1*4882a593Smuzhiyun // SPDX-License-Identifier: GPL-2.0
2*4882a593Smuzhiyun #include <linux/bitops.h>
3*4882a593Smuzhiyun #include <linux/fault-inject-usercopy.h>
4*4882a593Smuzhiyun #include <linux/instrumented.h>
5*4882a593Smuzhiyun #include <linux/uaccess.h>
6*4882a593Smuzhiyun
7*4882a593Smuzhiyun /* out-of-line parts */
8*4882a593Smuzhiyun
9*4882a593Smuzhiyun #ifndef INLINE_COPY_FROM_USER
_copy_from_user(void * to,const void __user * from,unsigned long n)10*4882a593Smuzhiyun unsigned long _copy_from_user(void *to, const void __user *from, unsigned long n)
11*4882a593Smuzhiyun {
12*4882a593Smuzhiyun unsigned long res = n;
13*4882a593Smuzhiyun might_fault();
14*4882a593Smuzhiyun if (!should_fail_usercopy() && likely(access_ok(from, n))) {
15*4882a593Smuzhiyun instrument_copy_from_user(to, from, n);
16*4882a593Smuzhiyun res = raw_copy_from_user(to, from, n);
17*4882a593Smuzhiyun }
18*4882a593Smuzhiyun if (unlikely(res))
19*4882a593Smuzhiyun memset(to + (n - res), 0, res);
20*4882a593Smuzhiyun return res;
21*4882a593Smuzhiyun }
22*4882a593Smuzhiyun EXPORT_SYMBOL(_copy_from_user);
23*4882a593Smuzhiyun #endif
24*4882a593Smuzhiyun
25*4882a593Smuzhiyun #ifndef INLINE_COPY_TO_USER
_copy_to_user(void __user * to,const void * from,unsigned long n)26*4882a593Smuzhiyun unsigned long _copy_to_user(void __user *to, const void *from, unsigned long n)
27*4882a593Smuzhiyun {
28*4882a593Smuzhiyun might_fault();
29*4882a593Smuzhiyun if (should_fail_usercopy())
30*4882a593Smuzhiyun return n;
31*4882a593Smuzhiyun if (likely(access_ok(to, n))) {
32*4882a593Smuzhiyun instrument_copy_to_user(to, from, n);
33*4882a593Smuzhiyun n = raw_copy_to_user(to, from, n);
34*4882a593Smuzhiyun }
35*4882a593Smuzhiyun return n;
36*4882a593Smuzhiyun }
37*4882a593Smuzhiyun EXPORT_SYMBOL(_copy_to_user);
38*4882a593Smuzhiyun #endif
39*4882a593Smuzhiyun
40*4882a593Smuzhiyun /**
41*4882a593Smuzhiyun * check_zeroed_user: check if a userspace buffer only contains zero bytes
42*4882a593Smuzhiyun * @from: Source address, in userspace.
43*4882a593Smuzhiyun * @size: Size of buffer.
44*4882a593Smuzhiyun *
45*4882a593Smuzhiyun * This is effectively shorthand for "memchr_inv(from, 0, size) == NULL" for
46*4882a593Smuzhiyun * userspace addresses (and is more efficient because we don't care where the
47*4882a593Smuzhiyun * first non-zero byte is).
48*4882a593Smuzhiyun *
49*4882a593Smuzhiyun * Returns:
50*4882a593Smuzhiyun * * 0: There were non-zero bytes present in the buffer.
51*4882a593Smuzhiyun * * 1: The buffer was full of zero bytes.
52*4882a593Smuzhiyun * * -EFAULT: access to userspace failed.
53*4882a593Smuzhiyun */
check_zeroed_user(const void __user * from,size_t size)54*4882a593Smuzhiyun int check_zeroed_user(const void __user *from, size_t size)
55*4882a593Smuzhiyun {
56*4882a593Smuzhiyun unsigned long val;
57*4882a593Smuzhiyun uintptr_t align = (uintptr_t) from % sizeof(unsigned long);
58*4882a593Smuzhiyun
59*4882a593Smuzhiyun if (unlikely(size == 0))
60*4882a593Smuzhiyun return 1;
61*4882a593Smuzhiyun
62*4882a593Smuzhiyun from -= align;
63*4882a593Smuzhiyun size += align;
64*4882a593Smuzhiyun
65*4882a593Smuzhiyun if (!user_read_access_begin(from, size))
66*4882a593Smuzhiyun return -EFAULT;
67*4882a593Smuzhiyun
68*4882a593Smuzhiyun unsafe_get_user(val, (unsigned long __user *) from, err_fault);
69*4882a593Smuzhiyun if (align)
70*4882a593Smuzhiyun val &= ~aligned_byte_mask(align);
71*4882a593Smuzhiyun
72*4882a593Smuzhiyun while (size > sizeof(unsigned long)) {
73*4882a593Smuzhiyun if (unlikely(val))
74*4882a593Smuzhiyun goto done;
75*4882a593Smuzhiyun
76*4882a593Smuzhiyun from += sizeof(unsigned long);
77*4882a593Smuzhiyun size -= sizeof(unsigned long);
78*4882a593Smuzhiyun
79*4882a593Smuzhiyun unsafe_get_user(val, (unsigned long __user *) from, err_fault);
80*4882a593Smuzhiyun }
81*4882a593Smuzhiyun
82*4882a593Smuzhiyun if (size < sizeof(unsigned long))
83*4882a593Smuzhiyun val &= aligned_byte_mask(size);
84*4882a593Smuzhiyun
85*4882a593Smuzhiyun done:
86*4882a593Smuzhiyun user_read_access_end();
87*4882a593Smuzhiyun return (val == 0);
88*4882a593Smuzhiyun err_fault:
89*4882a593Smuzhiyun user_read_access_end();
90*4882a593Smuzhiyun return -EFAULT;
91*4882a593Smuzhiyun }
92*4882a593Smuzhiyun EXPORT_SYMBOL(check_zeroed_user);
93