l2cap_core.c 116.8 KB
Newer Older
1
/*
L
Linus Torvalds 已提交
2 3
   BlueZ - Bluetooth protocol stack for Linux
   Copyright (C) 2000-2001 Qualcomm Incorporated
4
   Copyright (C) 2009-2010 Gustavo F. Padovan <gustavo@padovan.org>
5
   Copyright (C) 2010 Google Inc.
6
   Copyright (C) 2011 ProFUSION Embedded Systems
7
   Copyright (c) 2012 Code Aurora Forum.  All rights reserved.
L
Linus Torvalds 已提交
8 9 10 11 12 13 14 15 16 17 18

   Written 2000,2001 by Maxim Krasnyansky <maxk@qualcomm.com>

   This program is free software; you can redistribute it and/or modify
   it under the terms of the GNU General Public License version 2 as
   published by the Free Software Foundation;

   THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS
   OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
   FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT OF THIRD PARTY RIGHTS.
   IN NO EVENT SHALL THE COPYRIGHT HOLDER(S) AND AUTHOR(S) BE LIABLE FOR ANY
19 20 21
   CLAIM, OR ANY SPECIAL INDIRECT OR CONSEQUENTIAL DAMAGES, OR ANY DAMAGES
   WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
   ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
L
Linus Torvalds 已提交
22 23
   OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.

24 25
   ALL LIABILITY, INCLUDING LIABILITY FOR INFRINGEMENT OF ANY PATENTS,
   COPYRIGHTS, TRADEMARKS OR OTHER RIGHTS, RELATING TO USE OF THIS
L
Linus Torvalds 已提交
26 27 28
   SOFTWARE IS DISCLAIMED.
*/

29
/* Bluetooth L2CAP core. */
L
Linus Torvalds 已提交
30 31 32 33

#include <linux/module.h>

#include <linux/types.h>
34
#include <linux/capability.h>
L
Linus Torvalds 已提交
35 36 37 38 39 40 41 42 43 44 45
#include <linux/errno.h>
#include <linux/kernel.h>
#include <linux/sched.h>
#include <linux/slab.h>
#include <linux/poll.h>
#include <linux/fcntl.h>
#include <linux/init.h>
#include <linux/interrupt.h>
#include <linux/socket.h>
#include <linux/skbuff.h>
#include <linux/list.h>
46
#include <linux/device.h>
47 48
#include <linux/debugfs.h>
#include <linux/seq_file.h>
49
#include <linux/uaccess.h>
50
#include <linux/crc16.h>
L
Linus Torvalds 已提交
51 52 53 54 55 56 57
#include <net/sock.h>

#include <asm/unaligned.h>

#include <net/bluetooth/bluetooth.h>
#include <net/bluetooth/hci_core.h>
#include <net/bluetooth/l2cap.h>
58
#include <net/bluetooth/smp.h>
L
Linus Torvalds 已提交
59

60
bool disable_ertm;
61

62
static u32 l2cap_feat_mask = L2CAP_FEAT_FIXED_CHAN;
63
static u8 l2cap_fixed_chan[8] = { L2CAP_FC_L2CAP, };
L
Linus Torvalds 已提交
64

65 66
static LIST_HEAD(chan_list);
static DEFINE_RWLOCK(chan_list_lock);
L
Linus Torvalds 已提交
67 68 69

static struct sk_buff *l2cap_build_cmd(struct l2cap_conn *conn,
				u8 code, u8 ident, u16 dlen, void *data);
70 71
static void l2cap_send_cmd(struct l2cap_conn *conn, u8 ident, u8 code, u16 len,
								void *data);
72
static int l2cap_build_conf_req(struct l2cap_chan *chan, void *data);
73 74
static void l2cap_send_disconn_req(struct l2cap_conn *conn,
				struct l2cap_chan *chan, int err);
L
Linus Torvalds 已提交
75

76
/* ---- L2CAP channels ---- */
77

78
static struct l2cap_chan *__l2cap_get_chan_by_dcid(struct l2cap_conn *conn, u16 cid)
79
{
80
	struct l2cap_chan *c;
81

82 83 84
	list_for_each_entry(c, &conn->chan_l, list) {
		if (c->dcid == cid)
			return c;
85
	}
86
	return NULL;
87 88
}

89
static struct l2cap_chan *__l2cap_get_chan_by_scid(struct l2cap_conn *conn, u16 cid)
90
{
91
	struct l2cap_chan *c;
92

93 94 95
	list_for_each_entry(c, &conn->chan_l, list) {
		if (c->scid == cid)
			return c;
96
	}
97
	return NULL;
98 99 100 101
}

/* Find channel with given SCID.
 * Returns locked socket */
102
static struct l2cap_chan *l2cap_get_chan_by_scid(struct l2cap_conn *conn, u16 cid)
103
{
104
	struct l2cap_chan *c;
105

106
	mutex_lock(&conn->chan_lock);
107
	c = __l2cap_get_chan_by_scid(conn, cid);
108 109
	mutex_unlock(&conn->chan_lock);

110
	return c;
111 112
}

113
static struct l2cap_chan *__l2cap_get_chan_by_ident(struct l2cap_conn *conn, u8 ident)
114
{
115
	struct l2cap_chan *c;
116

117 118 119
	list_for_each_entry(c, &conn->chan_l, list) {
		if (c->ident == ident)
			return c;
120
	}
121
	return NULL;
122 123
}

124
static struct l2cap_chan *__l2cap_global_chan_by_addr(__le16 psm, bdaddr_t *src)
125
{
126
	struct l2cap_chan *c;
127

128 129
	list_for_each_entry(c, &chan_list, global_l) {
		if (c->sport == psm && !bacmp(&bt_sk(c->sk)->src, src))
130
			return c;
131
	}
132
	return NULL;
133 134 135 136
}

int l2cap_add_psm(struct l2cap_chan *chan, bdaddr_t *src, __le16 psm)
{
137 138
	int err;

139
	write_lock(&chan_list_lock);
140

141
	if (psm && __l2cap_global_chan_by_addr(psm, src)) {
142 143
		err = -EADDRINUSE;
		goto done;
144 145
	}

146 147 148 149 150 151 152 153 154
	if (psm) {
		chan->psm = psm;
		chan->sport = psm;
		err = 0;
	} else {
		u16 p;

		err = -EINVAL;
		for (p = 0x1001; p < 0x1100; p += 2)
155
			if (!__l2cap_global_chan_by_addr(cpu_to_le16(p), src)) {
156 157 158 159 160 161
				chan->psm   = cpu_to_le16(p);
				chan->sport = cpu_to_le16(p);
				err = 0;
				break;
			}
	}
162

163
done:
164
	write_unlock(&chan_list_lock);
165
	return err;
166 167 168 169
}

int l2cap_add_scid(struct l2cap_chan *chan,  __u16 scid)
{
170
	write_lock(&chan_list_lock);
171 172 173

	chan->scid = scid;

174
	write_unlock(&chan_list_lock);
175 176 177 178

	return 0;
}

179
static u16 l2cap_alloc_cid(struct l2cap_conn *conn)
180
{
181
	u16 cid = L2CAP_CID_DYN_START;
182

183
	for (; cid < L2CAP_CID_DYN_END; cid++) {
184
		if (!__l2cap_get_chan_by_scid(conn, cid))
185 186 187 188 189 190
			return cid;
	}

	return 0;
}

191
static void __l2cap_state_change(struct l2cap_chan *chan, int state)
192
{
193
	BT_DBG("chan %p %s -> %s", chan, state_to_string(chan->state),
194 195
						state_to_string(state));

196 197 198 199
	chan->state = state;
	chan->ops->state_change(chan->data, state);
}

200 201 202 203 204 205 206 207 208
static void l2cap_state_change(struct l2cap_chan *chan, int state)
{
	struct sock *sk = chan->sk;

	lock_sock(sk);
	__l2cap_state_change(chan, state);
	release_sock(sk);
}

209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224
static inline void __l2cap_chan_set_err(struct l2cap_chan *chan, int err)
{
	struct sock *sk = chan->sk;

	sk->sk_err = err;
}

static inline void l2cap_chan_set_err(struct l2cap_chan *chan, int err)
{
	struct sock *sk = chan->sk;

	lock_sock(sk);
	__l2cap_chan_set_err(chan, err);
	release_sock(sk);
}

225 226 227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 258 259 260 261 262 263 264 265 266 267 268 269 270 271 272 273 274 275 276 277 278 279 280 281 282 283 284 285 286 287 288 289 290 291 292 293 294 295 296 297 298 299 300 301 302 303 304 305 306 307 308 309 310 311 312
/* ---- L2CAP sequence number lists ---- */

/* For ERTM, ordered lists of sequence numbers must be tracked for
 * SREJ requests that are received and for frames that are to be
 * retransmitted. These seq_list functions implement a singly-linked
 * list in an array, where membership in the list can also be checked
 * in constant time. Items can also be added to the tail of the list
 * and removed from the head in constant time, without further memory
 * allocs or frees.
 */

static int l2cap_seq_list_init(struct l2cap_seq_list *seq_list, u16 size)
{
	size_t alloc_size, i;

	/* Allocated size is a power of 2 to map sequence numbers
	 * (which may be up to 14 bits) in to a smaller array that is
	 * sized for the negotiated ERTM transmit windows.
	 */
	alloc_size = roundup_pow_of_two(size);

	seq_list->list = kmalloc(sizeof(u16) * alloc_size, GFP_KERNEL);
	if (!seq_list->list)
		return -ENOMEM;

	seq_list->mask = alloc_size - 1;
	seq_list->head = L2CAP_SEQ_LIST_CLEAR;
	seq_list->tail = L2CAP_SEQ_LIST_CLEAR;
	for (i = 0; i < alloc_size; i++)
		seq_list->list[i] = L2CAP_SEQ_LIST_CLEAR;

	return 0;
}

static inline void l2cap_seq_list_free(struct l2cap_seq_list *seq_list)
{
	kfree(seq_list->list);
}

static inline bool l2cap_seq_list_contains(struct l2cap_seq_list *seq_list,
					   u16 seq)
{
	/* Constant-time check for list membership */
	return seq_list->list[seq & seq_list->mask] != L2CAP_SEQ_LIST_CLEAR;
}

static u16 l2cap_seq_list_remove(struct l2cap_seq_list *seq_list, u16 seq)
{
	u16 mask = seq_list->mask;

	if (seq_list->head == L2CAP_SEQ_LIST_CLEAR) {
		/* In case someone tries to pop the head of an empty list */
		return L2CAP_SEQ_LIST_CLEAR;
	} else if (seq_list->head == seq) {
		/* Head can be removed in constant time */
		seq_list->head = seq_list->list[seq & mask];
		seq_list->list[seq & mask] = L2CAP_SEQ_LIST_CLEAR;

		if (seq_list->head == L2CAP_SEQ_LIST_TAIL) {
			seq_list->head = L2CAP_SEQ_LIST_CLEAR;
			seq_list->tail = L2CAP_SEQ_LIST_CLEAR;
		}
	} else {
		/* Walk the list to find the sequence number */
		u16 prev = seq_list->head;
		while (seq_list->list[prev & mask] != seq) {
			prev = seq_list->list[prev & mask];
			if (prev == L2CAP_SEQ_LIST_TAIL)
				return L2CAP_SEQ_LIST_CLEAR;
		}

		/* Unlink the number from the list and clear it */
		seq_list->list[prev & mask] = seq_list->list[seq & mask];
		seq_list->list[seq & mask] = L2CAP_SEQ_LIST_CLEAR;
		if (seq_list->tail == seq)
			seq_list->tail = prev;
	}
	return seq;
}

static inline u16 l2cap_seq_list_pop(struct l2cap_seq_list *seq_list)
{
	/* Remove the head in constant time */
	return l2cap_seq_list_remove(seq_list, seq_list->head);
}

static void l2cap_seq_list_clear(struct l2cap_seq_list *seq_list)
{
313
	u16 i;
314

315 316 317 318 319 320 321 322
	if (seq_list->head == L2CAP_SEQ_LIST_CLEAR)
		return;

	for (i = 0; i <= seq_list->mask; i++)
		seq_list->list[i] = L2CAP_SEQ_LIST_CLEAR;

	seq_list->head = L2CAP_SEQ_LIST_CLEAR;
	seq_list->tail = L2CAP_SEQ_LIST_CLEAR;
323 324 325 326 327 328 329 330
}

static void l2cap_seq_list_append(struct l2cap_seq_list *seq_list, u16 seq)
{
	u16 mask = seq_list->mask;

	/* All appends happen in constant time */

331 332
	if (seq_list->list[seq & mask] != L2CAP_SEQ_LIST_CLEAR)
		return;
333

334 335 336 337 338 339 340
	if (seq_list->tail == L2CAP_SEQ_LIST_CLEAR)
		seq_list->head = seq;
	else
		seq_list->list[seq_list->tail & mask] = seq;

	seq_list->tail = seq;
	seq_list->list[seq & mask] = L2CAP_SEQ_LIST_TAIL;
341 342
}

343
static void l2cap_chan_timeout(struct work_struct *work)
344
{
345 346
	struct l2cap_chan *chan = container_of(work, struct l2cap_chan,
							chan_timer.work);
347
	struct l2cap_conn *conn = chan->conn;
348 349
	int reason;

350
	BT_DBG("chan %p state %s", chan, state_to_string(chan->state));
351

352
	mutex_lock(&conn->chan_lock);
353
	l2cap_chan_lock(chan);
354

355
	if (chan->state == BT_CONNECTED || chan->state == BT_CONFIG)
356
		reason = ECONNREFUSED;
357
	else if (chan->state == BT_CONNECT &&
358 359 360 361 362
					chan->sec_level != BT_SECURITY_SDP)
		reason = ECONNREFUSED;
	else
		reason = ETIMEDOUT;

363
	l2cap_chan_close(chan, reason);
364

365
	l2cap_chan_unlock(chan);
366

367
	chan->ops->close(chan->data);
368 369
	mutex_unlock(&conn->chan_lock);

370
	l2cap_chan_put(chan);
371 372
}

373
struct l2cap_chan *l2cap_chan_create(void)
374 375 376 377 378 379 380
{
	struct l2cap_chan *chan;

	chan = kzalloc(sizeof(*chan), GFP_ATOMIC);
	if (!chan)
		return NULL;

381 382
	mutex_init(&chan->lock);

383
	write_lock(&chan_list_lock);
384
	list_add(&chan->global_l, &chan_list);
385
	write_unlock(&chan_list_lock);
386

387
	INIT_DELAYED_WORK(&chan->chan_timer, l2cap_chan_timeout);
388

389 390
	chan->state = BT_OPEN;

391 392
	atomic_set(&chan->refcnt, 1);

393
	BT_DBG("chan %p", chan);
394

395 396 397
	return chan;
}

398
void l2cap_chan_destroy(struct l2cap_chan *chan)
399
{
400
	write_lock(&chan_list_lock);
401
	list_del(&chan->global_l);
402
	write_unlock(&chan_list_lock);
403

404
	l2cap_chan_put(chan);
405 406
}

407 408 409 410 411 412 413 414 415 416 417
void l2cap_chan_set_defaults(struct l2cap_chan *chan)
{
	chan->fcs  = L2CAP_FCS_CRC16;
	chan->max_tx = L2CAP_DEFAULT_MAX_TX;
	chan->tx_win = L2CAP_DEFAULT_TX_WINDOW;
	chan->tx_win_max = L2CAP_DEFAULT_TX_WINDOW;
	chan->sec_level = BT_SECURITY_LOW;

	set_bit(FLAG_FORCE_ACTIVE, &chan->flags);
}

418
static void __l2cap_chan_add(struct l2cap_conn *conn, struct l2cap_chan *chan)
419
{
420
	BT_DBG("conn %p, psm 0x%2.2x, dcid 0x%4.4x", conn,
421
	       __le16_to_cpu(chan->psm), chan->dcid);
422

423
	conn->disc_reason = HCI_ERROR_REMOTE_USER_TERM;
424

425
	chan->conn = conn;
426

427 428
	switch (chan->chan_type) {
	case L2CAP_CHAN_CONN_ORIENTED:
429 430
		if (conn->hcon->type == LE_LINK) {
			/* LE connection */
431
			chan->omtu = L2CAP_LE_DEFAULT_MTU;
432 433
			chan->scid = L2CAP_CID_LE_DATA;
			chan->dcid = L2CAP_CID_LE_DATA;
434 435
		} else {
			/* Alloc CID for connection-oriented socket */
436
			chan->scid = l2cap_alloc_cid(conn);
437
			chan->omtu = L2CAP_DEFAULT_MTU;
438
		}
439 440 441
		break;

	case L2CAP_CHAN_CONN_LESS:
442
		/* Connectionless socket */
443 444
		chan->scid = L2CAP_CID_CONN_LESS;
		chan->dcid = L2CAP_CID_CONN_LESS;
445
		chan->omtu = L2CAP_DEFAULT_MTU;
446 447 448
		break;

	default:
449
		/* Raw socket can send/recv signalling messages only */
450 451
		chan->scid = L2CAP_CID_SIGNALING;
		chan->dcid = L2CAP_CID_SIGNALING;
452
		chan->omtu = L2CAP_DEFAULT_MTU;
453 454
	}

455 456 457 458 459 460 461
	chan->local_id		= L2CAP_BESTEFFORT_ID;
	chan->local_stype	= L2CAP_SERV_BESTEFFORT;
	chan->local_msdu	= L2CAP_DEFAULT_MAX_SDU_SIZE;
	chan->local_sdu_itime	= L2CAP_DEFAULT_SDU_ITIME;
	chan->local_acc_lat	= L2CAP_DEFAULT_ACC_LAT;
	chan->local_flush_to	= L2CAP_DEFAULT_FLUSH_TO;

462
	l2cap_chan_hold(chan);
463

464
	list_add(&chan->list, &conn->chan_l);
465 466
}

467
static void l2cap_chan_add(struct l2cap_conn *conn, struct l2cap_chan *chan)
468 469 470
{
	mutex_lock(&conn->chan_lock);
	__l2cap_chan_add(conn, chan);
471
	mutex_unlock(&conn->chan_lock);
472 473
}

474
static void l2cap_chan_del(struct l2cap_chan *chan, int err)
475
{
476
	struct sock *sk = chan->sk;
477
	struct l2cap_conn *conn = chan->conn;
478 479
	struct sock *parent = bt_sk(sk)->parent;

480
	__clear_chan_timer(chan);
481

482
	BT_DBG("chan %p, conn %p, err %d", chan, conn, err);
483

484
	if (conn) {
485
		/* Delete from channel list */
486
		list_del(&chan->list);
487

488
		l2cap_chan_put(chan);
489

490
		chan->conn = NULL;
491 492 493
		hci_conn_put(conn->hcon);
	}

494 495
	lock_sock(sk);

496
	__l2cap_state_change(chan, BT_CLOSED);
497 498 499
	sock_set_flag(sk, SOCK_ZAPPED);

	if (err)
500
		__l2cap_chan_set_err(chan, err);
501 502 503 504 505 506

	if (parent) {
		bt_accept_unlink(sk);
		parent->sk_data_ready(parent, 0);
	} else
		sk->sk_state_change(sk);
507

508 509
	release_sock(sk);

510 511
	if (!(test_bit(CONF_OUTPUT_DONE, &chan->conf_state) &&
			test_bit(CONF_INPUT_DONE, &chan->conf_state)))
512
		return;
513

514
	skb_queue_purge(&chan->tx_q);
515

516
	if (chan->mode == L2CAP_MODE_ERTM) {
517 518
		struct srej_list *l, *tmp;

519 520 521
		__clear_retrans_timer(chan);
		__clear_monitor_timer(chan);
		__clear_ack_timer(chan);
522

523
		skb_queue_purge(&chan->srej_q);
524

525 526
		l2cap_seq_list_free(&chan->srej_list);
		l2cap_seq_list_free(&chan->retrans_list);
527
		list_for_each_entry_safe(l, tmp, &chan->srej_l, list) {
528 529 530 531
			list_del(&l->list);
			kfree(l);
		}
	}
532 533
}

534 535 536 537 538 539 540
static void l2cap_chan_cleanup_listen(struct sock *parent)
{
	struct sock *sk;

	BT_DBG("parent %p", parent);

	/* Close not yet accepted channels */
541
	while ((sk = bt_accept_dequeue(parent, NULL))) {
542
		struct l2cap_chan *chan = l2cap_pi(sk)->chan;
543

544
		l2cap_chan_lock(chan);
545
		__clear_chan_timer(chan);
546
		l2cap_chan_close(chan, ECONNRESET);
547
		l2cap_chan_unlock(chan);
548

549
		chan->ops->close(chan->data);
550
	}
551 552
}

553
void l2cap_chan_close(struct l2cap_chan *chan, int reason)
554 555 556 557
{
	struct l2cap_conn *conn = chan->conn;
	struct sock *sk = chan->sk;

558 559
	BT_DBG("chan %p state %s sk %p", chan,
					state_to_string(chan->state), sk);
560

561
	switch (chan->state) {
562
	case BT_LISTEN:
563
		lock_sock(sk);
564
		l2cap_chan_cleanup_listen(sk);
565

566
		__l2cap_state_change(chan, BT_CLOSED);
567
		sock_set_flag(sk, SOCK_ZAPPED);
568
		release_sock(sk);
569 570 571 572
		break;

	case BT_CONNECTED:
	case BT_CONFIG:
573
		if (chan->chan_type == L2CAP_CHAN_CONN_ORIENTED &&
574
					conn->hcon->type == ACL_LINK) {
575
			__set_chan_timer(chan, sk->sk_sndtimeo);
576 577 578 579 580 581
			l2cap_send_disconn_req(conn, chan, reason);
		} else
			l2cap_chan_del(chan, reason);
		break;

	case BT_CONNECT2:
582
		if (chan->chan_type == L2CAP_CHAN_CONN_ORIENTED &&
583 584 585 586 587 588 589 590
					conn->hcon->type == ACL_LINK) {
			struct l2cap_conn_rsp rsp;
			__u16 result;

			if (bt_sk(sk)->defer_setup)
				result = L2CAP_CR_SEC_BLOCK;
			else
				result = L2CAP_CR_BAD_PSM;
591
			l2cap_state_change(chan, BT_DISCONN);
592 593 594 595 596 597 598 599 600 601 602 603 604 605 606 607 608 609

			rsp.scid   = cpu_to_le16(chan->dcid);
			rsp.dcid   = cpu_to_le16(chan->scid);
			rsp.result = cpu_to_le16(result);
			rsp.status = cpu_to_le16(L2CAP_CS_NO_INFO);
			l2cap_send_cmd(conn, chan->ident, L2CAP_CONN_RSP,
							sizeof(rsp), &rsp);
		}

		l2cap_chan_del(chan, reason);
		break;

	case BT_CONNECT:
	case BT_DISCONN:
		l2cap_chan_del(chan, reason);
		break;

	default:
610
		lock_sock(sk);
611
		sock_set_flag(sk, SOCK_ZAPPED);
612
		release_sock(sk);
613 614 615 616
		break;
	}
}

617
static inline u8 l2cap_get_auth_type(struct l2cap_chan *chan)
618
{
619
	if (chan->chan_type == L2CAP_CHAN_RAW) {
620
		switch (chan->sec_level) {
621 622 623 624 625 626 627
		case BT_SECURITY_HIGH:
			return HCI_AT_DEDICATED_BONDING_MITM;
		case BT_SECURITY_MEDIUM:
			return HCI_AT_DEDICATED_BONDING;
		default:
			return HCI_AT_NO_BONDING;
		}
628
	} else if (chan->psm == cpu_to_le16(0x0001)) {
629 630
		if (chan->sec_level == BT_SECURITY_LOW)
			chan->sec_level = BT_SECURITY_SDP;
631

632
		if (chan->sec_level == BT_SECURITY_HIGH)
633
			return HCI_AT_NO_BONDING_MITM;
634
		else
635
			return HCI_AT_NO_BONDING;
636
	} else {
637
		switch (chan->sec_level) {
638
		case BT_SECURITY_HIGH:
639
			return HCI_AT_GENERAL_BONDING_MITM;
640
		case BT_SECURITY_MEDIUM:
641
			return HCI_AT_GENERAL_BONDING;
642
		default:
643
			return HCI_AT_NO_BONDING;
644
		}
645
	}
646 647 648
}

/* Service level security */
649
int l2cap_chan_check_security(struct l2cap_chan *chan)
650
{
651
	struct l2cap_conn *conn = chan->conn;
652 653
	__u8 auth_type;

654
	auth_type = l2cap_get_auth_type(chan);
655

656
	return hci_conn_security(conn->hcon, chan->sec_level, auth_type);
657 658
}

659
static u8 l2cap_get_ident(struct l2cap_conn *conn)
660 661 662 663 664 665 666 667 668
{
	u8 id;

	/* Get next available identificator.
	 *    1 - 128 are used by kernel.
	 *  129 - 199 are reserved.
	 *  200 - 254 are used by utilities like l2ping, etc.
	 */

669
	spin_lock(&conn->lock);
670 671 672 673 674 675

	if (++conn->tx_ident > 128)
		conn->tx_ident = 1;

	id = conn->tx_ident;

676
	spin_unlock(&conn->lock);
677 678 679 680

	return id;
}

681
static void l2cap_send_cmd(struct l2cap_conn *conn, u8 ident, u8 code, u16 len, void *data)
682 683
{
	struct sk_buff *skb = l2cap_build_cmd(conn, code, ident, len, data);
684
	u8 flags;
685 686 687 688

	BT_DBG("code 0x%2.2x", code);

	if (!skb)
689
		return;
690

691 692 693 694 695
	if (lmp_no_flush_capable(conn->hcon->hdev))
		flags = ACL_START_NO_FLUSH;
	else
		flags = ACL_START;

696
	bt_cb(skb)->force_active = BT_POWER_FORCE_ACTIVE_ON;
697
	skb->priority = HCI_PRIO_MAX;
698

699 700 701 702 703 704 705 706 707 708 709 710 711 712 713 714
	hci_send_acl(conn->hchan, skb, flags);
}

static void l2cap_do_send(struct l2cap_chan *chan, struct sk_buff *skb)
{
	struct hci_conn *hcon = chan->conn->hcon;
	u16 flags;

