xref: /openbmc/linux/net/bluetooth/hci_sock.c (revision 040030ef7d907107e6489b39da518bdf94136d68)
11da177e4SLinus Torvalds /*
21da177e4SLinus Torvalds    BlueZ - Bluetooth protocol stack for Linux
31da177e4SLinus Torvalds    Copyright (C) 2000-2001 Qualcomm Incorporated
41da177e4SLinus Torvalds 
51da177e4SLinus Torvalds    Written 2000,2001 by Maxim Krasnyansky <maxk@qualcomm.com>
61da177e4SLinus Torvalds 
71da177e4SLinus Torvalds    This program is free software; you can redistribute it and/or modify
81da177e4SLinus Torvalds    it under the terms of the GNU General Public License version 2 as
91da177e4SLinus Torvalds    published by the Free Software Foundation;
101da177e4SLinus Torvalds 
111da177e4SLinus Torvalds    THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS
121da177e4SLinus Torvalds    OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
131da177e4SLinus Torvalds    FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT OF THIRD PARTY RIGHTS.
141da177e4SLinus Torvalds    IN NO EVENT SHALL THE COPYRIGHT HOLDER(S) AND AUTHOR(S) BE LIABLE FOR ANY
151da177e4SLinus Torvalds    CLAIM, OR ANY SPECIAL INDIRECT OR CONSEQUENTIAL DAMAGES, OR ANY DAMAGES
161da177e4SLinus Torvalds    WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
171da177e4SLinus Torvalds    ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
181da177e4SLinus Torvalds    OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
191da177e4SLinus Torvalds 
201da177e4SLinus Torvalds    ALL LIABILITY, INCLUDING LIABILITY FOR INFRINGEMENT OF ANY PATENTS,
211da177e4SLinus Torvalds    COPYRIGHTS, TRADEMARKS OR OTHER RIGHTS, RELATING TO USE OF THIS
221da177e4SLinus Torvalds    SOFTWARE IS DISCLAIMED.
231da177e4SLinus Torvalds */
241da177e4SLinus Torvalds 
251da177e4SLinus Torvalds /* Bluetooth HCI sockets. */
261da177e4SLinus Torvalds 
271da177e4SLinus Torvalds #include <linux/module.h>
281da177e4SLinus Torvalds 
291da177e4SLinus Torvalds #include <linux/types.h>
304fc268d2SRandy Dunlap #include <linux/capability.h>
311da177e4SLinus Torvalds #include <linux/errno.h>
321da177e4SLinus Torvalds #include <linux/kernel.h>
331da177e4SLinus Torvalds #include <linux/slab.h>
341da177e4SLinus Torvalds #include <linux/poll.h>
351da177e4SLinus Torvalds #include <linux/fcntl.h>
361da177e4SLinus Torvalds #include <linux/init.h>
371da177e4SLinus Torvalds #include <linux/skbuff.h>
381da177e4SLinus Torvalds #include <linux/workqueue.h>
391da177e4SLinus Torvalds #include <linux/interrupt.h>
40767c5eb5SMarcel Holtmann #include <linux/compat.h>
411da177e4SLinus Torvalds #include <linux/socket.h>
421da177e4SLinus Torvalds #include <linux/ioctl.h>
431da177e4SLinus Torvalds #include <net/sock.h>
441da177e4SLinus Torvalds 
451da177e4SLinus Torvalds #include <asm/system.h>
4670f23020SAndrei Emeltchenko #include <linux/uaccess.h>
471da177e4SLinus Torvalds #include <asm/unaligned.h>
481da177e4SLinus Torvalds 
491da177e4SLinus Torvalds #include <net/bluetooth/bluetooth.h>
501da177e4SLinus Torvalds #include <net/bluetooth/hci_core.h>
511da177e4SLinus Torvalds 
52eb939922SRusty Russell static bool enable_mgmt;
530381101fSJohan Hedberg 
541da177e4SLinus Torvalds /* ----- HCI socket interface ----- */
551da177e4SLinus Torvalds 
561da177e4SLinus Torvalds static inline int hci_test_bit(int nr, void *addr)
571da177e4SLinus Torvalds {
581da177e4SLinus Torvalds 	return *((__u32 *) addr + (nr >> 5)) & ((__u32) 1 << (nr & 31));
591da177e4SLinus Torvalds }
601da177e4SLinus Torvalds 
611da177e4SLinus Torvalds /* Security filter */
621da177e4SLinus Torvalds static struct hci_sec_filter hci_sec_filter = {
631da177e4SLinus Torvalds 	/* Packet types */
641da177e4SLinus Torvalds 	0x10,
651da177e4SLinus Torvalds 	/* Events */
66dd7f5527SMarcel Holtmann 	{ 0x1000d9fe, 0x0000b00c },
671da177e4SLinus Torvalds 	/* Commands */
681da177e4SLinus Torvalds 	{
691da177e4SLinus Torvalds 		{ 0x0 },
701da177e4SLinus Torvalds 		/* OGF_LINK_CTL */
717c631a67SMarcel Holtmann 		{ 0xbe000006, 0x00000001, 0x00000000, 0x00 },
721da177e4SLinus Torvalds 		/* OGF_LINK_POLICY */
737c631a67SMarcel Holtmann 		{ 0x00005200, 0x00000000, 0x00000000, 0x00 },
741da177e4SLinus Torvalds 		/* OGF_HOST_CTL */
757c631a67SMarcel Holtmann 		{ 0xaab00200, 0x2b402aaa, 0x05220154, 0x00 },
761da177e4SLinus Torvalds 		/* OGF_INFO_PARAM */
777c631a67SMarcel Holtmann 		{ 0x000002be, 0x00000000, 0x00000000, 0x00 },
781da177e4SLinus Torvalds 		/* OGF_STATUS_PARAM */
797c631a67SMarcel Holtmann 		{ 0x000000ea, 0x00000000, 0x00000000, 0x00 }
801da177e4SLinus Torvalds 	}
811da177e4SLinus Torvalds };
821da177e4SLinus Torvalds 
831da177e4SLinus Torvalds static struct bt_sock_list hci_sk_list = {
84d5fb2962SRobert P. J. Day 	.lock = __RW_LOCK_UNLOCKED(hci_sk_list.lock)
851da177e4SLinus Torvalds };
861da177e4SLinus Torvalds 
871da177e4SLinus Torvalds /* Send frame to RAW socket */
88470fe1b5SMarcel Holtmann void hci_send_to_sock(struct hci_dev *hdev, struct sk_buff *skb)
891da177e4SLinus Torvalds {
901da177e4SLinus Torvalds 	struct sock *sk;
911da177e4SLinus Torvalds 	struct hlist_node *node;
92e0edf373SMarcel Holtmann 	struct sk_buff *skb_copy = NULL;
931da177e4SLinus Torvalds 
941da177e4SLinus Torvalds 	BT_DBG("hdev %p len %d", hdev, skb->len);
951da177e4SLinus Torvalds 
961da177e4SLinus Torvalds 	read_lock(&hci_sk_list.lock);
97470fe1b5SMarcel Holtmann 
981da177e4SLinus Torvalds 	sk_for_each(sk, node, &hci_sk_list.head) {
991da177e4SLinus Torvalds 		struct hci_filter *flt;
1001da177e4SLinus Torvalds 		struct sk_buff *nskb;
1011da177e4SLinus Torvalds 
1021da177e4SLinus Torvalds 		if (sk->sk_state != BT_BOUND || hci_pi(sk)->hdev != hdev)
1031da177e4SLinus Torvalds 			continue;
1041da177e4SLinus Torvalds 
1051da177e4SLinus Torvalds 		/* Don't send frame to the socket it came from */
1061da177e4SLinus Torvalds 		if (skb->sk == sk)
1071da177e4SLinus Torvalds 			continue;
1081da177e4SLinus Torvalds 
109470fe1b5SMarcel Holtmann 		if (hci_pi(sk)->channel != HCI_CHANNEL_RAW)
110a40c406cSJohan Hedberg 			continue;
111a40c406cSJohan Hedberg 
1121da177e4SLinus Torvalds 		/* Apply filter */
1131da177e4SLinus Torvalds 		flt = &hci_pi(sk)->filter;
1141da177e4SLinus Torvalds 
1150d48d939SMarcel Holtmann 		if (!test_bit((bt_cb(skb)->pkt_type == HCI_VENDOR_PKT) ?
