tty: Make lock subclasses available for other tty locks
[firefly-linux-kernel-4.4.55.git] / drivers / tty / n_tty.c
1 /*
2  * n_tty.c --- implements the N_TTY line discipline.
3  *
4  * This code used to be in tty_io.c, but things are getting hairy
5  * enough that it made sense to split things off.  (The N_TTY
6  * processing has changed so much that it's hardly recognizable,
7  * anyway...)
8  *
9  * Note that the open routine for N_TTY is guaranteed never to return
10  * an error.  This is because Linux will fall back to setting a line
11  * to N_TTY if it can not switch to any other line discipline.
12  *
13  * Written by Theodore Ts'o, Copyright 1994.
14  *
15  * This file also contains code originally written by Linus Torvalds,
16  * Copyright 1991, 1992, 1993, and by Julian Cowley, Copyright 1994.
17  *
18  * This file may be redistributed under the terms of the GNU General Public
19  * License.
20  *
21  * Reduced memory usage for older ARM systems  - Russell King.
22  *
23  * 2000/01/20   Fixed SMP locking on put_tty_queue using bits of
24  *              the patch by Andrew J. Kroll <ag784@freenet.buffalo.edu>
25  *              who actually finally proved there really was a race.
26  *
27  * 2002/03/18   Implemented n_tty_wakeup to send SIGIO POLL_OUTs to
28  *              waiting writing processes-Sapan Bhatia <sapan@corewars.org>.
29  *              Also fixed a bug in BLOCKING mode where n_tty_write returns
30  *              EAGAIN
31  */
32
33 #include <linux/types.h>
34 #include <linux/major.h>
35 #include <linux/errno.h>
36 #include <linux/signal.h>
37 #include <linux/fcntl.h>
38 #include <linux/sched.h>
39 #include <linux/interrupt.h>
40 #include <linux/tty.h>
41 #include <linux/timer.h>
42 #include <linux/ctype.h>
43 #include <linux/mm.h>
44 #include <linux/string.h>
45 #include <linux/slab.h>
46 #include <linux/poll.h>
47 #include <linux/bitops.h>
48 #include <linux/audit.h>
49 #include <linux/file.h>
50 #include <linux/uaccess.h>
51 #include <linux/module.h>
52 #include <linux/ratelimit.h>
53 #include <linux/vmalloc.h>
54
55
56 /* number of characters left in xmit buffer before select has we have room */
57 #define WAKEUP_CHARS 256
58
59 /*
60  * This defines the low- and high-watermarks for throttling and
61  * unthrottling the TTY driver.  These watermarks are used for
62  * controlling the space in the read buffer.
63  */
64 #define TTY_THRESHOLD_THROTTLE          128 /* now based on remaining room */
65 #define TTY_THRESHOLD_UNTHROTTLE        128
66
67 /*
68  * Special byte codes used in the echo buffer to represent operations
69  * or special handling of characters.  Bytes in the echo buffer that
70  * are not part of such special blocks are treated as normal character
71  * codes.
72  */
73 #define ECHO_OP_START 0xff
74 #define ECHO_OP_MOVE_BACK_COL 0x80
75 #define ECHO_OP_SET_CANON_COL 0x81
76 #define ECHO_OP_ERASE_TAB 0x82
77
78 #define ECHO_COMMIT_WATERMARK   256
79 #define ECHO_BLOCK              256
80 #define ECHO_DISCARD_WATERMARK  N_TTY_BUF_SIZE - (ECHO_BLOCK + 32)
81
82
83 #undef N_TTY_TRACE
84 #ifdef N_TTY_TRACE
85 # define n_tty_trace(f, args...)        trace_printk(f, ##args)
86 #else
87 # define n_tty_trace(f, args...)
88 #endif
89
90 struct n_tty_data {
91         /* producer-published */
92         size_t read_head;
93         size_t commit_head;
94         size_t canon_head;
95         size_t echo_head;
96         size_t echo_commit;
97         size_t echo_mark;
98         DECLARE_BITMAP(char_map, 256);
99
100         /* private to n_tty_receive_overrun (single-threaded) */
101         unsigned long overrun_time;
102         int num_overrun;
103
104         /* non-atomic */
105         bool no_room;
106
107         /* must hold exclusive termios_rwsem to reset these */
108         unsigned char lnext:1, erasing:1, raw:1, real_raw:1, icanon:1;
109         unsigned char push:1;
110
111         /* shared by producer and consumer */
112         char read_buf[N_TTY_BUF_SIZE];
113         DECLARE_BITMAP(read_flags, N_TTY_BUF_SIZE);
114         unsigned char echo_buf[N_TTY_BUF_SIZE];
115
116         int minimum_to_wake;
117
118         /* consumer-published */
119         size_t read_tail;
120         size_t line_start;
121
122         /* protected by output lock */
123         unsigned int column;
124         unsigned int canon_column;
125         size_t echo_tail;
126
127         struct mutex atomic_read_lock;
128         struct mutex output_lock;
129 };
130
131 static inline size_t read_cnt(struct n_tty_data *ldata)
132 {
133         return ldata->read_head - ldata->read_tail;
134 }
135
136 static inline unsigned char read_buf(struct n_tty_data *ldata, size_t i)
137 {
138         return ldata->read_buf[i & (N_TTY_BUF_SIZE - 1)];
139 }
140
141 static inline unsigned char *read_buf_addr(struct n_tty_data *ldata, size_t i)
142 {
143         return &ldata->read_buf[i & (N_TTY_BUF_SIZE - 1)];
144 }
145
146 static inline unsigned char echo_buf(struct n_tty_data *ldata, size_t i)
147 {
148         return ldata->echo_buf[i & (N_TTY_BUF_SIZE - 1)];
149 }
150
151 static inline unsigned char *echo_buf_addr(struct n_tty_data *ldata, size_t i)
152 {
153         return &ldata->echo_buf[i & (N_TTY_BUF_SIZE - 1)];
154 }
155
156 static inline int tty_put_user(struct tty_struct *tty, unsigned char x,
157                                unsigned char __user *ptr)
158 {
159         struct n_tty_data *ldata = tty->disc_data;
160
161         tty_audit_add_data(tty, &x, 1, ldata->icanon);
162         return put_user(x, ptr);
163 }
164
165 /**
166  *      n_tty_kick_worker - start input worker (if required)
167  *      @tty: terminal
168  *
169  *      Re-schedules the flip buffer work if it may have stopped
170  *
171  *      Caller holds exclusive termios_rwsem
172  *         or
173  *      n_tty_read()/consumer path:
174  *              holds non-exclusive termios_rwsem
175  */
176
177 static void n_tty_kick_worker(struct tty_struct *tty)
178 {
179         struct n_tty_data *ldata = tty->disc_data;
180
181         /* Did the input worker stop? Restart it */
182         if (unlikely(ldata->no_room)) {
183                 ldata->no_room = 0;
184
185                 WARN_RATELIMIT(tty->port->itty == NULL,
186                                 "scheduling with invalid itty\n");
187                 /* see if ldisc has been killed - if so, this means that
188                  * even though the ldisc has been halted and ->buf.work
189                  * cancelled, ->buf.work is about to be rescheduled
190                  */
191                 WARN_RATELIMIT(test_bit(TTY_LDISC_HALTED, &tty->flags),
192                                "scheduling buffer work for halted ldisc\n");
193                 queue_work(system_unbound_wq, &tty->port->buf.work);
194         }
195 }
196
197 static ssize_t chars_in_buffer(struct tty_struct *tty)
198 {
199         struct n_tty_data *ldata = tty->disc_data;
200         ssize_t n = 0;
201
202         if (!ldata->icanon)
203                 n = ldata->commit_head - ldata->read_tail;
204         else
205                 n = ldata->canon_head - ldata->read_tail;
206         return n;
207 }
208
209 /**
210  *      n_tty_write_wakeup      -       asynchronous I/O notifier
211  *      @tty: tty device
212  *
213  *      Required for the ptys, serial driver etc. since processes
214  *      that attach themselves to the master and rely on ASYNC
215  *      IO must be woken up
216  */
217
218 static void n_tty_write_wakeup(struct tty_struct *tty)
219 {
220         if (tty->fasync && test_and_clear_bit(TTY_DO_WRITE_WAKEUP, &tty->flags))
221                 kill_fasync(&tty->fasync, SIGIO, POLL_OUT);
222 }
223
224 static void n_tty_check_throttle(struct tty_struct *tty)
225 {
226         struct n_tty_data *ldata = tty->disc_data;
227
228         /*
229          * Check the remaining room for the input canonicalization
230          * mode.  We don't want to throttle the driver if we're in
231          * canonical mode and don't have a newline yet!
232          */
233         if (ldata->icanon && ldata->canon_head == ldata->read_tail)
234                 return;
235
236         while (1) {
237                 int throttled;
238                 tty_set_flow_change(tty, TTY_THROTTLE_SAFE);
239                 if (N_TTY_BUF_SIZE - read_cnt(ldata) >= TTY_THRESHOLD_THROTTLE)
240                         break;
241                 throttled = tty_throttle_safe(tty);
242                 if (!throttled)
243                         break;
244         }
245         __tty_set_flow_change(tty, 0);
246 }
247
248 static void n_tty_check_unthrottle(struct tty_struct *tty)
249 {
250         if (tty->driver->type == TTY_DRIVER_TYPE_PTY &&
251             tty->link->ldisc->ops->write_wakeup == n_tty_write_wakeup) {
252                 if (chars_in_buffer(tty) > TTY_THRESHOLD_UNTHROTTLE)
253                         return;
254                 if (!tty->count)
255                         return;
256                 n_tty_kick_worker(tty);
257                 n_tty_write_wakeup(tty->link);
258                 if (waitqueue_active(&tty->link->write_wait))
259                         wake_up_interruptible_poll(&tty->link->write_wait, POLLOUT);
260                 return;
261         }
262
263         /* If there is enough space in the read buffer now, let the
264          * low-level driver know. We use chars_in_buffer() to
265          * check the buffer, as it now knows about canonical mode.
266          * Otherwise, if the driver is throttled and the line is
267          * longer than TTY_THRESHOLD_UNTHROTTLE in canonical mode,
268          * we won't get any more characters.
269          */
270
271         while (1) {
272                 int unthrottled;
273                 tty_set_flow_change(tty, TTY_UNTHROTTLE_SAFE);
274                 if (chars_in_buffer(tty) > TTY_THRESHOLD_UNTHROTTLE)
275                         break;
276                 if (!tty->count)
277                         break;
278                 n_tty_kick_worker(tty);
279                 unthrottled = tty_unthrottle_safe(tty);
280                 if (!unthrottled)
281                         break;
282         }
283         __tty_set_flow_change(tty, 0);
284 }
285
286 /**
287  *      put_tty_queue           -       add character to tty
288  *      @c: character
289  *      @ldata: n_tty data
290  *
291  *      Add a character to the tty read_buf queue.
292  *
293  *      n_tty_receive_buf()/producer path:
294  *              caller holds non-exclusive termios_rwsem
295  */
296
297 static inline void put_tty_queue(unsigned char c, struct n_tty_data *ldata)
298 {
299         *read_buf_addr(ldata, ldata->read_head) = c;
300         ldata->read_head++;
301 }
302
303 /**
304  *      reset_buffer_flags      -       reset buffer state
305  *      @tty: terminal to reset
306  *
307  *      Reset the read buffer counters and clear the flags.
308  *      Called from n_tty_open() and n_tty_flush_buffer().
