9d1e247ee330c4083a4118c580d586383a4547eb
[firefly-linux-kernel-4.4.55.git] / drivers / tty / tty_io.c
1 /*
2  *  Copyright (C) 1991, 1992  Linus Torvalds
3  */
4
5 /*
6  * 'tty_io.c' gives an orthogonal feeling to tty's, be they consoles
7  * or rs-channels. It also implements echoing, cooked mode etc.
8  *
9  * Kill-line thanks to John T Kohl, who also corrected VMIN = VTIME = 0.
10  *
11  * Modified by Theodore Ts'o, 9/14/92, to dynamically allocate the
12  * tty_struct and tty_queue structures.  Previously there was an array
13  * of 256 tty_struct's which was statically allocated, and the
14  * tty_queue structures were allocated at boot time.  Both are now
15  * dynamically allocated only when the tty is open.
16  *
17  * Also restructured routines so that there is more of a separation
18  * between the high-level tty routines (tty_io.c and tty_ioctl.c) and
19  * the low-level tty routines (serial.c, pty.c, console.c).  This
20  * makes for cleaner and more compact code.  -TYT, 9/17/92
21  *
22  * Modified by Fred N. van Kempen, 01/29/93, to add line disciplines
23  * which can be dynamically activated and de-activated by the line
24  * discipline handling modules (like SLIP).
25  *
26  * NOTE: pay no attention to the line discipline code (yet); its
27  * interface is still subject to change in this version...
28  * -- TYT, 1/31/92
29  *
30  * Added functionality to the OPOST tty handling.  No delays, but all
31  * other bits should be there.
32  *      -- Nick Holloway <alfie@dcs.warwick.ac.uk>, 27th May 1993.
33  *
34  * Rewrote canonical mode and added more termios flags.
35  *      -- julian@uhunix.uhcc.hawaii.edu (J. Cowley), 13Jan94
36  *
37  * Reorganized FASYNC support so mouse code can share it.
38  *      -- ctm@ardi.com, 9Sep95
39  *
40  * New TIOCLINUX variants added.
41  *      -- mj@k332.feld.cvut.cz, 19-Nov-95
42  *
43  * Restrict vt switching via ioctl()
44  *      -- grif@cs.ucr.edu, 5-Dec-95
45  *
46  * Move console and virtual terminal code to more appropriate files,
47  * implement CONFIG_VT and generalize console device interface.
48  *      -- Marko Kohtala <Marko.Kohtala@hut.fi>, March 97
49  *
50  * Rewrote tty_init_dev and tty_release_dev to eliminate races.
51  *      -- Bill Hawes <whawes@star.net>, June 97
52  *
53  * Added devfs support.
54  *      -- C. Scott Ananian <cananian@alumni.princeton.edu>, 13-Jan-1998
55  *
56  * Added support for a Unix98-style ptmx device.
57  *      -- C. Scott Ananian <cananian@alumni.princeton.edu>, 14-Jan-1998
58  *
59  * Reduced memory usage for older ARM systems
60  *      -- Russell King <rmk@arm.linux.org.uk>
61  *
62  * Move do_SAK() into process context.  Less stack use in devfs functions.
63  * alloc_tty_struct() always uses kmalloc()
64  *                       -- Andrew Morton <andrewm@uow.edu.eu> 17Mar01
65  */
66
67 #include <linux/types.h>
68 #include <linux/major.h>
69 #include <linux/errno.h>
70 #include <linux/signal.h>
71 #include <linux/fcntl.h>
72 #include <linux/sched.h>
73 #include <linux/interrupt.h>
74 #include <linux/tty.h>
75 #include <linux/tty_driver.h>
76 #include <linux/tty_flip.h>
77 #include <linux/devpts_fs.h>
78 #include <linux/file.h>
79 #include <linux/fdtable.h>
80 #include <linux/console.h>
81 #include <linux/timer.h>
82 #include <linux/ctype.h>
83 #include <linux/kd.h>
84 #include <linux/mm.h>
85 #include <linux/string.h>
86 #include <linux/slab.h>
87 #include <linux/poll.h>
88 #include <linux/proc_fs.h>
89 #include <linux/init.h>
90 #include <linux/module.h>
91 #include <linux/device.h>
92 #include <linux/wait.h>
93 #include <linux/bitops.h>
94 #include <linux/delay.h>
95 #include <linux/seq_file.h>
96 #include <linux/serial.h>
97 #include <linux/ratelimit.h>
98
99 #include <linux/uaccess.h>
100
101 #include <linux/kbd_kern.h>
102 #include <linux/vt_kern.h>
103 #include <linux/selection.h>
104
105 #include <linux/kmod.h>
106 #include <linux/nsproxy.h>
107
108 #undef TTY_DEBUG_HANGUP
109
110 #define TTY_PARANOIA_CHECK 1
111 #define CHECK_TTY_COUNT 1
112
113 struct ktermios tty_std_termios = {     /* for the benefit of tty drivers  */
114         .c_iflag = ICRNL | IXON,
115         .c_oflag = OPOST | ONLCR,
116         .c_cflag = B38400 | CS8 | CREAD | HUPCL,
117         .c_lflag = ISIG | ICANON | ECHO | ECHOE | ECHOK |
118                    ECHOCTL | ECHOKE | IEXTEN,
119         .c_cc = INIT_C_CC,
120         .c_ispeed = 38400,
121         .c_ospeed = 38400
122 };
123
124 EXPORT_SYMBOL(tty_std_termios);
125
126 /* This list gets poked at by procfs and various bits of boot up code. This
127    could do with some rationalisation such as pulling the tty proc function
128    into this file */
129
130 LIST_HEAD(tty_drivers);                 /* linked list of tty drivers */
131
132 /* Mutex to protect creating and releasing a tty. This is shared with
133    vt.c for deeply disgusting hack reasons */
134 DEFINE_MUTEX(tty_mutex);
135 EXPORT_SYMBOL(tty_mutex);
136
137 /* Spinlock to protect the tty->tty_files list */
138 DEFINE_SPINLOCK(tty_files_lock);
139
140 static ssize_t tty_read(struct file *, char __user *, size_t, loff_t *);
141 static ssize_t tty_write(struct file *, const char __user *, size_t, loff_t *);
142 ssize_t redirected_tty_write(struct file *, const char __user *,
143                                                         size_t, loff_t *);
144 static unsigned int tty_poll(struct file *, poll_table *);
145 static int tty_open(struct inode *, struct file *);
146 long tty_ioctl(struct file *file, unsigned int cmd, unsigned long arg);
147 #ifdef CONFIG_COMPAT
148 static long tty_compat_ioctl(struct file *file, unsigned int cmd,
149                                 unsigned long arg);
150 #else
151 #define tty_compat_ioctl NULL
152 #endif
153 static int __tty_fasync(int fd, struct file *filp, int on);
154 static int tty_fasync(int fd, struct file *filp, int on);
155 static void release_tty(struct tty_struct *tty, int idx);
156
157 /**
158  *      free_tty_struct         -       free a disused tty
159  *      @tty: tty struct to free
160  *
161  *      Free the write buffers, tty queue and tty memory itself.
162  *
163  *      Locking: none. Must be called after tty is definitely unused
164  */
165
166 void free_tty_struct(struct tty_struct *tty)
167 {
168         if (!tty)
169                 return;
170         if (tty->dev)
171                 put_device(tty->dev);
172         kfree(tty->write_buf);
173         tty->magic = 0xDEADDEAD;
174         kfree(tty);
175 }
176
177 static inline struct tty_struct *file_tty(struct file *file)
178 {
179         return ((struct tty_file_private *)file->private_data)->tty;
180 }
181
182 int tty_alloc_file(struct file *file)
183 {
184         struct tty_file_private *priv;
185
186         priv = kmalloc(sizeof(*priv), GFP_KERNEL);
187         if (!priv)
188                 return -ENOMEM;
189
190         file->private_data = priv;
191
192         return 0;
193 }
194
195 /* Associate a new file with the tty structure */
196 void tty_add_file(struct tty_struct *tty, struct file *file)
197 {
198         struct tty_file_private *priv = file->private_data;
199
200         priv->tty = tty;
201         priv->file = file;
202
203         spin_lock(&tty_files_lock);
204         list_add(&priv->list, &tty->tty_files);
205         spin_unlock(&tty_files_lock);
206 }
207
208 /**
209  * tty_free_file - free file->private_data
210  *
211  * This shall be used only for fail path handling when tty_add_file was not
212  * called yet.
213  */
214 void tty_free_file(struct file *file)
215 {
216         struct tty_file_private *priv = file->private_data;
217
218         file->private_data = NULL;
219         kfree(priv);
220 }
221
222 /* Delete file from its tty */
223 static void tty_del_file(struct file *file)
224 {
225         struct tty_file_private *priv = file->private_data;
226
227         spin_lock(&tty_files_lock);
228         list_del(&priv->list);
229         spin_unlock(&tty_files_lock);
230         tty_free_file(file);
231 }
232
233
234 #define TTY_NUMBER(tty) ((tty)->index + (tty)->driver->name_base)
235
236 /**
237  *      tty_name        -       return tty naming
238  *      @tty: tty structure
239  *      @buf: buffer for output
240  *
241  *      Convert a tty structure into a name. The name reflects the kernel
242  *      naming policy and if udev is in use may not reflect user space
243  *
244  *      Locking: none
245  */
246
247 char *tty_name(struct tty_struct *tty, char *buf)
248 {
249         if (!tty) /* Hmm.  NULL pointer.  That's fun. */
250                 strcpy(buf, "NULL tty");
251         else
252                 strcpy(buf, tty->name);
253         return buf;
254 }
255
256 EXPORT_SYMBOL(tty_name);
257
258 int tty_paranoia_check(struct tty_struct *tty, struct inode *inode,
259                               const char *routine)
260 {
261 #ifdef TTY_PARANOIA_CHECK
262         if (!tty) {
263                 printk(KERN_WARNING
264                         "null TTY for (%d:%d) in %s\n",
265                         imajor(inode), iminor(inode), routine);
266                 return 1;
267         }
268         if (tty->magic != TTY_MAGIC) {
269                 printk(KERN_WARNING
270                         "bad magic number for tty struct (%d:%d) in %s\n",
271                         imajor(inode), iminor(inode), routine);
272                 return 1;
273         }
274 #endif
275         return 0;
276 }
277
278 static int check_tty_count(struct tty_struct *tty, const char *routine)
279 {
280 #ifdef CHECK_TTY_COUNT
281         struct list_head *p;
282         int count = 0;
283
284         spin_lock(&tty_files_lock);
285         list_for_each(p, &tty->tty_files) {
286                 count++;
287         }
288         spin_unlock(&tty_files_lock);
289         if (tty->driver->type == TTY_DRIVER_TYPE_PTY &&
290             tty->driver->subtype == PTY_TYPE_SLAVE &&
291             tty->link && tty->link->count)
292                 count++;
293         if (tty->count != count) {
294                 printk(KERN_WARNING "Warning: dev (%s) tty->count(%d) "
295                                     "!= #fd's(%d) in %s\n",
296                        tty->name, tty->count, count, routine);
297                 return count;
298         }
299 #endif
300         return 0;
301 }
302
303 /**
304  *      get_tty_driver          -       find device of a tty
305  *      @dev_t: device identifier
306  *      @index: returns the index of the tty
307  *
308  *      This routine returns a tty driver structure, given a device number
309  *      and also passes back the index number.
310  *
311  *      Locking: caller must hold tty_mutex
312  */
313
314 static struct tty_driver *get_tty_driver(dev_t device, int *index)
315 {
316         struct tty_driver *p;
317
318         list_for_each_entry(p, &tty_drivers, tty_drivers) {
319                 dev_t base = MKDEV(p->major, p->minor_start);
320                 if (device < base || device >= base + p->num)
321                         continue;
322                 *index = device - base;
323                 return tty_driver_kref_get(p);
324         }
325         return NULL;
326 }
327
328 #ifdef CONFIG_CONSOLE_POLL
329
330 /**
331  *      tty_find_polling_driver -       find device of a polled tty
332  *      @name: name string to match
333  *      @line: pointer to resulting tty line nr
334  *
335  *      This routine returns a tty driver structure, given a name
336  *      and the condition that the tty driver is capable of polled
337  *      operation.
338  */
339 struct tty_driver *tty_find_polling_driver(char *name, int *line)
340 {
341         struct tty_driver *p, *res = NULL;
342         int tty_line = 0;
343         int len;
344         char *str, *stp;
345
346         for (str = name; *str; str++)
347                 if ((*str >= '0' && *str <= '9') || *str == ',')
348                         break;
349         if (!*str)
350                 return NULL;
351
352         len = str - name;
353         tty_line = simple_strtoul(str, &str, 10);
354
355         mutex_lock(&tty_mutex);
356         /* Search through the tty devices to look for a match */
357         list_for_each_entry(p, &tty_drivers, tty_drivers) {
358                 if (strncmp(name, p->name, len) != 0)
359                         continue;
360                 stp = str;
361                 if (*stp == ',')
362                         stp++;
363                 if (*stp == '\0')
364                         stp = NULL;
365
366                 if (tty_line >= 0 && tty_line < p->num && p->ops &&
367                     p->ops->poll_init && !p->ops->poll_init(p, tty_line, stp)) {
368                         res = tty_driver_kref_get(p);
369                         *line = tty_line;
370                         break;
371                 }
372         }
373         mutex_unlock(&tty_mutex);
374
375         return res;
376 }
377 EXPORT_SYMBOL_GPL(tty_find_polling_driver);
378 #endif
379
380 /**
381  *      tty_check_change        -       check for POSIX terminal changes
382  *      @tty: tty to check
383  *
384  *      If we try to write to, or set the state of, a terminal and we're
385  *      not in the foreground, send a SIGTTOU.  If the signal is blocked or
386  *      ignored, go ahead and perform the operation.  (POSIX 7.2)
387  *
388  *      Locking: ctrl_lock
389  */
390
391 int tty_check_change(struct tty_struct *tty)
392 {
393         unsigned long flags;
394         int ret = 0;
395
396         if (current->signal->tty != tty)
397                 return 0;
398
399         spin_lock_irqsave(&tty->ctrl_lock, flags);
400
401         if (!tty->pgrp) {
402                 printk(KERN_WARNING "tty_check_change: tty->pgrp == NULL!\n");
403                 goto out_unlock;
404         }
405         if (task_pgrp(current) == tty->pgrp)
406                 goto out_unlock;
407         spin_unlock_irqrestore(&tty->ctrl_lock, flags);
408         if (is_ignored(SIGTTOU))
409                 goto out;
410         if (is_current_pgrp_orphaned()) {
411                 ret = -EIO;
412                 goto out;
413         }
414         kill_pgrp(task_pgrp(current), SIGTTOU, 1);
415         set_thread_flag(TIF_SIGPENDING);
416         ret = -ERESTARTSYS;
417 out:
418         return ret;
419 out_unlock:
420         spin_unlock_irqrestore(&tty->ctrl_lock, flags);
421         return ret;
422 }
423
424 EXPORT_SYMBOL(tty_check_change);
425
426 static ssize_t hung_up_tty_read(struct file *file, char __user *buf,
427                                 size_t count, loff_t *ppos)
428 {
429         return 0;
430 }
431
432 static ssize_t hung_up_tty_write(struct file *file, const char __user *buf,
433                                  size_t count, loff_t *ppos)
434 {
435         return -EIO;
436 }
437
438 /* No kernel lock held - none needed ;) */
439 static unsigned int hung_up_tty_poll(struct file *filp, poll_table *wait)
440 {
441         return POLLIN | POLLOUT | POLLERR | POLLHUP | POLLRDNORM | POLLWRNORM;
442 }
443
444 static long hung_up_tty_ioctl(struct file *file, unsigned int cmd,
445                 unsigned long arg)
446 {
447         return cmd == TIOCSPGRP ? -ENOTTY : -EIO;
448 }
449
450 static long hung_up_tty_compat_ioctl(struct file *file,
451                                      unsigned int cmd, unsigned long arg)
452 {
453         return cmd == TIOCSPGRP ? -ENOTTY : -EIO;
454 }
455
456 static const struct file_operations tty_fops = {
457         .llseek         = no_llseek,
458         .read           = tty_read,
459         .write          = tty_write,
460         .poll           = tty_poll,
461         .unlocked_ioctl = tty_ioctl,
462         .compat_ioctl   = tty_compat_ioctl,
463         .open           = tty_open,
464         .release        = tty_release,
465         .fasync         = tty_fasync,
466 };
467
468 static const struct file_operations console_fops = {
469         .llseek         = no_llseek,
470         .read           = tty_read,
471         .write          = redirected_tty_write,
472         .poll           = tty_poll,
473         .unlocked_ioctl = tty_ioctl,
474         .compat_ioctl   = tty_compat_ioctl,
475         .open           = tty_open,
476         .release        = tty_release,
477         .fasync         = tty_fasync,
478 };
479
480 static const struct file_operations hung_up_tty_fops = {
481         .llseek         = no_llseek,
482         .read           = hung_up_tty_read,
483         .write          = hung_up_tty_write,
484         .poll           = hung_up_tty_poll,
485         .unlocked_ioctl = hung_up_tty_ioctl,
486         .compat_ioctl   = hung_up_tty_compat_ioctl,
487         .release        = tty_release,
488 };
489
490 static DEFINE_SPINLOCK(redirect_lock);
491 static struct file *redirect;
492
493
494 void proc_clear_tty(struct task_struct *p)
495 {
496         unsigned long flags;
497         struct tty_struct *tty;
498         spin_lock_irqsave(&p->sighand->siglock, flags);
499         tty = p->signal->tty;
500         p->signal->tty = NULL;
501         spin_unlock_irqrestore(&p->sighand->siglock, flags);
502         tty_kref_put(tty);
503 }
504
505 /**
506  * proc_set_tty -  set the controlling terminal
507  *
508  * Only callable by the session leader and only if it does not already have
509  * a controlling terminal.
