l2cap_core.c 98.7 KB
Newer Older
1
/*
L
Linus Torvalds 已提交
2 3
   BlueZ - Bluetooth protocol stack for Linux
   Copyright (C) 2000-2001 Qualcomm Incorporated
4
   Copyright (C) 2009-2010 Gustavo F. Padovan <gustavo@padovan.org>
5
   Copyright (C) 2010 Google Inc.
L
Linus Torvalds 已提交
6 7 8 9 10 11 12 13 14 15 16

   Written 2000,2001 by Maxim Krasnyansky <maxk@qualcomm.com>

   This program is free software; you can redistribute it and/or modify
   it under the terms of the GNU General Public License version 2 as
   published by the Free Software Foundation;

   THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS
   OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
   FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT OF THIRD PARTY RIGHTS.
   IN NO EVENT SHALL THE COPYRIGHT HOLDER(S) AND AUTHOR(S) BE LIABLE FOR ANY
17 18 19
   CLAIM, OR ANY SPECIAL INDIRECT OR CONSEQUENTIAL DAMAGES, OR ANY DAMAGES
   WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
   ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
L
Linus Torvalds 已提交
20 21
   OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.

22 23
   ALL LIABILITY, INCLUDING LIABILITY FOR INFRINGEMENT OF ANY PATENTS,
   COPYRIGHTS, TRADEMARKS OR OTHER RIGHTS, RELATING TO USE OF THIS
L
Linus Torvalds 已提交
24 25 26
   SOFTWARE IS DISCLAIMED.
*/

27
/* Bluetooth L2CAP core. */
L
Linus Torvalds 已提交
28 29 30 31

#include <linux/module.h>

#include <linux/types.h>
32
#include <linux/capability.h>
L
Linus Torvalds 已提交
33 34 35 36 37 38 39 40 41 42 43
#include <linux/errno.h>
#include <linux/kernel.h>
#include <linux/sched.h>
#include <linux/slab.h>
#include <linux/poll.h>
#include <linux/fcntl.h>
#include <linux/init.h>
#include <linux/interrupt.h>
#include <linux/socket.h>
#include <linux/skbuff.h>
#include <linux/list.h>
44
#include <linux/device.h>
45 46
#include <linux/debugfs.h>
#include <linux/seq_file.h>
47
#include <linux/uaccess.h>
48
#include <linux/crc16.h>
L
Linus Torvalds 已提交
49 50 51 52 53 54 55 56 57
#include <net/sock.h>

#include <asm/system.h>
#include <asm/unaligned.h>

#include <net/bluetooth/bluetooth.h>
#include <net/bluetooth/hci_core.h>
#include <net/bluetooth/l2cap.h>

58
int disable_ertm;
59

60
static u32 l2cap_feat_mask = L2CAP_FEAT_FIXED_CHAN;
61
static u8 l2cap_fixed_chan[8] = { 0x02, };
L
Linus Torvalds 已提交
62

63 64
static struct workqueue_struct *_busy_wq;

65 66
static LIST_HEAD(chan_list);
static DEFINE_RWLOCK(chan_list_lock);
L
Linus Torvalds 已提交
67

68 69
static void l2cap_busy_work(struct work_struct *work);

L
Linus Torvalds 已提交
70 71
static struct sk_buff *l2cap_build_cmd(struct l2cap_conn *conn,
				u8 code, u8 ident, u16 dlen, void *data);
72 73
static void l2cap_send_cmd(struct l2cap_conn *conn, u8 ident, u8 code, u16 len,
								void *data);
74
static int l2cap_build_conf_req(struct l2cap_chan *chan, void *data);
75 76
static void l2cap_send_disconn_req(struct l2cap_conn *conn,
				struct l2cap_chan *chan, int err);
L
Linus Torvalds 已提交
77

78 79
static int l2cap_ertm_data_rcv(struct sock *sk, struct sk_buff *skb);

80
/* ---- L2CAP channels ---- */
81
static struct l2cap_chan *__l2cap_get_chan_by_dcid(struct l2cap_conn *conn, u16 cid)
82
{
83
	struct l2cap_chan *c;
84 85

	list_for_each_entry(c, &conn->chan_l, list) {
86
		if (c->dcid == cid)
87
			return c;
88
	}
89 90
	return NULL;

91 92
}

93
static struct l2cap_chan *__l2cap_get_chan_by_scid(struct l2cap_conn *conn, u16 cid)
94
{
95
	struct l2cap_chan *c;
96 97

	list_for_each_entry(c, &conn->chan_l, list) {
98
		if (c->scid == cid)
99
			return c;
100
	}
101
	return NULL;
102 103 104 105
}

/* Find channel with given SCID.
 * Returns locked socket */
106
static struct l2cap_chan *l2cap_get_chan_by_scid(struct l2cap_conn *conn, u16 cid)
107
{
108
	struct l2cap_chan *c;
109 110 111

	read_lock(&conn->chan_lock);
	c = __l2cap_get_chan_by_scid(conn, cid);
112 113
	if (c)
		bh_lock_sock(c->sk);
114
	read_unlock(&conn->chan_lock);
115
	return c;
116 117
}

118
static struct l2cap_chan *__l2cap_get_chan_by_ident(struct l2cap_conn *conn, u8 ident)
119
{
120
	struct l2cap_chan *c;
121 122

	list_for_each_entry(c, &conn->chan_l, list) {
123
		if (c->ident == ident)
124
			return c;
125
	}
126
	return NULL;
127 128
}

129
static inline struct l2cap_chan *l2cap_get_chan_by_ident(struct l2cap_conn *conn, u8 ident)
130
{
131
	struct l2cap_chan *c;
132 133 134

	read_lock(&conn->chan_lock);
	c = __l2cap_get_chan_by_ident(conn, ident);
135 136
	if (c)
		bh_lock_sock(c->sk);
137
	read_unlock(&conn->chan_lock);
138
	return c;
139 140
}

141
static struct l2cap_chan *__l2cap_global_chan_by_addr(__le16 psm, bdaddr_t *src)
142
{
143
	struct l2cap_chan *c;
144

145 146
	list_for_each_entry(c, &chan_list, global_l) {
		if (c->sport == psm && !bacmp(&bt_sk(c->sk)->src, src))
147 148 149
			goto found;
	}

150
	c = NULL;
151
found:
152
	return c;
153 154 155 156
}

int l2cap_add_psm(struct l2cap_chan *chan, bdaddr_t *src, __le16 psm)
{
157 158
	int err;

159
	write_lock_bh(&chan_list_lock);
160

161
	if (psm && __l2cap_global_chan_by_addr(psm, src)) {
162 163
		err = -EADDRINUSE;
		goto done;
164 165
	}

166 167 168 169 170 171 172 173 174
	if (psm) {
		chan->psm = psm;
		chan->sport = psm;
		err = 0;
	} else {
		u16 p;

		err = -EINVAL;
		for (p = 0x1001; p < 0x1100; p += 2)
175
			if (!__l2cap_global_chan_by_addr(cpu_to_le16(p), src)) {
176 177 178 179 180 181
				chan->psm   = cpu_to_le16(p);
				chan->sport = cpu_to_le16(p);
				err = 0;
				break;
			}
	}
182

183
done:
184
	write_unlock_bh(&chan_list_lock);
185
	return err;
186 187 188 189
}

int l2cap_add_scid(struct l2cap_chan *chan,  __u16 scid)
{
190
	write_lock_bh(&chan_list_lock);
191 192 193

	chan->scid = scid;

194
	write_unlock_bh(&chan_list_lock);
195 196 197 198

	return 0;
}

199
static u16 l2cap_alloc_cid(struct l2cap_conn *conn)
200
{
201
	u16 cid = L2CAP_CID_DYN_START;
202

203
	for (; cid < L2CAP_CID_DYN_END; cid++) {
204
		if (!__l2cap_get_chan_by_scid(conn, cid))
205 206 207 208 209 210
			return cid;
	}

	return 0;
}

211 212 213 214 215 216 217 218
static void l2cap_chan_set_timer(struct l2cap_chan *chan, long timeout)
{
       BT_DBG("chan %p state %d timeout %ld", chan->sk, chan->sk->sk_state,
								 timeout);
       if (!mod_timer(&chan->chan_timer, jiffies + timeout))
	       sock_hold(chan->sk);
}

219
static void l2cap_chan_clear_timer(struct l2cap_chan *chan)
220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 252
{
       BT_DBG("chan %p state %d", chan, chan->sk->sk_state);

       if (timer_pending(&chan->chan_timer) && del_timer(&chan->chan_timer))
	       __sock_put(chan->sk);
}

static void l2cap_chan_timeout(unsigned long arg)
{
	struct l2cap_chan *chan = (struct l2cap_chan *) arg;
	struct sock *sk = chan->sk;
	int reason;

	BT_DBG("chan %p state %d", chan, sk->sk_state);

	bh_lock_sock(sk);

	if (sock_owned_by_user(sk)) {
		/* sk is owned by user. Try again later */
		l2cap_chan_set_timer(chan, HZ / 5);
		bh_unlock_sock(sk);
		sock_put(sk);
		return;
	}

	if (sk->sk_state == BT_CONNECTED || sk->sk_state == BT_CONFIG)
		reason = ECONNREFUSED;
	else if (sk->sk_state == BT_CONNECT &&
					chan->sec_level != BT_SECURITY_SDP)
		reason = ECONNREFUSED;
	else
		reason = ETIMEDOUT;

253
	l2cap_chan_close(chan, reason);
254 255 256 257 258 259 260

	bh_unlock_sock(sk);

	l2cap_sock_kill(sk);
	sock_put(sk);
}

261
struct l2cap_chan *l2cap_chan_create(struct sock *sk)
262 263 264 265 266 267 268 269 270
{
	struct l2cap_chan *chan;

	chan = kzalloc(sizeof(*chan), GFP_ATOMIC);
	if (!chan)
		return NULL;

	chan->sk = sk;

271 272 273 274
	write_lock_bh(&chan_list_lock);
	list_add(&chan->global_l, &chan_list);
	write_unlock_bh(&chan_list_lock);

275 276
	setup_timer(&chan->chan_timer, l2cap_chan_timeout, (unsigned long) chan);

277 278 279
	return chan;
}

280
void l2cap_chan_destroy(struct l2cap_chan *chan)
281
{
282 283 284 285
	write_lock_bh(&chan_list_lock);
	list_del(&chan->global_l);
	write_unlock_bh(&chan_list_lock);

286 287 288
	kfree(chan);
}

289
static void __l2cap_chan_add(struct l2cap_conn *conn, struct l2cap_chan *chan)
290
{
291
	struct sock *sk = chan->sk;
292

293
	BT_DBG("conn %p, psm 0x%2.2x, dcid 0x%4.4x", conn,
294
			chan->psm, chan->dcid);
295

296 297
	conn->disc_reason = 0x13;

298
	chan->conn = conn;
299

300
	if (chan->chan_type == L2CAP_CHAN_CONN_ORIENTED) {
301 302
		if (conn->hcon->type == LE_LINK) {
			/* LE connection */
303
			chan->omtu = L2CAP_LE_DEFAULT_MTU;
304 305
			chan->scid = L2CAP_CID_LE_DATA;
			chan->dcid = L2CAP_CID_LE_DATA;
306 307
		} else {
			/* Alloc CID for connection-oriented socket */
308
			chan->scid = l2cap_alloc_cid(conn);
309
			chan->omtu = L2CAP_DEFAULT_MTU;
310
		}
311
	} else if (chan->chan_type == L2CAP_CHAN_CONN_LESS) {
312
		/* Connectionless socket */
313 314
		chan->scid = L2CAP_CID_CONN_LESS;
		chan->dcid = L2CAP_CID_CONN_LESS;
315
		chan->omtu = L2CAP_DEFAULT_MTU;
316 317
	} else {
		/* Raw socket can send/recv signalling messages only */
318 319
		chan->scid = L2CAP_CID_SIGNALING;
		chan->dcid = L2CAP_CID_SIGNALING;
320
		chan->omtu = L2CAP_DEFAULT_MTU;
321 322
	}

323 324 325
	sock_hold(sk);

	list_add(&chan->list, &conn->chan_l);
326 327
}

328
/* Delete channel.
329
 * Must be called on the locked socket. */
330
static void l2cap_chan_del(struct l2cap_chan *chan, int err)
331
{
332
	struct sock *sk = chan->sk;
333
	struct l2cap_conn *conn = chan->conn;
334 335
	struct sock *parent = bt_sk(sk)->parent;

336
	l2cap_chan_clear_timer(chan);
337

338
	BT_DBG("chan %p, conn %p, err %d", chan, conn, err);
339

340
	if (conn) {
341 342 343 344 345 346
		/* Delete from channel list */
		write_lock_bh(&conn->chan_lock);
		list_del(&chan->list);
		write_unlock_bh(&conn->chan_lock);
		__sock_put(sk);

347
		chan->conn = NULL;
348 349 350
		hci_conn_put(conn->hcon);
	}

351
	sk->sk_state = BT_CLOSED;
352 353 354 355 356 357 358 359 360 361
	sock_set_flag(sk, SOCK_ZAPPED);

	if (err)
		sk->sk_err = err;

	if (parent) {
		bt_accept_unlink(sk);
		parent->sk_data_ready(parent, 0);
	} else
		sk->sk_state_change(sk);
362

363 364
	if (!(chan->conf_state & L2CAP_CONF_OUTPUT_DONE &&
			chan->conf_state & L2CAP_CONF_INPUT_DONE))
365
		return;
366

367
	skb_queue_purge(&chan->tx_q);
368

369
	if (chan->mode == L2CAP_MODE_ERTM) {
370 371
		struct srej_list *l, *tmp;

372 373 374
		del_timer(&chan->retrans_timer);
		del_timer(&chan->monitor_timer);
		del_timer(&chan->ack_timer);
375

376 377
		skb_queue_purge(&chan->srej_q);
		skb_queue_purge(&chan->busy_q);
378

379
		list_for_each_entry_safe(l, tmp, &chan->srej_l, list) {
380 381 382 383
			list_del(&l->list);
			kfree(l);
		}
	}
384 385
}

386 387 388 389 390 391 392
static void l2cap_chan_cleanup_listen(struct sock *parent)
{
	struct sock *sk;

	BT_DBG("parent %p", parent);

	/* Close not yet accepted channels */
393 394 395 396 397 398 399
	while ((sk = bt_accept_dequeue(parent, NULL))) {
		l2cap_chan_clear_timer(l2cap_pi(sk)->chan);
		lock_sock(sk);
		l2cap_chan_close(l2cap_pi(sk)->chan, ECONNRESET);
		release_sock(sk);
		l2cap_sock_kill(sk);
	}
400 401 402 403 404

	parent->sk_state = BT_CLOSED;
	sock_set_flag(parent, SOCK_ZAPPED);
}

405
void l2cap_chan_close(struct l2cap_chan *chan, int reason)
406 407 408 409 410 411 412 413 414 415 416 417 418
{
	struct l2cap_conn *conn = chan->conn;
	struct sock *sk = chan->sk;

	BT_DBG("chan %p state %d socket %p", chan, sk->sk_state, sk->sk_socket);

	switch (sk->sk_state) {
	case BT_LISTEN:
		l2cap_chan_cleanup_listen(sk);
		break;

	case BT_CONNECTED:
	case BT_CONFIG:
419
		if (chan->chan_type == L2CAP_CHAN_CONN_ORIENTED &&
420
					conn->hcon->type == ACL_LINK) {
421
			l2cap_chan_clear_timer(chan);
422
			l2cap_chan_set_timer(chan, sk->sk_sndtimeo);
423 424 425 426 427 428
			l2cap_send_disconn_req(conn, chan, reason);
		} else
			l2cap_chan_del(chan, reason);
		break;

	case BT_CONNECT2:
429
		if (chan->chan_type == L2CAP_CHAN_CONN_ORIENTED &&
430 431 432 433 434 435 436 437
					conn->hcon->type == ACL_LINK) {
			struct l2cap_conn_rsp rsp;
			__u16 result;

			if (bt_sk(sk)->defer_setup)
				result = L2CAP_CR_SEC_BLOCK;
			else
				result = L2CAP_CR_BAD_PSM;
438
			sk->sk_state = BT_DISCONN;
439 440 441 442 443 444 445 446 447 448 449 450 451 452 453 454 455 456 457 458 459 460 461

			rsp.scid   = cpu_to_le16(chan->dcid);
			rsp.dcid   = cpu_to_le16(chan->scid);
			rsp.result = cpu_to_le16(result);
			rsp.status = cpu_to_le16(L2CAP_CS_NO_INFO);
			l2cap_send_cmd(conn, chan->ident, L2CAP_CONN_RSP,
							sizeof(rsp), &rsp);
		}

		l2cap_chan_del(chan, reason);
		break;

	case BT_CONNECT:
	case BT_DISCONN:
		l2cap_chan_del(chan, reason);
		break;

	default:
		sock_set_flag(sk, SOCK_ZAPPED);
		break;
	}
}

462
static inline u8 l2cap_get_auth_type(struct l2cap_chan *chan)
463
{
464
	if (chan->chan_type == L2CAP_CHAN_RAW) {
465
		switch (chan->sec_level) {
466 467 468 469 470 471 472
		case BT_SECURITY_HIGH:
			return HCI_AT_DEDICATED_BONDING_MITM;
		case BT_SECURITY_MEDIUM:
			return HCI_AT_DEDICATED_BONDING;
		default:
			return HCI_AT_NO_BONDING;
		}
473
	} else if (chan->psm == cpu_to_le16(0x0001)) {
474 475
		if (chan->sec_level == BT_SECURITY_LOW)
			chan->sec_level = BT_SECURITY_SDP;
476

477
		if (chan->sec_level == BT_SECURITY_HIGH)
478
			return HCI_AT_NO_BONDING_MITM;
479
		else
480
			return HCI_AT_NO_BONDING;
481
	} else {
482
		switch (chan->sec_level) {
483
		case BT_SECURITY_HIGH:
484
			return HCI_AT_GENERAL_BONDING_MITM;
485
		case BT_SECURITY_MEDIUM:
486
			return HCI_AT_GENERAL_BONDING;
487
		default:
488
			return HCI_AT_NO_BONDING;
489
		}
490
	}
491 492 493
}

/* Service level security */
494
static inline int l2cap_check_security(struct l2cap_chan *chan)
495
{
496
	struct l2cap_conn *conn = chan->conn;
497 498
	__u8 auth_type;

499
	auth_type = l2cap_get_auth_type(chan);
500

501
	return hci_conn_security(conn->hcon, chan->sec_level, auth_type);
502 503
}

504
static u8 l2cap_get_ident(struct l2cap_conn *conn)
505 506 507 508 509 510 511 512 513 514 515 516 517 518 519 520 521 522 523 524 525
{
	u8 id;

	/* Get next available identificator.
	 *    1 - 128 are used by kernel.
	 *  129 - 199 are reserved.
	 *  200 - 254 are used by utilities like l2ping, etc.
	 */

	spin_lock_bh(&conn->lock);

	if (++conn->tx_ident > 128)
		conn->tx_ident = 1;

	id = conn->tx_ident;

	spin_unlock_bh(&conn->lock);

	return id;
}

526
static void l2cap_send_cmd(struct l2cap_conn *conn, u8 ident, u8 code, u16 len, void *data)
527 528
{
	struct sk_buff *skb = l2cap_build_cmd(conn, code, ident, len, data);
529
	u8 flags;
530 531 532 533

	BT_DBG("code 0x%2.2x", code);

	if (!skb)
534
		return;
535

536 537 538 539 540
	if (lmp_no_flush_capable(conn->hcon->hdev))
		flags = ACL_START_NO_FLUSH;
	else
		flags = ACL_START;

541 542
	bt_cb(skb)->force_active = BT_POWER_FORCE_ACTIVE_ON;

543
	hci_send_acl(conn->hcon, skb, flags);
544 545
}

546
static inline void l2cap_send_sframe(struct l2cap_chan *chan, u16 control)
547 548 549
{
	struct sk_buff *skb;
	struct l2cap_hdr *lh;
550
	struct l2cap_pinfo *pi = l2cap_pi(chan->sk);
551
	struct l2cap_conn *conn = chan->conn;
552
	struct sock *sk = (struct sock *)pi;
553
	int count, hlen = L2CAP_HDR_SIZE + 2;
554
	u8 flags;
555

556 557 558
	if (sk->sk_state != BT_CONNECTED)
		return;

559
	if (chan->fcs == L2CAP_FCS_CRC16)
560
		hlen += 2;
561

562
	BT_DBG("chan %p, control 0x%2.2x", chan, control);
563

564
	count = min_t(unsigned int, conn->mtu, hlen);
565 566
	control |= L2CAP_CTRL_FRAME_TYPE;

567
	if (chan->conn_state & L2CAP_CONN_SEND_FBIT) {
568
		control |= L2CAP_CTRL_FINAL;
569
		chan->conn_state &= ~L2CAP_CONN_SEND_FBIT;
570 571
	}

572
	if (chan->conn_state & L2CAP_CONN_SEND_PBIT) {
573
		control |= L2CAP_CTRL_POLL;
574
		chan->conn_state &= ~L2CAP_CONN_SEND_PBIT;
575 576
	}

577 578
	skb = bt_skb_alloc(count, GFP_ATOMIC);
	if (!skb)
579
		return;
580 581

	lh = (struct l2cap_hdr *) skb_put(skb, L2CAP_HDR_SIZE);
582
	lh->len = cpu_to_le16(hlen - L2CAP_HDR_SIZE);
583
	lh->cid = cpu_to_le16(chan->dcid);
584 585
	put_unaligned_le16(control, skb_put(skb, 2));

586
	if (chan->fcs == L2CAP_FCS_CRC16) {
587 588 589 590
		u16 fcs = crc16(0, (u8 *)lh, count - 2);
		put_unaligned_le16(fcs, skb_put(skb, 2));
	}

591 592 593 594 595
	if (lmp_no_flush_capable(conn->hcon->hdev))
		flags = ACL_START_NO_FLUSH;
	else
		flags = ACL_START;

596 597
	bt_cb(skb)->force_active = chan->force_active;

598
	hci_send_acl(chan->conn->hcon, skb, flags);
599 600
}

601
static inline void l2cap_send_rr_or_rnr(struct l2cap_chan *chan, u16 control)
602
{
603
	if (chan->conn_state & L2CAP_CONN_LOCAL_BUSY) {
604
		control |= L2CAP_SUPER_RCV_NOT_READY;
605
		chan->conn_state |= L2CAP_CONN_RNR_SENT;
606
	} else
607 608
		control |= L2CAP_SUPER_RCV_READY;