309  *
310  *      Locking: caller holds exclusive termios_rwsem
311  *               (or locking is not required)
312  */
313
314 static void reset_buffer_flags(struct n_tty_data *ldata)
315 {
316         ldata->read_head = ldata->canon_head = ldata->read_tail = 0;
317         ldata->echo_head = ldata->echo_tail = ldata->echo_commit = 0;
318         ldata->commit_head = 0;
319         ldata->echo_mark = 0;
320         ldata->line_start = 0;
321
322         ldata->erasing = 0;
323         bitmap_zero(ldata->read_flags, N_TTY_BUF_SIZE);
324         ldata->push = 0;
325 }
326
327 static void n_tty_packet_mode_flush(struct tty_struct *tty)
328 {
329         unsigned long flags;
330
331         if (tty->link->packet) {
332                 spin_lock_irqsave(&tty->ctrl_lock, flags);
333                 tty->ctrl_status |= TIOCPKT_FLUSHREAD;
334                 spin_unlock_irqrestore(&tty->ctrl_lock, flags);
335                 if (waitqueue_active(&tty->link->read_wait))
336                         wake_up_interruptible(&tty->link->read_wait);
337         }
338 }
339
340 /**
341  *      n_tty_flush_buffer      -       clean input queue
342  *      @tty:   terminal device
343  *
344  *      Flush the input buffer. Called when the tty layer wants the
345  *      buffer flushed (eg at hangup) or when the N_TTY line discipline
346  *      internally has to clean the pending queue (for example some signals).
347  *
348  *      Holds termios_rwsem to exclude producer/consumer while
349  *      buffer indices are reset.
350  *
351  *      Locking: ctrl_lock, exclusive termios_rwsem
352  */
353
354 static void n_tty_flush_buffer(struct tty_struct *tty)
355 {
356         down_write(&tty->termios_rwsem);
357         reset_buffer_flags(tty->disc_data);
358         n_tty_kick_worker(tty);
359
360         if (tty->link)
361                 n_tty_packet_mode_flush(tty);
362         up_write(&tty->termios_rwsem);
363 }
364
365 /**
366  *      n_tty_chars_in_buffer   -       report available bytes
367  *      @tty: tty device
368  *
369  *      Report the number of characters buffered to be delivered to user
370  *      at this instant in time.
371  *
372  *      Locking: exclusive termios_rwsem
373  */
374
375 static ssize_t n_tty_chars_in_buffer(struct tty_struct *tty)
376 {
377         ssize_t n;
378
379         WARN_ONCE(1, "%s is deprecated and scheduled for removal.", __func__);
380
381         down_write(&tty->termios_rwsem);
382         n = chars_in_buffer(tty);
383         up_write(&tty->termios_rwsem);
384         return n;
385 }
386
387 /**
388  *      is_utf8_continuation    -       utf8 multibyte check
389  *      @c: byte to check
390  *
391  *      Returns true if the utf8 character 'c' is a multibyte continuation
392  *      character. We use this to correctly compute the on screen size
393  *      of the character when printing
394  */
395
396 static inline int is_utf8_continuation(unsigned char c)
397 {
398         return (c & 0xc0) == 0x80;
399 }
400
401 /**
402  *      is_continuation         -       multibyte check
403  *      @c: byte to check
404  *
405  *      Returns true if the utf8 character 'c' is a multibyte continuation
406  *      character and the terminal is in unicode mode.
407  */
408
409 static inline int is_continuation(unsigned char c, struct tty_struct *tty)
410 {
411         return I_IUTF8(tty) && is_utf8_continuation(c);
412 }
413
414 /**
415  *      do_output_char                  -       output one character
416  *      @c: character (or partial unicode symbol)
417  *      @tty: terminal device
418  *      @space: space available in tty driver write buffer
419  *
420  *      This is a helper function that handles one output character
421  *      (including special characters like TAB, CR, LF, etc.),
422  *      doing OPOST processing and putting the results in the
423  *      tty driver's write buffer.
424  *
425  *      Note that Linux currently ignores TABDLY, CRDLY, VTDLY, FFDLY
426  *      and NLDLY.  They simply aren't relevant in the world today.
427  *      If you ever need them, add them here.
428  *
429  *      Returns the number of bytes of buffer space used or -1 if
430  *      no space left.
431  *
432  *      Locking: should be called under the output_lock to protect
433  *               the column state and space left in the buffer
434  */
435
436 static int do_output_char(unsigned char c, struct tty_struct *tty, int space)
437 {
438         struct n_tty_data *ldata = tty->disc_data;
439         int     spaces;
440
441         if (!space)
442                 return -1;
443
444         switch (c) {
445         case '\n':
446                 if (O_ONLRET(tty))
447                         ldata->column = 0;
448                 if (O_ONLCR(tty)) {
449                         if (space < 2)
450                                 return -1;
451                         ldata->canon_column = ldata->column = 0;
452                         tty->ops->write(tty, "\r\n", 2);
453                         return 2;
454                 }
455                 ldata->canon_column = ldata->column;
456                 break;
457         case '\r':
458                 if (O_ONOCR(tty) && ldata->column == 0)
459                         return 0;
460                 if (O_OCRNL(tty)) {
461                         c = '\n';
462                         if (O_ONLRET(tty))
463                                 ldata->canon_column = ldata->column = 0;
464                         break;
465                 }
466                 ldata->canon_column = ldata->column = 0;
467                 break;
468         case '\t':
469                 spaces = 8 - (ldata->column & 7);
470                 if (O_TABDLY(tty) == XTABS) {
471                         if (space < spaces)
472                                 return -1;
473                         ldata->column += spaces;
474                         tty->ops->write(tty, "        ", spaces);
475                         return spaces;
476                 }
477                 ldata->column += spaces;
478                 break;
479         case '\b':
480                 if (ldata->column > 0)
481                         ldata->column--;
482                 break;
483         default:
484                 if (!iscntrl(c)) {
485                         if (O_OLCUC(tty))
486                                 c = toupper(c);
487                         if (!is_continuation(c, tty))
488                                 ldata->column++;
489                 }
490                 break;
491         }
492
493         tty_put_char(tty, c);
494         return 1;
495 }
496
497 /**
498  *      process_output                  -       output post processor
499  *      @c: character (or partial unicode symbol)
500  *      @tty: terminal device
501  *
502  *      Output one character with OPOST processing.
503  *      Returns -1 when the output device is full and the character
504  *      must be retried.
505  *
506  *      Locking: output_lock to protect column state and space left
507  *               (also, this is called from n_tty_write under the
508  *                tty layer write lock)
509  */
510
511 static int process_output(unsigned char c, struct tty_struct *tty)
512 {
513         struct n_tty_data *ldata = tty->disc_data;
514         int     space, retval;
515
516         mutex_lock(&ldata->output_lock);
517
518         space = tty_write_room(tty);
519         retval = do_output_char(c, tty, space);
520
521         mutex_unlock(&ldata->output_lock);
522         if (retval < 0)
523                 return -1;
524         else
525                 return 0;
526 }
527
528 /**
529  *      process_output_block            -       block post processor
530  *      @tty: terminal device
531  *      @buf: character buffer
532  *      @nr: number of bytes to output
533  *
534  *      Output a block of characters with OPOST processing.
535  *      Returns the number of characters output.
536  *
537  *      This path is used to speed up block console writes, among other
538  *      things when processing blocks of output data. It handles only
539  *      the simple cases normally found and helps to generate blocks of
540  *      symbols for the console driver and thus improve performance.
541  *
542  *      Locking: output_lock to protect column state and space left
543  *               (also, this is called from n_tty_write under the
544  *                tty layer write lock)
545  */
546
547 static ssize_t process_output_block(struct tty_struct *tty,
548                                     const unsigned char *buf, unsigned int nr)
549 {
550         struct n_tty_data *ldata = tty->disc_data;
551         int     space;
552         int     i;
553         const unsigned char *cp;
554
555         mutex_lock(&ldata->output_lock);
556
557         space = tty_write_room(tty);
558         if (!space) {
559                 mutex_unlock(&ldata->output_lock);
560                 return 0;
561         }
562         if (nr > space)
563                 nr = space;
564
565         for (i = 0, cp = buf; i < nr; i++, cp++) {
566                 unsigned char c = *cp;
567
568                 switch (c) {
569                 case '\n':
570                         if (O_ONLRET(tty))
571                                 ldata->column = 0;
572                         if (O_ONLCR(tty))
573                                 goto break_out;
574                         ldata->canon_column = ldata->column;
575                         break;
576                 case '\r':
577                         if (O_ONOCR(tty) && ldata->column == 0)
578                                 goto break_out;
579                         if (O_OCRNL(tty))
580                                 goto break_out;
581                         ldata->canon_column = ldata->column = 0;
582                         break;
583                 case '\t':
584                         goto break_out;
585                 case '\b':
586                         if (ldata->column > 0)
587                                 ldata->column--;
588                         break;
589                 default:
590                         if (!iscntrl(c)) {
591                                 if (O_OLCUC(tty))
592                                         goto break_out;
593                                 if (!is_continuation(c, tty))
594                                         ldata->column++;
595                         }
596                         break;
597                 }
598         }
599 break_out:
600         i = tty->ops->write(tty, buf, i);
601
602         mutex_unlock(&ldata->output_lock);
603         return i;
604 }
605
606 /**
607  *      process_echoes  -       write pending echo characters
608  *      @tty: terminal device
609  *
610  *      Write previously buffered echo (and other ldisc-generated)
611  *      characters to the tty.
612  *
613  *      Characters generated by the ldisc (including echoes) need to
614  *      be buffered because the driver's write buffer can fill during
615  *      heavy program output.  Echoing straight to the driver will
616  *      often fail under these conditions, causing lost characters and
617  *      resulting mismatches of ldisc state information.
618  *
619  *      Since the ldisc state must represent the characters actually sent
620  *      to the driver at the time of the write, operations like certain
621  *      changes in column state are also saved in the buffer and executed
622  *      here.
623  *
624  *      A circular fifo buffer is used so that the most recent characters
625  *      are prioritized.  Also, when control characters are echoed with a
626  *      prefixed "^", the pair is treated atomically and thus not separated.
627  *
628  *      Locking: callers must hold output_lock
629  */
630
631 static size_t __process_echoes(struct tty_struct *tty)
632 {
633         struct n_tty_data *ldata = tty->disc_data;
634         int     space, old_space;
635         size_t tail;
636         unsigned char c;
637
638         old_space = space = tty_write_room(tty);
639
640         tail = ldata->echo_tail;
641         while (ldata->echo_commit != tail) {
642                 c = echo_buf(ldata, tail);
643                 if (c == ECHO_OP_START) {
644                         unsigned char op;
645                         int no_space_left = 0;
646
647                         /*
648                          * If the buffer byte is the start of a multi-byte
649                          * operation, get the next byte, which is either the
650                          * op code or a control character value.
651                          */
652                         op = echo_buf(ldata, tail + 1);
653
654                         switch (op) {
655                                 unsigned int num_chars, num_bs;
656
657                         case ECHO_OP_ERASE_TAB:
658                                 num_chars = echo_buf(ldata, tail + 2);
659
660                                 /*
661                                  * Determine how many columns to go back
662                                  * in order to erase the tab.
663                                  * This depends on the number of columns
664                                  * used by other characters within the tab
665                                  * area.  If this (modulo 8) count is from
666                                  * the start of input rather than from a
667                                  * previous tab, we offset by canon column.
668                                  * Otherwise, tab spacing is normal.
