Bluetooth: Fix not closing SCO sockets in the BT_CONNECT2 state
[deliverable/linux.git] / net / bluetooth / sco.c
CommitLineData
8e87d142 1/*
1da177e4
LT
2 BlueZ - Bluetooth protocol stack for Linux
3 Copyright (C) 2000-2001 Qualcomm Incorporated
4
5 Written 2000,2001 by Maxim Krasnyansky <maxk@qualcomm.com>
6
7 This program is free software; you can redistribute it and/or modify
8 it under the terms of the GNU General Public License version 2 as
9 published by the Free Software Foundation;
10
11 THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS
12 OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
13 FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT OF THIRD PARTY RIGHTS.
14 IN NO EVENT SHALL THE COPYRIGHT HOLDER(S) AND AUTHOR(S) BE LIABLE FOR ANY
8e87d142
YH
15 CLAIM, OR ANY SPECIAL INDIRECT OR CONSEQUENTIAL DAMAGES, OR ANY DAMAGES
16 WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
17 ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
1da177e4
LT
18 OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
19
8e87d142
YH
20 ALL LIABILITY, INCLUDING LIABILITY FOR INFRINGEMENT OF ANY PATENTS,
21 COPYRIGHTS, TRADEMARKS OR OTHER RIGHTS, RELATING TO USE OF THIS
1da177e4
LT
22 SOFTWARE IS DISCLAIMED.
23*/
24
25/* Bluetooth SCO sockets. */
26
1da177e4 27#include <linux/module.h>
aef7d97c
MH
28#include <linux/debugfs.h>
29#include <linux/seq_file.h>
1da177e4
LT
30
31#include <net/bluetooth/bluetooth.h>
32#include <net/bluetooth/hci_core.h>
33#include <net/bluetooth/sco.h>
34
eb939922 35static bool disable_esco;
1da177e4 36
90ddc4f0 37static const struct proto_ops sco_sock_ops;
1da177e4
LT
38
39static struct bt_sock_list sco_sk_list = {
d5fb2962 40 .lock = __RW_LOCK_UNLOCKED(sco_sk_list.lock)
1da177e4
LT
41};
42
43static void __sco_chan_add(struct sco_conn *conn, struct sock *sk, struct sock *parent);
44static void sco_chan_del(struct sock *sk, int err);
45
1da177e4
LT
46static void sco_sock_close(struct sock *sk);
47static void sco_sock_kill(struct sock *sk);
48
49/* ---- SCO timers ---- */
50static void sco_sock_timeout(unsigned long arg)
51{
52 struct sock *sk = (struct sock *) arg;
53
54 BT_DBG("sock %p state %d", sk, sk->sk_state);
55
56 bh_lock_sock(sk);
57 sk->sk_err = ETIMEDOUT;
58 sk->sk_state_change(sk);
59 bh_unlock_sock(sk);
60
61 sco_sock_kill(sk);
62 sock_put(sk);
63}
64
65static void sco_sock_set_timer(struct sock *sk, long timeout)
66{
67 BT_DBG("sock %p state %d timeout %ld", sk, sk->sk_state, timeout);
68 sk_reset_timer(sk, &sk->sk_timer, jiffies + timeout);
69}
70
71static void sco_sock_clear_timer(struct sock *sk)
72{
73 BT_DBG("sock %p state %d", sk, sk->sk_state);
74 sk_stop_timer(sk, &sk->sk_timer);
75}
76
1da177e4 77/* ---- SCO connections ---- */
519e42b3 78static struct sco_conn *sco_conn_add(struct hci_conn *hcon)
1da177e4
LT
79{
80 struct hci_dev *hdev = hcon->hdev;
25ea6db0 81 struct sco_conn *conn = hcon->sco_data;
1da177e4 82
519e42b3 83 if (conn)
1da177e4
LT
84 return conn;
85
25ea6db0
MH
86 conn = kzalloc(sizeof(struct sco_conn), GFP_ATOMIC);
87 if (!conn)
1da177e4 88 return NULL;
1da177e4
LT
89
90 spin_lock_init(&conn->lock);
91
92 hcon->sco_data = conn;
93 conn->hcon = hcon;
94
95 conn->src = &hdev->bdaddr;
96 conn->dst = &hcon->dst;
97
98 if (hdev->sco_mtu > 0)
99 conn->mtu = hdev->sco_mtu;
100 else
101 conn->mtu = 60;
102
103 BT_DBG("hcon %p conn %p", hcon, conn);
25ea6db0 104
1da177e4
LT
105 return conn;
106}
107
6039aa73 108static struct sock *sco_chan_get(struct sco_conn *conn)
1da177e4
LT
109{
110 struct sock *sk = NULL;
111 sco_conn_lock(conn);
112 sk = conn->sk;
113 sco_conn_unlock(conn);
114 return sk;
115}
116
117static int sco_conn_del(struct hci_conn *hcon, int err)
118{
735cbc47 119 struct sco_conn *conn = hcon->sco_data;
1da177e4
LT
120 struct sock *sk;