1160d48d939SMarcel Holtmann 				0 : (bt_cb(skb)->pkt_type & HCI_FLT_TYPE_BITS), &flt->type_mask))
1171da177e4SLinus Torvalds 			continue;
1181da177e4SLinus Torvalds 
1190d48d939SMarcel Holtmann 		if (bt_cb(skb)->pkt_type == HCI_EVENT_PKT) {
1201da177e4SLinus Torvalds 			register int evt = (*(__u8 *)skb->data & HCI_FLT_EVENT_BITS);
1211da177e4SLinus Torvalds 
1221da177e4SLinus Torvalds 			if (!hci_test_bit(evt, &flt->event_mask))
1231da177e4SLinus Torvalds 				continue;
1241da177e4SLinus Torvalds 
1254498c80dSDavid S. Miller 			if (flt->opcode &&
1264498c80dSDavid S. Miller 			    ((evt == HCI_EV_CMD_COMPLETE &&
1274498c80dSDavid S. Miller 			      flt->opcode !=
128905f3ed6SAl Viro 			      get_unaligned((__le16 *)(skb->data + 3))) ||
1291da177e4SLinus Torvalds 			     (evt == HCI_EV_CMD_STATUS &&
1304498c80dSDavid S. Miller 			      flt->opcode !=
131905f3ed6SAl Viro 			      get_unaligned((__le16 *)(skb->data + 4)))))
1321da177e4SLinus Torvalds 				continue;
1331da177e4SLinus Torvalds 		}
1341da177e4SLinus Torvalds 
135e0edf373SMarcel Holtmann 		if (!skb_copy) {
136e0edf373SMarcel Holtmann 			/* Create a private copy with headroom */
137e0edf373SMarcel Holtmann 			skb_copy = __pskb_copy(skb, 1, GFP_ATOMIC);
138e0edf373SMarcel Holtmann 			if (!skb_copy)
1391da177e4SLinus Torvalds 				continue;
1401da177e4SLinus Torvalds 
1411da177e4SLinus Torvalds 			/* Put type byte before the data */
142e0edf373SMarcel Holtmann 			memcpy(skb_push(skb_copy, 1), &bt_cb(skb)->pkt_type, 1);
143e0edf373SMarcel Holtmann 		}
144e0edf373SMarcel Holtmann 
145e0edf373SMarcel Holtmann 		nskb = skb_clone(skb_copy, GFP_ATOMIC);
146e0edf373SMarcel Holtmann 		if (!nskb)
147e0edf373SMarcel Holtmann 			continue;
1481da177e4SLinus Torvalds 
1491da177e4SLinus Torvalds 		if (sock_queue_rcv_skb(sk, nskb))
1501da177e4SLinus Torvalds 			kfree_skb(nskb);
1511da177e4SLinus Torvalds 	}
152470fe1b5SMarcel Holtmann 
153470fe1b5SMarcel Holtmann 	read_unlock(&hci_sk_list.lock);
154e0edf373SMarcel Holtmann 
155e0edf373SMarcel Holtmann 	kfree_skb(skb_copy);
156470fe1b5SMarcel Holtmann }
157470fe1b5SMarcel Holtmann 
158470fe1b5SMarcel Holtmann /* Send frame to control socket */
159470fe1b5SMarcel Holtmann void hci_send_to_control(struct sk_buff *skb, struct sock *skip_sk)
160470fe1b5SMarcel Holtmann {
161470fe1b5SMarcel Holtmann 	struct sock *sk;
162470fe1b5SMarcel Holtmann 	struct hlist_node *node;
163470fe1b5SMarcel Holtmann 
164470fe1b5SMarcel Holtmann 	BT_DBG("len %d", skb->len);
165470fe1b5SMarcel Holtmann 
166470fe1b5SMarcel Holtmann 	read_lock(&hci_sk_list.lock);
167470fe1b5SMarcel Holtmann 
168470fe1b5SMarcel Holtmann 	sk_for_each(sk, node, &hci_sk_list.head) {
169470fe1b5SMarcel Holtmann 		struct sk_buff *nskb;
170470fe1b5SMarcel Holtmann 
171470fe1b5SMarcel Holtmann 		/* Skip the original socket */
172470fe1b5SMarcel Holtmann 		if (sk == skip_sk)
173470fe1b5SMarcel Holtmann 			continue;
174470fe1b5SMarcel Holtmann 
175470fe1b5SMarcel Holtmann 		if (sk->sk_state != BT_BOUND)
176470fe1b5SMarcel Holtmann 			continue;
177470fe1b5SMarcel Holtmann 
178470fe1b5SMarcel Holtmann 		if (hci_pi(sk)->channel != HCI_CHANNEL_CONTROL)
179470fe1b5SMarcel Holtmann 			continue;
180470fe1b5SMarcel Holtmann 
181470fe1b5SMarcel Holtmann 		nskb = skb_clone(skb, GFP_ATOMIC);
182470fe1b5SMarcel Holtmann 		if (!nskb)
183470fe1b5SMarcel Holtmann 			continue;
184470fe1b5SMarcel Holtmann 
185470fe1b5SMarcel Holtmann 		if (sock_queue_rcv_skb(sk, nskb))
186470fe1b5SMarcel Holtmann 			kfree_skb(nskb);
187470fe1b5SMarcel Holtmann 	}
188470fe1b5SMarcel Holtmann 
1891da177e4SLinus Torvalds 	read_unlock(&hci_sk_list.lock);
1901da177e4SLinus Torvalds }
1911da177e4SLinus Torvalds 
192*040030efSMarcel Holtmann /* Generate internal stack event */
193*040030efSMarcel Holtmann static void hci_si_event(struct hci_dev *hdev, int type, int dlen, void *data)
194*040030efSMarcel Holtmann {
195*040030efSMarcel Holtmann 	struct hci_event_hdr *hdr;
196*040030efSMarcel Holtmann 	struct hci_ev_stack_internal *ev;
197*040030efSMarcel Holtmann 	struct sk_buff *skb;
198*040030efSMarcel Holtmann 
199*040030efSMarcel Holtmann 	skb = bt_skb_alloc(HCI_EVENT_HDR_SIZE + sizeof(*ev) + dlen, GFP_ATOMIC);
200*040030efSMarcel Holtmann 	if (!skb)
201*040030efSMarcel Holtmann 		return;
202*040030efSMarcel Holtmann 
203*040030efSMarcel Holtmann 	hdr = (void *) skb_put(skb, HCI_EVENT_HDR_SIZE);
204*040030efSMarcel Holtmann 	hdr->evt  = HCI_EV_STACK_INTERNAL;
205*040030efSMarcel Holtmann 	hdr->plen = sizeof(*ev) + dlen;
206*040030efSMarcel Holtmann 
207*040030efSMarcel Holtmann 	ev  = (void *) skb_put(skb, sizeof(*ev) + dlen);
208*040030efSMarcel Holtmann 	ev->type = type;
209*040030efSMarcel Holtmann 	memcpy(ev->data, data, dlen);
210*040030efSMarcel Holtmann 
211*040030efSMarcel Holtmann 	bt_cb(skb)->incoming = 1;
212*040030efSMarcel Holtmann 	__net_timestamp(skb);
213*040030efSMarcel Holtmann 
214*040030efSMarcel Holtmann 	bt_cb(skb)->pkt_type = HCI_EVENT_PKT;
215*040030efSMarcel Holtmann 	skb->dev = (void *) hdev;
216*040030efSMarcel Holtmann 	hci_send_to_sock(hdev, skb);
217*040030efSMarcel Holtmann 	kfree_skb(skb);
218*040030efSMarcel Holtmann }
219*040030efSMarcel Holtmann 
220*040030efSMarcel Holtmann void hci_sock_dev_event(struct hci_dev *hdev, int event)
221*040030efSMarcel Holtmann {
222*040030efSMarcel Holtmann 	struct hci_ev_si_device ev;
223*040030efSMarcel Holtmann 
224*040030efSMarcel Holtmann 	BT_DBG("hdev %s event %d", hdev->name, event);
