l2cap_core.c 193 KB


  1. /*
  2. BlueZ - Bluetooth protocol stack for Linux
  3. Copyright (c) 2000-2001, 2010-2013 The Linux Foundation. All rights reserved.
  4. Copyright (C) 2009-2010 Gustavo F. Padovan <gustavo@padovan.org>
  5. Copyright (C) 2010 Google Inc.
  6. Written 2000,2001 by Maxim Krasnyansky <maxk@qualcomm.com>
  7. This program is free software; you can redistribute it and/or modify
  8. it under the terms of the GNU General Public License version 2 as
  9. published by the Free Software Foundation;
  10. THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS
  11. OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
  12. FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT OF THIRD PARTY RIGHTS.
  13. IN NO EVENT SHALL THE COPYRIGHT HOLDER(S) AND AUTHOR(S) BE LIABLE FOR ANY
  14. CLAIM, OR ANY SPECIAL INDIRECT OR CONSEQUENTIAL DAMAGES, OR ANY DAMAGES
  15. WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
  16. ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
  17. OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
  18. ALL LIABILITY, INCLUDING LIABILITY FOR INFRINGEMENT OF ANY PATENTS,
  19. COPYRIGHTS, TRADEMARKS OR OTHER RIGHTS, RELATING TO USE OF THIS
  20. SOFTWARE IS DISCLAIMED.
  21. */
  22. /* Bluetooth L2CAP core. */
  23. #include <linux/module.h>
  24. #include <linux/types.h>
  25. #include <linux/capability.h>
  26. #include <linux/errno.h>
  27. #include <linux/kernel.h>
  28. #include <linux/sched.h>
  29. #include <linux/slab.h>
  30. #include <linux/poll.h>
  31. #include <linux/fcntl.h>
  32. #include <linux/init.h>
  33. #include <linux/interrupt.h>
  34. #include <linux/socket.h>
  35. #include <linux/skbuff.h>
  36. #include <linux/list.h>
  37. #include <linux/device.h>
  38. #include <linux/debugfs.h>
  39. #include <linux/seq_file.h>
  40. #include <linux/uaccess.h>
  41. #include <linux/crc16.h>
  42. #include <linux/math64.h>
  43. #include <net/sock.h>
  44. #include <asm/system.h>
  45. #include <asm/unaligned.h>
  46. #include <net/bluetooth/bluetooth.h>
  47. #include <net/bluetooth/hci_core.h>
  48. #include <net/bluetooth/l2cap.h>
  49. #include <net/bluetooth/smp.h>
  50. #include <net/bluetooth/amp.h>
  51. bool disable_ertm;
  52. bool enable_hs;
  53. bool enable_reconfig;
  54. static u32 l2cap_feat_mask = L2CAP_FEAT_FIXED_CHAN;
  55. static u8 l2cap_fc_mask = L2CAP_FC_L2CAP;
  56. struct workqueue_struct *_l2cap_wq;
  57. struct bt_sock_list l2cap_sk_list = {
  58. .lock = __RW_LOCK_UNLOCKED(l2cap_sk_list.lock)
  59. };
  60. static void l2cap_send_move_chan_req(struct l2cap_conn *conn,
  61. struct l2cap_pinfo *pi, u16 icid, u8 dest_amp_id);
  62. static void l2cap_send_move_chan_cfm(struct l2cap_conn *conn,
  63. struct l2cap_pinfo *pi, u16 icid, u16 result);
  64. static void l2cap_send_move_chan_rsp(struct l2cap_conn *conn, u8 ident,
  65. u16 icid, u16 result);
  66. static void l2cap_amp_move_setup(struct sock *sk);
  67. static void l2cap_amp_move_success(struct sock *sk);
  68. static void l2cap_amp_move_revert(struct sock *sk);
  69. static int l2cap_ertm_rx_queued_iframes(struct sock *sk);
  70. static struct sk_buff *l2cap_build_cmd(struct l2cap_conn *conn,
  71. u8 code, u8 ident, u16 dlen, void *data);
  72. static int l2cap_answer_move_poll(struct sock *sk);
  73. static int l2cap_create_cfm(struct hci_chan *chan, u8 status);
  74. static int l2cap_deaggregate(struct hci_chan *chan, struct l2cap_pinfo *pi);
  75. static void l2cap_chan_ready(struct sock *sk);
  76. static void l2cap_conn_del(struct hci_conn *hcon, int err, u8 is_process);
  77. static u16 l2cap_get_smallest_flushto(struct l2cap_chan_list *l);
  78. static void l2cap_set_acl_flushto(struct hci_conn *hcon, u16 flush_to);
  79. static void l2cap_queue_acl_data(struct work_struct *worker);
  80. static struct att_channel_parameters{
  81. struct sk_buff *skb;
  82. struct l2cap_conn *conn;
  83. __le16 cid;
  84. int dir;
  85. } att_chn_params;
  86. /* ---- L2CAP channels ---- */
  87. static struct sock *__l2cap_get_chan_by_dcid(struct l2cap_chan_list *l, u16 cid)
  88. {
  89. struct sock *s;
  90. for (s = l->head; s; s = l2cap_pi(s)->next_c) {
  91. if (l2cap_pi(s)->dcid == cid)
  92. break;
  93. }
  94. return s;
  95. }
  96. /* Find channel with given DCID.
  97. * Returns locked socket */
  98. static inline struct sock *l2cap_get_chan_by_dcid(struct l2cap_chan_list *l,
  99. u16 cid)
  100. {
  101. struct sock *s;
  102. read_lock(&l->lock);
  103. s = __l2cap_get_chan_by_dcid(l, cid);
  104. if (s)
  105. bh_lock_sock(s);
  106. read_unlock(&l->lock);
  107. return s;
  108. }
  109. static struct sock *__l2cap_get_chan_by_scid(struct l2cap_chan_list *l, u16 cid)
  110. {
  111. struct sock *s;
  112. for (s = l->head; s; s = l2cap_pi(s)->next_c) {
  113. if (l2cap_pi(s)->scid == cid)
  114. break;
  115. }
  116. return s;
  117. }
  118. /* Find channel with given SCID.
  119. * Returns locked socket */
  120. static inline struct sock *l2cap_get_chan_by_scid(struct l2cap_chan_list *l, u16 cid)
  121. {
  122. struct sock *s;
  123. read_lock(&l->lock);
  124. s = __l2cap_get_chan_by_scid(l, cid);
  125. if (s)
  126. bh_lock_sock(s);
  127. read_unlock(&l->lock);
  128. return s;
  129. }
  130. static struct sock *__l2cap_get_chan_by_ident(struct l2cap_chan_list *l, u8 ident)
  131. {
  132. struct sock *s;
  133. for (s = l->head; s; s = l2cap_pi(s)->next_c) {
  134. if (l2cap_pi(s)->ident == ident)
  135. break;
  136. }
  137. return s;
  138. }
  139. static inline struct sock *l2cap_get_chan_by_ident(struct l2cap_chan_list *l, u8 ident)
  140. {
  141. struct sock *s;
  142. read_lock(&l->lock);
  143. s = __l2cap_get_chan_by_ident(l, ident);
  144. if (s)
  145. bh_lock_sock(s);
  146. read_unlock(&l->lock);
  147. return s;
  148. }
  149. static inline struct sk_buff *l2cap_ertm_seq_in_queue(struct sk_buff_head *head,
  150. u16 seq)
  151. {
  152. struct sk_buff *skb;
  153. skb_queue_walk(head, skb) {
  154. if (bt_cb(skb)->control.txseq == seq)
  155. return skb;
  156. }
  157. return NULL;
  158. }
  159. static int l2cap_seq_list_init(struct l2cap_seq_list *seq_list, u16 size)
  160. {
  161. u16 allocSize = 1;
  162. int err = 0;
  163. int i;
  164. /* Actual allocated size must be a power of 2 */
  165. while (allocSize && allocSize <= size)
  166. allocSize <<= 1;
  167. if (!allocSize)
  168. return -ENOMEM;
  169. seq_list->list = kzalloc(sizeof(u16) * allocSize, GFP_ATOMIC);
  170. if (!seq_list->list)
  171. return -ENOMEM;
  172. seq_list->size = allocSize;
  173. seq_list->mask = allocSize - 1;
  174. seq_list->head = L2CAP_SEQ_LIST_CLEAR;
  175. seq_list->tail = L2CAP_SEQ_LIST_CLEAR;
  176. for (i = 0; i < allocSize; i++)
  177. seq_list->list[i] = L2CAP_SEQ_LIST_CLEAR;
  178. return err;
  179. }
  180. static inline void l2cap_seq_list_free(struct l2cap_seq_list *seq_list)
  181. {
  182. kfree(seq_list->list);
  183. }
  184. static inline bool l2cap_seq_list_contains(struct l2cap_seq_list *seq_list,
  185. u16 seq)
  186. {
  187. return seq_list->list[seq & seq_list->mask] != L2CAP_SEQ_LIST_CLEAR;
  188. }
  189. static u16 l2cap_seq_list_remove(struct l2cap_seq_list *seq_list, u16 seq)
  190. {
  191. u16 mask = seq_list->mask;
  192. BT_DBG("seq_list %p, seq %d", seq_list, (int) seq);
  193. if (seq_list->head == L2CAP_SEQ_LIST_CLEAR) {
  194. /* In case someone tries to pop the head of an empty list */
  195. BT_DBG("List empty");
  196. return L2CAP_SEQ_LIST_CLEAR;
  197. } else if (seq_list->head == seq) {
  198. /* Head can be removed quickly */
  199. BT_DBG("Remove head");
  200. seq_list->head = seq_list->list[seq & mask];
  201. seq_list->list[seq & mask] = L2CAP_SEQ_LIST_CLEAR;
  202. if (seq_list->head == L2CAP_SEQ_LIST_TAIL) {
  203. seq_list->head = L2CAP_SEQ_LIST_CLEAR;
  204. seq_list->tail = L2CAP_SEQ_LIST_CLEAR;
  205. }
  206. } else {
  207. /* Non-head item must be found first */
  208. u16 prev = seq_list->head;
  209. BT_DBG("Find and remove");
  210. while (seq_list->list[prev & mask] != seq) {
  211. prev = seq_list->list[prev & mask];
  212. if (prev == L2CAP_SEQ_LIST_TAIL) {
  213. BT_DBG("seq %d not in list", (int) seq);
  214. return L2CAP_SEQ_LIST_CLEAR;
  215. }
  216. }
  217. seq_list->list[prev & mask] = seq_list->list[seq & mask];
  218. seq_list->list[seq & mask] = L2CAP_SEQ_LIST_CLEAR;
  219. if (seq_list->tail == seq)
  220. seq_list->tail = prev;
  221. }
  222. return seq;
  223. }
  224. static inline u16 l2cap_seq_list_pop(struct l2cap_seq_list *seq_list)
  225. {
  226. return l2cap_seq_list_remove(seq_list, seq_list->head);
  227. }
  228. static void l2cap_seq_list_clear(struct l2cap_seq_list *seq_list)
  229. {
  230. if (seq_list->head != L2CAP_SEQ_LIST_CLEAR) {
  231. u16 i;
  232. for (i = 0; i < seq_list->size; i++)
  233. seq_list->list[i] = L2CAP_SEQ_LIST_CLEAR;
  234. seq_list->head = L2CAP_SEQ_LIST_CLEAR;
  235. seq_list->tail = L2CAP_SEQ_LIST_CLEAR;
  236. }
  237. }
  238. static void l2cap_seq_list_append(struct l2cap_seq_list *seq_list, u16 seq)
  239. {
  240. u16 mask = seq_list->mask;
  241. BT_DBG("seq_list %p, seq %d", seq_list, (int) seq);
  242. if (seq_list->list[seq & mask] == L2CAP_SEQ_LIST_CLEAR) {
  243. if (seq_list->tail == L2CAP_SEQ_LIST_CLEAR)
  244. seq_list->head = seq;
  245. else
  246. seq_list->list[seq_list->tail & mask] = seq;
  247. seq_list->tail = seq;
  248. seq_list->list[seq & mask] = L2CAP_SEQ_LIST_TAIL;
  249. }
  250. }
  251. static u16 __pack_enhanced_control(struct bt_l2cap_control *control)
  252. {
  253. u16 packed;
  254. packed = (control->reqseq << L2CAP_CTRL_REQSEQ_SHIFT) &
  255. L2CAP_CTRL_REQSEQ;
  256. packed |= (control->final << L2CAP_CTRL_FINAL_SHIFT) &
  257. L2CAP_CTRL_FINAL;
  258. if (control->frame_type == 's') {
  259. packed |= (control->poll << L2CAP_CTRL_POLL_SHIFT) &
  260. L2CAP_CTRL_POLL;
  261. packed |= (control->super << L2CAP_CTRL_SUPERVISE_SHIFT) &
  262. L2CAP_CTRL_SUPERVISE;
  263. packed |= L2CAP_CTRL_FRAME_TYPE;
  264. } else {
  265. packed |= (control->sar << L2CAP_CTRL_SAR_SHIFT) &
  266. L2CAP_CTRL_SAR;
  267. packed |= (control->txseq << L2CAP_CTRL_TXSEQ_SHIFT) &
  268. L2CAP_CTRL_TXSEQ;
  269. }
  270. return packed;
  271. }
  272. static void __get_enhanced_control(u16 enhanced,
  273. struct bt_l2cap_control *control)
  274. {
  275. control->reqseq = (enhanced & L2CAP_CTRL_REQSEQ) >>
  276. L2CAP_CTRL_REQSEQ_SHIFT;
  277. control->final = (enhanced & L2CAP_CTRL_FINAL) >>
  278. L2CAP_CTRL_FINAL_SHIFT;
  279. if (enhanced & L2CAP_CTRL_FRAME_TYPE) {
  280. control->frame_type = 's';
  281. control->poll = (enhanced & L2CAP_CTRL_POLL) >>
  282. L2CAP_CTRL_POLL_SHIFT;
  283. control->super = (enhanced & L2CAP_CTRL_SUPERVISE) >>
  284. L2CAP_CTRL_SUPERVISE_SHIFT;
  285. control->sar = 0;
  286. control->txseq = 0;
  287. } else {
  288. control->frame_type = 'i';
  289. control->sar = (enhanced & L2CAP_CTRL_SAR) >>
  290. L2CAP_CTRL_SAR_SHIFT;
  291. control->txseq = (enhanced & L2CAP_CTRL_TXSEQ) >>
  292. L2CAP_CTRL_TXSEQ_SHIFT;
  293. control->poll = 0;
  294. control->super = 0;
  295. }
  296. }
  297. static u32 __pack_extended_control(struct bt_l2cap_control *control)
  298. {
  299. u32 packed;
  300. packed = (control->reqseq << L2CAP_EXT_CTRL_REQSEQ_SHIFT) &
  301. L2CAP_EXT_CTRL_REQSEQ;
  302. packed |= (control->final << L2CAP_EXT_CTRL_FINAL_SHIFT) &
  303. L2CAP_EXT_CTRL_FINAL;
  304. if (control->frame_type == 's') {
  305. packed |= (control->poll << L2CAP_EXT_CTRL_POLL_SHIFT) &
  306. L2CAP_EXT_CTRL_POLL;
  307. packed |= (control->super << L2CAP_EXT_CTRL_SUPERVISE_SHIFT) &
  308. L2CAP_EXT_CTRL_SUPERVISE;
  309. packed |= L2CAP_EXT_CTRL_FRAME_TYPE;
  310. } else {
  311. packed |= (control->sar << L2CAP_EXT_CTRL_SAR_SHIFT) &
  312. L2CAP_EXT_CTRL_SAR;
  313. packed |= (control->txseq << L2CAP_EXT_CTRL_TXSEQ_SHIFT) &
  314. L2CAP_EXT_CTRL_TXSEQ;
  315. }
  316. return packed;
  317. }
  318. static void __get_extended_control(u32 extended,
  319. struct bt_l2cap_control *control)
  320. {
  321. control->reqseq = (extended & L2CAP_EXT_CTRL_REQSEQ) >>
  322. L2CAP_EXT_CTRL_REQSEQ_SHIFT;
  323. control->final = (extended & L2CAP_EXT_CTRL_FINAL) >>
  324. L2CAP_EXT_CTRL_FINAL_SHIFT;
  325. if (extended & L2CAP_EXT_CTRL_FRAME_TYPE) {
  326. control->frame_type = 's';
  327. control->poll = (extended & L2CAP_EXT_CTRL_POLL) >>
  328. L2CAP_EXT_CTRL_POLL_SHIFT;
  329. control->super = (extended & L2CAP_EXT_CTRL_SUPERVISE) >>
  330. L2CAP_EXT_CTRL_SUPERVISE_SHIFT;
  331. control->sar = 0;
  332. control->txseq = 0;
  333. } else {
  334. control->frame_type = 'i';
  335. control->sar = (extended & L2CAP_EXT_CTRL_SAR) >>
  336. L2CAP_EXT_CTRL_SAR_SHIFT;
  337. control->txseq = (extended & L2CAP_EXT_CTRL_TXSEQ) >>
  338. L2CAP_EXT_CTRL_TXSEQ_SHIFT;
  339. control->poll = 0;
  340. control->super = 0;
  341. }
  342. }
  343. static inline void l2cap_ertm_stop_ack_timer(struct l2cap_pinfo *pi)
  344. {
  345. BT_DBG("pi %p", pi);
  346. __cancel_delayed_work(&pi->ack_work);
  347. }
  348. static inline void l2cap_ertm_start_ack_timer(struct l2cap_pinfo *pi)
  349. {
  350. BT_DBG("pi %p, pending %d", pi, delayed_work_pending(&pi->ack_work));
  351. if (!delayed_work_pending(&pi->ack_work)) {
  352. queue_delayed_work(_l2cap_wq, &pi->ack_work,
  353. msecs_to_jiffies(L2CAP_DEFAULT_ACK_TO));
  354. }
  355. }
  356. static inline void l2cap_ertm_stop_retrans_timer(struct l2cap_pinfo *pi)
  357. {
  358. BT_DBG("pi %p", pi);
  359. __cancel_delayed_work(&pi->retrans_work);
  360. }
  361. static inline void l2cap_ertm_start_retrans_timer(struct l2cap_pinfo *pi)
  362. {
  363. BT_DBG("pi %p", pi);
  364. if (!delayed_work_pending(&pi->monitor_work) && pi->retrans_timeout) {
  365. __cancel_delayed_work(&pi->retrans_work);
  366. queue_delayed_work(_l2cap_wq, &pi->retrans_work,
  367. msecs_to_jiffies(pi->retrans_timeout));
  368. }
  369. }
  370. static inline void l2cap_ertm_stop_monitor_timer(struct l2cap_pinfo *pi)
  371. {
  372. BT_DBG("pi %p", pi);
  373. __cancel_delayed_work(&pi->monitor_work);
  374. }
  375. static inline void l2cap_ertm_start_monitor_timer(struct l2cap_pinfo *pi)
  376. {
  377. BT_DBG("pi %p", pi);
  378. l2cap_ertm_stop_retrans_timer(pi);
  379. __cancel_delayed_work(&pi->monitor_work);
  380. if (pi->monitor_timeout) {
  381. queue_delayed_work(_l2cap_wq, &pi->monitor_work,
  382. msecs_to_jiffies(pi->monitor_timeout));
  383. }
  384. }
  385. static u16 l2cap_alloc_cid(struct l2cap_chan_list *l)
  386. {
  387. u16 cid = L2CAP_CID_DYN_START;
  388. for (; cid < L2CAP_CID_DYN_END; cid++) {
  389. if (!__l2cap_get_chan_by_scid(l, cid))
  390. return cid;
  391. }
  392. return 0;
  393. }
  394. static inline void __l2cap_chan_link(struct l2cap_chan_list *l, struct sock *sk)
  395. {
  396. sock_hold(sk);
  397. if (l->head)
  398. l2cap_pi(l->head)->prev_c = sk;
  399. l2cap_pi(sk)->next_c = l->head;
  400. l2cap_pi(sk)->prev_c = NULL;
  401. l->head = sk;
  402. }
  403. static inline void l2cap_chan_unlink(struct l2cap_chan_list *l, struct sock *sk)
  404. {
  405. struct sock *next = l2cap_pi(sk)->next_c, *prev = l2cap_pi(sk)->prev_c;
  406. write_lock_bh(&l->lock);
  407. if (sk == l->head)
  408. l->head = next;
  409. if (next)
  410. l2cap_pi(next)->prev_c = prev;
  411. if (prev)
  412. l2cap_pi(prev)->next_c = next;
  413. write_unlock_bh(&l->lock);
  414. __sock_put(sk);
  415. }
  416. static void __l2cap_chan_add(struct l2cap_conn *conn, struct sock *sk)
  417. {
  418. struct l2cap_chan_list *l = &conn->chan_list;
  419. BT_DBG("conn %p, psm 0x%2.2x, dcid 0x%4.4x", conn,
  420. l2cap_pi(sk)->psm, l2cap_pi(sk)->dcid);
  421. conn->disc_reason = 0x13;
  422. l2cap_pi(sk)->conn = conn;
  423. if (!l2cap_pi(sk)->fixed_channel &&
  424. (sk->sk_type == SOCK_SEQPACKET || sk->sk_type == SOCK_STREAM)) {
  425. if (conn->hcon->type == LE_LINK) {
  426. /* LE connection */
  427. if (l2cap_pi(sk)->imtu < L2CAP_LE_DEFAULT_MTU)
  428. l2cap_pi(sk)->imtu = L2CAP_LE_DEFAULT_MTU;
  429. if (l2cap_pi(sk)->omtu < L2CAP_LE_DEFAULT_MTU)
  430. l2cap_pi(sk)->omtu = L2CAP_LE_DEFAULT_MTU;
  431. l2cap_pi(sk)->scid = L2CAP_CID_LE_DATA;
  432. l2cap_pi(sk)->dcid = L2CAP_CID_LE_DATA;
  433. } else {
  434. /* Alloc CID for connection-oriented socket */
  435. l2cap_pi(sk)->scid = l2cap_alloc_cid(l);
  436. l2cap_pi(sk)->omtu = L2CAP_DEFAULT_MTU;
  437. }
  438. } else if (sk->sk_type == SOCK_DGRAM) {
  439. /* Connectionless socket */
  440. l2cap_pi(sk)->scid = L2CAP_CID_CONN_LESS;
  441. l2cap_pi(sk)->dcid = L2CAP_CID_CONN_LESS;
  442. l2cap_pi(sk)->omtu = L2CAP_DEFAULT_MTU;
  443. } else if (sk->sk_type == SOCK_RAW) {
  444. /* Raw socket can send/recv signalling messages only */
  445. l2cap_pi(sk)->scid = L2CAP_CID_SIGNALING;
  446. l2cap_pi(sk)->dcid = L2CAP_CID_SIGNALING;
  447. l2cap_pi(sk)->omtu = L2CAP_DEFAULT_MTU;
  448. }
  449. if (l2cap_get_smallest_flushto(l) > l2cap_pi(sk)->flush_to) {
  450. /*if flush timeout of the channel is lesser than existing */
  451. l2cap_set_acl_flushto(conn->hcon, l2cap_pi(sk)->flush_to);
  452. }
  453. /* Otherwise, do not set scid/dcid/omtu. These will be set up
  454. * by l2cap_fixed_channel_config()
  455. */
  456. __l2cap_chan_link(l, sk);
  457. }
  458. /* Delete channel.
  459. * Must be called on the locked socket. */
  460. void l2cap_chan_del(struct sock *sk, int err)
  461. {
  462. struct l2cap_conn *conn = l2cap_pi(sk)->conn;
  463. struct sock *parent = bt_sk(sk)->parent;
  464. l2cap_sock_clear_timer(sk);
  465. BT_DBG("sk %p, conn %p, err %d", sk, conn, err);
  466. if (conn) {
  467. struct l2cap_chan_list *l = &conn->chan_list;
  468. /* Unlink from channel list */
  469. l2cap_chan_unlink(l, sk);
  470. l2cap_pi(sk)->conn = NULL;
  471. if (!l2cap_pi(sk)->fixed_channel)
  472. hci_conn_put(conn->hcon);
  473. read_lock(&l->lock);
  474. if (l2cap_pi(sk)->flush_to < l2cap_get_smallest_flushto(l))
  475. l2cap_set_acl_flushto(conn->hcon,
  476. l2cap_get_smallest_flushto(l));
  477. read_unlock(&l->lock);
  478. }
  479. if (l2cap_pi(sk)->ampchan) {
  480. struct hci_chan *ampchan = l2cap_pi(sk)->ampchan;
  481. struct hci_conn *ampcon = l2cap_pi(sk)->ampcon;
  482. l2cap_pi(sk)->ampchan = NULL;
  483. l2cap_pi(sk)->ampcon = NULL;
  484. l2cap_pi(sk)->amp_id = 0;
  485. if (hci_chan_put(ampchan))
  486. ampcon->l2cap_data = NULL;
  487. else
  488. l2cap_deaggregate(ampchan, l2cap_pi(sk));
  489. }
  490. sk->sk_state = BT_CLOSED;
  491. sock_set_flag(sk, SOCK_ZAPPED);
  492. if (err)
  493. sk->sk_err = err;
  494. if (parent) {
  495. bt_accept_unlink(sk);
  496. parent->sk_data_ready(parent, 0);
  497. } else
  498. sk->sk_state_change(sk);
  499. sk->sk_send_head = NULL;
  500. skb_queue_purge(TX_QUEUE(sk));
  501. if (l2cap_pi(sk)->mode == L2CAP_MODE_ERTM) {
  502. if (l2cap_pi(sk)->sdu)
  503. kfree_skb(l2cap_pi(sk)->sdu);
  504. skb_queue_purge(SREJ_QUEUE(sk));
  505. __cancel_delayed_work(&l2cap_pi(sk)->ack_work);
  506. __cancel_delayed_work(&l2cap_pi(sk)->retrans_work);
  507. __cancel_delayed_work(&l2cap_pi(sk)->monitor_work);
  508. }
  509. }
  510. static inline u8 l2cap_get_auth_type(struct sock *sk)
  511. {
  512. if (sk->sk_type == SOCK_RAW) {
  513. switch (l2cap_pi(sk)->sec_level) {
  514. case BT_SECURITY_VERY_HIGH:
  515. case BT_SECURITY_HIGH:
  516. return HCI_AT_DEDICATED_BONDING_MITM;
  517. case BT_SECURITY_MEDIUM:
  518. return HCI_AT_DEDICATED_BONDING;
  519. default:
  520. return HCI_AT_NO_BONDING;
  521. }
  522. } else if (l2cap_pi(sk)->psm == cpu_to_le16(0x0001)) {
  523. if (l2cap_pi(sk)->sec_level == BT_SECURITY_LOW)
  524. l2cap_pi(sk)->sec_level = BT_SECURITY_SDP;
  525. if (l2cap_pi(sk)->sec_level == BT_SECURITY_HIGH ||
  526. l2cap_pi(sk)->sec_level == BT_SECURITY_VERY_HIGH)
  527. return HCI_AT_NO_BONDING_MITM;
  528. else
  529. return HCI_AT_NO_BONDING;
  530. } else {
  531. switch (l2cap_pi(sk)->sec_level) {
  532. case BT_SECURITY_VERY_HIGH:
  533. case BT_SECURITY_HIGH:
  534. return HCI_AT_GENERAL_BONDING_MITM;
  535. case BT_SECURITY_MEDIUM:
  536. return HCI_AT_GENERAL_BONDING;
  537. default:
  538. return HCI_AT_NO_BONDING;
  539. }
  540. }
  541. }
  542. /* Service level security */
  543. static inline int l2cap_check_security(struct sock *sk)
  544. {
  545. struct l2cap_conn *conn = l2cap_pi(sk)->conn;
  546. __u8 auth_type;
  547. auth_type = l2cap_get_auth_type(sk);
  548. return hci_conn_security(conn->hcon, l2cap_pi(sk)->sec_level,
  549. auth_type);
  550. }
  551. u8 l2cap_get_ident(struct l2cap_conn *conn)
  552. {
  553. u8 id;
  554. /* Get next available identificator.
  555. * 1 - 128 are used by kernel.
  556. * 129 - 199 are reserved.
  557. * 200 - 254 are used by utilities like l2ping, etc.
  558. */
  559. spin_lock_bh(&conn->lock);
  560. if (++conn->tx_ident > 128)
  561. conn->tx_ident = 1;
  562. id = conn->tx_ident;
  563. spin_unlock_bh(&conn->lock);
  564. return id;
  565. }
  566. static void apply_fcs(struct sk_buff *skb)
  567. {
  568. size_t len;
  569. u16 partial_crc;
  570. struct sk_buff *iter;
  571. struct sk_buff *final_frag = skb;
  572. if (skb_has_frag_list(skb))
  573. len = skb_headlen(skb);
  574. else
  575. len = skb->len - L2CAP_FCS_SIZE;
  576. partial_crc = crc16(0, (u8 *) skb->data, len);
  577. skb_walk_frags(skb, iter) {
  578. len = iter->len;
  579. if (!iter->next)
  580. len -= L2CAP_FCS_SIZE;
  581. partial_crc = crc16(partial_crc, iter->data, len);
  582. final_frag = iter;
  583. }
  584. put_unaligned_le16(partial_crc,
  585. final_frag->data + final_frag->len - L2CAP_FCS_SIZE);
  586. }
  587. void l2cap_send_cmd(struct l2cap_conn *conn, u8 ident, u8 code, u16 len, void *data)
  588. {
  589. struct sk_buff *skb = l2cap_build_cmd(conn, code, ident, len, data);
  590. u8 flags;
  591. BT_DBG("code 0x%2.2x", code);
  592. if (!skb)
  593. return;
  594. if (conn->hcon == NULL || conn->hcon->hdev == NULL)
  595. return;
  596. if (lmp_no_flush_capable(conn->hcon->hdev))
  597. flags = ACL_START_NO_FLUSH;
  598. else
  599. flags = ACL_START;
  600. bt_cb(skb)->force_active = 1;
  601. hci_send_acl(conn->hcon, NULL, skb, flags);
  602. }
  603. static inline int __l2cap_no_conn_pending(struct sock *sk)
  604. {
  605. return !(l2cap_pi(sk)->conf_state & L2CAP_CONF_CONNECT_PEND);
  606. }
  607. static void l2cap_send_conn_req(struct sock *sk)
  608. {
  609. struct l2cap_conn_req req;
  610. req.scid = cpu_to_le16(l2cap_pi(sk)->scid);
  611. req.psm = l2cap_pi(sk)->psm;
  612. l2cap_pi(sk)->ident = l2cap_get_ident(l2cap_pi(sk)->conn);
  613. l2cap_send_cmd(l2cap_pi(sk)->conn, l2cap_pi(sk)->ident,
  614. L2CAP_CONN_REQ, sizeof(req), &req);
  615. }
  616. static void l2cap_send_create_chan_req(struct sock *sk, u8 amp_id)
  617. {
  618. struct l2cap_create_chan_req req;
  619. req.scid = cpu_to_le16(l2cap_pi(sk)->scid);
  620. req.psm = l2cap_pi(sk)->psm;
  621. req.amp_id = amp_id;
  622. l2cap_pi(sk)->conf_state |= L2CAP_CONF_LOCKSTEP;
  623. l2cap_pi(sk)->ident = l2cap_get_ident(l2cap_pi(sk)->conn);
  624. l2cap_send_cmd(l2cap_pi(sk)->conn, l2cap_pi(sk)->ident,
  625. L2CAP_CREATE_CHAN_REQ, sizeof(req), &req);
  626. }
  627. static void l2cap_do_start(struct sock *sk)
  628. {
  629. struct l2cap_conn *conn = l2cap_pi(sk)->conn;
  630. if (conn->info_state & L2CAP_INFO_FEAT_MASK_REQ_SENT) {
  631. if (!(conn->info_state & L2CAP_INFO_FEAT_MASK_REQ_DONE))
  632. return;
  633. if (l2cap_check_security(sk) && __l2cap_no_conn_pending(sk)) {
  634. l2cap_pi(sk)->conf_state |= L2CAP_CONF_CONNECT_PEND;
  635. if (l2cap_pi(sk)->amp_pref ==
  636. BT_AMP_POLICY_PREFER_AMP &&
  637. enable_hs &&
  638. conn->fc_mask & L2CAP_FC_A2MP)
  639. amp_create_physical(conn, sk);
  640. else
  641. l2cap_send_conn_req(sk);
  642. }
  643. } else {
  644. struct l2cap_info_req req;
  645. req.type = cpu_to_le16(L2CAP_IT_FEAT_MASK);
  646. conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_SENT;
  647. conn->info_ident = l2cap_get_ident(conn);
  648. mod_timer(&conn->info_timer, jiffies +
  649. msecs_to_jiffies(L2CAP_INFO_TIMEOUT));
  650. l2cap_send_cmd(conn, conn->info_ident,
  651. L2CAP_INFO_REQ, sizeof(req), &req);
  652. }
  653. }
  654. static inline int l2cap_mode_supported(__u8 mode, __u32 feat_mask)
  655. {
  656. u32 local_feat_mask = l2cap_feat_mask;
  657. if (!disable_ertm)
  658. local_feat_mask |= L2CAP_FEAT_ERTM | L2CAP_FEAT_STREAMING;
  659. switch (mode) {
  660. case L2CAP_MODE_ERTM:
  661. return L2CAP_FEAT_ERTM & feat_mask & local_feat_mask;
  662. case L2CAP_MODE_STREAMING:
  663. return L2CAP_FEAT_STREAMING & feat_mask & local_feat_mask;
  664. default:
  665. return 0x00;
  666. }
  667. }
  668. void l2cap_send_disconn_req(struct l2cap_conn *conn, struct sock *sk, int err)
  669. {
  670. struct l2cap_disconn_req req;
  671. if (!conn)
  672. return;
  673. sk->sk_send_head = NULL;
  674. skb_queue_purge(TX_QUEUE(sk));
  675. if (l2cap_pi(sk)->mode == L2CAP_MODE_ERTM) {
  676. skb_queue_purge(SREJ_QUEUE(sk));
  677. __cancel_delayed_work(&l2cap_pi(sk)->ack_work);
  678. __cancel_delayed_work(&l2cap_pi(sk)->retrans_work);
  679. __cancel_delayed_work(&l2cap_pi(sk)->monitor_work);
  680. }
  681. req.dcid = cpu_to_le16(l2cap_pi(sk)->dcid);
  682. req.scid = cpu_to_le16(l2cap_pi(sk)->scid);
  683. l2cap_send_cmd(conn, l2cap_get_ident(conn),
  684. L2CAP_DISCONN_REQ, sizeof(req), &req);
  685. sk->sk_state = BT_DISCONN;
  686. sk->sk_err = err;
  687. }
  688. /* ---- L2CAP connections ---- */
  689. static void l2cap_conn_start(struct l2cap_conn *conn)
  690. {
  691. struct l2cap_chan_list *l = &conn->chan_list;
  692. struct sock_del_list del, *tmp1, *tmp2;
  693. struct sock *sk;
  694. BT_DBG("conn %p", conn);
  695. INIT_LIST_HEAD(&del.list);
  696. read_lock(&l->lock);
  697. for (sk = l->head; sk; sk = l2cap_pi(sk)->next_c) {
  698. bh_lock_sock(sk);
  699. if (sk->sk_type != SOCK_SEQPACKET &&
  700. sk->sk_type != SOCK_STREAM) {
  701. bh_unlock_sock(sk);
  702. continue;
  703. }
  704. if (sk->sk_state == BT_CONNECT) {
  705. if (!l2cap_check_security(sk) ||
  706. !__l2cap_no_conn_pending(sk)) {
  707. bh_unlock_sock(sk);
  708. continue;
  709. }
  710. if (!l2cap_mode_supported(l2cap_pi(sk)->mode,
  711. conn->feat_mask)
  712. && l2cap_pi(sk)->conf_state &
  713. L2CAP_CONF_STATE2_DEVICE) {
  714. tmp1 = kzalloc(sizeof(struct sock_del_list),
  715. GFP_ATOMIC);
  716. tmp1->sk = sk;
  717. list_add_tail(&tmp1->list, &del.list);
  718. bh_unlock_sock(sk);
  719. continue;
  720. }
  721. l2cap_pi(sk)->conf_state |= L2CAP_CONF_CONNECT_PEND;
  722. if (l2cap_pi(sk)->amp_pref ==
  723. BT_AMP_POLICY_PREFER_AMP &&
  724. enable_hs &&
  725. conn->fc_mask & L2CAP_FC_A2MP)
  726. amp_create_physical(conn, sk);
  727. else
  728. l2cap_send_conn_req(sk);
  729. } else if (sk->sk_state == BT_CONNECT2) {
  730. struct l2cap_conn_rsp rsp;
  731. char buf[128];
  732. rsp.scid = cpu_to_le16(l2cap_pi(sk)->dcid);
  733. rsp.dcid = cpu_to_le16(l2cap_pi(sk)->scid);
  734. if (l2cap_check_security(sk)) {
  735. if (bt_sk(sk)->defer_setup) {
  736. struct sock *parent = bt_sk(sk)->parent;
  737. rsp.result = cpu_to_le16(L2CAP_CR_PEND);
  738. rsp.status = cpu_to_le16(L2CAP_CS_AUTHOR_PEND);
  739. if (parent)
  740. parent->sk_data_ready(parent, 0);
  741. } else {
  742. sk->sk_state = BT_CONFIG;
  743. rsp.result = cpu_to_le16(L2CAP_CR_SUCCESS);
  744. rsp.status = cpu_to_le16(L2CAP_CS_NO_INFO);
  745. }
  746. } else {
  747. rsp.result = cpu_to_le16(L2CAP_CR_PEND);
  748. rsp.status = cpu_to_le16(L2CAP_CS_AUTHEN_PEND);
  749. }
  750. if (rsp.result == cpu_to_le16(L2CAP_CR_SUCCESS) &&
  751. l2cap_pi(sk)->amp_id) {
  752. amp_accept_physical(conn,
  753. l2cap_pi(sk)->amp_id, sk);
  754. bh_unlock_sock(sk);
  755. continue;
  756. }
  757. l2cap_send_cmd(conn, l2cap_pi(sk)->ident,
  758. L2CAP_CONN_RSP, sizeof(rsp), &rsp);
  759. if (l2cap_pi(sk)->conf_state & L2CAP_CONF_REQ_SENT ||
  760. rsp.result != L2CAP_CR_SUCCESS) {
  761. bh_unlock_sock(sk);
  762. continue;
  763. }
  764. l2cap_pi(sk)->conf_state |= L2CAP_CONF_REQ_SENT;
  765. l2cap_send_cmd(conn, l2cap_get_ident(conn), L2CAP_CONF_REQ,
  766. l2cap_build_conf_req(sk, buf, sizeof(buf)), buf);
  767. l2cap_pi(sk)->num_conf_req++;
  768. }
  769. bh_unlock_sock(sk);
  770. }
  771. read_unlock(&l->lock);
  772. list_for_each_entry_safe(tmp1, tmp2, &del.list, list) {
  773. bh_lock_sock(tmp1->sk);
  774. __l2cap_sock_close(tmp1->sk, ECONNRESET);
  775. bh_unlock_sock(tmp1->sk);
  776. list_del(&tmp1->list);
  777. kfree(tmp1);
  778. }
  779. }
  780. /* Find socket with fixed cid with given source and destination bdaddrs.
  781. * Direction of the req/rsp must match.
  782. */
  783. struct sock *l2cap_find_sock_by_fixed_cid_and_dir(__le16 cid, bdaddr_t *src,
  784. bdaddr_t *dst, int incoming)
  785. {
  786. struct sock *sk = NULL, *sk1 = NULL;
  787. struct hlist_node *node;
  788. BT_DBG(" %d", incoming);
  789. read_lock(&l2cap_sk_list.lock);
  790. sk_for_each(sk, node, &l2cap_sk_list.head) {
  791. if (incoming && !l2cap_pi(sk)->incoming)
  792. continue;
  793. if (!incoming && l2cap_pi(sk)->incoming)
  794. continue;
  795. if (l2cap_pi(sk)->scid == cid && !bacmp(&bt_sk(sk)->dst, dst)) {
  796. /* Exact match. */
  797. if (!bacmp(&bt_sk(sk)->src, src))
  798. break;
  799. /* Closest match */
  800. if (!bacmp(&bt_sk(sk)->src, BDADDR_ANY))
  801. sk1 = sk;
  802. }
  803. }
  804. read_unlock(&l2cap_sk_list.lock);
  805. return node ? sk : sk1;
  806. }
  807. /* Find socket with cid and source bdaddr.
  808. * Returns closest match, locked.
