1*4882a593Smuzhiyun // SPDX-License-Identifier: GPL-2.0
2*4882a593Smuzhiyun /*
3*4882a593Smuzhiyun * This file contains the procedures for the handling of select and poll
4*4882a593Smuzhiyun *
5*4882a593Smuzhiyun * Created for Linux based loosely upon Mathius Lattner's minix
6*4882a593Smuzhiyun * patches by Peter MacDonald. Heavily edited by Linus.
7*4882a593Smuzhiyun *
8*4882a593Smuzhiyun * 4 February 1994
9*4882a593Smuzhiyun * COFF/ELF binary emulation. If the process has the STICKY_TIMEOUTS
10*4882a593Smuzhiyun * flag set in its personality we do *not* modify the given timeout
11*4882a593Smuzhiyun * parameter to reflect time remaining.
12*4882a593Smuzhiyun *
13*4882a593Smuzhiyun * 24 January 2000
14*4882a593Smuzhiyun * Changed sys_poll()/do_poll() to use PAGE_SIZE chunk-based allocation
15*4882a593Smuzhiyun * of fds to overcome nfds < 16390 descriptors limit (Tigran Aivazian).
16*4882a593Smuzhiyun */
17*4882a593Smuzhiyun
18*4882a593Smuzhiyun #include <linux/kernel.h>
19*4882a593Smuzhiyun #include <linux/sched/signal.h>
20*4882a593Smuzhiyun #include <linux/sched/rt.h>
21*4882a593Smuzhiyun #include <linux/syscalls.h>
22*4882a593Smuzhiyun #include <linux/export.h>
23*4882a593Smuzhiyun #include <linux/slab.h>
24*4882a593Smuzhiyun #include <linux/poll.h>
25*4882a593Smuzhiyun #include <linux/personality.h> /* for STICKY_TIMEOUTS */
26*4882a593Smuzhiyun #include <linux/file.h>
27*4882a593Smuzhiyun #include <linux/fdtable.h>
28*4882a593Smuzhiyun #include <linux/fs.h>
29*4882a593Smuzhiyun #include <linux/rcupdate.h>
30*4882a593Smuzhiyun #include <linux/hrtimer.h>
31*4882a593Smuzhiyun #include <linux/freezer.h>
32*4882a593Smuzhiyun #include <net/busy_poll.h>
33*4882a593Smuzhiyun #include <linux/vmalloc.h>
34*4882a593Smuzhiyun
35*4882a593Smuzhiyun #include <linux/uaccess.h>
36*4882a593Smuzhiyun
37*4882a593Smuzhiyun
38*4882a593Smuzhiyun /*
39*4882a593Smuzhiyun * Estimate expected accuracy in ns from a timeval.
40*4882a593Smuzhiyun *
41*4882a593Smuzhiyun * After quite a bit of churning around, we've settled on
42*4882a593Smuzhiyun * a simple thing of taking 0.1% of the timeout as the
43*4882a593Smuzhiyun * slack, with a cap of 100 msec.
44*4882a593Smuzhiyun * "nice" tasks get a 0.5% slack instead.
45*4882a593Smuzhiyun *
46*4882a593Smuzhiyun * Consider this comment an open invitation to come up with even
47*4882a593Smuzhiyun * better solutions..
48*4882a593Smuzhiyun */
49*4882a593Smuzhiyun
50*4882a593Smuzhiyun #define MAX_SLACK (100 * NSEC_PER_MSEC)
51*4882a593Smuzhiyun
__estimate_accuracy(struct timespec64 * tv)52*4882a593Smuzhiyun static long __estimate_accuracy(struct timespec64 *tv)
53*4882a593Smuzhiyun {
54*4882a593Smuzhiyun long slack;
55*4882a593Smuzhiyun int divfactor = 1000;
56*4882a593Smuzhiyun
57*4882a593Smuzhiyun if (tv->tv_sec < 0)
58*4882a593Smuzhiyun return 0;
59*4882a593Smuzhiyun
60*4882a593Smuzhiyun if (task_nice(current) > 0)
61*4882a593Smuzhiyun divfactor = divfactor / 5;
62*4882a593Smuzhiyun
63*4882a593Smuzhiyun if (tv->tv_sec > MAX_SLACK / (NSEC_PER_SEC/divfactor))
64*4882a593Smuzhiyun return MAX_SLACK;
65*4882a593Smuzhiyun
66*4882a593Smuzhiyun slack = tv->tv_nsec / divfactor;
67*4882a593Smuzhiyun slack += tv->tv_sec * (NSEC_PER_SEC/divfactor);
68*4882a593Smuzhiyun
69*4882a593Smuzhiyun if (slack > MAX_SLACK)
70*4882a593Smuzhiyun return MAX_SLACK;
71*4882a593Smuzhiyun
72*4882a593Smuzhiyun return slack;
73*4882a593Smuzhiyun }
74*4882a593Smuzhiyun
select_estimate_accuracy(struct timespec64 * tv)75*4882a593Smuzhiyun u64 select_estimate_accuracy(struct timespec64 *tv)
76*4882a593Smuzhiyun {
77*4882a593Smuzhiyun u64 ret;
78*4882a593Smuzhiyun struct timespec64 now;
79*4882a593Smuzhiyun
80*4882a593Smuzhiyun /*
81*4882a593Smuzhiyun * Realtime tasks get a slack of 0 for obvious reasons.
82*4882a593Smuzhiyun */
83*4882a593Smuzhiyun
84*4882a593Smuzhiyun if (rt_task(current))
85*4882a593Smuzhiyun return 0;
86*4882a593Smuzhiyun
87*4882a593Smuzhiyun ktime_get_ts64(&now);
88*4882a593Smuzhiyun now = timespec64_sub(*tv, now);
89*4882a593Smuzhiyun ret = __estimate_accuracy(&now);
90*4882a593Smuzhiyun if (ret < current->timer_slack_ns)
91*4882a593Smuzhiyun return current->timer_slack_ns;
92*4882a593Smuzhiyun return ret;
93*4882a593Smuzhiyun }
94*4882a593Smuzhiyun
95*4882a593Smuzhiyun
96*4882a593Smuzhiyun
97*4882a593Smuzhiyun struct poll_table_page {
98*4882a593Smuzhiyun struct poll_table_page * next;
99*4882a593Smuzhiyun struct poll_table_entry * entry;
100*4882a593Smuzhiyun struct poll_table_entry entries[];
101*4882a593Smuzhiyun };
102*4882a593Smuzhiyun
103*4882a593Smuzhiyun #define POLL_TABLE_FULL(table) \
104*4882a593Smuzhiyun ((unsigned long)((table)->entry+1) > PAGE_SIZE + (unsigned long)(table))
105*4882a593Smuzhiyun
106*4882a593Smuzhiyun /*
107*4882a593Smuzhiyun * Ok, Peter made a complicated, but straightforward multiple_wait() function.
108*4882a593Smuzhiyun * I have rewritten this, taking some shortcuts: This code may not be easy to
109*4882a593Smuzhiyun * follow, but it should be free of race-conditions, and it's practical. If you
110*4882a593Smuzhiyun * understand what I'm doing here, then you understand how the linux
111*4882a593Smuzhiyun * sleep/wakeup mechanism works.
112*4882a593Smuzhiyun *
113*4882a593Smuzhiyun * Two very simple procedures, poll_wait() and poll_freewait() make all the
114*4882a593Smuzhiyun * work. poll_wait() is an inline-function defined in <linux/poll.h>,
115*4882a593Smuzhiyun * as all select/poll functions have to call it to add an entry to the
116*4882a593Smuzhiyun * poll table.
117*4882a593Smuzhiyun */
118*4882a593Smuzhiyun static void __pollwait(struct file *filp, wait_queue_head_t *wait_address,
119*4882a593Smuzhiyun poll_table *p);
120*4882a593Smuzhiyun
poll_initwait(struct poll_wqueues * pwq)121*4882a593Smuzhiyun void poll_initwait(struct poll_wqueues *pwq)
122*4882a593Smuzhiyun {
123*4882a593Smuzhiyun init_poll_funcptr(&pwq->pt, __pollwait);
124*4882a593Smuzhiyun pwq->polling_task = current;
125*4882a593Smuzhiyun pwq->triggered = 0;
126*4882a593Smuzhiyun pwq->error = 0;
127*4882a593Smuzhiyun pwq->table = NULL;
128*4882a593Smuzhiyun pwq->inline_index = 0;
129*4882a593Smuzhiyun }
130*4882a593Smuzhiyun EXPORT_SYMBOL(poll_initwait);
131*4882a593Smuzhiyun
free_poll_entry(struct poll_table_entry * entry)132*4882a593Smuzhiyun static void free_poll_entry(struct poll_table_entry *entry)
133*4882a593Smuzhiyun {
134*4882a593Smuzhiyun remove_wait_queue(entry->wait_address, &entry->wait);
135*4882a593Smuzhiyun fput(entry->filp);
136*4882a593Smuzhiyun }
137*4882a593Smuzhiyun
poll_freewait(struct poll_wqueues * pwq)138*4882a593Smuzhiyun void poll_freewait(struct poll_wqueues *pwq)
139*4882a593Smuzhiyun {
140*4882a593Smuzhiyun struct poll_table_page * p = pwq->table;
141*4882a593Smuzhiyun int i;
142*4882a593Smuzhiyun for (i = 0; i < pwq->inline_index; i++)
143*4882a593Smuzhiyun free_poll_entry(pwq->inline_entries + i);
144*4882a593Smuzhiyun while (p) {
145*4882a593Smuzhiyun struct poll_table_entry * entry;
146*4882a593Smuzhiyun struct poll_table_page *old;
147*4882a593Smuzhiyun
148*4882a593Smuzhiyun entry = p->entry;
149*4882a593Smuzhiyun do {
150*4882a593Smuzhiyun entry--;
151*4882a593Smuzhiyun free_poll_entry(entry);
152*4882a593Smuzhiyun } while (entry > p->entries);
153*4882a593Smuzhiyun old = p;
154*4882a593Smuzhiyun p = p->next;
155*4882a593Smuzhiyun free_page((unsigned long) old);
156*4882a593Smuzhiyun }
157*4882a593Smuzhiyun }
158*4882a593Smuzhiyun EXPORT_SYMBOL(poll_freewait);
159*4882a593Smuzhiyun
poll_get_entry(struct poll_wqueues * p)160*4882a593Smuzhiyun static struct poll_table_entry *poll_get_entry(struct poll_wqueues *p)
161*4882a593Smuzhiyun {
162*4882a593Smuzhiyun struct poll_table_page *table = p->table;
163*4882a593Smuzhiyun
164*4882a593Smuzhiyun if (p->inline_index < N_INLINE_POLL_ENTRIES)
165*4882a593Smuzhiyun return p->inline_entries + p->inline_index++;
166*4882a593Smuzhiyun
167*4882a593Smuzhiyun if (!table || POLL_TABLE_FULL(table)) {
168*4882a593Smuzhiyun struct poll_table_page *new_table;
169*4882a593Smuzhiyun
170*4882a593Smuzhiyun new_table = (struct poll_table_page *) __get_free_page(GFP_KERNEL);
171*4882a593Smuzhiyun if (!new_table) {
172*4882a593Smuzhiyun p->error = -ENOMEM;
173*4882a593Smuzhiyun return NULL;
174*4882a593Smuzhiyun }
175*4882a593Smuzhiyun new_table->entry = new_table->entries;
176*4882a593Smuzhiyun new_table->next = table;
177*4882a593Smuzhiyun p->table = new_table;
178*4882a593Smuzhiyun table = new_table;
179*4882a593Smuzhiyun }
180*4882a593Smuzhiyun
181*4882a593Smuzhiyun return table->entry++;
182*4882a593Smuzhiyun }
183*4882a593Smuzhiyun
__pollwake(wait_queue_entry_t * wait,unsigned mode,int sync,void * key)184*4882a593Smuzhiyun static int __pollwake(wait_queue_entry_t *wait, unsigned mode, int sync, void *key)
185*4882a593Smuzhiyun {
186*4882a593Smuzhiyun struct poll_wqueues *pwq = wait->private;
187*4882a593Smuzhiyun DECLARE_WAITQUEUE(dummy_wait, pwq->polling_task);
188*4882a593Smuzhiyun
189*4882a593Smuzhiyun /*
190*4882a593Smuzhiyun * Although this function is called under waitqueue lock, LOCK
191*4882a593Smuzhiyun * doesn't imply write barrier and the users expect write
192*4882a593Smuzhiyun * barrier semantics on wakeup functions. The following
193*4882a593Smuzhiyun * smp_wmb() is equivalent to smp_wmb() in try_to_wake_up()
194*4882a593Smuzhiyun * and is paired with smp_store_mb() in poll_schedule_timeout.