225*040030efSMarcel Holtmann 
226*040030efSMarcel Holtmann 	/* Send event to sockets */
227*040030efSMarcel Holtmann 	ev.event  = event;
228*040030efSMarcel Holtmann 	ev.dev_id = hdev->id;
229*040030efSMarcel Holtmann 	hci_si_event(NULL, HCI_EV_SI_DEVICE, sizeof(ev), &ev);
230*040030efSMarcel Holtmann 
231*040030efSMarcel Holtmann 	if (event == HCI_DEV_UNREG) {
232*040030efSMarcel Holtmann 		struct sock *sk;
233*040030efSMarcel Holtmann 		struct hlist_node *node;
234*040030efSMarcel Holtmann 
235*040030efSMarcel Holtmann 		/* Detach sockets from device */
236*040030efSMarcel Holtmann 		read_lock(&hci_sk_list.lock);
237*040030efSMarcel Holtmann 		sk_for_each(sk, node, &hci_sk_list.head) {
238*040030efSMarcel Holtmann 			bh_lock_sock_nested(sk);
239*040030efSMarcel Holtmann 			if (hci_pi(sk)->hdev == hdev) {
240*040030efSMarcel Holtmann 				hci_pi(sk)->hdev = NULL;
241*040030efSMarcel Holtmann 				sk->sk_err = EPIPE;
242*040030efSMarcel Holtmann 				sk->sk_state = BT_OPEN;
243*040030efSMarcel Holtmann 				sk->sk_state_change(sk);
244*040030efSMarcel Holtmann 
245*040030efSMarcel Holtmann 				hci_dev_put(hdev);
246*040030efSMarcel Holtmann 			}
247*040030efSMarcel Holtmann 			bh_unlock_sock(sk);
248*040030efSMarcel Holtmann 		}
249*040030efSMarcel Holtmann 		read_unlock(&hci_sk_list.lock);
250*040030efSMarcel Holtmann 	}
251*040030efSMarcel Holtmann }
252*040030efSMarcel Holtmann 
2531da177e4SLinus Torvalds static int hci_sock_release(struct socket *sock)
2541da177e4SLinus Torvalds {
2551da177e4SLinus Torvalds 	struct sock *sk = sock->sk;
2567b005bd3SMarcel Holtmann 	struct hci_dev *hdev;
2571da177e4SLinus Torvalds 
2581da177e4SLinus Torvalds 	BT_DBG("sock %p sk %p", sock, sk);
2591da177e4SLinus Torvalds 
2601da177e4SLinus Torvalds 	if (!sk)
2611da177e4SLinus Torvalds 		return 0;
2621da177e4SLinus Torvalds 
2637b005bd3SMarcel Holtmann 	hdev = hci_pi(sk)->hdev;
2647b005bd3SMarcel Holtmann 
2651da177e4SLinus Torvalds 	bt_sock_unlink(&hci_sk_list, sk);
2661da177e4SLinus Torvalds 
2671da177e4SLinus Torvalds 	if (hdev) {
2681da177e4SLinus Torvalds 		atomic_dec(&hdev->promisc);
2691da177e4SLinus Torvalds 		hci_dev_put(hdev);
2701da177e4SLinus Torvalds 	}
2711da177e4SLinus Torvalds 
2721da177e4SLinus Torvalds 	sock_orphan(sk);
2731da177e4SLinus Torvalds 
2741da177e4SLinus Torvalds 	skb_queue_purge(&sk->sk_receive_queue);
2751da177e4SLinus Torvalds 	skb_queue_purge(&sk->sk_write_queue);
2761da177e4SLinus Torvalds 
2771da177e4SLinus Torvalds 	sock_put(sk);
2781da177e4SLinus Torvalds 	return 0;
2791da177e4SLinus Torvalds }
2801da177e4SLinus Torvalds 
281b2a66aadSAntti Julku static int hci_sock_blacklist_add(struct hci_dev *hdev, void __user *arg)
282f0358568SJohan Hedberg {
283f0358568SJohan Hedberg 	bdaddr_t bdaddr;
2845e762444SAntti Julku 	int err;
285f0358568SJohan Hedberg 
286f0358568SJohan Hedberg 	if (copy_from_user(&bdaddr, arg, sizeof(bdaddr)))
287f0358568SJohan Hedberg 		return -EFAULT;
288f0358568SJohan Hedberg 
28909fd0de5SGustavo F. Padovan 	hci_dev_lock(hdev);
2905e762444SAntti Julku 
29188c1fe4bSJohan Hedberg 	err = hci_blacklist_add(hdev, &bdaddr, 0);
2925e762444SAntti Julku 
29309fd0de5SGustavo F. Padovan 	hci_dev_unlock(hdev);
2945e762444SAntti Julku 
2955e762444SAntti Julku 	return err;
296f0358568SJohan Hedberg }
297f0358568SJohan Hedberg 
298b2a66aadSAntti Julku static int hci_sock_blacklist_del(struct hci_dev *hdev, void __user *arg)
299f0358568SJohan Hedberg {
300f0358568SJohan Hedberg 	bdaddr_t bdaddr;
3015e762444SAntti Julku 	int err;
302f0358568SJohan Hedberg 
303f0358568SJohan Hedberg 	if (copy_from_user(&bdaddr, arg, sizeof(bdaddr)))
304f0358568SJohan Hedberg 		return -EFAULT;
305f0358568SJohan Hedberg 
30609fd0de5SGustavo F. Padovan 	hci_dev_lock(hdev);
3075e762444SAntti Julku 
30888c1fe4bSJohan Hedberg 	err = hci_blacklist_del(hdev, &bdaddr, 0);
3095e762444SAntti Julku 
31009fd0de5SGustavo F. Padovan 	hci_dev_unlock(hdev);
3115e762444SAntti Julku 
3125e762444SAntti Julku 	return err;
313f0358568SJohan Hedberg }
314f0358568SJohan Hedberg 
3151da177e4SLinus Torvalds /* Ioctls that require bound socket */
3161da177e4SLinus Torvalds static inline int hci_sock_bound_ioctl(struct sock *sk, unsigned int cmd, unsigned long arg)
3171da177e4SLinus Torvalds {
3181da177e4SLinus Torvalds 	struct hci_dev *hdev = hci_pi(sk)->hdev;
3191da177e4SLinus Torvalds 
3201da177e4SLinus Torvalds 	if (!hdev)
3211da177e4SLinus Torvalds 		return -EBADFD;
3221da177e4SLinus Torvalds 
3231da177e4SLinus Torvalds 	switch (cmd) {
3241da177e4SLinus Torvalds 	case HCISETRAW:
3251da177e4SLinus Torvalds 		if (!capable(CAP_NET_ADMIN))
3261da177e4SLinus Torvalds 			return -EACCES;
3271da177e4SLinus Torvalds 
3281da177e4SLinus Torvalds 		if (test_bit(HCI_QUIRK_RAW_DEVICE, &hdev->quirks))
3291da177e4SLinus Torvalds 			return -EPERM;
3301da177e4SLinus Torvalds 
3311da177e4SLinus Torvalds 		if (arg)
3321da177e4SLinus Torvalds 			set_bit(HCI_RAW, &hdev->flags);
3331da177e4SLinus Torvalds 		else
3341da177e4SLinus Torvalds 			clear_bit(HCI_RAW, &hdev->flags);
3351da177e4SLinus Torvalds 
3361da177e4SLinus Torvalds 		return 0;
3371da177e4SLinus Torvalds 
3381da177e4SLinus Torvalds 	case HCIGETCONNINFO:
3391da177e4SLinus Torvalds 		return hci_get_conn_info(hdev, (void __user *) arg);
3401da177e4SLinus Torvalds 
34140be492fSMarcel Holtmann 	case HCIGETAUTHINFO:
34240be492fSMarcel Holtmann 		return hci_get_auth_info(hdev, (void __user *) arg);
