Blame view

block/scsi_ioctl.c 19.8 KB
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
  /*
   * Copyright (C) 2001 Jens Axboe <axboe@suse.de>
   *
   * This program is free software; you can redistribute it and/or modify
   * it under the terms of the GNU General Public License version 2 as
   * published by the Free Software Foundation.
   *
   * This program is distributed in the hope that it will be useful,
   * but WITHOUT ANY WARRANTY; without even the implied warranty of
   *
   * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
   * GNU General Public License for more details.
   *
   * You should have received a copy of the GNU General Public Licens
   * along with this program; if not, write to the Free Software
   * Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA  02111-
   *
   */
  #include <linux/kernel.h>
  #include <linux/errno.h>
  #include <linux/string.h>
  #include <linux/module.h>
  #include <linux/blkdev.h>
c59ede7b7   Randy.Dunlap   [PATCH] move capa...
24
  #include <linux/capability.h>
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
25
26
  #include <linux/completion.h>
  #include <linux/cdrom.h>
0bfc96cb7   Paolo Bonzini   block: fail SCSI ...
27
  #include <linux/ratelimit.h>
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
28
29
  #include <linux/slab.h>
  #include <linux/times.h>
a27bb332c   Kent Overstreet   aio: don't includ...
30
  #include <linux/uio.h>
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
31
32
33
34
35
  #include <asm/uaccess.h>
  
  #include <scsi/scsi.h>
  #include <scsi/scsi_ioctl.h>
  #include <scsi/scsi_cmnd.h>
018e04468   Jens Axboe   block: get rid of...
36
37
38
  struct blk_cmd_filter {
  	unsigned long read_ok[BLK_SCSI_CMD_PER_LONG];
  	unsigned long write_ok[BLK_SCSI_CMD_PER_LONG];
476d42f13   H Hartley Sweeten   block/scsi_ioctl....
39
40
41
  };
  
  static struct blk_cmd_filter blk_default_cmd_filter;
018e04468   Jens Axboe   block: get rid of...
42

1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
43
  /* Command group 3 is reserved and should never be used.  */
db4742dd8   Boaz Harrosh   [SCSI] add suppor...
44
  const unsigned char scsi_command_size_tbl[8] =
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
45
46
47
48
  {
  	6, 10, 10, 12,
  	16, 12, 10, 10
  };
db4742dd8   Boaz Harrosh   [SCSI] add suppor...
49
  EXPORT_SYMBOL(scsi_command_size_tbl);
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
50

1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
51
52
53
54
  #include <scsi/sg.h>
  
  static int sg_get_version(int __user *p)
  {
64100099e   Arjan van de Ven   [BLOCK] mark some...
55
  	static const int sg_version_num = 30527;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
56
57
  	return put_user(sg_version_num, p);
  }
165125e1e   Jens Axboe   [BLOCK] Get rid o...
58
  static int scsi_get_idlun(struct request_queue *q, int __user *p)
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
59
60
61
  {
  	return put_user(0, p);
  }
165125e1e   Jens Axboe   [BLOCK] Get rid o...
62
  static int scsi_get_bus(struct request_queue *q, int __user *p)
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
63
64
65
  {
  	return put_user(0, p);
  }
165125e1e   Jens Axboe   [BLOCK] Get rid o...
66
  static int sg_get_timeout(struct request_queue *q)
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
67
  {
2b91bafcc   Milton Miller   scsi-ioctl: use c...
68
  	return jiffies_to_clock_t(q->sg_timeout);
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
69
  }
165125e1e   Jens Axboe   [BLOCK] Get rid o...
70
  static int sg_set_timeout(struct request_queue *q, int __user *p)
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
71
72
73
74
  {
  	int timeout, err = get_user(timeout, p);
  
  	if (!err)
2b91bafcc   Milton Miller   scsi-ioctl: use c...
75
  		q->sg_timeout = clock_t_to_jiffies(timeout);
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
76
77
78
  
  	return err;
  }
9b4231bf9   Akinobu Mita   block: fix SG_[GS...
79
80
81
82
83
84
85
86
  static int max_sectors_bytes(struct request_queue *q)
  {
  	unsigned int max_sectors = queue_max_sectors(q);
  
  	max_sectors = min_t(unsigned int, max_sectors, INT_MAX >> 9);
  
  	return max_sectors << 9;
  }
165125e1e   Jens Axboe   [BLOCK] Get rid o...
87
  static int sg_get_reserved_size(struct request_queue *q, int __user *p)
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
88
  {
9b4231bf9   Akinobu Mita   block: fix SG_[GS...
89
  	int val = min_t(int, q->sg_reserved_size, max_sectors_bytes(q));
44ec95425   Alan Stern   [SCSI] sg: cap re...
90
91
  
  	return put_user(val, p);
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
92
  }
165125e1e   Jens Axboe   [BLOCK] Get rid o...
93
  static int sg_set_reserved_size(struct request_queue *q, int __user *p)
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
94
95
96
97
98
99
100
101
  {
  	int size, err = get_user(size, p);
  
  	if (err)
  		return err;
  
  	if (size < 0)
  		return -EINVAL;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
102

9b4231bf9   Akinobu Mita   block: fix SG_[GS...
103
  	q->sg_reserved_size = min(size, max_sectors_bytes(q));
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
104
105
106
107
108
109
110
  	return 0;
  }
  
