l2cap_core.c 179 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053105410551056105710581059106010611062106310641065106610671068106910701071107210731074107510761077107810791080108110821083108410851086108710881089109010911092109310941095109610971098109911001101110211031104110511061107110811091110111111121113111411151116111711181119112011211122112311241125112611271128112911301131113211331134113511361137113811391140114111421143114411451146114711481149115011511152115311541155115611571158115911601161116211631164116511661167116811691170117111721173117411751176117711781179118011811182118311841185118611871188118911901191119211931194119511961197119811991200120112021203120412051206120712081209121012111212121312141215121612171218121912201221122212231224122512261227122812291230123112321233123412351236123712381239124012411242124312441245124612471248124912501251125212531254125512561257125812591260126112621263126412651266126712681269127012711272127312741275127612771278127912801281128212831284128512861287128812891290129112921293129412951296129712981299130013011302130313041305130613071308130913101311131213131314131513161317131813191320132113221323132413251326132713281329133013311332133313341335133613371338133913401341134213431344134513461347134813491350135113521353135413551356135713581359136013611362136313641365136613671368136913701371137213731374137513761377137813791380138113821383138413851386138713881389139013911392139313941395139613971398139914001401140214031404140514061407140814091410141114121413141414151416141714181419142014211422142314241425142614271428142914301431143214331434143514361437143814391440144114421443144414451446144714481449145014511452145314541455145614571458145914601461146214631464146514661467146814691470147114721473147414751476147714781479148014811482148314841485148614871488148914901491149214931494149514961497149814991500150115021503150415051506150715081509151015111512151315141515151615171518151915201521152215231524152515261527152815291530153115321533153415351536153715381539154015411542154315441545154615471548154915501551155215531554155515561557155815591560156115621563156415651566156715681569157015711572157315741575157615771578157915801581158215831584158515861587158815891590159115921593159415951596159715981599160016011602160316041605160616071608160916101611161216131614161516161617161816191620162116221623162416251626162716281629163016311632163316341635163616371638163916401641164216431644164516461647164816491650165116521653165416551656165716581659166016611662166316641665166616671668166916701671167216731674167516761677167816791680168116821683168416851686168716881689169016911692169316941695169616971698169917001701170217031704170517061707170817091710171117121713171417151716171717181719172017211722172317241725172617271728172917301731173217331734173517361737173817391740174117421743174417451746174717481749175017511752175317541755175617571758175917601761176217631764176517661767176817691770177117721773177417751776177717781779178017811782178317841785178617871788178917901791179217931794179517961797179817991800180118021803180418051806180718081809181018111812181318141815181618171818181918201821182218231824182518261827182818291830183118321833183418351836183718381839184018411842184318441845184618471848184918501851185218531854185518561857185818591860186118621863186418651866186718681869187018711872187318741875187618771878187918801881188218831884188518861887188818891890189118921893189418951896189718981899190019011902190319041905190619071908190919101911191219131914191519161917191819191920192119221923192419251926192719281929193019311932193319341935193619371938193919401941194219431944194519461947194819491950195119521953195419551956195719581959196019611962196319641965196619671968196919701971197219731974197519761977197819791980198119821983198419851986198719881989199019911992199319941995199619971998199920002001200220032004200520062007200820092010201120122013201420152016201720182019202020212022202320242025202620272028202920302031203220332034203520362037203820392040204120422043204420452046204720482049205020512052205320542055205620572058205920602061206220632064206520662067206820692070207120722073207420752076207720782079208020812082208320842085208620872088208920902091209220932094209520962097209820992100210121022103210421052106210721082109211021112112211321142115211621172118211921202121212221232124212521262127212821292130213121322133213421352136213721382139214021412142214321442145214621472148214921502151215221532154215521562157215821592160216121622163216421652166216721682169217021712172217321742175217621772178217921802181218221832184218521862187218821892190219121922193219421952196219721982199220022012202220322042205220622072208220922102211221222132214221522162217221822192220222122222223222422252226222722282229223022312232223322342235223622372238223922402241224222432244224522462247224822492250225122522253225422552256225722582259226022612262226322642265226622672268226922702271227222732274227522762277227822792280228122822283228422852286228722882289229022912292229322942295229622972298229923002301230223032304230523062307230823092310231123122313231423152316231723182319232023212322232323242325232623272328232923302331233223332334233523362337233823392340234123422343234423452346234723482349235023512352235323542355235623572358235923602361236223632364236523662367236823692370237123722373237423752376237723782379238023812382238323842385238623872388238923902391239223932394239523962397239823992400240124022403240424052406240724082409241024112412241324142415241624172418241924202421242224232424242524262427242824292430243124322433243424352436243724382439244024412442244324442445244624472448244924502451245224532454245524562457245824592460246124622463246424652466246724682469247024712472247324742475247624772478247924802481248224832484248524862487248824892490249124922493249424952496249724982499250025012502250325042505250625072508250925102511251225132514251525162517251825192520252125222523252425252526252725282529253025312532253325342535253625372538253925402541254225432544254525462547254825492550255125522553255425552556255725582559256025612562256325642565256625672568256925702571257225732574257525762577257825792580258125822583258425852586258725882589259025912592259325942595259625972598259926002601260226032604260526062607260826092610261126122613261426152616261726182619262026212622262326242625262626272628262926302631263226332634263526362637263826392640264126422643264426452646264726482649265026512652265326542655265626572658265926602661266226632664266526662667266826692670267126722673267426752676267726782679268026812682268326842685268626872688268926902691269226932694269526962697269826992700270127022703270427052706270727082709271027112712271327142715271627172718271927202721272227232724272527262727272827292730273127322733273427352736273727382739274027412742274327442745274627472748274927502751275227532754275527562757275827592760276127622763276427652766276727682769277027712772277327742775277627772778277927802781278227832784278527862787278827892790279127922793279427952796279727982799280028012802280328042805280628072808280928102811281228132814281528162817281828192820282128222823282428252826282728282829283028312832283328342835283628372838283928402841284228432844284528462847284828492850285128522853285428552856285728582859286028612862286328642865286628672868286928702871287228732874287528762877287828792880288128822883288428852886288728882889289028912892289328942895289628972898289929002901290229032904290529062907290829092910291129122913291429152916291729182919292029212922292329242925292629272928292929302931293229332934293529362937293829392940294129422943294429452946294729482949295029512952295329542955295629572958295929602961296229632964296529662967296829692970297129722973297429752976297729782979298029812982298329842985298629872988298929902991299229932994299529962997299829993000300130023003300430053006300730083009301030113012301330143015301630173018301930203021302230233024302530263027302830293030303130323033303430353036303730383039304030413042304330443045304630473048304930503051305230533054305530563057305830593060306130623063306430653066306730683069307030713072307330743075307630773078307930803081308230833084308530863087308830893090309130923093309430953096309730983099310031013102310331043105310631073108310931103111311231133114311531163117311831193120312131223123312431253126312731283129313031313132313331343135313631373138313931403141314231433144314531463147314831493150315131523153315431553156315731583159316031613162316331643165316631673168316931703171317231733174317531763177317831793180318131823183318431853186318731883189319031913192319331943195319631973198319932003201320232033204320532063207320832093210321132123213321432153216321732183219322032213222322332243225322632273228322932303231323232333234323532363237323832393240324132423243324432453246324732483249325032513252325332543255325632573258325932603261326232633264326532663267326832693270327132723273327432753276327732783279328032813282328332843285328632873288328932903291329232933294329532963297329832993300330133023303330433053306330733083309331033113312331333143315331633173318331933203321332233233324332533263327332833293330333133323333333433353336333733383339334033413342334333443345334633473348334933503351335233533354335533563357335833593360336133623363336433653366336733683369337033713372337333743375337633773378337933803381338233833384338533863387338833893390339133923393339433953396339733983399340034013402340334043405340634073408340934103411341234133414341534163417341834193420342134223423342434253426342734283429343034313432343334343435343634373438343934403441344234433444344534463447344834493450345134523453345434553456345734583459346034613462346334643465346634673468346934703471347234733474347534763477347834793480348134823483348434853486348734883489349034913492349334943495349634973498349935003501350235033504350535063507350835093510351135123513351435153516351735183519352035213522352335243525352635273528352935303531353235333534353535363537353835393540354135423543354435453546354735483549355035513552355335543555355635573558355935603561356235633564356535663567356835693570357135723573357435753576357735783579358035813582358335843585358635873588358935903591359235933594359535963597359835993600360136023603360436053606360736083609361036113612361336143615361636173618361936203621362236233624362536263627362836293630363136323633363436353636363736383639364036413642364336443645364636473648364936503651365236533654365536563657365836593660366136623663366436653666366736683669367036713672367336743675367636773678367936803681368236833684368536863687368836893690369136923693369436953696369736983699370037013702370337043705370637073708370937103711371237133714371537163717371837193720372137223723372437253726372737283729373037313732373337343735373637373738373937403741374237433744374537463747374837493750375137523753375437553756375737583759376037613762376337643765376637673768376937703771377237733774377537763777377837793780378137823783378437853786378737883789379037913792379337943795379637973798379938003801380238033804380538063807380838093810381138123813381438153816381738183819382038213822382338243825382638273828382938303831383238333834383538363837383838393840384138423843384438453846384738483849385038513852385338543855385638573858385938603861386238633864386538663867386838693870387138723873387438753876387738783879388038813882388338843885388638873888388938903891389238933894389538963897389838993900390139023903390439053906390739083909391039113912391339143915391639173918391939203921392239233924392539263927392839293930393139323933393439353936393739383939394039413942394339443945394639473948394939503951395239533954395539563957395839593960396139623963396439653966396739683969397039713972397339743975397639773978397939803981398239833984398539863987398839893990399139923993399439953996399739983999400040014002400340044005400640074008400940104011401240134014401540164017401840194020402140224023402440254026402740284029403040314032403340344035403640374038403940404041404240434044404540464047404840494050405140524053405440554056405740584059406040614062406340644065406640674068406940704071407240734074407540764077407840794080408140824083408440854086408740884089409040914092409340944095409640974098409941004101410241034104410541064107410841094110411141124113411441154116411741184119412041214122412341244125412641274128412941304131413241334134413541364137413841394140414141424143414441454146414741484149415041514152415341544155415641574158415941604161416241634164416541664167416841694170417141724173417441754176417741784179418041814182418341844185418641874188418941904191419241934194419541964197419841994200420142024203420442054206420742084209421042114212421342144215421642174218421942204221422242234224422542264227422842294230423142324233423442354236423742384239424042414242424342444245424642474248424942504251425242534254425542564257425842594260426142624263426442654266426742684269427042714272427342744275427642774278427942804281428242834284428542864287428842894290429142924293429442954296429742984299430043014302430343044305430643074308430943104311431243134314431543164317431843194320432143224323432443254326432743284329433043314332433343344335433643374338433943404341434243434344434543464347434843494350435143524353435443554356435743584359436043614362436343644365436643674368436943704371437243734374437543764377437843794380438143824383438443854386438743884389439043914392439343944395439643974398439944004401440244034404440544064407440844094410441144124413441444154416441744184419442044214422442344244425442644274428442944304431443244334434443544364437443844394440444144424443444444454446444744484449445044514452445344544455445644574458445944604461446244634464446544664467446844694470447144724473447444754476447744784479448044814482448344844485448644874488448944904491449244934494449544964497449844994500450145024503450445054506450745084509451045114512451345144515451645174518451945204521452245234524452545264527452845294530453145324533453445354536453745384539454045414542454345444545454645474548454945504551455245534554455545564557455845594560456145624563456445654566456745684569457045714572457345744575457645774578457945804581458245834584458545864587458845894590459145924593459445954596459745984599460046014602460346044605460646074608460946104611461246134614461546164617461846194620462146224623462446254626462746284629463046314632463346344635463646374638463946404641464246434644464546464647464846494650465146524653465446554656465746584659466046614662466346644665466646674668466946704671467246734674467546764677467846794680468146824683468446854686468746884689469046914692469346944695469646974698469947004701470247034704470547064707470847094710471147124713471447154716471747184719472047214722472347244725472647274728472947304731473247334734473547364737473847394740474147424743474447454746474747484749475047514752475347544755475647574758475947604761476247634764476547664767476847694770477147724773477447754776477747784779478047814782478347844785478647874788478947904791479247934794479547964797479847994800480148024803480448054806480748084809481048114812481348144815481648174818481948204821482248234824482548264827482848294830483148324833483448354836483748384839484048414842484348444845484648474848484948504851485248534854485548564857485848594860486148624863486448654866486748684869487048714872487348744875487648774878487948804881488248834884488548864887488848894890489148924893489448954896489748984899490049014902490349044905490649074908490949104911491249134914491549164917491849194920492149224923492449254926492749284929493049314932493349344935493649374938493949404941494249434944494549464947494849494950495149524953495449554956495749584959496049614962496349644965496649674968496949704971497249734974497549764977497849794980498149824983498449854986498749884989499049914992499349944995499649974998499950005001500250035004500550065007500850095010501150125013501450155016501750185019502050215022502350245025502650275028502950305031503250335034503550365037503850395040504150425043504450455046504750485049505050515052505350545055505650575058505950605061506250635064506550665067506850695070507150725073507450755076507750785079508050815082508350845085508650875088508950905091509250935094509550965097509850995100510151025103510451055106510751085109511051115112511351145115511651175118511951205121512251235124512551265127512851295130513151325133513451355136513751385139514051415142514351445145514651475148514951505151515251535154515551565157515851595160516151625163516451655166516751685169517051715172517351745175517651775178517951805181518251835184518551865187518851895190519151925193519451955196519751985199520052015202520352045205520652075208520952105211521252135214521552165217521852195220522152225223522452255226522752285229523052315232523352345235523652375238523952405241524252435244524552465247524852495250525152525253525452555256525752585259526052615262526352645265526652675268526952705271527252735274527552765277527852795280528152825283528452855286528752885289529052915292529352945295529652975298529953005301530253035304530553065307530853095310531153125313531453155316531753185319532053215322532353245325532653275328532953305331533253335334533553365337533853395340534153425343534453455346534753485349535053515352535353545355535653575358535953605361536253635364536553665367536853695370537153725373537453755376537753785379538053815382538353845385538653875388538953905391539253935394539553965397539853995400540154025403540454055406540754085409541054115412541354145415541654175418541954205421542254235424542554265427542854295430543154325433543454355436543754385439544054415442544354445445544654475448544954505451545254535454545554565457545854595460546154625463546454655466546754685469547054715472547354745475547654775478547954805481548254835484548554865487548854895490549154925493549454955496549754985499550055015502550355045505550655075508550955105511551255135514551555165517551855195520552155225523552455255526552755285529553055315532553355345535553655375538553955405541554255435544554555465547554855495550555155525553555455555556555755585559556055615562556355645565556655675568556955705571557255735574557555765577557855795580558155825583558455855586558755885589559055915592559355945595559655975598559956005601560256035604560556065607560856095610561156125613561456155616561756185619562056215622562356245625562656275628562956305631563256335634563556365637563856395640564156425643564456455646564756485649565056515652565356545655565656575658565956605661566256635664566556665667566856695670567156725673567456755676567756785679568056815682568356845685568656875688568956905691569256935694569556965697569856995700570157025703570457055706570757085709571057115712571357145715571657175718571957205721572257235724572557265727572857295730573157325733573457355736573757385739574057415742574357445745574657475748574957505751575257535754575557565757575857595760576157625763576457655766576757685769577057715772577357745775577657775778577957805781578257835784578557865787578857895790579157925793579457955796579757985799580058015802580358045805580658075808580958105811581258135814581558165817581858195820582158225823582458255826582758285829583058315832583358345835583658375838583958405841584258435844584558465847584858495850585158525853585458555856585758585859586058615862586358645865586658675868586958705871587258735874587558765877587858795880588158825883588458855886588758885889589058915892589358945895589658975898589959005901590259035904590559065907590859095910591159125913591459155916591759185919592059215922592359245925592659275928592959305931593259335934593559365937593859395940594159425943594459455946594759485949595059515952595359545955595659575958595959605961596259635964596559665967596859695970597159725973597459755976597759785979598059815982598359845985598659875988598959905991599259935994599559965997599859996000600160026003600460056006600760086009601060116012601360146015601660176018601960206021602260236024602560266027602860296030603160326033603460356036603760386039604060416042604360446045604660476048604960506051605260536054605560566057605860596060606160626063606460656066606760686069607060716072607360746075607660776078607960806081608260836084608560866087608860896090609160926093609460956096609760986099610061016102610361046105610661076108610961106111611261136114611561166117611861196120612161226123612461256126612761286129613061316132613361346135613661376138613961406141614261436144614561466147614861496150615161526153615461556156615761586159616061616162616361646165616661676168616961706171617261736174617561766177617861796180618161826183618461856186618761886189619061916192619361946195619661976198619962006201620262036204620562066207620862096210621162126213621462156216621762186219622062216222622362246225622662276228622962306231623262336234623562366237623862396240624162426243624462456246624762486249625062516252625362546255625662576258625962606261626262636264626562666267626862696270627162726273627462756276627762786279628062816282628362846285628662876288628962906291629262936294629562966297629862996300630163026303630463056306630763086309631063116312631363146315631663176318631963206321632263236324632563266327632863296330633163326333633463356336633763386339634063416342634363446345634663476348634963506351635263536354635563566357635863596360636163626363636463656366636763686369637063716372637363746375637663776378637963806381638263836384638563866387638863896390639163926393639463956396639763986399640064016402640364046405640664076408640964106411641264136414641564166417641864196420642164226423642464256426642764286429643064316432643364346435643664376438643964406441644264436444644564466447644864496450645164526453645464556456645764586459646064616462646364646465646664676468646964706471647264736474647564766477647864796480648164826483648464856486648764886489649064916492649364946495649664976498649965006501650265036504650565066507650865096510651165126513651465156516651765186519652065216522652365246525652665276528652965306531653265336534653565366537653865396540654165426543654465456546654765486549655065516552655365546555655665576558655965606561656265636564656565666567656865696570657165726573657465756576657765786579658065816582658365846585658665876588658965906591659265936594659565966597659865996600660166026603660466056606660766086609661066116612661366146615661666176618661966206621662266236624662566266627662866296630663166326633663466356636663766386639664066416642664366446645664666476648664966506651665266536654665566566657665866596660666166626663666466656666666766686669667066716672667366746675667666776678667966806681668266836684668566866687668866896690669166926693669466956696669766986699670067016702670367046705670667076708670967106711671267136714671567166717671867196720672167226723672467256726672767286729673067316732673367346735673667376738673967406741674267436744674567466747674867496750675167526753675467556756675767586759676067616762676367646765676667676768676967706771677267736774677567766777677867796780678167826783678467856786678767886789679067916792679367946795679667976798679968006801680268036804680568066807680868096810681168126813681468156816681768186819682068216822682368246825682668276828682968306831683268336834683568366837683868396840684168426843684468456846684768486849685068516852685368546855685668576858685968606861686268636864686568666867686868696870687168726873687468756876687768786879688068816882688368846885688668876888688968906891689268936894689568966897689868996900690169026903690469056906690769086909691069116912691369146915691669176918691969206921692269236924692569266927692869296930693169326933693469356936693769386939694069416942694369446945694669476948694969506951695269536954695569566957695869596960696169626963696469656966696769686969697069716972697369746975697669776978697969806981698269836984698569866987698869896990699169926993699469956996699769986999700070017002700370047005700670077008700970107011701270137014701570167017701870197020702170227023702470257026702770287029703070317032703370347035703670377038703970407041704270437044704570467047704870497050705170527053705470557056705770587059706070617062706370647065706670677068706970707071707270737074707570767077707870797080708170827083708470857086708770887089709070917092709370947095709670977098709971007101710271037104710571067107710871097110711171127113711471157116711771187119712071217122712371247125712671277128712971307131713271337134713571367137713871397140714171427143714471457146714771487149715071517152715371547155715671577158715971607161716271637164716571667167716871697170717171727173717471757176717771787179718071817182718371847185718671877188718971907191719271937194719571967197719871997200720172027203720472057206720772087209721072117212721372147215721672177218721972207221722272237224722572267227722872297230723172327233723472357236723772387239724072417242724372447245724672477248724972507251725272537254725572567257725872597260726172627263726472657266726772687269727072717272727372747275727672777278727972807281728272837284728572867287728872897290729172927293729472957296729772987299730073017302730373047305730673077308730973107311731273137314731573167317731873197320732173227323732473257326732773287329733073317332733373347335733673377338733973407341734273437344734573467347734873497350735173527353735473557356735773587359736073617362736373647365736673677368736973707371737273737374737573767377737873797380738173827383738473857386738773887389739073917392739373947395739673977398739974007401740274037404740574067407740874097410741174127413741474157416741774187419742074217422742374247425742674277428742974307431743274337434743574367437743874397440744174427443744474457446744774487449745074517452745374547455745674577458745974607461746274637464746574667467746874697470747174727473747474757476747774787479748074817482748374847485748674877488748974907491749274937494749574967497749874997500750175027503750475057506750775087509751075117512751375147515751675177518751975207521752275237524752575267527752875297530753175327533753475357536753775387539754075417542754375447545754675477548754975507551755275537554755575567557755875597560756175627563756475657566756775687569757075717572757375747575757675777578757975807581758275837584758575867587758875897590759175927593759475957596759775987599760076017602760376047605760676077608760976107611761276137614761576167617761876197620762176227623762476257626762776287629763076317632763376347635763676377638763976407641764276437644764576467647764876497650765176527653765476557656765776587659766076617662
  1. /*
  2. BlueZ - Bluetooth protocol stack for Linux
  3. Copyright (C) 2000-2001 Qualcomm Incorporated
  4. Copyright (C) 2009-2010 Gustavo F. Padovan <gustavo@padovan.org>
  5. Copyright (C) 2010 Google Inc.
  6. Copyright (C) 2011 ProFUSION Embedded Systems
  7. Copyright (c) 2012 Code Aurora Forum. All rights reserved.
  8. Written 2000,2001 by Maxim Krasnyansky <maxk@qualcomm.com>
  9. This program is free software; you can redistribute it and/or modify
  10. it under the terms of the GNU General Public License version 2 as
  11. published by the Free Software Foundation;
  12. THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS
  13. OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
  14. FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT OF THIRD PARTY RIGHTS.
  15. IN NO EVENT SHALL THE COPYRIGHT HOLDER(S) AND AUTHOR(S) BE LIABLE FOR ANY
  16. CLAIM, OR ANY SPECIAL INDIRECT OR CONSEQUENTIAL DAMAGES, OR ANY DAMAGES
  17. WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
  18. ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
  19. OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
  20. ALL LIABILITY, INCLUDING LIABILITY FOR INFRINGEMENT OF ANY PATENTS,
  21. COPYRIGHTS, TRADEMARKS OR OTHER RIGHTS, RELATING TO USE OF THIS
  22. SOFTWARE IS DISCLAIMED.
  23. */
  24. /* Bluetooth L2CAP core. */
  25. #include <linux/module.h>
  26. #include <linux/debugfs.h>
  27. #include <linux/crc16.h>
  28. #include <net/bluetooth/bluetooth.h>
  29. #include <net/bluetooth/hci_core.h>
  30. #include <net/bluetooth/l2cap.h>
  31. #include "smp.h"
  32. #include "a2mp.h"
  33. #include "amp.h"
  34. #define LE_FLOWCTL_MAX_CREDITS 65535
  35. bool disable_ertm;
  36. static u32 l2cap_feat_mask = L2CAP_FEAT_FIXED_CHAN | L2CAP_FEAT_UCD;
  37. static LIST_HEAD(chan_list);
  38. static DEFINE_RWLOCK(chan_list_lock);
  39. static u16 le_max_credits = L2CAP_LE_MAX_CREDITS;
  40. static u16 le_default_mps = L2CAP_LE_DEFAULT_MPS;
  41. static struct sk_buff *l2cap_build_cmd(struct l2cap_conn *conn,
  42. u8 code, u8 ident, u16 dlen, void *data);
  43. static void l2cap_send_cmd(struct l2cap_conn *conn, u8 ident, u8 code, u16 len,
  44. void *data);
  45. static int l2cap_build_conf_req(struct l2cap_chan *chan, void *data, size_t data_size);
  46. static void l2cap_send_disconn_req(struct l2cap_chan *chan, int err);
  47. static void l2cap_tx(struct l2cap_chan *chan, struct l2cap_ctrl *control,
  48. struct sk_buff_head *skbs, u8 event);
  49. static inline u8 bdaddr_type(u8 link_type, u8 bdaddr_type)
  50. {
  51. if (link_type == LE_LINK) {
  52. if (bdaddr_type == ADDR_LE_DEV_PUBLIC)
  53. return BDADDR_LE_PUBLIC;
  54. else
  55. return BDADDR_LE_RANDOM;
  56. }
  57. return BDADDR_BREDR;
  58. }
  59. static inline u8 bdaddr_src_type(struct hci_conn *hcon)
  60. {
  61. return bdaddr_type(hcon->type, hcon->src_type);
  62. }
  63. static inline u8 bdaddr_dst_type(struct hci_conn *hcon)
  64. {
  65. return bdaddr_type(hcon->type, hcon->dst_type);
  66. }
  67. /* ---- L2CAP channels ---- */
  68. static struct l2cap_chan *__l2cap_get_chan_by_dcid(struct l2cap_conn *conn,
  69. u16 cid)
  70. {
  71. struct l2cap_chan *c;
  72. list_for_each_entry(c, &conn->chan_l, list) {
  73. if (c->dcid == cid)
  74. return c;
  75. }
  76. return NULL;
  77. }
  78. static struct l2cap_chan *__l2cap_get_chan_by_scid(struct l2cap_conn *conn,
  79. u16 cid)
  80. {
  81. struct l2cap_chan *c;
  82. list_for_each_entry(c, &conn->chan_l, list) {
  83. if (c->scid == cid)
  84. return c;
  85. }
  86. return NULL;
  87. }
  88. /* Find channel with given SCID.
  89. * Returns locked channel. */
  90. static struct l2cap_chan *l2cap_get_chan_by_scid(struct l2cap_conn *conn,
  91. u16 cid)
  92. {
  93. struct l2cap_chan *c;
  94. mutex_lock(&conn->chan_lock);
  95. c = __l2cap_get_chan_by_scid(conn, cid);
  96. if (c)
  97. l2cap_chan_lock(c);
  98. mutex_unlock(&conn->chan_lock);
  99. return c;
  100. }
  101. /* Find channel with given DCID.
  102. * Returns locked channel.
  103. */
  104. static struct l2cap_chan *l2cap_get_chan_by_dcid(struct l2cap_conn *conn,
  105. u16 cid)
  106. {
  107. struct l2cap_chan *c;
  108. mutex_lock(&conn->chan_lock);
  109. c = __l2cap_get_chan_by_dcid(conn, cid);
  110. if (c)
  111. l2cap_chan_lock(c);
  112. mutex_unlock(&conn->chan_lock);
  113. return c;
  114. }
  115. static struct l2cap_chan *__l2cap_get_chan_by_ident(struct l2cap_conn *conn,
  116. u8 ident)
  117. {
  118. struct l2cap_chan *c;
  119. list_for_each_entry(c, &conn->chan_l, list) {
  120. if (c->ident == ident)
  121. return c;
  122. }
  123. return NULL;
  124. }
  125. static struct l2cap_chan *l2cap_get_chan_by_ident(struct l2cap_conn *conn,
  126. u8 ident)
  127. {
  128. struct l2cap_chan *c;
  129. mutex_lock(&conn->chan_lock);
  130. c = __l2cap_get_chan_by_ident(conn, ident);
  131. if (c)
  132. l2cap_chan_lock(c);
  133. mutex_unlock(&conn->chan_lock);
  134. return c;
  135. }
  136. static struct l2cap_chan *__l2cap_global_chan_by_addr(__le16 psm, bdaddr_t *src)
  137. {
  138. struct l2cap_chan *c;
  139. list_for_each_entry(c, &chan_list, global_l) {
  140. if (c->sport == psm && !bacmp(&c->src, src))
  141. return c;
  142. }
  143. return NULL;
  144. }
  145. int l2cap_add_psm(struct l2cap_chan *chan, bdaddr_t *src, __le16 psm)
  146. {
  147. int err;
  148. write_lock(&chan_list_lock);
  149. if (psm && __l2cap_global_chan_by_addr(psm, src)) {
  150. err = -EADDRINUSE;
  151. goto done;
  152. }
  153. if (psm) {
  154. chan->psm = psm;
  155. chan->sport = psm;
  156. err = 0;
  157. } else {
  158. u16 p;
  159. err = -EINVAL;
  160. for (p = 0x1001; p < 0x1100; p += 2)
  161. if (!__l2cap_global_chan_by_addr(cpu_to_le16(p), src)) {
  162. chan->psm = cpu_to_le16(p);
  163. chan->sport = cpu_to_le16(p);
  164. err = 0;
  165. break;
  166. }
  167. }
  168. done:
  169. write_unlock(&chan_list_lock);
  170. return err;
  171. }
  172. EXPORT_SYMBOL_GPL(l2cap_add_psm);
  173. int l2cap_add_scid(struct l2cap_chan *chan, __u16 scid)
  174. {
  175. write_lock(&chan_list_lock);
  176. /* Override the defaults (which are for conn-oriented) */
  177. chan->omtu = L2CAP_DEFAULT_MTU;
  178. chan->chan_type = L2CAP_CHAN_FIXED;
  179. chan->scid = scid;
  180. write_unlock(&chan_list_lock);
  181. return 0;
  182. }
  183. static u16 l2cap_alloc_cid(struct l2cap_conn *conn)
  184. {
  185. u16 cid, dyn_end;
  186. if (conn->hcon->type == LE_LINK)
  187. dyn_end = L2CAP_CID_LE_DYN_END;
  188. else
  189. dyn_end = L2CAP_CID_DYN_END;
  190. for (cid = L2CAP_CID_DYN_START; cid <= dyn_end; cid++) {
  191. if (!__l2cap_get_chan_by_scid(conn, cid))
  192. return cid;
  193. }
  194. return 0;
  195. }
  196. static void l2cap_state_change(struct l2cap_chan *chan, int state)
  197. {
  198. BT_DBG("chan %p %s -> %s", chan, state_to_string(chan->state),
  199. state_to_string(state));
  200. chan->state = state;
  201. chan->ops->state_change(chan, state, 0);
  202. }
  203. static inline void l2cap_state_change_and_error(struct l2cap_chan *chan,
  204. int state, int err)
  205. {
  206. chan->state = state;
  207. chan->ops->state_change(chan, chan->state, err);
  208. }
  209. static inline void l2cap_chan_set_err(struct l2cap_chan *chan, int err)
  210. {
  211. chan->ops->state_change(chan, chan->state, err);
  212. }
  213. static void __set_retrans_timer(struct l2cap_chan *chan)
  214. {
  215. if (!delayed_work_pending(&chan->monitor_timer) &&
  216. chan->retrans_timeout) {
  217. l2cap_set_timer(chan, &chan->retrans_timer,
  218. msecs_to_jiffies(chan->retrans_timeout));
  219. }
  220. }
  221. static void __set_monitor_timer(struct l2cap_chan *chan)
  222. {
  223. __clear_retrans_timer(chan);
  224. if (chan->monitor_timeout) {
  225. l2cap_set_timer(chan, &chan->monitor_timer,
  226. msecs_to_jiffies(chan->monitor_timeout));
  227. }
  228. }
  229. static struct sk_buff *l2cap_ertm_seq_in_queue(struct sk_buff_head *head,
  230. u16 seq)
  231. {
  232. struct sk_buff *skb;
  233. skb_queue_walk(head, skb) {
  234. if (bt_cb(skb)->l2cap.txseq == seq)
  235. return skb;
  236. }
  237. return NULL;
  238. }
  239. /* ---- L2CAP sequence number lists ---- */
  240. /* For ERTM, ordered lists of sequence numbers must be tracked for
  241. * SREJ requests that are received and for frames that are to be
  242. * retransmitted. These seq_list functions implement a singly-linked
  243. * list in an array, where membership in the list can also be checked
  244. * in constant time. Items can also be added to the tail of the list
  245. * and removed from the head in constant time, without further memory
  246. * allocs or frees.
  247. */
  248. static int l2cap_seq_list_init(struct l2cap_seq_list *seq_list, u16 size)
  249. {
  250. size_t alloc_size, i;
  251. /* Allocated size is a power of 2 to map sequence numbers
  252. * (which may be up to 14 bits) in to a smaller array that is
  253. * sized for the negotiated ERTM transmit windows.
  254. */
  255. alloc_size = roundup_pow_of_two(size);
  256. seq_list->list = kmalloc(sizeof(u16) * alloc_size, GFP_KERNEL);
  257. if (!seq_list->list)
  258. return -ENOMEM;
  259. seq_list->mask = alloc_size - 1;
  260. seq_list->head = L2CAP_SEQ_LIST_CLEAR;
  261. seq_list->tail = L2CAP_SEQ_LIST_CLEAR;
  262. for (i = 0; i < alloc_size; i++)
  263. seq_list->list[i] = L2CAP_SEQ_LIST_CLEAR;
  264. return 0;
  265. }
  266. static inline void l2cap_seq_list_free(struct l2cap_seq_list *seq_list)
  267. {
  268. kfree(seq_list->list);
  269. }
  270. static inline bool l2cap_seq_list_contains(struct l2cap_seq_list *seq_list,
  271. u16 seq)
  272. {
  273. /* Constant-time check for list membership */
  274. return seq_list->list[seq & seq_list->mask] != L2CAP_SEQ_LIST_CLEAR;
  275. }
  276. static inline u16 l2cap_seq_list_pop(struct l2cap_seq_list *seq_list)
  277. {
  278. u16 seq = seq_list->head;
  279. u16 mask = seq_list->mask;
  280. seq_list->head = seq_list->list[seq & mask];
  281. seq_list->list[seq & mask] = L2CAP_SEQ_LIST_CLEAR;
  282. if (seq_list->head == L2CAP_SEQ_LIST_TAIL) {
  283. seq_list->head = L2CAP_SEQ_LIST_CLEAR;
  284. seq_list->tail = L2CAP_SEQ_LIST_CLEAR;
  285. }
  286. return seq;
  287. }
  288. static void l2cap_seq_list_clear(struct l2cap_seq_list *seq_list)
  289. {
  290. u16 i;
  291. if (seq_list->head == L2CAP_SEQ_LIST_CLEAR)
  292. return;
  293. for (i = 0; i <= seq_list->mask; i++)
  294. seq_list->list[i] = L2CAP_SEQ_LIST_CLEAR;
  295. seq_list->head = L2CAP_SEQ_LIST_CLEAR;
  296. seq_list->tail = L2CAP_SEQ_LIST_CLEAR;
  297. }
  298. static void l2cap_seq_list_append(struct l2cap_seq_list *seq_list, u16 seq)
  299. {
  300. u16 mask = seq_list->mask;
  301. /* All appends happen in constant time */
  302. if (seq_list->list[seq & mask] != L2CAP_SEQ_LIST_CLEAR)
  303. return;
  304. if (seq_list->tail == L2CAP_SEQ_LIST_CLEAR)
  305. seq_list->head = seq;
  306. else
  307. seq_list->list[seq_list->tail & mask] = seq;
  308. seq_list->tail = seq;
  309. seq_list->list[seq & mask] = L2CAP_SEQ_LIST_TAIL;
  310. }
  311. static void l2cap_chan_timeout(struct work_struct *work)
  312. {
  313. struct l2cap_chan *chan = container_of(work, struct l2cap_chan,
  314. chan_timer.work);
  315. struct l2cap_conn *conn = chan->conn;
  316. int reason;
  317. BT_DBG("chan %p state %s", chan, state_to_string(chan->state));
  318. mutex_lock(&conn->chan_lock);
  319. l2cap_chan_lock(chan);
  320. if (chan->state == BT_CONNECTED || chan->state == BT_CONFIG)
  321. reason = ECONNREFUSED;
  322. else if (chan->state == BT_CONNECT &&
  323. chan->sec_level != BT_SECURITY_SDP)
  324. reason = ECONNREFUSED;
  325. else
  326. reason = ETIMEDOUT;
  327. l2cap_chan_close(chan, reason);
  328. l2cap_chan_unlock(chan);
  329. chan->ops->close(chan);
  330. mutex_unlock(&conn->chan_lock);
  331. l2cap_chan_put(chan);
  332. }
  333. struct l2cap_chan *l2cap_chan_create(void)
  334. {
  335. struct l2cap_chan *chan;
  336. chan = kzalloc(sizeof(*chan), GFP_ATOMIC);
  337. if (!chan)
  338. return NULL;
  339. mutex_init(&chan->lock);
  340. /* Set default lock nesting level */
  341. atomic_set(&chan->nesting, L2CAP_NESTING_NORMAL);
  342. write_lock(&chan_list_lock);
  343. list_add(&chan->global_l, &chan_list);
  344. write_unlock(&chan_list_lock);
  345. INIT_DELAYED_WORK(&chan->chan_timer, l2cap_chan_timeout);
  346. chan->state = BT_OPEN;
  347. kref_init(&chan->kref);
  348. /* This flag is cleared in l2cap_chan_ready() */
  349. set_bit(CONF_NOT_COMPLETE, &chan->conf_state);
  350. BT_DBG("chan %p", chan);
  351. return chan;
  352. }
  353. EXPORT_SYMBOL_GPL(l2cap_chan_create);
  354. static void l2cap_chan_destroy(struct kref *kref)
  355. {
  356. struct l2cap_chan *chan = container_of(kref, struct l2cap_chan, kref);
  357. BT_DBG("chan %p", chan);
  358. write_lock(&chan_list_lock);
  359. list_del(&chan->global_l);
  360. write_unlock(&chan_list_lock);
  361. kfree(chan);
  362. }
  363. void l2cap_chan_hold(struct l2cap_chan *c)
  364. {
  365. BT_DBG("chan %p orig refcnt %d", c, atomic_read(&c->kref.refcount));
  366. kref_get(&c->kref);
  367. }
  368. void l2cap_chan_put(struct l2cap_chan *c)
  369. {
  370. BT_DBG("chan %p orig refcnt %d", c, atomic_read(&c->kref.refcount));
  371. kref_put(&c->kref, l2cap_chan_destroy);
  372. }
  373. EXPORT_SYMBOL_GPL(l2cap_chan_put);
  374. void l2cap_chan_set_defaults(struct l2cap_chan *chan)
  375. {
  376. chan->fcs = L2CAP_FCS_CRC16;
  377. chan->max_tx = L2CAP_DEFAULT_MAX_TX;
  378. chan->tx_win = L2CAP_DEFAULT_TX_WINDOW;
  379. chan->tx_win_max = L2CAP_DEFAULT_TX_WINDOW;
  380. chan->remote_max_tx = chan->max_tx;
  381. chan->remote_tx_win = chan->tx_win;
  382. chan->ack_win = L2CAP_DEFAULT_TX_WINDOW;
  383. chan->sec_level = BT_SECURITY_LOW;
  384. chan->flush_to = L2CAP_DEFAULT_FLUSH_TO;
  385. chan->retrans_timeout = L2CAP_DEFAULT_RETRANS_TO;
  386. chan->monitor_timeout = L2CAP_DEFAULT_MONITOR_TO;
  387. chan->conf_state = 0;
  388. set_bit(FLAG_FORCE_ACTIVE, &chan->flags);
  389. }
  390. EXPORT_SYMBOL_GPL(l2cap_chan_set_defaults);
  391. static void l2cap_le_flowctl_init(struct l2cap_chan *chan)
  392. {
  393. chan->sdu = NULL;
  394. chan->sdu_last_frag = NULL;
  395. chan->sdu_len = 0;
  396. chan->tx_credits = 0;
  397. chan->rx_credits = le_max_credits;
  398. chan->mps = min_t(u16, chan->imtu, le_default_mps);
  399. skb_queue_head_init(&chan->tx_q);
  400. }
  401. void __l2cap_chan_add(struct l2cap_conn *conn, struct l2cap_chan *chan)
  402. {
  403. BT_DBG("conn %p, psm 0x%2.2x, dcid 0x%4.4x", conn,
  404. __le16_to_cpu(chan->psm), chan->dcid);
  405. conn->disc_reason = HCI_ERROR_REMOTE_USER_TERM;
  406. chan->conn = conn;
  407. switch (chan->chan_type) {
  408. case L2CAP_CHAN_CONN_ORIENTED:
  409. /* Alloc CID for connection-oriented socket */
  410. chan->scid = l2cap_alloc_cid(conn);
  411. if (conn->hcon->type == ACL_LINK)
  412. chan->omtu = L2CAP_DEFAULT_MTU;
  413. break;
  414. case L2CAP_CHAN_CONN_LESS:
  415. /* Connectionless socket */
  416. chan->scid = L2CAP_CID_CONN_LESS;
  417. chan->dcid = L2CAP_CID_CONN_LESS;
  418. chan->omtu = L2CAP_DEFAULT_MTU;
  419. break;
  420. case L2CAP_CHAN_FIXED:
  421. /* Caller will set CID and CID specific MTU values */
  422. break;
  423. default:
  424. /* Raw socket can send/recv signalling messages only */
  425. chan->scid = L2CAP_CID_SIGNALING;
  426. chan->dcid = L2CAP_CID_SIGNALING;
  427. chan->omtu = L2CAP_DEFAULT_MTU;
  428. }
  429. chan->local_id = L2CAP_BESTEFFORT_ID;
  430. chan->local_stype = L2CAP_SERV_BESTEFFORT;
  431. chan->local_msdu = L2CAP_DEFAULT_MAX_SDU_SIZE;
  432. chan->local_sdu_itime = L2CAP_DEFAULT_SDU_ITIME;
  433. chan->local_acc_lat = L2CAP_DEFAULT_ACC_LAT;
  434. chan->local_flush_to = L2CAP_EFS_DEFAULT_FLUSH_TO;
  435. l2cap_chan_hold(chan);
  436. /* Only keep a reference for fixed channels if they requested it */
  437. if (chan->chan_type != L2CAP_CHAN_FIXED ||
  438. test_bit(FLAG_HOLD_HCI_CONN, &chan->flags))
  439. hci_conn_hold(conn->hcon);
  440. list_add(&chan->list, &conn->chan_l);
  441. }
  442. void l2cap_chan_add(struct l2cap_conn *conn, struct l2cap_chan *chan)
  443. {
  444. mutex_lock(&conn->chan_lock);
  445. __l2cap_chan_add(conn, chan);
  446. mutex_unlock(&conn->chan_lock);
  447. }
  448. void l2cap_chan_del(struct l2cap_chan *chan, int err)
  449. {
  450. struct l2cap_conn *conn = chan->conn;
  451. __clear_chan_timer(chan);
  452. BT_DBG("chan %p, conn %p, err %d, state %s", chan, conn, err,
  453. state_to_string(chan->state));
  454. chan->ops->teardown(chan, err);
  455. if (conn) {
  456. struct amp_mgr *mgr = conn->hcon->amp_mgr;
  457. /* Delete from channel list */
  458. list_del(&chan->list);
  459. l2cap_chan_put(chan);
  460. chan->conn = NULL;
  461. /* Reference was only held for non-fixed channels or
  462. * fixed channels that explicitly requested it using the
  463. * FLAG_HOLD_HCI_CONN flag.