34340be492fSMarcel Holtmann 
344f0358568SJohan Hedberg 	case HCIBLOCKADDR:
345f0358568SJohan Hedberg 		if (!capable(CAP_NET_ADMIN))
346f0358568SJohan Hedberg 			return -EACCES;
347b2a66aadSAntti Julku 		return hci_sock_blacklist_add(hdev, (void __user *) arg);
348f0358568SJohan Hedberg 
349f0358568SJohan Hedberg 	case HCIUNBLOCKADDR:
350f0358568SJohan Hedberg 		if (!capable(CAP_NET_ADMIN))
351f0358568SJohan Hedberg 			return -EACCES;
352b2a66aadSAntti Julku 		return hci_sock_blacklist_del(hdev, (void __user *) arg);
353f0358568SJohan Hedberg 
3541da177e4SLinus Torvalds 	default:
3551da177e4SLinus Torvalds 		if (hdev->ioctl)
3561da177e4SLinus Torvalds 			return hdev->ioctl(hdev, cmd, arg);
3571da177e4SLinus Torvalds 		return -EINVAL;
3581da177e4SLinus Torvalds 	}
3591da177e4SLinus Torvalds }
3601da177e4SLinus Torvalds 
3611da177e4SLinus Torvalds static int hci_sock_ioctl(struct socket *sock, unsigned int cmd, unsigned long arg)
3621da177e4SLinus Torvalds {
3631da177e4SLinus Torvalds 	struct sock *sk = sock->sk;
3641da177e4SLinus Torvalds 	void __user *argp = (void __user *) arg;
3651da177e4SLinus Torvalds 	int err;
3661da177e4SLinus Torvalds 
3671da177e4SLinus Torvalds 	BT_DBG("cmd %x arg %lx", cmd, arg);
3681da177e4SLinus Torvalds 
3691da177e4SLinus Torvalds 	switch (cmd) {
3701da177e4SLinus Torvalds 	case HCIGETDEVLIST:
3711da177e4SLinus Torvalds 		return hci_get_dev_list(argp);
3721da177e4SLinus Torvalds 
3731da177e4SLinus Torvalds 	case HCIGETDEVINFO:
3741da177e4SLinus Torvalds 		return hci_get_dev_info(argp);
3751da177e4SLinus Torvalds 
3761da177e4SLinus Torvalds 	case HCIGETCONNLIST:
3771da177e4SLinus Torvalds 		return hci_get_conn_list(argp);
3781da177e4SLinus Torvalds 
3791da177e4SLinus Torvalds 	case HCIDEVUP:
3801da177e4SLinus Torvalds 		if (!capable(CAP_NET_ADMIN))
3811da177e4SLinus Torvalds 			return -EACCES;
3821da177e4SLinus Torvalds 		return hci_dev_open(arg);
3831da177e4SLinus Torvalds 
3841da177e4SLinus Torvalds 	case HCIDEVDOWN:
3851da177e4SLinus Torvalds 		if (!capable(CAP_NET_ADMIN))
3861da177e4SLinus Torvalds 			return -EACCES;
3871da177e4SLinus Torvalds 		return hci_dev_close(arg);
3881da177e4SLinus Torvalds 
3891da177e4SLinus Torvalds 	case HCIDEVRESET:
3901da177e4SLinus Torvalds 		if (!capable(CAP_NET_ADMIN))
3911da177e4SLinus Torvalds 			return -EACCES;
3921da177e4SLinus Torvalds 		return hci_dev_reset(arg);
3931da177e4SLinus Torvalds 
3941da177e4SLinus Torvalds 	case HCIDEVRESTAT:
3951da177e4SLinus Torvalds 		if (!capable(CAP_NET_ADMIN))
3961da177e4SLinus Torvalds 			return -EACCES;
3971da177e4SLinus Torvalds 		return hci_dev_reset_stat(arg);
3981da177e4SLinus Torvalds 
3991da177e4SLinus Torvalds 	case HCISETSCAN:
4001da177e4SLinus Torvalds 	case HCISETAUTH:
4011da177e4SLinus Torvalds 	case HCISETENCRYPT:
4021da177e4SLinus Torvalds 	case HCISETPTYPE:
4031da177e4SLinus Torvalds 	case HCISETLINKPOL:
4041da177e4SLinus Torvalds 	case HCISETLINKMODE:
4051da177e4SLinus Torvalds 	case HCISETACLMTU:
4061da177e4SLinus Torvalds 	case HCISETSCOMTU:
4071da177e4SLinus Torvalds 		if (!capable(CAP_NET_ADMIN))
4081da177e4SLinus Torvalds 			return -EACCES;
4091da177e4SLinus Torvalds 		return hci_dev_cmd(cmd, argp);
4101da177e4SLinus Torvalds 
4111da177e4SLinus Torvalds 	case HCIINQUIRY:
4121da177e4SLinus Torvalds 		return hci_inquiry(argp);
4131da177e4SLinus Torvalds 
4141da177e4SLinus Torvalds 	default:
4151da177e4SLinus Torvalds 		lock_sock(sk);
4161da177e4SLinus Torvalds 		err = hci_sock_bound_ioctl(sk, cmd, arg);
4171da177e4SLinus Torvalds 		release_sock(sk);
4181da177e4SLinus Torvalds 		return err;
4191da177e4SLinus Torvalds 	}
4201da177e4SLinus Torvalds }
4211da177e4SLinus Torvalds 
4221da177e4SLinus Torvalds static int hci_sock_bind(struct socket *sock, struct sockaddr *addr, int addr_len)
4231da177e4SLinus Torvalds {
4240381101fSJohan Hedberg 	struct sockaddr_hci haddr;
4251da177e4SLinus Torvalds 	struct sock *sk = sock->sk;
4261da177e4SLinus Torvalds 	struct hci_dev *hdev = NULL;
4270381101fSJohan Hedberg 	int len, err = 0;
4281da177e4SLinus Torvalds 
4291da177e4SLinus Torvalds 	BT_DBG("sock %p sk %p", sock, sk);
4301da177e4SLinus Torvalds 
4310381101fSJohan Hedberg 	if (!addr)
4320381101fSJohan Hedberg 		return -EINVAL;
4330381101fSJohan Hedberg 
4340381101fSJohan Hedberg 	memset(&haddr, 0, sizeof(haddr));
4350381101fSJohan Hedberg 	len = min_t(unsigned int, sizeof(haddr), addr_len);
4360381101fSJohan Hedberg 	memcpy(&haddr, addr, len);
4370381101fSJohan Hedberg 
4380381101fSJohan Hedberg 	if (haddr.hci_family != AF_BLUETOOTH)
4390381101fSJohan Hedberg 		return -EINVAL;
4400381101fSJohan Hedberg 
4411da177e4SLinus Torvalds 	lock_sock(sk);
4421da177e4SLinus Torvalds 
4437cc2ade2SMarcel Holtmann 	if (sk->sk_state == BT_BOUND) {
4447cc2ade2SMarcel Holtmann 		err = -EALREADY;
4457cc2ade2SMarcel Holtmann 		goto done;
4467cc2ade2SMarcel Holtmann 	}
4477cc2ade2SMarcel Holtmann 
4487cc2ade2SMarcel Holtmann 	switch (haddr.hci_channel) {
4497cc2ade2SMarcel Holtmann 	case HCI_CHANNEL_RAW:
4507cc2ade2SMarcel Holtmann 		if (hci_pi(sk)->hdev) {
4511da177e4SLinus Torvalds 			err = -EALREADY;
4521da177e4SLinus Torvalds 			goto done;
4531da177e4SLinus Torvalds 		}
4541da177e4SLinus Torvalds 
4550381101fSJohan Hedberg 		if (haddr.hci_dev != HCI_DEV_NONE) {
4560381101fSJohan Hedberg 			hdev = hci_dev_get(haddr.hci_dev);
45770f23020SAndrei Emeltchenko 			if (!hdev) {
4581da177e4SLinus Torvalds 				err = -ENODEV;