121
735cbc47 122 if (!conn)
1da177e4
LT
123 return 0;
124
125 BT_DBG("hcon %p conn %p, err %d", hcon, conn, err);
126
127 /* Kill socket */
735cbc47
AE
128 sk = sco_chan_get(conn);
129 if (sk) {
1da177e4
LT
130 bh_lock_sock(sk);
131 sco_sock_clear_timer(sk);
132 sco_chan_del(sk, err);
133 bh_unlock_sock(sk);
134 sco_sock_kill(sk);
135 }
136
137 hcon->sco_data = NULL;
138 kfree(conn);
139 return 0;
140}
141
6039aa73
GP
142static int sco_chan_add(struct sco_conn *conn, struct sock *sk,
143 struct sock *parent)
1da177e4
LT
144{
145 int err = 0;
146
147 sco_conn_lock(conn);
b9dbdbc1 148 if (conn->sk)
1da177e4 149 err = -EBUSY;
b9dbdbc1 150 else
1da177e4 151 __sco_chan_add(conn, sk, parent);
b9dbdbc1 152
1da177e4
LT
153 sco_conn_unlock(conn);
154 return err;
155}
156
157static int sco_connect(struct sock *sk)
158{
159 bdaddr_t *src = &bt_sk(sk)->src;
160 bdaddr_t *dst = &bt_sk(sk)->dst;
161 struct sco_conn *conn;
162 struct hci_conn *hcon;
163 struct hci_dev *hdev;
b6a0dc82 164 int err, type;
1da177e4 165
6ed93dc6 166 BT_DBG("%pMR -> %pMR", src, dst);
1da177e4 167
735cbc47
AE
168 hdev = hci_get_route(dst, src);
169 if (!hdev)
1da177e4
LT
170 return -EHOSTUNREACH;
171
09fd0de5 172 hci_dev_lock(hdev);
1da177e4 173
7cb127d5
MH
174 if (lmp_esco_capable(hdev) && !disable_esco)
175 type = ESCO_LINK;
176 else
177 type = SCO_LINK;
b6a0dc82 178
b12f62cf
AG
179 hcon = hci_connect(hdev, type, dst, BDADDR_BREDR, BT_SECURITY_LOW,
180 HCI_AT_NO_BONDING);
30e76272
VT
181 if (IS_ERR(hcon)) {
182 err = PTR_ERR(hcon);
1da177e4 183 goto done;
30e76272 184 }
1da177e4 185
519e42b3 186 conn = sco_conn_add(hcon);
1da177e4
LT
187 if (!conn) {
188 hci_conn_put(hcon);
30e76272 189 err = -ENOMEM;
1da177e4
LT
190 goto done;
191 }
192
193 /* Update source addr of the socket */
194 bacpy(src, conn->src);
195
196 err = sco_chan_add(conn, sk, NULL);
197 if (err)
198 goto done;
199
200 if (hcon->state == BT_CONNECTED) {
201 sco_sock_clear_timer(sk);
202 sk->sk_state = BT_CONNECTED;
203 } else {
204 sk->sk_state = BT_CONNECT;
205 sco_sock_set_timer(sk, sk->sk_sndtimeo);
206 }
b6a0dc82 207
1da177e4 208done:
09fd0de5 209 hci_dev_unlock(hdev);
1da177e4
LT
210 hci_dev_put(hdev);
211 return err;
212}
213
6039aa73 214static int sco_send_frame(struct sock *sk, struct msghdr *msg, int len)
1da177e4
LT
215{
216 struct sco_conn *conn = sco_pi(sk)->conn;
217 struct sk_buff *skb;
088ce088 218 int err;
1da177e4
LT
219
220 /* Check outgoing MTU */
221 if (len > conn->mtu)
222 return -EINVAL;
223
224 BT_DBG("sk %p len %d", sk, len);
225
088ce088 226 skb = bt_skb_send_alloc(sk, len, msg->msg_flags & MSG_DONTWAIT, &err);
b9dbdbc1 227 if (!skb)
1da177e4
LT
228 return err;
229
088ce088 230 if (memcpy_fromiovec(skb_put(skb, len), msg->msg_iov, len)) {
b9dbdbc1
GP
231 kfree_skb(skb);
232 return -EFAULT;
1da177e4
LT
233 }
234
0d861d8b 235 hci_send_sco(conn->hcon, skb);
1da177e4 236
088ce088 237 return len;
1da177e4
LT
238}
239
6039aa73 240static void sco_recv_frame(struct sco_conn *conn, struct sk_buff *skb)
1da177e4
LT
241{
242 struct sock *sk = sco_chan_get(conn);
243
244 if (!sk)
245 goto drop;
246
247 BT_DBG("sk %p len %d", sk, skb->len);
248
249 if (sk->sk_state != BT_CONNECTED)
250 goto drop;
251
252 if (!sock_queue_rcv_skb(sk, skb))
253 return;
254
255drop:
256 kfree_skb(skb);
1da177e4
LT
257}
258
259/* -------- Socket interface ---------- */
fb334059 260static struct sock *__sco_get_sock_listen_by_addr(bdaddr_t *ba)
1da177e4 261{
1da177e4 262 struct hlist_node *node;
fb334059
MH
263 struct sock *sk;
264
265 sk_for_each(sk, node, &sco_sk_list.head) {
266 if (sk->sk_state != BT_LISTEN)
267 continue;
1da177e4 268
1da177e4 269 if (!bacmp(&bt_sk(sk)->src, ba))
fb334059
MH
270 return sk;
271 }
272
273 return NULL;
1da177e4
LT
274}
275
276/* Find socket listening on source bdaddr.
