l2cap_core.c 98.4 KB
Newer Older
1
/*
L
Linus Torvalds 已提交
2 3
   BlueZ - Bluetooth protocol stack for Linux
   Copyright (C) 2000-2001 Qualcomm Incorporated
4
   Copyright (C) 2009-2010 Gustavo F. Padovan <gustavo@padovan.org>
5
   Copyright (C) 2010 Google Inc.
L
Linus Torvalds 已提交
6 7 8 9 10 11 12 13 14 15 16

   Written 2000,2001 by Maxim Krasnyansky <maxk@qualcomm.com>

   This program is free software; you can redistribute it and/or modify
   it under the terms of the GNU General Public License version 2 as
   published by the Free Software Foundation;

   THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS
   OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
   FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT OF THIRD PARTY RIGHTS.
   IN NO EVENT SHALL THE COPYRIGHT HOLDER(S) AND AUTHOR(S) BE LIABLE FOR ANY
17 18 19
   CLAIM, OR ANY SPECIAL INDIRECT OR CONSEQUENTIAL DAMAGES, OR ANY DAMAGES
   WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
   ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
L
Linus Torvalds 已提交
20 21
   OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.

22 23
   ALL LIABILITY, INCLUDING LIABILITY FOR INFRINGEMENT OF ANY PATENTS,
   COPYRIGHTS, TRADEMARKS OR OTHER RIGHTS, RELATING TO USE OF THIS
L
Linus Torvalds 已提交
24 25 26
   SOFTWARE IS DISCLAIMED.
*/

27
/* Bluetooth L2CAP core. */
L
Linus Torvalds 已提交
28 29 30 31

#include <linux/module.h>

#include <linux/types.h>
32
#include <linux/capability.h>
L
Linus Torvalds 已提交
33 34 35 36 37 38 39 40 41 42 43
#include <linux/errno.h>
#include <linux/kernel.h>
#include <linux/sched.h>
#include <linux/slab.h>
#include <linux/poll.h>
#include <linux/fcntl.h>
#include <linux/init.h>
#include <linux/interrupt.h>
#include <linux/socket.h>
#include <linux/skbuff.h>
#include <linux/list.h>
44
#include <linux/device.h>
45 46
#include <linux/debugfs.h>
#include <linux/seq_file.h>
47
#include <linux/uaccess.h>
48
#include <linux/crc16.h>
L
Linus Torvalds 已提交
49 50 51 52 53 54 55 56 57
#include <net/sock.h>

#include <asm/system.h>
#include <asm/unaligned.h>

#include <net/bluetooth/bluetooth.h>
#include <net/bluetooth/hci_core.h>
#include <net/bluetooth/l2cap.h>

58
int disable_ertm;
59

60
static u32 l2cap_feat_mask = L2CAP_FEAT_FIXED_CHAN;
61
static u8 l2cap_fixed_chan[8] = { 0x02, };
L
Linus Torvalds 已提交
62

63 64
static struct workqueue_struct *_busy_wq;

65 66
static LIST_HEAD(chan_list);
static DEFINE_RWLOCK(chan_list_lock);
L
Linus Torvalds 已提交
67

68 69
static void l2cap_busy_work(struct work_struct *work);

L
Linus Torvalds 已提交
70 71
static struct sk_buff *l2cap_build_cmd(struct l2cap_conn *conn,
				u8 code, u8 ident, u16 dlen, void *data);
72 73
static void l2cap_send_cmd(struct l2cap_conn *conn, u8 ident, u8 code, u16 len,
								void *data);
74
static int l2cap_build_conf_req(struct l2cap_chan *chan, void *data);
75 76
static void l2cap_send_disconn_req(struct l2cap_conn *conn,
				struct l2cap_chan *chan, int err);
L
Linus Torvalds 已提交
77

78 79
static int l2cap_ertm_data_rcv(struct sock *sk, struct sk_buff *skb);

80
/* ---- L2CAP channels ---- */
81
static struct l2cap_chan *__l2cap_get_chan_by_dcid(struct l2cap_conn *conn, u16 cid)
82
{
83
	struct l2cap_chan *c;
84 85

	list_for_each_entry(c, &conn->chan_l, list) {
86
		if (c->dcid == cid)
87
			return c;
88
	}
89 90
	return NULL;

91 92
}

93
static struct l2cap_chan *__l2cap_get_chan_by_scid(struct l2cap_conn *conn, u16 cid)
94
{
95
	struct l2cap_chan *c;
96 97

	list_for_each_entry(c, &conn->chan_l, list) {
98
		if (c->scid == cid)
99
			return c;
100
	}
101
	return NULL;
102 103 104 105
}

/* Find channel with given SCID.
 * Returns locked socket */
106
static struct l2cap_chan *l2cap_get_chan_by_scid(struct l2cap_conn *conn, u16 cid)
107
{
108
	struct l2cap_chan *c;
109 110 111

	read_lock(&conn->chan_lock);
	c = __l2cap_get_chan_by_scid(conn, cid);
112 113
	if (c)
		bh_lock_sock(c->sk);
114
	read_unlock(&conn->chan_lock);
115
	return c;
116 117
}

118
static struct l2cap_chan *__l2cap_get_chan_by_ident(struct l2cap_conn *conn, u8 ident)
119
{
120
	struct l2cap_chan *c;
121 122

	list_for_each_entry(c, &conn->chan_l, list) {
123
		if (c->ident == ident)
124
			return c;
125
	}
126
	return NULL;
127 128
}

129
static inline struct l2cap_chan *l2cap_get_chan_by_ident(struct l2cap_conn *conn, u8 ident)
130
{
131
	struct l2cap_chan *c;
132 133 134

	read_lock(&conn->chan_lock);
	c = __l2cap_get_chan_by_ident(conn, ident);
135 136
	if (c)
		bh_lock_sock(c->sk);
137
	read_unlock(&conn->chan_lock);
138
	return c;
139 140
}

141
static struct l2cap_chan *__l2cap_global_chan_by_addr(__le16 psm, bdaddr_t *src)
142
{
143
	struct l2cap_chan *c;
144

145 146
	list_for_each_entry(c, &chan_list, global_l) {
		if (c->sport == psm && !bacmp(&bt_sk(c->sk)->src, src))
147 148 149
			goto found;
	}

150
	c = NULL;
151
found:
152
	return c;
153 154 155 156
}

int l2cap_add_psm(struct l2cap_chan *chan, bdaddr_t *src, __le16 psm)
{
157 158
	int err;

159
	write_lock_bh(&chan_list_lock);
160

161
	if (psm && __l2cap_global_chan_by_addr(psm, src)) {
162 163
		err = -EADDRINUSE;
		goto done;
164 165
	}

166 167 168 169 170 171 172 173 174
	if (psm) {
		chan->psm = psm;
		chan->sport = psm;
		err = 0;
	} else {
		u16 p;

		err = -EINVAL;
		for (p = 0x1001; p < 0x1100; p += 2)
175
			if (!__l2cap_global_chan_by_addr(cpu_to_le16(p), src)) {
176 177 178 179 180 181
				chan->psm   = cpu_to_le16(p);
				chan->sport = cpu_to_le16(p);
				err = 0;
				break;
			}
	}
182

183
done:
184
	write_unlock_bh(&chan_list_lock);
185
	return err;
186 187 188 189
}

int l2cap_add_scid(struct l2cap_chan *chan,  __u16 scid)
{
190
	write_lock_bh(&chan_list_lock);
191 192 193

	chan->scid = scid;

194
	write_unlock_bh(&chan_list_lock);
195 196 197 198

	return 0;
}

199
static u16 l2cap_alloc_cid(struct l2cap_conn *conn)
200
{
201
	u16 cid = L2CAP_CID_DYN_START;
202

203
	for (; cid < L2CAP_CID_DYN_END; cid++) {
204
		if (!__l2cap_get_chan_by_scid(conn, cid))
205 206 207 208 209 210
			return cid;
	}

	return 0;
}

211 212 213 214 215 216 217 218
static void l2cap_chan_set_timer(struct l2cap_chan *chan, long timeout)
{
       BT_DBG("chan %p state %d timeout %ld", chan->sk, chan->sk->sk_state,
								 timeout);
       if (!mod_timer(&chan->chan_timer, jiffies + timeout))
	       sock_hold(chan->sk);
}

219
static void l2cap_chan_clear_timer(struct l2cap_chan *chan)
220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 252
{
       BT_DBG("chan %p state %d", chan, chan->sk->sk_state);

       if (timer_pending(&chan->chan_timer) && del_timer(&chan->chan_timer))
	       __sock_put(chan->sk);
}

static void l2cap_chan_timeout(unsigned long arg)
{
	struct l2cap_chan *chan = (struct l2cap_chan *) arg;
	struct sock *sk = chan->sk;
	int reason;

	BT_DBG("chan %p state %d", chan, sk->sk_state);

	bh_lock_sock(sk);

	if (sock_owned_by_user(sk)) {
		/* sk is owned by user. Try again later */
		l2cap_chan_set_timer(chan, HZ / 5);
		bh_unlock_sock(sk);
		sock_put(sk);
		return;
	}

	if (sk->sk_state == BT_CONNECTED || sk->sk_state == BT_CONFIG)
		reason = ECONNREFUSED;
	else if (sk->sk_state == BT_CONNECT &&
					chan->sec_level != BT_SECURITY_SDP)
		reason = ECONNREFUSED;
	else
		reason = ETIMEDOUT;

253
	l2cap_chan_close(chan, reason);
254 255 256 257 258 259 260

	bh_unlock_sock(sk);

	l2cap_sock_kill(sk);
	sock_put(sk);
}

261
struct l2cap_chan *l2cap_chan_create(struct sock *sk)
262 263 264 265 266 267 268 269 270
{
	struct l2cap_chan *chan;

	chan = kzalloc(sizeof(*chan), GFP_ATOMIC);
	if (!chan)
		return NULL;

	chan->sk = sk;

271 272 273 274
	write_lock_bh(&chan_list_lock);
	list_add(&chan->global_l, &chan_list);
	write_unlock_bh(&chan_list_lock);

275 276
	setup_timer(&chan->chan_timer, l2cap_chan_timeout, (unsigned long) chan);

277 278 279
	return chan;
}

280
void l2cap_chan_destroy(struct l2cap_chan *chan)
281
{
282 283 284 285
	write_lock_bh(&chan_list_lock);
	list_del(&chan->global_l);
	write_unlock_bh(&chan_list_lock);

286 287 288
	kfree(chan);
}

289
static void __l2cap_chan_add(struct l2cap_conn *conn, struct l2cap_chan *chan)
290
{
291
	struct sock *sk = chan->sk;
292

293
	BT_DBG("conn %p, psm 0x%2.2x, dcid 0x%4.4x", conn,
294
			chan->psm, chan->dcid);
295

296 297
	conn->disc_reason = 0x13;

298
	chan->conn = conn;
299

300
	if (chan->chan_type == L2CAP_CHAN_CONN_ORIENTED) {
301 302
		if (conn->hcon->type == LE_LINK) {
			/* LE connection */
303
			chan->omtu = L2CAP_LE_DEFAULT_MTU;
304 305
			chan->scid = L2CAP_CID_LE_DATA;
			chan->dcid = L2CAP_CID_LE_DATA;
306 307
		} else {
			/* Alloc CID for connection-oriented socket */
308
			chan->scid = l2cap_alloc_cid(conn);
309
			chan->omtu = L2CAP_DEFAULT_MTU;
310
		}
311
	} else if (chan->chan_type == L2CAP_CHAN_CONN_LESS) {
312
		/* Connectionless socket */
313 314
		chan->scid = L2CAP_CID_CONN_LESS;
		chan->dcid = L2CAP_CID_CONN_LESS;
315
		chan->omtu = L2CAP_DEFAULT_MTU;
316 317
	} else {
		/* Raw socket can send/recv signalling messages only */
318 319
		chan->scid = L2CAP_CID_SIGNALING;
		chan->dcid = L2CAP_CID_SIGNALING;
320
		chan->omtu = L2CAP_DEFAULT_MTU;
321 322
	}

323 324 325
	sock_hold(sk);

	list_add(&chan->list, &conn->chan_l);
326 327
}

328
/* Delete channel.
329
 * Must be called on the locked socket. */
330
static void l2cap_chan_del(struct l2cap_chan *chan, int err)
331
{
332
	struct sock *sk = chan->sk;
333
	struct l2cap_conn *conn = chan->conn;
334 335
	struct sock *parent = bt_sk(sk)->parent;

336
	l2cap_chan_clear_timer(chan);
337

338
	BT_DBG("chan %p, conn %p, err %d", chan, conn, err);
339

340
	if (conn) {
341 342 343 344 345 346
		/* Delete from channel list */
		write_lock_bh(&conn->chan_lock);
		list_del(&chan->list);
		write_unlock_bh(&conn->chan_lock);
		__sock_put(sk);

347
		chan->conn = NULL;
348 349 350
		hci_conn_put(conn->hcon);
	}

351
	sk->sk_state = BT_CLOSED;
352 353 354 355 356 357 358 359 360 361
	sock_set_flag(sk, SOCK_ZAPPED);

	if (err)
		sk->sk_err = err;

	if (parent) {
		bt_accept_unlink(sk);
		parent->sk_data_ready(parent, 0);
	} else
		sk->sk_state_change(sk);
362

363 364
	if (!(chan->conf_state & L2CAP_CONF_OUTPUT_DONE &&
			chan->conf_state & L2CAP_CONF_INPUT_DONE))
365
		return;
366

367
	skb_queue_purge(&chan->tx_q);
368

369
	if (chan->mode == L2CAP_MODE_ERTM) {
370 371
		struct srej_list *l, *tmp;

372 373 374
		del_timer(&chan->retrans_timer);
		del_timer(&chan->monitor_timer);
		del_timer(&chan->ack_timer);
375

376 377
		skb_queue_purge(&chan->srej_q);
		skb_queue_purge(&chan->busy_q);
378

379
		list_for_each_entry_safe(l, tmp, &chan->srej_l, list) {
380 381 382 383
			list_del(&l->list);
			kfree(l);
		}
	}
384 385
}

386 387 388 389 390 391 392
static void l2cap_chan_cleanup_listen(struct sock *parent)
{
	struct sock *sk;

	BT_DBG("parent %p", parent);

	/* Close not yet accepted channels */
393 394 395 396 397 398 399
	while ((sk = bt_accept_dequeue(parent, NULL))) {
		l2cap_chan_clear_timer(l2cap_pi(sk)->chan);
		lock_sock(sk);
		l2cap_chan_close(l2cap_pi(sk)->chan, ECONNRESET);
		release_sock(sk);
		l2cap_sock_kill(sk);
	}
400 401 402 403 404

	parent->sk_state = BT_CLOSED;
	sock_set_flag(parent, SOCK_ZAPPED);
}

405
void l2cap_chan_close(struct l2cap_chan *chan, int reason)
406 407 408 409 410 411 412 413 414 415 416 417 418
{
	struct l2cap_conn *conn = chan->conn;
	struct sock *sk = chan->sk;

	BT_DBG("chan %p state %d socket %p", chan, sk->sk_state, sk->sk_socket);

	switch (sk->sk_state) {
	case BT_LISTEN:
		l2cap_chan_cleanup_listen(sk);
		break;

	case BT_CONNECTED:
	case BT_CONFIG:
419
		if (chan->chan_type == L2CAP_CHAN_CONN_ORIENTED &&
420
					conn->hcon->type == ACL_LINK) {
421
			l2cap_chan_clear_timer(chan);
422
			l2cap_chan_set_timer(chan, sk->sk_sndtimeo);
423 424 425 426 427 428
			l2cap_send_disconn_req(conn, chan, reason);
		} else
			l2cap_chan_del(chan, reason);
		break;

	case BT_CONNECT2:
429
		if (chan->chan_type == L2CAP_CHAN_CONN_ORIENTED &&
430 431 432 433 434 435 436 437
					conn->hcon->type == ACL_LINK) {
			struct l2cap_conn_rsp rsp;
			__u16 result;

			if (bt_sk(sk)->defer_setup)
				result = L2CAP_CR_SEC_BLOCK;
			else
				result = L2CAP_CR_BAD_PSM;
438
			sk->sk_state = BT_DISCONN;
439 440 441 442 443 444 445 446 447 448 449 450 451 452 453 454 455 456 457 458 459 460 461

			rsp.scid   = cpu_to_le16(chan->dcid);
			rsp.dcid   = cpu_to_le16(chan->scid);
			rsp.result = cpu_to_le16(result);
			rsp.status = cpu_to_le16(L2CAP_CS_NO_INFO);
			l2cap_send_cmd(conn, chan->ident, L2CAP_CONN_RSP,
							sizeof(rsp), &rsp);
		}

		l2cap_chan_del(chan, reason);
		break;

	case BT_CONNECT:
	case BT_DISCONN:
		l2cap_chan_del(chan, reason);
		break;

	default:
		sock_set_flag(sk, SOCK_ZAPPED);
		break;
	}
}

462
static inline u8 l2cap_get_auth_type(struct l2cap_chan *chan)
463
{
464
	if (chan->chan_type == L2CAP_CHAN_RAW) {
465
		switch (chan->sec_level) {
466 467 468 469 470 471 472
		case BT_SECURITY_HIGH:
			return HCI_AT_DEDICATED_BONDING_MITM;
		case BT_SECURITY_MEDIUM:
			return HCI_AT_DEDICATED_BONDING;
		default:
			return HCI_AT_NO_BONDING;
		}
473
	} else if (chan->psm == cpu_to_le16(0x0001)) {
474 475
		if (chan->sec_level == BT_SECURITY_LOW)
			chan->sec_level = BT_SECURITY_SDP;
476

477
		if (chan->sec_level == BT_SECURITY_HIGH)
478
			return HCI_AT_NO_BONDING_MITM;
479
		else
480
			return HCI_AT_NO_BONDING;
481
	} else {
482
		switch (chan->sec_level) {
483
		case BT_SECURITY_HIGH:
484
			return HCI_AT_GENERAL_BONDING_MITM;
485
		case BT_SECURITY_MEDIUM:
486
			return HCI_AT_GENERAL_BONDING;
487
		default:
488
			return HCI_AT_NO_BONDING;
489
		}
490
	}
491 492 493
}

/* Service level security */
494
static inline int l2cap_check_security(struct l2cap_chan *chan)
495
{
496
	struct l2cap_conn *conn = chan->conn;
497 498
	__u8 auth_type;

499
	auth_type = l2cap_get_auth_type(chan);
500

501
	return hci_conn_security(conn->hcon, chan->sec_level, auth_type);
502 503
}

504
static u8 l2cap_get_ident(struct l2cap_conn *conn)
505 506 507 508 509 510 511 512 513 514 515 516 517 518 519 520 521 522 523 524 525
{
	u8 id;

	/* Get next available identificator.
	 *    1 - 128 are used by kernel.
	 *  129 - 199 are reserved.
	 *  200 - 254 are used by utilities like l2ping, etc.
	 */

	spin_lock_bh(&conn->lock);

	if (++conn->tx_ident > 128)
		conn->tx_ident = 1;

	id = conn->tx_ident;

	spin_unlock_bh(&conn->lock);

	return id;
}

526
static void l2cap_send_cmd(struct l2cap_conn *conn, u8 ident, u8 code, u16 len, void *data)
527 528
{
	struct sk_buff *skb = l2cap_build_cmd(conn, code, ident, len, data);
529
	u8 flags;
530 531 532 533

	BT_DBG("code 0x%2.2x", code);

	if (!skb)
534
		return;
535

536 537 538 539 540
	if (lmp_no_flush_capable(conn->hcon->hdev))
		flags = ACL_START_NO_FLUSH;
	else
		flags = ACL_START;

541 542
	bt_cb(skb)->force_active = BT_POWER_FORCE_ACTIVE_ON;

543
	hci_send_acl(conn->hcon, skb, flags);
544 545
}

546
static inline void l2cap_send_sframe(struct l2cap_chan *chan, u16 control)
547 548 549
{
	struct sk_buff *skb;
	struct l2cap_hdr *lh;
550
	struct l2cap_pinfo *pi = l2cap_pi(chan->sk);
551
	struct l2cap_conn *conn = chan->conn;
552
	struct sock *sk = (struct sock *)pi;
553
	int count, hlen = L2CAP_HDR_SIZE + 2;
554
	u8 flags;
555

556 557 558
	if (sk->sk_state != BT_CONNECTED)
		return;

559
	if (chan->fcs == L2CAP_FCS_CRC16)
560
		hlen += 2;
561

562
	BT_DBG("chan %p, control 0x%2.2x", chan, control);
563

564
	count = min_t(unsigned int, conn->mtu, hlen);
565 566
	control |= L2CAP_CTRL_FRAME_TYPE;

567
	if (chan->conn_state & L2CAP_CONN_SEND_FBIT) {
568
		control |= L2CAP_CTRL_FINAL;
569
		chan->conn_state &= ~L2CAP_CONN_SEND_FBIT;
570 571
	}

572
	if (chan->conn_state & L2CAP_CONN_SEND_PBIT) {
573
		control |= L2CAP_CTRL_POLL;
574
		chan->conn_state &= ~L2CAP_CONN_SEND_PBIT;
575 576
	}

577 578
	skb = bt_skb_alloc(count, GFP_ATOMIC);
	if (!skb)
579
		return;
580 581

	lh = (struct l2cap_hdr *) skb_put(skb, L2CAP_HDR_SIZE);
582
	lh->len = cpu_to_le16(hlen - L2CAP_HDR_SIZE);
583
	lh->cid = cpu_to_le16(chan->dcid);
584 585
	put_unaligned_le16(control, skb_put(skb, 2));

586
	if (chan->fcs == L2CAP_FCS_CRC16) {
587 588 589 590
		u16 fcs = crc16(0, (u8 *)lh, count - 2);
		put_unaligned_le16(fcs, skb_put(skb, 2));
	}

591 592 593 594 595
	if (lmp_no_flush_capable(conn->hcon->hdev))
		flags = ACL_START_NO_FLUSH;
	else
		flags = ACL_START;

596 597
	bt_cb(skb)->force_active = chan->force_active;

598
	hci_send_acl(chan->conn->hcon, skb, flags);
599 600
}

601
static inline void l2cap_send_rr_or_rnr(struct l2cap_chan *chan, u16 control)
602
{
603
	if (chan->conn_state & L2CAP_CONN_LOCAL_BUSY) {
604
		control |= L2CAP_SUPER_RCV_NOT_READY;
605
		chan->conn_state |= L2CAP_CONN_RNR_SENT;
606
	} else
607 608
		control |= L2CAP_SUPER_RCV_READY;

