n_tty.c 57.7 KB
Newer Older
L
Linus Torvalds 已提交
1 2
/*
 * n_tty.c --- implements the N_TTY line discipline.
3
 *
L
Linus Torvalds 已提交
4 5 6 7 8 9 10
 * This code used to be in tty_io.c, but things are getting hairy
 * enough that it made sense to split things off.  (The N_TTY
 * processing has changed so much that it's hardly recognizable,
 * anyway...)
 *
 * Note that the open routine for N_TTY is guaranteed never to return
 * an error.  This is because Linux will fall back to setting a line
11
 * to N_TTY if it can not switch to any other line discipline.
L
Linus Torvalds 已提交
12 13
 *
 * Written by Theodore Ts'o, Copyright 1994.
14
 *
L
Linus Torvalds 已提交
15 16
 * This file also contains code originally written by Linus Torvalds,
 * Copyright 1991, 1992, 1993, and by Julian Cowley, Copyright 1994.
17
 *
L
Linus Torvalds 已提交
18 19 20 21 22
 * This file may be redistributed under the terms of the GNU General Public
 * License.
 *
 * Reduced memory usage for older ARM systems  - Russell King.
 *
23
 * 2000/01/20   Fixed SMP locking on put_tty_queue using bits of
L
Linus Torvalds 已提交
24 25 26 27 28
 *		the patch by Andrew J. Kroll <ag784@freenet.buffalo.edu>
 *		who actually finally proved there really was a race.
 *
 * 2002/03/18   Implemented n_tty_wakeup to send SIGIO POLL_OUTs to
 *		waiting writing processes-Sapan Bhatia <sapan@corewars.org>.
29
 *		Also fixed a bug in BLOCKING mode where n_tty_write returns
L
Linus Torvalds 已提交
30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47
 *		EAGAIN
 */

#include <linux/types.h>
#include <linux/major.h>
#include <linux/errno.h>
#include <linux/signal.h>
#include <linux/fcntl.h>
#include <linux/sched.h>
#include <linux/interrupt.h>
#include <linux/tty.h>
#include <linux/timer.h>
#include <linux/ctype.h>
#include <linux/mm.h>
#include <linux/string.h>
#include <linux/slab.h>
#include <linux/poll.h>
#include <linux/bitops.h>
M
Miloslav Trmac 已提交
48 49
#include <linux/audit.h>
#include <linux/file.h>
A
Alan Cox 已提交
50
#include <linux/uaccess.h>
51
#include <linux/module.h>
52
#include <linux/ratelimit.h>
L
Linus Torvalds 已提交
53 54 55 56 57 58 59 60 61 62 63


/* number of characters left in xmit buffer before select has we have room */
#define WAKEUP_CHARS 256

/*
 * This defines the low- and high-watermarks for throttling and
 * unthrottling the TTY driver.  These watermarks are used for
 * controlling the space in the read buffer.
 */
#define TTY_THRESHOLD_THROTTLE		128 /* now based on remaining room */
64
#define TTY_THRESHOLD_UNTHROTTLE	128
L
Linus Torvalds 已提交
65

66 67 68 69 70 71 72 73 74 75 76
/*
 * Special byte codes used in the echo buffer to represent operations
 * or special handling of characters.  Bytes in the echo buffer that
 * are not part of such special blocks are treated as normal character
 * codes.
 */
#define ECHO_OP_START 0xff
#define ECHO_OP_MOVE_BACK_COL 0x80
#define ECHO_OP_SET_CANON_COL 0x81
#define ECHO_OP_ERASE_TAB 0x82

77 78 79 80 81 82 83
#undef N_TTY_TRACE
#ifdef N_TTY_TRACE
# define n_tty_trace(f, args...)	trace_printk(f, ##args)
#else
# define n_tty_trace(f, args...)
#endif

J
Jiri Slaby 已提交
84
struct n_tty_data {
85 86 87 88 89 90
	/* producer-published */
	size_t read_head;
	size_t canon_head;
	DECLARE_BITMAP(process_char_map, 256);

	/* private to n_tty_receive_overrun (single-threaded) */
91 92 93
	unsigned long overrun_time;
	int num_overrun;

94 95 96
	/* non-atomic */
	bool no_room;

97
	/* must hold exclusive termios_rwsem to reset these */
98 99
	unsigned char lnext:1, erasing:1, raw:1, real_raw:1, icanon:1;
	unsigned char echo_overrun:1;
100

101 102
	/* shared by producer and consumer */
	char *read_buf;
103
	DECLARE_BITMAP(read_flags, N_TTY_BUF_SIZE);
104

105
	int minimum_to_wake;
106

107 108 109 110
	/* consumer-published */
	size_t read_tail;

	/* protected by echo_lock */
111 112 113 114
	unsigned char *echo_buf;
	unsigned int echo_pos;
	unsigned int echo_cnt;

115 116
	/* protected by output lock */
	unsigned int column;
117
	unsigned int canon_column;
118 119 120 121

	struct mutex atomic_read_lock;
	struct mutex output_lock;
	struct mutex echo_lock;
J
Jiri Slaby 已提交
122 123
};

124 125
static inline size_t read_cnt(struct n_tty_data *ldata)
{
P
Peter Hurley 已提交
126
	return ldata->read_head - ldata->read_tail;
127 128
}

129 130 131 132 133 134 135 136 137 138
static inline unsigned char read_buf(struct n_tty_data *ldata, size_t i)
{
	return ldata->read_buf[i & (N_TTY_BUF_SIZE - 1)];
}

static inline unsigned char *read_buf_addr(struct n_tty_data *ldata, size_t i)
{
	return &ldata->read_buf[i & (N_TTY_BUF_SIZE - 1)];
}

M
Miloslav Trmac 已提交
139 140 141
static inline int tty_put_user(struct tty_struct *tty, unsigned char x,
			       unsigned char __user *ptr)
{
142 143 144
	struct n_tty_data *ldata = tty->disc_data;

	tty_audit_add_data(tty, &x, 1, ldata->icanon);
M
Miloslav Trmac 已提交
145 146 147
	return put_user(x, ptr);
}

148
static int receive_room(struct tty_struct *tty)
149
{
150
	struct n_tty_data *ldata = tty->disc_data;
151
	int left;
152

153 154 155 156
	if (I_PARMRK(tty)) {
		/* Multiply read_cnt by 3, since each byte might take up to
		 * three times as many spaces when PARMRK is set (depending on
		 * its flags, e.g. parity error). */
157
		left = N_TTY_BUF_SIZE - read_cnt(ldata) * 3 - 1;
158
	} else
159
		left = N_TTY_BUF_SIZE - read_cnt(ldata) - 1;
160

161 162 163 164 165 166 167
	/*
	 * If we are doing input canonicalization, and there are no
	 * pending newlines, let characters through without limit, so
	 * that erase characters will be handled.  Other excess
	 * characters will be beeped.
	 */
	if (left <= 0)
168
		left = ldata->icanon && ldata->canon_head == ldata->read_tail;
169

170
	return left;
171 172
}

173 174 175 176 177 178
/**
 *	n_tty_set_room	-	receive space
 *	@tty: terminal
 *
 *	Re-schedules the flip buffer work if space just became available.
 *
179 180 181 182
 *	Caller holds exclusive termios_rwsem
 *	   or
 *	n_tty_read()/consumer path:
 *		holds non-exclusive termios_rwsem
183 184
 */

185 186
static void n_tty_set_room(struct tty_struct *tty)
{
187 188
	struct n_tty_data *ldata = tty->disc_data;

189
	/* Did this open up the receive buffer? We may need to flip */
190 191 192
	if (unlikely(ldata->no_room) && receive_room(tty)) {
		ldata->no_room = 0;

J
Jiri Slaby 已提交
193
		WARN_RATELIMIT(tty->port->itty == NULL,
194
				"scheduling with invalid itty\n");
195 196 197 198 199 200
		/* see if ldisc has been killed - if so, this means that
		 * even though the ldisc has been halted and ->buf.work
		 * cancelled, ->buf.work is about to be rescheduled
		 */
		WARN_RATELIMIT(test_bit(TTY_LDISC_HALTED, &tty->flags),
			       "scheduling buffer work for halted ldisc\n");
J
Jiri Slaby 已提交
201 202
		schedule_work(&tty->port->buf.work);
	}
203 204
}

205 206 207 208 209 210 211 212 213 214 215 216
static ssize_t chars_in_buffer(struct tty_struct *tty)
{
	struct n_tty_data *ldata = tty->disc_data;
	ssize_t n = 0;

	if (!ldata->icanon)
		n = read_cnt(ldata);
	else
		n = ldata->canon_head - ldata->read_tail;
	return n;
}

217 218 219 220 221 222 223 224 225 226 227 228 229 230 231
/**
 *	n_tty_write_wakeup	-	asynchronous I/O notifier
 *	@tty: tty device
 *
 *	Required for the ptys, serial driver etc. since processes
 *	that attach themselves to the master and rely on ASYNC
 *	IO must be woken up
 */

static void n_tty_write_wakeup(struct tty_struct *tty)
{
	if (tty->fasync && test_and_clear_bit(TTY_DO_WRITE_WAKEUP, &tty->flags))
		kill_fasync(&tty->fasync, SIGIO, POLL_OUT);
}

232 233 234 235 236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 258 259 260 261 262 263 264 265 266 267 268 269 270 271 272 273 274 275
static inline void n_tty_check_throttle(struct tty_struct *tty)
{
	/*
	 * Check the remaining room for the input canonicalization
	 * mode.  We don't want to throttle the driver if we're in
	 * canonical mode and don't have a newline yet!
	 */
	while (1) {
		int throttled;
		tty_set_flow_change(tty, TTY_THROTTLE_SAFE);
		if (receive_room(tty) >= TTY_THRESHOLD_THROTTLE)
			break;
		throttled = tty_throttle_safe(tty);
		if (!throttled)
			break;
	}
	__tty_set_flow_change(tty, 0);
}

static inline void n_tty_check_unthrottle(struct tty_struct *tty)
{
	/* If there is enough space in the read buffer now, let the
	 * low-level driver know. We use chars_in_buffer() to
	 * check the buffer, as it now knows about canonical mode.
	 * Otherwise, if the driver is throttled and the line is
	 * longer than TTY_THRESHOLD_UNTHROTTLE in canonical mode,
	 * we won't get any more characters.
	 */

	while (1) {
		int unthrottled;
		tty_set_flow_change(tty, TTY_UNTHROTTLE_SAFE);
		if (chars_in_buffer(tty) > TTY_THRESHOLD_UNTHROTTLE)
			break;
		if (!tty->count)
			break;
		n_tty_set_room(tty);
		unthrottled = tty_unthrottle_safe(tty);
		if (!unthrottled)
			break;
	}
	__tty_set_flow_change(tty, 0);
}

276 277 278
/**
 *	put_tty_queue		-	add character to tty
 *	@c: character
J
Jiri Slaby 已提交
279
 *	@ldata: n_tty data
280
 *
281 282 283 284 285 286 287 288
 *	Add a character to the tty read_buf queue.
 *
 *	n_tty_receive_buf()/producer path:
 *		caller holds non-exclusive termios_rwsem
 *		modifies read_head
 *
 *	read_head is only considered 'published' if canonical mode is
 *	not active.
289 290
 */

J
Jiri Slaby 已提交
291
static void put_tty_queue(unsigned char c, struct n_tty_data *ldata)
L
Linus Torvalds 已提交
292
{
293 294 295 296
	if (read_cnt(ldata) < N_TTY_BUF_SIZE) {
		*read_buf_addr(ldata, ldata->read_head) = c;
		ldata->read_head++;
	}
L
Linus Torvalds 已提交
297 298 299 300 301 302
}

/**
 *	reset_buffer_flags	-	reset buffer state
 *	@tty: terminal to reset
 *
303 304
 *	Reset the read buffer counters and clear the flags.
 *	Called from n_tty_open() and n_tty_flush_buffer().
305
 *
306 307
 *	Locking: caller holds exclusive termios_rwsem
 *		 (or locking is not required)
L
Linus Torvalds 已提交
308
 */
309

310
static void reset_buffer_flags(struct n_tty_data *ldata)
L
Linus Torvalds 已提交
311
{
312
	ldata->read_head = ldata->canon_head = ldata->read_tail = 0;
313

314
	mutex_lock(&ldata->echo_lock);
315
	ldata->echo_pos = ldata->echo_cnt = ldata->echo_overrun = 0;
316
	mutex_unlock(&ldata->echo_lock);
317

