[PATCH] USB: fix buffer size limiting in skeleton driver
[deliverable/linux.git] / drivers / usb / usb-skeleton.c
CommitLineData
1da177e4
LT
1/*
2 * USB Skeleton driver - 2.0
3 *
4 * Copyright (C) 2001-2004 Greg Kroah-Hartman (greg@kroah.com)
5 *
6 * This program is free software; you can redistribute it and/or
7 * modify it under the terms of the GNU General Public License as
8 * published by the Free Software Foundation, version 2.
9 *
10 * This driver is based on the 2.6.3 version of drivers/usb/usb-skeleton.c
11 * but has been rewritten to be easy to read and use, as no locks are now
12 * needed anymore.
13 *
14 */
15
16#include <linux/config.h>
17#include <linux/kernel.h>
18#include <linux/errno.h>
19#include <linux/init.h>
20#include <linux/slab.h>
21#include <linux/module.h>
22#include <linux/kref.h>
23#include <asm/uaccess.h>
24#include <linux/usb.h>
25
26
27/* Define these values to match your devices */
28#define USB_SKEL_VENDOR_ID 0xfff0
29#define USB_SKEL_PRODUCT_ID 0xfff0
30
31/* table of devices that work with this driver */
32static struct usb_device_id skel_table [] = {
33 { USB_DEVICE(USB_SKEL_VENDOR_ID, USB_SKEL_PRODUCT_ID) },
34 { } /* Terminating entry */
35};
36MODULE_DEVICE_TABLE (usb, skel_table);
37
38
39/* Get a minor range for your devices from the usb maintainer */
40#define USB_SKEL_MINOR_BASE 192
41
ff906518
ON
42/* our private defines. if this grows any larger, use your own .h file */
43#define MAX_TRANSFER ( PAGE_SIZE - 512 )
44#define WRITES_IN_FLIGHT 8
45
1da177e4
LT
46/* Structure to hold all of our device specific stuff */
47struct usb_skel {
48 struct usb_device * udev; /* the usb device for this device */
49 struct usb_interface * interface; /* the interface for this device */
ff906518 50 struct semaphore limit_sem; /* limiting the number of writes in progress */
1da177e4
LT
51 unsigned char * bulk_in_buffer; /* the buffer to receive data */
52 size_t bulk_in_size; /* the size of the receive buffer */
53 __u8 bulk_in_endpointAddr; /* the address of the bulk in endpoint */
54 __u8 bulk_out_endpointAddr; /* the address of the bulk out endpoint */
55 struct kref kref;
56};
57#define to_skel_dev(d) container_of(d, struct usb_skel, kref)
58
59static struct usb_driver skel_driver;
60
61static void skel_delete(struct kref *kref)
62{
63 struct usb_skel *dev = to_skel_dev(kref);
64
65 usb_put_dev(dev->udev);
66 kfree (dev->bulk_in_buffer);
67 kfree (dev);
68}
69
70static int skel_open(struct inode *inode, struct file *file)
71{
72 struct usb_skel *dev;
73 struct usb_interface *interface;
74 int subminor;
75 int retval = 0;
76
77 subminor = iminor(inode);
78
79 interface = usb_find_interface(&skel_driver, subminor);
80 if (!interface) {
81 err ("%s - error, can't find device for minor %d",
82 __FUNCTION__, subminor);
83 retval = -ENODEV;
84 goto exit;
85 }
86
87 dev = usb_get_intfdata(interface);
88 if (!dev) {
89 retval = -ENODEV;
90 goto exit;
91 }
92
93 /* increment our usage count for the device */
94 kref_get(&dev->kref);
95
96 /* save our object in the file's private structure */
97 file->private_data = dev;
98
99exit:
100 return retval;
101}
102
103static int skel_release(struct inode *inode, struct file *file)
104{
105 struct usb_skel *dev;
106
107 dev = (struct usb_skel *)file->private_data;
108 if (dev == NULL)
109 return -ENODEV;
110
111 /* decrement the count on our device */
112 kref_put(&dev->kref, skel_delete);
113 return 0;
114}
115
116static ssize_t skel_read(struct file *file, char *buffer, size_t count, loff_t *ppos)
117{
118 struct usb_skel *dev;
119 int retval = 0;
120 int bytes_read;
121
122 dev = (struct usb_skel *)file->private_data;
123
124 /* do a blocking bulk read to get data from the device */
