l2cap_core.c 98.6 KB
Newer Older
1
/*
L
Linus Torvalds 已提交
2 3
   BlueZ - Bluetooth protocol stack for Linux
   Copyright (C) 2000-2001 Qualcomm Incorporated
4
   Copyright (C) 2009-2010 Gustavo F. Padovan <gustavo@padovan.org>
5
   Copyright (C) 2010 Google Inc.
L
Linus Torvalds 已提交
6 7 8 9 10 11 12 13 14 15 16

   Written 2000,2001 by Maxim Krasnyansky <maxk@qualcomm.com>

   This program is free software; you can redistribute it and/or modify
   it under the terms of the GNU General Public License version 2 as
   published by the Free Software Foundation;

   THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS
   OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
   FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT OF THIRD PARTY RIGHTS.
   IN NO EVENT SHALL THE COPYRIGHT HOLDER(S) AND AUTHOR(S) BE LIABLE FOR ANY
17 18 19
   CLAIM, OR ANY SPECIAL INDIRECT OR CONSEQUENTIAL DAMAGES, OR ANY DAMAGES
   WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
   ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
L
Linus Torvalds 已提交
20 21
   OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.

22 23
   ALL LIABILITY, INCLUDING LIABILITY FOR INFRINGEMENT OF ANY PATENTS,
   COPYRIGHTS, TRADEMARKS OR OTHER RIGHTS, RELATING TO USE OF THIS
L
Linus Torvalds 已提交
24 25 26
   SOFTWARE IS DISCLAIMED.
*/

27
/* Bluetooth L2CAP core. */
L
Linus Torvalds 已提交
28 29 30 31

#include <linux/module.h>

#include <linux/types.h>
32
#include <linux/capability.h>
L
Linus Torvalds 已提交
33 34 35 36 37 38 39 40 41 42 43
#include <linux/errno.h>
#include <linux/kernel.h>
#include <linux/sched.h>
#include <linux/slab.h>
#include <linux/poll.h>
#include <linux/fcntl.h>
#include <linux/init.h>
#include <linux/interrupt.h>
#include <linux/socket.h>
#include <linux/skbuff.h>
#include <linux/list.h>
44
#include <linux/device.h>
45 46
#include <linux/debugfs.h>
#include <linux/seq_file.h>
47
#include <linux/uaccess.h>
48
#include <linux/crc16.h>
L
Linus Torvalds 已提交
49 50 51 52 53 54 55 56 57
#include <net/sock.h>

#include <asm/system.h>
#include <asm/unaligned.h>

#include <net/bluetooth/bluetooth.h>
#include <net/bluetooth/hci_core.h>
#include <net/bluetooth/l2cap.h>

58
int disable_ertm;
59

60
static u32 l2cap_feat_mask = L2CAP_FEAT_FIXED_CHAN;
61
static u8 l2cap_fixed_chan[8] = { 0x02, };
L
Linus Torvalds 已提交
62

63 64
static struct workqueue_struct *_busy_wq;

65 66
LIST_HEAD(chan_list);
DEFINE_RWLOCK(chan_list_lock);
L
Linus Torvalds 已提交
67

68 69
static void l2cap_busy_work(struct work_struct *work);

L
Linus Torvalds 已提交
70 71
static struct sk_buff *l2cap_build_cmd(struct l2cap_conn *conn,
				u8 code, u8 ident, u16 dlen, void *data);
72 73
static void l2cap_send_cmd(struct l2cap_conn *conn, u8 ident, u8 code, u16 len,
								void *data);
74
static int l2cap_build_conf_req(struct l2cap_chan *chan, void *data);
75 76
static void l2cap_send_disconn_req(struct l2cap_conn *conn,
				struct l2cap_chan *chan, int err);
L
Linus Torvalds 已提交
77

78 79
static int l2cap_ertm_data_rcv(struct sock *sk, struct sk_buff *skb);

80
/* ---- L2CAP channels ---- */
81
static struct l2cap_chan *__l2cap_get_chan_by_dcid(struct l2cap_conn *conn, u16 cid)
82
{
83
	struct l2cap_chan *c;
84 85

	list_for_each_entry(c, &conn->chan_l, list) {
86
		if (c->dcid == cid)
87
			return c;
88
	}
89 90
	return NULL;

91 92
}

93
static struct l2cap_chan *__l2cap_get_chan_by_scid(struct l2cap_conn *conn, u16 cid)
94
{
95
	struct l2cap_chan *c;
96 97

	list_for_each_entry(c, &conn->chan_l, list) {
98
		if (c->scid == cid)
99
			return c;
100
	}
101
	return NULL;
102 103 104 105
}

/* Find channel with given SCID.
 * Returns locked socket */
106
static struct l2cap_chan *l2cap_get_chan_by_scid(struct l2cap_conn *conn, u16 cid)
107
{
108
	struct l2cap_chan *c;
109 110 111

	read_lock(&conn->chan_lock);
	c = __l2cap_get_chan_by_scid(conn, cid);
112 113
	if (c)
		bh_lock_sock(c->sk);
114
	read_unlock(&conn->chan_lock);
115
	return c;
116 117
}

118
static struct l2cap_chan *__l2cap_get_chan_by_ident(struct l2cap_conn *conn, u8 ident)
119
{
120
	struct l2cap_chan *c;
121 122

	list_for_each_entry(c, &conn->chan_l, list) {
123
		if (c->ident == ident)
124
			return c;
125
	}
126
	return NULL;
127 128
}

129
static inline struct l2cap_chan *l2cap_get_chan_by_ident(struct l2cap_conn *conn, u8 ident)
130
{
131
	struct l2cap_chan *c;
132 133 134

	read_lock(&conn->chan_lock);
	c = __l2cap_get_chan_by_ident(conn, ident);
135 136
	if (c)
		bh_lock_sock(c->sk);
137
	read_unlock(&conn->chan_lock);
138
	return c;
139 140
}

141
static struct l2cap_chan *__l2cap_global_chan_by_addr(__le16 psm, bdaddr_t *src)
142
{
143
	struct l2cap_chan *c;
144

145 146
	list_for_each_entry(c, &chan_list, global_l) {
		if (c->sport == psm && !bacmp(&bt_sk(c->sk)->src, src))
147 148 149
			goto found;
	}

150
	c = NULL;
151
found:
152
	return c;
153 154 155 156
}

int l2cap_add_psm(struct l2cap_chan *chan, bdaddr_t *src, __le16 psm)
{
157 158
	int err;

159
	write_lock_bh(&chan_list_lock);
160

161
	if (psm && __l2cap_global_chan_by_addr(psm, src)) {
162 163
		err = -EADDRINUSE;
		goto done;
164 165
	}

166 167 168 169 170 171 172 173 174
	if (psm) {
		chan->psm = psm;
		chan->sport = psm;
		err = 0;
	} else {
		u16 p;

		err = -EINVAL;
		for (p = 0x1001; p < 0x1100; p += 2)
175
			if (!__l2cap_global_chan_by_addr(cpu_to_le16(p), src)) {
176 177 178 179 180 181
				chan->psm   = cpu_to_le16(p);
				chan->sport = cpu_to_le16(p);
				err = 0;
				break;
			}
	}
182

183
done:
184
	write_unlock_bh(&chan_list_lock);
185
	return err;
186 187 188 189
}

int l2cap_add_scid(struct l2cap_chan *chan,  __u16 scid)
{
190
	write_lock_bh(&chan_list_lock);
191 192 193

	chan->scid = scid;

194
	write_unlock_bh(&chan_list_lock);
195 196 197 198

	return 0;
}

199
static u16 l2cap_alloc_cid(struct l2cap_conn *conn)
200
{
201
	u16 cid = L2CAP_CID_DYN_START;
202

203
	for (; cid < L2CAP_CID_DYN_END; cid++) {
204
		if (!__l2cap_get_chan_by_scid(conn, cid))
205 206 207 208 209 210
			return cid;
	}

	return 0;
}

211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 258 259 260
static void l2cap_chan_set_timer(struct l2cap_chan *chan, long timeout)
{
       BT_DBG("chan %p state %d timeout %ld", chan->sk, chan->sk->sk_state,
								 timeout);
       if (!mod_timer(&chan->chan_timer, jiffies + timeout))
	       sock_hold(chan->sk);
}

void l2cap_chan_clear_timer(struct l2cap_chan *chan)
{
       BT_DBG("chan %p state %d", chan, chan->sk->sk_state);

       if (timer_pending(&chan->chan_timer) && del_timer(&chan->chan_timer))
	       __sock_put(chan->sk);
}

static void l2cap_chan_timeout(unsigned long arg)
{
	struct l2cap_chan *chan = (struct l2cap_chan *) arg;
	struct sock *sk = chan->sk;
	int reason;

	BT_DBG("chan %p state %d", chan, sk->sk_state);

	bh_lock_sock(sk);

	if (sock_owned_by_user(sk)) {
		/* sk is owned by user. Try again later */
		l2cap_chan_set_timer(chan, HZ / 5);
		bh_unlock_sock(sk);
		sock_put(sk);
		return;
	}

	if (sk->sk_state == BT_CONNECTED || sk->sk_state == BT_CONFIG)
		reason = ECONNREFUSED;
	else if (sk->sk_state == BT_CONNECT &&
					chan->sec_level != BT_SECURITY_SDP)
		reason = ECONNREFUSED;
	else
		reason = ETIMEDOUT;

	__l2cap_chan_close(chan, reason);

	bh_unlock_sock(sk);

	l2cap_sock_kill(sk);
	sock_put(sk);
}

261
struct l2cap_chan *l2cap_chan_create(struct sock *sk)
262 263 264 265 266 267 268 269 270
{
	struct l2cap_chan *chan;

	chan = kzalloc(sizeof(*chan), GFP_ATOMIC);
	if (!chan)
		return NULL;

	chan->sk = sk;

271 272 273 274
	write_lock_bh(&chan_list_lock);
	list_add(&chan->global_l, &chan_list);
	write_unlock_bh(&chan_list_lock);

275 276
	setup_timer(&chan->chan_timer, l2cap_chan_timeout, (unsigned long) chan);

277 278 279
	return chan;
}

280
void l2cap_chan_destroy(struct l2cap_chan *chan)
281
{
282 283 284 285
	write_lock_bh(&chan_list_lock);
	list_del(&chan->global_l);
	write_unlock_bh(&chan_list_lock);

286 287 288
	kfree(chan);
}

289
static void __l2cap_chan_add(struct l2cap_conn *conn, struct l2cap_chan *chan)
290
{
291
	struct sock *sk = chan->sk;
292

293
	BT_DBG("conn %p, psm 0x%2.2x, dcid 0x%4.4x", conn,
294
			chan->psm, chan->dcid);
295

296 297
	conn->disc_reason = 0x13;

298
	chan->conn = conn;
299

300
	if (chan->chan_type == L2CAP_CHAN_CONN_ORIENTED) {
301 302
		if (conn->hcon->type == LE_LINK) {
			/* LE connection */
303
			chan->omtu = L2CAP_LE_DEFAULT_MTU;
304 305
			chan->scid = L2CAP_CID_LE_DATA;
			chan->dcid = L2CAP_CID_LE_DATA;
306 307
		} else {
			/* Alloc CID for connection-oriented socket */
308
			chan->scid = l2cap_alloc_cid(conn);
309
			chan->omtu = L2CAP_DEFAULT_MTU;
310
		}
311
	} else if (chan->chan_type == L2CAP_CHAN_CONN_LESS) {
312
		/* Connectionless socket */
313 314
		chan->scid = L2CAP_CID_CONN_LESS;
		chan->dcid = L2CAP_CID_CONN_LESS;
315
		chan->omtu = L2CAP_DEFAULT_MTU;
316 317
	} else {
		/* Raw socket can send/recv signalling messages only */
318 319
		chan->scid = L2CAP_CID_SIGNALING;
		chan->dcid = L2CAP_CID_SIGNALING;
320
		chan->omtu = L2CAP_DEFAULT_MTU;
321 322
	}

323 324 325
	sock_hold(sk);

	list_add(&chan->list, &conn->chan_l);
326 327
}

328
/* Delete channel.
329
 * Must be called on the locked socket. */
330
static void l2cap_chan_del(struct l2cap_chan *chan, int err)
331
{
332
	struct sock *sk = chan->sk;
333
	struct l2cap_conn *conn = chan->conn;
334 335
	struct sock *parent = bt_sk(sk)->parent;

336
	l2cap_chan_clear_timer(chan);
337

338
	BT_DBG("chan %p, conn %p, err %d", chan, conn, err);
339

340
	if (conn) {
341 342 343 344 345 346
		/* Delete from channel list */
		write_lock_bh(&conn->chan_lock);
		list_del(&chan->list);
		write_unlock_bh(&conn->chan_lock);
		__sock_put(sk);

347
		chan->conn = NULL;
348 349 350
		hci_conn_put(conn->hcon);
	}

351
	sk->sk_state = BT_CLOSED;
352 353 354 355 356 357 358 359 360 361
	sock_set_flag(sk, SOCK_ZAPPED);

	if (err)
		sk->sk_err = err;

	if (parent) {
		bt_accept_unlink(sk);
		parent->sk_data_ready(parent, 0);
	} else
		sk->sk_state_change(sk);
362

363 364
	if (!(chan->conf_state & L2CAP_CONF_OUTPUT_DONE &&
			chan->conf_state & L2CAP_CONF_INPUT_DONE))
365
		return;
366

367
	skb_queue_purge(&chan->tx_q);
368

369
	if (chan->mode == L2CAP_MODE_ERTM) {
370 371
		struct srej_list *l, *tmp;

372 373 374
		del_timer(&chan->retrans_timer);
		del_timer(&chan->monitor_timer);
		del_timer(&chan->ack_timer);
375

376 377
		skb_queue_purge(&chan->srej_q);
		skb_queue_purge(&chan->busy_q);
378

379
		list_for_each_entry_safe(l, tmp, &chan->srej_l, list) {
380 381 382 383
			list_del(&l->list);
			kfree(l);
		}
	}
384 385
}

386 387 388
/* Must be called on unlocked socket. */
static void l2cap_chan_close(struct sock *sk)
{
389
	l2cap_chan_clear_timer(l2cap_pi(sk)->chan);
390 391 392 393 394 395 396 397 398 399 400 401 402 403 404 405 406 407 408 409 410 411 412 413 414 415 416 417 418 419 420 421 422 423
	lock_sock(sk);
	__l2cap_chan_close(l2cap_pi(sk)->chan, ECONNRESET);
	release_sock(sk);
	l2cap_sock_kill(sk);
}

static void l2cap_chan_cleanup_listen(struct sock *parent)
{
	struct sock *sk;

	BT_DBG("parent %p", parent);

	/* Close not yet accepted channels */
	while ((sk = bt_accept_dequeue(parent, NULL)))
		l2cap_chan_close(sk);

	parent->sk_state = BT_CLOSED;
	sock_set_flag(parent, SOCK_ZAPPED);
}

void __l2cap_chan_close(struct l2cap_chan *chan, int reason)
{
	struct l2cap_conn *conn = chan->conn;
	struct sock *sk = chan->sk;

	BT_DBG("chan %p state %d socket %p", chan, sk->sk_state, sk->sk_socket);

	switch (sk->sk_state) {
	case BT_LISTEN:
		l2cap_chan_cleanup_listen(sk);
		break;

	case BT_CONNECTED:
	case BT_CONFIG:
424
		if (chan->chan_type == L2CAP_CHAN_CONN_ORIENTED &&
425
					conn->hcon->type == ACL_LINK) {
426
			l2cap_chan_set_timer(chan, sk->sk_sndtimeo);
427 428 429 430 431 432
			l2cap_send_disconn_req(conn, chan, reason);
		} else
			l2cap_chan_del(chan, reason);
		break;

	case BT_CONNECT2:
433
		if (chan->chan_type == L2CAP_CHAN_CONN_ORIENTED &&
434 435 436 437 438 439 440 441 442 443 444 445 446 447 448 449 450 451 452 453 454 455 456 457 458 459 460 461 462 463 464
					conn->hcon->type == ACL_LINK) {
			struct l2cap_conn_rsp rsp;
			__u16 result;

			if (bt_sk(sk)->defer_setup)
				result = L2CAP_CR_SEC_BLOCK;
			else
				result = L2CAP_CR_BAD_PSM;

			rsp.scid   = cpu_to_le16(chan->dcid);
			rsp.dcid   = cpu_to_le16(chan->scid);
			rsp.result = cpu_to_le16(result);
			rsp.status = cpu_to_le16(L2CAP_CS_NO_INFO);
			l2cap_send_cmd(conn, chan->ident, L2CAP_CONN_RSP,
							sizeof(rsp), &rsp);
		}

		l2cap_chan_del(chan, reason);
		break;

	case BT_CONNECT:
	case BT_DISCONN:
		l2cap_chan_del(chan, reason);
		break;

	default:
		sock_set_flag(sk, SOCK_ZAPPED);
		break;
	}
}

465
static inline u8 l2cap_get_auth_type(struct l2cap_chan *chan)
466
{
467
	if (chan->chan_type == L2CAP_CHAN_RAW) {
468
		switch (chan->sec_level) {
469 470 471 472 473 474 475
		case BT_SECURITY_HIGH:
			return HCI_AT_DEDICATED_BONDING_MITM;
		case BT_SECURITY_MEDIUM:
			return HCI_AT_DEDICATED_BONDING;
		default:
			return HCI_AT_NO_BONDING;
		}
476
	} else if (chan->psm == cpu_to_le16(0x0001)) {
477 478
		if (chan->sec_level == BT_SECURITY_LOW)
			chan->sec_level = BT_SECURITY_SDP;
479

480
		if (chan->sec_level == BT_SECURITY_HIGH)
481
			return HCI_AT_NO_BONDING_MITM;
482
		else
483
			return HCI_AT_NO_BONDING;
484
	} else {
485
		switch (chan->sec_level) {
486
		case BT_SECURITY_HIGH:
487
			return HCI_AT_GENERAL_BONDING_MITM;
488
		case BT_SECURITY_MEDIUM:
489
			return HCI_AT_GENERAL_BONDING;
490
		default:
491
			return HCI_AT_NO_BONDING;
492
		}
493
	}
494 495 496
}

/* Service level security */
497
static inline int l2cap_check_security(struct l2cap_chan *chan)
498
{
499
	struct l2cap_conn *conn = chan->conn;
500 501
	__u8 auth_type;

502
	auth_type = l2cap_get_auth_type(chan);
503

504
	return hci_conn_security(conn->hcon, chan->sec_level, auth_type);
505 506
}

507
u8 l2cap_get_ident(struct l2cap_conn *conn)
508 509 510 511 512 513 514 515 516 517 518 519 520 521 522 523 524 525 526 527 528
{
	u8 id;

	/* Get next available identificator.
	 *    1 - 128 are used by kernel.
	 *  129 - 199 are reserved.
	 *  200 - 254 are used by utilities like l2ping, etc.
	 */

	spin_lock_bh(&conn->lock);

	if (++conn->tx_ident > 128)
		conn->tx_ident = 1;

	id = conn->tx_ident;

	spin_unlock_bh(&conn->lock);

	return id;
}

529
static void l2cap_send_cmd(struct l2cap_conn *conn, u8 ident, u8 code, u16 len, void *data)
530 531
{
	struct sk_buff *skb = l2cap_build_cmd(conn, code, ident, len, data);
532
	u8 flags;
533 534 535 536

	BT_DBG("code 0x%2.2x", code);

	if (!skb)
537
		return;
538

539 540 541 542 543 544
	if (lmp_no_flush_capable(conn->hcon->hdev))
		flags = ACL_START_NO_FLUSH;
	else
		flags = ACL_START;

	hci_send_acl(conn->hcon, skb, flags);
545 546
}

547
static inline void l2cap_send_sframe(struct l2cap_chan *chan, u16 control)
548 549 550
{
	struct sk_buff *skb;
	struct l2cap_hdr *lh;
551
	struct l2cap_pinfo *pi = l2cap_pi(chan->sk);
552
	struct l2cap_conn *conn = chan->conn;
553
	struct sock *sk = (struct sock *)pi;
554
	int count, hlen = L2CAP_HDR_SIZE + 2;
555
	u8 flags;
556

557 558 559
	if (sk->sk_state != BT_CONNECTED)
		return;

560
	if (chan->fcs == L2CAP_FCS_CRC16)
561
		hlen += 2;
562

563
	BT_DBG("chan %p, control 0x%2.2x", chan, control);
564

565
	count = min_t(unsigned int, conn->mtu, hlen);
566 567
	control |= L2CAP_CTRL_FRAME_TYPE;

568
	if (chan->conn_state & L2CAP_CONN_SEND_FBIT) {
569
		control |= L2CAP_CTRL_FINAL;
570
		chan->conn_state &= ~L2CAP_CONN_SEND_FBIT;
571 572
	}

573
	if (chan->conn_state & L2CAP_CONN_SEND_PBIT) {
574
		control |= L2CAP_CTRL_POLL;
575
		chan->conn_state &= ~L2CAP_CONN_SEND_PBIT;
576 577
	}

578 579
	skb = bt_skb_alloc(count, GFP_ATOMIC);
	if (!skb)
580
		return;
581 582

	lh = (struct l2cap_hdr *) skb_put(skb, L2CAP_HDR_SIZE);
583
	lh->len = cpu_to_le16(hlen - L2CAP_HDR_SIZE);
584
	lh->cid = cpu_to_le16(chan->dcid);
585 586
	put_unaligned_le16(control, skb_put(skb, 2));

587
	if (chan->fcs == L2CAP_FCS_CRC16) {
588 589 590 591
		u16 fcs = crc16(0, (u8 *)lh, count - 2);
		put_unaligned_le16(fcs, skb_put(skb, 2));
	}

592 593 594 595 596
	if (lmp_no_flush_capable(conn->hcon->hdev))
		flags = ACL_START_NO_FLUSH;
	else
		flags = ACL_START;

597
	hci_send_acl(chan->conn->hcon, skb, flags);
598 599
}

600
static inline void l2cap_send_rr_or_rnr(struct l2cap_chan *chan, u16 control)
601
{
602
	if (chan->conn_state & L2CAP_CONN_LOCAL_BUSY) {
603
		control |= L2CAP_SUPER_RCV_NOT_READY;
604
		chan->conn_state |= L2CAP_CONN_RNR_SENT;
605
	} else
606 607
		control |= L2CAP_SUPER_RCV_READY;

