332 333 334 335 336 337 338 339 340
static inline int get_v4l2_sliced_vbi_format(struct v4l2_sliced_vbi_format *kp, struct v4l2_sliced_vbi_format __user *up)
{
	if (copy_from_user(kp, up, sizeof(struct v4l2_sliced_vbi_format)))
		return -EFAULT;
	return 0;
}

static inline int put_v4l2_sliced_vbi_format(struct v4l2_sliced_vbi_format *kp, struct v4l2_sliced_vbi_format __user *up)
{
	if (copy_to_user(up, kp, sizeof(struct v4l2_sliced_vbi_format)))
		return -EFAULT;
	return 0;
}

341
struct v4l2_format32 {
342
	enum v4l2_buf_type type;
343
	union {
344 345 346 347
		struct v4l2_pix_format	pix;
		struct v4l2_window32	win;
		struct v4l2_vbi_format	vbi;
		struct v4l2_sliced_vbi_format	sliced;
348
		__u8	raw_data[200];        /* user-defined */
349 350 351 352 353
	} fmt;
};

static int get_v4l2_format32(struct v4l2_format *kp, struct v4l2_format32 __user *up)
{
354 355 356
	if (!access_ok(VERIFY_READ, up, sizeof(struct v4l2_format32)) ||
			get_user(kp->type, &up->type))
			return -EFAULT;
357 358
	switch (kp->type) {
	case V4L2_BUF_TYPE_VIDEO_CAPTURE:
359
	case V4L2_BUF_TYPE_VIDEO_OUTPUT:
360 361
		return get_v4l2_pix_format(&kp->fmt.pix, &up->fmt.pix);
	case V4L2_BUF_TYPE_VIDEO_OVERLAY:
362
	case V4L2_BUF_TYPE_VIDEO_OUTPUT_OVERLAY:
363 364
		return get_v4l2_window32(&kp->fmt.win, &up->fmt.win);
	case V4L2_BUF_TYPE_VBI_CAPTURE:
365
	case V4L2_BUF_TYPE_VBI_OUTPUT:
366
		return get_v4l2_vbi_format(&kp->fmt.vbi, &up->fmt.vbi);
367 368 369 370 371 372 373 374 375
	case V4L2_BUF_TYPE_SLICED_VBI_CAPTURE:
	case V4L2_BUF_TYPE_SLICED_VBI_OUTPUT:
		return get_v4l2_sliced_vbi_format(&kp->fmt.sliced, &up->fmt.sliced);
	case V4L2_BUF_TYPE_PRIVATE:
		if (copy_from_user(kp, up, sizeof(kp->fmt.raw_data)))
			return -EFAULT;
		return 0;
	case 0:
		return -EINVAL;
376
	default:
377
		printk(KERN_INFO "compat_ioctl32: unexpected VIDIOC_FMT type %d\n",
378
								kp->type);
379
		return -EINVAL;
380 381 382 383 384
	}
}

static int put_v4l2_format32(struct v4l2_format *kp, struct v4l2_format32 __user *up)
{
385
	if (!access_ok(VERIFY_WRITE, up, sizeof(struct v4l2_format32)) ||
386
		put_user(kp->type, &up->type))
387 388 389
		return -EFAULT;
	switch (kp->type) {
	case V4L2_BUF_TYPE_VIDEO_CAPTURE:
390
	case V4L2_BUF_TYPE_VIDEO_OUTPUT:
391 392
		return put_v4l2_pix_format(&kp->fmt.pix, &up->fmt.pix);
	case V4L2_BUF_TYPE_VIDEO_OVERLAY:
393
	case V4L2_BUF_TYPE_VIDEO_OUTPUT_OVERLAY:
394 395
		return put_v4l2_window32(&kp->fmt.win, &up->fmt.win);
	case V4L2_BUF_TYPE_VBI_CAPTURE:
396
	case V4L2_BUF_TYPE_VBI_OUTPUT:
397
		return put_v4l2_vbi_format(&kp->fmt.vbi, &up->fmt.vbi);
398 399 400 401 402 403 404 405 406
	case V4L2_BUF_TYPE_SLICED_VBI_CAPTURE:
	case V4L2_BUF_TYPE_SLICED_VBI_OUTPUT:
		return put_v4l2_sliced_vbi_format(&kp->fmt.sliced, &up->fmt.sliced);
	case V4L2_BUF_TYPE_PRIVATE:
		if (copy_to_user(up, kp, sizeof(up->fmt.raw_data)))
			return -EFAULT;
		return 0;
	case 0:
		return -EINVAL;
407
	default:
408 409 410
		printk(KERN_INFO "compat_ioctl32: unexpected VIDIOC_FMT type %d\n",
								kp->type);
		return -EINVAL;
411 412 413
	}
}

