11da177e4SLinus Torvalds /* 21da177e4SLinus Torvalds BlueZ - Bluetooth protocol stack for Linux 31da177e4SLinus Torvalds Copyright (C) 2000-2001 Qualcomm Incorporated 41da177e4SLinus Torvalds 51da177e4SLinus Torvalds Written 2000,2001 by Maxim Krasnyansky <maxk@qualcomm.com> 61da177e4SLinus Torvalds 71da177e4SLinus Torvalds This program is free software; you can redistribute it and/or modify 81da177e4SLinus Torvalds it under the terms of the GNU General Public License version 2 as 91da177e4SLinus Torvalds published by the Free Software Foundation; 101da177e4SLinus Torvalds 111da177e4SLinus Torvalds THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS 121da177e4SLinus Torvalds OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, 131da177e4SLinus Torvalds FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT OF THIRD PARTY RIGHTS. 141da177e4SLinus Torvalds IN NO EVENT SHALL THE COPYRIGHT HOLDER(S) AND AUTHOR(S) BE LIABLE FOR ANY 151da177e4SLinus Torvalds CLAIM, OR ANY SPECIAL INDIRECT OR CONSEQUENTIAL DAMAGES, OR ANY DAMAGES 161da177e4SLinus Torvalds WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN 171da177e4SLinus Torvalds ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF 181da177e4SLinus Torvalds OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. 191da177e4SLinus Torvalds 201da177e4SLinus Torvalds ALL LIABILITY, INCLUDING LIABILITY FOR INFRINGEMENT OF ANY PATENTS, 211da177e4SLinus Torvalds COPYRIGHTS, TRADEMARKS OR OTHER RIGHTS, RELATING TO USE OF THIS 221da177e4SLinus Torvalds SOFTWARE IS DISCLAIMED. 231da177e4SLinus Torvalds */ 241da177e4SLinus Torvalds 251da177e4SLinus Torvalds /* Bluetooth HCI sockets. */ 261da177e4SLinus Torvalds 271da177e4SLinus Torvalds #include <linux/module.h> 281da177e4SLinus Torvalds 291da177e4SLinus Torvalds #include <linux/types.h> 304fc268d2SRandy Dunlap #include <linux/capability.h> 311da177e4SLinus Torvalds #include <linux/errno.h> 321da177e4SLinus Torvalds #include <linux/kernel.h> 331da177e4SLinus Torvalds #include <linux/slab.h> 341da177e4SLinus Torvalds #include <linux/poll.h> 351da177e4SLinus Torvalds #include <linux/fcntl.h> 361da177e4SLinus Torvalds #include <linux/init.h> 371da177e4SLinus Torvalds #include <linux/skbuff.h> 381da177e4SLinus Torvalds #include <linux/workqueue.h> 391da177e4SLinus Torvalds #include <linux/interrupt.h> 40767c5eb5SMarcel Holtmann #include <linux/compat.h> 411da177e4SLinus Torvalds #include <linux/socket.h> 421da177e4SLinus Torvalds #include <linux/ioctl.h> 431da177e4SLinus Torvalds #include <net/sock.h> 441da177e4SLinus Torvalds 451da177e4SLinus Torvalds #include <asm/system.h> 461da177e4SLinus Torvalds #include <asm/uaccess.h> 471da177e4SLinus Torvalds #include <asm/unaligned.h> 481da177e4SLinus Torvalds 491da177e4SLinus Torvalds #include <net/bluetooth/bluetooth.h> 501da177e4SLinus Torvalds #include <net/bluetooth/hci_core.h> 511da177e4SLinus Torvalds 521da177e4SLinus Torvalds #ifndef CONFIG_BT_HCI_SOCK_DEBUG 531da177e4SLinus Torvalds #undef BT_DBG 541da177e4SLinus Torvalds #define BT_DBG(D...) 551da177e4SLinus Torvalds #endif 561da177e4SLinus Torvalds 571da177e4SLinus Torvalds /* ----- HCI socket interface ----- */ 581da177e4SLinus Torvalds 591da177e4SLinus Torvalds static inline int hci_test_bit(int nr, void *addr) 601da177e4SLinus Torvalds { 611da177e4SLinus Torvalds return *((__u32 *) addr + (nr >> 5)) & ((__u32) 1 << (nr & 31)); 621da177e4SLinus Torvalds } 631da177e4SLinus Torvalds 641da177e4SLinus Torvalds /* Security filter */ 651da177e4SLinus Torvalds static struct hci_sec_filter hci_sec_filter = { 661da177e4SLinus Torvalds /* Packet types */ 671da177e4SLinus Torvalds 0x10, 681da177e4SLinus Torvalds /* Events */ 69dd7f5527SMarcel Holtmann { 0x1000d9fe, 0x0000b00c }, 701da177e4SLinus Torvalds /* Commands */ 711da177e4SLinus Torvalds { 721da177e4SLinus Torvalds { 0x0 }, 731da177e4SLinus Torvalds /* OGF_LINK_CTL */ 74*7c631a67SMarcel Holtmann { 0xbe000006, 0x00000001, 0x00000000, 0x00 }, 751da177e4SLinus Torvalds /* OGF_LINK_POLICY */ 76*7c631a67SMarcel Holtmann { 0x00005200, 0x00000000, 0x00000000, 0x00 }, 771da177e4SLinus Torvalds /* OGF_HOST_CTL */ 78*7c631a67SMarcel Holtmann { 0xaab00200, 0x2b402aaa, 0x05220154, 0x00 }, 791da177e4SLinus Torvalds /* OGF_INFO_PARAM */ 80*7c631a67SMarcel Holtmann { 0x000002be, 0x00000000, 0x00000000, 0x00 }, 811da177e4SLinus Torvalds /* OGF_STATUS_PARAM */ 82*7c631a67SMarcel Holtmann { 0x000000ea, 0x00000000, 0x00000000, 0x00 } 831da177e4SLinus Torvalds } 841da177e4SLinus Torvalds }; 851da177e4SLinus Torvalds 861da177e4SLinus Torvalds static struct bt_sock_list hci_sk_list = { 871da177e4SLinus Torvalds .lock = RW_LOCK_UNLOCKED 881da177e4SLinus Torvalds }; 891da177e4SLinus Torvalds 901da177e4SLinus Torvalds /* Send frame to RAW socket */ 911da177e4SLinus Torvalds void hci_send_to_sock(struct hci_dev *hdev, struct sk_buff *skb) 921da177e4SLinus Torvalds { 931da177e4SLinus Torvalds struct sock *sk; 941da177e4SLinus Torvalds struct hlist_node *node; 951da177e4SLinus Torvalds 961da177e4SLinus Torvalds BT_DBG("hdev %p len %d", hdev, skb->len); 971da177e4SLinus Torvalds 981da177e4SLinus Torvalds read_lock(&hci_sk_list.lock); 991da177e4SLinus Torvalds sk_for_each(sk, node, &hci_sk_list.head) { 1001da177e4SLinus Torvalds struct hci_filter *flt; 1011da177e4SLinus Torvalds struct sk_buff *nskb; 1021da177e4SLinus Torvalds 1031da177e4SLinus Torvalds if (sk->sk_state != BT_BOUND || hci_pi(sk)->hdev != hdev) 1041da177e4SLinus Torvalds continue; 1051da177e4SLinus Torvalds 1061da177e4SLinus Torvalds /* Don't send frame to the socket it came from */ 1071da177e4SLinus Torvalds if (skb->sk == sk) 1081da177e4SLinus Torvalds continue; 1091da177e4SLinus Torvalds 1101da177e4SLinus Torvalds /* Apply filter */ 1111da177e4SLinus Torvalds flt = &hci_pi(sk)->filter; 1121da177e4SLinus Torvalds 1130d48d939SMarcel Holtmann if (!test_bit((bt_cb(skb)->pkt_type == HCI_VENDOR_PKT) ? 1140d48d939SMarcel Holtmann 0 : (bt_cb(skb)->pkt_type & HCI_FLT_TYPE_BITS), &flt->type_mask)) 1151da177e4SLinus Torvalds continue; 1161da177e4SLinus Torvalds 1170d48d939SMarcel Holtmann if (bt_cb(skb)->pkt_type == HCI_EVENT_PKT) { 1181da177e4SLinus Torvalds register int evt = (*(__u8 *)skb->data & HCI_FLT_EVENT_BITS); 1191da177e4SLinus Torvalds 1201da177e4SLinus Torvalds if (!hci_test_bit(evt, &flt->event_mask)) 1211da177e4SLinus Torvalds continue; 1221da177e4SLinus Torvalds 1234498c80dSDavid S. Miller if (flt->opcode && 1244498c80dSDavid S. Miller ((evt == HCI_EV_CMD_COMPLETE && 1254498c80dSDavid S. Miller flt->opcode != 126905f3ed6SAl Viro get_unaligned((__le16 *)(skb->data + 3))) || 1271da177e4SLinus Torvalds (evt == HCI_EV_CMD_STATUS && 1284498c80dSDavid S. Miller flt->opcode != 129905f3ed6SAl Viro get_unaligned((__le16 *)(skb->data + 4))))) 1301da177e4SLinus Torvalds continue; 1311da177e4SLinus Torvalds } 1321da177e4SLinus Torvalds 1331da177e4SLinus Torvalds if (!(nskb = skb_clone(skb, GFP_ATOMIC))) 1341da177e4SLinus Torvalds continue; 1351da177e4SLinus Torvalds 1361da177e4SLinus Torvalds /* Put type byte before the data */ 1370d48d939SMarcel Holtmann memcpy(skb_push(nskb, 1), &bt_cb(nskb)->pkt_type, 1); 1381da177e4SLinus Torvalds 1391da177e4SLinus Torvalds if (sock_queue_rcv_skb(sk, nskb)) 1401da177e4SLinus Torvalds kfree_skb(nskb); 1411da177e4SLinus Torvalds } 1421da177e4SLinus Torvalds read_unlock(&hci_sk_list.lock); 1431da177e4SLinus Torvalds } 1441da177e4SLinus Torvalds 1451da177e4SLinus Torvalds static int hci_sock_release(struct socket *sock) 1461da177e4SLinus Torvalds { 1471da177e4SLinus Torvalds struct sock *sk = sock->sk; 1487b005bd3SMarcel Holtmann struct hci_dev *hdev; 1491da177e4SLinus Torvalds 1501da177e4SLinus Torvalds BT_DBG("sock %p sk %p", sock, sk); 1511da177e4SLinus Torvalds 1521da177e4SLinus Torvalds if (!sk) 1531da177e4SLinus Torvalds return 0; 1541da177e4SLinus Torvalds 1557b005bd3SMarcel Holtmann hdev = hci_pi(sk)->hdev; 1567b005bd3SMarcel Holtmann 1571da177e4SLinus Torvalds bt_sock_unlink(&hci_sk_list, sk); 1581da177e4SLinus Torvalds 1591da177e4SLinus Torvalds if (hdev) { 1601da177e4SLinus Torvalds atomic_dec(&hdev->promisc); 1611da177e4SLinus Torvalds hci_dev_put(hdev); 1621da177e4SLinus Torvalds } 1631da177e4SLinus Torvalds 1641da177e4SLinus Torvalds sock_orphan(sk); 1651da177e4SLinus Torvalds 1661da177e4SLinus Torvalds skb_queue_purge(&sk->sk_receive_queue); 1671da177e4SLinus Torvalds skb_queue_purge(&sk->sk_write_queue); 1681da177e4SLinus Torvalds 1691da177e4SLinus Torvalds sock_put(sk); 1701da177e4SLinus Torvalds return 0; 1711da177e4SLinus Torvalds } 1721da177e4SLinus Torvalds 1731da177e4SLinus Torvalds /* Ioctls that require bound socket */ 1741da177e4SLinus Torvalds static inline int hci_sock_bound_ioctl(struct sock *sk, unsigned int cmd, unsigned long arg) 1751da177e4SLinus Torvalds { 1761da177e4SLinus Torvalds struct hci_dev *hdev = hci_pi(sk)->hdev; 1771da177e4SLinus Torvalds 1781da177e4SLinus Torvalds if (!hdev) 1791da177e4SLinus Torvalds return -EBADFD; 1801da177e4SLinus Torvalds 1811da177e4SLinus Torvalds switch (cmd) { 1821da177e4SLinus Torvalds case HCISETRAW: 1831da177e4SLinus Torvalds if (!capable(CAP_NET_ADMIN)) 1841da177e4SLinus Torvalds return -EACCES; 1851da177e4SLinus Torvalds 1861da177e4SLinus Torvalds if (test_bit(HCI_QUIRK_RAW_DEVICE, &hdev->quirks)) 1871da177e4SLinus Torvalds return -EPERM; 1881da177e4SLinus Torvalds 1891da177e4SLinus Torvalds if (arg) 1901da177e4SLinus Torvalds set_bit(HCI_RAW, &hdev->flags); 1911da177e4SLinus Torvalds else 1921da177e4SLinus Torvalds clear_bit(HCI_RAW, &hdev->flags); 1931da177e4SLinus Torvalds 1941da177e4SLinus Torvalds return 0; 1951da177e4SLinus Torvalds 1961da177e4SLinus Torvalds case HCISETSECMGR: 1971da177e4SLinus Torvalds if (!capable(CAP_NET_ADMIN)) 1981da177e4SLinus Torvalds return -EACCES; 1991da177e4SLinus Torvalds 2001da177e4SLinus Torvalds if (arg) 2011da177e4SLinus Torvalds set_bit(HCI_SECMGR, &hdev->flags); 2021da177e4SLinus Torvalds else 2031da177e4SLinus Torvalds clear_bit(HCI_SECMGR, &hdev->flags); 2041da177e4SLinus Torvalds 2051da177e4SLinus Torvalds return 0; 2061da177e4SLinus Torvalds 2071da177e4SLinus Torvalds case HCIGETCONNINFO: 2081da177e4SLinus Torvalds return hci_get_conn_info(hdev, (void __user *)arg); 2091da177e4SLinus Torvalds 2101da177e4SLinus Torvalds default: 2111da177e4SLinus Torvalds if (hdev->ioctl) 2121da177e4SLinus Torvalds return hdev->ioctl(hdev, cmd, arg); 2131da177e4SLinus Torvalds return -EINVAL; 2141da177e4SLinus Torvalds } 2151da177e4SLinus Torvalds } 2161da177e4SLinus Torvalds 2171da177e4SLinus Torvalds static int hci_sock_ioctl(struct socket *sock, unsigned int cmd, unsigned long arg) 2181da177e4SLinus Torvalds { 2191da177e4SLinus Torvalds struct sock *sk = sock->sk; 2201da177e4SLinus Torvalds void __user *argp = (void __user *)arg; 2211da177e4SLinus Torvalds int err; 2221da177e4SLinus Torvalds 2231da177e4SLinus Torvalds BT_DBG("cmd %x arg %lx", cmd, arg); 2241da177e4SLinus Torvalds 2251da177e4SLinus Torvalds switch (cmd) { 2261da177e4SLinus Torvalds case HCIGETDEVLIST: 2271da177e4SLinus Torvalds return hci_get_dev_list(argp); 2281da177e4SLinus Torvalds 2291da177e4SLinus Torvalds case HCIGETDEVINFO: 2301da177e4SLinus Torvalds return hci_get_dev_info(argp); 2311da177e4SLinus Torvalds 2321da177e4SLinus Torvalds case HCIGETCONNLIST: 2331da177e4SLinus Torvalds return hci_get_conn_list(argp); 2341da177e4SLinus Torvalds 2351da177e4SLinus Torvalds case HCIDEVUP: 2361da177e4SLinus Torvalds if (!capable(CAP_NET_ADMIN)) 2371da177e4SLinus Torvalds return -EACCES; 2381da177e4SLinus Torvalds return hci_dev_open(arg); 2391da177e4SLinus Torvalds 2401da177e4SLinus Torvalds case HCIDEVDOWN: 2411da177e4SLinus Torvalds if (!capable(CAP_NET_ADMIN)) 2421da177e4SLinus Torvalds return -EACCES; 2431da177e4SLinus Torvalds return hci_dev_close(arg); 2441da177e4SLinus Torvalds 2451da177e4SLinus Torvalds case HCIDEVRESET: 2461da177e4SLinus Torvalds if (!capable(CAP_NET_ADMIN)) 2471da177e4SLinus Torvalds return -EACCES; 2481da177e4SLinus Torvalds return hci_dev_reset(arg); 2491da177e4SLinus Torvalds 2501da177e4SLinus Torvalds case HCIDEVRESTAT: 2511da177e4SLinus Torvalds if (!capable(CAP_NET_ADMIN)) 2521da177e4SLinus Torvalds return -EACCES; 2531da177e4SLinus Torvalds return hci_dev_reset_stat(arg); 2541da177e4SLinus Torvalds 2551da177e4SLinus Torvalds case HCISETSCAN: 2561da177e4SLinus Torvalds case HCISETAUTH: 2571da177e4SLinus Torvalds case HCISETENCRYPT: 2581da177e4SLinus Torvalds case HCISETPTYPE: 2591da177e4SLinus Torvalds case HCISETLINKPOL: 2601da177e4SLinus Torvalds case HCISETLINKMODE: 2611da177e4SLinus Torvalds case HCISETACLMTU: 2621da177e4SLinus Torvalds case HCISETSCOMTU: 2631da177e4SLinus Torvalds if (!capable(CAP_NET_ADMIN)) 2641da177e4SLinus Torvalds return -EACCES; 2651da177e4SLinus Torvalds return hci_dev_cmd(cmd, argp); 2661da177e4SLinus Torvalds 2671da177e4SLinus Torvalds case HCIINQUIRY: 2681da177e4SLinus Torvalds return hci_inquiry(argp); 2691da177e4SLinus Torvalds 2701da177e4SLinus Torvalds default: 2711da177e4SLinus Torvalds lock_sock(sk); 2721da177e4SLinus Torvalds err = hci_sock_bound_ioctl(sk, cmd, arg); 