  /*
   * will always return that we are ATAPI even for a real SCSI drive, I'm not
   * so sure this is worth doing anything about (why would you care??)
   */
165125e1e   Jens Axboe   [BLOCK] Get rid o...
111
  static int sg_emulated_host(struct request_queue *q, int __user *p)
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
112
113
114
  {
  	return put_user(1, p);
  }
018e04468   Jens Axboe   block: get rid of...
115
  static void blk_set_cmd_filter_defaults(struct blk_cmd_filter *filter)
abf543937   FUJITA Tomonori   block: move cmdfi...
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
  {
  	/* Basic read-only commands */
  	__set_bit(TEST_UNIT_READY, filter->read_ok);
  	__set_bit(REQUEST_SENSE, filter->read_ok);
  	__set_bit(READ_6, filter->read_ok);
  	__set_bit(READ_10, filter->read_ok);
  	__set_bit(READ_12, filter->read_ok);
  	__set_bit(READ_16, filter->read_ok);
  	__set_bit(READ_BUFFER, filter->read_ok);
  	__set_bit(READ_DEFECT_DATA, filter->read_ok);
  	__set_bit(READ_CAPACITY, filter->read_ok);
  	__set_bit(READ_LONG, filter->read_ok);
  	__set_bit(INQUIRY, filter->read_ok);
  	__set_bit(MODE_SENSE, filter->read_ok);
  	__set_bit(MODE_SENSE_10, filter->read_ok);
  	__set_bit(LOG_SENSE, filter->read_ok);
  	__set_bit(START_STOP, filter->read_ok);
  	__set_bit(GPCMD_VERIFY_10, filter->read_ok);
  	__set_bit(VERIFY_16, filter->read_ok);
  	__set_bit(REPORT_LUNS, filter->read_ok);
eb846d9f1   Hannes Reinecke   scsi: rename SERV...
136
  	__set_bit(SERVICE_ACTION_IN_16, filter->read_ok);
abf543937   FUJITA Tomonori   block: move cmdfi...
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
  	__set_bit(RECEIVE_DIAGNOSTIC, filter->read_ok);
  	__set_bit(MAINTENANCE_IN, filter->read_ok);
  	__set_bit(GPCMD_READ_BUFFER_CAPACITY, filter->read_ok);
  
  	/* Audio CD commands */
  	__set_bit(GPCMD_PLAY_CD, filter->read_ok);
  	__set_bit(GPCMD_PLAY_AUDIO_10, filter->read_ok);
  	__set_bit(GPCMD_PLAY_AUDIO_MSF, filter->read_ok);
  	__set_bit(GPCMD_PLAY_AUDIO_TI, filter->read_ok);
  	__set_bit(GPCMD_PAUSE_RESUME, filter->read_ok);
  
  	/* CD/DVD data reading */
  	__set_bit(GPCMD_READ_CD, filter->read_ok);
  	__set_bit(GPCMD_READ_CD_MSF, filter->read_ok);
  	__set_bit(GPCMD_READ_DISC_INFO, filter->read_ok);
  	__set_bit(GPCMD_READ_CDVD_CAPACITY, filter->read_ok);
  	__set_bit(GPCMD_READ_DVD_STRUCTURE, filter->read_ok);
  	__set_bit(GPCMD_READ_HEADER, filter->read_ok);
  	__set_bit(GPCMD_READ_TRACK_RZONE_INFO, filter->read_ok);
  	__set_bit(GPCMD_READ_SUBCHANNEL, filter->read_ok);
  	__set_bit(GPCMD_READ_TOC_PMA_ATIP, filter->read_ok);
  	__set_bit(GPCMD_REPORT_KEY, filter->read_ok);
  	__set_bit(GPCMD_SCAN, filter->read_ok);
  	__set_bit(GPCMD_GET_CONFIGURATION, filter->read_ok);
  	__set_bit(GPCMD_READ_FORMAT_CAPACITIES, filter->read_ok);
  	__set_bit(GPCMD_GET_EVENT_STATUS_NOTIFICATION, filter->read_ok);
  	__set_bit(GPCMD_GET_PERFORMANCE, filter->read_ok);
  	__set_bit(GPCMD_SEEK, filter->read_ok);
  	__set_bit(GPCMD_STOP_PLAY_SCAN, filter->read_ok);
  
