AFS: implement file locking
[linux-2.6-block.git] / drivers / char / tty_io.c
CommitLineData
1da177e4
LT
1/*
2 * linux/drivers/char/tty_io.c
3 *
4 * Copyright (C) 1991, 1992 Linus Torvalds
5 */
6
7/*
8 * 'tty_io.c' gives an orthogonal feeling to tty's, be they consoles
9 * or rs-channels. It also implements echoing, cooked mode etc.
10 *
11 * Kill-line thanks to John T Kohl, who also corrected VMIN = VTIME = 0.
12 *
13 * Modified by Theodore Ts'o, 9/14/92, to dynamically allocate the
14 * tty_struct and tty_queue structures. Previously there was an array
15 * of 256 tty_struct's which was statically allocated, and the
16 * tty_queue structures were allocated at boot time. Both are now
17 * dynamically allocated only when the tty is open.
18 *
19 * Also restructured routines so that there is more of a separation
20 * between the high-level tty routines (tty_io.c and tty_ioctl.c) and
21 * the low-level tty routines (serial.c, pty.c, console.c). This
22 * makes for cleaner and more compact code. -TYT, 9/17/92
23 *
24 * Modified by Fred N. van Kempen, 01/29/93, to add line disciplines
25 * which can be dynamically activated and de-activated by the line
26 * discipline handling modules (like SLIP).
27 *
28 * NOTE: pay no attention to the line discipline code (yet); its
29 * interface is still subject to change in this version...
30 * -- TYT, 1/31/92
31 *
32 * Added functionality to the OPOST tty handling. No delays, but all
33 * other bits should be there.
34 * -- Nick Holloway <alfie@dcs.warwick.ac.uk>, 27th May 1993.
35 *
36 * Rewrote canonical mode and added more termios flags.
37 * -- julian@uhunix.uhcc.hawaii.edu (J. Cowley), 13Jan94
38 *
39 * Reorganized FASYNC support so mouse code can share it.
40 * -- ctm@ardi.com, 9Sep95
41 *
42 * New TIOCLINUX variants added.
43 * -- mj@k332.feld.cvut.cz, 19-Nov-95
44 *
45 * Restrict vt switching via ioctl()
46 * -- grif@cs.ucr.edu, 5-Dec-95
47 *
48 * Move console and virtual terminal code to more appropriate files,
49 * implement CONFIG_VT and generalize console device interface.
50 * -- Marko Kohtala <Marko.Kohtala@hut.fi>, March 97
51 *
52 * Rewrote init_dev and release_dev to eliminate races.
53 * -- Bill Hawes <whawes@star.net>, June 97
54 *
55 * Added devfs support.
56 * -- C. Scott Ananian <cananian@alumni.princeton.edu>, 13-Jan-1998
57 *
58 * Added support for a Unix98-style ptmx device.
59 * -- C. Scott Ananian <cananian@alumni.princeton.edu>, 14-Jan-1998
60 *
61 * Reduced memory usage for older ARM systems
62 * -- Russell King <rmk@arm.linux.org.uk>
63 *
64 * Move do_SAK() into process context. Less stack use in devfs functions.
65 * alloc_tty_struct() always uses kmalloc() -- Andrew Morton <andrewm@uow.edu.eu> 17Mar01
66 */
67
1da177e4
LT
68#include <linux/types.h>
69#include <linux/major.h>
70#include <linux/errno.h>
71#include <linux/signal.h>
72#include <linux/fcntl.h>
73#include <linux/sched.h>
74#include <linux/interrupt.h>
75#include <linux/tty.h>
76#include <linux/tty_driver.h>
77#include <linux/tty_flip.h>
78#include <linux/devpts_fs.h>
79#include <linux/file.h>
80#include <linux/console.h>
81#include <linux/timer.h>
82#include <linux/ctype.h>
83#include <linux/kd.h>
84#include <linux/mm.h>
85#include <linux/string.h>
86#include <linux/slab.h>
87#include <linux/poll.h>
88#include <linux/proc_fs.h>
89#include <linux/init.h>
90#include <linux/module.h>
91#include <linux/smp_lock.h>
92#include <linux/device.h>
93#include <linux/idr.h>
94#include <linux/wait.h>
95#include <linux/bitops.h>
b20f3ae5 96#include <linux/delay.h>
1da177e4
LT
97
98#include <asm/uaccess.h>
99#include <asm/system.h>
100
101#include <linux/kbd_kern.h>
102#include <linux/vt_kern.h>
103#include <linux/selection.h>
1da177e4
LT
104
105#include <linux/kmod.h>
106
107#undef TTY_DEBUG_HANGUP
108
109#define TTY_PARANOIA_CHECK 1
110#define CHECK_TTY_COUNT 1
111
edc6afc5 112struct ktermios tty_std_termios = { /* for the benefit of tty drivers */
1da177e4
LT
113 .c_iflag = ICRNL | IXON,
114 .c_oflag = OPOST | ONLCR,
115 .c_cflag = B38400 | CS8 | CREAD | HUPCL,
116 .c_lflag = ISIG | ICANON | ECHO | ECHOE | ECHOK |
117 ECHOCTL | ECHOKE | IEXTEN,
edc6afc5
AC
118 .c_cc = INIT_C_CC,
119 .c_ispeed = 38400,
120 .c_ospeed = 38400
1da177e4
LT
121};
122
123EXPORT_SYMBOL(tty_std_termios);
124
125/* This list gets poked at by procfs and various bits of boot up code. This
126 could do with some rationalisation such as pulling the tty proc function
127 into this file */
128
129LIST_HEAD(tty_drivers); /* linked list of tty drivers */
130
24ec839c 131/* Mutex to protect creating and releasing a tty. This is shared with
1da177e4 132 vt.c for deeply disgusting hack reasons */
70522e12 133DEFINE_MUTEX(tty_mutex);
de2a84f2 134EXPORT_SYMBOL(tty_mutex);
1da177e4
LT
135
136#ifdef CONFIG_UNIX98_PTYS
137extern struct tty_driver *ptm_driver; /* Unix98 pty masters; for /dev/ptmx */
138extern int pty_limit; /* Config limit on Unix98 ptys */
139static DEFINE_IDR(allocated_ptys);
140static DECLARE_MUTEX(allocated_ptys_lock);
141static int ptmx_open(struct inode *, struct file *);
142#endif
143
1da177e4
LT
144static void initialize_tty_struct(struct tty_struct *tty);
145
146static ssize_t tty_read(struct file *, char __user *, size_t, loff_t *);
147static ssize_t tty_write(struct file *, const char __user *, size_t, loff_t *);
148ssize_t redirected_tty_write(struct file *, const char __user *, size_t, loff_t *);
149static unsigned int tty_poll(struct file *, poll_table *);
150static int tty_open(struct inode *, struct file *);
151static int tty_release(struct inode *, struct file *);
152int tty_ioctl(struct inode * inode, struct file * file,
153 unsigned int cmd, unsigned long arg);
e10cc1df
PF
154#ifdef CONFIG_COMPAT
155static long tty_compat_ioctl(struct file * file, unsigned int cmd,
156 unsigned long arg);
157#else
158#define tty_compat_ioctl NULL
159#endif
1da177e4 160static int tty_fasync(int fd, struct file * filp, int on);
d5698c28 161static void release_tty(struct tty_struct *tty, int idx);
2a65f1d9 162static void __proc_set_tty(struct task_struct *tsk, struct tty_struct *tty);
98a27ba4 163static void proc_set_tty(struct task_struct *tsk, struct tty_struct *tty);
1da177e4 164
af9b897e
AC
165/**
166 * alloc_tty_struct - allocate a tty object
167 *
168 * Return a new empty tty structure. The data fields have not
169 * been initialized in any way but has been zeroed
170 *
171 * Locking: none
af9b897e 172 */
1da177e4
LT
173
174static struct tty_struct *alloc_tty_struct(void)
175{
1266b1e1 176 return kzalloc(sizeof(struct tty_struct), GFP_KERNEL);
1da177e4
LT
177}
178
33f0f88f
AC
179static void tty_buffer_free_all(struct tty_struct *);
180
af9b897e
AC
181/**
182 * free_tty_struct - free a disused tty
183 * @tty: tty struct to free
184 *
185 * Free the write buffers, tty queue and tty memory itself.
186 *
187 * Locking: none. Must be called after tty is definitely unused
188 */
189
1da177e4
LT
190static inline void free_tty_struct(struct tty_struct *tty)
191{
192 kfree(tty->write_buf);
33f0f88f 193 tty_buffer_free_all(tty);
1da177e4
LT
194 kfree(tty);
195}
196
197#define TTY_NUMBER(tty) ((tty)->index + (tty)->driver->name_base)
198
af9b897e
AC
199/**
200 * tty_name - return tty naming
201 * @tty: tty structure
202 * @buf: buffer for output
203 *
204 * Convert a tty structure into a name. The name reflects the kernel
205 * naming policy and if udev is in use may not reflect user space
206 *
207 * Locking: none
208 */
209
1da177e4
LT
210char *tty_name(struct tty_struct *tty, char *buf)
211{
212 if (!tty) /* Hmm. NULL pointer. That's fun. */
213 strcpy(buf, "NULL tty");
214 else
215 strcpy(buf, tty->name);
216 return buf;
217}
218
219EXPORT_SYMBOL(tty_name);
220
d769a669 221int tty_paranoia_check(struct tty_struct *tty, struct inode *inode,
1da177e4
LT
222 const char *routine)
223{
224#ifdef TTY_PARANOIA_CHECK
225 if (!tty) {
226 printk(KERN_WARNING
227 "null TTY for (%d:%d) in %s\n",
228 imajor(inode), iminor(inode), routine);
229 return 1;
230 }
231 if (tty->magic != TTY_MAGIC) {
232 printk(KERN_WARNING
233 "bad magic number for tty struct (%d:%d) in %s\n",
234 imajor(inode), iminor(inode), routine);
235 return 1;
236 }
237#endif
238 return 0;
239}
240
241static int check_tty_count(struct tty_struct *tty, const char *routine)
242{
243#ifdef CHECK_TTY_COUNT
244 struct list_head *p;
245 int count = 0;
246
247 file_list_lock();
248 list_for_each(p, &tty->tty_files) {
249 count++;
250 }
251 file_list_unlock();
252 if (tty->driver->type == TTY_DRIVER_TYPE_PTY &&
253 tty->driver->subtype == PTY_TYPE_SLAVE &&
254 tty->link && tty->link->count)
255 count++;
256 if (tty->count != count) {
257 printk(KERN_WARNING "Warning: dev (%s) tty->count(%d) "
258 "!= #fd's(%d) in %s\n",
259 tty->name, tty->count, count, routine);
260 return count;
24ec839c 261 }
1da177e4
LT
262#endif
263 return 0;
264}
265
33f0f88f
AC
266/*
267 * Tty buffer allocation management
268 */
269
af9b897e
AC
270/**
271 * tty_buffer_free_all - free buffers used by a tty
272 * @tty: tty to free from
273 *
274 * Remove all the buffers pending on a tty whether queued with data
275 * or in the free ring. Must be called when the tty is no longer in use
276 *
277 * Locking: none
278 */
279
33f0f88f
AC
280static void tty_buffer_free_all(struct tty_struct *tty)
281{
282 struct tty_buffer *thead;
283 while((thead = tty->buf.head) != NULL) {
284 tty->buf.head = thead->next;
285 kfree(thead);
286 }
287 while((thead = tty->buf.free) != NULL) {
288 tty->buf.free = thead->next;
289 kfree(thead);
290 }
291 tty->buf.tail = NULL;
01da5fd8 292 tty->buf.memory_used = 0;
33f0f88f
AC
293}
294
01da5fd8
AC
295/**
296 * tty_buffer_init - prepare a tty buffer structure
297 * @tty: tty to initialise
298 *
299 * Set up the initial state of the buffer management for a tty device.
300 * Must be called before the other tty buffer functions are used.
301 *
302 * Locking: none
303 */
304
33f0f88f
AC
305static void tty_buffer_init(struct tty_struct *tty)
306{
808249ce 307 spin_lock_init(&tty->buf.lock);
33f0f88f
AC
308 tty->buf.head = NULL;
309 tty->buf.tail = NULL;
310 tty->buf.free = NULL;
01da5fd8 311 tty->buf.memory_used = 0;
33f0f88f
AC
312}
313
01da5fd8
AC
314/**
315 * tty_buffer_alloc - allocate a tty buffer
316 * @tty: tty device
317 * @size: desired size (characters)
318 *
319 * Allocate a new tty buffer to hold the desired number of characters.
320 * Return NULL if out of memory or the allocation would exceed the
321 * per device queue
322 *
323 * Locking: Caller must hold tty->buf.lock
324 */
325
326static struct tty_buffer *tty_buffer_alloc(struct tty_struct *tty, size_t size)
33f0f88f 327{
01da5fd8
AC
328 struct tty_buffer *p;
329
330 if (tty->buf.memory_used + size > 65536)
331 return NULL;
332 p = kmalloc(sizeof(struct tty_buffer) + 2 * size, GFP_ATOMIC);
33f0f88f
AC
333 if(p == NULL)
334 return NULL;
335 p->used = 0;
336 p->size = size;
337 p->next = NULL;
8977d929
PF
338 p->commit = 0;
339 p->read = 0;
33f0f88f
AC
340 p->char_buf_ptr = (char *)(p->data);
341 p->flag_buf_ptr = (unsigned char *)p->char_buf_ptr + size;
01da5fd8 342 tty->buf.memory_used += size;
33f0f88f
AC
343 return p;
344}
345
01da5fd8
AC
346/**
347 * tty_buffer_free - free a tty buffer
348 * @tty: tty owning the buffer
349 * @b: the buffer to free
350 *
351 * Free a tty buffer, or add it to the free list according to our
352 * internal strategy
353 *
354 * Locking: Caller must hold tty->buf.lock
355 */
33f0f88f
AC
356
357static void tty_buffer_free(struct tty_struct *tty, struct tty_buffer *b)
358{
359 /* Dumb strategy for now - should keep some stats */
01da5fd8
AC
360 tty->buf.memory_used -= b->size;
361 WARN_ON(tty->buf.memory_used < 0);
362
33f0f88f
AC
363 if(b->size >= 512)
364 kfree(b);
365 else {
366 b->next = tty->buf.free;
367 tty->buf.free = b;
368 }
369}
370
c5c34d48
PF
371/**
372 * tty_buffer_flush - flush full tty buffers
373 * @tty: tty to flush
374 *
375 * flush all the buffers containing receive data
376 *
377 * Locking: none
378 */
379
380static void tty_buffer_flush(struct tty_struct *tty)
381{
382 struct tty_buffer *thead;
383 unsigned long flags;
384
385 spin_lock_irqsave(&tty->buf.lock, flags);
386 while((thead = tty->buf.head) != NULL) {
387 tty->buf.head = thead->next;
388 tty_buffer_free(tty, thead);
389 }
390 tty->buf.tail = NULL;
391 spin_unlock_irqrestore(&tty->buf.lock, flags);
392}
393
01da5fd8
AC
394/**
395 * tty_buffer_find - find a free tty buffer
396 * @tty: tty owning the buffer
397 * @size: characters wanted
398 *
399 * Locate an existing suitable tty buffer or if we are lacking one then
400 * allocate a new one. We round our buffers off in 256 character chunks
401 * to get better allocation behaviour.
402 *
403 * Locking: Caller must hold tty->buf.lock
404 */
405
33f0f88f
AC
406static struct tty_buffer *tty_buffer_find(struct tty_struct *tty, size_t size)
407{
408 struct tty_buffer **tbh = &tty->buf.free;
409 while((*tbh) != NULL) {
410 struct tty_buffer *t = *tbh;
411 if(t->size >= size) {
412 *tbh = t->next;
413 t->next = NULL;
414 t->used = 0;
8977d929
PF
415 t->commit = 0;
416 t->read = 0;
01da5fd8 417 tty->buf.memory_used += t->size;
33f0f88f
AC
418 return t;
419 }
420 tbh = &((*tbh)->next);
421 }
422 /* Round the buffer size out */
423 size = (size + 0xFF) & ~ 0xFF;
01da5fd8 424 return tty_buffer_alloc(tty, size);
33f0f88f
AC
425 /* Should possibly check if this fails for the largest buffer we
426 have queued and recycle that ? */
427}
428
01da5fd8
AC
429/**
430 * tty_buffer_request_room - grow tty buffer if needed
431 * @tty: tty structure
432 * @size: size desired
433 *
434 * Make at least size bytes of linear space available for the tty
435 * buffer. If we fail return the size we managed to find.
436 *
437 * Locking: Takes tty->buf.lock
438 */
33f0f88f
AC
439int tty_buffer_request_room(struct tty_struct *tty, size_t size)
440{
808249ce
PF
441 struct tty_buffer *b, *n;
442 int left;
443 unsigned long flags;
444
445 spin_lock_irqsave(&tty->buf.lock, flags);
33f0f88f
AC
446
447 /* OPTIMISATION: We could keep a per tty "zero" sized buffer to
448 remove this conditional if its worth it. This would be invisible
449 to the callers */
33b37a33 450 if ((b = tty->buf.tail) != NULL)
33f0f88f 451 left = b->size - b->used;
33b37a33 452 else
808249ce
PF
453 left = 0;
454
455 if (left < size) {
456 /* This is the slow path - looking for new buffers to use */
457 if ((n = tty_buffer_find(tty, size)) != NULL) {
458 if (b != NULL) {
459 b->next = n;
8977d929 460 b->commit = b->used;
808249ce
PF
461 } else
462 tty->buf.head = n;
463 tty->buf.tail = n;
808249ce
PF
464 } else
465 size = left;
466 }
467
468 spin_unlock_irqrestore(&tty->buf.lock, flags);
33f0f88f
AC
469 return size;
470}
33f0f88f
AC
471EXPORT_SYMBOL_GPL(tty_buffer_request_room);
472
af9b897e
AC
473/**
474 * tty_insert_flip_string - Add characters to the tty buffer
475 * @tty: tty structure
476 * @chars: characters
477 * @size: size
478 *
479 * Queue a series of bytes to the tty buffering. All the characters
480 * passed are marked as without error. Returns the number added.
481 *
482 * Locking: Called functions may take tty->buf.lock
483 */
484
e1a25090
AM
485int tty_insert_flip_string(struct tty_struct *tty, const unsigned char *chars,
486 size_t size)
33f0f88f
AC
487{
488 int copied = 0;
489 do {
490 int space = tty_buffer_request_room(tty, size - copied);
491 struct tty_buffer *tb = tty->buf.tail;
492 /* If there is no space then tb may be NULL */
493 if(unlikely(space == 0))
494 break;
495 memcpy(tb->char_buf_ptr + tb->used, chars, space);
496 memset(tb->flag_buf_ptr + tb->used, TTY_NORMAL, space);
497 tb->used += space;
498 copied += space;
499 chars += space;
527063ba
AD
500 /* There is a small chance that we need to split the data over
501 several buffers. If this is the case we must loop */
502 } while (unlikely(size > copied));
33f0f88f
AC
503 return copied;
504}
ee37df78 505EXPORT_SYMBOL(tty_insert_flip_string);
33f0f88f 506
af9b897e
AC
507/**
508 * tty_insert_flip_string_flags - Add characters to the tty buffer
509 * @tty: tty structure
510 * @chars: characters
511 * @flags: flag bytes
512 * @size: size
513 *
514 * Queue a series of bytes to the tty buffering. For each character
515 * the flags array indicates the status of the character. Returns the
516 * number added.