609
	control |= chan->buffer_seq << L2CAP_CTRL_REQSEQ_SHIFT;
610

611
	l2cap_send_sframe(chan, control);
612 613
}

614
static inline int __l2cap_no_conn_pending(struct l2cap_chan *chan)
615
{
616
	return !(chan->conf_state & L2CAP_CONF_CONNECT_PEND);
617 618
}

619
static void l2cap_do_start(struct l2cap_chan *chan)
620
{
621
	struct l2cap_conn *conn = chan->conn;
622 623

	if (conn->info_state & L2CAP_INFO_FEAT_MASK_REQ_SENT) {
624 625 626
		if (!(conn->info_state & L2CAP_INFO_FEAT_MASK_REQ_DONE))
			return;

627 628
		if (l2cap_check_security(chan) &&
				__l2cap_no_conn_pending(chan)) {
629
			struct l2cap_conn_req req;
630 631
			req.scid = cpu_to_le16(chan->scid);
			req.psm  = chan->psm;
632

633
			chan->ident = l2cap_get_ident(conn);
634
			chan->conf_state |= L2CAP_CONF_CONNECT_PEND;
635

636 637
			l2cap_send_cmd(conn, chan->ident, L2CAP_CONN_REQ,
							sizeof(req), &req);
638
		}
639 640 641 642 643 644 645 646 647 648 649 650 651 652 653
	} else {
		struct l2cap_info_req req;
		req.type = cpu_to_le16(L2CAP_IT_FEAT_MASK);

		conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_SENT;
		conn->info_ident = l2cap_get_ident(conn);

		mod_timer(&conn->info_timer, jiffies +
					msecs_to_jiffies(L2CAP_INFO_TIMEOUT));

		l2cap_send_cmd(conn, conn->info_ident,
					L2CAP_INFO_REQ, sizeof(req), &req);
	}
}

654 655 656
static inline int l2cap_mode_supported(__u8 mode, __u32 feat_mask)
{
	u32 local_feat_mask = l2cap_feat_mask;
657
	if (!disable_ertm)
658 659 660 661 662 663 664 665 666 667 668 669
		local_feat_mask |= L2CAP_FEAT_ERTM | L2CAP_FEAT_STREAMING;

	switch (mode) {
	case L2CAP_MODE_ERTM:
		return L2CAP_FEAT_ERTM & feat_mask & local_feat_mask;
	case L2CAP_MODE_STREAMING:
		return L2CAP_FEAT_STREAMING & feat_mask & local_feat_mask;
	default:
		return 0x00;
	}
}

670
static void l2cap_send_disconn_req(struct l2cap_conn *conn, struct l2cap_chan *chan, int err)
671
{
672
	struct sock *sk;
673 674
	struct l2cap_disconn_req req;

675 676 677
	if (!conn)
		return;

678 679
	sk = chan->sk;

680
	if (chan->mode == L2CAP_MODE_ERTM) {
681 682 683
		del_timer(&chan->retrans_timer);
		del_timer(&chan->monitor_timer);
		del_timer(&chan->ack_timer);
684 685
	}

686 687
	req.dcid = cpu_to_le16(chan->dcid);
	req.scid = cpu_to_le16(chan->scid);
688 689
	l2cap_send_cmd(conn, l2cap_get_ident(conn),
			L2CAP_DISCONN_REQ, sizeof(req), &req);
690 691

	sk->sk_state = BT_DISCONN;
692
	sk->sk_err = err;
693 694
}

L
Linus Torvalds 已提交
695
/* ---- L2CAP connections ---- */
696 697
static void l2cap_conn_start(struct l2cap_conn *conn)
{
698
	struct l2cap_chan *chan, *tmp;
699 700 701

	BT_DBG("conn %p", conn);

702
	read_lock(&conn->chan_lock);
703

704
	list_for_each_entry_safe(chan, tmp, &conn->chan_l, list) {
705
		struct sock *sk = chan->sk;
706

707 708
		bh_lock_sock(sk);

709
		if (chan->chan_type != L2CAP_CHAN_CONN_ORIENTED) {
710 711 712 713 714
			bh_unlock_sock(sk);
			continue;
		}

		if (sk->sk_state == BT_CONNECT) {
715
			struct l2cap_conn_req req;
716

717
			if (!l2cap_check_security(chan) ||
718
					!__l2cap_no_conn_pending(chan)) {
719 720 721
				bh_unlock_sock(sk);
				continue;
			}
722

723
			if (!l2cap_mode_supported(chan->mode,
724
					conn->feat_mask)
725
					&& chan->conf_state &
726
					L2CAP_CONF_STATE2_DEVICE) {
727
				/* l2cap_chan_close() calls list_del(chan)
728 729
				 * so release the lock */
				read_unlock_bh(&conn->chan_lock);
730
				 l2cap_chan_close(chan, ECONNRESET);
731
				read_lock_bh(&conn->chan_lock);
732 733
				bh_unlock_sock(sk);
				continue;
734
			}
735

736 737
			req.scid = cpu_to_le16(chan->scid);
			req.psm  = chan->psm;
738

739
			chan->ident = l2cap_get_ident(conn);
740
			chan->conf_state |= L2CAP_CONF_CONNECT_PEND;
741

742 743
			l2cap_send_cmd(conn, chan->ident, L2CAP_CONN_REQ,
							sizeof(req), &req);
744

745 746
		} else if (sk->sk_state == BT_CONNECT2) {
			struct l2cap_conn_rsp rsp;
747
			char buf[128];
748 749
			rsp.scid = cpu_to_le16(chan->dcid);
			rsp.dcid = cpu_to_le16(chan->scid);
750

751
			if (l2cap_check_security(chan)) {
752 753 754 755 756 757 758 759 760 761 762
				if (bt_sk(sk)->defer_setup) {
					struct sock *parent = bt_sk(sk)->parent;
					rsp.result = cpu_to_le16(L2CAP_CR_PEND);
					rsp.status = cpu_to_le16(L2CAP_CS_AUTHOR_PEND);
					parent->sk_data_ready(parent, 0);

				} else {
					sk->sk_state = BT_CONFIG;
					rsp.result = cpu_to_le16(L2CAP_CR_SUCCESS);
					rsp.status = cpu_to_le16(L2CAP_CS_NO_INFO);
				}
763 764 765 766 767
			} else {
				rsp.result = cpu_to_le16(L2CAP_CR_PEND);
				rsp.status = cpu_to_le16(L2CAP_CS_AUTHEN_PEND);
			}

768 769
			l2cap_send_cmd(conn, chan->ident, L2CAP_CONN_RSP,
							sizeof(rsp), &rsp);
770

771
			if (chan->conf_state & L2CAP_CONF_REQ_SENT ||
772 773 774 775 776
					rsp.result != L2CAP_CR_SUCCESS) {
				bh_unlock_sock(sk);
				continue;
			}

777
			chan->conf_state |= L2CAP_CONF_REQ_SENT;
778
			l2cap_send_cmd(conn, l2cap_get_ident(conn), L2CAP_CONF_REQ,
779 780
						l2cap_build_conf_req(chan, buf), buf);
			chan->num_conf_req++;
781 782 783 784 785
		}

		bh_unlock_sock(sk);
	}

786
	read_unlock(&conn->chan_lock);
787 788
}

789 790 791
/* Find socket with cid and source bdaddr.
 * Returns closest match, locked.
 */
792
static struct l2cap_chan *l2cap_global_chan_by_scid(int state, __le16 cid, bdaddr_t *src)
793
{
794
	struct l2cap_chan *c, *c1 = NULL;
795

796
	read_lock(&chan_list_lock);
797

798 799
	list_for_each_entry(c, &chan_list, global_l) {
		struct sock *sk = c->sk;
800

801 802 803
		if (state && sk->sk_state != state)
			continue;

804
		if (c->scid == cid) {
805
			/* Exact match. */
806 807 808 809
			if (!bacmp(&bt_sk(sk)->src, src)) {
				read_unlock(&chan_list_lock);
				return c;
			}
810 811 812

			/* Closest match */
			if (!bacmp(&bt_sk(sk)->src, BDADDR_ANY))
813
				c1 = c;
814 815
		}
	}
816

817
	read_unlock(&chan_list_lock);
818

819
	return c1;
820 821 822 823
}

static void l2cap_le_conn_ready(struct l2cap_conn *conn)
{
824
	struct sock *parent, *sk;
825
	struct l2cap_chan *chan, *pchan;
826 827 828 829

	BT_DBG("");

	/* Check if we have socket listening on cid */
830
	pchan = l2cap_global_chan_by_scid(BT_LISTEN, L2CAP_CID_LE_DATA,
831
							conn->src);
832
	if (!pchan)
833 834
		return;

835 836
	parent = pchan->sk;

837 838
	bh_lock_sock(parent);

839 840 841 842 843 844
	/* Check for backlog size */
	if (sk_acceptq_is_full(parent)) {
		BT_DBG("backlog full %d", parent->sk_ack_backlog);
		goto clean;
	}

845 846
	chan = pchan->ops->new_connection(pchan->data);
	if (!chan)
847 848
		goto clean;

849
	sk = chan->sk;
850

851
	write_lock_bh(&conn->chan_lock);
852 853 854 855 856 857

	hci_conn_hold(conn->hcon);

	bacpy(&bt_sk(sk)->src, conn->src);
	bacpy(&bt_sk(sk)->dst, conn->dst);

858 859
	bt_accept_enqueue(parent, sk);

860 861
	__l2cap_chan_add(conn, chan);

862
	l2cap_chan_set_timer(chan, sk->sk_sndtimeo);
863 864 865 866

	sk->sk_state = BT_CONNECTED;
	parent->sk_data_ready(parent, 0);

867
	write_unlock_bh(&conn->chan_lock);
868 869 870 871 872

clean:
	bh_unlock_sock(parent);
}

873 874
static void l2cap_conn_ready(struct l2cap_conn *conn)
{
875
	struct l2cap_chan *chan;
876

877
	BT_DBG("conn %p", conn);
878

879 880 881
	if (!conn->hcon->out && conn->hcon->type == LE_LINK)
		l2cap_le_conn_ready(conn);

882
	read_lock(&conn->chan_lock);
883

884
	list_for_each_entry(chan, &conn->chan_l, list) {
885
		struct sock *sk = chan->sk;
886

887
		bh_lock_sock(sk);
888

889
		if (conn->hcon->type == LE_LINK) {
890
			l2cap_chan_clear_timer(chan);
891 892 893 894
			sk->sk_state = BT_CONNECTED;
			sk->sk_state_change(sk);
		}

895
		if (chan->chan_type != L2CAP_CHAN_CONN_ORIENTED) {
896
			l2cap_chan_clear_timer(chan);
897 898 899
			sk->sk_state = BT_CONNECTED;
			sk->sk_state_change(sk);
		} else if (sk->sk_state == BT_CONNECT)
900
			l2cap_do_start(chan);
901

902
		bh_unlock_sock(sk);
903
	}
904

905
	read_unlock(&conn->chan_lock);
906 907 908 909 910
}

/* Notify sockets that we cannot guaranty reliability anymore */
static void l2cap_conn_unreliable(struct l2cap_conn *conn, int err)
{
911
	struct l2cap_chan *chan;
912 913 914

	BT_DBG("conn %p", conn);

915
	read_lock(&conn->chan_lock);
916

917
	list_for_each_entry(chan, &conn->chan_l, list) {
918
		struct sock *sk = chan->sk;
919

920
		if (chan->force_reliable)
921 922 923
			sk->sk_err = err;
	}

924
	read_unlock(&conn->chan_lock);
925 926 927 928 929 930
}

static void l2cap_info_timeout(unsigned long arg)
{
	struct l2cap_conn *conn = (void *) arg;

931
	conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_DONE;
932
	conn->info_ident = 0;
933

934 935 936
	l2cap_conn_start(conn);
}

L
Linus Torvalds 已提交
937 938
static struct l2cap_conn *l2cap_conn_add(struct hci_conn *hcon, u8 status)
{
939
	struct l2cap_conn *conn = hcon->l2cap_data;
L
Linus Torvalds 已提交
940

941
	if (conn || status)
L
Linus Torvalds 已提交
942 943
		return conn;

944 945
	conn = kzalloc(sizeof(struct l2cap_conn), GFP_ATOMIC);
	if (!conn)
L
Linus Torvalds 已提交
946 947 948 949 950
		return NULL;

	hcon->l2cap_data = conn;
	conn->hcon = hcon;

951 952
	BT_DBG("hcon %p conn %p", hcon, conn);

953 954 955 956 957
	if (hcon->hdev->le_mtu && hcon->type == LE_LINK)
		conn->mtu = hcon->hdev->le_mtu;
	else
		conn->mtu = hcon->hdev->acl_mtu;

L
Linus Torvalds 已提交
958 959 960
	conn->src = &hcon->hdev->bdaddr;
	conn->dst = &hcon->dst;

961 962
	conn->feat_mask = 0;

L
Linus Torvalds 已提交
963
	spin_lock_init(&conn->lock);
964 965 966
	rwlock_init(&conn->chan_lock);

	INIT_LIST_HEAD(&conn->chan_l);
L
Linus Torvalds 已提交
967

968 969
	if (hcon->type != LE_LINK)
		setup_timer(&conn->info_timer, l2cap_info_timeout,
D
Dave Young 已提交
970 971
						(unsigned long) conn);

972 973
	conn->disc_reason = 0x13;

L
Linus Torvalds 已提交
974 975 976
	return conn;
}

977
static void l2cap_conn_del(struct hci_conn *hcon, int err)
L
Linus Torvalds 已提交
978
{
979
	struct l2cap_conn *conn = hcon->l2cap_data;
980
	struct l2cap_chan *chan, *l;
L
Linus Torvalds 已提交
981 982
	struct sock *sk;

983 984
	if (!conn)
		return;
L
Linus Torvalds 已提交
985 986 987

	BT_DBG("hcon %p conn %p, err %d", hcon, conn, err);

988
	kfree_skb(conn->rx_skb);
L
Linus Torvalds 已提交
989 990

	/* Kill channels */
991
	list_for_each_entry_safe(chan, l, &conn->chan_l, list) {
992
		sk = chan->sk;
L
Linus Torvalds 已提交
993
		bh_lock_sock(sk);
994
		l2cap_chan_del(chan, err);
L
Linus Torvalds 已提交
995 996 997 998
		bh_unlock_sock(sk);
		l2cap_sock_kill(sk);
	}

999 1000
	if (conn->info_state & L2CAP_INFO_FEAT_MASK_REQ_SENT)
		del_timer_sync(&conn->info_timer);
1001

L
Linus Torvalds 已提交
1002 1003 1004 1005
	hcon->l2cap_data = NULL;
	kfree(conn);
}

1006
static inline void l2cap_chan_add(struct l2cap_conn *conn, struct l2cap_chan *chan)
L
Linus Torvalds 已提交
1007
{
1008
	write_lock_bh(&conn->chan_lock);
1009
	__l2cap_chan_add(conn, chan);
1010
	write_unlock_bh(&conn->chan_lock);
L
Linus Torvalds 已提交
1011 1012 1013 1014 1015 1016 1017
}

/* ---- Socket interface ---- */

/* Find socket with psm and source bdaddr.
 * Returns closest match.
 */
1018
static struct l2cap_chan *l2cap_global_chan_by_psm(int state, __le16 psm, bdaddr_t *src)
L
Linus Torvalds 已提交
1019
{
1020
	struct l2cap_chan *c, *c1 = NULL;
L
Linus Torvalds 已提交
1021

1022
	read_lock(&chan_list_lock);
1023

1024 1025
	list_for_each_entry(c, &chan_list, global_l) {
		struct sock *sk = c->sk;
1026

L
Linus Torvalds 已提交
1027 1028 1029
		if (state && sk->sk_state != state)
			continue;

1030
		if (c->psm == psm) {
L
Linus Torvalds 已提交
1031
			/* Exact match. */
1032
			if (!bacmp(&bt_sk(sk)->src, src)) {
1033
				read_unlock(&chan_list_lock);
1034 1035
				return c;
			}
L
Linus Torvalds 已提交
1036 1037 1038

			/* Closest match */
			if (!bacmp(&bt_sk(sk)->src, BDADDR_ANY))
1039
				c1 = c;
L
Linus Torvalds 已提交
1040 1041 1042
		}
	}

1043
	read_unlock(&chan_list_lock);
1044

1045
	return c1;
L
Linus Torvalds 已提交
1046 1047
}

1048
int l2cap_chan_connect(struct l2cap_chan *chan)
L
Linus Torvalds 已提交
1049
{
1050
	struct sock *sk = chan->sk;
L
Linus Torvalds 已提交
1051 1052 1053 1054 1055
	bdaddr_t *src = &bt_sk(sk)->src;
	bdaddr_t *dst = &bt_sk(sk)->dst;
	struct l2cap_conn *conn;
	struct hci_conn *hcon;
	struct hci_dev *hdev;
1056
	__u8 auth_type;
1057
	int err;
L
Linus Torvalds 已提交
1058

1059
	BT_DBG("%s -> %s psm 0x%2.2x", batostr(src), batostr(dst),
1060
							chan->psm);
L
Linus Torvalds 已提交
1061

1062 1063
	hdev = hci_get_route(dst, src);
	if (!hdev)
L
Linus Torvalds 已提交
1064 1065 1066 1067
		return -EHOSTUNREACH;

	hci_dev_lock_bh(hdev);

1068
	auth_type = l2cap_get_auth_type(chan);
1069

1070
	if (chan->dcid == L2CAP_CID_LE_DATA)
1071
		hcon = hci_connect(hdev, LE_LINK, dst,
1072
					chan->sec_level, auth_type);
1073 1074
	else
		hcon = hci_connect(hdev, ACL_LINK, dst,
1075
					chan->sec_level, auth_type);
1076

1077 1078
	if (IS_ERR(hcon)) {
		err = PTR_ERR(hcon);
L
Linus Torvalds 已提交
1079
		goto done;
1080
	}
L
Linus Torvalds 已提交
1081 1082 1083 1084

	conn = l2cap_conn_add(hcon, 0);
	if (!conn) {
		hci_conn_put(hcon);
1085
		err = -ENOMEM;
L
Linus Torvalds 已提交
1086 1087 1088 1089 1090 1091
		goto done;
	}

	/* Update source addr of the socket */
	bacpy(src, conn->src);

1092 1093
	l2cap_chan_add(conn, chan);

L
Linus Torvalds 已提交
1094
	sk->sk_state = BT_CONNECT;
1095
	l2cap_chan_set_timer(chan, sk->sk_sndtimeo);
L
Linus Torvalds 已提交
1096 1097

	if (hcon->state == BT_CONNECTED) {
1098
		if (chan->chan_type != L2CAP_CHAN_CONN_ORIENTED) {
1099
			l2cap_chan_clear_timer(chan);
1100
			if (l2cap_check_security(chan))
1101
				sk->sk_state = BT_CONNECTED;
1102
		} else
1103
			l2cap_do_start(chan);
L
Linus Torvalds 已提交
1104 1105
	}

1106 1107
	err = 0;

L
Linus Torvalds 已提交
1108 1109 1110 1111 1112 1113
done:
	hci_dev_unlock_bh(hdev);
	hci_dev_put(hdev);
	return err;
}

1114
int __l2cap_wait_ack(struct sock *sk)
1115
{
1116
	struct l2cap_chan *chan = l2cap_pi(sk)->chan;
1117 1118 1119 1120
	DECLARE_WAITQUEUE(wait, current);
	int err = 0;
	int timeo = HZ/5;

1121
	add_wait_queue(sk_sleep(sk), &wait);
1122
	while ((chan->unacked_frames > 0 && chan->conn)) {
1123 1124 1125 1126 1127 1128 1129 1130 1131 1132 1133 1134 1135 1136 1137 1138 1139 1140 1141
		set_current_state(TASK_INTERRUPTIBLE);

		if (!timeo)
			timeo = HZ/5;

		if (signal_pending(current)) {
			err = sock_intr_errno(timeo);
			break;
		}

		release_sock(sk);
		timeo = schedule_timeout(timeo);
		lock_sock(sk);

		err = sock_error(sk);
		if (err)
			break;
	}
	set_current_state(TASK_RUNNING);
1142
	remove_wait_queue(sk_sleep(sk), &wait);
1143 1144 1145
	return err;
}

1146 1147
static void l2cap_monitor_timeout(unsigned long arg)
{
1148 1149
	struct l2cap_chan *chan = (void *) arg;
	struct sock *sk = chan->sk;
1150

1151
	BT_DBG("chan %p", chan);
1152

1153
	bh_lock_sock(sk);
1154
	if (chan->retry_count >= chan->remote_max_tx) {
1155
		l2cap_send_disconn_req(chan->conn, chan, ECONNABORTED);
1156
		bh_unlock_sock(sk);
1157 1158 1159
		return;
	}

1160
	chan->retry_count++;
1161 1162
	__mod_monitor_timer();

1163
	l2cap_send_rr_or_rnr(chan, L2CAP_CTRL_POLL);
1164
	bh_unlock_sock(sk);
1165 1166 1167 1168
}

static void l2cap_retrans_timeout(unsigned long arg)
{
1169 1170
	struct l2cap_chan *chan = (void *) arg;
	struct sock *sk = chan->sk;
1171

1172
	BT_DBG("chan %p", chan);
1173

1174
	bh_lock_sock(sk);
1175
	chan->retry_count = 1;
1176 1177
	__mod_monitor_timer();

1178
	chan->conn_state |= L2CAP_CONN_WAIT_F;
1179

1180
	l2cap_send_rr_or_rnr(chan, L2CAP_CTRL_POLL);
1181
	bh_unlock_sock(sk);
1182 1183
}

1184
static void l2cap_drop_acked_frames(struct l2cap_chan *chan)
L
Linus Torvalds 已提交
1185
{
1186
	struct sk_buff *skb;
L
Linus Torvalds 已提交
1187

1188
	while ((skb = skb_peek(&chan->tx_q)) &&
1189
			chan->unacked_frames) {
1190
		if (bt_cb(skb)->tx_seq == chan->expected_ack_seq)
1191
			break;
L
Linus Torvalds 已提交
1192

1193
		skb = skb_dequeue(&chan->tx_q);
1194
		kfree_skb(skb);
L
Linus Torvalds 已提交
1195

1196
		chan->unacked_frames--;
1197
	}
L
Linus Torvalds 已提交
1198

1199
	if (!chan->unacked_frames)
1200
		del_timer(&chan->retrans_timer);
1201
}
L
Linus Torvalds 已提交
1202

