Bluetooth: Add debugfs controls for LE CoC MPS and Credits
[deliverable/linux.git] / net / bluetooth / l2cap_sock.c
CommitLineData
bb58f747
GP
1/*
2 BlueZ - Bluetooth protocol stack for Linux
3 Copyright (C) 2000-2001 Qualcomm Incorporated
4 Copyright (C) 2009-2010 Gustavo F. Padovan <gustavo@padovan.org>
5 Copyright (C) 2010 Google Inc.
590051de 6 Copyright (C) 2011 ProFUSION Embedded Systems
bb58f747
GP
7
8 Written 2000,2001 by Maxim Krasnyansky <maxk@qualcomm.com>
9
10 This program is free software; you can redistribute it and/or modify
11 it under the terms of the GNU General Public License version 2 as
12 published by the Free Software Foundation;
13
14 THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS
15 OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
16 FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT OF THIRD PARTY RIGHTS.
17 IN NO EVENT SHALL THE COPYRIGHT HOLDER(S) AND AUTHOR(S) BE LIABLE FOR ANY
18 CLAIM, OR ANY SPECIAL INDIRECT OR CONSEQUENTIAL DAMAGES, OR ANY DAMAGES
19 WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
20 ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
21 OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
22
23 ALL LIABILITY, INCLUDING LIABILITY FOR INFRINGEMENT OF ANY PATENTS,
24 COPYRIGHTS, TRADEMARKS OR OTHER RIGHTS, RELATING TO USE OF THIS
25 SOFTWARE IS DISCLAIMED.
26*/
27
28/* Bluetooth L2CAP sockets. */
29
9149761a 30#include <linux/module.h>
bc3b2d7f 31#include <linux/export.h>
6230c9b4 32
bb58f747 33#include <net/bluetooth/bluetooth.h>
33575df7 34#include <net/bluetooth/hci_core.h>
bb58f747 35#include <net/bluetooth/l2cap.h>
ac4b7236
MH
36
37#include "smp.h"
bb58f747 38
9149761a
JH
39bool enable_lecoc;
40
5b28d95c
MY
41static struct bt_sock_list l2cap_sk_list = {
42 .lock = __RW_LOCK_UNLOCKED(l2cap_sk_list.lock)
43};
44
cf2f90f5 45static const struct proto_ops l2cap_sock_ops;
80808e43 46static void l2cap_sock_init(struct sock *sk, struct sock *parent);
2d792818
GP
47static struct sock *l2cap_sock_alloc(struct net *net, struct socket *sock,
48 int proto, gfp_t prio);
cf2f90f5 49
b3916db3
DH
50bool l2cap_is_socket(struct socket *sock)
51{
52 return sock && sock->ops == &l2cap_sock_ops;
53}
54EXPORT_SYMBOL(l2cap_is_socket);
55
4946096d
JH
56static int l2cap_validate_bredr_psm(u16 psm)
57{
58 /* PSM must be odd and lsb of upper byte must be 0 */
59 if ((psm & 0x0101) != 0x0001)
60 return -EINVAL;
61
62 /* Restrict usage of well-known PSMs */
63 if (psm < 0x1001 && !capable(CAP_NET_BIND_SERVICE))
64 return -EACCES;
65
66 return 0;
67}
68
69static int l2cap_validate_le_psm(u16 psm)
70{
71 /* Valid LE_PSM ranges are defined only until 0x00ff */
72 if (psm > 0x00ff)
73 return -EINVAL;
74
75 /* Restrict fixed, SIG assigned PSM values to CAP_NET_BIND_SERVICE */
76 if (psm <= 0x007f && !capable(CAP_NET_BIND_SERVICE))
77 return -EACCES;
78
79 return 0;
80}
81
af6bcd82
GP
82static int l2cap_sock_bind(struct socket *sock, struct sockaddr *addr, int alen)
83{
84 struct sock *sk = sock->sk;
4343478f 85 struct l2cap_chan *chan = l2cap_pi(sk)->chan;
af6bcd82
GP
86 struct sockaddr_l2 la;
87 int len, err = 0;
88
89 BT_DBG("sk %p", sk);
90
91 if (!addr || addr->sa_family != AF_BLUETOOTH)
92 return -EINVAL;
93
94 memset(&la, 0, sizeof(la));
95 len = min_t(unsigned int, sizeof(la), alen);
96 memcpy(&la, addr, len);
97
b62f328b 98 if (la.l2_cid && la.l2_psm)
af6bcd82
GP
99 return -EINVAL;
100
80c1a2e7
JH
101 if (!bdaddr_type_is_valid(la.l2_bdaddr_type))
102 return -EINVAL;
103
bfe4655f 104 if (bdaddr_type_is_le(la.l2_bdaddr_type)) {
9149761a 105 if (!enable_lecoc && la.l2_psm)
bfe4655f
JH
106 return -EINVAL;
107 /* We only allow ATT user space socket */
9149761a
JH
108 if (la.l2_cid &&
109 la.l2_cid != __constant_cpu_to_le16(L2CAP_CID_ATT))
bfe4655f
JH
110 return -EINVAL;
111 }
112
af6bcd82
GP
113 lock_sock(sk);
114
115 if (sk->sk_state != BT_OPEN) {
116 err = -EBADFD;
117 goto done;
118 }
119
120 if (la.l2_psm) {
121 __u16 psm = __le16_to_cpu(la.l2_psm);
122
4946096d
JH
123 if (la.l2_bdaddr_type == BDADDR_BREDR)
124 err = l2cap_validate_bredr_psm(psm);
125 else
126 err = l2cap_validate_le_psm(psm);
af6bcd82 127
4946096d 128 if (err)
af6bcd82 129 goto done;
af6bcd82
GP
130 }
131
9e4425ff 132 if (la.l2_cid)
6e4aff10 133 err = l2cap_add_scid(chan, __le16_to_cpu(la.l2_cid));
9e4425ff
GP
134 else
135 err = l2cap_add_psm(chan, &la.l2_bdaddr, la.l2_psm);
af6bcd82 136
9e4425ff
GP
137 if (err < 0)
138 goto done;
af6bcd82 139
6a974b50 140 switch (chan->chan_type) {
3124b843
MH
141 case L2CAP_CHAN_CONN_LESS:
142 if (__le16_to_cpu(la.l2_psm) == L2CAP_PSM_3DSP)
143 chan->sec_level = BT_SECURITY_SDP;
144 break;
6a974b50
MH
145 case L2CAP_CHAN_CONN_ORIENTED:
146 if (__le16_to_cpu(la.l2_psm) == L2CAP_PSM_SDP ||
147 __le16_to_cpu(la.l2_psm) == L2CAP_PSM_RFCOMM)
148 chan->sec_level = BT_SECURITY_SDP;
149 break;
150 }
b62f328b 151
7eafc59e 152 bacpy(&chan->src, &la.l2_bdaddr);
4f1654e0 153 chan->src_type = la.l2_bdaddr_type;
89bc500e 154
38319713
JH
155 if (chan->psm && bdaddr_type_is_le(chan->src_type))
156 l2cap_le_flowctl_init(chan);
157
89bc500e 158 chan->state = BT_BOUND;
9e4425ff 159 sk->sk_state = BT_BOUND;
af6bcd82
GP
160
161done:
162 release_sock(sk);
163 return err;
164}
165
2d792818
GP
166static int l2cap_sock_connect(struct socket *sock, struct sockaddr *addr,
167 int alen, int flags)
4e34c50b
GP
168{
169 struct sock *sk = sock->sk;
0c1bc5c6 170 struct l2cap_chan *chan = l2cap_pi(sk)->chan;
4e34c50b
GP
171 struct sockaddr_l2 la;
172 int len, err = 0;
173
174 BT_DBG("sk %p", sk);
175
176 if (!addr || alen < sizeof(addr->sa_family) ||
177 addr->sa_family != AF_BLUETOOTH)
178 return -EINVAL;
179
180 memset(&la, 0, sizeof(la));
181 len = min_t(unsigned int, sizeof(la), alen);
182 memcpy(&la, addr, len);
183
acd7d370 184 if (la.l2_cid && la.l2_psm)
4e34c50b
GP
185 return -EINVAL;
186
80c1a2e7
JH
187 if (!bdaddr_type_is_valid(la.l2_bdaddr_type))
188 return -EINVAL;
189
eb622495
JH
190 /* Check that the socket wasn't bound to something that
191 * conflicts with the address given to connect(). If chan->src
192 * is BDADDR_ANY it means bind() was never used, in which case
193 * chan->src_type and la.l2_bdaddr_type do not need to match.