517 *
518 * Locking: Called functions may take tty->buf.lock
519 */
520
e1a25090
AM
521int tty_insert_flip_string_flags(struct tty_struct *tty,
522 const unsigned char *chars, const char *flags, size_t size)
33f0f88f
AC
523{
524 int copied = 0;
525 do {
526 int space = tty_buffer_request_room(tty, size - copied);
527 struct tty_buffer *tb = tty->buf.tail;
528 /* If there is no space then tb may be NULL */
529 if(unlikely(space == 0))
530 break;
531 memcpy(tb->char_buf_ptr + tb->used, chars, space);
532 memcpy(tb->flag_buf_ptr + tb->used, flags, space);
533 tb->used += space;
534 copied += space;
535 chars += space;
536 flags += space;
527063ba
AD
537 /* There is a small chance that we need to split the data over
538 several buffers. If this is the case we must loop */
539 } while (unlikely(size > copied));
33f0f88f
AC
540 return copied;
541}
ff4547f4 542EXPORT_SYMBOL(tty_insert_flip_string_flags);
33f0f88f 543
af9b897e
AC
544/**
545 * tty_schedule_flip - push characters to ldisc
546 * @tty: tty to push from
547 *
548 * Takes any pending buffers and transfers their ownership to the
549 * ldisc side of the queue. It then schedules those characters for
550 * processing by the line discipline.
551 *
552 * Locking: Takes tty->buf.lock
553 */
554
e1a25090
AM
555void tty_schedule_flip(struct tty_struct *tty)
556{
557 unsigned long flags;
558 spin_lock_irqsave(&tty->buf.lock, flags);
33b37a33 559 if (tty->buf.tail != NULL)
e1a25090 560 tty->buf.tail->commit = tty->buf.tail->used;
e1a25090
AM
561 spin_unlock_irqrestore(&tty->buf.lock, flags);
562 schedule_delayed_work(&tty->buf.work, 1);
563}
564EXPORT_SYMBOL(tty_schedule_flip);
33f0f88f 565
af9b897e
AC
566/**
567 * tty_prepare_flip_string - make room for characters
568 * @tty: tty
569 * @chars: return pointer for character write area
570 * @size: desired size
571 *
33f0f88f
AC
572 * Prepare a block of space in the buffer for data. Returns the length
573 * available and buffer pointer to the space which is now allocated and
574 * accounted for as ready for normal characters. This is used for drivers
575 * that need their own block copy routines into the buffer. There is no
576 * guarantee the buffer is a DMA target!
af9b897e
AC
577 *
578 * Locking: May call functions taking tty->buf.lock
33f0f88f
AC
579 */
580
581int tty_prepare_flip_string(struct tty_struct *tty, unsigned char **chars, size_t size)
582{
583 int space = tty_buffer_request_room(tty, size);
808249ce
PF
584 if (likely(space)) {
585 struct tty_buffer *tb = tty->buf.tail;
586 *chars = tb->char_buf_ptr + tb->used;
587 memset(tb->flag_buf_ptr + tb->used, TTY_NORMAL, space);
588 tb->used += space;
589 }
33f0f88f
AC
590 return space;
591}
592
593EXPORT_SYMBOL_GPL(tty_prepare_flip_string);
594
af9b897e
AC
595/**
596 * tty_prepare_flip_string_flags - make room for characters
597 * @tty: tty
598 * @chars: return pointer for character write area
599 * @flags: return pointer for status flag write area
600 * @size: desired size
601 *
33f0f88f
AC
602 * Prepare a block of space in the buffer for data. Returns the length
603 * available and buffer pointer to the space which is now allocated and
604 * accounted for as ready for characters. This is used for drivers
605 * that need their own block copy routines into the buffer. There is no
606 * guarantee the buffer is a DMA target!
af9b897e
AC
607 *
608 * Locking: May call functions taking tty->buf.lock
33f0f88f
AC
609 */
610
611int tty_prepare_flip_string_flags(struct tty_struct *tty, unsigned char **chars, char **flags, size_t size)
612{
613 int space = tty_buffer_request_room(tty, size);
808249ce
PF
614 if (likely(space)) {
615 struct tty_buffer *tb = tty->buf.tail;
616 *chars = tb->char_buf_ptr + tb->used;
617 *flags = tb->flag_buf_ptr + tb->used;
618 tb->used += space;
619 }
33f0f88f
AC
620 return space;
621}
622
623EXPORT_SYMBOL_GPL(tty_prepare_flip_string_flags);
624
625
626
af9b897e
AC
627/**
628 * tty_set_termios_ldisc - set ldisc field
629 * @tty: tty structure
630 * @num: line discipline number
631 *
1da177e4
LT
632 * This is probably overkill for real world processors but
633 * they are not on hot paths so a little discipline won't do
634 * any harm.
af9b897e 635 *
24ec839c 636 * Locking: takes termios_mutex
1da177e4
LT
637 */
638
639static void tty_set_termios_ldisc(struct tty_struct *tty, int num)
640{
5785c95b 641 mutex_lock(&tty->termios_mutex);
1da177e4 642 tty->termios->c_line = num;
5785c95b 643 mutex_unlock(&tty->termios_mutex);
1da177e4
LT
644}
645
646/*
647 * This guards the refcounted line discipline lists. The lock
648 * must be taken with irqs off because there are hangup path
649 * callers who will do ldisc lookups and cannot sleep.
650 */
651
652static DEFINE_SPINLOCK(tty_ldisc_lock);
653static DECLARE_WAIT_QUEUE_HEAD(tty_ldisc_wait);
bfb07599 654static struct tty_ldisc tty_ldiscs[NR_LDISCS]; /* line disc dispatch table */
1da177e4 655
af9b897e
AC
656/**
657 * tty_register_ldisc - install a line discipline
658 * @disc: ldisc number
659 * @new_ldisc: pointer to the ldisc object
660 *
661 * Installs a new line discipline into the kernel. The discipline
662 * is set up as unreferenced and then made available to the kernel
663 * from this point onwards.
664 *
665 * Locking:
666 * takes tty_ldisc_lock to guard against ldisc races
667 */
668
1da177e4
LT
669int tty_register_ldisc(int disc, struct tty_ldisc *new_ldisc)
670{
671 unsigned long flags;
672 int ret = 0;
673
674 if (disc < N_TTY || disc >= NR_LDISCS)
675 return -EINVAL;
676
677 spin_lock_irqsave(&tty_ldisc_lock, flags);
bfb07599
AD
678 tty_ldiscs[disc] = *new_ldisc;
679 tty_ldiscs[disc].num = disc;
680 tty_ldiscs[disc].flags |= LDISC_FLAG_DEFINED;
681 tty_ldiscs[disc].refcount = 0;
1da177e4
LT
682 spin_unlock_irqrestore(&tty_ldisc_lock, flags);
683
684 return ret;
685}
1da177e4
LT
686EXPORT_SYMBOL(tty_register_ldisc);
687
af9b897e
AC
688/**
689 * tty_unregister_ldisc - unload a line discipline
690 * @disc: ldisc number
691 * @new_ldisc: pointer to the ldisc object
692 *
693 * Remove a line discipline from the kernel providing it is not
694 * currently in use.
695 *
696 * Locking:
697 * takes tty_ldisc_lock to guard against ldisc races
698 */
699
bfb07599
AD
700int tty_unregister_ldisc(int disc)
701{
702 unsigned long flags;
703 int ret = 0;
704
705 if (disc < N_TTY || disc >= NR_LDISCS)
706 return -EINVAL;
707
708 spin_lock_irqsave(&tty_ldisc_lock, flags);
709 if (tty_ldiscs[disc].refcount)
710 ret = -EBUSY;
711 else
712 tty_ldiscs[disc].flags &= ~LDISC_FLAG_DEFINED;
713 spin_unlock_irqrestore(&tty_ldisc_lock, flags);
714
715 return ret;
716}
717EXPORT_SYMBOL(tty_unregister_ldisc);
718
af9b897e
AC
719/**
720 * tty_ldisc_get - take a reference to an ldisc
721 * @disc: ldisc number
722 *
723 * Takes a reference to a line discipline. Deals with refcounts and
724 * module locking counts. Returns NULL if the discipline is not available.
725 * Returns a pointer to the discipline and bumps the ref count if it is
726 * available
727 *
728 * Locking:
729 * takes tty_ldisc_lock to guard against ldisc races
730 */
731
1da177e4
LT
732struct tty_ldisc *tty_ldisc_get(int disc)
733{
734 unsigned long flags;
735 struct tty_ldisc *ld;
736
737 if (disc < N_TTY || disc >= NR_LDISCS)
738 return NULL;
739
740 spin_lock_irqsave(&tty_ldisc_lock, flags);
741
742 ld = &tty_ldiscs[disc];
743 /* Check the entry is defined */
744 if(ld->flags & LDISC_FLAG_DEFINED)
745 {
746 /* If the module is being unloaded we can't use it */
747 if (!try_module_get(ld->owner))
748 ld = NULL;
749 else /* lock it */
750 ld->refcount++;
751 }
752 else
753 ld = NULL;
754 spin_unlock_irqrestore(&tty_ldisc_lock, flags);
755 return ld;
756}
757
758EXPORT_SYMBOL_GPL(tty_ldisc_get);
759
af9b897e
AC
760/**
761 * tty_ldisc_put - drop ldisc reference
762 * @disc: ldisc number
763 *
764 * Drop a reference to a line discipline. Manage refcounts and
765 * module usage counts
766 *
767 * Locking:
768 * takes tty_ldisc_lock to guard against ldisc races
769 */
770
1da177e4
LT
771void tty_ldisc_put(int disc)
772{
773 struct tty_ldisc *ld;
774 unsigned long flags;
775
56ee4827 776 BUG_ON(disc < N_TTY || disc >= NR_LDISCS);
1da177e4
LT
777
778 spin_lock_irqsave(&tty_ldisc_lock, flags);
779 ld = &tty_ldiscs[disc];
56ee4827
ES
780 BUG_ON(ld->refcount == 0);
781 ld->refcount--;
1da177e4
LT
782 module_put(ld->owner);
783 spin_unlock_irqrestore(&tty_ldisc_lock, flags);
784}
785
786EXPORT_SYMBOL_GPL(tty_ldisc_put);
787
af9b897e
AC
788/**
789 * tty_ldisc_assign - set ldisc on a tty
790 * @tty: tty to assign
791 * @ld: line discipline
792 *
793 * Install an instance of a line discipline into a tty structure. The
794 * ldisc must have a reference count above zero to ensure it remains/
795 * The tty instance refcount starts at zero.
796 *
797 * Locking:
798 * Caller must hold references
799 */
800
1da177e4
LT
801static void tty_ldisc_assign(struct tty_struct *tty, struct tty_ldisc *ld)
802{
803 tty->ldisc = *ld;
804 tty->ldisc.refcount = 0;
805}
806
807/**
808 * tty_ldisc_try - internal helper
809 * @tty: the tty
810 *
811 * Make a single attempt to grab and bump the refcount on
812 * the tty ldisc. Return 0 on failure or 1 on success. This is
813 * used to implement both the waiting and non waiting versions
814 * of tty_ldisc_ref
af9b897e
AC
815 *
816 * Locking: takes tty_ldisc_lock
1da177e4
LT
817 */
818
819static int tty_ldisc_try(struct tty_struct *tty)
820{
821 unsigned long flags;
822 struct tty_ldisc *ld;
823 int ret = 0;
824
825 spin_lock_irqsave(&tty_ldisc_lock, flags);
826 ld = &tty->ldisc;
827 if(test_bit(TTY_LDISC, &tty->flags))
828 {
829 ld->refcount++;
830 ret = 1;
831 }
832 spin_unlock_irqrestore(&tty_ldisc_lock, flags);
833 return ret;
834}
835
836/**
837 * tty_ldisc_ref_wait - wait for the tty ldisc
838 * @tty: tty device
839 *
840 * Dereference the line discipline for the terminal and take a
841 * reference to it. If the line discipline is in flux then
842 * wait patiently until it changes.
843 *
844 * Note: Must not be called from an IRQ/timer context. The caller
845 * must also be careful not to hold other locks that will deadlock
846 * against a discipline change, such as an existing ldisc reference
847 * (which we check for)
af9b897e
AC
848 *
849 * Locking: call functions take tty_ldisc_lock
1da177e4
LT
850 */
851
852struct tty_ldisc *tty_ldisc_ref_wait(struct tty_struct *tty)
853{
854 /* wait_event is a macro */
855 wait_event(tty_ldisc_wait, tty_ldisc_try(tty));
856 if(tty->ldisc.refcount == 0)
857 printk(KERN_ERR "tty_ldisc_ref_wait\n");
858 return &tty->ldisc;
859}
860
861EXPORT_SYMBOL_GPL(tty_ldisc_ref_wait);
862
863/**
864 * tty_ldisc_ref - get the tty ldisc
865 * @tty: tty device
866 *
867 * Dereference the line discipline for the terminal and take a
868 * reference to it. If the line discipline is in flux then
869 * return NULL. Can be called from IRQ and timer functions.
af9b897e
AC
870 *
871 * Locking: called functions take tty_ldisc_lock
1da177e4
LT
872 */
873
874struct tty_ldisc *tty_ldisc_ref(struct tty_struct *tty)
875{
876 if(tty_ldisc_try(tty))
877 return &tty->ldisc;
878 return NULL;
879}
880
881EXPORT_SYMBOL_GPL(tty_ldisc_ref);
882
883/**
884 * tty_ldisc_deref - free a tty ldisc reference
885 * @ld: reference to free up
886 *
887 * Undoes the effect of tty_ldisc_ref or tty_ldisc_ref_wait. May
888 * be called in IRQ context.
af9b897e
AC
889 *
890 * Locking: takes tty_ldisc_lock
1da177e4
LT
891 */
892
893void tty_ldisc_deref(struct tty_ldisc *ld)
894{
895 unsigned long flags;
896
56ee4827 897 BUG_ON(ld == NULL);
1da177e4
LT
898
899 spin_lock_irqsave(&tty_ldisc_lock, flags);
900 if(ld->refcount == 0)
901 printk(KERN_ERR "tty_ldisc_deref: no references.\n");
902 else
903 ld->refcount--;
904 if(ld->refcount == 0)
905 wake_up(&tty_ldisc_wait);
906 spin_unlock_irqrestore(&tty_ldisc_lock, flags);
907}
908
909EXPORT_SYMBOL_GPL(tty_ldisc_deref);
910
911/**
912 * tty_ldisc_enable - allow ldisc use
913 * @tty: terminal to activate ldisc on
914 *
915 * Set the TTY_LDISC flag when the line discipline can be called
916 * again. Do neccessary wakeups for existing sleepers.
917 *
918 * Note: nobody should set this bit except via this function. Clearing
919 * directly is allowed.
920 */
921
922static void tty_ldisc_enable(struct tty_struct *tty)
923{
924 set_bit(TTY_LDISC, &tty->flags);
925 wake_up(&tty_ldisc_wait);
926}
927
928/**
929 * tty_set_ldisc - set line discipline
930 * @tty: the terminal to set
931 * @ldisc: the line discipline
932 *
933 * Set the discipline of a tty line. Must be called from a process
934 * context.
af9b897e
AC
935 *
936 * Locking: takes tty_ldisc_lock.
24ec839c 937 * called functions take termios_mutex
1da177e4
LT
938 */
939
940static int tty_set_ldisc(struct tty_struct *tty, int ldisc)
941{
ff55fe20
JB
942 int retval = 0;
943 struct tty_ldisc o_ldisc;
1da177e4
LT
944 char buf[64];
945 int work;
946 unsigned long flags;
947 struct tty_ldisc *ld;
ff55fe20 948 struct tty_struct *o_tty;
1da177e4
LT
949
950 if ((ldisc < N_TTY) || (ldisc >= NR_LDISCS))
951 return -EINVAL;
952
953restart:
954
1da177e4
LT
955 ld = tty_ldisc_get(ldisc);
956 /* Eduardo Blanco <ejbs@cs.cs.com.uy> */
957 /* Cyrus Durgin <cider@speakeasy.org> */
958 if (ld == NULL) {
959 request_module("tty-ldisc-%d", ldisc);
960 ld = tty_ldisc_get(ldisc);
961 }
962 if (ld == NULL)
963 return -EINVAL;
964
33f0f88f
AC
965 /*
966 * Problem: What do we do if this blocks ?
967 */
968
1da177e4
LT
969 tty_wait_until_sent(tty, 0);
970
ff55fe20
JB
971 if (tty->ldisc.num == ldisc) {
972 tty_ldisc_put(ldisc);
973 return 0;
974 }
975
ae030e43
PF
976 /*
977 * No more input please, we are switching. The new ldisc
978 * will update this value in the ldisc open function
979 */
980
981 tty->receive_room = 0;
982
ff55fe20
JB
983 o_ldisc = tty->ldisc;
984 o_tty = tty->link;
985
1da177e4
LT
986 /*
987 * Make sure we don't change while someone holds a
988 * reference to the line discipline. The TTY_LDISC bit
989 * prevents anyone taking a reference once it is clear.
990 * We need the lock to avoid racing reference takers.
991 */
ff55fe20 992
1da177e4 993 spin_lock_irqsave(&tty_ldisc_lock, flags);
ff55fe20
JB
994 if (tty->ldisc.refcount || (o_tty && o_tty->ldisc.refcount)) {
995 if(tty->ldisc.refcount) {
996 /* Free the new ldisc we grabbed. Must drop the lock
997 first. */
998 spin_unlock_irqrestore(&tty_ldisc_lock, flags);
999 tty_ldisc_put(ldisc);
1000 /*
1001 * There are several reasons we may be busy, including
1002 * random momentary I/O traffic. We must therefore
1003 * retry. We could distinguish between blocking ops
1004 * and retries if we made tty_ldisc_wait() smarter. That
1005 * is up for discussion.
1006 */
1007 if (wait_event_interruptible(tty_ldisc_wait, tty->ldisc.refcount == 0) < 0)
1008 return -ERESTARTSYS;
1009 goto restart;
1010 }
1011 if(o_tty && o_tty->ldisc.refcount) {
1012 spin_unlock_irqrestore(&tty_ldisc_lock, flags);
1013 tty_ldisc_put(ldisc);
1014 if (wait_event_interruptible(tty_ldisc_wait, o_tty->ldisc.refcount == 0) < 0)
1015 return -ERESTARTSYS;
1016 goto restart;
1017 }
1018 }
1019
1020 /* if the TTY_LDISC bit is set, then we are racing against another ldisc change */
1021
1022 if (!test_bit(TTY_LDISC, &tty->flags)) {
1da177e4
LT
1023 spin_unlock_irqrestore(&tty_ldisc_lock, flags);
1024 tty_ldisc_put(ldisc);
ff55fe20
JB
1025 ld = tty_ldisc_ref_wait(tty);
1026 tty_ldisc_deref(ld);
1da177e4
LT
1027 goto restart;
1028 }
ff55fe20
JB
1029
1030 clear_bit(TTY_LDISC, &tty->flags);
817d6d3b 1031 if (o_tty)
ff55fe20 1032 clear_bit(TTY_LDISC, &o_tty->flags);
1da177e4 1033 spin_unlock_irqrestore(&tty_ldisc_lock, flags);
ff55fe20 1034
1da177e4
LT
1035 /*
1036 * From this point on we know nobody has an ldisc
1037 * usage reference, nor can they obtain one until
1038 * we say so later on.
