Files
android_kernel_fxtec_sm6115/include/linux/string.h
Thomas Turner b49f61e801 Merge tag 'v4.19.325-cip134' of https://git.kernel.org/pub/scm/linux/kernel/git/cip/linux-cip into android13-4.19-kona
version 4.19.325-cip134

* tag 'v4.19.325-cip134' of https://git.kernel.org/pub/scm/linux/kernel/git/cip/linux-cip:
  CIP: Bump version suffix to -cip134 after merge from cip/linux-4.19.y-st tree
  Update localversion-st, tree is up-to-date with 5.10.258.
  tipc: fix double-free in tipc_buf_append()
  slip: reject VJ receive packets on instances with no rstate array
  netfilter: nfnetlink_osf: fix potential NULL dereference in ttl check
  wifi: brcmfmac: Fix error pointer dereference
  bpf: fix end-of-list detection in cgroup_storage_get_next_key()
  crypto: ccp - copy IV using skcipher ivsize
  netfilter: ipset: stop hash:* range iteration at end
  net/sched: netem: fix queue limit check to include reordered packets
  cdrom, scsi: sr: propagate read-only status to block layer via set_disk_ro()
  btrfs: fix double-decrement of bytes_may_use in submit_one_async_extent()
  crypto: authencesn - reject short ahash digests during instance creation
  crypto: ccp: Don't attempt to copy PDH cert to userspace if PSP command failed
  crypto: ccp: Don't attempt to copy CSR to userspace if PSP command failed
  x86/uprobes: Fix XOL allocation failure for 32-bit tasks
  blk-mq: use quiesced elevator switch when reinitializing queues
  scsi: ufs: core: Improve SCSI abort handling
  bcache: fix cached_dev.sb_bio use-after-free and crash
  rxrpc: proc: size address buffers for %pISpc output
  can: raw: fix ro->uniq use-after-free in raw_rcv()
  can: af_can: export can_sock_destruct()
  batman-adv: hold claim backbone gateways by reference
  l2tp: Drop large packets with UDP encap
  xsk: tighten UMEM headroom validation to account for tailroom and min frame
  can: mcp251x: add error handling for power enable in open and resume
  net: skbuff: propagate shared-frag marker through frag-transfer helpers
  Revert "i2c: fsi: Fix a potential leak in fsi_i2c_probe()"
  net: usb: lan78xx: Fix double free issue with interrupt buffer allocation
  string: add mem_is_zero() helper to check if memory area is all zeros
  tracing: Avoid NULL return from hist_field_name() on truncation
  platform/x86: intel-hid: Check ACPI_HANDLE() against NULL
  HID: quirks: really enable the intended work around for appledisplay
  net: ethernet: cs89x0: remove stale CONFIG_MACH_MX31ADS reference
  net: ethernet: cortina: Carry over frag counter
  net: ethernet: cortina: Drop half-assembled SKB
  net: ethernet: cortina: Make RX SKB per-port
  irqchip/ath79-cpu: Remove unused function
  ARM: integrator: Fix early initialization
  batman-adv: tt: fix negative tt_buff_len
  batman-adv: tt: fix negative last_changeset_len
  batman-adv: tp_meter: avoid use of uninit sender vars
  batman-adv: bla: fix report_work leak on backbone_gw purge
  batman-adv: frag: disallow unicast fragment in fragment
  batman-adv: fix tp_meter counter underflow during shutdown
  batman-adv: fix fragment reassembly length accounting
  batman-adv: dat: handle forward allocation error
  batman-adv: clear current gateway during teardown
  batman-adv: mcast: fix use-after-free in orig_node RCU release
  drm/amd/display: Fix integer overflow in bios_get_image()
  spi: ti-qspi: fix use-after-free after DMA setup failure
  scsi: isci: Fix use-after-free in device removal path
  tracing: Do not call map->ops->elt_free() if elt_alloc() fails
  ixgbevf: fix use-after-free in VEPA multicast source pruning
  ipv4: raw: reject IP_HDRINCL packets with ihl < 5
  vsock/vmci: fix UAF when peer resets connection during handshake
  netfilter: ip6t_hbh: reject oversized option lists
  net: bcmgenet: keep RBUF EEE/PM disabled
  phonet/pep: disable BH around forwarded sk_receive_skb()
  Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths
  Bluetooth: bnep: Fix UAF read of dev->name
  ALSA: asihpi: Fix potential OOB array access at reading cache
  ALSA: ua101: Reject too-short USB descriptors
  sysfs: don't remove existing directory on update failure
  smb: client: reject userspace cifs.spnego descriptions
  Revert "s390/cio: Fix device lifecycle handling in css_alloc_subchannel()"
  selftests: lib.mk: Also install "config" and "settings"
  s390/debug: Reject zero-length input before trimming a newline
  net/rds: reset op_nents when zerocopy page pin fails
  drm/gma500/oaktrail_hdmi: fix i2c adapter leak on setup
  libceph: Fix potential out-of-bounds access in crush_decode()
  libceph: Fix potential null-ptr-deref in decode_choose_args()