194 */
195 if (chan->src_type == BDADDR_BREDR && bacmp(&chan->src, BDADDR_ANY) &&
196 bdaddr_type_is_le(la.l2_bdaddr_type)) {
197 /* Old user space versions will try to incorrectly bind
198 * the ATT socket using BDADDR_BREDR. We need to accept
199 * this and fix up the source address type only when
200 * both the source CID and destination CID indicate
201 * ATT. Anything else is an invalid combination.
202 */
203 if (chan->scid != L2CAP_CID_ATT ||
204 la.l2_cid != __constant_cpu_to_le16(L2CAP_CID_ATT))
205 return -EINVAL;
206
207 /* We don't have the hdev available here to make a
208 * better decision on random vs public, but since all
209 * user space versions that exhibit this issue anyway do
210 * not support random local addresses assuming public
211 * here is good enough.
212 */
213 chan->src_type = BDADDR_LE_PUBLIC;
214 }
1f209383
JH
215
216 if (chan->src_type != BDADDR_BREDR && la.l2_bdaddr_type == BDADDR_BREDR)
217 return -EINVAL;
218
bfe4655f 219 if (bdaddr_type_is_le(la.l2_bdaddr_type)) {
9149761a 220 if (!enable_lecoc && la.l2_psm)
bfe4655f
JH
221 return -EINVAL;
222 /* We only allow ATT user space socket */
9149761a
JH
223 if (la.l2_cid &&
224 la.l2_cid != __constant_cpu_to_le16(L2CAP_CID_ATT))
bfe4655f
JH
225 return -EINVAL;
226 }
227
38319713
JH
228 if (chan->psm && bdaddr_type_is_le(chan->src_type))
229 l2cap_le_flowctl_init(chan);
230
6e4aff10 231 err = l2cap_chan_connect(chan, la.l2_psm, __le16_to_cpu(la.l2_cid),
8e9f9892 232 &la.l2_bdaddr, la.l2_bdaddr_type);
4e34c50b 233 if (err)
b3fb611e 234 return err;
4e34c50b 235
6be36555
AE
236 lock_sock(sk);
237
4e34c50b 238 err = bt_sock_wait_state(sk, BT_CONNECTED,
2d792818 239 sock_sndtimeo(sk, flags & O_NONBLOCK));
b3fb611e
AE
240
241 release_sock(sk);
242
4e34c50b
GP
243 return err;
244}
245
af6bcd82
GP
246static int l2cap_sock_listen(struct socket *sock, int backlog)
247{
248 struct sock *sk = sock->sk;
0c1bc5c6 249 struct l2cap_chan *chan = l2cap_pi(sk)->chan;
af6bcd82
GP
250 int err = 0;
251
252 BT_DBG("sk %p backlog %d", sk, backlog);
253
254 lock_sock(sk);
255
6b3af733 256 if (sk->sk_state != BT_BOUND) {
af6bcd82
GP
257 err = -EBADFD;
258 goto done;
259 }
260
6b3af733
MH
261 if (sk->sk_type != SOCK_SEQPACKET && sk->sk_type != SOCK_STREAM) {
262 err = -EINVAL;
263 goto done;
264 }
265
0c1bc5c6 266 switch (chan->mode) {
af6bcd82 267 case L2CAP_MODE_BASIC:
38319713 268 case L2CAP_MODE_LE_FLOWCTL:
af6bcd82
GP
269 break;
270 case L2CAP_MODE_ERTM:
271 case L2CAP_MODE_STREAMING:
272 if (!disable_ertm)
273 break;
274 /* fall through */
275 default:
276 err = -ENOTSUPP;
277 goto done;
278 }
279
af6bcd82
GP
280 sk->sk_max_ack_backlog = backlog;
281 sk->sk_ack_backlog = 0;
89bc500e
GP
282
283 chan->state = BT_LISTEN;
af6bcd82
GP
284 sk->sk_state = BT_LISTEN;
285
286done:
287 release_sock(sk);
288 return err;
289}
290
2d792818
GP
291static int l2cap_sock_accept(struct socket *sock, struct socket *newsock,
292 int flags)
c47b7c72
GP
293{
294 DECLARE_WAITQUEUE(wait, current);
295 struct sock *sk = sock->sk, *nsk;
296 long timeo;
297 int err = 0;
298
299 lock_sock_nested(sk, SINGLE_DEPTH_NESTING);
300
c47b7c72
GP
301 timeo = sock_rcvtimeo(sk, flags & O_NONBLOCK);
302
303 BT_DBG("sk %p timeo %ld", sk, timeo);
304
305 /* Wait for an incoming connection. (wake-one). */
306 add_wait_queue_exclusive(sk_sleep(sk), &wait);
f9a3c20a 307 while (1) {
c47b7c72 308 set_current_state(TASK_INTERRUPTIBLE);
f9a3c20a
PH
309
310 if (sk->sk_state != BT_LISTEN) {
311 err = -EBADFD;
c47b7c72
GP
312 break;
313 }
314
f9a3c20a
PH
315 nsk = bt_accept_dequeue(sk, newsock);
316 if (nsk)
317 break;
c47b7c72 318
f9a3c20a
PH
319 if (!timeo) {
320 err = -EAGAIN;
c47b7c72
GP
321 break;
322 }
323
324 if (signal_pending(current)) {
325 err = sock_intr_errno(timeo);
326 break;
327 }
f9a3c20a
PH
328
329 release_sock(sk);
330 timeo = schedule_timeout(timeo);
331 lock_sock_nested(sk, SINGLE_DEPTH_NESTING);
c47b7c72 332 }
f9a3c20a 333 __set_current_state(TASK_RUNNING);
c47b7c72
GP
334 remove_wait_queue(sk_sleep(sk), &wait);
335
336 if (err)
337 goto done;
338
339 newsock->state = SS_CONNECTED;
340
341 BT_DBG("new socket %p", nsk);
342
343done:
344 release_sock(sk);
345 return err;
346}
347
2d792818
GP
348static int l2cap_sock_getname(struct socket *sock, struct sockaddr *addr,
349 int *len, int peer)
d7175d55
GP
350{
351 struct sockaddr_l2 *la = (struct sockaddr_l2 *) addr;
352 struct sock *sk = sock->sk;
0c1bc5c6 353 struct l2cap_chan *chan = l2cap_pi(sk)->chan;
d7175d55
GP
354
355 BT_DBG("sock %p, sk %p", sock, sk);
356
792039c7 357 memset(la, 0, sizeof(struct sockaddr_l2));
d7175d55
GP
358 addr->sa_family = AF_BLUETOOTH;
359 *len = sizeof(struct sockaddr_l2);
360
361 if (peer) {
fe4128e0 362 la->l2_psm = chan->psm;
7eafc59e 363 bacpy(&la->l2_bdaddr, &chan->dst);
fe4128e0 364 la->l2_cid = cpu_to_le16(chan->dcid);
4f1654e0 365 la->l2_bdaddr_type = chan->dst_type;
d7175d55 366 } else {
0c1bc5c6 367 la->l2_psm = chan->sport;
7eafc59e 368 bacpy(&la->l2_bdaddr, &chan->src);
fe4128e0 369 la->l2_cid = cpu_to_le16(chan->scid);
4f1654e0 370 la->l2_bdaddr_type = chan->src_type;
d7175d55
GP
371 }
372
373 return 0;
374}
375
2d792818
GP
376static int l2cap_sock_getsockopt_old(struct socket *sock, int optname,
377 char __user *optval, int __user *optlen)
99f4808d
GP
378{
379 struct sock *sk = sock->sk;
4343478f 380 struct l2cap_chan *chan = l2cap_pi(sk)->chan;
99f4808d
GP
381 struct l2cap_options opts;
382 struct l2cap_conninfo cinfo;
383 int len, err = 0;
384 u32 opt;
385
386 BT_DBG("sk %p", sk);
387
388 if (get_user(len, optlen))
389 return -EFAULT;
390
391 lock_sock(sk);
392
393 switch (optname) {
394 case L2CAP_OPTIONS:
64b4f8dc
JH
395 /* LE sockets should use BT_SNDMTU/BT_RCVMTU, but since
396 * legacy ATT code depends on getsockopt for
397 * L2CAP_OPTIONS we need to let this pass.