1039 */
ff55fe20 1040
33f0f88f 1041 work = cancel_delayed_work(&tty->buf.work);
1da177e4 1042 /*
33f0f88f 1043 * Wait for ->hangup_work and ->buf.work handlers to terminate
1da177e4
LT
1044 */
1045
1046 flush_scheduled_work();
1047 /* Shutdown the current discipline. */
1048 if (tty->ldisc.close)
1049 (tty->ldisc.close)(tty);
1050
1051 /* Now set up the new line discipline. */
1052 tty_ldisc_assign(tty, ld);
1053 tty_set_termios_ldisc(tty, ldisc);
1054 if (tty->ldisc.open)
1055 retval = (tty->ldisc.open)(tty);
1056 if (retval < 0) {
1057 tty_ldisc_put(ldisc);
1058 /* There is an outstanding reference here so this is safe */
1059 tty_ldisc_assign(tty, tty_ldisc_get(o_ldisc.num));
1060 tty_set_termios_ldisc(tty, tty->ldisc.num);
1061 if (tty->ldisc.open && (tty->ldisc.open(tty) < 0)) {
1062 tty_ldisc_put(o_ldisc.num);
1063 /* This driver is always present */
1064 tty_ldisc_assign(tty, tty_ldisc_get(N_TTY));
1065 tty_set_termios_ldisc(tty, N_TTY);
1066 if (tty->ldisc.open) {
1067 int r = tty->ldisc.open(tty);
1068
1069 if (r < 0)
1070 panic("Couldn't open N_TTY ldisc for "
1071 "%s --- error %d.",
1072 tty_name(tty, buf), r);
1073 }
1074 }
1075 }
1076 /* At this point we hold a reference to the new ldisc and a
1077 a reference to the old ldisc. If we ended up flipping back
1078 to the existing ldisc we have two references to it */
1079
1080 if (tty->ldisc.num != o_ldisc.num && tty->driver->set_ldisc)
1081 tty->driver->set_ldisc(tty);
1082
1083 tty_ldisc_put(o_ldisc.num);
1084
1085 /*
1086 * Allow ldisc referencing to occur as soon as the driver
1087 * ldisc callback completes.
1088 */
1089
1090 tty_ldisc_enable(tty);
ff55fe20
JB
1091 if (o_tty)
1092 tty_ldisc_enable(o_tty);
1da177e4
LT
1093
1094 /* Restart it in case no characters kick it off. Safe if
1095 already running */
ff55fe20 1096 if (work)
33f0f88f 1097 schedule_delayed_work(&tty->buf.work, 1);
1da177e4
LT
1098 return retval;
1099}
1100
af9b897e
AC
1101/**
1102 * get_tty_driver - find device of a tty
1103 * @dev_t: device identifier
1104 * @index: returns the index of the tty
1105 *
1106 * This routine returns a tty driver structure, given a device number
1107 * and also passes back the index number.
1108 *
1109 * Locking: caller must hold tty_mutex
1da177e4 1110 */
af9b897e 1111
1da177e4
LT
1112static struct tty_driver *get_tty_driver(dev_t device, int *index)
1113{
1114 struct tty_driver *p;
1115
1116 list_for_each_entry(p, &tty_drivers, tty_drivers) {
1117 dev_t base = MKDEV(p->major, p->minor_start);
1118 if (device < base || device >= base + p->num)
1119 continue;
1120 *index = device - base;
1121 return p;
1122 }
1123 return NULL;
1124}
1125
af9b897e
AC
1126/**
1127 * tty_check_change - check for POSIX terminal changes
1128 * @tty: tty to check
1129 *
1130 * If we try to write to, or set the state of, a terminal and we're
1131 * not in the foreground, send a SIGTTOU. If the signal is blocked or
1132 * ignored, go ahead and perform the operation. (POSIX 7.2)
1133 *
1134 * Locking: none
1da177e4 1135 */
af9b897e 1136
1da177e4
LT
1137int tty_check_change(struct tty_struct * tty)
1138{
1139 if (current->signal->tty != tty)
1140 return 0;
ab521dc0
EB
1141 if (!tty->pgrp) {
1142 printk(KERN_WARNING "tty_check_change: tty->pgrp == NULL!\n");
1da177e4
LT
1143 return 0;
1144 }
ab521dc0 1145 if (task_pgrp(current) == tty->pgrp)
1da177e4
LT
1146 return 0;
1147 if (is_ignored(SIGTTOU))
1148 return 0;
3e7cd6c4 1149 if (is_current_pgrp_orphaned())
1da177e4 1150 return -EIO;
040b6362
ON
1151 kill_pgrp(task_pgrp(current), SIGTTOU, 1);
1152 set_thread_flag(TIF_SIGPENDING);
1da177e4
LT
1153 return -ERESTARTSYS;
1154}
1155
1156EXPORT_SYMBOL(tty_check_change);
1157
1158static ssize_t hung_up_tty_read(struct file * file, char __user * buf,
1159 size_t count, loff_t *ppos)
1160{
1161 return 0;
1162}
1163
1164static ssize_t hung_up_tty_write(struct file * file, const char __user * buf,
1165 size_t count, loff_t *ppos)
1166{
1167 return -EIO;
1168}
1169
1170/* No kernel lock held - none needed ;) */
1171static unsigned int hung_up_tty_poll(struct file * filp, poll_table * wait)
1172{
1173 return POLLIN | POLLOUT | POLLERR | POLLHUP | POLLRDNORM | POLLWRNORM;
1174}
1175
38ad2ed0
PF
1176static int hung_up_tty_ioctl(struct inode * inode, struct file * file,
1177 unsigned int cmd, unsigned long arg)
1178{
1179 return cmd == TIOCSPGRP ? -ENOTTY : -EIO;
1180}
1181
1182static long hung_up_tty_compat_ioctl(struct file * file,
1183 unsigned int cmd, unsigned long arg)
1da177e4
LT
1184{
1185 return cmd == TIOCSPGRP ? -ENOTTY : -EIO;
1186}
1187
62322d25 1188static const struct file_operations tty_fops = {
1da177e4
LT
1189 .llseek = no_llseek,
1190 .read = tty_read,
1191 .write = tty_write,
1192 .poll = tty_poll,
1193 .ioctl = tty_ioctl,
e10cc1df 1194 .compat_ioctl = tty_compat_ioctl,
1da177e4
LT
1195 .open = tty_open,
1196 .release = tty_release,
1197 .fasync = tty_fasync,
1198};
1199
1200#ifdef CONFIG_UNIX98_PTYS
62322d25 1201static const struct file_operations ptmx_fops = {
1da177e4
LT
1202 .llseek = no_llseek,
1203 .read = tty_read,
1204 .write = tty_write,
1205 .poll = tty_poll,
1206 .ioctl = tty_ioctl,
e10cc1df 1207 .compat_ioctl = tty_compat_ioctl,
1da177e4
LT
1208 .open = ptmx_open,
1209 .release = tty_release,
1210 .fasync = tty_fasync,
1211};
1212#endif
1213
62322d25 1214static const struct file_operations console_fops = {
1da177e4
LT
1215 .llseek = no_llseek,
1216 .read = tty_read,
1217 .write = redirected_tty_write,
1218 .poll = tty_poll,
1219 .ioctl = tty_ioctl,
e10cc1df 1220 .compat_ioctl = tty_compat_ioctl,
1da177e4
LT
1221 .open = tty_open,
1222 .release = tty_release,
1223 .fasync = tty_fasync,
1224};
1225
62322d25 1226static const struct file_operations hung_up_tty_fops = {
1da177e4
LT
1227 .llseek = no_llseek,
1228 .read = hung_up_tty_read,
1229 .write = hung_up_tty_write,
1230 .poll = hung_up_tty_poll,
38ad2ed0
PF
1231 .ioctl = hung_up_tty_ioctl,
1232 .compat_ioctl = hung_up_tty_compat_ioctl,
1da177e4
LT
1233 .release = tty_release,
1234};
1235
1236static DEFINE_SPINLOCK(redirect_lock);
1237static struct file *redirect;
1238
1239/**
1240 * tty_wakeup - request more data
1241 * @tty: terminal
1242 *
1243 * Internal and external helper for wakeups of tty. This function
1244 * informs the line discipline if present that the driver is ready
1245 * to receive more output data.
1246 */
1247
1248void tty_wakeup(struct tty_struct *tty)
1249{
1250 struct tty_ldisc *ld;
1251
1252 if (test_bit(TTY_DO_WRITE_WAKEUP, &tty->flags)) {
1253 ld = tty_ldisc_ref(tty);
1254 if(ld) {
1255 if(ld->write_wakeup)
1256 ld->write_wakeup(tty);
1257 tty_ldisc_deref(ld);
1258 }
1259 }
1260 wake_up_interruptible(&tty->write_wait);
1261}
1262
1263EXPORT_SYMBOL_GPL(tty_wakeup);
1264
1265/**
1266 * tty_ldisc_flush - flush line discipline queue
1267 * @tty: tty
1268 *
1269 * Flush the line discipline queue (if any) for this tty. If there
1270 * is no line discipline active this is a no-op.
1271 */
1272
1273void tty_ldisc_flush(struct tty_struct *tty)
1274{
1275 struct tty_ldisc *ld = tty_ldisc_ref(tty);
1276 if(ld) {
1277 if(ld->flush_buffer)
1278 ld->flush_buffer(tty);
1279 tty_ldisc_deref(ld);
1280 }
c5c34d48 1281 tty_buffer_flush(tty);
1da177e4
LT
1282}
1283
1284EXPORT_SYMBOL_GPL(tty_ldisc_flush);
edc6afc5
AC
1285
1286/**
1287 * tty_reset_termios - reset terminal state
1288 * @tty: tty to reset
1289 *
1290 * Restore a terminal to the driver default state
1291 */
1292
1293static void tty_reset_termios(struct tty_struct *tty)
1294{
1295 mutex_lock(&tty->termios_mutex);
1296 *tty->termios = tty->driver->init_termios;
1297 tty->termios->c_ispeed = tty_termios_input_baud_rate(tty->termios);
1298 tty->termios->c_ospeed = tty_termios_baud_rate(tty->termios);
1299 mutex_unlock(&tty->termios_mutex);
1300}
1da177e4 1301
af9b897e
AC
1302/**
1303 * do_tty_hangup - actual handler for hangup events
65f27f38 1304 * @work: tty device
af9b897e
AC
1305 *
1306 * This can be called by the "eventd" kernel thread. That is process
1307 * synchronous but doesn't hold any locks, so we need to make sure we
1308 * have the appropriate locks for what we're doing.
1309 *
1310 * The hangup event clears any pending redirections onto the hung up
1311 * device. It ensures future writes will error and it does the needed
1312 * line discipline hangup and signal delivery. The tty object itself
1313 * remains intact.
1314 *
1315 * Locking:
1316 * BKL
24ec839c
PZ
1317 * redirect lock for undoing redirection
1318 * file list lock for manipulating list of ttys
1319 * tty_ldisc_lock from called functions
1320 * termios_mutex resetting termios data
1321 * tasklist_lock to walk task list for hangup event
1322 * ->siglock to protect ->signal/->sighand
1da177e4 1323 */
65f27f38 1324static void do_tty_hangup(struct work_struct *work)
1da177e4 1325{
65f27f38
DH
1326 struct tty_struct *tty =
1327 container_of(work, struct tty_struct, hangup_work);
1da177e4
LT
1328 struct file * cons_filp = NULL;
1329 struct file *filp, *f = NULL;
1330 struct task_struct *p;
1331 struct tty_ldisc *ld;
1332 int closecount = 0, n;
1333
1334 if (!tty)
1335 return;
1336
1337 /* inuse_filps is protected by the single kernel lock */
1338 lock_kernel();
1339
1340 spin_lock(&redirect_lock);
1341 if (redirect && redirect->private_data == tty) {
1342 f = redirect;
1343 redirect = NULL;
1344 }
1345 spin_unlock(&redirect_lock);
1346
1347 check_tty_count(tty, "do_tty_hangup");
1348 file_list_lock();
1349 /* This breaks for file handles being sent over AF_UNIX sockets ? */
2f512016 1350 list_for_each_entry(filp, &tty->tty_files, f_u.fu_list) {
1da177e4
LT
1351 if (filp->f_op->write == redirected_tty_write)
1352 cons_filp = filp;
1353 if (filp->f_op->write != tty_write)
1354 continue;
1355 closecount++;
1356 tty_fasync(-1, filp, 0); /* can't block */
1357 filp->f_op = &hung_up_tty_fops;
1358 }
1359 file_list_unlock();
1360
1361 /* FIXME! What are the locking issues here? This may me overdoing things..
1362 * this question is especially important now that we've removed the irqlock. */
1363
1364 ld = tty_ldisc_ref(tty);
1365 if(ld != NULL) /* We may have no line discipline at this point */
1366 {
1367 if (ld->flush_buffer)
1368 ld->flush_buffer(tty);
1369 if (tty->driver->flush_buffer)
1370 tty->driver->flush_buffer(tty);
1371 if ((test_bit(TTY_DO_WRITE_WAKEUP, &tty->flags)) &&
1372 ld->write_wakeup)
1373 ld->write_wakeup(tty);
1374 if (ld->hangup)
1375 ld->hangup(tty);
1376 }
1377
1378 /* FIXME: Once we trust the LDISC code better we can wait here for
1379 ldisc completion and fix the driver call race */
1380
1381 wake_up_interruptible(&tty->write_wait);
1382 wake_up_interruptible(&tty->read_wait);
1383
1384 /*
1385 * Shutdown the current line discipline, and reset it to
1386 * N_TTY.
1387 */
1388 if (tty->driver->flags & TTY_DRIVER_RESET_TERMIOS)
edc6afc5 1389 tty_reset_termios(tty);
1da177e4
LT
1390
1391 /* Defer ldisc switch */
1392 /* tty_deferred_ldisc_switch(N_TTY);
1393
1394 This should get done automatically when the port closes and
1395 tty_release is called */
1396
1397 read_lock(&tasklist_lock);
ab521dc0
EB
1398 if (tty->session) {
1399 do_each_pid_task(tty->session, PIDTYPE_SID, p) {
24ec839c 1400 spin_lock_irq(&p->sighand->siglock);
1da177e4
LT
1401 if (p->signal->tty == tty)
1402 p->signal->tty = NULL;
24ec839c
PZ
1403 if (!p->signal->leader) {
1404 spin_unlock_irq(&p->sighand->siglock);
1da177e4 1405 continue;
24ec839c
PZ
1406 }
1407 __group_send_sig_info(SIGHUP, SEND_SIG_PRIV, p);
1408 __group_send_sig_info(SIGCONT, SEND_SIG_PRIV, p);
ab521dc0
EB
1409 put_pid(p->signal->tty_old_pgrp); /* A noop */
1410 if (tty->pgrp)
1411 p->signal->tty_old_pgrp = get_pid(tty->pgrp);
24ec839c 1412 spin_unlock_irq(&p->sighand->siglock);
ab521dc0 1413 } while_each_pid_task(tty->session, PIDTYPE_SID, p);
1da177e4
LT
1414 }
1415 read_unlock(&tasklist_lock);
1416
1417 tty->flags = 0;
d9c1e9a8
EB
1418 put_pid(tty->session);
1419 put_pid(tty->pgrp);
ab521dc0
EB
1420 tty->session = NULL;
1421 tty->pgrp = NULL;
1da177e4
LT
1422 tty->ctrl_status = 0;
1423 /*
1424 * If one of the devices matches a console pointer, we
1425 * cannot just call hangup() because that will cause
1426 * tty->count and state->count to go out of sync.
1427 * So we just call close() the right number of times.
1428 */
1429 if (cons_filp) {
1430 if (tty->driver->close)
1431 for (n = 0; n < closecount; n++)
1432 tty->driver->close(tty, cons_filp);
1433 } else if (tty->driver->hangup)
1434 (tty->driver->hangup)(tty);
1435
1436 /* We don't want to have driver/ldisc interactions beyond
1437 the ones we did here. The driver layer expects no
1438 calls after ->hangup() from the ldisc side. However we
1439 can't yet guarantee all that */
1440
1441 set_bit(TTY_HUPPED, &tty->flags);
1442 if (ld) {
1443 tty_ldisc_enable(tty);
1444 tty_ldisc_deref(ld);
1445 }
1446 unlock_kernel();
1447 if (f)
1448 fput(f);
1449}
1450
af9b897e
AC
1451/**
1452 * tty_hangup - trigger a hangup event
1453 * @tty: tty to hangup
1454 *
1455 * A carrier loss (virtual or otherwise) has occurred on this like
1456 * schedule a hangup sequence to run after this event.
1457 */
1458
1da177e4
LT
1459void tty_hangup(struct tty_struct * tty)
1460{
1461#ifdef TTY_DEBUG_HANGUP
1462 char buf[64];
1463
1464 printk(KERN_DEBUG "%s hangup...\n", tty_name(tty, buf));
1465#endif
1466 schedule_work(&tty->hangup_work);
1467}
1468
1469EXPORT_SYMBOL(tty_hangup);
1470
af9b897e
AC
1471/**
1472 * tty_vhangup - process vhangup
1473 * @tty: tty to hangup
1474 *
1475 * The user has asked via system call for the terminal to be hung up.
1476 * We do this synchronously so that when the syscall returns the process
1477 * is complete. That guarantee is neccessary for security reasons.
1478 */
1479
1da177e4
LT
1480void tty_vhangup(struct tty_struct * tty)
1481{
1482#ifdef TTY_DEBUG_HANGUP
1483 char buf[64];
1484
1485 printk(KERN_DEBUG "%s vhangup...\n", tty_name(tty, buf));
1486#endif
65f27f38 1487 do_tty_hangup(&tty->hangup_work);
1da177e4
LT
1488}
1489EXPORT_SYMBOL(tty_vhangup);
1490
af9b897e
AC
1491/**
1492 * tty_hung_up_p - was tty hung up
1493 * @filp: file pointer of tty
1494 *
1495 * Return true if the tty has been subject to a vhangup or a carrier
1496 * loss
1497 */
1498
1da177e4
LT
1499int tty_hung_up_p(struct file * filp)
1500{
1501 return (filp->f_op == &hung_up_tty_fops);
1502}
1503
1504EXPORT_SYMBOL(tty_hung_up_p);
1505
ab521dc0 1506static void session_clear_tty(struct pid *session)
24ec839c
PZ
1507{
1508 struct task_struct *p;
ab521dc0 1509 do_each_pid_task(session, PIDTYPE_SID, p) {
24ec839c 1510 proc_clear_tty(p);
ab521dc0 1511 } while_each_pid_task(session, PIDTYPE_SID, p);
24ec839c
PZ
1512}
1513
af9b897e
AC
1514/**
1515 * disassociate_ctty - disconnect controlling tty
1516 * @on_exit: true if exiting so need to "hang up" the session
1da177e4 1517 *
af9b897e
AC
1518 * This function is typically called only by the session leader, when
1519 * it wants to disassociate itself from its controlling tty.
1520 *
1521 * It performs the following functions:
1da177e4
LT
1522 * (1) Sends a SIGHUP and SIGCONT to the foreground process group
1523 * (2) Clears the tty from being controlling the session
1524 * (3) Clears the controlling tty for all processes in the
1525 * session group.
1526 *
af9b897e
AC
1527 * The argument on_exit is set to 1 if called when a process is
1528 * exiting; it is 0 if called by the ioctl TIOCNOTTY.