318
	ldata->erasing = 0;
319
	bitmap_zero(ldata->read_flags, N_TTY_BUF_SIZE);
L
Linus Torvalds 已提交
320 321
}

322 323 324 325 326 327 328 329 330 331 332 333
static void n_tty_packet_mode_flush(struct tty_struct *tty)
{
	unsigned long flags;

	spin_lock_irqsave(&tty->ctrl_lock, flags);
	if (tty->link->packet) {
		tty->ctrl_status |= TIOCPKT_FLUSHREAD;
		wake_up_interruptible(&tty->link->read_wait);
	}
	spin_unlock_irqrestore(&tty->ctrl_lock, flags);
}

L
Linus Torvalds 已提交
334 335 336 337
/**
 *	n_tty_flush_buffer	-	clean input queue
 *	@tty:	terminal device
 *
338 339 340
 *	Flush the input buffer. Called when the tty layer wants the
 *	buffer flushed (eg at hangup) or when the N_TTY line discipline
 *	internally has to clean the pending queue (for example some signals).
L
Linus Torvalds 已提交
341
 *
342 343 344 345
 *	Holds termios_rwsem to exclude producer/consumer while
 *	buffer indices are reset.
 *
 *	Locking: ctrl_lock, exclusive termios_rwsem
L
Linus Torvalds 已提交
346
 */
347 348

static void n_tty_flush_buffer(struct tty_struct *tty)
L
Linus Torvalds 已提交
349
{
350
	down_write(&tty->termios_rwsem);
351 352
	reset_buffer_flags(tty->disc_data);
	n_tty_set_room(tty);
353

354 355
	if (tty->link)
		n_tty_packet_mode_flush(tty);
356
	up_write(&tty->termios_rwsem);
L
Linus Torvalds 已提交
357 358
}

359 360 361 362 363 364 365 366 367 368
/**
 *	n_tty_chars_in_buffer	-	report available bytes
 *	@tty: tty device
 *
 *	Report the number of characters buffered to be delivered to user
 *	at this instant in time.
 *
 *	Locking: exclusive termios_rwsem
 */

369 370
static ssize_t n_tty_chars_in_buffer(struct tty_struct *tty)
{
371 372
	ssize_t n;

373
	WARN_ONCE(1, "%s is deprecated and scheduled for removal.", __func__);
374 375 376 377 378

	down_write(&tty->termios_rwsem);
	n = chars_in_buffer(tty);
	up_write(&tty->termios_rwsem);
	return n;
379 380
}

L
Linus Torvalds 已提交
381 382 383 384 385 386 387 388
/**
 *	is_utf8_continuation	-	utf8 multibyte check
 *	@c: byte to check
 *
 *	Returns true if the utf8 character 'c' is a multibyte continuation
 *	character. We use this to correctly compute the on screen size
 *	of the character when printing
 */
389

L
Linus Torvalds 已提交
390 391 392 393 394 395 396 397 398 399 400 401
static inline int is_utf8_continuation(unsigned char c)
{
	return (c & 0xc0) == 0x80;
}

/**
 *	is_continuation		-	multibyte check
 *	@c: byte to check
 *
 *	Returns true if the utf8 character 'c' is a multibyte continuation
 *	character and the terminal is in unicode mode.
 */
402

L
Linus Torvalds 已提交
403 404 405 406 407 408
static inline int is_continuation(unsigned char c, struct tty_struct *tty)
{
	return I_IUTF8(tty) && is_utf8_continuation(c);
}

/**
409
 *	do_output_char			-	output one character
L
Linus Torvalds 已提交
410 411
 *	@c: character (or partial unicode symbol)
 *	@tty: terminal device
412
 *	@space: space available in tty driver write buffer
L
Linus Torvalds 已提交
413
 *
414 415
 *	This is a helper function that handles one output character
 *	(including special characters like TAB, CR, LF, etc.),
416 417
 *	doing OPOST processing and putting the results in the
 *	tty driver's write buffer.
418 419 420 421
 *
 *	Note that Linux currently ignores TABDLY, CRDLY, VTDLY, FFDLY
 *	and NLDLY.  They simply aren't relevant in the world today.
 *	If you ever need them, add them here.
L
Linus Torvalds 已提交
422
 *
423 424 425 426 427
 *	Returns the number of bytes of buffer space used or -1 if
 *	no space left.
 *
 *	Locking: should be called under the output_lock to protect
 *		 the column state and space left in the buffer
L
Linus Torvalds 已提交
428
 */
429

430
static int do_output_char(unsigned char c, struct tty_struct *tty, int space)
L
Linus Torvalds 已提交
431
{
432
	struct n_tty_data *ldata = tty->disc_data;
433
	int	spaces;
L
Linus Torvalds 已提交
434 435 436

	if (!space)
		return -1;
A
Alan Cox 已提交
437

438 439 440
	switch (c) {
	case '\n':
		if (O_ONLRET(tty))
441
			ldata->column = 0;
442 443 444
		if (O_ONLCR(tty)) {
			if (space < 2)
				return -1;
445
			ldata->canon_column = ldata->column = 0;
446
			tty->ops->write(tty, "\r\n", 2);
447 448
			return 2;
		}
449
		ldata->canon_column = ldata->column;
450 451
		break;
	case '\r':
452
		if (O_ONOCR(tty) && ldata->column == 0)
453 454 455 456
			return 0;
		if (O_OCRNL(tty)) {
			c = '\n';
			if (O_ONLRET(tty))
457
				ldata->canon_column = ldata->column = 0;
L
Linus Torvalds 已提交
458
			break;
459
		}
460
		ldata->canon_column = ldata->column = 0;
461 462
		break;
	case '\t':
463
		spaces = 8 - (ldata->column & 7);
464 465 466
		if (O_TABDLY(tty) == XTABS) {
			if (space < spaces)
				return -1;
467
			ldata->column += spaces;
468 469
			tty->ops->write(tty, "        ", spaces);
			return spaces;
L
Linus Torvalds 已提交
470
		}
471
		ldata->column += spaces;
472 473
		break;
	case '\b':
474 475
		if (ldata->column > 0)
			ldata->column--;
476 477
		break;
	default:
478 479 480 481
		if (!iscntrl(c)) {
			if (O_OLCUC(tty))
				c = toupper(c);
			if (!is_continuation(c, tty))
482
				ldata->column++;
483
		}
484
		break;
L
Linus Torvalds 已提交
485
	}
486

A
Alan Cox 已提交
487
	tty_put_char(tty, c);
488 489 490 491 492 493 494 495
	return 1;
}

/**
 *	process_output			-	output post processor
 *	@c: character (or partial unicode symbol)
 *	@tty: terminal device
 *
496 497 498
 *	Output one character with OPOST processing.
 *	Returns -1 when the output device is full and the character
 *	must be retried.
499 500 501 502 503 504 505 506
 *
 *	Locking: output_lock to protect column state and space left
 *		 (also, this is called from n_tty_write under the
 *		  tty layer write lock)
 */

static int process_output(unsigned char c, struct tty_struct *tty)
{
507
	struct n_tty_data *ldata = tty->disc_data;
508 509
	int	space, retval;

510
	mutex_lock(&ldata->output_lock);
511 512 513 514

	space = tty_write_room(tty);
	retval = do_output_char(c, tty, space);

515
	mutex_unlock(&ldata->output_lock);
516 517 518 519
	if (retval < 0)
		return -1;
	else
		return 0;
L
Linus Torvalds 已提交
520 521 522
}

/**
523
 *	process_output_block		-	block post processor
L
Linus Torvalds 已提交
524
 *	@tty: terminal device
525 526 527 528 529
 *	@buf: character buffer
 *	@nr: number of bytes to output
 *
 *	Output a block of characters with OPOST processing.
 *	Returns the number of characters output.
L
Linus Torvalds 已提交
530 531 532 533 534 535
 *
 *	This path is used to speed up block console writes, among other
 *	things when processing blocks of output data. It handles only
 *	the simple cases normally found and helps to generate blocks of
 *	symbols for the console driver and thus improve performance.
 *
536 537 538
 *	Locking: output_lock to protect column state and space left
 *		 (also, this is called from n_tty_write under the
 *		  tty layer write lock)
L
Linus Torvalds 已提交
539
 */
540

541 542
static ssize_t process_output_block(struct tty_struct *tty,
				    const unsigned char *buf, unsigned int nr)
L
Linus Torvalds 已提交
543
{
544
	struct n_tty_data *ldata = tty->disc_data;
L
Linus Torvalds 已提交
545
	int	space;
546
	int	i;
L
Linus Torvalds 已提交
547 548
	const unsigned char *cp;

549
	mutex_lock(&ldata->output_lock);
550

A
Alan Cox 已提交
551
	space = tty_write_room(tty);
A
Alan Cox 已提交
552
	if (!space) {
553
		mutex_unlock(&ldata->output_lock);
L
Linus Torvalds 已提交
554
		return 0;
555
	}
L
Linus Torvalds 已提交
556 557 558 559
	if (nr > space)
		nr = space;

	for (i = 0, cp = buf; i < nr; i++, cp++) {
560 561 562
		unsigned char c = *cp;

		switch (c) {
L
Linus Torvalds 已提交
563 564
		case '\n':
			if (O_ONLRET(tty))
565
				ldata->column = 0;
L
Linus Torvalds 已提交
566 567
			if (O_ONLCR(tty))
				goto break_out;
568
			ldata->canon_column = ldata->column;
L
Linus Torvalds 已提交
569 570
			break;
		case '\r':
571
			if (O_ONOCR(tty) && ldata->column == 0)
L
Linus Torvalds 已提交
572 573 574
				goto break_out;
			if (O_OCRNL(tty))
				goto break_out;
575
			ldata->canon_column = ldata->column = 0;
L
Linus Torvalds 已提交
576 577 578 579
			break;
		case '\t':
			goto break_out;
		case '\b':
580 581
			if (ldata->column > 0)
				ldata->column--;
L
Linus Torvalds 已提交
582 583
			break;
		default:
584 585 586 587
			if (!iscntrl(c)) {
				if (O_OLCUC(tty))
					goto break_out;
				if (!is_continuation(c, tty))
588
					ldata->column++;
589
			}
L
Linus Torvalds 已提交
590 591 592 593
			break;
		}
	}
break_out:
A
Alan Cox 已提交
594
	i = tty->ops->write(tty, buf, i);
595

596
	mutex_unlock(&ldata->output_lock);
L
Linus Torvalds 已提交
597 598 599
	return i;
}

600 601 602 603 604 605 606 607 608 609 610 611 612 613 614 615 616 617 618 619 620 621 622 623 624 625 626 627
/**
 *	process_echoes	-	write pending echo characters
 *	@tty: terminal device
 *
 *	Write previously buffered echo (and other ldisc-generated)
 *	characters to the tty.
 *
 *	Characters generated by the ldisc (including echoes) need to
 *	be buffered because the driver's write buffer can fill during
 *	heavy program output.  Echoing straight to the driver will
 *	often fail under these conditions, causing lost characters and
 *	resulting mismatches of ldisc state information.
 *
 *	Since the ldisc state must represent the characters actually sent
 *	to the driver at the time of the write, operations like certain
 *	changes in column state are also saved in the buffer and executed
 *	here.
 *
 *	A circular fifo buffer is used so that the most recent characters
 *	are prioritized.  Also, when control characters are echoed with a
 *	prefixed "^", the pair is treated atomically and thus not separated.
 *
 *	Locking: output_lock to protect column state and space left,
 *		 echo_lock to protect the echo buffer
 */

static void process_echoes(struct tty_struct *tty)
{
628
	struct n_tty_data *ldata = tty->disc_data;
629 630 631 632
	int	space, nr;
	unsigned char c;
	unsigned char *cp, *buf_end;

633
	if (!ldata->echo_cnt)
634 635
		return;

636 637
	mutex_lock(&ldata->output_lock);
	mutex_lock(&ldata->echo_lock);
638 639 640

	space = tty_write_room(tty);

641 642 643
	buf_end = ldata->echo_buf + N_TTY_BUF_SIZE;
	cp = ldata->echo_buf + ldata->echo_pos;
	nr = ldata->echo_cnt;
644 645 646 647 648 649 650 651 652 653 654 655 656 657 658 659
	while (nr > 0) {
		c = *cp;
		if (c == ECHO_OP_START) {
			unsigned char op;
			unsigned char *opp;
			int no_space_left = 0;

			/*
			 * If the buffer byte is the start of a multi-byte
			 * operation, get the next byte, which is either the
			 * op code or a control character value.
			 */
			opp = cp + 1;
			if (opp == buf_end)
				opp -= N_TTY_BUF_SIZE;
			op = *opp;
A
Alan Cox 已提交
660