  powerpc/warp: Fix error handling in pika_dtm_thread
  ceph: fix a buffer leak in __ceph_setxattr()
  ALSA: usb-audio: Bound MIDI endpoint descriptor scans
  audit: enforce AUDIT_LOCKED for AUDIT_TRIM and AUDIT_MAKE_EQUIV
  audit: fix incorrect inheritable capability in CAPSET records
  crypto: af_alg - Cap AEAD AD length to 0x80000000
  btrfs: tracepoints: fix sleep while in atomic context in btrfs_sync_file()
  drm/amd/display: Read EDID from VBIOS embedded panel info
  drm/amd/display: Allow DCE link encoder without AUX registers
  net/sched: sch_cake: annotate data-races in cake_dump_stats() (V)
  sctp: discard stale INIT after handshake completion
  ASoC: codecs: ab8500: Fix casting of private data
  NFC: trf7970a: Ignore antenna noise when checking for RF field
  net: usb: rtl8150: free skb on usb_submit_urb() failure in xmit
  net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit()
  vrf: Fix a potential NPD when removing a port from a VRF
  net/sched: sch_choke: annotate data-races in choke_dump_stats()
  net: sched: choke: remove unused variables in struct choke_sched_data
  net/sched: netem: validate slot configuration
  net/sched: netem: fix probability gaps in 4-state loss model
  net: sched: sch_netem: Refactor code in 4-state loss generator
  scsi: sr: Add memory allocation failure handling for get_capabilities()
  netfilter: nf_conntrack_sip: don't use simple_strtoul
  netfilter: xt_policy: fix strict mode inbound policy matching
  drm/amdgpu/gfx6: Support harvested SI chips with disabled TCCs (v2)
  netfilter: arp_tables: fix IEEE1394 ARP payload parsing
  tracing: branch: Fix inverted check on stat tracer registration
  mailbox: mailbox-test: initialize struct earlier
  mailbox: mailbox-test: don't free the reused channel
  mailbox: add sanity check for channel array
  cgroup/rdma: fix integer overflow in rdmacg_try_charge()
  mailbox: mailbox-test: free channels on probe error
  fbdev: offb: fix PCI device reference leak on probe failure
  net/sched: sch_sfb: annotate data-races in sfb_dump_stats()
  net/sched: sch_fq_codel: remove data-races from fq_codel_dump_stats()
  net_sched: sch_hhf: annotate data-races in hhf_dump_stats()
  net/rds: zero per-item info buffer before handing it to visitors
  slip: bound decode() reads against the compressed packet length
  netfilter: nfnetlink_osf: fix out-of-bounds read on option matching
  ipvs: fix MTU check for GSO packets in tunnel mode
  netfilter: xtables: restrict several matches to inet family
  netfilter: conntrack: remove sprintf usage
  netfilter: nfnetlink_osf: fix divide-by-zero in OSF_WSS_MODULO
  netfilter: nft_osf: restrict it to ipv4
  openvswitch: cap upcall PID array size and pre-size vport replies
  dissector: do not set invalid PPP protocol
  sctp: fix OOB write to userspace in sctp_getsockopt_peer_auth_chunks
  ipv6: fix possible UAF in icmpv6_rcv()
  e1000e: Unroll PTP in probe error handling
  i40e: don't advertise IFF_SUPP_NOFCS
  PCMCIA: Fix garbled log messages for KERN_CONT
  clk: xgene: Fix mapping leak in xgene_pllclk_init()
  clk: qoriq: avoid format string warning
  clk: imx: imx6q: Fix device node reference leak in of_assigned_ldb_sels()
  scsi: target: core: Fix integer overflow in UNMAP bounds check
  scsi: sg: Resolve soft lockup issue when opening /dev/sgX
  RDMA/core: Prefer NLA_NUL_STRING
  nfs/blocklayout: Fix compilation error (`make W=1`) in bl_write_pagelist()
  mfd: mc13xxx-core: Fix memory leak in mc13xxx_add_subdevice_pdata()
  tty: hvc_iucv: fix off-by-one in number of supported devices
  tty: hvc: remove HVC_IUCV_MAGIC
  platform/surface: surfacepro3_button: Drop wakeup source on remove
  driver core: device.h: remove extern from function prototypes
  perf util: Kill die() prototype, dead for a long time
  pinctrl: abx500: Fix type of 'argument' variable
  pinctrl: pinctrl-pic32: Fix resource leak
  bpf: Fix precedence bug in convert_bpf_ld_abs alignment check
  HID: usbhid: fix deadlock in hid_post_reset()
  mtd: rawnand: sunxi: fix sunxi_nfc_hw_ecc_read_extra_oob
  HID: asus: do not abort probe when not necessary
  HID: asus: make asus_resume adhere to linux kernel coding standards
  ima: check return value of crypto_shash_final() in boot aggregate
  tracing: Rebuild full_name on each hist_field_name() call
  ocfs2: validate group add input before caching
  ocfs2: validate bg_bits during freefrag scan
  ocfs2: fix listxattr handling when the buffer is full
  ocfs2/dlm: fix off-by-one in dlm_match_regions() region comparison
  ocfs2/dlm: validate qr_numregions in dlm_match_regions()
