GNU Linux-libre 4.4.299-gnu1
[releases.git] / arch / powerpc / include / asm / uaccess.h
1 #ifndef _ARCH_POWERPC_UACCESS_H
2 #define _ARCH_POWERPC_UACCESS_H
3
4 #ifdef __KERNEL__
5 #ifndef __ASSEMBLY__
6
7 #include <linux/sched.h>
8 #include <linux/errno.h>
9 #include <asm/asm-compat.h>
10 #include <asm/processor.h>
11 #include <asm/page.h>
12 #include <asm/kup.h>
13
14 #define VERIFY_READ     0
15 #define VERIFY_WRITE    1
16
17 /*
18  * The fs value determines whether argument validity checking should be
19  * performed or not.  If get_fs() == USER_DS, checking is performed, with
20  * get_fs() == KERNEL_DS, checking is bypassed.
21  *
22  * For historical reasons, these macros are grossly misnamed.
23  *
24  * The fs/ds values are now the highest legal address in the "segment".
25  * This simplifies the checking in the routines below.
26  */
27
28 #define MAKE_MM_SEG(s)  ((mm_segment_t) { (s) })
29
30 #define KERNEL_DS       MAKE_MM_SEG(~0UL)
31 #ifdef __powerpc64__
32 /* We use TASK_SIZE_USER64 as TASK_SIZE is not constant */
33 #define USER_DS         MAKE_MM_SEG(TASK_SIZE_USER64 - 1)
34 #else
35 #define USER_DS         MAKE_MM_SEG(TASK_SIZE - 1)
36 #endif
37
38 #define get_ds()        (KERNEL_DS)
39 #define get_fs()        (current->thread.fs)
40 #define set_fs(val)     (current->thread.fs = (val))
41
42 #define segment_eq(a, b)        ((a).seg == (b).seg)
43
44 #define user_addr_max() (get_fs().seg)
45
46 #ifdef __powerpc64__
47 /*
48  * This check is sufficient because there is a large enough
49  * gap between user addresses and the kernel addresses
50  */
51 #define __access_ok(addr, size, segment)        \
52         (((addr) <= (segment).seg) && ((size) <= (segment).seg))
53
54 #else
55
56 #define __access_ok(addr, size, segment)        \
57         (((addr) <= (segment).seg) &&           \
58          (((size) == 0) || (((size) - 1) <= ((segment).seg - (addr)))))
59
60 #endif
61
62 #define access_ok(type, addr, size)             \
63         (__chk_user_ptr(addr), (void)(type),            \
64          __access_ok((__force unsigned long)(addr), (size), get_fs()))
65
66 /*
67  * The exception table consists of pairs of addresses: the first is the
68  * address of an instruction that is allowed to fault, and the second is
69  * the address at which the program should continue.  No registers are
70  * modified, so it is entirely up to the continuation code to figure out
71  * what to do.
72  *
73  * All the routines below use bits of fixup code that are out of line
74  * with the main instruction path.  This means when everything is well,
75  * we don't even have to jump over them.  Further, they do not intrude
76  * on our cache or tlb entries.
77  */
78
79 struct exception_table_entry {
80         unsigned long insn;
81         unsigned long fixup;
82 };
83
84 /*
85  * These are the main single-value transfer routines.  They automatically
86  * use the right size if we just have the right pointer type.
87  *
88  * This gets kind of ugly. We want to return _two_ values in "get_user()"
89  * and yet we don't want to do any pointers, because that is too much
90  * of a performance impact. Thus we have a few rather ugly macros here,
91  * and hide all the ugliness from the user.
92  *
93  * The "__xxx" versions of the user access functions are versions that
94  * do not verify the address space, that must have been done previously
95  * with a separate "access_ok()" call (this is used when we do multiple
96  * accesses to the same area of user memory).
97  *
98  * As we use the same address space for kernel and user data on the
99  * PowerPC, we can just do these as direct assignments.  (Of course, the
100  * exception handling means that it's no longer "just"...)
