Bluetooth: Switch ATT channels to use L2CAP_CHAN_FIXED
[deliverable/linux.git] / net / bluetooth / l2cap_sock.c
CommitLineData
bb58f747
GP
1/*
2 BlueZ - Bluetooth protocol stack for Linux
3 Copyright (C) 2000-2001 Qualcomm Incorporated
4 Copyright (C) 2009-2010 Gustavo F. Padovan <gustavo@padovan.org>
5 Copyright (C) 2010 Google Inc.
590051de 6 Copyright (C) 2011 ProFUSION Embedded Systems
bb58f747
GP
7
8 Written 2000,2001 by Maxim Krasnyansky <maxk@qualcomm.com>
9
10 This program is free software; you can redistribute it and/or modify
11 it under the terms of the GNU General Public License version 2 as
12 published by the Free Software Foundation;
13
14 THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS
15 OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
16 FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT OF THIRD PARTY RIGHTS.
17 IN NO EVENT SHALL THE COPYRIGHT HOLDER(S) AND AUTHOR(S) BE LIABLE FOR ANY
18 CLAIM, OR ANY SPECIAL INDIRECT OR CONSEQUENTIAL DAMAGES, OR ANY DAMAGES
19 WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
20 ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
21 OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
22
23 ALL LIABILITY, INCLUDING LIABILITY FOR INFRINGEMENT OF ANY PATENTS,
24 COPYRIGHTS, TRADEMARKS OR OTHER RIGHTS, RELATING TO USE OF THIS
25 SOFTWARE IS DISCLAIMED.
26*/
27
28/* Bluetooth L2CAP sockets. */
29
9149761a 30#include <linux/module.h>
bc3b2d7f 31#include <linux/export.h>
6230c9b4 32
bb58f747 33#include <net/bluetooth/bluetooth.h>
33575df7 34#include <net/bluetooth/hci_core.h>
bb58f747 35#include <net/bluetooth/l2cap.h>
ac4b7236
MH
36
37#include "smp.h"
bb58f747 38
9149761a
JH
39bool enable_lecoc;
40
5b28d95c
MY
41static struct bt_sock_list l2cap_sk_list = {
42 .lock = __RW_LOCK_UNLOCKED(l2cap_sk_list.lock)
43};
44
cf2f90f5 45static const struct proto_ops l2cap_sock_ops;
80808e43 46static void l2cap_sock_init(struct sock *sk, struct sock *parent);
2d792818
GP
47static struct sock *l2cap_sock_alloc(struct net *net, struct socket *sock,
48 int proto, gfp_t prio);
cf2f90f5 49
b3916db3
DH
50bool l2cap_is_socket(struct socket *sock)
51{
52 return sock && sock->ops == &l2cap_sock_ops;
53}
54EXPORT_SYMBOL(l2cap_is_socket);
55
4946096d
JH
56static int l2cap_validate_bredr_psm(u16 psm)
57{
58 /* PSM must be odd and lsb of upper byte must be 0 */
59 if ((psm & 0x0101) != 0x0001)
60 return -EINVAL;
61
62 /* Restrict usage of well-known PSMs */
63 if (psm < 0x1001 && !capable(CAP_NET_BIND_SERVICE))
64 return -EACCES;
65
66 return 0;
67}
68
69static int l2cap_validate_le_psm(u16 psm)
70{
71 /* Valid LE_PSM ranges are defined only until 0x00ff */
72 if (psm > 0x00ff)
73 return -EINVAL;
74
75 /* Restrict fixed, SIG assigned PSM values to CAP_NET_BIND_SERVICE */
76 if (psm <= 0x007f && !capable(CAP_NET_BIND_SERVICE))
77 return -EACCES;
78
79 return 0;
80}
81
af6bcd82
GP
82static int l2cap_sock_bind(struct socket *sock, struct sockaddr *addr, int alen)
83{
84 struct sock *sk = sock->sk;
4343478f 85 struct l2cap_chan *chan = l2cap_pi(sk)->chan;
af6bcd82
GP
86 struct sockaddr_l2 la;
87 int len, err = 0;
88
89 BT_DBG("sk %p", sk);
90
91 if (!addr || addr->sa_family != AF_BLUETOOTH)
92 return -EINVAL;
93
94 memset(&la, 0, sizeof(la));
95 len = min_t(unsigned int, sizeof(la), alen);
96 memcpy(&la, addr, len);
97
b62f328b 98 if (la.l2_cid && la.l2_psm)
af6bcd82
GP
99 return -EINVAL;
100
80c1a2e7
JH
101 if (!bdaddr_type_is_valid(la.l2_bdaddr_type))
102 return -EINVAL;
103
21626e62
JH
104 if (la.l2_cid) {
105 /* When the socket gets created it defaults to
106 * CHAN_CONN_ORIENTED, so we need to overwrite the
107 * default here.
108 */
109 chan->chan_type = L2CAP_CHAN_FIXED;
110 chan->omtu = L2CAP_DEFAULT_MTU;
111 }
112
bfe4655f 113 if (bdaddr_type_is_le(la.l2_bdaddr_type)) {
9149761a 114 if (!enable_lecoc && la.l2_psm)
bfe4655f
JH
115 return -EINVAL;
116 /* We only allow ATT user space socket */
9149761a
JH
117 if (la.l2_cid &&
118 la.l2_cid != __constant_cpu_to_le16(L2CAP_CID_ATT))
bfe4655f
JH
119 return -EINVAL;
120 }
121
af6bcd82
GP
122 lock_sock(sk);
123
124 if (sk->sk_state != BT_OPEN) {
125 err = -EBADFD;
126 goto done;
127 }
128
129 if (la.l2_psm) {
130 __u16 psm = __le16_to_cpu(la.l2_psm);
131
4946096d
JH
132 if (la.l2_bdaddr_type == BDADDR_BREDR)
133 err = l2cap_validate_bredr_psm(psm);
134 else
135 err = l2cap_validate_le_psm(psm);
af6bcd82 136
4946096d 137 if (err)
af6bcd82 138 goto done;
af6bcd82
GP
139 }
140
9e4425ff 141 if (la.l2_cid)
6e4aff10 142 err = l2cap_add_scid(chan, __le16_to_cpu(la.l2_cid));
9e4425ff
GP
143 else
144 err = l2cap_add_psm(chan, &la.l2_bdaddr, la.l2_psm);
af6bcd82 145
9e4425ff
GP
146 if (err < 0)
147 goto done;
af6bcd82 148
6a974b50 149 switch (chan->chan_type) {
3124b843
MH
150 case L2CAP_CHAN_CONN_LESS:
151 if (__le16_to_cpu(la.l2_psm) == L2CAP_PSM_3DSP)
152 chan->sec_level = BT_SECURITY_SDP;
153 break;
6a974b50
MH
154 case L2CAP_CHAN_CONN_ORIENTED:
155 if (__le16_to_cpu(la.l2_psm) == L2CAP_PSM_SDP ||
156 __le16_to_cpu(la.l2_psm) == L2CAP_PSM_RFCOMM)
157 chan->sec_level = BT_SECURITY_SDP;
158 break;
cb6ca8e1
JH
159 case L2CAP_CHAN_RAW:
160 chan->sec_level = BT_SECURITY_SDP;
161 break;
6a974b50 162 }
b62f328b 163
7eafc59e 164 bacpy(&chan->src, &la.l2_bdaddr);
4f1654e0 165 chan->src_type = la.l2_bdaddr_type;
89bc500e 166
38319713 167 if (chan->psm && bdaddr_type_is_le(chan->src_type))
0ce43ce6 168 chan->mode = L2CAP_MODE_LE_FLOWCTL;
38319713 169
89bc500e 170 chan->state = BT_BOUND;
9e4425ff 171 sk->sk_state = BT_BOUND;
af6bcd82
GP
172
173done:
174 release_sock(sk);
175 return err;
176}
177
2d792818
GP
178static int l2cap_sock_connect(struct socket *sock, struct sockaddr *addr,
179 int alen, int flags)
4e34c50b
GP
180{
181 struct sock *sk = sock->sk;
0c1bc5c6 182 struct l2cap_chan *chan = l2cap_pi(sk)->chan;
4e34c50b
GP
183 struct sockaddr_l2 la;
184 int len, err = 0;
185
186 BT_DBG("sk %p", sk);
187
188 if (!addr || alen < sizeof(addr->sa_family) ||
189 addr->sa_family != AF_BLUETOOTH)
190 return -EINVAL;
191
192 memset(&la, 0, sizeof(la));
193 len = min_t(unsigned int, sizeof(la), alen);
194 memcpy(&la, addr, len);
195
acd7d370 196 if (la.l2_cid && la.l2_psm)
4e34c50b
GP
197 return -EINVAL;
198
80c1a2e7
JH
199 if (!bdaddr_type_is_valid(la.l2_bdaddr_type))
200 return -EINVAL;
201
eb622495
JH
202 /* Check that the socket wasn't bound to something that
203 * conflicts with the address given to connect(). If chan->src
204 * is BDADDR_ANY it means bind() was never used, in which case
205 * chan->src_type and la.l2_bdaddr_type do not need to match.