661 662 663 664 665 666 667 668 669 670 671 672 673 674 675 676 677 678 679
			switch (op) {
				unsigned int num_chars, num_bs;

			case ECHO_OP_ERASE_TAB:
				if (++opp == buf_end)
					opp -= N_TTY_BUF_SIZE;
				num_chars = *opp;

				/*
				 * Determine how many columns to go back
				 * in order to erase the tab.
				 * This depends on the number of columns
				 * used by other characters within the tab
				 * area.  If this (modulo 8) count is from
				 * the start of input rather than from a
				 * previous tab, we offset by canon column.
				 * Otherwise, tab spacing is normal.
				 */
				if (!(num_chars & 0x80))
680
					num_chars += ldata->canon_column;
681 682 683 684 685 686 687 688 689
				num_bs = 8 - (num_chars & 7);

				if (num_bs > space) {
					no_space_left = 1;
					break;
				}
				space -= num_bs;
				while (num_bs--) {
					tty_put_char(tty, '\b');
690 691
					if (ldata->column > 0)
						ldata->column--;
692 693 694 695 696 697
				}
				cp += 3;
				nr -= 3;
				break;

			case ECHO_OP_SET_CANON_COL:
698
				ldata->canon_column = ldata->column;
699 700 701 702 703
				cp += 2;
				nr -= 2;
				break;

			case ECHO_OP_MOVE_BACK_COL:
704 705
				if (ldata->column > 0)
					ldata->column--;
706 707 708 709 710 711 712 713 714 715 716
				cp += 2;
				nr -= 2;
				break;

			case ECHO_OP_START:
				/* This is an escaped echo op start code */
				if (!space) {
					no_space_left = 1;
					break;
				}
				tty_put_char(tty, ECHO_OP_START);
717
				ldata->column++;
718 719 720 721 722 723 724
				space--;
				cp += 2;
				nr -= 2;
				break;

			default:
				/*
725 726 727 728 729 730 731
				 * If the op is not a special byte code,
				 * it is a ctrl char tagged to be echoed
				 * as "^X" (where X is the letter
				 * representing the control char).
				 * Note that we must ensure there is
				 * enough space for the whole ctrl pair.
				 *
732
				 */
733 734 735 736 737 738
				if (space < 2) {
					no_space_left = 1;
					break;
				}
				tty_put_char(tty, '^');
				tty_put_char(tty, op ^ 0100);
739
				ldata->column += 2;
740
				space -= 2;
741 742 743 744 745 746 747
				cp += 2;
				nr -= 2;
			}

			if (no_space_left)
				break;
		} else {
P
Peter Hurley 已提交
748
			if (O_OPOST(tty)) {
749 750 751 752 753 754 755 756 757 758
				int retval = do_output_char(c, tty, space);
				if (retval < 0)
					break;
				space -= retval;
			} else {
				if (!space)
					break;
				tty_put_char(tty, c);
				space -= 1;
			}
759 760 761 762 763 764 765 766 767 768
			cp += 1;
			nr -= 1;
		}

		/* When end of circular buffer reached, wrap around */
		if (cp >= buf_end)
			cp -= N_TTY_BUF_SIZE;
	}

	if (nr == 0) {
769 770
		ldata->echo_pos = 0;
		ldata->echo_cnt = 0;
771
		ldata->echo_overrun = 0;
772
	} else {
773 774 775 776
		int num_processed = ldata->echo_cnt - nr;
		ldata->echo_pos += num_processed;
		ldata->echo_pos &= N_TTY_BUF_SIZE - 1;
		ldata->echo_cnt = nr;
777
		if (num_processed > 0)
778
			ldata->echo_overrun = 0;
779 780
	}

781 782
	mutex_unlock(&ldata->echo_lock);
	mutex_unlock(&ldata->output_lock);
783 784 785 786 787 788 789 790

	if (tty->ops->flush_chars)
		tty->ops->flush_chars(tty);
}

/**
 *	add_echo_byte	-	add a byte to the echo buffer
 *	@c: unicode byte to echo
J
Jiri Slaby 已提交
791
 *	@ldata: n_tty data
792 793 794 795 796 797
 *
 *	Add a character or operation byte to the echo buffer.
 *
 *	Should be called under the echo lock to protect the echo buffer.
 */

J
Jiri Slaby 已提交
798
static void add_echo_byte(unsigned char c, struct n_tty_data *ldata)
799 800 801
{
	int	new_byte_pos;

802
	if (ldata->echo_cnt == N_TTY_BUF_SIZE) {
803
		/* Circular buffer is already at capacity */
804
		new_byte_pos = ldata->echo_pos;
805 806 807 808 809

		/*
		 * Since the buffer start position needs to be advanced,
		 * be sure to step by a whole operation byte group.
		 */
810 811
		if (ldata->echo_buf[ldata->echo_pos] == ECHO_OP_START) {
			if (ldata->echo_buf[(ldata->echo_pos + 1) &
812 813
					  (N_TTY_BUF_SIZE - 1)] ==
						ECHO_OP_ERASE_TAB) {
814 815
				ldata->echo_pos += 3;
				ldata->echo_cnt -= 2;
816
			} else {
817 818
				ldata->echo_pos += 2;
				ldata->echo_cnt -= 1;
819 820
			}
		} else {
821
			ldata->echo_pos++;
822
		}
823
		ldata->echo_pos &= N_TTY_BUF_SIZE - 1;
824

825
		ldata->echo_overrun = 1;
826
	} else {
827
		new_byte_pos = ldata->echo_pos + ldata->echo_cnt;
828
		new_byte_pos &= N_TTY_BUF_SIZE - 1;
829
		ldata->echo_cnt++;
830 831
	}

832
	ldata->echo_buf[new_byte_pos] = c;
833 834 835 836
}

/**
 *	echo_move_back_col	-	add operation to move back a column
J
Jiri Slaby 已提交
837
 *	@ldata: n_tty data
838 839 840 841 842 843
 *
 *	Add an operation to the echo buffer to move back one column.
 *
 *	Locking: echo_lock to protect the echo buffer
 */

J
Jiri Slaby 已提交
844
static void echo_move_back_col(struct n_tty_data *ldata)
845
{
846
	mutex_lock(&ldata->echo_lock);
J
Jiri Slaby 已提交
847 848
	add_echo_byte(ECHO_OP_START, ldata);
	add_echo_byte(ECHO_OP_MOVE_BACK_COL, ldata);
849
	mutex_unlock(&ldata->echo_lock);
850 851 852 853
}

/**
 *	echo_set_canon_col	-	add operation to set the canon column
J
Jiri Slaby 已提交
854
 *	@ldata: n_tty data
855 856 857 858 859 860 861
 *
 *	Add an operation to the echo buffer to set the canon column
 *	to the current column.
 *
 *	Locking: echo_lock to protect the echo buffer
 */

J
Jiri Slaby 已提交
862
static void echo_set_canon_col(struct n_tty_data *ldata)
863
{
864
	mutex_lock(&ldata->echo_lock);
J
Jiri Slaby 已提交
865 866
	add_echo_byte(ECHO_OP_START, ldata);
	add_echo_byte(ECHO_OP_SET_CANON_COL, ldata);
867
	mutex_unlock(&ldata->echo_lock);
868 869 870 871 872 873
}

/**
 *	echo_erase_tab	-	add operation to erase a tab
 *	@num_chars: number of character columns already used
 *	@after_tab: true if num_chars starts after a previous tab
J
Jiri Slaby 已提交
874
 *	@ldata: n_tty data
875 876 877 878 879 880 881 882 883 884 885 886 887
 *
 *	Add an operation to the echo buffer to erase a tab.
 *
 *	Called by the eraser function, which knows how many character
 *	columns have been used since either a previous tab or the start
 *	of input.  This information will be used later, along with
 *	canon column (if applicable), to go back the correct number
 *	of columns.
 *
 *	Locking: echo_lock to protect the echo buffer
 */

static void echo_erase_tab(unsigned int num_chars, int after_tab,
J
Jiri Slaby 已提交
888
			   struct n_tty_data *ldata)
889
{
890
	mutex_lock(&ldata->echo_lock);
891

J
Jiri Slaby 已提交
892 893
	add_echo_byte(ECHO_OP_START, ldata);
	add_echo_byte(ECHO_OP_ERASE_TAB, ldata);
894 895 896 897 898 899 900

	/* We only need to know this modulo 8 (tab spacing) */
	num_chars &= 7;

	/* Set the high bit as a flag if num_chars is after a previous tab */
	if (after_tab)
		num_chars |= 0x80;
A
Alan Cox 已提交
901

J
Jiri Slaby 已提交
902
	add_echo_byte(num_chars, ldata);
903

904
	mutex_unlock(&ldata->echo_lock);
905 906 907 908 909 910 911 912 913 914 915 916 917 918 919
}

/**
 *	echo_char_raw	-	echo a character raw
 *	@c: unicode byte to echo
 *	@tty: terminal device
 *
 *	Echo user input back onto the screen. This must be called only when
 *	L_ECHO(tty) is true. Called from the driver receive_buf path.
 *
 *	This variant does not treat control characters specially.
 *
 *	Locking: echo_lock to protect the echo buffer
 */

J
Jiri Slaby 已提交
920
static void echo_char_raw(unsigned char c, struct n_tty_data *ldata)
921
{
922
	mutex_lock(&ldata->echo_lock);
923
	if (c == ECHO_OP_START) {
J
Jiri Slaby 已提交
924 925
		add_echo_byte(ECHO_OP_START, ldata);
		add_echo_byte(ECHO_OP_START, ldata);
926
	} else {
J
Jiri Slaby 已提交
927
		add_echo_byte(c, ldata);
928
	}
929
	mutex_unlock(&ldata->echo_lock);
930
}
L
Linus Torvalds 已提交
931 932

/**
933
 *	echo_char	-	echo a character
L
Linus Torvalds 已提交
934 935 936
 *	@c: unicode byte to echo
 *	@tty: terminal device
 *
937
 *	Echo user input back onto the screen. This must be called only when
L
Linus Torvalds 已提交
938
 *	L_ECHO(tty) is true. Called from the driver receive_buf path.
939
 *
940 941
 *	This variant tags control characters to be echoed as "^X"
 *	(where X is the letter representing the control char).
942 943
 *
 *	Locking: echo_lock to protect the echo buffer
L
Linus Torvalds 已提交
944 945 946 947
 */

static void echo_char(unsigned char c, struct tty_struct *tty)
{
948 949 950
	struct n_tty_data *ldata = tty->disc_data;

	mutex_lock(&ldata->echo_lock);
951 952

	if (c == ECHO_OP_START) {
J
Jiri Slaby 已提交
953 954
		add_echo_byte(ECHO_OP_START, ldata);
		add_echo_byte(ECHO_OP_START, ldata);
955
	} else {
956
		if (L_ECHOCTL(tty) && iscntrl(c) && c != '\t')
J
Jiri Slaby 已提交
957 958
			add_echo_byte(ECHO_OP_START, ldata);
		add_echo_byte(c, ldata);
959 960
	}

961
	mutex_unlock(&ldata->echo_lock);
L
Linus Torvalds 已提交
962 963
}

964
/**
965
 *	finish_erasing		-	complete erase
J
Jiri Slaby 已提交
966
 *	@ldata: n_tty data
967
 */
968

J
Jiri Slaby 已提交
969
static inline void finish_erasing(struct n_tty_data *ldata)
L
Linus Torvalds 已提交
970
{
971
	if (ldata->erasing) {
J
Jiri Slaby 已提交
972
		echo_char_raw('/', ldata);
973
		ldata->erasing = 0;
L
Linus Torvalds 已提交
974 975 976 977 978 979 980 981
	}
}

/**
 *	eraser		-	handle erase function
 *	@c: character input
 *	@tty: terminal device
 *
982
 *	Perform erase and necessary output when an erase character is
L
Linus Torvalds 已提交
983 984
 *	present in the stream from the driver layer. Handles the complexities
 *	of UTF-8 multibyte symbols.
985
 *
986 987 988 989 990 991
 *	n_tty_receive_buf()/producer path:
 *		caller holds non-exclusive termios_rwsem
 *		modifies read_head
 *
 *	Modifying the read_head is not considered a publish in this context
 *	because canonical mode is active -- only canon_head publishes
L
Linus Torvalds 已提交
992
 */
993