1529 *
24ec839c 1530 * Locking:
af9b897e 1531 * BKL is taken for hysterical raisins
24ec839c
PZ
1532 * tty_mutex is taken to protect tty
1533 * ->siglock is taken to protect ->signal/->sighand
1534 * tasklist_lock is taken to walk process list for sessions
1535 * ->siglock is taken to protect ->signal/->sighand
1da177e4 1536 */
af9b897e 1537
1da177e4
LT
1538void disassociate_ctty(int on_exit)
1539{
1540 struct tty_struct *tty;
ab521dc0 1541 struct pid *tty_pgrp = NULL;
1da177e4
LT
1542
1543 lock_kernel();
1544
70522e12 1545 mutex_lock(&tty_mutex);
24ec839c 1546 tty = get_current_tty();
1da177e4 1547 if (tty) {
ab521dc0 1548 tty_pgrp = get_pid(tty->pgrp);
70522e12 1549 mutex_unlock(&tty_mutex);
24ec839c 1550 /* XXX: here we race, there is nothing protecting tty */
1da177e4
LT
1551 if (on_exit && tty->driver->type != TTY_DRIVER_TYPE_PTY)
1552 tty_vhangup(tty);
680a9671 1553 } else if (on_exit) {
ab521dc0 1554 struct pid *old_pgrp;
680a9671
EB
1555 spin_lock_irq(&current->sighand->siglock);
1556 old_pgrp = current->signal->tty_old_pgrp;
ab521dc0 1557 current->signal->tty_old_pgrp = NULL;
680a9671 1558 spin_unlock_irq(&current->sighand->siglock);
24ec839c 1559 if (old_pgrp) {
ab521dc0
EB
1560 kill_pgrp(old_pgrp, SIGHUP, on_exit);
1561 kill_pgrp(old_pgrp, SIGCONT, on_exit);
1562 put_pid(old_pgrp);
1da177e4 1563 }
70522e12 1564 mutex_unlock(&tty_mutex);
1da177e4
LT
1565 unlock_kernel();
1566 return;
1567 }
ab521dc0
EB
1568 if (tty_pgrp) {
1569 kill_pgrp(tty_pgrp, SIGHUP, on_exit);
1da177e4 1570 if (!on_exit)
ab521dc0
EB
1571 kill_pgrp(tty_pgrp, SIGCONT, on_exit);
1572 put_pid(tty_pgrp);
1da177e4
LT
1573 }
1574
24ec839c 1575 spin_lock_irq(&current->sighand->siglock);
2a65f1d9 1576 put_pid(current->signal->tty_old_pgrp);
23cac8de 1577 current->signal->tty_old_pgrp = NULL;
24ec839c
PZ
1578 spin_unlock_irq(&current->sighand->siglock);
1579
1580 mutex_lock(&tty_mutex);
1581 /* It is possible that do_tty_hangup has free'd this tty */
1582 tty = get_current_tty();
1583 if (tty) {
ab521dc0
EB
1584 put_pid(tty->session);
1585 put_pid(tty->pgrp);
1586 tty->session = NULL;
1587 tty->pgrp = NULL;
24ec839c
PZ
1588 } else {
1589#ifdef TTY_DEBUG_HANGUP
1590 printk(KERN_DEBUG "error attempted to write to tty [0x%p]"
1591 " = NULL", tty);
1592#endif
1593 }
1594 mutex_unlock(&tty_mutex);
1da177e4
LT
1595
1596 /* Now clear signal->tty under the lock */
1597 read_lock(&tasklist_lock);
ab521dc0 1598 session_clear_tty(task_session(current));
1da177e4 1599 read_unlock(&tasklist_lock);
1da177e4
LT
1600 unlock_kernel();
1601}
1602
98a27ba4
EB
1603/**
1604 *
1605 * no_tty - Ensure the current process does not have a controlling tty
1606 */
1607void no_tty(void)
1608{
1609 struct task_struct *tsk = current;
1610 if (tsk->signal->leader)
1611 disassociate_ctty(0);
1612 proc_clear_tty(tsk);
1613}
1614
af9b897e
AC
1615
1616/**
beb7dd86 1617 * stop_tty - propagate flow control
af9b897e
AC
1618 * @tty: tty to stop
1619 *
1620 * Perform flow control to the driver. For PTY/TTY pairs we
beb7dd86 1621 * must also propagate the TIOCKPKT status. May be called
af9b897e
AC
1622 * on an already stopped device and will not re-call the driver
1623 * method.
1624 *
1625 * This functionality is used by both the line disciplines for
1626 * halting incoming flow and by the driver. It may therefore be
1627 * called from any context, may be under the tty atomic_write_lock
1628 * but not always.
1629 *
1630 * Locking:
1631 * Broken. Relies on BKL which is unsafe here.
1632 */
1633
1da177e4
LT
1634void stop_tty(struct tty_struct *tty)
1635{
1636 if (tty->stopped)
1637 return;
1638 tty->stopped = 1;
1639 if (tty->link && tty->link->packet) {
1640 tty->ctrl_status &= ~TIOCPKT_START;
1641 tty->ctrl_status |= TIOCPKT_STOP;
1642 wake_up_interruptible(&tty->link->read_wait);
1643 }
1644 if (tty->driver->stop)
1645 (tty->driver->stop)(tty);
1646}
1647
1648EXPORT_SYMBOL(stop_tty);
1649
af9b897e 1650/**
beb7dd86 1651 * start_tty - propagate flow control
af9b897e
AC
1652 * @tty: tty to start
1653 *
1654 * Start a tty that has been stopped if at all possible. Perform
beb7dd86 1655 * any neccessary wakeups and propagate the TIOCPKT status. If this
af9b897e
AC
1656 * is the tty was previous stopped and is being started then the
1657 * driver start method is invoked and the line discipline woken.
1658 *
1659 * Locking:
1660 * Broken. Relies on BKL which is unsafe here.
1661 */
1662
1da177e4
LT
1663void start_tty(struct tty_struct *tty)
1664{
1665 if (!tty->stopped || tty->flow_stopped)
1666 return;
1667 tty->stopped = 0;
1668 if (tty->link && tty->link->packet) {
1669 tty->ctrl_status &= ~TIOCPKT_STOP;
1670 tty->ctrl_status |= TIOCPKT_START;
1671 wake_up_interruptible(&tty->link->read_wait);
1672 }
1673 if (tty->driver->start)
1674 (tty->driver->start)(tty);
1675
1676 /* If we have a running line discipline it may need kicking */
1677 tty_wakeup(tty);
1da177e4
LT
1678}
1679
1680EXPORT_SYMBOL(start_tty);
1681
af9b897e
AC
1682/**
1683 * tty_read - read method for tty device files
1684 * @file: pointer to tty file
1685 * @buf: user buffer
1686 * @count: size of user buffer
1687 * @ppos: unused
1688 *
1689 * Perform the read system call function on this terminal device. Checks
1690 * for hung up devices before calling the line discipline method.
1691 *
1692 * Locking:
1693 * Locks the line discipline internally while needed
1694 * For historical reasons the line discipline read method is
1695 * invoked under the BKL. This will go away in time so do not rely on it
1696 * in new code. Multiple read calls may be outstanding in parallel.
1697 */
1698
1da177e4
LT
1699static ssize_t tty_read(struct file * file, char __user * buf, size_t count,
1700 loff_t *ppos)
1701{
1702 int i;
1703 struct tty_struct * tty;
1704 struct inode *inode;
1705 struct tty_ldisc *ld;
1706
1707 tty = (struct tty_struct *)file->private_data;
a7113a96 1708 inode = file->f_path.dentry->d_inode;
1da177e4
LT
1709 if (tty_paranoia_check(tty, inode, "tty_read"))
1710 return -EIO;
1711 if (!tty || (test_bit(TTY_IO_ERROR, &tty->flags)))
1712 return -EIO;
1713
1714 /* We want to wait for the line discipline to sort out in this
1715 situation */
1716 ld = tty_ldisc_ref_wait(tty);
1717 lock_kernel();
1718 if (ld->read)
1719 i = (ld->read)(tty,file,buf,count);
1720 else
1721 i = -EIO;
1722 tty_ldisc_deref(ld);
1723 unlock_kernel();
1724 if (i > 0)
1725 inode->i_atime = current_fs_time(inode->i_sb);
1726 return i;
1727}
1728
9c1729db
AC
1729void tty_write_unlock(struct tty_struct *tty)
1730{
1731 mutex_unlock(&tty->atomic_write_lock);
1732 wake_up_interruptible(&tty->write_wait);
1733}
1734
1735int tty_write_lock(struct tty_struct *tty, int ndelay)
1736{
1737 if (!mutex_trylock(&tty->atomic_write_lock)) {
1738 if (ndelay)
1739 return -EAGAIN;
1740 if (mutex_lock_interruptible(&tty->atomic_write_lock))
1741 return -ERESTARTSYS;
1742 }
1743 return 0;
1744}
1745
1da177e4
LT
1746/*
1747 * Split writes up in sane blocksizes to avoid
1748 * denial-of-service type attacks
1749 */
1750static inline ssize_t do_tty_write(
1751 ssize_t (*write)(struct tty_struct *, struct file *, const unsigned char *, size_t),
1752 struct tty_struct *tty,
1753 struct file *file,
1754 const char __user *buf,
1755 size_t count)
1756{
9c1729db 1757 ssize_t ret, written = 0;
1da177e4
LT
1758 unsigned int chunk;
1759
9c1729db
AC
1760 ret = tty_write_lock(tty, file->f_flags & O_NDELAY);
1761 if (ret < 0)
1762 return ret;
1da177e4
LT
1763
1764 /*
1765 * We chunk up writes into a temporary buffer. This
1766 * simplifies low-level drivers immensely, since they
1767 * don't have locking issues and user mode accesses.
1768 *
1769 * But if TTY_NO_WRITE_SPLIT is set, we should use a
1770 * big chunk-size..
1771 *
1772 * The default chunk-size is 2kB, because the NTTY
1773 * layer has problems with bigger chunks. It will
1774 * claim to be able to handle more characters than
1775 * it actually does.
af9b897e
AC
1776 *
1777 * FIXME: This can probably go away now except that 64K chunks
1778 * are too likely to fail unless switched to vmalloc...
1da177e4
LT
1779 */
1780 chunk = 2048;
1781 if (test_bit(TTY_NO_WRITE_SPLIT, &tty->flags))
1782 chunk = 65536;
1783 if (count < chunk)
1784 chunk = count;
1785
70522e12 1786 /* write_buf/write_cnt is protected by the atomic_write_lock mutex */
1da177e4
LT
1787 if (tty->write_cnt < chunk) {
1788 unsigned char *buf;
1789
1790 if (chunk < 1024)
1791 chunk = 1024;
1792
1793 buf = kmalloc(chunk, GFP_KERNEL);
1794 if (!buf) {
9c1729db
AC
1795 ret = -ENOMEM;
1796 goto out;
1da177e4
LT
1797 }
1798 kfree(tty->write_buf);
1799 tty->write_cnt = chunk;
1800 tty->write_buf = buf;
1801 }
1802
1803 /* Do the write .. */
1804 for (;;) {
1805 size_t size = count;
1806 if (size > chunk)
1807 size = chunk;
1808 ret = -EFAULT;
1809 if (copy_from_user(tty->write_buf, buf, size))
1810 break;
1811 lock_kernel();
1812 ret = write(tty, file, tty->write_buf, size);
1813 unlock_kernel();
1814 if (ret <= 0)
1815 break;
1816 written += ret;
1817 buf += ret;
1818 count -= ret;
1819 if (!count)
1820 break;
1821 ret = -ERESTARTSYS;
1822 if (signal_pending(current))
1823 break;
1824 cond_resched();
1825 }
1826 if (written) {
a7113a96 1827 struct inode *inode = file->f_path.dentry->d_inode;
1da177e4
LT
1828 inode->i_mtime = current_fs_time(inode->i_sb);
1829 ret = written;
1830 }
9c1729db
AC
1831out:
1832 tty_write_unlock(tty);
1da177e4
LT
1833 return ret;
1834}
1835
1836
af9b897e
AC
1837/**
1838 * tty_write - write method for tty device file
1839 * @file: tty file pointer
1840 * @buf: user data to write
1841 * @count: bytes to write
1842 * @ppos: unused
1843 *
1844 * Write data to a tty device via the line discipline.
1845 *
1846 * Locking:
1847 * Locks the line discipline as required
1848 * Writes to the tty driver are serialized by the atomic_write_lock
1849 * and are then processed in chunks to the device. The line discipline
1850 * write method will not be involked in parallel for each device
1851 * The line discipline write method is called under the big
1852 * kernel lock for historical reasons. New code should not rely on this.
1853 */
1854
1da177e4
LT
1855static ssize_t tty_write(struct file * file, const char __user * buf, size_t count,
1856 loff_t *ppos)
1857{
1858 struct tty_struct * tty;
a7113a96 1859 struct inode *inode = file->f_path.dentry->d_inode;
1da177e4
LT
1860 ssize_t ret;
1861 struct tty_ldisc *ld;
1862
1863 tty = (struct tty_struct *)file->private_data;
1864 if (tty_paranoia_check(tty, inode, "tty_write"))
1865 return -EIO;
1866 if (!tty || !tty->driver->write || (test_bit(TTY_IO_ERROR, &tty->flags)))
1867 return -EIO;
1868
1869 ld = tty_ldisc_ref_wait(tty);
1870 if (!ld->write)
1871 ret = -EIO;
1872 else
1873 ret = do_tty_write(ld->write, tty, file, buf, count);
1874 tty_ldisc_deref(ld);
1875 return ret;
1876}
1877
1878ssize_t redirected_tty_write(struct file * file, const char __user * buf, size_t count,
1879 loff_t *ppos)
1880{
1881 struct file *p = NULL;
1882
1883 spin_lock(&redirect_lock);
1884 if (redirect) {
1885 get_file(redirect);
1886 p = redirect;
1887 }
1888 spin_unlock(&redirect_lock);
1889
1890 if (p) {
1891 ssize_t res;
1892 res = vfs_write(p, buf, count, &p->f_pos);
1893 fput(p);
1894 return res;
1895 }
1896
1897 return tty_write(file, buf, count, ppos);
1898}
1899
1900static char ptychar[] = "pqrstuvwxyzabcde";
1901
af9b897e
AC
1902/**
1903 * pty_line_name - generate name for a pty
1904 * @driver: the tty driver in use
1905 * @index: the minor number
1906 * @p: output buffer of at least 6 bytes
1907 *
1908 * Generate a name from a driver reference and write it to the output
1909 * buffer.
1910 *
1911 * Locking: None
1912 */
1913static void pty_line_name(struct tty_driver *driver, int index, char *p)
1da177e4
LT
1914{
1915 int i = index + driver->name_base;
1916 /* ->name is initialized to "ttyp", but "tty" is expected */
1917 sprintf(p, "%s%c%x",
1918 driver->subtype == PTY_TYPE_SLAVE ? "tty" : driver->name,
1919 ptychar[i >> 4 & 0xf], i & 0xf);
1920}
1921
af9b897e
AC
1922/**
1923 * pty_line_name - generate name for a tty
1924 * @driver: the tty driver in use
1925 * @index: the minor number
1926 * @p: output buffer of at least 7 bytes
1927 *
1928 * Generate a name from a driver reference and write it to the output
1929 * buffer.
1930 *
1931 * Locking: None
1932 */
1933static void tty_line_name(struct tty_driver *driver, int index, char *p)
1da177e4
LT
1934{
1935 sprintf(p, "%s%d", driver->name, index + driver->name_base);
1936}
1937
af9b897e
AC
1938/**
1939 * init_dev - initialise a tty device
1940 * @driver: tty driver we are opening a device on
1941 * @idx: device index
1942 * @tty: returned tty structure
1943 *
1944 * Prepare a tty device. This may not be a "new" clean device but
1945 * could also be an active device. The pty drivers require special
1946 * handling because of this.
1947 *
1948 * Locking:
1949 * The function is called under the tty_mutex, which
1950 * protects us from the tty struct or driver itself going away.
1951 *
1952 * On exit the tty device has the line discipline attached and
1953 * a reference count of 1. If a pair was created for pty/tty use
1954 * and the other was a pty master then it too has a reference count of 1.
1955 *
1da177e4 1956 * WSH 06/09/97: Rewritten to remove races and properly clean up after a
70522e12
IM
1957 * failed open. The new code protects the open with a mutex, so it's
1958 * really quite straightforward. The mutex locking can probably be
1da177e4
LT
1959 * relaxed for the (most common) case of reopening a tty.
1960 */
af9b897e 1961
1da177e4
LT
1962static int init_dev(struct tty_driver *driver, int idx,
1963 struct tty_struct **ret_tty)
1964{
1965 struct tty_struct *tty, *o_tty;
edc6afc5
AC
1966 struct ktermios *tp, **tp_loc, *o_tp, **o_tp_loc;
1967 struct ktermios *ltp, **ltp_loc, *o_ltp, **o_ltp_loc;
af9b897e 1968 int retval = 0;
1da177e4
LT
1969
1970 /* check whether we're reopening an existing tty */
1971 if (driver->flags & TTY_DRIVER_DEVPTS_MEM) {
1972 tty = devpts_get_tty(idx);
5a39e8c6
ASRF
1973 /*
1974 * If we don't have a tty here on a slave open, it's because
1975 * the master already started the close process and there's
1976 * no relation between devpts file and tty anymore.
1977 */
1978 if (!tty && driver->subtype == PTY_TYPE_SLAVE) {
1979 retval = -EIO;
1980 goto end_init;
1981 }
1982 /*
1983 * It's safe from now on because init_dev() is called with
1984 * tty_mutex held and release_dev() won't change tty->count
1985 * or tty->flags without having to grab tty_mutex
1986 */
1da177e4
LT
1987 if (tty && driver->subtype == PTY_TYPE_MASTER)
1988 tty = tty->link;
1989 } else {
1990 tty = driver->ttys[idx];
1991 }
1992 if (tty) goto fast_track;
1993
1994 /*
1995 * First time open is complex, especially for PTY devices.
1996 * This code guarantees that either everything succeeds and the
1997 * TTY is ready for operation, or else the table slots are vacated
1998 * and the allocated memory released. (Except that the termios
1999 * and locked termios may be retained.)
2000 */
2001
2002 if (!try_module_get(driver->owner)) {
2003 retval = -ENODEV;
2004 goto end_init;
2005 }
2006
2007 o_tty = NULL;
2008 tp = o_tp = NULL;
2009 ltp = o_ltp = NULL;
2010
2011 tty = alloc_tty_struct();
2012 if(!tty)
2013 goto fail_no_mem;
2014 initialize_tty_struct(tty);
2015 tty->driver = driver;
2016 tty->index = idx;
2017 tty_line_name(driver, idx, tty->name);
2018
2019 if (driver->flags & TTY_DRIVER_DEVPTS_MEM) {
2020 tp_loc = &tty->termios;
2021 ltp_loc = &tty->termios_locked;
2022 } else {
2023 tp_loc = &driver->termios[idx];
2024 ltp_loc = &driver->termios_locked[idx];
2025 }
2026
2027 if (!*tp_loc) {
edc6afc5 2028 tp = (struct ktermios *) kmalloc(sizeof(struct ktermios),
1da177e4
LT
2029 GFP_KERNEL);
2030 if (!tp)
2031 goto free_mem_out;
2032 *tp = driver->init_termios;
2033 }
2034
2035 if (!*ltp_loc) {
edc6afc5 2036 ltp = (struct ktermios *) kmalloc(sizeof(struct ktermios),
1da177e4
LT
2037 GFP_KERNEL);
2038 if (!ltp)
2039 goto free_mem_out;
edc6afc5 2040 memset(ltp, 0, sizeof(struct ktermios));
1da177e4
LT
2041 }
2042
2043 if (driver->type == TTY_DRIVER_TYPE_PTY) {
2044 o_tty = alloc_tty_struct();
2045 if (!o_tty)
2046 goto free_mem_out;
2047 initialize_tty_struct(o_tty);
2048 o_tty->driver = driver->other;
2049 o_tty->index = idx;
2050 tty_line_name(driver->other, idx, o_tty->name);
2051
2052 if (driver->flags & TTY_DRIVER_DEVPTS_MEM) {
2053 o_tp_loc = &o_tty->termios;
2054 o_ltp_loc = &o_tty->termios_locked;
2055 } else {
2056 o_tp_loc = &driver->other->termios[idx];
2057 o_ltp_loc = &driver->other->termios_locked[idx];
2058 }
2059
2060 if (!*o_tp_loc) {
edc6afc5
AC
2061 o_tp = (struct ktermios *)
2062 kmalloc(sizeof(struct ktermios), GFP_KERNEL);
1da177e4
LT
2063 if (!o_tp)
2064 goto free_mem_out;
2065 *o_tp = driver->other->init_termios;
2066 }
2067
2068 if (!*o_ltp_loc) {
edc6afc5
AC
2069 o_ltp = (struct ktermios *)
2070 kmalloc(sizeof(struct ktermios), GFP_KERNEL);
1da177e4
LT
2071 if (!o_ltp)
2072 goto free_mem_out;
edc6afc5 2073 memset(o_ltp, 0, sizeof(struct ktermios));
1da177e4
LT
2074 }
2075
2076 /*
2077 * Everything allocated ... set up the o_tty structure.
