l2cap_core.c 98.5 KB
Newer Older
1
/*
L
Linus Torvalds 已提交
2 3
   BlueZ - Bluetooth protocol stack for Linux
   Copyright (C) 2000-2001 Qualcomm Incorporated
4
   Copyright (C) 2009-2010 Gustavo F. Padovan <gustavo@padovan.org>
5
   Copyright (C) 2010 Google Inc.
L
Linus Torvalds 已提交
6 7 8 9 10 11 12 13 14 15 16

   Written 2000,2001 by Maxim Krasnyansky <maxk@qualcomm.com>

   This program is free software; you can redistribute it and/or modify
   it under the terms of the GNU General Public License version 2 as
   published by the Free Software Foundation;

   THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS
   OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
   FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT OF THIRD PARTY RIGHTS.
   IN NO EVENT SHALL THE COPYRIGHT HOLDER(S) AND AUTHOR(S) BE LIABLE FOR ANY
17 18 19
   CLAIM, OR ANY SPECIAL INDIRECT OR CONSEQUENTIAL DAMAGES, OR ANY DAMAGES
   WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
   ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
L
Linus Torvalds 已提交
20 21
   OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.

22 23
   ALL LIABILITY, INCLUDING LIABILITY FOR INFRINGEMENT OF ANY PATENTS,
   COPYRIGHTS, TRADEMARKS OR OTHER RIGHTS, RELATING TO USE OF THIS
L
Linus Torvalds 已提交
24 25 26
   SOFTWARE IS DISCLAIMED.
*/

27
/* Bluetooth L2CAP core. */
L
Linus Torvalds 已提交
28 29 30 31

#include <linux/module.h>

#include <linux/types.h>
32
#include <linux/capability.h>
L
Linus Torvalds 已提交
33 34 35 36 37 38 39 40 41 42 43
#include <linux/errno.h>
#include <linux/kernel.h>
#include <linux/sched.h>
#include <linux/slab.h>
#include <linux/poll.h>
#include <linux/fcntl.h>
#include <linux/init.h>
#include <linux/interrupt.h>
#include <linux/socket.h>
#include <linux/skbuff.h>
#include <linux/list.h>
44
#include <linux/device.h>
45 46
#include <linux/debugfs.h>
#include <linux/seq_file.h>
47
#include <linux/uaccess.h>
48
#include <linux/crc16.h>
L
Linus Torvalds 已提交
49 50 51 52 53 54 55 56 57
#include <net/sock.h>

#include <asm/system.h>
#include <asm/unaligned.h>

#include <net/bluetooth/bluetooth.h>
#include <net/bluetooth/hci_core.h>
#include <net/bluetooth/l2cap.h>

58
int disable_ertm;
59

60
static u32 l2cap_feat_mask = L2CAP_FEAT_FIXED_CHAN;
61
static u8 l2cap_fixed_chan[8] = { 0x02, };
L
Linus Torvalds 已提交
62

63 64
static struct workqueue_struct *_busy_wq;

65 66
static LIST_HEAD(chan_list);
static DEFINE_RWLOCK(chan_list_lock);
L
Linus Torvalds 已提交
67

68 69
static void l2cap_busy_work(struct work_struct *work);

L
Linus Torvalds 已提交
70 71
static struct sk_buff *l2cap_build_cmd(struct l2cap_conn *conn,
				u8 code, u8 ident, u16 dlen, void *data);
72 73
static void l2cap_send_cmd(struct l2cap_conn *conn, u8 ident, u8 code, u16 len,
								void *data);
74
static int l2cap_build_conf_req(struct l2cap_chan *chan, void *data);
75 76
static void l2cap_send_disconn_req(struct l2cap_conn *conn,
				struct l2cap_chan *chan, int err);
L
Linus Torvalds 已提交
77

78 79
static int l2cap_ertm_data_rcv(struct sock *sk, struct sk_buff *skb);

80
/* ---- L2CAP channels ---- */
81
static struct l2cap_chan *__l2cap_get_chan_by_dcid(struct l2cap_conn *conn, u16 cid)
82
{
83
	struct l2cap_chan *c;
84 85

	list_for_each_entry(c, &conn->chan_l, list) {
86
		if (c->dcid == cid)
87
			return c;
88
	}
89 90
	return NULL;

91 92
}

93
static struct l2cap_chan *__l2cap_get_chan_by_scid(struct l2cap_conn *conn, u16 cid)
94
{
95
	struct l2cap_chan *c;
96 97

	list_for_each_entry(c, &conn->chan_l, list) {
98
		if (c->scid == cid)
99
			return c;
100
	}
101
	return NULL;
102 103 104 105
}

/* Find channel with given SCID.
 * Returns locked socket */
106
static struct l2cap_chan *l2cap_get_chan_by_scid(struct l2cap_conn *conn, u16 cid)
107
{
108
	struct l2cap_chan *c;
109 110 111

	read_lock(&conn->chan_lock);
	c = __l2cap_get_chan_by_scid(conn, cid);
112 113
	if (c)
		bh_lock_sock(c->sk);
114
	read_unlock(&conn->chan_lock);
115
	return c;
116 117
}

118
static struct l2cap_chan *__l2cap_get_chan_by_ident(struct l2cap_conn *conn, u8 ident)
119
{
120
	struct l2cap_chan *c;
121 122

	list_for_each_entry(c, &conn->chan_l, list) {
123
		if (c->ident == ident)
124
			return c;
125
	}
126
	return NULL;
127 128
}

129
static inline struct l2cap_chan *l2cap_get_chan_by_ident(struct l2cap_conn *conn, u8 ident)
130
{
131
	struct l2cap_chan *c;
132 133 134

	read_lock(&conn->chan_lock);
	c = __l2cap_get_chan_by_ident(conn, ident);
135 136
	if (c)
		bh_lock_sock(c->sk);
137
	read_unlock(&conn->chan_lock);
138
	return c;
139 140
}

141
static struct l2cap_chan *__l2cap_global_chan_by_addr(__le16 psm, bdaddr_t *src)
142
{
143
	struct l2cap_chan *c;
144

145 146
	list_for_each_entry(c, &chan_list, global_l) {
		if (c->sport == psm && !bacmp(&bt_sk(c->sk)->src, src))
147 148 149
			goto found;
	}

150
	c = NULL;
151
found:
152
	return c;
153 154 155 156
}

int l2cap_add_psm(struct l2cap_chan *chan, bdaddr_t *src, __le16 psm)
{
157 158
	int err;

159
	write_lock_bh(&chan_list_lock);
160

161
	if (psm && __l2cap_global_chan_by_addr(psm, src)) {
162 163
		err = -EADDRINUSE;
		goto done;
164 165
	}

166 167 168 169 170 171 172 173 174
	if (psm) {
		chan->psm = psm;
		chan->sport = psm;
		err = 0;
	} else {
		u16 p;

		err = -EINVAL;
		for (p = 0x1001; p < 0x1100; p += 2)
175
			if (!__l2cap_global_chan_by_addr(cpu_to_le16(p), src)) {
176 177 178 179 180 181
				chan->psm   = cpu_to_le16(p);
				chan->sport = cpu_to_le16(p);
				err = 0;
				break;
			}
	}
182

183
done:
184
	write_unlock_bh(&chan_list_lock);
185
	return err;
186 187 188 189
}

int l2cap_add_scid(struct l2cap_chan *chan,  __u16 scid)
{
190
	write_lock_bh(&chan_list_lock);
191 192 193

	chan->scid = scid;

194
	write_unlock_bh(&chan_list_lock);
195 196 197 198

	return 0;
}

199
static u16 l2cap_alloc_cid(struct l2cap_conn *conn)
200
{
201
	u16 cid = L2CAP_CID_DYN_START;
202

203
	for (; cid < L2CAP_CID_DYN_END; cid++) {
204
		if (!__l2cap_get_chan_by_scid(conn, cid))
205 206 207 208 209 210
			return cid;
	}

	return 0;
}

211 212 213 214 215 216 217 218
static void l2cap_chan_set_timer(struct l2cap_chan *chan, long timeout)
{
       BT_DBG("chan %p state %d timeout %ld", chan->sk, chan->sk->sk_state,
								 timeout);
       if (!mod_timer(&chan->chan_timer, jiffies + timeout))
	       sock_hold(chan->sk);
}

219
static void l2cap_chan_clear_timer(struct l2cap_chan *chan)
220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 252
{
       BT_DBG("chan %p state %d", chan, chan->sk->sk_state);

       if (timer_pending(&chan->chan_timer) && del_timer(&chan->chan_timer))
	       __sock_put(chan->sk);
}

static void l2cap_chan_timeout(unsigned long arg)
{
	struct l2cap_chan *chan = (struct l2cap_chan *) arg;
	struct sock *sk = chan->sk;
	int reason;

	BT_DBG("chan %p state %d", chan, sk->sk_state);

	bh_lock_sock(sk);

	if (sock_owned_by_user(sk)) {
		/* sk is owned by user. Try again later */
		l2cap_chan_set_timer(chan, HZ / 5);
		bh_unlock_sock(sk);
		sock_put(sk);
		return;
	}

	if (sk->sk_state == BT_CONNECTED || sk->sk_state == BT_CONFIG)
		reason = ECONNREFUSED;
	else if (sk->sk_state == BT_CONNECT &&
					chan->sec_level != BT_SECURITY_SDP)
		reason = ECONNREFUSED;
	else
		reason = ETIMEDOUT;

253
	l2cap_chan_close(chan, reason);
254 255 256

	bh_unlock_sock(sk);

257
	chan->ops->close(chan->data);
258 259 260
	sock_put(sk);
}

261
struct l2cap_chan *l2cap_chan_create(struct sock *sk)
262 263 264 265 266 267 268 269 270
{
	struct l2cap_chan *chan;

	chan = kzalloc(sizeof(*chan), GFP_ATOMIC);
	if (!chan)
		return NULL;

	chan->sk = sk;

271 272 273 274
	write_lock_bh(&chan_list_lock);
	list_add(&chan->global_l, &chan_list);
	write_unlock_bh(&chan_list_lock);

275 276
	setup_timer(&chan->chan_timer, l2cap_chan_timeout, (unsigned long) chan);

277 278 279
	return chan;
}

280
void l2cap_chan_destroy(struct l2cap_chan *chan)
281
{
282 283 284 285
	write_lock_bh(&chan_list_lock);
	list_del(&chan->global_l);
	write_unlock_bh(&chan_list_lock);

286 287 288
	kfree(chan);
}

289
static void __l2cap_chan_add(struct l2cap_conn *conn, struct l2cap_chan *chan)
290
{
291
	struct sock *sk = chan->sk;
292

293
	BT_DBG("conn %p, psm 0x%2.2x, dcid 0x%4.4x", conn,
294
			chan->psm, chan->dcid);
295

296 297
	conn->disc_reason = 0x13;

298
	chan->conn = conn;
299

300
	if (chan->chan_type == L2CAP_CHAN_CONN_ORIENTED) {
301 302
		if (conn->hcon->type == LE_LINK) {
			/* LE connection */
303
			chan->omtu = L2CAP_LE_DEFAULT_MTU;
304 305
			chan->scid = L2CAP_CID_LE_DATA;
			chan->dcid = L2CAP_CID_LE_DATA;
306 307
		} else {
			/* Alloc CID for connection-oriented socket */
308
			chan->scid = l2cap_alloc_cid(conn);
309
			chan->omtu = L2CAP_DEFAULT_MTU;
310
		}
311
	} else if (chan->chan_type == L2CAP_CHAN_CONN_LESS) {
312
		/* Connectionless socket */
313 314
		chan->scid = L2CAP_CID_CONN_LESS;
		chan->dcid = L2CAP_CID_CONN_LESS;
315
		chan->omtu = L2CAP_DEFAULT_MTU;
316 317
	} else {
		/* Raw socket can send/recv signalling messages only */
318 319
		chan->scid = L2CAP_CID_SIGNALING;
		chan->dcid = L2CAP_CID_SIGNALING;
320
		chan->omtu = L2CAP_DEFAULT_MTU;
321 322
	}

323 324 325
	sock_hold(sk);

	list_add(&chan->list, &conn->chan_l);
326 327
}

328
/* Delete channel.
329
 * Must be called on the locked socket. */
330
static void l2cap_chan_del(struct l2cap_chan *chan, int err)
331
{
332
	struct sock *sk = chan->sk;
333
	struct l2cap_conn *conn = chan->conn;
334 335
	struct sock *parent = bt_sk(sk)->parent;

336
	l2cap_chan_clear_timer(chan);
337

338
	BT_DBG("chan %p, conn %p, err %d", chan, conn, err);
339

340
	if (conn) {
341 342 343 344 345 346
		/* Delete from channel list */
		write_lock_bh(&conn->chan_lock);
		list_del(&chan->list);
		write_unlock_bh(&conn->chan_lock);
		__sock_put(sk);

347
		chan->conn = NULL;
348 349 350
		hci_conn_put(conn->hcon);
	}

351
	sk->sk_state = BT_CLOSED;
352 353 354 355 356 357 358 359 360 361
	sock_set_flag(sk, SOCK_ZAPPED);

	if (err)
		sk->sk_err = err;

	if (parent) {
		bt_accept_unlink(sk);
		parent->sk_data_ready(parent, 0);
	} else
		sk->sk_state_change(sk);
362

363 364
	if (!(chan->conf_state & L2CAP_CONF_OUTPUT_DONE &&
			chan->conf_state & L2CAP_CONF_INPUT_DONE))
365
		return;
366

367
	skb_queue_purge(&chan->tx_q);
368

369
	if (chan->mode == L2CAP_MODE_ERTM) {
370 371
		struct srej_list *l, *tmp;

372 373 374
		del_timer(&chan->retrans_timer);
		del_timer(&chan->monitor_timer);
		del_timer(&chan->ack_timer);
375

376 377
		skb_queue_purge(&chan->srej_q);
		skb_queue_purge(&chan->busy_q);
378

379
		list_for_each_entry_safe(l, tmp, &chan->srej_l, list) {
380 381 382 383
			list_del(&l->list);
			kfree(l);
		}
	}
384 385
}

386 387 388 389 390 391 392
static void l2cap_chan_cleanup_listen(struct sock *parent)
{
	struct sock *sk;

	BT_DBG("parent %p", parent);

	/* Close not yet accepted channels */
393
	while ((sk = bt_accept_dequeue(parent, NULL))) {
394 395
		struct l2cap_chan *chan = l2cap_pi(sk)->chan;
		l2cap_chan_clear_timer(chan);
396
		lock_sock(sk);
397
		l2cap_chan_close(chan, ECONNRESET);
398
		release_sock(sk);
399
		chan->ops->close(chan->data);
400
	}
401 402 403 404 405

	parent->sk_state = BT_CLOSED;
	sock_set_flag(parent, SOCK_ZAPPED);
}

406
void l2cap_chan_close(struct l2cap_chan *chan, int reason)
407 408 409 410 411 412 413 414 415 416 417 418 419
{
	struct l2cap_conn *conn = chan->conn;
	struct sock *sk = chan->sk;

	BT_DBG("chan %p state %d socket %p", chan, sk->sk_state, sk->sk_socket);

	switch (sk->sk_state) {
	case BT_LISTEN:
		l2cap_chan_cleanup_listen(sk);
		break;

	case BT_CONNECTED:
	case BT_CONFIG:
420
		if (chan->chan_type == L2CAP_CHAN_CONN_ORIENTED &&
421
					conn->hcon->type == ACL_LINK) {
422
			l2cap_chan_clear_timer(chan);
423
			l2cap_chan_set_timer(chan, sk->sk_sndtimeo);
424 425 426 427 428 429
			l2cap_send_disconn_req(conn, chan, reason);
		} else
			l2cap_chan_del(chan, reason);
		break;

	case BT_CONNECT2:
430
		if (chan->chan_type == L2CAP_CHAN_CONN_ORIENTED &&
431 432 433 434 435 436 437 438
					conn->hcon->type == ACL_LINK) {
			struct l2cap_conn_rsp rsp;
			__u16 result;

			if (bt_sk(sk)->defer_setup)
				result = L2CAP_CR_SEC_BLOCK;
			else
				result = L2CAP_CR_BAD_PSM;
439
			sk->sk_state = BT_DISCONN;
440 441 442 443 444 445 446 447 448 449 450 451 452 453 454 455 456 457 458 459 460 461 462

			rsp.scid   = cpu_to_le16(chan->dcid);
			rsp.dcid   = cpu_to_le16(chan->scid);
			rsp.result = cpu_to_le16(result);
			rsp.status = cpu_to_le16(L2CAP_CS_NO_INFO);
			l2cap_send_cmd(conn, chan->ident, L2CAP_CONN_RSP,
							sizeof(rsp), &rsp);
		}

		l2cap_chan_del(chan, reason);
		break;

	case BT_CONNECT:
	case BT_DISCONN:
		l2cap_chan_del(chan, reason);
		break;

	default:
		sock_set_flag(sk, SOCK_ZAPPED);
		break;
	}
}

463
static inline u8 l2cap_get_auth_type(struct l2cap_chan *chan)
464
{
465
	if (chan->chan_type == L2CAP_CHAN_RAW) {
466
		switch (chan->sec_level) {
467 468 469 470 471 472 473
		case BT_SECURITY_HIGH:
			return HCI_AT_DEDICATED_BONDING_MITM;
		case BT_SECURITY_MEDIUM:
			return HCI_AT_DEDICATED_BONDING;
		default:
			return HCI_AT_NO_BONDING;
		}
474
	} else if (chan->psm == cpu_to_le16(0x0001)) {
475 476
		if (chan->sec_level == BT_SECURITY_LOW)
			chan->sec_level = BT_SECURITY_SDP;
477

478
		if (chan->sec_level == BT_SECURITY_HIGH)
479
			return HCI_AT_NO_BONDING_MITM;
480
		else
481
			return HCI_AT_NO_BONDING;
482
	} else {
483
		switch (chan->sec_level) {
484
		case BT_SECURITY_HIGH:
485
			return HCI_AT_GENERAL_BONDING_MITM;
486
		case BT_SECURITY_MEDIUM:
487
			return HCI_AT_GENERAL_BONDING;
488
		default:
489
			return HCI_AT_NO_BONDING;
490
		}
491
	}
492 493 494
}

/* Service level security */
495
static inline int l2cap_check_security(struct l2cap_chan *chan)
496
{
497
	struct l2cap_conn *conn = chan->conn;
498 499
	__u8 auth_type;

500
	auth_type = l2cap_get_auth_type(chan);
501

502
	return hci_conn_security(conn->hcon, chan->sec_level, auth_type);
503 504
}

505
static u8 l2cap_get_ident(struct l2cap_conn *conn)
506 507 508 509 510 511 512 513 514 515 516 517 518 519 520 521 522 523 524 525 526
{
	u8 id;

	/* Get next available identificator.
	 *    1 - 128 are used by kernel.
	 *  129 - 199 are reserved.
	 *  200 - 254 are used by utilities like l2ping, etc.
	 */

	spin_lock_bh(&conn->lock);

	if (++conn->tx_ident > 128)
		conn->tx_ident = 1;

	id = conn->tx_ident;

	spin_unlock_bh(&conn->lock);

	return id;
}

527
static void l2cap_send_cmd(struct l2cap_conn *conn, u8 ident, u8 code, u16 len, void *data)
528 529
{
	struct sk_buff *skb = l2cap_build_cmd(conn, code, ident, len, data);
530
	u8 flags;
531 532 533 534

	BT_DBG("code 0x%2.2x", code);

	if (!skb)
535
		return;
536

537 538 539 540 541
	if (lmp_no_flush_capable(conn->hcon->hdev))
		flags = ACL_START_NO_FLUSH;
	else
		flags = ACL_START;

542 543
	bt_cb(skb)->force_active = BT_POWER_FORCE_ACTIVE_ON;

544
	hci_send_acl(conn->hcon, skb, flags);
545 546
}

547
static inline void l2cap_send_sframe(struct l2cap_chan *chan, u16 control)
548 549 550
{
	struct sk_buff *skb;
	struct l2cap_hdr *lh;
551
	struct l2cap_pinfo *pi = l2cap_pi(chan->sk);
552
	struct l2cap_conn *conn = chan->conn;
553
	struct sock *sk = (struct sock *)pi;
554
	int count, hlen = L2CAP_HDR_SIZE + 2;
555
	u8 flags;
556

557 558 559
	if (sk->sk_state != BT_CONNECTED)
		return;

560
	if (chan->fcs == L2CAP_FCS_CRC16)
561
		hlen += 2;
562

563
	BT_DBG("chan %p, control 0x%2.2x", chan, control);
564

565
	count = min_t(unsigned int, conn->mtu, hlen);
566 567
	control |= L2CAP_CTRL_FRAME_TYPE;

568
	if (chan->conn_state & L2CAP_CONN_SEND_FBIT) {
569
		control |= L2CAP_CTRL_FINAL;
570
		chan->conn_state &= ~L2CAP_CONN_SEND_FBIT;
571 572
	}

573
	if (chan->conn_state & L2CAP_CONN_SEND_PBIT) {
574
		control |= L2CAP_CTRL_POLL;
575
		chan->conn_state &= ~L2CAP_CONN_SEND_PBIT;
576 577
	}

578 579
	skb = bt_skb_alloc(count, GFP_ATOMIC);
	if (!skb)
580
		return;
581 582

	lh = (struct l2cap_hdr *) skb_put(skb, L2CAP_HDR_SIZE);
583
	lh->len = cpu_to_le16(hlen - L2CAP_HDR_SIZE);
584
	lh->cid = cpu_to_le16(chan->dcid);
585 586
	put_unaligned_le16(control, skb_put(skb, 2));

587
	if (chan->fcs == L2CAP_FCS_CRC16) {
588 589 590 591
		u16 fcs = crc16(0, (u8 *)lh, count - 2);
		put_unaligned_le16(fcs, skb_put(skb, 2));
	}

592 593 594 595 596
	if (lmp_no_flush_capable(conn->hcon->hdev))
		flags = ACL_START_NO_FLUSH;
	else
		flags = ACL_START;

597 598
	bt_cb(skb)->force_active = chan->force_active;

599
	hci_send_acl(chan->conn->hcon, skb, flags);
600 601
}

602
static inline void l2cap_send_rr_or_rnr(struct l2cap_chan *chan, u16 control)
603
{
604
	if (chan->conn_state & L2CAP_CONN_LOCAL_BUSY) {
605
		control |= L2CAP_SUPER_RCV_NOT_READY;
606
		chan->conn_state |= L2CAP_CONN_RNR_SENT;
607
	} else
608 609
		control |= L2CAP_SUPER_RCV_READY;