195*4882a593Smuzhiyun */
196*4882a593Smuzhiyun smp_wmb();
197*4882a593Smuzhiyun pwq->triggered = 1;
198*4882a593Smuzhiyun
199*4882a593Smuzhiyun /*
200*4882a593Smuzhiyun * Perform the default wake up operation using a dummy
201*4882a593Smuzhiyun * waitqueue.
202*4882a593Smuzhiyun *
203*4882a593Smuzhiyun * TODO: This is hacky but there currently is no interface to
204*4882a593Smuzhiyun * pass in @sync. @sync is scheduled to be removed and once
205*4882a593Smuzhiyun * that happens, wake_up_process() can be used directly.
206*4882a593Smuzhiyun */
207*4882a593Smuzhiyun return default_wake_function(&dummy_wait, mode, sync, key);
208*4882a593Smuzhiyun }
209*4882a593Smuzhiyun
pollwake(wait_queue_entry_t * wait,unsigned mode,int sync,void * key)210*4882a593Smuzhiyun static int pollwake(wait_queue_entry_t *wait, unsigned mode, int sync, void *key)
211*4882a593Smuzhiyun {
212*4882a593Smuzhiyun struct poll_table_entry *entry;
213*4882a593Smuzhiyun
214*4882a593Smuzhiyun entry = container_of(wait, struct poll_table_entry, wait);
215*4882a593Smuzhiyun if (key && !(key_to_poll(key) & entry->key))
216*4882a593Smuzhiyun return 0;
217*4882a593Smuzhiyun return __pollwake(wait, mode, sync, key);
218*4882a593Smuzhiyun }
219*4882a593Smuzhiyun
220*4882a593Smuzhiyun /* Add a new entry */
__pollwait(struct file * filp,wait_queue_head_t * wait_address,poll_table * p)221*4882a593Smuzhiyun static void __pollwait(struct file *filp, wait_queue_head_t *wait_address,
222*4882a593Smuzhiyun poll_table *p)
223*4882a593Smuzhiyun {
224*4882a593Smuzhiyun struct poll_wqueues *pwq = container_of(p, struct poll_wqueues, pt);
225*4882a593Smuzhiyun struct poll_table_entry *entry = poll_get_entry(pwq);
226*4882a593Smuzhiyun if (!entry)
227*4882a593Smuzhiyun return;
228*4882a593Smuzhiyun entry->filp = get_file(filp);
229*4882a593Smuzhiyun entry->wait_address = wait_address;
230*4882a593Smuzhiyun entry->key = p->_key;
231*4882a593Smuzhiyun init_waitqueue_func_entry(&entry->wait, pollwake);
232*4882a593Smuzhiyun entry->wait.private = pwq;
233*4882a593Smuzhiyun add_wait_queue(wait_address, &entry->wait);
234*4882a593Smuzhiyun }
235*4882a593Smuzhiyun
poll_schedule_timeout(struct poll_wqueues * pwq,int state,ktime_t * expires,unsigned long slack)236*4882a593Smuzhiyun static int poll_schedule_timeout(struct poll_wqueues *pwq, int state,
237*4882a593Smuzhiyun ktime_t *expires, unsigned long slack)
238*4882a593Smuzhiyun {
239*4882a593Smuzhiyun int rc = -EINTR;
240*4882a593Smuzhiyun
241*4882a593Smuzhiyun set_current_state(state);
242*4882a593Smuzhiyun if (!pwq->triggered)
243*4882a593Smuzhiyun rc = schedule_hrtimeout_range(expires, slack, HRTIMER_MODE_ABS);
244*4882a593Smuzhiyun __set_current_state(TASK_RUNNING);
245*4882a593Smuzhiyun
246*4882a593Smuzhiyun /*
247*4882a593Smuzhiyun * Prepare for the next iteration.
248*4882a593Smuzhiyun *
249*4882a593Smuzhiyun * The following smp_store_mb() serves two purposes. First, it's
250*4882a593Smuzhiyun * the counterpart rmb of the wmb in pollwake() such that data
251*4882a593Smuzhiyun * written before wake up is always visible after wake up.
252*4882a593Smuzhiyun * Second, the full barrier guarantees that triggered clearing
253*4882a593Smuzhiyun * doesn't pass event check of the next iteration. Note that
254*4882a593Smuzhiyun * this problem doesn't exist for the first iteration as
255*4882a593Smuzhiyun * add_wait_queue() has full barrier semantics.
256*4882a593Smuzhiyun */
257*4882a593Smuzhiyun smp_store_mb(pwq->triggered, 0);
258*4882a593Smuzhiyun
259*4882a593Smuzhiyun return rc;
260*4882a593Smuzhiyun }
261*4882a593Smuzhiyun
262*4882a593Smuzhiyun /**
263*4882a593Smuzhiyun * poll_select_set_timeout - helper function to setup the timeout value
264*4882a593Smuzhiyun * @to: pointer to timespec64 variable for the final timeout
265*4882a593Smuzhiyun * @sec: seconds (from user space)
266*4882a593Smuzhiyun * @nsec: nanoseconds (from user space)
267*4882a593Smuzhiyun *
268*4882a593Smuzhiyun * Note, we do not use a timespec for the user space value here, That
269*4882a593Smuzhiyun * way we can use the function for timeval and compat interfaces as well.
270*4882a593Smuzhiyun *
271*4882a593Smuzhiyun * Returns -EINVAL if sec/nsec are not normalized. Otherwise 0.
272*4882a593Smuzhiyun */
poll_select_set_timeout(struct timespec64 * to,time64_t sec,long nsec)273*4882a593Smuzhiyun int poll_select_set_timeout(struct timespec64 *to, time64_t sec, long nsec)
274*4882a593Smuzhiyun {
275*4882a593Smuzhiyun struct timespec64 ts = {.tv_sec = sec, .tv_nsec = nsec};
276*4882a593Smuzhiyun
277*4882a593Smuzhiyun if (!timespec64_valid(&ts))
278*4882a593Smuzhiyun return -EINVAL;
279*4882a593Smuzhiyun
280*4882a593Smuzhiyun /* Optimize for the zero timeout value here */
281*4882a593Smuzhiyun if (!sec && !nsec) {
282*4882a593Smuzhiyun to->tv_sec = to->tv_nsec = 0;
283*4882a593Smuzhiyun } else {
284*4882a593Smuzhiyun ktime_get_ts64(to);
285*4882a593Smuzhiyun *to = timespec64_add_safe(*to, ts);
286*4882a593Smuzhiyun }
287*4882a593Smuzhiyun return 0;
288*4882a593Smuzhiyun }
289*4882a593Smuzhiyun
290*4882a593Smuzhiyun enum poll_time_type {
291*4882a593Smuzhiyun PT_TIMEVAL = 0,
292*4882a593Smuzhiyun PT_OLD_TIMEVAL = 1,
293*4882a593Smuzhiyun PT_TIMESPEC = 2,
294*4882a593Smuzhiyun PT_OLD_TIMESPEC = 3,
295*4882a593Smuzhiyun };
296*4882a593Smuzhiyun
poll_select_finish(struct timespec64 * end_time,void __user * p,enum poll_time_type pt_type,int ret)297*4882a593Smuzhiyun static int poll_select_finish(struct timespec64 *end_time,
298*4882a593Smuzhiyun void __user *p,
299*4882a593Smuzhiyun enum poll_time_type pt_type, int ret)
300*4882a593Smuzhiyun {
301*4882a593Smuzhiyun struct timespec64 rts;
302*4882a593Smuzhiyun
303*4882a593Smuzhiyun restore_saved_sigmask_unless(ret == -ERESTARTNOHAND);
304*4882a593Smuzhiyun
305*4882a593Smuzhiyun if (!p)
306*4882a593Smuzhiyun return ret;
307*4882a593Smuzhiyun
308*4882a593Smuzhiyun if (current->personality & STICKY_TIMEOUTS)
309*4882a593Smuzhiyun goto sticky;
310*4882a593Smuzhiyun
311*4882a593Smuzhiyun /* No update for zero timeout */
312*4882a593Smuzhiyun if (!end_time->tv_sec && !end_time->tv_nsec)
313*4882a593Smuzhiyun return ret;
314*4882a593Smuzhiyun
315*4882a593Smuzhiyun ktime_get_ts64(&rts);
316*4882a593Smuzhiyun rts = timespec64_sub(*end_time, rts);
317*4882a593Smuzhiyun if (rts.tv_sec < 0)
318*4882a593Smuzhiyun rts.tv_sec = rts.tv_nsec = 0;
319*4882a593Smuzhiyun
320*4882a593Smuzhiyun
321*4882a593Smuzhiyun switch (pt_type) {
322*4882a593Smuzhiyun case PT_TIMEVAL:
323*4882a593Smuzhiyun {
324*4882a593Smuzhiyun struct __kernel_old_timeval rtv;
325*4882a593Smuzhiyun
326*4882a593Smuzhiyun if (sizeof(rtv) > sizeof(rtv.tv_sec) + sizeof(rtv.tv_usec))
327*4882a593Smuzhiyun memset(&rtv, 0, sizeof(rtv));
328*4882a593Smuzhiyun rtv.tv_sec = rts.tv_sec;
329*4882a593Smuzhiyun rtv.tv_usec = rts.tv_nsec / NSEC_PER_USEC;
330*4882a593Smuzhiyun if (!copy_to_user(p, &rtv, sizeof(rtv)))
331*4882a593Smuzhiyun return ret;
332*4882a593Smuzhiyun }
333*4882a593Smuzhiyun break;
334*4882a593Smuzhiyun case PT_OLD_TIMEVAL:
335*4882a593Smuzhiyun {
336*4882a593Smuzhiyun struct old_timeval32 rtv;
337*4882a593Smuzhiyun
338*4882a593Smuzhiyun rtv.tv_sec = rts.tv_sec;
339*4882a593Smuzhiyun rtv.tv_usec = rts.tv_nsec / NSEC_PER_USEC;
340*4882a593Smuzhiyun if (!copy_to_user(p, &rtv, sizeof(rtv)))
341*4882a593Smuzhiyun return ret;
342*4882a593Smuzhiyun }
343*4882a593Smuzhiyun break;
344*4882a593Smuzhiyun case PT_TIMESPEC:
345*4882a593Smuzhiyun if (!put_timespec64(&rts, p))
346*4882a593Smuzhiyun return ret;
347*4882a593Smuzhiyun break;
348*4882a593Smuzhiyun case PT_OLD_TIMESPEC:
349*4882a593Smuzhiyun if (!put_old_timespec32(&rts, p))
350*4882a593Smuzhiyun return ret;
351*4882a593Smuzhiyun break;
352*4882a593Smuzhiyun default:
353*4882a593Smuzhiyun BUG();
354*4882a593Smuzhiyun }
355*4882a593Smuzhiyun /*
356*4882a593Smuzhiyun * If an application puts its timeval in read-only memory, we
357*4882a593Smuzhiyun * don't want the Linux-specific update to the timeval to
358*4882a593Smuzhiyun * cause a fault after the select has completed
359*4882a593Smuzhiyun * successfully. However, because we're not updating the
360*4882a593Smuzhiyun * timeval, we can't restart the system call.
361*4882a593Smuzhiyun */
362*4882a593Smuzhiyun
363*4882a593Smuzhiyun sticky:
364*4882a593Smuzhiyun if (ret == -ERESTARTNOHAND)
365*4882a593Smuzhiyun ret = -EINTR;
366*4882a593Smuzhiyun return ret;
367*4882a593Smuzhiyun }
368*4882a593Smuzhiyun
369*4882a593Smuzhiyun /*
370*4882a593Smuzhiyun * Scalable version of the fd_set.
371*4882a593Smuzhiyun */
372*4882a593Smuzhiyun
373*4882a593Smuzhiyun typedef struct {
374*4882a593Smuzhiyun unsigned long *in, *out, *ex;
375*4882a593Smuzhiyun unsigned long *res_in, *res_out, *res_ex;
376*4882a593Smuzhiyun } fd_set_bits;
377*4882a593Smuzhiyun
378*4882a593Smuzhiyun /*
379*4882a593Smuzhiyun * How many longwords for "nr" bits?