669                                  */
670                                 if (!(num_chars & 0x80))
671                                         num_chars += ldata->canon_column;
672                                 num_bs = 8 - (num_chars & 7);
673
674                                 if (num_bs > space) {
675                                         no_space_left = 1;
676                                         break;
677                                 }
678                                 space -= num_bs;
679                                 while (num_bs--) {
680                                         tty_put_char(tty, '\b');
681                                         if (ldata->column > 0)
682                                                 ldata->column--;
683                                 }
684                                 tail += 3;
685                                 break;
686
687                         case ECHO_OP_SET_CANON_COL:
688                                 ldata->canon_column = ldata->column;
689                                 tail += 2;
690                                 break;
691
692                         case ECHO_OP_MOVE_BACK_COL:
693                                 if (ldata->column > 0)
694                                         ldata->column--;
695                                 tail += 2;
696                                 break;
697
698                         case ECHO_OP_START:
699                                 /* This is an escaped echo op start code */
700                                 if (!space) {
701                                         no_space_left = 1;
702                                         break;
703                                 }
704                                 tty_put_char(tty, ECHO_OP_START);
705                                 ldata->column++;
706                                 space--;
707                                 tail += 2;
708                                 break;
709
710                         default:
711                                 /*
712                                  * If the op is not a special byte code,
713                                  * it is a ctrl char tagged to be echoed
714                                  * as "^X" (where X is the letter
715                                  * representing the control char).
716                                  * Note that we must ensure there is
717                                  * enough space for the whole ctrl pair.
718                                  *
719                                  */
720                                 if (space < 2) {
721                                         no_space_left = 1;
722                                         break;
723                                 }
724                                 tty_put_char(tty, '^');
725                                 tty_put_char(tty, op ^ 0100);
726                                 ldata->column += 2;
727                                 space -= 2;
728                                 tail += 2;
729                         }
730
731                         if (no_space_left)
732                                 break;
733                 } else {
734                         if (O_OPOST(tty)) {
735                                 int retval = do_output_char(c, tty, space);
736                                 if (retval < 0)
737                                         break;
738                                 space -= retval;
739                         } else {
740                                 if (!space)
741                                         break;
742                                 tty_put_char(tty, c);
743                                 space -= 1;
744                         }
745                         tail += 1;
746                 }
747         }
748
749         /* If the echo buffer is nearly full (so that the possibility exists
750          * of echo overrun before the next commit), then discard enough
751          * data at the tail to prevent a subsequent overrun */
752         while (ldata->echo_commit - tail >= ECHO_DISCARD_WATERMARK) {
753                 if (echo_buf(ldata, tail) == ECHO_OP_START) {
754                         if (echo_buf(ldata, tail + 1) == ECHO_OP_ERASE_TAB)
755                                 tail += 3;
756                         else
757                                 tail += 2;
758                 } else
759                         tail++;
760         }
761
762         ldata->echo_tail = tail;
763         return old_space - space;
764 }
765
766 static void commit_echoes(struct tty_struct *tty)
767 {
768         struct n_tty_data *ldata = tty->disc_data;
769         size_t nr, old, echoed;
770         size_t head;
771
772         head = ldata->echo_head;
773         ldata->echo_mark = head;
774         old = ldata->echo_commit - ldata->echo_tail;
775
776         /* Process committed echoes if the accumulated # of bytes
777          * is over the threshold (and try again each time another
778          * block is accumulated) */
779         nr = head - ldata->echo_tail;
780         if (nr < ECHO_COMMIT_WATERMARK || (nr % ECHO_BLOCK > old % ECHO_BLOCK))
781                 return;
782
783         mutex_lock(&ldata->output_lock);
784         ldata->echo_commit = head;
785         echoed = __process_echoes(tty);
786         mutex_unlock(&ldata->output_lock);
787
788         if (echoed && tty->ops->flush_chars)
789                 tty->ops->flush_chars(tty);
790 }
791
792 static void process_echoes(struct tty_struct *tty)
793 {
794         struct n_tty_data *ldata = tty->disc_data;
795         size_t echoed;
796
797         if (ldata->echo_mark == ldata->echo_tail)
798                 return;
799
800         mutex_lock(&ldata->output_lock);
801         ldata->echo_commit = ldata->echo_mark;
802         echoed = __process_echoes(tty);
803         mutex_unlock(&ldata->output_lock);
804
805         if (echoed && tty->ops->flush_chars)
806                 tty->ops->flush_chars(tty);
807 }
808
809 /* NB: echo_mark and echo_head should be equivalent here */
810 static void flush_echoes(struct tty_struct *tty)
811 {
812         struct n_tty_data *ldata = tty->disc_data;
813
814         if ((!L_ECHO(tty) && !L_ECHONL(tty)) ||
815             ldata->echo_commit == ldata->echo_head)
816                 return;
817
818         mutex_lock(&ldata->output_lock);
819         ldata->echo_commit = ldata->echo_head;
820         __process_echoes(tty);
821         mutex_unlock(&ldata->output_lock);
822 }
823
824 /**
825  *      add_echo_byte   -       add a byte to the echo buffer
826  *      @c: unicode byte to echo
827  *      @ldata: n_tty data
828  *
829  *      Add a character or operation byte to the echo buffer.
830  */
831
832 static inline void add_echo_byte(unsigned char c, struct n_tty_data *ldata)
833 {
834         *echo_buf_addr(ldata, ldata->echo_head++) = c;
835 }
836
837 /**
838  *      echo_move_back_col      -       add operation to move back a column
839  *      @ldata: n_tty data
840  *
841  *      Add an operation to the echo buffer to move back one column.
842  */
843
844 static void echo_move_back_col(struct n_tty_data *ldata)
845 {
846         add_echo_byte(ECHO_OP_START, ldata);
847         add_echo_byte(ECHO_OP_MOVE_BACK_COL, ldata);
848 }
849
850 /**
851  *      echo_set_canon_col      -       add operation to set the canon column
852  *      @ldata: n_tty data
853  *
854  *      Add an operation to the echo buffer to set the canon column
855  *      to the current column.
856  */
857
858 static void echo_set_canon_col(struct n_tty_data *ldata)
859 {
860         add_echo_byte(ECHO_OP_START, ldata);
861         add_echo_byte(ECHO_OP_SET_CANON_COL, ldata);
862 }
863
864 /**
865  *      echo_erase_tab  -       add operation to erase a tab
866  *      @num_chars: number of character columns already used
867  *      @after_tab: true if num_chars starts after a previous tab
868  *      @ldata: n_tty data
869  *
870  *      Add an operation to the echo buffer to erase a tab.
871  *
872  *      Called by the eraser function, which knows how many character
873  *      columns have been used since either a previous tab or the start
874  *      of input.  This information will be used later, along with
875  *      canon column (if applicable), to go back the correct number
876  *      of columns.
877  */
878
879 static void echo_erase_tab(unsigned int num_chars, int after_tab,
880                            struct n_tty_data *ldata)
881 {
882         add_echo_byte(ECHO_OP_START, ldata);
883         add_echo_byte(ECHO_OP_ERASE_TAB, ldata);
884
885         /* We only need to know this modulo 8 (tab spacing) */
886         num_chars &= 7;
887
888         /* Set the high bit as a flag if num_chars is after a previous tab */
889         if (after_tab)
890                 num_chars |= 0x80;
891
892         add_echo_byte(num_chars, ldata);
893 }
894
895 /**
896  *      echo_char_raw   -       echo a character raw
897  *      @c: unicode byte to echo
898  *      @tty: terminal device
899  *
900  *      Echo user input back onto the screen. This must be called only when
901  *      L_ECHO(tty) is true. Called from the driver receive_buf path.
902  *
903  *      This variant does not treat control characters specially.
904  */
905
906 static void echo_char_raw(unsigned char c, struct n_tty_data *ldata)
907 {
908         if (c == ECHO_OP_START) {
909                 add_echo_byte(ECHO_OP_START, ldata);
910                 add_echo_byte(ECHO_OP_START, ldata);
911         } else {
912                 add_echo_byte(c, ldata);
913         }
914 }
915
916 /**
917  *      echo_char       -       echo a character
918  *      @c: unicode byte to echo
919  *      @tty: terminal device
920  *
921  *      Echo user input back onto the screen. This must be called only when
922  *      L_ECHO(tty) is true. Called from the driver receive_buf path.
923  *
924  *      This variant tags control characters to be echoed as "^X"
925  *      (where X is the letter representing the control char).
926  */
927
928 static void echo_char(unsigned char c, struct tty_struct *tty)
929 {
930         struct n_tty_data *ldata = tty->disc_data;
931
932         if (c == ECHO_OP_START) {
933                 add_echo_byte(ECHO_OP_START, ldata);
934                 add_echo_byte(ECHO_OP_START, ldata);
935         } else {
936                 if (L_ECHOCTL(tty) && iscntrl(c) && c != '\t')
937                         add_echo_byte(ECHO_OP_START, ldata);
938                 add_echo_byte(c, ldata);
939         }
940 }
941
942 /**
943  *      finish_erasing          -       complete erase
944  *      @ldata: n_tty data
945  */
946
947 static inline void finish_erasing(struct n_tty_data *ldata)
948 {
949         if (ldata->erasing) {
950                 echo_char_raw('/', ldata);
951                 ldata->erasing = 0;
952         }
953 }
954
955 /**
956  *      eraser          -       handle erase function
957  *      @c: character input
958  *      @tty: terminal device
959  *
960  *      Perform erase and necessary output when an erase character is
961  *      present in the stream from the driver layer. Handles the complexities
962  *      of UTF-8 multibyte symbols.
963  *
964  *      n_tty_receive_buf()/producer path:
965  *              caller holds non-exclusive termios_rwsem
966  */
967
968 static void eraser(unsigned char c, struct tty_struct *tty)
969 {
970         struct n_tty_data *ldata = tty->disc_data;
971         enum { ERASE, WERASE, KILL } kill_type;
972         size_t head;
973         size_t cnt;
974         int seen_alnums;
975
976         if (ldata->read_head == ldata->canon_head) {
977                 /* process_output('\a', tty); */ /* what do you think? */
978                 return;
979         }
980         if (c == ERASE_CHAR(tty))
981                 kill_type = ERASE;
982         else if (c == WERASE_CHAR(tty))
983                 kill_type = WERASE;
984         else {
985                 if (!L_ECHO(tty)) {
986                         ldata->read_head = ldata->canon_head;
987                         return;
988                 }
989                 if (!L_ECHOK(tty) || !L_ECHOKE(tty) || !L_ECHOE(tty)) {
990                         ldata->read_head = ldata->canon_head;
991                         finish_erasing(ldata);
992                         echo_char(KILL_CHAR(tty), tty);
993                         /* Add a newline if ECHOK is on and ECHOKE is off. */
994                         if (L_ECHOK(tty))
995                                 echo_char_raw('\n', ldata);
996                         return;
997                 }
998                 kill_type = KILL;
999         }
1000
1001         seen_alnums = 0;
1002         while (ldata->read_head != ldata->canon_head) {
1003                 head = ldata->read_head;
1004
1005                 /* erase a single possibly multibyte character */
1006                 do {
1007                         head--;
1008                         c = read_buf(ldata, head);
1009                 } while (is_continuation(c, tty) && head != ldata->canon_head);
1010
1011                 /* do not partially erase */
1012                 if (is_continuation(c, tty))
1013                         break;
1014
1015                 if (kill_type == WERASE) {
1016                         /* Equivalent to BSD's ALTWERASE. */
1017                         if (isalnum(c) || c == '_')
1018                                 seen_alnums++;
1019                         else if (seen_alnums)
1020                                 break;
1021                 }
1022                 cnt = ldata->read_head - head;
1023                 ldata->read_head = head;
1024                 if (L_ECHO(tty)) {
1025                         if (L_ECHOPRT(tty)) {
1026                                 if (!ldata->erasing) {
1027                                         echo_char_raw('\\', ldata);
1028                                         ldata->erasing = 1;
1029                                 }
1030                                 /* if cnt > 1, output a multi-byte character */
1031                                 echo_char(c, tty);
1032                                 while (--cnt > 0) {
1033                                         head++;
1034                                         echo_char_raw(read_buf(ldata, head), ldata);
1035                                         echo_move_back_col(ldata);
1036                                 }
1037                         } else if (kill_type == ERASE && !L_ECHOE(tty)) {
1038                                 echo_char(ERASE_CHAR(tty), tty);
1039                         } else if (c == '\t') {
1040                                 unsigned int num_chars = 0;
1041                                 int after_tab = 0;
1042                                 size_t tail = ldata->read_head;
1043
1044                                 /*
1045                                  * Count the columns used for characters
1046                                  * since the start of input or after a
1047                                  * previous tab.