610
	control |= chan->buffer_seq << L2CAP_CTRL_REQSEQ_SHIFT;
611

612
	l2cap_send_sframe(chan, control);
613 614
}

615
static inline int __l2cap_no_conn_pending(struct l2cap_chan *chan)
616
{
617
	return !(chan->conf_state & L2CAP_CONF_CONNECT_PEND);
618 619
}

620
static void l2cap_do_start(struct l2cap_chan *chan)
621
{
622
	struct l2cap_conn *conn = chan->conn;
623 624

	if (conn->info_state & L2CAP_INFO_FEAT_MASK_REQ_SENT) {
625 626 627
		if (!(conn->info_state & L2CAP_INFO_FEAT_MASK_REQ_DONE))
			return;

628 629
		if (l2cap_check_security(chan) &&
				__l2cap_no_conn_pending(chan)) {
630
			struct l2cap_conn_req req;
631 632
			req.scid = cpu_to_le16(chan->scid);
			req.psm  = chan->psm;
633

634
			chan->ident = l2cap_get_ident(conn);
635
			chan->conf_state |= L2CAP_CONF_CONNECT_PEND;
636

637 638
			l2cap_send_cmd(conn, chan->ident, L2CAP_CONN_REQ,
							sizeof(req), &req);
639
		}
640 641 642 643 644 645 646 647 648 649 650 651 652 653 654
	} else {
		struct l2cap_info_req req;
		req.type = cpu_to_le16(L2CAP_IT_FEAT_MASK);

		conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_SENT;
		conn->info_ident = l2cap_get_ident(conn);

		mod_timer(&conn->info_timer, jiffies +
					msecs_to_jiffies(L2CAP_INFO_TIMEOUT));

		l2cap_send_cmd(conn, conn->info_ident,
					L2CAP_INFO_REQ, sizeof(req), &req);
	}
}

655 656 657
static inline int l2cap_mode_supported(__u8 mode, __u32 feat_mask)
{
	u32 local_feat_mask = l2cap_feat_mask;
658
	if (!disable_ertm)
659 660 661 662 663 664 665 666 667 668 669 670
		local_feat_mask |= L2CAP_FEAT_ERTM | L2CAP_FEAT_STREAMING;

	switch (mode) {
	case L2CAP_MODE_ERTM:
		return L2CAP_FEAT_ERTM & feat_mask & local_feat_mask;
	case L2CAP_MODE_STREAMING:
		return L2CAP_FEAT_STREAMING & feat_mask & local_feat_mask;
	default:
		return 0x00;
	}
}

671
static void l2cap_send_disconn_req(struct l2cap_conn *conn, struct l2cap_chan *chan, int err)
672
{
673
	struct sock *sk;
674 675
	struct l2cap_disconn_req req;

676 677 678
	if (!conn)
		return;

679 680
	sk = chan->sk;

681
	if (chan->mode == L2CAP_MODE_ERTM) {
682 683 684
		del_timer(&chan->retrans_timer);
		del_timer(&chan->monitor_timer);
		del_timer(&chan->ack_timer);
685 686
	}

687 688
	req.dcid = cpu_to_le16(chan->dcid);
	req.scid = cpu_to_le16(chan->scid);
689 690
	l2cap_send_cmd(conn, l2cap_get_ident(conn),
			L2CAP_DISCONN_REQ, sizeof(req), &req);
691 692

	sk->sk_state = BT_DISCONN;
693
	sk->sk_err = err;
694 695
}

L
Linus Torvalds 已提交
696
/* ---- L2CAP connections ---- */
697 698
static void l2cap_conn_start(struct l2cap_conn *conn)
{
699
	struct l2cap_chan *chan, *tmp;
700 701 702

	BT_DBG("conn %p", conn);

703
	read_lock(&conn->chan_lock);
704

705
	list_for_each_entry_safe(chan, tmp, &conn->chan_l, list) {
706
		struct sock *sk = chan->sk;
707

708 709
		bh_lock_sock(sk);

710
		if (chan->chan_type != L2CAP_CHAN_CONN_ORIENTED) {
711 712 713 714 715
			bh_unlock_sock(sk);
			continue;
		}

		if (sk->sk_state == BT_CONNECT) {
716
			struct l2cap_conn_req req;
717

718
			if (!l2cap_check_security(chan) ||
719
					!__l2cap_no_conn_pending(chan)) {
720 721 722
				bh_unlock_sock(sk);
				continue;
			}
723

724
			if (!l2cap_mode_supported(chan->mode,
725
					conn->feat_mask)
726
					&& chan->conf_state &
727
					L2CAP_CONF_STATE2_DEVICE) {
728
				/* l2cap_chan_close() calls list_del(chan)
729 730
				 * so release the lock */
				read_unlock_bh(&conn->chan_lock);
731
				 l2cap_chan_close(chan, ECONNRESET);
732
				read_lock_bh(&conn->chan_lock);
733 734
				bh_unlock_sock(sk);
				continue;
735
			}
736

737 738
			req.scid = cpu_to_le16(chan->scid);
			req.psm  = chan->psm;
739

740
			chan->ident = l2cap_get_ident(conn);
741
			chan->conf_state |= L2CAP_CONF_CONNECT_PEND;
742

743 744
			l2cap_send_cmd(conn, chan->ident, L2CAP_CONN_REQ,
							sizeof(req), &req);
745

746 747
		} else if (sk->sk_state == BT_CONNECT2) {
			struct l2cap_conn_rsp rsp;
748
			char buf[128];
749 750
			rsp.scid = cpu_to_le16(chan->dcid);
			rsp.dcid = cpu_to_le16(chan->scid);
751

752
			if (l2cap_check_security(chan)) {
753 754 755 756 757 758 759 760 761 762 763
				if (bt_sk(sk)->defer_setup) {
					struct sock *parent = bt_sk(sk)->parent;
					rsp.result = cpu_to_le16(L2CAP_CR_PEND);
					rsp.status = cpu_to_le16(L2CAP_CS_AUTHOR_PEND);
					parent->sk_data_ready(parent, 0);

				} else {
					sk->sk_state = BT_CONFIG;
					rsp.result = cpu_to_le16(L2CAP_CR_SUCCESS);
					rsp.status = cpu_to_le16(L2CAP_CS_NO_INFO);
				}
764 765 766 767 768
			} else {
				rsp.result = cpu_to_le16(L2CAP_CR_PEND);
				rsp.status = cpu_to_le16(L2CAP_CS_AUTHEN_PEND);
			}

769 770
			l2cap_send_cmd(conn, chan->ident, L2CAP_CONN_RSP,
							sizeof(rsp), &rsp);
771

772
			if (chan->conf_state & L2CAP_CONF_REQ_SENT ||
773 774 775 776 777
					rsp.result != L2CAP_CR_SUCCESS) {
				bh_unlock_sock(sk);
				continue;
			}

778
			chan->conf_state |= L2CAP_CONF_REQ_SENT;
779
			l2cap_send_cmd(conn, l2cap_get_ident(conn), L2CAP_CONF_REQ,
780 781
						l2cap_build_conf_req(chan, buf), buf);
			chan->num_conf_req++;
782 783 784 785 786
		}

		bh_unlock_sock(sk);
	}

787
	read_unlock(&conn->chan_lock);
788 789
}

790 791 792
/* Find socket with cid and source bdaddr.
 * Returns closest match, locked.
 */
793
static struct l2cap_chan *l2cap_global_chan_by_scid(int state, __le16 cid, bdaddr_t *src)
794
{
795
	struct l2cap_chan *c, *c1 = NULL;
796

797
	read_lock(&chan_list_lock);
798

799 800
	list_for_each_entry(c, &chan_list, global_l) {
		struct sock *sk = c->sk;
801

802 803 804
		if (state && sk->sk_state != state)
			continue;

805
		if (c->scid == cid) {
806
			/* Exact match. */
807 808 809 810
			if (!bacmp(&bt_sk(sk)->src, src)) {
				read_unlock(&chan_list_lock);
				return c;
			}
811 812 813

			/* Closest match */
			if (!bacmp(&bt_sk(sk)->src, BDADDR_ANY))
814
				c1 = c;
815 816
		}
	}
817

818
	read_unlock(&chan_list_lock);
819

820
	return c1;
821 822 823 824
}

static void l2cap_le_conn_ready(struct l2cap_conn *conn)
{
825
	struct sock *parent, *sk;
826
	struct l2cap_chan *chan, *pchan;
827 828 829 830

	BT_DBG("");

	/* Check if we have socket listening on cid */
831
	pchan = l2cap_global_chan_by_scid(BT_LISTEN, L2CAP_CID_LE_DATA,
832
							conn->src);
833
	if (!pchan)
834 835
		return;

836 837
	parent = pchan->sk;

838 839
	bh_lock_sock(parent);

840 841 842 843 844 845
	/* Check for backlog size */
	if (sk_acceptq_is_full(parent)) {
		BT_DBG("backlog full %d", parent->sk_ack_backlog);
		goto clean;
	}

846 847
	chan = pchan->ops->new_connection(pchan->data);
	if (!chan)
848 849
		goto clean;

850
	sk = chan->sk;
851

852
	write_lock_bh(&conn->chan_lock);
853 854 855 856 857 858

	hci_conn_hold(conn->hcon);

	bacpy(&bt_sk(sk)->src, conn->src);
	bacpy(&bt_sk(sk)->dst, conn->dst);

859 860
	bt_accept_enqueue(parent, sk);

861 862
	__l2cap_chan_add(conn, chan);

863
	l2cap_chan_set_timer(chan, sk->sk_sndtimeo);
864 865 866 867

	sk->sk_state = BT_CONNECTED;
	parent->sk_data_ready(parent, 0);

868
	write_unlock_bh(&conn->chan_lock);
869 870 871 872 873

clean:
	bh_unlock_sock(parent);
}

874 875
static void l2cap_conn_ready(struct l2cap_conn *conn)
{
876
	struct l2cap_chan *chan;
877

878
	BT_DBG("conn %p", conn);
879

880 881 882
	if (!conn->hcon->out && conn->hcon->type == LE_LINK)
		l2cap_le_conn_ready(conn);

883
	read_lock(&conn->chan_lock);
884

885
	list_for_each_entry(chan, &conn->chan_l, list) {
886
		struct sock *sk = chan->sk;
887

888
		bh_lock_sock(sk);
889

890
		if (conn->hcon->type == LE_LINK) {
891
			l2cap_chan_clear_timer(chan);
892 893 894 895
			sk->sk_state = BT_CONNECTED;
			sk->sk_state_change(sk);
		}

896
		if (chan->chan_type != L2CAP_CHAN_CONN_ORIENTED) {
897
			l2cap_chan_clear_timer(chan);
898 899 900
			sk->sk_state = BT_CONNECTED;
			sk->sk_state_change(sk);
		} else if (sk->sk_state == BT_CONNECT)
901
			l2cap_do_start(chan);
902

903
		bh_unlock_sock(sk);
904
	}
905

906
	read_unlock(&conn->chan_lock);
907 908 909 910 911
}

/* Notify sockets that we cannot guaranty reliability anymore */
static void l2cap_conn_unreliable(struct l2cap_conn *conn, int err)
{
912
	struct l2cap_chan *chan;
913 914 915

	BT_DBG("conn %p", conn);

916
	read_lock(&conn->chan_lock);
917

918
	list_for_each_entry(chan, &conn->chan_l, list) {
919
		struct sock *sk = chan->sk;
920

921
		if (chan->force_reliable)
922 923 924
			sk->sk_err = err;
	}

925
	read_unlock(&conn->chan_lock);
926 927 928 929 930 931
}

static void l2cap_info_timeout(unsigned long arg)
{
	struct l2cap_conn *conn = (void *) arg;

932
	conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_DONE;
933
	conn->info_ident = 0;
934

935 936 937
	l2cap_conn_start(conn);
}

L
Linus Torvalds 已提交
938 939
static struct l2cap_conn *l2cap_conn_add(struct hci_conn *hcon, u8 status)
{
940
	struct l2cap_conn *conn = hcon->l2cap_data;
L
Linus Torvalds 已提交
941

942
	if (conn || status)
L
Linus Torvalds 已提交
943 944
		return conn;

945 946
	conn = kzalloc(sizeof(struct l2cap_conn), GFP_ATOMIC);
	if (!conn)
L
Linus Torvalds 已提交
947 948 949 950 951
		return NULL;

	hcon->l2cap_data = conn;
	conn->hcon = hcon;

952 953
	BT_DBG("hcon %p conn %p", hcon, conn);

954 955 956 957 958
	if (hcon->hdev->le_mtu && hcon->type == LE_LINK)
		conn->mtu = hcon->hdev->le_mtu;
	else
		conn->mtu = hcon->hdev->acl_mtu;

L
Linus Torvalds 已提交
959 960 961
	conn->src = &hcon->hdev->bdaddr;
	conn->dst = &hcon->dst;

962 963
	conn->feat_mask = 0;

L
Linus Torvalds 已提交
964
	spin_lock_init(&conn->lock);
965 966 967
	rwlock_init(&conn->chan_lock);

	INIT_LIST_HEAD(&conn->chan_l);
L
Linus Torvalds 已提交
968

969 970
	if (hcon->type != LE_LINK)
		setup_timer(&conn->info_timer, l2cap_info_timeout,
D
Dave Young 已提交
971 972
						(unsigned long) conn);

973 974
	conn->disc_reason = 0x13;

L
Linus Torvalds 已提交
975 976 977
	return conn;
}

978
static void l2cap_conn_del(struct hci_conn *hcon, int err)
L
Linus Torvalds 已提交
979
{
980
	struct l2cap_conn *conn = hcon->l2cap_data;
981
	struct l2cap_chan *chan, *l;
L
Linus Torvalds 已提交
982 983
	struct sock *sk;

984 985
	if (!conn)
		return;
L
Linus Torvalds 已提交
986 987 988

	BT_DBG("hcon %p conn %p, err %d", hcon, conn, err);

989
	kfree_skb(conn->rx_skb);
L
Linus Torvalds 已提交
990 991

	/* Kill channels */
992
	list_for_each_entry_safe(chan, l, &conn->chan_l, list) {
993
		sk = chan->sk;
L
Linus Torvalds 已提交
994
		bh_lock_sock(sk);
995
		l2cap_chan_del(chan, err);
L
Linus Torvalds 已提交
996
		bh_unlock_sock(sk);
997
		chan->ops->close(chan->data);
L
Linus Torvalds 已提交
998 999
	}

1000 1001
	if (conn->info_state & L2CAP_INFO_FEAT_MASK_REQ_SENT)
		del_timer_sync(&conn->info_timer);
1002

L
Linus Torvalds 已提交
1003 1004 1005 1006
	hcon->l2cap_data = NULL;
	kfree(conn);
}

1007
static inline void l2cap_chan_add(struct l2cap_conn *conn, struct l2cap_chan *chan)
L
Linus Torvalds 已提交
1008
{
1009
	write_lock_bh(&conn->chan_lock);
1010
	__l2cap_chan_add(conn, chan);
1011
	write_unlock_bh(&conn->chan_lock);
L
Linus Torvalds 已提交
1012 1013 1014 1015 1016 1017 1018
}

/* ---- Socket interface ---- */

/* Find socket with psm and source bdaddr.
 * Returns closest match.
 */
1019
static struct l2cap_chan *l2cap_global_chan_by_psm(int state, __le16 psm, bdaddr_t *src)
L
Linus Torvalds 已提交
1020
{
1021
	struct l2cap_chan *c, *c1 = NULL;
L
Linus Torvalds 已提交
1022

1023
	read_lock(&chan_list_lock);
1024

1025 1026
	list_for_each_entry(c, &chan_list, global_l) {
		struct sock *sk = c->sk;
1027

L
Linus Torvalds 已提交
1028 1029 1030
		if (state && sk->sk_state != state)
			continue;

1031
		if (c->psm == psm) {
L
Linus Torvalds 已提交
1032
			/* Exact match. */
1033
			if (!bacmp(&bt_sk(sk)->src, src)) {
1034
				read_unlock(&chan_list_lock);
1035 1036
				return c;
			}
L
Linus Torvalds 已提交
1037 1038 1039

			/* Closest match */
			if (!bacmp(&bt_sk(sk)->src, BDADDR_ANY))
1040
				c1 = c;
L
Linus Torvalds 已提交
1041 1042 1043
		}
	}

1044
	read_unlock(&chan_list_lock);
1045

1046
	return c1;
L
Linus Torvalds 已提交
1047 1048
}

1049
int l2cap_chan_connect(struct l2cap_chan *chan)
L
Linus Torvalds 已提交
1050
{
1051
	struct sock *sk = chan->sk;
L
Linus Torvalds 已提交
1052 1053 1054 1055 1056
	bdaddr_t *src = &bt_sk(sk)->src;
	bdaddr_t *dst = &bt_sk(sk)->dst;
	struct l2cap_conn *conn;
	struct hci_conn *hcon;
	struct hci_dev *hdev;
1057
	__u8 auth_type;
1058
	int err;
L
Linus Torvalds 已提交
1059

1060
	BT_DBG("%s -> %s psm 0x%2.2x", batostr(src), batostr(dst),
1061
							chan->psm);
L
Linus Torvalds 已提交
1062

1063 1064
	hdev = hci_get_route(dst, src);
	if (!hdev)
L
Linus Torvalds 已提交
1065 1066 1067 1068
		return -EHOSTUNREACH;

	hci_dev_lock_bh(hdev);

1069
	auth_type = l2cap_get_auth_type(chan);
1070

1071
	if (chan->dcid == L2CAP_CID_LE_DATA)
1072
		hcon = hci_connect(hdev, LE_LINK, dst,
1073
					chan->sec_level, auth_type);
1074 1075
	else
		hcon = hci_connect(hdev, ACL_LINK, dst,
1076
					chan->sec_level, auth_type);
1077

1078 1079
	if (IS_ERR(hcon)) {
		err = PTR_ERR(hcon);
L
Linus Torvalds 已提交
1080
		goto done;
1081
	}
L
Linus Torvalds 已提交
1082 1083 1084 1085

	conn = l2cap_conn_add(hcon, 0);
	if (!conn) {
		hci_conn_put(hcon);
1086
		err = -ENOMEM;
L
Linus Torvalds 已提交
1087 1088 1089 1090 1091 1092
		goto done;
	}

	/* Update source addr of the socket */
	bacpy(src, conn->src);

1093 1094
	l2cap_chan_add(conn, chan);

L
Linus Torvalds 已提交
1095
	sk->sk_state = BT_CONNECT;
1096
	l2cap_chan_set_timer(chan, sk->sk_sndtimeo);
L
Linus Torvalds 已提交
1097 1098

	if (hcon->state == BT_CONNECTED) {
1099
		if (chan->chan_type != L2CAP_CHAN_CONN_ORIENTED) {
1100
			l2cap_chan_clear_timer(chan);
1101
			if (l2cap_check_security(chan))
1102
				sk->sk_state = BT_CONNECTED;
1103
		} else
1104
			l2cap_do_start(chan);
L
Linus Torvalds 已提交
1105 1106
	}

1107 1108
	err = 0;

L
Linus Torvalds 已提交
1109 1110 1111 1112 1113 1114
done:
	hci_dev_unlock_bh(hdev);
	hci_dev_put(hdev);
	return err;
}

1115
int __l2cap_wait_ack(struct sock *sk)
1116
{
1117
	struct l2cap_chan *chan = l2cap_pi(sk)->chan;
1118 1119 1120 1121
	DECLARE_WAITQUEUE(wait, current);
	int err = 0;
	int timeo = HZ/5;

1122
	add_wait_queue(sk_sleep(sk), &wait);
1123
	while ((chan->unacked_frames > 0 && chan->conn)) {
1124 1125 1126 1127 1128 1129 1130 1131 1132 1133 1134 1135 1136 1137 1138 1139 1140 1141 1142
		set_current_state(TASK_INTERRUPTIBLE);

		if (!timeo)
			timeo = HZ/5;

		if (signal_pending(current)) {
			err = sock_intr_errno(timeo);
			break;
		}

		release_sock(sk);
		timeo = schedule_timeout(timeo);
		lock_sock(sk);

		err = sock_error(sk);
		if (err)
			break;
	}
	set_current_state(TASK_RUNNING);
1143
	remove_wait_queue(sk_sleep(sk), &wait);
1144 1145 1146
	return err;
}

1147 1148
static void l2cap_monitor_timeout(unsigned long arg)
{
1149 1150
	struct l2cap_chan *chan = (void *) arg;
	struct sock *sk = chan->sk;
1151

1152
	BT_DBG("chan %p", chan);
1153

1154
	bh_lock_sock(sk);
1155
	if (chan->retry_count >= chan->remote_max_tx) {
1156
		l2cap_send_disconn_req(chan->conn, chan, ECONNABORTED);
1157
		bh_unlock_sock(sk);
1158 1159 1160
		return;
	}

1161
	chan->retry_count++;
1162 1163
	__mod_monitor_timer();

1164
	l2cap_send_rr_or_rnr(chan, L2CAP_CTRL_POLL);
1165
	bh_unlock_sock(sk);
1166 1167 1168 1169
}

static void l2cap_retrans_timeout(unsigned long arg)
{
1170 1171
	struct l2cap_chan *chan = (void *) arg;
	struct sock *sk = chan->sk;
1172

1173
	BT_DBG("chan %p", chan);
1174

1175
	bh_lock_sock(sk);
1176
	chan->retry_count = 1;
1177 1178
	__mod_monitor_timer();

1179
	chan->conn_state |= L2CAP_CONN_WAIT_F;
1180

1181
	l2cap_send_rr_or_rnr(chan, L2CAP_CTRL_POLL);
1182
	bh_unlock_sock(sk);
1183 1184
}

1185
static void l2cap_drop_acked_frames(struct l2cap_chan *chan)
L
Linus Torvalds 已提交
1186
{
1187
	struct sk_buff *skb;
L
Linus Torvalds 已提交
1188

1189
	while ((skb = skb_peek(&chan->tx_q)) &&
1190
			chan->unacked_frames) {
1191
		if (bt_cb(skb)->tx_seq == chan->expected_ack_seq)
1192
			break;
L
Linus Torvalds 已提交
1193

1194
		skb = skb_dequeue(&chan->tx_q);
1195
		kfree_skb(skb);
L
Linus Torvalds 已提交
1196

1197
		chan->unacked_frames--;
1198
	}
L
Linus Torvalds 已提交
1199

1200
	if (!chan->unacked_frames)
1201
		del_timer(&chan->retrans_timer);
1202
}
L
Linus Torvalds 已提交
1203