4591da177e4SLinus Torvalds 				goto done;
4601da177e4SLinus Torvalds 			}
4611da177e4SLinus Torvalds 
4621da177e4SLinus Torvalds 			atomic_inc(&hdev->promisc);
4631da177e4SLinus Torvalds 		}
4641da177e4SLinus Torvalds 
4651da177e4SLinus Torvalds 		hci_pi(sk)->hdev = hdev;
4667cc2ade2SMarcel Holtmann 		break;
4677cc2ade2SMarcel Holtmann 
4687cc2ade2SMarcel Holtmann 	case HCI_CHANNEL_CONTROL:
4697cc2ade2SMarcel Holtmann 		if (haddr.hci_dev != HCI_DEV_NONE || !enable_mgmt) {
4707cc2ade2SMarcel Holtmann 			err = -EINVAL;
4717cc2ade2SMarcel Holtmann 			goto done;
4727cc2ade2SMarcel Holtmann 		}
4737cc2ade2SMarcel Holtmann 
4747cc2ade2SMarcel Holtmann 		set_bit(HCI_PI_MGMT_INIT, &hci_pi(sk)->flags);
4757cc2ade2SMarcel Holtmann 		break;
4767cc2ade2SMarcel Holtmann 
4777cc2ade2SMarcel Holtmann 	default:
4787cc2ade2SMarcel Holtmann 		err = -EINVAL;
4797cc2ade2SMarcel Holtmann 		goto done;
4807cc2ade2SMarcel Holtmann 	}
4817cc2ade2SMarcel Holtmann 
4827cc2ade2SMarcel Holtmann 
4837cc2ade2SMarcel Holtmann 	hci_pi(sk)->channel = haddr.hci_channel;
4841da177e4SLinus Torvalds 	sk->sk_state = BT_BOUND;
4851da177e4SLinus Torvalds 
4861da177e4SLinus Torvalds done:
4871da177e4SLinus Torvalds 	release_sock(sk);
4881da177e4SLinus Torvalds 	return err;
4891da177e4SLinus Torvalds }
4901da177e4SLinus Torvalds 
4911da177e4SLinus Torvalds static int hci_sock_getname(struct socket *sock, struct sockaddr *addr, int *addr_len, int peer)
4921da177e4SLinus Torvalds {
4931da177e4SLinus Torvalds 	struct sockaddr_hci *haddr = (struct sockaddr_hci *) addr;
4941da177e4SLinus Torvalds 	struct sock *sk = sock->sk;
4957b005bd3SMarcel Holtmann 	struct hci_dev *hdev = hci_pi(sk)->hdev;
4961da177e4SLinus Torvalds 
4971da177e4SLinus Torvalds 	BT_DBG("sock %p sk %p", sock, sk);
4981da177e4SLinus Torvalds 
4997b005bd3SMarcel Holtmann 	if (!hdev)
5007b005bd3SMarcel Holtmann 		return -EBADFD;
5017b005bd3SMarcel Holtmann 
5021da177e4SLinus Torvalds 	lock_sock(sk);
5031da177e4SLinus Torvalds 
5041da177e4SLinus Torvalds 	*addr_len = sizeof(*haddr);
5051da177e4SLinus Torvalds 	haddr->hci_family = AF_BLUETOOTH;
5067b005bd3SMarcel Holtmann 	haddr->hci_dev    = hdev->id;
5071da177e4SLinus Torvalds 
5081da177e4SLinus Torvalds 	release_sock(sk);
5091da177e4SLinus Torvalds 	return 0;
5101da177e4SLinus Torvalds }
5111da177e4SLinus Torvalds 
5121da177e4SLinus Torvalds static inline void hci_sock_cmsg(struct sock *sk, struct msghdr *msg, struct sk_buff *skb)
5131da177e4SLinus Torvalds {
5141da177e4SLinus Torvalds 	__u32 mask = hci_pi(sk)->cmsg_mask;
5151da177e4SLinus Torvalds 
5160d48d939SMarcel Holtmann 	if (mask & HCI_CMSG_DIR) {
5170d48d939SMarcel Holtmann 		int incoming = bt_cb(skb)->incoming;
5180d48d939SMarcel Holtmann 		put_cmsg(msg, SOL_HCI, HCI_CMSG_DIR, sizeof(incoming), &incoming);
5190d48d939SMarcel Holtmann 	}
5201da177e4SLinus Torvalds 
521a61bbcf2SPatrick McHardy 	if (mask & HCI_CMSG_TSTAMP) {
522f6e623a6SJohann Felix Soden #ifdef CONFIG_COMPAT
523f6e623a6SJohann Felix Soden 		struct compat_timeval ctv;
524f6e623a6SJohann Felix Soden #endif
525a61bbcf2SPatrick McHardy 		struct timeval tv;
526767c5eb5SMarcel Holtmann 		void *data;
527767c5eb5SMarcel Holtmann 		int len;
528a61bbcf2SPatrick McHardy 
529a61bbcf2SPatrick McHardy 		skb_get_timestamp(skb, &tv);
530767c5eb5SMarcel Holtmann 
5311da97f83SDavid S. Miller 		data = &tv;
5321da97f83SDavid S. Miller 		len = sizeof(tv);
5331da97f83SDavid S. Miller #ifdef CONFIG_COMPAT
534767c5eb5SMarcel Holtmann 		if (msg->msg_flags & MSG_CMSG_COMPAT) {
535767c5eb5SMarcel Holtmann 			ctv.tv_sec = tv.tv_sec;
536767c5eb5SMarcel Holtmann 			ctv.tv_usec = tv.tv_usec;
537767c5eb5SMarcel Holtmann 			data = &ctv;
538767c5eb5SMarcel Holtmann 			len = sizeof(ctv);
539767c5eb5SMarcel Holtmann 		}
5401da97f83SDavid S. Miller #endif
541767c5eb5SMarcel Holtmann 
542767c5eb5SMarcel Holtmann 		put_cmsg(msg, SOL_HCI, HCI_CMSG_TSTAMP, len, data);
543a61bbcf2SPatrick McHardy 	}
5441da177e4SLinus Torvalds }
5451da177e4SLinus Torvalds 
5461da177e4SLinus Torvalds static int hci_sock_recvmsg(struct kiocb *iocb, struct socket *sock,
5471da177e4SLinus Torvalds 				struct msghdr *msg, size_t len, int flags)
5481da177e4SLinus Torvalds {
5491da177e4SLinus Torvalds 	int noblock = flags & MSG_DONTWAIT;
5501da177e4SLinus Torvalds 	struct sock *sk = sock->sk;
5511da177e4SLinus Torvalds 	struct sk_buff *skb;
5521da177e4SLinus Torvalds 	int copied, err;
5531da177e4SLinus Torvalds 
5541da177e4SLinus Torvalds 	BT_DBG("sock %p, sk %p", sock, sk);
5551da177e4SLinus Torvalds 
5561da177e4SLinus Torvalds 	if (flags & (MSG_OOB))
5571da177e4SLinus Torvalds 		return -EOPNOTSUPP;
5581da177e4SLinus Torvalds 
5591da177e4SLinus Torvalds 	if (sk->sk_state == BT_CLOSED)
5601da177e4SLinus Torvalds 		return 0;
5611da177e4SLinus Torvalds 
56270f23020SAndrei Emeltchenko 	skb = skb_recv_datagram(sk, flags, noblock, &err);
56370f23020SAndrei Emeltchenko 	if (!skb)
5641da177e4SLinus Torvalds 		return err;
5651da177e4SLinus Torvalds 
5661da177e4SLinus Torvalds 	msg->msg_namelen = 0;
5671da177e4SLinus Torvalds 
5681da177e4SLinus Torvalds 	copied = skb->len;
5691da177e4SLinus Torvalds 	if (len < copied) {
5701da177e4SLinus Torvalds 		msg->msg_flags |= MSG_TRUNC;
5711da177e4SLinus Torvalds 		copied = len;
5721da177e4SLinus Torvalds 	}
5731da177e4SLinus Torvalds 
574badff6d0SArnaldo Carvalho de Melo 	skb_reset_transport_header(skb);
5751da177e4SLinus Torvalds 	err = skb_copy_datagram_iovec(skb, 0, msg->msg_iov, copied);