608
	control |= chan->buffer_seq << L2CAP_CTRL_REQSEQ_SHIFT;
609

610
	l2cap_send_sframe(chan, control);
611 612
}

613
static inline int __l2cap_no_conn_pending(struct l2cap_chan *chan)
614
{
615
	return !(chan->conf_state & L2CAP_CONF_CONNECT_PEND);
616 617
}

618
static void l2cap_do_start(struct l2cap_chan *chan)
619
{
620
	struct l2cap_conn *conn = chan->conn;
621 622

	if (conn->info_state & L2CAP_INFO_FEAT_MASK_REQ_SENT) {
623 624 625
		if (!(conn->info_state & L2CAP_INFO_FEAT_MASK_REQ_DONE))
			return;

626 627
		if (l2cap_check_security(chan) &&
				__l2cap_no_conn_pending(chan)) {
628
			struct l2cap_conn_req req;
629 630
			req.scid = cpu_to_le16(chan->scid);
			req.psm  = chan->psm;
631

632
			chan->ident = l2cap_get_ident(conn);
633
			chan->conf_state |= L2CAP_CONF_CONNECT_PEND;
634

635 636
			l2cap_send_cmd(conn, chan->ident, L2CAP_CONN_REQ,
							sizeof(req), &req);
637
		}
638 639 640 641 642 643 644 645 646 647 648 649 650 651 652
	} else {
		struct l2cap_info_req req;
		req.type = cpu_to_le16(L2CAP_IT_FEAT_MASK);

		conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_SENT;
		conn->info_ident = l2cap_get_ident(conn);

		mod_timer(&conn->info_timer, jiffies +
					msecs_to_jiffies(L2CAP_INFO_TIMEOUT));

		l2cap_send_cmd(conn, conn->info_ident,
					L2CAP_INFO_REQ, sizeof(req), &req);
	}
}

653 654 655
static inline int l2cap_mode_supported(__u8 mode, __u32 feat_mask)
{
	u32 local_feat_mask = l2cap_feat_mask;
656
	if (!disable_ertm)
657 658 659 660 661 662 663 664 665 666 667 668
		local_feat_mask |= L2CAP_FEAT_ERTM | L2CAP_FEAT_STREAMING;

	switch (mode) {
	case L2CAP_MODE_ERTM:
		return L2CAP_FEAT_ERTM & feat_mask & local_feat_mask;
	case L2CAP_MODE_STREAMING:
		return L2CAP_FEAT_STREAMING & feat_mask & local_feat_mask;
	default:
		return 0x00;
	}
}

669
static void l2cap_send_disconn_req(struct l2cap_conn *conn, struct l2cap_chan *chan, int err)
670
{
671
	struct sock *sk;
672 673
	struct l2cap_disconn_req req;

674 675 676
	if (!conn)
		return;

677 678
	sk = chan->sk;

679
	if (chan->mode == L2CAP_MODE_ERTM) {
680 681 682
		del_timer(&chan->retrans_timer);
		del_timer(&chan->monitor_timer);
		del_timer(&chan->ack_timer);
683 684
	}

685 686
	req.dcid = cpu_to_le16(chan->dcid);
	req.scid = cpu_to_le16(chan->scid);
687 688
	l2cap_send_cmd(conn, l2cap_get_ident(conn),
			L2CAP_DISCONN_REQ, sizeof(req), &req);
689 690

	sk->sk_state = BT_DISCONN;
691
	sk->sk_err = err;
692 693
}

L
Linus Torvalds 已提交
694
/* ---- L2CAP connections ---- */
695 696
static void l2cap_conn_start(struct l2cap_conn *conn)
{
697
	struct l2cap_chan *chan, *tmp;
698 699 700

	BT_DBG("conn %p", conn);

701
	read_lock(&conn->chan_lock);
702

703
	list_for_each_entry_safe(chan, tmp, &conn->chan_l, list) {
704
		struct sock *sk = chan->sk;
705

706 707
		bh_lock_sock(sk);

708
		if (chan->chan_type != L2CAP_CHAN_CONN_ORIENTED) {
709 710 711 712 713
			bh_unlock_sock(sk);
			continue;
		}

		if (sk->sk_state == BT_CONNECT) {
714
			struct l2cap_conn_req req;
715

716
			if (!l2cap_check_security(chan) ||
717
					!__l2cap_no_conn_pending(chan)) {
718 719 720
				bh_unlock_sock(sk);
				continue;
			}
721

722
			if (!l2cap_mode_supported(chan->mode,
723
					conn->feat_mask)
724
					&& chan->conf_state &
725
					L2CAP_CONF_STATE2_DEVICE) {
726
				/* __l2cap_chan_close() calls list_del(chan)
727 728
				 * so release the lock */
				read_unlock_bh(&conn->chan_lock);
729
				 __l2cap_chan_close(chan, ECONNRESET);
730
				read_lock_bh(&conn->chan_lock);
731 732
				bh_unlock_sock(sk);
				continue;
733
			}
734

735 736
			req.scid = cpu_to_le16(chan->scid);
			req.psm  = chan->psm;
737

738
			chan->ident = l2cap_get_ident(conn);
739
			chan->conf_state |= L2CAP_CONF_CONNECT_PEND;
740

741 742
			l2cap_send_cmd(conn, chan->ident, L2CAP_CONN_REQ,
							sizeof(req), &req);
743

744 745
		} else if (sk->sk_state == BT_CONNECT2) {
			struct l2cap_conn_rsp rsp;
746
			char buf[128];
747 748
			rsp.scid = cpu_to_le16(chan->dcid);
			rsp.dcid = cpu_to_le16(chan->scid);
749

750
			if (l2cap_check_security(chan)) {
751 752 753 754 755 756 757 758 759 760 761
				if (bt_sk(sk)->defer_setup) {
					struct sock *parent = bt_sk(sk)->parent;
					rsp.result = cpu_to_le16(L2CAP_CR_PEND);
					rsp.status = cpu_to_le16(L2CAP_CS_AUTHOR_PEND);
					parent->sk_data_ready(parent, 0);

				} else {
					sk->sk_state = BT_CONFIG;
					rsp.result = cpu_to_le16(L2CAP_CR_SUCCESS);
					rsp.status = cpu_to_le16(L2CAP_CS_NO_INFO);
				}
762 763 764 765 766
			} else {
				rsp.result = cpu_to_le16(L2CAP_CR_PEND);
				rsp.status = cpu_to_le16(L2CAP_CS_AUTHEN_PEND);
			}

767 768
			l2cap_send_cmd(conn, chan->ident, L2CAP_CONN_RSP,
							sizeof(rsp), &rsp);
769

770
			if (chan->conf_state & L2CAP_CONF_REQ_SENT ||
771 772 773 774 775
					rsp.result != L2CAP_CR_SUCCESS) {
				bh_unlock_sock(sk);
				continue;
			}

776
			chan->conf_state |= L2CAP_CONF_REQ_SENT;
777
			l2cap_send_cmd(conn, l2cap_get_ident(conn), L2CAP_CONF_REQ,
778 779
						l2cap_build_conf_req(chan, buf), buf);
			chan->num_conf_req++;
780 781 782 783 784
		}

		bh_unlock_sock(sk);
	}

785
	read_unlock(&conn->chan_lock);
786 787
}

788 789 790
/* Find socket with cid and source bdaddr.
 * Returns closest match, locked.
 */
791
static struct l2cap_chan *l2cap_global_chan_by_scid(int state, __le16 cid, bdaddr_t *src)
792
{
793
	struct l2cap_chan *c, *c1 = NULL;
794

795
	read_lock(&chan_list_lock);
796

797 798
	list_for_each_entry(c, &chan_list, global_l) {
		struct sock *sk = c->sk;
799

800 801 802
		if (state && sk->sk_state != state)
			continue;

803
		if (c->scid == cid) {
804
			/* Exact match. */
805 806 807 808
			if (!bacmp(&bt_sk(sk)->src, src)) {
				read_unlock(&chan_list_lock);
				return c;
			}
809 810 811

			/* Closest match */
			if (!bacmp(&bt_sk(sk)->src, BDADDR_ANY))
812
				c1 = c;
813 814
		}
	}
815

816
	read_unlock(&chan_list_lock);
817

818
	return c1;
819 820 821 822
}

static void l2cap_le_conn_ready(struct l2cap_conn *conn)
{
823
	struct sock *parent, *sk;
824
	struct l2cap_chan *chan, *pchan;
825 826 827 828

	BT_DBG("");

	/* Check if we have socket listening on cid */
829
	pchan = l2cap_global_chan_by_scid(BT_LISTEN, L2CAP_CID_LE_DATA,
830
							conn->src);
831
	if (!pchan)
832 833
		return;

834 835
	parent = pchan->sk;

836 837
	bh_lock_sock(parent);

838 839 840 841 842 843 844 845 846 847
	/* Check for backlog size */
	if (sk_acceptq_is_full(parent)) {
		BT_DBG("backlog full %d", parent->sk_ack_backlog);
		goto clean;
	}

	sk = l2cap_sock_alloc(sock_net(parent), NULL, BTPROTO_L2CAP, GFP_ATOMIC);
	if (!sk)
		goto clean;

848
	chan = l2cap_chan_create(sk);
849 850 851 852 853
	if (!chan) {
		l2cap_sock_kill(sk);
		goto clean;
	}

854 855
	l2cap_pi(sk)->chan = chan;

856
	write_lock_bh(&conn->chan_lock);
857 858 859 860

	hci_conn_hold(conn->hcon);

	l2cap_sock_init(sk, parent);
861

862 863 864
	bacpy(&bt_sk(sk)->src, conn->src);
	bacpy(&bt_sk(sk)->dst, conn->dst);

865 866
	bt_accept_enqueue(parent, sk);

867 868
	__l2cap_chan_add(conn, chan);

869
	l2cap_chan_set_timer(chan, sk->sk_sndtimeo);
870 871 872 873

	sk->sk_state = BT_CONNECTED;
	parent->sk_data_ready(parent, 0);

874
	write_unlock_bh(&conn->chan_lock);
875 876 877 878 879

clean:
	bh_unlock_sock(parent);
}

880 881
static void l2cap_conn_ready(struct l2cap_conn *conn)
{
882
	struct l2cap_chan *chan;
883

884
	BT_DBG("conn %p", conn);
885

886 887 888
	if (!conn->hcon->out && conn->hcon->type == LE_LINK)
		l2cap_le_conn_ready(conn);

889
	read_lock(&conn->chan_lock);
890

891
	list_for_each_entry(chan, &conn->chan_l, list) {
892
		struct sock *sk = chan->sk;
893

894
		bh_lock_sock(sk);
895

896
		if (conn->hcon->type == LE_LINK) {
897
			l2cap_chan_clear_timer(chan);
898 899 900 901
			sk->sk_state = BT_CONNECTED;
			sk->sk_state_change(sk);
		}

902
		if (chan->chan_type != L2CAP_CHAN_CONN_ORIENTED) {
903
			l2cap_chan_clear_timer(chan);
904 905 906
			sk->sk_state = BT_CONNECTED;
			sk->sk_state_change(sk);
		} else if (sk->sk_state == BT_CONNECT)
907
			l2cap_do_start(chan);
908

909
		bh_unlock_sock(sk);
910
	}
911

912
	read_unlock(&conn->chan_lock);
913 914 915 916 917
}

/* Notify sockets that we cannot guaranty reliability anymore */
static void l2cap_conn_unreliable(struct l2cap_conn *conn, int err)
{
918
	struct l2cap_chan *chan;
919 920 921

	BT_DBG("conn %p", conn);

922
	read_lock(&conn->chan_lock);
923

924
	list_for_each_entry(chan, &conn->chan_l, list) {
925
		struct sock *sk = chan->sk;
926

927
		if (chan->force_reliable)
928 929 930
			sk->sk_err = err;
	}

931
	read_unlock(&conn->chan_lock);
932 933 934 935 936 937
}

static void l2cap_info_timeout(unsigned long arg)
{
	struct l2cap_conn *conn = (void *) arg;

938
	conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_DONE;
939
	conn->info_ident = 0;
940

941 942 943
	l2cap_conn_start(conn);
}

L
Linus Torvalds 已提交
944 945
static struct l2cap_conn *l2cap_conn_add(struct hci_conn *hcon, u8 status)
{
946
	struct l2cap_conn *conn = hcon->l2cap_data;
L
Linus Torvalds 已提交
947

948
	if (conn || status)
L
Linus Torvalds 已提交
949 950
		return conn;

951 952
	conn = kzalloc(sizeof(struct l2cap_conn), GFP_ATOMIC);
	if (!conn)
L
Linus Torvalds 已提交
953 954 955 956 957
		return NULL;

	hcon->l2cap_data = conn;
	conn->hcon = hcon;

958 959
	BT_DBG("hcon %p conn %p", hcon, conn);

960 961 962 963 964
	if (hcon->hdev->le_mtu && hcon->type == LE_LINK)
		conn->mtu = hcon->hdev->le_mtu;
	else
		conn->mtu = hcon->hdev->acl_mtu;

L
Linus Torvalds 已提交
965 966 967
	conn->src = &hcon->hdev->bdaddr;
	conn->dst = &hcon->dst;

968 969
	conn->feat_mask = 0;

L
Linus Torvalds 已提交
970
	spin_lock_init(&conn->lock);
971 972 973
	rwlock_init(&conn->chan_lock);

	INIT_LIST_HEAD(&conn->chan_l);
L
Linus Torvalds 已提交
974

975 976
	if (hcon->type != LE_LINK)
		setup_timer(&conn->info_timer, l2cap_info_timeout,
D
Dave Young 已提交
977 978
						(unsigned long) conn);

979 980
	conn->disc_reason = 0x13;

L
Linus Torvalds 已提交
981 982 983
	return conn;
}

984
static void l2cap_conn_del(struct hci_conn *hcon, int err)
L
Linus Torvalds 已提交
985
{
986
	struct l2cap_conn *conn = hcon->l2cap_data;
987
	struct l2cap_chan *chan, *l;
L
Linus Torvalds 已提交
988 989
	struct sock *sk;

990 991
	if (!conn)
		return;
L
Linus Torvalds 已提交
992 993 994

	BT_DBG("hcon %p conn %p, err %d", hcon, conn, err);

995
	kfree_skb(conn->rx_skb);
L
Linus Torvalds 已提交
996 997

	/* Kill channels */
998
	list_for_each_entry_safe(chan, l, &conn->chan_l, list) {
999
		sk = chan->sk;
L
Linus Torvalds 已提交
1000
		bh_lock_sock(sk);
1001
		l2cap_chan_del(chan, err);
L
Linus Torvalds 已提交
1002 1003 1004 1005
		bh_unlock_sock(sk);
		l2cap_sock_kill(sk);
	}

1006 1007
	if (conn->info_state & L2CAP_INFO_FEAT_MASK_REQ_SENT)
		del_timer_sync(&conn->info_timer);
1008

L
Linus Torvalds 已提交
1009 1010 1011 1012
	hcon->l2cap_data = NULL;
	kfree(conn);
}

1013
static inline void l2cap_chan_add(struct l2cap_conn *conn, struct l2cap_chan *chan)
L
Linus Torvalds 已提交
1014
{
1015
	write_lock_bh(&conn->chan_lock);
1016
	__l2cap_chan_add(conn, chan);
1017
	write_unlock_bh(&conn->chan_lock);
L
Linus Torvalds 已提交
1018 1019 1020 1021 1022 1023 1024
}

/* ---- Socket interface ---- */

/* Find socket with psm and source bdaddr.
 * Returns closest match.
 */
1025
static struct l2cap_chan *l2cap_global_chan_by_psm(int state, __le16 psm, bdaddr_t *src)
L
Linus Torvalds 已提交
1026
{
1027
	struct l2cap_chan *c, *c1 = NULL;
L
Linus Torvalds 已提交
1028

1029
	read_lock(&chan_list_lock);
1030

1031 1032
	list_for_each_entry(c, &chan_list, global_l) {
		struct sock *sk = c->sk;
1033

L
Linus Torvalds 已提交
1034 1035 1036
		if (state && sk->sk_state != state)
			continue;

1037
		if (c->psm == psm) {
L
Linus Torvalds 已提交
1038
			/* Exact match. */
1039
			if (!bacmp(&bt_sk(sk)->src, src)) {
1040
				read_unlock(&chan_list_lock);
1041 1042
				return c;
			}
L
Linus Torvalds 已提交
1043 1044 1045

			/* Closest match */
			if (!bacmp(&bt_sk(sk)->src, BDADDR_ANY))
1046
				c1 = c;
L
Linus Torvalds 已提交
1047 1048 1049
		}
	}

1050
	read_unlock(&chan_list_lock);
1051

1052
	return c1;
L
Linus Torvalds 已提交
1053 1054
}

1055
int l2cap_chan_connect(struct l2cap_chan *chan)
L
Linus Torvalds 已提交
1056
{
1057
	struct sock *sk = chan->sk;
L
Linus Torvalds 已提交
1058 1059 1060 1061 1062
	bdaddr_t *src = &bt_sk(sk)->src;
	bdaddr_t *dst = &bt_sk(sk)->dst;
	struct l2cap_conn *conn;
	struct hci_conn *hcon;
	struct hci_dev *hdev;
1063
	__u8 auth_type;
1064
	int err;
L
Linus Torvalds 已提交
1065

1066
	BT_DBG("%s -> %s psm 0x%2.2x", batostr(src), batostr(dst),
1067
							chan->psm);
L
Linus Torvalds 已提交
1068

1069 1070
	hdev = hci_get_route(dst, src);
	if (!hdev)
L
Linus Torvalds 已提交
1071 1072 1073 1074
		return -EHOSTUNREACH;

	hci_dev_lock_bh(hdev);

1075
	auth_type = l2cap_get_auth_type(chan);
1076

1077
	if (chan->dcid == L2CAP_CID_LE_DATA)
1078
		hcon = hci_connect(hdev, LE_LINK, dst,
1079
					chan->sec_level, auth_type);
1080 1081
	else
		hcon = hci_connect(hdev, ACL_LINK, dst,
1082
					chan->sec_level, auth_type);
1083

1084 1085
	if (IS_ERR(hcon)) {
		err = PTR_ERR(hcon);
L
Linus Torvalds 已提交
1086
		goto done;
1087
	}
L
Linus Torvalds 已提交
1088 1089 1090 1091

	conn = l2cap_conn_add(hcon, 0);
	if (!conn) {
		hci_conn_put(hcon);
1092
		err = -ENOMEM;
L
Linus Torvalds 已提交
1093 1094 1095 1096 1097 1098
		goto done;
	}

	/* Update source addr of the socket */
	bacpy(src, conn->src);

1099 1100
	l2cap_chan_add(conn, chan);

L
Linus Torvalds 已提交
1101
	sk->sk_state = BT_CONNECT;
1102
	l2cap_chan_set_timer(chan, sk->sk_sndtimeo);
L
Linus Torvalds 已提交
1103 1104

	if (hcon->state == BT_CONNECTED) {
1105
		if (chan->chan_type != L2CAP_CHAN_CONN_ORIENTED) {
1106
			l2cap_chan_clear_timer(chan);
1107
			if (l2cap_check_security(chan))
1108
				sk->sk_state = BT_CONNECTED;
1109
		} else
1110
			l2cap_do_start(chan);
L
Linus Torvalds 已提交
1111 1112
	}

1113 1114
	err = 0;

L
Linus Torvalds 已提交
1115 1116 1117 1118 1119 1120
done:
	hci_dev_unlock_bh(hdev);
	hci_dev_put(hdev);
	return err;
}

1121
int __l2cap_wait_ack(struct sock *sk)
1122
{
1123
	struct l2cap_chan *chan = l2cap_pi(sk)->chan;
1124 1125 1126 1127
	DECLARE_WAITQUEUE(wait, current);
	int err = 0;
	int timeo = HZ/5;

1128
	add_wait_queue(sk_sleep(sk), &wait);
1129
	while ((chan->unacked_frames > 0 && chan->conn)) {
1130 1131 1132 1133 1134 1135 1136 1137 1138 1139 1140 1141 1142 1143 1144 1145 1146 1147 1148
		set_current_state(TASK_INTERRUPTIBLE);

		if (!timeo)
			timeo = HZ/5;

		if (signal_pending(current)) {
			err = sock_intr_errno(timeo);
			break;
		}

		release_sock(sk);
		timeo = schedule_timeout(timeo);
		lock_sock(sk);

		err = sock_error(sk);
		if (err)
			break;
	}
	set_current_state(TASK_RUNNING);
1149
	remove_wait_queue(sk_sleep(sk), &wait);
1150 1151 1152
	return err;
}

1153 1154
static void l2cap_monitor_timeout(unsigned long arg)
{
1155 1156
	struct l2cap_chan *chan = (void *) arg;
	struct sock *sk = chan->sk;
1157

1158
	BT_DBG("chan %p", chan);
1159

1160
	bh_lock_sock(sk);
1161
	if (chan->retry_count >= chan->remote_max_tx) {
1162
		l2cap_send_disconn_req(chan->conn, chan, ECONNABORTED);
1163
		bh_unlock_sock(sk);
1164 1165 1166
		return;
	}

1167
	chan->retry_count++;
1168 1169
	__mod_monitor_timer();

1170
	l2cap_send_rr_or_rnr(chan, L2CAP_CTRL_POLL);
1171
	bh_unlock_sock(sk);
1172 1173 1174 1175
}

static void l2cap_retrans_timeout(unsigned long arg)
{
1176 1177
	struct l2cap_chan *chan = (void *) arg;
	struct sock *sk = chan->sk;
1178

1179
	BT_DBG("chan %p", chan);
1180

1181
	bh_lock_sock(sk);
1182
	chan->retry_count = 1;
1183 1184
	__mod_monitor_timer();

1185
	chan->conn_state |= L2CAP_CONN_WAIT_F;
1186

1187
	l2cap_send_rr_or_rnr(chan, L2CAP_CTRL_POLL);
1188
	bh_unlock_sock(sk);
1189 1190
}

1191
static void l2cap_drop_acked_frames(struct l2cap_chan *chan)
L
Linus Torvalds 已提交
1192
{
1193
	struct sk_buff *skb;
L
Linus Torvalds 已提交
1194

1195
	while ((skb = skb_peek(&chan->tx_q)) &&
1196
			chan->unacked_frames) {
1197
		if (bt_cb(skb)->tx_seq == chan->expected_ack_seq)
1198
			break;
L
Linus Torvalds 已提交
1199

1200
		skb = skb_dequeue(&chan->tx_q);
1201
		kfree_skb(skb);
L
Linus Torvalds 已提交
1202