  464. */
  465. if (chan->chan_type != L2CAP_CHAN_FIXED ||
  466. test_bit(FLAG_HOLD_HCI_CONN, &chan->flags))
  467. hci_conn_drop(conn->hcon);
  468. if (mgr && mgr->bredr_chan == chan)
  469. mgr->bredr_chan = NULL;
  470. }
  471. if (chan->hs_hchan) {
  472. struct hci_chan *hs_hchan = chan->hs_hchan;
  473. BT_DBG("chan %p disconnect hs_hchan %p", chan, hs_hchan);
  474. amp_disconnect_logical_link(hs_hchan);
  475. }
  476. if (test_bit(CONF_NOT_COMPLETE, &chan->conf_state))
  477. return;
  478. switch(chan->mode) {
  479. case L2CAP_MODE_BASIC:
  480. break;
  481. case L2CAP_MODE_LE_FLOWCTL:
  482. skb_queue_purge(&chan->tx_q);
  483. break;
  484. case L2CAP_MODE_ERTM:
  485. __clear_retrans_timer(chan);
  486. __clear_monitor_timer(chan);
  487. __clear_ack_timer(chan);
  488. skb_queue_purge(&chan->srej_q);
  489. l2cap_seq_list_free(&chan->srej_list);
  490. l2cap_seq_list_free(&chan->retrans_list);
  491. /* fall through */
  492. case L2CAP_MODE_STREAMING:
  493. skb_queue_purge(&chan->tx_q);
  494. break;
  495. }
  496. return;
  497. }
  498. EXPORT_SYMBOL_GPL(l2cap_chan_del);
  499. static void l2cap_conn_update_id_addr(struct work_struct *work)
  500. {
  501. struct l2cap_conn *conn = container_of(work, struct l2cap_conn,
  502. id_addr_update_work);
  503. struct hci_conn *hcon = conn->hcon;
  504. struct l2cap_chan *chan;
  505. mutex_lock(&conn->chan_lock);
  506. list_for_each_entry(chan, &conn->chan_l, list) {
  507. l2cap_chan_lock(chan);
  508. bacpy(&chan->dst, &hcon->dst);
  509. chan->dst_type = bdaddr_dst_type(hcon);
  510. l2cap_chan_unlock(chan);
  511. }
  512. mutex_unlock(&conn->chan_lock);
  513. }
  514. static void l2cap_chan_le_connect_reject(struct l2cap_chan *chan)
  515. {
  516. struct l2cap_conn *conn = chan->conn;
  517. struct l2cap_le_conn_rsp rsp;
  518. u16 result;
  519. if (test_bit(FLAG_DEFER_SETUP, &chan->flags))
  520. result = L2CAP_CR_AUTHORIZATION;
  521. else
  522. result = L2CAP_CR_BAD_PSM;
  523. l2cap_state_change(chan, BT_DISCONN);
  524. rsp.dcid = cpu_to_le16(chan->scid);
  525. rsp.mtu = cpu_to_le16(chan->imtu);
  526. rsp.mps = cpu_to_le16(chan->mps);
  527. rsp.credits = cpu_to_le16(chan->rx_credits);
  528. rsp.result = cpu_to_le16(result);
  529. l2cap_send_cmd(conn, chan->ident, L2CAP_LE_CONN_RSP, sizeof(rsp),
  530. &rsp);
  531. }
  532. static void l2cap_chan_connect_reject(struct l2cap_chan *chan)
  533. {
  534. struct l2cap_conn *conn = chan->conn;
  535. struct l2cap_conn_rsp rsp;
  536. u16 result;
  537. if (test_bit(FLAG_DEFER_SETUP, &chan->flags))
  538. result = L2CAP_CR_SEC_BLOCK;
  539. else
  540. result = L2CAP_CR_BAD_PSM;
  541. l2cap_state_change(chan, BT_DISCONN);
  542. rsp.scid = cpu_to_le16(chan->dcid);
  543. rsp.dcid = cpu_to_le16(chan->scid);
  544. rsp.result = cpu_to_le16(result);
  545. rsp.status = cpu_to_le16(L2CAP_CS_NO_INFO);
  546. l2cap_send_cmd(conn, chan->ident, L2CAP_CONN_RSP, sizeof(rsp), &rsp);
  547. }
  548. void l2cap_chan_close(struct l2cap_chan *chan, int reason)
  549. {
  550. struct l2cap_conn *conn = chan->conn;
  551. BT_DBG("chan %p state %s", chan, state_to_string(chan->state));
  552. switch (chan->state) {
  553. case BT_LISTEN:
  554. chan->ops->teardown(chan, 0);
  555. break;
  556. case BT_CONNECTED:
  557. case BT_CONFIG:
  558. if (chan->chan_type == L2CAP_CHAN_CONN_ORIENTED) {
  559. __set_chan_timer(chan, chan->ops->get_sndtimeo(chan));
  560. l2cap_send_disconn_req(chan, reason);
  561. } else
  562. l2cap_chan_del(chan, reason);
  563. break;
  564. case BT_CONNECT2:
  565. if (chan->chan_type == L2CAP_CHAN_CONN_ORIENTED) {
  566. if (conn->hcon->type == ACL_LINK)
  567. l2cap_chan_connect_reject(chan);
  568. else if (conn->hcon->type == LE_LINK)
  569. l2cap_chan_le_connect_reject(chan);
  570. }
  571. l2cap_chan_del(chan, reason);
  572. break;
  573. case BT_CONNECT:
  574. case BT_DISCONN:
  575. l2cap_chan_del(chan, reason);
  576. break;
  577. default:
  578. chan->ops->teardown(chan, 0);
  579. break;
  580. }
  581. }
  582. EXPORT_SYMBOL(l2cap_chan_close);
  583. static inline u8 l2cap_get_auth_type(struct l2cap_chan *chan)
  584. {
  585. switch (chan->chan_type) {
  586. case L2CAP_CHAN_RAW:
  587. switch (chan->sec_level) {
  588. case BT_SECURITY_HIGH:
  589. case BT_SECURITY_FIPS:
  590. return HCI_AT_DEDICATED_BONDING_MITM;
  591. case BT_SECURITY_MEDIUM:
  592. return HCI_AT_DEDICATED_BONDING;
  593. default:
  594. return HCI_AT_NO_BONDING;
  595. }
  596. break;
  597. case L2CAP_CHAN_CONN_LESS:
  598. if (chan->psm == cpu_to_le16(L2CAP_PSM_3DSP)) {
  599. if (chan->sec_level == BT_SECURITY_LOW)
  600. chan->sec_level = BT_SECURITY_SDP;
  601. }
  602. if (chan->sec_level == BT_SECURITY_HIGH ||
  603. chan->sec_level == BT_SECURITY_FIPS)
  604. return HCI_AT_NO_BONDING_MITM;
  605. else
  606. return HCI_AT_NO_BONDING;
  607. break;
  608. case L2CAP_CHAN_CONN_ORIENTED:
  609. if (chan->psm == cpu_to_le16(L2CAP_PSM_SDP)) {
  610. if (chan->sec_level == BT_SECURITY_LOW)
  611. chan->sec_level = BT_SECURITY_SDP;
  612. if (chan->sec_level == BT_SECURITY_HIGH ||
  613. chan->sec_level == BT_SECURITY_FIPS)
  614. return HCI_AT_NO_BONDING_MITM;
  615. else
  616. return HCI_AT_NO_BONDING;
  617. }
  618. /* fall through */
  619. default:
  620. switch (chan->sec_level) {
  621. case BT_SECURITY_HIGH:
  622. case BT_SECURITY_FIPS:
  623. return HCI_AT_GENERAL_BONDING_MITM;
  624. case BT_SECURITY_MEDIUM:
  625. return HCI_AT_GENERAL_BONDING;
  626. default:
  627. return HCI_AT_NO_BONDING;
  628. }
  629. break;
  630. }
  631. }
  632. /* Service level security */
  633. int l2cap_chan_check_security(struct l2cap_chan *chan, bool initiator)
  634. {
  635. struct l2cap_conn *conn = chan->conn;
  636. __u8 auth_type;
  637. if (conn->hcon->type == LE_LINK)
  638. return smp_conn_security(conn->hcon, chan->sec_level);
  639. auth_type = l2cap_get_auth_type(chan);
  640. return hci_conn_security(conn->hcon, chan->sec_level, auth_type,
  641. initiator);
  642. }
  643. static u8 l2cap_get_ident(struct l2cap_conn *conn)
  644. {
  645. u8 id;
  646. /* Get next available identificator.
  647. * 1 - 128 are used by kernel.
  648. * 129 - 199 are reserved.
  649. * 200 - 254 are used by utilities like l2ping, etc.
  650. */
  651. mutex_lock(&conn->ident_lock);
  652. if (++conn->tx_ident > 128)
  653. conn->tx_ident = 1;
  654. id = conn->tx_ident;
  655. mutex_unlock(&conn->ident_lock);
  656. return id;
  657. }
  658. static void l2cap_send_cmd(struct l2cap_conn *conn, u8 ident, u8 code, u16 len,
  659. void *data)
  660. {
  661. struct sk_buff *skb = l2cap_build_cmd(conn, code, ident, len, data);
  662. u8 flags;
  663. BT_DBG("code 0x%2.2x", code);
  664. if (!skb)
  665. return;
  666. /* Use NO_FLUSH if supported or we have an LE link (which does
  667. * not support auto-flushing packets) */
  668. if (lmp_no_flush_capable(conn->hcon->hdev) ||
  669. conn->hcon->type == LE_LINK)
  670. flags = ACL_START_NO_FLUSH;
  671. else
  672. flags = ACL_START;
  673. bt_cb(skb)->force_active = BT_POWER_FORCE_ACTIVE_ON;
  674. skb->priority = HCI_PRIO_MAX;
  675. hci_send_acl(conn->hchan, skb, flags);
  676. }
  677. static bool __chan_is_moving(struct l2cap_chan *chan)
  678. {
  679. return chan->move_state != L2CAP_MOVE_STABLE &&
  680. chan->move_state != L2CAP_MOVE_WAIT_PREPARE;
  681. }
  682. static void l2cap_do_send(struct l2cap_chan *chan, struct sk_buff *skb)
  683. {
  684. struct hci_conn *hcon = chan->conn->hcon;
  685. u16 flags;
  686. BT_DBG("chan %p, skb %p len %d priority %u", chan, skb, skb->len,
  687. skb->priority);
  688. if (chan->hs_hcon && !__chan_is_moving(chan)) {
  689. if (chan->hs_hchan)
  690. hci_send_acl(chan->hs_hchan, skb, ACL_COMPLETE);
  691. else
  692. kfree_skb(skb);
  693. return;
  694. }
  695. /* Use NO_FLUSH for LE links (where this is the only option) or
  696. * if the BR/EDR link supports it and flushing has not been
  697. * explicitly requested (through FLAG_FLUSHABLE).
  698. */
  699. if (hcon->type == LE_LINK ||
  700. (!test_bit(FLAG_FLUSHABLE, &chan->flags) &&
  701. lmp_no_flush_capable(hcon->hdev)))
  702. flags = ACL_START_NO_FLUSH;
  703. else
  704. flags = ACL_START;
  705. bt_cb(skb)->force_active = test_bit(FLAG_FORCE_ACTIVE, &chan->flags);
  706. hci_send_acl(chan->conn->hchan, skb, flags);
  707. }
  708. static void __unpack_enhanced_control(u16 enh, struct l2cap_ctrl *control)
  709. {
  710. control->reqseq = (enh & L2CAP_CTRL_REQSEQ) >> L2CAP_CTRL_REQSEQ_SHIFT;
  711. control->final = (enh & L2CAP_CTRL_FINAL) >> L2CAP_CTRL_FINAL_SHIFT;
  712. if (enh & L2CAP_CTRL_FRAME_TYPE) {
  713. /* S-Frame */
  714. control->sframe = 1;
  715. control->poll = (enh & L2CAP_CTRL_POLL) >> L2CAP_CTRL_POLL_SHIFT;
  716. control->super = (enh & L2CAP_CTRL_SUPERVISE) >> L2CAP_CTRL_SUPER_SHIFT;
  717. control->sar = 0;
  718. control->txseq = 0;
  719. } else {
  720. /* I-Frame */
  721. control->sframe = 0;
  722. control->sar = (enh & L2CAP_CTRL_SAR) >> L2CAP_CTRL_SAR_SHIFT;
  723. control->txseq = (enh & L2CAP_CTRL_TXSEQ) >> L2CAP_CTRL_TXSEQ_SHIFT;
  724. control->poll = 0;
  725. control->super = 0;
  726. }
  727. }
  728. static void __unpack_extended_control(u32 ext, struct l2cap_ctrl *control)
  729. {
  730. control->reqseq = (ext & L2CAP_EXT_CTRL_REQSEQ) >> L2CAP_EXT_CTRL_REQSEQ_SHIFT;
  731. control->final = (ext & L2CAP_EXT_CTRL_FINAL) >> L2CAP_EXT_CTRL_FINAL_SHIFT;
  732. if (ext & L2CAP_EXT_CTRL_FRAME_TYPE) {
  733. /* S-Frame */
  734. control->sframe = 1;
  735. control->poll = (ext & L2CAP_EXT_CTRL_POLL) >> L2CAP_EXT_CTRL_POLL_SHIFT;
  736. control->super = (ext & L2CAP_EXT_CTRL_SUPERVISE) >> L2CAP_EXT_CTRL_SUPER_SHIFT;
  737. control->sar = 0;
  738. control->txseq = 0;
  739. } else {
  740. /* I-Frame */
  741. control->sframe = 0;
  742. control->sar = (ext & L2CAP_EXT_CTRL_SAR) >> L2CAP_EXT_CTRL_SAR_SHIFT;
  743. control->txseq = (ext & L2CAP_EXT_CTRL_TXSEQ) >> L2CAP_EXT_CTRL_TXSEQ_SHIFT;
  744. control->poll = 0;
  745. control->super = 0;
  746. }
  747. }
  748. static inline void __unpack_control(struct l2cap_chan *chan,
  749. struct sk_buff *skb)
  750. {
  751. if (test_bit(FLAG_EXT_CTRL, &chan->flags)) {
  752. __unpack_extended_control(get_unaligned_le32(skb->data),
  753. &bt_cb(skb)->l2cap);
  754. skb_pull(skb, L2CAP_EXT_CTRL_SIZE);
  755. } else {
  756. __unpack_enhanced_control(get_unaligned_le16(skb->data),
  757. &bt_cb(skb)->l2cap);
  758. skb_pull(skb, L2CAP_ENH_CTRL_SIZE);
  759. }
  760. }
  761. static u32 __pack_extended_control(struct l2cap_ctrl *control)
  762. {
  763. u32 packed;
  764. packed = control->reqseq << L2CAP_EXT_CTRL_REQSEQ_SHIFT;
  765. packed |= control->final << L2CAP_EXT_CTRL_FINAL_SHIFT;
  766. if (control->sframe) {
  767. packed |= control->poll << L2CAP_EXT_CTRL_POLL_SHIFT;
  768. packed |= control->super << L2CAP_EXT_CTRL_SUPER_SHIFT;
  769. packed |= L2CAP_EXT_CTRL_FRAME_TYPE;
  770. } else {
  771. packed |= control->sar << L2CAP_EXT_CTRL_SAR_SHIFT;
  772. packed |= control->txseq << L2CAP_EXT_CTRL_TXSEQ_SHIFT;
  773. }
  774. return packed;
  775. }
  776. static u16 __pack_enhanced_control(struct l2cap_ctrl *control)
  777. {
  778. u16 packed;
  779. packed = control->reqseq << L2CAP_CTRL_REQSEQ_SHIFT;
  780. packed |= control->final << L2CAP_CTRL_FINAL_SHIFT;
  781. if (control->sframe) {
  782. packed |= control->poll << L2CAP_CTRL_POLL_SHIFT;
  783. packed |= control->super << L2CAP_CTRL_SUPER_SHIFT;
  784. packed |= L2CAP_CTRL_FRAME_TYPE;
  785. } else {
  786. packed |= control->sar << L2CAP_CTRL_SAR_SHIFT;
  787. packed |= control->txseq << L2CAP_CTRL_TXSEQ_SHIFT;
  788. }
  789. return packed;
  790. }
  791. static inline void __pack_control(struct l2cap_chan *chan,
  792. struct l2cap_ctrl *control,
  793. struct sk_buff *skb)
  794. {
  795. if (test_bit(FLAG_EXT_CTRL, &chan->flags)) {
  796. put_unaligned_le32(__pack_extended_control(control),
  797. skb->data + L2CAP_HDR_SIZE);
  798. } else {
  799. put_unaligned_le16(__pack_enhanced_control(control),
  800. skb->data + L2CAP_HDR_SIZE);
  801. }
  802. }
  803. static inline unsigned int __ertm_hdr_size(struct l2cap_chan *chan)
  804. {
  805. if (test_bit(FLAG_EXT_CTRL, &chan->flags))
  806. return L2CAP_EXT_HDR_SIZE;
  807. else
  808. return L2CAP_ENH_HDR_SIZE;
  809. }
  810. static struct sk_buff *l2cap_create_sframe_pdu(struct l2cap_chan *chan,
  811. u32 control)
  812. {
  813. struct sk_buff *skb;
  814. struct l2cap_hdr *lh;
  815. int hlen = __ertm_hdr_size(chan);
  816. if (chan->fcs == L2CAP_FCS_CRC16)
  817. hlen += L2CAP_FCS_SIZE;
  818. skb = bt_skb_alloc(hlen, GFP_KERNEL);
  819. if (!skb)
  820. return ERR_PTR(-ENOMEM);
  821. lh = (struct l2cap_hdr *) skb_put(skb, L2CAP_HDR_SIZE);
  822. lh->len = cpu_to_le16(hlen - L2CAP_HDR_SIZE);
  823. lh->cid = cpu_to_le16(chan->dcid);
  824. if (test_bit(FLAG_EXT_CTRL, &chan->flags))
  825. put_unaligned_le32(control, skb_put(skb, L2CAP_EXT_CTRL_SIZE));
  826. else
  827. put_unaligned_le16(control, skb_put(skb, L2CAP_ENH_CTRL_SIZE));
  828. if (chan->fcs == L2CAP_FCS_CRC16) {
  829. u16 fcs = crc16(0, (u8 *)skb->data, skb->len);
  830. put_unaligned_le16(fcs, skb_put(skb, L2CAP_FCS_SIZE));
  831. }
  832. skb->priority = HCI_PRIO_MAX;
  833. return skb;
  834. }
  835. static void l2cap_send_sframe(struct l2cap_chan *chan,
  836. struct l2cap_ctrl *control)
  837. {
  838. struct sk_buff *skb;
  839. u32 control_field;
  840. BT_DBG("chan %p, control %p", chan, control);
  841. if (!control->sframe)
  842. return;
  843. if (__chan_is_moving(chan))
  844. return;
  845. if (test_and_clear_bit(CONN_SEND_FBIT, &chan->conn_state) &&
  846. !control->poll)
  847. control->final = 1;
  848. if (control->super == L2CAP_SUPER_RR)
  849. clear_bit(CONN_RNR_SENT, &chan->conn_state);
  850. else if (control->super == L2CAP_SUPER_RNR)
  851. set_bit(CONN_RNR_SENT, &chan->conn_state);
  852. if (control->super != L2CAP_SUPER_SREJ) {
  853. chan->last_acked_seq = control->reqseq;
  854. __clear_ack_timer(chan);
  855. }
  856. BT_DBG("reqseq %d, final %d, poll %d, super %d", control->reqseq,
  857. control->final, control->poll, control->super);
  858. if (test_bit(FLAG_EXT_CTRL, &chan->flags))
  859. control_field = __pack_extended_control(control);
  860. else
  861. control_field = __pack_enhanced_control(control);
  862. skb = l2cap_create_sframe_pdu(chan, control_field);
  863. if (!IS_ERR(skb))
  864. l2cap_do_send(chan, skb);
  865. }
  866. static void l2cap_send_rr_or_rnr(struct l2cap_chan *chan, bool poll)
  867. {
  868. struct l2cap_ctrl control;
  869. BT_DBG("chan %p, poll %d", chan, poll);
  870. memset(&control, 0, sizeof(control));
  871. control.sframe = 1;
  872. control.poll = poll;
  873. if (test_bit(CONN_LOCAL_BUSY, &chan->conn_state))
  874. control.super = L2CAP_SUPER_RNR;
  875. else
  876. control.super = L2CAP_SUPER_RR;
  877. control.reqseq = chan->buffer_seq;
  878. l2cap_send_sframe(chan, &control);
  879. }
  880. static inline int __l2cap_no_conn_pending(struct l2cap_chan *chan)
  881. {
  882. if (chan->chan_type != L2CAP_CHAN_CONN_ORIENTED)
  883. return true;
  884. return !test_bit(CONF_CONNECT_PEND, &chan->conf_state);
  885. }
  886. static bool __amp_capable(struct l2cap_chan *chan)
  887. {
  888. struct l2cap_conn *conn = chan->conn;
  889. struct hci_dev *hdev;
  890. bool amp_available = false;
  891. if (!(conn->local_fixed_chan & L2CAP_FC_A2MP))
  892. return false;
  893. if (!(conn->remote_fixed_chan & L2CAP_FC_A2MP))
  894. return false;
  895. read_lock(&hci_dev_list_lock);
  896. list_for_each_entry(hdev, &hci_dev_list, list) {
  897. if (hdev->amp_type != AMP_TYPE_BREDR &&
  898. test_bit(HCI_UP, &hdev->flags)) {
  899. amp_available = true;
  900. break;
  901. }
  902. }
  903. read_unlock(&hci_dev_list_lock);
  904. if (chan->chan_policy == BT_CHANNEL_POLICY_AMP_PREFERRED)
  905. return amp_available;
  906. return false;
  907. }
  908. static bool l2cap_check_efs(struct l2cap_chan *chan)
  909. {
  910. /* Check EFS parameters */
  911. return true;
  912. }
  913. void l2cap_send_conn_req(struct l2cap_chan *chan)
  914. {
  915. struct l2cap_conn *conn = chan->conn;
  916. struct l2cap_conn_req req;
  917. req.scid = cpu_to_le16(chan->scid);
  918. req.psm = chan->psm;
  919. chan->ident = l2cap_get_ident(conn);
  920. set_bit(CONF_CONNECT_PEND, &chan->conf_state);
  921. l2cap_send_cmd(conn, chan->ident, L2CAP_CONN_REQ, sizeof(req), &req);
  922. }
  923. static void l2cap_send_create_chan_req(struct l2cap_chan *chan, u8 amp_id)
  924. {
  925. struct l2cap_create_chan_req req;
  926. req.scid = cpu_to_le16(chan->scid);
  927. req.psm = chan->psm;
  928. req.amp_id = amp_id;
  929. chan->ident = l2cap_get_ident(chan->conn);
  930. l2cap_send_cmd(chan->conn, chan->ident, L2CAP_CREATE_CHAN_REQ,
  931. sizeof(req), &req);
  932. }
  933. static void l2cap_move_setup(struct l2cap_chan *chan)
  934. {
  935. struct sk_buff *skb;
  936. BT_DBG("chan %p", chan);
  937. if (chan->mode != L2CAP_MODE_ERTM)
  938. return;
  939. __clear_retrans_timer(chan);
  940. __clear_monitor_timer(chan);
  941. __clear_ack_timer(chan);
  942. chan->retry_count = 0;
  943. skb_queue_walk(&chan->tx_q, skb) {
  944. if (bt_cb(skb)->l2cap.retries)
  945. bt_cb(skb)->l2cap.retries = 1;
  946. else
  947. break;
  948. }
  949. chan->expected_tx_seq = chan->buffer_seq;
  950. clear_bit(CONN_REJ_ACT, &chan->conn_state);
  951. clear_bit(CONN_SREJ_ACT, &chan->conn_state);
  952. l2cap_seq_list_clear(&chan->retrans_list);
  953. l2cap_seq_list_clear(&chan->srej_list);
  954. skb_queue_purge(&chan->srej_q);
  955. chan->tx_state = L2CAP_TX_STATE_XMIT;
  956. chan->rx_state = L2CAP_RX_STATE_MOVE;
  957. set_bit(CONN_REMOTE_BUSY, &chan->conn_state);
  958. }
  959. static void l2cap_move_done(struct l2cap_chan *chan)
  960. {
  961. u8 move_role = chan->move_role;
  962. BT_DBG("chan %p", chan);
  963. chan->move_state = L2CAP_MOVE_STABLE;
  964. chan->move_role = L2CAP_MOVE_ROLE_NONE;
  965. if (chan->mode != L2CAP_MODE_ERTM)
  966. return;
  967. switch (move_role) {
  968. case L2CAP_MOVE_ROLE_INITIATOR:
  969. l2cap_tx(chan, NULL, NULL, L2CAP_EV_EXPLICIT_POLL);
  970. chan->rx_state = L2CAP_RX_STATE_WAIT_F;
  971. break;
  972. case L2CAP_MOVE_ROLE_RESPONDER:
  973. chan->rx_state = L2CAP_RX_STATE_WAIT_P;
  974. break;
  975. }
  976. }
  977. static void l2cap_chan_ready(struct l2cap_chan *chan)
  978. {
  979. /* The channel may have already been flagged as connected in
  980. * case of receiving data before the L2CAP info req/rsp
  981. * procedure is complete.
  982. */
  983. if (chan->state == BT_CONNECTED)
  984. return;
  985. /* This clears all conf flags, including CONF_NOT_COMPLETE */
  986. chan->conf_state = 0;
  987. __clear_chan_timer(chan);
  988. if (chan->mode == L2CAP_MODE_LE_FLOWCTL && !chan->tx_credits)
  989. chan->ops->suspend(chan);
  990. chan->state = BT_CONNECTED;
  991. chan->ops->ready(chan);
  992. }
  993. static void l2cap_le_connect(struct l2cap_chan *chan)
  994. {
  995. struct l2cap_conn *conn = chan->conn;
  996. struct l2cap_le_conn_req req;
  997. if (test_and_set_bit(FLAG_LE_CONN_REQ_SENT, &chan->flags))
  998. return;
  999. req.psm = chan->psm;
  1000. req.scid = cpu_to_le16(chan->scid);
  1001. req.mtu = cpu_to_le16(chan->imtu);
  1002. req.mps = cpu_to_le16(chan->mps);
  1003. req.credits = cpu_to_le16(chan->rx_credits);
  1004. chan->ident = l2cap_get_ident(conn);
  1005. l2cap_send_cmd(conn, chan->ident, L2CAP_LE_CONN_REQ,
  1006. sizeof(req), &req);
  1007. }
  1008. static void l2cap_le_start(struct l2cap_chan *chan)
  1009. {
  1010. struct l2cap_conn *conn = chan->conn;
  1011. if (!smp_conn_security(conn->hcon, chan->sec_level))
  1012. return;
  1013. if (!chan->psm) {
  1014. l2cap_chan_ready(chan);
  1015. return;
  1016. }
  1017. if (chan->state == BT_CONNECT)
  1018. l2cap_le_connect(chan);
  1019. }
  1020. static void l2cap_start_connection(struct l2cap_chan *chan)
  1021. {
  1022. if (__amp_capable(chan)) {
  1023. BT_DBG("chan %p AMP capable: discover AMPs", chan);
  1024. a2mp_discover_amp(chan);
  1025. } else if (chan->conn->hcon->type == LE_LINK) {
  1026. l2cap_le_start(chan);
  1027. } else {
  1028. l2cap_send_conn_req(chan);
  1029. }
  1030. }
  1031. static void l2cap_request_info(struct l2cap_conn *conn)
  1032. {
  1033. struct l2cap_info_req req;
  1034. if (conn->info_state & L2CAP_INFO_FEAT_MASK_REQ_SENT)
  1035. return;
  1036. req.type = cpu_to_le16(L2CAP_IT_FEAT_MASK);
  1037. conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_SENT;
  1038. conn->info_ident = l2cap_get_ident(conn);
  1039. schedule_delayed_work(&conn->info_timer, L2CAP_INFO_TIMEOUT);
  1040. l2cap_send_cmd(conn, conn->info_ident, L2CAP_INFO_REQ,
  1041. sizeof(req), &req);
  1042. }
  1043. static void l2cap_do_start(struct l2cap_chan *chan)
  1044. {
  1045. struct l2cap_conn *conn = chan->conn;
  1046. if (conn->hcon->type == LE_LINK) {
  1047. l2cap_le_start(chan);
  1048. return;
  1049. }
  1050. if (!(conn->info_state & L2CAP_INFO_FEAT_MASK_REQ_SENT)) {
  1051. l2cap_request_info(conn);
  1052. return;
  1053. }
  1054. if (!(conn->info_state & L2CAP_INFO_FEAT_MASK_REQ_DONE))
  1055. return;
  1056. if (l2cap_chan_check_security(chan, true) &&
  1057. __l2cap_no_conn_pending(chan))
  1058. l2cap_start_connection(chan);
  1059. }
  1060. static inline int l2cap_mode_supported(__u8 mode, __u32 feat_mask)
  1061. {
  1062. u32 local_feat_mask = l2cap_feat_mask;
  1063. if (!disable_ertm)
  1064. local_feat_mask |= L2CAP_FEAT_ERTM | L2CAP_FEAT_STREAMING;
  1065. switch (mode) {
  1066. case L2CAP_MODE_ERTM:
  1067. return L2CAP_FEAT_ERTM & feat_mask & local_feat_mask;
  1068. case L2CAP_MODE_STREAMING:
  1069. return L2CAP_FEAT_STREAMING & feat_mask & local_feat_mask;
  1070. default:
  1071. return 0x00;
  1072. }
  1073. }
  1074. static void l2cap_send_disconn_req(struct l2cap_chan *chan, int err)
  1075. {
  1076. struct l2cap_conn *conn = chan->conn;
  1077. struct l2cap_disconn_req req;
  1078. if (!conn)
  1079. return;
  1080. if (chan->mode == L2CAP_MODE_ERTM && chan->state == BT_CONNECTED) {
  1081. __clear_retrans_timer(chan);
  1082. __clear_monitor_timer(chan);
  1083. __clear_ack_timer(chan);
  1084. }
  1085. if (chan->scid == L2CAP_CID_A2MP) {
  1086. l2cap_state_change(chan, BT_DISCONN);
  1087. return;
  1088. }
  1089. req.dcid = cpu_to_le16(chan->dcid);
  1090. req.scid = cpu_to_le16(chan->scid);
  1091. l2cap_send_cmd(conn, l2cap_get_ident(conn), L2CAP_DISCONN_REQ,
  1092. sizeof(req), &req);
  1093. l2cap_state_change_and_error(chan, BT_DISCONN, err);
  1094. }
  1095. /* ---- L2CAP connections ---- */
  1096. static void l2cap_conn_start(struct l2cap_conn *conn)
  1097. {
  1098. struct l2cap_chan *chan, *tmp;
  1099. BT_DBG("conn %p", conn);
  1100. mutex_lock(&conn->chan_lock);
  1101. list_for_each_entry_safe(chan, tmp, &conn->chan_l, list) {
  1102. l2cap_chan_lock(chan);
  1103. if (chan->chan_type != L2CAP_CHAN_CONN_ORIENTED) {
  1104. l2cap_chan_ready(chan);
  1105. l2cap_chan_unlock(chan);
  1106. continue;
  1107. }
  1108. if (chan->state == BT_CONNECT) {
  1109. if (!l2cap_chan_check_security(chan, true) ||
  1110. !__l2cap_no_conn_pending(chan)) {
  1111. l2cap_chan_unlock(chan);
  1112. continue;
  1113. }
  1114. if (!l2cap_mode_supported(chan->mode, conn->feat_mask)
  1115. && test_bit(CONF_STATE2_DEVICE,
  1116. &chan->conf_state)) {
  1117. l2cap_chan_close(chan, ECONNRESET);
  1118. l2cap_chan_unlock(chan);
  1119. continue;
  1120. }
  1121. l2cap_start_connection(chan);
  1122. } else if (chan->state == BT_CONNECT2) {
  1123. struct l2cap_conn_rsp rsp;
  1124. char buf[128];
  1125. rsp.scid = cpu_to_le16(chan->dcid);
  1126. rsp.dcid = cpu_to_le16(chan->scid);
  1127. if (l2cap_chan_check_security(chan, false)) {
  1128. if (test_bit(FLAG_DEFER_SETUP, &chan->flags)) {
  1129. rsp.result = cpu_to_le16(L2CAP_CR_PEND);
  1130. rsp.status = cpu_to_le16(L2CAP_CS_AUTHOR_PEND);
  1131. chan->ops->defer(chan);
  1132. } else {
  1133. l2cap_state_change(chan, BT_CONFIG);
  1134. rsp.result = cpu_to_le16(L2CAP_CR_SUCCESS);
  1135. rsp.status = cpu_to_le16(L2CAP_CS_NO_INFO);
  1136. }
  1137. } else {
  1138. rsp.result = cpu_to_le16(L2CAP_CR_PEND);
  1139. rsp.status = cpu_to_le16(L2CAP_CS_AUTHEN_PEND);
  1140. }
  1141. l2cap_send_cmd(conn, chan->ident, L2CAP_CONN_RSP,
  1142. sizeof(rsp), &rsp);
  1143. if (test_bit(CONF_REQ_SENT, &chan->conf_state) ||
  1144. rsp.result != L2CAP_CR_SUCCESS) {
  1145. l2cap_chan_unlock(chan);
  1146. continue;
  1147. }
  1148. set_bit(CONF_REQ_SENT, &chan->conf_state);
  1149. l2cap_send_cmd(conn, l2cap_get_ident(conn), L2CAP_CONF_REQ,
  1150. l2cap_build_conf_req(chan, buf, sizeof(buf)), buf);
  1151. chan->num_conf_req++;
  1152. }
  1153. l2cap_chan_unlock(chan);
  1154. }
  1155. mutex_unlock(&conn->chan_lock);
  1156. }
  1157. static void l2cap_le_conn_ready(struct l2cap_conn *conn)
  1158. {
  1159. struct hci_conn *hcon = conn->hcon;
  1160. struct hci_dev *hdev = hcon->hdev;
  1161. BT_DBG("%s conn %p", hdev->name, conn);
  1162. /* For outgoing pairing which doesn't necessarily have an
  1163. * associated socket (e.g. mgmt_pair_device).
  1164. */
  1165. if (hcon->out)
  1166. smp_conn_security(hcon, hcon->pending_sec_level);
  1167. /* For LE slave connections, make sure the connection interval
  1168. * is in the range of the minium and maximum interval that has
  1169. * been configured for this connection. If not, then trigger
  1170. * the connection update procedure.