  809. */
  810. static struct sock *l2cap_get_sock_by_scid(int state, __le16 cid, bdaddr_t *src)
  811. {
  812. struct sock *sk = NULL, *sk1 = NULL;
  813. struct hlist_node *node;
  814. read_lock(&l2cap_sk_list.lock);
  815. sk_for_each(sk, node, &l2cap_sk_list.head) {
  816. if (state && sk->sk_state != state)
  817. continue;
  818. if (l2cap_pi(sk)->scid == cid) {
  819. /* Exact match. */
  820. if (!bacmp(&bt_sk(sk)->src, src))
  821. break;
  822. /* Closest match */
  823. if (!bacmp(&bt_sk(sk)->src, BDADDR_ANY))
  824. sk1 = sk;
  825. }
  826. }
  827. read_unlock(&l2cap_sk_list.lock);
  828. return node ? sk : sk1;
  829. }
  830. static void l2cap_le_conn_ready(struct l2cap_conn *conn)
  831. {
  832. struct l2cap_chan_list *list = &conn->chan_list;
  833. struct sock *parent, *uninitialized_var(sk);
  834. BT_DBG("");
  835. /* Check if we have socket listening on cid */
  836. parent = l2cap_get_sock_by_scid(BT_LISTEN, L2CAP_CID_LE_DATA,
  837. conn->src);
  838. if (!parent)
  839. return;
  840. bh_lock_sock(parent);
  841. /* Check for backlog size */
  842. if (sk_acceptq_is_full(parent)) {
  843. BT_DBG("backlog full %d", parent->sk_ack_backlog);
  844. goto clean;
  845. }
  846. sk = l2cap_sock_alloc(sock_net(parent), NULL, BTPROTO_L2CAP, GFP_ATOMIC);
  847. if (!sk)
  848. goto clean;
  849. write_lock_bh(&list->lock);
  850. hci_conn_hold(conn->hcon);
  851. conn->hcon->disc_timeout = HCI_DISCONN_TIMEOUT;
  852. l2cap_sock_init(sk, parent);
  853. bacpy(&bt_sk(sk)->src, conn->src);
  854. bacpy(&bt_sk(sk)->dst, conn->dst);
  855. l2cap_pi(sk)->incoming = 1;
  856. bt_accept_enqueue(parent, sk);
  857. __l2cap_chan_add(conn, sk);
  858. sk->sk_state = BT_CONNECTED;
  859. parent->sk_data_ready(parent, 0);
  860. write_unlock_bh(&list->lock);
  861. clean:
  862. bh_unlock_sock(parent);
  863. }
  864. static void l2cap_conn_ready(struct l2cap_conn *conn)
  865. {
  866. struct l2cap_chan_list *l = &conn->chan_list;
  867. struct sock *sk;
  868. struct hci_conn *hcon = conn->hcon;
  869. BT_DBG("conn %p", conn);
  870. if (!hcon->out && hcon->type == LE_LINK)
  871. l2cap_le_conn_ready(conn);
  872. if (hcon->out && hcon->type == LE_LINK)
  873. smp_conn_security(hcon, hcon->pending_sec_level);
  874. read_lock(&l->lock);
  875. if (l->head) {
  876. for (sk = l->head; sk; sk = l2cap_pi(sk)->next_c) {
  877. bh_lock_sock(sk);
  878. if (hcon->type == LE_LINK) {
  879. u8 sec_level = l2cap_pi(sk)->sec_level;
  880. u8 pending_sec = hcon->pending_sec_level;
  881. if (pending_sec > sec_level)
  882. sec_level = pending_sec;
  883. if (smp_conn_security(hcon, sec_level))
  884. l2cap_chan_ready(sk);
  885. hci_conn_put(conn->hcon);
  886. } else if (sk->sk_type != SOCK_SEQPACKET &&
  887. sk->sk_type != SOCK_STREAM) {
  888. l2cap_sock_clear_timer(sk);
  889. sk->sk_state = BT_CONNECTED;
  890. sk->sk_state_change(sk);
  891. } else if (sk->sk_state == BT_CONNECT)
  892. l2cap_do_start(sk);
  893. bh_unlock_sock(sk);
  894. }
  895. } else if (conn->hcon->type == LE_LINK) {
  896. smp_conn_security(hcon, BT_SECURITY_HIGH);
  897. }
  898. read_unlock(&l->lock);
  899. if (conn->hcon->out && conn->hcon->type == LE_LINK)
  900. l2cap_le_conn_ready(conn);
  901. }
  902. /* Notify sockets that we cannot guaranty reliability anymore */
  903. static void l2cap_conn_unreliable(struct l2cap_conn *conn, int err)
  904. {
  905. struct l2cap_chan_list *l = &conn->chan_list;
  906. struct sock *sk;
  907. BT_DBG("conn %p", conn);
  908. read_lock(&l->lock);
  909. for (sk = l->head; sk; sk = l2cap_pi(sk)->next_c) {
  910. if (l2cap_pi(sk)->force_reliable)
  911. sk->sk_err = err;
  912. }
  913. read_unlock(&l->lock);
  914. }
  915. static void l2cap_info_timeout(unsigned long arg)
  916. {
  917. struct l2cap_conn *conn = (void *) arg;
  918. conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_DONE;
  919. conn->info_ident = 0;
  920. l2cap_conn_start(conn);
  921. }
  922. static struct l2cap_conn *l2cap_conn_add(struct hci_conn *hcon, u8 status)
  923. {
  924. struct l2cap_conn *conn = hcon->l2cap_data;
  925. if (conn || status)
  926. return conn;
  927. conn = kzalloc(sizeof(struct l2cap_conn), GFP_ATOMIC);
  928. if (!conn)
  929. return NULL;
  930. hcon->l2cap_data = conn;
  931. conn->hcon = hcon;
  932. BT_DBG("hcon %p conn %p", hcon, conn);
  933. if (hcon->hdev->le_mtu && hcon->type == LE_LINK)
  934. conn->mtu = hcon->hdev->le_mtu;
  935. else
  936. conn->mtu = hcon->hdev->acl_mtu;
  937. conn->src = &hcon->hdev->bdaddr;
  938. conn->dst = &hcon->dst;
  939. conn->feat_mask = 0;
  940. spin_lock_init(&conn->lock);
  941. rwlock_init(&conn->chan_list.lock);
  942. if (hcon->type == LE_LINK)
  943. setup_timer(&hcon->smp_timer, smp_timeout,
  944. (unsigned long) conn);
  945. else
  946. setup_timer(&conn->info_timer, l2cap_info_timeout,
  947. (unsigned long) conn);
  948. conn->disc_reason = 0x13;
  949. return conn;
  950. }
  951. static void l2cap_conn_del(struct hci_conn *hcon, int err, u8 is_process)
  952. {
  953. struct l2cap_conn *conn = hcon->l2cap_data;
  954. struct sock *sk;
  955. struct sock *next;
  956. if (!conn)
  957. return;
  958. BT_DBG("hcon %p conn %p, err %d", hcon, conn, err);
  959. if ((conn->hcon == hcon) && (conn->rx_skb))
  960. kfree_skb(conn->rx_skb);
  961. BT_DBG("conn->hcon %p", conn->hcon);
  962. /* Kill channels */
  963. for (sk = conn->chan_list.head; sk; ) {
  964. BT_DBG("ampcon %p", l2cap_pi(sk)->ampcon);
  965. if ((conn->hcon == hcon) || (l2cap_pi(sk)->ampcon == hcon)) {
  966. next = l2cap_pi(sk)->next_c;
  967. if (is_process)
  968. lock_sock(sk);
  969. else
  970. bh_lock_sock(sk);
  971. l2cap_chan_del(sk, err);
  972. if (is_process)
  973. release_sock(sk);
  974. else
  975. bh_unlock_sock(sk);
  976. l2cap_sock_kill(sk);
  977. sk = next;
  978. } else
  979. sk = l2cap_pi(sk)->next_c;
  980. }
  981. if (conn->hcon == hcon) {
  982. if (conn->info_state & L2CAP_INFO_FEAT_MASK_REQ_SENT)
  983. del_timer_sync(&conn->info_timer);
  984. hcon->l2cap_data = NULL;
  985. kfree(conn);
  986. }
  987. att_chn_params.conn = NULL;
  988. BT_DBG("att_chn_params.conn set to NULL");
  989. }
  990. static inline void l2cap_chan_add(struct l2cap_conn *conn, struct sock *sk)
  991. {
  992. struct l2cap_chan_list *l = &conn->chan_list;
  993. write_lock_bh(&l->lock);
  994. __l2cap_chan_add(conn, sk);
  995. write_unlock_bh(&l->lock);
  996. }
  997. /* ---- Socket interface ---- */
  998. /* Find socket with psm and source bdaddr.
  999. * Returns closest match.
  1000. */
  1001. static struct sock *l2cap_get_sock_by_psm(int state, __le16 psm, bdaddr_t *src)
  1002. {
  1003. struct sock *sk = NULL, *sk1 = NULL;
  1004. struct hlist_node *node;
  1005. read_lock(&l2cap_sk_list.lock);
  1006. sk_for_each(sk, node, &l2cap_sk_list.head) {
  1007. if (state && sk->sk_state != state)
  1008. continue;
  1009. if (l2cap_pi(sk)->psm == psm) {
  1010. /* Exact match. */
  1011. if (!bacmp(&bt_sk(sk)->src, src))
  1012. break;
  1013. /* Closest match */
  1014. if (!bacmp(&bt_sk(sk)->src, BDADDR_ANY))
  1015. sk1 = sk;
  1016. }
  1017. }
  1018. read_unlock(&l2cap_sk_list.lock);
  1019. return node ? sk : sk1;
  1020. }
  1021. int l2cap_do_connect(struct sock *sk)
  1022. {
  1023. bdaddr_t *src = &bt_sk(sk)->src;
  1024. bdaddr_t *dst = &bt_sk(sk)->dst;
  1025. struct l2cap_conn *conn;
  1026. struct hci_conn *hcon;
  1027. struct hci_dev *hdev;
  1028. __u8 auth_type;
  1029. int err;
  1030. BT_DBG("%s -> %s psm 0x%2.2x", batostr(src), batostr(dst),
  1031. l2cap_pi(sk)->psm);
  1032. hdev = hci_get_route(dst, src);
  1033. if (!hdev)
  1034. return -EHOSTUNREACH;
  1035. hci_dev_lock_bh(hdev);
  1036. auth_type = l2cap_get_auth_type(sk);
  1037. if (l2cap_pi(sk)->fixed_channel) {
  1038. /* Fixed channels piggyback on existing ACL connections */
  1039. hcon = hci_conn_hash_lookup_ba(hdev, ACL_LINK, dst);
  1040. if (!hcon || !hcon->l2cap_data) {
  1041. err = -ENOTCONN;
  1042. goto done;
  1043. }
  1044. conn = hcon->l2cap_data;
  1045. } else {
  1046. if (l2cap_pi(sk)->dcid == L2CAP_CID_LE_DATA)
  1047. hcon = hci_le_connect(hdev, 0, dst,
  1048. l2cap_pi(sk)->sec_level, auth_type,
  1049. &bt_sk(sk)->le_params);
  1050. else
  1051. hcon = hci_connect(hdev, ACL_LINK, 0, dst,
  1052. l2cap_pi(sk)->sec_level, auth_type);
  1053. if (IS_ERR(hcon)) {
  1054. err = PTR_ERR(hcon);
  1055. goto done;
  1056. }
  1057. conn = l2cap_conn_add(hcon, 0);
  1058. if (!conn) {
  1059. hci_conn_put(hcon);
  1060. err = -ENOMEM;
  1061. goto done;
  1062. }
  1063. }
  1064. /* Update source addr of the socket */
  1065. bacpy(src, conn->src);
  1066. l2cap_chan_add(conn, sk);
  1067. if ((l2cap_pi(sk)->fixed_channel) ||
  1068. (l2cap_pi(sk)->dcid == L2CAP_CID_LE_DATA &&
  1069. hcon->state == BT_CONNECTED)) {
  1070. sk->sk_state = BT_CONNECTED;
  1071. sk->sk_state_change(sk);
  1072. } else {
  1073. sk->sk_state = BT_CONNECT;
  1074. /* If we have valid LE Params, let timeout override default */
  1075. if (l2cap_pi(sk)->dcid == L2CAP_CID_LE_DATA &&
  1076. l2cap_sock_le_params_valid(&bt_sk(sk)->le_params)) {
  1077. u16 timeout = bt_sk(sk)->le_params.conn_timeout;
  1078. if (timeout)
  1079. l2cap_sock_set_timer(sk,
  1080. msecs_to_jiffies(timeout*1000));
  1081. } else
  1082. l2cap_sock_set_timer(sk, sk->sk_sndtimeo);
  1083. sk->sk_state_change(sk);
  1084. if (hcon->state == BT_CONNECTED) {
  1085. if (sk->sk_type != SOCK_SEQPACKET &&
  1086. sk->sk_type != SOCK_STREAM) {
  1087. l2cap_sock_clear_timer(sk);
  1088. if (l2cap_check_security(sk)) {
  1089. sk->sk_state = BT_CONNECTED;
  1090. sk->sk_state_change(sk);
  1091. }
  1092. } else
  1093. l2cap_do_start(sk);
  1094. }
  1095. }
  1096. err = 0;
  1097. done:
  1098. hci_dev_unlock_bh(hdev);
  1099. hci_dev_put(hdev);
  1100. return err;
  1101. }
  1102. int __l2cap_wait_ack(struct sock *sk)
  1103. {
  1104. DECLARE_WAITQUEUE(wait, current);
  1105. int err = 0;
  1106. int timeo = HZ/5;
  1107. add_wait_queue(sk_sleep(sk), &wait);
  1108. while (l2cap_pi(sk)->unacked_frames > 0 && l2cap_pi(sk)->conn &&
  1109. atomic_read(&l2cap_pi(sk)->ertm_queued)) {
  1110. set_current_state(TASK_INTERRUPTIBLE);
  1111. if (!timeo)
  1112. timeo = HZ/5;
  1113. if (signal_pending(current)) {
  1114. err = sock_intr_errno(timeo);
  1115. break;
  1116. }
  1117. release_sock(sk);
  1118. timeo = schedule_timeout(timeo);
  1119. lock_sock(sk);
  1120. err = sock_error(sk);
  1121. if (err)
  1122. break;
  1123. }
  1124. set_current_state(TASK_RUNNING);
  1125. remove_wait_queue(sk_sleep(sk), &wait);
  1126. return err;
  1127. }
  1128. static void l2cap_ertm_tx_worker(struct work_struct *work)
  1129. {
  1130. struct l2cap_pinfo *pi =
  1131. container_of(work, struct l2cap_pinfo, tx_work);
  1132. struct sock *sk = (struct sock *)pi;
  1133. BT_DBG("%p", pi);
  1134. lock_sock(sk);
  1135. l2cap_ertm_send(sk);
  1136. release_sock(sk);
  1137. sock_put(sk);
  1138. }
  1139. static void l2cap_skb_destructor(struct sk_buff *skb)
  1140. {
  1141. struct sock *sk = skb->sk;
  1142. int queued;
  1143. int keep_sk = 0;
  1144. queued = atomic_sub_return(1, &l2cap_pi(sk)->ertm_queued);
  1145. if (queued < L2CAP_MIN_ERTM_QUEUED)
  1146. keep_sk = queue_work(_l2cap_wq, &l2cap_pi(sk)->tx_work);
  1147. if (!keep_sk)
  1148. sock_put(sk);
  1149. }
  1150. void l2cap_do_send(struct sock *sk, struct sk_buff *skb)
  1151. {
  1152. struct l2cap_pinfo *pi = l2cap_pi(sk);
  1153. BT_DBG("sk %p, skb %p len %d", sk, skb, skb->len);
  1154. if (pi->ampcon && (pi->amp_move_state == L2CAP_AMP_STATE_STABLE ||
  1155. pi->amp_move_state == L2CAP_AMP_STATE_WAIT_PREPARE)) {
  1156. BT_DBG("Sending on AMP connection %p %p",
  1157. pi->ampcon, pi->ampchan);
  1158. if (pi->ampchan)
  1159. hci_send_acl(pi->ampcon, pi->ampchan, skb,
  1160. ACL_COMPLETE);
  1161. else
  1162. kfree_skb(skb);
  1163. } else {
  1164. u16 flags;
  1165. if (!(pi->conn)) {
  1166. kfree_skb(skb);
  1167. return;
  1168. }
  1169. bt_cb(skb)->force_active = pi->force_active;
  1170. BT_DBG("Sending on BR/EDR connection %p", pi->conn->hcon);
  1171. if (lmp_no_flush_capable(pi->conn->hcon->hdev) &&
  1172. !l2cap_pi(sk)->flushable)
  1173. flags = ACL_START_NO_FLUSH;
  1174. else
  1175. flags = ACL_START;
  1176. hci_send_acl(pi->conn->hcon, NULL, skb, flags);
  1177. }
  1178. }
  1179. int l2cap_ertm_send(struct sock *sk)
  1180. {
  1181. struct sk_buff *skb, *tx_skb;
  1182. struct l2cap_pinfo *pi = l2cap_pi(sk);
  1183. struct bt_l2cap_control *control;
  1184. int sent = 0;
  1185. BT_DBG("sk %p", sk);
  1186. if (sk->sk_state != BT_CONNECTED)
  1187. return -ENOTCONN;
  1188. if (pi->conn_state & L2CAP_CONN_REMOTE_BUSY)
  1189. return 0;
  1190. if (pi->amp_move_state != L2CAP_AMP_STATE_STABLE &&
  1191. pi->amp_move_state != L2CAP_AMP_STATE_WAIT_PREPARE)
  1192. return 0;
  1193. while (sk->sk_send_head && (pi->unacked_frames < pi->remote_tx_win) &&
  1194. atomic_read(&pi->ertm_queued) < L2CAP_MAX_ERTM_QUEUED &&
  1195. (pi->tx_state == L2CAP_ERTM_TX_STATE_XMIT)) {
  1196. skb = sk->sk_send_head;
  1197. bt_cb(skb)->retries = 1;
  1198. control = &bt_cb(skb)->control;
  1199. if (pi->conn_state & L2CAP_CONN_SEND_FBIT) {
  1200. control->final = 1;
  1201. pi->conn_state &= ~L2CAP_CONN_SEND_FBIT;
  1202. }
  1203. control->reqseq = pi->buffer_seq;
  1204. pi->last_acked_seq = pi->buffer_seq;
  1205. control->txseq = pi->next_tx_seq;
  1206. if (pi->extended_control) {
  1207. put_unaligned_le32(__pack_extended_control(control),
  1208. skb->data + L2CAP_HDR_SIZE);
  1209. } else {
  1210. put_unaligned_le16(__pack_enhanced_control(control),
  1211. skb->data + L2CAP_HDR_SIZE);
  1212. }
  1213. if (pi->fcs == L2CAP_FCS_CRC16)
  1214. apply_fcs(skb);
  1215. /* Clone after data has been modified. Data is assumed to be
  1216. read-only (for locking purposes) on cloned sk_buffs.
  1217. */
  1218. tx_skb = skb_clone(skb, GFP_ATOMIC);
  1219. if (!tx_skb)
  1220. break;
  1221. sock_hold(sk);
  1222. tx_skb->sk = sk;
  1223. tx_skb->destructor = l2cap_skb_destructor;
  1224. atomic_inc(&pi->ertm_queued);
  1225. l2cap_ertm_start_retrans_timer(pi);
  1226. pi->next_tx_seq = __next_seq(pi->next_tx_seq, pi);
  1227. pi->unacked_frames += 1;
  1228. pi->frames_sent += 1;
  1229. sent += 1;
  1230. if (skb_queue_is_last(TX_QUEUE(sk), skb))
  1231. sk->sk_send_head = NULL;
  1232. else
  1233. sk->sk_send_head = skb_queue_next(TX_QUEUE(sk), skb);
  1234. l2cap_do_send(sk, tx_skb);
  1235. BT_DBG("Sent txseq %d", (int)control->txseq);
  1236. }
  1237. BT_DBG("Sent %d, %d unacked, %d in ERTM queue, %d in HCI queue", sent,
  1238. (int) pi->unacked_frames, skb_queue_len(TX_QUEUE(sk)),
  1239. atomic_read(&pi->ertm_queued));
  1240. return sent;
  1241. }
  1242. int l2cap_strm_tx(struct sock *sk, struct sk_buff_head *skbs)
  1243. {
  1244. struct sk_buff *skb;
  1245. struct l2cap_pinfo *pi = l2cap_pi(sk);
  1246. struct bt_l2cap_control *control;
  1247. int sent = 0;
  1248. BT_DBG("sk %p, skbs %p", sk, skbs);
  1249. if (sk->sk_state != BT_CONNECTED)
  1250. return -ENOTCONN;
  1251. if (pi->amp_move_state != L2CAP_AMP_STATE_STABLE &&
  1252. pi->amp_move_state != L2CAP_AMP_STATE_WAIT_PREPARE)
  1253. return 0;
  1254. skb_queue_splice_tail_init(skbs, TX_QUEUE(sk));
  1255. BT_DBG("skb queue empty 0x%2.2x", skb_queue_empty(TX_QUEUE(sk)));
  1256. while (!skb_queue_empty(TX_QUEUE(sk))) {
  1257. skb = skb_dequeue(TX_QUEUE(sk));
  1258. BT_DBG("skb %p", skb);
  1259. bt_cb(skb)->retries = 1;
  1260. control = &bt_cb(skb)->control;
  1261. BT_DBG("control %p", control);
  1262. control->reqseq = 0;
  1263. control->txseq = pi->next_tx_seq;
  1264. if (pi->extended_control) {
  1265. put_unaligned_le32(__pack_extended_control(control),
  1266. skb->data + L2CAP_HDR_SIZE);
  1267. } else {
  1268. put_unaligned_le16(__pack_enhanced_control(control),
  1269. skb->data + L2CAP_HDR_SIZE);
  1270. }
  1271. if (pi->fcs == L2CAP_FCS_CRC16)
  1272. apply_fcs(skb);
  1273. l2cap_do_send(sk, skb);
  1274. BT_DBG("Sent txseq %d", (int)control->txseq);
  1275. pi->next_tx_seq = __next_seq(pi->next_tx_seq, pi);
  1276. pi->frames_sent += 1;
  1277. sent += 1;
  1278. }
  1279. BT_DBG("Sent %d", sent);
  1280. return 0;
  1281. }
  1282. static int memcpy_fromkvec(unsigned char *kdata, struct kvec *iv, int len)
  1283. {
  1284. while (len > 0) {
  1285. if (iv->iov_len) {
  1286. int copy = min_t(unsigned int, len, iv->iov_len);
  1287. memcpy(kdata, iv->iov_base, copy);
  1288. len -= copy;
  1289. kdata += copy;
  1290. iv->iov_base += copy;
  1291. iv->iov_len -= copy;
  1292. }
  1293. iv++;
  1294. }
  1295. return 0;
  1296. }
  1297. static inline int l2cap_skbuff_fromiovec(struct sock *sk, struct msghdr *msg,
  1298. int len, int count, struct sk_buff *skb,
  1299. int reseg)
  1300. {
  1301. struct l2cap_conn *conn = l2cap_pi(sk)->conn;
  1302. struct sk_buff **frag;
  1303. struct sk_buff *final;
  1304. int err, sent = 0;
  1305. BT_DBG("sk %p, msg %p, len %d, count %d, skb %p", sk,
  1306. msg, (int)len, (int)count, skb);
  1307. if (!conn)
  1308. return -ENOTCONN;
  1309. /* When resegmenting, data is copied from kernel space */
  1310. if (reseg) {
  1311. err = memcpy_fromkvec(skb_put(skb, count),
  1312. (struct kvec *) msg->msg_iov, count);
  1313. } else {
  1314. err = memcpy_fromiovec(skb_put(skb, count), msg->msg_iov,
  1315. count);
  1316. }
  1317. if (err)
  1318. return -EFAULT;
  1319. sent += count;
  1320. len -= count;
  1321. final = skb;
  1322. /* Continuation fragments (no L2CAP header) */
  1323. frag = &skb_shinfo(skb)->frag_list;
  1324. while (len) {
  1325. int skblen;
  1326. count = min_t(unsigned int, conn->mtu, len);
  1327. /* Add room for the FCS if it fits */
  1328. if (bt_cb(skb)->control.fcs == L2CAP_FCS_CRC16 &&
  1329. len + L2CAP_FCS_SIZE <= conn->mtu)
  1330. skblen = count + L2CAP_FCS_SIZE;
  1331. else
  1332. skblen = count;
  1333. /* Don't use bt_skb_send_alloc() while resegmenting, since
  1334. * it is not ok to block.
  1335. */
  1336. if (reseg) {
  1337. *frag = bt_skb_alloc(skblen, GFP_ATOMIC);
  1338. if (*frag)
  1339. skb_set_owner_w(*frag, sk);
  1340. } else {
  1341. *frag = bt_skb_send_alloc(sk, skblen,
  1342. msg->msg_flags & MSG_DONTWAIT, &err);
  1343. }
  1344. if (!*frag)
  1345. return -EFAULT;
  1346. /* When resegmenting, data is copied from kernel space */
  1347. if (reseg) {
  1348. err = memcpy_fromkvec(skb_put(*frag, count),
  1349. (struct kvec *) msg->msg_iov,
  1350. count);
  1351. } else {
  1352. err = memcpy_fromiovec(skb_put(*frag, count),
  1353. msg->msg_iov, count);
  1354. }
  1355. if (err)
  1356. return -EFAULT;
  1357. sent += count;
  1358. len -= count;
  1359. final = *frag;
  1360. frag = &(*frag)->next;
  1361. }
  1362. if (bt_cb(skb)->control.fcs == L2CAP_FCS_CRC16) {
  1363. if (skb_tailroom(final) < L2CAP_FCS_SIZE) {
  1364. if (reseg) {
  1365. *frag = bt_skb_alloc(L2CAP_FCS_SIZE,
  1366. GFP_ATOMIC);
  1367. if (*frag)
  1368. skb_set_owner_w(*frag, sk);
  1369. } else {
  1370. *frag = bt_skb_send_alloc(sk, L2CAP_FCS_SIZE,
  1371. msg->msg_flags & MSG_DONTWAIT,
  1372. &err);
  1373. }
  1374. if (!*frag)
  1375. return -EFAULT;
  1376. final = *frag;
  1377. }
  1378. skb_put(final, L2CAP_FCS_SIZE);
  1379. }
  1380. return sent;
  1381. }
  1382. struct sk_buff *l2cap_create_connless_pdu(struct sock *sk, struct msghdr *msg, size_t len)
  1383. {
  1384. struct l2cap_conn *conn = l2cap_pi(sk)->conn;
  1385. struct sk_buff *skb;
  1386. int err, count, hlen = L2CAP_HDR_SIZE + 2;
  1387. struct l2cap_hdr *lh;
  1388. BT_DBG("sk %p len %d", sk, (int)len);
  1389. count = min_t(unsigned int, (conn->mtu - hlen), len);
  1390. skb = bt_skb_send_alloc(sk, count + hlen,
  1391. msg->msg_flags & MSG_DONTWAIT, &err);
  1392. if (!skb)
  1393. return ERR_PTR(err);
  1394. /* Create L2CAP header */
  1395. lh = (struct l2cap_hdr *) skb_put(skb, L2CAP_HDR_SIZE);
  1396. lh->cid = cpu_to_le16(l2cap_pi(sk)->dcid);
  1397. lh->len = cpu_to_le16(len + (hlen - L2CAP_HDR_SIZE));
  1398. put_unaligned_le16(l2cap_pi(sk)->psm, skb_put(skb, 2));
  1399. err = l2cap_skbuff_fromiovec(sk, msg, len, count, skb, 0);
  1400. if (unlikely(err < 0)) {
  1401. kfree_skb(skb);
  1402. return ERR_PTR(err);
  1403. }
  1404. return skb;
  1405. }
  1406. struct sk_buff *l2cap_create_basic_pdu(struct sock *sk, struct msghdr *msg, size_t len)
  1407. {
  1408. struct l2cap_conn *conn = l2cap_pi(sk)->conn;
  1409. struct sk_buff *skb;
  1410. int err, count, hlen = L2CAP_HDR_SIZE;
  1411. struct l2cap_hdr *lh;
  1412. BT_DBG("sk %p len %d", sk, (int)len);
  1413. count = min_t(unsigned int, (conn->mtu - hlen), len);
  1414. skb = bt_skb_send_alloc(sk, count + hlen,
  1415. msg->msg_flags & MSG_DONTWAIT, &err);
  1416. if (!skb)
  1417. return ERR_PTR(err);
  1418. /* Create L2CAP header */
  1419. lh = (struct l2cap_hdr *) skb_put(skb, L2CAP_HDR_SIZE);
  1420. lh->cid = cpu_to_le16(l2cap_pi(sk)->dcid);
  1421. lh->len = cpu_to_le16(len + (hlen - L2CAP_HDR_SIZE));
  1422. err = l2cap_skbuff_fromiovec(sk, msg, len, count, skb, 0);
  1423. if (unlikely(err < 0)) {
  1424. kfree_skb(skb);
  1425. return ERR_PTR(err);
  1426. }
  1427. return skb;
  1428. }
  1429. struct sk_buff *l2cap_create_iframe_pdu(struct sock *sk,
  1430. struct msghdr *msg, size_t len,
  1431. u16 sdulen, int reseg)
  1432. {
  1433. struct sk_buff *skb;
  1434. int err, count, hlen;
  1435. int reserve = 0;
  1436. struct l2cap_hdr *lh;
  1437. u8 fcs = l2cap_pi(sk)->fcs;
  1438. if (l2cap_pi(sk)->extended_control)
  1439. hlen = L2CAP_EXTENDED_HDR_SIZE;
  1440. else
  1441. hlen = L2CAP_ENHANCED_HDR_SIZE;
  1442. if (sdulen)
  1443. hlen += L2CAP_SDULEN_SIZE;
  1444. if (fcs == L2CAP_FCS_CRC16)
  1445. hlen += L2CAP_FCS_SIZE;
  1446. BT_DBG("sk %p, msg %p, len %d, sdulen %d, hlen %d",
  1447. sk, msg, (int)len, (int)sdulen, hlen);
  1448. count = min_t(unsigned int, (l2cap_pi(sk)->conn->mtu - hlen), len);
  1449. /* Allocate extra headroom for Qualcomm PAL. This is only
  1450. * necessary in two places (here and when creating sframes)
  1451. * because only unfragmented iframes and sframes are sent
  1452. * using AMP controllers.
  1453. */
  1454. if (l2cap_pi(sk)->ampcon &&
  1455. l2cap_pi(sk)->ampcon->hdev->manufacturer == 0x001d)
  1456. reserve = BT_SKB_RESERVE_80211;
  1457. /* Don't use bt_skb_send_alloc() while resegmenting, since
  1458. * it is not ok to block.
  1459. */
  1460. if (reseg) {
  1461. skb = bt_skb_alloc(count + hlen + reserve, GFP_ATOMIC);
  1462. if (skb)
  1463. skb_set_owner_w(skb, sk);
  1464. } else {
  1465. skb = bt_skb_send_alloc(sk, count + hlen + reserve,
  1466. msg->msg_flags & MSG_DONTWAIT, &err);
  1467. }
  1468. if (!skb)
  1469. return ERR_PTR(err);
  1470. if (reserve)
  1471. skb_reserve(skb, reserve);
  1472. bt_cb(skb)->control.fcs = fcs;
  1473. /* Create L2CAP header */
  1474. lh = (struct l2cap_hdr *) skb_put(skb, L2CAP_HDR_SIZE);
  1475. lh->cid = cpu_to_le16(l2cap_pi(sk)->dcid);
  1476. lh->len = cpu_to_le16(len + hlen - L2CAP_HDR_SIZE);
  1477. /* Control header is populated later */
  1478. if (l2cap_pi(sk)->extended_control)
  1479. put_unaligned_le32(0, skb_put(skb, 4));
  1480. else
  1481. put_unaligned_le16(0, skb_put(skb, 2));
  1482. if (sdulen)
  1483. put_unaligned_le16(sdulen, skb_put(skb, L2CAP_SDULEN_SIZE));
  1484. err = l2cap_skbuff_fromiovec(sk, msg, len, count, skb, reseg);
  1485. if (unlikely(err < 0)) {
  1486. BT_DBG("err %d", err);
  1487. kfree_skb(skb);
  1488. return ERR_PTR(err);
  1489. }
  1490. bt_cb(skb)->retries = 0;
  1491. return skb;
  1492. }
  1493. static void l2cap_ertm_process_reqseq(struct sock *sk, u16 reqseq)
  1494. {
  1495. struct l2cap_pinfo *pi;
  1496. struct sk_buff *acked_skb;
  1497. u16 ackseq;
  1498. BT_DBG("sk %p, reqseq %d", sk, (int) reqseq);
  1499. pi = l2cap_pi(sk);
  1500. if (pi->unacked_frames == 0 || reqseq == pi->expected_ack_seq)
  1501. return;
  1502. BT_DBG("expected_ack_seq %d, unacked_frames %d",
  1503. (int) pi->expected_ack_seq, (int) pi->unacked_frames);
  1504. for (ackseq = pi->expected_ack_seq; ackseq != reqseq;
  1505. ackseq = __next_seq(ackseq, pi)) {
  1506. acked_skb = l2cap_ertm_seq_in_queue(TX_QUEUE(sk), ackseq);
  1507. if (acked_skb) {
  1508. skb_unlink(acked_skb, TX_QUEUE(sk));
  1509. kfree_skb(acked_skb);
  1510. pi->unacked_frames--;
  1511. }
  1512. }
  1513. pi->expected_ack_seq = reqseq;
  1514. if (pi->unacked_frames == 0)
  1515. l2cap_ertm_stop_retrans_timer(pi);
  1516. BT_DBG("unacked_frames %d", (int) pi->unacked_frames);
  1517. }
  1518. static struct sk_buff *l2cap_create_sframe_pdu(struct sock *sk, u32 control)
  1519. {
  1520. struct sk_buff *skb;
  1521. int len;
  1522. int reserve = 0;
  1523. struct l2cap_hdr *lh;
  1524. if (l2cap_pi(sk)->extended_control)
  1525. len = L2CAP_EXTENDED_HDR_SIZE;
  1526. else
  1527. len = L2CAP_ENHANCED_HDR_SIZE;
  1528. if (l2cap_pi(sk)->fcs == L2CAP_FCS_CRC16)
  1529. len += L2CAP_FCS_SIZE;
  1530. /* Allocate extra headroom for Qualcomm PAL */
  1531. if (l2cap_pi(sk)->ampcon &&
  1532. l2cap_pi(sk)->ampcon->hdev->manufacturer == 0x001d)
  1533. reserve = BT_SKB_RESERVE_80211;
  1534. skb = bt_skb_alloc(len + reserve, GFP_ATOMIC);
  1535. if (!skb)
  1536. return ERR_PTR(-ENOMEM);
  1537. if (reserve)
  1538. skb_reserve(skb, reserve);
  1539. lh = (struct l2cap_hdr *) skb_put(skb, L2CAP_HDR_SIZE);
  1540. lh->cid = cpu_to_le16(l2cap_pi(sk)->dcid);
  1541. lh->len = cpu_to_le16(len - L2CAP_HDR_SIZE);
  1542. if (l2cap_pi(sk)->extended_control)
  1543. put_unaligned_le32(control, skb_put(skb, 4));
  1544. else
  1545. put_unaligned_le16(control, skb_put(skb, 2));
  1546. if (l2cap_pi(sk)->fcs == L2CAP_FCS_CRC16) {
  1547. u16 fcs = crc16(0, (u8 *) skb->data, skb->len);
  1548. put_unaligned_le16(fcs, skb_put(skb, L2CAP_FCS_SIZE));
  1549. }
  1550. return skb;
  1551. }
  1552. static void l2cap_ertm_send_sframe(struct sock *sk,
  1553. struct bt_l2cap_control *control)
  1554. {
  1555. struct l2cap_pinfo *pi;
  1556. struct sk_buff *skb;
  1557. u32 control_field;
  1558. BT_DBG("sk %p, control %p", sk, control);
  1559. if (control->frame_type != 's')
  1560. return;
  1561. pi = l2cap_pi(sk);
  1562. if (pi->amp_move_state != L2CAP_AMP_STATE_STABLE &&
  1563. pi->amp_move_state != L2CAP_AMP_STATE_WAIT_PREPARE &&
  1564. pi->amp_move_state != L2CAP_AMP_STATE_RESEGMENT) {
  1565. BT_DBG("AMP error - attempted S-Frame send during AMP move");
  1566. return;
  1567. }
  1568. if ((pi->conn_state & L2CAP_CONN_SEND_FBIT) && !control->poll) {
  1569. control->final = 1;
  1570. pi->conn_state &= ~L2CAP_CONN_SEND_FBIT;
  1571. }
  1572. if (control->super == L2CAP_SFRAME_RR)
  1573. pi->conn_state &= ~L2CAP_CONN_SENT_RNR;
  1574. else if (control->super == L2CAP_SFRAME_RNR)
  1575. pi->conn_state |= L2CAP_CONN_SENT_RNR;
  1576. if (control->super != L2CAP_SFRAME_SREJ) {
  1577. pi->last_acked_seq = control->reqseq;
  1578. l2cap_ertm_stop_ack_timer(pi);
  1579. }
  1580. BT_DBG("reqseq %d, final %d, poll %d, super %d", (int) control->reqseq,
  1581. (int) control->final, (int) control->poll,
  1582. (int) control->super);
  1583. if (pi->extended_control)
  1584. control_field = __pack_extended_control(control);
  1585. else
  1586. control_field = __pack_enhanced_control(control);
  1587. skb = l2cap_create_sframe_pdu(sk, control_field);
  1588. if (!IS_ERR(skb))
  1589. l2cap_do_send(sk, skb);
  1590. }
  1591. static void l2cap_ertm_send_ack(struct sock *sk)
  1592. {
  1593. struct l2cap_pinfo *pi = l2cap_pi(sk);
  1594. struct bt_l2cap_control control;
  1595. u16 frames_to_ack = __delta_seq(pi->buffer_seq, pi->last_acked_seq, pi);
  1596. int threshold;
  1597. BT_DBG("sk %p", sk);
  1598. BT_DBG("last_acked_seq %d, buffer_seq %d", (int)pi->last_acked_seq,
  1599. (int)pi->buffer_seq);
  1600. memset(&control, 0, sizeof(control));
  1601. control.frame_type = 's';
  1602. if ((pi->conn_state & L2CAP_CONN_LOCAL_BUSY) &&
  1603. pi->rx_state == L2CAP_ERTM_RX_STATE_RECV) {
  1604. l2cap_ertm_stop_ack_timer(pi);
  1605. control.super = L2CAP_SFRAME_RNR;
  1606. control.reqseq = pi->buffer_seq;
  1607. l2cap_ertm_send_sframe(sk, &control);
  1608. } else {
  1609. if (!(pi->conn_state & L2CAP_CONN_REMOTE_BUSY)) {
  1610. l2cap_ertm_send(sk);
  1611. /* If any i-frames were sent, they included an ack */
  1612. if (pi->buffer_seq == pi->last_acked_seq)
  1613. frames_to_ack = 0;
  1614. }
  1615. /* Ack now if the window is 3/4ths full.
  1616. * Calculate without mul or div
  1617. */
  1618. threshold = pi->ack_win;
  1619. threshold += threshold << 1;
  1620. threshold >>= 2;
  1621. BT_DBG("frames_to_ack %d, threshold %d", (int)frames_to_ack,
  1622. threshold);
  1623. if (frames_to_ack >= threshold) {
  1624. l2cap_ertm_stop_ack_timer(pi);
  1625. control.super = L2CAP_SFRAME_RR;
  1626. control.reqseq = pi->buffer_seq;
  1627. l2cap_ertm_send_sframe(sk, &control);
  1628. frames_to_ack = 0;
  1629. }
  1630. if (frames_to_ack)
  1631. l2cap_ertm_start_ack_timer(pi);
  1632. }
  1633. }
  1634. static void l2cap_ertm_send_rr_or_rnr(struct sock *sk, bool poll)
  1635. {
  1636. struct l2cap_pinfo *pi;
  1637. struct bt_l2cap_control control;
  1638. BT_DBG("sk %p, poll %d", sk, (int) poll);
  1639. pi = l2cap_pi(sk);
  1640. memset(&control, 0, sizeof(control));
  1641. control.frame_type = 's';
  1642. control.poll = poll;
  1643. if (pi->conn_state & L2CAP_CONN_LOCAL_BUSY)
  1644. control.super = L2CAP_SFRAME_RNR;
  1645. else
  1646. control.super = L2CAP_SFRAME_RR;
  1647. control.reqseq = pi->buffer_seq;
  1648. l2cap_ertm_send_sframe(sk, &control);
  1649. }
  1650. static void l2cap_ertm_send_i_or_rr_or_rnr(struct sock *sk)
  1651. {
  1652. struct l2cap_pinfo *pi;
  1653. struct bt_l2cap_control control;
  1654. BT_DBG("sk %p", sk);
  1655. pi = l2cap_pi(sk);
  1656. memset(&control, 0, sizeof(control));
  1657. control.frame_type = 's';
  1658. control.final = 1;
  1659. control.reqseq = pi->buffer_seq;
  1660. pi->conn_state |= L2CAP_CONN_SEND_FBIT;
  1661. if (pi->conn_state & L2CAP_CONN_LOCAL_BUSY) {
  1662. control.super = L2CAP_SFRAME_RNR;
  1663. l2cap_ertm_send_sframe(sk, &control);
  1664. }
  1665. if ((pi->conn_state & L2CAP_CONN_REMOTE_BUSY) &&
  1666. (pi->unacked_frames > 0))
  1667. l2cap_ertm_start_retrans_timer(pi);
  1668. pi->conn_state &= ~L2CAP_CONN_REMOTE_BUSY;
  1669. /* Send pending iframes */
  1670. l2cap_ertm_send(sk);
  1671. if (pi->conn_state & L2CAP_CONN_SEND_FBIT) {
  1672. /* F-bit wasn't sent in an s-frame or i-frame yet, so
  1673. * send it now.