1048                                  * This info is used to go back the correct
1049                                  * number of columns.
1050                                  */
1051                                 while (tail != ldata->canon_head) {
1052                                         tail--;
1053                                         c = read_buf(ldata, tail);
1054                                         if (c == '\t') {
1055                                                 after_tab = 1;
1056                                                 break;
1057                                         } else if (iscntrl(c)) {
1058                                                 if (L_ECHOCTL(tty))
1059                                                         num_chars += 2;
1060                                         } else if (!is_continuation(c, tty)) {
1061                                                 num_chars++;
1062                                         }
1063                                 }
1064                                 echo_erase_tab(num_chars, after_tab, ldata);
1065                         } else {
1066                                 if (iscntrl(c) && L_ECHOCTL(tty)) {
1067                                         echo_char_raw('\b', ldata);
1068                                         echo_char_raw(' ', ldata);
1069                                         echo_char_raw('\b', ldata);
1070                                 }
1071                                 if (!iscntrl(c) || L_ECHOCTL(tty)) {
1072                                         echo_char_raw('\b', ldata);
1073                                         echo_char_raw(' ', ldata);
1074                                         echo_char_raw('\b', ldata);
1075                                 }
1076                         }
1077                 }
1078                 if (kill_type == ERASE)
1079                         break;
1080         }
1081         if (ldata->read_head == ldata->canon_head && L_ECHO(tty))
1082                 finish_erasing(ldata);
1083 }
1084
1085 /**
1086  *      isig            -       handle the ISIG optio
1087  *      @sig: signal
1088  *      @tty: terminal
1089  *
1090  *      Called when a signal is being sent due to terminal input.
1091  *      Called from the driver receive_buf path so serialized.
1092  *
1093  *      Locking: ctrl_lock
1094  */
1095
1096 static void isig(int sig, struct tty_struct *tty)
1097 {
1098         struct pid *tty_pgrp = tty_get_pgrp(tty);
1099         if (tty_pgrp) {
1100                 kill_pgrp(tty_pgrp, sig, 1);
1101                 put_pid(tty_pgrp);
1102         }
1103 }
1104
1105 /**
1106  *      n_tty_receive_break     -       handle break
1107  *      @tty: terminal
1108  *
1109  *      An RS232 break event has been hit in the incoming bitstream. This
1110  *      can cause a variety of events depending upon the termios settings.
1111  *
1112  *      n_tty_receive_buf()/producer path:
1113  *              caller holds non-exclusive termios_rwsem
1114  *
1115  *      Note: may get exclusive termios_rwsem if flushing input buffer
1116  */
1117
1118 static void n_tty_receive_break(struct tty_struct *tty)
1119 {
1120         struct n_tty_data *ldata = tty->disc_data;
1121
1122         if (I_IGNBRK(tty))
1123                 return;
1124         if (I_BRKINT(tty)) {
1125                 isig(SIGINT, tty);
1126                 if (!L_NOFLSH(tty)) {
1127                         /* flushing needs exclusive termios_rwsem */
1128                         up_read(&tty->termios_rwsem);
1129                         n_tty_flush_buffer(tty);
1130                         tty_driver_flush_buffer(tty);
1131                         down_read(&tty->termios_rwsem);
1132                 }
1133                 return;
1134         }
1135         if (I_PARMRK(tty)) {
1136                 put_tty_queue('\377', ldata);
1137                 put_tty_queue('\0', ldata);
1138         }
1139         put_tty_queue('\0', ldata);
1140         if (waitqueue_active(&tty->read_wait))
1141                 wake_up_interruptible_poll(&tty->read_wait, POLLIN);
1142 }
1143
1144 /**
1145  *      n_tty_receive_overrun   -       handle overrun reporting
1146  *      @tty: terminal
1147  *
1148  *      Data arrived faster than we could process it. While the tty
1149  *      driver has flagged this the bits that were missed are gone
1150  *      forever.
1151  *
1152  *      Called from the receive_buf path so single threaded. Does not
1153  *      need locking as num_overrun and overrun_time are function
1154  *      private.
1155  */
1156
1157 static void n_tty_receive_overrun(struct tty_struct *tty)
1158 {
1159         struct n_tty_data *ldata = tty->disc_data;
1160         char buf[64];
1161
1162         ldata->num_overrun++;
1163         if (time_after(jiffies, ldata->overrun_time + HZ) ||
1164                         time_after(ldata->overrun_time, jiffies)) {
1165                 printk(KERN_WARNING "%s: %d input overrun(s)\n",
1166                         tty_name(tty, buf),
1167                         ldata->num_overrun);
1168                 ldata->overrun_time = jiffies;
1169                 ldata->num_overrun = 0;
1170         }
1171 }
1172
1173 /**
1174  *      n_tty_receive_parity_error      -       error notifier
1175  *      @tty: terminal device
1176  *      @c: character
1177  *
1178  *      Process a parity error and queue the right data to indicate
1179  *      the error case if necessary.
1180  *
1181  *      n_tty_receive_buf()/producer path:
1182  *              caller holds non-exclusive termios_rwsem
1183  */
1184 static void n_tty_receive_parity_error(struct tty_struct *tty, unsigned char c)
1185 {
1186         struct n_tty_data *ldata = tty->disc_data;
1187
1188         if (I_INPCK(tty)) {
1189                 if (I_IGNPAR(tty))
1190                         return;
1191                 if (I_PARMRK(tty)) {
1192                         put_tty_queue('\377', ldata);
1193                         put_tty_queue('\0', ldata);
1194                         put_tty_queue(c, ldata);
1195                 } else
1196                         put_tty_queue('\0', ldata);
1197         } else
1198                 put_tty_queue(c, ldata);
1199         if (waitqueue_active(&tty->read_wait))
1200                 wake_up_interruptible_poll(&tty->read_wait, POLLIN);
1201 }
1202
1203 static void
1204 n_tty_receive_signal_char(struct tty_struct *tty, int signal, unsigned char c)
1205 {
1206         if (!L_NOFLSH(tty)) {
1207                 /* flushing needs exclusive termios_rwsem */
1208                 up_read(&tty->termios_rwsem);
1209                 n_tty_flush_buffer(tty);
1210                 tty_driver_flush_buffer(tty);
1211                 down_read(&tty->termios_rwsem);
1212         }
1213         if (I_IXON(tty))
1214                 start_tty(tty);
1215         if (L_ECHO(tty)) {
1216                 echo_char(c, tty);
1217                 commit_echoes(tty);
1218         } else
1219                 process_echoes(tty);
1220         isig(signal, tty);
1221         return;
1222 }
1223
1224 /**
1225  *      n_tty_receive_char      -       perform processing
1226  *      @tty: terminal device
1227  *      @c: character
1228  *
1229  *      Process an individual character of input received from the driver.
1230  *      This is serialized with respect to itself by the rules for the
1231  *      driver above.
1232  *
1233  *      n_tty_receive_buf()/producer path:
1234  *              caller holds non-exclusive termios_rwsem
1235  *              publishes canon_head if canonical mode is active
1236  *
1237  *      Returns 1 if LNEXT was received, else returns 0
1238  */
1239
1240 static int
1241 n_tty_receive_char_special(struct tty_struct *tty, unsigned char c)
1242 {
1243         struct n_tty_data *ldata = tty->disc_data;
1244
1245         if (I_IXON(tty)) {
1246                 if (c == START_CHAR(tty)) {
1247                         start_tty(tty);
1248                         process_echoes(tty);
1249                         return 0;
1250                 }
1251                 if (c == STOP_CHAR(tty)) {
1252                         stop_tty(tty);
1253                         return 0;
1254                 }
1255         }
1256
1257         if (L_ISIG(tty)) {
1258                 if (c == INTR_CHAR(tty)) {
1259                         n_tty_receive_signal_char(tty, SIGINT, c);
1260                         return 0;
1261                 } else if (c == QUIT_CHAR(tty)) {
1262                         n_tty_receive_signal_char(tty, SIGQUIT, c);
1263                         return 0;
1264                 } else if (c == SUSP_CHAR(tty)) {
1265                         n_tty_receive_signal_char(tty, SIGTSTP, c);
1266                         return 0;
1267                 }
1268         }
1269
1270         if (tty->stopped && !tty->flow_stopped && I_IXON(tty) && I_IXANY(tty)) {
1271                 start_tty(tty);
1272                 process_echoes(tty);
1273         }
1274
1275         if (c == '\r') {
1276                 if (I_IGNCR(tty))
1277                         return 0;
1278                 if (I_ICRNL(tty))
1279                         c = '\n';
1280         } else if (c == '\n' && I_INLCR(tty))
1281                 c = '\r';
1282
1283         if (ldata->icanon) {
1284                 if (c == ERASE_CHAR(tty) || c == KILL_CHAR(tty) ||
1285                     (c == WERASE_CHAR(tty) && L_IEXTEN(tty))) {
1286                         eraser(c, tty);
1287                         commit_echoes(tty);
1288                         return 0;
1289                 }
1290                 if (c == LNEXT_CHAR(tty) && L_IEXTEN(tty)) {
1291                         ldata->lnext = 1;
1292                         if (L_ECHO(tty)) {
1293                                 finish_erasing(ldata);
1294                                 if (L_ECHOCTL(tty)) {
1295                                         echo_char_raw('^', ldata);
1296                                         echo_char_raw('\b', ldata);
1297                                         commit_echoes(tty);
1298                                 }
1299                         }
1300                         return 1;
1301                 }
1302                 if (c == REPRINT_CHAR(tty) && L_ECHO(tty) && L_IEXTEN(tty)) {
1303                         size_t tail = ldata->canon_head;
1304
1305                         finish_erasing(ldata);
1306                         echo_char(c, tty);
1307                         echo_char_raw('\n', ldata);
1308                         while (tail != ldata->read_head) {
1309                                 echo_char(read_buf(ldata, tail), tty);
1310                                 tail++;
1311                         }
1312                         commit_echoes(tty);
1313                         return 0;
1314                 }
1315                 if (c == '\n') {
1316                         if (L_ECHO(tty) || L_ECHONL(tty)) {
1317                                 echo_char_raw('\n', ldata);
1318                                 commit_echoes(tty);
1319                         }
1320                         goto handle_newline;
1321                 }
1322                 if (c == EOF_CHAR(tty)) {
1323                         c = __DISABLED_CHAR;
1324                         goto handle_newline;
1325                 }
1326                 if ((c == EOL_CHAR(tty)) ||
1327                     (c == EOL2_CHAR(tty) && L_IEXTEN(tty))) {
1328                         /*
1329                          * XXX are EOL_CHAR and EOL2_CHAR echoed?!?
1330                          */
1331                         if (L_ECHO(tty)) {
1332                                 /* Record the column of first canon char. */
1333                                 if (ldata->canon_head == ldata->read_head)
1334                                         echo_set_canon_col(ldata);
1335                                 echo_char(c, tty);
1336                                 commit_echoes(tty);
1337                         }
1338                         /*
1339                          * XXX does PARMRK doubling happen for
1340                          * EOL_CHAR and EOL2_CHAR?