414
struct v4l2_standard32 {
415 416 417 418 419 420 421 422 423 424 425
	__u32		     index;
	__u32		     id[2]; /* __u64 would get the alignment wrong */
	__u8		     name[24];
	struct v4l2_fract    frameperiod; /* Frames, not fields */
	__u32		     framelines;
	__u32		     reserved[4];
};

static int get_v4l2_standard32(struct v4l2_standard *kp, struct v4l2_standard32 __user *up)
{
	/* other fields are not set by the user, nor used by the driver */
426 427 428 429
	if (!access_ok(VERIFY_READ, up, sizeof(struct v4l2_standard32)) ||
		get_user(kp->index, &up->index))
		return -EFAULT;
	return 0;
430 431 432 433
}

static int put_v4l2_standard32(struct v4l2_standard *kp, struct v4l2_standard32 __user *up)
{
434
	if (!access_ok(VERIFY_WRITE, up, sizeof(struct v4l2_standard32)) ||
435 436 437 438 439 440 441 442 443 444
		put_user(kp->index, &up->index) ||
		copy_to_user(up->id, &kp->id, sizeof(__u64)) ||
		copy_to_user(up->name, kp->name, 24) ||
		copy_to_user(&up->frameperiod, &kp->frameperiod, sizeof(kp->frameperiod)) ||
		put_user(kp->framelines, &up->framelines) ||
		copy_to_user(up->reserved, kp->reserved, 4 * sizeof(__u32)))
			return -EFAULT;
	return 0;
}

445
struct v4l2_buffer32 {
446 447 448 449 450 451 452 453 454 455 456 457 458 459 460 461 462 463 464 465 466 467 468
	__u32			index;
	enum v4l2_buf_type      type;
	__u32			bytesused;
	__u32			flags;
	enum v4l2_field		field;
	struct compat_timeval	timestamp;
	struct v4l2_timecode	timecode;
	__u32			sequence;

	/* memory location */
	enum v4l2_memory        memory;
	union {
		__u32           offset;
		compat_long_t   userptr;
	} m;
	__u32			length;
	__u32			input;
	__u32			reserved;
};

static int get_v4l2_buffer32(struct v4l2_buffer *kp, struct v4l2_buffer32 __user *up)
{

469 470 471 472 473 474 475
	if (!access_ok(VERIFY_READ, up, sizeof(struct v4l2_buffer32)) ||
		get_user(kp->index, &up->index) ||
		get_user(kp->type, &up->type) ||
		get_user(kp->flags, &up->flags) ||
		get_user(kp->memory, &up->memory) ||
		get_user(kp->input, &up->input))
			return -EFAULT;
476
	switch (kp->memory) {
477 478 479 480
	case V4L2_MEMORY_MMAP:
		break;
	case V4L2_MEMORY_USERPTR:
		{
481
		compat_long_t tmp;
482

483 484 485 486 487
		if (get_user(kp->length, &up->length) ||
		    get_user(tmp, &up->m.userptr))
			return -EFAULT;

		kp->m.userptr = (unsigned long)compat_ptr(tmp);
488 489 490
		}
		break;
	case V4L2_MEMORY_OVERLAY:
491
		if (get_user(kp->m.offset, &up->m.offset))
492
			return -EFAULT;
493 494 495 496 497 498 499
		break;
	}
	return 0;
}

static int put_v4l2_buffer32(struct v4l2_buffer *kp, struct v4l2_buffer32 __user *up)
{
500 501 502 503 504 505 506
	if (!access_ok(VERIFY_WRITE, up, sizeof(struct v4l2_buffer32)) ||
		put_user(kp->index, &up->index) ||
		put_user(kp->type, &up->type) ||
		put_user(kp->flags, &up->flags) ||
		put_user(kp->memory, &up->memory) ||
		put_user(kp->input, &up->input))
			return -EFAULT;
507
	switch (kp->memory) {
508
	case V4L2_MEMORY_MMAP:
509 510 511
		if (put_user(kp->length, &up->length) ||
			put_user(kp->m.offset, &up->m.offset))
			return -EFAULT;
512 513
		break;
	case V4L2_MEMORY_USERPTR:
514 515 516
		if (put_user(kp->length, &up->length) ||
			put_user(kp->m.userptr, &up->m.userptr))
			return -EFAULT;
517 518
		break;
	case V4L2_MEMORY_OVERLAY:
519 520
		if (put_user(kp->m.offset, &up->m.offset))
			return -EFAULT;
521 522
		break;
	}
523 524 525 526 527 528 529 530
	if (put_user(kp->bytesused, &up->bytesused) ||
		put_user(kp->field, &up->field) ||
		put_user(kp->timestamp.tv_sec, &up->timestamp.tv_sec) ||
		put_user(kp->timestamp.tv_usec, &up->timestamp.tv_usec) ||
		copy_to_user(&up->timecode, &kp->timecode, sizeof(struct v4l2_timecode)) ||
		put_user(kp->sequence, &up->sequence) ||
		put_user(kp->reserved, &up->reserved))
			return -EFAULT;
531 532 533
	return 0;
}