5761da177e4SLinus Torvalds 
5773a208627SMarcel Holtmann 	switch (hci_pi(sk)->channel) {
5783a208627SMarcel Holtmann 	case HCI_CHANNEL_RAW:
5791da177e4SLinus Torvalds 		hci_sock_cmsg(sk, msg, skb);
5803a208627SMarcel Holtmann 		break;
5813a208627SMarcel Holtmann 	}
5821da177e4SLinus Torvalds 
5831da177e4SLinus Torvalds 	skb_free_datagram(sk, skb);
5841da177e4SLinus Torvalds 
5851da177e4SLinus Torvalds 	return err ? : copied;
5861da177e4SLinus Torvalds }
5871da177e4SLinus Torvalds 
5881da177e4SLinus Torvalds static int hci_sock_sendmsg(struct kiocb *iocb, struct socket *sock,
5891da177e4SLinus Torvalds 			    struct msghdr *msg, size_t len)
5901da177e4SLinus Torvalds {
5911da177e4SLinus Torvalds 	struct sock *sk = sock->sk;
5921da177e4SLinus Torvalds 	struct hci_dev *hdev;
5931da177e4SLinus Torvalds 	struct sk_buff *skb;
5941da177e4SLinus Torvalds 	int err;
5951da177e4SLinus Torvalds 
5961da177e4SLinus Torvalds 	BT_DBG("sock %p sk %p", sock, sk);
5971da177e4SLinus Torvalds 
5981da177e4SLinus Torvalds 	if (msg->msg_flags & MSG_OOB)
5991da177e4SLinus Torvalds 		return -EOPNOTSUPP;
6001da177e4SLinus Torvalds 
6011da177e4SLinus Torvalds 	if (msg->msg_flags & ~(MSG_DONTWAIT|MSG_NOSIGNAL|MSG_ERRQUEUE))
6021da177e4SLinus Torvalds 		return -EINVAL;
6031da177e4SLinus Torvalds 
6041da177e4SLinus Torvalds 	if (len < 4 || len > HCI_MAX_FRAME_SIZE)
6051da177e4SLinus Torvalds 		return -EINVAL;
6061da177e4SLinus Torvalds 
6071da177e4SLinus Torvalds 	lock_sock(sk);
6081da177e4SLinus Torvalds 
6090381101fSJohan Hedberg 	switch (hci_pi(sk)->channel) {
6100381101fSJohan Hedberg 	case HCI_CHANNEL_RAW:
6110381101fSJohan Hedberg 		break;
6120381101fSJohan Hedberg 	case HCI_CHANNEL_CONTROL:
6130381101fSJohan Hedberg 		err = mgmt_control(sk, msg, len);
6140381101fSJohan Hedberg 		goto done;
6150381101fSJohan Hedberg 	default:
6160381101fSJohan Hedberg 		err = -EINVAL;
6170381101fSJohan Hedberg 		goto done;
6180381101fSJohan Hedberg 	}
6190381101fSJohan Hedberg 
62070f23020SAndrei Emeltchenko 	hdev = hci_pi(sk)->hdev;
62170f23020SAndrei Emeltchenko 	if (!hdev) {
6221da177e4SLinus Torvalds 		err = -EBADFD;
6231da177e4SLinus Torvalds 		goto done;
6241da177e4SLinus Torvalds 	}
6251da177e4SLinus Torvalds 
6267e21addcSMarcel Holtmann 	if (!test_bit(HCI_UP, &hdev->flags)) {
6277e21addcSMarcel Holtmann 		err = -ENETDOWN;
6287e21addcSMarcel Holtmann 		goto done;
6297e21addcSMarcel Holtmann 	}
6307e21addcSMarcel Holtmann 
63170f23020SAndrei Emeltchenko 	skb = bt_skb_send_alloc(sk, len, msg->msg_flags & MSG_DONTWAIT, &err);
63270f23020SAndrei Emeltchenko 	if (!skb)
6331da177e4SLinus Torvalds 		goto done;
6341da177e4SLinus Torvalds 
6351da177e4SLinus Torvalds 	if (memcpy_fromiovec(skb_put(skb, len), msg->msg_iov, len)) {
6361da177e4SLinus Torvalds 		err = -EFAULT;
6371da177e4SLinus Torvalds 		goto drop;
6381da177e4SLinus Torvalds 	}
6391da177e4SLinus Torvalds 
6400d48d939SMarcel Holtmann 	bt_cb(skb)->pkt_type = *((unsigned char *) skb->data);
6411da177e4SLinus Torvalds 	skb_pull(skb, 1);
6421da177e4SLinus Torvalds 	skb->dev = (void *) hdev;
6431da177e4SLinus Torvalds 
6440d48d939SMarcel Holtmann 	if (bt_cb(skb)->pkt_type == HCI_COMMAND_PKT) {
64583985319SHarvey Harrison 		u16 opcode = get_unaligned_le16(skb->data);
6461da177e4SLinus Torvalds 		u16 ogf = hci_opcode_ogf(opcode);
6471da177e4SLinus Torvalds 		u16 ocf = hci_opcode_ocf(opcode);
6481da177e4SLinus Torvalds 
6491da177e4SLinus Torvalds 		if (((ogf > HCI_SFLT_MAX_OGF) ||
6501da177e4SLinus Torvalds 				!hci_test_bit(ocf & HCI_FLT_OCF_BITS, &hci_sec_filter.ocf_mask[ogf])) &&
6511da177e4SLinus Torvalds 					!capable(CAP_NET_RAW)) {
6521da177e4SLinus Torvalds 			err = -EPERM;
6531da177e4SLinus Torvalds 			goto drop;
6541da177e4SLinus Torvalds 		}
6551da177e4SLinus Torvalds 
656a9de9248SMarcel Holtmann 		if (test_bit(HCI_RAW, &hdev->flags) || (ogf == 0x3f)) {
6571da177e4SLinus Torvalds 			skb_queue_tail(&hdev->raw_q, skb);
6583eff45eaSGustavo F. Padovan 			queue_work(hdev->workqueue, &hdev->tx_work);
6591da177e4SLinus Torvalds 		} else {
6601da177e4SLinus Torvalds 			skb_queue_tail(&hdev->cmd_q, skb);
661c347b765SGustavo F. Padovan 			queue_work(hdev->workqueue, &hdev->cmd_work);
6621da177e4SLinus Torvalds 		}
6631da177e4SLinus Torvalds 	} else {
6641da177e4SLinus Torvalds 		if (!capable(CAP_NET_RAW)) {
6651da177e4SLinus Torvalds 			err = -EPERM;
6661da177e4SLinus Torvalds 			goto drop;
6671da177e4SLinus Torvalds 		}
6681da177e4SLinus Torvalds 
6691da177e4SLinus Torvalds 		skb_queue_tail(&hdev->raw_q, skb);
6703eff45eaSGustavo F. Padovan 		queue_work(hdev->workqueue, &hdev->tx_work);
6711da177e4SLinus Torvalds 	}
6721da177e4SLinus Torvalds 
6731da177e4SLinus Torvalds 	err = len;
6741da177e4SLinus Torvalds 
6751da177e4SLinus Torvalds done:
6761da177e4SLinus Torvalds 	release_sock(sk);
6771da177e4SLinus Torvalds 	return err;
6781da177e4SLinus Torvalds 
6791da177e4SLinus Torvalds drop:
6801da177e4SLinus Torvalds 	kfree_skb(skb);
6811da177e4SLinus Torvalds 	goto done;
6821da177e4SLinus Torvalds }
6831da177e4SLinus Torvalds 
684b7058842SDavid S. Miller static int hci_sock_setsockopt(struct socket *sock, int level, int optname, char __user *optval, unsigned int len)
6851da177e4SLinus Torvalds {
6861da177e4SLinus Torvalds 	struct hci_ufilter uf = { .opcode = 0 };
6871da177e4SLinus Torvalds 	struct sock *sk = sock->sk;
6881da177e4SLinus Torvalds 	int err = 0, opt = 0;
6891da177e4SLinus Torvalds 