  memory: tegra124-emc: Fix dll_change check
  ARM: dts: mediatek: mt7623: fix efuse fallback compatible
  efi/capsule-loader: fix incorrect sizeof in phys array reallocation
  quota: Fix race of dquot_scan_active() with quota deactivation
  ktest: Honor empty per-test option overrides
  ktest: Avoid undef warning when WARNINGS_FILE is unset
  selftest: memcg: skip memcg_sock test if address family not supported
  Documentation: fix a hugetlbfs reservation statement
  ALSA: hda/realtek: fix code style (ERROR: else should follow close brace '}')
  ALSA: hda/realtek: Whitespace fix
  drm/amd/pm/ci: Clear EnabledForActivity field for memory levels
  drm/amd/pm/ci: Fix powertune defaults for Hawaii 0x67B0
  drm/amd/pm/ci: Use highest MCLK on CI when MCLK DPM is disabled
  ALSA: core: Validate compress device numbers without dynamic minors
  ALSA: compress: Drop unused functions
  fbdev: matroxfb: Mark variable with __maybe_unused to avoid W=1 build break
  drm/sun4i: Fix resource leaks
  dm log: fix out-of-bounds write due to region_count overflow
  dm cache metadata: fix memory leak on metadata abort retry
  dm cache: fix concurrent write failure in passthrough mode
  dm cache policy smq: fix missing locks in invalidating cache blocks
  dm cache: fix write path cache coherency in passthrough mode
  dm cache: fix null-deref with concurrent writes in passthrough mode
  ASoC: sti: use managed regmap_field allocations
  ASoC: sti: Return errors from regmap_field_alloc()
  Bluetooth: hci_ldisc: Clear HCI_UART_PROTO_INIT on error
  Bluetooth: L2CAP: Fix printing wrong information if SDU length exceeds MTU
  ppp: require CAP_NET_ADMIN in target netns for unattached ioctls
  net/rds: Optimize rds_ib_laddr_check
  net: hamradio: 6pack: fix uninit-value in sixpack_receive_buf
  6pack: propagage new tty types
  netfilter: nft_fwd_netdev: check ttl/hl before forwarding
  net: bcmgenet: fix off-by-one in bcmgenet_put_txcb
  wifi: rtlwifi: pci: fix possible use-after-free caused by unfinished irq_prepare_bcn_tasklet
  firmware: dmi: Correct an indexing error in dmi.h
  locking: Fix rwlock support in <linux/spinlock_up.h>
  irqchip/irq-pic32-evic: Address warning related to wrong printf() formatter
  thermal/drivers/spear: Fix error condition for reading st,thermal-flags
  pstore/ram: fix resource leak when ioremap() fails
  nilfs2: reject zero bd_oblocknr in nilfs_ioctl_mark_blocks_dirty()
  drbd: Balance RCU calls in drbd_adm_dump_devices()
  fs/omfs: reject s_sys_blocksize smaller than OMFS_DIR_START
  Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_get_sndtimeo_cb()
  batman-adv: bla: put backbone reference on failed claim hash insert
  batman-adv: bla: only purge non-released claims
  batman-adv: bla: prevent use-after-free when deleting claims
  batman-adv: reject new tp_meter sessions during teardown
  batman-adv: fix integer overflow on buff_pos
  sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL
  drm/amdgpu/pm: align Hawaii mclk workaround with radeon
  drm/amdgpu/pm: add missing revision check for CI
  drm/amdgpu/sdma4: replace BUG_ON with WARN_ON in fence emission
  drm/amdgpu/gfx9: drop unnecessary 64-bit fence flag check in KIQ
  drm/radeon: add missing revision check for CI
  spi: mpc52xx: fix use-after-free on unbind
  media: dib8000: avoid division by 0 in dib8000_set_dds()
  media: rc: streamzap: Error handling in probe
  media: uvcvideo: Enable VB2_DMABUF for metadata stream
  RDMA/rxe: Reject unknown opcodes before ICRC processing
  RDMA/ocrdma: Don't NULL deref uctx on errors in ocrdma_copy_pd_uresp()
  power: supply: max17042: avoid overflow when determining health
  PCI/AER: Stop ruling out unbound devices as error source
  s390/debug: Reject zero-length input in debug_input_flush_fn()
  nvmet: avoid recursive nvmet-wq flush in nvmet_ctrl_free
  md/raid10: fix divide-by-zero in setup_geo() with zero far_copies
  isofs: validate block number from NFS file handle in isofs_export_iget
  isofs: validate Rock Ridge CE continuation extent against volume size
  dm-verity-fec: correctly reject too-small hash devices
  dm-verity-fec: correctly reject too-small FEC devices
  dm: fix a buffer overflow in ioctl processing
  dm: don't report warning when doing deferred remove
  cpuidle: powerpc: avoid double clear when breaking snooze
  spi: topcliff-pch: fix use-after-free on unbind
  udf: reject descriptors with oversized CRC length
  ibmveth: Disable GSO for packets with small MSS
  parisc: Fix IRQ leak in LASI driver
  net/rds: handle zerocopy send cleanup before the message is queued
  ip6_gre: Use cached t->net in ip6erspan_changelink().
