l2cap_core.c 98.8 KB
Newer Older
1
/*
L
Linus Torvalds 已提交
2 3
   BlueZ - Bluetooth protocol stack for Linux
   Copyright (C) 2000-2001 Qualcomm Incorporated
4
   Copyright (C) 2009-2010 Gustavo F. Padovan <gustavo@padovan.org>
5
   Copyright (C) 2010 Google Inc.
L
Linus Torvalds 已提交
6 7 8 9 10 11 12 13 14 15 16

   Written 2000,2001 by Maxim Krasnyansky <maxk@qualcomm.com>

   This program is free software; you can redistribute it and/or modify
   it under the terms of the GNU General Public License version 2 as
   published by the Free Software Foundation;

   THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS
   OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
   FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT OF THIRD PARTY RIGHTS.
   IN NO EVENT SHALL THE COPYRIGHT HOLDER(S) AND AUTHOR(S) BE LIABLE FOR ANY
17 18 19
   CLAIM, OR ANY SPECIAL INDIRECT OR CONSEQUENTIAL DAMAGES, OR ANY DAMAGES
   WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
   ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
L
Linus Torvalds 已提交
20 21
   OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.

22 23
   ALL LIABILITY, INCLUDING LIABILITY FOR INFRINGEMENT OF ANY PATENTS,
   COPYRIGHTS, TRADEMARKS OR OTHER RIGHTS, RELATING TO USE OF THIS
L
Linus Torvalds 已提交
24 25 26
   SOFTWARE IS DISCLAIMED.
*/

27
/* Bluetooth L2CAP core. */
L
Linus Torvalds 已提交
28 29 30 31

#include <linux/module.h>

#include <linux/types.h>
32
#include <linux/capability.h>
L
Linus Torvalds 已提交
33 34 35 36 37 38 39 40 41 42 43
#include <linux/errno.h>
#include <linux/kernel.h>
#include <linux/sched.h>
#include <linux/slab.h>
#include <linux/poll.h>
#include <linux/fcntl.h>
#include <linux/init.h>
#include <linux/interrupt.h>
#include <linux/socket.h>
#include <linux/skbuff.h>
#include <linux/list.h>
44
#include <linux/device.h>
45 46
#include <linux/debugfs.h>
#include <linux/seq_file.h>
47
#include <linux/uaccess.h>
48
#include <linux/crc16.h>
L
Linus Torvalds 已提交
49 50 51 52 53 54 55 56 57
#include <net/sock.h>

#include <asm/system.h>
#include <asm/unaligned.h>

#include <net/bluetooth/bluetooth.h>
#include <net/bluetooth/hci_core.h>
#include <net/bluetooth/l2cap.h>

58
int disable_ertm;
59

60
static u32 l2cap_feat_mask = L2CAP_FEAT_FIXED_CHAN;
61
static u8 l2cap_fixed_chan[8] = { 0x02, };
L
Linus Torvalds 已提交
62

63 64
static struct workqueue_struct *_busy_wq;

65 66
static LIST_HEAD(chan_list);
static DEFINE_RWLOCK(chan_list_lock);
L
Linus Torvalds 已提交
67

68 69
static void l2cap_busy_work(struct work_struct *work);

L
Linus Torvalds 已提交
70 71
static struct sk_buff *l2cap_build_cmd(struct l2cap_conn *conn,
				u8 code, u8 ident, u16 dlen, void *data);
72 73
static void l2cap_send_cmd(struct l2cap_conn *conn, u8 ident, u8 code, u16 len,
								void *data);
74
static int l2cap_build_conf_req(struct l2cap_chan *chan, void *data);
75 76
static void l2cap_send_disconn_req(struct l2cap_conn *conn,
				struct l2cap_chan *chan, int err);
L
Linus Torvalds 已提交
77

78 79
static int l2cap_ertm_data_rcv(struct sock *sk, struct sk_buff *skb);

80
/* ---- L2CAP channels ---- */
81
static struct l2cap_chan *__l2cap_get_chan_by_dcid(struct l2cap_conn *conn, u16 cid)
82
{
83
	struct l2cap_chan *c;
84 85

	list_for_each_entry(c, &conn->chan_l, list) {
86
		if (c->dcid == cid)
87
			return c;
88
	}
89 90
	return NULL;

91 92
}

93
static struct l2cap_chan *__l2cap_get_chan_by_scid(struct l2cap_conn *conn, u16 cid)
94
{
95
	struct l2cap_chan *c;
96 97

	list_for_each_entry(c, &conn->chan_l, list) {
98
		if (c->scid == cid)
99
			return c;
100
	}
101
	return NULL;
102 103 104 105
}

/* Find channel with given SCID.
 * Returns locked socket */
106
static struct l2cap_chan *l2cap_get_chan_by_scid(struct l2cap_conn *conn, u16 cid)
107
{
108
	struct l2cap_chan *c;
109 110 111

	read_lock(&conn->chan_lock);
	c = __l2cap_get_chan_by_scid(conn, cid);
112 113
	if (c)
		bh_lock_sock(c->sk);
114
	read_unlock(&conn->chan_lock);
115
	return c;
116 117
}

118
static struct l2cap_chan *__l2cap_get_chan_by_ident(struct l2cap_conn *conn, u8 ident)
119
{
120
	struct l2cap_chan *c;
121 122

	list_for_each_entry(c, &conn->chan_l, list) {
123
		if (c->ident == ident)
124
			return c;
125
	}
126
	return NULL;
127 128
}

129
static inline struct l2cap_chan *l2cap_get_chan_by_ident(struct l2cap_conn *conn, u8 ident)
130
{
131
	struct l2cap_chan *c;
132 133 134

	read_lock(&conn->chan_lock);
	c = __l2cap_get_chan_by_ident(conn, ident);
135 136
	if (c)
		bh_lock_sock(c->sk);
137
	read_unlock(&conn->chan_lock);
138
	return c;
139 140
}

141
static struct l2cap_chan *__l2cap_global_chan_by_addr(__le16 psm, bdaddr_t *src)
142
{
143
	struct l2cap_chan *c;
144

145 146
	list_for_each_entry(c, &chan_list, global_l) {
		if (c->sport == psm && !bacmp(&bt_sk(c->sk)->src, src))
147 148 149
			goto found;
	}

150
	c = NULL;
151
found:
152
	return c;
153 154 155 156
}

int l2cap_add_psm(struct l2cap_chan *chan, bdaddr_t *src, __le16 psm)
{
157 158
	int err;

159
	write_lock_bh(&chan_list_lock);
160

161
	if (psm && __l2cap_global_chan_by_addr(psm, src)) {
162 163
		err = -EADDRINUSE;
		goto done;
164 165
	}

166 167 168 169 170 171 172 173 174
	if (psm) {
		chan->psm = psm;
		chan->sport = psm;
		err = 0;
	} else {
		u16 p;

		err = -EINVAL;
		for (p = 0x1001; p < 0x1100; p += 2)
175
			if (!__l2cap_global_chan_by_addr(cpu_to_le16(p), src)) {
176 177 178 179 180 181
				chan->psm   = cpu_to_le16(p);
				chan->sport = cpu_to_le16(p);
				err = 0;
				break;
			}
	}
182

183
done:
184
	write_unlock_bh(&chan_list_lock);
185
	return err;
186 187 188 189
}

int l2cap_add_scid(struct l2cap_chan *chan,  __u16 scid)
{
190
	write_lock_bh(&chan_list_lock);
191 192 193

	chan->scid = scid;

194
	write_unlock_bh(&chan_list_lock);
195 196 197 198

	return 0;
}

199
static u16 l2cap_alloc_cid(struct l2cap_conn *conn)
200
{
201
	u16 cid = L2CAP_CID_DYN_START;
202

203
	for (; cid < L2CAP_CID_DYN_END; cid++) {
204
		if (!__l2cap_get_chan_by_scid(conn, cid))
205 206 207 208 209 210
			return cid;
	}

	return 0;
}

211 212
static void l2cap_chan_set_timer(struct l2cap_chan *chan, long timeout)
{
213 214
       BT_DBG("chan %p state %d timeout %ld", chan->sk, chan->state, timeout);

215 216 217 218
       if (!mod_timer(&chan->chan_timer, jiffies + timeout))
	       sock_hold(chan->sk);
}

219
static void l2cap_chan_clear_timer(struct l2cap_chan *chan)
220
{
221
       BT_DBG("chan %p state %d", chan, chan->state);
222 223 224 225 226

       if (timer_pending(&chan->chan_timer) && del_timer(&chan->chan_timer))
	       __sock_put(chan->sk);
}

227 228 229 230 231 232
static void l2cap_state_change(struct l2cap_chan *chan, int state)
{
	chan->state = state;
	chan->ops->state_change(chan->data, state);
}

233 234 235 236 237 238
static void l2cap_chan_timeout(unsigned long arg)
{
	struct l2cap_chan *chan = (struct l2cap_chan *) arg;
	struct sock *sk = chan->sk;
	int reason;

239
	BT_DBG("chan %p state %d", chan, chan->state);
240 241 242 243 244 245 246 247 248 249 250

	bh_lock_sock(sk);

	if (sock_owned_by_user(sk)) {
		/* sk is owned by user. Try again later */
		l2cap_chan_set_timer(chan, HZ / 5);
		bh_unlock_sock(sk);
		sock_put(sk);
		return;
	}

251
	if (chan->state == BT_CONNECTED || chan->state == BT_CONFIG)
252
		reason = ECONNREFUSED;
253
	else if (chan->state == BT_CONNECT &&
254 255 256 257 258
					chan->sec_level != BT_SECURITY_SDP)
		reason = ECONNREFUSED;
	else
		reason = ETIMEDOUT;

259
	l2cap_chan_close(chan, reason);
260 261 262

	bh_unlock_sock(sk);

263
	chan->ops->close(chan->data);
264 265 266
	sock_put(sk);
}

267
struct l2cap_chan *l2cap_chan_create(struct sock *sk)
268 269 270 271 272 273 274 275 276
{
	struct l2cap_chan *chan;

	chan = kzalloc(sizeof(*chan), GFP_ATOMIC);
	if (!chan)
		return NULL;

	chan->sk = sk;

277 278 279 280
	write_lock_bh(&chan_list_lock);
	list_add(&chan->global_l, &chan_list);
	write_unlock_bh(&chan_list_lock);

281 282
	setup_timer(&chan->chan_timer, l2cap_chan_timeout, (unsigned long) chan);

283 284
	chan->state = BT_OPEN;

285 286 287
	return chan;
}

288
void l2cap_chan_destroy(struct l2cap_chan *chan)
289
{
290 291 292 293
	write_lock_bh(&chan_list_lock);
	list_del(&chan->global_l);
	write_unlock_bh(&chan_list_lock);

294 295 296
	kfree(chan);
}

297
static void __l2cap_chan_add(struct l2cap_conn *conn, struct l2cap_chan *chan)
298
{
299
	struct sock *sk = chan->sk;
300

301
	BT_DBG("conn %p, psm 0x%2.2x, dcid 0x%4.4x", conn,
302
			chan->psm, chan->dcid);
303

304 305
	conn->disc_reason = 0x13;

306
	chan->conn = conn;
307

308
	if (chan->chan_type == L2CAP_CHAN_CONN_ORIENTED) {
309 310
		if (conn->hcon->type == LE_LINK) {
			/* LE connection */
311
			chan->omtu = L2CAP_LE_DEFAULT_MTU;
312 313
			chan->scid = L2CAP_CID_LE_DATA;
			chan->dcid = L2CAP_CID_LE_DATA;
314 315
		} else {
			/* Alloc CID for connection-oriented socket */
316
			chan->scid = l2cap_alloc_cid(conn);
317
			chan->omtu = L2CAP_DEFAULT_MTU;
318
		}
319
	} else if (chan->chan_type == L2CAP_CHAN_CONN_LESS) {
320
		/* Connectionless socket */
321 322
		chan->scid = L2CAP_CID_CONN_LESS;
		chan->dcid = L2CAP_CID_CONN_LESS;
323
		chan->omtu = L2CAP_DEFAULT_MTU;
324 325
	} else {
		/* Raw socket can send/recv signalling messages only */
326 327
		chan->scid = L2CAP_CID_SIGNALING;
		chan->dcid = L2CAP_CID_SIGNALING;
328
		chan->omtu = L2CAP_DEFAULT_MTU;
329 330
	}

331 332 333
	sock_hold(sk);

	list_add(&chan->list, &conn->chan_l);
334 335
}

336
/* Delete channel.
337
 * Must be called on the locked socket. */
338
static void l2cap_chan_del(struct l2cap_chan *chan, int err)
339
{
340
	struct sock *sk = chan->sk;
341
	struct l2cap_conn *conn = chan->conn;
342 343
	struct sock *parent = bt_sk(sk)->parent;

344
	l2cap_chan_clear_timer(chan);
345

346
	BT_DBG("chan %p, conn %p, err %d", chan, conn, err);
347

348
	if (conn) {
349 350 351 352 353 354
		/* Delete from channel list */
		write_lock_bh(&conn->chan_lock);
		list_del(&chan->list);
		write_unlock_bh(&conn->chan_lock);
		__sock_put(sk);

355
		chan->conn = NULL;
356 357 358
		hci_conn_put(conn->hcon);
	}

359
	l2cap_state_change(chan, BT_CLOSED);
360 361 362 363 364 365 366 367 368 369
	sock_set_flag(sk, SOCK_ZAPPED);

	if (err)
		sk->sk_err = err;

	if (parent) {
		bt_accept_unlink(sk);
		parent->sk_data_ready(parent, 0);
	} else
		sk->sk_state_change(sk);
370

371 372
	if (!(chan->conf_state & L2CAP_CONF_OUTPUT_DONE &&
			chan->conf_state & L2CAP_CONF_INPUT_DONE))
373
		return;
374

375
	skb_queue_purge(&chan->tx_q);
376

377
	if (chan->mode == L2CAP_MODE_ERTM) {
378 379
		struct srej_list *l, *tmp;

380 381 382
		del_timer(&chan->retrans_timer);
		del_timer(&chan->monitor_timer);
		del_timer(&chan->ack_timer);
383

384 385
		skb_queue_purge(&chan->srej_q);
		skb_queue_purge(&chan->busy_q);
386

387
		list_for_each_entry_safe(l, tmp, &chan->srej_l, list) {
388 389 390 391
			list_del(&l->list);
			kfree(l);
		}
	}
392 393
}

394 395 396 397 398 399 400
static void l2cap_chan_cleanup_listen(struct sock *parent)
{
	struct sock *sk;

	BT_DBG("parent %p", parent);

	/* Close not yet accepted channels */
401
	while ((sk = bt_accept_dequeue(parent, NULL))) {
402 403
		struct l2cap_chan *chan = l2cap_pi(sk)->chan;
		l2cap_chan_clear_timer(chan);
404
		lock_sock(sk);
405
		l2cap_chan_close(chan, ECONNRESET);
406
		release_sock(sk);
407
		chan->ops->close(chan->data);
408
	}
409 410
}

411
void l2cap_chan_close(struct l2cap_chan *chan, int reason)
412 413 414 415
{
	struct l2cap_conn *conn = chan->conn;
	struct sock *sk = chan->sk;

416
	BT_DBG("chan %p state %d socket %p", chan, chan->state, sk->sk_socket);
417

418
	switch (chan->state) {
419 420
	case BT_LISTEN:
		l2cap_chan_cleanup_listen(sk);
421 422 423

		l2cap_state_change(chan, BT_CLOSED);
		sock_set_flag(sk, SOCK_ZAPPED);
424 425 426 427
		break;

	case BT_CONNECTED:
	case BT_CONFIG:
428
		if (chan->chan_type == L2CAP_CHAN_CONN_ORIENTED &&
429
					conn->hcon->type == ACL_LINK) {
430
			l2cap_chan_clear_timer(chan);
431
			l2cap_chan_set_timer(chan, sk->sk_sndtimeo);
432 433 434 435 436 437
			l2cap_send_disconn_req(conn, chan, reason);
		} else
			l2cap_chan_del(chan, reason);
		break;

	case BT_CONNECT2:
438
		if (chan->chan_type == L2CAP_CHAN_CONN_ORIENTED &&
439 440 441 442 443 444 445 446
					conn->hcon->type == ACL_LINK) {
			struct l2cap_conn_rsp rsp;
			__u16 result;

			if (bt_sk(sk)->defer_setup)
				result = L2CAP_CR_SEC_BLOCK;
			else
				result = L2CAP_CR_BAD_PSM;
447
			l2cap_state_change(chan, BT_DISCONN);
448 449 450 451 452 453 454 455 456 457 458 459 460 461 462 463 464 465 466 467 468 469 470

			rsp.scid   = cpu_to_le16(chan->dcid);
			rsp.dcid   = cpu_to_le16(chan->scid);
			rsp.result = cpu_to_le16(result);
			rsp.status = cpu_to_le16(L2CAP_CS_NO_INFO);
			l2cap_send_cmd(conn, chan->ident, L2CAP_CONN_RSP,
							sizeof(rsp), &rsp);
		}

		l2cap_chan_del(chan, reason);
		break;

	case BT_CONNECT:
	case BT_DISCONN:
		l2cap_chan_del(chan, reason);
		break;

	default:
		sock_set_flag(sk, SOCK_ZAPPED);
		break;
	}
}

471
static inline u8 l2cap_get_auth_type(struct l2cap_chan *chan)
472
{
473
	if (chan->chan_type == L2CAP_CHAN_RAW) {
474
		switch (chan->sec_level) {
475 476 477 478 479 480 481
		case BT_SECURITY_HIGH:
			return HCI_AT_DEDICATED_BONDING_MITM;
		case BT_SECURITY_MEDIUM:
			return HCI_AT_DEDICATED_BONDING;
		default:
			return HCI_AT_NO_BONDING;
		}
482
	} else if (chan->psm == cpu_to_le16(0x0001)) {
483 484
		if (chan->sec_level == BT_SECURITY_LOW)
			chan->sec_level = BT_SECURITY_SDP;
485

486
		if (chan->sec_level == BT_SECURITY_HIGH)
487
			return HCI_AT_NO_BONDING_MITM;
488
		else
489
			return HCI_AT_NO_BONDING;
490
	} else {
491
		switch (chan->sec_level) {
492
		case BT_SECURITY_HIGH:
493
			return HCI_AT_GENERAL_BONDING_MITM;
494
		case BT_SECURITY_MEDIUM:
495
			return HCI_AT_GENERAL_BONDING;
496
		default:
497
			return HCI_AT_NO_BONDING;
498
		}
499
	}
500 501 502
}

/* Service level security */
503
static inline int l2cap_check_security(struct l2cap_chan *chan)
504
{
505
	struct l2cap_conn *conn = chan->conn;
506 507
	__u8 auth_type;

508
	auth_type = l2cap_get_auth_type(chan);
509

510
	return hci_conn_security(conn->hcon, chan->sec_level, auth_type);
511 512
}

513
static u8 l2cap_get_ident(struct l2cap_conn *conn)
514 515 516 517 518 519 520 521 522 523 524 525 526 527 528 529 530 531 532 533 534
{
	u8 id;

	/* Get next available identificator.
	 *    1 - 128 are used by kernel.
	 *  129 - 199 are reserved.
	 *  200 - 254 are used by utilities like l2ping, etc.
	 */

	spin_lock_bh(&conn->lock);

	if (++conn->tx_ident > 128)
		conn->tx_ident = 1;

	id = conn->tx_ident;

	spin_unlock_bh(&conn->lock);

	return id;
}

535
static void l2cap_send_cmd(struct l2cap_conn *conn, u8 ident, u8 code, u16 len, void *data)
536 537
{
	struct sk_buff *skb = l2cap_build_cmd(conn, code, ident, len, data);
538
	u8 flags;
539 540 541 542

	BT_DBG("code 0x%2.2x", code);

	if (!skb)
543
		return;
544

545 546 547 548 549
	if (lmp_no_flush_capable(conn->hcon->hdev))
		flags = ACL_START_NO_FLUSH;
	else
		flags = ACL_START;

550 551
	bt_cb(skb)->force_active = BT_POWER_FORCE_ACTIVE_ON;

552
	hci_send_acl(conn->hcon, skb, flags);
553 554
}

555
static inline void l2cap_send_sframe(struct l2cap_chan *chan, u16 control)
556 557 558
{
	struct sk_buff *skb;
	struct l2cap_hdr *lh;
559
	struct l2cap_conn *conn = chan->conn;
560
	int count, hlen = L2CAP_HDR_SIZE + 2;
561
	u8 flags;
562

563
	if (chan->state != BT_CONNECTED)
564 565
		return;

566
	if (chan->fcs == L2CAP_FCS_CRC16)
567
		hlen += 2;
568

569
	BT_DBG("chan %p, control 0x%2.2x", chan, control);
570

571
	count = min_t(unsigned int, conn->mtu, hlen);
572 573
	control |= L2CAP_CTRL_FRAME_TYPE;

574
	if (chan->conn_state & L2CAP_CONN_SEND_FBIT) {
575
		control |= L2CAP_CTRL_FINAL;
576
		chan->conn_state &= ~L2CAP_CONN_SEND_FBIT;
577 578
	}

579
	if (chan->conn_state & L2CAP_CONN_SEND_PBIT) {
580
		control |= L2CAP_CTRL_POLL;
581
		chan->conn_state &= ~L2CAP_CONN_SEND_PBIT;
582 583
	}

584 585
	skb = bt_skb_alloc(count, GFP_ATOMIC);
	if (!skb)
586
		return;
587 588

	lh = (struct l2cap_hdr *) skb_put(skb, L2CAP_HDR_SIZE);
589
	lh->len = cpu_to_le16(hlen - L2CAP_HDR_SIZE);
590
	lh->cid = cpu_to_le16(chan->dcid);
591 592
	put_unaligned_le16(control, skb_put(skb, 2));

593
	if (chan->fcs == L2CAP_FCS_CRC16) {
594 595 596 597
		u16 fcs = crc16(0, (u8 *)lh, count - 2);
		put_unaligned_le16(fcs, skb_put(skb, 2));
	}

598 599 600 601 602
	if (lmp_no_flush_capable(conn->hcon->hdev))
		flags = ACL_START_NO_FLUSH;
	else
		flags = ACL_START;

603 604
	bt_cb(skb)->force_active = chan->force_active;

605
	hci_send_acl(chan->conn->hcon, skb, flags);
606 607
}

608
static inline void l2cap_send_rr_or_rnr(struct l2cap_chan *chan, u16 control)
609
{
610
	if (chan->conn_state & L2CAP_CONN_LOCAL_BUSY) {
611
		control |= L2CAP_SUPER_RCV_NOT_READY;
612
		chan->conn_state |= L2CAP_CONN_RNR_SENT;
613
	} else
614 615
		control |= L2CAP_SUPER_RCV_READY;