2078 */
2079 if (!(driver->other->flags & TTY_DRIVER_DEVPTS_MEM)) {
2080 driver->other->ttys[idx] = o_tty;
2081 }
2082 if (!*o_tp_loc)
2083 *o_tp_loc = o_tp;
2084 if (!*o_ltp_loc)
2085 *o_ltp_loc = o_ltp;
2086 o_tty->termios = *o_tp_loc;
2087 o_tty->termios_locked = *o_ltp_loc;
2088 driver->other->refcount++;
2089 if (driver->subtype == PTY_TYPE_MASTER)
2090 o_tty->count++;
2091
2092 /* Establish the links in both directions */
2093 tty->link = o_tty;
2094 o_tty->link = tty;
2095 }
2096
2097 /*
2098 * All structures have been allocated, so now we install them.
d5698c28 2099 * Failures after this point use release_tty to clean up, so
1da177e4
LT
2100 * there's no need to null out the local pointers.
2101 */
2102 if (!(driver->flags & TTY_DRIVER_DEVPTS_MEM)) {
2103 driver->ttys[idx] = tty;
2104 }
2105
2106 if (!*tp_loc)
2107 *tp_loc = tp;
2108 if (!*ltp_loc)
2109 *ltp_loc = ltp;
2110 tty->termios = *tp_loc;
2111 tty->termios_locked = *ltp_loc;
edc6afc5
AC
2112 /* Compatibility until drivers always set this */
2113 tty->termios->c_ispeed = tty_termios_input_baud_rate(tty->termios);
2114 tty->termios->c_ospeed = tty_termios_baud_rate(tty->termios);
1da177e4
LT
2115 driver->refcount++;
2116 tty->count++;
2117
2118 /*
2119 * Structures all installed ... call the ldisc open routines.
d5698c28
CH
2120 * If we fail here just call release_tty to clean up. No need
2121 * to decrement the use counts, as release_tty doesn't care.
1da177e4
LT
2122 */
2123
2124 if (tty->ldisc.open) {
2125 retval = (tty->ldisc.open)(tty);
2126 if (retval)
2127 goto release_mem_out;
2128 }
2129 if (o_tty && o_tty->ldisc.open) {
2130 retval = (o_tty->ldisc.open)(o_tty);
2131 if (retval) {
2132 if (tty->ldisc.close)
2133 (tty->ldisc.close)(tty);
2134 goto release_mem_out;
2135 }
2136 tty_ldisc_enable(o_tty);
2137 }
2138 tty_ldisc_enable(tty);
2139 goto success;
2140
2141 /*
2142 * This fast open can be used if the tty is already open.
2143 * No memory is allocated, and the only failures are from
2144 * attempting to open a closing tty or attempting multiple
2145 * opens on a pty master.
2146 */
2147fast_track:
2148 if (test_bit(TTY_CLOSING, &tty->flags)) {
2149 retval = -EIO;
2150 goto end_init;
2151 }
2152 if (driver->type == TTY_DRIVER_TYPE_PTY &&
2153 driver->subtype == PTY_TYPE_MASTER) {
2154 /*
2155 * special case for PTY masters: only one open permitted,
2156 * and the slave side open count is incremented as well.
2157 */
2158 if (tty->count) {
2159 retval = -EIO;
2160 goto end_init;
2161 }
2162 tty->link->count++;
2163 }
2164 tty->count++;
2165 tty->driver = driver; /* N.B. why do this every time?? */
2166
2167 /* FIXME */
2168 if(!test_bit(TTY_LDISC, &tty->flags))
2169 printk(KERN_ERR "init_dev but no ldisc\n");
2170success:
2171 *ret_tty = tty;
2172
70522e12 2173 /* All paths come through here to release the mutex */
1da177e4
LT
2174end_init:
2175 return retval;
2176
2177 /* Release locally allocated memory ... nothing placed in slots */
2178free_mem_out:
735d5661 2179 kfree(o_tp);
1da177e4
LT
2180 if (o_tty)
2181 free_tty_struct(o_tty);
735d5661
JJ
2182 kfree(ltp);
2183 kfree(tp);
1da177e4
LT
2184 free_tty_struct(tty);
2185
2186fail_no_mem:
2187 module_put(driver->owner);
2188 retval = -ENOMEM;
2189 goto end_init;
2190
d5698c28 2191 /* call the tty release_tty routine to clean out this slot */
1da177e4 2192release_mem_out:
4050914f
AM
2193 if (printk_ratelimit())
2194 printk(KERN_INFO "init_dev: ldisc open failed, "
2195 "clearing slot %d\n", idx);
d5698c28 2196 release_tty(tty, idx);
1da177e4
LT
2197 goto end_init;
2198}
2199
af9b897e 2200/**
d5698c28 2201 * release_one_tty - release tty structure memory
af9b897e
AC
2202 *
2203 * Releases memory associated with a tty structure, and clears out the
2204 * driver table slots. This function is called when a device is no longer
2205 * in use. It also gets called when setup of a device fails.
2206 *
2207 * Locking:
2208 * tty_mutex - sometimes only
2209 * takes the file list lock internally when working on the list
2210 * of ttys that the driver keeps.
2211 * FIXME: should we require tty_mutex is held here ??
1da177e4 2212 */
d5698c28 2213static void release_one_tty(struct tty_struct *tty, int idx)
1da177e4 2214{
1da177e4 2215 int devpts = tty->driver->flags & TTY_DRIVER_DEVPTS_MEM;
d5698c28 2216 struct ktermios *tp;
1da177e4
LT
2217
2218 if (!devpts)
2219 tty->driver->ttys[idx] = NULL;
d5698c28 2220
1da177e4
LT
2221 if (tty->driver->flags & TTY_DRIVER_RESET_TERMIOS) {
2222 tp = tty->termios;
2223 if (!devpts)
2224 tty->driver->termios[idx] = NULL;
2225 kfree(tp);
2226
2227 tp = tty->termios_locked;
2228 if (!devpts)
2229 tty->driver->termios_locked[idx] = NULL;
2230 kfree(tp);
2231 }
2232
d5698c28 2233
1da177e4
LT
2234 tty->magic = 0;
2235 tty->driver->refcount--;
d5698c28 2236
1da177e4
LT
2237 file_list_lock();
2238 list_del_init(&tty->tty_files);
2239 file_list_unlock();
d5698c28 2240
1da177e4
LT
2241 free_tty_struct(tty);
2242}
2243
d5698c28
CH
2244/**
2245 * release_tty - release tty structure memory
2246 *
2247 * Release both @tty and a possible linked partner (think pty pair),
2248 * and decrement the refcount of the backing module.
2249 *
2250 * Locking:
2251 * tty_mutex - sometimes only
2252 * takes the file list lock internally when working on the list
2253 * of ttys that the driver keeps.
2254 * FIXME: should we require tty_mutex is held here ??
2255 */
2256static void release_tty(struct tty_struct *tty, int idx)
2257{
2258 struct tty_driver *driver = tty->driver;
2259
2260 if (tty->link)
2261 release_one_tty(tty->link, idx);
2262 release_one_tty(tty, idx);
2263 module_put(driver->owner);
2264}
2265
1da177e4
LT
2266/*
2267 * Even releasing the tty structures is a tricky business.. We have
2268 * to be very careful that the structures are all released at the
2269 * same time, as interrupts might otherwise get the wrong pointers.
2270 *
2271 * WSH 09/09/97: rewritten to avoid some nasty race conditions that could
2272 * lead to double frees or releasing memory still in use.
2273 */
2274static void release_dev(struct file * filp)
2275{
2276 struct tty_struct *tty, *o_tty;
2277 int pty_master, tty_closing, o_tty_closing, do_sleep;
14a6283e 2278 int devpts;
1da177e4
LT
2279 int idx;
2280 char buf[64];
2281 unsigned long flags;
2282
2283 tty = (struct tty_struct *)filp->private_data;
a7113a96 2284 if (tty_paranoia_check(tty, filp->f_path.dentry->d_inode, "release_dev"))
1da177e4
LT
2285 return;
2286
2287 check_tty_count(tty, "release_dev");
2288
2289 tty_fasync(-1, filp, 0);
2290
2291 idx = tty->index;
2292 pty_master = (tty->driver->type == TTY_DRIVER_TYPE_PTY &&
2293 tty->driver->subtype == PTY_TYPE_MASTER);
2294 devpts = (tty->driver->flags & TTY_DRIVER_DEVPTS_MEM) != 0;
1da177e4
LT
2295 o_tty = tty->link;
2296
2297#ifdef TTY_PARANOIA_CHECK
2298 if (idx < 0 || idx >= tty->driver->num) {
2299 printk(KERN_DEBUG "release_dev: bad idx when trying to "
2300 "free (%s)\n", tty->name);
2301 return;
2302 }
2303 if (!(tty->driver->flags & TTY_DRIVER_DEVPTS_MEM)) {
2304 if (tty != tty->driver->ttys[idx]) {
2305 printk(KERN_DEBUG "release_dev: driver.table[%d] not tty "
2306 "for (%s)\n", idx, tty->name);
2307 return;
2308 }
2309 if (tty->termios != tty->driver->termios[idx]) {
2310 printk(KERN_DEBUG "release_dev: driver.termios[%d] not termios "
2311 "for (%s)\n",
2312 idx, tty->name);
2313 return;
2314 }
2315 if (tty->termios_locked != tty->driver->termios_locked[idx]) {
2316 printk(KERN_DEBUG "release_dev: driver.termios_locked[%d] not "
2317 "termios_locked for (%s)\n",
2318 idx, tty->name);
2319 return;
2320 }
2321 }
2322#endif
2323
2324#ifdef TTY_DEBUG_HANGUP
2325 printk(KERN_DEBUG "release_dev of %s (tty count=%d)...",
2326 tty_name(tty, buf), tty->count);
2327#endif
2328
2329#ifdef TTY_PARANOIA_CHECK
2330 if (tty->driver->other &&
2331 !(tty->driver->flags & TTY_DRIVER_DEVPTS_MEM)) {
2332 if (o_tty != tty->driver->other->ttys[idx]) {
2333 printk(KERN_DEBUG "release_dev: other->table[%d] "
2334 "not o_tty for (%s)\n",
2335 idx, tty->name);
2336 return;
2337 }
2338 if (o_tty->termios != tty->driver->other->termios[idx]) {
2339 printk(KERN_DEBUG "release_dev: other->termios[%d] "
2340 "not o_termios for (%s)\n",
2341 idx, tty->name);
2342 return;
2343 }
2344 if (o_tty->termios_locked !=
2345 tty->driver->other->termios_locked[idx]) {
2346 printk(KERN_DEBUG "release_dev: other->termios_locked["
2347 "%d] not o_termios_locked for (%s)\n",
2348 idx, tty->name);
2349 return;
2350 }
2351 if (o_tty->link != tty) {
2352 printk(KERN_DEBUG "release_dev: bad pty pointers\n");
2353 return;
2354 }
2355 }
2356#endif
2357 if (tty->driver->close)
2358 tty->driver->close(tty, filp);
2359
2360 /*
2361 * Sanity check: if tty->count is going to zero, there shouldn't be
2362 * any waiters on tty->read_wait or tty->write_wait. We test the
2363 * wait queues and kick everyone out _before_ actually starting to
2364 * close. This ensures that we won't block while releasing the tty
2365 * structure.
2366 *
2367 * The test for the o_tty closing is necessary, since the master and
2368 * slave sides may close in any order. If the slave side closes out
2369 * first, its count will be one, since the master side holds an open.
2370 * Thus this test wouldn't be triggered at the time the slave closes,
2371 * so we do it now.
2372 *
2373 * Note that it's possible for the tty to be opened again while we're
2374 * flushing out waiters. By recalculating the closing flags before
2375 * each iteration we avoid any problems.
2376 */
2377 while (1) {
2378 /* Guard against races with tty->count changes elsewhere and
2379 opens on /dev/tty */
2380
70522e12 2381 mutex_lock(&tty_mutex);
1da177e4
LT
2382 tty_closing = tty->count <= 1;
2383 o_tty_closing = o_tty &&
2384 (o_tty->count <= (pty_master ? 1 : 0));
1da177e4
LT
2385 do_sleep = 0;
2386
2387 if (tty_closing) {
2388 if (waitqueue_active(&tty->read_wait)) {
2389 wake_up(&tty->read_wait);
2390 do_sleep++;
2391 }
2392 if (waitqueue_active(&tty->write_wait)) {
2393 wake_up(&tty->write_wait);
2394 do_sleep++;
2395 }
2396 }
2397 if (o_tty_closing) {
2398 if (waitqueue_active(&o_tty->read_wait)) {
2399 wake_up(&o_tty->read_wait);
2400 do_sleep++;
2401 }
2402 if (waitqueue_active(&o_tty->write_wait)) {
2403 wake_up(&o_tty->write_wait);
2404 do_sleep++;
2405 }
2406 }
2407 if (!do_sleep)
2408 break;
2409
2410 printk(KERN_WARNING "release_dev: %s: read/write wait queue "
2411 "active!\n", tty_name(tty, buf));
70522e12 2412 mutex_unlock(&tty_mutex);
1da177e4
LT
2413 schedule();
2414 }
2415
2416 /*
2417 * The closing flags are now consistent with the open counts on
2418 * both sides, and we've completed the last operation that could
2419 * block, so it's safe to proceed with closing.
2420 */
1da177e4
LT
2421 if (pty_master) {
2422 if (--o_tty->count < 0) {
2423 printk(KERN_WARNING "release_dev: bad pty slave count "
2424 "(%d) for %s\n",
2425 o_tty->count, tty_name(o_tty, buf));
2426 o_tty->count = 0;
2427 }
2428 }
2429 if (--tty->count < 0) {
2430 printk(KERN_WARNING "release_dev: bad tty->count (%d) for %s\n",
2431 tty->count, tty_name(tty, buf));
2432 tty->count = 0;
2433 }
1da177e4
LT
2434
2435 /*
2436 * We've decremented tty->count, so we need to remove this file
2437 * descriptor off the tty->tty_files list; this serves two
2438 * purposes:
2439 * - check_tty_count sees the correct number of file descriptors
2440 * associated with this tty.
2441 * - do_tty_hangup no longer sees this file descriptor as
2442 * something that needs to be handled for hangups.
2443 */
2444 file_kill(filp);
2445 filp->private_data = NULL;
2446
2447 /*
2448 * Perform some housekeeping before deciding whether to return.
2449 *
2450 * Set the TTY_CLOSING flag if this was the last open. In the
2451 * case of a pty we may have to wait around for the other side
2452 * to close, and TTY_CLOSING makes sure we can't be reopened.
2453 */
2454 if(tty_closing)
2455 set_bit(TTY_CLOSING, &tty->flags);
2456 if(o_tty_closing)
2457 set_bit(TTY_CLOSING, &o_tty->flags);
2458
2459 /*
2460 * If _either_ side is closing, make sure there aren't any
2461 * processes that still think tty or o_tty is their controlling
2462 * tty.
2463 */
2464 if (tty_closing || o_tty_closing) {
1da177e4 2465 read_lock(&tasklist_lock);
24ec839c 2466 session_clear_tty(tty->session);
1da177e4 2467 if (o_tty)
24ec839c 2468 session_clear_tty(o_tty->session);
1da177e4
LT
2469 read_unlock(&tasklist_lock);
2470 }
2471
70522e12 2472 mutex_unlock(&tty_mutex);
da965822 2473
1da177e4
LT
2474 /* check whether both sides are closing ... */
2475 if (!tty_closing || (o_tty && !o_tty_closing))
2476 return;
2477
2478#ifdef TTY_DEBUG_HANGUP
2479 printk(KERN_DEBUG "freeing tty structure...");
2480#endif
2481 /*
2482 * Prevent flush_to_ldisc() from rescheduling the work for later. Then
2483 * kill any delayed work. As this is the final close it does not
2484 * race with the set_ldisc code path.
2485 */
2486 clear_bit(TTY_LDISC, &tty->flags);
33f0f88f 2487 cancel_delayed_work(&tty->buf.work);
1da177e4
LT
2488
2489 /*
33f0f88f 2490 * Wait for ->hangup_work and ->buf.work handlers to terminate
1da177e4
LT
2491 */
2492
2493 flush_scheduled_work();
2494
2495 /*
2496 * Wait for any short term users (we know they are just driver
2497 * side waiters as the file is closing so user count on the file
2498 * side is zero.
2499 */
2500 spin_lock_irqsave(&tty_ldisc_lock, flags);
2501 while(tty->ldisc.refcount)
2502 {
2503 spin_unlock_irqrestore(&tty_ldisc_lock, flags);
2504 wait_event(tty_ldisc_wait, tty->ldisc.refcount == 0);
2505 spin_lock_irqsave(&tty_ldisc_lock, flags);
2506 }
2507 spin_unlock_irqrestore(&tty_ldisc_lock, flags);
2508 /*
2509 * Shutdown the current line discipline, and reset it to N_TTY.
2510 * N.B. why reset ldisc when we're releasing the memory??
2511 *
2512 * FIXME: this MUST get fixed for the new reflocking
2513 */
2514 if (tty->ldisc.close)
2515 (tty->ldisc.close)(tty);
2516 tty_ldisc_put(tty->ldisc.num);
2517
2518 /*
2519 * Switch the line discipline back
2520 */
2521 tty_ldisc_assign(tty, tty_ldisc_get(N_TTY));
2522 tty_set_termios_ldisc(tty,N_TTY);
2523 if (o_tty) {
2524 /* FIXME: could o_tty be in setldisc here ? */
2525 clear_bit(TTY_LDISC, &o_tty->flags);
2526 if (o_tty->ldisc.close)
2527 (o_tty->ldisc.close)(o_tty);
2528 tty_ldisc_put(o_tty->ldisc.num);
2529 tty_ldisc_assign(o_tty, tty_ldisc_get(N_TTY));
2530 tty_set_termios_ldisc(o_tty,N_TTY);
2531 }
2532 /*
d5698c28 2533 * The release_tty function takes care of the details of clearing
1da177e4
LT
2534 * the slots and preserving the termios structure.
2535 */
d5698c28 2536 release_tty(tty, idx);
1da177e4
LT
2537
2538#ifdef CONFIG_UNIX98_PTYS
2539 /* Make this pty number available for reallocation */
2540 if (devpts) {
2541 down(&allocated_ptys_lock);
2542 idr_remove(&allocated_ptys, idx);
2543 up(&allocated_ptys_lock);
2544 }
2545#endif
2546
2547}
2548
af9b897e
AC
2549/**
2550 * tty_open - open a tty device
2551 * @inode: inode of device file
2552 * @filp: file pointer to tty
1da177e4 2553 *
af9b897e
AC
2554 * tty_open and tty_release keep up the tty count that contains the
2555 * number of opens done on a tty. We cannot use the inode-count, as
2556 * different inodes might point to the same tty.