  sound: ua101: fix division by zero at probe
  Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_state_change_cb()
  Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_new_connection_cb()
  usb: ulpi: fix memory leak on ulpi_register() error paths
  USB: serial: option: add Telit Cinterion LE910Cx compositions
  USB: omap_udc: DMA: Don't enable burst 4 mode
  ALSA: usb-audio: Fix UAC3 cluster descriptor size check
  ALSA: usb-audio: Avoid potential endless loop in convert_chmap_v3()
  usb: usblp: fix uninitialized heap leak via LPGETSTATUS ioctl
  usb: usblp: fix heap leak in IEEE 1284 device ID via short response
  wifi: b43: enforce bounds check on firmware key index in b43_rx()
  wifi: ath5k: do not access array OOB
  wifi: rsi: fix kthread lifetime race between self-exit and external-stop
  wifi: b43legacy: enforce bounds check on firmware key index in RX path
  ipmi:ssif: NULL thread on error
  ipmi:ssif: Remove unnecessary indention
  ipmi:ssif: Clean up kthread on errors
  ipmi:ssif: Fix a shutdown race
  net/sched: sch_red: Replace direct dequeue call with peek and qdisc_dequeue_peeked
  fbdev: udlfb: add vm_ops to dlfb_ops_mmap to prevent use-after-free
  ipmi:si: Return state to normal if message allocation fails
  ipmi: Check event message buffer response for bad data
  ipmi: Add limits to event and receive message requests
  scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show()
  ALSA: caiaq: fix usb_dev refcount leak on probe failure
  ALSA: caiaq: Don't abort when no input device is available
  ALSA: caiaq: Fix potentially leftover ep1_in_urb at error path
  dm mirror: fix integer overflow in create_dirty_log()
  crypto: atmel-tdes - fix DMA sync direction
  crypto: ccree - fix a memory leak in cc_mac_digest()
  crypto: hisilicon - Fix dma_unmap_single() direction
  crypto: atmel-ecc - Release client on allocation failure
  crypto: atmel-aes - Fix 3-page memory leak in atmel_aes_buff_cleanup
  taskstats: set version in TGID exit notifications
  inotify: fix watch count leak when fsnotify_add_inode_mark_locked() fails
  md/raid5: validate payload size before accessing journal metadata
  md/raid5: fix soft lockup in retry_aligned_read()
  ext4: fix missing brelse() in ext4_xattr_inode_dec_ref_all()
  userfaultfd: allow registration of ranges below mmap_min_addr
  tpm: tpm_tis: add error logging for data transfer
  mmc: block: use single block write in retry
  RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv
  ALSA: 6fire: Fix input volume change detection
  ALSA: caiaq: Handle probe errors properly
  ALSA: caiaq: Fix control_put() result and cache rollback
  ALSA: seq_oss: return full count for successful SEQ_FULLSIZE writes
  ALSA: ctxfi: Add fallback to default RSR for S/PDIF
  lib/ts_kmp: fix integer overflow in pattern length calculation
  Revert "ALSA: usb: Increase volume range that triggers a warning"
  net: strparser: fix skb_head leak in strp_abort_strp()
  net: caif: clear client service pointer on teardown
  ALSA: control: Validate buf_len before strnlen() in snd_ctl_elem_init_enum_names()
  crypto: pcrypt - Fix handling of MAY_BACKLOG requests
  um: drivers: call kernel_strrchr() explicitly in cow_user.c
  firmware: google: framebuffer: Do not mark framebuffer as busy
  ibmasm: fix heap over-read in ibmasm_send_i2o_message()
  ibmasm: fix OOB reads in command_file_write due to missing size checks
  misc: ibmasm: fix OOB MMIO read in ibmasm_handle_mouse_interrupt()
  ALSA: usb-audio: Fix Audio Advantage Micro II SPDIF switch
  ALSA: usb-audio: Avoid false E-MU sample-rate notifications
  ALSA: usb-audio: stop parsing UAC2 rates at MAX_NR_RATES
  rxrpc: Fix missing validation of ticket length in non-XDR key preparsing
  ALSA: caiaq: take a reference on the USB device in create_card()
  ALSA: usb-audio: apply quirk for MOONDROP JU Jiu
  rxrpc: Fix anonymous key handling
  scripts/dtc: Remove unused dts_version in dtc-lexer.l
  gfs2: Validate i_depth for exhash directories
  mm: blk-cgroup: fix use-after-free in cgwb_release_workfn()
  ocfs2: fix possible deadlock between unlink and dio_end_io_write
  fs/ocfs2: fix comments mentioning i_mutex
  rxrpc: reject undecryptable rxkad response tickets
  ocfs2: fix out-of-bounds write in ocfs2_write_end_inline
  ocfs2: validate inline data i_size during inode read
  ocfs2: add inline inode consistency check to ocfs2_validate_inode_block()
  xfrm: clear trailing padding in build_polexpire()
  rxrpc: fix reference count leak in rxrpc_server_keyring()
  mailbox: Prevent out-of-bounds access in of_mbox_index_xlate()
  wifi: mac80211: always free skb on ieee80211_tx_prepare_skb() failure
  ipv6: add NULL checks for idev in SRv6 paths
  net: tap: NULL pointer derefence in dev_parse_header_protocol when skb->dev is null
  media: hackrf: fix to not free memory after the device is registered in hackrf_probe()
  nilfs2: fix NULL i_assoc_inode dereference in nilfs_mdt_save_to_shadow_map