534
struct v4l2_framebuffer32 {
535 536 537 538 539 540
	__u32			capability;
	__u32			flags;
	compat_caddr_t 		base;
	struct v4l2_pix_format	fmt;
};

541 542 543 544
static int get_v4l2_framebuffer32(struct v4l2_framebuffer *kp, struct v4l2_framebuffer32 __user *up)
{
	u32 tmp;

545 546 547 548 549
	if (!access_ok(VERIFY_READ, up, sizeof(struct v4l2_framebuffer32)) ||
		get_user(tmp, &up->base) ||
		get_user(kp->capability, &up->capability) ||
		get_user(kp->flags, &up->flags))
			return -EFAULT;
550 551 552 553 554
	kp->base = compat_ptr(tmp);
	get_v4l2_pix_format(&kp->fmt, &up->fmt);
	return 0;
}

555 556 557 558
static int put_v4l2_framebuffer32(struct v4l2_framebuffer *kp, struct v4l2_framebuffer32 __user *up)
{
	u32 tmp = (u32)((unsigned long)kp->base);

559
	if (!access_ok(VERIFY_WRITE, up, sizeof(struct v4l2_framebuffer32)) ||
560 561 562 563
		put_user(tmp, &up->base) ||
		put_user(kp->capability, &up->capability) ||
		put_user(kp->flags, &up->flags))
			return -EFAULT;
564 565 566 567
	put_v4l2_pix_format(&kp->fmt, &up->fmt);
	return 0;
}

568 569 570 571 572 573 574 575 576 577 578 579 580 581
struct v4l2_input32 {
	__u32	     index;		/*  Which input */
	__u8	     name[32];		/*  Label */
	__u32	     type;		/*  Type of input */
	__u32	     audioset;		/*  Associated audios (bitfield) */
	__u32        tuner;             /*  Associated tuner */
	v4l2_std_id  std;
	__u32	     status;
	__u32	     reserved[4];
} __attribute__ ((packed));

/* The 64-bit v4l2_input struct has extra padding at the end of the struct.
   Otherwise it is identical to the 32-bit version. */
static inline int get_v4l2_input32(struct v4l2_input *kp, struct v4l2_input32 __user *up)
582
{
583
	if (copy_from_user(kp, up, sizeof(struct v4l2_input32)))
584
		return -EFAULT;
585 586 587
	return 0;
}

588
static inline int put_v4l2_input32(struct v4l2_input *kp, struct v4l2_input32 __user *up)
589
{
590
	if (copy_to_user(up, kp, sizeof(struct v4l2_input32)))
591
		return -EFAULT;
592 593 594
	return 0;
}

595 596 597 598 599 600
struct v4l2_ext_controls32 {
       __u32 ctrl_class;
       __u32 count;
       __u32 error_idx;
       __u32 reserved[2];
       compat_caddr_t controls; /* actually struct v4l2_ext_control32 * */
601 602
};

603 604 605 606 607 608 609 610 611 612 613 614 615 616 617 618
struct v4l2_ext_control32 {
	__u32 id;
	__u32 size;
	__u32 reserved2[1];
	union {
		__s32 value;
		__s64 value64;
		compat_caddr_t string; /* actually char * */
	};
} __attribute__ ((packed));

/* The following function really belong in v4l2-common, but that causes
   a circular dependency between modules. We need to think about this, but
   for now this will do. */

/* Return non-zero if this control is a pointer type. Currently only
619
   type STRING is a pointer type. */
620 621
static inline int ctrl_is_pointer(u32 id)
{
622 623 624 625 626 627 628
	switch (id) {
	case V4L2_CID_RDS_TX_PS_NAME:
	case V4L2_CID_RDS_TX_RADIO_TEXT:
		return 1;
	default:
		return 0;
	}
629 630
}

