NFC: Fix LLCP sockets releasing path
[deliverable/linux.git] / net / nfc / llcp / commands.c
CommitLineData
d646960f
SO
1/*
2 * Copyright (C) 2011 Intel Corporation. All rights reserved.
3 *
4 * This program is free software; you can redistribute it and/or modify
5 * it under the terms of the GNU General Public License as published by
6 * the Free Software Foundation; either version 2 of the License, or
7 * (at your option) any later version.
8 *
9 * This program is distributed in the hope that it will be useful,
10 * but WITHOUT ANY WARRANTY; without even the implied warranty of
11 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
12 * GNU General Public License for more details.
13 *
14 * You should have received a copy of the GNU General Public License
15 * along with this program; if not, write to the
16 * Free Software Foundation, Inc.,
17 * 59 Temple Place - Suite 330, Boston, MA 02111-1307, USA.
18 */
19
20#define pr_fmt(fmt) "llcp: %s: " fmt, __func__
21
22#include <linux/init.h>
23#include <linux/kernel.h>
24#include <linux/module.h>
25#include <linux/nfc.h>
26
27#include <net/nfc/nfc.h>
28
29#include "../nfc.h"
30#include "llcp.h"
31
32static u8 llcp_tlv_length[LLCP_TLV_MAX] = {
33 0,
34 1, /* VERSION */
35 2, /* MIUX */
36 2, /* WKS */
37 1, /* LTO */
38 1, /* RW */
39 0, /* SN */
40 1, /* OPT */
41 0, /* SDREQ */
42 2, /* SDRES */
43
44};
45
46static u8 llcp_tlv8(u8 *tlv, u8 type)
47{
48 if (tlv[0] != type || tlv[1] != llcp_tlv_length[tlv[0]])
49 return 0;
50
51 return tlv[2];
52}
53
54static u8 llcp_tlv16(u8 *tlv, u8 type)
55{
56 if (tlv[0] != type || tlv[1] != llcp_tlv_length[tlv[0]])
57 return 0;
58
59 return be16_to_cpu(*((__be16 *)(tlv + 2)));
60}
61
62
63static u8 llcp_tlv_version(u8 *tlv)
64{
65 return llcp_tlv8(tlv, LLCP_TLV_VERSION);
66}
67
68static u16 llcp_tlv_miux(u8 *tlv)
69{
70 return llcp_tlv16(tlv, LLCP_TLV_MIUX) & 0x7f;
71}
72
73static u16 llcp_tlv_wks(u8 *tlv)
74{
75 return llcp_tlv16(tlv, LLCP_TLV_WKS);
76}
77
78static u16 llcp_tlv_lto(u8 *tlv)
79{
80 return llcp_tlv8(tlv, LLCP_TLV_LTO);
81}
82
83static u8 llcp_tlv_opt(u8 *tlv)
84{
85 return llcp_tlv8(tlv, LLCP_TLV_OPT);
86}
87
88static u8 llcp_tlv_rw(u8 *tlv)
89{
90 return llcp_tlv8(tlv, LLCP_TLV_RW) & 0xf;
91}
92
93u8 *nfc_llcp_build_tlv(u8 type, u8 *value, u8 value_length, u8 *tlv_length)
94{
95 u8 *tlv, length;
96
97 pr_debug("type %d\n", type);
98
99 if (type >= LLCP_TLV_MAX)
100 return NULL;
101
102 length = llcp_tlv_length[type];
103 if (length == 0 && value_length == 0)
104 return NULL;
105 else
106 length = value_length;
107
108 *tlv_length = 2 + length;
109 tlv = kzalloc(2 + length, GFP_KERNEL);
110 if (tlv == NULL)
111 return tlv;
112
113 tlv[0] = type;
114 tlv[1] = length;
115 memcpy(tlv + 2, value, length);
116
117 return tlv;
118}
119
120int nfc_llcp_parse_tlv(struct nfc_llcp_local *local,
121 u8 *tlv_array, u16 tlv_array_len)
122{
123 u8 *tlv = tlv_array, type, length, offset = 0;
124
125 pr_debug("TLV array length %d\n", tlv_array_len);
126
127 if (local == NULL)
128 return -ENODEV;
129
130 while (offset < tlv_array_len) {
131 type = tlv[0];
132 length = tlv[1];
133
134 pr_debug("type 0x%x length %d\n", type, length);
135