398 */
399 if (bdaddr_type_is_le(chan->src_type) &&
400 chan->scid != L2CAP_CID_ATT) {
401 err = -EINVAL;
402 break;
403 }
404
e3fb592b 405 memset(&opts, 0, sizeof(opts));
0c1bc5c6
GP
406 opts.imtu = chan->imtu;
407 opts.omtu = chan->omtu;
408 opts.flush_to = chan->flush_to;
409 opts.mode = chan->mode;
47d1ec61
GP
410 opts.fcs = chan->fcs;
411 opts.max_tx = chan->max_tx;
6327eb98 412 opts.txwin_size = chan->tx_win;
99f4808d
GP
413
414 len = min_t(unsigned int, len, sizeof(opts));
415 if (copy_to_user(optval, (char *) &opts, len))
416 err = -EFAULT;
417
418 break;
419
420 case L2CAP_LM:
4343478f 421 switch (chan->sec_level) {
99f4808d
GP
422 case BT_SECURITY_LOW:
423 opt = L2CAP_LM_AUTH;
424 break;
425 case BT_SECURITY_MEDIUM:
426 opt = L2CAP_LM_AUTH | L2CAP_LM_ENCRYPT;
427 break;
428 case BT_SECURITY_HIGH:
429 opt = L2CAP_LM_AUTH | L2CAP_LM_ENCRYPT |
2d792818 430 L2CAP_LM_SECURE;
99f4808d
GP
431 break;
432 default:
433 opt = 0;
434 break;
435 }
436
43bd0f32 437 if (test_bit(FLAG_ROLE_SWITCH, &chan->flags))
99f4808d
GP
438 opt |= L2CAP_LM_MASTER;
439
ecf61bdb 440 if (test_bit(FLAG_FORCE_RELIABLE, &chan->flags))
99f4808d
GP
441 opt |= L2CAP_LM_RELIABLE;
442
443 if (put_user(opt, (u32 __user *) optval))
444 err = -EFAULT;
445 break;
446
447 case L2CAP_CONNINFO:
448 if (sk->sk_state != BT_CONNECTED &&
c5daa683
GP
449 !(sk->sk_state == BT_CONNECT2 &&
450 test_bit(BT_SK_DEFER_SETUP, &bt_sk(sk)->flags))) {
99f4808d
GP
451 err = -ENOTCONN;
452 break;
453 }
454
8d03e971 455 memset(&cinfo, 0, sizeof(cinfo));
8c1d787b
GP
456 cinfo.hci_handle = chan->conn->hcon->handle;
457 memcpy(cinfo.dev_class, chan->conn->hcon->dev_class, 3);
99f4808d
GP
458
459 len = min_t(unsigned int, len, sizeof(cinfo));
460 if (copy_to_user(optval, (char *) &cinfo, len))
461 err = -EFAULT;
462
463 break;
464
465 default:
466 err = -ENOPROTOOPT;
467 break;
468 }
469
470 release_sock(sk);
471 return err;
472}
473
2d792818
GP
474static int l2cap_sock_getsockopt(struct socket *sock, int level, int optname,
475 char __user *optval, int __user *optlen)
99f4808d
GP
476{
477 struct sock *sk = sock->sk;
4343478f 478 struct l2cap_chan *chan = l2cap_pi(sk)->chan;
99f4808d 479 struct bt_security sec;
14b12d0b 480 struct bt_power pwr;
99f4808d
GP
481 int len, err = 0;
482
483 BT_DBG("sk %p", sk);
484
485 if (level == SOL_L2CAP)
486 return l2cap_sock_getsockopt_old(sock, optname, optval, optlen);
487
488 if (level != SOL_BLUETOOTH)
489 return -ENOPROTOOPT;
490
491 if (get_user(len, optlen))
492 return -EFAULT;
493
494 lock_sock(sk);
495
496 switch (optname) {
497 case BT_SECURITY:
715ec005 498 if (chan->chan_type != L2CAP_CHAN_CONN_ORIENTED &&
2d792818 499 chan->chan_type != L2CAP_CHAN_RAW) {
99f4808d
GP
500 err = -EINVAL;
501 break;
502 }
503
8f360119 504 memset(&sec, 0, sizeof(sec));
85e34368 505 if (chan->conn) {
c6585a4d 506 sec.level = chan->conn->hcon->sec_level;
99f4808d 507
85e34368
AE
508 if (sk->sk_state == BT_CONNECTED)
509 sec.key_size = chan->conn->hcon->enc_key_size;
510 } else {
511 sec.level = chan->sec_level;
512 }
8f360119 513
99f4808d
GP
514 len = min_t(unsigned int, len, sizeof(sec));
515 if (copy_to_user(optval, (char *) &sec, len))
516 err = -EFAULT;
517
518 break;
519
520 case BT_DEFER_SETUP:
521 if (sk->sk_state != BT_BOUND && sk->sk_state != BT_LISTEN) {
522 err = -EINVAL;
523 break;
524 }
525
c5daa683
GP
526 if (put_user(test_bit(BT_SK_DEFER_SETUP, &bt_sk(sk)->flags),
527 (u32 __user *) optval))
99f4808d
GP
528 err = -EFAULT;
529
530 break;
531
532 case BT_FLUSHABLE:
d57b0e8b 533 if (put_user(test_bit(FLAG_FLUSHABLE, &chan->flags),
2d792818 534 (u32 __user *) optval))
99f4808d
GP
535 err = -EFAULT;
536
537 break;
538
14b12d0b
JG
539 case BT_POWER:
540 if (sk->sk_type != SOCK_SEQPACKET && sk->sk_type != SOCK_STREAM
2d792818 541 && sk->sk_type != SOCK_RAW) {
14b12d0b
JG
542 err = -EINVAL;
543 break;
544 }
545
15770b1a 546 pwr.force_active = test_bit(FLAG_FORCE_ACTIVE, &chan->flags);
14b12d0b
JG
547
548 len = min_t(unsigned int, len, sizeof(pwr));
549 if (copy_to_user(optval, (char *) &pwr, len))
550 err = -EFAULT;
551
552 break;
553
2ea66482 554 case BT_CHANNEL_POLICY:
2ea66482
MM
555 if (put_user(chan->chan_policy, (u32 __user *) optval))
556 err = -EFAULT;
557 break;
558
1f435424
JH
559 case BT_SNDMTU:
560 if (!enable_lecoc) {
561 err = -EPROTONOSUPPORT;
562 break;
563 }
564
565 if (!bdaddr_type_is_le(chan->src_type)) {
566 err = -EINVAL;
567 break;
568 }
569
570 if (sk->sk_state != BT_CONNECTED) {
571 err = -ENOTCONN;
572 break;
573 }
574
575 if (put_user(chan->omtu, (u16 __user *) optval))
576 err = -EFAULT;
577 break;
578
579 case BT_RCVMTU:
580 if (!enable_lecoc) {
581 err = -EPROTONOSUPPORT;
582 break;
583 }
584
585 if (!bdaddr_type_is_le(chan->src_type)) {
586 err = -EINVAL;
587 break;
588 }
589
590 if (put_user(chan->imtu, (u16 __user *) optval))
591 err = -EFAULT;
592 break;
593
99f4808d
GP
594 default:
595 err = -ENOPROTOOPT;
596 break;
597 }
598
599 release_sock(sk);
600 return err;
601}
602
682877c3
AG
603static bool l2cap_valid_mtu(struct l2cap_chan *chan, u16 mtu)
604{
605 switch (chan->scid) {
073d1cf3 606 case L2CAP_CID_ATT:
8c3a4f00 607 if (mtu < L2CAP_LE_MIN_MTU)
682877c3
AG
608 return false;
609 break;
610
611 default:
612 if (mtu < L2CAP_DEFAULT_MIN_MTU)
613 return false;
614 }
615