L
Linus Torvalds 已提交
994 995
static void eraser(unsigned char c, struct tty_struct *tty)
{
996
	struct n_tty_data *ldata = tty->disc_data;
L
Linus Torvalds 已提交
997
	enum { ERASE, WERASE, KILL } kill_type;
998 999 1000
	size_t head;
	size_t cnt;
	int seen_alnums;
L
Linus Torvalds 已提交
1001

1002
	if (ldata->read_head == ldata->canon_head) {
1003
		/* process_output('\a', tty); */ /* what do you think? */
L
Linus Torvalds 已提交
1004 1005 1006 1007 1008 1009 1010 1011
		return;
	}
	if (c == ERASE_CHAR(tty))
		kill_type = ERASE;
	else if (c == WERASE_CHAR(tty))
		kill_type = WERASE;
	else {
		if (!L_ECHO(tty)) {
1012
			ldata->read_head = ldata->canon_head;
L
Linus Torvalds 已提交
1013 1014 1015
			return;
		}
		if (!L_ECHOK(tty) || !L_ECHOKE(tty) || !L_ECHOE(tty)) {
1016
			ldata->read_head = ldata->canon_head;
J
Jiri Slaby 已提交
1017
			finish_erasing(ldata);
L
Linus Torvalds 已提交
1018 1019 1020
			echo_char(KILL_CHAR(tty), tty);
			/* Add a newline if ECHOK is on and ECHOKE is off. */
			if (L_ECHOK(tty))
J
Jiri Slaby 已提交
1021
				echo_char_raw('\n', ldata);
L
Linus Torvalds 已提交
1022 1023 1024 1025 1026 1027
			return;
		}
		kill_type = KILL;
	}

	seen_alnums = 0;
1028 1029
	while (ldata->read_head != ldata->canon_head) {
		head = ldata->read_head;
L
Linus Torvalds 已提交
1030 1031 1032

		/* erase a single possibly multibyte character */
		do {
1033 1034
			head--;
			c = read_buf(ldata, head);
1035
		} while (is_continuation(c, tty) && head != ldata->canon_head);
L
Linus Torvalds 已提交
1036 1037 1038 1039 1040 1041 1042 1043 1044 1045 1046 1047

		/* do not partially erase */
		if (is_continuation(c, tty))
			break;

		if (kill_type == WERASE) {
			/* Equivalent to BSD's ALTWERASE. */
			if (isalnum(c) || c == '_')
				seen_alnums++;
			else if (seen_alnums)
				break;
		}
1048
		cnt = ldata->read_head - head;
1049
		ldata->read_head = head;
L
Linus Torvalds 已提交
1050 1051
		if (L_ECHO(tty)) {
			if (L_ECHOPRT(tty)) {
1052
				if (!ldata->erasing) {
J
Jiri Slaby 已提交
1053
					echo_char_raw('\\', ldata);
1054
					ldata->erasing = 1;
L
Linus Torvalds 已提交
1055 1056 1057 1058
				}
				/* if cnt > 1, output a multi-byte character */
				echo_char(c, tty);
				while (--cnt > 0) {
1059 1060
					head++;
					echo_char_raw(read_buf(ldata, head), ldata);
J
Jiri Slaby 已提交
1061
					echo_move_back_col(ldata);
L
Linus Torvalds 已提交
1062 1063 1064 1065
				}
			} else if (kill_type == ERASE && !L_ECHOE(tty)) {
				echo_char(ERASE_CHAR(tty), tty);
			} else if (c == '\t') {
1066 1067
				unsigned int num_chars = 0;
				int after_tab = 0;
1068
				size_t tail = ldata->read_head;
1069 1070 1071 1072 1073 1074 1075 1076

				/*
				 * Count the columns used for characters
				 * since the start of input or after a
				 * previous tab.
				 * This info is used to go back the correct
				 * number of columns.
				 */
1077
				while (tail != ldata->canon_head) {
1078 1079
					tail--;
					c = read_buf(ldata, tail);
1080 1081 1082
					if (c == '\t') {
						after_tab = 1;
						break;
A
Alan Cox 已提交
1083
					} else if (iscntrl(c)) {
L
Linus Torvalds 已提交
1084
						if (L_ECHOCTL(tty))
1085 1086 1087 1088
							num_chars += 2;
					} else if (!is_continuation(c, tty)) {
						num_chars++;
					}
L
Linus Torvalds 已提交
1089
				}
J
Jiri Slaby 已提交
1090
				echo_erase_tab(num_chars, after_tab, ldata);
L
Linus Torvalds 已提交
1091 1092
			} else {
				if (iscntrl(c) && L_ECHOCTL(tty)) {
J
Jiri Slaby 已提交
1093 1094 1095
					echo_char_raw('\b', ldata);
					echo_char_raw(' ', ldata);
					echo_char_raw('\b', ldata);
L
Linus Torvalds 已提交
1096 1097
				}
				if (!iscntrl(c) || L_ECHOCTL(tty)) {
J
Jiri Slaby 已提交
1098 1099 1100
					echo_char_raw('\b', ldata);
					echo_char_raw(' ', ldata);
					echo_char_raw('\b', ldata);
L
Linus Torvalds 已提交
1101 1102 1103 1104 1105 1106
				}
			}
		}
		if (kill_type == ERASE)
			break;
	}
1107
	if (ldata->read_head == ldata->canon_head && L_ECHO(tty))
J
Jiri Slaby 已提交
1108
		finish_erasing(ldata);
L
Linus Torvalds 已提交
1109 1110 1111 1112 1113 1114 1115
}

/**
 *	isig		-	handle the ISIG optio
 *	@sig: signal
 *	@tty: terminal
 *
1116 1117
 *	Called when a signal is being sent due to terminal input.
 *	Called from the driver receive_buf path so serialized.
1118
 *
1119
 *	Locking: ctrl_lock
L
Linus Torvalds 已提交
1120
 */
1121

1122
static inline void isig(int sig, struct tty_struct *tty)
L
Linus Torvalds 已提交
1123
{
1124 1125 1126 1127
	struct pid *tty_pgrp = tty_get_pgrp(tty);
	if (tty_pgrp) {
		kill_pgrp(tty_pgrp, sig, 1);
		put_pid(tty_pgrp);
L
Linus Torvalds 已提交
1128 1129 1130 1131 1132 1133 1134 1135 1136 1137
	}
}

/**
 *	n_tty_receive_break	-	handle break
 *	@tty: terminal
 *
 *	An RS232 break event has been hit in the incoming bitstream. This
 *	can cause a variety of events depending upon the termios settings.
 *
1138 1139 1140 1141 1142
 *	n_tty_receive_buf()/producer path:
 *		caller holds non-exclusive termios_rwsem
 *		publishes read_head via put_tty_queue()
 *
 *	Note: may get exclusive termios_rwsem if flushing input buffer
L
Linus Torvalds 已提交
1143
 */
1144

L
Linus Torvalds 已提交
1145 1146
static inline void n_tty_receive_break(struct tty_struct *tty)
{
J
Jiri Slaby 已提交
1147 1148
	struct n_tty_data *ldata = tty->disc_data;

L
Linus Torvalds 已提交
1149 1150 1151
	if (I_IGNBRK(tty))
		return;
	if (I_BRKINT(tty)) {
1152 1153
		isig(SIGINT, tty);
		if (!L_NOFLSH(tty)) {
1154 1155
			/* flushing needs exclusive termios_rwsem */
			up_read(&tty->termios_rwsem);
1156 1157
			n_tty_flush_buffer(tty);
			tty_driver_flush_buffer(tty);
1158
			down_read(&tty->termios_rwsem);
1159
		}
L
Linus Torvalds 已提交
1160 1161 1162
		return;
	}
	if (I_PARMRK(tty)) {
J
Jiri Slaby 已提交
1163 1164
		put_tty_queue('\377', ldata);
		put_tty_queue('\0', ldata);
L
Linus Torvalds 已提交
1165
	}
J
Jiri Slaby 已提交
1166
	put_tty_queue('\0', ldata);
L
Linus Torvalds 已提交
1167 1168 1169 1170 1171 1172 1173 1174 1175 1176 1177 1178 1179 1180 1181
	wake_up_interruptible(&tty->read_wait);
}

/**
 *	n_tty_receive_overrun	-	handle overrun reporting
 *	@tty: terminal
 *
 *	Data arrived faster than we could process it. While the tty
 *	driver has flagged this the bits that were missed are gone
 *	forever.
 *
 *	Called from the receive_buf path so single threaded. Does not
 *	need locking as num_overrun and overrun_time are function
 *	private.
 */
1182

L
Linus Torvalds 已提交
1183 1184
static inline void n_tty_receive_overrun(struct tty_struct *tty)
{
1185
	struct n_tty_data *ldata = tty->disc_data;
L
Linus Torvalds 已提交
1186 1187
	char buf[64];

1188 1189 1190
	ldata->num_overrun++;
	if (time_after(jiffies, ldata->overrun_time + HZ) ||
			time_after(ldata->overrun_time, jiffies)) {
L
Linus Torvalds 已提交
1191 1192
		printk(KERN_WARNING "%s: %d input overrun(s)\n",
			tty_name(tty, buf),
1193 1194 1195
			ldata->num_overrun);
		ldata->overrun_time = jiffies;
		ldata->num_overrun = 0;
L
Linus Torvalds 已提交
1196 1197 1198 1199 1200 1201 1202 1203 1204
	}
}

/**
 *	n_tty_receive_parity_error	-	error notifier
 *	@tty: terminal device
 *	@c: character
 *
 *	Process a parity error and queue the right data to indicate
1205 1206 1207 1208 1209
 *	the error case if necessary.
 *
 *	n_tty_receive_buf()/producer path:
 *		caller holds non-exclusive termios_rwsem
 *		publishes read_head via put_tty_queue()
L
Linus Torvalds 已提交
1210 1211 1212 1213
 */
static inline void n_tty_receive_parity_error(struct tty_struct *tty,
					      unsigned char c)
{
J
Jiri Slaby 已提交
1214 1215
	struct n_tty_data *ldata = tty->disc_data;

1216
	if (I_IGNPAR(tty))
L
Linus Torvalds 已提交
1217 1218
		return;
	if (I_PARMRK(tty)) {
J
Jiri Slaby 已提交
1219 1220 1221
		put_tty_queue('\377', ldata);
		put_tty_queue('\0', ldata);
		put_tty_queue(c, ldata);
L
Linus Torvalds 已提交
1222
	} else	if (I_INPCK(tty))
J
Jiri Slaby 已提交
1223
		put_tty_queue('\0', ldata);
L
Linus Torvalds 已提交
1224
	else
J
Jiri Slaby 已提交
1225
		put_tty_queue(c, ldata);
L
Linus Torvalds 已提交
1226 1227 1228 1229 1230 1231 1232 1233 1234
	wake_up_interruptible(&tty->read_wait);
}

/**
 *	n_tty_receive_char	-	perform processing
 *	@tty: terminal device
 *	@c: character
 *
 *	Process an individual character of input received from the driver.
1235
 *	This is serialized with respect to itself by the rules for the
L
Linus Torvalds 已提交
1236
 *	driver above.
1237 1238 1239 1240 1241
 *
 *	n_tty_receive_buf()/producer path:
 *		caller holds non-exclusive termios_rwsem
 *		publishes canon_head if canonical mode is active
 *		otherwise, publishes read_head via put_tty_queue()
L
Linus Torvalds 已提交
1242 1243 1244 1245
 */

static inline void n_tty_receive_char(struct tty_struct *tty, unsigned char c)
{
1246
	struct n_tty_data *ldata = tty->disc_data;
1247
	int parmrk;
L
Linus Torvalds 已提交
1248

1249
	if (ldata->raw) {
J
Jiri Slaby 已提交
1250
		put_tty_queue(c, ldata);
L
Linus Torvalds 已提交
1251 1252
		return;
	}
1253

L
Linus Torvalds 已提交
1254 1255 1256
	if (I_ISTRIP(tty))
		c &= 0x7f;
	if (I_IUCLC(tty) && L_IEXTEN(tty))
A
Alan Cox 已提交
1257
		c = tolower(c);
L
Linus Torvalds 已提交
1258

1259
	if (L_EXTPROC(tty)) {
J
Jiri Slaby 已提交
1260
		put_tty_queue(c, ldata);
1261 1262 1263
		return;
	}

1264
	if (tty->stopped && !tty->flow_stopped && I_IXON(tty) &&
1265 1266
	    I_IXANY(tty) && c != START_CHAR(tty) && c != STOP_CHAR(tty) &&
	    c != INTR_CHAR(tty) && c != QUIT_CHAR(tty) && c != SUSP_CHAR(tty)) {
1267
		start_tty(tty);
1268 1269
		process_echoes(tty);
	}
1270