206 */
207 if (chan->src_type == BDADDR_BREDR && bacmp(&chan->src, BDADDR_ANY) &&
208 bdaddr_type_is_le(la.l2_bdaddr_type)) {
209 /* Old user space versions will try to incorrectly bind
210 * the ATT socket using BDADDR_BREDR. We need to accept
211 * this and fix up the source address type only when
212 * both the source CID and destination CID indicate
213 * ATT. Anything else is an invalid combination.
214 */
215 if (chan->scid != L2CAP_CID_ATT ||
216 la.l2_cid != __constant_cpu_to_le16(L2CAP_CID_ATT))
217 return -EINVAL;
218
219 /* We don't have the hdev available here to make a
220 * better decision on random vs public, but since all
221 * user space versions that exhibit this issue anyway do
222 * not support random local addresses assuming public
223 * here is good enough.
224 */
225 chan->src_type = BDADDR_LE_PUBLIC;
226 }
1f209383
JH
227
228 if (chan->src_type != BDADDR_BREDR && la.l2_bdaddr_type == BDADDR_BREDR)
229 return -EINVAL;
230
bfe4655f 231 if (bdaddr_type_is_le(la.l2_bdaddr_type)) {
9149761a 232 if (!enable_lecoc && la.l2_psm)
bfe4655f
JH
233 return -EINVAL;
234 /* We only allow ATT user space socket */
9149761a
JH
235 if (la.l2_cid &&
236 la.l2_cid != __constant_cpu_to_le16(L2CAP_CID_ATT))
bfe4655f
JH
237 return -EINVAL;
238 }
239
38319713 240 if (chan->psm && bdaddr_type_is_le(chan->src_type))
0ce43ce6 241 chan->mode = L2CAP_MODE_LE_FLOWCTL;
38319713 242
6e4aff10 243 err = l2cap_chan_connect(chan, la.l2_psm, __le16_to_cpu(la.l2_cid),
8e9f9892 244 &la.l2_bdaddr, la.l2_bdaddr_type);
4e34c50b 245 if (err)
b3fb611e 246 return err;
4e34c50b 247
6be36555
AE
248 lock_sock(sk);
249
4e34c50b 250 err = bt_sock_wait_state(sk, BT_CONNECTED,
2d792818 251 sock_sndtimeo(sk, flags & O_NONBLOCK));
b3fb611e
AE
252
253 release_sock(sk);
254
4e34c50b
GP
255 return err;
256}
257
af6bcd82
GP
258static int l2cap_sock_listen(struct socket *sock, int backlog)
259{
260 struct sock *sk = sock->sk;
0c1bc5c6 261 struct l2cap_chan *chan = l2cap_pi(sk)->chan;
af6bcd82
GP
262 int err = 0;
263
264 BT_DBG("sk %p backlog %d", sk, backlog);
265
266 lock_sock(sk);
267
6b3af733 268 if (sk->sk_state != BT_BOUND) {
af6bcd82
GP
269 err = -EBADFD;
270 goto done;
271 }
272
6b3af733
MH
273 if (sk->sk_type != SOCK_SEQPACKET && sk->sk_type != SOCK_STREAM) {
274 err = -EINVAL;
275 goto done;
276 }
277
0c1bc5c6 278 switch (chan->mode) {
af6bcd82 279 case L2CAP_MODE_BASIC:
38319713 280 case L2CAP_MODE_LE_FLOWCTL:
af6bcd82
GP
281 break;
282 case L2CAP_MODE_ERTM:
283 case L2CAP_MODE_STREAMING:
284 if (!disable_ertm)
285 break;
286 /* fall through */
287 default:
288 err = -ENOTSUPP;
289 goto done;
290 }
291
af6bcd82
GP
292 sk->sk_max_ack_backlog = backlog;
293 sk->sk_ack_backlog = 0;
89bc500e
GP
294
295 chan->state = BT_LISTEN;
af6bcd82
GP
296 sk->sk_state = BT_LISTEN;
297
298done:
299 release_sock(sk);
300 return err;
301}
302
2d792818
GP
303static int l2cap_sock_accept(struct socket *sock, struct socket *newsock,
304 int flags)
c47b7c72
GP
305{
306 DECLARE_WAITQUEUE(wait, current);
307 struct sock *sk = sock->sk, *nsk;
308 long timeo;
309 int err = 0;
310
311 lock_sock_nested(sk, SINGLE_DEPTH_NESTING);
312
c47b7c72
GP
313 timeo = sock_rcvtimeo(sk, flags & O_NONBLOCK);
314
315 BT_DBG("sk %p timeo %ld", sk, timeo);
316
317 /* Wait for an incoming connection. (wake-one). */
318 add_wait_queue_exclusive(sk_sleep(sk), &wait);
f9a3c20a 319 while (1) {
c47b7c72 320 set_current_state(TASK_INTERRUPTIBLE);
f9a3c20a
PH
321
322 if (sk->sk_state != BT_LISTEN) {
323 err = -EBADFD;
c47b7c72
GP
324 break;
325 }
326
f9a3c20a
PH
327 nsk = bt_accept_dequeue(sk, newsock);
328 if (nsk)
329 break;
c47b7c72 330
f9a3c20a
PH
331 if (!timeo) {
332 err = -EAGAIN;
c47b7c72
GP
333 break;
334 }
335
336 if (signal_pending(current)) {
337 err = sock_intr_errno(timeo);
338 break;
339 }
f9a3c20a
PH
340
341 release_sock(sk);
342 timeo = schedule_timeout(timeo);
343 lock_sock_nested(sk, SINGLE_DEPTH_NESTING);
c47b7c72 344 }
f9a3c20a 345 __set_current_state(TASK_RUNNING);
c47b7c72
GP
346 remove_wait_queue(sk_sleep(sk), &wait);
347
348 if (err)
349 goto done;
350
351 newsock->state = SS_CONNECTED;
352
353 BT_DBG("new socket %p", nsk);
354
355done:
356 release_sock(sk);
357 return err;
358}
359
2d792818
GP
360static int l2cap_sock_getname(struct socket *sock, struct sockaddr *addr,
361 int *len, int peer)
d7175d55
GP
362{
363 struct sockaddr_l2 *la = (struct sockaddr_l2 *) addr;
364 struct sock *sk = sock->sk;
0c1bc5c6 365 struct l2cap_chan *chan = l2cap_pi(sk)->chan;
d7175d55
GP
366
367 BT_DBG("sock %p, sk %p", sock, sk);
368
792039c7 369 memset(la, 0, sizeof(struct sockaddr_l2));
d7175d55
GP
370 addr->sa_family = AF_BLUETOOTH;
371 *len = sizeof(struct sockaddr_l2);
372
373 if (peer) {
fe4128e0 374 la->l2_psm = chan->psm;
7eafc59e 375 bacpy(&la->l2_bdaddr, &chan->dst);
fe4128e0 376 la->l2_cid = cpu_to_le16(chan->dcid);
4f1654e0 377 la->l2_bdaddr_type = chan->dst_type;
d7175d55 378 } else {
0c1bc5c6 379 la->l2_psm = chan->sport;
7eafc59e 380 bacpy(&la->l2_bdaddr, &chan->src);
fe4128e0 381 la->l2_cid = cpu_to_le16(chan->scid);
4f1654e0 382 la->l2_bdaddr_type = chan->src_type;
d7175d55
GP
383 }
384
385 return 0;
386}
387
2d792818
GP
388static int l2cap_sock_getsockopt_old(struct socket *sock, int optname,
389 char __user *optval, int __user *optlen)
99f4808d
GP
390{
391 struct sock *sk = sock->sk;
4343478f 392 struct l2cap_chan *chan = l2cap_pi(sk)->chan;
99f4808d
GP
393 struct l2cap_options opts;
394 struct l2cap_conninfo cinfo;
395 int len, err = 0;
396 u32 opt;
397
398 BT_DBG("sk %p", sk);
399
400 if (get_user(len, optlen))
401 return -EFAULT;
402
403 lock_sock(sk);
404
405 switch (optname) {
406 case L2CAP_OPTIONS:
64b4f8dc
JH
407 /* LE sockets should use BT_SNDMTU/BT_RCVMTU, but since
408 * legacy ATT code depends on getsockopt for
409 * L2CAP_OPTIONS we need to let this pass.