  media: as102: fix to not free memory after the device is registered in as102_usb_probe()
  ALSA: 6fire: fix use-after-free on disconnect
  media: em28xx: fix use-after-free in em28xx_v4l2_open()
  mm/kasan: fix double free for kasan pXds
  KVM: x86: Use scratch field in MMIO fragment to hold small write values
  media: uvcvideo: Allow extra entities
  Revert "wifi: cfg80211: stop NAN and P2P in cfg80211_leave"
  rxrpc: Fix call removal to use RCU safe deletion
  ACPI: property: Constify stubs for CONFIG_ACPI=n case
  ocfs2: handle invalid dinode in ocfs2_group_extend
  ocfs2: fix use-after-free in ocfs2_fault() when VM_FAULT_RETRY
  ALSA: ctxfi: Limit PTP to a single page
  USB: serial: option: add Telit Cinterion FN990A MBIM composition
  fbdev: udlfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO
  usb: storage: Expand range of matched versions for VL817 quirks entry
  usbip: validate number_of_packets in usbip_pack_ret_submit()
  usb: gadget: renesas_usb3: validate endpoint index in standard request handlers
  usb: gadget: f_phonet: fix skb frags[] overflow in pn_rx_complete()
  usb: gadget: f_ncm: validate minimum block_len in ncm_unwrap_ntb()
  fbdev: tdfxfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO
  ALSA: fireworks: bound device-supplied status before string array lookup
  NFC: digital: Bounds check NFC-A cascade depth in SDD response handler
  net: usb: cdc-phonet: fix skb frags[] overflow in rx_complete()
  HID: core: clamp report_size in s32ton() to avoid undefined shift
  HID: alps: fix NULL pointer dereference in alps_raw_event()
  staging: rtl8723bs: initialize le_tmp64 in rtw_BIP_verify()
  i2c: s3c24xx: check the size of the SMBUS message before using it
  nfc: llcp: add missing return after LLCP_CLOSED checks
  MIPS: mm: Suppress TLB uniquification on EHINV hardware
  af_unix: read UNIX_DIAG_VFS data under unix_state_lock
  netfilter: ip6t_eui64: reject invalid MAC header for all packets
  netfilter: xt_multiport: validate range encoding in checkentry
  netfilter: nfnetlink_log: initialize nfgenmsg in NLMSG_DONE terminator
  xfrm_user: fix info leak in build_mapping()
  e1000: check return value of e1000_read_eeprom
  net: lapbether: replace comparison to NULL with "lapbeth_get_x25_dev"
  net: lapbether: Close the LAPB device before its underlying Ethernet device closes
  net: sched: act_csum: validate nested VLAN headers
  drm/vc4: Protect madv read in vc4_gem_object_mmap() with madv_lock
  drm/vc4: Fix a memory leak in hang state error path
  drm/vc4: Fix memory leak of BO array in hang state
  ASoC: stm32_sai: fix incorrect BCLK polarity for DSP_A/B, LEFT_J
  wifi: brcmfmac: validate bsscfg indices in IF events
  ata: ahci: force 32-bit DMA for JMicron JMB582/JMB585
  HID: roccat: fix use-after-free in roccat_report_event
  HID: quirks: add HID_QUIRK_ALWAYS_POLL for 8BitDo Pro 3
  wifi: wl1251: validate packet IDs before indexing tx_frames
  btrfs: tracepoints: get correct superblock from dentry in event btrfs_sync_file()
  ALSA: asihpi: avoid write overflow check warning
  net: skbuff: preserve shared-frag marker during coalescing

Change-Id: I535ecdb1a77312a12564125fedb9f99b3a5533d1
2026-07-09 22:06:07 +01:00

530 lines
16 KiB
C

/* SPDX-License-Identifier: GPL-2.0 */
#ifndef _LINUX_STRING_H_
#define _LINUX_STRING_H_
#include <linux/compiler.h> /* for inline */
#include <linux/types.h> /* for size_t */
#include <linux/stddef.h> /* for NULL */
#include <stdarg.h>
#include <uapi/linux/string.h>
extern char *strndup_user(const char __user *, long);
extern void *memdup_user(const void __user *, size_t);
extern void *vmemdup_user(const void __user *, size_t);
extern void *memdup_user_nul(const void __user *, size_t);
/*
* Include machine specific inline routines
*/
#include <asm/string.h>
#ifndef __HAVE_ARCH_STRCPY
extern char * strcpy(char *,const char *);
#endif
#ifndef __HAVE_ARCH_STRNCPY
extern char * strncpy(char *,const char *, __kernel_size_t);
#endif
#ifndef __HAVE_ARCH_STRLCPY
size_t strlcpy(char *, const char *, size_t);
#endif
#ifndef __HAVE_ARCH_STRSCPY
ssize_t strscpy(char *, const char *, size_t);
#endif
/* Wraps calls to strscpy()/memset(), no arch specific code required */
ssize_t strscpy_pad(char *dest, const char *src, size_t count);
#ifndef __HAVE_ARCH_STRCAT
extern char * strcat(char *, const char *);
#endif
#ifndef __HAVE_ARCH_STRNCAT
extern char * strncat(char *, const char *, __kernel_size_t);
#endif
#ifndef __HAVE_ARCH_STRLCAT
extern size_t strlcat(char *, const char *, __kernel_size_t);
#endif
#ifndef __HAVE_ARCH_STRCMP
extern int strcmp(const char *,const char *);
#endif
#ifndef __HAVE_ARCH_STRNCMP
extern int strncmp(const char *,const char *,__kernel_size_t);
#endif
#ifndef __HAVE_ARCH_STRCASECMP
extern int strcasecmp(const char *s1, const char *s2);
#endif
#ifndef __HAVE_ARCH_STRNCASECMP
extern int strncasecmp(const char *s1, const char *s2, size_t n);
#endif
#ifndef __HAVE_ARCH_STRCHR
extern char * strchr(const char *,int);
#endif