2731da177e4SLinus Torvalds release_sock(sk); 2741da177e4SLinus Torvalds return err; 2751da177e4SLinus Torvalds } 2761da177e4SLinus Torvalds } 2771da177e4SLinus Torvalds 2781da177e4SLinus Torvalds static int hci_sock_bind(struct socket *sock, struct sockaddr *addr, int addr_len) 2791da177e4SLinus Torvalds { 2801da177e4SLinus Torvalds struct sockaddr_hci *haddr = (struct sockaddr_hci *) addr; 2811da177e4SLinus Torvalds struct sock *sk = sock->sk; 2821da177e4SLinus Torvalds struct hci_dev *hdev = NULL; 2831da177e4SLinus Torvalds int err = 0; 2841da177e4SLinus Torvalds 2851da177e4SLinus Torvalds BT_DBG("sock %p sk %p", sock, sk); 2861da177e4SLinus Torvalds 2871da177e4SLinus Torvalds if (!haddr || haddr->hci_family != AF_BLUETOOTH) 2881da177e4SLinus Torvalds return -EINVAL; 2891da177e4SLinus Torvalds 2901da177e4SLinus Torvalds lock_sock(sk); 2911da177e4SLinus Torvalds 2921da177e4SLinus Torvalds if (hci_pi(sk)->hdev) { 2931da177e4SLinus Torvalds err = -EALREADY; 2941da177e4SLinus Torvalds goto done; 2951da177e4SLinus Torvalds } 2961da177e4SLinus Torvalds 2971da177e4SLinus Torvalds if (haddr->hci_dev != HCI_DEV_NONE) { 2981da177e4SLinus Torvalds if (!(hdev = hci_dev_get(haddr->hci_dev))) { 2991da177e4SLinus Torvalds err = -ENODEV; 3001da177e4SLinus Torvalds goto done; 3011da177e4SLinus Torvalds } 3021da177e4SLinus Torvalds 3031da177e4SLinus Torvalds atomic_inc(&hdev->promisc); 3041da177e4SLinus Torvalds } 3051da177e4SLinus Torvalds 3061da177e4SLinus Torvalds hci_pi(sk)->hdev = hdev; 3071da177e4SLinus Torvalds sk->sk_state = BT_BOUND; 3081da177e4SLinus Torvalds 3091da177e4SLinus Torvalds done: 3101da177e4SLinus Torvalds release_sock(sk); 3111da177e4SLinus Torvalds return err; 3121da177e4SLinus Torvalds } 3131da177e4SLinus Torvalds 3141da177e4SLinus Torvalds static int hci_sock_getname(struct socket *sock, struct sockaddr *addr, int *addr_len, int peer) 3151da177e4SLinus Torvalds { 3161da177e4SLinus Torvalds struct sockaddr_hci *haddr = (struct sockaddr_hci *) addr; 3171da177e4SLinus Torvalds struct sock *sk = sock->sk; 3187b005bd3SMarcel Holtmann struct hci_dev *hdev = hci_pi(sk)->hdev; 3191da177e4SLinus Torvalds 3201da177e4SLinus Torvalds BT_DBG("sock %p sk %p", sock, sk); 3211da177e4SLinus Torvalds 3227b005bd3SMarcel Holtmann if (!hdev) 3237b005bd3SMarcel Holtmann return -EBADFD; 3247b005bd3SMarcel Holtmann 3251da177e4SLinus Torvalds lock_sock(sk); 3261da177e4SLinus Torvalds 3271da177e4SLinus Torvalds *addr_len = sizeof(*haddr); 3281da177e4SLinus Torvalds haddr->hci_family = AF_BLUETOOTH; 3297b005bd3SMarcel Holtmann haddr->hci_dev = hdev->id; 3301da177e4SLinus Torvalds 3311da177e4SLinus Torvalds release_sock(sk); 3321da177e4SLinus Torvalds return 0; 3331da177e4SLinus Torvalds } 3341da177e4SLinus Torvalds 3351da177e4SLinus Torvalds static inline void hci_sock_cmsg(struct sock *sk, struct msghdr *msg, struct sk_buff *skb) 3361da177e4SLinus Torvalds { 3371da177e4SLinus Torvalds __u32 mask = hci_pi(sk)->cmsg_mask; 3381da177e4SLinus Torvalds 3390d48d939SMarcel Holtmann if (mask & HCI_CMSG_DIR) { 3400d48d939SMarcel Holtmann int incoming = bt_cb(skb)->incoming; 3410d48d939SMarcel Holtmann put_cmsg(msg, SOL_HCI, HCI_CMSG_DIR, sizeof(incoming), &incoming); 3420d48d939SMarcel Holtmann } 3431da177e4SLinus Torvalds 344a61bbcf2SPatrick McHardy if (mask & HCI_CMSG_TSTAMP) { 345a61bbcf2SPatrick McHardy struct timeval tv; 346767c5eb5SMarcel Holtmann void *data; 347767c5eb5SMarcel Holtmann int len; 348a61bbcf2SPatrick McHardy 349a61bbcf2SPatrick McHardy skb_get_timestamp(skb, &tv); 350767c5eb5SMarcel Holtmann 351767c5eb5SMarcel Holtmann if (msg->msg_flags & MSG_CMSG_COMPAT) { 352767c5eb5SMarcel Holtmann struct compat_timeval ctv; 353767c5eb5SMarcel Holtmann ctv.tv_sec = tv.tv_sec; 354767c5eb5SMarcel Holtmann ctv.tv_usec = tv.tv_usec; 355767c5eb5SMarcel Holtmann data = &ctv; 356767c5eb5SMarcel Holtmann len = sizeof(ctv); 357767c5eb5SMarcel Holtmann } else { 358767c5eb5SMarcel Holtmann data = &tv; 359767c5eb5SMarcel Holtmann len = sizeof(tv); 360767c5eb5SMarcel Holtmann } 361767c5eb5SMarcel Holtmann 362767c5eb5SMarcel Holtmann put_cmsg(msg, SOL_HCI, HCI_CMSG_TSTAMP, len, data); 363a61bbcf2SPatrick McHardy } 3641da177e4SLinus Torvalds } 3651da177e4SLinus Torvalds 3661da177e4SLinus Torvalds static int hci_sock_recvmsg(struct kiocb *iocb, struct socket *sock, 3671da177e4SLinus