1da177e4 2557 *
af9b897e
AC
2558 * Open-counting is needed for pty masters, as well as for keeping
2559 * track of serial lines: DTR is dropped when the last close happens.
2560 * (This is not done solely through tty->count, now. - Ted 1/27/92)
2561 *
2562 * The termios state of a pty is reset on first open so that
2563 * settings don't persist across reuse.
2564 *
24ec839c
PZ
2565 * Locking: tty_mutex protects tty, get_tty_driver and init_dev work.
2566 * tty->count should protect the rest.
2567 * ->siglock protects ->signal/->sighand
1da177e4 2568 */
af9b897e 2569
1da177e4
LT
2570static int tty_open(struct inode * inode, struct file * filp)
2571{
2572 struct tty_struct *tty;
2573 int noctty, retval;
2574 struct tty_driver *driver;
2575 int index;
2576 dev_t device = inode->i_rdev;
2577 unsigned short saved_flags = filp->f_flags;
2578
2579 nonseekable_open(inode, filp);
2580
2581retry_open:
2582 noctty = filp->f_flags & O_NOCTTY;
2583 index = -1;
2584 retval = 0;
2585
70522e12 2586 mutex_lock(&tty_mutex);
1da177e4
LT
2587
2588 if (device == MKDEV(TTYAUX_MAJOR,0)) {
24ec839c
PZ
2589 tty = get_current_tty();
2590 if (!tty) {
70522e12 2591 mutex_unlock(&tty_mutex);
1da177e4
LT
2592 return -ENXIO;
2593 }
24ec839c
PZ
2594 driver = tty->driver;
2595 index = tty->index;
1da177e4
LT
2596 filp->f_flags |= O_NONBLOCK; /* Don't let /dev/tty block */
2597 /* noctty = 1; */
2598 goto got_driver;
2599 }
2600#ifdef CONFIG_VT
2601 if (device == MKDEV(TTY_MAJOR,0)) {
2602 extern struct tty_driver *console_driver;
2603 driver = console_driver;
2604 index = fg_console;
2605 noctty = 1;
2606 goto got_driver;
2607 }
2608#endif
2609 if (device == MKDEV(TTYAUX_MAJOR,1)) {
2610 driver = console_device(&index);
2611 if (driver) {
2612 /* Don't let /dev/console block */
2613 filp->f_flags |= O_NONBLOCK;
2614 noctty = 1;
2615 goto got_driver;
2616 }
70522e12 2617 mutex_unlock(&tty_mutex);
1da177e4
LT
2618 return -ENODEV;
2619 }
2620
2621 driver = get_tty_driver(device, &index);
2622 if (!driver) {
70522e12 2623 mutex_unlock(&tty_mutex);
1da177e4
LT
2624 return -ENODEV;
2625 }
2626got_driver:
2627 retval = init_dev(driver, index, &tty);
70522e12 2628 mutex_unlock(&tty_mutex);
1da177e4
LT
2629 if (retval)
2630 return retval;
2631
2632 filp->private_data = tty;
2633 file_move(filp, &tty->tty_files);
2634 check_tty_count(tty, "tty_open");
2635 if (tty->driver->type == TTY_DRIVER_TYPE_PTY &&
2636 tty->driver->subtype == PTY_TYPE_MASTER)
2637 noctty = 1;
2638#ifdef TTY_DEBUG_HANGUP
2639 printk(KERN_DEBUG "opening %s...", tty->name);
2640#endif
2641 if (!retval) {
2642 if (tty->driver->open)
2643 retval = tty->driver->open(tty, filp);
2644 else
2645 retval = -ENODEV;
2646 }
2647 filp->f_flags = saved_flags;
2648
2649 if (!retval && test_bit(TTY_EXCLUSIVE, &tty->flags) && !capable(CAP_SYS_ADMIN))
2650 retval = -EBUSY;
2651
2652 if (retval) {
2653#ifdef TTY_DEBUG_HANGUP
2654 printk(KERN_DEBUG "error %d in opening %s...", retval,
2655 tty->name);
2656#endif
2657 release_dev(filp);
2658 if (retval != -ERESTARTSYS)
2659 return retval;
2660 if (signal_pending(current))
2661 return retval;
2662 schedule();
2663 /*
2664 * Need to reset f_op in case a hangup happened.
2665 */
2666 if (filp->f_op == &hung_up_tty_fops)
2667 filp->f_op = &tty_fops;
2668 goto retry_open;
2669 }
24ec839c
PZ
2670
2671 mutex_lock(&tty_mutex);
2672 spin_lock_irq(&current->sighand->siglock);
1da177e4
LT
2673 if (!noctty &&
2674 current->signal->leader &&
2675 !current->signal->tty &&
ab521dc0 2676 tty->session == NULL)
2a65f1d9 2677 __proc_set_tty(current, tty);
24ec839c
PZ
2678 spin_unlock_irq(&current->sighand->siglock);
2679 mutex_unlock(&tty_mutex);
1da177e4
LT
2680 return 0;
2681}
2682
2683#ifdef CONFIG_UNIX98_PTYS
af9b897e
AC
2684/**
2685 * ptmx_open - open a unix 98 pty master
2686 * @inode: inode of device file
2687 * @filp: file pointer to tty
2688 *
2689 * Allocate a unix98 pty master device from the ptmx driver.
2690 *
2691 * Locking: tty_mutex protects theinit_dev work. tty->count should
2692 protect the rest.
2693 * allocated_ptys_lock handles the list of free pty numbers
2694 */
2695
1da177e4
LT
2696static int ptmx_open(struct inode * inode, struct file * filp)
2697{
2698 struct tty_struct *tty;
2699 int retval;
2700 int index;
2701 int idr_ret;
2702
2703 nonseekable_open(inode, filp);
2704
2705 /* find a device that is not in use. */
2706 down(&allocated_ptys_lock);
2707 if (!idr_pre_get(&allocated_ptys, GFP_KERNEL)) {
2708 up(&allocated_ptys_lock);
2709 return -ENOMEM;
2710 }
2711 idr_ret = idr_get_new(&allocated_ptys, NULL, &index);
2712 if (idr_ret < 0) {
2713 up(&allocated_ptys_lock);
2714 if (idr_ret == -EAGAIN)
2715 return -ENOMEM;
2716 return -EIO;
2717 }
2718 if (index >= pty_limit) {
2719 idr_remove(&allocated_ptys, index);
2720 up(&allocated_ptys_lock);
2721 return -EIO;
2722 }
2723 up(&allocated_ptys_lock);
2724
70522e12 2725 mutex_lock(&tty_mutex);
1da177e4 2726 retval = init_dev(ptm_driver, index, &tty);
70522e12 2727 mutex_unlock(&tty_mutex);
1da177e4
LT
2728
2729 if (retval)
2730 goto out;
2731
2732 set_bit(TTY_PTY_LOCK, &tty->flags); /* LOCK THE SLAVE */
2733 filp->private_data = tty;
2734 file_move(filp, &tty->tty_files);
2735
2736 retval = -ENOMEM;
2737 if (devpts_pty_new(tty->link))
2738 goto out1;
2739
2740 check_tty_count(tty, "tty_open");
2741 retval = ptm_driver->open(tty, filp);
2742 if (!retval)
2743 return 0;
2744out1:
2745 release_dev(filp);
9453a5ad 2746 return retval;
1da177e4
LT
2747out:
2748 down(&allocated_ptys_lock);
2749 idr_remove(&allocated_ptys, index);
2750 up(&allocated_ptys_lock);
2751 return retval;
2752}
2753#endif
2754
af9b897e
AC
2755/**
2756 * tty_release - vfs callback for close
2757 * @inode: inode of tty
2758 * @filp: file pointer for handle to tty
2759 *
2760 * Called the last time each file handle is closed that references
2761 * this tty. There may however be several such references.
2762 *
2763 * Locking:
2764 * Takes bkl. See release_dev
2765 */
2766
1da177e4
LT
2767static int tty_release(struct inode * inode, struct file * filp)
2768{
2769 lock_kernel();
2770 release_dev(filp);
2771 unlock_kernel();
2772 return 0;
2773}
2774
af9b897e
AC
2775/**
2776 * tty_poll - check tty status
2777 * @filp: file being polled
2778 * @wait: poll wait structures to update
2779 *
2780 * Call the line discipline polling method to obtain the poll
2781 * status of the device.
2782 *
2783 * Locking: locks called line discipline but ldisc poll method
2784 * may be re-entered freely by other callers.
2785 */
2786
1da177e4
LT
2787static unsigned int tty_poll(struct file * filp, poll_table * wait)
2788{
2789 struct tty_struct * tty;
2790 struct tty_ldisc *ld;
2791 int ret = 0;
2792
2793 tty = (struct tty_struct *)filp->private_data;
a7113a96 2794 if (tty_paranoia_check(tty, filp->f_path.dentry->d_inode, "tty_poll"))
1da177e4
LT
2795 return 0;
2796
2797 ld = tty_ldisc_ref_wait(tty);
2798 if (ld->poll)
2799 ret = (ld->poll)(tty, filp, wait);
2800 tty_ldisc_deref(ld);
2801 return ret;
2802}
2803
2804static int tty_fasync(int fd, struct file * filp, int on)
2805{
2806 struct tty_struct * tty;
2807 int retval;
2808
2809 tty = (struct tty_struct *)filp->private_data;
a7113a96 2810 if (tty_paranoia_check(tty, filp->f_path.dentry->d_inode, "tty_fasync"))
1da177e4
LT
2811 return 0;
2812
2813 retval = fasync_helper(fd, filp, on, &tty->fasync);
2814 if (retval <= 0)
2815 return retval;
2816
2817 if (on) {
ab521dc0
EB
2818 enum pid_type type;
2819 struct pid *pid;
1da177e4
LT
2820 if (!waitqueue_active(&tty->read_wait))
2821 tty->minimum_to_wake = 1;
ab521dc0
EB
2822 if (tty->pgrp) {
2823 pid = tty->pgrp;
2824 type = PIDTYPE_PGID;
2825 } else {
2826 pid = task_pid(current);
2827 type = PIDTYPE_PID;
2828 }
2829 retval = __f_setown(filp, pid, type, 0);
1da177e4
LT
2830 if (retval)
2831 return retval;
2832 } else {
2833 if (!tty->fasync && !waitqueue_active(&tty->read_wait))
2834 tty->minimum_to_wake = N_TTY_BUF_SIZE;
2835 }
2836 return 0;
2837}
2838
af9b897e
AC
2839/**
2840 * tiocsti - fake input character
2841 * @tty: tty to fake input into
2842 * @p: pointer to character
2843 *
2844 * Fake input to a tty device. Does the neccessary locking and
2845 * input management.
2846 *
2847 * FIXME: does not honour flow control ??
2848 *
2849 * Locking:
2850 * Called functions take tty_ldisc_lock
2851 * current->signal->tty check is safe without locks
28298232
AC
2852 *
2853 * FIXME: may race normal receive processing
af9b897e
AC
2854 */
2855
1da177e4
LT
2856static int tiocsti(struct tty_struct *tty, char __user *p)
2857{
2858 char ch, mbz = 0;
2859 struct tty_ldisc *ld;
2860
2861 if ((current->signal->tty != tty) && !capable(CAP_SYS_ADMIN))
2862 return -EPERM;
2863 if (get_user(ch, p))
2864 return -EFAULT;
2865 ld = tty_ldisc_ref_wait(tty);
2866 ld->receive_buf(tty, &ch, &mbz, 1);
2867 tty_ldisc_deref(ld);
2868 return 0;
2869}
2870
af9b897e
AC
2871/**
2872 * tiocgwinsz - implement window query ioctl
2873 * @tty; tty
2874 * @arg: user buffer for result
2875 *
808a0d38 2876 * Copies the kernel idea of the window size into the user buffer.
af9b897e 2877 *
24ec839c 2878 * Locking: tty->termios_mutex is taken to ensure the winsize data
808a0d38 2879 * is consistent.
af9b897e
AC
2880 */
2881
1da177e4
LT
2882static int tiocgwinsz(struct tty_struct *tty, struct winsize __user * arg)
2883{
808a0d38
AC
2884 int err;
2885
5785c95b 2886 mutex_lock(&tty->termios_mutex);
808a0d38 2887 err = copy_to_user(arg, &tty->winsize, sizeof(*arg));
5785c95b 2888 mutex_unlock(&tty->termios_mutex);
808a0d38
AC
2889
2890 return err ? -EFAULT: 0;
1da177e4
LT
2891}
2892
af9b897e
AC
2893/**
2894 * tiocswinsz - implement window size set ioctl
2895 * @tty; tty
2896 * @arg: user buffer for result
2897 *
2898 * Copies the user idea of the window size to the kernel. Traditionally
2899 * this is just advisory information but for the Linux console it
2900 * actually has driver level meaning and triggers a VC resize.
2901 *
2902 * Locking:
ca9bda00
AC
2903 * Called function use the console_sem is used to ensure we do
2904 * not try and resize the console twice at once.
24ec839c
PZ
2905 * The tty->termios_mutex is used to ensure we don't double
2906 * resize and get confused. Lock order - tty->termios_mutex before
ca9bda00 2907 * console sem
af9b897e
AC
2908 */
2909
1da177e4
LT
2910static int tiocswinsz(struct tty_struct *tty, struct tty_struct *real_tty,
2911 struct winsize __user * arg)
2912{
2913 struct winsize tmp_ws;
2914
2915 if (copy_from_user(&tmp_ws, arg, sizeof(*arg)))
2916 return -EFAULT;
ca9bda00 2917
5785c95b 2918 mutex_lock(&tty->termios_mutex);
1da177e4 2919 if (!memcmp(&tmp_ws, &tty->winsize, sizeof(*arg)))
ca9bda00
AC
2920 goto done;
2921
1da177e4
LT
2922#ifdef CONFIG_VT
2923 if (tty->driver->type == TTY_DRIVER_TYPE_CONSOLE) {
5785c95b
AV
2924 if (vc_lock_resize(tty->driver_data, tmp_ws.ws_col,
2925 tmp_ws.ws_row)) {
2926 mutex_unlock(&tty->termios_mutex);
ca9bda00
AC
2927 return -ENXIO;
2928 }
1da177e4
LT
2929 }
2930#endif
ab521dc0
EB
2931 if (tty->pgrp)
2932 kill_pgrp(tty->pgrp, SIGWINCH, 1);
2933 if ((real_tty->pgrp != tty->pgrp) && real_tty->pgrp)
2934 kill_pgrp(real_tty->pgrp, SIGWINCH, 1);
1da177e4
LT
2935 tty->winsize = tmp_ws;
2936 real_tty->winsize = tmp_ws;
ca9bda00 2937done:
5785c95b 2938 mutex_unlock(&tty->termios_mutex);
1da177e4
LT
2939 return 0;
2940}
2941
af9b897e
AC
2942/**
2943 * tioccons - allow admin to move logical console
2944 * @file: the file to become console
2945 *
2946 * Allow the adminstrator to move the redirected console device
2947 *
2948 * Locking: uses redirect_lock to guard the redirect information
2949 */
2950
1da177e4
LT
2951static int tioccons(struct file *file)
2952{
2953 if (!capable(CAP_SYS_ADMIN))
2954 return -EPERM;
2955 if (file->f_op->write == redirected_tty_write) {
2956 struct file *f;
2957 spin_lock(&redirect_lock);
2958 f = redirect;
2959 redirect = NULL;
2960 spin_unlock(&redirect_lock);
2961 if (f)
2962 fput(f);
2963 return 0;
2964 }
2965 spin_lock(&redirect_lock);
2966 if (redirect) {
2967 spin_unlock(&redirect_lock);
2968 return -EBUSY;
2969 }
2970 get_file(file);
2971 redirect = file;
2972 spin_unlock(&redirect_lock);
2973 return 0;
2974}
2975
af9b897e
AC
2976/**
2977 * fionbio - non blocking ioctl
2978 * @file: file to set blocking value
2979 * @p: user parameter
2980 *
2981 * Historical tty interfaces had a blocking control ioctl before
2982 * the generic functionality existed. This piece of history is preserved
2983 * in the expected tty API of posix OS's.
2984 *
2985 * Locking: none, the open fle handle ensures it won't go away.
2986 */
1da177e4
LT
2987
2988static int fionbio(struct file *file, int __user *p)
2989{
2990 int nonblock;
2991
2992 if (get_user(nonblock, p))
2993 return -EFAULT;
2994
2995 if (nonblock)
2996 file->f_flags |= O_NONBLOCK;
2997 else
2998 file->f_flags &= ~O_NONBLOCK;
2999 return 0;
3000}
3001
af9b897e
AC
3002/**
3003 * tiocsctty - set controlling tty
3004 * @tty: tty structure
3005 * @arg: user argument
3006 *
3007 * This ioctl is used to manage job control. It permits a session
3008 * leader to set this tty as the controlling tty for the session.
3009 *
3010 * Locking:
28298232 3011 * Takes tty_mutex() to protect tty instance
24ec839c
PZ
3012 * Takes tasklist_lock internally to walk sessions
3013 * Takes ->siglock() when updating signal->tty
af9b897e
AC
3014 */
3015
1da177e4
LT
3016static int tiocsctty(struct tty_struct *tty, int arg)
3017{
24ec839c 3018 int ret = 0;
ab521dc0 3019 if (current->signal->leader && (task_session(current) == tty->session))
24ec839c
PZ
3020 return ret;
3021
3022 mutex_lock(&tty_mutex);
1da177e4
LT
3023 /*
3024 * The process must be a session leader and
3025 * not have a controlling tty already.
3026 */
24ec839c
PZ
3027 if (!current->signal->leader || current->signal->tty) {
3028 ret = -EPERM;
3029 goto unlock;
3030 }
3031
ab521dc0 3032 if (tty->session) {
1da177e4
LT
3033 /*
3034 * This tty is already the controlling
3035 * tty for another session group!
3036 */
3037 if ((arg == 1) && capable(CAP_SYS_ADMIN)) {
3038 /*
3039 * Steal it away
3040 */
1da177e4 3041 read_lock(&tasklist_lock);
24ec839c 3042 session_clear_tty(tty->session);
1da177e4 3043 read_unlock(&tasklist_lock);
24ec839c
PZ
3044 } else {
3045 ret = -EPERM;
3046 goto unlock;
3047 }
1da177e4 3048 }
24ec839c
PZ
3049 proc_set_tty(current, tty);
3050unlock:
28298232 3051 mutex_unlock(&tty_mutex);
24ec839c 3052 return ret;
1da177e4
LT
3053}
3054
af9b897e
AC
3055/**
3056 * tiocgpgrp - get process group
3057 * @tty: tty passed by user
3058 * @real_tty: tty side of the tty pased by the user if a pty else the tty
3059 * @p: returned pid
3060 *
3061 * Obtain the process group of the tty. If there is no process group
3062 * return an error.
3063 *
24ec839c 3064 * Locking: none. Reference to current->signal->tty is safe.
af9b897e
AC
3065 */
3066
1da177e4
LT
3067static int tiocgpgrp(struct tty_struct *tty, struct tty_struct *real_tty, pid_t __user *p)
3068{
3069 /*
3070 * (tty == real_tty) is a cheap way of
3071 * testing if the tty is NOT a master pty.
3072 */
3073 if (tty == real_tty && current->signal->tty != real_tty)
3074 return -ENOTTY;
ab521dc0 3075 return put_user(pid_nr(real_tty->pgrp), p);
1da177e4
LT
3076}
3077
af9b897e
AC
3078/**
3079 * tiocspgrp - attempt to set process group
3080 * @tty: tty passed by user
3081 * @real_tty: tty side device matching tty passed by user
3082 * @p: pid pointer
3083 *
3084 * Set the process group of the tty to the session passed. Only
3085 * permitted where the tty session is our session.