277 * Returns closest match.
278 */
279static struct sock *sco_get_sock_listen(bdaddr_t *src)
280{
281 struct sock *sk = NULL, *sk1 = NULL;
282 struct hlist_node *node;
283
284 read_lock(&sco_sk_list.lock);
285
286 sk_for_each(sk, node, &sco_sk_list.head) {
287 if (sk->sk_state != BT_LISTEN)
288 continue;
289
290 /* Exact match. */
291 if (!bacmp(&bt_sk(sk)->src, src))
292 break;
293
294 /* Closest match */
295 if (!bacmp(&bt_sk(sk)->src, BDADDR_ANY))
296 sk1 = sk;
297 }
298
299 read_unlock(&sco_sk_list.lock);
300
301 return node ? sk : sk1;
302}
303
304static void sco_sock_destruct(struct sock *sk)
305{
306 BT_DBG("sk %p", sk);
307
308 skb_queue_purge(&sk->sk_receive_queue);
309 skb_queue_purge(&sk->sk_write_queue);
310}
311
312static void sco_sock_cleanup_listen(struct sock *parent)
313{
314 struct sock *sk;
315
316 BT_DBG("parent %p", parent);
317
318 /* Close not yet accepted channels */
319 while ((sk = bt_accept_dequeue(parent, NULL))) {
320 sco_sock_close(sk);
321 sco_sock_kill(sk);
322 }
323
324 parent->sk_state = BT_CLOSED;
325 sock_set_flag(parent, SOCK_ZAPPED);
326}
327
328/* Kill socket (only if zapped and orphan)
329 * Must be called on unlocked socket.
330 */
331static void sco_sock_kill(struct sock *sk)
332{
333 if (!sock_flag(sk, SOCK_ZAPPED) || sk->sk_socket)
334 return;
335
336 BT_DBG("sk %p state %d", sk, sk->sk_state);
337
338 /* Kill poor orphan */
339 bt_sock_unlink(&sco_sk_list, sk);
340 sock_set_flag(sk, SOCK_DEAD);
341 sock_put(sk);
342}
343
fd0b3ff7 344static void __sco_sock_close(struct sock *sk)
1da177e4 345{
fd0b3ff7 346 BT_DBG("sk %p state %d socket %p", sk, sk->sk_state, sk->sk_socket);
1da177e4
LT
347
348 switch (sk->sk_state) {
349 case BT_LISTEN:
350 sco_sock_cleanup_listen(sk);
351 break;
352
353 case BT_CONNECTED:
354 case BT_CONFIG:
b7e98b51 355 if (sco_pi(sk)->conn->hcon) {
4a77708b
LAD
356 sk->sk_state = BT_DISCONN;
357 sco_sock_set_timer(sk, SCO_DISCONN_TIMEOUT);
358 hci_conn_put(sco_pi(sk)->conn->hcon);
359 sco_pi(sk)->conn->hcon = NULL;
360 } else
361 sco_chan_del(sk, ECONNRESET);
362 break;
363
eb20ff9c 364 case BT_CONNECT2:
1da177e4
LT
365 case BT_CONNECT:
366 case BT_DISCONN:
367 sco_chan_del(sk, ECONNRESET);
368 break;
369
370 default:
371 sock_set_flag(sk, SOCK_ZAPPED);
372 break;
3ff50b79 373 }
fd0b3ff7 374}
1da177e4 375
fd0b3ff7
MH
376/* Must be called on unlocked socket. */
377static void sco_sock_close(struct sock *sk)
378{
379 sco_sock_clear_timer(sk);
380 lock_sock(sk);
381 __sco_sock_close(sk);
1da177e4 382 release_sock(sk);
1da177e4
LT
383 sco_sock_kill(sk);
384}
385
386static void sco_sock_init(struct sock *sk, struct sock *parent)
387{
388 BT_DBG("sk %p", sk);
389
6230c9b4 390 if (parent) {
1da177e4 391 sk->sk_type = parent->sk_type;
20714bfe 392 bt_sk(sk)->flags = bt_sk(parent)->flags;
6230c9b4
PM
393 security_sk_clone(parent, sk);
394 }
1da177e4
LT
395}
396
397static struct proto sco_proto = {
398 .name = "SCO",
399 .owner = THIS_MODULE,
400 .obj_size = sizeof(struct sco_pinfo)
401};
402
1b8d7ae4 403static struct sock *sco_sock_alloc(struct net *net, struct socket *sock, int proto, gfp_t prio)
1da177e4
LT
404{
405 struct sock *sk;
406
6257ff21 407 sk = sk_alloc(net, PF_BLUETOOTH, prio, &sco_proto);
1da177e4
LT
408 if (!sk)
409 return NULL;
410
411 sock_init_data(sock, sk);
412 INIT_LIST_HEAD(&bt_sk(sk)->accept_q);
413
414 sk->sk_destruct = sco_sock_destruct;
415 sk->sk_sndtimeo = SCO_CONN_TIMEOUT;
416