510  *
511  * Caller must hold:  tty_lock()
512  *                    a readlock on tasklist_lock
513  *                    sighand lock
514  */
515 static void __proc_set_tty(struct tty_struct *tty)
516 {
517         unsigned long flags;
518
519         spin_lock_irqsave(&tty->ctrl_lock, flags);
520         /*
521          * The session and fg pgrp references will be non-NULL if
522          * tiocsctty() is stealing the controlling tty
523          */
524         put_pid(tty->session);
525         put_pid(tty->pgrp);
526         tty->pgrp = get_pid(task_pgrp(current));
527         spin_unlock_irqrestore(&tty->ctrl_lock, flags);
528         tty->session = get_pid(task_session(current));
529         if (current->signal->tty) {
530                 printk(KERN_DEBUG "tty not NULL!!\n");
531                 tty_kref_put(current->signal->tty);
532         }
533         put_pid(current->signal->tty_old_pgrp);
534         current->signal->tty = tty_kref_get(tty);
535         current->signal->tty_old_pgrp = NULL;
536 }
537
538 static void proc_set_tty(struct tty_struct *tty)
539 {
540         spin_lock_irq(&current->sighand->siglock);
541         __proc_set_tty(tty);
542         spin_unlock_irq(&current->sighand->siglock);
543 }
544
545 struct tty_struct *get_current_tty(void)
546 {
547         struct tty_struct *tty;
548         unsigned long flags;
549
550         spin_lock_irqsave(&current->sighand->siglock, flags);
551         tty = tty_kref_get(current->signal->tty);
552         spin_unlock_irqrestore(&current->sighand->siglock, flags);
553         return tty;
554 }
555 EXPORT_SYMBOL_GPL(get_current_tty);
556
557 static void session_clear_tty(struct pid *session)
558 {
559         struct task_struct *p;
560         do_each_pid_task(session, PIDTYPE_SID, p) {
561                 proc_clear_tty(p);
562         } while_each_pid_task(session, PIDTYPE_SID, p);
563 }
564
565 /**
566  *      tty_wakeup      -       request more data
567  *      @tty: terminal
568  *
569  *      Internal and external helper for wakeups of tty. This function
570  *      informs the line discipline if present that the driver is ready
571  *      to receive more output data.
572  */
573
574 void tty_wakeup(struct tty_struct *tty)
575 {
576         struct tty_ldisc *ld;
577
578         if (test_bit(TTY_DO_WRITE_WAKEUP, &tty->flags)) {
579                 ld = tty_ldisc_ref(tty);
580                 if (ld) {
581                         if (ld->ops->write_wakeup)
582                                 ld->ops->write_wakeup(tty);
583                         tty_ldisc_deref(ld);
584                 }
585         }
586         wake_up_interruptible_poll(&tty->write_wait, POLLOUT);
587 }
588
589 EXPORT_SYMBOL_GPL(tty_wakeup);
590
591 /**
592  *      tty_signal_session_leader       - sends SIGHUP to session leader
593  *      @tty            controlling tty
594  *      @exit_session   if non-zero, signal all foreground group processes
595  *
596  *      Send SIGHUP and SIGCONT to the session leader and its process group.
597  *      Optionally, signal all processes in the foreground process group.
598  *
599  *      Returns the number of processes in the session with this tty
600  *      as their controlling terminal. This value is used to drop
601  *      tty references for those processes.
602  */
603 static int tty_signal_session_leader(struct tty_struct *tty, int exit_session)
604 {
605         struct task_struct *p;
606         int refs = 0;
607         struct pid *tty_pgrp = NULL;
608
609         read_lock(&tasklist_lock);
610         if (tty->session) {
611                 do_each_pid_task(tty->session, PIDTYPE_SID, p) {
612                         spin_lock_irq(&p->sighand->siglock);
613                         if (p->signal->tty == tty) {
614                                 p->signal->tty = NULL;
615                                 /* We defer the dereferences outside fo
616                                    the tasklist lock */
617                                 refs++;
618                         }
619                         if (!p->signal->leader) {
620                                 spin_unlock_irq(&p->sighand->siglock);
621                                 continue;
622                         }
623                         __group_send_sig_info(SIGHUP, SEND_SIG_PRIV, p);
624                         __group_send_sig_info(SIGCONT, SEND_SIG_PRIV, p);
625                         put_pid(p->signal->tty_old_pgrp);  /* A noop */
626                         spin_lock(&tty->ctrl_lock);
627                         tty_pgrp = get_pid(tty->pgrp);
628                         if (tty->pgrp)
629                                 p->signal->tty_old_pgrp = get_pid(tty->pgrp);
630                         spin_unlock(&tty->ctrl_lock);
631                         spin_unlock_irq(&p->sighand->siglock);
632                 } while_each_pid_task(tty->session, PIDTYPE_SID, p);
633         }
634         read_unlock(&tasklist_lock);
635
636         if (tty_pgrp) {
637                 if (exit_session)
638                         kill_pgrp(tty_pgrp, SIGHUP, exit_session);
639                 put_pid(tty_pgrp);
640         }
641
642         return refs;
643 }
644
645 /**
646  *      __tty_hangup            -       actual handler for hangup events
647  *      @work: tty device
648  *
649  *      This can be called by a "kworker" kernel thread.  That is process
650  *      synchronous but doesn't hold any locks, so we need to make sure we
651  *      have the appropriate locks for what we're doing.
652  *
653  *      The hangup event clears any pending redirections onto the hung up
654  *      device. It ensures future writes will error and it does the needed
655  *      line discipline hangup and signal delivery. The tty object itself
656  *      remains intact.
657  *
658  *      Locking:
659  *              BTM
660  *                redirect lock for undoing redirection
661  *                file list lock for manipulating list of ttys
662  *                tty_ldiscs_lock from called functions
663  *                termios_rwsem resetting termios data
664  *                tasklist_lock to walk task list for hangup event
665  *                  ->siglock to protect ->signal/->sighand
666  */
667 static void __tty_hangup(struct tty_struct *tty, int exit_session)
668 {
669         struct file *cons_filp = NULL;
670         struct file *filp, *f = NULL;
671         struct tty_file_private *priv;
672         int    closecount = 0, n;
673         int refs;
674
675         if (!tty)
676                 return;
677
678
679         spin_lock(&redirect_lock);
680         if (redirect && file_tty(redirect) == tty) {
681                 f = redirect;
682                 redirect = NULL;
683         }
684         spin_unlock(&redirect_lock);
685
686         tty_lock(tty);
687
688         if (test_bit(TTY_HUPPED, &tty->flags)) {
689                 tty_unlock(tty);
690                 return;
691         }
692
693         /* some functions below drop BTM, so we need this bit */
694         set_bit(TTY_HUPPING, &tty->flags);
695
696         /* inuse_filps is protected by the single tty lock,
697            this really needs to change if we want to flush the
698            workqueue with the lock held */
699         check_tty_count(tty, "tty_hangup");
700
701         spin_lock(&tty_files_lock);
702         /* This breaks for file handles being sent over AF_UNIX sockets ? */
703         list_for_each_entry(priv, &tty->tty_files, list) {
704                 filp = priv->file;
705                 if (filp->f_op->write == redirected_tty_write)
706                         cons_filp = filp;
707                 if (filp->f_op->write != tty_write)
708                         continue;
709                 closecount++;
710                 __tty_fasync(-1, filp, 0);      /* can't block */
711                 filp->f_op = &hung_up_tty_fops;
712         }
713         spin_unlock(&tty_files_lock);
714
715         refs = tty_signal_session_leader(tty, exit_session);
716         /* Account for the p->signal references we killed */
717         while (refs--)
718                 tty_kref_put(tty);
719
720         /*
721          * it drops BTM and thus races with reopen
722          * we protect the race by TTY_HUPPING
723          */
724         tty_ldisc_hangup(tty);
725
726         spin_lock_irq(&tty->ctrl_lock);
727         clear_bit(TTY_THROTTLED, &tty->flags);
728         clear_bit(TTY_DO_WRITE_WAKEUP, &tty->flags);
729         put_pid(tty->session);
730         put_pid(tty->pgrp);
731         tty->session = NULL;
732         tty->pgrp = NULL;
733         tty->ctrl_status = 0;
734         spin_unlock_irq(&tty->ctrl_lock);
735
736         /*
737          * If one of the devices matches a console pointer, we
738          * cannot just call hangup() because that will cause
739          * tty->count and state->count to go out of sync.
740          * So we just call close() the right number of times.
741          */
742         if (cons_filp) {
743                 if (tty->ops->close)
744                         for (n = 0; n < closecount; n++)
745                                 tty->ops->close(tty, cons_filp);
746         } else if (tty->ops->hangup)
747                 tty->ops->hangup(tty);
748         /*
749          * We don't want to have driver/ldisc interactions beyond
750          * the ones we did here. The driver layer expects no
751          * calls after ->hangup() from the ldisc side. However we
752          * can't yet guarantee all that.
753          */
754         set_bit(TTY_HUPPED, &tty->flags);
755         clear_bit(TTY_HUPPING, &tty->flags);
756
757         tty_unlock(tty);
758
759         if (f)
760                 fput(f);
761 }
762
763 static void do_tty_hangup(struct work_struct *work)
764 {
765         struct tty_struct *tty =
766                 container_of(work, struct tty_struct, hangup_work);
767
768         __tty_hangup(tty, 0);
769 }
770
771 /**
772  *      tty_hangup              -       trigger a hangup event
773  *      @tty: tty to hangup
774  *
775  *      A carrier loss (virtual or otherwise) has occurred on this like
776  *      schedule a hangup sequence to run after this event.
777  */
778
779 void tty_hangup(struct tty_struct *tty)
780 {
781 #ifdef TTY_DEBUG_HANGUP
782         char    buf[64];
783         printk(KERN_DEBUG "%s hangup...\n", tty_name(tty, buf));
784 #endif
785         schedule_work(&tty->hangup_work);
786 }
787
788 EXPORT_SYMBOL(tty_hangup);
789
790 /**
791  *      tty_vhangup             -       process vhangup
792  *      @tty: tty to hangup
793  *
794  *      The user has asked via system call for the terminal to be hung up.
795  *      We do this synchronously so that when the syscall returns the process
796  *      is complete. That guarantee is necessary for security reasons.
797  */
798
799 void tty_vhangup(struct tty_struct *tty)
800 {
801 #ifdef TTY_DEBUG_HANGUP
802         char    buf[64];
803
804         printk(KERN_DEBUG "%s vhangup...\n", tty_name(tty, buf));
805 #endif
806         __tty_hangup(tty, 0);
807 }
808
809 EXPORT_SYMBOL(tty_vhangup);
810
811
812 /**
813  *      tty_vhangup_self        -       process vhangup for own ctty
814  *
815  *      Perform a vhangup on the current controlling tty
816  */
817
818 void tty_vhangup_self(void)
819 {
820         struct tty_struct *tty;
821
822         tty = get_current_tty();
823         if (tty) {
824                 tty_vhangup(tty);
825                 tty_kref_put(tty);
826         }
827 }
828
829 /**
830  *      tty_vhangup_session             -       hangup session leader exit
831  *      @tty: tty to hangup
832  *
833  *      The session leader is exiting and hanging up its controlling terminal.
834  *      Every process in the foreground process group is signalled SIGHUP.
835  *
836  *      We do this synchronously so that when the syscall returns the process
837  *      is complete. That guarantee is necessary for security reasons.
838  */
839
840 static void tty_vhangup_session(struct tty_struct *tty)
841 {
842 #ifdef TTY_DEBUG_HANGUP
843         char    buf[64];
844
845         printk(KERN_DEBUG "%s vhangup session...\n", tty_name(tty, buf));
846 #endif
847         __tty_hangup(tty, 1);
848 }
849
850 /**
851  *      tty_hung_up_p           -       was tty hung up
852  *      @filp: file pointer of tty
853  *
854  *      Return true if the tty has been subject to a vhangup or a carrier
855  *      loss
856  */
857
858 int tty_hung_up_p(struct file *filp)
859 {
860         return (filp->f_op == &hung_up_tty_fops);
861 }
862
863 EXPORT_SYMBOL(tty_hung_up_p);
864
865 /**
866  *      disassociate_ctty       -       disconnect controlling tty
867  *      @on_exit: true if exiting so need to "hang up" the session
868  *
869  *      This function is typically called only by the session leader, when
870  *      it wants to disassociate itself from its controlling tty.
871  *
872  *      It performs the following functions:
873  *      (1)  Sends a SIGHUP and SIGCONT to the foreground process group
874  *      (2)  Clears the tty from being controlling the session
875  *      (3)  Clears the controlling tty for all processes in the
876  *              session group.
877  *
878  *      The argument on_exit is set to 1 if called when a process is
879  *      exiting; it is 0 if called by the ioctl TIOCNOTTY.
880  *
881  *      Locking:
882  *              BTM is taken for hysterical raisins, and held when
883  *                called from no_tty().