616 return true;
617}
618
2d792818
GP
619static int l2cap_sock_setsockopt_old(struct socket *sock, int optname,
620 char __user *optval, unsigned int optlen)
33575df7
GP
621{
622 struct sock *sk = sock->sk;
b4450035 623 struct l2cap_chan *chan = l2cap_pi(sk)->chan;
33575df7
GP
624 struct l2cap_options opts;
625 int len, err = 0;
626 u32 opt;
627
628 BT_DBG("sk %p", sk);
629
630 lock_sock(sk);
631
632 switch (optname) {
633 case L2CAP_OPTIONS:
64b4f8dc
JH
634 if (bdaddr_type_is_le(chan->src_type)) {
635 err = -EINVAL;
636 break;
637 }
638
33575df7
GP
639 if (sk->sk_state == BT_CONNECTED) {
640 err = -EINVAL;
641 break;
642 }
643
0c1bc5c6
GP
644 opts.imtu = chan->imtu;
645 opts.omtu = chan->omtu;
646 opts.flush_to = chan->flush_to;
647 opts.mode = chan->mode;
47d1ec61
GP
648 opts.fcs = chan->fcs;
649 opts.max_tx = chan->max_tx;
6327eb98 650 opts.txwin_size = chan->tx_win;
33575df7
GP
651
652 len = min_t(unsigned int, sizeof(opts), optlen);
653 if (copy_from_user((char *) &opts, optval, len)) {
654 err = -EFAULT;
655 break;
656 }
657
6327eb98 658 if (opts.txwin_size > L2CAP_DEFAULT_EXT_WINDOW) {
33575df7
GP
659 err = -EINVAL;
660 break;
661 }
662
682877c3
AG
663 if (!l2cap_valid_mtu(chan, opts.imtu)) {
664 err = -EINVAL;
665 break;
666 }
667
0c1bc5c6
GP
668 chan->mode = opts.mode;
669 switch (chan->mode) {
38319713
JH
670 case L2CAP_MODE_LE_FLOWCTL:
671 break;
33575df7 672 case L2CAP_MODE_BASIC:
c1360a1c 673 clear_bit(CONF_STATE2_DEVICE, &chan->conf_state);
33575df7
GP
674 break;
675 case L2CAP_MODE_ERTM:
676 case L2CAP_MODE_STREAMING:
677 if (!disable_ertm)
678 break;
679 /* fall through */
680 default:
681 err = -EINVAL;
682 break;
683 }
684
0c1bc5c6
GP
685 chan->imtu = opts.imtu;
686 chan->omtu = opts.omtu;
47d1ec61
GP
687 chan->fcs = opts.fcs;
688 chan->max_tx = opts.max_tx;
6327eb98 689 chan->tx_win = opts.txwin_size;
12d59781 690 chan->flush_to = opts.flush_to;
33575df7
GP
691 break;
692
693 case L2CAP_LM:
694 if (get_user(opt, (u32 __user *) optval)) {
695 err = -EFAULT;
696 break;
697 }
698
699 if (opt & L2CAP_LM_AUTH)
4343478f 700 chan->sec_level = BT_SECURITY_LOW;
33575df7 701 if (opt & L2CAP_LM_ENCRYPT)
4343478f 702 chan->sec_level = BT_SECURITY_MEDIUM;
33575df7 703 if (opt & L2CAP_LM_SECURE)
4343478f 704 chan->sec_level = BT_SECURITY_HIGH;
33575df7 705
43bd0f32
AE
706 if (opt & L2CAP_LM_MASTER)
707 set_bit(FLAG_ROLE_SWITCH, &chan->flags);
708 else
709 clear_bit(FLAG_ROLE_SWITCH, &chan->flags);
ecf61bdb
AE
710
711 if (opt & L2CAP_LM_RELIABLE)
712 set_bit(FLAG_FORCE_RELIABLE, &chan->flags);
713 else
714 clear_bit(FLAG_FORCE_RELIABLE, &chan->flags);
33575df7
GP
715 break;
716
717 default:
718 err = -ENOPROTOOPT;
719 break;
720 }
721
722 release_sock(sk);
723 return err;
724}
725
2d792818
GP
726static int l2cap_sock_setsockopt(struct socket *sock, int level, int optname,
727 char __user *optval, unsigned int optlen)
33575df7
GP
728{
729 struct sock *sk = sock->sk;
4343478f 730 struct l2cap_chan *chan = l2cap_pi(sk)->chan;
33575df7 731 struct bt_security sec;
14b12d0b 732 struct bt_power pwr;
f1cb9af5 733 struct l2cap_conn *conn;
33575df7
GP
734 int len, err = 0;
735 u32 opt;
736
737 BT_DBG("sk %p", sk);
738
739 if (level == SOL_L2CAP)
740 return l2cap_sock_setsockopt_old(sock, optname, optval, optlen);
741
742 if (level != SOL_BLUETOOTH)
743 return -ENOPROTOOPT;
744
745 lock_sock(sk);
746
747 switch (optname) {
748 case BT_SECURITY:
715ec005 749 if (chan->chan_type != L2CAP_CHAN_CONN_ORIENTED &&
2d792818 750 chan->chan_type != L2CAP_CHAN_RAW) {
33575df7
GP
751 err = -EINVAL;
752 break;
753 }
754
755 sec.level = BT_SECURITY_LOW;
756
757 len = min_t(unsigned int, sizeof(sec), optlen);
758 if (copy_from_user((char *) &sec, optval, len)) {
759 err = -EFAULT;
760 break;
761 }
762
763 if (sec.level < BT_SECURITY_LOW ||
2d792818 764 sec.level > BT_SECURITY_HIGH) {
33575df7
GP
765 err = -EINVAL;
766 break;
767 }
768
4343478f 769 chan->sec_level = sec.level;
f1cb9af5 770
0bee1d60
GP
771 if (!chan->conn)
772 break;
773
f1cb9af5 774 conn = chan->conn;
0bee1d60
GP
775
776 /*change security for LE channels */
073d1cf3 777 if (chan->scid == L2CAP_CID_ATT) {
f1cb9af5
VCG
778 if (!conn->hcon->out) {
779 err = -EINVAL;
780 break;
781 }
782
cc110922 783 if (smp_conn_security(conn->hcon, sec.level))
f1cb9af5 784 break;
f1cb9af5 785 sk->sk_state = BT_CONFIG;
3542b854 786 chan->state = BT_CONFIG;
0bee1d60 787
a7d7723a
GP
788 /* or for ACL link */
789 } else if ((sk->sk_state == BT_CONNECT2 &&
2d792818 790 test_bit(BT_SK_DEFER_SETUP, &bt_sk(sk)->flags)) ||
a7d7723a
GP
791 sk->sk_state == BT_CONNECTED) {
792 if (!l2cap_chan_check_security(chan))
c5daa683 793 set_bit(BT_SK_SUSPEND, &bt_sk(sk)->flags);
a7d7723a
GP
794 else
795 sk->sk_state_change(sk);
0bee1d60
GP
796 } else {
797 err = -EINVAL;
f1cb9af5 798 }
33575df7
GP
799 break;
800
801 case BT_DEFER_SETUP:
802 if (sk->sk_state != BT_BOUND && sk->sk_state != BT_LISTEN) {
803 err = -EINVAL;
804 break;
805 }
806
807 if (get_user(opt, (u32 __user *) optval)) {
808 err = -EFAULT;
809 break;
810 }
811
bdc25783 812 if (opt) {
c5daa683 813 set_bit(BT_SK_DEFER_SETUP, &bt_sk(sk)->flags);
bdc25783
MH
814 set_bit(FLAG_DEFER_SETUP, &chan->flags);
815 } else {
c5daa683 816 clear_bit(BT_SK_DEFER_SETUP, &bt_sk(sk)->flags);
bdc25783
MH
817 clear_bit(FLAG_DEFER_SETUP, &chan->flags);