Torvalds struct msghdr *msg, size_t len, int flags) 3681da177e4SLinus Torvalds { 3691da177e4SLinus Torvalds int noblock = flags & MSG_DONTWAIT; 3701da177e4SLinus Torvalds struct sock *sk = sock->sk; 3711da177e4SLinus Torvalds struct sk_buff *skb; 3721da177e4SLinus Torvalds int copied, err; 3731da177e4SLinus Torvalds 3741da177e4SLinus Torvalds BT_DBG("sock %p, sk %p", sock, sk); 3751da177e4SLinus Torvalds 3761da177e4SLinus Torvalds if (flags & (MSG_OOB)) 3771da177e4SLinus Torvalds return -EOPNOTSUPP; 3781da177e4SLinus Torvalds 3791da177e4SLinus Torvalds if (sk->sk_state == BT_CLOSED) 3801da177e4SLinus Torvalds return 0; 3811da177e4SLinus Torvalds 3821da177e4SLinus Torvalds if (!(skb = skb_recv_datagram(sk, flags, noblock, &err))) 3831da177e4SLinus Torvalds return err; 3841da177e4SLinus Torvalds 3851da177e4SLinus Torvalds msg->msg_namelen = 0; 3861da177e4SLinus Torvalds 3871da177e4SLinus Torvalds copied = skb->len; 3881da177e4SLinus Torvalds if (len < copied) { 3891da177e4SLinus Torvalds msg->msg_flags |= MSG_TRUNC; 3901da177e4SLinus Torvalds copied = len; 3911da177e4SLinus Torvalds } 3921da177e4SLinus Torvalds 393badff6d0SArnaldo Carvalho de Melo skb_reset_transport_header(skb); 3941da177e4SLinus Torvalds err = skb_copy_datagram_iovec(skb, 0, msg->msg_iov, copied); 3951da177e4SLinus Torvalds 3961da177e4SLinus Torvalds hci_sock_cmsg(sk, msg, skb); 3971da177e4SLinus Torvalds 3981da177e4SLinus Torvalds skb_free_datagram(sk, skb); 3991da177e4SLinus Torvalds 4001da177e4SLinus Torvalds return err ? : copied; 4011da177e4SLinus Torvalds } 4021da177e4SLinus Torvalds 4031da177e4SLinus Torvalds static int hci_sock_sendmsg(struct kiocb *iocb, struct socket *sock, 4041da177e4SLinus Torvalds struct msghdr *msg, size_t len) 4051da177e4SLinus Torvalds { 4061da177e4SLinus Torvalds struct sock *sk = sock->sk; 4071da177e4SLinus Torvalds struct hci_dev *hdev; 4081da177e4SLinus Torvalds struct sk_buff *skb; 4091da177e4SLinus Torvalds int err; 4101da177e4SLinus Torvalds 4111da177e4SLinus Torvalds BT_DBG("sock %p sk %p", sock, sk); 4121da177e4SLinus Torvalds 4131da177e4SLinus Torvalds if (msg->msg_flags & MSG_OOB) 4141da177e4SLinus Torvalds return -EOPNOTSUPP; 4151da177e4SLinus Torvalds 4161da177e4SLinus Torvalds if (msg->msg_flags & ~(MSG_DONTWAIT|MSG_NOSIGNAL|MSG_ERRQUEUE)) 4171da177e4SLinus Torvalds return -EINVAL; 4181da177e4SLinus Torvalds 4191da177e4SLinus Torvalds if (len < 4 || len > HCI_MAX_FRAME_SIZE) 4201da177e4SLinus Torvalds return -EINVAL; 4211da177e4SLinus Torvalds 4221da177e4SLinus Torvalds lock_sock(sk); 4231da177e4SLinus Torvalds 4241da177e4SLinus Torvalds if (!(hdev = hci_pi(sk)->hdev)) { 4251da177e4SLinus Torvalds err = -EBADFD; 4261da177e4SLinus Torvalds goto done; 4271da177e4SLinus Torvalds } 4281da177e4SLinus Torvalds 4291da177e4SLinus Torvalds if (!(skb = bt_skb_send_alloc(sk, len, msg->msg_flags & MSG_DONTWAIT, &err))) 4301da177e4SLinus Torvalds goto done; 4311da177e4SLinus Torvalds 4321da177e4SLinus Torvalds if (memcpy_fromiovec(skb_put(skb, len), msg->msg_iov, len)) { 4331da177e4SLinus Torvalds err = -EFAULT; 4341da177e4SLinus Torvalds goto drop; 4351da177e4SLinus Torvalds } 4361da177e4SLinus Torvalds 4370d48d939SMarcel Holtmann bt_cb(skb)->pkt_type = *((unsigned char *) skb->data); 4381da177e4SLinus Torvalds skb_pull(skb, 1); 4391da177e4SLinus Torvalds skb->dev = (void *) hdev; 4401da177e4SLinus Torvalds 4410d48d939SMarcel Holtmann if (bt_cb(skb)->pkt_type == HCI_COMMAND_PKT) { 4421ebb9252SMarcel Holtmann u16 opcode = __le16_to_cpu(get_unaligned((__le16 *) skb->data)); 4431da177e4SLinus Torvalds u16 ogf = hci_opcode_ogf(opcode); 4441da177e4SLinus Torvalds u16 ocf = hci_opcode_ocf(opcode); 4451da177e4SLinus Torvalds 4461da177e4SLinus Torvalds if (((ogf > HCI_SFLT_MAX_OGF) || 4471da177e4SLinus Torvalds !hci_test_bit(ocf & HCI_FLT_OCF_BITS, &hci_sec_filter.ocf_mask[ogf])) && 4481da177e4SLinus Torvalds !capable(CAP_NET_RAW)) { 4491da177e4SLinus Torvalds err = -EPERM; 4501da177e4SLinus Torvalds goto drop; 4511da177e4SLinus Torvalds } 4521da177e4SLinus Torvalds 4531da177e4SLinus Torvalds if (test_bit(HCI_RAW, &hdev->flags) || (ogf == OGF_VENDOR_CMD)) { 4541da177e4SLinus Torvalds skb_queue_tail(&hdev->raw_q, skb); 4551da177e4SLinus Torvalds hci_sched_tx(hdev); 4561da177e4SLinus Torvalds } else { 4571da177e4SLinus Torvalds skb_queue_tail(&hdev->cmd_q, skb); 4581da177e4SLinus