NFC: Forbid LLCP service name reusing
[deliverable/linux.git] / net / nfc / llcp / llcp.c
CommitLineData
d646960f
SO
1/*
2 * Copyright (C) 2011 Intel Corporation. All rights reserved.
3 *
4 * This program is free software; you can redistribute it and/or modify
5 * it under the terms of the GNU General Public License as published by
6 * the Free Software Foundation; either version 2 of the License, or
7 * (at your option) any later version.
8 *
9 * This program is distributed in the hope that it will be useful,
10 * but WITHOUT ANY WARRANTY; without even the implied warranty of
11 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
12 * GNU General Public License for more details.
13 *
14 * You should have received a copy of the GNU General Public License
15 * along with this program; if not, write to the
16 * Free Software Foundation, Inc.,
17 * 59 Temple Place - Suite 330, Boston, MA 02111-1307, USA.
18 */
19
20#define pr_fmt(fmt) "llcp: %s: " fmt, __func__
21
22#include <linux/init.h>
23#include <linux/kernel.h>
24#include <linux/list.h>
25#include <linux/nfc.h>
26
27#include "../nfc.h"
28#include "llcp.h"
29
30static u8 llcp_magic[3] = {0x46, 0x66, 0x6d};
31
32static struct list_head llcp_devices;
33
a69f32af 34void nfc_llcp_sock_link(struct llcp_sock_list *l, struct sock *sk)
d646960f 35{
a69f32af
SO
36 write_lock(&l->lock);
37 sk_add_node(sk, &l->head);
38 write_unlock(&l->lock);
39}
d646960f 40
a69f32af
SO
41void nfc_llcp_sock_unlink(struct llcp_sock_list *l, struct sock *sk)
42{
43 write_lock(&l->lock);
44 sk_del_node_init(sk);
45 write_unlock(&l->lock);
46}
d646960f 47
4d22ea15 48static void nfc_llcp_socket_release(struct nfc_llcp_local *local, bool listen)
a69f32af
SO
49{
50 struct sock *sk;
51 struct hlist_node *node, *tmp;
52 struct nfc_llcp_sock *llcp_sock;
d646960f 53
a69f32af 54 write_lock(&local->sockets.lock);
40c75f81 55
a69f32af
SO
56 sk_for_each_safe(sk, node, tmp, &local->sockets.head) {
57 llcp_sock = nfc_llcp_sock(sk);
d646960f 58
a69f32af 59 lock_sock(sk);
d646960f 60
a69f32af
SO
61 if (sk->sk_state == LLCP_CONNECTED)
62 nfc_put_device(llcp_sock->dev);
d646960f 63
a69f32af 64 if (sk->sk_state == LLCP_LISTEN) {
d646960f
SO
65 struct nfc_llcp_sock *lsk, *n;
66 struct sock *accept_sk;
67
a69f32af 68 list_for_each_entry_safe(lsk, n, &llcp_sock->accept_queue,
427a2eb1 69 accept_queue) {
d646960f
SO
70 accept_sk = &lsk->sk;
71 lock_sock(accept_sk);
72
73 nfc_llcp_accept_unlink(accept_sk);
74
75 accept_sk->sk_state = LLCP_CLOSED;
d646960f
SO
76
77 release_sock(accept_sk);
78
79 sock_orphan(accept_sk);
80 }
4d22ea15
SO
81
82 if (listen == true) {
83 release_sock(sk);
84 continue;
85 }
d646960f
SO
86 }
87
a69f32af 88 sk->sk_state = LLCP_CLOSED;
d646960f 89
a69f32af 90 release_sock(sk);
d646960f 91
a69f32af 92 sock_orphan(sk);
40c75f81 93
a69f32af 94 sk_del_node_init(sk);
d646960f
SO
95 }
96
a69f32af 97 write_unlock(&local->sockets.lock);
d646960f
SO
98}
99
c7aa1225
SO
100struct nfc_llcp_local *nfc_llcp_local_get(struct nfc_llcp_local *local)
101{
102 kref_get(&local->ref);
103
104 return local;
105}
106
107static void local_release(struct kref *ref)
108{
109 struct nfc_llcp_local *local;
110
111 local = container_of(ref, struct nfc_llcp_local, ref);
112
113 list_del(&local->list);
4d22ea15 114 nfc_llcp_socket_release(local, false);
c7aa1225
SO
115 del_timer_sync(&local->link_timer);
116 skb_queue_purge(&local->tx_queue);
117 destroy_workqueue(local->tx_wq);
118 destroy_workqueue(local->rx_wq);
07922bb1 119 destroy_workqueue(local->timeout_wq);
c7aa1225
SO
120 kfree_skb(local->rx_pending);
121 kfree(local);
122}
123
124int nfc_llcp_local_put(struct nfc_llcp_local *local)