417 sock_reset_flag(sk, SOCK_ZAPPED);
418
419 sk->sk_protocol = proto;
420 sk->sk_state = BT_OPEN;
421
b24b8a24 422 setup_timer(&sk->sk_timer, sco_sock_timeout, (unsigned long)sk);
1da177e4
LT
423
424 bt_sock_link(&sco_sk_list, sk);
425 return sk;
426}
427
3f378b68
EP
428static int sco_sock_create(struct net *net, struct socket *sock, int protocol,
429 int kern)
1da177e4
LT
430{
431 struct sock *sk;
432
433 BT_DBG("sock %p", sock);
434
435 sock->state = SS_UNCONNECTED;
436
437 if (sock->type != SOCK_SEQPACKET)
438 return -ESOCKTNOSUPPORT;
439
440 sock->ops = &sco_sock_ops;
441
1b8d7ae4 442 sk = sco_sock_alloc(net, sock, protocol, GFP_ATOMIC);
74da626a 443 if (!sk)
1da177e4
LT
444 return -ENOMEM;
445
446 sco_sock_init(sk, NULL);
447 return 0;
448}
449
450static int sco_sock_bind(struct socket *sock, struct sockaddr *addr, int addr_len)
451{
452 struct sockaddr_sco *sa = (struct sockaddr_sco *) addr;
453 struct sock *sk = sock->sk;
1da177e4
LT
454 int err = 0;
455
6ed93dc6 456 BT_DBG("sk %p %pMR", sk, &sa->sco_bdaddr);
1da177e4
LT
457
458 if (!addr || addr->sa_family != AF_BLUETOOTH)
459 return -EINVAL;
460
461 lock_sock(sk);
462
463 if (sk->sk_state != BT_OPEN) {
464 err = -EBADFD;
465 goto done;
466 }
467
8ed21f7e
MH
468 if (sk->sk_type != SOCK_SEQPACKET) {
469 err = -EINVAL;
470 goto done;
1da177e4
LT
471 }
472
8ed21f7e
MH
473 bacpy(&bt_sk(sk)->src, &sa->sco_bdaddr);
474
475 sk->sk_state = BT_BOUND;
1da177e4
LT
476
477done:
478 release_sock(sk);
479 return err;
480}
481
482static int sco_sock_connect(struct socket *sock, struct sockaddr *addr, int alen, int flags)
483{
484 struct sockaddr_sco *sa = (struct sockaddr_sco *) addr;
485 struct sock *sk = sock->sk;
486 int err = 0;
487
488
489 BT_DBG("sk %p", sk);
490
6503d961
CG
491 if (alen < sizeof(struct sockaddr_sco) ||
492 addr->sa_family != AF_BLUETOOTH)
1da177e4
LT
493 return -EINVAL;
494
495 if (sk->sk_state != BT_OPEN && sk->sk_state != BT_BOUND)
496 return -EBADFD;
497
498 if (sk->sk_type != SOCK_SEQPACKET)
499 return -EINVAL;
500
501 lock_sock(sk);
502
503 /* Set destination address and psm */
504 bacpy(&bt_sk(sk)->dst, &sa->sco_bdaddr);
505
735cbc47
AE
506 err = sco_connect(sk);
507 if (err)
1da177e4
LT
508 goto done;
509
8e87d142 510 err = bt_sock_wait_state(sk, BT_CONNECTED,
be7c2b99 511 sock_sndtimeo(sk, flags & O_NONBLOCK));
1da177e4
LT
512
513done:
514 release_sock(sk);
515 return err;
516}
517
518static int sco_sock_listen(struct socket *sock, int backlog)
519{
520 struct sock *sk = sock->sk;
fb334059 521 bdaddr_t *src = &bt_sk(sk)->src;
1da177e4
LT
522 int err = 0;
523
524 BT_DBG("sk %p backlog %d", sk, backlog);
525
526 lock_sock(sk);
527
7d5d775a 528 if (sk->sk_state != BT_BOUND) {
1da177e4
LT
529 err = -EBADFD;
530 goto done;
531 }
532
7d5d775a
MH
533 if (sk->sk_type != SOCK_SEQPACKET) {
534 err = -EINVAL;
535 goto done;
536 }
537
fb334059
MH
538 write_lock(&sco_sk_list.lock);
539
540 if (__sco_get_sock_listen_by_addr(src)) {
541 err = -EADDRINUSE;
542 goto unlock;
543 }
544
1da177e4
LT
545 sk->sk_max_ack_backlog = backlog;
546 sk->sk_ack_backlog = 0;
fb334059 547
1da177e4
LT
548 sk->sk_state = BT_LISTEN;
549
fb334059
MH
550unlock:
551 write_unlock(&sco_sk_list.lock);
552
1da177e4
LT
553done:
554 release_sock(sk);
555 return err;
556}
557
558static int sco_sock_accept(struct socket *sock, struct socket *newsock, int flags)
559{
560 DECLARE_WAITQUEUE(wait, current);
561 struct sock *sk = sock->sk, *ch;