  1171. */
  1172. if (hcon->role == HCI_ROLE_SLAVE &&
  1173. (hcon->le_conn_interval < hcon->le_conn_min_interval ||
  1174. hcon->le_conn_interval > hcon->le_conn_max_interval)) {
  1175. struct l2cap_conn_param_update_req req;
  1176. req.min = cpu_to_le16(hcon->le_conn_min_interval);
  1177. req.max = cpu_to_le16(hcon->le_conn_max_interval);
  1178. req.latency = cpu_to_le16(hcon->le_conn_latency);
  1179. req.to_multiplier = cpu_to_le16(hcon->le_supv_timeout);
  1180. l2cap_send_cmd(conn, l2cap_get_ident(conn),
  1181. L2CAP_CONN_PARAM_UPDATE_REQ, sizeof(req), &req);
  1182. }
  1183. }
  1184. static void l2cap_conn_ready(struct l2cap_conn *conn)
  1185. {
  1186. struct l2cap_chan *chan;
  1187. struct hci_conn *hcon = conn->hcon;
  1188. BT_DBG("conn %p", conn);
  1189. if (hcon->type == ACL_LINK)
  1190. l2cap_request_info(conn);
  1191. mutex_lock(&conn->chan_lock);
  1192. list_for_each_entry(chan, &conn->chan_l, list) {
  1193. l2cap_chan_lock(chan);
  1194. if (chan->scid == L2CAP_CID_A2MP) {
  1195. l2cap_chan_unlock(chan);
  1196. continue;
  1197. }
  1198. if (hcon->type == LE_LINK) {
  1199. l2cap_le_start(chan);
  1200. } else if (chan->chan_type != L2CAP_CHAN_CONN_ORIENTED) {
  1201. if (conn->info_state & L2CAP_INFO_FEAT_MASK_REQ_DONE)
  1202. l2cap_chan_ready(chan);
  1203. } else if (chan->state == BT_CONNECT) {
  1204. l2cap_do_start(chan);
  1205. }
  1206. l2cap_chan_unlock(chan);
  1207. }
  1208. mutex_unlock(&conn->chan_lock);
  1209. if (hcon->type == LE_LINK)
  1210. l2cap_le_conn_ready(conn);
  1211. queue_work(hcon->hdev->workqueue, &conn->pending_rx_work);
  1212. }
  1213. /* Notify sockets that we cannot guaranty reliability anymore */
  1214. static void l2cap_conn_unreliable(struct l2cap_conn *conn, int err)
  1215. {
  1216. struct l2cap_chan *chan;
  1217. BT_DBG("conn %p", conn);
  1218. mutex_lock(&conn->chan_lock);
  1219. list_for_each_entry(chan, &conn->chan_l, list) {
  1220. if (test_bit(FLAG_FORCE_RELIABLE, &chan->flags))
  1221. l2cap_chan_set_err(chan, err);
  1222. }
  1223. mutex_unlock(&conn->chan_lock);
  1224. }
  1225. static void l2cap_info_timeout(struct work_struct *work)
  1226. {
  1227. struct l2cap_conn *conn = container_of(work, struct l2cap_conn,
  1228. info_timer.work);
  1229. conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_DONE;
  1230. conn->info_ident = 0;
  1231. l2cap_conn_start(conn);
  1232. }
  1233. /*
  1234. * l2cap_user
  1235. * External modules can register l2cap_user objects on l2cap_conn. The ->probe
  1236. * callback is called during registration. The ->remove callback is called
  1237. * during unregistration.
  1238. * An l2cap_user object can either be explicitly unregistered or when the
  1239. * underlying l2cap_conn object is deleted. This guarantees that l2cap->hcon,
  1240. * l2cap->hchan, .. are valid as long as the remove callback hasn't been called.
  1241. * External modules must own a reference to the l2cap_conn object if they intend
  1242. * to call l2cap_unregister_user(). The l2cap_conn object might get destroyed at
  1243. * any time if they don't.
  1244. */
  1245. int l2cap_register_user(struct l2cap_conn *conn, struct l2cap_user *user)
  1246. {
  1247. struct hci_dev *hdev = conn->hcon->hdev;
  1248. int ret;
  1249. /* We need to check whether l2cap_conn is registered. If it is not, we
  1250. * must not register the l2cap_user. l2cap_conn_del() is unregisters
  1251. * l2cap_conn objects, but doesn't provide its own locking. Instead, it
  1252. * relies on the parent hci_conn object to be locked. This itself relies
  1253. * on the hci_dev object to be locked. So we must lock the hci device
  1254. * here, too. */
  1255. hci_dev_lock(hdev);
  1256. if (!list_empty(&user->list)) {
  1257. ret = -EINVAL;
  1258. goto out_unlock;
  1259. }
  1260. /* conn->hchan is NULL after l2cap_conn_del() was called */
  1261. if (!conn->hchan) {
  1262. ret = -ENODEV;
  1263. goto out_unlock;
  1264. }
  1265. ret = user->probe(conn, user);
  1266. if (ret)
  1267. goto out_unlock;
  1268. list_add(&user->list, &conn->users);
  1269. ret = 0;
  1270. out_unlock:
  1271. hci_dev_unlock(hdev);
  1272. return ret;
  1273. }
  1274. EXPORT_SYMBOL(l2cap_register_user);
  1275. void l2cap_unregister_user(struct l2cap_conn *conn, struct l2cap_user *user)
  1276. {
  1277. struct hci_dev *hdev = conn->hcon->hdev;
  1278. hci_dev_lock(hdev);
  1279. if (list_empty(&user->list))
  1280. goto out_unlock;
  1281. list_del_init(&user->list);
  1282. user->remove(conn, user);
  1283. out_unlock:
  1284. hci_dev_unlock(hdev);
  1285. }
  1286. EXPORT_SYMBOL(l2cap_unregister_user);
  1287. static void l2cap_unregister_all_users(struct l2cap_conn *conn)
  1288. {
  1289. struct l2cap_user *user;
  1290. while (!list_empty(&conn->users)) {
  1291. user = list_first_entry(&conn->users, struct l2cap_user, list);
  1292. list_del_init(&user->list);
  1293. user->remove(conn, user);
  1294. }
  1295. }
  1296. static void l2cap_conn_del(struct hci_conn *hcon, int err)
  1297. {
  1298. struct l2cap_conn *conn = hcon->l2cap_data;
  1299. struct l2cap_chan *chan, *l;
  1300. if (!conn)
  1301. return;
  1302. BT_DBG("hcon %p conn %p, err %d", hcon, conn, err);
  1303. kfree_skb(conn->rx_skb);
  1304. skb_queue_purge(&conn->pending_rx);
  1305. /* We can not call flush_work(&conn->pending_rx_work) here since we
  1306. * might block if we are running on a worker from the same workqueue
  1307. * pending_rx_work is waiting on.
  1308. */
  1309. if (work_pending(&conn->pending_rx_work))
  1310. cancel_work_sync(&conn->pending_rx_work);
  1311. if (work_pending(&conn->id_addr_update_work))
  1312. cancel_work_sync(&conn->id_addr_update_work);
  1313. l2cap_unregister_all_users(conn);
  1314. /* Force the connection to be immediately dropped */
  1315. hcon->disc_timeout = 0;
  1316. mutex_lock(&conn->chan_lock);
  1317. /* Kill channels */
  1318. list_for_each_entry_safe(chan, l, &conn->chan_l, list) {
  1319. l2cap_chan_hold(chan);
  1320. l2cap_chan_lock(chan);
  1321. l2cap_chan_del(chan, err);
  1322. l2cap_chan_unlock(chan);
  1323. chan->ops->close(chan);
  1324. l2cap_chan_put(chan);
  1325. }
  1326. mutex_unlock(&conn->chan_lock);
  1327. hci_chan_del(conn->hchan);
  1328. if (conn->info_state & L2CAP_INFO_FEAT_MASK_REQ_SENT)
  1329. cancel_delayed_work_sync(&conn->info_timer);
  1330. hcon->l2cap_data = NULL;
  1331. conn->hchan = NULL;
  1332. l2cap_conn_put(conn);
  1333. }
  1334. static void l2cap_conn_free(struct kref *ref)
  1335. {
  1336. struct l2cap_conn *conn = container_of(ref, struct l2cap_conn, ref);
  1337. hci_conn_put(conn->hcon);
  1338. kfree(conn);
  1339. }
  1340. struct l2cap_conn *l2cap_conn_get(struct l2cap_conn *conn)
  1341. {
  1342. kref_get(&conn->ref);
  1343. return conn;
  1344. }
  1345. EXPORT_SYMBOL(l2cap_conn_get);
  1346. void l2cap_conn_put(struct l2cap_conn *conn)
  1347. {
  1348. kref_put(&conn->ref, l2cap_conn_free);
  1349. }
  1350. EXPORT_SYMBOL(l2cap_conn_put);
  1351. /* ---- Socket interface ---- */
  1352. /* Find socket with psm and source / destination bdaddr.
  1353. * Returns closest match.
  1354. */
  1355. static struct l2cap_chan *l2cap_global_chan_by_psm(int state, __le16 psm,
  1356. bdaddr_t *src,
  1357. bdaddr_t *dst,
  1358. u8 link_type)
  1359. {
  1360. struct l2cap_chan *c, *c1 = NULL;
  1361. read_lock(&chan_list_lock);
  1362. list_for_each_entry(c, &chan_list, global_l) {
  1363. if (state && c->state != state)
  1364. continue;
  1365. if (link_type == ACL_LINK && c->src_type != BDADDR_BREDR)
  1366. continue;
  1367. if (link_type == LE_LINK && c->src_type == BDADDR_BREDR)
  1368. continue;
  1369. if (c->psm == psm) {
  1370. int src_match, dst_match;
  1371. int src_any, dst_any;
  1372. /* Exact match. */
  1373. src_match = !bacmp(&c->src, src);
  1374. dst_match = !bacmp(&c->dst, dst);
  1375. if (src_match && dst_match) {
  1376. l2cap_chan_hold(c);
  1377. read_unlock(&chan_list_lock);
  1378. return c;
  1379. }
  1380. /* Closest match */
  1381. src_any = !bacmp(&c->src, BDADDR_ANY);
  1382. dst_any = !bacmp(&c->dst, BDADDR_ANY);
  1383. if ((src_match && dst_any) || (src_any && dst_match) ||
  1384. (src_any && dst_any))
  1385. c1 = c;
  1386. }
  1387. }
  1388. if (c1)
  1389. l2cap_chan_hold(c1);
  1390. read_unlock(&chan_list_lock);
  1391. return c1;
  1392. }
  1393. static void l2cap_monitor_timeout(struct work_struct *work)
  1394. {
  1395. struct l2cap_chan *chan = container_of(work, struct l2cap_chan,
  1396. monitor_timer.work);
  1397. BT_DBG("chan %p", chan);
  1398. l2cap_chan_lock(chan);
  1399. if (!chan->conn) {
  1400. l2cap_chan_unlock(chan);
  1401. l2cap_chan_put(chan);
  1402. return;
  1403. }
  1404. l2cap_tx(chan, NULL, NULL, L2CAP_EV_MONITOR_TO);
  1405. l2cap_chan_unlock(chan);
  1406. l2cap_chan_put(chan);
  1407. }
  1408. static void l2cap_retrans_timeout(struct work_struct *work)
  1409. {
  1410. struct l2cap_chan *chan = container_of(work, struct l2cap_chan,
  1411. retrans_timer.work);
  1412. BT_DBG("chan %p", chan);
  1413. l2cap_chan_lock(chan);
  1414. if (!chan->conn) {
  1415. l2cap_chan_unlock(chan);
  1416. l2cap_chan_put(chan);
  1417. return;
  1418. }
  1419. l2cap_tx(chan, NULL, NULL, L2CAP_EV_RETRANS_TO);
  1420. l2cap_chan_unlock(chan);
  1421. l2cap_chan_put(chan);
  1422. }
  1423. static void l2cap_streaming_send(struct l2cap_chan *chan,
  1424. struct sk_buff_head *skbs)
  1425. {
  1426. struct sk_buff *skb;
  1427. struct l2cap_ctrl *control;
  1428. BT_DBG("chan %p, skbs %p", chan, skbs);
  1429. if (__chan_is_moving(chan))
  1430. return;
  1431. skb_queue_splice_tail_init(skbs, &chan->tx_q);
  1432. while (!skb_queue_empty(&chan->tx_q)) {
  1433. skb = skb_dequeue(&chan->tx_q);
  1434. bt_cb(skb)->l2cap.retries = 1;
  1435. control = &bt_cb(skb)->l2cap;
  1436. control->reqseq = 0;
  1437. control->txseq = chan->next_tx_seq;
  1438. __pack_control(chan, control, skb);
  1439. if (chan->fcs == L2CAP_FCS_CRC16) {
  1440. u16 fcs = crc16(0, (u8 *) skb->data, skb->len);
  1441. put_unaligned_le16(fcs, skb_put(skb, L2CAP_FCS_SIZE));
  1442. }
  1443. l2cap_do_send(chan, skb);
  1444. BT_DBG("Sent txseq %u", control->txseq);
  1445. chan->next_tx_seq = __next_seq(chan, chan->next_tx_seq);
  1446. chan->frames_sent++;
  1447. }
  1448. }
  1449. static int l2cap_ertm_send(struct l2cap_chan *chan)
  1450. {
  1451. struct sk_buff *skb, *tx_skb;
  1452. struct l2cap_ctrl *control;
  1453. int sent = 0;
  1454. BT_DBG("chan %p", chan);
  1455. if (chan->state != BT_CONNECTED)
  1456. return -ENOTCONN;
  1457. if (test_bit(CONN_REMOTE_BUSY, &chan->conn_state))
  1458. return 0;
  1459. if (__chan_is_moving(chan))
  1460. return 0;
  1461. while (chan->tx_send_head &&
  1462. chan->unacked_frames < chan->remote_tx_win &&
  1463. chan->tx_state == L2CAP_TX_STATE_XMIT) {
  1464. skb = chan->tx_send_head;
  1465. bt_cb(skb)->l2cap.retries = 1;
  1466. control = &bt_cb(skb)->l2cap;
  1467. if (test_and_clear_bit(CONN_SEND_FBIT, &chan->conn_state))
  1468. control->final = 1;
  1469. control->reqseq = chan->buffer_seq;
  1470. chan->last_acked_seq = chan->buffer_seq;
  1471. control->txseq = chan->next_tx_seq;
  1472. __pack_control(chan, control, skb);
  1473. if (chan->fcs == L2CAP_FCS_CRC16) {
  1474. u16 fcs = crc16(0, (u8 *) skb->data, skb->len);
  1475. put_unaligned_le16(fcs, skb_put(skb, L2CAP_FCS_SIZE));
  1476. }
  1477. /* Clone after data has been modified. Data is assumed to be
  1478. read-only (for locking purposes) on cloned sk_buffs.
  1479. */
  1480. tx_skb = skb_clone(skb, GFP_KERNEL);
  1481. if (!tx_skb)
  1482. break;
  1483. __set_retrans_timer(chan);
  1484. chan->next_tx_seq = __next_seq(chan, chan->next_tx_seq);
  1485. chan->unacked_frames++;
  1486. chan->frames_sent++;
  1487. sent++;
  1488. if (skb_queue_is_last(&chan->tx_q, skb))
  1489. chan->tx_send_head = NULL;
  1490. else
  1491. chan->tx_send_head = skb_queue_next(&chan->tx_q, skb);
  1492. l2cap_do_send(chan, tx_skb);
  1493. BT_DBG("Sent txseq %u", control->txseq);
  1494. }
  1495. BT_DBG("Sent %d, %u unacked, %u in ERTM queue", sent,
  1496. chan->unacked_frames, skb_queue_len(&chan->tx_q));
  1497. return sent;
  1498. }
  1499. static void l2cap_ertm_resend(struct l2cap_chan *chan)
  1500. {
  1501. struct l2cap_ctrl control;
  1502. struct sk_buff *skb;
  1503. struct sk_buff *tx_skb;
  1504. u16 seq;
  1505. BT_DBG("chan %p", chan);
  1506. if (test_bit(CONN_REMOTE_BUSY, &chan->conn_state))
  1507. return;
  1508. if (__chan_is_moving(chan))
  1509. return;
  1510. while (chan->retrans_list.head != L2CAP_SEQ_LIST_CLEAR) {
  1511. seq = l2cap_seq_list_pop(&chan->retrans_list);
  1512. skb = l2cap_ertm_seq_in_queue(&chan->tx_q, seq);
  1513. if (!skb) {
  1514. BT_DBG("Error: Can't retransmit seq %d, frame missing",
  1515. seq);
  1516. continue;
  1517. }
  1518. bt_cb(skb)->l2cap.retries++;
  1519. control = bt_cb(skb)->l2cap;
  1520. if (chan->max_tx != 0 &&
  1521. bt_cb(skb)->l2cap.retries > chan->max_tx) {
  1522. BT_DBG("Retry limit exceeded (%d)", chan->max_tx);
  1523. l2cap_send_disconn_req(chan, ECONNRESET);
  1524. l2cap_seq_list_clear(&chan->retrans_list);
  1525. break;
  1526. }
  1527. control.reqseq = chan->buffer_seq;
  1528. if (test_and_clear_bit(CONN_SEND_FBIT, &chan->conn_state))
  1529. control.final = 1;
  1530. else
  1531. control.final = 0;
  1532. if (skb_cloned(skb)) {
  1533. /* Cloned sk_buffs are read-only, so we need a
  1534. * writeable copy
  1535. */
  1536. tx_skb = skb_copy(skb, GFP_KERNEL);
  1537. } else {
  1538. tx_skb = skb_clone(skb, GFP_KERNEL);
  1539. }
  1540. if (!tx_skb) {
  1541. l2cap_seq_list_clear(&chan->retrans_list);
  1542. break;
  1543. }
  1544. /* Update skb contents */
  1545. if (test_bit(FLAG_EXT_CTRL, &chan->flags)) {
  1546. put_unaligned_le32(__pack_extended_control(&control),
  1547. tx_skb->data + L2CAP_HDR_SIZE);
  1548. } else {
  1549. put_unaligned_le16(__pack_enhanced_control(&control),
  1550. tx_skb->data + L2CAP_HDR_SIZE);
  1551. }
  1552. /* Update FCS */
  1553. if (chan->fcs == L2CAP_FCS_CRC16) {
  1554. u16 fcs = crc16(0, (u8 *) tx_skb->data,
  1555. tx_skb->len - L2CAP_FCS_SIZE);
  1556. put_unaligned_le16(fcs, skb_tail_pointer(tx_skb) -
  1557. L2CAP_FCS_SIZE);
  1558. }
  1559. l2cap_do_send(chan, tx_skb);
  1560. BT_DBG("Resent txseq %d", control.txseq);
  1561. chan->last_acked_seq = chan->buffer_seq;
  1562. }
  1563. }
  1564. static void l2cap_retransmit(struct l2cap_chan *chan,
  1565. struct l2cap_ctrl *control)
  1566. {
  1567. BT_DBG("chan %p, control %p", chan, control);
  1568. l2cap_seq_list_append(&chan->retrans_list, control->reqseq);
  1569. l2cap_ertm_resend(chan);
  1570. }
  1571. static void l2cap_retransmit_all(struct l2cap_chan *chan,
  1572. struct l2cap_ctrl *control)
  1573. {
  1574. struct sk_buff *skb;
  1575. BT_DBG("chan %p, control %p", chan, control);
  1576. if (control->poll)
  1577. set_bit(CONN_SEND_FBIT, &chan->conn_state);
  1578. l2cap_seq_list_clear(&chan->retrans_list);
  1579. if (test_bit(CONN_REMOTE_BUSY, &chan->conn_state))
  1580. return;
  1581. if (chan->unacked_frames) {
  1582. skb_queue_walk(&chan->tx_q, skb) {
  1583. if (bt_cb(skb)->l2cap.txseq == control->reqseq ||
  1584. skb == chan->tx_send_head)
  1585. break;
  1586. }
  1587. skb_queue_walk_from(&chan->tx_q, skb) {
  1588. if (skb == chan->tx_send_head)
  1589. break;
  1590. l2cap_seq_list_append(&chan->retrans_list,
  1591. bt_cb(skb)->l2cap.txseq);
  1592. }
  1593. l2cap_ertm_resend(chan);
  1594. }
  1595. }
  1596. static void l2cap_send_ack(struct l2cap_chan *chan)
  1597. {
  1598. struct l2cap_ctrl control;
  1599. u16 frames_to_ack = __seq_offset(chan, chan->buffer_seq,
  1600. chan->last_acked_seq);
  1601. int threshold;
  1602. BT_DBG("chan %p last_acked_seq %d buffer_seq %d",
  1603. chan, chan->last_acked_seq, chan->buffer_seq);
  1604. memset(&control, 0, sizeof(control));
  1605. control.sframe = 1;
  1606. if (test_bit(CONN_LOCAL_BUSY, &chan->conn_state) &&
  1607. chan->rx_state == L2CAP_RX_STATE_RECV) {
  1608. __clear_ack_timer(chan);
  1609. control.super = L2CAP_SUPER_RNR;
  1610. control.reqseq = chan->buffer_seq;
  1611. l2cap_send_sframe(chan, &control);
  1612. } else {
  1613. if (!test_bit(CONN_REMOTE_BUSY, &chan->conn_state)) {
  1614. l2cap_ertm_send(chan);
  1615. /* If any i-frames were sent, they included an ack */
  1616. if (chan->buffer_seq == chan->last_acked_seq)
  1617. frames_to_ack = 0;
  1618. }
  1619. /* Ack now if the window is 3/4ths full.
  1620. * Calculate without mul or div
  1621. */
  1622. threshold = chan->ack_win;
  1623. threshold += threshold << 1;
  1624. threshold >>= 2;
  1625. BT_DBG("frames_to_ack %u, threshold %d", frames_to_ack,
  1626. threshold);
  1627. if (frames_to_ack >= threshold) {
  1628. __clear_ack_timer(chan);
  1629. control.super = L2CAP_SUPER_RR;
  1630. control.reqseq = chan->buffer_seq;
  1631. l2cap_send_sframe(chan, &control);
  1632. frames_to_ack = 0;
  1633. }
  1634. if (frames_to_ack)
  1635. __set_ack_timer(chan);
  1636. }
  1637. }
  1638. static inline int l2cap_skbuff_fromiovec(struct l2cap_chan *chan,
  1639. struct msghdr *msg, int len,
  1640. int count, struct sk_buff *skb)
  1641. {
  1642. struct l2cap_conn *conn = chan->conn;
  1643. struct sk_buff **frag;
  1644. int sent = 0;
  1645. if (copy_from_iter(skb_put(skb, count), count, &msg->msg_iter) != count)
  1646. return -EFAULT;
  1647. sent += count;
  1648. len -= count;
  1649. /* Continuation fragments (no L2CAP header) */
  1650. frag = &skb_shinfo(skb)->frag_list;
  1651. while (len) {
  1652. struct sk_buff *tmp;
  1653. count = min_t(unsigned int, conn->mtu, len);
  1654. tmp = chan->ops->alloc_skb(chan, 0, count,
  1655. msg->msg_flags & MSG_DONTWAIT);
  1656. if (IS_ERR(tmp))
  1657. return PTR_ERR(tmp);
  1658. *frag = tmp;
  1659. if (copy_from_iter(skb_put(*frag, count), count,
  1660. &msg->msg_iter) != count)
  1661. return -EFAULT;
  1662. sent += count;
  1663. len -= count;
  1664. skb->len += (*frag)->len;
  1665. skb->data_len += (*frag)->len;
  1666. frag = &(*frag)->next;
  1667. }
  1668. return sent;
  1669. }
  1670. static struct sk_buff *l2cap_create_connless_pdu(struct l2cap_chan *chan,
  1671. struct msghdr *msg, size_t len)
  1672. {
  1673. struct l2cap_conn *conn = chan->conn;
  1674. struct sk_buff *skb;
  1675. int err, count, hlen = L2CAP_HDR_SIZE + L2CAP_PSMLEN_SIZE;
  1676. struct l2cap_hdr *lh;
  1677. BT_DBG("chan %p psm 0x%2.2x len %zu", chan,
  1678. __le16_to_cpu(chan->psm), len);
  1679. count = min_t(unsigned int, (conn->mtu - hlen), len);
  1680. skb = chan->ops->alloc_skb(chan, hlen, count,
  1681. msg->msg_flags & MSG_DONTWAIT);
  1682. if (IS_ERR(skb))
  1683. return skb;
  1684. /* Create L2CAP header */
  1685. lh = (struct l2cap_hdr *) skb_put(skb, L2CAP_HDR_SIZE);
  1686. lh->cid = cpu_to_le16(chan->dcid);
  1687. lh->len = cpu_to_le16(len + L2CAP_PSMLEN_SIZE);
  1688. put_unaligned(chan->psm, (__le16 *) skb_put(skb, L2CAP_PSMLEN_SIZE));
  1689. err = l2cap_skbuff_fromiovec(chan, msg, len, count, skb);
  1690. if (unlikely(err < 0)) {
  1691. kfree_skb(skb);
  1692. return ERR_PTR(err);
  1693. }
  1694. return skb;
  1695. }
  1696. static struct sk_buff *l2cap_create_basic_pdu(struct l2cap_chan *chan,
  1697. struct msghdr *msg, size_t len)
  1698. {
  1699. struct l2cap_conn *conn = chan->conn;
  1700. struct sk_buff *skb;
  1701. int err, count;
  1702. struct l2cap_hdr *lh;
  1703. BT_DBG("chan %p len %zu", chan, len);
  1704. count = min_t(unsigned int, (conn->mtu - L2CAP_HDR_SIZE), len);
  1705. skb = chan->ops->alloc_skb(chan, L2CAP_HDR_SIZE, count,
  1706. msg->msg_flags & MSG_DONTWAIT);
  1707. if (IS_ERR(skb))
  1708. return skb;
  1709. /* Create L2CAP header */
  1710. lh = (struct l2cap_hdr *) skb_put(skb, L2CAP_HDR_SIZE);
  1711. lh->cid = cpu_to_le16(chan->dcid);
  1712. lh->len = cpu_to_le16(len);
  1713. err = l2cap_skbuff_fromiovec(chan, msg, len, count, skb);
  1714. if (unlikely(err < 0)) {
  1715. kfree_skb(skb);
  1716. return ERR_PTR(err);
  1717. }
  1718. return skb;
  1719. }
  1720. static struct sk_buff *l2cap_create_iframe_pdu(struct l2cap_chan *chan,
  1721. struct msghdr *msg, size_t len,
  1722. u16 sdulen)
  1723. {
  1724. struct l2cap_conn *conn = chan->conn;
  1725. struct sk_buff *skb;
  1726. int err, count, hlen;
  1727. struct l2cap_hdr *lh;
  1728. BT_DBG("chan %p len %zu", chan, len);
  1729. if (!conn)
  1730. return ERR_PTR(-ENOTCONN);
  1731. hlen = __ertm_hdr_size(chan);
  1732. if (sdulen)
  1733. hlen += L2CAP_SDULEN_SIZE;
  1734. if (chan->fcs == L2CAP_FCS_CRC16)
  1735. hlen += L2CAP_FCS_SIZE;
  1736. count = min_t(unsigned int, (conn->mtu - hlen), len);
  1737. skb = chan->ops->alloc_skb(chan, hlen, count,
  1738. msg->msg_flags & MSG_DONTWAIT);
  1739. if (IS_ERR(skb))
  1740. return skb;
  1741. /* Create L2CAP header */
  1742. lh = (struct l2cap_hdr *) skb_put(skb, L2CAP_HDR_SIZE);
  1743. lh->cid = cpu_to_le16(chan->dcid);
  1744. lh->len = cpu_to_le16(len + (hlen - L2CAP_HDR_SIZE));
  1745. /* Control header is populated later */
  1746. if (test_bit(FLAG_EXT_CTRL, &chan->flags))
  1747. put_unaligned_le32(0, skb_put(skb, L2CAP_EXT_CTRL_SIZE));
  1748. else
  1749. put_unaligned_le16(0, skb_put(skb, L2CAP_ENH_CTRL_SIZE));
  1750. if (sdulen)
  1751. put_unaligned_le16(sdulen, skb_put(skb, L2CAP_SDULEN_SIZE));
  1752. err = l2cap_skbuff_fromiovec(chan, msg, len, count, skb);
  1753. if (unlikely(err < 0)) {
  1754. kfree_skb(skb);
  1755. return ERR_PTR(err);
  1756. }
  1757. bt_cb(skb)->l2cap.fcs = chan->fcs;
  1758. bt_cb(skb)->l2cap.retries = 0;
  1759. return skb;
  1760. }
  1761. static int l2cap_segment_sdu(struct l2cap_chan *chan,
  1762. struct sk_buff_head *seg_queue,
  1763. struct msghdr *msg, size_t len)
  1764. {
  1765. struct sk_buff *skb;
  1766. u16 sdu_len;
  1767. size_t pdu_len;
  1768. u8 sar;
  1769. BT_DBG("chan %p, msg %p, len %zu", chan, msg, len);
  1770. /* It is critical that ERTM PDUs fit in a single HCI fragment,
  1771. * so fragmented skbs are not used. The HCI layer's handling
  1772. * of fragmented skbs is not compatible with ERTM's queueing.
  1773. */
  1774. /* PDU size is derived from the HCI MTU */
  1775. pdu_len = chan->conn->mtu;
  1776. /* Constrain PDU size for BR/EDR connections */
  1777. if (!chan->hs_hcon)
  1778. pdu_len = min_t(size_t, pdu_len, L2CAP_BREDR_MAX_PAYLOAD);
  1779. /* Adjust for largest possible L2CAP overhead. */
  1780. if (chan->fcs)
  1781. pdu_len -= L2CAP_FCS_SIZE;
  1782. pdu_len -= __ertm_hdr_size(chan);
  1783. /* Remote device may have requested smaller PDUs */
  1784. pdu_len = min_t(size_t, pdu_len, chan->remote_mps);
  1785. if (len <= pdu_len) {
  1786. sar = L2CAP_SAR_UNSEGMENTED;
  1787. sdu_len = 0;
  1788. pdu_len = len;
  1789. } else {
  1790. sar = L2CAP_SAR_START;
  1791. sdu_len = len;
  1792. }
  1793. while (len > 0) {
  1794. skb = l2cap_create_iframe_pdu(chan, msg, pdu_len, sdu_len);
  1795. if (IS_ERR(skb)) {
  1796. __skb_queue_purge(seg_queue);
  1797. return PTR_ERR(skb);
  1798. }
  1799. bt_cb(skb)->l2cap.sar = sar;
  1800. __skb_queue_tail(seg_queue, skb);
  1801. len -= pdu_len;
  1802. if (sdu_len)
  1803. sdu_len = 0;
  1804. if (len <= pdu_len) {
  1805. sar = L2CAP_SAR_END;
  1806. pdu_len = len;
  1807. } else {
  1808. sar = L2CAP_SAR_CONTINUE;
  1809. }
  1810. }
  1811. return 0;
  1812. }
  1813. static struct sk_buff *l2cap_create_le_flowctl_pdu(struct l2cap_chan *chan,
  1814. struct msghdr *msg,
  1815. size_t len, u16 sdulen)
  1816. {
  1817. struct l2cap_conn *conn = chan->conn;
  1818. struct sk_buff *skb;
  1819. int err, count, hlen;
  1820. struct l2cap_hdr *lh;
  1821. BT_DBG("chan %p len %zu", chan, len);
  1822. if (!conn)
  1823. return ERR_PTR(-ENOTCONN);
  1824. hlen = L2CAP_HDR_SIZE;
  1825. if (sdulen)
  1826. hlen += L2CAP_SDULEN_SIZE;
  1827. count = min_t(unsigned int, (conn->mtu - hlen), len);
  1828. skb = chan->ops->alloc_skb(chan, hlen, count,
  1829. msg->msg_flags & MSG_DONTWAIT);
  1830. if (IS_ERR(skb))
  1831. return skb;
  1832. /* Create L2CAP header */
  1833. lh = (struct l2cap_hdr *) skb_put(skb, L2CAP_HDR_SIZE);
  1834. lh->cid = cpu_to_le16(chan->dcid);
  1835. lh->len = cpu_to_le16(len + (hlen - L2CAP_HDR_SIZE));
  1836. if (sdulen)
  1837. put_unaligned_le16(sdulen, skb_put(skb, L2CAP_SDULEN_SIZE));
  1838. err = l2cap_skbuff_fromiovec(chan, msg, len, count, skb);
  1839. if (unlikely(err < 0)) {
  1840. kfree_skb(skb);
  1841. return ERR_PTR(err);
  1842. }
  1843. return skb;
  1844. }
  1845. static int l2cap_segment_le_sdu(struct l2cap_chan *chan,
  1846. struct sk_buff_head *seg_queue,
  1847. struct msghdr *msg, size_t len)
  1848. {
  1849. struct sk_buff *skb;
  1850. size_t pdu_len;
  1851. u16 sdu_len;
  1852. BT_DBG("chan %p, msg %p, len %zu", chan, msg, len);
  1853. sdu_len = len;
  1854. pdu_len = chan->remote_mps - L2CAP_SDULEN_SIZE;
  1855. while (len > 0) {
  1856. if (len <= pdu_len)
  1857. pdu_len = len;
  1858. skb = l2cap_create_le_flowctl_pdu(chan, msg, pdu_len, sdu_len);
  1859. if (IS_ERR(skb)) {
  1860. __skb_queue_purge(seg_queue);
  1861. return PTR_ERR(skb);
  1862. }
  1863. __skb_queue_tail(seg_queue, skb);
  1864. len -= pdu_len;
  1865. if (sdu_len) {
  1866. sdu_len = 0;
  1867. pdu_len += L2CAP_SDULEN_SIZE;
  1868. }
  1869. }
  1870. return 0;
  1871. }
  1872. int l2cap_chan_send(struct l2cap_chan *chan, struct msghdr *msg, size_t len)
  1873. {
  1874. struct sk_buff *skb;
  1875. int err;
  1876. struct sk_buff_head seg_queue;
  1877. if (!chan->conn)
  1878. return -ENOTCONN;
  1879. /* Connectionless channel */
  1880. if (chan->chan_type == L2CAP_CHAN_CONN_LESS) {
  1881. skb = l2cap_create_connless_pdu(chan, msg, len);
  1882. if (IS_ERR(skb))
  1883. return PTR_ERR(skb);
  1884. /* Channel lock is released before requesting new skb and then
  1885. * reacquired thus we need to recheck channel state.
  1886. */
  1887. if (chan->state != BT_CONNECTED) {
  1888. kfree_skb(skb);
  1889. return -ENOTCONN;
  1890. }
  1891. l2cap_do_send(chan, skb);
  1892. return len;
  1893. }
  1894. switch (chan->mode) {
  1895. case L2CAP_MODE_LE_FLOWCTL:
  1896. /* Check outgoing MTU */
  1897. if (len > chan->omtu)
  1898. return -EMSGSIZE;
  1899. if (!chan->tx_credits)
  1900. return -EAGAIN;
  1901. __skb_queue_head_init(&seg_queue);
  1902. err = l2cap_segment_le_sdu(chan, &seg_queue, msg, len);
  1903. if (chan->state != BT_CONNECTED) {
  1904. __skb_queue_purge(&seg_queue);
  1905. err = -ENOTCONN;
  1906. }
  1907. if (err)
  1908. return err;
  1909. skb_queue_splice_tail_init(&seg_queue, &chan->tx_q);
  1910. while (chan->tx_credits && !skb_queue_empty(&chan->tx_q)) {
  1911. l2cap_do_send(chan, skb_dequeue(&chan->tx_q));
  1912. chan->tx_credits--;
  1913. }
  1914. if (!chan->tx_credits)
  1915. chan->ops->suspend(chan);
  1916. err = len;
  1917. break;
  1918. case L2CAP_MODE_BASIC:
  1919. /* Check outgoing MTU */
  1920. if (len > chan->omtu)
  1921. return -EMSGSIZE;
  1922. /* Create a basic PDU */
  1923. skb = l2cap_create_basic_pdu(chan, msg, len);
  1924. if (IS_ERR(skb))
  1925. return PTR_ERR(skb);
  1926. /* Channel lock is released before requesting new skb and then
  1927. * reacquired thus we need to recheck channel state.
  1928. */
  1929. if (chan->state != BT_CONNECTED) {
  1930. kfree_skb(skb);
  1931. return -ENOTCONN;
  1932. }
  1933. l2cap_do_send(chan, skb);
  1934. err = len;
  1935. break;
  1936. case L2CAP_MODE_ERTM:
  1937. case L2CAP_MODE_STREAMING:
  1938. /* Check outgoing MTU */
  1939. if (len > chan->omtu) {
  1940. err = -EMSGSIZE;
  1941. break;
  1942. }
  1943. __skb_queue_head_init(&seg_queue);
  1944. /* Do segmentation before calling in to the state machine,
  1945. * since it's possible to block while waiting for memory
  1946. * allocation.
  1947. */
  1948. err = l2cap_segment_sdu(chan, &seg_queue, msg, len);
  1949. /* The channel could have been closed while segmenting,
  1950. * check that it is still connected.
  1951. */
  1952. if (chan->state != BT_CONNECTED) {
  1953. __skb_queue_purge(&seg_queue);
  1954. err = -ENOTCONN;
  1955. }
  1956. if (err)
  1957. break;
  1958. if (chan->mode == L2CAP_MODE_ERTM)
  1959. l2cap_tx(chan, NULL, &seg_queue, L2CAP_EV_DATA_REQUEST);
  1960. else
  1961. l2cap_streaming_send(chan, &seg_queue);
  1962. err = len;
  1963. /* If the skbs were not queued for sending, they'll still be in
  1964. * seg_queue and need to be purged.