1203
void l2cap_do_send(struct l2cap_chan *chan, struct sk_buff *skb)
1204
{
1205
	struct hci_conn *hcon = chan->conn->hcon;
1206
	u16 flags;
1207

1208
	BT_DBG("chan %p, skb %p len %d", chan, skb, skb->len);
L
Linus Torvalds 已提交
1209

1210
	if (!chan->flushable && lmp_no_flush_capable(hcon->hdev))
1211 1212 1213 1214
		flags = ACL_START_NO_FLUSH;
	else
		flags = ACL_START;

1215
	bt_cb(skb)->force_active = chan->force_active;
1216
	hci_send_acl(hcon, skb, flags);
1217 1218
}

1219
void l2cap_streaming_send(struct l2cap_chan *chan)
1220
{
1221
	struct sk_buff *skb;
1222
	u16 control, fcs;
1223

1224
	while ((skb = skb_dequeue(&chan->tx_q))) {
1225
		control = get_unaligned_le16(skb->data + L2CAP_HDR_SIZE);
1226
		control |= chan->next_tx_seq << L2CAP_CTRL_TXSEQ_SHIFT;
1227
		put_unaligned_le16(control, skb->data + L2CAP_HDR_SIZE);
1228

1229
		if (chan->fcs == L2CAP_FCS_CRC16) {
1230 1231
			fcs = crc16(0, (u8 *)skb->data, skb->len - 2);
			put_unaligned_le16(fcs, skb->data + skb->len - 2);
1232 1233
		}

1234
		l2cap_do_send(chan, skb);
1235

1236
		chan->next_tx_seq = (chan->next_tx_seq + 1) % 64;
1237 1238 1239
	}
}

1240
static void l2cap_retransmit_one_frame(struct l2cap_chan *chan, u8 tx_seq)
1241 1242 1243 1244
{
	struct sk_buff *skb, *tx_skb;
	u16 control, fcs;

1245
	skb = skb_peek(&chan->tx_q);
1246 1247
	if (!skb)
		return;
1248

1249 1250
	do {
		if (bt_cb(skb)->tx_seq == tx_seq)
1251 1252
			break;

1253
		if (skb_queue_is_last(&chan->tx_q, skb))
1254
			return;
1255

1256
	} while ((skb = skb_queue_next(&chan->tx_q, skb)));
1257

1258 1259
	if (chan->remote_max_tx &&
			bt_cb(skb)->retries == chan->remote_max_tx) {
1260
		l2cap_send_disconn_req(chan->conn, chan, ECONNABORTED);
1261 1262 1263 1264 1265 1266
		return;
	}

	tx_skb = skb_clone(skb, GFP_ATOMIC);
	bt_cb(skb)->retries++;
	control = get_unaligned_le16(tx_skb->data + L2CAP_HDR_SIZE);
1267
	control &= L2CAP_CTRL_SAR;
1268

1269
	if (chan->conn_state & L2CAP_CONN_SEND_FBIT) {
1270
		control |= L2CAP_CTRL_FINAL;
1271
		chan->conn_state &= ~L2CAP_CONN_SEND_FBIT;
1272
	}
1273

1274
	control |= (chan->buffer_seq << L2CAP_CTRL_REQSEQ_SHIFT)
1275
			| (tx_seq << L2CAP_CTRL_TXSEQ_SHIFT);
1276

1277 1278
	put_unaligned_le16(control, tx_skb->data + L2CAP_HDR_SIZE);

1279
	if (chan->fcs == L2CAP_FCS_CRC16) {
1280 1281 1282 1283
		fcs = crc16(0, (u8 *)tx_skb->data, tx_skb->len - 2);
		put_unaligned_le16(fcs, tx_skb->data + tx_skb->len - 2);
	}

1284
	l2cap_do_send(chan, tx_skb);
1285 1286
}

1287
int l2cap_ertm_send(struct l2cap_chan *chan)
1288 1289
{
	struct sk_buff *skb, *tx_skb;
1290
	struct sock *sk = chan->sk;
1291
	u16 control, fcs;
1292
	int nsent = 0;
1293

1294 1295
	if (sk->sk_state != BT_CONNECTED)
		return -ENOTCONN;
1296

1297
	while ((skb = chan->tx_send_head) && (!l2cap_tx_window_full(chan))) {
1298

1299 1300
		if (chan->remote_max_tx &&
				bt_cb(skb)->retries == chan->remote_max_tx) {
1301
			l2cap_send_disconn_req(chan->conn, chan, ECONNABORTED);
1302 1303 1304
			break;
		}

1305 1306
		tx_skb = skb_clone(skb, GFP_ATOMIC);

1307 1308
		bt_cb(skb)->retries++;

1309
		control = get_unaligned_le16(tx_skb->data + L2CAP_HDR_SIZE);
1310 1311
		control &= L2CAP_CTRL_SAR;

1312
		if (chan->conn_state & L2CAP_CONN_SEND_FBIT) {
1313
			control |= L2CAP_CTRL_FINAL;
1314
			chan->conn_state &= ~L2CAP_CONN_SEND_FBIT;
1315
		}
1316 1317
		control |= (chan->buffer_seq << L2CAP_CTRL_REQSEQ_SHIFT)
				| (chan->next_tx_seq << L2CAP_CTRL_TXSEQ_SHIFT);
1318 1319
		put_unaligned_le16(control, tx_skb->data + L2CAP_HDR_SIZE);

1320

1321
		if (chan->fcs == L2CAP_FCS_CRC16) {
1322 1323 1324 1325
			fcs = crc16(0, (u8 *)skb->data, tx_skb->len - 2);
			put_unaligned_le16(fcs, skb->data + tx_skb->len - 2);
		}

1326
		l2cap_do_send(chan, tx_skb);
1327

1328
		__mod_retrans_timer();
1329

1330 1331
		bt_cb(skb)->tx_seq = chan->next_tx_seq;
		chan->next_tx_seq = (chan->next_tx_seq + 1) % 64;
1332

1333
		if (bt_cb(skb)->retries == 1)
1334
			chan->unacked_frames++;
1335

1336
		chan->frames_sent++;
1337

1338 1339
		if (skb_queue_is_last(&chan->tx_q, skb))
			chan->tx_send_head = NULL;
1340
		else
1341
			chan->tx_send_head = skb_queue_next(&chan->tx_q, skb);
1342 1343

		nsent++;
1344 1345
	}

1346 1347 1348
	return nsent;
}

1349
static int l2cap_retransmit_frames(struct l2cap_chan *chan)
1350 1351 1352
{
	int ret;

1353 1354
	if (!skb_queue_empty(&chan->tx_q))
		chan->tx_send_head = chan->tx_q.next;
1355

1356
	chan->next_tx_seq = chan->expected_ack_seq;
1357
	ret = l2cap_ertm_send(chan);
1358 1359 1360
	return ret;
}

1361
static void l2cap_send_ack(struct l2cap_chan *chan)
1362 1363 1364
{
	u16 control = 0;

1365
	control |= chan->buffer_seq << L2CAP_CTRL_REQSEQ_SHIFT;
1366

1367
	if (chan->conn_state & L2CAP_CONN_LOCAL_BUSY) {
1368
		control |= L2CAP_SUPER_RCV_NOT_READY;
1369 1370
		chan->conn_state |= L2CAP_CONN_RNR_SENT;
		l2cap_send_sframe(chan, control);
1371
		return;
1372
	}
1373

1374
	if (l2cap_ertm_send(chan) > 0)
1375 1376 1377
		return;

	control |= L2CAP_SUPER_RCV_READY;
1378
	l2cap_send_sframe(chan, control);
1379 1380
}

1381
static void l2cap_send_srejtail(struct l2cap_chan *chan)
1382 1383 1384 1385 1386 1387 1388
{
	struct srej_list *tail;
	u16 control;

	control = L2CAP_SUPER_SELECT_REJECT;
	control |= L2CAP_CTRL_FINAL;

1389
	tail = list_entry((&chan->srej_l)->prev, struct srej_list, list);
1390 1391
	control |= tail->tx_seq << L2CAP_CTRL_REQSEQ_SHIFT;

1392
	l2cap_send_sframe(chan, control);
1393 1394
}

1395 1396
static inline int l2cap_skbuff_fromiovec(struct sock *sk, struct msghdr *msg, int len, int count, struct sk_buff *skb)
{
1397
	struct l2cap_conn *conn = l2cap_pi(sk)->chan->conn;
1398 1399
	struct sk_buff **frag;
	int err, sent = 0;
L
Linus Torvalds 已提交
1400

1401
	if (memcpy_fromiovec(skb_put(skb, count), msg->msg_iov, count))
1402
		return -EFAULT;
L
Linus Torvalds 已提交
1403 1404 1405 1406 1407 1408 1409 1410 1411 1412 1413

	sent += count;
	len  -= count;

	/* Continuation fragments (no L2CAP header) */
	frag = &skb_shinfo(skb)->frag_list;
	while (len) {
		count = min_t(unsigned int, conn->mtu, len);

		*frag = bt_skb_send_alloc(sk, count, msg->msg_flags & MSG_DONTWAIT, &err);
		if (!*frag)
1414
			return err;
1415 1416
		if (memcpy_fromiovec(skb_put(*frag, count), msg->msg_iov, count))
			return -EFAULT;
L
Linus Torvalds 已提交
1417 1418 1419 1420 1421 1422 1423 1424

		sent += count;
		len  -= count;

		frag = &(*frag)->next;
	}

	return sent;
1425
}
L
Linus Torvalds 已提交
1426

1427
struct sk_buff *l2cap_create_connless_pdu(struct l2cap_chan *chan, struct msghdr *msg, size_t len)
1428
{
1429
	struct sock *sk = chan->sk;
1430
	struct l2cap_conn *conn = chan->conn;
1431 1432 1433 1434 1435 1436 1437 1438 1439 1440
	struct sk_buff *skb;
	int err, count, hlen = L2CAP_HDR_SIZE + 2;
	struct l2cap_hdr *lh;

	BT_DBG("sk %p len %d", sk, (int)len);

	count = min_t(unsigned int, (conn->mtu - hlen), len);
	skb = bt_skb_send_alloc(sk, count + hlen,
			msg->msg_flags & MSG_DONTWAIT, &err);
	if (!skb)
1441
		return ERR_PTR(err);
1442 1443 1444

	/* Create L2CAP header */
	lh = (struct l2cap_hdr *) skb_put(skb, L2CAP_HDR_SIZE);
1445
	lh->cid = cpu_to_le16(chan->dcid);
1446
	lh->len = cpu_to_le16(len + (hlen - L2CAP_HDR_SIZE));
1447
	put_unaligned_le16(chan->psm, skb_put(skb, 2));
1448 1449 1450 1451 1452 1453 1454 1455 1456

	err = l2cap_skbuff_fromiovec(sk, msg, len, count, skb);
	if (unlikely(err < 0)) {
		kfree_skb(skb);
		return ERR_PTR(err);
	}
	return skb;
}

1457
struct sk_buff *l2cap_create_basic_pdu(struct l2cap_chan *chan, struct msghdr *msg, size_t len)
1458
{
1459
	struct sock *sk = chan->sk;
1460
	struct l2cap_conn *conn = chan->conn;
1461 1462 1463 1464 1465 1466 1467 1468 1469 1470
	struct sk_buff *skb;
	int err, count, hlen = L2CAP_HDR_SIZE;
	struct l2cap_hdr *lh;

	BT_DBG("sk %p len %d", sk, (int)len);

	count = min_t(unsigned int, (conn->mtu - hlen), len);
	skb = bt_skb_send_alloc(sk, count + hlen,
			msg->msg_flags & MSG_DONTWAIT, &err);
	if (!skb)
1471
		return ERR_PTR(err);
1472 1473 1474

	/* Create L2CAP header */
	lh = (struct l2cap_hdr *) skb_put(skb, L2CAP_HDR_SIZE);
1475
	lh->cid = cpu_to_le16(chan->dcid);
1476 1477 1478 1479 1480 1481 1482 1483 1484 1485
	lh->len = cpu_to_le16(len + (hlen - L2CAP_HDR_SIZE));

	err = l2cap_skbuff_fromiovec(sk, msg, len, count, skb);
	if (unlikely(err < 0)) {
		kfree_skb(skb);
		return ERR_PTR(err);
	}
	return skb;
}

1486
struct sk_buff *l2cap_create_iframe_pdu(struct l2cap_chan *chan, struct msghdr *msg, size_t len, u16 control, u16 sdulen)
1487
{
1488
	struct sock *sk = chan->sk;
1489
	struct l2cap_conn *conn = chan->conn;
1490 1491 1492 1493 1494 1495
	struct sk_buff *skb;
	int err, count, hlen = L2CAP_HDR_SIZE + 2;
	struct l2cap_hdr *lh;

	BT_DBG("sk %p len %d", sk, (int)len);

1496 1497 1498
	if (!conn)
		return ERR_PTR(-ENOTCONN);

1499 1500 1501
	if (sdulen)
		hlen += 2;

1502
	if (chan->fcs == L2CAP_FCS_CRC16)
1503 1504
		hlen += 2;

1505 1506 1507 1508
	count = min_t(unsigned int, (conn->mtu - hlen), len);
	skb = bt_skb_send_alloc(sk, count + hlen,
			msg->msg_flags & MSG_DONTWAIT, &err);
	if (!skb)
1509
		return ERR_PTR(err);
1510 1511 1512

	/* Create L2CAP header */
	lh = (struct l2cap_hdr *) skb_put(skb, L2CAP_HDR_SIZE);
1513
	lh->cid = cpu_to_le16(chan->dcid);
1514 1515
	lh->len = cpu_to_le16(len + (hlen - L2CAP_HDR_SIZE));
	put_unaligned_le16(control, skb_put(skb, 2));
1516 1517
	if (sdulen)
		put_unaligned_le16(sdulen, skb_put(skb, 2));
1518 1519 1520 1521 1522 1523

	err = l2cap_skbuff_fromiovec(sk, msg, len, count, skb);
	if (unlikely(err < 0)) {
		kfree_skb(skb);
		return ERR_PTR(err);
	}
1524

1525
	if (chan->fcs == L2CAP_FCS_CRC16)
1526 1527
		put_unaligned_le16(0, skb_put(skb, 2));

1528
	bt_cb(skb)->retries = 0;
1529
	return skb;
L
Linus Torvalds 已提交
1530 1531
}

1532
int l2cap_sar_segment_sdu(struct l2cap_chan *chan, struct msghdr *msg, size_t len)
1533 1534 1535 1536 1537 1538
{
	struct sk_buff *skb;
	struct sk_buff_head sar_queue;
	u16 control;
	size_t size = 0;

1539
	skb_queue_head_init(&sar_queue);
1540
	control = L2CAP_SDU_START;
1541
	skb = l2cap_create_iframe_pdu(chan, msg, chan->remote_mps, control, len);
1542 1543 1544 1545
	if (IS_ERR(skb))
		return PTR_ERR(skb);

	__skb_queue_tail(&sar_queue, skb);
1546 1547
	len -= chan->remote_mps;
	size += chan->remote_mps;
1548 1549 1550 1551

	while (len > 0) {
		size_t buflen;

1552
		if (len > chan->remote_mps) {
1553
			control = L2CAP_SDU_CONTINUE;
1554
			buflen = chan->remote_mps;
1555
		} else {
1556
			control = L2CAP_SDU_END;
1557 1558 1559
			buflen = len;
		}

1560
		skb = l2cap_create_iframe_pdu(chan, msg, buflen, control, 0);
1561 1562 1563 1564 1565 1566 1567 1568 1569
		if (IS_ERR(skb)) {
			skb_queue_purge(&sar_queue);
			return PTR_ERR(skb);
		}

		__skb_queue_tail(&sar_queue, skb);
		len -= buflen;
		size += buflen;
	}
1570 1571 1572
	skb_queue_splice_tail(&sar_queue, &chan->tx_q);
	if (chan->tx_send_head == NULL)
		chan->tx_send_head = sar_queue.next;
1573 1574 1575 1576

	return size;
}

1577 1578 1579 1580 1581 1582 1583
int l2cap_chan_send(struct l2cap_chan *chan, struct msghdr *msg, size_t len)
{
	struct sk_buff *skb;
	u16 control;
	int err;

	/* Connectionless channel */
1584
	if (chan->chan_type == L2CAP_CHAN_CONN_LESS) {
1585 1586 1587 1588 1589 1590 1591 1592 1593 1594 1595 1596 1597 1598 1599 1600 1601 1602 1603 1604 1605 1606 1607 1608 1609 1610 1611 1612 1613 1614 1615 1616 1617 1618 1619 1620 1621 1622 1623 1624 1625 1626 1627 1628 1629 1630 1631 1632 1633 1634 1635 1636 1637 1638 1639 1640 1641 1642 1643 1644 1645 1646 1647 1648 1649 1650 1651 1652 1653 1654 1655
		skb = l2cap_create_connless_pdu(chan, msg, len);
		if (IS_ERR(skb))
			return PTR_ERR(skb);

		l2cap_do_send(chan, skb);
		return len;
	}

	switch (chan->mode) {
	case L2CAP_MODE_BASIC:
		/* Check outgoing MTU */
		if (len > chan->omtu)
			return -EMSGSIZE;

		/* Create a basic PDU */
		skb = l2cap_create_basic_pdu(chan, msg, len);
		if (IS_ERR(skb))
			return PTR_ERR(skb);

		l2cap_do_send(chan, skb);
		err = len;
		break;

	case L2CAP_MODE_ERTM:
	case L2CAP_MODE_STREAMING:
		/* Entire SDU fits into one PDU */
		if (len <= chan->remote_mps) {
			control = L2CAP_SDU_UNSEGMENTED;
			skb = l2cap_create_iframe_pdu(chan, msg, len, control,
									0);
			if (IS_ERR(skb))
				return PTR_ERR(skb);

			__skb_queue_tail(&chan->tx_q, skb);

			if (chan->tx_send_head == NULL)
				chan->tx_send_head = skb;

		} else {
			/* Segment SDU into multiples PDUs */
			err = l2cap_sar_segment_sdu(chan, msg, len);
			if (err < 0)
				return err;
		}

		if (chan->mode == L2CAP_MODE_STREAMING) {
			l2cap_streaming_send(chan);
			err = len;
			break;
		}

		if ((chan->conn_state & L2CAP_CONN_REMOTE_BUSY) &&
				(chan->conn_state & L2CAP_CONN_WAIT_F)) {
			err = len;
			break;
		}

		err = l2cap_ertm_send(chan);
		if (err >= 0)
			err = len;

		break;

	default:
		BT_DBG("bad state %1.1x", chan->mode);
		err = -EBADFD;
	}

	return err;
}

L
Linus Torvalds 已提交
1656 1657 1658
static void l2cap_chan_ready(struct sock *sk)
{
	struct sock *parent = bt_sk(sk)->parent;
1659
	struct l2cap_chan *chan = l2cap_pi(sk)->chan;
L
Linus Torvalds 已提交
1660 1661 1662

	BT_DBG("sk %p, parent %p", sk, parent);

1663
	chan->conf_state = 0;
1664
	l2cap_chan_clear_timer(chan);
L
Linus Torvalds 已提交
1665 1666 1667 1668 1669 1670 1671 1672 1673 1674 1675 1676 1677 1678 1679 1680 1681 1682 1683

	if (!parent) {
		/* Outgoing channel.
		 * Wake up socket sleeping on connect.
		 */
		sk->sk_state = BT_CONNECTED;
		sk->sk_state_change(sk);
	} else {
		/* Incoming channel.
		 * Wake up socket sleeping on accept.
		 */
		parent->sk_data_ready(parent, 0);
	}
}

/* Copy frame to all raw sockets on that connection */
static void l2cap_raw_recv(struct l2cap_conn *conn, struct sk_buff *skb)
{
	struct sk_buff *nskb;
1684
	struct l2cap_chan *chan;
L
Linus Torvalds 已提交
1685 1686 1687

	BT_DBG("conn %p", conn);

1688 1689
	read_lock(&conn->chan_lock);
	list_for_each_entry(chan, &conn->chan_l, list) {
1690
		struct sock *sk = chan->sk;
1691
		if (chan->chan_type != L2CAP_CHAN_RAW)
L
Linus Torvalds 已提交
1692 1693 1694 1695 1696
			continue;

		/* Don't send frame to the socket it came from */
		if (skb->sk == sk)
			continue;
1697 1698
		nskb = skb_clone(skb, GFP_ATOMIC);
		if (!nskb)
L
Linus Torvalds 已提交
1699 1700 1701 1702 1703
			continue;

		if (sock_queue_rcv_skb(sk, nskb))
			kfree_skb(nskb);
	}
1704
	read_unlock(&conn->chan_lock);
L
Linus Torvalds 已提交
1705 1706 1707 1708 1709 1710 1711 1712 1713 1714 1715
}

/* ---- L2CAP signalling commands ---- */
static struct sk_buff *l2cap_build_cmd(struct l2cap_conn *conn,
				u8 code, u8 ident, u16 dlen, void *data)
{
	struct sk_buff *skb, **frag;
	struct l2cap_cmd_hdr *cmd;
	struct l2cap_hdr *lh;
	int len, count;

1716 1717
	BT_DBG("conn %p, code 0x%2.2x, ident 0x%2.2x, len %d",
			conn, code, ident, dlen);
L
Linus Torvalds 已提交
1718 1719 1720 1721 1722 1723 1724 1725 1726

	len = L2CAP_HDR_SIZE + L2CAP_CMD_HDR_SIZE + dlen;
	count = min_t(unsigned int, conn->mtu, len);

	skb = bt_skb_alloc(count, GFP_ATOMIC);
	if (!skb)
		return NULL;

	lh = (struct l2cap_hdr *) skb_put(skb, L2CAP_HDR_SIZE);
1727
	lh->len = cpu_to_le16(L2CAP_CMD_HDR_SIZE + dlen);
1728 1729 1730 1731 1732

	if (conn->hcon->type == LE_LINK)
		lh->cid = cpu_to_le16(L2CAP_CID_LE_SIGNALING);
	else
		lh->cid = cpu_to_le16(L2CAP_CID_SIGNALING);
L
Linus Torvalds 已提交
1733 1734 1735 1736

	cmd = (struct l2cap_cmd_hdr *) skb_put(skb, L2CAP_CMD_HDR_SIZE);
	cmd->code  = code;
	cmd->ident = ident;
1737
	cmd->len   = cpu_to_le16(dlen);
L
Linus Torvalds 已提交
1738 1739 1740 1741 1742 1743 1744 1745 1746 1747 1748 1749 1750 1751 1752 1753 1754 1755 1756 1757 1758 1759 1760 1761 1762 1763 1764 1765 1766 1767 1768 1769 1770 1771 1772 1773 1774 1775 1776 1777 1778 1779 1780 1781 1782 1783 1784 1785 1786 1787

	if (dlen) {
		count -= L2CAP_HDR_SIZE + L2CAP_CMD_HDR_SIZE;
		memcpy(skb_put(skb, count), data, count);
		data += count;
	}

	len -= skb->len;