  	/* Basic writing commands */
  	__set_bit(WRITE_6, filter->write_ok);
  	__set_bit(WRITE_10, filter->write_ok);
  	__set_bit(WRITE_VERIFY, filter->write_ok);
  	__set_bit(WRITE_12, filter->write_ok);
  	__set_bit(WRITE_VERIFY_12, filter->write_ok);
  	__set_bit(WRITE_16, filter->write_ok);
  	__set_bit(WRITE_LONG, filter->write_ok);
  	__set_bit(WRITE_LONG_2, filter->write_ok);
  	__set_bit(ERASE, filter->write_ok);
  	__set_bit(GPCMD_MODE_SELECT_10, filter->write_ok);
  	__set_bit(MODE_SELECT, filter->write_ok);
  	__set_bit(LOG_SELECT, filter->write_ok);
  	__set_bit(GPCMD_BLANK, filter->write_ok);
  	__set_bit(GPCMD_CLOSE_TRACK, filter->write_ok);
  	__set_bit(GPCMD_FLUSH_CACHE, filter->write_ok);
  	__set_bit(GPCMD_FORMAT_UNIT, filter->write_ok);
  	__set_bit(GPCMD_REPAIR_RZONE_TRACK, filter->write_ok);
  	__set_bit(GPCMD_RESERVE_RZONE_TRACK, filter->write_ok);
  	__set_bit(GPCMD_SEND_DVD_STRUCTURE, filter->write_ok);
  	__set_bit(GPCMD_SEND_EVENT, filter->write_ok);
  	__set_bit(GPCMD_SEND_KEY, filter->write_ok);
  	__set_bit(GPCMD_SEND_OPC, filter->write_ok);
  	__set_bit(GPCMD_SEND_CUE_SHEET, filter->write_ok);
  	__set_bit(GPCMD_SET_SPEED, filter->write_ok);
  	__set_bit(GPCMD_PREVENT_ALLOW_MEDIUM_REMOVAL, filter->write_ok);
  	__set_bit(GPCMD_LOAD_UNLOAD, filter->write_ok);
  	__set_bit(GPCMD_SET_STREAMING, filter->write_ok);
35e396cd1   xiphmont@xiph.org   SG_IO block filte...
195
  	__set_bit(GPCMD_SET_READ_AHEAD, filter->write_ok);
abf543937   FUJITA Tomonori   block: move cmdfi...
196
  }
018e04468   Jens Axboe   block: get rid of...
197
198
199
200
201
202
203
204
  
  int blk_verify_command(unsigned char *cmd, fmode_t has_write_perm)
  {
  	struct blk_cmd_filter *filter = &blk_default_cmd_filter;
  
  	/* root can do any command. */
  	if (capable(CAP_SYS_RAWIO))
  		return 0;
018e04468   Jens Axboe   block: get rid of...
205
206
207
208
209
210
211
212
213
214
215
  	/* Anybody who can open the device can do a read-safe command */
  	if (test_bit(cmd[0], filter->read_ok))
  		return 0;
  
  	/* Write-safe commands require a writable open */
  	if (test_bit(cmd[0], filter->write_ok) && has_write_perm)
  		return 0;
  
  	return -EPERM;
  }
  EXPORT_SYMBOL(blk_verify_command);
abf543937   FUJITA Tomonori   block: move cmdfi...
216

165125e1e   Jens Axboe   [BLOCK] Get rid o...
217
  static int blk_fill_sghdr_rq(struct request_queue *q, struct request *rq,
5842e51ff   Al Viro   [PATCH] pass mode...
218
  			     struct sg_io_hdr *hdr, fmode_t mode)
3d6392cfb   Jens Axboe   bsg: support for ...
219
  {
3d6392cfb   Jens Axboe   bsg: support for ...
220
221
  	if (copy_from_user(rq->cmd, hdr->cmdp, hdr->cmd_len))
  		return -EFAULT;
018e04468   Jens Axboe   block: get rid of...
222
  	if (blk_verify_command(rq->cmd, mode & FMODE_WRITE))
3d6392cfb   Jens Axboe   bsg: support for ...
223
224
225
226
227
228
  		return -EPERM;
  
  	/*
  	 * fill in request structure
  	 */
  	rq->cmd_len = hdr->cmd_len;
3d6392cfb   Jens Axboe   bsg: support for ...
229

24bb8fb99   Tejun Heo   block: use jiffie...
230
  	rq->timeout = msecs_to_jiffies(hdr->timeout);
3d6392cfb   Jens Axboe   bsg: support for ...
231
232
233
234
  	if (!rq->timeout)
  		rq->timeout = q->sg_timeout;
  	if (!rq->timeout)
  		rq->timeout = BLK_DEFAULT_SG_TIMEOUT;
f2f1fa78a   Linus Torvalds   Enforce a minimum...
235
236
  	if (rq->timeout < BLK_MIN_SG_TIMEOUT)
  		rq->timeout = BLK_MIN_SG_TIMEOUT;
3d6392cfb   Jens Axboe   bsg: support for ...
237
238
239
  
  	return 0;
  }
3d6392cfb   Jens Axboe   bsg: support for ...
240

a63bbaecb   Richard Zhu   MLK-11444 ata: im...
241
242
243
244
245
  #ifdef CONFIG_AHCI_IMX
  extern void *sg_io_buffer_hack;
  #else
  #define sg_io_buffer_hack NULL
  #endif
41e1703b9   FUJITA Tomonori   [SCSI] bsg: unexp...
246
247
  static int blk_complete_sghdr_rq(struct request *rq, struct sg_io_hdr *hdr,
  				 struct bio *bio)
3d6392cfb   Jens Axboe   bsg: support for ...
248
  {
91e463c8f   FUJITA Tomonori   block: fix SG_IO ...
249
  	int r, ret = 0;
3d6392cfb   Jens Axboe   bsg: support for ...
250
251
252
253
254
255
256
257
258
259
260
261
  