136 switch (type) {
137 case LLCP_TLV_VERSION:
138 local->remote_version = llcp_tlv_version(tlv);
139 break;
140 case LLCP_TLV_MIUX:
141 local->remote_miu = llcp_tlv_miux(tlv) + 128;
142 break;
143 case LLCP_TLV_WKS:
144 local->remote_wks = llcp_tlv_wks(tlv);
145 break;
146 case LLCP_TLV_LTO:
147 local->remote_lto = llcp_tlv_lto(tlv) * 10;
148 break;
149 case LLCP_TLV_OPT:
150 local->remote_opt = llcp_tlv_opt(tlv);
151 break;
152 case LLCP_TLV_RW:
153 local->remote_rw = llcp_tlv_rw(tlv);
154 break;
9dda50f4
SO
155 case LLCP_TLV_SN:
156 break;
d646960f
SO
157 default:
158 pr_err("Invalid gt tlv value 0x%x\n", type);
159 break;
160 }
161
162 offset += length + 2;
163 tlv += length + 2;
164 }
165
166 pr_debug("version 0x%x miu %d lto %d opt 0x%x wks 0x%x rw %d\n",
167 local->remote_version, local->remote_miu,
168 local->remote_lto, local->remote_opt,
169 local->remote_wks, local->remote_rw);
170
171 return 0;
172}
173
174static struct sk_buff *llcp_add_header(struct sk_buff *pdu,
175 u8 dsap, u8 ssap, u8 ptype)
176{
177 u8 header[2];
178
179 pr_debug("ptype 0x%x dsap 0x%x ssap 0x%x\n", ptype, dsap, ssap);
180
181 header[0] = (u8)((dsap << 2) | (ptype >> 2));
182 header[1] = (u8)((ptype << 6) | ssap);
183
184 pr_debug("header 0x%x 0x%x\n", header[0], header[1]);
185
186 memcpy(skb_put(pdu, LLCP_HEADER_SIZE), header, LLCP_HEADER_SIZE);
187
188 return pdu;
189}
190
191static struct sk_buff *llcp_add_tlv(struct sk_buff *pdu, u8 *tlv, u8 tlv_length)
192{
193 /* XXX Add an skb length check */
194
195 if (tlv == NULL)
196 return NULL;
197
198 memcpy(skb_put(pdu, tlv_length), tlv, tlv_length);
199
200 return pdu;
201}
202
203static struct sk_buff *llcp_allocate_pdu(struct nfc_llcp_sock *sock,
204 u8 cmd, u16 size)
205{
206 struct sk_buff *skb;
207 int err;
208
209 if (sock->ssap == 0)
210 return NULL;
211
212 skb = nfc_alloc_send_skb(sock->dev, &sock->sk, MSG_DONTWAIT,
213 size + LLCP_HEADER_SIZE, &err);
214 if (skb == NULL) {
215 pr_err("Could not allocate PDU\n");
216 return NULL;
217 }
218
219 skb = llcp_add_header(skb, sock->dsap, sock->ssap, cmd);
220
221 return skb;
222}
223
224int nfc_llcp_disconnect(struct nfc_llcp_sock *sock)
225{
226 struct sk_buff *skb;
227 struct nfc_dev *dev;
228 struct nfc_llcp_local *local;
229 u16 size = 0;
230
231 pr_debug("Sending DISC\n");
232
233 local = sock->local;
234 if (local == NULL)
235 return -ENODEV;
236
237 dev = sock->dev;
238 if (dev == NULL)
239 return -ENODEV;
240
241 size += LLCP_HEADER_SIZE;
242 size += dev->tx_headroom + dev->tx_tailroom + NFC_HEADER_SIZE;
243
244 skb = alloc_skb(size, GFP_ATOMIC);
245 if (skb == NULL)
246 return -ENOMEM;
247
248 skb_reserve(skb, dev->tx_headroom + NFC_HEADER_SIZE);
249
250 skb = llcp_add_header(skb, sock->ssap, sock->dsap, LLCP_PDU_DISC);
251
252 skb_queue_tail(&local->tx_queue, skb);
253
254 return 0;
255}
256
257int nfc_llcp_send_symm(struct nfc_dev *dev)
258{
259 struct sk_buff *skb;
260 struct nfc_llcp_local *local;
261 u16 size = 0;
262
263 pr_debug("Sending SYMM\n");
264
265 local = nfc_llcp_find_local(dev);
266 if (local == NULL)
267 return -ENODEV;
268
269 size += LLCP_HEADER_SIZE;
270 size += dev->tx_headroom + dev->tx_tailroom + NFC_HEADER_SIZE;