818 }
33575df7
GP
819 break;
820
821 case BT_FLUSHABLE:
822 if (get_user(opt, (u32 __user *) optval)) {
823 err = -EFAULT;
824 break;
825 }
826
827 if (opt > BT_FLUSHABLE_ON) {
828 err = -EINVAL;
829 break;
830 }
831
832 if (opt == BT_FLUSHABLE_OFF) {
c1f23a2b 833 conn = chan->conn;
25985edc 834 /* proceed further only when we have l2cap_conn and
33575df7
GP
835 No Flush support in the LM */
836 if (!conn || !lmp_no_flush_capable(conn->hcon->hdev)) {
837 err = -EINVAL;
838 break;
839 }
840 }
841
d57b0e8b
AE
842 if (opt)
843 set_bit(FLAG_FLUSHABLE, &chan->flags);
844 else
845 clear_bit(FLAG_FLUSHABLE, &chan->flags);
33575df7
GP
846 break;
847
14b12d0b
JG
848 case BT_POWER:
849 if (chan->chan_type != L2CAP_CHAN_CONN_ORIENTED &&
2d792818 850 chan->chan_type != L2CAP_CHAN_RAW) {
14b12d0b
JG
851 err = -EINVAL;
852 break;
853 }
854
855 pwr.force_active = BT_POWER_FORCE_ACTIVE_ON;
856
857 len = min_t(unsigned int, sizeof(pwr), optlen);
858 if (copy_from_user((char *) &pwr, optval, len)) {
859 err = -EFAULT;
860 break;
861 }
15770b1a
AE
862
863 if (pwr.force_active)
864 set_bit(FLAG_FORCE_ACTIVE, &chan->flags);
865 else
866 clear_bit(FLAG_FORCE_ACTIVE, &chan->flags);
14b12d0b
JG
867 break;
868
2ea66482 869 case BT_CHANNEL_POLICY:
2ea66482
MM
870 if (get_user(opt, (u32 __user *) optval)) {
871 err = -EFAULT;
872 break;
873 }
874
875 if (opt > BT_CHANNEL_POLICY_AMP_PREFERRED) {
876 err = -EINVAL;
877 break;
878 }
879
880 if (chan->mode != L2CAP_MODE_ERTM &&
2d792818 881 chan->mode != L2CAP_MODE_STREAMING) {
2ea66482
MM
882 err = -EOPNOTSUPP;
883 break;
884 }
885
886 chan->chan_policy = (u8) opt;
3f7a56c4
MM
887
888 if (sk->sk_state == BT_CONNECTED &&
889 chan->move_role == L2CAP_MOVE_ROLE_NONE)
890 l2cap_move_start(chan);
891
14b12d0b
JG
892 break;
893
1f435424
JH
894 case BT_SNDMTU:
895 if (!enable_lecoc) {
896 err = -EPROTONOSUPPORT;
897 break;
898 }
899
900 if (!bdaddr_type_is_le(chan->src_type)) {
901 err = -EINVAL;
902 break;
903 }
904
905 /* Setting is not supported as it's the remote side that
906 * decides this.
907 */
908 err = -EPERM;
909 break;
910
911 case BT_RCVMTU:
912 if (!enable_lecoc) {
913 err = -EPROTONOSUPPORT;
914 break;
915 }
916
917 if (!bdaddr_type_is_le(chan->src_type)) {
918 err = -EINVAL;
919 break;
920 }
921
922 if (sk->sk_state == BT_CONNECTED) {
923 err = -EISCONN;
924 break;
925 }
926
927 if (get_user(opt, (u32 __user *) optval)) {
928 err = -EFAULT;
929 break;
930 }
931
932 chan->imtu = opt;
933 break;
934
33575df7
GP
935 default:
936 err = -ENOPROTOOPT;
937 break;
938 }
939
940 release_sock(sk);
941 return err;
942}
fd83ccdb 943
2d792818
GP
944static int l2cap_sock_sendmsg(struct kiocb *iocb, struct socket *sock,
945 struct msghdr *msg, size_t len)
fd83ccdb
GP
946{
947 struct sock *sk = sock->sk;
0c1bc5c6 948 struct l2cap_chan *chan = l2cap_pi(sk)->chan;
fd83ccdb
GP
949 int err;
950
951 BT_DBG("sock %p, sk %p", sock, sk);
952
953 err = sock_error(sk);
954 if (err)
955 return err;
956
957 if (msg->msg_flags & MSG_OOB)
958 return -EOPNOTSUPP;
959
a6a5568c 960 if (sk->sk_state != BT_CONNECTED)
9a91a04a 961 return -ENOTCONN;
fd83ccdb 962
e793dcf0
JH
963 lock_sock(sk);
964 err = bt_sock_wait_ready(sk, msg->msg_flags);
965 release_sock(sk);
966 if (err)
967 return err;
968
a6a5568c 969 l2cap_chan_lock(chan);
5e59b791 970 err = l2cap_chan_send(chan, msg, len, sk->sk_priority);
a6a5568c 971 l2cap_chan_unlock(chan);
fd83ccdb 972
fd83ccdb
GP
973 return err;
974}
33575df7 975
2d792818
GP
976static int l2cap_sock_recvmsg(struct kiocb *iocb, struct socket *sock,
977 struct msghdr *msg, size_t len, int flags)
68983259
GP
978{
979 struct sock *sk = sock->sk;
e328140f
MM
980 struct l2cap_pinfo *pi = l2cap_pi(sk);
981 int err;
68983259
GP
982
983 lock_sock(sk);
984
c5daa683
GP
985 if (sk->sk_state == BT_CONNECT2 && test_bit(BT_SK_DEFER_SETUP,
986 &bt_sk(sk)->flags)) {
38319713
JH
987 if (bdaddr_type_is_le(pi->chan->src_type)) {
988 sk->sk_state = BT_CONNECTED;
989 pi->chan->state = BT_CONNECTED;
990 __l2cap_le_connect_rsp_defer(pi->chan);
991 } else {
992 sk->sk_state = BT_CONFIG;
993 pi->chan->state = BT_CONFIG;
994 __l2cap_connect_rsp_defer(pi->chan);
995 }
8c1d787b 996
970871bc
JH
997 err = 0;
998 goto done;
68983259
GP
999 }
1000
1001 release_sock(sk);
1002
1003 if (sock->type == SOCK_STREAM)
e328140f
MM
1004 err = bt_sock_stream_recvmsg(iocb, sock, msg, len, flags);
1005 else
1006 err = bt_sock_recvmsg(iocb, sock, msg, len, flags);
1007
1008 if (pi->chan->mode != L2CAP_MODE_ERTM)
1009 return err;
1010
1011 /* Attempt to put pending rx data in the socket buffer */
1012
1013 lock_sock(sk);
1014
1015 if (!test_bit(CONN_LOCAL_BUSY, &pi->chan->conn_state))
1016 goto done;
1017
1018 if (pi->rx_busy_skb) {
1019 if (!sock_queue_rcv_skb(sk, pi->rx_busy_skb))
1020 pi->rx_busy_skb = NULL;
1021 else
1022 goto done;
1023 }
1024
1025 /* Restore data flow when half of the receive buffer is
1026 * available. This avoids resending large numbers of
1027 * frames.
1028 */
1029 if (atomic_read(&sk->sk_rmem_alloc) <= sk->sk_rcvbuf >> 1)
1030 l2cap_chan_busy(pi->chan, 0);
68983259 1031
e328140f
MM
1032done:
1033 release_sock(sk);
1034 return err;
68983259
GP
1035}
1036
05fc1576
GP
1037/* Kill socket (only if zapped and orphan)
1038 * Must be called on unlocked socket.