616
	control |= chan->buffer_seq << L2CAP_CTRL_REQSEQ_SHIFT;
617

618
	l2cap_send_sframe(chan, control);
619 620
}

621
static inline int __l2cap_no_conn_pending(struct l2cap_chan *chan)
622
{
623
	return !(chan->conf_state & L2CAP_CONF_CONNECT_PEND);
624 625
}

626
static void l2cap_do_start(struct l2cap_chan *chan)
627
{
628
	struct l2cap_conn *conn = chan->conn;
629 630

	if (conn->info_state & L2CAP_INFO_FEAT_MASK_REQ_SENT) {
631 632 633
		if (!(conn->info_state & L2CAP_INFO_FEAT_MASK_REQ_DONE))
			return;

634 635
		if (l2cap_check_security(chan) &&
				__l2cap_no_conn_pending(chan)) {
636
			struct l2cap_conn_req req;
637 638
			req.scid = cpu_to_le16(chan->scid);
			req.psm  = chan->psm;
639

640
			chan->ident = l2cap_get_ident(conn);
641
			chan->conf_state |= L2CAP_CONF_CONNECT_PEND;
642

643 644
			l2cap_send_cmd(conn, chan->ident, L2CAP_CONN_REQ,
							sizeof(req), &req);
645
		}
646 647 648 649 650 651 652 653 654 655 656 657 658 659 660
	} else {
		struct l2cap_info_req req;
		req.type = cpu_to_le16(L2CAP_IT_FEAT_MASK);

		conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_SENT;
		conn->info_ident = l2cap_get_ident(conn);

		mod_timer(&conn->info_timer, jiffies +
					msecs_to_jiffies(L2CAP_INFO_TIMEOUT));

		l2cap_send_cmd(conn, conn->info_ident,
					L2CAP_INFO_REQ, sizeof(req), &req);
	}
}

661 662 663
static inline int l2cap_mode_supported(__u8 mode, __u32 feat_mask)
{
	u32 local_feat_mask = l2cap_feat_mask;
664
	if (!disable_ertm)
665 666 667 668 669 670 671 672 673 674 675 676
		local_feat_mask |= L2CAP_FEAT_ERTM | L2CAP_FEAT_STREAMING;

	switch (mode) {
	case L2CAP_MODE_ERTM:
		return L2CAP_FEAT_ERTM & feat_mask & local_feat_mask;
	case L2CAP_MODE_STREAMING:
		return L2CAP_FEAT_STREAMING & feat_mask & local_feat_mask;
	default:
		return 0x00;
	}
}

677
static void l2cap_send_disconn_req(struct l2cap_conn *conn, struct l2cap_chan *chan, int err)
678
{
679
	struct sock *sk;
680 681
	struct l2cap_disconn_req req;

682 683 684
	if (!conn)
		return;

685 686
	sk = chan->sk;

687
	if (chan->mode == L2CAP_MODE_ERTM) {
688 689 690
		del_timer(&chan->retrans_timer);
		del_timer(&chan->monitor_timer);
		del_timer(&chan->ack_timer);
691 692
	}

693 694
	req.dcid = cpu_to_le16(chan->dcid);
	req.scid = cpu_to_le16(chan->scid);
695 696
	l2cap_send_cmd(conn, l2cap_get_ident(conn),
			L2CAP_DISCONN_REQ, sizeof(req), &req);
697

698
	l2cap_state_change(chan, BT_DISCONN);
699
	sk->sk_err = err;
700 701
}

L
Linus Torvalds 已提交
702
/* ---- L2CAP connections ---- */
703 704
static void l2cap_conn_start(struct l2cap_conn *conn)
{
705
	struct l2cap_chan *chan, *tmp;
706 707 708

	BT_DBG("conn %p", conn);

709
	read_lock(&conn->chan_lock);
710

711
	list_for_each_entry_safe(chan, tmp, &conn->chan_l, list) {
712
		struct sock *sk = chan->sk;
713

714 715
		bh_lock_sock(sk);

716
		if (chan->chan_type != L2CAP_CHAN_CONN_ORIENTED) {
717 718 719 720
			bh_unlock_sock(sk);
			continue;
		}

721
		if (chan->state == BT_CONNECT) {
722
			struct l2cap_conn_req req;
723

724
			if (!l2cap_check_security(chan) ||
725
					!__l2cap_no_conn_pending(chan)) {
726 727 728
				bh_unlock_sock(sk);
				continue;
			}
729

730
			if (!l2cap_mode_supported(chan->mode,
731
					conn->feat_mask)
732
					&& chan->conf_state &
733
					L2CAP_CONF_STATE2_DEVICE) {
734
				/* l2cap_chan_close() calls list_del(chan)
735 736
				 * so release the lock */
				read_unlock_bh(&conn->chan_lock);
737
				l2cap_chan_close(chan, ECONNRESET);
738
				read_lock_bh(&conn->chan_lock);
739 740
				bh_unlock_sock(sk);
				continue;
741
			}
742

743 744
			req.scid = cpu_to_le16(chan->scid);
			req.psm  = chan->psm;
745

746
			chan->ident = l2cap_get_ident(conn);
747
			chan->conf_state |= L2CAP_CONF_CONNECT_PEND;
748

749 750
			l2cap_send_cmd(conn, chan->ident, L2CAP_CONN_REQ,
							sizeof(req), &req);
751

752
		} else if (chan->state == BT_CONNECT2) {
753
			struct l2cap_conn_rsp rsp;
754
			char buf[128];
755 756
			rsp.scid = cpu_to_le16(chan->dcid);
			rsp.dcid = cpu_to_le16(chan->scid);
757

758
			if (l2cap_check_security(chan)) {
759 760 761 762 763 764 765
				if (bt_sk(sk)->defer_setup) {
					struct sock *parent = bt_sk(sk)->parent;
					rsp.result = cpu_to_le16(L2CAP_CR_PEND);
					rsp.status = cpu_to_le16(L2CAP_CS_AUTHOR_PEND);
					parent->sk_data_ready(parent, 0);

				} else {
766
					l2cap_state_change(chan, BT_CONFIG);
767 768 769
					rsp.result = cpu_to_le16(L2CAP_CR_SUCCESS);
					rsp.status = cpu_to_le16(L2CAP_CS_NO_INFO);
				}
770 771 772 773 774
			} else {
				rsp.result = cpu_to_le16(L2CAP_CR_PEND);
				rsp.status = cpu_to_le16(L2CAP_CS_AUTHEN_PEND);
			}

775 776
			l2cap_send_cmd(conn, chan->ident, L2CAP_CONN_RSP,
							sizeof(rsp), &rsp);
777

778
			if (chan->conf_state & L2CAP_CONF_REQ_SENT ||
779 780 781 782 783
					rsp.result != L2CAP_CR_SUCCESS) {
				bh_unlock_sock(sk);
				continue;
			}

784
			chan->conf_state |= L2CAP_CONF_REQ_SENT;
785
			l2cap_send_cmd(conn, l2cap_get_ident(conn), L2CAP_CONF_REQ,
786 787
						l2cap_build_conf_req(chan, buf), buf);
			chan->num_conf_req++;
788 789 790 791 792
		}

		bh_unlock_sock(sk);
	}

793
	read_unlock(&conn->chan_lock);
794 795
}

796 797 798
/* Find socket with cid and source bdaddr.
 * Returns closest match, locked.
 */
799
static struct l2cap_chan *l2cap_global_chan_by_scid(int state, __le16 cid, bdaddr_t *src)
800
{
801
	struct l2cap_chan *c, *c1 = NULL;
802

803
	read_lock(&chan_list_lock);
804

805 806
	list_for_each_entry(c, &chan_list, global_l) {
		struct sock *sk = c->sk;
807

808
		if (state && c->state != state)
809 810
			continue;

811
		if (c->scid == cid) {
812
			/* Exact match. */
813 814 815 816
			if (!bacmp(&bt_sk(sk)->src, src)) {
				read_unlock(&chan_list_lock);
				return c;
			}
817 818 819

			/* Closest match */
			if (!bacmp(&bt_sk(sk)->src, BDADDR_ANY))
820
				c1 = c;
821 822
		}
	}
823

824
	read_unlock(&chan_list_lock);
825

826
	return c1;
827 828 829 830
}

static void l2cap_le_conn_ready(struct l2cap_conn *conn)
{
831
	struct sock *parent, *sk;
832
	struct l2cap_chan *chan, *pchan;
833 834 835 836

	BT_DBG("");

	/* Check if we have socket listening on cid */
837
	pchan = l2cap_global_chan_by_scid(BT_LISTEN, L2CAP_CID_LE_DATA,
838
							conn->src);
839
	if (!pchan)
840 841
		return;

842 843
	parent = pchan->sk;

844 845
	bh_lock_sock(parent);

846 847 848 849 850 851
	/* Check for backlog size */
	if (sk_acceptq_is_full(parent)) {
		BT_DBG("backlog full %d", parent->sk_ack_backlog);
		goto clean;
	}

852 853
	chan = pchan->ops->new_connection(pchan->data);
	if (!chan)
854 855
		goto clean;

856
	sk = chan->sk;
857

858
	write_lock_bh(&conn->chan_lock);
859 860 861 862 863 864

	hci_conn_hold(conn->hcon);

	bacpy(&bt_sk(sk)->src, conn->src);
	bacpy(&bt_sk(sk)->dst, conn->dst);

865 866
	bt_accept_enqueue(parent, sk);

867 868
	__l2cap_chan_add(conn, chan);

869
	l2cap_chan_set_timer(chan, sk->sk_sndtimeo);
870

871
	l2cap_state_change(chan, BT_CONNECTED);
872 873
	parent->sk_data_ready(parent, 0);

874
	write_unlock_bh(&conn->chan_lock);
875 876 877 878 879

clean:
	bh_unlock_sock(parent);
}

880 881
static void l2cap_conn_ready(struct l2cap_conn *conn)
{
882
	struct l2cap_chan *chan;
883

884
	BT_DBG("conn %p", conn);
885

886 887 888
	if (!conn->hcon->out && conn->hcon->type == LE_LINK)
		l2cap_le_conn_ready(conn);

889
	read_lock(&conn->chan_lock);
890

891
	list_for_each_entry(chan, &conn->chan_l, list) {
892
		struct sock *sk = chan->sk;
893

894
		bh_lock_sock(sk);
895

896
		if (conn->hcon->type == LE_LINK) {
897
			l2cap_chan_clear_timer(chan);
898
			l2cap_state_change(chan, BT_CONNECTED);
899 900 901
			sk->sk_state_change(sk);
		}

902
		if (chan->chan_type != L2CAP_CHAN_CONN_ORIENTED) {
903
			l2cap_chan_clear_timer(chan);
904
			l2cap_state_change(chan, BT_CONNECTED);
905
			sk->sk_state_change(sk);
906
		} else if (chan->state == BT_CONNECT)
907
			l2cap_do_start(chan);
908

909
		bh_unlock_sock(sk);
910
	}
911

912
	read_unlock(&conn->chan_lock);
913 914 915 916 917
}

/* Notify sockets that we cannot guaranty reliability anymore */
static void l2cap_conn_unreliable(struct l2cap_conn *conn, int err)
{
918
	struct l2cap_chan *chan;
919 920 921

	BT_DBG("conn %p", conn);

922
	read_lock(&conn->chan_lock);
923

924
	list_for_each_entry(chan, &conn->chan_l, list) {
925
		struct sock *sk = chan->sk;
926

927
		if (chan->force_reliable)
928 929 930
			sk->sk_err = err;
	}

931
	read_unlock(&conn->chan_lock);
932 933 934 935 936 937
}

static void l2cap_info_timeout(unsigned long arg)
{
	struct l2cap_conn *conn = (void *) arg;

938
	conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_DONE;
939
	conn->info_ident = 0;
940

941 942 943
	l2cap_conn_start(conn);
}

L
Linus Torvalds 已提交
944 945
static struct l2cap_conn *l2cap_conn_add(struct hci_conn *hcon, u8 status)
{
946
	struct l2cap_conn *conn = hcon->l2cap_data;
L
Linus Torvalds 已提交
947

948
	if (conn || status)
L
Linus Torvalds 已提交
949 950
		return conn;

951 952
	conn = kzalloc(sizeof(struct l2cap_conn), GFP_ATOMIC);
	if (!conn)
L
Linus Torvalds 已提交
953 954 955 956 957
		return NULL;

	hcon->l2cap_data = conn;
	conn->hcon = hcon;

958 959
	BT_DBG("hcon %p conn %p", hcon, conn);

960 961 962 963 964
	if (hcon->hdev->le_mtu && hcon->type == LE_LINK)
		conn->mtu = hcon->hdev->le_mtu;
	else
		conn->mtu = hcon->hdev->acl_mtu;

L
Linus Torvalds 已提交
965 966 967
	conn->src = &hcon->hdev->bdaddr;
	conn->dst = &hcon->dst;

968 969
	conn->feat_mask = 0;

L
Linus Torvalds 已提交
970
	spin_lock_init(&conn->lock);
971 972 973
	rwlock_init(&conn->chan_lock);

	INIT_LIST_HEAD(&conn->chan_l);
L
Linus Torvalds 已提交
974

975 976
	if (hcon->type != LE_LINK)
		setup_timer(&conn->info_timer, l2cap_info_timeout,
D
Dave Young 已提交
977 978
						(unsigned long) conn);

979 980
	conn->disc_reason = 0x13;

L
Linus Torvalds 已提交
981 982 983
	return conn;
}

984
static void l2cap_conn_del(struct hci_conn *hcon, int err)
L
Linus Torvalds 已提交
985
{
986
	struct l2cap_conn *conn = hcon->l2cap_data;
987
	struct l2cap_chan *chan, *l;
L
Linus Torvalds 已提交
988 989
	struct sock *sk;

990 991
	if (!conn)
		return;
L
Linus Torvalds 已提交
992 993 994

	BT_DBG("hcon %p conn %p, err %d", hcon, conn, err);

995
	kfree_skb(conn->rx_skb);
L
Linus Torvalds 已提交
996 997

	/* Kill channels */
998
	list_for_each_entry_safe(chan, l, &conn->chan_l, list) {
999
		sk = chan->sk;
L
Linus Torvalds 已提交
1000
		bh_lock_sock(sk);
1001
		l2cap_chan_del(chan, err);
L
Linus Torvalds 已提交
1002
		bh_unlock_sock(sk);
1003
		chan->ops->close(chan->data);
L
Linus Torvalds 已提交
1004 1005
	}

1006 1007
	if (conn->info_state & L2CAP_INFO_FEAT_MASK_REQ_SENT)
		del_timer_sync(&conn->info_timer);
1008

L
Linus Torvalds 已提交
1009 1010 1011 1012
	hcon->l2cap_data = NULL;
	kfree(conn);
}

1013
static inline void l2cap_chan_add(struct l2cap_conn *conn, struct l2cap_chan *chan)
L
Linus Torvalds 已提交
1014
{
1015
	write_lock_bh(&conn->chan_lock);
1016
	__l2cap_chan_add(conn, chan);
1017
	write_unlock_bh(&conn->chan_lock);
L
Linus Torvalds 已提交
1018 1019 1020 1021 1022 1023 1024
}

/* ---- Socket interface ---- */

/* Find socket with psm and source bdaddr.
 * Returns closest match.
 */
1025
static struct l2cap_chan *l2cap_global_chan_by_psm(int state, __le16 psm, bdaddr_t *src)
L
Linus Torvalds 已提交
1026
{
1027
	struct l2cap_chan *c, *c1 = NULL;
L
Linus Torvalds 已提交
1028

1029
	read_lock(&chan_list_lock);
1030

1031 1032
	list_for_each_entry(c, &chan_list, global_l) {
		struct sock *sk = c->sk;
1033

1034
		if (state && c->state != state)
L
Linus Torvalds 已提交
1035 1036
			continue;

1037
		if (c->psm == psm) {
L
Linus Torvalds 已提交
1038
			/* Exact match. */
1039
			if (!bacmp(&bt_sk(sk)->src, src)) {
1040
				read_unlock(&chan_list_lock);
1041 1042
				return c;
			}
L
Linus Torvalds 已提交
1043 1044 1045

			/* Closest match */
			if (!bacmp(&bt_sk(sk)->src, BDADDR_ANY))
1046
				c1 = c;
L
Linus Torvalds 已提交
1047 1048 1049
		}
	}

1050
	read_unlock(&chan_list_lock);
1051

1052
	return c1;
L
Linus Torvalds 已提交
1053 1054
}

1055
int l2cap_chan_connect(struct l2cap_chan *chan)
L
Linus Torvalds 已提交
1056
{
1057
	struct sock *sk = chan->sk;
L
Linus Torvalds 已提交
1058 1059 1060 1061 1062
	bdaddr_t *src = &bt_sk(sk)->src;
	bdaddr_t *dst = &bt_sk(sk)->dst;
	struct l2cap_conn *conn;
	struct hci_conn *hcon;
	struct hci_dev *hdev;
1063
	__u8 auth_type;
1064
	int err;
L
Linus Torvalds 已提交
1065

1066
	BT_DBG("%s -> %s psm 0x%2.2x", batostr(src), batostr(dst),
1067
							chan->psm);
L
Linus Torvalds 已提交
1068

1069 1070
	hdev = hci_get_route(dst, src);
	if (!hdev)
L
Linus Torvalds 已提交
1071 1072 1073 1074
		return -EHOSTUNREACH;

	hci_dev_lock_bh(hdev);

1075
	auth_type = l2cap_get_auth_type(chan);
1076

1077
	if (chan->dcid == L2CAP_CID_LE_DATA)
1078
		hcon = hci_connect(hdev, LE_LINK, dst,
1079
					chan->sec_level, auth_type);
1080 1081
	else
		hcon = hci_connect(hdev, ACL_LINK, dst,
1082
					chan->sec_level, auth_type);
1083

1084 1085
	if (IS_ERR(hcon)) {
		err = PTR_ERR(hcon);
L
Linus Torvalds 已提交
1086
		goto done;
1087
	}
L
Linus Torvalds 已提交
1088 1089 1090 1091

	conn = l2cap_conn_add(hcon, 0);
	if (!conn) {
		hci_conn_put(hcon);
1092
		err = -ENOMEM;
L
Linus Torvalds 已提交
1093 1094 1095 1096 1097 1098
		goto done;
	}

	/* Update source addr of the socket */
	bacpy(src, conn->src);

1099 1100
	l2cap_chan_add(conn, chan);

1101
	l2cap_state_change(chan, BT_CONNECT);
1102
	l2cap_chan_set_timer(chan, sk->sk_sndtimeo);
L
Linus Torvalds 已提交
1103 1104

	if (hcon->state == BT_CONNECTED) {
1105
		if (chan->chan_type != L2CAP_CHAN_CONN_ORIENTED) {
1106
			l2cap_chan_clear_timer(chan);
1107
			if (l2cap_check_security(chan))
1108
				l2cap_state_change(chan, BT_CONNECTED);
1109
		} else
1110
			l2cap_do_start(chan);
L
Linus Torvalds 已提交
1111 1112
	}

1113 1114
	err = 0;

L
Linus Torvalds 已提交
1115 1116 1117 1118 1119 1120
done:
	hci_dev_unlock_bh(hdev);
	hci_dev_put(hdev);
	return err;
}

1121
int __l2cap_wait_ack(struct sock *sk)
1122
{
1123
	struct l2cap_chan *chan = l2cap_pi(sk)->chan;
1124 1125 1126 1127
	DECLARE_WAITQUEUE(wait, current);
	int err = 0;
	int timeo = HZ/5;

1128
	add_wait_queue(sk_sleep(sk), &wait);
1129
	while ((chan->unacked_frames > 0 && chan->conn)) {
1130 1131 1132 1133 1134 1135 1136 1137 1138 1139 1140 1141 1142 1143 1144 1145 1146 1147 1148
		set_current_state(TASK_INTERRUPTIBLE);

		if (!timeo)
			timeo = HZ/5;

		if (signal_pending(current)) {
			err = sock_intr_errno(timeo);
			break;
		}

		release_sock(sk);
		timeo = schedule_timeout(timeo);
		lock_sock(sk);

		err = sock_error(sk);
		if (err)
			break;
	}
	set_current_state(TASK_RUNNING);
1149
	remove_wait_queue(sk_sleep(sk), &wait);
1150 1151 1152
	return err;
}

1153 1154
static void l2cap_monitor_timeout(unsigned long arg)
{
1155 1156
	struct l2cap_chan *chan = (void *) arg;
	struct sock *sk = chan->sk;
1157

1158
	BT_DBG("chan %p", chan);
1159

1160
	bh_lock_sock(sk);
1161
	if (chan->retry_count >= chan->remote_max_tx) {
1162
		l2cap_send_disconn_req(chan->conn, chan, ECONNABORTED);
1163
		bh_unlock_sock(sk);
1164 1165 1166
		return;
	}

1167
	chan->retry_count++;
1168 1169
	__mod_monitor_timer();

1170
	l2cap_send_rr_or_rnr(chan, L2CAP_CTRL_POLL);
1171
	bh_unlock_sock(sk);
1172 1173 1174 1175
}

static void l2cap_retrans_timeout(unsigned long arg)
{
1176 1177
	struct l2cap_chan *chan = (void *) arg;
	struct sock *sk = chan->sk;
1178

1179
	BT_DBG("chan %p", chan);
1180

1181
	bh_lock_sock(sk);
1182
	chan->retry_count = 1;
1183 1184
	__mod_monitor_timer();

1185
	chan->conn_state |= L2CAP_CONN_WAIT_F;
1186

1187
	l2cap_send_rr_or_rnr(chan, L2CAP_CTRL_POLL);
1188
	bh_unlock_sock(sk);
1189 1190
}

1191
static void l2cap_drop_acked_frames(struct l2cap_chan *chan)
L
Linus Torvalds 已提交
1192
{
1193
	struct sk_buff *skb;
L
Linus Torvalds 已提交
1194

1195
	while ((skb = skb_peek(&chan->tx_q)) &&
1196
			chan->unacked_frames) {
1197
		if (bt_cb(skb)->tx_seq == chan->expected_ack_seq)
1198
			break;
L
Linus Torvalds 已提交
1199

1200
		skb = skb_dequeue(&chan->tx_q);
1201
		kfree_skb(skb);
L
Linus Torvalds 已提交
1202