1204
void l2cap_do_send(struct l2cap_chan *chan, struct sk_buff *skb)
1205
{
1206
	struct hci_conn *hcon = chan->conn->hcon;
1207
	u16 flags;
1208

1209
	BT_DBG("chan %p, skb %p len %d", chan, skb, skb->len);
L
Linus Torvalds 已提交
1210

1211
	if (!chan->flushable && lmp_no_flush_capable(hcon->hdev))
1212 1213 1214 1215
		flags = ACL_START_NO_FLUSH;
	else
		flags = ACL_START;

1216
	bt_cb(skb)->force_active = chan->force_active;
1217
	hci_send_acl(hcon, skb, flags);
1218 1219
}

1220
void l2cap_streaming_send(struct l2cap_chan *chan)
1221
{
1222
	struct sk_buff *skb;
1223
	u16 control, fcs;
1224

1225
	while ((skb = skb_dequeue(&chan->tx_q))) {
1226
		control = get_unaligned_le16(skb->data + L2CAP_HDR_SIZE);
1227
		control |= chan->next_tx_seq << L2CAP_CTRL_TXSEQ_SHIFT;
1228
		put_unaligned_le16(control, skb->data + L2CAP_HDR_SIZE);
1229

1230
		if (chan->fcs == L2CAP_FCS_CRC16) {
1231 1232
			fcs = crc16(0, (u8 *)skb->data, skb->len - 2);
			put_unaligned_le16(fcs, skb->data + skb->len - 2);
1233 1234
		}

1235
		l2cap_do_send(chan, skb);
1236

1237
		chan->next_tx_seq = (chan->next_tx_seq + 1) % 64;
1238 1239 1240
	}
}

1241
static void l2cap_retransmit_one_frame(struct l2cap_chan *chan, u8 tx_seq)
1242 1243 1244 1245
{
	struct sk_buff *skb, *tx_skb;
	u16 control, fcs;

1246
	skb = skb_peek(&chan->tx_q);
1247 1248
	if (!skb)
		return;
1249

1250 1251
	do {
		if (bt_cb(skb)->tx_seq == tx_seq)
1252 1253
			break;

1254
		if (skb_queue_is_last(&chan->tx_q, skb))
1255
			return;
1256

1257
	} while ((skb = skb_queue_next(&chan->tx_q, skb)));
1258

1259 1260
	if (chan->remote_max_tx &&
			bt_cb(skb)->retries == chan->remote_max_tx) {
1261
		l2cap_send_disconn_req(chan->conn, chan, ECONNABORTED);
1262 1263 1264 1265 1266 1267
		return;
	}

	tx_skb = skb_clone(skb, GFP_ATOMIC);
	bt_cb(skb)->retries++;
	control = get_unaligned_le16(tx_skb->data + L2CAP_HDR_SIZE);
1268
	control &= L2CAP_CTRL_SAR;
1269

1270
	if (chan->conn_state & L2CAP_CONN_SEND_FBIT) {
1271
		control |= L2CAP_CTRL_FINAL;
1272
		chan->conn_state &= ~L2CAP_CONN_SEND_FBIT;
1273
	}
1274

1275
	control |= (chan->buffer_seq << L2CAP_CTRL_REQSEQ_SHIFT)
1276
			| (tx_seq << L2CAP_CTRL_TXSEQ_SHIFT);
1277

1278 1279
	put_unaligned_le16(control, tx_skb->data + L2CAP_HDR_SIZE);

1280
	if (chan->fcs == L2CAP_FCS_CRC16) {
1281 1282 1283 1284
		fcs = crc16(0, (u8 *)tx_skb->data, tx_skb->len - 2);
		put_unaligned_le16(fcs, tx_skb->data + tx_skb->len - 2);
	}

1285
	l2cap_do_send(chan, tx_skb);
1286 1287
}

1288
int l2cap_ertm_send(struct l2cap_chan *chan)
1289 1290
{
	struct sk_buff *skb, *tx_skb;
1291
	struct sock *sk = chan->sk;
1292
	u16 control, fcs;
1293
	int nsent = 0;
1294

1295 1296
	if (sk->sk_state != BT_CONNECTED)
		return -ENOTCONN;
1297

1298
	while ((skb = chan->tx_send_head) && (!l2cap_tx_window_full(chan))) {
1299

1300 1301
		if (chan->remote_max_tx &&
				bt_cb(skb)->retries == chan->remote_max_tx) {
1302
			l2cap_send_disconn_req(chan->conn, chan, ECONNABORTED);
1303 1304 1305
			break;
		}

1306 1307
		tx_skb = skb_clone(skb, GFP_ATOMIC);

1308 1309
		bt_cb(skb)->retries++;

1310
		control = get_unaligned_le16(tx_skb->data + L2CAP_HDR_SIZE);
1311 1312
		control &= L2CAP_CTRL_SAR;

1313
		if (chan->conn_state & L2CAP_CONN_SEND_FBIT) {
1314
			control |= L2CAP_CTRL_FINAL;
1315
			chan->conn_state &= ~L2CAP_CONN_SEND_FBIT;
1316
		}
1317 1318
		control |= (chan->buffer_seq << L2CAP_CTRL_REQSEQ_SHIFT)
				| (chan->next_tx_seq << L2CAP_CTRL_TXSEQ_SHIFT);
1319 1320
		put_unaligned_le16(control, tx_skb->data + L2CAP_HDR_SIZE);

1321

1322
		if (chan->fcs == L2CAP_FCS_CRC16) {
1323 1324 1325 1326
			fcs = crc16(0, (u8 *)skb->data, tx_skb->len - 2);
			put_unaligned_le16(fcs, skb->data + tx_skb->len - 2);
		}

1327
		l2cap_do_send(chan, tx_skb);
1328

1329
		__mod_retrans_timer();
1330

1331 1332
		bt_cb(skb)->tx_seq = chan->next_tx_seq;
		chan->next_tx_seq = (chan->next_tx_seq + 1) % 64;
1333

1334
		if (bt_cb(skb)->retries == 1)
1335
			chan->unacked_frames++;
1336

1337
		chan->frames_sent++;
1338

1339 1340
		if (skb_queue_is_last(&chan->tx_q, skb))
			chan->tx_send_head = NULL;
1341
		else
1342
			chan->tx_send_head = skb_queue_next(&chan->tx_q, skb);
1343 1344

		nsent++;
1345 1346
	}

1347 1348 1349
	return nsent;
}

1350
static int l2cap_retransmit_frames(struct l2cap_chan *chan)
1351 1352 1353
{
	int ret;

1354 1355
	if (!skb_queue_empty(&chan->tx_q))
		chan->tx_send_head = chan->tx_q.next;
1356

1357
	chan->next_tx_seq = chan->expected_ack_seq;
1358
	ret = l2cap_ertm_send(chan);
1359 1360 1361
	return ret;
}

1362
static void l2cap_send_ack(struct l2cap_chan *chan)
1363 1364 1365
{
	u16 control = 0;

1366
	control |= chan->buffer_seq << L2CAP_CTRL_REQSEQ_SHIFT;
1367

1368
	if (chan->conn_state & L2CAP_CONN_LOCAL_BUSY) {
1369
		control |= L2CAP_SUPER_RCV_NOT_READY;
1370 1371
		chan->conn_state |= L2CAP_CONN_RNR_SENT;
		l2cap_send_sframe(chan, control);
1372
		return;
1373
	}
1374

1375
	if (l2cap_ertm_send(chan) > 0)
1376 1377 1378
		return;

	control |= L2CAP_SUPER_RCV_READY;
1379
	l2cap_send_sframe(chan, control);
1380 1381
}

1382
static void l2cap_send_srejtail(struct l2cap_chan *chan)
1383 1384 1385 1386 1387 1388 1389
{
	struct srej_list *tail;
	u16 control;

	control = L2CAP_SUPER_SELECT_REJECT;
	control |= L2CAP_CTRL_FINAL;

1390
	tail = list_entry((&chan->srej_l)->prev, struct srej_list, list);
1391 1392
	control |= tail->tx_seq << L2CAP_CTRL_REQSEQ_SHIFT;

1393
	l2cap_send_sframe(chan, control);
1394 1395
}

1396 1397
static inline int l2cap_skbuff_fromiovec(struct sock *sk, struct msghdr *msg, int len, int count, struct sk_buff *skb)
{
1398
	struct l2cap_conn *conn = l2cap_pi(sk)->chan->conn;
1399 1400
	struct sk_buff **frag;
	int err, sent = 0;
L
Linus Torvalds 已提交
1401

1402
	if (memcpy_fromiovec(skb_put(skb, count), msg->msg_iov, count))
1403
		return -EFAULT;
L
Linus Torvalds 已提交
1404 1405 1406 1407 1408 1409 1410 1411 1412 1413 1414

	sent += count;
	len  -= count;

	/* Continuation fragments (no L2CAP header) */
	frag = &skb_shinfo(skb)->frag_list;
	while (len) {
		count = min_t(unsigned int, conn->mtu, len);

		*frag = bt_skb_send_alloc(sk, count, msg->msg_flags & MSG_DONTWAIT, &err);
		if (!*frag)
1415
			return err;
1416 1417
		if (memcpy_fromiovec(skb_put(*frag, count), msg->msg_iov, count))
			return -EFAULT;
L
Linus Torvalds 已提交
1418 1419 1420 1421 1422 1423 1424 1425

		sent += count;
		len  -= count;

		frag = &(*frag)->next;
	}

	return sent;
1426
}
L
Linus Torvalds 已提交
1427

1428
struct sk_buff *l2cap_create_connless_pdu(struct l2cap_chan *chan, struct msghdr *msg, size_t len)
1429
{
1430
	struct sock *sk = chan->sk;
1431
	struct l2cap_conn *conn = chan->conn;
1432 1433 1434 1435 1436 1437 1438 1439 1440 1441
	struct sk_buff *skb;
	int err, count, hlen = L2CAP_HDR_SIZE + 2;
	struct l2cap_hdr *lh;

	BT_DBG("sk %p len %d", sk, (int)len);

	count = min_t(unsigned int, (conn->mtu - hlen), len);
	skb = bt_skb_send_alloc(sk, count + hlen,
			msg->msg_flags & MSG_DONTWAIT, &err);
	if (!skb)
1442
		return ERR_PTR(err);
1443 1444 1445

	/* Create L2CAP header */
	lh = (struct l2cap_hdr *) skb_put(skb, L2CAP_HDR_SIZE);
1446
	lh->cid = cpu_to_le16(chan->dcid);
1447
	lh->len = cpu_to_le16(len + (hlen - L2CAP_HDR_SIZE));
1448
	put_unaligned_le16(chan->psm, skb_put(skb, 2));
1449 1450 1451 1452 1453 1454 1455 1456 1457

	err = l2cap_skbuff_fromiovec(sk, msg, len, count, skb);
	if (unlikely(err < 0)) {
		kfree_skb(skb);
		return ERR_PTR(err);
	}
	return skb;
}

1458
struct sk_buff *l2cap_create_basic_pdu(struct l2cap_chan *chan, struct msghdr *msg, size_t len)
1459
{
1460
	struct sock *sk = chan->sk;
1461
	struct l2cap_conn *conn = chan->conn;
1462 1463 1464 1465 1466 1467 1468 1469 1470 1471
	struct sk_buff *skb;
	int err, count, hlen = L2CAP_HDR_SIZE;
	struct l2cap_hdr *lh;

	BT_DBG("sk %p len %d", sk, (int)len);

	count = min_t(unsigned int, (conn->mtu - hlen), len);
	skb = bt_skb_send_alloc(sk, count + hlen,
			msg->msg_flags & MSG_DONTWAIT, &err);
	if (!skb)
1472
		return ERR_PTR(err);
1473 1474 1475

	/* Create L2CAP header */
	lh = (struct l2cap_hdr *) skb_put(skb, L2CAP_HDR_SIZE);
1476
	lh->cid = cpu_to_le16(chan->dcid);
1477 1478 1479 1480 1481 1482 1483 1484 1485 1486
	lh->len = cpu_to_le16(len + (hlen - L2CAP_HDR_SIZE));

	err = l2cap_skbuff_fromiovec(sk, msg, len, count, skb);
	if (unlikely(err < 0)) {
		kfree_skb(skb);
		return ERR_PTR(err);
	}
	return skb;
}

1487
struct sk_buff *l2cap_create_iframe_pdu(struct l2cap_chan *chan, struct msghdr *msg, size_t len, u16 control, u16 sdulen)
1488
{
1489
	struct sock *sk = chan->sk;
1490
	struct l2cap_conn *conn = chan->conn;
1491 1492 1493 1494 1495 1496
	struct sk_buff *skb;
	int err, count, hlen = L2CAP_HDR_SIZE + 2;
	struct l2cap_hdr *lh;

	BT_DBG("sk %p len %d", sk, (int)len);

1497 1498 1499
	if (!conn)
		return ERR_PTR(-ENOTCONN);

1500 1501 1502
	if (sdulen)
		hlen += 2;

1503
	if (chan->fcs == L2CAP_FCS_CRC16)
1504 1505
		hlen += 2;

1506 1507 1508 1509
	count = min_t(unsigned int, (conn->mtu - hlen), len);
	skb = bt_skb_send_alloc(sk, count + hlen,
			msg->msg_flags & MSG_DONTWAIT, &err);
	if (!skb)
1510
		return ERR_PTR(err);
1511 1512 1513

	/* Create L2CAP header */
	lh = (struct l2cap_hdr *) skb_put(skb, L2CAP_HDR_SIZE);
1514
	lh->cid = cpu_to_le16(chan->dcid);
1515 1516
	lh->len = cpu_to_le16(len + (hlen - L2CAP_HDR_SIZE));
	put_unaligned_le16(control, skb_put(skb, 2));
1517 1518
	if (sdulen)
		put_unaligned_le16(sdulen, skb_put(skb, 2));
1519 1520 1521 1522 1523 1524

	err = l2cap_skbuff_fromiovec(sk, msg, len, count, skb);
	if (unlikely(err < 0)) {
		kfree_skb(skb);
		return ERR_PTR(err);
	}
1525

1526
	if (chan->fcs == L2CAP_FCS_CRC16)
1527 1528
		put_unaligned_le16(0, skb_put(skb, 2));

1529
	bt_cb(skb)->retries = 0;
1530
	return skb;
L
Linus Torvalds 已提交
1531 1532
}

1533
int l2cap_sar_segment_sdu(struct l2cap_chan *chan, struct msghdr *msg, size_t len)
1534 1535 1536 1537 1538 1539
{
	struct sk_buff *skb;
	struct sk_buff_head sar_queue;
	u16 control;
	size_t size = 0;

1540
	skb_queue_head_init(&sar_queue);
1541
	control = L2CAP_SDU_START;
1542
	skb = l2cap_create_iframe_pdu(chan, msg, chan->remote_mps, control, len);
1543 1544 1545 1546
	if (IS_ERR(skb))
		return PTR_ERR(skb);

	__skb_queue_tail(&sar_queue, skb);
1547 1548
	len -= chan->remote_mps;
	size += chan->remote_mps;
1549 1550 1551 1552

	while (len > 0) {
		size_t buflen;

1553
		if (len > chan->remote_mps) {
1554
			control = L2CAP_SDU_CONTINUE;
1555
			buflen = chan->remote_mps;
1556
		} else {
1557
			control = L2CAP_SDU_END;
1558 1559 1560
			buflen = len;
		}

1561
		skb = l2cap_create_iframe_pdu(chan, msg, buflen, control, 0);
1562 1563 1564 1565 1566 1567 1568 1569 1570
		if (IS_ERR(skb)) {
			skb_queue_purge(&sar_queue);
			return PTR_ERR(skb);
		}

		__skb_queue_tail(&sar_queue, skb);
		len -= buflen;
		size += buflen;
	}
1571 1572 1573
	skb_queue_splice_tail(&sar_queue, &chan->tx_q);
	if (chan->tx_send_head == NULL)
		chan->tx_send_head = sar_queue.next;
1574 1575 1576 1577

	return size;
}

1578 1579 1580 1581 1582 1583 1584
int l2cap_chan_send(struct l2cap_chan *chan, struct msghdr *msg, size_t len)
{
	struct sk_buff *skb;
	u16 control;
	int err;

	/* Connectionless channel */
1585
	if (chan->chan_type == L2CAP_CHAN_CONN_LESS) {
1586 1587 1588 1589 1590 1591 1592 1593 1594 1595 1596 1597 1598 1599 1600 1601 1602 1603 1604 1605 1606 1607 1608 1609 1610 1611 1612 1613 1614 1615 1616 1617 1618 1619 1620 1621 1622 1623 1624 1625 1626 1627 1628 1629 1630 1631 1632 1633 1634 1635 1636 1637 1638 1639 1640 1641 1642 1643 1644 1645 1646 1647 1648 1649 1650 1651 1652 1653 1654 1655 1656
		skb = l2cap_create_connless_pdu(chan, msg, len);
		if (IS_ERR(skb))
			return PTR_ERR(skb);

		l2cap_do_send(chan, skb);
		return len;
	}

	switch (chan->mode) {
	case L2CAP_MODE_BASIC:
		/* Check outgoing MTU */
		if (len > chan->omtu)
			return -EMSGSIZE;

		/* Create a basic PDU */
		skb = l2cap_create_basic_pdu(chan, msg, len);
		if (IS_ERR(skb))
			return PTR_ERR(skb);

		l2cap_do_send(chan, skb);
		err = len;
		break;

	case L2CAP_MODE_ERTM:
	case L2CAP_MODE_STREAMING:
		/* Entire SDU fits into one PDU */
		if (len <= chan->remote_mps) {
			control = L2CAP_SDU_UNSEGMENTED;
			skb = l2cap_create_iframe_pdu(chan, msg, len, control,
									0);
			if (IS_ERR(skb))
				return PTR_ERR(skb);

			__skb_queue_tail(&chan->tx_q, skb);

			if (chan->tx_send_head == NULL)
				chan->tx_send_head = skb;

		} else {
			/* Segment SDU into multiples PDUs */
			err = l2cap_sar_segment_sdu(chan, msg, len);
			if (err < 0)
				return err;
		}

		if (chan->mode == L2CAP_MODE_STREAMING) {
			l2cap_streaming_send(chan);
			err = len;
			break;
		}

		if ((chan->conn_state & L2CAP_CONN_REMOTE_BUSY) &&
				(chan->conn_state & L2CAP_CONN_WAIT_F)) {
			err = len;
			break;
		}

		err = l2cap_ertm_send(chan);
		if (err >= 0)
			err = len;

		break;

	default:
		BT_DBG("bad state %1.1x", chan->mode);
		err = -EBADFD;
	}

	return err;
}

L
Linus Torvalds 已提交
1657 1658 1659
static void l2cap_chan_ready(struct sock *sk)
{
	struct sock *parent = bt_sk(sk)->parent;
1660
	struct l2cap_chan *chan = l2cap_pi(sk)->chan;
L
Linus Torvalds 已提交
1661 1662 1663

	BT_DBG("sk %p, parent %p", sk, parent);

1664
	chan->conf_state = 0;
1665
	l2cap_chan_clear_timer(chan);
L
Linus Torvalds 已提交
1666 1667 1668 1669 1670 1671 1672 1673 1674 1675 1676 1677 1678 1679 1680 1681 1682 1683 1684

	if (!parent) {
		/* Outgoing channel.
		 * Wake up socket sleeping on connect.
		 */
		sk->sk_state = BT_CONNECTED;
		sk->sk_state_change(sk);
	} else {
		/* Incoming channel.
		 * Wake up socket sleeping on accept.
		 */
		parent->sk_data_ready(parent, 0);
	}
}

/* Copy frame to all raw sockets on that connection */
static void l2cap_raw_recv(struct l2cap_conn *conn, struct sk_buff *skb)
{
	struct sk_buff *nskb;
1685
	struct l2cap_chan *chan;
L
Linus Torvalds 已提交
1686 1687 1688

	BT_DBG("conn %p", conn);

1689 1690
	read_lock(&conn->chan_lock);
	list_for_each_entry(chan, &conn->chan_l, list) {
1691
		struct sock *sk = chan->sk;
1692
		if (chan->chan_type != L2CAP_CHAN_RAW)
L
Linus Torvalds 已提交
1693 1694 1695 1696 1697
			continue;

		/* Don't send frame to the socket it came from */
		if (skb->sk == sk)
			continue;
1698 1699
		nskb = skb_clone(skb, GFP_ATOMIC);
		if (!nskb)
L
Linus Torvalds 已提交
1700 1701
			continue;

1702
		if (chan->ops->recv(chan->data, nskb))
L
Linus Torvalds 已提交
1703 1704
			kfree_skb(nskb);
	}
1705
	read_unlock(&conn->chan_lock);
L
Linus Torvalds 已提交
1706 1707 1708 1709 1710 1711 1712 1713 1714 1715 1716
}

/* ---- L2CAP signalling commands ---- */
static struct sk_buff *l2cap_build_cmd(struct l2cap_conn *conn,
				u8 code, u8 ident, u16 dlen, void *data)
{
	struct sk_buff *skb, **frag;
	struct l2cap_cmd_hdr *cmd;
	struct l2cap_hdr *lh;
	int len, count;

1717 1718
	BT_DBG("conn %p, code 0x%2.2x, ident 0x%2.2x, len %d",
			conn, code, ident, dlen);
L
Linus Torvalds 已提交
1719 1720 1721 1722 1723 1724 1725 1726 1727

	len = L2CAP_HDR_SIZE + L2CAP_CMD_HDR_SIZE + dlen;
	count = min_t(unsigned int, conn->mtu, len);

	skb = bt_skb_alloc(count, GFP_ATOMIC);
	if (!skb)
		return NULL;

	lh = (struct l2cap_hdr *) skb_put(skb, L2CAP_HDR_SIZE);
1728
	lh->len = cpu_to_le16(L2CAP_CMD_HDR_SIZE + dlen);
1729 1730 1731 1732 1733

	if (conn->hcon->type == LE_LINK)
		lh->cid = cpu_to_le16(L2CAP_CID_LE_SIGNALING);
	else
		lh->cid = cpu_to_le16(L2CAP_CID_SIGNALING);
L
Linus Torvalds 已提交
1734 1735 1736 1737

	cmd = (struct l2cap_cmd_hdr *) skb_put(skb, L2CAP_CMD_HDR_SIZE);
	cmd->code  = code;
	cmd->ident = ident;
1738
	cmd->len   = cpu_to_le16(dlen);
L
Linus Torvalds 已提交
1739 1740 1741 1742 1743 1744 1745 1746 1747 1748 1749 1750 1751 1752 1753 1754 1755 1756 1757 1758 1759 1760 1761 1762 1763 1764 1765 1766 1767 1768 1769 1770 1771 1772 1773 1774 1775 1776 1777 1778 1779 1780 1781 1782 1783 1784 1785 1786 1787 1788

	if (dlen) {
		count -= L2CAP_HDR_SIZE + L2CAP_CMD_HDR_SIZE;
		memcpy(skb_put(skb, count), data, count);
		data += count;
	}

	len -= skb->len;