101  *
102  */
103 #define get_user(x, ptr) \
104         __get_user_check((x), (ptr), sizeof(*(ptr)))
105 #define put_user(x, ptr) \
106         __put_user_check((__typeof__(*(ptr)))(x), (ptr), sizeof(*(ptr)))
107
108 #define __get_user(x, ptr) \
109         __get_user_nocheck((x), (ptr), sizeof(*(ptr)), true)
110 #define __put_user(x, ptr) \
111         __put_user_nocheck((__typeof__(*(ptr)))(x), (ptr), sizeof(*(ptr)), true)
112
113 #define __get_user_allowed(x, ptr) \
114         __get_user_nocheck((x), (ptr), sizeof(*(ptr)), false)
115 #define __put_user_allowed(x, ptr) \
116         __put_user_nocheck((__typeof__(*(ptr)))(x), (ptr), sizeof(*(ptr)), false)
117
118 #define __get_user_inatomic(x, ptr) \
119         __get_user_nosleep((x), (ptr), sizeof(*(ptr)))
120 #define __put_user_inatomic(x, ptr) \
121         __put_user_nosleep((__typeof__(*(ptr)))(x), (ptr), sizeof(*(ptr)))
122
123 #define __get_user_unaligned __get_user
124 #define __put_user_unaligned __put_user
125
126 extern long __put_user_bad(void);
127
128 /*
129  * We don't tell gcc that we are accessing memory, but this is OK
130  * because we do not write to any memory gcc knows about, so there
131  * are no aliasing issues.
132  */
133 #define __put_user_asm(x, addr, err, op)                        \
134         __asm__ __volatile__(                                   \
135                 "1:     " op " %1,0(%2) # put_user\n"           \
136                 "2:\n"                                          \
137                 ".section .fixup,\"ax\"\n"                      \
138                 "3:     li %0,%3\n"                             \
139                 "       b 2b\n"                                 \
140                 ".previous\n"                                   \
141                 ".section __ex_table,\"a\"\n"                   \
142                         PPC_LONG_ALIGN "\n"                     \
143                         PPC_LONG "1b,3b\n"                      \
144                 ".previous"                                     \
145                 : "=r" (err)                                    \
146                 : "r" (x), "b" (addr), "i" (-EFAULT), "0" (err))
147
148 #ifdef __powerpc64__
149 #define __put_user_asm2(x, ptr, retval)                         \
150           __put_user_asm(x, ptr, retval, "std")
151 #else /* __powerpc64__ */
152 #define __put_user_asm2(x, addr, err)                           \
153         __asm__ __volatile__(                                   \
154                 "1:     stw %1,0(%2)\n"                         \
155                 "2:     stw %1+1,4(%2)\n"                       \
156                 "3:\n"                                          \
157                 ".section .fixup,\"ax\"\n"                      \
158                 "4:     li %0,%3\n"                             \
159                 "       b 3b\n"                                 \
160                 ".previous\n"                                   \
161                 ".section __ex_table,\"a\"\n"                   \
162                         PPC_LONG_ALIGN "\n"                     \
163                         PPC_LONG "1b,4b\n"                      \
164                         PPC_LONG "2b,4b\n"                      \
165                 ".previous"                                     \
166                 : "=r" (err)                                    \
167                 : "r" (x), "b" (addr), "i" (-EFAULT), "0" (err))
168 #endif /* __powerpc64__ */
169
170 #define __put_user_size_allowed(x, ptr, size, retval)           \
171 do {                                                            \
172         retval = 0;                                             \
173         switch (size) {                                         \
174           case 1: __put_user_asm(x, ptr, retval, "stb"); break; \
175           case 2: __put_user_asm(x, ptr, retval, "sth"); break; \
176           case 4: __put_user_asm(x, ptr, retval, "stw"); break; \
177           case 8: __put_user_asm2(x, ptr, retval); break;       \
178           default: __put_user_bad();                            \
179         }                                                       \
180 } while (0)
181
182 #define __put_user_size(x, ptr, size, retval)                   \
183 do {                                                            \
184         allow_write_to_user(ptr, size);                         \
185         __put_user_size_allowed(x, ptr, size, retval);          \
186         prevent_write_to_user(ptr, size);                       \
187 } while (0)
188
189 #define __put_user_nocheck(x, ptr, size, do_allow)                      \
190 ({                                                              \
191         long __pu_err;                                          \
192         __typeof__(*(ptr)) __user *__pu_addr = (ptr);           \
193         __typeof__(*(ptr)) __pu_val = (x);                      \
194         __typeof__(size) __pu_size = (size);                    \
195                                                                 \
196         if (!is_kernel_addr((unsigned long)__pu_addr))          \
197                 might_fault();                                  \
198         __chk_user_ptr(__pu_addr);                              \
199         if (do_allow)                                                           \