125{
a69f32af
SO
126 WARN_ON(local == NULL);
127
128 if (local == NULL)
129 return 0;
130
c7aa1225
SO
131 return kref_put(&local->ref, local_release);
132}
133
d646960f
SO
134static void nfc_llcp_timeout_work(struct work_struct *work)
135{
136 struct nfc_llcp_local *local = container_of(work, struct nfc_llcp_local,
427a2eb1 137 timeout_work);
d646960f
SO
138
139 nfc_dep_link_down(local->dev);
140}
141
142static void nfc_llcp_symm_timer(unsigned long data)
143{
144 struct nfc_llcp_local *local = (struct nfc_llcp_local *) data;
145
146 pr_err("SYMM timeout\n");
147
148 queue_work(local->timeout_wq, &local->timeout_work);
149}
150
151struct nfc_llcp_local *nfc_llcp_find_local(struct nfc_dev *dev)
152{
153 struct nfc_llcp_local *local, *n;
154
155 list_for_each_entry_safe(local, n, &llcp_devices, list)
156 if (local->dev == dev)
157 return local;
158
159 pr_debug("No device found\n");
160
161 return NULL;
162}
163
164static char *wks[] = {
165 NULL,
166 NULL, /* SDP */
167 "urn:nfc:sn:ip",
168 "urn:nfc:sn:obex",
169 "urn:nfc:sn:snep",
170};
171
172static int nfc_llcp_wks_sap(char *service_name, size_t service_name_len)
173{
174 int sap, num_wks;
175
176 pr_debug("%s\n", service_name);
177
178 if (service_name == NULL)
179 return -EINVAL;
180
181 num_wks = ARRAY_SIZE(wks);
182
427a2eb1 183 for (sap = 0; sap < num_wks; sap++) {
d646960f
SO
184 if (wks[sap] == NULL)
185 continue;
186
187 if (strncmp(wks[sap], service_name, service_name_len) == 0)
188 return sap;
189 }
190
191 return -EINVAL;
192}
193
194u8 nfc_llcp_get_sdp_ssap(struct nfc_llcp_local *local,
427a2eb1 195 struct nfc_llcp_sock *sock)
d646960f
SO
196{
197 mutex_lock(&local->sdp_lock);
198
199 if (sock->service_name != NULL && sock->service_name_len > 0) {
200 int ssap = nfc_llcp_wks_sap(sock->service_name,
427a2eb1 201 sock->service_name_len);
d646960f
SO
202
203 if (ssap > 0) {
204 pr_debug("WKS %d\n", ssap);
205
206 /* This is a WKS, let's check if it's free */
207 if (local->local_wks & BIT(ssap)) {
208 mutex_unlock(&local->sdp_lock);
209
210 return LLCP_SAP_MAX;
211 }
212
1762c17c 213 set_bit(ssap, &local->local_wks);
d646960f
SO
214 mutex_unlock(&local->sdp_lock);
215
216 return ssap;
217 }
218
219 /*
220 * This is not a well known service,
221 * we should try to find a local SDP free spot
222 */
223 ssap = find_first_zero_bit(&local->local_sdp, LLCP_SDP_NUM_SAP);
224 if (ssap == LLCP_SDP_NUM_SAP) {
225 mutex_unlock(&local->sdp_lock);
226
227 return LLCP_SAP_MAX;
228 }
229
230 pr_debug("SDP ssap %d\n", LLCP_WKS_NUM_SAP + ssap);
231
1762c17c 232 set_bit(ssap, &local->local_sdp);
d646960f
SO
233 mutex_unlock(&local->sdp_lock);
234
235 return LLCP_WKS_NUM_SAP + ssap;
236
237 } else if (sock->ssap != 0) {
238 if (sock->ssap < LLCP_WKS_NUM_SAP) {
1762c17c
SO
239 if (!test_bit(sock->ssap, &local->local_wks)) {
240 set_bit(sock->ssap, &local->local_wks);
d646960f
SO
241 mutex_unlock(&local->sdp_lock);
242
243 return sock->ssap;
244 }
245
246 } else if (sock->ssap < LLCP_SDP_NUM_SAP) {
1762c17c
SO
247 if (!test_bit(sock->ssap - LLCP_WKS_NUM_SAP,
248 &local->local_sdp)) {
249 set_bit(sock->ssap - LLCP_WKS_NUM_SAP,
250 &local->local_sdp);
d646960f
SO
251 mutex_unlock(&local->sdp_lock);
252
253 return sock->ssap;
254 }
255 }
256 }
257
258 mutex_unlock(&local->sdp_lock);
259
260 return LLCP_SAP_MAX;
261}
262
263u8 nfc_llcp_get_local_ssap(struct nfc_llcp_local *local)
264{
265 u8 local_ssap;
266
267 mutex_lock(&local->sdp_lock);
268
269 local_ssap = find_first_zero_bit(&local->local_sap, LLCP_LOCAL_NUM_SAP);
270 if (local_ssap == LLCP_LOCAL_NUM_SAP) {
271 mutex_unlock(&local->sdp_lock);
272 return LLCP_SAP_MAX;
273 }
274