380*4882a593Smuzhiyun */
381*4882a593Smuzhiyun #define FDS_BITPERLONG (8*sizeof(long))
382*4882a593Smuzhiyun #define FDS_LONGS(nr) (((nr)+FDS_BITPERLONG-1)/FDS_BITPERLONG)
383*4882a593Smuzhiyun #define FDS_BYTES(nr) (FDS_LONGS(nr)*sizeof(long))
384*4882a593Smuzhiyun
385*4882a593Smuzhiyun /*
386*4882a593Smuzhiyun * Use "unsigned long" accesses to let user-mode fd_set's be long-aligned.
387*4882a593Smuzhiyun */
388*4882a593Smuzhiyun static inline
get_fd_set(unsigned long nr,void __user * ufdset,unsigned long * fdset)389*4882a593Smuzhiyun int get_fd_set(unsigned long nr, void __user *ufdset, unsigned long *fdset)
390*4882a593Smuzhiyun {
391*4882a593Smuzhiyun nr = FDS_BYTES(nr);
392*4882a593Smuzhiyun if (ufdset)
393*4882a593Smuzhiyun return copy_from_user(fdset, ufdset, nr) ? -EFAULT : 0;
394*4882a593Smuzhiyun
395*4882a593Smuzhiyun memset(fdset, 0, nr);
396*4882a593Smuzhiyun return 0;
397*4882a593Smuzhiyun }
398*4882a593Smuzhiyun
399*4882a593Smuzhiyun static inline unsigned long __must_check
set_fd_set(unsigned long nr,void __user * ufdset,unsigned long * fdset)400*4882a593Smuzhiyun set_fd_set(unsigned long nr, void __user *ufdset, unsigned long *fdset)
401*4882a593Smuzhiyun {
402*4882a593Smuzhiyun if (ufdset)
403*4882a593Smuzhiyun return __copy_to_user(ufdset, fdset, FDS_BYTES(nr));
404*4882a593Smuzhiyun return 0;
405*4882a593Smuzhiyun }
406*4882a593Smuzhiyun
407*4882a593Smuzhiyun static inline
zero_fd_set(unsigned long nr,unsigned long * fdset)408*4882a593Smuzhiyun void zero_fd_set(unsigned long nr, unsigned long *fdset)
409*4882a593Smuzhiyun {
410*4882a593Smuzhiyun memset(fdset, 0, FDS_BYTES(nr));
411*4882a593Smuzhiyun }
412*4882a593Smuzhiyun
413*4882a593Smuzhiyun #define FDS_IN(fds, n) (fds->in + n)
414*4882a593Smuzhiyun #define FDS_OUT(fds, n) (fds->out + n)
415*4882a593Smuzhiyun #define FDS_EX(fds, n) (fds->ex + n)
416*4882a593Smuzhiyun
417*4882a593Smuzhiyun #define BITS(fds, n) (*FDS_IN(fds, n)|*FDS_OUT(fds, n)|*FDS_EX(fds, n))
418*4882a593Smuzhiyun
max_select_fd(unsigned long n,fd_set_bits * fds)419*4882a593Smuzhiyun static int max_select_fd(unsigned long n, fd_set_bits *fds)
420*4882a593Smuzhiyun {
421*4882a593Smuzhiyun unsigned long *open_fds;
422*4882a593Smuzhiyun unsigned long set;
423*4882a593Smuzhiyun int max;
424*4882a593Smuzhiyun struct fdtable *fdt;
425*4882a593Smuzhiyun
426*4882a593Smuzhiyun /* handle last in-complete long-word first */
427*4882a593Smuzhiyun set = ~(~0UL << (n & (BITS_PER_LONG-1)));
428*4882a593Smuzhiyun n /= BITS_PER_LONG;
429*4882a593Smuzhiyun fdt = files_fdtable(current->files);
430*4882a593Smuzhiyun open_fds = fdt->open_fds + n;
431*4882a593Smuzhiyun max = 0;
432*4882a593Smuzhiyun if (set) {
433*4882a593Smuzhiyun set &= BITS(fds, n);
434*4882a593Smuzhiyun if (set) {
435*4882a593Smuzhiyun if (!(set & ~*open_fds))
436*4882a593Smuzhiyun goto get_max;
437*4882a593Smuzhiyun return -EBADF;
438*4882a593Smuzhiyun }
439*4882a593Smuzhiyun }
440*4882a593Smuzhiyun while (n) {
441*4882a593Smuzhiyun open_fds--;
442*4882a593Smuzhiyun n--;
443*4882a593Smuzhiyun set = BITS(fds, n);
444*4882a593Smuzhiyun if (!set)
445*4882a593Smuzhiyun continue;
446*4882a593Smuzhiyun if (set & ~*open_fds)
447*4882a593Smuzhiyun return -EBADF;
448*4882a593Smuzhiyun if (max)
449*4882a593Smuzhiyun continue;
450*4882a593Smuzhiyun get_max:
451*4882a593Smuzhiyun do {
452*4882a593Smuzhiyun max++;
453*4882a593Smuzhiyun set >>= 1;
454*4882a593Smuzhiyun } while (set);
455*4882a593Smuzhiyun max += n * BITS_PER_LONG;
456*4882a593Smuzhiyun }
457*4882a593Smuzhiyun
458*4882a593Smuzhiyun return max;
459*4882a593Smuzhiyun }
460*4882a593Smuzhiyun
461*4882a593Smuzhiyun #define POLLIN_SET (EPOLLRDNORM | EPOLLRDBAND | EPOLLIN | EPOLLHUP | EPOLLERR |\
462*4882a593Smuzhiyun EPOLLNVAL)
463*4882a593Smuzhiyun #define POLLOUT_SET (EPOLLWRBAND | EPOLLWRNORM | EPOLLOUT | EPOLLERR |\
464*4882a593Smuzhiyun EPOLLNVAL)
465*4882a593Smuzhiyun #define POLLEX_SET (EPOLLPRI | EPOLLNVAL)
466*4882a593Smuzhiyun
wait_key_set(poll_table * wait,unsigned long in,unsigned long out,unsigned long bit,__poll_t ll_flag)467*4882a593Smuzhiyun static inline void wait_key_set(poll_table *wait, unsigned long in,
468*4882a593Smuzhiyun unsigned long out, unsigned long bit,
469*4882a593Smuzhiyun __poll_t ll_flag)
470*4882a593Smuzhiyun {
471*4882a593Smuzhiyun wait->_key = POLLEX_SET | ll_flag;
472*4882a593Smuzhiyun if (in & bit)
473*4882a593Smuzhiyun wait->_key |= POLLIN_SET;
474*4882a593Smuzhiyun if (out & bit)
475*4882a593Smuzhiyun wait->_key |= POLLOUT_SET;
476*4882a593Smuzhiyun }
477*4882a593Smuzhiyun
do_select(int n,fd_set_bits * fds,struct timespec64 * end_time)478*4882a593Smuzhiyun static int do_select(int n, fd_set_bits *fds, struct timespec64 *end_time)
479*4882a593Smuzhiyun {
480*4882a593Smuzhiyun ktime_t expire, *to = NULL;
481*4882a593Smuzhiyun struct poll_wqueues table;
482*4882a593Smuzhiyun poll_table *wait;
483*4882a593Smuzhiyun int retval, i, timed_out = 0;
484*4882a593Smuzhiyun u64 slack = 0;
485*4882a593Smuzhiyun __poll_t busy_flag = net_busy_loop_on() ? POLL_BUSY_LOOP : 0;
486*4882a593Smuzhiyun unsigned long busy_start = 0;
487*4882a593Smuzhiyun
488*4882a593Smuzhiyun rcu_read_lock();
489*4882a593Smuzhiyun retval = max_select_fd(n, fds);
490*4882a593Smuzhiyun rcu_read_unlock();
491*4882a593Smuzhiyun
492*4882a593Smuzhiyun if (retval < 0)
493*4882a593Smuzhiyun return retval;
494*4882a593Smuzhiyun n = retval;
495*4882a593Smuzhiyun
496*4882a593Smuzhiyun poll_initwait(&table);
497*4882a593Smuzhiyun wait = &table.pt;
498*4882a593Smuzhiyun if (end_time && !end_time->tv_sec && !end_time->tv_nsec) {
499*4882a593Smuzhiyun wait->_qproc = NULL;
500*4882a593Smuzhiyun timed_out = 1;
501*4882a593Smuzhiyun }
502*4882a593Smuzhiyun
503*4882a593Smuzhiyun if (end_time && !timed_out)
504*4882a593Smuzhiyun slack = select_estimate_accuracy(end_time);
505*4882a593Smuzhiyun
506*4882a593Smuzhiyun retval = 0;
507*4882a593Smuzhiyun for (;;) {
508*4882a593Smuzhiyun unsigned long *rinp, *routp, *rexp, *inp, *outp, *exp;
509*4882a593Smuzhiyun bool can_busy_loop = false;
510*4882a593Smuzhiyun
511*4882a593Smuzhiyun inp = fds->in; outp = fds->out; exp = fds->ex;
512*4882a593Smuzhiyun rinp = fds->res_in; routp = fds->res_out; rexp = fds->res_ex;
513*4882a593Smuzhiyun
514*4882a593Smuzhiyun for (i = 0; i < n; ++rinp, ++routp, ++rexp) {
515*4882a593Smuzhiyun unsigned long in, out, ex, all_bits, bit = 1, j;
516*4882a593Smuzhiyun unsigned long res_in = 0, res_out = 0, res_ex = 0;
517*4882a593Smuzhiyun __poll_t mask;
518*4882a593Smuzhiyun
519*4882a593Smuzhiyun in = *inp++; out = *outp++; ex = *exp++;
520*4882a593Smuzhiyun all_bits = in | out | ex;
521*4882a593Smuzhiyun if (all_bits == 0) {
522*4882a593Smuzhiyun i += BITS_PER_LONG;
523*4882a593Smuzhiyun continue;
524*4882a593Smuzhiyun }
525*4882a593Smuzhiyun
526*4882a593Smuzhiyun for (j = 0; j < BITS_PER_LONG; ++j, ++i, bit <<= 1) {
527*4882a593Smuzhiyun struct fd f;
528*4882a593Smuzhiyun if (i >= n)
529*4882a593Smuzhiyun break;
530*4882a593Smuzhiyun if (!(bit & all_bits))
531*4882a593Smuzhiyun continue;
532*4882a593Smuzhiyun mask = EPOLLNVAL;
533*4882a593Smuzhiyun f = fdget(i);
534*4882a593Smuzhiyun if (f.file) {
535*4882a593Smuzhiyun wait_key_set(wait, in, out, bit,
536*4882a593Smuzhiyun busy_flag);
537*4882a593Smuzhiyun mask = vfs_poll(f.file, wait);
538*4882a593Smuzhiyun
539*4882a593Smuzhiyun fdput(f);
540*4882a593Smuzhiyun }
541*4882a593Smuzhiyun if ((mask & POLLIN_SET) && (in & bit)) {
542*4882a593Smuzhiyun res_in |= bit;
543*4882a593Smuzhiyun retval++;
544*4882a593Smuzhiyun wait->_qproc = NULL;
545*4882a593Smuzhiyun }
546*4882a593Smuzhiyun if ((mask & POLLOUT_SET) && (out & bit)) {
547*4882a593Smuzhiyun res_out |= bit;
548*4882a593Smuzhiyun retval++;
549*4882a593Smuzhiyun wait->_qproc = NULL;
550*4882a593Smuzhiyun }
551*4882a593Smuzhiyun if ((mask & POLLEX_SET) && (ex & bit)) {
552*4882a593Smuzhiyun res_ex |= bit;
553*4882a593Smuzhiyun retval++;
554*4882a593Smuzhiyun wait->_qproc = NULL;
555*4882a593Smuzhiyun }
556*4882a593Smuzhiyun /* got something, stop busy polling */
557*4882a593Smuzhiyun if (retval) {
558*4882a593Smuzhiyun can_busy_loop = false;
559*4882a593Smuzhiyun busy_flag = 0;
560*4882a593Smuzhiyun
561*4882a593Smuzhiyun /*
562*4882a593Smuzhiyun * only remember a returned
563*4882a593Smuzhiyun * POLL_BUSY_LOOP if we asked for it
564*4882a593Smuzhiyun */
565*4882a593Smuzhiyun } else if (busy_flag & mask)
566*4882a593Smuzhiyun can_busy_loop = true;
567*4882a593Smuzhiyun
568*4882a593Smuzhiyun }
569*4882a593Smuzhiyun if (res_in)
570*4882a593Smuzhiyun *rinp = res_in;
571*4882a593Smuzhiyun if (res_out)
572*4882a593Smuzhiyun *routp = res_out;
573*4882a593Smuzhiyun if (res_ex)
574*4882a593Smuzhiyun *rexp = res_ex;
575*4882a593Smuzhiyun cond_resched();
576*4882a593Smuzhiyun }
577*4882a593Smuzhiyun wait->_qproc = NULL;
578*4882a593Smuzhiyun if (retval || timed_out || signal_pending(current))
579*4882a593Smuzhiyun break;
580*4882a593Smuzhiyun if (table.error) {
581*4882a593Smuzhiyun retval = table.error;
582*4882a593Smuzhiyun break;
583*4882a593Smuzhiyun }
584*4882a593Smuzhiyun
585*4882a593Smuzhiyun /* only if found POLL_BUSY_LOOP sockets && not out of time */
586*4882a593Smuzhiyun if (can_busy_loop && !need_resched()) {
587*4882a593Smuzhiyun if (!busy_start) {
588*4882a593Smuzhiyun busy_start = busy_loop_current_time();
589*4882a593Smuzhiyun continue;
590*4882a593Smuzhiyun }
591*4882a593Smuzhiyun if (!busy_loop_timeout(busy_start))
592*4882a593Smuzhiyun continue;
593*4882a593Smuzhiyun }
594*4882a593Smuzhiyun busy_flag = 0;
595*4882a593Smuzhiyun
596*4882a593Smuzhiyun /*
597*4882a593Smuzhiyun * If this is the first loop and we have a timeout
598*4882a593Smuzhiyun * given, then we convert to ktime_t and set the to
599*4882a593Smuzhiyun * pointer to the expiry value.