609
	control |= chan->buffer_seq << L2CAP_CTRL_REQSEQ_SHIFT;
610

611
	l2cap_send_sframe(chan, control);
612 613
}

614
static inline int __l2cap_no_conn_pending(struct l2cap_chan *chan)
615
{
616
	return !(chan->conf_state & L2CAP_CONF_CONNECT_PEND);
617 618
}

619
static void l2cap_do_start(struct l2cap_chan *chan)
620
{
621
	struct l2cap_conn *conn = chan->conn;
622 623

	if (conn->info_state & L2CAP_INFO_FEAT_MASK_REQ_SENT) {
624 625 626
		if (!(conn->info_state & L2CAP_INFO_FEAT_MASK_REQ_DONE))
			return;

627 628
		if (l2cap_check_security(chan) &&
				__l2cap_no_conn_pending(chan)) {
629
			struct l2cap_conn_req req;
630 631
			req.scid = cpu_to_le16(chan->scid);
			req.psm  = chan->psm;
632

633
			chan->ident = l2cap_get_ident(conn);
634
			chan->conf_state |= L2CAP_CONF_CONNECT_PEND;
635

636 637
			l2cap_send_cmd(conn, chan->ident, L2CAP_CONN_REQ,
							sizeof(req), &req);
638
		}
639 640 641 642 643 644 645 646 647 648 649 650 651 652 653
	} else {
		struct l2cap_info_req req;
		req.type = cpu_to_le16(L2CAP_IT_FEAT_MASK);

		conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_SENT;
		conn->info_ident = l2cap_get_ident(conn);

		mod_timer(&conn->info_timer, jiffies +
					msecs_to_jiffies(L2CAP_INFO_TIMEOUT));

		l2cap_send_cmd(conn, conn->info_ident,
					L2CAP_INFO_REQ, sizeof(req), &req);
	}
}

654 655 656
static inline int l2cap_mode_supported(__u8 mode, __u32 feat_mask)
{
	u32 local_feat_mask = l2cap_feat_mask;
657
	if (!disable_ertm)
658 659 660 661 662 663 664 665 666 667 668 669
		local_feat_mask |= L2CAP_FEAT_ERTM | L2CAP_FEAT_STREAMING;

	switch (mode) {
	case L2CAP_MODE_ERTM:
		return L2CAP_FEAT_ERTM & feat_mask & local_feat_mask;
	case L2CAP_MODE_STREAMING:
		return L2CAP_FEAT_STREAMING & feat_mask & local_feat_mask;
	default:
		return 0x00;
	}
}

670
static void l2cap_send_disconn_req(struct l2cap_conn *conn, struct l2cap_chan *chan, int err)
671
{
672
	struct sock *sk;
673 674
	struct l2cap_disconn_req req;

675 676 677
	if (!conn)
		return;

678 679
	sk = chan->sk;

680
	if (chan->mode == L2CAP_MODE_ERTM) {
681 682 683
		del_timer(&chan->retrans_timer);
		del_timer(&chan->monitor_timer);
		del_timer(&chan->ack_timer);
684 685
	}

686 687
	req.dcid = cpu_to_le16(chan->dcid);
	req.scid = cpu_to_le16(chan->scid);
688 689
	l2cap_send_cmd(conn, l2cap_get_ident(conn),
			L2CAP_DISCONN_REQ, sizeof(req), &req);
690 691

	sk->sk_state = BT_DISCONN;
692
	sk->sk_err = err;
693 694
}

L
Linus Torvalds 已提交
695
/* ---- L2CAP connections ---- */
696 697
static void l2cap_conn_start(struct l2cap_conn *conn)
{
698
	struct l2cap_chan *chan, *tmp;
699 700 701

	BT_DBG("conn %p", conn);

702
	read_lock(&conn->chan_lock);
703

704
	list_for_each_entry_safe(chan, tmp, &conn->chan_l, list) {
705
		struct sock *sk = chan->sk;
706

707 708
		bh_lock_sock(sk);

709
		if (chan->chan_type != L2CAP_CHAN_CONN_ORIENTED) {
710 711 712 713 714
			bh_unlock_sock(sk);
			continue;
		}

		if (sk->sk_state == BT_CONNECT) {
715
			struct l2cap_conn_req req;
716

717
			if (!l2cap_check_security(chan) ||
718
					!__l2cap_no_conn_pending(chan)) {
719 720 721
				bh_unlock_sock(sk);
				continue;
			}
722

723
			if (!l2cap_mode_supported(chan->mode,
724
					conn->feat_mask)
725
					&& chan->conf_state &
726
					L2CAP_CONF_STATE2_DEVICE) {
727
				/* l2cap_chan_close() calls list_del(chan)
728 729
				 * so release the lock */
				read_unlock_bh(&conn->chan_lock);
730
				 l2cap_chan_close(chan, ECONNRESET);
731
				read_lock_bh(&conn->chan_lock);
732 733
				bh_unlock_sock(sk);
				continue;
734
			}
735

736 737
			req.scid = cpu_to_le16(chan->scid);
			req.psm  = chan->psm;
738

739
			chan->ident = l2cap_get_ident(conn);
740
			chan->conf_state |= L2CAP_CONF_CONNECT_PEND;
741

742 743
			l2cap_send_cmd(conn, chan->ident, L2CAP_CONN_REQ,
							sizeof(req), &req);
744

745 746
		} else if (sk->sk_state == BT_CONNECT2) {
			struct l2cap_conn_rsp rsp;
747
			char buf[128];
748 749
			rsp.scid = cpu_to_le16(chan->dcid);
			rsp.dcid = cpu_to_le16(chan->scid);
750

751
			if (l2cap_check_security(chan)) {
752 753 754 755 756 757 758 759 760 761 762
				if (bt_sk(sk)->defer_setup) {
					struct sock *parent = bt_sk(sk)->parent;
					rsp.result = cpu_to_le16(L2CAP_CR_PEND);
					rsp.status = cpu_to_le16(L2CAP_CS_AUTHOR_PEND);
					parent->sk_data_ready(parent, 0);

				} else {
					sk->sk_state = BT_CONFIG;
					rsp.result = cpu_to_le16(L2CAP_CR_SUCCESS);
					rsp.status = cpu_to_le16(L2CAP_CS_NO_INFO);
				}
763 764 765 766 767
			} else {
				rsp.result = cpu_to_le16(L2CAP_CR_PEND);
				rsp.status = cpu_to_le16(L2CAP_CS_AUTHEN_PEND);
			}

768 769
			l2cap_send_cmd(conn, chan->ident, L2CAP_CONN_RSP,
							sizeof(rsp), &rsp);
770

771
			if (chan->conf_state & L2CAP_CONF_REQ_SENT ||
772 773 774 775 776
					rsp.result != L2CAP_CR_SUCCESS) {
				bh_unlock_sock(sk);
				continue;
			}

777
			chan->conf_state |= L2CAP_CONF_REQ_SENT;
778
			l2cap_send_cmd(conn, l2cap_get_ident(conn), L2CAP_CONF_REQ,
779 780
						l2cap_build_conf_req(chan, buf), buf);
			chan->num_conf_req++;
781 782 783 784 785
		}

		bh_unlock_sock(sk);
	}

786
	read_unlock(&conn->chan_lock);
787 788
}

789 790 791
/* Find socket with cid and source bdaddr.
 * Returns closest match, locked.
 */
792
static struct l2cap_chan *l2cap_global_chan_by_scid(int state, __le16 cid, bdaddr_t *src)
793
{
794
	struct l2cap_chan *c, *c1 = NULL;
795

796
	read_lock(&chan_list_lock);
797

798 799
	list_for_each_entry(c, &chan_list, global_l) {
		struct sock *sk = c->sk;
800

801 802 803
		if (state && sk->sk_state != state)
			continue;

804
		if (c->scid == cid) {
805
			/* Exact match. */
806 807 808 809
			if (!bacmp(&bt_sk(sk)->src, src)) {
				read_unlock(&chan_list_lock);
				return c;
			}
810 811 812

			/* Closest match */
			if (!bacmp(&bt_sk(sk)->src, BDADDR_ANY))
813
				c1 = c;
814 815
		}
	}
816

817
	read_unlock(&chan_list_lock);
818

819
	return c1;
820 821 822 823
}

static void l2cap_le_conn_ready(struct l2cap_conn *conn)
{
824
	struct sock *parent, *sk;
825
	struct l2cap_chan *chan, *pchan;
826 827 828 829

	BT_DBG("");

	/* Check if we have socket listening on cid */
830
	pchan = l2cap_global_chan_by_scid(BT_LISTEN, L2CAP_CID_LE_DATA,
831
							conn->src);
832
	if (!pchan)
833 834
		return;

835 836
	parent = pchan->sk;

837 838
	bh_lock_sock(parent);

839 840 841 842 843 844 845 846 847 848
	/* Check for backlog size */
	if (sk_acceptq_is_full(parent)) {
		BT_DBG("backlog full %d", parent->sk_ack_backlog);
		goto clean;
	}

	sk = l2cap_sock_alloc(sock_net(parent), NULL, BTPROTO_L2CAP, GFP_ATOMIC);
	if (!sk)
		goto clean;

849
	chan = l2cap_chan_create(sk);
850 851 852 853 854
	if (!chan) {
		l2cap_sock_kill(sk);
		goto clean;
	}

855 856
	l2cap_pi(sk)->chan = chan;

857
	write_lock_bh(&conn->chan_lock);
858 859 860 861

	hci_conn_hold(conn->hcon);

	l2cap_sock_init(sk, parent);
862

863 864 865
	bacpy(&bt_sk(sk)->src, conn->src);
	bacpy(&bt_sk(sk)->dst, conn->dst);

866 867
	bt_accept_enqueue(parent, sk);

868 869
	__l2cap_chan_add(conn, chan);

870
	l2cap_chan_set_timer(chan, sk->sk_sndtimeo);
871 872 873 874

	sk->sk_state = BT_CONNECTED;
	parent->sk_data_ready(parent, 0);

875
	write_unlock_bh(&conn->chan_lock);
876 877 878 879 880

clean:
	bh_unlock_sock(parent);
}

881 882
static void l2cap_conn_ready(struct l2cap_conn *conn)
{
883
	struct l2cap_chan *chan;
884

885
	BT_DBG("conn %p", conn);
886

887 888 889
	if (!conn->hcon->out && conn->hcon->type == LE_LINK)
		l2cap_le_conn_ready(conn);

890
	read_lock(&conn->chan_lock);
891

892
	list_for_each_entry(chan, &conn->chan_l, list) {
893
		struct sock *sk = chan->sk;
894

895
		bh_lock_sock(sk);
896

897
		if (conn->hcon->type == LE_LINK) {
898
			l2cap_chan_clear_timer(chan);
899 900 901 902
			sk->sk_state = BT_CONNECTED;
			sk->sk_state_change(sk);
		}

903
		if (chan->chan_type != L2CAP_CHAN_CONN_ORIENTED) {
904
			l2cap_chan_clear_timer(chan);
905 906 907
			sk->sk_state = BT_CONNECTED;
			sk->sk_state_change(sk);
		} else if (sk->sk_state == BT_CONNECT)
908
			l2cap_do_start(chan);
909

910
		bh_unlock_sock(sk);
911
	}
912

913
	read_unlock(&conn->chan_lock);
914 915 916 917 918
}

/* Notify sockets that we cannot guaranty reliability anymore */
static void l2cap_conn_unreliable(struct l2cap_conn *conn, int err)
{
919
	struct l2cap_chan *chan;
920 921 922

	BT_DBG("conn %p", conn);

923
	read_lock(&conn->chan_lock);
924

925
	list_for_each_entry(chan, &conn->chan_l, list) {
926
		struct sock *sk = chan->sk;
927

928
		if (chan->force_reliable)
929 930 931
			sk->sk_err = err;
	}

932
	read_unlock(&conn->chan_lock);
933 934 935 936 937 938
}

static void l2cap_info_timeout(unsigned long arg)
{
	struct l2cap_conn *conn = (void *) arg;

939
	conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_DONE;
940
	conn->info_ident = 0;
941

942 943 944
	l2cap_conn_start(conn);
}

L
Linus Torvalds 已提交
945 946
static struct l2cap_conn *l2cap_conn_add(struct hci_conn *hcon, u8 status)
{
947
	struct l2cap_conn *conn = hcon->l2cap_data;
L
Linus Torvalds 已提交
948

949
	if (conn || status)
L
Linus Torvalds 已提交
950 951
		return conn;

952 953
	conn = kzalloc(sizeof(struct l2cap_conn), GFP_ATOMIC);
	if (!conn)
L
Linus Torvalds 已提交
954 955 956 957 958
		return NULL;

	hcon->l2cap_data = conn;
	conn->hcon = hcon;

959 960
	BT_DBG("hcon %p conn %p", hcon, conn);

961 962 963 964 965
	if (hcon->hdev->le_mtu && hcon->type == LE_LINK)
		conn->mtu = hcon->hdev->le_mtu;
	else
		conn->mtu = hcon->hdev->acl_mtu;

L
Linus Torvalds 已提交
966 967 968
	conn->src = &hcon->hdev->bdaddr;
	conn->dst = &hcon->dst;

969 970
	conn->feat_mask = 0;

L
Linus Torvalds 已提交
971
	spin_lock_init(&conn->lock);
972 973 974
	rwlock_init(&conn->chan_lock);

	INIT_LIST_HEAD(&conn->chan_l);
L
Linus Torvalds 已提交
975

976 977
	if (hcon->type != LE_LINK)
		setup_timer(&conn->info_timer, l2cap_info_timeout,
D
Dave Young 已提交
978 979
						(unsigned long) conn);

980 981
	conn->disc_reason = 0x13;

L
Linus Torvalds 已提交
982 983 984
	return conn;
}

985
static void l2cap_conn_del(struct hci_conn *hcon, int err)
L
Linus Torvalds 已提交
986
{
987
	struct l2cap_conn *conn = hcon->l2cap_data;
988
	struct l2cap_chan *chan, *l;
L
Linus Torvalds 已提交
989 990
	struct sock *sk;

991 992
	if (!conn)
		return;
L
Linus Torvalds 已提交
993 994 995

	BT_DBG("hcon %p conn %p, err %d", hcon, conn, err);

996
	kfree_skb(conn->rx_skb);
L
Linus Torvalds 已提交
997 998

	/* Kill channels */
999
	list_for_each_entry_safe(chan, l, &conn->chan_l, list) {
1000
		sk = chan->sk;
L
Linus Torvalds 已提交
1001
		bh_lock_sock(sk);
1002
		l2cap_chan_del(chan, err);
L
Linus Torvalds 已提交
1003 1004 1005 1006
		bh_unlock_sock(sk);
		l2cap_sock_kill(sk);
	}

1007 1008
	if (conn->info_state & L2CAP_INFO_FEAT_MASK_REQ_SENT)
		del_timer_sync(&conn->info_timer);
1009

L
Linus Torvalds 已提交
1010 1011 1012 1013
	hcon->l2cap_data = NULL;
	kfree(conn);
}

1014
static inline void l2cap_chan_add(struct l2cap_conn *conn, struct l2cap_chan *chan)
L
Linus Torvalds 已提交
1015
{
1016
	write_lock_bh(&conn->chan_lock);
1017
	__l2cap_chan_add(conn, chan);
1018
	write_unlock_bh(&conn->chan_lock);
L
Linus Torvalds 已提交
1019 1020 1021 1022 1023 1024 1025
}

/* ---- Socket interface ---- */

/* Find socket with psm and source bdaddr.
 * Returns closest match.
 */
1026
static struct l2cap_chan *l2cap_global_chan_by_psm(int state, __le16 psm, bdaddr_t *src)
L
Linus Torvalds 已提交
1027
{
1028
	struct l2cap_chan *c, *c1 = NULL;
L
Linus Torvalds 已提交
1029

1030
	read_lock(&chan_list_lock);
1031

1032 1033
	list_for_each_entry(c, &chan_list, global_l) {
		struct sock *sk = c->sk;
1034

L
Linus Torvalds 已提交
1035 1036 1037
		if (state && sk->sk_state != state)
			continue;

1038
		if (c->psm == psm) {
L
Linus Torvalds 已提交
1039
			/* Exact match. */
1040
			if (!bacmp(&bt_sk(sk)->src, src)) {
1041
				read_unlock(&chan_list_lock);
1042 1043
				return c;
			}
L
Linus Torvalds 已提交
1044 1045 1046

			/* Closest match */
			if (!bacmp(&bt_sk(sk)->src, BDADDR_ANY))
1047
				c1 = c;
L
Linus Torvalds 已提交
1048 1049 1050
		}
	}

1051
	read_unlock(&chan_list_lock);
1052

1053
	return c1;
L
Linus Torvalds 已提交
1054 1055
}

1056
int l2cap_chan_connect(struct l2cap_chan *chan)
L
Linus Torvalds 已提交
1057
{
1058
	struct sock *sk = chan->sk;
L
Linus Torvalds 已提交
1059 1060 1061 1062 1063
	bdaddr_t *src = &bt_sk(sk)->src;
	bdaddr_t *dst = &bt_sk(sk)->dst;
	struct l2cap_conn *conn;
	struct hci_conn *hcon;
	struct hci_dev *hdev;
1064
	__u8 auth_type;
1065
	int err;
L
Linus Torvalds 已提交
1066

1067
	BT_DBG("%s -> %s psm 0x%2.2x", batostr(src), batostr(dst),
1068
							chan->psm);
L
Linus Torvalds 已提交
1069

1070 1071
	hdev = hci_get_route(dst, src);
	if (!hdev)
L
Linus Torvalds 已提交
1072 1073 1074 1075
		return -EHOSTUNREACH;

	hci_dev_lock_bh(hdev);

1076
	auth_type = l2cap_get_auth_type(chan);
1077

1078
	if (chan->dcid == L2CAP_CID_LE_DATA)
1079
		hcon = hci_connect(hdev, LE_LINK, dst,
1080
					chan->sec_level, auth_type);
1081 1082
	else
		hcon = hci_connect(hdev, ACL_LINK, dst,
1083
					chan->sec_level, auth_type);
1084

1085 1086
	if (IS_ERR(hcon)) {
		err = PTR_ERR(hcon);
L
Linus Torvalds 已提交
1087
		goto done;
1088
	}
L
Linus Torvalds 已提交
1089 1090 1091 1092

	conn = l2cap_conn_add(hcon, 0);
	if (!conn) {
		hci_conn_put(hcon);
1093
		err = -ENOMEM;
L
Linus Torvalds 已提交
1094 1095 1096 1097 1098 1099
		goto done;
	}

	/* Update source addr of the socket */
	bacpy(src, conn->src);

1100 1101
	l2cap_chan_add(conn, chan);

L
Linus Torvalds 已提交
1102
	sk->sk_state = BT_CONNECT;
1103
	l2cap_chan_set_timer(chan, sk->sk_sndtimeo);
L
Linus Torvalds 已提交
1104 1105

	if (hcon->state == BT_CONNECTED) {
1106
		if (chan->chan_type != L2CAP_CHAN_CONN_ORIENTED) {
1107
			l2cap_chan_clear_timer(chan);
1108
			if (l2cap_check_security(chan))
1109
				sk->sk_state = BT_CONNECTED;
1110
		} else
1111
			l2cap_do_start(chan);
L
Linus Torvalds 已提交
1112 1113
	}

1114 1115
	err = 0;

L
Linus Torvalds 已提交
1116 1117 1118 1119 1120 1121
done:
	hci_dev_unlock_bh(hdev);
	hci_dev_put(hdev);
	return err;
}

1122
int __l2cap_wait_ack(struct sock *sk)
1123
{
1124
	struct l2cap_chan *chan = l2cap_pi(sk)->chan;
1125 1126 1127 1128
	DECLARE_WAITQUEUE(wait, current);
	int err = 0;
	int timeo = HZ/5;

1129
	add_wait_queue(sk_sleep(sk), &wait);
1130
	while ((chan->unacked_frames > 0 && chan->conn)) {
1131 1132 1133 1134 1135 1136 1137 1138 1139 1140 1141 1142 1143 1144 1145 1146 1147 1148 1149
		set_current_state(TASK_INTERRUPTIBLE);

		if (!timeo)
			timeo = HZ/5;

		if (signal_pending(current)) {
			err = sock_intr_errno(timeo);
			break;
		}

		release_sock(sk);
		timeo = schedule_timeout(timeo);
		lock_sock(sk);

		err = sock_error(sk);
		if (err)
			break;
	}
	set_current_state(TASK_RUNNING);
1150
	remove_wait_queue(sk_sleep(sk), &wait);
1151 1152 1153
	return err;
}

1154 1155
static void l2cap_monitor_timeout(unsigned long arg)
{
1156 1157
	struct l2cap_chan *chan = (void *) arg;
	struct sock *sk = chan->sk;
1158

1159
	BT_DBG("chan %p", chan);
1160

1161
	bh_lock_sock(sk);
1162
	if (chan->retry_count >= chan->remote_max_tx) {
1163
		l2cap_send_disconn_req(chan->conn, chan, ECONNABORTED);
1164
		bh_unlock_sock(sk);
1165 1166 1167
		return;
	}

1168
	chan->retry_count++;
1169 1170
	__mod_monitor_timer();

1171
	l2cap_send_rr_or_rnr(chan, L2CAP_CTRL_POLL);
1172
	bh_unlock_sock(sk);
1173 1174 1175 1176
}

static void l2cap_retrans_timeout(unsigned long arg)
{
1177 1178
	struct l2cap_chan *chan = (void *) arg;
	struct sock *sk = chan->sk;
1179

1180
	BT_DBG("chan %p", chan);
1181

1182
	bh_lock_sock(sk);
1183
	chan->retry_count = 1;
1184 1185
	__mod_monitor_timer();

1186
	chan->conn_state |= L2CAP_CONN_WAIT_F;
1187

1188
	l2cap_send_rr_or_rnr(chan, L2CAP_CTRL_POLL);
1189
	bh_unlock_sock(sk);
1190 1191
}

1192
static void l2cap_drop_acked_frames(struct l2cap_chan *chan)
L
Linus Torvalds 已提交
1193
{
1194
	struct sk_buff *skb;
L
Linus Torvalds 已提交
1195

1196
	while ((skb = skb_peek(&chan->tx_q)) &&
1197
			chan->unacked_frames) {
1198
		if (bt_cb(skb)->tx_seq == chan->expected_ack_seq)
1199
			break;
L
Linus Torvalds 已提交
1200

1201
		skb = skb_dequeue(&chan->tx_q);
1202
		kfree_skb(skb);
L
Linus Torvalds 已提交
1203