	BT_DBG("chan %p, skb %p len %d priority %u", chan, skb, skb->len,
							skb->priority);

	if (!test_bit(FLAG_FLUSHABLE, &chan->flags) &&
					lmp_no_flush_capable(hcon->hdev))
		flags = ACL_START_NO_FLUSH;
	else
		flags = ACL_START;
715

716 717
	bt_cb(skb)->force_active = test_bit(FLAG_FORCE_ACTIVE, &chan->flags);
	hci_send_acl(chan->conn->hchan, skb, flags);
718 719
}

720 721 722 723 724 725 726 727 728 729 730 731 732 733 734 735 736 737 738 739 740 741 742 743 744 745 746 747 748 749 750 751 752 753 754 755 756 757 758 759 760 761 762 763 764 765 766 767 768 769 770 771 772 773 774 775 776 777 778 779
static void __unpack_enhanced_control(u16 enh, struct l2cap_ctrl *control)
{
	control->reqseq = (enh & L2CAP_CTRL_REQSEQ) >> L2CAP_CTRL_REQSEQ_SHIFT;
	control->final = (enh & L2CAP_CTRL_FINAL) >> L2CAP_CTRL_FINAL_SHIFT;

	if (enh & L2CAP_CTRL_FRAME_TYPE) {
		/* S-Frame */
		control->sframe = 1;
		control->poll = (enh & L2CAP_CTRL_POLL) >> L2CAP_CTRL_POLL_SHIFT;
		control->super = (enh & L2CAP_CTRL_SUPERVISE) >> L2CAP_CTRL_SUPER_SHIFT;

		control->sar = 0;
		control->txseq = 0;
	} else {
		/* I-Frame */
		control->sframe = 0;
		control->sar = (enh & L2CAP_CTRL_SAR) >> L2CAP_CTRL_SAR_SHIFT;
		control->txseq = (enh & L2CAP_CTRL_TXSEQ) >> L2CAP_CTRL_TXSEQ_SHIFT;

		control->poll = 0;
		control->super = 0;
	}
}

static void __unpack_extended_control(u32 ext, struct l2cap_ctrl *control)
{
	control->reqseq = (ext & L2CAP_EXT_CTRL_REQSEQ) >> L2CAP_EXT_CTRL_REQSEQ_SHIFT;
	control->final = (ext & L2CAP_EXT_CTRL_FINAL) >> L2CAP_EXT_CTRL_FINAL_SHIFT;

	if (ext & L2CAP_EXT_CTRL_FRAME_TYPE) {
		/* S-Frame */
		control->sframe = 1;
		control->poll = (ext & L2CAP_EXT_CTRL_POLL) >> L2CAP_EXT_CTRL_POLL_SHIFT;
		control->super = (ext & L2CAP_EXT_CTRL_SUPERVISE) >> L2CAP_EXT_CTRL_SUPER_SHIFT;

		control->sar = 0;
		control->txseq = 0;
	} else {
		/* I-Frame */
		control->sframe = 0;
		control->sar = (ext & L2CAP_EXT_CTRL_SAR) >> L2CAP_EXT_CTRL_SAR_SHIFT;
		control->txseq = (ext & L2CAP_EXT_CTRL_TXSEQ) >> L2CAP_EXT_CTRL_TXSEQ_SHIFT;

		control->poll = 0;
		control->super = 0;
	}
}

static inline void __unpack_control(struct l2cap_chan *chan,
				    struct sk_buff *skb)
{
	if (test_bit(FLAG_EXT_CTRL, &chan->flags)) {
		__unpack_extended_control(get_unaligned_le32(skb->data),
					  &bt_cb(skb)->control);
	} else {
		__unpack_enhanced_control(get_unaligned_le16(skb->data),
					  &bt_cb(skb)->control);
	}
}

780 781 782 783 784 785 786 787 788 789 790 791 792 793 794 795 796 797 798 799 800 801 802 803 804 805 806 807 808 809 810 811 812 813 814 815 816 817
static u32 __pack_extended_control(struct l2cap_ctrl *control)
{
	u32 packed;

	packed = control->reqseq << L2CAP_EXT_CTRL_REQSEQ_SHIFT;
	packed |= control->final << L2CAP_EXT_CTRL_FINAL_SHIFT;

	if (control->sframe) {
		packed |= control->poll << L2CAP_EXT_CTRL_POLL_SHIFT;
		packed |= control->super << L2CAP_EXT_CTRL_SUPER_SHIFT;
		packed |= L2CAP_EXT_CTRL_FRAME_TYPE;
	} else {
		packed |= control->sar << L2CAP_EXT_CTRL_SAR_SHIFT;
		packed |= control->txseq << L2CAP_EXT_CTRL_TXSEQ_SHIFT;
	}

	return packed;
}

static u16 __pack_enhanced_control(struct l2cap_ctrl *control)
{
	u16 packed;

	packed = control->reqseq << L2CAP_CTRL_REQSEQ_SHIFT;
	packed |= control->final << L2CAP_CTRL_FINAL_SHIFT;

	if (control->sframe) {
		packed |= control->poll << L2CAP_CTRL_POLL_SHIFT;
		packed |= control->super << L2CAP_CTRL_SUPER_SHIFT;
		packed |= L2CAP_CTRL_FRAME_TYPE;
	} else {
		packed |= control->sar << L2CAP_CTRL_SAR_SHIFT;
		packed |= control->txseq << L2CAP_CTRL_TXSEQ_SHIFT;
	}

	return packed;
}

818 819 820 821 822 823 824 825 826 827 828 829 830
static inline void __pack_control(struct l2cap_chan *chan,
				  struct l2cap_ctrl *control,
				  struct sk_buff *skb)
{
	if (test_bit(FLAG_EXT_CTRL, &chan->flags)) {
		put_unaligned_le32(__pack_extended_control(control),
				   skb->data + L2CAP_HDR_SIZE);
	} else {
		put_unaligned_le16(__pack_enhanced_control(control),
				   skb->data + L2CAP_HDR_SIZE);
	}
}

831 832 833 834 835 836 837 838 839 840 841 842 843 844 845 846 847 848 849 850 851 852 853 854 855 856 857 858 859 860 861 862 863 864 865 866 867 868 869 870 871 872 873 874 875 876 877 878 879 880 881 882 883 884 885 886 887 888 889 890 891 892
static inline void l2cap_send_sframe(struct l2cap_chan *chan, u32 control)
{
	struct sk_buff *skb;
	struct l2cap_hdr *lh;
	struct l2cap_conn *conn = chan->conn;
	int count, hlen;

	if (chan->state != BT_CONNECTED)
		return;

	if (test_bit(FLAG_EXT_CTRL, &chan->flags))
		hlen = L2CAP_EXT_HDR_SIZE;
	else
		hlen = L2CAP_ENH_HDR_SIZE;

	if (chan->fcs == L2CAP_FCS_CRC16)
		hlen += L2CAP_FCS_SIZE;

	BT_DBG("chan %p, control 0x%8.8x", chan, control);

	count = min_t(unsigned int, conn->mtu, hlen);

	control |= __set_sframe(chan);

	if (test_and_clear_bit(CONN_SEND_FBIT, &chan->conn_state))
		control |= __set_ctrl_final(chan);

	if (test_and_clear_bit(CONN_SEND_PBIT, &chan->conn_state))
		control |= __set_ctrl_poll(chan);

	skb = bt_skb_alloc(count, GFP_ATOMIC);
	if (!skb)
		return;

	lh = (struct l2cap_hdr *) skb_put(skb, L2CAP_HDR_SIZE);
	lh->len = cpu_to_le16(hlen - L2CAP_HDR_SIZE);
	lh->cid = cpu_to_le16(chan->dcid);

	__put_control(chan, control, skb_put(skb, __ctrl_size(chan)));

	if (chan->fcs == L2CAP_FCS_CRC16) {
		u16 fcs = crc16(0, (u8 *)lh, count - L2CAP_FCS_SIZE);
		put_unaligned_le16(fcs, skb_put(skb, L2CAP_FCS_SIZE));
	}

	skb->priority = HCI_PRIO_MAX;
	l2cap_do_send(chan, skb);
}

static inline void l2cap_send_rr_or_rnr(struct l2cap_chan *chan, u32 control)
{
	if (test_bit(CONN_LOCAL_BUSY, &chan->conn_state)) {
		control |= __set_ctrl_super(chan, L2CAP_SUPER_RNR);
		set_bit(CONN_RNR_SENT, &chan->conn_state);
	} else
		control |= __set_ctrl_super(chan, L2CAP_SUPER_RR);

	control |= __set_reqseq(chan, chan->buffer_seq);

	l2cap_send_sframe(chan, control);
}

893
static inline int __l2cap_no_conn_pending(struct l2cap_chan *chan)
894
{
895
	return !test_bit(CONF_CONNECT_PEND, &chan->conf_state);
896 897
}

898 899 900 901 902 903 904 905 906 907 908 909 910 911 912
static void l2cap_send_conn_req(struct l2cap_chan *chan)
{
	struct l2cap_conn *conn = chan->conn;
	struct l2cap_conn_req req;

	req.scid = cpu_to_le16(chan->scid);
	req.psm  = chan->psm;

	chan->ident = l2cap_get_ident(conn);

	set_bit(CONF_CONNECT_PEND, &chan->conf_state);

	l2cap_send_cmd(conn, chan->ident, L2CAP_CONN_REQ, sizeof(req), &req);
}

913 914 915 916 917 918 919 920 921 922 923 924 925 926 927 928 929 930 931 932 933 934 935
static void l2cap_chan_ready(struct l2cap_chan *chan)
{
	struct sock *sk = chan->sk;
	struct sock *parent;

	lock_sock(sk);

	parent = bt_sk(sk)->parent;

	BT_DBG("sk %p, parent %p", sk, parent);

	chan->conf_state = 0;
	__clear_chan_timer(chan);

	__l2cap_state_change(chan, BT_CONNECTED);
	sk->sk_state_change(sk);

	if (parent)
		parent->sk_data_ready(parent, 0);

	release_sock(sk);
}

936
static void l2cap_do_start(struct l2cap_chan *chan)
937
{
938
	struct l2cap_conn *conn = chan->conn;
939

940 941 942 943 944
	if (conn->hcon->type == LE_LINK) {
		l2cap_chan_ready(chan);
		return;
	}

945
	if (conn->info_state & L2CAP_INFO_FEAT_MASK_REQ_SENT) {
946 947 948
		if (!(conn->info_state & L2CAP_INFO_FEAT_MASK_REQ_DONE))
			return;

949
		if (l2cap_chan_check_security(chan) &&
950 951
				__l2cap_no_conn_pending(chan))
			l2cap_send_conn_req(chan);
952 953 954 955 956 957 958
	} else {
		struct l2cap_info_req req;
		req.type = cpu_to_le16(L2CAP_IT_FEAT_MASK);

		conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_SENT;
		conn->info_ident = l2cap_get_ident(conn);

959
		schedule_delayed_work(&conn->info_timer, L2CAP_INFO_TIMEOUT);
960 961 962 963 964 965

		l2cap_send_cmd(conn, conn->info_ident,
					L2CAP_INFO_REQ, sizeof(req), &req);
	}
}

966 967 968
static inline int l2cap_mode_supported(__u8 mode, __u32 feat_mask)
{
	u32 local_feat_mask = l2cap_feat_mask;
969
	if (!disable_ertm)
970 971 972 973 974 975 976 977 978 979 980 981
		local_feat_mask |= L2CAP_FEAT_ERTM | L2CAP_FEAT_STREAMING;

	switch (mode) {
	case L2CAP_MODE_ERTM:
		return L2CAP_FEAT_ERTM & feat_mask & local_feat_mask;
	case L2CAP_MODE_STREAMING:
		return L2CAP_FEAT_STREAMING & feat_mask & local_feat_mask;
	default:
		return 0x00;
	}
}

982
static void l2cap_send_disconn_req(struct l2cap_conn *conn, struct l2cap_chan *chan, int err)
983
{
984
	struct sock *sk = chan->sk;
985 986
	struct l2cap_disconn_req req;

987 988 989
	if (!conn)
		return;

990
	if (chan->mode == L2CAP_MODE_ERTM) {
991 992 993
		__clear_retrans_timer(chan);
		__clear_monitor_timer(chan);
		__clear_ack_timer(chan);
994 995
	}

996 997
	req.dcid = cpu_to_le16(chan->dcid);
	req.scid = cpu_to_le16(chan->scid);
998 999
	l2cap_send_cmd(conn, l2cap_get_ident(conn),
			L2CAP_DISCONN_REQ, sizeof(req), &req);
1000

1001
	lock_sock(sk);
1002
	__l2cap_state_change(chan, BT_DISCONN);
1003
	__l2cap_chan_set_err(chan, err);
1004
	release_sock(sk);
1005 1006
}

L
Linus Torvalds 已提交
1007
/* ---- L2CAP connections ---- */
1008 1009
static void l2cap_conn_start(struct l2cap_conn *conn)
{
1010
	struct l2cap_chan *chan, *tmp;
1011 1012 1013

	BT_DBG("conn %p", conn);

1014
	mutex_lock(&conn->chan_lock);
1015

1016
	list_for_each_entry_safe(chan, tmp, &conn->chan_l, list) {
1017
		struct sock *sk = chan->sk;
1018

1019
		l2cap_chan_lock(chan);
1020

1021
		if (chan->chan_type != L2CAP_CHAN_CONN_ORIENTED) {
1022
			l2cap_chan_unlock(chan);
1023 1024 1025
			continue;
		}

1026
		if (chan->state == BT_CONNECT) {
1027
			if (!l2cap_chan_check_security(chan) ||
1028
					!__l2cap_no_conn_pending(chan)) {
1029
				l2cap_chan_unlock(chan);
1030 1031
				continue;
			}
1032

1033 1034 1035
			if (!l2cap_mode_supported(chan->mode, conn->feat_mask)
					&& test_bit(CONF_STATE2_DEVICE,
					&chan->conf_state)) {
1036
				l2cap_chan_close(chan, ECONNRESET);
1037
				l2cap_chan_unlock(chan);
1038
				continue;
1039
			}
1040

1041
			l2cap_send_conn_req(chan);
1042

1043
		} else if (chan->state == BT_CONNECT2) {
1044
			struct l2cap_conn_rsp rsp;
1045
			char buf[128];
1046 1047
			rsp.scid = cpu_to_le16(chan->dcid);
			rsp.dcid = cpu_to_le16(chan->scid);
1048

1049
			if (l2cap_chan_check_security(chan)) {
1050
				lock_sock(sk);
1051 1052 1053 1054
				if (bt_sk(sk)->defer_setup) {
					struct sock *parent = bt_sk(sk)->parent;
					rsp.result = cpu_to_le16(L2CAP_CR_PEND);
					rsp.status = cpu_to_le16(L2CAP_CS_AUTHOR_PEND);
1055 1056
					if (parent)
						parent->sk_data_ready(parent, 0);
1057 1058

				} else {
1059
					__l2cap_state_change(chan, BT_CONFIG);
1060 1061 1062
					rsp.result = cpu_to_le16(L2CAP_CR_SUCCESS);
					rsp.status = cpu_to_le16(L2CAP_CS_NO_INFO);
				}
1063
				release_sock(sk);
1064 1065 1066 1067 1068
			} else {
				rsp.result = cpu_to_le16(L2CAP_CR_PEND);
				rsp.status = cpu_to_le16(L2CAP_CS_AUTHEN_PEND);
			}

1069 1070
			l2cap_send_cmd(conn, chan->ident, L2CAP_CONN_RSP,
							sizeof(rsp), &rsp);
1071

1072
			if (test_bit(CONF_REQ_SENT, &chan->conf_state) ||
1073
					rsp.result != L2CAP_CR_SUCCESS) {
1074
				l2cap_chan_unlock(chan);
1075 1076 1077
				continue;
			}

1078
			set_bit(CONF_REQ_SENT, &chan->conf_state);
1079
			l2cap_send_cmd(conn, l2cap_get_ident(conn), L2CAP_CONF_REQ,
1080 1081
						l2cap_build_conf_req(chan, buf), buf);
			chan->num_conf_req++;
1082 1083
		}

1084
		l2cap_chan_unlock(chan);
1085 1086
	}

1087
	mutex_unlock(&conn->chan_lock);
1088 1089
}

1090
/* Find socket with cid and source/destination bdaddr.
1091 1092
 * Returns closest match, locked.
 */
1093
static struct l2cap_chan *l2cap_global_chan_by_scid(int state, u16 cid,
1094 1095
						    bdaddr_t *src,
						    bdaddr_t *dst)
1096
{
1097
	struct l2cap_chan *c, *c1 = NULL;
1098

1099
	read_lock(&chan_list_lock);
1100

1101 1102
	list_for_each_entry(c, &chan_list, global_l) {
		struct sock *sk = c->sk;
1103

1104
		if (state && c->state != state)
1105 1106
			continue;

1107
		if (c->scid == cid) {
1108 1109 1110
			int src_match, dst_match;
			int src_any, dst_any;

1111
			/* Exact match. */
1112 1113 1114
			src_match = !bacmp(&bt_sk(sk)->src, src);
			dst_match = !bacmp(&bt_sk(sk)->dst, dst);
			if (src_match && dst_match) {
1115 1116 1117
				read_unlock(&chan_list_lock);
				return c;
			}
1118 1119

			/* Closest match */
1120 1121 1122 1123
			src_any = !bacmp(&bt_sk(sk)->src, BDADDR_ANY);
			dst_any = !bacmp(&bt_sk(sk)->dst, BDADDR_ANY);
			if ((src_match && dst_any) || (src_any && dst_match) ||
			    (src_any && dst_any))
1124
				c1 = c;
1125 1126
		}
	}
1127

1128
	read_unlock(&chan_list_lock);
1129

1130
	return c1;
1131 1132 1133 1134
}

static void l2cap_le_conn_ready(struct l2cap_conn *conn)
{
1135
	struct sock *parent, *sk;
1136
	struct l2cap_chan *chan, *pchan;
1137 1138 1139 1140

	BT_DBG("");

	/* Check if we have socket listening on cid */
1141
	pchan = l2cap_global_chan_by_scid(BT_LISTEN, L2CAP_CID_LE_DATA,
1142
					  conn->src, conn->dst);
1143
	if (!pchan)
1144 1145
		return;

1146 1147
	parent = pchan->sk;

1148
	lock_sock(parent);
1149

1150 1151 1152 1153 1154 1155
	/* Check for backlog size */
	if (sk_acceptq_is_full(parent)) {
		BT_DBG("backlog full %d", parent->sk_ack_backlog);
		goto clean;
	}

1156 1157
	chan = pchan->ops->new_connection(pchan->data);
	if (!chan)
1158 1159
		goto clean;

1160
	sk = chan->sk;
1161

1162 1163 1164 1165 1166
	hci_conn_hold(conn->hcon);

	bacpy(&bt_sk(sk)->src, conn->src);
	bacpy(&bt_sk(sk)->dst, conn->dst);

1167 1168
	bt_accept_enqueue(parent, sk);

1169
	l2cap_chan_add(conn, chan);
1170

1171
	__set_chan_timer(chan, sk->sk_sndtimeo);
1172

1173
	__l2cap_state_change(chan, BT_CONNECTED);
1174 1175 1176
	parent->sk_data_ready(parent, 0);

clean:
1177
	release_sock(parent);
1178 1179
}

1180 1181
static void l2cap_conn_ready(struct l2cap_conn *conn)
{
1182
	struct l2cap_chan *chan;
1183

1184
	BT_DBG("conn %p", conn);
1185

1186 1187 1188
	if (!conn->hcon->out && conn->hcon->type == LE_LINK)
		l2cap_le_conn_ready(conn);

1189 1190 1191
	if (conn->hcon->out && conn->hcon->type == LE_LINK)
		smp_conn_security(conn, conn->hcon->pending_sec_level);

1192
	mutex_lock(&conn->chan_lock);
1193

1194
	list_for_each_entry(chan, &conn->chan_l, list) {
1195

1196
		l2cap_chan_lock(chan);
1197

1198
		if (conn->hcon->type == LE_LINK) {
1199
			if (smp_conn_security(conn, chan->sec_level))
1200
				l2cap_chan_ready(chan);
1201

1202
		} else if (chan->chan_type != L2CAP_CHAN_CONN_ORIENTED) {
1203
			struct sock *sk = chan->sk;
1204
			__clear_chan_timer(chan);
1205
			lock_sock(sk);
1206
			__l2cap_state_change(chan, BT_CONNECTED);
1207
			sk->sk_state_change(sk);
1208
			release_sock(sk);
1209

1210
		} else if (chan->state == BT_CONNECT)
1211
			l2cap_do_start(chan);
1212

1213
		l2cap_chan_unlock(chan);
1214
	}
1215

1216
	mutex_unlock(&conn->chan_lock);
1217 1218 1219 1220 1221
}

/* Notify sockets that we cannot guaranty reliability anymore */
static void l2cap_conn_unreliable(struct l2cap_conn *conn, int err)
{
1222
	struct l2cap_chan *chan;
1223 1224 1225

	BT_DBG("conn %p", conn);

1226
	mutex_lock(&conn->chan_lock);
1227

1228
	list_for_each_entry(chan, &conn->chan_l, list) {
1229
		if (test_bit(FLAG_FORCE_RELIABLE, &chan->flags))
1230
			__l2cap_chan_set_err(chan, err);
1231 1232
	}

1233
	mutex_unlock(&conn->chan_lock);
1234 1235
}

1236
static void l2cap_info_timeout(struct work_struct *work)
1237
{
1238
	struct l2cap_conn *conn = container_of(work, struct l2cap_conn,
1239
							info_timer.work);
1240

1241
	conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_DONE;
1242
	conn->info_ident = 0;
1243

1244 1245 1246
	l2cap_conn_start(conn);
}

1247 1248 1249 1250 1251 1252 1253 1254 1255 1256 1257 1258
static void l2cap_conn_del(struct hci_conn *hcon, int err)
{
	struct l2cap_conn *conn = hcon->l2cap_data;
	struct l2cap_chan *chan, *l;

	if (!conn)
		return;

	BT_DBG("hcon %p conn %p, err %d", hcon, conn, err);

	kfree_skb(conn->rx_skb);

1259 1260
	mutex_lock(&conn->chan_lock);

1261 1262
	/* Kill channels */
	list_for_each_entry_safe(chan, l, &conn->chan_l, list) {
1263
		l2cap_chan_hold(chan);
1264 1265
		l2cap_chan_lock(chan);

1266
		l2cap_chan_del(chan, err);
1267 1268 1269

		l2cap_chan_unlock(chan);

1270
		chan->ops->close(chan->data);
1271
		l2cap_chan_put(chan);
1272 1273
	}

1274 1275
	mutex_unlock(&conn->chan_lock);

1276 1277
	hci_chan_del(conn->hchan);

1278
	if (conn->info_state & L2CAP_INFO_FEAT_MASK_REQ_SENT)
1279
		cancel_delayed_work_sync(&conn->info_timer);
1280

1281
	if (test_and_clear_bit(HCI_CONN_LE_SMP_PEND, &hcon->flags)) {
1282
		cancel_delayed_work_sync(&conn->security_timer);
1283
		smp_chan_destroy(conn);
1284
	}
1285 1286 1287 1288 1289

	hcon->l2cap_data = NULL;
	kfree(conn);
}

1290
static void security_timeout(struct work_struct *work)
1291
{
1292 1293
	struct l2cap_conn *conn = container_of(work, struct l2cap_conn,
						security_timer.work);
1294 1295 1296 1297

	l2cap_conn_del(conn->hcon, ETIMEDOUT);
}

L
Linus Torvalds 已提交
1298 1299
static struct l2cap_conn *l2cap_conn_add(struct hci_conn *hcon, u8 status)
{
1300
	struct l2cap_conn *conn = hcon->l2cap_data;
1301
	struct hci_chan *hchan;
L
Linus Torvalds 已提交
1302

1303
	if (conn || status)
L
Linus Torvalds 已提交
1304 1305
		return conn;

1306 1307 1308 1309
	hchan = hci_chan_create(hcon);
	if (!hchan)
		return NULL;

1310
	conn = kzalloc(sizeof(struct l2cap_conn), GFP_ATOMIC);
1311 1312
	if (!conn) {
		hci_chan_del(hchan);
L
Linus Torvalds 已提交
1313
		return NULL;
1314
	}
L
Linus Torvalds 已提交
1315 1316 1317

	hcon->l2cap_data = conn;
	conn->hcon = hcon;
1318
	conn->hchan = hchan;
L
Linus Torvalds 已提交
1319

1320
	BT_DBG("hcon %p conn %p hchan %p", hcon, conn, hchan);
1321

1322 1323 1324 1325 1326
	if (hcon->hdev->le_mtu && hcon->type == LE_LINK)
		conn->mtu = hcon->hdev->le_mtu;
	else
		conn->mtu = hcon->hdev->acl_mtu;

L
Linus Torvalds 已提交
1327 1328 1329
	conn->src = &hcon->hdev->bdaddr;
	conn->dst = &hcon->dst;

1330 1331
	conn->feat_mask = 0;

L
Linus Torvalds 已提交
1332
	spin_lock_init(&conn->lock);
1333
	mutex_init(&conn->chan_lock);
1334 1335

	INIT_LIST_HEAD(&conn->chan_l);
L
Linus Torvalds 已提交
1336

1337
	if (hcon->type == LE_LINK)
1338
		INIT_DELAYED_WORK(&conn->security_timer, security_timeout);
1339
	else
1340
		INIT_DELAYED_WORK(&conn->info_timer, l2cap_info_timeout);
D
Dave Young 已提交
1341

1342
	conn->disc_reason = HCI_ERROR_REMOTE_USER_TERM;
1343

L
Linus Torvalds 已提交
1344 1345 1346 1347 1348
	return conn;
}

/* ---- Socket interface ---- */

1349
/* Find socket with psm and source / destination bdaddr.
L
Linus Torvalds 已提交
1350 1351
 * Returns closest match.
 */
1352 1353 1354
static struct l2cap_chan *l2cap_global_chan_by_psm(int state, __le16 psm,
						   bdaddr_t *src,
						   bdaddr_t *dst)
L
Linus Torvalds 已提交
1355
{
1356
	struct l2cap_chan *c, *c1 = NULL;
L
Linus Torvalds 已提交
1357