Torvalds hci_sched_cmd(hdev); 4591da177e4SLinus Torvalds } 4601da177e4SLinus Torvalds } else { 4611da177e4SLinus Torvalds if (!capable(CAP_NET_RAW)) { 4621da177e4SLinus Torvalds err = -EPERM; 4631da177e4SLinus Torvalds goto drop; 4641da177e4SLinus Torvalds } 4651da177e4SLinus Torvalds 4661da177e4SLinus Torvalds skb_queue_tail(&hdev->raw_q, skb); 4671da177e4SLinus Torvalds hci_sched_tx(hdev); 4681da177e4SLinus Torvalds } 4691da177e4SLinus Torvalds 4701da177e4SLinus Torvalds err = len; 4711da177e4SLinus Torvalds 4721da177e4SLinus Torvalds done: 4731da177e4SLinus Torvalds release_sock(sk); 4741da177e4SLinus Torvalds return err; 4751da177e4SLinus Torvalds 4761da177e4SLinus Torvalds drop: 4771da177e4SLinus Torvalds kfree_skb(skb); 4781da177e4SLinus Torvalds goto done; 4791da177e4SLinus Torvalds } 4801da177e4SLinus Torvalds 4811da177e4SLinus Torvalds static int hci_sock_setsockopt(struct socket *sock, int level, int optname, char __user *optval, int len) 4821da177e4SLinus Torvalds { 4831da177e4SLinus Torvalds struct hci_ufilter uf = { .opcode = 0 }; 4841da177e4SLinus Torvalds struct sock *sk = sock->sk; 4851da177e4SLinus Torvalds int err = 0, opt = 0; 4861da177e4SLinus Torvalds 4871da177e4SLinus Torvalds BT_DBG("sk %p, opt %d", sk, optname); 4881da177e4SLinus Torvalds 4891da177e4SLinus Torvalds lock_sock(sk); 4901da177e4SLinus Torvalds 4911da177e4SLinus Torvalds switch (optname) { 4921da177e4SLinus Torvalds case HCI_DATA_DIR: 4931da177e4SLinus Torvalds if (get_user(opt, (int __user *)optval)) { 4941da177e4SLinus Torvalds err = -EFAULT; 4951da177e4SLinus Torvalds break; 4961da177e4SLinus Torvalds } 4971da177e4SLinus Torvalds 4981da177e4SLinus Torvalds if (opt) 4991da177e4SLinus Torvalds hci_pi(sk)->cmsg_mask |= HCI_CMSG_DIR; 5001da177e4SLinus Torvalds else 5011da177e4SLinus Torvalds hci_pi(sk)->cmsg_mask &= ~HCI_CMSG_DIR; 5021da177e4SLinus Torvalds break; 5031da177e4SLinus Torvalds 5041da177e4SLinus Torvalds case HCI_TIME_STAMP: 5051da177e4SLinus Torvalds if (get_user(opt, (int __user *)optval)) { 5061da177e4SLinus Torvalds err = -EFAULT; 5071da177e4SLinus Torvalds break; 5081da177e4SLinus Torvalds } 5091da177e4SLinus Torvalds 5101da177e4SLinus Torvalds if (opt) 5111da177e4SLinus Torvalds hci_pi(sk)->cmsg_mask |= HCI_CMSG_TSTAMP; 5121da177e4SLinus Torvalds else 5131da177e4SLinus Torvalds hci_pi(sk)->cmsg_mask &= ~HCI_CMSG_TSTAMP; 5141da177e4SLinus Torvalds break; 5151da177e4SLinus Torvalds 5161da177e4SLinus Torvalds case HCI_FILTER: 5170878b666SMarcel Holtmann { 5180878b666SMarcel Holtmann struct hci_filter *f = &hci_pi(sk)->filter; 5190878b666SMarcel Holtmann 5200878b666SMarcel Holtmann uf.type_mask = f->type_mask; 5210878b666SMarcel Holtmann uf.opcode = f->opcode; 5220878b666SMarcel Holtmann uf.event_mask[0] = *((u32 *) f->event_mask + 0); 5230878b666SMarcel Holtmann uf.event_mask[1] = *((u32 *) f->event_mask + 1); 5240878b666SMarcel Holtmann } 5250878b666SMarcel Holtmann 5261da177e4SLinus Torvalds len = min_t(unsigned int, len, sizeof(uf)); 5271da177e4SLinus Torvalds if (copy_from_user(&uf, optval, len)) { 5281da177e4SLinus Torvalds err = -EFAULT; 5291da177e4SLinus Torvalds break; 5301da177e4SLinus Torvalds } 5311da177e4SLinus Torvalds 5321da177e4SLinus Torvalds if (!capable(CAP_NET_RAW)) { 5331da177e4SLinus Torvalds uf.type_mask &= hci_sec_filter.type_mask; 5341da177e4SLinus Torvalds uf.event_mask[0] &= *((u32 *) hci_sec_filter.event_mask + 0); 5351da177e4SLinus Torvalds uf.event_mask[1] &= *((u32 *) hci_sec_filter.event_mask + 1); 5361da177e4SLinus Torvalds } 5371da177e4SLinus Torvalds 5381da177e4SLinus Torvalds { 5391da177e4SLinus Torvalds struct hci_filter *f = &hci_pi(sk)->filter; 5401da177e4SLinus Torvalds 5411da177e4SLinus Torvalds f->type_mask = uf.type_mask; 5421da177e4SLinus Torvalds f->opcode = uf.opcode; 5431da177e4SLinus Torvalds *((u32 *) f->event_mask + 0) = uf.event_mask[0]; 5441da177e4SLinus Torvalds *((u32 *) f->event_mask + 1) = uf.event_mask[1]; 5451da177e4SLinus Torvalds } 5461da177e4SLinus Torvalds break; 5471da177e4SLinus Torvalds 5481da177e4SLinus Torvalds default: 5491da177e4SLinus Torvalds err = -ENOPROTOOPT; 5501da177e4SLinus Torvalds break; 5511da177e4SLinus Torvalds } 5521da177e4SLinus Torvalds 5531da177e4SLinus Torvalds release_sock(sk); 5541da177e4SLinus Torvalds return err; 5551da177e4SLinus Torvalds } 5561da177e4SLinus Torvalds 5571da177e4SLinus