600*4882a593Smuzhiyun */
601*4882a593Smuzhiyun if (end_time && !to) {
602*4882a593Smuzhiyun expire = timespec64_to_ktime(*end_time);
603*4882a593Smuzhiyun to = &expire;
604*4882a593Smuzhiyun }
605*4882a593Smuzhiyun
606*4882a593Smuzhiyun if (!poll_schedule_timeout(&table, TASK_INTERRUPTIBLE,
607*4882a593Smuzhiyun to, slack))
608*4882a593Smuzhiyun timed_out = 1;
609*4882a593Smuzhiyun }
610*4882a593Smuzhiyun
611*4882a593Smuzhiyun poll_freewait(&table);
612*4882a593Smuzhiyun
613*4882a593Smuzhiyun return retval;
614*4882a593Smuzhiyun }
615*4882a593Smuzhiyun
616*4882a593Smuzhiyun /*
617*4882a593Smuzhiyun * We can actually return ERESTARTSYS instead of EINTR, but I'd
618*4882a593Smuzhiyun * like to be certain this leads to no problems. So I return
619*4882a593Smuzhiyun * EINTR just for safety.
620*4882a593Smuzhiyun *
621*4882a593Smuzhiyun * Update: ERESTARTSYS breaks at least the xview clock binary, so
622*4882a593Smuzhiyun * I'm trying ERESTARTNOHAND which restart only when you want to.
623*4882a593Smuzhiyun */
core_sys_select(int n,fd_set __user * inp,fd_set __user * outp,fd_set __user * exp,struct timespec64 * end_time)624*4882a593Smuzhiyun int core_sys_select(int n, fd_set __user *inp, fd_set __user *outp,
625*4882a593Smuzhiyun fd_set __user *exp, struct timespec64 *end_time)
626*4882a593Smuzhiyun {
627*4882a593Smuzhiyun fd_set_bits fds;
628*4882a593Smuzhiyun void *bits;
629*4882a593Smuzhiyun int ret, max_fds;
630*4882a593Smuzhiyun size_t size, alloc_size;
631*4882a593Smuzhiyun struct fdtable *fdt;
632*4882a593Smuzhiyun /* Allocate small arguments on the stack to save memory and be faster */
633*4882a593Smuzhiyun long stack_fds[SELECT_STACK_ALLOC/sizeof(long)];
634*4882a593Smuzhiyun
635*4882a593Smuzhiyun ret = -EINVAL;
636*4882a593Smuzhiyun if (n < 0)
637*4882a593Smuzhiyun goto out_nofds;
638*4882a593Smuzhiyun
639*4882a593Smuzhiyun /* max_fds can increase, so grab it once to avoid race */
640*4882a593Smuzhiyun rcu_read_lock();
641*4882a593Smuzhiyun fdt = files_fdtable(current->files);
642*4882a593Smuzhiyun max_fds = fdt->max_fds;
643*4882a593Smuzhiyun rcu_read_unlock();
644*4882a593Smuzhiyun if (n > max_fds)
645*4882a593Smuzhiyun n = max_fds;
646*4882a593Smuzhiyun
647*4882a593Smuzhiyun /*
648*4882a593Smuzhiyun * We need 6 bitmaps (in/out/ex for both incoming and outgoing),
649*4882a593Smuzhiyun * since we used fdset we need to allocate memory in units of
650*4882a593Smuzhiyun * long-words.
651*4882a593Smuzhiyun */
652*4882a593Smuzhiyun size = FDS_BYTES(n);
653*4882a593Smuzhiyun bits = stack_fds;
654*4882a593Smuzhiyun if (size > sizeof(stack_fds) / 6) {
655*4882a593Smuzhiyun /* Not enough space in on-stack array; must use kmalloc */
656*4882a593Smuzhiyun ret = -ENOMEM;
657*4882a593Smuzhiyun if (size > (SIZE_MAX / 6))
658*4882a593Smuzhiyun goto out_nofds;
659*4882a593Smuzhiyun
660*4882a593Smuzhiyun alloc_size = 6 * size;
661*4882a593Smuzhiyun bits = kvmalloc(alloc_size, GFP_KERNEL);
662*4882a593Smuzhiyun if (!bits)
663*4882a593Smuzhiyun goto out_nofds;
664*4882a593Smuzhiyun }
665*4882a593Smuzhiyun fds.in = bits;
666*4882a593Smuzhiyun fds.out = bits + size;
667*4882a593Smuzhiyun fds.ex = bits + 2*size;
668*4882a593Smuzhiyun fds.res_in = bits + 3*size;
669*4882a593Smuzhiyun fds.res_out = bits + 4*size;
670*4882a593Smuzhiyun fds.res_ex = bits + 5*size;
671*4882a593Smuzhiyun
672*4882a593Smuzhiyun if ((ret = get_fd_set(n, inp, fds.in)) ||
673*4882a593Smuzhiyun (ret = get_fd_set(n, outp, fds.out)) ||
674*4882a593Smuzhiyun (ret = get_fd_set(n, exp, fds.ex)))
675*4882a593Smuzhiyun goto out;
676*4882a593Smuzhiyun zero_fd_set(n, fds.res_in);
677*4882a593Smuzhiyun zero_fd_set(n, fds.res_out);
678*4882a593Smuzhiyun zero_fd_set(n, fds.res_ex);
679*4882a593Smuzhiyun
680*4882a593Smuzhiyun ret = do_select(n, &fds, end_time);
681*4882a593Smuzhiyun
682*4882a593Smuzhiyun if (ret < 0)
683*4882a593Smuzhiyun goto out;
684*4882a593Smuzhiyun if (!ret) {
685*4882a593Smuzhiyun ret = -ERESTARTNOHAND;
686*4882a593Smuzhiyun if (signal_pending(current))
687*4882a593Smuzhiyun goto out;
688*4882a593Smuzhiyun ret = 0;
689*4882a593Smuzhiyun }
690*4882a593Smuzhiyun
691*4882a593Smuzhiyun if (set_fd_set(n, inp, fds.res_in) ||
692*4882a593Smuzhiyun set_fd_set(n, outp, fds.res_out) ||
693*4882a593Smuzhiyun set_fd_set(n, exp, fds.res_ex))
694*4882a593Smuzhiyun ret = -EFAULT;
695*4882a593Smuzhiyun
696*4882a593Smuzhiyun out:
697*4882a593Smuzhiyun if (bits != stack_fds)
698*4882a593Smuzhiyun kvfree(bits);
699*4882a593Smuzhiyun out_nofds:
700*4882a593Smuzhiyun return ret;
701*4882a593Smuzhiyun }
702*4882a593Smuzhiyun
kern_select(int n,fd_set __user * inp,fd_set __user * outp,fd_set __user * exp,struct __kernel_old_timeval __user * tvp)703*4882a593Smuzhiyun static int kern_select(int n, fd_set __user *inp, fd_set __user *outp,
704*4882a593Smuzhiyun fd_set __user *exp, struct __kernel_old_timeval __user *tvp)
705*4882a593Smuzhiyun {
706*4882a593Smuzhiyun struct timespec64 end_time, *to = NULL;
707*4882a593Smuzhiyun struct __kernel_old_timeval tv;
708*4882a593Smuzhiyun int ret;
709*4882a593Smuzhiyun
710*4882a593Smuzhiyun if (tvp) {
711*4882a593Smuzhiyun if (copy_from_user(&tv, tvp, sizeof(tv)))
712*4882a593Smuzhiyun return -EFAULT;
713*4882a593Smuzhiyun
714*4882a593Smuzhiyun to = &end_time;
715*4882a593Smuzhiyun if (poll_select_set_timeout(to,
716*4882a593Smuzhiyun tv.tv_sec + (tv.tv_usec / USEC_PER_SEC),
717*4882a593Smuzhiyun (tv.tv_usec % USEC_PER_SEC) * NSEC_PER_USEC))
718*4882a593Smuzhiyun return -EINVAL;
719*4882a593Smuzhiyun }
720*4882a593Smuzhiyun
721*4882a593Smuzhiyun ret = core_sys_select(n, inp, outp, exp, to);
722*4882a593Smuzhiyun return poll_select_finish(&end_time, tvp, PT_TIMEVAL, ret);
723*4882a593Smuzhiyun }
724*4882a593Smuzhiyun
SYSCALL_DEFINE5(select,int,n,fd_set __user *,inp,fd_set __user *,outp,fd_set __user *,exp,struct __kernel_old_timeval __user *,tvp)725*4882a593Smuzhiyun SYSCALL_DEFINE5(select, int, n, fd_set __user *, inp, fd_set __user *, outp,
726*4882a593Smuzhiyun fd_set __user *, exp, struct __kernel_old_timeval __user *, tvp)
727*4882a593Smuzhiyun {
728*4882a593Smuzhiyun return kern_select(n, inp, outp, exp, tvp);
729*4882a593Smuzhiyun }
730*4882a593Smuzhiyun
do_pselect(int n,fd_set __user * inp,fd_set __user * outp,fd_set __user * exp,void __user * tsp,const sigset_t __user * sigmask,size_t sigsetsize,enum poll_time_type type)731*4882a593Smuzhiyun static long do_pselect(int n, fd_set __user *inp, fd_set __user *outp,
732*4882a593Smuzhiyun fd_set __user *exp, void __user *tsp,
733*4882a593Smuzhiyun const sigset_t __user *sigmask, size_t sigsetsize,
734*4882a593Smuzhiyun enum poll_time_type type)
735*4882a593Smuzhiyun {
736*4882a593Smuzhiyun struct timespec64 ts, end_time, *to = NULL;
737*4882a593Smuzhiyun int ret;
738*4882a593Smuzhiyun
739*4882a593Smuzhiyun if (tsp) {
740*4882a593Smuzhiyun switch (type) {
741*4882a593Smuzhiyun case PT_TIMESPEC:
742*4882a593Smuzhiyun if (get_timespec64(&ts, tsp))
743*4882a593Smuzhiyun return -EFAULT;
744*4882a593Smuzhiyun break;
745*4882a593Smuzhiyun case PT_OLD_TIMESPEC:
746*4882a593Smuzhiyun if (get_old_timespec32(&ts, tsp))
747*4882a593Smuzhiyun return -EFAULT;
748*4882a593Smuzhiyun break;
749*4882a593Smuzhiyun default:
750*4882a593Smuzhiyun BUG();
751*4882a593Smuzhiyun }
752*4882a593Smuzhiyun
753*4882a593Smuzhiyun to = &end_time;
754*4882a593Smuzhiyun if (poll_select_set_timeout(to, ts.tv_sec, ts.tv_nsec))
755*4882a593Smuzhiyun return -EINVAL;
756*4882a593Smuzhiyun }
757*4882a593Smuzhiyun
758*4882a593Smuzhiyun ret = set_user_sigmask(sigmask, sigsetsize);
759*4882a593Smuzhiyun if (ret)
760*4882a593Smuzhiyun return ret;
761*4882a593Smuzhiyun
762*4882a593Smuzhiyun ret = core_sys_select(n, inp, outp, exp, to);
763*4882a593Smuzhiyun return poll_select_finish(&end_time, tsp, type, ret);
764*4882a593Smuzhiyun }
765*4882a593Smuzhiyun
766*4882a593Smuzhiyun /*
767*4882a593Smuzhiyun * Most architectures can't handle 7-argument syscalls. So we provide a
768*4882a593Smuzhiyun * 6-argument version where the sixth argument is a pointer to a structure
769*4882a593Smuzhiyun * which has a pointer to the sigset_t itself followed by a size_t containing
770*4882a593Smuzhiyun * the sigset size.