1762c17c 275 set_bit(local_ssap, &local->local_sap);
d646960f
SO
276
277 mutex_unlock(&local->sdp_lock);
278
279 return local_ssap + LLCP_LOCAL_SAP_OFFSET;
280}
281
282void nfc_llcp_put_ssap(struct nfc_llcp_local *local, u8 ssap)
283{
284 u8 local_ssap;
285 unsigned long *sdp;
286
287 if (ssap < LLCP_WKS_NUM_SAP) {
288 local_ssap = ssap;
289 sdp = &local->local_wks;
290 } else if (ssap < LLCP_LOCAL_NUM_SAP) {
291 local_ssap = ssap - LLCP_WKS_NUM_SAP;
292 sdp = &local->local_sdp;
293 } else if (ssap < LLCP_MAX_SAP) {
294 local_ssap = ssap - LLCP_LOCAL_NUM_SAP;
295 sdp = &local->local_sap;
296 } else {
297 return;
298 }
299
300 mutex_lock(&local->sdp_lock);
301
1762c17c 302 clear_bit(local_ssap, sdp);
d646960f
SO
303
304 mutex_unlock(&local->sdp_lock);
305}
306
d646960f
SO
307static int nfc_llcp_build_gb(struct nfc_llcp_local *local)
308{
309 u8 *gb_cur, *version_tlv, version, version_length;
310 u8 *lto_tlv, lto, lto_length;
311 u8 *wks_tlv, wks_length;
56d5876a
SO
312 u8 *miux_tlv, miux_length;
313 __be16 miux;
d646960f
SO
314 u8 gb_len = 0;
315
316 version = LLCP_VERSION_11;
317 version_tlv = nfc_llcp_build_tlv(LLCP_TLV_VERSION, &version,
427a2eb1 318 1, &version_length);
d646960f
SO
319 gb_len += version_length;
320
321 /* 1500 ms */
322 lto = 150;
91b0ade1 323 lto_tlv = nfc_llcp_build_tlv(LLCP_TLV_LTO, &lto, 1, &lto_length);
d646960f
SO
324 gb_len += lto_length;
325
326 pr_debug("Local wks 0x%lx\n", local->local_wks);
327 wks_tlv = nfc_llcp_build_tlv(LLCP_TLV_WKS, (u8 *)&local->local_wks, 2,
427a2eb1 328 &wks_length);
d646960f
SO
329 gb_len += wks_length;
330
56d5876a
SO
331 miux = cpu_to_be16(LLCP_MAX_MIUX);
332 miux_tlv = nfc_llcp_build_tlv(LLCP_TLV_MIUX, (u8 *)&miux, 0,
333 &miux_length);
334 gb_len += miux_length;
335
d646960f
SO
336 gb_len += ARRAY_SIZE(llcp_magic);
337
338 if (gb_len > NFC_MAX_GT_LEN) {
339 kfree(version_tlv);
340 return -EINVAL;
341 }
342
343 gb_cur = local->gb;
344
345 memcpy(gb_cur, llcp_magic, ARRAY_SIZE(llcp_magic));
346 gb_cur += ARRAY_SIZE(llcp_magic);
347
348 memcpy(gb_cur, version_tlv, version_length);
349 gb_cur += version_length;
350
351 memcpy(gb_cur, lto_tlv, lto_length);
352 gb_cur += lto_length;
353
354 memcpy(gb_cur, wks_tlv, wks_length);
355 gb_cur += wks_length;
356
56d5876a
SO
357 memcpy(gb_cur, miux_tlv, miux_length);
358 gb_cur += miux_length;
359
d646960f
SO
360 kfree(version_tlv);
361 kfree(lto_tlv);
362
363 local->gb_len = gb_len;
364
365 return 0;
366}
367
b8e7a06d
SO
368u8 *nfc_llcp_general_bytes(struct nfc_dev *dev, size_t *general_bytes_len)
369{
370 struct nfc_llcp_local *local;
371
372 local = nfc_llcp_find_local(dev);
373 if (local == NULL) {
374 *general_bytes_len = 0;
375 return NULL;
376 }
377
378 nfc_llcp_build_gb(local);
379
380 *general_bytes_len = local->gb_len;
381
382 return local->gb;
383}
384
d646960f
SO
385int nfc_llcp_set_remote_gb(struct nfc_dev *dev, u8 *gb, u8 gb_len)
386{
387 struct nfc_llcp_local *local = nfc_llcp_find_local(dev);
388
389 if (local == NULL) {
390 pr_err("No LLCP device\n");
391 return -ENODEV;
392 }
393
394 memset(local->remote_gb, 0, NFC_MAX_GT_LEN);
395 memcpy(local->remote_gb, gb, gb_len);
396 local->remote_gb_len = gb_len;
397
427a2eb1 398 if (local->remote_gb == NULL || local->remote_gb_len == 0)
d646960f
SO
399 return -ENODEV;
400
401 if (memcmp(local->remote_gb, llcp_magic, 3)) {
402 pr_err("MAC does not support LLCP\n");
403 return -EINVAL;
404 }
405
7a06e586
SO
406 return nfc_llcp_parse_gb_tlv(local,
407 &local->remote_gb[3],
408 local->remote_gb_len - 3);
d646960f
SO
409}
410
d646960f
SO
411static u8 nfc_llcp_dsap(struct sk_buff *pdu)
412{
413 return (pdu->data[0] & 0xfc) >> 2;
414}
415