  	/*
  	 * fill in all the output members
  	 */
  	hdr->status = rq->errors & 0xff;
  	hdr->masked_status = status_byte(rq->errors);
  	hdr->msg_status = msg_byte(rq->errors);
  	hdr->host_status = host_byte(rq->errors);
  	hdr->driver_status = driver_byte(rq->errors);
  	hdr->info = 0;
  	if (hdr->masked_status || hdr->host_status || hdr->driver_status)
  		hdr->info |= SG_INFO_CHECK;
c3a4d78c5   Tejun Heo   block: add rq->re...
262
  	hdr->resid = rq->resid_len;
3d6392cfb   Jens Axboe   bsg: support for ...
263
264
265
266
267
268
269
270
271
272
  	hdr->sb_len_wr = 0;
  
  	if (rq->sense_len && hdr->sbp) {
  		int len = min((unsigned int) hdr->mx_sb_len, rq->sense_len);
  
  		if (!copy_to_user(hdr->sbp, rq->sense, len))
  			hdr->sb_len_wr = len;
  		else
  			ret = -EFAULT;
  	}
a63bbaecb   Richard Zhu   MLK-11444 ata: im...
273
274
275
276
277
  	if (sg_io_buffer_hack && !hdr->iovec_count)
  		r = copy_to_user(hdr->dxferp, sg_io_buffer_hack,
  				hdr->dxfer_len);
  	else
  		r = blk_rq_unmap_user(bio);
91e463c8f   FUJITA Tomonori   block: fix SG_IO ...
278
279
  	if (!ret)
  		ret = r;
3d6392cfb   Jens Axboe   bsg: support for ...
280

1cd96c242   Boaz Harrosh   block: WARN in __...
281
  	return ret;
3d6392cfb   Jens Axboe   bsg: support for ...
282
  }
3d6392cfb   Jens Axboe   bsg: support for ...
283

5842e51ff   Al Viro   [PATCH] pass mode...
284
285
  static int sg_io(struct request_queue *q, struct gendisk *bd_disk,
  		struct sg_io_hdr *hdr, fmode_t mode)
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
286
  {
3d6392cfb   Jens Axboe   bsg: support for ...
287
  	unsigned long start_time;
e0ce0eacb   Kent Overstreet   block: Use rw_cop...
288
289
  	ssize_t ret = 0;
  	int writing = 0;
d15156138   Douglas Gilbert   block SG_IO: add ...
290
  	int at_head = 0;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
291
  	struct request *rq;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
292
  	char sense[SCSI_SENSE_BUFFERSIZE];
77d172ce2   FUJITA Tomonori   [PATCH] fix SG_IO...
293
  	struct bio *bio;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
294
295
296
  
  	if (hdr->interface_id != 'S')
  		return -EINVAL;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
297

ae03bf639   Martin K. Petersen   block: Use access...
298
  	if (hdr->dxfer_len > (queue_max_hw_sectors(q) << 9))
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
299
  		return -EIO;
a63bbaecb   Richard Zhu   MLK-11444 ata: im...
300
301
  	if (sg_io_buffer_hack && hdr->dxfer_len > 0x10000)
  		return -EIO;
f1970baf6   James Bottomley   [PATCH] Add scatt...
302
  	if (hdr->dxfer_len)
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
303
304
305
  		switch (hdr->dxfer_direction) {
  		default:
  			return -EINVAL;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
306
307
308
  		case SG_DXFER_TO_DEV:
  			writing = 1;
  			break;
616e8a091   Jens Axboe   [PATCH] Fix bad d...
309
  		case SG_DXFER_TO_FROM_DEV:
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
310
  		case SG_DXFER_FROM_DEV:
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
311
312
  			break;
  		}
d15156138   Douglas Gilbert   block SG_IO: add ...
313
314
  	if (hdr->flags & SG_FLAG_Q_AT_HEAD)
  		at_head = 1;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
315

a57821cac   Christoph Hellwig   block: support > ...
316
  	ret = -ENOMEM;
dd1cab95f   Jens Axboe   [PATCH] Cleanup b...
317
  	rq = blk_get_request(q, writing ? WRITE : READ, GFP_KERNEL);
a492f0754   Joe Lawrence   block,scsi: fixup...
318
319
  	if (IS_ERR(rq))
  		return PTR_ERR(rq);
f27b087b8   Jens Axboe   block: add blk_rq...
320
  	blk_rq_set_block_pc(rq);
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
321

a57821cac   Christoph Hellwig   block: support > ...
322
323
324
325
  	if (hdr->cmd_len > BLK_MAX_CDB) {
  		rq->cmd = kzalloc(hdr->cmd_len, GFP_KERNEL);
  		if (!rq->cmd)
  			goto out_put_request;
3d6392cfb   Jens Axboe   bsg: support for ...
326
  	}
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
327

2c4cffe85   Paolo Bonzini   block: fix bogus ...
328
329
  	ret = blk_fill_sghdr_rq(q, rq, hdr, mode);
  	if (ret < 0)
a57821cac   Christoph Hellwig   block: support > ...
330
  		goto out_free_cdb;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
331

d19d74468   Sabrina Dubroca   block: fix error ...
332
  	ret = 0;
0e75f9063   Mike Christie   [PATCH] block: su...
333
  	if (hdr->iovec_count) {
26e49cfc7   Kent Overstreet   block: pass iov_i...
334
  		struct iov_iter i;
17a05cca9   Christian Engelmayer   block: Fix memory...
335
  		struct iovec *iov = NULL;
0e75f9063   Mike Christie   [PATCH] block: su...
336

e272b89ff   Al Viro   sg_io(): use impo...
337
338
339
340
  		ret = import_iovec(rq_data_dir(rq),
  				   hdr->dxferp, hdr->iovec_count,
  				   0, &iov, &i);
  		if (ret < 0)
a57821cac   Christoph Hellwig   block: support > ...
341
  			goto out_free_cdb;
0e75f9063   Mike Christie   [PATCH] block: su...
342