125 retval = usb_bulk_msg(dev->udev,
126 usb_rcvbulkpipe(dev->udev, dev->bulk_in_endpointAddr),
127 dev->bulk_in_buffer,
128 min(dev->bulk_in_size, count),
129 &bytes_read, 10000);
130
131 /* if the read was successful, copy the data to userspace */
132 if (!retval) {
133 if (copy_to_user(buffer, dev->bulk_in_buffer, bytes_read))
134 retval = -EFAULT;
135 else
136 retval = bytes_read;
137 }
138
139 return retval;
140}
141
142static void skel_write_bulk_callback(struct urb *urb, struct pt_regs *regs)
143{
144 struct usb_skel *dev;
145
146 dev = (struct usb_skel *)urb->context;
147
148 /* sync/async unlink faults aren't errors */
149 if (urb->status &&
150 !(urb->status == -ENOENT ||
151 urb->status == -ECONNRESET ||
152 urb->status == -ESHUTDOWN)) {
153 dbg("%s - nonzero write bulk status received: %d",
154 __FUNCTION__, urb->status);
155 }
156
157 /* free up our allocated buffer */
158 usb_buffer_free(urb->dev, urb->transfer_buffer_length,
159 urb->transfer_buffer, urb->transfer_dma);
ff906518 160 up(&dev->limit_sem);
1da177e4
LT
161}
162
163static ssize_t skel_write(struct file *file, const char *user_buffer, size_t count, loff_t *ppos)
164{
165 struct usb_skel *dev;
166 int retval = 0;
167 struct urb *urb = NULL;
168 char *buf = NULL;
cb5b3f69 169 size_t writesize = min(count, MAX_TRANSFER);
1da177e4
LT
170
171 dev = (struct usb_skel *)file->private_data;
172
173 /* verify that we actually have some data to write */
174 if (count == 0)
175 goto exit;
176
ff906518
ON
177 /* limit the number of URBs in flight to stop a user from using up all RAM */
178 down (&dev->limit_sem);
179
1da177e4
LT
180 /* create a urb, and a buffer for it, and copy the data to the urb */
181 urb = usb_alloc_urb(0, GFP_KERNEL);
182 if (!urb) {
183 retval = -ENOMEM;
184 goto error;
185 }
186
ff906518 187 buf = usb_buffer_alloc(dev->udev, writesize, GFP_KERNEL, &urb->transfer_dma);
1da177e4
LT
188 if (!buf) {
189 retval = -ENOMEM;
190 goto error;
191 }
192
ff906518 193 if (copy_from_user(buf, user_buffer, writesize)) {
1da177e4
LT
194 retval = -EFAULT;
195 goto error;
196 }
197
198 /* initialize the urb properly */
199 usb_fill_bulk_urb(urb, dev->udev,
200 usb_sndbulkpipe(dev->udev, dev->bulk_out_endpointAddr),
ff906518 201 buf, writesize, skel_write_bulk_callback, dev);
1da177e4
LT
202 urb->transfer_flags |= URB_NO_TRANSFER_DMA_MAP;
203
204 /* send the data out the bulk port */
205 retval = usb_submit_urb(urb, GFP_KERNEL);
206 if (retval) {
207 err("%s - failed submitting write urb, error %d", __FUNCTION__, retval);
208 goto error;
209 }
210
211 /* release our reference to this urb, the USB core will eventually free it entirely */
212 usb_free_urb(urb);
213
214exit:
ff906518 215 return writesize;
1da177e4
LT
216
217error:
ff906518 218 usb_buffer_free(dev->udev, writesize, buf, urb->transfer_dma);
1da177e4 219 usb_free_urb(urb);
ff906518 220 up(&dev->limit_sem);
1da177e4
LT
221 return retval;
222}
223
224static struct file_operations skel_fops = {
225 .owner = THIS_MODULE,
226 .read = skel_read,
227 .write = skel_write,
228 .open = skel_open,
229 .release = skel_release,
230};
231
232/*
233 * usb class driver info in order to get a minor number from the usb core,
234 * and to have the device registered with devfs and the driver core
235 */
236static struct usb_class_driver skel_class = {
d6e5bcf4 237 .name = "skel%d",
1da177e4 238 .fops = &skel_fops,
1da177e4
LT
239 .minor_base = USB_SKEL_MINOR_BASE,
240};
241
242static int skel_probe(struct usb_interface *interface, const struct usb_device_id *id)
243{
244 struct usb_skel *dev = NULL;
245 struct usb_host_interface *iface_desc;
246 struct usb_endpoint_descriptor *endpoint;
247 size_t buffer_size;
248 int i;
249 int retval = -ENOMEM;
250