771*4882a593Smuzhiyun */
772*4882a593Smuzhiyun struct sigset_argpack {
773*4882a593Smuzhiyun sigset_t __user *p;
774*4882a593Smuzhiyun size_t size;
775*4882a593Smuzhiyun };
776*4882a593Smuzhiyun
get_sigset_argpack(struct sigset_argpack * to,struct sigset_argpack __user * from)777*4882a593Smuzhiyun static inline int get_sigset_argpack(struct sigset_argpack *to,
778*4882a593Smuzhiyun struct sigset_argpack __user *from)
779*4882a593Smuzhiyun {
780*4882a593Smuzhiyun // the path is hot enough for overhead of copy_from_user() to matter
781*4882a593Smuzhiyun if (from) {
782*4882a593Smuzhiyun if (!user_read_access_begin(from, sizeof(*from)))
783*4882a593Smuzhiyun return -EFAULT;
784*4882a593Smuzhiyun unsafe_get_user(to->p, &from->p, Efault);
785*4882a593Smuzhiyun unsafe_get_user(to->size, &from->size, Efault);
786*4882a593Smuzhiyun user_read_access_end();
787*4882a593Smuzhiyun }
788*4882a593Smuzhiyun return 0;
789*4882a593Smuzhiyun Efault:
790*4882a593Smuzhiyun user_access_end();
791*4882a593Smuzhiyun return -EFAULT;
792*4882a593Smuzhiyun }
793*4882a593Smuzhiyun
SYSCALL_DEFINE6(pselect6,int,n,fd_set __user *,inp,fd_set __user *,outp,fd_set __user *,exp,struct __kernel_timespec __user *,tsp,void __user *,sig)794*4882a593Smuzhiyun SYSCALL_DEFINE6(pselect6, int, n, fd_set __user *, inp, fd_set __user *, outp,
795*4882a593Smuzhiyun fd_set __user *, exp, struct __kernel_timespec __user *, tsp,
796*4882a593Smuzhiyun void __user *, sig)
797*4882a593Smuzhiyun {
798*4882a593Smuzhiyun struct sigset_argpack x = {NULL, 0};
799*4882a593Smuzhiyun
800*4882a593Smuzhiyun if (get_sigset_argpack(&x, sig))
801*4882a593Smuzhiyun return -EFAULT;
802*4882a593Smuzhiyun
803*4882a593Smuzhiyun return do_pselect(n, inp, outp, exp, tsp, x.p, x.size, PT_TIMESPEC);
804*4882a593Smuzhiyun }
805*4882a593Smuzhiyun
806*4882a593Smuzhiyun #if defined(CONFIG_COMPAT_32BIT_TIME) && !defined(CONFIG_64BIT)
807*4882a593Smuzhiyun
SYSCALL_DEFINE6(pselect6_time32,int,n,fd_set __user *,inp,fd_set __user *,outp,fd_set __user *,exp,struct old_timespec32 __user *,tsp,void __user *,sig)808*4882a593Smuzhiyun SYSCALL_DEFINE6(pselect6_time32, int, n, fd_set __user *, inp, fd_set __user *, outp,
809*4882a593Smuzhiyun fd_set __user *, exp, struct old_timespec32 __user *, tsp,
810*4882a593Smuzhiyun void __user *, sig)
811*4882a593Smuzhiyun {
812*4882a593Smuzhiyun struct sigset_argpack x = {NULL, 0};
813*4882a593Smuzhiyun
814*4882a593Smuzhiyun if (get_sigset_argpack(&x, sig))
815*4882a593Smuzhiyun return -EFAULT;
816*4882a593Smuzhiyun
817*4882a593Smuzhiyun return do_pselect(n, inp, outp, exp, tsp, x.p, x.size, PT_OLD_TIMESPEC);
818*4882a593Smuzhiyun }
819*4882a593Smuzhiyun
820*4882a593Smuzhiyun #endif
821*4882a593Smuzhiyun
822*4882a593Smuzhiyun #ifdef __ARCH_WANT_SYS_OLD_SELECT
823*4882a593Smuzhiyun struct sel_arg_struct {
824*4882a593Smuzhiyun unsigned long n;
825*4882a593Smuzhiyun fd_set __user *inp, *outp, *exp;
826*4882a593Smuzhiyun struct __kernel_old_timeval __user *tvp;
827*4882a593Smuzhiyun };
828*4882a593Smuzhiyun
SYSCALL_DEFINE1(old_select,struct sel_arg_struct __user *,arg)829*4882a593Smuzhiyun SYSCALL_DEFINE1(old_select, struct sel_arg_struct __user *, arg)
830*4882a593Smuzhiyun {
831*4882a593Smuzhiyun struct sel_arg_struct a;
832*4882a593Smuzhiyun
833*4882a593Smuzhiyun if (copy_from_user(&a, arg, sizeof(a)))
834*4882a593Smuzhiyun return -EFAULT;
835*4882a593Smuzhiyun return kern_select(a.n, a.inp, a.outp, a.exp, a.tvp);
836*4882a593Smuzhiyun }
837*4882a593Smuzhiyun #endif
838*4882a593Smuzhiyun
839*4882a593Smuzhiyun struct poll_list {
840*4882a593Smuzhiyun struct poll_list *next;
841*4882a593Smuzhiyun int len;
842*4882a593Smuzhiyun struct pollfd entries[];
843*4882a593Smuzhiyun };
844*4882a593Smuzhiyun
845*4882a593Smuzhiyun #define POLLFD_PER_PAGE ((PAGE_SIZE-sizeof(struct poll_list)) / sizeof(struct pollfd))
846*4882a593Smuzhiyun
847*4882a593Smuzhiyun /*
848*4882a593Smuzhiyun * Fish for pollable events on the pollfd->fd file descriptor. We're only
849*4882a593Smuzhiyun * interested in events matching the pollfd->events mask, and the result
850*4882a593Smuzhiyun * matching that mask is both recorded in pollfd->revents and returned. The
851*4882a593Smuzhiyun * pwait poll_table will be used by the fd-provided poll handler for waiting,
852*4882a593Smuzhiyun * if pwait->_qproc is non-NULL.
853*4882a593Smuzhiyun */
do_pollfd(struct pollfd * pollfd,poll_table * pwait,bool * can_busy_poll,__poll_t busy_flag)854*4882a593Smuzhiyun static inline __poll_t do_pollfd(struct pollfd *pollfd, poll_table *pwait,
855*4882a593Smuzhiyun bool *can_busy_poll,
856*4882a593Smuzhiyun __poll_t busy_flag)
857*4882a593Smuzhiyun {
858*4882a593Smuzhiyun int fd = pollfd->fd;
859*4882a593Smuzhiyun __poll_t mask = 0, filter;
860*4882a593Smuzhiyun struct fd f;
861*4882a593Smuzhiyun
862*4882a593Smuzhiyun if (fd < 0)
863*4882a593Smuzhiyun goto out;
864*4882a593Smuzhiyun mask = EPOLLNVAL;
865*4882a593Smuzhiyun f = fdget(fd);
866*4882a593Smuzhiyun if (!f.file)
867*4882a593Smuzhiyun goto out;
868*4882a593Smuzhiyun
869*4882a593Smuzhiyun /* userland u16 ->events contains POLL... bitmap */
870*4882a593Smuzhiyun filter = demangle_poll(pollfd->events) | EPOLLERR | EPOLLHUP;
871*4882a593Smuzhiyun pwait->_key = filter | busy_flag;
872*4882a593Smuzhiyun mask = vfs_poll(f.file, pwait);
873*4882a593Smuzhiyun if (mask & busy_flag)
874*4882a593Smuzhiyun *can_busy_poll = true;
875*4882a593Smuzhiyun mask &= filter; /* Mask out unneeded events. */
876*4882a593Smuzhiyun fdput(f);
877*4882a593Smuzhiyun
878*4882a593Smuzhiyun out:
879*4882a593Smuzhiyun /* ... and so does ->revents */
880*4882a593Smuzhiyun pollfd->revents = mangle_poll(mask);
881*4882a593Smuzhiyun return mask;
882*4882a593Smuzhiyun }
883*4882a593Smuzhiyun
do_poll(struct poll_list * list,struct poll_wqueues * wait,struct timespec64 * end_time)884*4882a593Smuzhiyun static int do_poll(struct poll_list *list, struct poll_wqueues *wait,
885*4882a593Smuzhiyun struct timespec64 *end_time)
886*4882a593Smuzhiyun {
887*4882a593Smuzhiyun poll_table* pt = &wait->pt;
888*4882a593Smuzhiyun ktime_t expire, *to = NULL;
889*4882a593Smuzhiyun int timed_out = 0, count = 0;
890*4882a593Smuzhiyun u64 slack = 0;
891*4882a593Smuzhiyun __poll_t busy_flag = net_busy_loop_on() ? POLL_BUSY_LOOP : 0;
892*4882a593Smuzhiyun unsigned long busy_start = 0;
893*4882a593Smuzhiyun
894*4882a593Smuzhiyun /* Optimise the no-wait case */
895*4882a593Smuzhiyun if (end_time && !end_time->tv_sec && !end_time->tv_nsec) {
896*4882a593Smuzhiyun pt->_qproc = NULL;
897*4882a593Smuzhiyun timed_out = 1;
898*4882a593Smuzhiyun }
899*4882a593Smuzhiyun
900*4882a593Smuzhiyun if (end_time && !timed_out)
901*4882a593Smuzhiyun slack = select_estimate_accuracy(end_time);
902*4882a593Smuzhiyun
903*4882a593Smuzhiyun for (;;) {
904*4882a593Smuzhiyun struct poll_list *walk;
905*4882a593Smuzhiyun bool can_busy_loop = false;
906*4882a593Smuzhiyun
907*4882a593Smuzhiyun for (walk = list; walk != NULL; walk = walk->next) {
908*4882a593Smuzhiyun struct pollfd * pfd, * pfd_end;
909*4882a593Smuzhiyun
910*4882a593Smuzhiyun pfd = walk->entries;
911*4882a593Smuzhiyun pfd_end = pfd + walk->len;
912*4882a593Smuzhiyun for (; pfd != pfd_end; pfd++) {
913*4882a593Smuzhiyun /*
914*4882a593Smuzhiyun * Fish for events. If we found one, record it
915*4882a593Smuzhiyun * and kill poll_table->_qproc, so we don't
916*4882a593Smuzhiyun * needlessly register any other waiters after
917*4882a593Smuzhiyun * this. They'll get immediately deregistered
918*4882a593Smuzhiyun * when we break out and return.
919*4882a593Smuzhiyun */
920*4882a593Smuzhiyun if (do_pollfd(pfd, pt, &can_busy_loop,
921*4882a593Smuzhiyun busy_flag)) {
922*4882a593Smuzhiyun count++;
923*4882a593Smuzhiyun pt->_qproc = NULL;
924*4882a593Smuzhiyun /* found something, stop busy polling */
925*4882a593Smuzhiyun busy_flag = 0;
926*4882a593Smuzhiyun can_busy_loop = false;
927*4882a593Smuzhiyun }
928*4882a593Smuzhiyun }
929*4882a593Smuzhiyun }
930*4882a593Smuzhiyun /*
931*4882a593Smuzhiyun * All waiters have already been registered, so don't provide
932*4882a593Smuzhiyun * a poll_table->_qproc to them on the next loop iteration.