884  *                tty_mutex is taken to protect tty
885  *                ->siglock is taken to protect ->signal/->sighand
886  *                tasklist_lock is taken to walk process list for sessions
887  *                  ->siglock is taken to protect ->signal/->sighand
888  */
889
890 void disassociate_ctty(int on_exit)
891 {
892         struct tty_struct *tty;
893
894         if (!current->signal->leader)
895                 return;
896
897         tty = get_current_tty();
898         if (tty) {
899                 if (on_exit && tty->driver->type != TTY_DRIVER_TYPE_PTY) {
900                         tty_vhangup_session(tty);
901                 } else {
902                         struct pid *tty_pgrp = tty_get_pgrp(tty);
903                         if (tty_pgrp) {
904                                 kill_pgrp(tty_pgrp, SIGHUP, on_exit);
905                                 if (!on_exit)
906                                         kill_pgrp(tty_pgrp, SIGCONT, on_exit);
907                                 put_pid(tty_pgrp);
908                         }
909                 }
910                 tty_kref_put(tty);
911
912         } else if (on_exit) {
913                 struct pid *old_pgrp;
914                 spin_lock_irq(&current->sighand->siglock);
915                 old_pgrp = current->signal->tty_old_pgrp;
916                 current->signal->tty_old_pgrp = NULL;
917                 spin_unlock_irq(&current->sighand->siglock);
918                 if (old_pgrp) {
919                         kill_pgrp(old_pgrp, SIGHUP, on_exit);
920                         kill_pgrp(old_pgrp, SIGCONT, on_exit);
921                         put_pid(old_pgrp);
922                 }
923                 return;
924         }
925
926         spin_lock_irq(&current->sighand->siglock);
927         put_pid(current->signal->tty_old_pgrp);
928         current->signal->tty_old_pgrp = NULL;
929
930         tty = tty_kref_get(current->signal->tty);
931         if (tty) {
932                 unsigned long flags;
933                 spin_lock_irqsave(&tty->ctrl_lock, flags);
934                 put_pid(tty->session);
935                 put_pid(tty->pgrp);
936                 tty->session = NULL;
937                 tty->pgrp = NULL;
938                 spin_unlock_irqrestore(&tty->ctrl_lock, flags);
939                 tty_kref_put(tty);
940         } else {
941 #ifdef TTY_DEBUG_HANGUP
942                 printk(KERN_DEBUG "error attempted to write to tty [0x%p]"
943                        " = NULL", tty);
944 #endif
945         }
946
947         spin_unlock_irq(&current->sighand->siglock);
948         /* Now clear signal->tty under the lock */
949         read_lock(&tasklist_lock);
950         session_clear_tty(task_session(current));
951         read_unlock(&tasklist_lock);
952 }
953
954 /**
955  *
956  *      no_tty  - Ensure the current process does not have a controlling tty
957  */
958 void no_tty(void)
959 {
960         /* FIXME: Review locking here. The tty_lock never covered any race
961            between a new association and proc_clear_tty but possible we need
962            to protect against this anyway */
963         struct task_struct *tsk = current;
964         disassociate_ctty(0);
965         proc_clear_tty(tsk);
966 }
967
968
969 /**
970  *      stop_tty        -       propagate flow control
971  *      @tty: tty to stop
972  *
973  *      Perform flow control to the driver. May be called
974  *      on an already stopped device and will not re-call the driver
975  *      method.
976  *
977  *      This functionality is used by both the line disciplines for
978  *      halting incoming flow and by the driver. It may therefore be
979  *      called from any context, may be under the tty atomic_write_lock
980  *      but not always.
981  *
982  *      Locking:
983  *              flow_lock
984  */
985
986 void __stop_tty(struct tty_struct *tty)
987 {
988         if (tty->stopped)
989                 return;
990         tty->stopped = 1;
991         if (tty->ops->stop)
992                 (tty->ops->stop)(tty);
993 }
994
995 void stop_tty(struct tty_struct *tty)
996 {
997         unsigned long flags;
998
999         spin_lock_irqsave(&tty->flow_lock, flags);
1000         __stop_tty(tty);
1001         spin_unlock_irqrestore(&tty->flow_lock, flags);
1002 }
1003 EXPORT_SYMBOL(stop_tty);
1004
1005 /**
1006  *      start_tty       -       propagate flow control
1007  *      @tty: tty to start
1008  *
1009  *      Start a tty that has been stopped if at all possible. If this
1010  *      tty was previous stopped and is now being started, the driver
1011  *      start method is invoked and the line discipline woken.
1012  *
1013  *      Locking:
1014  *              flow_lock
1015  */
1016
1017 void __start_tty(struct tty_struct *tty)
1018 {
1019         if (!tty->stopped || tty->flow_stopped)
1020                 return;
1021         tty->stopped = 0;
1022         if (tty->ops->start)
1023                 (tty->ops->start)(tty);
1024         tty_wakeup(tty);
1025 }
1026
1027 void start_tty(struct tty_struct *tty)
1028 {
1029         unsigned long flags;
1030
1031         spin_lock_irqsave(&tty->flow_lock, flags);
1032         __start_tty(tty);
1033         spin_unlock_irqrestore(&tty->flow_lock, flags);
1034 }
1035 EXPORT_SYMBOL(start_tty);
1036
1037 /* We limit tty time update visibility to every 8 seconds or so. */
1038 static void tty_update_time(struct timespec *time)
1039 {
1040         unsigned long sec = get_seconds() & ~7;
1041         if ((long)(sec - time->tv_sec) > 0)
1042                 time->tv_sec = sec;
1043 }
1044
1045 /**
1046  *      tty_read        -       read method for tty device files
1047  *      @file: pointer to tty file
1048  *      @buf: user buffer
1049  *      @count: size of user buffer
1050  *      @ppos: unused
1051  *
1052  *      Perform the read system call function on this terminal device. Checks
1053  *      for hung up devices before calling the line discipline method.
1054  *
1055  *      Locking:
1056  *              Locks the line discipline internally while needed. Multiple
1057  *      read calls may be outstanding in parallel.
1058  */
1059
1060 static ssize_t tty_read(struct file *file, char __user *buf, size_t count,
1061                         loff_t *ppos)
1062 {
1063         int i;
1064         struct inode *inode = file_inode(file);
1065         struct tty_struct *tty = file_tty(file);
1066         struct tty_ldisc *ld;
1067
1068         if (tty_paranoia_check(tty, inode, "tty_read"))
1069                 return -EIO;
1070         if (!tty || (test_bit(TTY_IO_ERROR, &tty->flags)))
1071                 return -EIO;
1072
1073         /* We want to wait for the line discipline to sort out in this
1074            situation */
1075         ld = tty_ldisc_ref_wait(tty);
1076         if (ld->ops->read)
1077                 i = (ld->ops->read)(tty, file, buf, count);
1078         else
1079                 i = -EIO;
1080         tty_ldisc_deref(ld);
1081
1082         if (i > 0)
1083                 tty_update_time(&inode->i_atime);
1084
1085         return i;
1086 }
1087
1088 static void tty_write_unlock(struct tty_struct *tty)
1089 {
1090         mutex_unlock(&tty->atomic_write_lock);
1091         wake_up_interruptible_poll(&tty->write_wait, POLLOUT);
1092 }
1093
1094 static int tty_write_lock(struct tty_struct *tty, int ndelay)
1095 {
1096         if (!mutex_trylock(&tty->atomic_write_lock)) {
1097                 if (ndelay)
1098                         return -EAGAIN;
1099                 if (mutex_lock_interruptible(&tty->atomic_write_lock))
1100                         return -ERESTARTSYS;
1101         }
1102         return 0;
1103 }
1104
1105 /*
1106  * Split writes up in sane blocksizes to avoid
1107  * denial-of-service type attacks
1108  */
1109 static inline ssize_t do_tty_write(
1110         ssize_t (*write)(struct tty_struct *, struct file *, const unsigned char *, size_t),
1111         struct tty_struct *tty,
1112         struct file *file,
1113         const char __user *buf,
1114         size_t count)
1115 {
1116         ssize_t ret, written = 0;
1117         unsigned int chunk;
1118
1119         ret = tty_write_lock(tty, file->f_flags & O_NDELAY);
1120         if (ret < 0)
1121                 return ret;
1122
1123         /*
1124          * We chunk up writes into a temporary buffer. This
1125          * simplifies low-level drivers immensely, since they
1126          * don't have locking issues and user mode accesses.
1127          *
1128          * But if TTY_NO_WRITE_SPLIT is set, we should use a
1129          * big chunk-size..
1130          *
1131          * The default chunk-size is 2kB, because the NTTY
1132          * layer has problems with bigger chunks. It will
1133          * claim to be able to handle more characters than
1134          * it actually does.
1135          *
1136          * FIXME: This can probably go away now except that 64K chunks
1137          * are too likely to fail unless switched to vmalloc...
1138          */
1139         chunk = 2048;
1140         if (test_bit(TTY_NO_WRITE_SPLIT, &tty->flags))
1141                 chunk = 65536;
1142         if (count < chunk)
1143                 chunk = count;
1144
1145         /* write_buf/write_cnt is protected by the atomic_write_lock mutex */
1146         if (tty->write_cnt < chunk) {
1147                 unsigned char *buf_chunk;
1148
1149                 if (chunk < 1024)
1150                         chunk = 1024;
1151
1152                 buf_chunk = kmalloc(chunk, GFP_KERNEL);
1153                 if (!buf_chunk) {
1154                         ret = -ENOMEM;
1155                         goto out;
1156                 }
1157                 kfree(tty->write_buf);
1158                 tty->write_cnt = chunk;
1159                 tty->write_buf = buf_chunk;
1160         }
1161
1162         /* Do the write .. */
1163         for (;;) {
1164                 size_t size = count;
1165                 if (size > chunk)
1166                         size = chunk;
1167                 ret = -EFAULT;
1168                 if (copy_from_user(tty->write_buf, buf, size))
1169                         break;
1170                 ret = write(tty, file, tty->write_buf, size);
1171                 if (ret <= 0)
1172                         break;
1173                 written += ret;
1174                 buf += ret;
1175                 count -= ret;
1176                 if (!count)
1177                         break;
1178                 ret = -ERESTARTSYS;
1179                 if (signal_pending(current))
1180                         break;
1181                 cond_resched();
1182         }
1183         if (written) {
1184                 tty_update_time(&file_inode(file)->i_mtime);
1185                 ret = written;
1186         }
1187 out:
1188         tty_write_unlock(tty);
1189         return ret;
1190 }
1191
1192 /**
1193  * tty_write_message - write a message to a certain tty, not just the console.
1194  * @tty: the destination tty_struct
1195  * @msg: the message to write
1196  *
1197  * This is used for messages that need to be redirected to a specific tty.
1198  * We don't put it into the syslog queue right now maybe in the future if
1199  * really needed.
1200  *
1201  * We must still hold the BTM and test the CLOSING flag for the moment.
1202  */
1203
1204 void tty_write_message(struct tty_struct *tty, char *msg)
1205 {
1206         if (tty) {
1207                 mutex_lock(&tty->atomic_write_lock);
1208                 tty_lock(tty);
1209                 if (tty->ops->write && !test_bit(TTY_CLOSING, &tty->flags)) {
1210                         tty_unlock(tty);
1211                         tty->ops->write(tty, msg, strlen(msg));
1212                 } else
1213                         tty_unlock(tty);
1214                 tty_write_unlock(tty);
1215         }
1216         return;
1217 }
1218
1219
1220 /**
1221  *      tty_write               -       write method for tty device file
1222  *      @file: tty file pointer
1223  *      @buf: user data to write
1224  *      @count: bytes to write
1225  *      @ppos: unused
1226  *
1227  *      Write data to a tty device via the line discipline.
1228  *
1229  *      Locking:
1230  *              Locks the line discipline as required
1231  *              Writes to the tty driver are serialized by the atomic_write_lock
1232  *      and are then processed in chunks to the device. The line discipline
1233  *      write method will not be invoked in parallel for each device.
1234  */
1235
1236 static ssize_t tty_write(struct file *file, const char __user *buf,
1237                                                 size_t count, loff_t *ppos)
1238 {
1239         struct tty_struct *tty = file_tty(file);
1240         struct tty_ldisc *ld;
1241         ssize_t ret;
1242
1243         if (tty_paranoia_check(tty, file_inode(file), "tty_write"))
1244                 return -EIO;
1245         if (!tty || !tty->ops->write ||
1246                 (test_bit(TTY_IO_ERROR, &tty->flags)))
1247                         return -EIO;
1248         /* Short term debug to catch buggy drivers */
1249         if (tty->ops->write_room == NULL)
1250                 printk(KERN_ERR "tty driver %s lacks a write_room method.\n",
1251                         tty->driver->name);
1252         ld = tty_ldisc_ref_wait(tty);
1253         if (!ld->ops->write)
1254                 ret = -EIO;
1255         else
1256                 ret = do_tty_write(ld->ops->write, tty, file, buf, count);
1257         tty_ldisc_deref(ld);
1258         return ret;
1259 }
1260
1261 ssize_t redirected_tty_write(struct file *file, const char __user *buf,
1262                                                 size_t count, loff_t *ppos)
1263 {
1264         struct file *p = NULL;
1265
1266         spin_lock(&redirect_lock);
1267         if (redirect)
1268                 p = get_file(redirect);
1269         spin_unlock(&redirect_lock);
1270
1271         if (p) {
1272                 ssize_t res;
1273                 res = vfs_write(p, buf, count, &p->f_pos);
1274                 fput(p);
1275                 return res;
1276         }
1277         return tty_write(file, buf, count, ppos);
1278 }
1279
1280 /**
1281  *      tty_send_xchar  -       send priority character
1282  *
1283  *      Send a high priority character to the tty even if stopped
1284  *
1285  *      Locking: none for xchar method, write ordering for write method.
1286  */
1287
1288 int tty_send_xchar(struct tty_struct *tty, char ch)
1289 {
1290         int     was_stopped = tty->stopped;
1291
1292         if (tty->ops->send_xchar) {
1293                 tty->ops->send_xchar(tty, ch);
1294                 return 0;
1295         }
1296
1297         if (tty_write_lock(tty, 0) < 0)
1298                 return -ERESTARTSYS;
1299
1300         if (was_stopped)
1301                 start_tty(tty);
1302         tty->ops->write(tty, &ch, 1);
1303         if (was_stopped)
1304                 stop_tty(tty);
1305         tty_write_unlock(tty);
1306         return 0;
1307 }
1308
1309 static char ptychar[] = "pqrstuvwxyzabcde";
1310
1311 /**
1312  *      pty_line_name   -       generate name for a pty
1313  *      @driver: the tty driver in use
1314  *      @index: the minor number
1315  *      @p: output buffer of at least 6 bytes
1316  *
1317  *      Generate a name from a driver reference and write it to the output
1318  *      buffer.
1319  *
1320  *      Locking: None
1321  */
1322 static void pty_line_name(struct tty_driver *driver, int index, char *p)
1323 {
1324         int i = index + driver->name_base;
1325         /* ->name is initialized to "ttyp", but "tty" is expected */
1326         sprintf(p, "%s%c%x",
1327                 driver->subtype == PTY_TYPE_SLAVE ? "tty" : driver->name,
1328                 ptychar[i >> 4 & 0xf], i & 0xf);
1329 }
1330
1331 /**
1332  *      tty_line_name   -       generate name for a tty
1333  *      @driver: the tty driver in use
1334  *      @index: the minor number
1335  *      @p: output buffer of at least 7 bytes
1336  *
1337  *      Generate a name from a driver reference and write it to the output
1338  *      buffer.
1339  *
1340  *      Locking: None
1341  */
1342 static ssize_t tty_line_name(struct tty_driver *driver, int index, char *p)
1343 {
1344         if (driver->flags & TTY_DRIVER_UNNUMBERED_NODE)
1345                 return sprintf(p, "%s", driver->name);
1346         else
1347                 return sprintf(p, "%s%d", driver->name,
1348                                index + driver->name_base);
1349 }
1350
1351 /**
1352  *      tty_driver_lookup_tty() - find an existing tty, if any
1353  *      @driver: the driver for the tty
1354  *      @idx:    the minor number
1355  *
1356  *      Return the tty, if found or ERR_PTR() otherwise.
1357  *
1358  *      Locking: tty_mutex must be held. If tty is found, the mutex must
1359  *      be held until the 'fast-open' is also done. Will change once we
1360  *      have refcounting in the driver and per driver locking
1361  */
1362 static struct tty_struct *tty_driver_lookup_tty(struct tty_driver *driver,
1363                 struct inode *inode, int idx)
1364 {
1365         if (driver->ops->lookup)
1366                 return driver->ops->lookup(driver, inode, idx);
1367
1368         return driver->ttys[idx];
1369 }
1370
1371 /**
1372  *      tty_init_termios        -  helper for termios setup
1373  *      @tty: the tty to set up
1374  *
1375  *      Initialise the termios structures for this tty. Thus runs under
1376  *      the tty_mutex currently so we can be relaxed about ordering.