  1965. */
  1966. __skb_queue_purge(&seg_queue);
  1967. break;
  1968. default:
  1969. BT_DBG("bad state %1.1x", chan->mode);
  1970. err = -EBADFD;
  1971. }
  1972. return err;
  1973. }
  1974. EXPORT_SYMBOL_GPL(l2cap_chan_send);
  1975. static void l2cap_send_srej(struct l2cap_chan *chan, u16 txseq)
  1976. {
  1977. struct l2cap_ctrl control;
  1978. u16 seq;
  1979. BT_DBG("chan %p, txseq %u", chan, txseq);
  1980. memset(&control, 0, sizeof(control));
  1981. control.sframe = 1;
  1982. control.super = L2CAP_SUPER_SREJ;
  1983. for (seq = chan->expected_tx_seq; seq != txseq;
  1984. seq = __next_seq(chan, seq)) {
  1985. if (!l2cap_ertm_seq_in_queue(&chan->srej_q, seq)) {
  1986. control.reqseq = seq;
  1987. l2cap_send_sframe(chan, &control);
  1988. l2cap_seq_list_append(&chan->srej_list, seq);
  1989. }
  1990. }
  1991. chan->expected_tx_seq = __next_seq(chan, txseq);
  1992. }
  1993. static void l2cap_send_srej_tail(struct l2cap_chan *chan)
  1994. {
  1995. struct l2cap_ctrl control;
  1996. BT_DBG("chan %p", chan);
  1997. if (chan->srej_list.tail == L2CAP_SEQ_LIST_CLEAR)
  1998. return;
  1999. memset(&control, 0, sizeof(control));
  2000. control.sframe = 1;
  2001. control.super = L2CAP_SUPER_SREJ;
  2002. control.reqseq = chan->srej_list.tail;
  2003. l2cap_send_sframe(chan, &control);
  2004. }
  2005. static void l2cap_send_srej_list(struct l2cap_chan *chan, u16 txseq)
  2006. {
  2007. struct l2cap_ctrl control;
  2008. u16 initial_head;
  2009. u16 seq;
  2010. BT_DBG("chan %p, txseq %u", chan, txseq);
  2011. memset(&control, 0, sizeof(control));
  2012. control.sframe = 1;
  2013. control.super = L2CAP_SUPER_SREJ;
  2014. /* Capture initial list head to allow only one pass through the list. */
  2015. initial_head = chan->srej_list.head;
  2016. do {
  2017. seq = l2cap_seq_list_pop(&chan->srej_list);
  2018. if (seq == txseq || seq == L2CAP_SEQ_LIST_CLEAR)
  2019. break;
  2020. control.reqseq = seq;
  2021. l2cap_send_sframe(chan, &control);
  2022. l2cap_seq_list_append(&chan->srej_list, seq);
  2023. } while (chan->srej_list.head != initial_head);
  2024. }
  2025. static void l2cap_process_reqseq(struct l2cap_chan *chan, u16 reqseq)
  2026. {
  2027. struct sk_buff *acked_skb;
  2028. u16 ackseq;
  2029. BT_DBG("chan %p, reqseq %u", chan, reqseq);
  2030. if (chan->unacked_frames == 0 || reqseq == chan->expected_ack_seq)
  2031. return;
  2032. BT_DBG("expected_ack_seq %u, unacked_frames %u",
  2033. chan->expected_ack_seq, chan->unacked_frames);
  2034. for (ackseq = chan->expected_ack_seq; ackseq != reqseq;
  2035. ackseq = __next_seq(chan, ackseq)) {
  2036. acked_skb = l2cap_ertm_seq_in_queue(&chan->tx_q, ackseq);
  2037. if (acked_skb) {
  2038. skb_unlink(acked_skb, &chan->tx_q);
  2039. kfree_skb(acked_skb);
  2040. chan->unacked_frames--;
  2041. }
  2042. }
  2043. chan->expected_ack_seq = reqseq;
  2044. if (chan->unacked_frames == 0)
  2045. __clear_retrans_timer(chan);
  2046. BT_DBG("unacked_frames %u", chan->unacked_frames);
  2047. }
  2048. static void l2cap_abort_rx_srej_sent(struct l2cap_chan *chan)
  2049. {
  2050. BT_DBG("chan %p", chan);
  2051. chan->expected_tx_seq = chan->buffer_seq;
  2052. l2cap_seq_list_clear(&chan->srej_list);
  2053. skb_queue_purge(&chan->srej_q);
  2054. chan->rx_state = L2CAP_RX_STATE_RECV;
  2055. }
  2056. static void l2cap_tx_state_xmit(struct l2cap_chan *chan,
  2057. struct l2cap_ctrl *control,
  2058. struct sk_buff_head *skbs, u8 event)
  2059. {
  2060. BT_DBG("chan %p, control %p, skbs %p, event %d", chan, control, skbs,
  2061. event);
  2062. switch (event) {
  2063. case L2CAP_EV_DATA_REQUEST:
  2064. if (chan->tx_send_head == NULL)
  2065. chan->tx_send_head = skb_peek(skbs);
  2066. skb_queue_splice_tail_init(skbs, &chan->tx_q);
  2067. l2cap_ertm_send(chan);
  2068. break;
  2069. case L2CAP_EV_LOCAL_BUSY_DETECTED:
  2070. BT_DBG("Enter LOCAL_BUSY");
  2071. set_bit(CONN_LOCAL_BUSY, &chan->conn_state);
  2072. if (chan->rx_state == L2CAP_RX_STATE_SREJ_SENT) {
  2073. /* The SREJ_SENT state must be aborted if we are to
  2074. * enter the LOCAL_BUSY state.
  2075. */
  2076. l2cap_abort_rx_srej_sent(chan);
  2077. }
  2078. l2cap_send_ack(chan);
  2079. break;
  2080. case L2CAP_EV_LOCAL_BUSY_CLEAR:
  2081. BT_DBG("Exit LOCAL_BUSY");
  2082. clear_bit(CONN_LOCAL_BUSY, &chan->conn_state);
  2083. if (test_bit(CONN_RNR_SENT, &chan->conn_state)) {
  2084. struct l2cap_ctrl local_control;
  2085. memset(&local_control, 0, sizeof(local_control));
  2086. local_control.sframe = 1;
  2087. local_control.super = L2CAP_SUPER_RR;
  2088. local_control.poll = 1;
  2089. local_control.reqseq = chan->buffer_seq;
  2090. l2cap_send_sframe(chan, &local_control);
  2091. chan->retry_count = 1;
  2092. __set_monitor_timer(chan);
  2093. chan->tx_state = L2CAP_TX_STATE_WAIT_F;
  2094. }
  2095. break;
  2096. case L2CAP_EV_RECV_REQSEQ_AND_FBIT:
  2097. l2cap_process_reqseq(chan, control->reqseq);
  2098. break;
  2099. case L2CAP_EV_EXPLICIT_POLL:
  2100. l2cap_send_rr_or_rnr(chan, 1);
  2101. chan->retry_count = 1;
  2102. __set_monitor_timer(chan);
  2103. __clear_ack_timer(chan);
  2104. chan->tx_state = L2CAP_TX_STATE_WAIT_F;
  2105. break;
  2106. case L2CAP_EV_RETRANS_TO:
  2107. l2cap_send_rr_or_rnr(chan, 1);
  2108. chan->retry_count = 1;
  2109. __set_monitor_timer(chan);
  2110. chan->tx_state = L2CAP_TX_STATE_WAIT_F;
  2111. break;
  2112. case L2CAP_EV_RECV_FBIT:
  2113. /* Nothing to process */
  2114. break;
  2115. default:
  2116. break;
  2117. }
  2118. }
  2119. static void l2cap_tx_state_wait_f(struct l2cap_chan *chan,
  2120. struct l2cap_ctrl *control,
  2121. struct sk_buff_head *skbs, u8 event)
  2122. {
  2123. BT_DBG("chan %p, control %p, skbs %p, event %d", chan, control, skbs,
  2124. event);
  2125. switch (event) {
  2126. case L2CAP_EV_DATA_REQUEST:
  2127. if (chan->tx_send_head == NULL)
  2128. chan->tx_send_head = skb_peek(skbs);
  2129. /* Queue data, but don't send. */
  2130. skb_queue_splice_tail_init(skbs, &chan->tx_q);
  2131. break;
  2132. case L2CAP_EV_LOCAL_BUSY_DETECTED:
  2133. BT_DBG("Enter LOCAL_BUSY");
  2134. set_bit(CONN_LOCAL_BUSY, &chan->conn_state);
  2135. if (chan->rx_state == L2CAP_RX_STATE_SREJ_SENT) {
  2136. /* The SREJ_SENT state must be aborted if we are to
  2137. * enter the LOCAL_BUSY state.
  2138. */
  2139. l2cap_abort_rx_srej_sent(chan);
  2140. }
  2141. l2cap_send_ack(chan);
  2142. break;
  2143. case L2CAP_EV_LOCAL_BUSY_CLEAR:
  2144. BT_DBG("Exit LOCAL_BUSY");
  2145. clear_bit(CONN_LOCAL_BUSY, &chan->conn_state);
  2146. if (test_bit(CONN_RNR_SENT, &chan->conn_state)) {
  2147. struct l2cap_ctrl local_control;
  2148. memset(&local_control, 0, sizeof(local_control));
  2149. local_control.sframe = 1;
  2150. local_control.super = L2CAP_SUPER_RR;
  2151. local_control.poll = 1;
  2152. local_control.reqseq = chan->buffer_seq;
  2153. l2cap_send_sframe(chan, &local_control);
  2154. chan->retry_count = 1;
  2155. __set_monitor_timer(chan);
  2156. chan->tx_state = L2CAP_TX_STATE_WAIT_F;
  2157. }
  2158. break;
  2159. case L2CAP_EV_RECV_REQSEQ_AND_FBIT:
  2160. l2cap_process_reqseq(chan, control->reqseq);
  2161. /* Fall through */
  2162. case L2CAP_EV_RECV_FBIT:
  2163. if (control && control->final) {
  2164. __clear_monitor_timer(chan);
  2165. if (chan->unacked_frames > 0)
  2166. __set_retrans_timer(chan);
  2167. chan->retry_count = 0;
  2168. chan->tx_state = L2CAP_TX_STATE_XMIT;
  2169. BT_DBG("recv fbit tx_state 0x2.2%x", chan->tx_state);
  2170. }
  2171. break;
  2172. case L2CAP_EV_EXPLICIT_POLL:
  2173. /* Ignore */
  2174. break;
  2175. case L2CAP_EV_MONITOR_TO:
  2176. if (chan->max_tx == 0 || chan->retry_count < chan->max_tx) {
  2177. l2cap_send_rr_or_rnr(chan, 1);
  2178. __set_monitor_timer(chan);
  2179. chan->retry_count++;
  2180. } else {
  2181. l2cap_send_disconn_req(chan, ECONNABORTED);
  2182. }
  2183. break;
  2184. default:
  2185. break;
  2186. }
  2187. }
  2188. static void l2cap_tx(struct l2cap_chan *chan, struct l2cap_ctrl *control,
  2189. struct sk_buff_head *skbs, u8 event)
  2190. {
  2191. BT_DBG("chan %p, control %p, skbs %p, event %d, state %d",
  2192. chan, control, skbs, event, chan->tx_state);
  2193. switch (chan->tx_state) {
  2194. case L2CAP_TX_STATE_XMIT:
  2195. l2cap_tx_state_xmit(chan, control, skbs, event);
  2196. break;
  2197. case L2CAP_TX_STATE_WAIT_F:
  2198. l2cap_tx_state_wait_f(chan, control, skbs, event);
  2199. break;
  2200. default:
  2201. /* Ignore event */
  2202. break;
  2203. }
  2204. }
  2205. static void l2cap_pass_to_tx(struct l2cap_chan *chan,
  2206. struct l2cap_ctrl *control)
  2207. {
  2208. BT_DBG("chan %p, control %p", chan, control);
  2209. l2cap_tx(chan, control, NULL, L2CAP_EV_RECV_REQSEQ_AND_FBIT);
  2210. }
  2211. static void l2cap_pass_to_tx_fbit(struct l2cap_chan *chan,
  2212. struct l2cap_ctrl *control)
  2213. {
  2214. BT_DBG("chan %p, control %p", chan, control);
  2215. l2cap_tx(chan, control, NULL, L2CAP_EV_RECV_FBIT);
  2216. }
  2217. /* Copy frame to all raw sockets on that connection */
  2218. static void l2cap_raw_recv(struct l2cap_conn *conn, struct sk_buff *skb)
  2219. {
  2220. struct sk_buff *nskb;
  2221. struct l2cap_chan *chan;
  2222. BT_DBG("conn %p", conn);
  2223. mutex_lock(&conn->chan_lock);
  2224. list_for_each_entry(chan, &conn->chan_l, list) {
  2225. if (chan->chan_type != L2CAP_CHAN_RAW)
  2226. continue;
  2227. /* Don't send frame to the channel it came from */
  2228. if (bt_cb(skb)->l2cap.chan == chan)
  2229. continue;
  2230. nskb = skb_clone(skb, GFP_KERNEL);
  2231. if (!nskb)
  2232. continue;
  2233. if (chan->ops->recv(chan, nskb))
  2234. kfree_skb(nskb);
  2235. }
  2236. mutex_unlock(&conn->chan_lock);
  2237. }
  2238. /* ---- L2CAP signalling commands ---- */
  2239. static struct sk_buff *l2cap_build_cmd(struct l2cap_conn *conn, u8 code,
  2240. u8 ident, u16 dlen, void *data)
  2241. {
  2242. struct sk_buff *skb, **frag;
  2243. struct l2cap_cmd_hdr *cmd;
  2244. struct l2cap_hdr *lh;
  2245. int len, count;
  2246. BT_DBG("conn %p, code 0x%2.2x, ident 0x%2.2x, len %u",
  2247. conn, code, ident, dlen);
  2248. if (conn->mtu < L2CAP_HDR_SIZE + L2CAP_CMD_HDR_SIZE)
  2249. return NULL;
  2250. len = L2CAP_HDR_SIZE + L2CAP_CMD_HDR_SIZE + dlen;
  2251. count = min_t(unsigned int, conn->mtu, len);
  2252. skb = bt_skb_alloc(count, GFP_KERNEL);
  2253. if (!skb)
  2254. return NULL;
  2255. lh = (struct l2cap_hdr *) skb_put(skb, L2CAP_HDR_SIZE);
  2256. lh->len = cpu_to_le16(L2CAP_CMD_HDR_SIZE + dlen);
  2257. if (conn->hcon->type == LE_LINK)
  2258. lh->cid = cpu_to_le16(L2CAP_CID_LE_SIGNALING);
  2259. else
  2260. lh->cid = cpu_to_le16(L2CAP_CID_SIGNALING);
  2261. cmd = (struct l2cap_cmd_hdr *) skb_put(skb, L2CAP_CMD_HDR_SIZE);
  2262. cmd->code = code;
  2263. cmd->ident = ident;
  2264. cmd->len = cpu_to_le16(dlen);
  2265. if (dlen) {
  2266. count -= L2CAP_HDR_SIZE + L2CAP_CMD_HDR_SIZE;
  2267. memcpy(skb_put(skb, count), data, count);
  2268. data += count;
  2269. }
  2270. len -= skb->len;
  2271. /* Continuation fragments (no L2CAP header) */
  2272. frag = &skb_shinfo(skb)->frag_list;
  2273. while (len) {
  2274. count = min_t(unsigned int, conn->mtu, len);
  2275. *frag = bt_skb_alloc(count, GFP_KERNEL);
  2276. if (!*frag)
  2277. goto fail;
  2278. memcpy(skb_put(*frag, count), data, count);
  2279. len -= count;
  2280. data += count;
  2281. frag = &(*frag)->next;
  2282. }
  2283. return skb;
  2284. fail:
  2285. kfree_skb(skb);
  2286. return NULL;
  2287. }
  2288. static inline int l2cap_get_conf_opt(void **ptr, int *type, int *olen,
  2289. unsigned long *val)
  2290. {
  2291. struct l2cap_conf_opt *opt = *ptr;
  2292. int len;
  2293. len = L2CAP_CONF_OPT_SIZE + opt->len;
  2294. *ptr += len;
  2295. *type = opt->type;
  2296. *olen = opt->len;
  2297. switch (opt->len) {
  2298. case 1:
  2299. *val = *((u8 *) opt->val);
  2300. break;
  2301. case 2:
  2302. *val = get_unaligned_le16(opt->val);
  2303. break;
  2304. case 4:
  2305. *val = get_unaligned_le32(opt->val);
  2306. break;
  2307. default:
  2308. *val = (unsigned long) opt->val;
  2309. break;
  2310. }
  2311. BT_DBG("type 0x%2.2x len %u val 0x%lx", *type, opt->len, *val);
  2312. return len;
  2313. }
  2314. static void l2cap_add_conf_opt(void **ptr, u8 type, u8 len, unsigned long val, size_t size)
  2315. {
  2316. struct l2cap_conf_opt *opt = *ptr;
  2317. BT_DBG("type 0x%2.2x len %u val 0x%lx", type, len, val);
  2318. if (size < L2CAP_CONF_OPT_SIZE + len)
  2319. return;
  2320. opt->type = type;
  2321. opt->len = len;
  2322. switch (len) {
  2323. case 1:
  2324. *((u8 *) opt->val) = val;
  2325. break;
  2326. case 2:
  2327. put_unaligned_le16(val, opt->val);
  2328. break;
  2329. case 4:
  2330. put_unaligned_le32(val, opt->val);
  2331. break;
  2332. default:
  2333. memcpy(opt->val, (void *) val, len);
  2334. break;
  2335. }
  2336. *ptr += L2CAP_CONF_OPT_SIZE + len;
  2337. }
  2338. static void l2cap_add_opt_efs(void **ptr, struct l2cap_chan *chan, size_t size)
  2339. {
  2340. struct l2cap_conf_efs efs;
  2341. switch (chan->mode) {
  2342. case L2CAP_MODE_ERTM:
  2343. efs.id = chan->local_id;
  2344. efs.stype = chan->local_stype;
  2345. efs.msdu = cpu_to_le16(chan->local_msdu);
  2346. efs.sdu_itime = cpu_to_le32(chan->local_sdu_itime);
  2347. efs.acc_lat = cpu_to_le32(L2CAP_DEFAULT_ACC_LAT);
  2348. efs.flush_to = cpu_to_le32(L2CAP_EFS_DEFAULT_FLUSH_TO);
  2349. break;
  2350. case L2CAP_MODE_STREAMING:
  2351. efs.id = 1;
  2352. efs.stype = L2CAP_SERV_BESTEFFORT;
  2353. efs.msdu = cpu_to_le16(chan->local_msdu);
  2354. efs.sdu_itime = cpu_to_le32(chan->local_sdu_itime);
  2355. efs.acc_lat = 0;
  2356. efs.flush_to = 0;
  2357. break;
  2358. default:
  2359. return;
  2360. }
  2361. l2cap_add_conf_opt(ptr, L2CAP_CONF_EFS, sizeof(efs),
  2362. (unsigned long) &efs, size);
  2363. }
  2364. static void l2cap_ack_timeout(struct work_struct *work)
  2365. {
  2366. struct l2cap_chan *chan = container_of(work, struct l2cap_chan,
  2367. ack_timer.work);
  2368. u16 frames_to_ack;
  2369. BT_DBG("chan %p", chan);
  2370. l2cap_chan_lock(chan);
  2371. frames_to_ack = __seq_offset(chan, chan->buffer_seq,
  2372. chan->last_acked_seq);
  2373. if (frames_to_ack)
  2374. l2cap_send_rr_or_rnr(chan, 0);
  2375. l2cap_chan_unlock(chan);
  2376. l2cap_chan_put(chan);
  2377. }
  2378. int l2cap_ertm_init(struct l2cap_chan *chan)
  2379. {
  2380. int err;
  2381. chan->next_tx_seq = 0;
  2382. chan->expected_tx_seq = 0;
  2383. chan->expected_ack_seq = 0;
  2384. chan->unacked_frames = 0;
  2385. chan->buffer_seq = 0;
  2386. chan->frames_sent = 0;
  2387. chan->last_acked_seq = 0;
  2388. chan->sdu = NULL;
  2389. chan->sdu_last_frag = NULL;
  2390. chan->sdu_len = 0;
  2391. skb_queue_head_init(&chan->tx_q);
  2392. chan->local_amp_id = AMP_ID_BREDR;
  2393. chan->move_id = AMP_ID_BREDR;
  2394. chan->move_state = L2CAP_MOVE_STABLE;
  2395. chan->move_role = L2CAP_MOVE_ROLE_NONE;
  2396. if (chan->mode != L2CAP_MODE_ERTM)
  2397. return 0;
  2398. chan->rx_state = L2CAP_RX_STATE_RECV;
  2399. chan->tx_state = L2CAP_TX_STATE_XMIT;
  2400. INIT_DELAYED_WORK(&chan->retrans_timer, l2cap_retrans_timeout);
  2401. INIT_DELAYED_WORK(&chan->monitor_timer, l2cap_monitor_timeout);
  2402. INIT_DELAYED_WORK(&chan->ack_timer, l2cap_ack_timeout);
  2403. skb_queue_head_init(&chan->srej_q);
  2404. err = l2cap_seq_list_init(&chan->srej_list, chan->tx_win);
  2405. if (err < 0)
  2406. return err;
  2407. err = l2cap_seq_list_init(&chan->retrans_list, chan->remote_tx_win);
  2408. if (err < 0)
  2409. l2cap_seq_list_free(&chan->srej_list);
  2410. return err;
  2411. }
  2412. static inline __u8 l2cap_select_mode(__u8 mode, __u16 remote_feat_mask)
  2413. {
  2414. switch (mode) {
  2415. case L2CAP_MODE_STREAMING:
  2416. case L2CAP_MODE_ERTM:
  2417. if (l2cap_mode_supported(mode, remote_feat_mask))
  2418. return mode;
  2419. /* fall through */
  2420. default:
  2421. return L2CAP_MODE_BASIC;
  2422. }
  2423. }
  2424. static inline bool __l2cap_ews_supported(struct l2cap_conn *conn)
  2425. {
  2426. return ((conn->local_fixed_chan & L2CAP_FC_A2MP) &&
  2427. (conn->feat_mask & L2CAP_FEAT_EXT_WINDOW));
  2428. }
  2429. static inline bool __l2cap_efs_supported(struct l2cap_conn *conn)
  2430. {
  2431. return ((conn->local_fixed_chan & L2CAP_FC_A2MP) &&
  2432. (conn->feat_mask & L2CAP_FEAT_EXT_FLOW));
  2433. }
  2434. static void __l2cap_set_ertm_timeouts(struct l2cap_chan *chan,
  2435. struct l2cap_conf_rfc *rfc)
  2436. {
  2437. if (chan->local_amp_id != AMP_ID_BREDR && chan->hs_hcon) {
  2438. u64 ertm_to = chan->hs_hcon->hdev->amp_be_flush_to;
  2439. /* Class 1 devices have must have ERTM timeouts
  2440. * exceeding the Link Supervision Timeout. The
  2441. * default Link Supervision Timeout for AMP
  2442. * controllers is 10 seconds.
  2443. *
  2444. * Class 1 devices use 0xffffffff for their
  2445. * best-effort flush timeout, so the clamping logic
  2446. * will result in a timeout that meets the above
  2447. * requirement. ERTM timeouts are 16-bit values, so
  2448. * the maximum timeout is 65.535 seconds.
  2449. */
  2450. /* Convert timeout to milliseconds and round */
  2451. ertm_to = DIV_ROUND_UP_ULL(ertm_to, 1000);
  2452. /* This is the recommended formula for class 2 devices
  2453. * that start ERTM timers when packets are sent to the
  2454. * controller.
  2455. */
  2456. ertm_to = 3 * ertm_to + 500;
  2457. if (ertm_to > 0xffff)
  2458. ertm_to = 0xffff;
  2459. rfc->retrans_timeout = cpu_to_le16((u16) ertm_to);
  2460. rfc->monitor_timeout = rfc->retrans_timeout;
  2461. } else {
  2462. rfc->retrans_timeout = cpu_to_le16(L2CAP_DEFAULT_RETRANS_TO);
  2463. rfc->monitor_timeout = cpu_to_le16(L2CAP_DEFAULT_MONITOR_TO);
  2464. }
  2465. }
  2466. static inline void l2cap_txwin_setup(struct l2cap_chan *chan)
  2467. {
  2468. if (chan->tx_win > L2CAP_DEFAULT_TX_WINDOW &&
  2469. __l2cap_ews_supported(chan->conn)) {
  2470. /* use extended control field */
  2471. set_bit(FLAG_EXT_CTRL, &chan->flags);
  2472. chan->tx_win_max = L2CAP_DEFAULT_EXT_WINDOW;
  2473. } else {
  2474. chan->tx_win = min_t(u16, chan->tx_win,
  2475. L2CAP_DEFAULT_TX_WINDOW);
  2476. chan->tx_win_max = L2CAP_DEFAULT_TX_WINDOW;
  2477. }
  2478. chan->ack_win = chan->tx_win;
  2479. }
  2480. static int l2cap_build_conf_req(struct l2cap_chan *chan, void *data, size_t data_size)
  2481. {
  2482. struct l2cap_conf_req *req = data;
  2483. struct l2cap_conf_rfc rfc = { .mode = chan->mode };
  2484. void *ptr = req->data;
  2485. void *endptr = data + data_size;
  2486. u16 size;
  2487. BT_DBG("chan %p", chan);
  2488. if (chan->num_conf_req || chan->num_conf_rsp)
  2489. goto done;
  2490. switch (chan->mode) {
  2491. case L2CAP_MODE_STREAMING:
  2492. case L2CAP_MODE_ERTM:
  2493. if (test_bit(CONF_STATE2_DEVICE, &chan->conf_state))
  2494. break;
  2495. if (__l2cap_efs_supported(chan->conn))
  2496. set_bit(FLAG_EFS_ENABLE, &chan->flags);
  2497. /* fall through */
  2498. default:
  2499. chan->mode = l2cap_select_mode(rfc.mode, chan->conn->feat_mask);
  2500. break;
  2501. }
  2502. done:
  2503. if (chan->imtu != L2CAP_DEFAULT_MTU)
  2504. l2cap_add_conf_opt(&ptr, L2CAP_CONF_MTU, 2, chan->imtu, endptr - ptr);
  2505. switch (chan->mode) {
  2506. case L2CAP_MODE_BASIC:
  2507. if (disable_ertm)
  2508. break;
  2509. if (!(chan->conn->feat_mask & L2CAP_FEAT_ERTM) &&
  2510. !(chan->conn->feat_mask & L2CAP_FEAT_STREAMING))
  2511. break;
  2512. rfc.mode = L2CAP_MODE_BASIC;
  2513. rfc.txwin_size = 0;
  2514. rfc.max_transmit = 0;
  2515. rfc.retrans_timeout = 0;
  2516. rfc.monitor_timeout = 0;
  2517. rfc.max_pdu_size = 0;
  2518. l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC, sizeof(rfc),
  2519. (unsigned long) &rfc, endptr - ptr);
  2520. break;
  2521. case L2CAP_MODE_ERTM:
  2522. rfc.mode = L2CAP_MODE_ERTM;
  2523. rfc.max_transmit = chan->max_tx;
  2524. __l2cap_set_ertm_timeouts(chan, &rfc);
  2525. size = min_t(u16, L2CAP_DEFAULT_MAX_PDU_SIZE, chan->conn->mtu -
  2526. L2CAP_EXT_HDR_SIZE - L2CAP_SDULEN_SIZE -
  2527. L2CAP_FCS_SIZE);
  2528. rfc.max_pdu_size = cpu_to_le16(size);
  2529. l2cap_txwin_setup(chan);
  2530. rfc.txwin_size = min_t(u16, chan->tx_win,
  2531. L2CAP_DEFAULT_TX_WINDOW);
  2532. l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC, sizeof(rfc),
  2533. (unsigned long) &rfc, endptr - ptr);
  2534. if (test_bit(FLAG_EFS_ENABLE, &chan->flags))
  2535. l2cap_add_opt_efs(&ptr, chan, endptr - ptr);
  2536. if (test_bit(FLAG_EXT_CTRL, &chan->flags))
  2537. l2cap_add_conf_opt(&ptr, L2CAP_CONF_EWS, 2,
  2538. chan->tx_win, endptr - ptr);
  2539. if (chan->conn->feat_mask & L2CAP_FEAT_FCS)
  2540. if (chan->fcs == L2CAP_FCS_NONE ||
  2541. test_bit(CONF_RECV_NO_FCS, &chan->conf_state)) {
  2542. chan->fcs = L2CAP_FCS_NONE;
  2543. l2cap_add_conf_opt(&ptr, L2CAP_CONF_FCS, 1,
  2544. chan->fcs, endptr - ptr);
  2545. }
  2546. break;
  2547. case L2CAP_MODE_STREAMING:
  2548. l2cap_txwin_setup(chan);
  2549. rfc.mode = L2CAP_MODE_STREAMING;
  2550. rfc.txwin_size = 0;
  2551. rfc.max_transmit = 0;
  2552. rfc.retrans_timeout = 0;
  2553. rfc.monitor_timeout = 0;
  2554. size = min_t(u16, L2CAP_DEFAULT_MAX_PDU_SIZE, chan->conn->mtu -
  2555. L2CAP_EXT_HDR_SIZE - L2CAP_SDULEN_SIZE -
  2556. L2CAP_FCS_SIZE);
  2557. rfc.max_pdu_size = cpu_to_le16(size);
  2558. l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC, sizeof(rfc),
  2559. (unsigned long) &rfc, endptr - ptr);
  2560. if (test_bit(FLAG_EFS_ENABLE, &chan->flags))
  2561. l2cap_add_opt_efs(&ptr, chan, endptr - ptr);
  2562. if (chan->conn->feat_mask & L2CAP_FEAT_FCS)
  2563. if (chan->fcs == L2CAP_FCS_NONE ||
  2564. test_bit(CONF_RECV_NO_FCS, &chan->conf_state)) {
  2565. chan->fcs = L2CAP_FCS_NONE;
  2566. l2cap_add_conf_opt(&ptr, L2CAP_CONF_FCS, 1,
  2567. chan->fcs, endptr - ptr);
  2568. }
  2569. break;
  2570. }
  2571. req->dcid = cpu_to_le16(chan->dcid);
  2572. req->flags = cpu_to_le16(0);
  2573. return ptr - data;
  2574. }
  2575. static int l2cap_parse_conf_req(struct l2cap_chan *chan, void *data, size_t data_size)
  2576. {
  2577. struct l2cap_conf_rsp *rsp = data;
  2578. void *ptr = rsp->data;
  2579. void *endptr = data + data_size;
  2580. void *req = chan->conf_req;
  2581. int len = chan->conf_len;
  2582. int type, hint, olen;
  2583. unsigned long val;
  2584. struct l2cap_conf_rfc rfc = { .mode = L2CAP_MODE_BASIC };
  2585. struct l2cap_conf_efs efs;
  2586. u8 remote_efs = 0;
  2587. u16 mtu = L2CAP_DEFAULT_MTU;
  2588. u16 result = L2CAP_CONF_SUCCESS;
  2589. u16 size;
  2590. BT_DBG("chan %p", chan);
  2591. while (len >= L2CAP_CONF_OPT_SIZE) {
  2592. len -= l2cap_get_conf_opt(&req, &type, &olen, &val);
  2593. if (len < 0)
  2594. break;
  2595. hint = type & L2CAP_CONF_HINT;
  2596. type &= L2CAP_CONF_MASK;
  2597. switch (type) {
  2598. case L2CAP_CONF_MTU:
  2599. if (olen != 2)
  2600. break;
  2601. mtu = val;
  2602. break;
  2603. case L2CAP_CONF_FLUSH_TO:
  2604. if (olen != 2)
  2605. break;
  2606. chan->flush_to = val;
  2607. break;
  2608. case L2CAP_CONF_QOS:
  2609. break;
  2610. case L2CAP_CONF_RFC:
  2611. if (olen != sizeof(rfc))
  2612. break;
  2613. memcpy(&rfc, (void *) val, olen);
  2614. break;
  2615. case L2CAP_CONF_FCS:
  2616. if (olen != 1)
  2617. break;
  2618. if (val == L2CAP_FCS_NONE)
  2619. set_bit(CONF_RECV_NO_FCS, &chan->conf_state);
  2620. break;
  2621. case L2CAP_CONF_EFS:
  2622. if (olen != sizeof(efs))
  2623. break;
  2624. remote_efs = 1;
  2625. memcpy(&efs, (void *) val, olen);
  2626. break;
  2627. case L2CAP_CONF_EWS:
  2628. if (olen != 2)
  2629. break;
  2630. if (!(chan->conn->local_fixed_chan & L2CAP_FC_A2MP))
  2631. return -ECONNREFUSED;
  2632. set_bit(FLAG_EXT_CTRL, &chan->flags);
  2633. set_bit(CONF_EWS_RECV, &chan->conf_state);
  2634. chan->tx_win_max = L2CAP_DEFAULT_EXT_WINDOW;
  2635. chan->remote_tx_win = val;
  2636. break;
  2637. default:
  2638. if (hint)
  2639. break;
  2640. result = L2CAP_CONF_UNKNOWN;
  2641. *((u8 *) ptr++) = type;
  2642. break;
  2643. }
  2644. }
  2645. if (chan->num_conf_rsp || chan->num_conf_req > 1)
  2646. goto done;
  2647. switch (chan->mode) {
  2648. case L2CAP_MODE_STREAMING:
  2649. case L2CAP_MODE_ERTM:
  2650. if (!test_bit(CONF_STATE2_DEVICE, &chan->conf_state)) {
  2651. chan->mode = l2cap_select_mode(rfc.mode,
  2652. chan->conn->feat_mask);
  2653. break;
  2654. }
  2655. if (remote_efs) {
  2656. if (__l2cap_efs_supported(chan->conn))
  2657. set_bit(FLAG_EFS_ENABLE, &chan->flags);
  2658. else
  2659. return -ECONNREFUSED;
  2660. }
  2661. if (chan->mode != rfc.mode)
  2662. return -ECONNREFUSED;
  2663. break;
  2664. }
  2665. done:
  2666. if (chan->mode != rfc.mode) {
  2667. result = L2CAP_CONF_UNACCEPT;
  2668. rfc.mode = chan->mode;
  2669. if (chan->num_conf_rsp == 1)
  2670. return -ECONNREFUSED;
  2671. l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC, sizeof(rfc),
  2672. (unsigned long) &rfc, endptr - ptr);
  2673. }
  2674. if (result == L2CAP_CONF_SUCCESS) {
  2675. /* Configure output options and let the other side know
  2676. * which ones we don't like. */
  2677. if (mtu < L2CAP_DEFAULT_MIN_MTU)
  2678. result = L2CAP_CONF_UNACCEPT;
  2679. else {
  2680. chan->omtu = mtu;
  2681. set_bit(CONF_MTU_DONE, &chan->conf_state);
  2682. }
  2683. l2cap_add_conf_opt(&ptr, L2CAP_CONF_MTU, 2, chan->omtu, endptr - ptr);
  2684. if (remote_efs) {
  2685. if (chan->local_stype != L2CAP_SERV_NOTRAFIC &&
  2686. efs.stype != L2CAP_SERV_NOTRAFIC &&
  2687. efs.stype != chan->local_stype) {
  2688. result = L2CAP_CONF_UNACCEPT;
  2689. if (chan->num_conf_req >= 1)
  2690. return -ECONNREFUSED;
  2691. l2cap_add_conf_opt(&ptr, L2CAP_CONF_EFS,
  2692. sizeof(efs),
  2693. (unsigned long) &efs, endptr - ptr);
  2694. } else {
  2695. /* Send PENDING Conf Rsp */
  2696. result = L2CAP_CONF_PENDING;
  2697. set_bit(CONF_LOC_CONF_PEND, &chan->conf_state);
  2698. }
  2699. }
  2700. switch (rfc.mode) {
  2701. case L2CAP_MODE_BASIC:
  2702. chan->fcs = L2CAP_FCS_NONE;
  2703. set_bit(CONF_MODE_DONE, &chan->conf_state);
  2704. break;
  2705. case L2CAP_MODE_ERTM:
  2706. if (!test_bit(CONF_EWS_RECV, &chan->conf_state))
  2707. chan->remote_tx_win = rfc.txwin_size;
  2708. else
  2709. rfc.txwin_size = L2CAP_DEFAULT_TX_WINDOW;
  2710. chan->remote_max_tx = rfc.max_transmit;
  2711. size = min_t(u16, le16_to_cpu(rfc.max_pdu_size),
  2712. chan->conn->mtu - L2CAP_EXT_HDR_SIZE -
  2713. L2CAP_SDULEN_SIZE - L2CAP_FCS_SIZE);
  2714. rfc.max_pdu_size = cpu_to_le16(size);
  2715. chan->remote_mps = size;
  2716. __l2cap_set_ertm_timeouts(chan, &rfc);
  2717. set_bit(CONF_MODE_DONE, &chan->conf_state);
  2718. l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC,
  2719. sizeof(rfc), (unsigned long) &rfc, endptr - ptr);
  2720. if (test_bit(FLAG_EFS_ENABLE, &chan->flags)) {
  2721. chan->remote_id = efs.id;
  2722. chan->remote_stype = efs.stype;
  2723. chan->remote_msdu = le16_to_cpu(efs.msdu);
  2724. chan->remote_flush_to =
  2725. le32_to_cpu(efs.flush_to);
  2726. chan->remote_acc_lat =
  2727. le32_to_cpu(efs.acc_lat);
  2728. chan->remote_sdu_itime =
  2729. le32_to_cpu(efs.sdu_itime);
  2730. l2cap_add_conf_opt(&ptr, L2CAP_CONF_EFS,
  2731. sizeof(efs),
  2732. (unsigned long) &efs, endptr - ptr);
  2733. }
  2734. break;
  2735. case L2CAP_MODE_STREAMING:
  2736. size = min_t(u16, le16_to_cpu(rfc.max_pdu_size),
  2737. chan->conn->mtu - L2CAP_EXT_HDR_SIZE -
  2738. L2CAP_SDULEN_SIZE - L2CAP_FCS_SIZE);
  2739. rfc.max_pdu_size = cpu_to_le16(size);
  2740. chan->remote_mps = size;
  2741. set_bit(CONF_MODE_DONE, &chan->conf_state);
  2742. l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC, sizeof(rfc),
  2743. (unsigned long) &rfc, endptr - ptr);
  2744. break;
  2745. default:
  2746. result = L2CAP_CONF_UNACCEPT;
  2747. memset(&rfc, 0, sizeof(rfc));
  2748. rfc.mode = chan->mode;
  2749. }
  2750. if (result == L2CAP_CONF_SUCCESS)
  2751. set_bit(CONF_OUTPUT_DONE, &chan->conf_state);
  2752. }
  2753. rsp->scid = cpu_to_le16(chan->dcid);
  2754. rsp->result = cpu_to_le16(result);
  2755. rsp->flags = cpu_to_le16(0);
  2756. return ptr - data;
  2757. }
  2758. static int l2cap_parse_conf_rsp(struct l2cap_chan *chan, void *rsp, int len,
  2759. void *data, size_t size, u16 *result)
  2760. {
  2761. struct l2cap_conf_req *req = data;
  2762. void *ptr = req->data;
  2763. void *endptr = data + size;
  2764. int type, olen;
  2765. unsigned long val;
  2766. struct l2cap_conf_rfc rfc = { .mode = L2CAP_MODE_BASIC };
  2767. struct l2cap_conf_efs efs;
  2768. BT_DBG("chan %p, rsp %p, len %d, req %p", chan, rsp, len, data);
  2769. while (len >= L2CAP_CONF_OPT_SIZE) {
  2770. len -= l2cap_get_conf_opt(&rsp, &type, &olen, &val);
  2771. if (len < 0)
  2772. break;
  2773. switch (type) {
  2774. case L2CAP_CONF_MTU:
  2775. if (olen != 2)
  2776. break;
  2777. if (val < L2CAP_DEFAULT_MIN_MTU) {
  2778. *result = L2CAP_CONF_UNACCEPT;
  2779. chan->imtu = L2CAP_DEFAULT_MIN_MTU;
  2780. } else
  2781. chan->imtu = val;
  2782. l2cap_add_conf_opt(&ptr, L2CAP_CONF_MTU, 2, chan->imtu,
  2783. endptr - ptr);
  2784. break;
  2785. case L2CAP_CONF_FLUSH_TO:
  2786. if (olen != 2)
  2787. break;
  2788. chan->flush_to = val;
  2789. l2cap_add_conf_opt(&ptr, L2CAP_CONF_FLUSH_TO, 2,
  2790. chan->flush_to, endptr - ptr);
  2791. break;
  2792. case L2CAP_CONF_RFC:
  2793. if (olen != sizeof(rfc))
  2794. break;
  2795. memcpy(&rfc, (void *)val, olen);
  2796. if (test_bit(CONF_STATE2_DEVICE, &chan->conf_state) &&
  2797. rfc.mode != chan->mode)
  2798. return -ECONNREFUSED;
  2799. chan->fcs = 0;
  2800. l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC, sizeof(rfc),
  2801. (unsigned long) &rfc, endptr - ptr);
  2802. break;
  2803. case L2CAP_CONF_EWS:
  2804. if (olen != 2)
  2805. break;
  2806. chan->ack_win = min_t(u16, val, chan->ack_win);
  2807. l2cap_add_conf_opt(&ptr, L2CAP_CONF_EWS, 2,
  2808. chan->tx_win, endptr - ptr);
  2809. break;
  2810. case L2CAP_CONF_EFS:
  2811. if (olen != sizeof(efs))
  2812. break;
  2813. memcpy(&efs, (void *)val, olen);
  2814. if (chan->local_stype != L2CAP_SERV_NOTRAFIC &&
  2815. efs.stype != L2CAP_SERV_NOTRAFIC &&
  2816. efs.stype != chan->local_stype)
  2817. return -ECONNREFUSED;
  2818. l2cap_add_conf_opt(&ptr, L2CAP_CONF_EFS, sizeof(efs),
  2819. (unsigned long) &efs, endptr - ptr);
  2820. break;
  2821. case L2CAP_CONF_FCS:
  2822. if (olen != 1)
  2823. break;
  2824. if (*result == L2CAP_CONF_PENDING)
  2825. if (val == L2CAP_FCS_NONE)
  2826. set_bit(CONF_RECV_NO_FCS,
  2827. &chan->conf_state);
  2828. break;
  2829. }
  2830. }
  2831. if (chan->mode == L2CAP_MODE_BASIC && chan->mode != rfc.mode)
  2832. return -ECONNREFUSED;
  2833. chan->mode = rfc.mode;
  2834. if (*result == L2CAP_CONF_SUCCESS || *result == L2CAP_CONF_PENDING) {
  2835. switch (rfc.mode) {
  2836. case L2CAP_MODE_ERTM:
  2837. chan->retrans_timeout = le16_to_cpu(rfc.retrans_timeout);
  2838. chan->monitor_timeout = le16_to_cpu(rfc.monitor_timeout);
  2839. chan->mps = le16_to_cpu(rfc.max_pdu_size);
  2840. if (!test_bit(FLAG_EXT_CTRL, &chan->flags))
  2841. chan->ack_win = min_t(u16, chan->ack_win,
  2842. rfc.txwin_size);
  2843. if (test_bit(FLAG_EFS_ENABLE, &chan->flags)) {
  2844. chan->local_msdu = le16_to_cpu(efs.msdu);
  2845. chan->local_sdu_itime =
  2846. le32_to_cpu(efs.sdu_itime);
  2847. chan->local_acc_lat = le32_to_cpu(efs.acc_lat);
  2848. chan->local_flush_to =
  2849. le32_to_cpu(efs.flush_to);
  2850. }
  2851. break;
  2852. case L2CAP_MODE_STREAMING:
  2853. chan->mps = le16_to_cpu(rfc.max_pdu_size);
  2854. }
  2855. }
  2856. req->dcid = cpu_to_le16(chan->dcid);
  2857. req->flags = cpu_to_le16(0);
  2858. return ptr - data;
  2859. }
  2860. static int l2cap_build_conf_rsp(struct l2cap_chan *chan, void *data,
  2861. u16 result, u16 flags)
  2862. {
  2863. struct l2cap_conf_rsp *rsp = data;
  2864. void *ptr = rsp->data;
  2865. BT_DBG("chan %p", chan);
  2866. rsp->scid = cpu_to_le16(chan->dcid);
  2867. rsp->result = cpu_to_le16(result);
  2868. rsp->flags = cpu_to_le16(flags);
  2869. return ptr - data;
  2870. }
  2871. void __l2cap_le_connect_rsp_defer(struct l2cap_chan *chan)
  2872. {
  2873. struct l2cap_le_conn_rsp rsp;
  2874. struct l2cap_conn *conn = chan->conn;
  2875. BT_DBG("chan %p", chan);
  2876. rsp.dcid = cpu_to_le16(chan->scid);
  2877. rsp.mtu = cpu_to_le16(chan->imtu);
  2878. rsp.mps = cpu_to_le16(chan->mps);
  2879. rsp.credits = cpu_to_le16(chan->rx_credits);
  2880. rsp.result = cpu_to_le16(L2CAP_CR_SUCCESS);
  2881. l2cap_send_cmd(conn, chan->ident, L2CAP_LE_CONN_RSP, sizeof(rsp),
  2882. &rsp);
  2883. }
  2884. void __l2cap_connect_rsp_defer(struct l2cap_chan *chan)
  2885. {
  2886. struct l2cap_conn_rsp rsp;
  2887. struct l2cap_conn *conn = chan->conn;
  2888. u8 buf[128];
  2889. u8 rsp_code;
  2890. rsp.scid = cpu_to_le16(chan->dcid);
  2891. rsp.dcid = cpu_to_le16(chan->scid);
  2892. rsp.result = cpu_to_le16(L2CAP_CR_SUCCESS);
  2893. rsp.status = cpu_to_le16(L2CAP_CS_NO_INFO);
  2894. if (chan->hs_hcon)
  2895. rsp_code = L2CAP_CREATE_CHAN_RSP;
  2896. else
  2897. rsp_code = L2CAP_CONN_RSP;
  2898. BT_DBG("chan %p rsp_code %u", chan, rsp_code);
  2899. l2cap_send_cmd(conn, chan->ident, rsp_code, sizeof(rsp), &rsp);
  2900. if (test_and_set_bit(CONF_REQ_SENT, &chan->conf_state))
  2901. return;
  2902. l2cap_send_cmd(conn, l2cap_get_ident(conn), L2CAP_CONF_REQ,
  2903. l2cap_build_conf_req(chan, buf, sizeof(buf)), buf);
  2904. chan->num_conf_req++;
  2905. }
  2906. static void l2cap_conf_rfc_get(struct l2cap_chan *chan, void *rsp, int len)
  2907. {
  2908. int type, olen;
  2909. unsigned long val;
  2910. /* Use sane default values in case a misbehaving remote device
  2911. * did not send an RFC or extended window size option.
