blob: 425cbf677f760351a5d70ac3d6fe9f8197c85694 [file] [log] [blame]
bellard579a97f2007-11-11 14:26:47 +00001/* User memory access */
Peter Maydelld39594e2016-01-26 18:17:02 +00002#include "qemu/osdep.h"
Veronia Bahaaf348b6d2016-03-20 19:16:19 +02003#include "qemu/cutils.h"
bellard579a97f2007-11-11 14:26:47 +00004
5#include "qemu.h"
Peter Maydell3b249d22021-09-08 16:44:03 +01006#include "user-internals.h"
bellard579a97f2007-11-11 14:26:47 +00007
Richard Henderson360f0ab2021-03-15 14:40:04 -06008void *lock_user(int type, abi_ulong guest_addr, ssize_t len, bool copy)
Richard Henderson687ca792021-02-12 10:48:48 -08009{
Richard Henderson31c04832021-02-12 10:48:50 -080010 void *host_addr;
11
12 guest_addr = cpu_untagged_addr(thread_cpu, guest_addr);
Richard Henderson687ca792021-02-12 10:48:48 -080013 if (!access_ok_untagged(type, guest_addr, len)) {
14 return NULL;
15 }
Richard Henderson31c04832021-02-12 10:48:50 -080016 host_addr = g2h_untagged(guest_addr);
Richard Henderson687ca792021-02-12 10:48:48 -080017#ifdef DEBUG_REMAP
Richard Henderson31c04832021-02-12 10:48:50 -080018 if (copy) {
19 host_addr = g_memdup(host_addr, len);
20 } else {
21 host_addr = g_malloc0(len);
Richard Henderson687ca792021-02-12 10:48:48 -080022 }
Richard Henderson687ca792021-02-12 10:48:48 -080023#endif
Richard Henderson31c04832021-02-12 10:48:50 -080024 return host_addr;
Richard Henderson687ca792021-02-12 10:48:48 -080025}
26
27#ifdef DEBUG_REMAP
Richard Henderson360f0ab2021-03-15 14:40:04 -060028void unlock_user(void *host_ptr, abi_ulong guest_addr, ssize_t len)
Richard Henderson687ca792021-02-12 10:48:48 -080029{
Richard Henderson31c04832021-02-12 10:48:50 -080030 void *host_ptr_conv;
31
Richard Henderson687ca792021-02-12 10:48:48 -080032 if (!host_ptr) {
33 return;
34 }
Richard Henderson31c04832021-02-12 10:48:50 -080035 host_ptr_conv = g2h(thread_cpu, guest_addr);
36 if (host_ptr == host_ptr_conv) {
Richard Henderson687ca792021-02-12 10:48:48 -080037 return;
38 }
Richard Henderson360f0ab2021-03-15 14:40:04 -060039 if (len > 0) {
Richard Henderson31c04832021-02-12 10:48:50 -080040 memcpy(host_ptr_conv, host_ptr, len);
Richard Henderson687ca792021-02-12 10:48:48 -080041 }
42 g_free(host_ptr);
43}
44#endif
45
46void *lock_user_string(abi_ulong guest_addr)
47{
Richard Henderson09f679b2021-02-12 10:48:49 -080048 ssize_t len = target_strlen(guest_addr);
Richard Henderson687ca792021-02-12 10:48:48 -080049 if (len < 0) {
50 return NULL;
51 }
Richard Henderson360f0ab2021-03-15 14:40:04 -060052 return lock_user(VERIFY_READ, guest_addr, len + 1, 1);
Richard Henderson687ca792021-02-12 10:48:48 -080053}
54
bellard579a97f2007-11-11 14:26:47 +000055/* copy_from_user() and copy_to_user() are usually used to copy data
56 * buffers between the target and host. These internally perform
57 * locking/unlocking of the memory.