271
272 skb = alloc_skb(size, GFP_KERNEL);
273 if (skb == NULL)
274 return -ENOMEM;
275
276 skb_reserve(skb, dev->tx_headroom + NFC_HEADER_SIZE);
277
278 skb = llcp_add_header(skb, 0, 0, LLCP_PDU_SYMM);
279
280 return nfc_data_exchange(dev, local->target_idx, skb,
281 nfc_llcp_recv, local);
282}
283
284int nfc_llcp_send_connect(struct nfc_llcp_sock *sock)
285{
286 struct nfc_llcp_local *local;
287 struct sk_buff *skb;
288 u8 *service_name_tlv = NULL, service_name_tlv_length;
eda21f16
SO
289 u8 *miux_tlv = NULL, miux_tlv_length;
290 u8 *rw_tlv = NULL, rw_tlv_length, rw;
291 __be16 miux;
d646960f
SO
292 int err;
293 u16 size = 0;
294
295 pr_debug("Sending CONNECT\n");
296
297 local = sock->local;
298 if (local == NULL)
299 return -ENODEV;
300
301 if (sock->service_name != NULL) {
302 service_name_tlv = nfc_llcp_build_tlv(LLCP_TLV_SN,
303 sock->service_name,
304 sock->service_name_len,
305 &service_name_tlv_length);
306 size += service_name_tlv_length;
307 }
308
eda21f16
SO
309 miux = cpu_to_be16(LLCP_MAX_MIUX);
310 miux_tlv = nfc_llcp_build_tlv(LLCP_TLV_MIUX, (u8 *)&miux, 0, &miux_tlv_length);
311 size += miux_tlv_length;
312
313 rw = LLCP_MAX_RW;
314 rw_tlv = nfc_llcp_build_tlv(LLCP_TLV_RW, &rw, 0, &rw_tlv_length);
315 size += rw_tlv_length;
316
d646960f
SO
317 pr_debug("SKB size %d SN length %zu\n", size, sock->service_name_len);
318
319 skb = llcp_allocate_pdu(sock, LLCP_PDU_CONNECT, size);
320 if (skb == NULL) {
321 err = -ENOMEM;
322 goto error_tlv;
323 }
324
325 if (service_name_tlv != NULL)
326 skb = llcp_add_tlv(skb, service_name_tlv,
327 service_name_tlv_length);
328
eda21f16
SO
329 skb = llcp_add_tlv(skb, miux_tlv, miux_tlv_length);
330 skb = llcp_add_tlv(skb, rw_tlv, rw_tlv_length);
331
d646960f
SO
332 skb_queue_tail(&local->tx_queue, skb);
333
334 return 0;
335
336error_tlv:
337 pr_err("error %d\n", err);
338
339 kfree(service_name_tlv);
eda21f16
SO
340 kfree(miux_tlv);
341 kfree(rw_tlv);
d646960f
SO
342
343 return err;
344}
345
346int nfc_llcp_send_cc(struct nfc_llcp_sock *sock)
347{
348 struct nfc_llcp_local *local;
349 struct sk_buff *skb;
eda21f16
SO
350 u8 *miux_tlv = NULL, miux_tlv_length;
351 u8 *rw_tlv = NULL, rw_tlv_length, rw;
352 __be16 miux;
353 int err;
354 u16 size = 0;
d646960f
SO
355
356 pr_debug("Sending CC\n");
357
358 local = sock->local;
359 if (local == NULL)
360 return -ENODEV;
361
eda21f16
SO
362 miux = cpu_to_be16(LLCP_MAX_MIUX);
363 miux_tlv = nfc_llcp_build_tlv(LLCP_TLV_MIUX, (u8 *)&miux, 0, &miux_tlv_length);
364 size += miux_tlv_length;
365
366 rw = LLCP_MAX_RW;
367 rw_tlv = nfc_llcp_build_tlv(LLCP_TLV_RW, &rw, 0, &rw_tlv_length);
368 size += rw_tlv_length;
369
370 skb = llcp_allocate_pdu(sock, LLCP_PDU_CC, size);
371 if (skb == NULL) {
372 err = -ENOMEM;
373 goto error_tlv;
374 }
375
376 skb = llcp_add_tlv(skb, miux_tlv, miux_tlv_length);
377 skb = llcp_add_tlv(skb, rw_tlv, rw_tlv_length);
d646960f
SO
378
379 skb_queue_tail(&local->tx_queue, skb);
380
381 return 0;
eda21f16
SO
382
383error_tlv:
384 pr_err("error %d\n", err);
385
386 kfree(miux_tlv);
387 kfree(rw_tlv);
388
389 return err;
d646960f
SO
390}
391
392int nfc_llcp_send_dm(struct nfc_llcp_local *local, u8 ssap, u8 dsap, u8 reason)