Torvalds static int hci_sock_getsockopt(struct socket *sock, int level, int optname, char __user *optval, int __user *optlen) 5581da177e4SLinus Torvalds { 5591da177e4SLinus Torvalds struct hci_ufilter uf; 5601da177e4SLinus Torvalds struct sock *sk = sock->sk; 5611da177e4SLinus Torvalds int len, opt; 5621da177e4SLinus Torvalds 5631da177e4SLinus Torvalds if (get_user(len, optlen)) 5641da177e4SLinus Torvalds return -EFAULT; 5651da177e4SLinus Torvalds 5661da177e4SLinus Torvalds switch (optname) { 5671da177e4SLinus Torvalds case HCI_DATA_DIR: 5681da177e4SLinus Torvalds if (hci_pi(sk)->cmsg_mask & HCI_CMSG_DIR) 5691da177e4SLinus Torvalds opt = 1; 5701da177e4SLinus Torvalds else 5711da177e4SLinus Torvalds opt = 0; 5721da177e4SLinus Torvalds 5731da177e4SLinus Torvalds if (put_user(opt, optval)) 5741da177e4SLinus Torvalds return -EFAULT; 5751da177e4SLinus Torvalds break; 5761da177e4SLinus Torvalds 5771da177e4SLinus Torvalds case HCI_TIME_STAMP: 5781da177e4SLinus Torvalds if (hci_pi(sk)->cmsg_mask & HCI_CMSG_TSTAMP) 5791da177e4SLinus Torvalds opt = 1; 5801da177e4SLinus Torvalds else 5811da177e4SLinus Torvalds opt = 0; 5821da177e4SLinus Torvalds 5831da177e4SLinus Torvalds if (put_user(opt, optval)) 5841da177e4SLinus Torvalds return -EFAULT; 5851da177e4SLinus Torvalds break; 5861da177e4SLinus Torvalds 5871da177e4SLinus Torvalds case HCI_FILTER: 5881da177e4SLinus Torvalds { 5891da177e4SLinus Torvalds struct hci_filter *f = &hci_pi(sk)->filter; 5901da177e4SLinus Torvalds 5911da177e4SLinus Torvalds uf.type_mask = f->type_mask; 5921da177e4SLinus Torvalds uf.opcode = f->opcode; 5931da177e4SLinus Torvalds uf.event_mask[0] = *((u32 *) f->event_mask + 0); 5941da177e4SLinus Torvalds uf.event_mask[1] = *((u32 *) f->event_mask + 1); 5951da177e4SLinus Torvalds } 5961da177e4SLinus Torvalds 5971da177e4SLinus Torvalds len = min_t(unsigned int, len, sizeof(uf)); 5981da177e4SLinus Torvalds if (copy_to_user(optval, &uf, len)) 5991da177e4SLinus Torvalds return -EFAULT; 6001da177e4SLinus Torvalds break; 6011da177e4SLinus Torvalds 6021da177e4SLinus Torvalds default: 6031da177e4SLinus Torvalds return -ENOPROTOOPT; 6041da177e4SLinus Torvalds break; 6051da177e4SLinus Torvalds } 6061da177e4SLinus Torvalds 6071da177e4SLinus Torvalds return 0; 6081da177e4SLinus Torvalds } 6091da177e4SLinus Torvalds 61090ddc4f0SEric Dumazet static const struct proto_ops hci_sock_ops = { 6111da177e4SLinus Torvalds .family = PF_BLUETOOTH, 6121da177e4SLinus Torvalds .owner = THIS_MODULE, 6131da177e4SLinus Torvalds .release = hci_sock_release, 6141da177e4SLinus Torvalds .bind = hci_sock_bind, 6151da177e4SLinus Torvalds .getname = hci_sock_getname, 6161da177e4SLinus Torvalds .sendmsg = hci_sock_sendmsg, 6171da177e4SLinus Torvalds .recvmsg = hci_sock_recvmsg, 6181da177e4SLinus Torvalds .ioctl = hci_sock_ioctl, 6191da177e4SLinus Torvalds .poll = datagram_poll, 6201da177e4SLinus Torvalds .listen = sock_no_listen, 6211da177e4SLinus Torvalds .shutdown = sock_no_shutdown, 6221da177e4SLinus Torvalds .setsockopt = hci_sock_setsockopt, 6231da177e4SLinus Torvalds .getsockopt = hci_sock_getsockopt, 6241da177e4SLinus Torvalds .connect = sock_no_connect, 6251da177e4SLinus Torvalds .socketpair = sock_no_socketpair, 6261da177e4SLinus Torvalds .accept = sock_no_accept, 6271da177e4SLinus Torvalds .mmap = sock_no_mmap 6281da177e4SLinus Torvalds }; 6291da177e4SLinus Torvalds 6301da177e4SLinus Torvalds static struct proto hci_sk_proto = { 6311da177e4SLinus Torvalds .name = "HCI", 6321da177e4SLinus Torvalds .owner = THIS_MODULE, 6331da177e4SLinus Torvalds .obj_size = sizeof(struct hci_pinfo) 6341da177e4SLinus Torvalds }; 6351da177e4SLinus Torvalds 6361da177e4SLinus Torvalds static int hci_sock_create(struct socket *sock, int protocol) 6371da177e4SLinus Torvalds { 6381da177e4SLinus Torvalds struct sock *sk; 6391da177e4SLinus Torvalds 6401da177e4SLinus Torvalds BT_DBG("sock %p", sock); 6411da177e4SLinus Torvalds 6421da177e4SLinus Torvalds if (sock->type != SOCK_RAW) 6431da177e4SLinus Torvalds return -ESOCKTNOSUPPORT; 6441da177e4SLinus Torvalds 6451da177e4SLinus Torvalds sock->ops = &hci_sock_ops; 6461da177e4SLinus Torvalds 64774da626aSMarcel Holtmann sk = sk_alloc(PF_BLUETOOTH, GFP_ATOMIC, &hci_sk_proto, 1); 6481da177e4SLinus Torvalds if (!sk) 6491da177e4SLinus Torvalds return -ENOMEM; 6501da177e4SLinus Torvalds 6511da177e4SLinus Torvalds