	/* Continuation fragments (no L2CAP header) */
	frag = &skb_shinfo(skb)->frag_list;
	while (len) {
		count = min_t(unsigned int, conn->mtu, len);

		*frag = bt_skb_alloc(count, GFP_ATOMIC);
		if (!*frag)
			goto fail;

		memcpy(skb_put(*frag, count), data, count);

		len  -= count;
		data += count;

		frag = &(*frag)->next;
	}

	return skb;

fail:
	kfree_skb(skb);
	return NULL;
}

static inline int l2cap_get_conf_opt(void **ptr, int *type, int *olen, unsigned long *val)
{
	struct l2cap_conf_opt *opt = *ptr;
	int len;

	len = L2CAP_CONF_OPT_SIZE + opt->len;
	*ptr += len;

	*type = opt->type;
	*olen = opt->len;

	switch (opt->len) {
	case 1:
		*val = *((u8 *) opt->val);
		break;

	case 2:
1789
		*val = get_unaligned_le16(opt->val);
L
Linus Torvalds 已提交
1790 1791 1792
		break;

	case 4:
1793
		*val = get_unaligned_le32(opt->val);
L
Linus Torvalds 已提交
1794 1795 1796 1797 1798 1799 1800 1801 1802 1803 1804 1805 1806 1807 1808 1809 1810 1811 1812 1813 1814 1815 1816 1817 1818 1819
		break;

	default:
		*val = (unsigned long) opt->val;
		break;
	}

	BT_DBG("type 0x%2.2x len %d val 0x%lx", *type, opt->len, *val);
	return len;
}

static void l2cap_add_conf_opt(void **ptr, u8 type, u8 len, unsigned long val)
{
	struct l2cap_conf_opt *opt = *ptr;

	BT_DBG("type 0x%2.2x len %d val 0x%lx", type, len, val);

	opt->type = type;
	opt->len  = len;

	switch (len) {
	case 1:
		*((u8 *) opt->val)  = val;
		break;

	case 2:
1820
		put_unaligned_le16(val, opt->val);
L
Linus Torvalds 已提交
1821 1822 1823
		break;

	case 4:
1824
		put_unaligned_le32(val, opt->val);
L
Linus Torvalds 已提交
1825 1826 1827 1828 1829 1830 1831 1832 1833 1834
		break;

	default:
		memcpy(opt->val, (void *) val, len);
		break;
	}

	*ptr += L2CAP_CONF_OPT_SIZE + len;
}

1835 1836
static void l2cap_ack_timeout(unsigned long arg)
{
1837
	struct l2cap_chan *chan = (void *) arg;
1838

1839 1840 1841
	bh_lock_sock(chan->sk);
	l2cap_send_ack(chan);
	bh_unlock_sock(chan->sk);
1842 1843
}

1844
static inline void l2cap_ertm_init(struct l2cap_chan *chan)
1845
{
1846 1847
	struct sock *sk = chan->sk;

1848
	chan->expected_ack_seq = 0;
1849
	chan->unacked_frames = 0;
1850
	chan->buffer_seq = 0;
1851 1852
	chan->num_acked = 0;
	chan->frames_sent = 0;
1853

1854 1855 1856 1857 1858
	setup_timer(&chan->retrans_timer, l2cap_retrans_timeout,
							(unsigned long) chan);
	setup_timer(&chan->monitor_timer, l2cap_monitor_timeout,
							(unsigned long) chan);
	setup_timer(&chan->ack_timer, l2cap_ack_timeout, (unsigned long) chan);
1859

1860 1861
	skb_queue_head_init(&chan->srej_q);
	skb_queue_head_init(&chan->busy_q);
1862

1863 1864
	INIT_LIST_HEAD(&chan->srej_l);

1865
	INIT_WORK(&chan->busy_work, l2cap_busy_work);
1866 1867

	sk->sk_backlog_rcv = l2cap_ertm_data_rcv;
1868 1869
}

1870 1871 1872 1873 1874 1875 1876 1877 1878 1879 1880 1881 1882
static inline __u8 l2cap_select_mode(__u8 mode, __u16 remote_feat_mask)
{
	switch (mode) {
	case L2CAP_MODE_STREAMING:
	case L2CAP_MODE_ERTM:
		if (l2cap_mode_supported(mode, remote_feat_mask))
			return mode;
		/* fall through */
	default:
		return L2CAP_MODE_BASIC;
	}
}

1883
static int l2cap_build_conf_req(struct l2cap_chan *chan, void *data)
L
Linus Torvalds 已提交
1884 1885
{
	struct l2cap_conf_req *req = data;
1886
	struct l2cap_conf_rfc rfc = { .mode = chan->mode };
L
Linus Torvalds 已提交
1887 1888
	void *ptr = req->data;

1889
	BT_DBG("chan %p", chan);
L
Linus Torvalds 已提交
1890

1891
	if (chan->num_conf_req || chan->num_conf_rsp)
1892 1893
		goto done;

1894
	switch (chan->mode) {
1895 1896
	case L2CAP_MODE_STREAMING:
	case L2CAP_MODE_ERTM:
1897
		if (chan->conf_state & L2CAP_CONF_STATE2_DEVICE)
1898 1899
			break;

1900
		/* fall through */
1901
	default:
1902
		chan->mode = l2cap_select_mode(rfc.mode, chan->conn->feat_mask);
1903 1904 1905 1906
		break;
	}

done:
1907 1908
	if (chan->imtu != L2CAP_DEFAULT_MTU)
		l2cap_add_conf_opt(&ptr, L2CAP_CONF_MTU, 2, chan->imtu);
1909

1910
	switch (chan->mode) {
1911
	case L2CAP_MODE_BASIC:
1912 1913
		if (!(chan->conn->feat_mask & L2CAP_FEAT_ERTM) &&
				!(chan->conn->feat_mask & L2CAP_FEAT_STREAMING))
1914 1915
			break;

1916 1917 1918 1919 1920 1921 1922
		rfc.mode            = L2CAP_MODE_BASIC;
		rfc.txwin_size      = 0;
		rfc.max_transmit    = 0;
		rfc.retrans_timeout = 0;
		rfc.monitor_timeout = 0;
		rfc.max_pdu_size    = 0;

1923 1924
		l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC, sizeof(rfc),
							(unsigned long) &rfc);
1925 1926 1927 1928
		break;

	case L2CAP_MODE_ERTM:
		rfc.mode            = L2CAP_MODE_ERTM;
1929 1930
		rfc.txwin_size      = chan->tx_win;
		rfc.max_transmit    = chan->max_tx;
1931 1932
		rfc.retrans_timeout = 0;
		rfc.monitor_timeout = 0;
1933
		rfc.max_pdu_size    = cpu_to_le16(L2CAP_DEFAULT_MAX_PDU_SIZE);
1934 1935
		if (L2CAP_DEFAULT_MAX_PDU_SIZE > chan->conn->mtu - 10)
			rfc.max_pdu_size = cpu_to_le16(chan->conn->mtu - 10);
1936

1937 1938 1939
		l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC, sizeof(rfc),
							(unsigned long) &rfc);

1940
		if (!(chan->conn->feat_mask & L2CAP_FEAT_FCS))
1941 1942
			break;

1943
		if (chan->fcs == L2CAP_FCS_NONE ||
1944
				chan->conf_state & L2CAP_CONF_NO_FCS_RECV) {
1945 1946
			chan->fcs = L2CAP_FCS_NONE;
			l2cap_add_conf_opt(&ptr, L2CAP_CONF_FCS, 1, chan->fcs);
1947
		}
1948 1949 1950 1951 1952 1953 1954 1955
		break;

	case L2CAP_MODE_STREAMING:
		rfc.mode            = L2CAP_MODE_STREAMING;
		rfc.txwin_size      = 0;
		rfc.max_transmit    = 0;
		rfc.retrans_timeout = 0;
		rfc.monitor_timeout = 0;
1956
		rfc.max_pdu_size    = cpu_to_le16(L2CAP_DEFAULT_MAX_PDU_SIZE);
1957 1958
		if (L2CAP_DEFAULT_MAX_PDU_SIZE > chan->conn->mtu - 10)
			rfc.max_pdu_size = cpu_to_le16(chan->conn->mtu - 10);
1959

1960 1961 1962
		l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC, sizeof(rfc),
							(unsigned long) &rfc);

1963
		if (!(chan->conn->feat_mask & L2CAP_FEAT_FCS))
1964 1965
			break;

1966
		if (chan->fcs == L2CAP_FCS_NONE ||
1967
				chan->conf_state & L2CAP_CONF_NO_FCS_RECV) {
1968 1969
			chan->fcs = L2CAP_FCS_NONE;
			l2cap_add_conf_opt(&ptr, L2CAP_CONF_FCS, 1, chan->fcs);
1970
		}
1971 1972
		break;
	}
L
Linus Torvalds 已提交
1973

1974
	req->dcid  = cpu_to_le16(chan->dcid);
1975
	req->flags = cpu_to_le16(0);
L
Linus Torvalds 已提交
1976 1977 1978 1979

	return ptr - data;
}

1980
static int l2cap_parse_conf_req(struct l2cap_chan *chan, void *data)
L
Linus Torvalds 已提交
1981
{
1982 1983
	struct l2cap_conf_rsp *rsp = data;
	void *ptr = rsp->data;
1984 1985
	void *req = chan->conf_req;
	int len = chan->conf_len;
1986 1987
	int type, hint, olen;
	unsigned long val;
1988
	struct l2cap_conf_rfc rfc = { .mode = L2CAP_MODE_BASIC };
1989
	u16 mtu = L2CAP_DEFAULT_MTU;
1990
	u16 result = L2CAP_CONF_SUCCESS;
L
Linus Torvalds 已提交
1991

1992
	BT_DBG("chan %p", chan);
1993

1994 1995
	while (len >= L2CAP_CONF_OPT_SIZE) {
		len -= l2cap_get_conf_opt(&req, &type, &olen, &val);
L
Linus Torvalds 已提交
1996

1997
		hint  = type & L2CAP_CONF_HINT;
1998
		type &= L2CAP_CONF_MASK;
1999 2000 2001

		switch (type) {
		case L2CAP_CONF_MTU:
2002
			mtu = val;
2003 2004 2005
			break;

		case L2CAP_CONF_FLUSH_TO:
2006
			chan->flush_to = val;
2007 2008 2009 2010 2011
			break;

		case L2CAP_CONF_QOS:
			break;

2012 2013 2014 2015 2016
		case L2CAP_CONF_RFC:
			if (olen == sizeof(rfc))
				memcpy(&rfc, (void *) val, olen);
			break;

2017 2018
		case L2CAP_CONF_FCS:
			if (val == L2CAP_FCS_NONE)
2019
				chan->conf_state |= L2CAP_CONF_NO_FCS_RECV;
2020 2021 2022

			break;

2023 2024 2025 2026 2027 2028 2029 2030 2031 2032
		default:
			if (hint)
				break;

			result = L2CAP_CONF_UNKNOWN;
			*((u8 *) ptr++) = type;
			break;
		}
	}

2033
	if (chan->num_conf_rsp || chan->num_conf_req > 1)
2034 2035
		goto done;

2036
	switch (chan->mode) {
2037 2038
	case L2CAP_MODE_STREAMING:
	case L2CAP_MODE_ERTM:
2039
		if (!(chan->conf_state & L2CAP_CONF_STATE2_DEVICE)) {
2040
			chan->mode = l2cap_select_mode(rfc.mode,
2041
					chan->conn->feat_mask);
2042 2043 2044
			break;
		}

2045
		if (chan->mode != rfc.mode)
2046
			return -ECONNREFUSED;
2047

2048 2049 2050 2051
		break;
	}

done:
2052
	if (chan->mode != rfc.mode) {
2053
		result = L2CAP_CONF_UNACCEPT;
2054
		rfc.mode = chan->mode;
2055

2056
		if (chan->num_conf_rsp == 1)
2057 2058 2059 2060 2061 2062 2063
			return -ECONNREFUSED;

		l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC,
					sizeof(rfc), (unsigned long) &rfc);
	}


2064 2065 2066 2067
	if (result == L2CAP_CONF_SUCCESS) {
		/* Configure output options and let the other side know
		 * which ones we don't like. */

2068 2069 2070
		if (mtu < L2CAP_DEFAULT_MIN_MTU)
			result = L2CAP_CONF_UNACCEPT;
		else {
2071
			chan->omtu = mtu;
2072
			chan->conf_state |= L2CAP_CONF_MTU_DONE;
2073
		}
2074
		l2cap_add_conf_opt(&ptr, L2CAP_CONF_MTU, 2, chan->omtu);
2075

2076 2077
		switch (rfc.mode) {
		case L2CAP_MODE_BASIC:
2078
			chan->fcs = L2CAP_FCS_NONE;
2079
			chan->conf_state |= L2CAP_CONF_MODE_DONE;
2080 2081 2082
			break;

		case L2CAP_MODE_ERTM:
2083 2084
			chan->remote_tx_win = rfc.txwin_size;
			chan->remote_max_tx = rfc.max_transmit;
2085

2086 2087
			if (le16_to_cpu(rfc.max_pdu_size) > chan->conn->mtu - 10)
				rfc.max_pdu_size = cpu_to_le16(chan->conn->mtu - 10);
2088

2089
			chan->remote_mps = le16_to_cpu(rfc.max_pdu_size);
2090

2091 2092 2093 2094
			rfc.retrans_timeout =
				le16_to_cpu(L2CAP_DEFAULT_RETRANS_TO);
			rfc.monitor_timeout =
				le16_to_cpu(L2CAP_DEFAULT_MONITOR_TO);
2095

2096
			chan->conf_state |= L2CAP_CONF_MODE_DONE;
2097 2098 2099 2100

			l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC,
					sizeof(rfc), (unsigned long) &rfc);

2101 2102 2103
			break;

		case L2CAP_MODE_STREAMING:
2104 2105
			if (le16_to_cpu(rfc.max_pdu_size) > chan->conn->mtu - 10)
				rfc.max_pdu_size = cpu_to_le16(chan->conn->mtu - 10);
2106

2107
			chan->remote_mps = le16_to_cpu(rfc.max_pdu_size);
2108

2109
			chan->conf_state |= L2CAP_CONF_MODE_DONE;
2110 2111 2112 2113

			l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC,
					sizeof(rfc), (unsigned long) &rfc);

2114 2115 2116
			break;

		default:
2117 2118
			result = L2CAP_CONF_UNACCEPT;

2119
			memset(&rfc, 0, sizeof(rfc));
2120
			rfc.mode = chan->mode;
2121
		}
2122

2123
		if (result == L2CAP_CONF_SUCCESS)
2124
			chan->conf_state |= L2CAP_CONF_OUTPUT_DONE;
2125
	}
2126
	rsp->scid   = cpu_to_le16(chan->dcid);
2127 2128 2129 2130
	rsp->result = cpu_to_le16(result);
	rsp->flags  = cpu_to_le16(0x0000);

	return ptr - data;
L
Linus Torvalds 已提交
2131 2132
}

2133
static int l2cap_parse_conf_rsp(struct l2cap_chan *chan, void *rsp, int len, void *data, u16 *result)
2134 2135 2136 2137 2138 2139 2140
{
	struct l2cap_conf_req *req = data;
	void *ptr = req->data;
	int type, olen;
	unsigned long val;
	struct l2cap_conf_rfc rfc;

2141
	BT_DBG("chan %p, rsp %p, len %d, req %p", chan, rsp, len, data);
2142 2143 2144 2145 2146 2147 2148 2149

	while (len >= L2CAP_CONF_OPT_SIZE) {
		len -= l2cap_get_conf_opt(&rsp, &type, &olen, &val);

		switch (type) {
		case L2CAP_CONF_MTU:
			if (val < L2CAP_DEFAULT_MIN_MTU) {
				*result = L2CAP_CONF_UNACCEPT;
2150
				chan->imtu = L2CAP_DEFAULT_MIN_MTU;
2151
			} else
2152 2153
				chan->imtu = val;
			l2cap_add_conf_opt(&ptr, L2CAP_CONF_MTU, 2, chan->imtu);
2154 2155 2156
			break;

		case L2CAP_CONF_FLUSH_TO:
2157
			chan->flush_to = val;
2158
			l2cap_add_conf_opt(&ptr, L2CAP_CONF_FLUSH_TO,
2159
							2, chan->flush_to);
2160 2161 2162 2163 2164 2165
			break;

		case L2CAP_CONF_RFC:
			if (olen == sizeof(rfc))
				memcpy(&rfc, (void *)val, olen);

2166
			if ((chan->conf_state & L2CAP_CONF_STATE2_DEVICE) &&
2167
							rfc.mode != chan->mode)
2168 2169
				return -ECONNREFUSED;

2170
			chan->fcs = 0;
2171 2172 2173 2174 2175 2176 2177

			l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC,
					sizeof(rfc), (unsigned long) &rfc);
			break;
		}
	}

2178
	if (chan->mode == L2CAP_MODE_BASIC && chan->mode != rfc.mode)
2179 2180
		return -ECONNREFUSED;

2181
	chan->mode = rfc.mode;
2182

2183 2184 2185
	if (*result == L2CAP_CONF_SUCCESS) {
		switch (rfc.mode) {
		case L2CAP_MODE_ERTM:
2186 2187 2188
			chan->retrans_timeout = le16_to_cpu(rfc.retrans_timeout);
			chan->monitor_timeout = le16_to_cpu(rfc.monitor_timeout);
			chan->mps    = le16_to_cpu(rfc.max_pdu_size);
2189 2190
			break;
		case L2CAP_MODE_STREAMING:
2191
			chan->mps    = le16_to_cpu(rfc.max_pdu_size);
2192 2193 2194
		}
	}

2195
	req->dcid   = cpu_to_le16(chan->dcid);
2196 2197 2198 2199 2200
	req->flags  = cpu_to_le16(0x0000);

	return ptr - data;
}

2201
static int l2cap_build_conf_rsp(struct l2cap_chan *chan, void *data, u16 result, u16 flags)
L
Linus Torvalds 已提交
2202 2203 2204 2205
{
	struct l2cap_conf_rsp *rsp = data;
	void *ptr = rsp->data;

2206
	BT_DBG("chan %p", chan);
L
Linus Torvalds 已提交
2207

2208
	rsp->scid   = cpu_to_le16(chan->dcid);
2209
	rsp->result = cpu_to_le16(result);
2210
	rsp->flags  = cpu_to_le16(flags);
L
Linus Torvalds 已提交
2211 2212 2213 2214

	return ptr - data;
}

2215
void __l2cap_connect_rsp_defer(struct l2cap_chan *chan)
2216 2217
{
	struct l2cap_conn_rsp rsp;
2218
	struct l2cap_conn *conn = chan->conn;
2219 2220
	u8 buf[128];

2221 2222
	rsp.scid   = cpu_to_le16(chan->dcid);
	rsp.dcid   = cpu_to_le16(chan->scid);
2223 2224 2225 2226 2227
	rsp.result = cpu_to_le16(L2CAP_CR_SUCCESS);
	rsp.status = cpu_to_le16(L2CAP_CS_NO_INFO);
	l2cap_send_cmd(conn, chan->ident,
				L2CAP_CONN_RSP, sizeof(rsp), &rsp);

2228
	if (chan->conf_state & L2CAP_CONF_REQ_SENT)
2229 2230
		return;

2231
	chan->conf_state |= L2CAP_CONF_REQ_SENT;
2232 2233 2234 2235 2236
	l2cap_send_cmd(conn, l2cap_get_ident(conn), L2CAP_CONF_REQ,
			l2cap_build_conf_req(chan, buf), buf);
	chan->num_conf_req++;
}

2237
static void l2cap_conf_rfc_get(struct l2cap_chan *chan, void *rsp, int len)
2238 2239 2240 2241 2242
{
	int type, olen;
	unsigned long val;
	struct l2cap_conf_rfc rfc;

2243
	BT_DBG("chan %p, rsp %p, len %d", chan, rsp, len);
2244

2245
	if ((chan->mode != L2CAP_MODE_ERTM) && (chan->mode != L2CAP_MODE_STREAMING))
2246 2247 2248 2249 2250 2251 2252 2253 2254 2255 2256 2257 2258 2259 2260 2261
		return;

	while (len >= L2CAP_CONF_OPT_SIZE) {
		len -= l2cap_get_conf_opt(&rsp, &type, &olen, &val);

		switch (type) {
		case L2CAP_CONF_RFC:
			if (olen == sizeof(rfc))
				memcpy(&rfc, (void *)val, olen);
			goto done;
		}
	}

done:
	switch (rfc.mode) {
	case L2CAP_MODE_ERTM:
2262 2263 2264
		chan->retrans_timeout = le16_to_cpu(rfc.retrans_timeout);
		chan->monitor_timeout = le16_to_cpu(rfc.monitor_timeout);
		chan->mps    = le16_to_cpu(rfc.max_pdu_size);
2265 2266
		break;
	case L2CAP_MODE_STREAMING:
2267
		chan->mps    = le16_to_cpu(rfc.max_pdu_size);
2268 2269 2270
	}
}

2271 2272 2273 2274 2275 2276 2277 2278 2279 2280
static inline int l2cap_command_rej(struct l2cap_conn *conn, struct l2cap_cmd_hdr *cmd, u8 *data)
{
	struct l2cap_cmd_rej *rej = (struct l2cap_cmd_rej *) data;

	if (rej->reason != 0x0000)
		return 0;

	if ((conn->info_state & L2CAP_INFO_FEAT_MASK_REQ_SENT) &&
					cmd->ident == conn->info_ident) {
		del_timer(&conn->info_timer);
2281 2282

		conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_DONE;
2283
		conn->info_ident = 0;
2284