25636e282   Tejun Heo   block: fix SG_IO ...
343
  		/* SG_IO howto says that the shorter of the two wins */
e272b89ff   Al Viro   sg_io(): use impo...
344
  		iov_iter_truncate(&i, hdr->dxfer_len);
25636e282   Tejun Heo   block: fix SG_IO ...
345

26e49cfc7   Kent Overstreet   block: pass iov_i...
346
  		ret = blk_rq_map_user_iov(q, rq, NULL, &i, GFP_KERNEL);
e0ce0eacb   Kent Overstreet   block: Use rw_cop...
347
  		kfree(iov);
a63bbaecb   Richard Zhu   MLK-11444 ata: im...
348
349
350
351
352
353
354
355
  	} else if (hdr->dxfer_len) {
  		if (sg_io_buffer_hack)
  			ret = blk_rq_map_kern(q, rq, sg_io_buffer_hack,
  					hdr->dxfer_len, GFP_KERNEL);
  		else
  			ret = blk_rq_map_user(q, rq, NULL, hdr->dxferp,
  					hdr->dxfer_len, GFP_KERNEL);
  	}
0e75f9063   Mike Christie   [PATCH] block: su...
356
357
  
  	if (ret)
a57821cac   Christoph Hellwig   block: support > ...
358
  		goto out_free_cdb;
0e75f9063   Mike Christie   [PATCH] block: su...
359

77d172ce2   FUJITA Tomonori   [PATCH] fix SG_IO...
360
  	bio = rq->bio;
3d6392cfb   Jens Axboe   bsg: support for ...
361
362
363
  	memset(sense, 0, sizeof(sense));
  	rq->sense = sense;
  	rq->sense_len = 0;
01840f9c9   Jens Axboe   [PATCH] blk: Fix ...
364
  	rq->retries = 0;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
365
366
367
368
369
370
  	start_time = jiffies;
  
  	/* ignore return value. All information is passed back to caller
  	 * (if he doesn't check that is his problem).
  	 * N.B. a non-zero SCSI status is _not_ necessarily an error.
  	 */
d15156138   Douglas Gilbert   block SG_IO: add ...
371
  	blk_execute_rq(q, bd_disk, rq, at_head);
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
372

24bb8fb99   Tejun Heo   block: use jiffie...
373
  	hdr->duration = jiffies_to_msecs(jiffies - start_time);
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
374

2cada584b   Christoph Hellwig   block: cleanup er...
375
  	ret = blk_complete_sghdr_rq(rq, hdr, bio);
a57821cac   Christoph Hellwig   block: support > ...
376
377
378
379
380
  
  out_free_cdb:
  	if (rq->cmd != rq->__cmd)
  		kfree(rq->cmd);
  out_put_request:
dd1cab95f   Jens Axboe   [PATCH] Cleanup b...
381
382
  	blk_put_request(rq);
  	return ret;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
383
  }
21b2f0c80   Christoph Hellwig   [SCSI] unify SCSI...
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
  /**
   * sg_scsi_ioctl  --  handle deprecated SCSI_IOCTL_SEND_COMMAND ioctl
   * @file:	file this ioctl operates on (optional)
   * @q:		request queue to send scsi commands down
   * @disk:	gendisk to operate on (option)
   * @sic:	userspace structure describing the command to perform
   *
   * Send down the scsi command described by @sic to the device below
   * the request queue @q.  If @file is non-NULL it's used to perform
   * fine-grained permission checks that allow users to send down
   * non-destructive SCSI commands.  If the caller has a struct gendisk
   * available it should be passed in as @disk to allow the low level
   * driver to use the information contained in it.  A non-NULL @disk
   * is only allowed if the caller knows that the low level driver doesn't
   * need it (e.g. in the scsi subsystem).
   *
   * Notes:
   *   -  This interface is deprecated - users should use the SG_IO
   *      interface instead, as this is a more flexible approach to
   *      performing SCSI commands on a device.
   *   -  The SCSI command length is determined by examining the 1st byte
   *      of the given command. There is no way to override this.
   *   -  Data transfers are limited to PAGE_SIZE
   *   -  The length (x + y) must be at least OMAX_SB_LEN bytes long to
   *      accommodate the sense buffer when an error occurs.
   *      The sense buffer is truncated to OMAX_SB_LEN (16) bytes so that
   *      old code will not be surprised.
   *   -  If a Unix error occurs (e.g. ENOMEM) then the user will receive
   *      a negative return and the Unix error code in 'errno'.
   *      If the SCSI command succeeds then 0 is returned.
   *      Positive numbers returned are the compacted SCSI error codes (4
   *      bytes in one int) where the lowest byte is the SCSI status.
   */
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
417
  #define OMAX_SB_LEN 16          /* For backward compatibility */
e915e872e   Al Viro   [PATCH] switch sg...
418
419
  int sg_scsi_ioctl(struct request_queue *q, struct gendisk *disk, fmode_t mode,
  		struct scsi_ioctl_command __user *sic)
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
420
421
  {
  	struct request *rq;
aeb5d7270   Al Viro   [PATCH] introduce...
422
  	int err;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
423
424
  	unsigned int in_len, out_len, bytes, opcode, cmdlen;
  	char *buffer = NULL, sense[SCSI_SENSE_BUFFERSIZE];
21b2f0c80   Christoph Hellwig   [SCSI] unify SCSI...
425
426
  	if (!sic)
  		return -EINVAL;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
427
428
429
430
431
432
433
434
435
436
437
438
439
440
  	/*
  	 * get in an out lengths, verify they don't exceed a page worth of data
  	 */
  	if (get_user(in_len, &sic->inlen))
  		return -EFAULT;
  	if (get_user(out_len, &sic->outlen))
  		return -EFAULT;
  	if (in_len > PAGE_SIZE || out_len > PAGE_SIZE)
  		return -EINVAL;
  	if (get_user(opcode, sic->data))
  		return -EFAULT;
  