416static u8 nfc_llcp_ptype(struct sk_buff *pdu)
417{
418 return ((pdu->data[0] & 0x03) << 2) | ((pdu->data[1] & 0xc0) >> 6);
419}
420
421static u8 nfc_llcp_ssap(struct sk_buff *pdu)
422{
423 return pdu->data[1] & 0x3f;
424}
425
426static u8 nfc_llcp_ns(struct sk_buff *pdu)
427{
428 return pdu->data[2] >> 4;
429}
430
431static u8 nfc_llcp_nr(struct sk_buff *pdu)
432{
433 return pdu->data[2] & 0xf;
434}
435
436static void nfc_llcp_set_nrns(struct nfc_llcp_sock *sock, struct sk_buff *pdu)
437{
279cf174 438 pdu->data[2] = (sock->send_n << 4) | (sock->recv_n);
d646960f
SO
439 sock->send_n = (sock->send_n + 1) % 16;
440 sock->recv_ack_n = (sock->recv_n - 1) % 16;
441}
442
84457960
SO
443static void nfc_llcp_tx_work(struct work_struct *work)
444{
445 struct nfc_llcp_local *local = container_of(work, struct nfc_llcp_local,
446 tx_work);
447 struct sk_buff *skb;
448 struct sock *sk;
449 struct nfc_llcp_sock *llcp_sock;
450
451 skb = skb_dequeue(&local->tx_queue);
452 if (skb != NULL) {
453 sk = skb->sk;
454 llcp_sock = nfc_llcp_sock(sk);
455 if (llcp_sock != NULL) {
456 int ret;
457
458 pr_debug("Sending pending skb\n");
459 print_hex_dump(KERN_DEBUG, "LLCP Tx: ",
460 DUMP_PREFIX_OFFSET, 16, 1,
461 skb->data, skb->len, true);
462
463 ret = nfc_data_exchange(local->dev, local->target_idx,
464 skb, nfc_llcp_recv, local);
465
466 if (!ret && nfc_llcp_ptype(skb) == LLCP_PDU_I) {
467 skb = skb_get(skb);
468 skb_queue_tail(&llcp_sock->tx_pending_queue,
469 skb);
470 }
471 } else {
472 nfc_llcp_send_symm(local->dev);
473 }
474 } else {
475 nfc_llcp_send_symm(local->dev);
476 }
477
478 mod_timer(&local->link_timer,
479 jiffies + msecs_to_jiffies(2 * local->remote_lto));
480}
481
a69f32af
SO
482static struct nfc_llcp_sock *nfc_llcp_connecting_sock_get(struct nfc_llcp_local *local,
483 u8 ssap)
484{
485 struct sock *sk;
486 struct nfc_llcp_sock *llcp_sock;
487 struct hlist_node *node;
488
489 read_lock(&local->connecting_sockets.lock);
490
491 sk_for_each(sk, node, &local->connecting_sockets.head) {
492 llcp_sock = nfc_llcp_sock(sk);
493
5a0f6f3b
SO
494 if (llcp_sock->ssap == ssap) {
495 sock_hold(&llcp_sock->sk);
a69f32af 496 goto out;
5a0f6f3b 497 }
a69f32af
SO
498 }
499
500 llcp_sock = NULL;
501
502out:
503 read_unlock(&local->connecting_sockets.lock);
504
a69f32af
SO
505 return llcp_sock;
506}
507
d646960f 508static struct nfc_llcp_sock *nfc_llcp_sock_get(struct nfc_llcp_local *local,
427a2eb1 509 u8 ssap, u8 dsap)
d646960f 510{
a69f32af
SO
511 struct sock *sk;
512 struct hlist_node *node;
513 struct nfc_llcp_sock *llcp_sock;
d646960f 514
ff353d86
SO
515 pr_debug("ssap dsap %d %d\n", ssap, dsap);
516
d646960f
SO
517 if (ssap == 0 && dsap == 0)
518 return NULL;
519
a69f32af
SO
520 read_lock(&local->sockets.lock);
521
522 llcp_sock = NULL;
d646960f 523
a69f32af
SO
524 sk_for_each(sk, node, &local->sockets.head) {
525 llcp_sock = nfc_llcp_sock(sk);
d646960f 526
a69f32af
SO
527 if (llcp_sock->ssap == ssap &&
528 llcp_sock->dsap == dsap)
529 break;
d646960f
SO
530 }
531
a69f32af
SO
532 read_unlock(&local->sockets.lock);
533
534 if (llcp_sock == NULL)
535 return NULL;
536
537 sock_hold(&llcp_sock->sk);
538
539 return llcp_sock;
540}
541
542static struct nfc_llcp_sock *nfc_llcp_sock_get_sn(struct nfc_llcp_local *local,
543 u8 *sn, size_t sn_len)
544{
545 struct sock *sk;
546 struct hlist_node *node;
547 struct nfc_llcp_sock *llcp_sock;
548
549 pr_debug("sn %zd\n", sn_len);
550
551 if (sn == NULL || sn_len == 0)
552 return NULL;
553
554 read_lock(&local->sockets.lock);
555
556 llcp_sock = NULL;
557
558 sk_for_each(sk, node, &local->sockets.head) {
559 llcp_sock = nfc_llcp_sock(sk);
560
561 if (llcp_sock->sk.sk_state != LLCP_LISTEN)