1203
		chan->unacked_frames--;
1204
	}
L
Linus Torvalds 已提交
1205

1206
	if (!chan->unacked_frames)
1207
		del_timer(&chan->retrans_timer);
1208
}
L
Linus Torvalds 已提交
1209

1210
void l2cap_do_send(struct l2cap_chan *chan, struct sk_buff *skb)
1211
{
1212
	struct hci_conn *hcon = chan->conn->hcon;
1213
	u16 flags;
1214

1215
	BT_DBG("chan %p, skb %p len %d", chan, skb, skb->len);
L
Linus Torvalds 已提交
1216

1217
	if (!chan->flushable && lmp_no_flush_capable(hcon->hdev))
1218 1219 1220 1221 1222
		flags = ACL_START_NO_FLUSH;
	else
		flags = ACL_START;

	hci_send_acl(hcon, skb, flags);
1223 1224
}

1225
void l2cap_streaming_send(struct l2cap_chan *chan)
1226
{
1227
	struct sk_buff *skb;
1228
	u16 control, fcs;
1229

1230
	while ((skb = skb_dequeue(&chan->tx_q))) {
1231
		control = get_unaligned_le16(skb->data + L2CAP_HDR_SIZE);
1232
		control |= chan->next_tx_seq << L2CAP_CTRL_TXSEQ_SHIFT;
1233
		put_unaligned_le16(control, skb->data + L2CAP_HDR_SIZE);
1234

1235
		if (chan->fcs == L2CAP_FCS_CRC16) {
1236 1237
			fcs = crc16(0, (u8 *)skb->data, skb->len - 2);
			put_unaligned_le16(fcs, skb->data + skb->len - 2);
1238 1239
		}

1240
		l2cap_do_send(chan, skb);
1241

1242
		chan->next_tx_seq = (chan->next_tx_seq + 1) % 64;
1243 1244 1245
	}
}

1246
static void l2cap_retransmit_one_frame(struct l2cap_chan *chan, u8 tx_seq)
1247 1248 1249 1250
{
	struct sk_buff *skb, *tx_skb;
	u16 control, fcs;

1251
	skb = skb_peek(&chan->tx_q);
1252 1253
	if (!skb)
		return;
1254

1255 1256
	do {
		if (bt_cb(skb)->tx_seq == tx_seq)
1257 1258
			break;

1259
		if (skb_queue_is_last(&chan->tx_q, skb))
1260
			return;
1261

1262
	} while ((skb = skb_queue_next(&chan->tx_q, skb)));
1263

1264 1265
	if (chan->remote_max_tx &&
			bt_cb(skb)->retries == chan->remote_max_tx) {
1266
		l2cap_send_disconn_req(chan->conn, chan, ECONNABORTED);
1267 1268 1269 1270 1271 1272
		return;
	}

	tx_skb = skb_clone(skb, GFP_ATOMIC);
	bt_cb(skb)->retries++;
	control = get_unaligned_le16(tx_skb->data + L2CAP_HDR_SIZE);
1273
	control &= L2CAP_CTRL_SAR;
1274

1275
	if (chan->conn_state & L2CAP_CONN_SEND_FBIT) {
1276
		control |= L2CAP_CTRL_FINAL;
1277
		chan->conn_state &= ~L2CAP_CONN_SEND_FBIT;
1278
	}
1279

1280
	control |= (chan->buffer_seq << L2CAP_CTRL_REQSEQ_SHIFT)
1281
			| (tx_seq << L2CAP_CTRL_TXSEQ_SHIFT);
1282

1283 1284
	put_unaligned_le16(control, tx_skb->data + L2CAP_HDR_SIZE);

1285
	if (chan->fcs == L2CAP_FCS_CRC16) {
1286 1287 1288 1289
		fcs = crc16(0, (u8 *)tx_skb->data, tx_skb->len - 2);
		put_unaligned_le16(fcs, tx_skb->data + tx_skb->len - 2);
	}

1290
	l2cap_do_send(chan, tx_skb);
1291 1292
}

1293
int l2cap_ertm_send(struct l2cap_chan *chan)
1294 1295
{
	struct sk_buff *skb, *tx_skb;
1296
	struct sock *sk = chan->sk;
1297
	u16 control, fcs;
1298
	int nsent = 0;
1299

1300 1301
	if (sk->sk_state != BT_CONNECTED)
		return -ENOTCONN;
1302

1303
	while ((skb = chan->tx_send_head) && (!l2cap_tx_window_full(chan))) {
1304

1305 1306
		if (chan->remote_max_tx &&
				bt_cb(skb)->retries == chan->remote_max_tx) {
1307
			l2cap_send_disconn_req(chan->conn, chan, ECONNABORTED);
1308 1309 1310
			break;
		}

1311 1312
		tx_skb = skb_clone(skb, GFP_ATOMIC);

1313 1314
		bt_cb(skb)->retries++;

1315
		control = get_unaligned_le16(tx_skb->data + L2CAP_HDR_SIZE);
1316 1317
		control &= L2CAP_CTRL_SAR;

1318
		if (chan->conn_state & L2CAP_CONN_SEND_FBIT) {
1319
			control |= L2CAP_CTRL_FINAL;
1320
			chan->conn_state &= ~L2CAP_CONN_SEND_FBIT;
1321
		}
1322 1323
		control |= (chan->buffer_seq << L2CAP_CTRL_REQSEQ_SHIFT)
				| (chan->next_tx_seq << L2CAP_CTRL_TXSEQ_SHIFT);
1324 1325
		put_unaligned_le16(control, tx_skb->data + L2CAP_HDR_SIZE);

1326

1327
		if (chan->fcs == L2CAP_FCS_CRC16) {
1328 1329 1330 1331
			fcs = crc16(0, (u8 *)skb->data, tx_skb->len - 2);
			put_unaligned_le16(fcs, skb->data + tx_skb->len - 2);
		}

1332
		l2cap_do_send(chan, tx_skb);
1333

1334
		__mod_retrans_timer();
1335

1336 1337
		bt_cb(skb)->tx_seq = chan->next_tx_seq;
		chan->next_tx_seq = (chan->next_tx_seq + 1) % 64;
1338

1339
		if (bt_cb(skb)->retries == 1)
1340
			chan->unacked_frames++;
1341

1342
		chan->frames_sent++;
1343

1344 1345
		if (skb_queue_is_last(&chan->tx_q, skb))
			chan->tx_send_head = NULL;
1346
		else
1347
			chan->tx_send_head = skb_queue_next(&chan->tx_q, skb);
1348 1349

		nsent++;
1350 1351
	}

1352 1353 1354
	return nsent;
}

1355
static int l2cap_retransmit_frames(struct l2cap_chan *chan)
1356 1357 1358
{
	int ret;

1359 1360
	if (!skb_queue_empty(&chan->tx_q))
		chan->tx_send_head = chan->tx_q.next;
1361

1362
	chan->next_tx_seq = chan->expected_ack_seq;
1363
	ret = l2cap_ertm_send(chan);
1364 1365 1366
	return ret;
}

1367
static void l2cap_send_ack(struct l2cap_chan *chan)
1368 1369 1370
{
	u16 control = 0;

1371
	control |= chan->buffer_seq << L2CAP_CTRL_REQSEQ_SHIFT;
1372

1373
	if (chan->conn_state & L2CAP_CONN_LOCAL_BUSY) {
1374
		control |= L2CAP_SUPER_RCV_NOT_READY;
1375 1376
		chan->conn_state |= L2CAP_CONN_RNR_SENT;
		l2cap_send_sframe(chan, control);
1377
		return;
1378
	}
1379

1380
	if (l2cap_ertm_send(chan) > 0)
1381 1382 1383
		return;

	control |= L2CAP_SUPER_RCV_READY;
1384
	l2cap_send_sframe(chan, control);
1385 1386
}

1387
static void l2cap_send_srejtail(struct l2cap_chan *chan)
1388 1389 1390 1391 1392 1393 1394
{
	struct srej_list *tail;
	u16 control;

	control = L2CAP_SUPER_SELECT_REJECT;
	control |= L2CAP_CTRL_FINAL;

1395
	tail = list_entry((&chan->srej_l)->prev, struct srej_list, list);
1396 1397
	control |= tail->tx_seq << L2CAP_CTRL_REQSEQ_SHIFT;

1398
	l2cap_send_sframe(chan, control);
1399 1400
}

1401 1402
static inline int l2cap_skbuff_fromiovec(struct sock *sk, struct msghdr *msg, int len, int count, struct sk_buff *skb)
{
1403
	struct l2cap_conn *conn = l2cap_pi(sk)->chan->conn;
1404 1405
	struct sk_buff **frag;
	int err, sent = 0;
L
Linus Torvalds 已提交
1406

1407
	if (memcpy_fromiovec(skb_put(skb, count), msg->msg_iov, count))
1408
		return -EFAULT;
L
Linus Torvalds 已提交
1409 1410 1411 1412 1413 1414 1415 1416 1417 1418 1419

	sent += count;
	len  -= count;

	/* Continuation fragments (no L2CAP header) */
	frag = &skb_shinfo(skb)->frag_list;
	while (len) {
		count = min_t(unsigned int, conn->mtu, len);

		*frag = bt_skb_send_alloc(sk, count, msg->msg_flags & MSG_DONTWAIT, &err);
		if (!*frag)
1420
			return err;
1421 1422
		if (memcpy_fromiovec(skb_put(*frag, count), msg->msg_iov, count))
			return -EFAULT;
L
Linus Torvalds 已提交
1423 1424 1425 1426 1427 1428 1429 1430

		sent += count;
		len  -= count;

		frag = &(*frag)->next;
	}

	return sent;
1431
}
L
Linus Torvalds 已提交
1432

1433
struct sk_buff *l2cap_create_connless_pdu(struct l2cap_chan *chan, struct msghdr *msg, size_t len)
1434
{
1435
	struct sock *sk = chan->sk;
1436
	struct l2cap_conn *conn = chan->conn;
1437 1438 1439 1440 1441 1442 1443 1444 1445 1446
	struct sk_buff *skb;
	int err, count, hlen = L2CAP_HDR_SIZE + 2;
	struct l2cap_hdr *lh;

	BT_DBG("sk %p len %d", sk, (int)len);

	count = min_t(unsigned int, (conn->mtu - hlen), len);
	skb = bt_skb_send_alloc(sk, count + hlen,
			msg->msg_flags & MSG_DONTWAIT, &err);
	if (!skb)
1447
		return ERR_PTR(err);
1448 1449 1450

	/* Create L2CAP header */
	lh = (struct l2cap_hdr *) skb_put(skb, L2CAP_HDR_SIZE);
1451
	lh->cid = cpu_to_le16(chan->dcid);
1452
	lh->len = cpu_to_le16(len + (hlen - L2CAP_HDR_SIZE));
1453
	put_unaligned_le16(chan->psm, skb_put(skb, 2));
1454 1455 1456 1457 1458 1459 1460 1461 1462

	err = l2cap_skbuff_fromiovec(sk, msg, len, count, skb);
	if (unlikely(err < 0)) {
		kfree_skb(skb);
		return ERR_PTR(err);
	}
	return skb;
}

1463
struct sk_buff *l2cap_create_basic_pdu(struct l2cap_chan *chan, struct msghdr *msg, size_t len)
1464
{
1465
	struct sock *sk = chan->sk;
1466
	struct l2cap_conn *conn = chan->conn;
1467 1468 1469 1470 1471 1472 1473 1474 1475 1476
	struct sk_buff *skb;
	int err, count, hlen = L2CAP_HDR_SIZE;
	struct l2cap_hdr *lh;

	BT_DBG("sk %p len %d", sk, (int)len);

	count = min_t(unsigned int, (conn->mtu - hlen), len);
	skb = bt_skb_send_alloc(sk, count + hlen,
			msg->msg_flags & MSG_DONTWAIT, &err);
	if (!skb)
1477
		return ERR_PTR(err);
1478 1479 1480

	/* Create L2CAP header */
	lh = (struct l2cap_hdr *) skb_put(skb, L2CAP_HDR_SIZE);
1481
	lh->cid = cpu_to_le16(chan->dcid);
1482 1483 1484 1485 1486 1487 1488 1489 1490 1491
	lh->len = cpu_to_le16(len + (hlen - L2CAP_HDR_SIZE));

	err = l2cap_skbuff_fromiovec(sk, msg, len, count, skb);
	if (unlikely(err < 0)) {
		kfree_skb(skb);
		return ERR_PTR(err);
	}
	return skb;
}

1492
struct sk_buff *l2cap_create_iframe_pdu(struct l2cap_chan *chan, struct msghdr *msg, size_t len, u16 control, u16 sdulen)
1493
{
1494
	struct sock *sk = chan->sk;
1495
	struct l2cap_conn *conn = chan->conn;
1496 1497 1498 1499 1500 1501
	struct sk_buff *skb;
	int err, count, hlen = L2CAP_HDR_SIZE + 2;
	struct l2cap_hdr *lh;

	BT_DBG("sk %p len %d", sk, (int)len);

1502 1503 1504
	if (!conn)
		return ERR_PTR(-ENOTCONN);

1505 1506 1507
	if (sdulen)
		hlen += 2;

1508
	if (chan->fcs == L2CAP_FCS_CRC16)
1509 1510
		hlen += 2;

1511 1512 1513 1514
	count = min_t(unsigned int, (conn->mtu - hlen), len);
	skb = bt_skb_send_alloc(sk, count + hlen,
			msg->msg_flags & MSG_DONTWAIT, &err);
	if (!skb)
1515
		return ERR_PTR(err);
1516 1517 1518

	/* Create L2CAP header */
	lh = (struct l2cap_hdr *) skb_put(skb, L2CAP_HDR_SIZE);
1519
	lh->cid = cpu_to_le16(chan->dcid);
1520 1521
	lh->len = cpu_to_le16(len + (hlen - L2CAP_HDR_SIZE));
	put_unaligned_le16(control, skb_put(skb, 2));
1522 1523
	if (sdulen)
		put_unaligned_le16(sdulen, skb_put(skb, 2));
1524 1525 1526 1527 1528 1529

	err = l2cap_skbuff_fromiovec(sk, msg, len, count, skb);
	if (unlikely(err < 0)) {
		kfree_skb(skb);
		return ERR_PTR(err);
	}
1530

1531
	if (chan->fcs == L2CAP_FCS_CRC16)
1532 1533
		put_unaligned_le16(0, skb_put(skb, 2));

1534
	bt_cb(skb)->retries = 0;
1535
	return skb;
L
Linus Torvalds 已提交
1536 1537
}

1538
int l2cap_sar_segment_sdu(struct l2cap_chan *chan, struct msghdr *msg, size_t len)
1539 1540 1541 1542 1543 1544
{
	struct sk_buff *skb;
	struct sk_buff_head sar_queue;
	u16 control;
	size_t size = 0;

1545
	skb_queue_head_init(&sar_queue);
1546
	control = L2CAP_SDU_START;
1547
	skb = l2cap_create_iframe_pdu(chan, msg, chan->remote_mps, control, len);
1548 1549 1550 1551
	if (IS_ERR(skb))
		return PTR_ERR(skb);

	__skb_queue_tail(&sar_queue, skb);
1552 1553
	len -= chan->remote_mps;
	size += chan->remote_mps;
1554 1555 1556 1557

	while (len > 0) {
		size_t buflen;

1558
		if (len > chan->remote_mps) {
1559
			control = L2CAP_SDU_CONTINUE;
1560
			buflen = chan->remote_mps;
1561
		} else {
1562
			control = L2CAP_SDU_END;
1563 1564 1565
			buflen = len;
		}

1566
		skb = l2cap_create_iframe_pdu(chan, msg, buflen, control, 0);
1567 1568 1569 1570 1571 1572 1573 1574 1575
		if (IS_ERR(skb)) {
			skb_queue_purge(&sar_queue);
			return PTR_ERR(skb);
		}

		__skb_queue_tail(&sar_queue, skb);
		len -= buflen;
		size += buflen;
	}
1576 1577 1578
	skb_queue_splice_tail(&sar_queue, &chan->tx_q);
	if (chan->tx_send_head == NULL)
		chan->tx_send_head = sar_queue.next;
1579 1580 1581 1582

	return size;
}

1583 1584 1585 1586 1587 1588 1589
int l2cap_chan_send(struct l2cap_chan *chan, struct msghdr *msg, size_t len)
{
	struct sk_buff *skb;
	u16 control;
	int err;

	/* Connectionless channel */
1590
	if (chan->chan_type == L2CAP_CHAN_CONN_LESS) {
1591 1592 1593 1594 1595 1596 1597 1598 1599 1600 1601 1602 1603 1604 1605 1606 1607 1608 1609 1610 1611 1612 1613 1614 1615 1616 1617 1618 1619 1620 1621 1622 1623 1624 1625 1626 1627 1628 1629 1630 1631 1632 1633 1634 1635 1636 1637 1638 1639 1640 1641 1642 1643 1644 1645 1646 1647 1648 1649 1650 1651 1652 1653 1654 1655 1656 1657 1658 1659 1660 1661
		skb = l2cap_create_connless_pdu(chan, msg, len);
		if (IS_ERR(skb))
			return PTR_ERR(skb);

		l2cap_do_send(chan, skb);
		return len;
	}

	switch (chan->mode) {
	case L2CAP_MODE_BASIC:
		/* Check outgoing MTU */
		if (len > chan->omtu)
			return -EMSGSIZE;

		/* Create a basic PDU */
		skb = l2cap_create_basic_pdu(chan, msg, len);
		if (IS_ERR(skb))
			return PTR_ERR(skb);

		l2cap_do_send(chan, skb);
		err = len;
		break;

	case L2CAP_MODE_ERTM:
	case L2CAP_MODE_STREAMING:
		/* Entire SDU fits into one PDU */
		if (len <= chan->remote_mps) {
			control = L2CAP_SDU_UNSEGMENTED;
			skb = l2cap_create_iframe_pdu(chan, msg, len, control,
									0);
			if (IS_ERR(skb))
				return PTR_ERR(skb);

			__skb_queue_tail(&chan->tx_q, skb);

			if (chan->tx_send_head == NULL)
				chan->tx_send_head = skb;

		} else {
			/* Segment SDU into multiples PDUs */
			err = l2cap_sar_segment_sdu(chan, msg, len);
			if (err < 0)
				return err;
		}

		if (chan->mode == L2CAP_MODE_STREAMING) {
			l2cap_streaming_send(chan);
			err = len;
			break;
		}

		if ((chan->conn_state & L2CAP_CONN_REMOTE_BUSY) &&
				(chan->conn_state & L2CAP_CONN_WAIT_F)) {
			err = len;
			break;
		}

		err = l2cap_ertm_send(chan);
		if (err >= 0)
			err = len;

		break;

	default:
		BT_DBG("bad state %1.1x", chan->mode);
		err = -EBADFD;
	}

	return err;
}

L
Linus Torvalds 已提交
1662 1663 1664
static void l2cap_chan_ready(struct sock *sk)
{
	struct sock *parent = bt_sk(sk)->parent;
1665
	struct l2cap_chan *chan = l2cap_pi(sk)->chan;
L
Linus Torvalds 已提交
1666 1667 1668

	BT_DBG("sk %p, parent %p", sk, parent);

1669
	chan->conf_state = 0;
1670
	l2cap_chan_clear_timer(chan);
L
Linus Torvalds 已提交
1671 1672 1673 1674 1675 1676 1677 1678 1679 1680 1681 1682 1683 1684 1685 1686 1687 1688 1689

	if (!parent) {
		/* Outgoing channel.
		 * Wake up socket sleeping on connect.
		 */
		sk->sk_state = BT_CONNECTED;
		sk->sk_state_change(sk);
	} else {
		/* Incoming channel.
		 * Wake up socket sleeping on accept.
		 */
		parent->sk_data_ready(parent, 0);
	}
}

/* Copy frame to all raw sockets on that connection */
static void l2cap_raw_recv(struct l2cap_conn *conn, struct sk_buff *skb)
{
	struct sk_buff *nskb;
1690
	struct l2cap_chan *chan;
L
Linus Torvalds 已提交
1691 1692 1693

	BT_DBG("conn %p", conn);

1694 1695
	read_lock(&conn->chan_lock);
	list_for_each_entry(chan, &conn->chan_l, list) {
1696
		struct sock *sk = chan->sk;
1697
		if (chan->chan_type != L2CAP_CHAN_RAW)
L
Linus Torvalds 已提交
1698 1699 1700 1701 1702
			continue;

		/* Don't send frame to the socket it came from */
		if (skb->sk == sk)
			continue;
1703 1704
		nskb = skb_clone(skb, GFP_ATOMIC);
		if (!nskb)
L
Linus Torvalds 已提交
1705 1706 1707 1708 1709
			continue;

		if (sock_queue_rcv_skb(sk, nskb))
			kfree_skb(nskb);
	}
1710
	read_unlock(&conn->chan_lock);
L
Linus Torvalds 已提交
1711 1712 1713 1714 1715 1716 1717 1718 1719 1720 1721
}

/* ---- L2CAP signalling commands ---- */
static struct sk_buff *l2cap_build_cmd(struct l2cap_conn *conn,
				u8 code, u8 ident, u16 dlen, void *data)
{
	struct sk_buff *skb, **frag;
	struct l2cap_cmd_hdr *cmd;
	struct l2cap_hdr *lh;
	int len, count;

1722 1723
	BT_DBG("conn %p, code 0x%2.2x, ident 0x%2.2x, len %d",
			conn, code, ident, dlen);
L
Linus Torvalds 已提交
1724 1725 1726 1727 1728 1729 1730 1731 1732

	len = L2CAP_HDR_SIZE + L2CAP_CMD_HDR_SIZE + dlen;
	count = min_t(unsigned int, conn->mtu, len);

	skb = bt_skb_alloc(count, GFP_ATOMIC);
	if (!skb)
		return NULL;

	lh = (struct l2cap_hdr *) skb_put(skb, L2CAP_HDR_SIZE);
1733
	lh->len = cpu_to_le16(L2CAP_CMD_HDR_SIZE + dlen);
1734 1735 1736 1737 1738

	if (conn->hcon->type == LE_LINK)
		lh->cid = cpu_to_le16(L2CAP_CID_LE_SIGNALING);
	else
		lh->cid = cpu_to_le16(L2CAP_CID_SIGNALING);
L
Linus Torvalds 已提交
1739 1740 1741 1742

	cmd = (struct l2cap_cmd_hdr *) skb_put(skb, L2CAP_CMD_HDR_SIZE);
	cmd->code  = code;
	cmd->ident = ident;
1743
	cmd->len   = cpu_to_le16(dlen);
L
Linus Torvalds 已提交
1744 1745 1746 1747 1748 1749 1750 1751 1752 1753 1754 1755 1756 1757 1758 1759 1760 1761 1762 1763 1764 1765 1766 1767 1768 1769 1770 1771 1772 1773 1774 1775 1776 1777 1778 1779 1780 1781 1782 1783 1784 1785 1786 1787 1788 1789 1790 1791 1792 1793

	if (dlen) {
		count -= L2CAP_HDR_SIZE + L2CAP_CMD_HDR_SIZE;
		memcpy(skb_put(skb, count), data, count);
		data += count;
	}

	len -= skb->len;

