1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
|
/*
* linux/drivers/video/fb_sys_read.c - Generic file operations where
* framebuffer is in system RAM
*
* Copyright (C) 2007 Antonino Daplas <adaplas@pol.net>
*
* This file is subject to the terms and conditions of the GNU General Public
* License. See the file COPYING in the main directory of this archive
* for more details.
*
*/
#include <linux/export.h>
#include <linux/fb.h>
#include <linux/module.h>
#include <linux/uaccess.h>
ssize_t fb_sys_read(struct fb_info *info, char __user *buf, size_t count,
loff_t *ppos)
{
unsigned long p = *ppos;
void *src;
int err = 0;
unsigned long total_size, c;
ssize_t ret;
if (!(info->flags & FBINFO_VIRTFB))
fb_warn_once(info, "Framebuffer is not in virtual address space.");
if (!info->screen_buffer)
return -ENODEV;
total_size = info->screen_size;
if (total_size == 0)
total_size = info->fix.smem_len;
/*
* Security Hardening: Defend against buggy legacy drivers that may
* calculate a malformed screen_size. Clamp total_size to the actual
* hardware mapped memory limit (smem_len) to prevent OOB access.
*/
if (info->fix.smem_len && total_size > info->fix.smem_len)
total_size = info->fix.smem_len;
if (p >= total_size)
return 0;
if (count >= total_size)
count = total_size;
if (count + p > total_size)
count = total_size - p;
src = info->screen_buffer + p;
if (info->fbops->fb_sync)
info->fbops->fb_sync(info);
c = copy_to_user(buf, src, count);
if (c)
err = -EFAULT;
ret = count - c;
*ppos += ret;
return ret ? ret : err;
}
EXPORT_SYMBOL_GPL(fb_sys_read);
ssize_t fb_sys_write(struct fb_info *info, const char __user *buf,
size_t count, loff_t *ppos)
{
unsigned long p = *ppos;
void *dst;
int err = 0;
unsigned long total_size, c;
size_t ret;
if (!(info->flags & FBINFO_VIRTFB))
fb_warn_once(info, "Framebuffer is not in virtual address space.");
if (!info->screen_buffer)
return -ENODEV;
total_size = info->screen_size;
if (total_size == 0)
total_size = info->fix.smem_len;
/*
* Security Hardening: Defend against buggy legacy drivers that may
* calculate a malformed screen_size. Clamp total_size to the actual
* hardware mapped memory limit (smem_len) to prevent OOB access.
*/
if (info->fix.smem_len && total_size > info->fix.smem_len)
total_size = info->fix.smem_len;
if (p > total_size)
return -EFBIG;
if (count > total_size) {
err = -EFBIG;
count = total_size;
}
if (count + p > total_size) {
if (!err)
err = -ENOSPC;
count = total_size - p;
}
dst = info->screen_buffer + p;
if (info->fbops->fb_sync)
info->fbops->fb_sync(info);
c = copy_from_user(dst, buf, count);
if (c)
err = -EFAULT;
ret = count - c;
*ppos += ret;
return ret ? ret : err;
}
EXPORT_SYMBOL_GPL(fb_sys_write);
MODULE_AUTHOR("Antonino Daplas <adaplas@pol.net>");
MODULE_DESCRIPTION("Generic file read (fb in system RAM)");
MODULE_LICENSE("GPL");
|