631
static int get_v4l2_ext_controls32(struct v4l2_ext_controls *kp, struct v4l2_ext_controls32 __user *up)
632
{
633
	struct v4l2_ext_control32 __user *ucontrols;
634 635 636 637 638 639 640 641 642 643 644 645 646 647 648 649 650 651 652 653 654 655 656
	struct v4l2_ext_control __user *kcontrols;
	int n;
	compat_caddr_t p;

	if (!access_ok(VERIFY_READ, up, sizeof(struct v4l2_ext_controls32)) ||
		get_user(kp->ctrl_class, &up->ctrl_class) ||
		get_user(kp->count, &up->count) ||
		get_user(kp->error_idx, &up->error_idx) ||
		copy_from_user(kp->reserved, up->reserved, sizeof(kp->reserved)))
			return -EFAULT;
	n = kp->count;
	if (n == 0) {
		kp->controls = NULL;
		return 0;
	}
	if (get_user(p, &up->controls))
		return -EFAULT;
	ucontrols = compat_ptr(p);
	if (!access_ok(VERIFY_READ, ucontrols, n * sizeof(struct v4l2_ext_control)))
		return -EFAULT;
	kcontrols = compat_alloc_user_space(n * sizeof(struct v4l2_ext_control));
	kp->controls = kcontrols;
	while (--n >= 0) {
657
		if (copy_in_user(kcontrols, ucontrols, sizeof(*kcontrols)))
658
			return -EFAULT;
659 660 661 662 663 664 665 666 667
		if (ctrl_is_pointer(kcontrols->id)) {
			void __user *s;

			if (get_user(p, &ucontrols->string))
				return -EFAULT;
			s = compat_ptr(p);
			if (put_user(s, &kcontrols->string))
				return -EFAULT;
		}
668 669 670
		ucontrols++;
		kcontrols++;
	}
671 672 673
	return 0;
}

674
static int put_v4l2_ext_controls32(struct v4l2_ext_controls *kp, struct v4l2_ext_controls32 __user *up)
675
{
676
	struct v4l2_ext_control32 __user *ucontrols;
677 678 679 680 681 682 683 684 685 686 687 688
	struct v4l2_ext_control __user *kcontrols = kp->controls;
	int n = kp->count;
	compat_caddr_t p;

	if (!access_ok(VERIFY_WRITE, up, sizeof(struct v4l2_ext_controls32)) ||
		put_user(kp->ctrl_class, &up->ctrl_class) ||
		put_user(kp->count, &up->count) ||
		put_user(kp->error_idx, &up->error_idx) ||
		copy_to_user(up->reserved, kp->reserved, sizeof(up->reserved)))
			return -EFAULT;
	if (!kp->count)
		return 0;
689

690
	if (get_user(p, &up->controls))
691
		return -EFAULT;
692 693
	ucontrols = compat_ptr(p);
	if (!access_ok(VERIFY_WRITE, ucontrols, n * sizeof(struct v4l2_ext_control)))
694 695
		return -EFAULT;

696
	while (--n >= 0) {
697 698 699 700 701 702 703 704
		unsigned size = sizeof(*ucontrols);

		/* Do not modify the pointer when copying a pointer control.
		   The contents of the pointer was changed, not the pointer
		   itself. */
		if (ctrl_is_pointer(kcontrols->id))
			size -= sizeof(ucontrols->value64);
		if (copy_in_user(ucontrols, kcontrols, size))
705 706 707
			return -EFAULT;
		ucontrols++;
		kcontrols++;
708
	}
709
	return 0;
710
}
711 712 713 714 715 716 717 718 719 720 721 722 723 724 725 726

#define VIDIOC_G_FMT32		_IOWR('V',  4, struct v4l2_format32)
#define VIDIOC_S_FMT32		_IOWR('V',  5, struct v4l2_format32)
#define VIDIOC_QUERYBUF32	_IOWR('V',  9, struct v4l2_buffer32)
#define VIDIOC_G_FBUF32		_IOR ('V', 10, struct v4l2_framebuffer32)
#define VIDIOC_S_FBUF32		_IOW ('V', 11, struct v4l2_framebuffer32)
#define VIDIOC_QBUF32		_IOWR('V', 15, struct v4l2_buffer32)
#define VIDIOC_DQBUF32		_IOWR('V', 17, struct v4l2_buffer32)
#define VIDIOC_ENUMSTD32	_IOWR('V', 25, struct v4l2_standard32)
#define VIDIOC_ENUMINPUT32	_IOWR('V', 26, struct v4l2_input32)
#define VIDIOC_TRY_FMT32      	_IOWR('V', 64, struct v4l2_format32)
#define VIDIOC_G_EXT_CTRLS32    _IOWR('V', 71, struct v4l2_ext_controls32)
#define VIDIOC_S_EXT_CTRLS32    _IOWR('V', 72, struct v4l2_ext_controls32)
#define VIDIOC_TRY_EXT_CTRLS32  _IOWR('V', 73, struct v4l2_ext_controls32)