933*4882a593Smuzhiyun */
934*4882a593Smuzhiyun pt->_qproc = NULL;
935*4882a593Smuzhiyun if (!count) {
936*4882a593Smuzhiyun count = wait->error;
937*4882a593Smuzhiyun if (signal_pending(current))
938*4882a593Smuzhiyun count = -ERESTARTNOHAND;
939*4882a593Smuzhiyun }
940*4882a593Smuzhiyun if (count || timed_out)
941*4882a593Smuzhiyun break;
942*4882a593Smuzhiyun
943*4882a593Smuzhiyun /* only if found POLL_BUSY_LOOP sockets && not out of time */
944*4882a593Smuzhiyun if (can_busy_loop && !need_resched()) {
945*4882a593Smuzhiyun if (!busy_start) {
946*4882a593Smuzhiyun busy_start = busy_loop_current_time();
947*4882a593Smuzhiyun continue;
948*4882a593Smuzhiyun }
949*4882a593Smuzhiyun if (!busy_loop_timeout(busy_start))
950*4882a593Smuzhiyun continue;
951*4882a593Smuzhiyun }
952*4882a593Smuzhiyun busy_flag = 0;
953*4882a593Smuzhiyun
954*4882a593Smuzhiyun /*
955*4882a593Smuzhiyun * If this is the first loop and we have a timeout
956*4882a593Smuzhiyun * given, then we convert to ktime_t and set the to
957*4882a593Smuzhiyun * pointer to the expiry value.
958*4882a593Smuzhiyun */
959*4882a593Smuzhiyun if (end_time && !to) {
960*4882a593Smuzhiyun expire = timespec64_to_ktime(*end_time);
961*4882a593Smuzhiyun to = &expire;
962*4882a593Smuzhiyun }
963*4882a593Smuzhiyun
964*4882a593Smuzhiyun if (!poll_schedule_timeout(wait, TASK_INTERRUPTIBLE, to, slack))
965*4882a593Smuzhiyun timed_out = 1;
966*4882a593Smuzhiyun }
967*4882a593Smuzhiyun return count;
968*4882a593Smuzhiyun }
969*4882a593Smuzhiyun
970*4882a593Smuzhiyun #define N_STACK_PPS ((sizeof(stack_pps) - sizeof(struct poll_list)) / \
971*4882a593Smuzhiyun sizeof(struct pollfd))
972*4882a593Smuzhiyun
do_sys_poll(struct pollfd __user * ufds,unsigned int nfds,struct timespec64 * end_time)973*4882a593Smuzhiyun static int do_sys_poll(struct pollfd __user *ufds, unsigned int nfds,
974*4882a593Smuzhiyun struct timespec64 *end_time)
975*4882a593Smuzhiyun {
976*4882a593Smuzhiyun struct poll_wqueues table;
977*4882a593Smuzhiyun int err = -EFAULT, fdcount, len;
978*4882a593Smuzhiyun /* Allocate small arguments on the stack to save memory and be
979*4882a593Smuzhiyun faster - use long to make sure the buffer is aligned properly
980*4882a593Smuzhiyun on 64 bit archs to avoid unaligned access */
981*4882a593Smuzhiyun long stack_pps[POLL_STACK_ALLOC/sizeof(long)];
982*4882a593Smuzhiyun struct poll_list *const head = (struct poll_list *)stack_pps;
983*4882a593Smuzhiyun struct poll_list *walk = head;
984*4882a593Smuzhiyun unsigned long todo = nfds;
985*4882a593Smuzhiyun
986*4882a593Smuzhiyun if (nfds > rlimit(RLIMIT_NOFILE))
987*4882a593Smuzhiyun return -EINVAL;
988*4882a593Smuzhiyun
989*4882a593Smuzhiyun len = min_t(unsigned int, nfds, N_STACK_PPS);
990*4882a593Smuzhiyun for (;;) {
991*4882a593Smuzhiyun walk->next = NULL;
992*4882a593Smuzhiyun walk->len = len;
993*4882a593Smuzhiyun if (!len)
994*4882a593Smuzhiyun break;
995*4882a593Smuzhiyun
996*4882a593Smuzhiyun if (copy_from_user(walk->entries, ufds + nfds-todo,
997*4882a593Smuzhiyun sizeof(struct pollfd) * walk->len))
998*4882a593Smuzhiyun goto out_fds;
999*4882a593Smuzhiyun
1000*4882a593Smuzhiyun todo -= walk->len;
1001*4882a593Smuzhiyun if (!todo)
1002*4882a593Smuzhiyun break;
1003*4882a593Smuzhiyun
1004*4882a593Smuzhiyun len = min(todo, POLLFD_PER_PAGE);
1005*4882a593Smuzhiyun walk = walk->next = kmalloc(struct_size(walk, entries, len),
1006*4882a593Smuzhiyun GFP_KERNEL);
1007*4882a593Smuzhiyun if (!walk) {
1008*4882a593Smuzhiyun err = -ENOMEM;
1009*4882a593Smuzhiyun goto out_fds;
1010*4882a593Smuzhiyun }
1011*4882a593Smuzhiyun }
1012*4882a593Smuzhiyun
1013*4882a593Smuzhiyun poll_initwait(&table);
1014*4882a593Smuzhiyun fdcount = do_poll(head, &table, end_time);
1015*4882a593Smuzhiyun poll_freewait(&table);
1016*4882a593Smuzhiyun
1017*4882a593Smuzhiyun if (!user_write_access_begin(ufds, nfds * sizeof(*ufds)))
1018*4882a593Smuzhiyun goto out_fds;
1019*4882a593Smuzhiyun
1020*4882a593Smuzhiyun for (walk = head; walk; walk = walk->next) {
1021*4882a593Smuzhiyun struct pollfd *fds = walk->entries;
1022*4882a593Smuzhiyun int j;
1023*4882a593Smuzhiyun
1024*4882a593Smuzhiyun for (j = walk->len; j; fds++, ufds++, j--)
1025*4882a593Smuzhiyun unsafe_put_user(fds->revents, &ufds->revents, Efault);
1026*4882a593Smuzhiyun }
1027*4882a593Smuzhiyun user_write_access_end();
1028*4882a593Smuzhiyun
1029*4882a593Smuzhiyun err = fdcount;
1030*4882a593Smuzhiyun out_fds:
1031*4882a593Smuzhiyun walk = head->next;
1032*4882a593Smuzhiyun while (walk) {
1033*4882a593Smuzhiyun struct poll_list *pos = walk;
1034*4882a593Smuzhiyun walk = walk->next;
1035*4882a593Smuzhiyun kfree(pos);
1036*4882a593Smuzhiyun }
1037*4882a593Smuzhiyun
1038*4882a593Smuzhiyun return err;
1039*4882a593Smuzhiyun
1040*4882a593Smuzhiyun Efault:
1041*4882a593Smuzhiyun user_write_access_end();
1042*4882a593Smuzhiyun err = -EFAULT;
1043*4882a593Smuzhiyun goto out_fds;
1044*4882a593Smuzhiyun }
1045*4882a593Smuzhiyun
do_restart_poll(struct restart_block * restart_block)1046*4882a593Smuzhiyun static long do_restart_poll(struct restart_block *restart_block)
1047*4882a593Smuzhiyun {
1048*4882a593Smuzhiyun struct pollfd __user *ufds = restart_block->poll.ufds;
1049*4882a593Smuzhiyun int nfds = restart_block->poll.nfds;
1050*4882a593Smuzhiyun struct timespec64 *to = NULL, end_time;
1051*4882a593Smuzhiyun int ret;
1052*4882a593Smuzhiyun
1053*4882a593Smuzhiyun if (restart_block->poll.has_timeout) {
1054*4882a593Smuzhiyun end_time.tv_sec = restart_block->poll.tv_sec;
1055*4882a593Smuzhiyun end_time.tv_nsec = restart_block->poll.tv_nsec;
1056*4882a593Smuzhiyun to = &end_time;
1057*4882a593Smuzhiyun }
1058*4882a593Smuzhiyun
1059*4882a593Smuzhiyun ret = do_sys_poll(ufds, nfds, to);
1060*4882a593Smuzhiyun
1061*4882a593Smuzhiyun if (ret == -ERESTARTNOHAND)
1062*4882a593Smuzhiyun ret = set_restart_fn(restart_block, do_restart_poll);
1063*4882a593Smuzhiyun
1064*4882a593Smuzhiyun return ret;
1065*4882a593Smuzhiyun }
1066*4882a593Smuzhiyun
SYSCALL_DEFINE3(poll,struct pollfd __user *,ufds,unsigned int,nfds,int,timeout_msecs)1067*4882a593Smuzhiyun SYSCALL_DEFINE3(poll, struct pollfd __user *, ufds, unsigned int, nfds,
1068*4882a593Smuzhiyun int, timeout_msecs)
1069*4882a593Smuzhiyun {
1070*4882a593Smuzhiyun struct timespec64 end_time, *to = NULL;
1071*4882a593Smuzhiyun int ret;
1072*4882a593Smuzhiyun
1073*4882a593Smuzhiyun if (timeout_msecs >= 0) {
1074*4882a593Smuzhiyun to = &end_time;
1075*4882a593Smuzhiyun poll_select_set_timeout(to, timeout_msecs / MSEC_PER_SEC,
1076*4882a593Smuzhiyun NSEC_PER_MSEC * (timeout_msecs % MSEC_PER_SEC));
1077*4882a593Smuzhiyun }
1078*4882a593Smuzhiyun
1079*4882a593Smuzhiyun ret = do_sys_poll(ufds, nfds, to);
1080*4882a593Smuzhiyun
1081*4882a593Smuzhiyun if (ret == -ERESTARTNOHAND) {
1082*4882a593Smuzhiyun struct restart_block *restart_block;
1083*4882a593Smuzhiyun
1084*4882a593Smuzhiyun restart_block = ¤t->restart_block;
1085*4882a593Smuzhiyun restart_block->poll.ufds = ufds;
1086*4882a593Smuzhiyun restart_block->poll.nfds = nfds;
1087*4882a593Smuzhiyun
1088*4882a593Smuzhiyun if (timeout_msecs >= 0) {
1089*4882a593Smuzhiyun restart_block->poll.tv_sec = end_time.tv_sec;
1090*4882a593Smuzhiyun restart_block->poll.tv_nsec = end_time.tv_nsec;
1091*4882a593Smuzhiyun restart_block->poll.has_timeout = 1;
1092*4882a593Smuzhiyun } else
1093*4882a593Smuzhiyun restart_block->poll.has_timeout = 0;
1094*4882a593Smuzhiyun
1095*4882a593Smuzhiyun ret = set_restart_fn(restart_block, do_restart_poll);
1096*4882a593Smuzhiyun }
1097*4882a593Smuzhiyun return ret;
1098*4882a593Smuzhiyun }
1099*4882a593Smuzhiyun
SYSCALL_DEFINE5(ppoll,struct pollfd __user *,ufds,unsigned int,nfds,struct __kernel_timespec __user *,tsp,const sigset_t __user *,sigmask,size_t,sigsetsize)1100*4882a593Smuzhiyun SYSCALL_DEFINE5(ppoll, struct pollfd __user *, ufds, unsigned int, nfds,
1101*4882a593Smuzhiyun struct __kernel_timespec __user *, tsp, const sigset_t __user *, sigmask,
1102*4882a593Smuzhiyun size_t, sigsetsize)
1103*4882a593Smuzhiyun {
1104*4882a593Smuzhiyun struct timespec64 ts, end_time, *to = NULL;
1105*4882a593Smuzhiyun int ret;
1106*4882a593Smuzhiyun
1107*4882a593Smuzhiyun if (tsp) {
1108*4882a593Smuzhiyun if (get_timespec64(&ts, tsp))
1109*4882a593Smuzhiyun return -EFAULT;
1110*4882a593Smuzhiyun
1111*4882a593Smuzhiyun to = &end_time;
1112*4882a593Smuzhiyun if (poll_select_set_timeout(to, ts.tv_sec, ts.tv_nsec))
1113*4882a593Smuzhiyun return -EINVAL;
1114*4882a593Smuzhiyun }
1115*4882a593Smuzhiyun
1116*4882a593Smuzhiyun ret = set_user_sigmask(sigmask, sigsetsize);
1117*4882a593Smuzhiyun if (ret)
1118*4882a593Smuzhiyun return ret;
1119*4882a593Smuzhiyun
1120*4882a593Smuzhiyun ret = do_sys_poll(ufds, nfds, to);
1121*4882a593Smuzhiyun return poll_select_finish(&end_time, tsp, PT_TIMESPEC, ret);
1122*4882a593Smuzhiyun }
1123*4882a593Smuzhiyun
1124*4882a593Smuzhiyun #if defined(CONFIG_COMPAT_32BIT_TIME) && !defined(CONFIG_64BIT)
1125*4882a593Smuzhiyun
SYSCALL_DEFINE5(ppoll_time32,struct pollfd __user *,ufds,unsigned int,nfds,struct old_timespec32 __user *,tsp,const sigset_t __user *,sigmask,size_t,sigsetsize)1126*4882a593Smuzhiyun SYSCALL_DEFINE5(ppoll_time32, struct pollfd __user *, ufds, unsigned int, nfds,
1127*4882a593Smuzhiyun struct old_timespec32 __user *, tsp, const sigset_t __user *, sigmask,
1128*4882a593Smuzhiyun size_t, sigsetsize)
1129*4882a593Smuzhiyun {
1130*4882a593Smuzhiyun struct timespec64 ts, end_time, *to = NULL;
1131*4882a593Smuzhiyun int ret;
1132*4882a593Smuzhiyun
1133*4882a593Smuzhiyun if (tsp) {
1134*4882a593Smuzhiyun if (get_old_timespec32(&ts, tsp))
1135*4882a593Smuzhiyun return -EFAULT;
1136*4882a593Smuzhiyun
1137*4882a593Smuzhiyun to = &end_time;
1138*4882a593Smuzhiyun if (poll_select_set_timeout(to, ts.tv_sec, ts.tv_nsec))
1139*4882a593Smuzhiyun return -EINVAL;
1140*4882a593Smuzhiyun }
1141*4882a593Smuzhiyun
1142*4882a593Smuzhiyun ret = set_user_sigmask(sigmask, sigsetsize);
1143*4882a593Smuzhiyun if (ret)
1144*4882a593Smuzhiyun return ret;
1145*4882a593Smuzhiyun
1146*4882a593Smuzhiyun ret = do_sys_poll(ufds, nfds, to);
1147*4882a593Smuzhiyun return poll_select_finish(&end_time, tsp, PT_OLD_TIMESPEC, ret);
1148*4882a593Smuzhiyun }
1149*4882a593Smuzhiyun #endif
1150*4882a593Smuzhiyun
1151*4882a593Smuzhiyun #ifdef CONFIG_COMPAT
1152*4882a593Smuzhiyun #define __COMPAT_NFDBITS (8 * sizeof(compat_ulong_t))
1153*4882a593Smuzhiyun
1154*4882a593Smuzhiyun /*
1155*4882a593Smuzhiyun * Ooo, nasty. We need here to frob 32-bit unsigned longs to
1156*4882a593Smuzhiyun * 64-bit unsigned longs.