	/* Continuation fragments (no L2CAP header) */
	frag = &skb_shinfo(skb)->frag_list;
	while (len) {
		count = min_t(unsigned int, conn->mtu, len);

		*frag = bt_skb_alloc(count, GFP_ATOMIC);
		if (!*frag)
			goto fail;

		memcpy(skb_put(*frag, count), data, count);

		len  -= count;
		data += count;

		frag = &(*frag)->next;
	}

	return skb;

fail:
	kfree_skb(skb);
	return NULL;
}

static inline int l2cap_get_conf_opt(void **ptr, int *type, int *olen, unsigned long *val)
{
	struct l2cap_conf_opt *opt = *ptr;
	int len;

	len = L2CAP_CONF_OPT_SIZE + opt->len;
	*ptr += len;

	*type = opt->type;
	*olen = opt->len;

	switch (opt->len) {
	case 1:
		*val = *((u8 *) opt->val);
		break;

	case 2:
1794
		*val = get_unaligned_le16(opt->val);
L
Linus Torvalds 已提交
1795 1796 1797
		break;

	case 4:
1798
		*val = get_unaligned_le32(opt->val);
L
Linus Torvalds 已提交
1799 1800 1801 1802 1803 1804 1805 1806 1807 1808 1809 1810 1811 1812 1813 1814 1815 1816 1817 1818 1819 1820 1821 1822 1823 1824
		break;

	default:
		*val = (unsigned long) opt->val;
		break;
	}

	BT_DBG("type 0x%2.2x len %d val 0x%lx", *type, opt->len, *val);
	return len;
}

static void l2cap_add_conf_opt(void **ptr, u8 type, u8 len, unsigned long val)
{
	struct l2cap_conf_opt *opt = *ptr;

	BT_DBG("type 0x%2.2x len %d val 0x%lx", type, len, val);

	opt->type = type;
	opt->len  = len;

	switch (len) {
	case 1:
		*((u8 *) opt->val)  = val;
		break;

	case 2:
1825
		put_unaligned_le16(val, opt->val);
L
Linus Torvalds 已提交
1826 1827 1828
		break;

	case 4:
1829
		put_unaligned_le32(val, opt->val);
L
Linus Torvalds 已提交
1830 1831 1832 1833 1834 1835 1836 1837 1838 1839
		break;

	default:
		memcpy(opt->val, (void *) val, len);
		break;
	}

	*ptr += L2CAP_CONF_OPT_SIZE + len;
}

1840 1841
static void l2cap_ack_timeout(unsigned long arg)
{
1842
	struct l2cap_chan *chan = (void *) arg;
1843

1844 1845 1846
	bh_lock_sock(chan->sk);
	l2cap_send_ack(chan);
	bh_unlock_sock(chan->sk);
1847 1848
}

1849
static inline void l2cap_ertm_init(struct l2cap_chan *chan)
1850
{
1851 1852
	struct sock *sk = chan->sk;

1853
	chan->expected_ack_seq = 0;
1854
	chan->unacked_frames = 0;
1855
	chan->buffer_seq = 0;
1856 1857
	chan->num_acked = 0;
	chan->frames_sent = 0;
1858

1859 1860 1861 1862 1863
	setup_timer(&chan->retrans_timer, l2cap_retrans_timeout,
							(unsigned long) chan);
	setup_timer(&chan->monitor_timer, l2cap_monitor_timeout,
							(unsigned long) chan);
	setup_timer(&chan->ack_timer, l2cap_ack_timeout, (unsigned long) chan);
1864

1865 1866
	skb_queue_head_init(&chan->srej_q);
	skb_queue_head_init(&chan->busy_q);
1867

1868 1869
	INIT_LIST_HEAD(&chan->srej_l);

1870
	INIT_WORK(&chan->busy_work, l2cap_busy_work);
1871 1872

	sk->sk_backlog_rcv = l2cap_ertm_data_rcv;
1873 1874
}

1875 1876 1877 1878 1879 1880 1881 1882 1883 1884 1885 1886 1887
static inline __u8 l2cap_select_mode(__u8 mode, __u16 remote_feat_mask)
{
	switch (mode) {
	case L2CAP_MODE_STREAMING:
	case L2CAP_MODE_ERTM:
		if (l2cap_mode_supported(mode, remote_feat_mask))
			return mode;
		/* fall through */
	default:
		return L2CAP_MODE_BASIC;
	}
}

1888
static int l2cap_build_conf_req(struct l2cap_chan *chan, void *data)
L
Linus Torvalds 已提交
1889 1890
{
	struct l2cap_conf_req *req = data;
1891
	struct l2cap_conf_rfc rfc = { .mode = chan->mode };
L
Linus Torvalds 已提交
1892 1893
	void *ptr = req->data;

1894
	BT_DBG("chan %p", chan);
L
Linus Torvalds 已提交
1895

1896
	if (chan->num_conf_req || chan->num_conf_rsp)
1897 1898
		goto done;

1899
	switch (chan->mode) {
1900 1901
	case L2CAP_MODE_STREAMING:
	case L2CAP_MODE_ERTM:
1902
		if (chan->conf_state & L2CAP_CONF_STATE2_DEVICE)
1903 1904
			break;

1905
		/* fall through */
1906
	default:
1907
		chan->mode = l2cap_select_mode(rfc.mode, chan->conn->feat_mask);
1908 1909 1910 1911
		break;
	}

done:
1912 1913
	if (chan->imtu != L2CAP_DEFAULT_MTU)
		l2cap_add_conf_opt(&ptr, L2CAP_CONF_MTU, 2, chan->imtu);
1914

1915
	switch (chan->mode) {
1916
	case L2CAP_MODE_BASIC:
1917 1918
		if (!(chan->conn->feat_mask & L2CAP_FEAT_ERTM) &&
				!(chan->conn->feat_mask & L2CAP_FEAT_STREAMING))
1919 1920
			break;

1921 1922 1923 1924 1925 1926 1927
		rfc.mode            = L2CAP_MODE_BASIC;
		rfc.txwin_size      = 0;
		rfc.max_transmit    = 0;
		rfc.retrans_timeout = 0;
		rfc.monitor_timeout = 0;
		rfc.max_pdu_size    = 0;

1928 1929
		l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC, sizeof(rfc),
							(unsigned long) &rfc);
1930 1931 1932 1933
		break;

	case L2CAP_MODE_ERTM:
		rfc.mode            = L2CAP_MODE_ERTM;
1934 1935
		rfc.txwin_size      = chan->tx_win;
		rfc.max_transmit    = chan->max_tx;
1936 1937
		rfc.retrans_timeout = 0;
		rfc.monitor_timeout = 0;
1938
		rfc.max_pdu_size    = cpu_to_le16(L2CAP_DEFAULT_MAX_PDU_SIZE);
1939 1940
		if (L2CAP_DEFAULT_MAX_PDU_SIZE > chan->conn->mtu - 10)
			rfc.max_pdu_size = cpu_to_le16(chan->conn->mtu - 10);
1941

1942 1943 1944
		l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC, sizeof(rfc),
							(unsigned long) &rfc);

1945
		if (!(chan->conn->feat_mask & L2CAP_FEAT_FCS))
1946 1947
			break;

1948
		if (chan->fcs == L2CAP_FCS_NONE ||
1949
				chan->conf_state & L2CAP_CONF_NO_FCS_RECV) {
1950 1951
			chan->fcs = L2CAP_FCS_NONE;
			l2cap_add_conf_opt(&ptr, L2CAP_CONF_FCS, 1, chan->fcs);
1952
		}
1953 1954 1955 1956 1957 1958 1959 1960
		break;

	case L2CAP_MODE_STREAMING:
		rfc.mode            = L2CAP_MODE_STREAMING;
		rfc.txwin_size      = 0;
		rfc.max_transmit    = 0;
		rfc.retrans_timeout = 0;
		rfc.monitor_timeout = 0;
1961
		rfc.max_pdu_size    = cpu_to_le16(L2CAP_DEFAULT_MAX_PDU_SIZE);
1962 1963
		if (L2CAP_DEFAULT_MAX_PDU_SIZE > chan->conn->mtu - 10)
			rfc.max_pdu_size = cpu_to_le16(chan->conn->mtu - 10);
1964

1965 1966 1967
		l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC, sizeof(rfc),
							(unsigned long) &rfc);

1968
		if (!(chan->conn->feat_mask & L2CAP_FEAT_FCS))
1969 1970
			break;

1971
		if (chan->fcs == L2CAP_FCS_NONE ||
1972
				chan->conf_state & L2CAP_CONF_NO_FCS_RECV) {
1973 1974
			chan->fcs = L2CAP_FCS_NONE;
			l2cap_add_conf_opt(&ptr, L2CAP_CONF_FCS, 1, chan->fcs);
1975
		}
1976 1977
		break;
	}
L
Linus Torvalds 已提交
1978

1979
	req->dcid  = cpu_to_le16(chan->dcid);
1980
	req->flags = cpu_to_le16(0);
L
Linus Torvalds 已提交
1981 1982 1983 1984

	return ptr - data;
}

1985
static int l2cap_parse_conf_req(struct l2cap_chan *chan, void *data)
L
Linus Torvalds 已提交
1986
{
1987 1988
	struct l2cap_conf_rsp *rsp = data;
	void *ptr = rsp->data;
1989 1990
	void *req = chan->conf_req;
	int len = chan->conf_len;
1991 1992
	int type, hint, olen;
	unsigned long val;
1993
	struct l2cap_conf_rfc rfc = { .mode = L2CAP_MODE_BASIC };
1994
	u16 mtu = L2CAP_DEFAULT_MTU;
1995
	u16 result = L2CAP_CONF_SUCCESS;
L
Linus Torvalds 已提交
1996

1997
	BT_DBG("chan %p", chan);
1998

1999 2000
	while (len >= L2CAP_CONF_OPT_SIZE) {
		len -= l2cap_get_conf_opt(&req, &type, &olen, &val);
L
Linus Torvalds 已提交
2001

2002
		hint  = type & L2CAP_CONF_HINT;
2003
		type &= L2CAP_CONF_MASK;
2004 2005 2006

		switch (type) {
		case L2CAP_CONF_MTU:
2007
			mtu = val;
2008 2009 2010
			break;

		case L2CAP_CONF_FLUSH_TO:
2011
			chan->flush_to = val;
2012 2013 2014 2015 2016
			break;

		case L2CAP_CONF_QOS:
			break;

2017 2018 2019 2020 2021
		case L2CAP_CONF_RFC:
			if (olen == sizeof(rfc))
				memcpy(&rfc, (void *) val, olen);
			break;

2022 2023
		case L2CAP_CONF_FCS:
			if (val == L2CAP_FCS_NONE)
2024
				chan->conf_state |= L2CAP_CONF_NO_FCS_RECV;
2025 2026 2027

			break;

2028 2029 2030 2031 2032 2033 2034 2035 2036 2037
		default:
			if (hint)
				break;

			result = L2CAP_CONF_UNKNOWN;
			*((u8 *) ptr++) = type;
			break;
		}
	}

2038
	if (chan->num_conf_rsp || chan->num_conf_req > 1)
2039 2040
		goto done;

2041
	switch (chan->mode) {
2042 2043
	case L2CAP_MODE_STREAMING:
	case L2CAP_MODE_ERTM:
2044
		if (!(chan->conf_state & L2CAP_CONF_STATE2_DEVICE)) {
2045
			chan->mode = l2cap_select_mode(rfc.mode,
2046
					chan->conn->feat_mask);
2047 2048 2049
			break;
		}

2050
		if (chan->mode != rfc.mode)
2051
			return -ECONNREFUSED;
2052

2053 2054 2055 2056
		break;
	}

done:
2057
	if (chan->mode != rfc.mode) {
2058
		result = L2CAP_CONF_UNACCEPT;
2059
		rfc.mode = chan->mode;
2060

2061
		if (chan->num_conf_rsp == 1)
2062 2063 2064 2065 2066 2067 2068
			return -ECONNREFUSED;

		l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC,
					sizeof(rfc), (unsigned long) &rfc);
	}


2069 2070 2071 2072
	if (result == L2CAP_CONF_SUCCESS) {
		/* Configure output options and let the other side know
		 * which ones we don't like. */

2073 2074 2075
		if (mtu < L2CAP_DEFAULT_MIN_MTU)
			result = L2CAP_CONF_UNACCEPT;
		else {
2076
			chan->omtu = mtu;
2077
			chan->conf_state |= L2CAP_CONF_MTU_DONE;
2078
		}
2079
		l2cap_add_conf_opt(&ptr, L2CAP_CONF_MTU, 2, chan->omtu);
2080

2081 2082
		switch (rfc.mode) {
		case L2CAP_MODE_BASIC:
2083
			chan->fcs = L2CAP_FCS_NONE;
2084
			chan->conf_state |= L2CAP_CONF_MODE_DONE;
2085 2086 2087
			break;

		case L2CAP_MODE_ERTM:
2088 2089
			chan->remote_tx_win = rfc.txwin_size;
			chan->remote_max_tx = rfc.max_transmit;
2090

2091 2092
			if (le16_to_cpu(rfc.max_pdu_size) > chan->conn->mtu - 10)
				rfc.max_pdu_size = cpu_to_le16(chan->conn->mtu - 10);
2093

2094
			chan->remote_mps = le16_to_cpu(rfc.max_pdu_size);
2095

2096 2097 2098 2099
			rfc.retrans_timeout =
				le16_to_cpu(L2CAP_DEFAULT_RETRANS_TO);
			rfc.monitor_timeout =
				le16_to_cpu(L2CAP_DEFAULT_MONITOR_TO);
2100

2101
			chan->conf_state |= L2CAP_CONF_MODE_DONE;
2102 2103 2104 2105

			l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC,
					sizeof(rfc), (unsigned long) &rfc);

2106 2107 2108
			break;

		case L2CAP_MODE_STREAMING:
2109 2110
			if (le16_to_cpu(rfc.max_pdu_size) > chan->conn->mtu - 10)
				rfc.max_pdu_size = cpu_to_le16(chan->conn->mtu - 10);
2111

2112
			chan->remote_mps = le16_to_cpu(rfc.max_pdu_size);
2113

2114
			chan->conf_state |= L2CAP_CONF_MODE_DONE;
2115 2116 2117 2118

			l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC,
					sizeof(rfc), (unsigned long) &rfc);

2119 2120 2121
			break;

		default:
2122 2123
			result = L2CAP_CONF_UNACCEPT;

2124
			memset(&rfc, 0, sizeof(rfc));
2125
			rfc.mode = chan->mode;
2126
		}
2127

2128
		if (result == L2CAP_CONF_SUCCESS)
2129
			chan->conf_state |= L2CAP_CONF_OUTPUT_DONE;
2130
	}
2131
	rsp->scid   = cpu_to_le16(chan->dcid);
2132 2133 2134 2135
	rsp->result = cpu_to_le16(result);
	rsp->flags  = cpu_to_le16(0x0000);

	return ptr - data;
L
Linus Torvalds 已提交
2136 2137
}

2138
static int l2cap_parse_conf_rsp(struct l2cap_chan *chan, void *rsp, int len, void *data, u16 *result)
2139 2140 2141 2142 2143 2144 2145
{
	struct l2cap_conf_req *req = data;
	void *ptr = req->data;
	int type, olen;
	unsigned long val;
	struct l2cap_conf_rfc rfc;

2146
	BT_DBG("chan %p, rsp %p, len %d, req %p", chan, rsp, len, data);
2147 2148 2149 2150 2151 2152 2153 2154

	while (len >= L2CAP_CONF_OPT_SIZE) {
		len -= l2cap_get_conf_opt(&rsp, &type, &olen, &val);

		switch (type) {
		case L2CAP_CONF_MTU:
			if (val < L2CAP_DEFAULT_MIN_MTU) {
				*result = L2CAP_CONF_UNACCEPT;
2155
				chan->imtu = L2CAP_DEFAULT_MIN_MTU;
2156
			} else
2157 2158
				chan->imtu = val;
			l2cap_add_conf_opt(&ptr, L2CAP_CONF_MTU, 2, chan->imtu);
2159 2160 2161
			break;

		case L2CAP_CONF_FLUSH_TO:
2162
			chan->flush_to = val;
2163
			l2cap_add_conf_opt(&ptr, L2CAP_CONF_FLUSH_TO,
2164
							2, chan->flush_to);
2165 2166 2167 2168 2169 2170
			break;

		case L2CAP_CONF_RFC:
			if (olen == sizeof(rfc))
				memcpy(&rfc, (void *)val, olen);

2171
			if ((chan->conf_state & L2CAP_CONF_STATE2_DEVICE) &&
2172
							rfc.mode != chan->mode)
2173 2174
				return -ECONNREFUSED;

2175
			chan->fcs = 0;
2176 2177 2178 2179 2180 2181 2182

			l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC,
					sizeof(rfc), (unsigned long) &rfc);
			break;
		}
	}

2183
	if (chan->mode == L2CAP_MODE_BASIC && chan->mode != rfc.mode)
2184 2185
		return -ECONNREFUSED;

2186
	chan->mode = rfc.mode;
2187

2188 2189 2190
	if (*result == L2CAP_CONF_SUCCESS) {
		switch (rfc.mode) {
		case L2CAP_MODE_ERTM:
2191 2192 2193
			chan->retrans_timeout = le16_to_cpu(rfc.retrans_timeout);
			chan->monitor_timeout = le16_to_cpu(rfc.monitor_timeout);
			chan->mps    = le16_to_cpu(rfc.max_pdu_size);
2194 2195
			break;
		case L2CAP_MODE_STREAMING:
2196
			chan->mps    = le16_to_cpu(rfc.max_pdu_size);
2197 2198 2199
		}
	}

2200
	req->dcid   = cpu_to_le16(chan->dcid);
2201 2202 2203 2204 2205
	req->flags  = cpu_to_le16(0x0000);

	return ptr - data;
}

2206
static int l2cap_build_conf_rsp(struct l2cap_chan *chan, void *data, u16 result, u16 flags)
L
Linus Torvalds 已提交
2207 2208 2209 2210
{
	struct l2cap_conf_rsp *rsp = data;
	void *ptr = rsp->data;

2211
	BT_DBG("chan %p", chan);
L
Linus Torvalds 已提交
2212

2213
	rsp->scid   = cpu_to_le16(chan->dcid);
2214
	rsp->result = cpu_to_le16(result);
2215
	rsp->flags  = cpu_to_le16(flags);
L
Linus Torvalds 已提交
2216 2217 2218 2219

	return ptr - data;
}

2220
void __l2cap_connect_rsp_defer(struct l2cap_chan *chan)
2221 2222
{
	struct l2cap_conn_rsp rsp;
2223
	struct l2cap_conn *conn = chan->conn;
2224 2225
	u8 buf[128];

2226 2227
	rsp.scid   = cpu_to_le16(chan->dcid);
	rsp.dcid   = cpu_to_le16(chan->scid);
2228 2229 2230 2231 2232
	rsp.result = cpu_to_le16(L2CAP_CR_SUCCESS);
	rsp.status = cpu_to_le16(L2CAP_CS_NO_INFO);
	l2cap_send_cmd(conn, chan->ident,
				L2CAP_CONN_RSP, sizeof(rsp), &rsp);

2233
	if (chan->conf_state & L2CAP_CONF_REQ_SENT)
2234 2235
		return;

2236
	chan->conf_state |= L2CAP_CONF_REQ_SENT;
2237 2238 2239 2240 2241
	l2cap_send_cmd(conn, l2cap_get_ident(conn), L2CAP_CONF_REQ,
			l2cap_build_conf_req(chan, buf), buf);
	chan->num_conf_req++;
}

2242
static void l2cap_conf_rfc_get(struct l2cap_chan *chan, void *rsp, int len)
2243 2244 2245 2246 2247
{
	int type, olen;
	unsigned long val;
	struct l2cap_conf_rfc rfc;

2248
	BT_DBG("chan %p, rsp %p, len %d", chan, rsp, len);
2249

2250
	if ((chan->mode != L2CAP_MODE_ERTM) && (chan->mode != L2CAP_MODE_STREAMING))
2251 2252 2253 2254 2255 2256 2257 2258 2259 2260 2261 2262 2263 2264 2265 2266
		return;

	while (len >= L2CAP_CONF_OPT_SIZE) {
		len -= l2cap_get_conf_opt(&rsp, &type, &olen, &val);

		switch (type) {
		case L2CAP_CONF_RFC:
			if (olen == sizeof(rfc))
				memcpy(&rfc, (void *)val, olen);
			goto done;
		}
	}

done:
	switch (rfc.mode) {
	case L2CAP_MODE_ERTM:
2267 2268 2269
		chan->retrans_timeout = le16_to_cpu(rfc.retrans_timeout);
		chan->monitor_timeout = le16_to_cpu(rfc.monitor_timeout);
		chan->mps    = le16_to_cpu(rfc.max_pdu_size);
2270 2271
		break;
	case L2CAP_MODE_STREAMING:
2272
		chan->mps    = le16_to_cpu(rfc.max_pdu_size);
2273 2274 2275
	}
}

2276 2277 2278 2279 2280 2281 2282 2283 2284 2285
static inline int l2cap_command_rej(struct l2cap_conn *conn, struct l2cap_cmd_hdr *cmd, u8 *data)
{
	struct l2cap_cmd_rej *rej = (struct l2cap_cmd_rej *) data;

	if (rej->reason != 0x0000)
		return 0;

	if ((conn->info_state & L2CAP_INFO_FEAT_MASK_REQ_SENT) &&
					cmd->ident == conn->info_ident) {
		del_timer(&conn->info_timer);
2286 2287

		conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_DONE;
2288
		conn->info_ident = 0;
2289