	/* Continuation fragments (no L2CAP header) */
	frag = &skb_shinfo(skb)->frag_list;
	while (len) {
		count = min_t(unsigned int, conn->mtu, len);

		*frag = bt_skb_alloc(count, GFP_ATOMIC);
		if (!*frag)
			goto fail;

		memcpy(skb_put(*frag, count), data, count);

		len  -= count;
		data += count;

		frag = &(*frag)->next;
	}

	return skb;

fail:
	kfree_skb(skb);
	return NULL;
}

static inline int l2cap_get_conf_opt(void **ptr, int *type, int *olen, unsigned long *val)
{
	struct l2cap_conf_opt *opt = *ptr;
	int len;

	len = L2CAP_CONF_OPT_SIZE + opt->len;
	*ptr += len;

	*type = opt->type;
	*olen = opt->len;

	switch (opt->len) {
	case 1:
		*val = *((u8 *) opt->val);
		break;

	case 2:
1788
		*val = get_unaligned_le16(opt->val);
L
Linus Torvalds 已提交
1789 1790 1791
		break;

	case 4:
1792
		*val = get_unaligned_le32(opt->val);
L
Linus Torvalds 已提交
1793 1794 1795 1796 1797 1798 1799 1800 1801 1802 1803 1804 1805 1806 1807 1808 1809 1810 1811 1812 1813 1814 1815 1816 1817 1818
		break;

	default:
		*val = (unsigned long) opt->val;
		break;
	}

	BT_DBG("type 0x%2.2x len %d val 0x%lx", *type, opt->len, *val);
	return len;
}

static void l2cap_add_conf_opt(void **ptr, u8 type, u8 len, unsigned long val)
{
	struct l2cap_conf_opt *opt = *ptr;

	BT_DBG("type 0x%2.2x len %d val 0x%lx", type, len, val);

	opt->type = type;
	opt->len  = len;

	switch (len) {
	case 1:
		*((u8 *) opt->val)  = val;
		break;

	case 2:
1819
		put_unaligned_le16(val, opt->val);
L
Linus Torvalds 已提交
1820 1821 1822
		break;

	case 4:
1823
		put_unaligned_le32(val, opt->val);
L
Linus Torvalds 已提交
1824 1825 1826 1827 1828 1829 1830 1831 1832 1833
		break;

	default:
		memcpy(opt->val, (void *) val, len);
		break;
	}

	*ptr += L2CAP_CONF_OPT_SIZE + len;
}

1834 1835
static void l2cap_ack_timeout(unsigned long arg)
{
1836
	struct l2cap_chan *chan = (void *) arg;
1837

1838 1839 1840
	bh_lock_sock(chan->sk);
	l2cap_send_ack(chan);
	bh_unlock_sock(chan->sk);
1841 1842
}

1843
static inline void l2cap_ertm_init(struct l2cap_chan *chan)
1844
{
1845 1846
	struct sock *sk = chan->sk;

1847
	chan->expected_ack_seq = 0;
1848
	chan->unacked_frames = 0;
1849
	chan->buffer_seq = 0;
1850 1851
	chan->num_acked = 0;
	chan->frames_sent = 0;
1852

1853 1854 1855 1856 1857
	setup_timer(&chan->retrans_timer, l2cap_retrans_timeout,
							(unsigned long) chan);
	setup_timer(&chan->monitor_timer, l2cap_monitor_timeout,
							(unsigned long) chan);
	setup_timer(&chan->ack_timer, l2cap_ack_timeout, (unsigned long) chan);
1858

1859 1860
	skb_queue_head_init(&chan->srej_q);
	skb_queue_head_init(&chan->busy_q);
1861

1862 1863
	INIT_LIST_HEAD(&chan->srej_l);

1864
	INIT_WORK(&chan->busy_work, l2cap_busy_work);
1865 1866

	sk->sk_backlog_rcv = l2cap_ertm_data_rcv;
1867 1868
}

1869 1870 1871 1872 1873 1874 1875 1876 1877 1878 1879 1880 1881
static inline __u8 l2cap_select_mode(__u8 mode, __u16 remote_feat_mask)
{
	switch (mode) {
	case L2CAP_MODE_STREAMING:
	case L2CAP_MODE_ERTM:
		if (l2cap_mode_supported(mode, remote_feat_mask))
			return mode;
		/* fall through */
	default:
		return L2CAP_MODE_BASIC;
	}
}

1882
static int l2cap_build_conf_req(struct l2cap_chan *chan, void *data)
L
Linus Torvalds 已提交
1883 1884
{
	struct l2cap_conf_req *req = data;
1885
	struct l2cap_conf_rfc rfc = { .mode = chan->mode };
L
Linus Torvalds 已提交
1886 1887
	void *ptr = req->data;

1888
	BT_DBG("chan %p", chan);
L
Linus Torvalds 已提交
1889

1890
	if (chan->num_conf_req || chan->num_conf_rsp)
1891 1892
		goto done;

1893
	switch (chan->mode) {
1894 1895
	case L2CAP_MODE_STREAMING:
	case L2CAP_MODE_ERTM:
1896
		if (chan->conf_state & L2CAP_CONF_STATE2_DEVICE)
1897 1898
			break;

1899
		/* fall through */
1900
	default:
1901
		chan->mode = l2cap_select_mode(rfc.mode, chan->conn->feat_mask);
1902 1903 1904 1905
		break;
	}

done:
1906 1907
	if (chan->imtu != L2CAP_DEFAULT_MTU)
		l2cap_add_conf_opt(&ptr, L2CAP_CONF_MTU, 2, chan->imtu);
1908

1909
	switch (chan->mode) {
1910
	case L2CAP_MODE_BASIC:
1911 1912
		if (!(chan->conn->feat_mask & L2CAP_FEAT_ERTM) &&
				!(chan->conn->feat_mask & L2CAP_FEAT_STREAMING))
1913 1914
			break;

1915 1916 1917 1918 1919 1920 1921
		rfc.mode            = L2CAP_MODE_BASIC;
		rfc.txwin_size      = 0;
		rfc.max_transmit    = 0;
		rfc.retrans_timeout = 0;
		rfc.monitor_timeout = 0;
		rfc.max_pdu_size    = 0;

1922 1923
		l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC, sizeof(rfc),
							(unsigned long) &rfc);
1924 1925 1926 1927
		break;

	case L2CAP_MODE_ERTM:
		rfc.mode            = L2CAP_MODE_ERTM;
1928 1929
		rfc.txwin_size      = chan->tx_win;
		rfc.max_transmit    = chan->max_tx;
1930 1931
		rfc.retrans_timeout = 0;
		rfc.monitor_timeout = 0;
1932
		rfc.max_pdu_size    = cpu_to_le16(L2CAP_DEFAULT_MAX_PDU_SIZE);
1933 1934
		if (L2CAP_DEFAULT_MAX_PDU_SIZE > chan->conn->mtu - 10)
			rfc.max_pdu_size = cpu_to_le16(chan->conn->mtu - 10);
1935

1936 1937 1938
		l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC, sizeof(rfc),
							(unsigned long) &rfc);

1939
		if (!(chan->conn->feat_mask & L2CAP_FEAT_FCS))
1940 1941
			break;

1942
		if (chan->fcs == L2CAP_FCS_NONE ||
1943
				chan->conf_state & L2CAP_CONF_NO_FCS_RECV) {
1944 1945
			chan->fcs = L2CAP_FCS_NONE;
			l2cap_add_conf_opt(&ptr, L2CAP_CONF_FCS, 1, chan->fcs);
1946
		}
1947 1948 1949 1950 1951 1952 1953 1954
		break;

	case L2CAP_MODE_STREAMING:
		rfc.mode            = L2CAP_MODE_STREAMING;
		rfc.txwin_size      = 0;
		rfc.max_transmit    = 0;
		rfc.retrans_timeout = 0;
		rfc.monitor_timeout = 0;
1955
		rfc.max_pdu_size    = cpu_to_le16(L2CAP_DEFAULT_MAX_PDU_SIZE);
1956 1957
		if (L2CAP_DEFAULT_MAX_PDU_SIZE > chan->conn->mtu - 10)
			rfc.max_pdu_size = cpu_to_le16(chan->conn->mtu - 10);
1958

1959 1960 1961
		l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC, sizeof(rfc),
							(unsigned long) &rfc);

1962
		if (!(chan->conn->feat_mask & L2CAP_FEAT_FCS))
1963 1964
			break;

1965
		if (chan->fcs == L2CAP_FCS_NONE ||
1966
				chan->conf_state & L2CAP_CONF_NO_FCS_RECV) {
1967 1968
			chan->fcs = L2CAP_FCS_NONE;
			l2cap_add_conf_opt(&ptr, L2CAP_CONF_FCS, 1, chan->fcs);
1969
		}
1970 1971
		break;
	}
L
Linus Torvalds 已提交
1972

1973
	req->dcid  = cpu_to_le16(chan->dcid);
1974
	req->flags = cpu_to_le16(0);
L
Linus Torvalds 已提交
1975 1976 1977 1978

	return ptr - data;
}

1979
static int l2cap_parse_conf_req(struct l2cap_chan *chan, void *data)
L
Linus Torvalds 已提交
1980
{
1981 1982
	struct l2cap_conf_rsp *rsp = data;
	void *ptr = rsp->data;
1983 1984
	void *req = chan->conf_req;
	int len = chan->conf_len;
1985 1986
	int type, hint, olen;
	unsigned long val;
1987
	struct l2cap_conf_rfc rfc = { .mode = L2CAP_MODE_BASIC };
1988
	u16 mtu = L2CAP_DEFAULT_MTU;
1989
	u16 result = L2CAP_CONF_SUCCESS;
L
Linus Torvalds 已提交
1990

1991
	BT_DBG("chan %p", chan);
1992

1993 1994
	while (len >= L2CAP_CONF_OPT_SIZE) {
		len -= l2cap_get_conf_opt(&req, &type, &olen, &val);
L
Linus Torvalds 已提交
1995

1996
		hint  = type & L2CAP_CONF_HINT;
1997
		type &= L2CAP_CONF_MASK;
1998 1999 2000

		switch (type) {
		case L2CAP_CONF_MTU:
2001
			mtu = val;
2002 2003 2004
			break;

		case L2CAP_CONF_FLUSH_TO:
2005
			chan->flush_to = val;
2006 2007 2008 2009 2010
			break;

		case L2CAP_CONF_QOS:
			break;

2011 2012 2013 2014 2015
		case L2CAP_CONF_RFC:
			if (olen == sizeof(rfc))
				memcpy(&rfc, (void *) val, olen);
			break;

2016 2017
		case L2CAP_CONF_FCS:
			if (val == L2CAP_FCS_NONE)
2018
				chan->conf_state |= L2CAP_CONF_NO_FCS_RECV;
2019 2020 2021

			break;

2022 2023 2024 2025 2026 2027 2028 2029 2030 2031
		default:
			if (hint)
				break;

			result = L2CAP_CONF_UNKNOWN;
			*((u8 *) ptr++) = type;
			break;
		}
	}

2032
	if (chan->num_conf_rsp || chan->num_conf_req > 1)
2033 2034
		goto done;

2035
	switch (chan->mode) {
2036 2037
	case L2CAP_MODE_STREAMING:
	case L2CAP_MODE_ERTM:
2038
		if (!(chan->conf_state & L2CAP_CONF_STATE2_DEVICE)) {
2039
			chan->mode = l2cap_select_mode(rfc.mode,
2040
					chan->conn->feat_mask);
2041 2042 2043
			break;
		}

2044
		if (chan->mode != rfc.mode)
2045
			return -ECONNREFUSED;
2046

2047 2048 2049 2050
		break;
	}

done:
2051
	if (chan->mode != rfc.mode) {
2052
		result = L2CAP_CONF_UNACCEPT;
2053
		rfc.mode = chan->mode;
2054

2055
		if (chan->num_conf_rsp == 1)
2056 2057 2058 2059 2060 2061 2062
			return -ECONNREFUSED;

		l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC,
					sizeof(rfc), (unsigned long) &rfc);
	}


2063 2064 2065 2066
	if (result == L2CAP_CONF_SUCCESS) {
		/* Configure output options and let the other side know
		 * which ones we don't like. */

2067 2068 2069
		if (mtu < L2CAP_DEFAULT_MIN_MTU)
			result = L2CAP_CONF_UNACCEPT;
		else {
2070
			chan->omtu = mtu;
2071
			chan->conf_state |= L2CAP_CONF_MTU_DONE;
2072
		}
2073
		l2cap_add_conf_opt(&ptr, L2CAP_CONF_MTU, 2, chan->omtu);
2074

2075 2076
		switch (rfc.mode) {
		case L2CAP_MODE_BASIC:
2077
			chan->fcs = L2CAP_FCS_NONE;
2078
			chan->conf_state |= L2CAP_CONF_MODE_DONE;
2079 2080 2081
			break;

		case L2CAP_MODE_ERTM:
2082 2083
			chan->remote_tx_win = rfc.txwin_size;
			chan->remote_max_tx = rfc.max_transmit;
2084

2085 2086
			if (le16_to_cpu(rfc.max_pdu_size) > chan->conn->mtu - 10)
				rfc.max_pdu_size = cpu_to_le16(chan->conn->mtu - 10);
2087

2088
			chan->remote_mps = le16_to_cpu(rfc.max_pdu_size);
2089

2090 2091 2092 2093
			rfc.retrans_timeout =
				le16_to_cpu(L2CAP_DEFAULT_RETRANS_TO);
			rfc.monitor_timeout =
				le16_to_cpu(L2CAP_DEFAULT_MONITOR_TO);
2094

2095
			chan->conf_state |= L2CAP_CONF_MODE_DONE;
2096 2097 2098 2099

			l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC,
					sizeof(rfc), (unsigned long) &rfc);

2100 2101 2102
			break;

		case L2CAP_MODE_STREAMING:
2103 2104
			if (le16_to_cpu(rfc.max_pdu_size) > chan->conn->mtu - 10)
				rfc.max_pdu_size = cpu_to_le16(chan->conn->mtu - 10);
2105

2106
			chan->remote_mps = le16_to_cpu(rfc.max_pdu_size);
2107

2108
			chan->conf_state |= L2CAP_CONF_MODE_DONE;
2109 2110 2111 2112

			l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC,
					sizeof(rfc), (unsigned long) &rfc);

2113 2114 2115
			break;

		default:
2116 2117
			result = L2CAP_CONF_UNACCEPT;

2118
			memset(&rfc, 0, sizeof(rfc));
2119
			rfc.mode = chan->mode;
2120
		}
2121

2122
		if (result == L2CAP_CONF_SUCCESS)
2123
			chan->conf_state |= L2CAP_CONF_OUTPUT_DONE;
2124
	}
2125
	rsp->scid   = cpu_to_le16(chan->dcid);
2126 2127 2128 2129
	rsp->result = cpu_to_le16(result);
	rsp->flags  = cpu_to_le16(0x0000);

	return ptr - data;
L
Linus Torvalds 已提交
2130 2131
}

2132
static int l2cap_parse_conf_rsp(struct l2cap_chan *chan, void *rsp, int len, void *data, u16 *result)
2133 2134 2135 2136 2137 2138 2139
{
	struct l2cap_conf_req *req = data;
	void *ptr = req->data;
	int type, olen;
	unsigned long val;
	struct l2cap_conf_rfc rfc;

2140
	BT_DBG("chan %p, rsp %p, len %d, req %p", chan, rsp, len, data);
2141 2142 2143 2144 2145 2146 2147 2148

	while (len >= L2CAP_CONF_OPT_SIZE) {
		len -= l2cap_get_conf_opt(&rsp, &type, &olen, &val);

		switch (type) {
		case L2CAP_CONF_MTU:
			if (val < L2CAP_DEFAULT_MIN_MTU) {
				*result = L2CAP_CONF_UNACCEPT;
2149
				chan->imtu = L2CAP_DEFAULT_MIN_MTU;
2150
			} else
2151 2152
				chan->imtu = val;
			l2cap_add_conf_opt(&ptr, L2CAP_CONF_MTU, 2, chan->imtu);
2153 2154 2155
			break;

		case L2CAP_CONF_FLUSH_TO:
2156
			chan->flush_to = val;
2157
			l2cap_add_conf_opt(&ptr, L2CAP_CONF_FLUSH_TO,
2158
							2, chan->flush_to);
2159 2160 2161 2162 2163 2164
			break;

		case L2CAP_CONF_RFC:
			if (olen == sizeof(rfc))
				memcpy(&rfc, (void *)val, olen);

2165
			if ((chan->conf_state & L2CAP_CONF_STATE2_DEVICE) &&
2166
							rfc.mode != chan->mode)
2167 2168
				return -ECONNREFUSED;

2169
			chan->fcs = 0;
2170 2171 2172 2173 2174 2175 2176

			l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC,
					sizeof(rfc), (unsigned long) &rfc);
			break;
		}
	}

2177
	if (chan->mode == L2CAP_MODE_BASIC && chan->mode != rfc.mode)
2178 2179
		return -ECONNREFUSED;

2180
	chan->mode = rfc.mode;
2181

2182 2183 2184
	if (*result == L2CAP_CONF_SUCCESS) {
		switch (rfc.mode) {
		case L2CAP_MODE_ERTM:
2185 2186 2187
			chan->retrans_timeout = le16_to_cpu(rfc.retrans_timeout);
			chan->monitor_timeout = le16_to_cpu(rfc.monitor_timeout);
			chan->mps    = le16_to_cpu(rfc.max_pdu_size);
2188 2189
			break;
		case L2CAP_MODE_STREAMING:
2190
			chan->mps    = le16_to_cpu(rfc.max_pdu_size);
2191 2192 2193
		}
	}

2194
	req->dcid   = cpu_to_le16(chan->dcid);
2195 2196 2197 2198 2199
	req->flags  = cpu_to_le16(0x0000);

	return ptr - data;
}

2200
static int l2cap_build_conf_rsp(struct l2cap_chan *chan, void *data, u16 result, u16 flags)
L
Linus Torvalds 已提交
2201 2202 2203 2204
{
	struct l2cap_conf_rsp *rsp = data;
	void *ptr = rsp->data;

2205
	BT_DBG("chan %p", chan);
L
Linus Torvalds 已提交
2206

2207
	rsp->scid   = cpu_to_le16(chan->dcid);
2208
	rsp->result = cpu_to_le16(result);
2209
	rsp->flags  = cpu_to_le16(flags);
L
Linus Torvalds 已提交
2210 2211 2212 2213

	return ptr - data;
}

2214
void __l2cap_connect_rsp_defer(struct l2cap_chan *chan)
2215 2216
{
	struct l2cap_conn_rsp rsp;
2217
	struct l2cap_conn *conn = chan->conn;
2218 2219
	u8 buf[128];

2220 2221
	rsp.scid   = cpu_to_le16(chan->dcid);
	rsp.dcid   = cpu_to_le16(chan->scid);
2222 2223 2224 2225 2226
	rsp.result = cpu_to_le16(L2CAP_CR_SUCCESS);
	rsp.status = cpu_to_le16(L2CAP_CS_NO_INFO);
	l2cap_send_cmd(conn, chan->ident,
				L2CAP_CONN_RSP, sizeof(rsp), &rsp);

2227
	if (chan->conf_state & L2CAP_CONF_REQ_SENT)
2228 2229
		return;

2230
	chan->conf_state |= L2CAP_CONF_REQ_SENT;
2231 2232 2233 2234 2235
	l2cap_send_cmd(conn, l2cap_get_ident(conn), L2CAP_CONF_REQ,
			l2cap_build_conf_req(chan, buf), buf);
	chan->num_conf_req++;
}

2236
static void l2cap_conf_rfc_get(struct l2cap_chan *chan, void *rsp, int len)
2237 2238 2239 2240 2241
{
	int type, olen;
	unsigned long val;
	struct l2cap_conf_rfc rfc;

2242
	BT_DBG("chan %p, rsp %p, len %d", chan, rsp, len);
2243

2244
	if ((chan->mode != L2CAP_MODE_ERTM) && (chan->mode != L2CAP_MODE_STREAMING))
2245 2246 2247 2248 2249 2250 2251 2252 2253 2254 2255 2256 2257 2258 2259 2260
		return;

	while (len >= L2CAP_CONF_OPT_SIZE) {
		len -= l2cap_get_conf_opt(&rsp, &type, &olen, &val);

		switch (type) {
		case L2CAP_CONF_RFC:
			if (olen == sizeof(rfc))
				memcpy(&rfc, (void *)val, olen);
			goto done;
		}
	}

done:
	switch (rfc.mode) {
	case L2CAP_MODE_ERTM:
2261 2262 2263
		chan->retrans_timeout = le16_to_cpu(rfc.retrans_timeout);
		chan->monitor_timeout = le16_to_cpu(rfc.monitor_timeout);
		chan->mps    = le16_to_cpu(rfc.max_pdu_size);
2264 2265
		break;
	case L2CAP_MODE_STREAMING:
2266
		chan->mps    = le16_to_cpu(rfc.max_pdu_size);
2267 2268 2269
	}
}

2270 2271 2272 2273 2274 2275 2276 2277 2278 2279
static inline int l2cap_command_rej(struct l2cap_conn *conn, struct l2cap_cmd_hdr *cmd, u8 *data)
{
	struct l2cap_cmd_rej *rej = (struct l2cap_cmd_rej *) data;

	if (rej->reason != 0x0000)
		return 0;

	if ((conn->info_state & L2CAP_INFO_FEAT_MASK_REQ_SENT) &&
					cmd->ident == conn->info_ident) {
		del_timer(&conn->info_timer);
2280 2281

		conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_DONE;
2282
		conn->info_ident = 0;
2283