  1674. */
  1675. control.super = L2CAP_SFRAME_RR;
  1676. l2cap_ertm_send_sframe(sk, &control);
  1677. }
  1678. }
  1679. static void l2cap_ertm_send_srej(struct sock *sk, u16 txseq)
  1680. {
  1681. struct bt_l2cap_control control;
  1682. struct l2cap_pinfo *pi;
  1683. u16 seq;
  1684. BT_DBG("sk %p, txseq %d", sk, (int)txseq);
  1685. pi = l2cap_pi(sk);
  1686. memset(&control, 0, sizeof(control));
  1687. control.frame_type = 's';
  1688. control.super = L2CAP_SFRAME_SREJ;
  1689. for (seq = pi->expected_tx_seq; seq != txseq;
  1690. seq = __next_seq(seq, pi)) {
  1691. if (!l2cap_ertm_seq_in_queue(SREJ_QUEUE(pi), seq)) {
  1692. control.reqseq = seq;
  1693. l2cap_ertm_send_sframe(sk, &control);
  1694. l2cap_seq_list_append(&pi->srej_list, seq);
  1695. }
  1696. }
  1697. pi->expected_tx_seq = __next_seq(txseq, pi);
  1698. }
  1699. static void l2cap_ertm_send_srej_tail(struct sock *sk)
  1700. {
  1701. struct bt_l2cap_control control;
  1702. struct l2cap_pinfo *pi;
  1703. BT_DBG("sk %p", sk);
  1704. pi = l2cap_pi(sk);
  1705. if (pi->srej_list.tail == L2CAP_SEQ_LIST_CLEAR)
  1706. return;
  1707. memset(&control, 0, sizeof(control));
  1708. control.frame_type = 's';
  1709. control.super = L2CAP_SFRAME_SREJ;
  1710. control.reqseq = pi->srej_list.tail;
  1711. l2cap_ertm_send_sframe(sk, &control);
  1712. }
  1713. static void l2cap_ertm_send_srej_list(struct sock *sk, u16 txseq)
  1714. {
  1715. struct bt_l2cap_control control;
  1716. struct l2cap_pinfo *pi;
  1717. u16 initial_head;
  1718. u16 seq;
  1719. BT_DBG("sk %p, txseq %d", sk, (int) txseq);
  1720. pi = l2cap_pi(sk);
  1721. memset(&control, 0, sizeof(control));
  1722. control.frame_type = 's';
  1723. control.super = L2CAP_SFRAME_SREJ;
  1724. /* Capture initial list head to allow only one pass through the list. */
  1725. initial_head = pi->srej_list.head;
  1726. do {
  1727. seq = l2cap_seq_list_pop(&pi->srej_list);
  1728. if ((seq == txseq) || (seq == L2CAP_SEQ_LIST_CLEAR))
  1729. break;
  1730. control.reqseq = seq;
  1731. l2cap_ertm_send_sframe(sk, &control);
  1732. l2cap_seq_list_append(&pi->srej_list, seq);
  1733. } while (pi->srej_list.head != initial_head);
  1734. }
  1735. static void l2cap_ertm_abort_rx_srej_sent(struct sock *sk)
  1736. {
  1737. struct l2cap_pinfo *pi = l2cap_pi(sk);
  1738. BT_DBG("sk %p", sk);
  1739. pi->expected_tx_seq = pi->buffer_seq;
  1740. l2cap_seq_list_clear(&l2cap_pi(sk)->srej_list);
  1741. skb_queue_purge(SREJ_QUEUE(sk));
  1742. pi->rx_state = L2CAP_ERTM_RX_STATE_RECV;
  1743. }
  1744. static int l2cap_ertm_tx_state_xmit(struct sock *sk,
  1745. struct bt_l2cap_control *control,
  1746. struct sk_buff_head *skbs, u8 event)
  1747. {
  1748. struct l2cap_pinfo *pi;
  1749. int err = 0;
  1750. BT_DBG("sk %p, control %p, skbs %p, event %d", sk, control, skbs,
  1751. (int)event);
  1752. pi = l2cap_pi(sk);
  1753. switch (event) {
  1754. case L2CAP_ERTM_EVENT_DATA_REQUEST:
  1755. if (sk->sk_send_head == NULL)
  1756. sk->sk_send_head = skb_peek(skbs);
  1757. skb_queue_splice_tail_init(skbs, TX_QUEUE(sk));
  1758. l2cap_ertm_send(sk);
  1759. break;
  1760. case L2CAP_ERTM_EVENT_LOCAL_BUSY_DETECTED:
  1761. BT_DBG("Enter LOCAL_BUSY");
  1762. pi->conn_state |= L2CAP_CONN_LOCAL_BUSY;
  1763. if (pi->rx_state == L2CAP_ERTM_RX_STATE_SREJ_SENT) {
  1764. /* The SREJ_SENT state must be aborted if we are to
  1765. * enter the LOCAL_BUSY state.
  1766. */
  1767. l2cap_ertm_abort_rx_srej_sent(sk);
  1768. }
  1769. l2cap_ertm_send_ack(sk);
  1770. break;
  1771. case L2CAP_ERTM_EVENT_LOCAL_BUSY_CLEAR:
  1772. BT_DBG("Exit LOCAL_BUSY");
  1773. pi->conn_state &= ~L2CAP_CONN_LOCAL_BUSY;
  1774. if (pi->amp_move_state == L2CAP_AMP_STATE_WAIT_LOCAL_BUSY) {
  1775. if (pi->amp_move_role == L2CAP_AMP_MOVE_INITIATOR) {
  1776. pi->amp_move_state =
  1777. L2CAP_AMP_STATE_WAIT_MOVE_CONFIRM_RSP;
  1778. l2cap_send_move_chan_cfm(pi->conn, pi,
  1779. pi->scid,
  1780. L2CAP_MOVE_CHAN_CONFIRMED);
  1781. l2cap_sock_set_timer(sk, L2CAP_MOVE_TIMEOUT);
  1782. } else if (pi->amp_move_role ==
  1783. L2CAP_AMP_MOVE_RESPONDER) {
  1784. pi->amp_move_state =
  1785. L2CAP_AMP_STATE_WAIT_MOVE_CONFIRM;
  1786. l2cap_send_move_chan_rsp(pi->conn,
  1787. pi->amp_move_cmd_ident,
  1788. pi->dcid,
  1789. L2CAP_MOVE_CHAN_SUCCESS);
  1790. }
  1791. break;
  1792. }
  1793. if (pi->amp_move_role == L2CAP_AMP_MOVE_NONE &&
  1794. (pi->conn_state & L2CAP_CONN_SENT_RNR)) {
  1795. struct bt_l2cap_control local_control;
  1796. memset(&local_control, 0, sizeof(local_control));
  1797. local_control.frame_type = 's';
  1798. local_control.super = L2CAP_SFRAME_RR;
  1799. local_control.poll = 1;
  1800. local_control.reqseq = pi->buffer_seq;
  1801. l2cap_ertm_send_sframe(sk, &local_control);
  1802. pi->retry_count = 1;
  1803. l2cap_ertm_start_monitor_timer(pi);
  1804. pi->tx_state = L2CAP_ERTM_TX_STATE_WAIT_F;
  1805. }
  1806. break;
  1807. case L2CAP_ERTM_EVENT_RECV_REQSEQ_AND_FBIT:
  1808. l2cap_ertm_process_reqseq(sk, control->reqseq);
  1809. break;
  1810. case L2CAP_ERTM_EVENT_EXPLICIT_POLL:
  1811. l2cap_ertm_send_rr_or_rnr(sk, 1);
  1812. pi->retry_count = 1;
  1813. l2cap_ertm_start_monitor_timer(pi);
  1814. l2cap_ertm_stop_ack_timer(pi);
  1815. pi->tx_state = L2CAP_ERTM_TX_STATE_WAIT_F;
  1816. break;
  1817. case L2CAP_ERTM_EVENT_RETRANS_TIMER_EXPIRES:
  1818. l2cap_ertm_send_rr_or_rnr(sk, 1);
  1819. pi->retry_count = 1;
  1820. l2cap_ertm_start_monitor_timer(pi);
  1821. pi->tx_state = L2CAP_ERTM_TX_STATE_WAIT_F;
  1822. break;
  1823. case L2CAP_ERTM_EVENT_RECV_FBIT:
  1824. /* Nothing to process */
  1825. break;
  1826. default:
  1827. break;
  1828. }
  1829. return err;
  1830. }
  1831. static int l2cap_ertm_tx_state_wait_f(struct sock *sk,
  1832. struct bt_l2cap_control *control,
  1833. struct sk_buff_head *skbs, u8 event)
  1834. {
  1835. struct l2cap_pinfo *pi;
  1836. int err = 0;
  1837. BT_DBG("sk %p, control %p, skbs %p, event %d", sk, control, skbs,
  1838. (int)event);
  1839. pi = l2cap_pi(sk);
  1840. switch (event) {
  1841. case L2CAP_ERTM_EVENT_DATA_REQUEST:
  1842. if (sk->sk_send_head == NULL)
  1843. sk->sk_send_head = skb_peek(skbs);
  1844. /* Queue data, but don't send. */
  1845. skb_queue_splice_tail_init(skbs, TX_QUEUE(sk));
  1846. break;
  1847. case L2CAP_ERTM_EVENT_LOCAL_BUSY_DETECTED:
  1848. BT_DBG("Enter LOCAL_BUSY");
  1849. pi->conn_state |= L2CAP_CONN_LOCAL_BUSY;
  1850. if (pi->rx_state == L2CAP_ERTM_RX_STATE_SREJ_SENT) {
  1851. /* The SREJ_SENT state must be aborted if we are to
  1852. * enter the LOCAL_BUSY state.
  1853. */
  1854. l2cap_ertm_abort_rx_srej_sent(sk);
  1855. }
  1856. l2cap_ertm_send_ack(sk);
  1857. break;
  1858. case L2CAP_ERTM_EVENT_LOCAL_BUSY_CLEAR:
  1859. BT_DBG("Exit LOCAL_BUSY");
  1860. pi->conn_state &= ~L2CAP_CONN_LOCAL_BUSY;
  1861. if (pi->conn_state & L2CAP_CONN_SENT_RNR) {
  1862. struct bt_l2cap_control local_control;
  1863. memset(&local_control, 0, sizeof(local_control));
  1864. local_control.frame_type = 's';
  1865. local_control.super = L2CAP_SFRAME_RR;
  1866. local_control.poll = 1;
  1867. local_control.reqseq = pi->buffer_seq;
  1868. l2cap_ertm_send_sframe(sk, &local_control);
  1869. pi->retry_count = 1;
  1870. l2cap_ertm_start_monitor_timer(pi);
  1871. pi->tx_state = L2CAP_ERTM_TX_STATE_WAIT_F;
  1872. }
  1873. break;
  1874. case L2CAP_ERTM_EVENT_RECV_REQSEQ_AND_FBIT:
  1875. l2cap_ertm_process_reqseq(sk, control->reqseq);
  1876. /* Fall through */
  1877. case L2CAP_ERTM_EVENT_RECV_FBIT:
  1878. if (control && control->final) {
  1879. l2cap_ertm_stop_monitor_timer(pi);
  1880. if (pi->unacked_frames > 0)
  1881. l2cap_ertm_start_retrans_timer(pi);
  1882. pi->retry_count = 0;
  1883. pi->tx_state = L2CAP_ERTM_TX_STATE_XMIT;
  1884. BT_DBG("recv fbit tx_state 0x2.2%x", pi->tx_state);
  1885. }
  1886. break;
  1887. case L2CAP_ERTM_EVENT_EXPLICIT_POLL:
  1888. /* Ignore */
  1889. break;
  1890. case L2CAP_ERTM_EVENT_MONITOR_TIMER_EXPIRES:
  1891. if ((pi->max_tx == 0) || (pi->retry_count < pi->max_tx)) {
  1892. l2cap_ertm_send_rr_or_rnr(sk, 1);
  1893. l2cap_ertm_start_monitor_timer(pi);
  1894. pi->retry_count += 1;
  1895. } else
  1896. l2cap_send_disconn_req(pi->conn, sk, ECONNABORTED);
  1897. break;
  1898. default:
  1899. break;
  1900. }
  1901. return err;
  1902. }
  1903. int l2cap_ertm_tx(struct sock *sk, struct bt_l2cap_control *control,
  1904. struct sk_buff_head *skbs, u8 event)
  1905. {
  1906. struct l2cap_pinfo *pi;
  1907. int err = 0;
  1908. BT_DBG("sk %p, control %p, skbs %p, event %d, state %d",
  1909. sk, control, skbs, (int)event, l2cap_pi(sk)->tx_state);
  1910. pi = l2cap_pi(sk);
  1911. switch (pi->tx_state) {
  1912. case L2CAP_ERTM_TX_STATE_XMIT:
  1913. err = l2cap_ertm_tx_state_xmit(sk, control, skbs, event);
  1914. break;
  1915. case L2CAP_ERTM_TX_STATE_WAIT_F:
  1916. err = l2cap_ertm_tx_state_wait_f(sk, control, skbs, event);
  1917. break;
  1918. default:
  1919. /* Ignore event */
  1920. break;
  1921. }
  1922. return err;
  1923. }
  1924. int l2cap_segment_sdu(struct sock *sk, struct sk_buff_head* seg_queue,
  1925. struct msghdr *msg, size_t len, int reseg)
  1926. {
  1927. struct sk_buff *skb;
  1928. u16 sdu_len;
  1929. size_t pdu_len;
  1930. int err = 0;
  1931. u8 sar;
  1932. BT_DBG("sk %p, msg %p, len %d", sk, msg, (int)len);
  1933. /* It is critical that ERTM PDUs fit in a single HCI fragment,
  1934. * so fragmented skbs are not used. The HCI layer's handling
  1935. * of fragmented skbs is not compatible with ERTM's queueing.
  1936. */
  1937. /* PDU size is derived from the HCI MTU */
  1938. pdu_len = l2cap_pi(sk)->conn->mtu;
  1939. /* Constrain BR/EDR PDU size to fit within the largest radio packet */
  1940. if (!l2cap_pi(sk)->ampcon)
  1941. pdu_len = min_t(size_t, pdu_len, L2CAP_BREDR_MAX_PAYLOAD);
  1942. /* Adjust for largest possible L2CAP overhead. */
  1943. pdu_len -= L2CAP_EXTENDED_HDR_SIZE + L2CAP_FCS_SIZE;
  1944. /* Remote device may have requested smaller PDUs */
  1945. pdu_len = min_t(size_t, pdu_len, l2cap_pi(sk)->remote_mps);
  1946. if (len <= pdu_len) {
  1947. sar = L2CAP_SAR_UNSEGMENTED;
  1948. sdu_len = 0;
  1949. pdu_len = len;
  1950. } else {
  1951. sar = L2CAP_SAR_START;
  1952. sdu_len = len;
  1953. pdu_len -= L2CAP_SDULEN_SIZE;
  1954. }
  1955. while (len) {
  1956. skb = l2cap_create_iframe_pdu(sk, msg, pdu_len, sdu_len, reseg);
  1957. BT_DBG("iframe skb %p", skb);
  1958. if (IS_ERR(skb)) {
  1959. __skb_queue_purge(seg_queue);
  1960. return PTR_ERR(skb);
  1961. }
  1962. bt_cb(skb)->control.sar = sar;
  1963. __skb_queue_tail(seg_queue, skb);
  1964. len -= pdu_len;
  1965. if (sdu_len) {
  1966. sdu_len = 0;
  1967. pdu_len += L2CAP_SDULEN_SIZE;
  1968. }
  1969. if (len <= pdu_len) {
  1970. sar = L2CAP_SAR_END;
  1971. pdu_len = len;
  1972. } else {
  1973. sar = L2CAP_SAR_CONTINUE;
  1974. }
  1975. }
  1976. return err;
  1977. }
  1978. static inline int is_initial_frame(u8 sar)
  1979. {
  1980. return (sar == L2CAP_SAR_UNSEGMENTED ||
  1981. sar == L2CAP_SAR_START);
  1982. }
  1983. static inline int l2cap_skbuff_to_kvec(struct sk_buff *skb, struct kvec *iv,
  1984. size_t veclen)
  1985. {
  1986. struct sk_buff *frag_iter;
  1987. BT_DBG("skb %p (len %d), iv %p", skb, (int)skb->len, iv);
  1988. if (iv->iov_len + skb->len > veclen)
  1989. return -ENOMEM;
  1990. memcpy(iv->iov_base + iv->iov_len, skb->data, skb->len);
  1991. iv->iov_len += skb->len;
  1992. skb_walk_frags(skb, frag_iter) {
  1993. if (iv->iov_len + skb->len > veclen)
  1994. return -ENOMEM;
  1995. BT_DBG("Copying %d bytes", (int)frag_iter->len);
  1996. memcpy(iv->iov_base + iv->iov_len, frag_iter->data,
  1997. frag_iter->len);
  1998. iv->iov_len += frag_iter->len;
  1999. }
  2000. return 0;
  2001. }
  2002. int l2cap_resegment_queue(struct sock *sk, struct sk_buff_head *queue)
  2003. {
  2004. void *buf;
  2005. int buflen;
  2006. int err = 0;
  2007. struct sk_buff *skb;
  2008. struct msghdr msg;
  2009. struct kvec iv;
  2010. struct sk_buff_head old_frames;
  2011. struct l2cap_pinfo *pi = l2cap_pi(sk);
  2012. BT_DBG("sk %p", sk);
  2013. if (skb_queue_empty(queue))
  2014. return 0;
  2015. memset(&msg, 0, sizeof(msg));
  2016. msg.msg_iov = (struct iovec *) &iv;
  2017. buflen = pi->omtu + L2CAP_FCS_SIZE;
  2018. buf = kzalloc(buflen, GFP_TEMPORARY);
  2019. if (!buf) {
  2020. BT_DBG("Could not allocate resegmentation buffer");
  2021. return -ENOMEM;
  2022. }
  2023. /* Move current frames off the original queue */
  2024. __skb_queue_head_init(&old_frames);
  2025. skb_queue_splice_tail_init(queue, &old_frames);
  2026. while (!skb_queue_empty(&old_frames)) {
  2027. struct sk_buff_head current_sdu;
  2028. u8 original_sar;
  2029. /* Reassemble each SDU from one or more PDUs */
  2030. iv.iov_base = buf;
  2031. iv.iov_len = 0;
  2032. skb = skb_peek(&old_frames);
  2033. original_sar = bt_cb(skb)->control.sar;
  2034. __skb_unlink(skb, &old_frames);
  2035. /* Append data to SDU */
  2036. if (pi->extended_control)
  2037. skb_pull(skb, L2CAP_EXTENDED_HDR_SIZE);
  2038. else
  2039. skb_pull(skb, L2CAP_ENHANCED_HDR_SIZE);
  2040. if (original_sar == L2CAP_SAR_START)
  2041. skb_pull(skb, L2CAP_SDULEN_SIZE);
  2042. err = l2cap_skbuff_to_kvec(skb, &iv, buflen);
  2043. if (bt_cb(skb)->control.fcs == L2CAP_FCS_CRC16)
  2044. iv.iov_len -= L2CAP_FCS_SIZE;
  2045. /* Free skb */
  2046. kfree_skb(skb);
  2047. if (err)
  2048. break;
  2049. while (!skb_queue_empty(&old_frames) && !err) {
  2050. /* Check next frame */
  2051. skb = skb_peek(&old_frames);
  2052. if (is_initial_frame(bt_cb(skb)->control.sar))
  2053. break;
  2054. __skb_unlink(skb, &old_frames);
  2055. /* Append data to SDU */
  2056. if (pi->extended_control)
  2057. skb_pull(skb, L2CAP_EXTENDED_HDR_SIZE);
  2058. else
  2059. skb_pull(skb, L2CAP_ENHANCED_HDR_SIZE);
  2060. if (bt_cb(skb)->control.sar == L2CAP_SAR_START)
  2061. skb_pull(skb, L2CAP_SDULEN_SIZE);
  2062. err = l2cap_skbuff_to_kvec(skb, &iv, buflen);
  2063. if (bt_cb(skb)->control.fcs == L2CAP_FCS_CRC16)
  2064. iv.iov_len -= L2CAP_FCS_SIZE;
  2065. /* Free skb */
  2066. kfree_skb(skb);
  2067. }
  2068. if (err)
  2069. break;
  2070. /* Segment data */
  2071. __skb_queue_head_init(&current_sdu);
  2072. /* skbs for the SDU were just freed, but the
  2073. * resegmenting process could produce more, smaller
  2074. * skbs due to smaller PDUs and reduced HCI MTU. The
  2075. * overhead from the sk_buff structs could put us over
  2076. * the sk_sndbuf limit.
  2077. *
  2078. * Since this code is running in response to a
  2079. * received poll/final packet, it cannot block.
  2080. * Therefore, memory allocation needs to be allowed by
  2081. * falling back to bt_skb_alloc() (with
  2082. * skb_set_owner_w() to maintain sk_wmem_alloc
  2083. * correctly).
  2084. */
  2085. msg.msg_iovlen = iv.iov_len;
  2086. err = l2cap_segment_sdu(sk, &current_sdu, &msg,
  2087. msg.msg_iovlen, 1);
  2088. if (err || skb_queue_empty(&current_sdu)) {
  2089. BT_DBG("Error %d resegmenting data for socket %p",
  2090. err, sk);
  2091. __skb_queue_purge(&current_sdu);
  2092. break;
  2093. }
  2094. /* Fix up first PDU SAR bits */
  2095. if (!is_initial_frame(original_sar)) {
  2096. BT_DBG("Changing SAR bits, %d PDUs",
  2097. skb_queue_len(&current_sdu));
  2098. skb = skb_peek(&current_sdu);
  2099. if (skb_queue_len(&current_sdu) == 1) {
  2100. /* Change SAR from 'unsegmented' to 'end' */
  2101. bt_cb(skb)->control.sar = L2CAP_SAR_END;
  2102. } else {
  2103. struct l2cap_hdr *lh;
  2104. size_t hdrlen;
  2105. /* Change SAR from 'start' to 'continue' */
  2106. bt_cb(skb)->control.sar = L2CAP_SAR_CONTINUE;
  2107. /* Start frames contain 2 bytes for
  2108. * sdulen and continue frames don't.
  2109. * Must rewrite header to eliminate
  2110. * sdulen and then adjust l2cap frame
  2111. * length.
  2112. */
  2113. if (pi->extended_control)
  2114. hdrlen = L2CAP_EXTENDED_HDR_SIZE;
  2115. else
  2116. hdrlen = L2CAP_ENHANCED_HDR_SIZE;
  2117. memmove(skb->data + L2CAP_SDULEN_SIZE,
  2118. skb->data, hdrlen);
  2119. skb_pull(skb, L2CAP_SDULEN_SIZE);
  2120. lh = (struct l2cap_hdr *)skb->data;
  2121. lh->len = cpu_to_le16(le16_to_cpu(lh->len) -
  2122. L2CAP_SDULEN_SIZE);
  2123. }
  2124. }
  2125. /* Add to queue */
  2126. skb_queue_splice_tail(&current_sdu, queue);
  2127. }
  2128. __skb_queue_purge(&old_frames);
  2129. if (err)
  2130. __skb_queue_purge(queue);
  2131. kfree(buf);
  2132. BT_DBG("Queue resegmented, err=%d", err);
  2133. return err;
  2134. }
  2135. static void l2cap_resegment_worker(struct work_struct *work)
  2136. {
  2137. int err = 0;
  2138. struct l2cap_resegment_work *seg_work =
  2139. container_of(work, struct l2cap_resegment_work, work);
  2140. struct sock *sk = seg_work->sk;
  2141. kfree(seg_work);
  2142. BT_DBG("sk %p", sk);
  2143. lock_sock(sk);
  2144. if (l2cap_pi(sk)->amp_move_state != L2CAP_AMP_STATE_RESEGMENT) {
  2145. release_sock(sk);
  2146. sock_put(sk);
  2147. return;
  2148. }
  2149. err = l2cap_resegment_queue(sk, TX_QUEUE(sk));
  2150. l2cap_pi(sk)->amp_move_state = L2CAP_AMP_STATE_STABLE;
  2151. if (skb_queue_empty(TX_QUEUE(sk)))
  2152. sk->sk_send_head = NULL;
  2153. else
  2154. sk->sk_send_head = skb_peek(TX_QUEUE(sk));
  2155. if (err)
  2156. l2cap_send_disconn_req(l2cap_pi(sk)->conn, sk, ECONNRESET);
  2157. else
  2158. l2cap_ertm_send(sk);
  2159. release_sock(sk);
  2160. sock_put(sk);
  2161. }
  2162. static int l2cap_setup_resegment(struct sock *sk)
  2163. {
  2164. struct l2cap_resegment_work *seg_work;
  2165. BT_DBG("sk %p", sk);
  2166. if (skb_queue_empty(TX_QUEUE(sk)))
  2167. return 0;
  2168. seg_work = kzalloc(sizeof(*seg_work), GFP_ATOMIC);
  2169. if (!seg_work)
  2170. return -ENOMEM;
  2171. INIT_WORK(&seg_work->work, l2cap_resegment_worker);
  2172. sock_hold(sk);
  2173. seg_work->sk = sk;
  2174. if (!queue_work(_l2cap_wq, &seg_work->work)) {
  2175. kfree(seg_work);
  2176. sock_put(sk);
  2177. return -ENOMEM;
  2178. }
  2179. l2cap_pi(sk)->amp_move_state = L2CAP_AMP_STATE_RESEGMENT;
  2180. return 0;
  2181. }
  2182. static inline int l2cap_rmem_available(struct sock *sk)
  2183. {
  2184. BT_DBG("sk_rmem_alloc %d, sk_rcvbuf %d",
  2185. atomic_read(&sk->sk_rmem_alloc), sk->sk_rcvbuf);
  2186. return atomic_read(&sk->sk_rmem_alloc) < sk->sk_rcvbuf / 3;
  2187. }
  2188. static inline int l2cap_rmem_full(struct sock *sk)
  2189. {
  2190. BT_DBG("sk_rmem_alloc %d, sk_rcvbuf %d",
  2191. atomic_read(&sk->sk_rmem_alloc), sk->sk_rcvbuf);
  2192. return atomic_read(&sk->sk_rmem_alloc) > (2 * sk->sk_rcvbuf) / 3;
  2193. }
  2194. void l2cap_amp_move_init(struct sock *sk)
  2195. {
  2196. BT_DBG("sk %p", sk);
  2197. if (!l2cap_pi(sk)->conn)
  2198. return;
  2199. if (!(l2cap_pi(sk)->conn->fc_mask & L2CAP_FC_A2MP) || !enable_hs)
  2200. return;
  2201. if (l2cap_pi(sk)->amp_id == 0) {
  2202. if (l2cap_pi(sk)->amp_pref != BT_AMP_POLICY_PREFER_AMP)
  2203. return;
  2204. l2cap_pi(sk)->amp_move_role = L2CAP_AMP_MOVE_INITIATOR;
  2205. l2cap_pi(sk)->amp_move_state = L2CAP_AMP_STATE_WAIT_PREPARE;
  2206. amp_create_physical(l2cap_pi(sk)->conn, sk);
  2207. } else {
  2208. l2cap_pi(sk)->amp_move_role = L2CAP_AMP_MOVE_INITIATOR;
  2209. l2cap_pi(sk)->amp_move_state =
  2210. L2CAP_AMP_STATE_WAIT_MOVE_RSP_SUCCESS;
  2211. l2cap_pi(sk)->amp_move_id = 0;
  2212. l2cap_amp_move_setup(sk);
  2213. l2cap_send_move_chan_req(l2cap_pi(sk)->conn,
  2214. l2cap_pi(sk), l2cap_pi(sk)->scid, 0);
  2215. l2cap_sock_set_timer(sk, L2CAP_MOVE_TIMEOUT);
  2216. }
  2217. }
  2218. static void l2cap_chan_ready(struct sock *sk)
  2219. {
  2220. struct sock *parent = bt_sk(sk)->parent;
  2221. BT_DBG("sk %p, parent %p", sk, parent);
  2222. l2cap_pi(sk)->conf_state = 0;
  2223. l2cap_sock_clear_timer(sk);
  2224. if (!parent) {
  2225. /* Outgoing channel.
  2226. * Wake up socket sleeping on connect.
  2227. */
  2228. sk->sk_state = BT_CONNECTED;
  2229. sk->sk_state_change(sk);
  2230. } else {
  2231. /* Incoming channel.
  2232. * Wake up socket sleeping on accept.
  2233. */
  2234. parent->sk_data_ready(parent, 0);
  2235. }
  2236. }
  2237. /* Copy frame to all raw sockets on that connection */
  2238. static void l2cap_raw_recv(struct l2cap_conn *conn, struct sk_buff *skb)
  2239. {
  2240. struct l2cap_chan_list *l = &conn->chan_list;
  2241. struct sk_buff *nskb;
  2242. struct sock *sk;
  2243. BT_DBG("conn %p", conn);
  2244. read_lock(&l->lock);
  2245. for (sk = l->head; sk; sk = l2cap_pi(sk)->next_c) {
  2246. if (sk->sk_type != SOCK_RAW)
  2247. continue;
  2248. /* Don't send frame to the socket it came from */
  2249. if (skb->sk == sk)
  2250. continue;
  2251. nskb = skb_clone(skb, GFP_ATOMIC);
  2252. if (!nskb)
  2253. continue;
  2254. if (sock_queue_rcv_skb(sk, nskb))
  2255. kfree_skb(nskb);
  2256. }
  2257. read_unlock(&l->lock);
  2258. }
  2259. /* ---- L2CAP signalling commands ---- */
  2260. static struct sk_buff *l2cap_build_cmd(struct l2cap_conn *conn,
  2261. u8 code, u8 ident, u16 dlen, void *data)
  2262. {
  2263. struct sk_buff *skb, **frag;
  2264. struct l2cap_cmd_hdr *cmd;
  2265. struct l2cap_hdr *lh;
  2266. int len, count;
  2267. unsigned int mtu = conn->hcon->hdev->acl_mtu;
  2268. BT_DBG("conn %p, code 0x%2.2x, ident 0x%2.2x, len %d",
  2269. conn, code, ident, dlen);
  2270. if (conn->mtu < L2CAP_HDR_SIZE + L2CAP_CMD_HDR_SIZE)
  2271. return NULL;
  2272. len = L2CAP_HDR_SIZE + L2CAP_CMD_HDR_SIZE + dlen;
  2273. count = min_t(unsigned int, mtu, len);
  2274. skb = bt_skb_alloc(count, GFP_ATOMIC);
  2275. if (!skb)
  2276. return NULL;
  2277. lh = (struct l2cap_hdr *) skb_put(skb, L2CAP_HDR_SIZE);
  2278. lh->len = cpu_to_le16(L2CAP_CMD_HDR_SIZE + dlen);
  2279. if (conn->hcon->type == LE_LINK)
  2280. lh->cid = cpu_to_le16(L2CAP_CID_LE_SIGNALING);
  2281. else
  2282. lh->cid = cpu_to_le16(L2CAP_CID_SIGNALING);
  2283. cmd = (struct l2cap_cmd_hdr *) skb_put(skb, L2CAP_CMD_HDR_SIZE);
  2284. cmd->code = code;
  2285. cmd->ident = ident;
  2286. cmd->len = cpu_to_le16(dlen);
  2287. if (dlen) {
  2288. count -= L2CAP_HDR_SIZE + L2CAP_CMD_HDR_SIZE;
  2289. memcpy(skb_put(skb, count), data, count);
  2290. data += count;
  2291. }
  2292. len -= skb->len;
  2293. /* Continuation fragments (no L2CAP header) */
  2294. frag = &skb_shinfo(skb)->frag_list;
  2295. while (len) {
  2296. count = min_t(unsigned int, mtu, len);
  2297. *frag = bt_skb_alloc(count, GFP_ATOMIC);
  2298. if (!*frag)
  2299. goto fail;
  2300. memcpy(skb_put(*frag, count), data, count);
  2301. len -= count;
  2302. data += count;
  2303. frag = &(*frag)->next;
  2304. }
  2305. return skb;
  2306. fail:
  2307. kfree_skb(skb);
  2308. return NULL;
  2309. }
  2310. static inline int l2cap_get_conf_opt(void **ptr, int *type, int *olen, unsigned long *val)
  2311. {
  2312. struct l2cap_conf_opt *opt = *ptr;
  2313. int len;
  2314. len = L2CAP_CONF_OPT_SIZE + opt->len;
  2315. *ptr += len;
  2316. *type = opt->type;
  2317. *olen = opt->len;
  2318. switch (opt->len) {
  2319. case 1:
  2320. *val = *((u8 *) opt->val);
  2321. break;
  2322. case 2:
  2323. *val = get_unaligned_le16(opt->val);
  2324. break;
  2325. case 4:
  2326. *val = get_unaligned_le32(opt->val);
  2327. break;
  2328. default:
  2329. *val = (unsigned long) opt->val;
  2330. break;
  2331. }
  2332. BT_DBG("type 0x%2.2x len %d val 0x%lx", *type, opt->len, *val);
  2333. return len;
  2334. }
  2335. static void l2cap_add_conf_opt(void **ptr, u8 type, u8 len, unsigned long val, size_t size)
  2336. {
  2337. struct l2cap_conf_opt *opt = *ptr;
  2338. BT_DBG("type 0x%2.2x len %d val 0x%lx", type, len, val);
  2339. if (size < L2CAP_CONF_OPT_SIZE + len)
  2340. return;
  2341. opt->type = type;
  2342. opt->len = len;
  2343. switch (len) {
  2344. case 1:
  2345. *((u8 *) opt->val) = val;
  2346. break;
  2347. case 2:
  2348. put_unaligned_le16(val, opt->val);
  2349. break;
  2350. case 4:
  2351. put_unaligned_le32(val, opt->val);
  2352. break;
  2353. default:
  2354. memcpy(opt->val, (void *) val, len);
  2355. break;
  2356. }
  2357. *ptr += L2CAP_CONF_OPT_SIZE + len;
  2358. }
  2359. static void l2cap_ertm_ack_timeout(struct work_struct *work)
  2360. {
  2361. struct delayed_work *delayed =
  2362. container_of(work, struct delayed_work, work);
  2363. struct l2cap_pinfo *pi =
  2364. container_of(delayed, struct l2cap_pinfo, ack_work);
  2365. struct sock *sk = (struct sock *)pi;
  2366. u16 frames_to_ack;
  2367. BT_DBG("sk %p", sk);
  2368. if (!sk)
  2369. return;
  2370. lock_sock(sk);
  2371. if (!l2cap_pi(sk)->conn) {
  2372. release_sock(sk);
  2373. return;
  2374. }
  2375. frames_to_ack = __delta_seq(l2cap_pi(sk)->buffer_seq,
  2376. l2cap_pi(sk)->last_acked_seq,
  2377. l2cap_pi(sk));
  2378. if (frames_to_ack)
  2379. l2cap_ertm_send_rr_or_rnr(sk, 0);
  2380. release_sock(sk);
  2381. }
  2382. static void l2cap_ertm_retrans_timeout(struct work_struct *work)
  2383. {
  2384. struct delayed_work *delayed =
  2385. container_of(work, struct delayed_work, work);
  2386. struct l2cap_pinfo *pi =
  2387. container_of(delayed, struct l2cap_pinfo, retrans_work);
  2388. struct sock *sk = (struct sock *)pi;
  2389. BT_DBG("sk %p", sk);
  2390. if (!sk)
  2391. return;
  2392. lock_sock(sk);
  2393. if (!l2cap_pi(sk)->conn) {
  2394. release_sock(sk);
  2395. return;
  2396. }
  2397. l2cap_ertm_tx(sk, 0, 0, L2CAP_ERTM_EVENT_RETRANS_TIMER_EXPIRES);
  2398. release_sock(sk);
  2399. }
  2400. static void l2cap_ertm_monitor_timeout(struct work_struct *work)
  2401. {
  2402. struct delayed_work *delayed =
  2403. container_of(work, struct delayed_work, work);
  2404. struct l2cap_pinfo *pi =
  2405. container_of(delayed, struct l2cap_pinfo, monitor_work);
  2406. struct sock *sk = (struct sock *)pi;
  2407. BT_DBG("sk %p", sk);
  2408. if (!sk)
  2409. return;
  2410. lock_sock(sk);
  2411. if (!l2cap_pi(sk)->conn) {
  2412. release_sock(sk);
  2413. return;
  2414. }
  2415. l2cap_ertm_tx(sk, 0, 0, L2CAP_ERTM_EVENT_MONITOR_TIMER_EXPIRES);
  2416. release_sock(sk);
  2417. }
  2418. static inline void l2cap_ertm_init(struct sock *sk)
  2419. {
  2420. l2cap_pi(sk)->next_tx_seq = 0;
  2421. l2cap_pi(sk)->expected_tx_seq = 0;
  2422. l2cap_pi(sk)->expected_ack_seq = 0;
  2423. l2cap_pi(sk)->unacked_frames = 0;
  2424. l2cap_pi(sk)->buffer_seq = 0;
  2425. l2cap_pi(sk)->frames_sent = 0;
  2426. l2cap_pi(sk)->last_acked_seq = 0;
  2427. l2cap_pi(sk)->sdu = NULL;
  2428. l2cap_pi(sk)->sdu_last_frag = NULL;
  2429. l2cap_pi(sk)->sdu_len = 0;
  2430. atomic_set(&l2cap_pi(sk)->ertm_queued, 0);
  2431. l2cap_pi(sk)->rx_state = L2CAP_ERTM_RX_STATE_RECV;
  2432. l2cap_pi(sk)->tx_state = L2CAP_ERTM_TX_STATE_XMIT;
  2433. BT_DBG("tx_state 0x2.2%x rx_state 0x2.2%x", l2cap_pi(sk)->tx_state,
  2434. l2cap_pi(sk)->rx_state);
  2435. l2cap_pi(sk)->amp_id = 0;
  2436. l2cap_pi(sk)->amp_move_state = L2CAP_AMP_STATE_STABLE;
  2437. l2cap_pi(sk)->amp_move_role = L2CAP_AMP_MOVE_NONE;
  2438. l2cap_pi(sk)->amp_move_reqseq = 0;
  2439. l2cap_pi(sk)->amp_move_event = 0;
  2440. INIT_DELAYED_WORK(&l2cap_pi(sk)->ack_work, l2cap_ertm_ack_timeout);
  2441. INIT_DELAYED_WORK(&l2cap_pi(sk)->retrans_work,
  2442. l2cap_ertm_retrans_timeout);
  2443. INIT_DELAYED_WORK(&l2cap_pi(sk)->monitor_work,
  2444. l2cap_ertm_monitor_timeout);
  2445. INIT_WORK(&l2cap_pi(sk)->tx_work, l2cap_ertm_tx_worker);
  2446. skb_queue_head_init(SREJ_QUEUE(sk));
  2447. skb_queue_head_init(TX_QUEUE(sk));
  2448. l2cap_seq_list_init(&l2cap_pi(sk)->srej_list, l2cap_pi(sk)->tx_win);
  2449. l2cap_seq_list_init(&l2cap_pi(sk)->retrans_list,
  2450. l2cap_pi(sk)->remote_tx_win);
  2451. }
  2452. void l2cap_ertm_destruct(struct sock *sk)
  2453. {
  2454. l2cap_seq_list_free(&l2cap_pi(sk)->srej_list);
  2455. l2cap_seq_list_free(&l2cap_pi(sk)->retrans_list);
  2456. }
  2457. void l2cap_ertm_shutdown(struct sock *sk)
  2458. {
  2459. l2cap_ertm_stop_ack_timer(l2cap_pi(sk));
  2460. l2cap_ertm_stop_retrans_timer(l2cap_pi(sk));
  2461. l2cap_ertm_stop_monitor_timer(l2cap_pi(sk));
  2462. }
  2463. void l2cap_ertm_recv_done(struct sock *sk)
  2464. {
  2465. lock_sock(sk);
  2466. if (l2cap_pi(sk)->mode != L2CAP_MODE_ERTM ||
  2467. sk->sk_state != BT_CONNECTED) {
  2468. release_sock(sk);
  2469. return;
  2470. }
  2471. /* Consume any queued incoming frames and update local busy status */
  2472. if (l2cap_pi(sk)->rx_state == L2CAP_ERTM_RX_STATE_SREJ_SENT &&
  2473. l2cap_ertm_rx_queued_iframes(sk))
  2474. l2cap_send_disconn_req(l2cap_pi(sk)->conn, sk, ECONNRESET);
  2475. else if ((l2cap_pi(sk)->conn_state & L2CAP_CONN_LOCAL_BUSY) &&
  2476. l2cap_rmem_available(sk))
  2477. l2cap_ertm_tx(sk, 0, 0, L2CAP_ERTM_EVENT_LOCAL_BUSY_CLEAR);
  2478. release_sock(sk);
  2479. }
  2480. static inline __u8 l2cap_select_mode(__u8 mode, __u16 remote_feat_mask)
  2481. {
  2482. switch (mode) {
  2483. case L2CAP_MODE_STREAMING:
  2484. case L2CAP_MODE_ERTM:
  2485. if (l2cap_mode_supported(mode, remote_feat_mask))
  2486. return mode;
  2487. /* fall through */
  2488. default:
  2489. return L2CAP_MODE_BASIC;
  2490. }
  2491. }
  2492. static void l2cap_setup_txwin(struct l2cap_pinfo *pi)
  2493. {
  2494. if (pi->tx_win > L2CAP_TX_WIN_MAX_ENHANCED &&
  2495. (pi->conn->feat_mask & L2CAP_FEAT_EXT_WINDOW)) {
  2496. pi->tx_win_max = L2CAP_TX_WIN_MAX_EXTENDED;
  2497. pi->extended_control = 1;
  2498. } else {
  2499. if (pi->tx_win > L2CAP_TX_WIN_MAX_ENHANCED)
  2500. pi->tx_win = L2CAP_TX_WIN_MAX_ENHANCED;
  2501. pi->tx_win_max = L2CAP_TX_WIN_MAX_ENHANCED;
  2502. pi->extended_control = 0;
  2503. }
  2504. pi->ack_win = pi->tx_win;
  2505. }
  2506. static void l2cap_aggregate_fs(struct hci_ext_fs *cur,
  2507. struct hci_ext_fs *new,
  2508. struct hci_ext_fs *agg)
  2509. {
  2510. *agg = *cur;
  2511. if ((cur->max_sdu != 0xFFFF) && (cur->sdu_arr_time != 0xFFFFFFFF)) {
  2512. /* current flow spec has known rate */
  2513. if ((new->max_sdu == 0xFFFF) ||
  2514. (new->sdu_arr_time == 0xFFFFFFFF)) {
  2515. /* new fs has unknown rate, so aggregate is unknown */
  2516. agg->max_sdu = 0xFFFF;
  2517. agg->sdu_arr_time = 0xFFFFFFFF;
  2518. } else {
  2519. /* new fs has known rate, so aggregate is known */
  2520. u64 cur_rate;
  2521. u64 new_rate;
  2522. cur_rate = cur->max_sdu * 1000000ULL;
  2523. if (cur->sdu_arr_time)
  2524. cur_rate = div_u64(cur_rate, cur->sdu_arr_time);
  2525. new_rate = new->max_sdu * 1000000ULL;
  2526. if (new->sdu_arr_time)
  2527. new_rate = div_u64(new_rate, new->sdu_arr_time);
  2528. cur_rate = cur_rate + new_rate;
  2529. if (cur_rate)
  2530. agg->sdu_arr_time = div64_u64(
  2531. agg->max_sdu * 1000000ULL, cur_rate);
  2532. }
  2533. }
  2534. }
  2535. static int l2cap_aggregate(struct hci_chan *chan, struct l2cap_pinfo *pi)
  2536. {
  2537. struct hci_ext_fs tx_fs;
  2538. struct hci_ext_fs rx_fs;
  2539. BT_DBG("chan %p", chan);
  2540. if (((chan->tx_fs.max_sdu == 0xFFFF) ||
  2541. (chan->tx_fs.sdu_arr_time == 0xFFFFFFFF)) &&
  2542. ((chan->rx_fs.max_sdu == 0xFFFF) ||
  2543. (chan->rx_fs.sdu_arr_time == 0xFFFFFFFF)))
  2544. return 0;
  2545. l2cap_aggregate_fs(&chan->tx_fs,
  2546. (struct hci_ext_fs *) &pi->local_fs, &tx_fs);
  2547. l2cap_aggregate_fs(&chan->rx_fs,
  2548. (struct hci_ext_fs *) &pi->remote_fs, &rx_fs);
  2549. hci_chan_modify(chan, &tx_fs, &rx_fs);
  2550. return 1;
  2551. }
  2552. static void l2cap_deaggregate_fs(struct hci_ext_fs *cur,
  2553. struct hci_ext_fs *old,
  2554. struct hci_ext_fs *agg)
  2555. {
  2556. *agg = *cur;
  2557. if ((cur->max_sdu != 0xFFFF) && (cur->sdu_arr_time != 0xFFFFFFFF)) {
  2558. u64 cur_rate;
  2559. u64 old_rate;
  2560. cur_rate = cur->max_sdu * 1000000ULL;
  2561. if (cur->sdu_arr_time)
  2562. cur_rate = div_u64(cur_rate, cur->sdu_arr_time);
  2563. old_rate = old->max_sdu * 1000000ULL;
  2564. if (old->sdu_arr_time)
  2565. old_rate = div_u64(old_rate, old->sdu_arr_time);
  2566. cur_rate = cur_rate - old_rate;
  2567. if (cur_rate)
  2568. agg->sdu_arr_time = div64_u64(
  2569. agg->max_sdu * 1000000ULL, cur_rate);
  2570. }
  2571. }
  2572. static int l2cap_deaggregate(struct hci_chan *chan, struct l2cap_pinfo *pi)
  2573. {
  2574. struct hci_ext_fs tx_fs;
  2575. struct hci_ext_fs rx_fs;
  2576. BT_DBG("chan %p", chan);
  2577. if (((chan->tx_fs.max_sdu == 0xFFFF) ||
  2578. (chan->tx_fs.sdu_arr_time == 0xFFFFFFFF)) &&
  2579. ((chan->rx_fs.max_sdu == 0xFFFF) ||
  2580. (chan->rx_fs.sdu_arr_time == 0xFFFFFFFF)))
  2581. return 0;
  2582. l2cap_deaggregate_fs(&chan->tx_fs,
  2583. (struct hci_ext_fs *) &pi->local_fs, &tx_fs);
  2584. l2cap_deaggregate_fs(&chan->rx_fs,
  2585. (struct hci_ext_fs *) &pi->remote_fs, &rx_fs);
  2586. hci_chan_modify(chan, &tx_fs, &rx_fs);
  2587. return 1;
  2588. }
  2589. static struct hci_chan *l2cap_chan_admit(u8 amp_id, struct sock *sk)
  2590. {
  2591. struct l2cap_pinfo *pi = l2cap_pi(sk);
  2592. struct hci_dev *hdev;
  2593. struct hci_conn *hcon;
  2594. struct hci_chan *chan;
  2595. hdev = hci_dev_get(amp_id);
  2596. if (!hdev)
  2597. return NULL;
  2598. BT_DBG("hdev %s", hdev->name);
  2599. hcon = hci_conn_hash_lookup_ba(hdev, ACL_LINK, pi->conn->dst);
  2600. if (!hcon) {
  2601. chan = NULL;
  2602. goto done;
  2603. }
  2604. chan = hci_chan_list_lookup_id(hdev, hcon->handle);
  2605. if (chan) {
  2606. l2cap_aggregate(chan, pi);
  2607. sock_hold(sk);
  2608. chan->l2cap_sk = sk;
  2609. hci_chan_hold(chan);
  2610. pi->ampchan = chan;
  2611. goto done;
  2612. }
  2613. chan = hci_chan_add(hdev);
  2614. if (chan) {
  2615. chan->conn = hcon;
  2616. sock_hold(sk);
  2617. chan->l2cap_sk = sk;
  2618. hci_chan_hold(chan);
  2619. pi->ampchan = chan;
  2620. hci_chan_create(chan,
  2621. (struct hci_ext_fs *) &pi->local_fs,
  2622. (struct hci_ext_fs *) &pi->remote_fs);
  2623. }
  2624. done:
  2625. hci_dev_put(hdev);
  2626. return chan;
  2627. }
  2628. static void l2cap_get_ertm_timeouts(struct l2cap_conf_rfc *rfc,
  2629. struct l2cap_pinfo *pi)
  2630. {
  2631. if (pi->amp_id && pi->ampcon) {
  2632. u64 ertm_to = pi->ampcon->hdev->amp_be_flush_to;
  2633. /* Class 1 devices have must have ERTM timeouts
  2634. * exceeding the Link Supervision Timeout. The
  2635. * default Link Supervision Timeout for AMP
  2636. * controllers is 10 seconds.
