1579a97f7Sbellard /* User memory access */
2d39594e9SPeter Maydell #include "qemu/osdep.h"
3f348b6d1SVeronia Bahaa #include "qemu/cutils.h"
4579a97f7Sbellard
5579a97f7Sbellard #include "qemu.h"
63b249d26SPeter Maydell #include "user-internals.h"
7579a97f7Sbellard
lock_user(int type,abi_ulong guest_addr,ssize_t len,bool copy)8360f0abdSRichard Henderson void *lock_user(int type, abi_ulong guest_addr, ssize_t len, bool copy)
9687ca797SRichard Henderson {
1031c04834SRichard Henderson void *host_addr;
1131c04834SRichard Henderson
1231c04834SRichard Henderson guest_addr = cpu_untagged_addr(thread_cpu, guest_addr);
13687ca797SRichard Henderson if (!access_ok_untagged(type, guest_addr, len)) {
14687ca797SRichard Henderson return NULL;
15687ca797SRichard Henderson }
1631c04834SRichard Henderson host_addr = g2h_untagged(guest_addr);
17*1f2355f5SIlya Leoshkevich #ifdef CONFIG_DEBUG_REMAP
18687ca797SRichard Henderson if (copy) {
1931c04834SRichard Henderson host_addr = g_memdup(host_addr, len);
20687ca797SRichard Henderson } else {
2131c04834SRichard Henderson host_addr = g_malloc0(len);
22687ca797SRichard Henderson }
23687ca797SRichard Henderson #endif
2431c04834SRichard Henderson return host_addr;
25687ca797SRichard Henderson }
26687ca797SRichard Henderson
27*1f2355f5SIlya Leoshkevich #ifdef CONFIG_DEBUG_REMAP
unlock_user(void * host_ptr,abi_ulong guest_addr,ssize_t len)28360f0abdSRichard Henderson void unlock_user(void *host_ptr, abi_ulong guest_addr, ssize_t len)
29687ca797SRichard Henderson {
3031c04834SRichard Henderson void *host_ptr_conv;
3131c04834SRichard Henderson
32687ca797SRichard Henderson if (!host_ptr) {
33687ca797SRichard Henderson return;
34687ca797SRichard Henderson }
3531c04834SRichard Henderson host_ptr_conv = g2h(thread_cpu, guest_addr);
3631c04834SRichard Henderson if (host_ptr == host_ptr_conv) {
37687ca797SRichard Henderson return;
38687ca797SRichard Henderson }
39360f0abdSRichard Henderson if (len > 0) {
4031c04834SRichard Henderson memcpy(host_ptr_conv, host_ptr, len);
41687ca797SRichard Henderson }
42687ca797SRichard Henderson g_free(host_ptr);
43687ca797SRichard Henderson }
44687ca797SRichard Henderson #endif
45687ca797SRichard Henderson
lock_user_string(abi_ulong guest_addr)46687ca797SRichard Henderson void *lock_user_string(abi_ulong guest_addr)
47687ca797SRichard Henderson {
4809f679b6SRichard Henderson ssize_t len = target_strlen(guest_addr);
49687ca797SRichard Henderson if (len < 0) {
50687ca797SRichard Henderson return NULL;
51687ca797SRichard Henderson }
52360f0abdSRichard Henderson return lock_user(VERIFY_READ, guest_addr, len + 1, 1);
53687ca797SRichard Henderson }
54687ca797SRichard Henderson
55579a97f7Sbellard /* copy_from_user() and copy_to_user() are usually used to copy data
56579a97f7Sbellard * buffers between the target and host. These internally perform
57579a97f7Sbellard * locking/unlocking of the memory.
58579a97f7Sbellard */
copy_from_user(void * hptr,abi_ulong gaddr,ssize_t len)59360f0abdSRichard Henderson int copy_from_user(void *hptr, abi_ulong gaddr, ssize_t len)
60579a97f7Sbellard {
6109f679b6SRichard Henderson int ret = 0;
6209f679b6SRichard Henderson void *ghptr = lock_user(VERIFY_READ, gaddr, len, 1);
63579a97f7Sbellard
6409f679b6SRichard Henderson if (ghptr) {
65579a97f7Sbellard memcpy(hptr, ghptr, len);
66579a97f7Sbellard unlock_user(ghptr, gaddr, 0);
6709f679b6SRichard Henderson } else {
68579a97f7Sbellard ret = -TARGET_EFAULT;
6909f679b6SRichard Henderson }
70579a97f7Sbellard return ret;
71579a97f7Sbellard }
72579a97f7Sbellard
copy_to_user(abi_ulong gaddr,void * hptr,ssize_t len)73360f0abdSRichard Henderson int copy_to_user(abi_ulong gaddr, void *hptr, ssize_t len)
74579a97f7Sbellard {
7509f679b6SRichard Henderson int ret = 0;
7609f679b6SRichard Henderson void *ghptr = lock_user(VERIFY_WRITE, gaddr, len, 0);
77579a97f7Sbellard
7809f679b6SRichard Henderson if (ghptr) {
79579a97f7Sbellard memcpy(ghptr, hptr, len);
80579a97f7Sbellard unlock_user(ghptr, gaddr, len);
8109f679b6SRichard Henderson } else {
82579a97f7Sbellard ret = -TARGET_EFAULT;
8309f679b6SRichard Henderson }
84579a97f7Sbellard
85579a97f7Sbellard return ret;
86579a97f7Sbellard }
87579a97f7Sbellard
883dd98412Sbellard /* Return the length of a string in target memory or -TARGET_EFAULT if
893dd98412Sbellard access error */
target_strlen(abi_ulong guest_addr1)9009f679b6SRichard Henderson ssize_t target_strlen(abi_ulong guest_addr1)
913dd98412Sbellard {
923dd98412Sbellard uint8_t *ptr;
933dd98412Sbellard abi_ulong guest_addr;
9409f679b6SRichard Henderson size_t max_len, len;
953dd98412Sbellard
963dd98412Sbellard guest_addr = guest_addr1;
973dd98412Sbellard for(;;) {
983dd98412Sbellard max_len = TARGET_PAGE_SIZE - (guest_addr & ~TARGET_PAGE_MASK);
993dd98412Sbellard ptr = lock_user(VERIFY_READ, guest_addr, max_len, 1);
1003dd98412Sbellard if (!ptr)
1013dd98412Sbellard return -TARGET_EFAULT;
102b55266b5Sblueswir1 len = qemu_strnlen((const char *)ptr, max_len);
1033dd98412Sbellard unlock_user(ptr, guest_addr, 0);
1043dd98412Sbellard guest_addr += len;
1053dd98412Sbellard /* we don't allow wrapping or integer overflow */
10609f679b6SRichard Henderson if (guest_addr == 0 || (guest_addr - guest_addr1) > 0x7fffffff) {
1073dd98412Sbellard return -TARGET_EFAULT;
10809f679b6SRichard Henderson }
10909f679b6SRichard Henderson if (len != max_len) {
1103dd98412Sbellard break;
1113dd98412Sbellard }
11209f679b6SRichard Henderson }
1133dd98412Sbellard return guest_addr - guest_addr1;
114579a97f7Sbellard }
115