562 long timeo;
563 int err = 0;
564
565 lock_sock(sk);
566
1da177e4
LT
567 timeo = sock_rcvtimeo(sk, flags & O_NONBLOCK);
568
569 BT_DBG("sk %p timeo %ld", sk, timeo);
570
571 /* Wait for an incoming connection. (wake-one). */
aa395145 572 add_wait_queue_exclusive(sk_sleep(sk), &wait);
552b0d3c 573 while (1) {
1da177e4 574 set_current_state(TASK_INTERRUPTIBLE);
552b0d3c
PH
575
576 if (sk->sk_state != BT_LISTEN) {
577 err = -EBADFD;
1da177e4
LT
578 break;
579 }
580
552b0d3c
PH
581 ch = bt_accept_dequeue(sk, newsock);
582 if (ch)
583 break;
1da177e4 584
552b0d3c
PH
585 if (!timeo) {
586 err = -EAGAIN;
1da177e4
LT
587 break;
588 }
589
590 if (signal_pending(current)) {
591 err = sock_intr_errno(timeo);
592 break;
593 }
552b0d3c
PH
594
595 release_sock(sk);
596 timeo = schedule_timeout(timeo);
597 lock_sock(sk);
1da177e4 598 }
552b0d3c 599 __set_current_state(TASK_RUNNING);
aa395145 600 remove_wait_queue(sk_sleep(sk), &wait);
1da177e4
LT
601
602 if (err)
603 goto done;
604
605 newsock->state = SS_CONNECTED;
606
607 BT_DBG("new socket %p", ch);
608
609done:
610 release_sock(sk);
611 return err;
612}
613
614static int sco_sock_getname(struct socket *sock, struct sockaddr *addr, int *len, int peer)
615{
616 struct sockaddr_sco *sa = (struct sockaddr_sco *) addr;
617 struct sock *sk = sock->sk;
618
619 BT_DBG("sock %p, sk %p", sock, sk);
620
621 addr->sa_family = AF_BLUETOOTH;
622 *len = sizeof(struct sockaddr_sco);
623
624 if (peer)
625 bacpy(&sa->sco_bdaddr, &bt_sk(sk)->dst);
626 else
627 bacpy(&sa->sco_bdaddr, &bt_sk(sk)->src);
628
629 return 0;
630}
631
8e87d142 632static int sco_sock_sendmsg(struct kiocb *iocb, struct socket *sock,
1da177e4
LT
633 struct msghdr *msg, size_t len)
634{
635 struct sock *sk = sock->sk;
b9dbdbc1 636 int err;
1da177e4
LT
637
638 BT_DBG("sock %p, sk %p", sock, sk);
639
c1cbe4b7
BL
640 err = sock_error(sk);
641 if (err)
642 return err;
1da177e4
LT
643
644 if (msg->msg_flags & MSG_OOB)
645 return -EOPNOTSUPP;
646
647 lock_sock(sk);
648
649 if (sk->sk_state == BT_CONNECTED)
650 err = sco_send_frame(sk, msg, len);
651 else
652 err = -ENOTCONN;
653
654 release_sock(sk);
655 return err;
656}
657
20714bfe
FD
658static int sco_sock_recvmsg(struct kiocb *iocb, struct socket *sock,
659 struct msghdr *msg, size_t len, int flags)
660{
661 struct sock *sk = sock->sk;
662 struct sco_pinfo *pi = sco_pi(sk);
663
664 lock_sock(sk);
665
666 if (sk->sk_state == BT_CONNECT2 &&
667 test_bit(BT_SK_DEFER_SETUP, &bt_sk(sk)->flags)) {
668 hci_conn_accept(pi->conn->hcon, 0);
669 sk->sk_state = BT_CONFIG;
670
671 release_sock(sk);
672 return 0;
673 }
674
675 release_sock(sk);
676
677 return bt_sock_recvmsg(iocb, sock, msg, len, flags);
678}
679
b7058842 680static int sco_sock_setsockopt(struct socket *sock, int level, int optname, char __user *optval, unsigned int optlen)
1da177e4
LT
681{
682 struct sock *sk = sock->sk;
683 int err = 0;
b96e9c67 684 u32 opt;
1da177e4
LT
685
686 BT_DBG("sk %p", sk);
687
688 lock_sock(sk);
689
690 switch (optname) {
b96e9c67
FD
691
692 case BT_DEFER_SETUP:
693 if (sk->sk_state != BT_BOUND && sk->sk_state != BT_LISTEN) {
694 err = -EINVAL;
695 break;
696 }
697
698 if (get_user(opt, (u32 __user *) optval)) {
699 err = -EFAULT;
700 break;
701 }
702
703 if (opt)
704 set_bit(BT_SK_DEFER_SETUP, &bt_sk(sk)->flags);
705 else
706 clear_bit(BT_SK_DEFER_SETUP, &bt_sk(sk)->flags);
707 break;
708
1da177e4
LT
709 default:
710 err = -ENOPROTOOPT;
711 break;