410 */
411 if (bdaddr_type_is_le(chan->src_type) &&
412 chan->scid != L2CAP_CID_ATT) {
413 err = -EINVAL;
414 break;
415 }
416
e3fb592b 417 memset(&opts, 0, sizeof(opts));
0c1bc5c6
GP
418 opts.imtu = chan->imtu;
419 opts.omtu = chan->omtu;
420 opts.flush_to = chan->flush_to;
421 opts.mode = chan->mode;
47d1ec61
GP
422 opts.fcs = chan->fcs;
423 opts.max_tx = chan->max_tx;
6327eb98 424 opts.txwin_size = chan->tx_win;
99f4808d
GP
425
426 len = min_t(unsigned int, len, sizeof(opts));
427 if (copy_to_user(optval, (char *) &opts, len))
428 err = -EFAULT;
429
430 break;
431
432 case L2CAP_LM:
4343478f 433 switch (chan->sec_level) {
99f4808d
GP
434 case BT_SECURITY_LOW:
435 opt = L2CAP_LM_AUTH;
436 break;
437 case BT_SECURITY_MEDIUM:
438 opt = L2CAP_LM_AUTH | L2CAP_LM_ENCRYPT;
439 break;
440 case BT_SECURITY_HIGH:
441 opt = L2CAP_LM_AUTH | L2CAP_LM_ENCRYPT |
2d792818 442 L2CAP_LM_SECURE;
99f4808d 443 break;
7d513e92
MH
444 case BT_SECURITY_FIPS:
445 opt = L2CAP_LM_AUTH | L2CAP_LM_ENCRYPT |
446 L2CAP_LM_SECURE | L2CAP_LM_FIPS;
447 break;
99f4808d
GP
448 default:
449 opt = 0;
450 break;
451 }
452
43bd0f32 453 if (test_bit(FLAG_ROLE_SWITCH, &chan->flags))
99f4808d
GP
454 opt |= L2CAP_LM_MASTER;
455
ecf61bdb 456 if (test_bit(FLAG_FORCE_RELIABLE, &chan->flags))
99f4808d
GP
457 opt |= L2CAP_LM_RELIABLE;
458
459 if (put_user(opt, (u32 __user *) optval))
460 err = -EFAULT;
7d513e92 461
99f4808d
GP
462 break;
463
464 case L2CAP_CONNINFO:
465 if (sk->sk_state != BT_CONNECTED &&
c5daa683
GP
466 !(sk->sk_state == BT_CONNECT2 &&
467 test_bit(BT_SK_DEFER_SETUP, &bt_sk(sk)->flags))) {
99f4808d
GP
468 err = -ENOTCONN;
469 break;
470 }
471
8d03e971 472 memset(&cinfo, 0, sizeof(cinfo));
8c1d787b
GP
473 cinfo.hci_handle = chan->conn->hcon->handle;
474 memcpy(cinfo.dev_class, chan->conn->hcon->dev_class, 3);
99f4808d
GP
475
476 len = min_t(unsigned int, len, sizeof(cinfo));
477 if (copy_to_user(optval, (char *) &cinfo, len))
478 err = -EFAULT;
479
480 break;
481
482 default:
483 err = -ENOPROTOOPT;
484 break;
485 }
486
487 release_sock(sk);
488 return err;
489}
490
2d792818
GP
491static int l2cap_sock_getsockopt(struct socket *sock, int level, int optname,
492 char __user *optval, int __user *optlen)
99f4808d
GP
493{
494 struct sock *sk = sock->sk;
4343478f 495 struct l2cap_chan *chan = l2cap_pi(sk)->chan;
99f4808d 496 struct bt_security sec;
14b12d0b 497 struct bt_power pwr;
99f4808d
GP
498 int len, err = 0;
499
500 BT_DBG("sk %p", sk);
501
502 if (level == SOL_L2CAP)
503 return l2cap_sock_getsockopt_old(sock, optname, optval, optlen);
504
505 if (level != SOL_BLUETOOTH)
506 return -ENOPROTOOPT;
507
508 if (get_user(len, optlen))
509 return -EFAULT;
510
511 lock_sock(sk);
512
513 switch (optname) {
514 case BT_SECURITY:
715ec005 515 if (chan->chan_type != L2CAP_CHAN_CONN_ORIENTED &&
2d792818 516 chan->chan_type != L2CAP_CHAN_RAW) {
99f4808d
GP
517 err = -EINVAL;
518 break;
519 }
520
8f360119 521 memset(&sec, 0, sizeof(sec));
85e34368 522 if (chan->conn) {
c6585a4d 523 sec.level = chan->conn->hcon->sec_level;
99f4808d 524
85e34368
AE
525 if (sk->sk_state == BT_CONNECTED)
526 sec.key_size = chan->conn->hcon->enc_key_size;
527 } else {
528 sec.level = chan->sec_level;
529 }
8f360119 530
99f4808d
GP
531 len = min_t(unsigned int, len, sizeof(sec));
532 if (copy_to_user(optval, (char *) &sec, len))
533 err = -EFAULT;
534
535 break;
536
537 case BT_DEFER_SETUP:
538 if (sk->sk_state != BT_BOUND && sk->sk_state != BT_LISTEN) {
539 err = -EINVAL;
540 break;
541 }
542
c5daa683
GP
543 if (put_user(test_bit(BT_SK_DEFER_SETUP, &bt_sk(sk)->flags),
544 (u32 __user *) optval))
99f4808d
GP
545 err = -EFAULT;
546
547 break;
548
549 case BT_FLUSHABLE:
d57b0e8b 550 if (put_user(test_bit(FLAG_FLUSHABLE, &chan->flags),
2d792818 551 (u32 __user *) optval))
99f4808d
GP
552 err = -EFAULT;
553
554 break;
555
14b12d0b
JG
556 case BT_POWER:
557 if (sk->sk_type != SOCK_SEQPACKET && sk->sk_type != SOCK_STREAM
2d792818 558 && sk->sk_type != SOCK_RAW) {
14b12d0b
JG
559 err = -EINVAL;
560 break;
561 }
562
15770b1a 563 pwr.force_active = test_bit(FLAG_FORCE_ACTIVE, &chan->flags);
14b12d0b
JG
564
565 len = min_t(unsigned int, len, sizeof(pwr));
566 if (copy_to_user(optval, (char *) &pwr, len))
567 err = -EFAULT;
568
569 break;
570
2ea66482 571 case BT_CHANNEL_POLICY:
2ea66482
MM
572 if (put_user(chan->chan_policy, (u32 __user *) optval))
573 err = -EFAULT;
574 break;
575
1f435424
JH
576 case BT_SNDMTU:
577 if (!enable_lecoc) {
578 err = -EPROTONOSUPPORT;
579 break;
580 }
581
582 if (!bdaddr_type_is_le(chan->src_type)) {
583 err = -EINVAL;
584 break;
585 }
586
587 if (sk->sk_state != BT_CONNECTED) {
588 err = -ENOTCONN;
589 break;
590 }
591
592 if (put_user(chan->omtu, (u16 __user *) optval))
593 err = -EFAULT;
594 break;
595
596 case BT_RCVMTU:
597 if (!enable_lecoc) {
598 err = -EPROTONOSUPPORT;
599 break;
600 }
601
602 if (!bdaddr_type_is_le(chan->src_type)) {
603 err = -EINVAL;
604 break;
605 }
606
607 if (put_user(chan->imtu, (u16 __user *) optval))
608 err = -EFAULT;
609 break;
610
99f4808d
GP
611 default:
612 err = -ENOPROTOOPT;
613 break;
614 }
615
616 release_sock(sk);
617 return err;
618}
619
682877c3
AG
620static bool l2cap_valid_mtu(struct l2cap_chan *chan, u16 mtu)
621{
622 switch (chan->scid) {
073d1cf3 623 case L2CAP_CID_ATT:
8c3a4f00 624 if (mtu < L2CAP_LE_MIN_MTU)
682877c3
AG
625 return false;
626 break;
627
628 default:
629 if (mtu < L2CAP_DEFAULT_MIN_MTU)
630 return false;
631 }
632
633 return true;
634}
635
2d792818
GP
636static int l2cap_sock_setsockopt_old(struct socket *sock, int optname,
637 char __user *optval, unsigned int optlen)
33575df7
GP
638{
639 struct sock *sk = sock->sk;
b4450035 640 struct l2cap_chan *chan = l2cap_pi(sk)->chan;
33575df7
GP
641 struct l2cap_options opts;
642 int len, err = 0;
643 u32 opt;
644
645 BT_DBG("sk %p", sk);
646
647 lock_sock(sk);
648
649 switch (optname) {
650 case L2CAP_OPTIONS:
64b4f8dc
JH
651 if (bdaddr_type_is_le(chan->src_type)) {
652 err = -EINVAL;
653 break;
654 }
655
33575df7
GP
656 if (sk->sk_state == BT_CONNECTED) {
657 err = -EINVAL;
658 break;
659 }
660
0c1bc5c6
GP
661 opts.imtu = chan->imtu;
662 opts.omtu = chan->omtu;
663 opts.flush_to = chan->flush_to;
664 opts.mode = chan->mode;
47d1ec61
GP
665 opts.fcs = chan->fcs;
666 opts.max_tx = chan->max_tx;
6327eb98 667 opts.txwin_size = chan->tx_win;
33575df7
GP
668
669 len = min_t(unsigned int, sizeof(opts), optlen);
670 if (copy_from_user((char *) &opts, optval, len)) {
671 err = -EFAULT;
672 break;
673 }
674
6327eb98 675 if (opts.txwin_size > L2CAP_DEFAULT_EXT_WINDOW) {
33575df7
GP
676 err = -EINVAL;
677 break;
678 }
679
682877c3
AG
680 if (!l2cap_valid_mtu(chan, opts.imtu)) {
681 err = -EINVAL;
682 break;
683 }
684
0c1bc5c6
GP
685 chan->mode = opts.mode;
686 switch (chan->mode) {
38319713
JH
687 case L2CAP_MODE_LE_FLOWCTL:
688 break;
33575df7 689 case L2CAP_MODE_BASIC:
c1360a1c 690 clear_bit(CONF_STATE2_DEVICE, &chan->conf_state);
33575df7
GP
691 break;
692 case L2CAP_MODE_ERTM:
693 case L2CAP_MODE_STREAMING:
694 if (!disable_ertm)
695 break;
696 /* fall through */
697 default:
698 err = -EINVAL;
699 break;
700 }
701
0c1bc5c6
GP
702 chan->imtu = opts.imtu;
703 chan->omtu = opts.omtu;
47d1ec61
GP
704 chan->fcs = opts.fcs;
705 chan->max_tx = opts.max_tx;
6327eb98 706 chan->tx_win = opts.txwin_size;
12d59781 707 chan->flush_to = opts.flush_to;
33575df7
GP
708 break;
709
710 case L2CAP_LM:
711 if (get_user(opt, (u32 __user *) optval)) {
712 err = -EFAULT;
713 break;
714 }
715
7d513e92
MH
716 if (opt & L2CAP_LM_FIPS) {
717 err = -EINVAL;
718 break;
719 }
720
33575df7 721 if (opt & L2CAP_LM_AUTH)
4343478f 722 chan->sec_level = BT_SECURITY_LOW;
33575df7 723 if (opt & L2CAP_LM_ENCRYPT)
4343478f 724 chan->sec_level = BT_SECURITY_MEDIUM;
33575df7 725 if (opt & L2CAP_LM_SECURE)
4343478f 726 chan->sec_level = BT_SECURITY_HIGH;
33575df7 727
43bd0f32
AE
728 if (opt & L2CAP_LM_MASTER)
729 set_bit(FLAG_ROLE_SWITCH, &chan->flags);
730 else
731 clear_bit(FLAG_ROLE_SWITCH, &chan->flags);
ecf61bdb
AE
732
733 if (opt & L2CAP_LM_RELIABLE)
734 set_bit(FLAG_FORCE_RELIABLE, &chan->flags);
735 else
736 clear_bit(FLAG_FORCE_RELIABLE, &chan->flags);
33575df7
GP
737 break;
738
739 default:
740 err = -ENOPROTOOPT;
741 break;
742 }
743
744 release_sock(sk);
745 return err;
746}
747
2d792818
GP
748static int l2cap_sock_setsockopt(struct socket *sock, int level, int optname,
749 char __user *optval, unsigned int optlen)
33575df7
GP
750{
751 struct sock *sk = sock->sk;
4343478f 752 struct l2cap_chan *chan = l2cap_pi(sk)->chan;
33575df7 753 struct bt_security sec;
14b12d0b 754 struct bt_power pwr;
f1cb9af5 755 struct l2cap_conn *conn;
33575df7
GP
756 int len, err = 0;
757 u32 opt;
758
759 BT_DBG("sk %p", sk);
760
761 if (level == SOL_L2CAP)
762 return l2cap_sock_setsockopt_old(sock, optname, optval, optlen);
763
764 if (level != SOL_BLUETOOTH)
765 return -ENOPROTOOPT;
766
767 lock_sock(sk);
768
769 switch (optname) {
770 case BT_SECURITY:
715ec005 771 if (chan->chan_type != L2CAP_CHAN_CONN_ORIENTED &&
2d792818 772 chan->chan_type != L2CAP_CHAN_RAW) {
33575df7
GP
773 err = -EINVAL;
774 break;
775 }
776
777 sec.level = BT_SECURITY_LOW;
778
779 len = min_t(unsigned int, sizeof(sec), optlen);
780 if (copy_from_user((char *) &sec, optval, len)) {
781 err = -EFAULT;
782 break;
783 }
784
785 if (sec.level < BT_SECURITY_LOW ||
2d792818 786 sec.level > BT_SECURITY_HIGH) {
33575df7
GP
787 err = -EINVAL;
788 break;
789 }
790
4343478f 791 chan->sec_level = sec.level;
f1cb9af5 792
0bee1d60
GP
793 if (!chan->conn)
794 break;
795
f1cb9af5 796 conn = chan->conn;
0bee1d60
GP
797
798 /*change security for LE channels */
073d1cf3 799 if (chan->scid == L2CAP_CID_ATT) {
f1cb9af5
VCG
800 if (!conn->hcon->out) {
801 err = -EINVAL;
802 break;
803 }
804
cc110922 805 if (smp_conn_security(conn->hcon, sec.level))
f1cb9af5 806 break;
f1cb9af5 807 sk->sk_state = BT_CONFIG;
3542b854 808 chan->state = BT_CONFIG;
0bee1d60 809
a7d7723a
GP
810 /* or for ACL link */
811 } else if ((sk->sk_state == BT_CONNECT2 &&
2d792818 812 test_bit(BT_SK_DEFER_SETUP, &bt_sk(sk)->flags)) ||
a7d7723a
GP
813 sk->sk_state == BT_CONNECTED) {
814 if (!l2cap_chan_check_security(chan))
c5daa683 815 set_bit(BT_SK_SUSPEND, &bt_sk(sk)->flags);
a7d7723a
GP
816 else
817 sk->sk_state_change(sk);
0bee1d60
GP
818 } else {
819 err = -EINVAL;
f1cb9af5 820 }
33575df7
GP
821 break;
822
823 case BT_DEFER_SETUP:
824 if (sk->sk_state != BT_BOUND && sk->sk_state != BT_LISTEN) {
825 err = -EINVAL;
826 break;
827 }
828
829 if (get_user(opt, (u32 __user *) optval)) {
830 err = -EFAULT;