1039 */
ba3bd0ee 1040static void l2cap_sock_kill(struct sock *sk)
05fc1576
GP
1041{
1042 if (!sock_flag(sk, SOCK_ZAPPED) || sk->sk_socket)
1043 return;
1044
e05dcc32 1045 BT_DBG("sk %p state %s", sk, state_to_string(sk->sk_state));
05fc1576
GP
1046
1047 /* Kill poor orphan */
6ff5abbf 1048
4af66c69 1049 l2cap_chan_put(l2cap_pi(sk)->chan);
05fc1576
GP
1050 sock_set_flag(sk, SOCK_DEAD);
1051 sock_put(sk);
1052}
1053
dc25306b
GP
1054static int __l2cap_wait_ack(struct sock *sk)
1055{
1056 struct l2cap_chan *chan = l2cap_pi(sk)->chan;
1057 DECLARE_WAITQUEUE(wait, current);
1058 int err = 0;
1059 int timeo = HZ/5;
1060
1061 add_wait_queue(sk_sleep(sk), &wait);
1062 set_current_state(TASK_INTERRUPTIBLE);
1063 while (chan->unacked_frames > 0 && chan->conn) {
1064 if (!timeo)
1065 timeo = HZ/5;
1066
1067 if (signal_pending(current)) {
1068 err = sock_intr_errno(timeo);
1069 break;
1070 }
1071
1072 release_sock(sk);
1073 timeo = schedule_timeout(timeo);
1074 lock_sock(sk);
1075 set_current_state(TASK_INTERRUPTIBLE);
1076
1077 err = sock_error(sk);
1078 if (err)
1079 break;
1080 }
1081 set_current_state(TASK_RUNNING);
1082 remove_wait_queue(sk_sleep(sk), &wait);
1083 return err;
1084}
1085
dcba0dba
GP
1086static int l2cap_sock_shutdown(struct socket *sock, int how)
1087{
1088 struct sock *sk = sock->sk;
7ddb6e0f 1089 struct l2cap_chan *chan;
3df91ea2 1090 struct l2cap_conn *conn;
dcba0dba
GP
1091 int err = 0;
1092
1093 BT_DBG("sock %p, sk %p", sock, sk);
1094
1095 if (!sk)
1096 return 0;
1097
7ddb6e0f 1098 chan = l2cap_pi(sk)->chan;
3df91ea2
AE
1099 conn = chan->conn;
1100
1101 if (conn)
1102 mutex_lock(&conn->chan_lock);
7ddb6e0f 1103
6be36555 1104 l2cap_chan_lock(chan);
dcba0dba 1105 lock_sock(sk);
6be36555 1106
dcba0dba 1107 if (!sk->sk_shutdown) {
0c1bc5c6 1108 if (chan->mode == L2CAP_MODE_ERTM)
dcba0dba
GP
1109 err = __l2cap_wait_ack(sk);
1110
1111 sk->sk_shutdown = SHUTDOWN_MASK;
3df91ea2 1112
6be36555 1113 release_sock(sk);
0f852724 1114 l2cap_chan_close(chan, 0);
6be36555 1115 lock_sock(sk);
dcba0dba
GP
1116
1117 if (sock_flag(sk, SOCK_LINGER) && sk->sk_lingertime)
1118 err = bt_sock_wait_state(sk, BT_CLOSED,
2d792818 1119 sk->sk_lingertime);
dcba0dba
GP
1120 }
1121
1122 if (!err && sk->sk_err)
1123 err = -sk->sk_err;
1124
1125 release_sock(sk);
6be36555 1126 l2cap_chan_unlock(chan);
3df91ea2
AE
1127
1128 if (conn)
1129 mutex_unlock(&conn->chan_lock);
1130
dcba0dba
GP
1131 return err;
1132}
1133
554f05bb
GP
1134static int l2cap_sock_release(struct socket *sock)
1135{
1136 struct sock *sk = sock->sk;
1137 int err;
1138
1139 BT_DBG("sock %p, sk %p", sock, sk);
1140
1141 if (!sk)
1142 return 0;
1143
5b28d95c
MY
1144 bt_sock_unlink(&l2cap_sk_list, sk);
1145
554f05bb
GP
1146 err = l2cap_sock_shutdown(sock, 2);
1147
1148 sock_orphan(sk);
1149 l2cap_sock_kill(sk);
1150 return err;
1151}
1152
c0df7f6e
AE
1153static void l2cap_sock_cleanup_listen(struct sock *parent)
1154{
1155 struct sock *sk;
1156
1157 BT_DBG("parent %p", parent);
1158
1159 /* Close not yet accepted channels */
1160 while ((sk = bt_accept_dequeue(parent, NULL))) {
1161 struct l2cap_chan *chan = l2cap_pi(sk)->chan;
1162
1163 l2cap_chan_lock(chan);
1164 __clear_chan_timer(chan);
1165 l2cap_chan_close(chan, ECONNRESET);
1166 l2cap_chan_unlock(chan);
1167
1168 l2cap_sock_kill(sk);
1169 }
1170}
1171
80b98027 1172static struct l2cap_chan *l2cap_sock_new_connection_cb(struct l2cap_chan *chan)
80808e43 1173{
80b98027 1174 struct sock *sk, *parent = chan->data;
80808e43 1175
8ffb9290
GP
1176 lock_sock(parent);
1177
53826692
GP
1178 /* Check for backlog size */
1179 if (sk_acceptq_is_full(parent)) {
1180 BT_DBG("backlog full %d", parent->sk_ack_backlog);
1181 return NULL;
1182 }
1183
80808e43 1184 sk = l2cap_sock_alloc(sock_net(parent), NULL, BTPROTO_L2CAP,
2d792818 1185 GFP_ATOMIC);
80808e43
GP
1186 if (!sk)
1187 return NULL;
1188
d22015aa
OP
1189 bt_sock_reclassify_lock(sk, BTPROTO_L2CAP);
1190
80808e43
GP
1191 l2cap_sock_init(sk, parent);
1192
644912e1
GP
1193 bt_accept_enqueue(parent, sk);
1194
8ffb9290
GP
1195 release_sock(parent);
1196
80808e43
GP
1197 return l2cap_pi(sk)->chan;
1198}
1199
80b98027 1200static int l2cap_sock_recv_cb(struct l2cap_chan *chan, struct sk_buff *skb)
23070494 1201{
80b98027 1202 struct sock *sk = chan->data;
84b34d98 1203 int err;
e328140f 1204
6be36555
AE
1205 lock_sock(sk);
1206
84b34d98 1207 if (l2cap_pi(sk)->rx_busy_skb) {
6be36555
AE
1208 err = -ENOMEM;
1209 goto done;
1210 }
e328140f
MM
1211
1212 err = sock_queue_rcv_skb(sk, skb);
1213
1214 /* For ERTM, handle one skb that doesn't fit into the recv
1215 * buffer. This is important to do because the data frames
1216 * have already been acked, so the skb cannot be discarded.
1217 *
1218 * Notify the l2cap core that the buffer is full, so the
1219 * LOCAL_BUSY state is entered and no more frames are
1220 * acked and reassembled until there is buffer space
1221 * available.