1203
		chan->unacked_frames--;
1204
	}
L
Linus Torvalds 已提交
1205

1206
	if (!chan->unacked_frames)
1207
		del_timer(&chan->retrans_timer);
1208
}
L
Linus Torvalds 已提交
1209

1210
void l2cap_do_send(struct l2cap_chan *chan, struct sk_buff *skb)
1211
{
1212
	struct hci_conn *hcon = chan->conn->hcon;
1213
	u16 flags;
1214

1215
	BT_DBG("chan %p, skb %p len %d", chan, skb, skb->len);
L
Linus Torvalds 已提交
1216

1217
	if (!chan->flushable && lmp_no_flush_capable(hcon->hdev))
1218 1219 1220 1221
		flags = ACL_START_NO_FLUSH;
	else
		flags = ACL_START;

1222
	bt_cb(skb)->force_active = chan->force_active;
1223
	hci_send_acl(hcon, skb, flags);
1224 1225
}

1226
void l2cap_streaming_send(struct l2cap_chan *chan)
1227
{
1228
	struct sk_buff *skb;
1229
	u16 control, fcs;
1230

1231
	while ((skb = skb_dequeue(&chan->tx_q))) {
1232
		control = get_unaligned_le16(skb->data + L2CAP_HDR_SIZE);
1233
		control |= chan->next_tx_seq << L2CAP_CTRL_TXSEQ_SHIFT;
1234
		put_unaligned_le16(control, skb->data + L2CAP_HDR_SIZE);
1235

1236
		if (chan->fcs == L2CAP_FCS_CRC16) {
1237 1238
			fcs = crc16(0, (u8 *)skb->data, skb->len - 2);
			put_unaligned_le16(fcs, skb->data + skb->len - 2);
1239 1240
		}

1241
		l2cap_do_send(chan, skb);
1242

1243
		chan->next_tx_seq = (chan->next_tx_seq + 1) % 64;
1244 1245 1246
	}
}

1247
static void l2cap_retransmit_one_frame(struct l2cap_chan *chan, u8 tx_seq)
1248 1249 1250 1251
{
	struct sk_buff *skb, *tx_skb;
	u16 control, fcs;

1252
	skb = skb_peek(&chan->tx_q);
1253 1254
	if (!skb)
		return;
1255

1256 1257
	do {
		if (bt_cb(skb)->tx_seq == tx_seq)
1258 1259
			break;

1260
		if (skb_queue_is_last(&chan->tx_q, skb))
1261
			return;
1262

1263
	} while ((skb = skb_queue_next(&chan->tx_q, skb)));
1264

1265 1266
	if (chan->remote_max_tx &&
			bt_cb(skb)->retries == chan->remote_max_tx) {
1267
		l2cap_send_disconn_req(chan->conn, chan, ECONNABORTED);
1268 1269 1270 1271 1272 1273
		return;
	}

	tx_skb = skb_clone(skb, GFP_ATOMIC);
	bt_cb(skb)->retries++;
	control = get_unaligned_le16(tx_skb->data + L2CAP_HDR_SIZE);
1274
	control &= L2CAP_CTRL_SAR;
1275

1276
	if (chan->conn_state & L2CAP_CONN_SEND_FBIT) {
1277
		control |= L2CAP_CTRL_FINAL;
1278
		chan->conn_state &= ~L2CAP_CONN_SEND_FBIT;
1279
	}
1280

1281
	control |= (chan->buffer_seq << L2CAP_CTRL_REQSEQ_SHIFT)
1282
			| (tx_seq << L2CAP_CTRL_TXSEQ_SHIFT);
1283

1284 1285
	put_unaligned_le16(control, tx_skb->data + L2CAP_HDR_SIZE);

1286
	if (chan->fcs == L2CAP_FCS_CRC16) {
1287 1288 1289 1290
		fcs = crc16(0, (u8 *)tx_skb->data, tx_skb->len - 2);
		put_unaligned_le16(fcs, tx_skb->data + tx_skb->len - 2);
	}

1291
	l2cap_do_send(chan, tx_skb);
1292 1293
}

1294
int l2cap_ertm_send(struct l2cap_chan *chan)
1295 1296
{
	struct sk_buff *skb, *tx_skb;
1297
	u16 control, fcs;
1298
	int nsent = 0;
1299

1300
	if (chan->state != BT_CONNECTED)
1301
		return -ENOTCONN;
1302

1303
	while ((skb = chan->tx_send_head) && (!l2cap_tx_window_full(chan))) {
1304

1305 1306
		if (chan->remote_max_tx &&
				bt_cb(skb)->retries == chan->remote_max_tx) {
1307
			l2cap_send_disconn_req(chan->conn, chan, ECONNABORTED);
1308 1309 1310
			break;
		}

1311 1312
		tx_skb = skb_clone(skb, GFP_ATOMIC);

1313 1314
		bt_cb(skb)->retries++;

1315
		control = get_unaligned_le16(tx_skb->data + L2CAP_HDR_SIZE);
1316 1317
		control &= L2CAP_CTRL_SAR;

1318
		if (chan->conn_state & L2CAP_CONN_SEND_FBIT) {
1319
			control |= L2CAP_CTRL_FINAL;
1320
			chan->conn_state &= ~L2CAP_CONN_SEND_FBIT;
1321
		}
1322 1323
		control |= (chan->buffer_seq << L2CAP_CTRL_REQSEQ_SHIFT)
				| (chan->next_tx_seq << L2CAP_CTRL_TXSEQ_SHIFT);
1324 1325
		put_unaligned_le16(control, tx_skb->data + L2CAP_HDR_SIZE);

1326

1327
		if (chan->fcs == L2CAP_FCS_CRC16) {
1328 1329 1330 1331
			fcs = crc16(0, (u8 *)skb->data, tx_skb->len - 2);
			put_unaligned_le16(fcs, skb->data + tx_skb->len - 2);
		}

1332
		l2cap_do_send(chan, tx_skb);
1333

1334
		__mod_retrans_timer();
1335

1336 1337
		bt_cb(skb)->tx_seq = chan->next_tx_seq;
		chan->next_tx_seq = (chan->next_tx_seq + 1) % 64;
1338

1339
		if (bt_cb(skb)->retries == 1)
1340
			chan->unacked_frames++;
1341

1342
		chan->frames_sent++;
1343

1344 1345
		if (skb_queue_is_last(&chan->tx_q, skb))
			chan->tx_send_head = NULL;
1346
		else
1347
			chan->tx_send_head = skb_queue_next(&chan->tx_q, skb);
1348 1349

		nsent++;
1350 1351
	}

1352 1353 1354
	return nsent;
}

1355
static int l2cap_retransmit_frames(struct l2cap_chan *chan)
1356 1357 1358
{
	int ret;

1359 1360
	if (!skb_queue_empty(&chan->tx_q))
		chan->tx_send_head = chan->tx_q.next;
1361

1362
	chan->next_tx_seq = chan->expected_ack_seq;
1363
	ret = l2cap_ertm_send(chan);
1364 1365 1366
	return ret;
}

1367
static void l2cap_send_ack(struct l2cap_chan *chan)
1368 1369 1370
{
	u16 control = 0;

1371
	control |= chan->buffer_seq << L2CAP_CTRL_REQSEQ_SHIFT;
1372

1373
	if (chan->conn_state & L2CAP_CONN_LOCAL_BUSY) {
1374
		control |= L2CAP_SUPER_RCV_NOT_READY;
1375 1376
		chan->conn_state |= L2CAP_CONN_RNR_SENT;
		l2cap_send_sframe(chan, control);
1377
		return;
1378
	}
1379

1380
	if (l2cap_ertm_send(chan) > 0)
1381 1382 1383
		return;

	control |= L2CAP_SUPER_RCV_READY;
1384
	l2cap_send_sframe(chan, control);
1385 1386
}

1387
static void l2cap_send_srejtail(struct l2cap_chan *chan)
1388 1389 1390 1391 1392 1393 1394
{
	struct srej_list *tail;
	u16 control;

	control = L2CAP_SUPER_SELECT_REJECT;
	control |= L2CAP_CTRL_FINAL;

1395
	tail = list_entry((&chan->srej_l)->prev, struct srej_list, list);
1396 1397
	control |= tail->tx_seq << L2CAP_CTRL_REQSEQ_SHIFT;

1398
	l2cap_send_sframe(chan, control);
1399 1400
}

1401 1402
static inline int l2cap_skbuff_fromiovec(struct sock *sk, struct msghdr *msg, int len, int count, struct sk_buff *skb)
{
1403
	struct l2cap_conn *conn = l2cap_pi(sk)->chan->conn;
1404 1405
	struct sk_buff **frag;
	int err, sent = 0;
L
Linus Torvalds 已提交
1406

1407
	if (memcpy_fromiovec(skb_put(skb, count), msg->msg_iov, count))
1408
		return -EFAULT;
L
Linus Torvalds 已提交
1409 1410 1411 1412 1413 1414 1415 1416 1417 1418 1419

	sent += count;
	len  -= count;

	/* Continuation fragments (no L2CAP header) */
	frag = &skb_shinfo(skb)->frag_list;
	while (len) {
		count = min_t(unsigned int, conn->mtu, len);

		*frag = bt_skb_send_alloc(sk, count, msg->msg_flags & MSG_DONTWAIT, &err);
		if (!*frag)
1420
			return err;
1421 1422
		if (memcpy_fromiovec(skb_put(*frag, count), msg->msg_iov, count))
			return -EFAULT;
L
Linus Torvalds 已提交
1423 1424 1425 1426 1427 1428 1429 1430

		sent += count;
		len  -= count;

		frag = &(*frag)->next;
	}

	return sent;
1431
}
L
Linus Torvalds 已提交
1432

1433
struct sk_buff *l2cap_create_connless_pdu(struct l2cap_chan *chan, struct msghdr *msg, size_t len)
1434
{
1435
	struct sock *sk = chan->sk;
1436
	struct l2cap_conn *conn = chan->conn;
1437 1438 1439 1440 1441 1442 1443 1444 1445 1446
	struct sk_buff *skb;
	int err, count, hlen = L2CAP_HDR_SIZE + 2;
	struct l2cap_hdr *lh;

	BT_DBG("sk %p len %d", sk, (int)len);

	count = min_t(unsigned int, (conn->mtu - hlen), len);
	skb = bt_skb_send_alloc(sk, count + hlen,
			msg->msg_flags & MSG_DONTWAIT, &err);
	if (!skb)
1447
		return ERR_PTR(err);
1448 1449 1450

	/* Create L2CAP header */
	lh = (struct l2cap_hdr *) skb_put(skb, L2CAP_HDR_SIZE);
1451
	lh->cid = cpu_to_le16(chan->dcid);
1452
	lh->len = cpu_to_le16(len + (hlen - L2CAP_HDR_SIZE));
1453
	put_unaligned_le16(chan->psm, skb_put(skb, 2));
1454 1455 1456 1457 1458 1459 1460 1461 1462

	err = l2cap_skbuff_fromiovec(sk, msg, len, count, skb);
	if (unlikely(err < 0)) {
		kfree_skb(skb);
		return ERR_PTR(err);
	}
	return skb;
}

1463
struct sk_buff *l2cap_create_basic_pdu(struct l2cap_chan *chan, struct msghdr *msg, size_t len)
1464
{
1465
	struct sock *sk = chan->sk;
1466
	struct l2cap_conn *conn = chan->conn;
1467 1468 1469 1470 1471 1472 1473 1474 1475 1476
	struct sk_buff *skb;
	int err, count, hlen = L2CAP_HDR_SIZE;
	struct l2cap_hdr *lh;

	BT_DBG("sk %p len %d", sk, (int)len);

	count = min_t(unsigned int, (conn->mtu - hlen), len);
	skb = bt_skb_send_alloc(sk, count + hlen,
			msg->msg_flags & MSG_DONTWAIT, &err);
	if (!skb)
1477
		return ERR_PTR(err);
1478 1479 1480

	/* Create L2CAP header */
	lh = (struct l2cap_hdr *) skb_put(skb, L2CAP_HDR_SIZE);
1481
	lh->cid = cpu_to_le16(chan->dcid);
1482 1483 1484 1485 1486 1487 1488 1489 1490 1491
	lh->len = cpu_to_le16(len + (hlen - L2CAP_HDR_SIZE));

	err = l2cap_skbuff_fromiovec(sk, msg, len, count, skb);
	if (unlikely(err < 0)) {
		kfree_skb(skb);
		return ERR_PTR(err);
	}
	return skb;
}

1492
struct sk_buff *l2cap_create_iframe_pdu(struct l2cap_chan *chan, struct msghdr *msg, size_t len, u16 control, u16 sdulen)
1493
{
1494
	struct sock *sk = chan->sk;
1495
	struct l2cap_conn *conn = chan->conn;
1496 1497 1498 1499 1500 1501
	struct sk_buff *skb;
	int err, count, hlen = L2CAP_HDR_SIZE + 2;
	struct l2cap_hdr *lh;

	BT_DBG("sk %p len %d", sk, (int)len);

1502 1503 1504
	if (!conn)
		return ERR_PTR(-ENOTCONN);

1505 1506 1507
	if (sdulen)
		hlen += 2;

1508
	if (chan->fcs == L2CAP_FCS_CRC16)
1509 1510
		hlen += 2;

1511 1512 1513 1514
	count = min_t(unsigned int, (conn->mtu - hlen), len);
	skb = bt_skb_send_alloc(sk, count + hlen,
			msg->msg_flags & MSG_DONTWAIT, &err);
	if (!skb)
1515
		return ERR_PTR(err);
1516 1517 1518

	/* Create L2CAP header */
	lh = (struct l2cap_hdr *) skb_put(skb, L2CAP_HDR_SIZE);
1519
	lh->cid = cpu_to_le16(chan->dcid);
1520 1521
	lh->len = cpu_to_le16(len + (hlen - L2CAP_HDR_SIZE));
	put_unaligned_le16(control, skb_put(skb, 2));
1522 1523
	if (sdulen)
		put_unaligned_le16(sdulen, skb_put(skb, 2));
1524 1525 1526 1527 1528 1529

	err = l2cap_skbuff_fromiovec(sk, msg, len, count, skb);
	if (unlikely(err < 0)) {
		kfree_skb(skb);
		return ERR_PTR(err);
	}
1530

1531
	if (chan->fcs == L2CAP_FCS_CRC16)
1532 1533
		put_unaligned_le16(0, skb_put(skb, 2));

1534
	bt_cb(skb)->retries = 0;
1535
	return skb;
L
Linus Torvalds 已提交
1536 1537
}

1538
int l2cap_sar_segment_sdu(struct l2cap_chan *chan, struct msghdr *msg, size_t len)
1539 1540 1541 1542 1543 1544
{
	struct sk_buff *skb;
	struct sk_buff_head sar_queue;
	u16 control;
	size_t size = 0;

1545
	skb_queue_head_init(&sar_queue);
1546
	control = L2CAP_SDU_START;
1547
	skb = l2cap_create_iframe_pdu(chan, msg, chan->remote_mps, control, len);
1548 1549 1550 1551
	if (IS_ERR(skb))
		return PTR_ERR(skb);

	__skb_queue_tail(&sar_queue, skb);
1552 1553
	len -= chan->remote_mps;
	size += chan->remote_mps;
1554 1555 1556 1557

	while (len > 0) {
		size_t buflen;

1558
		if (len > chan->remote_mps) {
1559
			control = L2CAP_SDU_CONTINUE;
1560
			buflen = chan->remote_mps;
1561
		} else {
1562
			control = L2CAP_SDU_END;
1563 1564 1565
			buflen = len;
		}

1566
		skb = l2cap_create_iframe_pdu(chan, msg, buflen, control, 0);
1567 1568 1569 1570 1571 1572 1573 1574 1575
		if (IS_ERR(skb)) {
			skb_queue_purge(&sar_queue);
			return PTR_ERR(skb);
		}

		__skb_queue_tail(&sar_queue, skb);
		len -= buflen;
		size += buflen;
	}
1576 1577 1578
	skb_queue_splice_tail(&sar_queue, &chan->tx_q);
	if (chan->tx_send_head == NULL)
		chan->tx_send_head = sar_queue.next;
1579 1580 1581 1582

	return size;
}

1583 1584 1585 1586 1587 1588 1589
int l2cap_chan_send(struct l2cap_chan *chan, struct msghdr *msg, size_t len)
{
	struct sk_buff *skb;
	u16 control;
	int err;

	/* Connectionless channel */
1590
	if (chan->chan_type == L2CAP_CHAN_CONN_LESS) {
1591 1592 1593 1594 1595 1596 1597 1598 1599 1600 1601 1602 1603 1604 1605 1606 1607 1608 1609 1610 1611 1612 1613 1614 1615 1616 1617 1618 1619 1620 1621 1622 1623 1624 1625 1626 1627 1628 1629 1630 1631 1632 1633 1634 1635 1636 1637 1638 1639 1640 1641 1642 1643 1644 1645 1646 1647 1648 1649 1650 1651 1652 1653 1654 1655 1656 1657 1658 1659 1660 1661
		skb = l2cap_create_connless_pdu(chan, msg, len);
		if (IS_ERR(skb))
			return PTR_ERR(skb);

		l2cap_do_send(chan, skb);
		return len;
	}

	switch (chan->mode) {
	case L2CAP_MODE_BASIC:
		/* Check outgoing MTU */
		if (len > chan->omtu)
			return -EMSGSIZE;

		/* Create a basic PDU */
		skb = l2cap_create_basic_pdu(chan, msg, len);
		if (IS_ERR(skb))
			return PTR_ERR(skb);

		l2cap_do_send(chan, skb);
		err = len;
		break;

	case L2CAP_MODE_ERTM:
	case L2CAP_MODE_STREAMING:
		/* Entire SDU fits into one PDU */
		if (len <= chan->remote_mps) {
			control = L2CAP_SDU_UNSEGMENTED;
			skb = l2cap_create_iframe_pdu(chan, msg, len, control,
									0);
			if (IS_ERR(skb))
				return PTR_ERR(skb);

			__skb_queue_tail(&chan->tx_q, skb);

			if (chan->tx_send_head == NULL)
				chan->tx_send_head = skb;

		} else {
			/* Segment SDU into multiples PDUs */
			err = l2cap_sar_segment_sdu(chan, msg, len);
			if (err < 0)
				return err;
		}

		if (chan->mode == L2CAP_MODE_STREAMING) {
			l2cap_streaming_send(chan);
			err = len;
			break;
		}

		if ((chan->conn_state & L2CAP_CONN_REMOTE_BUSY) &&
				(chan->conn_state & L2CAP_CONN_WAIT_F)) {
			err = len;
			break;
		}

		err = l2cap_ertm_send(chan);
		if (err >= 0)
			err = len;

		break;

	default:
		BT_DBG("bad state %1.1x", chan->mode);
		err = -EBADFD;
	}

	return err;
}

L
Linus Torvalds 已提交
1662 1663 1664
static void l2cap_chan_ready(struct sock *sk)
{
	struct sock *parent = bt_sk(sk)->parent;
1665
	struct l2cap_chan *chan = l2cap_pi(sk)->chan;
L
Linus Torvalds 已提交
1666 1667 1668

	BT_DBG("sk %p, parent %p", sk, parent);

1669
	chan->conf_state = 0;
1670
	l2cap_chan_clear_timer(chan);
L
Linus Torvalds 已提交
1671 1672 1673 1674 1675

	if (!parent) {
		/* Outgoing channel.
		 * Wake up socket sleeping on connect.
		 */
1676
		l2cap_state_change(chan, BT_CONNECTED);
L
Linus Torvalds 已提交
1677 1678 1679 1680 1681 1682 1683 1684 1685 1686 1687 1688 1689
		sk->sk_state_change(sk);
	} else {
		/* Incoming channel.
		 * Wake up socket sleeping on accept.
		 */
		parent->sk_data_ready(parent, 0);
	}
}

/* Copy frame to all raw sockets on that connection */
static void l2cap_raw_recv(struct l2cap_conn *conn, struct sk_buff *skb)
{
	struct sk_buff *nskb;
1690
	struct l2cap_chan *chan;
L
Linus Torvalds 已提交
1691 1692 1693

	BT_DBG("conn %p", conn);

1694 1695
	read_lock(&conn->chan_lock);
	list_for_each_entry(chan, &conn->chan_l, list) {
1696
		struct sock *sk = chan->sk;
1697
		if (chan->chan_type != L2CAP_CHAN_RAW)
L
Linus Torvalds 已提交
1698 1699 1700 1701 1702
			continue;

		/* Don't send frame to the socket it came from */
		if (skb->sk == sk)
			continue;
1703 1704
		nskb = skb_clone(skb, GFP_ATOMIC);
		if (!nskb)
L
Linus Torvalds 已提交
1705 1706
			continue;

1707
		if (chan->ops->recv(chan->data, nskb))
L
Linus Torvalds 已提交
1708 1709
			kfree_skb(nskb);
	}
1710
	read_unlock(&conn->chan_lock);
L
Linus Torvalds 已提交
1711 1712 1713 1714 1715 1716 1717 1718 1719 1720 1721
}

/* ---- L2CAP signalling commands ---- */
static struct sk_buff *l2cap_build_cmd(struct l2cap_conn *conn,
				u8 code, u8 ident, u16 dlen, void *data)
{
	struct sk_buff *skb, **frag;
	struct l2cap_cmd_hdr *cmd;
	struct l2cap_hdr *lh;
	int len, count;

1722 1723
	BT_DBG("conn %p, code 0x%2.2x, ident 0x%2.2x, len %d",
			conn, code, ident, dlen);
L
Linus Torvalds 已提交
1724 1725 1726 1727 1728 1729 1730 1731 1732

	len = L2CAP_HDR_SIZE + L2CAP_CMD_HDR_SIZE + dlen;
	count = min_t(unsigned int, conn->mtu, len);

	skb = bt_skb_alloc(count, GFP_ATOMIC);
	if (!skb)
		return NULL;

	lh = (struct l2cap_hdr *) skb_put(skb, L2CAP_HDR_SIZE);
1733
	lh->len = cpu_to_le16(L2CAP_CMD_HDR_SIZE + dlen);
1734 1735 1736 1737 1738

	if (conn->hcon->type == LE_LINK)
		lh->cid = cpu_to_le16(L2CAP_CID_LE_SIGNALING);
	else
		lh->cid = cpu_to_le16(L2CAP_CID_SIGNALING);
L
Linus Torvalds 已提交
1739 1740 1741 1742

	cmd = (struct l2cap_cmd_hdr *) skb_put(skb, L2CAP_CMD_HDR_SIZE);
	cmd->code  = code;
	cmd->ident = ident;
1743
	cmd->len   = cpu_to_le16(dlen);
L
Linus Torvalds 已提交
1744 1745 1746 1747 1748 1749 1750 1751 1752 1753 1754 1755 1756 1757 1758 1759 1760 1761 1762 1763 1764 1765 1766 1767 1768 1769 1770 1771 1772 1773 1774 1775 1776 1777 1778 1779 1780 1781 1782 1783 1784 1785 1786 1787 1788 1789 1790 1791 1792 1793

	if (dlen) {
		count -= L2CAP_HDR_SIZE + L2CAP_CMD_HDR_SIZE;
		memcpy(skb_put(skb, count), data, count);
		data += count;
	}

	len -= skb->len;