1358
	read_lock(&chan_list_lock);
1359

1360 1361
	list_for_each_entry(c, &chan_list, global_l) {
		struct sock *sk = c->sk;
1362

1363
		if (state && c->state != state)
L
Linus Torvalds 已提交
1364 1365
			continue;

1366
		if (c->psm == psm) {
1367 1368 1369
			int src_match, dst_match;
			int src_any, dst_any;

L
Linus Torvalds 已提交
1370
			/* Exact match. */
1371 1372 1373
			src_match = !bacmp(&bt_sk(sk)->src, src);
			dst_match = !bacmp(&bt_sk(sk)->dst, dst);
			if (src_match && dst_match) {
1374
				read_unlock(&chan_list_lock);
1375 1376
				return c;
			}
L
Linus Torvalds 已提交
1377 1378

			/* Closest match */
1379 1380 1381 1382
			src_any = !bacmp(&bt_sk(sk)->src, BDADDR_ANY);
			dst_any = !bacmp(&bt_sk(sk)->dst, BDADDR_ANY);
			if ((src_match && dst_any) || (src_any && dst_match) ||
			    (src_any && dst_any))
1383
				c1 = c;
L
Linus Torvalds 已提交
1384 1385 1386
		}
	}

1387
	read_unlock(&chan_list_lock);
1388

1389
	return c1;
L
Linus Torvalds 已提交
1390 1391
}

1392 1393
int l2cap_chan_connect(struct l2cap_chan *chan, __le16 psm, u16 cid,
		       bdaddr_t *dst, u8 dst_type)
L
Linus Torvalds 已提交
1394
{
1395
	struct sock *sk = chan->sk;
L
Linus Torvalds 已提交
1396 1397 1398 1399
	bdaddr_t *src = &bt_sk(sk)->src;
	struct l2cap_conn *conn;
	struct hci_conn *hcon;
	struct hci_dev *hdev;
1400
	__u8 auth_type;
1401
	int err;
L
Linus Torvalds 已提交
1402

1403 1404
	BT_DBG("%s -> %s (type %u) psm 0x%2.2x", batostr(src), batostr(dst),
	       dst_type, __le16_to_cpu(chan->psm));
L
Linus Torvalds 已提交
1405

1406 1407
	hdev = hci_get_route(dst, src);
	if (!hdev)
L
Linus Torvalds 已提交
1408 1409
		return -EHOSTUNREACH;

1410
	hci_dev_lock(hdev);
L
Linus Torvalds 已提交
1411

1412
	l2cap_chan_lock(chan);
1413 1414 1415 1416 1417 1418 1419 1420 1421 1422 1423 1424 1425 1426 1427 1428 1429 1430 1431 1432 1433 1434 1435 1436 1437 1438

	/* PSM must be odd and lsb of upper byte must be 0 */
	if ((__le16_to_cpu(psm) & 0x0101) != 0x0001 && !cid &&
					chan->chan_type != L2CAP_CHAN_RAW) {
		err = -EINVAL;
		goto done;
	}

	if (chan->chan_type == L2CAP_CHAN_CONN_ORIENTED && !(psm || cid)) {
		err = -EINVAL;
		goto done;
	}

	switch (chan->mode) {
	case L2CAP_MODE_BASIC:
		break;
	case L2CAP_MODE_ERTM:
	case L2CAP_MODE_STREAMING:
		if (!disable_ertm)
			break;
		/* fall through */
	default:
		err = -ENOTSUPP;
		goto done;
	}

1439 1440
	lock_sock(sk);

1441 1442 1443 1444 1445 1446
	switch (sk->sk_state) {
	case BT_CONNECT:
	case BT_CONNECT2:
	case BT_CONFIG:
		/* Already connecting */
		err = 0;
1447
		release_sock(sk);
1448 1449 1450 1451 1452
		goto done;

	case BT_CONNECTED:
		/* Already connected */
		err = -EISCONN;
1453
		release_sock(sk);
1454 1455 1456 1457 1458 1459 1460 1461 1462
		goto done;

	case BT_OPEN:
	case BT_BOUND:
		/* Can connect */
		break;

	default:
		err = -EBADFD;
1463
		release_sock(sk);
1464 1465 1466 1467
		goto done;
	}

	/* Set destination address and psm */
1468
	bacpy(&bt_sk(sk)->dst, dst);
1469 1470 1471

	release_sock(sk);

1472 1473
	chan->psm = psm;
	chan->dcid = cid;
L
Linus Torvalds 已提交
1474

1475
	auth_type = l2cap_get_auth_type(chan);
1476

1477
	if (chan->dcid == L2CAP_CID_LE_DATA)
1478
		hcon = hci_connect(hdev, LE_LINK, dst, dst_type,
1479
				   chan->sec_level, auth_type);
1480
	else
1481
		hcon = hci_connect(hdev, ACL_LINK, dst, dst_type,
1482
				   chan->sec_level, auth_type);
1483

1484 1485
	if (IS_ERR(hcon)) {
		err = PTR_ERR(hcon);
L
Linus Torvalds 已提交
1486
		goto done;
1487
	}
L
Linus Torvalds 已提交
1488 1489 1490 1491

	conn = l2cap_conn_add(hcon, 0);
	if (!conn) {
		hci_conn_put(hcon);
1492
		err = -ENOMEM;
L
Linus Torvalds 已提交
1493 1494 1495
		goto done;
	}

1496 1497 1498 1499 1500 1501 1502 1503 1504 1505 1506 1507
	if (hcon->type == LE_LINK) {
		err = 0;

		if (!list_empty(&conn->chan_l)) {
			err = -EBUSY;
			hci_conn_put(hcon);
		}

		if (err)
			goto done;
	}

L
Linus Torvalds 已提交
1508 1509 1510
	/* Update source addr of the socket */
	bacpy(src, conn->src);

1511
	l2cap_chan_unlock(chan);
1512
	l2cap_chan_add(conn, chan);
1513
	l2cap_chan_lock(chan);
1514

1515
	l2cap_state_change(chan, BT_CONNECT);
1516
	__set_chan_timer(chan, sk->sk_sndtimeo);
L
Linus Torvalds 已提交
1517 1518

	if (hcon->state == BT_CONNECTED) {
1519
		if (chan->chan_type != L2CAP_CHAN_CONN_ORIENTED) {
1520
			__clear_chan_timer(chan);
1521
			if (l2cap_chan_check_security(chan))
1522
				l2cap_state_change(chan, BT_CONNECTED);
1523
		} else
1524
			l2cap_do_start(chan);
L
Linus Torvalds 已提交
1525 1526
	}

1527 1528
	err = 0;

L
Linus Torvalds 已提交
1529
done:
1530
	l2cap_chan_unlock(chan);
1531
	hci_dev_unlock(hdev);
L
Linus Torvalds 已提交
1532 1533 1534 1535
	hci_dev_put(hdev);
	return err;
}

1536
int __l2cap_wait_ack(struct sock *sk)
1537
{
1538
	struct l2cap_chan *chan = l2cap_pi(sk)->chan;
1539 1540 1541 1542
	DECLARE_WAITQUEUE(wait, current);
	int err = 0;
	int timeo = HZ/5;

1543
	add_wait_queue(sk_sleep(sk), &wait);
1544 1545
	set_current_state(TASK_INTERRUPTIBLE);
	while (chan->unacked_frames > 0 && chan->conn) {
1546 1547 1548 1549 1550 1551 1552 1553 1554 1555 1556
		if (!timeo)
			timeo = HZ/5;

		if (signal_pending(current)) {
			err = sock_intr_errno(timeo);
			break;
		}

		release_sock(sk);
		timeo = schedule_timeout(timeo);
		lock_sock(sk);
1557
		set_current_state(TASK_INTERRUPTIBLE);
1558 1559 1560 1561 1562 1563

		err = sock_error(sk);
		if (err)
			break;
	}
	set_current_state(TASK_RUNNING);
1564
	remove_wait_queue(sk_sleep(sk), &wait);
1565 1566 1567
	return err;
}

1568
static void l2cap_monitor_timeout(struct work_struct *work)
1569
{
1570 1571
	struct l2cap_chan *chan = container_of(work, struct l2cap_chan,
							monitor_timer.work);
1572

1573
	BT_DBG("chan %p", chan);
1574

1575 1576
	l2cap_chan_lock(chan);

1577
	if (chan->retry_count >= chan->remote_max_tx) {
1578
		l2cap_send_disconn_req(chan->conn, chan, ECONNABORTED);
1579
		l2cap_chan_unlock(chan);
1580
		l2cap_chan_put(chan);
1581 1582 1583
		return;
	}

1584
	chan->retry_count++;
1585
	__set_monitor_timer(chan);
1586

1587
	l2cap_send_rr_or_rnr(chan, L2CAP_CTRL_POLL);
1588
	l2cap_chan_unlock(chan);
1589
	l2cap_chan_put(chan);
1590 1591
}

1592
static void l2cap_retrans_timeout(struct work_struct *work)
1593
{
1594 1595
	struct l2cap_chan *chan = container_of(work, struct l2cap_chan,
							retrans_timer.work);
1596

1597
	BT_DBG("chan %p", chan);
1598

1599 1600
	l2cap_chan_lock(chan);

1601
	chan->retry_count = 1;
1602
	__set_monitor_timer(chan);
1603

1604
	set_bit(CONN_WAIT_F, &chan->conn_state);
1605

1606
	l2cap_send_rr_or_rnr(chan, L2CAP_CTRL_POLL);
1607 1608

	l2cap_chan_unlock(chan);
1609
	l2cap_chan_put(chan);
1610 1611
}

1612
static void l2cap_drop_acked_frames(struct l2cap_chan *chan)
L
Linus Torvalds 已提交
1613
{
1614
	struct sk_buff *skb;
L
Linus Torvalds 已提交
1615

1616
	while ((skb = skb_peek(&chan->tx_q)) &&
1617
			chan->unacked_frames) {
1618
		if (bt_cb(skb)->control.txseq == chan->expected_ack_seq)
1619
			break;
L
Linus Torvalds 已提交
1620

1621
		skb = skb_dequeue(&chan->tx_q);
1622
		kfree_skb(skb);
L
Linus Torvalds 已提交
1623

1624
		chan->unacked_frames--;
1625
	}
L
Linus Torvalds 已提交
1626

1627
	if (!chan->unacked_frames)
1628
		__clear_retrans_timer(chan);
1629
}
L
Linus Torvalds 已提交
1630

1631
static void l2cap_streaming_send(struct l2cap_chan *chan)
1632
{
1633
	struct sk_buff *skb;
1634 1635
	u32 control;
	u16 fcs;
1636

1637
	while ((skb = skb_dequeue(&chan->tx_q))) {
1638
		control = __get_control(chan, skb->data + L2CAP_HDR_SIZE);
1639
		control |= __set_txseq(chan, chan->next_tx_seq);
1640
		control |= __set_ctrl_sar(chan, bt_cb(skb)->control.sar);
1641
		__put_control(chan, control, skb->data + L2CAP_HDR_SIZE);
1642

1643
		if (chan->fcs == L2CAP_FCS_CRC16) {
1644 1645 1646 1647
			fcs = crc16(0, (u8 *)skb->data,
						skb->len - L2CAP_FCS_SIZE);
			put_unaligned_le16(fcs,
					skb->data + skb->len - L2CAP_FCS_SIZE);
1648 1649
		}

1650
		l2cap_do_send(chan, skb);
1651

1652
		chan->next_tx_seq = __next_seq(chan, chan->next_tx_seq);
1653 1654 1655
	}
}

1656
static void l2cap_retransmit_one_frame(struct l2cap_chan *chan, u16 tx_seq)
1657 1658
{
	struct sk_buff *skb, *tx_skb;
1659 1660
	u16 fcs;
	u32 control;
1661

1662
	skb = skb_peek(&chan->tx_q);
1663 1664
	if (!skb)
		return;
1665

1666
	while (bt_cb(skb)->control.txseq != tx_seq) {
1667
		if (skb_queue_is_last(&chan->tx_q, skb))
1668
			return;
1669

1670 1671
		skb = skb_queue_next(&chan->tx_q, skb);
	}
1672

1673 1674
	if (bt_cb(skb)->control.retries == chan->remote_max_tx &&
	    chan->remote_max_tx) {
1675
		l2cap_send_disconn_req(chan->conn, chan, ECONNABORTED);
1676 1677 1678 1679
		return;
	}

	tx_skb = skb_clone(skb, GFP_ATOMIC);
1680
	bt_cb(skb)->control.retries++;
1681 1682

	control = __get_control(chan, tx_skb->data + L2CAP_HDR_SIZE);
1683
	control &= __get_sar_mask(chan);
1684

1685
	if (test_and_clear_bit(CONN_SEND_FBIT, &chan->conn_state))
1686
		control |= __set_ctrl_final(chan);
1687

1688
	control |= __set_reqseq(chan, chan->buffer_seq);
1689
	control |= __set_txseq(chan, tx_seq);
1690

1691
	__put_control(chan, control, tx_skb->data + L2CAP_HDR_SIZE);
1692

1693
	if (chan->fcs == L2CAP_FCS_CRC16) {
1694 1695 1696 1697
		fcs = crc16(0, (u8 *)tx_skb->data,
						tx_skb->len - L2CAP_FCS_SIZE);
		put_unaligned_le16(fcs,
				tx_skb->data + tx_skb->len - L2CAP_FCS_SIZE);
1698 1699
	}

1700
	l2cap_do_send(chan, tx_skb);
1701 1702
}

1703
static int l2cap_ertm_send(struct l2cap_chan *chan)
1704 1705
{
	struct sk_buff *skb, *tx_skb;
1706 1707
	u16 fcs;
	u32 control;
1708
	int nsent = 0;
1709

1710
	if (chan->state != BT_CONNECTED)
1711
		return -ENOTCONN;
1712

1713 1714 1715
	if (test_bit(CONN_REMOTE_BUSY, &chan->conn_state))
		return 0;

1716
	while ((skb = chan->tx_send_head) && (!l2cap_tx_window_full(chan))) {
1717

1718 1719
		if (bt_cb(skb)->control.retries == chan->remote_max_tx &&
		    chan->remote_max_tx) {
1720
			l2cap_send_disconn_req(chan->conn, chan, ECONNABORTED);
1721 1722 1723
			break;
		}

1724 1725
		tx_skb = skb_clone(skb, GFP_ATOMIC);

1726
		bt_cb(skb)->control.retries++;
1727

1728
		control = __get_control(chan, tx_skb->data + L2CAP_HDR_SIZE);
1729
		control &= __get_sar_mask(chan);
1730

1731
		if (test_and_clear_bit(CONN_SEND_FBIT, &chan->conn_state))
1732
			control |= __set_ctrl_final(chan);
1733

1734
		control |= __set_reqseq(chan, chan->buffer_seq);
1735
		control |= __set_txseq(chan, chan->next_tx_seq);
1736
		control |= __set_ctrl_sar(chan, bt_cb(skb)->control.sar);
1737

1738
		__put_control(chan, control, tx_skb->data + L2CAP_HDR_SIZE);
1739

1740
		if (chan->fcs == L2CAP_FCS_CRC16) {
1741 1742 1743 1744
			fcs = crc16(0, (u8 *)skb->data,
						tx_skb->len - L2CAP_FCS_SIZE);
			put_unaligned_le16(fcs, skb->data +
						tx_skb->len - L2CAP_FCS_SIZE);
1745 1746
		}

1747
		l2cap_do_send(chan, tx_skb);
1748

1749
		__set_retrans_timer(chan);
1750

1751
		bt_cb(skb)->control.txseq = chan->next_tx_seq;
1752 1753

		chan->next_tx_seq = __next_seq(chan, chan->next_tx_seq);
1754

1755
		if (bt_cb(skb)->control.retries == 1) {
1756
			chan->unacked_frames++;
1757 1758 1759

			if (!nsent++)
				__clear_ack_timer(chan);
1760
		}
1761

1762
		chan->frames_sent++;
1763

1764 1765
		if (skb_queue_is_last(&chan->tx_q, skb))
			chan->tx_send_head = NULL;
1766
		else
1767
			chan->tx_send_head = skb_queue_next(&chan->tx_q, skb);
1768 1769
	}

1770 1771 1772
	return nsent;
}

1773
static int l2cap_retransmit_frames(struct l2cap_chan *chan)
1774 1775 1776
{
	int ret;

1777 1778
	if (!skb_queue_empty(&chan->tx_q))
		chan->tx_send_head = chan->tx_q.next;
1779

1780
	chan->next_tx_seq = chan->expected_ack_seq;
1781
	ret = l2cap_ertm_send(chan);
1782 1783 1784
	return ret;
}

1785
static void __l2cap_send_ack(struct l2cap_chan *chan)
1786
{
1787
	u32 control = 0;
1788

1789
	control |= __set_reqseq(chan, chan->buffer_seq);
1790

1791
	if (test_bit(CONN_LOCAL_BUSY, &chan->conn_state)) {
1792
		control |= __set_ctrl_super(chan, L2CAP_SUPER_RNR);
1793
		set_bit(CONN_RNR_SENT, &chan->conn_state);
1794
		l2cap_send_sframe(chan, control);
1795
		return;
1796
	}
1797

1798
	if (l2cap_ertm_send(chan) > 0)
1799 1800
		return;

1801
	control |= __set_ctrl_super(chan, L2CAP_SUPER_RR);
1802
	l2cap_send_sframe(chan, control);
1803 1804
}

1805 1806 1807 1808 1809 1810
static void l2cap_send_ack(struct l2cap_chan *chan)
{
	__clear_ack_timer(chan);
	__l2cap_send_ack(chan);
}

1811
static void l2cap_send_srejtail(struct l2cap_chan *chan)
1812 1813
{
	struct srej_list *tail;
1814
	u32 control;
1815

1816
	control = __set_ctrl_super(chan, L2CAP_SUPER_SREJ);
1817
	control |= __set_ctrl_final(chan);
1818

1819
	tail = list_entry((&chan->srej_l)->prev, struct srej_list, list);
1820
	control |= __set_reqseq(chan, tail->tx_seq);
1821

1822
	l2cap_send_sframe(chan, control);
1823 1824
}

1825 1826 1827
static inline int l2cap_skbuff_fromiovec(struct l2cap_chan *chan,
					 struct msghdr *msg, int len,
					 int count, struct sk_buff *skb)
1828
{
1829
	struct l2cap_conn *conn = chan->conn;
1830
	struct sk_buff **frag;
1831
	int sent = 0;
L
Linus Torvalds 已提交
1832

1833
	if (memcpy_fromiovec(skb_put(skb, count), msg->msg_iov, count))
1834
		return -EFAULT;
L
Linus Torvalds 已提交
1835 1836 1837 1838 1839 1840 1841

	sent += count;
	len  -= count;

	/* Continuation fragments (no L2CAP header) */
	frag = &skb_shinfo(skb)->frag_list;
	while (len) {
1842 1843
		struct sk_buff *tmp;

L
Linus Torvalds 已提交
1844 1845
		count = min_t(unsigned int, conn->mtu, len);

1846 1847 1848 1849 1850 1851
		tmp = chan->ops->alloc_skb(chan, count,
					   msg->msg_flags & MSG_DONTWAIT);
		if (IS_ERR(tmp))
			return PTR_ERR(tmp);

		*frag = tmp;
1852

1853 1854
		if (memcpy_fromiovec(skb_put(*frag, count), msg->msg_iov, count))
			return -EFAULT;
L
Linus Torvalds 已提交
1855

1856 1857
		(*frag)->priority = skb->priority;

L
Linus Torvalds 已提交
1858 1859 1860
		sent += count;
		len  -= count;

1861 1862 1863
		skb->len += (*frag)->len;
		skb->data_len += (*frag)->len;

L
Linus Torvalds 已提交
1864 1865 1866 1867
		frag = &(*frag)->next;
	}

	return sent;
1868
}
L
Linus Torvalds 已提交
1869

1870 1871 1872
static struct sk_buff *l2cap_create_connless_pdu(struct l2cap_chan *chan,
						struct msghdr *msg, size_t len,
						u32 priority)
1873
{
1874
	struct l2cap_conn *conn = chan->conn;
1875
	struct sk_buff *skb;
1876
	int err, count, hlen = L2CAP_HDR_SIZE + L2CAP_PSMLEN_SIZE;
1877 1878
	struct l2cap_hdr *lh;

1879
	BT_DBG("chan %p len %d priority %u", chan, (int)len, priority);
1880 1881

	count = min_t(unsigned int, (conn->mtu - hlen), len);
1882 1883

	skb = chan->ops->alloc_skb(chan, count + hlen,
1884 1885 1886
				   msg->msg_flags & MSG_DONTWAIT);
	if (IS_ERR(skb))
		return skb;
1887

1888 1889
	skb->priority = priority;

1890 1891
	/* Create L2CAP header */
	lh = (struct l2cap_hdr *) skb_put(skb, L2CAP_HDR_SIZE);
1892
	lh->cid = cpu_to_le16(chan->dcid);
1893 1894
	lh->len = cpu_to_le16(len + L2CAP_PSMLEN_SIZE);
	put_unaligned(chan->psm, skb_put(skb, L2CAP_PSMLEN_SIZE));
1895

1896
	err = l2cap_skbuff_fromiovec(chan, msg, len, count, skb);
1897 1898 1899 1900 1901 1902 1903
	if (unlikely(err < 0)) {
		kfree_skb(skb);
		return ERR_PTR(err);
	}
	return skb;
}

1904 1905 1906
static struct sk_buff *l2cap_create_basic_pdu(struct l2cap_chan *chan,
						struct msghdr *msg, size_t len,
						u32 priority)
1907
{
1908
	struct l2cap_conn *conn = chan->conn;
1909
	struct sk_buff *skb;
1910
	int err, count;
1911 1912
	struct l2cap_hdr *lh;

1913
	BT_DBG("chan %p len %d", chan, (int)len);
1914

1915
	count = min_t(unsigned int, (conn->mtu - L2CAP_HDR_SIZE), len);
1916

1917
	skb = chan->ops->alloc_skb(chan, count + L2CAP_HDR_SIZE,
1918 1919 1920
				   msg->msg_flags & MSG_DONTWAIT);
	if (IS_ERR(skb))
		return skb;
1921

1922 1923
	skb->priority = priority;

1924 1925
	/* Create L2CAP header */
	lh = (struct l2cap_hdr *) skb_put(skb, L2CAP_HDR_SIZE);
1926
	lh->cid = cpu_to_le16(chan->dcid);
1927
	lh->len = cpu_to_le16(len);
1928

1929
	err = l2cap_skbuff_fromiovec(chan, msg, len, count, skb);
1930 1931 1932 1933 1934 1935 1936
	if (unlikely(err < 0)) {
		kfree_skb(skb);
		return ERR_PTR(err);
	}
	return skb;
}

1937 1938
static struct sk_buff *l2cap_create_iframe_pdu(struct l2cap_chan *chan,
						struct msghdr *msg, size_t len,
1939
						u16 sdulen)
1940
{
1941
	struct l2cap_conn *conn = chan->conn;
1942
	struct sk_buff *skb;
1943
	int err, count, hlen;
1944 1945
	struct l2cap_hdr *lh;

1946
	BT_DBG("chan %p len %d", chan, (int)len);
1947

1948 1949 1950
	if (!conn)
		return ERR_PTR(-ENOTCONN);

1951 1952 1953 1954 1955
	if (test_bit(FLAG_EXT_CTRL, &chan->flags))
		hlen = L2CAP_EXT_HDR_SIZE;
	else
		hlen = L2CAP_ENH_HDR_SIZE;

1956
	if (sdulen)
1957
		hlen += L2CAP_SDULEN_SIZE;
1958

1959
	if (chan->fcs == L2CAP_FCS_CRC16)
1960
		hlen += L2CAP_FCS_SIZE;
1961

1962
	count = min_t(unsigned int, (conn->mtu - hlen), len);
1963 1964

	skb = chan->ops->alloc_skb(chan, count + hlen,
1965 1966 1967
				   msg->msg_flags & MSG_DONTWAIT);
	if (IS_ERR(skb))
		return skb;
1968 1969 1970

	/* Create L2CAP header */
	lh = (struct l2cap_hdr *) skb_put(skb, L2CAP_HDR_SIZE);
1971
	lh->cid = cpu_to_le16(chan->dcid);
1972
	lh->len = cpu_to_le16(len + (hlen - L2CAP_HDR_SIZE));
1973

1974
	__put_control(chan, 0, skb_put(skb, __ctrl_size(chan)));
1975

1976
	if (sdulen)
1977
		put_unaligned_le16(sdulen, skb_put(skb, L2CAP_SDULEN_SIZE));
1978

1979
	err = l2cap_skbuff_fromiovec(chan, msg, len, count, skb);
1980 1981 1982 1983
	if (unlikely(err < 0)) {
		kfree_skb(skb);
		return ERR_PTR(err);
	}
1984

1985
	if (chan->fcs == L2CAP_FCS_CRC16)
1986
		put_unaligned_le16(0, skb_put(skb, L2CAP_FCS_SIZE));
1987

1988
	bt_cb(skb)->control.retries = 0;
1989
	return skb;
L
Linus Torvalds 已提交
1990 1991
}

1992 1993 1994
static int l2cap_segment_sdu(struct l2cap_chan *chan,
			     struct sk_buff_head *seg_queue,
			     struct msghdr *msg, size_t len)
1995 1996
{
	struct sk_buff *skb;
1997 1998 1999 2000
	u16 sdu_len;
	size_t pdu_len;
	int err = 0;
	u8 sar;
2001

2002
	BT_DBG("chan %p, msg %p, len %d", chan, msg, (int)len);
2003

2004 2005 2006 2007
	/* It is critical that ERTM PDUs fit in a single HCI fragment,
	 * so fragmented skbs are not used.  The HCI layer's handling
	 * of fragmented skbs is not compatible with ERTM's queueing.
	 */
2008

2009 2010
	/* PDU size is derived from the HCI MTU */
	pdu_len = chan->conn->mtu;
2011