1204
		chan->unacked_frames--;
1205
	}
L
Linus Torvalds 已提交
1206

1207
	if (!chan->unacked_frames)
1208
		del_timer(&chan->retrans_timer);
1209
}
L
Linus Torvalds 已提交
1210

1211
void l2cap_do_send(struct l2cap_chan *chan, struct sk_buff *skb)
1212
{
1213
	struct hci_conn *hcon = chan->conn->hcon;
1214
	u16 flags;
1215

1216
	BT_DBG("chan %p, skb %p len %d", chan, skb, skb->len);
L
Linus Torvalds 已提交
1217

1218
	if (!chan->flushable && lmp_no_flush_capable(hcon->hdev))
1219 1220 1221 1222
		flags = ACL_START_NO_FLUSH;
	else
		flags = ACL_START;

1223
	bt_cb(skb)->force_active = chan->force_active;
1224
	hci_send_acl(hcon, skb, flags);
1225 1226
}

1227
void l2cap_streaming_send(struct l2cap_chan *chan)
1228
{
1229
	struct sk_buff *skb;
1230
	u16 control, fcs;
1231

1232
	while ((skb = skb_dequeue(&chan->tx_q))) {
1233
		control = get_unaligned_le16(skb->data + L2CAP_HDR_SIZE);
1234
		control |= chan->next_tx_seq << L2CAP_CTRL_TXSEQ_SHIFT;
1235
		put_unaligned_le16(control, skb->data + L2CAP_HDR_SIZE);
1236

1237
		if (chan->fcs == L2CAP_FCS_CRC16) {
1238 1239
			fcs = crc16(0, (u8 *)skb->data, skb->len - 2);
			put_unaligned_le16(fcs, skb->data + skb->len - 2);
1240 1241
		}

1242
		l2cap_do_send(chan, skb);
1243

1244
		chan->next_tx_seq = (chan->next_tx_seq + 1) % 64;
1245 1246 1247
	}
}

1248
static void l2cap_retransmit_one_frame(struct l2cap_chan *chan, u8 tx_seq)
1249 1250 1251 1252
{
	struct sk_buff *skb, *tx_skb;
	u16 control, fcs;

1253
	skb = skb_peek(&chan->tx_q);
1254 1255
	if (!skb)
		return;
1256

1257 1258
	do {
		if (bt_cb(skb)->tx_seq == tx_seq)
1259 1260
			break;

1261
		if (skb_queue_is_last(&chan->tx_q, skb))
1262
			return;
1263

1264
	} while ((skb = skb_queue_next(&chan->tx_q, skb)));
1265

1266 1267
	if (chan->remote_max_tx &&
			bt_cb(skb)->retries == chan->remote_max_tx) {
1268
		l2cap_send_disconn_req(chan->conn, chan, ECONNABORTED);
1269 1270 1271 1272 1273 1274
		return;
	}

	tx_skb = skb_clone(skb, GFP_ATOMIC);
	bt_cb(skb)->retries++;
	control = get_unaligned_le16(tx_skb->data + L2CAP_HDR_SIZE);
1275
	control &= L2CAP_CTRL_SAR;
1276

1277
	if (chan->conn_state & L2CAP_CONN_SEND_FBIT) {
1278
		control |= L2CAP_CTRL_FINAL;
1279
		chan->conn_state &= ~L2CAP_CONN_SEND_FBIT;
1280
	}
1281

1282
	control |= (chan->buffer_seq << L2CAP_CTRL_REQSEQ_SHIFT)
1283
			| (tx_seq << L2CAP_CTRL_TXSEQ_SHIFT);
1284

1285 1286
	put_unaligned_le16(control, tx_skb->data + L2CAP_HDR_SIZE);

1287
	if (chan->fcs == L2CAP_FCS_CRC16) {
1288 1289 1290 1291
		fcs = crc16(0, (u8 *)tx_skb->data, tx_skb->len - 2);
		put_unaligned_le16(fcs, tx_skb->data + tx_skb->len - 2);
	}

1292
	l2cap_do_send(chan, tx_skb);
1293 1294
}

1295
int l2cap_ertm_send(struct l2cap_chan *chan)
1296 1297
{
	struct sk_buff *skb, *tx_skb;
1298
	struct sock *sk = chan->sk;
1299
	u16 control, fcs;
1300
	int nsent = 0;
1301

1302 1303
	if (sk->sk_state != BT_CONNECTED)
		return -ENOTCONN;
1304

1305
	while ((skb = chan->tx_send_head) && (!l2cap_tx_window_full(chan))) {
1306

1307 1308
		if (chan->remote_max_tx &&
				bt_cb(skb)->retries == chan->remote_max_tx) {
1309
			l2cap_send_disconn_req(chan->conn, chan, ECONNABORTED);
1310 1311 1312
			break;
		}

1313 1314
		tx_skb = skb_clone(skb, GFP_ATOMIC);

1315 1316
		bt_cb(skb)->retries++;

1317
		control = get_unaligned_le16(tx_skb->data + L2CAP_HDR_SIZE);
1318 1319
		control &= L2CAP_CTRL_SAR;

1320
		if (chan->conn_state & L2CAP_CONN_SEND_FBIT) {
1321
			control |= L2CAP_CTRL_FINAL;
1322
			chan->conn_state &= ~L2CAP_CONN_SEND_FBIT;
1323
		}
1324 1325
		control |= (chan->buffer_seq << L2CAP_CTRL_REQSEQ_SHIFT)
				| (chan->next_tx_seq << L2CAP_CTRL_TXSEQ_SHIFT);
1326 1327
		put_unaligned_le16(control, tx_skb->data + L2CAP_HDR_SIZE);

1328

1329
		if (chan->fcs == L2CAP_FCS_CRC16) {
1330 1331 1332 1333
			fcs = crc16(0, (u8 *)skb->data, tx_skb->len - 2);
			put_unaligned_le16(fcs, skb->data + tx_skb->len - 2);
		}

1334
		l2cap_do_send(chan, tx_skb);
1335

1336
		__mod_retrans_timer();
1337

1338 1339
		bt_cb(skb)->tx_seq = chan->next_tx_seq;
		chan->next_tx_seq = (chan->next_tx_seq + 1) % 64;
1340

1341
		if (bt_cb(skb)->retries == 1)
1342
			chan->unacked_frames++;
1343

1344
		chan->frames_sent++;
1345

1346 1347
		if (skb_queue_is_last(&chan->tx_q, skb))
			chan->tx_send_head = NULL;
1348
		else
1349
			chan->tx_send_head = skb_queue_next(&chan->tx_q, skb);
1350 1351

		nsent++;
1352 1353
	}

1354 1355 1356
	return nsent;
}

1357
static int l2cap_retransmit_frames(struct l2cap_chan *chan)
1358 1359 1360
{
	int ret;

1361 1362
	if (!skb_queue_empty(&chan->tx_q))
		chan->tx_send_head = chan->tx_q.next;
1363

1364
	chan->next_tx_seq = chan->expected_ack_seq;
1365
	ret = l2cap_ertm_send(chan);
1366 1367 1368
	return ret;
}

1369
static void l2cap_send_ack(struct l2cap_chan *chan)
1370 1371 1372
{
	u16 control = 0;

1373
	control |= chan->buffer_seq << L2CAP_CTRL_REQSEQ_SHIFT;
1374

1375
	if (chan->conn_state & L2CAP_CONN_LOCAL_BUSY) {
1376
		control |= L2CAP_SUPER_RCV_NOT_READY;
1377 1378
		chan->conn_state |= L2CAP_CONN_RNR_SENT;
		l2cap_send_sframe(chan, control);
1379
		return;
1380
	}
1381

1382
	if (l2cap_ertm_send(chan) > 0)
1383 1384 1385
		return;

	control |= L2CAP_SUPER_RCV_READY;
1386
	l2cap_send_sframe(chan, control);
1387 1388
}

1389
static void l2cap_send_srejtail(struct l2cap_chan *chan)
1390 1391 1392 1393 1394 1395 1396
{
	struct srej_list *tail;
	u16 control;

	control = L2CAP_SUPER_SELECT_REJECT;
	control |= L2CAP_CTRL_FINAL;

1397
	tail = list_entry((&chan->srej_l)->prev, struct srej_list, list);
1398 1399
	control |= tail->tx_seq << L2CAP_CTRL_REQSEQ_SHIFT;

1400
	l2cap_send_sframe(chan, control);
1401 1402
}

1403 1404
static inline int l2cap_skbuff_fromiovec(struct sock *sk, struct msghdr *msg, int len, int count, struct sk_buff *skb)
{
1405
	struct l2cap_conn *conn = l2cap_pi(sk)->chan->conn;
1406 1407
	struct sk_buff **frag;
	int err, sent = 0;
L
Linus Torvalds 已提交
1408

1409
	if (memcpy_fromiovec(skb_put(skb, count), msg->msg_iov, count))
1410
		return -EFAULT;
L
Linus Torvalds 已提交
1411 1412 1413 1414 1415 1416 1417 1418 1419 1420 1421

	sent += count;
	len  -= count;

	/* Continuation fragments (no L2CAP header) */
	frag = &skb_shinfo(skb)->frag_list;
	while (len) {
		count = min_t(unsigned int, conn->mtu, len);

		*frag = bt_skb_send_alloc(sk, count, msg->msg_flags & MSG_DONTWAIT, &err);
		if (!*frag)
1422
			return err;
1423 1424
		if (memcpy_fromiovec(skb_put(*frag, count), msg->msg_iov, count))
			return -EFAULT;
L
Linus Torvalds 已提交
1425 1426 1427 1428 1429 1430 1431 1432

		sent += count;
		len  -= count;

		frag = &(*frag)->next;
	}

	return sent;
1433
}
L
Linus Torvalds 已提交
1434

1435
struct sk_buff *l2cap_create_connless_pdu(struct l2cap_chan *chan, struct msghdr *msg, size_t len)
1436
{
1437
	struct sock *sk = chan->sk;
1438
	struct l2cap_conn *conn = chan->conn;
1439 1440 1441 1442 1443 1444 1445 1446 1447 1448
	struct sk_buff *skb;
	int err, count, hlen = L2CAP_HDR_SIZE + 2;
	struct l2cap_hdr *lh;

	BT_DBG("sk %p len %d", sk, (int)len);

	count = min_t(unsigned int, (conn->mtu - hlen), len);
	skb = bt_skb_send_alloc(sk, count + hlen,
			msg->msg_flags & MSG_DONTWAIT, &err);
	if (!skb)
1449
		return ERR_PTR(err);
1450 1451 1452

	/* Create L2CAP header */
	lh = (struct l2cap_hdr *) skb_put(skb, L2CAP_HDR_SIZE);
1453
	lh->cid = cpu_to_le16(chan->dcid);
1454
	lh->len = cpu_to_le16(len + (hlen - L2CAP_HDR_SIZE));
1455
	put_unaligned_le16(chan->psm, skb_put(skb, 2));
1456 1457 1458 1459 1460 1461 1462 1463 1464

	err = l2cap_skbuff_fromiovec(sk, msg, len, count, skb);
	if (unlikely(err < 0)) {
		kfree_skb(skb);
		return ERR_PTR(err);
	}
	return skb;
}

1465
struct sk_buff *l2cap_create_basic_pdu(struct l2cap_chan *chan, struct msghdr *msg, size_t len)
1466
{
1467
	struct sock *sk = chan->sk;
1468
	struct l2cap_conn *conn = chan->conn;
1469 1470 1471 1472 1473 1474 1475 1476 1477 1478
	struct sk_buff *skb;
	int err, count, hlen = L2CAP_HDR_SIZE;
	struct l2cap_hdr *lh;

	BT_DBG("sk %p len %d", sk, (int)len);

	count = min_t(unsigned int, (conn->mtu - hlen), len);
	skb = bt_skb_send_alloc(sk, count + hlen,
			msg->msg_flags & MSG_DONTWAIT, &err);
	if (!skb)
1479
		return ERR_PTR(err);
1480 1481 1482

	/* Create L2CAP header */
	lh = (struct l2cap_hdr *) skb_put(skb, L2CAP_HDR_SIZE);
1483
	lh->cid = cpu_to_le16(chan->dcid);
1484 1485 1486 1487 1488 1489 1490 1491 1492 1493
	lh->len = cpu_to_le16(len + (hlen - L2CAP_HDR_SIZE));

	err = l2cap_skbuff_fromiovec(sk, msg, len, count, skb);
	if (unlikely(err < 0)) {
		kfree_skb(skb);
		return ERR_PTR(err);
	}
	return skb;
}

1494
struct sk_buff *l2cap_create_iframe_pdu(struct l2cap_chan *chan, struct msghdr *msg, size_t len, u16 control, u16 sdulen)
1495
{
1496
	struct sock *sk = chan->sk;
1497
	struct l2cap_conn *conn = chan->conn;
1498 1499 1500 1501 1502 1503
	struct sk_buff *skb;
	int err, count, hlen = L2CAP_HDR_SIZE + 2;
	struct l2cap_hdr *lh;

	BT_DBG("sk %p len %d", sk, (int)len);

1504 1505 1506
	if (!conn)
		return ERR_PTR(-ENOTCONN);

1507 1508 1509
	if (sdulen)
		hlen += 2;

1510
	if (chan->fcs == L2CAP_FCS_CRC16)
1511 1512
		hlen += 2;

1513 1514 1515 1516
	count = min_t(unsigned int, (conn->mtu - hlen), len);
	skb = bt_skb_send_alloc(sk, count + hlen,
			msg->msg_flags & MSG_DONTWAIT, &err);
	if (!skb)
1517
		return ERR_PTR(err);
1518 1519 1520

	/* Create L2CAP header */
	lh = (struct l2cap_hdr *) skb_put(skb, L2CAP_HDR_SIZE);
1521
	lh->cid = cpu_to_le16(chan->dcid);
1522 1523
	lh->len = cpu_to_le16(len + (hlen - L2CAP_HDR_SIZE));
	put_unaligned_le16(control, skb_put(skb, 2));
1524 1525
	if (sdulen)
		put_unaligned_le16(sdulen, skb_put(skb, 2));
1526 1527 1528 1529 1530 1531

	err = l2cap_skbuff_fromiovec(sk, msg, len, count, skb);
	if (unlikely(err < 0)) {
		kfree_skb(skb);
		return ERR_PTR(err);
	}
1532

1533
	if (chan->fcs == L2CAP_FCS_CRC16)
1534 1535
		put_unaligned_le16(0, skb_put(skb, 2));

1536
	bt_cb(skb)->retries = 0;
1537
	return skb;
L
Linus Torvalds 已提交
1538 1539
}

1540
int l2cap_sar_segment_sdu(struct l2cap_chan *chan, struct msghdr *msg, size_t len)
1541 1542 1543 1544 1545 1546
{
	struct sk_buff *skb;
	struct sk_buff_head sar_queue;
	u16 control;
	size_t size = 0;

1547
	skb_queue_head_init(&sar_queue);
1548
	control = L2CAP_SDU_START;
1549
	skb = l2cap_create_iframe_pdu(chan, msg, chan->remote_mps, control, len);
1550 1551 1552 1553
	if (IS_ERR(skb))
		return PTR_ERR(skb);

	__skb_queue_tail(&sar_queue, skb);
1554 1555
	len -= chan->remote_mps;
	size += chan->remote_mps;
1556 1557 1558 1559

	while (len > 0) {
		size_t buflen;

1560
		if (len > chan->remote_mps) {
1561
			control = L2CAP_SDU_CONTINUE;
1562
			buflen = chan->remote_mps;
1563
		} else {
1564
			control = L2CAP_SDU_END;
1565 1566 1567
			buflen = len;
		}

1568
		skb = l2cap_create_iframe_pdu(chan, msg, buflen, control, 0);
1569 1570 1571 1572 1573 1574 1575 1576 1577
		if (IS_ERR(skb)) {
			skb_queue_purge(&sar_queue);
			return PTR_ERR(skb);
		}

		__skb_queue_tail(&sar_queue, skb);
		len -= buflen;
		size += buflen;
	}
1578 1579 1580
	skb_queue_splice_tail(&sar_queue, &chan->tx_q);
	if (chan->tx_send_head == NULL)
		chan->tx_send_head = sar_queue.next;
1581 1582 1583 1584

	return size;
}

1585 1586 1587 1588 1589 1590 1591
int l2cap_chan_send(struct l2cap_chan *chan, struct msghdr *msg, size_t len)
{
	struct sk_buff *skb;
	u16 control;
	int err;

	/* Connectionless channel */
1592
	if (chan->chan_type == L2CAP_CHAN_CONN_LESS) {
1593 1594 1595 1596 1597 1598 1599 1600 1601 1602 1603 1604 1605 1606 1607 1608 1609 1610 1611 1612 1613 1614 1615 1616 1617 1618 1619 1620 1621 1622 1623 1624 1625 1626 1627 1628 1629 1630 1631 1632 1633 1634 1635 1636 1637 1638 1639 1640 1641 1642 1643 1644 1645 1646 1647 1648 1649 1650 1651 1652 1653 1654 1655 1656 1657 1658 1659 1660 1661 1662 1663
		skb = l2cap_create_connless_pdu(chan, msg, len);
		if (IS_ERR(skb))
			return PTR_ERR(skb);

		l2cap_do_send(chan, skb);
		return len;
	}

	switch (chan->mode) {
	case L2CAP_MODE_BASIC:
		/* Check outgoing MTU */
		if (len > chan->omtu)
			return -EMSGSIZE;

		/* Create a basic PDU */
		skb = l2cap_create_basic_pdu(chan, msg, len);
		if (IS_ERR(skb))
			return PTR_ERR(skb);

		l2cap_do_send(chan, skb);
		err = len;
		break;

	case L2CAP_MODE_ERTM:
	case L2CAP_MODE_STREAMING:
		/* Entire SDU fits into one PDU */
		if (len <= chan->remote_mps) {
			control = L2CAP_SDU_UNSEGMENTED;
			skb = l2cap_create_iframe_pdu(chan, msg, len, control,
									0);
			if (IS_ERR(skb))
				return PTR_ERR(skb);

			__skb_queue_tail(&chan->tx_q, skb);

			if (chan->tx_send_head == NULL)
				chan->tx_send_head = skb;

		} else {
			/* Segment SDU into multiples PDUs */
			err = l2cap_sar_segment_sdu(chan, msg, len);
			if (err < 0)
				return err;
		}

		if (chan->mode == L2CAP_MODE_STREAMING) {
			l2cap_streaming_send(chan);
			err = len;
			break;
		}

		if ((chan->conn_state & L2CAP_CONN_REMOTE_BUSY) &&
				(chan->conn_state & L2CAP_CONN_WAIT_F)) {
			err = len;
			break;
		}

		err = l2cap_ertm_send(chan);
		if (err >= 0)
			err = len;

		break;

	default:
		BT_DBG("bad state %1.1x", chan->mode);
		err = -EBADFD;
	}

	return err;
}

L
Linus Torvalds 已提交
1664 1665 1666
static void l2cap_chan_ready(struct sock *sk)
{
	struct sock *parent = bt_sk(sk)->parent;
1667
	struct l2cap_chan *chan = l2cap_pi(sk)->chan;
L
Linus Torvalds 已提交
1668 1669 1670

	BT_DBG("sk %p, parent %p", sk, parent);

1671
	chan->conf_state = 0;
1672
	l2cap_chan_clear_timer(chan);
L
Linus Torvalds 已提交
1673 1674 1675 1676 1677 1678 1679 1680 1681 1682 1683 1684 1685 1686 1687 1688 1689 1690 1691

	if (!parent) {
		/* Outgoing channel.
		 * Wake up socket sleeping on connect.
		 */
		sk->sk_state = BT_CONNECTED;
		sk->sk_state_change(sk);
	} else {
		/* Incoming channel.
		 * Wake up socket sleeping on accept.
		 */
		parent->sk_data_ready(parent, 0);
	}
}

/* Copy frame to all raw sockets on that connection */
static void l2cap_raw_recv(struct l2cap_conn *conn, struct sk_buff *skb)
{
	struct sk_buff *nskb;
1692
	struct l2cap_chan *chan;
L
Linus Torvalds 已提交
1693 1694 1695

	BT_DBG("conn %p", conn);

1696 1697
	read_lock(&conn->chan_lock);
	list_for_each_entry(chan, &conn->chan_l, list) {
1698
		struct sock *sk = chan->sk;
1699
		if (chan->chan_type != L2CAP_CHAN_RAW)
L
Linus Torvalds 已提交
1700 1701 1702 1703 1704
			continue;

		/* Don't send frame to the socket it came from */
		if (skb->sk == sk)
			continue;
1705 1706
		nskb = skb_clone(skb, GFP_ATOMIC);
		if (!nskb)
L
Linus Torvalds 已提交
1707 1708 1709 1710 1711
			continue;

		if (sock_queue_rcv_skb(sk, nskb))
			kfree_skb(nskb);
	}
1712
	read_unlock(&conn->chan_lock);
L
Linus Torvalds 已提交
1713 1714 1715 1716 1717 1718 1719 1720 1721 1722 1723
}

/* ---- L2CAP signalling commands ---- */
static struct sk_buff *l2cap_build_cmd(struct l2cap_conn *conn,
				u8 code, u8 ident, u16 dlen, void *data)
{
	struct sk_buff *skb, **frag;
	struct l2cap_cmd_hdr *cmd;
	struct l2cap_hdr *lh;
	int len, count;

1724 1725
	BT_DBG("conn %p, code 0x%2.2x, ident 0x%2.2x, len %d",
			conn, code, ident, dlen);
L
Linus Torvalds 已提交
1726 1727 1728 1729 1730 1731 1732 1733 1734

	len = L2CAP_HDR_SIZE + L2CAP_CMD_HDR_SIZE + dlen;
	count = min_t(unsigned int, conn->mtu, len);

	skb = bt_skb_alloc(count, GFP_ATOMIC);
	if (!skb)
		return NULL;

	lh = (struct l2cap_hdr *) skb_put(skb, L2CAP_HDR_SIZE);
1735
	lh->len = cpu_to_le16(L2CAP_CMD_HDR_SIZE + dlen);
1736 1737 1738 1739 1740

	if (conn->hcon->type == LE_LINK)
		lh->cid = cpu_to_le16(L2CAP_CID_LE_SIGNALING);
	else
		lh->cid = cpu_to_le16(L2CAP_CID_SIGNALING);
L
Linus Torvalds 已提交
1741 1742 1743 1744

	cmd = (struct l2cap_cmd_hdr *) skb_put(skb, L2CAP_CMD_HDR_SIZE);
	cmd->code  = code;
	cmd->ident = ident;
1745
	cmd->len   = cpu_to_le16(dlen);
L
Linus Torvalds 已提交
1746 1747 1748 1749 1750 1751 1752 1753 1754 1755 1756 1757 1758 1759 1760 1761 1762 1763 1764 1765 1766 1767 1768 1769 1770 1771 1772 1773 1774 1775 1776 1777 1778 1779 1780 1781 1782 1783 1784 1785 1786 1787 1788 1789 1790 1791 1792 1793 1794 1795

	if (dlen) {
		count -= L2CAP_HDR_SIZE + L2CAP_CMD_HDR_SIZE;
		memcpy(skb_put(skb, count), data, count);
		data += count;
	}

	len -= skb->len;