2284 2285 2286 2287 2288 2289
		l2cap_conn_start(conn);
	}

	return 0;
}

L
Linus Torvalds 已提交
2290 2291 2292 2293
static inline int l2cap_connect_req(struct l2cap_conn *conn, struct l2cap_cmd_hdr *cmd, u8 *data)
{
	struct l2cap_conn_req *req = (struct l2cap_conn_req *) data;
	struct l2cap_conn_rsp rsp;
2294
	struct l2cap_chan *chan = NULL, *pchan;
2295
	struct sock *parent, *sk = NULL;
2296
	int result, status = L2CAP_CS_NO_INFO;
L
Linus Torvalds 已提交
2297 2298

	u16 dcid = 0, scid = __le16_to_cpu(req->scid);
2299
	__le16 psm = req->psm;
L
Linus Torvalds 已提交
2300 2301 2302 2303

	BT_DBG("psm 0x%2.2x scid 0x%4.4x", psm, scid);

	/* Check if we have socket listening on psm */
2304 2305
	pchan = l2cap_global_chan_by_psm(BT_LISTEN, psm, conn->src);
	if (!pchan) {
L
Linus Torvalds 已提交
2306 2307 2308 2309
		result = L2CAP_CR_BAD_PSM;
		goto sendresp;
	}

2310 2311
	parent = pchan->sk;

2312 2313
	bh_lock_sock(parent);

2314 2315 2316
	/* Check if the ACL is secure enough (if not SDP) */
	if (psm != cpu_to_le16(0x0001) &&
				!hci_conn_check_link_mode(conn->hcon)) {
2317
		conn->disc_reason = 0x05;
2318 2319 2320 2321
		result = L2CAP_CR_SEC_BLOCK;
		goto response;
	}

L
Linus Torvalds 已提交
2322 2323 2324 2325
	result = L2CAP_CR_NO_MEM;

	/* Check for backlog size */
	if (sk_acceptq_is_full(parent)) {
2326
		BT_DBG("backlog full %d", parent->sk_ack_backlog);
L
Linus Torvalds 已提交
2327 2328 2329
		goto response;
	}

2330 2331
	chan = pchan->ops->new_connection(pchan->data);
	if (!chan)
L
Linus Torvalds 已提交
2332 2333
		goto response;

2334 2335
	sk = chan->sk;

2336
	write_lock_bh(&conn->chan_lock);
L
Linus Torvalds 已提交
2337 2338

	/* Check if we already have channel with that dcid */
2339 2340
	if (__l2cap_get_chan_by_dcid(conn, scid)) {
		write_unlock_bh(&conn->chan_lock);
L
Linus Torvalds 已提交
2341 2342 2343 2344 2345 2346 2347 2348 2349
		sock_set_flag(sk, SOCK_ZAPPED);
		l2cap_sock_kill(sk);
		goto response;
	}

	hci_conn_hold(conn->hcon);

	bacpy(&bt_sk(sk)->src, conn->src);
	bacpy(&bt_sk(sk)->dst, conn->dst);
2350 2351
	chan->psm  = psm;
	chan->dcid = scid;
L
Linus Torvalds 已提交
2352

2353 2354
	bt_accept_enqueue(parent, sk);

2355 2356
	__l2cap_chan_add(conn, chan);

2357
	dcid = chan->scid;
L
Linus Torvalds 已提交
2358

2359
	l2cap_chan_set_timer(chan, sk->sk_sndtimeo);
L
Linus Torvalds 已提交
2360

2361
	chan->ident = cmd->ident;
L
Linus Torvalds 已提交
2362

2363
	if (conn->info_state & L2CAP_INFO_FEAT_MASK_REQ_DONE) {
2364
		if (l2cap_check_security(chan)) {
2365 2366 2367 2368 2369 2370 2371 2372 2373 2374
			if (bt_sk(sk)->defer_setup) {
				sk->sk_state = BT_CONNECT2;
				result = L2CAP_CR_PEND;
				status = L2CAP_CS_AUTHOR_PEND;
				parent->sk_data_ready(parent, 0);
			} else {
				sk->sk_state = BT_CONFIG;
				result = L2CAP_CR_SUCCESS;
				status = L2CAP_CS_NO_INFO;
			}
2375 2376 2377 2378 2379 2380 2381 2382 2383
		} else {
			sk->sk_state = BT_CONNECT2;
			result = L2CAP_CR_PEND;
			status = L2CAP_CS_AUTHEN_PEND;
		}
	} else {
		sk->sk_state = BT_CONNECT2;
		result = L2CAP_CR_PEND;
		status = L2CAP_CS_NO_INFO;
L
Linus Torvalds 已提交
2384 2385
	}

2386
	write_unlock_bh(&conn->chan_lock);
L
Linus Torvalds 已提交
2387 2388 2389 2390 2391

response:
	bh_unlock_sock(parent);

sendresp:
2392 2393 2394 2395
	rsp.scid   = cpu_to_le16(scid);
	rsp.dcid   = cpu_to_le16(dcid);
	rsp.result = cpu_to_le16(result);
	rsp.status = cpu_to_le16(status);
L
Linus Torvalds 已提交
2396
	l2cap_send_cmd(conn, cmd->ident, L2CAP_CONN_RSP, sizeof(rsp), &rsp);
2397 2398 2399 2400 2401 2402 2403 2404 2405 2406 2407 2408 2409 2410 2411

	if (result == L2CAP_CR_PEND && status == L2CAP_CS_NO_INFO) {
		struct l2cap_info_req info;
		info.type = cpu_to_le16(L2CAP_IT_FEAT_MASK);

		conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_SENT;
		conn->info_ident = l2cap_get_ident(conn);

		mod_timer(&conn->info_timer, jiffies +
					msecs_to_jiffies(L2CAP_INFO_TIMEOUT));

		l2cap_send_cmd(conn, conn->info_ident,
					L2CAP_INFO_REQ, sizeof(info), &info);
	}

2412
	if (chan && !(chan->conf_state & L2CAP_CONF_REQ_SENT) &&
2413 2414
				result == L2CAP_CR_SUCCESS) {
		u8 buf[128];
2415
		chan->conf_state |= L2CAP_CONF_REQ_SENT;
2416
		l2cap_send_cmd(conn, l2cap_get_ident(conn), L2CAP_CONF_REQ,
2417 2418
					l2cap_build_conf_req(chan, buf), buf);
		chan->num_conf_req++;
2419 2420
	}

L
Linus Torvalds 已提交
2421 2422 2423 2424 2425 2426 2427
	return 0;
}

static inline int l2cap_connect_rsp(struct l2cap_conn *conn, struct l2cap_cmd_hdr *cmd, u8 *data)
{
	struct l2cap_conn_rsp *rsp = (struct l2cap_conn_rsp *) data;
	u16 scid, dcid, result, status;
2428
	struct l2cap_chan *chan;
L
Linus Torvalds 已提交
2429 2430 2431 2432 2433 2434 2435 2436 2437 2438 2439
	struct sock *sk;
	u8 req[128];

	scid   = __le16_to_cpu(rsp->scid);
	dcid   = __le16_to_cpu(rsp->dcid);
	result = __le16_to_cpu(rsp->result);
	status = __le16_to_cpu(rsp->status);

	BT_DBG("dcid 0x%4.4x scid 0x%4.4x result 0x%2.2x status 0x%2.2x", dcid, scid, result, status);

	if (scid) {
2440
		chan = l2cap_get_chan_by_scid(conn, scid);
2441
		if (!chan)
2442
			return -EFAULT;
L
Linus Torvalds 已提交
2443
	} else {
2444
		chan = l2cap_get_chan_by_ident(conn, cmd->ident);
2445
		if (!chan)
2446
			return -EFAULT;
L
Linus Torvalds 已提交
2447 2448
	}

2449 2450
	sk = chan->sk;

L
Linus Torvalds 已提交
2451 2452 2453
	switch (result) {
	case L2CAP_CR_SUCCESS:
		sk->sk_state = BT_CONFIG;
2454
		chan->ident = 0;
2455
		chan->dcid = dcid;
2456
		chan->conf_state &= ~L2CAP_CONF_CONNECT_PEND;
2457

2458
		if (chan->conf_state & L2CAP_CONF_REQ_SENT)
2459 2460
			break;

2461
		chan->conf_state |= L2CAP_CONF_REQ_SENT;
2462

L
Linus Torvalds 已提交
2463
		l2cap_send_cmd(conn, l2cap_get_ident(conn), L2CAP_CONF_REQ,
2464 2465
					l2cap_build_conf_req(chan, req), req);
		chan->num_conf_req++;
L
Linus Torvalds 已提交
2466 2467 2468
		break;

	case L2CAP_CR_PEND:
2469
		chan->conf_state |= L2CAP_CONF_CONNECT_PEND;
L
Linus Torvalds 已提交
2470 2471 2472
		break;

	default:
2473 2474 2475
		/* don't delete l2cap channel if sk is owned by user */
		if (sock_owned_by_user(sk)) {
			sk->sk_state = BT_DISCONN;
2476 2477
			l2cap_chan_clear_timer(chan);
			l2cap_chan_set_timer(chan, HZ / 5);
2478 2479 2480
			break;
		}

2481
		l2cap_chan_del(chan, ECONNREFUSED);
L
Linus Torvalds 已提交
2482 2483 2484 2485 2486 2487 2488
		break;
	}

	bh_unlock_sock(sk);
	return 0;
}

2489
static inline void set_default_fcs(struct l2cap_chan *chan)
2490
{
2491 2492
	struct l2cap_pinfo *pi = l2cap_pi(chan->sk);

2493 2494 2495
	/* FCS is enabled only in ERTM or streaming mode, if one or both
	 * sides request it.
	 */
2496
	if (chan->mode != L2CAP_MODE_ERTM && chan->mode != L2CAP_MODE_STREAMING)
2497
		chan->fcs = L2CAP_FCS_NONE;
2498
	else if (!(pi->chan->conf_state & L2CAP_CONF_NO_FCS_RECV))
2499
		chan->fcs = L2CAP_FCS_CRC16;
2500 2501
}

2502
static inline int l2cap_config_req(struct l2cap_conn *conn, struct l2cap_cmd_hdr *cmd, u16 cmd_len, u8 *data)
L
Linus Torvalds 已提交
2503 2504 2505 2506
{
	struct l2cap_conf_req *req = (struct l2cap_conf_req *) data;
	u16 dcid, flags;
	u8 rsp[64];
2507
	struct l2cap_chan *chan;
L
Linus Torvalds 已提交
2508
	struct sock *sk;
2509
	int len;
L
Linus Torvalds 已提交
2510 2511 2512 2513 2514 2515

	dcid  = __le16_to_cpu(req->dcid);
	flags = __le16_to_cpu(req->flags);

	BT_DBG("dcid 0x%4.4x flags 0x%2.2x", dcid, flags);

2516
	chan = l2cap_get_chan_by_scid(conn, dcid);
2517
	if (!chan)
L
Linus Torvalds 已提交
2518 2519
		return -ENOENT;

2520 2521
	sk = chan->sk;

2522 2523 2524 2525 2526 2527
	if (sk->sk_state != BT_CONFIG) {
		struct l2cap_cmd_rej rej;

		rej.reason = cpu_to_le16(0x0002);
		l2cap_send_cmd(conn, cmd->ident, L2CAP_COMMAND_REJ,
				sizeof(rej), &rej);
2528
		goto unlock;
2529
	}
2530

2531
	/* Reject if config buffer is too small. */
2532
	len = cmd_len - sizeof(*req);
2533
	if (chan->conf_len + len > sizeof(chan->conf_req)) {
2534
		l2cap_send_cmd(conn, cmd->ident, L2CAP_CONF_RSP,
2535
				l2cap_build_conf_rsp(chan, rsp,
2536 2537 2538 2539 2540
					L2CAP_CONF_REJECT, flags), rsp);
		goto unlock;
	}

	/* Store config. */
2541 2542
	memcpy(chan->conf_req + chan->conf_len, req->data, len);
	chan->conf_len += len;
L
Linus Torvalds 已提交
2543 2544 2545 2546

	if (flags & 0x0001) {
		/* Incomplete config. Send empty response. */
		l2cap_send_cmd(conn, cmd->ident, L2CAP_CONF_RSP,
2547
				l2cap_build_conf_rsp(chan, rsp,
2548
					L2CAP_CONF_SUCCESS, 0x0001), rsp);
L
Linus Torvalds 已提交
2549 2550 2551 2552
		goto unlock;
	}

	/* Complete config. */
2553
	len = l2cap_parse_conf_req(chan, rsp);
2554
	if (len < 0) {
2555
		l2cap_send_disconn_req(conn, chan, ECONNRESET);
L
Linus Torvalds 已提交
2556
		goto unlock;
2557
	}
L
Linus Torvalds 已提交
2558

2559
	l2cap_send_cmd(conn, cmd->ident, L2CAP_CONF_RSP, len, rsp);
2560
	chan->num_conf_rsp++;
2561 2562

	/* Reset config buffer. */
2563
	chan->conf_len = 0;
2564

2565
	if (!(chan->conf_state & L2CAP_CONF_OUTPUT_DONE))
2566 2567
		goto unlock;

2568
	if (chan->conf_state & L2CAP_CONF_INPUT_DONE) {
2569
		set_default_fcs(chan);
2570

L
Linus Torvalds 已提交
2571
		sk->sk_state = BT_CONNECTED;
2572

2573 2574
		chan->next_tx_seq = 0;
		chan->expected_tx_seq = 0;
2575
		skb_queue_head_init(&chan->tx_q);
2576
		if (chan->mode == L2CAP_MODE_ERTM)
2577
			l2cap_ertm_init(chan);
2578

L
Linus Torvalds 已提交
2579
		l2cap_chan_ready(sk);
2580 2581 2582
		goto unlock;
	}

2583
	if (!(chan->conf_state & L2CAP_CONF_REQ_SENT)) {
2584
		u8 buf[64];
2585
		chan->conf_state |= L2CAP_CONF_REQ_SENT;
L
Linus Torvalds 已提交
2586
		l2cap_send_cmd(conn, l2cap_get_ident(conn), L2CAP_CONF_REQ,
2587 2588
					l2cap_build_conf_req(chan, buf), buf);
		chan->num_conf_req++;
L
Linus Torvalds 已提交
2589 2590 2591 2592 2593 2594 2595 2596 2597 2598 2599
	}

unlock:
	bh_unlock_sock(sk);
	return 0;
}

static inline int l2cap_config_rsp(struct l2cap_conn *conn, struct l2cap_cmd_hdr *cmd, u8 *data)
{
	struct l2cap_conf_rsp *rsp = (struct l2cap_conf_rsp *)data;
	u16 scid, flags, result;
2600
	struct l2cap_chan *chan;
L
Linus Torvalds 已提交
2601
	struct sock *sk;
2602
	int len = cmd->len - sizeof(*rsp);
L
Linus Torvalds 已提交
2603 2604 2605 2606 2607

	scid   = __le16_to_cpu(rsp->scid);
	flags  = __le16_to_cpu(rsp->flags);
	result = __le16_to_cpu(rsp->result);

2608 2609
	BT_DBG("scid 0x%4.4x flags 0x%2.2x result 0x%2.2x",
			scid, flags, result);
L
Linus Torvalds 已提交
2610

2611
	chan = l2cap_get_chan_by_scid(conn, scid);
2612
	if (!chan)
L
Linus Torvalds 已提交
2613 2614
		return 0;

2615 2616
	sk = chan->sk;

L
Linus Torvalds 已提交
2617 2618
	switch (result) {
	case L2CAP_CONF_SUCCESS:
2619
		l2cap_conf_rfc_get(chan, rsp->data, len);
L
Linus Torvalds 已提交
2620 2621 2622
		break;

	case L2CAP_CONF_UNACCEPT:
2623
		if (chan->num_conf_rsp <= L2CAP_CONF_MAX_CONF_RSP) {
2624 2625
			char req[64];

2626
			if (len > sizeof(req) - sizeof(struct l2cap_conf_req)) {
2627
				l2cap_send_disconn_req(conn, chan, ECONNRESET);
2628 2629 2630
				goto done;
			}

2631 2632
			/* throw out any old stored conf requests */
			result = L2CAP_CONF_SUCCESS;
2633 2634
			len = l2cap_parse_conf_rsp(chan, rsp->data, len,
								req, &result);
2635
			if (len < 0) {
2636
				l2cap_send_disconn_req(conn, chan, ECONNRESET);
2637 2638 2639 2640 2641
				goto done;
			}

			l2cap_send_cmd(conn, l2cap_get_ident(conn),
						L2CAP_CONF_REQ, len, req);
2642
			chan->num_conf_req++;
2643 2644 2645
			if (result != L2CAP_CONF_SUCCESS)
				goto done;
			break;
L
Linus Torvalds 已提交
2646 2647
		}

2648
	default:
2649
		sk->sk_err = ECONNRESET;
2650
		l2cap_chan_set_timer(chan, HZ * 5);
2651
		l2cap_send_disconn_req(conn, chan, ECONNRESET);
L
Linus Torvalds 已提交
2652 2653 2654 2655 2656 2657
		goto done;
	}

	if (flags & 0x01)
		goto done;

2658
	chan->conf_state |= L2CAP_CONF_INPUT_DONE;
L
Linus Torvalds 已提交
2659

2660
	if (chan->conf_state & L2CAP_CONF_OUTPUT_DONE) {
2661
		set_default_fcs(chan);
2662

L
Linus Torvalds 已提交
2663
		sk->sk_state = BT_CONNECTED;
2664 2665
		chan->next_tx_seq = 0;
		chan->expected_tx_seq = 0;
2666
		skb_queue_head_init(&chan->tx_q);
2667
		if (chan->mode ==  L2CAP_MODE_ERTM)
2668
			l2cap_ertm_init(chan);
2669

L
Linus Torvalds 已提交
2670 2671 2672 2673 2674 2675 2676 2677 2678 2679 2680 2681 2682
		l2cap_chan_ready(sk);
	}

done:
	bh_unlock_sock(sk);
	return 0;
}

static inline int l2cap_disconnect_req(struct l2cap_conn *conn, struct l2cap_cmd_hdr *cmd, u8 *data)
{
	struct l2cap_disconn_req *req = (struct l2cap_disconn_req *) data;
	struct l2cap_disconn_rsp rsp;
	u16 dcid, scid;
2683
	struct l2cap_chan *chan;
L
Linus Torvalds 已提交
2684 2685 2686 2687 2688 2689 2690
	struct sock *sk;

	scid = __le16_to_cpu(req->scid);
	dcid = __le16_to_cpu(req->dcid);

	BT_DBG("scid 0x%4.4x dcid 0x%4.4x", scid, dcid);

2691
	chan = l2cap_get_chan_by_scid(conn, dcid);
2692
	if (!chan)
L
Linus Torvalds 已提交
2693 2694
		return 0;

2695 2696
	sk = chan->sk;

2697 2698
	rsp.dcid = cpu_to_le16(chan->scid);
	rsp.scid = cpu_to_le16(chan->dcid);
L
Linus Torvalds 已提交
2699 2700 2701 2702
	l2cap_send_cmd(conn, cmd->ident, L2CAP_DISCONN_RSP, sizeof(rsp), &rsp);

	sk->sk_shutdown = SHUTDOWN_MASK;

2703 2704 2705
	/* don't delete l2cap channel if sk is owned by user */
	if (sock_owned_by_user(sk)) {
		sk->sk_state = BT_DISCONN;
2706 2707
		l2cap_chan_clear_timer(chan);
		l2cap_chan_set_timer(chan, HZ / 5);
2708 2709 2710 2711
		bh_unlock_sock(sk);
		return 0;
	}

2712
	l2cap_chan_del(chan, ECONNRESET);
L
Linus Torvalds 已提交
2713 2714 2715 2716 2717 2718 2719 2720 2721 2722
	bh_unlock_sock(sk);

	l2cap_sock_kill(sk);
	return 0;
}

static inline int l2cap_disconnect_rsp(struct l2cap_conn *conn, struct l2cap_cmd_hdr *cmd, u8 *data)
{
	struct l2cap_disconn_rsp *rsp = (struct l2cap_disconn_rsp *) data;
	u16 dcid, scid;
2723
	struct l2cap_chan *chan;
L
Linus Torvalds 已提交
2724 2725 2726 2727 2728 2729 2730
	struct sock *sk;

	scid = __le16_to_cpu(rsp->scid);
	dcid = __le16_to_cpu(rsp->dcid);

	BT_DBG("dcid 0x%4.4x scid 0x%4.4x", dcid, scid);

2731
	chan = l2cap_get_chan_by_scid(conn, scid);
2732
	if (!chan)
L
Linus Torvalds 已提交
2733 2734
		return 0;

2735 2736
	sk = chan->sk;

2737 2738 2739
	/* don't delete l2cap channel if sk is owned by user */
	if (sock_owned_by_user(sk)) {
		sk->sk_state = BT_DISCONN;
2740 2741
		l2cap_chan_clear_timer(chan);
		l2cap_chan_set_timer(chan, HZ / 5);
2742 2743 2744 2745
		bh_unlock_sock(sk);
		return 0;
	}

2746
	l2cap_chan_del(chan, 0);
L
Linus Torvalds 已提交
2747 2748 2749 2750 2751 2752 2753 2754 2755 2756 2757 2758 2759 2760 2761
	bh_unlock_sock(sk);

	l2cap_sock_kill(sk);
	return 0;
}

static inline int l2cap_information_req(struct l2cap_conn *conn, struct l2cap_cmd_hdr *cmd, u8 *data)
{
	struct l2cap_info_req *req = (struct l2cap_info_req *) data;
	u16 type;

	type = __le16_to_cpu(req->type);

	BT_DBG("type 0x%4.4x", type);