#define VIDIOC_OVERLAY32	_IOW ('V', 14, s32)
727
#ifdef __OLD_VIDIOC_
728
#define VIDIOC_OVERLAY32_OLD	_IOWR('V', 14, s32)
729
#endif
730 731 732 733 734 735
#define VIDIOC_STREAMON32	_IOW ('V', 18, s32)
#define VIDIOC_STREAMOFF32	_IOW ('V', 19, s32)
#define VIDIOC_G_INPUT32	_IOR ('V', 38, s32)
#define VIDIOC_S_INPUT32	_IOWR('V', 39, s32)
#define VIDIOC_G_OUTPUT32	_IOR ('V', 46, s32)
#define VIDIOC_S_OUTPUT32	_IOWR('V', 47, s32)
736

737
static long do_video_ioctl(struct file *file, unsigned int cmd, unsigned long arg)
738 739
{
	union {
740
#ifdef CONFIG_VIDEO_V4L1_COMPAT
741 742 743
		struct video_tuner vt;
		struct video_buffer vb;
		struct video_window vw;
744
		struct video_code vc;
745
		struct video_audio va;
746
#endif
747 748 749
		struct v4l2_format v2f;
		struct v4l2_buffer v2b;
		struct v4l2_framebuffer v2fb;
750
		struct v4l2_input v2i;
751 752
		struct v4l2_standard v2s;
		struct v4l2_ext_controls v2ecs;
753
		unsigned long vx;
754
		int vi;
755 756
	} karg;
	void __user *up = compat_ptr(arg);
757
	int compatible_arg = 1;
758
	long err = 0;
759 760

	/* First, convert the command. */
761
	switch (cmd) {
762
#ifdef CONFIG_VIDEO_V4L1_COMPAT
763 764 765 766 767 768 769 770 771
	case VIDIOCGTUNER32: cmd = VIDIOCGTUNER; break;
	case VIDIOCSTUNER32: cmd = VIDIOCSTUNER; break;
	case VIDIOCGWIN32: cmd = VIDIOCGWIN; break;
	case VIDIOCSWIN32: cmd = VIDIOCSWIN; break;
	case VIDIOCGFBUF32: cmd = VIDIOCGFBUF; break;
	case VIDIOCSFBUF32: cmd = VIDIOCSFBUF; break;
	case VIDIOCGFREQ32: cmd = VIDIOCGFREQ; break;
	case VIDIOCSFREQ32: cmd = VIDIOCSFREQ; break;
	case VIDIOCSMICROCODE32: cmd = VIDIOCSMICROCODE; break;
772
#endif
773 774 775 776 777 778 779 780 781 782 783 784 785 786
	case VIDIOC_G_FMT32: cmd = VIDIOC_G_FMT; break;
	case VIDIOC_S_FMT32: cmd = VIDIOC_S_FMT; break;
	case VIDIOC_QUERYBUF32: cmd = VIDIOC_QUERYBUF; break;
	case VIDIOC_G_FBUF32: cmd = VIDIOC_G_FBUF; break;
	case VIDIOC_S_FBUF32: cmd = VIDIOC_S_FBUF; break;
	case VIDIOC_QBUF32: cmd = VIDIOC_QBUF; break;
	case VIDIOC_DQBUF32: cmd = VIDIOC_DQBUF; break;
	case VIDIOC_ENUMSTD32: cmd = VIDIOC_ENUMSTD; break;
	case VIDIOC_ENUMINPUT32: cmd = VIDIOC_ENUMINPUT; break;
	case VIDIOC_TRY_FMT32: cmd = VIDIOC_TRY_FMT; break;
	case VIDIOC_G_EXT_CTRLS32: cmd = VIDIOC_G_EXT_CTRLS; break;
	case VIDIOC_S_EXT_CTRLS32: cmd = VIDIOC_S_EXT_CTRLS; break;
	case VIDIOC_TRY_EXT_CTRLS32: cmd = VIDIOC_TRY_EXT_CTRLS; break;
	case VIDIOC_OVERLAY32: cmd = VIDIOC_OVERLAY; break;
787
#ifdef __OLD_VIDIOC_
788
	case VIDIOC_OVERLAY32_OLD: cmd = VIDIOC_OVERLAY; break;
789
#endif
790 791 792 793 794 795 796
	case VIDIOC_STREAMON32: cmd = VIDIOC_STREAMON; break;
	case VIDIOC_STREAMOFF32: cmd = VIDIOC_STREAMOFF; break;
	case VIDIOC_G_INPUT32: cmd = VIDIOC_G_INPUT; break;
	case VIDIOC_S_INPUT32: cmd = VIDIOC_S_INPUT; break;
	case VIDIOC_G_OUTPUT32: cmd = VIDIOC_G_OUTPUT; break;
	case VIDIOC_S_OUTPUT32: cmd = VIDIOC_S_OUTPUT; break;
	}
797