sock_init_data(sock, sk); 6521da177e4SLinus Torvalds 6531da177e4SLinus Torvalds sock_reset_flag(sk, SOCK_ZAPPED); 6541da177e4SLinus Torvalds 6551da177e4SLinus Torvalds sk->sk_protocol = protocol; 6561da177e4SLinus Torvalds 6571da177e4SLinus Torvalds sock->state = SS_UNCONNECTED; 6581da177e4SLinus Torvalds sk->sk_state = BT_OPEN; 6591da177e4SLinus Torvalds 6601da177e4SLinus Torvalds bt_sock_link(&hci_sk_list, sk); 6611da177e4SLinus Torvalds return 0; 6621da177e4SLinus Torvalds } 6631da177e4SLinus Torvalds 6641da177e4SLinus Torvalds static int hci_sock_dev_event(struct notifier_block *this, unsigned long event, void *ptr) 6651da177e4SLinus Torvalds { 6661da177e4SLinus Torvalds struct hci_dev *hdev = (struct hci_dev *) ptr; 6671da177e4SLinus Torvalds struct hci_ev_si_device ev; 6681da177e4SLinus Torvalds 6691da177e4SLinus Torvalds BT_DBG("hdev %s event %ld", hdev->name, event); 6701da177e4SLinus Torvalds 6711da177e4SLinus Torvalds /* Send event to sockets */ 6721da177e4SLinus Torvalds ev.event = event; 6731da177e4SLinus Torvalds ev.dev_id = hdev->id; 6741da177e4SLinus Torvalds hci_si_event(NULL, HCI_EV_SI_DEVICE, sizeof(ev), &ev); 6751da177e4SLinus Torvalds 6761da177e4SLinus Torvalds if (event == HCI_DEV_UNREG) { 6771da177e4SLinus Torvalds struct sock *sk; 6781da177e4SLinus Torvalds struct hlist_node *node; 6791da177e4SLinus Torvalds 6801da177e4SLinus Torvalds /* Detach sockets from device */ 6811da177e4SLinus Torvalds read_lock(&hci_sk_list.lock); 6821da177e4SLinus Torvalds sk_for_each(sk, node, &hci_sk_list.head) { 6834ce61d1cSSatyam Sharma local_bh_disable(); 6844ce61d1cSSatyam Sharma bh_lock_sock_nested(sk); 6851da177e4SLinus Torvalds if (hci_pi(sk)->hdev == hdev) { 6861da177e4SLinus Torvalds hci_pi(sk)->hdev = NULL; 6871da177e4SLinus Torvalds sk->sk_err = EPIPE; 6881da177e4SLinus Torvalds sk->sk_state = BT_OPEN; 6891da177e4SLinus Torvalds sk->sk_state_change(sk); 6901da177e4SLinus Torvalds 6911da177e4SLinus Torvalds hci_dev_put(hdev); 6921da177e4SLinus Torvalds } 6934ce61d1cSSatyam Sharma bh_unlock_sock(sk); 6944ce61d1cSSatyam Sharma local_bh_enable(); 6951da177e4SLinus Torvalds } 6961da177e4SLinus Torvalds read_unlock(&hci_sk_list.lock); 6971da177e4SLinus Torvalds } 6981da177e4SLinus Torvalds 6991da177e4SLinus Torvalds return NOTIFY_DONE; 7001da177e4SLinus Torvalds } 7011da177e4SLinus Torvalds 7021da177e4SLinus Torvalds static struct net_proto_family hci_sock_family_ops = { 7031da177e4SLinus Torvalds .family = PF_BLUETOOTH, 7041da177e4SLinus Torvalds .owner = THIS_MODULE, 7051da177e4SLinus Torvalds .create = hci_sock_create, 7061da177e4SLinus Torvalds }; 7071da177e4SLinus Torvalds 7081da177e4SLinus Torvalds static struct notifier_block hci_sock_nblock = { 7091da177e4SLinus Torvalds .notifier_call = hci_sock_dev_event 7101da177e4SLinus Torvalds }; 7111da177e4SLinus Torvalds 7121da177e4SLinus Torvalds int __init hci_sock_init(void) 7131da177e4SLinus Torvalds { 7141da177e4SLinus Torvalds int err; 7151da177e4SLinus Torvalds 7161da177e4SLinus Torvalds err = proto_register(&hci_sk_proto, 0); 7171da177e4SLinus Torvalds if (err < 0) 7181da177e4SLinus Torvalds return err; 7191da177e4SLinus Torvalds 7201da177e4SLinus Torvalds err = bt_sock_register(BTPROTO_HCI, &hci_sock_family_ops); 7211da177e4SLinus Torvalds if (err < 0) 7221da177e4SLinus Torvalds goto error; 7231da177e4SLinus Torvalds 7241da177e4SLinus Torvalds hci_register_notifier(&hci_sock_nblock); 7251da177e4SLinus Torvalds 7261da177e4SLinus Torvalds BT_INFO("HCI socket layer initialized"); 7271da177e4SLinus Torvalds 7281da177e4SLinus Torvalds return 0; 7291da177e4SLinus Torvalds 7301da177e4SLinus Torvalds error: 7311da177e4SLinus Torvalds BT_ERR("HCI socket registration failed"); 7321da177e4SLinus Torvalds proto_unregister(&hci_sk_proto); 7331da177e4SLinus Torvalds return err; 7341da177e4SLinus Torvalds } 7351da177e4SLinus Torvalds 7361da177e4SLinus Torvalds int __exit hci_sock_cleanup(void) 7371da177e4SLinus Torvalds { 7381da177e4SLinus Torvalds if (bt_sock_unregister(BTPROTO_HCI) < 0) 7391da177e4SLinus Torvalds BT_ERR("HCI socket unregistration failed"); 7401da177e4SLinus Torvalds 7411da177e4SLinus Torvalds hci_unregister_notifier(&hci_sock_nblock); 7421da177e4SLinus Torvalds 7431da177e4SLinus Torvalds proto_unregister(&hci_sk_proto); 7441da177e4SLinus Torvalds 7451da177e4SLinus Torvalds return 0; 7461da177e4SLinus Torvalds } 747