#ifndef __HAVE_ARCH_STRCHRNUL
extern char * strchrnul(const char *,int);
#endif
#ifndef __HAVE_ARCH_STRNCHR
extern char * strnchr(const char *, size_t, int);
#endif
#ifndef __HAVE_ARCH_STRRCHR
extern char * strrchr(const char *,int);
#endif
extern char * __must_check skip_spaces(const char *);
extern char *strim(char *);
static inline __must_check char *strstrip(char *str)
{
return strim(str);
}
#ifndef __HAVE_ARCH_STRSTR
extern char * strstr(const char *, const char *);
#endif
#ifndef __HAVE_ARCH_STRNSTR
extern char * strnstr(const char *, const char *, size_t);
#endif
#ifndef __HAVE_ARCH_STRLEN
extern __kernel_size_t strlen(const char *);
#endif
#ifndef __HAVE_ARCH_STRNLEN
extern __kernel_size_t strnlen(const char *,__kernel_size_t);
#endif
#ifndef __HAVE_ARCH_STRPBRK
extern char * strpbrk(const char *,const char *);
#endif
#ifndef __HAVE_ARCH_STRSEP
extern char * strsep(char **,const char *);
#endif
#ifndef __HAVE_ARCH_STRSPN
extern __kernel_size_t strspn(const char *,const char *);
#endif
#ifndef __HAVE_ARCH_STRCSPN
extern __kernel_size_t strcspn(const char *,const char *);
#endif
#ifndef __HAVE_ARCH_MEMSET
extern void * memset(void *,int,__kernel_size_t);
#endif
#ifndef __HAVE_ARCH_MEMSET16
extern void *memset16(uint16_t *, uint16_t, __kernel_size_t);
#endif
#ifndef __HAVE_ARCH_MEMSET32
extern void *memset32(uint32_t *, uint32_t, __kernel_size_t);
#endif
#ifndef __HAVE_ARCH_MEMSET64
extern void *memset64(uint64_t *, uint64_t, __kernel_size_t);
#endif
static inline void *memset_l(unsigned long *p, unsigned long v,
__kernel_size_t n)
{
if (BITS_PER_LONG == 32)
return memset32((uint32_t *)p, v, n);
else
return memset64((uint64_t *)p, v, n);
}
static inline void *memset_p(void **p, void *v, __kernel_size_t n)
{
if (BITS_PER_LONG == 32)
return memset32((uint32_t *)p, (uintptr_t)v, n);
else
return memset64((uint64_t *)p, (uintptr_t)v, n);
}
#ifndef __HAVE_ARCH_MEMCPY
extern void * memcpy(void *,const void *,__kernel_size_t);
#endif
#ifndef __HAVE_ARCH_MEMMOVE
extern void * memmove(void *,const void *,__kernel_size_t);
#endif
#ifndef __HAVE_ARCH_MEMSCAN
extern void * memscan(void *,int,__kernel_size_t);
#endif
#ifndef __HAVE_ARCH_MEMCMP
extern int memcmp(const void *,const void *,__kernel_size_t);
#endif
#ifndef __HAVE_ARCH_BCMP
extern int bcmp(const void *,const void *,__kernel_size_t);
#endif
#ifndef __HAVE_ARCH_MEMCHR
extern void * memchr(const void *,int,__kernel_size_t);
#endif
#ifndef __HAVE_ARCH_MEMCPY_MCSAFE
static inline __must_check unsigned long memcpy_mcsafe(void *dst,
const void *src, size_t cnt)
{
memcpy(dst, src, cnt);
return 0;
}
#endif
#ifndef __HAVE_ARCH_MEMCPY_FLUSHCACHE
static inline void memcpy_flushcache(void *dst, const void *src, size_t cnt)
{
memcpy(dst, src, cnt);
}
#endif
void *memchr_inv(const void *s, int c, size_t n);
char *strreplace(char *s, char old, char new);
/**
* mem_is_zero - Check if an area of memory is all 0's.
* @s: The memory area
* @n: The size of the area
*
* Return: True if the area of memory is all 0's.
*/
static inline bool mem_is_zero(const void *s, size_t n)
{
return !memchr_inv(s, 0, n);
}
extern void kfree_const(const void *x);
extern char *kstrdup(const char *s, gfp_t gfp) __malloc;
extern const char *kstrdup_const(const char *s, gfp_t gfp);
extern char *kstrndup(const char *s, size_t len, gfp_t gfp);
extern void *kmemdup(const void *src, size_t len, gfp_t gfp);
extern char *kmemdup_nul(const char *s, size_t len, gfp_t gfp);
extern char **argv_split(gfp_t gfp, const char *str, int *argcp);
extern void argv_free(char **argv);
extern bool sysfs_streq(const char *s1, const char *s2);
extern int kstrtobool(const char *s, bool *res);
static inline int strtobool(const char *s, bool *res)
{
return kstrtobool(s, res);
}
int match_string(const char * const *array, size_t n, const char *string);
int __sysfs_match_string(const char * const *array, size_t n, const char *s);
/**
* sysfs_match_string - matches given string in an array
* @_a: array of strings
* @_s: string to match with
*
* Helper for __sysfs_match_string(). Calculates the size of @a automatically.
*/
#define sysfs_match_string(_a, _s) __sysfs_match_string(_a, ARRAY_SIZE(_a), _s)
#ifdef CONFIG_BINARY_PRINTF
int vbin_printf(u32 *bin_buf, size_t size, const char *fmt, va_list args);
int bstr_printf(char *buf, size_t size, const char *fmt, const u32 *bin_buf);
int bprintf(u32 *bin_buf, size_t size, const char *fmt, ...) __printf(3, 4);
#endif
extern ssize_t memory_read_from_buffer(void *to, size_t count, loff_t *ppos,
const void *from, size_t available);
int ptr_to_hashval(const void *ptr, unsigned long *hashval_out);
/**
* strstarts - does @str start with @prefix?
* @str: string to examine
* @prefix: prefix to look for.
*/
static inline bool strstarts(const char *str, const char *prefix)
{
return strncmp(str, prefix, strlen(prefix)) == 0;
}
size_t memweight(const void *ptr, size_t bytes);
void memzero_explicit(void *s, size_t count);
/**
* kbasename - return the last part of a pathname.