2012 2013 2014 2015 2016 2017 2018 2019 2020 2021 2022 2023 2024 2025 2026 2027 2028 2029 2030 2031
	pdu_len = min_t(size_t, pdu_len, L2CAP_BREDR_MAX_PAYLOAD);

	/* Adjust for largest possible L2CAP overhead. */
	pdu_len -= L2CAP_EXT_HDR_SIZE + L2CAP_FCS_SIZE;

	/* Remote device may have requested smaller PDUs */
	pdu_len = min_t(size_t, pdu_len, chan->remote_mps);

	if (len <= pdu_len) {
		sar = L2CAP_SAR_UNSEGMENTED;
		sdu_len = 0;
		pdu_len = len;
	} else {
		sar = L2CAP_SAR_START;
		sdu_len = len;
		pdu_len -= L2CAP_SDULEN_SIZE;
	}

	while (len > 0) {
		skb = l2cap_create_iframe_pdu(chan, msg, pdu_len, sdu_len);
2032 2033

		if (IS_ERR(skb)) {
2034
			__skb_queue_purge(seg_queue);
2035 2036 2037
			return PTR_ERR(skb);
		}

2038 2039 2040 2041 2042 2043 2044 2045 2046 2047 2048 2049 2050 2051 2052
		bt_cb(skb)->control.sar = sar;
		__skb_queue_tail(seg_queue, skb);

		len -= pdu_len;
		if (sdu_len) {
			sdu_len = 0;
			pdu_len += L2CAP_SDULEN_SIZE;
		}

		if (len <= pdu_len) {
			sar = L2CAP_SAR_END;
			pdu_len = len;
		} else {
			sar = L2CAP_SAR_CONTINUE;
		}
2053 2054
	}

2055
	return err;
2056 2057
}

2058 2059
int l2cap_chan_send(struct l2cap_chan *chan, struct msghdr *msg, size_t len,
								u32 priority)
2060 2061 2062
{
	struct sk_buff *skb;
	int err;
2063
	struct sk_buff_head seg_queue;
2064 2065

	/* Connectionless channel */
2066
	if (chan->chan_type == L2CAP_CHAN_CONN_LESS) {
2067
		skb = l2cap_create_connless_pdu(chan, msg, len, priority);
2068 2069 2070 2071 2072 2073 2074 2075 2076 2077 2078 2079 2080 2081
		if (IS_ERR(skb))
			return PTR_ERR(skb);

		l2cap_do_send(chan, skb);
		return len;
	}

	switch (chan->mode) {
	case L2CAP_MODE_BASIC:
		/* Check outgoing MTU */
		if (len > chan->omtu)
			return -EMSGSIZE;

		/* Create a basic PDU */
2082
		skb = l2cap_create_basic_pdu(chan, msg, len, priority);
2083 2084 2085 2086 2087 2088 2089 2090 2091
		if (IS_ERR(skb))
			return PTR_ERR(skb);

		l2cap_do_send(chan, skb);
		err = len;
		break;

	case L2CAP_MODE_ERTM:
	case L2CAP_MODE_STREAMING:
2092 2093 2094 2095 2096
		/* Check outgoing MTU */
		if (len > chan->omtu) {
			err = -EMSGSIZE;
			break;
		}
2097

2098
		__skb_queue_head_init(&seg_queue);
2099

2100 2101 2102 2103 2104
		/* Do segmentation before calling in to the state machine,
		 * since it's possible to block while waiting for memory
		 * allocation.
		 */
		err = l2cap_segment_sdu(chan, &seg_queue, msg, len);
2105

2106 2107 2108 2109 2110 2111
		/* The channel could have been closed while segmenting,
		 * check that it is still connected.
		 */
		if (chan->state != BT_CONNECTED) {
			__skb_queue_purge(&seg_queue);
			err = -ENOTCONN;
2112 2113
		}

2114
		if (err)
2115 2116
			break;

2117 2118
		if (chan->mode == L2CAP_MODE_ERTM && chan->tx_send_head == NULL)
			chan->tx_send_head = seg_queue.next;
2119
		skb_queue_splice_tail_init(&seg_queue, &chan->tx_q);
2120

2121 2122 2123 2124
		if (chan->mode == L2CAP_MODE_ERTM)
			err = l2cap_ertm_send(chan);
		else
			l2cap_streaming_send(chan);
2125 2126 2127 2128

		if (err >= 0)
			err = len;

2129 2130 2131 2132
		/* If the skbs were not queued for sending, they'll still be in
		 * seg_queue and need to be purged.
		 */
		__skb_queue_purge(&seg_queue);
2133 2134 2135 2136 2137 2138 2139 2140 2141 2142
		break;

	default:
		BT_DBG("bad state %1.1x", chan->mode);
		err = -EBADFD;
	}

	return err;
}

L
Linus Torvalds 已提交
2143 2144 2145 2146
/* Copy frame to all raw sockets on that connection */
static void l2cap_raw_recv(struct l2cap_conn *conn, struct sk_buff *skb)
{
	struct sk_buff *nskb;
2147
	struct l2cap_chan *chan;
L
Linus Torvalds 已提交
2148 2149 2150

	BT_DBG("conn %p", conn);

2151
	mutex_lock(&conn->chan_lock);
2152

2153
	list_for_each_entry(chan, &conn->chan_l, list) {
2154
		struct sock *sk = chan->sk;
2155
		if (chan->chan_type != L2CAP_CHAN_RAW)
L
Linus Torvalds 已提交
2156 2157 2158 2159 2160
			continue;

		/* Don't send frame to the socket it came from */
		if (skb->sk == sk)
			continue;
2161 2162
		nskb = skb_clone(skb, GFP_ATOMIC);
		if (!nskb)
L
Linus Torvalds 已提交
2163 2164
			continue;

2165
		if (chan->ops->recv(chan->data, nskb))
L
Linus Torvalds 已提交
2166 2167
			kfree_skb(nskb);
	}
2168

2169
	mutex_unlock(&conn->chan_lock);
L
Linus Torvalds 已提交
2170 2171 2172 2173 2174 2175 2176 2177 2178 2179 2180
}

/* ---- L2CAP signalling commands ---- */
static struct sk_buff *l2cap_build_cmd(struct l2cap_conn *conn,
				u8 code, u8 ident, u16 dlen, void *data)
{
	struct sk_buff *skb, **frag;
	struct l2cap_cmd_hdr *cmd;
	struct l2cap_hdr *lh;
	int len, count;

2181 2182
	BT_DBG("conn %p, code 0x%2.2x, ident 0x%2.2x, len %d",
			conn, code, ident, dlen);
L
Linus Torvalds 已提交
2183 2184 2185 2186 2187 2188 2189 2190 2191

	len = L2CAP_HDR_SIZE + L2CAP_CMD_HDR_SIZE + dlen;
	count = min_t(unsigned int, conn->mtu, len);

	skb = bt_skb_alloc(count, GFP_ATOMIC);
	if (!skb)
		return NULL;

	lh = (struct l2cap_hdr *) skb_put(skb, L2CAP_HDR_SIZE);
2192
	lh->len = cpu_to_le16(L2CAP_CMD_HDR_SIZE + dlen);
2193 2194 2195 2196 2197

	if (conn->hcon->type == LE_LINK)
		lh->cid = cpu_to_le16(L2CAP_CID_LE_SIGNALING);
	else
		lh->cid = cpu_to_le16(L2CAP_CID_SIGNALING);
L
Linus Torvalds 已提交
2198 2199 2200 2201

	cmd = (struct l2cap_cmd_hdr *) skb_put(skb, L2CAP_CMD_HDR_SIZE);
	cmd->code  = code;
	cmd->ident = ident;
2202
	cmd->len   = cpu_to_le16(dlen);
L
Linus Torvalds 已提交
2203 2204 2205 2206 2207 2208 2209 2210 2211 2212 2213 2214 2215 2216 2217 2218 2219 2220 2221 2222 2223 2224 2225 2226 2227 2228 2229 2230 2231 2232 2233 2234 2235 2236 2237 2238 2239 2240 2241 2242 2243 2244 2245 2246 2247 2248 2249 2250 2251 2252

	if (dlen) {
		count -= L2CAP_HDR_SIZE + L2CAP_CMD_HDR_SIZE;
		memcpy(skb_put(skb, count), data, count);
		data += count;
	}

	len -= skb->len;

	/* Continuation fragments (no L2CAP header) */
	frag = &skb_shinfo(skb)->frag_list;
	while (len) {
		count = min_t(unsigned int, conn->mtu, len);

		*frag = bt_skb_alloc(count, GFP_ATOMIC);
		if (!*frag)
			goto fail;

		memcpy(skb_put(*frag, count), data, count);

		len  -= count;
		data += count;

		frag = &(*frag)->next;
	}

	return skb;

fail:
	kfree_skb(skb);
	return NULL;
}

static inline int l2cap_get_conf_opt(void **ptr, int *type, int *olen, unsigned long *val)
{
	struct l2cap_conf_opt *opt = *ptr;
	int len;

	len = L2CAP_CONF_OPT_SIZE + opt->len;
	*ptr += len;

	*type = opt->type;
	*olen = opt->len;

	switch (opt->len) {
	case 1:
		*val = *((u8 *) opt->val);
		break;

	case 2:
2253
		*val = get_unaligned_le16(opt->val);
L
Linus Torvalds 已提交
2254 2255 2256
		break;

	case 4:
2257
		*val = get_unaligned_le32(opt->val);
L
Linus Torvalds 已提交
2258 2259 2260 2261 2262 2263 2264 2265 2266 2267 2268 2269 2270 2271 2272 2273 2274 2275 2276 2277 2278 2279 2280 2281 2282 2283
		break;

	default:
		*val = (unsigned long) opt->val;
		break;
	}

	BT_DBG("type 0x%2.2x len %d val 0x%lx", *type, opt->len, *val);
	return len;
}

static void l2cap_add_conf_opt(void **ptr, u8 type, u8 len, unsigned long val)
{
	struct l2cap_conf_opt *opt = *ptr;

	BT_DBG("type 0x%2.2x len %d val 0x%lx", type, len, val);

	opt->type = type;
	opt->len  = len;

	switch (len) {
	case 1:
		*((u8 *) opt->val)  = val;
		break;

	case 2:
2284
		put_unaligned_le16(val, opt->val);
L
Linus Torvalds 已提交
2285 2286 2287
		break;

	case 4:
2288
		put_unaligned_le32(val, opt->val);
L
Linus Torvalds 已提交
2289 2290 2291 2292 2293 2294 2295 2296 2297 2298
		break;

	default:
		memcpy(opt->val, (void *) val, len);
		break;
	}

	*ptr += L2CAP_CONF_OPT_SIZE + len;
}

2299 2300 2301 2302
static void l2cap_add_opt_efs(void **ptr, struct l2cap_chan *chan)
{
	struct l2cap_conf_efs efs;

2303
	switch (chan->mode) {
2304 2305 2306 2307 2308 2309 2310 2311 2312 2313 2314 2315 2316 2317 2318 2319 2320 2321 2322 2323 2324 2325 2326 2327 2328 2329
	case L2CAP_MODE_ERTM:
		efs.id		= chan->local_id;
		efs.stype	= chan->local_stype;
		efs.msdu	= cpu_to_le16(chan->local_msdu);
		efs.sdu_itime	= cpu_to_le32(chan->local_sdu_itime);
		efs.acc_lat	= cpu_to_le32(L2CAP_DEFAULT_ACC_LAT);
		efs.flush_to	= cpu_to_le32(L2CAP_DEFAULT_FLUSH_TO);
		break;

	case L2CAP_MODE_STREAMING:
		efs.id		= 1;
		efs.stype	= L2CAP_SERV_BESTEFFORT;
		efs.msdu	= cpu_to_le16(chan->local_msdu);
		efs.sdu_itime	= cpu_to_le32(chan->local_sdu_itime);
		efs.acc_lat	= 0;
		efs.flush_to	= 0;
		break;

	default:
		return;
	}

	l2cap_add_conf_opt(ptr, L2CAP_CONF_EFS, sizeof(efs),
							(unsigned long) &efs);
}

2330
static void l2cap_ack_timeout(struct work_struct *work)
2331
{
2332 2333
	struct l2cap_chan *chan = container_of(work, struct l2cap_chan,
							ack_timer.work);
2334

2335 2336
	BT_DBG("chan %p", chan);

2337 2338
	l2cap_chan_lock(chan);

2339
	__l2cap_send_ack(chan);
2340 2341

	l2cap_chan_unlock(chan);
2342 2343

	l2cap_chan_put(chan);
2344 2345
}

2346
static inline int l2cap_ertm_init(struct l2cap_chan *chan)
2347
{
2348 2349
	int err;

2350 2351
	chan->next_tx_seq = 0;
	chan->expected_tx_seq = 0;
2352
	chan->expected_ack_seq = 0;
2353
	chan->unacked_frames = 0;
2354
	chan->buffer_seq = 0;
2355 2356
	chan->num_acked = 0;
	chan->frames_sent = 0;
2357 2358 2359 2360 2361
	chan->last_acked_seq = 0;
	chan->sdu = NULL;
	chan->sdu_last_frag = NULL;
	chan->sdu_len = 0;

2362 2363
	skb_queue_head_init(&chan->tx_q);

2364 2365 2366 2367 2368
	if (chan->mode != L2CAP_MODE_ERTM)
		return 0;

	chan->rx_state = L2CAP_RX_STATE_RECV;
	chan->tx_state = L2CAP_TX_STATE_XMIT;
2369

2370 2371 2372
	INIT_DELAYED_WORK(&chan->retrans_timer, l2cap_retrans_timeout);
	INIT_DELAYED_WORK(&chan->monitor_timer, l2cap_monitor_timeout);
	INIT_DELAYED_WORK(&chan->ack_timer, l2cap_ack_timeout);
2373

2374
	skb_queue_head_init(&chan->srej_q);
2375

2376
	INIT_LIST_HEAD(&chan->srej_l);
2377 2378 2379 2380 2381
	err = l2cap_seq_list_init(&chan->srej_list, chan->tx_win);
	if (err < 0)
		return err;

	return l2cap_seq_list_init(&chan->retrans_list, chan->remote_tx_win);
2382 2383
}

2384 2385 2386 2387 2388 2389 2390 2391 2392 2393 2394 2395 2396
static inline __u8 l2cap_select_mode(__u8 mode, __u16 remote_feat_mask)
{
	switch (mode) {
	case L2CAP_MODE_STREAMING:
	case L2CAP_MODE_ERTM:
		if (l2cap_mode_supported(mode, remote_feat_mask))
			return mode;
		/* fall through */
	default:
		return L2CAP_MODE_BASIC;
	}
}

2397 2398 2399 2400 2401
static inline bool __l2cap_ews_supported(struct l2cap_chan *chan)
{
	return enable_hs && chan->conn->feat_mask & L2CAP_FEAT_EXT_WINDOW;
}

2402 2403 2404 2405 2406
static inline bool __l2cap_efs_supported(struct l2cap_chan *chan)
{
	return enable_hs && chan->conn->feat_mask & L2CAP_FEAT_EXT_FLOW;
}

2407 2408 2409
static inline void l2cap_txwin_setup(struct l2cap_chan *chan)
{
	if (chan->tx_win > L2CAP_DEFAULT_TX_WINDOW &&
2410
						__l2cap_ews_supported(chan)) {
2411 2412
		/* use extended control field */
		set_bit(FLAG_EXT_CTRL, &chan->flags);
2413 2414
		chan->tx_win_max = L2CAP_DEFAULT_EXT_WINDOW;
	} else {
2415 2416
		chan->tx_win = min_t(u16, chan->tx_win,
						L2CAP_DEFAULT_TX_WINDOW);
2417 2418
		chan->tx_win_max = L2CAP_DEFAULT_TX_WINDOW;
	}
2419 2420
}

2421
static int l2cap_build_conf_req(struct l2cap_chan *chan, void *data)
L
Linus Torvalds 已提交
2422 2423
{
	struct l2cap_conf_req *req = data;
2424
	struct l2cap_conf_rfc rfc = { .mode = chan->mode };
L
Linus Torvalds 已提交
2425
	void *ptr = req->data;
2426
	u16 size;
L
Linus Torvalds 已提交
2427

2428
	BT_DBG("chan %p", chan);
L
Linus Torvalds 已提交
2429

2430
	if (chan->num_conf_req || chan->num_conf_rsp)
2431 2432
		goto done;

2433
	switch (chan->mode) {
2434 2435
	case L2CAP_MODE_STREAMING:
	case L2CAP_MODE_ERTM:
2436
		if (test_bit(CONF_STATE2_DEVICE, &chan->conf_state))
2437 2438
			break;

2439 2440 2441
		if (__l2cap_efs_supported(chan))
			set_bit(FLAG_EFS_ENABLE, &chan->flags);

2442
		/* fall through */
2443
	default:
2444
		chan->mode = l2cap_select_mode(rfc.mode, chan->conn->feat_mask);
2445 2446 2447 2448
		break;
	}

done:
2449 2450
	if (chan->imtu != L2CAP_DEFAULT_MTU)
		l2cap_add_conf_opt(&ptr, L2CAP_CONF_MTU, 2, chan->imtu);
2451

2452
	switch (chan->mode) {
2453
	case L2CAP_MODE_BASIC:
2454 2455
		if (!(chan->conn->feat_mask & L2CAP_FEAT_ERTM) &&
				!(chan->conn->feat_mask & L2CAP_FEAT_STREAMING))
2456 2457
			break;

2458 2459 2460 2461 2462 2463 2464
		rfc.mode            = L2CAP_MODE_BASIC;
		rfc.txwin_size      = 0;
		rfc.max_transmit    = 0;
		rfc.retrans_timeout = 0;
		rfc.monitor_timeout = 0;
		rfc.max_pdu_size    = 0;

2465 2466
		l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC, sizeof(rfc),
							(unsigned long) &rfc);
2467 2468 2469 2470
		break;

	case L2CAP_MODE_ERTM:
		rfc.mode            = L2CAP_MODE_ERTM;
2471
		rfc.max_transmit    = chan->max_tx;
2472 2473
		rfc.retrans_timeout = 0;
		rfc.monitor_timeout = 0;
2474 2475 2476 2477 2478 2479

		size = min_t(u16, L2CAP_DEFAULT_MAX_PDU_SIZE, chan->conn->mtu -
						L2CAP_EXT_HDR_SIZE -
						L2CAP_SDULEN_SIZE -
						L2CAP_FCS_SIZE);
		rfc.max_pdu_size = cpu_to_le16(size);
2480

2481 2482 2483 2484
		l2cap_txwin_setup(chan);

		rfc.txwin_size = min_t(u16, chan->tx_win,
						L2CAP_DEFAULT_TX_WINDOW);
2485

2486 2487 2488
		l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC, sizeof(rfc),
							(unsigned long) &rfc);

2489 2490 2491
		if (test_bit(FLAG_EFS_ENABLE, &chan->flags))
			l2cap_add_opt_efs(&ptr, chan);

2492
		if (!(chan->conn->feat_mask & L2CAP_FEAT_FCS))
2493 2494
			break;

2495
		if (chan->fcs == L2CAP_FCS_NONE ||
2496
				test_bit(CONF_NO_FCS_RECV, &chan->conf_state)) {
2497 2498
			chan->fcs = L2CAP_FCS_NONE;
			l2cap_add_conf_opt(&ptr, L2CAP_CONF_FCS, 1, chan->fcs);
2499
		}
2500 2501 2502 2503

		if (test_bit(FLAG_EXT_CTRL, &chan->flags))
			l2cap_add_conf_opt(&ptr, L2CAP_CONF_EWS, 2,
								chan->tx_win);
2504 2505 2506 2507 2508 2509 2510 2511
		break;

	case L2CAP_MODE_STREAMING:
		rfc.mode            = L2CAP_MODE_STREAMING;
		rfc.txwin_size      = 0;
		rfc.max_transmit    = 0;
		rfc.retrans_timeout = 0;
		rfc.monitor_timeout = 0;
2512 2513 2514 2515 2516 2517

		size = min_t(u16, L2CAP_DEFAULT_MAX_PDU_SIZE, chan->conn->mtu -
						L2CAP_EXT_HDR_SIZE -
						L2CAP_SDULEN_SIZE -
						L2CAP_FCS_SIZE);
		rfc.max_pdu_size = cpu_to_le16(size);
2518

2519 2520 2521
		l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC, sizeof(rfc),
							(unsigned long) &rfc);

2522 2523 2524
		if (test_bit(FLAG_EFS_ENABLE, &chan->flags))
			l2cap_add_opt_efs(&ptr, chan);

2525
		if (!(chan->conn->feat_mask & L2CAP_FEAT_FCS))
2526 2527
			break;

2528
		if (chan->fcs == L2CAP_FCS_NONE ||
2529
				test_bit(CONF_NO_FCS_RECV, &chan->conf_state)) {
2530 2531
			chan->fcs = L2CAP_FCS_NONE;
			l2cap_add_conf_opt(&ptr, L2CAP_CONF_FCS, 1, chan->fcs);
2532
		}
2533 2534
		break;
	}
L
Linus Torvalds 已提交
2535

2536
	req->dcid  = cpu_to_le16(chan->dcid);
2537
	req->flags = cpu_to_le16(0);
L
Linus Torvalds 已提交
2538 2539 2540 2541

	return ptr - data;
}

2542
static int l2cap_parse_conf_req(struct l2cap_chan *chan, void *data)
L
Linus Torvalds 已提交
2543
{
2544 2545
	struct l2cap_conf_rsp *rsp = data;
	void *ptr = rsp->data;
2546 2547
	void *req = chan->conf_req;
	int len = chan->conf_len;
2548 2549
	int type, hint, olen;
	unsigned long val;
2550
	struct l2cap_conf_rfc rfc = { .mode = L2CAP_MODE_BASIC };
2551 2552
	struct l2cap_conf_efs efs;
	u8 remote_efs = 0;
2553
	u16 mtu = L2CAP_DEFAULT_MTU;
2554
	u16 result = L2CAP_CONF_SUCCESS;
2555
	u16 size;
L
Linus Torvalds 已提交
2556

2557
	BT_DBG("chan %p", chan);
2558

2559 2560
	while (len >= L2CAP_CONF_OPT_SIZE) {
		len -= l2cap_get_conf_opt(&req, &type, &olen, &val);
L
Linus Torvalds 已提交
2561

2562
		hint  = type & L2CAP_CONF_HINT;
2563
		type &= L2CAP_CONF_MASK;
2564 2565 2566

		switch (type) {
		case L2CAP_CONF_MTU:
2567
			mtu = val;
2568 2569 2570
			break;

		case L2CAP_CONF_FLUSH_TO:
2571
			chan->flush_to = val;
2572 2573 2574 2575 2576
			break;

		case L2CAP_CONF_QOS:
			break;

2577 2578 2579 2580 2581
		case L2CAP_CONF_RFC:
			if (olen == sizeof(rfc))
				memcpy(&rfc, (void *) val, olen);
			break;

2582 2583
		case L2CAP_CONF_FCS:
			if (val == L2CAP_FCS_NONE)
2584
				set_bit(CONF_NO_FCS_RECV, &chan->conf_state);
2585
			break;
2586

2587 2588 2589 2590
		case L2CAP_CONF_EFS:
			remote_efs = 1;
			if (olen == sizeof(efs))
				memcpy(&efs, (void *) val, olen);
2591 2592
			break;

2593 2594 2595
		case L2CAP_CONF_EWS:
			if (!enable_hs)
				return -ECONNREFUSED;
2596

2597 2598
			set_bit(FLAG_EXT_CTRL, &chan->flags);
			set_bit(CONF_EWS_RECV, &chan->conf_state);
2599
			chan->tx_win_max = L2CAP_DEFAULT_EXT_WINDOW;
2600
			chan->remote_tx_win = val;
2601 2602
			break;

2603 2604 2605 2606 2607 2608 2609 2610 2611 2612
		default:
			if (hint)
				break;

			result = L2CAP_CONF_UNKNOWN;
			*((u8 *) ptr++) = type;
			break;
		}
	}

2613
	if (chan->num_conf_rsp || chan->num_conf_req > 1)
2614 2615
		goto done;

2616
	switch (chan->mode) {
2617 2618
	case L2CAP_MODE_STREAMING:
	case L2CAP_MODE_ERTM:
2619
		if (!test_bit(CONF_STATE2_DEVICE, &chan->conf_state)) {
2620
			chan->mode = l2cap_select_mode(rfc.mode,
2621
					chan->conn->feat_mask);
2622 2623 2624
			break;
		}

2625 2626 2627 2628 2629 2630 2631
		if (remote_efs) {
			if (__l2cap_efs_supported(chan))
				set_bit(FLAG_EFS_ENABLE, &chan->flags);
			else
				return -ECONNREFUSED;
		}

2632
		if (chan->mode != rfc.mode)
2633
			return -ECONNREFUSED;
2634

2635 2636 2637 2638
		break;
	}

done:
2639
	if (chan->mode != rfc.mode) {
2640
		result = L2CAP_CONF_UNACCEPT;
2641
		rfc.mode = chan->mode;
2642

2643
		if (chan->num_conf_rsp == 1)
2644 2645 2646 2647 2648 2649
			return -ECONNREFUSED;

		l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC,
					sizeof(rfc), (unsigned long) &rfc);
	}

2650 2651 2652 2653
	if (result == L2CAP_CONF_SUCCESS) {
		/* Configure output options and let the other side know
		 * which ones we don't like. */

2654 2655 2656
		if (mtu < L2CAP_DEFAULT_MIN_MTU)
			result = L2CAP_CONF_UNACCEPT;
		else {
2657
			chan->omtu = mtu;
2658
			set_bit(CONF_MTU_DONE, &chan->conf_state);
2659
		}
2660
		l2cap_add_conf_opt(&ptr, L2CAP_CONF_MTU, 2, chan->omtu);
2661

2662 2663 2664 2665 2666 2667 2668 2669 2670 2671 2672
		if (remote_efs) {
			if (chan->local_stype != L2CAP_SERV_NOTRAFIC &&
					efs.stype != L2CAP_SERV_NOTRAFIC &&
					efs.stype != chan->local_stype) {

				result = L2CAP_CONF_UNACCEPT;

				if (chan->num_conf_req >= 1)
					return -ECONNREFUSED;

				l2cap_add_conf_opt(&ptr, L2CAP_CONF_EFS,
2673
							sizeof(efs),
2674
							(unsigned long) &efs);
2675
			} else {
2676
				/* Send PENDING Conf Rsp */
2677 2678
				result = L2CAP_CONF_PENDING;
				set_bit(CONF_LOC_CONF_PEND, &chan->conf_state);
2679 2680 2681
			}
		}