3086 *
3087 * Locking: None
af9b897e
AC
3088 */
3089
1da177e4
LT
3090static int tiocspgrp(struct tty_struct *tty, struct tty_struct *real_tty, pid_t __user *p)
3091{
04a2e6a5
EB
3092 struct pid *pgrp;
3093 pid_t pgrp_nr;
1da177e4
LT
3094 int retval = tty_check_change(real_tty);
3095
3096 if (retval == -EIO)
3097 return -ENOTTY;
3098 if (retval)
3099 return retval;
3100 if (!current->signal->tty ||
3101 (current->signal->tty != real_tty) ||
ab521dc0 3102 (real_tty->session != task_session(current)))
1da177e4 3103 return -ENOTTY;
04a2e6a5 3104 if (get_user(pgrp_nr, p))
1da177e4 3105 return -EFAULT;
04a2e6a5 3106 if (pgrp_nr < 0)
1da177e4 3107 return -EINVAL;
04a2e6a5
EB
3108 rcu_read_lock();
3109 pgrp = find_pid(pgrp_nr);
3110 retval = -ESRCH;
3111 if (!pgrp)
3112 goto out_unlock;
3113 retval = -EPERM;
3114 if (session_of_pgrp(pgrp) != task_session(current))
3115 goto out_unlock;
3116 retval = 0;
ab521dc0
EB
3117 put_pid(real_tty->pgrp);
3118 real_tty->pgrp = get_pid(pgrp);
04a2e6a5
EB
3119out_unlock:
3120 rcu_read_unlock();
3121 return retval;
1da177e4
LT
3122}
3123
af9b897e
AC
3124/**
3125 * tiocgsid - get session id
3126 * @tty: tty passed by user
3127 * @real_tty: tty side of the tty pased by the user if a pty else the tty
3128 * @p: pointer to returned session id
3129 *
3130 * Obtain the session id of the tty. If there is no session
3131 * return an error.
3132 *
24ec839c 3133 * Locking: none. Reference to current->signal->tty is safe.
af9b897e
AC
3134 */
3135
1da177e4
LT
3136static int tiocgsid(struct tty_struct *tty, struct tty_struct *real_tty, pid_t __user *p)
3137{
3138 /*
3139 * (tty == real_tty) is a cheap way of
3140 * testing if the tty is NOT a master pty.
3141 */
3142 if (tty == real_tty && current->signal->tty != real_tty)
3143 return -ENOTTY;
ab521dc0 3144 if (!real_tty->session)
1da177e4 3145 return -ENOTTY;
ab521dc0 3146 return put_user(pid_nr(real_tty->session), p);
1da177e4
LT
3147}
3148
af9b897e
AC
3149/**
3150 * tiocsetd - set line discipline
3151 * @tty: tty device
3152 * @p: pointer to user data
3153 *
3154 * Set the line discipline according to user request.
3155 *
3156 * Locking: see tty_set_ldisc, this function is just a helper
3157 */
3158
1da177e4
LT
3159static int tiocsetd(struct tty_struct *tty, int __user *p)
3160{
3161 int ldisc;
3162
3163 if (get_user(ldisc, p))
3164 return -EFAULT;
3165 return tty_set_ldisc(tty, ldisc);
3166}
3167
af9b897e
AC
3168/**
3169 * send_break - performed time break
3170 * @tty: device to break on
3171 * @duration: timeout in mS
3172 *
3173 * Perform a timed break on hardware that lacks its own driver level
3174 * timed break functionality.
3175 *
3176 * Locking:
28298232 3177 * atomic_write_lock serializes
af9b897e 3178 *
af9b897e
AC
3179 */
3180
b20f3ae5 3181static int send_break(struct tty_struct *tty, unsigned int duration)
1da177e4 3182{
9c1729db 3183 if (tty_write_lock(tty, 0) < 0)
28298232 3184 return -EINTR;
1da177e4 3185 tty->driver->break_ctl(tty, -1);
9c1729db 3186 if (!signal_pending(current))
b20f3ae5 3187 msleep_interruptible(duration);
1da177e4 3188 tty->driver->break_ctl(tty, 0);
9c1729db 3189 tty_write_unlock(tty);
1da177e4
LT
3190 if (signal_pending(current))
3191 return -EINTR;
3192 return 0;
3193}
3194
af9b897e
AC
3195/**
3196 * tiocmget - get modem status
3197 * @tty: tty device
3198 * @file: user file pointer
3199 * @p: pointer to result
3200 *
3201 * Obtain the modem status bits from the tty driver if the feature
3202 * is supported. Return -EINVAL if it is not available.
3203 *
3204 * Locking: none (up to the driver)
3205 */
3206
3207static int tty_tiocmget(struct tty_struct *tty, struct file *file, int __user *p)
1da177e4
LT
3208{
3209 int retval = -EINVAL;
3210
3211 if (tty->driver->tiocmget) {
3212 retval = tty->driver->tiocmget(tty, file);
3213
3214 if (retval >= 0)
3215 retval = put_user(retval, p);
3216 }
3217 return retval;
3218}
3219
af9b897e
AC
3220/**
3221 * tiocmset - set modem status
3222 * @tty: tty device
3223 * @file: user file pointer
3224 * @cmd: command - clear bits, set bits or set all
3225 * @p: pointer to desired bits
3226 *
3227 * Set the modem status bits from the tty driver if the feature
3228 * is supported. Return -EINVAL if it is not available.
3229 *
3230 * Locking: none (up to the driver)
3231 */
3232
3233static int tty_tiocmset(struct tty_struct *tty, struct file *file, unsigned int cmd,
1da177e4
LT
3234 unsigned __user *p)
3235{
3236 int retval = -EINVAL;
3237
3238 if (tty->driver->tiocmset) {
3239 unsigned int set, clear, val;
3240
3241 retval = get_user(val, p);
3242 if (retval)
3243 return retval;
3244
3245 set = clear = 0;
3246 switch (cmd) {
3247 case TIOCMBIS:
3248 set = val;
3249 break;
3250 case TIOCMBIC:
3251 clear = val;
3252 break;
3253 case TIOCMSET:
3254 set = val;
3255 clear = ~val;
3256 break;
3257 }
3258
3259 set &= TIOCM_DTR|TIOCM_RTS|TIOCM_OUT1|TIOCM_OUT2|TIOCM_LOOP;
3260 clear &= TIOCM_DTR|TIOCM_RTS|TIOCM_OUT1|TIOCM_OUT2|TIOCM_LOOP;
3261
3262 retval = tty->driver->tiocmset(tty, file, set, clear);
3263 }
3264 return retval;
3265}
3266
3267/*
3268 * Split this up, as gcc can choke on it otherwise..
3269 */
3270int tty_ioctl(struct inode * inode, struct file * file,
3271 unsigned int cmd, unsigned long arg)
3272{
3273 struct tty_struct *tty, *real_tty;
3274 void __user *p = (void __user *)arg;
3275 int retval;
3276 struct tty_ldisc *ld;
3277
3278 tty = (struct tty_struct *)file->private_data;
3279 if (tty_paranoia_check(tty, inode, "tty_ioctl"))
3280 return -EINVAL;
3281
28298232
AC
3282 /* CHECKME: is this safe as one end closes ? */
3283
1da177e4
LT
3284 real_tty = tty;
3285 if (tty->driver->type == TTY_DRIVER_TYPE_PTY &&
3286 tty->driver->subtype == PTY_TYPE_MASTER)
3287 real_tty = tty->link;
3288
3289 /*
3290 * Break handling by driver
3291 */
3292 if (!tty->driver->break_ctl) {
3293 switch(cmd) {
3294 case TIOCSBRK:
3295 case TIOCCBRK:
3296 if (tty->driver->ioctl)
3297 return tty->driver->ioctl(tty, file, cmd, arg);
3298 return -EINVAL;
3299
3300 /* These two ioctl's always return success; even if */
3301 /* the driver doesn't support them. */
3302 case TCSBRK:
3303 case TCSBRKP:
3304 if (!tty->driver->ioctl)
3305 return 0;
3306 retval = tty->driver->ioctl(tty, file, cmd, arg);
3307 if (retval == -ENOIOCTLCMD)
3308 retval = 0;
3309 return retval;
3310 }
3311 }
3312
3313 /*
3314 * Factor out some common prep work
3315 */
3316 switch (cmd) {
3317 case TIOCSETD:
3318 case TIOCSBRK:
3319 case TIOCCBRK:
3320 case TCSBRK:
3321 case TCSBRKP:
3322 retval = tty_check_change(tty);
3323 if (retval)
3324 return retval;
3325 if (cmd != TIOCCBRK) {
3326 tty_wait_until_sent(tty, 0);
3327 if (signal_pending(current))
3328 return -EINTR;
3329 }
3330 break;
3331 }
3332
3333 switch (cmd) {
3334 case TIOCSTI:
3335 return tiocsti(tty, p);
3336 case TIOCGWINSZ:
3337 return tiocgwinsz(tty, p);
3338 case TIOCSWINSZ:
3339 return tiocswinsz(tty, real_tty, p);
3340 case TIOCCONS:
3341 return real_tty!=tty ? -EINVAL : tioccons(file);
3342 case FIONBIO:
3343 return fionbio(file, p);
3344 case TIOCEXCL:
3345 set_bit(TTY_EXCLUSIVE, &tty->flags);
3346 return 0;
3347 case TIOCNXCL:
3348 clear_bit(TTY_EXCLUSIVE, &tty->flags);
3349 return 0;
3350 case TIOCNOTTY:
3351 if (current->signal->tty != tty)
3352 return -ENOTTY;
98a27ba4 3353 no_tty();
1da177e4
LT
3354 return 0;
3355 case TIOCSCTTY:
3356 return tiocsctty(tty, arg);
3357 case TIOCGPGRP:
3358 return tiocgpgrp(tty, real_tty, p);
3359 case TIOCSPGRP:
3360 return tiocspgrp(tty, real_tty, p);
3361 case TIOCGSID:
3362 return tiocgsid(tty, real_tty, p);
3363 case TIOCGETD:
3364 /* FIXME: check this is ok */
3365 return put_user(tty->ldisc.num, (int __user *)p);
3366 case TIOCSETD:
3367 return tiocsetd(tty, p);
3368#ifdef CONFIG_VT
3369 case TIOCLINUX:
3370 return tioclinux(tty, arg);
3371#endif
3372 /*
3373 * Break handling
3374 */
3375 case TIOCSBRK: /* Turn break on, unconditionally */
3376 tty->driver->break_ctl(tty, -1);
3377 return 0;
3378
3379 case TIOCCBRK: /* Turn break off, unconditionally */
3380 tty->driver->break_ctl(tty, 0);
3381 return 0;
3382 case TCSBRK: /* SVID version: non-zero arg --> no break */
283fef59
PF
3383 /* non-zero arg means wait for all output data
3384 * to be sent (performed above) but don't send break.
3385 * This is used by the tcdrain() termios function.
1da177e4
LT
3386 */
3387 if (!arg)
b20f3ae5 3388 return send_break(tty, 250);
1da177e4
LT
3389 return 0;
3390 case TCSBRKP: /* support for POSIX tcsendbreak() */
b20f3ae5 3391 return send_break(tty, arg ? arg*100 : 250);
1da177e4
LT
3392
3393 case TIOCMGET:
3394 return tty_tiocmget(tty, file, p);
3395
3396 case TIOCMSET:
3397 case TIOCMBIC:
3398 case TIOCMBIS:
3399 return tty_tiocmset(tty, file, cmd, p);
c5c34d48
PF
3400 case TCFLSH:
3401 switch (arg) {
3402 case TCIFLUSH:
3403 case TCIOFLUSH:
3404 /* flush tty buffer and allow ldisc to process ioctl */
3405 tty_buffer_flush(tty);
3406 break;
3407 }
3408 break;
1da177e4
LT
3409 }
3410 if (tty->driver->ioctl) {
3411 retval = (tty->driver->ioctl)(tty, file, cmd, arg);
3412 if (retval != -ENOIOCTLCMD)
3413 return retval;
3414 }
3415 ld = tty_ldisc_ref_wait(tty);
3416 retval = -EINVAL;
3417 if (ld->ioctl) {
3418 retval = ld->ioctl(tty, file, cmd, arg);
3419 if (retval == -ENOIOCTLCMD)
3420 retval = -EINVAL;
3421 }
3422 tty_ldisc_deref(ld);
3423 return retval;
3424}
3425
e10cc1df
PF
3426#ifdef CONFIG_COMPAT
3427static long tty_compat_ioctl(struct file * file, unsigned int cmd,
3428 unsigned long arg)
3429{
3430 struct inode *inode = file->f_dentry->d_inode;
3431 struct tty_struct *tty = file->private_data;
3432 struct tty_ldisc *ld;
3433 int retval = -ENOIOCTLCMD;
3434
3435 if (tty_paranoia_check(tty, inode, "tty_ioctl"))
3436 return -EINVAL;
3437
3438 if (tty->driver->compat_ioctl) {
3439 retval = (tty->driver->compat_ioctl)(tty, file, cmd, arg);
3440 if (retval != -ENOIOCTLCMD)
3441 return retval;
3442 }
3443
3444 ld = tty_ldisc_ref_wait(tty);
3445 if (ld->compat_ioctl)
3446 retval = ld->compat_ioctl(tty, file, cmd, arg);
3447 tty_ldisc_deref(ld);
3448
3449 return retval;
3450}
3451#endif
1da177e4
LT
3452
3453/*
3454 * This implements the "Secure Attention Key" --- the idea is to
3455 * prevent trojan horses by killing all processes associated with this
3456 * tty when the user hits the "Secure Attention Key". Required for
3457 * super-paranoid applications --- see the Orange Book for more details.
3458 *
3459 * This code could be nicer; ideally it should send a HUP, wait a few
3460 * seconds, then send a INT, and then a KILL signal. But you then
3461 * have to coordinate with the init process, since all processes associated
3462 * with the current tty must be dead before the new getty is allowed
3463 * to spawn.
3464 *
3465 * Now, if it would be correct ;-/ The current code has a nasty hole -
3466 * it doesn't catch files in flight. We may send the descriptor to ourselves
3467 * via AF_UNIX socket, close it and later fetch from socket. FIXME.
3468 *
3469 * Nasty bug: do_SAK is being called in interrupt context. This can
3470 * deadlock. We punt it up to process context. AKPM - 16Mar2001
3471 */
8b6312f4 3472void __do_SAK(struct tty_struct *tty)
1da177e4
LT
3473{
3474#ifdef TTY_SOFT_SAK
3475 tty_hangup(tty);
3476#else
652486fb 3477 struct task_struct *g, *p;
ab521dc0 3478 struct pid *session;
1da177e4
LT
3479 int i;
3480 struct file *filp;
badf1662 3481 struct fdtable *fdt;
1da177e4
LT
3482
3483 if (!tty)
3484 return;
24ec839c 3485 session = tty->session;
1da177e4 3486
b3f13deb 3487 tty_ldisc_flush(tty);
1da177e4
LT
3488
3489 if (tty->driver->flush_buffer)
3490 tty->driver->flush_buffer(tty);
3491
3492 read_lock(&tasklist_lock);
652486fb 3493 /* Kill the entire session */
ab521dc0 3494 do_each_pid_task(session, PIDTYPE_SID, p) {
652486fb 3495 printk(KERN_NOTICE "SAK: killed process %d"
937949d9 3496 " (%s): process_session(p)==tty->session\n",
652486fb
EB
3497 p->pid, p->comm);
3498 send_sig(SIGKILL, p, 1);
ab521dc0 3499 } while_each_pid_task(session, PIDTYPE_SID, p);
652486fb
EB
3500 /* Now kill any processes that happen to have the
3501 * tty open.
3502 */
3503 do_each_thread(g, p) {
3504 if (p->signal->tty == tty) {
1da177e4 3505 printk(KERN_NOTICE "SAK: killed process %d"
937949d9 3506 " (%s): process_session(p)==tty->session\n",
1da177e4
LT
3507 p->pid, p->comm);
3508 send_sig(SIGKILL, p, 1);
3509 continue;
3510 }
3511 task_lock(p);
3512 if (p->files) {
ca99c1da
DS
3513 /*
3514 * We don't take a ref to the file, so we must
3515 * hold ->file_lock instead.
3516 */
3517 spin_lock(&p->files->file_lock);
badf1662
DS
3518 fdt = files_fdtable(p->files);
3519 for (i=0; i < fdt->max_fds; i++) {
1da177e4
LT
3520 filp = fcheck_files(p->files, i);
3521 if (!filp)
3522 continue;
3523 if (filp->f_op->read == tty_read &&
3524 filp->private_data == tty) {
3525 printk(KERN_NOTICE "SAK: killed process %d"
3526 " (%s): fd#%d opened to the tty\n",
3527 p->pid, p->comm, i);
20ac9437 3528 force_sig(SIGKILL, p);
1da177e4
LT
3529 break;
3530 }
3531 }
ca99c1da 3532 spin_unlock(&p->files->file_lock);
1da177e4
LT
3533 }
3534 task_unlock(p);
652486fb 3535 } while_each_thread(g, p);
1da177e4
LT
3536 read_unlock(&tasklist_lock);
3537#endif
3538}
3539
8b6312f4
EB
3540static void do_SAK_work(struct work_struct *work)
3541{
3542 struct tty_struct *tty =
3543 container_of(work, struct tty_struct, SAK_work);
3544 __do_SAK(tty);
3545}
3546
1da177e4
LT
3547/*
3548 * The tq handling here is a little racy - tty->SAK_work may already be queued.
3549 * Fortunately we don't need to worry, because if ->SAK_work is already queued,
3550 * the values which we write to it will be identical to the values which it
3551 * already has. --akpm
3552 */
3553void do_SAK(struct tty_struct *tty)
3554{
3555 if (!tty)
3556 return;
1da177e4
LT
3557 schedule_work(&tty->SAK_work);
3558}
3559
3560EXPORT_SYMBOL(do_SAK);
3561
af9b897e
AC
3562/**
3563 * flush_to_ldisc
65f27f38 3564 * @work: tty structure passed from work queue.
af9b897e
AC
3565 *
3566 * This routine is called out of the software interrupt to flush data
3567 * from the buffer chain to the line discipline.
3568 *
3569 * Locking: holds tty->buf.lock to guard buffer list. Drops the lock
3570 * while invoking the line discipline receive_buf method. The
3571 * receive_buf method is single threaded for each tty instance.