712 }
713
714 release_sock(sk);
715 return err;
716}
717
d58daf42 718static int sco_sock_getsockopt_old(struct socket *sock, int optname, char __user *optval, int __user *optlen)
1da177e4
LT
719{
720 struct sock *sk = sock->sk;
721 struct sco_options opts;
722 struct sco_conninfo cinfo;
8e87d142 723 int len, err = 0;
1da177e4
LT
724
725 BT_DBG("sk %p", sk);
726
727 if (get_user(len, optlen))
728 return -EFAULT;
729
730 lock_sock(sk);
731
732 switch (optname) {
733 case SCO_OPTIONS:
734 if (sk->sk_state != BT_CONNECTED) {
735 err = -ENOTCONN;
736 break;
737 }
738
739 opts.mtu = sco_pi(sk)->conn->mtu;
740
741 BT_DBG("mtu %d", opts.mtu);
742
743 len = min_t(unsigned int, len, sizeof(opts));
744 if (copy_to_user(optval, (char *)&opts, len))
745 err = -EFAULT;
746
747 break;
748
749 case SCO_CONNINFO:
750 if (sk->sk_state != BT_CONNECTED) {
751 err = -ENOTCONN;
752 break;
753 }
754
c4c896e1 755 memset(&cinfo, 0, sizeof(cinfo));
1da177e4
LT
756 cinfo.hci_handle = sco_pi(sk)->conn->hcon->handle;
757 memcpy(cinfo.dev_class, sco_pi(sk)->conn->hcon->dev_class, 3);
758
759 len = min_t(unsigned int, len, sizeof(cinfo));
760 if (copy_to_user(optval, (char *)&cinfo, len))
761 err = -EFAULT;
762
763 break;
764
765 default:
766 err = -ENOPROTOOPT;
767 break;
768 }
769
770 release_sock(sk);
771 return err;
772}
773
d58daf42
MH
774static int sco_sock_getsockopt(struct socket *sock, int level, int optname, char __user *optval, int __user *optlen)
775{
776 struct sock *sk = sock->sk;
777 int len, err = 0;
778
779 BT_DBG("sk %p", sk);
780
781 if (level == SOL_SCO)
782 return sco_sock_getsockopt_old(sock, optname, optval, optlen);
783
784 if (get_user(len, optlen))
785 return -EFAULT;
786
787 lock_sock(sk);
788
789 switch (optname) {
b96e9c67
FD
790
791 case BT_DEFER_SETUP:
792 if (sk->sk_state != BT_BOUND && sk->sk_state != BT_LISTEN) {
793 err = -EINVAL;
794 break;
795 }
796
797 if (put_user(test_bit(BT_SK_DEFER_SETUP, &bt_sk(sk)->flags),
798 (u32 __user *) optval))
799 err = -EFAULT;
800
801 break;
802
d58daf42
MH
803 default:
804 err = -ENOPROTOOPT;
805 break;
806 }
807
808 release_sock(sk);
809 return err;
810}
811
fd0b3ff7
MH
812static int sco_sock_shutdown(struct socket *sock, int how)
813{
814 struct sock *sk = sock->sk;
815 int err = 0;
816
817 BT_DBG("sock %p, sk %p", sock, sk);
818
819 if (!sk)
820 return 0;
821
822 lock_sock(sk);
823 if (!sk->sk_shutdown) {
824 sk->sk_shutdown = SHUTDOWN_MASK;
825 sco_sock_clear_timer(sk);
826 __sco_sock_close(sk);
827
828 if (sock_flag(sk, SOCK_LINGER) && sk->sk_lingertime)
829 err = bt_sock_wait_state(sk, BT_CLOSED,
be7c2b99 830 sk->sk_lingertime);
fd0b3ff7
MH
831 }
832 release_sock(sk);
833 return err;
834}
835
1da177e4
LT
836static int sco_sock_release(struct socket *sock)
837{
838 struct sock *sk = sock->sk;
839 int err = 0;
840
841 BT_DBG("sock %p, sk %p", sock, sk);
842
843 if (!sk)
844 return 0;
845
846 sco_sock_close(sk);
847
848 if (sock_flag(sk, SOCK_LINGER) && sk->sk_lingertime) {
849 lock_sock(sk);
850 err = bt_sock_wait_state(sk, BT_CLOSED, sk->sk_lingertime);
851 release_sock(sk);
852 }
853
854 sock_orphan(sk);
855 sco_sock_kill(sk);
856 return err;
857}
858
859static void __sco_chan_add(struct sco_conn *conn, struct sock *sk, struct sock *parent)
860{
861 BT_DBG("conn %p", conn);
862
863 sco_pi(sk)->conn = conn;
864 conn->sk = sk;
865
866 if (parent)
867 bt_accept_enqueue(parent, sk);
868}
869
8e87d142 870/* Delete channel.