  2637. *
  2638. * Class 1 devices use 0xffffffff for their
  2639. * best-effort flush timeout, so the clamping logic
  2640. * will result in a timeout that meets the above
  2641. * requirement. ERTM timeouts are 16-bit values, so
  2642. * the maximum timeout is 65.535 seconds.
  2643. */
  2644. /* Convert timeout to milliseconds and round */
  2645. ertm_to = div_u64(ertm_to + 999, 1000);
  2646. /* This is the recommended formula for class 2 devices
  2647. * that start ERTM timers when packets are sent to the
  2648. * controller.
  2649. */
  2650. ertm_to = 3 * ertm_to + 500;
  2651. if (ertm_to > 0xffff)
  2652. ertm_to = 0xffff;
  2653. rfc->retrans_timeout = cpu_to_le16((u16) ertm_to);
  2654. rfc->monitor_timeout = rfc->retrans_timeout;
  2655. } else {
  2656. rfc->retrans_timeout = cpu_to_le16(L2CAP_DEFAULT_RETRANS_TO);
  2657. rfc->monitor_timeout = cpu_to_le16(L2CAP_DEFAULT_MONITOR_TO);
  2658. }
  2659. }
  2660. int l2cap_build_conf_req(struct sock *sk, void *data, size_t data_size)
  2661. {
  2662. struct l2cap_pinfo *pi = l2cap_pi(sk);
  2663. struct l2cap_conf_req *req = data;
  2664. struct l2cap_conf_rfc rfc = { .mode = pi->mode };
  2665. void *ptr = req->data;
  2666. void *endptr = data + data_size;
  2667. BT_DBG("sk %p mode %d", sk, pi->mode);
  2668. if (pi->num_conf_req || pi->num_conf_rsp)
  2669. goto done;
  2670. switch (pi->mode) {
  2671. case L2CAP_MODE_STREAMING:
  2672. case L2CAP_MODE_ERTM:
  2673. if (pi->conf_state & L2CAP_CONF_STATE2_DEVICE)
  2674. break;
  2675. /* fall through */
  2676. default:
  2677. pi->mode = l2cap_select_mode(rfc.mode, pi->conn->feat_mask);
  2678. break;
  2679. }
  2680. done:
  2681. if (pi->imtu != L2CAP_DEFAULT_MTU)
  2682. l2cap_add_conf_opt(&ptr, L2CAP_CONF_MTU, 2, pi->imtu, endptr - ptr);
  2683. switch (pi->mode) {
  2684. case L2CAP_MODE_BASIC:
  2685. if (!(pi->conn->feat_mask & L2CAP_FEAT_ERTM) &&
  2686. !(pi->conn->feat_mask & L2CAP_FEAT_STREAMING))
  2687. break;
  2688. rfc.txwin_size = 0;
  2689. rfc.max_transmit = 0;
  2690. rfc.retrans_timeout = 0;
  2691. rfc.monitor_timeout = 0;
  2692. rfc.max_pdu_size = 0;
  2693. l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC, sizeof(rfc),
  2694. (unsigned long) &rfc, endptr - ptr);
  2695. break;
  2696. case L2CAP_MODE_ERTM:
  2697. l2cap_setup_txwin(pi);
  2698. if (pi->tx_win > L2CAP_TX_WIN_MAX_ENHANCED)
  2699. rfc.txwin_size = L2CAP_TX_WIN_MAX_ENHANCED;
  2700. else
  2701. rfc.txwin_size = pi->tx_win;
  2702. rfc.max_transmit = pi->max_tx;
  2703. rfc.max_pdu_size = cpu_to_le16(L2CAP_DEFAULT_MAX_PDU_SIZE);
  2704. l2cap_get_ertm_timeouts(&rfc, pi);
  2705. if (L2CAP_DEFAULT_MAX_PDU_SIZE > pi->imtu)
  2706. rfc.max_pdu_size = cpu_to_le16(pi->imtu);
  2707. l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC, sizeof(rfc),
  2708. (unsigned long) &rfc, endptr - ptr);
  2709. if ((pi->conn->feat_mask & L2CAP_FEAT_EXT_WINDOW) &&
  2710. pi->extended_control) {
  2711. l2cap_add_conf_opt(&ptr, L2CAP_CONF_EXT_WINDOW, 2,
  2712. pi->tx_win, endptr - ptr);
  2713. }
  2714. if (pi->amp_id) {
  2715. /* default best effort extended flow spec */
  2716. struct l2cap_conf_ext_fs fs = {1, 1, 0xFFFF,
  2717. 0xFFFFFFFF, 0xFFFFFFFF, 0xFFFFFFFF};
  2718. l2cap_add_conf_opt(&ptr, L2CAP_CONF_EXT_FS,
  2719. sizeof(fs), (unsigned long) &fs, endptr - ptr);
  2720. }
  2721. if (!(pi->conn->feat_mask & L2CAP_FEAT_FCS))
  2722. break;
  2723. if (pi->fcs == L2CAP_FCS_NONE ||
  2724. pi->conf_state & L2CAP_CONF_NO_FCS_RECV) {
  2725. pi->fcs = L2CAP_FCS_NONE;
  2726. l2cap_add_conf_opt(&ptr, L2CAP_CONF_FCS, 1, pi->fcs, endptr - ptr);
  2727. }
  2728. break;
  2729. case L2CAP_MODE_STREAMING:
  2730. l2cap_setup_txwin(pi);
  2731. rfc.txwin_size = 0;
  2732. rfc.max_transmit = 0;
  2733. rfc.retrans_timeout = 0;
  2734. rfc.monitor_timeout = 0;
  2735. rfc.max_pdu_size = cpu_to_le16(L2CAP_DEFAULT_MAX_PDU_SIZE);
  2736. if (L2CAP_DEFAULT_MAX_PDU_SIZE > pi->imtu)
  2737. rfc.max_pdu_size = cpu_to_le16(pi->imtu);
  2738. l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC, sizeof(rfc),
  2739. (unsigned long) &rfc, endptr - ptr);
  2740. if ((pi->conn->feat_mask & L2CAP_FEAT_EXT_WINDOW) &&
  2741. pi->extended_control) {
  2742. l2cap_add_conf_opt(&ptr, L2CAP_CONF_EXT_WINDOW, 2, 0, endptr - ptr);
  2743. }
  2744. if (!(pi->conn->feat_mask & L2CAP_FEAT_FCS))
  2745. break;
  2746. if (pi->fcs == L2CAP_FCS_NONE ||
  2747. pi->conf_state & L2CAP_CONF_NO_FCS_RECV) {
  2748. pi->fcs = L2CAP_FCS_NONE;
  2749. l2cap_add_conf_opt(&ptr, L2CAP_CONF_FCS, 1, pi->fcs, endptr - ptr);
  2750. }
  2751. break;
  2752. }
  2753. req->dcid = cpu_to_le16(pi->dcid);
  2754. req->flags = cpu_to_le16(0);
  2755. return ptr - data;
  2756. }
  2757. static int l2cap_build_amp_reconf_req(struct sock *sk, void *data, size_t data_size)
  2758. {
  2759. struct l2cap_pinfo *pi = l2cap_pi(sk);
  2760. struct l2cap_conf_req *req = data;
  2761. struct l2cap_conf_rfc rfc = { .mode = pi->mode };
  2762. void *ptr = req->data;
  2763. void *endptr = data + data_size;
  2764. BT_DBG("sk %p", sk);
  2765. switch (pi->mode) {
  2766. case L2CAP_MODE_ERTM:
  2767. rfc.mode = L2CAP_MODE_ERTM;
  2768. rfc.txwin_size = pi->tx_win;
  2769. rfc.max_transmit = pi->max_tx;
  2770. rfc.max_pdu_size = cpu_to_le16(L2CAP_DEFAULT_MAX_PDU_SIZE);
  2771. l2cap_get_ertm_timeouts(&rfc, pi);
  2772. if (L2CAP_DEFAULT_MAX_PDU_SIZE > pi->imtu)
  2773. rfc.max_pdu_size = cpu_to_le16(pi->imtu);
  2774. break;
  2775. default:
  2776. return -ECONNREFUSED;
  2777. }
  2778. l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC, sizeof(rfc),
  2779. (unsigned long) &rfc, endptr - ptr);
  2780. if (pi->conn->feat_mask & L2CAP_FEAT_FCS) {
  2781. /* TODO assign fcs for br/edr based on socket config option */
  2782. /* FCS is not used with AMP because it is redundant - lower
  2783. * layers already include a checksum. */
  2784. if (pi->amp_id)
  2785. pi->local_conf.fcs = L2CAP_FCS_NONE;
  2786. else
  2787. pi->local_conf.fcs = L2CAP_FCS_CRC16;
  2788. l2cap_add_conf_opt(&ptr, L2CAP_CONF_FCS, 1, pi->local_conf.fcs, endptr - ptr);
  2789. pi->fcs = pi->local_conf.fcs | pi->remote_conf.fcs;
  2790. }
  2791. req->dcid = cpu_to_le16(pi->dcid);
  2792. req->flags = cpu_to_le16(0);
  2793. return ptr - data;
  2794. }
  2795. static int l2cap_parse_conf_req(struct sock *sk, void *data, size_t data_size)
  2796. {
  2797. struct l2cap_pinfo *pi = l2cap_pi(sk);
  2798. struct l2cap_conf_rsp *rsp = data;
  2799. void *ptr = rsp->data;
  2800. void *endptr = data + data_size;
  2801. void *req = pi->conf_req;
  2802. int len = pi->conf_len;
  2803. int type, hint, olen;
  2804. unsigned long val;
  2805. struct l2cap_conf_rfc rfc = { .mode = L2CAP_MODE_BASIC };
  2806. struct l2cap_conf_ext_fs fs;
  2807. u16 mtu = L2CAP_DEFAULT_MTU;
  2808. u16 result = L2CAP_CONF_SUCCESS;
  2809. BT_DBG("sk %p", sk);
  2810. if (pi->omtu > mtu)
  2811. mtu = pi->omtu;
  2812. while (len >= L2CAP_CONF_OPT_SIZE) {
  2813. len -= l2cap_get_conf_opt(&req, &type, &olen, &val);
  2814. if (len < 0)
  2815. break;
  2816. hint = type & L2CAP_CONF_HINT;
  2817. type &= L2CAP_CONF_MASK;
  2818. switch (type) {
  2819. case L2CAP_CONF_MTU:
  2820. if (olen != 2)
  2821. break;
  2822. mtu = val;
  2823. break;
  2824. case L2CAP_CONF_FLUSH_TO:
  2825. if (olen != 2)
  2826. break;
  2827. pi->flush_to = val;
  2828. if (pi->conf_state & L2CAP_CONF_LOCKSTEP)
  2829. result = L2CAP_CONF_UNACCEPT;
  2830. else
  2831. pi->remote_conf.flush_to = val;
  2832. break;
  2833. case L2CAP_CONF_QOS:
  2834. if (pi->conf_state & L2CAP_CONF_LOCKSTEP)
  2835. result = L2CAP_CONF_UNACCEPT;
  2836. break;
  2837. case L2CAP_CONF_RFC:
  2838. if (olen != sizeof(rfc))
  2839. break;
  2840. memcpy(&rfc, (void *) val, olen);
  2841. break;
  2842. case L2CAP_CONF_FCS:
  2843. if (olen != 1)
  2844. break;
  2845. if (val == L2CAP_FCS_NONE)
  2846. pi->conf_state |= L2CAP_CONF_NO_FCS_RECV;
  2847. pi->remote_conf.fcs = val;
  2848. break;
  2849. case L2CAP_CONF_EXT_FS:
  2850. if (olen == sizeof(fs)) {
  2851. pi->conf_state |= L2CAP_CONF_EFS_RECV;
  2852. if (!(pi->conf_state & L2CAP_CONF_LOCKSTEP)) {
  2853. result = L2CAP_CONF_UNACCEPT;
  2854. break;
  2855. }
  2856. memcpy(&fs, (void *) val, olen);
  2857. if (fs.type != L2CAP_SERVICE_BEST_EFFORT) {
  2858. result = L2CAP_CONF_FLOW_SPEC_REJECT;
  2859. break;
  2860. }
  2861. pi->remote_conf.flush_to =
  2862. le32_to_cpu(fs.flush_to);
  2863. pi->remote_fs.id = fs.id;
  2864. pi->remote_fs.type = fs.type;
  2865. pi->remote_fs.max_sdu =
  2866. le16_to_cpu(fs.max_sdu);
  2867. pi->remote_fs.sdu_arr_time =
  2868. le32_to_cpu(fs.sdu_arr_time);
  2869. pi->remote_fs.acc_latency =
  2870. le32_to_cpu(fs.acc_latency);
  2871. pi->remote_fs.flush_to =
  2872. le32_to_cpu(fs.flush_to);
  2873. }
  2874. break;
  2875. case L2CAP_CONF_EXT_WINDOW:
  2876. pi->extended_control = 1;
  2877. pi->remote_tx_win = val;
  2878. pi->tx_win_max = L2CAP_TX_WIN_MAX_EXTENDED;
  2879. pi->conf_state |= L2CAP_CONF_EXT_WIN_RECV;
  2880. break;
  2881. default:
  2882. if (hint)
  2883. break;
  2884. result = L2CAP_CONF_UNKNOWN;
  2885. *((u8 *) ptr++) = type;
  2886. break;
  2887. }
  2888. }
  2889. if (pi->num_conf_rsp || pi->num_conf_req > 1)
  2890. goto done;
  2891. switch (pi->mode) {
  2892. case L2CAP_MODE_STREAMING:
  2893. case L2CAP_MODE_ERTM:
  2894. if (!(pi->conf_state & L2CAP_CONF_STATE2_DEVICE)) {
  2895. pi->mode = l2cap_select_mode(rfc.mode,
  2896. pi->conn->feat_mask);
  2897. break;
  2898. }
  2899. if (pi->mode != rfc.mode)
  2900. return -ECONNREFUSED;
  2901. break;
  2902. }
  2903. done:
  2904. if (pi->mode != rfc.mode) {
  2905. result = L2CAP_CONF_UNACCEPT;
  2906. rfc.mode = pi->mode;
  2907. if (mtu > L2CAP_DEFAULT_MTU)
  2908. pi->omtu = mtu;
  2909. if (pi->num_conf_rsp == 1)
  2910. return -ECONNREFUSED;
  2911. l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC,
  2912. sizeof(rfc), (unsigned long) &rfc,
  2913. endptr - ptr);
  2914. }
  2915. if ((pi->conf_state & L2CAP_CONF_LOCKSTEP) &&
  2916. !(pi->conf_state & L2CAP_CONF_EFS_RECV))
  2917. return -ECONNREFUSED;
  2918. if (result == L2CAP_CONF_SUCCESS) {
  2919. /* Configure output options and let the other side know
  2920. * which ones we don't like. */
  2921. if (mtu < L2CAP_DEFAULT_MIN_MTU) {
  2922. result = L2CAP_CONF_UNACCEPT;
  2923. pi->omtu = L2CAP_DEFAULT_MIN_MTU;
  2924. } else {
  2925. pi->omtu = mtu;
  2926. pi->conf_state |= L2CAP_CONF_MTU_DONE;
  2927. }
  2928. l2cap_add_conf_opt(&ptr, L2CAP_CONF_MTU, 2, pi->omtu, endptr - ptr);
  2929. switch (rfc.mode) {
  2930. case L2CAP_MODE_BASIC:
  2931. pi->fcs = L2CAP_FCS_NONE;
  2932. pi->conf_state |= L2CAP_CONF_MODE_DONE;
  2933. break;
  2934. case L2CAP_MODE_ERTM:
  2935. if (!(pi->conf_state & L2CAP_CONF_EXT_WIN_RECV))
  2936. pi->remote_tx_win = rfc.txwin_size;
  2937. pi->remote_max_tx = rfc.max_transmit;
  2938. pi->remote_mps = le16_to_cpu(rfc.max_pdu_size);
  2939. l2cap_get_ertm_timeouts(&rfc, pi);
  2940. pi->conf_state |= L2CAP_CONF_MODE_DONE;
  2941. l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC,
  2942. sizeof(rfc), (unsigned long) &rfc, endptr - ptr);
  2943. if (pi->conf_state & L2CAP_CONF_LOCKSTEP)
  2944. l2cap_add_conf_opt(&ptr, L2CAP_CONF_EXT_FS,
  2945. sizeof(fs), (unsigned long) &fs, endptr - ptr);
  2946. break;
  2947. case L2CAP_MODE_STREAMING:
  2948. pi->remote_mps = le16_to_cpu(rfc.max_pdu_size);
  2949. pi->conf_state |= L2CAP_CONF_MODE_DONE;
  2950. l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC,
  2951. sizeof(rfc), (unsigned long) &rfc, endptr - ptr);
  2952. break;
  2953. default:
  2954. result = L2CAP_CONF_UNACCEPT;
  2955. memset(&rfc, 0, sizeof(rfc));
  2956. rfc.mode = pi->mode;
  2957. }
  2958. if (pi->conf_state & L2CAP_CONF_LOCKSTEP &&
  2959. !(pi->conf_state & L2CAP_CONF_PEND_SENT)) {
  2960. pi->conf_state |= L2CAP_CONF_PEND_SENT;
  2961. result = L2CAP_CONF_PENDING;
  2962. if (pi->conf_state & L2CAP_CONF_LOCKSTEP_PEND &&
  2963. pi->amp_id) {
  2964. struct hci_chan *chan;
  2965. /* Trigger logical link creation only on AMP */
  2966. chan = l2cap_chan_admit(pi->amp_id, sk);
  2967. if (!chan)
  2968. return -ECONNREFUSED;
  2969. if (chan->state == BT_CONNECTED)
  2970. l2cap_create_cfm(chan, 0);
  2971. }
  2972. }
  2973. if (result == L2CAP_CONF_SUCCESS)
  2974. pi->conf_state |= L2CAP_CONF_OUTPUT_DONE;
  2975. }
  2976. rsp->scid = cpu_to_le16(pi->dcid);
  2977. rsp->result = cpu_to_le16(result);
  2978. rsp->flags = cpu_to_le16(0x0000);
  2979. return ptr - data;
  2980. }
  2981. static int l2cap_parse_amp_move_reconf_req(struct sock *sk, void *data, size_t data_size)
  2982. {
  2983. struct l2cap_pinfo *pi = l2cap_pi(sk);
  2984. struct l2cap_conf_rsp *rsp = data;
  2985. void *ptr = rsp->data;
  2986. void *endptr = data + data_size;
  2987. void *req = pi->conf_req;
  2988. int len = pi->conf_len;
  2989. int type, hint, olen;
  2990. unsigned long val;
  2991. struct l2cap_conf_rfc rfc = { .mode = L2CAP_MODE_BASIC };
  2992. struct l2cap_conf_ext_fs fs;
  2993. u16 mtu = pi->omtu;
  2994. u16 tx_win = pi->remote_tx_win;
  2995. u16 result = L2CAP_CONF_SUCCESS;
  2996. BT_DBG("sk %p", sk);
  2997. while (len >= L2CAP_CONF_OPT_SIZE) {
  2998. len -= l2cap_get_conf_opt(&req, &type, &olen, &val);
  2999. hint = type & L2CAP_CONF_HINT;
  3000. type &= L2CAP_CONF_MASK;
  3001. switch (type) {
  3002. case L2CAP_CONF_MTU:
  3003. mtu = val;
  3004. break;
  3005. case L2CAP_CONF_FLUSH_TO:
  3006. if (pi->amp_move_id)
  3007. result = L2CAP_CONF_UNACCEPT;
  3008. else
  3009. pi->remote_conf.flush_to = val;
  3010. break;
  3011. case L2CAP_CONF_QOS:
  3012. if (pi->amp_move_id)
  3013. result = L2CAP_CONF_UNACCEPT;
  3014. break;
  3015. case L2CAP_CONF_RFC:
  3016. if (olen != sizeof(rfc))
  3017. break;
  3018. memcpy(&rfc, (void *) val, olen);
  3019. break;
  3020. case L2CAP_CONF_FCS:
  3021. if (olen != 1)
  3022. break;
  3023. pi->remote_conf.fcs = val;
  3024. break;
  3025. case L2CAP_CONF_EXT_FS:
  3026. if (olen != sizeof(fs))
  3027. break;
  3028. memcpy(&fs, (void *) val, olen);
  3029. if (fs.type != L2CAP_SERVICE_BEST_EFFORT)
  3030. result = L2CAP_CONF_FLOW_SPEC_REJECT;
  3031. else {
  3032. pi->remote_conf.flush_to =
  3033. le32_to_cpu(fs.flush_to);
  3034. }
  3035. break;
  3036. case L2CAP_CONF_EXT_WINDOW:
  3037. tx_win = val;
  3038. break;
  3039. default:
  3040. if (hint)
  3041. break;
  3042. result = L2CAP_CONF_UNKNOWN;
  3043. *((u8 *) ptr++) = type;
  3044. break;
  3045. }
  3046. }
  3047. BT_DBG("result 0x%2.2x cur mode 0x%2.2x req mode 0x%2.2x",
  3048. result, pi->mode, rfc.mode);
  3049. if (pi->mode != rfc.mode || rfc.mode == L2CAP_MODE_BASIC)
  3050. result = L2CAP_CONF_UNACCEPT;
  3051. if (result == L2CAP_CONF_SUCCESS) {
  3052. /* Configure output options and let the other side know
  3053. * which ones we don't like. */
  3054. /* Don't allow mtu to decrease. */
  3055. if (mtu < pi->omtu)
  3056. result = L2CAP_CONF_UNACCEPT;
  3057. BT_DBG("mtu %d omtu %d", mtu, pi->omtu);
  3058. l2cap_add_conf_opt(&ptr, L2CAP_CONF_MTU, 2, pi->omtu, endptr - ptr);
  3059. /* Don't allow extended transmit window to change. */
  3060. if (tx_win != pi->remote_tx_win) {
  3061. result = L2CAP_CONF_UNACCEPT;
  3062. l2cap_add_conf_opt(&ptr, L2CAP_CONF_EXT_WINDOW, 2,
  3063. pi->remote_tx_win, endptr - ptr);
  3064. }
  3065. pi->remote_mps = rfc.max_pdu_size;
  3066. if (rfc.mode == L2CAP_MODE_ERTM) {
  3067. l2cap_get_ertm_timeouts(&rfc, pi);
  3068. } else {
  3069. rfc.retrans_timeout = 0;
  3070. rfc.monitor_timeout = 0;
  3071. }
  3072. l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC,
  3073. sizeof(rfc), (unsigned long) &rfc, endptr - ptr);
  3074. }
  3075. if (result != L2CAP_CONF_SUCCESS)
  3076. goto done;
  3077. pi->fcs = pi->remote_conf.fcs | pi->local_conf.fcs;
  3078. if (pi->rx_state == L2CAP_ERTM_RX_STATE_WAIT_F_FLAG)
  3079. pi->flush_to = pi->remote_conf.flush_to;
  3080. done:
  3081. rsp->scid = cpu_to_le16(pi->dcid);
  3082. rsp->result = cpu_to_le16(result);
  3083. rsp->flags = cpu_to_le16(0x0000);
  3084. return ptr - data;
  3085. }
  3086. static int l2cap_parse_conf_rsp(struct sock *sk, void *rsp, int len, void *data, size_t size, u16 *result)
  3087. {
  3088. struct l2cap_pinfo *pi = l2cap_pi(sk);
  3089. struct l2cap_conf_req *req = data;
  3090. void *ptr = req->data;
  3091. void *endptr = data + size;
  3092. int type, olen;
  3093. unsigned long val;
  3094. struct l2cap_conf_rfc rfc;
  3095. BT_DBG("sk %p, rsp %p, len %d, req %p", sk, rsp, len, data);
  3096. /* Initialize rfc in case no rfc option is received */
  3097. rfc.mode = pi->mode;
  3098. rfc.retrans_timeout = cpu_to_le16(L2CAP_DEFAULT_RETRANS_TO);
  3099. rfc.monitor_timeout = cpu_to_le16(L2CAP_DEFAULT_MONITOR_TO);
  3100. rfc.max_pdu_size = cpu_to_le16(L2CAP_DEFAULT_MAX_PDU_SIZE);
  3101. while (len >= L2CAP_CONF_OPT_SIZE) {
  3102. len -= l2cap_get_conf_opt(&rsp, &type, &olen, &val);
  3103. if (len < 0)
  3104. break;
  3105. switch (type) {
  3106. case L2CAP_CONF_MTU:
  3107. if (olen != 2)
  3108. break;
  3109. if (val < L2CAP_DEFAULT_MIN_MTU) {
  3110. *result = L2CAP_CONF_UNACCEPT;
  3111. pi->imtu = L2CAP_DEFAULT_MIN_MTU;
  3112. } else
  3113. pi->imtu = val;
  3114. l2cap_add_conf_opt(&ptr, L2CAP_CONF_MTU, 2, pi->imtu,
  3115. endptr - ptr);
  3116. break;
  3117. case L2CAP_CONF_FLUSH_TO:
  3118. if (olen != 2)
  3119. break;
  3120. pi->flush_to = val;
  3121. l2cap_add_conf_opt(&ptr, L2CAP_CONF_FLUSH_TO, 2,
  3122. pi->flush_to, endptr - ptr);
  3123. break;
  3124. case L2CAP_CONF_RFC:
  3125. if (olen != sizeof(rfc))
  3126. break;
  3127. memcpy(&rfc, (void *)val, olen);
  3128. if ((pi->conf_state & L2CAP_CONF_STATE2_DEVICE) &&
  3129. rfc.mode != pi->mode)
  3130. return -ECONNREFUSED;
  3131. pi->fcs = 0;
  3132. l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC, sizeof(rfc),
  3133. (unsigned long) &rfc, endptr - ptr);
  3134. break;
  3135. case L2CAP_CONF_EXT_WINDOW:
  3136. if (olen != 2)
  3137. break;
  3138. pi->ack_win = min_t(u16, val, pi->ack_win);
  3139. l2cap_add_conf_opt(&ptr, L2CAP_CONF_EXT_WINDOW,
  3140. 2, pi->tx_win, endptr - ptr);
  3141. break;
  3142. default:
  3143. break;
  3144. }
  3145. }
  3146. if (pi->mode == L2CAP_MODE_BASIC && pi->mode != rfc.mode)
  3147. return -ECONNREFUSED;
  3148. pi->mode = rfc.mode;
  3149. if (*result == L2CAP_CONF_SUCCESS) {
  3150. switch (rfc.mode) {
  3151. case L2CAP_MODE_ERTM:
  3152. pi->retrans_timeout = le16_to_cpu(rfc.retrans_timeout);
  3153. pi->monitor_timeout = le16_to_cpu(rfc.monitor_timeout);
  3154. pi->mps = le16_to_cpu(rfc.max_pdu_size);
  3155. if (!pi->extended_control) {
  3156. pi->ack_win = min_t(u16, pi->ack_win,
  3157. rfc.txwin_size);
  3158. }
  3159. break;
  3160. case L2CAP_MODE_STREAMING:
  3161. pi->mps = le16_to_cpu(rfc.max_pdu_size);
  3162. }
  3163. }
  3164. req->dcid = cpu_to_le16(pi->dcid);
  3165. req->flags = cpu_to_le16(0x0000);
  3166. return ptr - data;
  3167. }
  3168. static int l2cap_build_conf_rsp(struct sock *sk, void *data, u16 result, u16 flags)
  3169. {
  3170. struct l2cap_conf_rsp *rsp = data;
  3171. void *ptr = rsp->data;
  3172. BT_DBG("sk %p", sk);
  3173. rsp->scid = cpu_to_le16(l2cap_pi(sk)->dcid);
  3174. rsp->result = cpu_to_le16(result);
  3175. rsp->flags = cpu_to_le16(flags);
  3176. return ptr - data;
  3177. }
  3178. static void l2cap_conf_rfc_get(struct sock *sk, void *rsp, int len)
  3179. {
  3180. struct l2cap_pinfo *pi = l2cap_pi(sk);
  3181. int type, olen;
  3182. unsigned long val;
  3183. struct l2cap_conf_rfc rfc;
  3184. u16 txwin_ext = pi->ack_win;
  3185. BT_DBG("sk %p, rsp %p, len %d", sk, rsp, len);
  3186. /* Initialize rfc in case no rfc option is received */
  3187. rfc.mode = pi->mode;
  3188. rfc.retrans_timeout = cpu_to_le16(L2CAP_DEFAULT_RETRANS_TO);
  3189. rfc.monitor_timeout = cpu_to_le16(L2CAP_DEFAULT_MONITOR_TO);
  3190. rfc.max_pdu_size = cpu_to_le16(L2CAP_DEFAULT_MAX_PDU_SIZE);
  3191. rfc.txwin_size = min_t(u16, pi->ack_win, L2CAP_DEFAULT_TX_WINDOW);
  3192. if ((pi->mode != L2CAP_MODE_ERTM) && (pi->mode != L2CAP_MODE_STREAMING))
  3193. return;
  3194. while (len >= L2CAP_CONF_OPT_SIZE) {
  3195. len -= l2cap_get_conf_opt(&rsp, &type, &olen, &val);
  3196. if (len < 0)
  3197. break;
  3198. switch (type) {
  3199. case L2CAP_CONF_RFC:
  3200. if (olen != sizeof(rfc))
  3201. break;
  3202. memcpy(&rfc, (void *)val, olen);
  3203. break;
  3204. case L2CAP_CONF_EXT_WINDOW:
  3205. if (olen != 2)
  3206. break;
  3207. txwin_ext = val;
  3208. break;
  3209. }
  3210. }
  3211. switch (rfc.mode) {
  3212. case L2CAP_MODE_ERTM:
  3213. pi->retrans_timeout = le16_to_cpu(rfc.retrans_timeout);
  3214. pi->monitor_timeout = le16_to_cpu(rfc.monitor_timeout);
  3215. pi->mps = le16_to_cpu(rfc.max_pdu_size);
  3216. if (pi->extended_control)
  3217. pi->ack_win = min_t(u16, pi->ack_win, txwin_ext);
  3218. else
  3219. pi->ack_win = min_t(u16, pi->ack_win, rfc.txwin_size);
  3220. break;
  3221. case L2CAP_MODE_STREAMING:
  3222. pi->mps = le16_to_cpu(rfc.max_pdu_size);
  3223. }
  3224. }
  3225. static void l2cap_conf_ext_fs_get(struct sock *sk, void *rsp, int len)
  3226. {
  3227. struct l2cap_pinfo *pi = l2cap_pi(sk);
  3228. int type, olen;
  3229. unsigned long val;
  3230. struct l2cap_conf_ext_fs fs;
  3231. BT_DBG("sk %p, rsp %p, len %d", sk, rsp, len);
  3232. while (len >= L2CAP_CONF_OPT_SIZE) {
  3233. len -= l2cap_get_conf_opt(&rsp, &type, &olen, &val);
  3234. if ((type == L2CAP_CONF_EXT_FS) &&
  3235. (olen == sizeof(struct l2cap_conf_ext_fs))) {
  3236. memcpy(&fs, (void *)val, olen);
  3237. pi->local_fs.id = fs.id;
  3238. pi->local_fs.type = fs.type;
  3239. pi->local_fs.max_sdu = le16_to_cpu(fs.max_sdu);
  3240. pi->local_fs.sdu_arr_time =
  3241. le32_to_cpu(fs.sdu_arr_time);
  3242. pi->local_fs.acc_latency = le32_to_cpu(fs.acc_latency);
  3243. pi->local_fs.flush_to = le32_to_cpu(fs.flush_to);
  3244. break;
  3245. }
  3246. }
  3247. }
  3248. static int l2cap_finish_amp_move(struct sock *sk)
  3249. {
  3250. struct l2cap_pinfo *pi;
  3251. int err;
  3252. BT_DBG("sk %p", sk);
  3253. pi = l2cap_pi(sk);
  3254. pi->amp_move_role = L2CAP_AMP_MOVE_NONE;
  3255. pi->rx_state = L2CAP_ERTM_RX_STATE_RECV;
  3256. if (pi->ampcon)
  3257. pi->conn->mtu = pi->ampcon->hdev->acl_mtu;
  3258. else
  3259. pi->conn->mtu = pi->conn->hcon->hdev->acl_mtu;
  3260. err = l2cap_setup_resegment(sk);
  3261. return err;
  3262. }
  3263. static int l2cap_amp_move_reconf_rsp(struct sock *sk, void *rsp, int len,
  3264. u16 result)
  3265. {
  3266. int err = 0;
  3267. struct l2cap_conf_rfc rfc = {.mode = L2CAP_MODE_BASIC};
  3268. struct l2cap_pinfo *pi = l2cap_pi(sk);
  3269. BT_DBG("sk %p, rsp %p, len %d, res 0x%2.2x", sk, rsp, len, result);
  3270. if (pi->reconf_state == L2CAP_RECONF_NONE)
  3271. return -ECONNREFUSED;
  3272. if (result == L2CAP_CONF_SUCCESS) {
  3273. while (len >= L2CAP_CONF_OPT_SIZE) {
  3274. int type, olen;
  3275. unsigned long val;
  3276. len -= l2cap_get_conf_opt(&rsp, &type, &olen, &val);
  3277. if (type == L2CAP_CONF_RFC) {
  3278. if (olen == sizeof(rfc))
  3279. memcpy(&rfc, (void *)val, olen);
  3280. if (rfc.mode != pi->mode) {
  3281. l2cap_send_disconn_req(pi->conn, sk,
  3282. ECONNRESET);
  3283. return -ECONNRESET;
  3284. }
  3285. goto done;
  3286. }
  3287. }
  3288. }
  3289. BT_ERR("Expected RFC option was missing, using existing values");
  3290. rfc.mode = pi->mode;
  3291. rfc.retrans_timeout = cpu_to_le16(pi->retrans_timeout);
  3292. rfc.monitor_timeout = cpu_to_le16(pi->monitor_timeout);
  3293. done:
  3294. l2cap_ertm_stop_ack_timer(pi);
  3295. l2cap_ertm_stop_retrans_timer(pi);
  3296. l2cap_ertm_stop_monitor_timer(pi);
  3297. pi->mps = le16_to_cpu(rfc.max_pdu_size);
  3298. if (pi->mode == L2CAP_MODE_ERTM) {
  3299. pi->retrans_timeout = le16_to_cpu(rfc.retrans_timeout);
  3300. pi->monitor_timeout = le16_to_cpu(rfc.monitor_timeout);
  3301. }
  3302. if (l2cap_pi(sk)->reconf_state == L2CAP_RECONF_ACC) {
  3303. l2cap_pi(sk)->reconf_state = L2CAP_RECONF_NONE;
  3304. /* Respond to poll */
  3305. err = l2cap_answer_move_poll(sk);
  3306. } else if (l2cap_pi(sk)->reconf_state == L2CAP_RECONF_INT) {
  3307. if (pi->mode == L2CAP_MODE_ERTM) {
  3308. l2cap_ertm_tx(sk, NULL, NULL,
  3309. L2CAP_ERTM_EVENT_EXPLICIT_POLL);
  3310. pi->rx_state = L2CAP_ERTM_RX_STATE_WAIT_F_FLAG;
  3311. }
  3312. }
  3313. return err;
  3314. }
  3315. static inline int l2cap_command_rej(struct l2cap_conn *conn,
  3316. struct l2cap_cmd_hdr *cmd, u16 cmd_len,
  3317. u8 *data)
  3318. {
  3319. struct l2cap_cmd_rej *rej = (struct l2cap_cmd_rej *) data;
  3320. if (cmd_len < sizeof(*rej))
  3321. return -EPROTO;
  3322. if (rej->reason != 0x0000)
  3323. return 0;
  3324. if ((conn->info_state & L2CAP_INFO_FEAT_MASK_REQ_SENT) &&
  3325. cmd->ident == conn->info_ident) {
  3326. del_timer(&conn->info_timer);
  3327. conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_DONE;
  3328. conn->info_ident = 0;
  3329. l2cap_conn_start(conn);
  3330. }
  3331. return 0;
  3332. }
  3333. static struct sock *l2cap_create_connect(struct l2cap_conn *conn,
  3334. struct l2cap_cmd_hdr *cmd,
  3335. u16 cmd_len, u8 *data,
  3336. u8 rsp_code,
  3337. u8 amp_id)
  3338. {
  3339. struct l2cap_chan_list *list = &conn->chan_list;
  3340. struct l2cap_conn_req *req = (struct l2cap_conn_req *) data;
  3341. struct l2cap_conn_rsp rsp;
  3342. struct sock *parent, *sk = NULL;
  3343. int result, status = L2CAP_CS_NO_INFO;
  3344. u16 dcid = 0, scid;
  3345. __le16 psm;
  3346. if (cmd_len < sizeof(struct l2cap_conn_req))
  3347. return NULL;
  3348. scid = __le16_to_cpu(req->scid);
  3349. psm = req->psm;
  3350. BT_DBG("psm 0x%2.2x scid 0x%4.4x", psm, scid);
  3351. /* Check if we have socket listening on psm */
  3352. parent = l2cap_get_sock_by_psm(BT_LISTEN, psm, conn->src);
  3353. if (!parent) {
  3354. result = L2CAP_CR_BAD_PSM;
  3355. goto sendresp;
  3356. }
  3357. bh_lock_sock(parent);
  3358. /* Check if the ACL is secure enough (if not SDP) */
  3359. if (psm != cpu_to_le16(0x0001) &&
  3360. !hci_conn_check_link_mode(conn->hcon)) {
  3361. conn->disc_reason = 0x05;
  3362. result = L2CAP_CR_SEC_BLOCK;
  3363. goto response;
  3364. }
  3365. result = L2CAP_CR_NO_MEM;
  3366. /* Check for backlog size */
  3367. if (sk_acceptq_is_full(parent)) {
  3368. BT_DBG("backlog full %d", parent->sk_ack_backlog);
  3369. goto response;
  3370. }
  3371. sk = l2cap_sock_alloc(sock_net(parent), NULL, BTPROTO_L2CAP, GFP_ATOMIC);
  3372. if (!sk)
  3373. goto response;
  3374. write_lock_bh(&list->lock);
  3375. /* Check if we already have channel with that dcid */
  3376. if (__l2cap_get_chan_by_dcid(list, scid)) {
  3377. write_unlock_bh(&list->lock);
  3378. sock_set_flag(sk, SOCK_ZAPPED);
  3379. l2cap_sock_kill(sk);
  3380. sk = NULL;
  3381. goto response;
  3382. }
  3383. hci_conn_hold(conn->hcon);
  3384. l2cap_sock_init(sk, parent);
  3385. bacpy(&bt_sk(sk)->src, conn->src);
  3386. bacpy(&bt_sk(sk)->dst, conn->dst);
  3387. l2cap_pi(sk)->psm = psm;
  3388. l2cap_pi(sk)->dcid = scid;
  3389. bt_accept_enqueue(parent, sk);
  3390. __l2cap_chan_add(conn, sk);
  3391. dcid = l2cap_pi(sk)->scid;
  3392. l2cap_pi(sk)->amp_id = amp_id;
  3393. l2cap_sock_set_timer(sk, sk->sk_sndtimeo);
  3394. l2cap_pi(sk)->ident = cmd->ident;
  3395. if (conn->info_state & L2CAP_INFO_FEAT_MASK_REQ_DONE) {
  3396. if (l2cap_check_security(sk)) {
  3397. if (bt_sk(sk)->defer_setup) {
  3398. sk->sk_state = BT_CONNECT2;
  3399. result = L2CAP_CR_PEND;
  3400. status = L2CAP_CS_AUTHOR_PEND;
  3401. parent->sk_data_ready(parent, 0);
  3402. } else {
  3403. /* Force pending result for AMP controllers.