2290 2291 2292 2293 2294 2295
		l2cap_conn_start(conn);
	}

	return 0;
}

L
Linus Torvalds 已提交
2296 2297 2298 2299
static inline int l2cap_connect_req(struct l2cap_conn *conn, struct l2cap_cmd_hdr *cmd, u8 *data)
{
	struct l2cap_conn_req *req = (struct l2cap_conn_req *) data;
	struct l2cap_conn_rsp rsp;
2300
	struct l2cap_chan *chan = NULL, *pchan;
2301
	struct sock *parent, *sk = NULL;
2302
	int result, status = L2CAP_CS_NO_INFO;
L
Linus Torvalds 已提交
2303 2304

	u16 dcid = 0, scid = __le16_to_cpu(req->scid);
2305
	__le16 psm = req->psm;
L
Linus Torvalds 已提交
2306 2307 2308 2309

	BT_DBG("psm 0x%2.2x scid 0x%4.4x", psm, scid);

	/* Check if we have socket listening on psm */
2310 2311
	pchan = l2cap_global_chan_by_psm(BT_LISTEN, psm, conn->src);
	if (!pchan) {
L
Linus Torvalds 已提交
2312 2313 2314 2315
		result = L2CAP_CR_BAD_PSM;
		goto sendresp;
	}

2316 2317
	parent = pchan->sk;

2318 2319
	bh_lock_sock(parent);

2320 2321 2322
	/* Check if the ACL is secure enough (if not SDP) */
	if (psm != cpu_to_le16(0x0001) &&
				!hci_conn_check_link_mode(conn->hcon)) {
2323
		conn->disc_reason = 0x05;
2324 2325 2326 2327
		result = L2CAP_CR_SEC_BLOCK;
		goto response;
	}

L
Linus Torvalds 已提交
2328 2329 2330 2331
	result = L2CAP_CR_NO_MEM;

	/* Check for backlog size */
	if (sk_acceptq_is_full(parent)) {
2332
		BT_DBG("backlog full %d", parent->sk_ack_backlog);
L
Linus Torvalds 已提交
2333 2334 2335
		goto response;
	}

2336
	sk = l2cap_sock_alloc(sock_net(parent), NULL, BTPROTO_L2CAP, GFP_ATOMIC);
L
Linus Torvalds 已提交
2337 2338 2339
	if (!sk)
		goto response;

2340
	chan = l2cap_chan_create(sk);
2341 2342 2343 2344 2345
	if (!chan) {
		l2cap_sock_kill(sk);
		goto response;
	}

2346 2347
	l2cap_pi(sk)->chan = chan;

2348
	write_lock_bh(&conn->chan_lock);
L
Linus Torvalds 已提交
2349 2350

	/* Check if we already have channel with that dcid */
2351 2352
	if (__l2cap_get_chan_by_dcid(conn, scid)) {
		write_unlock_bh(&conn->chan_lock);
L
Linus Torvalds 已提交
2353 2354 2355 2356 2357 2358 2359 2360 2361 2362
		sock_set_flag(sk, SOCK_ZAPPED);
		l2cap_sock_kill(sk);
		goto response;
	}

	hci_conn_hold(conn->hcon);

	l2cap_sock_init(sk, parent);
	bacpy(&bt_sk(sk)->src, conn->src);
	bacpy(&bt_sk(sk)->dst, conn->dst);
2363 2364
	chan->psm  = psm;
	chan->dcid = scid;
L
Linus Torvalds 已提交
2365

2366 2367
	bt_accept_enqueue(parent, sk);

2368 2369
	__l2cap_chan_add(conn, chan);

2370
	dcid = chan->scid;
L
Linus Torvalds 已提交
2371

2372
	l2cap_chan_set_timer(chan, sk->sk_sndtimeo);
L
Linus Torvalds 已提交
2373

2374
	chan->ident = cmd->ident;
L
Linus Torvalds 已提交
2375

2376
	if (conn->info_state & L2CAP_INFO_FEAT_MASK_REQ_DONE) {
2377
		if (l2cap_check_security(chan)) {
2378 2379 2380 2381 2382 2383 2384 2385 2386 2387
			if (bt_sk(sk)->defer_setup) {
				sk->sk_state = BT_CONNECT2;
				result = L2CAP_CR_PEND;
				status = L2CAP_CS_AUTHOR_PEND;
				parent->sk_data_ready(parent, 0);
			} else {
				sk->sk_state = BT_CONFIG;
				result = L2CAP_CR_SUCCESS;
				status = L2CAP_CS_NO_INFO;
			}
2388 2389 2390 2391 2392 2393 2394 2395 2396
		} else {
			sk->sk_state = BT_CONNECT2;
			result = L2CAP_CR_PEND;
			status = L2CAP_CS_AUTHEN_PEND;
		}
	} else {
		sk->sk_state = BT_CONNECT2;
		result = L2CAP_CR_PEND;
		status = L2CAP_CS_NO_INFO;
L
Linus Torvalds 已提交
2397 2398
	}

2399
	write_unlock_bh(&conn->chan_lock);
L
Linus Torvalds 已提交
2400 2401 2402 2403 2404

response:
	bh_unlock_sock(parent);

sendresp:
2405 2406 2407 2408
	rsp.scid   = cpu_to_le16(scid);
	rsp.dcid   = cpu_to_le16(dcid);
	rsp.result = cpu_to_le16(result);
	rsp.status = cpu_to_le16(status);
L
Linus Torvalds 已提交
2409
	l2cap_send_cmd(conn, cmd->ident, L2CAP_CONN_RSP, sizeof(rsp), &rsp);
2410 2411 2412 2413 2414 2415 2416 2417 2418 2419 2420 2421 2422 2423 2424

	if (result == L2CAP_CR_PEND && status == L2CAP_CS_NO_INFO) {
		struct l2cap_info_req info;
		info.type = cpu_to_le16(L2CAP_IT_FEAT_MASK);

		conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_SENT;
		conn->info_ident = l2cap_get_ident(conn);

		mod_timer(&conn->info_timer, jiffies +
					msecs_to_jiffies(L2CAP_INFO_TIMEOUT));

		l2cap_send_cmd(conn, conn->info_ident,
					L2CAP_INFO_REQ, sizeof(info), &info);
	}

2425
	if (chan && !(chan->conf_state & L2CAP_CONF_REQ_SENT) &&
2426 2427
				result == L2CAP_CR_SUCCESS) {
		u8 buf[128];
2428
		chan->conf_state |= L2CAP_CONF_REQ_SENT;
2429
		l2cap_send_cmd(conn, l2cap_get_ident(conn), L2CAP_CONF_REQ,
2430 2431
					l2cap_build_conf_req(chan, buf), buf);
		chan->num_conf_req++;
2432 2433
	}

L
Linus Torvalds 已提交
2434 2435 2436 2437 2438 2439 2440
	return 0;
}

static inline int l2cap_connect_rsp(struct l2cap_conn *conn, struct l2cap_cmd_hdr *cmd, u8 *data)
{
	struct l2cap_conn_rsp *rsp = (struct l2cap_conn_rsp *) data;
	u16 scid, dcid, result, status;
2441
	struct l2cap_chan *chan;
L
Linus Torvalds 已提交
2442 2443 2444 2445 2446 2447 2448 2449 2450 2451 2452
	struct sock *sk;
	u8 req[128];

	scid   = __le16_to_cpu(rsp->scid);
	dcid   = __le16_to_cpu(rsp->dcid);
	result = __le16_to_cpu(rsp->result);
	status = __le16_to_cpu(rsp->status);

	BT_DBG("dcid 0x%4.4x scid 0x%4.4x result 0x%2.2x status 0x%2.2x", dcid, scid, result, status);

	if (scid) {
2453
		chan = l2cap_get_chan_by_scid(conn, scid);
2454
		if (!chan)
2455
			return -EFAULT;
L
Linus Torvalds 已提交
2456
	} else {
2457
		chan = l2cap_get_chan_by_ident(conn, cmd->ident);
2458
		if (!chan)
2459
			return -EFAULT;
L
Linus Torvalds 已提交
2460 2461
	}

2462 2463
	sk = chan->sk;

L
Linus Torvalds 已提交
2464 2465 2466
	switch (result) {
	case L2CAP_CR_SUCCESS:
		sk->sk_state = BT_CONFIG;
2467
		chan->ident = 0;
2468
		chan->dcid = dcid;
2469
		chan->conf_state &= ~L2CAP_CONF_CONNECT_PEND;
2470

2471
		if (chan->conf_state & L2CAP_CONF_REQ_SENT)
2472 2473
			break;

2474
		chan->conf_state |= L2CAP_CONF_REQ_SENT;
2475

L
Linus Torvalds 已提交
2476
		l2cap_send_cmd(conn, l2cap_get_ident(conn), L2CAP_CONF_REQ,
2477 2478
					l2cap_build_conf_req(chan, req), req);
		chan->num_conf_req++;
L
Linus Torvalds 已提交
2479 2480 2481
		break;

	case L2CAP_CR_PEND:
2482
		chan->conf_state |= L2CAP_CONF_CONNECT_PEND;
L
Linus Torvalds 已提交
2483 2484 2485
		break;

	default:
2486 2487 2488
		/* don't delete l2cap channel if sk is owned by user */
		if (sock_owned_by_user(sk)) {
			sk->sk_state = BT_DISCONN;
2489 2490
			l2cap_chan_clear_timer(chan);
			l2cap_chan_set_timer(chan, HZ / 5);
2491 2492 2493
			break;
		}

2494
		l2cap_chan_del(chan, ECONNREFUSED);
L
Linus Torvalds 已提交
2495 2496 2497 2498 2499 2500 2501
		break;
	}

	bh_unlock_sock(sk);
	return 0;
}

2502
static inline void set_default_fcs(struct l2cap_chan *chan)
2503
{
2504 2505
	struct l2cap_pinfo *pi = l2cap_pi(chan->sk);

2506 2507 2508
	/* FCS is enabled only in ERTM or streaming mode, if one or both
	 * sides request it.
	 */
2509
	if (chan->mode != L2CAP_MODE_ERTM && chan->mode != L2CAP_MODE_STREAMING)
2510
		chan->fcs = L2CAP_FCS_NONE;
2511
	else if (!(pi->chan->conf_state & L2CAP_CONF_NO_FCS_RECV))
2512
		chan->fcs = L2CAP_FCS_CRC16;
2513 2514
}

2515
static inline int l2cap_config_req(struct l2cap_conn *conn, struct l2cap_cmd_hdr *cmd, u16 cmd_len, u8 *data)
L
Linus Torvalds 已提交
2516 2517 2518 2519
{
	struct l2cap_conf_req *req = (struct l2cap_conf_req *) data;
	u16 dcid, flags;
	u8 rsp[64];
2520
	struct l2cap_chan *chan;
L
Linus Torvalds 已提交
2521
	struct sock *sk;
2522
	int len;
L
Linus Torvalds 已提交
2523 2524 2525 2526 2527 2528

	dcid  = __le16_to_cpu(req->dcid);
	flags = __le16_to_cpu(req->flags);

	BT_DBG("dcid 0x%4.4x flags 0x%2.2x", dcid, flags);

2529
	chan = l2cap_get_chan_by_scid(conn, dcid);
2530
	if (!chan)
L
Linus Torvalds 已提交
2531 2532
		return -ENOENT;

2533 2534
	sk = chan->sk;

2535 2536 2537 2538 2539 2540
	if (sk->sk_state != BT_CONFIG) {
		struct l2cap_cmd_rej rej;

		rej.reason = cpu_to_le16(0x0002);
		l2cap_send_cmd(conn, cmd->ident, L2CAP_COMMAND_REJ,
				sizeof(rej), &rej);
2541
		goto unlock;
2542
	}
2543

2544
	/* Reject if config buffer is too small. */
2545
	len = cmd_len - sizeof(*req);
2546
	if (chan->conf_len + len > sizeof(chan->conf_req)) {
2547
		l2cap_send_cmd(conn, cmd->ident, L2CAP_CONF_RSP,
2548
				l2cap_build_conf_rsp(chan, rsp,
2549 2550 2551 2552 2553
					L2CAP_CONF_REJECT, flags), rsp);
		goto unlock;
	}

	/* Store config. */
2554 2555
	memcpy(chan->conf_req + chan->conf_len, req->data, len);
	chan->conf_len += len;
L
Linus Torvalds 已提交
2556 2557 2558 2559

	if (flags & 0x0001) {
		/* Incomplete config. Send empty response. */
		l2cap_send_cmd(conn, cmd->ident, L2CAP_CONF_RSP,
2560
				l2cap_build_conf_rsp(chan, rsp,
2561
					L2CAP_CONF_SUCCESS, 0x0001), rsp);
L
Linus Torvalds 已提交
2562 2563 2564 2565
		goto unlock;
	}

	/* Complete config. */
2566
	len = l2cap_parse_conf_req(chan, rsp);
2567
	if (len < 0) {
2568
		l2cap_send_disconn_req(conn, chan, ECONNRESET);
L
Linus Torvalds 已提交
2569
		goto unlock;
2570
	}
L
Linus Torvalds 已提交
2571

2572
	l2cap_send_cmd(conn, cmd->ident, L2CAP_CONF_RSP, len, rsp);
2573
	chan->num_conf_rsp++;
2574 2575

	/* Reset config buffer. */
2576
	chan->conf_len = 0;
2577

2578
	if (!(chan->conf_state & L2CAP_CONF_OUTPUT_DONE))
2579 2580
		goto unlock;

2581
	if (chan->conf_state & L2CAP_CONF_INPUT_DONE) {
2582
		set_default_fcs(chan);
2583

L
Linus Torvalds 已提交
2584
		sk->sk_state = BT_CONNECTED;
2585

2586 2587
		chan->next_tx_seq = 0;
		chan->expected_tx_seq = 0;
2588
		skb_queue_head_init(&chan->tx_q);
2589
		if (chan->mode == L2CAP_MODE_ERTM)
2590
			l2cap_ertm_init(chan);
2591

L
Linus Torvalds 已提交
2592
		l2cap_chan_ready(sk);
2593 2594 2595
		goto unlock;
	}

2596
	if (!(chan->conf_state & L2CAP_CONF_REQ_SENT)) {
2597
		u8 buf[64];
2598
		chan->conf_state |= L2CAP_CONF_REQ_SENT;
L
Linus Torvalds 已提交
2599
		l2cap_send_cmd(conn, l2cap_get_ident(conn), L2CAP_CONF_REQ,
2600 2601
					l2cap_build_conf_req(chan, buf), buf);
		chan->num_conf_req++;
L
Linus Torvalds 已提交
2602 2603 2604 2605 2606 2607 2608 2609 2610 2611 2612
	}

unlock:
	bh_unlock_sock(sk);
	return 0;
}

static inline int l2cap_config_rsp(struct l2cap_conn *conn, struct l2cap_cmd_hdr *cmd, u8 *data)
{
	struct l2cap_conf_rsp *rsp = (struct l2cap_conf_rsp *)data;
	u16 scid, flags, result;
2613
	struct l2cap_chan *chan;
L
Linus Torvalds 已提交
2614
	struct sock *sk;
2615
	int len = cmd->len - sizeof(*rsp);
L
Linus Torvalds 已提交
2616 2617 2618 2619 2620

	scid   = __le16_to_cpu(rsp->scid);
	flags  = __le16_to_cpu(rsp->flags);
	result = __le16_to_cpu(rsp->result);

2621 2622
	BT_DBG("scid 0x%4.4x flags 0x%2.2x result 0x%2.2x",
			scid, flags, result);
L
Linus Torvalds 已提交
2623

2624
	chan = l2cap_get_chan_by_scid(conn, scid);
2625
	if (!chan)
L
Linus Torvalds 已提交
2626 2627
		return 0;

2628 2629
	sk = chan->sk;

L
Linus Torvalds 已提交
2630 2631
	switch (result) {
	case L2CAP_CONF_SUCCESS:
2632
		l2cap_conf_rfc_get(chan, rsp->data, len);
L
Linus Torvalds 已提交
2633 2634 2635
		break;

	case L2CAP_CONF_UNACCEPT:
2636
		if (chan->num_conf_rsp <= L2CAP_CONF_MAX_CONF_RSP) {
2637 2638
			char req[64];

2639
			if (len > sizeof(req) - sizeof(struct l2cap_conf_req)) {
2640
				l2cap_send_disconn_req(conn, chan, ECONNRESET);
2641 2642 2643
				goto done;
			}

2644 2645
			/* throw out any old stored conf requests */
			result = L2CAP_CONF_SUCCESS;
2646 2647
			len = l2cap_parse_conf_rsp(chan, rsp->data, len,
								req, &result);
2648
			if (len < 0) {
2649
				l2cap_send_disconn_req(conn, chan, ECONNRESET);
2650 2651 2652 2653 2654
				goto done;
			}

			l2cap_send_cmd(conn, l2cap_get_ident(conn),
						L2CAP_CONF_REQ, len, req);
2655
			chan->num_conf_req++;
2656 2657 2658
			if (result != L2CAP_CONF_SUCCESS)
				goto done;
			break;
L
Linus Torvalds 已提交
2659 2660
		}

2661
	default:
2662
		sk->sk_err = ECONNRESET;
2663
		l2cap_chan_set_timer(chan, HZ * 5);
2664
		l2cap_send_disconn_req(conn, chan, ECONNRESET);
L
Linus Torvalds 已提交
2665 2666 2667 2668 2669 2670
		goto done;
	}

	if (flags & 0x01)
		goto done;

2671
	chan->conf_state |= L2CAP_CONF_INPUT_DONE;
L
Linus Torvalds 已提交
2672

2673
	if (chan->conf_state & L2CAP_CONF_OUTPUT_DONE) {
2674
		set_default_fcs(chan);
2675

L
Linus Torvalds 已提交
2676
		sk->sk_state = BT_CONNECTED;
2677 2678
		chan->next_tx_seq = 0;
		chan->expected_tx_seq = 0;
2679
		skb_queue_head_init(&chan->tx_q);
2680
		if (chan->mode ==  L2CAP_MODE_ERTM)
2681
			l2cap_ertm_init(chan);
2682

L
Linus Torvalds 已提交
2683 2684 2685 2686 2687 2688 2689 2690 2691 2692 2693 2694 2695
		l2cap_chan_ready(sk);
	}

done:
	bh_unlock_sock(sk);
	return 0;
}

static inline int l2cap_disconnect_req(struct l2cap_conn *conn, struct l2cap_cmd_hdr *cmd, u8 *data)
{
	struct l2cap_disconn_req *req = (struct l2cap_disconn_req *) data;
	struct l2cap_disconn_rsp rsp;
	u16 dcid, scid;
2696
	struct l2cap_chan *chan;
L
Linus Torvalds 已提交
2697 2698 2699 2700 2701 2702 2703
	struct sock *sk;

	scid = __le16_to_cpu(req->scid);
	dcid = __le16_to_cpu(req->dcid);

	BT_DBG("scid 0x%4.4x dcid 0x%4.4x", scid, dcid);

2704
	chan = l2cap_get_chan_by_scid(conn, dcid);
2705
	if (!chan)
L
Linus Torvalds 已提交
2706 2707
		return 0;

2708 2709
	sk = chan->sk;

2710 2711
	rsp.dcid = cpu_to_le16(chan->scid);
	rsp.scid = cpu_to_le16(chan->dcid);
L
Linus Torvalds 已提交
2712 2713 2714 2715
	l2cap_send_cmd(conn, cmd->ident, L2CAP_DISCONN_RSP, sizeof(rsp), &rsp);

	sk->sk_shutdown = SHUTDOWN_MASK;

2716 2717 2718
	/* don't delete l2cap channel if sk is owned by user */
	if (sock_owned_by_user(sk)) {
		sk->sk_state = BT_DISCONN;
2719 2720
		l2cap_chan_clear_timer(chan);
		l2cap_chan_set_timer(chan, HZ / 5);
2721 2722 2723 2724
		bh_unlock_sock(sk);
		return 0;
	}

2725
	l2cap_chan_del(chan, ECONNRESET);
L
Linus Torvalds 已提交
2726 2727 2728 2729 2730 2731 2732 2733 2734 2735
	bh_unlock_sock(sk);

	l2cap_sock_kill(sk);
	return 0;
}

static inline int l2cap_disconnect_rsp(struct l2cap_conn *conn, struct l2cap_cmd_hdr *cmd, u8 *data)
{
	struct l2cap_disconn_rsp *rsp = (struct l2cap_disconn_rsp *) data;
	u16 dcid, scid;
2736
	struct l2cap_chan *chan;
L
Linus Torvalds 已提交
2737 2738 2739 2740 2741 2742 2743
	struct sock *sk;

	scid = __le16_to_cpu(rsp->scid);
	dcid = __le16_to_cpu(rsp->dcid);

	BT_DBG("dcid 0x%4.4x scid 0x%4.4x", dcid, scid);

2744
	chan = l2cap_get_chan_by_scid(conn, scid);
2745
	if (!chan)
L
Linus Torvalds 已提交
2746 2747
		return 0;

2748 2749
	sk = chan->sk;

2750 2751 2752
	/* don't delete l2cap channel if sk is owned by user */
	if (sock_owned_by_user(sk)) {
		sk->sk_state = BT_DISCONN;
2753 2754
		l2cap_chan_clear_timer(chan);
		l2cap_chan_set_timer(chan, HZ / 5);
2755 2756 2757 2758
		bh_unlock_sock(sk);
		return 0;
	}

2759
	l2cap_chan_del(chan, 0);
L
Linus Torvalds 已提交
2760 2761 2762 2763 2764 2765 2766 2767 2768 2769 2770 2771 2772 2773 2774
	bh_unlock_sock(sk);

	l2cap_sock_kill(sk);
	return 0;
}

static inline int l2cap_information_req(struct l2cap_conn *conn, struct l2cap_cmd_hdr *cmd, u8 *data)
{
	struct l2cap_info_req *req = (struct l2cap_info_req *) data;
	u16 type;

	type = __le16_to_cpu(req->type);

	BT_DBG("type 0x%4.4x", type);