2285 2286 2287 2288 2289 2290
		l2cap_conn_start(conn);
	}

	return 0;
}

L
Linus Torvalds 已提交
2291 2292 2293 2294
static inline int l2cap_connect_req(struct l2cap_conn *conn, struct l2cap_cmd_hdr *cmd, u8 *data)
{
	struct l2cap_conn_req *req = (struct l2cap_conn_req *) data;
	struct l2cap_conn_rsp rsp;
2295
	struct l2cap_chan *chan = NULL, *pchan;
2296
	struct sock *parent, *sk = NULL;
2297
	int result, status = L2CAP_CS_NO_INFO;
L
Linus Torvalds 已提交
2298 2299

	u16 dcid = 0, scid = __le16_to_cpu(req->scid);
2300
	__le16 psm = req->psm;
L
Linus Torvalds 已提交
2301 2302 2303 2304

	BT_DBG("psm 0x%2.2x scid 0x%4.4x", psm, scid);

	/* Check if we have socket listening on psm */
2305 2306
	pchan = l2cap_global_chan_by_psm(BT_LISTEN, psm, conn->src);
	if (!pchan) {
L
Linus Torvalds 已提交
2307 2308 2309 2310
		result = L2CAP_CR_BAD_PSM;
		goto sendresp;
	}

2311 2312
	parent = pchan->sk;

2313 2314
	bh_lock_sock(parent);

2315 2316 2317
	/* Check if the ACL is secure enough (if not SDP) */
	if (psm != cpu_to_le16(0x0001) &&
				!hci_conn_check_link_mode(conn->hcon)) {
2318
		conn->disc_reason = 0x05;
2319 2320 2321 2322
		result = L2CAP_CR_SEC_BLOCK;
		goto response;
	}

L
Linus Torvalds 已提交
2323 2324 2325 2326
	result = L2CAP_CR_NO_MEM;

	/* Check for backlog size */
	if (sk_acceptq_is_full(parent)) {
2327
		BT_DBG("backlog full %d", parent->sk_ack_backlog);
L
Linus Torvalds 已提交
2328 2329 2330
		goto response;
	}

2331 2332
	chan = pchan->ops->new_connection(pchan->data);
	if (!chan)
L
Linus Torvalds 已提交
2333 2334
		goto response;

2335 2336
	sk = chan->sk;

2337
	write_lock_bh(&conn->chan_lock);
L
Linus Torvalds 已提交
2338 2339

	/* Check if we already have channel with that dcid */
2340 2341
	if (__l2cap_get_chan_by_dcid(conn, scid)) {
		write_unlock_bh(&conn->chan_lock);
L
Linus Torvalds 已提交
2342
		sock_set_flag(sk, SOCK_ZAPPED);
2343
		chan->ops->close(chan->data);
L
Linus Torvalds 已提交
2344 2345 2346 2347 2348 2349 2350
		goto response;
	}

	hci_conn_hold(conn->hcon);

	bacpy(&bt_sk(sk)->src, conn->src);
	bacpy(&bt_sk(sk)->dst, conn->dst);
2351 2352
	chan->psm  = psm;
	chan->dcid = scid;
L
Linus Torvalds 已提交
2353

2354 2355
	bt_accept_enqueue(parent, sk);

2356 2357
	__l2cap_chan_add(conn, chan);

2358
	dcid = chan->scid;
L
Linus Torvalds 已提交
2359

2360
	l2cap_chan_set_timer(chan, sk->sk_sndtimeo);
L
Linus Torvalds 已提交
2361

2362
	chan->ident = cmd->ident;
L
Linus Torvalds 已提交
2363

2364
	if (conn->info_state & L2CAP_INFO_FEAT_MASK_REQ_DONE) {
2365
		if (l2cap_check_security(chan)) {
2366 2367 2368 2369 2370 2371 2372 2373 2374 2375
			if (bt_sk(sk)->defer_setup) {
				sk->sk_state = BT_CONNECT2;
				result = L2CAP_CR_PEND;
				status = L2CAP_CS_AUTHOR_PEND;
				parent->sk_data_ready(parent, 0);
			} else {
				sk->sk_state = BT_CONFIG;
				result = L2CAP_CR_SUCCESS;
				status = L2CAP_CS_NO_INFO;
			}
2376 2377 2378 2379 2380 2381 2382 2383 2384
		} else {
			sk->sk_state = BT_CONNECT2;
			result = L2CAP_CR_PEND;
			status = L2CAP_CS_AUTHEN_PEND;
		}
	} else {
		sk->sk_state = BT_CONNECT2;
		result = L2CAP_CR_PEND;
		status = L2CAP_CS_NO_INFO;
L
Linus Torvalds 已提交
2385 2386
	}

2387
	write_unlock_bh(&conn->chan_lock);
L
Linus Torvalds 已提交
2388 2389 2390 2391 2392

response:
	bh_unlock_sock(parent);

sendresp:
2393 2394 2395 2396
	rsp.scid   = cpu_to_le16(scid);
	rsp.dcid   = cpu_to_le16(dcid);
	rsp.result = cpu_to_le16(result);
	rsp.status = cpu_to_le16(status);
L
Linus Torvalds 已提交
2397
	l2cap_send_cmd(conn, cmd->ident, L2CAP_CONN_RSP, sizeof(rsp), &rsp);
2398 2399 2400 2401 2402 2403 2404 2405 2406 2407 2408 2409 2410 2411 2412

	if (result == L2CAP_CR_PEND && status == L2CAP_CS_NO_INFO) {
		struct l2cap_info_req info;
		info.type = cpu_to_le16(L2CAP_IT_FEAT_MASK);

		conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_SENT;
		conn->info_ident = l2cap_get_ident(conn);

		mod_timer(&conn->info_timer, jiffies +
					msecs_to_jiffies(L2CAP_INFO_TIMEOUT));

		l2cap_send_cmd(conn, conn->info_ident,
					L2CAP_INFO_REQ, sizeof(info), &info);
	}

2413
	if (chan && !(chan->conf_state & L2CAP_CONF_REQ_SENT) &&
2414 2415
				result == L2CAP_CR_SUCCESS) {
		u8 buf[128];
2416
		chan->conf_state |= L2CAP_CONF_REQ_SENT;
2417
		l2cap_send_cmd(conn, l2cap_get_ident(conn), L2CAP_CONF_REQ,
2418 2419
					l2cap_build_conf_req(chan, buf), buf);
		chan->num_conf_req++;
2420 2421
	}

L
Linus Torvalds 已提交
2422 2423 2424 2425 2426 2427 2428
	return 0;
}

static inline int l2cap_connect_rsp(struct l2cap_conn *conn, struct l2cap_cmd_hdr *cmd, u8 *data)
{
	struct l2cap_conn_rsp *rsp = (struct l2cap_conn_rsp *) data;
	u16 scid, dcid, result, status;
2429
	struct l2cap_chan *chan;
L
Linus Torvalds 已提交
2430 2431 2432 2433 2434 2435 2436 2437 2438 2439 2440
	struct sock *sk;
	u8 req[128];

	scid   = __le16_to_cpu(rsp->scid);
	dcid   = __le16_to_cpu(rsp->dcid);
	result = __le16_to_cpu(rsp->result);
	status = __le16_to_cpu(rsp->status);

	BT_DBG("dcid 0x%4.4x scid 0x%4.4x result 0x%2.2x status 0x%2.2x", dcid, scid, result, status);

	if (scid) {
2441
		chan = l2cap_get_chan_by_scid(conn, scid);
2442
		if (!chan)
2443
			return -EFAULT;
L
Linus Torvalds 已提交
2444
	} else {
2445
		chan = l2cap_get_chan_by_ident(conn, cmd->ident);
2446
		if (!chan)
2447
			return -EFAULT;
L
Linus Torvalds 已提交
2448 2449
	}

2450 2451
	sk = chan->sk;

L
Linus Torvalds 已提交
2452 2453 2454
	switch (result) {
	case L2CAP_CR_SUCCESS:
		sk->sk_state = BT_CONFIG;
2455
		chan->ident = 0;
2456
		chan->dcid = dcid;
2457
		chan->conf_state &= ~L2CAP_CONF_CONNECT_PEND;
2458

2459
		if (chan->conf_state & L2CAP_CONF_REQ_SENT)
2460 2461
			break;

2462
		chan->conf_state |= L2CAP_CONF_REQ_SENT;
2463

L
Linus Torvalds 已提交
2464
		l2cap_send_cmd(conn, l2cap_get_ident(conn), L2CAP_CONF_REQ,
2465 2466
					l2cap_build_conf_req(chan, req), req);
		chan->num_conf_req++;
L
Linus Torvalds 已提交
2467 2468 2469
		break;

	case L2CAP_CR_PEND:
2470
		chan->conf_state |= L2CAP_CONF_CONNECT_PEND;
L
Linus Torvalds 已提交
2471 2472 2473
		break;

	default:
2474 2475 2476
		/* don't delete l2cap channel if sk is owned by user */
		if (sock_owned_by_user(sk)) {
			sk->sk_state = BT_DISCONN;
2477 2478
			l2cap_chan_clear_timer(chan);
			l2cap_chan_set_timer(chan, HZ / 5);
2479 2480 2481
			break;
		}

2482
		l2cap_chan_del(chan, ECONNREFUSED);
L
Linus Torvalds 已提交
2483 2484 2485 2486 2487 2488 2489
		break;
	}

	bh_unlock_sock(sk);
	return 0;
}

2490
static inline void set_default_fcs(struct l2cap_chan *chan)
2491
{
2492 2493
	struct l2cap_pinfo *pi = l2cap_pi(chan->sk);

2494 2495 2496
	/* FCS is enabled only in ERTM or streaming mode, if one or both
	 * sides request it.
	 */
2497
	if (chan->mode != L2CAP_MODE_ERTM && chan->mode != L2CAP_MODE_STREAMING)
2498
		chan->fcs = L2CAP_FCS_NONE;
2499
	else if (!(pi->chan->conf_state & L2CAP_CONF_NO_FCS_RECV))
2500
		chan->fcs = L2CAP_FCS_CRC16;
2501 2502
}

2503
static inline int l2cap_config_req(struct l2cap_conn *conn, struct l2cap_cmd_hdr *cmd, u16 cmd_len, u8 *data)
L
Linus Torvalds 已提交
2504 2505 2506 2507
{
	struct l2cap_conf_req *req = (struct l2cap_conf_req *) data;
	u16 dcid, flags;
	u8 rsp[64];
2508
	struct l2cap_chan *chan;
L
Linus Torvalds 已提交
2509
	struct sock *sk;
2510
	int len;
L
Linus Torvalds 已提交
2511 2512 2513 2514 2515 2516

	dcid  = __le16_to_cpu(req->dcid);
	flags = __le16_to_cpu(req->flags);

	BT_DBG("dcid 0x%4.4x flags 0x%2.2x", dcid, flags);

2517
	chan = l2cap_get_chan_by_scid(conn, dcid);
2518
	if (!chan)
L
Linus Torvalds 已提交
2519 2520
		return -ENOENT;

2521 2522
	sk = chan->sk;

2523 2524 2525 2526 2527 2528
	if (sk->sk_state != BT_CONFIG) {
		struct l2cap_cmd_rej rej;

		rej.reason = cpu_to_le16(0x0002);
		l2cap_send_cmd(conn, cmd->ident, L2CAP_COMMAND_REJ,
				sizeof(rej), &rej);
2529
		goto unlock;
2530
	}
2531

2532
	/* Reject if config buffer is too small. */
2533
	len = cmd_len - sizeof(*req);
2534
	if (chan->conf_len + len > sizeof(chan->conf_req)) {
2535
		l2cap_send_cmd(conn, cmd->ident, L2CAP_CONF_RSP,
2536
				l2cap_build_conf_rsp(chan, rsp,
2537 2538 2539 2540 2541
					L2CAP_CONF_REJECT, flags), rsp);
		goto unlock;
	}

	/* Store config. */
2542 2543
	memcpy(chan->conf_req + chan->conf_len, req->data, len);
	chan->conf_len += len;
L
Linus Torvalds 已提交
2544 2545 2546 2547

	if (flags & 0x0001) {
		/* Incomplete config. Send empty response. */
		l2cap_send_cmd(conn, cmd->ident, L2CAP_CONF_RSP,
2548
				l2cap_build_conf_rsp(chan, rsp,
2549
					L2CAP_CONF_SUCCESS, 0x0001), rsp);
L
Linus Torvalds 已提交
2550 2551 2552 2553
		goto unlock;
	}

	/* Complete config. */
2554
	len = l2cap_parse_conf_req(chan, rsp);
2555
	if (len < 0) {
2556
		l2cap_send_disconn_req(conn, chan, ECONNRESET);
L
Linus Torvalds 已提交
2557
		goto unlock;
2558
	}
L
Linus Torvalds 已提交
2559

2560
	l2cap_send_cmd(conn, cmd->ident, L2CAP_CONF_RSP, len, rsp);
2561
	chan->num_conf_rsp++;
2562 2563

	/* Reset config buffer. */
2564
	chan->conf_len = 0;
2565

2566
	if (!(chan->conf_state & L2CAP_CONF_OUTPUT_DONE))
2567 2568
		goto unlock;

2569
	if (chan->conf_state & L2CAP_CONF_INPUT_DONE) {
2570
		set_default_fcs(chan);
2571

L
Linus Torvalds 已提交
2572
		sk->sk_state = BT_CONNECTED;
2573

2574 2575
		chan->next_tx_seq = 0;
		chan->expected_tx_seq = 0;
2576
		skb_queue_head_init(&chan->tx_q);
2577
		if (chan->mode == L2CAP_MODE_ERTM)
2578
			l2cap_ertm_init(chan);
2579

L
Linus Torvalds 已提交
2580
		l2cap_chan_ready(sk);
2581 2582 2583
		goto unlock;
	}

2584
	if (!(chan->conf_state & L2CAP_CONF_REQ_SENT)) {
2585
		u8 buf[64];
2586
		chan->conf_state |= L2CAP_CONF_REQ_SENT;
L
Linus Torvalds 已提交
2587
		l2cap_send_cmd(conn, l2cap_get_ident(conn), L2CAP_CONF_REQ,
2588 2589
					l2cap_build_conf_req(chan, buf), buf);
		chan->num_conf_req++;
L
Linus Torvalds 已提交
2590 2591 2592 2593 2594 2595 2596 2597 2598 2599 2600
	}

unlock:
	bh_unlock_sock(sk);
	return 0;
}

static inline int l2cap_config_rsp(struct l2cap_conn *conn, struct l2cap_cmd_hdr *cmd, u8 *data)
{
	struct l2cap_conf_rsp *rsp = (struct l2cap_conf_rsp *)data;
	u16 scid, flags, result;
2601
	struct l2cap_chan *chan;
L
Linus Torvalds 已提交
2602
	struct sock *sk;
2603
	int len = cmd->len - sizeof(*rsp);
L
Linus Torvalds 已提交
2604 2605 2606 2607 2608

	scid   = __le16_to_cpu(rsp->scid);
	flags  = __le16_to_cpu(rsp->flags);
	result = __le16_to_cpu(rsp->result);

2609 2610
	BT_DBG("scid 0x%4.4x flags 0x%2.2x result 0x%2.2x",
			scid, flags, result);
L
Linus Torvalds 已提交
2611

2612
	chan = l2cap_get_chan_by_scid(conn, scid);
2613
	if (!chan)
L
Linus Torvalds 已提交
2614 2615
		return 0;

2616 2617
	sk = chan->sk;

L
Linus Torvalds 已提交
2618 2619
	switch (result) {
	case L2CAP_CONF_SUCCESS:
2620
		l2cap_conf_rfc_get(chan, rsp->data, len);
L
Linus Torvalds 已提交
2621 2622 2623
		break;

	case L2CAP_CONF_UNACCEPT:
2624
		if (chan->num_conf_rsp <= L2CAP_CONF_MAX_CONF_RSP) {
2625 2626
			char req[64];

2627
			if (len > sizeof(req) - sizeof(struct l2cap_conf_req)) {
2628
				l2cap_send_disconn_req(conn, chan, ECONNRESET);
2629 2630 2631
				goto done;
			}

2632 2633
			/* throw out any old stored conf requests */
			result = L2CAP_CONF_SUCCESS;
2634 2635
			len = l2cap_parse_conf_rsp(chan, rsp->data, len,
								req, &result);
2636
			if (len < 0) {
2637
				l2cap_send_disconn_req(conn, chan, ECONNRESET);
2638 2639 2640 2641 2642
				goto done;
			}

			l2cap_send_cmd(conn, l2cap_get_ident(conn),
						L2CAP_CONF_REQ, len, req);
2643
			chan->num_conf_req++;
2644 2645 2646
			if (result != L2CAP_CONF_SUCCESS)
				goto done;
			break;
L
Linus Torvalds 已提交
2647 2648
		}

2649
	default:
2650
		sk->sk_err = ECONNRESET;
2651
		l2cap_chan_set_timer(chan, HZ * 5);
2652
		l2cap_send_disconn_req(conn, chan, ECONNRESET);
L
Linus Torvalds 已提交
2653 2654 2655 2656 2657 2658
		goto done;
	}

	if (flags & 0x01)
		goto done;

2659
	chan->conf_state |= L2CAP_CONF_INPUT_DONE;
L
Linus Torvalds 已提交
2660

2661
	if (chan->conf_state & L2CAP_CONF_OUTPUT_DONE) {
2662
		set_default_fcs(chan);
2663

L
Linus Torvalds 已提交
2664
		sk->sk_state = BT_CONNECTED;
2665 2666
		chan->next_tx_seq = 0;
		chan->expected_tx_seq = 0;
2667
		skb_queue_head_init(&chan->tx_q);
2668
		if (chan->mode ==  L2CAP_MODE_ERTM)
2669
			l2cap_ertm_init(chan);
2670

L
Linus Torvalds 已提交
2671 2672 2673 2674 2675 2676 2677 2678 2679 2680 2681 2682 2683
		l2cap_chan_ready(sk);
	}

done:
	bh_unlock_sock(sk);
	return 0;
}

static inline int l2cap_disconnect_req(struct l2cap_conn *conn, struct l2cap_cmd_hdr *cmd, u8 *data)
{
	struct l2cap_disconn_req *req = (struct l2cap_disconn_req *) data;
	struct l2cap_disconn_rsp rsp;
	u16 dcid, scid;
2684
	struct l2cap_chan *chan;
L
Linus Torvalds 已提交
2685 2686 2687 2688 2689 2690 2691
	struct sock *sk;

	scid = __le16_to_cpu(req->scid);
	dcid = __le16_to_cpu(req->dcid);

	BT_DBG("scid 0x%4.4x dcid 0x%4.4x", scid, dcid);

2692
	chan = l2cap_get_chan_by_scid(conn, dcid);
2693
	if (!chan)
L
Linus Torvalds 已提交
2694 2695
		return 0;

2696 2697
	sk = chan->sk;

2698 2699
	rsp.dcid = cpu_to_le16(chan->scid);
	rsp.scid = cpu_to_le16(chan->dcid);
L
Linus Torvalds 已提交
2700 2701 2702 2703
	l2cap_send_cmd(conn, cmd->ident, L2CAP_DISCONN_RSP, sizeof(rsp), &rsp);

	sk->sk_shutdown = SHUTDOWN_MASK;

2704 2705 2706
	/* don't delete l2cap channel if sk is owned by user */
	if (sock_owned_by_user(sk)) {
		sk->sk_state = BT_DISCONN;
2707 2708
		l2cap_chan_clear_timer(chan);
		l2cap_chan_set_timer(chan, HZ / 5);
2709 2710 2711 2712
		bh_unlock_sock(sk);
		return 0;
	}

2713
	l2cap_chan_del(chan, ECONNRESET);
L
Linus Torvalds 已提交
2714 2715
	bh_unlock_sock(sk);

2716
	chan->ops->close(chan->data);
L
Linus Torvalds 已提交
2717 2718 2719 2720 2721 2722 2723
	return 0;
}

static inline int l2cap_disconnect_rsp(struct l2cap_conn *conn, struct l2cap_cmd_hdr *cmd, u8 *data)
{
	struct l2cap_disconn_rsp *rsp = (struct l2cap_disconn_rsp *) data;
	u16 dcid, scid;
2724
	struct l2cap_chan *chan;
L
Linus Torvalds 已提交
2725 2726 2727 2728 2729 2730 2731
	struct sock *sk;

	scid = __le16_to_cpu(rsp->scid);
	dcid = __le16_to_cpu(rsp->dcid);

	BT_DBG("dcid 0x%4.4x scid 0x%4.4x", dcid, scid);

2732
	chan = l2cap_get_chan_by_scid(conn, scid);
2733
	if (!chan)
L
Linus Torvalds 已提交
2734 2735
		return 0;

2736 2737
	sk = chan->sk;

2738 2739 2740
	/* don't delete l2cap channel if sk is owned by user */
	if (sock_owned_by_user(sk)) {
		sk->sk_state = BT_DISCONN;
2741 2742
		l2cap_chan_clear_timer(chan);
		l2cap_chan_set_timer(chan, HZ / 5);
2743 2744 2745 2746
		bh_unlock_sock(sk);
		return 0;
	}

2747
	l2cap_chan_del(chan, 0);
L
Linus Torvalds 已提交
2748 2749
	bh_unlock_sock(sk);

2750
	chan->ops->close(chan->data);
L
Linus Torvalds 已提交
2751 2752 2753 2754 2755 2756 2757 2758 2759 2760 2761 2762
	return 0;
}

static inline int l2cap_information_req(struct l2cap_conn *conn, struct l2cap_cmd_hdr *cmd, u8 *data)
{
	struct l2cap_info_req *req = (struct l2cap_info_req *) data;
	u16 type;

	type = __le16_to_cpu(req->type);

	BT_DBG("type 0x%4.4x", type);