1157*4882a593Smuzhiyun */
1158*4882a593Smuzhiyun static
compat_get_fd_set(unsigned long nr,compat_ulong_t __user * ufdset,unsigned long * fdset)1159*4882a593Smuzhiyun int compat_get_fd_set(unsigned long nr, compat_ulong_t __user *ufdset,
1160*4882a593Smuzhiyun unsigned long *fdset)
1161*4882a593Smuzhiyun {
1162*4882a593Smuzhiyun if (ufdset) {
1163*4882a593Smuzhiyun return compat_get_bitmap(fdset, ufdset, nr);
1164*4882a593Smuzhiyun } else {
1165*4882a593Smuzhiyun zero_fd_set(nr, fdset);
1166*4882a593Smuzhiyun return 0;
1167*4882a593Smuzhiyun }
1168*4882a593Smuzhiyun }
1169*4882a593Smuzhiyun
1170*4882a593Smuzhiyun static
compat_set_fd_set(unsigned long nr,compat_ulong_t __user * ufdset,unsigned long * fdset)1171*4882a593Smuzhiyun int compat_set_fd_set(unsigned long nr, compat_ulong_t __user *ufdset,
1172*4882a593Smuzhiyun unsigned long *fdset)
1173*4882a593Smuzhiyun {
1174*4882a593Smuzhiyun if (!ufdset)
1175*4882a593Smuzhiyun return 0;
1176*4882a593Smuzhiyun return compat_put_bitmap(ufdset, fdset, nr);
1177*4882a593Smuzhiyun }
1178*4882a593Smuzhiyun
1179*4882a593Smuzhiyun
1180*4882a593Smuzhiyun /*
1181*4882a593Smuzhiyun * This is a virtual copy of sys_select from fs/select.c and probably
1182*4882a593Smuzhiyun * should be compared to it from time to time
1183*4882a593Smuzhiyun */
1184*4882a593Smuzhiyun
1185*4882a593Smuzhiyun /*
1186*4882a593Smuzhiyun * We can actually return ERESTARTSYS instead of EINTR, but I'd
1187*4882a593Smuzhiyun * like to be certain this leads to no problems. So I return
1188*4882a593Smuzhiyun * EINTR just for safety.
1189*4882a593Smuzhiyun *
1190*4882a593Smuzhiyun * Update: ERESTARTSYS breaks at least the xview clock binary, so
1191*4882a593Smuzhiyun * I'm trying ERESTARTNOHAND which restart only when you want to.
1192*4882a593Smuzhiyun */
compat_core_sys_select(int n,compat_ulong_t __user * inp,compat_ulong_t __user * outp,compat_ulong_t __user * exp,struct timespec64 * end_time)1193*4882a593Smuzhiyun static int compat_core_sys_select(int n, compat_ulong_t __user *inp,
1194*4882a593Smuzhiyun compat_ulong_t __user *outp, compat_ulong_t __user *exp,
1195*4882a593Smuzhiyun struct timespec64 *end_time)
1196*4882a593Smuzhiyun {
1197*4882a593Smuzhiyun fd_set_bits fds;
1198*4882a593Smuzhiyun void *bits;
1199*4882a593Smuzhiyun int size, max_fds, ret = -EINVAL;
1200*4882a593Smuzhiyun struct fdtable *fdt;
1201*4882a593Smuzhiyun long stack_fds[SELECT_STACK_ALLOC/sizeof(long)];
1202*4882a593Smuzhiyun
1203*4882a593Smuzhiyun if (n < 0)
1204*4882a593Smuzhiyun goto out_nofds;
1205*4882a593Smuzhiyun
1206*4882a593Smuzhiyun /* max_fds can increase, so grab it once to avoid race */
1207*4882a593Smuzhiyun rcu_read_lock();
1208*4882a593Smuzhiyun fdt = files_fdtable(current->files);
1209*4882a593Smuzhiyun max_fds = fdt->max_fds;
1210*4882a593Smuzhiyun rcu_read_unlock();
1211*4882a593Smuzhiyun if (n > max_fds)
1212*4882a593Smuzhiyun n = max_fds;
1213*4882a593Smuzhiyun
1214*4882a593Smuzhiyun /*
1215*4882a593Smuzhiyun * We need 6 bitmaps (in/out/ex for both incoming and outgoing),
1216*4882a593Smuzhiyun * since we used fdset we need to allocate memory in units of
1217*4882a593Smuzhiyun * long-words.
1218*4882a593Smuzhiyun */
1219*4882a593Smuzhiyun size = FDS_BYTES(n);
1220*4882a593Smuzhiyun bits = stack_fds;
1221*4882a593Smuzhiyun if (size > sizeof(stack_fds) / 6) {
1222*4882a593Smuzhiyun bits = kmalloc_array(6, size, GFP_KERNEL);
1223*4882a593Smuzhiyun ret = -ENOMEM;
1224*4882a593Smuzhiyun if (!bits)
1225*4882a593Smuzhiyun goto out_nofds;
1226*4882a593Smuzhiyun }
1227*4882a593Smuzhiyun fds.in = (unsigned long *) bits;
1228*4882a593Smuzhiyun fds.out = (unsigned long *) (bits + size);
1229*4882a593Smuzhiyun fds.ex = (unsigned long *) (bits + 2*size);
1230*4882a593Smuzhiyun fds.res_in = (unsigned long *) (bits + 3*size);
1231*4882a593Smuzhiyun fds.res_out = (unsigned long *) (bits + 4*size);
1232*4882a593Smuzhiyun fds.res_ex = (unsigned long *) (bits + 5*size);
1233*4882a593Smuzhiyun
1234*4882a593Smuzhiyun if ((ret = compat_get_fd_set(n, inp, fds.in)) ||
1235*4882a593Smuzhiyun (ret = compat_get_fd_set(n, outp, fds.out)) ||
1236*4882a593Smuzhiyun (ret = compat_get_fd_set(n, exp, fds.ex)))
1237*4882a593Smuzhiyun goto out;
1238*4882a593Smuzhiyun zero_fd_set(n, fds.res_in);
1239*4882a593Smuzhiyun zero_fd_set(n, fds.res_out);
1240*4882a593Smuzhiyun zero_fd_set(n, fds.res_ex);
1241*4882a593Smuzhiyun
1242*4882a593Smuzhiyun ret = do_select(n, &fds, end_time);
1243*4882a593Smuzhiyun
1244*4882a593Smuzhiyun if (ret < 0)
1245*4882a593Smuzhiyun goto out;
1246*4882a593Smuzhiyun if (!ret) {
1247*4882a593Smuzhiyun ret = -ERESTARTNOHAND;
1248*4882a593Smuzhiyun if (signal_pending(current))
1249*4882a593Smuzhiyun goto out;
1250*4882a593Smuzhiyun ret = 0;
1251*4882a593Smuzhiyun }
1252*4882a593Smuzhiyun
1253*4882a593Smuzhiyun if (compat_set_fd_set(n, inp, fds.res_in) ||
1254*4882a593Smuzhiyun compat_set_fd_set(n, outp, fds.res_out) ||
1255*4882a593Smuzhiyun compat_set_fd_set(n, exp, fds.res_ex))
1256*4882a593Smuzhiyun ret = -EFAULT;
1257*4882a593Smuzhiyun out:
1258*4882a593Smuzhiyun if (bits != stack_fds)
1259*4882a593Smuzhiyun kfree(bits);
1260*4882a593Smuzhiyun out_nofds:
1261*4882a593Smuzhiyun return ret;
1262*4882a593Smuzhiyun }
1263*4882a593Smuzhiyun
do_compat_select(int n,compat_ulong_t __user * inp,compat_ulong_t __user * outp,compat_ulong_t __user * exp,struct old_timeval32 __user * tvp)1264*4882a593Smuzhiyun static int do_compat_select(int n, compat_ulong_t __user *inp,
1265*4882a593Smuzhiyun compat_ulong_t __user *outp, compat_ulong_t __user *exp,
1266*4882a593Smuzhiyun struct old_timeval32 __user *tvp)
1267*4882a593Smuzhiyun {
1268*4882a593Smuzhiyun struct timespec64 end_time, *to = NULL;
1269*4882a593Smuzhiyun struct old_timeval32 tv;
1270*4882a593Smuzhiyun int ret;
1271*4882a593Smuzhiyun
1272*4882a593Smuzhiyun if (tvp) {
1273*4882a593Smuzhiyun if (copy_from_user(&tv, tvp, sizeof(tv)))
1274*4882a593Smuzhiyun return -EFAULT;
1275*4882a593Smuzhiyun
1276*4882a593Smuzhiyun to = &end_time;
1277*4882a593Smuzhiyun if (poll_select_set_timeout(to,
1278*4882a593Smuzhiyun tv.tv_sec + (tv.tv_usec / USEC_PER_SEC),
1279*4882a593Smuzhiyun (tv.tv_usec % USEC_PER_SEC) * NSEC_PER_USEC))
1280*4882a593Smuzhiyun return -EINVAL;
1281*4882a593Smuzhiyun }
1282*4882a593Smuzhiyun
1283*4882a593Smuzhiyun ret = compat_core_sys_select(n, inp, outp, exp, to);
1284*4882a593Smuzhiyun return poll_select_finish(&end_time, tvp, PT_OLD_TIMEVAL, ret);
1285*4882a593Smuzhiyun }
1286*4882a593Smuzhiyun
COMPAT_SYSCALL_DEFINE5(select,int,n,compat_ulong_t __user *,inp,compat_ulong_t __user *,outp,compat_ulong_t __user *,exp,struct old_timeval32 __user *,tvp)1287*4882a593Smuzhiyun COMPAT_SYSCALL_DEFINE5(select, int, n, compat_ulong_t __user *, inp,
1288*4882a593Smuzhiyun compat_ulong_t __user *, outp, compat_ulong_t __user *, exp,
1289*4882a593Smuzhiyun struct old_timeval32 __user *, tvp)
1290*4882a593Smuzhiyun {
1291*4882a593Smuzhiyun return do_compat_select(n, inp, outp, exp, tvp);
1292*4882a593Smuzhiyun }
1293*4882a593Smuzhiyun
1294*4882a593Smuzhiyun struct compat_sel_arg_struct {
1295*4882a593Smuzhiyun compat_ulong_t n;
1296*4882a593Smuzhiyun compat_uptr_t inp;
1297*4882a593Smuzhiyun compat_uptr_t outp;
1298*4882a593Smuzhiyun compat_uptr_t exp;
1299*4882a593Smuzhiyun compat_uptr_t tvp;
1300*4882a593Smuzhiyun };
1301*4882a593Smuzhiyun
COMPAT_SYSCALL_DEFINE1(old_select,struct compat_sel_arg_struct __user *,arg)1302*4882a593Smuzhiyun COMPAT_SYSCALL_DEFINE1(old_select, struct compat_sel_arg_struct __user *, arg)
1303*4882a593Smuzhiyun {
1304*4882a593Smuzhiyun struct compat_sel_arg_struct a;
1305*4882a593Smuzhiyun
1306*4882a593Smuzhiyun if (copy_from_user(&a, arg, sizeof(a)))