1222 */
84b34d98
MH
1223 if (err < 0 && chan->mode == L2CAP_MODE_ERTM) {
1224 l2cap_pi(sk)->rx_busy_skb = skb;
1225 l2cap_chan_busy(chan, 1);
e328140f
MM
1226 err = 0;
1227 }
23070494 1228
6be36555
AE
1229done:
1230 release_sock(sk);
1231
e328140f 1232 return err;
23070494
GP
1233}
1234
80b98027 1235static void l2cap_sock_close_cb(struct l2cap_chan *chan)
ba3bd0ee 1236{
80b98027 1237 struct sock *sk = chan->data;
ba3bd0ee
GP
1238
1239 l2cap_sock_kill(sk);
1240}
1241
c0df7f6e
AE
1242static void l2cap_sock_teardown_cb(struct l2cap_chan *chan, int err)
1243{
1244 struct sock *sk = chan->data;
1245 struct sock *parent;
1246
1247 lock_sock(sk);
1248
1249 parent = bt_sk(sk)->parent;
1250
1251 sock_set_flag(sk, SOCK_ZAPPED);
1252
1253 switch (chan->state) {
1254 case BT_OPEN:
1255 case BT_BOUND:
1256 case BT_CLOSED:
1257 break;
1258 case BT_LISTEN:
1259 l2cap_sock_cleanup_listen(sk);
1260 sk->sk_state = BT_CLOSED;
1261 chan->state = BT_CLOSED;
1262
1263 break;
1264 default:
1265 sk->sk_state = BT_CLOSED;
1266 chan->state = BT_CLOSED;
1267
1268 sk->sk_err = err;
1269
1270 if (parent) {
1271 bt_accept_unlink(sk);
1272 parent->sk_data_ready(parent, 0);
1273 } else {
1274 sk->sk_state_change(sk);
1275 }
1276
1277 break;
1278 }
1279
1280 release_sock(sk);
1281}
1282
53f52121
GP
1283static void l2cap_sock_state_change_cb(struct l2cap_chan *chan, int state,
1284 int err)
89bc500e 1285{
80b98027 1286 struct sock *sk = chan->data;
89bc500e
GP
1287
1288 sk->sk_state = state;
53f52121
GP
1289
1290 if (err)
1291 sk->sk_err = err;
89bc500e
GP
1292}
1293
2f7719ce 1294static struct sk_buff *l2cap_sock_alloc_skb_cb(struct l2cap_chan *chan,
90338947 1295 unsigned long len, int nb)
2f7719ce 1296{
0f2c6153 1297 struct sock *sk = chan->data;
90338947
GP
1298 struct sk_buff *skb;
1299 int err;
1300
a6a5568c 1301 l2cap_chan_unlock(chan);
0f2c6153 1302 skb = bt_skb_send_alloc(sk, len, nb, &err);
a6a5568c
MM
1303 l2cap_chan_lock(chan);
1304
90338947
GP
1305 if (!skb)
1306 return ERR_PTR(err);
2f7719ce 1307
0e790c64
GP
1308 bt_cb(skb)->chan = chan;
1309
90338947 1310 return skb;
2f7719ce
AE
1311}
1312
54a59aa2
AE
1313static void l2cap_sock_ready_cb(struct l2cap_chan *chan)
1314{
1315 struct sock *sk = chan->data;
1316 struct sock *parent;
1317
1318 lock_sock(sk);
1319
1320 parent = bt_sk(sk)->parent;
1321
1322 BT_DBG("sk %p, parent %p", sk, parent);
1323
1324 sk->sk_state = BT_CONNECTED;
1325 sk->sk_state_change(sk);
1326
1327 if (parent)
1328 parent->sk_data_ready(parent, 0);
1329
1330 release_sock(sk);
1331}
1332
2dc4e510
GP
1333static void l2cap_sock_defer_cb(struct l2cap_chan *chan)
1334{
acdcabf5
GP
1335 struct sock *parent, *sk = chan->data;
1336
1337 lock_sock(sk);
2dc4e510 1338
acdcabf5 1339 parent = bt_sk(sk)->parent;
2dc4e510
GP
1340 if (parent)
1341 parent->sk_data_ready(parent, 0);
acdcabf5
GP
1342
1343 release_sock(sk);
2dc4e510
GP
1344}
1345
d97c899b
MH
1346static void l2cap_sock_resume_cb(struct l2cap_chan *chan)
1347{
1348 struct sock *sk = chan->data;
1349
1350 clear_bit(BT_SK_SUSPEND, &bt_sk(sk)->flags);
1351 sk->sk_state_change(sk);
1352}
1353
5ec1bbe5
GP
1354static void l2cap_sock_set_shutdown_cb(struct l2cap_chan *chan)
1355{
1356 struct sock *sk = chan->data;
1357
1358 lock_sock(sk);
1359 sk->sk_shutdown = SHUTDOWN_MASK;
1360 release_sock(sk);
1361}
1362
8d836d71
GP
1363static long l2cap_sock_get_sndtimeo_cb(struct l2cap_chan *chan)
1364{
1365 struct sock *sk = chan->data;
1366
1367 return sk->sk_sndtimeo;
1368}
1369
837776f7
JH
1370static void l2cap_sock_suspend_cb(struct l2cap_chan *chan)
1371{
1372 struct sock *sk = chan->data;
1373
1374 set_bit(BT_SK_SUSPEND, &bt_sk(sk)->flags);
1375 sk->sk_state_change(sk);
1376}
1377
80808e43
GP
1378static struct l2cap_ops l2cap_chan_ops = {
1379 .name = "L2CAP Socket Interface",
1380 .new_connection = l2cap_sock_new_connection_cb,
23070494 1381 .recv = l2cap_sock_recv_cb,
ba3bd0ee 1382 .close = l2cap_sock_close_cb,
c0df7f6e 1383 .teardown = l2cap_sock_teardown_cb,
89bc500e 1384 .state_change = l2cap_sock_state_change_cb,
54a59aa2 1385 .ready = l2cap_sock_ready_cb,
2dc4e510 1386 .defer = l2cap_sock_defer_cb,
d97c899b 1387 .resume = l2cap_sock_resume_cb,
837776f7 1388 .suspend = l2cap_sock_suspend_cb,
5ec1bbe5 1389 .set_shutdown = l2cap_sock_set_shutdown_cb,
8d836d71 1390 .get_sndtimeo = l2cap_sock_get_sndtimeo_cb,
2f7719ce 1391 .alloc_skb = l2cap_sock_alloc_skb_cb,
80808e43
GP
1392};
1393
bb58f747
GP
1394static void l2cap_sock_destruct(struct sock *sk)
1395{
1396 BT_DBG("sk %p", sk);
1397
23d3a869
SL
1398 if (l2cap_pi(sk)->chan)
1399 l2cap_chan_put(l2cap_pi(sk)->chan);
84b34d98 1400
e328140f
MM
1401 if (l2cap_pi(sk)->rx_busy_skb) {
1402 kfree_skb(l2cap_pi(sk)->rx_busy_skb);
1403 l2cap_pi(sk)->rx_busy_skb = NULL;
1404 }
1405
bb58f747
GP
1406 skb_queue_purge(&sk->sk_receive_queue);
1407 skb_queue_purge(&sk->sk_write_queue);
1408}
1409
2edf870d
MH
1410static void l2cap_skb_msg_name(struct sk_buff *skb, void *msg_name,
1411 int *msg_namelen)
1412{
1413 struct sockaddr_l2 *la = (struct sockaddr_l2 *) msg_name;
1414
1415 memset(la, 0, sizeof(struct sockaddr_l2));
1416 la->l2_family = AF_BLUETOOTH;
1417 la->l2_psm = bt_cb(skb)->psm;
1418 bacpy(&la->l2_bdaddr, &bt_cb(skb)->bdaddr);
1419
1420 *msg_namelen = sizeof(struct sockaddr_l2);
1421}
1422
80808e43 1423static void l2cap_sock_init(struct sock *sk, struct sock *parent)
bb58f747 1424{
84b34d98 1425 struct l2cap_chan *chan = l2cap_pi(sk)->chan;
bb58f747
GP
1426
1427 BT_DBG("sk %p", sk);
1428
1429 if (parent) {
b4450035
GP
1430 struct l2cap_chan *pchan = l2cap_pi(parent)->chan;
1431