798
	switch (cmd) {
799
#ifdef CONFIG_VIDEO_V4L1_COMPAT
800 801 802
	case VIDIOCSTUNER:
	case VIDIOCGTUNER:
		err = get_video_tuner32(&karg.vt, up);
803
		compatible_arg = 0;
804 805 806 807
		break;

	case VIDIOCSFBUF:
		err = get_video_buffer32(&karg.vb, up);
808
		compatible_arg = 0;
809 810
		break;

811 812 813 814 815 816 817 818 819 820 821 822 823 824 825
	case VIDIOCSWIN:
		err = get_video_window32(&karg.vw, up);
		compatible_arg = 0;
		break;

	case VIDIOCGWIN:
	case VIDIOCGFBUF:
	case VIDIOCGFREQ:
		compatible_arg = 0;
		break;

	case VIDIOCSMICROCODE:
		err = get_microcode32(&karg.vc, up);
		compatible_arg = 0;
		break;
826

827
	case VIDIOCSFREQ:
828 829 830 831 832 833 834
		err = get_user(karg.vx, (u32 __user *)up);
		compatible_arg = 0;
		break;

	case VIDIOCCAPTURE:
	case VIDIOCSYNC:
	case VIDIOCSWRITEMODE:
835
#endif
836
	case VIDIOC_OVERLAY:
837 838
	case VIDIOC_STREAMON:
	case VIDIOC_STREAMOFF:
839 840 841 842
	case VIDIOC_S_INPUT:
	case VIDIOC_S_OUTPUT:
		err = get_user(karg.vi, (s32 __user *)up);
		compatible_arg = 0;
843
		break;
844

845 846
	case VIDIOC_G_INPUT:
	case VIDIOC_G_OUTPUT:
847 848
		compatible_arg = 0;
		break;
849 850 851 852 853 854 855 856 857 858 859 860 861 862 863

	case VIDIOC_G_FMT:
	case VIDIOC_S_FMT:
	case VIDIOC_TRY_FMT:
		err = get_v4l2_format32(&karg.v2f, up);
		compatible_arg = 0;
		break;

	case VIDIOC_QUERYBUF:
	case VIDIOC_QBUF:
	case VIDIOC_DQBUF:
		err = get_v4l2_buffer32(&karg.v2b, up);
		compatible_arg = 0;
		break;

864 865
	case VIDIOC_S_FBUF:
		err = get_v4l2_framebuffer32(&karg.v2fb, up);
866 867 868
		compatible_arg = 0;
		break;

869
	case VIDIOC_G_FBUF:
870 871 872
		compatible_arg = 0;
		break;

873 874
	case VIDIOC_ENUMSTD:
		err = get_v4l2_standard32(&karg.v2s, up);
875 876 877
		compatible_arg = 0;
		break;

878
	case VIDIOC_ENUMINPUT:
879 880 881 882
		err = get_v4l2_input32(&karg.v2i, up);
		compatible_arg = 0;
		break;

883 884 885 886
	case VIDIOC_G_EXT_CTRLS:
	case VIDIOC_S_EXT_CTRLS:
	case VIDIOC_TRY_EXT_CTRLS:
		err = get_v4l2_ext_controls32(&karg.v2ecs, up);
887 888
		compatible_arg = 0;
		break;
889
	}
890
	if (err)
891
		return err;
892

893
	if (compatible_arg)
894
		err = native_ioctl(file, cmd, (unsigned long)up);
895 896
	else {
		mm_segment_t old_fs = get_fs();
897

898
		set_fs(KERNEL_DS);
899
		err = native_ioctl(file, cmd, (unsigned long)&karg);
900 901
		set_fs(old_fs);
	}
902 903 904 905 906 907 908 909 910 911 912 913 914 915 916 917

	/* Special case: even after an error we need to put the
	   results back for these ioctls since the error_idx will
	   contain information on which control failed. */
	switch (cmd) {
	case VIDIOC_G_EXT_CTRLS:
	case VIDIOC_S_EXT_CTRLS:
	case VIDIOC_TRY_EXT_CTRLS:
		if (put_v4l2_ext_controls32(&karg.v2ecs, up))
			err = -EFAULT;
		break;
	}
	if (err)
		return err;

	switch (cmd) {
918
#ifdef CONFIG_VIDEO_V4L1_COMPAT
919 920 921
	case VIDIOCGTUNER:
		err = put_video_tuner32(&karg.vt, up);
		break;
922