  3404. * The connection will succeed after the
  3405. * physical link is up. */
  3406. if (amp_id) {
  3407. sk->sk_state = BT_CONNECT2;
  3408. result = L2CAP_CR_PEND;
  3409. } else {
  3410. sk->sk_state = BT_CONFIG;
  3411. result = L2CAP_CR_SUCCESS;
  3412. }
  3413. status = L2CAP_CS_NO_INFO;
  3414. }
  3415. } else {
  3416. sk->sk_state = BT_CONNECT2;
  3417. result = L2CAP_CR_PEND;
  3418. status = L2CAP_CS_AUTHEN_PEND;
  3419. }
  3420. } else {
  3421. sk->sk_state = BT_CONNECT2;
  3422. result = L2CAP_CR_PEND;
  3423. status = L2CAP_CS_NO_INFO;
  3424. }
  3425. write_unlock_bh(&list->lock);
  3426. response:
  3427. bh_unlock_sock(parent);
  3428. sendresp:
  3429. rsp.scid = cpu_to_le16(scid);
  3430. rsp.dcid = cpu_to_le16(dcid);
  3431. rsp.result = cpu_to_le16(result);
  3432. rsp.status = cpu_to_le16(status);
  3433. l2cap_send_cmd(conn, cmd->ident, rsp_code, sizeof(rsp), &rsp);
  3434. if (!(conn->info_state & L2CAP_INFO_FEAT_MASK_REQ_DONE)) {
  3435. struct l2cap_info_req info;
  3436. info.type = cpu_to_le16(L2CAP_IT_FEAT_MASK);
  3437. conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_SENT;
  3438. conn->info_ident = l2cap_get_ident(conn);
  3439. mod_timer(&conn->info_timer, jiffies +
  3440. msecs_to_jiffies(L2CAP_INFO_TIMEOUT));
  3441. l2cap_send_cmd(conn, conn->info_ident,
  3442. L2CAP_INFO_REQ, sizeof(info), &info);
  3443. }
  3444. if (sk && !(l2cap_pi(sk)->conf_state & L2CAP_CONF_REQ_SENT) &&
  3445. result == L2CAP_CR_SUCCESS) {
  3446. u8 buf[128];
  3447. l2cap_pi(sk)->conf_state |= L2CAP_CONF_REQ_SENT;
  3448. l2cap_send_cmd(conn, l2cap_get_ident(conn), L2CAP_CONF_REQ,
  3449. l2cap_build_conf_req(sk, buf, sizeof(buf)), buf);
  3450. l2cap_pi(sk)->num_conf_req++;
  3451. }
  3452. return sk;
  3453. }
  3454. static inline int l2cap_connect_req(struct l2cap_conn *conn,
  3455. struct l2cap_cmd_hdr *cmd, u16 cmd_len, u8 *data)
  3456. {
  3457. if (!l2cap_create_connect(conn, cmd, cmd_len, data, L2CAP_CONN_RSP, 0))
  3458. return -EPROTO;
  3459. else
  3460. return 0;
  3461. }
  3462. static inline int l2cap_connect_rsp(struct l2cap_conn *conn,
  3463. struct l2cap_cmd_hdr *cmd, u16 cmd_len,
  3464. u8 *data)
  3465. {
  3466. struct l2cap_conn_rsp *rsp = (struct l2cap_conn_rsp *) data;
  3467. u16 scid, dcid, result, status;
  3468. struct sock *sk;
  3469. u8 req[128];
  3470. if (cmd_len < sizeof(*rsp))
  3471. return -EPROTO;
  3472. scid = __le16_to_cpu(rsp->scid);
  3473. dcid = __le16_to_cpu(rsp->dcid);
  3474. result = __le16_to_cpu(rsp->result);
  3475. status = __le16_to_cpu(rsp->status);
  3476. BT_DBG("dcid 0x%4.4x scid 0x%4.4x result 0x%2.2x status 0x%2.2x", dcid, scid, result, status);
  3477. if (scid) {
  3478. sk = l2cap_get_chan_by_scid(&conn->chan_list, scid);
  3479. if (!sk)
  3480. return -EFAULT;
  3481. } else {
  3482. sk = l2cap_get_chan_by_ident(&conn->chan_list, cmd->ident);
  3483. if (!sk)
  3484. return -EFAULT;
  3485. }
  3486. switch (result) {
  3487. case L2CAP_CR_SUCCESS:
  3488. sk->sk_state = BT_CONFIG;
  3489. l2cap_pi(sk)->ident = 0;
  3490. l2cap_pi(sk)->dcid = dcid;
  3491. l2cap_pi(sk)->conf_state &= ~L2CAP_CONF_CONNECT_PEND;
  3492. if (l2cap_pi(sk)->conf_state & L2CAP_CONF_REQ_SENT)
  3493. break;
  3494. l2cap_pi(sk)->conf_state |= L2CAP_CONF_REQ_SENT;
  3495. l2cap_send_cmd(conn, l2cap_get_ident(conn), L2CAP_CONF_REQ,
  3496. l2cap_build_conf_req(sk, req, sizeof(req)), req);
  3497. l2cap_pi(sk)->num_conf_req++;
  3498. break;
  3499. case L2CAP_CR_PEND:
  3500. l2cap_pi(sk)->conf_state |= L2CAP_CONF_CONNECT_PEND;
  3501. break;
  3502. default:
  3503. /* don't delete l2cap channel if sk is owned by user */
  3504. if (sock_owned_by_user(sk)) {
  3505. sk->sk_state = BT_DISCONN;
  3506. l2cap_sock_clear_timer(sk);
  3507. l2cap_sock_set_timer(sk, HZ / 5);
  3508. break;
  3509. }
  3510. l2cap_chan_del(sk, ECONNREFUSED);
  3511. break;
  3512. }
  3513. bh_unlock_sock(sk);
  3514. return 0;
  3515. }
  3516. static inline void set_default_fcs(struct l2cap_pinfo *pi)
  3517. {
  3518. /* FCS is enabled only in ERTM or streaming mode, if one or both
  3519. * sides request it.
  3520. */
  3521. if (pi->mode != L2CAP_MODE_ERTM && pi->mode != L2CAP_MODE_STREAMING)
  3522. pi->fcs = L2CAP_FCS_NONE;
  3523. else if (!(pi->conf_state & L2CAP_CONF_NO_FCS_RECV))
  3524. pi->fcs = L2CAP_FCS_CRC16;
  3525. }
  3526. static inline int l2cap_config_req(struct l2cap_conn *conn, struct l2cap_cmd_hdr *cmd, u16 cmd_len, u8 *data)
  3527. {
  3528. struct l2cap_conf_req *req = (struct l2cap_conf_req *) data;
  3529. u16 dcid, flags;
  3530. u8 rspbuf[64];
  3531. struct l2cap_conf_rsp *rsp = (struct l2cap_conf_rsp *) rspbuf;
  3532. struct sock *sk;
  3533. int len;
  3534. u8 amp_move_reconf = 0;
  3535. if (cmd_len < sizeof(*req))
  3536. return -EPROTO;
  3537. dcid = __le16_to_cpu(req->dcid);
  3538. flags = __le16_to_cpu(req->flags);
  3539. BT_DBG("dcid 0x%4.4x flags 0x%2.2x", dcid, flags);
  3540. sk = l2cap_get_chan_by_scid(&conn->chan_list, dcid);
  3541. if (!sk)
  3542. return -ENOENT;
  3543. BT_DBG("sk_state 0x%2.2x rx_state 0x%2.2x "
  3544. "reconf_state 0x%2.2x amp_id 0x%2.2x amp_move_id 0x%2.2x",
  3545. sk->sk_state, l2cap_pi(sk)->rx_state,
  3546. l2cap_pi(sk)->reconf_state, l2cap_pi(sk)->amp_id,
  3547. l2cap_pi(sk)->amp_move_id);
  3548. /* Detect a reconfig request due to channel move between
  3549. * BR/EDR and AMP
  3550. */
  3551. if (sk->sk_state == BT_CONNECTED &&
  3552. l2cap_pi(sk)->rx_state ==
  3553. L2CAP_ERTM_RX_STATE_WAIT_P_FLAG_RECONFIGURE)
  3554. l2cap_pi(sk)->reconf_state = L2CAP_RECONF_ACC;
  3555. if (l2cap_pi(sk)->reconf_state != L2CAP_RECONF_NONE)
  3556. amp_move_reconf = 1;
  3557. if (sk->sk_state != BT_CONFIG && !amp_move_reconf) {
  3558. struct l2cap_cmd_rej rej;
  3559. rej.reason = cpu_to_le16(0x0002);
  3560. l2cap_send_cmd(conn, cmd->ident, L2CAP_COMMAND_REJ,
  3561. sizeof(rej), &rej);
  3562. goto unlock;
  3563. }
  3564. /* Reject if config buffer is too small. */
  3565. len = cmd_len - sizeof(*req);
  3566. if (l2cap_pi(sk)->conf_len + len > sizeof(l2cap_pi(sk)->conf_req)) {
  3567. l2cap_send_cmd(conn, cmd->ident, L2CAP_CONF_RSP,
  3568. l2cap_build_conf_rsp(sk, rspbuf,
  3569. L2CAP_CONF_REJECT, flags), rspbuf);
  3570. goto unlock;
  3571. }
  3572. /* Store config. */
  3573. memcpy(l2cap_pi(sk)->conf_req + l2cap_pi(sk)->conf_len, req->data, len);
  3574. l2cap_pi(sk)->conf_len += len;
  3575. if (flags & 0x0001) {
  3576. /* Incomplete config. Send empty response. */
  3577. l2cap_send_cmd(conn, cmd->ident, L2CAP_CONF_RSP,
  3578. l2cap_build_conf_rsp(sk, rspbuf,
  3579. L2CAP_CONF_SUCCESS, 0x0001), rspbuf);
  3580. goto unlock;
  3581. }
  3582. /* Complete config. */
  3583. if (!amp_move_reconf)
  3584. len = l2cap_parse_conf_req(sk, rspbuf, sizeof(rspbuf));
  3585. else
  3586. len = l2cap_parse_amp_move_reconf_req(sk, rspbuf, sizeof(rspbuf));
  3587. if (len < 0) {
  3588. l2cap_send_disconn_req(conn, sk, ECONNRESET);
  3589. goto unlock;
  3590. }
  3591. l2cap_pi(sk)->conf_ident = cmd->ident;
  3592. l2cap_send_cmd(conn, cmd->ident, L2CAP_CONF_RSP, len, rspbuf);
  3593. if (l2cap_pi(sk)->conf_state & L2CAP_CONF_LOCKSTEP &&
  3594. rsp->result == cpu_to_le16(L2CAP_CONF_PENDING) &&
  3595. !l2cap_pi(sk)->amp_id) {
  3596. /* Send success response right after pending if using
  3597. * lockstep config on BR/EDR
  3598. */
  3599. rsp->result = cpu_to_le16(L2CAP_CONF_SUCCESS);
  3600. l2cap_pi(sk)->conf_state |= L2CAP_CONF_OUTPUT_DONE;
  3601. l2cap_send_cmd(conn, cmd->ident, L2CAP_CONF_RSP, len, rspbuf);
  3602. }
  3603. /* Reset config buffer. */
  3604. l2cap_pi(sk)->conf_len = 0;
  3605. if (amp_move_reconf)
  3606. goto unlock;
  3607. l2cap_pi(sk)->num_conf_rsp++;
  3608. if (!(l2cap_pi(sk)->conf_state & L2CAP_CONF_OUTPUT_DONE))
  3609. goto unlock;
  3610. if (l2cap_pi(sk)->conf_state & L2CAP_CONF_INPUT_DONE) {
  3611. set_default_fcs(l2cap_pi(sk));
  3612. sk->sk_state = BT_CONNECTED;
  3613. if (l2cap_pi(sk)->mode == L2CAP_MODE_ERTM ||
  3614. l2cap_pi(sk)->mode == L2CAP_MODE_STREAMING)
  3615. l2cap_ertm_init(sk);
  3616. l2cap_chan_ready(sk);
  3617. goto unlock;
  3618. }
  3619. if (!(l2cap_pi(sk)->conf_state & L2CAP_CONF_REQ_SENT)) {
  3620. u8 buf[64];
  3621. l2cap_pi(sk)->conf_state |= L2CAP_CONF_REQ_SENT;
  3622. l2cap_send_cmd(conn, l2cap_get_ident(conn), L2CAP_CONF_REQ,
  3623. l2cap_build_conf_req(sk, buf, sizeof(buf)), buf);
  3624. l2cap_pi(sk)->num_conf_req++;
  3625. }
  3626. unlock:
  3627. bh_unlock_sock(sk);
  3628. return 0;
  3629. }
  3630. static inline int l2cap_config_rsp(struct l2cap_conn *conn,
  3631. struct l2cap_cmd_hdr *cmd, u16 cmd_len,
  3632. u8 *data)
  3633. {
  3634. struct l2cap_conf_rsp *rsp = (struct l2cap_conf_rsp *)data;
  3635. u16 scid, flags, result;
  3636. struct sock *sk;
  3637. struct l2cap_pinfo *pi;
  3638. int len = cmd->len - sizeof(*rsp);
  3639. if (cmd_len != sizeof(*rsp))
  3640. return -EPROTO;
  3641. scid = __le16_to_cpu(rsp->scid);
  3642. flags = __le16_to_cpu(rsp->flags);
  3643. result = __le16_to_cpu(rsp->result);
  3644. BT_DBG("scid 0x%4.4x flags 0x%2.2x result 0x%2.2x",
  3645. scid, flags, result);
  3646. sk = l2cap_get_chan_by_scid(&conn->chan_list, scid);
  3647. if (!sk)
  3648. return 0;
  3649. pi = l2cap_pi(sk);
  3650. if (pi->reconf_state != L2CAP_RECONF_NONE) {
  3651. l2cap_amp_move_reconf_rsp(sk, rsp->data, len, result);
  3652. goto done;
  3653. }
  3654. switch (result) {
  3655. case L2CAP_CONF_SUCCESS:
  3656. if (pi->conf_state & L2CAP_CONF_LOCKSTEP &&
  3657. !(pi->conf_state & L2CAP_CONF_LOCKSTEP_PEND)) {
  3658. /* Lockstep procedure requires a pending response
  3659. * before success.
  3660. */
  3661. l2cap_send_disconn_req(conn, sk, ECONNRESET);
  3662. goto done;
  3663. }
  3664. l2cap_conf_rfc_get(sk, rsp->data, len);
  3665. break;
  3666. case L2CAP_CONF_PENDING:
  3667. if (!(pi->conf_state & L2CAP_CONF_LOCKSTEP)) {
  3668. l2cap_send_disconn_req(conn, sk, ECONNRESET);
  3669. goto done;
  3670. }
  3671. l2cap_conf_rfc_get(sk, rsp->data, len);
  3672. pi->conf_state |= L2CAP_CONF_LOCKSTEP_PEND;
  3673. l2cap_conf_ext_fs_get(sk, rsp->data, len);
  3674. if (pi->amp_id && pi->conf_state & L2CAP_CONF_PEND_SENT) {
  3675. struct hci_chan *chan;
  3676. /* Already sent a 'pending' response, so set up
  3677. * the logical link now
  3678. */
  3679. chan = l2cap_chan_admit(pi->amp_id, sk);
  3680. if (!chan) {
  3681. l2cap_send_disconn_req(pi->conn, sk,
  3682. ECONNRESET);
  3683. goto done;
  3684. }
  3685. if (chan->state == BT_CONNECTED)
  3686. l2cap_create_cfm(chan, 0);
  3687. }
  3688. goto done;
  3689. case L2CAP_CONF_UNACCEPT:
  3690. if (pi->num_conf_rsp <= L2CAP_CONF_MAX_CONF_RSP) {
  3691. char req[64];
  3692. if (len > sizeof(req) - sizeof(struct l2cap_conf_req)) {
  3693. l2cap_send_disconn_req(conn, sk, ECONNRESET);
  3694. goto done;
  3695. }
  3696. /* throw out any old stored conf requests */
  3697. result = L2CAP_CONF_SUCCESS;
  3698. len = l2cap_parse_conf_rsp(sk, rsp->data,
  3699. len, req, sizeof(req), &result);
  3700. if (len < 0) {
  3701. l2cap_send_disconn_req(conn, sk, ECONNRESET);
  3702. goto done;
  3703. }
  3704. l2cap_send_cmd(conn, l2cap_get_ident(conn),
  3705. L2CAP_CONF_REQ, len, req);
  3706. pi->num_conf_req++;
  3707. if (result != L2CAP_CONF_SUCCESS)
  3708. goto done;
  3709. break;
  3710. }
  3711. default:
  3712. sk->sk_err = ECONNRESET;
  3713. l2cap_sock_set_timer(sk, HZ * 5);
  3714. l2cap_send_disconn_req(conn, sk, ECONNRESET);
  3715. goto done;
  3716. }
  3717. if (flags & 0x01)
  3718. goto done;
  3719. pi->conf_state |= L2CAP_CONF_INPUT_DONE;
  3720. if (pi->conf_state & L2CAP_CONF_OUTPUT_DONE) {
  3721. set_default_fcs(pi);
  3722. sk->sk_state = BT_CONNECTED;
  3723. if (pi->mode == L2CAP_MODE_ERTM ||
  3724. pi->mode == L2CAP_MODE_STREAMING)
  3725. l2cap_ertm_init(sk);
  3726. l2cap_chan_ready(sk);
  3727. }
  3728. done:
  3729. bh_unlock_sock(sk);
  3730. return 0;
  3731. }
  3732. static inline int l2cap_disconnect_req(struct l2cap_conn *conn,
  3733. struct l2cap_cmd_hdr *cmd, u16 cmd_len,
  3734. u8 *data)
  3735. {
  3736. struct l2cap_disconn_req *req = (struct l2cap_disconn_req *) data;
  3737. struct l2cap_disconn_rsp rsp;
  3738. u16 dcid, scid;
  3739. struct sock *sk;
  3740. if (cmd_len != sizeof(rsp))
  3741. return -EPROTO;
  3742. scid = __le16_to_cpu(req->scid);
  3743. dcid = __le16_to_cpu(req->dcid);
  3744. BT_DBG("scid 0x%4.4x dcid 0x%4.4x", scid, dcid);
  3745. sk = l2cap_get_chan_by_scid(&conn->chan_list, dcid);
  3746. if (!sk)
  3747. return 0;
  3748. rsp.dcid = cpu_to_le16(l2cap_pi(sk)->scid);
  3749. rsp.scid = cpu_to_le16(l2cap_pi(sk)->dcid);
  3750. l2cap_send_cmd(conn, cmd->ident, L2CAP_DISCONN_RSP, sizeof(rsp), &rsp);
  3751. /* Only do cleanup if a disconnect request was not sent already */
  3752. if (sk->sk_state != BT_DISCONN) {
  3753. sk->sk_shutdown = SHUTDOWN_MASK;
  3754. sk->sk_send_head = NULL;
  3755. skb_queue_purge(TX_QUEUE(sk));
  3756. if (l2cap_pi(sk)->mode == L2CAP_MODE_ERTM) {
  3757. skb_queue_purge(SREJ_QUEUE(sk));
  3758. __cancel_delayed_work(&l2cap_pi(sk)->ack_work);
  3759. __cancel_delayed_work(&l2cap_pi(sk)->retrans_work);
  3760. __cancel_delayed_work(&l2cap_pi(sk)->monitor_work);
  3761. }
  3762. }
  3763. /* don't delete l2cap channel if sk is owned by user */
  3764. if (sock_owned_by_user(sk)) {
  3765. sk->sk_state = BT_DISCONN;
  3766. l2cap_sock_clear_timer(sk);
  3767. l2cap_sock_set_timer(sk, HZ / 5);
  3768. bh_unlock_sock(sk);
  3769. return 0;
  3770. }
  3771. l2cap_chan_del(sk, ECONNRESET);
  3772. bh_unlock_sock(sk);
  3773. l2cap_sock_kill(sk);
  3774. return 0;
  3775. }
  3776. static inline int l2cap_disconnect_rsp(struct l2cap_conn *conn,
  3777. struct l2cap_cmd_hdr *cmd, u16 cmd_len,
  3778. u8 *data)
  3779. {
  3780. struct l2cap_disconn_rsp *rsp = (struct l2cap_disconn_rsp *) data;
  3781. u16 dcid, scid;
  3782. struct sock *sk;
  3783. if (cmd_len != sizeof(*rsp))
  3784. return -EPROTO;
  3785. scid = __le16_to_cpu(rsp->scid);
  3786. dcid = __le16_to_cpu(rsp->dcid);
  3787. BT_DBG("dcid 0x%4.4x scid 0x%4.4x", dcid, scid);
  3788. sk = l2cap_get_chan_by_scid(&conn->chan_list, scid);
  3789. if (!sk)
  3790. return 0;
  3791. /* don't delete l2cap channel if sk is owned by user */
  3792. if (sock_owned_by_user(sk)) {
  3793. sk->sk_state = BT_DISCONN;
  3794. l2cap_sock_clear_timer(sk);
  3795. l2cap_sock_set_timer(sk, HZ / 5);
  3796. bh_unlock_sock(sk);
  3797. return 0;
  3798. }
  3799. l2cap_chan_del(sk, 0);
  3800. bh_unlock_sock(sk);
  3801. l2cap_sock_kill(sk);
  3802. return 0;
  3803. }
  3804. static inline int l2cap_information_req(struct l2cap_conn *conn,
  3805. struct l2cap_cmd_hdr *cmd, u16 cmd_len,
  3806. u8 *data)
  3807. {
  3808. struct l2cap_info_req *req = (struct l2cap_info_req *) data;
  3809. u16 type;
  3810. if (cmd_len != sizeof(*req))
  3811. return -EPROTO;
  3812. type = __le16_to_cpu(req->type);
  3813. BT_DBG("type 0x%4.4x", type);
  3814. if (type == L2CAP_IT_FEAT_MASK) {
  3815. u8 buf[8];
  3816. u32 feat_mask = l2cap_feat_mask;
  3817. struct l2cap_info_rsp *rsp = (struct l2cap_info_rsp *) buf;
  3818. rsp->type = cpu_to_le16(L2CAP_IT_FEAT_MASK);
  3819. rsp->result = cpu_to_le16(L2CAP_IR_SUCCESS);
  3820. if (!disable_ertm)
  3821. feat_mask |= L2CAP_FEAT_ERTM | L2CAP_FEAT_STREAMING
  3822. | L2CAP_FEAT_FCS | L2CAP_FEAT_EXT_WINDOW;
  3823. put_unaligned_le32(feat_mask, rsp->data);
  3824. l2cap_send_cmd(conn, cmd->ident,
  3825. L2CAP_INFO_RSP, sizeof(buf), buf);
  3826. } else if (type == L2CAP_IT_FIXED_CHAN) {
  3827. u8 buf[12];
  3828. u8 fc_mask = l2cap_fc_mask;
  3829. struct l2cap_info_rsp *rsp = (struct l2cap_info_rsp *) buf;
  3830. rsp->type = cpu_to_le16(L2CAP_IT_FIXED_CHAN);
  3831. rsp->result = cpu_to_le16(L2CAP_IR_SUCCESS);
  3832. if (enable_hs)
  3833. fc_mask |= L2CAP_FC_A2MP;
  3834. memset(rsp->data, 0, 8);
  3835. rsp->data[0] = fc_mask;
  3836. l2cap_send_cmd(conn, cmd->ident,
  3837. L2CAP_INFO_RSP, sizeof(buf), buf);
  3838. } else {
  3839. struct l2cap_info_rsp rsp;
  3840. rsp.type = cpu_to_le16(type);
  3841. rsp.result = cpu_to_le16(L2CAP_IR_NOTSUPP);
  3842. l2cap_send_cmd(conn, cmd->ident,
  3843. L2CAP_INFO_RSP, sizeof(rsp), &rsp);
  3844. }
  3845. return 0;
  3846. }
  3847. static inline int l2cap_information_rsp(struct l2cap_conn *conn,
  3848. struct l2cap_cmd_hdr *cmd, u16 cmd_len,
  3849. u8 *data)
  3850. {
  3851. struct l2cap_info_rsp *rsp = (struct l2cap_info_rsp *) data;
  3852. u16 type, result;
  3853. if (cmd_len < sizeof(*rsp))
  3854. return -EPROTO;
  3855. type = __le16_to_cpu(rsp->type);
  3856. result = __le16_to_cpu(rsp->result);
  3857. BT_DBG("type 0x%4.4x result 0x%2.2x", type, result);
  3858. /* L2CAP Info req/rsp are unbound to channels, add extra checks */
  3859. if (cmd->ident != conn->info_ident ||
  3860. conn->info_state & L2CAP_INFO_FEAT_MASK_REQ_DONE)
  3861. return 0;
  3862. del_timer(&conn->info_timer);
  3863. if (result != L2CAP_IR_SUCCESS) {
  3864. conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_DONE;
  3865. conn->info_ident = 0;
  3866. l2cap_conn_start(conn);
  3867. return 0;
  3868. }
  3869. if (type == L2CAP_IT_FEAT_MASK) {
  3870. conn->feat_mask = get_unaligned_le32(rsp->data);
  3871. if (conn->feat_mask & L2CAP_FEAT_FIXED_CHAN) {
  3872. struct l2cap_info_req req;
  3873. req.type = cpu_to_le16(L2CAP_IT_FIXED_CHAN);
  3874. conn->info_ident = l2cap_get_ident(conn);
  3875. l2cap_send_cmd(conn, conn->info_ident,
  3876. L2CAP_INFO_REQ, sizeof(req), &req);
  3877. } else {
  3878. conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_DONE;
  3879. conn->info_ident = 0;
  3880. l2cap_conn_start(conn);
  3881. }
  3882. } else if (type == L2CAP_IT_FIXED_CHAN) {
  3883. conn->fc_mask = rsp->data[0];
  3884. conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_DONE;
  3885. conn->info_ident = 0;
  3886. l2cap_conn_start(conn);
  3887. }
  3888. return 0;
  3889. }
  3890. static void l2cap_send_move_chan_req(struct l2cap_conn *conn,
  3891. struct l2cap_pinfo *pi, u16 icid, u8 dest_amp_id)
  3892. {
  3893. struct l2cap_move_chan_req req;
  3894. u8 ident;
  3895. BT_DBG("pi %p, icid %d, dest_amp_id %d", pi, (int) icid,
  3896. (int) dest_amp_id);
  3897. ident = l2cap_get_ident(conn);
  3898. if (pi)
  3899. pi->ident = ident;
  3900. req.icid = cpu_to_le16(icid);
  3901. req.dest_amp_id = dest_amp_id;
  3902. l2cap_send_cmd(conn, ident, L2CAP_MOVE_CHAN_REQ, sizeof(req), &req);
  3903. }
  3904. static void l2cap_send_move_chan_rsp(struct l2cap_conn *conn, u8 ident,
  3905. u16 icid, u16 result)
  3906. {
  3907. struct l2cap_move_chan_rsp rsp;
  3908. BT_DBG("icid %d, result %d", (int) icid, (int) result);
  3909. rsp.icid = cpu_to_le16(icid);
  3910. rsp.result = cpu_to_le16(result);
  3911. l2cap_send_cmd(conn, ident, L2CAP_MOVE_CHAN_RSP, sizeof(rsp), &rsp);
  3912. }
  3913. static void l2cap_send_move_chan_cfm(struct l2cap_conn *conn,
  3914. struct l2cap_pinfo *pi, u16 icid, u16 result)
  3915. {
  3916. struct l2cap_move_chan_cfm cfm;
  3917. u8 ident;
  3918. BT_DBG("icid %d, result %d", (int) icid, (int) result);
  3919. ident = l2cap_get_ident(conn);
  3920. if (pi)
  3921. pi->ident = ident;
  3922. cfm.icid = cpu_to_le16(icid);
  3923. cfm.result = cpu_to_le16(result);
  3924. l2cap_send_cmd(conn, ident, L2CAP_MOVE_CHAN_CFM, sizeof(cfm), &cfm);
  3925. }
  3926. static void l2cap_send_move_chan_cfm_rsp(struct l2cap_conn *conn, u8 ident,
  3927. u16 icid)
  3928. {
  3929. struct l2cap_move_chan_cfm_rsp rsp;
  3930. BT_DBG("icid %d", (int) icid);
  3931. rsp.icid = cpu_to_le16(icid);
  3932. l2cap_send_cmd(conn, ident, L2CAP_MOVE_CHAN_CFM_RSP, sizeof(rsp), &rsp);
  3933. }
  3934. static inline int l2cap_create_channel_req(struct l2cap_conn *conn,
  3935. struct l2cap_cmd_hdr *cmd, u16 cmd_len,
  3936. u8 *data)
  3937. {
  3938. struct l2cap_create_chan_req *req =
  3939. (struct l2cap_create_chan_req *) data;
  3940. struct sock *sk;
  3941. u16 psm, scid;
  3942. psm = le16_to_cpu(req->psm);
  3943. scid = le16_to_cpu(req->scid);
  3944. BT_DBG("psm %d, scid %d, amp_id %d", (int) psm, (int) scid,
  3945. (int) req->amp_id);
  3946. if (req->amp_id) {
  3947. struct hci_dev *hdev;
  3948. /* Validate AMP controller id */
  3949. hdev = hci_dev_get(req->amp_id);
  3950. if (!hdev || !test_bit(HCI_UP, &hdev->flags)) {
  3951. struct l2cap_create_chan_rsp rsp;
  3952. rsp.dcid = 0;
  3953. rsp.scid = cpu_to_le16(scid);
  3954. rsp.result = L2CAP_CREATE_CHAN_REFUSED_CONTROLLER;
  3955. rsp.status = L2CAP_CREATE_CHAN_STATUS_NONE;
  3956. l2cap_send_cmd(conn, cmd->ident, L2CAP_CREATE_CHAN_RSP,
  3957. sizeof(rsp), &rsp);
  3958. if (hdev)
  3959. hci_dev_put(hdev);
  3960. return 0;
  3961. }
  3962. hci_dev_put(hdev);
  3963. }
  3964. sk = l2cap_create_connect(conn, cmd, cmd_len, data, L2CAP_CREATE_CHAN_RSP,
  3965. req->amp_id);
  3966. if (sk)
  3967. l2cap_pi(sk)->conf_state |= L2CAP_CONF_LOCKSTEP;
  3968. if (sk && req->amp_id &&
  3969. (conn->info_state & L2CAP_INFO_FEAT_MASK_REQ_DONE))
  3970. amp_accept_physical(conn, req->amp_id, sk);
  3971. return 0;
  3972. }
  3973. static inline int l2cap_create_channel_rsp(struct l2cap_conn *conn,
  3974. struct l2cap_cmd_hdr *cmd, u16 cmd_len,
  3975. u8 *data)
  3976. {
  3977. BT_DBG("conn %p", conn);
  3978. return l2cap_connect_rsp(conn, cmd, cmd_len, data);
  3979. }
  3980. static inline int l2cap_move_channel_req(struct l2cap_conn *conn,
  3981. struct l2cap_cmd_hdr *cmd, u8 *data)
  3982. {
  3983. struct l2cap_move_chan_req *req = (struct l2cap_move_chan_req *) data;
  3984. struct sock *sk;
  3985. struct l2cap_pinfo *pi;
  3986. u16 icid = 0;
  3987. u16 result = L2CAP_MOVE_CHAN_REFUSED_NOT_ALLOWED;
  3988. icid = le16_to_cpu(req->icid);
  3989. BT_DBG("icid %d, dest_amp_id %d", (int) icid, (int) req->dest_amp_id);
  3990. read_lock(&conn->chan_list.lock);
  3991. sk = __l2cap_get_chan_by_dcid(&conn->chan_list, icid);
  3992. read_unlock(&conn->chan_list.lock);
  3993. if (!sk)
  3994. goto send_move_response;
  3995. lock_sock(sk);
  3996. pi = l2cap_pi(sk);
  3997. if (pi->scid < L2CAP_CID_DYN_START ||
  3998. (pi->mode != L2CAP_MODE_ERTM &&
  3999. pi->mode != L2CAP_MODE_STREAMING)) {
  4000. goto send_move_response;
  4001. }
  4002. if (pi->amp_id == req->dest_amp_id) {
  4003. result = L2CAP_MOVE_CHAN_REFUSED_SAME_ID;
  4004. goto send_move_response;
  4005. }
  4006. if (req->dest_amp_id) {
  4007. struct hci_dev *hdev;
  4008. hdev = hci_dev_get(req->dest_amp_id);
  4009. if (!hdev || !test_bit(HCI_UP, &hdev->flags)) {
  4010. if (hdev)
  4011. hci_dev_put(hdev);
  4012. result = L2CAP_MOVE_CHAN_REFUSED_CONTROLLER;
  4013. goto send_move_response;
  4014. }
  4015. hci_dev_put(hdev);
  4016. }
  4017. if (((pi->amp_move_state != L2CAP_AMP_STATE_STABLE &&
  4018. pi->amp_move_state != L2CAP_AMP_STATE_WAIT_PREPARE) ||
  4019. pi->amp_move_role != L2CAP_AMP_MOVE_NONE) &&
  4020. bacmp(conn->src, conn->dst) > 0) {
  4021. result = L2CAP_MOVE_CHAN_REFUSED_COLLISION;
  4022. goto send_move_response;
  4023. }
  4024. if (pi->amp_pref == BT_AMP_POLICY_REQUIRE_BR_EDR) {
  4025. result = L2CAP_MOVE_CHAN_REFUSED_NOT_ALLOWED;
  4026. goto send_move_response;
  4027. }
  4028. pi->amp_move_cmd_ident = cmd->ident;
  4029. pi->amp_move_role = L2CAP_AMP_MOVE_RESPONDER;
  4030. l2cap_amp_move_setup(sk);
  4031. pi->amp_move_id = req->dest_amp_id;
  4032. icid = pi->dcid;
  4033. if (req->dest_amp_id == 0) {
  4034. /* Moving to BR/EDR */
  4035. if (pi->conn_state & L2CAP_CONN_LOCAL_BUSY) {
  4036. pi->amp_move_state = L2CAP_AMP_STATE_WAIT_LOCAL_BUSY;
  4037. result = L2CAP_MOVE_CHAN_PENDING;
  4038. } else {
  4039. pi->amp_move_state = L2CAP_AMP_STATE_WAIT_MOVE_CONFIRM;
  4040. result = L2CAP_MOVE_CHAN_SUCCESS;
  4041. }
  4042. } else {
  4043. pi->amp_move_state = L2CAP_AMP_STATE_WAIT_PREPARE;
  4044. amp_accept_physical(pi->conn, req->dest_amp_id, sk);
  4045. result = L2CAP_MOVE_CHAN_PENDING;
  4046. }
  4047. send_move_response:
  4048. l2cap_send_move_chan_rsp(conn, cmd->ident, icid, result);
  4049. if (sk)
  4050. release_sock(sk);
  4051. return 0;
  4052. }
  4053. static inline int l2cap_move_channel_rsp(struct l2cap_conn *conn,
  4054. struct l2cap_cmd_hdr *cmd, u8 *data)
  4055. {
  4056. struct l2cap_move_chan_rsp *rsp = (struct l2cap_move_chan_rsp *) data;
  4057. struct sock *sk;
  4058. struct l2cap_pinfo *pi;
  4059. u16 icid, result;
  4060. icid = le16_to_cpu(rsp->icid);
  4061. result = le16_to_cpu(rsp->result);
  4062. BT_DBG("icid %d, result %d", (int) icid, (int) result);
  4063. switch (result) {
  4064. case L2CAP_MOVE_CHAN_SUCCESS:
  4065. case L2CAP_MOVE_CHAN_PENDING:
  4066. read_lock(&conn->chan_list.lock);
  4067. sk = __l2cap_get_chan_by_scid(&conn->chan_list, icid);
  4068. read_unlock(&conn->chan_list.lock);
  4069. if (!sk) {
  4070. l2cap_send_move_chan_cfm(conn, NULL, icid,
  4071. L2CAP_MOVE_CHAN_UNCONFIRMED);
  4072. break;
  4073. }
  4074. lock_sock(sk);
  4075. pi = l2cap_pi(sk);
  4076. l2cap_sock_clear_timer(sk);
  4077. if (result == L2CAP_MOVE_CHAN_PENDING)
  4078. l2cap_sock_set_timer(sk, L2CAP_MOVE_ERTX_TIMEOUT);
  4079. if (pi->amp_move_state ==
  4080. L2CAP_AMP_STATE_WAIT_LOGICAL_COMPLETE) {
  4081. /* Move confirm will be sent when logical link
  4082. * is complete.