L
Linus Torvalds 已提交
1271 1272
	if (tty->closing) {
		if (I_IXON(tty)) {
1273
			if (c == START_CHAR(tty)) {
L
Linus Torvalds 已提交
1274
				start_tty(tty);
1275
				process_echoes(tty);
A
Alan Cox 已提交
1276
			} else if (c == STOP_CHAR(tty))
L
Linus Torvalds 已提交
1277 1278 1279 1280 1281 1282 1283 1284 1285 1286 1287
				stop_tty(tty);
		}
		return;
	}

	/*
	 * If the previous character was LNEXT, or we know that this
	 * character is not one of the characters that we'll have to
	 * handle specially, do shortcut processing to speed things
	 * up.
	 */
1288
	if (!test_bit(c, ldata->process_char_map) || ldata->lnext) {
1289
		ldata->lnext = 0;
1290
		parmrk = (c == (unsigned char) '\377' && I_PARMRK(tty)) ? 1 : 0;
1291
		if (read_cnt(ldata) >= (N_TTY_BUF_SIZE - parmrk - 1)) {
1292
			/* beep if no space */
1293 1294
			if (L_ECHO(tty))
				process_output('\a', tty);
1295 1296 1297
			return;
		}
		if (L_ECHO(tty)) {
J
Jiri Slaby 已提交
1298
			finish_erasing(ldata);
L
Linus Torvalds 已提交
1299
			/* Record the column of first canon char. */
1300
			if (ldata->canon_head == ldata->read_head)
J
Jiri Slaby 已提交
1301
				echo_set_canon_col(ldata);
L
Linus Torvalds 已提交
1302
			echo_char(c, tty);
1303
			process_echoes(tty);
L
Linus Torvalds 已提交
1304
		}
1305
		if (parmrk)
J
Jiri Slaby 已提交
1306 1307
			put_tty_queue(c, ldata);
		put_tty_queue(c, ldata);
L
Linus Torvalds 已提交
1308 1309
		return;
	}
1310

L
Linus Torvalds 已提交
1311 1312 1313
	if (I_IXON(tty)) {
		if (c == START_CHAR(tty)) {
			start_tty(tty);
1314
			process_echoes(tty);
L
Linus Torvalds 已提交
1315 1316 1317 1318 1319 1320 1321
			return;
		}
		if (c == STOP_CHAR(tty)) {
			stop_tty(tty);
			return;
		}
	}
1322

L
Linus Torvalds 已提交
1323 1324 1325 1326 1327 1328 1329 1330 1331 1332 1333
	if (L_ISIG(tty)) {
		int signal;
		signal = SIGINT;
		if (c == INTR_CHAR(tty))
			goto send_signal;
		signal = SIGQUIT;
		if (c == QUIT_CHAR(tty))
			goto send_signal;
		signal = SIGTSTP;
		if (c == SUSP_CHAR(tty)) {
send_signal:
1334
			if (!L_NOFLSH(tty)) {
1335 1336
				/* flushing needs exclusive termios_rwsem */
				up_read(&tty->termios_rwsem);
1337
				n_tty_flush_buffer(tty);
A
Alan Cox 已提交
1338
				tty_driver_flush_buffer(tty);
1339
				down_read(&tty->termios_rwsem);
1340
			}
1341 1342 1343
			if (I_IXON(tty))
				start_tty(tty);
			if (L_ECHO(tty)) {
1344
				echo_char(c, tty);
1345 1346
				process_echoes(tty);
			}
1347
			isig(signal, tty);
L
Linus Torvalds 已提交
1348 1349 1350
			return;
		}
	}
1351 1352 1353 1354 1355 1356 1357 1358 1359

	if (c == '\r') {
		if (I_IGNCR(tty))
			return;
		if (I_ICRNL(tty))
			c = '\n';
	} else if (c == '\n' && I_INLCR(tty))
		c = '\r';

1360
	if (ldata->icanon) {
L
Linus Torvalds 已提交
1361 1362 1363
		if (c == ERASE_CHAR(tty) || c == KILL_CHAR(tty) ||
		    (c == WERASE_CHAR(tty) && L_IEXTEN(tty))) {
			eraser(c, tty);
1364
			process_echoes(tty);
L
Linus Torvalds 已提交
1365 1366 1367
			return;
		}
		if (c == LNEXT_CHAR(tty) && L_IEXTEN(tty)) {
1368
			ldata->lnext = 1;
L
Linus Torvalds 已提交
1369
			if (L_ECHO(tty)) {
J
Jiri Slaby 已提交
1370
				finish_erasing(ldata);
L
Linus Torvalds 已提交
1371
				if (L_ECHOCTL(tty)) {
J
Jiri Slaby 已提交
1372 1373
					echo_char_raw('^', ldata);
					echo_char_raw('\b', ldata);
1374
					process_echoes(tty);
L
Linus Torvalds 已提交
1375 1376 1377 1378 1379 1380
				}
			}
			return;
		}
		if (c == REPRINT_CHAR(tty) && L_ECHO(tty) &&
		    L_IEXTEN(tty)) {
1381
			size_t tail = ldata->canon_head;
L
Linus Torvalds 已提交
1382

J
Jiri Slaby 已提交
1383
			finish_erasing(ldata);
L
Linus Torvalds 已提交
1384
			echo_char(c, tty);
J
Jiri Slaby 已提交
1385
			echo_char_raw('\n', ldata);
1386
			while (tail != ldata->read_head) {
1387 1388
				echo_char(read_buf(ldata, tail), tty);
				tail++;
L
Linus Torvalds 已提交
1389
			}
1390
			process_echoes(tty);
L
Linus Torvalds 已提交
1391 1392 1393
			return;
		}
		if (c == '\n') {
1394
			if (read_cnt(ldata) >= N_TTY_BUF_SIZE) {
1395 1396
				if (L_ECHO(tty))
					process_output('\a', tty);
1397 1398 1399
				return;
			}
			if (L_ECHO(tty) || L_ECHONL(tty)) {
J
Jiri Slaby 已提交
1400
				echo_char_raw('\n', ldata);
1401
				process_echoes(tty);
L
Linus Torvalds 已提交
1402 1403 1404 1405
			}
			goto handle_newline;
		}
		if (c == EOF_CHAR(tty)) {
1406
			if (read_cnt(ldata) >= N_TTY_BUF_SIZE)
1407
				return;
1408
			if (ldata->canon_head != ldata->read_head)
1409
				set_bit(TTY_PUSH, &tty->flags);
L
Linus Torvalds 已提交
1410 1411 1412 1413 1414
			c = __DISABLED_CHAR;
			goto handle_newline;
		}
		if ((c == EOL_CHAR(tty)) ||
		    (c == EOL2_CHAR(tty) && L_IEXTEN(tty))) {
1415 1416
			parmrk = (c == (unsigned char) '\377' && I_PARMRK(tty))
				 ? 1 : 0;
1417
			if (read_cnt(ldata) >= (N_TTY_BUF_SIZE - parmrk)) {
1418 1419
				if (L_ECHO(tty))
					process_output('\a', tty);
1420 1421
				return;
			}
L
Linus Torvalds 已提交
1422 1423 1424 1425 1426
			/*
			 * XXX are EOL_CHAR and EOL2_CHAR echoed?!?
			 */
			if (L_ECHO(tty)) {
				/* Record the column of first canon char. */
1427
				if (ldata->canon_head == ldata->read_head)
J
Jiri Slaby 已提交
1428
					echo_set_canon_col(ldata);
L
Linus Torvalds 已提交
1429
				echo_char(c, tty);
1430
				process_echoes(tty);
L
Linus Torvalds 已提交
1431 1432 1433 1434 1435
			}
			/*
			 * XXX does PARMRK doubling happen for
			 * EOL_CHAR and EOL2_CHAR?
			 */
1436
			if (parmrk)
J
Jiri Slaby 已提交
1437
				put_tty_queue(c, ldata);
L
Linus Torvalds 已提交
1438

1439
handle_newline:
1440
			set_bit(ldata->read_head & (N_TTY_BUF_SIZE - 1), ldata->read_flags);
1441
			put_tty_queue(c, ldata);
1442
			ldata->canon_head = ldata->read_head;
L
Linus Torvalds 已提交
1443 1444 1445 1446 1447 1448
			kill_fasync(&tty->fasync, SIGIO, POLL_IN);
			if (waitqueue_active(&tty->read_wait))
				wake_up_interruptible(&tty->read_wait);
			return;
		}
	}
1449

1450
	parmrk = (c == (unsigned char) '\377' && I_PARMRK(tty)) ? 1 : 0;
1451
	if (read_cnt(ldata) >= (N_TTY_BUF_SIZE - parmrk - 1)) {
1452
		/* beep if no space */
1453 1454
		if (L_ECHO(tty))
			process_output('\a', tty);
1455 1456 1457
		return;
	}
	if (L_ECHO(tty)) {
J
Jiri Slaby 已提交
1458
		finish_erasing(ldata);
L
Linus Torvalds 已提交
1459
		if (c == '\n')
J
Jiri Slaby 已提交
1460
			echo_char_raw('\n', ldata);
L
Linus Torvalds 已提交
1461 1462
		else {
			/* Record the column of first canon char. */
1463
			if (ldata->canon_head == ldata->read_head)
J
Jiri Slaby 已提交
1464
				echo_set_canon_col(ldata);
L
Linus Torvalds 已提交
1465 1466
			echo_char(c, tty);
		}
1467
		process_echoes(tty);
L
Linus Torvalds 已提交
1468 1469
	}

1470
	if (parmrk)
J
Jiri Slaby 已提交
1471
		put_tty_queue(c, ldata);
L
Linus Torvalds 已提交
1472

J
Jiri Slaby 已提交
1473
	put_tty_queue(c, ldata);
1474
}
L
Linus Torvalds 已提交
1475 1476 1477 1478 1479 1480 1481 1482 1483 1484 1485 1486

/**
 *	n_tty_receive_buf	-	data receive
 *	@tty: terminal device
 *	@cp: buffer
 *	@fp: flag buffer
 *	@count: characters
 *
 *	Called by the terminal driver when a block of characters has
 *	been received. This function must be called from soft contexts
 *	not from interrupt context. The driver is responsible for making
 *	calls one at a time and in order (or using flush_to_ldisc)
1487 1488 1489 1490
 *
 *	n_tty_receive_buf()/producer path:
 *		claims non-exclusive termios_rwsem
 *		publishes read_head and canon_head
L
Linus Torvalds 已提交
1491
 */
1492

1493 1494
static void __receive_buf(struct tty_struct *tty, const unsigned char *cp,
			  char *fp, int count)
L
Linus Torvalds 已提交
1495
{
1496
	struct n_tty_data *ldata = tty->disc_data;
L
Linus Torvalds 已提交
1497 1498 1499 1500
	const unsigned char *p;
	char *f, flags = TTY_NORMAL;
	char	buf[64];

1501
	if (ldata->real_raw) {
1502 1503 1504 1505 1506 1507 1508 1509 1510 1511 1512 1513 1514 1515 1516
		size_t n, head;

		head = ldata->read_head & (N_TTY_BUF_SIZE - 1);
		n = N_TTY_BUF_SIZE - max(read_cnt(ldata), head);
		n = min_t(size_t, count, n);
		memcpy(read_buf_addr(ldata, head), cp, n);
		ldata->read_head += n;
		cp += n;
		count -= n;

		head = ldata->read_head & (N_TTY_BUF_SIZE - 1);
		n = N_TTY_BUF_SIZE - max(read_cnt(ldata), head);
		n = min_t(size_t, count, n);
		memcpy(read_buf_addr(ldata, head), cp, n);
		ldata->read_head += n;
L
Linus Torvalds 已提交
1517
	} else {
1518 1519
		int i;

1520
		for (i = count, p = cp, f = fp; i; i--, p++) {
L
Linus Torvalds 已提交
1521 1522 1523 1524 1525 1526 1527 1528 1529 1530 1531 1532 1533 1534 1535 1536 1537
			if (f)
				flags = *f++;
			switch (flags) {
			case TTY_NORMAL:
				n_tty_receive_char(tty, *p);
				break;
			case TTY_BREAK:
				n_tty_receive_break(tty);
				break;
			case TTY_PARITY:
			case TTY_FRAME:
				n_tty_receive_parity_error(tty, *p);
				break;
			case TTY_OVERRUN:
				n_tty_receive_overrun(tty);
				break;
			default:
1538
				printk(KERN_ERR "%s: unknown flag %d\n",
L
Linus Torvalds 已提交
1539 1540 1541 1542
				       tty_name(tty, buf), flags);
				break;
			}
		}
A
Alan Cox 已提交
1543 1544
		if (tty->ops->flush_chars)
			tty->ops->flush_chars(tty);
L
Linus Torvalds 已提交
1545 1546
	}