1377  */
1378
1379 int tty_init_termios(struct tty_struct *tty)
1380 {
1381         struct ktermios *tp;
1382         int idx = tty->index;
1383
1384         if (tty->driver->flags & TTY_DRIVER_RESET_TERMIOS)
1385                 tty->termios = tty->driver->init_termios;
1386         else {
1387                 /* Check for lazy saved data */
1388                 tp = tty->driver->termios[idx];
1389                 if (tp != NULL)
1390                         tty->termios = *tp;
1391                 else
1392                         tty->termios = tty->driver->init_termios;
1393         }
1394         /* Compatibility until drivers always set this */
1395         tty->termios.c_ispeed = tty_termios_input_baud_rate(&tty->termios);
1396         tty->termios.c_ospeed = tty_termios_baud_rate(&tty->termios);
1397         return 0;
1398 }
1399 EXPORT_SYMBOL_GPL(tty_init_termios);
1400
1401 int tty_standard_install(struct tty_driver *driver, struct tty_struct *tty)
1402 {
1403         int ret = tty_init_termios(tty);
1404         if (ret)
1405                 return ret;
1406
1407         tty_driver_kref_get(driver);
1408         tty->count++;
1409         driver->ttys[tty->index] = tty;
1410         return 0;
1411 }
1412 EXPORT_SYMBOL_GPL(tty_standard_install);
1413
1414 /**
1415  *      tty_driver_install_tty() - install a tty entry in the driver
1416  *      @driver: the driver for the tty
1417  *      @tty: the tty
1418  *
1419  *      Install a tty object into the driver tables. The tty->index field
1420  *      will be set by the time this is called. This method is responsible
1421  *      for ensuring any need additional structures are allocated and
1422  *      configured.
1423  *
1424  *      Locking: tty_mutex for now
1425  */
1426 static int tty_driver_install_tty(struct tty_driver *driver,
1427                                                 struct tty_struct *tty)
1428 {
1429         return driver->ops->install ? driver->ops->install(driver, tty) :
1430                 tty_standard_install(driver, tty);
1431 }
1432
1433 /**
1434  *      tty_driver_remove_tty() - remove a tty from the driver tables
1435  *      @driver: the driver for the tty
1436  *      @idx:    the minor number
1437  *
1438  *      Remvoe a tty object from the driver tables. The tty->index field
1439  *      will be set by the time this is called.
1440  *
1441  *      Locking: tty_mutex for now
1442  */
1443 void tty_driver_remove_tty(struct tty_driver *driver, struct tty_struct *tty)
1444 {
1445         if (driver->ops->remove)
1446                 driver->ops->remove(driver, tty);
1447         else
1448                 driver->ttys[tty->index] = NULL;
1449 }
1450
1451 /*
1452  *      tty_reopen()    - fast re-open of an open tty
1453  *      @tty    - the tty to open
1454  *
1455  *      Return 0 on success, -errno on error.
1456  *
1457  *      Locking: tty_mutex must be held from the time the tty was found
1458  *               till this open completes.
1459  */
1460 static int tty_reopen(struct tty_struct *tty)
1461 {
1462         struct tty_driver *driver = tty->driver;
1463
1464         if (test_bit(TTY_CLOSING, &tty->flags) ||
1465                         test_bit(TTY_HUPPING, &tty->flags))
1466                 return -EIO;
1467
1468         if (driver->type == TTY_DRIVER_TYPE_PTY &&
1469             driver->subtype == PTY_TYPE_MASTER) {
1470                 /*
1471                  * special case for PTY masters: only one open permitted,
1472                  * and the slave side open count is incremented as well.
1473                  */
1474                 if (tty->count)
1475                         return -EIO;
1476
1477                 tty->link->count++;
1478         }
1479         tty->count++;
1480
1481         WARN_ON(!tty->ldisc);
1482
1483         return 0;
1484 }
1485
1486 /**
1487  *      tty_init_dev            -       initialise a tty device
1488  *      @driver: tty driver we are opening a device on
1489  *      @idx: device index
1490  *      @ret_tty: returned tty structure
1491  *
1492  *      Prepare a tty device. This may not be a "new" clean device but
1493  *      could also be an active device. The pty drivers require special
1494  *      handling because of this.
1495  *
1496  *      Locking:
1497  *              The function is called under the tty_mutex, which
1498  *      protects us from the tty struct or driver itself going away.
1499  *
1500  *      On exit the tty device has the line discipline attached and
1501  *      a reference count of 1. If a pair was created for pty/tty use
1502  *      and the other was a pty master then it too has a reference count of 1.
1503  *
1504  * WSH 06/09/97: Rewritten to remove races and properly clean up after a
1505  * failed open.  The new code protects the open with a mutex, so it's
1506  * really quite straightforward.  The mutex locking can probably be
1507  * relaxed for the (most common) case of reopening a tty.
1508  */
1509
1510 struct tty_struct *tty_init_dev(struct tty_driver *driver, int idx)
1511 {
1512         struct tty_struct *tty;
1513         int retval;
1514
1515         /*
1516          * First time open is complex, especially for PTY devices.
1517          * This code guarantees that either everything succeeds and the
1518          * TTY is ready for operation, or else the table slots are vacated
1519          * and the allocated memory released.  (Except that the termios
1520          * and locked termios may be retained.)
1521          */
1522
1523         if (!try_module_get(driver->owner))
1524                 return ERR_PTR(-ENODEV);
1525
1526         tty = alloc_tty_struct(driver, idx);
1527         if (!tty) {
1528                 retval = -ENOMEM;
1529                 goto err_module_put;
1530         }
1531
1532         tty_lock(tty);
1533         retval = tty_driver_install_tty(driver, tty);
1534         if (retval < 0)
1535                 goto err_deinit_tty;
1536
1537         if (!tty->port)
1538                 tty->port = driver->ports[idx];
1539
1540         WARN_RATELIMIT(!tty->port,
1541                         "%s: %s driver does not set tty->port. This will crash the kernel later. Fix the driver!\n",
1542                         __func__, tty->driver->name);
1543
1544         tty->port->itty = tty;
1545
1546         /*
1547          * Structures all installed ... call the ldisc open routines.
1548          * If we fail here just call release_tty to clean up.  No need
1549          * to decrement the use counts, as release_tty doesn't care.
1550          */
1551         retval = tty_ldisc_setup(tty, tty->link);
1552         if (retval)
1553                 goto err_release_tty;
1554         /* Return the tty locked so that it cannot vanish under the caller */
1555         return tty;
1556
1557 err_deinit_tty:
1558         tty_unlock(tty);
1559         deinitialize_tty_struct(tty);
1560         free_tty_struct(tty);
1561 err_module_put:
1562         module_put(driver->owner);
1563         return ERR_PTR(retval);
1564
1565         /* call the tty release_tty routine to clean out this slot */
1566 err_release_tty:
1567         tty_unlock(tty);
1568         printk_ratelimited(KERN_INFO "tty_init_dev: ldisc open failed, "
1569                                  "clearing slot %d\n", idx);
1570         release_tty(tty, idx);
1571         return ERR_PTR(retval);
1572 }
1573
1574 void tty_free_termios(struct tty_struct *tty)
1575 {
1576         struct ktermios *tp;
1577         int idx = tty->index;
1578
1579         /* If the port is going to reset then it has no termios to save */
1580         if (tty->driver->flags & TTY_DRIVER_RESET_TERMIOS)
1581                 return;
1582
1583         /* Stash the termios data */
1584         tp = tty->driver->termios[idx];
1585         if (tp == NULL) {
1586                 tp = kmalloc(sizeof(struct ktermios), GFP_KERNEL);
1587                 if (tp == NULL) {
1588                         pr_warn("tty: no memory to save termios state.\n");
1589                         return;
1590                 }
1591                 tty->driver->termios[idx] = tp;
1592         }
1593         *tp = tty->termios;
1594 }
1595 EXPORT_SYMBOL(tty_free_termios);
1596
1597 /**
1598  *      tty_flush_works         -       flush all works of a tty
1599  *      @tty: tty device to flush works for
1600  *
1601  *      Sync flush all works belonging to @tty.
1602  */
1603 static void tty_flush_works(struct tty_struct *tty)
1604 {
1605         flush_work(&tty->SAK_work);
1606         flush_work(&tty->hangup_work);
1607 }
1608
1609 /**
1610  *      release_one_tty         -       release tty structure memory
1611  *      @kref: kref of tty we are obliterating
1612  *
1613  *      Releases memory associated with a tty structure, and clears out the
1614  *      driver table slots. This function is called when a device is no longer
1615  *      in use. It also gets called when setup of a device fails.
1616  *
1617  *      Locking:
1618  *              takes the file list lock internally when working on the list
1619  *      of ttys that the driver keeps.
1620  *
1621  *      This method gets called from a work queue so that the driver private
1622  *      cleanup ops can sleep (needed for USB at least)
1623  */
1624 static void release_one_tty(struct work_struct *work)
1625 {
1626         struct tty_struct *tty =
1627                 container_of(work, struct tty_struct, hangup_work);
1628         struct tty_driver *driver = tty->driver;
1629         struct module *owner = driver->owner;
1630
1631         if (tty->ops->cleanup)
1632                 tty->ops->cleanup(tty);
1633
1634         tty->magic = 0;
1635         tty_driver_kref_put(driver);
1636         module_put(owner);
1637
1638         spin_lock(&tty_files_lock);
1639         list_del_init(&tty->tty_files);
1640         spin_unlock(&tty_files_lock);
1641
1642         put_pid(tty->pgrp);
1643         put_pid(tty->session);
1644         free_tty_struct(tty);
1645 }
1646
1647 static void queue_release_one_tty(struct kref *kref)
1648 {
1649         struct tty_struct *tty = container_of(kref, struct tty_struct, kref);
1650
1651         /* The hangup queue is now free so we can reuse it rather than
1652            waste a chunk of memory for each port */
1653         INIT_WORK(&tty->hangup_work, release_one_tty);
1654         schedule_work(&tty->hangup_work);
1655 }
1656
1657 /**
1658  *      tty_kref_put            -       release a tty kref
1659  *      @tty: tty device
1660  *
1661  *      Release a reference to a tty device and if need be let the kref
1662  *      layer destruct the object for us
1663  */
1664
1665 void tty_kref_put(struct tty_struct *tty)
1666 {
1667         if (tty)
1668                 kref_put(&tty->kref, queue_release_one_tty);
1669 }
1670 EXPORT_SYMBOL(tty_kref_put);
1671
1672 /**
1673  *      release_tty             -       release tty structure memory
1674  *
1675  *      Release both @tty and a possible linked partner (think pty pair),
1676  *      and decrement the refcount of the backing module.
1677  *
1678  *      Locking:
1679  *              tty_mutex
1680  *              takes the file list lock internally when working on the list
1681  *      of ttys that the driver keeps.
1682  *
1683  */
1684 static void release_tty(struct tty_struct *tty, int idx)
1685 {
1686         /* This should always be true but check for the moment */
1687         WARN_ON(tty->index != idx);
1688         WARN_ON(!mutex_is_locked(&tty_mutex));
1689         if (tty->ops->shutdown)
1690                 tty->ops->shutdown(tty);
1691         tty_free_termios(tty);
1692         tty_driver_remove_tty(tty->driver, tty);
1693         tty->port->itty = NULL;
1694         if (tty->link)
1695                 tty->link->port->itty = NULL;
1696         cancel_work_sync(&tty->port->buf.work);
1697
1698         if (tty->link)
1699                 tty_kref_put(tty->link);
1700         tty_kref_put(tty);
1701 }
1702
1703 /**
1704  *      tty_release_checks - check a tty before real release
1705  *      @tty: tty to check
1706  *      @o_tty: link of @tty (if any)
1707  *      @idx: index of the tty
1708  *
1709  *      Performs some paranoid checking before true release of the @tty.
1710  *      This is a no-op unless TTY_PARANOIA_CHECK is defined.
1711  */
1712 static int tty_release_checks(struct tty_struct *tty, struct tty_struct *o_tty,
1713                 int idx)
1714 {
1715 #ifdef TTY_PARANOIA_CHECK
1716         if (idx < 0 || idx >= tty->driver->num) {
1717                 printk(KERN_DEBUG "%s: bad idx when trying to free (%s)\n",
1718                                 __func__, tty->name);
1719                 return -1;
1720         }
1721
1722         /* not much to check for devpts */
1723         if (tty->driver->flags & TTY_DRIVER_DEVPTS_MEM)
1724                 return 0;
1725
1726         if (tty != tty->driver->ttys[idx]) {
1727                 printk(KERN_DEBUG "%s: driver.table[%d] not tty for (%s)\n",
1728                                 __func__, idx, tty->name);
1729                 return -1;
1730         }
1731         if (tty->driver->other) {
1732                 if (o_tty != tty->driver->other->ttys[idx]) {
1733                         printk(KERN_DEBUG "%s: other->table[%d] not o_tty for (%s)\n",
1734                                         __func__, idx, tty->name);
1735                         return -1;
1736                 }
1737                 if (o_tty->link != tty) {
1738                         printk(KERN_DEBUG "%s: bad pty pointers\n", __func__);
1739                         return -1;
1740                 }
1741         }
1742 #endif
1743         return 0;
1744 }
1745
1746 /**
1747  *      tty_release             -       vfs callback for close
1748  *      @inode: inode of tty
1749  *      @filp: file pointer for handle to tty
1750  *
1751  *      Called the last time each file handle is closed that references
1752  *      this tty. There may however be several such references.
1753  *
1754  *      Locking:
1755  *              Takes bkl. See tty_release_dev
1756  *
1757  * Even releasing the tty structures is a tricky business.. We have
1758  * to be very careful that the structures are all released at the
1759  * same time, as interrupts might otherwise get the wrong pointers.
1760  *
1761  * WSH 09/09/97: rewritten to avoid some nasty race conditions that could
1762  * lead to double frees or releasing memory still in use.
1763  */
1764
1765 int tty_release(struct inode *inode, struct file *filp)
1766 {
1767         struct tty_struct *tty = file_tty(filp);
1768         struct tty_struct *o_tty;
1769         int     pty_master, tty_closing, o_tty_closing, do_sleep;
1770         int     idx;
1771         char    buf[64];
1772
1773         if (tty_paranoia_check(tty, inode, __func__))
1774                 return 0;
1775
1776         tty_lock(tty);
1777         check_tty_count(tty, __func__);
1778
1779         __tty_fasync(-1, filp, 0);
1780
1781         idx = tty->index;
1782         pty_master = (tty->driver->type == TTY_DRIVER_TYPE_PTY &&
1783                       tty->driver->subtype == PTY_TYPE_MASTER);
1784         /* Review: parallel close */
1785         o_tty = tty->link;
1786
1787         if (tty_release_checks(tty, o_tty, idx)) {
1788                 tty_unlock(tty);
1789                 return 0;
1790         }
1791
1792 #ifdef TTY_DEBUG_HANGUP
1793         printk(KERN_DEBUG "%s: %s (tty count=%d)...\n", __func__,
1794                         tty_name(tty, buf), tty->count);
1795 #endif
1796
1797         if (tty->ops->close)
1798                 tty->ops->close(tty, filp);
1799
1800         tty_unlock(tty);
1801         /*
1802          * Sanity check: if tty->count is going to zero, there shouldn't be
1803          * any waiters on tty->read_wait or tty->write_wait.  We test the
1804          * wait queues and kick everyone out _before_ actually starting to
1805          * close.  This ensures that we won't block while releasing the tty
1806          * structure.
1807          *
1808          * The test for the o_tty closing is necessary, since the master and
1809          * slave sides may close in any order.  If the slave side closes out
1810          * first, its count will be one, since the master side holds an open.
1811          * Thus this test wouldn't be triggered at the time the slave closes,
1812          * so we do it now.
1813          *
1814          * Note that it's possible for the tty to be opened again while we're
1815          * flushing out waiters.  By recalculating the closing flags before
1816          * each iteration we avoid any problems.