251 /* allocate memory for our device state and initialize it */
ff906518 252 dev = kzalloc(sizeof(*dev), GFP_KERNEL);
1da177e4
LT
253 if (dev == NULL) {
254 err("Out of memory");
255 goto error;
256 }
1da177e4 257 kref_init(&dev->kref);
ff906518 258 sema_init(&dev->limit_sem, WRITES_IN_FLIGHT);
1da177e4
LT
259
260 dev->udev = usb_get_dev(interface_to_usbdev(interface));
261 dev->interface = interface;
262
263 /* set up the endpoint information */
264 /* use only the first bulk-in and bulk-out endpoints */
265 iface_desc = interface->cur_altsetting;
266 for (i = 0; i < iface_desc->desc.bNumEndpoints; ++i) {
267 endpoint = &iface_desc->endpoint[i].desc;
268
269 if (!dev->bulk_in_endpointAddr &&
6b216df8
CC
270 ((endpoint->bEndpointAddress & USB_ENDPOINT_DIR_MASK)
271 == USB_DIR_IN) &&
1da177e4
LT
272 ((endpoint->bmAttributes & USB_ENDPOINT_XFERTYPE_MASK)
273 == USB_ENDPOINT_XFER_BULK)) {
274 /* we found a bulk in endpoint */
275 buffer_size = le16_to_cpu(endpoint->wMaxPacketSize);
276 dev->bulk_in_size = buffer_size;
277 dev->bulk_in_endpointAddr = endpoint->bEndpointAddress;
278 dev->bulk_in_buffer = kmalloc(buffer_size, GFP_KERNEL);
279 if (!dev->bulk_in_buffer) {
280 err("Could not allocate bulk_in_buffer");
281 goto error;
282 }
283 }
284
285 if (!dev->bulk_out_endpointAddr &&
6b216df8
CC
286 ((endpoint->bEndpointAddress & USB_ENDPOINT_DIR_MASK)
287 == USB_DIR_OUT) &&
1da177e4
LT
288 ((endpoint->bmAttributes & USB_ENDPOINT_XFERTYPE_MASK)
289 == USB_ENDPOINT_XFER_BULK)) {
290 /* we found a bulk out endpoint */
291 dev->bulk_out_endpointAddr = endpoint->bEndpointAddress;
292 }
293 }
294 if (!(dev->bulk_in_endpointAddr && dev->bulk_out_endpointAddr)) {
295 err("Could not find both bulk-in and bulk-out endpoints");
296 goto error;
297 }
298
299 /* save our data pointer in this interface device */
300 usb_set_intfdata(interface, dev);
301
302 /* we can register the device now, as it is ready */
303 retval = usb_register_dev(interface, &skel_class);
304 if (retval) {
305 /* something prevented us from registering this driver */
306 err("Not able to get a minor for this device.");
307 usb_set_intfdata(interface, NULL);
308 goto error;
309 }
310
311 /* let the user know what node this device is now attached to */
312 info("USB Skeleton device now attached to USBSkel-%d", interface->minor);
313 return 0;
314
315error:
316 if (dev)
317 kref_put(&dev->kref, skel_delete);
318 return retval;
319}
320
321static void skel_disconnect(struct usb_interface *interface)
322{
323 struct usb_skel *dev;
324 int minor = interface->minor;
325
326 /* prevent skel_open() from racing skel_disconnect() */
327 lock_kernel();
328
329 dev = usb_get_intfdata(interface);
330 usb_set_intfdata(interface, NULL);
331
332 /* give back our minor */
333 usb_deregister_dev(interface, &skel_class);
334
335 unlock_kernel();
336
337 /* decrement our usage count */
338 kref_put(&dev->kref, skel_delete);
339
340 info("USB Skeleton #%d now disconnected", minor);
341}
342
343static struct usb_driver skel_driver = {
1da177e4
LT
344 .name = "skeleton",
345 .probe = skel_probe,
346 .disconnect = skel_disconnect,
347 .id_table = skel_table,
348};
349
350static int __init usb_skel_init(void)
351{
352 int result;
353
354 /* register this driver with the USB subsystem */
355 result = usb_register(&skel_driver);
356 if (result)
357 err("usb_register failed. Error number %d", result);
358
359 return result;
360}
361
362static void __exit usb_skel_exit(void)
363{
364 /* deregister this driver with the USB subsystem */
365 usb_deregister(&skel_driver);
366}
367
368module_init (usb_skel_init);
369module_exit (usb_skel_exit);
370
371MODULE_LICENSE("GPL");
This page took 0.095932 seconds and 5 git commands to generate.