fbdev: imsttfb: Fix use after free bug in imsttfb_probe
[linux-block.git] / drivers / dma-buf / sync_file.c
CommitLineData
9c92ab61 1// SPDX-License-Identifier: GPL-2.0-only
d4cab38e
GP
2/*
3 * drivers/dma-buf/sync_file.c
4 *
5 * Copyright (C) 2012 Google, Inc.
d4cab38e
GP
6 */
7
519f490d 8#include <linux/dma-fence-unwrap.h>
d4cab38e
GP
9#include <linux/export.h>
10#include <linux/file.h>
11#include <linux/fs.h>
12#include <linux/kernel.h>
13#include <linux/poll.h>
14#include <linux/sched.h>
15#include <linux/slab.h>
16#include <linux/uaccess.h>
17#include <linux/anon_inodes.h>
460bfc41
GP
18#include <linux/sync_file.h>
19#include <uapi/linux/sync_file.h>
d4cab38e
GP
20
21static const struct file_operations sync_file_fops;
22
a02b9dc9 23static struct sync_file *sync_file_alloc(void)
d4cab38e
GP
24{
25 struct sync_file *sync_file;
26
a02b9dc9 27 sync_file = kzalloc(sizeof(*sync_file), GFP_KERNEL);
d4cab38e
GP
28 if (!sync_file)
29 return NULL;
30
31 sync_file->file = anon_inode_getfile("sync_file", &sync_file_fops,
32 sync_file, 0);
33 if (IS_ERR(sync_file->file))
34 goto err;
35
d4cab38e
GP
36 init_waitqueue_head(&sync_file->wq);
37
a02b9dc9
GP
38 INIT_LIST_HEAD(&sync_file->cb.node);
39
d4cab38e
GP
40 return sync_file;
41
42err:
43 kfree(sync_file);
44 return NULL;
45}
46
f54d1867 47static void fence_check_cb_func(struct dma_fence *f, struct dma_fence_cb *cb)
d4cab38e 48{
d4cab38e
GP
49 struct sync_file *sync_file;
50
a02b9dc9 51 sync_file = container_of(cb, struct sync_file, cb);
d4cab38e 52
a02b9dc9 53 wake_up_all(&sync_file->wq);
d4cab38e
GP
54}
55
56/**
c240a714 57 * sync_file_create() - creates a sync file
d4cab38e
GP
58 * @fence: fence to add to the sync_fence
59 *
24a36734
DV
60 * Creates a sync_file containg @fence. This function acquires and additional
61 * reference of @fence for the newly-created &sync_file, if it succeeds. The
62 * sync_file can be released with fput(sync_file->file). Returns the
63 * sync_file or NULL in case of error.
d4cab38e 64 */
f54d1867 65struct sync_file *sync_file_create(struct dma_fence *fence)
d4cab38e
GP
66{
67 struct sync_file *sync_file;
68
a02b9dc9 69 sync_file = sync_file_alloc();
d4cab38e
GP
70 if (!sync_file)
71 return NULL;
72
f54d1867 73 sync_file->fence = dma_fence_get(fence);
a02b9dc9 74
d4cab38e
GP
75 return sync_file;
76}
77EXPORT_SYMBOL(sync_file_create);
78
d4cab38e
GP
79static struct sync_file *sync_file_fdget(int fd)
80{
81 struct file *file = fget(fd);
82
83 if (!file)
84 return NULL;
85
86 if (file->f_op != &sync_file_fops)
87 goto err;
88
89 return file->private_data;
90
91err:
92 fput(file);
93 return NULL;
94}
95
972526a4
GP
96/**
97 * sync_file_get_fence - get the fence related to the sync_file fd
98 * @fd: sync_file fd to get the fence from
99 *
100 * Ensures @fd references a valid sync_file and returns a fence that
101 * represents all fence in the sync_file. On error NULL is returned.
102 */
f54d1867 103struct dma_fence *sync_file_get_fence(int fd)
972526a4
GP
104{
105 struct sync_file *sync_file;
f54d1867 106 struct dma_fence *fence;
972526a4
GP
107
108 sync_file = sync_file_fdget(fd);
109 if (!sync_file)
110 return NULL;
111
f54d1867 112 fence = dma_fence_get(sync_file->fence);
972526a4
GP
113 fput(sync_file->file);
114
115 return fence;
116}
117EXPORT_SYMBOL(sync_file_get_fence);
118
71ebc9a3
CW
119/**
120 * sync_file_get_name - get the name of the sync_file
121 * @sync_file: sync_file to get the fence from
122 * @buf: destination buffer to copy sync_file name into
123 * @len: available size of destination buffer.
124 *
125 * Each sync_file may have a name assigned either by the user (when merging
126 * sync_files together) or created from the fence it contains. In the latter
127 * case construction of the name is deferred until use, and so requires
128 * sync_file_get_name().