	/* Continuation fragments (no L2CAP header) */
	frag = &skb_shinfo(skb)->frag_list;
	while (len) {
		count = min_t(unsigned int, conn->mtu, len);

		*frag = bt_skb_alloc(count, GFP_ATOMIC);
		if (!*frag)
			goto fail;

		memcpy(skb_put(*frag, count), data, count);

		len  -= count;
		data += count;

		frag = &(*frag)->next;
	}

	return skb;

fail:
	kfree_skb(skb);
	return NULL;
}

static inline int l2cap_get_conf_opt(void **ptr, int *type, int *olen, unsigned long *val)
{
	struct l2cap_conf_opt *opt = *ptr;
	int len;

	len = L2CAP_CONF_OPT_SIZE + opt->len;
	*ptr += len;

	*type = opt->type;
	*olen = opt->len;

	switch (opt->len) {
	case 1:
		*val = *((u8 *) opt->val);
		break;

	case 2:
1794
		*val = get_unaligned_le16(opt->val);
L
Linus Torvalds 已提交
1795 1796 1797
		break;

	case 4:
1798
		*val = get_unaligned_le32(opt->val);
L
Linus Torvalds 已提交
1799 1800 1801 1802 1803 1804 1805 1806 1807 1808 1809 1810 1811 1812 1813 1814 1815 1816 1817 1818 1819 1820 1821 1822 1823 1824
		break;

	default:
		*val = (unsigned long) opt->val;
		break;
	}

	BT_DBG("type 0x%2.2x len %d val 0x%lx", *type, opt->len, *val);
	return len;
}

static void l2cap_add_conf_opt(void **ptr, u8 type, u8 len, unsigned long val)
{
	struct l2cap_conf_opt *opt = *ptr;

	BT_DBG("type 0x%2.2x len %d val 0x%lx", type, len, val);

	opt->type = type;
	opt->len  = len;

	switch (len) {
	case 1:
		*((u8 *) opt->val)  = val;
		break;

	case 2:
1825
		put_unaligned_le16(val, opt->val);
L
Linus Torvalds 已提交
1826 1827 1828
		break;

	case 4:
1829
		put_unaligned_le32(val, opt->val);
L
Linus Torvalds 已提交
1830 1831 1832 1833 1834 1835 1836 1837 1838 1839
		break;

	default:
		memcpy(opt->val, (void *) val, len);
		break;
	}

	*ptr += L2CAP_CONF_OPT_SIZE + len;
}

1840 1841
static void l2cap_ack_timeout(unsigned long arg)
{
1842
	struct l2cap_chan *chan = (void *) arg;
1843

1844 1845 1846
	bh_lock_sock(chan->sk);
	l2cap_send_ack(chan);
	bh_unlock_sock(chan->sk);
1847 1848
}

1849
static inline void l2cap_ertm_init(struct l2cap_chan *chan)
1850
{
1851 1852
	struct sock *sk = chan->sk;

1853
	chan->expected_ack_seq = 0;
1854
	chan->unacked_frames = 0;
1855
	chan->buffer_seq = 0;
1856 1857
	chan->num_acked = 0;
	chan->frames_sent = 0;
1858

1859 1860 1861 1862 1863
	setup_timer(&chan->retrans_timer, l2cap_retrans_timeout,
							(unsigned long) chan);
	setup_timer(&chan->monitor_timer, l2cap_monitor_timeout,
							(unsigned long) chan);
	setup_timer(&chan->ack_timer, l2cap_ack_timeout, (unsigned long) chan);
1864

1865 1866
	skb_queue_head_init(&chan->srej_q);
	skb_queue_head_init(&chan->busy_q);
1867

1868 1869
	INIT_LIST_HEAD(&chan->srej_l);

1870
	INIT_WORK(&chan->busy_work, l2cap_busy_work);
1871 1872

	sk->sk_backlog_rcv = l2cap_ertm_data_rcv;
1873 1874
}

1875 1876 1877 1878 1879 1880 1881 1882 1883 1884 1885 1886 1887
static inline __u8 l2cap_select_mode(__u8 mode, __u16 remote_feat_mask)
{
	switch (mode) {
	case L2CAP_MODE_STREAMING:
	case L2CAP_MODE_ERTM:
		if (l2cap_mode_supported(mode, remote_feat_mask))
			return mode;
		/* fall through */
	default:
		return L2CAP_MODE_BASIC;
	}
}

1888
static int l2cap_build_conf_req(struct l2cap_chan *chan, void *data)
L
Linus Torvalds 已提交
1889 1890
{
	struct l2cap_conf_req *req = data;
1891
	struct l2cap_conf_rfc rfc = { .mode = chan->mode };
L
Linus Torvalds 已提交
1892 1893
	void *ptr = req->data;

1894
	BT_DBG("chan %p", chan);
L
Linus Torvalds 已提交
1895

1896
	if (chan->num_conf_req || chan->num_conf_rsp)
1897 1898
		goto done;

1899
	switch (chan->mode) {
1900 1901
	case L2CAP_MODE_STREAMING:
	case L2CAP_MODE_ERTM:
1902
		if (chan->conf_state & L2CAP_CONF_STATE2_DEVICE)
1903 1904
			break;

1905
		/* fall through */
1906
	default:
1907
		chan->mode = l2cap_select_mode(rfc.mode, chan->conn->feat_mask);
1908 1909 1910 1911
		break;
	}

done:
1912 1913
	if (chan->imtu != L2CAP_DEFAULT_MTU)
		l2cap_add_conf_opt(&ptr, L2CAP_CONF_MTU, 2, chan->imtu);
1914

1915
	switch (chan->mode) {
1916
	case L2CAP_MODE_BASIC:
1917 1918
		if (!(chan->conn->feat_mask & L2CAP_FEAT_ERTM) &&
				!(chan->conn->feat_mask & L2CAP_FEAT_STREAMING))
1919 1920
			break;

1921 1922 1923 1924 1925 1926 1927
		rfc.mode            = L2CAP_MODE_BASIC;
		rfc.txwin_size      = 0;
		rfc.max_transmit    = 0;
		rfc.retrans_timeout = 0;
		rfc.monitor_timeout = 0;
		rfc.max_pdu_size    = 0;

1928 1929
		l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC, sizeof(rfc),
							(unsigned long) &rfc);
1930 1931 1932 1933
		break;

	case L2CAP_MODE_ERTM:
		rfc.mode            = L2CAP_MODE_ERTM;
1934 1935
		rfc.txwin_size      = chan->tx_win;
		rfc.max_transmit    = chan->max_tx;
1936 1937
		rfc.retrans_timeout = 0;
		rfc.monitor_timeout = 0;
1938
		rfc.max_pdu_size    = cpu_to_le16(L2CAP_DEFAULT_MAX_PDU_SIZE);
1939 1940
		if (L2CAP_DEFAULT_MAX_PDU_SIZE > chan->conn->mtu - 10)
			rfc.max_pdu_size = cpu_to_le16(chan->conn->mtu - 10);
1941

1942 1943 1944
		l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC, sizeof(rfc),
							(unsigned long) &rfc);

1945
		if (!(chan->conn->feat_mask & L2CAP_FEAT_FCS))
1946 1947
			break;

1948
		if (chan->fcs == L2CAP_FCS_NONE ||
1949
				chan->conf_state & L2CAP_CONF_NO_FCS_RECV) {
1950 1951
			chan->fcs = L2CAP_FCS_NONE;
			l2cap_add_conf_opt(&ptr, L2CAP_CONF_FCS, 1, chan->fcs);
1952
		}
1953 1954 1955 1956 1957 1958 1959 1960
		break;

	case L2CAP_MODE_STREAMING:
		rfc.mode            = L2CAP_MODE_STREAMING;
		rfc.txwin_size      = 0;
		rfc.max_transmit    = 0;
		rfc.retrans_timeout = 0;
		rfc.monitor_timeout = 0;
1961
		rfc.max_pdu_size    = cpu_to_le16(L2CAP_DEFAULT_MAX_PDU_SIZE);
1962 1963
		if (L2CAP_DEFAULT_MAX_PDU_SIZE > chan->conn->mtu - 10)
			rfc.max_pdu_size = cpu_to_le16(chan->conn->mtu - 10);
1964

1965 1966 1967
		l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC, sizeof(rfc),
							(unsigned long) &rfc);

1968
		if (!(chan->conn->feat_mask & L2CAP_FEAT_FCS))
1969 1970
			break;

1971
		if (chan->fcs == L2CAP_FCS_NONE ||
1972
				chan->conf_state & L2CAP_CONF_NO_FCS_RECV) {
1973 1974
			chan->fcs = L2CAP_FCS_NONE;
			l2cap_add_conf_opt(&ptr, L2CAP_CONF_FCS, 1, chan->fcs);
1975
		}
1976 1977
		break;
	}
L
Linus Torvalds 已提交
1978

1979
	req->dcid  = cpu_to_le16(chan->dcid);
1980
	req->flags = cpu_to_le16(0);
L
Linus Torvalds 已提交
1981 1982 1983 1984

	return ptr - data;
}

1985
static int l2cap_parse_conf_req(struct l2cap_chan *chan, void *data)
L
Linus Torvalds 已提交
1986
{
1987 1988
	struct l2cap_conf_rsp *rsp = data;
	void *ptr = rsp->data;
1989 1990
	void *req = chan->conf_req;
	int len = chan->conf_len;
1991 1992
	int type, hint, olen;
	unsigned long val;
1993
	struct l2cap_conf_rfc rfc = { .mode = L2CAP_MODE_BASIC };
1994
	u16 mtu = L2CAP_DEFAULT_MTU;
1995
	u16 result = L2CAP_CONF_SUCCESS;
L
Linus Torvalds 已提交
1996

1997
	BT_DBG("chan %p", chan);
1998

1999 2000
	while (len >= L2CAP_CONF_OPT_SIZE) {
		len -= l2cap_get_conf_opt(&req, &type, &olen, &val);
L
Linus Torvalds 已提交
2001

2002
		hint  = type & L2CAP_CONF_HINT;
2003
		type &= L2CAP_CONF_MASK;
2004 2005 2006

		switch (type) {
		case L2CAP_CONF_MTU:
2007
			mtu = val;
2008 2009 2010
			break;

		case L2CAP_CONF_FLUSH_TO:
2011
			chan->flush_to = val;
2012 2013 2014 2015 2016
			break;

		case L2CAP_CONF_QOS:
			break;

2017 2018 2019 2020 2021
		case L2CAP_CONF_RFC:
			if (olen == sizeof(rfc))
				memcpy(&rfc, (void *) val, olen);
			break;

2022 2023
		case L2CAP_CONF_FCS:
			if (val == L2CAP_FCS_NONE)
2024
				chan->conf_state |= L2CAP_CONF_NO_FCS_RECV;
2025 2026 2027

			break;

2028 2029 2030 2031 2032 2033 2034 2035 2036 2037
		default:
			if (hint)
				break;

			result = L2CAP_CONF_UNKNOWN;
			*((u8 *) ptr++) = type;
			break;
		}
	}

2038
	if (chan->num_conf_rsp || chan->num_conf_req > 1)
2039 2040
		goto done;

2041
	switch (chan->mode) {
2042 2043
	case L2CAP_MODE_STREAMING:
	case L2CAP_MODE_ERTM:
2044
		if (!(chan->conf_state & L2CAP_CONF_STATE2_DEVICE)) {
2045
			chan->mode = l2cap_select_mode(rfc.mode,
2046
					chan->conn->feat_mask);
2047 2048 2049
			break;
		}

2050
		if (chan->mode != rfc.mode)
2051
			return -ECONNREFUSED;
2052

2053 2054 2055 2056
		break;
	}

done:
2057
	if (chan->mode != rfc.mode) {
2058
		result = L2CAP_CONF_UNACCEPT;
2059
		rfc.mode = chan->mode;
2060

2061
		if (chan->num_conf_rsp == 1)
2062 2063 2064 2065 2066 2067 2068
			return -ECONNREFUSED;

		l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC,
					sizeof(rfc), (unsigned long) &rfc);
	}


2069 2070 2071 2072
	if (result == L2CAP_CONF_SUCCESS) {
		/* Configure output options and let the other side know
		 * which ones we don't like. */

2073 2074 2075
		if (mtu < L2CAP_DEFAULT_MIN_MTU)
			result = L2CAP_CONF_UNACCEPT;
		else {
2076
			chan->omtu = mtu;
2077
			chan->conf_state |= L2CAP_CONF_MTU_DONE;
2078
		}
2079
		l2cap_add_conf_opt(&ptr, L2CAP_CONF_MTU, 2, chan->omtu);
2080

2081 2082
		switch (rfc.mode) {
		case L2CAP_MODE_BASIC:
2083
			chan->fcs = L2CAP_FCS_NONE;
2084
			chan->conf_state |= L2CAP_CONF_MODE_DONE;
2085 2086 2087
			break;

		case L2CAP_MODE_ERTM:
2088 2089
			chan->remote_tx_win = rfc.txwin_size;
			chan->remote_max_tx = rfc.max_transmit;
2090

2091 2092
			if (le16_to_cpu(rfc.max_pdu_size) > chan->conn->mtu - 10)
				rfc.max_pdu_size = cpu_to_le16(chan->conn->mtu - 10);
2093

2094
			chan->remote_mps = le16_to_cpu(rfc.max_pdu_size);
2095

2096 2097 2098 2099
			rfc.retrans_timeout =
				le16_to_cpu(L2CAP_DEFAULT_RETRANS_TO);
			rfc.monitor_timeout =
				le16_to_cpu(L2CAP_DEFAULT_MONITOR_TO);
2100

2101
			chan->conf_state |= L2CAP_CONF_MODE_DONE;
2102 2103 2104 2105

			l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC,
					sizeof(rfc), (unsigned long) &rfc);

2106 2107 2108
			break;

		case L2CAP_MODE_STREAMING:
2109 2110
			if (le16_to_cpu(rfc.max_pdu_size) > chan->conn->mtu - 10)
				rfc.max_pdu_size = cpu_to_le16(chan->conn->mtu - 10);
2111

2112
			chan->remote_mps = le16_to_cpu(rfc.max_pdu_size);
2113

2114
			chan->conf_state |= L2CAP_CONF_MODE_DONE;
2115 2116 2117 2118

			l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC,
					sizeof(rfc), (unsigned long) &rfc);

2119 2120 2121
			break;

		default:
2122 2123
			result = L2CAP_CONF_UNACCEPT;

2124
			memset(&rfc, 0, sizeof(rfc));
2125
			rfc.mode = chan->mode;
2126
		}
2127

2128
		if (result == L2CAP_CONF_SUCCESS)
2129
			chan->conf_state |= L2CAP_CONF_OUTPUT_DONE;
2130
	}
2131
	rsp->scid   = cpu_to_le16(chan->dcid);
2132 2133 2134 2135
	rsp->result = cpu_to_le16(result);
	rsp->flags  = cpu_to_le16(0x0000);

	return ptr - data;
L
Linus Torvalds 已提交
2136 2137
}

2138
static int l2cap_parse_conf_rsp(struct l2cap_chan *chan, void *rsp, int len, void *data, u16 *result)
2139 2140 2141 2142 2143 2144 2145
{
	struct l2cap_conf_req *req = data;
	void *ptr = req->data;
	int type, olen;
	unsigned long val;
	struct l2cap_conf_rfc rfc;

2146
	BT_DBG("chan %p, rsp %p, len %d, req %p", chan, rsp, len, data);
2147 2148 2149 2150 2151 2152 2153 2154

	while (len >= L2CAP_CONF_OPT_SIZE) {
		len -= l2cap_get_conf_opt(&rsp, &type, &olen, &val);

		switch (type) {
		case L2CAP_CONF_MTU:
			if (val < L2CAP_DEFAULT_MIN_MTU) {
				*result = L2CAP_CONF_UNACCEPT;
2155
				chan->imtu = L2CAP_DEFAULT_MIN_MTU;
2156
			} else
2157 2158
				chan->imtu = val;
			l2cap_add_conf_opt(&ptr, L2CAP_CONF_MTU, 2, chan->imtu);
2159 2160 2161
			break;

		case L2CAP_CONF_FLUSH_TO:
2162
			chan->flush_to = val;
2163
			l2cap_add_conf_opt(&ptr, L2CAP_CONF_FLUSH_TO,
2164
							2, chan->flush_to);
2165 2166 2167 2168 2169 2170
			break;

		case L2CAP_CONF_RFC:
			if (olen == sizeof(rfc))
				memcpy(&rfc, (void *)val, olen);

2171
			if ((chan->conf_state & L2CAP_CONF_STATE2_DEVICE) &&
2172
							rfc.mode != chan->mode)
2173 2174
				return -ECONNREFUSED;

2175
			chan->fcs = 0;
2176 2177 2178 2179 2180 2181 2182

			l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC,
					sizeof(rfc), (unsigned long) &rfc);
			break;
		}
	}

2183
	if (chan->mode == L2CAP_MODE_BASIC && chan->mode != rfc.mode)
2184 2185
		return -ECONNREFUSED;

2186
	chan->mode = rfc.mode;
2187

2188 2189 2190
	if (*result == L2CAP_CONF_SUCCESS) {
		switch (rfc.mode) {
		case L2CAP_MODE_ERTM:
2191 2192 2193
			chan->retrans_timeout = le16_to_cpu(rfc.retrans_timeout);
			chan->monitor_timeout = le16_to_cpu(rfc.monitor_timeout);
			chan->mps    = le16_to_cpu(rfc.max_pdu_size);
2194 2195
			break;
		case L2CAP_MODE_STREAMING:
2196
			chan->mps    = le16_to_cpu(rfc.max_pdu_size);
2197 2198 2199
		}
	}

2200
	req->dcid   = cpu_to_le16(chan->dcid);
2201 2202 2203 2204 2205
	req->flags  = cpu_to_le16(0x0000);

	return ptr - data;
}

2206
static int l2cap_build_conf_rsp(struct l2cap_chan *chan, void *data, u16 result, u16 flags)
L
Linus Torvalds 已提交
2207 2208 2209 2210
{
	struct l2cap_conf_rsp *rsp = data;
	void *ptr = rsp->data;

2211
	BT_DBG("chan %p", chan);
L
Linus Torvalds 已提交
2212

2213
	rsp->scid   = cpu_to_le16(chan->dcid);
2214
	rsp->result = cpu_to_le16(result);
2215
	rsp->flags  = cpu_to_le16(flags);
L
Linus Torvalds 已提交
2216 2217 2218 2219

	return ptr - data;
}

2220
void __l2cap_connect_rsp_defer(struct l2cap_chan *chan)
2221 2222
{
	struct l2cap_conn_rsp rsp;
2223
	struct l2cap_conn *conn = chan->conn;
2224 2225
	u8 buf[128];

2226 2227
	rsp.scid   = cpu_to_le16(chan->dcid);
	rsp.dcid   = cpu_to_le16(chan->scid);
2228 2229 2230 2231 2232
	rsp.result = cpu_to_le16(L2CAP_CR_SUCCESS);
	rsp.status = cpu_to_le16(L2CAP_CS_NO_INFO);
	l2cap_send_cmd(conn, chan->ident,
				L2CAP_CONN_RSP, sizeof(rsp), &rsp);

2233
	if (chan->conf_state & L2CAP_CONF_REQ_SENT)
2234 2235
		return;

2236
	chan->conf_state |= L2CAP_CONF_REQ_SENT;
2237 2238 2239 2240 2241
	l2cap_send_cmd(conn, l2cap_get_ident(conn), L2CAP_CONF_REQ,
			l2cap_build_conf_req(chan, buf), buf);
	chan->num_conf_req++;
}

2242
static void l2cap_conf_rfc_get(struct l2cap_chan *chan, void *rsp, int len)
2243 2244 2245 2246 2247
{
	int type, olen;
	unsigned long val;
	struct l2cap_conf_rfc rfc;

2248
	BT_DBG("chan %p, rsp %p, len %d", chan, rsp, len);
2249

2250
	if ((chan->mode != L2CAP_MODE_ERTM) && (chan->mode != L2CAP_MODE_STREAMING))
2251 2252 2253 2254 2255 2256 2257 2258 2259 2260 2261 2262 2263 2264 2265 2266
		return;

	while (len >= L2CAP_CONF_OPT_SIZE) {
		len -= l2cap_get_conf_opt(&rsp, &type, &olen, &val);

		switch (type) {
		case L2CAP_CONF_RFC:
			if (olen == sizeof(rfc))
				memcpy(&rfc, (void *)val, olen);
			goto done;
		}
	}

done:
	switch (rfc.mode) {
	case L2CAP_MODE_ERTM:
2267 2268 2269
		chan->retrans_timeout = le16_to_cpu(rfc.retrans_timeout);
		chan->monitor_timeout = le16_to_cpu(rfc.monitor_timeout);
		chan->mps    = le16_to_cpu(rfc.max_pdu_size);
2270 2271
		break;
	case L2CAP_MODE_STREAMING:
2272
		chan->mps    = le16_to_cpu(rfc.max_pdu_size);
2273 2274 2275
	}
}

2276 2277 2278 2279 2280 2281 2282 2283 2284 2285
static inline int l2cap_command_rej(struct l2cap_conn *conn, struct l2cap_cmd_hdr *cmd, u8 *data)
{
	struct l2cap_cmd_rej *rej = (struct l2cap_cmd_rej *) data;

	if (rej->reason != 0x0000)
		return 0;

	if ((conn->info_state & L2CAP_INFO_FEAT_MASK_REQ_SENT) &&
					cmd->ident == conn->info_ident) {
		del_timer(&conn->info_timer);
2286 2287

		conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_DONE;
2288
		conn->info_ident = 0;
2289