1547
	if ((!ldata->icanon && (read_cnt(ldata) >= ldata->minimum_to_wake)) ||
1548
		L_EXTPROC(tty)) {
L
Linus Torvalds 已提交
1549 1550 1551 1552 1553
		kill_fasync(&tty->fasync, SIGIO, POLL_IN);
		if (waitqueue_active(&tty->read_wait))
			wake_up_interruptible(&tty->read_wait);
	}

1554
	n_tty_check_throttle(tty);
L
Linus Torvalds 已提交
1555 1556
}

1557 1558 1559
static void n_tty_receive_buf(struct tty_struct *tty, const unsigned char *cp,
			      char *fp, int count)
{
1560
	down_read(&tty->termios_rwsem);
1561
	__receive_buf(tty, cp, fp, count);
1562
	up_read(&tty->termios_rwsem);
1563 1564 1565 1566 1567 1568 1569 1570
}

static int n_tty_receive_buf2(struct tty_struct *tty, const unsigned char *cp,
			      char *fp, int count)
{
	struct n_tty_data *ldata = tty->disc_data;
	int room;

1571 1572
	down_read(&tty->termios_rwsem);

1573 1574 1575 1576 1577 1578 1579
	tty->receive_room = room = receive_room(tty);
	if (!room)
		ldata->no_room = 1;
	count = min(count, room);
	if (count)
		__receive_buf(tty, cp, fp, count);

1580 1581
	up_read(&tty->termios_rwsem);

1582 1583 1584
	return count;
}

L
Linus Torvalds 已提交
1585 1586 1587
int is_ignored(int sig)
{
	return (sigismember(&current->blocked, sig) ||
1588
		current->sighand->action[sig-1].sa.sa_handler == SIG_IGN);
L
Linus Torvalds 已提交
1589 1590 1591 1592 1593 1594 1595 1596 1597
}

/**
 *	n_tty_set_termios	-	termios data changed
 *	@tty: terminal
 *	@old: previous data
 *
 *	Called by the tty layer when the user changes termios flags so
 *	that the line discipline can plan ahead. This function cannot sleep
1598
 *	and is protected from re-entry by the tty layer. The user is
L
Linus Torvalds 已提交
1599 1600
 *	guaranteed that this function will not be re-entered or in progress
 *	when the ldisc is closed.
1601
 *
1602
 *	Locking: Caller holds tty->termios_rwsem
L
Linus Torvalds 已提交
1603
 */
1604 1605

static void n_tty_set_termios(struct tty_struct *tty, struct ktermios *old)
L
Linus Torvalds 已提交
1606
{
1607
	struct n_tty_data *ldata = tty->disc_data;
1608 1609 1610
	int canon_change = 1;

	if (old)
1611
		canon_change = (old->c_lflag ^ tty->termios.c_lflag) & ICANON;
1612
	if (canon_change) {
1613
		bitmap_zero(ldata->read_flags, N_TTY_BUF_SIZE);
1614
		ldata->canon_head = ldata->read_tail;
1615
		ldata->erasing = 0;
1616
		ldata->lnext = 0;
1617 1618
	}

1619
	if (canon_change && !L_ICANON(tty) && read_cnt(ldata))
1620
		wake_up_interruptible(&tty->read_wait);
1621

1622
	ldata->icanon = (L_ICANON(tty) != 0);
P
Peter Hurley 已提交
1623

L
Linus Torvalds 已提交
1624 1625 1626 1627
	if (I_ISTRIP(tty) || I_IUCLC(tty) || I_IGNCR(tty) ||
	    I_ICRNL(tty) || I_INLCR(tty) || L_ICANON(tty) ||
	    I_IXON(tty) || L_ISIG(tty) || L_ECHO(tty) ||
	    I_PARMRK(tty)) {
1628
		bitmap_zero(ldata->process_char_map, 256);
L
Linus Torvalds 已提交
1629 1630

		if (I_IGNCR(tty) || I_ICRNL(tty))
1631
			set_bit('\r', ldata->process_char_map);
L
Linus Torvalds 已提交
1632
		if (I_INLCR(tty))
1633
			set_bit('\n', ldata->process_char_map);
L
Linus Torvalds 已提交
1634 1635

		if (L_ICANON(tty)) {
1636 1637 1638 1639 1640
			set_bit(ERASE_CHAR(tty), ldata->process_char_map);
			set_bit(KILL_CHAR(tty), ldata->process_char_map);
			set_bit(EOF_CHAR(tty), ldata->process_char_map);
			set_bit('\n', ldata->process_char_map);
			set_bit(EOL_CHAR(tty), ldata->process_char_map);
L
Linus Torvalds 已提交
1641 1642
			if (L_IEXTEN(tty)) {
				set_bit(WERASE_CHAR(tty),
1643
					ldata->process_char_map);
L
Linus Torvalds 已提交
1644
				set_bit(LNEXT_CHAR(tty),
1645
					ldata->process_char_map);
L
Linus Torvalds 已提交
1646
				set_bit(EOL2_CHAR(tty),
1647
					ldata->process_char_map);
L
Linus Torvalds 已提交
1648 1649
				if (L_ECHO(tty))
					set_bit(REPRINT_CHAR(tty),
1650
						ldata->process_char_map);
L
Linus Torvalds 已提交
1651 1652 1653
			}
		}
		if (I_IXON(tty)) {
1654 1655
			set_bit(START_CHAR(tty), ldata->process_char_map);
			set_bit(STOP_CHAR(tty), ldata->process_char_map);
L
Linus Torvalds 已提交
1656 1657
		}
		if (L_ISIG(tty)) {
1658 1659 1660
			set_bit(INTR_CHAR(tty), ldata->process_char_map);
			set_bit(QUIT_CHAR(tty), ldata->process_char_map);
			set_bit(SUSP_CHAR(tty), ldata->process_char_map);
L
Linus Torvalds 已提交
1661
		}
1662
		clear_bit(__DISABLED_CHAR, ldata->process_char_map);
1663 1664
		ldata->raw = 0;
		ldata->real_raw = 0;
L
Linus Torvalds 已提交
1665
	} else {
1666
		ldata->raw = 1;
L
Linus Torvalds 已提交
1667 1668 1669
		if ((I_IGNBRK(tty) || (!I_BRKINT(tty) && !I_PARMRK(tty))) &&
		    (I_IGNPAR(tty) || !I_INPCK(tty)) &&
		    (tty->driver->flags & TTY_DRIVER_REAL_RAW))
1670
			ldata->real_raw = 1;
L
Linus Torvalds 已提交
1671
		else
1672
			ldata->real_raw = 0;
L
Linus Torvalds 已提交
1673
	}
1674
	n_tty_set_room(tty);
1675 1676 1677 1678 1679 1680 1681 1682
	/*
	 * Fix tty hang when I_IXON(tty) is cleared, but the tty
	 * been stopped by STOP_CHAR(tty) before it.
	 */
	if (!I_IXON(tty) && old && (old->c_iflag & IXON) && !tty->flow_stopped) {
		start_tty(tty);
	}

A
Alan Cox 已提交
1683 1684 1685
	/* The termios change make the tty ready for I/O */
	wake_up_interruptible(&tty->write_wait);
	wake_up_interruptible(&tty->read_wait);
L
Linus Torvalds 已提交
1686 1687 1688 1689 1690 1691
}

/**
 *	n_tty_close		-	close the ldisc for this tty
 *	@tty: device
 *
1692 1693
 *	Called from the terminal layer when this line discipline is
 *	being shut down, either because of a close or becsuse of a
L
Linus Torvalds 已提交
1694 1695 1696
 *	discipline change. The function will not be called while other
 *	ldisc methods are in progress.
 */
1697

L
Linus Torvalds 已提交
1698 1699
static void n_tty_close(struct tty_struct *tty)
{
J
Jiri Slaby 已提交
1700 1701
	struct n_tty_data *ldata = tty->disc_data;

1702 1703 1704
	if (tty->link)
		n_tty_packet_mode_flush(tty);

1705 1706
	kfree(ldata->read_buf);
	kfree(ldata->echo_buf);
J
Jiri Slaby 已提交
1707 1708
	kfree(ldata);
	tty->disc_data = NULL;
L
Linus Torvalds 已提交
1709 1710 1711 1712 1713 1714
}

/**
 *	n_tty_open		-	open an ldisc
 *	@tty: terminal to open
 *
1715
 *	Called when this line discipline is being attached to the
L
Linus Torvalds 已提交
1716 1717 1718 1719 1720 1721 1722
 *	terminal device. Can sleep. Called serialized so that no
 *	other events will occur in parallel. No further open will occur
 *	until a close.
 */

static int n_tty_open(struct tty_struct *tty)
{
J
Jiri Slaby 已提交
1723 1724 1725 1726 1727 1728
	struct n_tty_data *ldata;

	ldata = kzalloc(sizeof(*ldata), GFP_KERNEL);
	if (!ldata)
		goto err;

1729
	ldata->overrun_time = jiffies;
1730 1731 1732
	mutex_init(&ldata->atomic_read_lock);
	mutex_init(&ldata->output_lock);
	mutex_init(&ldata->echo_lock);
1733

1734
	/* These are ugly. Currently a malloc failure here can panic */
1735 1736 1737
	ldata->read_buf = kzalloc(N_TTY_BUF_SIZE, GFP_KERNEL);
	ldata->echo_buf = kzalloc(N_TTY_BUF_SIZE, GFP_KERNEL);
	if (!ldata->read_buf || !ldata->echo_buf)
1738
		goto err_free_bufs;
1739

J
Jiri Slaby 已提交
1740
	tty->disc_data = ldata;
1741
	reset_buffer_flags(tty->disc_data);
1742
	ldata->column = 0;
1743
	ldata->minimum_to_wake = 1;
L
Linus Torvalds 已提交
1744
	tty->closing = 0;
1745 1746 1747 1748
	/* indicate buffer work may resume */
	clear_bit(TTY_LDISC_HALTED, &tty->flags);
	n_tty_set_termios(tty, NULL);
	tty_unthrottle(tty);
J
Jiri Slaby 已提交
1749

L
Linus Torvalds 已提交
1750
	return 0;
1751
err_free_bufs:
1752 1753
	kfree(ldata->read_buf);
	kfree(ldata->echo_buf);
J
Jiri Slaby 已提交
1754 1755
	kfree(ldata);
err:
1756
	return -ENOMEM;
L
Linus Torvalds 已提交
1757 1758 1759 1760
}

static inline int input_available_p(struct tty_struct *tty, int amt)
{
1761 1762 1763
	struct n_tty_data *ldata = tty->disc_data;

	if (ldata->icanon && !L_EXTPROC(tty)) {
1764
		if (ldata->canon_head != ldata->read_tail)
L
Linus Torvalds 已提交
1765
			return 1;
1766
	} else if (read_cnt(ldata) >= (amt ? amt : 1))
L
Linus Torvalds 已提交
1767 1768 1769 1770 1771 1772
		return 1;

	return 0;
}

/**
1773
 *	copy_from_read_buf	-	copy read data directly
L
Linus Torvalds 已提交
1774 1775 1776 1777
 *	@tty: terminal device
 *	@b: user data
 *	@nr: size of data
 *
1778
 *	Helper function to speed up n_tty_read.  It is only called when
L
Linus Torvalds 已提交
1779 1780 1781 1782 1783 1784
 *	ICANON is off; it copies characters straight from the tty queue to
 *	user space directly.  It can be profitably called twice; once to
 *	drain the space from the tail pointer to the (physical) end of the
 *	buffer, and once to drain the space from the (physical) beginning of
 *	the buffer to head pointer.
 *
1785
 *	Called under the ldata->atomic_read_lock sem
L
Linus Torvalds 已提交
1786
 *
1787 1788 1789
 *	n_tty_read()/consumer path:
 *		caller holds non-exclusive termios_rwsem
 *		read_tail published
L
Linus Torvalds 已提交
1790
 */
1791

A
Alan Cox 已提交
1792
static int copy_from_read_buf(struct tty_struct *tty,
L
Linus Torvalds 已提交
1793 1794 1795 1796
				      unsigned char __user **b,
				      size_t *nr)