*
* @path: path to extract the filename from.
*/
static inline const char *kbasename(const char *path)
{
const char *tail = strrchr(path, '/');
return tail ? tail + 1 : path;
}
#define __FORTIFY_INLINE extern __always_inline __attribute__((gnu_inline))
#define __RENAME(x) __asm__(#x)
void fortify_panic(const char *name) __noreturn __cold;
void __read_overflow(void) __compiletime_error("detected read beyond size of object passed as 1st parameter");
void __read_overflow2(void) __compiletime_error("detected read beyond size of object passed as 2nd parameter");
void __read_overflow3(void) __compiletime_error("detected read beyond size of object passed as 3rd parameter");
void __write_overflow(void) __compiletime_error("detected write beyond size of object passed as 1st parameter");
#if !defined(__NO_FORTIFY) && defined(__OPTIMIZE__) && defined(CONFIG_FORTIFY_SOURCE)
#ifdef CONFIG_KASAN
extern void *__underlying_memchr(const void *p, int c, __kernel_size_t size) __RENAME(memchr);
extern int __underlying_memcmp(const void *p, const void *q, __kernel_size_t size) __RENAME(memcmp);
extern void *__underlying_memcpy(void *p, const void *q, __kernel_size_t size) __RENAME(memcpy);
extern void *__underlying_memmove(void *p, const void *q, __kernel_size_t size) __RENAME(memmove);
extern void *__underlying_memset(void *p, int c, __kernel_size_t size) __RENAME(memset);
extern char *__underlying_strcat(char *p, const char *q) __RENAME(strcat);
extern char *__underlying_strcpy(char *p, const char *q) __RENAME(strcpy);
extern __kernel_size_t __underlying_strlen(const char *p) __RENAME(strlen);
extern char *__underlying_strncat(char *p, const char *q, __kernel_size_t count) __RENAME(strncat);
extern char *__underlying_strncpy(char *p, const char *q, __kernel_size_t size) __RENAME(strncpy);
#else
#define __underlying_memchr __builtin_memchr
#define __underlying_memcmp __builtin_memcmp
#define __underlying_memcpy __builtin_memcpy
#define __underlying_memmove __builtin_memmove
#define __underlying_memset __builtin_memset
#define __underlying_strcat __builtin_strcat
#define __underlying_strcpy __builtin_strcpy
#define __underlying_strlen __builtin_strlen
#define __underlying_strncat __builtin_strncat
#define __underlying_strncpy __builtin_strncpy
#endif
__FORTIFY_INLINE char *strncpy(char *p, const char *q, __kernel_size_t size)
{
size_t p_size = __builtin_object_size(p, 0);
if (__builtin_constant_p(size) && p_size < size)
__write_overflow();
if (p_size < size)
fortify_panic(__func__);
return __underlying_strncpy(p, q, size);
}
__FORTIFY_INLINE char *strcat(char *p, const char *q)
{
size_t p_size = __builtin_object_size(p, 0);
if (p_size == (size_t)-1)
return __underlying_strcat(p, q);
if (strlcat(p, q, p_size) >= p_size)
fortify_panic(__func__);
return p;
}
__FORTIFY_INLINE __kernel_size_t strlen(const char *p)
{
__kernel_size_t ret;
size_t p_size = __builtin_object_size(p, 0);
/* Work around gcc excess stack consumption issue */
if (p_size == (size_t)-1 ||
(__builtin_constant_p(p[p_size - 1]) && p[p_size - 1] == '\0'))
return __underlying_strlen(p);
ret = strnlen(p, p_size);
if (p_size <= ret)
fortify_panic(__func__);
return ret;
}
extern __kernel_size_t __real_strnlen(const char *, __kernel_size_t) __RENAME(strnlen);
__FORTIFY_INLINE __kernel_size_t strnlen(const char *p, __kernel_size_t maxlen)
{
size_t p_size = __builtin_object_size(p, 0);
__kernel_size_t ret = __real_strnlen(p, maxlen < p_size ? maxlen : p_size);
if (p_size <= ret && maxlen != ret)
fortify_panic(__func__);
return ret;
}
/* defined after fortified strlen to reuse it */
extern size_t __real_strlcpy(char *, const char *, size_t) __RENAME(strlcpy);
__FORTIFY_INLINE size_t strlcpy(char *p, const char *q, size_t size)
{
size_t ret;
size_t p_size = __builtin_object_size(p, 0);
size_t q_size = __builtin_object_size(q, 0);
if (p_size == (size_t)-1 && q_size == (size_t)-1)
return __real_strlcpy(p, q, size);
ret = strlen(q);
if (size) {
size_t len = (ret >= size) ? size - 1 : ret;
if (__builtin_constant_p(len) && len >= p_size)
__write_overflow();
if (len >= p_size)
fortify_panic(__func__);
__underlying_memcpy(p, q, len);
p[len] = '\0';
}
return ret;
}
/* defined after fortified strlen and strnlen to reuse them */
__FORTIFY_INLINE char *strncat(char *p, const char *q, __kernel_size_t count)
{
size_t p_len, copy_len;
size_t p_size = __builtin_object_size(p, 0);
size_t q_size = __builtin_object_size(q, 0);
if (p_size == (size_t)-1 && q_size == (size_t)-1)
return __underlying_strncat(p, q, count);
p_len = strlen(p);
copy_len = strnlen(q, count);
if (p_size < p_len + copy_len + 1)
fortify_panic(__func__);