2290 2291 2292 2293 2294 2295
		l2cap_conn_start(conn);
	}

	return 0;
}

L
Linus Torvalds 已提交
2296 2297 2298 2299
static inline int l2cap_connect_req(struct l2cap_conn *conn, struct l2cap_cmd_hdr *cmd, u8 *data)
{
	struct l2cap_conn_req *req = (struct l2cap_conn_req *) data;
	struct l2cap_conn_rsp rsp;
2300
	struct l2cap_chan *chan = NULL, *pchan;
2301
	struct sock *parent, *sk = NULL;
2302
	int result, status = L2CAP_CS_NO_INFO;
L
Linus Torvalds 已提交
2303 2304

	u16 dcid = 0, scid = __le16_to_cpu(req->scid);
2305
	__le16 psm = req->psm;
L
Linus Torvalds 已提交
2306 2307 2308 2309

	BT_DBG("psm 0x%2.2x scid 0x%4.4x", psm, scid);

	/* Check if we have socket listening on psm */
2310 2311
	pchan = l2cap_global_chan_by_psm(BT_LISTEN, psm, conn->src);
	if (!pchan) {
L
Linus Torvalds 已提交
2312 2313 2314 2315
		result = L2CAP_CR_BAD_PSM;
		goto sendresp;
	}

2316 2317
	parent = pchan->sk;

2318 2319
	bh_lock_sock(parent);

2320 2321 2322
	/* Check if the ACL is secure enough (if not SDP) */
	if (psm != cpu_to_le16(0x0001) &&
				!hci_conn_check_link_mode(conn->hcon)) {
2323
		conn->disc_reason = 0x05;
2324 2325 2326 2327
		result = L2CAP_CR_SEC_BLOCK;
		goto response;
	}

L
Linus Torvalds 已提交
2328 2329 2330 2331
	result = L2CAP_CR_NO_MEM;

	/* Check for backlog size */
	if (sk_acceptq_is_full(parent)) {
2332
		BT_DBG("backlog full %d", parent->sk_ack_backlog);
L
Linus Torvalds 已提交
2333 2334 2335
		goto response;
	}

2336 2337
	chan = pchan->ops->new_connection(pchan->data);
	if (!chan)
L
Linus Torvalds 已提交
2338 2339
		goto response;

2340 2341
	sk = chan->sk;

2342
	write_lock_bh(&conn->chan_lock);
L
Linus Torvalds 已提交
2343 2344

	/* Check if we already have channel with that dcid */
2345 2346
	if (__l2cap_get_chan_by_dcid(conn, scid)) {
		write_unlock_bh(&conn->chan_lock);
L
Linus Torvalds 已提交
2347
		sock_set_flag(sk, SOCK_ZAPPED);
2348
		chan->ops->close(chan->data);
L
Linus Torvalds 已提交
2349 2350 2351 2352 2353 2354 2355
		goto response;
	}

	hci_conn_hold(conn->hcon);

	bacpy(&bt_sk(sk)->src, conn->src);
	bacpy(&bt_sk(sk)->dst, conn->dst);
2356 2357
	chan->psm  = psm;
	chan->dcid = scid;
L
Linus Torvalds 已提交
2358

2359 2360
	bt_accept_enqueue(parent, sk);

2361 2362
	__l2cap_chan_add(conn, chan);

2363
	dcid = chan->scid;
L
Linus Torvalds 已提交
2364

2365
	l2cap_chan_set_timer(chan, sk->sk_sndtimeo);
L
Linus Torvalds 已提交
2366

2367
	chan->ident = cmd->ident;
L
Linus Torvalds 已提交
2368

2369
	if (conn->info_state & L2CAP_INFO_FEAT_MASK_REQ_DONE) {
2370
		if (l2cap_check_security(chan)) {
2371
			if (bt_sk(sk)->defer_setup) {
2372
				l2cap_state_change(chan, BT_CONNECT2);
2373 2374 2375 2376
				result = L2CAP_CR_PEND;
				status = L2CAP_CS_AUTHOR_PEND;
				parent->sk_data_ready(parent, 0);
			} else {
2377
				l2cap_state_change(chan, BT_CONFIG);
2378 2379 2380
				result = L2CAP_CR_SUCCESS;
				status = L2CAP_CS_NO_INFO;
			}
2381
		} else {
2382
			l2cap_state_change(chan, BT_CONNECT2);
2383 2384 2385 2386
			result = L2CAP_CR_PEND;
			status = L2CAP_CS_AUTHEN_PEND;
		}
	} else {
2387
		l2cap_state_change(chan, BT_CONNECT2);
2388 2389
		result = L2CAP_CR_PEND;
		status = L2CAP_CS_NO_INFO;
L
Linus Torvalds 已提交
2390 2391
	}

2392
	write_unlock_bh(&conn->chan_lock);
L
Linus Torvalds 已提交
2393 2394 2395 2396 2397

response:
	bh_unlock_sock(parent);

sendresp:
2398 2399 2400 2401
	rsp.scid   = cpu_to_le16(scid);
	rsp.dcid   = cpu_to_le16(dcid);
	rsp.result = cpu_to_le16(result);
	rsp.status = cpu_to_le16(status);
L
Linus Torvalds 已提交
2402
	l2cap_send_cmd(conn, cmd->ident, L2CAP_CONN_RSP, sizeof(rsp), &rsp);
2403 2404 2405 2406 2407 2408 2409 2410 2411 2412 2413 2414 2415 2416 2417

	if (result == L2CAP_CR_PEND && status == L2CAP_CS_NO_INFO) {
		struct l2cap_info_req info;
		info.type = cpu_to_le16(L2CAP_IT_FEAT_MASK);

		conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_SENT;
		conn->info_ident = l2cap_get_ident(conn);

		mod_timer(&conn->info_timer, jiffies +
					msecs_to_jiffies(L2CAP_INFO_TIMEOUT));

		l2cap_send_cmd(conn, conn->info_ident,
					L2CAP_INFO_REQ, sizeof(info), &info);
	}

2418
	if (chan && !(chan->conf_state & L2CAP_CONF_REQ_SENT) &&
2419 2420
				result == L2CAP_CR_SUCCESS) {
		u8 buf[128];
2421
		chan->conf_state |= L2CAP_CONF_REQ_SENT;
2422
		l2cap_send_cmd(conn, l2cap_get_ident(conn), L2CAP_CONF_REQ,
2423 2424
					l2cap_build_conf_req(chan, buf), buf);
		chan->num_conf_req++;
2425 2426
	}

L
Linus Torvalds 已提交
2427 2428 2429 2430 2431 2432 2433
	return 0;
}

static inline int l2cap_connect_rsp(struct l2cap_conn *conn, struct l2cap_cmd_hdr *cmd, u8 *data)
{
	struct l2cap_conn_rsp *rsp = (struct l2cap_conn_rsp *) data;
	u16 scid, dcid, result, status;
2434
	struct l2cap_chan *chan;
L
Linus Torvalds 已提交
2435 2436 2437 2438 2439 2440 2441 2442 2443 2444 2445
	struct sock *sk;
	u8 req[128];

	scid   = __le16_to_cpu(rsp->scid);
	dcid   = __le16_to_cpu(rsp->dcid);
	result = __le16_to_cpu(rsp->result);
	status = __le16_to_cpu(rsp->status);

	BT_DBG("dcid 0x%4.4x scid 0x%4.4x result 0x%2.2x status 0x%2.2x", dcid, scid, result, status);

	if (scid) {
2446
		chan = l2cap_get_chan_by_scid(conn, scid);
2447
		if (!chan)
2448
			return -EFAULT;
L
Linus Torvalds 已提交
2449
	} else {
2450
		chan = l2cap_get_chan_by_ident(conn, cmd->ident);
2451
		if (!chan)
2452
			return -EFAULT;
L
Linus Torvalds 已提交
2453 2454
	}

2455 2456
	sk = chan->sk;

L
Linus Torvalds 已提交
2457 2458
	switch (result) {
	case L2CAP_CR_SUCCESS:
2459
		l2cap_state_change(chan, BT_CONFIG);
2460
		chan->ident = 0;
2461
		chan->dcid = dcid;
2462
		chan->conf_state &= ~L2CAP_CONF_CONNECT_PEND;
2463

2464
		if (chan->conf_state & L2CAP_CONF_REQ_SENT)
2465 2466
			break;

2467
		chan->conf_state |= L2CAP_CONF_REQ_SENT;
2468

L
Linus Torvalds 已提交
2469
		l2cap_send_cmd(conn, l2cap_get_ident(conn), L2CAP_CONF_REQ,
2470 2471
					l2cap_build_conf_req(chan, req), req);
		chan->num_conf_req++;
L
Linus Torvalds 已提交
2472 2473 2474
		break;

	case L2CAP_CR_PEND:
2475
		chan->conf_state |= L2CAP_CONF_CONNECT_PEND;
L
Linus Torvalds 已提交
2476 2477 2478
		break;

	default:
2479 2480
		/* don't delete l2cap channel if sk is owned by user */
		if (sock_owned_by_user(sk)) {
2481
			l2cap_state_change(chan, BT_DISCONN);
2482 2483
			l2cap_chan_clear_timer(chan);
			l2cap_chan_set_timer(chan, HZ / 5);
2484 2485 2486
			break;
		}

2487
		l2cap_chan_del(chan, ECONNREFUSED);
L
Linus Torvalds 已提交
2488 2489 2490 2491 2492 2493 2494
		break;
	}

	bh_unlock_sock(sk);
	return 0;
}

2495
static inline void set_default_fcs(struct l2cap_chan *chan)
2496
{
2497 2498
	struct l2cap_pinfo *pi = l2cap_pi(chan->sk);

2499 2500 2501
	/* FCS is enabled only in ERTM or streaming mode, if one or both
	 * sides request it.
	 */
2502
	if (chan->mode != L2CAP_MODE_ERTM && chan->mode != L2CAP_MODE_STREAMING)
2503
		chan->fcs = L2CAP_FCS_NONE;
2504
	else if (!(pi->chan->conf_state & L2CAP_CONF_NO_FCS_RECV))
2505
		chan->fcs = L2CAP_FCS_CRC16;
2506 2507
}

2508
static inline int l2cap_config_req(struct l2cap_conn *conn, struct l2cap_cmd_hdr *cmd, u16 cmd_len, u8 *data)
L
Linus Torvalds 已提交
2509 2510 2511 2512
{
	struct l2cap_conf_req *req = (struct l2cap_conf_req *) data;
	u16 dcid, flags;
	u8 rsp[64];
2513
	struct l2cap_chan *chan;
L
Linus Torvalds 已提交
2514
	struct sock *sk;
2515
	int len;
L
Linus Torvalds 已提交
2516 2517 2518 2519 2520 2521

	dcid  = __le16_to_cpu(req->dcid);
	flags = __le16_to_cpu(req->flags);

	BT_DBG("dcid 0x%4.4x flags 0x%2.2x", dcid, flags);

2522
	chan = l2cap_get_chan_by_scid(conn, dcid);
2523
	if (!chan)
L
Linus Torvalds 已提交
2524 2525
		return -ENOENT;

2526 2527
	sk = chan->sk;

2528
	if (chan->state != BT_CONFIG) {
2529 2530 2531 2532 2533
		struct l2cap_cmd_rej rej;

		rej.reason = cpu_to_le16(0x0002);
		l2cap_send_cmd(conn, cmd->ident, L2CAP_COMMAND_REJ,
				sizeof(rej), &rej);
2534
		goto unlock;
2535
	}
2536

2537
	/* Reject if config buffer is too small. */
2538
	len = cmd_len - sizeof(*req);
2539
	if (chan->conf_len + len > sizeof(chan->conf_req)) {
2540
		l2cap_send_cmd(conn, cmd->ident, L2CAP_CONF_RSP,
2541
				l2cap_build_conf_rsp(chan, rsp,
2542 2543 2544 2545 2546
					L2CAP_CONF_REJECT, flags), rsp);
		goto unlock;
	}

	/* Store config. */
2547 2548
	memcpy(chan->conf_req + chan->conf_len, req->data, len);
	chan->conf_len += len;
L
Linus Torvalds 已提交
2549 2550 2551 2552

	if (flags & 0x0001) {
		/* Incomplete config. Send empty response. */
		l2cap_send_cmd(conn, cmd->ident, L2CAP_CONF_RSP,
2553
				l2cap_build_conf_rsp(chan, rsp,
2554
					L2CAP_CONF_SUCCESS, 0x0001), rsp);
L
Linus Torvalds 已提交
2555 2556 2557 2558
		goto unlock;
	}

	/* Complete config. */
2559
	len = l2cap_parse_conf_req(chan, rsp);
2560
	if (len < 0) {
2561
		l2cap_send_disconn_req(conn, chan, ECONNRESET);
L
Linus Torvalds 已提交
2562
		goto unlock;
2563
	}
L
Linus Torvalds 已提交
2564

2565
	l2cap_send_cmd(conn, cmd->ident, L2CAP_CONF_RSP, len, rsp);
2566
	chan->num_conf_rsp++;
2567 2568

	/* Reset config buffer. */
2569
	chan->conf_len = 0;
2570

2571
	if (!(chan->conf_state & L2CAP_CONF_OUTPUT_DONE))
2572 2573
		goto unlock;

2574
	if (chan->conf_state & L2CAP_CONF_INPUT_DONE) {
2575
		set_default_fcs(chan);
2576

2577
		l2cap_state_change(chan, BT_CONNECTED);
2578

2579 2580
		chan->next_tx_seq = 0;
		chan->expected_tx_seq = 0;
2581
		skb_queue_head_init(&chan->tx_q);
2582
		if (chan->mode == L2CAP_MODE_ERTM)
2583
			l2cap_ertm_init(chan);
2584

L
Linus Torvalds 已提交
2585
		l2cap_chan_ready(sk);
2586 2587 2588
		goto unlock;
	}

2589
	if (!(chan->conf_state & L2CAP_CONF_REQ_SENT)) {
2590
		u8 buf[64];
2591
		chan->conf_state |= L2CAP_CONF_REQ_SENT;
L
Linus Torvalds 已提交
2592
		l2cap_send_cmd(conn, l2cap_get_ident(conn), L2CAP_CONF_REQ,
2593 2594
					l2cap_build_conf_req(chan, buf), buf);
		chan->num_conf_req++;
L
Linus Torvalds 已提交
2595 2596 2597 2598 2599 2600 2601 2602 2603 2604 2605
	}

unlock:
	bh_unlock_sock(sk);
	return 0;
}

static inline int l2cap_config_rsp(struct l2cap_conn *conn, struct l2cap_cmd_hdr *cmd, u8 *data)
{
	struct l2cap_conf_rsp *rsp = (struct l2cap_conf_rsp *)data;
	u16 scid, flags, result;
2606
	struct l2cap_chan *chan;
L
Linus Torvalds 已提交
2607
	struct sock *sk;
2608
	int len = cmd->len - sizeof(*rsp);
L
Linus Torvalds 已提交
2609 2610 2611 2612 2613

	scid   = __le16_to_cpu(rsp->scid);
	flags  = __le16_to_cpu(rsp->flags);
	result = __le16_to_cpu(rsp->result);

2614 2615
	BT_DBG("scid 0x%4.4x flags 0x%2.2x result 0x%2.2x",
			scid, flags, result);
L
Linus Torvalds 已提交
2616

2617
	chan = l2cap_get_chan_by_scid(conn, scid);
2618
	if (!chan)
L
Linus Torvalds 已提交
2619 2620
		return 0;

2621 2622
	sk = chan->sk;

L
Linus Torvalds 已提交
2623 2624
	switch (result) {
	case L2CAP_CONF_SUCCESS:
2625
		l2cap_conf_rfc_get(chan, rsp->data, len);
L
Linus Torvalds 已提交
2626 2627 2628
		break;

	case L2CAP_CONF_UNACCEPT:
2629
		if (chan->num_conf_rsp <= L2CAP_CONF_MAX_CONF_RSP) {
2630 2631
			char req[64];

2632
			if (len > sizeof(req) - sizeof(struct l2cap_conf_req)) {
2633
				l2cap_send_disconn_req(conn, chan, ECONNRESET);
2634 2635 2636
				goto done;
			}

2637 2638
			/* throw out any old stored conf requests */
			result = L2CAP_CONF_SUCCESS;
2639 2640
			len = l2cap_parse_conf_rsp(chan, rsp->data, len,
								req, &result);
2641
			if (len < 0) {
2642
				l2cap_send_disconn_req(conn, chan, ECONNRESET);
2643 2644 2645 2646 2647
				goto done;
			}

			l2cap_send_cmd(conn, l2cap_get_ident(conn),
						L2CAP_CONF_REQ, len, req);
2648
			chan->num_conf_req++;
2649 2650 2651
			if (result != L2CAP_CONF_SUCCESS)
				goto done;
			break;
L
Linus Torvalds 已提交
2652 2653
		}

2654
	default:
2655
		sk->sk_err = ECONNRESET;
2656
		l2cap_chan_set_timer(chan, HZ * 5);
2657
		l2cap_send_disconn_req(conn, chan, ECONNRESET);
L
Linus Torvalds 已提交
2658 2659 2660 2661 2662 2663
		goto done;
	}

	if (flags & 0x01)
		goto done;

2664
	chan->conf_state |= L2CAP_CONF_INPUT_DONE;
L
Linus Torvalds 已提交
2665

2666
	if (chan->conf_state & L2CAP_CONF_OUTPUT_DONE) {
2667
		set_default_fcs(chan);
2668

2669
		l2cap_state_change(chan, BT_CONNECTED);
2670 2671
		chan->next_tx_seq = 0;
		chan->expected_tx_seq = 0;
2672
		skb_queue_head_init(&chan->tx_q);
2673
		if (chan->mode ==  L2CAP_MODE_ERTM)
2674
			l2cap_ertm_init(chan);
2675

L
Linus Torvalds 已提交
2676 2677 2678 2679 2680 2681 2682 2683 2684 2685 2686 2687 2688
		l2cap_chan_ready(sk);
	}

done:
	bh_unlock_sock(sk);
	return 0;
}

static inline int l2cap_disconnect_req(struct l2cap_conn *conn, struct l2cap_cmd_hdr *cmd, u8 *data)
{
	struct l2cap_disconn_req *req = (struct l2cap_disconn_req *) data;
	struct l2cap_disconn_rsp rsp;
	u16 dcid, scid;
2689
	struct l2cap_chan *chan;
L
Linus Torvalds 已提交
2690 2691 2692 2693 2694 2695 2696
	struct sock *sk;

	scid = __le16_to_cpu(req->scid);
	dcid = __le16_to_cpu(req->dcid);

	BT_DBG("scid 0x%4.4x dcid 0x%4.4x", scid, dcid);

2697
	chan = l2cap_get_chan_by_scid(conn, dcid);
2698
	if (!chan)
L
Linus Torvalds 已提交
2699 2700
		return 0;

2701 2702
	sk = chan->sk;

2703 2704
	rsp.dcid = cpu_to_le16(chan->scid);
	rsp.scid = cpu_to_le16(chan->dcid);
L
Linus Torvalds 已提交
2705 2706 2707 2708
	l2cap_send_cmd(conn, cmd->ident, L2CAP_DISCONN_RSP, sizeof(rsp), &rsp);

	sk->sk_shutdown = SHUTDOWN_MASK;

2709 2710
	/* don't delete l2cap channel if sk is owned by user */
	if (sock_owned_by_user(sk)) {
2711
		l2cap_state_change(chan, BT_DISCONN);
2712 2713
		l2cap_chan_clear_timer(chan);
		l2cap_chan_set_timer(chan, HZ / 5);
2714 2715 2716 2717
		bh_unlock_sock(sk);
		return 0;
	}

2718
	l2cap_chan_del(chan, ECONNRESET);
L
Linus Torvalds 已提交
2719 2720
	bh_unlock_sock(sk);

2721
	chan->ops->close(chan->data);
L
Linus Torvalds 已提交
2722 2723 2724 2725 2726 2727 2728
	return 0;
}

static inline int l2cap_disconnect_rsp(struct l2cap_conn *conn, struct l2cap_cmd_hdr *cmd, u8 *data)
{
	struct l2cap_disconn_rsp *rsp = (struct l2cap_disconn_rsp *) data;
	u16 dcid, scid;
2729
	struct l2cap_chan *chan;
L
Linus Torvalds 已提交
2730 2731 2732 2733 2734 2735 2736
	struct sock *sk;

	scid = __le16_to_cpu(rsp->scid);
	dcid = __le16_to_cpu(rsp->dcid);

	BT_DBG("dcid 0x%4.4x scid 0x%4.4x", dcid, scid);

2737
	chan = l2cap_get_chan_by_scid(conn, scid);
2738
	if (!chan)
L
Linus Torvalds 已提交
2739 2740
		return 0;

2741 2742
	sk = chan->sk;

2743 2744
	/* don't delete l2cap channel if sk is owned by user */
	if (sock_owned_by_user(sk)) {
2745
		l2cap_state_change(chan,BT_DISCONN);
2746 2747
		l2cap_chan_clear_timer(chan);
		l2cap_chan_set_timer(chan, HZ / 5);
2748 2749 2750 2751
		bh_unlock_sock(sk);
		return 0;
	}

2752
	l2cap_chan_del(chan, 0);
L
Linus Torvalds 已提交
2753 2754
	bh_unlock_sock(sk);

2755
	chan->ops->close(chan->data);
L
Linus Torvalds 已提交
2756 2757 2758 2759 2760 2761 2762 2763 2764 2765 2766 2767
	return 0;
}

static inline int l2cap_information_req(struct l2cap_conn *conn, struct l2cap_cmd_hdr *cmd, u8 *data)
{
	struct l2cap_info_req *req = (struct l2cap_info_req *) data;
	u16 type;

	type = __le16_to_cpu(req->type);

	BT_DBG("type 0x%4.4x", type);