  2912. */
  2913. u16 txwin_ext = chan->ack_win;
  2914. struct l2cap_conf_rfc rfc = {
  2915. .mode = chan->mode,
  2916. .retrans_timeout = cpu_to_le16(L2CAP_DEFAULT_RETRANS_TO),
  2917. .monitor_timeout = cpu_to_le16(L2CAP_DEFAULT_MONITOR_TO),
  2918. .max_pdu_size = cpu_to_le16(chan->imtu),
  2919. .txwin_size = min_t(u16, chan->ack_win, L2CAP_DEFAULT_TX_WINDOW),
  2920. };
  2921. BT_DBG("chan %p, rsp %p, len %d", chan, rsp, len);
  2922. if ((chan->mode != L2CAP_MODE_ERTM) && (chan->mode != L2CAP_MODE_STREAMING))
  2923. return;
  2924. while (len >= L2CAP_CONF_OPT_SIZE) {
  2925. len -= l2cap_get_conf_opt(&rsp, &type, &olen, &val);
  2926. if (len < 0)
  2927. break;
  2928. switch (type) {
  2929. case L2CAP_CONF_RFC:
  2930. if (olen != sizeof(rfc))
  2931. break;
  2932. memcpy(&rfc, (void *)val, olen);
  2933. break;
  2934. case L2CAP_CONF_EWS:
  2935. if (olen != 2)
  2936. break;
  2937. txwin_ext = val;
  2938. break;
  2939. }
  2940. }
  2941. switch (rfc.mode) {
  2942. case L2CAP_MODE_ERTM:
  2943. chan->retrans_timeout = le16_to_cpu(rfc.retrans_timeout);
  2944. chan->monitor_timeout = le16_to_cpu(rfc.monitor_timeout);
  2945. chan->mps = le16_to_cpu(rfc.max_pdu_size);
  2946. if (test_bit(FLAG_EXT_CTRL, &chan->flags))
  2947. chan->ack_win = min_t(u16, chan->ack_win, txwin_ext);
  2948. else
  2949. chan->ack_win = min_t(u16, chan->ack_win,
  2950. rfc.txwin_size);
  2951. break;
  2952. case L2CAP_MODE_STREAMING:
  2953. chan->mps = le16_to_cpu(rfc.max_pdu_size);
  2954. }
  2955. }
  2956. static inline int l2cap_command_rej(struct l2cap_conn *conn,
  2957. struct l2cap_cmd_hdr *cmd, u16 cmd_len,
  2958. u8 *data)
  2959. {
  2960. struct l2cap_cmd_rej_unk *rej = (struct l2cap_cmd_rej_unk *) data;
  2961. if (cmd_len < sizeof(*rej))
  2962. return -EPROTO;
  2963. if (rej->reason != L2CAP_REJ_NOT_UNDERSTOOD)
  2964. return 0;
  2965. if ((conn->info_state & L2CAP_INFO_FEAT_MASK_REQ_SENT) &&
  2966. cmd->ident == conn->info_ident) {
  2967. cancel_delayed_work(&conn->info_timer);
  2968. conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_DONE;
  2969. conn->info_ident = 0;
  2970. l2cap_conn_start(conn);
  2971. }
  2972. return 0;
  2973. }
  2974. static struct l2cap_chan *l2cap_connect(struct l2cap_conn *conn,
  2975. struct l2cap_cmd_hdr *cmd,
  2976. u8 *data, u8 rsp_code, u8 amp_id)
  2977. {
  2978. struct l2cap_conn_req *req = (struct l2cap_conn_req *) data;
  2979. struct l2cap_conn_rsp rsp;
  2980. struct l2cap_chan *chan = NULL, *pchan;
  2981. int result, status = L2CAP_CS_NO_INFO;
  2982. u16 dcid = 0, scid = __le16_to_cpu(req->scid);
  2983. __le16 psm = req->psm;
  2984. BT_DBG("psm 0x%2.2x scid 0x%4.4x", __le16_to_cpu(psm), scid);
  2985. /* Check if we have socket listening on psm */
  2986. pchan = l2cap_global_chan_by_psm(BT_LISTEN, psm, &conn->hcon->src,
  2987. &conn->hcon->dst, ACL_LINK);
  2988. if (!pchan) {
  2989. result = L2CAP_CR_BAD_PSM;
  2990. goto sendresp;
  2991. }
  2992. mutex_lock(&conn->chan_lock);
  2993. l2cap_chan_lock(pchan);
  2994. /* Check if the ACL is secure enough (if not SDP) */
  2995. if (psm != cpu_to_le16(L2CAP_PSM_SDP) &&
  2996. !hci_conn_check_link_mode(conn->hcon)) {
  2997. conn->disc_reason = HCI_ERROR_AUTH_FAILURE;
  2998. result = L2CAP_CR_SEC_BLOCK;
  2999. goto response;
  3000. }
  3001. result = L2CAP_CR_NO_MEM;
  3002. /* Check if we already have channel with that dcid */
  3003. if (__l2cap_get_chan_by_dcid(conn, scid))
  3004. goto response;
  3005. chan = pchan->ops->new_connection(pchan);
  3006. if (!chan)
  3007. goto response;
  3008. /* For certain devices (ex: HID mouse), support for authentication,
  3009. * pairing and bonding is optional. For such devices, inorder to avoid
  3010. * the ACL alive for too long after L2CAP disconnection, reset the ACL
  3011. * disc_timeout back to HCI_DISCONN_TIMEOUT during L2CAP connect.
  3012. */
  3013. conn->hcon->disc_timeout = HCI_DISCONN_TIMEOUT;
  3014. bacpy(&chan->src, &conn->hcon->src);
  3015. bacpy(&chan->dst, &conn->hcon->dst);
  3016. chan->src_type = bdaddr_src_type(conn->hcon);
  3017. chan->dst_type = bdaddr_dst_type(conn->hcon);
  3018. chan->psm = psm;
  3019. chan->dcid = scid;
  3020. chan->local_amp_id = amp_id;
  3021. __l2cap_chan_add(conn, chan);
  3022. dcid = chan->scid;
  3023. __set_chan_timer(chan, chan->ops->get_sndtimeo(chan));
  3024. chan->ident = cmd->ident;
  3025. if (conn->info_state & L2CAP_INFO_FEAT_MASK_REQ_DONE) {
  3026. if (l2cap_chan_check_security(chan, false)) {
  3027. if (test_bit(FLAG_DEFER_SETUP, &chan->flags)) {
  3028. l2cap_state_change(chan, BT_CONNECT2);
  3029. result = L2CAP_CR_PEND;
  3030. status = L2CAP_CS_AUTHOR_PEND;
  3031. chan->ops->defer(chan);
  3032. } else {
  3033. /* Force pending result for AMP controllers.
  3034. * The connection will succeed after the
  3035. * physical link is up.
  3036. */
  3037. if (amp_id == AMP_ID_BREDR) {
  3038. l2cap_state_change(chan, BT_CONFIG);
  3039. result = L2CAP_CR_SUCCESS;
  3040. } else {
  3041. l2cap_state_change(chan, BT_CONNECT2);
  3042. result = L2CAP_CR_PEND;
  3043. }
  3044. status = L2CAP_CS_NO_INFO;
  3045. }
  3046. } else {
  3047. l2cap_state_change(chan, BT_CONNECT2);
  3048. result = L2CAP_CR_PEND;
  3049. status = L2CAP_CS_AUTHEN_PEND;
  3050. }
  3051. } else {
  3052. l2cap_state_change(chan, BT_CONNECT2);
  3053. result = L2CAP_CR_PEND;
  3054. status = L2CAP_CS_NO_INFO;
  3055. }
  3056. response:
  3057. l2cap_chan_unlock(pchan);
  3058. mutex_unlock(&conn->chan_lock);
  3059. l2cap_chan_put(pchan);
  3060. sendresp:
  3061. rsp.scid = cpu_to_le16(scid);
  3062. rsp.dcid = cpu_to_le16(dcid);
  3063. rsp.result = cpu_to_le16(result);
  3064. rsp.status = cpu_to_le16(status);
  3065. l2cap_send_cmd(conn, cmd->ident, rsp_code, sizeof(rsp), &rsp);
  3066. if (result == L2CAP_CR_PEND && status == L2CAP_CS_NO_INFO) {
  3067. struct l2cap_info_req info;
  3068. info.type = cpu_to_le16(L2CAP_IT_FEAT_MASK);
  3069. conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_SENT;
  3070. conn->info_ident = l2cap_get_ident(conn);
  3071. schedule_delayed_work(&conn->info_timer, L2CAP_INFO_TIMEOUT);
  3072. l2cap_send_cmd(conn, conn->info_ident, L2CAP_INFO_REQ,
  3073. sizeof(info), &info);
  3074. }
  3075. if (chan && !test_bit(CONF_REQ_SENT, &chan->conf_state) &&
  3076. result == L2CAP_CR_SUCCESS) {
  3077. u8 buf[128];
  3078. set_bit(CONF_REQ_SENT, &chan->conf_state);
  3079. l2cap_send_cmd(conn, l2cap_get_ident(conn), L2CAP_CONF_REQ,
  3080. l2cap_build_conf_req(chan, buf, sizeof(buf)), buf);
  3081. chan->num_conf_req++;
  3082. }
  3083. return chan;
  3084. }
  3085. static int l2cap_connect_req(struct l2cap_conn *conn,
  3086. struct l2cap_cmd_hdr *cmd, u16 cmd_len, u8 *data)
  3087. {
  3088. struct hci_dev *hdev = conn->hcon->hdev;
  3089. struct hci_conn *hcon = conn->hcon;
  3090. if (cmd_len < sizeof(struct l2cap_conn_req))
  3091. return -EPROTO;
  3092. hci_dev_lock(hdev);
  3093. if (hci_dev_test_flag(hdev, HCI_MGMT) &&
  3094. !test_and_set_bit(HCI_CONN_MGMT_CONNECTED, &hcon->flags))
  3095. mgmt_device_connected(hdev, hcon, 0, NULL, 0);
  3096. hci_dev_unlock(hdev);
  3097. l2cap_connect(conn, cmd, data, L2CAP_CONN_RSP, 0);
  3098. return 0;
  3099. }
  3100. static int l2cap_connect_create_rsp(struct l2cap_conn *conn,
  3101. struct l2cap_cmd_hdr *cmd, u16 cmd_len,
  3102. u8 *data)
  3103. {
  3104. struct l2cap_conn_rsp *rsp = (struct l2cap_conn_rsp *) data;
  3105. u16 scid, dcid, result, status;
  3106. struct l2cap_chan *chan;
  3107. u8 req[128];
  3108. int err;
  3109. if (cmd_len < sizeof(*rsp))
  3110. return -EPROTO;
  3111. scid = __le16_to_cpu(rsp->scid);
  3112. dcid = __le16_to_cpu(rsp->dcid);
  3113. result = __le16_to_cpu(rsp->result);
  3114. status = __le16_to_cpu(rsp->status);
  3115. BT_DBG("dcid 0x%4.4x scid 0x%4.4x result 0x%2.2x status 0x%2.2x",
  3116. dcid, scid, result, status);
  3117. mutex_lock(&conn->chan_lock);
  3118. if (scid) {
  3119. chan = __l2cap_get_chan_by_scid(conn, scid);
  3120. if (!chan) {
  3121. err = -EBADSLT;
  3122. goto unlock;
  3123. }
  3124. } else {
  3125. chan = __l2cap_get_chan_by_ident(conn, cmd->ident);
  3126. if (!chan) {
  3127. err = -EBADSLT;
  3128. goto unlock;
  3129. }
  3130. }
  3131. err = 0;
  3132. l2cap_chan_lock(chan);
  3133. switch (result) {
  3134. case L2CAP_CR_SUCCESS:
  3135. l2cap_state_change(chan, BT_CONFIG);
  3136. chan->ident = 0;
  3137. chan->dcid = dcid;
  3138. clear_bit(CONF_CONNECT_PEND, &chan->conf_state);
  3139. if (test_and_set_bit(CONF_REQ_SENT, &chan->conf_state))
  3140. break;
  3141. l2cap_send_cmd(conn, l2cap_get_ident(conn), L2CAP_CONF_REQ,
  3142. l2cap_build_conf_req(chan, req, sizeof(req)), req);
  3143. chan->num_conf_req++;
  3144. break;
  3145. case L2CAP_CR_PEND:
  3146. set_bit(CONF_CONNECT_PEND, &chan->conf_state);
  3147. break;
  3148. default:
  3149. l2cap_chan_del(chan, ECONNREFUSED);
  3150. break;
  3151. }
  3152. l2cap_chan_unlock(chan);
  3153. unlock:
  3154. mutex_unlock(&conn->chan_lock);
  3155. return err;
  3156. }
  3157. static inline void set_default_fcs(struct l2cap_chan *chan)
  3158. {
  3159. /* FCS is enabled only in ERTM or streaming mode, if one or both
  3160. * sides request it.
  3161. */
  3162. if (chan->mode != L2CAP_MODE_ERTM && chan->mode != L2CAP_MODE_STREAMING)
  3163. chan->fcs = L2CAP_FCS_NONE;
  3164. else if (!test_bit(CONF_RECV_NO_FCS, &chan->conf_state))
  3165. chan->fcs = L2CAP_FCS_CRC16;
  3166. }
  3167. static void l2cap_send_efs_conf_rsp(struct l2cap_chan *chan, void *data,
  3168. u8 ident, u16 flags)
  3169. {
  3170. struct l2cap_conn *conn = chan->conn;
  3171. BT_DBG("conn %p chan %p ident %d flags 0x%4.4x", conn, chan, ident,
  3172. flags);
  3173. clear_bit(CONF_LOC_CONF_PEND, &chan->conf_state);
  3174. set_bit(CONF_OUTPUT_DONE, &chan->conf_state);
  3175. l2cap_send_cmd(conn, ident, L2CAP_CONF_RSP,
  3176. l2cap_build_conf_rsp(chan, data,
  3177. L2CAP_CONF_SUCCESS, flags), data);
  3178. }
  3179. static void cmd_reject_invalid_cid(struct l2cap_conn *conn, u8 ident,
  3180. u16 scid, u16 dcid)
  3181. {
  3182. struct l2cap_cmd_rej_cid rej;
  3183. rej.reason = cpu_to_le16(L2CAP_REJ_INVALID_CID);
  3184. rej.scid = __cpu_to_le16(scid);
  3185. rej.dcid = __cpu_to_le16(dcid);
  3186. l2cap_send_cmd(conn, ident, L2CAP_COMMAND_REJ, sizeof(rej), &rej);
  3187. }
  3188. static inline int l2cap_config_req(struct l2cap_conn *conn,
  3189. struct l2cap_cmd_hdr *cmd, u16 cmd_len,
  3190. u8 *data)
  3191. {
  3192. struct l2cap_conf_req *req = (struct l2cap_conf_req *) data;
  3193. u16 dcid, flags;
  3194. u8 rsp[64];
  3195. struct l2cap_chan *chan;
  3196. int len, err = 0;
  3197. if (cmd_len < sizeof(*req))
  3198. return -EPROTO;
  3199. dcid = __le16_to_cpu(req->dcid);
  3200. flags = __le16_to_cpu(req->flags);
  3201. BT_DBG("dcid 0x%4.4x flags 0x%2.2x", dcid, flags);
  3202. chan = l2cap_get_chan_by_scid(conn, dcid);
  3203. if (!chan) {
  3204. cmd_reject_invalid_cid(conn, cmd->ident, dcid, 0);
  3205. return 0;
  3206. }
  3207. if (chan->state != BT_CONFIG && chan->state != BT_CONNECT2) {
  3208. cmd_reject_invalid_cid(conn, cmd->ident, chan->scid,
  3209. chan->dcid);
  3210. goto unlock;
  3211. }
  3212. /* Reject if config buffer is too small. */
  3213. len = cmd_len - sizeof(*req);
  3214. if (chan->conf_len + len > sizeof(chan->conf_req)) {
  3215. l2cap_send_cmd(conn, cmd->ident, L2CAP_CONF_RSP,
  3216. l2cap_build_conf_rsp(chan, rsp,
  3217. L2CAP_CONF_REJECT, flags), rsp);
  3218. goto unlock;
  3219. }
  3220. /* Store config. */
  3221. memcpy(chan->conf_req + chan->conf_len, req->data, len);
  3222. chan->conf_len += len;
  3223. if (flags & L2CAP_CONF_FLAG_CONTINUATION) {
  3224. /* Incomplete config. Send empty response. */
  3225. l2cap_send_cmd(conn, cmd->ident, L2CAP_CONF_RSP,
  3226. l2cap_build_conf_rsp(chan, rsp,
  3227. L2CAP_CONF_SUCCESS, flags), rsp);
  3228. goto unlock;
  3229. }
  3230. /* Complete config. */
  3231. len = l2cap_parse_conf_req(chan, rsp, sizeof(rsp));
  3232. if (len < 0) {
  3233. l2cap_send_disconn_req(chan, ECONNRESET);
  3234. goto unlock;
  3235. }
  3236. chan->ident = cmd->ident;
  3237. l2cap_send_cmd(conn, cmd->ident, L2CAP_CONF_RSP, len, rsp);
  3238. chan->num_conf_rsp++;
  3239. /* Reset config buffer. */
  3240. chan->conf_len = 0;
  3241. if (!test_bit(CONF_OUTPUT_DONE, &chan->conf_state))
  3242. goto unlock;
  3243. if (test_bit(CONF_INPUT_DONE, &chan->conf_state)) {
  3244. set_default_fcs(chan);
  3245. if (chan->mode == L2CAP_MODE_ERTM ||
  3246. chan->mode == L2CAP_MODE_STREAMING)
  3247. err = l2cap_ertm_init(chan);
  3248. if (err < 0)
  3249. l2cap_send_disconn_req(chan, -err);
  3250. else
  3251. l2cap_chan_ready(chan);
  3252. goto unlock;
  3253. }
  3254. if (!test_and_set_bit(CONF_REQ_SENT, &chan->conf_state)) {
  3255. u8 buf[64];
  3256. l2cap_send_cmd(conn, l2cap_get_ident(conn), L2CAP_CONF_REQ,
  3257. l2cap_build_conf_req(chan, buf, sizeof(buf)), buf);
  3258. chan->num_conf_req++;
  3259. }
  3260. /* Got Conf Rsp PENDING from remote side and assume we sent
  3261. Conf Rsp PENDING in the code above */
  3262. if (test_bit(CONF_REM_CONF_PEND, &chan->conf_state) &&
  3263. test_bit(CONF_LOC_CONF_PEND, &chan->conf_state)) {
  3264. /* check compatibility */
  3265. /* Send rsp for BR/EDR channel */
  3266. if (!chan->hs_hcon)
  3267. l2cap_send_efs_conf_rsp(chan, rsp, cmd->ident, flags);
  3268. else
  3269. chan->ident = cmd->ident;
  3270. }
  3271. unlock:
  3272. l2cap_chan_unlock(chan);
  3273. return err;
  3274. }
  3275. static inline int l2cap_config_rsp(struct l2cap_conn *conn,
  3276. struct l2cap_cmd_hdr *cmd, u16 cmd_len,
  3277. u8 *data)
  3278. {
  3279. struct l2cap_conf_rsp *rsp = (struct l2cap_conf_rsp *)data;
  3280. u16 scid, flags, result;
  3281. struct l2cap_chan *chan;
  3282. int len = cmd_len - sizeof(*rsp);
  3283. int err = 0;
  3284. if (cmd_len < sizeof(*rsp))
  3285. return -EPROTO;
  3286. scid = __le16_to_cpu(rsp->scid);
  3287. flags = __le16_to_cpu(rsp->flags);
  3288. result = __le16_to_cpu(rsp->result);
  3289. BT_DBG("scid 0x%4.4x flags 0x%2.2x result 0x%2.2x len %d", scid, flags,
  3290. result, len);
  3291. chan = l2cap_get_chan_by_scid(conn, scid);
  3292. if (!chan)
  3293. return 0;
  3294. switch (result) {
  3295. case L2CAP_CONF_SUCCESS:
  3296. l2cap_conf_rfc_get(chan, rsp->data, len);
  3297. clear_bit(CONF_REM_CONF_PEND, &chan->conf_state);
  3298. break;
  3299. case L2CAP_CONF_PENDING:
  3300. set_bit(CONF_REM_CONF_PEND, &chan->conf_state);
  3301. if (test_bit(CONF_LOC_CONF_PEND, &chan->conf_state)) {
  3302. char buf[64];
  3303. len = l2cap_parse_conf_rsp(chan, rsp->data, len,
  3304. buf, sizeof(buf), &result);
  3305. if (len < 0) {
  3306. l2cap_send_disconn_req(chan, ECONNRESET);
  3307. goto done;
  3308. }
  3309. if (!chan->hs_hcon) {
  3310. l2cap_send_efs_conf_rsp(chan, buf, cmd->ident,
  3311. 0);
  3312. } else {
  3313. if (l2cap_check_efs(chan)) {
  3314. amp_create_logical_link(chan);
  3315. chan->ident = cmd->ident;
  3316. }
  3317. }
  3318. }
  3319. goto done;
  3320. case L2CAP_CONF_UNACCEPT:
  3321. if (chan->num_conf_rsp <= L2CAP_CONF_MAX_CONF_RSP) {
  3322. char req[64];
  3323. if (len > sizeof(req) - sizeof(struct l2cap_conf_req)) {
  3324. l2cap_send_disconn_req(chan, ECONNRESET);
  3325. goto done;
  3326. }
  3327. /* throw out any old stored conf requests */
  3328. result = L2CAP_CONF_SUCCESS;
  3329. len = l2cap_parse_conf_rsp(chan, rsp->data, len,
  3330. req, sizeof(req), &result);
  3331. if (len < 0) {
  3332. l2cap_send_disconn_req(chan, ECONNRESET);
  3333. goto done;
  3334. }
  3335. l2cap_send_cmd(conn, l2cap_get_ident(conn),
  3336. L2CAP_CONF_REQ, len, req);
  3337. chan->num_conf_req++;
  3338. if (result != L2CAP_CONF_SUCCESS)
  3339. goto done;
  3340. break;
  3341. }
  3342. default:
  3343. l2cap_chan_set_err(chan, ECONNRESET);
  3344. __set_chan_timer(chan, L2CAP_DISC_REJ_TIMEOUT);
  3345. l2cap_send_disconn_req(chan, ECONNRESET);
  3346. goto done;
  3347. }
  3348. if (flags & L2CAP_CONF_FLAG_CONTINUATION)
  3349. goto done;
  3350. set_bit(CONF_INPUT_DONE, &chan->conf_state);
  3351. if (test_bit(CONF_OUTPUT_DONE, &chan->conf_state)) {
  3352. set_default_fcs(chan);
  3353. if (chan->mode == L2CAP_MODE_ERTM ||
  3354. chan->mode == L2CAP_MODE_STREAMING)
  3355. err = l2cap_ertm_init(chan);
  3356. if (err < 0)
  3357. l2cap_send_disconn_req(chan, -err);
  3358. else
  3359. l2cap_chan_ready(chan);
  3360. }
  3361. done:
  3362. l2cap_chan_unlock(chan);
  3363. return err;
  3364. }
  3365. static inline int l2cap_disconnect_req(struct l2cap_conn *conn,
  3366. struct l2cap_cmd_hdr *cmd, u16 cmd_len,
  3367. u8 *data)
  3368. {
  3369. struct l2cap_disconn_req *req = (struct l2cap_disconn_req *) data;
  3370. struct l2cap_disconn_rsp rsp;
  3371. u16 dcid, scid;
  3372. struct l2cap_chan *chan;
  3373. if (cmd_len != sizeof(*req))
  3374. return -EPROTO;
  3375. scid = __le16_to_cpu(req->scid);
  3376. dcid = __le16_to_cpu(req->dcid);
  3377. BT_DBG("scid 0x%4.4x dcid 0x%4.4x", scid, dcid);
  3378. mutex_lock(&conn->chan_lock);
  3379. chan = __l2cap_get_chan_by_scid(conn, dcid);
  3380. if (!chan) {
  3381. mutex_unlock(&conn->chan_lock);
  3382. cmd_reject_invalid_cid(conn, cmd->ident, dcid, scid);
  3383. return 0;
  3384. }
  3385. l2cap_chan_lock(chan);
  3386. rsp.dcid = cpu_to_le16(chan->scid);
  3387. rsp.scid = cpu_to_le16(chan->dcid);
  3388. l2cap_send_cmd(conn, cmd->ident, L2CAP_DISCONN_RSP, sizeof(rsp), &rsp);
  3389. chan->ops->set_shutdown(chan);
  3390. l2cap_chan_hold(chan);
  3391. l2cap_chan_del(chan, ECONNRESET);
  3392. l2cap_chan_unlock(chan);
  3393. chan->ops->close(chan);
  3394. l2cap_chan_put(chan);
  3395. mutex_unlock(&conn->chan_lock);
  3396. return 0;
  3397. }
  3398. static inline int l2cap_disconnect_rsp(struct l2cap_conn *conn,
  3399. struct l2cap_cmd_hdr *cmd, u16 cmd_len,
  3400. u8 *data)
  3401. {
  3402. struct l2cap_disconn_rsp *rsp = (struct l2cap_disconn_rsp *) data;
  3403. u16 dcid, scid;
  3404. struct l2cap_chan *chan;
  3405. if (cmd_len != sizeof(*rsp))
  3406. return -EPROTO;
  3407. scid = __le16_to_cpu(rsp->scid);
  3408. dcid = __le16_to_cpu(rsp->dcid);
  3409. BT_DBG("dcid 0x%4.4x scid 0x%4.4x", dcid, scid);
  3410. mutex_lock(&conn->chan_lock);
  3411. chan = __l2cap_get_chan_by_scid(conn, scid);
  3412. if (!chan) {
  3413. mutex_unlock(&conn->chan_lock);
  3414. return 0;
  3415. }
  3416. l2cap_chan_lock(chan);
  3417. l2cap_chan_hold(chan);
  3418. l2cap_chan_del(chan, 0);
  3419. l2cap_chan_unlock(chan);
  3420. chan->ops->close(chan);
  3421. l2cap_chan_put(chan);
  3422. mutex_unlock(&conn->chan_lock);
  3423. return 0;
  3424. }
  3425. static inline int l2cap_information_req(struct l2cap_conn *conn,
  3426. struct l2cap_cmd_hdr *cmd, u16 cmd_len,
  3427. u8 *data)
  3428. {
  3429. struct l2cap_info_req *req = (struct l2cap_info_req *) data;
  3430. u16 type;
  3431. if (cmd_len != sizeof(*req))
  3432. return -EPROTO;
  3433. type = __le16_to_cpu(req->type);
  3434. BT_DBG("type 0x%4.4x", type);
  3435. if (type == L2CAP_IT_FEAT_MASK) {
  3436. u8 buf[8];
  3437. u32 feat_mask = l2cap_feat_mask;
  3438. struct l2cap_info_rsp *rsp = (struct l2cap_info_rsp *) buf;
  3439. rsp->type = cpu_to_le16(L2CAP_IT_FEAT_MASK);
  3440. rsp->result = cpu_to_le16(L2CAP_IR_SUCCESS);
  3441. if (!disable_ertm)
  3442. feat_mask |= L2CAP_FEAT_ERTM | L2CAP_FEAT_STREAMING
  3443. | L2CAP_FEAT_FCS;
  3444. if (conn->local_fixed_chan & L2CAP_FC_A2MP)
  3445. feat_mask |= L2CAP_FEAT_EXT_FLOW
  3446. | L2CAP_FEAT_EXT_WINDOW;
  3447. put_unaligned_le32(feat_mask, rsp->data);
  3448. l2cap_send_cmd(conn, cmd->ident, L2CAP_INFO_RSP, sizeof(buf),
  3449. buf);
  3450. } else if (type == L2CAP_IT_FIXED_CHAN) {
  3451. u8 buf[12];
  3452. struct l2cap_info_rsp *rsp = (struct l2cap_info_rsp *) buf;
  3453. rsp->type = cpu_to_le16(L2CAP_IT_FIXED_CHAN);
  3454. rsp->result = cpu_to_le16(L2CAP_IR_SUCCESS);
  3455. rsp->data[0] = conn->local_fixed_chan;
  3456. memset(rsp->data + 1, 0, 7);
  3457. l2cap_send_cmd(conn, cmd->ident, L2CAP_INFO_RSP, sizeof(buf),
  3458. buf);
  3459. } else {
  3460. struct l2cap_info_rsp rsp;
  3461. rsp.type = cpu_to_le16(type);
  3462. rsp.result = cpu_to_le16(L2CAP_IR_NOTSUPP);
  3463. l2cap_send_cmd(conn, cmd->ident, L2CAP_INFO_RSP, sizeof(rsp),
  3464. &rsp);
  3465. }
  3466. return 0;
  3467. }
  3468. static inline int l2cap_information_rsp(struct l2cap_conn *conn,
  3469. struct l2cap_cmd_hdr *cmd, u16 cmd_len,
  3470. u8 *data)
  3471. {
  3472. struct l2cap_info_rsp *rsp = (struct l2cap_info_rsp *) data;
  3473. u16 type, result;
  3474. if (cmd_len < sizeof(*rsp))
  3475. return -EPROTO;
  3476. type = __le16_to_cpu(rsp->type);
  3477. result = __le16_to_cpu(rsp->result);
  3478. BT_DBG("type 0x%4.4x result 0x%2.2x", type, result);
  3479. /* L2CAP Info req/rsp are unbound to channels, add extra checks */
  3480. if (cmd->ident != conn->info_ident ||
  3481. conn->info_state & L2CAP_INFO_FEAT_MASK_REQ_DONE)
  3482. return 0;
  3483. cancel_delayed_work(&conn->info_timer);
  3484. if (result != L2CAP_IR_SUCCESS) {
  3485. conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_DONE;
  3486. conn->info_ident = 0;
  3487. l2cap_conn_start(conn);
  3488. return 0;
  3489. }
  3490. switch (type) {
  3491. case L2CAP_IT_FEAT_MASK:
  3492. conn->feat_mask = get_unaligned_le32(rsp->data);
  3493. if (conn->feat_mask & L2CAP_FEAT_FIXED_CHAN) {
  3494. struct l2cap_info_req req;
  3495. req.type = cpu_to_le16(L2CAP_IT_FIXED_CHAN);
  3496. conn->info_ident = l2cap_get_ident(conn);
  3497. l2cap_send_cmd(conn, conn->info_ident,
  3498. L2CAP_INFO_REQ, sizeof(req), &req);
  3499. } else {
  3500. conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_DONE;
  3501. conn->info_ident = 0;
  3502. l2cap_conn_start(conn);
  3503. }
  3504. break;
  3505. case L2CAP_IT_FIXED_CHAN:
  3506. conn->remote_fixed_chan = rsp->data[0];
  3507. conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_DONE;
  3508. conn->info_ident = 0;
  3509. l2cap_conn_start(conn);
  3510. break;
  3511. }
  3512. return 0;
  3513. }
  3514. static int l2cap_create_channel_req(struct l2cap_conn *conn,
  3515. struct l2cap_cmd_hdr *cmd,
  3516. u16 cmd_len, void *data)
  3517. {
  3518. struct l2cap_create_chan_req *req = data;
  3519. struct l2cap_create_chan_rsp rsp;
  3520. struct l2cap_chan *chan;
  3521. struct hci_dev *hdev;
  3522. u16 psm, scid;
  3523. if (cmd_len != sizeof(*req))
  3524. return -EPROTO;
  3525. if (!(conn->local_fixed_chan & L2CAP_FC_A2MP))
  3526. return -EINVAL;
  3527. psm = le16_to_cpu(req->psm);
  3528. scid = le16_to_cpu(req->scid);
  3529. BT_DBG("psm 0x%2.2x, scid 0x%4.4x, amp_id %d", psm, scid, req->amp_id);
  3530. /* For controller id 0 make BR/EDR connection */
  3531. if (req->amp_id == AMP_ID_BREDR) {
  3532. l2cap_connect(conn, cmd, data, L2CAP_CREATE_CHAN_RSP,
  3533. req->amp_id);
  3534. return 0;
  3535. }
  3536. /* Validate AMP controller id */
  3537. hdev = hci_dev_get(req->amp_id);
  3538. if (!hdev)
  3539. goto error;
  3540. if (hdev->dev_type != HCI_AMP || !test_bit(HCI_UP, &hdev->flags)) {
  3541. hci_dev_put(hdev);
  3542. goto error;
  3543. }
  3544. chan = l2cap_connect(conn, cmd, data, L2CAP_CREATE_CHAN_RSP,
  3545. req->amp_id);
  3546. if (chan) {
  3547. struct amp_mgr *mgr = conn->hcon->amp_mgr;
  3548. struct hci_conn *hs_hcon;
  3549. hs_hcon = hci_conn_hash_lookup_ba(hdev, AMP_LINK,
  3550. &conn->hcon->dst);
  3551. if (!hs_hcon) {
  3552. hci_dev_put(hdev);
  3553. cmd_reject_invalid_cid(conn, cmd->ident, chan->scid,
  3554. chan->dcid);
  3555. return 0;
  3556. }
  3557. BT_DBG("mgr %p bredr_chan %p hs_hcon %p", mgr, chan, hs_hcon);
  3558. mgr->bredr_chan = chan;
  3559. chan->hs_hcon = hs_hcon;
  3560. chan->fcs = L2CAP_FCS_NONE;
  3561. conn->mtu = hdev->block_mtu;
  3562. }
  3563. hci_dev_put(hdev);
  3564. return 0;
  3565. error:
  3566. rsp.dcid = 0;
  3567. rsp.scid = cpu_to_le16(scid);
  3568. rsp.result = cpu_to_le16(L2CAP_CR_BAD_AMP);
  3569. rsp.status = cpu_to_le16(L2CAP_CS_NO_INFO);
  3570. l2cap_send_cmd(conn, cmd->ident, L2CAP_CREATE_CHAN_RSP,
  3571. sizeof(rsp), &rsp);
  3572. return 0;
  3573. }
  3574. static void l2cap_send_move_chan_req(struct l2cap_chan *chan, u8 dest_amp_id)
  3575. {
  3576. struct l2cap_move_chan_req req;
  3577. u8 ident;
  3578. BT_DBG("chan %p, dest_amp_id %d", chan, dest_amp_id);
  3579. ident = l2cap_get_ident(chan->conn);
  3580. chan->ident = ident;
  3581. req.icid = cpu_to_le16(chan->scid);
  3582. req.dest_amp_id = dest_amp_id;
  3583. l2cap_send_cmd(chan->conn, ident, L2CAP_MOVE_CHAN_REQ, sizeof(req),
  3584. &req);
  3585. __set_chan_timer(chan, L2CAP_MOVE_TIMEOUT);
  3586. }
  3587. static void l2cap_send_move_chan_rsp(struct l2cap_chan *chan, u16 result)
  3588. {
  3589. struct l2cap_move_chan_rsp rsp;
  3590. BT_DBG("chan %p, result 0x%4.4x", chan, result);
  3591. rsp.icid = cpu_to_le16(chan->dcid);
  3592. rsp.result = cpu_to_le16(result);
  3593. l2cap_send_cmd(chan->conn, chan->ident, L2CAP_MOVE_CHAN_RSP,
  3594. sizeof(rsp), &rsp);
  3595. }
  3596. static void l2cap_send_move_chan_cfm(struct l2cap_chan *chan, u16 result)
  3597. {
  3598. struct l2cap_move_chan_cfm cfm;
  3599. BT_DBG("chan %p, result 0x%4.4x", chan, result);
  3600. chan->ident = l2cap_get_ident(chan->conn);
  3601. cfm.icid = cpu_to_le16(chan->scid);
  3602. cfm.result = cpu_to_le16(result);
  3603. l2cap_send_cmd(chan->conn, chan->ident, L2CAP_MOVE_CHAN_CFM,
  3604. sizeof(cfm), &cfm);
  3605. __set_chan_timer(chan, L2CAP_MOVE_TIMEOUT);
  3606. }
  3607. static void l2cap_send_move_chan_cfm_icid(struct l2cap_conn *conn, u16 icid)
  3608. {
  3609. struct l2cap_move_chan_cfm cfm;
  3610. BT_DBG("conn %p, icid 0x%4.4x", conn, icid);
  3611. cfm.icid = cpu_to_le16(icid);
  3612. cfm.result = cpu_to_le16(L2CAP_MC_UNCONFIRMED);
  3613. l2cap_send_cmd(conn, l2cap_get_ident(conn), L2CAP_MOVE_CHAN_CFM,
  3614. sizeof(cfm), &cfm);
  3615. }
  3616. static void l2cap_send_move_chan_cfm_rsp(struct l2cap_conn *conn, u8 ident,
  3617. u16 icid)
  3618. {
  3619. struct l2cap_move_chan_cfm_rsp rsp;
  3620. BT_DBG("icid 0x%4.4x", icid);
  3621. rsp.icid = cpu_to_le16(icid);
  3622. l2cap_send_cmd(conn, ident, L2CAP_MOVE_CHAN_CFM_RSP, sizeof(rsp), &rsp);