bb58f747 1432 sk->sk_type = parent->sk_type;
c5daa683 1433 bt_sk(sk)->flags = bt_sk(parent)->flags;
bb58f747 1434
715ec005 1435 chan->chan_type = pchan->chan_type;
0c1bc5c6
GP
1436 chan->imtu = pchan->imtu;
1437 chan->omtu = pchan->omtu;
b4450035 1438 chan->conf_state = pchan->conf_state;
0c1bc5c6 1439 chan->mode = pchan->mode;
47d1ec61
GP
1440 chan->fcs = pchan->fcs;
1441 chan->max_tx = pchan->max_tx;
1442 chan->tx_win = pchan->tx_win;
6b3c7104 1443 chan->tx_win_max = pchan->tx_win_max;
4343478f 1444 chan->sec_level = pchan->sec_level;
d57b0e8b 1445 chan->flags = pchan->flags;
0cd75f7e
JH
1446 chan->tx_credits = pchan->tx_credits;
1447 chan->rx_credits = pchan->rx_credits;
6230c9b4
PM
1448
1449 security_sk_clone(parent, sk);
bb58f747 1450 } else {
715ec005
GP
1451 switch (sk->sk_type) {
1452 case SOCK_RAW:
1453 chan->chan_type = L2CAP_CHAN_RAW;
1454 break;
1455 case SOCK_DGRAM:
1456 chan->chan_type = L2CAP_CHAN_CONN_LESS;
2edf870d 1457 bt_sk(sk)->skb_msg_name = l2cap_skb_msg_name;
715ec005
GP
1458 break;
1459 case SOCK_SEQPACKET:
1460 case SOCK_STREAM:
1461 chan->chan_type = L2CAP_CHAN_CONN_ORIENTED;
1462 break;
1463 }
1464
0c1bc5c6
GP
1465 chan->imtu = L2CAP_DEFAULT_MTU;
1466 chan->omtu = 0;
bb58f747 1467 if (!disable_ertm && sk->sk_type == SOCK_STREAM) {
0c1bc5c6 1468 chan->mode = L2CAP_MODE_ERTM;
c1360a1c 1469 set_bit(CONF_STATE2_DEVICE, &chan->conf_state);
bb58f747 1470 } else {
0c1bc5c6 1471 chan->mode = L2CAP_MODE_BASIC;
bb58f747 1472 }
bd4b1653
AE
1473
1474 l2cap_chan_set_defaults(chan);
bb58f747
GP
1475 }
1476
1477 /* Default config options */
0c1bc5c6 1478 chan->flush_to = L2CAP_DEFAULT_FLUSH_TO;
80808e43
GP
1479
1480 chan->data = sk;
1481 chan->ops = &l2cap_chan_ops;
bb58f747
GP
1482}
1483
1484static struct proto l2cap_proto = {
1485 .name = "L2CAP",
1486 .owner = THIS_MODULE,
1487 .obj_size = sizeof(struct l2cap_pinfo)
1488};
1489
2d792818
GP
1490static struct sock *l2cap_sock_alloc(struct net *net, struct socket *sock,
1491 int proto, gfp_t prio)
bb58f747
GP
1492{
1493 struct sock *sk;
dc50a06d 1494 struct l2cap_chan *chan;
bb58f747
GP
1495
1496 sk = sk_alloc(net, PF_BLUETOOTH, prio, &l2cap_proto);
1497 if (!sk)
1498 return NULL;
1499
1500 sock_init_data(sock, sk);
1501 INIT_LIST_HEAD(&bt_sk(sk)->accept_q);
1502
1503 sk->sk_destruct = l2cap_sock_destruct;
ba13ccd9 1504 sk->sk_sndtimeo = L2CAP_CONN_TIMEOUT;
bb58f747
GP
1505
1506 sock_reset_flag(sk, SOCK_ZAPPED);
1507
1508 sk->sk_protocol = proto;
1509 sk->sk_state = BT_OPEN;
1510
eef1d9b6 1511 chan = l2cap_chan_create();
dc50a06d 1512 if (!chan) {
49dfbb91 1513 sk_free(sk);
dc50a06d
GP
1514 return NULL;
1515 }
1516
61d6ef3e
MM
1517 l2cap_chan_hold(chan);
1518
dc50a06d
GP
1519 l2cap_pi(sk)->chan = chan;
1520
bb58f747
GP
1521 return sk;
1522}
1523
1524static int l2cap_sock_create(struct net *net, struct socket *sock, int protocol,
1525 int kern)
1526{
1527 struct sock *sk;
1528
1529 BT_DBG("sock %p", sock);
1530
1531 sock->state = SS_UNCONNECTED;
1532
1533 if (sock->type != SOCK_SEQPACKET && sock->type != SOCK_STREAM &&
2d792818 1534 sock->type != SOCK_DGRAM && sock->type != SOCK_RAW)
bb58f747
GP
1535 return -ESOCKTNOSUPPORT;
1536
1537 if (sock->type == SOCK_RAW && !kern && !capable(CAP_NET_RAW))
1538 return -EPERM;
1539
1540 sock->ops = &l2cap_sock_ops;
1541
1542 sk = l2cap_sock_alloc(net, sock, protocol, GFP_ATOMIC);
1543 if (!sk)
1544 return -ENOMEM;
1545
1546 l2cap_sock_init(sk, NULL);
5b28d95c 1547 bt_sock_link(&l2cap_sk_list, sk);
bb58f747
GP
1548 return 0;
1549}
1550
cf2f90f5 1551static const struct proto_ops l2cap_sock_ops = {
65390587
GP
1552 .family = PF_BLUETOOTH,
1553 .owner = THIS_MODULE,
1554 .release = l2cap_sock_release,
1555 .bind = l2cap_sock_bind,
1556 .connect = l2cap_sock_connect,
1557 .listen = l2cap_sock_listen,
1558 .accept = l2cap_sock_accept,
1559 .getname = l2cap_sock_getname,
1560 .sendmsg = l2cap_sock_sendmsg,
1561 .recvmsg = l2cap_sock_recvmsg,
1562 .poll = bt_sock_poll,
1563 .ioctl = bt_sock_ioctl,
1564 .mmap = sock_no_mmap,
1565 .socketpair = sock_no_socketpair,
1566 .shutdown = l2cap_sock_shutdown,
1567 .setsockopt = l2cap_sock_setsockopt,
1568 .getsockopt = l2cap_sock_getsockopt
1569};
1570
bb58f747
GP
1571static const struct net_proto_family l2cap_sock_family_ops = {
1572 .family = PF_BLUETOOTH,
1573 .owner = THIS_MODULE,
1574 .create = l2cap_sock_create,
1575};
1576
1577int __init l2cap_init_sockets(void)
1578{
e2174ca4 1579 int err;
bb58f747 1580
e2174ca4
GP
1581 err = proto_register(&l2cap_proto, 0);
1582 if (err < 0)
1583 return err;
bb58f747 1584
e2174ca4 1585 err = bt_sock_register(BTPROTO_L2CAP, &l2cap_sock_family_ops);
5b28d95c
MY
1586 if (err < 0) {
1587 BT_ERR("L2CAP socket registration failed");
e2174ca4 1588 goto error;
5b28d95c
MY
1589 }
1590
b0316615 1591 err = bt_procfs_init(&init_net, "l2cap", &l2cap_sk_list,
2d792818 1592 NULL);
5b28d95c
MY
1593 if (err < 0) {
1594 BT_ERR("Failed to create L2CAP proc file");
1595 bt_sock_unregister(BTPROTO_L2CAP);
1596 goto error;
1597 }
bb58f747 1598
e2174ca4 1599 BT_INFO("L2CAP socket layer initialized");
bb58f747 1600
e2174ca4 1601 return 0;
bb58f747
GP
1602
1603error:
e2174ca4
GP
1604 proto_unregister(&l2cap_proto);
1605 return err;
bb58f747
GP
1606}
1607
1608void l2cap_cleanup_sockets(void)
1609{
5b28d95c 1610 bt_procfs_cleanup(&init_net, "l2cap");
5e9d7f86 1611 bt_sock_unregister(BTPROTO_L2CAP);
e2174ca4 1612 proto_unregister(&l2cap_proto);
bb58f747 1613}
9149761a
JH
1614
1615module_param(enable_lecoc, bool, 0644);
1616MODULE_PARM_DESC(enable_lecoc, "Enable support for LE CoC");
This page took 0.249061 seconds and 5 git commands to generate.