2762 2763
	if (type == L2CAP_IT_FEAT_MASK) {
		u8 buf[8];
2764
		u32 feat_mask = l2cap_feat_mask;
2765 2766 2767
		struct l2cap_info_rsp *rsp = (struct l2cap_info_rsp *) buf;
		rsp->type   = cpu_to_le16(L2CAP_IT_FEAT_MASK);
		rsp->result = cpu_to_le16(L2CAP_IR_SUCCESS);
2768
		if (!disable_ertm)
2769 2770
			feat_mask |= L2CAP_FEAT_ERTM | L2CAP_FEAT_STREAMING
							 | L2CAP_FEAT_FCS;
2771
		put_unaligned_le32(feat_mask, rsp->data);
2772 2773
		l2cap_send_cmd(conn, cmd->ident,
					L2CAP_INFO_RSP, sizeof(buf), buf);
2774 2775 2776 2777 2778 2779 2780 2781
	} else if (type == L2CAP_IT_FIXED_CHAN) {
		u8 buf[12];
		struct l2cap_info_rsp *rsp = (struct l2cap_info_rsp *) buf;
		rsp->type   = cpu_to_le16(L2CAP_IT_FIXED_CHAN);
		rsp->result = cpu_to_le16(L2CAP_IR_SUCCESS);
		memcpy(buf + 4, l2cap_fixed_chan, 8);
		l2cap_send_cmd(conn, cmd->ident,
					L2CAP_INFO_RSP, sizeof(buf), buf);
2782 2783 2784 2785 2786 2787 2788
	} else {
		struct l2cap_info_rsp rsp;
		rsp.type   = cpu_to_le16(type);
		rsp.result = cpu_to_le16(L2CAP_IR_NOTSUPP);
		l2cap_send_cmd(conn, cmd->ident,
					L2CAP_INFO_RSP, sizeof(rsp), &rsp);
	}
L
Linus Torvalds 已提交
2789 2790 2791 2792 2793 2794 2795 2796 2797 2798 2799 2800 2801 2802

	return 0;
}

static inline int l2cap_information_rsp(struct l2cap_conn *conn, struct l2cap_cmd_hdr *cmd, u8 *data)
{
	struct l2cap_info_rsp *rsp = (struct l2cap_info_rsp *) data;
	u16 type, result;

	type   = __le16_to_cpu(rsp->type);
	result = __le16_to_cpu(rsp->result);

	BT_DBG("type 0x%4.4x result 0x%2.2x", type, result);

2803 2804 2805 2806 2807
	/* L2CAP Info req/rsp are unbound to channels, add extra checks */
	if (cmd->ident != conn->info_ident ||
			conn->info_state & L2CAP_INFO_FEAT_MASK_REQ_DONE)
		return 0;

2808 2809
	del_timer(&conn->info_timer);

2810 2811 2812 2813 2814 2815 2816 2817 2818
	if (result != L2CAP_IR_SUCCESS) {
		conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_DONE;
		conn->info_ident = 0;

		l2cap_conn_start(conn);

		return 0;
	}

2819
	if (type == L2CAP_IT_FEAT_MASK) {
2820
		conn->feat_mask = get_unaligned_le32(rsp->data);
2821

2822
		if (conn->feat_mask & L2CAP_FEAT_FIXED_CHAN) {
2823 2824 2825 2826 2827 2828 2829 2830 2831 2832 2833 2834 2835 2836
			struct l2cap_info_req req;
			req.type = cpu_to_le16(L2CAP_IT_FIXED_CHAN);

			conn->info_ident = l2cap_get_ident(conn);

			l2cap_send_cmd(conn, conn->info_ident,
					L2CAP_INFO_REQ, sizeof(req), &req);
		} else {
			conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_DONE;
			conn->info_ident = 0;

			l2cap_conn_start(conn);
		}
	} else if (type == L2CAP_IT_FIXED_CHAN) {
2837
		conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_DONE;
2838
		conn->info_ident = 0;
2839 2840 2841

		l2cap_conn_start(conn);
	}
2842

L
Linus Torvalds 已提交
2843 2844 2845
	return 0;
}

2846
static inline int l2cap_check_conn_param(u16 min, u16 max, u16 latency,
2847 2848 2849 2850 2851 2852 2853 2854 2855 2856 2857 2858 2859 2860 2861 2862 2863 2864 2865 2866 2867 2868 2869 2870 2871 2872 2873
							u16 to_multiplier)
{
	u16 max_latency;

	if (min > max || min < 6 || max > 3200)
		return -EINVAL;

	if (to_multiplier < 10 || to_multiplier > 3200)
		return -EINVAL;

	if (max >= to_multiplier * 8)
		return -EINVAL;

	max_latency = (to_multiplier * 8 / max) - 1;
	if (latency > 499 || latency > max_latency)
		return -EINVAL;

	return 0;
}

static inline int l2cap_conn_param_update_req(struct l2cap_conn *conn,
					struct l2cap_cmd_hdr *cmd, u8 *data)
{
	struct hci_conn *hcon = conn->hcon;
	struct l2cap_conn_param_update_req *req;
	struct l2cap_conn_param_update_rsp rsp;
	u16 min, max, latency, to_multiplier, cmd_len;
2874
	int err;
2875 2876 2877 2878 2879 2880 2881 2882 2883

	if (!(hcon->link_mode & HCI_LM_MASTER))
		return -EINVAL;

	cmd_len = __le16_to_cpu(cmd->len);
	if (cmd_len != sizeof(struct l2cap_conn_param_update_req))
		return -EPROTO;

	req = (struct l2cap_conn_param_update_req *) data;
2884 2885
	min		= __le16_to_cpu(req->min);
	max		= __le16_to_cpu(req->max);
2886 2887 2888 2889 2890 2891 2892
	latency		= __le16_to_cpu(req->latency);
	to_multiplier	= __le16_to_cpu(req->to_multiplier);

	BT_DBG("min 0x%4.4x max 0x%4.4x latency: 0x%4.4x Timeout: 0x%4.4x",
						min, max, latency, to_multiplier);

	memset(&rsp, 0, sizeof(rsp));
2893 2894 2895

	err = l2cap_check_conn_param(min, max, latency, to_multiplier);
	if (err)
2896 2897 2898 2899 2900 2901 2902
		rsp.result = cpu_to_le16(L2CAP_CONN_PARAM_REJECTED);
	else
		rsp.result = cpu_to_le16(L2CAP_CONN_PARAM_ACCEPTED);

	l2cap_send_cmd(conn, cmd->ident, L2CAP_CONN_PARAM_UPDATE_RSP,
							sizeof(rsp), &rsp);

2903 2904 2905
	if (!err)
		hci_le_conn_update(hcon, min, max, latency, to_multiplier);

2906 2907 2908
	return 0;
}

2909 2910 2911 2912 2913 2914 2915 2916 2917 2918 2919 2920 2921 2922 2923 2924 2925 2926 2927 2928 2929 2930 2931 2932 2933 2934 2935 2936 2937 2938 2939 2940 2941 2942 2943 2944 2945 2946 2947 2948 2949 2950 2951 2952 2953 2954 2955 2956 2957 2958 2959 2960 2961 2962 2963 2964 2965 2966 2967 2968 2969 2970 2971 2972 2973 2974
static inline int l2cap_bredr_sig_cmd(struct l2cap_conn *conn,
			struct l2cap_cmd_hdr *cmd, u16 cmd_len, u8 *data)
{
	int err = 0;

	switch (cmd->code) {
	case L2CAP_COMMAND_REJ:
		l2cap_command_rej(conn, cmd, data);
		break;

	case L2CAP_CONN_REQ:
		err = l2cap_connect_req(conn, cmd, data);
		break;

	case L2CAP_CONN_RSP:
		err = l2cap_connect_rsp(conn, cmd, data);
		break;

	case L2CAP_CONF_REQ:
		err = l2cap_config_req(conn, cmd, cmd_len, data);
		break;

	case L2CAP_CONF_RSP:
		err = l2cap_config_rsp(conn, cmd, data);
		break;

	case L2CAP_DISCONN_REQ:
		err = l2cap_disconnect_req(conn, cmd, data);
		break;

	case L2CAP_DISCONN_RSP:
		err = l2cap_disconnect_rsp(conn, cmd, data);
		break;

	case L2CAP_ECHO_REQ:
		l2cap_send_cmd(conn, cmd->ident, L2CAP_ECHO_RSP, cmd_len, data);
		break;

	case L2CAP_ECHO_RSP:
		break;

	case L2CAP_INFO_REQ:
		err = l2cap_information_req(conn, cmd, data);
		break;

	case L2CAP_INFO_RSP:
		err = l2cap_information_rsp(conn, cmd, data);
		break;

	default:
		BT_ERR("Unknown BR/EDR signaling command 0x%2.2x", cmd->code);
		err = -EINVAL;
		break;
	}

	return err;
}

static inline int l2cap_le_sig_cmd(struct l2cap_conn *conn,
					struct l2cap_cmd_hdr *cmd, u8 *data)
{
	switch (cmd->code) {
	case L2CAP_COMMAND_REJ:
		return 0;

	case L2CAP_CONN_PARAM_UPDATE_REQ:
2975
		return l2cap_conn_param_update_req(conn, cmd, data);
2976 2977 2978 2979 2980 2981 2982 2983 2984 2985 2986 2987

	case L2CAP_CONN_PARAM_UPDATE_RSP:
		return 0;

	default:
		BT_ERR("Unknown LE signaling command 0x%2.2x", cmd->code);
		return -EINVAL;
	}
}

static inline void l2cap_sig_channel(struct l2cap_conn *conn,
							struct sk_buff *skb)
L
Linus Torvalds 已提交
2988 2989 2990 2991
{
	u8 *data = skb->data;
	int len = skb->len;
	struct l2cap_cmd_hdr cmd;
2992
	int err;
L
Linus Torvalds 已提交
2993 2994 2995 2996

	l2cap_raw_recv(conn, skb);

	while (len >= L2CAP_CMD_HDR_SIZE) {
2997
		u16 cmd_len;
L
Linus Torvalds 已提交
2998 2999 3000 3001
		memcpy(&cmd, data, L2CAP_CMD_HDR_SIZE);
		data += L2CAP_CMD_HDR_SIZE;
		len  -= L2CAP_CMD_HDR_SIZE;

3002
		cmd_len = le16_to_cpu(cmd.len);
L
Linus Torvalds 已提交
3003

3004
		BT_DBG("code 0x%2.2x len %d id 0x%2.2x", cmd.code, cmd_len, cmd.ident);
L
Linus Torvalds 已提交
3005

3006
		if (cmd_len > len || !cmd.ident) {
L
Linus Torvalds 已提交
3007 3008 3009 3010
			BT_DBG("corrupted command");
			break;
		}

3011 3012 3013 3014
		if (conn->hcon->type == LE_LINK)
			err = l2cap_le_sig_cmd(conn, &cmd, data);
		else
			err = l2cap_bredr_sig_cmd(conn, &cmd, cmd_len, data);
L
Linus Torvalds 已提交
3015 3016 3017

		if (err) {
			struct l2cap_cmd_rej rej;
3018 3019

			BT_ERR("Wrong link type (%d)", err);
L
Linus Torvalds 已提交
3020 3021

			/* FIXME: Map err to a valid reason */
3022
			rej.reason = cpu_to_le16(0);
L
Linus Torvalds 已提交
3023 3024 3025
			l2cap_send_cmd(conn, cmd.ident, L2CAP_COMMAND_REJ, sizeof(rej), &rej);
		}

3026 3027
		data += cmd_len;
		len  -= cmd_len;
L
Linus Torvalds 已提交
3028 3029 3030 3031 3032
	}

	kfree_skb(skb);
}

3033
static int l2cap_check_fcs(struct l2cap_chan *chan,  struct sk_buff *skb)
3034 3035 3036 3037
{
	u16 our_fcs, rcv_fcs;
	int hdr_size = L2CAP_HDR_SIZE + 2;

3038
	if (chan->fcs == L2CAP_FCS_CRC16) {
3039 3040 3041 3042 3043
		skb_trim(skb, skb->len - 2);
		rcv_fcs = get_unaligned_le16(skb->data + skb->len);
		our_fcs = crc16(0, skb->data - hdr_size, skb->len + hdr_size);

		if (our_fcs != rcv_fcs)
3044
			return -EBADMSG;
3045 3046 3047 3048
	}
	return 0;
}

3049
static inline void l2cap_send_i_or_rr_or_rnr(struct l2cap_chan *chan)
3050 3051 3052
{
	u16 control = 0;

3053
	chan->frames_sent = 0;
3054

3055
	control |= chan->buffer_seq << L2CAP_CTRL_REQSEQ_SHIFT;
3056

3057
	if (chan->conn_state & L2CAP_CONN_LOCAL_BUSY) {
3058
		control |= L2CAP_SUPER_RCV_NOT_READY;
3059 3060
		l2cap_send_sframe(chan, control);
		chan->conn_state |= L2CAP_CONN_RNR_SENT;
3061 3062
	}

3063 3064
	if (chan->conn_state & L2CAP_CONN_REMOTE_BUSY)
		l2cap_retransmit_frames(chan);
3065

3066
	l2cap_ertm_send(chan);
3067

3068
	if (!(chan->conn_state & L2CAP_CONN_LOCAL_BUSY) &&
3069
			chan->frames_sent == 0) {
3070
		control |= L2CAP_SUPER_RCV_READY;
3071
		l2cap_send_sframe(chan, control);
3072 3073 3074
	}
}

3075
static int l2cap_add_to_srej_queue(struct l2cap_chan *chan, struct sk_buff *skb, u8 tx_seq, u8 sar)
3076 3077
{
	struct sk_buff *next_skb;
3078
	int tx_seq_offset, next_tx_seq_offset;
3079 3080 3081 3082

	bt_cb(skb)->tx_seq = tx_seq;
	bt_cb(skb)->sar = sar;

3083
	next_skb = skb_peek(&chan->srej_q);
3084
	if (!next_skb) {
3085
		__skb_queue_tail(&chan->srej_q, skb);
3086
		return 0;
3087 3088
	}

3089
	tx_seq_offset = (tx_seq - chan->buffer_seq) % 64;
3090 3091 3092
	if (tx_seq_offset < 0)
		tx_seq_offset += 64;

3093
	do {
3094 3095 3096
		if (bt_cb(next_skb)->tx_seq == tx_seq)
			return -EINVAL;

3097
		next_tx_seq_offset = (bt_cb(next_skb)->tx_seq -
3098
						chan->buffer_seq) % 64;
3099 3100 3101 3102
		if (next_tx_seq_offset < 0)
			next_tx_seq_offset += 64;

		if (next_tx_seq_offset > tx_seq_offset) {
3103
			__skb_queue_before(&chan->srej_q, next_skb, skb);
3104
			return 0;
3105 3106
		}

3107
		if (skb_queue_is_last(&chan->srej_q, next_skb))
3108 3109
			break;

3110
	} while ((next_skb = skb_queue_next(&chan->srej_q, next_skb)));
3111

3112
	__skb_queue_tail(&chan->srej_q, skb);
3113 3114

	return 0;
3115 3116
}

3117
static int l2cap_ertm_reassembly_sdu(struct l2cap_chan *chan, struct sk_buff *skb, u16 control)
3118 3119
{
	struct sk_buff *_skb;
3120
	int err;
3121 3122 3123

	switch (control & L2CAP_CTRL_SAR) {
	case L2CAP_SDU_UNSEGMENTED:
3124
		if (chan->conn_state & L2CAP_CONN_SAR_SDU)
3125 3126
			goto drop;

3127
		return sock_queue_rcv_skb(chan->sk, skb);
3128 3129

	case L2CAP_SDU_START:
3130
		if (chan->conn_state & L2CAP_CONN_SAR_SDU)
3131 3132
			goto drop;

3133
		chan->sdu_len = get_unaligned_le16(skb->data);
3134

3135
		if (chan->sdu_len > chan->imtu)
3136 3137
			goto disconnect;

3138 3139
		chan->sdu = bt_skb_alloc(chan->sdu_len, GFP_ATOMIC);
		if (!chan->sdu)
3140 3141 3142 3143 3144 3145
			return -ENOMEM;

		/* pull sdu_len bytes only after alloc, because of Local Busy
		 * condition we have to be sure that this will be executed
		 * only once, i.e., when alloc does not fail */
		skb_pull(skb, 2);
3146

3147
		memcpy(skb_put(chan->sdu, skb->len), skb->data, skb->len);
3148

3149
		chan->conn_state |= L2CAP_CONN_SAR_SDU;
3150
		chan->partial_sdu_len = skb->len;
3151 3152 3153
		break;

	case L2CAP_SDU_CONTINUE:
3154
		if (!(chan->conn_state & L2CAP_CONN_SAR_SDU))
3155 3156
			goto disconnect;

3157
		if (!chan->sdu)
3158 3159
			goto disconnect;

3160 3161
		chan->partial_sdu_len += skb->len;
		if (chan->partial_sdu_len > chan->sdu_len)
3162 3163
			goto drop;

3164
		memcpy(skb_put(chan->sdu, skb->len), skb->data, skb->len);
3165

3166 3167 3168
		break;

	case L2CAP_SDU_END:
3169
		if (!(chan->conn_state & L2CAP_CONN_SAR_SDU))
3170 3171
			goto disconnect;

3172
		if (!chan->sdu)
3173 3174
			goto disconnect;

3175
		if (!(chan->conn_state & L2CAP_CONN_SAR_RETRY)) {
3176
			chan->partial_sdu_len += skb->len;
3177

3178
			if (chan->partial_sdu_len > chan->imtu)
3179
				goto drop;
3180

3181
			if (chan->partial_sdu_len != chan->sdu_len)
3182
				goto drop;
3183

3184
			memcpy(skb_put(chan->sdu, skb->len), skb->data, skb->len);
3185
		}
3186

3187
		_skb = skb_clone(chan->sdu, GFP_ATOMIC);
3188
		if (!_skb) {
3189
			chan->conn_state |= L2CAP_CONN_SAR_RETRY;
3190 3191 3192
			return -ENOMEM;
		}

3193
		err = sock_queue_rcv_skb(chan->sk, _skb);
3194
		if (err < 0) {
3195
			kfree_skb(_skb);
3196
			chan->conn_state |= L2CAP_CONN_SAR_RETRY;
3197 3198 3199
			return err;
		}

3200 3201
		chan->conn_state &= ~L2CAP_CONN_SAR_RETRY;
		chan->conn_state &= ~L2CAP_CONN_SAR_SDU;
3202

3203
		kfree_skb(chan->sdu);
3204 3205 3206 3207
		break;
	}

	kfree_skb(skb);
3208
	return 0;
3209 3210

drop:
3211 3212
	kfree_skb(chan->sdu);
	chan->sdu = NULL;
3213 3214

disconnect:
3215
	l2cap_send_disconn_req(chan->conn, chan, ECONNRESET);
3216 3217 3218 3219
	kfree_skb(skb);
	return 0;
}

3220
static int l2cap_try_push_rx_skb(struct l2cap_chan *chan)
3221 3222 3223 3224 3225
{
	struct sk_buff *skb;
	u16 control;
	int err;

3226
	while ((skb = skb_dequeue(&chan->busy_q))) {
3227
		control = bt_cb(skb)->sar << L2CAP_CTRL_SAR_SHIFT;
3228
		err = l2cap_ertm_reassembly_sdu(chan, skb, control);
3229
		if (err < 0) {
3230
			skb_queue_head(&chan->busy_q, skb);
3231 3232 3233
			return -EBUSY;
		}

3234
		chan->buffer_seq = (chan->buffer_seq + 1) % 64;
3235 3236
	}

3237
	if (!(chan->conn_state & L2CAP_CONN_RNR_SENT))
3238 3239
		goto done;

3240
	control = chan->buffer_seq << L2CAP_CTRL_REQSEQ_SHIFT;
3241
	control |= L2CAP_SUPER_RCV_READY | L2CAP_CTRL_POLL;
3242
	l2cap_send_sframe(chan, control);
3243
	chan->retry_count = 1;
3244

3245
	del_timer(&chan->retrans_timer);
3246 3247
	__mod_monitor_timer();

3248
	chan->conn_state |= L2CAP_CONN_WAIT_F;
3249 3250

done:
3251 3252
	chan->conn_state &= ~L2CAP_CONN_LOCAL_BUSY;
	chan->conn_state &= ~L2CAP_CONN_RNR_SENT;
3253

3254
	BT_DBG("chan %p, Exit local busy", chan);
3255 3256 3257 3258

	return 0;
}

3259 3260 3261
static void l2cap_busy_work(struct work_struct *work)
{
	DECLARE_WAITQUEUE(wait, current);
3262 3263 3264
	struct l2cap_chan *chan =
		container_of(work, struct l2cap_chan, busy_work);
	struct sock *sk = chan->sk;
3265 3266 3267 3268 3269
	int n_tries = 0, timeo = HZ/5, err;
	struct sk_buff *skb;

	lock_sock(sk);

3270
	add_wait_queue(sk_sleep(sk), &wait);
3271
	while ((skb = skb_peek(&chan->busy_q))) {
3272 3273 3274 3275
		set_current_state(TASK_INTERRUPTIBLE);

		if (n_tries++ > L2CAP_LOCAL_BUSY_TRIES) {
			err = -EBUSY;
3276
			l2cap_send_disconn_req(chan->conn, chan, EBUSY);
3277
			break;
3278 3279 3280 3281 3282 3283 3284
		}

		if (!timeo)
			timeo = HZ/5;

		if (signal_pending(current)) {
			err = sock_intr_errno(timeo);
3285
			break;
3286 3287 3288 3289 3290 3291 3292 3293
		}

		release_sock(sk);
		timeo = schedule_timeout(timeo);
		lock_sock(sk);

		err = sock_error(sk);
		if (err)
3294
			break;
3295

3296
		if (l2cap_try_push_rx_skb(chan) == 0)
3297 3298 3299 3300
			break;
	}

	set_current_state(TASK_RUNNING);
3301
	remove_wait_queue(sk_sleep(sk), &wait);
3302 3303 3304 3305

	release_sock(sk);
}

3306
static int l2cap_push_rx_skb(struct l2cap_chan *chan, struct sk_buff *skb, u16 control)
3307 3308 3309
{
	int sctrl, err;

3310
	if (chan->conn_state & L2CAP_CONN_LOCAL_BUSY) {
3311
		bt_cb(skb)->sar = control >> L2CAP_CTRL_SAR_SHIFT;
3312
		__skb_queue_tail(&chan->busy_q, skb);
3313
		return l2cap_try_push_rx_skb(chan);
3314 3315


3316 3317
	}

3318
	err = l2cap_ertm_reassembly_sdu(chan, skb, control);
3319
	if (err >= 0) {
3320
		chan->buffer_seq = (chan->buffer_seq + 1) % 64;
3321 3322 3323 3324
		return err;
	}

	/* Busy Condition */
3325
	BT_DBG("chan %p, Enter local busy", chan);
3326

3327
	chan->conn_state |= L2CAP_CONN_LOCAL_BUSY;
3328
	bt_cb(skb)->sar = control >> L2CAP_CTRL_SAR_SHIFT;
3329
	__skb_queue_tail(&chan->busy_q, skb);
3330

3331
	sctrl = chan->buffer_seq << L2CAP_CTRL_REQSEQ_SHIFT;
3332
	sctrl |= L2CAP_SUPER_RCV_NOT_READY;
3333
	l2cap_send_sframe(chan, sctrl);
3334