200                 __put_user_size(__pu_val, __pu_addr, __pu_size, __pu_err);      \
201         else                                                                    \
202                 __put_user_size_allowed(__pu_val, __pu_addr, __pu_size, __pu_err); \
203                                                                 \
204         __pu_err;                                               \
205 })
206
207 #define __put_user_check(x, ptr, size)                                  \
208 ({                                                                      \
209         long __pu_err = -EFAULT;                                        \
210         __typeof__(*(ptr)) __user *__pu_addr = (ptr);                   \
211         __typeof__(*(ptr)) __pu_val = (x);                              \
212         __typeof__(size) __pu_size = (size);                            \
213                                                                         \
214         might_fault();                                                  \
215         if (access_ok(VERIFY_WRITE, __pu_addr, __pu_size))                      \
216                 __put_user_size(__pu_val, __pu_addr, __pu_size, __pu_err); \
217                                                                         \
218         __pu_err;                                                       \
219 })
220
221 #define __put_user_nosleep(x, ptr, size)                        \
222 ({                                                              \
223         long __pu_err;                                          \
224         __typeof__(*(ptr)) __user *__pu_addr = (ptr);           \
225         __typeof__(*(ptr)) __pu_val = (x);                      \
226         __typeof__(size) __pu_size = (size);                    \
227                                                                 \
228         __chk_user_ptr(__pu_addr);                              \
229         __put_user_size(__pu_val, __pu_addr, __pu_size, __pu_err); \
230                                                                 \
231         __pu_err;                                               \
232 })
233
234
235 extern long __get_user_bad(void);
236
237 #define __get_user_asm(x, addr, err, op)                \
238         __asm__ __volatile__(                           \
239                 "1:     "op" %1,0(%2)   # get_user\n"   \
240                 "2:\n"                                  \
241                 ".section .fixup,\"ax\"\n"              \
242                 "3:     li %0,%3\n"                     \
243                 "       li %1,0\n"                      \
244                 "       b 2b\n"                         \
245                 ".previous\n"                           \
246                 ".section __ex_table,\"a\"\n"           \
247                         PPC_LONG_ALIGN "\n"             \
248                         PPC_LONG "1b,3b\n"              \
249                 ".previous"                             \
250                 : "=r" (err), "=r" (x)                  \
251                 : "b" (addr), "i" (-EFAULT), "0" (err))
252
253 #ifdef __powerpc64__
254 #define __get_user_asm2(x, addr, err)                   \
255         __get_user_asm(x, addr, err, "ld")
256 #else /* __powerpc64__ */
257 #define __get_user_asm2(x, addr, err)                   \
258         __asm__ __volatile__(                           \
259                 "1:     lwz %1,0(%2)\n"                 \
260                 "2:     lwz %1+1,4(%2)\n"               \
261                 "3:\n"                                  \
262                 ".section .fixup,\"ax\"\n"              \
263                 "4:     li %0,%3\n"                     \
264                 "       li %1,0\n"                      \
265                 "       li %1+1,0\n"                    \
266                 "       b 3b\n"                         \
267                 ".previous\n"                           \
268                 ".section __ex_table,\"a\"\n"           \
269                         PPC_LONG_ALIGN "\n"             \
270                         PPC_LONG "1b,4b\n"              \
271                         PPC_LONG "2b,4b\n"              \
272                 ".previous"                             \
273                 : "=r" (err), "=&r" (x)                 \
274                 : "b" (addr), "i" (-EFAULT), "0" (err))
275 #endif /* __powerpc64__ */
276
277 #define __get_user_size_allowed(x, ptr, size, retval)           \
278 do {                                                            \
279         retval = 0;                                             \
280         __chk_user_ptr(ptr);                                    \
281         if (size > sizeof(x))                                   \
282                 (x) = __get_user_bad();                         \
283         switch (size) {                                         \
284         case 1: __get_user_asm(x, ptr, retval, "lbz"); break;   \
285         case 2: __get_user_asm(x, ptr, retval, "lhz"); break;   \
286         case 4: __get_user_asm(x, ptr, retval, "lwz"); break;   \
287         case 8: __get_user_asm2(x, ptr, retval);  break;        \
288         default: (x) = __get_user_bad();                        \
289         }                                                       \
290 } while (0)
291