58 */
Richard Henderson360f0ab2021-03-15 14:40:04 -060059int copy_from_user(void *hptr, abi_ulong gaddr, ssize_t len)
bellard579a97f2007-11-11 14:26:47 +000060{
Richard Henderson09f679b2021-02-12 10:48:49 -080061 int ret = 0;
62 void *ghptr = lock_user(VERIFY_READ, gaddr, len, 1);
bellard579a97f2007-11-11 14:26:47 +000063
Richard Henderson09f679b2021-02-12 10:48:49 -080064 if (ghptr) {
bellard579a97f2007-11-11 14:26:47 +000065 memcpy(hptr, ghptr, len);
66 unlock_user(ghptr, gaddr, 0);
Richard Henderson09f679b2021-02-12 10:48:49 -080067 } else {
bellard579a97f2007-11-11 14:26:47 +000068 ret = -TARGET_EFAULT;
Richard Henderson09f679b2021-02-12 10:48:49 -080069 }
bellard579a97f2007-11-11 14:26:47 +000070 return ret;
71}
72
Richard Henderson360f0ab2021-03-15 14:40:04 -060073int copy_to_user(abi_ulong gaddr, void *hptr, ssize_t len)
bellard579a97f2007-11-11 14:26:47 +000074{
Richard Henderson09f679b2021-02-12 10:48:49 -080075 int ret = 0;
76 void *ghptr = lock_user(VERIFY_WRITE, gaddr, len, 0);
bellard579a97f2007-11-11 14:26:47 +000077
Richard Henderson09f679b2021-02-12 10:48:49 -080078 if (ghptr) {
bellard579a97f2007-11-11 14:26:47 +000079 memcpy(ghptr, hptr, len);
Paolo Bonzini7d374352018-12-13 23:37:37 +010080 unlock_user(ghptr, gaddr, len);
Richard Henderson09f679b2021-02-12 10:48:49 -080081 } else {
bellard579a97f2007-11-11 14:26:47 +000082 ret = -TARGET_EFAULT;
Richard Henderson09f679b2021-02-12 10:48:49 -080083 }
bellard579a97f2007-11-11 14:26:47 +000084
85 return ret;
86}
87
bellard3dd98412007-11-14 10:17:35 +000088/* Return the length of a string in target memory or -TARGET_EFAULT if
89 access error */
Richard Henderson09f679b2021-02-12 10:48:49 -080090ssize_t target_strlen(abi_ulong guest_addr1)
bellard3dd98412007-11-14 10:17:35 +000091{
92 uint8_t *ptr;
93 abi_ulong guest_addr;
Richard Henderson09f679b2021-02-12 10:48:49 -080094 size_t max_len, len;
bellard3dd98412007-11-14 10:17:35 +000095
96 guest_addr = guest_addr1;
97 for(;;) {
98 max_len = TARGET_PAGE_SIZE - (guest_addr & ~TARGET_PAGE_MASK);
99 ptr = lock_user(VERIFY_READ, guest_addr, max_len, 1);
100 if (!ptr)
101 return -TARGET_EFAULT;
blueswir1b55266b2008-09-20 08:07:15 +0000102 len = qemu_strnlen((const char *)ptr, max_len);
bellard3dd98412007-11-14 10:17:35 +0000103 unlock_user(ptr, guest_addr, 0);
104 guest_addr += len;
105 /* we don't allow wrapping or integer overflow */
Richard Henderson09f679b2021-02-12 10:48:49 -0800106 if (guest_addr == 0 || (guest_addr - guest_addr1) > 0x7fffffff) {
bellard3dd98412007-11-14 10:17:35 +0000107 return -TARGET_EFAULT;
Richard Henderson09f679b2021-02-12 10:48:49 -0800108 }
109 if (len != max_len) {
bellard3dd98412007-11-14 10:17:35 +0000110 break;
Richard Henderson09f679b2021-02-12 10:48:49 -0800111 }
bellard3dd98412007-11-14 10:17:35 +0000112 }
113 return guest_addr - guest_addr1;
bellard579a97f2007-11-11 14:26:47 +0000114}