6901da177e4SLinus Torvalds 	BT_DBG("sk %p, opt %d", sk, optname);
6911da177e4SLinus Torvalds 
6921da177e4SLinus Torvalds 	lock_sock(sk);
6931da177e4SLinus Torvalds 
6942f39cdb7SMarcel Holtmann 	if (hci_pi(sk)->channel != HCI_CHANNEL_RAW) {
6952f39cdb7SMarcel Holtmann 		err = -EINVAL;
6962f39cdb7SMarcel Holtmann 		goto done;
6972f39cdb7SMarcel Holtmann 	}
6982f39cdb7SMarcel Holtmann 
6991da177e4SLinus Torvalds 	switch (optname) {
7001da177e4SLinus Torvalds 	case HCI_DATA_DIR:
7011da177e4SLinus Torvalds 		if (get_user(opt, (int __user *)optval)) {
7021da177e4SLinus Torvalds 			err = -EFAULT;
7031da177e4SLinus Torvalds 			break;
7041da177e4SLinus Torvalds 		}
7051da177e4SLinus Torvalds 
7061da177e4SLinus Torvalds 		if (opt)
7071da177e4SLinus Torvalds 			hci_pi(sk)->cmsg_mask |= HCI_CMSG_DIR;
7081da177e4SLinus Torvalds 		else
7091da177e4SLinus Torvalds 			hci_pi(sk)->cmsg_mask &= ~HCI_CMSG_DIR;
7101da177e4SLinus Torvalds 		break;
7111da177e4SLinus Torvalds 
7121da177e4SLinus Torvalds 	case HCI_TIME_STAMP:
7131da177e4SLinus Torvalds 		if (get_user(opt, (int __user *)optval)) {
7141da177e4SLinus Torvalds 			err = -EFAULT;
7151da177e4SLinus Torvalds 			break;
7161da177e4SLinus Torvalds 		}
7171da177e4SLinus Torvalds 
7181da177e4SLinus Torvalds 		if (opt)
7191da177e4SLinus Torvalds 			hci_pi(sk)->cmsg_mask |= HCI_CMSG_TSTAMP;
7201da177e4SLinus Torvalds 		else
7211da177e4SLinus Torvalds 			hci_pi(sk)->cmsg_mask &= ~HCI_CMSG_TSTAMP;
7221da177e4SLinus Torvalds 		break;
7231da177e4SLinus Torvalds 
7241da177e4SLinus Torvalds 	case HCI_FILTER:
7250878b666SMarcel Holtmann 		{
7260878b666SMarcel Holtmann 			struct hci_filter *f = &hci_pi(sk)->filter;
7270878b666SMarcel Holtmann 
7280878b666SMarcel Holtmann 			uf.type_mask = f->type_mask;
7290878b666SMarcel Holtmann 			uf.opcode    = f->opcode;
7300878b666SMarcel Holtmann 			uf.event_mask[0] = *((u32 *) f->event_mask + 0);
7310878b666SMarcel Holtmann 			uf.event_mask[1] = *((u32 *) f->event_mask + 1);
7320878b666SMarcel Holtmann 		}
7330878b666SMarcel Holtmann 
7341da177e4SLinus Torvalds 		len = min_t(unsigned int, len, sizeof(uf));
7351da177e4SLinus Torvalds 		if (copy_from_user(&uf, optval, len)) {
7361da177e4SLinus Torvalds 			err = -EFAULT;
7371da177e4SLinus Torvalds 			break;
7381da177e4SLinus Torvalds 		}
7391da177e4SLinus Torvalds 
7401da177e4SLinus Torvalds 		if (!capable(CAP_NET_RAW)) {
7411da177e4SLinus Torvalds 			uf.type_mask &= hci_sec_filter.type_mask;
7421da177e4SLinus Torvalds 			uf.event_mask[0] &= *((u32 *) hci_sec_filter.event_mask + 0);
7431da177e4SLinus Torvalds 			uf.event_mask[1] &= *((u32 *) hci_sec_filter.event_mask + 1);
7441da177e4SLinus Torvalds 		}
7451da177e4SLinus Torvalds 
7461da177e4SLinus Torvalds 		{
7471da177e4SLinus Torvalds 			struct hci_filter *f = &hci_pi(sk)->filter;
7481da177e4SLinus Torvalds 
7491da177e4SLinus Torvalds 			f->type_mask = uf.type_mask;
7501da177e4SLinus Torvalds 			f->opcode    = uf.opcode;
7511da177e4SLinus Torvalds 			*((u32 *) f->event_mask + 0) = uf.event_mask[0];
7521da177e4SLinus Torvalds 			*((u32 *) f->event_mask + 1) = uf.event_mask[1];
7531da177e4SLinus Torvalds 		}
7541da177e4SLinus Torvalds 		break;
7551da177e4SLinus Torvalds 
7561da177e4SLinus Torvalds 	default:
7571da177e4SLinus Torvalds 		err = -ENOPROTOOPT;
7581da177e4SLinus Torvalds 		break;
7591da177e4SLinus Torvalds 	}
7601da177e4SLinus Torvalds 
7612f39cdb7SMarcel Holtmann done:
7621da177e4SLinus Torvalds 	release_sock(sk);
7631da177e4SLinus Torvalds 	return err;
7641da177e4SLinus Torvalds }
7651da177e4SLinus Torvalds 
7661da177e4SLinus Torvalds static int hci_sock_getsockopt(struct socket *sock, int level, int optname, char __user *optval, int __user *optlen)
7671da177e4SLinus Torvalds {
7681da177e4SLinus Torvalds 	struct hci_ufilter uf;
7691da177e4SLinus Torvalds 	struct sock *sk = sock->sk;
770cedc5469SMarcel Holtmann 	int len, opt, err = 0;
771cedc5469SMarcel Holtmann 
772cedc5469SMarcel Holtmann 	BT_DBG("sk %p, opt %d", sk, optname);
7731da177e4SLinus Torvalds 
7741da177e4SLinus Torvalds 	if (get_user(len, optlen))
7751da177e4SLinus Torvalds 		return -EFAULT;
7761da177e4SLinus Torvalds 
777cedc5469SMarcel Holtmann 	lock_sock(sk);
778cedc5469SMarcel Holtmann 
779cedc5469SMarcel Holtmann 	if (hci_pi(sk)->channel != HCI_CHANNEL_RAW) {
780cedc5469SMarcel Holtmann 		err = -EINVAL;
781cedc5469SMarcel Holtmann 		goto done;
782cedc5469SMarcel Holtmann 	}
783cedc5469SMarcel Holtmann 
7841da177e4SLinus Torvalds 	switch (optname) {
7851da177e4SLinus Torvalds 	case HCI_DATA_DIR:
7861da177e4SLinus Torvalds 		if (hci_pi(sk)->cmsg_mask & HCI_CMSG_DIR)
7871da177e4SLinus Torvalds 			opt = 1;
7881da177e4SLinus Torvalds 		else
7891da177e4SLinus Torvalds 			opt = 0;
7901da177e4SLinus Torvalds 
7911da177e4SLinus Torvalds 		if (put_user(opt, optval))
792cedc5469SMarcel Holtmann 			err = -EFAULT;
7931da177e4SLinus Torvalds 		break;
7941da177e4SLinus Torvalds 
7951da177e4SLinus Torvalds 	case HCI_TIME_STAMP:
7961da177e4SLinus Torvalds 		if (hci_pi(sk)->cmsg_mask & HCI_CMSG_TSTAMP)
7971da177e4SLinus Torvalds 			opt = 1;
7981da177e4SLinus Torvalds 		else
7991da177e4SLinus Torvalds 			opt = 0;
8001da177e4SLinus Torvalds 
8011da177e4SLinus Torvalds 		if (put_user(opt, optval))
802cedc5469SMarcel Holtmann 			err = -EFAULT;
8031da177e4SLinus Torvalds 		break;
8041da177e4SLinus Torvalds 
8051da177e4SLinus Torvalds 	case HCI_FILTER:
8061da177e4SLinus Torvalds 		{
8071da177e4SLinus Torvalds 			struct hci_filter *f = &hci_pi(sk)->filter;