2775 2776
	if (type == L2CAP_IT_FEAT_MASK) {
		u8 buf[8];
2777
		u32 feat_mask = l2cap_feat_mask;
2778 2779 2780
		struct l2cap_info_rsp *rsp = (struct l2cap_info_rsp *) buf;
		rsp->type   = cpu_to_le16(L2CAP_IT_FEAT_MASK);
		rsp->result = cpu_to_le16(L2CAP_IR_SUCCESS);
2781
		if (!disable_ertm)
2782 2783
			feat_mask |= L2CAP_FEAT_ERTM | L2CAP_FEAT_STREAMING
							 | L2CAP_FEAT_FCS;
2784
		put_unaligned_le32(feat_mask, rsp->data);
2785 2786
		l2cap_send_cmd(conn, cmd->ident,
					L2CAP_INFO_RSP, sizeof(buf), buf);
2787 2788 2789 2790 2791 2792 2793 2794
	} else if (type == L2CAP_IT_FIXED_CHAN) {
		u8 buf[12];
		struct l2cap_info_rsp *rsp = (struct l2cap_info_rsp *) buf;
		rsp->type   = cpu_to_le16(L2CAP_IT_FIXED_CHAN);
		rsp->result = cpu_to_le16(L2CAP_IR_SUCCESS);
		memcpy(buf + 4, l2cap_fixed_chan, 8);
		l2cap_send_cmd(conn, cmd->ident,
					L2CAP_INFO_RSP, sizeof(buf), buf);
2795 2796 2797 2798 2799 2800 2801
	} else {
		struct l2cap_info_rsp rsp;
		rsp.type   = cpu_to_le16(type);
		rsp.result = cpu_to_le16(L2CAP_IR_NOTSUPP);
		l2cap_send_cmd(conn, cmd->ident,
					L2CAP_INFO_RSP, sizeof(rsp), &rsp);
	}
L
Linus Torvalds 已提交
2802 2803 2804 2805 2806 2807 2808 2809 2810 2811 2812 2813 2814 2815

	return 0;
}

static inline int l2cap_information_rsp(struct l2cap_conn *conn, struct l2cap_cmd_hdr *cmd, u8 *data)
{
	struct l2cap_info_rsp *rsp = (struct l2cap_info_rsp *) data;
	u16 type, result;

	type   = __le16_to_cpu(rsp->type);
	result = __le16_to_cpu(rsp->result);

	BT_DBG("type 0x%4.4x result 0x%2.2x", type, result);

2816 2817 2818 2819 2820
	/* L2CAP Info req/rsp are unbound to channels, add extra checks */
	if (cmd->ident != conn->info_ident ||
			conn->info_state & L2CAP_INFO_FEAT_MASK_REQ_DONE)
		return 0;

2821 2822
	del_timer(&conn->info_timer);

2823 2824 2825 2826 2827 2828 2829 2830 2831
	if (result != L2CAP_IR_SUCCESS) {
		conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_DONE;
		conn->info_ident = 0;

		l2cap_conn_start(conn);

		return 0;
	}

2832
	if (type == L2CAP_IT_FEAT_MASK) {
2833
		conn->feat_mask = get_unaligned_le32(rsp->data);
2834

2835
		if (conn->feat_mask & L2CAP_FEAT_FIXED_CHAN) {
2836 2837 2838 2839 2840 2841 2842 2843 2844 2845 2846 2847 2848 2849
			struct l2cap_info_req req;
			req.type = cpu_to_le16(L2CAP_IT_FIXED_CHAN);

			conn->info_ident = l2cap_get_ident(conn);

			l2cap_send_cmd(conn, conn->info_ident,
					L2CAP_INFO_REQ, sizeof(req), &req);
		} else {
			conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_DONE;
			conn->info_ident = 0;

			l2cap_conn_start(conn);
		}
	} else if (type == L2CAP_IT_FIXED_CHAN) {
2850
		conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_DONE;
2851
		conn->info_ident = 0;
2852 2853 2854

		l2cap_conn_start(conn);
	}
2855

L
Linus Torvalds 已提交
2856 2857 2858
	return 0;
}

2859
static inline int l2cap_check_conn_param(u16 min, u16 max, u16 latency,
2860 2861 2862 2863 2864 2865 2866 2867 2868 2869 2870 2871 2872 2873 2874 2875 2876 2877 2878 2879 2880 2881 2882 2883 2884 2885 2886
							u16 to_multiplier)
{
	u16 max_latency;

	if (min > max || min < 6 || max > 3200)
		return -EINVAL;

	if (to_multiplier < 10 || to_multiplier > 3200)
		return -EINVAL;

	if (max >= to_multiplier * 8)
		return -EINVAL;

	max_latency = (to_multiplier * 8 / max) - 1;
	if (latency > 499 || latency > max_latency)
		return -EINVAL;

	return 0;
}

static inline int l2cap_conn_param_update_req(struct l2cap_conn *conn,
					struct l2cap_cmd_hdr *cmd, u8 *data)
{
	struct hci_conn *hcon = conn->hcon;
	struct l2cap_conn_param_update_req *req;
	struct l2cap_conn_param_update_rsp rsp;
	u16 min, max, latency, to_multiplier, cmd_len;
2887
	int err;
2888 2889 2890 2891 2892 2893 2894 2895 2896

	if (!(hcon->link_mode & HCI_LM_MASTER))
		return -EINVAL;

	cmd_len = __le16_to_cpu(cmd->len);
	if (cmd_len != sizeof(struct l2cap_conn_param_update_req))
		return -EPROTO;

	req = (struct l2cap_conn_param_update_req *) data;
2897 2898
	min		= __le16_to_cpu(req->min);
	max		= __le16_to_cpu(req->max);
2899 2900 2901 2902 2903 2904 2905
	latency		= __le16_to_cpu(req->latency);
	to_multiplier	= __le16_to_cpu(req->to_multiplier);

	BT_DBG("min 0x%4.4x max 0x%4.4x latency: 0x%4.4x Timeout: 0x%4.4x",
						min, max, latency, to_multiplier);

	memset(&rsp, 0, sizeof(rsp));
2906 2907 2908

	err = l2cap_check_conn_param(min, max, latency, to_multiplier);
	if (err)
2909 2910 2911 2912 2913 2914 2915
		rsp.result = cpu_to_le16(L2CAP_CONN_PARAM_REJECTED);
	else
		rsp.result = cpu_to_le16(L2CAP_CONN_PARAM_ACCEPTED);

	l2cap_send_cmd(conn, cmd->ident, L2CAP_CONN_PARAM_UPDATE_RSP,
							sizeof(rsp), &rsp);

2916 2917 2918
	if (!err)
		hci_le_conn_update(hcon, min, max, latency, to_multiplier);

2919 2920 2921
	return 0;
}

2922 2923 2924 2925 2926 2927 2928 2929 2930 2931 2932 2933 2934 2935 2936 2937 2938 2939 2940 2941 2942 2943 2944 2945 2946 2947 2948 2949 2950 2951 2952 2953 2954 2955 2956 2957 2958 2959 2960 2961 2962 2963 2964 2965 2966 2967 2968 2969 2970 2971 2972 2973 2974 2975 2976 2977 2978 2979 2980 2981 2982 2983 2984 2985 2986 2987
static inline int l2cap_bredr_sig_cmd(struct l2cap_conn *conn,
			struct l2cap_cmd_hdr *cmd, u16 cmd_len, u8 *data)
{
	int err = 0;

	switch (cmd->code) {
	case L2CAP_COMMAND_REJ:
		l2cap_command_rej(conn, cmd, data);
		break;

	case L2CAP_CONN_REQ:
		err = l2cap_connect_req(conn, cmd, data);
		break;

	case L2CAP_CONN_RSP:
		err = l2cap_connect_rsp(conn, cmd, data);
		break;

	case L2CAP_CONF_REQ:
		err = l2cap_config_req(conn, cmd, cmd_len, data);
		break;

	case L2CAP_CONF_RSP:
		err = l2cap_config_rsp(conn, cmd, data);
		break;

	case L2CAP_DISCONN_REQ:
		err = l2cap_disconnect_req(conn, cmd, data);
		break;

	case L2CAP_DISCONN_RSP:
		err = l2cap_disconnect_rsp(conn, cmd, data);
		break;

	case L2CAP_ECHO_REQ:
		l2cap_send_cmd(conn, cmd->ident, L2CAP_ECHO_RSP, cmd_len, data);
		break;

	case L2CAP_ECHO_RSP:
		break;

	case L2CAP_INFO_REQ:
		err = l2cap_information_req(conn, cmd, data);
		break;

	case L2CAP_INFO_RSP:
		err = l2cap_information_rsp(conn, cmd, data);
		break;

	default:
		BT_ERR("Unknown BR/EDR signaling command 0x%2.2x", cmd->code);
		err = -EINVAL;
		break;
	}

	return err;
}

static inline int l2cap_le_sig_cmd(struct l2cap_conn *conn,
					struct l2cap_cmd_hdr *cmd, u8 *data)
{
	switch (cmd->code) {
	case L2CAP_COMMAND_REJ:
		return 0;

	case L2CAP_CONN_PARAM_UPDATE_REQ:
2988
		return l2cap_conn_param_update_req(conn, cmd, data);
2989 2990 2991 2992 2993 2994 2995 2996 2997 2998 2999 3000

	case L2CAP_CONN_PARAM_UPDATE_RSP:
		return 0;

	default:
		BT_ERR("Unknown LE signaling command 0x%2.2x", cmd->code);
		return -EINVAL;
	}
}

static inline void l2cap_sig_channel(struct l2cap_conn *conn,
							struct sk_buff *skb)
L
Linus Torvalds 已提交
3001 3002 3003 3004
{
	u8 *data = skb->data;
	int len = skb->len;
	struct l2cap_cmd_hdr cmd;
3005
	int err;
L
Linus Torvalds 已提交
3006 3007 3008 3009

	l2cap_raw_recv(conn, skb);

	while (len >= L2CAP_CMD_HDR_SIZE) {
3010
		u16 cmd_len;
L
Linus Torvalds 已提交
3011 3012 3013 3014
		memcpy(&cmd, data, L2CAP_CMD_HDR_SIZE);
		data += L2CAP_CMD_HDR_SIZE;
		len  -= L2CAP_CMD_HDR_SIZE;

3015
		cmd_len = le16_to_cpu(cmd.len);
L
Linus Torvalds 已提交
3016

3017
		BT_DBG("code 0x%2.2x len %d id 0x%2.2x", cmd.code, cmd_len, cmd.ident);
L
Linus Torvalds 已提交
3018

3019
		if (cmd_len > len || !cmd.ident) {
L
Linus Torvalds 已提交
3020 3021 3022 3023
			BT_DBG("corrupted command");
			break;
		}

3024 3025 3026 3027
		if (conn->hcon->type == LE_LINK)
			err = l2cap_le_sig_cmd(conn, &cmd, data);
		else
			err = l2cap_bredr_sig_cmd(conn, &cmd, cmd_len, data);
L
Linus Torvalds 已提交
3028 3029 3030

		if (err) {
			struct l2cap_cmd_rej rej;
3031 3032

			BT_ERR("Wrong link type (%d)", err);
L
Linus Torvalds 已提交
3033 3034

			/* FIXME: Map err to a valid reason */
3035
			rej.reason = cpu_to_le16(0);
L
Linus Torvalds 已提交
3036 3037 3038
			l2cap_send_cmd(conn, cmd.ident, L2CAP_COMMAND_REJ, sizeof(rej), &rej);
		}

3039 3040
		data += cmd_len;
		len  -= cmd_len;
L
Linus Torvalds 已提交
3041 3042 3043 3044 3045
	}

	kfree_skb(skb);
}

3046
static int l2cap_check_fcs(struct l2cap_chan *chan,  struct sk_buff *skb)
3047 3048 3049 3050
{
	u16 our_fcs, rcv_fcs;
	int hdr_size = L2CAP_HDR_SIZE + 2;

3051
	if (chan->fcs == L2CAP_FCS_CRC16) {
3052 3053 3054 3055 3056
		skb_trim(skb, skb->len - 2);
		rcv_fcs = get_unaligned_le16(skb->data + skb->len);
		our_fcs = crc16(0, skb->data - hdr_size, skb->len + hdr_size);

		if (our_fcs != rcv_fcs)
3057
			return -EBADMSG;
3058 3059 3060 3061
	}
	return 0;
}

3062
static inline void l2cap_send_i_or_rr_or_rnr(struct l2cap_chan *chan)
3063 3064 3065
{
	u16 control = 0;

3066
	chan->frames_sent = 0;
3067

3068
	control |= chan->buffer_seq << L2CAP_CTRL_REQSEQ_SHIFT;
3069

3070
	if (chan->conn_state & L2CAP_CONN_LOCAL_BUSY) {
3071
		control |= L2CAP_SUPER_RCV_NOT_READY;
3072 3073
		l2cap_send_sframe(chan, control);
		chan->conn_state |= L2CAP_CONN_RNR_SENT;
3074 3075
	}

3076 3077
	if (chan->conn_state & L2CAP_CONN_REMOTE_BUSY)
		l2cap_retransmit_frames(chan);
3078

3079
	l2cap_ertm_send(chan);
3080

3081
	if (!(chan->conn_state & L2CAP_CONN_LOCAL_BUSY) &&
3082
			chan->frames_sent == 0) {
3083
		control |= L2CAP_SUPER_RCV_READY;
3084
		l2cap_send_sframe(chan, control);
3085 3086 3087
	}
}

3088
static int l2cap_add_to_srej_queue(struct l2cap_chan *chan, struct sk_buff *skb, u8 tx_seq, u8 sar)
3089 3090
{
	struct sk_buff *next_skb;
3091
	int tx_seq_offset, next_tx_seq_offset;
3092 3093 3094 3095

	bt_cb(skb)->tx_seq = tx_seq;
	bt_cb(skb)->sar = sar;

3096
	next_skb = skb_peek(&chan->srej_q);
3097
	if (!next_skb) {
3098
		__skb_queue_tail(&chan->srej_q, skb);
3099
		return 0;
3100 3101
	}

3102
	tx_seq_offset = (tx_seq - chan->buffer_seq) % 64;
3103 3104 3105
	if (tx_seq_offset < 0)
		tx_seq_offset += 64;

3106
	do {
3107 3108 3109
		if (bt_cb(next_skb)->tx_seq == tx_seq)
			return -EINVAL;

3110
		next_tx_seq_offset = (bt_cb(next_skb)->tx_seq -
3111
						chan->buffer_seq) % 64;
3112 3113 3114 3115
		if (next_tx_seq_offset < 0)
			next_tx_seq_offset += 64;

		if (next_tx_seq_offset > tx_seq_offset) {
3116
			__skb_queue_before(&chan->srej_q, next_skb, skb);
3117
			return 0;
3118 3119
		}

3120
		if (skb_queue_is_last(&chan->srej_q, next_skb))
3121 3122
			break;

3123
	} while ((next_skb = skb_queue_next(&chan->srej_q, next_skb)));
3124

3125
	__skb_queue_tail(&chan->srej_q, skb);
3126 3127

	return 0;
3128 3129
}

3130
static int l2cap_ertm_reassembly_sdu(struct l2cap_chan *chan, struct sk_buff *skb, u16 control)
3131 3132
{
	struct sk_buff *_skb;
3133
	int err;
3134 3135 3136

	switch (control & L2CAP_CTRL_SAR) {
	case L2CAP_SDU_UNSEGMENTED:
3137
		if (chan->conn_state & L2CAP_CONN_SAR_SDU)
3138 3139
			goto drop;

3140
		return sock_queue_rcv_skb(chan->sk, skb);
3141 3142

	case L2CAP_SDU_START:
3143
		if (chan->conn_state & L2CAP_CONN_SAR_SDU)
3144 3145
			goto drop;

3146
		chan->sdu_len = get_unaligned_le16(skb->data);
3147

3148
		if (chan->sdu_len > chan->imtu)
3149 3150
			goto disconnect;

3151 3152
		chan->sdu = bt_skb_alloc(chan->sdu_len, GFP_ATOMIC);
		if (!chan->sdu)
3153 3154 3155 3156 3157 3158
			return -ENOMEM;

		/* pull sdu_len bytes only after alloc, because of Local Busy
		 * condition we have to be sure that this will be executed
		 * only once, i.e., when alloc does not fail */
		skb_pull(skb, 2);
3159

3160
		memcpy(skb_put(chan->sdu, skb->len), skb->data, skb->len);
3161

3162
		chan->conn_state |= L2CAP_CONN_SAR_SDU;
3163
		chan->partial_sdu_len = skb->len;
3164 3165 3166
		break;

	case L2CAP_SDU_CONTINUE:
3167
		if (!(chan->conn_state & L2CAP_CONN_SAR_SDU))
3168 3169
			goto disconnect;

3170
		if (!chan->sdu)
3171 3172
			goto disconnect;

3173 3174
		chan->partial_sdu_len += skb->len;
		if (chan->partial_sdu_len > chan->sdu_len)
3175 3176
			goto drop;

3177
		memcpy(skb_put(chan->sdu, skb->len), skb->data, skb->len);
3178

3179 3180 3181
		break;

	case L2CAP_SDU_END:
3182
		if (!(chan->conn_state & L2CAP_CONN_SAR_SDU))
3183 3184
			goto disconnect;

3185
		if (!chan->sdu)
3186 3187
			goto disconnect;

3188
		if (!(chan->conn_state & L2CAP_CONN_SAR_RETRY)) {
3189
			chan->partial_sdu_len += skb->len;
3190

3191
			if (chan->partial_sdu_len > chan->imtu)
3192
				goto drop;
3193

3194
			if (chan->partial_sdu_len != chan->sdu_len)
3195
				goto drop;
3196

3197
			memcpy(skb_put(chan->sdu, skb->len), skb->data, skb->len);
3198
		}
3199

3200
		_skb = skb_clone(chan->sdu, GFP_ATOMIC);
3201
		if (!_skb) {
3202
			chan->conn_state |= L2CAP_CONN_SAR_RETRY;
3203 3204 3205
			return -ENOMEM;
		}

3206
		err = sock_queue_rcv_skb(chan->sk, _skb);
3207
		if (err < 0) {
3208
			kfree_skb(_skb);
3209
			chan->conn_state |= L2CAP_CONN_SAR_RETRY;
3210 3211 3212
			return err;
		}

3213 3214
		chan->conn_state &= ~L2CAP_CONN_SAR_RETRY;
		chan->conn_state &= ~L2CAP_CONN_SAR_SDU;
3215

3216
		kfree_skb(chan->sdu);
3217 3218 3219 3220
		break;
	}

	kfree_skb(skb);
3221
	return 0;
3222 3223

drop:
3224 3225
	kfree_skb(chan->sdu);
	chan->sdu = NULL;
3226 3227

disconnect:
3228
	l2cap_send_disconn_req(chan->conn, chan, ECONNRESET);
3229 3230 3231 3232
	kfree_skb(skb);
	return 0;
}

3233
static int l2cap_try_push_rx_skb(struct l2cap_chan *chan)
3234 3235 3236 3237 3238
{
	struct sk_buff *skb;
	u16 control;
	int err;

3239
	while ((skb = skb_dequeue(&chan->busy_q))) {
3240
		control = bt_cb(skb)->sar << L2CAP_CTRL_SAR_SHIFT;
3241
		err = l2cap_ertm_reassembly_sdu(chan, skb, control);
3242
		if (err < 0) {
3243
			skb_queue_head(&chan->busy_q, skb);
3244 3245 3246
			return -EBUSY;
		}

3247
		chan->buffer_seq = (chan->buffer_seq + 1) % 64;
3248 3249
	}

3250
	if (!(chan->conn_state & L2CAP_CONN_RNR_SENT))
3251 3252
		goto done;

3253
	control = chan->buffer_seq << L2CAP_CTRL_REQSEQ_SHIFT;
3254
	control |= L2CAP_SUPER_RCV_READY | L2CAP_CTRL_POLL;
3255
	l2cap_send_sframe(chan, control);
3256
	chan->retry_count = 1;
3257

3258
	del_timer(&chan->retrans_timer);
3259 3260
	__mod_monitor_timer();

3261
	chan->conn_state |= L2CAP_CONN_WAIT_F;
3262 3263

done:
3264 3265
	chan->conn_state &= ~L2CAP_CONN_LOCAL_BUSY;
	chan->conn_state &= ~L2CAP_CONN_RNR_SENT;
3266

3267
	BT_DBG("chan %p, Exit local busy", chan);
3268 3269 3270 3271

	return 0;
}

3272 3273 3274
static void l2cap_busy_work(struct work_struct *work)
{
	DECLARE_WAITQUEUE(wait, current);
3275 3276 3277
	struct l2cap_chan *chan =
		container_of(work, struct l2cap_chan, busy_work);
	struct sock *sk = chan->sk;
3278 3279 3280 3281 3282
	int n_tries = 0, timeo = HZ/5, err;
	struct sk_buff *skb;

	lock_sock(sk);

3283
	add_wait_queue(sk_sleep(sk), &wait);
3284
	while ((skb = skb_peek(&chan->busy_q))) {
3285 3286 3287 3288
		set_current_state(TASK_INTERRUPTIBLE);

		if (n_tries++ > L2CAP_LOCAL_BUSY_TRIES) {
			err = -EBUSY;
3289
			l2cap_send_disconn_req(chan->conn, chan, EBUSY);
3290
			break;
3291 3292 3293 3294 3295 3296 3297
		}

		if (!timeo)
			timeo = HZ/5;

		if (signal_pending(current)) {
			err = sock_intr_errno(timeo);
3298
			break;
3299 3300 3301 3302 3303 3304 3305 3306
		}

		release_sock(sk);
		timeo = schedule_timeout(timeo);
		lock_sock(sk);

		err = sock_error(sk);
		if (err)
3307
			break;
3308

3309
		if (l2cap_try_push_rx_skb(chan) == 0)
3310 3311 3312 3313
			break;
	}

	set_current_state(TASK_RUNNING);
3314
	remove_wait_queue(sk_sleep(sk), &wait);
3315 3316 3317 3318

	release_sock(sk);
}

3319
static int l2cap_push_rx_skb(struct l2cap_chan *chan, struct sk_buff *skb, u16 control)
3320 3321 3322
{
	int sctrl, err;

3323
	if (chan->conn_state & L2CAP_CONN_LOCAL_BUSY) {
3324
		bt_cb(skb)->sar = control >> L2CAP_CTRL_SAR_SHIFT;
3325
		__skb_queue_tail(&chan->busy_q, skb);
3326
		return l2cap_try_push_rx_skb(chan);
3327 3328


3329 3330
	}

3331
	err = l2cap_ertm_reassembly_sdu(chan, skb, control);
3332
	if (err >= 0) {
3333
		chan->buffer_seq = (chan->buffer_seq + 1) % 64;
3334 3335 3336 3337
		return err;
	}

	/* Busy Condition */
3338
	BT_DBG("chan %p, Enter local busy", chan);
3339

3340
	chan->conn_state |= L2CAP_CONN_LOCAL_BUSY;
3341
	bt_cb(skb)->sar = control >> L2CAP_CTRL_SAR_SHIFT;
3342
	__skb_queue_tail(&chan->busy_q, skb);
3343

3344
	sctrl = chan->buffer_seq << L2CAP_CTRL_REQSEQ_SHIFT;
3345
	sctrl |= L2CAP_SUPER_RCV_NOT_READY;
3346
	l2cap_send_sframe(chan, sctrl);
3347