2682 2683
		switch (rfc.mode) {
		case L2CAP_MODE_BASIC:
2684
			chan->fcs = L2CAP_FCS_NONE;
2685
			set_bit(CONF_MODE_DONE, &chan->conf_state);
2686 2687 2688
			break;

		case L2CAP_MODE_ERTM:
2689 2690 2691 2692
			if (!test_bit(CONF_EWS_RECV, &chan->conf_state))
				chan->remote_tx_win = rfc.txwin_size;
			else
				rfc.txwin_size = L2CAP_DEFAULT_TX_WINDOW;
2693

2694
			chan->remote_max_tx = rfc.max_transmit;
2695

2696 2697 2698 2699 2700 2701 2702
			size = min_t(u16, le16_to_cpu(rfc.max_pdu_size),
						chan->conn->mtu -
						L2CAP_EXT_HDR_SIZE -
						L2CAP_SDULEN_SIZE -
						L2CAP_FCS_SIZE);
			rfc.max_pdu_size = cpu_to_le16(size);
			chan->remote_mps = size;
2703

2704
			rfc.retrans_timeout =
2705
				__constant_cpu_to_le16(L2CAP_DEFAULT_RETRANS_TO);
2706
			rfc.monitor_timeout =
2707
				__constant_cpu_to_le16(L2CAP_DEFAULT_MONITOR_TO);
2708

2709
			set_bit(CONF_MODE_DONE, &chan->conf_state);
2710 2711 2712 2713

			l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC,
					sizeof(rfc), (unsigned long) &rfc);

2714 2715 2716 2717 2718 2719 2720 2721 2722 2723 2724 2725 2726
			if (test_bit(FLAG_EFS_ENABLE, &chan->flags)) {
				chan->remote_id = efs.id;
				chan->remote_stype = efs.stype;
				chan->remote_msdu = le16_to_cpu(efs.msdu);
				chan->remote_flush_to =
						le32_to_cpu(efs.flush_to);
				chan->remote_acc_lat =
						le32_to_cpu(efs.acc_lat);
				chan->remote_sdu_itime =
					le32_to_cpu(efs.sdu_itime);
				l2cap_add_conf_opt(&ptr, L2CAP_CONF_EFS,
					sizeof(efs), (unsigned long) &efs);
			}
2727 2728 2729
			break;

		case L2CAP_MODE_STREAMING:
2730 2731 2732 2733 2734 2735 2736
			size = min_t(u16, le16_to_cpu(rfc.max_pdu_size),
						chan->conn->mtu -
						L2CAP_EXT_HDR_SIZE -
						L2CAP_SDULEN_SIZE -
						L2CAP_FCS_SIZE);
			rfc.max_pdu_size = cpu_to_le16(size);
			chan->remote_mps = size;
2737

2738
			set_bit(CONF_MODE_DONE, &chan->conf_state);
2739 2740 2741 2742

			l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC,
					sizeof(rfc), (unsigned long) &rfc);

2743 2744 2745
			break;

		default:
2746 2747
			result = L2CAP_CONF_UNACCEPT;

2748
			memset(&rfc, 0, sizeof(rfc));
2749
			rfc.mode = chan->mode;
2750
		}
2751

2752
		if (result == L2CAP_CONF_SUCCESS)
2753
			set_bit(CONF_OUTPUT_DONE, &chan->conf_state);
2754
	}
2755
	rsp->scid   = cpu_to_le16(chan->dcid);
2756 2757 2758 2759
	rsp->result = cpu_to_le16(result);
	rsp->flags  = cpu_to_le16(0x0000);

	return ptr - data;
L
Linus Torvalds 已提交
2760 2761
}

2762
static int l2cap_parse_conf_rsp(struct l2cap_chan *chan, void *rsp, int len, void *data, u16 *result)
2763 2764 2765 2766 2767
{
	struct l2cap_conf_req *req = data;
	void *ptr = req->data;
	int type, olen;
	unsigned long val;
2768
	struct l2cap_conf_rfc rfc = { .mode = L2CAP_MODE_BASIC };
2769
	struct l2cap_conf_efs efs;
2770

2771
	BT_DBG("chan %p, rsp %p, len %d, req %p", chan, rsp, len, data);
2772 2773 2774 2775 2776 2777 2778 2779

	while (len >= L2CAP_CONF_OPT_SIZE) {
		len -= l2cap_get_conf_opt(&rsp, &type, &olen, &val);

		switch (type) {
		case L2CAP_CONF_MTU:
			if (val < L2CAP_DEFAULT_MIN_MTU) {
				*result = L2CAP_CONF_UNACCEPT;
2780
				chan->imtu = L2CAP_DEFAULT_MIN_MTU;
2781
			} else
2782 2783
				chan->imtu = val;
			l2cap_add_conf_opt(&ptr, L2CAP_CONF_MTU, 2, chan->imtu);
2784 2785 2786
			break;

		case L2CAP_CONF_FLUSH_TO:
2787
			chan->flush_to = val;
2788
			l2cap_add_conf_opt(&ptr, L2CAP_CONF_FLUSH_TO,
2789
							2, chan->flush_to);
2790 2791 2792 2793 2794 2795
			break;

		case L2CAP_CONF_RFC:
			if (olen == sizeof(rfc))
				memcpy(&rfc, (void *)val, olen);

2796
			if (test_bit(CONF_STATE2_DEVICE, &chan->conf_state) &&
2797
							rfc.mode != chan->mode)
2798 2799
				return -ECONNREFUSED;

2800
			chan->fcs = 0;
2801 2802 2803 2804

			l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC,
					sizeof(rfc), (unsigned long) &rfc);
			break;
2805 2806 2807 2808

		case L2CAP_CONF_EWS:
			chan->tx_win = min_t(u16, val,
						L2CAP_DEFAULT_EXT_WINDOW);
2809 2810
			l2cap_add_conf_opt(&ptr, L2CAP_CONF_EWS, 2,
							chan->tx_win);
2811
			break;
2812 2813 2814 2815 2816 2817 2818 2819 2820 2821 2822 2823 2824

		case L2CAP_CONF_EFS:
			if (olen == sizeof(efs))
				memcpy(&efs, (void *)val, olen);

			if (chan->local_stype != L2CAP_SERV_NOTRAFIC &&
					efs.stype != L2CAP_SERV_NOTRAFIC &&
					efs.stype != chan->local_stype)
				return -ECONNREFUSED;

			l2cap_add_conf_opt(&ptr, L2CAP_CONF_EFS,
					sizeof(efs), (unsigned long) &efs);
			break;
2825 2826 2827
		}
	}

2828
	if (chan->mode == L2CAP_MODE_BASIC && chan->mode != rfc.mode)
2829 2830
		return -ECONNREFUSED;

2831
	chan->mode = rfc.mode;
2832

2833
	if (*result == L2CAP_CONF_SUCCESS || *result == L2CAP_CONF_PENDING) {
2834 2835
		switch (rfc.mode) {
		case L2CAP_MODE_ERTM:
2836 2837 2838
			chan->retrans_timeout = le16_to_cpu(rfc.retrans_timeout);
			chan->monitor_timeout = le16_to_cpu(rfc.monitor_timeout);
			chan->mps    = le16_to_cpu(rfc.max_pdu_size);
2839 2840 2841 2842 2843 2844 2845 2846 2847

			if (test_bit(FLAG_EFS_ENABLE, &chan->flags)) {
				chan->local_msdu = le16_to_cpu(efs.msdu);
				chan->local_sdu_itime =
						le32_to_cpu(efs.sdu_itime);
				chan->local_acc_lat = le32_to_cpu(efs.acc_lat);
				chan->local_flush_to =
						le32_to_cpu(efs.flush_to);
			}
2848
			break;
2849

2850
		case L2CAP_MODE_STREAMING:
2851
			chan->mps    = le16_to_cpu(rfc.max_pdu_size);
2852 2853 2854
		}
	}

2855
	req->dcid   = cpu_to_le16(chan->dcid);
2856 2857 2858 2859 2860
	req->flags  = cpu_to_le16(0x0000);

	return ptr - data;
}

2861
static int l2cap_build_conf_rsp(struct l2cap_chan *chan, void *data, u16 result, u16 flags)
L
Linus Torvalds 已提交
2862 2863 2864 2865
{
	struct l2cap_conf_rsp *rsp = data;
	void *ptr = rsp->data;

2866
	BT_DBG("chan %p", chan);
L
Linus Torvalds 已提交
2867

2868
	rsp->scid   = cpu_to_le16(chan->dcid);
2869
	rsp->result = cpu_to_le16(result);
2870
	rsp->flags  = cpu_to_le16(flags);
L
Linus Torvalds 已提交
2871 2872 2873 2874

	return ptr - data;
}

2875
void __l2cap_connect_rsp_defer(struct l2cap_chan *chan)
2876 2877
{
	struct l2cap_conn_rsp rsp;
2878
	struct l2cap_conn *conn = chan->conn;
2879 2880
	u8 buf[128];

2881 2882
	rsp.scid   = cpu_to_le16(chan->dcid);
	rsp.dcid   = cpu_to_le16(chan->scid);
2883 2884 2885 2886 2887
	rsp.result = cpu_to_le16(L2CAP_CR_SUCCESS);
	rsp.status = cpu_to_le16(L2CAP_CS_NO_INFO);
	l2cap_send_cmd(conn, chan->ident,
				L2CAP_CONN_RSP, sizeof(rsp), &rsp);

2888
	if (test_and_set_bit(CONF_REQ_SENT, &chan->conf_state))
2889 2890 2891 2892 2893 2894 2895
		return;

	l2cap_send_cmd(conn, l2cap_get_ident(conn), L2CAP_CONF_REQ,
			l2cap_build_conf_req(chan, buf), buf);
	chan->num_conf_req++;
}

2896
static void l2cap_conf_rfc_get(struct l2cap_chan *chan, void *rsp, int len)
2897 2898 2899 2900 2901
{
	int type, olen;
	unsigned long val;
	struct l2cap_conf_rfc rfc;

2902
	BT_DBG("chan %p, rsp %p, len %d", chan, rsp, len);
2903

2904
	if ((chan->mode != L2CAP_MODE_ERTM) && (chan->mode != L2CAP_MODE_STREAMING))
2905 2906 2907 2908 2909 2910 2911 2912 2913 2914 2915 2916 2917
		return;

	while (len >= L2CAP_CONF_OPT_SIZE) {
		len -= l2cap_get_conf_opt(&rsp, &type, &olen, &val);

		switch (type) {
		case L2CAP_CONF_RFC:
			if (olen == sizeof(rfc))
				memcpy(&rfc, (void *)val, olen);
			goto done;
		}
	}

2918 2919 2920 2921 2922 2923 2924 2925 2926 2927
	/* Use sane default values in case a misbehaving remote device
	 * did not send an RFC option.
	 */
	rfc.mode = chan->mode;
	rfc.retrans_timeout = cpu_to_le16(L2CAP_DEFAULT_RETRANS_TO);
	rfc.monitor_timeout = cpu_to_le16(L2CAP_DEFAULT_MONITOR_TO);
	rfc.max_pdu_size = cpu_to_le16(chan->imtu);

	BT_ERR("Expected RFC option was not found, using defaults");

2928 2929 2930
done:
	switch (rfc.mode) {
	case L2CAP_MODE_ERTM:
2931 2932 2933
		chan->retrans_timeout = le16_to_cpu(rfc.retrans_timeout);
		chan->monitor_timeout = le16_to_cpu(rfc.monitor_timeout);
		chan->mps    = le16_to_cpu(rfc.max_pdu_size);
2934 2935
		break;
	case L2CAP_MODE_STREAMING:
2936
		chan->mps    = le16_to_cpu(rfc.max_pdu_size);
2937 2938 2939
	}
}

2940 2941
static inline int l2cap_command_rej(struct l2cap_conn *conn, struct l2cap_cmd_hdr *cmd, u8 *data)
{
2942
	struct l2cap_cmd_rej_unk *rej = (struct l2cap_cmd_rej_unk *) data;
2943

2944
	if (rej->reason != L2CAP_REJ_NOT_UNDERSTOOD)
2945 2946 2947 2948
		return 0;

	if ((conn->info_state & L2CAP_INFO_FEAT_MASK_REQ_SENT) &&
					cmd->ident == conn->info_ident) {
2949
		cancel_delayed_work(&conn->info_timer);
2950 2951

		conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_DONE;
2952
		conn->info_ident = 0;
2953

2954 2955 2956 2957 2958 2959
		l2cap_conn_start(conn);
	}

	return 0;
}

L
Linus Torvalds 已提交
2960 2961 2962 2963
static inline int l2cap_connect_req(struct l2cap_conn *conn, struct l2cap_cmd_hdr *cmd, u8 *data)
{
	struct l2cap_conn_req *req = (struct l2cap_conn_req *) data;
	struct l2cap_conn_rsp rsp;
2964
	struct l2cap_chan *chan = NULL, *pchan;
2965
	struct sock *parent, *sk = NULL;
2966
	int result, status = L2CAP_CS_NO_INFO;
L
Linus Torvalds 已提交
2967 2968

	u16 dcid = 0, scid = __le16_to_cpu(req->scid);
2969
	__le16 psm = req->psm;
L
Linus Torvalds 已提交
2970

2971
	BT_DBG("psm 0x%2.2x scid 0x%4.4x", __le16_to_cpu(psm), scid);
L
Linus Torvalds 已提交
2972 2973

	/* Check if we have socket listening on psm */
2974
	pchan = l2cap_global_chan_by_psm(BT_LISTEN, psm, conn->src, conn->dst);
2975
	if (!pchan) {
L
Linus Torvalds 已提交
2976 2977 2978 2979
		result = L2CAP_CR_BAD_PSM;
		goto sendresp;
	}

2980 2981
	parent = pchan->sk;

2982
	mutex_lock(&conn->chan_lock);
2983
	lock_sock(parent);
2984

2985 2986 2987
	/* Check if the ACL is secure enough (if not SDP) */
	if (psm != cpu_to_le16(0x0001) &&
				!hci_conn_check_link_mode(conn->hcon)) {
2988
		conn->disc_reason = HCI_ERROR_AUTH_FAILURE;
2989 2990 2991 2992
		result = L2CAP_CR_SEC_BLOCK;
		goto response;
	}

L
Linus Torvalds 已提交
2993 2994 2995 2996
	result = L2CAP_CR_NO_MEM;

	/* Check for backlog size */
	if (sk_acceptq_is_full(parent)) {
2997
		BT_DBG("backlog full %d", parent->sk_ack_backlog);
L
Linus Torvalds 已提交
2998 2999 3000
		goto response;
	}

3001 3002
	chan = pchan->ops->new_connection(pchan->data);
	if (!chan)
L
Linus Torvalds 已提交
3003 3004
		goto response;

3005 3006
	sk = chan->sk;

L
Linus Torvalds 已提交
3007
	/* Check if we already have channel with that dcid */
3008
	if (__l2cap_get_chan_by_dcid(conn, scid)) {
L
Linus Torvalds 已提交
3009
		sock_set_flag(sk, SOCK_ZAPPED);
3010
		chan->ops->close(chan->data);
L
Linus Torvalds 已提交
3011 3012 3013 3014 3015 3016 3017
		goto response;
	}

	hci_conn_hold(conn->hcon);

	bacpy(&bt_sk(sk)->src, conn->src);
	bacpy(&bt_sk(sk)->dst, conn->dst);
3018 3019
	chan->psm  = psm;
	chan->dcid = scid;
L
Linus Torvalds 已提交
3020

3021 3022
	bt_accept_enqueue(parent, sk);

3023
	__l2cap_chan_add(conn, chan);
3024

3025
	dcid = chan->scid;
L
Linus Torvalds 已提交
3026

3027
	__set_chan_timer(chan, sk->sk_sndtimeo);
L
Linus Torvalds 已提交
3028

3029
	chan->ident = cmd->ident;
L
Linus Torvalds 已提交
3030

3031
	if (conn->info_state & L2CAP_INFO_FEAT_MASK_REQ_DONE) {
3032
		if (l2cap_chan_check_security(chan)) {
3033
			if (bt_sk(sk)->defer_setup) {
3034
				__l2cap_state_change(chan, BT_CONNECT2);
3035 3036 3037 3038
				result = L2CAP_CR_PEND;
				status = L2CAP_CS_AUTHOR_PEND;
				parent->sk_data_ready(parent, 0);
			} else {
3039
				__l2cap_state_change(chan, BT_CONFIG);
3040 3041 3042
				result = L2CAP_CR_SUCCESS;
				status = L2CAP_CS_NO_INFO;
			}
3043
		} else {
3044
			__l2cap_state_change(chan, BT_CONNECT2);
3045 3046 3047 3048
			result = L2CAP_CR_PEND;
			status = L2CAP_CS_AUTHEN_PEND;
		}
	} else {
3049
		__l2cap_state_change(chan, BT_CONNECT2);
3050 3051
		result = L2CAP_CR_PEND;
		status = L2CAP_CS_NO_INFO;
L
Linus Torvalds 已提交
3052 3053 3054
	}

response:
3055
	release_sock(parent);
3056
	mutex_unlock(&conn->chan_lock);
L
Linus Torvalds 已提交
3057 3058

sendresp:
3059 3060 3061 3062
	rsp.scid   = cpu_to_le16(scid);
	rsp.dcid   = cpu_to_le16(dcid);
	rsp.result = cpu_to_le16(result);
	rsp.status = cpu_to_le16(status);
L
Linus Torvalds 已提交
3063
	l2cap_send_cmd(conn, cmd->ident, L2CAP_CONN_RSP, sizeof(rsp), &rsp);
3064 3065 3066 3067 3068 3069 3070 3071

	if (result == L2CAP_CR_PEND && status == L2CAP_CS_NO_INFO) {
		struct l2cap_info_req info;
		info.type = cpu_to_le16(L2CAP_IT_FEAT_MASK);

		conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_SENT;
		conn->info_ident = l2cap_get_ident(conn);

3072
		schedule_delayed_work(&conn->info_timer, L2CAP_INFO_TIMEOUT);
3073 3074 3075 3076 3077

		l2cap_send_cmd(conn, conn->info_ident,
					L2CAP_INFO_REQ, sizeof(info), &info);
	}

3078
	if (chan && !test_bit(CONF_REQ_SENT, &chan->conf_state) &&
3079 3080
				result == L2CAP_CR_SUCCESS) {
		u8 buf[128];
3081
		set_bit(CONF_REQ_SENT, &chan->conf_state);
3082
		l2cap_send_cmd(conn, l2cap_get_ident(conn), L2CAP_CONF_REQ,
3083 3084
					l2cap_build_conf_req(chan, buf), buf);
		chan->num_conf_req++;
3085 3086
	}

L
Linus Torvalds 已提交
3087 3088 3089 3090 3091 3092 3093
	return 0;
}

static inline int l2cap_connect_rsp(struct l2cap_conn *conn, struct l2cap_cmd_hdr *cmd, u8 *data)
{
	struct l2cap_conn_rsp *rsp = (struct l2cap_conn_rsp *) data;
	u16 scid, dcid, result, status;
3094
	struct l2cap_chan *chan;
L
Linus Torvalds 已提交
3095
	u8 req[128];
3096
	int err;
L
Linus Torvalds 已提交
3097 3098 3099 3100 3101 3102

	scid   = __le16_to_cpu(rsp->scid);
	dcid   = __le16_to_cpu(rsp->dcid);
	result = __le16_to_cpu(rsp->result);
	status = __le16_to_cpu(rsp->status);

3103 3104
	BT_DBG("dcid 0x%4.4x scid 0x%4.4x result 0x%2.2x status 0x%2.2x",
						dcid, scid, result, status);
L
Linus Torvalds 已提交
3105

3106 3107
	mutex_lock(&conn->chan_lock);

L
Linus Torvalds 已提交
3108
	if (scid) {
3109 3110 3111 3112 3113
		chan = __l2cap_get_chan_by_scid(conn, scid);
		if (!chan) {
			err = -EFAULT;
			goto unlock;
		}
L
Linus Torvalds 已提交
3114
	} else {
3115 3116 3117 3118 3119
		chan = __l2cap_get_chan_by_ident(conn, cmd->ident);
		if (!chan) {
			err = -EFAULT;
			goto unlock;
		}
L
Linus Torvalds 已提交
3120 3121
	}

3122 3123
	err = 0;

3124
	l2cap_chan_lock(chan);
3125

L
Linus Torvalds 已提交
3126 3127
	switch (result) {
	case L2CAP_CR_SUCCESS:
3128
		l2cap_state_change(chan, BT_CONFIG);
3129
		chan->ident = 0;
3130
		chan->dcid = dcid;
3131
		clear_bit(CONF_CONNECT_PEND, &chan->conf_state);
3132

3133
		if (test_and_set_bit(CONF_REQ_SENT, &chan->conf_state))
3134 3135
			break;

L
Linus Torvalds 已提交
3136
		l2cap_send_cmd(conn, l2cap_get_ident(conn), L2CAP_CONF_REQ,
3137 3138
					l2cap_build_conf_req(chan, req), req);
		chan->num_conf_req++;
L
Linus Torvalds 已提交
3139 3140 3141
		break;

	case L2CAP_CR_PEND:
3142
		set_bit(CONF_CONNECT_PEND, &chan->conf_state);
L
Linus Torvalds 已提交
3143 3144 3145
		break;

	default:
3146
		l2cap_chan_del(chan, ECONNREFUSED);
L
Linus Torvalds 已提交
3147 3148 3149
		break;
	}

3150
	l2cap_chan_unlock(chan);
3151 3152 3153 3154 3155

unlock:
	mutex_unlock(&conn->chan_lock);

	return err;
L
Linus Torvalds 已提交
3156 3157
}

3158
static inline void set_default_fcs(struct l2cap_chan *chan)
3159 3160 3161 3162
{
	/* FCS is enabled only in ERTM or streaming mode, if one or both
	 * sides request it.
	 */
3163
	if (chan->mode != L2CAP_MODE_ERTM && chan->mode != L2CAP_MODE_STREAMING)
3164
		chan->fcs = L2CAP_FCS_NONE;
3165
	else if (!test_bit(CONF_NO_FCS_RECV, &chan->conf_state))
3166
		chan->fcs = L2CAP_FCS_CRC16;
3167 3168
}

3169
static inline int l2cap_config_req(struct l2cap_conn *conn, struct l2cap_cmd_hdr *cmd, u16 cmd_len, u8 *data)
L
Linus Torvalds 已提交
3170 3171 3172 3173
{
	struct l2cap_conf_req *req = (struct l2cap_conf_req *) data;
	u16 dcid, flags;
	u8 rsp[64];
3174
	struct l2cap_chan *chan;
3175
	int len, err = 0;
L
Linus Torvalds 已提交
3176 3177 3178 3179 3180 3181

	dcid  = __le16_to_cpu(req->dcid);
	flags = __le16_to_cpu(req->flags);

	BT_DBG("dcid 0x%4.4x flags 0x%2.2x", dcid, flags);

3182
	chan = l2cap_get_chan_by_scid(conn, dcid);
3183
	if (!chan)
L
Linus Torvalds 已提交
3184 3185
		return -ENOENT;

3186
	l2cap_chan_lock(chan);
3187

3188
	if (chan->state != BT_CONFIG && chan->state != BT_CONNECT2) {
3189 3190 3191 3192 3193
		struct l2cap_cmd_rej_cid rej;

		rej.reason = cpu_to_le16(L2CAP_REJ_INVALID_CID);
		rej.scid = cpu_to_le16(chan->scid);
		rej.dcid = cpu_to_le16(chan->dcid);
3194 3195 3196

		l2cap_send_cmd(conn, cmd->ident, L2CAP_COMMAND_REJ,
				sizeof(rej), &rej);
3197
		goto unlock;
3198
	}
3199

3200
	/* Reject if config buffer is too small. */
3201
	len = cmd_len - sizeof(*req);
3202
	if (len < 0 || chan->conf_len + len > sizeof(chan->conf_req)) {
3203
		l2cap_send_cmd(conn, cmd->ident, L2CAP_CONF_RSP,
3204
				l2cap_build_conf_rsp(chan, rsp,
3205 3206 3207 3208 3209
					L2CAP_CONF_REJECT, flags), rsp);
		goto unlock;
	}

	/* Store config. */
3210 3211
	memcpy(chan->conf_req + chan->conf_len, req->data, len);
	chan->conf_len += len;
L
Linus Torvalds 已提交
3212 3213 3214 3215

	if (flags & 0x0001) {
		/* Incomplete config. Send empty response. */
		l2cap_send_cmd(conn, cmd->ident, L2CAP_CONF_RSP,
3216
				l2cap_build_conf_rsp(chan, rsp,
3217
					L2CAP_CONF_SUCCESS, 0x0001), rsp);
L
Linus Torvalds 已提交
3218 3219 3220 3221
		goto unlock;
	}

	/* Complete config. */
3222
	len = l2cap_parse_conf_req(chan, rsp);
3223
	if (len < 0) {
3224
		l2cap_send_disconn_req(conn, chan, ECONNRESET);
L
Linus Torvalds 已提交
3225
		goto unlock;
3226
	}
L
Linus Torvalds 已提交
3227

3228
	l2cap_send_cmd(conn, cmd->ident, L2CAP_CONF_RSP, len, rsp);
3229
	chan->num_conf_rsp++;
3230 3231

	/* Reset config buffer. */
3232
	chan->conf_len = 0;
3233

3234
	if (!test_bit(CONF_OUTPUT_DONE, &chan->conf_state))
3235 3236
		goto unlock;

3237
	if (test_bit(CONF_INPUT_DONE, &chan->conf_state)) {
3238
		set_default_fcs(chan);
3239

3240
		l2cap_state_change(chan, BT_CONNECTED);
3241

3242 3243
		if (chan->mode == L2CAP_MODE_ERTM ||
		    chan->mode == L2CAP_MODE_STREAMING)
3244 3245 3246 3247 3248 3249
			err = l2cap_ertm_init(chan);

		if (err < 0)
			l2cap_send_disconn_req(chan->conn, chan, -err);
		else
			l2cap_chan_ready(chan);
3250