831 break;
832 }
833
bdc25783 834 if (opt) {
c5daa683 835 set_bit(BT_SK_DEFER_SETUP, &bt_sk(sk)->flags);
bdc25783
MH
836 set_bit(FLAG_DEFER_SETUP, &chan->flags);
837 } else {
c5daa683 838 clear_bit(BT_SK_DEFER_SETUP, &bt_sk(sk)->flags);
bdc25783
MH
839 clear_bit(FLAG_DEFER_SETUP, &chan->flags);
840 }
33575df7
GP
841 break;
842
843 case BT_FLUSHABLE:
844 if (get_user(opt, (u32 __user *) optval)) {
845 err = -EFAULT;
846 break;
847 }
848
849 if (opt > BT_FLUSHABLE_ON) {
850 err = -EINVAL;
851 break;
852 }
853
854 if (opt == BT_FLUSHABLE_OFF) {
c1f23a2b 855 conn = chan->conn;
25985edc 856 /* proceed further only when we have l2cap_conn and
33575df7
GP
857 No Flush support in the LM */
858 if (!conn || !lmp_no_flush_capable(conn->hcon->hdev)) {
859 err = -EINVAL;
860 break;
861 }
862 }
863
d57b0e8b
AE
864 if (opt)
865 set_bit(FLAG_FLUSHABLE, &chan->flags);
866 else
867 clear_bit(FLAG_FLUSHABLE, &chan->flags);
33575df7
GP
868 break;
869
14b12d0b
JG
870 case BT_POWER:
871 if (chan->chan_type != L2CAP_CHAN_CONN_ORIENTED &&
2d792818 872 chan->chan_type != L2CAP_CHAN_RAW) {
14b12d0b
JG
873 err = -EINVAL;
874 break;
875 }
876
877 pwr.force_active = BT_POWER_FORCE_ACTIVE_ON;
878
879 len = min_t(unsigned int, sizeof(pwr), optlen);
880 if (copy_from_user((char *) &pwr, optval, len)) {
881 err = -EFAULT;
882 break;
883 }
15770b1a
AE
884
885 if (pwr.force_active)
886 set_bit(FLAG_FORCE_ACTIVE, &chan->flags);
887 else
888 clear_bit(FLAG_FORCE_ACTIVE, &chan->flags);
14b12d0b
JG
889 break;
890
2ea66482 891 case BT_CHANNEL_POLICY:
2ea66482
MM
892 if (get_user(opt, (u32 __user *) optval)) {
893 err = -EFAULT;
894 break;
895 }
896
897 if (opt > BT_CHANNEL_POLICY_AMP_PREFERRED) {
898 err = -EINVAL;
899 break;
900 }
901
902 if (chan->mode != L2CAP_MODE_ERTM &&
2d792818 903 chan->mode != L2CAP_MODE_STREAMING) {
2ea66482
MM
904 err = -EOPNOTSUPP;
905 break;
906 }
907
908 chan->chan_policy = (u8) opt;
3f7a56c4
MM
909
910 if (sk->sk_state == BT_CONNECTED &&
911 chan->move_role == L2CAP_MOVE_ROLE_NONE)
912 l2cap_move_start(chan);
913
14b12d0b
JG
914 break;
915
1f435424
JH
916 case BT_SNDMTU:
917 if (!enable_lecoc) {
918 err = -EPROTONOSUPPORT;
919 break;
920 }
921
922 if (!bdaddr_type_is_le(chan->src_type)) {
923 err = -EINVAL;
924 break;
925 }
926
927 /* Setting is not supported as it's the remote side that
928 * decides this.
929 */
930 err = -EPERM;
931 break;
932
933 case BT_RCVMTU:
934 if (!enable_lecoc) {
935 err = -EPROTONOSUPPORT;
936 break;
937 }
938
939 if (!bdaddr_type_is_le(chan->src_type)) {
940 err = -EINVAL;
941 break;
942 }
943
944 if (sk->sk_state == BT_CONNECTED) {
945 err = -EISCONN;
946 break;
947 }
948
949 if (get_user(opt, (u32 __user *) optval)) {
950 err = -EFAULT;
951 break;
952 }
953
954 chan->imtu = opt;
955 break;
956
33575df7
GP
957 default:
958 err = -ENOPROTOOPT;
959 break;
960 }
961
962 release_sock(sk);
963 return err;
964}
fd83ccdb 965
2d792818
GP
966static int l2cap_sock_sendmsg(struct kiocb *iocb, struct socket *sock,
967 struct msghdr *msg, size_t len)
fd83ccdb
GP
968{
969 struct sock *sk = sock->sk;
0c1bc5c6 970 struct l2cap_chan *chan = l2cap_pi(sk)->chan;
fd83ccdb
GP
971 int err;
972
973 BT_DBG("sock %p, sk %p", sock, sk);
974
975 err = sock_error(sk);
976 if (err)
977 return err;
978
979 if (msg->msg_flags & MSG_OOB)
980 return -EOPNOTSUPP;
981
a6a5568c 982 if (sk->sk_state != BT_CONNECTED)
9a91a04a 983 return -ENOTCONN;
fd83ccdb 984
e793dcf0
JH
985 lock_sock(sk);
986 err = bt_sock_wait_ready(sk, msg->msg_flags);
987 release_sock(sk);
988 if (err)
989 return err;
990
a6a5568c 991 l2cap_chan_lock(chan);
5e59b791 992 err = l2cap_chan_send(chan, msg, len, sk->sk_priority);
a6a5568c 993 l2cap_chan_unlock(chan);
fd83ccdb 994
fd83ccdb
GP
995 return err;
996}
33575df7 997
2d792818
GP
998static int l2cap_sock_recvmsg(struct kiocb *iocb, struct socket *sock,
999 struct msghdr *msg, size_t len, int flags)
68983259
GP
1000{
1001 struct sock *sk = sock->sk;
e328140f
MM
1002 struct l2cap_pinfo *pi = l2cap_pi(sk);
1003 int err;
68983259
GP
1004
1005 lock_sock(sk);
1006
c5daa683
GP
1007 if (sk->sk_state == BT_CONNECT2 && test_bit(BT_SK_DEFER_SETUP,
1008 &bt_sk(sk)->flags)) {
38319713
JH
1009 if (bdaddr_type_is_le(pi->chan->src_type)) {
1010 sk->sk_state = BT_CONNECTED;
1011 pi->chan->state = BT_CONNECTED;
1012 __l2cap_le_connect_rsp_defer(pi->chan);
1013 } else {
1014 sk->sk_state = BT_CONFIG;
1015 pi->chan->state = BT_CONFIG;
1016 __l2cap_connect_rsp_defer(pi->chan);
1017 }
8c1d787b 1018
970871bc
JH
1019 err = 0;
1020 goto done;
68983259
GP
1021 }
1022
1023 release_sock(sk);
1024
1025 if (sock->type == SOCK_STREAM)
e328140f
MM
1026 err = bt_sock_stream_recvmsg(iocb, sock, msg, len, flags);
1027 else
1028 err = bt_sock_recvmsg(iocb, sock, msg, len, flags);
1029
1030 if (pi->chan->mode != L2CAP_MODE_ERTM)
1031 return err;
1032
1033 /* Attempt to put pending rx data in the socket buffer */
1034
1035 lock_sock(sk);
1036
1037 if (!test_bit(CONN_LOCAL_BUSY, &pi->chan->conn_state))
1038 goto done;
1039
1040 if (pi->rx_busy_skb) {
1041 if (!sock_queue_rcv_skb(sk, pi->rx_busy_skb))
1042 pi->rx_busy_skb = NULL;
1043 else
1044 goto done;
1045 }
1046
1047 /* Restore data flow when half of the receive buffer is
1048 * available. This avoids resending large numbers of
1049 * frames.