1341                          */
1342                         if (c == (unsigned char) '\377' && I_PARMRK(tty))
1343                                 put_tty_queue(c, ldata);
1344
1345 handle_newline:
1346                         set_bit(ldata->read_head & (N_TTY_BUF_SIZE - 1), ldata->read_flags);
1347                         put_tty_queue(c, ldata);
1348                         smp_store_release(&ldata->canon_head, ldata->read_head);
1349                         kill_fasync(&tty->fasync, SIGIO, POLL_IN);
1350                         if (waitqueue_active(&tty->read_wait))
1351                                 wake_up_interruptible_poll(&tty->read_wait, POLLIN);
1352                         return 0;
1353                 }
1354         }
1355
1356         if (L_ECHO(tty)) {
1357                 finish_erasing(ldata);
1358                 if (c == '\n')
1359                         echo_char_raw('\n', ldata);
1360                 else {
1361                         /* Record the column of first canon char. */
1362                         if (ldata->canon_head == ldata->read_head)
1363                                 echo_set_canon_col(ldata);
1364                         echo_char(c, tty);
1365                 }
1366                 commit_echoes(tty);
1367         }
1368
1369         /* PARMRK doubling check */
1370         if (c == (unsigned char) '\377' && I_PARMRK(tty))
1371                 put_tty_queue(c, ldata);
1372
1373         put_tty_queue(c, ldata);
1374         return 0;
1375 }
1376
1377 static inline void
1378 n_tty_receive_char_inline(struct tty_struct *tty, unsigned char c)
1379 {
1380         struct n_tty_data *ldata = tty->disc_data;
1381
1382         if (tty->stopped && !tty->flow_stopped && I_IXON(tty) && I_IXANY(tty)) {
1383                 start_tty(tty);
1384                 process_echoes(tty);
1385         }
1386         if (L_ECHO(tty)) {
1387                 finish_erasing(ldata);
1388                 /* Record the column of first canon char. */
1389                 if (ldata->canon_head == ldata->read_head)
1390                         echo_set_canon_col(ldata);
1391                 echo_char(c, tty);
1392                 commit_echoes(tty);
1393         }
1394         /* PARMRK doubling check */
1395         if (c == (unsigned char) '\377' && I_PARMRK(tty))
1396                 put_tty_queue(c, ldata);
1397         put_tty_queue(c, ldata);
1398 }
1399
1400 static void n_tty_receive_char(struct tty_struct *tty, unsigned char c)
1401 {
1402         n_tty_receive_char_inline(tty, c);
1403 }
1404
1405 static inline void
1406 n_tty_receive_char_fast(struct tty_struct *tty, unsigned char c)
1407 {
1408         struct n_tty_data *ldata = tty->disc_data;
1409
1410         if (tty->stopped && !tty->flow_stopped && I_IXON(tty) && I_IXANY(tty)) {
1411                 start_tty(tty);
1412                 process_echoes(tty);
1413         }
1414         if (L_ECHO(tty)) {
1415                 finish_erasing(ldata);
1416                 /* Record the column of first canon char. */
1417                 if (ldata->canon_head == ldata->read_head)
1418                         echo_set_canon_col(ldata);
1419                 echo_char(c, tty);
1420                 commit_echoes(tty);
1421         }
1422         put_tty_queue(c, ldata);
1423 }
1424
1425 static void n_tty_receive_char_closing(struct tty_struct *tty, unsigned char c)
1426 {
1427         if (I_ISTRIP(tty))
1428                 c &= 0x7f;
1429         if (I_IUCLC(tty) && L_IEXTEN(tty))
1430                 c = tolower(c);
1431
1432         if (I_IXON(tty)) {
1433                 if (c == STOP_CHAR(tty))
1434                         stop_tty(tty);
1435                 else if (c == START_CHAR(tty) ||
1436                          (tty->stopped && !tty->flow_stopped && I_IXANY(tty) &&
1437                           c != INTR_CHAR(tty) && c != QUIT_CHAR(tty) &&
1438                           c != SUSP_CHAR(tty))) {
1439                         start_tty(tty);
1440                         process_echoes(tty);
1441                 }
1442         }
1443 }
1444
1445 static void
1446 n_tty_receive_char_flagged(struct tty_struct *tty, unsigned char c, char flag)
1447 {
1448         char buf[64];
1449
1450         switch (flag) {
1451         case TTY_BREAK:
1452                 n_tty_receive_break(tty);
1453                 break;
1454         case TTY_PARITY:
1455         case TTY_FRAME:
1456                 n_tty_receive_parity_error(tty, c);
1457                 break;
1458         case TTY_OVERRUN:
1459                 n_tty_receive_overrun(tty);
1460                 break;
1461         default:
1462                 printk(KERN_ERR "%s: unknown flag %d\n",
1463                        tty_name(tty, buf), flag);
1464                 break;
1465         }
1466 }
1467
1468 static void
1469 n_tty_receive_char_lnext(struct tty_struct *tty, unsigned char c, char flag)
1470 {
1471         struct n_tty_data *ldata = tty->disc_data;
1472
1473         ldata->lnext = 0;
1474         if (likely(flag == TTY_NORMAL)) {
1475                 if (I_ISTRIP(tty))
1476                         c &= 0x7f;
1477                 if (I_IUCLC(tty) && L_IEXTEN(tty))
1478                         c = tolower(c);
1479                 n_tty_receive_char(tty, c);
1480         } else
1481                 n_tty_receive_char_flagged(tty, c, flag);
1482 }
1483
1484 static void
1485 n_tty_receive_buf_real_raw(struct tty_struct *tty, const unsigned char *cp,
1486                            char *fp, int count)
1487 {
1488         struct n_tty_data *ldata = tty->disc_data;
1489         size_t n, head;
1490
1491         head = ldata->read_head & (N_TTY_BUF_SIZE - 1);
1492         n = min_t(size_t, count, N_TTY_BUF_SIZE - head);
1493         memcpy(read_buf_addr(ldata, head), cp, n);
1494         ldata->read_head += n;
1495         cp += n;
1496         count -= n;
1497
1498         head = ldata->read_head & (N_TTY_BUF_SIZE - 1);
1499         n = min_t(size_t, count, N_TTY_BUF_SIZE - head);
1500         memcpy(read_buf_addr(ldata, head), cp, n);
1501         ldata->read_head += n;
1502 }
1503
1504 static void
1505 n_tty_receive_buf_raw(struct tty_struct *tty, const unsigned char *cp,
1506                       char *fp, int count)
1507 {
1508         struct n_tty_data *ldata = tty->disc_data;
1509         char flag = TTY_NORMAL;
1510
1511         while (count--) {
1512                 if (fp)
1513                         flag = *fp++;
1514                 if (likely(flag == TTY_NORMAL))
1515                         put_tty_queue(*cp++, ldata);
1516                 else
1517                         n_tty_receive_char_flagged(tty, *cp++, flag);
1518         }
1519 }
1520
1521 static void
1522 n_tty_receive_buf_closing(struct tty_struct *tty, const unsigned char *cp,
1523                           char *fp, int count)
1524 {
1525         char flag = TTY_NORMAL;
1526
1527         while (count--) {
1528                 if (fp)
1529                         flag = *fp++;
1530                 if (likely(flag == TTY_NORMAL))
1531                         n_tty_receive_char_closing(tty, *cp++);
1532                 else
1533                         n_tty_receive_char_flagged(tty, *cp++, flag);
1534         }
1535 }
1536
1537 static void
1538 n_tty_receive_buf_standard(struct tty_struct *tty, const unsigned char *cp,
1539                           char *fp, int count)
1540 {
1541         struct n_tty_data *ldata = tty->disc_data;
1542         char flag = TTY_NORMAL;
1543
1544         while (count--) {
1545                 if (fp)
1546                         flag = *fp++;
1547                 if (likely(flag == TTY_NORMAL)) {
1548                         unsigned char c = *cp++;
1549
1550                         if (I_ISTRIP(tty))
1551                                 c &= 0x7f;
1552                         if (I_IUCLC(tty) && L_IEXTEN(tty))
1553                                 c = tolower(c);
1554                         if (L_EXTPROC(tty)) {
1555                                 put_tty_queue(c, ldata);
1556                                 continue;
1557                         }
1558                         if (!test_bit(c, ldata->char_map))
1559                                 n_tty_receive_char_inline(tty, c);
1560                         else if (n_tty_receive_char_special(tty, c) && count) {
1561                                 if (fp)
1562                                         flag = *fp++;
1563                                 n_tty_receive_char_lnext(tty, *cp++, flag);
1564                                 count--;
1565                         }
1566                 } else
1567                         n_tty_receive_char_flagged(tty, *cp++, flag);
1568         }
1569 }
1570
1571 static void
1572 n_tty_receive_buf_fast(struct tty_struct *tty, const unsigned char *cp,
1573                        char *fp, int count)
1574 {
1575         struct n_tty_data *ldata = tty->disc_data;
1576         char flag = TTY_NORMAL;
1577
1578         while (count--) {
1579                 if (fp)
1580                         flag = *fp++;
1581                 if (likely(flag == TTY_NORMAL)) {
1582                         unsigned char c = *cp++;
1583
1584                         if (!test_bit(c, ldata->char_map))
1585                                 n_tty_receive_char_fast(tty, c);
1586                         else if (n_tty_receive_char_special(tty, c) && count) {
1587                                 if (fp)
1588                                         flag = *fp++;
1589                                 n_tty_receive_char_lnext(tty, *cp++, flag);
1590                                 count--;
1591                         }
1592                 } else
1593                         n_tty_receive_char_flagged(tty, *cp++, flag);
1594         }
1595 }
1596
1597 static void __receive_buf(struct tty_struct *tty, const unsigned char *cp,
1598                           char *fp, int count)
1599 {
1600         struct n_tty_data *ldata = tty->disc_data;
1601         bool preops = I_ISTRIP(tty) || (I_IUCLC(tty) && L_IEXTEN(tty));
1602
1603         if (ldata->real_raw)
1604                 n_tty_receive_buf_real_raw(tty, cp, fp, count);
1605         else if (ldata->raw || (L_EXTPROC(tty) && !preops))
1606                 n_tty_receive_buf_raw(tty, cp, fp, count);
1607         else if (tty->closing && !L_EXTPROC(tty))
1608                 n_tty_receive_buf_closing(tty, cp, fp, count);
1609         else {
1610                 if (ldata->lnext) {
1611                         char flag = TTY_NORMAL;
1612
1613                         if (fp)
1614                                 flag = *fp++;
1615                         n_tty_receive_char_lnext(tty, *cp++, flag);
1616                         count--;
1617                 }
1618
1619                 if (!preops && !I_PARMRK(tty))
1620                         n_tty_receive_buf_fast(tty, cp, fp, count);
1621                 else
1622                         n_tty_receive_buf_standard(tty, cp, fp, count);
1623
1624                 flush_echoes(tty);
1625                 if (tty->ops->flush_chars)
1626                         tty->ops->flush_chars(tty);
1627         }
1628
1629         if (ldata->icanon && !L_EXTPROC(tty))
1630                 return;
1631
1632         /* publish read_head to consumer */
1633         smp_store_release(&ldata->commit_head, ldata->read_head);
1634
1635         if ((read_cnt(ldata) >= ldata->minimum_to_wake) || L_EXTPROC(tty)) {
1636                 kill_fasync(&tty->fasync, SIGIO, POLL_IN);
1637                 if (waitqueue_active(&tty->read_wait))
1638                         wake_up_interruptible_poll(&tty->read_wait, POLLIN);
1639         }
1640 }
1641
1642 /**
1643  *      n_tty_receive_buf_common        -       process input
1644  *      @tty: device to receive input
1645  *      @cp: input chars
1646  *      @fp: flags for each char (if NULL, all chars are TTY_NORMAL)
1647  *      @count: number of input chars in @cp
1648  *
1649  *      Called by the terminal driver when a block of characters has
1650  *      been received. This function must be called from soft contexts
1651  *      not from interrupt context. The driver is responsible for making
1652  *      calls one at a time and in order (or using flush_to_ldisc)
1653  *
1654  *      Returns the # of input chars from @cp which were processed.