3348
	chan->conn_state |= L2CAP_CONN_RNR_SENT;
3349

3350
	del_timer(&chan->ack_timer);
3351

3352
	queue_work(_busy_wq, &chan->busy_work);
3353 3354 3355 3356

	return err;
}

3357
static int l2cap_streaming_reassembly_sdu(struct l2cap_chan *chan, struct sk_buff *skb, u16 control)
3358 3359 3360 3361
{
	struct sk_buff *_skb;
	int err = -EINVAL;

3362 3363 3364 3365 3366
	/*
	 * TODO: We have to notify the userland if some data is lost with the
	 * Streaming Mode.
	 */

3367 3368
	switch (control & L2CAP_CTRL_SAR) {
	case L2CAP_SDU_UNSEGMENTED:
3369
		if (chan->conn_state & L2CAP_CONN_SAR_SDU) {
3370
			kfree_skb(chan->sdu);
3371 3372 3373
			break;
		}

3374
		err = sock_queue_rcv_skb(chan->sk, skb);
3375 3376 3377 3378 3379 3380
		if (!err)
			return 0;

		break;

	case L2CAP_SDU_START:
3381
		if (chan->conn_state & L2CAP_CONN_SAR_SDU) {
3382
			kfree_skb(chan->sdu);
3383 3384 3385
			break;
		}

3386
		chan->sdu_len = get_unaligned_le16(skb->data);
3387 3388
		skb_pull(skb, 2);

3389
		if (chan->sdu_len > chan->imtu) {
3390 3391 3392 3393
			err = -EMSGSIZE;
			break;
		}

3394 3395
		chan->sdu = bt_skb_alloc(chan->sdu_len, GFP_ATOMIC);
		if (!chan->sdu) {
3396 3397 3398 3399
			err = -ENOMEM;
			break;
		}

3400
		memcpy(skb_put(chan->sdu, skb->len), skb->data, skb->len);
3401

3402
		chan->conn_state |= L2CAP_CONN_SAR_SDU;
3403
		chan->partial_sdu_len = skb->len;
3404 3405 3406 3407
		err = 0;
		break;

	case L2CAP_SDU_CONTINUE:
3408
		if (!(chan->conn_state & L2CAP_CONN_SAR_SDU))
3409 3410
			break;

3411
		memcpy(skb_put(chan->sdu, skb->len), skb->data, skb->len);
3412

3413 3414 3415
		chan->partial_sdu_len += skb->len;
		if (chan->partial_sdu_len > chan->sdu_len)
			kfree_skb(chan->sdu);
3416 3417 3418 3419 3420 3421
		else
			err = 0;

		break;

	case L2CAP_SDU_END:
3422
		if (!(chan->conn_state & L2CAP_CONN_SAR_SDU))
3423 3424
			break;

3425
		memcpy(skb_put(chan->sdu, skb->len), skb->data, skb->len);
3426

3427
		chan->conn_state &= ~L2CAP_CONN_SAR_SDU;
3428
		chan->partial_sdu_len += skb->len;
3429

3430
		if (chan->partial_sdu_len > chan->imtu)
3431 3432
			goto drop;

3433 3434
		if (chan->partial_sdu_len == chan->sdu_len) {
			_skb = skb_clone(chan->sdu, GFP_ATOMIC);
3435
			err = sock_queue_rcv_skb(chan->sk, _skb);
3436 3437 3438 3439 3440
			if (err < 0)
				kfree_skb(_skb);
		}
		err = 0;

3441
drop:
3442
		kfree_skb(chan->sdu);
3443 3444 3445 3446 3447 3448 3449
		break;
	}

	kfree_skb(skb);
	return err;
}

3450
static void l2cap_check_srej_gap(struct l2cap_chan *chan, u8 tx_seq)
3451 3452
{
	struct sk_buff *skb;
3453
	u16 control;
3454

3455
	while ((skb = skb_peek(&chan->srej_q))) {
3456 3457 3458
		if (bt_cb(skb)->tx_seq != tx_seq)
			break;

3459
		skb = skb_dequeue(&chan->srej_q);
3460
		control = bt_cb(skb)->sar << L2CAP_CTRL_SAR_SHIFT;
3461
		l2cap_ertm_reassembly_sdu(chan, skb, control);
3462 3463
		chan->buffer_seq_srej =
			(chan->buffer_seq_srej + 1) % 64;
3464
		tx_seq = (tx_seq + 1) % 64;
3465 3466 3467
	}
}

3468
static void l2cap_resend_srejframe(struct l2cap_chan *chan, u8 tx_seq)
3469 3470 3471 3472
{
	struct srej_list *l, *tmp;
	u16 control;

3473
	list_for_each_entry_safe(l, tmp, &chan->srej_l, list) {
3474 3475 3476 3477 3478 3479 3480
		if (l->tx_seq == tx_seq) {
			list_del(&l->list);
			kfree(l);
			return;
		}
		control = L2CAP_SUPER_SELECT_REJECT;
		control |= l->tx_seq << L2CAP_CTRL_REQSEQ_SHIFT;
3481
		l2cap_send_sframe(chan, control);
3482
		list_del(&l->list);
3483
		list_add_tail(&l->list, &chan->srej_l);
3484 3485 3486
	}
}

3487
static void l2cap_send_srejframe(struct l2cap_chan *chan, u8 tx_seq)
3488 3489 3490 3491
{
	struct srej_list *new;
	u16 control;

3492
	while (tx_seq != chan->expected_tx_seq) {
3493
		control = L2CAP_SUPER_SELECT_REJECT;
3494
		control |= chan->expected_tx_seq << L2CAP_CTRL_REQSEQ_SHIFT;
3495
		l2cap_send_sframe(chan, control);
3496 3497

		new = kzalloc(sizeof(struct srej_list), GFP_ATOMIC);
3498 3499
		new->tx_seq = chan->expected_tx_seq;
		chan->expected_tx_seq = (chan->expected_tx_seq + 1) % 64;
3500
		list_add_tail(&new->list, &chan->srej_l);
3501
	}
3502
	chan->expected_tx_seq = (chan->expected_tx_seq + 1) % 64;
3503 3504
}

3505
static inline int l2cap_data_channel_iframe(struct l2cap_chan *chan, u16 rx_control, struct sk_buff *skb)
3506 3507
{
	u8 tx_seq = __get_txseq(rx_control);
3508
	u8 req_seq = __get_reqseq(rx_control);
3509
	u8 sar = rx_control >> L2CAP_CTRL_SAR_SHIFT;
3510
	int tx_seq_offset, expected_tx_seq_offset;
3511
	int num_to_ack = (chan->tx_win/6) + 1;
3512 3513
	int err = 0;

3514 3515
	BT_DBG("chan %p len %d tx_seq %d rx_control 0x%4.4x", chan, skb->len,
							tx_seq, rx_control);
3516

3517
	if (L2CAP_CTRL_FINAL & rx_control &&
3518
			chan->conn_state & L2CAP_CONN_WAIT_F) {
3519
		del_timer(&chan->monitor_timer);
3520
		if (chan->unacked_frames > 0)
3521
			__mod_retrans_timer();
3522
		chan->conn_state &= ~L2CAP_CONN_WAIT_F;
3523 3524
	}

3525 3526
	chan->expected_ack_seq = req_seq;
	l2cap_drop_acked_frames(chan);
3527

3528
	if (tx_seq == chan->expected_tx_seq)
3529
		goto expected;
3530

3531
	tx_seq_offset = (tx_seq - chan->buffer_seq) % 64;
3532 3533 3534 3535
	if (tx_seq_offset < 0)
		tx_seq_offset += 64;

	/* invalid tx_seq */
3536
	if (tx_seq_offset >= chan->tx_win) {
3537
		l2cap_send_disconn_req(chan->conn, chan, ECONNRESET);
3538 3539 3540
		goto drop;
	}

3541
	if (chan->conn_state == L2CAP_CONN_LOCAL_BUSY)
3542 3543
		goto drop;

3544
	if (chan->conn_state & L2CAP_CONN_SREJ_SENT) {
3545
		struct srej_list *first;
3546

3547
		first = list_first_entry(&chan->srej_l,
3548 3549
				struct srej_list, list);
		if (tx_seq == first->tx_seq) {
3550
			l2cap_add_to_srej_queue(chan, skb, tx_seq, sar);
3551
			l2cap_check_srej_gap(chan, tx_seq);
3552 3553 3554 3555

			list_del(&first->list);
			kfree(first);

3556
			if (list_empty(&chan->srej_l)) {
3557
				chan->buffer_seq = chan->buffer_seq_srej;
3558 3559
				chan->conn_state &= ~L2CAP_CONN_SREJ_SENT;
				l2cap_send_ack(chan);
3560
				BT_DBG("chan %p, Exit SREJ_SENT", chan);
3561 3562 3563
			}
		} else {
			struct srej_list *l;
3564 3565

			/* duplicated tx_seq */
3566
			if (l2cap_add_to_srej_queue(chan, skb, tx_seq, sar) < 0)
3567
				goto drop;
3568

3569
			list_for_each_entry(l, &chan->srej_l, list) {
3570
				if (l->tx_seq == tx_seq) {
3571
					l2cap_resend_srejframe(chan, tx_seq);
3572 3573 3574
					return 0;
				}
			}
3575
			l2cap_send_srejframe(chan, tx_seq);
3576 3577
		}
	} else {
3578
		expected_tx_seq_offset =
3579
			(chan->expected_tx_seq - chan->buffer_seq) % 64;
3580 3581 3582 3583 3584 3585 3586
		if (expected_tx_seq_offset < 0)
			expected_tx_seq_offset += 64;

		/* duplicated tx_seq */
		if (tx_seq_offset < expected_tx_seq_offset)
			goto drop;

3587
		chan->conn_state |= L2CAP_CONN_SREJ_SENT;
3588

3589
		BT_DBG("chan %p, Enter SREJ", chan);
3590

3591
		INIT_LIST_HEAD(&chan->srej_l);
3592
		chan->buffer_seq_srej = chan->buffer_seq;
3593

3594 3595
		__skb_queue_head_init(&chan->srej_q);
		__skb_queue_head_init(&chan->busy_q);
3596
		l2cap_add_to_srej_queue(chan, skb, tx_seq, sar);
3597

3598
		chan->conn_state |= L2CAP_CONN_SEND_PBIT;
3599

3600
		l2cap_send_srejframe(chan, tx_seq);
3601

3602
		del_timer(&chan->ack_timer);
3603
	}
3604 3605
	return 0;

3606
expected:
3607
	chan->expected_tx_seq = (chan->expected_tx_seq + 1) % 64;
3608

3609
	if (chan->conn_state & L2CAP_CONN_SREJ_SENT) {
3610 3611
		bt_cb(skb)->tx_seq = tx_seq;
		bt_cb(skb)->sar = sar;
3612
		__skb_queue_tail(&chan->srej_q, skb);
3613 3614 3615
		return 0;
	}

3616
	err = l2cap_push_rx_skb(chan, skb, rx_control);
3617 3618 3619
	if (err < 0)
		return 0;

3620
	if (rx_control & L2CAP_CTRL_FINAL) {
3621 3622
		if (chan->conn_state & L2CAP_CONN_REJ_ACT)
			chan->conn_state &= ~L2CAP_CONN_REJ_ACT;
3623
		else
3624
			l2cap_retransmit_frames(chan);
3625 3626
	}

3627 3628
	__mod_ack_timer();

3629 3630
	chan->num_acked = (chan->num_acked + 1) % num_to_ack;
	if (chan->num_acked == num_to_ack - 1)
3631
		l2cap_send_ack(chan);
3632

3633
	return 0;
3634 3635 3636 3637

drop:
	kfree_skb(skb);
	return 0;
3638 3639
}

3640
static inline void l2cap_data_channel_rrframe(struct l2cap_chan *chan, u16 rx_control)
3641
{
3642
	BT_DBG("chan %p, req_seq %d ctrl 0x%4.4x", chan, __get_reqseq(rx_control),
3643 3644
						rx_control);

3645 3646
	chan->expected_ack_seq = __get_reqseq(rx_control);
	l2cap_drop_acked_frames(chan);
3647

3648
	if (rx_control & L2CAP_CTRL_POLL) {
3649 3650 3651
		chan->conn_state |= L2CAP_CONN_SEND_FBIT;
		if (chan->conn_state & L2CAP_CONN_SREJ_SENT) {
			if ((chan->conn_state & L2CAP_CONN_REMOTE_BUSY) &&
3652
					(chan->unacked_frames > 0))
3653 3654
				__mod_retrans_timer();

3655 3656
			chan->conn_state &= ~L2CAP_CONN_REMOTE_BUSY;
			l2cap_send_srejtail(chan);
3657
		} else {
3658
			l2cap_send_i_or_rr_or_rnr(chan);
3659
		}
3660

3661
	} else if (rx_control & L2CAP_CTRL_FINAL) {
3662
		chan->conn_state &= ~L2CAP_CONN_REMOTE_BUSY;
3663

3664 3665
		if (chan->conn_state & L2CAP_CONN_REJ_ACT)
			chan->conn_state &= ~L2CAP_CONN_REJ_ACT;
3666
		else
3667
			l2cap_retransmit_frames(chan);
3668

3669
	} else {
3670
		if ((chan->conn_state & L2CAP_CONN_REMOTE_BUSY) &&
3671
				(chan->unacked_frames > 0))
3672
			__mod_retrans_timer();
3673

3674 3675 3676
		chan->conn_state &= ~L2CAP_CONN_REMOTE_BUSY;
		if (chan->conn_state & L2CAP_CONN_SREJ_SENT)
			l2cap_send_ack(chan);
3677
		else
3678
			l2cap_ertm_send(chan);
3679 3680
	}
}
3681

3682
static inline void l2cap_data_channel_rejframe(struct l2cap_chan *chan, u16 rx_control)
3683 3684
{
	u8 tx_seq = __get_reqseq(rx_control);
3685

3686
	BT_DBG("chan %p, req_seq %d ctrl 0x%4.4x", chan, tx_seq, rx_control);
3687

3688
	chan->conn_state &= ~L2CAP_CONN_REMOTE_BUSY;
3689

3690 3691
	chan->expected_ack_seq = tx_seq;
	l2cap_drop_acked_frames(chan);
3692 3693

	if (rx_control & L2CAP_CTRL_FINAL) {
3694 3695
		if (chan->conn_state & L2CAP_CONN_REJ_ACT)
			chan->conn_state &= ~L2CAP_CONN_REJ_ACT;
3696
		else
3697
			l2cap_retransmit_frames(chan);
3698
	} else {
3699
		l2cap_retransmit_frames(chan);
3700

3701 3702
		if (chan->conn_state & L2CAP_CONN_WAIT_F)
			chan->conn_state |= L2CAP_CONN_REJ_ACT;
3703 3704
	}
}
3705
static inline void l2cap_data_channel_srejframe(struct l2cap_chan *chan, u16 rx_control)
3706 3707
{
	u8 tx_seq = __get_reqseq(rx_control);
3708

3709
	BT_DBG("chan %p, req_seq %d ctrl 0x%4.4x", chan, tx_seq, rx_control);
3710

3711
	chan->conn_state &= ~L2CAP_CONN_REMOTE_BUSY;
3712

3713
	if (rx_control & L2CAP_CTRL_POLL) {
3714 3715
		chan->expected_ack_seq = tx_seq;
		l2cap_drop_acked_frames(chan);
3716

3717 3718
		chan->conn_state |= L2CAP_CONN_SEND_FBIT;
		l2cap_retransmit_one_frame(chan, tx_seq);
3719

3720
		l2cap_ertm_send(chan);
3721

3722
		if (chan->conn_state & L2CAP_CONN_WAIT_F) {
3723
			chan->srej_save_reqseq = tx_seq;
3724
			chan->conn_state |= L2CAP_CONN_SREJ_ACT;
3725
		}
3726
	} else if (rx_control & L2CAP_CTRL_FINAL) {
3727
		if ((chan->conn_state & L2CAP_CONN_SREJ_ACT) &&
3728
				chan->srej_save_reqseq == tx_seq)
3729
			chan->conn_state &= ~L2CAP_CONN_SREJ_ACT;
3730
		else
3731
			l2cap_retransmit_one_frame(chan, tx_seq);
3732
	} else {
3733 3734
		l2cap_retransmit_one_frame(chan, tx_seq);
		if (chan->conn_state & L2CAP_CONN_WAIT_F) {
3735
			chan->srej_save_reqseq = tx_seq;
3736
			chan->conn_state |= L2CAP_CONN_SREJ_ACT;
3737
		}
3738 3739 3740
	}
}

3741
static inline void l2cap_data_channel_rnrframe(struct l2cap_chan *chan, u16 rx_control)
3742 3743 3744
{
	u8 tx_seq = __get_reqseq(rx_control);

3745
	BT_DBG("chan %p, req_seq %d ctrl 0x%4.4x", chan, tx_seq, rx_control);
3746

3747
	chan->conn_state |= L2CAP_CONN_REMOTE_BUSY;
3748 3749
	chan->expected_ack_seq = tx_seq;
	l2cap_drop_acked_frames(chan);
3750

3751
	if (rx_control & L2CAP_CTRL_POLL)
3752
		chan->conn_state |= L2CAP_CONN_SEND_FBIT;
3753

3754
	if (!(chan->conn_state & L2CAP_CONN_SREJ_SENT)) {
3755
		del_timer(&chan->retrans_timer);
3756
		if (rx_control & L2CAP_CTRL_POLL)
3757
			l2cap_send_rr_or_rnr(chan, L2CAP_CTRL_FINAL);
3758
		return;
3759
	}
3760 3761

	if (rx_control & L2CAP_CTRL_POLL)
3762
		l2cap_send_srejtail(chan);
3763
	else
3764
		l2cap_send_sframe(chan, L2CAP_SUPER_RCV_READY);
3765 3766
}

3767
static inline int l2cap_data_channel_sframe(struct l2cap_chan *chan, u16 rx_control, struct sk_buff *skb)
3768
{
3769
	BT_DBG("chan %p rx_control 0x%4.4x len %d", chan, rx_control, skb->len);
3770

3771
	if (L2CAP_CTRL_FINAL & rx_control &&
3772
			chan->conn_state & L2CAP_CONN_WAIT_F) {
3773
		del_timer(&chan->monitor_timer);
3774
		if (chan->unacked_frames > 0)
3775
			__mod_retrans_timer();
3776
		chan->conn_state &= ~L2CAP_CONN_WAIT_F;
3777 3778 3779 3780
	}

	switch (rx_control & L2CAP_CTRL_SUPERVISE) {
	case L2CAP_SUPER_RCV_READY:
3781
		l2cap_data_channel_rrframe(chan, rx_control);
3782 3783
		break;

3784
	case L2CAP_SUPER_REJECT:
3785
		l2cap_data_channel_rejframe(chan, rx_control);
3786
		break;
3787

3788
	case L2CAP_SUPER_SELECT_REJECT:
3789
		l2cap_data_channel_srejframe(chan, rx_control);
3790 3791 3792
		break;

	case L2CAP_SUPER_RCV_NOT_READY:
3793
		l2cap_data_channel_rnrframe(chan, rx_control);
3794 3795 3796
		break;
	}

3797
	kfree_skb(skb);
3798 3799 3800
	return 0;
}

3801 3802
static int l2cap_ertm_data_rcv(struct sock *sk, struct sk_buff *skb)
{
3803
	struct l2cap_chan *chan = l2cap_pi(sk)->chan;
3804 3805 3806 3807 3808 3809 3810 3811 3812 3813 3814 3815 3816
	u16 control;
	u8 req_seq;
	int len, next_tx_seq_offset, req_seq_offset;

	control = get_unaligned_le16(skb->data);
	skb_pull(skb, 2);
	len = skb->len;

	/*
	 * We can just drop the corrupted I-frame here.
	 * Receiver will miss it and start proper recovery
	 * procedures and ask retransmission.
	 */
3817
	if (l2cap_check_fcs(chan, skb))
3818 3819 3820 3821 3822
		goto drop;

	if (__is_sar_start(control) && __is_iframe(control))
		len -= 2;

3823
	if (chan->fcs == L2CAP_FCS_CRC16)
3824 3825
		len -= 2;

3826
	if (len > chan->mps) {
3827
		l2cap_send_disconn_req(chan->conn, chan, ECONNRESET);
3828 3829 3830 3831
		goto drop;
	}

	req_seq = __get_reqseq(control);
3832
	req_seq_offset = (req_seq - chan->expected_ack_seq) % 64;
3833 3834 3835 3836
	if (req_seq_offset < 0)
		req_seq_offset += 64;

	next_tx_seq_offset =
3837
		(chan->next_tx_seq - chan->expected_ack_seq) % 64;
3838 3839 3840 3841 3842
	if (next_tx_seq_offset < 0)
		next_tx_seq_offset += 64;

	/* check for invalid req-seq */
	if (req_seq_offset > next_tx_seq_offset) {
3843
		l2cap_send_disconn_req(chan->conn, chan, ECONNRESET);
3844 3845 3846 3847 3848
		goto drop;
	}

	if (__is_iframe(control)) {
		if (len < 0) {
3849
			l2cap_send_disconn_req(chan->conn, chan, ECONNRESET);
3850 3851 3852
			goto drop;
		}

3853
		l2cap_data_channel_iframe(chan, control, skb);
3854 3855 3856
	} else {
		if (len != 0) {
			BT_ERR("%d", len);
3857
			l2cap_send_disconn_req(chan->conn, chan, ECONNRESET);
3858 3859 3860
			goto drop;
		}

3861
		l2cap_data_channel_sframe(chan, control, skb);
3862 3863 3864 3865 3866 3867 3868 3869 3870
	}

	return 0;

drop:
	kfree_skb(skb);
	return 0;
}

L
Linus Torvalds 已提交
3871 3872
static inline int l2cap_data_channel(struct l2cap_conn *conn, u16 cid, struct sk_buff *skb)
{
3873
	struct l2cap_chan *chan;
3874
	struct sock *sk = NULL;
3875
	u16 control;
3876 3877
	u8 tx_seq;
	int len;
L
Linus Torvalds 已提交
3878

3879
	chan = l2cap_get_chan_by_scid(conn, cid);
3880
	if (!chan) {
L
Linus Torvalds 已提交
3881 3882 3883 3884
		BT_DBG("unknown cid 0x%4.4x", cid);
		goto drop;
	}

3885
	sk = chan->sk;
3886

3887
	BT_DBG("chan %p, len %d", chan, skb->len);
L
Linus Torvalds 已提交
3888 3889 3890 3891

	if (sk->sk_state != BT_CONNECTED)
		goto drop;