	/* Continuation fragments (no L2CAP header) */
	frag = &skb_shinfo(skb)->frag_list;
	while (len) {
		count = min_t(unsigned int, conn->mtu, len);

		*frag = bt_skb_alloc(count, GFP_ATOMIC);
		if (!*frag)
			goto fail;

		memcpy(skb_put(*frag, count), data, count);

		len  -= count;
		data += count;

		frag = &(*frag)->next;
	}

	return skb;

fail:
	kfree_skb(skb);
	return NULL;
}

static inline int l2cap_get_conf_opt(void **ptr, int *type, int *olen, unsigned long *val)
{
	struct l2cap_conf_opt *opt = *ptr;
	int len;

	len = L2CAP_CONF_OPT_SIZE + opt->len;
	*ptr += len;

	*type = opt->type;
	*olen = opt->len;

	switch (opt->len) {
	case 1:
		*val = *((u8 *) opt->val);
		break;

	case 2:
1796
		*val = get_unaligned_le16(opt->val);
L
Linus Torvalds 已提交
1797 1798 1799
		break;

	case 4:
1800
		*val = get_unaligned_le32(opt->val);
L
Linus Torvalds 已提交
1801 1802 1803 1804 1805 1806 1807 1808 1809 1810 1811 1812 1813 1814 1815 1816 1817 1818 1819 1820 1821 1822 1823 1824 1825 1826
		break;

	default:
		*val = (unsigned long) opt->val;
		break;
	}

	BT_DBG("type 0x%2.2x len %d val 0x%lx", *type, opt->len, *val);
	return len;
}

static void l2cap_add_conf_opt(void **ptr, u8 type, u8 len, unsigned long val)
{
	struct l2cap_conf_opt *opt = *ptr;

	BT_DBG("type 0x%2.2x len %d val 0x%lx", type, len, val);

	opt->type = type;
	opt->len  = len;

	switch (len) {
	case 1:
		*((u8 *) opt->val)  = val;
		break;

	case 2:
1827
		put_unaligned_le16(val, opt->val);
L
Linus Torvalds 已提交
1828 1829 1830
		break;

	case 4:
1831
		put_unaligned_le32(val, opt->val);
L
Linus Torvalds 已提交
1832 1833 1834 1835 1836 1837 1838 1839 1840 1841
		break;

	default:
		memcpy(opt->val, (void *) val, len);
		break;
	}

	*ptr += L2CAP_CONF_OPT_SIZE + len;
}

1842 1843
static void l2cap_ack_timeout(unsigned long arg)
{
1844
	struct l2cap_chan *chan = (void *) arg;
1845

1846 1847 1848
	bh_lock_sock(chan->sk);
	l2cap_send_ack(chan);
	bh_unlock_sock(chan->sk);
1849 1850
}

1851
static inline void l2cap_ertm_init(struct l2cap_chan *chan)
1852
{
1853 1854
	struct sock *sk = chan->sk;

1855
	chan->expected_ack_seq = 0;
1856
	chan->unacked_frames = 0;
1857
	chan->buffer_seq = 0;
1858 1859
	chan->num_acked = 0;
	chan->frames_sent = 0;
1860

1861 1862 1863 1864 1865
	setup_timer(&chan->retrans_timer, l2cap_retrans_timeout,
							(unsigned long) chan);
	setup_timer(&chan->monitor_timer, l2cap_monitor_timeout,
							(unsigned long) chan);
	setup_timer(&chan->ack_timer, l2cap_ack_timeout, (unsigned long) chan);
1866

1867 1868
	skb_queue_head_init(&chan->srej_q);
	skb_queue_head_init(&chan->busy_q);
1869

1870 1871
	INIT_LIST_HEAD(&chan->srej_l);

1872
	INIT_WORK(&chan->busy_work, l2cap_busy_work);
1873 1874

	sk->sk_backlog_rcv = l2cap_ertm_data_rcv;
1875 1876
}

1877 1878 1879 1880 1881 1882 1883 1884 1885 1886 1887 1888 1889
static inline __u8 l2cap_select_mode(__u8 mode, __u16 remote_feat_mask)
{
	switch (mode) {
	case L2CAP_MODE_STREAMING:
	case L2CAP_MODE_ERTM:
		if (l2cap_mode_supported(mode, remote_feat_mask))
			return mode;
		/* fall through */
	default:
		return L2CAP_MODE_BASIC;
	}
}

1890
static int l2cap_build_conf_req(struct l2cap_chan *chan, void *data)
L
Linus Torvalds 已提交
1891 1892
{
	struct l2cap_conf_req *req = data;
1893
	struct l2cap_conf_rfc rfc = { .mode = chan->mode };
L
Linus Torvalds 已提交
1894 1895
	void *ptr = req->data;

1896
	BT_DBG("chan %p", chan);
L
Linus Torvalds 已提交
1897

1898
	if (chan->num_conf_req || chan->num_conf_rsp)
1899 1900
		goto done;

1901
	switch (chan->mode) {
1902 1903
	case L2CAP_MODE_STREAMING:
	case L2CAP_MODE_ERTM:
1904
		if (chan->conf_state & L2CAP_CONF_STATE2_DEVICE)
1905 1906
			break;

1907
		/* fall through */
1908
	default:
1909
		chan->mode = l2cap_select_mode(rfc.mode, chan->conn->feat_mask);
1910 1911 1912 1913
		break;
	}

done:
1914 1915
	if (chan->imtu != L2CAP_DEFAULT_MTU)
		l2cap_add_conf_opt(&ptr, L2CAP_CONF_MTU, 2, chan->imtu);
1916

1917
	switch (chan->mode) {
1918
	case L2CAP_MODE_BASIC:
1919 1920
		if (!(chan->conn->feat_mask & L2CAP_FEAT_ERTM) &&
				!(chan->conn->feat_mask & L2CAP_FEAT_STREAMING))
1921 1922
			break;

1923 1924 1925 1926 1927 1928 1929
		rfc.mode            = L2CAP_MODE_BASIC;
		rfc.txwin_size      = 0;
		rfc.max_transmit    = 0;
		rfc.retrans_timeout = 0;
		rfc.monitor_timeout = 0;
		rfc.max_pdu_size    = 0;

1930 1931
		l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC, sizeof(rfc),
							(unsigned long) &rfc);
1932 1933 1934 1935
		break;

	case L2CAP_MODE_ERTM:
		rfc.mode            = L2CAP_MODE_ERTM;
1936 1937
		rfc.txwin_size      = chan->tx_win;
		rfc.max_transmit    = chan->max_tx;
1938 1939
		rfc.retrans_timeout = 0;
		rfc.monitor_timeout = 0;
1940
		rfc.max_pdu_size    = cpu_to_le16(L2CAP_DEFAULT_MAX_PDU_SIZE);
1941 1942
		if (L2CAP_DEFAULT_MAX_PDU_SIZE > chan->conn->mtu - 10)
			rfc.max_pdu_size = cpu_to_le16(chan->conn->mtu - 10);
1943

1944 1945 1946
		l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC, sizeof(rfc),
							(unsigned long) &rfc);

1947
		if (!(chan->conn->feat_mask & L2CAP_FEAT_FCS))
1948 1949
			break;

1950
		if (chan->fcs == L2CAP_FCS_NONE ||
1951
				chan->conf_state & L2CAP_CONF_NO_FCS_RECV) {
1952 1953
			chan->fcs = L2CAP_FCS_NONE;
			l2cap_add_conf_opt(&ptr, L2CAP_CONF_FCS, 1, chan->fcs);
1954
		}
1955 1956 1957 1958 1959 1960 1961 1962
		break;

	case L2CAP_MODE_STREAMING:
		rfc.mode            = L2CAP_MODE_STREAMING;
		rfc.txwin_size      = 0;
		rfc.max_transmit    = 0;
		rfc.retrans_timeout = 0;
		rfc.monitor_timeout = 0;
1963
		rfc.max_pdu_size    = cpu_to_le16(L2CAP_DEFAULT_MAX_PDU_SIZE);
1964 1965
		if (L2CAP_DEFAULT_MAX_PDU_SIZE > chan->conn->mtu - 10)
			rfc.max_pdu_size = cpu_to_le16(chan->conn->mtu - 10);
1966

1967 1968 1969
		l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC, sizeof(rfc),
							(unsigned long) &rfc);

1970
		if (!(chan->conn->feat_mask & L2CAP_FEAT_FCS))
1971 1972
			break;

1973
		if (chan->fcs == L2CAP_FCS_NONE ||
1974
				chan->conf_state & L2CAP_CONF_NO_FCS_RECV) {
1975 1976
			chan->fcs = L2CAP_FCS_NONE;
			l2cap_add_conf_opt(&ptr, L2CAP_CONF_FCS, 1, chan->fcs);
1977
		}
1978 1979
		break;
	}
L
Linus Torvalds 已提交
1980

1981
	req->dcid  = cpu_to_le16(chan->dcid);
1982
	req->flags = cpu_to_le16(0);
L
Linus Torvalds 已提交
1983 1984 1985 1986

	return ptr - data;
}

1987
static int l2cap_parse_conf_req(struct l2cap_chan *chan, void *data)
L
Linus Torvalds 已提交
1988
{
1989 1990
	struct l2cap_conf_rsp *rsp = data;
	void *ptr = rsp->data;
1991 1992
	void *req = chan->conf_req;
	int len = chan->conf_len;
1993 1994
	int type, hint, olen;
	unsigned long val;
1995
	struct l2cap_conf_rfc rfc = { .mode = L2CAP_MODE_BASIC };
1996
	u16 mtu = L2CAP_DEFAULT_MTU;
1997
	u16 result = L2CAP_CONF_SUCCESS;
L
Linus Torvalds 已提交
1998

1999
	BT_DBG("chan %p", chan);
2000

2001 2002
	while (len >= L2CAP_CONF_OPT_SIZE) {
		len -= l2cap_get_conf_opt(&req, &type, &olen, &val);
L
Linus Torvalds 已提交
2003

2004
		hint  = type & L2CAP_CONF_HINT;
2005
		type &= L2CAP_CONF_MASK;
2006 2007 2008

		switch (type) {
		case L2CAP_CONF_MTU:
2009
			mtu = val;
2010 2011 2012
			break;

		case L2CAP_CONF_FLUSH_TO:
2013
			chan->flush_to = val;
2014 2015 2016 2017 2018
			break;

		case L2CAP_CONF_QOS:
			break;

2019 2020 2021 2022 2023
		case L2CAP_CONF_RFC:
			if (olen == sizeof(rfc))
				memcpy(&rfc, (void *) val, olen);
			break;

2024 2025
		case L2CAP_CONF_FCS:
			if (val == L2CAP_FCS_NONE)
2026
				chan->conf_state |= L2CAP_CONF_NO_FCS_RECV;
2027 2028 2029

			break;

2030 2031 2032 2033 2034 2035 2036 2037 2038 2039
		default:
			if (hint)
				break;

			result = L2CAP_CONF_UNKNOWN;
			*((u8 *) ptr++) = type;
			break;
		}
	}

2040
	if (chan->num_conf_rsp || chan->num_conf_req > 1)
2041 2042
		goto done;

2043
	switch (chan->mode) {
2044 2045
	case L2CAP_MODE_STREAMING:
	case L2CAP_MODE_ERTM:
2046
		if (!(chan->conf_state & L2CAP_CONF_STATE2_DEVICE)) {
2047
			chan->mode = l2cap_select_mode(rfc.mode,
2048
					chan->conn->feat_mask);
2049 2050 2051
			break;
		}

2052
		if (chan->mode != rfc.mode)
2053
			return -ECONNREFUSED;
2054

2055 2056 2057 2058
		break;
	}

done:
2059
	if (chan->mode != rfc.mode) {
2060
		result = L2CAP_CONF_UNACCEPT;
2061
		rfc.mode = chan->mode;
2062

2063
		if (chan->num_conf_rsp == 1)
2064 2065 2066 2067 2068 2069 2070
			return -ECONNREFUSED;

		l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC,
					sizeof(rfc), (unsigned long) &rfc);
	}


2071 2072 2073 2074
	if (result == L2CAP_CONF_SUCCESS) {
		/* Configure output options and let the other side know
		 * which ones we don't like. */

2075 2076 2077
		if (mtu < L2CAP_DEFAULT_MIN_MTU)
			result = L2CAP_CONF_UNACCEPT;
		else {
2078
			chan->omtu = mtu;
2079
			chan->conf_state |= L2CAP_CONF_MTU_DONE;
2080
		}
2081
		l2cap_add_conf_opt(&ptr, L2CAP_CONF_MTU, 2, chan->omtu);
2082

2083 2084
		switch (rfc.mode) {
		case L2CAP_MODE_BASIC:
2085
			chan->fcs = L2CAP_FCS_NONE;
2086
			chan->conf_state |= L2CAP_CONF_MODE_DONE;
2087 2088 2089
			break;

		case L2CAP_MODE_ERTM:
2090 2091
			chan->remote_tx_win = rfc.txwin_size;
			chan->remote_max_tx = rfc.max_transmit;
2092

2093 2094
			if (le16_to_cpu(rfc.max_pdu_size) > chan->conn->mtu - 10)
				rfc.max_pdu_size = cpu_to_le16(chan->conn->mtu - 10);
2095

2096
			chan->remote_mps = le16_to_cpu(rfc.max_pdu_size);
2097

2098 2099 2100 2101
			rfc.retrans_timeout =
				le16_to_cpu(L2CAP_DEFAULT_RETRANS_TO);
			rfc.monitor_timeout =
				le16_to_cpu(L2CAP_DEFAULT_MONITOR_TO);
2102

2103
			chan->conf_state |= L2CAP_CONF_MODE_DONE;
2104 2105 2106 2107

			l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC,
					sizeof(rfc), (unsigned long) &rfc);

2108 2109 2110
			break;

		case L2CAP_MODE_STREAMING:
2111 2112
			if (le16_to_cpu(rfc.max_pdu_size) > chan->conn->mtu - 10)
				rfc.max_pdu_size = cpu_to_le16(chan->conn->mtu - 10);
2113

2114
			chan->remote_mps = le16_to_cpu(rfc.max_pdu_size);
2115

2116
			chan->conf_state |= L2CAP_CONF_MODE_DONE;
2117 2118 2119 2120

			l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC,
					sizeof(rfc), (unsigned long) &rfc);

2121 2122 2123
			break;

		default:
2124 2125
			result = L2CAP_CONF_UNACCEPT;

2126
			memset(&rfc, 0, sizeof(rfc));
2127
			rfc.mode = chan->mode;
2128
		}
2129

2130
		if (result == L2CAP_CONF_SUCCESS)
2131
			chan->conf_state |= L2CAP_CONF_OUTPUT_DONE;
2132
	}
2133
	rsp->scid   = cpu_to_le16(chan->dcid);
2134 2135 2136 2137
	rsp->result = cpu_to_le16(result);
	rsp->flags  = cpu_to_le16(0x0000);

	return ptr - data;
L
Linus Torvalds 已提交
2138 2139
}

2140
static int l2cap_parse_conf_rsp(struct l2cap_chan *chan, void *rsp, int len, void *data, u16 *result)
2141 2142 2143 2144 2145 2146 2147
{
	struct l2cap_conf_req *req = data;
	void *ptr = req->data;
	int type, olen;
	unsigned long val;
	struct l2cap_conf_rfc rfc;

2148
	BT_DBG("chan %p, rsp %p, len %d, req %p", chan, rsp, len, data);
2149 2150 2151 2152 2153 2154 2155 2156

	while (len >= L2CAP_CONF_OPT_SIZE) {
		len -= l2cap_get_conf_opt(&rsp, &type, &olen, &val);

		switch (type) {
		case L2CAP_CONF_MTU:
			if (val < L2CAP_DEFAULT_MIN_MTU) {
				*result = L2CAP_CONF_UNACCEPT;
2157
				chan->imtu = L2CAP_DEFAULT_MIN_MTU;
2158
			} else
2159 2160
				chan->imtu = val;
			l2cap_add_conf_opt(&ptr, L2CAP_CONF_MTU, 2, chan->imtu);
2161 2162 2163
			break;

		case L2CAP_CONF_FLUSH_TO:
2164
			chan->flush_to = val;
2165
			l2cap_add_conf_opt(&ptr, L2CAP_CONF_FLUSH_TO,
2166
							2, chan->flush_to);
2167 2168 2169 2170 2171 2172
			break;

		case L2CAP_CONF_RFC:
			if (olen == sizeof(rfc))
				memcpy(&rfc, (void *)val, olen);

2173
			if ((chan->conf_state & L2CAP_CONF_STATE2_DEVICE) &&
2174
							rfc.mode != chan->mode)
2175 2176
				return -ECONNREFUSED;

2177
			chan->fcs = 0;
2178 2179 2180 2181 2182 2183 2184

			l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC,
					sizeof(rfc), (unsigned long) &rfc);
			break;
		}
	}

2185
	if (chan->mode == L2CAP_MODE_BASIC && chan->mode != rfc.mode)
2186 2187
		return -ECONNREFUSED;

2188
	chan->mode = rfc.mode;
2189

2190 2191 2192
	if (*result == L2CAP_CONF_SUCCESS) {
		switch (rfc.mode) {
		case L2CAP_MODE_ERTM:
2193 2194 2195
			chan->retrans_timeout = le16_to_cpu(rfc.retrans_timeout);
			chan->monitor_timeout = le16_to_cpu(rfc.monitor_timeout);
			chan->mps    = le16_to_cpu(rfc.max_pdu_size);
2196 2197
			break;
		case L2CAP_MODE_STREAMING:
2198
			chan->mps    = le16_to_cpu(rfc.max_pdu_size);
2199 2200 2201
		}
	}

2202
	req->dcid   = cpu_to_le16(chan->dcid);
2203 2204 2205 2206 2207
	req->flags  = cpu_to_le16(0x0000);

	return ptr - data;
}

2208
static int l2cap_build_conf_rsp(struct l2cap_chan *chan, void *data, u16 result, u16 flags)
L
Linus Torvalds 已提交
2209 2210 2211 2212
{
	struct l2cap_conf_rsp *rsp = data;
	void *ptr = rsp->data;

2213
	BT_DBG("chan %p", chan);
L
Linus Torvalds 已提交
2214

2215
	rsp->scid   = cpu_to_le16(chan->dcid);
2216
	rsp->result = cpu_to_le16(result);
2217
	rsp->flags  = cpu_to_le16(flags);
L
Linus Torvalds 已提交
2218 2219 2220 2221

	return ptr - data;
}

2222
void __l2cap_connect_rsp_defer(struct l2cap_chan *chan)
2223 2224
{
	struct l2cap_conn_rsp rsp;
2225
	struct l2cap_conn *conn = chan->conn;
2226 2227
	u8 buf[128];

2228 2229
	rsp.scid   = cpu_to_le16(chan->dcid);
	rsp.dcid   = cpu_to_le16(chan->scid);
2230 2231 2232 2233 2234
	rsp.result = cpu_to_le16(L2CAP_CR_SUCCESS);
	rsp.status = cpu_to_le16(L2CAP_CS_NO_INFO);
	l2cap_send_cmd(conn, chan->ident,
				L2CAP_CONN_RSP, sizeof(rsp), &rsp);

2235
	if (chan->conf_state & L2CAP_CONF_REQ_SENT)
2236 2237
		return;

2238
	chan->conf_state |= L2CAP_CONF_REQ_SENT;
2239 2240 2241 2242 2243
	l2cap_send_cmd(conn, l2cap_get_ident(conn), L2CAP_CONF_REQ,
			l2cap_build_conf_req(chan, buf), buf);
	chan->num_conf_req++;
}

2244
static void l2cap_conf_rfc_get(struct l2cap_chan *chan, void *rsp, int len)
2245 2246 2247 2248 2249
{
	int type, olen;
	unsigned long val;
	struct l2cap_conf_rfc rfc;

2250
	BT_DBG("chan %p, rsp %p, len %d", chan, rsp, len);
2251

2252
	if ((chan->mode != L2CAP_MODE_ERTM) && (chan->mode != L2CAP_MODE_STREAMING))
2253 2254 2255 2256 2257 2258 2259 2260 2261 2262 2263 2264 2265 2266 2267 2268
		return;

	while (len >= L2CAP_CONF_OPT_SIZE) {
		len -= l2cap_get_conf_opt(&rsp, &type, &olen, &val);

		switch (type) {
		case L2CAP_CONF_RFC:
			if (olen == sizeof(rfc))
				memcpy(&rfc, (void *)val, olen);
			goto done;
		}
	}

done:
	switch (rfc.mode) {
	case L2CAP_MODE_ERTM:
2269 2270 2271
		chan->retrans_timeout = le16_to_cpu(rfc.retrans_timeout);
		chan->monitor_timeout = le16_to_cpu(rfc.monitor_timeout);
		chan->mps    = le16_to_cpu(rfc.max_pdu_size);
2272 2273
		break;
	case L2CAP_MODE_STREAMING:
2274
		chan->mps    = le16_to_cpu(rfc.max_pdu_size);
2275 2276 2277
	}
}

2278 2279 2280 2281 2282 2283 2284 2285 2286 2287
static inline int l2cap_command_rej(struct l2cap_conn *conn, struct l2cap_cmd_hdr *cmd, u8 *data)
{
	struct l2cap_cmd_rej *rej = (struct l2cap_cmd_rej *) data;

	if (rej->reason != 0x0000)
		return 0;

	if ((conn->info_state & L2CAP_INFO_FEAT_MASK_REQ_SENT) &&
					cmd->ident == conn->info_ident) {
		del_timer(&conn->info_timer);
2288 2289

		conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_DONE;
2290
		conn->info_ident = 0;
2291

