Loading...
bsd/dev/memdev.c xnu-12377.121.6 xnu-8019.41.5
--- xnu/xnu-12377.121.6/bsd/dev/memdev.c
+++ xnu/xnu-8019.41.5/bsd/dev/memdev.c
@@ -92,7 +92,7 @@
 #include <libkern/libkern.h>
 
 #include <vm/pmap.h>
-#include <vm/vm_pager_xnu.h>
+#include <vm/vm_pager.h>
 #include <mach/memory_object_types.h>
 #include <kern/debug.h>
 
@@ -158,8 +158,8 @@
 };
 
 struct mdev {
-	uint64_t        mdBase;         /* base page number (pages are assumed to be 4K). Multiply by 4096 to find actual address */
-	uint32_t        mdSize;         /* size in pages (pages are assumed to be 4K). Multiply by 4096 to find actual size. */
+	uint64_t        mdBase;         /* file size in bytes */
+	uint32_t        mdSize;         /* file size in bytes */
 	int                     mdFlags;        /* flags */
 	int                     mdSecsize;      /* sector size */
 	int                     mdBDev;         /* Block device number */
@@ -196,7 +196,7 @@
 
 	devid = minor(dev);                                                                     /* Get minor device number */
 
-	if (devid >= NB_MAX_MDEVICES || devid < 0) {
+	if (devid >= NB_MAX_MDEVICES) {
 		return ENXIO;                                                                 /* Not valid */
 	}
 	if ((flags & FWRITE) && (mdev[devid].mdFlags & mdRO)) {
@@ -211,26 +211,24 @@
 	int                     status;
 	addr64_t                mdata;
 	int                     devid;
-	enum uio_seg            saveflag;
-	int                     count;
+	enum uio_seg    saveflag;
 
 	devid = minor(dev);                                                                     /* Get minor device number */
 
-	if (devid >= NB_MAX_MDEVICES || devid < 0) {
+	if (devid >= NB_MAX_MDEVICES) {
 		return ENXIO;                                                                 /* Not valid */
 	}
 	if (!(mdev[devid].mdFlags & mdInited)) {
 		return ENXIO;                                 /* Have we actually been defined yet? */
 	}
-	if (uio->uio_offset < 0) {
-		return EINVAL;  /* invalid offset */
-	}
-	if (uio_resid(uio) < 0) {
-		return EINVAL;
-	}
 	mdata = ((addr64_t)mdev[devid].mdBase << 12) + uio->uio_offset; /* Point to the area in "file" */
 
 	saveflag = uio->uio_segflg;                                                     /* Remember what the request is */
+#if LP64_DEBUG
+	if (UIO_IS_USER_SPACE(uio) == 0 && UIO_IS_SYS_SPACE(uio) == 0) {
+		panic("mdevrw - invalid uio_segflg");
+	}
+#endif /* LP64_DEBUG */
 	/* Make sure we are moving from physical ram if physical device */
 	if (mdev[devid].mdFlags & mdPhys) {
 		if (uio->uio_segflg == UIO_USERSPACE64) {
@@ -241,14 +239,7 @@
 			uio->uio_segflg = UIO_PHYS_USERSPACE;
 		}
 	}
-
-	if (uio->uio_offset > (mdev[devid].mdSize << 12)) {
-		count = 0;
-	} else {
-		count = imin(uio_resid(uio), (mdev[devid].mdSize << 12) - uio->uio_offset);
-	}
-
-	status = uiomove64(mdata, count, uio);     /* Move the data */
+	status = uiomove64(mdata, (int)uio_resid(uio), uio);    /* Move the data */
 	uio->uio_segflg = saveflag;                                                     /* Restore the flag */
 
 	return status;
@@ -384,7 +375,7 @@
 
 	devid = minor(dev);                                                                     /* Get minor device number */
 
-	if (devid >= NB_MAX_MDEVICES || devid < 0) {
+	if (devid >= NB_MAX_MDEVICES) {
 		return ENXIO;                                                                 /* Not valid */
 	}
 	error = proc_suser(p);                  /* Are we superman? */
@@ -468,7 +459,7 @@
 	int devid;
 
 	devid = minor(dev);                                                                     /* Get minor device number */
-	if (devid >= NB_MAX_MDEVICES || devid < 0) {
+	if (devid >= NB_MAX_MDEVICES) {
 		return ENXIO;                                                                 /* Not valid */
 	}
 	if ((mdev[devid].mdFlags & mdInited) == 0) {