3251 3252 3253
		goto unlock;
	}

3254
	if (!test_and_set_bit(CONF_REQ_SENT, &chan->conf_state)) {
3255
		u8 buf[64];
L
Linus Torvalds 已提交
3256
		l2cap_send_cmd(conn, l2cap_get_ident(conn), L2CAP_CONF_REQ,
3257 3258
					l2cap_build_conf_req(chan, buf), buf);
		chan->num_conf_req++;
L
Linus Torvalds 已提交
3259 3260
	}

3261 3262 3263 3264 3265 3266 3267 3268 3269 3270 3271
	/* Got Conf Rsp PENDING from remote side and asume we sent
	   Conf Rsp PENDING in the code above */
	if (test_bit(CONF_REM_CONF_PEND, &chan->conf_state) &&
			test_bit(CONF_LOC_CONF_PEND, &chan->conf_state)) {

		/* check compatibility */

		clear_bit(CONF_LOC_CONF_PEND, &chan->conf_state);
		set_bit(CONF_OUTPUT_DONE, &chan->conf_state);

		l2cap_send_cmd(conn, cmd->ident, L2CAP_CONF_RSP,
3272
					l2cap_build_conf_rsp(chan, rsp,
3273 3274 3275
					L2CAP_CONF_SUCCESS, 0x0000), rsp);
	}

L
Linus Torvalds 已提交
3276
unlock:
3277
	l2cap_chan_unlock(chan);
3278
	return err;
L
Linus Torvalds 已提交
3279 3280 3281 3282 3283 3284
}

static inline int l2cap_config_rsp(struct l2cap_conn *conn, struct l2cap_cmd_hdr *cmd, u8 *data)
{
	struct l2cap_conf_rsp *rsp = (struct l2cap_conf_rsp *)data;
	u16 scid, flags, result;
3285
	struct l2cap_chan *chan;
3286
	int len = le16_to_cpu(cmd->len) - sizeof(*rsp);
3287
	int err = 0;
L
Linus Torvalds 已提交
3288 3289 3290 3291 3292

	scid   = __le16_to_cpu(rsp->scid);
	flags  = __le16_to_cpu(rsp->flags);
	result = __le16_to_cpu(rsp->result);

3293 3294
	BT_DBG("scid 0x%4.4x flags 0x%2.2x result 0x%2.2x len %d", scid, flags,
	       result, len);
L
Linus Torvalds 已提交
3295

3296
	chan = l2cap_get_chan_by_scid(conn, scid);
3297
	if (!chan)
L
Linus Torvalds 已提交
3298 3299
		return 0;

3300
	l2cap_chan_lock(chan);
3301

L
Linus Torvalds 已提交
3302 3303
	switch (result) {
	case L2CAP_CONF_SUCCESS:
3304
		l2cap_conf_rfc_get(chan, rsp->data, len);
3305
		clear_bit(CONF_REM_CONF_PEND, &chan->conf_state);
L
Linus Torvalds 已提交
3306 3307
		break;

3308 3309 3310 3311 3312 3313 3314 3315 3316 3317 3318 3319 3320 3321 3322 3323 3324 3325 3326
	case L2CAP_CONF_PENDING:
		set_bit(CONF_REM_CONF_PEND, &chan->conf_state);

		if (test_bit(CONF_LOC_CONF_PEND, &chan->conf_state)) {
			char buf[64];

			len = l2cap_parse_conf_rsp(chan, rsp->data, len,
								buf, &result);
			if (len < 0) {
				l2cap_send_disconn_req(conn, chan, ECONNRESET);
				goto done;
			}

			/* check compatibility */

			clear_bit(CONF_LOC_CONF_PEND, &chan->conf_state);
			set_bit(CONF_OUTPUT_DONE, &chan->conf_state);

			l2cap_send_cmd(conn, cmd->ident, L2CAP_CONF_RSP,
3327
						l2cap_build_conf_rsp(chan, buf,
3328 3329 3330 3331
						L2CAP_CONF_SUCCESS, 0x0000), buf);
		}
		goto done;

L
Linus Torvalds 已提交
3332
	case L2CAP_CONF_UNACCEPT:
3333
		if (chan->num_conf_rsp <= L2CAP_CONF_MAX_CONF_RSP) {
3334 3335
			char req[64];

3336
			if (len > sizeof(req) - sizeof(struct l2cap_conf_req)) {
3337
				l2cap_send_disconn_req(conn, chan, ECONNRESET);
3338 3339 3340
				goto done;
			}

3341 3342
			/* throw out any old stored conf requests */
			result = L2CAP_CONF_SUCCESS;
3343 3344
			len = l2cap_parse_conf_rsp(chan, rsp->data, len,
								req, &result);
3345
			if (len < 0) {
3346
				l2cap_send_disconn_req(conn, chan, ECONNRESET);
3347 3348 3349 3350 3351
				goto done;
			}

			l2cap_send_cmd(conn, l2cap_get_ident(conn),
						L2CAP_CONF_REQ, len, req);
3352
			chan->num_conf_req++;
3353 3354 3355
			if (result != L2CAP_CONF_SUCCESS)
				goto done;
			break;
L
Linus Torvalds 已提交
3356 3357
		}

3358
	default:
3359
		l2cap_chan_set_err(chan, ECONNRESET);
3360

3361
		__set_chan_timer(chan, L2CAP_DISC_REJ_TIMEOUT);
3362
		l2cap_send_disconn_req(conn, chan, ECONNRESET);
L
Linus Torvalds 已提交
3363 3364 3365 3366 3367 3368
		goto done;
	}

	if (flags & 0x01)
		goto done;

3369
	set_bit(CONF_INPUT_DONE, &chan->conf_state);
L
Linus Torvalds 已提交
3370

3371
	if (test_bit(CONF_OUTPUT_DONE, &chan->conf_state)) {
3372
		set_default_fcs(chan);
3373

3374
		l2cap_state_change(chan, BT_CONNECTED);
3375 3376
		if (chan->mode == L2CAP_MODE_ERTM ||
		    chan->mode == L2CAP_MODE_STREAMING)
3377
			err = l2cap_ertm_init(chan);
3378

3379 3380 3381 3382
		if (err < 0)
			l2cap_send_disconn_req(chan->conn, chan, -err);
		else
			l2cap_chan_ready(chan);
L
Linus Torvalds 已提交
3383 3384 3385
	}

done:
3386
	l2cap_chan_unlock(chan);
3387
	return err;
L
Linus Torvalds 已提交
3388 3389 3390 3391 3392 3393 3394
}

static inline int l2cap_disconnect_req(struct l2cap_conn *conn, struct l2cap_cmd_hdr *cmd, u8 *data)
{
	struct l2cap_disconn_req *req = (struct l2cap_disconn_req *) data;
	struct l2cap_disconn_rsp rsp;
	u16 dcid, scid;
3395
	struct l2cap_chan *chan;
L
Linus Torvalds 已提交
3396 3397 3398 3399 3400 3401 3402
	struct sock *sk;

	scid = __le16_to_cpu(req->scid);
	dcid = __le16_to_cpu(req->dcid);

	BT_DBG("scid 0x%4.4x dcid 0x%4.4x", scid, dcid);

3403 3404 3405 3406 3407
	mutex_lock(&conn->chan_lock);

	chan = __l2cap_get_chan_by_scid(conn, dcid);
	if (!chan) {
		mutex_unlock(&conn->chan_lock);
L
Linus Torvalds 已提交
3408
		return 0;
3409
	}
L
Linus Torvalds 已提交
3410

3411 3412
	l2cap_chan_lock(chan);

3413 3414
	sk = chan->sk;

3415 3416
	rsp.dcid = cpu_to_le16(chan->scid);
	rsp.scid = cpu_to_le16(chan->dcid);
L
Linus Torvalds 已提交
3417 3418
	l2cap_send_cmd(conn, cmd->ident, L2CAP_DISCONN_RSP, sizeof(rsp), &rsp);

3419
	lock_sock(sk);
L
Linus Torvalds 已提交
3420
	sk->sk_shutdown = SHUTDOWN_MASK;
3421
	release_sock(sk);
L
Linus Torvalds 已提交
3422

3423
	l2cap_chan_hold(chan);
3424
	l2cap_chan_del(chan, ECONNRESET);
3425 3426

	l2cap_chan_unlock(chan);
L
Linus Torvalds 已提交
3427

3428
	chan->ops->close(chan->data);
3429
	l2cap_chan_put(chan);
3430 3431 3432

	mutex_unlock(&conn->chan_lock);

L
Linus Torvalds 已提交
3433 3434 3435 3436 3437 3438 3439
	return 0;
}

static inline int l2cap_disconnect_rsp(struct l2cap_conn *conn, struct l2cap_cmd_hdr *cmd, u8 *data)
{
	struct l2cap_disconn_rsp *rsp = (struct l2cap_disconn_rsp *) data;
	u16 dcid, scid;
3440
	struct l2cap_chan *chan;
L
Linus Torvalds 已提交
3441 3442 3443 3444 3445 3446

	scid = __le16_to_cpu(rsp->scid);
	dcid = __le16_to_cpu(rsp->dcid);

	BT_DBG("dcid 0x%4.4x scid 0x%4.4x", dcid, scid);

3447 3448 3449 3450 3451
	mutex_lock(&conn->chan_lock);

	chan = __l2cap_get_chan_by_scid(conn, scid);
	if (!chan) {
		mutex_unlock(&conn->chan_lock);
L
Linus Torvalds 已提交
3452
		return 0;
3453
	}
L
Linus Torvalds 已提交
3454

3455
	l2cap_chan_lock(chan);
3456

3457
	l2cap_chan_hold(chan);
3458
	l2cap_chan_del(chan, 0);
3459 3460

	l2cap_chan_unlock(chan);
L
Linus Torvalds 已提交
3461

3462
	chan->ops->close(chan->data);
3463
	l2cap_chan_put(chan);
3464 3465 3466

	mutex_unlock(&conn->chan_lock);

L
Linus Torvalds 已提交
3467 3468 3469 3470 3471 3472 3473 3474 3475 3476 3477 3478
	return 0;
}

static inline int l2cap_information_req(struct l2cap_conn *conn, struct l2cap_cmd_hdr *cmd, u8 *data)
{
	struct l2cap_info_req *req = (struct l2cap_info_req *) data;
	u16 type;

	type = __le16_to_cpu(req->type);

	BT_DBG("type 0x%4.4x", type);

3479 3480
	if (type == L2CAP_IT_FEAT_MASK) {
		u8 buf[8];
3481
		u32 feat_mask = l2cap_feat_mask;
3482 3483 3484
		struct l2cap_info_rsp *rsp = (struct l2cap_info_rsp *) buf;
		rsp->type   = cpu_to_le16(L2CAP_IT_FEAT_MASK);
		rsp->result = cpu_to_le16(L2CAP_IR_SUCCESS);
3485
		if (!disable_ertm)
3486 3487
			feat_mask |= L2CAP_FEAT_ERTM | L2CAP_FEAT_STREAMING
							 | L2CAP_FEAT_FCS;
3488
		if (enable_hs)
3489 3490
			feat_mask |= L2CAP_FEAT_EXT_FLOW
						| L2CAP_FEAT_EXT_WINDOW;
3491

3492
		put_unaligned_le32(feat_mask, rsp->data);
3493 3494
		l2cap_send_cmd(conn, cmd->ident,
					L2CAP_INFO_RSP, sizeof(buf), buf);
3495 3496 3497
	} else if (type == L2CAP_IT_FIXED_CHAN) {
		u8 buf[12];
		struct l2cap_info_rsp *rsp = (struct l2cap_info_rsp *) buf;
3498 3499 3500 3501 3502 3503

		if (enable_hs)
			l2cap_fixed_chan[0] |= L2CAP_FC_A2MP;
		else
			l2cap_fixed_chan[0] &= ~L2CAP_FC_A2MP;

3504 3505
		rsp->type   = cpu_to_le16(L2CAP_IT_FIXED_CHAN);
		rsp->result = cpu_to_le16(L2CAP_IR_SUCCESS);
3506
		memcpy(rsp->data, l2cap_fixed_chan, sizeof(l2cap_fixed_chan));
3507 3508
		l2cap_send_cmd(conn, cmd->ident,
					L2CAP_INFO_RSP, sizeof(buf), buf);
3509 3510 3511 3512 3513 3514 3515
	} else {
		struct l2cap_info_rsp rsp;
		rsp.type   = cpu_to_le16(type);
		rsp.result = cpu_to_le16(L2CAP_IR_NOTSUPP);
		l2cap_send_cmd(conn, cmd->ident,
					L2CAP_INFO_RSP, sizeof(rsp), &rsp);
	}
L
Linus Torvalds 已提交
3516 3517 3518 3519 3520 3521 3522 3523 3524 3525 3526 3527 3528 3529

	return 0;
}

static inline int l2cap_information_rsp(struct l2cap_conn *conn, struct l2cap_cmd_hdr *cmd, u8 *data)
{
	struct l2cap_info_rsp *rsp = (struct l2cap_info_rsp *) data;
	u16 type, result;

	type   = __le16_to_cpu(rsp->type);
	result = __le16_to_cpu(rsp->result);

	BT_DBG("type 0x%4.4x result 0x%2.2x", type, result);

3530 3531 3532 3533 3534
	/* L2CAP Info req/rsp are unbound to channels, add extra checks */
	if (cmd->ident != conn->info_ident ||
			conn->info_state & L2CAP_INFO_FEAT_MASK_REQ_DONE)
		return 0;

3535
	cancel_delayed_work(&conn->info_timer);
3536

3537 3538 3539 3540 3541 3542 3543 3544 3545
	if (result != L2CAP_IR_SUCCESS) {
		conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_DONE;
		conn->info_ident = 0;

		l2cap_conn_start(conn);

		return 0;
	}

3546 3547
	switch (type) {
	case L2CAP_IT_FEAT_MASK:
3548
		conn->feat_mask = get_unaligned_le32(rsp->data);
3549

3550
		if (conn->feat_mask & L2CAP_FEAT_FIXED_CHAN) {
3551 3552 3553 3554 3555 3556 3557 3558 3559 3560 3561 3562 3563
			struct l2cap_info_req req;
			req.type = cpu_to_le16(L2CAP_IT_FIXED_CHAN);

			conn->info_ident = l2cap_get_ident(conn);

			l2cap_send_cmd(conn, conn->info_ident,
					L2CAP_INFO_REQ, sizeof(req), &req);
		} else {
			conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_DONE;
			conn->info_ident = 0;

			l2cap_conn_start(conn);
		}
3564 3565 3566 3567
		break;

	case L2CAP_IT_FIXED_CHAN:
		conn->fixed_chan_mask = rsp->data[0];
3568
		conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_DONE;
3569
		conn->info_ident = 0;
3570 3571

		l2cap_conn_start(conn);
3572
		break;
3573
	}
3574

L
Linus Torvalds 已提交
3575 3576 3577
	return 0;
}

3578 3579 3580 3581 3582 3583 3584 3585 3586 3587 3588 3589 3590 3591 3592 3593 3594 3595 3596 3597 3598 3599
static inline int l2cap_create_channel_req(struct l2cap_conn *conn,
					struct l2cap_cmd_hdr *cmd, u16 cmd_len,
					void *data)
{
	struct l2cap_create_chan_req *req = data;
	struct l2cap_create_chan_rsp rsp;
	u16 psm, scid;

	if (cmd_len != sizeof(*req))
		return -EPROTO;

	if (!enable_hs)
		return -EINVAL;

	psm = le16_to_cpu(req->psm);
	scid = le16_to_cpu(req->scid);

	BT_DBG("psm %d, scid %d, amp_id %d", psm, scid, req->amp_id);

	/* Placeholder: Always reject */
	rsp.dcid = 0;
	rsp.scid = cpu_to_le16(scid);
3600 3601
	rsp.result = __constant_cpu_to_le16(L2CAP_CR_NO_MEM);
	rsp.status = __constant_cpu_to_le16(L2CAP_CS_NO_INFO);
3602 3603 3604 3605 3606 3607 3608 3609 3610 3611 3612 3613 3614 3615 3616

	l2cap_send_cmd(conn, cmd->ident, L2CAP_CREATE_CHAN_RSP,
		       sizeof(rsp), &rsp);

	return 0;
}

static inline int l2cap_create_channel_rsp(struct l2cap_conn *conn,
					struct l2cap_cmd_hdr *cmd, void *data)
{
	BT_DBG("conn %p", conn);

	return l2cap_connect_rsp(conn, cmd, data);
}

3617 3618 3619 3620 3621 3622 3623 3624 3625 3626 3627 3628 3629 3630 3631 3632 3633 3634 3635 3636 3637 3638 3639 3640 3641 3642 3643 3644 3645 3646 3647 3648 3649 3650 3651 3652 3653 3654 3655 3656 3657 3658 3659 3660 3661 3662 3663 3664 3665 3666 3667 3668 3669 3670 3671 3672 3673 3674 3675 3676 3677 3678 3679 3680 3681 3682 3683 3684 3685 3686 3687 3688 3689 3690 3691 3692 3693 3694 3695 3696 3697 3698 3699 3700 3701 3702 3703 3704 3705 3706 3707 3708 3709 3710 3711 3712 3713 3714 3715 3716 3717 3718 3719 3720 3721 3722 3723 3724 3725 3726 3727 3728 3729 3730 3731 3732 3733 3734 3735 3736
static void l2cap_send_move_chan_rsp(struct l2cap_conn *conn, u8 ident,
							u16 icid, u16 result)
{
	struct l2cap_move_chan_rsp rsp;

	BT_DBG("icid %d, result %d", icid, result);

	rsp.icid = cpu_to_le16(icid);
	rsp.result = cpu_to_le16(result);

	l2cap_send_cmd(conn, ident, L2CAP_MOVE_CHAN_RSP, sizeof(rsp), &rsp);
}

static void l2cap_send_move_chan_cfm(struct l2cap_conn *conn,
				struct l2cap_chan *chan, u16 icid, u16 result)
{
	struct l2cap_move_chan_cfm cfm;
	u8 ident;

	BT_DBG("icid %d, result %d", icid, result);

	ident = l2cap_get_ident(conn);
	if (chan)
		chan->ident = ident;

	cfm.icid = cpu_to_le16(icid);
	cfm.result = cpu_to_le16(result);

	l2cap_send_cmd(conn, ident, L2CAP_MOVE_CHAN_CFM, sizeof(cfm), &cfm);
}

static void l2cap_send_move_chan_cfm_rsp(struct l2cap_conn *conn, u8 ident,
								u16 icid)
{
	struct l2cap_move_chan_cfm_rsp rsp;

	BT_DBG("icid %d", icid);

	rsp.icid = cpu_to_le16(icid);
	l2cap_send_cmd(conn, ident, L2CAP_MOVE_CHAN_CFM_RSP, sizeof(rsp), &rsp);
}

static inline int l2cap_move_channel_req(struct l2cap_conn *conn,
			struct l2cap_cmd_hdr *cmd, u16 cmd_len, void *data)
{
	struct l2cap_move_chan_req *req = data;
	u16 icid = 0;
	u16 result = L2CAP_MR_NOT_ALLOWED;

	if (cmd_len != sizeof(*req))
		return -EPROTO;

	icid = le16_to_cpu(req->icid);

	BT_DBG("icid %d, dest_amp_id %d", icid, req->dest_amp_id);

	if (!enable_hs)
		return -EINVAL;

	/* Placeholder: Always refuse */
	l2cap_send_move_chan_rsp(conn, cmd->ident, icid, result);

	return 0;
}

static inline int l2cap_move_channel_rsp(struct l2cap_conn *conn,
			struct l2cap_cmd_hdr *cmd, u16 cmd_len, void *data)
{
	struct l2cap_move_chan_rsp *rsp = data;
	u16 icid, result;

	if (cmd_len != sizeof(*rsp))
		return -EPROTO;

	icid = le16_to_cpu(rsp->icid);
	result = le16_to_cpu(rsp->result);

	BT_DBG("icid %d, result %d", icid, result);

	/* Placeholder: Always unconfirmed */
	l2cap_send_move_chan_cfm(conn, NULL, icid, L2CAP_MC_UNCONFIRMED);

	return 0;
}

static inline int l2cap_move_channel_confirm(struct l2cap_conn *conn,
			struct l2cap_cmd_hdr *cmd, u16 cmd_len, void *data)
{
	struct l2cap_move_chan_cfm *cfm = data;
	u16 icid, result;

	if (cmd_len != sizeof(*cfm))
		return -EPROTO;

	icid = le16_to_cpu(cfm->icid);
	result = le16_to_cpu(cfm->result);

	BT_DBG("icid %d, result %d", icid, result);

	l2cap_send_move_chan_cfm_rsp(conn, cmd->ident, icid);

	return 0;
}

static inline int l2cap_move_channel_confirm_rsp(struct l2cap_conn *conn,
			struct l2cap_cmd_hdr *cmd, u16 cmd_len, void *data)
{
	struct l2cap_move_chan_cfm_rsp *rsp = data;
	u16 icid;

	if (cmd_len != sizeof(*rsp))
		return -EPROTO;

	icid = le16_to_cpu(rsp->icid);

	BT_DBG("icid %d", icid);

	return 0;
}

3737
static inline int l2cap_check_conn_param(u16 min, u16 max, u16 latency,
3738 3739 3740 3741 3742 3743 3744 3745 3746 3747 3748 3749 3750 3751 3752 3753 3754 3755 3756 3757 3758 3759 3760 3761 3762 3763 3764
							u16 to_multiplier)
{
	u16 max_latency;

	if (min > max || min < 6 || max > 3200)
		return -EINVAL;

	if (to_multiplier < 10 || to_multiplier > 3200)
		return -EINVAL;

	if (max >= to_multiplier * 8)
		return -EINVAL;

	max_latency = (to_multiplier * 8 / max) - 1;
	if (latency > 499 || latency > max_latency)
		return -EINVAL;

	return 0;
}

static inline int l2cap_conn_param_update_req(struct l2cap_conn *conn,
					struct l2cap_cmd_hdr *cmd, u8 *data)
{
	struct hci_conn *hcon = conn->hcon;
	struct l2cap_conn_param_update_req *req;
	struct l2cap_conn_param_update_rsp rsp;
	u16 min, max, latency, to_multiplier, cmd_len;
3765
	int err;
3766 3767 3768 3769 3770 3771 3772 3773 3774

	if (!(hcon->link_mode & HCI_LM_MASTER))
		return -EINVAL;

	cmd_len = __le16_to_cpu(cmd->len);
	if (cmd_len != sizeof(struct l2cap_conn_param_update_req))
		return -EPROTO;

	req = (struct l2cap_conn_param_update_req *) data;
3775 3776
	min		= __le16_to_cpu(req->min);
	max		= __le16_to_cpu(req->max);
3777 3778 3779 3780 3781 3782 3783
	latency		= __le16_to_cpu(req->latency);
	to_multiplier	= __le16_to_cpu(req->to_multiplier);

	BT_DBG("min 0x%4.4x max 0x%4.4x latency: 0x%4.4x Timeout: 0x%4.4x",
						min, max, latency, to_multiplier);

	memset(&rsp, 0, sizeof(rsp));
3784 3785 3786

	err = l2cap_check_conn_param(min, max, latency, to_multiplier);
	if (err)
3787 3788 3789 3790 3791 3792 3793
		rsp.result = cpu_to_le16(L2CAP_CONN_PARAM_REJECTED);
	else
		rsp.result = cpu_to_le16(L2CAP_CONN_PARAM_ACCEPTED);

	l2cap_send_cmd(conn, cmd->ident, L2CAP_CONN_PARAM_UPDATE_RSP,
							sizeof(rsp), &rsp);

3794 3795 3796
	if (!err)
		hci_le_conn_update(hcon, min, max, latency, to_multiplier);

3797 3798 3799
	return 0;
}

3800 3801 3802 3803 3804 3805 3806 3807 3808 3809 3810 3811 3812 3813 3814 3815 3816 3817 3818 3819 3820 3821 3822 3823 3824 3825 3826 3827 3828 3829 3830 3831 3832 3833 3834 3835 3836 3837 3838 3839 3840 3841 3842 3843 3844 3845 3846 3847 3848
static inline int l2cap_bredr_sig_cmd(struct l2cap_conn *conn,
			struct l2cap_cmd_hdr *cmd, u16 cmd_len, u8 *data)
{
	int err = 0;

	switch (cmd->code) {
	case L2CAP_COMMAND_REJ:
		l2cap_command_rej(conn, cmd, data);
		break;

	case L2CAP_CONN_REQ:
		err = l2cap_connect_req(conn, cmd, data);
		break;

	case L2CAP_CONN_RSP:
		err = l2cap_connect_rsp(conn, cmd, data);
		break;

	case L2CAP_CONF_REQ:
		err = l2cap_config_req(conn, cmd, cmd_len, data);
		break;

	case L2CAP_CONF_RSP:
		err = l2cap_config_rsp(conn, cmd, data);
		break;

	case L2CAP_DISCONN_REQ:
		err = l2cap_disconnect_req(conn, cmd, data);
		break;

	case L2CAP_DISCONN_RSP:
		err = l2cap_disconnect_rsp(conn, cmd, data);
		break;

	case L2CAP_ECHO_REQ:
		l2cap_send_cmd(conn, cmd->ident, L2CAP_ECHO_RSP, cmd_len, data);
		break;

	case L2CAP_ECHO_RSP:
		break;

	case L2CAP_INFO_REQ:
		err = l2cap_information_req(conn, cmd, data);
		break;

	case L2CAP_INFO_RSP:
		err = l2cap_information_rsp(conn, cmd, data);
		break;

3849 3850 3851 3852 3853 3854 3855 3856
	case L2CAP_CREATE_CHAN_REQ:
		err = l2cap_create_channel_req(conn, cmd, cmd_len, data);
		break;

	case L2CAP_CREATE_CHAN_RSP:
		err = l2cap_create_channel_rsp(conn, cmd, data);
		break;