2292 2293 2294 2295 2296 2297
		l2cap_conn_start(conn);
	}

	return 0;
}

L
Linus Torvalds 已提交
2298 2299 2300 2301
static inline int l2cap_connect_req(struct l2cap_conn *conn, struct l2cap_cmd_hdr *cmd, u8 *data)
{
	struct l2cap_conn_req *req = (struct l2cap_conn_req *) data;
	struct l2cap_conn_rsp rsp;
2302
	struct l2cap_chan *chan = NULL, *pchan;
2303
	struct sock *parent, *sk = NULL;
2304
	int result, status = L2CAP_CS_NO_INFO;
L
Linus Torvalds 已提交
2305 2306

	u16 dcid = 0, scid = __le16_to_cpu(req->scid);
2307
	__le16 psm = req->psm;
L
Linus Torvalds 已提交
2308 2309 2310 2311

	BT_DBG("psm 0x%2.2x scid 0x%4.4x", psm, scid);

	/* Check if we have socket listening on psm */
2312 2313
	pchan = l2cap_global_chan_by_psm(BT_LISTEN, psm, conn->src);
	if (!pchan) {
L
Linus Torvalds 已提交
2314 2315 2316 2317
		result = L2CAP_CR_BAD_PSM;
		goto sendresp;
	}

2318 2319
	parent = pchan->sk;

2320 2321
	bh_lock_sock(parent);

2322 2323 2324
	/* Check if the ACL is secure enough (if not SDP) */
	if (psm != cpu_to_le16(0x0001) &&
				!hci_conn_check_link_mode(conn->hcon)) {
2325
		conn->disc_reason = 0x05;
2326 2327 2328 2329
		result = L2CAP_CR_SEC_BLOCK;
		goto response;
	}

L
Linus Torvalds 已提交
2330 2331 2332 2333
	result = L2CAP_CR_NO_MEM;

	/* Check for backlog size */
	if (sk_acceptq_is_full(parent)) {
2334
		BT_DBG("backlog full %d", parent->sk_ack_backlog);
L
Linus Torvalds 已提交
2335 2336 2337
		goto response;
	}

2338
	sk = l2cap_sock_alloc(sock_net(parent), NULL, BTPROTO_L2CAP, GFP_ATOMIC);
L
Linus Torvalds 已提交
2339 2340 2341
	if (!sk)
		goto response;

2342
	chan = l2cap_chan_create(sk);
2343 2344 2345 2346 2347
	if (!chan) {
		l2cap_sock_kill(sk);
		goto response;
	}

2348 2349
	l2cap_pi(sk)->chan = chan;

2350
	write_lock_bh(&conn->chan_lock);
L
Linus Torvalds 已提交
2351 2352

	/* Check if we already have channel with that dcid */
2353 2354
	if (__l2cap_get_chan_by_dcid(conn, scid)) {
		write_unlock_bh(&conn->chan_lock);
L
Linus Torvalds 已提交
2355 2356 2357 2358 2359 2360 2361 2362 2363 2364
		sock_set_flag(sk, SOCK_ZAPPED);
		l2cap_sock_kill(sk);
		goto response;
	}

	hci_conn_hold(conn->hcon);

	l2cap_sock_init(sk, parent);
	bacpy(&bt_sk(sk)->src, conn->src);
	bacpy(&bt_sk(sk)->dst, conn->dst);
2365 2366
	chan->psm  = psm;
	chan->dcid = scid;
L
Linus Torvalds 已提交
2367

2368 2369
	bt_accept_enqueue(parent, sk);

2370 2371
	__l2cap_chan_add(conn, chan);

2372
	dcid = chan->scid;
L
Linus Torvalds 已提交
2373

2374
	l2cap_chan_set_timer(chan, sk->sk_sndtimeo);
L
Linus Torvalds 已提交
2375

2376
	chan->ident = cmd->ident;
L
Linus Torvalds 已提交
2377

2378
	if (conn->info_state & L2CAP_INFO_FEAT_MASK_REQ_DONE) {
2379
		if (l2cap_check_security(chan)) {
2380 2381 2382 2383 2384 2385 2386 2387 2388 2389
			if (bt_sk(sk)->defer_setup) {
				sk->sk_state = BT_CONNECT2;
				result = L2CAP_CR_PEND;
				status = L2CAP_CS_AUTHOR_PEND;
				parent->sk_data_ready(parent, 0);
			} else {
				sk->sk_state = BT_CONFIG;
				result = L2CAP_CR_SUCCESS;
				status = L2CAP_CS_NO_INFO;
			}
2390 2391 2392 2393 2394 2395 2396 2397 2398
		} else {
			sk->sk_state = BT_CONNECT2;
			result = L2CAP_CR_PEND;
			status = L2CAP_CS_AUTHEN_PEND;
		}
	} else {
		sk->sk_state = BT_CONNECT2;
		result = L2CAP_CR_PEND;
		status = L2CAP_CS_NO_INFO;
L
Linus Torvalds 已提交
2399 2400
	}

2401
	write_unlock_bh(&conn->chan_lock);
L
Linus Torvalds 已提交
2402 2403 2404 2405 2406

response:
	bh_unlock_sock(parent);

sendresp:
2407 2408 2409 2410
	rsp.scid   = cpu_to_le16(scid);
	rsp.dcid   = cpu_to_le16(dcid);
	rsp.result = cpu_to_le16(result);
	rsp.status = cpu_to_le16(status);
L
Linus Torvalds 已提交
2411
	l2cap_send_cmd(conn, cmd->ident, L2CAP_CONN_RSP, sizeof(rsp), &rsp);
2412 2413 2414 2415 2416 2417 2418 2419 2420 2421 2422 2423 2424 2425 2426

	if (result == L2CAP_CR_PEND && status == L2CAP_CS_NO_INFO) {
		struct l2cap_info_req info;
		info.type = cpu_to_le16(L2CAP_IT_FEAT_MASK);

		conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_SENT;
		conn->info_ident = l2cap_get_ident(conn);

		mod_timer(&conn->info_timer, jiffies +
					msecs_to_jiffies(L2CAP_INFO_TIMEOUT));

		l2cap_send_cmd(conn, conn->info_ident,
					L2CAP_INFO_REQ, sizeof(info), &info);
	}

2427
	if (chan && !(chan->conf_state & L2CAP_CONF_REQ_SENT) &&
2428 2429
				result == L2CAP_CR_SUCCESS) {
		u8 buf[128];
2430
		chan->conf_state |= L2CAP_CONF_REQ_SENT;
2431
		l2cap_send_cmd(conn, l2cap_get_ident(conn), L2CAP_CONF_REQ,
2432 2433
					l2cap_build_conf_req(chan, buf), buf);
		chan->num_conf_req++;
2434 2435
	}

L
Linus Torvalds 已提交
2436 2437 2438 2439 2440 2441 2442
	return 0;
}

static inline int l2cap_connect_rsp(struct l2cap_conn *conn, struct l2cap_cmd_hdr *cmd, u8 *data)
{
	struct l2cap_conn_rsp *rsp = (struct l2cap_conn_rsp *) data;
	u16 scid, dcid, result, status;
2443
	struct l2cap_chan *chan;
L
Linus Torvalds 已提交
2444 2445 2446 2447 2448 2449 2450 2451 2452 2453 2454
	struct sock *sk;
	u8 req[128];

	scid   = __le16_to_cpu(rsp->scid);
	dcid   = __le16_to_cpu(rsp->dcid);
	result = __le16_to_cpu(rsp->result);
	status = __le16_to_cpu(rsp->status);

	BT_DBG("dcid 0x%4.4x scid 0x%4.4x result 0x%2.2x status 0x%2.2x", dcid, scid, result, status);

	if (scid) {
2455
		chan = l2cap_get_chan_by_scid(conn, scid);
2456
		if (!chan)
2457
			return -EFAULT;
L
Linus Torvalds 已提交
2458
	} else {
2459
		chan = l2cap_get_chan_by_ident(conn, cmd->ident);
2460
		if (!chan)
2461
			return -EFAULT;
L
Linus Torvalds 已提交
2462 2463
	}

2464 2465
	sk = chan->sk;

L
Linus Torvalds 已提交
2466 2467 2468
	switch (result) {
	case L2CAP_CR_SUCCESS:
		sk->sk_state = BT_CONFIG;
2469
		chan->ident = 0;
2470
		chan->dcid = dcid;
2471
		chan->conf_state &= ~L2CAP_CONF_CONNECT_PEND;
2472

2473
		if (chan->conf_state & L2CAP_CONF_REQ_SENT)
2474 2475
			break;

2476
		chan->conf_state |= L2CAP_CONF_REQ_SENT;
2477

L
Linus Torvalds 已提交
2478
		l2cap_send_cmd(conn, l2cap_get_ident(conn), L2CAP_CONF_REQ,
2479 2480
					l2cap_build_conf_req(chan, req), req);
		chan->num_conf_req++;
L
Linus Torvalds 已提交
2481 2482 2483
		break;

	case L2CAP_CR_PEND:
2484
		chan->conf_state |= L2CAP_CONF_CONNECT_PEND;
L
Linus Torvalds 已提交
2485 2486 2487
		break;

	default:
2488 2489 2490
		/* don't delete l2cap channel if sk is owned by user */
		if (sock_owned_by_user(sk)) {
			sk->sk_state = BT_DISCONN;
2491 2492
			l2cap_chan_clear_timer(chan);
			l2cap_chan_set_timer(chan, HZ / 5);
2493 2494 2495
			break;
		}

2496
		l2cap_chan_del(chan, ECONNREFUSED);
L
Linus Torvalds 已提交
2497 2498 2499 2500 2501 2502 2503
		break;
	}

	bh_unlock_sock(sk);
	return 0;
}

2504
static inline void set_default_fcs(struct l2cap_chan *chan)
2505
{
2506 2507
	struct l2cap_pinfo *pi = l2cap_pi(chan->sk);

2508 2509 2510
	/* FCS is enabled only in ERTM or streaming mode, if one or both
	 * sides request it.
	 */
2511
	if (chan->mode != L2CAP_MODE_ERTM && chan->mode != L2CAP_MODE_STREAMING)
2512
		chan->fcs = L2CAP_FCS_NONE;
2513
	else if (!(pi->chan->conf_state & L2CAP_CONF_NO_FCS_RECV))
2514
		chan->fcs = L2CAP_FCS_CRC16;
2515 2516
}

2517
static inline int l2cap_config_req(struct l2cap_conn *conn, struct l2cap_cmd_hdr *cmd, u16 cmd_len, u8 *data)
L
Linus Torvalds 已提交
2518 2519 2520 2521
{
	struct l2cap_conf_req *req = (struct l2cap_conf_req *) data;
	u16 dcid, flags;
	u8 rsp[64];
2522
	struct l2cap_chan *chan;
L
Linus Torvalds 已提交
2523
	struct sock *sk;
2524
	int len;
L
Linus Torvalds 已提交
2525 2526 2527 2528 2529 2530

	dcid  = __le16_to_cpu(req->dcid);
	flags = __le16_to_cpu(req->flags);

	BT_DBG("dcid 0x%4.4x flags 0x%2.2x", dcid, flags);

2531
	chan = l2cap_get_chan_by_scid(conn, dcid);
2532
	if (!chan)
L
Linus Torvalds 已提交
2533 2534
		return -ENOENT;

2535 2536
	sk = chan->sk;

2537 2538 2539 2540 2541 2542
	if (sk->sk_state != BT_CONFIG) {
		struct l2cap_cmd_rej rej;

		rej.reason = cpu_to_le16(0x0002);
		l2cap_send_cmd(conn, cmd->ident, L2CAP_COMMAND_REJ,
				sizeof(rej), &rej);
2543
		goto unlock;
2544
	}
2545

2546
	/* Reject if config buffer is too small. */
2547
	len = cmd_len - sizeof(*req);
2548
	if (chan->conf_len + len > sizeof(chan->conf_req)) {
2549
		l2cap_send_cmd(conn, cmd->ident, L2CAP_CONF_RSP,
2550
				l2cap_build_conf_rsp(chan, rsp,
2551 2552 2553 2554 2555
					L2CAP_CONF_REJECT, flags), rsp);
		goto unlock;
	}

	/* Store config. */
2556 2557
	memcpy(chan->conf_req + chan->conf_len, req->data, len);
	chan->conf_len += len;
L
Linus Torvalds 已提交
2558 2559 2560 2561

	if (flags & 0x0001) {
		/* Incomplete config. Send empty response. */
		l2cap_send_cmd(conn, cmd->ident, L2CAP_CONF_RSP,
2562
				l2cap_build_conf_rsp(chan, rsp,
2563
					L2CAP_CONF_SUCCESS, 0x0001), rsp);
L
Linus Torvalds 已提交
2564 2565 2566 2567
		goto unlock;
	}

	/* Complete config. */
2568
	len = l2cap_parse_conf_req(chan, rsp);
2569
	if (len < 0) {
2570
		l2cap_send_disconn_req(conn, chan, ECONNRESET);
L
Linus Torvalds 已提交
2571
		goto unlock;
2572
	}
L
Linus Torvalds 已提交
2573

2574
	l2cap_send_cmd(conn, cmd->ident, L2CAP_CONF_RSP, len, rsp);
2575
	chan->num_conf_rsp++;
2576 2577

	/* Reset config buffer. */
2578
	chan->conf_len = 0;
2579

2580
	if (!(chan->conf_state & L2CAP_CONF_OUTPUT_DONE))
2581 2582
		goto unlock;

2583
	if (chan->conf_state & L2CAP_CONF_INPUT_DONE) {
2584
		set_default_fcs(chan);
2585

L
Linus Torvalds 已提交
2586
		sk->sk_state = BT_CONNECTED;
2587

2588 2589
		chan->next_tx_seq = 0;
		chan->expected_tx_seq = 0;
2590
		skb_queue_head_init(&chan->tx_q);
2591
		if (chan->mode == L2CAP_MODE_ERTM)
2592
			l2cap_ertm_init(chan);
2593

L
Linus Torvalds 已提交
2594
		l2cap_chan_ready(sk);
2595 2596 2597
		goto unlock;
	}

2598
	if (!(chan->conf_state & L2CAP_CONF_REQ_SENT)) {
2599
		u8 buf[64];
2600
		chan->conf_state |= L2CAP_CONF_REQ_SENT;
L
Linus Torvalds 已提交
2601
		l2cap_send_cmd(conn, l2cap_get_ident(conn), L2CAP_CONF_REQ,
2602 2603
					l2cap_build_conf_req(chan, buf), buf);
		chan->num_conf_req++;
L
Linus Torvalds 已提交
2604 2605 2606 2607 2608 2609 2610 2611 2612 2613 2614
	}

unlock:
	bh_unlock_sock(sk);
	return 0;
}

static inline int l2cap_config_rsp(struct l2cap_conn *conn, struct l2cap_cmd_hdr *cmd, u8 *data)
{
	struct l2cap_conf_rsp *rsp = (struct l2cap_conf_rsp *)data;
	u16 scid, flags, result;
2615
	struct l2cap_chan *chan;
L
Linus Torvalds 已提交
2616
	struct sock *sk;
2617
	int len = cmd->len - sizeof(*rsp);
L
Linus Torvalds 已提交
2618 2619 2620 2621 2622

	scid   = __le16_to_cpu(rsp->scid);
	flags  = __le16_to_cpu(rsp->flags);
	result = __le16_to_cpu(rsp->result);

2623 2624
	BT_DBG("scid 0x%4.4x flags 0x%2.2x result 0x%2.2x",
			scid, flags, result);
L
Linus Torvalds 已提交
2625

2626
	chan = l2cap_get_chan_by_scid(conn, scid);
2627
	if (!chan)
L
Linus Torvalds 已提交
2628 2629
		return 0;

2630 2631
	sk = chan->sk;

L
Linus Torvalds 已提交
2632 2633
	switch (result) {
	case L2CAP_CONF_SUCCESS:
2634
		l2cap_conf_rfc_get(chan, rsp->data, len);
L
Linus Torvalds 已提交
2635 2636 2637
		break;

	case L2CAP_CONF_UNACCEPT:
2638
		if (chan->num_conf_rsp <= L2CAP_CONF_MAX_CONF_RSP) {
2639 2640
			char req[64];

2641
			if (len > sizeof(req) - sizeof(struct l2cap_conf_req)) {
2642
				l2cap_send_disconn_req(conn, chan, ECONNRESET);
2643 2644 2645
				goto done;
			}

2646 2647
			/* throw out any old stored conf requests */
			result = L2CAP_CONF_SUCCESS;
2648 2649
			len = l2cap_parse_conf_rsp(chan, rsp->data, len,
								req, &result);
2650
			if (len < 0) {
2651
				l2cap_send_disconn_req(conn, chan, ECONNRESET);
2652 2653 2654 2655 2656
				goto done;
			}

			l2cap_send_cmd(conn, l2cap_get_ident(conn),
						L2CAP_CONF_REQ, len, req);
2657
			chan->num_conf_req++;
2658 2659 2660
			if (result != L2CAP_CONF_SUCCESS)
				goto done;
			break;
L
Linus Torvalds 已提交
2661 2662
		}

2663
	default:
2664
		sk->sk_err = ECONNRESET;
2665
		l2cap_chan_set_timer(chan, HZ * 5);
2666
		l2cap_send_disconn_req(conn, chan, ECONNRESET);
L
Linus Torvalds 已提交
2667 2668 2669 2670 2671 2672
		goto done;
	}

	if (flags & 0x01)
		goto done;

2673
	chan->conf_state |= L2CAP_CONF_INPUT_DONE;
L
Linus Torvalds 已提交
2674

2675
	if (chan->conf_state & L2CAP_CONF_OUTPUT_DONE) {
2676
		set_default_fcs(chan);
2677

L
Linus Torvalds 已提交
2678
		sk->sk_state = BT_CONNECTED;
2679 2680
		chan->next_tx_seq = 0;
		chan->expected_tx_seq = 0;
2681
		skb_queue_head_init(&chan->tx_q);
2682
		if (chan->mode ==  L2CAP_MODE_ERTM)
2683
			l2cap_ertm_init(chan);
2684

L
Linus Torvalds 已提交
2685 2686 2687 2688 2689 2690 2691 2692 2693 2694 2695 2696 2697
		l2cap_chan_ready(sk);
	}

done:
	bh_unlock_sock(sk);
	return 0;
}

static inline int l2cap_disconnect_req(struct l2cap_conn *conn, struct l2cap_cmd_hdr *cmd, u8 *data)
{
	struct l2cap_disconn_req *req = (struct l2cap_disconn_req *) data;
	struct l2cap_disconn_rsp rsp;
	u16 dcid, scid;
2698
	struct l2cap_chan *chan;
L
Linus Torvalds 已提交
2699 2700 2701 2702 2703 2704 2705
	struct sock *sk;

	scid = __le16_to_cpu(req->scid);
	dcid = __le16_to_cpu(req->dcid);

	BT_DBG("scid 0x%4.4x dcid 0x%4.4x", scid, dcid);

2706
	chan = l2cap_get_chan_by_scid(conn, dcid);
2707
	if (!chan)
L
Linus Torvalds 已提交
2708 2709
		return 0;

2710 2711
	sk = chan->sk;

2712 2713
	rsp.dcid = cpu_to_le16(chan->scid);
	rsp.scid = cpu_to_le16(chan->dcid);
L
Linus Torvalds 已提交
2714 2715 2716 2717
	l2cap_send_cmd(conn, cmd->ident, L2CAP_DISCONN_RSP, sizeof(rsp), &rsp);

	sk->sk_shutdown = SHUTDOWN_MASK;

2718 2719 2720
	/* don't delete l2cap channel if sk is owned by user */
	if (sock_owned_by_user(sk)) {
		sk->sk_state = BT_DISCONN;
2721 2722
		l2cap_chan_clear_timer(chan);
		l2cap_chan_set_timer(chan, HZ / 5);
2723 2724 2725 2726
		bh_unlock_sock(sk);
		return 0;
	}

2727
	l2cap_chan_del(chan, ECONNRESET);
L
Linus Torvalds 已提交
2728 2729 2730 2731 2732 2733 2734 2735 2736 2737
	bh_unlock_sock(sk);

	l2cap_sock_kill(sk);
	return 0;
}

static inline int l2cap_disconnect_rsp(struct l2cap_conn *conn, struct l2cap_cmd_hdr *cmd, u8 *data)
{
	struct l2cap_disconn_rsp *rsp = (struct l2cap_disconn_rsp *) data;
	u16 dcid, scid;
2738
	struct l2cap_chan *chan;
L
Linus Torvalds 已提交
2739 2740 2741 2742 2743 2744 2745
	struct sock *sk;

	scid = __le16_to_cpu(rsp->scid);
	dcid = __le16_to_cpu(rsp->dcid);

	BT_DBG("dcid 0x%4.4x scid 0x%4.4x", dcid, scid);

2746
	chan = l2cap_get_chan_by_scid(conn, scid);
2747
	if (!chan)
L
Linus Torvalds 已提交
2748 2749
		return 0;

2750 2751
	sk = chan->sk;

2752 2753 2754
	/* don't delete l2cap channel if sk is owned by user */
	if (sock_owned_by_user(sk)) {
		sk->sk_state = BT_DISCONN;
2755 2756
		l2cap_chan_clear_timer(chan);
		l2cap_chan_set_timer(chan, HZ / 5);
2757 2758 2759 2760
		bh_unlock_sock(sk);
		return 0;
	}

2761
	l2cap_chan_del(chan, 0);
L
Linus Torvalds 已提交
2762 2763 2764 2765 2766 2767 2768 2769 2770 2771 2772 2773 2774 2775 2776
	bh_unlock_sock(sk);

	l2cap_sock_kill(sk);
	return 0;
}

static inline int l2cap_information_req(struct l2cap_conn *conn, struct l2cap_cmd_hdr *cmd, u8 *data)
{
	struct l2cap_info_req *req = (struct l2cap_info_req *) data;
	u16 type;

	type = __le16_to_cpu(req->type);

	BT_DBG("type 0x%4.4x", type);