1050 */
1051 if (atomic_read(&sk->sk_rmem_alloc) <= sk->sk_rcvbuf >> 1)
1052 l2cap_chan_busy(pi->chan, 0);
68983259 1053
e328140f
MM
1054done:
1055 release_sock(sk);
1056 return err;
68983259
GP
1057}
1058
05fc1576
GP
1059/* Kill socket (only if zapped and orphan)
1060 * Must be called on unlocked socket.
1061 */
ba3bd0ee 1062static void l2cap_sock_kill(struct sock *sk)
05fc1576
GP
1063{
1064 if (!sock_flag(sk, SOCK_ZAPPED) || sk->sk_socket)
1065 return;
1066
e05dcc32 1067 BT_DBG("sk %p state %s", sk, state_to_string(sk->sk_state));
05fc1576
GP
1068
1069 /* Kill poor orphan */
6ff5abbf 1070
4af66c69 1071 l2cap_chan_put(l2cap_pi(sk)->chan);
05fc1576
GP
1072 sock_set_flag(sk, SOCK_DEAD);
1073 sock_put(sk);
1074}
1075
dc25306b
GP
1076static int __l2cap_wait_ack(struct sock *sk)
1077{
1078 struct l2cap_chan *chan = l2cap_pi(sk)->chan;
1079 DECLARE_WAITQUEUE(wait, current);
1080 int err = 0;
1081 int timeo = HZ/5;
1082
1083 add_wait_queue(sk_sleep(sk), &wait);
1084 set_current_state(TASK_INTERRUPTIBLE);
1085 while (chan->unacked_frames > 0 && chan->conn) {
1086 if (!timeo)
1087 timeo = HZ/5;
1088
1089 if (signal_pending(current)) {
1090 err = sock_intr_errno(timeo);
1091 break;
1092 }
1093
1094 release_sock(sk);
1095 timeo = schedule_timeout(timeo);
1096 lock_sock(sk);
1097 set_current_state(TASK_INTERRUPTIBLE);
1098
1099 err = sock_error(sk);
1100 if (err)
1101 break;
1102 }
1103 set_current_state(TASK_RUNNING);
1104 remove_wait_queue(sk_sleep(sk), &wait);
1105 return err;
1106}
1107
dcba0dba
GP
1108static int l2cap_sock_shutdown(struct socket *sock, int how)
1109{
1110 struct sock *sk = sock->sk;
7ddb6e0f 1111 struct l2cap_chan *chan;
3df91ea2 1112 struct l2cap_conn *conn;
dcba0dba
GP
1113 int err = 0;
1114
1115 BT_DBG("sock %p, sk %p", sock, sk);
1116
1117 if (!sk)
1118 return 0;
1119
7ddb6e0f 1120 chan = l2cap_pi(sk)->chan;
3df91ea2
AE
1121 conn = chan->conn;
1122
1123 if (conn)
1124 mutex_lock(&conn->chan_lock);
7ddb6e0f 1125
6be36555 1126 l2cap_chan_lock(chan);
dcba0dba 1127 lock_sock(sk);
6be36555 1128
dcba0dba 1129 if (!sk->sk_shutdown) {
0c1bc5c6 1130 if (chan->mode == L2CAP_MODE_ERTM)
dcba0dba
GP
1131 err = __l2cap_wait_ack(sk);
1132
1133 sk->sk_shutdown = SHUTDOWN_MASK;
3df91ea2 1134
6be36555 1135 release_sock(sk);
0f852724 1136 l2cap_chan_close(chan, 0);
6be36555 1137 lock_sock(sk);
dcba0dba
GP
1138
1139 if (sock_flag(sk, SOCK_LINGER) && sk->sk_lingertime)
1140 err = bt_sock_wait_state(sk, BT_CLOSED,
2d792818 1141 sk->sk_lingertime);
dcba0dba
GP
1142 }
1143
1144 if (!err && sk->sk_err)
1145 err = -sk->sk_err;
1146
1147 release_sock(sk);
6be36555 1148 l2cap_chan_unlock(chan);
3df91ea2
AE
1149
1150 if (conn)
1151 mutex_unlock(&conn->chan_lock);
1152
dcba0dba
GP
1153 return err;
1154}
1155
554f05bb
GP
1156static int l2cap_sock_release(struct socket *sock)
1157{
1158 struct sock *sk = sock->sk;
1159 int err;
1160
1161 BT_DBG("sock %p, sk %p", sock, sk);
1162
1163 if (!sk)
1164 return 0;
1165
5b28d95c
MY
1166 bt_sock_unlink(&l2cap_sk_list, sk);
1167
554f05bb
GP
1168 err = l2cap_sock_shutdown(sock, 2);
1169
1170 sock_orphan(sk);
1171 l2cap_sock_kill(sk);
1172 return err;
1173}
1174
c0df7f6e
AE
1175static void l2cap_sock_cleanup_listen(struct sock *parent)
1176{
1177 struct sock *sk;
1178
1179 BT_DBG("parent %p", parent);
1180
1181 /* Close not yet accepted channels */
1182 while ((sk = bt_accept_dequeue(parent, NULL))) {
1183 struct l2cap_chan *chan = l2cap_pi(sk)->chan;
1184
1185 l2cap_chan_lock(chan);
1186 __clear_chan_timer(chan);
1187 l2cap_chan_close(chan, ECONNRESET);
1188 l2cap_chan_unlock(chan);
1189
1190 l2cap_sock_kill(sk);
1191 }
1192}
1193
80b98027 1194static struct l2cap_chan *l2cap_sock_new_connection_cb(struct l2cap_chan *chan)
80808e43 1195{
80b98027 1196 struct sock *sk, *parent = chan->data;
80808e43 1197
8ffb9290
GP
1198 lock_sock(parent);
1199
53826692
GP
1200 /* Check for backlog size */
1201 if (sk_acceptq_is_full(parent)) {
1202 BT_DBG("backlog full %d", parent->sk_ack_backlog);
1203 return NULL;
1204 }
1205
80808e43 1206 sk = l2cap_sock_alloc(sock_net(parent), NULL, BTPROTO_L2CAP,
2d792818 1207 GFP_ATOMIC);
80808e43
GP
1208 if (!sk)
1209 return NULL;
1210
d22015aa
OP
1211 bt_sock_reclassify_lock(sk, BTPROTO_L2CAP);
1212
80808e43
GP
1213 l2cap_sock_init(sk, parent);
1214
644912e1
GP
1215 bt_accept_enqueue(parent, sk);
1216
8ffb9290
GP
1217 release_sock(parent);
1218
80808e43
GP
1219 return l2cap_pi(sk)->chan;
1220}
1221
80b98027 1222static int l2cap_sock_recv_cb(struct l2cap_chan *chan, struct sk_buff *skb)
23070494 1223{
80b98027 1224 struct sock *sk = chan->data;
84b34d98 1225 int err;
e328140f 1226
6be36555
AE
1227 lock_sock(sk);
1228
84b34d98 1229 if (l2cap_pi(sk)->rx_busy_skb) {
6be36555
AE
1230 err = -ENOMEM;
1231 goto done;
1232 }
e328140f
MM
1233
1234 err = sock_queue_rcv_skb(sk, skb);
1235
1236 /* For ERTM, handle one skb that doesn't fit into the recv
1237 * buffer. This is important to do because the data frames
1238 * have already been acked, so the skb cannot be discarded.
1239 *
1240 * Notify the l2cap core that the buffer is full, so the
1241 * LOCAL_BUSY state is entered and no more frames are
1242 * acked and reassembled until there is buffer space
1243 * available.