  3623. }
  3624. static void __release_logical_link(struct l2cap_chan *chan)
  3625. {
  3626. chan->hs_hchan = NULL;
  3627. chan->hs_hcon = NULL;
  3628. /* Placeholder - release the logical link */
  3629. }
  3630. static void l2cap_logical_fail(struct l2cap_chan *chan)
  3631. {
  3632. /* Logical link setup failed */
  3633. if (chan->state != BT_CONNECTED) {
  3634. /* Create channel failure, disconnect */
  3635. l2cap_send_disconn_req(chan, ECONNRESET);
  3636. return;
  3637. }
  3638. switch (chan->move_role) {
  3639. case L2CAP_MOVE_ROLE_RESPONDER:
  3640. l2cap_move_done(chan);
  3641. l2cap_send_move_chan_rsp(chan, L2CAP_MR_NOT_SUPP);
  3642. break;
  3643. case L2CAP_MOVE_ROLE_INITIATOR:
  3644. if (chan->move_state == L2CAP_MOVE_WAIT_LOGICAL_COMP ||
  3645. chan->move_state == L2CAP_MOVE_WAIT_LOGICAL_CFM) {
  3646. /* Remote has only sent pending or
  3647. * success responses, clean up
  3648. */
  3649. l2cap_move_done(chan);
  3650. }
  3651. /* Other amp move states imply that the move
  3652. * has already aborted
  3653. */
  3654. l2cap_send_move_chan_cfm(chan, L2CAP_MC_UNCONFIRMED);
  3655. break;
  3656. }
  3657. }
  3658. static void l2cap_logical_finish_create(struct l2cap_chan *chan,
  3659. struct hci_chan *hchan)
  3660. {
  3661. struct l2cap_conf_rsp rsp;
  3662. chan->hs_hchan = hchan;
  3663. chan->hs_hcon->l2cap_data = chan->conn;
  3664. l2cap_send_efs_conf_rsp(chan, &rsp, chan->ident, 0);
  3665. if (test_bit(CONF_INPUT_DONE, &chan->conf_state)) {
  3666. int err;
  3667. set_default_fcs(chan);
  3668. err = l2cap_ertm_init(chan);
  3669. if (err < 0)
  3670. l2cap_send_disconn_req(chan, -err);
  3671. else
  3672. l2cap_chan_ready(chan);
  3673. }
  3674. }
  3675. static void l2cap_logical_finish_move(struct l2cap_chan *chan,
  3676. struct hci_chan *hchan)
  3677. {
  3678. chan->hs_hcon = hchan->conn;
  3679. chan->hs_hcon->l2cap_data = chan->conn;
  3680. BT_DBG("move_state %d", chan->move_state);
  3681. switch (chan->move_state) {
  3682. case L2CAP_MOVE_WAIT_LOGICAL_COMP:
  3683. /* Move confirm will be sent after a success
  3684. * response is received
  3685. */
  3686. chan->move_state = L2CAP_MOVE_WAIT_RSP_SUCCESS;
  3687. break;
  3688. case L2CAP_MOVE_WAIT_LOGICAL_CFM:
  3689. if (test_bit(CONN_LOCAL_BUSY, &chan->conn_state)) {
  3690. chan->move_state = L2CAP_MOVE_WAIT_LOCAL_BUSY;
  3691. } else if (chan->move_role == L2CAP_MOVE_ROLE_INITIATOR) {
  3692. chan->move_state = L2CAP_MOVE_WAIT_CONFIRM_RSP;
  3693. l2cap_send_move_chan_cfm(chan, L2CAP_MC_CONFIRMED);
  3694. } else if (chan->move_role == L2CAP_MOVE_ROLE_RESPONDER) {
  3695. chan->move_state = L2CAP_MOVE_WAIT_CONFIRM;
  3696. l2cap_send_move_chan_rsp(chan, L2CAP_MR_SUCCESS);
  3697. }
  3698. break;
  3699. default:
  3700. /* Move was not in expected state, free the channel */
  3701. __release_logical_link(chan);
  3702. chan->move_state = L2CAP_MOVE_STABLE;
  3703. }
  3704. }
  3705. /* Call with chan locked */
  3706. void l2cap_logical_cfm(struct l2cap_chan *chan, struct hci_chan *hchan,
  3707. u8 status)
  3708. {
  3709. BT_DBG("chan %p, hchan %p, status %d", chan, hchan, status);
  3710. if (status) {
  3711. l2cap_logical_fail(chan);
  3712. __release_logical_link(chan);
  3713. return;
  3714. }
  3715. if (chan->state != BT_CONNECTED) {
  3716. /* Ignore logical link if channel is on BR/EDR */
  3717. if (chan->local_amp_id != AMP_ID_BREDR)
  3718. l2cap_logical_finish_create(chan, hchan);
  3719. } else {
  3720. l2cap_logical_finish_move(chan, hchan);
  3721. }
  3722. }
  3723. void l2cap_move_start(struct l2cap_chan *chan)
  3724. {
  3725. BT_DBG("chan %p", chan);
  3726. if (chan->local_amp_id == AMP_ID_BREDR) {
  3727. if (chan->chan_policy != BT_CHANNEL_POLICY_AMP_PREFERRED)
  3728. return;
  3729. chan->move_role = L2CAP_MOVE_ROLE_INITIATOR;
  3730. chan->move_state = L2CAP_MOVE_WAIT_PREPARE;
  3731. /* Placeholder - start physical link setup */
  3732. } else {
  3733. chan->move_role = L2CAP_MOVE_ROLE_INITIATOR;
  3734. chan->move_state = L2CAP_MOVE_WAIT_RSP_SUCCESS;
  3735. chan->move_id = 0;
  3736. l2cap_move_setup(chan);
  3737. l2cap_send_move_chan_req(chan, 0);
  3738. }
  3739. }
  3740. static void l2cap_do_create(struct l2cap_chan *chan, int result,
  3741. u8 local_amp_id, u8 remote_amp_id)
  3742. {
  3743. BT_DBG("chan %p state %s %u -> %u", chan, state_to_string(chan->state),
  3744. local_amp_id, remote_amp_id);
  3745. chan->fcs = L2CAP_FCS_NONE;
  3746. /* Outgoing channel on AMP */
  3747. if (chan->state == BT_CONNECT) {
  3748. if (result == L2CAP_CR_SUCCESS) {
  3749. chan->local_amp_id = local_amp_id;
  3750. l2cap_send_create_chan_req(chan, remote_amp_id);
  3751. } else {
  3752. /* Revert to BR/EDR connect */
  3753. l2cap_send_conn_req(chan);
  3754. }
  3755. return;
  3756. }
  3757. /* Incoming channel on AMP */
  3758. if (__l2cap_no_conn_pending(chan)) {
  3759. struct l2cap_conn_rsp rsp;
  3760. char buf[128];
  3761. rsp.scid = cpu_to_le16(chan->dcid);
  3762. rsp.dcid = cpu_to_le16(chan->scid);
  3763. if (result == L2CAP_CR_SUCCESS) {
  3764. /* Send successful response */
  3765. rsp.result = cpu_to_le16(L2CAP_CR_SUCCESS);
  3766. rsp.status = cpu_to_le16(L2CAP_CS_NO_INFO);
  3767. } else {
  3768. /* Send negative response */
  3769. rsp.result = cpu_to_le16(L2CAP_CR_NO_MEM);
  3770. rsp.status = cpu_to_le16(L2CAP_CS_NO_INFO);
  3771. }
  3772. l2cap_send_cmd(chan->conn, chan->ident, L2CAP_CREATE_CHAN_RSP,
  3773. sizeof(rsp), &rsp);
  3774. if (result == L2CAP_CR_SUCCESS) {
  3775. l2cap_state_change(chan, BT_CONFIG);
  3776. set_bit(CONF_REQ_SENT, &chan->conf_state);
  3777. l2cap_send_cmd(chan->conn, l2cap_get_ident(chan->conn),
  3778. L2CAP_CONF_REQ,
  3779. l2cap_build_conf_req(chan, buf, sizeof(buf)), buf);
  3780. chan->num_conf_req++;
  3781. }
  3782. }
  3783. }
  3784. static void l2cap_do_move_initiate(struct l2cap_chan *chan, u8 local_amp_id,
  3785. u8 remote_amp_id)
  3786. {
  3787. l2cap_move_setup(chan);
  3788. chan->move_id = local_amp_id;
  3789. chan->move_state = L2CAP_MOVE_WAIT_RSP;
  3790. l2cap_send_move_chan_req(chan, remote_amp_id);
  3791. }
  3792. static void l2cap_do_move_respond(struct l2cap_chan *chan, int result)
  3793. {
  3794. struct hci_chan *hchan = NULL;
  3795. /* Placeholder - get hci_chan for logical link */
  3796. if (hchan) {
  3797. if (hchan->state == BT_CONNECTED) {
  3798. /* Logical link is ready to go */
  3799. chan->hs_hcon = hchan->conn;
  3800. chan->hs_hcon->l2cap_data = chan->conn;
  3801. chan->move_state = L2CAP_MOVE_WAIT_CONFIRM;
  3802. l2cap_send_move_chan_rsp(chan, L2CAP_MR_SUCCESS);
  3803. l2cap_logical_cfm(chan, hchan, L2CAP_MR_SUCCESS);
  3804. } else {
  3805. /* Wait for logical link to be ready */
  3806. chan->move_state = L2CAP_MOVE_WAIT_LOGICAL_CFM;
  3807. }
  3808. } else {
  3809. /* Logical link not available */
  3810. l2cap_send_move_chan_rsp(chan, L2CAP_MR_NOT_ALLOWED);
  3811. }
  3812. }
  3813. static void l2cap_do_move_cancel(struct l2cap_chan *chan, int result)
  3814. {
  3815. if (chan->move_role == L2CAP_MOVE_ROLE_RESPONDER) {
  3816. u8 rsp_result;
  3817. if (result == -EINVAL)
  3818. rsp_result = L2CAP_MR_BAD_ID;
  3819. else
  3820. rsp_result = L2CAP_MR_NOT_ALLOWED;
  3821. l2cap_send_move_chan_rsp(chan, rsp_result);
  3822. }
  3823. chan->move_role = L2CAP_MOVE_ROLE_NONE;
  3824. chan->move_state = L2CAP_MOVE_STABLE;
  3825. /* Restart data transmission */
  3826. l2cap_ertm_send(chan);
  3827. }
  3828. /* Invoke with locked chan */
  3829. void __l2cap_physical_cfm(struct l2cap_chan *chan, int result)
  3830. {
  3831. u8 local_amp_id = chan->local_amp_id;
  3832. u8 remote_amp_id = chan->remote_amp_id;
  3833. BT_DBG("chan %p, result %d, local_amp_id %d, remote_amp_id %d",
  3834. chan, result, local_amp_id, remote_amp_id);
  3835. if (chan->state == BT_DISCONN || chan->state == BT_CLOSED) {
  3836. l2cap_chan_unlock(chan);
  3837. return;
  3838. }
  3839. if (chan->state != BT_CONNECTED) {
  3840. l2cap_do_create(chan, result, local_amp_id, remote_amp_id);
  3841. } else if (result != L2CAP_MR_SUCCESS) {
  3842. l2cap_do_move_cancel(chan, result);
  3843. } else {
  3844. switch (chan->move_role) {
  3845. case L2CAP_MOVE_ROLE_INITIATOR:
  3846. l2cap_do_move_initiate(chan, local_amp_id,
  3847. remote_amp_id);
  3848. break;
  3849. case L2CAP_MOVE_ROLE_RESPONDER:
  3850. l2cap_do_move_respond(chan, result);
  3851. break;
  3852. default:
  3853. l2cap_do_move_cancel(chan, result);
  3854. break;
  3855. }
  3856. }
  3857. }
  3858. static inline int l2cap_move_channel_req(struct l2cap_conn *conn,
  3859. struct l2cap_cmd_hdr *cmd,
  3860. u16 cmd_len, void *data)
  3861. {
  3862. struct l2cap_move_chan_req *req = data;
  3863. struct l2cap_move_chan_rsp rsp;
  3864. struct l2cap_chan *chan;
  3865. u16 icid = 0;
  3866. u16 result = L2CAP_MR_NOT_ALLOWED;
  3867. if (cmd_len != sizeof(*req))
  3868. return -EPROTO;
  3869. icid = le16_to_cpu(req->icid);
  3870. BT_DBG("icid 0x%4.4x, dest_amp_id %d", icid, req->dest_amp_id);
  3871. if (!(conn->local_fixed_chan & L2CAP_FC_A2MP))
  3872. return -EINVAL;
  3873. chan = l2cap_get_chan_by_dcid(conn, icid);
  3874. if (!chan) {
  3875. rsp.icid = cpu_to_le16(icid);
  3876. rsp.result = cpu_to_le16(L2CAP_MR_NOT_ALLOWED);
  3877. l2cap_send_cmd(conn, cmd->ident, L2CAP_MOVE_CHAN_RSP,
  3878. sizeof(rsp), &rsp);
  3879. return 0;
  3880. }
  3881. chan->ident = cmd->ident;
  3882. if (chan->scid < L2CAP_CID_DYN_START ||
  3883. chan->chan_policy == BT_CHANNEL_POLICY_BREDR_ONLY ||
  3884. (chan->mode != L2CAP_MODE_ERTM &&
  3885. chan->mode != L2CAP_MODE_STREAMING)) {
  3886. result = L2CAP_MR_NOT_ALLOWED;
  3887. goto send_move_response;
  3888. }
  3889. if (chan->local_amp_id == req->dest_amp_id) {
  3890. result = L2CAP_MR_SAME_ID;
  3891. goto send_move_response;
  3892. }
  3893. if (req->dest_amp_id != AMP_ID_BREDR) {
  3894. struct hci_dev *hdev;
  3895. hdev = hci_dev_get(req->dest_amp_id);
  3896. if (!hdev || hdev->dev_type != HCI_AMP ||
  3897. !test_bit(HCI_UP, &hdev->flags)) {
  3898. if (hdev)
  3899. hci_dev_put(hdev);
  3900. result = L2CAP_MR_BAD_ID;
  3901. goto send_move_response;
  3902. }
  3903. hci_dev_put(hdev);
  3904. }
  3905. /* Detect a move collision. Only send a collision response
  3906. * if this side has "lost", otherwise proceed with the move.
  3907. * The winner has the larger bd_addr.
  3908. */
  3909. if ((__chan_is_moving(chan) ||
  3910. chan->move_role != L2CAP_MOVE_ROLE_NONE) &&
  3911. bacmp(&conn->hcon->src, &conn->hcon->dst) > 0) {
  3912. result = L2CAP_MR_COLLISION;
  3913. goto send_move_response;
  3914. }
  3915. chan->move_role = L2CAP_MOVE_ROLE_RESPONDER;
  3916. l2cap_move_setup(chan);
  3917. chan->move_id = req->dest_amp_id;
  3918. icid = chan->dcid;
  3919. if (req->dest_amp_id == AMP_ID_BREDR) {
  3920. /* Moving to BR/EDR */
  3921. if (test_bit(CONN_LOCAL_BUSY, &chan->conn_state)) {
  3922. chan->move_state = L2CAP_MOVE_WAIT_LOCAL_BUSY;
  3923. result = L2CAP_MR_PEND;
  3924. } else {
  3925. chan->move_state = L2CAP_MOVE_WAIT_CONFIRM;
  3926. result = L2CAP_MR_SUCCESS;
  3927. }
  3928. } else {
  3929. chan->move_state = L2CAP_MOVE_WAIT_PREPARE;
  3930. /* Placeholder - uncomment when amp functions are available */
  3931. /*amp_accept_physical(chan, req->dest_amp_id);*/
  3932. result = L2CAP_MR_PEND;
  3933. }
  3934. send_move_response:
  3935. l2cap_send_move_chan_rsp(chan, result);
  3936. l2cap_chan_unlock(chan);
  3937. return 0;
  3938. }
  3939. static void l2cap_move_continue(struct l2cap_conn *conn, u16 icid, u16 result)
  3940. {
  3941. struct l2cap_chan *chan;
  3942. struct hci_chan *hchan = NULL;
  3943. chan = l2cap_get_chan_by_scid(conn, icid);
  3944. if (!chan) {
  3945. l2cap_send_move_chan_cfm_icid(conn, icid);
  3946. return;
  3947. }
  3948. __clear_chan_timer(chan);
  3949. if (result == L2CAP_MR_PEND)
  3950. __set_chan_timer(chan, L2CAP_MOVE_ERTX_TIMEOUT);
  3951. switch (chan->move_state) {
  3952. case L2CAP_MOVE_WAIT_LOGICAL_COMP:
  3953. /* Move confirm will be sent when logical link
  3954. * is complete.
  3955. */
  3956. chan->move_state = L2CAP_MOVE_WAIT_LOGICAL_CFM;
  3957. break;
  3958. case L2CAP_MOVE_WAIT_RSP_SUCCESS:
  3959. if (result == L2CAP_MR_PEND) {
  3960. break;
  3961. } else if (test_bit(CONN_LOCAL_BUSY,
  3962. &chan->conn_state)) {
  3963. chan->move_state = L2CAP_MOVE_WAIT_LOCAL_BUSY;
  3964. } else {
  3965. /* Logical link is up or moving to BR/EDR,
  3966. * proceed with move
  3967. */
  3968. chan->move_state = L2CAP_MOVE_WAIT_CONFIRM_RSP;
  3969. l2cap_send_move_chan_cfm(chan, L2CAP_MC_CONFIRMED);
  3970. }
  3971. break;
  3972. case L2CAP_MOVE_WAIT_RSP:
  3973. /* Moving to AMP */
  3974. if (result == L2CAP_MR_SUCCESS) {
  3975. /* Remote is ready, send confirm immediately
  3976. * after logical link is ready
  3977. */
  3978. chan->move_state = L2CAP_MOVE_WAIT_LOGICAL_CFM;
  3979. } else {
  3980. /* Both logical link and move success
  3981. * are required to confirm
  3982. */
  3983. chan->move_state = L2CAP_MOVE_WAIT_LOGICAL_COMP;
  3984. }
  3985. /* Placeholder - get hci_chan for logical link */
  3986. if (!hchan) {
  3987. /* Logical link not available */
  3988. l2cap_send_move_chan_cfm(chan, L2CAP_MC_UNCONFIRMED);
  3989. break;
  3990. }
  3991. /* If the logical link is not yet connected, do not
  3992. * send confirmation.
  3993. */
  3994. if (hchan->state != BT_CONNECTED)
  3995. break;
  3996. /* Logical link is already ready to go */
  3997. chan->hs_hcon = hchan->conn;
  3998. chan->hs_hcon->l2cap_data = chan->conn;
  3999. if (result == L2CAP_MR_SUCCESS) {
  4000. /* Can confirm now */
  4001. l2cap_send_move_chan_cfm(chan, L2CAP_MC_CONFIRMED);
  4002. } else {
  4003. /* Now only need move success
  4004. * to confirm
  4005. */
  4006. chan->move_state = L2CAP_MOVE_WAIT_RSP_SUCCESS;
  4007. }
  4008. l2cap_logical_cfm(chan, hchan, L2CAP_MR_SUCCESS);
  4009. break;
  4010. default:
  4011. /* Any other amp move state means the move failed. */
  4012. chan->move_id = chan->local_amp_id;
  4013. l2cap_move_done(chan);
  4014. l2cap_send_move_chan_cfm(chan, L2CAP_MC_UNCONFIRMED);
  4015. }
  4016. l2cap_chan_unlock(chan);
  4017. }
  4018. static void l2cap_move_fail(struct l2cap_conn *conn, u8 ident, u16 icid,
  4019. u16 result)
  4020. {
  4021. struct l2cap_chan *chan;
  4022. chan = l2cap_get_chan_by_ident(conn, ident);
  4023. if (!chan) {
  4024. /* Could not locate channel, icid is best guess */
  4025. l2cap_send_move_chan_cfm_icid(conn, icid);
  4026. return;
  4027. }
  4028. __clear_chan_timer(chan);
  4029. if (chan->move_role == L2CAP_MOVE_ROLE_INITIATOR) {
  4030. if (result == L2CAP_MR_COLLISION) {
  4031. chan->move_role = L2CAP_MOVE_ROLE_RESPONDER;
  4032. } else {
  4033. /* Cleanup - cancel move */
  4034. chan->move_id = chan->local_amp_id;
  4035. l2cap_move_done(chan);
  4036. }
  4037. }
  4038. l2cap_send_move_chan_cfm(chan, L2CAP_MC_UNCONFIRMED);
  4039. l2cap_chan_unlock(chan);
  4040. }
  4041. static int l2cap_move_channel_rsp(struct l2cap_conn *conn,
  4042. struct l2cap_cmd_hdr *cmd,
  4043. u16 cmd_len, void *data)
  4044. {
  4045. struct l2cap_move_chan_rsp *rsp = data;
  4046. u16 icid, result;
  4047. if (cmd_len != sizeof(*rsp))
  4048. return -EPROTO;
  4049. icid = le16_to_cpu(rsp->icid);
  4050. result = le16_to_cpu(rsp->result);
  4051. BT_DBG("icid 0x%4.4x, result 0x%4.4x", icid, result);
  4052. if (result == L2CAP_MR_SUCCESS || result == L2CAP_MR_PEND)
  4053. l2cap_move_continue(conn, icid, result);
  4054. else
  4055. l2cap_move_fail(conn, cmd->ident, icid, result);
  4056. return 0;
  4057. }
  4058. static int l2cap_move_channel_confirm(struct l2cap_conn *conn,
  4059. struct l2cap_cmd_hdr *cmd,
  4060. u16 cmd_len, void *data)
  4061. {
  4062. struct l2cap_move_chan_cfm *cfm = data;
  4063. struct l2cap_chan *chan;
  4064. u16 icid, result;
  4065. if (cmd_len != sizeof(*cfm))
  4066. return -EPROTO;
  4067. icid = le16_to_cpu(cfm->icid);
  4068. result = le16_to_cpu(cfm->result);
  4069. BT_DBG("icid 0x%4.4x, result 0x%4.4x", icid, result);
  4070. chan = l2cap_get_chan_by_dcid(conn, icid);
  4071. if (!chan) {
  4072. /* Spec requires a response even if the icid was not found */
  4073. l2cap_send_move_chan_cfm_rsp(conn, cmd->ident, icid);
  4074. return 0;
  4075. }
  4076. if (chan->move_state == L2CAP_MOVE_WAIT_CONFIRM) {
  4077. if (result == L2CAP_MC_CONFIRMED) {
  4078. chan->local_amp_id = chan->move_id;
  4079. if (chan->local_amp_id == AMP_ID_BREDR)
  4080. __release_logical_link(chan);
  4081. } else {
  4082. chan->move_id = chan->local_amp_id;
  4083. }
  4084. l2cap_move_done(chan);
  4085. }
  4086. l2cap_send_move_chan_cfm_rsp(conn, cmd->ident, icid);
  4087. l2cap_chan_unlock(chan);
  4088. return 0;
  4089. }
  4090. static inline int l2cap_move_channel_confirm_rsp(struct l2cap_conn *conn,
  4091. struct l2cap_cmd_hdr *cmd,
  4092. u16 cmd_len, void *data)
  4093. {
  4094. struct l2cap_move_chan_cfm_rsp *rsp = data;
  4095. struct l2cap_chan *chan;
  4096. u16 icid;
  4097. if (cmd_len != sizeof(*rsp))
  4098. return -EPROTO;
  4099. icid = le16_to_cpu(rsp->icid);
  4100. BT_DBG("icid 0x%4.4x", icid);
  4101. chan = l2cap_get_chan_by_scid(conn, icid);
  4102. if (!chan)
  4103. return 0;
  4104. __clear_chan_timer(chan);
  4105. if (chan->move_state == L2CAP_MOVE_WAIT_CONFIRM_RSP) {
  4106. chan->local_amp_id = chan->move_id;
  4107. if (chan->local_amp_id == AMP_ID_BREDR && chan->hs_hchan)
  4108. __release_logical_link(chan);
  4109. l2cap_move_done(chan);
  4110. }
  4111. l2cap_chan_unlock(chan);
  4112. return 0;
  4113. }
  4114. static inline int l2cap_conn_param_update_req(struct l2cap_conn *conn,
  4115. struct l2cap_cmd_hdr *cmd,
  4116. u16 cmd_len, u8 *data)
  4117. {
  4118. struct hci_conn *hcon = conn->hcon;
  4119. struct l2cap_conn_param_update_req *req;
  4120. struct l2cap_conn_param_update_rsp rsp;
  4121. u16 min, max, latency, to_multiplier;
  4122. int err;
  4123. if (hcon->role != HCI_ROLE_MASTER)
  4124. return -EINVAL;
  4125. if (cmd_len != sizeof(struct l2cap_conn_param_update_req))
  4126. return -EPROTO;
  4127. req = (struct l2cap_conn_param_update_req *) data;
  4128. min = __le16_to_cpu(req->min);
  4129. max = __le16_to_cpu(req->max);
  4130. latency = __le16_to_cpu(req->latency);
  4131. to_multiplier = __le16_to_cpu(req->to_multiplier);
  4132. BT_DBG("min 0x%4.4x max 0x%4.4x latency: 0x%4.4x Timeout: 0x%4.4x",
  4133. min, max, latency, to_multiplier);
  4134. memset(&rsp, 0, sizeof(rsp));
  4135. err = hci_check_conn_params(min, max, latency, to_multiplier);
  4136. if (err)
  4137. rsp.result = cpu_to_le16(L2CAP_CONN_PARAM_REJECTED);
  4138. else
  4139. rsp.result = cpu_to_le16(L2CAP_CONN_PARAM_ACCEPTED);
  4140. l2cap_send_cmd(conn, cmd->ident, L2CAP_CONN_PARAM_UPDATE_RSP,
  4141. sizeof(rsp), &rsp);
  4142. if (!err) {
  4143. u8 store_hint;
  4144. store_hint = hci_le_conn_update(hcon, min, max, latency,
  4145. to_multiplier);
  4146. mgmt_new_conn_param(hcon->hdev, &hcon->dst, hcon->dst_type,
  4147. store_hint, min, max, latency,
  4148. to_multiplier);
  4149. }
  4150. return 0;
  4151. }
  4152. static int l2cap_le_connect_rsp(struct l2cap_conn *conn,
  4153. struct l2cap_cmd_hdr *cmd, u16 cmd_len,
  4154. u8 *data)
  4155. {
  4156. struct l2cap_le_conn_rsp *rsp = (struct l2cap_le_conn_rsp *) data;
  4157. struct hci_conn *hcon = conn->hcon;
  4158. u16 dcid, mtu, mps, credits, result;
  4159. struct l2cap_chan *chan;
  4160. int err, sec_level;
  4161. if (cmd_len < sizeof(*rsp))
  4162. return -EPROTO;
  4163. dcid = __le16_to_cpu(rsp->dcid);
  4164. mtu = __le16_to_cpu(rsp->mtu);
  4165. mps = __le16_to_cpu(rsp->mps);
  4166. credits = __le16_to_cpu(rsp->credits);
  4167. result = __le16_to_cpu(rsp->result);
  4168. if (result == L2CAP_CR_SUCCESS && (mtu < 23 || mps < 23 ||
  4169. dcid < L2CAP_CID_DYN_START ||
  4170. dcid > L2CAP_CID_LE_DYN_END))
  4171. return -EPROTO;
  4172. BT_DBG("dcid 0x%4.4x mtu %u mps %u credits %u result 0x%2.2x",
  4173. dcid, mtu, mps, credits, result);
  4174. mutex_lock(&conn->chan_lock);
  4175. chan = __l2cap_get_chan_by_ident(conn, cmd->ident);
  4176. if (!chan) {
  4177. err = -EBADSLT;
  4178. goto unlock;
  4179. }
  4180. err = 0;
  4181. l2cap_chan_lock(chan);
  4182. switch (result) {
  4183. case L2CAP_CR_SUCCESS:
  4184. if (__l2cap_get_chan_by_dcid(conn, dcid)) {
  4185. err = -EBADSLT;
  4186. break;
  4187. }
  4188. chan->ident = 0;
  4189. chan->dcid = dcid;
  4190. chan->omtu = mtu;
  4191. chan->remote_mps = mps;
  4192. chan->tx_credits = credits;
  4193. l2cap_chan_ready(chan);
  4194. break;
  4195. case L2CAP_CR_AUTHENTICATION:
  4196. case L2CAP_CR_ENCRYPTION:
  4197. /* If we already have MITM protection we can't do
  4198. * anything.
  4199. */
  4200. if (hcon->sec_level > BT_SECURITY_MEDIUM) {
  4201. l2cap_chan_del(chan, ECONNREFUSED);
  4202. break;
  4203. }
  4204. sec_level = hcon->sec_level + 1;
  4205. if (chan->sec_level < sec_level)
  4206. chan->sec_level = sec_level;
  4207. /* We'll need to send a new Connect Request */
  4208. clear_bit(FLAG_LE_CONN_REQ_SENT, &chan->flags);
  4209. smp_conn_security(hcon, chan->sec_level);
  4210. break;
  4211. default:
  4212. l2cap_chan_del(chan, ECONNREFUSED);
  4213. break;
  4214. }
  4215. l2cap_chan_unlock(chan);
  4216. unlock:
  4217. mutex_unlock(&conn->chan_lock);
  4218. return err;
  4219. }
  4220. static inline int l2cap_bredr_sig_cmd(struct l2cap_conn *conn,
  4221. struct l2cap_cmd_hdr *cmd, u16 cmd_len,
  4222. u8 *data)
  4223. {
  4224. int err = 0;
  4225. switch (cmd->code) {
  4226. case L2CAP_COMMAND_REJ:
  4227. l2cap_command_rej(conn, cmd, cmd_len, data);
  4228. break;
  4229. case L2CAP_CONN_REQ:
  4230. err = l2cap_connect_req(conn, cmd, cmd_len, data);
  4231. break;
  4232. case L2CAP_CONN_RSP:
  4233. case L2CAP_CREATE_CHAN_RSP:
  4234. l2cap_connect_create_rsp(conn, cmd, cmd_len, data);
  4235. break;
  4236. case L2CAP_CONF_REQ:
  4237. err = l2cap_config_req(conn, cmd, cmd_len, data);
  4238. break;
  4239. case L2CAP_CONF_RSP:
  4240. l2cap_config_rsp(conn, cmd, cmd_len, data);
  4241. break;
  4242. case L2CAP_DISCONN_REQ:
  4243. err = l2cap_disconnect_req(conn, cmd, cmd_len, data);
  4244. break;
  4245. case L2CAP_DISCONN_RSP:
  4246. l2cap_disconnect_rsp(conn, cmd, cmd_len, data);
  4247. break;
  4248. case L2CAP_ECHO_REQ:
  4249. l2cap_send_cmd(conn, cmd->ident, L2CAP_ECHO_RSP, cmd_len, data);
  4250. break;
  4251. case L2CAP_ECHO_RSP:
  4252. break;
  4253. case L2CAP_INFO_REQ:
  4254. err = l2cap_information_req(conn, cmd, cmd_len, data);
  4255. break;
  4256. case L2CAP_INFO_RSP:
  4257. l2cap_information_rsp(conn, cmd, cmd_len, data);
  4258. break;
  4259. case L2CAP_CREATE_CHAN_REQ:
  4260. err = l2cap_create_channel_req(conn, cmd, cmd_len, data);
  4261. break;
  4262. case L2CAP_MOVE_CHAN_REQ:
  4263. err = l2cap_move_channel_req(conn, cmd, cmd_len, data);
  4264. break;
  4265. case L2CAP_MOVE_CHAN_RSP:
  4266. l2cap_move_channel_rsp(conn, cmd, cmd_len, data);
  4267. break;
  4268. case L2CAP_MOVE_CHAN_CFM:
  4269. err = l2cap_move_channel_confirm(conn, cmd, cmd_len, data);
  4270. break;
  4271. case L2CAP_MOVE_CHAN_CFM_RSP:
  4272. l2cap_move_channel_confirm_rsp(conn, cmd, cmd_len, data);
  4273. break;
  4274. default:
  4275. BT_ERR("Unknown BR/EDR signaling command 0x%2.2x", cmd->code);
  4276. err = -EINVAL;
  4277. break;
  4278. }
  4279. return err;
  4280. }
  4281. static int l2cap_le_connect_req(struct l2cap_conn *conn,
  4282. struct l2cap_cmd_hdr *cmd, u16 cmd_len,
  4283. u8 *data)
  4284. {
  4285. struct l2cap_le_conn_req *req = (struct l2cap_le_conn_req *) data;
  4286. struct l2cap_le_conn_rsp rsp;
  4287. struct l2cap_chan *chan, *pchan;
  4288. u16 dcid, scid, credits, mtu, mps;
  4289. __le16 psm;
  4290. u8 result;
  4291. if (cmd_len != sizeof(*req))
  4292. return -EPROTO;
  4293. scid = __le16_to_cpu(req->scid);
  4294. mtu = __le16_to_cpu(req->mtu);
  4295. mps = __le16_to_cpu(req->mps);
  4296. psm = req->psm;
  4297. dcid = 0;
  4298. credits = 0;
  4299. if (mtu < 23 || mps < 23)
  4300. return -EPROTO;
  4301. BT_DBG("psm 0x%2.2x scid 0x%4.4x mtu %u mps %u", __le16_to_cpu(psm),
  4302. scid, mtu, mps);
  4303. /* Check if we have socket listening on psm */
  4304. pchan = l2cap_global_chan_by_psm(BT_LISTEN, psm, &conn->hcon->src,
  4305. &conn->hcon->dst, LE_LINK);
  4306. if (!pchan) {
  4307. result = L2CAP_CR_BAD_PSM;
  4308. chan = NULL;
  4309. goto response;
  4310. }
  4311. mutex_lock(&conn->chan_lock);
  4312. l2cap_chan_lock(pchan);
  4313. if (!smp_sufficient_security(conn->hcon, pchan->sec_level,
  4314. SMP_ALLOW_STK)) {
  4315. result = L2CAP_CR_AUTHENTICATION;
  4316. chan = NULL;
  4317. goto response_unlock;
  4318. }
  4319. /* Check for valid dynamic CID range */
  4320. if (scid < L2CAP_CID_DYN_START || scid > L2CAP_CID_LE_DYN_END) {
  4321. result = L2CAP_CR_INVALID_SCID;
  4322. chan = NULL;
  4323. goto response_unlock;
  4324. }
  4325. /* Check if we already have channel with that dcid */
  4326. if (__l2cap_get_chan_by_dcid(conn, scid)) {
  4327. result = L2CAP_CR_SCID_IN_USE;
  4328. chan = NULL;
  4329. goto response_unlock;
  4330. }
  4331. chan = pchan->ops->new_connection(pchan);
  4332. if (!chan) {
  4333. result = L2CAP_CR_NO_MEM;
  4334. goto response_unlock;
  4335. }
  4336. l2cap_le_flowctl_init(chan);
  4337. bacpy(&chan->src, &conn->hcon->src);
  4338. bacpy(&chan->dst, &conn->hcon->dst);
  4339. chan->src_type = bdaddr_src_type(conn->hcon);
  4340. chan->dst_type = bdaddr_dst_type(conn->hcon);
  4341. chan->psm = psm;
  4342. chan->dcid = scid;
  4343. chan->omtu = mtu;
  4344. chan->remote_mps = mps;
  4345. chan->tx_credits = __le16_to_cpu(req->credits);
  4346. __l2cap_chan_add(conn, chan);
  4347. dcid = chan->scid;
  4348. credits = chan->rx_credits;
  4349. __set_chan_timer(chan, chan->ops->get_sndtimeo(chan));
  4350. chan->ident = cmd->ident;
  4351. if (test_bit(FLAG_DEFER_SETUP, &chan->flags)) {
  4352. l2cap_state_change(chan, BT_CONNECT2);
  4353. /* The following result value is actually not defined
  4354. * for LE CoC but we use it to let the function know
  4355. * that it should bail out after doing its cleanup
  4356. * instead of sending a response.