2777 2778
	if (type == L2CAP_IT_FEAT_MASK) {
		u8 buf[8];
2779
		u32 feat_mask = l2cap_feat_mask;
2780 2781 2782
		struct l2cap_info_rsp *rsp = (struct l2cap_info_rsp *) buf;
		rsp->type   = cpu_to_le16(L2CAP_IT_FEAT_MASK);
		rsp->result = cpu_to_le16(L2CAP_IR_SUCCESS);
2783
		if (!disable_ertm)
2784 2785
			feat_mask |= L2CAP_FEAT_ERTM | L2CAP_FEAT_STREAMING
							 | L2CAP_FEAT_FCS;
2786
		put_unaligned_le32(feat_mask, rsp->data);
2787 2788
		l2cap_send_cmd(conn, cmd->ident,
					L2CAP_INFO_RSP, sizeof(buf), buf);
2789 2790 2791 2792 2793 2794 2795 2796
	} else if (type == L2CAP_IT_FIXED_CHAN) {
		u8 buf[12];
		struct l2cap_info_rsp *rsp = (struct l2cap_info_rsp *) buf;
		rsp->type   = cpu_to_le16(L2CAP_IT_FIXED_CHAN);
		rsp->result = cpu_to_le16(L2CAP_IR_SUCCESS);
		memcpy(buf + 4, l2cap_fixed_chan, 8);
		l2cap_send_cmd(conn, cmd->ident,
					L2CAP_INFO_RSP, sizeof(buf), buf);
2797 2798 2799 2800 2801 2802 2803
	} else {
		struct l2cap_info_rsp rsp;
		rsp.type   = cpu_to_le16(type);
		rsp.result = cpu_to_le16(L2CAP_IR_NOTSUPP);
		l2cap_send_cmd(conn, cmd->ident,
					L2CAP_INFO_RSP, sizeof(rsp), &rsp);
	}
L
Linus Torvalds 已提交
2804 2805 2806 2807 2808 2809 2810 2811 2812 2813 2814 2815 2816 2817

	return 0;
}

static inline int l2cap_information_rsp(struct l2cap_conn *conn, struct l2cap_cmd_hdr *cmd, u8 *data)
{
	struct l2cap_info_rsp *rsp = (struct l2cap_info_rsp *) data;
	u16 type, result;

	type   = __le16_to_cpu(rsp->type);
	result = __le16_to_cpu(rsp->result);

	BT_DBG("type 0x%4.4x result 0x%2.2x", type, result);

2818 2819 2820 2821 2822
	/* L2CAP Info req/rsp are unbound to channels, add extra checks */
	if (cmd->ident != conn->info_ident ||
			conn->info_state & L2CAP_INFO_FEAT_MASK_REQ_DONE)
		return 0;

2823 2824
	del_timer(&conn->info_timer);

2825 2826 2827 2828 2829 2830 2831 2832 2833
	if (result != L2CAP_IR_SUCCESS) {
		conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_DONE;
		conn->info_ident = 0;

		l2cap_conn_start(conn);

		return 0;
	}

2834
	if (type == L2CAP_IT_FEAT_MASK) {
2835
		conn->feat_mask = get_unaligned_le32(rsp->data);
2836

2837
		if (conn->feat_mask & L2CAP_FEAT_FIXED_CHAN) {
2838 2839 2840 2841 2842 2843 2844 2845 2846 2847 2848 2849 2850 2851
			struct l2cap_info_req req;
			req.type = cpu_to_le16(L2CAP_IT_FIXED_CHAN);

			conn->info_ident = l2cap_get_ident(conn);

			l2cap_send_cmd(conn, conn->info_ident,
					L2CAP_INFO_REQ, sizeof(req), &req);
		} else {
			conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_DONE;
			conn->info_ident = 0;

			l2cap_conn_start(conn);
		}
	} else if (type == L2CAP_IT_FIXED_CHAN) {
2852
		conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_DONE;
2853
		conn->info_ident = 0;
2854 2855 2856

		l2cap_conn_start(conn);
	}
2857

L
Linus Torvalds 已提交
2858 2859 2860
	return 0;
}

2861
static inline int l2cap_check_conn_param(u16 min, u16 max, u16 latency,
2862 2863 2864 2865 2866 2867 2868 2869 2870 2871 2872 2873 2874 2875 2876 2877 2878 2879 2880 2881 2882 2883 2884 2885 2886 2887 2888
							u16 to_multiplier)
{
	u16 max_latency;

	if (min > max || min < 6 || max > 3200)
		return -EINVAL;

	if (to_multiplier < 10 || to_multiplier > 3200)
		return -EINVAL;

	if (max >= to_multiplier * 8)
		return -EINVAL;

	max_latency = (to_multiplier * 8 / max) - 1;
	if (latency > 499 || latency > max_latency)
		return -EINVAL;

	return 0;
}

static inline int l2cap_conn_param_update_req(struct l2cap_conn *conn,
					struct l2cap_cmd_hdr *cmd, u8 *data)
{
	struct hci_conn *hcon = conn->hcon;
	struct l2cap_conn_param_update_req *req;
	struct l2cap_conn_param_update_rsp rsp;
	u16 min, max, latency, to_multiplier, cmd_len;
2889
	int err;
2890 2891 2892 2893 2894 2895 2896 2897 2898

	if (!(hcon->link_mode & HCI_LM_MASTER))
		return -EINVAL;

	cmd_len = __le16_to_cpu(cmd->len);
	if (cmd_len != sizeof(struct l2cap_conn_param_update_req))
		return -EPROTO;

	req = (struct l2cap_conn_param_update_req *) data;
2899 2900
	min		= __le16_to_cpu(req->min);
	max		= __le16_to_cpu(req->max);
2901 2902 2903 2904 2905 2906 2907
	latency		= __le16_to_cpu(req->latency);
	to_multiplier	= __le16_to_cpu(req->to_multiplier);

	BT_DBG("min 0x%4.4x max 0x%4.4x latency: 0x%4.4x Timeout: 0x%4.4x",
						min, max, latency, to_multiplier);

	memset(&rsp, 0, sizeof(rsp));
2908 2909 2910

	err = l2cap_check_conn_param(min, max, latency, to_multiplier);
	if (err)
2911 2912 2913 2914 2915 2916 2917
		rsp.result = cpu_to_le16(L2CAP_CONN_PARAM_REJECTED);
	else
		rsp.result = cpu_to_le16(L2CAP_CONN_PARAM_ACCEPTED);

	l2cap_send_cmd(conn, cmd->ident, L2CAP_CONN_PARAM_UPDATE_RSP,
							sizeof(rsp), &rsp);

2918 2919 2920
	if (!err)
		hci_le_conn_update(hcon, min, max, latency, to_multiplier);

2921 2922 2923
	return 0;
}

2924 2925 2926 2927 2928 2929 2930 2931 2932 2933 2934 2935 2936 2937 2938 2939 2940 2941 2942 2943 2944 2945 2946 2947 2948 2949 2950 2951 2952 2953 2954 2955 2956 2957 2958 2959 2960 2961 2962 2963 2964 2965 2966 2967 2968 2969 2970 2971 2972 2973 2974 2975 2976 2977 2978 2979 2980 2981 2982 2983 2984 2985 2986 2987 2988 2989
static inline int l2cap_bredr_sig_cmd(struct l2cap_conn *conn,
			struct l2cap_cmd_hdr *cmd, u16 cmd_len, u8 *data)
{
	int err = 0;

	switch (cmd->code) {
	case L2CAP_COMMAND_REJ:
		l2cap_command_rej(conn, cmd, data);
		break;

	case L2CAP_CONN_REQ:
		err = l2cap_connect_req(conn, cmd, data);
		break;

	case L2CAP_CONN_RSP:
		err = l2cap_connect_rsp(conn, cmd, data);
		break;

	case L2CAP_CONF_REQ:
		err = l2cap_config_req(conn, cmd, cmd_len, data);
		break;

	case L2CAP_CONF_RSP:
		err = l2cap_config_rsp(conn, cmd, data);
		break;

	case L2CAP_DISCONN_REQ:
		err = l2cap_disconnect_req(conn, cmd, data);
		break;

	case L2CAP_DISCONN_RSP:
		err = l2cap_disconnect_rsp(conn, cmd, data);
		break;

	case L2CAP_ECHO_REQ:
		l2cap_send_cmd(conn, cmd->ident, L2CAP_ECHO_RSP, cmd_len, data);
		break;

	case L2CAP_ECHO_RSP:
		break;

	case L2CAP_INFO_REQ:
		err = l2cap_information_req(conn, cmd, data);
		break;

	case L2CAP_INFO_RSP:
		err = l2cap_information_rsp(conn, cmd, data);
		break;

	default:
		BT_ERR("Unknown BR/EDR signaling command 0x%2.2x", cmd->code);
		err = -EINVAL;
		break;
	}

	return err;
}

static inline int l2cap_le_sig_cmd(struct l2cap_conn *conn,
					struct l2cap_cmd_hdr *cmd, u8 *data)
{
	switch (cmd->code) {
	case L2CAP_COMMAND_REJ:
		return 0;

	case L2CAP_CONN_PARAM_UPDATE_REQ:
2990
		return l2cap_conn_param_update_req(conn, cmd, data);
2991 2992 2993 2994 2995 2996 2997 2998 2999 3000 3001 3002

	case L2CAP_CONN_PARAM_UPDATE_RSP:
		return 0;

	default:
		BT_ERR("Unknown LE signaling command 0x%2.2x", cmd->code);
		return -EINVAL;
	}
}

static inline void l2cap_sig_channel(struct l2cap_conn *conn,
							struct sk_buff *skb)
L
Linus Torvalds 已提交
3003 3004 3005 3006
{
	u8 *data = skb->data;
	int len = skb->len;
	struct l2cap_cmd_hdr cmd;
3007
	int err;
L
Linus Torvalds 已提交
3008 3009 3010 3011

	l2cap_raw_recv(conn, skb);

	while (len >= L2CAP_CMD_HDR_SIZE) {
3012
		u16 cmd_len;
L
Linus Torvalds 已提交
3013 3014 3015 3016
		memcpy(&cmd, data, L2CAP_CMD_HDR_SIZE);
		data += L2CAP_CMD_HDR_SIZE;
		len  -= L2CAP_CMD_HDR_SIZE;

3017
		cmd_len = le16_to_cpu(cmd.len);
L
Linus Torvalds 已提交
3018

3019
		BT_DBG("code 0x%2.2x len %d id 0x%2.2x", cmd.code, cmd_len, cmd.ident);
L
Linus Torvalds 已提交
3020

3021
		if (cmd_len > len || !cmd.ident) {
L
Linus Torvalds 已提交
3022 3023 3024 3025
			BT_DBG("corrupted command");
			break;
		}

3026 3027 3028 3029
		if (conn->hcon->type == LE_LINK)
			err = l2cap_le_sig_cmd(conn, &cmd, data);
		else
			err = l2cap_bredr_sig_cmd(conn, &cmd, cmd_len, data);
L
Linus Torvalds 已提交
3030 3031 3032

		if (err) {
			struct l2cap_cmd_rej rej;
3033 3034

			BT_ERR("Wrong link type (%d)", err);
L
Linus Torvalds 已提交
3035 3036

			/* FIXME: Map err to a valid reason */
3037
			rej.reason = cpu_to_le16(0);
L
Linus Torvalds 已提交
3038 3039 3040
			l2cap_send_cmd(conn, cmd.ident, L2CAP_COMMAND_REJ, sizeof(rej), &rej);
		}

3041 3042
		data += cmd_len;
		len  -= cmd_len;
L
Linus Torvalds 已提交
3043 3044 3045 3046 3047
	}

	kfree_skb(skb);
}

3048
static int l2cap_check_fcs(struct l2cap_chan *chan,  struct sk_buff *skb)
3049 3050 3051 3052
{
	u16 our_fcs, rcv_fcs;
	int hdr_size = L2CAP_HDR_SIZE + 2;

3053
	if (chan->fcs == L2CAP_FCS_CRC16) {
3054 3055 3056 3057 3058
		skb_trim(skb, skb->len - 2);
		rcv_fcs = get_unaligned_le16(skb->data + skb->len);
		our_fcs = crc16(0, skb->data - hdr_size, skb->len + hdr_size);

		if (our_fcs != rcv_fcs)
3059
			return -EBADMSG;
3060 3061 3062 3063
	}
	return 0;
}

3064
static inline void l2cap_send_i_or_rr_or_rnr(struct l2cap_chan *chan)
3065 3066 3067
{
	u16 control = 0;

3068
	chan->frames_sent = 0;
3069

3070
	control |= chan->buffer_seq << L2CAP_CTRL_REQSEQ_SHIFT;
3071

3072
	if (chan->conn_state & L2CAP_CONN_LOCAL_BUSY) {
3073
		control |= L2CAP_SUPER_RCV_NOT_READY;
3074 3075
		l2cap_send_sframe(chan, control);
		chan->conn_state |= L2CAP_CONN_RNR_SENT;
3076 3077
	}

3078 3079
	if (chan->conn_state & L2CAP_CONN_REMOTE_BUSY)
		l2cap_retransmit_frames(chan);
3080

3081
	l2cap_ertm_send(chan);
3082

3083
	if (!(chan->conn_state & L2CAP_CONN_LOCAL_BUSY) &&
3084
			chan->frames_sent == 0) {
3085
		control |= L2CAP_SUPER_RCV_READY;
3086
		l2cap_send_sframe(chan, control);
3087 3088 3089
	}
}

3090
static int l2cap_add_to_srej_queue(struct l2cap_chan *chan, struct sk_buff *skb, u8 tx_seq, u8 sar)
3091 3092
{
	struct sk_buff *next_skb;
3093
	int tx_seq_offset, next_tx_seq_offset;
3094 3095 3096 3097

	bt_cb(skb)->tx_seq = tx_seq;
	bt_cb(skb)->sar = sar;

3098
	next_skb = skb_peek(&chan->srej_q);
3099
	if (!next_skb) {
3100
		__skb_queue_tail(&chan->srej_q, skb);
3101
		return 0;
3102 3103
	}

3104
	tx_seq_offset = (tx_seq - chan->buffer_seq) % 64;
3105 3106 3107
	if (tx_seq_offset < 0)
		tx_seq_offset += 64;

3108
	do {
3109 3110 3111
		if (bt_cb(next_skb)->tx_seq == tx_seq)
			return -EINVAL;

3112
		next_tx_seq_offset = (bt_cb(next_skb)->tx_seq -
3113
						chan->buffer_seq) % 64;
3114 3115 3116 3117
		if (next_tx_seq_offset < 0)
			next_tx_seq_offset += 64;

		if (next_tx_seq_offset > tx_seq_offset) {
3118
			__skb_queue_before(&chan->srej_q, next_skb, skb);
3119
			return 0;
3120 3121
		}

3122
		if (skb_queue_is_last(&chan->srej_q, next_skb))
3123 3124
			break;

3125
	} while ((next_skb = skb_queue_next(&chan->srej_q, next_skb)));
3126

3127
	__skb_queue_tail(&chan->srej_q, skb);
3128 3129

	return 0;
3130 3131
}

3132
static int l2cap_ertm_reassembly_sdu(struct l2cap_chan *chan, struct sk_buff *skb, u16 control)
3133 3134
{
	struct sk_buff *_skb;
3135
	int err;
3136 3137 3138

	switch (control & L2CAP_CTRL_SAR) {
	case L2CAP_SDU_UNSEGMENTED:
3139
		if (chan->conn_state & L2CAP_CONN_SAR_SDU)
3140 3141
			goto drop;

3142
		return sock_queue_rcv_skb(chan->sk, skb);
3143 3144

	case L2CAP_SDU_START:
3145
		if (chan->conn_state & L2CAP_CONN_SAR_SDU)
3146 3147
			goto drop;

3148
		chan->sdu_len = get_unaligned_le16(skb->data);
3149

3150
		if (chan->sdu_len > chan->imtu)
3151 3152
			goto disconnect;

3153 3154
		chan->sdu = bt_skb_alloc(chan->sdu_len, GFP_ATOMIC);
		if (!chan->sdu)
3155 3156 3157 3158 3159 3160
			return -ENOMEM;

		/* pull sdu_len bytes only after alloc, because of Local Busy
		 * condition we have to be sure that this will be executed
		 * only once, i.e., when alloc does not fail */
		skb_pull(skb, 2);
3161

3162
		memcpy(skb_put(chan->sdu, skb->len), skb->data, skb->len);
3163

3164
		chan->conn_state |= L2CAP_CONN_SAR_SDU;
3165
		chan->partial_sdu_len = skb->len;
3166 3167 3168
		break;

	case L2CAP_SDU_CONTINUE:
3169
		if (!(chan->conn_state & L2CAP_CONN_SAR_SDU))
3170 3171
			goto disconnect;

3172
		if (!chan->sdu)
3173 3174
			goto disconnect;

3175 3176
		chan->partial_sdu_len += skb->len;
		if (chan->partial_sdu_len > chan->sdu_len)
3177 3178
			goto drop;

3179
		memcpy(skb_put(chan->sdu, skb->len), skb->data, skb->len);
3180

3181 3182 3183
		break;

	case L2CAP_SDU_END:
3184
		if (!(chan->conn_state & L2CAP_CONN_SAR_SDU))
3185 3186
			goto disconnect;

3187
		if (!chan->sdu)
3188 3189
			goto disconnect;

3190
		if (!(chan->conn_state & L2CAP_CONN_SAR_RETRY)) {
3191
			chan->partial_sdu_len += skb->len;
3192

3193
			if (chan->partial_sdu_len > chan->imtu)
3194
				goto drop;
3195

3196
			if (chan->partial_sdu_len != chan->sdu_len)
3197
				goto drop;
3198

3199
			memcpy(skb_put(chan->sdu, skb->len), skb->data, skb->len);
3200
		}
3201

3202
		_skb = skb_clone(chan->sdu, GFP_ATOMIC);
3203
		if (!_skb) {
3204
			chan->conn_state |= L2CAP_CONN_SAR_RETRY;
3205 3206 3207
			return -ENOMEM;
		}

3208
		err = sock_queue_rcv_skb(chan->sk, _skb);
3209
		if (err < 0) {
3210
			kfree_skb(_skb);
3211
			chan->conn_state |= L2CAP_CONN_SAR_RETRY;
3212 3213 3214
			return err;
		}

3215 3216
		chan->conn_state &= ~L2CAP_CONN_SAR_RETRY;
		chan->conn_state &= ~L2CAP_CONN_SAR_SDU;
3217

3218
		kfree_skb(chan->sdu);
3219 3220 3221 3222
		break;
	}

	kfree_skb(skb);
3223
	return 0;
3224 3225

drop:
3226 3227
	kfree_skb(chan->sdu);
	chan->sdu = NULL;
3228 3229

disconnect:
3230
	l2cap_send_disconn_req(chan->conn, chan, ECONNRESET);
3231 3232 3233 3234
	kfree_skb(skb);
	return 0;
}

3235
static int l2cap_try_push_rx_skb(struct l2cap_chan *chan)
3236 3237 3238 3239 3240
{
	struct sk_buff *skb;
	u16 control;
	int err;

3241
	while ((skb = skb_dequeue(&chan->busy_q))) {
3242
		control = bt_cb(skb)->sar << L2CAP_CTRL_SAR_SHIFT;
3243
		err = l2cap_ertm_reassembly_sdu(chan, skb, control);
3244
		if (err < 0) {
3245
			skb_queue_head(&chan->busy_q, skb);
3246 3247 3248
			return -EBUSY;
		}

3249
		chan->buffer_seq = (chan->buffer_seq + 1) % 64;
3250 3251
	}

3252
	if (!(chan->conn_state & L2CAP_CONN_RNR_SENT))
3253 3254
		goto done;

3255
	control = chan->buffer_seq << L2CAP_CTRL_REQSEQ_SHIFT;
3256
	control |= L2CAP_SUPER_RCV_READY | L2CAP_CTRL_POLL;
3257
	l2cap_send_sframe(chan, control);
3258
	chan->retry_count = 1;
3259

3260
	del_timer(&chan->retrans_timer);
3261 3262
	__mod_monitor_timer();

3263
	chan->conn_state |= L2CAP_CONN_WAIT_F;
3264 3265

done:
3266 3267
	chan->conn_state &= ~L2CAP_CONN_LOCAL_BUSY;
	chan->conn_state &= ~L2CAP_CONN_RNR_SENT;
3268

3269
	BT_DBG("chan %p, Exit local busy", chan);
3270 3271 3272 3273

	return 0;
}

3274 3275 3276
static void l2cap_busy_work(struct work_struct *work)
{
	DECLARE_WAITQUEUE(wait, current);
3277 3278 3279
	struct l2cap_chan *chan =
		container_of(work, struct l2cap_chan, busy_work);
	struct sock *sk = chan->sk;
3280 3281 3282 3283 3284
	int n_tries = 0, timeo = HZ/5, err;
	struct sk_buff *skb;

	lock_sock(sk);

3285
	add_wait_queue(sk_sleep(sk), &wait);
3286
	while ((skb = skb_peek(&chan->busy_q))) {
3287 3288 3289 3290
		set_current_state(TASK_INTERRUPTIBLE);

		if (n_tries++ > L2CAP_LOCAL_BUSY_TRIES) {
			err = -EBUSY;
3291
			l2cap_send_disconn_req(chan->conn, chan, EBUSY);
3292
			break;
3293 3294 3295 3296 3297 3298 3299
		}

		if (!timeo)
			timeo = HZ/5;

		if (signal_pending(current)) {
			err = sock_intr_errno(timeo);
3300
			break;
3301 3302 3303 3304 3305 3306 3307 3308
		}

		release_sock(sk);
		timeo = schedule_timeout(timeo);
		lock_sock(sk);

		err = sock_error(sk);
		if (err)
3309
			break;
3310

3311
		if (l2cap_try_push_rx_skb(chan) == 0)
3312 3313 3314 3315
			break;
	}

	set_current_state(TASK_RUNNING);
3316
	remove_wait_queue(sk_sleep(sk), &wait);
3317 3318 3319 3320

	release_sock(sk);
}

3321
static int l2cap_push_rx_skb(struct l2cap_chan *chan, struct sk_buff *skb, u16 control)
3322 3323 3324
{
	int sctrl, err;

3325
	if (chan->conn_state & L2CAP_CONN_LOCAL_BUSY) {
3326
		bt_cb(skb)->sar = control >> L2CAP_CTRL_SAR_SHIFT;
3327
		__skb_queue_tail(&chan->busy_q, skb);
3328
		return l2cap_try_push_rx_skb(chan);
3329 3330


3331 3332
	}

3333
	err = l2cap_ertm_reassembly_sdu(chan, skb, control);
3334
	if (err >= 0) {
3335
		chan->buffer_seq = (chan->buffer_seq + 1) % 64;
3336 3337 3338 3339
		return err;
	}

	/* Busy Condition */
3340
	BT_DBG("chan %p, Enter local busy", chan);
3341

3342
	chan->conn_state |= L2CAP_CONN_LOCAL_BUSY;
3343
	bt_cb(skb)->sar = control >> L2CAP_CTRL_SAR_SHIFT;
3344
	__skb_queue_tail(&chan->busy_q, skb);
3345

3346
	sctrl = chan->buffer_seq << L2CAP_CTRL_REQSEQ_SHIFT;
3347
	sctrl |= L2CAP_SUPER_RCV_NOT_READY;
3348
	l2cap_send_sframe(chan, sctrl);
3349