562 continue;
563
564 if (llcp_sock->service_name == NULL ||
565 llcp_sock->service_name_len == 0)
566 continue;
567
568 if (llcp_sock->service_name_len != sn_len)
569 continue;
570
571 if (memcmp(sn, llcp_sock->service_name, sn_len) == 0)
572 break;
d646960f
SO
573 }
574
a69f32af 575 read_unlock(&local->sockets.lock);
d646960f 576
a69f32af
SO
577 if (llcp_sock == NULL)
578 return NULL;
d646960f 579
a69f32af
SO
580 sock_hold(&llcp_sock->sk);
581
582 return llcp_sock;
d646960f
SO
583}
584
585static void nfc_llcp_sock_put(struct nfc_llcp_sock *sock)
586{
587 sock_put(&sock->sk);
588}
589
590static u8 *nfc_llcp_connect_sn(struct sk_buff *skb, size_t *sn_len)
591{
592 u8 *tlv = &skb->data[2], type, length;
593 size_t tlv_array_len = skb->len - LLCP_HEADER_SIZE, offset = 0;
594
595 while (offset < tlv_array_len) {
596 type = tlv[0];
597 length = tlv[1];
598
599 pr_debug("type 0x%x length %d\n", type, length);
600
601 if (type == LLCP_TLV_SN) {
602 *sn_len = length;
603 return &tlv[2];
604 }
605
606 offset += length + 2;
607 tlv += length + 2;
608 }
609
610 return NULL;
611}
612
613static void nfc_llcp_recv_connect(struct nfc_llcp_local *local,
427a2eb1 614 struct sk_buff *skb)
d646960f
SO
615{
616 struct sock *new_sk, *parent;
617 struct nfc_llcp_sock *sock, *new_sock;
a69f32af 618 u8 dsap, ssap, reason;
d646960f
SO
619
620 dsap = nfc_llcp_dsap(skb);
621 ssap = nfc_llcp_ssap(skb);
622
623 pr_debug("%d %d\n", dsap, ssap);
624
d646960f 625 if (dsap != LLCP_SAP_SDP) {
a69f32af
SO
626 sock = nfc_llcp_sock_get(local, dsap, LLCP_SAP_SDP);
627 if (sock == NULL || sock->sk.sk_state != LLCP_LISTEN) {
d646960f
SO
628 reason = LLCP_DM_NOBOUND;
629 goto fail;
630 }
d646960f
SO
631 } else {
632 u8 *sn;
633 size_t sn_len;
634
635 sn = nfc_llcp_connect_sn(skb, &sn_len);
636 if (sn == NULL) {
637 reason = LLCP_DM_NOBOUND;
638 goto fail;
639 }
640
641 pr_debug("Service name length %zu\n", sn_len);
642
a69f32af
SO
643 sock = nfc_llcp_sock_get_sn(local, sn, sn_len);
644 if (sock == NULL) {
645 reason = LLCP_DM_NOBOUND;
646 goto fail;
d646960f 647 }
d646960f
SO
648 }
649
a69f32af 650 lock_sock(&sock->sk);
d646960f 651
d646960f
SO
652 parent = &sock->sk;
653
654 if (sk_acceptq_is_full(parent)) {
655 reason = LLCP_DM_REJ;
656 release_sock(&sock->sk);
657 sock_put(&sock->sk);
658 goto fail;
659 }
660
427a2eb1 661 new_sk = nfc_llcp_sock_alloc(NULL, parent->sk_type, GFP_ATOMIC);
d646960f
SO
662 if (new_sk == NULL) {
663 reason = LLCP_DM_REJ;
664 release_sock(&sock->sk);
665 sock_put(&sock->sk);
666 goto fail;
667 }
668
669 new_sock = nfc_llcp_sock(new_sk);
670 new_sock->dev = local->dev;
c7aa1225 671 new_sock->local = nfc_llcp_local_get(local);
93d7e490 672 new_sock->miu = local->remote_miu;
d646960f 673 new_sock->nfc_protocol = sock->nfc_protocol;
a69f32af 674 new_sock->ssap = sock->ssap;
d646960f 675 new_sock->dsap = ssap;
025f1520 676 new_sock->target_idx = local->target_idx;
d646960f
SO
677 new_sock->parent = parent;
678
7a06e586
SO
679 nfc_llcp_parse_connection_tlv(new_sock, &skb->data[LLCP_HEADER_SIZE],
680 skb->len - LLCP_HEADER_SIZE);
681
d646960f
SO
682 pr_debug("new sock %p sk %p\n", new_sock, &new_sock->sk);
683
a69f32af 684 nfc_llcp_sock_link(&local->sockets, new_sk);
d646960f
SO
685
686 nfc_llcp_accept_enqueue(&sock->sk, new_sk);
687
688 nfc_get_device(local->dev->idx);
689
690 new_sk->sk_state = LLCP_CONNECTED;
691
692 /* Wake the listening processes */
693 parent->sk_data_ready(parent, 0);
694
695 /* Send CC */
696 nfc_llcp_send_cc(new_sock);
697
698 release_sock(&sock->sk);
699 sock_put(&sock->sk);
700
701 return;
702
703fail:
704 /* Send DM */
705 nfc_llcp_send_dm(local, dsap, ssap, reason);
706