  4357. */
  4358. result = L2CAP_CR_PEND;
  4359. chan->ops->defer(chan);
  4360. } else {
  4361. l2cap_chan_ready(chan);
  4362. result = L2CAP_CR_SUCCESS;
  4363. }
  4364. response_unlock:
  4365. l2cap_chan_unlock(pchan);
  4366. mutex_unlock(&conn->chan_lock);
  4367. l2cap_chan_put(pchan);
  4368. if (result == L2CAP_CR_PEND)
  4369. return 0;
  4370. response:
  4371. if (chan) {
  4372. rsp.mtu = cpu_to_le16(chan->imtu);
  4373. rsp.mps = cpu_to_le16(chan->mps);
  4374. } else {
  4375. rsp.mtu = 0;
  4376. rsp.mps = 0;
  4377. }
  4378. rsp.dcid = cpu_to_le16(dcid);
  4379. rsp.credits = cpu_to_le16(credits);
  4380. rsp.result = cpu_to_le16(result);
  4381. l2cap_send_cmd(conn, cmd->ident, L2CAP_LE_CONN_RSP, sizeof(rsp), &rsp);
  4382. return 0;
  4383. }
  4384. static inline int l2cap_le_credits(struct l2cap_conn *conn,
  4385. struct l2cap_cmd_hdr *cmd, u16 cmd_len,
  4386. u8 *data)
  4387. {
  4388. struct l2cap_le_credits *pkt;
  4389. struct l2cap_chan *chan;
  4390. u16 cid, credits, max_credits;
  4391. if (cmd_len != sizeof(*pkt))
  4392. return -EPROTO;
  4393. pkt = (struct l2cap_le_credits *) data;
  4394. cid = __le16_to_cpu(pkt->cid);
  4395. credits = __le16_to_cpu(pkt->credits);
  4396. BT_DBG("cid 0x%4.4x credits 0x%4.4x", cid, credits);
  4397. chan = l2cap_get_chan_by_dcid(conn, cid);
  4398. if (!chan)
  4399. return -EBADSLT;
  4400. max_credits = LE_FLOWCTL_MAX_CREDITS - chan->tx_credits;
  4401. if (credits > max_credits) {
  4402. BT_ERR("LE credits overflow");
  4403. l2cap_send_disconn_req(chan, ECONNRESET);
  4404. l2cap_chan_unlock(chan);
  4405. /* Return 0 so that we don't trigger an unnecessary
  4406. * command reject packet.
  4407. */
  4408. return 0;
  4409. }
  4410. chan->tx_credits += credits;
  4411. while (chan->tx_credits && !skb_queue_empty(&chan->tx_q)) {
  4412. l2cap_do_send(chan, skb_dequeue(&chan->tx_q));
  4413. chan->tx_credits--;
  4414. }
  4415. if (chan->tx_credits)
  4416. chan->ops->resume(chan);
  4417. l2cap_chan_unlock(chan);
  4418. return 0;
  4419. }
  4420. static inline int l2cap_le_command_rej(struct l2cap_conn *conn,
  4421. struct l2cap_cmd_hdr *cmd, u16 cmd_len,
  4422. u8 *data)
  4423. {
  4424. struct l2cap_cmd_rej_unk *rej = (struct l2cap_cmd_rej_unk *) data;
  4425. struct l2cap_chan *chan;
  4426. if (cmd_len < sizeof(*rej))
  4427. return -EPROTO;
  4428. mutex_lock(&conn->chan_lock);
  4429. chan = __l2cap_get_chan_by_ident(conn, cmd->ident);
  4430. if (!chan)
  4431. goto done;
  4432. l2cap_chan_lock(chan);
  4433. l2cap_chan_del(chan, ECONNREFUSED);
  4434. l2cap_chan_unlock(chan);
  4435. done:
  4436. mutex_unlock(&conn->chan_lock);
  4437. return 0;
  4438. }
  4439. static inline int l2cap_le_sig_cmd(struct l2cap_conn *conn,
  4440. struct l2cap_cmd_hdr *cmd, u16 cmd_len,
  4441. u8 *data)
  4442. {
  4443. int err = 0;
  4444. switch (cmd->code) {
  4445. case L2CAP_COMMAND_REJ:
  4446. l2cap_le_command_rej(conn, cmd, cmd_len, data);
  4447. break;
  4448. case L2CAP_CONN_PARAM_UPDATE_REQ:
  4449. err = l2cap_conn_param_update_req(conn, cmd, cmd_len, data);
  4450. break;
  4451. case L2CAP_CONN_PARAM_UPDATE_RSP:
  4452. break;
  4453. case L2CAP_LE_CONN_RSP:
  4454. l2cap_le_connect_rsp(conn, cmd, cmd_len, data);
  4455. break;
  4456. case L2CAP_LE_CONN_REQ:
  4457. err = l2cap_le_connect_req(conn, cmd, cmd_len, data);
  4458. break;
  4459. case L2CAP_LE_CREDITS:
  4460. err = l2cap_le_credits(conn, cmd, cmd_len, data);
  4461. break;
  4462. case L2CAP_DISCONN_REQ:
  4463. err = l2cap_disconnect_req(conn, cmd, cmd_len, data);
  4464. break;
  4465. case L2CAP_DISCONN_RSP:
  4466. l2cap_disconnect_rsp(conn, cmd, cmd_len, data);
  4467. break;
  4468. default:
  4469. BT_ERR("Unknown LE signaling command 0x%2.2x", cmd->code);
  4470. err = -EINVAL;
  4471. break;
  4472. }
  4473. return err;
  4474. }
  4475. static inline void l2cap_le_sig_channel(struct l2cap_conn *conn,
  4476. struct sk_buff *skb)
  4477. {
  4478. struct hci_conn *hcon = conn->hcon;
  4479. struct l2cap_cmd_hdr *cmd;
  4480. u16 len;
  4481. int err;
  4482. if (hcon->type != LE_LINK)
  4483. goto drop;
  4484. if (skb->len < L2CAP_CMD_HDR_SIZE)
  4485. goto drop;
  4486. cmd = (void *) skb->data;
  4487. skb_pull(skb, L2CAP_CMD_HDR_SIZE);
  4488. len = le16_to_cpu(cmd->len);
  4489. BT_DBG("code 0x%2.2x len %d id 0x%2.2x", cmd->code, len, cmd->ident);
  4490. if (len != skb->len || !cmd->ident) {
  4491. BT_DBG("corrupted command");
  4492. goto drop;
  4493. }
  4494. err = l2cap_le_sig_cmd(conn, cmd, len, skb->data);
  4495. if (err) {
  4496. struct l2cap_cmd_rej_unk rej;
  4497. BT_ERR("Wrong link type (%d)", err);
  4498. rej.reason = cpu_to_le16(L2CAP_REJ_NOT_UNDERSTOOD);
  4499. l2cap_send_cmd(conn, cmd->ident, L2CAP_COMMAND_REJ,
  4500. sizeof(rej), &rej);
  4501. }
  4502. drop:
  4503. kfree_skb(skb);
  4504. }
  4505. static inline void l2cap_sig_channel(struct l2cap_conn *conn,
  4506. struct sk_buff *skb)
  4507. {
  4508. struct hci_conn *hcon = conn->hcon;
  4509. u8 *data = skb->data;
  4510. int len = skb->len;
  4511. struct l2cap_cmd_hdr cmd;
  4512. int err;
  4513. l2cap_raw_recv(conn, skb);
  4514. if (hcon->type != ACL_LINK)
  4515. goto drop;
  4516. while (len >= L2CAP_CMD_HDR_SIZE) {
  4517. u16 cmd_len;
  4518. memcpy(&cmd, data, L2CAP_CMD_HDR_SIZE);
  4519. data += L2CAP_CMD_HDR_SIZE;
  4520. len -= L2CAP_CMD_HDR_SIZE;
  4521. cmd_len = le16_to_cpu(cmd.len);
  4522. BT_DBG("code 0x%2.2x len %d id 0x%2.2x", cmd.code, cmd_len,
  4523. cmd.ident);
  4524. if (cmd_len > len || !cmd.ident) {
  4525. BT_DBG("corrupted command");
  4526. break;
  4527. }
  4528. err = l2cap_bredr_sig_cmd(conn, &cmd, cmd_len, data);
  4529. if (err) {
  4530. struct l2cap_cmd_rej_unk rej;
  4531. BT_ERR("Wrong link type (%d)", err);
  4532. rej.reason = cpu_to_le16(L2CAP_REJ_NOT_UNDERSTOOD);
  4533. l2cap_send_cmd(conn, cmd.ident, L2CAP_COMMAND_REJ,
  4534. sizeof(rej), &rej);
  4535. }
  4536. data += cmd_len;
  4537. len -= cmd_len;
  4538. }
  4539. drop:
  4540. kfree_skb(skb);
  4541. }
  4542. static int l2cap_check_fcs(struct l2cap_chan *chan, struct sk_buff *skb)
  4543. {
  4544. u16 our_fcs, rcv_fcs;
  4545. int hdr_size;
  4546. if (test_bit(FLAG_EXT_CTRL, &chan->flags))
  4547. hdr_size = L2CAP_EXT_HDR_SIZE;
  4548. else
  4549. hdr_size = L2CAP_ENH_HDR_SIZE;
  4550. if (chan->fcs == L2CAP_FCS_CRC16) {
  4551. skb_trim(skb, skb->len - L2CAP_FCS_SIZE);
  4552. rcv_fcs = get_unaligned_le16(skb->data + skb->len);
  4553. our_fcs = crc16(0, skb->data - hdr_size, skb->len + hdr_size);
  4554. if (our_fcs != rcv_fcs)
  4555. return -EBADMSG;
  4556. }
  4557. return 0;
  4558. }
  4559. static void l2cap_send_i_or_rr_or_rnr(struct l2cap_chan *chan)
  4560. {
  4561. struct l2cap_ctrl control;
  4562. BT_DBG("chan %p", chan);
  4563. memset(&control, 0, sizeof(control));
  4564. control.sframe = 1;
  4565. control.final = 1;
  4566. control.reqseq = chan->buffer_seq;
  4567. set_bit(CONN_SEND_FBIT, &chan->conn_state);
  4568. if (test_bit(CONN_LOCAL_BUSY, &chan->conn_state)) {
  4569. control.super = L2CAP_SUPER_RNR;
  4570. l2cap_send_sframe(chan, &control);
  4571. }
  4572. if (test_and_clear_bit(CONN_REMOTE_BUSY, &chan->conn_state) &&
  4573. chan->unacked_frames > 0)
  4574. __set_retrans_timer(chan);
  4575. /* Send pending iframes */
  4576. l2cap_ertm_send(chan);
  4577. if (!test_bit(CONN_LOCAL_BUSY, &chan->conn_state) &&
  4578. test_bit(CONN_SEND_FBIT, &chan->conn_state)) {
  4579. /* F-bit wasn't sent in an s-frame or i-frame yet, so
  4580. * send it now.
  4581. */
  4582. control.super = L2CAP_SUPER_RR;
  4583. l2cap_send_sframe(chan, &control);
  4584. }
  4585. }
  4586. static void append_skb_frag(struct sk_buff *skb, struct sk_buff *new_frag,
  4587. struct sk_buff **last_frag)
  4588. {
  4589. /* skb->len reflects data in skb as well as all fragments
  4590. * skb->data_len reflects only data in fragments
  4591. */
  4592. if (!skb_has_frag_list(skb))
  4593. skb_shinfo(skb)->frag_list = new_frag;
  4594. new_frag->next = NULL;
  4595. (*last_frag)->next = new_frag;
  4596. *last_frag = new_frag;
  4597. skb->len += new_frag->len;
  4598. skb->data_len += new_frag->len;
  4599. skb->truesize += new_frag->truesize;
  4600. }
  4601. static int l2cap_reassemble_sdu(struct l2cap_chan *chan, struct sk_buff *skb,
  4602. struct l2cap_ctrl *control)
  4603. {
  4604. int err = -EINVAL;
  4605. switch (control->sar) {
  4606. case L2CAP_SAR_UNSEGMENTED:
  4607. if (chan->sdu)
  4608. break;
  4609. err = chan->ops->recv(chan, skb);
  4610. break;
  4611. case L2CAP_SAR_START:
  4612. if (chan->sdu)
  4613. break;
  4614. chan->sdu_len = get_unaligned_le16(skb->data);
  4615. skb_pull(skb, L2CAP_SDULEN_SIZE);
  4616. if (chan->sdu_len > chan->imtu) {
  4617. err = -EMSGSIZE;
  4618. break;
  4619. }
  4620. if (skb->len >= chan->sdu_len)
  4621. break;
  4622. chan->sdu = skb;
  4623. chan->sdu_last_frag = skb;
  4624. skb = NULL;
  4625. err = 0;
  4626. break;
  4627. case L2CAP_SAR_CONTINUE:
  4628. if (!chan->sdu)
  4629. break;
  4630. append_skb_frag(chan->sdu, skb,
  4631. &chan->sdu_last_frag);
  4632. skb = NULL;
  4633. if (chan->sdu->len >= chan->sdu_len)
  4634. break;
  4635. err = 0;
  4636. break;
  4637. case L2CAP_SAR_END:
  4638. if (!chan->sdu)
  4639. break;
  4640. append_skb_frag(chan->sdu, skb,
  4641. &chan->sdu_last_frag);
  4642. skb = NULL;
  4643. if (chan->sdu->len != chan->sdu_len)
  4644. break;
  4645. err = chan->ops->recv(chan, chan->sdu);
  4646. if (!err) {
  4647. /* Reassembly complete */
  4648. chan->sdu = NULL;
  4649. chan->sdu_last_frag = NULL;
  4650. chan->sdu_len = 0;
  4651. }
  4652. break;
  4653. }
  4654. if (err) {
  4655. kfree_skb(skb);
  4656. kfree_skb(chan->sdu);
  4657. chan->sdu = NULL;
  4658. chan->sdu_last_frag = NULL;
  4659. chan->sdu_len = 0;
  4660. }
  4661. return err;
  4662. }
  4663. static int l2cap_resegment(struct l2cap_chan *chan)
  4664. {
  4665. /* Placeholder */
  4666. return 0;
  4667. }
  4668. void l2cap_chan_busy(struct l2cap_chan *chan, int busy)
  4669. {
  4670. u8 event;
  4671. if (chan->mode != L2CAP_MODE_ERTM)
  4672. return;
  4673. event = busy ? L2CAP_EV_LOCAL_BUSY_DETECTED : L2CAP_EV_LOCAL_BUSY_CLEAR;
  4674. l2cap_tx(chan, NULL, NULL, event);
  4675. }
  4676. static int l2cap_rx_queued_iframes(struct l2cap_chan *chan)
  4677. {
  4678. int err = 0;
  4679. /* Pass sequential frames to l2cap_reassemble_sdu()
  4680. * until a gap is encountered.
  4681. */
  4682. BT_DBG("chan %p", chan);
  4683. while (!test_bit(CONN_LOCAL_BUSY, &chan->conn_state)) {
  4684. struct sk_buff *skb;
  4685. BT_DBG("Searching for skb with txseq %d (queue len %d)",
  4686. chan->buffer_seq, skb_queue_len(&chan->srej_q));
  4687. skb = l2cap_ertm_seq_in_queue(&chan->srej_q, chan->buffer_seq);
  4688. if (!skb)
  4689. break;
  4690. skb_unlink(skb, &chan->srej_q);
  4691. chan->buffer_seq = __next_seq(chan, chan->buffer_seq);
  4692. err = l2cap_reassemble_sdu(chan, skb, &bt_cb(skb)->l2cap);
  4693. if (err)
  4694. break;
  4695. }
  4696. if (skb_queue_empty(&chan->srej_q)) {
  4697. chan->rx_state = L2CAP_RX_STATE_RECV;
  4698. l2cap_send_ack(chan);
  4699. }
  4700. return err;
  4701. }
  4702. static void l2cap_handle_srej(struct l2cap_chan *chan,
  4703. struct l2cap_ctrl *control)
  4704. {
  4705. struct sk_buff *skb;
  4706. BT_DBG("chan %p, control %p", chan, control);
  4707. if (control->reqseq == chan->next_tx_seq) {
  4708. BT_DBG("Invalid reqseq %d, disconnecting", control->reqseq);
  4709. l2cap_send_disconn_req(chan, ECONNRESET);
  4710. return;
  4711. }
  4712. skb = l2cap_ertm_seq_in_queue(&chan->tx_q, control->reqseq);
  4713. if (skb == NULL) {
  4714. BT_DBG("Seq %d not available for retransmission",
  4715. control->reqseq);
  4716. return;
  4717. }
  4718. if (chan->max_tx != 0 && bt_cb(skb)->l2cap.retries >= chan->max_tx) {
  4719. BT_DBG("Retry limit exceeded (%d)", chan->max_tx);
  4720. l2cap_send_disconn_req(chan, ECONNRESET);
  4721. return;
  4722. }
  4723. clear_bit(CONN_REMOTE_BUSY, &chan->conn_state);
  4724. if (control->poll) {
  4725. l2cap_pass_to_tx(chan, control);
  4726. set_bit(CONN_SEND_FBIT, &chan->conn_state);
  4727. l2cap_retransmit(chan, control);
  4728. l2cap_ertm_send(chan);
  4729. if (chan->tx_state == L2CAP_TX_STATE_WAIT_F) {
  4730. set_bit(CONN_SREJ_ACT, &chan->conn_state);
  4731. chan->srej_save_reqseq = control->reqseq;
  4732. }
  4733. } else {
  4734. l2cap_pass_to_tx_fbit(chan, control);
  4735. if (control->final) {
  4736. if (chan->srej_save_reqseq != control->reqseq ||
  4737. !test_and_clear_bit(CONN_SREJ_ACT,
  4738. &chan->conn_state))
  4739. l2cap_retransmit(chan, control);
  4740. } else {
  4741. l2cap_retransmit(chan, control);
  4742. if (chan->tx_state == L2CAP_TX_STATE_WAIT_F) {
  4743. set_bit(CONN_SREJ_ACT, &chan->conn_state);
  4744. chan->srej_save_reqseq = control->reqseq;
  4745. }
  4746. }
  4747. }
  4748. }
  4749. static void l2cap_handle_rej(struct l2cap_chan *chan,
  4750. struct l2cap_ctrl *control)
  4751. {
  4752. struct sk_buff *skb;
  4753. BT_DBG("chan %p, control %p", chan, control);
  4754. if (control->reqseq == chan->next_tx_seq) {
  4755. BT_DBG("Invalid reqseq %d, disconnecting", control->reqseq);
  4756. l2cap_send_disconn_req(chan, ECONNRESET);
  4757. return;
  4758. }
  4759. skb = l2cap_ertm_seq_in_queue(&chan->tx_q, control->reqseq);
  4760. if (chan->max_tx && skb &&
  4761. bt_cb(skb)->l2cap.retries >= chan->max_tx) {
  4762. BT_DBG("Retry limit exceeded (%d)", chan->max_tx);
  4763. l2cap_send_disconn_req(chan, ECONNRESET);
  4764. return;
  4765. }
  4766. clear_bit(CONN_REMOTE_BUSY, &chan->conn_state);
  4767. l2cap_pass_to_tx(chan, control);
  4768. if (control->final) {
  4769. if (!test_and_clear_bit(CONN_REJ_ACT, &chan->conn_state))
  4770. l2cap_retransmit_all(chan, control);
  4771. } else {
  4772. l2cap_retransmit_all(chan, control);
  4773. l2cap_ertm_send(chan);
  4774. if (chan->tx_state == L2CAP_TX_STATE_WAIT_F)
  4775. set_bit(CONN_REJ_ACT, &chan->conn_state);
  4776. }
  4777. }
  4778. static u8 l2cap_classify_txseq(struct l2cap_chan *chan, u16 txseq)
  4779. {
  4780. BT_DBG("chan %p, txseq %d", chan, txseq);
  4781. BT_DBG("last_acked_seq %d, expected_tx_seq %d", chan->last_acked_seq,
  4782. chan->expected_tx_seq);
  4783. if (chan->rx_state == L2CAP_RX_STATE_SREJ_SENT) {
  4784. if (__seq_offset(chan, txseq, chan->last_acked_seq) >=
  4785. chan->tx_win) {
  4786. /* See notes below regarding "double poll" and
  4787. * invalid packets.
  4788. */
  4789. if (chan->tx_win <= ((chan->tx_win_max + 1) >> 1)) {
  4790. BT_DBG("Invalid/Ignore - after SREJ");
  4791. return L2CAP_TXSEQ_INVALID_IGNORE;
  4792. } else {
  4793. BT_DBG("Invalid - in window after SREJ sent");
  4794. return L2CAP_TXSEQ_INVALID;
  4795. }
  4796. }
  4797. if (chan->srej_list.head == txseq) {
  4798. BT_DBG("Expected SREJ");
  4799. return L2CAP_TXSEQ_EXPECTED_SREJ;
  4800. }
  4801. if (l2cap_ertm_seq_in_queue(&chan->srej_q, txseq)) {
  4802. BT_DBG("Duplicate SREJ - txseq already stored");
  4803. return L2CAP_TXSEQ_DUPLICATE_SREJ;
  4804. }
  4805. if (l2cap_seq_list_contains(&chan->srej_list, txseq)) {
  4806. BT_DBG("Unexpected SREJ - not requested");
  4807. return L2CAP_TXSEQ_UNEXPECTED_SREJ;
  4808. }
  4809. }
  4810. if (chan->expected_tx_seq == txseq) {
  4811. if (__seq_offset(chan, txseq, chan->last_acked_seq) >=
  4812. chan->tx_win) {
  4813. BT_DBG("Invalid - txseq outside tx window");
  4814. return L2CAP_TXSEQ_INVALID;
  4815. } else {
  4816. BT_DBG("Expected");
  4817. return L2CAP_TXSEQ_EXPECTED;
  4818. }
  4819. }
  4820. if (__seq_offset(chan, txseq, chan->last_acked_seq) <
  4821. __seq_offset(chan, chan->expected_tx_seq, chan->last_acked_seq)) {
  4822. BT_DBG("Duplicate - expected_tx_seq later than txseq");
  4823. return L2CAP_TXSEQ_DUPLICATE;
  4824. }
  4825. if (__seq_offset(chan, txseq, chan->last_acked_seq) >= chan->tx_win) {
  4826. /* A source of invalid packets is a "double poll" condition,
  4827. * where delays cause us to send multiple poll packets. If
  4828. * the remote stack receives and processes both polls,
  4829. * sequence numbers can wrap around in such a way that a
  4830. * resent frame has a sequence number that looks like new data
  4831. * with a sequence gap. This would trigger an erroneous SREJ
  4832. * request.
  4833. *
  4834. * Fortunately, this is impossible with a tx window that's
  4835. * less than half of the maximum sequence number, which allows
  4836. * invalid frames to be safely ignored.
  4837. *
  4838. * With tx window sizes greater than half of the tx window
  4839. * maximum, the frame is invalid and cannot be ignored. This
  4840. * causes a disconnect.
  4841. */
  4842. if (chan->tx_win <= ((chan->tx_win_max + 1) >> 1)) {
  4843. BT_DBG("Invalid/Ignore - txseq outside tx window");
  4844. return L2CAP_TXSEQ_INVALID_IGNORE;
  4845. } else {
  4846. BT_DBG("Invalid - txseq outside tx window");
  4847. return L2CAP_TXSEQ_INVALID;
  4848. }
  4849. } else {
  4850. BT_DBG("Unexpected - txseq indicates missing frames");
  4851. return L2CAP_TXSEQ_UNEXPECTED;
  4852. }
  4853. }
  4854. static int l2cap_rx_state_recv(struct l2cap_chan *chan,
  4855. struct l2cap_ctrl *control,
  4856. struct sk_buff *skb, u8 event)
  4857. {
  4858. int err = 0;
  4859. bool skb_in_use = false;
  4860. BT_DBG("chan %p, control %p, skb %p, event %d", chan, control, skb,
  4861. event);
  4862. switch (event) {
  4863. case L2CAP_EV_RECV_IFRAME:
  4864. switch (l2cap_classify_txseq(chan, control->txseq)) {
  4865. case L2CAP_TXSEQ_EXPECTED:
  4866. l2cap_pass_to_tx(chan, control);
  4867. if (test_bit(CONN_LOCAL_BUSY, &chan->conn_state)) {
  4868. BT_DBG("Busy, discarding expected seq %d",
  4869. control->txseq);
  4870. break;
  4871. }
  4872. chan->expected_tx_seq = __next_seq(chan,
  4873. control->txseq);
  4874. chan->buffer_seq = chan->expected_tx_seq;
  4875. skb_in_use = true;
  4876. err = l2cap_reassemble_sdu(chan, skb, control);
  4877. if (err)
  4878. break;
  4879. if (control->final) {
  4880. if (!test_and_clear_bit(CONN_REJ_ACT,
  4881. &chan->conn_state)) {
  4882. control->final = 0;
  4883. l2cap_retransmit_all(chan, control);
  4884. l2cap_ertm_send(chan);
  4885. }
  4886. }
  4887. if (!test_bit(CONN_LOCAL_BUSY, &chan->conn_state))
  4888. l2cap_send_ack(chan);
  4889. break;
  4890. case L2CAP_TXSEQ_UNEXPECTED:
  4891. l2cap_pass_to_tx(chan, control);
  4892. /* Can't issue SREJ frames in the local busy state.
  4893. * Drop this frame, it will be seen as missing
  4894. * when local busy is exited.
  4895. */
  4896. if (test_bit(CONN_LOCAL_BUSY, &chan->conn_state)) {
  4897. BT_DBG("Busy, discarding unexpected seq %d",
  4898. control->txseq);
  4899. break;
  4900. }
  4901. /* There was a gap in the sequence, so an SREJ
  4902. * must be sent for each missing frame. The
  4903. * current frame is stored for later use.
  4904. */
  4905. skb_queue_tail(&chan->srej_q, skb);
  4906. skb_in_use = true;
  4907. BT_DBG("Queued %p (queue len %d)", skb,
  4908. skb_queue_len(&chan->srej_q));
  4909. clear_bit(CONN_SREJ_ACT, &chan->conn_state);
  4910. l2cap_seq_list_clear(&chan->srej_list);
  4911. l2cap_send_srej(chan, control->txseq);
  4912. chan->rx_state = L2CAP_RX_STATE_SREJ_SENT;
  4913. break;
  4914. case L2CAP_TXSEQ_DUPLICATE:
  4915. l2cap_pass_to_tx(chan, control);
  4916. break;
  4917. case L2CAP_TXSEQ_INVALID_IGNORE:
  4918. break;
  4919. case L2CAP_TXSEQ_INVALID:
  4920. default:
  4921. l2cap_send_disconn_req(chan, ECONNRESET);
  4922. break;
  4923. }
  4924. break;
  4925. case L2CAP_EV_RECV_RR:
  4926. l2cap_pass_to_tx(chan, control);
  4927. if (control->final) {
  4928. clear_bit(CONN_REMOTE_BUSY, &chan->conn_state);
  4929. if (!test_and_clear_bit(CONN_REJ_ACT, &chan->conn_state) &&
  4930. !__chan_is_moving(chan)) {
  4931. control->final = 0;
  4932. l2cap_retransmit_all(chan, control);
  4933. }
  4934. l2cap_ertm_send(chan);
  4935. } else if (control->poll) {
  4936. l2cap_send_i_or_rr_or_rnr(chan);
  4937. } else {
  4938. if (test_and_clear_bit(CONN_REMOTE_BUSY,
  4939. &chan->conn_state) &&
  4940. chan->unacked_frames)
  4941. __set_retrans_timer(chan);
  4942. l2cap_ertm_send(chan);
  4943. }
  4944. break;
  4945. case L2CAP_EV_RECV_RNR:
  4946. set_bit(CONN_REMOTE_BUSY, &chan->conn_state);
  4947. l2cap_pass_to_tx(chan, control);
  4948. if (control && control->poll) {
  4949. set_bit(CONN_SEND_FBIT, &chan->conn_state);
  4950. l2cap_send_rr_or_rnr(chan, 0);
  4951. }
  4952. __clear_retrans_timer(chan);
  4953. l2cap_seq_list_clear(&chan->retrans_list);
  4954. break;
  4955. case L2CAP_EV_RECV_REJ:
  4956. l2cap_handle_rej(chan, control);
  4957. break;
  4958. case L2CAP_EV_RECV_SREJ:
  4959. l2cap_handle_srej(chan, control);
  4960. break;
  4961. default:
  4962. break;
  4963. }
  4964. if (skb && !skb_in_use) {
  4965. BT_DBG("Freeing %p", skb);
  4966. kfree_skb(skb);
  4967. }
  4968. return err;
  4969. }
  4970. static int l2cap_rx_state_srej_sent(struct l2cap_chan *chan,
  4971. struct l2cap_ctrl *control,
  4972. struct sk_buff *skb, u8 event)
  4973. {
  4974. int err = 0;
  4975. u16 txseq = control->txseq;
  4976. bool skb_in_use = false;
  4977. BT_DBG("chan %p, control %p, skb %p, event %d", chan, control, skb,
  4978. event);
  4979. switch (event) {
  4980. case L2CAP_EV_RECV_IFRAME:
  4981. switch (l2cap_classify_txseq(chan, txseq)) {
  4982. case L2CAP_TXSEQ_EXPECTED:
  4983. /* Keep frame for reassembly later */
  4984. l2cap_pass_to_tx(chan, control);
  4985. skb_queue_tail(&chan->srej_q, skb);
  4986. skb_in_use = true;
  4987. BT_DBG("Queued %p (queue len %d)", skb,
  4988. skb_queue_len(&chan->srej_q));
  4989. chan->expected_tx_seq = __next_seq(chan, txseq);
  4990. break;
  4991. case L2CAP_TXSEQ_EXPECTED_SREJ:
  4992. l2cap_seq_list_pop(&chan->srej_list);
  4993. l2cap_pass_to_tx(chan, control);
  4994. skb_queue_tail(&chan->srej_q, skb);
  4995. skb_in_use = true;
  4996. BT_DBG("Queued %p (queue len %d)", skb,
  4997. skb_queue_len(&chan->srej_q));
  4998. err = l2cap_rx_queued_iframes(chan);
  4999. if (err)
  5000. break;
  5001. break;
  5002. case L2CAP_TXSEQ_UNEXPECTED:
  5003. /* Got a frame that can't be reassembled yet.
  5004. * Save it for later, and send SREJs to cover
  5005. * the missing frames.
  5006. */
  5007. skb_queue_tail(&chan->srej_q, skb);
  5008. skb_in_use = true;
  5009. BT_DBG("Queued %p (queue len %d)", skb,
  5010. skb_queue_len(&chan->srej_q));
  5011. l2cap_pass_to_tx(chan, control);
  5012. l2cap_send_srej(chan, control->txseq);
  5013. break;
  5014. case L2CAP_TXSEQ_UNEXPECTED_SREJ:
  5015. /* This frame was requested with an SREJ, but
  5016. * some expected retransmitted frames are
  5017. * missing. Request retransmission of missing
  5018. * SREJ'd frames.
  5019. */
  5020. skb_queue_tail(&chan->srej_q, skb);
  5021. skb_in_use = true;
  5022. BT_DBG("Queued %p (queue len %d)", skb,
  5023. skb_queue_len(&chan->srej_q));
  5024. l2cap_pass_to_tx(chan, control);
  5025. l2cap_send_srej_list(chan, control->txseq);
  5026. break;
  5027. case L2CAP_TXSEQ_DUPLICATE_SREJ:
  5028. /* We've already queued this frame. Drop this copy. */
  5029. l2cap_pass_to_tx(chan, control);
  5030. break;
  5031. case L2CAP_TXSEQ_DUPLICATE:
  5032. /* Expecting a later sequence number, so this frame
  5033. * was already received. Ignore it completely.
  5034. */
  5035. break;
  5036. case L2CAP_TXSEQ_INVALID_IGNORE:
  5037. break;
  5038. case L2CAP_TXSEQ_INVALID:
  5039. default:
  5040. l2cap_send_disconn_req(chan, ECONNRESET);
  5041. break;
  5042. }
  5043. break;
  5044. case L2CAP_EV_RECV_RR:
  5045. l2cap_pass_to_tx(chan, control);
  5046. if (control->final) {
  5047. clear_bit(CONN_REMOTE_BUSY, &chan->conn_state);
  5048. if (!test_and_clear_bit(CONN_REJ_ACT,
  5049. &chan->conn_state)) {
  5050. control->final = 0;
  5051. l2cap_retransmit_all(chan, control);
  5052. }
  5053. l2cap_ertm_send(chan);
  5054. } else if (control->poll) {
  5055. if (test_and_clear_bit(CONN_REMOTE_BUSY,
  5056. &chan->conn_state) &&
  5057. chan->unacked_frames) {
  5058. __set_retrans_timer(chan);
  5059. }
  5060. set_bit(CONN_SEND_FBIT, &chan->conn_state);
  5061. l2cap_send_srej_tail(chan);
  5062. } else {
  5063. if (test_and_clear_bit(CONN_REMOTE_BUSY,
  5064. &chan->conn_state) &&
  5065. chan->unacked_frames)
  5066. __set_retrans_timer(chan);
  5067. l2cap_send_ack(chan);
  5068. }
  5069. break;
  5070. case L2CAP_EV_RECV_RNR:
  5071. set_bit(CONN_REMOTE_BUSY, &chan->conn_state);
  5072. l2cap_pass_to_tx(chan, control);
  5073. if (control->poll) {
  5074. l2cap_send_srej_tail(chan);
  5075. } else {
  5076. struct l2cap_ctrl rr_control;
  5077. memset(&rr_control, 0, sizeof(rr_control));
  5078. rr_control.sframe = 1;
  5079. rr_control.super = L2CAP_SUPER_RR;
  5080. rr_control.reqseq = chan->buffer_seq;
  5081. l2cap_send_sframe(chan, &rr_control);
  5082. }
  5083. break;
  5084. case L2CAP_EV_RECV_REJ:
  5085. l2cap_handle_rej(chan, control);
  5086. break;
  5087. case L2CAP_EV_RECV_SREJ:
  5088. l2cap_handle_srej(chan, control);
  5089. break;
  5090. }
  5091. if (skb && !skb_in_use) {
  5092. BT_DBG("Freeing %p", skb);
  5093. kfree_skb(skb);
  5094. }
  5095. return err;
  5096. }
  5097. static int l2cap_finish_move(struct l2cap_chan *chan)
  5098. {
  5099. BT_DBG("chan %p", chan);
  5100. chan->rx_state = L2CAP_RX_STATE_RECV;
  5101. if (chan->hs_hcon)
  5102. chan->conn->mtu = chan->hs_hcon->hdev->block_mtu;
  5103. else
  5104. chan->conn->mtu = chan->conn->hcon->hdev->acl_mtu;
  5105. return l2cap_resegment(chan);
  5106. }
  5107. static int l2cap_rx_state_wait_p(struct l2cap_chan *chan,
  5108. struct l2cap_ctrl *control,
  5109. struct sk_buff *skb, u8 event)
  5110. {
  5111. int err;
  5112. BT_DBG("chan %p, control %p, skb %p, event %d", chan, control, skb,
  5113. event);
  5114. if (!control->poll)
  5115. return -EPROTO;
  5116. l2cap_process_reqseq(chan, control->reqseq);
  5117. if (!skb_queue_empty(&chan->tx_q))
  5118. chan->tx_send_head = skb_peek(&chan->tx_q);
  5119. else
  5120. chan->tx_send_head = NULL;
  5121. /* Rewind next_tx_seq to the point expected
  5122. * by the receiver.
  5123. */
  5124. chan->next_tx_seq = control->reqseq;
  5125. chan->unacked_frames = 0;
  5126. err = l2cap_finish_move(chan);
  5127. if (err)
  5128. return err;
  5129. set_bit(CONN_SEND_FBIT, &chan->conn_state);
  5130. l2cap_send_i_or_rr_or_rnr(chan);
  5131. if (event == L2CAP_EV_RECV_IFRAME)
  5132. return -EPROTO;
  5133. return l2cap_rx_state_recv(chan, control, NULL, event);
  5134. }
  5135. static int l2cap_rx_state_wait_f(struct l2cap_chan *chan,
  5136. struct l2cap_ctrl *control,
  5137. struct sk_buff *skb, u8 event)
  5138. {
  5139. int err;
  5140. if (!control->final)
  5141. return -EPROTO;
  5142. clear_bit(CONN_REMOTE_BUSY, &chan->conn_state);
  5143. chan->rx_state = L2CAP_RX_STATE_RECV;
  5144. l2cap_process_reqseq(chan, control->reqseq);
  5145. if (!skb_queue_empty(&chan->tx_q))
  5146. chan->tx_send_head = skb_peek(&chan->tx_q);
  5147. else
  5148. chan->tx_send_head = NULL;
  5149. /* Rewind next_tx_seq to the point expected
  5150. * by the receiver.
  5151. */
  5152. chan->next_tx_seq = control->reqseq;
  5153. chan->unacked_frames = 0;
  5154. if (chan->hs_hcon)
  5155. chan->conn->mtu = chan->hs_hcon->hdev->block_mtu;
  5156. else
  5157. chan->conn->mtu = chan->conn->hcon->hdev->acl_mtu;
  5158. err = l2cap_resegment(chan);
  5159. if (!err)
  5160. err = l2cap_rx_state_recv(chan, control, skb, event);
  5161. return err;
  5162. }
  5163. static bool __valid_reqseq(struct l2cap_chan *chan, u16 reqseq)
  5164. {
  5165. /* Make sure reqseq is for a packet that has been sent but not acked */
  5166. u16 unacked;
  5167. unacked = __seq_offset(chan, chan->next_tx_seq, chan->expected_ack_seq);
  5168. return __seq_offset(chan, chan->next_tx_seq, reqseq) <= unacked;
  5169. }
  5170. static int l2cap_rx(struct l2cap_chan *chan, struct l2cap_ctrl *control,
  5171. struct sk_buff *skb, u8 event)
  5172. {
  5173. int err = 0;
  5174. BT_DBG("chan %p, control %p, skb %p, event %d, state %d", chan,
  5175. control, skb, event, chan->rx_state);
  5176. if (__valid_reqseq(chan, control->reqseq)) {
  5177. switch (chan->rx_state) {
  5178. case L2CAP_RX_STATE_RECV:
  5179. err = l2cap_rx_state_recv(chan, control, skb, event);
  5180. break;
  5181. case L2CAP_RX_STATE_SREJ_SENT:
  5182. err = l2cap_rx_state_srej_sent(chan, control, skb,
  5183. event);
  5184. break;
  5185. case L2CAP_RX_STATE_WAIT_P:
  5186. err = l2cap_rx_state_wait_p(chan, control, skb, event);
  5187. break;
  5188. case L2CAP_RX_STATE_WAIT_F:
  5189. err = l2cap_rx_state_wait_f(chan, control, skb, event);
  5190. break;
  5191. default:
  5192. /* shut it down */
  5193. break;
  5194. }
  5195. } else {
  5196. BT_DBG("Invalid reqseq %d (next_tx_seq %d, expected_ack_seq %d",
  5197. control->reqseq, chan->next_tx_seq,
  5198. chan->expected_ack_seq);
  5199. l2cap_send_disconn_req(chan, ECONNRESET);
  5200. }
  5201. return err;
  5202. }
  5203. static int l2cap_stream_rx(struct l2cap_chan *chan, struct l2cap_ctrl *control,
  5204. struct sk_buff *skb)
  5205. {
  5206. int err = 0;
  5207. BT_DBG("chan %p, control %p, skb %p, state %d", chan, control, skb,
  5208. chan->rx_state);
  5209. if (l2cap_classify_txseq(chan, control->txseq) ==
  5210. L2CAP_TXSEQ_EXPECTED) {
  5211. l2cap_pass_to_tx(chan, control);
  5212. BT_DBG("buffer_seq %d->%d", chan->buffer_seq,
  5213. __next_seq(chan, chan->buffer_seq));
  5214. chan->buffer_seq = __next_seq(chan, chan->buffer_seq);
  5215. l2cap_reassemble_sdu(chan, skb, control);
  5216. } else {
  5217. if (chan->sdu) {
  5218. kfree_skb(chan->sdu);
  5219. chan->sdu = NULL;
  5220. }
  5221. chan->sdu_last_frag = NULL;
  5222. chan->sdu_len = 0;
  5223. if (skb) {
  5224. BT_DBG("Freeing %p", skb);
  5225. kfree_skb(skb);
  5226. }
  5227. }
  5228. chan->last_acked_seq = control->txseq;
  5229. chan->expected_tx_seq = __next_seq(chan, control->txseq);
  5230. return err;
  5231. }
  5232. static int l2cap_data_rcv(struct l2cap_chan *chan, struct sk_buff *skb)
  5233. {
  5234. struct l2cap_ctrl *control = &bt_cb(skb)->l2cap;
  5235. u16 len;
  5236. u8 event;
  5237. __unpack_control(chan, skb);
  5238. len = skb->len;
  5239. /*
  5240. * We can just drop the corrupted I-frame here.