393{
394 struct sk_buff *skb;
395 struct nfc_dev *dev;
396 u16 size = 1; /* Reason code */
397
398 pr_debug("Sending DM reason 0x%x\n", reason);
399
400 if (local == NULL)
401 return -ENODEV;
402
403 dev = local->dev;
404 if (dev == NULL)
405 return -ENODEV;
406
407 size += LLCP_HEADER_SIZE;
408 size += dev->tx_headroom + dev->tx_tailroom + NFC_HEADER_SIZE;
409
410 skb = alloc_skb(size, GFP_KERNEL);
411 if (skb == NULL)
412 return -ENOMEM;
413
414 skb_reserve(skb, dev->tx_headroom + NFC_HEADER_SIZE);
415
416 skb = llcp_add_header(skb, ssap, dsap, LLCP_PDU_DM);
417
418 memcpy(skb_put(skb, 1), &reason, 1);
419
420 skb_queue_head(&local->tx_queue, skb);
421
422 return 0;
423}
424
425int nfc_llcp_send_disconnect(struct nfc_llcp_sock *sock)
426{
427 struct sk_buff *skb;
428 struct nfc_llcp_local *local;
429
430 pr_debug("Send DISC\n");
431
432 local = sock->local;
433 if (local == NULL)
434 return -ENODEV;
435
436 skb = llcp_allocate_pdu(sock, LLCP_PDU_DISC, 0);
437 if (skb == NULL)
438 return -ENOMEM;
439
440 skb_queue_head(&local->tx_queue, skb);
441
442 return 0;
443}
53a0ac2e
SO
444
445int nfc_llcp_send_i_frame(struct nfc_llcp_sock *sock,
446 struct msghdr *msg, size_t len)
447{
448 struct sk_buff *pdu;
e65b0f46
SO
449 struct sock *sk = &sock->sk;
450 struct nfc_llcp_local *local;
451 size_t frag_len = 0, remaining_len;
452 u8 *msg_data, *msg_ptr;
53a0ac2e 453
e65b0f46 454 pr_debug("Send I frame len %zd\n", len);
53a0ac2e 455
e65b0f46
SO
456 local = sock->local;
457 if (local == NULL)
458 return -ENODEV;
53a0ac2e 459
e65b0f46
SO
460 msg_data = kzalloc(len, GFP_KERNEL);
461 if (msg_data == NULL)
462 return -ENOMEM;
53a0ac2e 463
e65b0f46
SO
464 if (memcpy_fromiovec(msg_data, msg->msg_iov, len)) {
465 kfree(msg_data);
466 return -EFAULT;
53a0ac2e
SO
467 }
468
e65b0f46
SO
469 remaining_len = len;
470 msg_ptr = msg_data;
471
472 while (remaining_len > 0) {
473
474 frag_len = min_t(u16, local->remote_miu, remaining_len);
53a0ac2e 475
e65b0f46
SO
476 pr_debug("Fragment %zd bytes remaining %zd",
477 frag_len, remaining_len);
53a0ac2e 478
e65b0f46
SO
479 pdu = llcp_allocate_pdu(sock, LLCP_PDU_I,
480 frag_len + LLCP_SEQUENCE_SIZE);
481 if (pdu == NULL)
482 return -ENOMEM;
483
484 skb_put(pdu, LLCP_SEQUENCE_SIZE);
485
486 memcpy(skb_put(pdu, frag_len), msg_ptr, frag_len);
487
488 skb_queue_head(&sock->tx_queue, pdu);
489
490 lock_sock(sk);
491
492 nfc_llcp_queue_i_frames(sock);
493
494 release_sock(sk);
495
496 remaining_len -= frag_len;
497 msg_ptr += len;
498 }
53a0ac2e 499
e65b0f46 500 kfree(msg_data);
53a0ac2e
SO
501
502 return 0;
503}
d094afa1
SO
504
505int nfc_llcp_send_rr(struct nfc_llcp_sock *sock)
506{
507 struct sk_buff *skb;
508 struct nfc_llcp_local *local;
509
510 pr_debug("Send rr nr %d\n", sock->recv_n);
511
512 local = sock->local;
513 if (local == NULL)
514 return -ENODEV;
515
516 skb = llcp_allocate_pdu(sock, LLCP_PDU_RR, LLCP_SEQUENCE_SIZE);
517 if (skb == NULL)
518 return -ENOMEM;
519
520 skb_put(skb, LLCP_SEQUENCE_SIZE);
521
522 skb->data[2] = sock->recv_n % 16;
523
524 skb_queue_head(&local->tx_queue, skb);
525
526 return 0;
527}
This page took 0.060063 seconds and 5 git commands to generate.