3335
	chan->conn_state |= L2CAP_CONN_RNR_SENT;
3336

3337
	del_timer(&chan->ack_timer);
3338

3339
	queue_work(_busy_wq, &chan->busy_work);
3340 3341 3342 3343

	return err;
}

3344
static int l2cap_streaming_reassembly_sdu(struct l2cap_chan *chan, struct sk_buff *skb, u16 control)
3345 3346 3347 3348
{
	struct sk_buff *_skb;
	int err = -EINVAL;

3349 3350 3351 3352 3353
	/*
	 * TODO: We have to notify the userland if some data is lost with the
	 * Streaming Mode.
	 */

3354 3355
	switch (control & L2CAP_CTRL_SAR) {
	case L2CAP_SDU_UNSEGMENTED:
3356
		if (chan->conn_state & L2CAP_CONN_SAR_SDU) {
3357
			kfree_skb(chan->sdu);
3358 3359 3360
			break;
		}

3361
		err = sock_queue_rcv_skb(chan->sk, skb);
3362 3363 3364 3365 3366 3367
		if (!err)
			return 0;

		break;

	case L2CAP_SDU_START:
3368
		if (chan->conn_state & L2CAP_CONN_SAR_SDU) {
3369
			kfree_skb(chan->sdu);
3370 3371 3372
			break;
		}

3373
		chan->sdu_len = get_unaligned_le16(skb->data);
3374 3375
		skb_pull(skb, 2);

3376
		if (chan->sdu_len > chan->imtu) {
3377 3378 3379 3380
			err = -EMSGSIZE;
			break;
		}

3381 3382
		chan->sdu = bt_skb_alloc(chan->sdu_len, GFP_ATOMIC);
		if (!chan->sdu) {
3383 3384 3385 3386
			err = -ENOMEM;
			break;
		}

3387
		memcpy(skb_put(chan->sdu, skb->len), skb->data, skb->len);
3388

3389
		chan->conn_state |= L2CAP_CONN_SAR_SDU;
3390
		chan->partial_sdu_len = skb->len;
3391 3392 3393 3394
		err = 0;
		break;

	case L2CAP_SDU_CONTINUE:
3395
		if (!(chan->conn_state & L2CAP_CONN_SAR_SDU))
3396 3397
			break;

3398
		memcpy(skb_put(chan->sdu, skb->len), skb->data, skb->len);
3399

3400 3401 3402
		chan->partial_sdu_len += skb->len;
		if (chan->partial_sdu_len > chan->sdu_len)
			kfree_skb(chan->sdu);
3403 3404 3405 3406 3407 3408
		else
			err = 0;

		break;

	case L2CAP_SDU_END:
3409
		if (!(chan->conn_state & L2CAP_CONN_SAR_SDU))
3410 3411
			break;

3412
		memcpy(skb_put(chan->sdu, skb->len), skb->data, skb->len);
3413

3414
		chan->conn_state &= ~L2CAP_CONN_SAR_SDU;
3415
		chan->partial_sdu_len += skb->len;
3416

3417
		if (chan->partial_sdu_len > chan->imtu)
3418 3419
			goto drop;

3420 3421
		if (chan->partial_sdu_len == chan->sdu_len) {
			_skb = skb_clone(chan->sdu, GFP_ATOMIC);
3422
			err = sock_queue_rcv_skb(chan->sk, _skb);
3423 3424 3425 3426 3427
			if (err < 0)
				kfree_skb(_skb);
		}
		err = 0;

3428
drop:
3429
		kfree_skb(chan->sdu);
3430 3431 3432 3433 3434 3435 3436
		break;
	}

	kfree_skb(skb);
	return err;
}

3437
static void l2cap_check_srej_gap(struct l2cap_chan *chan, u8 tx_seq)
3438 3439
{
	struct sk_buff *skb;
3440
	u16 control;
3441

3442
	while ((skb = skb_peek(&chan->srej_q))) {
3443 3444 3445
		if (bt_cb(skb)->tx_seq != tx_seq)
			break;

3446
		skb = skb_dequeue(&chan->srej_q);
3447
		control = bt_cb(skb)->sar << L2CAP_CTRL_SAR_SHIFT;
3448
		l2cap_ertm_reassembly_sdu(chan, skb, control);
3449 3450
		chan->buffer_seq_srej =
			(chan->buffer_seq_srej + 1) % 64;
3451
		tx_seq = (tx_seq + 1) % 64;
3452 3453 3454
	}
}

3455
static void l2cap_resend_srejframe(struct l2cap_chan *chan, u8 tx_seq)
3456 3457 3458 3459
{
	struct srej_list *l, *tmp;
	u16 control;

3460
	list_for_each_entry_safe(l, tmp, &chan->srej_l, list) {
3461 3462 3463 3464 3465 3466 3467
		if (l->tx_seq == tx_seq) {
			list_del(&l->list);
			kfree(l);
			return;
		}
		control = L2CAP_SUPER_SELECT_REJECT;
		control |= l->tx_seq << L2CAP_CTRL_REQSEQ_SHIFT;
3468
		l2cap_send_sframe(chan, control);
3469
		list_del(&l->list);
3470
		list_add_tail(&l->list, &chan->srej_l);
3471 3472 3473
	}
}

3474
static void l2cap_send_srejframe(struct l2cap_chan *chan, u8 tx_seq)
3475 3476 3477 3478
{
	struct srej_list *new;
	u16 control;

3479
	while (tx_seq != chan->expected_tx_seq) {
3480
		control = L2CAP_SUPER_SELECT_REJECT;
3481
		control |= chan->expected_tx_seq << L2CAP_CTRL_REQSEQ_SHIFT;
3482
		l2cap_send_sframe(chan, control);
3483 3484

		new = kzalloc(sizeof(struct srej_list), GFP_ATOMIC);
3485 3486
		new->tx_seq = chan->expected_tx_seq;
		chan->expected_tx_seq = (chan->expected_tx_seq + 1) % 64;
3487
		list_add_tail(&new->list, &chan->srej_l);
3488
	}
3489
	chan->expected_tx_seq = (chan->expected_tx_seq + 1) % 64;
3490 3491
}

3492
static inline int l2cap_data_channel_iframe(struct l2cap_chan *chan, u16 rx_control, struct sk_buff *skb)
3493 3494
{
	u8 tx_seq = __get_txseq(rx_control);
3495
	u8 req_seq = __get_reqseq(rx_control);
3496
	u8 sar = rx_control >> L2CAP_CTRL_SAR_SHIFT;
3497
	int tx_seq_offset, expected_tx_seq_offset;
3498
	int num_to_ack = (chan->tx_win/6) + 1;
3499 3500
	int err = 0;

3501 3502
	BT_DBG("chan %p len %d tx_seq %d rx_control 0x%4.4x", chan, skb->len,
							tx_seq, rx_control);
3503

3504
	if (L2CAP_CTRL_FINAL & rx_control &&
3505
			chan->conn_state & L2CAP_CONN_WAIT_F) {
3506
		del_timer(&chan->monitor_timer);
3507
		if (chan->unacked_frames > 0)
3508
			__mod_retrans_timer();
3509
		chan->conn_state &= ~L2CAP_CONN_WAIT_F;
3510 3511
	}

3512 3513
	chan->expected_ack_seq = req_seq;
	l2cap_drop_acked_frames(chan);
3514

3515
	if (tx_seq == chan->expected_tx_seq)
3516
		goto expected;
3517

3518
	tx_seq_offset = (tx_seq - chan->buffer_seq) % 64;
3519 3520 3521 3522
	if (tx_seq_offset < 0)
		tx_seq_offset += 64;

	/* invalid tx_seq */
3523
	if (tx_seq_offset >= chan->tx_win) {
3524
		l2cap_send_disconn_req(chan->conn, chan, ECONNRESET);
3525 3526 3527
		goto drop;
	}

3528
	if (chan->conn_state & L2CAP_CONN_LOCAL_BUSY)
3529 3530
		goto drop;

3531
	if (chan->conn_state & L2CAP_CONN_SREJ_SENT) {
3532
		struct srej_list *first;
3533

3534
		first = list_first_entry(&chan->srej_l,
3535 3536
				struct srej_list, list);
		if (tx_seq == first->tx_seq) {
3537
			l2cap_add_to_srej_queue(chan, skb, tx_seq, sar);
3538
			l2cap_check_srej_gap(chan, tx_seq);
3539 3540 3541 3542

			list_del(&first->list);
			kfree(first);

3543
			if (list_empty(&chan->srej_l)) {
3544
				chan->buffer_seq = chan->buffer_seq_srej;
3545 3546
				chan->conn_state &= ~L2CAP_CONN_SREJ_SENT;
				l2cap_send_ack(chan);
3547
				BT_DBG("chan %p, Exit SREJ_SENT", chan);
3548 3549 3550
			}
		} else {
			struct srej_list *l;
3551 3552

			/* duplicated tx_seq */
3553
			if (l2cap_add_to_srej_queue(chan, skb, tx_seq, sar) < 0)
3554
				goto drop;
3555

3556
			list_for_each_entry(l, &chan->srej_l, list) {
3557
				if (l->tx_seq == tx_seq) {
3558
					l2cap_resend_srejframe(chan, tx_seq);
3559 3560 3561
					return 0;
				}
			}
3562
			l2cap_send_srejframe(chan, tx_seq);
3563 3564
		}
	} else {
3565
		expected_tx_seq_offset =
3566
			(chan->expected_tx_seq - chan->buffer_seq) % 64;
3567 3568 3569 3570 3571 3572 3573
		if (expected_tx_seq_offset < 0)
			expected_tx_seq_offset += 64;

		/* duplicated tx_seq */
		if (tx_seq_offset < expected_tx_seq_offset)
			goto drop;

3574
		chan->conn_state |= L2CAP_CONN_SREJ_SENT;
3575

3576
		BT_DBG("chan %p, Enter SREJ", chan);
3577

3578
		INIT_LIST_HEAD(&chan->srej_l);
3579
		chan->buffer_seq_srej = chan->buffer_seq;
3580

3581 3582
		__skb_queue_head_init(&chan->srej_q);
		__skb_queue_head_init(&chan->busy_q);
3583
		l2cap_add_to_srej_queue(chan, skb, tx_seq, sar);
3584

3585
		chan->conn_state |= L2CAP_CONN_SEND_PBIT;
3586

3587
		l2cap_send_srejframe(chan, tx_seq);
3588

3589
		del_timer(&chan->ack_timer);
3590
	}
3591 3592
	return 0;

3593
expected:
3594
	chan->expected_tx_seq = (chan->expected_tx_seq + 1) % 64;
3595

3596
	if (chan->conn_state & L2CAP_CONN_SREJ_SENT) {
3597 3598
		bt_cb(skb)->tx_seq = tx_seq;
		bt_cb(skb)->sar = sar;
3599
		__skb_queue_tail(&chan->srej_q, skb);
3600 3601 3602
		return 0;
	}

3603
	err = l2cap_push_rx_skb(chan, skb, rx_control);
3604 3605 3606
	if (err < 0)
		return 0;

3607
	if (rx_control & L2CAP_CTRL_FINAL) {
3608 3609
		if (chan->conn_state & L2CAP_CONN_REJ_ACT)
			chan->conn_state &= ~L2CAP_CONN_REJ_ACT;
3610
		else
3611
			l2cap_retransmit_frames(chan);
3612 3613
	}

3614 3615
	__mod_ack_timer();

3616 3617
	chan->num_acked = (chan->num_acked + 1) % num_to_ack;
	if (chan->num_acked == num_to_ack - 1)
3618
		l2cap_send_ack(chan);
3619

3620
	return 0;
3621 3622 3623 3624

drop:
	kfree_skb(skb);
	return 0;
3625 3626
}

3627
static inline void l2cap_data_channel_rrframe(struct l2cap_chan *chan, u16 rx_control)
3628
{
3629
	BT_DBG("chan %p, req_seq %d ctrl 0x%4.4x", chan, __get_reqseq(rx_control),
3630 3631
						rx_control);

3632 3633
	chan->expected_ack_seq = __get_reqseq(rx_control);
	l2cap_drop_acked_frames(chan);
3634

3635
	if (rx_control & L2CAP_CTRL_POLL) {
3636 3637 3638
		chan->conn_state |= L2CAP_CONN_SEND_FBIT;
		if (chan->conn_state & L2CAP_CONN_SREJ_SENT) {
			if ((chan->conn_state & L2CAP_CONN_REMOTE_BUSY) &&
3639
					(chan->unacked_frames > 0))
3640 3641
				__mod_retrans_timer();

3642 3643
			chan->conn_state &= ~L2CAP_CONN_REMOTE_BUSY;
			l2cap_send_srejtail(chan);
3644
		} else {
3645
			l2cap_send_i_or_rr_or_rnr(chan);
3646
		}
3647

3648
	} else if (rx_control & L2CAP_CTRL_FINAL) {
3649
		chan->conn_state &= ~L2CAP_CONN_REMOTE_BUSY;
3650

3651 3652
		if (chan->conn_state & L2CAP_CONN_REJ_ACT)
			chan->conn_state &= ~L2CAP_CONN_REJ_ACT;
3653
		else
3654
			l2cap_retransmit_frames(chan);
3655

3656
	} else {
3657
		if ((chan->conn_state & L2CAP_CONN_REMOTE_BUSY) &&
3658
				(chan->unacked_frames > 0))
3659
			__mod_retrans_timer();
3660

3661 3662 3663
		chan->conn_state &= ~L2CAP_CONN_REMOTE_BUSY;
		if (chan->conn_state & L2CAP_CONN_SREJ_SENT)
			l2cap_send_ack(chan);
3664
		else
3665
			l2cap_ertm_send(chan);
3666 3667
	}
}
3668

3669
static inline void l2cap_data_channel_rejframe(struct l2cap_chan *chan, u16 rx_control)
3670 3671
{
	u8 tx_seq = __get_reqseq(rx_control);
3672

3673
	BT_DBG("chan %p, req_seq %d ctrl 0x%4.4x", chan, tx_seq, rx_control);
3674

3675
	chan->conn_state &= ~L2CAP_CONN_REMOTE_BUSY;
3676

3677 3678
	chan->expected_ack_seq = tx_seq;
	l2cap_drop_acked_frames(chan);
3679 3680

	if (rx_control & L2CAP_CTRL_FINAL) {
3681 3682
		if (chan->conn_state & L2CAP_CONN_REJ_ACT)
			chan->conn_state &= ~L2CAP_CONN_REJ_ACT;
3683
		else
3684
			l2cap_retransmit_frames(chan);
3685
	} else {
3686
		l2cap_retransmit_frames(chan);
3687

3688 3689
		if (chan->conn_state & L2CAP_CONN_WAIT_F)
			chan->conn_state |= L2CAP_CONN_REJ_ACT;
3690 3691
	}
}
3692
static inline void l2cap_data_channel_srejframe(struct l2cap_chan *chan, u16 rx_control)
3693 3694
{
	u8 tx_seq = __get_reqseq(rx_control);
3695

3696
	BT_DBG("chan %p, req_seq %d ctrl 0x%4.4x", chan, tx_seq, rx_control);
3697

3698
	chan->conn_state &= ~L2CAP_CONN_REMOTE_BUSY;
3699

3700
	if (rx_control & L2CAP_CTRL_POLL) {
3701 3702
		chan->expected_ack_seq = tx_seq;
		l2cap_drop_acked_frames(chan);
3703

3704 3705
		chan->conn_state |= L2CAP_CONN_SEND_FBIT;
		l2cap_retransmit_one_frame(chan, tx_seq);
3706

3707
		l2cap_ertm_send(chan);
3708

3709
		if (chan->conn_state & L2CAP_CONN_WAIT_F) {
3710
			chan->srej_save_reqseq = tx_seq;
3711
			chan->conn_state |= L2CAP_CONN_SREJ_ACT;
3712
		}
3713
	} else if (rx_control & L2CAP_CTRL_FINAL) {
3714
		if ((chan->conn_state & L2CAP_CONN_SREJ_ACT) &&
3715
				chan->srej_save_reqseq == tx_seq)
3716
			chan->conn_state &= ~L2CAP_CONN_SREJ_ACT;
3717
		else
3718
			l2cap_retransmit_one_frame(chan, tx_seq);
3719
	} else {
3720 3721
		l2cap_retransmit_one_frame(chan, tx_seq);
		if (chan->conn_state & L2CAP_CONN_WAIT_F) {
3722
			chan->srej_save_reqseq = tx_seq;
3723
			chan->conn_state |= L2CAP_CONN_SREJ_ACT;
3724
		}
3725 3726 3727
	}
}

3728
static inline void l2cap_data_channel_rnrframe(struct l2cap_chan *chan, u16 rx_control)
3729 3730 3731
{
	u8 tx_seq = __get_reqseq(rx_control);

3732
	BT_DBG("chan %p, req_seq %d ctrl 0x%4.4x", chan, tx_seq, rx_control);
3733

3734
	chan->conn_state |= L2CAP_CONN_REMOTE_BUSY;
3735 3736
	chan->expected_ack_seq = tx_seq;
	l2cap_drop_acked_frames(chan);
3737

3738
	if (rx_control & L2CAP_CTRL_POLL)
3739
		chan->conn_state |= L2CAP_CONN_SEND_FBIT;
3740

3741
	if (!(chan->conn_state & L2CAP_CONN_SREJ_SENT)) {
3742
		del_timer(&chan->retrans_timer);
3743
		if (rx_control & L2CAP_CTRL_POLL)
3744
			l2cap_send_rr_or_rnr(chan, L2CAP_CTRL_FINAL);
3745
		return;
3746
	}
3747 3748

	if (rx_control & L2CAP_CTRL_POLL)
3749
		l2cap_send_srejtail(chan);
3750
	else
3751
		l2cap_send_sframe(chan, L2CAP_SUPER_RCV_READY);
3752 3753
}

3754
static inline int l2cap_data_channel_sframe(struct l2cap_chan *chan, u16 rx_control, struct sk_buff *skb)
3755
{
3756
	BT_DBG("chan %p rx_control 0x%4.4x len %d", chan, rx_control, skb->len);
3757

3758
	if (L2CAP_CTRL_FINAL & rx_control &&
3759
			chan->conn_state & L2CAP_CONN_WAIT_F) {
3760
		del_timer(&chan->monitor_timer);
3761
		if (chan->unacked_frames > 0)
3762
			__mod_retrans_timer();
3763
		chan->conn_state &= ~L2CAP_CONN_WAIT_F;
3764 3765 3766 3767
	}

	switch (rx_control & L2CAP_CTRL_SUPERVISE) {
	case L2CAP_SUPER_RCV_READY:
3768
		l2cap_data_channel_rrframe(chan, rx_control);
3769 3770
		break;

3771
	case L2CAP_SUPER_REJECT:
3772
		l2cap_data_channel_rejframe(chan, rx_control);
3773
		break;
3774

3775
	case L2CAP_SUPER_SELECT_REJECT:
3776
		l2cap_data_channel_srejframe(chan, rx_control);
3777 3778 3779
		break;

	case L2CAP_SUPER_RCV_NOT_READY:
3780
		l2cap_data_channel_rnrframe(chan, rx_control);
3781 3782 3783
		break;
	}

3784
	kfree_skb(skb);
3785 3786 3787
	return 0;
}

3788 3789
static int l2cap_ertm_data_rcv(struct sock *sk, struct sk_buff *skb)
{
3790
	struct l2cap_chan *chan = l2cap_pi(sk)->chan;
3791 3792 3793 3794 3795 3796 3797 3798 3799 3800 3801 3802 3803
	u16 control;
	u8 req_seq;
	int len, next_tx_seq_offset, req_seq_offset;

	control = get_unaligned_le16(skb->data);
	skb_pull(skb, 2);
	len = skb->len;

	/*
	 * We can just drop the corrupted I-frame here.
	 * Receiver will miss it and start proper recovery
	 * procedures and ask retransmission.
	 */
3804
	if (l2cap_check_fcs(chan, skb))
3805 3806 3807 3808 3809
		goto drop;

	if (__is_sar_start(control) && __is_iframe(control))
		len -= 2;

3810
	if (chan->fcs == L2CAP_FCS_CRC16)
3811 3812
		len -= 2;

3813
	if (len > chan->mps) {
3814
		l2cap_send_disconn_req(chan->conn, chan, ECONNRESET);
3815 3816 3817 3818
		goto drop;
	}

	req_seq = __get_reqseq(control);
3819
	req_seq_offset = (req_seq - chan->expected_ack_seq) % 64;
3820 3821 3822 3823
	if (req_seq_offset < 0)
		req_seq_offset += 64;

	next_tx_seq_offset =
3824
		(chan->next_tx_seq - chan->expected_ack_seq) % 64;
3825 3826 3827 3828 3829
	if (next_tx_seq_offset < 0)
		next_tx_seq_offset += 64;

	/* check for invalid req-seq */
	if (req_seq_offset > next_tx_seq_offset) {
3830
		l2cap_send_disconn_req(chan->conn, chan, ECONNRESET);
3831 3832 3833 3834 3835
		goto drop;
	}

	if (__is_iframe(control)) {
		if (len < 0) {
3836
			l2cap_send_disconn_req(chan->conn, chan, ECONNRESET);
3837 3838 3839
			goto drop;
		}

3840
		l2cap_data_channel_iframe(chan, control, skb);
3841 3842 3843
	} else {
		if (len != 0) {
			BT_ERR("%d", len);
3844
			l2cap_send_disconn_req(chan->conn, chan, ECONNRESET);
3845 3846 3847
			goto drop;
		}

3848
		l2cap_data_channel_sframe(chan, control, skb);
3849 3850 3851 3852 3853 3854 3855 3856 3857
	}

	return 0;

drop:
	kfree_skb(skb);
	return 0;
}

L
Linus Torvalds 已提交
3858 3859
static inline int l2cap_data_channel(struct l2cap_conn *conn, u16 cid, struct sk_buff *skb)
{
3860
	struct l2cap_chan *chan;
3861
	struct sock *sk = NULL;
3862
	u16 control;
3863 3864
	u8 tx_seq;
	int len;
L
Linus Torvalds 已提交
3865

3866
	chan = l2cap_get_chan_by_scid(conn, cid);
3867
	if (!chan) {
L
Linus Torvalds 已提交
3868 3869 3870 3871
		BT_DBG("unknown cid 0x%4.4x", cid);
		goto drop;
	}

3872
	sk = chan->sk;
3873

3874
	BT_DBG("chan %p, len %d", chan, skb->len);
L
Linus Torvalds 已提交
3875 3876 3877 3878

	if (sk->sk_state != BT_CONNECTED)
		goto drop;