2763 2764
	if (type == L2CAP_IT_FEAT_MASK) {
		u8 buf[8];
2765
		u32 feat_mask = l2cap_feat_mask;
2766 2767 2768
		struct l2cap_info_rsp *rsp = (struct l2cap_info_rsp *) buf;
		rsp->type   = cpu_to_le16(L2CAP_IT_FEAT_MASK);
		rsp->result = cpu_to_le16(L2CAP_IR_SUCCESS);
2769
		if (!disable_ertm)
2770 2771
			feat_mask |= L2CAP_FEAT_ERTM | L2CAP_FEAT_STREAMING
							 | L2CAP_FEAT_FCS;
2772
		put_unaligned_le32(feat_mask, rsp->data);
2773 2774
		l2cap_send_cmd(conn, cmd->ident,
					L2CAP_INFO_RSP, sizeof(buf), buf);
2775 2776 2777 2778 2779 2780 2781 2782
	} else if (type == L2CAP_IT_FIXED_CHAN) {
		u8 buf[12];
		struct l2cap_info_rsp *rsp = (struct l2cap_info_rsp *) buf;
		rsp->type   = cpu_to_le16(L2CAP_IT_FIXED_CHAN);
		rsp->result = cpu_to_le16(L2CAP_IR_SUCCESS);
		memcpy(buf + 4, l2cap_fixed_chan, 8);
		l2cap_send_cmd(conn, cmd->ident,
					L2CAP_INFO_RSP, sizeof(buf), buf);
2783 2784 2785 2786 2787 2788 2789
	} else {
		struct l2cap_info_rsp rsp;
		rsp.type   = cpu_to_le16(type);
		rsp.result = cpu_to_le16(L2CAP_IR_NOTSUPP);
		l2cap_send_cmd(conn, cmd->ident,
					L2CAP_INFO_RSP, sizeof(rsp), &rsp);
	}
L
Linus Torvalds 已提交
2790 2791 2792 2793 2794 2795 2796 2797 2798 2799 2800 2801 2802 2803

	return 0;
}

static inline int l2cap_information_rsp(struct l2cap_conn *conn, struct l2cap_cmd_hdr *cmd, u8 *data)
{
	struct l2cap_info_rsp *rsp = (struct l2cap_info_rsp *) data;
	u16 type, result;

	type   = __le16_to_cpu(rsp->type);
	result = __le16_to_cpu(rsp->result);

	BT_DBG("type 0x%4.4x result 0x%2.2x", type, result);

2804 2805 2806 2807 2808
	/* L2CAP Info req/rsp are unbound to channels, add extra checks */
	if (cmd->ident != conn->info_ident ||
			conn->info_state & L2CAP_INFO_FEAT_MASK_REQ_DONE)
		return 0;

2809 2810
	del_timer(&conn->info_timer);

2811 2812 2813 2814 2815 2816 2817 2818 2819
	if (result != L2CAP_IR_SUCCESS) {
		conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_DONE;
		conn->info_ident = 0;

		l2cap_conn_start(conn);

		return 0;
	}

2820
	if (type == L2CAP_IT_FEAT_MASK) {
2821
		conn->feat_mask = get_unaligned_le32(rsp->data);
2822

2823
		if (conn->feat_mask & L2CAP_FEAT_FIXED_CHAN) {
2824 2825 2826 2827 2828 2829 2830 2831 2832 2833 2834 2835 2836 2837
			struct l2cap_info_req req;
			req.type = cpu_to_le16(L2CAP_IT_FIXED_CHAN);

			conn->info_ident = l2cap_get_ident(conn);

			l2cap_send_cmd(conn, conn->info_ident,
					L2CAP_INFO_REQ, sizeof(req), &req);
		} else {
			conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_DONE;
			conn->info_ident = 0;

			l2cap_conn_start(conn);
		}
	} else if (type == L2CAP_IT_FIXED_CHAN) {
2838
		conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_DONE;
2839
		conn->info_ident = 0;
2840 2841 2842

		l2cap_conn_start(conn);
	}
2843

L
Linus Torvalds 已提交
2844 2845 2846
	return 0;
}

2847
static inline int l2cap_check_conn_param(u16 min, u16 max, u16 latency,
2848 2849 2850 2851 2852 2853 2854 2855 2856 2857 2858 2859 2860 2861 2862 2863 2864 2865 2866 2867 2868 2869 2870 2871 2872 2873 2874
							u16 to_multiplier)
{
	u16 max_latency;

	if (min > max || min < 6 || max > 3200)
		return -EINVAL;

	if (to_multiplier < 10 || to_multiplier > 3200)
		return -EINVAL;

	if (max >= to_multiplier * 8)
		return -EINVAL;

	max_latency = (to_multiplier * 8 / max) - 1;
	if (latency > 499 || latency > max_latency)
		return -EINVAL;

	return 0;
}

static inline int l2cap_conn_param_update_req(struct l2cap_conn *conn,
					struct l2cap_cmd_hdr *cmd, u8 *data)
{
	struct hci_conn *hcon = conn->hcon;
	struct l2cap_conn_param_update_req *req;
	struct l2cap_conn_param_update_rsp rsp;
	u16 min, max, latency, to_multiplier, cmd_len;
2875
	int err;
2876 2877 2878 2879 2880 2881 2882 2883 2884

	if (!(hcon->link_mode & HCI_LM_MASTER))
		return -EINVAL;

	cmd_len = __le16_to_cpu(cmd->len);
	if (cmd_len != sizeof(struct l2cap_conn_param_update_req))
		return -EPROTO;

	req = (struct l2cap_conn_param_update_req *) data;
2885 2886
	min		= __le16_to_cpu(req->min);
	max		= __le16_to_cpu(req->max);
2887 2888 2889 2890 2891 2892 2893
	latency		= __le16_to_cpu(req->latency);
	to_multiplier	= __le16_to_cpu(req->to_multiplier);

	BT_DBG("min 0x%4.4x max 0x%4.4x latency: 0x%4.4x Timeout: 0x%4.4x",
						min, max, latency, to_multiplier);

	memset(&rsp, 0, sizeof(rsp));
2894 2895 2896

	err = l2cap_check_conn_param(min, max, latency, to_multiplier);
	if (err)
2897 2898 2899 2900 2901 2902 2903
		rsp.result = cpu_to_le16(L2CAP_CONN_PARAM_REJECTED);
	else
		rsp.result = cpu_to_le16(L2CAP_CONN_PARAM_ACCEPTED);

	l2cap_send_cmd(conn, cmd->ident, L2CAP_CONN_PARAM_UPDATE_RSP,
							sizeof(rsp), &rsp);

2904 2905 2906
	if (!err)
		hci_le_conn_update(hcon, min, max, latency, to_multiplier);

2907 2908 2909
	return 0;
}

2910 2911 2912 2913 2914 2915 2916 2917 2918 2919 2920 2921 2922 2923 2924 2925 2926 2927 2928 2929 2930 2931 2932 2933 2934 2935 2936 2937 2938 2939 2940 2941 2942 2943 2944 2945 2946 2947 2948 2949 2950 2951 2952 2953 2954 2955 2956 2957 2958 2959 2960 2961 2962 2963 2964 2965 2966 2967 2968 2969 2970 2971 2972 2973 2974 2975
static inline int l2cap_bredr_sig_cmd(struct l2cap_conn *conn,
			struct l2cap_cmd_hdr *cmd, u16 cmd_len, u8 *data)
{
	int err = 0;

	switch (cmd->code) {
	case L2CAP_COMMAND_REJ:
		l2cap_command_rej(conn, cmd, data);
		break;

	case L2CAP_CONN_REQ:
		err = l2cap_connect_req(conn, cmd, data);
		break;

	case L2CAP_CONN_RSP:
		err = l2cap_connect_rsp(conn, cmd, data);
		break;

	case L2CAP_CONF_REQ:
		err = l2cap_config_req(conn, cmd, cmd_len, data);
		break;

	case L2CAP_CONF_RSP:
		err = l2cap_config_rsp(conn, cmd, data);
		break;

	case L2CAP_DISCONN_REQ:
		err = l2cap_disconnect_req(conn, cmd, data);
		break;

	case L2CAP_DISCONN_RSP:
		err = l2cap_disconnect_rsp(conn, cmd, data);
		break;

	case L2CAP_ECHO_REQ:
		l2cap_send_cmd(conn, cmd->ident, L2CAP_ECHO_RSP, cmd_len, data);
		break;

	case L2CAP_ECHO_RSP:
		break;

	case L2CAP_INFO_REQ:
		err = l2cap_information_req(conn, cmd, data);
		break;

	case L2CAP_INFO_RSP:
		err = l2cap_information_rsp(conn, cmd, data);
		break;

	default:
		BT_ERR("Unknown BR/EDR signaling command 0x%2.2x", cmd->code);
		err = -EINVAL;
		break;
	}

	return err;
}

static inline int l2cap_le_sig_cmd(struct l2cap_conn *conn,
					struct l2cap_cmd_hdr *cmd, u8 *data)
{
	switch (cmd->code) {
	case L2CAP_COMMAND_REJ:
		return 0;

	case L2CAP_CONN_PARAM_UPDATE_REQ:
2976
		return l2cap_conn_param_update_req(conn, cmd, data);
2977 2978 2979 2980 2981 2982 2983 2984 2985 2986 2987 2988

	case L2CAP_CONN_PARAM_UPDATE_RSP:
		return 0;

	default:
		BT_ERR("Unknown LE signaling command 0x%2.2x", cmd->code);
		return -EINVAL;
	}
}

static inline void l2cap_sig_channel(struct l2cap_conn *conn,
							struct sk_buff *skb)
L
Linus Torvalds 已提交
2989 2990 2991 2992
{
	u8 *data = skb->data;
	int len = skb->len;
	struct l2cap_cmd_hdr cmd;
2993
	int err;
L
Linus Torvalds 已提交
2994 2995 2996 2997

	l2cap_raw_recv(conn, skb);

	while (len >= L2CAP_CMD_HDR_SIZE) {
2998
		u16 cmd_len;
L
Linus Torvalds 已提交
2999 3000 3001 3002
		memcpy(&cmd, data, L2CAP_CMD_HDR_SIZE);
		data += L2CAP_CMD_HDR_SIZE;
		len  -= L2CAP_CMD_HDR_SIZE;

3003
		cmd_len = le16_to_cpu(cmd.len);
L
Linus Torvalds 已提交
3004

3005
		BT_DBG("code 0x%2.2x len %d id 0x%2.2x", cmd.code, cmd_len, cmd.ident);
L
Linus Torvalds 已提交
3006

3007
		if (cmd_len > len || !cmd.ident) {
L
Linus Torvalds 已提交
3008 3009 3010 3011
			BT_DBG("corrupted command");
			break;
		}

3012 3013 3014 3015
		if (conn->hcon->type == LE_LINK)
			err = l2cap_le_sig_cmd(conn, &cmd, data);
		else
			err = l2cap_bredr_sig_cmd(conn, &cmd, cmd_len, data);
L
Linus Torvalds 已提交
3016 3017 3018

		if (err) {
			struct l2cap_cmd_rej rej;
3019 3020

			BT_ERR("Wrong link type (%d)", err);
L
Linus Torvalds 已提交
3021 3022

			/* FIXME: Map err to a valid reason */
3023
			rej.reason = cpu_to_le16(0);
L
Linus Torvalds 已提交
3024 3025 3026
			l2cap_send_cmd(conn, cmd.ident, L2CAP_COMMAND_REJ, sizeof(rej), &rej);
		}

3027 3028
		data += cmd_len;
		len  -= cmd_len;
L
Linus Torvalds 已提交
3029 3030 3031 3032 3033
	}

	kfree_skb(skb);
}

3034
static int l2cap_check_fcs(struct l2cap_chan *chan,  struct sk_buff *skb)
3035 3036 3037 3038
{
	u16 our_fcs, rcv_fcs;
	int hdr_size = L2CAP_HDR_SIZE + 2;

3039
	if (chan->fcs == L2CAP_FCS_CRC16) {
3040 3041 3042 3043 3044
		skb_trim(skb, skb->len - 2);
		rcv_fcs = get_unaligned_le16(skb->data + skb->len);
		our_fcs = crc16(0, skb->data - hdr_size, skb->len + hdr_size);

		if (our_fcs != rcv_fcs)
3045
			return -EBADMSG;
3046 3047 3048 3049
	}
	return 0;
}

3050
static inline void l2cap_send_i_or_rr_or_rnr(struct l2cap_chan *chan)
3051 3052 3053
{
	u16 control = 0;

3054
	chan->frames_sent = 0;
3055

3056
	control |= chan->buffer_seq << L2CAP_CTRL_REQSEQ_SHIFT;
3057

3058
	if (chan->conn_state & L2CAP_CONN_LOCAL_BUSY) {
3059
		control |= L2CAP_SUPER_RCV_NOT_READY;
3060 3061
		l2cap_send_sframe(chan, control);
		chan->conn_state |= L2CAP_CONN_RNR_SENT;
3062 3063
	}

3064 3065
	if (chan->conn_state & L2CAP_CONN_REMOTE_BUSY)
		l2cap_retransmit_frames(chan);
3066

3067
	l2cap_ertm_send(chan);
3068

3069
	if (!(chan->conn_state & L2CAP_CONN_LOCAL_BUSY) &&
3070
			chan->frames_sent == 0) {
3071
		control |= L2CAP_SUPER_RCV_READY;
3072
		l2cap_send_sframe(chan, control);
3073 3074 3075
	}
}

3076
static int l2cap_add_to_srej_queue(struct l2cap_chan *chan, struct sk_buff *skb, u8 tx_seq, u8 sar)
3077 3078
{
	struct sk_buff *next_skb;
3079
	int tx_seq_offset, next_tx_seq_offset;
3080 3081 3082 3083

	bt_cb(skb)->tx_seq = tx_seq;
	bt_cb(skb)->sar = sar;

3084
	next_skb = skb_peek(&chan->srej_q);
3085
	if (!next_skb) {
3086
		__skb_queue_tail(&chan->srej_q, skb);
3087
		return 0;
3088 3089
	}

3090
	tx_seq_offset = (tx_seq - chan->buffer_seq) % 64;
3091 3092 3093
	if (tx_seq_offset < 0)
		tx_seq_offset += 64;

3094
	do {
3095 3096 3097
		if (bt_cb(next_skb)->tx_seq == tx_seq)
			return -EINVAL;

3098
		next_tx_seq_offset = (bt_cb(next_skb)->tx_seq -
3099
						chan->buffer_seq) % 64;
3100 3101 3102 3103
		if (next_tx_seq_offset < 0)
			next_tx_seq_offset += 64;

		if (next_tx_seq_offset > tx_seq_offset) {
3104
			__skb_queue_before(&chan->srej_q, next_skb, skb);
3105
			return 0;
3106 3107
		}

3108
		if (skb_queue_is_last(&chan->srej_q, next_skb))
3109 3110
			break;

3111
	} while ((next_skb = skb_queue_next(&chan->srej_q, next_skb)));
3112

3113
	__skb_queue_tail(&chan->srej_q, skb);
3114 3115

	return 0;
3116 3117
}

3118
static int l2cap_ertm_reassembly_sdu(struct l2cap_chan *chan, struct sk_buff *skb, u16 control)
3119 3120
{
	struct sk_buff *_skb;
3121
	int err;
3122 3123 3124

	switch (control & L2CAP_CTRL_SAR) {
	case L2CAP_SDU_UNSEGMENTED:
3125
		if (chan->conn_state & L2CAP_CONN_SAR_SDU)
3126 3127
			goto drop;

3128
		return chan->ops->recv(chan->data, skb);
3129 3130

	case L2CAP_SDU_START:
3131
		if (chan->conn_state & L2CAP_CONN_SAR_SDU)
3132 3133
			goto drop;

3134
		chan->sdu_len = get_unaligned_le16(skb->data);
3135

3136
		if (chan->sdu_len > chan->imtu)
3137 3138
			goto disconnect;

3139 3140
		chan->sdu = bt_skb_alloc(chan->sdu_len, GFP_ATOMIC);
		if (!chan->sdu)
3141 3142 3143 3144 3145 3146
			return -ENOMEM;

		/* pull sdu_len bytes only after alloc, because of Local Busy
		 * condition we have to be sure that this will be executed
		 * only once, i.e., when alloc does not fail */
		skb_pull(skb, 2);
3147

3148
		memcpy(skb_put(chan->sdu, skb->len), skb->data, skb->len);
3149

3150
		chan->conn_state |= L2CAP_CONN_SAR_SDU;
3151
		chan->partial_sdu_len = skb->len;
3152 3153 3154
		break;

	case L2CAP_SDU_CONTINUE:
3155
		if (!(chan->conn_state & L2CAP_CONN_SAR_SDU))
3156 3157
			goto disconnect;

3158
		if (!chan->sdu)
3159 3160
			goto disconnect;

3161 3162
		chan->partial_sdu_len += skb->len;
		if (chan->partial_sdu_len > chan->sdu_len)
3163 3164
			goto drop;

3165
		memcpy(skb_put(chan->sdu, skb->len), skb->data, skb->len);
3166

3167 3168 3169
		break;

	case L2CAP_SDU_END:
3170
		if (!(chan->conn_state & L2CAP_CONN_SAR_SDU))
3171 3172
			goto disconnect;

3173
		if (!chan->sdu)
3174 3175
			goto disconnect;

3176
		if (!(chan->conn_state & L2CAP_CONN_SAR_RETRY)) {
3177
			chan->partial_sdu_len += skb->len;
3178

3179
			if (chan->partial_sdu_len > chan->imtu)
3180
				goto drop;
3181

3182
			if (chan->partial_sdu_len != chan->sdu_len)
3183
				goto drop;
3184

3185
			memcpy(skb_put(chan->sdu, skb->len), skb->data, skb->len);
3186
		}
3187

3188
		_skb = skb_clone(chan->sdu, GFP_ATOMIC);
3189
		if (!_skb) {
3190
			chan->conn_state |= L2CAP_CONN_SAR_RETRY;
3191 3192 3193
			return -ENOMEM;
		}

3194
		err = chan->ops->recv(chan->data, _skb);
3195
		if (err < 0) {
3196
			kfree_skb(_skb);
3197
			chan->conn_state |= L2CAP_CONN_SAR_RETRY;
3198 3199 3200
			return err;
		}

3201 3202
		chan->conn_state &= ~L2CAP_CONN_SAR_RETRY;
		chan->conn_state &= ~L2CAP_CONN_SAR_SDU;
3203

3204
		kfree_skb(chan->sdu);
3205 3206 3207 3208
		break;
	}

	kfree_skb(skb);
3209
	return 0;
3210 3211

drop:
3212 3213
	kfree_skb(chan->sdu);
	chan->sdu = NULL;
3214 3215

disconnect:
3216
	l2cap_send_disconn_req(chan->conn, chan, ECONNRESET);
3217 3218 3219 3220
	kfree_skb(skb);
	return 0;
}

3221
static int l2cap_try_push_rx_skb(struct l2cap_chan *chan)
3222 3223 3224 3225 3226
{
	struct sk_buff *skb;
	u16 control;
	int err;

3227
	while ((skb = skb_dequeue(&chan->busy_q))) {
3228
		control = bt_cb(skb)->sar << L2CAP_CTRL_SAR_SHIFT;
3229
		err = l2cap_ertm_reassembly_sdu(chan, skb, control);
3230
		if (err < 0) {
3231
			skb_queue_head(&chan->busy_q, skb);
3232 3233 3234
			return -EBUSY;
		}

3235
		chan->buffer_seq = (chan->buffer_seq + 1) % 64;
3236 3237
	}

3238
	if (!(chan->conn_state & L2CAP_CONN_RNR_SENT))
3239 3240
		goto done;

3241
	control = chan->buffer_seq << L2CAP_CTRL_REQSEQ_SHIFT;
3242
	control |= L2CAP_SUPER_RCV_READY | L2CAP_CTRL_POLL;
3243
	l2cap_send_sframe(chan, control);
3244
	chan->retry_count = 1;
3245

3246
	del_timer(&chan->retrans_timer);
3247 3248
	__mod_monitor_timer();

3249
	chan->conn_state |= L2CAP_CONN_WAIT_F;
3250 3251

done:
3252 3253
	chan->conn_state &= ~L2CAP_CONN_LOCAL_BUSY;
	chan->conn_state &= ~L2CAP_CONN_RNR_SENT;
3254

3255
	BT_DBG("chan %p, Exit local busy", chan);
3256 3257 3258 3259

	return 0;
}

3260 3261 3262
static void l2cap_busy_work(struct work_struct *work)
{
	DECLARE_WAITQUEUE(wait, current);
3263 3264 3265
	struct l2cap_chan *chan =
		container_of(work, struct l2cap_chan, busy_work);
	struct sock *sk = chan->sk;
3266 3267 3268 3269 3270
	int n_tries = 0, timeo = HZ/5, err;
	struct sk_buff *skb;

	lock_sock(sk);

3271
	add_wait_queue(sk_sleep(sk), &wait);
3272
	while ((skb = skb_peek(&chan->busy_q))) {
3273 3274 3275 3276
		set_current_state(TASK_INTERRUPTIBLE);

		if (n_tries++ > L2CAP_LOCAL_BUSY_TRIES) {
			err = -EBUSY;
3277
			l2cap_send_disconn_req(chan->conn, chan, EBUSY);
3278
			break;
3279 3280 3281 3282 3283 3284 3285
		}

		if (!timeo)
			timeo = HZ/5;

		if (signal_pending(current)) {
			err = sock_intr_errno(timeo);
3286
			break;
3287 3288 3289 3290 3291 3292 3293 3294
		}

		release_sock(sk);
		timeo = schedule_timeout(timeo);
		lock_sock(sk);

		err = sock_error(sk);
		if (err)
3295
			break;
3296

3297
		if (l2cap_try_push_rx_skb(chan) == 0)
3298 3299 3300 3301
			break;
	}

	set_current_state(TASK_RUNNING);
3302
	remove_wait_queue(sk_sleep(sk), &wait);
3303 3304 3305 3306

	release_sock(sk);
}

3307
static int l2cap_push_rx_skb(struct l2cap_chan *chan, struct sk_buff *skb, u16 control)
3308 3309 3310
{
	int sctrl, err;

3311
	if (chan->conn_state & L2CAP_CONN_LOCAL_BUSY) {
3312
		bt_cb(skb)->sar = control >> L2CAP_CTRL_SAR_SHIFT;
3313
		__skb_queue_tail(&chan->busy_q, skb);
3314
		return l2cap_try_push_rx_skb(chan);
3315 3316


3317 3318
	}

3319
	err = l2cap_ertm_reassembly_sdu(chan, skb, control);
3320
	if (err >= 0) {
3321
		chan->buffer_seq = (chan->buffer_seq + 1) % 64;
3322 3323 3324 3325
		return err;
	}

	/* Busy Condition */
3326
	BT_DBG("chan %p, Enter local busy", chan);
3327

3328
	chan->conn_state |= L2CAP_CONN_LOCAL_BUSY;
3329
	bt_cb(skb)->sar = control >> L2CAP_CTRL_SAR_SHIFT;
3330
	__skb_queue_tail(&chan->busy_q, skb);
3331

3332
	sctrl = chan->buffer_seq << L2CAP_CTRL_REQSEQ_SHIFT;
3333
	sctrl |= L2CAP_SUPER_RCV_NOT_READY;
3334
	l2cap_send_sframe(chan, sctrl);
3335