129 *
130 * Returns: a string representing the name.
131 */
132char *sync_file_get_name(struct sync_file *sync_file, char *buf, int len)
133{
134 if (sync_file->user_name[0]) {
bcfa6be2 135 strscpy(buf, sync_file->user_name, len);
71ebc9a3
CW
136 } else {
137 struct dma_fence *fence = sync_file->fence;
138
b312d8ca 139 snprintf(buf, len, "%s-%s%llu-%lld",
71ebc9a3
CW
140 fence->ops->get_driver_name(fence),
141 fence->ops->get_timeline_name(fence),
142 fence->context,
143 fence->seqno);
144 }
145
146 return buf;
147}
148
d4cab38e
GP
149/**
150 * sync_file_merge() - merge two sync_files
151 * @name: name of new fence
152 * @a: sync_file a
153 * @b: sync_file b
154 *
155 * Creates a new sync_file which contains copies of all the fences in both
156 * @a and @b. @a and @b remain valid, independent sync_file. Returns the
157 * new merged sync_file or NULL in case of error.
158 */
159static struct sync_file *sync_file_merge(const char *name, struct sync_file *a,
160 struct sync_file *b)
161{
d4cab38e 162 struct sync_file *sync_file;
245a4a7b 163 struct dma_fence *fence;
d4cab38e 164
a02b9dc9 165 sync_file = sync_file_alloc();
d4cab38e
GP
166 if (!sync_file)
167 return NULL;
168
245a4a7b
CK
169 fence = dma_fence_unwrap_merge(a->fence, b->fence);
170 if (!fence) {
171 fput(sync_file->file);
172 return NULL;
d4cab38e 173 }
245a4a7b 174 sync_file->fence = fence;
bcfa6be2 175 strscpy(sync_file->user_name, name, sizeof(sync_file->user_name));
d4cab38e
GP
176 return sync_file;
177}
178
d8f2ebaa 179static int sync_file_release(struct inode *inode, struct file *file)
d4cab38e 180{
d8f2ebaa 181 struct sync_file *sync_file = file->private_data;
d4cab38e 182
99f82843 183 if (test_bit(POLL_ENABLED, &sync_file->flags))
f54d1867
CW
184 dma_fence_remove_callback(sync_file->fence, &sync_file->cb);
185 dma_fence_put(sync_file->fence);
d4cab38e 186 kfree(sync_file);
d4cab38e 187
d4cab38e
GP
188 return 0;
189}
190
afc9a42b 191static __poll_t sync_file_poll(struct file *file, poll_table *wait)
d4cab38e
GP
192{
193 struct sync_file *sync_file = file->private_data;
d4cab38e
GP
194
195 poll_wait(file, &sync_file->wq, wait);
196
99f82843
CW
197 if (list_empty(&sync_file->cb.node) &&
198 !test_and_set_bit(POLL_ENABLED, &sync_file->flags)) {
f54d1867
CW
199 if (dma_fence_add_callback(sync_file->fence, &sync_file->cb,
200 fence_check_cb_func) < 0)
e2416553
GP
201 wake_up_all(&sync_file->wq);
202 }
d4cab38e 203
a9a08845 204 return dma_fence_is_signaled(sync_file->fence) ? EPOLLIN : 0;
d4cab38e
GP
205}
206
207static long sync_file_ioctl_merge(struct sync_file *sync_file,
92e06213 208 unsigned long arg)
d4cab38e
GP
209{
210 int fd = get_unused_fd_flags(O_CLOEXEC);
211 int err;
212 struct sync_file *fence2, *fence3;
213 struct sync_merge_data data;
214
215 if (fd < 0)
216 return fd;
217
218 if (copy_from_user(&data, (void __user *)arg, sizeof(data))) {
219 err = -EFAULT;
220 goto err_put_fd;
221 }
222
223 if (data.flags || data.pad) {
224 err = -EINVAL;
225 goto err_put_fd;
226 }
227
228 fence2 = sync_file_fdget(data.fd2);
229 if (!fence2) {
230 err = -ENOENT;
231 goto err_put_fd;
232 }
233
234 data.name[sizeof(data.name) - 1] = '\0';
235 fence3 = sync_file_merge(data.name, sync_file, fence2);
236 if (!fence3) {
237 err = -ENOMEM;
238 goto err_put_fence2;
239 }
240
241 data.fence = fd;
242 if (copy_to_user((void __user *)arg, &data, sizeof(data))) {
243 err = -EFAULT;
244 goto err_put_fence3;
245 }
246
247 fd_install(fd, fence3->file);
248 fput(fence2->file);
249 return 0;
250
251err_put_fence3:
252 fput(fence3->file);
253
254err_put_fence2:
255 fput(fence2->file);
256
257err_put_fd:
258 put_unused_fd(fd);
259 return err;
260}
261
f7974880 262static int sync_fill_fence_info(struct dma_fence *fence,
92e06213 263 struct sync_fence_info *info)
d4cab38e 264{
bcfa6be2 265 strscpy(info->obj_name, fence->ops->get_timeline_name(fence),
d4cab38e 266 sizeof(info->obj_name));
bcfa6be2 267 strscpy(info->driver_name, fence->ops->get_driver_name(fence),
d4cab38e 268 sizeof(info->driver_name));
d6c99f4b
CW
269
270 info->status = dma_fence_get_status(fence);
76250f2b
CW
271 while (test_bit(DMA_FENCE_FLAG_SIGNALED_BIT, &fence->flags) &&
272 !test_bit(DMA_FENCE_FLAG_TIMESTAMP_BIT, &fence->flags))
273 cpu_relax();
274 info->timestamp_ns =
275 test_bit(DMA_FENCE_FLAG_TIMESTAMP_BIT, &fence->flags) ?