3857 3858 3859 3860 3861 3862 3863 3864 3865 3866 3867 3868 3869 3870 3871 3872
	case L2CAP_MOVE_CHAN_REQ:
		err = l2cap_move_channel_req(conn, cmd, cmd_len, data);
		break;

	case L2CAP_MOVE_CHAN_RSP:
		err = l2cap_move_channel_rsp(conn, cmd, cmd_len, data);
		break;

	case L2CAP_MOVE_CHAN_CFM:
		err = l2cap_move_channel_confirm(conn, cmd, cmd_len, data);
		break;

	case L2CAP_MOVE_CHAN_CFM_RSP:
		err = l2cap_move_channel_confirm_rsp(conn, cmd, cmd_len, data);
		break;

3873 3874 3875 3876 3877 3878 3879 3880 3881 3882 3883 3884 3885 3886 3887 3888 3889
	default:
		BT_ERR("Unknown BR/EDR signaling command 0x%2.2x", cmd->code);
		err = -EINVAL;
		break;
	}

	return err;
}

static inline int l2cap_le_sig_cmd(struct l2cap_conn *conn,
					struct l2cap_cmd_hdr *cmd, u8 *data)
{
	switch (cmd->code) {
	case L2CAP_COMMAND_REJ:
		return 0;

	case L2CAP_CONN_PARAM_UPDATE_REQ:
3890
		return l2cap_conn_param_update_req(conn, cmd, data);
3891 3892 3893 3894 3895 3896 3897 3898 3899 3900 3901 3902

	case L2CAP_CONN_PARAM_UPDATE_RSP:
		return 0;

	default:
		BT_ERR("Unknown LE signaling command 0x%2.2x", cmd->code);
		return -EINVAL;
	}
}

static inline void l2cap_sig_channel(struct l2cap_conn *conn,
							struct sk_buff *skb)
L
Linus Torvalds 已提交
3903 3904 3905 3906
{
	u8 *data = skb->data;
	int len = skb->len;
	struct l2cap_cmd_hdr cmd;
3907
	int err;
L
Linus Torvalds 已提交
3908 3909 3910 3911

	l2cap_raw_recv(conn, skb);

	while (len >= L2CAP_CMD_HDR_SIZE) {
3912
		u16 cmd_len;
L
Linus Torvalds 已提交
3913 3914 3915 3916
		memcpy(&cmd, data, L2CAP_CMD_HDR_SIZE);
		data += L2CAP_CMD_HDR_SIZE;
		len  -= L2CAP_CMD_HDR_SIZE;

3917
		cmd_len = le16_to_cpu(cmd.len);
L
Linus Torvalds 已提交
3918

3919
		BT_DBG("code 0x%2.2x len %d id 0x%2.2x", cmd.code, cmd_len, cmd.ident);
L
Linus Torvalds 已提交
3920

3921
		if (cmd_len > len || !cmd.ident) {
L
Linus Torvalds 已提交
3922 3923 3924 3925
			BT_DBG("corrupted command");
			break;
		}

3926 3927 3928 3929
		if (conn->hcon->type == LE_LINK)
			err = l2cap_le_sig_cmd(conn, &cmd, data);
		else
			err = l2cap_bredr_sig_cmd(conn, &cmd, cmd_len, data);
L
Linus Torvalds 已提交
3930 3931

		if (err) {
3932
			struct l2cap_cmd_rej_unk rej;
3933 3934

			BT_ERR("Wrong link type (%d)", err);
L
Linus Torvalds 已提交
3935 3936

			/* FIXME: Map err to a valid reason */
3937
			rej.reason = cpu_to_le16(L2CAP_REJ_NOT_UNDERSTOOD);
L
Linus Torvalds 已提交
3938 3939 3940
			l2cap_send_cmd(conn, cmd.ident, L2CAP_COMMAND_REJ, sizeof(rej), &rej);
		}

3941 3942
		data += cmd_len;
		len  -= cmd_len;
L
Linus Torvalds 已提交
3943 3944 3945 3946 3947
	}

	kfree_skb(skb);
}

3948
static int l2cap_check_fcs(struct l2cap_chan *chan,  struct sk_buff *skb)
3949 3950
{
	u16 our_fcs, rcv_fcs;
3951 3952 3953 3954 3955 3956
	int hdr_size;

	if (test_bit(FLAG_EXT_CTRL, &chan->flags))
		hdr_size = L2CAP_EXT_HDR_SIZE;
	else
		hdr_size = L2CAP_ENH_HDR_SIZE;
3957

3958
	if (chan->fcs == L2CAP_FCS_CRC16) {
3959
		skb_trim(skb, skb->len - L2CAP_FCS_SIZE);
3960 3961 3962 3963
		rcv_fcs = get_unaligned_le16(skb->data + skb->len);
		our_fcs = crc16(0, skb->data - hdr_size, skb->len + hdr_size);

		if (our_fcs != rcv_fcs)
3964
			return -EBADMSG;
3965 3966 3967 3968
	}
	return 0;
}

3969
static inline void l2cap_send_i_or_rr_or_rnr(struct l2cap_chan *chan)
3970
{
3971
	u32 control = 0;
3972

3973
	chan->frames_sent = 0;
3974

3975
	control |= __set_reqseq(chan, chan->buffer_seq);
3976

3977
	if (test_bit(CONN_LOCAL_BUSY, &chan->conn_state)) {
3978
		control |= __set_ctrl_super(chan, L2CAP_SUPER_RNR);
3979
		l2cap_send_sframe(chan, control);
3980
		set_bit(CONN_RNR_SENT, &chan->conn_state);
3981 3982
	}

3983
	if (test_bit(CONN_REMOTE_BUSY, &chan->conn_state))
3984
		l2cap_retransmit_frames(chan);
3985

3986
	l2cap_ertm_send(chan);
3987

3988
	if (!test_bit(CONN_LOCAL_BUSY, &chan->conn_state) &&
3989
			chan->frames_sent == 0) {
3990
		control |= __set_ctrl_super(chan, L2CAP_SUPER_RR);
3991
		l2cap_send_sframe(chan, control);
3992 3993 3994
	}
}

3995
static int l2cap_add_to_srej_queue(struct l2cap_chan *chan, struct sk_buff *skb, u16 tx_seq, u8 sar)
3996 3997
{
	struct sk_buff *next_skb;
3998
	int tx_seq_offset, next_tx_seq_offset;
3999

4000 4001
	bt_cb(skb)->control.txseq = tx_seq;
	bt_cb(skb)->control.sar = sar;
4002

4003
	next_skb = skb_peek(&chan->srej_q);
4004

4005
	tx_seq_offset = __seq_offset(chan, tx_seq, chan->buffer_seq);
4006

4007
	while (next_skb) {
4008
		if (bt_cb(next_skb)->control.txseq == tx_seq)
4009 4010
			return -EINVAL;

4011
		next_tx_seq_offset = __seq_offset(chan,
4012
			bt_cb(next_skb)->control.txseq, chan->buffer_seq);
4013 4014

		if (next_tx_seq_offset > tx_seq_offset) {
4015
			__skb_queue_before(&chan->srej_q, next_skb, skb);
4016
			return 0;
4017 4018
		}

4019
		if (skb_queue_is_last(&chan->srej_q, next_skb))
4020 4021 4022 4023
			next_skb = NULL;
		else
			next_skb = skb_queue_next(&chan->srej_q, next_skb);
	}
4024

4025
	__skb_queue_tail(&chan->srej_q, skb);
4026 4027

	return 0;
4028 4029
}

4030 4031
static void append_skb_frag(struct sk_buff *skb,
			struct sk_buff *new_frag, struct sk_buff **last_frag)
4032
{
4033 4034 4035 4036 4037 4038 4039 4040 4041 4042 4043 4044 4045 4046 4047 4048
	/* skb->len reflects data in skb as well as all fragments
	 * skb->data_len reflects only data in fragments
	 */
	if (!skb_has_frag_list(skb))
		skb_shinfo(skb)->frag_list = new_frag;

	new_frag->next = NULL;

	(*last_frag)->next = new_frag;
	*last_frag = new_frag;

	skb->len += new_frag->len;
	skb->data_len += new_frag->len;
	skb->truesize += new_frag->truesize;
}

4049
static int l2cap_reassemble_sdu(struct l2cap_chan *chan, struct sk_buff *skb, u32 control)
4050 4051
{
	int err = -EINVAL;
4052

4053 4054
	switch (__get_ctrl_sar(chan, control)) {
	case L2CAP_SAR_UNSEGMENTED:
4055 4056
		if (chan->sdu)
			break;
4057

4058 4059
		err = chan->ops->recv(chan->data, skb);
		break;
4060

4061
	case L2CAP_SAR_START:
4062 4063
		if (chan->sdu)
			break;
4064

4065
		chan->sdu_len = get_unaligned_le16(skb->data);
4066
		skb_pull(skb, L2CAP_SDULEN_SIZE);
4067

4068 4069 4070 4071
		if (chan->sdu_len > chan->imtu) {
			err = -EMSGSIZE;
			break;
		}
4072

4073 4074
		if (skb->len >= chan->sdu_len)
			break;
4075

4076 4077
		chan->sdu = skb;
		chan->sdu_last_frag = skb;
4078

4079 4080
		skb = NULL;
		err = 0;
4081 4082
		break;

4083
	case L2CAP_SAR_CONTINUE:
4084
		if (!chan->sdu)
4085
			break;
4086

4087 4088 4089
		append_skb_frag(chan->sdu, skb,
				&chan->sdu_last_frag);
		skb = NULL;
4090

4091 4092
		if (chan->sdu->len >= chan->sdu_len)
			break;
4093

4094
		err = 0;
4095 4096
		break;

4097
	case L2CAP_SAR_END:
4098
		if (!chan->sdu)
4099
			break;
4100

4101 4102 4103
		append_skb_frag(chan->sdu, skb,
				&chan->sdu_last_frag);
		skb = NULL;
4104

4105 4106
		if (chan->sdu->len != chan->sdu_len)
			break;
4107

4108
		err = chan->ops->recv(chan->data, chan->sdu);
4109

4110 4111 4112 4113 4114
		if (!err) {
			/* Reassembly complete */
			chan->sdu = NULL;
			chan->sdu_last_frag = NULL;
			chan->sdu_len = 0;
4115
		}
4116 4117 4118
		break;
	}

4119 4120 4121 4122 4123 4124 4125
	if (err) {
		kfree_skb(skb);
		kfree_skb(chan->sdu);
		chan->sdu = NULL;
		chan->sdu_last_frag = NULL;
		chan->sdu_len = 0;
	}
4126

4127
	return err;
4128 4129
}

4130
static void l2cap_ertm_enter_local_busy(struct l2cap_chan *chan)
4131
{
4132
	BT_DBG("chan %p, Enter local busy", chan);
4133

4134
	set_bit(CONN_LOCAL_BUSY, &chan->conn_state);
4135
	l2cap_seq_list_clear(&chan->srej_list);
4136

4137
	__set_ack_timer(chan);
4138 4139 4140 4141
}

static void l2cap_ertm_exit_local_busy(struct l2cap_chan *chan)
{
4142
	u32 control;
4143

4144
	if (!test_bit(CONN_RNR_SENT, &chan->conn_state))
4145 4146
		goto done;

4147
	control = __set_reqseq(chan, chan->buffer_seq);
4148
	control |= __set_ctrl_poll(chan);
4149
	control |= __set_ctrl_super(chan, L2CAP_SUPER_RR);
4150
	l2cap_send_sframe(chan, control);
4151
	chan->retry_count = 1;
4152

4153 4154
	__clear_retrans_timer(chan);
	__set_monitor_timer(chan);
4155

4156
	set_bit(CONN_WAIT_F, &chan->conn_state);
4157 4158

done:
4159 4160
	clear_bit(CONN_LOCAL_BUSY, &chan->conn_state);
	clear_bit(CONN_RNR_SENT, &chan->conn_state);
4161

4162
	BT_DBG("chan %p, Exit local busy", chan);
4163 4164
}

4165
void l2cap_chan_busy(struct l2cap_chan *chan, int busy)
4166
{
4167 4168 4169 4170 4171
	if (chan->mode == L2CAP_MODE_ERTM) {
		if (busy)
			l2cap_ertm_enter_local_busy(chan);
		else
			l2cap_ertm_exit_local_busy(chan);
4172 4173 4174
	}
}

4175
static void l2cap_check_srej_gap(struct l2cap_chan *chan, u16 tx_seq)
4176 4177
{
	struct sk_buff *skb;
4178
	u32 control;
4179

4180 4181 4182 4183
	while ((skb = skb_peek(&chan->srej_q)) &&
			!test_bit(CONN_LOCAL_BUSY, &chan->conn_state)) {
		int err;

4184
		if (bt_cb(skb)->control.txseq != tx_seq)
4185 4186
			break;

4187
		skb = skb_dequeue(&chan->srej_q);
4188
		control = __set_ctrl_sar(chan, bt_cb(skb)->control.sar);
4189
		err = l2cap_reassemble_sdu(chan, skb, control);
4190 4191 4192 4193 4194 4195

		if (err < 0) {
			l2cap_send_disconn_req(chan->conn, chan, ECONNRESET);
			break;
		}

4196 4197
		chan->buffer_seq_srej = __next_seq(chan, chan->buffer_seq_srej);
		tx_seq = __next_seq(chan, tx_seq);
4198 4199 4200
	}
}

4201
static void l2cap_resend_srejframe(struct l2cap_chan *chan, u16 tx_seq)
4202 4203
{
	struct srej_list *l, *tmp;
4204
	u32 control;
4205

4206
	list_for_each_entry_safe(l, tmp, &chan->srej_l, list) {
4207 4208 4209 4210 4211
		if (l->tx_seq == tx_seq) {
			list_del(&l->list);
			kfree(l);
			return;
		}
4212
		control = __set_ctrl_super(chan, L2CAP_SUPER_SREJ);
4213
		control |= __set_reqseq(chan, l->tx_seq);
4214
		l2cap_send_sframe(chan, control);
4215
		list_del(&l->list);
4216
		list_add_tail(&l->list, &chan->srej_l);
4217 4218 4219
	}
}

4220
static int l2cap_send_srejframe(struct l2cap_chan *chan, u16 tx_seq)
4221 4222
{
	struct srej_list *new;
4223
	u32 control;
4224

4225
	while (tx_seq != chan->expected_tx_seq) {
4226
		control = __set_ctrl_super(chan, L2CAP_SUPER_SREJ);
4227
		control |= __set_reqseq(chan, chan->expected_tx_seq);
4228
		l2cap_seq_list_append(&chan->srej_list, chan->expected_tx_seq);
4229
		l2cap_send_sframe(chan, control);
4230 4231

		new = kzalloc(sizeof(struct srej_list), GFP_ATOMIC);
4232 4233 4234
		if (!new)
			return -ENOMEM;

4235
		new->tx_seq = chan->expected_tx_seq;
4236 4237 4238

		chan->expected_tx_seq = __next_seq(chan, chan->expected_tx_seq);

4239
		list_add_tail(&new->list, &chan->srej_l);
4240
	}
4241 4242

	chan->expected_tx_seq = __next_seq(chan, chan->expected_tx_seq);
4243 4244

	return 0;
4245 4246
}

4247
static inline int l2cap_data_channel_iframe(struct l2cap_chan *chan, u32 rx_control, struct sk_buff *skb)
4248
{
4249
	u16 tx_seq = __get_txseq(chan, rx_control);
4250
	u16 req_seq = __get_reqseq(chan, rx_control);
4251
	u8 sar = __get_ctrl_sar(chan, rx_control);
4252
	int tx_seq_offset, expected_tx_seq_offset;
4253
	int num_to_ack = (chan->tx_win/6) + 1;
4254 4255
	int err = 0;

4256
	BT_DBG("chan %p len %d tx_seq %d rx_control 0x%8.8x", chan, skb->len,
4257
							tx_seq, rx_control);
4258

4259
	if (__is_ctrl_final(chan, rx_control) &&
4260
			test_bit(CONN_WAIT_F, &chan->conn_state)) {
4261
		__clear_monitor_timer(chan);
4262
		if (chan->unacked_frames > 0)
4263
			__set_retrans_timer(chan);
4264
		clear_bit(CONN_WAIT_F, &chan->conn_state);
4265 4266
	}

4267 4268
	chan->expected_ack_seq = req_seq;
	l2cap_drop_acked_frames(chan);
4269

4270
	tx_seq_offset = __seq_offset(chan, tx_seq, chan->buffer_seq);
4271 4272

	/* invalid tx_seq */
4273
	if (tx_seq_offset >= chan->tx_win) {
4274
		l2cap_send_disconn_req(chan->conn, chan, ECONNRESET);
4275 4276 4277
		goto drop;
	}

4278 4279 4280
	if (test_bit(CONN_LOCAL_BUSY, &chan->conn_state)) {
		if (!test_bit(CONN_RNR_SENT, &chan->conn_state))
			l2cap_send_ack(chan);
4281
		goto drop;
4282
	}
4283

4284 4285 4286
	if (tx_seq == chan->expected_tx_seq)
		goto expected;

4287
	if (test_bit(CONN_SREJ_SENT, &chan->conn_state)) {
4288
		struct srej_list *first;
4289

4290
		first = list_first_entry(&chan->srej_l,
4291 4292
				struct srej_list, list);
		if (tx_seq == first->tx_seq) {
4293
			l2cap_add_to_srej_queue(chan, skb, tx_seq, sar);
4294
			l2cap_check_srej_gap(chan, tx_seq);
4295 4296 4297 4298

			list_del(&first->list);
			kfree(first);

4299
			if (list_empty(&chan->srej_l)) {
4300
				chan->buffer_seq = chan->buffer_seq_srej;
4301
				clear_bit(CONN_SREJ_SENT, &chan->conn_state);
4302
				l2cap_send_ack(chan);
4303
				BT_DBG("chan %p, Exit SREJ_SENT", chan);
4304 4305 4306
			}
		} else {
			struct srej_list *l;
4307 4308

			/* duplicated tx_seq */
4309
			if (l2cap_add_to_srej_queue(chan, skb, tx_seq, sar) < 0)
4310
				goto drop;
4311

4312
			list_for_each_entry(l, &chan->srej_l, list) {
4313
				if (l->tx_seq == tx_seq) {
4314
					l2cap_resend_srejframe(chan, tx_seq);
4315 4316 4317
					return 0;
				}
			}
4318 4319 4320 4321 4322 4323

			err = l2cap_send_srejframe(chan, tx_seq);
			if (err < 0) {
				l2cap_send_disconn_req(chan->conn, chan, -err);
				return err;
			}
4324 4325
		}
	} else {
4326 4327
		expected_tx_seq_offset = __seq_offset(chan,
				chan->expected_tx_seq, chan->buffer_seq);
4328 4329 4330 4331 4332

		/* duplicated tx_seq */
		if (tx_seq_offset < expected_tx_seq_offset)
			goto drop;

4333
		set_bit(CONN_SREJ_SENT, &chan->conn_state);
4334

4335
		BT_DBG("chan %p, Enter SREJ", chan);
4336

4337
		INIT_LIST_HEAD(&chan->srej_l);
4338
		chan->buffer_seq_srej = chan->buffer_seq;
4339

4340
		__skb_queue_head_init(&chan->srej_q);
4341
		l2cap_add_to_srej_queue(chan, skb, tx_seq, sar);
4342

4343 4344 4345
		/* Set P-bit only if there are some I-frames to ack. */
		if (__clear_ack_timer(chan))
			set_bit(CONN_SEND_PBIT, &chan->conn_state);
4346

4347 4348 4349 4350 4351
		err = l2cap_send_srejframe(chan, tx_seq);
		if (err < 0) {
			l2cap_send_disconn_req(chan->conn, chan, -err);
			return err;
		}
4352
	}
4353 4354
	return 0;

4355
expected:
4356
	chan->expected_tx_seq = __next_seq(chan, chan->expected_tx_seq);
4357

4358
	if (test_bit(CONN_SREJ_SENT, &chan->conn_state)) {
4359 4360
		bt_cb(skb)->control.txseq = tx_seq;
		bt_cb(skb)->control.sar = sar;
4361
		__skb_queue_tail(&chan->srej_q, skb);
4362 4363 4364
		return 0;
	}

4365
	err = l2cap_reassemble_sdu(chan, skb, rx_control);
4366 4367
	chan->buffer_seq = __next_seq(chan, chan->buffer_seq);

4368 4369 4370 4371
	if (err < 0) {
		l2cap_send_disconn_req(chan->conn, chan, ECONNRESET);
		return err;
	}
4372

4373
	if (__is_ctrl_final(chan, rx_control)) {
4374
		if (!test_and_clear_bit(CONN_REJ_ACT, &chan->conn_state))
4375
			l2cap_retransmit_frames(chan);
4376 4377
	}

4378

4379 4380
	chan->num_acked = (chan->num_acked + 1) % num_to_ack;
	if (chan->num_acked == num_to_ack - 1)
4381
		l2cap_send_ack(chan);
4382 4383
	else
		__set_ack_timer(chan);
4384

4385
	return 0;
4386 4387 4388 4389

drop:
	kfree_skb(skb);
	return 0;
4390 4391
}

4392
static inline void l2cap_data_channel_rrframe(struct l2cap_chan *chan, u32 rx_control)
4393
{
4394
	BT_DBG("chan %p, req_seq %d ctrl 0x%8.8x", chan,
4395
				__get_reqseq(chan, rx_control), rx_control);
4396

4397
	chan->expected_ack_seq = __get_reqseq(chan, rx_control);
4398
	l2cap_drop_acked_frames(chan);
4399

4400
	if (__is_ctrl_poll(chan, rx_control)) {
4401 4402 4403
		set_bit(CONN_SEND_FBIT, &chan->conn_state);
		if (test_bit(CONN_SREJ_SENT, &chan->conn_state)) {
			if (test_bit(CONN_REMOTE_BUSY, &chan->conn_state) &&
4404
					(chan->unacked_frames > 0))
4405
				__set_retrans_timer(chan);
4406

4407
			clear_bit(CONN_REMOTE_BUSY, &chan->conn_state);
4408
			l2cap_send_srejtail(chan);
4409
		} else {
4410
			l2cap_send_i_or_rr_or_rnr(chan);
4411
		}
4412

4413
	} else if (__is_ctrl_final(chan, rx_control)) {
4414
		clear_bit(CONN_REMOTE_BUSY, &chan->conn_state);
4415

4416
		if (!test_and_clear_bit(CONN_REJ_ACT, &chan->conn_state))
4417
			l2cap_retransmit_frames(chan);
4418

4419
	} else {
4420
		if (test_bit(CONN_REMOTE_BUSY, &chan->conn_state) &&
4421
				(chan->unacked_frames > 0))
4422
			__set_retrans_timer(chan);
4423

4424 4425
		clear_bit(CONN_REMOTE_BUSY, &chan->conn_state);
		if (test_bit(CONN_SREJ_SENT, &chan->conn_state))
4426
			l2cap_send_ack(chan);
4427
		else
4428
			l2cap_ertm_send(chan);
4429 4430
	}
}
4431

4432
static inline void l2cap_data_channel_rejframe(struct l2cap_chan *chan, u32 rx_control)
4433
{
4434
	u16 tx_seq = __get_reqseq(chan, rx_control);
4435

4436
	BT_DBG("chan %p, req_seq %d ctrl 0x%8.8x", chan, tx_seq, rx_control);
4437

4438
	clear_bit(CONN_REMOTE_BUSY, &chan->conn_state);
4439

4440 4441
	chan->expected_ack_seq = tx_seq;
	l2cap_drop_acked_frames(chan);
4442

4443
	if (__is_ctrl_final(chan, rx_control)) {
4444
		if (!test_and_clear_bit(CONN_REJ_ACT, &chan->conn_state))
4445
			l2cap_retransmit_frames(chan);
4446
	} else {
4447
		l2cap_retransmit_frames(chan);
4448

4449 4450
		if (test_bit(CONN_WAIT_F, &chan->conn_state))
			set_bit(CONN_REJ_ACT, &chan->conn_state);
4451 4452
	}
}
4453
static inline void l2cap_data_channel_srejframe(struct l2cap_chan *chan, u32 rx_control)
4454
{
4455
	u16 tx_seq = __get_reqseq(chan, rx_control);
4456

4457
	BT_DBG("chan %p, req_seq %d ctrl 0x%8.8x", chan, tx_seq, rx_control);
4458

4459
	clear_bit(CONN_REMOTE_BUSY, &chan->conn_state);
4460

4461
	if (__is_ctrl_poll(chan, rx_control)) {
4462 4463
		chan->expected_ack_seq = tx_seq;
		l2cap_drop_acked_frames(chan);
4464

4465
		set_bit(CONN_SEND_FBIT, &chan->conn_state);
4466
		l2cap_retransmit_one_frame(chan, tx_seq);
4467

4468
		l2cap_ertm_send(chan);
4469

4470
		if (test_bit(CONN_WAIT_F, &chan->conn_state)) {
4471
			chan->srej_save_reqseq = tx_seq;
4472
			set_bit(CONN_SREJ_ACT, &chan->conn_state);
4473
		}
4474
	} else if (__is_ctrl_final(chan, rx_control)) {
4475
		if (test_bit(CONN_SREJ_ACT, &chan->conn_state) &&
4476
				chan->srej_save_reqseq == tx_seq)
4477
			clear_bit(CONN_SREJ_ACT, &chan->conn_state);
4478
		else
4479
			l2cap_retransmit_one_frame(chan, tx_seq);
4480
	} else {
4481
		l2cap_retransmit_one_frame(chan, tx_seq);
4482
		if (test_bit(CONN_WAIT_F, &chan->conn_state)) {
4483
			chan->srej_save_reqseq = tx_seq;
4484
			set_bit(CONN_SREJ_ACT, &chan->conn_state);
4485
		}
4486 4487 4488
	}
}

4489
static inline void l2cap_data_channel_rnrframe(struct l2cap_chan *chan, u32 rx_control)
4490
{
4491
	u16 tx_seq = __get_reqseq(chan, rx_control);
4492

4493
	BT_DBG("chan %p, req_seq %d ctrl 0x%8.8x", chan, tx_seq, rx_control);
4494

4495
	set_bit(CONN_REMOTE_BUSY, &chan->conn_state);
4496 4497
	chan->expected_ack_seq = tx_seq;
	l2cap_drop_acked_frames(chan);
4498