  4083. */
  4084. pi->amp_move_state =
  4085. L2CAP_AMP_STATE_WAIT_LOGICAL_CONFIRM;
  4086. } else if (pi->amp_move_state ==
  4087. L2CAP_AMP_STATE_WAIT_MOVE_RSP_SUCCESS) {
  4088. if (result == L2CAP_MOVE_CHAN_PENDING) {
  4089. break;
  4090. } else if (pi->conn_state & L2CAP_CONN_LOCAL_BUSY) {
  4091. pi->amp_move_state =
  4092. L2CAP_AMP_STATE_WAIT_LOCAL_BUSY;
  4093. } else {
  4094. /* Logical link is up or moving to BR/EDR,
  4095. * proceed with move */
  4096. pi->amp_move_state =
  4097. L2CAP_AMP_STATE_WAIT_MOVE_CONFIRM_RSP;
  4098. l2cap_send_move_chan_cfm(conn, pi, pi->scid,
  4099. L2CAP_MOVE_CHAN_CONFIRMED);
  4100. l2cap_sock_set_timer(sk, L2CAP_MOVE_TIMEOUT);
  4101. }
  4102. } else if (pi->amp_move_state ==
  4103. L2CAP_AMP_STATE_WAIT_MOVE_RSP) {
  4104. struct l2cap_conf_ext_fs default_fs = {1, 1, 0xFFFF,
  4105. 0xFFFFFFFF, 0xFFFFFFFF, 0xFFFFFFFF};
  4106. struct hci_chan *chan;
  4107. /* Moving to AMP */
  4108. if (result == L2CAP_MOVE_CHAN_SUCCESS) {
  4109. /* Remote is ready, send confirm immediately
  4110. * after logical link is ready
  4111. */
  4112. pi->amp_move_state =
  4113. L2CAP_AMP_STATE_WAIT_LOGICAL_CONFIRM;
  4114. } else {
  4115. /* Both logical link and move success
  4116. * are required to confirm
  4117. */
  4118. pi->amp_move_state =
  4119. L2CAP_AMP_STATE_WAIT_LOGICAL_COMPLETE;
  4120. }
  4121. pi->remote_fs = default_fs;
  4122. pi->local_fs = default_fs;
  4123. chan = l2cap_chan_admit(pi->amp_move_id, sk);
  4124. if (!chan) {
  4125. /* Logical link not available */
  4126. l2cap_send_move_chan_cfm(conn, pi, pi->scid,
  4127. L2CAP_MOVE_CHAN_UNCONFIRMED);
  4128. break;
  4129. }
  4130. if (chan->state == BT_CONNECTED) {
  4131. /* Logical link is already ready to go */
  4132. pi->ampcon = chan->conn;
  4133. pi->ampcon->l2cap_data = pi->conn;
  4134. if (result == L2CAP_MOVE_CHAN_SUCCESS) {
  4135. /* Can confirm now */
  4136. l2cap_send_move_chan_cfm(conn, pi,
  4137. pi->scid,
  4138. L2CAP_MOVE_CHAN_CONFIRMED);
  4139. } else {
  4140. /* Now only need move success
  4141. * required to confirm
  4142. */
  4143. pi->amp_move_state =
  4144. L2CAP_AMP_STATE_WAIT_MOVE_RSP_SUCCESS;
  4145. }
  4146. l2cap_create_cfm(chan, 0);
  4147. }
  4148. } else {
  4149. /* Any other amp move state means the move failed. */
  4150. pi->amp_move_id = pi->amp_id;
  4151. pi->amp_move_state = L2CAP_AMP_STATE_STABLE;
  4152. l2cap_amp_move_revert(sk);
  4153. pi->amp_move_role = L2CAP_AMP_MOVE_NONE;
  4154. l2cap_send_move_chan_cfm(conn, pi, pi->scid,
  4155. L2CAP_MOVE_CHAN_UNCONFIRMED);
  4156. l2cap_sock_set_timer(sk, L2CAP_MOVE_TIMEOUT);
  4157. }
  4158. break;
  4159. default:
  4160. /* Failed (including collision case) */
  4161. read_lock(&conn->chan_list.lock);
  4162. sk = __l2cap_get_chan_by_ident(&conn->chan_list, cmd->ident);
  4163. read_unlock(&conn->chan_list.lock);
  4164. if (!sk) {
  4165. /* Could not locate channel, icid is best guess */
  4166. l2cap_send_move_chan_cfm(conn, NULL, icid,
  4167. L2CAP_MOVE_CHAN_UNCONFIRMED);
  4168. break;
  4169. }
  4170. lock_sock(sk);
  4171. pi = l2cap_pi(sk);
  4172. l2cap_sock_clear_timer(sk);
  4173. if (pi->amp_move_role == L2CAP_AMP_MOVE_INITIATOR) {
  4174. if (result == L2CAP_MOVE_CHAN_REFUSED_COLLISION)
  4175. pi->amp_move_role = L2CAP_AMP_MOVE_RESPONDER;
  4176. else {
  4177. /* Cleanup - cancel move */
  4178. pi->amp_move_id = pi->amp_id;
  4179. pi->amp_move_state = L2CAP_AMP_STATE_STABLE;
  4180. l2cap_amp_move_revert(sk);
  4181. pi->amp_move_role = L2CAP_AMP_MOVE_NONE;
  4182. }
  4183. }
  4184. l2cap_send_move_chan_cfm(conn, pi, pi->scid,
  4185. L2CAP_MOVE_CHAN_UNCONFIRMED);
  4186. l2cap_sock_set_timer(sk, L2CAP_MOVE_TIMEOUT);
  4187. break;
  4188. }
  4189. if (sk)
  4190. release_sock(sk);
  4191. return 0;
  4192. }
  4193. static inline int l2cap_move_channel_confirm(struct l2cap_conn *conn,
  4194. struct l2cap_cmd_hdr *cmd, u8 *data)
  4195. {
  4196. struct l2cap_move_chan_cfm *cfm = (struct l2cap_move_chan_cfm *) data;
  4197. struct sock *sk;
  4198. struct l2cap_pinfo *pi;
  4199. u16 icid, result;
  4200. icid = le16_to_cpu(cfm->icid);
  4201. result = le16_to_cpu(cfm->result);
  4202. BT_DBG("icid %d, result %d", (int) icid, (int) result);
  4203. read_lock(&conn->chan_list.lock);
  4204. sk = __l2cap_get_chan_by_dcid(&conn->chan_list, icid);
  4205. read_unlock(&conn->chan_list.lock);
  4206. if (!sk) {
  4207. BT_DBG("Bad channel (%d)", (int) icid);
  4208. goto send_move_confirm_response;
  4209. }
  4210. lock_sock(sk);
  4211. pi = l2cap_pi(sk);
  4212. if (pi->amp_move_state == L2CAP_AMP_STATE_WAIT_MOVE_CONFIRM) {
  4213. pi->amp_move_state = L2CAP_AMP_STATE_STABLE;
  4214. if (result == L2CAP_MOVE_CHAN_CONFIRMED) {
  4215. pi->amp_id = pi->amp_move_id;
  4216. if (!pi->amp_id && pi->ampchan) {
  4217. struct hci_chan *ampchan = pi->ampchan;
  4218. struct hci_conn *ampcon = pi->ampcon;
  4219. /* Have moved off of AMP, free the channel */
  4220. pi->ampchan = NULL;
  4221. pi->ampcon = NULL;
  4222. if (hci_chan_put(ampchan))
  4223. ampcon->l2cap_data = NULL;
  4224. else
  4225. l2cap_deaggregate(ampchan, pi);
  4226. }
  4227. l2cap_amp_move_success(sk);
  4228. } else {
  4229. pi->amp_move_id = pi->amp_id;
  4230. l2cap_amp_move_revert(sk);
  4231. }
  4232. pi->amp_move_role = L2CAP_AMP_MOVE_NONE;
  4233. } else if (pi->amp_move_state ==
  4234. L2CAP_AMP_STATE_WAIT_LOGICAL_CONFIRM) {
  4235. BT_DBG("Bad AMP_MOVE_STATE (%d)", pi->amp_move_state);
  4236. }
  4237. send_move_confirm_response:
  4238. l2cap_send_move_chan_cfm_rsp(conn, cmd->ident, icid);
  4239. if (sk)
  4240. release_sock(sk);
  4241. return 0;
  4242. }
  4243. static inline int l2cap_move_channel_confirm_rsp(struct l2cap_conn *conn,
  4244. struct l2cap_cmd_hdr *cmd, u8 *data)
  4245. {
  4246. struct l2cap_move_chan_cfm_rsp *rsp =
  4247. (struct l2cap_move_chan_cfm_rsp *) data;
  4248. struct sock *sk;
  4249. struct l2cap_pinfo *pi;
  4250. u16 icid;
  4251. icid = le16_to_cpu(rsp->icid);
  4252. BT_DBG("icid %d", (int) icid);
  4253. read_lock(&conn->chan_list.lock);
  4254. sk = __l2cap_get_chan_by_scid(&conn->chan_list, icid);
  4255. read_unlock(&conn->chan_list.lock);
  4256. if (!sk)
  4257. return 0;
  4258. lock_sock(sk);
  4259. pi = l2cap_pi(sk);
  4260. l2cap_sock_clear_timer(sk);
  4261. if (pi->amp_move_state ==
  4262. L2CAP_AMP_STATE_WAIT_MOVE_CONFIRM_RSP) {
  4263. pi->amp_move_state = L2CAP_AMP_STATE_STABLE;
  4264. pi->amp_id = pi->amp_move_id;
  4265. if (!pi->amp_id && pi->ampchan) {
  4266. struct hci_chan *ampchan = pi->ampchan;
  4267. struct hci_conn *ampcon = pi->ampcon;
  4268. /* Have moved off of AMP, free the channel */
  4269. pi->ampchan = NULL;
  4270. pi->ampcon = NULL;
  4271. if (hci_chan_put(ampchan))
  4272. ampcon->l2cap_data = NULL;
  4273. else
  4274. l2cap_deaggregate(ampchan, pi);
  4275. }
  4276. l2cap_amp_move_success(sk);
  4277. pi->amp_move_role = L2CAP_AMP_MOVE_NONE;
  4278. }
  4279. release_sock(sk);
  4280. return 0;
  4281. }
  4282. static void l2cap_amp_signal_worker(struct work_struct *work)
  4283. {
  4284. int err = 0;
  4285. struct l2cap_amp_signal_work *ampwork =
  4286. container_of(work, struct l2cap_amp_signal_work, work);
  4287. switch (ampwork->cmd.code) {
  4288. case L2CAP_MOVE_CHAN_REQ:
  4289. err = l2cap_move_channel_req(ampwork->conn, &ampwork->cmd,
  4290. ampwork->data);
  4291. break;
  4292. case L2CAP_MOVE_CHAN_RSP:
  4293. err = l2cap_move_channel_rsp(ampwork->conn, &ampwork->cmd,
  4294. ampwork->data);
  4295. break;
  4296. case L2CAP_MOVE_CHAN_CFM:
  4297. err = l2cap_move_channel_confirm(ampwork->conn, &ampwork->cmd,
  4298. ampwork->data);
  4299. break;
  4300. case L2CAP_MOVE_CHAN_CFM_RSP:
  4301. err = l2cap_move_channel_confirm_rsp(ampwork->conn,
  4302. &ampwork->cmd, ampwork->data);
  4303. break;
  4304. default:
  4305. BT_ERR("Unknown signaling command 0x%2.2x", ampwork->cmd.code);
  4306. err = -EINVAL;
  4307. break;
  4308. }
  4309. if (err) {
  4310. struct l2cap_cmd_rej rej;
  4311. BT_DBG("error %d", err);
  4312. /* In this context, commands are only rejected with
  4313. * "command not understood", code 0.
  4314. */
  4315. rej.reason = cpu_to_le16(0);
  4316. l2cap_send_cmd(ampwork->conn, ampwork->cmd.ident,
  4317. L2CAP_COMMAND_REJ, sizeof(rej), &rej);
  4318. }
  4319. kfree_skb(ampwork->skb);
  4320. kfree(ampwork);
  4321. }
  4322. void l2cap_amp_physical_complete(int result, u8 local_id, u8 remote_id,
  4323. struct sock *sk)
  4324. {
  4325. struct l2cap_pinfo *pi;
  4326. BT_DBG("result %d, local_id %d, remote_id %d, sk %p", result,
  4327. (int) local_id, (int) remote_id, sk);
  4328. lock_sock(sk);
  4329. if (sk->sk_state == BT_DISCONN || sk->sk_state == BT_CLOSED) {
  4330. release_sock(sk);
  4331. return;
  4332. }
  4333. pi = l2cap_pi(sk);
  4334. if (sk->sk_state != BT_CONNECTED) {
  4335. if (bt_sk(sk)->parent) {
  4336. struct l2cap_conn_rsp rsp;
  4337. char buf[128];
  4338. rsp.scid = cpu_to_le16(l2cap_pi(sk)->dcid);
  4339. rsp.dcid = cpu_to_le16(l2cap_pi(sk)->scid);
  4340. /* Incoming channel on AMP */
  4341. if (result == L2CAP_CREATE_CHAN_SUCCESS) {
  4342. /* Send successful response */
  4343. rsp.result = cpu_to_le16(L2CAP_CR_SUCCESS);
  4344. rsp.status = cpu_to_le16(L2CAP_CS_NO_INFO);
  4345. } else {
  4346. /* Send negative response */
  4347. rsp.result = cpu_to_le16(L2CAP_CR_NO_MEM);
  4348. rsp.status = cpu_to_le16(L2CAP_CS_NO_INFO);
  4349. }
  4350. l2cap_send_cmd(pi->conn, pi->ident,
  4351. L2CAP_CREATE_CHAN_RSP,
  4352. sizeof(rsp), &rsp);
  4353. if (result == L2CAP_CREATE_CHAN_SUCCESS) {
  4354. sk->sk_state = BT_CONFIG;
  4355. pi->conf_state |= L2CAP_CONF_REQ_SENT;
  4356. l2cap_send_cmd(pi->conn,
  4357. l2cap_get_ident(pi->conn),
  4358. L2CAP_CONF_REQ,
  4359. l2cap_build_conf_req(sk, buf, sizeof(buf)), buf);
  4360. l2cap_pi(sk)->num_conf_req++;
  4361. }
  4362. } else {
  4363. /* Outgoing channel on AMP */
  4364. if (result != L2CAP_CREATE_CHAN_SUCCESS) {
  4365. /* Revert to BR/EDR connect */
  4366. l2cap_send_conn_req(sk);
  4367. } else {
  4368. pi->amp_id = local_id;
  4369. l2cap_send_create_chan_req(sk, remote_id);
  4370. }
  4371. }
  4372. } else if (result == L2CAP_MOVE_CHAN_SUCCESS &&
  4373. pi->amp_move_role == L2CAP_AMP_MOVE_INITIATOR) {
  4374. l2cap_amp_move_setup(sk);
  4375. pi->amp_move_id = local_id;
  4376. pi->amp_move_state = L2CAP_AMP_STATE_WAIT_MOVE_RSP;
  4377. l2cap_send_move_chan_req(pi->conn, pi, pi->scid, remote_id);
  4378. l2cap_sock_set_timer(sk, L2CAP_MOVE_TIMEOUT);
  4379. } else if (result == L2CAP_MOVE_CHAN_SUCCESS &&
  4380. pi->amp_move_role == L2CAP_AMP_MOVE_RESPONDER) {
  4381. struct hci_chan *chan;
  4382. struct l2cap_conf_ext_fs default_fs = {1, 1, 0xFFFF,
  4383. 0xFFFFFFFF, 0xFFFFFFFF, 0xFFFFFFFF};
  4384. pi->remote_fs = default_fs;
  4385. pi->local_fs = default_fs;
  4386. chan = l2cap_chan_admit(local_id, sk);
  4387. if (chan) {
  4388. if (chan->state == BT_CONNECTED) {
  4389. /* Logical link is ready to go */
  4390. pi->ampcon = chan->conn;
  4391. pi->ampcon->l2cap_data = pi->conn;
  4392. pi->amp_move_state =
  4393. L2CAP_AMP_STATE_WAIT_MOVE_CONFIRM;
  4394. l2cap_send_move_chan_rsp(pi->conn,
  4395. pi->amp_move_cmd_ident, pi->dcid,
  4396. L2CAP_MOVE_CHAN_SUCCESS);
  4397. l2cap_create_cfm(chan, 0);
  4398. } else {
  4399. /* Wait for logical link to be ready */
  4400. pi->amp_move_state =
  4401. L2CAP_AMP_STATE_WAIT_LOGICAL_CONFIRM;
  4402. }
  4403. } else {
  4404. /* Logical link not available */
  4405. l2cap_send_move_chan_rsp(pi->conn,
  4406. pi->amp_move_cmd_ident, pi->dcid,
  4407. L2CAP_MOVE_CHAN_REFUSED_NOT_ALLOWED);
  4408. }
  4409. } else {
  4410. BT_DBG("result %d, role %d, local_busy %d", result,
  4411. (int) pi->amp_move_role,
  4412. (int) ((pi->conn_state & L2CAP_CONN_LOCAL_BUSY) != 0));
  4413. if (pi->amp_move_role == L2CAP_AMP_MOVE_RESPONDER) {
  4414. if (result == -EINVAL)
  4415. l2cap_send_move_chan_rsp(pi->conn,
  4416. pi->amp_move_cmd_ident, pi->dcid,
  4417. L2CAP_MOVE_CHAN_REFUSED_CONTROLLER);
  4418. else
  4419. l2cap_send_move_chan_rsp(pi->conn,
  4420. pi->amp_move_cmd_ident, pi->dcid,
  4421. L2CAP_MOVE_CHAN_REFUSED_NOT_ALLOWED);
  4422. }
  4423. pi->amp_move_role = L2CAP_AMP_MOVE_NONE;
  4424. pi->amp_move_state = L2CAP_AMP_STATE_STABLE;
  4425. if ((l2cap_pi(sk)->conn_state & L2CAP_CONN_LOCAL_BUSY) &&
  4426. l2cap_rmem_available(sk))
  4427. l2cap_ertm_tx(sk, 0, 0,
  4428. L2CAP_ERTM_EVENT_LOCAL_BUSY_CLEAR);
  4429. /* Restart data transmission */
  4430. l2cap_ertm_send(sk);
  4431. }
  4432. release_sock(sk);
  4433. }
  4434. static void l2cap_logical_link_complete(struct hci_chan *chan, u8 status)
  4435. {
  4436. struct l2cap_pinfo *pi;
  4437. struct sock *sk;
  4438. struct hci_chan *ampchan;
  4439. struct hci_conn *ampcon;
  4440. BT_DBG("status %d, chan %p, conn %p", (int) status, chan, chan->conn);
  4441. sk = chan->l2cap_sk;
  4442. chan->l2cap_sk = NULL;
  4443. BT_DBG("sk %p", sk);
  4444. lock_sock(sk);
  4445. if (sk->sk_state != BT_CONNECTED && !l2cap_pi(sk)->amp_id) {
  4446. release_sock(sk);
  4447. return;
  4448. }
  4449. pi = l2cap_pi(sk);
  4450. if ((!status) && (chan != NULL)) {
  4451. pi->ampcon = chan->conn;
  4452. pi->ampcon->l2cap_data = pi->conn;
  4453. BT_DBG("amp_move_state %d", pi->amp_move_state);
  4454. if (sk->sk_state != BT_CONNECTED) {
  4455. struct l2cap_conf_rsp rsp;
  4456. /* Must use spinlock to prevent concurrent
  4457. * execution of l2cap_config_rsp()
  4458. */
  4459. bh_lock_sock(sk);
  4460. l2cap_send_cmd(pi->conn, pi->conf_ident, L2CAP_CONF_RSP,
  4461. l2cap_build_conf_rsp(sk, &rsp,
  4462. L2CAP_CONF_SUCCESS, 0), &rsp);
  4463. pi->conf_state |= L2CAP_CONF_OUTPUT_DONE;
  4464. if (l2cap_pi(sk)->conf_state & L2CAP_CONF_INPUT_DONE) {
  4465. set_default_fcs(l2cap_pi(sk));
  4466. sk->sk_state = BT_CONNECTED;
  4467. if (l2cap_pi(sk)->mode == L2CAP_MODE_ERTM ||
  4468. l2cap_pi(sk)->mode == L2CAP_MODE_STREAMING)
  4469. l2cap_ertm_init(sk);
  4470. l2cap_chan_ready(sk);
  4471. }
  4472. bh_unlock_sock(sk);
  4473. } else if (pi->amp_move_state ==
  4474. L2CAP_AMP_STATE_WAIT_LOGICAL_COMPLETE) {
  4475. /* Move confirm will be sent after a success
  4476. * response is received
  4477. */
  4478. pi->amp_move_state =
  4479. L2CAP_AMP_STATE_WAIT_MOVE_RSP_SUCCESS;
  4480. } else if (pi->amp_move_state ==
  4481. L2CAP_AMP_STATE_WAIT_LOGICAL_CONFIRM) {
  4482. if (pi->conn_state & L2CAP_CONN_LOCAL_BUSY)
  4483. pi->amp_move_state =
  4484. L2CAP_AMP_STATE_WAIT_LOCAL_BUSY;
  4485. else if (pi->amp_move_role ==
  4486. L2CAP_AMP_MOVE_INITIATOR) {
  4487. pi->amp_move_state =
  4488. L2CAP_AMP_STATE_WAIT_MOVE_CONFIRM_RSP;
  4489. l2cap_send_move_chan_cfm(pi->conn, pi, pi->scid,
  4490. L2CAP_MOVE_CHAN_SUCCESS);
  4491. l2cap_sock_set_timer(sk, L2CAP_MOVE_TIMEOUT);
  4492. } else if (pi->amp_move_role ==
  4493. L2CAP_AMP_MOVE_RESPONDER) {
  4494. pi->amp_move_state =
  4495. L2CAP_AMP_STATE_WAIT_MOVE_CONFIRM;
  4496. l2cap_send_move_chan_rsp(pi->conn,
  4497. pi->amp_move_cmd_ident, pi->dcid,
  4498. L2CAP_MOVE_CHAN_SUCCESS);
  4499. }
  4500. } else if ((pi->amp_move_state !=
  4501. L2CAP_AMP_STATE_WAIT_MOVE_RSP_SUCCESS) &&
  4502. (pi->amp_move_state !=
  4503. L2CAP_AMP_STATE_WAIT_MOVE_CONFIRM) &&
  4504. (pi->amp_move_state !=
  4505. L2CAP_AMP_STATE_WAIT_MOVE_CONFIRM_RSP)) {
  4506. /* Move was not in expected state, free the channel */
  4507. ampchan = pi->ampchan;
  4508. ampcon = pi->ampcon;
  4509. pi->ampchan = NULL;
  4510. pi->ampcon = NULL;
  4511. if (ampchan) {
  4512. if (hci_chan_put(ampchan))
  4513. ampcon->l2cap_data = NULL;
  4514. else
  4515. l2cap_deaggregate(ampchan, pi);
  4516. }
  4517. pi->amp_move_state = L2CAP_AMP_STATE_STABLE;
  4518. }
  4519. } else {
  4520. /* Logical link setup failed. */
  4521. if (sk->sk_state != BT_CONNECTED)
  4522. l2cap_send_disconn_req(pi->conn, sk, ECONNRESET);
  4523. else if (pi->amp_move_role == L2CAP_AMP_MOVE_RESPONDER) {
  4524. l2cap_amp_move_revert(sk);
  4525. l2cap_pi(sk)->amp_move_role = L2CAP_AMP_MOVE_NONE;
  4526. pi->amp_move_state = L2CAP_AMP_STATE_STABLE;
  4527. l2cap_send_move_chan_rsp(pi->conn,
  4528. pi->amp_move_cmd_ident, pi->dcid,
  4529. L2CAP_MOVE_CHAN_REFUSED_CONFIG);
  4530. } else if (pi->amp_move_role == L2CAP_AMP_MOVE_INITIATOR) {
  4531. if ((pi->amp_move_state ==
  4532. L2CAP_AMP_STATE_WAIT_LOGICAL_COMPLETE) ||
  4533. (pi->amp_move_state ==
  4534. L2CAP_AMP_STATE_WAIT_LOGICAL_CONFIRM)) {
  4535. /* Remote has only sent pending or
  4536. * success responses, clean up
  4537. */
  4538. l2cap_amp_move_revert(sk);
  4539. l2cap_pi(sk)->amp_move_role =
  4540. L2CAP_AMP_MOVE_NONE;
  4541. pi->amp_move_state = L2CAP_AMP_STATE_STABLE;
  4542. }
  4543. /* Other amp move states imply that the move
  4544. * has already aborted
  4545. */
  4546. l2cap_send_move_chan_cfm(pi->conn, pi, pi->scid,
  4547. L2CAP_MOVE_CHAN_UNCONFIRMED);
  4548. l2cap_sock_set_timer(sk, L2CAP_MOVE_TIMEOUT);
  4549. }
  4550. ampchan = pi->ampchan;
  4551. ampcon = pi->ampcon;
  4552. pi->ampchan = NULL;
  4553. pi->ampcon = NULL;
  4554. if (ampchan) {
  4555. if (hci_chan_put(ampchan))
  4556. ampcon->l2cap_data = NULL;
  4557. else
  4558. l2cap_deaggregate(ampchan, pi);
  4559. }
  4560. }
  4561. release_sock(sk);
  4562. }
  4563. static void l2cap_logical_link_worker(struct work_struct *work)
  4564. {
  4565. struct l2cap_logical_link_work *log_link_work =
  4566. container_of(work, struct l2cap_logical_link_work, work);
  4567. struct sock *sk = log_link_work->chan->l2cap_sk;
  4568. if (sk) {
  4569. l2cap_logical_link_complete(log_link_work->chan,
  4570. log_link_work->status);
  4571. sock_put(sk);
  4572. }
  4573. hci_chan_put(log_link_work->chan);
  4574. kfree(log_link_work);
  4575. }
  4576. static int l2cap_create_cfm(struct hci_chan *chan, u8 status)
  4577. {
  4578. struct l2cap_logical_link_work *amp_work;
  4579. if (!chan->l2cap_sk) {
  4580. BT_ERR("Expected l2cap_sk to point to connecting socket");
  4581. return -EFAULT;
  4582. }
  4583. amp_work = kzalloc(sizeof(*amp_work), GFP_ATOMIC);
  4584. if (!amp_work) {
  4585. sock_put(chan->l2cap_sk);
  4586. return -ENOMEM;
  4587. }
  4588. INIT_WORK(&amp_work->work, l2cap_logical_link_worker);
  4589. amp_work->chan = chan;
  4590. amp_work->status = status;
  4591. hci_chan_hold(chan);
  4592. if (!queue_work(_l2cap_wq, &amp_work->work)) {
  4593. kfree(amp_work);
  4594. sock_put(chan->l2cap_sk);
  4595. hci_chan_put(chan);
  4596. return -ENOMEM;
  4597. }
  4598. return 0;
  4599. }
  4600. int l2cap_modify_cfm(struct hci_chan *chan, u8 status)
  4601. {
  4602. struct l2cap_conn *conn = chan->conn->l2cap_data;
  4603. BT_DBG("chan %p conn %p status %d", chan, conn, status);
  4604. /* TODO: if failed status restore previous fs */
  4605. return 0;
  4606. }
  4607. int l2cap_destroy_cfm(struct hci_chan *chan, u8 reason)
  4608. {
  4609. struct l2cap_chan_list *l;
  4610. struct l2cap_conn *conn = chan->conn->l2cap_data;
  4611. struct sock *sk;
  4612. BT_DBG("chan %p conn %p", chan, conn);
  4613. if (!conn)
  4614. return 0;
  4615. l = &conn->chan_list;
  4616. read_lock(&l->lock);
  4617. for (sk = l->head; sk; sk = l2cap_pi(sk)->next_c) {
  4618. bh_lock_sock(sk);
  4619. /* TODO MM/PK - What to do if connection is LOCAL_BUSY? */
  4620. if (l2cap_pi(sk)->ampchan == chan) {
  4621. struct hci_conn *ampcon = l2cap_pi(sk)->ampcon;
  4622. l2cap_pi(sk)->ampchan = NULL;
  4623. l2cap_pi(sk)->ampcon = NULL;
  4624. if (hci_chan_put(chan))
  4625. ampcon->l2cap_data = NULL;
  4626. else
  4627. l2cap_deaggregate(chan, l2cap_pi(sk));
  4628. l2cap_amp_move_init(sk);
  4629. }
  4630. bh_unlock_sock(sk);
  4631. }
  4632. read_unlock(&l->lock);
  4633. return 0;
  4634. }
  4635. static int l2cap_sig_amp(struct l2cap_conn *conn, struct l2cap_cmd_hdr *cmd,
  4636. u8 *data, struct sk_buff *skb)
  4637. {
  4638. struct l2cap_amp_signal_work *amp_work;
  4639. amp_work = kzalloc(sizeof(*amp_work), GFP_ATOMIC);
  4640. if (!amp_work)
  4641. return -ENOMEM;
  4642. INIT_WORK(&amp_work->work, l2cap_amp_signal_worker);
  4643. amp_work->conn = conn;
  4644. amp_work->cmd = *cmd;
  4645. amp_work->data = data;
  4646. amp_work->skb = skb_clone(skb, GFP_ATOMIC);
  4647. if (!amp_work->skb) {
  4648. kfree(amp_work);
  4649. return -ENOMEM;
  4650. }
  4651. if (!queue_work(_l2cap_wq, &amp_work->work)) {
  4652. kfree_skb(amp_work->skb);
  4653. kfree(amp_work);
  4654. return -ENOMEM;
  4655. }
  4656. return 0;
  4657. }
  4658. static inline int l2cap_check_conn_param(u16 min, u16 max, u16 latency,
  4659. u16 to_multiplier)
  4660. {
  4661. u16 max_latency;
  4662. if (min > max || min < 6 || max > 3200)
  4663. return -EINVAL;
  4664. if (to_multiplier < 10 || to_multiplier > 3200)
  4665. return -EINVAL;
  4666. if (max >= to_multiplier * 8)
  4667. return -EINVAL;
  4668. max_latency = (to_multiplier * 8 / max) - 1;
  4669. if (latency > 499 || latency > max_latency)
  4670. return -EINVAL;
  4671. return 0;
  4672. }
  4673. static inline int l2cap_conn_param_update_req(struct l2cap_conn *conn,
  4674. struct l2cap_cmd_hdr *cmd, u8 *data)
  4675. {
  4676. struct hci_conn *hcon = conn->hcon;
  4677. struct l2cap_conn_param_update_req *req;
  4678. struct l2cap_conn_param_update_rsp rsp;
  4679. struct sock *sk;
  4680. u16 min, max, latency, timeout, cmd_len;
  4681. int err;
  4682. if (!(hcon->link_mode & HCI_LM_MASTER))
  4683. return -EINVAL;
  4684. cmd_len = __le16_to_cpu(cmd->len);
  4685. if (cmd_len != sizeof(struct l2cap_conn_param_update_req))
  4686. return -EPROTO;
  4687. memset(&rsp, 0, sizeof(rsp));
  4688. rsp.result = cpu_to_le16(L2CAP_CONN_PARAM_REJECTED);
  4689. sk = l2cap_find_sock_by_fixed_cid_and_dir(4, conn->src, conn->dst, 0);
  4690. if (sk && !bt_sk(sk)->le_params.prohibit_remote_chg) {
  4691. req = (struct l2cap_conn_param_update_req *) data;
  4692. min = __le16_to_cpu(req->min);
  4693. max = __le16_to_cpu(req->max);
  4694. latency = __le16_to_cpu(req->latency);
  4695. timeout = __le16_to_cpu(req->to_multiplier);
  4696. err = l2cap_check_conn_param(min, max, latency, timeout);
  4697. if (!err) {
  4698. rsp.result = cpu_to_le16(L2CAP_CONN_PARAM_ACCEPTED);
  4699. hci_le_conn_update(hcon, min, max, latency, timeout);
  4700. bt_sk(sk)->le_params.interval_min = min;
  4701. bt_sk(sk)->le_params.interval_max = max;
  4702. bt_sk(sk)->le_params.latency = latency;
  4703. bt_sk(sk)->le_params.supervision_timeout = timeout;
  4704. }
  4705. }
  4706. l2cap_send_cmd(conn, cmd->ident, L2CAP_CONN_PARAM_UPDATE_RSP,
  4707. sizeof(rsp), &rsp);
  4708. return 0;
  4709. }
  4710. static inline int l2cap_bredr_sig_cmd(struct l2cap_conn *conn,
  4711. struct l2cap_cmd_hdr *cmd, u16 cmd_len, u8 *data,
  4712. struct sk_buff *skb)
  4713. {
  4714. int err = 0;
  4715. switch (cmd->code) {
  4716. case L2CAP_COMMAND_REJ:
  4717. l2cap_command_rej(conn, cmd, cmd_len, data);
  4718. break;
  4719. case L2CAP_CONN_REQ:
  4720. err = l2cap_connect_req(conn, cmd, cmd_len, data);
  4721. break;
  4722. case L2CAP_CONN_RSP:
  4723. err = l2cap_connect_rsp(conn, cmd, cmd_len, data);
  4724. break;
  4725. case L2CAP_CONF_REQ:
  4726. err = l2cap_config_req(conn, cmd, cmd_len, data);
  4727. break;
  4728. case L2CAP_CONF_RSP:
  4729. err = l2cap_config_rsp(conn, cmd, cmd_len, data);
  4730. break;
  4731. case L2CAP_DISCONN_REQ:
  4732. err = l2cap_disconnect_req(conn, cmd, cmd_len, data);
  4733. break;
  4734. case L2CAP_DISCONN_RSP:
  4735. err = l2cap_disconnect_rsp(conn, cmd, cmd_len, data);
  4736. break;
  4737. case L2CAP_ECHO_REQ:
  4738. l2cap_send_cmd(conn, cmd->ident, L2CAP_ECHO_RSP, cmd_len, data);
  4739. break;
  4740. case L2CAP_ECHO_RSP:
  4741. break;
  4742. case L2CAP_INFO_REQ:
  4743. err = l2cap_information_req(conn, cmd, cmd_len, data);
  4744. break;
  4745. case L2CAP_INFO_RSP:
  4746. err = l2cap_information_rsp(conn, cmd, cmd_len, data);
  4747. break;
  4748. case L2CAP_CREATE_CHAN_REQ:
  4749. err = l2cap_create_channel_req(conn, cmd, cmd_len, data);
  4750. break;
  4751. case L2CAP_CREATE_CHAN_RSP:
  4752. err = l2cap_create_channel_rsp(conn, cmd, cmd_len, data);
  4753. break;
  4754. case L2CAP_MOVE_CHAN_REQ:
  4755. case L2CAP_MOVE_CHAN_RSP:
  4756. case L2CAP_MOVE_CHAN_CFM:
  4757. case L2CAP_MOVE_CHAN_CFM_RSP:
  4758. err = l2cap_sig_amp(conn, cmd, data, skb);
  4759. break;
  4760. default:
  4761. BT_ERR("Unknown BR/EDR signaling command 0x%2.2x", cmd->code);
  4762. err = -EINVAL;
  4763. break;
  4764. }
  4765. return err;
  4766. }
  4767. static inline int l2cap_le_sig_cmd(struct l2cap_conn *conn,
  4768. struct l2cap_cmd_hdr *cmd, u8 *data)
  4769. {
  4770. switch (cmd->code) {
  4771. case L2CAP_COMMAND_REJ:
  4772. return 0;
  4773. case L2CAP_CONN_PARAM_UPDATE_REQ:
  4774. return l2cap_conn_param_update_req(conn, cmd, data);
  4775. case L2CAP_CONN_PARAM_UPDATE_RSP:
  4776. return 0;
  4777. default:
  4778. BT_ERR("Unknown LE signaling command 0x%2.2x", cmd->code);
  4779. return -EINVAL;
  4780. }
  4781. }
  4782. static inline void l2cap_sig_channel(struct l2cap_conn *conn,
  4783. struct sk_buff *skb)
  4784. {
  4785. u8 *data = skb->data;
  4786. int len = skb->len;
  4787. struct l2cap_cmd_hdr cmd;
  4788. int err;
  4789. l2cap_raw_recv(conn, skb);
  4790. while (len >= L2CAP_CMD_HDR_SIZE) {
  4791. u16 cmd_len;
  4792. memcpy(&cmd, data, L2CAP_CMD_HDR_SIZE);
  4793. data += L2CAP_CMD_HDR_SIZE;
  4794. len -= L2CAP_CMD_HDR_SIZE;
  4795. cmd_len = le16_to_cpu(cmd.len);
  4796. BT_DBG("code 0x%2.2x len %d id 0x%2.2x", cmd.code, cmd_len, cmd.ident);
  4797. if (cmd_len > len || !cmd.ident) {
  4798. BT_DBG("corrupted command");
  4799. break;
  4800. }
  4801. if (conn->hcon->type == LE_LINK)
  4802. err = l2cap_le_sig_cmd(conn, &cmd, data);
  4803. else
  4804. err = l2cap_bredr_sig_cmd(conn, &cmd, cmd_len,
  4805. data, skb);
  4806. if (err) {
  4807. struct l2cap_cmd_rej rej;
  4808. BT_ERR("Wrong link type (%d)", err);
  4809. /* FIXME: Map err to a valid reason */
  4810. rej.reason = cpu_to_le16(0);
  4811. l2cap_send_cmd(conn, cmd.ident, L2CAP_COMMAND_REJ, sizeof(rej), &rej);
  4812. }
  4813. data += cmd_len;
  4814. len -= cmd_len;
  4815. }
  4816. kfree_skb(skb);
  4817. }
  4818. static int l2cap_check_fcs(struct l2cap_pinfo *pi, struct sk_buff *skb)
  4819. {
  4820. u16 our_fcs, rcv_fcs;
  4821. int hdr_size;
  4822. if (pi->extended_control)
  4823. hdr_size = L2CAP_EXTENDED_HDR_SIZE;
  4824. else
  4825. hdr_size = L2CAP_ENHANCED_HDR_SIZE;
  4826. if (pi->fcs == L2CAP_FCS_CRC16) {
  4827. skb_trim(skb, skb->len - L2CAP_FCS_SIZE);
  4828. rcv_fcs = get_unaligned_le16(skb->data + skb->len);
  4829. our_fcs = crc16(0, skb->data - hdr_size, skb->len + hdr_size);
  4830. if (our_fcs != rcv_fcs) {
  4831. BT_DBG("Bad FCS");
  4832. return -EBADMSG;
  4833. }
  4834. }
  4835. return 0;
  4836. }
  4837. static void l2cap_ertm_pass_to_tx(struct sock *sk,
  4838. struct bt_l2cap_control *control)
  4839. {
  4840. BT_DBG("sk %p, control %p", sk, control);
  4841. l2cap_ertm_tx(sk, control, 0, L2CAP_ERTM_EVENT_RECV_REQSEQ_AND_FBIT);
  4842. }
  4843. static void l2cap_ertm_pass_to_tx_fbit(struct sock *sk,
  4844. struct bt_l2cap_control *control)
  4845. {
  4846. BT_DBG("sk %p, control %p", sk, control);
  4847. l2cap_ertm_tx(sk, control, 0, L2CAP_ERTM_EVENT_RECV_FBIT);
  4848. }
  4849. static void l2cap_ertm_resend(struct sock *sk)
  4850. {
  4851. struct bt_l2cap_control control;
  4852. struct l2cap_pinfo *pi;
  4853. struct sk_buff *skb;
  4854. struct sk_buff *tx_skb;
  4855. u16 seq;
  4856. BT_DBG("sk %p", sk);
  4857. pi = l2cap_pi(sk);
  4858. if (pi->conn_state & L2CAP_CONN_REMOTE_BUSY)
  4859. return;
  4860. if (pi->amp_move_state != L2CAP_AMP_STATE_STABLE &&
  4861. pi->amp_move_state != L2CAP_AMP_STATE_WAIT_PREPARE)
  4862. return;
  4863. while (pi->retrans_list.head != L2CAP_SEQ_LIST_CLEAR) {
  4864. seq = l2cap_seq_list_pop(&pi->retrans_list);
  4865. skb = l2cap_ertm_seq_in_queue(TX_QUEUE(sk), seq);
  4866. if (!skb) {
  4867. BT_DBG("Error: Can't retransmit seq %d, frame missing",
  4868. (int) seq);
  4869. continue;
  4870. }
  4871. bt_cb(skb)->retries += 1;
  4872. control = bt_cb(skb)->control;
  4873. if ((pi->max_tx != 0) && (bt_cb(skb)->retries > pi->max_tx)) {
  4874. BT_DBG("Retry limit exceeded (%d)", (int) pi->max_tx);
  4875. l2cap_send_disconn_req(pi->conn, sk, ECONNRESET);
  4876. l2cap_seq_list_clear(&pi->retrans_list);
  4877. break;
  4878. }
  4879. control.reqseq = pi->buffer_seq;
  4880. if (pi->conn_state & L2CAP_CONN_SEND_FBIT) {
  4881. control.final = 1;
  4882. pi->conn_state &= ~L2CAP_CONN_SEND_FBIT;
  4883. } else {
  4884. control.final = 0;
  4885. }
  4886. if (skb_cloned(skb)) {
  4887. /* Cloned sk_buffs are read-only, so we need a
  4888. * writeable copy
  4889. */
  4890. tx_skb = skb_copy(skb, GFP_ATOMIC);
  4891. } else {
  4892. tx_skb = skb_clone(skb, GFP_ATOMIC);
  4893. }
  4894. if (!tx_skb) {
  4895. l2cap_seq_list_clear(&pi->retrans_list);
  4896. break;
  4897. }
  4898. /* Update skb contents */
  4899. if (pi->extended_control) {
  4900. put_unaligned_le32(__pack_extended_control(&control),
  4901. tx_skb->data + L2CAP_HDR_SIZE);
  4902. } else {
  4903. put_unaligned_le16(__pack_enhanced_control(&control),
  4904. tx_skb->data + L2CAP_HDR_SIZE);
  4905. }
  4906. if (pi->fcs == L2CAP_FCS_CRC16)
  4907. apply_fcs(tx_skb);
  4908. sock_hold(sk);
  4909. tx_skb->sk = sk;
  4910. tx_skb->destructor = l2cap_skb_destructor;
  4911. atomic_inc(&pi->ertm_queued);
  4912. l2cap_do_send(sk, tx_skb);
  4913. BT_DBG("Resent txseq %d", (int)control.txseq);
  4914. pi->last_acked_seq = pi->buffer_seq;
  4915. }
  4916. }
  4917. static inline void l2cap_ertm_retransmit(struct sock *sk,
  4918. struct bt_l2cap_control *control)
  4919. {
  4920. BT_DBG("sk %p, control %p", sk, control);
  4921. l2cap_seq_list_append(&l2cap_pi(sk)->retrans_list, control->reqseq);
  4922. l2cap_ertm_resend(sk);
  4923. }
  4924. static void l2cap_ertm_retransmit_all(struct sock *sk,
  4925. struct bt_l2cap_control *control)
  4926. {
  4927. struct l2cap_pinfo *pi;
  4928. struct sk_buff *skb;
  4929. BT_DBG("sk %p, control %p", sk, control);
  4930. pi = l2cap_pi(sk);
  4931. if (control->poll)
  4932. pi->conn_state |= L2CAP_CONN_SEND_FBIT;
  4933. l2cap_seq_list_clear(&pi->retrans_list);
  4934. if (pi->conn_state & L2CAP_CONN_REMOTE_BUSY)
  4935. return;
  4936. if (pi->unacked_frames) {
  4937. skb_queue_walk(TX_QUEUE(sk), skb) {
  4938. if ((bt_cb(skb)->control.txseq == control->reqseq) ||
  4939. skb == sk->sk_send_head)
  4940. break;
  4941. }
  4942. skb_queue_walk_from(TX_QUEUE(sk), skb) {
  4943. if (skb == sk->sk_send_head)
  4944. break;
  4945. l2cap_seq_list_append(&pi->retrans_list,
  4946. bt_cb(skb)->control.txseq);
  4947. }
  4948. l2cap_ertm_resend(sk);
  4949. }
  4950. }
  4951. static inline void append_skb_frag(struct sk_buff *skb,
  4952. struct sk_buff *new_frag, struct sk_buff **last_frag)
  4953. {
  4954. /* skb->len reflects data in skb as well as all fragments
  4955. skb->data_len reflects only data in fragments
  4956. */
  4957. BT_DBG("skb %p, new_frag %p, *last_frag %p", skb, new_frag, *last_frag);
  4958. if (!skb_has_frag_list(skb))
  4959. skb_shinfo(skb)->frag_list = new_frag;
  4960. new_frag->next = NULL;
  4961. (*last_frag)->next = new_frag;
  4962. *last_frag = new_frag;
  4963. skb->len += new_frag->len;
  4964. skb->data_len += new_frag->len;
  4965. skb->truesize += new_frag->truesize;
  4966. }
  4967. static int l2cap_ertm_rx_expected_iframe(struct sock *sk,
  4968. struct bt_l2cap_control *control, struct sk_buff *skb)
  4969. {
  4970. struct l2cap_pinfo *pi;
  4971. int err = -EINVAL;
  4972. BT_DBG("sk %p, control %p, skb %p len %d truesize %d", sk, control,
  4973. skb, skb->len, skb->truesize);
  4974. if (!control)
  4975. return err;
  4976. pi = l2cap_pi(sk);
  4977. BT_DBG("type %c, sar %d, txseq %d, reqseq %d, final %d",
  4978. control->frame_type, control->sar, control->txseq,
  4979. control->reqseq, control->final);
  4980. switch (control->sar) {
  4981. case L2CAP_SAR_UNSEGMENTED:
  4982. if (pi->sdu) {
  4983. BT_DBG("Unexpected unsegmented PDU during reassembly");
  4984. kfree_skb(pi->sdu);
  4985. pi->sdu = NULL;
  4986. pi->sdu_last_frag = NULL;
  4987. pi->sdu_len = 0;
  4988. }
  4989. BT_DBG("Unsegmented");
  4990. err = sock_queue_rcv_skb(sk, skb);
  4991. break;
  4992. case L2CAP_SAR_START:
  4993. if (pi->sdu) {
  4994. BT_DBG("Unexpected start PDU during reassembly");
  4995. kfree_skb(pi->sdu);
  4996. }
  4997. pi->sdu_len = get_unaligned_le16(skb->data);
  4998. skb_pull(skb, 2);
  4999. if (pi->sdu_len > pi->imtu) {
  5000. err = -EMSGSIZE;
  5001. break;
  5002. }
  5003. if (skb->len >= pi->sdu_len)
  5004. break;
  5005. pi->sdu = skb;
  5006. pi->sdu_last_frag = skb;
  5007. BT_DBG("Start");
  5008. skb = NULL;
  5009. err = 0;
  5010. break;
  5011. case L2CAP_SAR_CONTINUE:
  5012. if (!pi->sdu)
  5013. break;
  5014. append_skb_frag(pi->sdu, skb,
  5015. &pi->sdu_last_frag);
  5016. skb = NULL;
  5017. if (pi->sdu->len >= pi->sdu_len)
  5018. break;
  5019. BT_DBG("Continue, reassembled %d", pi->sdu->len);
  5020. err = 0;
  5021. break;
  5022. case L2CAP_SAR_END:
  5023. if (!pi->sdu)
  5024. break;
  5025. append_skb_frag(pi->sdu, skb,
  5026. &pi->sdu_last_frag);
  5027. skb = NULL;
  5028. if (pi->sdu->len != pi->sdu_len)
  5029. break;
  5030. BT_DBG("End, reassembled %d", pi->sdu->len);
  5031. /* If the sender used tiny PDUs, the rcv queuing could fail.