  	bytes = max(in_len, out_len);
  	if (bytes) {
dd00cc486   Yoann Padioleau   some kmalloc/mems...
441
  		buffer = kzalloc(bytes, q->bounce_gfp | GFP_USER| __GFP_NOWARN);
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
442
443
  		if (!buffer)
  			return -ENOMEM;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
444
  	}
71baba4b9   Mel Gorman   mm, page_alloc: r...
445
  	rq = blk_get_request(q, in_len ? WRITE : READ, __GFP_RECLAIM);
a492f0754   Joe Lawrence   block,scsi: fixup...
446
447
  	if (IS_ERR(rq)) {
  		err = PTR_ERR(rq);
92697dc94   Tony Battersby   scsi: Fix more er...
448
  		goto error_free_buffer;
eb571eead   Joe Lawrence   block,scsi: verif...
449
  	}
2ba136daa   Tony Battersby   fix regression in...
450
  	blk_rq_set_block_pc(rq);
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
451
452
453
454
455
456
457
458
459
460
  
  	cmdlen = COMMAND_SIZE(opcode);
  
  	/*
  	 * get command and data to send to device, if any
  	 */
  	err = -EFAULT;
  	rq->cmd_len = cmdlen;
  	if (copy_from_user(rq->cmd, sic->data, cmdlen))
  		goto error;
21b2f0c80   Christoph Hellwig   [SCSI] unify SCSI...
461
  	if (in_len && copy_from_user(buffer, sic->data + cmdlen, in_len))
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
462
  		goto error;
018e04468   Jens Axboe   block: get rid of...
463
  	err = blk_verify_command(rq->cmd, mode & FMODE_WRITE);
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
464
465
  	if (err)
  		goto error;
21b2f0c80   Christoph Hellwig   [SCSI] unify SCSI...
466
467
  	/* default.  possible overriden later */
  	rq->retries = 5;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
468
  	switch (opcode) {
21b2f0c80   Christoph Hellwig   [SCSI] unify SCSI...
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
  	case SEND_DIAGNOSTIC:
  	case FORMAT_UNIT:
  		rq->timeout = FORMAT_UNIT_TIMEOUT;
  		rq->retries = 1;
  		break;
  	case START_STOP:
  		rq->timeout = START_STOP_TIMEOUT;
  		break;
  	case MOVE_MEDIUM:
  		rq->timeout = MOVE_MEDIUM_TIMEOUT;
  		break;
  	case READ_ELEMENT_STATUS:
  		rq->timeout = READ_ELEMENT_STATUS_TIMEOUT;
  		break;
  	case READ_DEFECT_DATA:
  		rq->timeout = READ_DEFECT_DATA_TIMEOUT;
  		rq->retries = 1;
  		break;
  	default:
3d6392cfb   Jens Axboe   bsg: support for ...
488
  		rq->timeout = BLK_DEFAULT_SG_TIMEOUT;
21b2f0c80   Christoph Hellwig   [SCSI] unify SCSI...
489
490
  		break;
  	}
71baba4b9   Mel Gorman   mm, page_alloc: r...
491
  	if (bytes && blk_rq_map_kern(q, rq, buffer, bytes, __GFP_RECLAIM)) {
21b2f0c80   Christoph Hellwig   [SCSI] unify SCSI...
492
  		err = DRIVER_ERROR << 24;
84ce0f0e9   Jan Kara   scsi: Fix error h...
493
  		goto error;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
494
495
496
497
498
  	}
  
  	memset(sense, 0, sizeof(sense));
  	rq->sense = sense;
  	rq->sense_len = 0;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
499

21b2f0c80   Christoph Hellwig   [SCSI] unify SCSI...
500
  	blk_execute_rq(q, disk, rq, 0);
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
501
502
503
504
505
506
507
508
509
510
511
512
513
514
  	err = rq->errors & 0xff;	/* only 8 bit SCSI status */
  	if (err) {
  		if (rq->sense_len && rq->sense) {
  			bytes = (OMAX_SB_LEN > rq->sense_len) ?
  				rq->sense_len : OMAX_SB_LEN;
  			if (copy_to_user(sic->data, rq->sense, bytes))
  				err = -EFAULT;
  		}
  	} else {
  		if (copy_to_user(sic->data, buffer, out_len))
  			err = -EFAULT;
  	}
  	
  error:
92697dc94   Tony Battersby   scsi: Fix more er...
515
516
517
  	blk_put_request(rq);
  
  error_free_buffer:
eb571eead   Joe Lawrence   block,scsi: verif...
518
  	kfree(buffer);
92697dc94   Tony Battersby   scsi: Fix more er...
519

1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
520
521
  	return err;
  }
21b2f0c80   Christoph Hellwig   [SCSI] unify SCSI...
522
  EXPORT_SYMBOL_GPL(sg_scsi_ioctl);
f98d2dfd0   Ben Collins   [PATCH] block: Cl...
523
524
  