3350
	chan->conn_state |= L2CAP_CONN_RNR_SENT;
3351

3352
	del_timer(&chan->ack_timer);
3353

3354
	queue_work(_busy_wq, &chan->busy_work);
3355 3356 3357 3358

	return err;
}

3359
static int l2cap_streaming_reassembly_sdu(struct l2cap_chan *chan, struct sk_buff *skb, u16 control)
3360 3361 3362 3363
{
	struct sk_buff *_skb;
	int err = -EINVAL;

3364 3365 3366 3367 3368
	/*
	 * TODO: We have to notify the userland if some data is lost with the
	 * Streaming Mode.
	 */

3369 3370
	switch (control & L2CAP_CTRL_SAR) {
	case L2CAP_SDU_UNSEGMENTED:
3371
		if (chan->conn_state & L2CAP_CONN_SAR_SDU) {
3372
			kfree_skb(chan->sdu);
3373 3374 3375
			break;
		}

3376
		err = sock_queue_rcv_skb(chan->sk, skb);
3377 3378 3379 3380 3381 3382
		if (!err)
			return 0;

		break;

	case L2CAP_SDU_START:
3383
		if (chan->conn_state & L2CAP_CONN_SAR_SDU) {
3384
			kfree_skb(chan->sdu);
3385 3386 3387
			break;
		}

3388
		chan->sdu_len = get_unaligned_le16(skb->data);
3389 3390
		skb_pull(skb, 2);

3391
		if (chan->sdu_len > chan->imtu) {
3392 3393 3394 3395
			err = -EMSGSIZE;
			break;
		}

3396 3397
		chan->sdu = bt_skb_alloc(chan->sdu_len, GFP_ATOMIC);
		if (!chan->sdu) {
3398 3399 3400 3401
			err = -ENOMEM;
			break;
		}

3402
		memcpy(skb_put(chan->sdu, skb->len), skb->data, skb->len);
3403

3404
		chan->conn_state |= L2CAP_CONN_SAR_SDU;
3405
		chan->partial_sdu_len = skb->len;
3406 3407 3408 3409
		err = 0;
		break;

	case L2CAP_SDU_CONTINUE:
3410
		if (!(chan->conn_state & L2CAP_CONN_SAR_SDU))
3411 3412
			break;

3413
		memcpy(skb_put(chan->sdu, skb->len), skb->data, skb->len);
3414

3415 3416 3417
		chan->partial_sdu_len += skb->len;
		if (chan->partial_sdu_len > chan->sdu_len)
			kfree_skb(chan->sdu);
3418 3419 3420 3421 3422 3423
		else
			err = 0;

		break;

	case L2CAP_SDU_END:
3424
		if (!(chan->conn_state & L2CAP_CONN_SAR_SDU))
3425 3426
			break;

3427
		memcpy(skb_put(chan->sdu, skb->len), skb->data, skb->len);
3428

3429
		chan->conn_state &= ~L2CAP_CONN_SAR_SDU;
3430
		chan->partial_sdu_len += skb->len;
3431

3432
		if (chan->partial_sdu_len > chan->imtu)
3433 3434
			goto drop;

3435 3436
		if (chan->partial_sdu_len == chan->sdu_len) {
			_skb = skb_clone(chan->sdu, GFP_ATOMIC);
3437
			err = sock_queue_rcv_skb(chan->sk, _skb);
3438 3439 3440 3441 3442
			if (err < 0)
				kfree_skb(_skb);
		}
		err = 0;

3443
drop:
3444
		kfree_skb(chan->sdu);
3445 3446 3447 3448 3449 3450 3451
		break;
	}

	kfree_skb(skb);
	return err;
}

3452
static void l2cap_check_srej_gap(struct l2cap_chan *chan, u8 tx_seq)
3453 3454
{
	struct sk_buff *skb;
3455
	u16 control;
3456

3457
	while ((skb = skb_peek(&chan->srej_q))) {
3458 3459 3460
		if (bt_cb(skb)->tx_seq != tx_seq)
			break;

3461
		skb = skb_dequeue(&chan->srej_q);
3462
		control = bt_cb(skb)->sar << L2CAP_CTRL_SAR_SHIFT;
3463
		l2cap_ertm_reassembly_sdu(chan, skb, control);
3464 3465
		chan->buffer_seq_srej =
			(chan->buffer_seq_srej + 1) % 64;
3466
		tx_seq = (tx_seq + 1) % 64;
3467 3468 3469
	}
}

3470
static void l2cap_resend_srejframe(struct l2cap_chan *chan, u8 tx_seq)
3471 3472 3473 3474
{
	struct srej_list *l, *tmp;
	u16 control;

3475
	list_for_each_entry_safe(l, tmp, &chan->srej_l, list) {
3476 3477 3478 3479 3480 3481 3482
		if (l->tx_seq == tx_seq) {
			list_del(&l->list);
			kfree(l);
			return;
		}
		control = L2CAP_SUPER_SELECT_REJECT;
		control |= l->tx_seq << L2CAP_CTRL_REQSEQ_SHIFT;
3483
		l2cap_send_sframe(chan, control);
3484
		list_del(&l->list);
3485
		list_add_tail(&l->list, &chan->srej_l);
3486 3487 3488
	}
}

3489
static void l2cap_send_srejframe(struct l2cap_chan *chan, u8 tx_seq)
3490 3491 3492 3493
{
	struct srej_list *new;
	u16 control;

3494
	while (tx_seq != chan->expected_tx_seq) {
3495
		control = L2CAP_SUPER_SELECT_REJECT;
3496
		control |= chan->expected_tx_seq << L2CAP_CTRL_REQSEQ_SHIFT;
3497
		l2cap_send_sframe(chan, control);
3498 3499

		new = kzalloc(sizeof(struct srej_list), GFP_ATOMIC);
3500 3501
		new->tx_seq = chan->expected_tx_seq;
		chan->expected_tx_seq = (chan->expected_tx_seq + 1) % 64;
3502
		list_add_tail(&new->list, &chan->srej_l);
3503
	}
3504
	chan->expected_tx_seq = (chan->expected_tx_seq + 1) % 64;
3505 3506
}

3507
static inline int l2cap_data_channel_iframe(struct l2cap_chan *chan, u16 rx_control, struct sk_buff *skb)
3508 3509
{
	u8 tx_seq = __get_txseq(rx_control);
3510
	u8 req_seq = __get_reqseq(rx_control);
3511
	u8 sar = rx_control >> L2CAP_CTRL_SAR_SHIFT;
3512
	int tx_seq_offset, expected_tx_seq_offset;
3513
	int num_to_ack = (chan->tx_win/6) + 1;
3514 3515
	int err = 0;

3516 3517
	BT_DBG("chan %p len %d tx_seq %d rx_control 0x%4.4x", chan, skb->len,
							tx_seq, rx_control);
3518

3519
	if (L2CAP_CTRL_FINAL & rx_control &&
3520
			chan->conn_state & L2CAP_CONN_WAIT_F) {
3521
		del_timer(&chan->monitor_timer);
3522
		if (chan->unacked_frames > 0)
3523
			__mod_retrans_timer();
3524
		chan->conn_state &= ~L2CAP_CONN_WAIT_F;
3525 3526
	}

3527 3528
	chan->expected_ack_seq = req_seq;
	l2cap_drop_acked_frames(chan);
3529

3530
	if (tx_seq == chan->expected_tx_seq)
3531
		goto expected;
3532

3533
	tx_seq_offset = (tx_seq - chan->buffer_seq) % 64;
3534 3535 3536 3537
	if (tx_seq_offset < 0)
		tx_seq_offset += 64;

	/* invalid tx_seq */
3538
	if (tx_seq_offset >= chan->tx_win) {
3539
		l2cap_send_disconn_req(chan->conn, chan, ECONNRESET);
3540 3541 3542
		goto drop;
	}

3543
	if (chan->conn_state == L2CAP_CONN_LOCAL_BUSY)
3544 3545
		goto drop;

3546
	if (chan->conn_state & L2CAP_CONN_SREJ_SENT) {
3547
		struct srej_list *first;
3548

3549
		first = list_first_entry(&chan->srej_l,
3550 3551
				struct srej_list, list);
		if (tx_seq == first->tx_seq) {
3552
			l2cap_add_to_srej_queue(chan, skb, tx_seq, sar);
3553
			l2cap_check_srej_gap(chan, tx_seq);
3554 3555 3556 3557

			list_del(&first->list);
			kfree(first);

3558
			if (list_empty(&chan->srej_l)) {
3559
				chan->buffer_seq = chan->buffer_seq_srej;
3560 3561
				chan->conn_state &= ~L2CAP_CONN_SREJ_SENT;
				l2cap_send_ack(chan);
3562
				BT_DBG("chan %p, Exit SREJ_SENT", chan);
3563 3564 3565
			}
		} else {
			struct srej_list *l;
3566 3567

			/* duplicated tx_seq */
3568
			if (l2cap_add_to_srej_queue(chan, skb, tx_seq, sar) < 0)
3569
				goto drop;
3570

3571
			list_for_each_entry(l, &chan->srej_l, list) {
3572
				if (l->tx_seq == tx_seq) {
3573
					l2cap_resend_srejframe(chan, tx_seq);
3574 3575 3576
					return 0;
				}
			}
3577
			l2cap_send_srejframe(chan, tx_seq);
3578 3579
		}
	} else {
3580
		expected_tx_seq_offset =
3581
			(chan->expected_tx_seq - chan->buffer_seq) % 64;
3582 3583 3584 3585 3586 3587 3588
		if (expected_tx_seq_offset < 0)
			expected_tx_seq_offset += 64;

		/* duplicated tx_seq */
		if (tx_seq_offset < expected_tx_seq_offset)
			goto drop;

3589
		chan->conn_state |= L2CAP_CONN_SREJ_SENT;
3590

3591
		BT_DBG("chan %p, Enter SREJ", chan);
3592

3593
		INIT_LIST_HEAD(&chan->srej_l);
3594
		chan->buffer_seq_srej = chan->buffer_seq;
3595

3596 3597
		__skb_queue_head_init(&chan->srej_q);
		__skb_queue_head_init(&chan->busy_q);
3598
		l2cap_add_to_srej_queue(chan, skb, tx_seq, sar);
3599

3600
		chan->conn_state |= L2CAP_CONN_SEND_PBIT;
3601

3602
		l2cap_send_srejframe(chan, tx_seq);
3603

3604
		del_timer(&chan->ack_timer);
3605
	}
3606 3607
	return 0;

3608
expected:
3609
	chan->expected_tx_seq = (chan->expected_tx_seq + 1) % 64;
3610

3611
	if (chan->conn_state & L2CAP_CONN_SREJ_SENT) {
3612 3613
		bt_cb(skb)->tx_seq = tx_seq;
		bt_cb(skb)->sar = sar;
3614
		__skb_queue_tail(&chan->srej_q, skb);
3615 3616 3617
		return 0;
	}

3618
	err = l2cap_push_rx_skb(chan, skb, rx_control);
3619 3620 3621
	if (err < 0)
		return 0;

3622
	if (rx_control & L2CAP_CTRL_FINAL) {
3623 3624
		if (chan->conn_state & L2CAP_CONN_REJ_ACT)
			chan->conn_state &= ~L2CAP_CONN_REJ_ACT;
3625
		else
3626
			l2cap_retransmit_frames(chan);
3627 3628
	}

3629 3630
	__mod_ack_timer();

3631 3632
	chan->num_acked = (chan->num_acked + 1) % num_to_ack;
	if (chan->num_acked == num_to_ack - 1)
3633
		l2cap_send_ack(chan);
3634

3635
	return 0;
3636 3637 3638 3639

drop:
	kfree_skb(skb);
	return 0;
3640 3641
}

3642
static inline void l2cap_data_channel_rrframe(struct l2cap_chan *chan, u16 rx_control)
3643
{
3644
	BT_DBG("chan %p, req_seq %d ctrl 0x%4.4x", chan, __get_reqseq(rx_control),
3645 3646
						rx_control);

3647 3648
	chan->expected_ack_seq = __get_reqseq(rx_control);
	l2cap_drop_acked_frames(chan);
3649

3650
	if (rx_control & L2CAP_CTRL_POLL) {
3651 3652 3653
		chan->conn_state |= L2CAP_CONN_SEND_FBIT;
		if (chan->conn_state & L2CAP_CONN_SREJ_SENT) {
			if ((chan->conn_state & L2CAP_CONN_REMOTE_BUSY) &&
3654
					(chan->unacked_frames > 0))
3655 3656
				__mod_retrans_timer();

3657 3658
			chan->conn_state &= ~L2CAP_CONN_REMOTE_BUSY;
			l2cap_send_srejtail(chan);
3659
		} else {
3660
			l2cap_send_i_or_rr_or_rnr(chan);
3661
		}
3662

3663
	} else if (rx_control & L2CAP_CTRL_FINAL) {
3664
		chan->conn_state &= ~L2CAP_CONN_REMOTE_BUSY;
3665

3666 3667
		if (chan->conn_state & L2CAP_CONN_REJ_ACT)
			chan->conn_state &= ~L2CAP_CONN_REJ_ACT;
3668
		else
3669
			l2cap_retransmit_frames(chan);
3670

3671
	} else {
3672
		if ((chan->conn_state & L2CAP_CONN_REMOTE_BUSY) &&
3673
				(chan->unacked_frames > 0))
3674
			__mod_retrans_timer();
3675

3676 3677 3678
		chan->conn_state &= ~L2CAP_CONN_REMOTE_BUSY;
		if (chan->conn_state & L2CAP_CONN_SREJ_SENT)
			l2cap_send_ack(chan);
3679
		else
3680
			l2cap_ertm_send(chan);
3681 3682
	}
}
3683

3684
static inline void l2cap_data_channel_rejframe(struct l2cap_chan *chan, u16 rx_control)
3685 3686
{
	u8 tx_seq = __get_reqseq(rx_control);
3687

3688
	BT_DBG("chan %p, req_seq %d ctrl 0x%4.4x", chan, tx_seq, rx_control);
3689

3690
	chan->conn_state &= ~L2CAP_CONN_REMOTE_BUSY;
3691

3692 3693
	chan->expected_ack_seq = tx_seq;
	l2cap_drop_acked_frames(chan);
3694 3695

	if (rx_control & L2CAP_CTRL_FINAL) {
3696 3697
		if (chan->conn_state & L2CAP_CONN_REJ_ACT)
			chan->conn_state &= ~L2CAP_CONN_REJ_ACT;
3698
		else
3699
			l2cap_retransmit_frames(chan);
3700
	} else {
3701
		l2cap_retransmit_frames(chan);
3702

3703 3704
		if (chan->conn_state & L2CAP_CONN_WAIT_F)
			chan->conn_state |= L2CAP_CONN_REJ_ACT;
3705 3706
	}
}
3707
static inline void l2cap_data_channel_srejframe(struct l2cap_chan *chan, u16 rx_control)
3708 3709
{
	u8 tx_seq = __get_reqseq(rx_control);
3710

3711
	BT_DBG("chan %p, req_seq %d ctrl 0x%4.4x", chan, tx_seq, rx_control);
3712

3713
	chan->conn_state &= ~L2CAP_CONN_REMOTE_BUSY;
3714

3715
	if (rx_control & L2CAP_CTRL_POLL) {
3716 3717
		chan->expected_ack_seq = tx_seq;
		l2cap_drop_acked_frames(chan);
3718

3719 3720
		chan->conn_state |= L2CAP_CONN_SEND_FBIT;
		l2cap_retransmit_one_frame(chan, tx_seq);
3721

3722
		l2cap_ertm_send(chan);
3723

3724
		if (chan->conn_state & L2CAP_CONN_WAIT_F) {
3725
			chan->srej_save_reqseq = tx_seq;
3726
			chan->conn_state |= L2CAP_CONN_SREJ_ACT;
3727
		}
3728
	} else if (rx_control & L2CAP_CTRL_FINAL) {
3729
		if ((chan->conn_state & L2CAP_CONN_SREJ_ACT) &&
3730
				chan->srej_save_reqseq == tx_seq)
3731
			chan->conn_state &= ~L2CAP_CONN_SREJ_ACT;
3732
		else
3733
			l2cap_retransmit_one_frame(chan, tx_seq);
3734
	} else {
3735 3736
		l2cap_retransmit_one_frame(chan, tx_seq);
		if (chan->conn_state & L2CAP_CONN_WAIT_F) {
3737
			chan->srej_save_reqseq = tx_seq;
3738
			chan->conn_state |= L2CAP_CONN_SREJ_ACT;
3739
		}
3740 3741 3742
	}
}

3743
static inline void l2cap_data_channel_rnrframe(struct l2cap_chan *chan, u16 rx_control)
3744 3745 3746
{
	u8 tx_seq = __get_reqseq(rx_control);

3747
	BT_DBG("chan %p, req_seq %d ctrl 0x%4.4x", chan, tx_seq, rx_control);
3748

3749
	chan->conn_state |= L2CAP_CONN_REMOTE_BUSY;
3750 3751
	chan->expected_ack_seq = tx_seq;
	l2cap_drop_acked_frames(chan);
3752

3753
	if (rx_control & L2CAP_CTRL_POLL)
3754
		chan->conn_state |= L2CAP_CONN_SEND_FBIT;
3755

3756
	if (!(chan->conn_state & L2CAP_CONN_SREJ_SENT)) {
3757
		del_timer(&chan->retrans_timer);
3758
		if (rx_control & L2CAP_CTRL_POLL)
3759
			l2cap_send_rr_or_rnr(chan, L2CAP_CTRL_FINAL);
3760
		return;
3761
	}
3762 3763

	if (rx_control & L2CAP_CTRL_POLL)
3764
		l2cap_send_srejtail(chan);
3765
	else
3766
		l2cap_send_sframe(chan, L2CAP_SUPER_RCV_READY);
3767 3768
}

3769
static inline int l2cap_data_channel_sframe(struct l2cap_chan *chan, u16 rx_control, struct sk_buff *skb)
3770
{
3771
	BT_DBG("chan %p rx_control 0x%4.4x len %d", chan, rx_control, skb->len);
3772

3773
	if (L2CAP_CTRL_FINAL & rx_control &&
3774
			chan->conn_state & L2CAP_CONN_WAIT_F) {
3775
		del_timer(&chan->monitor_timer);
3776
		if (chan->unacked_frames > 0)
3777
			__mod_retrans_timer();
3778
		chan->conn_state &= ~L2CAP_CONN_WAIT_F;
3779 3780 3781 3782
	}

	switch (rx_control & L2CAP_CTRL_SUPERVISE) {
	case L2CAP_SUPER_RCV_READY:
3783
		l2cap_data_channel_rrframe(chan, rx_control);
3784 3785
		break;

3786
	case L2CAP_SUPER_REJECT:
3787
		l2cap_data_channel_rejframe(chan, rx_control);
3788
		break;
3789

3790
	case L2CAP_SUPER_SELECT_REJECT:
3791
		l2cap_data_channel_srejframe(chan, rx_control);
3792 3793 3794
		break;

	case L2CAP_SUPER_RCV_NOT_READY:
3795
		l2cap_data_channel_rnrframe(chan, rx_control);
3796 3797 3798
		break;
	}

3799
	kfree_skb(skb);
3800 3801 3802
	return 0;
}

3803 3804
static int l2cap_ertm_data_rcv(struct sock *sk, struct sk_buff *skb)
{
3805
	struct l2cap_chan *chan = l2cap_pi(sk)->chan;
3806 3807 3808 3809 3810 3811 3812 3813 3814 3815 3816 3817 3818
	u16 control;
	u8 req_seq;
	int len, next_tx_seq_offset, req_seq_offset;

	control = get_unaligned_le16(skb->data);
	skb_pull(skb, 2);
	len = skb->len;

	/*
	 * We can just drop the corrupted I-frame here.
	 * Receiver will miss it and start proper recovery
	 * procedures and ask retransmission.
	 */
3819
	if (l2cap_check_fcs(chan, skb))
3820 3821 3822 3823 3824
		goto drop;

	if (__is_sar_start(control) && __is_iframe(control))
		len -= 2;

3825
	if (chan->fcs == L2CAP_FCS_CRC16)
3826 3827
		len -= 2;

3828
	if (len > chan->mps) {
3829
		l2cap_send_disconn_req(chan->conn, chan, ECONNRESET);
3830 3831 3832 3833
		goto drop;
	}

	req_seq = __get_reqseq(control);
3834
	req_seq_offset = (req_seq - chan->expected_ack_seq) % 64;
3835 3836 3837 3838
	if (req_seq_offset < 0)
		req_seq_offset += 64;

	next_tx_seq_offset =
3839
		(chan->next_tx_seq - chan->expected_ack_seq) % 64;
3840 3841 3842 3843 3844
	if (next_tx_seq_offset < 0)
		next_tx_seq_offset += 64;

	/* check for invalid req-seq */
	if (req_seq_offset > next_tx_seq_offset) {
3845
		l2cap_send_disconn_req(chan->conn, chan, ECONNRESET);
3846 3847 3848 3849 3850
		goto drop;
	}

	if (__is_iframe(control)) {
		if (len < 0) {
3851
			l2cap_send_disconn_req(chan->conn, chan, ECONNRESET);
3852 3853 3854
			goto drop;
		}

3855
		l2cap_data_channel_iframe(chan, control, skb);
3856 3857 3858
	} else {
		if (len != 0) {
			BT_ERR("%d", len);
3859
			l2cap_send_disconn_req(chan->conn, chan, ECONNRESET);
3860 3861 3862
			goto drop;
		}

3863
		l2cap_data_channel_sframe(chan, control, skb);
3864 3865 3866 3867 3868 3869 3870 3871 3872
	}

	return 0;

drop:
	kfree_skb(skb);
	return 0;
}

L
Linus Torvalds 已提交
3873 3874
static inline int l2cap_data_channel(struct l2cap_conn *conn, u16 cid, struct sk_buff *skb)
{
3875
	struct l2cap_chan *chan;
3876
	struct sock *sk = NULL;
3877
	u16 control;
3878 3879
	u8 tx_seq;
	int len;
L
Linus Torvalds 已提交
3880

3881
	chan = l2cap_get_chan_by_scid(conn, cid);
3882
	if (!chan) {
L
Linus Torvalds 已提交
3883 3884 3885 3886
		BT_DBG("unknown cid 0x%4.4x", cid);
		goto drop;
	}

3887
	sk = chan->sk;
3888

3889
	BT_DBG("chan %p, len %d", chan, skb->len);
L
Linus Torvalds 已提交
3890 3891 3892 3893

	if (sk->sk_state != BT_CONNECTED)
		goto drop;