1817          */
1818         while (1) {
1819                 /* Guard against races with tty->count changes elsewhere and
1820                    opens on /dev/tty */
1821
1822                 mutex_lock(&tty_mutex);
1823                 tty_lock_pair(tty, o_tty);
1824                 tty_closing = tty->count <= 1;
1825                 o_tty_closing = o_tty &&
1826                         (o_tty->count <= (pty_master ? 1 : 0));
1827                 do_sleep = 0;
1828
1829                 if (tty_closing) {
1830                         if (waitqueue_active(&tty->read_wait)) {
1831                                 wake_up_poll(&tty->read_wait, POLLIN);
1832                                 do_sleep++;
1833                         }
1834                         if (waitqueue_active(&tty->write_wait)) {
1835                                 wake_up_poll(&tty->write_wait, POLLOUT);
1836                                 do_sleep++;
1837                         }
1838                 }
1839                 if (o_tty_closing) {
1840                         if (waitqueue_active(&o_tty->read_wait)) {
1841                                 wake_up_poll(&o_tty->read_wait, POLLIN);
1842                                 do_sleep++;
1843                         }
1844                         if (waitqueue_active(&o_tty->write_wait)) {
1845                                 wake_up_poll(&o_tty->write_wait, POLLOUT);
1846                                 do_sleep++;
1847                         }
1848                 }
1849                 if (!do_sleep)
1850                         break;
1851
1852                 printk(KERN_WARNING "%s: %s: read/write wait queue active!\n",
1853                                 __func__, tty_name(tty, buf));
1854                 tty_unlock_pair(tty, o_tty);
1855                 mutex_unlock(&tty_mutex);
1856                 schedule();
1857         }
1858
1859         /*
1860          * The closing flags are now consistent with the open counts on
1861          * both sides, and we've completed the last operation that could
1862          * block, so it's safe to proceed with closing.
1863          *
1864          * We must *not* drop the tty_mutex until we ensure that a further
1865          * entry into tty_open can not pick up this tty.
1866          */
1867         if (pty_master) {
1868                 if (--o_tty->count < 0) {
1869                         printk(KERN_WARNING "%s: bad pty slave count (%d) for %s\n",
1870                                 __func__, o_tty->count, tty_name(o_tty, buf));
1871                         o_tty->count = 0;
1872                 }
1873         }
1874         if (--tty->count < 0) {
1875                 printk(KERN_WARNING "%s: bad tty->count (%d) for %s\n",
1876                                 __func__, tty->count, tty_name(tty, buf));
1877                 tty->count = 0;
1878         }
1879
1880         /*
1881          * We've decremented tty->count, so we need to remove this file
1882          * descriptor off the tty->tty_files list; this serves two
1883          * purposes:
1884          *  - check_tty_count sees the correct number of file descriptors
1885          *    associated with this tty.
1886          *  - do_tty_hangup no longer sees this file descriptor as
1887          *    something that needs to be handled for hangups.
1888          */
1889         tty_del_file(filp);
1890
1891         /*
1892          * Perform some housekeeping before deciding whether to return.
1893          *
1894          * Set the TTY_CLOSING flag if this was the last open.  In the
1895          * case of a pty we may have to wait around for the other side
1896          * to close, and TTY_CLOSING makes sure we can't be reopened.
1897          */
1898         if (tty_closing)
1899                 set_bit(TTY_CLOSING, &tty->flags);
1900         if (o_tty_closing)
1901                 set_bit(TTY_CLOSING, &o_tty->flags);
1902
1903         /*
1904          * If _either_ side is closing, make sure there aren't any
1905          * processes that still think tty or o_tty is their controlling
1906          * tty.
1907          */
1908         if (tty_closing || o_tty_closing) {
1909                 read_lock(&tasklist_lock);
1910                 session_clear_tty(tty->session);
1911                 if (o_tty)
1912                         session_clear_tty(o_tty->session);
1913                 read_unlock(&tasklist_lock);
1914         }
1915
1916         mutex_unlock(&tty_mutex);
1917         tty_unlock_pair(tty, o_tty);
1918         /* At this point the TTY_CLOSING flag should ensure a dead tty
1919            cannot be re-opened by a racing opener */
1920
1921         /* check whether both sides are closing ... */
1922         if (!tty_closing || (o_tty && !o_tty_closing))
1923                 return 0;
1924
1925 #ifdef TTY_DEBUG_HANGUP
1926         printk(KERN_DEBUG "%s: %s: final close\n", __func__, tty_name(tty, buf));
1927 #endif
1928         /*
1929          * Ask the line discipline code to release its structures
1930          */
1931         tty_ldisc_release(tty, o_tty);
1932
1933         /* Wait for pending work before tty destruction commmences */
1934         tty_flush_works(tty);
1935         if (o_tty)
1936                 tty_flush_works(o_tty);
1937
1938 #ifdef TTY_DEBUG_HANGUP
1939         printk(KERN_DEBUG "%s: %s: freeing structure...\n", __func__, tty_name(tty, buf));
1940 #endif
1941         /*
1942          * The release_tty function takes care of the details of clearing
1943          * the slots and preserving the termios structure. The tty_unlock_pair
1944          * should be safe as we keep a kref while the tty is locked (so the
1945          * unlock never unlocks a freed tty).
1946          */
1947         mutex_lock(&tty_mutex);
1948         release_tty(tty, idx);
1949         mutex_unlock(&tty_mutex);
1950
1951         return 0;
1952 }
1953
1954 /**
1955  *      tty_open_current_tty - get tty of current task for open
1956  *      @device: device number
1957  *      @filp: file pointer to tty
1958  *      @return: tty of the current task iff @device is /dev/tty
1959  *
1960  *      We cannot return driver and index like for the other nodes because
1961  *      devpts will not work then. It expects inodes to be from devpts FS.
1962  *
1963  *      We need to move to returning a refcounted object from all the lookup
1964  *      paths including this one.
1965  */
1966 static struct tty_struct *tty_open_current_tty(dev_t device, struct file *filp)
1967 {
1968         struct tty_struct *tty;
1969
1970         if (device != MKDEV(TTYAUX_MAJOR, 0))
1971                 return NULL;
1972
1973         tty = get_current_tty();
1974         if (!tty)
1975                 return ERR_PTR(-ENXIO);
1976
1977         filp->f_flags |= O_NONBLOCK; /* Don't let /dev/tty block */
1978         /* noctty = 1; */
1979         tty_kref_put(tty);
1980         /* FIXME: we put a reference and return a TTY! */
1981         /* This is only safe because the caller holds tty_mutex */
1982         return tty;
1983 }
1984
1985 /**
1986  *      tty_lookup_driver - lookup a tty driver for a given device file
1987  *      @device: device number
1988  *      @filp: file pointer to tty
1989  *      @noctty: set if the device should not become a controlling tty
1990  *      @index: index for the device in the @return driver
1991  *      @return: driver for this inode (with increased refcount)
1992  *
1993  *      If @return is not erroneous, the caller is responsible to decrement the
1994  *      refcount by tty_driver_kref_put.
1995  *
1996  *      Locking: tty_mutex protects get_tty_driver
1997  */
1998 static struct tty_driver *tty_lookup_driver(dev_t device, struct file *filp,
1999                 int *noctty, int *index)
2000 {
2001         struct tty_driver *driver;
2002
2003         switch (device) {
2004 #ifdef CONFIG_VT
2005         case MKDEV(TTY_MAJOR, 0): {
2006                 extern struct tty_driver *console_driver;
2007                 driver = tty_driver_kref_get(console_driver);
2008                 *index = fg_console;
2009                 *noctty = 1;
2010                 break;
2011         }
2012 #endif
2013         case MKDEV(TTYAUX_MAJOR, 1): {
2014                 struct tty_driver *console_driver = console_device(index);
2015                 if (console_driver) {
2016                         driver = tty_driver_kref_get(console_driver);
2017                         if (driver) {
2018                                 /* Don't let /dev/console block */
2019                                 filp->f_flags |= O_NONBLOCK;
2020                                 *noctty = 1;
2021                                 break;
2022                         }
2023                 }
2024                 return ERR_PTR(-ENODEV);
2025         }
2026         default:
2027                 driver = get_tty_driver(device, index);
2028                 if (!driver)
2029                         return ERR_PTR(-ENODEV);
2030                 break;
2031         }
2032         return driver;
2033 }
2034
2035 /**
2036  *      tty_open                -       open a tty device
2037  *      @inode: inode of device file
2038  *      @filp: file pointer to tty
2039  *
2040  *      tty_open and tty_release keep up the tty count that contains the
2041  *      number of opens done on a tty. We cannot use the inode-count, as
2042  *      different inodes might point to the same tty.
2043  *
2044  *      Open-counting is needed for pty masters, as well as for keeping
2045  *      track of serial lines: DTR is dropped when the last close happens.
2046  *      (This is not done solely through tty->count, now.  - Ted 1/27/92)
2047  *
2048  *      The termios state of a pty is reset on first open so that
2049  *      settings don't persist across reuse.
2050  *
2051  *      Locking: tty_mutex protects tty, tty_lookup_driver and tty_init_dev.
2052  *               tty->count should protect the rest.
2053  *               ->siglock protects ->signal/->sighand
2054  *
2055  *      Note: the tty_unlock/lock cases without a ref are only safe due to
2056  *      tty_mutex
2057  */
2058
2059 static int tty_open(struct inode *inode, struct file *filp)
2060 {
2061         struct tty_struct *tty;
2062         int noctty, retval;
2063         struct tty_driver *driver = NULL;
2064         int index;
2065         dev_t device = inode->i_rdev;
2066         unsigned saved_flags = filp->f_flags;
2067
2068         nonseekable_open(inode, filp);
2069
2070 retry_open:
2071         retval = tty_alloc_file(filp);
2072         if (retval)
2073                 return -ENOMEM;
2074
2075         noctty = filp->f_flags & O_NOCTTY;
2076         index  = -1;
2077         retval = 0;
2078
2079         mutex_lock(&tty_mutex);
2080         /* This is protected by the tty_mutex */
2081         tty = tty_open_current_tty(device, filp);
2082         if (IS_ERR(tty)) {
2083                 retval = PTR_ERR(tty);
2084                 goto err_unlock;
2085         } else if (!tty) {
2086                 driver = tty_lookup_driver(device, filp, &noctty, &index);
2087                 if (IS_ERR(driver)) {
2088                         retval = PTR_ERR(driver);
2089                         goto err_unlock;
2090                 }
2091
2092                 /* check whether we're reopening an existing tty */
2093                 tty = tty_driver_lookup_tty(driver, inode, index);
2094                 if (IS_ERR(tty)) {
2095                         retval = PTR_ERR(tty);
2096                         goto err_unlock;
2097                 }
2098         }
2099
2100         if (tty) {
2101                 tty_lock(tty);
2102                 retval = tty_reopen(tty);
2103                 if (retval < 0) {
2104                         tty_unlock(tty);
2105                         tty = ERR_PTR(retval);
2106                 }
2107         } else  /* Returns with the tty_lock held for now */
2108                 tty = tty_init_dev(driver, index);
2109
2110         mutex_unlock(&tty_mutex);
2111         if (driver)
2112                 tty_driver_kref_put(driver);
2113         if (IS_ERR(tty)) {
2114                 retval = PTR_ERR(tty);
2115                 goto err_file;
2116         }
2117
2118         tty_add_file(tty, filp);
2119
2120         check_tty_count(tty, __func__);
2121         if (tty->driver->type == TTY_DRIVER_TYPE_PTY &&
2122             tty->driver->subtype == PTY_TYPE_MASTER)
2123                 noctty = 1;
2124 #ifdef TTY_DEBUG_HANGUP
2125         printk(KERN_DEBUG "%s: opening %s...\n", __func__, tty->name);
2126 #endif
2127         if (tty->ops->open)
2128                 retval = tty->ops->open(tty, filp);
2129         else
2130                 retval = -ENODEV;
2131         filp->f_flags = saved_flags;
2132
2133         if (!retval && test_bit(TTY_EXCLUSIVE, &tty->flags) &&
2134                                                 !capable(CAP_SYS_ADMIN))
2135                 retval = -EBUSY;
2136
2137         if (retval) {
2138 #ifdef TTY_DEBUG_HANGUP
2139                 printk(KERN_DEBUG "%s: error %d in opening %s...\n", __func__,
2140                                 retval, tty->name);
2141 #endif
2142                 tty_unlock(tty); /* need to call tty_release without BTM */
2143                 tty_release(inode, filp);
2144                 if (retval != -ERESTARTSYS)
2145                         return retval;
2146
2147                 if (signal_pending(current))
2148                         return retval;
2149
2150                 schedule();
2151                 /*
2152                  * Need to reset f_op in case a hangup happened.
2153                  */
2154                 if (filp->f_op == &hung_up_tty_fops)
2155                         filp->f_op = &tty_fops;
2156                 goto retry_open;
2157         }
2158         clear_bit(TTY_HUPPED, &tty->flags);
2159
2160
2161         read_lock(&tasklist_lock);
2162         spin_lock_irq(&current->sighand->siglock);
2163         if (!noctty &&
2164             current->signal->leader &&
2165             !current->signal->tty &&
2166             tty->session == NULL)
2167                 __proc_set_tty(tty);
2168         spin_unlock_irq(&current->sighand->siglock);
2169         read_unlock(&tasklist_lock);
2170         tty_unlock(tty);
2171         return 0;
2172 err_unlock:
2173         mutex_unlock(&tty_mutex);
2174         /* after locks to avoid deadlock */
2175         if (!IS_ERR_OR_NULL(driver))
2176                 tty_driver_kref_put(driver);
2177 err_file:
2178         tty_free_file(filp);
2179         return retval;
2180 }
2181
2182
2183
2184 /**
2185  *      tty_poll        -       check tty status
2186  *      @filp: file being polled
2187  *      @wait: poll wait structures to update
2188  *
2189  *      Call the line discipline polling method to obtain the poll
2190  *      status of the device.
2191  *
2192  *      Locking: locks called line discipline but ldisc poll method
2193  *      may be re-entered freely by other callers.
2194  */
2195
2196 static unsigned int tty_poll(struct file *filp, poll_table *wait)
2197 {
2198         struct tty_struct *tty = file_tty(filp);
2199         struct tty_ldisc *ld;
2200         int ret = 0;
2201
2202         if (tty_paranoia_check(tty, file_inode(filp), "tty_poll"))
2203                 return 0;
2204
2205         ld = tty_ldisc_ref_wait(tty);
2206         if (ld->ops->poll)
2207                 ret = (ld->ops->poll)(tty, filp, wait);
2208         tty_ldisc_deref(ld);
2209         return ret;
2210 }
2211
2212 static int __tty_fasync(int fd, struct file *filp, int on)
2213 {
2214         struct tty_struct *tty = file_tty(filp);
2215         struct tty_ldisc *ldisc;
2216         unsigned long flags;
2217         int retval = 0;
2218
2219         if (tty_paranoia_check(tty, file_inode(filp), "tty_fasync"))
2220                 goto out;
2221
2222         retval = fasync_helper(fd, filp, on, &tty->fasync);
2223         if (retval <= 0)
2224                 goto out;
2225
2226         ldisc = tty_ldisc_ref(tty);
2227         if (ldisc) {
2228                 if (ldisc->ops->fasync)
2229                         ldisc->ops->fasync(tty, on);
2230                 tty_ldisc_deref(ldisc);
2231         }
2232
2233         if (on) {
2234                 enum pid_type type;
2235                 struct pid *pid;
2236
2237                 spin_lock_irqsave(&tty->ctrl_lock, flags);
2238                 if (tty->pgrp) {
2239                         pid = tty->pgrp;
2240                         type = PIDTYPE_PGID;
2241                 } else {
2242                         pid = task_pid(current);
2243                         type = PIDTYPE_PID;
2244                 }
2245                 get_pid(pid);
2246                 spin_unlock_irqrestore(&tty->ctrl_lock, flags);
2247                 __f_setown(filp, pid, type, 0);
2248                 put_pid(pid);
2249                 retval = 0;
2250         }
2251 out:
2252         return retval;
2253 }
2254
2255 static int tty_fasync(int fd, struct file *filp, int on)
2256 {
2257         struct tty_struct *tty = file_tty(filp);
2258         int retval;
2259
2260         tty_lock(tty);
2261         retval = __tty_fasync(fd, filp, on);
2262         tty_unlock(tty);
2263
2264         return retval;
2265 }
2266
2267 /**
2268  *      tiocsti                 -       fake input character
2269  *      @tty: tty to fake input into
2270  *      @p: pointer to character
2271  *
2272  *      Fake input to a tty device. Does the necessary locking and
2273  *      input management.
2274  *
2275  *      FIXME: does not honour flow control ??