276 ktime_to_ns(fence->timestamp) :
277 ktime_set(0, 0);
f7974880
JER
278
279 return info->status;
d4cab38e
GP
280}
281
282static long sync_file_ioctl_fence_info(struct sync_file *sync_file,
92e06213 283 unsigned long arg)
d4cab38e 284{
d4cab38e 285 struct sync_fence_info *fence_info = NULL;
519f490d
CK
286 struct dma_fence_unwrap iter;
287 struct sync_file_info info;
288 unsigned int num_fences;
289 struct dma_fence *fence;
290 int ret;
d4cab38e 291 __u32 size;
d4cab38e
GP
292
293 if (copy_from_user(&info, (void __user *)arg, sizeof(info)))
294 return -EFAULT;
295
296 if (info.flags || info.pad)
297 return -EINVAL;
298
519f490d
CK
299 num_fences = 0;
300 dma_fence_unwrap_for_each(fence, &iter, sync_file->fence)
301 ++num_fences;
a02b9dc9 302
d4cab38e
GP
303 /*
304 * Passing num_fences = 0 means that userspace doesn't want to
305 * retrieve any sync_fence_info. If num_fences = 0 we skip filling
306 * sync_fence_info and return the actual number of fences on
307 * info->num_fences.
308 */
f7974880 309 if (!info.num_fences) {
7891c30a 310 info.status = dma_fence_get_status(sync_file->fence);
d4cab38e 311 goto no_fences;
f7974880
JER
312 } else {
313 info.status = 1;
314 }
d4cab38e 315
a02b9dc9 316 if (info.num_fences < num_fences)
d4cab38e
GP
317 return -EINVAL;
318
a02b9dc9 319 size = num_fences * sizeof(*fence_info);
d4cab38e
GP
320 fence_info = kzalloc(size, GFP_KERNEL);
321 if (!fence_info)
322 return -ENOMEM;
323
519f490d
CK
324 num_fences = 0;
325 dma_fence_unwrap_for_each(fence, &iter, sync_file->fence) {
326 int status;
327
328 status = sync_fill_fence_info(fence, &fence_info[num_fences++]);
f7974880
JER
329 info.status = info.status <= 0 ? info.status : status;
330 }
d4cab38e
GP
331
332 if (copy_to_user(u64_to_user_ptr(info.sync_fence_info), fence_info,
333 size)) {
334 ret = -EFAULT;
335 goto out;
336 }
337
338no_fences:
71ebc9a3 339 sync_file_get_name(sync_file, info.name, sizeof(info.name));
a02b9dc9 340 info.num_fences = num_fences;
d4cab38e
GP
341
342 if (copy_to_user((void __user *)arg, &info, sizeof(info)))
343 ret = -EFAULT;
344 else
345 ret = 0;
346
347out:
348 kfree(fence_info);
349
350 return ret;
351}
352
353static long sync_file_ioctl(struct file *file, unsigned int cmd,
92e06213 354 unsigned long arg)
d4cab38e
GP
355{
356 struct sync_file *sync_file = file->private_data;
357
358 switch (cmd) {
359 case SYNC_IOC_MERGE:
360 return sync_file_ioctl_merge(sync_file, arg);
361
362 case SYNC_IOC_FILE_INFO:
363 return sync_file_ioctl_fence_info(sync_file, arg);
364
365 default:
366 return -ENOTTY;
367 }
368}
369
370static const struct file_operations sync_file_fops = {
371 .release = sync_file_release,
372 .poll = sync_file_poll,
373 .unlocked_ioctl = sync_file_ioctl,
1832f2d8 374 .compat_ioctl = compat_ptr_ioctl,
d4cab38e 375};