1244 */
84b34d98
MH
1245 if (err < 0 && chan->mode == L2CAP_MODE_ERTM) {
1246 l2cap_pi(sk)->rx_busy_skb = skb;
1247 l2cap_chan_busy(chan, 1);
e328140f
MM
1248 err = 0;
1249 }
23070494 1250
6be36555
AE
1251done:
1252 release_sock(sk);
1253
e328140f 1254 return err;
23070494
GP
1255}
1256
80b98027 1257static void l2cap_sock_close_cb(struct l2cap_chan *chan)
ba3bd0ee 1258{
80b98027 1259 struct sock *sk = chan->data;
ba3bd0ee
GP
1260
1261 l2cap_sock_kill(sk);
1262}
1263
c0df7f6e
AE
1264static void l2cap_sock_teardown_cb(struct l2cap_chan *chan, int err)
1265{
1266 struct sock *sk = chan->data;
1267 struct sock *parent;
1268
1269 lock_sock(sk);
1270
1271 parent = bt_sk(sk)->parent;
1272
1273 sock_set_flag(sk, SOCK_ZAPPED);
1274
1275 switch (chan->state) {
1276 case BT_OPEN:
1277 case BT_BOUND:
1278 case BT_CLOSED:
1279 break;
1280 case BT_LISTEN:
1281 l2cap_sock_cleanup_listen(sk);
1282 sk->sk_state = BT_CLOSED;
1283 chan->state = BT_CLOSED;
1284
1285 break;
1286 default:
1287 sk->sk_state = BT_CLOSED;
1288 chan->state = BT_CLOSED;
1289
1290 sk->sk_err = err;
1291
1292 if (parent) {
1293 bt_accept_unlink(sk);
1294 parent->sk_data_ready(parent, 0);
1295 } else {
1296 sk->sk_state_change(sk);
1297 }
1298
1299 break;
1300 }
1301
1302 release_sock(sk);
1303}
1304
53f52121
GP
1305static void l2cap_sock_state_change_cb(struct l2cap_chan *chan, int state,
1306 int err)
89bc500e 1307{
80b98027 1308 struct sock *sk = chan->data;
89bc500e
GP
1309
1310 sk->sk_state = state;
53f52121
GP
1311
1312 if (err)
1313 sk->sk_err = err;
89bc500e
GP
1314}
1315
2f7719ce 1316static struct sk_buff *l2cap_sock_alloc_skb_cb(struct l2cap_chan *chan,
90338947 1317 unsigned long len, int nb)
2f7719ce 1318{
0f2c6153 1319 struct sock *sk = chan->data;
90338947
GP
1320 struct sk_buff *skb;
1321 int err;
1322
a6a5568c 1323 l2cap_chan_unlock(chan);
0f2c6153 1324 skb = bt_skb_send_alloc(sk, len, nb, &err);
a6a5568c
MM
1325 l2cap_chan_lock(chan);
1326
90338947
GP
1327 if (!skb)
1328 return ERR_PTR(err);
2f7719ce 1329
0e790c64
GP
1330 bt_cb(skb)->chan = chan;
1331
90338947 1332 return skb;
2f7719ce
AE
1333}
1334
54a59aa2
AE
1335static void l2cap_sock_ready_cb(struct l2cap_chan *chan)
1336{
1337 struct sock *sk = chan->data;
1338 struct sock *parent;
1339
1340 lock_sock(sk);
1341
1342 parent = bt_sk(sk)->parent;
1343
1344 BT_DBG("sk %p, parent %p", sk, parent);
1345
1346 sk->sk_state = BT_CONNECTED;
1347 sk->sk_state_change(sk);
1348
1349 if (parent)
1350 parent->sk_data_ready(parent, 0);
1351
1352 release_sock(sk);
1353}
1354
2dc4e510
GP
1355static void l2cap_sock_defer_cb(struct l2cap_chan *chan)
1356{
acdcabf5
GP
1357 struct sock *parent, *sk = chan->data;
1358
1359 lock_sock(sk);
2dc4e510 1360
acdcabf5 1361 parent = bt_sk(sk)->parent;
2dc4e510
GP
1362 if (parent)
1363 parent->sk_data_ready(parent, 0);
acdcabf5
GP
1364
1365 release_sock(sk);
2dc4e510
GP
1366}
1367
d97c899b
MH
1368static void l2cap_sock_resume_cb(struct l2cap_chan *chan)
1369{
1370 struct sock *sk = chan->data;
1371
1372 clear_bit(BT_SK_SUSPEND, &bt_sk(sk)->flags);
1373 sk->sk_state_change(sk);
1374}
1375
5ec1bbe5
GP
1376static void l2cap_sock_set_shutdown_cb(struct l2cap_chan *chan)
1377{
1378 struct sock *sk = chan->data;
1379
1380 lock_sock(sk);
1381 sk->sk_shutdown = SHUTDOWN_MASK;
1382 release_sock(sk);
1383}
1384
8d836d71
GP
1385static long l2cap_sock_get_sndtimeo_cb(struct l2cap_chan *chan)
1386{
1387 struct sock *sk = chan->data;
1388
1389 return sk->sk_sndtimeo;
1390}
1391
837776f7
JH
1392static void l2cap_sock_suspend_cb(struct l2cap_chan *chan)
1393{
1394 struct sock *sk = chan->data;
1395
1396 set_bit(BT_SK_SUSPEND, &bt_sk(sk)->flags);
1397 sk->sk_state_change(sk);
1398}
1399
80808e43
GP
1400static struct l2cap_ops l2cap_chan_ops = {
1401 .name = "L2CAP Socket Interface",
1402 .new_connection = l2cap_sock_new_connection_cb,
23070494 1403 .recv = l2cap_sock_recv_cb,
ba3bd0ee 1404 .close = l2cap_sock_close_cb,
c0df7f6e 1405 .teardown = l2cap_sock_teardown_cb,
89bc500e 1406 .state_change = l2cap_sock_state_change_cb,
54a59aa2 1407 .ready = l2cap_sock_ready_cb,
2dc4e510 1408 .defer = l2cap_sock_defer_cb,
d97c899b 1409 .resume = l2cap_sock_resume_cb,
837776f7 1410 .suspend = l2cap_sock_suspend_cb,
5ec1bbe5 1411 .set_shutdown = l2cap_sock_set_shutdown_cb,
8d836d71 1412 .get_sndtimeo = l2cap_sock_get_sndtimeo_cb,
2f7719ce 1413 .alloc_skb = l2cap_sock_alloc_skb_cb,
80808e43
GP
1414};
1415
bb58f747
GP
1416static void l2cap_sock_destruct(struct sock *sk)
1417{
1418 BT_DBG("sk %p", sk);
1419
23d3a869
SL
1420 if (l2cap_pi(sk)->chan)
1421 l2cap_chan_put(l2cap_pi(sk)->chan);
84b34d98 1422
e328140f
MM
1423 if (l2cap_pi(sk)->rx_busy_skb) {
1424 kfree_skb(l2cap_pi(sk)->rx_busy_skb);
1425 l2cap_pi(sk)->rx_busy_skb = NULL;
1426 }
1427
bb58f747
GP
1428 skb_queue_purge(&sk->sk_receive_queue);
1429 skb_queue_purge(&sk->sk_write_queue);
1430}
1431
2edf870d
MH
1432static void l2cap_skb_msg_name(struct sk_buff *skb, void *msg_name,
1433 int *msg_namelen)
1434{
342dfc30 1435 DECLARE_SOCKADDR(struct sockaddr_l2 *, la, msg_name);
2edf870d
MH
1436
1437 memset(la, 0, sizeof(struct sockaddr_l2));
1438 la->l2_family = AF_BLUETOOTH;
1439 la->l2_psm = bt_cb(skb)->psm;
1440 bacpy(&la->l2_bdaddr, &bt_cb(skb)->bdaddr);
1441
1442 *msg_namelen = sizeof(struct sockaddr_l2);
1443}
1444
80808e43 1445static void l2cap_sock_init(struct sock *sk, struct sock *parent)
bb58f747 1446{
84b34d98 1447 struct l2cap_chan *chan = l2cap_pi(sk)->chan;
bb58f747
GP
1448
1449 BT_DBG("sk %p", sk);
1450
1451 if (parent) {
b4450035
GP
1452 struct l2cap_chan *pchan = l2cap_pi(parent)->chan;
1453