  5241. * Receiver will miss it and start proper recovery
  5242. * procedures and ask for retransmission.
  5243. */
  5244. if (l2cap_check_fcs(chan, skb))
  5245. goto drop;
  5246. if (!control->sframe && control->sar == L2CAP_SAR_START)
  5247. len -= L2CAP_SDULEN_SIZE;
  5248. if (chan->fcs == L2CAP_FCS_CRC16)
  5249. len -= L2CAP_FCS_SIZE;
  5250. if (len > chan->mps) {
  5251. l2cap_send_disconn_req(chan, ECONNRESET);
  5252. goto drop;
  5253. }
  5254. if (!control->sframe) {
  5255. int err;
  5256. BT_DBG("iframe sar %d, reqseq %d, final %d, txseq %d",
  5257. control->sar, control->reqseq, control->final,
  5258. control->txseq);
  5259. /* Validate F-bit - F=0 always valid, F=1 only
  5260. * valid in TX WAIT_F
  5261. */
  5262. if (control->final && chan->tx_state != L2CAP_TX_STATE_WAIT_F)
  5263. goto drop;
  5264. if (chan->mode != L2CAP_MODE_STREAMING) {
  5265. event = L2CAP_EV_RECV_IFRAME;
  5266. err = l2cap_rx(chan, control, skb, event);
  5267. } else {
  5268. err = l2cap_stream_rx(chan, control, skb);
  5269. }
  5270. if (err)
  5271. l2cap_send_disconn_req(chan, ECONNRESET);
  5272. } else {
  5273. const u8 rx_func_to_event[4] = {
  5274. L2CAP_EV_RECV_RR, L2CAP_EV_RECV_REJ,
  5275. L2CAP_EV_RECV_RNR, L2CAP_EV_RECV_SREJ
  5276. };
  5277. /* Only I-frames are expected in streaming mode */
  5278. if (chan->mode == L2CAP_MODE_STREAMING)
  5279. goto drop;
  5280. BT_DBG("sframe reqseq %d, final %d, poll %d, super %d",
  5281. control->reqseq, control->final, control->poll,
  5282. control->super);
  5283. if (len != 0) {
  5284. BT_ERR("Trailing bytes: %d in sframe", len);
  5285. l2cap_send_disconn_req(chan, ECONNRESET);
  5286. goto drop;
  5287. }
  5288. /* Validate F and P bits */
  5289. if (control->final && (control->poll ||
  5290. chan->tx_state != L2CAP_TX_STATE_WAIT_F))
  5291. goto drop;
  5292. event = rx_func_to_event[control->super];
  5293. if (l2cap_rx(chan, control, skb, event))
  5294. l2cap_send_disconn_req(chan, ECONNRESET);
  5295. }
  5296. return 0;
  5297. drop:
  5298. kfree_skb(skb);
  5299. return 0;
  5300. }
  5301. static void l2cap_chan_le_send_credits(struct l2cap_chan *chan)
  5302. {
  5303. struct l2cap_conn *conn = chan->conn;
  5304. struct l2cap_le_credits pkt;
  5305. u16 return_credits;
  5306. /* We return more credits to the sender only after the amount of
  5307. * credits falls below half of the initial amount.
  5308. */
  5309. if (chan->rx_credits >= (le_max_credits + 1) / 2)
  5310. return;
  5311. return_credits = le_max_credits - chan->rx_credits;
  5312. BT_DBG("chan %p returning %u credits to sender", chan, return_credits);
  5313. chan->rx_credits += return_credits;
  5314. pkt.cid = cpu_to_le16(chan->scid);
  5315. pkt.credits = cpu_to_le16(return_credits);
  5316. chan->ident = l2cap_get_ident(conn);
  5317. l2cap_send_cmd(conn, chan->ident, L2CAP_LE_CREDITS, sizeof(pkt), &pkt);
  5318. }
  5319. static int l2cap_le_data_rcv(struct l2cap_chan *chan, struct sk_buff *skb)
  5320. {
  5321. int err;
  5322. if (!chan->rx_credits) {
  5323. BT_ERR("No credits to receive LE L2CAP data");
  5324. l2cap_send_disconn_req(chan, ECONNRESET);
  5325. return -ENOBUFS;
  5326. }
  5327. if (chan->imtu < skb->len) {
  5328. BT_ERR("Too big LE L2CAP PDU");
  5329. return -ENOBUFS;
  5330. }
  5331. chan->rx_credits--;
  5332. BT_DBG("rx_credits %u -> %u", chan->rx_credits + 1, chan->rx_credits);
  5333. l2cap_chan_le_send_credits(chan);
  5334. err = 0;
  5335. if (!chan->sdu) {
  5336. u16 sdu_len;
  5337. sdu_len = get_unaligned_le16(skb->data);
  5338. skb_pull(skb, L2CAP_SDULEN_SIZE);
  5339. BT_DBG("Start of new SDU. sdu_len %u skb->len %u imtu %u",
  5340. sdu_len, skb->len, chan->imtu);
  5341. if (sdu_len > chan->imtu) {
  5342. BT_ERR("Too big LE L2CAP SDU length received");
  5343. err = -EMSGSIZE;
  5344. goto failed;
  5345. }
  5346. if (skb->len > sdu_len) {
  5347. BT_ERR("Too much LE L2CAP data received");
  5348. err = -EINVAL;
  5349. goto failed;
  5350. }
  5351. if (skb->len == sdu_len)
  5352. return chan->ops->recv(chan, skb);
  5353. chan->sdu = skb;
  5354. chan->sdu_len = sdu_len;
  5355. chan->sdu_last_frag = skb;
  5356. return 0;
  5357. }
  5358. BT_DBG("SDU fragment. chan->sdu->len %u skb->len %u chan->sdu_len %u",
  5359. chan->sdu->len, skb->len, chan->sdu_len);
  5360. if (chan->sdu->len + skb->len > chan->sdu_len) {
  5361. BT_ERR("Too much LE L2CAP data received");
  5362. err = -EINVAL;
  5363. goto failed;
  5364. }
  5365. append_skb_frag(chan->sdu, skb, &chan->sdu_last_frag);
  5366. skb = NULL;
  5367. if (chan->sdu->len == chan->sdu_len) {
  5368. err = chan->ops->recv(chan, chan->sdu);
  5369. if (!err) {
  5370. chan->sdu = NULL;
  5371. chan->sdu_last_frag = NULL;
  5372. chan->sdu_len = 0;
  5373. }
  5374. }
  5375. failed:
  5376. if (err) {
  5377. kfree_skb(skb);
  5378. kfree_skb(chan->sdu);
  5379. chan->sdu = NULL;
  5380. chan->sdu_last_frag = NULL;
  5381. chan->sdu_len = 0;
  5382. }
  5383. /* We can't return an error here since we took care of the skb
  5384. * freeing internally. An error return would cause the caller to
  5385. * do a double-free of the skb.
  5386. */
  5387. return 0;
  5388. }
  5389. static void l2cap_data_channel(struct l2cap_conn *conn, u16 cid,
  5390. struct sk_buff *skb)
  5391. {
  5392. struct l2cap_chan *chan;
  5393. chan = l2cap_get_chan_by_scid(conn, cid);
  5394. if (!chan) {
  5395. if (cid == L2CAP_CID_A2MP) {
  5396. chan = a2mp_channel_create(conn, skb);
  5397. if (!chan) {
  5398. kfree_skb(skb);
  5399. return;
  5400. }
  5401. l2cap_chan_lock(chan);
  5402. } else {
  5403. BT_DBG("unknown cid 0x%4.4x", cid);
  5404. /* Drop packet and return */
  5405. kfree_skb(skb);
  5406. return;
  5407. }
  5408. }
  5409. BT_DBG("chan %p, len %d", chan, skb->len);
  5410. /* If we receive data on a fixed channel before the info req/rsp
  5411. * procdure is done simply assume that the channel is supported
  5412. * and mark it as ready.
  5413. */
  5414. if (chan->chan_type == L2CAP_CHAN_FIXED)
  5415. l2cap_chan_ready(chan);
  5416. if (chan->state != BT_CONNECTED)
  5417. goto drop;
  5418. switch (chan->mode) {
  5419. case L2CAP_MODE_LE_FLOWCTL:
  5420. if (l2cap_le_data_rcv(chan, skb) < 0)
  5421. goto drop;
  5422. goto done;
  5423. case L2CAP_MODE_BASIC:
  5424. /* If socket recv buffers overflows we drop data here
  5425. * which is *bad* because L2CAP has to be reliable.
  5426. * But we don't have any other choice. L2CAP doesn't
  5427. * provide flow control mechanism. */
  5428. if (chan->imtu < skb->len) {
  5429. BT_ERR("Dropping L2CAP data: receive buffer overflow");
  5430. goto drop;
  5431. }
  5432. if (!chan->ops->recv(chan, skb))
  5433. goto done;
  5434. break;
  5435. case L2CAP_MODE_ERTM:
  5436. case L2CAP_MODE_STREAMING:
  5437. l2cap_data_rcv(chan, skb);
  5438. goto done;
  5439. default:
  5440. BT_DBG("chan %p: bad mode 0x%2.2x", chan, chan->mode);
  5441. break;
  5442. }
  5443. drop:
  5444. kfree_skb(skb);
  5445. done:
  5446. l2cap_chan_unlock(chan);
  5447. }
  5448. static void l2cap_conless_channel(struct l2cap_conn *conn, __le16 psm,
  5449. struct sk_buff *skb)
  5450. {
  5451. struct hci_conn *hcon = conn->hcon;
  5452. struct l2cap_chan *chan;
  5453. if (hcon->type != ACL_LINK)
  5454. goto free_skb;
  5455. chan = l2cap_global_chan_by_psm(0, psm, &hcon->src, &hcon->dst,
  5456. ACL_LINK);
  5457. if (!chan)
  5458. goto free_skb;
  5459. BT_DBG("chan %p, len %d", chan, skb->len);
  5460. if (chan->state != BT_BOUND && chan->state != BT_CONNECTED)
  5461. goto drop;
  5462. if (chan->imtu < skb->len)
  5463. goto drop;
  5464. /* Store remote BD_ADDR and PSM for msg_name */
  5465. bacpy(&bt_cb(skb)->l2cap.bdaddr, &hcon->dst);
  5466. bt_cb(skb)->l2cap.psm = psm;
  5467. if (!chan->ops->recv(chan, skb)) {
  5468. l2cap_chan_put(chan);
  5469. return;
  5470. }
  5471. drop:
  5472. l2cap_chan_put(chan);
  5473. free_skb:
  5474. kfree_skb(skb);
  5475. }
  5476. static void l2cap_recv_frame(struct l2cap_conn *conn, struct sk_buff *skb)
  5477. {
  5478. struct l2cap_hdr *lh = (void *) skb->data;
  5479. struct hci_conn *hcon = conn->hcon;
  5480. u16 cid, len;
  5481. __le16 psm;
  5482. if (hcon->state != BT_CONNECTED) {
  5483. BT_DBG("queueing pending rx skb");
  5484. skb_queue_tail(&conn->pending_rx, skb);
  5485. return;
  5486. }
  5487. skb_pull(skb, L2CAP_HDR_SIZE);
  5488. cid = __le16_to_cpu(lh->cid);
  5489. len = __le16_to_cpu(lh->len);
  5490. if (len != skb->len) {
  5491. kfree_skb(skb);
  5492. return;
  5493. }
  5494. /* Since we can't actively block incoming LE connections we must
  5495. * at least ensure that we ignore incoming data from them.
  5496. */
  5497. if (hcon->type == LE_LINK &&
  5498. hci_bdaddr_list_lookup(&hcon->hdev->blacklist, &hcon->dst,
  5499. bdaddr_dst_type(hcon))) {
  5500. kfree_skb(skb);
  5501. return;
  5502. }
  5503. BT_DBG("len %d, cid 0x%4.4x", len, cid);
  5504. switch (cid) {
  5505. case L2CAP_CID_SIGNALING:
  5506. l2cap_sig_channel(conn, skb);
  5507. break;
  5508. case L2CAP_CID_CONN_LESS:
  5509. psm = get_unaligned((__le16 *) skb->data);
  5510. skb_pull(skb, L2CAP_PSMLEN_SIZE);
  5511. l2cap_conless_channel(conn, psm, skb);
  5512. break;
  5513. case L2CAP_CID_LE_SIGNALING:
  5514. l2cap_le_sig_channel(conn, skb);
  5515. break;
  5516. default:
  5517. l2cap_data_channel(conn, cid, skb);
  5518. break;
  5519. }
  5520. }
  5521. static void process_pending_rx(struct work_struct *work)
  5522. {
  5523. struct l2cap_conn *conn = container_of(work, struct l2cap_conn,
  5524. pending_rx_work);
  5525. struct sk_buff *skb;
  5526. BT_DBG("");
  5527. while ((skb = skb_dequeue(&conn->pending_rx)))
  5528. l2cap_recv_frame(conn, skb);
  5529. }
  5530. static struct l2cap_conn *l2cap_conn_add(struct hci_conn *hcon)
  5531. {
  5532. struct l2cap_conn *conn = hcon->l2cap_data;
  5533. struct hci_chan *hchan;
  5534. if (conn)
  5535. return conn;
  5536. hchan = hci_chan_create(hcon);
  5537. if (!hchan)
  5538. return NULL;
  5539. conn = kzalloc(sizeof(*conn), GFP_KERNEL);
  5540. if (!conn) {
  5541. hci_chan_del(hchan);
  5542. return NULL;
  5543. }
  5544. kref_init(&conn->ref);
  5545. hcon->l2cap_data = conn;
  5546. conn->hcon = hci_conn_get(hcon);
  5547. conn->hchan = hchan;
  5548. BT_DBG("hcon %p conn %p hchan %p", hcon, conn, hchan);
  5549. switch (hcon->type) {
  5550. case LE_LINK:
  5551. if (hcon->hdev->le_mtu) {
  5552. conn->mtu = hcon->hdev->le_mtu;
  5553. break;
  5554. }
  5555. /* fall through */
  5556. default:
  5557. conn->mtu = hcon->hdev->acl_mtu;
  5558. break;
  5559. }
  5560. conn->feat_mask = 0;
  5561. conn->local_fixed_chan = L2CAP_FC_SIG_BREDR | L2CAP_FC_CONNLESS;
  5562. if (hcon->type == ACL_LINK &&
  5563. hci_dev_test_flag(hcon->hdev, HCI_HS_ENABLED))
  5564. conn->local_fixed_chan |= L2CAP_FC_A2MP;
  5565. if (hci_dev_test_flag(hcon->hdev, HCI_LE_ENABLED) &&
  5566. (bredr_sc_enabled(hcon->hdev) ||
  5567. hci_dev_test_flag(hcon->hdev, HCI_FORCE_BREDR_SMP)))
  5568. conn->local_fixed_chan |= L2CAP_FC_SMP_BREDR;
  5569. mutex_init(&conn->ident_lock);
  5570. mutex_init(&conn->chan_lock);
  5571. INIT_LIST_HEAD(&conn->chan_l);
  5572. INIT_LIST_HEAD(&conn->users);
  5573. INIT_DELAYED_WORK(&conn->info_timer, l2cap_info_timeout);
  5574. skb_queue_head_init(&conn->pending_rx);
  5575. INIT_WORK(&conn->pending_rx_work, process_pending_rx);
  5576. INIT_WORK(&conn->id_addr_update_work, l2cap_conn_update_id_addr);
  5577. conn->disc_reason = HCI_ERROR_REMOTE_USER_TERM;
  5578. return conn;
  5579. }
  5580. static bool is_valid_psm(u16 psm, u8 dst_type) {
  5581. if (!psm)
  5582. return false;
  5583. if (bdaddr_type_is_le(dst_type))
  5584. return (psm <= 0x00ff);
  5585. /* PSM must be odd and lsb of upper byte must be 0 */
  5586. return ((psm & 0x0101) == 0x0001);
  5587. }
  5588. int l2cap_chan_connect(struct l2cap_chan *chan, __le16 psm, u16 cid,
  5589. bdaddr_t *dst, u8 dst_type)
  5590. {
  5591. struct l2cap_conn *conn;
  5592. struct hci_conn *hcon;
  5593. struct hci_dev *hdev;
  5594. int err;
  5595. BT_DBG("%pMR -> %pMR (type %u) psm 0x%2.2x", &chan->src, dst,
  5596. dst_type, __le16_to_cpu(psm));
  5597. hdev = hci_get_route(dst, &chan->src);
  5598. if (!hdev)
  5599. return -EHOSTUNREACH;
  5600. hci_dev_lock(hdev);
  5601. if (!is_valid_psm(__le16_to_cpu(psm), dst_type) && !cid &&
  5602. chan->chan_type != L2CAP_CHAN_RAW) {
  5603. err = -EINVAL;
  5604. goto done;
  5605. }
  5606. if (chan->chan_type == L2CAP_CHAN_CONN_ORIENTED && !psm) {
  5607. err = -EINVAL;
  5608. goto done;
  5609. }
  5610. if (chan->chan_type == L2CAP_CHAN_FIXED && !cid) {
  5611. err = -EINVAL;
  5612. goto done;
  5613. }
  5614. switch (chan->mode) {
  5615. case L2CAP_MODE_BASIC:
  5616. break;
  5617. case L2CAP_MODE_LE_FLOWCTL:
  5618. l2cap_le_flowctl_init(chan);
  5619. break;
  5620. case L2CAP_MODE_ERTM:
  5621. case L2CAP_MODE_STREAMING:
  5622. if (!disable_ertm)
  5623. break;
  5624. /* fall through */
  5625. default:
  5626. err = -EOPNOTSUPP;
  5627. goto done;
  5628. }
  5629. switch (chan->state) {
  5630. case BT_CONNECT:
  5631. case BT_CONNECT2:
  5632. case BT_CONFIG:
  5633. /* Already connecting */
  5634. err = 0;
  5635. goto done;
  5636. case BT_CONNECTED:
  5637. /* Already connected */
  5638. err = -EISCONN;
  5639. goto done;
  5640. case BT_OPEN:
  5641. case BT_BOUND:
  5642. /* Can connect */
  5643. break;
  5644. default:
  5645. err = -EBADFD;
  5646. goto done;
  5647. }
  5648. /* Set destination address and psm */
  5649. bacpy(&chan->dst, dst);
  5650. chan->dst_type = dst_type;
  5651. chan->psm = psm;
  5652. chan->dcid = cid;
  5653. if (bdaddr_type_is_le(dst_type)) {
  5654. u8 role;
  5655. /* Convert from L2CAP channel address type to HCI address type
  5656. */
  5657. if (dst_type == BDADDR_LE_PUBLIC)
  5658. dst_type = ADDR_LE_DEV_PUBLIC;
  5659. else
  5660. dst_type = ADDR_LE_DEV_RANDOM;
  5661. if (hci_dev_test_flag(hdev, HCI_ADVERTISING))
  5662. role = HCI_ROLE_SLAVE;
  5663. else
  5664. role = HCI_ROLE_MASTER;
  5665. hcon = hci_connect_le_scan(hdev, dst, dst_type,
  5666. chan->sec_level,
  5667. HCI_LE_CONN_TIMEOUT,
  5668. role);
  5669. } else {
  5670. u8 auth_type = l2cap_get_auth_type(chan);
  5671. hcon = hci_connect_acl(hdev, dst, chan->sec_level, auth_type);
  5672. }
  5673. if (IS_ERR(hcon)) {
  5674. err = PTR_ERR(hcon);
  5675. goto done;
  5676. }
  5677. conn = l2cap_conn_add(hcon);
  5678. if (!conn) {
  5679. hci_conn_drop(hcon);
  5680. err = -ENOMEM;
  5681. goto done;
  5682. }
  5683. mutex_lock(&conn->chan_lock);
  5684. l2cap_chan_lock(chan);
  5685. if (cid && __l2cap_get_chan_by_dcid(conn, cid)) {
  5686. hci_conn_drop(hcon);
  5687. err = -EBUSY;
  5688. goto chan_unlock;
  5689. }
  5690. /* Update source addr of the socket */
  5691. bacpy(&chan->src, &hcon->src);
  5692. chan->src_type = bdaddr_src_type(hcon);
  5693. __l2cap_chan_add(conn, chan);
  5694. /* l2cap_chan_add takes its own ref so we can drop this one */
  5695. hci_conn_drop(hcon);
  5696. l2cap_state_change(chan, BT_CONNECT);
  5697. __set_chan_timer(chan, chan->ops->get_sndtimeo(chan));
  5698. /* Release chan->sport so that it can be reused by other
  5699. * sockets (as it's only used for listening sockets).
  5700. */
  5701. write_lock(&chan_list_lock);
  5702. chan->sport = 0;
  5703. write_unlock(&chan_list_lock);
  5704. if (hcon->state == BT_CONNECTED) {
  5705. if (chan->chan_type != L2CAP_CHAN_CONN_ORIENTED) {
  5706. __clear_chan_timer(chan);
  5707. if (l2cap_chan_check_security(chan, true))
  5708. l2cap_state_change(chan, BT_CONNECTED);
  5709. } else
  5710. l2cap_do_start(chan);
  5711. }
  5712. err = 0;
  5713. chan_unlock:
  5714. l2cap_chan_unlock(chan);
  5715. mutex_unlock(&conn->chan_lock);
  5716. done:
  5717. hci_dev_unlock(hdev);
  5718. hci_dev_put(hdev);
  5719. return err;
  5720. }
  5721. EXPORT_SYMBOL_GPL(l2cap_chan_connect);
  5722. /* ---- L2CAP interface with lower layer (HCI) ---- */
  5723. int l2cap_connect_ind(struct hci_dev *hdev, bdaddr_t *bdaddr)
  5724. {
  5725. int exact = 0, lm1 = 0, lm2 = 0;
  5726. struct l2cap_chan *c;
  5727. BT_DBG("hdev %s, bdaddr %pMR", hdev->name, bdaddr);
  5728. /* Find listening sockets and check their link_mode */
  5729. read_lock(&chan_list_lock);
  5730. list_for_each_entry(c, &chan_list, global_l) {
  5731. if (c->state != BT_LISTEN)
  5732. continue;
  5733. if (!bacmp(&c->src, &hdev->bdaddr)) {
  5734. lm1 |= HCI_LM_ACCEPT;
  5735. if (test_bit(FLAG_ROLE_SWITCH, &c->flags))
  5736. lm1 |= HCI_LM_MASTER;
  5737. exact++;
  5738. } else if (!bacmp(&c->src, BDADDR_ANY)) {
  5739. lm2 |= HCI_LM_ACCEPT;
  5740. if (test_bit(FLAG_ROLE_SWITCH, &c->flags))
  5741. lm2 |= HCI_LM_MASTER;
  5742. }
  5743. }
  5744. read_unlock(&chan_list_lock);
  5745. return exact ? lm1 : lm2;
  5746. }
  5747. /* Find the next fixed channel in BT_LISTEN state, continue iteration
  5748. * from an existing channel in the list or from the beginning of the
  5749. * global list (by passing NULL as first parameter).
  5750. */
  5751. static struct l2cap_chan *l2cap_global_fixed_chan(struct l2cap_chan *c,
  5752. struct hci_conn *hcon)
  5753. {
  5754. u8 src_type = bdaddr_src_type(hcon);
  5755. read_lock(&chan_list_lock);
  5756. if (c)
  5757. c = list_next_entry(c, global_l);
  5758. else
  5759. c = list_entry(chan_list.next, typeof(*c), global_l);
  5760. list_for_each_entry_from(c, &chan_list, global_l) {
  5761. if (c->chan_type != L2CAP_CHAN_FIXED)
  5762. continue;
  5763. if (c->state != BT_LISTEN)
  5764. continue;
  5765. if (bacmp(&c->src, &hcon->src) && bacmp(&c->src, BDADDR_ANY))
  5766. continue;
  5767. if (src_type != c->src_type)
  5768. continue;
  5769. l2cap_chan_hold(c);
  5770. read_unlock(&chan_list_lock);
  5771. return c;
  5772. }
  5773. read_unlock(&chan_list_lock);
  5774. return NULL;
  5775. }
  5776. static void l2cap_connect_cfm(struct hci_conn *hcon, u8 status)
  5777. {
  5778. struct hci_dev *hdev = hcon->hdev;
  5779. struct l2cap_conn *conn;
  5780. struct l2cap_chan *pchan;
  5781. u8 dst_type;
  5782. if (hcon->type != ACL_LINK && hcon->type != LE_LINK)
  5783. return;
  5784. BT_DBG("hcon %p bdaddr %pMR status %d", hcon, &hcon->dst, status);
  5785. if (status) {
  5786. l2cap_conn_del(hcon, bt_to_errno(status));
  5787. return;
  5788. }
  5789. conn = l2cap_conn_add(hcon);
  5790. if (!conn)
  5791. return;
  5792. dst_type = bdaddr_dst_type(hcon);
  5793. /* If device is blocked, do not create channels for it */
  5794. if (hci_bdaddr_list_lookup(&hdev->blacklist, &hcon->dst, dst_type))
  5795. return;
  5796. /* Find fixed channels and notify them of the new connection. We
  5797. * use multiple individual lookups, continuing each time where
  5798. * we left off, because the list lock would prevent calling the
  5799. * potentially sleeping l2cap_chan_lock() function.
  5800. */
  5801. pchan = l2cap_global_fixed_chan(NULL, hcon);
  5802. while (pchan) {
  5803. struct l2cap_chan *chan, *next;
  5804. /* Client fixed channels should override server ones */
  5805. if (__l2cap_get_chan_by_dcid(conn, pchan->scid))
  5806. goto next;
  5807. l2cap_chan_lock(pchan);
  5808. chan = pchan->ops->new_connection(pchan);
  5809. if (chan) {
  5810. bacpy(&chan->src, &hcon->src);
  5811. bacpy(&chan->dst, &hcon->dst);
  5812. chan->src_type = bdaddr_src_type(hcon);
  5813. chan->dst_type = dst_type;
  5814. __l2cap_chan_add(conn, chan);
  5815. }
  5816. l2cap_chan_unlock(pchan);
  5817. next:
  5818. next = l2cap_global_fixed_chan(pchan, hcon);
  5819. l2cap_chan_put(pchan);
  5820. pchan = next;
  5821. }
  5822. l2cap_conn_ready(conn);
  5823. }
  5824. int l2cap_disconn_ind(struct hci_conn *hcon)
  5825. {
  5826. struct l2cap_conn *conn = hcon->l2cap_data;
  5827. BT_DBG("hcon %p", hcon);
  5828. if (!conn)
  5829. return HCI_ERROR_REMOTE_USER_TERM;
  5830. return conn->disc_reason;
  5831. }
  5832. static void l2cap_disconn_cfm(struct hci_conn *hcon, u8 reason)
  5833. {
  5834. if (hcon->type != ACL_LINK && hcon->type != LE_LINK)
  5835. return;
  5836. BT_DBG("hcon %p reason %d", hcon, reason);
  5837. l2cap_conn_del(hcon, bt_to_errno(reason));
  5838. }
  5839. static inline void l2cap_check_encryption(struct l2cap_chan *chan, u8 encrypt)
  5840. {
  5841. if (chan->chan_type != L2CAP_CHAN_CONN_ORIENTED)
  5842. return;
  5843. if (encrypt == 0x00) {
  5844. if (chan->sec_level == BT_SECURITY_MEDIUM) {
  5845. __set_chan_timer(chan, L2CAP_ENC_TIMEOUT);
  5846. } else if (chan->sec_level == BT_SECURITY_HIGH ||
  5847. chan->sec_level == BT_SECURITY_FIPS)
  5848. l2cap_chan_close(chan, ECONNREFUSED);
  5849. } else {
  5850. if (chan->sec_level == BT_SECURITY_MEDIUM)
  5851. __clear_chan_timer(chan);
  5852. }
  5853. }
  5854. static void l2cap_security_cfm(struct hci_conn *hcon, u8 status, u8 encrypt)
  5855. {
  5856. struct l2cap_conn *conn = hcon->l2cap_data;
  5857. struct l2cap_chan *chan;
  5858. if (!conn)
  5859. return;
  5860. BT_DBG("conn %p status 0x%2.2x encrypt %u", conn, status, encrypt);
  5861. mutex_lock(&conn->chan_lock);
  5862. list_for_each_entry(chan, &conn->chan_l, list) {
  5863. l2cap_chan_lock(chan);
  5864. BT_DBG("chan %p scid 0x%4.4x state %s", chan, chan->scid,
  5865. state_to_string(chan->state));
  5866. if (chan->scid == L2CAP_CID_A2MP) {
  5867. l2cap_chan_unlock(chan);
  5868. continue;
  5869. }
  5870. if (!status && encrypt)
  5871. chan->sec_level = hcon->sec_level;
  5872. if (!__l2cap_no_conn_pending(chan)) {
  5873. l2cap_chan_unlock(chan);
  5874. continue;
  5875. }
  5876. if (!status && (chan->state == BT_CONNECTED ||
  5877. chan->state == BT_CONFIG)) {
  5878. chan->ops->resume(chan);
  5879. l2cap_check_encryption(chan, encrypt);
  5880. l2cap_chan_unlock(chan);
  5881. continue;
  5882. }
  5883. if (chan->state == BT_CONNECT) {
  5884. if (!status)
  5885. l2cap_start_connection(chan);
  5886. else
  5887. __set_chan_timer(chan, L2CAP_DISC_TIMEOUT);
  5888. } else if (chan->state == BT_CONNECT2 &&
  5889. chan->mode != L2CAP_MODE_LE_FLOWCTL) {
  5890. struct l2cap_conn_rsp rsp;
  5891. __u16 res, stat;
  5892. if (!status) {
  5893. if (test_bit(FLAG_DEFER_SETUP, &chan->flags)) {
  5894. res = L2CAP_CR_PEND;
  5895. stat = L2CAP_CS_AUTHOR_PEND;
  5896. chan->ops->defer(chan);
  5897. } else {
  5898. l2cap_state_change(chan, BT_CONFIG);
  5899. res = L2CAP_CR_SUCCESS;
  5900. stat = L2CAP_CS_NO_INFO;
  5901. }
  5902. } else {
  5903. l2cap_state_change(chan, BT_DISCONN);
  5904. __set_chan_timer(chan, L2CAP_DISC_TIMEOUT);
  5905. res = L2CAP_CR_SEC_BLOCK;
  5906. stat = L2CAP_CS_NO_INFO;
  5907. }
  5908. rsp.scid = cpu_to_le16(chan->dcid);
  5909. rsp.dcid = cpu_to_le16(chan->scid);
  5910. rsp.result = cpu_to_le16(res);
  5911. rsp.status = cpu_to_le16(stat);
  5912. l2cap_send_cmd(conn, chan->ident, L2CAP_CONN_RSP,
  5913. sizeof(rsp), &rsp);
  5914. if (!test_bit(CONF_REQ_SENT, &chan->conf_state) &&
  5915. res == L2CAP_CR_SUCCESS) {
  5916. char buf[128];
  5917. set_bit(CONF_REQ_SENT, &chan->conf_state);
  5918. l2cap_send_cmd(conn, l2cap_get_ident(conn),
  5919. L2CAP_CONF_REQ,
  5920. l2cap_build_conf_req(chan, buf, sizeof(buf)),
  5921. buf);
  5922. chan->num_conf_req++;
  5923. }
  5924. }
  5925. l2cap_chan_unlock(chan);
  5926. }
  5927. mutex_unlock(&conn->chan_lock);
  5928. }
  5929. void l2cap_recv_acldata(struct hci_conn *hcon, struct sk_buff *skb, u16 flags)
  5930. {
  5931. struct l2cap_conn *conn = hcon->l2cap_data;
  5932. struct l2cap_hdr *hdr;
  5933. int len;
  5934. /* For AMP controller do not create l2cap conn */
  5935. if (!conn && hcon->hdev->dev_type != HCI_BREDR)
  5936. goto drop;
  5937. if (!conn)
  5938. conn = l2cap_conn_add(hcon);
  5939. if (!conn)
  5940. goto drop;
  5941. BT_DBG("conn %p len %d flags 0x%x", conn, skb->len, flags);
  5942. switch (flags) {
  5943. case ACL_START:
  5944. case ACL_START_NO_FLUSH:
  5945. case ACL_COMPLETE:
  5946. if (conn->rx_len) {
  5947. BT_ERR("Unexpected start frame (len %d)", skb->len);
  5948. kfree_skb(conn->rx_skb);
  5949. conn->rx_skb = NULL;
  5950. conn->rx_len = 0;
  5951. l2cap_conn_unreliable(conn, ECOMM);
  5952. }
  5953. /* Start fragment always begin with Basic L2CAP header */
  5954. if (skb->len < L2CAP_HDR_SIZE) {
  5955. BT_ERR("Frame is too short (len %d)", skb->len);
  5956. l2cap_conn_unreliable(conn, ECOMM);
  5957. goto drop;
  5958. }
  5959. hdr = (struct l2cap_hdr *) skb->data;
  5960. len = __le16_to_cpu(hdr->len) + L2CAP_HDR_SIZE;
  5961. if (len == skb->len) {
  5962. /* Complete frame received */
  5963. l2cap_recv_frame(conn, skb);
  5964. return;
  5965. }
  5966. BT_DBG("Start: total len %d, frag len %d", len, skb->len);
  5967. if (skb->len > len) {
  5968. BT_ERR("Frame is too long (len %d, expected len %d)",
  5969. skb->len, len);
  5970. l2cap_conn_unreliable(conn, ECOMM);
  5971. goto drop;
  5972. }
  5973. /* Allocate skb for the complete frame (with header) */
  5974. conn->rx_skb = bt_skb_alloc(len, GFP_KERNEL);
  5975. if (!conn->rx_skb)
  5976. goto drop;
  5977. skb_copy_from_linear_data(skb, skb_put(conn->rx_skb, skb->len),
  5978. skb->len);
  5979. conn->rx_len = len - skb->len;
  5980. break;
  5981. case ACL_CONT:
  5982. BT_DBG("Cont: frag len %d (expecting %d)", skb->len, conn->rx_len);
  5983. if (!conn->rx_len) {
  5984. BT_ERR("Unexpected continuation frame (len %d)", skb->len);
  5985. l2cap_conn_unreliable(conn, ECOMM);
  5986. goto drop;
  5987. }
  5988. if (skb->len > conn->rx_len) {
  5989. BT_ERR("Fragment is too long (len %d, expected %d)",
  5990. skb->len, conn->rx_len);
  5991. kfree_skb(conn->rx_skb);
  5992. conn->rx_skb = NULL;
  5993. conn->rx_len = 0;
  5994. l2cap_conn_unreliable(conn, ECOMM);
  5995. goto drop;
  5996. }
  5997. skb_copy_from_linear_data(skb, skb_put(conn->rx_skb, skb->len),
  5998. skb->len);
  5999. conn->rx_len -= skb->len;
  6000. if (!conn->rx_len) {
  6001. /* Complete frame received. l2cap_recv_frame
  6002. * takes ownership of the skb so set the global
  6003. * rx_skb pointer to NULL first.
  6004. */
  6005. struct sk_buff *rx_skb = conn->rx_skb;
  6006. conn->rx_skb = NULL;
  6007. l2cap_recv_frame(conn, rx_skb);
  6008. }
  6009. break;
  6010. }
  6011. drop:
  6012. kfree_skb(skb);
  6013. }
  6014. static struct hci_cb l2cap_cb = {
  6015. .name = "L2CAP",
  6016. .connect_cfm = l2cap_connect_cfm,
  6017. .disconn_cfm = l2cap_disconn_cfm,
  6018. .security_cfm = l2cap_security_cfm,
  6019. };
  6020. static int l2cap_debugfs_show(struct seq_file *f, void *p)
  6021. {
  6022. struct l2cap_chan *c;
  6023. read_lock(&chan_list_lock);
  6024. list_for_each_entry(c, &chan_list, global_l) {
  6025. seq_printf(f, "%pMR (%u) %pMR (%u) %d %d 0x%4.4x 0x%4.4x %d %d %d %d\n",
  6026. &c->src, c->src_type, &c->dst, c->dst_type,
  6027. c->state, __le16_to_cpu(c->psm),
  6028. c->scid, c->dcid, c->imtu, c->omtu,
  6029. c->sec_level, c->mode);
  6030. }
  6031. read_unlock(&chan_list_lock);
  6032. return 0;
  6033. }
  6034. static int l2cap_debugfs_open(struct inode *inode, struct file *file)
  6035. {
  6036. return single_open(file, l2cap_debugfs_show, inode->i_private);
  6037. }
  6038. static const struct file_operations l2cap_debugfs_fops = {
  6039. .open = l2cap_debugfs_open,
  6040. .read = seq_read,
  6041. .llseek = seq_lseek,
  6042. .release = single_release,
  6043. };
  6044. static struct dentry *l2cap_debugfs;
  6045. int __init l2cap_init(void)
  6046. {
  6047. int err;
  6048. err = l2cap_init_sockets();
  6049. if (err < 0)
  6050. return err;
  6051. hci_register_cb(&l2cap_cb);
  6052. if (IS_ERR_OR_NULL(bt_debugfs))
  6053. return 0;
  6054. l2cap_debugfs = debugfs_create_file("l2cap", 0444, bt_debugfs,
  6055. NULL, &l2cap_debugfs_fops);
  6056. debugfs_create_u16("l2cap_le_max_credits", 0644, bt_debugfs,
  6057. &le_max_credits);
  6058. debugfs_create_u16("l2cap_le_default_mps", 0644, bt_debugfs,
  6059. &le_default_mps);
  6060. return 0;
  6061. }
  6062. void l2cap_exit(void)
  6063. {
  6064. debugfs_remove(l2cap_debugfs);
  6065. hci_unregister_cb(&l2cap_cb);
  6066. l2cap_cleanup_sockets();
  6067. }
  6068. module_param(disable_ertm, bool, 0644);
  6069. MODULE_PARM_DESC(disable_ertm, "Disable enhanced retransmission mode");