  5032. * Applications that have issues here should use a larger
  5033. * sk_rcvbuf.
  5034. */
  5035. err = sock_queue_rcv_skb(sk, pi->sdu);
  5036. if (!err) {
  5037. /* Reassembly complete */
  5038. pi->sdu = NULL;
  5039. pi->sdu_last_frag = NULL;
  5040. pi->sdu_len = 0;
  5041. }
  5042. break;
  5043. default:
  5044. BT_DBG("Bad SAR value");
  5045. break;
  5046. }
  5047. if (err) {
  5048. BT_DBG("Reassembly error %d, sk_rcvbuf %d, sk_rmem_alloc %d",
  5049. err, sk->sk_rcvbuf, atomic_read(&sk->sk_rmem_alloc));
  5050. if (pi->sdu) {
  5051. kfree_skb(pi->sdu);
  5052. pi->sdu = NULL;
  5053. }
  5054. pi->sdu_last_frag = NULL;
  5055. pi->sdu_len = 0;
  5056. if (skb)
  5057. kfree_skb(skb);
  5058. }
  5059. /* Update local busy state */
  5060. if (!(pi->conn_state & L2CAP_CONN_LOCAL_BUSY) && l2cap_rmem_full(sk))
  5061. l2cap_ertm_tx(sk, 0, 0, L2CAP_ERTM_EVENT_LOCAL_BUSY_DETECTED);
  5062. return err;
  5063. }
  5064. static int l2cap_ertm_rx_queued_iframes(struct sock *sk)
  5065. {
  5066. int err = 0;
  5067. /* Pass sequential frames to l2cap_ertm_rx_expected_iframe()
  5068. * until a gap is encountered.
  5069. */
  5070. struct l2cap_pinfo *pi;
  5071. BT_DBG("sk %p", sk);
  5072. pi = l2cap_pi(sk);
  5073. while (l2cap_rmem_available(sk)) {
  5074. struct sk_buff *skb;
  5075. BT_DBG("Searching for skb with txseq %d (queue len %d)",
  5076. (int) pi->buffer_seq, skb_queue_len(SREJ_QUEUE(sk)));
  5077. skb = l2cap_ertm_seq_in_queue(SREJ_QUEUE(sk), pi->buffer_seq);
  5078. if (!skb)
  5079. break;
  5080. skb_unlink(skb, SREJ_QUEUE(sk));
  5081. pi->buffer_seq = __next_seq(pi->buffer_seq, pi);
  5082. err = l2cap_ertm_rx_expected_iframe(sk,
  5083. &bt_cb(skb)->control, skb);
  5084. if (err)
  5085. break;
  5086. }
  5087. if (skb_queue_empty(SREJ_QUEUE(sk))) {
  5088. pi->rx_state = L2CAP_ERTM_RX_STATE_RECV;
  5089. l2cap_ertm_send_ack(sk);
  5090. }
  5091. return err;
  5092. }
  5093. static void l2cap_ertm_handle_srej(struct sock *sk,
  5094. struct bt_l2cap_control *control)
  5095. {
  5096. struct l2cap_pinfo *pi;
  5097. struct sk_buff *skb;
  5098. BT_DBG("sk %p, control %p", sk, control);
  5099. pi = l2cap_pi(sk);
  5100. if (control->reqseq == pi->next_tx_seq) {
  5101. BT_DBG("Invalid reqseq %d, disconnecting",
  5102. (int) control->reqseq);
  5103. l2cap_send_disconn_req(pi->conn, sk, ECONNRESET);
  5104. return;
  5105. }
  5106. skb = l2cap_ertm_seq_in_queue(TX_QUEUE(sk), control->reqseq);
  5107. if (skb == NULL) {
  5108. BT_DBG("Seq %d not available for retransmission",
  5109. (int) control->reqseq);
  5110. return;
  5111. }
  5112. if ((pi->max_tx != 0) && (bt_cb(skb)->retries >= pi->max_tx)) {
  5113. BT_DBG("Retry limit exceeded (%d)", (int) pi->max_tx);
  5114. l2cap_send_disconn_req(pi->conn, sk, ECONNRESET);
  5115. return;
  5116. }
  5117. pi->conn_state &= ~L2CAP_CONN_REMOTE_BUSY;
  5118. if (control->poll) {
  5119. l2cap_ertm_pass_to_tx(sk, control);
  5120. pi->conn_state |= L2CAP_CONN_SEND_FBIT;
  5121. l2cap_ertm_retransmit(sk, control);
  5122. l2cap_ertm_send(sk);
  5123. if (pi->tx_state == L2CAP_ERTM_TX_STATE_WAIT_F) {
  5124. pi->conn_state |= L2CAP_CONN_SREJ_ACT;
  5125. pi->srej_save_reqseq = control->reqseq;
  5126. }
  5127. } else {
  5128. l2cap_ertm_pass_to_tx_fbit(sk, control);
  5129. if (control->final) {
  5130. if ((pi->conn_state & L2CAP_CONN_SREJ_ACT) &&
  5131. (pi->srej_save_reqseq == control->reqseq)) {
  5132. pi->conn_state &= ~L2CAP_CONN_SREJ_ACT;
  5133. } else {
  5134. l2cap_ertm_retransmit(sk, control);
  5135. }
  5136. } else {
  5137. l2cap_ertm_retransmit(sk, control);
  5138. if (pi->tx_state == L2CAP_ERTM_TX_STATE_WAIT_F) {
  5139. pi->conn_state |= L2CAP_CONN_SREJ_ACT;
  5140. pi->srej_save_reqseq = control->reqseq;
  5141. }
  5142. }
  5143. }
  5144. }
  5145. static void l2cap_ertm_handle_rej(struct sock *sk,
  5146. struct bt_l2cap_control *control)
  5147. {
  5148. struct l2cap_pinfo *pi;
  5149. struct sk_buff *skb;
  5150. BT_DBG("sk %p, control %p", sk, control);
  5151. pi = l2cap_pi(sk);
  5152. if (control->reqseq == pi->next_tx_seq) {
  5153. BT_DBG("Invalid reqseq %d, disconnecting",
  5154. (int) control->reqseq);
  5155. l2cap_send_disconn_req(pi->conn, sk, ECONNRESET);
  5156. return;
  5157. }
  5158. skb = l2cap_ertm_seq_in_queue(TX_QUEUE(sk), control->reqseq);
  5159. if (pi->max_tx && skb && bt_cb(skb)->retries >= pi->max_tx) {
  5160. BT_DBG("Retry limit exceeded (%d)", (int) pi->max_tx);
  5161. l2cap_send_disconn_req(pi->conn, sk, ECONNRESET);
  5162. return;
  5163. }
  5164. pi->conn_state &= ~L2CAP_CONN_REMOTE_BUSY;
  5165. l2cap_ertm_pass_to_tx(sk, control);
  5166. if (control->final) {
  5167. if (pi->conn_state & L2CAP_CONN_REJ_ACT)
  5168. pi->conn_state &= ~L2CAP_CONN_REJ_ACT;
  5169. else
  5170. l2cap_ertm_retransmit_all(sk, control);
  5171. } else {
  5172. l2cap_ertm_retransmit_all(sk, control);
  5173. l2cap_ertm_send(sk);
  5174. if (pi->tx_state == L2CAP_ERTM_TX_STATE_WAIT_F)
  5175. pi->conn_state |= L2CAP_CONN_REJ_ACT;
  5176. }
  5177. }
  5178. static u8 l2cap_ertm_classify_txseq(struct sock *sk, u16 txseq)
  5179. {
  5180. struct l2cap_pinfo *pi;
  5181. BT_DBG("sk %p, txseq %d", sk, (int)txseq);
  5182. pi = l2cap_pi(sk);
  5183. BT_DBG("last_acked_seq %d, expected_tx_seq %d", (int)pi->last_acked_seq,
  5184. (int)pi->expected_tx_seq);
  5185. if (pi->rx_state == L2CAP_ERTM_RX_STATE_SREJ_SENT) {
  5186. if (__delta_seq(txseq, pi->last_acked_seq, pi) >= pi->tx_win) {
  5187. /* See notes below regarding "double poll" and
  5188. * invalid packets.
  5189. */
  5190. if (pi->tx_win <= ((pi->tx_win_max + 1) >> 1)) {
  5191. BT_DBG("Invalid/Ignore - txseq outside "
  5192. "tx window after SREJ sent");
  5193. return L2CAP_ERTM_TXSEQ_INVALID_IGNORE;
  5194. } else {
  5195. BT_DBG("Invalid - bad txseq within tx "
  5196. "window after SREJ sent");
  5197. return L2CAP_ERTM_TXSEQ_INVALID;
  5198. }
  5199. }
  5200. if (pi->srej_list.head == txseq) {
  5201. BT_DBG("Expected SREJ");
  5202. return L2CAP_ERTM_TXSEQ_EXPECTED_SREJ;
  5203. }
  5204. if (l2cap_ertm_seq_in_queue(SREJ_QUEUE(sk), txseq)) {
  5205. BT_DBG("Duplicate SREJ - txseq already stored");
  5206. return L2CAP_ERTM_TXSEQ_DUPLICATE_SREJ;
  5207. }
  5208. if (l2cap_seq_list_contains(&pi->srej_list, txseq)) {
  5209. BT_DBG("Unexpected SREJ - txseq not requested "
  5210. "with SREJ");
  5211. return L2CAP_ERTM_TXSEQ_UNEXPECTED_SREJ;
  5212. }
  5213. }
  5214. if (pi->expected_tx_seq == txseq) {
  5215. if (__delta_seq(txseq, pi->last_acked_seq, pi) >= pi->tx_win) {
  5216. BT_DBG("Invalid - txseq outside tx window");
  5217. return L2CAP_ERTM_TXSEQ_INVALID;
  5218. } else {
  5219. BT_DBG("Expected");
  5220. return L2CAP_ERTM_TXSEQ_EXPECTED;
  5221. }
  5222. }
  5223. if (__delta_seq(txseq, pi->last_acked_seq, pi) <
  5224. __delta_seq(pi->expected_tx_seq, pi->last_acked_seq, pi)) {
  5225. BT_DBG("Duplicate - expected_tx_seq later than txseq");
  5226. return L2CAP_ERTM_TXSEQ_DUPLICATE;
  5227. }
  5228. if (__delta_seq(txseq, pi->last_acked_seq, pi) >= pi->tx_win) {
  5229. /* A source of invalid packets is a "double poll" condition,
  5230. * where delays cause us to send multiple poll packets. If
  5231. * the remote stack receives and processes both polls,
  5232. * sequence numbers can wrap around in such a way that a
  5233. * resent frame has a sequence number that looks like new data
  5234. * with a sequence gap. This would trigger an erroneous SREJ
  5235. * request.
  5236. *
  5237. * Fortunately, this is impossible with a tx window that's
  5238. * less than half of the maximum sequence number, which allows
  5239. * invalid frames to be safely ignored.
  5240. *
  5241. * With tx window sizes greater than half of the tx window
  5242. * maximum, the frame is invalid and cannot be ignored. This
  5243. * causes a disconnect.
  5244. */
  5245. if (pi->tx_win <= ((pi->tx_win_max + 1) >> 1)) {
  5246. BT_DBG("Invalid/Ignore - txseq outside tx window");
  5247. return L2CAP_ERTM_TXSEQ_INVALID_IGNORE;
  5248. } else {
  5249. BT_DBG("Invalid - txseq outside tx window");
  5250. return L2CAP_ERTM_TXSEQ_INVALID;
  5251. }
  5252. } else {
  5253. BT_DBG("Unexpected - txseq indicates missing frames");
  5254. return L2CAP_ERTM_TXSEQ_UNEXPECTED;
  5255. }
  5256. }
  5257. static int l2cap_ertm_rx_state_recv(struct sock *sk,
  5258. struct bt_l2cap_control *control,
  5259. struct sk_buff *skb, u8 event)
  5260. {
  5261. struct l2cap_pinfo *pi;
  5262. int err = 0;
  5263. bool skb_in_use = 0;
  5264. BT_DBG("sk %p, control %p, skb %p, event %d", sk, control, skb,
  5265. (int)event);
  5266. pi = l2cap_pi(sk);
  5267. switch (event) {
  5268. case L2CAP_ERTM_EVENT_RECV_IFRAME:
  5269. switch (l2cap_ertm_classify_txseq(sk, control->txseq)) {
  5270. case L2CAP_ERTM_TXSEQ_EXPECTED:
  5271. l2cap_ertm_pass_to_tx(sk, control);
  5272. if (pi->conn_state & L2CAP_CONN_LOCAL_BUSY) {
  5273. BT_DBG("Busy, discarding expected seq %d",
  5274. control->txseq);
  5275. break;
  5276. }
  5277. pi->expected_tx_seq = __next_seq(control->txseq, pi);
  5278. pi->buffer_seq = pi->expected_tx_seq;
  5279. skb_in_use = 1;
  5280. err = l2cap_ertm_rx_expected_iframe(sk, control, skb);
  5281. if (err)
  5282. break;
  5283. if (control->final) {
  5284. if (pi->conn_state & L2CAP_CONN_REJ_ACT)
  5285. pi->conn_state &= ~L2CAP_CONN_REJ_ACT;
  5286. else {
  5287. control->final = 0;
  5288. l2cap_ertm_retransmit_all(sk, control);
  5289. l2cap_ertm_send(sk);
  5290. }
  5291. }
  5292. if (!(pi->conn_state & L2CAP_CONN_LOCAL_BUSY))
  5293. l2cap_ertm_send_ack(sk);
  5294. break;
  5295. case L2CAP_ERTM_TXSEQ_UNEXPECTED:
  5296. l2cap_ertm_pass_to_tx(sk, control);
  5297. /* Can't issue SREJ frames in the local busy state.
  5298. * Drop this frame, it will be seen as missing
  5299. * when local busy is exited.
  5300. */
  5301. if (pi->conn_state & L2CAP_CONN_LOCAL_BUSY) {
  5302. BT_DBG("Busy, discarding unexpected seq %d",
  5303. control->txseq);
  5304. break;
  5305. }
  5306. /* There was a gap in the sequence, so an SREJ
  5307. * must be sent for each missing frame. The
  5308. * current frame is stored for later use.
  5309. */
  5310. skb_queue_tail(SREJ_QUEUE(sk), skb);
  5311. skb_in_use = 1;
  5312. BT_DBG("Queued %p (queue len %d)", skb,
  5313. skb_queue_len(SREJ_QUEUE(sk)));
  5314. pi->conn_state &= ~L2CAP_CONN_SREJ_ACT;
  5315. l2cap_seq_list_clear(&pi->srej_list);
  5316. l2cap_ertm_send_srej(sk, control->txseq);
  5317. pi->rx_state = L2CAP_ERTM_RX_STATE_SREJ_SENT;
  5318. break;
  5319. case L2CAP_ERTM_TXSEQ_DUPLICATE:
  5320. l2cap_ertm_pass_to_tx(sk, control);
  5321. break;
  5322. case L2CAP_ERTM_TXSEQ_INVALID_IGNORE:
  5323. break;
  5324. case L2CAP_ERTM_TXSEQ_INVALID:
  5325. default:
  5326. l2cap_send_disconn_req(l2cap_pi(sk)->conn, sk,
  5327. ECONNRESET);
  5328. break;
  5329. }
  5330. break;
  5331. case L2CAP_ERTM_EVENT_RECV_RR:
  5332. l2cap_ertm_pass_to_tx(sk, control);
  5333. if (control->final) {
  5334. pi->conn_state &= ~L2CAP_CONN_REMOTE_BUSY;
  5335. if (pi->conn_state & L2CAP_CONN_REJ_ACT)
  5336. pi->conn_state &= ~L2CAP_CONN_REJ_ACT;
  5337. else if (pi->amp_move_state == L2CAP_AMP_STATE_STABLE ||
  5338. pi->amp_move_state ==
  5339. L2CAP_AMP_STATE_WAIT_PREPARE) {
  5340. control->final = 0;
  5341. l2cap_ertm_retransmit_all(sk, control);
  5342. }
  5343. l2cap_ertm_send(sk);
  5344. } else if (control->poll) {
  5345. l2cap_ertm_send_i_or_rr_or_rnr(sk);
  5346. } else {
  5347. if ((pi->conn_state & L2CAP_CONN_REMOTE_BUSY) &&
  5348. pi->unacked_frames)
  5349. l2cap_ertm_start_retrans_timer(pi);
  5350. pi->conn_state &= ~L2CAP_CONN_REMOTE_BUSY;
  5351. l2cap_ertm_send(sk);
  5352. }
  5353. break;
  5354. case L2CAP_ERTM_EVENT_RECV_RNR:
  5355. pi->conn_state |= L2CAP_CONN_REMOTE_BUSY;
  5356. l2cap_ertm_pass_to_tx(sk, control);
  5357. if (control && control->poll) {
  5358. pi->conn_state |= L2CAP_CONN_SEND_FBIT;
  5359. l2cap_ertm_send_rr_or_rnr(sk, 0);
  5360. }
  5361. l2cap_ertm_stop_retrans_timer(pi);
  5362. l2cap_seq_list_clear(&pi->retrans_list);
  5363. break;
  5364. case L2CAP_ERTM_EVENT_RECV_REJ:
  5365. l2cap_ertm_handle_rej(sk, control);
  5366. break;
  5367. case L2CAP_ERTM_EVENT_RECV_SREJ:
  5368. l2cap_ertm_handle_srej(sk, control);
  5369. break;
  5370. default:
  5371. break;
  5372. }
  5373. if (skb && !skb_in_use) {
  5374. BT_DBG("Freeing %p", skb);
  5375. kfree_skb(skb);
  5376. }
  5377. return err;
  5378. }
  5379. static int l2cap_ertm_rx_state_srej_sent(struct sock *sk,
  5380. struct bt_l2cap_control *control,
  5381. struct sk_buff *skb, u8 event)
  5382. {
  5383. struct l2cap_pinfo *pi;
  5384. int err = 0;
  5385. u16 txseq = control->txseq;
  5386. bool skb_in_use = 0;
  5387. BT_DBG("sk %p, control %p, skb %p, event %d", sk, control, skb,
  5388. (int)event);
  5389. pi = l2cap_pi(sk);
  5390. switch (event) {
  5391. case L2CAP_ERTM_EVENT_RECV_IFRAME:
  5392. switch (l2cap_ertm_classify_txseq(sk, txseq)) {
  5393. case L2CAP_ERTM_TXSEQ_EXPECTED:
  5394. /* Keep frame for reassembly later */
  5395. l2cap_ertm_pass_to_tx(sk, control);
  5396. skb_queue_tail(SREJ_QUEUE(sk), skb);
  5397. skb_in_use = 1;
  5398. BT_DBG("Queued %p (queue len %d)", skb,
  5399. skb_queue_len(SREJ_QUEUE(sk)));
  5400. pi->expected_tx_seq = __next_seq(txseq, pi);
  5401. break;
  5402. case L2CAP_ERTM_TXSEQ_EXPECTED_SREJ:
  5403. l2cap_seq_list_pop(&pi->srej_list);
  5404. l2cap_ertm_pass_to_tx(sk, control);
  5405. skb_queue_tail(SREJ_QUEUE(sk), skb);
  5406. skb_in_use = 1;
  5407. BT_DBG("Queued %p (queue len %d)", skb,
  5408. skb_queue_len(SREJ_QUEUE(sk)));
  5409. err = l2cap_ertm_rx_queued_iframes(sk);
  5410. if (err)
  5411. break;
  5412. break;
  5413. case L2CAP_ERTM_TXSEQ_UNEXPECTED:
  5414. /* Got a frame that can't be reassembled yet.
  5415. * Save it for later, and send SREJs to cover
  5416. * the missing frames.
  5417. */
  5418. skb_queue_tail(SREJ_QUEUE(sk), skb);
  5419. skb_in_use = 1;
  5420. BT_DBG("Queued %p (queue len %d)", skb,
  5421. skb_queue_len(SREJ_QUEUE(sk)));
  5422. l2cap_ertm_pass_to_tx(sk, control);
  5423. l2cap_ertm_send_srej(sk, control->txseq);
  5424. break;
  5425. case L2CAP_ERTM_TXSEQ_UNEXPECTED_SREJ:
  5426. /* This frame was requested with an SREJ, but
  5427. * some expected retransmitted frames are
  5428. * missing. Request retransmission of missing
  5429. * SREJ'd frames.
  5430. */
  5431. skb_queue_tail(SREJ_QUEUE(sk), skb);
  5432. skb_in_use = 1;
  5433. BT_DBG("Queued %p (queue len %d)", skb,
  5434. skb_queue_len(SREJ_QUEUE(sk)));
  5435. l2cap_ertm_pass_to_tx(sk, control);
  5436. l2cap_ertm_send_srej_list(sk, control->txseq);
  5437. break;
  5438. case L2CAP_ERTM_TXSEQ_DUPLICATE_SREJ:
  5439. /* We've already queued this frame. Drop this copy. */
  5440. l2cap_ertm_pass_to_tx(sk, control);
  5441. break;
  5442. case L2CAP_ERTM_TXSEQ_DUPLICATE:
  5443. /* Expecting a later sequence number, so this frame
  5444. * was already received. Ignore it completely.
  5445. */
  5446. break;
  5447. case L2CAP_ERTM_TXSEQ_INVALID_IGNORE:
  5448. break;
  5449. case L2CAP_ERTM_TXSEQ_INVALID:
  5450. default:
  5451. l2cap_send_disconn_req(l2cap_pi(sk)->conn, sk,
  5452. ECONNRESET);
  5453. break;
  5454. }
  5455. break;
  5456. case L2CAP_ERTM_EVENT_RECV_RR:
  5457. l2cap_ertm_pass_to_tx(sk, control);
  5458. if (control->final) {
  5459. pi->conn_state &= ~L2CAP_CONN_REMOTE_BUSY;
  5460. if (pi->conn_state & L2CAP_CONN_REJ_ACT)
  5461. pi->conn_state &= ~L2CAP_CONN_REJ_ACT;
  5462. else {
  5463. control->final = 0;
  5464. l2cap_ertm_retransmit_all(sk, control);
  5465. }
  5466. l2cap_ertm_send(sk);
  5467. } else if (control->poll) {
  5468. if ((pi->conn_state & L2CAP_CONN_REMOTE_BUSY) &&
  5469. pi->unacked_frames) {
  5470. l2cap_ertm_start_retrans_timer(pi);
  5471. }
  5472. pi->conn_state &= ~L2CAP_CONN_REMOTE_BUSY;
  5473. pi->conn_state |= L2CAP_CONN_SEND_FBIT;
  5474. l2cap_ertm_send_srej_tail(sk);
  5475. } else {
  5476. if ((pi->conn_state & L2CAP_CONN_REMOTE_BUSY) &&
  5477. pi->unacked_frames) {
  5478. l2cap_ertm_start_retrans_timer(pi);
  5479. }
  5480. pi->conn_state &= ~L2CAP_CONN_REMOTE_BUSY;
  5481. l2cap_ertm_send_ack(sk);
  5482. }
  5483. break;
  5484. case L2CAP_ERTM_EVENT_RECV_RNR:
  5485. pi->conn_state |= L2CAP_CONN_REMOTE_BUSY;
  5486. l2cap_ertm_pass_to_tx(sk, control);
  5487. if (control->poll)
  5488. l2cap_ertm_send_srej_tail(sk);
  5489. else {
  5490. struct bt_l2cap_control rr_control;
  5491. memset(&rr_control, 0, sizeof(rr_control));
  5492. rr_control.frame_type = 's';
  5493. rr_control.super = L2CAP_SFRAME_RR;
  5494. rr_control.reqseq = pi->buffer_seq;
  5495. l2cap_ertm_send_sframe(sk, &rr_control);
  5496. }
  5497. break;
  5498. case L2CAP_ERTM_EVENT_RECV_REJ:
  5499. l2cap_ertm_handle_rej(sk, control);
  5500. break;
  5501. case L2CAP_ERTM_EVENT_RECV_SREJ:
  5502. l2cap_ertm_handle_srej(sk, control);
  5503. break;
  5504. }
  5505. if (skb && !skb_in_use) {
  5506. BT_DBG("Freeing %p", skb);
  5507. kfree_skb(skb);
  5508. }
  5509. return err;
  5510. }
  5511. static int l2cap_ertm_rx_state_amp_move(struct sock *sk,
  5512. struct bt_l2cap_control *control,
  5513. struct sk_buff *skb, u8 event)
  5514. {
  5515. struct l2cap_pinfo *pi;
  5516. int err = 0;
  5517. bool skb_in_use = 0;
  5518. BT_DBG("sk %p, control %p, skb %p, event %d", sk, control, skb,
  5519. (int)event);
  5520. pi = l2cap_pi(sk);
  5521. /* Only handle expected frames, to avoid state changes. */
  5522. switch (event) {
  5523. case L2CAP_ERTM_EVENT_RECV_IFRAME:
  5524. if (l2cap_ertm_classify_txseq(sk, control->txseq) ==
  5525. L2CAP_ERTM_TXSEQ_EXPECTED) {
  5526. l2cap_ertm_pass_to_tx(sk, control);
  5527. if (pi->conn_state & L2CAP_CONN_LOCAL_BUSY) {
  5528. BT_DBG("Busy, discarding expected seq %d",
  5529. control->txseq);
  5530. break;
  5531. }
  5532. pi->expected_tx_seq = __next_seq(control->txseq, pi);
  5533. pi->buffer_seq = pi->expected_tx_seq;
  5534. skb_in_use = 1;
  5535. err = l2cap_ertm_rx_expected_iframe(sk, control, skb);
  5536. if (err)
  5537. break;
  5538. if (control->final) {
  5539. if (pi->conn_state & L2CAP_CONN_REJ_ACT)
  5540. pi->conn_state &= ~L2CAP_CONN_REJ_ACT;
  5541. else
  5542. control->final = 0;
  5543. }
  5544. }
  5545. break;
  5546. case L2CAP_ERTM_EVENT_RECV_RR:
  5547. case L2CAP_ERTM_EVENT_RECV_RNR:
  5548. case L2CAP_ERTM_EVENT_RECV_REJ:
  5549. l2cap_ertm_process_reqseq(sk, control->reqseq);
  5550. break;
  5551. case L2CAP_ERTM_EVENT_RECV_SREJ:
  5552. /* Ignore */
  5553. break;
  5554. default:
  5555. break;
  5556. }
  5557. if (skb && !skb_in_use) {
  5558. BT_DBG("Freeing %p", skb);
  5559. kfree_skb(skb);
  5560. }
  5561. return err;
  5562. }
  5563. static int l2cap_answer_move_poll(struct sock *sk)
  5564. {
  5565. struct l2cap_pinfo *pi;
  5566. struct bt_l2cap_control control;
  5567. int err = 0;
  5568. BT_DBG("sk %p", sk);
  5569. pi = l2cap_pi(sk);
  5570. l2cap_ertm_process_reqseq(sk, pi->amp_move_reqseq);
  5571. if (!skb_queue_empty(TX_QUEUE(sk)))
  5572. sk->sk_send_head = skb_peek(TX_QUEUE(sk));
  5573. else
  5574. sk->sk_send_head = NULL;
  5575. /* Rewind next_tx_seq to the point expected
  5576. * by the receiver.
  5577. */
  5578. pi->next_tx_seq = pi->amp_move_reqseq;
  5579. pi->unacked_frames = 0;
  5580. err = l2cap_finish_amp_move(sk);
  5581. if (err)
  5582. return err;
  5583. pi->conn_state |= L2CAP_CONN_SEND_FBIT;
  5584. l2cap_ertm_send_i_or_rr_or_rnr(sk);
  5585. memset(&control, 0, sizeof(control));
  5586. control.reqseq = pi->amp_move_reqseq;
  5587. if (pi->amp_move_event == L2CAP_ERTM_EVENT_RECV_IFRAME)
  5588. err = -EPROTO;
  5589. else
  5590. err = l2cap_ertm_rx_state_recv(sk, &control, NULL,
  5591. pi->amp_move_event);
  5592. return err;
  5593. }
  5594. static void l2cap_amp_move_setup(struct sock *sk)
  5595. {
  5596. struct l2cap_pinfo *pi;
  5597. struct sk_buff *skb;
  5598. BT_DBG("sk %p", sk);
  5599. pi = l2cap_pi(sk);
  5600. l2cap_ertm_stop_ack_timer(pi);
  5601. l2cap_ertm_stop_retrans_timer(pi);
  5602. l2cap_ertm_stop_monitor_timer(pi);
  5603. pi->retry_count = 0;
  5604. skb_queue_walk(TX_QUEUE(sk), skb) {
  5605. if (bt_cb(skb)->retries)
  5606. bt_cb(skb)->retries = 1;
  5607. else
  5608. break;
  5609. }
  5610. pi->expected_tx_seq = pi->buffer_seq;
  5611. pi->conn_state &= ~(L2CAP_CONN_REJ_ACT | L2CAP_CONN_SREJ_ACT);
  5612. l2cap_seq_list_clear(&pi->retrans_list);
  5613. l2cap_seq_list_clear(&l2cap_pi(sk)->srej_list);
  5614. skb_queue_purge(SREJ_QUEUE(sk));
  5615. pi->tx_state = L2CAP_ERTM_TX_STATE_XMIT;
  5616. pi->rx_state = L2CAP_ERTM_RX_STATE_AMP_MOVE;
  5617. BT_DBG("tx_state 0x2.2%x rx_state 0x2.2%x", pi->tx_state,
  5618. pi->rx_state);
  5619. pi->conn_state |= L2CAP_CONN_REMOTE_BUSY;
  5620. }
  5621. static void l2cap_amp_move_revert(struct sock *sk)
  5622. {
  5623. struct l2cap_pinfo *pi;
  5624. BT_DBG("sk %p", sk);
  5625. pi = l2cap_pi(sk);
  5626. if (pi->amp_move_role == L2CAP_AMP_MOVE_INITIATOR) {
  5627. l2cap_ertm_tx(sk, NULL, NULL, L2CAP_ERTM_EVENT_EXPLICIT_POLL);
  5628. pi->rx_state = L2CAP_ERTM_RX_STATE_WAIT_F_FLAG;
  5629. } else if (pi->amp_move_role == L2CAP_AMP_MOVE_RESPONDER)
  5630. pi->rx_state = L2CAP_ERTM_RX_STATE_WAIT_P_FLAG;
  5631. }
  5632. static int l2cap_amp_move_reconf(struct sock *sk)
  5633. {
  5634. struct l2cap_pinfo *pi;
  5635. u8 buf[64];
  5636. int err = 0;
  5637. BT_DBG("sk %p", sk);
  5638. pi = l2cap_pi(sk);
  5639. l2cap_send_cmd(pi->conn, l2cap_get_ident(pi->conn), L2CAP_CONF_REQ,
  5640. l2cap_build_amp_reconf_req(sk, buf, sizeof(buf)), buf);
  5641. return err;
  5642. }
  5643. static void l2cap_amp_move_success(struct sock *sk)
  5644. {
  5645. struct l2cap_pinfo *pi;
  5646. BT_DBG("sk %p", sk);
  5647. pi = l2cap_pi(sk);
  5648. if (pi->amp_move_role == L2CAP_AMP_MOVE_INITIATOR) {
  5649. int err = 0;
  5650. /* Send reconfigure request */
  5651. if (pi->mode == L2CAP_MODE_ERTM) {
  5652. pi->reconf_state = L2CAP_RECONF_INT;
  5653. if (enable_reconfig)
  5654. err = l2cap_amp_move_reconf(sk);
  5655. if (err || !enable_reconfig) {
  5656. pi->reconf_state = L2CAP_RECONF_NONE;
  5657. l2cap_ertm_tx(sk, NULL, NULL,
  5658. L2CAP_ERTM_EVENT_EXPLICIT_POLL);
  5659. pi->rx_state = L2CAP_ERTM_RX_STATE_WAIT_F_FLAG;
  5660. }
  5661. } else
  5662. pi->rx_state = L2CAP_ERTM_RX_STATE_RECV;
  5663. } else if (pi->amp_move_role == L2CAP_AMP_MOVE_RESPONDER) {
  5664. if (pi->mode == L2CAP_MODE_ERTM)
  5665. pi->rx_state =
  5666. L2CAP_ERTM_RX_STATE_WAIT_P_FLAG_RECONFIGURE;
  5667. else
  5668. pi->rx_state = L2CAP_ERTM_RX_STATE_RECV;
  5669. }
  5670. }
  5671. static inline bool __valid_reqseq(struct l2cap_pinfo *pi, u16 reqseq)
  5672. {
  5673. /* Make sure reqseq is for a packet that has been sent but not acked */
  5674. u16 unacked = __delta_seq(pi->next_tx_seq, pi->expected_ack_seq, pi);
  5675. return __delta_seq(pi->next_tx_seq, reqseq, pi) <= unacked;
  5676. }
  5677. static int l2cap_strm_rx(struct sock *sk, struct bt_l2cap_control *control,
  5678. struct sk_buff *skb)
  5679. {
  5680. struct l2cap_pinfo *pi;
  5681. int err = 0;
  5682. BT_DBG("sk %p, control %p, skb %p, state %d",
  5683. sk, control, skb, l2cap_pi(sk)->rx_state);
  5684. pi = l2cap_pi(sk);
  5685. if (l2cap_ertm_classify_txseq(sk, control->txseq) ==
  5686. L2CAP_ERTM_TXSEQ_EXPECTED) {
  5687. l2cap_ertm_pass_to_tx(sk, control);
  5688. BT_DBG("buffer_seq %d->%d", pi->buffer_seq,
  5689. __next_seq(pi->buffer_seq, pi));
  5690. pi->buffer_seq = __next_seq(pi->buffer_seq, pi);
  5691. l2cap_ertm_rx_expected_iframe(sk, control, skb);
  5692. } else {
  5693. if (pi->sdu) {
  5694. kfree_skb(pi->sdu);
  5695. pi->sdu = NULL;
  5696. }
  5697. pi->sdu_last_frag = NULL;
  5698. pi->sdu_len = 0;
  5699. if (skb) {
  5700. BT_DBG("Freeing %p", skb);
  5701. kfree_skb(skb);
  5702. }
  5703. }
  5704. pi->last_acked_seq = control->txseq;
  5705. pi->expected_tx_seq = __next_seq(control->txseq, pi);
  5706. return err;
  5707. }
  5708. static int l2cap_ertm_rx(struct sock *sk, struct bt_l2cap_control *control,
  5709. struct sk_buff *skb, u8 event)
  5710. {
  5711. struct l2cap_pinfo *pi;
  5712. int err = 0;
  5713. BT_DBG("sk %p, control %p, skb %p, event %d, state %d",
  5714. sk, control, skb, (int)event, l2cap_pi(sk)->rx_state);
  5715. pi = l2cap_pi(sk);
  5716. if (__valid_reqseq(pi, control->reqseq)) {
  5717. switch (pi->rx_state) {
  5718. case L2CAP_ERTM_RX_STATE_RECV:
  5719. err = l2cap_ertm_rx_state_recv(sk, control, skb, event);
  5720. break;
  5721. case L2CAP_ERTM_RX_STATE_SREJ_SENT:
  5722. err = l2cap_ertm_rx_state_srej_sent(sk, control, skb,
  5723. event);
  5724. break;
  5725. case L2CAP_ERTM_RX_STATE_AMP_MOVE:
  5726. err = l2cap_ertm_rx_state_amp_move(sk, control, skb,
  5727. event);
  5728. break;
  5729. case L2CAP_ERTM_RX_STATE_WAIT_F_FLAG:
  5730. if (control->final) {
  5731. pi->conn_state &= ~L2CAP_CONN_REMOTE_BUSY;
  5732. pi->amp_move_role = L2CAP_AMP_MOVE_NONE;
  5733. pi->rx_state = L2CAP_ERTM_RX_STATE_RECV;
  5734. l2cap_ertm_process_reqseq(sk, control->reqseq);
  5735. if (!skb_queue_empty(TX_QUEUE(sk)))
  5736. sk->sk_send_head =
  5737. skb_peek(TX_QUEUE(sk));
  5738. else
  5739. sk->sk_send_head = NULL;
  5740. /* Rewind next_tx_seq to the point expected
  5741. * by the receiver.