{
1797
	struct n_tty_data *ldata = tty->disc_data;
L
Linus Torvalds 已提交
1798 1799
	int retval;
	size_t n;
1800
	bool is_eof;
1801
	size_t tail = ldata->read_tail & (N_TTY_BUF_SIZE - 1);
L
Linus Torvalds 已提交
1802 1803

	retval = 0;
1804
	n = min(read_cnt(ldata), N_TTY_BUF_SIZE - tail);
L
Linus Torvalds 已提交
1805 1806
	n = min(*nr, n);
	if (n) {
1807
		retval = copy_to_user(*b, read_buf_addr(ldata, tail), n);
L
Linus Torvalds 已提交
1808
		n -= retval;
1809 1810
		is_eof = n == 1 && read_buf(ldata, tail) == EOF_CHAR(tty);
		tty_audit_add_data(tty, read_buf_addr(ldata, tail), n,
1811
				ldata->icanon);
1812
		ldata->read_tail += n;
1813
		/* Turn single EOF into zero-length read */
1814
		if (L_EXTPROC(tty) && ldata->icanon && is_eof && !read_cnt(ldata))
1815
			n = 0;
L
Linus Torvalds 已提交
1816 1817 1818 1819 1820 1821
		*b += n;
		*nr -= n;
	}
	return retval;
}

1822
/**
1823
 *	canon_copy_from_read_buf	-	copy read data in canonical mode
1824 1825 1826 1827 1828
 *	@tty: terminal device
 *	@b: user data
 *	@nr: size of data
 *
 *	Helper function for n_tty_read.  It is only called when ICANON is on;
1829 1830
 *	it copies one line of input up to and including the line-delimiting
 *	character into the user-space buffer.
1831 1832
 *
 *	Called under the atomic_read_lock mutex
1833 1834 1835 1836
 *
 *	n_tty_read()/consumer path:
 *		caller holds non-exclusive termios_rwsem
 *		read_tail published
1837 1838
 */

1839 1840 1841
static int canon_copy_from_read_buf(struct tty_struct *tty,
				    unsigned char __user **b,
				    size_t *nr)
1842 1843
{
	struct n_tty_data *ldata = tty->disc_data;
1844
	size_t n, size, more, c;
1845 1846 1847
	size_t eol;
	size_t tail;
	int ret, found = 0;
1848 1849

	/* N.B. avoid overrun if nr == 0 */
1850
	n = min(*nr, read_cnt(ldata));
1851
	if (!n)
1852
		return 0;
1853

1854
	tail = ldata->read_tail & (N_TTY_BUF_SIZE - 1);
1855 1856
	size = min_t(size_t, tail + n, N_TTY_BUF_SIZE);

1857
	n_tty_trace("%s: nr:%zu tail:%zu n:%zu size:%zu\n",
1858 1859 1860 1861 1862 1863 1864 1865 1866 1867 1868 1869 1870 1871 1872 1873
		    __func__, *nr, tail, n, size);

	eol = find_next_bit(ldata->read_flags, size, tail);
	more = n - (size - tail);
	if (eol == N_TTY_BUF_SIZE && more) {
		/* scan wrapped without finding set bit */
		eol = find_next_bit(ldata->read_flags, more, 0);
		if (eol != more)
			found = 1;
	} else if (eol != size)
		found = 1;

	size = N_TTY_BUF_SIZE - tail;
	n = (found + eol + size) & (N_TTY_BUF_SIZE - 1);
	c = n;

1874
	if (found && read_buf(ldata, eol) == __DISABLED_CHAR)
1875 1876
		n--;

1877
	n_tty_trace("%s: eol:%zu found:%d n:%zu c:%zu size:%zu more:%zu\n",
1878 1879 1880
		    __func__, eol, found, n, c, size, more);

	if (n > size) {
1881
		ret = copy_to_user(*b, read_buf_addr(ldata, tail), size);
1882 1883 1884 1885
		if (ret)
			return -EFAULT;
		ret = copy_to_user(*b + size, ldata->read_buf, n - size);
	} else
1886
		ret = copy_to_user(*b, read_buf_addr(ldata, tail), n);
1887 1888 1889 1890 1891 1892

	if (ret)
		return -EFAULT;
	*b += n;
	*nr -= n;

1893
	if (found)
1894 1895 1896
		clear_bit(eol, ldata->read_flags);
	smp_mb__after_clear_bit();
	ldata->read_tail += c;
1897

1898 1899
	if (found)
		tty_audit_push(tty);
1900 1901 1902
	return 0;
}

1903
extern ssize_t redirected_tty_write(struct file *, const char __user *,
1904
							size_t, loff_t *);
L
Linus Torvalds 已提交
1905 1906 1907 1908 1909 1910 1911

/**
 *	job_control		-	check job control
 *	@tty: tty
 *	@file: file handle
 *
 *	Perform job control management checks on this file/tty descriptor
1912
 *	and if appropriate send any needed signals and return a negative
L
Linus Torvalds 已提交
1913
 *	error code if action should be taken.
A
Alan Cox 已提交
1914
 *
1915 1916 1917
 *	Locking: redirected write test is safe
 *		 current->signal->tty check is safe
 *		 ctrl_lock to safely reference tty->pgrp
L
Linus Torvalds 已提交
1918
 */
1919

L
Linus Torvalds 已提交
1920 1921 1922 1923 1924 1925 1926
static int job_control(struct tty_struct *tty, struct file *file)
{
	/* Job control check -- must be done at start and after
	   every sleep (POSIX.1 7.1.1.4). */
	/* NOTE: not yet done after every sleep pending a thorough
	   check of the logic of this change. -- jlc */
	/* don't stop on /dev/console */
1927 1928 1929 1930 1931 1932 1933 1934 1935 1936 1937 1938 1939 1940
	if (file->f_op->write == redirected_tty_write ||
	    current->signal->tty != tty)
		return 0;

	spin_lock_irq(&tty->ctrl_lock);
	if (!tty->pgrp)
		printk(KERN_ERR "n_tty_read: no tty->pgrp!\n");
	else if (task_pgrp(current) != tty->pgrp) {
		spin_unlock_irq(&tty->ctrl_lock);
		if (is_ignored(SIGTTIN) || is_current_pgrp_orphaned())
			return -EIO;
		kill_pgrp(task_pgrp(current), SIGTTIN, 1);
		set_thread_flag(TIF_SIGPENDING);
		return -ERESTARTSYS;
L
Linus Torvalds 已提交
1941
	}
1942
	spin_unlock_irq(&tty->ctrl_lock);
L
Linus Torvalds 已提交
1943 1944
	return 0;
}
1945

L
Linus Torvalds 已提交
1946 1947

/**
1948
 *	n_tty_read		-	read function for tty
L
Linus Torvalds 已提交
1949 1950 1951 1952 1953 1954 1955 1956 1957 1958 1959
 *	@tty: tty device
 *	@file: file object
 *	@buf: userspace buffer pointer
 *	@nr: size of I/O
 *
 *	Perform reads for the line discipline. We are guaranteed that the
 *	line discipline will not be closed under us but we may get multiple
 *	parallel readers and must handle this ourselves. We may also get
 *	a hangup. Always called in user context, may sleep.
 *
 *	This code must be sure never to sleep through a hangup.
1960 1961 1962 1963
 *
 *	n_tty_read()/consumer path:
 *		claims non-exclusive termios_rwsem
 *		publishes read_tail
L
Linus Torvalds 已提交
1964
 */
1965

1966
static ssize_t n_tty_read(struct tty_struct *tty, struct file *file,
L
Linus Torvalds 已提交
1967 1968
			 unsigned char __user *buf, size_t nr)
{
1969
	struct n_tty_data *ldata = tty->disc_data;
L
Linus Torvalds 已提交
1970 1971 1972 1973 1974 1975 1976 1977
	unsigned char __user *b = buf;
	DECLARE_WAITQUEUE(wait, current);
	int c;
	int minimum, time;
	ssize_t retval = 0;
	ssize_t size;
	long timeout;
	unsigned long flags;
A
Alan Cox 已提交
1978
	int packet;
L
Linus Torvalds 已提交
1979 1980 1981

do_it_again:
	c = job_control(tty, file);
1982
	if (c < 0)
L
Linus Torvalds 已提交
1983
		return c;
1984

1985 1986
	down_read(&tty->termios_rwsem);

L
Linus Torvalds 已提交
1987 1988
	minimum = time = 0;
	timeout = MAX_SCHEDULE_TIMEOUT;
1989
	if (!ldata->icanon) {
L
Linus Torvalds 已提交
1990 1991
		minimum = MIN_CHAR(tty);
		if (minimum) {
1992
			time = (HZ / 10) * TIME_CHAR(tty);
L
Linus Torvalds 已提交
1993
			if (time)
1994
				ldata->minimum_to_wake = 1;
L
Linus Torvalds 已提交
1995
			else if (!waitqueue_active(&tty->read_wait) ||
1996 1997
				 (ldata->minimum_to_wake > minimum))
				ldata->minimum_to_wake = minimum;
L
Linus Torvalds 已提交
1998
		} else {
1999
			timeout = (HZ / 10) * TIME_CHAR(tty);
2000
			ldata->minimum_to_wake = minimum = 1;
L
Linus Torvalds 已提交
2001 2002 2003 2004 2005 2006 2007
		}
	}

	/*
	 *	Internal serialization of reads.
	 */
	if (file->f_flags & O_NONBLOCK) {
2008 2009
		if (!mutex_trylock(&ldata->atomic_read_lock)) {
			up_read(&tty->termios_rwsem);
L
Linus Torvalds 已提交
2010
			return -EAGAIN;
2011
		}
2012
	} else {
2013 2014
		if (mutex_lock_interruptible(&ldata->atomic_read_lock)) {
			up_read(&tty->termios_rwsem);
L
Linus Torvalds 已提交
2015
			return -ERESTARTSYS;
2016
		}
L
Linus Torvalds 已提交
2017
	}
A
Alan Cox 已提交
2018
	packet = tty->packet;
L
Linus Torvalds 已提交
2019 2020 2021 2022

	add_wait_queue(&tty->read_wait, &wait);
	while (nr) {
		/* First test for status change. */
A
Alan Cox 已提交
2023
		if (packet && tty->link->ctrl_status) {
L
Linus Torvalds 已提交
2024 2025 2026
			unsigned char cs;
			if (b != buf)
				break;
A
Alan Cox 已提交
2027
			spin_lock_irqsave(&tty->link->ctrl_lock, flags);
L
Linus Torvalds 已提交
2028 2029
			cs = tty->link->ctrl_status;
			tty->link->ctrl_status = 0;
A
Alan Cox 已提交
2030
			spin_unlock_irqrestore(&tty->link->ctrl_lock, flags);
M
Miloslav Trmac 已提交
2031
			if (tty_put_user(tty, cs, b++)) {
L
Linus Torvalds 已提交
2032 2033 2034 2035 2036 2037 2038 2039 2040 2041 2042
				retval = -EFAULT;
				b--;
				break;
			}
			nr--;
			break;
		}
		/* This statement must be first before checking for input
		   so that any interrupt will set the state back to
		   TASK_RUNNING. */
		set_current_state(TASK_INTERRUPTIBLE);
2043

2044
		if (((minimum - (b - buf)) < ldata->minimum_to_wake) &&
L
Linus Torvalds 已提交
2045
		    ((minimum - (b - buf)) >= 1))
2046
			ldata->minimum_to_wake = (minimum - (b - buf));
2047

L
Linus Torvalds 已提交
2048 2049 2050 2051 2052 2053 2054 2055 2056 2057 2058 2059 2060 2061 2062 2063 2064
		if (!input_available_p(tty, 0)) {
			if (test_bit(TTY_OTHER_CLOSED, &tty->flags)) {
				retval = -EIO;
				break;
			}
			if (tty_hung_up_p(file))
				break;
			if (!timeout)
				break;
			if (file->f_flags & O_NONBLOCK) {
				retval = -EAGAIN;
				break;
			}
			if (signal_pending(current)) {
				retval = -ERESTARTSYS;
				break;
			}
2065
			n_tty_set_room(tty);
2066 2067
			up_read(&tty->termios_rwsem);

L
Linus Torvalds 已提交
2068
			timeout = schedule_timeout(timeout);
2069 2070

			down_read(&tty->termios_rwsem);
L
Linus Torvalds 已提交
2071 2072 2073 2074 2075
			continue;
		}
		__set_current_state(TASK_RUNNING);

		/* Deal with packet mode. */
A
Alan Cox 已提交
2076
		if (packet && b == buf) {
M
Miloslav Trmac 已提交
2077
			if (tty_put_user(tty, TIOCPKT_DATA, b++)) {
L
Linus Torvalds 已提交
2078 2079 2080 2081 2082 2083 2084
				retval = -EFAULT;
				b--;
				break;
			}
			nr--;
		}