__underlying_memcpy(p + p_len, q, copy_len);
p[p_len + copy_len] = '\0';
return p;
}
__FORTIFY_INLINE void *memset(void *p, int c, __kernel_size_t size)
{
size_t p_size = __builtin_object_size(p, 0);
if (__builtin_constant_p(size) && p_size < size)
__write_overflow();
if (p_size < size)
fortify_panic(__func__);
return __underlying_memset(p, c, size);
}
__FORTIFY_INLINE void *memcpy(void *p, const void *q, __kernel_size_t size)
{
size_t p_size = __builtin_object_size(p, 0);
size_t q_size = __builtin_object_size(q, 0);
if (__builtin_constant_p(size)) {
if (p_size < size)
__write_overflow();
if (q_size < size)
__read_overflow2();
}
if (p_size < size || q_size < size)
fortify_panic(__func__);
return __underlying_memcpy(p, q, size);
}
__FORTIFY_INLINE void *memmove(void *p, const void *q, __kernel_size_t size)
{
size_t p_size = __builtin_object_size(p, 0);
size_t q_size = __builtin_object_size(q, 0);
if (__builtin_constant_p(size)) {
if (p_size < size)
__write_overflow();
if (q_size < size)
__read_overflow2();
}
if (p_size < size || q_size < size)
fortify_panic(__func__);
return __underlying_memmove(p, q, size);
}
extern void *__real_memscan(void *, int, __kernel_size_t) __RENAME(memscan);
__FORTIFY_INLINE void *memscan(void *p, int c, __kernel_size_t size)
{
size_t p_size = __builtin_object_size(p, 0);
if (__builtin_constant_p(size) && p_size < size)
__read_overflow();
if (p_size < size)
fortify_panic(__func__);
return __real_memscan(p, c, size);
}
__FORTIFY_INLINE int memcmp(const void *p, const void *q, __kernel_size_t size)
{
size_t p_size = __builtin_object_size(p, 0);
size_t q_size = __builtin_object_size(q, 0);
if (__builtin_constant_p(size)) {
if (p_size < size)
__read_overflow();
if (q_size < size)
__read_overflow2();
}
if (p_size < size || q_size < size)
fortify_panic(__func__);
return __underlying_memcmp(p, q, size);
}
__FORTIFY_INLINE void *memchr(const void *p, int c, __kernel_size_t size)
{
size_t p_size = __builtin_object_size(p, 0);
if (__builtin_constant_p(size) && p_size < size)
__read_overflow();
if (p_size < size)
fortify_panic(__func__);
return __underlying_memchr(p, c, size);
}
void *__real_memchr_inv(const void *s, int c, size_t n) __RENAME(memchr_inv);
__FORTIFY_INLINE void *memchr_inv(const void *p, int c, size_t size)
{
size_t p_size = __builtin_object_size(p, 0);
if (__builtin_constant_p(size) && p_size < size)
__read_overflow();
if (p_size < size)
fortify_panic(__func__);
return __real_memchr_inv(p, c, size);
}
extern void *__real_kmemdup(const void *src, size_t len, gfp_t gfp) __RENAME(kmemdup);
__FORTIFY_INLINE void *kmemdup(const void *p, size_t size, gfp_t gfp)
{
size_t p_size = __builtin_object_size(p, 0);
if (__builtin_constant_p(size) && p_size < size)
__read_overflow();
if (p_size < size)
fortify_panic(__func__);
return __real_kmemdup(p, size, gfp);
}
/* defined after fortified strlen and memcpy to reuse them */
__FORTIFY_INLINE char *strcpy(char *p, const char *q)
{
size_t p_size = __builtin_object_size(p, 0);
size_t q_size = __builtin_object_size(q, 0);
if (p_size == (size_t)-1 && q_size == (size_t)-1)
return __underlying_strcpy(p, q);
memcpy(p, q, strlen(q) + 1);
return p;
}
/* Don't use these outside the FORITFY_SOURCE implementation */
#undef __underlying_memchr
#undef __underlying_memcmp
#undef __underlying_memcpy
#undef __underlying_memmove
#undef __underlying_memset
#undef __underlying_strcat
#undef __underlying_strcpy
#undef __underlying_strlen
#undef __underlying_strncat
#undef __underlying_strncpy
#endif
/**
* memcpy_and_pad - Copy one buffer to another with padding
* @dest: Where to copy to
* @dest_len: The destination buffer size
* @src: Where to copy from
* @count: The number of bytes to copy
* @pad: Character to use for padding if space is left in destination.
*/
static inline void memcpy_and_pad(void *dest, size_t dest_len,
const void *src, size_t count, int pad)
{
if (dest_len > count) {
memcpy(dest, src, count);
memset(dest + count, pad, dest_len - count);
} else
memcpy(dest, src, dest_len);
}
/**
* str_has_prefix - Test if a string has a given prefix
* @str: The string to test
* @prefix: The string to see if @str starts with
*
* A common way to test a prefix of a string is to do:
* strncmp(str, prefix, sizeof(prefix) - 1)
*
* But this can lead to bugs due to typos, or if prefix is a pointer
* and not a constant. Instead use str_has_prefix().
*
* Returns: 0 if @str does not start with @prefix
strlen(@prefix) if @str does start with @prefix
*/
static __always_inline size_t str_has_prefix(const char *str, const char *prefix)
{
size_t len = strlen(prefix);
return strncmp(str, prefix, len) == 0 ? len : 0;
}
#endif /* _LINUX_STRING_H_ */