3336
	chan->conn_state |= L2CAP_CONN_RNR_SENT;
3337

3338
	del_timer(&chan->ack_timer);
3339

3340
	queue_work(_busy_wq, &chan->busy_work);
3341 3342 3343 3344

	return err;
}

3345
static int l2cap_streaming_reassembly_sdu(struct l2cap_chan *chan, struct sk_buff *skb, u16 control)
3346 3347 3348 3349
{
	struct sk_buff *_skb;
	int err = -EINVAL;

3350 3351 3352 3353 3354
	/*
	 * TODO: We have to notify the userland if some data is lost with the
	 * Streaming Mode.
	 */

3355 3356
	switch (control & L2CAP_CTRL_SAR) {
	case L2CAP_SDU_UNSEGMENTED:
3357
		if (chan->conn_state & L2CAP_CONN_SAR_SDU) {
3358
			kfree_skb(chan->sdu);
3359 3360 3361
			break;
		}

3362
		err = chan->ops->recv(chan->data, skb);
3363 3364 3365 3366 3367 3368
		if (!err)
			return 0;

		break;

	case L2CAP_SDU_START:
3369
		if (chan->conn_state & L2CAP_CONN_SAR_SDU) {
3370
			kfree_skb(chan->sdu);
3371 3372 3373
			break;
		}

3374
		chan->sdu_len = get_unaligned_le16(skb->data);
3375 3376
		skb_pull(skb, 2);

3377
		if (chan->sdu_len > chan->imtu) {
3378 3379 3380 3381
			err = -EMSGSIZE;
			break;
		}

3382 3383
		chan->sdu = bt_skb_alloc(chan->sdu_len, GFP_ATOMIC);
		if (!chan->sdu) {
3384 3385 3386 3387
			err = -ENOMEM;
			break;
		}

3388
		memcpy(skb_put(chan->sdu, skb->len), skb->data, skb->len);
3389

3390
		chan->conn_state |= L2CAP_CONN_SAR_SDU;
3391
		chan->partial_sdu_len = skb->len;
3392 3393 3394 3395
		err = 0;
		break;

	case L2CAP_SDU_CONTINUE:
3396
		if (!(chan->conn_state & L2CAP_CONN_SAR_SDU))
3397 3398
			break;

3399
		memcpy(skb_put(chan->sdu, skb->len), skb->data, skb->len);
3400

3401 3402 3403
		chan->partial_sdu_len += skb->len;
		if (chan->partial_sdu_len > chan->sdu_len)
			kfree_skb(chan->sdu);
3404 3405 3406 3407 3408 3409
		else
			err = 0;

		break;

	case L2CAP_SDU_END:
3410
		if (!(chan->conn_state & L2CAP_CONN_SAR_SDU))
3411 3412
			break;

3413
		memcpy(skb_put(chan->sdu, skb->len), skb->data, skb->len);
3414

3415
		chan->conn_state &= ~L2CAP_CONN_SAR_SDU;
3416
		chan->partial_sdu_len += skb->len;
3417

3418
		if (chan->partial_sdu_len > chan->imtu)
3419 3420
			goto drop;

3421 3422
		if (chan->partial_sdu_len == chan->sdu_len) {
			_skb = skb_clone(chan->sdu, GFP_ATOMIC);
3423
			err = chan->ops->recv(chan->data, _skb);
3424 3425 3426 3427 3428
			if (err < 0)
				kfree_skb(_skb);
		}
		err = 0;

3429
drop:
3430
		kfree_skb(chan->sdu);
3431 3432 3433 3434 3435 3436 3437
		break;
	}

	kfree_skb(skb);
	return err;
}

3438
static void l2cap_check_srej_gap(struct l2cap_chan *chan, u8 tx_seq)
3439 3440
{
	struct sk_buff *skb;
3441
	u16 control;
3442

3443
	while ((skb = skb_peek(&chan->srej_q))) {
3444 3445 3446
		if (bt_cb(skb)->tx_seq != tx_seq)
			break;

3447
		skb = skb_dequeue(&chan->srej_q);
3448
		control = bt_cb(skb)->sar << L2CAP_CTRL_SAR_SHIFT;
3449
		l2cap_ertm_reassembly_sdu(chan, skb, control);
3450 3451
		chan->buffer_seq_srej =
			(chan->buffer_seq_srej + 1) % 64;
3452
		tx_seq = (tx_seq + 1) % 64;
3453 3454 3455
	}
}

3456
static void l2cap_resend_srejframe(struct l2cap_chan *chan, u8 tx_seq)
3457 3458 3459 3460
{
	struct srej_list *l, *tmp;
	u16 control;

3461
	list_for_each_entry_safe(l, tmp, &chan->srej_l, list) {
3462 3463 3464 3465 3466 3467 3468
		if (l->tx_seq == tx_seq) {
			list_del(&l->list);
			kfree(l);
			return;
		}
		control = L2CAP_SUPER_SELECT_REJECT;
		control |= l->tx_seq << L2CAP_CTRL_REQSEQ_SHIFT;
3469
		l2cap_send_sframe(chan, control);
3470
		list_del(&l->list);
3471
		list_add_tail(&l->list, &chan->srej_l);
3472 3473 3474
	}
}

3475
static void l2cap_send_srejframe(struct l2cap_chan *chan, u8 tx_seq)
3476 3477 3478 3479
{
	struct srej_list *new;
	u16 control;

3480
	while (tx_seq != chan->expected_tx_seq) {
3481
		control = L2CAP_SUPER_SELECT_REJECT;
3482
		control |= chan->expected_tx_seq << L2CAP_CTRL_REQSEQ_SHIFT;
3483
		l2cap_send_sframe(chan, control);
3484 3485

		new = kzalloc(sizeof(struct srej_list), GFP_ATOMIC);
3486 3487
		new->tx_seq = chan->expected_tx_seq;
		chan->expected_tx_seq = (chan->expected_tx_seq + 1) % 64;
3488
		list_add_tail(&new->list, &chan->srej_l);
3489
	}
3490
	chan->expected_tx_seq = (chan->expected_tx_seq + 1) % 64;
3491 3492
}

3493
static inline int l2cap_data_channel_iframe(struct l2cap_chan *chan, u16 rx_control, struct sk_buff *skb)
3494 3495
{
	u8 tx_seq = __get_txseq(rx_control);
3496
	u8 req_seq = __get_reqseq(rx_control);
3497
	u8 sar = rx_control >> L2CAP_CTRL_SAR_SHIFT;
3498
	int tx_seq_offset, expected_tx_seq_offset;
3499
	int num_to_ack = (chan->tx_win/6) + 1;
3500 3501
	int err = 0;

3502 3503
	BT_DBG("chan %p len %d tx_seq %d rx_control 0x%4.4x", chan, skb->len,
							tx_seq, rx_control);
3504

3505
	if (L2CAP_CTRL_FINAL & rx_control &&
3506
			chan->conn_state & L2CAP_CONN_WAIT_F) {
3507
		del_timer(&chan->monitor_timer);
3508
		if (chan->unacked_frames > 0)
3509
			__mod_retrans_timer();
3510
		chan->conn_state &= ~L2CAP_CONN_WAIT_F;
3511 3512
	}

3513 3514
	chan->expected_ack_seq = req_seq;
	l2cap_drop_acked_frames(chan);
3515

3516
	if (tx_seq == chan->expected_tx_seq)
3517
		goto expected;
3518

3519
	tx_seq_offset = (tx_seq - chan->buffer_seq) % 64;
3520 3521 3522 3523
	if (tx_seq_offset < 0)
		tx_seq_offset += 64;

	/* invalid tx_seq */
3524
	if (tx_seq_offset >= chan->tx_win) {
3525
		l2cap_send_disconn_req(chan->conn, chan, ECONNRESET);
3526 3527 3528
		goto drop;
	}

3529
	if (chan->conn_state & L2CAP_CONN_LOCAL_BUSY)
3530 3531
		goto drop;

3532
	if (chan->conn_state & L2CAP_CONN_SREJ_SENT) {
3533
		struct srej_list *first;
3534

3535
		first = list_first_entry(&chan->srej_l,
3536 3537
				struct srej_list, list);
		if (tx_seq == first->tx_seq) {
3538
			l2cap_add_to_srej_queue(chan, skb, tx_seq, sar);
3539
			l2cap_check_srej_gap(chan, tx_seq);
3540 3541 3542 3543

			list_del(&first->list);
			kfree(first);

3544
			if (list_empty(&chan->srej_l)) {
3545
				chan->buffer_seq = chan->buffer_seq_srej;
3546 3547
				chan->conn_state &= ~L2CAP_CONN_SREJ_SENT;
				l2cap_send_ack(chan);
3548
				BT_DBG("chan %p, Exit SREJ_SENT", chan);
3549 3550 3551
			}
		} else {
			struct srej_list *l;
3552 3553

			/* duplicated tx_seq */
3554
			if (l2cap_add_to_srej_queue(chan, skb, tx_seq, sar) < 0)
3555
				goto drop;
3556

3557
			list_for_each_entry(l, &chan->srej_l, list) {
3558
				if (l->tx_seq == tx_seq) {
3559
					l2cap_resend_srejframe(chan, tx_seq);
3560 3561 3562
					return 0;
				}
			}
3563
			l2cap_send_srejframe(chan, tx_seq);
3564 3565
		}
	} else {
3566
		expected_tx_seq_offset =
3567
			(chan->expected_tx_seq - chan->buffer_seq) % 64;
3568 3569 3570 3571 3572 3573 3574
		if (expected_tx_seq_offset < 0)
			expected_tx_seq_offset += 64;

		/* duplicated tx_seq */
		if (tx_seq_offset < expected_tx_seq_offset)
			goto drop;

3575
		chan->conn_state |= L2CAP_CONN_SREJ_SENT;
3576

3577
		BT_DBG("chan %p, Enter SREJ", chan);
3578

3579
		INIT_LIST_HEAD(&chan->srej_l);
3580
		chan->buffer_seq_srej = chan->buffer_seq;
3581

3582 3583
		__skb_queue_head_init(&chan->srej_q);
		__skb_queue_head_init(&chan->busy_q);
3584
		l2cap_add_to_srej_queue(chan, skb, tx_seq, sar);
3585

3586
		chan->conn_state |= L2CAP_CONN_SEND_PBIT;
3587

3588
		l2cap_send_srejframe(chan, tx_seq);
3589

3590
		del_timer(&chan->ack_timer);
3591
	}
3592 3593
	return 0;

3594
expected:
3595
	chan->expected_tx_seq = (chan->expected_tx_seq + 1) % 64;
3596

3597
	if (chan->conn_state & L2CAP_CONN_SREJ_SENT) {
3598 3599
		bt_cb(skb)->tx_seq = tx_seq;
		bt_cb(skb)->sar = sar;
3600
		__skb_queue_tail(&chan->srej_q, skb);
3601 3602 3603
		return 0;
	}

3604
	err = l2cap_push_rx_skb(chan, skb, rx_control);
3605 3606 3607
	if (err < 0)
		return 0;

3608
	if (rx_control & L2CAP_CTRL_FINAL) {
3609 3610
		if (chan->conn_state & L2CAP_CONN_REJ_ACT)
			chan->conn_state &= ~L2CAP_CONN_REJ_ACT;
3611
		else
3612
			l2cap_retransmit_frames(chan);
3613 3614
	}

3615 3616
	__mod_ack_timer();

3617 3618
	chan->num_acked = (chan->num_acked + 1) % num_to_ack;
	if (chan->num_acked == num_to_ack - 1)
3619
		l2cap_send_ack(chan);
3620

3621
	return 0;
3622 3623 3624 3625

drop:
	kfree_skb(skb);
	return 0;
3626 3627
}

3628
static inline void l2cap_data_channel_rrframe(struct l2cap_chan *chan, u16 rx_control)
3629
{
3630
	BT_DBG("chan %p, req_seq %d ctrl 0x%4.4x", chan, __get_reqseq(rx_control),
3631 3632
						rx_control);

3633 3634
	chan->expected_ack_seq = __get_reqseq(rx_control);
	l2cap_drop_acked_frames(chan);
3635

3636
	if (rx_control & L2CAP_CTRL_POLL) {
3637 3638 3639
		chan->conn_state |= L2CAP_CONN_SEND_FBIT;
		if (chan->conn_state & L2CAP_CONN_SREJ_SENT) {
			if ((chan->conn_state & L2CAP_CONN_REMOTE_BUSY) &&
3640
					(chan->unacked_frames > 0))
3641 3642
				__mod_retrans_timer();

3643 3644
			chan->conn_state &= ~L2CAP_CONN_REMOTE_BUSY;
			l2cap_send_srejtail(chan);
3645
		} else {
3646
			l2cap_send_i_or_rr_or_rnr(chan);
3647
		}
3648

3649
	} else if (rx_control & L2CAP_CTRL_FINAL) {
3650
		chan->conn_state &= ~L2CAP_CONN_REMOTE_BUSY;
3651

3652 3653
		if (chan->conn_state & L2CAP_CONN_REJ_ACT)
			chan->conn_state &= ~L2CAP_CONN_REJ_ACT;
3654
		else
3655
			l2cap_retransmit_frames(chan);
3656

3657
	} else {
3658
		if ((chan->conn_state & L2CAP_CONN_REMOTE_BUSY) &&
3659
				(chan->unacked_frames > 0))
3660
			__mod_retrans_timer();
3661

3662 3663 3664
		chan->conn_state &= ~L2CAP_CONN_REMOTE_BUSY;
		if (chan->conn_state & L2CAP_CONN_SREJ_SENT)
			l2cap_send_ack(chan);
3665
		else
3666
			l2cap_ertm_send(chan);
3667 3668
	}
}
3669

3670
static inline void l2cap_data_channel_rejframe(struct l2cap_chan *chan, u16 rx_control)
3671 3672
{
	u8 tx_seq = __get_reqseq(rx_control);
3673

3674
	BT_DBG("chan %p, req_seq %d ctrl 0x%4.4x", chan, tx_seq, rx_control);
3675

3676
	chan->conn_state &= ~L2CAP_CONN_REMOTE_BUSY;
3677

3678 3679
	chan->expected_ack_seq = tx_seq;
	l2cap_drop_acked_frames(chan);
3680 3681

	if (rx_control & L2CAP_CTRL_FINAL) {
3682 3683
		if (chan->conn_state & L2CAP_CONN_REJ_ACT)
			chan->conn_state &= ~L2CAP_CONN_REJ_ACT;
3684
		else
3685
			l2cap_retransmit_frames(chan);
3686
	} else {
3687
		l2cap_retransmit_frames(chan);
3688

3689 3690
		if (chan->conn_state & L2CAP_CONN_WAIT_F)
			chan->conn_state |= L2CAP_CONN_REJ_ACT;
3691 3692
	}
}
3693
static inline void l2cap_data_channel_srejframe(struct l2cap_chan *chan, u16 rx_control)
3694 3695
{
	u8 tx_seq = __get_reqseq(rx_control);
3696

3697
	BT_DBG("chan %p, req_seq %d ctrl 0x%4.4x", chan, tx_seq, rx_control);
3698

3699
	chan->conn_state &= ~L2CAP_CONN_REMOTE_BUSY;
3700

3701
	if (rx_control & L2CAP_CTRL_POLL) {
3702 3703
		chan->expected_ack_seq = tx_seq;
		l2cap_drop_acked_frames(chan);
3704

3705 3706
		chan->conn_state |= L2CAP_CONN_SEND_FBIT;
		l2cap_retransmit_one_frame(chan, tx_seq);
3707

3708
		l2cap_ertm_send(chan);
3709

3710
		if (chan->conn_state & L2CAP_CONN_WAIT_F) {
3711
			chan->srej_save_reqseq = tx_seq;
3712
			chan->conn_state |= L2CAP_CONN_SREJ_ACT;
3713
		}
3714
	} else if (rx_control & L2CAP_CTRL_FINAL) {
3715
		if ((chan->conn_state & L2CAP_CONN_SREJ_ACT) &&
3716
				chan->srej_save_reqseq == tx_seq)
3717
			chan->conn_state &= ~L2CAP_CONN_SREJ_ACT;
3718
		else
3719
			l2cap_retransmit_one_frame(chan, tx_seq);
3720
	} else {
3721 3722
		l2cap_retransmit_one_frame(chan, tx_seq);
		if (chan->conn_state & L2CAP_CONN_WAIT_F) {
3723
			chan->srej_save_reqseq = tx_seq;
3724
			chan->conn_state |= L2CAP_CONN_SREJ_ACT;
3725
		}
3726 3727 3728
	}
}

3729
static inline void l2cap_data_channel_rnrframe(struct l2cap_chan *chan, u16 rx_control)
3730 3731 3732
{
	u8 tx_seq = __get_reqseq(rx_control);

3733
	BT_DBG("chan %p, req_seq %d ctrl 0x%4.4x", chan, tx_seq, rx_control);
3734

3735
	chan->conn_state |= L2CAP_CONN_REMOTE_BUSY;
3736 3737
	chan->expected_ack_seq = tx_seq;
	l2cap_drop_acked_frames(chan);
3738

3739
	if (rx_control & L2CAP_CTRL_POLL)
3740
		chan->conn_state |= L2CAP_CONN_SEND_FBIT;
3741

3742
	if (!(chan->conn_state & L2CAP_CONN_SREJ_SENT)) {
3743
		del_timer(&chan->retrans_timer);
3744
		if (rx_control & L2CAP_CTRL_POLL)
3745
			l2cap_send_rr_or_rnr(chan, L2CAP_CTRL_FINAL);
3746
		return;
3747
	}
3748 3749

	if (rx_control & L2CAP_CTRL_POLL)
3750
		l2cap_send_srejtail(chan);
3751
	else
3752
		l2cap_send_sframe(chan, L2CAP_SUPER_RCV_READY);
3753 3754
}

3755
static inline int l2cap_data_channel_sframe(struct l2cap_chan *chan, u16 rx_control, struct sk_buff *skb)
3756
{
3757
	BT_DBG("chan %p rx_control 0x%4.4x len %d", chan, rx_control, skb->len);
3758

3759
	if (L2CAP_CTRL_FINAL & rx_control &&
3760
			chan->conn_state & L2CAP_CONN_WAIT_F) {
3761
		del_timer(&chan->monitor_timer);
3762
		if (chan->unacked_frames > 0)
3763
			__mod_retrans_timer();
3764
		chan->conn_state &= ~L2CAP_CONN_WAIT_F;
3765 3766 3767 3768
	}

	switch (rx_control & L2CAP_CTRL_SUPERVISE) {
	case L2CAP_SUPER_RCV_READY:
3769
		l2cap_data_channel_rrframe(chan, rx_control);
3770 3771
		break;

3772
	case L2CAP_SUPER_REJECT:
3773
		l2cap_data_channel_rejframe(chan, rx_control);
3774
		break;
3775

3776
	case L2CAP_SUPER_SELECT_REJECT:
3777
		l2cap_data_channel_srejframe(chan, rx_control);
3778 3779 3780
		break;

	case L2CAP_SUPER_RCV_NOT_READY:
3781
		l2cap_data_channel_rnrframe(chan, rx_control);
3782 3783 3784
		break;
	}

3785
	kfree_skb(skb);
3786 3787 3788
	return 0;
}

3789 3790
static int l2cap_ertm_data_rcv(struct sock *sk, struct sk_buff *skb)
{
3791
	struct l2cap_chan *chan = l2cap_pi(sk)->chan;
3792 3793 3794 3795 3796 3797 3798 3799 3800 3801 3802 3803 3804
	u16 control;
	u8 req_seq;
	int len, next_tx_seq_offset, req_seq_offset;

	control = get_unaligned_le16(skb->data);
	skb_pull(skb, 2);
	len = skb->len;

	/*
	 * We can just drop the corrupted I-frame here.
	 * Receiver will miss it and start proper recovery
	 * procedures and ask retransmission.
	 */
3805
	if (l2cap_check_fcs(chan, skb))
3806 3807 3808 3809 3810
		goto drop;

	if (__is_sar_start(control) && __is_iframe(control))
		len -= 2;

3811
	if (chan->fcs == L2CAP_FCS_CRC16)
3812 3813
		len -= 2;

3814
	if (len > chan->mps) {
3815
		l2cap_send_disconn_req(chan->conn, chan, ECONNRESET);
3816 3817 3818 3819
		goto drop;
	}

	req_seq = __get_reqseq(control);
3820
	req_seq_offset = (req_seq - chan->expected_ack_seq) % 64;
3821 3822 3823 3824
	if (req_seq_offset < 0)
		req_seq_offset += 64;

	next_tx_seq_offset =
3825
		(chan->next_tx_seq - chan->expected_ack_seq) % 64;
3826 3827 3828 3829 3830
	if (next_tx_seq_offset < 0)
		next_tx_seq_offset += 64;

	/* check for invalid req-seq */
	if (req_seq_offset > next_tx_seq_offset) {
3831
		l2cap_send_disconn_req(chan->conn, chan, ECONNRESET);
3832 3833 3834 3835 3836
		goto drop;
	}

	if (__is_iframe(control)) {
		if (len < 0) {
3837
			l2cap_send_disconn_req(chan->conn, chan, ECONNRESET);
3838 3839 3840
			goto drop;
		}

3841
		l2cap_data_channel_iframe(chan, control, skb);
3842 3843 3844
	} else {
		if (len != 0) {
			BT_ERR("%d", len);
3845
			l2cap_send_disconn_req(chan->conn, chan, ECONNRESET);
3846 3847 3848
			goto drop;
		}

3849
		l2cap_data_channel_sframe(chan, control, skb);
3850 3851 3852 3853 3854 3855 3856 3857 3858
	}

	return 0;

drop:
	kfree_skb(skb);
	return 0;
}

L
Linus Torvalds 已提交
3859 3860
static inline int l2cap_data_channel(struct l2cap_conn *conn, u16 cid, struct sk_buff *skb)
{
3861
	struct l2cap_chan *chan;
3862
	struct sock *sk = NULL;
3863
	u16 control;
3864 3865
	u8 tx_seq;
	int len;
L
Linus Torvalds 已提交
3866

3867
	chan = l2cap_get_chan_by_scid(conn, cid);
3868
	if (!chan) {
L
Linus Torvalds 已提交
3869 3870 3871 3872
		BT_DBG("unknown cid 0x%4.4x", cid);
		goto drop;
	}

3873
	sk = chan->sk;
3874

3875
	BT_DBG("chan %p, len %d", chan, skb->len);
L
Linus Torvalds 已提交
3876 3877 3878 3879

	if (sk->sk_state != BT_CONNECTED)
		goto drop;