4499
	if (__is_ctrl_poll(chan, rx_control))
4500
		set_bit(CONN_SEND_FBIT, &chan->conn_state);
4501

4502
	if (!test_bit(CONN_SREJ_SENT, &chan->conn_state)) {
4503
		__clear_retrans_timer(chan);
4504
		if (__is_ctrl_poll(chan, rx_control))
4505
			l2cap_send_rr_or_rnr(chan, L2CAP_CTRL_FINAL);
4506
		return;
4507
	}
4508

4509
	if (__is_ctrl_poll(chan, rx_control)) {
4510
		l2cap_send_srejtail(chan);
4511 4512 4513 4514
	} else {
		rx_control = __set_ctrl_super(chan, L2CAP_SUPER_RR);
		l2cap_send_sframe(chan, rx_control);
	}
4515 4516
}

4517
static inline int l2cap_data_channel_sframe(struct l2cap_chan *chan, u32 rx_control, struct sk_buff *skb)
4518
{
4519
	BT_DBG("chan %p rx_control 0x%8.8x len %d", chan, rx_control, skb->len);
4520

4521
	if (__is_ctrl_final(chan, rx_control) &&
4522
			test_bit(CONN_WAIT_F, &chan->conn_state)) {
4523
		__clear_monitor_timer(chan);
4524
		if (chan->unacked_frames > 0)
4525
			__set_retrans_timer(chan);
4526
		clear_bit(CONN_WAIT_F, &chan->conn_state);
4527 4528
	}

4529 4530
	switch (__get_ctrl_super(chan, rx_control)) {
	case L2CAP_SUPER_RR:
4531
		l2cap_data_channel_rrframe(chan, rx_control);
4532 4533
		break;

4534
	case L2CAP_SUPER_REJ:
4535
		l2cap_data_channel_rejframe(chan, rx_control);
4536
		break;
4537

4538
	case L2CAP_SUPER_SREJ:
4539
		l2cap_data_channel_srejframe(chan, rx_control);
4540 4541
		break;

4542
	case L2CAP_SUPER_RNR:
4543
		l2cap_data_channel_rnrframe(chan, rx_control);
4544 4545 4546
		break;
	}

4547
	kfree_skb(skb);
4548 4549 4550
	return 0;
}

4551
static int l2cap_ertm_data_rcv(struct l2cap_chan *chan, struct sk_buff *skb)
4552
{
4553
	u32 control;
4554
	u16 req_seq;
4555 4556
	int len, next_tx_seq_offset, req_seq_offset;

4557 4558
	__unpack_control(chan, skb);

4559 4560
	control = __get_control(chan, skb->data);
	skb_pull(skb, __ctrl_size(chan));
4561 4562 4563 4564 4565 4566 4567
	len = skb->len;

	/*
	 * We can just drop the corrupted I-frame here.
	 * Receiver will miss it and start proper recovery
	 * procedures and ask retransmission.
	 */
4568
	if (l2cap_check_fcs(chan, skb))
4569 4570
		goto drop;

4571
	if (__is_sar_start(chan, control) && !__is_sframe(chan, control))
4572
		len -= L2CAP_SDULEN_SIZE;
4573

4574
	if (chan->fcs == L2CAP_FCS_CRC16)
4575
		len -= L2CAP_FCS_SIZE;
4576

4577
	if (len > chan->mps) {
4578
		l2cap_send_disconn_req(chan->conn, chan, ECONNRESET);
4579 4580 4581
		goto drop;
	}

4582
	req_seq = __get_reqseq(chan, control);
4583

4584 4585 4586 4587
	req_seq_offset = __seq_offset(chan, req_seq, chan->expected_ack_seq);

	next_tx_seq_offset = __seq_offset(chan, chan->next_tx_seq,
						chan->expected_ack_seq);
4588 4589 4590

	/* check for invalid req-seq */
	if (req_seq_offset > next_tx_seq_offset) {
4591
		l2cap_send_disconn_req(chan->conn, chan, ECONNRESET);
4592 4593 4594
		goto drop;
	}

4595
	if (!__is_sframe(chan, control)) {
4596
		if (len < 0) {
4597
			l2cap_send_disconn_req(chan->conn, chan, ECONNRESET);
4598 4599 4600
			goto drop;
		}

4601
		l2cap_data_channel_iframe(chan, control, skb);
4602 4603 4604
	} else {
		if (len != 0) {
			BT_ERR("%d", len);
4605
			l2cap_send_disconn_req(chan->conn, chan, ECONNRESET);
4606 4607 4608
			goto drop;
		}

4609
		l2cap_data_channel_sframe(chan, control, skb);
4610 4611 4612 4613 4614 4615 4616 4617 4618
	}

	return 0;

drop:
	kfree_skb(skb);
	return 0;
}

L
Linus Torvalds 已提交
4619 4620
static inline int l2cap_data_channel(struct l2cap_conn *conn, u16 cid, struct sk_buff *skb)
{
4621
	struct l2cap_chan *chan;
4622
	u32 control;
4623
	u16 tx_seq;
4624
	int len;
L
Linus Torvalds 已提交
4625

4626
	chan = l2cap_get_chan_by_scid(conn, cid);
4627
	if (!chan) {
L
Linus Torvalds 已提交
4628
		BT_DBG("unknown cid 0x%4.4x", cid);
4629
		/* Drop packet and return */
4630
		kfree_skb(skb);
4631
		return 0;
L
Linus Torvalds 已提交
4632 4633
	}

4634
	l2cap_chan_lock(chan);
4635

4636
	BT_DBG("chan %p, len %d", chan, skb->len);
L
Linus Torvalds 已提交
4637

4638
	if (chan->state != BT_CONNECTED)
L
Linus Torvalds 已提交
4639 4640
		goto drop;

4641
	switch (chan->mode) {
4642 4643 4644 4645 4646
	case L2CAP_MODE_BASIC:
		/* If socket recv buffers overflows we drop data here
		 * which is *bad* because L2CAP has to be reliable.
		 * But we don't have any other choice. L2CAP doesn't
		 * provide flow control mechanism. */
L
Linus Torvalds 已提交
4647

4648
		if (chan->imtu < skb->len)
4649
			goto drop;
L
Linus Torvalds 已提交
4650

4651
		if (!chan->ops->recv(chan->data, skb))
4652 4653 4654 4655
			goto done;
		break;

	case L2CAP_MODE_ERTM:
4656
		l2cap_ertm_data_rcv(chan, skb);
4657

4658
		goto done;
4659

4660
	case L2CAP_MODE_STREAMING:
4661 4662
		control = __get_control(chan, skb->data);
		skb_pull(skb, __ctrl_size(chan));
4663 4664
		len = skb->len;

4665
		if (l2cap_check_fcs(chan, skb))
4666 4667
			goto drop;

4668
		if (__is_sar_start(chan, control))
4669
			len -= L2CAP_SDULEN_SIZE;
4670

4671
		if (chan->fcs == L2CAP_FCS_CRC16)
4672
			len -= L2CAP_FCS_SIZE;
4673

4674
		if (len > chan->mps || len < 0 || __is_sframe(chan, control))
4675 4676
			goto drop;

4677
		tx_seq = __get_txseq(chan, control);
4678

4679 4680 4681 4682 4683 4684
		if (chan->expected_tx_seq != tx_seq) {
			/* Frame(s) missing - must discard partial SDU */
			kfree_skb(chan->sdu);
			chan->sdu = NULL;
			chan->sdu_last_frag = NULL;
			chan->sdu_len = 0;
4685

4686 4687 4688
			/* TODO: Notify userland of missing data */
		}

4689
		chan->expected_tx_seq = __next_seq(chan, tx_seq);
4690 4691 4692

		if (l2cap_reassemble_sdu(chan, skb, control) == -EMSGSIZE)
			l2cap_send_disconn_req(chan->conn, chan, ECONNRESET);
4693 4694 4695

		goto done;

4696
	default:
4697
		BT_DBG("chan %p: bad mode 0x%2.2x", chan, chan->mode);
4698 4699
		break;
	}
L
Linus Torvalds 已提交
4700 4701 4702 4703 4704

drop:
	kfree_skb(skb);

done:
4705
	l2cap_chan_unlock(chan);
4706

L
Linus Torvalds 已提交
4707 4708 4709
	return 0;
}

4710
static inline int l2cap_conless_channel(struct l2cap_conn *conn, __le16 psm, struct sk_buff *skb)
L
Linus Torvalds 已提交
4711
{
4712
	struct l2cap_chan *chan;
L
Linus Torvalds 已提交
4713

4714
	chan = l2cap_global_chan_by_psm(0, psm, conn->src, conn->dst);
4715
	if (!chan)
L
Linus Torvalds 已提交
4716 4717
		goto drop;

4718
	BT_DBG("chan %p, len %d", chan, skb->len);
L
Linus Torvalds 已提交
4719

4720
	if (chan->state != BT_BOUND && chan->state != BT_CONNECTED)
L
Linus Torvalds 已提交
4721 4722
		goto drop;

4723
	if (chan->imtu < skb->len)
L
Linus Torvalds 已提交
4724 4725
		goto drop;

4726
	if (!chan->ops->recv(chan->data, skb))
4727
		return 0;
L
Linus Torvalds 已提交
4728 4729 4730 4731 4732 4733 4734

drop:
	kfree_skb(skb);

	return 0;
}

4735 4736
static inline int l2cap_att_channel(struct l2cap_conn *conn, u16 cid,
				    struct sk_buff *skb)
4737
{
4738
	struct l2cap_chan *chan;
4739

4740
	chan = l2cap_global_chan_by_scid(0, cid, conn->src, conn->dst);
4741
	if (!chan)
4742 4743
		goto drop;

4744
	BT_DBG("chan %p, len %d", chan, skb->len);
4745

4746
	if (chan->state != BT_BOUND && chan->state != BT_CONNECTED)
4747 4748
		goto drop;

4749
	if (chan->imtu < skb->len)
4750 4751
		goto drop;

4752
	if (!chan->ops->recv(chan->data, skb))
4753
		return 0;
4754 4755 4756 4757 4758 4759 4760

drop:
	kfree_skb(skb);

	return 0;
}

L
Linus Torvalds 已提交
4761 4762 4763
static void l2cap_recv_frame(struct l2cap_conn *conn, struct sk_buff *skb)
{
	struct l2cap_hdr *lh = (void *) skb->data;
4764 4765
	u16 cid, len;
	__le16 psm;
L
Linus Torvalds 已提交
4766 4767 4768 4769 4770

	skb_pull(skb, L2CAP_HDR_SIZE);
	cid = __le16_to_cpu(lh->cid);
	len = __le16_to_cpu(lh->len);

4771 4772 4773 4774 4775
	if (len != skb->len) {
		kfree_skb(skb);
		return;
	}

L
Linus Torvalds 已提交
4776 4777 4778
	BT_DBG("len %d, cid 0x%4.4x", len, cid);

	switch (cid) {
4779
	case L2CAP_CID_LE_SIGNALING:
4780
	case L2CAP_CID_SIGNALING:
L
Linus Torvalds 已提交
4781 4782 4783
		l2cap_sig_channel(conn, skb);
		break;

4784
	case L2CAP_CID_CONN_LESS:
4785
		psm = get_unaligned((__le16 *) skb->data);
L
Linus Torvalds 已提交
4786 4787 4788 4789
		skb_pull(skb, 2);
		l2cap_conless_channel(conn, psm, skb);
		break;

4790 4791 4792 4793
	case L2CAP_CID_LE_DATA:
		l2cap_att_channel(conn, cid, skb);
		break;

4794 4795 4796 4797 4798
	case L2CAP_CID_SMP:
		if (smp_sig_channel(conn, skb))
			l2cap_conn_del(conn->hcon, EACCES);
		break;

L
Linus Torvalds 已提交
4799 4800 4801 4802 4803 4804 4805 4806
	default:
		l2cap_data_channel(conn, cid, skb);
		break;
	}
}

/* ---- L2CAP interface with lower layer (HCI) ---- */

4807
int l2cap_connect_ind(struct hci_dev *hdev, bdaddr_t *bdaddr)
L
Linus Torvalds 已提交
4808 4809
{
	int exact = 0, lm1 = 0, lm2 = 0;
4810
	struct l2cap_chan *c;
L
Linus Torvalds 已提交
4811 4812 4813 4814

	BT_DBG("hdev %s, bdaddr %s", hdev->name, batostr(bdaddr));

	/* Find listening sockets and check their link_mode */
4815 4816 4817
	read_lock(&chan_list_lock);
	list_for_each_entry(c, &chan_list, global_l) {
		struct sock *sk = c->sk;
4818

4819
		if (c->state != BT_LISTEN)
L
Linus Torvalds 已提交
4820 4821 4822
			continue;

		if (!bacmp(&bt_sk(sk)->src, &hdev->bdaddr)) {
4823
			lm1 |= HCI_LM_ACCEPT;
4824
			if (test_bit(FLAG_ROLE_SWITCH, &c->flags))
4825
				lm1 |= HCI_LM_MASTER;
L
Linus Torvalds 已提交
4826
			exact++;
4827 4828
		} else if (!bacmp(&bt_sk(sk)->src, BDADDR_ANY)) {
			lm2 |= HCI_LM_ACCEPT;
4829
			if (test_bit(FLAG_ROLE_SWITCH, &c->flags))
4830 4831
				lm2 |= HCI_LM_MASTER;
		}
L
Linus Torvalds 已提交
4832
	}
4833
	read_unlock(&chan_list_lock);
L
Linus Torvalds 已提交
4834 4835 4836 4837

	return exact ? lm1 : lm2;
}

4838
int l2cap_connect_cfm(struct hci_conn *hcon, u8 status)
L
Linus Torvalds 已提交
4839
{
4840 4841
	struct l2cap_conn *conn;

L
Linus Torvalds 已提交
4842 4843 4844 4845 4846 4847
	BT_DBG("hcon %p bdaddr %s status %d", hcon, batostr(&hcon->dst), status);

	if (!status) {
		conn = l2cap_conn_add(hcon, status);
		if (conn)
			l2cap_conn_ready(conn);
4848
	} else
4849
		l2cap_conn_del(hcon, bt_to_errno(status));
L
Linus Torvalds 已提交
4850 4851 4852 4853

	return 0;
}

4854
int l2cap_disconn_ind(struct hci_conn *hcon)
4855 4856 4857 4858 4859
{
	struct l2cap_conn *conn = hcon->l2cap_data;

	BT_DBG("hcon %p", hcon);

4860
	if (!conn)
4861
		return HCI_ERROR_REMOTE_USER_TERM;
4862 4863 4864
	return conn->disc_reason;
}

4865
int l2cap_disconn_cfm(struct hci_conn *hcon, u8 reason)
L
Linus Torvalds 已提交
4866 4867 4868
{
	BT_DBG("hcon %p reason %d", hcon, reason);

4869
	l2cap_conn_del(hcon, bt_to_errno(reason));
L
Linus Torvalds 已提交
4870 4871 4872
	return 0;
}

4873
static inline void l2cap_check_encryption(struct l2cap_chan *chan, u8 encrypt)
4874
{
4875
	if (chan->chan_type != L2CAP_CHAN_CONN_ORIENTED)
4876 4877
		return;

4878
	if (encrypt == 0x00) {
4879
		if (chan->sec_level == BT_SECURITY_MEDIUM) {
4880
			__set_chan_timer(chan, L2CAP_ENC_TIMEOUT);
4881
		} else if (chan->sec_level == BT_SECURITY_HIGH)
4882
			l2cap_chan_close(chan, ECONNREFUSED);
4883
	} else {
4884
		if (chan->sec_level == BT_SECURITY_MEDIUM)
4885
			__clear_chan_timer(chan);
4886 4887 4888
	}
}

4889
int l2cap_security_cfm(struct hci_conn *hcon, u8 status, u8 encrypt)
L
Linus Torvalds 已提交
4890
{
4891
	struct l2cap_conn *conn = hcon->l2cap_data;
4892
	struct l2cap_chan *chan;
L
Linus Torvalds 已提交
4893

4894
	if (!conn)
L
Linus Torvalds 已提交
4895
		return 0;
4896

L
Linus Torvalds 已提交
4897 4898
	BT_DBG("conn %p", conn);

4899
	if (hcon->type == LE_LINK) {
4900 4901
		if (!status && encrypt)
			smp_distribute_keys(conn, 0);
4902
		cancel_delayed_work(&conn->security_timer);
4903 4904
	}

4905
	mutex_lock(&conn->chan_lock);
L
Linus Torvalds 已提交
4906

4907
	list_for_each_entry(chan, &conn->chan_l, list) {
4908
		l2cap_chan_lock(chan);
L
Linus Torvalds 已提交
4909

4910 4911 4912 4913 4914
		BT_DBG("chan->scid %d", chan->scid);

		if (chan->scid == L2CAP_CID_LE_DATA) {
			if (!status && encrypt) {
				chan->sec_level = hcon->sec_level;
4915
				l2cap_chan_ready(chan);
4916 4917
			}

4918
			l2cap_chan_unlock(chan);
4919 4920 4921
			continue;
		}

4922
		if (test_bit(CONF_CONNECT_PEND, &chan->conf_state)) {
4923
			l2cap_chan_unlock(chan);
4924 4925 4926
			continue;
		}

4927 4928
		if (!status && (chan->state == BT_CONNECTED ||
						chan->state == BT_CONFIG)) {
4929 4930 4931 4932 4933
			struct sock *sk = chan->sk;

			bt_sk(sk)->suspended = false;
			sk->sk_state_change(sk);

4934
			l2cap_check_encryption(chan, encrypt);
4935
			l2cap_chan_unlock(chan);
4936 4937 4938
			continue;
		}

4939
		if (chan->state == BT_CONNECT) {
4940
			if (!status) {
4941
				l2cap_send_conn_req(chan);
4942
			} else {
4943
				__set_chan_timer(chan, L2CAP_DISC_TIMEOUT);
4944
			}
4945
		} else if (chan->state == BT_CONNECT2) {
4946
			struct sock *sk = chan->sk;
4947
			struct l2cap_conn_rsp rsp;
4948
			__u16 res, stat;
L
Linus Torvalds 已提交
4949

4950 4951
			lock_sock(sk);

4952
			if (!status) {
4953 4954 4955 4956
				if (bt_sk(sk)->defer_setup) {
					struct sock *parent = bt_sk(sk)->parent;
					res = L2CAP_CR_PEND;
					stat = L2CAP_CS_AUTHOR_PEND;
4957 4958
					if (parent)
						parent->sk_data_ready(parent, 0);
4959
				} else {
4960
					__l2cap_state_change(chan, BT_CONFIG);
4961 4962 4963
					res = L2CAP_CR_SUCCESS;
					stat = L2CAP_CS_NO_INFO;
				}
4964
			} else {
4965
				__l2cap_state_change(chan, BT_DISCONN);
4966
				__set_chan_timer(chan, L2CAP_DISC_TIMEOUT);
4967 4968
				res = L2CAP_CR_SEC_BLOCK;
				stat = L2CAP_CS_NO_INFO;
4969 4970
			}

4971 4972
			release_sock(sk);

4973 4974
			rsp.scid   = cpu_to_le16(chan->dcid);
			rsp.dcid   = cpu_to_le16(chan->scid);
4975 4976
			rsp.result = cpu_to_le16(res);
			rsp.status = cpu_to_le16(stat);
4977 4978
			l2cap_send_cmd(conn, chan->ident, L2CAP_CONN_RSP,
							sizeof(rsp), &rsp);
4979
		}
L
Linus Torvalds 已提交
4980

4981
		l2cap_chan_unlock(chan);
L
Linus Torvalds 已提交
4982 4983
	}

4984
	mutex_unlock(&conn->chan_lock);
4985

L
Linus Torvalds 已提交
4986 4987 4988
	return 0;
}

4989
int l2cap_recv_acldata(struct hci_conn *hcon, struct sk_buff *skb, u16 flags)
L
Linus Torvalds 已提交
4990 4991 4992
{
	struct l2cap_conn *conn = hcon->l2cap_data;

4993 4994 4995 4996
	if (!conn)
		conn = l2cap_conn_add(hcon, 0);

	if (!conn)
L
Linus Torvalds 已提交
4997 4998 4999 5000
		goto drop;

	BT_DBG("conn %p len %d flags 0x%x", conn, skb->len, flags);

5001
	if (!(flags & ACL_CONT)) {
L
Linus Torvalds 已提交
5002 5003 5004 5005 5006 5007 5008 5009 5010 5011 5012
		struct l2cap_hdr *hdr;
		int len;

		if (conn->rx_len) {
			BT_ERR("Unexpected start frame (len %d)", skb->len);
			kfree_skb(conn->rx_skb);
			conn->rx_skb = NULL;
			conn->rx_len = 0;
			l2cap_conn_unreliable(conn, ECOMM);
		}

5013 5014
		/* Start fragment always begin with Basic L2CAP header */
		if (skb->len < L2CAP_HDR_SIZE) {
L
Linus Torvalds 已提交
5015 5016 5017 5018 5019 5020 5021 5022 5023 5024 5025 5026 5027 5028 5029 5030 5031 5032 5033 5034 5035 5036 5037 5038
			BT_ERR("Frame is too short (len %d)", skb->len);
			l2cap_conn_unreliable(conn, ECOMM);
			goto drop;
		}

		hdr = (struct l2cap_hdr *) skb->data;
		len = __le16_to_cpu(hdr->len) + L2CAP_HDR_SIZE;

		if (len == skb->len) {
			/* Complete frame received */
			l2cap_recv_frame(conn, skb);
			return 0;
		}

		BT_DBG("Start: total len %d, frag len %d", len, skb->len);

		if (skb->len > len) {
			BT_ERR("Frame is too long (len %d, expected len %d)",
				skb->len, len);
			l2cap_conn_unreliable(conn, ECOMM);
			goto drop;
		}

		/* Allocate skb for the complete frame (with header) */
5039 5040
		conn->rx_skb = bt_skb_alloc(len, GFP_ATOMIC);
		if (!conn->rx_skb)
L
Linus Torvalds 已提交
5041 5042
			goto drop;

5043
		skb_copy_from_linear_data(skb, skb_put(conn->rx_skb, skb->len),
5044
								skb->len);
L
Linus Torvalds 已提交
5045 5046 5047 5048 5049 5050 5051 5052 5053 5054 5055 5056 5057 5058 5059 5060 5061 5062 5063 5064
		conn->rx_len = len - skb->len;
	} else {
		BT_DBG("Cont: frag len %d (expecting %d)", skb->len, conn->rx_len);

		if (!conn->rx_len) {
			BT_ERR("Unexpected continuation frame (len %d)", skb->len);
			l2cap_conn_unreliable(conn, ECOMM);
			goto drop;
		}

		if (skb->len > conn->rx_len) {
			BT_ERR("Fragment is too long (len %d, expected %d)",
					skb->len, conn->rx_len);
			kfree_skb(conn->rx_skb);
			conn->rx_skb = NULL;
			conn->rx_len = 0;
			l2cap_conn_unreliable(conn, ECOMM);
			goto drop;
		}

5065
		skb_copy_from_linear_data(skb, skb_put(conn->rx_skb, skb->len),
5066
								skb->len);
L
Linus Torvalds 已提交
5067 5068 5069 5070 5071 5072 5073 5074 5075 5076 5077 5078 5079 5080
		conn->rx_len -= skb->len;

		if (!conn->rx_len) {
			/* Complete frame received */
			l2cap_recv_frame(conn, conn->rx_skb);
			conn->rx_skb = NULL;
		}
	}

drop:
	kfree_skb(skb);
	return 0;
}

5081
static int l2cap_debugfs_show(struct seq_file *f, void *p)
L
Linus Torvalds 已提交
5082
{
5083
	struct l2cap_chan *c;
L
Linus Torvalds 已提交
5084

5085
	read_lock(&chan_list_lock);
L
Linus Torvalds 已提交
5086

5087 5088
	list_for_each_entry(c, &chan_list, global_l) {
		struct sock *sk = c->sk;
5089

5090
		seq_printf(f, "%s %s %d %d 0x%4.4x 0x%4.4x %d %d %d %d\n",
5091 5092
					batostr(&bt_sk(sk)->src),
					batostr(&bt_sk(sk)->dst),
5093
					c->state, __le16_to_cpu(c->psm),
5094 5095
					c->scid, c->dcid, c->imtu, c->omtu,
					c->sec_level, c->mode);
5096
	}
L
Linus Torvalds 已提交
5097

5098
	read_unlock(&chan_list_lock);
L
Linus Torvalds 已提交
5099

5100
	return 0;
L
Linus Torvalds 已提交
5101 5102
}

5103 5104 5105 5106 5107 5108 5109 5110 5111 5112 5113 5114 5115
static int l2cap_debugfs_open(struct inode *inode, struct file *file)
{
	return single_open(file, l2cap_debugfs_show, inode->i_private);
}

static const struct file_operations l2cap_debugfs_fops = {
	.open		= l2cap_debugfs_open,
	.read		= seq_read,
	.llseek		= seq_lseek,
	.release	= single_release,
};

static struct dentry *l2cap_debugfs;
L
Linus Torvalds 已提交
5116

5117
int __init l2cap_init(void)
L
Linus Torvalds 已提交
5118 5119
{
	int err;
5120

5121
	err = l2cap_init_sockets();
L
Linus Torvalds 已提交
5122 5123 5124
	if (err < 0)
		return err;

5125 5126 5127 5128 5129 5130
	if (bt_debugfs) {
		l2cap_debugfs = debugfs_create_file("l2cap", 0444,
					bt_debugfs, NULL, &l2cap_debugfs_fops);
		if (!l2cap_debugfs)
			BT_ERR("Failed to create L2CAP debug file");
	}
L
Linus Torvalds 已提交
5131 5132 5133 5134

	return 0;
}

5135
void l2cap_exit(void)
L
Linus Torvalds 已提交
5136
{
5137
	debugfs_remove(l2cap_debugfs);
5138
	l2cap_cleanup_sockets();
L
Linus Torvalds 已提交
5139 5140
}

5141 5142
module_param(disable_ertm, bool, 0644);
MODULE_PARM_DESC(disable_ertm, "Disable enhanced retransmission mode");