2768 2769
	if (type == L2CAP_IT_FEAT_MASK) {
		u8 buf[8];
2770
		u32 feat_mask = l2cap_feat_mask;
2771 2772 2773
		struct l2cap_info_rsp *rsp = (struct l2cap_info_rsp *) buf;
		rsp->type   = cpu_to_le16(L2CAP_IT_FEAT_MASK);
		rsp->result = cpu_to_le16(L2CAP_IR_SUCCESS);
2774
		if (!disable_ertm)
2775 2776
			feat_mask |= L2CAP_FEAT_ERTM | L2CAP_FEAT_STREAMING
							 | L2CAP_FEAT_FCS;
2777
		put_unaligned_le32(feat_mask, rsp->data);
2778 2779
		l2cap_send_cmd(conn, cmd->ident,
					L2CAP_INFO_RSP, sizeof(buf), buf);
2780 2781 2782 2783 2784 2785 2786 2787
	} else if (type == L2CAP_IT_FIXED_CHAN) {
		u8 buf[12];
		struct l2cap_info_rsp *rsp = (struct l2cap_info_rsp *) buf;
		rsp->type   = cpu_to_le16(L2CAP_IT_FIXED_CHAN);
		rsp->result = cpu_to_le16(L2CAP_IR_SUCCESS);
		memcpy(buf + 4, l2cap_fixed_chan, 8);
		l2cap_send_cmd(conn, cmd->ident,
					L2CAP_INFO_RSP, sizeof(buf), buf);
2788 2789 2790 2791 2792 2793 2794
	} else {
		struct l2cap_info_rsp rsp;
		rsp.type   = cpu_to_le16(type);
		rsp.result = cpu_to_le16(L2CAP_IR_NOTSUPP);
		l2cap_send_cmd(conn, cmd->ident,
					L2CAP_INFO_RSP, sizeof(rsp), &rsp);
	}
L
Linus Torvalds 已提交
2795 2796 2797 2798 2799 2800 2801 2802 2803 2804 2805 2806 2807 2808

	return 0;
}

static inline int l2cap_information_rsp(struct l2cap_conn *conn, struct l2cap_cmd_hdr *cmd, u8 *data)
{
	struct l2cap_info_rsp *rsp = (struct l2cap_info_rsp *) data;
	u16 type, result;

	type   = __le16_to_cpu(rsp->type);
	result = __le16_to_cpu(rsp->result);

	BT_DBG("type 0x%4.4x result 0x%2.2x", type, result);

2809 2810 2811 2812 2813
	/* L2CAP Info req/rsp are unbound to channels, add extra checks */
	if (cmd->ident != conn->info_ident ||
			conn->info_state & L2CAP_INFO_FEAT_MASK_REQ_DONE)
		return 0;

2814 2815
	del_timer(&conn->info_timer);

2816 2817 2818 2819 2820 2821 2822 2823 2824
	if (result != L2CAP_IR_SUCCESS) {
		conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_DONE;
		conn->info_ident = 0;

		l2cap_conn_start(conn);

		return 0;
	}

2825
	if (type == L2CAP_IT_FEAT_MASK) {
2826
		conn->feat_mask = get_unaligned_le32(rsp->data);
2827

2828
		if (conn->feat_mask & L2CAP_FEAT_FIXED_CHAN) {
2829 2830 2831 2832 2833 2834 2835 2836 2837 2838 2839 2840 2841 2842
			struct l2cap_info_req req;
			req.type = cpu_to_le16(L2CAP_IT_FIXED_CHAN);

			conn->info_ident = l2cap_get_ident(conn);

			l2cap_send_cmd(conn, conn->info_ident,
					L2CAP_INFO_REQ, sizeof(req), &req);
		} else {
			conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_DONE;
			conn->info_ident = 0;

			l2cap_conn_start(conn);
		}
	} else if (type == L2CAP_IT_FIXED_CHAN) {
2843
		conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_DONE;
2844
		conn->info_ident = 0;
2845 2846 2847

		l2cap_conn_start(conn);
	}
2848

L
Linus Torvalds 已提交
2849 2850 2851
	return 0;
}

2852
static inline int l2cap_check_conn_param(u16 min, u16 max, u16 latency,
2853 2854 2855 2856 2857 2858 2859 2860 2861 2862 2863 2864 2865 2866 2867 2868 2869 2870 2871 2872 2873 2874 2875 2876 2877 2878 2879
							u16 to_multiplier)
{
	u16 max_latency;

	if (min > max || min < 6 || max > 3200)
		return -EINVAL;

	if (to_multiplier < 10 || to_multiplier > 3200)
		return -EINVAL;

	if (max >= to_multiplier * 8)
		return -EINVAL;

	max_latency = (to_multiplier * 8 / max) - 1;
	if (latency > 499 || latency > max_latency)
		return -EINVAL;

	return 0;
}

static inline int l2cap_conn_param_update_req(struct l2cap_conn *conn,
					struct l2cap_cmd_hdr *cmd, u8 *data)
{
	struct hci_conn *hcon = conn->hcon;
	struct l2cap_conn_param_update_req *req;
	struct l2cap_conn_param_update_rsp rsp;
	u16 min, max, latency, to_multiplier, cmd_len;
2880
	int err;
2881 2882 2883 2884 2885 2886 2887 2888 2889

	if (!(hcon->link_mode & HCI_LM_MASTER))
		return -EINVAL;

	cmd_len = __le16_to_cpu(cmd->len);
	if (cmd_len != sizeof(struct l2cap_conn_param_update_req))
		return -EPROTO;

	req = (struct l2cap_conn_param_update_req *) data;
2890 2891
	min		= __le16_to_cpu(req->min);
	max		= __le16_to_cpu(req->max);
2892 2893 2894 2895 2896 2897 2898
	latency		= __le16_to_cpu(req->latency);
	to_multiplier	= __le16_to_cpu(req->to_multiplier);

	BT_DBG("min 0x%4.4x max 0x%4.4x latency: 0x%4.4x Timeout: 0x%4.4x",
						min, max, latency, to_multiplier);

	memset(&rsp, 0, sizeof(rsp));
2899 2900 2901

	err = l2cap_check_conn_param(min, max, latency, to_multiplier);
	if (err)
2902 2903 2904 2905 2906 2907 2908
		rsp.result = cpu_to_le16(L2CAP_CONN_PARAM_REJECTED);
	else
		rsp.result = cpu_to_le16(L2CAP_CONN_PARAM_ACCEPTED);

	l2cap_send_cmd(conn, cmd->ident, L2CAP_CONN_PARAM_UPDATE_RSP,
							sizeof(rsp), &rsp);

2909 2910 2911
	if (!err)
		hci_le_conn_update(hcon, min, max, latency, to_multiplier);

2912 2913 2914
	return 0;
}

2915 2916 2917 2918 2919 2920 2921 2922 2923 2924 2925 2926 2927 2928 2929 2930 2931 2932 2933 2934 2935 2936 2937 2938 2939 2940 2941 2942 2943 2944 2945 2946 2947 2948 2949 2950 2951 2952 2953 2954 2955 2956 2957 2958 2959 2960 2961 2962 2963 2964 2965 2966 2967 2968 2969 2970 2971 2972 2973 2974 2975 2976 2977 2978 2979 2980
static inline int l2cap_bredr_sig_cmd(struct l2cap_conn *conn,
			struct l2cap_cmd_hdr *cmd, u16 cmd_len, u8 *data)
{
	int err = 0;

	switch (cmd->code) {
	case L2CAP_COMMAND_REJ:
		l2cap_command_rej(conn, cmd, data);
		break;

	case L2CAP_CONN_REQ:
		err = l2cap_connect_req(conn, cmd, data);
		break;

	case L2CAP_CONN_RSP:
		err = l2cap_connect_rsp(conn, cmd, data);
		break;

	case L2CAP_CONF_REQ:
		err = l2cap_config_req(conn, cmd, cmd_len, data);
		break;

	case L2CAP_CONF_RSP:
		err = l2cap_config_rsp(conn, cmd, data);
		break;

	case L2CAP_DISCONN_REQ:
		err = l2cap_disconnect_req(conn, cmd, data);
		break;

	case L2CAP_DISCONN_RSP:
		err = l2cap_disconnect_rsp(conn, cmd, data);
		break;

	case L2CAP_ECHO_REQ:
		l2cap_send_cmd(conn, cmd->ident, L2CAP_ECHO_RSP, cmd_len, data);
		break;

	case L2CAP_ECHO_RSP:
		break;

	case L2CAP_INFO_REQ:
		err = l2cap_information_req(conn, cmd, data);
		break;

	case L2CAP_INFO_RSP:
		err = l2cap_information_rsp(conn, cmd, data);
		break;

	default:
		BT_ERR("Unknown BR/EDR signaling command 0x%2.2x", cmd->code);
		err = -EINVAL;
		break;
	}

	return err;
}

static inline int l2cap_le_sig_cmd(struct l2cap_conn *conn,
					struct l2cap_cmd_hdr *cmd, u8 *data)
{
	switch (cmd->code) {
	case L2CAP_COMMAND_REJ:
		return 0;

	case L2CAP_CONN_PARAM_UPDATE_REQ:
2981
		return l2cap_conn_param_update_req(conn, cmd, data);
2982 2983 2984 2985 2986 2987 2988 2989 2990 2991 2992 2993

	case L2CAP_CONN_PARAM_UPDATE_RSP:
		return 0;

	default:
		BT_ERR("Unknown LE signaling command 0x%2.2x", cmd->code);
		return -EINVAL;
	}
}

static inline void l2cap_sig_channel(struct l2cap_conn *conn,
							struct sk_buff *skb)
L
Linus Torvalds 已提交
2994 2995 2996 2997
{
	u8 *data = skb->data;
	int len = skb->len;
	struct l2cap_cmd_hdr cmd;
2998
	int err;
L
Linus Torvalds 已提交
2999 3000 3001 3002

	l2cap_raw_recv(conn, skb);

	while (len >= L2CAP_CMD_HDR_SIZE) {
3003
		u16 cmd_len;
L
Linus Torvalds 已提交
3004 3005 3006 3007
		memcpy(&cmd, data, L2CAP_CMD_HDR_SIZE);
		data += L2CAP_CMD_HDR_SIZE;
		len  -= L2CAP_CMD_HDR_SIZE;

3008
		cmd_len = le16_to_cpu(cmd.len);
L
Linus Torvalds 已提交
3009

3010
		BT_DBG("code 0x%2.2x len %d id 0x%2.2x", cmd.code, cmd_len, cmd.ident);
L
Linus Torvalds 已提交
3011

3012
		if (cmd_len > len || !cmd.ident) {
L
Linus Torvalds 已提交
3013 3014 3015 3016
			BT_DBG("corrupted command");
			break;
		}

3017 3018 3019 3020
		if (conn->hcon->type == LE_LINK)
			err = l2cap_le_sig_cmd(conn, &cmd, data);
		else
			err = l2cap_bredr_sig_cmd(conn, &cmd, cmd_len, data);
L
Linus Torvalds 已提交
3021 3022 3023

		if (err) {
			struct l2cap_cmd_rej rej;
3024 3025

			BT_ERR("Wrong link type (%d)", err);
L
Linus Torvalds 已提交
3026 3027

			/* FIXME: Map err to a valid reason */
3028
			rej.reason = cpu_to_le16(0);
L
Linus Torvalds 已提交
3029 3030 3031
			l2cap_send_cmd(conn, cmd.ident, L2CAP_COMMAND_REJ, sizeof(rej), &rej);
		}

3032 3033
		data += cmd_len;
		len  -= cmd_len;
L
Linus Torvalds 已提交
3034 3035 3036 3037 3038
	}

	kfree_skb(skb);
}

3039
static int l2cap_check_fcs(struct l2cap_chan *chan,  struct sk_buff *skb)
3040 3041 3042 3043
{
	u16 our_fcs, rcv_fcs;
	int hdr_size = L2CAP_HDR_SIZE + 2;

3044
	if (chan->fcs == L2CAP_FCS_CRC16) {
3045 3046 3047 3048 3049
		skb_trim(skb, skb->len - 2);
		rcv_fcs = get_unaligned_le16(skb->data + skb->len);
		our_fcs = crc16(0, skb->data - hdr_size, skb->len + hdr_size);

		if (our_fcs != rcv_fcs)
3050
			return -EBADMSG;
3051 3052 3053 3054
	}
	return 0;
}

3055
static inline void l2cap_send_i_or_rr_or_rnr(struct l2cap_chan *chan)
3056 3057 3058
{
	u16 control = 0;

3059
	chan->frames_sent = 0;
3060

3061
	control |= chan->buffer_seq << L2CAP_CTRL_REQSEQ_SHIFT;
3062

3063
	if (chan->conn_state & L2CAP_CONN_LOCAL_BUSY) {
3064
		control |= L2CAP_SUPER_RCV_NOT_READY;
3065 3066
		l2cap_send_sframe(chan, control);
		chan->conn_state |= L2CAP_CONN_RNR_SENT;
3067 3068
	}

3069 3070
	if (chan->conn_state & L2CAP_CONN_REMOTE_BUSY)
		l2cap_retransmit_frames(chan);
3071

3072
	l2cap_ertm_send(chan);
3073

3074
	if (!(chan->conn_state & L2CAP_CONN_LOCAL_BUSY) &&
3075
			chan->frames_sent == 0) {
3076
		control |= L2CAP_SUPER_RCV_READY;
3077
		l2cap_send_sframe(chan, control);
3078 3079 3080
	}
}

3081
static int l2cap_add_to_srej_queue(struct l2cap_chan *chan, struct sk_buff *skb, u8 tx_seq, u8 sar)
3082 3083
{
	struct sk_buff *next_skb;
3084
	int tx_seq_offset, next_tx_seq_offset;
3085 3086 3087 3088

	bt_cb(skb)->tx_seq = tx_seq;
	bt_cb(skb)->sar = sar;

3089
	next_skb = skb_peek(&chan->srej_q);
3090
	if (!next_skb) {
3091
		__skb_queue_tail(&chan->srej_q, skb);
3092
		return 0;
3093 3094
	}

3095
	tx_seq_offset = (tx_seq - chan->buffer_seq) % 64;
3096 3097 3098
	if (tx_seq_offset < 0)
		tx_seq_offset += 64;

3099
	do {
3100 3101 3102
		if (bt_cb(next_skb)->tx_seq == tx_seq)
			return -EINVAL;

3103
		next_tx_seq_offset = (bt_cb(next_skb)->tx_seq -
3104
						chan->buffer_seq) % 64;
3105 3106 3107 3108
		if (next_tx_seq_offset < 0)
			next_tx_seq_offset += 64;

		if (next_tx_seq_offset > tx_seq_offset) {
3109
			__skb_queue_before(&chan->srej_q, next_skb, skb);
3110
			return 0;
3111 3112
		}

3113
		if (skb_queue_is_last(&chan->srej_q, next_skb))
3114 3115
			break;

3116
	} while ((next_skb = skb_queue_next(&chan->srej_q, next_skb)));
3117

3118
	__skb_queue_tail(&chan->srej_q, skb);
3119 3120

	return 0;
3121 3122
}

3123
static int l2cap_ertm_reassembly_sdu(struct l2cap_chan *chan, struct sk_buff *skb, u16 control)
3124 3125
{
	struct sk_buff *_skb;
3126
	int err;
3127 3128 3129

	switch (control & L2CAP_CTRL_SAR) {
	case L2CAP_SDU_UNSEGMENTED:
3130
		if (chan->conn_state & L2CAP_CONN_SAR_SDU)
3131 3132
			goto drop;

3133
		return chan->ops->recv(chan->data, skb);
3134 3135

	case L2CAP_SDU_START:
3136
		if (chan->conn_state & L2CAP_CONN_SAR_SDU)
3137 3138
			goto drop;

3139
		chan->sdu_len = get_unaligned_le16(skb->data);
3140

3141
		if (chan->sdu_len > chan->imtu)
3142 3143
			goto disconnect;

3144 3145
		chan->sdu = bt_skb_alloc(chan->sdu_len, GFP_ATOMIC);
		if (!chan->sdu)
3146 3147 3148 3149 3150 3151
			return -ENOMEM;

		/* pull sdu_len bytes only after alloc, because of Local Busy
		 * condition we have to be sure that this will be executed
		 * only once, i.e., when alloc does not fail */
		skb_pull(skb, 2);
3152

3153
		memcpy(skb_put(chan->sdu, skb->len), skb->data, skb->len);
3154

3155
		chan->conn_state |= L2CAP_CONN_SAR_SDU;
3156
		chan->partial_sdu_len = skb->len;
3157 3158 3159
		break;

	case L2CAP_SDU_CONTINUE:
3160
		if (!(chan->conn_state & L2CAP_CONN_SAR_SDU))
3161 3162
			goto disconnect;

3163
		if (!chan->sdu)
3164 3165
			goto disconnect;

3166 3167
		chan->partial_sdu_len += skb->len;
		if (chan->partial_sdu_len > chan->sdu_len)
3168 3169
			goto drop;

3170
		memcpy(skb_put(chan->sdu, skb->len), skb->data, skb->len);
3171

3172 3173 3174
		break;

	case L2CAP_SDU_END:
3175
		if (!(chan->conn_state & L2CAP_CONN_SAR_SDU))
3176 3177
			goto disconnect;

3178
		if (!chan->sdu)
3179 3180
			goto disconnect;

3181
		if (!(chan->conn_state & L2CAP_CONN_SAR_RETRY)) {
3182
			chan->partial_sdu_len += skb->len;
3183

3184
			if (chan->partial_sdu_len > chan->imtu)
3185
				goto drop;
3186

3187
			if (chan->partial_sdu_len != chan->sdu_len)
3188
				goto drop;
3189

3190
			memcpy(skb_put(chan->sdu, skb->len), skb->data, skb->len);
3191
		}
3192

3193
		_skb = skb_clone(chan->sdu, GFP_ATOMIC);
3194
		if (!_skb) {
3195
			chan->conn_state |= L2CAP_CONN_SAR_RETRY;
3196 3197 3198
			return -ENOMEM;
		}

3199
		err = chan->ops->recv(chan->data, _skb);
3200
		if (err < 0) {
3201
			kfree_skb(_skb);
3202
			chan->conn_state |= L2CAP_CONN_SAR_RETRY;
3203 3204 3205
			return err;
		}

3206 3207
		chan->conn_state &= ~L2CAP_CONN_SAR_RETRY;
		chan->conn_state &= ~L2CAP_CONN_SAR_SDU;
3208

3209
		kfree_skb(chan->sdu);
3210 3211 3212 3213
		break;
	}

	kfree_skb(skb);
3214
	return 0;
3215 3216

drop:
3217 3218
	kfree_skb(chan->sdu);
	chan->sdu = NULL;
3219 3220

disconnect:
3221
	l2cap_send_disconn_req(chan->conn, chan, ECONNRESET);
3222 3223 3224 3225
	kfree_skb(skb);
	return 0;
}

3226
static int l2cap_try_push_rx_skb(struct l2cap_chan *chan)
3227 3228 3229 3230 3231
{
	struct sk_buff *skb;
	u16 control;
	int err;

3232
	while ((skb = skb_dequeue(&chan->busy_q))) {
3233
		control = bt_cb(skb)->sar << L2CAP_CTRL_SAR_SHIFT;
3234
		err = l2cap_ertm_reassembly_sdu(chan, skb, control);
3235
		if (err < 0) {
3236
			skb_queue_head(&chan->busy_q, skb);
3237 3238 3239
			return -EBUSY;
		}

3240
		chan->buffer_seq = (chan->buffer_seq + 1) % 64;
3241 3242
	}

3243
	if (!(chan->conn_state & L2CAP_CONN_RNR_SENT))
3244 3245
		goto done;

3246
	control = chan->buffer_seq << L2CAP_CTRL_REQSEQ_SHIFT;
3247
	control |= L2CAP_SUPER_RCV_READY | L2CAP_CTRL_POLL;
3248
	l2cap_send_sframe(chan, control);
3249
	chan->retry_count = 1;
3250

3251
	del_timer(&chan->retrans_timer);
3252 3253
	__mod_monitor_timer();

3254
	chan->conn_state |= L2CAP_CONN_WAIT_F;
3255 3256

done:
3257 3258
	chan->conn_state &= ~L2CAP_CONN_LOCAL_BUSY;
	chan->conn_state &= ~L2CAP_CONN_RNR_SENT;
3259

3260
	BT_DBG("chan %p, Exit local busy", chan);
3261 3262 3263 3264

	return 0;
}

3265 3266 3267
static void l2cap_busy_work(struct work_struct *work)
{
	DECLARE_WAITQUEUE(wait, current);
3268 3269 3270
	struct l2cap_chan *chan =
		container_of(work, struct l2cap_chan, busy_work);
	struct sock *sk = chan->sk;
3271 3272 3273 3274 3275
	int n_tries = 0, timeo = HZ/5, err;
	struct sk_buff *skb;

	lock_sock(sk);

3276
	add_wait_queue(sk_sleep(sk), &wait);
3277
	while ((skb = skb_peek(&chan->busy_q))) {
3278 3279 3280 3281
		set_current_state(TASK_INTERRUPTIBLE);

		if (n_tries++ > L2CAP_LOCAL_BUSY_TRIES) {
			err = -EBUSY;
3282
			l2cap_send_disconn_req(chan->conn, chan, EBUSY);
3283
			break;
3284 3285 3286 3287 3288 3289 3290
		}

		if (!timeo)
			timeo = HZ/5;

		if (signal_pending(current)) {
			err = sock_intr_errno(timeo);
3291
			break;
3292 3293 3294 3295 3296 3297 3298 3299
		}

		release_sock(sk);
		timeo = schedule_timeout(timeo);
		lock_sock(sk);

		err = sock_error(sk);
		if (err)
3300
			break;
3301

3302
		if (l2cap_try_push_rx_skb(chan) == 0)
3303 3304 3305 3306
			break;
	}

	set_current_state(TASK_RUNNING);
3307
	remove_wait_queue(sk_sleep(sk), &wait);
3308 3309 3310 3311

	release_sock(sk);
}

3312
static int l2cap_push_rx_skb(struct l2cap_chan *chan, struct sk_buff *skb, u16 control)
3313 3314 3315
{
	int sctrl, err;

3316
	if (chan->conn_state & L2CAP_CONN_LOCAL_BUSY) {
3317
		bt_cb(skb)->sar = control >> L2CAP_CTRL_SAR_SHIFT;
3318
		__skb_queue_tail(&chan->busy_q, skb);
3319
		return l2cap_try_push_rx_skb(chan);
3320 3321


3322 3323
	}

3324
	err = l2cap_ertm_reassembly_sdu(chan, skb, control);
3325
	if (err >= 0) {
3326
		chan->buffer_seq = (chan->buffer_seq + 1) % 64;
3327 3328 3329 3330
		return err;
	}

	/* Busy Condition */
3331
	BT_DBG("chan %p, Enter local busy", chan);
3332

3333
	chan->conn_state |= L2CAP_CONN_LOCAL_BUSY;
3334
	bt_cb(skb)->sar = control >> L2CAP_CTRL_SAR_SHIFT;
3335
	__skb_queue_tail(&chan->busy_q, skb);
3336

3337
	sctrl = chan->buffer_seq << L2CAP_CTRL_REQSEQ_SHIFT;
3338
	sctrl |= L2CAP_SUPER_RCV_NOT_READY;
3339
	l2cap_send_sframe(chan, sctrl);
3340