707 return;
708
709}
710
d094afa1 711int nfc_llcp_queue_i_frames(struct nfc_llcp_sock *sock)
4722d2b7 712{
d094afa1 713 int nr_frames = 0;
4722d2b7
SO
714 struct nfc_llcp_local *local = sock->local;
715
716 pr_debug("Remote ready %d tx queue len %d remote rw %d",
427a2eb1 717 sock->remote_ready, skb_queue_len(&sock->tx_pending_queue),
7a06e586 718 sock->rw);
4722d2b7
SO
719
720 /* Try to queue some I frames for transmission */
721 while (sock->remote_ready &&
7a06e586 722 skb_queue_len(&sock->tx_pending_queue) < sock->rw) {
84457960 723 struct sk_buff *pdu;
4722d2b7
SO
724
725 pdu = skb_dequeue(&sock->tx_queue);
726 if (pdu == NULL)
727 break;
728
729 /* Update N(S)/N(R) */
730 nfc_llcp_set_nrns(sock, pdu);
731
4722d2b7 732 skb_queue_tail(&local->tx_queue, pdu);
d094afa1 733 nr_frames++;
4722d2b7 734 }
d094afa1
SO
735
736 return nr_frames;
4722d2b7
SO
737}
738
d646960f 739static void nfc_llcp_recv_hdlc(struct nfc_llcp_local *local,
427a2eb1 740 struct sk_buff *skb)
d646960f
SO
741{
742 struct nfc_llcp_sock *llcp_sock;
743 struct sock *sk;
744 u8 dsap, ssap, ptype, ns, nr;
745
746 ptype = nfc_llcp_ptype(skb);
747 dsap = nfc_llcp_dsap(skb);
748 ssap = nfc_llcp_ssap(skb);
749 ns = nfc_llcp_ns(skb);
750 nr = nfc_llcp_nr(skb);
751
752 pr_debug("%d %d R %d S %d\n", dsap, ssap, nr, ns);
753
754 llcp_sock = nfc_llcp_sock_get(local, dsap, ssap);
755 if (llcp_sock == NULL) {
756 nfc_llcp_send_dm(local, dsap, ssap, LLCP_DM_NOCONN);
757 return;
758 }
759
760 sk = &llcp_sock->sk;
761 lock_sock(sk);
762 if (sk->sk_state == LLCP_CLOSED) {
763 release_sock(sk);
764 nfc_llcp_sock_put(llcp_sock);
765 }
766
d646960f
SO
767 /* Pass the payload upstream */
768 if (ptype == LLCP_PDU_I) {
769 pr_debug("I frame, queueing on %p\n", &llcp_sock->sk);
770
53aef920
SO
771 if (ns == llcp_sock->recv_n)
772 llcp_sock->recv_n = (llcp_sock->recv_n + 1) % 16;
773 else
774 pr_err("Received out of sequence I PDU\n");
775
d646960f
SO
776 skb_pull(skb, LLCP_HEADER_SIZE + LLCP_SEQUENCE_SIZE);
777 if (sock_queue_rcv_skb(&llcp_sock->sk, skb)) {
778 pr_err("receive queue is full\n");
779 skb_queue_head(&llcp_sock->tx_backlog_queue, skb);
780 }
781 }
782
783 /* Remove skbs from the pending queue */
784 if (llcp_sock->send_ack_n != nr) {
785 struct sk_buff *s, *tmp;
786
787 llcp_sock->send_ack_n = nr;
788
84457960
SO
789 /* Remove and free all skbs until ns == nr */
790 skb_queue_walk_safe(&llcp_sock->tx_pending_queue, s, tmp) {
791 skb_unlink(s, &llcp_sock->tx_pending_queue);
792 kfree_skb(s);
793
794 if (nfc_llcp_ns(s) == nr)
795 break;
796 }
797
798 /* Re-queue the remaining skbs for transmission */
799 skb_queue_reverse_walk_safe(&llcp_sock->tx_pending_queue,
800 s, tmp) {
801 skb_unlink(s, &llcp_sock->tx_pending_queue);
802 skb_queue_head(&local->tx_queue, s);
803 }
d646960f
SO
804 }
805
53aef920
SO
806 if (ptype == LLCP_PDU_RR)
807 llcp_sock->remote_ready = true;
427a2eb1 808 else if (ptype == LLCP_PDU_RNR)
53aef920
SO
809 llcp_sock->remote_ready = false;
810
56af2568 811 if (nfc_llcp_queue_i_frames(llcp_sock) == 0 && ptype == LLCP_PDU_I)
d094afa1 812 nfc_llcp_send_rr(llcp_sock);
d646960f
SO
813
814 release_sock(sk);
815 nfc_llcp_sock_put(llcp_sock);
816}
817
818static void nfc_llcp_recv_disc(struct nfc_llcp_local *local,
427a2eb1 819 struct sk_buff *skb)
d646960f
SO
820{
821 struct nfc_llcp_sock *llcp_sock;
822 struct sock *sk;
823 u8 dsap, ssap;
824
825 dsap = nfc_llcp_dsap(skb);
826 ssap = nfc_llcp_ssap(skb);
827
828 llcp_sock = nfc_llcp_sock_get(local, dsap, ssap);
829 if (llcp_sock == NULL) {
830 nfc_llcp_send_dm(local, dsap, ssap, LLCP_DM_NOCONN);
831 return;
832 }
833
834 sk = &llcp_sock->sk;
835 lock_sock(sk);