1da177e4
LT
871 * Must be called on the locked socket. */
872static void sco_chan_del(struct sock *sk, int err)
873{
874 struct sco_conn *conn;
875
876 conn = sco_pi(sk)->conn;
877
878 BT_DBG("sk %p, conn %p, err %d", sk, conn, err);
879
0b27a4b9
GP
880 if (conn) {
881 sco_conn_lock(conn);
882 conn->sk = NULL;
883 sco_pi(sk)->conn = NULL;
884 sco_conn_unlock(conn);
885
886 if (conn->hcon)
887 hci_conn_put(conn->hcon);
888 }
889
1da177e4
LT
890 sk->sk_state = BT_CLOSED;
891 sk->sk_err = err;
892 sk->sk_state_change(sk);
893
894 sock_set_flag(sk, SOCK_ZAPPED);
895}
896
897static void sco_conn_ready(struct sco_conn *conn)
898{
735cbc47
AE
899 struct sock *parent;
900 struct sock *sk = conn->sk;
1da177e4
LT
901
902 BT_DBG("conn %p", conn);
903
904 sco_conn_lock(conn);
905
735cbc47 906 if (sk) {
1da177e4
LT
907 sco_sock_clear_timer(sk);
908 bh_lock_sock(sk);
909 sk->sk_state = BT_CONNECTED;
910 sk->sk_state_change(sk);
911 bh_unlock_sock(sk);
912 } else {
913 parent = sco_get_sock_listen(conn->src);
914 if (!parent)
915 goto done;
916
917 bh_lock_sock(parent);
918
b9dbdbc1 919 sk = sco_sock_alloc(sock_net(parent), NULL,
be7c2b99 920 BTPROTO_SCO, GFP_ATOMIC);
1da177e4
LT
921 if (!sk) {
922 bh_unlock_sock(parent);
923 goto done;
924 }
925
926 sco_sock_init(sk, parent);
927
928 bacpy(&bt_sk(sk)->src, conn->src);
929 bacpy(&bt_sk(sk)->dst, conn->dst);
930
931 hci_conn_hold(conn->hcon);
932 __sco_chan_add(conn, sk, parent);
933
20714bfe
FD
934 if (test_bit(BT_SK_DEFER_SETUP, &bt_sk(parent)->flags))
935 sk->sk_state = BT_CONNECT2;
936 else
937 sk->sk_state = BT_CONNECTED;
1da177e4
LT
938
939 /* Wake up parent */
940 parent->sk_data_ready(parent, 1);
941
942 bh_unlock_sock(parent);
943 }
944
945done:
946 sco_conn_unlock(conn);
947}
948
949/* ----- SCO interface with lower layer (HCI) ----- */
20714bfe 950int sco_connect_ind(struct hci_dev *hdev, bdaddr_t *bdaddr, __u8 *flags)
1da177e4 951{
fc5fef61 952 struct sock *sk;
71aeeaa1
MH
953 struct hlist_node *node;
954 int lm = 0;
955
6ed93dc6 956 BT_DBG("hdev %s, bdaddr %pMR", hdev->name, bdaddr);
1da177e4 957
71aeeaa1
MH
958 /* Find listening sockets */
959 read_lock(&sco_sk_list.lock);
960 sk_for_each(sk, node, &sco_sk_list.head) {
961 if (sk->sk_state != BT_LISTEN)
962 continue;
963
964 if (!bacmp(&bt_sk(sk)->src, &hdev->bdaddr) ||
be7c2b99 965 !bacmp(&bt_sk(sk)->src, BDADDR_ANY)) {
71aeeaa1 966 lm |= HCI_LM_ACCEPT;
20714bfe
FD
967
968 if (test_bit(BT_SK_DEFER_SETUP, &bt_sk(sk)->flags))
969 *flags |= HCI_PROTO_DEFER;
71aeeaa1
MH
970 break;
971 }
972 }
973 read_unlock(&sco_sk_list.lock);
974
975 return lm;
1da177e4
LT
976}
977
9e664631 978void sco_connect_cfm(struct hci_conn *hcon, __u8 status)
1da177e4 979{
6ed93dc6 980 BT_DBG("hcon %p bdaddr %pMR status %d", hcon, &hcon->dst, status);
1da177e4
LT
981 if (!status) {
982 struct sco_conn *conn;
983
519e42b3 984 conn = sco_conn_add(hcon);
1da177e4
LT
985 if (conn)
986 sco_conn_ready(conn);
8e87d142 987 } else
e175072f 988 sco_conn_del(hcon, bt_to_errno(status));
1da177e4
LT
989}
990
9e664631 991void sco_disconn_cfm(struct hci_conn *hcon, __u8 reason)
1da177e4
LT
992{
993 BT_DBG("hcon %p reason %d", hcon, reason);
994
e175072f 995 sco_conn_del(hcon, bt_to_errno(reason));
1da177e4
LT
996}
997
686ebf28 998int sco_recv_scodata(struct hci_conn *hcon, struct sk_buff *skb)
1da177e4
LT
999{
1000 struct sco_conn *conn = hcon->sco_data;
1001
1002 if (!conn)
1003 goto drop;
1004
1005 BT_DBG("conn %p len %d", conn, skb->len);