8081da177e4SLinus Torvalds 
8091da177e4SLinus Torvalds 			uf.type_mask = f->type_mask;
8101da177e4SLinus Torvalds 			uf.opcode    = f->opcode;
8111da177e4SLinus Torvalds 			uf.event_mask[0] = *((u32 *) f->event_mask + 0);
8121da177e4SLinus Torvalds 			uf.event_mask[1] = *((u32 *) f->event_mask + 1);
8131da177e4SLinus Torvalds 		}
8141da177e4SLinus Torvalds 
8151da177e4SLinus Torvalds 		len = min_t(unsigned int, len, sizeof(uf));
8161da177e4SLinus Torvalds 		if (copy_to_user(optval, &uf, len))
817cedc5469SMarcel Holtmann 			err = -EFAULT;
8181da177e4SLinus Torvalds 		break;
8191da177e4SLinus Torvalds 
8201da177e4SLinus Torvalds 	default:
821cedc5469SMarcel Holtmann 		err = -ENOPROTOOPT;
8221da177e4SLinus Torvalds 		break;
8231da177e4SLinus Torvalds 	}
8241da177e4SLinus Torvalds 
825cedc5469SMarcel Holtmann done:
826cedc5469SMarcel Holtmann 	release_sock(sk);
827cedc5469SMarcel Holtmann 	return err;
8281da177e4SLinus Torvalds }
8291da177e4SLinus Torvalds 
83090ddc4f0SEric Dumazet static const struct proto_ops hci_sock_ops = {
8311da177e4SLinus Torvalds 	.family		= PF_BLUETOOTH,
8321da177e4SLinus Torvalds 	.owner		= THIS_MODULE,
8331da177e4SLinus Torvalds 	.release	= hci_sock_release,
8341da177e4SLinus Torvalds 	.bind		= hci_sock_bind,
8351da177e4SLinus Torvalds 	.getname	= hci_sock_getname,
8361da177e4SLinus Torvalds 	.sendmsg	= hci_sock_sendmsg,
8371da177e4SLinus Torvalds 	.recvmsg	= hci_sock_recvmsg,
8381da177e4SLinus Torvalds 	.ioctl		= hci_sock_ioctl,
8391da177e4SLinus Torvalds 	.poll		= datagram_poll,
8401da177e4SLinus Torvalds 	.listen		= sock_no_listen,
8411da177e4SLinus Torvalds 	.shutdown	= sock_no_shutdown,
8421da177e4SLinus Torvalds 	.setsockopt	= hci_sock_setsockopt,
8431da177e4SLinus Torvalds 	.getsockopt	= hci_sock_getsockopt,
8441da177e4SLinus Torvalds 	.connect	= sock_no_connect,
8451da177e4SLinus Torvalds 	.socketpair	= sock_no_socketpair,
8461da177e4SLinus Torvalds 	.accept		= sock_no_accept,
8471da177e4SLinus Torvalds 	.mmap		= sock_no_mmap
8481da177e4SLinus Torvalds };
8491da177e4SLinus Torvalds 
8501da177e4SLinus Torvalds static struct proto hci_sk_proto = {
8511da177e4SLinus Torvalds 	.name		= "HCI",
8521da177e4SLinus Torvalds 	.owner		= THIS_MODULE,
8531da177e4SLinus Torvalds 	.obj_size	= sizeof(struct hci_pinfo)
8541da177e4SLinus Torvalds };
8551da177e4SLinus Torvalds 
8563f378b68SEric Paris static int hci_sock_create(struct net *net, struct socket *sock, int protocol,
8573f378b68SEric Paris 			   int kern)
8581da177e4SLinus Torvalds {
8591da177e4SLinus Torvalds 	struct sock *sk;
8601da177e4SLinus Torvalds 
8611da177e4SLinus Torvalds 	BT_DBG("sock %p", sock);
8621da177e4SLinus Torvalds 
8631da177e4SLinus Torvalds 	if (sock->type != SOCK_RAW)
8641da177e4SLinus Torvalds 		return -ESOCKTNOSUPPORT;
8651da177e4SLinus Torvalds 
8661da177e4SLinus Torvalds 	sock->ops = &hci_sock_ops;
8671da177e4SLinus Torvalds 
8686257ff21SPavel Emelyanov 	sk = sk_alloc(net, PF_BLUETOOTH, GFP_ATOMIC, &hci_sk_proto);
8691da177e4SLinus Torvalds 	if (!sk)
8701da177e4SLinus Torvalds 		return -ENOMEM;
8711da177e4SLinus Torvalds 
8721da177e4SLinus Torvalds 	sock_init_data(sock, sk);
8731da177e4SLinus Torvalds 
8741da177e4SLinus Torvalds 	sock_reset_flag(sk, SOCK_ZAPPED);
8751da177e4SLinus Torvalds 
8761da177e4SLinus Torvalds 	sk->sk_protocol = protocol;
8771da177e4SLinus Torvalds 
8781da177e4SLinus Torvalds 	sock->state = SS_UNCONNECTED;
8791da177e4SLinus Torvalds 	sk->sk_state = BT_OPEN;
8801da177e4SLinus Torvalds 
8811da177e4SLinus Torvalds 	bt_sock_link(&hci_sk_list, sk);
8821da177e4SLinus Torvalds 	return 0;
8831da177e4SLinus Torvalds }
8841da177e4SLinus Torvalds 
885ec1b4cf7SStephen Hemminger static const struct net_proto_family hci_sock_family_ops = {
8861da177e4SLinus Torvalds 	.family	= PF_BLUETOOTH,
8871da177e4SLinus Torvalds 	.owner	= THIS_MODULE,
8881da177e4SLinus Torvalds 	.create	= hci_sock_create,
8891da177e4SLinus Torvalds };
8901da177e4SLinus Torvalds 
8911da177e4SLinus Torvalds int __init hci_sock_init(void)
8921da177e4SLinus Torvalds {
8931da177e4SLinus Torvalds 	int err;
8941da177e4SLinus Torvalds 
8951da177e4SLinus Torvalds 	err = proto_register(&hci_sk_proto, 0);
8961da177e4SLinus Torvalds 	if (err < 0)
8971da177e4SLinus Torvalds 		return err;
8981da177e4SLinus Torvalds 
8991da177e4SLinus Torvalds 	err = bt_sock_register(BTPROTO_HCI, &hci_sock_family_ops);
9001da177e4SLinus Torvalds 	if (err < 0)
9011da177e4SLinus Torvalds 		goto error;
9021da177e4SLinus Torvalds 
9031da177e4SLinus Torvalds 	BT_INFO("HCI socket layer initialized");
9041da177e4SLinus Torvalds 
9051da177e4SLinus Torvalds 	return 0;
9061da177e4SLinus Torvalds 
9071da177e4SLinus Torvalds error:
9081da177e4SLinus Torvalds 	BT_ERR("HCI socket registration failed");
9091da177e4SLinus Torvalds 	proto_unregister(&hci_sk_proto);
9101da177e4SLinus Torvalds 	return err;
9111da177e4SLinus Torvalds }
9121da177e4SLinus Torvalds 
913b7440a14SAnand Gadiyar void hci_sock_cleanup(void)
9141da177e4SLinus Torvalds {
9151da177e4SLinus Torvalds 	if (bt_sock_unregister(BTPROTO_HCI) < 0)
9161da177e4SLinus Torvalds 		BT_ERR("HCI socket unregistration failed");
9171da177e4SLinus Torvalds 
9181da177e4SLinus Torvalds 	proto_unregister(&hci_sk_proto);
9191da177e4SLinus Torvalds }
9200381101fSJohan Hedberg 
9210381101fSJohan Hedberg module_param(enable_mgmt, bool, 0644);
9220381101fSJohan Hedberg MODULE_PARM_DESC(enable_mgmt, "Enable Management interface");
923