1da177e4
LT
3572 */
3573
65f27f38 3574static void flush_to_ldisc(struct work_struct *work)
1da177e4 3575{
65f27f38
DH
3576 struct tty_struct *tty =
3577 container_of(work, struct tty_struct, buf.work.work);
1da177e4
LT
3578 unsigned long flags;
3579 struct tty_ldisc *disc;
2c3bb20f 3580 struct tty_buffer *tbuf, *head;
8977d929
PF
3581 char *char_buf;
3582 unsigned char *flag_buf;
1da177e4
LT
3583
3584 disc = tty_ldisc_ref(tty);
3585 if (disc == NULL) /* !TTY_LDISC */
3586 return;
3587
808249ce 3588 spin_lock_irqsave(&tty->buf.lock, flags);
2c3bb20f
PF
3589 head = tty->buf.head;
3590 if (head != NULL) {
3591 tty->buf.head = NULL;
3592 for (;;) {
3593 int count = head->commit - head->read;
3594 if (!count) {
3595 if (head->next == NULL)
3596 break;
3597 tbuf = head;
3598 head = head->next;
3599 tty_buffer_free(tty, tbuf);
3600 continue;
3601 }
3602 if (!tty->receive_room) {
3603 schedule_delayed_work(&tty->buf.work, 1);
3604 break;
3605 }
3606 if (count > tty->receive_room)
3607 count = tty->receive_room;
3608 char_buf = head->char_buf_ptr + head->read;
3609 flag_buf = head->flag_buf_ptr + head->read;
3610 head->read += count;
8977d929
PF
3611 spin_unlock_irqrestore(&tty->buf.lock, flags);
3612 disc->receive_buf(tty, char_buf, flag_buf, count);
3613 spin_lock_irqsave(&tty->buf.lock, flags);
3614 }
2c3bb20f 3615 tty->buf.head = head;
33f0f88f 3616 }
808249ce 3617 spin_unlock_irqrestore(&tty->buf.lock, flags);
817d6d3b 3618
1da177e4
LT
3619 tty_ldisc_deref(disc);
3620}
3621
1da177e4
LT
3622/**
3623 * tty_flip_buffer_push - terminal
3624 * @tty: tty to push
3625 *
3626 * Queue a push of the terminal flip buffers to the line discipline. This
3627 * function must not be called from IRQ context if tty->low_latency is set.
3628 *
3629 * In the event of the queue being busy for flipping the work will be
3630 * held off and retried later.
af9b897e
AC
3631 *
3632 * Locking: tty buffer lock. Driver locks in low latency mode.
1da177e4
LT
3633 */
3634
3635void tty_flip_buffer_push(struct tty_struct *tty)
3636{
808249ce
PF
3637 unsigned long flags;
3638 spin_lock_irqsave(&tty->buf.lock, flags);
33b37a33 3639 if (tty->buf.tail != NULL)
8977d929 3640 tty->buf.tail->commit = tty->buf.tail->used;
808249ce
PF
3641 spin_unlock_irqrestore(&tty->buf.lock, flags);
3642
1da177e4 3643 if (tty->low_latency)
65f27f38 3644 flush_to_ldisc(&tty->buf.work.work);
1da177e4 3645 else
33f0f88f 3646 schedule_delayed_work(&tty->buf.work, 1);
1da177e4
LT
3647}
3648
3649EXPORT_SYMBOL(tty_flip_buffer_push);
3650
33f0f88f 3651
af9b897e
AC
3652/**
3653 * initialize_tty_struct
3654 * @tty: tty to initialize
3655 *
3656 * This subroutine initializes a tty structure that has been newly
3657 * allocated.
3658 *
3659 * Locking: none - tty in question must not be exposed at this point
1da177e4 3660 */
af9b897e 3661
1da177e4
LT
3662static void initialize_tty_struct(struct tty_struct *tty)
3663{
3664 memset(tty, 0, sizeof(struct tty_struct));
3665 tty->magic = TTY_MAGIC;
3666 tty_ldisc_assign(tty, tty_ldisc_get(N_TTY));
ab521dc0
EB
3667 tty->session = NULL;
3668 tty->pgrp = NULL;
1da177e4 3669 tty->overrun_time = jiffies;
33f0f88f
AC
3670 tty->buf.head = tty->buf.tail = NULL;
3671 tty_buffer_init(tty);
65f27f38 3672 INIT_DELAYED_WORK(&tty->buf.work, flush_to_ldisc);
33f0f88f 3673 init_MUTEX(&tty->buf.pty_sem);
5785c95b 3674 mutex_init(&tty->termios_mutex);
1da177e4
LT
3675 init_waitqueue_head(&tty->write_wait);
3676 init_waitqueue_head(&tty->read_wait);
65f27f38 3677 INIT_WORK(&tty->hangup_work, do_tty_hangup);
70522e12
IM
3678 mutex_init(&tty->atomic_read_lock);
3679 mutex_init(&tty->atomic_write_lock);
1da177e4
LT
3680 spin_lock_init(&tty->read_lock);
3681 INIT_LIST_HEAD(&tty->tty_files);
7f1f86a0 3682 INIT_WORK(&tty->SAK_work, do_SAK_work);
1da177e4
LT
3683}
3684
3685/*
3686 * The default put_char routine if the driver did not define one.
3687 */
af9b897e 3688
1da177e4
LT
3689static void tty_default_put_char(struct tty_struct *tty, unsigned char ch)
3690{
3691 tty->driver->write(tty, &ch, 1);
3692}
3693
7fe845d1 3694static struct class *tty_class;
1da177e4
LT
3695
3696/**
af9b897e
AC
3697 * tty_register_device - register a tty device
3698 * @driver: the tty driver that describes the tty device
3699 * @index: the index in the tty driver for this tty device
3700 * @device: a struct device that is associated with this tty device.
3701 * This field is optional, if there is no known struct device
3702 * for this tty device it can be set to NULL safely.
1da177e4 3703 *
01107d34
GKH
3704 * Returns a pointer to the struct device for this tty device
3705 * (or ERR_PTR(-EFOO) on error).
1cdcb6b4 3706 *
af9b897e
AC
3707 * This call is required to be made to register an individual tty device
3708 * if the tty driver's flags have the TTY_DRIVER_DYNAMIC_DEV bit set. If
3709 * that bit is not set, this function should not be called by a tty
3710 * driver.
3711 *
3712 * Locking: ??
1da177e4 3713 */
af9b897e 3714
01107d34
GKH
3715struct device *tty_register_device(struct tty_driver *driver, unsigned index,
3716 struct device *device)
1da177e4
LT
3717{
3718 char name[64];
3719 dev_t dev = MKDEV(driver->major, driver->minor_start) + index;
3720
3721 if (index >= driver->num) {
3722 printk(KERN_ERR "Attempt to register invalid tty line number "
3723 " (%d).\n", index);
1cdcb6b4 3724 return ERR_PTR(-EINVAL);
1da177e4
LT
3725 }
3726
1da177e4
LT
3727 if (driver->type == TTY_DRIVER_TYPE_PTY)
3728 pty_line_name(driver, index, name);
3729 else
3730 tty_line_name(driver, index, name);
1cdcb6b4 3731
01107d34 3732 return device_create(tty_class, device, dev, name);
1da177e4
LT
3733}
3734
3735/**
af9b897e
AC
3736 * tty_unregister_device - unregister a tty device
3737 * @driver: the tty driver that describes the tty device
3738 * @index: the index in the tty driver for this tty device
1da177e4 3739 *
af9b897e
AC
3740 * If a tty device is registered with a call to tty_register_device() then
3741 * this function must be called when the tty device is gone.
3742 *
3743 * Locking: ??
1da177e4 3744 */
af9b897e 3745
1da177e4
LT
3746void tty_unregister_device(struct tty_driver *driver, unsigned index)
3747{
01107d34 3748 device_destroy(tty_class, MKDEV(driver->major, driver->minor_start) + index);
1da177e4
LT
3749}
3750
3751EXPORT_SYMBOL(tty_register_device);
3752EXPORT_SYMBOL(tty_unregister_device);
3753
3754struct tty_driver *alloc_tty_driver(int lines)
3755{
3756 struct tty_driver *driver;
3757
3758 driver = kmalloc(sizeof(struct tty_driver), GFP_KERNEL);
3759 if (driver) {
3760 memset(driver, 0, sizeof(struct tty_driver));
3761 driver->magic = TTY_DRIVER_MAGIC;
3762 driver->num = lines;
3763 /* later we'll move allocation of tables here */
3764 }
3765 return driver;
3766}
3767
3768void put_tty_driver(struct tty_driver *driver)
3769{
3770 kfree(driver);
3771}
3772
b68e31d0
JD
3773void tty_set_operations(struct tty_driver *driver,
3774 const struct tty_operations *op)
1da177e4
LT
3775{
3776 driver->open = op->open;
3777 driver->close = op->close;
3778 driver->write = op->write;
3779 driver->put_char = op->put_char;
3780 driver->flush_chars = op->flush_chars;
3781 driver->write_room = op->write_room;
3782 driver->chars_in_buffer = op->chars_in_buffer;
3783 driver->ioctl = op->ioctl;
e10cc1df 3784 driver->compat_ioctl = op->compat_ioctl;
1da177e4
LT
3785 driver->set_termios = op->set_termios;
3786 driver->throttle = op->throttle;
3787 driver->unthrottle = op->unthrottle;
3788 driver->stop = op->stop;
3789 driver->start = op->start;
3790 driver->hangup = op->hangup;
3791 driver->break_ctl = op->break_ctl;
3792 driver->flush_buffer = op->flush_buffer;
3793 driver->set_ldisc = op->set_ldisc;
3794 driver->wait_until_sent = op->wait_until_sent;
3795 driver->send_xchar = op->send_xchar;
3796 driver->read_proc = op->read_proc;
3797 driver->write_proc = op->write_proc;
3798 driver->tiocmget = op->tiocmget;
3799 driver->tiocmset = op->tiocmset;
3800}
3801
3802
3803EXPORT_SYMBOL(alloc_tty_driver);
3804EXPORT_SYMBOL(put_tty_driver);
3805EXPORT_SYMBOL(tty_set_operations);
3806
3807/*
3808 * Called by a tty driver to register itself.
3809 */
3810int tty_register_driver(struct tty_driver *driver)
3811{
3812 int error;
3813 int i;
3814 dev_t dev;
3815 void **p = NULL;
3816
3817 if (driver->flags & TTY_DRIVER_INSTALLED)
3818 return 0;
3819
543691a6
AW
3820 if (!(driver->flags & TTY_DRIVER_DEVPTS_MEM) && driver->num) {
3821 p = kzalloc(driver->num * 3 * sizeof(void *), GFP_KERNEL);
1da177e4
LT
3822 if (!p)
3823 return -ENOMEM;
1da177e4
LT
3824 }
3825
3826 if (!driver->major) {
3827 error = alloc_chrdev_region(&dev, driver->minor_start, driver->num,
e5717c48 3828 driver->name);
1da177e4
LT
3829 if (!error) {
3830 driver->major = MAJOR(dev);
3831 driver->minor_start = MINOR(dev);
3832 }
3833 } else {
3834 dev = MKDEV(driver->major, driver->minor_start);
e5717c48 3835 error = register_chrdev_region(dev, driver->num, driver->name);
1da177e4
LT
3836 }
3837 if (error < 0) {
3838 kfree(p);
3839 return error;
3840 }
3841
3842 if (p) {
3843 driver->ttys = (struct tty_struct **)p;
edc6afc5
AC
3844 driver->termios = (struct ktermios **)(p + driver->num);
3845 driver->termios_locked = (struct ktermios **)(p + driver->num * 2);
1da177e4
LT
3846 } else {
3847 driver->ttys = NULL;
3848 driver->termios = NULL;
3849 driver->termios_locked = NULL;
3850 }
3851
3852 cdev_init(&driver->cdev, &tty_fops);
3853 driver->cdev.owner = driver->owner;
3854 error = cdev_add(&driver->cdev, dev, driver->num);
3855 if (error) {
1da177e4
LT
3856 unregister_chrdev_region(dev, driver->num);
3857 driver->ttys = NULL;
3858 driver->termios = driver->termios_locked = NULL;
3859 kfree(p);
3860 return error;
3861 }
3862
3863 if (!driver->put_char)
3864 driver->put_char = tty_default_put_char;
3865
ca509f69 3866 mutex_lock(&tty_mutex);
1da177e4 3867 list_add(&driver->tty_drivers, &tty_drivers);
ca509f69 3868 mutex_unlock(&tty_mutex);
1da177e4 3869
331b8319 3870 if ( !(driver->flags & TTY_DRIVER_DYNAMIC_DEV) ) {
1da177e4
LT
3871 for(i = 0; i < driver->num; i++)
3872 tty_register_device(driver, i, NULL);
3873 }
3874 proc_tty_register_driver(driver);
3875 return 0;
3876}
3877
3878EXPORT_SYMBOL(tty_register_driver);
3879
3880/*
3881 * Called by a tty driver to unregister itself.
3882 */
3883int tty_unregister_driver(struct tty_driver *driver)
3884{
3885 int i;
edc6afc5 3886 struct ktermios *tp;
1da177e4
LT
3887 void *p;
3888
3889 if (driver->refcount)
3890 return -EBUSY;
3891
3892 unregister_chrdev_region(MKDEV(driver->major, driver->minor_start),
3893 driver->num);
ca509f69 3894 mutex_lock(&tty_mutex);
1da177e4 3895 list_del(&driver->tty_drivers);
ca509f69 3896 mutex_unlock(&tty_mutex);
1da177e4
LT
3897
3898 /*
3899 * Free the termios and termios_locked structures because
3900 * we don't want to get memory leaks when modular tty
3901 * drivers are removed from the kernel.
3902 */
3903 for (i = 0; i < driver->num; i++) {
3904 tp = driver->termios[i];
3905 if (tp) {
3906 driver->termios[i] = NULL;
3907 kfree(tp);
3908 }
3909 tp = driver->termios_locked[i];
3910 if (tp) {
3911 driver->termios_locked[i] = NULL;
3912 kfree(tp);
3913 }
331b8319 3914 if (!(driver->flags & TTY_DRIVER_DYNAMIC_DEV))
1da177e4
LT
3915 tty_unregister_device(driver, i);
3916 }
3917 p = driver->ttys;
3918 proc_tty_unregister_driver(driver);
3919 driver->ttys = NULL;
3920 driver->termios = driver->termios_locked = NULL;
3921 kfree(p);
3922 cdev_del(&driver->cdev);
3923 return 0;
3924}
1da177e4
LT
3925EXPORT_SYMBOL(tty_unregister_driver);
3926
24ec839c
PZ
3927dev_t tty_devnum(struct tty_struct *tty)
3928{
3929 return MKDEV(tty->driver->major, tty->driver->minor_start) + tty->index;
3930}
3931EXPORT_SYMBOL(tty_devnum);
3932
3933void proc_clear_tty(struct task_struct *p)
3934{
3935 spin_lock_irq(&p->sighand->siglock);
3936 p->signal->tty = NULL;
3937 spin_unlock_irq(&p->sighand->siglock);
3938}
7cac4ce5 3939EXPORT_SYMBOL(proc_clear_tty);
24ec839c 3940
2a65f1d9 3941static void __proc_set_tty(struct task_struct *tsk, struct tty_struct *tty)
24ec839c
PZ
3942{
3943 if (tty) {
d9c1e9a8
EB
3944 /* We should not have a session or pgrp to here but.... */
3945 put_pid(tty->session);
3946 put_pid(tty->pgrp);
ab521dc0
EB
3947 tty->session = get_pid(task_session(tsk));
3948 tty->pgrp = get_pid(task_pgrp(tsk));
24ec839c 3949 }
2a65f1d9 3950 put_pid(tsk->signal->tty_old_pgrp);
24ec839c 3951 tsk->signal->tty = tty;
ab521dc0 3952 tsk->signal->tty_old_pgrp = NULL;
24ec839c
PZ
3953}
3954
98a27ba4 3955static void proc_set_tty(struct task_struct *tsk, struct tty_struct *tty)
24ec839c
PZ
3956{
3957 spin_lock_irq(&tsk->sighand->siglock);
2a65f1d9 3958 __proc_set_tty(tsk, tty);
24ec839c
PZ
3959 spin_unlock_irq(&tsk->sighand->siglock);
3960}
3961
3962struct tty_struct *get_current_tty(void)
3963{
3964 struct tty_struct *tty;
3965 WARN_ON_ONCE(!mutex_is_locked(&tty_mutex));
3966 tty = current->signal->tty;
3967 /*
3968 * session->tty can be changed/cleared from under us, make sure we
3969 * issue the load. The obtained pointer, when not NULL, is valid as
3970 * long as we hold tty_mutex.
3971 */
3972 barrier();
3973 return tty;
3974}
a311f743 3975EXPORT_SYMBOL_GPL(get_current_tty);
1da177e4
LT
3976
3977/*
3978 * Initialize the console device. This is called *early*, so
3979 * we can't necessarily depend on lots of kernel help here.
3980 * Just do some early initializations, and do the complex setup
3981 * later.
3982 */
3983void __init console_init(void)
3984{
3985 initcall_t *call;
3986
3987 /* Setup the default TTY line discipline. */
3988 (void) tty_register_ldisc(N_TTY, &tty_ldisc_N_TTY);
3989
3990 /*
3991 * set up the console device so that later boot sequences can
3992 * inform about problems etc..
3993 */
1da177e4
LT
3994 call = __con_initcall_start;
3995 while (call < __con_initcall_end) {
3996 (*call)();
3997 call++;
3998 }
3999}
4000
4001#ifdef CONFIG_VT
4002extern int vty_init(void);
4003#endif
4004
4005static int __init tty_class_init(void)
4006{
7fe845d1 4007 tty_class = class_create(THIS_MODULE, "tty");
1da177e4
LT
4008 if (IS_ERR(tty_class))
4009 return PTR_ERR(tty_class);
4010 return 0;
4011}
4012
4013postcore_initcall(tty_class_init);
4014
4015/* 3/2004 jmc: why do these devices exist? */
4016
4017static struct cdev tty_cdev, console_cdev;
4018#ifdef CONFIG_UNIX98_PTYS
4019static struct cdev ptmx_cdev;
4020#endif
4021#ifdef CONFIG_VT
4022static struct cdev vc0_cdev;
4023#endif
4024
4025/*
4026 * Ok, now we can initialize the rest of the tty devices and can count
4027 * on memory allocations, interrupts etc..
4028 */
4029static int __init tty_init(void)
4030{
4031 cdev_init(&tty_cdev, &tty_fops);
4032 if (cdev_add(&tty_cdev, MKDEV(TTYAUX_MAJOR, 0), 1) ||
4033 register_chrdev_region(MKDEV(TTYAUX_MAJOR, 0), 1, "/dev/tty") < 0)
4034 panic("Couldn't register /dev/tty driver\n");
01107d34 4035 device_create(tty_class, NULL, MKDEV(TTYAUX_MAJOR, 0), "tty");
1da177e4
LT
4036
4037 cdev_init(&console_cdev, &console_fops);
4038 if (cdev_add(&console_cdev, MKDEV(TTYAUX_MAJOR, 1), 1) ||
4039 register_chrdev_region(MKDEV(TTYAUX_MAJOR, 1), 1, "/dev/console") < 0)
4040 panic("Couldn't register /dev/console driver\n");
01107d34 4041 device_create(tty_class, NULL, MKDEV(TTYAUX_MAJOR, 1), "console");
1da177e4
LT
4042
4043#ifdef CONFIG_UNIX98_PTYS
4044 cdev_init(&ptmx_cdev, &ptmx_fops);
4045 if (cdev_add(&ptmx_cdev, MKDEV(TTYAUX_MAJOR, 2), 1) ||
4046 register_chrdev_region(MKDEV(TTYAUX_MAJOR, 2), 1, "/dev/ptmx") < 0)
4047 panic("Couldn't register /dev/ptmx driver\n");
01107d34 4048 device_create(tty_class, NULL, MKDEV(TTYAUX_MAJOR, 2), "ptmx");
1da177e4
LT
4049#endif
4050
4051#ifdef CONFIG_VT
4052 cdev_init(&vc0_cdev, &console_fops);
4053 if (cdev_add(&vc0_cdev, MKDEV(TTY_MAJOR, 0), 1) ||
4054 register_chrdev_region(MKDEV(TTY_MAJOR, 0), 1, "/dev/vc/0") < 0)
4055 panic("Couldn't register /dev/tty0 driver\n");
01107d34 4056 device_create(tty_class, NULL, MKDEV(TTY_MAJOR, 0), "tty0");
1da177e4
LT
4057
4058 vty_init();
4059#endif
4060 return 0;
4061}
4062module_init(tty_init);