  /* Send basic block requests */
165125e1e   Jens Axboe   [BLOCK] Get rid o...
525
526
  static int __blk_send_generic(struct request_queue *q, struct gendisk *bd_disk,
  			      int cmd, int data)
f98d2dfd0   Ben Collins   [PATCH] block: Cl...
527
528
529
  {
  	struct request *rq;
  	int err;
71baba4b9   Mel Gorman   mm, page_alloc: r...
530
  	rq = blk_get_request(q, WRITE, __GFP_RECLAIM);
a492f0754   Joe Lawrence   block,scsi: fixup...
531
532
  	if (IS_ERR(rq))
  		return PTR_ERR(rq);
f27b087b8   Jens Axboe   block: add blk_rq...
533
  	blk_rq_set_block_pc(rq);
3d6392cfb   Jens Axboe   bsg: support for ...
534
  	rq->timeout = BLK_DEFAULT_SG_TIMEOUT;
f98d2dfd0   Ben Collins   [PATCH] block: Cl...
535
536
537
538
539
540
541
542
  	rq->cmd[0] = cmd;
  	rq->cmd[4] = data;
  	rq->cmd_len = 6;
  	err = blk_execute_rq(q, bd_disk, rq, 0);
  	blk_put_request(rq);
  
  	return err;
  }
165125e1e   Jens Axboe   [BLOCK] Get rid o...
543
544
  static inline int blk_send_start_stop(struct request_queue *q,
  				      struct gendisk *bd_disk, int data)
f98d2dfd0   Ben Collins   [PATCH] block: Cl...
545
546
547
  {
  	return __blk_send_generic(q, bd_disk, GPCMD_START_STOP_UNIT, data);
  }
74f3c8aff   Al Viro   [PATCH] switch sc...
548
549
  int scsi_cmd_ioctl(struct request_queue *q, struct gendisk *bd_disk, fmode_t mode,
  		   unsigned int cmd, void __user *arg)
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
550
  {
f98d2dfd0   Ben Collins   [PATCH] block: Cl...
551
  	int err;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
552

315fceee8   Tejun Heo   block: drop unnec...
553
  	if (!q)
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
554
555
556
557
558
559
560
561
562
563
564
565
566
567
568
569
570
571
572
573
574
575
576
577
578
579
580
581
582
583
584
585
586
587
588
589
  		return -ENXIO;
  
  	switch (cmd) {
  		/*
  		 * new sgv3 interface
  		 */
  		case SG_GET_VERSION_NUM:
  			err = sg_get_version(arg);
  			break;
  		case SCSI_IOCTL_GET_IDLUN:
  			err = scsi_get_idlun(q, arg);
  			break;
  		case SCSI_IOCTL_GET_BUS_NUMBER:
  			err = scsi_get_bus(q, arg);
  			break;
  		case SG_SET_TIMEOUT:
  			err = sg_set_timeout(q, arg);
  			break;
  		case SG_GET_TIMEOUT:
  			err = sg_get_timeout(q);
  			break;
  		case SG_GET_RESERVED_SIZE:
  			err = sg_get_reserved_size(q, arg);
  			break;
  		case SG_SET_RESERVED_SIZE:
  			err = sg_set_reserved_size(q, arg);
  			break;
  		case SG_EMULATED_HOST:
  			err = sg_emulated_host(q, arg);
  			break;
  		case SG_IO: {
  			struct sg_io_hdr hdr;
  
  			err = -EFAULT;
  			if (copy_from_user(&hdr, arg, sizeof(hdr)))
  				break;
74f3c8aff   Al Viro   [PATCH] switch sc...
590
  			err = sg_io(q, bd_disk, &hdr, mode);
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
591
592
593
594
595
596
597
598
599
600
601
602
603
604
605
606
607
608
609
610
611
612
613
614
615
616
617
618
619
620
621
622
623
624
625
626
627
628
629
630
631
632
633
  			if (err == -EFAULT)
  				break;
  
  			if (copy_to_user(arg, &hdr, sizeof(hdr)))
  				err = -EFAULT;
  			break;
  		}
  		case CDROM_SEND_PACKET: {
  			struct cdrom_generic_command cgc;
  			struct sg_io_hdr hdr;
  
  			err = -EFAULT;
  			if (copy_from_user(&cgc, arg, sizeof(cgc)))
  				break;
  			cgc.timeout = clock_t_to_jiffies(cgc.timeout);
  			memset(&hdr, 0, sizeof(hdr));
  			hdr.interface_id = 'S';
  			hdr.cmd_len = sizeof(cgc.cmd);
  			hdr.dxfer_len = cgc.buflen;
  			err = 0;
  			switch (cgc.data_direction) {
  				case CGC_DATA_UNKNOWN:
  					hdr.dxfer_direction = SG_DXFER_UNKNOWN;
  					break;
  				case CGC_DATA_WRITE:
  					hdr.dxfer_direction = SG_DXFER_TO_DEV;
  					break;
  				case CGC_DATA_READ:
  					hdr.dxfer_direction = SG_DXFER_FROM_DEV;
  					break;
  				case CGC_DATA_NONE:
  					hdr.dxfer_direction = SG_DXFER_NONE;
  					break;
  				default:
  					err = -EINVAL;
  			}
  			if (err)
  				break;
  