1655  *
1656  *      In canonical mode, the maximum line length is 4096 chars (including
1657  *      the line termination char); lines longer than 4096 chars are
1658  *      truncated. After 4095 chars, input data is still processed but
1659  *      not stored. Overflow processing ensures the tty can always
1660  *      receive more input until at least one line can be read.
1661  *
1662  *      In non-canonical mode, the read buffer will only accept 4095 chars;
1663  *      this provides the necessary space for a newline char if the input
1664  *      mode is switched to canonical.
1665  *
1666  *      Note it is possible for the read buffer to _contain_ 4096 chars
1667  *      in non-canonical mode: the read buffer could already contain the
1668  *      maximum canon line of 4096 chars when the mode is switched to
1669  *      non-canonical.
1670  *
1671  *      n_tty_receive_buf()/producer path:
1672  *              claims non-exclusive termios_rwsem
1673  *              publishes commit_head or canon_head
1674  */
1675 static int
1676 n_tty_receive_buf_common(struct tty_struct *tty, const unsigned char *cp,
1677                          char *fp, int count, int flow)
1678 {
1679         struct n_tty_data *ldata = tty->disc_data;
1680         int room, n, rcvd = 0, overflow;
1681
1682         down_read(&tty->termios_rwsem);
1683
1684         while (1) {
1685                 /*
1686                  * When PARMRK is set, each input char may take up to 3 chars
1687                  * in the read buf; reduce the buffer space avail by 3x
1688                  *
1689                  * If we are doing input canonicalization, and there are no
1690                  * pending newlines, let characters through without limit, so
1691                  * that erase characters will be handled.  Other excess
1692                  * characters will be beeped.
1693                  *
1694                  * paired with store in *_copy_from_read_buf() -- guarantees
1695                  * the consumer has loaded the data in read_buf up to the new
1696                  * read_tail (so this producer will not overwrite unread data)
1697                  */
1698                 size_t tail = smp_load_acquire(&ldata->read_tail);
1699
1700                 room = N_TTY_BUF_SIZE - (ldata->read_head - tail);
1701                 if (I_PARMRK(tty))
1702                         room = (room + 2) / 3;
1703                 room--;
1704                 if (room <= 0) {
1705                         overflow = ldata->icanon && ldata->canon_head == tail;
1706                         if (overflow && room < 0)
1707                                 ldata->read_head--;
1708                         room = overflow;
1709                         ldata->no_room = flow && !room;
1710                 } else
1711                         overflow = 0;
1712
1713                 n = min(count, room);
1714                 if (!n)
1715                         break;
1716
1717                 /* ignore parity errors if handling overflow */
1718                 if (!overflow || !fp || *fp != TTY_PARITY)
1719                         __receive_buf(tty, cp, fp, n);
1720
1721                 cp += n;
1722                 if (fp)
1723                         fp += n;
1724                 count -= n;
1725                 rcvd += n;
1726         }
1727
1728         tty->receive_room = room;
1729
1730         /* Unthrottle if handling overflow on pty */
1731         if (tty->driver->type == TTY_DRIVER_TYPE_PTY) {
1732                 if (overflow) {
1733                         tty_set_flow_change(tty, TTY_UNTHROTTLE_SAFE);
1734                         tty_unthrottle_safe(tty);
1735                         __tty_set_flow_change(tty, 0);
1736                 }
1737         } else
1738                 n_tty_check_throttle(tty);
1739
1740         up_read(&tty->termios_rwsem);
1741
1742         return rcvd;
1743 }
1744
1745 static void n_tty_receive_buf(struct tty_struct *tty, const unsigned char *cp,
1746                               char *fp, int count)
1747 {
1748         n_tty_receive_buf_common(tty, cp, fp, count, 0);
1749 }
1750
1751 static int n_tty_receive_buf2(struct tty_struct *tty, const unsigned char *cp,
1752                               char *fp, int count)
1753 {
1754         return n_tty_receive_buf_common(tty, cp, fp, count, 1);
1755 }
1756
1757 int is_ignored(int sig)
1758 {
1759         return (sigismember(&current->blocked, sig) ||
1760                 current->sighand->action[sig-1].sa.sa_handler == SIG_IGN);
1761 }
1762
1763 /**
1764  *      n_tty_set_termios       -       termios data changed
1765  *      @tty: terminal
1766  *      @old: previous data
1767  *
1768  *      Called by the tty layer when the user changes termios flags so
1769  *      that the line discipline can plan ahead. This function cannot sleep
1770  *      and is protected from re-entry by the tty layer. The user is
1771  *      guaranteed that this function will not be re-entered or in progress
1772  *      when the ldisc is closed.
1773  *
1774  *      Locking: Caller holds tty->termios_rwsem
1775  */
1776
1777 static void n_tty_set_termios(struct tty_struct *tty, struct ktermios *old)
1778 {
1779         struct n_tty_data *ldata = tty->disc_data;
1780
1781         if (!old || (old->c_lflag ^ tty->termios.c_lflag) & ICANON) {
1782                 bitmap_zero(ldata->read_flags, N_TTY_BUF_SIZE);
1783                 ldata->line_start = ldata->read_tail;
1784                 if (!L_ICANON(tty) || !read_cnt(ldata)) {
1785                         ldata->canon_head = ldata->read_tail;
1786                         ldata->push = 0;
1787                 } else {
1788                         set_bit((ldata->read_head - 1) & (N_TTY_BUF_SIZE - 1),
1789                                 ldata->read_flags);
1790                         ldata->canon_head = ldata->read_head;
1791                         ldata->push = 1;
1792                 }
1793                 ldata->commit_head = ldata->read_head;
1794                 ldata->erasing = 0;
1795                 ldata->lnext = 0;
1796         }
1797
1798         ldata->icanon = (L_ICANON(tty) != 0);
1799
1800         if (I_ISTRIP(tty) || I_IUCLC(tty) || I_IGNCR(tty) ||
1801             I_ICRNL(tty) || I_INLCR(tty) || L_ICANON(tty) ||
1802             I_IXON(tty) || L_ISIG(tty) || L_ECHO(tty) ||
1803             I_PARMRK(tty)) {
1804                 bitmap_zero(ldata->char_map, 256);
1805
1806                 if (I_IGNCR(tty) || I_ICRNL(tty))
1807                         set_bit('\r', ldata->char_map);
1808                 if (I_INLCR(tty))
1809                         set_bit('\n', ldata->char_map);
1810
1811                 if (L_ICANON(tty)) {
1812                         set_bit(ERASE_CHAR(tty), ldata->char_map);
1813                         set_bit(KILL_CHAR(tty), ldata->char_map);
1814                         set_bit(EOF_CHAR(tty), ldata->char_map);
1815                         set_bit('\n', ldata->char_map);
1816                         set_bit(EOL_CHAR(tty), ldata->char_map);
1817                         if (L_IEXTEN(tty)) {
1818                                 set_bit(WERASE_CHAR(tty), ldata->char_map);
1819                                 set_bit(LNEXT_CHAR(tty), ldata->char_map);
1820                                 set_bit(EOL2_CHAR(tty), ldata->char_map);
1821                                 if (L_ECHO(tty))
1822                                         set_bit(REPRINT_CHAR(tty),
1823                                                 ldata->char_map);
1824                         }
1825                 }
1826                 if (I_IXON(tty)) {
1827                         set_bit(START_CHAR(tty), ldata->char_map);
1828                         set_bit(STOP_CHAR(tty), ldata->char_map);
1829                 }
1830                 if (L_ISIG(tty)) {
1831                         set_bit(INTR_CHAR(tty), ldata->char_map);
1832                         set_bit(QUIT_CHAR(tty), ldata->char_map);
1833                         set_bit(SUSP_CHAR(tty), ldata->char_map);
1834                 }
1835                 clear_bit(__DISABLED_CHAR, ldata->char_map);
1836                 ldata->raw = 0;
1837                 ldata->real_raw = 0;
1838         } else {
1839                 ldata->raw = 1;
1840                 if ((I_IGNBRK(tty) || (!I_BRKINT(tty) && !I_PARMRK(tty))) &&
1841                     (I_IGNPAR(tty) || !I_INPCK(tty)) &&
1842                     (tty->driver->flags & TTY_DRIVER_REAL_RAW))
1843                         ldata->real_raw = 1;
1844                 else
1845                         ldata->real_raw = 0;
1846         }
1847         /*
1848          * Fix tty hang when I_IXON(tty) is cleared, but the tty
1849          * been stopped by STOP_CHAR(tty) before it.
1850          */
1851         if (!I_IXON(tty) && old && (old->c_iflag & IXON) && !tty->flow_stopped) {
1852                 start_tty(tty);
1853                 process_echoes(tty);
1854         }
1855
1856         /* The termios change make the tty ready for I/O */
1857         if (waitqueue_active(&tty->write_wait))
1858                 wake_up_interruptible(&tty->write_wait);
1859         if (waitqueue_active(&tty->read_wait))
1860                 wake_up_interruptible(&tty->read_wait);
1861 }
1862
1863 /**
1864  *      n_tty_close             -       close the ldisc for this tty
1865  *      @tty: device
1866  *
1867  *      Called from the terminal layer when this line discipline is
1868  *      being shut down, either because of a close or becsuse of a
1869  *      discipline change. The function will not be called while other
1870  *      ldisc methods are in progress.
1871  */
1872
1873 static void n_tty_close(struct tty_struct *tty)
1874 {
1875         struct n_tty_data *ldata = tty->disc_data;
1876
1877         if (tty->link)
1878                 n_tty_packet_mode_flush(tty);
1879
1880         vfree(ldata);
1881         tty->disc_data = NULL;
1882 }
1883
1884 /**
1885  *      n_tty_open              -       open an ldisc
1886  *      @tty: terminal to open
1887  *
1888  *      Called when this line discipline is being attached to the
1889  *      terminal device. Can sleep. Called serialized so that no
1890  *      other events will occur in parallel. No further open will occur
1891  *      until a close.
1892  */
1893
1894 static int n_tty_open(struct tty_struct *tty)
1895 {
1896         struct n_tty_data *ldata;
1897
1898         /* Currently a malloc failure here can panic */
1899         ldata = vmalloc(sizeof(*ldata));
1900         if (!ldata)
1901                 goto err;
1902
1903         ldata->overrun_time = jiffies;
1904         mutex_init(&ldata->atomic_read_lock);
1905         mutex_init(&ldata->output_lock);
1906
1907         tty->disc_data = ldata;
1908         reset_buffer_flags(tty->disc_data);
1909         ldata->column = 0;
1910         ldata->canon_column = 0;
1911         ldata->minimum_to_wake = 1;
1912         ldata->num_overrun = 0;
1913         ldata->no_room = 0;
1914         ldata->lnext = 0;
1915         tty->closing = 0;
1916         /* indicate buffer work may resume */
1917         clear_bit(TTY_LDISC_HALTED, &tty->flags);
1918         n_tty_set_termios(tty, NULL);
1919         tty_unthrottle(tty);
1920
1921         return 0;
1922 err:
1923         return -ENOMEM;
1924 }
1925
1926 static inline int input_available_p(struct tty_struct *tty, int poll)
1927 {
1928         struct n_tty_data *ldata = tty->disc_data;
1929         int amt = poll && !TIME_CHAR(tty) && MIN_CHAR(tty) ? MIN_CHAR(tty) : 1;
1930
1931         if (ldata->icanon && !L_EXTPROC(tty))
1932                 return ldata->canon_head != ldata->read_tail;
1933         else
1934                 return ldata->commit_head - ldata->read_tail >= amt;
1935 }
1936
1937 /**
1938  *      copy_from_read_buf      -       copy read data directly
1939  *      @tty: terminal device
1940  *      @b: user data
1941  *      @nr: size of data
1942  *
1943  *      Helper function to speed up n_tty_read.  It is only called when
1944  *      ICANON is off; it copies characters straight from the tty queue to
1945  *      user space directly.  It can be profitably called twice; once to
1946  *      drain the space from the tail pointer to the (physical) end of the
1947  *      buffer, and once to drain the space from the (physical) beginning of
1948  *      the buffer to head pointer.