836 if (sk->sk_state == LLCP_CLOSED) {
837 release_sock(sk);
838 nfc_llcp_sock_put(llcp_sock);
839 }
840
d646960f
SO
841 if (sk->sk_state == LLCP_CONNECTED) {
842 nfc_put_device(local->dev);
843 sk->sk_state = LLCP_CLOSED;
844 sk->sk_state_change(sk);
845 }
846
847 nfc_llcp_send_dm(local, dsap, ssap, LLCP_DM_DISC);
848
849 release_sock(sk);
850 nfc_llcp_sock_put(llcp_sock);
851}
852
427a2eb1 853static void nfc_llcp_recv_cc(struct nfc_llcp_local *local, struct sk_buff *skb)
d646960f
SO
854{
855 struct nfc_llcp_sock *llcp_sock;
ff353d86 856 struct sock *sk;
d646960f
SO
857 u8 dsap, ssap;
858
d646960f
SO
859 dsap = nfc_llcp_dsap(skb);
860 ssap = nfc_llcp_ssap(skb);
861
a69f32af 862 llcp_sock = nfc_llcp_connecting_sock_get(local, dsap);
d646960f
SO
863 if (llcp_sock == NULL) {
864 pr_err("Invalid CC\n");
865 nfc_llcp_send_dm(local, dsap, ssap, LLCP_DM_NOCONN);
866
867 return;
868 }
869
ff353d86 870 sk = &llcp_sock->sk;
d646960f 871
a69f32af
SO
872 /* Unlink from connecting and link to the client array */
873 nfc_llcp_sock_unlink(&local->connecting_sockets, sk);
874 nfc_llcp_sock_link(&local->sockets, sk);
875 llcp_sock->dsap = ssap;
876
7a06e586
SO
877 nfc_llcp_parse_connection_tlv(llcp_sock, &skb->data[LLCP_HEADER_SIZE],
878 skb->len - LLCP_HEADER_SIZE);
d646960f 879
ff353d86
SO
880 sk->sk_state = LLCP_CONNECTED;
881 sk->sk_state_change(sk);
882
d646960f
SO
883 nfc_llcp_sock_put(llcp_sock);
884}
885
886static void nfc_llcp_rx_work(struct work_struct *work)
887{
888 struct nfc_llcp_local *local = container_of(work, struct nfc_llcp_local,
427a2eb1 889 rx_work);
d646960f
SO
890 u8 dsap, ssap, ptype;
891 struct sk_buff *skb;
892
893 skb = local->rx_pending;
894 if (skb == NULL) {
895 pr_debug("No pending SKB\n");
896 return;
897 }
898
899 ptype = nfc_llcp_ptype(skb);
900 dsap = nfc_llcp_dsap(skb);
901 ssap = nfc_llcp_ssap(skb);
902
903 pr_debug("ptype 0x%x dsap 0x%x ssap 0x%x\n", ptype, dsap, ssap);
904
4be646ec
SO
905 if (ptype != LLCP_PDU_SYMM)
906 print_hex_dump(KERN_DEBUG, "LLCP Rx: ", DUMP_PREFIX_OFFSET,
907 16, 1, skb->data, skb->len, true);
908
d646960f
SO
909 switch (ptype) {
910 case LLCP_PDU_SYMM:
911 pr_debug("SYMM\n");
912 break;
913
914 case LLCP_PDU_CONNECT:
915 pr_debug("CONNECT\n");
916 nfc_llcp_recv_connect(local, skb);
917 break;
918
919 case LLCP_PDU_DISC:
920 pr_debug("DISC\n");
921 nfc_llcp_recv_disc(local, skb);
922 break;
923
924 case LLCP_PDU_CC:
925 pr_debug("CC\n");
926 nfc_llcp_recv_cc(local, skb);
927 break;
928
929 case LLCP_PDU_I:
930 case LLCP_PDU_RR:
53aef920 931 case LLCP_PDU_RNR:
d646960f
SO
932 pr_debug("I frame\n");
933 nfc_llcp_recv_hdlc(local, skb);
934 break;
935
936 }
937
938 queue_work(local->tx_wq, &local->tx_work);
939 kfree_skb(local->rx_pending);
940 local->rx_pending = NULL;
941
942 return;
943}
944
945void nfc_llcp_recv(void *data, struct sk_buff *skb, int err)
946{
947 struct nfc_llcp_local *local = (struct nfc_llcp_local *) data;
948
949 pr_debug("Received an LLCP PDU\n");
950 if (err < 0) {
427a2eb1 951 pr_err("err %d\n", err);
d646960f
SO
952 return;
953 }
954
955 local->rx_pending = skb_get(skb);
956 del_timer(&local->link_timer);
957 queue_work(local->rx_wq, &local->rx_work);
958
959 return;
960}
961
73167ced
SO
962int nfc_llcp_data_received(struct nfc_dev *dev, struct sk_buff *skb)
963{
964 struct nfc_llcp_local *local;
965
966 local = nfc_llcp_find_local(dev);
967 if (local == NULL)
968 return -ENODEV;
969
970 local->rx_pending = skb_get(skb);
971 del_timer(&local->link_timer);
972 queue_work(local->rx_wq, &local->rx_work);
973
974 return 0;
975}
976
d646960f
SO
977void nfc_llcp_mac_is_down(struct nfc_dev *dev)
978{
979 struct nfc_llcp_local *local;