bb58f747 1454 sk->sk_type = parent->sk_type;
c5daa683 1455 bt_sk(sk)->flags = bt_sk(parent)->flags;
bb58f747 1456
715ec005 1457 chan->chan_type = pchan->chan_type;
0c1bc5c6
GP
1458 chan->imtu = pchan->imtu;
1459 chan->omtu = pchan->omtu;
b4450035 1460 chan->conf_state = pchan->conf_state;
0c1bc5c6 1461 chan->mode = pchan->mode;
47d1ec61
GP
1462 chan->fcs = pchan->fcs;
1463 chan->max_tx = pchan->max_tx;
1464 chan->tx_win = pchan->tx_win;
6b3c7104 1465 chan->tx_win_max = pchan->tx_win_max;
4343478f 1466 chan->sec_level = pchan->sec_level;
d57b0e8b 1467 chan->flags = pchan->flags;
0cd75f7e
JH
1468 chan->tx_credits = pchan->tx_credits;
1469 chan->rx_credits = pchan->rx_credits;
6230c9b4
PM
1470
1471 security_sk_clone(parent, sk);
bb58f747 1472 } else {
715ec005
GP
1473 switch (sk->sk_type) {
1474 case SOCK_RAW:
1475 chan->chan_type = L2CAP_CHAN_RAW;
1476 break;
1477 case SOCK_DGRAM:
1478 chan->chan_type = L2CAP_CHAN_CONN_LESS;
2edf870d 1479 bt_sk(sk)->skb_msg_name = l2cap_skb_msg_name;
715ec005
GP
1480 break;
1481 case SOCK_SEQPACKET:
1482 case SOCK_STREAM:
1483 chan->chan_type = L2CAP_CHAN_CONN_ORIENTED;
1484 break;
1485 }
1486
0c1bc5c6
GP
1487 chan->imtu = L2CAP_DEFAULT_MTU;
1488 chan->omtu = 0;
bb58f747 1489 if (!disable_ertm && sk->sk_type == SOCK_STREAM) {
0c1bc5c6 1490 chan->mode = L2CAP_MODE_ERTM;
c1360a1c 1491 set_bit(CONF_STATE2_DEVICE, &chan->conf_state);
bb58f747 1492 } else {
0c1bc5c6 1493 chan->mode = L2CAP_MODE_BASIC;
bb58f747 1494 }
bd4b1653
AE
1495
1496 l2cap_chan_set_defaults(chan);
bb58f747
GP
1497 }
1498
1499 /* Default config options */
0c1bc5c6 1500 chan->flush_to = L2CAP_DEFAULT_FLUSH_TO;
80808e43
GP
1501
1502 chan->data = sk;
1503 chan->ops = &l2cap_chan_ops;
bb58f747
GP
1504}
1505
1506static struct proto l2cap_proto = {
1507 .name = "L2CAP",
1508 .owner = THIS_MODULE,
1509 .obj_size = sizeof(struct l2cap_pinfo)
1510};
1511
2d792818
GP
1512static struct sock *l2cap_sock_alloc(struct net *net, struct socket *sock,
1513 int proto, gfp_t prio)
bb58f747
GP
1514{
1515 struct sock *sk;
dc50a06d 1516 struct l2cap_chan *chan;
bb58f747
GP
1517
1518 sk = sk_alloc(net, PF_BLUETOOTH, prio, &l2cap_proto);
1519 if (!sk)
1520 return NULL;
1521
1522 sock_init_data(sock, sk);
1523 INIT_LIST_HEAD(&bt_sk(sk)->accept_q);
1524
1525 sk->sk_destruct = l2cap_sock_destruct;
ba13ccd9 1526 sk->sk_sndtimeo = L2CAP_CONN_TIMEOUT;
bb58f747
GP
1527
1528 sock_reset_flag(sk, SOCK_ZAPPED);
1529
1530 sk->sk_protocol = proto;
1531 sk->sk_state = BT_OPEN;
1532
eef1d9b6 1533 chan = l2cap_chan_create();
dc50a06d 1534 if (!chan) {
49dfbb91 1535 sk_free(sk);
dc50a06d
GP
1536 return NULL;
1537 }
1538
61d6ef3e
MM
1539 l2cap_chan_hold(chan);
1540
dc50a06d
GP
1541 l2cap_pi(sk)->chan = chan;
1542
bb58f747
GP
1543 return sk;
1544}
1545
1546static int l2cap_sock_create(struct net *net, struct socket *sock, int protocol,
1547 int kern)
1548{
1549 struct sock *sk;
1550
1551 BT_DBG("sock %p", sock);
1552
1553 sock->state = SS_UNCONNECTED;
1554
1555 if (sock->type != SOCK_SEQPACKET && sock->type != SOCK_STREAM &&
2d792818 1556 sock->type != SOCK_DGRAM && sock->type != SOCK_RAW)
bb58f747
GP
1557 return -ESOCKTNOSUPPORT;
1558
1559 if (sock->type == SOCK_RAW && !kern && !capable(CAP_NET_RAW))
1560 return -EPERM;
1561
1562 sock->ops = &l2cap_sock_ops;
1563
1564 sk = l2cap_sock_alloc(net, sock, protocol, GFP_ATOMIC);
1565 if (!sk)
1566 return -ENOMEM;
1567
1568 l2cap_sock_init(sk, NULL);
5b28d95c 1569 bt_sock_link(&l2cap_sk_list, sk);
bb58f747
GP
1570 return 0;
1571}
1572
cf2f90f5 1573static const struct proto_ops l2cap_sock_ops = {
65390587
GP
1574 .family = PF_BLUETOOTH,
1575 .owner = THIS_MODULE,
1576 .release = l2cap_sock_release,
1577 .bind = l2cap_sock_bind,
1578 .connect = l2cap_sock_connect,
1579 .listen = l2cap_sock_listen,
1580 .accept = l2cap_sock_accept,
1581 .getname = l2cap_sock_getname,
1582 .sendmsg = l2cap_sock_sendmsg,
1583 .recvmsg = l2cap_sock_recvmsg,
1584 .poll = bt_sock_poll,
1585 .ioctl = bt_sock_ioctl,
1586 .mmap = sock_no_mmap,
1587 .socketpair = sock_no_socketpair,
1588 .shutdown = l2cap_sock_shutdown,
1589 .setsockopt = l2cap_sock_setsockopt,
1590 .getsockopt = l2cap_sock_getsockopt
1591};
1592
bb58f747
GP
1593static const struct net_proto_family l2cap_sock_family_ops = {
1594 .family = PF_BLUETOOTH,
1595 .owner = THIS_MODULE,
1596 .create = l2cap_sock_create,
1597};
1598
1599int __init l2cap_init_sockets(void)
1600{
e2174ca4 1601 int err;
bb58f747 1602
e2174ca4
GP
1603 err = proto_register(&l2cap_proto, 0);
1604 if (err < 0)
1605 return err;
bb58f747 1606
e2174ca4 1607 err = bt_sock_register(BTPROTO_L2CAP, &l2cap_sock_family_ops);
5b28d95c
MY
1608 if (err < 0) {
1609 BT_ERR("L2CAP socket registration failed");
e2174ca4 1610 goto error;
5b28d95c
MY
1611 }
1612
b0316615 1613 err = bt_procfs_init(&init_net, "l2cap", &l2cap_sk_list,
2d792818 1614 NULL);
5b28d95c
MY
1615 if (err < 0) {
1616 BT_ERR("Failed to create L2CAP proc file");
1617 bt_sock_unregister(BTPROTO_L2CAP);
1618 goto error;
1619 }
bb58f747 1620
e2174ca4 1621 BT_INFO("L2CAP socket layer initialized");
bb58f747 1622
e2174ca4 1623 return 0;
bb58f747
GP
1624
1625error:
e2174ca4
GP
1626 proto_unregister(&l2cap_proto);
1627 return err;
bb58f747
GP
1628}
1629
1630void l2cap_cleanup_sockets(void)
1631{
5b28d95c 1632 bt_procfs_cleanup(&init_net, "l2cap");
5e9d7f86 1633 bt_sock_unregister(BTPROTO_L2CAP);
e2174ca4 1634 proto_unregister(&l2cap_proto);
bb58f747 1635}
9149761a
JH
1636
1637module_param(enable_lecoc, bool, 0644);
1638MODULE_PARM_DESC(enable_lecoc, "Enable support for LE CoC");
This page took 0.260953 seconds and 5 git commands to generate.