1949  *
1950  *      Called under the ldata->atomic_read_lock sem
1951  *
1952  *      n_tty_read()/consumer path:
1953  *              caller holds non-exclusive termios_rwsem
1954  *              read_tail published
1955  */
1956
1957 static int copy_from_read_buf(struct tty_struct *tty,
1958                                       unsigned char __user **b,
1959                                       size_t *nr)
1960
1961 {
1962         struct n_tty_data *ldata = tty->disc_data;
1963         int retval;
1964         size_t n;
1965         bool is_eof;
1966         size_t head = smp_load_acquire(&ldata->commit_head);
1967         size_t tail = ldata->read_tail & (N_TTY_BUF_SIZE - 1);
1968
1969         retval = 0;
1970         n = min(head - ldata->read_tail, N_TTY_BUF_SIZE - tail);
1971         n = min(*nr, n);
1972         if (n) {
1973                 retval = copy_to_user(*b, read_buf_addr(ldata, tail), n);
1974                 n -= retval;
1975                 is_eof = n == 1 && read_buf(ldata, tail) == EOF_CHAR(tty);
1976                 tty_audit_add_data(tty, read_buf_addr(ldata, tail), n,
1977                                 ldata->icanon);
1978                 smp_store_release(&ldata->read_tail, ldata->read_tail + n);
1979                 /* Turn single EOF into zero-length read */
1980                 if (L_EXTPROC(tty) && ldata->icanon && is_eof &&
1981                     (head == ldata->read_tail))
1982                         n = 0;
1983                 *b += n;
1984                 *nr -= n;
1985         }
1986         return retval;
1987 }
1988
1989 /**
1990  *      canon_copy_from_read_buf        -       copy read data in canonical mode
1991  *      @tty: terminal device
1992  *      @b: user data
1993  *      @nr: size of data
1994  *
1995  *      Helper function for n_tty_read.  It is only called when ICANON is on;
1996  *      it copies one line of input up to and including the line-delimiting
1997  *      character into the user-space buffer.
1998  *
1999  *      NB: When termios is changed from non-canonical to canonical mode and
2000  *      the read buffer contains data, n_tty_set_termios() simulates an EOF
2001  *      push (as if C-d were input) _without_ the DISABLED_CHAR in the buffer.
2002  *      This causes data already processed as input to be immediately available
2003  *      as input although a newline has not been received.
2004  *
2005  *      Called under the atomic_read_lock mutex
2006  *
2007  *      n_tty_read()/consumer path:
2008  *              caller holds non-exclusive termios_rwsem
2009  *              read_tail published
2010  */
2011
2012 static int canon_copy_from_read_buf(struct tty_struct *tty,
2013                                     unsigned char __user **b,
2014                                     size_t *nr)
2015 {
2016         struct n_tty_data *ldata = tty->disc_data;
2017         size_t n, size, more, c;
2018         size_t eol;
2019         size_t tail;
2020         int ret, found = 0;
2021         bool eof_push = 0;
2022
2023         /* N.B. avoid overrun if nr == 0 */
2024         n = min(*nr, smp_load_acquire(&ldata->canon_head) - ldata->read_tail);
2025         if (!n)
2026                 return 0;
2027
2028         tail = ldata->read_tail & (N_TTY_BUF_SIZE - 1);
2029         size = min_t(size_t, tail + n, N_TTY_BUF_SIZE);
2030
2031         n_tty_trace("%s: nr:%zu tail:%zu n:%zu size:%zu\n",
2032                     __func__, *nr, tail, n, size);
2033
2034         eol = find_next_bit(ldata->read_flags, size, tail);
2035         more = n - (size - tail);
2036         if (eol == N_TTY_BUF_SIZE && more) {
2037                 /* scan wrapped without finding set bit */
2038                 eol = find_next_bit(ldata->read_flags, more, 0);
2039                 if (eol != more)
2040                         found = 1;
2041         } else if (eol != size)
2042                 found = 1;
2043
2044         size = N_TTY_BUF_SIZE - tail;
2045         n = eol - tail;
2046         if (n > 4096)
2047                 n += 4096;
2048         n += found;
2049         c = n;
2050
2051         if (found && !ldata->push && read_buf(ldata, eol) == __DISABLED_CHAR) {
2052                 n--;
2053                 eof_push = !n && ldata->read_tail != ldata->line_start;
2054         }
2055
2056         n_tty_trace("%s: eol:%zu found:%d n:%zu c:%zu size:%zu more:%zu\n",
2057                     __func__, eol, found, n, c, size, more);
2058
2059         if (n > size) {
2060                 ret = copy_to_user(*b, read_buf_addr(ldata, tail), size);
2061                 if (ret)
2062                         return -EFAULT;
2063                 ret = copy_to_user(*b + size, ldata->read_buf, n - size);
2064         } else
2065                 ret = copy_to_user(*b, read_buf_addr(ldata, tail), n);
2066
2067         if (ret)
2068                 return -EFAULT;
2069         *b += n;
2070         *nr -= n;
2071
2072         if (found)
2073                 clear_bit(eol, ldata->read_flags);
2074         smp_store_release(&ldata->read_tail, ldata->read_tail + c);
2075
2076         if (found) {
2077                 if (!ldata->push)
2078                         ldata->line_start = ldata->read_tail;
2079                 else
2080                         ldata->push = 0;
2081                 tty_audit_push(tty);
2082         }
2083         return eof_push ? -EAGAIN : 0;
2084 }
2085
2086 extern ssize_t redirected_tty_write(struct file *, const char __user *,
2087                                                         size_t, loff_t *);
2088
2089 /**
2090  *      job_control             -       check job control
2091  *      @tty: tty
2092  *      @file: file handle
2093  *
2094  *      Perform job control management checks on this file/tty descriptor
2095  *      and if appropriate send any needed signals and return a negative
2096  *      error code if action should be taken.
2097  *
2098  *      Locking: redirected write test is safe
2099  *               current->signal->tty check is safe
2100  *               ctrl_lock to safely reference tty->pgrp
2101  */
2102
2103 static int job_control(struct tty_struct *tty, struct file *file)
2104 {
2105         /* Job control check -- must be done at start and after
2106            every sleep (POSIX.1 7.1.1.4). */
2107         /* NOTE: not yet done after every sleep pending a thorough
2108            check of the logic of this change. -- jlc */
2109         /* don't stop on /dev/console */
2110         if (file->f_op->write == redirected_tty_write ||
2111             current->signal->tty != tty)
2112                 return 0;
2113
2114         spin_lock_irq(&tty->ctrl_lock);
2115         if (!tty->pgrp)
2116                 printk(KERN_ERR "n_tty_read: no tty->pgrp!\n");
2117         else if (task_pgrp(current) != tty->pgrp) {
2118                 spin_unlock_irq(&tty->ctrl_lock);
2119                 if (is_ignored(SIGTTIN) || is_current_pgrp_orphaned())
2120                         return -EIO;
2121                 kill_pgrp(task_pgrp(current), SIGTTIN, 1);
2122                 set_thread_flag(TIF_SIGPENDING);
2123                 return -ERESTARTSYS;
2124         }
2125         spin_unlock_irq(&tty->ctrl_lock);
2126         return 0;
2127 }
2128
2129
2130 /**
2131  *      n_tty_read              -       read function for tty
2132  *      @tty: tty device
2133  *      @file: file object
2134  *      @buf: userspace buffer pointer
2135  *      @nr: size of I/O
2136  *
2137  *      Perform reads for the line discipline. We are guaranteed that the
2138  *      line discipline will not be closed under us but we may get multiple
2139  *      parallel readers and must handle this ourselves. We may also get
2140  *      a hangup. Always called in user context, may sleep.
2141  *
2142  *      This code must be sure never to sleep through a hangup.
2143  *
2144  *      n_tty_read()/consumer path:
2145  *              claims non-exclusive termios_rwsem
2146  *              publishes read_tail
2147  */
2148
2149 static ssize_t n_tty_read(struct tty_struct *tty, struct file *file,
2150                          unsigned char __user *buf, size_t nr)
2151 {
2152         struct n_tty_data *ldata = tty->disc_data;
2153         unsigned char __user *b = buf;
2154         DEFINE_WAIT_FUNC(wait, woken_wake_function);
2155         int c;
2156         int minimum, time;
2157         ssize_t retval = 0;
2158         long timeout;
2159         int packet;
2160         size_t tail;
2161
2162         c = job_control(tty, file);
2163         if (c < 0)
2164                 return c;
2165
2166         /*
2167          *      Internal serialization of reads.