1307*4882a593Smuzhiyun return -EFAULT;
1308*4882a593Smuzhiyun return do_compat_select(a.n, compat_ptr(a.inp), compat_ptr(a.outp),
1309*4882a593Smuzhiyun compat_ptr(a.exp), compat_ptr(a.tvp));
1310*4882a593Smuzhiyun }
1311*4882a593Smuzhiyun
do_compat_pselect(int n,compat_ulong_t __user * inp,compat_ulong_t __user * outp,compat_ulong_t __user * exp,void __user * tsp,compat_sigset_t __user * sigmask,compat_size_t sigsetsize,enum poll_time_type type)1312*4882a593Smuzhiyun static long do_compat_pselect(int n, compat_ulong_t __user *inp,
1313*4882a593Smuzhiyun compat_ulong_t __user *outp, compat_ulong_t __user *exp,
1314*4882a593Smuzhiyun void __user *tsp, compat_sigset_t __user *sigmask,
1315*4882a593Smuzhiyun compat_size_t sigsetsize, enum poll_time_type type)
1316*4882a593Smuzhiyun {
1317*4882a593Smuzhiyun struct timespec64 ts, end_time, *to = NULL;
1318*4882a593Smuzhiyun int ret;
1319*4882a593Smuzhiyun
1320*4882a593Smuzhiyun if (tsp) {
1321*4882a593Smuzhiyun switch (type) {
1322*4882a593Smuzhiyun case PT_OLD_TIMESPEC:
1323*4882a593Smuzhiyun if (get_old_timespec32(&ts, tsp))
1324*4882a593Smuzhiyun return -EFAULT;
1325*4882a593Smuzhiyun break;
1326*4882a593Smuzhiyun case PT_TIMESPEC:
1327*4882a593Smuzhiyun if (get_timespec64(&ts, tsp))
1328*4882a593Smuzhiyun return -EFAULT;
1329*4882a593Smuzhiyun break;
1330*4882a593Smuzhiyun default:
1331*4882a593Smuzhiyun BUG();
1332*4882a593Smuzhiyun }
1333*4882a593Smuzhiyun
1334*4882a593Smuzhiyun to = &end_time;
1335*4882a593Smuzhiyun if (poll_select_set_timeout(to, ts.tv_sec, ts.tv_nsec))
1336*4882a593Smuzhiyun return -EINVAL;
1337*4882a593Smuzhiyun }
1338*4882a593Smuzhiyun
1339*4882a593Smuzhiyun ret = set_compat_user_sigmask(sigmask, sigsetsize);
1340*4882a593Smuzhiyun if (ret)
1341*4882a593Smuzhiyun return ret;
1342*4882a593Smuzhiyun
1343*4882a593Smuzhiyun ret = compat_core_sys_select(n, inp, outp, exp, to);
1344*4882a593Smuzhiyun return poll_select_finish(&end_time, tsp, type, ret);
1345*4882a593Smuzhiyun }
1346*4882a593Smuzhiyun
1347*4882a593Smuzhiyun struct compat_sigset_argpack {
1348*4882a593Smuzhiyun compat_uptr_t p;
1349*4882a593Smuzhiyun compat_size_t size;
1350*4882a593Smuzhiyun };
get_compat_sigset_argpack(struct compat_sigset_argpack * to,struct compat_sigset_argpack __user * from)1351*4882a593Smuzhiyun static inline int get_compat_sigset_argpack(struct compat_sigset_argpack *to,
1352*4882a593Smuzhiyun struct compat_sigset_argpack __user *from)
1353*4882a593Smuzhiyun {
1354*4882a593Smuzhiyun if (from) {
1355*4882a593Smuzhiyun if (!user_read_access_begin(from, sizeof(*from)))
1356*4882a593Smuzhiyun return -EFAULT;
1357*4882a593Smuzhiyun unsafe_get_user(to->p, &from->p, Efault);
1358*4882a593Smuzhiyun unsafe_get_user(to->size, &from->size, Efault);
1359*4882a593Smuzhiyun user_read_access_end();
1360*4882a593Smuzhiyun }
1361*4882a593Smuzhiyun return 0;
1362*4882a593Smuzhiyun Efault:
1363*4882a593Smuzhiyun user_access_end();
1364*4882a593Smuzhiyun return -EFAULT;
1365*4882a593Smuzhiyun }
1366*4882a593Smuzhiyun
COMPAT_SYSCALL_DEFINE6(pselect6_time64,int,n,compat_ulong_t __user *,inp,compat_ulong_t __user *,outp,compat_ulong_t __user *,exp,struct __kernel_timespec __user *,tsp,void __user *,sig)1367*4882a593Smuzhiyun COMPAT_SYSCALL_DEFINE6(pselect6_time64, int, n, compat_ulong_t __user *, inp,
1368*4882a593Smuzhiyun compat_ulong_t __user *, outp, compat_ulong_t __user *, exp,
1369*4882a593Smuzhiyun struct __kernel_timespec __user *, tsp, void __user *, sig)
1370*4882a593Smuzhiyun {
1371*4882a593Smuzhiyun struct compat_sigset_argpack x = {0, 0};
1372*4882a593Smuzhiyun
1373*4882a593Smuzhiyun if (get_compat_sigset_argpack(&x, sig))
1374*4882a593Smuzhiyun return -EFAULT;
1375*4882a593Smuzhiyun
1376*4882a593Smuzhiyun return do_compat_pselect(n, inp, outp, exp, tsp, compat_ptr(x.p),
1377*4882a593Smuzhiyun x.size, PT_TIMESPEC);
1378*4882a593Smuzhiyun }
1379*4882a593Smuzhiyun
1380*4882a593Smuzhiyun #if defined(CONFIG_COMPAT_32BIT_TIME)
1381*4882a593Smuzhiyun
COMPAT_SYSCALL_DEFINE6(pselect6_time32,int,n,compat_ulong_t __user *,inp,compat_ulong_t __user *,outp,compat_ulong_t __user *,exp,struct old_timespec32 __user *,tsp,void __user *,sig)1382*4882a593Smuzhiyun COMPAT_SYSCALL_DEFINE6(pselect6_time32, int, n, compat_ulong_t __user *, inp,
1383*4882a593Smuzhiyun compat_ulong_t __user *, outp, compat_ulong_t __user *, exp,
1384*4882a593Smuzhiyun struct old_timespec32 __user *, tsp, void __user *, sig)
1385*4882a593Smuzhiyun {
1386*4882a593Smuzhiyun struct compat_sigset_argpack x = {0, 0};
1387*4882a593Smuzhiyun
1388*4882a593Smuzhiyun if (get_compat_sigset_argpack(&x, sig))
1389*4882a593Smuzhiyun return -EFAULT;
1390*4882a593Smuzhiyun
1391*4882a593Smuzhiyun return do_compat_pselect(n, inp, outp, exp, tsp, compat_ptr(x.p),
1392*4882a593Smuzhiyun x.size, PT_OLD_TIMESPEC);
1393*4882a593Smuzhiyun }
1394*4882a593Smuzhiyun
1395*4882a593Smuzhiyun #endif
1396*4882a593Smuzhiyun
1397*4882a593Smuzhiyun #if defined(CONFIG_COMPAT_32BIT_TIME)
COMPAT_SYSCALL_DEFINE5(ppoll_time32,struct pollfd __user *,ufds,unsigned int,nfds,struct old_timespec32 __user *,tsp,const compat_sigset_t __user *,sigmask,compat_size_t,sigsetsize)1398*4882a593Smuzhiyun COMPAT_SYSCALL_DEFINE5(ppoll_time32, struct pollfd __user *, ufds,
1399*4882a593Smuzhiyun unsigned int, nfds, struct old_timespec32 __user *, tsp,
1400*4882a593Smuzhiyun const compat_sigset_t __user *, sigmask, compat_size_t, sigsetsize)
1401*4882a593Smuzhiyun {
1402*4882a593Smuzhiyun struct timespec64 ts, end_time, *to = NULL;
1403*4882a593Smuzhiyun int ret;
1404*4882a593Smuzhiyun
1405*4882a593Smuzhiyun if (tsp) {
1406*4882a593Smuzhiyun if (get_old_timespec32(&ts, tsp))
1407*4882a593Smuzhiyun return -EFAULT;
1408*4882a593Smuzhiyun
1409*4882a593Smuzhiyun to = &end_time;
1410*4882a593Smuzhiyun if (poll_select_set_timeout(to, ts.tv_sec, ts.tv_nsec))
1411*4882a593Smuzhiyun return -EINVAL;
1412*4882a593Smuzhiyun }
1413*4882a593Smuzhiyun
1414*4882a593Smuzhiyun ret = set_compat_user_sigmask(sigmask, sigsetsize);
1415*4882a593Smuzhiyun if (ret)
1416*4882a593Smuzhiyun return ret;
1417*4882a593Smuzhiyun
1418*4882a593Smuzhiyun ret = do_sys_poll(ufds, nfds, to);
1419*4882a593Smuzhiyun return poll_select_finish(&end_time, tsp, PT_OLD_TIMESPEC, ret);
1420*4882a593Smuzhiyun }
1421*4882a593Smuzhiyun #endif
1422*4882a593Smuzhiyun
1423*4882a593Smuzhiyun /* New compat syscall for 64 bit time_t*/
COMPAT_SYSCALL_DEFINE5(ppoll_time64,struct pollfd __user *,ufds,unsigned int,nfds,struct __kernel_timespec __user *,tsp,const compat_sigset_t __user *,sigmask,compat_size_t,sigsetsize)1424*4882a593Smuzhiyun COMPAT_SYSCALL_DEFINE5(ppoll_time64, struct pollfd __user *, ufds,
1425*4882a593Smuzhiyun unsigned int, nfds, struct __kernel_timespec __user *, tsp,
1426*4882a593Smuzhiyun const compat_sigset_t __user *, sigmask, compat_size_t, sigsetsize)
1427*4882a593Smuzhiyun {
1428*4882a593Smuzhiyun struct timespec64 ts, end_time, *to = NULL;
1429*4882a593Smuzhiyun int ret;
1430*4882a593Smuzhiyun
1431*4882a593Smuzhiyun if (tsp) {
1432*4882a593Smuzhiyun if (get_timespec64(&ts, tsp))
1433*4882a593Smuzhiyun return -EFAULT;
1434*4882a593Smuzhiyun
1435*4882a593Smuzhiyun to = &end_time;
1436*4882a593Smuzhiyun if (poll_select_set_timeout(to, ts.tv_sec, ts.tv_nsec))
1437*4882a593Smuzhiyun return -EINVAL;
1438*4882a593Smuzhiyun }
1439*4882a593Smuzhiyun
1440*4882a593Smuzhiyun ret = set_compat_user_sigmask(sigmask, sigsetsize);
1441*4882a593Smuzhiyun if (ret)
1442*4882a593Smuzhiyun return ret;
1443*4882a593Smuzhiyun
1444*4882a593Smuzhiyun ret = do_sys_poll(ufds, nfds, to);
1445*4882a593Smuzhiyun return poll_select_finish(&end_time, tsp, PT_TIMESPEC, ret);
1446*4882a593Smuzhiyun }
1447*4882a593Smuzhiyun
1448*4882a593Smuzhiyun #endif
1449