923 924 925
	case VIDIOCGWIN:
		err = put_video_window32(&karg.vw, up);
		break;
926

927 928 929
	case VIDIOCGFBUF:
		err = put_video_buffer32(&karg.vb, up);
		break;
930

931 932 933
	case VIDIOCGFREQ:
		err = put_user(((u32)karg.vx), (u32 __user *)up);
		break;
934
#endif
935 936 937 938 939 940
	case VIDIOC_S_INPUT:
	case VIDIOC_S_OUTPUT:
	case VIDIOC_G_INPUT:
	case VIDIOC_G_OUTPUT:
		err = put_user(((s32)karg.vi), (s32 __user *)up);
		break;
941

942 943 944 945 946 947 948 949 950 951 952 953 954 955 956 957 958 959 960 961 962 963 964
	case VIDIOC_G_FBUF:
		err = put_v4l2_framebuffer32(&karg.v2fb, up);
		break;

	case VIDIOC_G_FMT:
	case VIDIOC_S_FMT:
	case VIDIOC_TRY_FMT:
		err = put_v4l2_format32(&karg.v2f, up);
		break;

	case VIDIOC_QUERYBUF:
	case VIDIOC_QBUF:
	case VIDIOC_DQBUF:
		err = put_v4l2_buffer32(&karg.v2b, up);
		break;

	case VIDIOC_ENUMSTD:
		err = put_v4l2_standard32(&karg.v2s, up);
		break;

	case VIDIOC_ENUMINPUT:
		err = put_v4l2_input32(&karg.v2i, up);
		break;
965 966 967 968
	}
	return err;
}

969
long v4l2_compat_ioctl32(struct file *file, unsigned int cmd, unsigned long arg)
970
{
971
	long ret = -ENOIOCTLCMD;
972

973
	if (!file->f_op->ioctl && !file->f_op->unlocked_ioctl)
974 975 976
		return ret;