3341
	chan->conn_state |= L2CAP_CONN_RNR_SENT;
3342

3343
	del_timer(&chan->ack_timer);
3344

3345
	queue_work(_busy_wq, &chan->busy_work);
3346 3347 3348 3349

	return err;
}

3350
static int l2cap_streaming_reassembly_sdu(struct l2cap_chan *chan, struct sk_buff *skb, u16 control)
3351 3352 3353 3354
{
	struct sk_buff *_skb;
	int err = -EINVAL;

3355 3356 3357 3358 3359
	/*
	 * TODO: We have to notify the userland if some data is lost with the
	 * Streaming Mode.
	 */

3360 3361
	switch (control & L2CAP_CTRL_SAR) {
	case L2CAP_SDU_UNSEGMENTED:
3362
		if (chan->conn_state & L2CAP_CONN_SAR_SDU) {
3363
			kfree_skb(chan->sdu);
3364 3365 3366
			break;
		}

3367
		err = chan->ops->recv(chan->data, skb);
3368 3369 3370 3371 3372 3373
		if (!err)
			return 0;

		break;

	case L2CAP_SDU_START:
3374
		if (chan->conn_state & L2CAP_CONN_SAR_SDU) {
3375
			kfree_skb(chan->sdu);
3376 3377 3378
			break;
		}

3379
		chan->sdu_len = get_unaligned_le16(skb->data);
3380 3381
		skb_pull(skb, 2);

3382
		if (chan->sdu_len > chan->imtu) {
3383 3384 3385 3386
			err = -EMSGSIZE;
			break;
		}

3387 3388
		chan->sdu = bt_skb_alloc(chan->sdu_len, GFP_ATOMIC);
		if (!chan->sdu) {
3389 3390 3391 3392
			err = -ENOMEM;
			break;
		}

3393
		memcpy(skb_put(chan->sdu, skb->len), skb->data, skb->len);
3394

3395
		chan->conn_state |= L2CAP_CONN_SAR_SDU;
3396
		chan->partial_sdu_len = skb->len;
3397 3398 3399 3400
		err = 0;
		break;

	case L2CAP_SDU_CONTINUE:
3401
		if (!(chan->conn_state & L2CAP_CONN_SAR_SDU))
3402 3403
			break;

3404
		memcpy(skb_put(chan->sdu, skb->len), skb->data, skb->len);
3405

3406 3407 3408
		chan->partial_sdu_len += skb->len;
		if (chan->partial_sdu_len > chan->sdu_len)
			kfree_skb(chan->sdu);
3409 3410 3411 3412 3413 3414
		else
			err = 0;

		break;

	case L2CAP_SDU_END:
3415
		if (!(chan->conn_state & L2CAP_CONN_SAR_SDU))
3416 3417
			break;

3418
		memcpy(skb_put(chan->sdu, skb->len), skb->data, skb->len);
3419

3420
		chan->conn_state &= ~L2CAP_CONN_SAR_SDU;
3421
		chan->partial_sdu_len += skb->len;
3422

3423
		if (chan->partial_sdu_len > chan->imtu)
3424 3425
			goto drop;

3426 3427
		if (chan->partial_sdu_len == chan->sdu_len) {
			_skb = skb_clone(chan->sdu, GFP_ATOMIC);
3428
			err = chan->ops->recv(chan->data, _skb);
3429 3430 3431 3432 3433
			if (err < 0)
				kfree_skb(_skb);
		}
		err = 0;

3434
drop:
3435
		kfree_skb(chan->sdu);
3436 3437 3438 3439 3440 3441 3442
		break;
	}

	kfree_skb(skb);
	return err;
}

3443
static void l2cap_check_srej_gap(struct l2cap_chan *chan, u8 tx_seq)
3444 3445
{
	struct sk_buff *skb;
3446
	u16 control;
3447

3448
	while ((skb = skb_peek(&chan->srej_q))) {
3449 3450 3451
		if (bt_cb(skb)->tx_seq != tx_seq)
			break;

3452
		skb = skb_dequeue(&chan->srej_q);
3453
		control = bt_cb(skb)->sar << L2CAP_CTRL_SAR_SHIFT;
3454
		l2cap_ertm_reassembly_sdu(chan, skb, control);
3455 3456
		chan->buffer_seq_srej =
			(chan->buffer_seq_srej + 1) % 64;
3457
		tx_seq = (tx_seq + 1) % 64;
3458 3459 3460
	}
}

3461
static void l2cap_resend_srejframe(struct l2cap_chan *chan, u8 tx_seq)
3462 3463 3464 3465
{
	struct srej_list *l, *tmp;
	u16 control;

3466
	list_for_each_entry_safe(l, tmp, &chan->srej_l, list) {
3467 3468 3469 3470 3471 3472 3473
		if (l->tx_seq == tx_seq) {
			list_del(&l->list);
			kfree(l);
			return;
		}
		control = L2CAP_SUPER_SELECT_REJECT;
		control |= l->tx_seq << L2CAP_CTRL_REQSEQ_SHIFT;
3474
		l2cap_send_sframe(chan, control);
3475
		list_del(&l->list);
3476
		list_add_tail(&l->list, &chan->srej_l);
3477 3478 3479
	}
}

3480
static void l2cap_send_srejframe(struct l2cap_chan *chan, u8 tx_seq)
3481 3482 3483 3484
{
	struct srej_list *new;
	u16 control;

3485
	while (tx_seq != chan->expected_tx_seq) {
3486
		control = L2CAP_SUPER_SELECT_REJECT;
3487
		control |= chan->expected_tx_seq << L2CAP_CTRL_REQSEQ_SHIFT;
3488
		l2cap_send_sframe(chan, control);
3489 3490

		new = kzalloc(sizeof(struct srej_list), GFP_ATOMIC);
3491 3492
		new->tx_seq = chan->expected_tx_seq;
		chan->expected_tx_seq = (chan->expected_tx_seq + 1) % 64;
3493
		list_add_tail(&new->list, &chan->srej_l);
3494
	}
3495
	chan->expected_tx_seq = (chan->expected_tx_seq + 1) % 64;
3496 3497
}

3498
static inline int l2cap_data_channel_iframe(struct l2cap_chan *chan, u16 rx_control, struct sk_buff *skb)
3499 3500
{
	u8 tx_seq = __get_txseq(rx_control);
3501
	u8 req_seq = __get_reqseq(rx_control);
3502
	u8 sar = rx_control >> L2CAP_CTRL_SAR_SHIFT;
3503
	int tx_seq_offset, expected_tx_seq_offset;
3504
	int num_to_ack = (chan->tx_win/6) + 1;
3505 3506
	int err = 0;

3507 3508
	BT_DBG("chan %p len %d tx_seq %d rx_control 0x%4.4x", chan, skb->len,
							tx_seq, rx_control);
3509

3510
	if (L2CAP_CTRL_FINAL & rx_control &&
3511
			chan->conn_state & L2CAP_CONN_WAIT_F) {
3512
		del_timer(&chan->monitor_timer);
3513
		if (chan->unacked_frames > 0)
3514
			__mod_retrans_timer();
3515
		chan->conn_state &= ~L2CAP_CONN_WAIT_F;
3516 3517
	}

3518 3519
	chan->expected_ack_seq = req_seq;
	l2cap_drop_acked_frames(chan);
3520

3521
	if (tx_seq == chan->expected_tx_seq)
3522
		goto expected;
3523

3524
	tx_seq_offset = (tx_seq - chan->buffer_seq) % 64;
3525 3526 3527 3528
	if (tx_seq_offset < 0)
		tx_seq_offset += 64;

	/* invalid tx_seq */
3529
	if (tx_seq_offset >= chan->tx_win) {
3530
		l2cap_send_disconn_req(chan->conn, chan, ECONNRESET);
3531 3532 3533
		goto drop;
	}

3534
	if (chan->conn_state & L2CAP_CONN_LOCAL_BUSY)
3535 3536
		goto drop;

3537
	if (chan->conn_state & L2CAP_CONN_SREJ_SENT) {
3538
		struct srej_list *first;
3539

3540
		first = list_first_entry(&chan->srej_l,
3541 3542
				struct srej_list, list);
		if (tx_seq == first->tx_seq) {
3543
			l2cap_add_to_srej_queue(chan, skb, tx_seq, sar);
3544
			l2cap_check_srej_gap(chan, tx_seq);
3545 3546 3547 3548

			list_del(&first->list);
			kfree(first);

3549
			if (list_empty(&chan->srej_l)) {
3550
				chan->buffer_seq = chan->buffer_seq_srej;
3551 3552
				chan->conn_state &= ~L2CAP_CONN_SREJ_SENT;
				l2cap_send_ack(chan);
3553
				BT_DBG("chan %p, Exit SREJ_SENT", chan);
3554 3555 3556
			}
		} else {
			struct srej_list *l;
3557 3558

			/* duplicated tx_seq */
3559
			if (l2cap_add_to_srej_queue(chan, skb, tx_seq, sar) < 0)
3560
				goto drop;
3561

3562
			list_for_each_entry(l, &chan->srej_l, list) {
3563
				if (l->tx_seq == tx_seq) {
3564
					l2cap_resend_srejframe(chan, tx_seq);
3565 3566 3567
					return 0;
				}
			}
3568
			l2cap_send_srejframe(chan, tx_seq);
3569 3570
		}
	} else {
3571
		expected_tx_seq_offset =
3572
			(chan->expected_tx_seq - chan->buffer_seq) % 64;
3573 3574 3575 3576 3577 3578 3579
		if (expected_tx_seq_offset < 0)
			expected_tx_seq_offset += 64;

		/* duplicated tx_seq */
		if (tx_seq_offset < expected_tx_seq_offset)
			goto drop;

3580
		chan->conn_state |= L2CAP_CONN_SREJ_SENT;
3581

3582
		BT_DBG("chan %p, Enter SREJ", chan);
3583

3584
		INIT_LIST_HEAD(&chan->srej_l);
3585
		chan->buffer_seq_srej = chan->buffer_seq;
3586

3587 3588
		__skb_queue_head_init(&chan->srej_q);
		__skb_queue_head_init(&chan->busy_q);
3589
		l2cap_add_to_srej_queue(chan, skb, tx_seq, sar);
3590

3591
		chan->conn_state |= L2CAP_CONN_SEND_PBIT;
3592

3593
		l2cap_send_srejframe(chan, tx_seq);
3594

3595
		del_timer(&chan->ack_timer);
3596
	}
3597 3598
	return 0;

3599
expected:
3600
	chan->expected_tx_seq = (chan->expected_tx_seq + 1) % 64;
3601

3602
	if (chan->conn_state & L2CAP_CONN_SREJ_SENT) {
3603 3604
		bt_cb(skb)->tx_seq = tx_seq;
		bt_cb(skb)->sar = sar;
3605
		__skb_queue_tail(&chan->srej_q, skb);
3606 3607 3608
		return 0;
	}

3609
	err = l2cap_push_rx_skb(chan, skb, rx_control);
3610 3611 3612
	if (err < 0)
		return 0;

3613
	if (rx_control & L2CAP_CTRL_FINAL) {
3614 3615
		if (chan->conn_state & L2CAP_CONN_REJ_ACT)
			chan->conn_state &= ~L2CAP_CONN_REJ_ACT;
3616
		else
3617
			l2cap_retransmit_frames(chan);
3618 3619
	}

3620 3621
	__mod_ack_timer();

3622 3623
	chan->num_acked = (chan->num_acked + 1) % num_to_ack;
	if (chan->num_acked == num_to_ack - 1)
3624
		l2cap_send_ack(chan);
3625

3626
	return 0;
3627 3628 3629 3630

drop:
	kfree_skb(skb);
	return 0;
3631 3632
}

3633
static inline void l2cap_data_channel_rrframe(struct l2cap_chan *chan, u16 rx_control)
3634
{
3635
	BT_DBG("chan %p, req_seq %d ctrl 0x%4.4x", chan, __get_reqseq(rx_control),
3636 3637
						rx_control);

3638 3639
	chan->expected_ack_seq = __get_reqseq(rx_control);
	l2cap_drop_acked_frames(chan);
3640

3641
	if (rx_control & L2CAP_CTRL_POLL) {
3642 3643 3644
		chan->conn_state |= L2CAP_CONN_SEND_FBIT;
		if (chan->conn_state & L2CAP_CONN_SREJ_SENT) {
			if ((chan->conn_state & L2CAP_CONN_REMOTE_BUSY) &&
3645
					(chan->unacked_frames > 0))
3646 3647
				__mod_retrans_timer();

3648 3649
			chan->conn_state &= ~L2CAP_CONN_REMOTE_BUSY;
			l2cap_send_srejtail(chan);
3650
		} else {
3651
			l2cap_send_i_or_rr_or_rnr(chan);
3652
		}
3653

3654
	} else if (rx_control & L2CAP_CTRL_FINAL) {
3655
		chan->conn_state &= ~L2CAP_CONN_REMOTE_BUSY;
3656

3657 3658
		if (chan->conn_state & L2CAP_CONN_REJ_ACT)
			chan->conn_state &= ~L2CAP_CONN_REJ_ACT;
3659
		else
3660
			l2cap_retransmit_frames(chan);
3661

3662
	} else {
3663
		if ((chan->conn_state & L2CAP_CONN_REMOTE_BUSY) &&
3664
				(chan->unacked_frames > 0))
3665
			__mod_retrans_timer();
3666

3667 3668 3669
		chan->conn_state &= ~L2CAP_CONN_REMOTE_BUSY;
		if (chan->conn_state & L2CAP_CONN_SREJ_SENT)
			l2cap_send_ack(chan);
3670
		else
3671
			l2cap_ertm_send(chan);
3672 3673
	}
}
3674

3675
static inline void l2cap_data_channel_rejframe(struct l2cap_chan *chan, u16 rx_control)
3676 3677
{
	u8 tx_seq = __get_reqseq(rx_control);
3678

3679
	BT_DBG("chan %p, req_seq %d ctrl 0x%4.4x", chan, tx_seq, rx_control);
3680

3681
	chan->conn_state &= ~L2CAP_CONN_REMOTE_BUSY;
3682

3683 3684
	chan->expected_ack_seq = tx_seq;
	l2cap_drop_acked_frames(chan);
3685 3686

	if (rx_control & L2CAP_CTRL_FINAL) {
3687 3688
		if (chan->conn_state & L2CAP_CONN_REJ_ACT)
			chan->conn_state &= ~L2CAP_CONN_REJ_ACT;
3689
		else
3690
			l2cap_retransmit_frames(chan);
3691
	} else {
3692
		l2cap_retransmit_frames(chan);
3693

3694 3695
		if (chan->conn_state & L2CAP_CONN_WAIT_F)
			chan->conn_state |= L2CAP_CONN_REJ_ACT;
3696 3697
	}
}
3698
static inline void l2cap_data_channel_srejframe(struct l2cap_chan *chan, u16 rx_control)
3699 3700
{
	u8 tx_seq = __get_reqseq(rx_control);
3701

3702
	BT_DBG("chan %p, req_seq %d ctrl 0x%4.4x", chan, tx_seq, rx_control);
3703

3704
	chan->conn_state &= ~L2CAP_CONN_REMOTE_BUSY;
3705

3706
	if (rx_control & L2CAP_CTRL_POLL) {
3707 3708
		chan->expected_ack_seq = tx_seq;
		l2cap_drop_acked_frames(chan);
3709

3710 3711
		chan->conn_state |= L2CAP_CONN_SEND_FBIT;
		l2cap_retransmit_one_frame(chan, tx_seq);
3712

3713
		l2cap_ertm_send(chan);
3714

3715
		if (chan->conn_state & L2CAP_CONN_WAIT_F) {
3716
			chan->srej_save_reqseq = tx_seq;
3717
			chan->conn_state |= L2CAP_CONN_SREJ_ACT;
3718
		}
3719
	} else if (rx_control & L2CAP_CTRL_FINAL) {
3720
		if ((chan->conn_state & L2CAP_CONN_SREJ_ACT) &&
3721
				chan->srej_save_reqseq == tx_seq)
3722
			chan->conn_state &= ~L2CAP_CONN_SREJ_ACT;
3723
		else
3724
			l2cap_retransmit_one_frame(chan, tx_seq);
3725
	} else {
3726 3727
		l2cap_retransmit_one_frame(chan, tx_seq);
		if (chan->conn_state & L2CAP_CONN_WAIT_F) {
3728
			chan->srej_save_reqseq = tx_seq;
3729
			chan->conn_state |= L2CAP_CONN_SREJ_ACT;
3730
		}
3731 3732 3733
	}
}

3734
static inline void l2cap_data_channel_rnrframe(struct l2cap_chan *chan, u16 rx_control)
3735 3736 3737
{
	u8 tx_seq = __get_reqseq(rx_control);

3738
	BT_DBG("chan %p, req_seq %d ctrl 0x%4.4x", chan, tx_seq, rx_control);
3739

3740
	chan->conn_state |= L2CAP_CONN_REMOTE_BUSY;
3741 3742
	chan->expected_ack_seq = tx_seq;
	l2cap_drop_acked_frames(chan);
3743

3744
	if (rx_control & L2CAP_CTRL_POLL)
3745
		chan->conn_state |= L2CAP_CONN_SEND_FBIT;
3746

3747
	if (!(chan->conn_state & L2CAP_CONN_SREJ_SENT)) {
3748
		del_timer(&chan->retrans_timer);
3749
		if (rx_control & L2CAP_CTRL_POLL)
3750
			l2cap_send_rr_or_rnr(chan, L2CAP_CTRL_FINAL);
3751
		return;
3752
	}
3753 3754

	if (rx_control & L2CAP_CTRL_POLL)
3755
		l2cap_send_srejtail(chan);
3756
	else
3757
		l2cap_send_sframe(chan, L2CAP_SUPER_RCV_READY);
3758 3759
}

3760
static inline int l2cap_data_channel_sframe(struct l2cap_chan *chan, u16 rx_control, struct sk_buff *skb)
3761
{
3762
	BT_DBG("chan %p rx_control 0x%4.4x len %d", chan, rx_control, skb->len);
3763

3764
	if (L2CAP_CTRL_FINAL & rx_control &&
3765
			chan->conn_state & L2CAP_CONN_WAIT_F) {
3766
		del_timer(&chan->monitor_timer);
3767
		if (chan->unacked_frames > 0)
3768
			__mod_retrans_timer();
3769
		chan->conn_state &= ~L2CAP_CONN_WAIT_F;
3770 3771 3772 3773
	}

	switch (rx_control & L2CAP_CTRL_SUPERVISE) {
	case L2CAP_SUPER_RCV_READY:
3774
		l2cap_data_channel_rrframe(chan, rx_control);
3775 3776
		break;

3777
	case L2CAP_SUPER_REJECT:
3778
		l2cap_data_channel_rejframe(chan, rx_control);
3779
		break;
3780

3781
	case L2CAP_SUPER_SELECT_REJECT:
3782
		l2cap_data_channel_srejframe(chan, rx_control);
3783 3784 3785
		break;

	case L2CAP_SUPER_RCV_NOT_READY:
3786
		l2cap_data_channel_rnrframe(chan, rx_control);
3787 3788 3789
		break;
	}

3790
	kfree_skb(skb);
3791 3792 3793
	return 0;
}

3794 3795
static int l2cap_ertm_data_rcv(struct sock *sk, struct sk_buff *skb)
{
3796
	struct l2cap_chan *chan = l2cap_pi(sk)->chan;
3797 3798 3799 3800 3801 3802 3803 3804 3805 3806 3807 3808 3809
	u16 control;
	u8 req_seq;
	int len, next_tx_seq_offset, req_seq_offset;

	control = get_unaligned_le16(skb->data);
	skb_pull(skb, 2);
	len = skb->len;

	/*
	 * We can just drop the corrupted I-frame here.
	 * Receiver will miss it and start proper recovery
	 * procedures and ask retransmission.
	 */
3810
	if (l2cap_check_fcs(chan, skb))
3811 3812 3813 3814 3815
		goto drop;

	if (__is_sar_start(control) && __is_iframe(control))
		len -= 2;

3816
	if (chan->fcs == L2CAP_FCS_CRC16)
3817 3818
		len -= 2;

3819
	if (len > chan->mps) {
3820
		l2cap_send_disconn_req(chan->conn, chan, ECONNRESET);
3821 3822 3823 3824
		goto drop;
	}

	req_seq = __get_reqseq(control);
3825
	req_seq_offset = (req_seq - chan->expected_ack_seq) % 64;
3826 3827 3828 3829
	if (req_seq_offset < 0)
		req_seq_offset += 64;

	next_tx_seq_offset =
3830
		(chan->next_tx_seq - chan->expected_ack_seq) % 64;
3831 3832 3833 3834 3835
	if (next_tx_seq_offset < 0)
		next_tx_seq_offset += 64;

	/* check for invalid req-seq */
	if (req_seq_offset > next_tx_seq_offset) {
3836
		l2cap_send_disconn_req(chan->conn, chan, ECONNRESET);
3837 3838 3839 3840 3841
		goto drop;
	}

	if (__is_iframe(control)) {
		if (len < 0) {
3842
			l2cap_send_disconn_req(chan->conn, chan, ECONNRESET);
3843 3844 3845
			goto drop;
		}

3846
		l2cap_data_channel_iframe(chan, control, skb);
3847 3848 3849
	} else {
		if (len != 0) {
			BT_ERR("%d", len);
3850
			l2cap_send_disconn_req(chan->conn, chan, ECONNRESET);
3851 3852 3853
			goto drop;
		}

3854
		l2cap_data_channel_sframe(chan, control, skb);
3855 3856 3857 3858 3859 3860 3861 3862 3863
	}

	return 0;

drop:
	kfree_skb(skb);
	return 0;
}

L
Linus Torvalds 已提交
3864 3865
static inline int l2cap_data_channel(struct l2cap_conn *conn, u16 cid, struct sk_buff *skb)
{
3866
	struct l2cap_chan *chan;
3867
	struct sock *sk = NULL;
3868
	u16 control;
3869 3870
	u8 tx_seq;
	int len;
L
Linus Torvalds 已提交
3871

3872
	chan = l2cap_get_chan_by_scid(conn, cid);
3873
	if (!chan) {
L
Linus Torvalds 已提交
3874 3875 3876 3877
		BT_DBG("unknown cid 0x%4.4x", cid);
		goto drop;
	}

3878
	sk = chan->sk;
3879

3880
	BT_DBG("chan %p, len %d", chan, skb->len);
L
Linus Torvalds 已提交
3881

3882
	if (chan->state != BT_CONNECTED)
L
Linus Torvalds 已提交
3883 3884
		goto drop;