3880
	switch (chan->mode) {
3881 3882 3883 3884 3885
	case L2CAP_MODE_BASIC:
		/* If socket recv buffers overflows we drop data here
		 * which is *bad* because L2CAP has to be reliable.
		 * But we don't have any other choice. L2CAP doesn't
		 * provide flow control mechanism. */
L
Linus Torvalds 已提交
3886

3887
		if (chan->imtu < skb->len)
3888
			goto drop;
L
Linus Torvalds 已提交
3889

3890
		if (!chan->ops->recv(chan->data, skb))
3891 3892 3893 3894
			goto done;
		break;

	case L2CAP_MODE_ERTM:
3895 3896
		if (!sock_owned_by_user(sk)) {
			l2cap_ertm_data_rcv(sk, skb);
3897
		} else {
3898
			if (sk_add_backlog(sk, skb))
3899 3900
				goto drop;
		}
3901

3902
		goto done;
3903

3904 3905 3906 3907 3908
	case L2CAP_MODE_STREAMING:
		control = get_unaligned_le16(skb->data);
		skb_pull(skb, 2);
		len = skb->len;

3909
		if (l2cap_check_fcs(chan, skb))
3910 3911
			goto drop;

3912 3913 3914
		if (__is_sar_start(control))
			len -= 2;

3915
		if (chan->fcs == L2CAP_FCS_CRC16)
3916 3917
			len -= 2;

3918
		if (len > chan->mps || len < 0 || __is_sframe(control))
3919 3920 3921 3922
			goto drop;

		tx_seq = __get_txseq(control);

3923 3924
		if (chan->expected_tx_seq == tx_seq)
			chan->expected_tx_seq = (chan->expected_tx_seq + 1) % 64;
3925
		else
3926
			chan->expected_tx_seq = (tx_seq + 1) % 64;
3927

3928
		l2cap_streaming_reassembly_sdu(chan, skb, control);
3929 3930 3931

		goto done;

3932
	default:
3933
		BT_DBG("chan %p: bad mode 0x%2.2x", chan, chan->mode);
3934 3935
		break;
	}
L
Linus Torvalds 已提交
3936 3937 3938 3939 3940

drop:
	kfree_skb(skb);

done:
3941 3942 3943
	if (sk)
		bh_unlock_sock(sk);

L
Linus Torvalds 已提交
3944 3945 3946
	return 0;
}

3947
static inline int l2cap_conless_channel(struct l2cap_conn *conn, __le16 psm, struct sk_buff *skb)
L
Linus Torvalds 已提交
3948
{
3949
	struct sock *sk = NULL;
3950
	struct l2cap_chan *chan;
L
Linus Torvalds 已提交
3951

3952 3953
	chan = l2cap_global_chan_by_psm(0, psm, conn->src);
	if (!chan)
L
Linus Torvalds 已提交
3954 3955
		goto drop;

3956 3957
	sk = chan->sk;

3958 3959
	bh_lock_sock(sk);

L
Linus Torvalds 已提交
3960 3961 3962 3963 3964
	BT_DBG("sk %p, len %d", sk, skb->len);

	if (sk->sk_state != BT_BOUND && sk->sk_state != BT_CONNECTED)
		goto drop;

3965
	if (l2cap_pi(sk)->chan->imtu < skb->len)
L
Linus Torvalds 已提交
3966 3967
		goto drop;

3968
	if (!chan->ops->recv(chan->data, skb))
L
Linus Torvalds 已提交
3969 3970 3971 3972 3973 3974
		goto done;

drop:
	kfree_skb(skb);

done:
3975 3976
	if (sk)
		bh_unlock_sock(sk);
L
Linus Torvalds 已提交
3977 3978 3979
	return 0;
}

3980 3981
static inline int l2cap_att_channel(struct l2cap_conn *conn, __le16 cid, struct sk_buff *skb)
{
3982
	struct sock *sk = NULL;
3983
	struct l2cap_chan *chan;
3984

3985 3986
	chan = l2cap_global_chan_by_scid(0, cid, conn->src);
	if (!chan)
3987 3988
		goto drop;

3989 3990
	sk = chan->sk;

3991 3992 3993 3994 3995 3996 3997
	bh_lock_sock(sk);

	BT_DBG("sk %p, len %d", sk, skb->len);

	if (sk->sk_state != BT_BOUND && sk->sk_state != BT_CONNECTED)
		goto drop;

3998
	if (l2cap_pi(sk)->chan->imtu < skb->len)
3999 4000
		goto drop;

4001
	if (!chan->ops->recv(chan->data, skb))
4002 4003 4004 4005 4006 4007 4008 4009 4010 4011 4012
		goto done;

drop:
	kfree_skb(skb);

done:
	if (sk)
		bh_unlock_sock(sk);
	return 0;
}

L
Linus Torvalds 已提交
4013 4014 4015
static void l2cap_recv_frame(struct l2cap_conn *conn, struct sk_buff *skb)
{
	struct l2cap_hdr *lh = (void *) skb->data;
4016 4017
	u16 cid, len;
	__le16 psm;
L
Linus Torvalds 已提交
4018 4019 4020 4021 4022

	skb_pull(skb, L2CAP_HDR_SIZE);
	cid = __le16_to_cpu(lh->cid);
	len = __le16_to_cpu(lh->len);

4023 4024 4025 4026 4027
	if (len != skb->len) {
		kfree_skb(skb);
		return;
	}

L
Linus Torvalds 已提交
4028 4029 4030
	BT_DBG("len %d, cid 0x%4.4x", len, cid);

	switch (cid) {
4031
	case L2CAP_CID_LE_SIGNALING:
4032
	case L2CAP_CID_SIGNALING:
L
Linus Torvalds 已提交
4033 4034 4035
		l2cap_sig_channel(conn, skb);
		break;

4036
	case L2CAP_CID_CONN_LESS:
4037
		psm = get_unaligned_le16(skb->data);
L
Linus Torvalds 已提交
4038 4039 4040 4041
		skb_pull(skb, 2);
		l2cap_conless_channel(conn, psm, skb);
		break;

4042 4043 4044 4045
	case L2CAP_CID_LE_DATA:
		l2cap_att_channel(conn, cid, skb);
		break;

L
Linus Torvalds 已提交
4046 4047 4048 4049 4050 4051 4052 4053 4054 4055 4056
	default:
		l2cap_data_channel(conn, cid, skb);
		break;
	}
}

/* ---- L2CAP interface with lower layer (HCI) ---- */

static int l2cap_connect_ind(struct hci_dev *hdev, bdaddr_t *bdaddr, u8 type)
{
	int exact = 0, lm1 = 0, lm2 = 0;
4057
	struct l2cap_chan *c;
L
Linus Torvalds 已提交
4058 4059

	if (type != ACL_LINK)
4060
		return -EINVAL;
L
Linus Torvalds 已提交
4061 4062 4063 4064

	BT_DBG("hdev %s, bdaddr %s", hdev->name, batostr(bdaddr));

	/* Find listening sockets and check their link_mode */
4065 4066 4067
	read_lock(&chan_list_lock);
	list_for_each_entry(c, &chan_list, global_l) {
		struct sock *sk = c->sk;
4068

L
Linus Torvalds 已提交
4069 4070 4071 4072
		if (sk->sk_state != BT_LISTEN)
			continue;

		if (!bacmp(&bt_sk(sk)->src, &hdev->bdaddr)) {
4073
			lm1 |= HCI_LM_ACCEPT;
4074
			if (c->role_switch)
4075
				lm1 |= HCI_LM_MASTER;
L
Linus Torvalds 已提交
4076
			exact++;
4077 4078
		} else if (!bacmp(&bt_sk(sk)->src, BDADDR_ANY)) {
			lm2 |= HCI_LM_ACCEPT;
4079
			if (c->role_switch)
4080 4081
				lm2 |= HCI_LM_MASTER;
		}
L
Linus Torvalds 已提交
4082
	}
4083
	read_unlock(&chan_list_lock);
L
Linus Torvalds 已提交
4084 4085 4086 4087 4088 4089

	return exact ? lm1 : lm2;
}

static int l2cap_connect_cfm(struct hci_conn *hcon, u8 status)
{
4090 4091
	struct l2cap_conn *conn;

L
Linus Torvalds 已提交
4092 4093
	BT_DBG("hcon %p bdaddr %s status %d", hcon, batostr(&hcon->dst), status);

4094
	if (!(hcon->type == ACL_LINK || hcon->type == LE_LINK))
4095
		return -EINVAL;
L
Linus Torvalds 已提交
4096 4097 4098 4099 4100

	if (!status) {
		conn = l2cap_conn_add(hcon, status);
		if (conn)
			l2cap_conn_ready(conn);
4101
	} else
L
Linus Torvalds 已提交
4102 4103 4104 4105 4106
		l2cap_conn_del(hcon, bt_err(status));

	return 0;
}

4107 4108 4109 4110 4111 4112 4113 4114 4115 4116 4117 4118 4119
static int l2cap_disconn_ind(struct hci_conn *hcon)
{
	struct l2cap_conn *conn = hcon->l2cap_data;

	BT_DBG("hcon %p", hcon);

	if (hcon->type != ACL_LINK || !conn)
		return 0x13;

	return conn->disc_reason;
}

static int l2cap_disconn_cfm(struct hci_conn *hcon, u8 reason)
L
Linus Torvalds 已提交
4120 4121 4122
{
	BT_DBG("hcon %p reason %d", hcon, reason);

4123
	if (!(hcon->type == ACL_LINK || hcon->type == LE_LINK))
4124
		return -EINVAL;
L
Linus Torvalds 已提交
4125 4126

	l2cap_conn_del(hcon, bt_err(reason));
4127

L
Linus Torvalds 已提交
4128 4129 4130
	return 0;
}

4131
static inline void l2cap_check_encryption(struct l2cap_chan *chan, u8 encrypt)
4132
{
4133
	if (chan->chan_type != L2CAP_CHAN_CONN_ORIENTED)
4134 4135
		return;

4136
	if (encrypt == 0x00) {
4137
		if (chan->sec_level == BT_SECURITY_MEDIUM) {
4138 4139
			l2cap_chan_clear_timer(chan);
			l2cap_chan_set_timer(chan, HZ * 5);
4140
		} else if (chan->sec_level == BT_SECURITY_HIGH)
4141
			l2cap_chan_close(chan, ECONNREFUSED);
4142
	} else {
4143
		if (chan->sec_level == BT_SECURITY_MEDIUM)
4144
			l2cap_chan_clear_timer(chan);
4145 4146 4147
	}
}

4148
static int l2cap_security_cfm(struct hci_conn *hcon, u8 status, u8 encrypt)
L
Linus Torvalds 已提交
4149
{
4150
	struct l2cap_conn *conn = hcon->l2cap_data;
4151
	struct l2cap_chan *chan;
L
Linus Torvalds 已提交
4152

4153
	if (!conn)
L
Linus Torvalds 已提交
4154
		return 0;
4155

L
Linus Torvalds 已提交
4156 4157
	BT_DBG("conn %p", conn);

4158
	read_lock(&conn->chan_lock);
L
Linus Torvalds 已提交
4159

4160
	list_for_each_entry(chan, &conn->chan_l, list) {
4161
		struct sock *sk = chan->sk;
4162

L
Linus Torvalds 已提交
4163 4164
		bh_lock_sock(sk);

4165
		if (chan->conf_state & L2CAP_CONF_CONNECT_PEND) {
4166 4167 4168 4169
			bh_unlock_sock(sk);
			continue;
		}

4170
		if (!status && (sk->sk_state == BT_CONNECTED ||
4171
						sk->sk_state == BT_CONFIG)) {
4172
			l2cap_check_encryption(chan, encrypt);
4173 4174 4175 4176
			bh_unlock_sock(sk);
			continue;
		}

4177 4178 4179
		if (sk->sk_state == BT_CONNECT) {
			if (!status) {
				struct l2cap_conn_req req;
4180 4181
				req.scid = cpu_to_le16(chan->scid);
				req.psm  = chan->psm;
L
Linus Torvalds 已提交
4182

4183
				chan->ident = l2cap_get_ident(conn);
4184
				chan->conf_state |= L2CAP_CONF_CONNECT_PEND;
L
Linus Torvalds 已提交
4185

4186
				l2cap_send_cmd(conn, chan->ident,
4187 4188
					L2CAP_CONN_REQ, sizeof(req), &req);
			} else {
4189 4190
				l2cap_chan_clear_timer(chan);
				l2cap_chan_set_timer(chan, HZ / 10);
4191 4192 4193 4194
			}
		} else if (sk->sk_state == BT_CONNECT2) {
			struct l2cap_conn_rsp rsp;
			__u16 result;
L
Linus Torvalds 已提交
4195

4196 4197 4198 4199 4200
			if (!status) {
				sk->sk_state = BT_CONFIG;
				result = L2CAP_CR_SUCCESS;
			} else {
				sk->sk_state = BT_DISCONN;
4201
				l2cap_chan_set_timer(chan, HZ / 10);
4202 4203 4204
				result = L2CAP_CR_SEC_BLOCK;
			}

4205 4206
			rsp.scid   = cpu_to_le16(chan->dcid);
			rsp.dcid   = cpu_to_le16(chan->scid);
4207
			rsp.result = cpu_to_le16(result);
4208
			rsp.status = cpu_to_le16(L2CAP_CS_NO_INFO);
4209 4210
			l2cap_send_cmd(conn, chan->ident, L2CAP_CONN_RSP,
							sizeof(rsp), &rsp);
4211
		}
L
Linus Torvalds 已提交
4212 4213 4214 4215

		bh_unlock_sock(sk);
	}

4216
	read_unlock(&conn->chan_lock);
4217

L
Linus Torvalds 已提交
4218 4219 4220 4221 4222 4223 4224
	return 0;
}

static int l2cap_recv_acldata(struct hci_conn *hcon, struct sk_buff *skb, u16 flags)
{
	struct l2cap_conn *conn = hcon->l2cap_data;

4225 4226 4227 4228
	if (!conn)
		conn = l2cap_conn_add(hcon, 0);

	if (!conn)
L
Linus Torvalds 已提交
4229 4230 4231 4232
		goto drop;

	BT_DBG("conn %p len %d flags 0x%x", conn, skb->len, flags);

4233
	if (!(flags & ACL_CONT)) {
L
Linus Torvalds 已提交
4234
		struct l2cap_hdr *hdr;
4235
		struct l2cap_chan *chan;
4236
		u16 cid;
L
Linus Torvalds 已提交
4237 4238 4239 4240 4241 4242 4243 4244 4245 4246
		int len;

		if (conn->rx_len) {
			BT_ERR("Unexpected start frame (len %d)", skb->len);
			kfree_skb(conn->rx_skb);
			conn->rx_skb = NULL;
			conn->rx_len = 0;
			l2cap_conn_unreliable(conn, ECOMM);
		}

4247 4248
		/* Start fragment always begin with Basic L2CAP header */
		if (skb->len < L2CAP_HDR_SIZE) {
L
Linus Torvalds 已提交
4249 4250 4251 4252 4253 4254 4255
			BT_ERR("Frame is too short (len %d)", skb->len);
			l2cap_conn_unreliable(conn, ECOMM);
			goto drop;
		}

		hdr = (struct l2cap_hdr *) skb->data;
		len = __le16_to_cpu(hdr->len) + L2CAP_HDR_SIZE;
4256
		cid = __le16_to_cpu(hdr->cid);
L
Linus Torvalds 已提交
4257 4258 4259 4260 4261 4262 4263 4264 4265 4266 4267 4268 4269 4270 4271 4272

		if (len == skb->len) {
			/* Complete frame received */
			l2cap_recv_frame(conn, skb);
			return 0;
		}

		BT_DBG("Start: total len %d, frag len %d", len, skb->len);

		if (skb->len > len) {
			BT_ERR("Frame is too long (len %d, expected len %d)",
				skb->len, len);
			l2cap_conn_unreliable(conn, ECOMM);
			goto drop;
		}

4273
		chan = l2cap_get_chan_by_scid(conn, cid);
4274

4275 4276
		if (chan && chan->sk) {
			struct sock *sk = chan->sk;
4277

4278
			if (chan->imtu < len - L2CAP_HDR_SIZE) {
4279 4280
				BT_ERR("Frame exceeding recv MTU (len %d, "
							"MTU %d)", len,
4281
							chan->imtu);
4282 4283 4284 4285
				bh_unlock_sock(sk);
				l2cap_conn_unreliable(conn, ECOMM);
				goto drop;
			}
4286
			bh_unlock_sock(sk);
4287
		}
4288

L
Linus Torvalds 已提交
4289
		/* Allocate skb for the complete frame (with header) */
4290 4291
		conn->rx_skb = bt_skb_alloc(len, GFP_ATOMIC);
		if (!conn->rx_skb)
L
Linus Torvalds 已提交
4292 4293
			goto drop;

4294
		skb_copy_from_linear_data(skb, skb_put(conn->rx_skb, skb->len),
4295
								skb->len);
L
Linus Torvalds 已提交
4296 4297 4298 4299 4300 4301 4302 4303 4304 4305 4306 4307 4308 4309 4310 4311 4312 4313 4314 4315
		conn->rx_len = len - skb->len;
	} else {
		BT_DBG("Cont: frag len %d (expecting %d)", skb->len, conn->rx_len);

		if (!conn->rx_len) {
			BT_ERR("Unexpected continuation frame (len %d)", skb->len);
			l2cap_conn_unreliable(conn, ECOMM);
			goto drop;
		}

		if (skb->len > conn->rx_len) {
			BT_ERR("Fragment is too long (len %d, expected %d)",
					skb->len, conn->rx_len);
			kfree_skb(conn->rx_skb);
			conn->rx_skb = NULL;
			conn->rx_len = 0;
			l2cap_conn_unreliable(conn, ECOMM);
			goto drop;
		}

4316
		skb_copy_from_linear_data(skb, skb_put(conn->rx_skb, skb->len),
4317
								skb->len);
L
Linus Torvalds 已提交
4318 4319 4320 4321 4322 4323 4324 4325 4326 4327 4328 4329 4330 4331
		conn->rx_len -= skb->len;

		if (!conn->rx_len) {
			/* Complete frame received */
			l2cap_recv_frame(conn, conn->rx_skb);
			conn->rx_skb = NULL;
		}
	}

drop:
	kfree_skb(skb);
	return 0;
}

4332
static int l2cap_debugfs_show(struct seq_file *f, void *p)
L
Linus Torvalds 已提交
4333
{
4334
	struct l2cap_chan *c;
L
Linus Torvalds 已提交
4335

4336
	read_lock_bh(&chan_list_lock);
L
Linus Torvalds 已提交
4337

4338 4339
	list_for_each_entry(c, &chan_list, global_l) {
		struct sock *sk = c->sk;
4340

4341
		seq_printf(f, "%s %s %d %d 0x%4.4x 0x%4.4x %d %d %d %d\n",
4342 4343
					batostr(&bt_sk(sk)->src),
					batostr(&bt_sk(sk)->dst),
4344 4345 4346
					sk->sk_state, __le16_to_cpu(c->psm),
					c->scid, c->dcid, c->imtu, c->omtu,
					c->sec_level, c->mode);
4347
	}
L
Linus Torvalds 已提交
4348

4349
	read_unlock_bh(&chan_list_lock);
L
Linus Torvalds 已提交
4350

4351
	return 0;
L
Linus Torvalds 已提交
4352 4353
}

4354 4355 4356 4357 4358 4359 4360 4361 4362 4363 4364 4365 4366
static int l2cap_debugfs_open(struct inode *inode, struct file *file)
{
	return single_open(file, l2cap_debugfs_show, inode->i_private);
}

static const struct file_operations l2cap_debugfs_fops = {
	.open		= l2cap_debugfs_open,
	.read		= seq_read,
	.llseek		= seq_lseek,
	.release	= single_release,
};

static struct dentry *l2cap_debugfs;
L
Linus Torvalds 已提交
4367 4368 4369 4370 4371 4372 4373

static struct hci_proto l2cap_hci_proto = {
	.name		= "L2CAP",
	.id		= HCI_PROTO_L2CAP,
	.connect_ind	= l2cap_connect_ind,
	.connect_cfm	= l2cap_connect_cfm,
	.disconn_ind	= l2cap_disconn_ind,
4374
	.disconn_cfm	= l2cap_disconn_cfm,
4375
	.security_cfm	= l2cap_security_cfm,
L
Linus Torvalds 已提交
4376 4377 4378
	.recv_acldata	= l2cap_recv_acldata
};

4379
int __init l2cap_init(void)
L
Linus Torvalds 已提交
4380 4381
{
	int err;
4382

4383
	err = l2cap_init_sockets();
L
Linus Torvalds 已提交
4384 4385 4386
	if (err < 0)
		return err;

4387
	_busy_wq = create_singlethread_workqueue("l2cap");
4388
	if (!_busy_wq) {
4389
		err = -ENOMEM;
L
Linus Torvalds 已提交
4390 4391 4392 4393 4394 4395 4396 4397 4398 4399
		goto error;
	}

	err = hci_register_proto(&l2cap_hci_proto);
	if (err < 0) {
		BT_ERR("L2CAP protocol registration failed");
		bt_sock_unregister(BTPROTO_L2CAP);
		goto error;
	}

4400 4401 4402 4403 4404 4405
	if (bt_debugfs) {
		l2cap_debugfs = debugfs_create_file("l2cap", 0444,
					bt_debugfs, NULL, &l2cap_debugfs_fops);
		if (!l2cap_debugfs)
			BT_ERR("Failed to create L2CAP debug file");
	}
L
Linus Torvalds 已提交
4406 4407 4408 4409

	return 0;

error:
4410
	destroy_workqueue(_busy_wq);
4411
	l2cap_cleanup_sockets();
L
Linus Torvalds 已提交
4412 4413 4414
	return err;
}

4415
void l2cap_exit(void)
L
Linus Torvalds 已提交
4416
{
4417
	debugfs_remove(l2cap_debugfs);
L
Linus Torvalds 已提交
4418

4419 4420 4421
	flush_workqueue(_busy_wq);
	destroy_workqueue(_busy_wq);

L
Linus Torvalds 已提交
4422 4423 4424
	if (hci_unregister_proto(&l2cap_hci_proto) < 0)
		BT_ERR("L2CAP protocol unregistration failed");

4425
	l2cap_cleanup_sockets();
L
Linus Torvalds 已提交
4426 4427
}

4428 4429
module_param(disable_ertm, bool, 0644);
MODULE_PARM_DESC(disable_ertm, "Disable enhanced retransmission mode");