2276  *
2277  *      Locking:
2278  *              Called functions take tty_ldiscs_lock
2279  *              current->signal->tty check is safe without locks
2280  *
2281  *      FIXME: may race normal receive processing
2282  */
2283
2284 static int tiocsti(struct tty_struct *tty, char __user *p)
2285 {
2286         char ch, mbz = 0;
2287         struct tty_ldisc *ld;
2288
2289         if ((current->signal->tty != tty) && !capable(CAP_SYS_ADMIN))
2290                 return -EPERM;
2291         if (get_user(ch, p))
2292                 return -EFAULT;
2293         tty_audit_tiocsti(tty, ch);
2294         ld = tty_ldisc_ref_wait(tty);
2295         ld->ops->receive_buf(tty, &ch, &mbz, 1);
2296         tty_ldisc_deref(ld);
2297         return 0;
2298 }
2299
2300 /**
2301  *      tiocgwinsz              -       implement window query ioctl
2302  *      @tty; tty
2303  *      @arg: user buffer for result
2304  *
2305  *      Copies the kernel idea of the window size into the user buffer.
2306  *
2307  *      Locking: tty->winsize_mutex is taken to ensure the winsize data
2308  *              is consistent.
2309  */
2310
2311 static int tiocgwinsz(struct tty_struct *tty, struct winsize __user *arg)
2312 {
2313         int err;
2314
2315         mutex_lock(&tty->winsize_mutex);
2316         err = copy_to_user(arg, &tty->winsize, sizeof(*arg));
2317         mutex_unlock(&tty->winsize_mutex);
2318
2319         return err ? -EFAULT: 0;
2320 }
2321
2322 /**
2323  *      tty_do_resize           -       resize event
2324  *      @tty: tty being resized
2325  *      @rows: rows (character)
2326  *      @cols: cols (character)
2327  *
2328  *      Update the termios variables and send the necessary signals to
2329  *      peform a terminal resize correctly
2330  */
2331
2332 int tty_do_resize(struct tty_struct *tty, struct winsize *ws)
2333 {
2334         struct pid *pgrp;
2335
2336         /* Lock the tty */
2337         mutex_lock(&tty->winsize_mutex);
2338         if (!memcmp(ws, &tty->winsize, sizeof(*ws)))
2339                 goto done;
2340
2341         /* Signal the foreground process group */
2342         pgrp = tty_get_pgrp(tty);
2343         if (pgrp)
2344                 kill_pgrp(pgrp, SIGWINCH, 1);
2345         put_pid(pgrp);
2346
2347         tty->winsize = *ws;
2348 done:
2349         mutex_unlock(&tty->winsize_mutex);
2350         return 0;
2351 }
2352 EXPORT_SYMBOL(tty_do_resize);
2353
2354 /**
2355  *      tiocswinsz              -       implement window size set ioctl
2356  *      @tty; tty side of tty
2357  *      @arg: user buffer for result
2358  *
2359  *      Copies the user idea of the window size to the kernel. Traditionally
2360  *      this is just advisory information but for the Linux console it
2361  *      actually has driver level meaning and triggers a VC resize.
2362  *
2363  *      Locking:
2364  *              Driver dependent. The default do_resize method takes the
2365  *      tty termios mutex and ctrl_lock. The console takes its own lock
2366  *      then calls into the default method.
2367  */
2368
2369 static int tiocswinsz(struct tty_struct *tty, struct winsize __user *arg)
2370 {
2371         struct winsize tmp_ws;
2372         if (copy_from_user(&tmp_ws, arg, sizeof(*arg)))
2373                 return -EFAULT;
2374
2375         if (tty->ops->resize)
2376                 return tty->ops->resize(tty, &tmp_ws);
2377         else
2378                 return tty_do_resize(tty, &tmp_ws);
2379 }
2380
2381 /**
2382  *      tioccons        -       allow admin to move logical console
2383  *      @file: the file to become console
2384  *
2385  *      Allow the administrator to move the redirected console device
2386  *
2387  *      Locking: uses redirect_lock to guard the redirect information
2388  */
2389
2390 static int tioccons(struct file *file)
2391 {
2392         if (!capable(CAP_SYS_ADMIN))
2393                 return -EPERM;
2394         if (file->f_op->write == redirected_tty_write) {
2395                 struct file *f;
2396                 spin_lock(&redirect_lock);
2397                 f = redirect;
2398                 redirect = NULL;
2399                 spin_unlock(&redirect_lock);
2400                 if (f)
2401                         fput(f);
2402                 return 0;
2403         }
2404         spin_lock(&redirect_lock);
2405         if (redirect) {
2406                 spin_unlock(&redirect_lock);
2407                 return -EBUSY;
2408         }
2409         redirect = get_file(file);
2410         spin_unlock(&redirect_lock);
2411         return 0;
2412 }
2413
2414 /**
2415  *      fionbio         -       non blocking ioctl
2416  *      @file: file to set blocking value
2417  *      @p: user parameter
2418  *
2419  *      Historical tty interfaces had a blocking control ioctl before
2420  *      the generic functionality existed. This piece of history is preserved
2421  *      in the expected tty API of posix OS's.
2422  *
2423  *      Locking: none, the open file handle ensures it won't go away.
2424  */
2425
2426 static int fionbio(struct file *file, int __user *p)
2427 {
2428         int nonblock;
2429
2430         if (get_user(nonblock, p))
2431                 return -EFAULT;
2432
2433         spin_lock(&file->f_lock);
2434         if (nonblock)
2435                 file->f_flags |= O_NONBLOCK;
2436         else
2437                 file->f_flags &= ~O_NONBLOCK;
2438         spin_unlock(&file->f_lock);
2439         return 0;
2440 }
2441
2442 /**
2443  *      tiocsctty       -       set controlling tty
2444  *      @tty: tty structure
2445  *      @arg: user argument
2446  *
2447  *      This ioctl is used to manage job control. It permits a session
2448  *      leader to set this tty as the controlling tty for the session.
2449  *
2450  *      Locking:
2451  *              Takes tty_lock() to serialize proc_set_tty() for this tty
2452  *              Takes tasklist_lock internally to walk sessions
2453  *              Takes ->siglock() when updating signal->tty
2454  */
2455
2456 static int tiocsctty(struct tty_struct *tty, int arg)
2457 {
2458         int ret = 0;
2459
2460         tty_lock(tty);
2461         read_lock(&tasklist_lock);
2462
2463         if (current->signal->leader && (task_session(current) == tty->session))
2464                 goto unlock;
2465
2466         /*
2467          * The process must be a session leader and
2468          * not have a controlling tty already.
2469          */
2470         if (!current->signal->leader || current->signal->tty) {
2471                 ret = -EPERM;
2472                 goto unlock;
2473         }
2474
2475         if (tty->session) {
2476                 /*
2477                  * This tty is already the controlling
2478                  * tty for another session group!
2479                  */
2480                 if (arg == 1 && capable(CAP_SYS_ADMIN)) {
2481                         /*
2482                          * Steal it away
2483                          */
2484                         session_clear_tty(tty->session);
2485                 } else {
2486                         ret = -EPERM;
2487                         goto unlock;
2488                 }
2489         }
2490         proc_set_tty(tty);
2491 unlock:
2492         read_unlock(&tasklist_lock);
2493         tty_unlock(tty);
2494         return ret;
2495 }
2496
2497 /**
2498  *      tty_get_pgrp    -       return a ref counted pgrp pid
2499  *      @tty: tty to read
2500  *
2501  *      Returns a refcounted instance of the pid struct for the process
2502  *      group controlling the tty.
2503  */
2504
2505 struct pid *tty_get_pgrp(struct tty_struct *tty)
2506 {
2507         unsigned long flags;
2508         struct pid *pgrp;
2509
2510         spin_lock_irqsave(&tty->ctrl_lock, flags);
2511         pgrp = get_pid(tty->pgrp);
2512         spin_unlock_irqrestore(&tty->ctrl_lock, flags);
2513
2514         return pgrp;
2515 }
2516 EXPORT_SYMBOL_GPL(tty_get_pgrp);
2517
2518 /*
2519  * This checks not only the pgrp, but falls back on the pid if no
2520  * satisfactory pgrp is found. I dunno - gdb doesn't work correctly
2521  * without this...
2522  *
2523  * The caller must hold rcu lock or the tasklist lock.
2524  */
2525 static struct pid *session_of_pgrp(struct pid *pgrp)
2526 {
2527         struct task_struct *p;
2528         struct pid *sid = NULL;
2529
2530         p = pid_task(pgrp, PIDTYPE_PGID);
2531         if (p == NULL)
2532                 p = pid_task(pgrp, PIDTYPE_PID);
2533         if (p != NULL)
2534                 sid = task_session(p);
2535
2536         return sid;
2537 }
2538
2539 /**
2540  *      tiocgpgrp               -       get process group
2541  *      @tty: tty passed by user
2542  *      @real_tty: tty side of the tty passed by the user if a pty else the tty
2543  *      @p: returned pid
2544  *
2545  *      Obtain the process group of the tty. If there is no process group
2546  *      return an error.
2547  *
2548  *      Locking: none. Reference to current->signal->tty is safe.
2549  */
2550
2551 static int tiocgpgrp(struct tty_struct *tty, struct tty_struct *real_tty, pid_t __user *p)
2552 {
2553         struct pid *pid;
2554         int ret;
2555         /*
2556          * (tty == real_tty) is a cheap way of
2557          * testing if the tty is NOT a master pty.
2558          */
2559         if (tty == real_tty && current->signal->tty != real_tty)
2560                 return -ENOTTY;
2561         pid = tty_get_pgrp(real_tty);
2562         ret =  put_user(pid_vnr(pid), p);
2563         put_pid(pid);
2564         return ret;
2565 }
2566
2567 /**
2568  *      tiocspgrp               -       attempt to set process group
2569  *      @tty: tty passed by user
2570  *      @real_tty: tty side device matching tty passed by user
2571  *      @p: pid pointer
2572  *
2573  *      Set the process group of the tty to the session passed. Only
2574  *      permitted where the tty session is our session.
2575  *
2576  *      Locking: RCU, ctrl lock
2577  */
2578
2579 static int tiocspgrp(struct tty_struct *tty, struct tty_struct *real_tty, pid_t __user *p)
2580 {
2581         struct pid *pgrp;
2582         pid_t pgrp_nr;
2583         int retval = tty_check_change(real_tty);
2584         unsigned long flags;
2585
2586         if (retval == -EIO)
2587                 return -ENOTTY;
2588         if (retval)
2589                 return retval;
2590         if (!current->signal->tty ||
2591             (current->signal->tty != real_tty) ||
2592             (real_tty->session != task_session(current)))
2593                 return -ENOTTY;
2594         if (get_user(pgrp_nr, p))
2595                 return -EFAULT;
2596         if (pgrp_nr < 0)
2597                 return -EINVAL;
2598         rcu_read_lock();
2599         pgrp = find_vpid(pgrp_nr);
2600         retval = -ESRCH;
2601         if (!pgrp)
2602                 goto out_unlock;
2603         retval = -EPERM;
2604         if (session_of_pgrp(pgrp) != task_session(current))
2605                 goto out_unlock;
2606         retval = 0;
2607         spin_lock_irqsave(&tty->ctrl_lock, flags);
2608         put_pid(real_tty->pgrp);
2609         real_tty->pgrp = get_pid(pgrp);
2610         spin_unlock_irqrestore(&tty->ctrl_lock, flags);
2611 out_unlock:
2612         rcu_read_unlock();
2613         return retval;
2614 }
2615
2616 /**
2617  *      tiocgsid                -       get session id
2618  *      @tty: tty passed by user
2619  *      @real_tty: tty side of the tty passed by the user if a pty else the tty
2620  *      @p: pointer to returned session id
2621  *
2622  *      Obtain the session id of the tty. If there is no session
2623  *      return an error.
2624  *
2625  *      Locking: none. Reference to current->signal->tty is safe.
2626  */
2627
2628 static int tiocgsid(struct tty_struct *tty, struct tty_struct *real_tty, pid_t __user *p)
2629 {
2630         /*
2631          * (tty == real_tty) is a cheap way of
2632          * testing if the tty is NOT a master pty.
2633         */
2634         if (tty == real_tty && current->signal->tty != real_tty)
2635                 return -ENOTTY;
2636         if (!real_tty->session)
2637                 return -ENOTTY;
2638         return put_user(pid_vnr(real_tty->session), p);
2639 }
2640
2641 /**
2642  *      tiocsetd        -       set line discipline
2643  *      @tty: tty device
2644  *      @p: pointer to user data
2645  *
2646  *      Set the line discipline according to user request.
2647  *
2648  *      Locking: see tty_set_ldisc, this function is just a helper
2649  */
2650
2651 static int tiocsetd(struct tty_struct *tty, int __user *p)
2652 {
2653         int ldisc;
2654         int ret;
2655
2656         if (get_user(ldisc, p))
2657                 return -EFAULT;
2658
2659         ret = tty_set_ldisc(tty, ldisc);
2660
2661         return ret;
2662 }
2663
2664 /**
2665  *      send_break      -       performed time break
2666  *      @tty: device to break on
2667  *      @duration: timeout in mS
2668  *
2669  *      Perform a timed break on hardware that lacks its own driver level
2670  *      timed break functionality.
2671  *
2672  *      Locking:
2673  *              atomic_write_lock serializes
2674  *
2675  */
2676
2677 static int send_break(struct tty_struct *tty, unsigned int duration)
2678 {
2679         int retval;
2680
2681         if (tty->ops->break_ctl == NULL)
2682                 return 0;
2683
2684         if (tty->driver->flags & TTY_DRIVER_HARDWARE_BREAK)
2685                 retval = tty->ops->break_ctl(tty, duration);
2686         else {
2687                 /* Do the work ourselves */
2688                 if (tty_write_lock(tty, 0) < 0)
2689                         return -EINTR;
2690                 retval = tty->ops->break_ctl(tty, -1);
2691                 if (retval)
2692                         goto out;
2693                 if (!signal_pending(current))
2694                         msleep_interruptible(duration);
2695                 retval = tty->ops->break_ctl(tty, 0);
2696 out:
2697                 tty_write_unlock(tty);
2698                 if (signal_pending(current))
2699                         retval = -EINTR;
2700         }
2701         return retval;
2702 }
2703
2704 /**
2705  *      tty_tiocmget            -       get modem status
2706  *      @tty: tty device
2707  *      @file: user file pointer
2708  *      @p: pointer to result
2709  *
2710  *      Obtain the modem status bits from the tty driver if the feature
2711  *      is supported. Return -EINVAL if it is not available.
2712  *
2713  *      Locking: none (up to the driver)
2714  */
2715
2716 static int tty_tiocmget(struct tty_struct *tty, int __user *p)
2717 {
2718         int retval = -EINVAL;
2719
2720         if (tty->ops->tiocmget) {
2721                 retval = tty->ops->tiocmget(tty);
2722
2723                 if (retval >= 0)
2724                         retval = put_user(retval, p);
2725         }
2726         return retval;
2727 }
2728
2729 /**
2730  *      tty_tiocmset            -       set modem status
2731  *      @tty: tty device
2732  *      @cmd: command - clear bits, set bits or set all
2733  *      @p: pointer to desired bits
2734  *
2735  *      Set the modem status bits from the tty driver if the feature
2736  *      is supported. Return -EINVAL if it is not available.