2085
		if (ldata->icanon && !L_EXTPROC(tty)) {
2086
			retval = canon_copy_from_read_buf(tty, &b, &nr);
L
Linus Torvalds 已提交
2087 2088 2089 2090
			if (retval)
				break;
		} else {
			int uncopied;
A
Alan Cox 已提交
2091 2092
			/* The copy function takes the read lock and handles
			   locking internally for this case */
L
Linus Torvalds 已提交
2093 2094 2095 2096 2097 2098 2099 2100
			uncopied = copy_from_read_buf(tty, &b, &nr);
			uncopied += copy_from_read_buf(tty, &b, &nr);
			if (uncopied) {
				retval = -EFAULT;
				break;
			}
		}

2101
		n_tty_check_unthrottle(tty);
L
Linus Torvalds 已提交
2102 2103 2104 2105 2106 2107

		if (b - buf >= minimum)
			break;
		if (time)
			timeout = time;
	}
2108
	mutex_unlock(&ldata->atomic_read_lock);
L
Linus Torvalds 已提交
2109 2110 2111
	remove_wait_queue(&tty->read_wait, &wait);

	if (!waitqueue_active(&tty->read_wait))
2112
		ldata->minimum_to_wake = minimum;
L
Linus Torvalds 已提交
2113 2114 2115 2116 2117 2118

	__set_current_state(TASK_RUNNING);
	size = b - buf;
	if (size) {
		retval = size;
		if (nr)
2119
			clear_bit(TTY_PUSH, &tty->flags);
2120 2121
	} else if (test_and_clear_bit(TTY_PUSH, &tty->flags)) {
		up_read(&tty->termios_rwsem);
2122
		goto do_it_again;
2123
	}
L
Linus Torvalds 已提交
2124

2125
	n_tty_set_room(tty);
2126
	up_read(&tty->termios_rwsem);
L
Linus Torvalds 已提交
2127 2128 2129 2130
	return retval;
}

/**
2131
 *	n_tty_write		-	write function for tty
L
Linus Torvalds 已提交
2132 2133 2134 2135 2136
 *	@tty: tty device
 *	@file: file object
 *	@buf: userspace buffer pointer
 *	@nr: size of I/O
 *
2137
 *	Write function of the terminal device.  This is serialized with
L
Linus Torvalds 已提交
2138
 *	respect to other write callers but not to termios changes, reads
2139 2140 2141 2142 2143
 *	and other such events.  Since the receive code will echo characters,
 *	thus calling driver write methods, the output_lock is used in
 *	the output processing functions called here as well as in the
 *	echo processing function to protect the column state and space
 *	left in the buffer.
L
Linus Torvalds 已提交
2144 2145
 *
 *	This code must be sure never to sleep through a hangup.
2146 2147 2148 2149
 *
 *	Locking: output_lock to protect column state and space left
 *		 (note that the process_output*() functions take this
 *		  lock themselves)
L
Linus Torvalds 已提交
2150
 */
2151

2152
static ssize_t n_tty_write(struct tty_struct *tty, struct file *file,
2153
			   const unsigned char *buf, size_t nr)
L
Linus Torvalds 已提交
2154 2155 2156 2157 2158 2159 2160 2161 2162 2163 2164 2165 2166
{
	const unsigned char *b = buf;
	DECLARE_WAITQUEUE(wait, current);
	int c;
	ssize_t retval = 0;

	/* Job control check -- must be done at start (POSIX.1 7.1.1.4). */
	if (L_TOSTOP(tty) && file->f_op->write != redirected_tty_write) {
		retval = tty_check_change(tty);
		if (retval)
			return retval;
	}

2167 2168
	down_read(&tty->termios_rwsem);

2169 2170
	/* Write out any echoed characters that are still pending */
	process_echoes(tty);
A
Alan Cox 已提交
2171

L
Linus Torvalds 已提交
2172 2173 2174 2175 2176 2177 2178 2179 2180 2181 2182
	add_wait_queue(&tty->write_wait, &wait);
	while (1) {
		set_current_state(TASK_INTERRUPTIBLE);
		if (signal_pending(current)) {
			retval = -ERESTARTSYS;
			break;
		}
		if (tty_hung_up_p(file) || (tty->link && !tty->link->count)) {
			retval = -EIO;
			break;
		}
P
Peter Hurley 已提交
2183
		if (O_OPOST(tty)) {
L
Linus Torvalds 已提交
2184
			while (nr > 0) {
2185
				ssize_t num = process_output_block(tty, b, nr);
L
Linus Torvalds 已提交
2186 2187 2188 2189 2190 2191 2192 2193 2194 2195 2196
				if (num < 0) {
					if (num == -EAGAIN)
						break;
					retval = num;
					goto break_out;
				}
				b += num;
				nr -= num;
				if (nr == 0)
					break;
				c = *b;
2197
				if (process_output(c, tty) < 0)
L
Linus Torvalds 已提交
2198 2199 2200
					break;
				b++; nr--;
			}
A
Alan Cox 已提交
2201 2202
			if (tty->ops->flush_chars)
				tty->ops->flush_chars(tty);
L
Linus Torvalds 已提交
2203
		} else {
R
Roman Zippel 已提交
2204
			while (nr > 0) {
A
Alan Cox 已提交
2205
				c = tty->ops->write(tty, b, nr);
R
Roman Zippel 已提交
2206 2207 2208 2209 2210 2211 2212 2213
				if (c < 0) {
					retval = c;
					goto break_out;
				}
				if (!c)
					break;
				b += c;
				nr -= c;
L
Linus Torvalds 已提交
2214 2215 2216 2217 2218 2219 2220 2221
			}
		}
		if (!nr)
			break;
		if (file->f_flags & O_NONBLOCK) {
			retval = -EAGAIN;
			break;
		}
2222 2223
		up_read(&tty->termios_rwsem);

L
Linus Torvalds 已提交
2224
		schedule();
2225 2226

		down_read(&tty->termios_rwsem);
L
Linus Torvalds 已提交
2227 2228 2229 2230
	}
break_out:
	__set_current_state(TASK_RUNNING);
	remove_wait_queue(&tty->write_wait, &wait);
2231 2232
	if (b - buf != nr && tty->fasync)
		set_bit(TTY_DO_WRITE_WAKEUP, &tty->flags);
2233
	up_read(&tty->termios_rwsem);
L
Linus Torvalds 已提交
2234 2235 2236 2237
	return (b - buf) ? b - buf : retval;
}

/**
2238
 *	n_tty_poll		-	poll method for N_TTY
L
Linus Torvalds 已提交
2239 2240 2241 2242 2243 2244 2245 2246 2247 2248 2249
 *	@tty: terminal device
 *	@file: file accessing it
 *	@wait: poll table
 *
 *	Called when the line discipline is asked to poll() for data or
 *	for special events. This code is not serialized with respect to
 *	other events save open/close.
 *
 *	This code must be sure never to sleep through a hangup.
 *	Called without the kernel lock held - fine
 */
2250

2251
static unsigned int n_tty_poll(struct tty_struct *tty, struct file *file,
2252
							poll_table *wait)
L
Linus Torvalds 已提交
2253
{
2254
	struct n_tty_data *ldata = tty->disc_data;
L
Linus Torvalds 已提交
2255 2256 2257 2258 2259 2260 2261 2262 2263 2264 2265 2266 2267 2268
	unsigned int mask = 0;

	poll_wait(file, &tty->read_wait, wait);
	poll_wait(file, &tty->write_wait, wait);
	if (input_available_p(tty, TIME_CHAR(tty) ? 0 : MIN_CHAR(tty)))
		mask |= POLLIN | POLLRDNORM;
	if (tty->packet && tty->link->ctrl_status)
		mask |= POLLPRI | POLLIN | POLLRDNORM;
	if (test_bit(TTY_OTHER_CLOSED, &tty->flags))
		mask |= POLLHUP;
	if (tty_hung_up_p(file))
		mask |= POLLHUP;
	if (!(mask & (POLLHUP | POLLIN | POLLRDNORM))) {
		if (MIN_CHAR(tty) && !TIME_CHAR(tty))
2269
			ldata->minimum_to_wake = MIN_CHAR(tty);
L
Linus Torvalds 已提交
2270
		else
2271
			ldata->minimum_to_wake = 1;
L
Linus Torvalds 已提交
2272
	}
A
Alan Cox 已提交
2273 2274 2275
	if (tty->ops->write && !tty_is_writelocked(tty) &&
			tty_chars_in_buffer(tty) < WAKEUP_CHARS &&
			tty_write_room(tty) > 0)
L
Linus Torvalds 已提交
2276 2277 2278 2279
		mask |= POLLOUT | POLLWRNORM;
	return mask;
}

J
Jiri Slaby 已提交
2280
static unsigned long inq_canon(struct n_tty_data *ldata)
2281
{
2282
	size_t nr, head, tail;
2283

2284
	if (ldata->canon_head == ldata->read_tail)
2285
		return 0;
2286 2287
	head = ldata->canon_head;
	tail = ldata->read_tail;
2288
	nr = head - tail;
2289 2290
	/* Skip EOF-chars.. */
	while (head != tail) {
2291 2292
		if (test_bit(tail & (N_TTY_BUF_SIZE - 1), ldata->read_flags) &&
		    read_buf(ldata, tail) == __DISABLED_CHAR)
2293
			nr--;
2294
		tail++;
2295 2296 2297 2298 2299 2300 2301
	}
	return nr;
}

static int n_tty_ioctl(struct tty_struct *tty, struct file *file,
		       unsigned int cmd, unsigned long arg)
{
2302
	struct n_tty_data *ldata = tty->disc_data;
2303 2304 2305 2306 2307 2308
	int retval;

	switch (cmd) {
	case TIOCOUTQ:
		return put_user(tty_chars_in_buffer(tty), (int __user *) arg);
	case TIOCINQ:
2309
		down_write(&tty->termios_rwsem);
2310
		if (L_ICANON(tty))
J
Jiri Slaby 已提交
2311
			retval = inq_canon(ldata);
2312 2313 2314
		else
			retval = read_cnt(ldata);
		up_write(&tty->termios_rwsem);
2315 2316 2317 2318 2319 2320
		return put_user(retval, (unsigned int __user *) arg);
	default:
		return n_tty_ioctl_helper(tty, file, cmd, arg);
	}
}

2321 2322 2323 2324 2325 2326 2327 2328 2329 2330 2331 2332
static void n_tty_fasync(struct tty_struct *tty, int on)
{
	struct n_tty_data *ldata = tty->disc_data;

	if (!waitqueue_active(&tty->read_wait)) {
		if (on)
			ldata->minimum_to_wake = 1;
		else if (!tty->fasync)
			ldata->minimum_to_wake = N_TTY_BUF_SIZE;
	}
}

A
Alan Cox 已提交
2333
struct tty_ldisc_ops tty_ldisc_N_TTY = {
P
Paul Fulghum 已提交
2334 2335 2336 2337 2338 2339
	.magic           = TTY_LDISC_MAGIC,
	.name            = "n_tty",
	.open            = n_tty_open,
	.close           = n_tty_close,
	.flush_buffer    = n_tty_flush_buffer,
	.chars_in_buffer = n_tty_chars_in_buffer,
2340 2341
	.read            = n_tty_read,
	.write           = n_tty_write,
P
Paul Fulghum 已提交
2342 2343
	.ioctl           = n_tty_ioctl,
	.set_termios     = n_tty_set_termios,
2344
	.poll            = n_tty_poll,
P
Paul Fulghum 已提交
2345
	.receive_buf     = n_tty_receive_buf,
2346 2347
	.write_wakeup    = n_tty_write_wakeup,
	.fasync		 = n_tty_fasync,
2348
	.receive_buf2	 = n_tty_receive_buf2,
L
Linus Torvalds 已提交
2349
};
2350 2351 2352 2353 2354

/**
 *	n_tty_inherit_ops	-	inherit N_TTY methods
 *	@ops: struct tty_ldisc_ops where to save N_TTY methods
 *
2355
 *	Enables a 'subclass' line discipline to 'inherit' N_TTY
2356 2357 2358 2359 2360 2361 2362 2363 2364 2365
 *	methods.
 */

void n_tty_inherit_ops(struct tty_ldisc_ops *ops)
{
	*ops = tty_ldisc_N_TTY;
	ops->owner = NULL;
	ops->refcount = ops->flags = 0;
}
EXPORT_SYMBOL_GPL(n_tty_inherit_ops);