3885
	switch (chan->mode) {
3886 3887 3888 3889 3890
	case L2CAP_MODE_BASIC:
		/* If socket recv buffers overflows we drop data here
		 * which is *bad* because L2CAP has to be reliable.
		 * But we don't have any other choice. L2CAP doesn't
		 * provide flow control mechanism. */
L
Linus Torvalds 已提交
3891

3892
		if (chan->imtu < skb->len)
3893
			goto drop;
L
Linus Torvalds 已提交
3894

3895
		if (!chan->ops->recv(chan->data, skb))
3896 3897 3898 3899
			goto done;
		break;

	case L2CAP_MODE_ERTM:
3900 3901
		if (!sock_owned_by_user(sk)) {
			l2cap_ertm_data_rcv(sk, skb);
3902
		} else {
3903
			if (sk_add_backlog(sk, skb))
3904 3905
				goto drop;
		}
3906

3907
		goto done;
3908

3909 3910 3911 3912 3913
	case L2CAP_MODE_STREAMING:
		control = get_unaligned_le16(skb->data);
		skb_pull(skb, 2);
		len = skb->len;

3914
		if (l2cap_check_fcs(chan, skb))
3915 3916
			goto drop;

3917 3918 3919
		if (__is_sar_start(control))
			len -= 2;

3920
		if (chan->fcs == L2CAP_FCS_CRC16)
3921 3922
			len -= 2;

3923
		if (len > chan->mps || len < 0 || __is_sframe(control))
3924 3925 3926 3927
			goto drop;

		tx_seq = __get_txseq(control);

3928 3929
		if (chan->expected_tx_seq == tx_seq)
			chan->expected_tx_seq = (chan->expected_tx_seq + 1) % 64;
3930
		else
3931
			chan->expected_tx_seq = (tx_seq + 1) % 64;
3932

3933
		l2cap_streaming_reassembly_sdu(chan, skb, control);
3934 3935 3936

		goto done;

3937
	default:
3938
		BT_DBG("chan %p: bad mode 0x%2.2x", chan, chan->mode);
3939 3940
		break;
	}
L
Linus Torvalds 已提交
3941 3942 3943 3944 3945

drop:
	kfree_skb(skb);

done:
3946 3947 3948
	if (sk)
		bh_unlock_sock(sk);

L
Linus Torvalds 已提交
3949 3950 3951
	return 0;
}

3952
static inline int l2cap_conless_channel(struct l2cap_conn *conn, __le16 psm, struct sk_buff *skb)
L
Linus Torvalds 已提交
3953
{
3954
	struct sock *sk = NULL;
3955
	struct l2cap_chan *chan;
L
Linus Torvalds 已提交
3956

3957 3958
	chan = l2cap_global_chan_by_psm(0, psm, conn->src);
	if (!chan)
L
Linus Torvalds 已提交
3959 3960
		goto drop;

3961 3962
	sk = chan->sk;

3963 3964
	bh_lock_sock(sk);

L
Linus Torvalds 已提交
3965 3966
	BT_DBG("sk %p, len %d", sk, skb->len);

3967
	if (chan->state != BT_BOUND && chan->state != BT_CONNECTED)
L
Linus Torvalds 已提交
3968 3969
		goto drop;

3970
	if (l2cap_pi(sk)->chan->imtu < skb->len)
L
Linus Torvalds 已提交
3971 3972
		goto drop;

3973
	if (!chan->ops->recv(chan->data, skb))
L
Linus Torvalds 已提交
3974 3975 3976 3977 3978 3979
		goto done;

drop:
	kfree_skb(skb);

done:
3980 3981
	if (sk)
		bh_unlock_sock(sk);
L
Linus Torvalds 已提交
3982 3983 3984
	return 0;
}

3985 3986
static inline int l2cap_att_channel(struct l2cap_conn *conn, __le16 cid, struct sk_buff *skb)
{
3987
	struct sock *sk = NULL;
3988
	struct l2cap_chan *chan;
3989

3990 3991
	chan = l2cap_global_chan_by_scid(0, cid, conn->src);
	if (!chan)
3992 3993
		goto drop;

3994 3995
	sk = chan->sk;

3996 3997 3998 3999
	bh_lock_sock(sk);

	BT_DBG("sk %p, len %d", sk, skb->len);

4000
	if (chan->state != BT_BOUND && chan->state != BT_CONNECTED)
4001 4002
		goto drop;

4003
	if (l2cap_pi(sk)->chan->imtu < skb->len)
4004 4005
		goto drop;

4006
	if (!chan->ops->recv(chan->data, skb))
4007 4008 4009 4010 4011 4012 4013 4014 4015 4016 4017
		goto done;

drop:
	kfree_skb(skb);

done:
	if (sk)
		bh_unlock_sock(sk);
	return 0;
}

L
Linus Torvalds 已提交
4018 4019 4020
static void l2cap_recv_frame(struct l2cap_conn *conn, struct sk_buff *skb)
{
	struct l2cap_hdr *lh = (void *) skb->data;
4021 4022
	u16 cid, len;
	__le16 psm;
L
Linus Torvalds 已提交
4023 4024 4025 4026 4027

	skb_pull(skb, L2CAP_HDR_SIZE);
	cid = __le16_to_cpu(lh->cid);
	len = __le16_to_cpu(lh->len);

4028 4029 4030 4031 4032
	if (len != skb->len) {
		kfree_skb(skb);
		return;
	}

L
Linus Torvalds 已提交
4033 4034 4035
	BT_DBG("len %d, cid 0x%4.4x", len, cid);

	switch (cid) {
4036
	case L2CAP_CID_LE_SIGNALING:
4037
	case L2CAP_CID_SIGNALING:
L
Linus Torvalds 已提交
4038 4039 4040
		l2cap_sig_channel(conn, skb);
		break;

4041
	case L2CAP_CID_CONN_LESS:
4042
		psm = get_unaligned_le16(skb->data);
L
Linus Torvalds 已提交
4043 4044 4045 4046
		skb_pull(skb, 2);
		l2cap_conless_channel(conn, psm, skb);
		break;

4047 4048 4049 4050
	case L2CAP_CID_LE_DATA:
		l2cap_att_channel(conn, cid, skb);
		break;

L
Linus Torvalds 已提交
4051 4052 4053 4054 4055 4056 4057 4058 4059 4060 4061
	default:
		l2cap_data_channel(conn, cid, skb);
		break;
	}
}

/* ---- L2CAP interface with lower layer (HCI) ---- */

static int l2cap_connect_ind(struct hci_dev *hdev, bdaddr_t *bdaddr, u8 type)
{
	int exact = 0, lm1 = 0, lm2 = 0;
4062
	struct l2cap_chan *c;
L
Linus Torvalds 已提交
4063 4064

	if (type != ACL_LINK)
4065
		return -EINVAL;
L
Linus Torvalds 已提交
4066 4067 4068 4069

	BT_DBG("hdev %s, bdaddr %s", hdev->name, batostr(bdaddr));

	/* Find listening sockets and check their link_mode */
4070 4071 4072
	read_lock(&chan_list_lock);
	list_for_each_entry(c, &chan_list, global_l) {
		struct sock *sk = c->sk;
4073

4074
		if (c->state != BT_LISTEN)
L
Linus Torvalds 已提交
4075 4076 4077
			continue;

		if (!bacmp(&bt_sk(sk)->src, &hdev->bdaddr)) {
4078
			lm1 |= HCI_LM_ACCEPT;
4079
			if (c->role_switch)
4080
				lm1 |= HCI_LM_MASTER;
L
Linus Torvalds 已提交
4081
			exact++;
4082 4083
		} else if (!bacmp(&bt_sk(sk)->src, BDADDR_ANY)) {
			lm2 |= HCI_LM_ACCEPT;
4084
			if (c->role_switch)
4085 4086
				lm2 |= HCI_LM_MASTER;
		}
L
Linus Torvalds 已提交
4087
	}
4088
	read_unlock(&chan_list_lock);
L
Linus Torvalds 已提交
4089 4090 4091 4092 4093 4094

	return exact ? lm1 : lm2;
}

static int l2cap_connect_cfm(struct hci_conn *hcon, u8 status)
{
4095 4096
	struct l2cap_conn *conn;

L
Linus Torvalds 已提交
4097 4098
	BT_DBG("hcon %p bdaddr %s status %d", hcon, batostr(&hcon->dst), status);

4099
	if (!(hcon->type == ACL_LINK || hcon->type == LE_LINK))
4100
		return -EINVAL;
L
Linus Torvalds 已提交
4101 4102 4103 4104 4105

	if (!status) {
		conn = l2cap_conn_add(hcon, status);
		if (conn)
			l2cap_conn_ready(conn);
4106
	} else
L
Linus Torvalds 已提交
4107 4108 4109 4110 4111
		l2cap_conn_del(hcon, bt_err(status));

	return 0;
}

4112 4113 4114 4115 4116 4117 4118 4119 4120 4121 4122 4123 4124
static int l2cap_disconn_ind(struct hci_conn *hcon)
{
	struct l2cap_conn *conn = hcon->l2cap_data;

	BT_DBG("hcon %p", hcon);

	if (hcon->type != ACL_LINK || !conn)
		return 0x13;

	return conn->disc_reason;
}

static int l2cap_disconn_cfm(struct hci_conn *hcon, u8 reason)
L
Linus Torvalds 已提交
4125 4126 4127
{
	BT_DBG("hcon %p reason %d", hcon, reason);

4128
	if (!(hcon->type == ACL_LINK || hcon->type == LE_LINK))
4129
		return -EINVAL;
L
Linus Torvalds 已提交
4130 4131

	l2cap_conn_del(hcon, bt_err(reason));
4132

L
Linus Torvalds 已提交
4133 4134 4135
	return 0;
}

4136
static inline void l2cap_check_encryption(struct l2cap_chan *chan, u8 encrypt)
4137
{
4138
	if (chan->chan_type != L2CAP_CHAN_CONN_ORIENTED)
4139 4140
		return;

4141
	if (encrypt == 0x00) {
4142
		if (chan->sec_level == BT_SECURITY_MEDIUM) {
4143 4144
			l2cap_chan_clear_timer(chan);
			l2cap_chan_set_timer(chan, HZ * 5);
4145
		} else if (chan->sec_level == BT_SECURITY_HIGH)
4146
			l2cap_chan_close(chan, ECONNREFUSED);
4147
	} else {
4148
		if (chan->sec_level == BT_SECURITY_MEDIUM)
4149
			l2cap_chan_clear_timer(chan);
4150 4151 4152
	}
}

4153
static int l2cap_security_cfm(struct hci_conn *hcon, u8 status, u8 encrypt)
L
Linus Torvalds 已提交
4154
{
4155
	struct l2cap_conn *conn = hcon->l2cap_data;
4156
	struct l2cap_chan *chan;
L
Linus Torvalds 已提交
4157

4158
	if (!conn)
L
Linus Torvalds 已提交
4159
		return 0;
4160

L
Linus Torvalds 已提交
4161 4162
	BT_DBG("conn %p", conn);

4163
	read_lock(&conn->chan_lock);
L
Linus Torvalds 已提交
4164

4165
	list_for_each_entry(chan, &conn->chan_l, list) {
4166
		struct sock *sk = chan->sk;
4167

L
Linus Torvalds 已提交
4168 4169
		bh_lock_sock(sk);

4170
		if (chan->conf_state & L2CAP_CONF_CONNECT_PEND) {
4171 4172 4173 4174
			bh_unlock_sock(sk);
			continue;
		}

4175 4176
		if (!status && (chan->state == BT_CONNECTED ||
						chan->state == BT_CONFIG)) {
4177
			l2cap_check_encryption(chan, encrypt);
4178 4179 4180 4181
			bh_unlock_sock(sk);
			continue;
		}

4182
		if (chan->state == BT_CONNECT) {
4183 4184
			if (!status) {
				struct l2cap_conn_req req;
4185 4186
				req.scid = cpu_to_le16(chan->scid);
				req.psm  = chan->psm;
L
Linus Torvalds 已提交
4187

4188
				chan->ident = l2cap_get_ident(conn);
4189
				chan->conf_state |= L2CAP_CONF_CONNECT_PEND;
L
Linus Torvalds 已提交
4190

4191
				l2cap_send_cmd(conn, chan->ident,
4192 4193
					L2CAP_CONN_REQ, sizeof(req), &req);
			} else {
4194 4195
				l2cap_chan_clear_timer(chan);
				l2cap_chan_set_timer(chan, HZ / 10);
4196
			}
4197
		} else if (chan->state == BT_CONNECT2) {
4198 4199
			struct l2cap_conn_rsp rsp;
			__u16 result;
L
Linus Torvalds 已提交
4200

4201
			if (!status) {
4202
				l2cap_state_change(chan, BT_CONFIG);
4203 4204
				result = L2CAP_CR_SUCCESS;
			} else {
4205
				l2cap_state_change(chan, BT_DISCONN);
4206
				l2cap_chan_set_timer(chan, HZ / 10);
4207 4208 4209
				result = L2CAP_CR_SEC_BLOCK;
			}

4210 4211
			rsp.scid   = cpu_to_le16(chan->dcid);
			rsp.dcid   = cpu_to_le16(chan->scid);
4212
			rsp.result = cpu_to_le16(result);
4213
			rsp.status = cpu_to_le16(L2CAP_CS_NO_INFO);
4214 4215
			l2cap_send_cmd(conn, chan->ident, L2CAP_CONN_RSP,
							sizeof(rsp), &rsp);
4216
		}
L
Linus Torvalds 已提交
4217 4218 4219 4220

		bh_unlock_sock(sk);
	}

4221
	read_unlock(&conn->chan_lock);
4222

L
Linus Torvalds 已提交
4223 4224 4225 4226 4227 4228 4229
	return 0;
}

static int l2cap_recv_acldata(struct hci_conn *hcon, struct sk_buff *skb, u16 flags)
{
	struct l2cap_conn *conn = hcon->l2cap_data;

4230 4231 4232 4233
	if (!conn)
		conn = l2cap_conn_add(hcon, 0);

	if (!conn)
L
Linus Torvalds 已提交
4234 4235 4236 4237
		goto drop;

	BT_DBG("conn %p len %d flags 0x%x", conn, skb->len, flags);

4238
	if (!(flags & ACL_CONT)) {
L
Linus Torvalds 已提交
4239
		struct l2cap_hdr *hdr;
4240
		struct l2cap_chan *chan;
4241
		u16 cid;
L
Linus Torvalds 已提交
4242 4243 4244 4245 4246 4247 4248 4249 4250 4251
		int len;

		if (conn->rx_len) {
			BT_ERR("Unexpected start frame (len %d)", skb->len);
			kfree_skb(conn->rx_skb);
			conn->rx_skb = NULL;
			conn->rx_len = 0;
			l2cap_conn_unreliable(conn, ECOMM);
		}

4252 4253
		/* Start fragment always begin with Basic L2CAP header */
		if (skb->len < L2CAP_HDR_SIZE) {
L
Linus Torvalds 已提交
4254 4255 4256 4257 4258 4259 4260
			BT_ERR("Frame is too short (len %d)", skb->len);
			l2cap_conn_unreliable(conn, ECOMM);
			goto drop;
		}

		hdr = (struct l2cap_hdr *) skb->data;
		len = __le16_to_cpu(hdr->len) + L2CAP_HDR_SIZE;
4261
		cid = __le16_to_cpu(hdr->cid);
L
Linus Torvalds 已提交
4262 4263 4264 4265 4266 4267 4268 4269 4270 4271 4272 4273 4274 4275 4276 4277

		if (len == skb->len) {
			/* Complete frame received */
			l2cap_recv_frame(conn, skb);
			return 0;
		}

		BT_DBG("Start: total len %d, frag len %d", len, skb->len);

		if (skb->len > len) {
			BT_ERR("Frame is too long (len %d, expected len %d)",
				skb->len, len);
			l2cap_conn_unreliable(conn, ECOMM);
			goto drop;
		}

4278
		chan = l2cap_get_chan_by_scid(conn, cid);
4279

4280 4281
		if (chan && chan->sk) {
			struct sock *sk = chan->sk;
4282

4283
			if (chan->imtu < len - L2CAP_HDR_SIZE) {
4284 4285
				BT_ERR("Frame exceeding recv MTU (len %d, "
							"MTU %d)", len,
4286
							chan->imtu);
4287 4288 4289 4290
				bh_unlock_sock(sk);
				l2cap_conn_unreliable(conn, ECOMM);
				goto drop;
			}
4291
			bh_unlock_sock(sk);
4292
		}
4293

L
Linus Torvalds 已提交
4294
		/* Allocate skb for the complete frame (with header) */
4295 4296
		conn->rx_skb = bt_skb_alloc(len, GFP_ATOMIC);
		if (!conn->rx_skb)
L
Linus Torvalds 已提交
4297 4298
			goto drop;

4299
		skb_copy_from_linear_data(skb, skb_put(conn->rx_skb, skb->len),
4300
								skb->len);
L
Linus Torvalds 已提交
4301 4302 4303 4304 4305 4306 4307 4308 4309 4310 4311 4312 4313 4314 4315 4316 4317 4318 4319 4320
		conn->rx_len = len - skb->len;
	} else {
		BT_DBG("Cont: frag len %d (expecting %d)", skb->len, conn->rx_len);

		if (!conn->rx_len) {
			BT_ERR("Unexpected continuation frame (len %d)", skb->len);
			l2cap_conn_unreliable(conn, ECOMM);
			goto drop;
		}

		if (skb->len > conn->rx_len) {
			BT_ERR("Fragment is too long (len %d, expected %d)",
					skb->len, conn->rx_len);
			kfree_skb(conn->rx_skb);
			conn->rx_skb = NULL;
			conn->rx_len = 0;
			l2cap_conn_unreliable(conn, ECOMM);
			goto drop;
		}

4321
		skb_copy_from_linear_data(skb, skb_put(conn->rx_skb, skb->len),
4322
								skb->len);
L
Linus Torvalds 已提交
4323 4324 4325 4326 4327 4328 4329 4330 4331 4332 4333 4334 4335 4336
		conn->rx_len -= skb->len;

		if (!conn->rx_len) {
			/* Complete frame received */
			l2cap_recv_frame(conn, conn->rx_skb);
			conn->rx_skb = NULL;
		}
	}

drop:
	kfree_skb(skb);
	return 0;
}

4337
static int l2cap_debugfs_show(struct seq_file *f, void *p)
L
Linus Torvalds 已提交
4338
{
4339
	struct l2cap_chan *c;
L
Linus Torvalds 已提交
4340

4341
	read_lock_bh(&chan_list_lock);
L
Linus Torvalds 已提交
4342

4343 4344
	list_for_each_entry(c, &chan_list, global_l) {
		struct sock *sk = c->sk;
4345

4346
		seq_printf(f, "%s %s %d %d 0x%4.4x 0x%4.4x %d %d %d %d\n",
4347 4348
					batostr(&bt_sk(sk)->src),
					batostr(&bt_sk(sk)->dst),
4349
					c->state, __le16_to_cpu(c->psm),
4350 4351
					c->scid, c->dcid, c->imtu, c->omtu,
					c->sec_level, c->mode);
4352
	}
L
Linus Torvalds 已提交
4353

4354
	read_unlock_bh(&chan_list_lock);
L
Linus Torvalds 已提交
4355

4356
	return 0;
L
Linus Torvalds 已提交
4357 4358
}

4359 4360 4361 4362 4363 4364 4365 4366 4367 4368 4369 4370 4371
static int l2cap_debugfs_open(struct inode *inode, struct file *file)
{
	return single_open(file, l2cap_debugfs_show, inode->i_private);
}

static const struct file_operations l2cap_debugfs_fops = {
	.open		= l2cap_debugfs_open,
	.read		= seq_read,
	.llseek		= seq_lseek,
	.release	= single_release,
};

static struct dentry *l2cap_debugfs;
L
Linus Torvalds 已提交
4372 4373 4374 4375 4376 4377 4378

static struct hci_proto l2cap_hci_proto = {
	.name		= "L2CAP",
	.id		= HCI_PROTO_L2CAP,
	.connect_ind	= l2cap_connect_ind,
	.connect_cfm	= l2cap_connect_cfm,
	.disconn_ind	= l2cap_disconn_ind,
4379
	.disconn_cfm	= l2cap_disconn_cfm,
4380
	.security_cfm	= l2cap_security_cfm,
L
Linus Torvalds 已提交
4381 4382 4383
	.recv_acldata	= l2cap_recv_acldata
};

4384
int __init l2cap_init(void)
L
Linus Torvalds 已提交
4385 4386
{
	int err;
4387

4388
	err = l2cap_init_sockets();
L
Linus Torvalds 已提交
4389 4390 4391
	if (err < 0)
		return err;

4392
	_busy_wq = create_singlethread_workqueue("l2cap");
4393
	if (!_busy_wq) {
4394
		err = -ENOMEM;
L
Linus Torvalds 已提交
4395 4396 4397 4398 4399 4400 4401 4402 4403 4404
		goto error;
	}

	err = hci_register_proto(&l2cap_hci_proto);
	if (err < 0) {
		BT_ERR("L2CAP protocol registration failed");
		bt_sock_unregister(BTPROTO_L2CAP);
		goto error;
	}

4405 4406 4407 4408 4409 4410
	if (bt_debugfs) {
		l2cap_debugfs = debugfs_create_file("l2cap", 0444,
					bt_debugfs, NULL, &l2cap_debugfs_fops);
		if (!l2cap_debugfs)
			BT_ERR("Failed to create L2CAP debug file");
	}
L
Linus Torvalds 已提交
4411 4412 4413 4414

	return 0;

error:
4415
	destroy_workqueue(_busy_wq);
4416
	l2cap_cleanup_sockets();
L
Linus Torvalds 已提交
4417 4418 4419
	return err;
}

4420
void l2cap_exit(void)
L
Linus Torvalds 已提交
4421
{
4422
	debugfs_remove(l2cap_debugfs);
L
Linus Torvalds 已提交
4423

4424 4425 4426
	flush_workqueue(_busy_wq);
	destroy_workqueue(_busy_wq);

L
Linus Torvalds 已提交
4427 4428 4429
	if (hci_unregister_proto(&l2cap_hci_proto) < 0)
		BT_ERR("L2CAP protocol unregistration failed");

4430
	l2cap_cleanup_sockets();
L
Linus Torvalds 已提交
4431 4432
}

4433 4434
module_param(disable_ertm, bool, 0644);
MODULE_PARM_DESC(disable_ertm, "Disable enhanced retransmission mode");