292 #define __get_user_size(x, ptr, size, retval)                   \
293 do {                                                            \
294         allow_read_from_user(ptr, size);                        \
295         __get_user_size_allowed(x, ptr, size, retval);          \
296         prevent_read_from_user(ptr, size);                      \
297 } while (0)
298
299 #define __get_user_nocheck(x, ptr, size, do_allow)                      \
300 ({                                                              \
301         long __gu_err;                                          \
302         unsigned long __gu_val;                                 \
303         __typeof__(*(ptr)) __user *__gu_addr = (ptr);   \
304         __typeof__(size) __gu_size = (size);                    \
305                                                                 \
306         __chk_user_ptr(__gu_addr);                              \
307         if (!is_kernel_addr((unsigned long)__gu_addr))          \
308                 might_fault();                                  \
309         barrier_nospec();                                       \
310         if (do_allow)                                                           \
311                 __get_user_size(__gu_val, __gu_addr, __gu_size, __gu_err);      \
312         else                                                                    \
313                 __get_user_size_allowed(__gu_val, __gu_addr, __gu_size, __gu_err); \
314         (x) = (__typeof__(*(ptr)))__gu_val;                     \
315                                                                 \
316         __gu_err;                                               \
317 })
318
319 #ifndef __powerpc64__
320 #define __get_user64_nocheck(x, ptr, size)                      \
321 ({                                                              \
322         long __gu_err;                                          \
323         long long __gu_val;                                     \
324         __typeof__(*(ptr)) __user *__gu_addr = (ptr);   \
325         __chk_user_ptr(ptr);                                    \
326         if (!is_kernel_addr((unsigned long)__gu_addr))          \
327                 might_fault();                                  \
328         barrier_nospec();                                       \
329         __get_user_size(__gu_val, __gu_addr, (size), __gu_err); \
330         (x) = (__force __typeof__(*(ptr)))__gu_val;                     \
331         __gu_err;                                               \
332 })
333 #endif /* __powerpc64__ */
334
335 #define __get_user_check(x, ptr, size)                                  \
336 ({                                                                      \
337         long __gu_err = -EFAULT;                                        \
338         unsigned long  __gu_val = 0;                                    \
339         __typeof__(*(ptr)) __user *__gu_addr = (ptr);           \
340         __typeof__(size) __gu_size = (size);                            \
341                                                                         \
342         might_fault();                                                  \
343         if (access_ok(VERIFY_READ, __gu_addr, __gu_size)) {             \
344                 barrier_nospec();                                       \
345                 __get_user_size(__gu_val, __gu_addr, __gu_size, __gu_err); \
346         }                                                               \
347         (x) = (__force __typeof__(*(ptr)))__gu_val;                             \
348                                                                         \
349         __gu_err;                                                       \
350 })
351
352 #define __get_user_nosleep(x, ptr, size)                        \
353 ({                                                              \
354         long __gu_err;                                          \
355         unsigned long __gu_val;                                 \
356         __typeof__(*(ptr)) __user *__gu_addr = (ptr);   \
357         __typeof__(size) __gu_size = (size);                    \
358                                                                 \
359         __chk_user_ptr(__gu_addr);                              \
360         barrier_nospec();                                       \
361         __get_user_size(__gu_val, __gu_addr, __gu_size, __gu_err); \
362         (x) = (__force __typeof__(*(ptr)))__gu_val;                     \
363                                                                 \
364         __gu_err;                                               \
365 })
366
367
368 /* more complex routines */
369
370 extern unsigned long __copy_tofrom_user(void __user *to,
371                 const void __user *from, unsigned long size);
372
373 #ifndef __powerpc64__
374
375 static inline unsigned long copy_from_user(void *to,
376                 const void __user *from, unsigned long n)
377 {
378         unsigned long ret;
379
380         if (likely(access_ok(VERIFY_READ, from, n))) {
381                 allow_user_access(to, from, n);
382                 barrier_nospec();
383                 ret = __copy_tofrom_user((__force void __user *)to, from, n);
384                 prevent_user_access(to, from, n);
385                 return ret;
386         }