  5742. */
  5743. pi->next_tx_seq = control->reqseq;
  5744. pi->unacked_frames = 0;
  5745. if (pi->ampcon)
  5746. pi->conn->mtu =
  5747. pi->ampcon->hdev->acl_mtu;
  5748. else
  5749. pi->conn->mtu =
  5750. pi->conn->hcon->hdev->acl_mtu;
  5751. err = l2cap_setup_resegment(sk);
  5752. if (err)
  5753. break;
  5754. err = l2cap_ertm_rx_state_recv(sk, control, skb,
  5755. event);
  5756. }
  5757. break;
  5758. case L2CAP_ERTM_RX_STATE_WAIT_P_FLAG:
  5759. if (control->poll) {
  5760. pi->amp_move_reqseq = control->reqseq;
  5761. pi->amp_move_event = event;
  5762. err = l2cap_answer_move_poll(sk);
  5763. }
  5764. break;
  5765. case L2CAP_ERTM_RX_STATE_WAIT_P_FLAG_RECONFIGURE:
  5766. if (control->poll) {
  5767. pi->amp_move_reqseq = control->reqseq;
  5768. pi->amp_move_event = event;
  5769. BT_DBG("amp_move_role 0x%2.2x, "
  5770. "reconf_state 0x%2.2x",
  5771. pi->amp_move_role, pi->reconf_state);
  5772. if (pi->reconf_state == L2CAP_RECONF_ACC)
  5773. err = l2cap_amp_move_reconf(sk);
  5774. else
  5775. err = l2cap_answer_move_poll(sk);
  5776. }
  5777. break;
  5778. default:
  5779. /* shut it down */
  5780. break;
  5781. }
  5782. } else {
  5783. BT_DBG("Invalid reqseq %d (next_tx_seq %d, expected_ack_seq %d",
  5784. control->reqseq, pi->next_tx_seq, pi->expected_ack_seq);
  5785. l2cap_send_disconn_req(pi->conn, sk, ECONNRESET);
  5786. }
  5787. return err;
  5788. }
  5789. void l2cap_fixed_channel_config(struct sock *sk, struct l2cap_options *opt)
  5790. {
  5791. lock_sock(sk);
  5792. l2cap_pi(sk)->fixed_channel = 1;
  5793. l2cap_pi(sk)->imtu = opt->imtu;
  5794. l2cap_pi(sk)->omtu = opt->omtu;
  5795. l2cap_pi(sk)->remote_mps = opt->omtu;
  5796. l2cap_pi(sk)->mps = opt->omtu;
  5797. l2cap_pi(sk)->flush_to = opt->flush_to;
  5798. l2cap_pi(sk)->mode = opt->mode;
  5799. l2cap_pi(sk)->fcs = opt->fcs;
  5800. l2cap_pi(sk)->max_tx = opt->max_tx;
  5801. l2cap_pi(sk)->remote_max_tx = opt->max_tx;
  5802. l2cap_pi(sk)->tx_win = opt->txwin_size;
  5803. l2cap_pi(sk)->remote_tx_win = opt->txwin_size;
  5804. l2cap_pi(sk)->retrans_timeout = L2CAP_DEFAULT_RETRANS_TO;
  5805. l2cap_pi(sk)->monitor_timeout = L2CAP_DEFAULT_MONITOR_TO;
  5806. if (opt->mode == L2CAP_MODE_ERTM ||
  5807. l2cap_pi(sk)->mode == L2CAP_MODE_STREAMING)
  5808. l2cap_ertm_init(sk);
  5809. release_sock(sk);
  5810. return;
  5811. }
  5812. static const u8 l2cap_ertm_rx_func_to_event[4] = {
  5813. L2CAP_ERTM_EVENT_RECV_RR, L2CAP_ERTM_EVENT_RECV_REJ,
  5814. L2CAP_ERTM_EVENT_RECV_RNR, L2CAP_ERTM_EVENT_RECV_SREJ
  5815. };
  5816. int l2cap_data_channel(struct sock *sk, struct sk_buff *skb)
  5817. {
  5818. struct l2cap_pinfo *pi;
  5819. struct bt_l2cap_control *control;
  5820. u16 len;
  5821. u8 event;
  5822. pi = l2cap_pi(sk);
  5823. BT_DBG("sk %p, len %d, mode %d", sk, skb->len, pi->mode);
  5824. if (sk->sk_state != BT_CONNECTED)
  5825. goto drop;
  5826. switch (pi->mode) {
  5827. case L2CAP_MODE_BASIC:
  5828. /* If socket recv buffers overflows we drop data here
  5829. * which is *bad* because L2CAP has to be reliable.
  5830. * But we don't have any other choice. L2CAP doesn't
  5831. * provide flow control mechanism. */
  5832. if (pi->imtu < skb->len)
  5833. goto drop;
  5834. if (!sock_queue_rcv_skb(sk, skb))
  5835. goto done;
  5836. break;
  5837. case L2CAP_MODE_ERTM:
  5838. case L2CAP_MODE_STREAMING:
  5839. control = &bt_cb(skb)->control;
  5840. if (pi->extended_control) {
  5841. __get_extended_control(get_unaligned_le32(skb->data),
  5842. control);
  5843. skb_pull(skb, 4);
  5844. } else {
  5845. __get_enhanced_control(get_unaligned_le16(skb->data),
  5846. control);
  5847. skb_pull(skb, 2);
  5848. }
  5849. len = skb->len;
  5850. if (l2cap_check_fcs(pi, skb))
  5851. goto drop;
  5852. if ((control->frame_type == 'i') &&
  5853. (control->sar == L2CAP_SAR_START))
  5854. len -= 2;
  5855. if (pi->fcs == L2CAP_FCS_CRC16)
  5856. len -= 2;
  5857. /*
  5858. * We can just drop the corrupted I-frame here.
  5859. * Receiver will miss it and start proper recovery
  5860. * procedures and ask for retransmission.
  5861. */
  5862. if (len > pi->mps) {
  5863. l2cap_send_disconn_req(pi->conn, sk, ECONNRESET);
  5864. goto drop;
  5865. }
  5866. if (control->frame_type == 'i') {
  5867. int err;
  5868. BT_DBG("iframe sar %d, reqseq %d, final %d, txseq %d",
  5869. control->sar, control->reqseq, control->final,
  5870. control->txseq);
  5871. /* Validate F-bit - F=0 always valid, F=1 only
  5872. * valid in TX WAIT_F
  5873. */
  5874. if (control->final && (pi->tx_state !=
  5875. L2CAP_ERTM_TX_STATE_WAIT_F))
  5876. goto drop;
  5877. if (pi->mode != L2CAP_MODE_STREAMING) {
  5878. event = L2CAP_ERTM_EVENT_RECV_IFRAME;
  5879. err = l2cap_ertm_rx(sk, control, skb, event);
  5880. } else
  5881. err = l2cap_strm_rx(sk, control, skb);
  5882. if (err)
  5883. l2cap_send_disconn_req(pi->conn, sk,
  5884. ECONNRESET);
  5885. } else {
  5886. /* Only I-frames are expected in streaming mode */
  5887. if (pi->mode == L2CAP_MODE_STREAMING)
  5888. goto drop;
  5889. BT_DBG("sframe reqseq %d, final %d, poll %d, super %d",
  5890. control->reqseq, control->final, control->poll,
  5891. control->super);
  5892. if (len != 0) {
  5893. l2cap_send_disconn_req(pi->conn, sk,
  5894. ECONNRESET);
  5895. goto drop;
  5896. }
  5897. /* Validate F and P bits */
  5898. if (control->final &&
  5899. ((pi->tx_state != L2CAP_ERTM_TX_STATE_WAIT_F)
  5900. || control->poll))
  5901. goto drop;
  5902. event = l2cap_ertm_rx_func_to_event[control->super];
  5903. if (l2cap_ertm_rx(sk, control, skb, event))
  5904. l2cap_send_disconn_req(pi->conn, sk,
  5905. ECONNRESET);
  5906. }
  5907. goto done;
  5908. default:
  5909. BT_DBG("sk %p: bad mode 0x%2.2x", sk, pi->mode);
  5910. break;
  5911. }
  5912. drop:
  5913. kfree_skb(skb);
  5914. done:
  5915. return 0;
  5916. }
  5917. void l2cap_recv_deferred_frame(struct sock *sk, struct sk_buff *skb)
  5918. {
  5919. lock_sock(sk);
  5920. l2cap_data_channel(sk, skb);
  5921. release_sock(sk);
  5922. }
  5923. static inline int l2cap_conless_channel(struct l2cap_conn *conn, __le16 psm, struct sk_buff *skb)
  5924. {
  5925. struct sock *sk;
  5926. sk = l2cap_get_sock_by_psm(0, psm, conn->src);
  5927. if (!sk)
  5928. goto drop;
  5929. bh_lock_sock(sk);
  5930. BT_DBG("sk %p, len %d", sk, skb->len);
  5931. if (sk->sk_state != BT_BOUND && sk->sk_state != BT_CONNECTED)
  5932. goto drop;
  5933. if (l2cap_pi(sk)->imtu < skb->len)
  5934. goto drop;
  5935. if (!sock_queue_rcv_skb(sk, skb))
  5936. goto done;
  5937. drop:
  5938. kfree_skb(skb);
  5939. done:
  5940. if (sk)
  5941. bh_unlock_sock(sk);
  5942. return 0;
  5943. }
  5944. static inline int l2cap_att_channel(struct l2cap_conn *conn, __le16 cid,
  5945. struct sk_buff *skb)
  5946. {
  5947. struct sock *sk = NULL;
  5948. struct sk_buff *skb_rsp;
  5949. struct l2cap_hdr *lh;
  5950. int dir;
  5951. struct work_struct *open_worker;
  5952. u8 err_rsp[] = {L2CAP_ATT_ERROR, 0x00, 0x00, 0x00,
  5953. L2CAP_ATT_NOT_SUPPORTED};
  5954. if (skb->data[0] == L2CAP_ATT_MTU_REQ) {
  5955. u8 mtu_rsp[] = {L2CAP_ATT_MTU_RSP, 23, 0};
  5956. skb_rsp = bt_skb_alloc(sizeof(mtu_rsp) + L2CAP_HDR_SIZE,
  5957. GFP_ATOMIC);
  5958. if (!skb_rsp)
  5959. goto drop;
  5960. lh = (struct l2cap_hdr *) skb_put(skb_rsp, L2CAP_HDR_SIZE);
  5961. lh->len = cpu_to_le16(sizeof(mtu_rsp));
  5962. lh->cid = cpu_to_le16(L2CAP_CID_LE_DATA);
  5963. memcpy(skb_put(skb_rsp, sizeof(mtu_rsp)), mtu_rsp,
  5964. sizeof(mtu_rsp));
  5965. hci_send_acl(conn->hcon, NULL, skb_rsp, 0);
  5966. goto free_skb;
  5967. }
  5968. dir = (skb->data[0] & L2CAP_ATT_RESPONSE_BIT) ? 0 : 1;
  5969. sk = l2cap_find_sock_by_fixed_cid_and_dir(cid, conn->src,
  5970. conn->dst, dir);
  5971. BT_DBG("sk %p, dir:%d", sk, dir);
  5972. if (!sk)
  5973. goto drop;
  5974. bh_lock_sock(sk);
  5975. BT_DBG("sk %p, len %d", sk, skb->len);
  5976. if (sk->sk_state != BT_BOUND && sk->sk_state != BT_CONNECTED) {
  5977. att_chn_params.cid = cid;
  5978. att_chn_params.conn = conn;
  5979. att_chn_params.dir = dir;
  5980. att_chn_params.skb = skb;
  5981. open_worker = kzalloc(sizeof(*open_worker), GFP_ATOMIC);
  5982. if (!open_worker)
  5983. BT_ERR("Out of memory");
  5984. INIT_WORK(open_worker, l2cap_queue_acl_data);
  5985. schedule_work(open_worker);
  5986. goto done;
  5987. }
  5988. if (l2cap_pi(sk)->imtu < skb->len)
  5989. goto drop;
  5990. if (!sock_queue_rcv_skb(sk, skb))
  5991. goto done;
  5992. drop:
  5993. if (skb->data[0] != L2CAP_ATT_INDICATE)
  5994. goto not_indicate;
  5995. /* If this is an incoming Indication, we are required to confirm */
  5996. skb_rsp = bt_skb_alloc(sizeof(u8) + L2CAP_HDR_SIZE, GFP_ATOMIC);
  5997. if (!skb_rsp)
  5998. goto free_skb;
  5999. lh = (struct l2cap_hdr *) skb_put(skb_rsp, L2CAP_HDR_SIZE);
  6000. lh->len = cpu_to_le16(sizeof(u8));
  6001. lh->cid = cpu_to_le16(L2CAP_CID_LE_DATA);
  6002. err_rsp[0] = L2CAP_ATT_CONFIRM;
  6003. memcpy(skb_put(skb_rsp, sizeof(u8)), err_rsp, sizeof(u8));
  6004. hci_send_acl(conn->hcon, NULL, skb_rsp, 0);
  6005. goto free_skb;
  6006. not_indicate:
  6007. if (skb->data[0] & L2CAP_ATT_RESPONSE_BIT ||
  6008. skb->data[0] == L2CAP_ATT_CONFIRM)
  6009. goto free_skb;
  6010. /* If this is an incoming PDU that requires a response, respond with
  6011. * a generic error so remote device doesn't hang */
  6012. skb_rsp = bt_skb_alloc(sizeof(err_rsp) + L2CAP_HDR_SIZE, GFP_ATOMIC);
  6013. if (!skb_rsp)
  6014. goto free_skb;
  6015. lh = (struct l2cap_hdr *) skb_put(skb_rsp, L2CAP_HDR_SIZE);
  6016. lh->len = cpu_to_le16(sizeof(err_rsp));
  6017. lh->cid = cpu_to_le16(L2CAP_CID_LE_DATA);
  6018. err_rsp[1] = skb->data[0];
  6019. memcpy(skb_put(skb_rsp, sizeof(err_rsp)), err_rsp, sizeof(err_rsp));
  6020. hci_send_acl(conn->hcon, NULL, skb_rsp, 0);
  6021. free_skb:
  6022. kfree_skb(skb);
  6023. done:
  6024. if (sk)
  6025. bh_unlock_sock(sk);
  6026. return 0;
  6027. }
  6028. static void l2cap_recv_frame(struct l2cap_conn *conn, struct sk_buff *skb)
  6029. {
  6030. struct l2cap_hdr *lh = (void *) skb->data;
  6031. struct sock *sk;
  6032. u16 cid, len;
  6033. __le16 psm;
  6034. skb_pull(skb, L2CAP_HDR_SIZE);
  6035. cid = __le16_to_cpu(lh->cid);
  6036. len = __le16_to_cpu(lh->len);
  6037. if (len != skb->len) {
  6038. kfree_skb(skb);
  6039. return;
  6040. }
  6041. BT_DBG("len %d, cid 0x%4.4x", len, cid);
  6042. switch (cid) {
  6043. case L2CAP_CID_LE_SIGNALING:
  6044. case L2CAP_CID_SIGNALING:
  6045. l2cap_sig_channel(conn, skb);
  6046. break;
  6047. case L2CAP_CID_CONN_LESS:
  6048. psm = get_unaligned_le16(skb->data);
  6049. skb_pull(skb, 2);
  6050. l2cap_conless_channel(conn, psm, skb);
  6051. break;
  6052. case L2CAP_CID_LE_DATA:
  6053. l2cap_att_channel(conn, cid, skb);
  6054. break;
  6055. case L2CAP_CID_SMP:
  6056. if (smp_sig_channel(conn, skb))
  6057. l2cap_conn_del(conn->hcon, EACCES, 0);
  6058. break;
  6059. default:
  6060. sk = l2cap_get_chan_by_scid(&conn->chan_list, cid);
  6061. if (sk) {
  6062. if (sock_owned_by_user(sk)) {
  6063. BT_DBG("backlog sk %p", sk);
  6064. if (sk_add_backlog(sk, skb))
  6065. kfree_skb(skb);
  6066. } else
  6067. l2cap_data_channel(sk, skb);
  6068. bh_unlock_sock(sk);
  6069. } else if ((cid == L2CAP_CID_A2MP) && enable_hs) {
  6070. BT_DBG("A2MP");
  6071. amp_conn_ind(conn->hcon, skb);
  6072. } else {
  6073. BT_DBG("unknown cid 0x%4.4x", cid);
  6074. kfree_skb(skb);
  6075. }
  6076. break;
  6077. }
  6078. }
  6079. /* ---- L2CAP interface with lower layer (HCI) ---- */
  6080. static int l2cap_connect_ind(struct hci_dev *hdev, bdaddr_t *bdaddr, u8 type)
  6081. {
  6082. int exact = 0, lm1 = 0, lm2 = 0;
  6083. register struct sock *sk;
  6084. struct hlist_node *node;
  6085. if (type != ACL_LINK)
  6086. return 0;
  6087. BT_DBG("hdev %s, bdaddr %s", hdev->name, batostr(bdaddr));
  6088. /* Find listening sockets and check their link_mode */
  6089. read_lock(&l2cap_sk_list.lock);
  6090. sk_for_each(sk, node, &l2cap_sk_list.head) {
  6091. if (sk->sk_state != BT_LISTEN)
  6092. continue;
  6093. if (!bacmp(&bt_sk(sk)->src, &hdev->bdaddr)) {
  6094. lm1 |= HCI_LM_ACCEPT;
  6095. if (l2cap_pi(sk)->role_switch)
  6096. lm1 |= HCI_LM_MASTER;
  6097. exact++;
  6098. } else if (!bacmp(&bt_sk(sk)->src, BDADDR_ANY)) {
  6099. lm2 |= HCI_LM_ACCEPT;
  6100. if (l2cap_pi(sk)->role_switch)
  6101. lm2 |= HCI_LM_MASTER;
  6102. }
  6103. }
  6104. read_unlock(&l2cap_sk_list.lock);
  6105. return exact ? lm1 : lm2;
  6106. }
  6107. static int l2cap_connect_cfm(struct hci_conn *hcon, u8 status)
  6108. {
  6109. struct l2cap_conn *conn;
  6110. BT_DBG("hcon %p bdaddr %s status %d", hcon, batostr(&hcon->dst), status);
  6111. if (!(hcon->type == ACL_LINK || hcon->type == LE_LINK))
  6112. return -EINVAL;
  6113. if (!status) {
  6114. conn = l2cap_conn_add(hcon, status);
  6115. if (conn)
  6116. l2cap_conn_ready(conn);
  6117. } else
  6118. l2cap_conn_del(hcon, bt_err(status), 0);
  6119. return 0;
  6120. }
  6121. static int l2cap_disconn_ind(struct hci_conn *hcon)
  6122. {
  6123. struct l2cap_conn *conn = hcon->l2cap_data;
  6124. BT_DBG("hcon %p", hcon);
  6125. if (hcon->type != ACL_LINK || !conn)
  6126. return 0x13;
  6127. return conn->disc_reason;
  6128. }
  6129. static int l2cap_disconn_cfm(struct hci_conn *hcon, u8 reason, u8 is_process)
  6130. {
  6131. BT_DBG("hcon %p reason %d", hcon, reason);
  6132. if (!(hcon->type == ACL_LINK || hcon->type == LE_LINK))
  6133. return -EINVAL;
  6134. l2cap_conn_del(hcon, bt_err(reason), is_process);
  6135. return 0;
  6136. }
  6137. static inline void l2cap_check_encryption(struct sock *sk, u8 encrypt)
  6138. {
  6139. if (sk->sk_type != SOCK_SEQPACKET && sk->sk_type != SOCK_STREAM)
  6140. return;
  6141. if (encrypt == 0x00) {
  6142. if (l2cap_pi(sk)->sec_level == BT_SECURITY_MEDIUM) {
  6143. l2cap_sock_clear_timer(sk);
  6144. l2cap_sock_set_timer(sk, HZ * 5);
  6145. } else if (l2cap_pi(sk)->sec_level == BT_SECURITY_HIGH ||
  6146. l2cap_pi(sk)->sec_level == BT_SECURITY_VERY_HIGH)
  6147. __l2cap_sock_close(sk, ECONNREFUSED);
  6148. } else {
  6149. if (l2cap_pi(sk)->sec_level == BT_SECURITY_MEDIUM)
  6150. l2cap_sock_clear_timer(sk);
  6151. }
  6152. }
  6153. static int l2cap_security_cfm(struct hci_conn *hcon, u8 status, u8 encrypt)
  6154. {
  6155. struct l2cap_chan_list *l;
  6156. struct l2cap_conn *conn = hcon->l2cap_data;
  6157. struct sock *sk;
  6158. int smp = 0;
  6159. if (!conn)
  6160. return 0;
  6161. l = &conn->chan_list;
  6162. BT_DBG("conn %p", conn);
  6163. read_lock(&l->lock);
  6164. for (sk = l->head; sk; sk = l2cap_pi(sk)->next_c) {
  6165. bh_lock_sock(sk);
  6166. BT_DBG("sk->scid %d", l2cap_pi(sk)->scid);
  6167. if (l2cap_pi(sk)->scid == L2CAP_CID_LE_DATA) {
  6168. if (!status && encrypt) {
  6169. l2cap_pi(sk)->sec_level = hcon->sec_level;
  6170. l2cap_chan_ready(sk);
  6171. }
  6172. smp = 1;
  6173. bh_unlock_sock(sk);
  6174. continue;
  6175. }
  6176. if (l2cap_pi(sk)->conf_state & L2CAP_CONF_CONNECT_PEND) {
  6177. bh_unlock_sock(sk);
  6178. continue;
  6179. }
  6180. if (!status && (sk->sk_state == BT_CONNECTED ||
  6181. sk->sk_state == BT_CONFIG)) {
  6182. l2cap_check_encryption(sk, encrypt);
  6183. bh_unlock_sock(sk);
  6184. continue;
  6185. }
  6186. if (sk->sk_state == BT_CONNECT) {
  6187. if (!status) {
  6188. l2cap_pi(sk)->conf_state |=
  6189. L2CAP_CONF_CONNECT_PEND;
  6190. if ((l2cap_pi(sk)->amp_pref ==
  6191. BT_AMP_POLICY_PREFER_AMP) &&
  6192. enable_hs) {
  6193. amp_create_physical(l2cap_pi(sk)->conn,
  6194. sk);
  6195. } else
  6196. l2cap_send_conn_req(sk);
  6197. } else {
  6198. l2cap_sock_clear_timer(sk);
  6199. l2cap_sock_set_timer(sk, HZ / 10);
  6200. }
  6201. } else if (sk->sk_state == BT_CONNECT2) {
  6202. struct l2cap_conn_rsp rsp;
  6203. __u16 result;
  6204. if (!status) {
  6205. if (l2cap_pi(sk)->amp_id) {
  6206. amp_accept_physical(conn,
  6207. l2cap_pi(sk)->amp_id, sk);
  6208. bh_unlock_sock(sk);
  6209. continue;
  6210. }
  6211. sk->sk_state = BT_CONFIG;
  6212. result = L2CAP_CR_SUCCESS;
  6213. } else {
  6214. sk->sk_state = BT_DISCONN;
  6215. l2cap_sock_set_timer(sk, HZ / 10);
  6216. result = L2CAP_CR_SEC_BLOCK;
  6217. }
  6218. rsp.scid = cpu_to_le16(l2cap_pi(sk)->dcid);
  6219. rsp.dcid = cpu_to_le16(l2cap_pi(sk)->scid);
  6220. rsp.result = cpu_to_le16(result);
  6221. rsp.status = cpu_to_le16(L2CAP_CS_NO_INFO);
  6222. l2cap_send_cmd(conn, l2cap_pi(sk)->ident,
  6223. L2CAP_CONN_RSP, sizeof(rsp), &rsp);
  6224. if (!(l2cap_pi(sk)->conf_state & L2CAP_CONF_REQ_SENT) &&
  6225. result == L2CAP_CR_SUCCESS) {
  6226. char buf[128];
  6227. l2cap_pi(sk)->conf_state |= L2CAP_CONF_REQ_SENT;
  6228. l2cap_send_cmd(conn, l2cap_get_ident(conn),
  6229. L2CAP_CONF_REQ,
  6230. l2cap_build_conf_req(sk, buf, sizeof(buf)),
  6231. buf);
  6232. l2cap_pi(sk)->num_conf_req++;
  6233. }
  6234. }
  6235. bh_unlock_sock(sk);
  6236. }
  6237. read_unlock(&l->lock);
  6238. if (smp) {
  6239. del_timer(&hcon->smp_timer);
  6240. smp_link_encrypt_cmplt(conn, status, encrypt);
  6241. }
  6242. return 0;
  6243. }
  6244. static int l2cap_recv_acldata(struct hci_conn *hcon, struct sk_buff *skb, u16 flags)
  6245. {
  6246. struct l2cap_conn *conn = hcon->l2cap_data;
  6247. if (!conn && hcon->hdev->dev_type != HCI_BREDR)
  6248. goto drop;
  6249. if (!conn)
  6250. conn = l2cap_conn_add(hcon, 0);
  6251. if (!conn)
  6252. goto drop;
  6253. BT_DBG("conn %p len %d flags 0x%x", conn, skb->len, flags);
  6254. if (flags & ACL_START) {
  6255. struct l2cap_hdr *hdr;
  6256. int len;
  6257. if (conn->rx_len) {
  6258. BT_ERR("Unexpected start frame (len %d)", skb->len);
  6259. kfree_skb(conn->rx_skb);
  6260. conn->rx_skb = NULL;
  6261. conn->rx_len = 0;
  6262. l2cap_conn_unreliable(conn, ECOMM);
  6263. }
  6264. /* Start fragment always begin with Basic L2CAP header */
  6265. if (skb->len < L2CAP_HDR_SIZE) {
  6266. BT_ERR("Frame is too short (len %d)", skb->len);
  6267. l2cap_conn_unreliable(conn, ECOMM);
  6268. goto drop;
  6269. }
  6270. hdr = (struct l2cap_hdr *) skb->data;
  6271. len = __le16_to_cpu(hdr->len) + L2CAP_HDR_SIZE;
  6272. if (len == skb->len) {
  6273. /* Complete frame received */
  6274. l2cap_recv_frame(conn, skb);
  6275. return 0;
  6276. }
  6277. if (flags & ACL_CONT) {
  6278. BT_ERR("Complete frame is incomplete "
  6279. "(len %d, expected len %d)",
  6280. skb->len, len);
  6281. l2cap_conn_unreliable(conn, ECOMM);
  6282. goto drop;
  6283. }
  6284. BT_DBG("Start: total len %d, frag len %d", len, skb->len);
  6285. if (skb->len > len) {
  6286. BT_ERR("Frame is too long (len %d, expected len %d)",
  6287. skb->len, len);
  6288. l2cap_conn_unreliable(conn, ECOMM);
  6289. goto drop;
  6290. }
  6291. /* Allocate skb for the complete frame (with header) */
  6292. conn->rx_skb = bt_skb_alloc(len, GFP_ATOMIC);
  6293. if (!conn->rx_skb)
  6294. goto drop;
  6295. skb_copy_from_linear_data(skb, skb_put(conn->rx_skb, skb->len),
  6296. skb->len);
  6297. conn->rx_len = len - skb->len;
  6298. } else {
  6299. BT_DBG("Cont: frag len %d (expecting %d)", skb->len, conn->rx_len);
  6300. if (!conn->rx_len) {
  6301. BT_ERR("Unexpected continuation frame (len %d)", skb->len);
  6302. l2cap_conn_unreliable(conn, ECOMM);
  6303. goto drop;
  6304. }
  6305. if (skb->len > conn->rx_len) {
  6306. BT_ERR("Fragment is too long (len %d, expected %d)",
  6307. skb->len, conn->rx_len);
  6308. kfree_skb(conn->rx_skb);
  6309. conn->rx_skb = NULL;
  6310. conn->rx_len = 0;
  6311. l2cap_conn_unreliable(conn, ECOMM);
  6312. goto drop;
  6313. }
  6314. skb_copy_from_linear_data(skb, skb_put(conn->rx_skb, skb->len),
  6315. skb->len);
  6316. conn->rx_len -= skb->len;
  6317. if (!conn->rx_len) {
  6318. /* Complete frame received */
  6319. l2cap_recv_frame(conn, conn->rx_skb);
  6320. conn->rx_skb = NULL;
  6321. }
  6322. }
  6323. drop:
  6324. kfree_skb(skb);
  6325. return 0;
  6326. }
  6327. static void l2cap_set_acl_flushto(struct hci_conn *hcon, u16 flush_to)
  6328. {
  6329. struct hci_cp_write_automatic_flush_timeout flush_tm;
  6330. if (hcon && hcon->hdev) {
  6331. flush_tm.handle = hcon->handle;
  6332. if (flush_to == L2CAP_DEFAULT_FLUSH_TO)
  6333. flush_to = 0;
  6334. flush_tm.timeout = (flush_to < L2CAP_MAX_FLUSH_TO) ?
  6335. flush_to : L2CAP_MAX_FLUSH_TO;
  6336. hci_send_cmd(hcon->hdev,
  6337. HCI_OP_WRITE_AUTOMATIC_FLUSH_TIMEOUT,
  6338. 4, &(flush_tm));
  6339. }
  6340. }
  6341. static u16 l2cap_get_smallest_flushto(struct l2cap_chan_list *l)
  6342. {
  6343. int ret_flush_to = L2CAP_DEFAULT_FLUSH_TO;
  6344. struct sock *s;
  6345. for (s = l->head; s; s = l2cap_pi(s)->next_c) {
  6346. if (l2cap_pi(s)->flush_to > 0 &&
  6347. l2cap_pi(s)->flush_to < ret_flush_to)
  6348. ret_flush_to = l2cap_pi(s)->flush_to;
  6349. }
  6350. return ret_flush_to;
  6351. }
  6352. static int l2cap_debugfs_show(struct seq_file *f, void *p)
  6353. {
  6354. struct sock *sk;
  6355. struct hlist_node *node;
  6356. read_lock_bh(&l2cap_sk_list.lock);
  6357. sk_for_each(sk, node, &l2cap_sk_list.head) {
  6358. struct l2cap_pinfo *pi = l2cap_pi(sk);
  6359. seq_printf(f, "%s %s %d %d 0x%4.4x 0x%4.4x %d %d %d %d\n",
  6360. batostr(&bt_sk(sk)->src),
  6361. batostr(&bt_sk(sk)->dst),
  6362. sk->sk_state, __le16_to_cpu(pi->psm),
  6363. pi->scid, pi->dcid,
  6364. pi->imtu, pi->omtu, pi->sec_level,
  6365. pi->mode);
  6366. }
  6367. read_unlock_bh(&l2cap_sk_list.lock);
  6368. return 0;
  6369. }
  6370. static void l2cap_queue_acl_data(struct work_struct *worker)
  6371. {
  6372. struct sock *sk = NULL;
  6373. int attempts = 0;
  6374. struct sk_buff *skb_rsp;
  6375. struct l2cap_hdr *lh;
  6376. u8 err_rsp[] = {L2CAP_ATT_ERROR, 0x00, 0x00, 0x00,
  6377. L2CAP_ATT_NOT_SUPPORTED};
  6378. for (attempts = 0; attempts < 40; attempts++) {
  6379. msleep(50);
  6380. if (!att_chn_params.conn) {
  6381. BT_DBG("att_chn_params.conn is NULL");
  6382. return;
  6383. }
  6384. sk = l2cap_find_sock_by_fixed_cid_and_dir
  6385. (att_chn_params.cid,
  6386. att_chn_params.conn->src,
  6387. att_chn_params.conn->dst,
  6388. att_chn_params.dir);
  6389. bh_lock_sock(sk);
  6390. if (sk->sk_state == BT_CONNECTED) {
  6391. sock_queue_rcv_skb(sk, att_chn_params.skb);
  6392. if (sk)
  6393. bh_unlock_sock(sk);
  6394. return;
  6395. }
  6396. bh_unlock_sock(sk);
  6397. }
  6398. bh_lock_sock(sk);
  6399. if (att_chn_params.skb->data[0] != L2CAP_ATT_INDICATE)
  6400. goto not_indicate;
  6401. /* If this is an incoming Indication, we are required to confirm */
  6402. skb_rsp = bt_skb_alloc(sizeof(u8) + L2CAP_HDR_SIZE, GFP_ATOMIC);
  6403. if (!skb_rsp)
  6404. goto free_skb;
  6405. lh = (struct l2cap_hdr *) skb_put(skb_rsp, L2CAP_HDR_SIZE);
  6406. lh->len = cpu_to_le16(sizeof(u8));
  6407. lh->cid = cpu_to_le16(L2CAP_CID_LE_DATA);
  6408. err_rsp[0] = L2CAP_ATT_CONFIRM;
  6409. memcpy(skb_put(skb_rsp, sizeof(u8)), err_rsp, sizeof(u8));
  6410. hci_send_acl(att_chn_params.conn->hcon, NULL, skb_rsp, 0);
  6411. goto free_skb;
  6412. not_indicate:
  6413. if (att_chn_params.skb->data[0] & L2CAP_ATT_RESPONSE_BIT ||
  6414. att_chn_params.skb->data[0] == L2CAP_ATT_CONFIRM)
  6415. goto free_skb;
  6416. /* If this is an incoming PDU that requires a response, respond with
  6417. * a generic error so remote device doesn't hang */
  6418. skb_rsp = bt_skb_alloc(sizeof(err_rsp) + L2CAP_HDR_SIZE, GFP_ATOMIC);
  6419. if (!skb_rsp)
  6420. goto free_skb;
  6421. lh = (struct l2cap_hdr *) skb_put(skb_rsp, L2CAP_HDR_SIZE);
  6422. lh->len = cpu_to_le16(sizeof(err_rsp));
  6423. lh->cid = cpu_to_le16(L2CAP_CID_LE_DATA);
  6424. err_rsp[1] = att_chn_params.skb->data[0];
  6425. memcpy(skb_put(skb_rsp, sizeof(err_rsp)), err_rsp, sizeof(err_rsp));
  6426. hci_send_acl(att_chn_params.conn->hcon, NULL, skb_rsp, 0);
  6427. free_skb:
  6428. kfree_skb(att_chn_params.skb);
  6429. if (sk)
  6430. bh_unlock_sock(sk);
  6431. }
  6432. static int l2cap_debugfs_open(struct inode *inode, struct file *file)
  6433. {
  6434. return single_open(file, l2cap_debugfs_show, inode->i_private);
  6435. }
  6436. static const struct file_operations l2cap_debugfs_fops = {
  6437. .open = l2cap_debugfs_open,
  6438. .read = seq_read,
  6439. .llseek = seq_lseek,
  6440. .release = single_release,
  6441. };
  6442. static struct dentry *l2cap_debugfs;
  6443. static struct hci_proto l2cap_hci_proto = {
  6444. .name = "L2CAP",
  6445. .id = HCI_PROTO_L2CAP,
  6446. .connect_ind = l2cap_connect_ind,
  6447. .connect_cfm = l2cap_connect_cfm,
  6448. .disconn_ind = l2cap_disconn_ind,
  6449. .disconn_cfm = l2cap_disconn_cfm,
  6450. .security_cfm = l2cap_security_cfm,
  6451. .recv_acldata = l2cap_recv_acldata,
  6452. .create_cfm = l2cap_create_cfm,
  6453. .modify_cfm = l2cap_modify_cfm,
  6454. .destroy_cfm = l2cap_destroy_cfm,
  6455. };
  6456. int __init l2cap_init(void)
  6457. {
  6458. int err;
  6459. err = l2cap_init_sockets();
  6460. if (err < 0)
  6461. return err;
  6462. _l2cap_wq = create_singlethread_workqueue("l2cap");
  6463. if (!_l2cap_wq) {
  6464. err = -ENOMEM;
  6465. goto error;
  6466. }
  6467. err = hci_register_proto(&l2cap_hci_proto);
  6468. if (err < 0) {
  6469. BT_ERR("L2CAP protocol registration failed");
  6470. bt_sock_unregister(BTPROTO_L2CAP);
  6471. goto error;
  6472. }
  6473. if (bt_debugfs) {
  6474. l2cap_debugfs = debugfs_create_file("l2cap", 0444,
  6475. bt_debugfs, NULL, &l2cap_debugfs_fops);
  6476. if (!l2cap_debugfs)
  6477. BT_ERR("Failed to create L2CAP debug file");
  6478. }
  6479. if (amp_init() < 0) {
  6480. BT_ERR("AMP Manager initialization failed");
  6481. goto error;
  6482. }
  6483. return 0;
  6484. error:
  6485. destroy_workqueue(_l2cap_wq);
  6486. l2cap_cleanup_sockets();
  6487. return err;
  6488. }
  6489. void l2cap_exit(void)
  6490. {
  6491. amp_exit();
  6492. debugfs_remove(l2cap_debugfs);
  6493. flush_workqueue(_l2cap_wq);
  6494. destroy_workqueue(_l2cap_wq);
  6495. if (hci_unregister_proto(&l2cap_hci_proto) < 0)
  6496. BT_ERR("L2CAP protocol unregistration failed");
  6497. l2cap_cleanup_sockets();
  6498. }
  6499. module_param(disable_ertm, bool, 0644);
  6500. MODULE_PARM_DESC(disable_ertm, "Disable enhanced retransmission mode");
  6501. module_param(enable_hs, bool, 0644);
  6502. MODULE_PARM_DESC(enable_hs, "Enable A2MP protocol");
  6503. module_param(enable_reconfig, bool, 0644);
  6504. MODULE_PARM_DESC(enable_reconfig, "Enable reconfig after initiating AMP move");