3894
	switch (chan->mode) {
3895 3896 3897 3898 3899
	case L2CAP_MODE_BASIC:
		/* If socket recv buffers overflows we drop data here
		 * which is *bad* because L2CAP has to be reliable.
		 * But we don't have any other choice. L2CAP doesn't
		 * provide flow control mechanism. */
L
Linus Torvalds 已提交
3900

3901
		if (chan->imtu < skb->len)
3902
			goto drop;
L
Linus Torvalds 已提交
3903

3904 3905 3906 3907 3908
		if (!sock_queue_rcv_skb(sk, skb))
			goto done;
		break;

	case L2CAP_MODE_ERTM:
3909 3910
		if (!sock_owned_by_user(sk)) {
			l2cap_ertm_data_rcv(sk, skb);
3911
		} else {
3912
			if (sk_add_backlog(sk, skb))
3913 3914
				goto drop;
		}
3915

3916
		goto done;
3917

3918 3919 3920 3921 3922
	case L2CAP_MODE_STREAMING:
		control = get_unaligned_le16(skb->data);
		skb_pull(skb, 2);
		len = skb->len;

3923
		if (l2cap_check_fcs(chan, skb))
3924 3925
			goto drop;

3926 3927 3928
		if (__is_sar_start(control))
			len -= 2;

3929
		if (chan->fcs == L2CAP_FCS_CRC16)
3930 3931
			len -= 2;

3932
		if (len > chan->mps || len < 0 || __is_sframe(control))
3933 3934 3935 3936
			goto drop;

		tx_seq = __get_txseq(control);

3937 3938
		if (chan->expected_tx_seq == tx_seq)
			chan->expected_tx_seq = (chan->expected_tx_seq + 1) % 64;
3939
		else
3940
			chan->expected_tx_seq = (tx_seq + 1) % 64;
3941

3942
		l2cap_streaming_reassembly_sdu(chan, skb, control);
3943 3944 3945

		goto done;

3946
	default:
3947
		BT_DBG("chan %p: bad mode 0x%2.2x", chan, chan->mode);
3948 3949
		break;
	}
L
Linus Torvalds 已提交
3950 3951 3952 3953 3954

drop:
	kfree_skb(skb);

done:
3955 3956 3957
	if (sk)
		bh_unlock_sock(sk);

L
Linus Torvalds 已提交
3958 3959 3960
	return 0;
}

3961
static inline int l2cap_conless_channel(struct l2cap_conn *conn, __le16 psm, struct sk_buff *skb)
L
Linus Torvalds 已提交
3962
{
3963
	struct sock *sk = NULL;
3964
	struct l2cap_chan *chan;
L
Linus Torvalds 已提交
3965

3966 3967
	chan = l2cap_global_chan_by_psm(0, psm, conn->src);
	if (!chan)
L
Linus Torvalds 已提交
3968 3969
		goto drop;

3970 3971
	sk = chan->sk;

3972 3973
	bh_lock_sock(sk);

L
Linus Torvalds 已提交
3974 3975 3976 3977 3978
	BT_DBG("sk %p, len %d", sk, skb->len);

	if (sk->sk_state != BT_BOUND && sk->sk_state != BT_CONNECTED)
		goto drop;

3979
	if (l2cap_pi(sk)->chan->imtu < skb->len)
L
Linus Torvalds 已提交
3980 3981 3982 3983 3984 3985 3986 3987 3988
		goto drop;

	if (!sock_queue_rcv_skb(sk, skb))
		goto done;

drop:
	kfree_skb(skb);

done:
3989 3990
	if (sk)
		bh_unlock_sock(sk);
L
Linus Torvalds 已提交
3991 3992 3993
	return 0;
}

3994 3995
static inline int l2cap_att_channel(struct l2cap_conn *conn, __le16 cid, struct sk_buff *skb)
{
3996
	struct sock *sk = NULL;
3997
	struct l2cap_chan *chan;
3998

3999 4000
	chan = l2cap_global_chan_by_scid(0, cid, conn->src);
	if (!chan)
4001 4002
		goto drop;

4003 4004
	sk = chan->sk;

4005 4006 4007 4008 4009 4010 4011
	bh_lock_sock(sk);

	BT_DBG("sk %p, len %d", sk, skb->len);

	if (sk->sk_state != BT_BOUND && sk->sk_state != BT_CONNECTED)
		goto drop;

4012
	if (l2cap_pi(sk)->chan->imtu < skb->len)
4013 4014 4015 4016 4017 4018 4019 4020 4021 4022 4023 4024 4025 4026
		goto drop;

	if (!sock_queue_rcv_skb(sk, skb))
		goto done;

drop:
	kfree_skb(skb);

done:
	if (sk)
		bh_unlock_sock(sk);
	return 0;
}

L
Linus Torvalds 已提交
4027 4028 4029
static void l2cap_recv_frame(struct l2cap_conn *conn, struct sk_buff *skb)
{
	struct l2cap_hdr *lh = (void *) skb->data;
4030 4031
	u16 cid, len;
	__le16 psm;
L
Linus Torvalds 已提交
4032 4033 4034 4035 4036

	skb_pull(skb, L2CAP_HDR_SIZE);
	cid = __le16_to_cpu(lh->cid);
	len = __le16_to_cpu(lh->len);

4037 4038 4039 4040 4041
	if (len != skb->len) {
		kfree_skb(skb);
		return;
	}

L
Linus Torvalds 已提交
4042 4043 4044
	BT_DBG("len %d, cid 0x%4.4x", len, cid);

	switch (cid) {
4045
	case L2CAP_CID_LE_SIGNALING:
4046
	case L2CAP_CID_SIGNALING:
L
Linus Torvalds 已提交
4047 4048 4049
		l2cap_sig_channel(conn, skb);
		break;

4050
	case L2CAP_CID_CONN_LESS:
4051
		psm = get_unaligned_le16(skb->data);
L
Linus Torvalds 已提交
4052 4053 4054 4055
		skb_pull(skb, 2);
		l2cap_conless_channel(conn, psm, skb);
		break;

4056 4057 4058 4059
	case L2CAP_CID_LE_DATA:
		l2cap_att_channel(conn, cid, skb);
		break;

L
Linus Torvalds 已提交
4060 4061 4062 4063 4064 4065 4066 4067 4068 4069 4070
	default:
		l2cap_data_channel(conn, cid, skb);
		break;
	}
}

/* ---- L2CAP interface with lower layer (HCI) ---- */

static int l2cap_connect_ind(struct hci_dev *hdev, bdaddr_t *bdaddr, u8 type)
{
	int exact = 0, lm1 = 0, lm2 = 0;
4071
	struct l2cap_chan *c;
L
Linus Torvalds 已提交
4072 4073

	if (type != ACL_LINK)
4074
		return -EINVAL;
L
Linus Torvalds 已提交
4075 4076 4077 4078

	BT_DBG("hdev %s, bdaddr %s", hdev->name, batostr(bdaddr));

	/* Find listening sockets and check their link_mode */
4079 4080 4081
	read_lock(&chan_list_lock);
	list_for_each_entry(c, &chan_list, global_l) {
		struct sock *sk = c->sk;
4082

L
Linus Torvalds 已提交
4083 4084 4085 4086
		if (sk->sk_state != BT_LISTEN)
			continue;

		if (!bacmp(&bt_sk(sk)->src, &hdev->bdaddr)) {
4087
			lm1 |= HCI_LM_ACCEPT;
4088
			if (c->role_switch)
4089
				lm1 |= HCI_LM_MASTER;
L
Linus Torvalds 已提交
4090
			exact++;
4091 4092
		} else if (!bacmp(&bt_sk(sk)->src, BDADDR_ANY)) {
			lm2 |= HCI_LM_ACCEPT;
4093
			if (c->role_switch)
4094 4095
				lm2 |= HCI_LM_MASTER;
		}
L
Linus Torvalds 已提交
4096
	}
4097
	read_unlock(&chan_list_lock);
L
Linus Torvalds 已提交
4098 4099 4100 4101 4102 4103

	return exact ? lm1 : lm2;
}

static int l2cap_connect_cfm(struct hci_conn *hcon, u8 status)
{
4104 4105
	struct l2cap_conn *conn;

L
Linus Torvalds 已提交
4106 4107
	BT_DBG("hcon %p bdaddr %s status %d", hcon, batostr(&hcon->dst), status);

4108
	if (!(hcon->type == ACL_LINK || hcon->type == LE_LINK))
4109
		return -EINVAL;
L
Linus Torvalds 已提交
4110 4111 4112 4113 4114

	if (!status) {
		conn = l2cap_conn_add(hcon, status);
		if (conn)
			l2cap_conn_ready(conn);
4115
	} else
L
Linus Torvalds 已提交
4116 4117 4118 4119 4120
		l2cap_conn_del(hcon, bt_err(status));

	return 0;
}

4121 4122 4123 4124 4125 4126 4127 4128 4129 4130 4131 4132 4133
static int l2cap_disconn_ind(struct hci_conn *hcon)
{
	struct l2cap_conn *conn = hcon->l2cap_data;

	BT_DBG("hcon %p", hcon);

	if (hcon->type != ACL_LINK || !conn)
		return 0x13;

	return conn->disc_reason;
}

static int l2cap_disconn_cfm(struct hci_conn *hcon, u8 reason)
L
Linus Torvalds 已提交
4134 4135 4136
{
	BT_DBG("hcon %p reason %d", hcon, reason);

4137
	if (!(hcon->type == ACL_LINK || hcon->type == LE_LINK))
4138
		return -EINVAL;
L
Linus Torvalds 已提交
4139 4140

	l2cap_conn_del(hcon, bt_err(reason));
4141

L
Linus Torvalds 已提交
4142 4143 4144
	return 0;
}

4145
static inline void l2cap_check_encryption(struct l2cap_chan *chan, u8 encrypt)
4146
{
4147
	if (chan->chan_type != L2CAP_CHAN_CONN_ORIENTED)
4148 4149
		return;

4150
	if (encrypt == 0x00) {
4151
		if (chan->sec_level == BT_SECURITY_MEDIUM) {
4152 4153
			l2cap_chan_clear_timer(chan);
			l2cap_chan_set_timer(chan, HZ * 5);
4154
		} else if (chan->sec_level == BT_SECURITY_HIGH)
4155
			l2cap_chan_close(chan, ECONNREFUSED);
4156
	} else {
4157
		if (chan->sec_level == BT_SECURITY_MEDIUM)
4158
			l2cap_chan_clear_timer(chan);
4159 4160 4161
	}
}

4162
static int l2cap_security_cfm(struct hci_conn *hcon, u8 status, u8 encrypt)
L
Linus Torvalds 已提交
4163
{
4164
	struct l2cap_conn *conn = hcon->l2cap_data;
4165
	struct l2cap_chan *chan;
L
Linus Torvalds 已提交
4166

4167
	if (!conn)
L
Linus Torvalds 已提交
4168
		return 0;
4169

L
Linus Torvalds 已提交
4170 4171
	BT_DBG("conn %p", conn);

4172
	read_lock(&conn->chan_lock);
L
Linus Torvalds 已提交
4173

4174
	list_for_each_entry(chan, &conn->chan_l, list) {
4175
		struct sock *sk = chan->sk;
4176

L
Linus Torvalds 已提交
4177 4178
		bh_lock_sock(sk);

4179
		if (chan->conf_state & L2CAP_CONF_CONNECT_PEND) {
4180 4181 4182 4183
			bh_unlock_sock(sk);
			continue;
		}

4184
		if (!status && (sk->sk_state == BT_CONNECTED ||
4185
						sk->sk_state == BT_CONFIG)) {
4186
			l2cap_check_encryption(chan, encrypt);
4187 4188 4189 4190
			bh_unlock_sock(sk);
			continue;
		}

4191 4192 4193
		if (sk->sk_state == BT_CONNECT) {
			if (!status) {
				struct l2cap_conn_req req;
4194 4195
				req.scid = cpu_to_le16(chan->scid);
				req.psm  = chan->psm;
L
Linus Torvalds 已提交
4196

4197
				chan->ident = l2cap_get_ident(conn);
4198
				chan->conf_state |= L2CAP_CONF_CONNECT_PEND;
L
Linus Torvalds 已提交
4199

4200
				l2cap_send_cmd(conn, chan->ident,
4201 4202
					L2CAP_CONN_REQ, sizeof(req), &req);
			} else {
4203 4204
				l2cap_chan_clear_timer(chan);
				l2cap_chan_set_timer(chan, HZ / 10);
4205 4206 4207 4208
			}
		} else if (sk->sk_state == BT_CONNECT2) {
			struct l2cap_conn_rsp rsp;
			__u16 result;
L
Linus Torvalds 已提交
4209

4210 4211 4212 4213 4214
			if (!status) {
				sk->sk_state = BT_CONFIG;
				result = L2CAP_CR_SUCCESS;
			} else {
				sk->sk_state = BT_DISCONN;
4215
				l2cap_chan_set_timer(chan, HZ / 10);
4216 4217 4218
				result = L2CAP_CR_SEC_BLOCK;
			}

4219 4220
			rsp.scid   = cpu_to_le16(chan->dcid);
			rsp.dcid   = cpu_to_le16(chan->scid);
4221
			rsp.result = cpu_to_le16(result);
4222
			rsp.status = cpu_to_le16(L2CAP_CS_NO_INFO);
4223 4224
			l2cap_send_cmd(conn, chan->ident, L2CAP_CONN_RSP,
							sizeof(rsp), &rsp);
4225
		}
L
Linus Torvalds 已提交
4226 4227 4228 4229

		bh_unlock_sock(sk);
	}

4230
	read_unlock(&conn->chan_lock);
4231

L
Linus Torvalds 已提交
4232 4233 4234 4235 4236 4237 4238
	return 0;
}

static int l2cap_recv_acldata(struct hci_conn *hcon, struct sk_buff *skb, u16 flags)
{
	struct l2cap_conn *conn = hcon->l2cap_data;

4239 4240 4241 4242
	if (!conn)
		conn = l2cap_conn_add(hcon, 0);

	if (!conn)
L
Linus Torvalds 已提交
4243 4244 4245 4246
		goto drop;

	BT_DBG("conn %p len %d flags 0x%x", conn, skb->len, flags);

4247
	if (!(flags & ACL_CONT)) {
L
Linus Torvalds 已提交
4248
		struct l2cap_hdr *hdr;
4249
		struct l2cap_chan *chan;
4250
		u16 cid;
L
Linus Torvalds 已提交
4251 4252 4253 4254 4255 4256 4257 4258 4259 4260
		int len;

		if (conn->rx_len) {
			BT_ERR("Unexpected start frame (len %d)", skb->len);
			kfree_skb(conn->rx_skb);
			conn->rx_skb = NULL;
			conn->rx_len = 0;
			l2cap_conn_unreliable(conn, ECOMM);
		}

4261 4262
		/* Start fragment always begin with Basic L2CAP header */
		if (skb->len < L2CAP_HDR_SIZE) {
L
Linus Torvalds 已提交
4263 4264 4265 4266 4267 4268 4269
			BT_ERR("Frame is too short (len %d)", skb->len);
			l2cap_conn_unreliable(conn, ECOMM);
			goto drop;
		}

		hdr = (struct l2cap_hdr *) skb->data;
		len = __le16_to_cpu(hdr->len) + L2CAP_HDR_SIZE;
4270
		cid = __le16_to_cpu(hdr->cid);
L
Linus Torvalds 已提交
4271 4272 4273 4274 4275 4276 4277 4278 4279 4280 4281 4282 4283 4284 4285 4286

		if (len == skb->len) {
			/* Complete frame received */
			l2cap_recv_frame(conn, skb);
			return 0;
		}

		BT_DBG("Start: total len %d, frag len %d", len, skb->len);

		if (skb->len > len) {
			BT_ERR("Frame is too long (len %d, expected len %d)",
				skb->len, len);
			l2cap_conn_unreliable(conn, ECOMM);
			goto drop;
		}

4287
		chan = l2cap_get_chan_by_scid(conn, cid);
4288

4289 4290
		if (chan && chan->sk) {
			struct sock *sk = chan->sk;
4291

4292
			if (chan->imtu < len - L2CAP_HDR_SIZE) {
4293 4294
				BT_ERR("Frame exceeding recv MTU (len %d, "
							"MTU %d)", len,
4295
							chan->imtu);
4296 4297 4298 4299
				bh_unlock_sock(sk);
				l2cap_conn_unreliable(conn, ECOMM);
				goto drop;
			}
4300
			bh_unlock_sock(sk);
4301
		}
4302

L
Linus Torvalds 已提交
4303
		/* Allocate skb for the complete frame (with header) */
4304 4305
		conn->rx_skb = bt_skb_alloc(len, GFP_ATOMIC);
		if (!conn->rx_skb)
L
Linus Torvalds 已提交
4306 4307
			goto drop;

4308
		skb_copy_from_linear_data(skb, skb_put(conn->rx_skb, skb->len),
4309
								skb->len);
L
Linus Torvalds 已提交
4310 4311 4312 4313 4314 4315 4316 4317 4318 4319 4320 4321 4322 4323 4324 4325 4326 4327 4328 4329
		conn->rx_len = len - skb->len;
	} else {
		BT_DBG("Cont: frag len %d (expecting %d)", skb->len, conn->rx_len);

		if (!conn->rx_len) {
			BT_ERR("Unexpected continuation frame (len %d)", skb->len);
			l2cap_conn_unreliable(conn, ECOMM);
			goto drop;
		}

		if (skb->len > conn->rx_len) {
			BT_ERR("Fragment is too long (len %d, expected %d)",
					skb->len, conn->rx_len);
			kfree_skb(conn->rx_skb);
			conn->rx_skb = NULL;
			conn->rx_len = 0;
			l2cap_conn_unreliable(conn, ECOMM);
			goto drop;
		}

4330
		skb_copy_from_linear_data(skb, skb_put(conn->rx_skb, skb->len),
4331
								skb->len);
L
Linus Torvalds 已提交
4332 4333 4334 4335 4336 4337 4338 4339 4340 4341 4342 4343 4344 4345
		conn->rx_len -= skb->len;

		if (!conn->rx_len) {
			/* Complete frame received */
			l2cap_recv_frame(conn, conn->rx_skb);
			conn->rx_skb = NULL;
		}
	}

drop:
	kfree_skb(skb);
	return 0;
}

4346
static int l2cap_debugfs_show(struct seq_file *f, void *p)
L
Linus Torvalds 已提交
4347
{
4348
	struct l2cap_chan *c;
L
Linus Torvalds 已提交
4349

4350
	read_lock_bh(&chan_list_lock);
L
Linus Torvalds 已提交
4351

4352 4353
	list_for_each_entry(c, &chan_list, global_l) {
		struct sock *sk = c->sk;
4354

4355
		seq_printf(f, "%s %s %d %d 0x%4.4x 0x%4.4x %d %d %d %d\n",
4356 4357
					batostr(&bt_sk(sk)->src),
					batostr(&bt_sk(sk)->dst),
4358 4359 4360
					sk->sk_state, __le16_to_cpu(c->psm),
					c->scid, c->dcid, c->imtu, c->omtu,
					c->sec_level, c->mode);
4361
	}
L
Linus Torvalds 已提交
4362

4363
	read_unlock_bh(&chan_list_lock);
L
Linus Torvalds 已提交
4364

4365
	return 0;
L
Linus Torvalds 已提交
4366 4367
}

4368 4369 4370 4371 4372 4373 4374 4375 4376 4377 4378 4379 4380
static int l2cap_debugfs_open(struct inode *inode, struct file *file)
{
	return single_open(file, l2cap_debugfs_show, inode->i_private);
}

static const struct file_operations l2cap_debugfs_fops = {
	.open		= l2cap_debugfs_open,
	.read		= seq_read,
	.llseek		= seq_lseek,
	.release	= single_release,
};

static struct dentry *l2cap_debugfs;
L
Linus Torvalds 已提交
4381 4382 4383 4384 4385 4386 4387

static struct hci_proto l2cap_hci_proto = {
	.name		= "L2CAP",
	.id		= HCI_PROTO_L2CAP,
	.connect_ind	= l2cap_connect_ind,
	.connect_cfm	= l2cap_connect_cfm,
	.disconn_ind	= l2cap_disconn_ind,
4388
	.disconn_cfm	= l2cap_disconn_cfm,
4389
	.security_cfm	= l2cap_security_cfm,
L
Linus Torvalds 已提交
4390 4391 4392
	.recv_acldata	= l2cap_recv_acldata
};

4393
int __init l2cap_init(void)
L
Linus Torvalds 已提交
4394 4395
{
	int err;
4396

4397
	err = l2cap_init_sockets();
L
Linus Torvalds 已提交
4398 4399 4400
	if (err < 0)
		return err;

4401
	_busy_wq = create_singlethread_workqueue("l2cap");
4402
	if (!_busy_wq) {
4403
		err = -ENOMEM;
L
Linus Torvalds 已提交
4404 4405 4406 4407 4408 4409 4410 4411 4412 4413
		goto error;
	}

	err = hci_register_proto(&l2cap_hci_proto);
	if (err < 0) {
		BT_ERR("L2CAP protocol registration failed");
		bt_sock_unregister(BTPROTO_L2CAP);
		goto error;
	}

4414 4415 4416 4417 4418 4419
	if (bt_debugfs) {
		l2cap_debugfs = debugfs_create_file("l2cap", 0444,
					bt_debugfs, NULL, &l2cap_debugfs_fops);
		if (!l2cap_debugfs)
			BT_ERR("Failed to create L2CAP debug file");
	}
L
Linus Torvalds 已提交
4420 4421 4422 4423

	return 0;

error:
4424
	destroy_workqueue(_busy_wq);
4425
	l2cap_cleanup_sockets();
L
Linus Torvalds 已提交
4426 4427 4428
	return err;
}

4429
void l2cap_exit(void)
L
Linus Torvalds 已提交
4430
{
4431
	debugfs_remove(l2cap_debugfs);
L
Linus Torvalds 已提交
4432

4433 4434 4435
	flush_workqueue(_busy_wq);
	destroy_workqueue(_busy_wq);

L
Linus Torvalds 已提交
4436 4437 4438
	if (hci_unregister_proto(&l2cap_hci_proto) < 0)
		BT_ERR("L2CAP protocol unregistration failed");

4439
	l2cap_cleanup_sockets();
L
Linus Torvalds 已提交
4440 4441
}

4442 4443
module_param(disable_ertm, bool, 0644);
MODULE_PARM_DESC(disable_ertm, "Disable enhanced retransmission mode");