2737  *
2738  *      Locking: none (up to the driver)
2739  */
2740
2741 static int tty_tiocmset(struct tty_struct *tty, unsigned int cmd,
2742              unsigned __user *p)
2743 {
2744         int retval;
2745         unsigned int set, clear, val;
2746
2747         if (tty->ops->tiocmset == NULL)
2748                 return -EINVAL;
2749
2750         retval = get_user(val, p);
2751         if (retval)
2752                 return retval;
2753         set = clear = 0;
2754         switch (cmd) {
2755         case TIOCMBIS:
2756                 set = val;
2757                 break;
2758         case TIOCMBIC:
2759                 clear = val;
2760                 break;
2761         case TIOCMSET:
2762                 set = val;
2763                 clear = ~val;
2764                 break;
2765         }
2766         set &= TIOCM_DTR|TIOCM_RTS|TIOCM_OUT1|TIOCM_OUT2|TIOCM_LOOP;
2767         clear &= TIOCM_DTR|TIOCM_RTS|TIOCM_OUT1|TIOCM_OUT2|TIOCM_LOOP;
2768         return tty->ops->tiocmset(tty, set, clear);
2769 }
2770
2771 static int tty_tiocgicount(struct tty_struct *tty, void __user *arg)
2772 {
2773         int retval = -EINVAL;
2774         struct serial_icounter_struct icount;
2775         memset(&icount, 0, sizeof(icount));
2776         if (tty->ops->get_icount)
2777                 retval = tty->ops->get_icount(tty, &icount);
2778         if (retval != 0)
2779                 return retval;
2780         if (copy_to_user(arg, &icount, sizeof(icount)))
2781                 return -EFAULT;
2782         return 0;
2783 }
2784
2785 /*
2786  * if pty, return the slave side (real_tty)
2787  * otherwise, return self
2788  */
2789 static struct tty_struct *tty_pair_get_tty(struct tty_struct *tty)
2790 {
2791         if (tty->driver->type == TTY_DRIVER_TYPE_PTY &&
2792             tty->driver->subtype == PTY_TYPE_MASTER)
2793                 tty = tty->link;
2794         return tty;
2795 }
2796
2797 /*
2798  * Split this up, as gcc can choke on it otherwise..
2799  */
2800 long tty_ioctl(struct file *file, unsigned int cmd, unsigned long arg)
2801 {
2802         struct tty_struct *tty = file_tty(file);
2803         struct tty_struct *real_tty;
2804         void __user *p = (void __user *)arg;
2805         int retval;
2806         struct tty_ldisc *ld;
2807
2808         if (tty_paranoia_check(tty, file_inode(file), "tty_ioctl"))
2809                 return -EINVAL;
2810
2811         real_tty = tty_pair_get_tty(tty);
2812
2813         /*
2814          * Factor out some common prep work
2815          */
2816         switch (cmd) {
2817         case TIOCSETD:
2818         case TIOCSBRK:
2819         case TIOCCBRK:
2820         case TCSBRK:
2821         case TCSBRKP:
2822                 retval = tty_check_change(tty);
2823                 if (retval)
2824                         return retval;
2825                 if (cmd != TIOCCBRK) {
2826                         tty_wait_until_sent(tty, 0);
2827                         if (signal_pending(current))
2828                                 return -EINTR;
2829                 }
2830                 break;
2831         }
2832
2833         /*
2834          *      Now do the stuff.
2835          */
2836         switch (cmd) {
2837         case TIOCSTI:
2838                 return tiocsti(tty, p);
2839         case TIOCGWINSZ:
2840                 return tiocgwinsz(real_tty, p);
2841         case TIOCSWINSZ:
2842                 return tiocswinsz(real_tty, p);
2843         case TIOCCONS:
2844                 return real_tty != tty ? -EINVAL : tioccons(file);
2845         case FIONBIO:
2846                 return fionbio(file, p);
2847         case TIOCEXCL:
2848                 set_bit(TTY_EXCLUSIVE, &tty->flags);
2849                 return 0;
2850         case TIOCNXCL:
2851                 clear_bit(TTY_EXCLUSIVE, &tty->flags);
2852                 return 0;
2853         case TIOCGEXCL:
2854         {
2855                 int excl = test_bit(TTY_EXCLUSIVE, &tty->flags);
2856                 return put_user(excl, (int __user *)p);
2857         }
2858         case TIOCNOTTY:
2859                 if (current->signal->tty != tty)
2860                         return -ENOTTY;
2861                 no_tty();
2862                 return 0;
2863         case TIOCSCTTY:
2864                 return tiocsctty(tty, arg);
2865         case TIOCGPGRP:
2866                 return tiocgpgrp(tty, real_tty, p);
2867         case TIOCSPGRP:
2868                 return tiocspgrp(tty, real_tty, p);
2869         case TIOCGSID:
2870                 return tiocgsid(tty, real_tty, p);
2871         case TIOCGETD:
2872                 return put_user(tty->ldisc->ops->num, (int __user *)p);
2873         case TIOCSETD:
2874                 return tiocsetd(tty, p);
2875         case TIOCVHANGUP:
2876                 if (!capable(CAP_SYS_ADMIN))
2877                         return -EPERM;
2878                 tty_vhangup(tty);
2879                 return 0;
2880         case TIOCGDEV:
2881         {
2882                 unsigned int ret = new_encode_dev(tty_devnum(real_tty));
2883                 return put_user(ret, (unsigned int __user *)p);
2884         }
2885         /*
2886          * Break handling
2887          */
2888         case TIOCSBRK:  /* Turn break on, unconditionally */
2889                 if (tty->ops->break_ctl)
2890                         return tty->ops->break_ctl(tty, -1);
2891                 return 0;
2892         case TIOCCBRK:  /* Turn break off, unconditionally */
2893                 if (tty->ops->break_ctl)
2894                         return tty->ops->break_ctl(tty, 0);
2895                 return 0;
2896         case TCSBRK:   /* SVID version: non-zero arg --> no break */
2897                 /* non-zero arg means wait for all output data
2898                  * to be sent (performed above) but don't send break.
2899                  * This is used by the tcdrain() termios function.
2900                  */
2901                 if (!arg)
2902                         return send_break(tty, 250);
2903                 return 0;
2904         case TCSBRKP:   /* support for POSIX tcsendbreak() */
2905                 return send_break(tty, arg ? arg*100 : 250);
2906
2907         case TIOCMGET:
2908                 return tty_tiocmget(tty, p);
2909         case TIOCMSET:
2910         case TIOCMBIC:
2911         case TIOCMBIS:
2912                 return tty_tiocmset(tty, cmd, p);
2913         case TIOCGICOUNT:
2914                 retval = tty_tiocgicount(tty, p);
2915                 /* For the moment allow fall through to the old method */
2916                 if (retval != -EINVAL)
2917                         return retval;
2918                 break;
2919         case TCFLSH:
2920                 switch (arg) {
2921                 case TCIFLUSH:
2922                 case TCIOFLUSH:
2923                 /* flush tty buffer and allow ldisc to process ioctl */
2924                         tty_buffer_flush(tty);
2925                         break;
2926                 }
2927                 break;
2928         }
2929         if (tty->ops->ioctl) {
2930                 retval = (tty->ops->ioctl)(tty, cmd, arg);
2931                 if (retval != -ENOIOCTLCMD)
2932                         return retval;
2933         }
2934         ld = tty_ldisc_ref_wait(tty);
2935         retval = -EINVAL;
2936         if (ld->ops->ioctl) {
2937                 retval = ld->ops->ioctl(tty, file, cmd, arg);
2938                 if (retval == -ENOIOCTLCMD)
2939                         retval = -ENOTTY;
2940         }
2941         tty_ldisc_deref(ld);
2942         return retval;
2943 }
2944
2945 #ifdef CONFIG_COMPAT
2946 static long tty_compat_ioctl(struct file *file, unsigned int cmd,
2947                                 unsigned long arg)
2948 {
2949         struct tty_struct *tty = file_tty(file);
2950         struct tty_ldisc *ld;
2951         int retval = -ENOIOCTLCMD;
2952
2953         if (tty_paranoia_check(tty, file_inode(file), "tty_ioctl"))
2954                 return -EINVAL;
2955
2956         if (tty->ops->compat_ioctl) {
2957                 retval = (tty->ops->compat_ioctl)(tty, cmd, arg);
2958                 if (retval != -ENOIOCTLCMD)
2959                         return retval;
2960         }
2961
2962         ld = tty_ldisc_ref_wait(tty);
2963         if (ld->ops->compat_ioctl)
2964                 retval = ld->ops->compat_ioctl(tty, file, cmd, arg);
2965         else
2966                 retval = n_tty_compat_ioctl_helper(tty, file, cmd, arg);
2967         tty_ldisc_deref(ld);
2968
2969         return retval;
2970 }
2971 #endif
2972
2973 static int this_tty(const void *t, struct file *file, unsigned fd)
2974 {
2975         if (likely(file->f_op->read != tty_read))
2976                 return 0;
2977         return file_tty(file) != t ? 0 : fd + 1;
2978 }
2979         
2980 /*
2981  * This implements the "Secure Attention Key" ---  the idea is to
2982  * prevent trojan horses by killing all processes associated with this
2983  * tty when the user hits the "Secure Attention Key".  Required for
2984  * super-paranoid applications --- see the Orange Book for more details.
2985  *
2986  * This code could be nicer; ideally it should send a HUP, wait a few
2987  * seconds, then send a INT, and then a KILL signal.  But you then
2988  * have to coordinate with the init process, since all processes associated
2989  * with the current tty must be dead before the new getty is allowed
2990  * to spawn.
2991  *
2992  * Now, if it would be correct ;-/ The current code has a nasty hole -
2993  * it doesn't catch files in flight. We may send the descriptor to ourselves
2994  * via AF_UNIX socket, close it and later fetch from socket. FIXME.
2995  *
2996  * Nasty bug: do_SAK is being called in interrupt context.  This can
2997  * deadlock.  We punt it up to process context.  AKPM - 16Mar2001
2998  */
2999 void __do_SAK(struct tty_struct *tty)
3000 {
3001 #ifdef TTY_SOFT_SAK
3002         tty_hangup(tty);
3003 #else
3004         struct task_struct *g, *p;
3005         struct pid *session;
3006         int             i;
3007
3008         if (!tty)
3009                 return;
3010         session = tty->session;
3011
3012         tty_ldisc_flush(tty);
3013
3014         tty_driver_flush_buffer(tty);
3015
3016         read_lock(&tasklist_lock);
3017         /* Kill the entire session */
3018         do_each_pid_task(session, PIDTYPE_SID, p) {
3019                 printk(KERN_NOTICE "SAK: killed process %d"
3020                         " (%s): task_session(p)==tty->session\n",
3021                         task_pid_nr(p), p->comm);
3022                 send_sig(SIGKILL, p, 1);
3023         } while_each_pid_task(session, PIDTYPE_SID, p);
3024         /* Now kill any processes that happen to have the
3025          * tty open.
3026          */
3027         do_each_thread(g, p) {
3028                 if (p->signal->tty == tty) {
3029                         printk(KERN_NOTICE "SAK: killed process %d"
3030                             " (%s): task_session(p)==tty->session\n",
3031                             task_pid_nr(p), p->comm);
3032                         send_sig(SIGKILL, p, 1);
3033                         continue;
3034                 }
3035                 task_lock(p);
3036                 i = iterate_fd(p->files, 0, this_tty, tty);
3037                 if (i != 0) {
3038                         printk(KERN_NOTICE "SAK: killed process %d"
3039                             " (%s): fd#%d opened to the tty\n",
3040                                     task_pid_nr(p), p->comm, i - 1);
3041                         force_sig(SIGKILL, p);
3042                 }
3043                 task_unlock(p);
3044         } while_each_thread(g, p);
3045         read_unlock(&tasklist_lock);
3046 #endif
3047 }
3048
3049 static void do_SAK_work(struct work_struct *work)
3050 {
3051         struct tty_struct *tty =
3052                 container_of(work, struct tty_struct, SAK_work);
3053         __do_SAK(tty);
3054 }
3055
3056 /*
3057  * The tq handling here is a little racy - tty->SAK_work may already be queued.
3058  * Fortunately we don't need to worry, because if ->SAK_work is already queued,
3059  * the values which we write to it will be identical to the values which it
3060  * already has. --akpm
3061  */
3062 void do_SAK(struct tty_struct *tty)
3063 {
3064         if (!tty)
3065                 return;
3066         schedule_work(&tty->SAK_work);
3067 }
3068
3069 EXPORT_SYMBOL(do_SAK);
3070
3071 static int dev_match_devt(struct device *dev, const void *data)
3072 {
3073         const dev_t *devt = data;
3074         return dev->devt == *devt;
3075 }
3076
3077 /* Must put_device() after it's unused! */
3078 static struct device *tty_get_device(struct tty_struct *tty)
3079 {
3080         dev_t devt = tty_devnum(tty);
3081         return class_find_device(tty_class, NULL, &devt, dev_match_devt);
3082 }
3083
3084
3085 /**
3086  *      alloc_tty_struct
3087  *
3088  *      This subroutine allocates and initializes a tty structure.
3089  *
3090  *      Locking: none - tty in question is not exposed at this point
3091  */
3092
3093 struct tty_struct *alloc_tty_struct(struct tty_driver *driver, int idx)
3094 {
3095         struct tty_struct *tty;
3096
3097         tty = kzalloc(sizeof(*tty), GFP_KERNEL);
3098         if (!tty)
3099                 return NULL;
3100
3101         kref_init(&tty->kref);
3102         tty->magic = TTY_MAGIC;
3103         tty_ldisc_init(tty);
3104         tty->session = NULL;
3105         tty->pgrp = NULL;
3106         mutex_init(&tty->legacy_mutex);
3107         mutex_init(&tty->throttle_mutex);
3108         init_rwsem(&tty->termios_rwsem);
3109         mutex_init(&tty->winsize_mutex);
3110         init_ldsem(&tty->ldisc_sem);
3111         init_waitqueue_head(&tty->write_wait);
3112         init_waitqueue_head(&tty->read_wait);
3113         INIT_WORK(&tty->hangup_work, do_tty_hangup);
3114         mutex_init(&tty->atomic_write_lock);
3115         spin_lock_init(&tty->ctrl_lock);
3116         spin_lock_init(&tty->flow_lock);
3117         INIT_LIST_HEAD(&tty->tty_files);
3118         INIT_WORK(&tty->SAK_work, do_SAK_work);
3119
3120         tty->driver = driver;
3121         tty->ops = driver->ops;
3122         tty->index = idx;
3123         tty_line_name(driver, idx, tty->name);
3124         tty->dev = tty_get_device(tty);
3125
3126         return tty;
3127 }
3128
3129 /**
3130  *      deinitialize_tty_struct
3131  *      @tty: tty to deinitialize
3132  *
3133  *      This subroutine deinitializes a tty structure that has been newly
3134  *      allocated but tty_release cannot be called on that yet.
3135  *
3136  *      Locking: none - tty in question must not be exposed at this point
3137  */
3138 void deinitialize_tty_struct(struct tty_struct *tty)
3139 {
3140         tty_ldisc_deinit(tty);
3141 }
3142
3143 /**
3144  *      tty_put_char    -       write one character to a tty
3145  *      @tty: tty
3146  *      @ch: character
3147  *
3148  *      Write one byte to the tty using the provided put_char method
3149  *      if present. Returns the number of characters successfully output.
3150  *
3151  *      Note: the specific put_char operation in the driver layer may go
3152  *      away soon. Don't call it directly, use this method
3153  */
3154
3155 int tty_put_char(struct tty_struct *tty, unsigned char ch)
3156 {
3157         if (tty->ops->put_char)
3158                 return tty->ops->put_char(tty, ch);
3159         return tty->ops->write(tty, &ch, 1);
3160 }
3161 EXPORT_SYMBOL_GPL(tty_put_char);
3162
3163 struct class *tty_class;
3164
3165 static int tty_cdev_add(struct tty_driver *driver, dev_t dev,
3166                 unsigned int index, unsigned int count)
3167 {
3168         /* init here, since reused cdevs cause crashes */
3169         cdev_init(&driver->cdevs[index], &tty_fops);
3170         driver->cdevs[index].owner = driver->owner;
3171         return cdev_add(&driver->cdevs[index], dev, count);
3172 }
3173
3174 /**
3175  *      tty_register_device - register a tty device
3176  *      @driver: the tty driver that describes the tty device
3177  *      @index: the index in the tty driver for this tty device
3178  *      @device: a struct device that is associated with this tty device.
3179  *              This field is optional, if there is no known struct device
3180  *              for this tty device it can be set to NULL safely.
3181  *
3182  *      Returns a pointer to the struct device for this tty device
3183  *      (or ERR_PTR(-EFOO) on error).
3184  *
3185  *      This call is required to be made to register an individual tty device
3186  *      if the tty driver's flags have the TTY_DRIVER_DYNAMIC_DEV bit set.  If
3187  *      that bit is not set, this function should not be called by a tty
3188  *      driver.
3189  *
3190  *      Locking: ??