387         memset(to, 0, n);
388         return n;
389 }
390
391 static inline unsigned long copy_to_user(void __user *to,
392                 const void *from, unsigned long n)
393 {
394         if (access_ok(VERIFY_WRITE, to, n))
395                 return __copy_tofrom_user(to, (__force void __user *)from, n);
396         return n;
397 }
398
399 #else /* __powerpc64__ */
400
401 #define __copy_in_user(to, from, size) \
402         __copy_tofrom_user((to), (from), (size))
403
404 extern unsigned long copy_from_user(void *to, const void __user *from,
405                                     unsigned long n);
406 extern unsigned long copy_to_user(void __user *to, const void *from,
407                                   unsigned long n);
408 extern unsigned long copy_in_user(void __user *to, const void __user *from,
409                                   unsigned long n);
410
411 #endif /* __powerpc64__ */
412
413 static inline unsigned long __copy_from_user_inatomic(void *to,
414                 const void __user *from, unsigned long n)
415 {
416         unsigned long ret;
417         if (__builtin_constant_p(n) && (n <= 8)) {
418                 ret = 1;
419
420                 switch (n) {
421                 case 1:
422                         barrier_nospec();
423                         __get_user_size(*(u8 *)to, from, 1, ret);
424                         break;
425                 case 2:
426                         barrier_nospec();
427                         __get_user_size(*(u16 *)to, from, 2, ret);
428                         break;
429                 case 4:
430                         barrier_nospec();
431                         __get_user_size(*(u32 *)to, from, 4, ret);
432                         break;
433                 case 8:
434                         barrier_nospec();
435                         __get_user_size(*(u64 *)to, from, 8, ret);
436                         break;
437                 }
438                 if (ret == 0)
439                         return 0;
440         }
441
442         barrier_nospec();
443         allow_read_from_user(from, n);
444         ret = __copy_tofrom_user((__force void __user *)to, from, n);
445         prevent_read_from_user(from, n);
446         return ret;
447 }
448
449 static inline unsigned long __copy_to_user_inatomic(void __user *to,
450                 const void *from, unsigned long n)
451 {
452         unsigned long ret;
453
454         if (__builtin_constant_p(n) && (n <= 8)) {
455                 ret = 1;
456
457                 switch (n) {
458                 case 1:
459                         __put_user_size_allowed(*(u8 *)from, (u8 __user *)to, 1, ret);
460                         break;
461                 case 2:
462                         __put_user_size_allowed(*(u16 *)from, (u16 __user *)to, 2, ret);
463                         break;
464                 case 4:
465                         __put_user_size_allowed(*(u32 *)from, (u32 __user *)to, 4, ret);
466                         break;
467                 case 8:
468                         __put_user_size_allowed(*(u64 *)from, (u64 __user *)to, 8, ret);
469                         break;
470                 }
471                 if (ret == 0)
472                         return 0;
473         }
474
475         allow_write_to_user(to, n);
476         ret = __copy_tofrom_user(to, (__force const void __user *)from, n);
477         prevent_write_to_user(to, n);
478         return ret;
479 }
480
481 static inline unsigned long __copy_from_user(void *to,
482                 const void __user *from, unsigned long size)
483 {
484         might_fault();
485         return __copy_from_user_inatomic(to, from, size);
486 }
487
488 static inline unsigned long __copy_to_user(void __user *to,
489                 const void *from, unsigned long size)
490 {
491         might_fault();
492         return __copy_to_user_inatomic(to, from, size);
493 }
494
495 unsigned long __arch_clear_user(void __user *addr, unsigned long size);
496
497 static inline unsigned long clear_user(void __user *addr, unsigned long size)
498 {
499         unsigned long ret = size;
500         might_fault();
501         if (likely(access_ok(VERIFY_WRITE, addr, size))) {
502                 allow_write_to_user(addr, size);
503                 ret = __arch_clear_user(addr, size);
504                 prevent_write_to_user(addr, size);
505         }
506         return ret;
507 }
508
509 static inline unsigned long __clear_user(void __user *addr, unsigned long size)
510 {
511         return clear_user(addr, size);
512 }
513
514 extern long strncpy_from_user(char *dst, const char __user *src, long count);
515 extern __must_check long strlen_user(const char __user *str);
516 extern __must_check long strnlen_user(const char __user *str, long n);
517
518
519 #define user_access_begin()     do { } while (0)
520 #define user_access_end()       prevent_user_access(NULL, NULL, ~0ul)
521
522 #define unsafe_op_wrap(op, err) do { if (unlikely(op)) goto err; } while (0)
523 #define unsafe_get_user(x, p, e) unsafe_op_wrap(__get_user_allowed(x, p), e)
524 #define unsafe_put_user(x, p, e) unsafe_op_wrap(__put_user_allowed(x, p), e)
525 #define unsafe_copy_to_user(d, s, l, e) \
526         unsafe_op_wrap(__copy_to_user_inatomic(d, s, l), e)
527
528 #endif  /* __ASSEMBLY__ */
529 #endif /* __KERNEL__ */
530
531 #endif  /* _ARCH_POWERPC_UACCESS_H */