	switch (cmd) {
977
#ifdef CONFIG_VIDEO_V4L1_COMPAT
978 979 980
	case VIDIOCGCAP:
	case VIDIOCGCHAN:
	case VIDIOCSCHAN:
981 982
	case VIDIOCGTUNER32:
	case VIDIOCSTUNER32:
983 984 985
	case VIDIOCGPICT:
	case VIDIOCSPICT:
	case VIDIOCCAPTURE32:
986
	case VIDIOCGWIN32:
987
	case VIDIOCSWIN32:
988 989
	case VIDIOCGFBUF32:
	case VIDIOCSFBUF32:
990
	case VIDIOCKEY:
991
	case VIDIOCGFREQ32:
992
	case VIDIOCSFREQ32:
993 994
	case VIDIOCGAUDIO:
	case VIDIOCSAUDIO:
995 996 997 998 999 1000 1001 1002 1003 1004
	case VIDIOCSYNC32:
	case VIDIOCMCAPTURE:
	case VIDIOCGMBUF:
	case VIDIOCGUNIT:
	case VIDIOCGCAPTURE:
	case VIDIOCSCAPTURE:
	case VIDIOCSPLAYMODE:
	case VIDIOCSWRITEMODE32:
	case VIDIOCGPLAYINFO:
	case VIDIOCSMICROCODE32:
1005 1006
	case VIDIOCGVBIFMT:
	case VIDIOCSVBIFMT:
1007 1008 1009 1010 1011 1012 1013 1014
#endif
#ifdef __OLD_VIDIOC_
	case VIDIOC_OVERLAY32_OLD:
	case VIDIOC_S_PARM_OLD:
	case VIDIOC_S_CTRL_OLD:
	case VIDIOC_G_AUDIO_OLD:
	case VIDIOC_G_AUDOUT_OLD:
	case VIDIOC_CROPCAP_OLD:
1015
#endif
1016
	case VIDIOC_QUERYCAP:
1017
	case VIDIOC_RESERVED:
1018 1019 1020 1021 1022 1023 1024 1025 1026 1027 1028 1029 1030
	case VIDIOC_ENUM_FMT:
	case VIDIOC_G_FMT32:
	case VIDIOC_S_FMT32:
	case VIDIOC_REQBUFS:
	case VIDIOC_QUERYBUF32:
	case VIDIOC_G_FBUF32:
	case VIDIOC_S_FBUF32:
	case VIDIOC_OVERLAY32:
	case VIDIOC_QBUF32:
	case VIDIOC_DQBUF32:
	case VIDIOC_STREAMON32:
	case VIDIOC_STREAMOFF32:
	case VIDIOC_G_PARM:
1031
	case VIDIOC_S_PARM:
1032 1033 1034 1035 1036
	case VIDIOC_G_STD:
	case VIDIOC_S_STD:
	case VIDIOC_ENUMSTD32:
	case VIDIOC_ENUMINPUT32:
	case VIDIOC_G_CTRL:
1037
	case VIDIOC_S_CTRL:
1038 1039 1040 1041
	case VIDIOC_G_TUNER:
	case VIDIOC_S_TUNER:
	case VIDIOC_G_AUDIO:
	case VIDIOC_S_AUDIO:
1042
	case VIDIOC_QUERYCTRL:
1043
	case VIDIOC_QUERYMENU:
1044 1045
	case VIDIOC_G_INPUT32:
	case VIDIOC_S_INPUT32:
1046 1047 1048 1049 1050 1051 1052 1053 1054 1055 1056 1057 1058 1059 1060
	case VIDIOC_G_OUTPUT32:
	case VIDIOC_S_OUTPUT32:
	case VIDIOC_ENUMOUTPUT:
	case VIDIOC_G_AUDOUT:
	case VIDIOC_S_AUDOUT:
	case VIDIOC_G_MODULATOR:
	case VIDIOC_S_MODULATOR:
	case VIDIOC_S_FREQUENCY:
	case VIDIOC_G_FREQUENCY:
	case VIDIOC_CROPCAP:
	case VIDIOC_G_CROP:
	case VIDIOC_S_CROP:
	case VIDIOC_G_JPEGCOMP:
	case VIDIOC_S_JPEGCOMP:
	case VIDIOC_QUERYSTD:
1061
	case VIDIOC_TRY_FMT32:
1062 1063 1064 1065 1066 1067 1068 1069 1070
	case VIDIOC_ENUMAUDIO:
	case VIDIOC_ENUMAUDOUT:
	case VIDIOC_G_PRIORITY:
	case VIDIOC_S_PRIORITY:
	case VIDIOC_G_SLICED_VBI_CAP:
	case VIDIOC_LOG_STATUS:
	case VIDIOC_G_EXT_CTRLS32:
	case VIDIOC_S_EXT_CTRLS32:
	case VIDIOC_TRY_EXT_CTRLS32:
1071 1072
	case VIDIOC_ENUM_FRAMESIZES:
	case VIDIOC_ENUM_FRAMEINTERVALS:
1073 1074 1075 1076 1077
	case VIDIOC_G_ENC_INDEX:
	case VIDIOC_ENCODER_CMD:
	case VIDIOC_TRY_ENCODER_CMD:
	case VIDIOC_DBG_S_REGISTER:
	case VIDIOC_DBG_G_REGISTER:
1078
	case VIDIOC_DBG_G_CHIP_IDENT:
1079
	case VIDIOC_S_HW_FREQ_SEEK:
1080 1081 1082
		ret = do_video_ioctl(file, cmd, arg);
		break;

1083
#ifdef CONFIG_VIDEO_V4L1_COMPAT
1084 1085 1086 1087 1088 1089 1090 1091 1092 1093 1094
	/* BTTV specific... */
	case _IOW('v',  BASE_VIDIOCPRIVATE+0, char [256]):
	case _IOR('v',  BASE_VIDIOCPRIVATE+1, char [256]):
	case _IOR('v' , BASE_VIDIOCPRIVATE+2, unsigned int):
	case _IOW('v' , BASE_VIDIOCPRIVATE+3, char [16]): /* struct bttv_pll_info */
	case _IOR('v' , BASE_VIDIOCPRIVATE+4, int):
	case _IOR('v' , BASE_VIDIOCPRIVATE+5, int):
	case _IOR('v' , BASE_VIDIOCPRIVATE+6, int):
	case _IOR('v' , BASE_VIDIOCPRIVATE+7, int):
		ret = native_ioctl(file, cmd, (unsigned long)compat_ptr(arg));
		break;
1095
#endif
1096
	default:
1097 1098 1099
		printk(KERN_WARNING "compat_ioctl32: "
			"unknown ioctl '%c', dir=%d, #%d (0x%08x)\n",
			_IOC_TYPE(cmd), _IOC_DIR(cmd), _IOC_NR(cmd), cmd);
1100
		break;
1101
	}
1102
	return ret;
1103
}
1104
EXPORT_SYMBOL_GPL(v4l2_compat_ioctl32);
1105
#endif
1106 1107

MODULE_LICENSE("GPL");