3879
	switch (chan->mode) {
3880 3881 3882 3883 3884
	case L2CAP_MODE_BASIC:
		/* If socket recv buffers overflows we drop data here
		 * which is *bad* because L2CAP has to be reliable.
		 * But we don't have any other choice. L2CAP doesn't
		 * provide flow control mechanism. */
L
Linus Torvalds 已提交
3885

3886
		if (chan->imtu < skb->len)
3887
			goto drop;
L
Linus Torvalds 已提交
3888

3889 3890 3891 3892 3893
		if (!sock_queue_rcv_skb(sk, skb))
			goto done;
		break;

	case L2CAP_MODE_ERTM:
3894 3895
		if (!sock_owned_by_user(sk)) {
			l2cap_ertm_data_rcv(sk, skb);
3896
		} else {
3897
			if (sk_add_backlog(sk, skb))
3898 3899
				goto drop;
		}
3900

3901
		goto done;
3902

3903 3904 3905 3906 3907
	case L2CAP_MODE_STREAMING:
		control = get_unaligned_le16(skb->data);
		skb_pull(skb, 2);
		len = skb->len;

3908
		if (l2cap_check_fcs(chan, skb))
3909 3910
			goto drop;

3911 3912 3913
		if (__is_sar_start(control))
			len -= 2;

3914
		if (chan->fcs == L2CAP_FCS_CRC16)
3915 3916
			len -= 2;

3917
		if (len > chan->mps || len < 0 || __is_sframe(control))
3918 3919 3920 3921
			goto drop;

		tx_seq = __get_txseq(control);

3922 3923
		if (chan->expected_tx_seq == tx_seq)
			chan->expected_tx_seq = (chan->expected_tx_seq + 1) % 64;
3924
		else
3925
			chan->expected_tx_seq = (tx_seq + 1) % 64;
3926

3927
		l2cap_streaming_reassembly_sdu(chan, skb, control);
3928 3929 3930

		goto done;

3931
	default:
3932
		BT_DBG("chan %p: bad mode 0x%2.2x", chan, chan->mode);
3933 3934
		break;
	}
L
Linus Torvalds 已提交
3935 3936 3937 3938 3939

drop:
	kfree_skb(skb);

done:
3940 3941 3942
	if (sk)
		bh_unlock_sock(sk);

L
Linus Torvalds 已提交
3943 3944 3945
	return 0;
}

3946
static inline int l2cap_conless_channel(struct l2cap_conn *conn, __le16 psm, struct sk_buff *skb)
L
Linus Torvalds 已提交
3947
{
3948
	struct sock *sk = NULL;
3949
	struct l2cap_chan *chan;
L
Linus Torvalds 已提交
3950

3951 3952
	chan = l2cap_global_chan_by_psm(0, psm, conn->src);
	if (!chan)
L
Linus Torvalds 已提交
3953 3954
		goto drop;

3955 3956
	sk = chan->sk;

3957 3958
	bh_lock_sock(sk);

L
Linus Torvalds 已提交
3959 3960 3961 3962 3963
	BT_DBG("sk %p, len %d", sk, skb->len);

	if (sk->sk_state != BT_BOUND && sk->sk_state != BT_CONNECTED)
		goto drop;

3964
	if (l2cap_pi(sk)->chan->imtu < skb->len)
L
Linus Torvalds 已提交
3965 3966 3967 3968 3969 3970 3971 3972 3973
		goto drop;

	if (!sock_queue_rcv_skb(sk, skb))
		goto done;

drop:
	kfree_skb(skb);

done:
3974 3975
	if (sk)
		bh_unlock_sock(sk);
L
Linus Torvalds 已提交
3976 3977 3978
	return 0;
}

3979 3980
static inline int l2cap_att_channel(struct l2cap_conn *conn, __le16 cid, struct sk_buff *skb)
{
3981
	struct sock *sk = NULL;
3982
	struct l2cap_chan *chan;
3983

3984 3985
	chan = l2cap_global_chan_by_scid(0, cid, conn->src);
	if (!chan)
3986 3987
		goto drop;

3988 3989
	sk = chan->sk;

3990 3991 3992 3993 3994 3995 3996
	bh_lock_sock(sk);

	BT_DBG("sk %p, len %d", sk, skb->len);

	if (sk->sk_state != BT_BOUND && sk->sk_state != BT_CONNECTED)
		goto drop;

3997
	if (l2cap_pi(sk)->chan->imtu < skb->len)
3998 3999 4000 4001 4002 4003 4004 4005 4006 4007 4008 4009 4010 4011
		goto drop;

	if (!sock_queue_rcv_skb(sk, skb))
		goto done;

drop:
	kfree_skb(skb);

done:
	if (sk)
		bh_unlock_sock(sk);
	return 0;
}

L
Linus Torvalds 已提交
4012 4013 4014
static void l2cap_recv_frame(struct l2cap_conn *conn, struct sk_buff *skb)
{
	struct l2cap_hdr *lh = (void *) skb->data;
4015 4016
	u16 cid, len;
	__le16 psm;
L
Linus Torvalds 已提交
4017 4018 4019 4020 4021

	skb_pull(skb, L2CAP_HDR_SIZE);
	cid = __le16_to_cpu(lh->cid);
	len = __le16_to_cpu(lh->len);

4022 4023 4024 4025 4026
	if (len != skb->len) {
		kfree_skb(skb);
		return;
	}

L
Linus Torvalds 已提交
4027 4028 4029
	BT_DBG("len %d, cid 0x%4.4x", len, cid);

	switch (cid) {
4030
	case L2CAP_CID_LE_SIGNALING:
4031
	case L2CAP_CID_SIGNALING:
L
Linus Torvalds 已提交
4032 4033 4034
		l2cap_sig_channel(conn, skb);
		break;

4035
	case L2CAP_CID_CONN_LESS:
4036
		psm = get_unaligned_le16(skb->data);
L
Linus Torvalds 已提交
4037 4038 4039 4040
		skb_pull(skb, 2);
		l2cap_conless_channel(conn, psm, skb);
		break;

4041 4042 4043 4044
	case L2CAP_CID_LE_DATA:
		l2cap_att_channel(conn, cid, skb);
		break;

L
Linus Torvalds 已提交
4045 4046 4047 4048 4049 4050 4051 4052 4053 4054 4055
	default:
		l2cap_data_channel(conn, cid, skb);
		break;
	}
}

/* ---- L2CAP interface with lower layer (HCI) ---- */

static int l2cap_connect_ind(struct hci_dev *hdev, bdaddr_t *bdaddr, u8 type)
{
	int exact = 0, lm1 = 0, lm2 = 0;
4056
	struct l2cap_chan *c;
L
Linus Torvalds 已提交
4057 4058

	if (type != ACL_LINK)
4059
		return -EINVAL;
L
Linus Torvalds 已提交
4060 4061 4062 4063

	BT_DBG("hdev %s, bdaddr %s", hdev->name, batostr(bdaddr));

	/* Find listening sockets and check their link_mode */
4064 4065 4066
	read_lock(&chan_list_lock);
	list_for_each_entry(c, &chan_list, global_l) {
		struct sock *sk = c->sk;
4067

L
Linus Torvalds 已提交
4068 4069 4070 4071
		if (sk->sk_state != BT_LISTEN)
			continue;

		if (!bacmp(&bt_sk(sk)->src, &hdev->bdaddr)) {
4072
			lm1 |= HCI_LM_ACCEPT;
4073
			if (c->role_switch)
4074
				lm1 |= HCI_LM_MASTER;
L
Linus Torvalds 已提交
4075
			exact++;
4076 4077
		} else if (!bacmp(&bt_sk(sk)->src, BDADDR_ANY)) {
			lm2 |= HCI_LM_ACCEPT;
4078
			if (c->role_switch)
4079 4080
				lm2 |= HCI_LM_MASTER;
		}
L
Linus Torvalds 已提交
4081
	}
4082
	read_unlock(&chan_list_lock);
L
Linus Torvalds 已提交
4083 4084 4085 4086 4087 4088

	return exact ? lm1 : lm2;
}

static int l2cap_connect_cfm(struct hci_conn *hcon, u8 status)
{
4089 4090
	struct l2cap_conn *conn;

L
Linus Torvalds 已提交
4091 4092
	BT_DBG("hcon %p bdaddr %s status %d", hcon, batostr(&hcon->dst), status);

4093
	if (!(hcon->type == ACL_LINK || hcon->type == LE_LINK))
4094
		return -EINVAL;
L
Linus Torvalds 已提交
4095 4096 4097 4098 4099

	if (!status) {
		conn = l2cap_conn_add(hcon, status);
		if (conn)
			l2cap_conn_ready(conn);
4100
	} else
L
Linus Torvalds 已提交
4101 4102 4103 4104 4105
		l2cap_conn_del(hcon, bt_err(status));

	return 0;
}

4106 4107 4108 4109 4110 4111 4112 4113 4114 4115 4116 4117 4118
static int l2cap_disconn_ind(struct hci_conn *hcon)
{
	struct l2cap_conn *conn = hcon->l2cap_data;

	BT_DBG("hcon %p", hcon);

	if (hcon->type != ACL_LINK || !conn)
		return 0x13;

	return conn->disc_reason;
}

static int l2cap_disconn_cfm(struct hci_conn *hcon, u8 reason)
L
Linus Torvalds 已提交
4119 4120 4121
{
	BT_DBG("hcon %p reason %d", hcon, reason);

4122
	if (!(hcon->type == ACL_LINK || hcon->type == LE_LINK))
4123
		return -EINVAL;
L
Linus Torvalds 已提交
4124 4125

	l2cap_conn_del(hcon, bt_err(reason));
4126

L
Linus Torvalds 已提交
4127 4128 4129
	return 0;
}

4130
static inline void l2cap_check_encryption(struct l2cap_chan *chan, u8 encrypt)
4131
{
4132
	if (chan->chan_type != L2CAP_CHAN_CONN_ORIENTED)
4133 4134
		return;

4135
	if (encrypt == 0x00) {
4136
		if (chan->sec_level == BT_SECURITY_MEDIUM) {
4137 4138
			l2cap_chan_clear_timer(chan);
			l2cap_chan_set_timer(chan, HZ * 5);
4139
		} else if (chan->sec_level == BT_SECURITY_HIGH)
4140
			l2cap_chan_close(chan, ECONNREFUSED);
4141
	} else {
4142
		if (chan->sec_level == BT_SECURITY_MEDIUM)
4143
			l2cap_chan_clear_timer(chan);
4144 4145 4146
	}
}

4147
static int l2cap_security_cfm(struct hci_conn *hcon, u8 status, u8 encrypt)
L
Linus Torvalds 已提交
4148
{
4149
	struct l2cap_conn *conn = hcon->l2cap_data;
4150
	struct l2cap_chan *chan;
L
Linus Torvalds 已提交
4151

4152
	if (!conn)
L
Linus Torvalds 已提交
4153
		return 0;
4154

L
Linus Torvalds 已提交
4155 4156
	BT_DBG("conn %p", conn);

4157
	read_lock(&conn->chan_lock);
L
Linus Torvalds 已提交
4158

4159
	list_for_each_entry(chan, &conn->chan_l, list) {
4160
		struct sock *sk = chan->sk;
4161

L
Linus Torvalds 已提交
4162 4163
		bh_lock_sock(sk);

4164
		if (chan->conf_state & L2CAP_CONF_CONNECT_PEND) {
4165 4166 4167 4168
			bh_unlock_sock(sk);
			continue;
		}

4169
		if (!status && (sk->sk_state == BT_CONNECTED ||
4170
						sk->sk_state == BT_CONFIG)) {
4171
			l2cap_check_encryption(chan, encrypt);
4172 4173 4174 4175
			bh_unlock_sock(sk);
			continue;
		}

4176 4177 4178
		if (sk->sk_state == BT_CONNECT) {
			if (!status) {
				struct l2cap_conn_req req;
4179 4180
				req.scid = cpu_to_le16(chan->scid);
				req.psm  = chan->psm;
L
Linus Torvalds 已提交
4181

4182
				chan->ident = l2cap_get_ident(conn);
4183
				chan->conf_state |= L2CAP_CONF_CONNECT_PEND;
L
Linus Torvalds 已提交
4184

4185
				l2cap_send_cmd(conn, chan->ident,
4186 4187
					L2CAP_CONN_REQ, sizeof(req), &req);
			} else {
4188 4189
				l2cap_chan_clear_timer(chan);
				l2cap_chan_set_timer(chan, HZ / 10);
4190 4191 4192 4193
			}
		} else if (sk->sk_state == BT_CONNECT2) {
			struct l2cap_conn_rsp rsp;
			__u16 result;
L
Linus Torvalds 已提交
4194

4195 4196 4197 4198 4199
			if (!status) {
				sk->sk_state = BT_CONFIG;
				result = L2CAP_CR_SUCCESS;
			} else {
				sk->sk_state = BT_DISCONN;
4200
				l2cap_chan_set_timer(chan, HZ / 10);
4201 4202 4203
				result = L2CAP_CR_SEC_BLOCK;
			}

4204 4205
			rsp.scid   = cpu_to_le16(chan->dcid);
			rsp.dcid   = cpu_to_le16(chan->scid);
4206
			rsp.result = cpu_to_le16(result);
4207
			rsp.status = cpu_to_le16(L2CAP_CS_NO_INFO);
4208 4209
			l2cap_send_cmd(conn, chan->ident, L2CAP_CONN_RSP,
							sizeof(rsp), &rsp);
4210
		}
L
Linus Torvalds 已提交
4211 4212 4213 4214

		bh_unlock_sock(sk);
	}

4215
	read_unlock(&conn->chan_lock);
4216

L
Linus Torvalds 已提交
4217 4218 4219 4220 4221 4222 4223
	return 0;
}

static int l2cap_recv_acldata(struct hci_conn *hcon, struct sk_buff *skb, u16 flags)
{
	struct l2cap_conn *conn = hcon->l2cap_data;

4224 4225 4226 4227
	if (!conn)
		conn = l2cap_conn_add(hcon, 0);

	if (!conn)
L
Linus Torvalds 已提交
4228 4229 4230 4231
		goto drop;

	BT_DBG("conn %p len %d flags 0x%x", conn, skb->len, flags);

4232
	if (!(flags & ACL_CONT)) {
L
Linus Torvalds 已提交
4233
		struct l2cap_hdr *hdr;
4234
		struct l2cap_chan *chan;
4235
		u16 cid;
L
Linus Torvalds 已提交
4236 4237 4238 4239 4240 4241 4242 4243 4244 4245
		int len;

		if (conn->rx_len) {
			BT_ERR("Unexpected start frame (len %d)", skb->len);
			kfree_skb(conn->rx_skb);
			conn->rx_skb = NULL;
			conn->rx_len = 0;
			l2cap_conn_unreliable(conn, ECOMM);
		}

4246 4247
		/* Start fragment always begin with Basic L2CAP header */
		if (skb->len < L2CAP_HDR_SIZE) {
L
Linus Torvalds 已提交
4248 4249 4250 4251 4252 4253 4254
			BT_ERR("Frame is too short (len %d)", skb->len);
			l2cap_conn_unreliable(conn, ECOMM);
			goto drop;
		}

		hdr = (struct l2cap_hdr *) skb->data;
		len = __le16_to_cpu(hdr->len) + L2CAP_HDR_SIZE;
4255
		cid = __le16_to_cpu(hdr->cid);
L
Linus Torvalds 已提交
4256 4257 4258 4259 4260 4261 4262 4263 4264 4265 4266 4267 4268 4269 4270 4271

		if (len == skb->len) {
			/* Complete frame received */
			l2cap_recv_frame(conn, skb);
			return 0;
		}

		BT_DBG("Start: total len %d, frag len %d", len, skb->len);

		if (skb->len > len) {
			BT_ERR("Frame is too long (len %d, expected len %d)",
				skb->len, len);
			l2cap_conn_unreliable(conn, ECOMM);
			goto drop;
		}

4272
		chan = l2cap_get_chan_by_scid(conn, cid);
4273

4274 4275
		if (chan && chan->sk) {
			struct sock *sk = chan->sk;
4276

4277
			if (chan->imtu < len - L2CAP_HDR_SIZE) {
4278 4279
				BT_ERR("Frame exceeding recv MTU (len %d, "
							"MTU %d)", len,
4280
							chan->imtu);
4281 4282 4283 4284
				bh_unlock_sock(sk);
				l2cap_conn_unreliable(conn, ECOMM);
				goto drop;
			}
4285
			bh_unlock_sock(sk);
4286
		}
4287

L
Linus Torvalds 已提交
4288
		/* Allocate skb for the complete frame (with header) */
4289 4290
		conn->rx_skb = bt_skb_alloc(len, GFP_ATOMIC);
		if (!conn->rx_skb)
L
Linus Torvalds 已提交
4291 4292
			goto drop;

4293
		skb_copy_from_linear_data(skb, skb_put(conn->rx_skb, skb->len),
4294
								skb->len);
L
Linus Torvalds 已提交
4295 4296 4297 4298 4299 4300 4301 4302 4303 4304 4305 4306 4307 4308 4309 4310 4311 4312 4313 4314
		conn->rx_len = len - skb->len;
	} else {
		BT_DBG("Cont: frag len %d (expecting %d)", skb->len, conn->rx_len);

		if (!conn->rx_len) {
			BT_ERR("Unexpected continuation frame (len %d)", skb->len);
			l2cap_conn_unreliable(conn, ECOMM);
			goto drop;
		}

		if (skb->len > conn->rx_len) {
			BT_ERR("Fragment is too long (len %d, expected %d)",
					skb->len, conn->rx_len);
			kfree_skb(conn->rx_skb);
			conn->rx_skb = NULL;
			conn->rx_len = 0;
			l2cap_conn_unreliable(conn, ECOMM);
			goto drop;
		}

4315
		skb_copy_from_linear_data(skb, skb_put(conn->rx_skb, skb->len),
4316
								skb->len);
L
Linus Torvalds 已提交
4317 4318 4319 4320 4321 4322 4323 4324 4325 4326 4327 4328 4329 4330
		conn->rx_len -= skb->len;

		if (!conn->rx_len) {
			/* Complete frame received */
			l2cap_recv_frame(conn, conn->rx_skb);
			conn->rx_skb = NULL;
		}
	}

drop:
	kfree_skb(skb);
	return 0;
}

4331
static int l2cap_debugfs_show(struct seq_file *f, void *p)
L
Linus Torvalds 已提交
4332
{
4333
	struct l2cap_chan *c;
L
Linus Torvalds 已提交
4334

4335
	read_lock_bh(&chan_list_lock);
L
Linus Torvalds 已提交
4336

4337 4338
	list_for_each_entry(c, &chan_list, global_l) {
		struct sock *sk = c->sk;
4339

4340
		seq_printf(f, "%s %s %d %d 0x%4.4x 0x%4.4x %d %d %d %d\n",
4341 4342
					batostr(&bt_sk(sk)->src),
					batostr(&bt_sk(sk)->dst),
4343 4344 4345
					sk->sk_state, __le16_to_cpu(c->psm),
					c->scid, c->dcid, c->imtu, c->omtu,
					c->sec_level, c->mode);
4346
	}
L
Linus Torvalds 已提交
4347

4348
	read_unlock_bh(&chan_list_lock);
L
Linus Torvalds 已提交
4349

4350
	return 0;
L
Linus Torvalds 已提交
4351 4352
}

4353 4354 4355 4356 4357 4358 4359 4360 4361 4362 4363 4364 4365
static int l2cap_debugfs_open(struct inode *inode, struct file *file)
{
	return single_open(file, l2cap_debugfs_show, inode->i_private);
}

static const struct file_operations l2cap_debugfs_fops = {
	.open		= l2cap_debugfs_open,
	.read		= seq_read,
	.llseek		= seq_lseek,
	.release	= single_release,
};

static struct dentry *l2cap_debugfs;
L
Linus Torvalds 已提交
4366 4367 4368 4369 4370 4371 4372

static struct hci_proto l2cap_hci_proto = {
	.name		= "L2CAP",
	.id		= HCI_PROTO_L2CAP,
	.connect_ind	= l2cap_connect_ind,
	.connect_cfm	= l2cap_connect_cfm,
	.disconn_ind	= l2cap_disconn_ind,
4373
	.disconn_cfm	= l2cap_disconn_cfm,
4374
	.security_cfm	= l2cap_security_cfm,
L
Linus Torvalds 已提交
4375 4376 4377
	.recv_acldata	= l2cap_recv_acldata
};

4378
int __init l2cap_init(void)
L
Linus Torvalds 已提交
4379 4380
{
	int err;
4381

4382
	err = l2cap_init_sockets();
L
Linus Torvalds 已提交
4383 4384 4385
	if (err < 0)
		return err;

4386
	_busy_wq = create_singlethread_workqueue("l2cap");
4387
	if (!_busy_wq) {
4388
		err = -ENOMEM;
L
Linus Torvalds 已提交
4389 4390 4391 4392 4393 4394 4395 4396 4397 4398
		goto error;
	}

	err = hci_register_proto(&l2cap_hci_proto);
	if (err < 0) {
		BT_ERR("L2CAP protocol registration failed");
		bt_sock_unregister(BTPROTO_L2CAP);
		goto error;
	}

4399 4400 4401 4402 4403 4404
	if (bt_debugfs) {
		l2cap_debugfs = debugfs_create_file("l2cap", 0444,
					bt_debugfs, NULL, &l2cap_debugfs_fops);
		if (!l2cap_debugfs)
			BT_ERR("Failed to create L2CAP debug file");
	}
L
Linus Torvalds 已提交
4405 4406 4407 4408

	return 0;

error:
4409
	destroy_workqueue(_busy_wq);
4410
	l2cap_cleanup_sockets();
L
Linus Torvalds 已提交
4411 4412 4413
	return err;
}

4414
void l2cap_exit(void)
L
Linus Torvalds 已提交
4415
{
4416
	debugfs_remove(l2cap_debugfs);
L
Linus Torvalds 已提交
4417

4418 4419 4420
	flush_workqueue(_busy_wq);
	destroy_workqueue(_busy_wq);

L
Linus Torvalds 已提交
4421 4422 4423
	if (hci_unregister_proto(&l2cap_hci_proto) < 0)
		BT_ERR("L2CAP protocol unregistration failed");

4424
	l2cap_cleanup_sockets();
L
Linus Torvalds 已提交
4425 4426
}

4427 4428
module_param(disable_ertm, bool, 0644);
MODULE_PARM_DESC(disable_ertm, "Disable enhanced retransmission mode");