  			hdr.dxferp = cgc.buffer;
  			hdr.sbp = cgc.sense;
  			if (hdr.sbp)
  				hdr.mx_sb_len = sizeof(struct request_sense);
ad337591f   Tim Wright   [SCSI] block: Fix...
634
  			hdr.timeout = jiffies_to_msecs(cgc.timeout);
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
635
636
  			hdr.cmdp = ((struct cdrom_generic_command __user*) arg)->cmd;
  			hdr.cmd_len = sizeof(cgc.cmd);
74f3c8aff   Al Viro   [PATCH] switch sc...
637
  			err = sg_io(q, bd_disk, &hdr, mode);
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
638
639
640
641
642
643
644
645
646
647
648
649
650
651
652
653
654
655
656
657
658
659
660
  			if (err == -EFAULT)
  				break;
  
  			if (hdr.status)
  				err = -EIO;
  
  			cgc.stat = err;
  			cgc.buflen = hdr.resid;
  			if (copy_to_user(arg, &cgc, sizeof(cgc)))
  				err = -EFAULT;
  
  			break;
  		}
  
  		/*
  		 * old junk scsi send command ioctl
  		 */
  		case SCSI_IOCTL_SEND_COMMAND:
  			printk(KERN_WARNING "program %s is using a deprecated SCSI ioctl, please convert it to SG_IO
  ", current->comm);
  			err = -EINVAL;
  			if (!arg)
  				break;
74f3c8aff   Al Viro   [PATCH] switch sc...
661
  			err = sg_scsi_ioctl(q, bd_disk, mode, arg);
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
662
663
  			break;
  		case CDROMCLOSETRAY:
f98d2dfd0   Ben Collins   [PATCH] block: Cl...
664
665
  			err = blk_send_start_stop(q, bd_disk, 0x03);
  			break;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
666
  		case CDROMEJECT:
f98d2dfd0   Ben Collins   [PATCH] block: Cl...
667
  			err = blk_send_start_stop(q, bd_disk, 0x02);
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
668
669
670
671
  			break;
  		default:
  			err = -ENOTTY;
  	}
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
672
673
  	return err;
  }
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
674
  EXPORT_SYMBOL(scsi_cmd_ioctl);
018e04468   Jens Axboe   block: get rid of...
675

0bfc96cb7   Paolo Bonzini   block: fail SCSI ...
676
677
678
679
680
681
682
683
684
685
686
687
688
689
690
691
692
693
694
695
696
697
698
699
700
701
702
703
704
  int scsi_verify_blk_ioctl(struct block_device *bd, unsigned int cmd)
  {
  	if (bd && bd == bd->bd_contains)
  		return 0;
  
  	/* Actually none of these is particularly useful on a partition,
  	 * but they are safe.
  	 */
  	switch (cmd) {
  	case SCSI_IOCTL_GET_IDLUN:
  	case SCSI_IOCTL_GET_BUS_NUMBER:
  	case SCSI_IOCTL_GET_PCI:
  	case SCSI_IOCTL_PROBE_HOST:
  	case SG_GET_VERSION_NUM:
  	case SG_SET_TIMEOUT:
  	case SG_GET_TIMEOUT:
  	case SG_GET_RESERVED_SIZE:
  	case SG_SET_RESERVED_SIZE:
  	case SG_EMULATED_HOST:
  		return 0;
  	case CDROM_GET_CAPABILITY:
  		/* Keep this until we remove the printk below.  udev sends it
  		 * and we do not want to spam dmesg about it.   CD-ROMs do
  		 * not have partitions, so we get here only for disks.
  		 */
  		return -ENOIOCTLCMD;
  	default:
  		break;
  	}
6d9359280   Jan Kara   scsi: Silence unn...
705
706
  	if (capable(CAP_SYS_RAWIO))
  		return 0;
0bfc96cb7   Paolo Bonzini   block: fail SCSI ...
707
708
709
710
  	/* In particular, rule out all resets and host-specific ioctls.  */
  	printk_ratelimited(KERN_WARNING
  			   "%s: sending ioctl %x to a partition!
  ", current->comm, cmd);
6d9359280   Jan Kara   scsi: Silence unn...
711
  	return -ENOIOCTLCMD;
0bfc96cb7   Paolo Bonzini   block: fail SCSI ...
712
713
  }
  EXPORT_SYMBOL(scsi_verify_blk_ioctl);
577ebb374   Paolo Bonzini   block: add and us...
714
715
716
  int scsi_cmd_blk_ioctl(struct block_device *bd, fmode_t mode,
  		       unsigned int cmd, void __user *arg)
  {
0bfc96cb7   Paolo Bonzini   block: fail SCSI ...
717
718
719
720
721
  	int ret;
  
  	ret = scsi_verify_blk_ioctl(bd, cmd);
  	if (ret < 0)
  		return ret;
577ebb374   Paolo Bonzini   block: add and us...
722
723
724
  	return scsi_cmd_ioctl(bd->bd_disk->queue, bd->bd_disk, mode, cmd, arg);
  }
  EXPORT_SYMBOL(scsi_cmd_blk_ioctl);
476d42f13   H Hartley Sweeten   block/scsi_ioctl....
725
  static int __init blk_scsi_ioctl_init(void)
018e04468   Jens Axboe   block: get rid of...
726
727
728
729
  {
  	blk_set_cmd_filter_defaults(&blk_default_cmd_filter);
  	return 0;
  }
76da03467   FUJITA Tomonori   block: call blk_s...
730
  fs_initcall(blk_scsi_ioctl_init);