3191  */
3192
3193 struct device *tty_register_device(struct tty_driver *driver, unsigned index,
3194                                    struct device *device)
3195 {
3196         return tty_register_device_attr(driver, index, device, NULL, NULL);
3197 }
3198 EXPORT_SYMBOL(tty_register_device);
3199
3200 static void tty_device_create_release(struct device *dev)
3201 {
3202         pr_debug("device: '%s': %s\n", dev_name(dev), __func__);
3203         kfree(dev);
3204 }
3205
3206 /**
3207  *      tty_register_device_attr - register a tty device
3208  *      @driver: the tty driver that describes the tty device
3209  *      @index: the index in the tty driver for this tty device
3210  *      @device: a struct device that is associated with this tty device.
3211  *              This field is optional, if there is no known struct device
3212  *              for this tty device it can be set to NULL safely.
3213  *      @drvdata: Driver data to be set to device.
3214  *      @attr_grp: Attribute group to be set on device.
3215  *
3216  *      Returns a pointer to the struct device for this tty device
3217  *      (or ERR_PTR(-EFOO) on error).
3218  *
3219  *      This call is required to be made to register an individual tty device
3220  *      if the tty driver's flags have the TTY_DRIVER_DYNAMIC_DEV bit set.  If
3221  *      that bit is not set, this function should not be called by a tty
3222  *      driver.
3223  *
3224  *      Locking: ??
3225  */
3226 struct device *tty_register_device_attr(struct tty_driver *driver,
3227                                    unsigned index, struct device *device,
3228                                    void *drvdata,
3229                                    const struct attribute_group **attr_grp)
3230 {
3231         char name[64];
3232         dev_t devt = MKDEV(driver->major, driver->minor_start) + index;
3233         struct device *dev = NULL;
3234         int retval = -ENODEV;
3235         bool cdev = false;
3236
3237         if (index >= driver->num) {
3238                 printk(KERN_ERR "Attempt to register invalid tty line number "
3239                        " (%d).\n", index);
3240                 return ERR_PTR(-EINVAL);
3241         }
3242
3243         if (driver->type == TTY_DRIVER_TYPE_PTY)
3244                 pty_line_name(driver, index, name);
3245         else
3246                 tty_line_name(driver, index, name);
3247
3248         if (!(driver->flags & TTY_DRIVER_DYNAMIC_ALLOC)) {
3249                 retval = tty_cdev_add(driver, devt, index, 1);
3250                 if (retval)
3251                         goto error;
3252                 cdev = true;
3253         }
3254
3255         dev = kzalloc(sizeof(*dev), GFP_KERNEL);
3256         if (!dev) {
3257                 retval = -ENOMEM;
3258                 goto error;
3259         }
3260
3261         dev->devt = devt;
3262         dev->class = tty_class;
3263         dev->parent = device;
3264         dev->release = tty_device_create_release;
3265         dev_set_name(dev, "%s", name);
3266         dev->groups = attr_grp;
3267         dev_set_drvdata(dev, drvdata);
3268
3269         retval = device_register(dev);
3270         if (retval)
3271                 goto error;
3272
3273         return dev;
3274
3275 error:
3276         put_device(dev);
3277         if (cdev)
3278                 cdev_del(&driver->cdevs[index]);
3279         return ERR_PTR(retval);
3280 }
3281 EXPORT_SYMBOL_GPL(tty_register_device_attr);
3282
3283 /**
3284  *      tty_unregister_device - unregister a tty device
3285  *      @driver: the tty driver that describes the tty device
3286  *      @index: the index in the tty driver for this tty device
3287  *
3288  *      If a tty device is registered with a call to tty_register_device() then
3289  *      this function must be called when the tty device is gone.
3290  *
3291  *      Locking: ??
3292  */
3293
3294 void tty_unregister_device(struct tty_driver *driver, unsigned index)
3295 {
3296         device_destroy(tty_class,
3297                 MKDEV(driver->major, driver->minor_start) + index);
3298         if (!(driver->flags & TTY_DRIVER_DYNAMIC_ALLOC))
3299                 cdev_del(&driver->cdevs[index]);
3300 }
3301 EXPORT_SYMBOL(tty_unregister_device);
3302
3303 /**
3304  * __tty_alloc_driver -- allocate tty driver
3305  * @lines: count of lines this driver can handle at most
3306  * @owner: module which is repsonsible for this driver
3307  * @flags: some of TTY_DRIVER_* flags, will be set in driver->flags
3308  *
3309  * This should not be called directly, some of the provided macros should be
3310  * used instead. Use IS_ERR and friends on @retval.
3311  */
3312 struct tty_driver *__tty_alloc_driver(unsigned int lines, struct module *owner,
3313                 unsigned long flags)
3314 {
3315         struct tty_driver *driver;
3316         unsigned int cdevs = 1;
3317         int err;
3318
3319         if (!lines || (flags & TTY_DRIVER_UNNUMBERED_NODE && lines > 1))
3320                 return ERR_PTR(-EINVAL);
3321
3322         driver = kzalloc(sizeof(struct tty_driver), GFP_KERNEL);
3323         if (!driver)
3324                 return ERR_PTR(-ENOMEM);
3325
3326         kref_init(&driver->kref);
3327         driver->magic = TTY_DRIVER_MAGIC;
3328         driver->num = lines;
3329         driver->owner = owner;
3330         driver->flags = flags;
3331
3332         if (!(flags & TTY_DRIVER_DEVPTS_MEM)) {
3333                 driver->ttys = kcalloc(lines, sizeof(*driver->ttys),
3334                                 GFP_KERNEL);
3335                 driver->termios = kcalloc(lines, sizeof(*driver->termios),
3336                                 GFP_KERNEL);
3337                 if (!driver->ttys || !driver->termios) {
3338                         err = -ENOMEM;
3339                         goto err_free_all;
3340                 }
3341         }
3342
3343         if (!(flags & TTY_DRIVER_DYNAMIC_ALLOC)) {
3344                 driver->ports = kcalloc(lines, sizeof(*driver->ports),
3345                                 GFP_KERNEL);
3346                 if (!driver->ports) {
3347                         err = -ENOMEM;
3348                         goto err_free_all;
3349                 }
3350                 cdevs = lines;
3351         }
3352
3353         driver->cdevs = kcalloc(cdevs, sizeof(*driver->cdevs), GFP_KERNEL);
3354         if (!driver->cdevs) {
3355                 err = -ENOMEM;
3356                 goto err_free_all;
3357         }
3358
3359         return driver;
3360 err_free_all:
3361         kfree(driver->ports);
3362         kfree(driver->ttys);
3363         kfree(driver->termios);
3364         kfree(driver);
3365         return ERR_PTR(err);
3366 }
3367 EXPORT_SYMBOL(__tty_alloc_driver);
3368
3369 static void destruct_tty_driver(struct kref *kref)
3370 {
3371         struct tty_driver *driver = container_of(kref, struct tty_driver, kref);
3372         int i;
3373         struct ktermios *tp;
3374
3375         if (driver->flags & TTY_DRIVER_INSTALLED) {
3376                 /*
3377                  * Free the termios and termios_locked structures because
3378                  * we don't want to get memory leaks when modular tty
3379                  * drivers are removed from the kernel.
3380                  */
3381                 for (i = 0; i < driver->num; i++) {
3382                         tp = driver->termios[i];
3383                         if (tp) {
3384                                 driver->termios[i] = NULL;
3385                                 kfree(tp);
3386                         }
3387                         if (!(driver->flags & TTY_DRIVER_DYNAMIC_DEV))
3388                                 tty_unregister_device(driver, i);
3389                 }
3390                 proc_tty_unregister_driver(driver);
3391                 if (driver->flags & TTY_DRIVER_DYNAMIC_ALLOC)
3392                         cdev_del(&driver->cdevs[0]);
3393         }
3394         kfree(driver->cdevs);
3395         kfree(driver->ports);
3396         kfree(driver->termios);
3397         kfree(driver->ttys);
3398         kfree(driver);
3399 }
3400
3401 void tty_driver_kref_put(struct tty_driver *driver)
3402 {
3403         kref_put(&driver->kref, destruct_tty_driver);
3404 }
3405 EXPORT_SYMBOL(tty_driver_kref_put);
3406
3407 void tty_set_operations(struct tty_driver *driver,
3408                         const struct tty_operations *op)
3409 {
3410         driver->ops = op;
3411 };
3412 EXPORT_SYMBOL(tty_set_operations);
3413
3414 void put_tty_driver(struct tty_driver *d)
3415 {
3416         tty_driver_kref_put(d);
3417 }
3418 EXPORT_SYMBOL(put_tty_driver);
3419
3420 /*
3421  * Called by a tty driver to register itself.
3422  */
3423 int tty_register_driver(struct tty_driver *driver)
3424 {
3425         int error;
3426         int i;
3427         dev_t dev;
3428         struct device *d;
3429
3430         if (!driver->major) {
3431                 error = alloc_chrdev_region(&dev, driver->minor_start,
3432                                                 driver->num, driver->name);
3433                 if (!error) {
3434                         driver->major = MAJOR(dev);
3435                         driver->minor_start = MINOR(dev);
3436                 }
3437         } else {
3438                 dev = MKDEV(driver->major, driver->minor_start);
3439                 error = register_chrdev_region(dev, driver->num, driver->name);
3440         }
3441         if (error < 0)
3442                 goto err;
3443
3444         if (driver->flags & TTY_DRIVER_DYNAMIC_ALLOC) {
3445                 error = tty_cdev_add(driver, dev, 0, driver->num);
3446                 if (error)
3447                         goto err_unreg_char;
3448         }
3449
3450         mutex_lock(&tty_mutex);
3451         list_add(&driver->tty_drivers, &tty_drivers);
3452         mutex_unlock(&tty_mutex);
3453
3454         if (!(driver->flags & TTY_DRIVER_DYNAMIC_DEV)) {
3455                 for (i = 0; i < driver->num; i++) {
3456                         d = tty_register_device(driver, i, NULL);
3457                         if (IS_ERR(d)) {
3458                                 error = PTR_ERR(d);
3459                                 goto err_unreg_devs;
3460                         }
3461                 }
3462         }
3463         proc_tty_register_driver(driver);
3464         driver->flags |= TTY_DRIVER_INSTALLED;
3465         return 0;
3466
3467 err_unreg_devs:
3468         for (i--; i >= 0; i--)
3469                 tty_unregister_device(driver, i);
3470
3471         mutex_lock(&tty_mutex);
3472         list_del(&driver->tty_drivers);
3473         mutex_unlock(&tty_mutex);
3474
3475 err_unreg_char:
3476         unregister_chrdev_region(dev, driver->num);
3477 err:
3478         return error;
3479 }
3480 EXPORT_SYMBOL(tty_register_driver);
3481
3482 /*
3483  * Called by a tty driver to unregister itself.
3484  */
3485 int tty_unregister_driver(struct tty_driver *driver)
3486 {
3487 #if 0
3488         /* FIXME */
3489         if (driver->refcount)
3490                 return -EBUSY;
3491 #endif
3492         unregister_chrdev_region(MKDEV(driver->major, driver->minor_start),
3493                                 driver->num);
3494         mutex_lock(&tty_mutex);
3495         list_del(&driver->tty_drivers);
3496         mutex_unlock(&tty_mutex);
3497         return 0;
3498 }
3499
3500 EXPORT_SYMBOL(tty_unregister_driver);
3501
3502 dev_t tty_devnum(struct tty_struct *tty)
3503 {
3504         return MKDEV(tty->driver->major, tty->driver->minor_start) + tty->index;
3505 }
3506 EXPORT_SYMBOL(tty_devnum);
3507
3508 void tty_default_fops(struct file_operations *fops)
3509 {
3510         *fops = tty_fops;
3511 }
3512
3513 /*
3514  * Initialize the console device. This is called *early*, so
3515  * we can't necessarily depend on lots of kernel help here.
3516  * Just do some early initializations, and do the complex setup
3517  * later.
3518  */
3519 void __init console_init(void)
3520 {
3521         initcall_t *call;
3522
3523         /* Setup the default TTY line discipline. */
3524         tty_ldisc_begin();
3525
3526         /*
3527          * set up the console device so that later boot sequences can
3528          * inform about problems etc..
3529          */
3530         call = __con_initcall_start;
3531         while (call < __con_initcall_end) {
3532                 (*call)();
3533                 call++;
3534         }
3535 }
3536
3537 static char *tty_devnode(struct device *dev, umode_t *mode)
3538 {
3539         if (!mode)
3540                 return NULL;
3541         if (dev->devt == MKDEV(TTYAUX_MAJOR, 0) ||
3542             dev->devt == MKDEV(TTYAUX_MAJOR, 2))
3543                 *mode = 0666;
3544         return NULL;
3545 }
3546
3547 static int __init tty_class_init(void)
3548 {
3549         tty_class = class_create(THIS_MODULE, "tty");
3550         if (IS_ERR(tty_class))
3551                 return PTR_ERR(tty_class);
3552         tty_class->devnode = tty_devnode;
3553         return 0;
3554 }
3555
3556 postcore_initcall(tty_class_init);
3557
3558 /* 3/2004 jmc: why do these devices exist? */
3559 static struct cdev tty_cdev, console_cdev;
3560
3561 static ssize_t show_cons_active(struct device *dev,
3562                                 struct device_attribute *attr, char *buf)
3563 {
3564         struct console *cs[16];
3565         int i = 0;
3566         struct console *c;
3567         ssize_t count = 0;
3568
3569         console_lock();
3570         for_each_console(c) {
3571                 if (!c->device)
3572                         continue;
3573                 if (!c->write)
3574                         continue;
3575                 if ((c->flags & CON_ENABLED) == 0)
3576                         continue;
3577                 cs[i++] = c;
3578                 if (i >= ARRAY_SIZE(cs))
3579                         break;
3580         }
3581         while (i--) {
3582                 int index = cs[i]->index;
3583                 struct tty_driver *drv = cs[i]->device(cs[i], &index);
3584
3585                 /* don't resolve tty0 as some programs depend on it */
3586                 if (drv && (cs[i]->index > 0 || drv->major != TTY_MAJOR))
3587                         count += tty_line_name(drv, index, buf + count);
3588                 else
3589                         count += sprintf(buf + count, "%s%d",
3590                                          cs[i]->name, cs[i]->index);
3591
3592                 count += sprintf(buf + count, "%c", i ? ' ':'\n');
3593         }
3594         console_unlock();
3595
3596         return count;
3597 }
3598 static DEVICE_ATTR(active, S_IRUGO, show_cons_active, NULL);
3599
3600 static struct device *consdev;
3601
3602 void console_sysfs_notify(void)
3603 {
3604         if (consdev)
3605                 sysfs_notify(&consdev->kobj, NULL, "active");
3606 }
3607
3608 /*
3609  * Ok, now we can initialize the rest of the tty devices and can count
3610  * on memory allocations, interrupts etc..
3611  */
3612 int __init tty_init(void)
3613 {
3614         cdev_init(&tty_cdev, &tty_fops);
3615         if (cdev_add(&tty_cdev, MKDEV(TTYAUX_MAJOR, 0), 1) ||
3616             register_chrdev_region(MKDEV(TTYAUX_MAJOR, 0), 1, "/dev/tty") < 0)
3617                 panic("Couldn't register /dev/tty driver\n");
3618         device_create(tty_class, NULL, MKDEV(TTYAUX_MAJOR, 0), NULL, "tty");
3619
3620         cdev_init(&console_cdev, &console_fops);
3621         if (cdev_add(&console_cdev, MKDEV(TTYAUX_MAJOR, 1), 1) ||
3622             register_chrdev_region(MKDEV(TTYAUX_MAJOR, 1), 1, "/dev/console") < 0)
3623                 panic("Couldn't register /dev/console driver\n");
3624         consdev = device_create(tty_class, NULL, MKDEV(TTYAUX_MAJOR, 1), NULL,
3625                               "console");
3626         if (IS_ERR(consdev))
3627                 consdev = NULL;
3628         else
3629                 WARN_ON(device_create_file(consdev, &dev_attr_active) < 0);
3630
3631 #ifdef CONFIG_VT
3632         vty_init(&console_fops);
3633 #endif
3634         return 0;
3635 }
3636