3892
	switch (chan->mode) {
3893 3894 3895 3896 3897
	case L2CAP_MODE_BASIC:
		/* If socket recv buffers overflows we drop data here
		 * which is *bad* because L2CAP has to be reliable.
		 * But we don't have any other choice. L2CAP doesn't
		 * provide flow control mechanism. */
L
Linus Torvalds 已提交
3898

3899
		if (chan->imtu < skb->len)
3900
			goto drop;
L
Linus Torvalds 已提交
3901

3902 3903 3904 3905 3906
		if (!sock_queue_rcv_skb(sk, skb))
			goto done;
		break;

	case L2CAP_MODE_ERTM:
3907 3908
		if (!sock_owned_by_user(sk)) {
			l2cap_ertm_data_rcv(sk, skb);
3909
		} else {
3910
			if (sk_add_backlog(sk, skb))
3911 3912
				goto drop;
		}
3913

3914
		goto done;
3915

3916 3917 3918 3919 3920
	case L2CAP_MODE_STREAMING:
		control = get_unaligned_le16(skb->data);
		skb_pull(skb, 2);
		len = skb->len;

3921
		if (l2cap_check_fcs(chan, skb))
3922 3923
			goto drop;

3924 3925 3926
		if (__is_sar_start(control))
			len -= 2;

3927
		if (chan->fcs == L2CAP_FCS_CRC16)
3928 3929
			len -= 2;

3930
		if (len > chan->mps || len < 0 || __is_sframe(control))
3931 3932 3933 3934
			goto drop;

		tx_seq = __get_txseq(control);

3935 3936
		if (chan->expected_tx_seq == tx_seq)
			chan->expected_tx_seq = (chan->expected_tx_seq + 1) % 64;
3937
		else
3938
			chan->expected_tx_seq = (tx_seq + 1) % 64;
3939

3940
		l2cap_streaming_reassembly_sdu(chan, skb, control);
3941 3942 3943

		goto done;

3944
	default:
3945
		BT_DBG("chan %p: bad mode 0x%2.2x", chan, chan->mode);
3946 3947
		break;
	}
L
Linus Torvalds 已提交
3948 3949 3950 3951 3952

drop:
	kfree_skb(skb);

done:
3953 3954 3955
	if (sk)
		bh_unlock_sock(sk);

L
Linus Torvalds 已提交
3956 3957 3958
	return 0;
}

3959
static inline int l2cap_conless_channel(struct l2cap_conn *conn, __le16 psm, struct sk_buff *skb)
L
Linus Torvalds 已提交
3960
{
3961
	struct sock *sk = NULL;
3962
	struct l2cap_chan *chan;
L
Linus Torvalds 已提交
3963

3964 3965
	chan = l2cap_global_chan_by_psm(0, psm, conn->src);
	if (!chan)
L
Linus Torvalds 已提交
3966 3967
		goto drop;

3968 3969
	sk = chan->sk;

3970 3971
	bh_lock_sock(sk);

L
Linus Torvalds 已提交
3972 3973 3974 3975 3976
	BT_DBG("sk %p, len %d", sk, skb->len);

	if (sk->sk_state != BT_BOUND && sk->sk_state != BT_CONNECTED)
		goto drop;

3977
	if (l2cap_pi(sk)->chan->imtu < skb->len)
L
Linus Torvalds 已提交
3978 3979 3980 3981 3982 3983 3984 3985 3986
		goto drop;

	if (!sock_queue_rcv_skb(sk, skb))
		goto done;

drop:
	kfree_skb(skb);

done:
3987 3988
	if (sk)
		bh_unlock_sock(sk);
L
Linus Torvalds 已提交
3989 3990 3991
	return 0;
}

3992 3993
static inline int l2cap_att_channel(struct l2cap_conn *conn, __le16 cid, struct sk_buff *skb)
{
3994
	struct sock *sk = NULL;
3995
	struct l2cap_chan *chan;
3996

3997 3998
	chan = l2cap_global_chan_by_scid(0, cid, conn->src);
	if (!chan)
3999 4000
		goto drop;

4001 4002
	sk = chan->sk;

4003 4004 4005 4006 4007 4008 4009
	bh_lock_sock(sk);

	BT_DBG("sk %p, len %d", sk, skb->len);

	if (sk->sk_state != BT_BOUND && sk->sk_state != BT_CONNECTED)
		goto drop;

4010
	if (l2cap_pi(sk)->chan->imtu < skb->len)
4011 4012 4013 4014 4015 4016 4017 4018 4019 4020 4021 4022 4023 4024
		goto drop;

	if (!sock_queue_rcv_skb(sk, skb))
		goto done;

drop:
	kfree_skb(skb);

done:
	if (sk)
		bh_unlock_sock(sk);
	return 0;
}

L
Linus Torvalds 已提交
4025 4026 4027
static void l2cap_recv_frame(struct l2cap_conn *conn, struct sk_buff *skb)
{
	struct l2cap_hdr *lh = (void *) skb->data;
4028 4029
	u16 cid, len;
	__le16 psm;
L
Linus Torvalds 已提交
4030 4031 4032 4033 4034

	skb_pull(skb, L2CAP_HDR_SIZE);
	cid = __le16_to_cpu(lh->cid);
	len = __le16_to_cpu(lh->len);

4035 4036 4037 4038 4039
	if (len != skb->len) {
		kfree_skb(skb);
		return;
	}

L
Linus Torvalds 已提交
4040 4041 4042
	BT_DBG("len %d, cid 0x%4.4x", len, cid);

	switch (cid) {
4043
	case L2CAP_CID_LE_SIGNALING:
4044
	case L2CAP_CID_SIGNALING:
L
Linus Torvalds 已提交
4045 4046 4047
		l2cap_sig_channel(conn, skb);
		break;

4048
	case L2CAP_CID_CONN_LESS:
4049
		psm = get_unaligned_le16(skb->data);
L
Linus Torvalds 已提交
4050 4051 4052 4053
		skb_pull(skb, 2);
		l2cap_conless_channel(conn, psm, skb);
		break;

4054 4055 4056 4057
	case L2CAP_CID_LE_DATA:
		l2cap_att_channel(conn, cid, skb);
		break;

L
Linus Torvalds 已提交
4058 4059 4060 4061 4062 4063 4064 4065 4066 4067 4068
	default:
		l2cap_data_channel(conn, cid, skb);
		break;
	}
}

/* ---- L2CAP interface with lower layer (HCI) ---- */

static int l2cap_connect_ind(struct hci_dev *hdev, bdaddr_t *bdaddr, u8 type)
{
	int exact = 0, lm1 = 0, lm2 = 0;
4069
	struct l2cap_chan *c;
L
Linus Torvalds 已提交
4070 4071

	if (type != ACL_LINK)
4072
		return -EINVAL;
L
Linus Torvalds 已提交
4073 4074 4075 4076

	BT_DBG("hdev %s, bdaddr %s", hdev->name, batostr(bdaddr));

	/* Find listening sockets and check their link_mode */
4077 4078 4079
	read_lock(&chan_list_lock);
	list_for_each_entry(c, &chan_list, global_l) {
		struct sock *sk = c->sk;
4080

L
Linus Torvalds 已提交
4081 4082 4083 4084
		if (sk->sk_state != BT_LISTEN)
			continue;

		if (!bacmp(&bt_sk(sk)->src, &hdev->bdaddr)) {
4085
			lm1 |= HCI_LM_ACCEPT;
4086
			if (c->role_switch)
4087
				lm1 |= HCI_LM_MASTER;
L
Linus Torvalds 已提交
4088
			exact++;
4089 4090
		} else if (!bacmp(&bt_sk(sk)->src, BDADDR_ANY)) {
			lm2 |= HCI_LM_ACCEPT;
4091
			if (c->role_switch)
4092 4093
				lm2 |= HCI_LM_MASTER;
		}
L
Linus Torvalds 已提交
4094
	}
4095
	read_unlock(&chan_list_lock);
L
Linus Torvalds 已提交
4096 4097 4098 4099 4100 4101

	return exact ? lm1 : lm2;
}

static int l2cap_connect_cfm(struct hci_conn *hcon, u8 status)
{
4102 4103
	struct l2cap_conn *conn;

L
Linus Torvalds 已提交
4104 4105
	BT_DBG("hcon %p bdaddr %s status %d", hcon, batostr(&hcon->dst), status);

4106
	if (!(hcon->type == ACL_LINK || hcon->type == LE_LINK))
4107
		return -EINVAL;
L
Linus Torvalds 已提交
4108 4109 4110 4111 4112

	if (!status) {
		conn = l2cap_conn_add(hcon, status);
		if (conn)
			l2cap_conn_ready(conn);
4113
	} else
L
Linus Torvalds 已提交
4114 4115 4116 4117 4118
		l2cap_conn_del(hcon, bt_err(status));

	return 0;
}

4119 4120 4121 4122 4123 4124 4125 4126 4127 4128 4129 4130 4131
static int l2cap_disconn_ind(struct hci_conn *hcon)
{
	struct l2cap_conn *conn = hcon->l2cap_data;

	BT_DBG("hcon %p", hcon);

	if (hcon->type != ACL_LINK || !conn)
		return 0x13;

	return conn->disc_reason;
}

static int l2cap_disconn_cfm(struct hci_conn *hcon, u8 reason)
L
Linus Torvalds 已提交
4132 4133 4134
{
	BT_DBG("hcon %p reason %d", hcon, reason);

4135
	if (!(hcon->type == ACL_LINK || hcon->type == LE_LINK))
4136
		return -EINVAL;
L
Linus Torvalds 已提交
4137 4138

	l2cap_conn_del(hcon, bt_err(reason));
4139

L
Linus Torvalds 已提交
4140 4141 4142
	return 0;
}

4143
static inline void l2cap_check_encryption(struct l2cap_chan *chan, u8 encrypt)
4144
{
4145
	if (chan->chan_type != L2CAP_CHAN_CONN_ORIENTED)
4146 4147
		return;

4148
	if (encrypt == 0x00) {
4149
		if (chan->sec_level == BT_SECURITY_MEDIUM) {
4150 4151
			l2cap_chan_clear_timer(chan);
			l2cap_chan_set_timer(chan, HZ * 5);
4152
		} else if (chan->sec_level == BT_SECURITY_HIGH)
4153
			__l2cap_chan_close(chan, ECONNREFUSED);
4154
	} else {
4155
		if (chan->sec_level == BT_SECURITY_MEDIUM)
4156
			l2cap_chan_clear_timer(chan);
4157 4158 4159
	}
}

4160
static int l2cap_security_cfm(struct hci_conn *hcon, u8 status, u8 encrypt)
L
Linus Torvalds 已提交
4161
{
4162
	struct l2cap_conn *conn = hcon->l2cap_data;
4163
	struct l2cap_chan *chan;
L
Linus Torvalds 已提交
4164

4165
	if (!conn)
L
Linus Torvalds 已提交
4166
		return 0;
4167

L
Linus Torvalds 已提交
4168 4169
	BT_DBG("conn %p", conn);

4170
	read_lock(&conn->chan_lock);
L
Linus Torvalds 已提交
4171

4172
	list_for_each_entry(chan, &conn->chan_l, list) {
4173
		struct sock *sk = chan->sk;
4174

L
Linus Torvalds 已提交
4175 4176
		bh_lock_sock(sk);

4177
		if (chan->conf_state & L2CAP_CONF_CONNECT_PEND) {
4178 4179 4180 4181
			bh_unlock_sock(sk);
			continue;
		}

4182
		if (!status && (sk->sk_state == BT_CONNECTED ||
4183
						sk->sk_state == BT_CONFIG)) {
4184
			l2cap_check_encryption(chan, encrypt);
4185 4186 4187 4188
			bh_unlock_sock(sk);
			continue;
		}

4189 4190 4191
		if (sk->sk_state == BT_CONNECT) {
			if (!status) {
				struct l2cap_conn_req req;
4192 4193
				req.scid = cpu_to_le16(chan->scid);
				req.psm  = chan->psm;
L
Linus Torvalds 已提交
4194

4195
				chan->ident = l2cap_get_ident(conn);
4196
				chan->conf_state |= L2CAP_CONF_CONNECT_PEND;
L
Linus Torvalds 已提交
4197

4198
				l2cap_send_cmd(conn, chan->ident,
4199 4200
					L2CAP_CONN_REQ, sizeof(req), &req);
			} else {
4201 4202
				l2cap_chan_clear_timer(chan);
				l2cap_chan_set_timer(chan, HZ / 10);
4203 4204 4205 4206
			}
		} else if (sk->sk_state == BT_CONNECT2) {
			struct l2cap_conn_rsp rsp;
			__u16 result;
L
Linus Torvalds 已提交
4207

4208 4209 4210 4211 4212
			if (!status) {
				sk->sk_state = BT_CONFIG;
				result = L2CAP_CR_SUCCESS;
			} else {
				sk->sk_state = BT_DISCONN;
4213
				l2cap_chan_set_timer(chan, HZ / 10);
4214 4215 4216
				result = L2CAP_CR_SEC_BLOCK;
			}

4217 4218
			rsp.scid   = cpu_to_le16(chan->dcid);
			rsp.dcid   = cpu_to_le16(chan->scid);
4219
			rsp.result = cpu_to_le16(result);
4220
			rsp.status = cpu_to_le16(L2CAP_CS_NO_INFO);
4221 4222
			l2cap_send_cmd(conn, chan->ident, L2CAP_CONN_RSP,
							sizeof(rsp), &rsp);
4223
		}
L
Linus Torvalds 已提交
4224 4225 4226 4227

		bh_unlock_sock(sk);
	}

4228
	read_unlock(&conn->chan_lock);
4229

L
Linus Torvalds 已提交
4230 4231 4232 4233 4234 4235 4236
	return 0;
}

static int l2cap_recv_acldata(struct hci_conn *hcon, struct sk_buff *skb, u16 flags)
{
	struct l2cap_conn *conn = hcon->l2cap_data;

4237 4238 4239 4240
	if (!conn)
		conn = l2cap_conn_add(hcon, 0);

	if (!conn)
L
Linus Torvalds 已提交
4241 4242 4243 4244
		goto drop;

	BT_DBG("conn %p len %d flags 0x%x", conn, skb->len, flags);

4245
	if (!(flags & ACL_CONT)) {
L
Linus Torvalds 已提交
4246
		struct l2cap_hdr *hdr;
4247
		struct l2cap_chan *chan;
4248
		u16 cid;
L
Linus Torvalds 已提交
4249 4250 4251 4252 4253 4254 4255 4256 4257 4258
		int len;

		if (conn->rx_len) {
			BT_ERR("Unexpected start frame (len %d)", skb->len);
			kfree_skb(conn->rx_skb);
			conn->rx_skb = NULL;
			conn->rx_len = 0;
			l2cap_conn_unreliable(conn, ECOMM);
		}

4259 4260
		/* Start fragment always begin with Basic L2CAP header */
		if (skb->len < L2CAP_HDR_SIZE) {
L
Linus Torvalds 已提交
4261 4262 4263 4264 4265 4266 4267
			BT_ERR("Frame is too short (len %d)", skb->len);
			l2cap_conn_unreliable(conn, ECOMM);
			goto drop;
		}

		hdr = (struct l2cap_hdr *) skb->data;
		len = __le16_to_cpu(hdr->len) + L2CAP_HDR_SIZE;
4268
		cid = __le16_to_cpu(hdr->cid);
L
Linus Torvalds 已提交
4269 4270 4271 4272 4273 4274 4275 4276 4277 4278 4279 4280 4281 4282 4283 4284

		if (len == skb->len) {
			/* Complete frame received */
			l2cap_recv_frame(conn, skb);
			return 0;
		}

		BT_DBG("Start: total len %d, frag len %d", len, skb->len);

		if (skb->len > len) {
			BT_ERR("Frame is too long (len %d, expected len %d)",
				skb->len, len);
			l2cap_conn_unreliable(conn, ECOMM);
			goto drop;
		}

4285
		chan = l2cap_get_chan_by_scid(conn, cid);
4286

4287 4288
		if (chan && chan->sk) {
			struct sock *sk = chan->sk;
4289

4290
			if (chan->imtu < len - L2CAP_HDR_SIZE) {
4291 4292
				BT_ERR("Frame exceeding recv MTU (len %d, "
							"MTU %d)", len,
4293
							chan->imtu);
4294 4295 4296 4297
				bh_unlock_sock(sk);
				l2cap_conn_unreliable(conn, ECOMM);
				goto drop;
			}
4298
			bh_unlock_sock(sk);
4299
		}
4300

L
Linus Torvalds 已提交
4301
		/* Allocate skb for the complete frame (with header) */
4302 4303
		conn->rx_skb = bt_skb_alloc(len, GFP_ATOMIC);
		if (!conn->rx_skb)
L
Linus Torvalds 已提交
4304 4305
			goto drop;

4306
		skb_copy_from_linear_data(skb, skb_put(conn->rx_skb, skb->len),
4307
								skb->len);
L
Linus Torvalds 已提交
4308 4309 4310 4311 4312 4313 4314 4315 4316 4317 4318 4319 4320 4321 4322 4323 4324 4325 4326 4327
		conn->rx_len = len - skb->len;
	} else {
		BT_DBG("Cont: frag len %d (expecting %d)", skb->len, conn->rx_len);

		if (!conn->rx_len) {
			BT_ERR("Unexpected continuation frame (len %d)", skb->len);
			l2cap_conn_unreliable(conn, ECOMM);
			goto drop;
		}

		if (skb->len > conn->rx_len) {
			BT_ERR("Fragment is too long (len %d, expected %d)",
					skb->len, conn->rx_len);
			kfree_skb(conn->rx_skb);
			conn->rx_skb = NULL;
			conn->rx_len = 0;
			l2cap_conn_unreliable(conn, ECOMM);
			goto drop;
		}

4328
		skb_copy_from_linear_data(skb, skb_put(conn->rx_skb, skb->len),
4329
								skb->len);
L
Linus Torvalds 已提交
4330 4331 4332 4333 4334 4335 4336 4337 4338 4339 4340 4341 4342 4343
		conn->rx_len -= skb->len;

		if (!conn->rx_len) {
			/* Complete frame received */
			l2cap_recv_frame(conn, conn->rx_skb);
			conn->rx_skb = NULL;
		}
	}

drop:
	kfree_skb(skb);
	return 0;
}

4344
static int l2cap_debugfs_show(struct seq_file *f, void *p)
L
Linus Torvalds 已提交
4345
{
4346
	struct l2cap_chan *c;
L
Linus Torvalds 已提交
4347

4348
	read_lock_bh(&chan_list_lock);
L
Linus Torvalds 已提交
4349

4350 4351
	list_for_each_entry(c, &chan_list, global_l) {
		struct sock *sk = c->sk;
4352

4353
		seq_printf(f, "%s %s %d %d 0x%4.4x 0x%4.4x %d %d %d %d\n",
4354 4355
					batostr(&bt_sk(sk)->src),
					batostr(&bt_sk(sk)->dst),
4356 4357 4358
					sk->sk_state, __le16_to_cpu(c->psm),
					c->scid, c->dcid, c->imtu, c->omtu,
					c->sec_level, c->mode);
4359
	}
L
Linus Torvalds 已提交
4360

4361
	read_unlock_bh(&chan_list_lock);
L
Linus Torvalds 已提交
4362

4363
	return 0;
L
Linus Torvalds 已提交
4364 4365
}

4366 4367 4368 4369 4370 4371 4372 4373 4374 4375 4376 4377 4378
static int l2cap_debugfs_open(struct inode *inode, struct file *file)
{
	return single_open(file, l2cap_debugfs_show, inode->i_private);
}

static const struct file_operations l2cap_debugfs_fops = {
	.open		= l2cap_debugfs_open,
	.read		= seq_read,
	.llseek		= seq_lseek,
	.release	= single_release,
};

static struct dentry *l2cap_debugfs;
L
Linus Torvalds 已提交
4379 4380 4381 4382 4383 4384 4385

static struct hci_proto l2cap_hci_proto = {
	.name		= "L2CAP",
	.id		= HCI_PROTO_L2CAP,
	.connect_ind	= l2cap_connect_ind,
	.connect_cfm	= l2cap_connect_cfm,
	.disconn_ind	= l2cap_disconn_ind,
4386
	.disconn_cfm	= l2cap_disconn_cfm,
4387
	.security_cfm	= l2cap_security_cfm,
L
Linus Torvalds 已提交
4388 4389 4390
	.recv_acldata	= l2cap_recv_acldata
};

4391
int __init l2cap_init(void)
L
Linus Torvalds 已提交
4392 4393
{
	int err;
4394

4395
	err = l2cap_init_sockets();
L
Linus Torvalds 已提交
4396 4397 4398
	if (err < 0)
		return err;

4399
	_busy_wq = create_singlethread_workqueue("l2cap");
4400
	if (!_busy_wq) {
4401
		err = -ENOMEM;
L
Linus Torvalds 已提交
4402 4403 4404 4405 4406 4407 4408 4409 4410 4411
		goto error;
	}

	err = hci_register_proto(&l2cap_hci_proto);
	if (err < 0) {
		BT_ERR("L2CAP protocol registration failed");
		bt_sock_unregister(BTPROTO_L2CAP);
		goto error;
	}

4412 4413 4414 4415 4416 4417
	if (bt_debugfs) {
		l2cap_debugfs = debugfs_create_file("l2cap", 0444,
					bt_debugfs, NULL, &l2cap_debugfs_fops);
		if (!l2cap_debugfs)
			BT_ERR("Failed to create L2CAP debug file");
	}
L
Linus Torvalds 已提交
4418 4419 4420 4421

	return 0;

error:
4422
	destroy_workqueue(_busy_wq);
4423
	l2cap_cleanup_sockets();
L
Linus Torvalds 已提交
4424 4425 4426
	return err;
}

4427
void l2cap_exit(void)
L
Linus Torvalds 已提交
4428
{
4429
	debugfs_remove(l2cap_debugfs);
L
Linus Torvalds 已提交
4430

4431 4432 4433
	flush_workqueue(_busy_wq);
	destroy_workqueue(_busy_wq);

L
Linus Torvalds 已提交
4434 4435 4436
	if (hci_unregister_proto(&l2cap_hci_proto) < 0)
		BT_ERR("L2CAP protocol unregistration failed");

4437
	l2cap_cleanup_sockets();
L
Linus Torvalds 已提交
4438 4439
}

4440 4441
module_param(disable_ertm, bool, 0644);
MODULE_PARM_DESC(disable_ertm, "Disable enhanced retransmission mode");