1006
1007 if (skb->len) {
1008 sco_recv_frame(conn, skb);
1009 return 0;
1010 }
1011
1012drop:
8e87d142 1013 kfree_skb(skb);
1da177e4
LT
1014 return 0;
1015}
1016
aef7d97c 1017static int sco_debugfs_show(struct seq_file *f, void *p)
1da177e4
LT
1018{
1019 struct sock *sk;
1020 struct hlist_node *node;
1da177e4 1021
ee65d19e 1022 read_lock(&sco_sk_list.lock);
1da177e4 1023
be9d1227 1024 sk_for_each(sk, node, &sco_sk_list.head) {
fcb73338
AE
1025 seq_printf(f, "%pMR %pMR %d\n", &bt_sk(sk)->src,
1026 &bt_sk(sk)->dst, sk->sk_state);
be9d1227 1027 }
1da177e4 1028
ee65d19e 1029 read_unlock(&sco_sk_list.lock);
1da177e4 1030
aef7d97c 1031 return 0;
1da177e4
LT
1032}
1033
aef7d97c
MH
1034static int sco_debugfs_open(struct inode *inode, struct file *file)
1035{
1036 return single_open(file, sco_debugfs_show, inode->i_private);
1037}
1038
1039static const struct file_operations sco_debugfs_fops = {
1040 .open = sco_debugfs_open,
1041 .read = seq_read,
1042 .llseek = seq_lseek,
1043 .release = single_release,
1044};
1045
1046static struct dentry *sco_debugfs;
1da177e4 1047
90ddc4f0 1048static const struct proto_ops sco_sock_ops = {
1da177e4
LT
1049 .family = PF_BLUETOOTH,
1050 .owner = THIS_MODULE,
1051 .release = sco_sock_release,
1052 .bind = sco_sock_bind,
1053 .connect = sco_sock_connect,
1054 .listen = sco_sock_listen,
1055 .accept = sco_sock_accept,
1056 .getname = sco_sock_getname,
1057 .sendmsg = sco_sock_sendmsg,
20714bfe 1058 .recvmsg = sco_sock_recvmsg,
1da177e4 1059 .poll = bt_sock_poll,
3241ad82 1060 .ioctl = bt_sock_ioctl,
1da177e4
LT
1061 .mmap = sock_no_mmap,
1062 .socketpair = sock_no_socketpair,
fd0b3ff7 1063 .shutdown = sco_sock_shutdown,
1da177e4
LT
1064 .setsockopt = sco_sock_setsockopt,
1065 .getsockopt = sco_sock_getsockopt
1066};
1067
ec1b4cf7 1068static const struct net_proto_family sco_sock_family_ops = {
1da177e4
LT
1069 .family = PF_BLUETOOTH,
1070 .owner = THIS_MODULE,
1071 .create = sco_sock_create,
1072};
1073
64274518 1074int __init sco_init(void)
1da177e4
LT
1075{
1076 int err;
1077
1078 err = proto_register(&sco_proto, 0);
1079 if (err < 0)
1080 return err;
1081
1082 err = bt_sock_register(BTPROTO_SCO, &sco_sock_family_ops);
1083 if (err < 0) {
1084 BT_ERR("SCO socket registration failed");
1085 goto error;
1086 }
1087
de9b9212
MY
1088 err = bt_procfs_init(THIS_MODULE, &init_net, "sco", &sco_sk_list, NULL);
1089 if (err < 0) {
1090 BT_ERR("Failed to create SCO proc file");
1091 bt_sock_unregister(BTPROTO_SCO);
1092 goto error;
1093 }
1094
aef7d97c 1095 if (bt_debugfs) {
be7c2b99
GP
1096 sco_debugfs = debugfs_create_file("sco", 0444, bt_debugfs,
1097 NULL, &sco_debugfs_fops);
aef7d97c
MH
1098 if (!sco_debugfs)
1099 BT_ERR("Failed to create SCO debug file");
1100 }
1da177e4 1101
1da177e4
LT
1102 BT_INFO("SCO socket layer initialized");
1103
1104 return 0;
1105
1106error:
1107 proto_unregister(&sco_proto);
1108 return err;
1109}
1110
64274518 1111void __exit sco_exit(void)
1da177e4 1112{
de9b9212
MY
1113 bt_procfs_cleanup(&init_net, "sco");
1114
aef7d97c 1115 debugfs_remove(sco_debugfs);
1da177e4
LT
1116
1117 if (bt_sock_unregister(BTPROTO_SCO) < 0)
1118 BT_ERR("SCO socket unregistration failed");
1119
1da177e4
LT
1120 proto_unregister(&sco_proto);
1121}
1122
7cb127d5
MH
1123module_param(disable_esco, bool, 0644);
1124MODULE_PARM_DESC(disable_esco, "Disable eSCO connection creation");
This page took 0.803408 seconds and 5 git commands to generate.