2168          */
2169         if (file->f_flags & O_NONBLOCK) {
2170                 if (!mutex_trylock(&ldata->atomic_read_lock))
2171                         return -EAGAIN;
2172         } else {
2173                 if (mutex_lock_interruptible(&ldata->atomic_read_lock))
2174                         return -ERESTARTSYS;
2175         }
2176
2177         down_read(&tty->termios_rwsem);
2178
2179         minimum = time = 0;
2180         timeout = MAX_SCHEDULE_TIMEOUT;
2181         if (!ldata->icanon) {
2182                 minimum = MIN_CHAR(tty);
2183                 if (minimum) {
2184                         time = (HZ / 10) * TIME_CHAR(tty);
2185                         if (time)
2186                                 ldata->minimum_to_wake = 1;
2187                         else if (!waitqueue_active(&tty->read_wait) ||
2188                                  (ldata->minimum_to_wake > minimum))
2189                                 ldata->minimum_to_wake = minimum;
2190                 } else {
2191                         timeout = (HZ / 10) * TIME_CHAR(tty);
2192                         ldata->minimum_to_wake = minimum = 1;
2193                 }
2194         }
2195
2196         packet = tty->packet;
2197         tail = ldata->read_tail;
2198
2199         add_wait_queue(&tty->read_wait, &wait);
2200         while (nr) {
2201                 /* First test for status change. */
2202                 if (packet && tty->link->ctrl_status) {
2203                         unsigned char cs;
2204                         if (b != buf)
2205                                 break;
2206                         spin_lock_irq(&tty->link->ctrl_lock);
2207                         cs = tty->link->ctrl_status;
2208                         tty->link->ctrl_status = 0;
2209                         spin_unlock_irq(&tty->link->ctrl_lock);
2210                         if (tty_put_user(tty, cs, b++)) {
2211                                 retval = -EFAULT;
2212                                 b--;
2213                                 break;
2214                         }
2215                         nr--;
2216                         break;
2217                 }
2218
2219                 if (((minimum - (b - buf)) < ldata->minimum_to_wake) &&
2220                     ((minimum - (b - buf)) >= 1))
2221                         ldata->minimum_to_wake = (minimum - (b - buf));
2222
2223                 if (!input_available_p(tty, 0)) {
2224                         if (test_bit(TTY_OTHER_CLOSED, &tty->flags)) {
2225                                 retval = -EIO;
2226                                 break;
2227                         }
2228                         if (tty_hung_up_p(file))
2229                                 break;
2230                         if (!timeout)
2231                                 break;
2232                         if (file->f_flags & O_NONBLOCK) {
2233                                 retval = -EAGAIN;
2234                                 break;
2235                         }
2236                         if (signal_pending(current)) {
2237                                 retval = -ERESTARTSYS;
2238                                 break;
2239                         }
2240                         up_read(&tty->termios_rwsem);
2241
2242                         timeout = wait_woken(&wait, TASK_INTERRUPTIBLE,
2243                                              timeout);
2244
2245                         down_read(&tty->termios_rwsem);
2246                         continue;
2247                 }
2248
2249                 if (ldata->icanon && !L_EXTPROC(tty)) {
2250                         retval = canon_copy_from_read_buf(tty, &b, &nr);
2251                         if (retval == -EAGAIN) {
2252                                 retval = 0;
2253                                 continue;
2254                         } else if (retval)
2255                                 break;
2256                 } else {
2257                         int uncopied;
2258
2259                         /* Deal with packet mode. */
2260                         if (packet && b == buf) {
2261                                 if (tty_put_user(tty, TIOCPKT_DATA, b++)) {
2262                                         retval = -EFAULT;
2263                                         b--;
2264                                         break;
2265                                 }
2266                                 nr--;
2267                         }
2268
2269                         uncopied = copy_from_read_buf(tty, &b, &nr);
2270                         uncopied += copy_from_read_buf(tty, &b, &nr);
2271                         if (uncopied) {
2272                                 retval = -EFAULT;
2273                                 break;
2274                         }
2275                 }
2276
2277                 n_tty_check_unthrottle(tty);
2278
2279                 if (b - buf >= minimum)
2280                         break;
2281                 if (time)
2282                         timeout = time;
2283         }
2284         if (tail != ldata->read_tail)
2285                 n_tty_kick_worker(tty);
2286         up_read(&tty->termios_rwsem);
2287
2288         remove_wait_queue(&tty->read_wait, &wait);
2289         if (!waitqueue_active(&tty->read_wait))
2290                 ldata->minimum_to_wake = minimum;
2291
2292         mutex_unlock(&ldata->atomic_read_lock);
2293
2294         if (b - buf)
2295                 retval = b - buf;
2296
2297         return retval;
2298 }
2299
2300 /**
2301  *      n_tty_write             -       write function for tty
2302  *      @tty: tty device
2303  *      @file: file object
2304  *      @buf: userspace buffer pointer
2305  *      @nr: size of I/O
2306  *
2307  *      Write function of the terminal device.  This is serialized with
2308  *      respect to other write callers but not to termios changes, reads
2309  *      and other such events.  Since the receive code will echo characters,
2310  *      thus calling driver write methods, the output_lock is used in
2311  *      the output processing functions called here as well as in the
2312  *      echo processing function to protect the column state and space
2313  *      left in the buffer.
2314  *
2315  *      This code must be sure never to sleep through a hangup.
2316  *
2317  *      Locking: output_lock to protect column state and space left
2318  *               (note that the process_output*() functions take this
2319  *                lock themselves)
2320  */
2321
2322 static ssize_t n_tty_write(struct tty_struct *tty, struct file *file,
2323                            const unsigned char *buf, size_t nr)
2324 {
2325         const unsigned char *b = buf;
2326         DEFINE_WAIT_FUNC(wait, woken_wake_function);
2327         int c;
2328         ssize_t retval = 0;
2329
2330         /* Job control check -- must be done at start (POSIX.1 7.1.1.4). */
2331         if (L_TOSTOP(tty) && file->f_op->write != redirected_tty_write) {
2332                 retval = tty_check_change(tty);
2333                 if (retval)
2334                         return retval;
2335         }
2336
2337         down_read(&tty->termios_rwsem);
2338
2339         /* Write out any echoed characters that are still pending */
2340         process_echoes(tty);
2341
2342         add_wait_queue(&tty->write_wait, &wait);
2343         while (1) {
2344                 if (signal_pending(current)) {
2345                         retval = -ERESTARTSYS;
2346                         break;
2347                 }
2348                 if (tty_hung_up_p(file) || (tty->link && !tty->link->count)) {
2349                         retval = -EIO;
2350                         break;
2351                 }
2352                 if (O_OPOST(tty)) {
2353                         while (nr > 0) {
2354                                 ssize_t num = process_output_block(tty, b, nr);
2355                                 if (num < 0) {
2356                                         if (num == -EAGAIN)
2357                                                 break;
2358                                         retval = num;
2359                                         goto break_out;
2360                                 }
2361                                 b += num;
2362                                 nr -= num;
2363                                 if (nr == 0)
2364                                         break;
2365                                 c = *b;
2366                                 if (process_output(c, tty) < 0)
2367                                         break;
2368                                 b++; nr--;
2369                         }
2370                         if (tty->ops->flush_chars)
2371                                 tty->ops->flush_chars(tty);
2372                 } else {
2373                         struct n_tty_data *ldata = tty->disc_data;
2374
2375                         while (nr > 0) {
2376                                 mutex_lock(&ldata->output_lock);
2377                                 c = tty->ops->write(tty, b, nr);
2378                                 mutex_unlock(&ldata->output_lock);
2379                                 if (c < 0) {
2380                                         retval = c;
2381                                         goto break_out;
2382                                 }
2383                                 if (!c)
2384                                         break;
2385                                 b += c;
2386                                 nr -= c;
2387                         }
2388                 }
2389                 if (!nr)
2390                         break;
2391                 if (file->f_flags & O_NONBLOCK) {
2392                         retval = -EAGAIN;
2393                         break;
2394                 }
2395                 up_read(&tty->termios_rwsem);
2396
2397                 wait_woken(&wait, TASK_INTERRUPTIBLE, MAX_SCHEDULE_TIMEOUT);
2398
2399                 down_read(&tty->termios_rwsem);
2400         }
2401 break_out:
2402         remove_wait_queue(&tty->write_wait, &wait);
2403         if (b - buf != nr && tty->fasync)
2404                 set_bit(TTY_DO_WRITE_WAKEUP, &tty->flags);
2405         up_read(&tty->termios_rwsem);
2406         return (b - buf) ? b - buf : retval;
2407 }
2408
2409 /**
2410  *      n_tty_poll              -       poll method for N_TTY
2411  *      @tty: terminal device
2412  *      @file: file accessing it
2413  *      @wait: poll table
2414  *
2415  *      Called when the line discipline is asked to poll() for data or
2416  *      for special events. This code is not serialized with respect to
2417  *      other events save open/close.
2418  *
2419  *      This code must be sure never to sleep through a hangup.
2420  *      Called without the kernel lock held - fine
2421  */
2422
2423 static unsigned int n_tty_poll(struct tty_struct *tty, struct file *file,
2424                                                         poll_table *wait)
2425 {
2426         struct n_tty_data *ldata = tty->disc_data;
2427         unsigned int mask = 0;
2428
2429         poll_wait(file, &tty->read_wait, wait);
2430         poll_wait(file, &tty->write_wait, wait);
2431         if (input_available_p(tty, 1))
2432                 mask |= POLLIN | POLLRDNORM;
2433         if (tty->packet && tty->link->ctrl_status)
2434                 mask |= POLLPRI | POLLIN | POLLRDNORM;
2435         if (test_bit(TTY_OTHER_CLOSED, &tty->flags))
2436                 mask |= POLLHUP;
2437         if (tty_hung_up_p(file))
2438                 mask |= POLLHUP;
2439         if (!(mask & (POLLHUP | POLLIN | POLLRDNORM))) {
2440                 if (MIN_CHAR(tty) && !TIME_CHAR(tty))
2441                         ldata->minimum_to_wake = MIN_CHAR(tty);
2442                 else
2443                         ldata->minimum_to_wake = 1;
2444         }
2445         if (tty->ops->write && !tty_is_writelocked(tty) &&
2446                         tty_chars_in_buffer(tty) < WAKEUP_CHARS &&
2447                         tty_write_room(tty) > 0)
2448                 mask |= POLLOUT | POLLWRNORM;
2449         return mask;
2450 }
2451
2452 static unsigned long inq_canon(struct n_tty_data *ldata)
2453 {
2454         size_t nr, head, tail;
2455
2456         if (ldata->canon_head == ldata->read_tail)
2457                 return 0;
2458         head = ldata->canon_head;
2459         tail = ldata->read_tail;
2460         nr = head - tail;
2461         /* Skip EOF-chars.. */
2462         while (head != tail) {
2463                 if (test_bit(tail & (N_TTY_BUF_SIZE - 1), ldata->read_flags) &&
2464                     read_buf(ldata, tail) == __DISABLED_CHAR)
2465                         nr--;
2466                 tail++;
2467         }
2468         return nr;
2469 }
2470
2471 static int n_tty_ioctl(struct tty_struct *tty, struct file *file,
2472                        unsigned int cmd, unsigned long arg)
2473 {
2474         struct n_tty_data *ldata = tty->disc_data;
2475         int retval;
2476
2477         switch (cmd) {
2478         case TIOCOUTQ:
2479                 return put_user(tty_chars_in_buffer(tty), (int __user *) arg);
2480         case TIOCINQ:
2481                 down_write(&tty->termios_rwsem);
2482                 if (L_ICANON(tty))
2483                         retval = inq_canon(ldata);
2484                 else
2485                         retval = read_cnt(ldata);
2486                 up_write(&tty->termios_rwsem);
2487                 return put_user(retval, (unsigned int __user *) arg);
2488         default:
2489                 return n_tty_ioctl_helper(tty, file, cmd, arg);
2490         }
2491 }
2492
2493 static void n_tty_fasync(struct tty_struct *tty, int on)
2494 {
2495         struct n_tty_data *ldata = tty->disc_data;
2496
2497         if (!waitqueue_active(&tty->read_wait)) {
2498                 if (on)
2499                         ldata->minimum_to_wake = 1;
2500                 else if (!tty->fasync)
2501                         ldata->minimum_to_wake = N_TTY_BUF_SIZE;
2502         }
2503 }
2504
2505 struct tty_ldisc_ops tty_ldisc_N_TTY = {
2506         .magic           = TTY_LDISC_MAGIC,
2507         .name            = "n_tty",
2508         .open            = n_tty_open,
2509         .close           = n_tty_close,
2510         .flush_buffer    = n_tty_flush_buffer,
2511         .chars_in_buffer = n_tty_chars_in_buffer,
2512         .read            = n_tty_read,
2513         .write           = n_tty_write,
2514         .ioctl           = n_tty_ioctl,
2515         .set_termios     = n_tty_set_termios,
2516         .poll            = n_tty_poll,
2517         .receive_buf     = n_tty_receive_buf,
2518         .write_wakeup    = n_tty_write_wakeup,
2519         .fasync          = n_tty_fasync,
2520         .receive_buf2    = n_tty_receive_buf2,
2521 };
2522
2523 /**
2524  *      n_tty_inherit_ops       -       inherit N_TTY methods
2525  *      @ops: struct tty_ldisc_ops where to save N_TTY methods
2526  *
2527  *      Enables a 'subclass' line discipline to 'inherit' N_TTY
2528  *      methods.
2529  */
2530
2531 void n_tty_inherit_ops(struct tty_ldisc_ops *ops)
2532 {
2533         *ops = tty_ldisc_N_TTY;
2534         ops->owner = NULL;
2535         ops->refcount = ops->flags = 0;
2536 }
2537 EXPORT_SYMBOL_GPL(n_tty_inherit_ops);