980
981 local = nfc_llcp_find_local(dev);
982 if (local == NULL)
983 return;
984
985 /* Close and purge all existing sockets */
4d22ea15 986 nfc_llcp_socket_release(local, true);
d646960f
SO
987}
988
989void nfc_llcp_mac_is_up(struct nfc_dev *dev, u32 target_idx,
990 u8 comm_mode, u8 rf_mode)
991{
992 struct nfc_llcp_local *local;
993
994 pr_debug("rf mode %d\n", rf_mode);
995
996 local = nfc_llcp_find_local(dev);
997 if (local == NULL)
998 return;
999
1000 local->target_idx = target_idx;
1001 local->comm_mode = comm_mode;
1002 local->rf_mode = rf_mode;
1003
1004 if (rf_mode == NFC_RF_INITIATOR) {
1005 pr_debug("Queueing Tx work\n");
1006
1007 queue_work(local->tx_wq, &local->tx_work);
1008 } else {
1009 mod_timer(&local->link_timer,
427a2eb1 1010 jiffies + msecs_to_jiffies(local->remote_lto));
d646960f
SO
1011 }
1012}
1013
1014int nfc_llcp_register_device(struct nfc_dev *ndev)
1015{
1016 struct device *dev = &ndev->dev;
1017 struct nfc_llcp_local *local;
1018 char name[32];
1019 int err;
1020
1021 local = kzalloc(sizeof(struct nfc_llcp_local), GFP_KERNEL);
1022 if (local == NULL)
1023 return -ENOMEM;
1024
1025 local->dev = ndev;
1026 INIT_LIST_HEAD(&local->list);
c7aa1225 1027 kref_init(&local->ref);
d646960f 1028 mutex_init(&local->sdp_lock);
d646960f
SO
1029 init_timer(&local->link_timer);
1030 local->link_timer.data = (unsigned long) local;
1031 local->link_timer.function = nfc_llcp_symm_timer;
1032
1033 skb_queue_head_init(&local->tx_queue);
1034 INIT_WORK(&local->tx_work, nfc_llcp_tx_work);
1035 snprintf(name, sizeof(name), "%s_llcp_tx_wq", dev_name(dev));
427a2eb1
SO
1036 local->tx_wq =
1037 alloc_workqueue(name,
1038 WQ_NON_REENTRANT | WQ_UNBOUND | WQ_MEM_RECLAIM,
1039 1);
d646960f
SO
1040 if (local->tx_wq == NULL) {
1041 err = -ENOMEM;
1042 goto err_local;
1043 }
1044
1045 local->rx_pending = NULL;
1046 INIT_WORK(&local->rx_work, nfc_llcp_rx_work);
1047 snprintf(name, sizeof(name), "%s_llcp_rx_wq", dev_name(dev));
427a2eb1
SO
1048 local->rx_wq =
1049 alloc_workqueue(name,
1050 WQ_NON_REENTRANT | WQ_UNBOUND | WQ_MEM_RECLAIM,
1051 1);
d646960f
SO
1052 if (local->rx_wq == NULL) {
1053 err = -ENOMEM;
1054 goto err_tx_wq;
1055 }
1056
1057 INIT_WORK(&local->timeout_work, nfc_llcp_timeout_work);
1058 snprintf(name, sizeof(name), "%s_llcp_timeout_wq", dev_name(dev));
427a2eb1
SO
1059 local->timeout_wq =
1060 alloc_workqueue(name,
1061 WQ_NON_REENTRANT | WQ_UNBOUND | WQ_MEM_RECLAIM,
1062 1);
d646960f
SO
1063 if (local->timeout_wq == NULL) {
1064 err = -ENOMEM;
1065 goto err_rx_wq;
1066 }
1067
a69f32af
SO
1068 local->sockets.lock = __RW_LOCK_UNLOCKED(local->sockets.lock);
1069 local->connecting_sockets.lock = __RW_LOCK_UNLOCKED(local->connecting_sockets.lock);
1070
d646960f
SO
1071 nfc_llcp_build_gb(local);
1072
1073 local->remote_miu = LLCP_DEFAULT_MIU;
1074 local->remote_lto = LLCP_DEFAULT_LTO;
d646960f
SO
1075
1076 list_add(&llcp_devices, &local->list);
1077
1078 return 0;
1079
1080err_rx_wq:
1081 destroy_workqueue(local->rx_wq);
1082
1083err_tx_wq:
1084 destroy_workqueue(local->tx_wq);
1085
1086err_local:
1087 kfree(local);
1088
1089 return 0;
1090}
1091
1092void nfc_llcp_unregister_device(struct nfc_dev *dev)
1093{
1094 struct nfc_llcp_local *local = nfc_llcp_find_local(dev);
1095
1096 if (local == NULL) {
1097 pr_debug("No such device\n");
1098 return;
1099 }
1100
c7aa1225 1101 nfc_llcp_local_put(local);
d646960f
SO
1102}
1103
1104int __init nfc_llcp_init(void)
1105{
1106 INIT_LIST_HEAD(&llcp_devices);
1107
1108 return nfc_llcp_sock_init();
1109}
1110
1111void nfc_llcp_exit(void)
1112{
1113 nfc_llcp_sock_exit();
1114}
This page took 0.108261 seconds and 5 git commands to generate.