xref: /openbmc/linux/net/bluetooth/hci_sock.c (revision 7cc2ade2cbc6f71090f0f8d0e11cb68886ddc65e)
11da177e4SLinus Torvalds /*
21da177e4SLinus Torvalds    BlueZ - Bluetooth protocol stack for Linux
31da177e4SLinus Torvalds    Copyright (C) 2000-2001 Qualcomm Incorporated
41da177e4SLinus Torvalds 
51da177e4SLinus Torvalds    Written 2000,2001 by Maxim Krasnyansky <maxk@qualcomm.com>
61da177e4SLinus Torvalds 
71da177e4SLinus Torvalds    This program is free software; you can redistribute it and/or modify
81da177e4SLinus Torvalds    it under the terms of the GNU General Public License version 2 as
91da177e4SLinus Torvalds    published by the Free Software Foundation;
101da177e4SLinus Torvalds 
111da177e4SLinus Torvalds    THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS
121da177e4SLinus Torvalds    OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
131da177e4SLinus Torvalds    FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT OF THIRD PARTY RIGHTS.
141da177e4SLinus Torvalds    IN NO EVENT SHALL THE COPYRIGHT HOLDER(S) AND AUTHOR(S) BE LIABLE FOR ANY
151da177e4SLinus Torvalds    CLAIM, OR ANY SPECIAL INDIRECT OR CONSEQUENTIAL DAMAGES, OR ANY DAMAGES
161da177e4SLinus Torvalds    WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
171da177e4SLinus Torvalds    ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
181da177e4SLinus Torvalds    OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
191da177e4SLinus Torvalds 
201da177e4SLinus Torvalds    ALL LIABILITY, INCLUDING LIABILITY FOR INFRINGEMENT OF ANY PATENTS,
211da177e4SLinus Torvalds    COPYRIGHTS, TRADEMARKS OR OTHER RIGHTS, RELATING TO USE OF THIS
221da177e4SLinus Torvalds    SOFTWARE IS DISCLAIMED.
231da177e4SLinus Torvalds */
241da177e4SLinus Torvalds 
251da177e4SLinus Torvalds /* Bluetooth HCI sockets. */
261da177e4SLinus Torvalds 
271da177e4SLinus Torvalds #include <linux/module.h>
281da177e4SLinus Torvalds 
291da177e4SLinus Torvalds #include <linux/types.h>
304fc268d2SRandy Dunlap #include <linux/capability.h>
311da177e4SLinus Torvalds #include <linux/errno.h>
321da177e4SLinus Torvalds #include <linux/kernel.h>
331da177e4SLinus Torvalds #include <linux/slab.h>
341da177e4SLinus Torvalds #include <linux/poll.h>
351da177e4SLinus Torvalds #include <linux/fcntl.h>
361da177e4SLinus Torvalds #include <linux/init.h>
371da177e4SLinus Torvalds #include <linux/skbuff.h>
381da177e4SLinus Torvalds #include <linux/workqueue.h>
391da177e4SLinus Torvalds #include <linux/interrupt.h>
40767c5eb5SMarcel Holtmann #include <linux/compat.h>
411da177e4SLinus Torvalds #include <linux/socket.h>
421da177e4SLinus Torvalds #include <linux/ioctl.h>
431da177e4SLinus Torvalds #include <net/sock.h>
441da177e4SLinus Torvalds 
451da177e4SLinus Torvalds #include <asm/system.h>
4670f23020SAndrei Emeltchenko #include <linux/uaccess.h>
471da177e4SLinus Torvalds #include <asm/unaligned.h>
481da177e4SLinus Torvalds 
491da177e4SLinus Torvalds #include <net/bluetooth/bluetooth.h>
501da177e4SLinus Torvalds #include <net/bluetooth/hci_core.h>
511da177e4SLinus Torvalds 
52eb939922SRusty Russell static bool enable_mgmt;
530381101fSJohan Hedberg 
541da177e4SLinus Torvalds /* ----- HCI socket interface ----- */
551da177e4SLinus Torvalds 
561da177e4SLinus Torvalds static inline int hci_test_bit(int nr, void *addr)
571da177e4SLinus Torvalds {
581da177e4SLinus Torvalds 	return *((__u32 *) addr + (nr >> 5)) & ((__u32) 1 << (nr & 31));
591da177e4SLinus Torvalds }
601da177e4SLinus Torvalds 
611da177e4SLinus Torvalds /* Security filter */
621da177e4SLinus Torvalds static struct hci_sec_filter hci_sec_filter = {
631da177e4SLinus Torvalds 	/* Packet types */
641da177e4SLinus Torvalds 	0x10,
651da177e4SLinus Torvalds 	/* Events */
66dd7f5527SMarcel Holtmann 	{ 0x1000d9fe, 0x0000b00c },
671da177e4SLinus Torvalds 	/* Commands */
681da177e4SLinus Torvalds 	{
691da177e4SLinus Torvalds 		{ 0x0 },
701da177e4SLinus Torvalds 		/* OGF_LINK_CTL */
717c631a67SMarcel Holtmann 		{ 0xbe000006, 0x00000001, 0x00000000, 0x00 },
721da177e4SLinus Torvalds 		/* OGF_LINK_POLICY */
737c631a67SMarcel Holtmann 		{ 0x00005200, 0x00000000, 0x00000000, 0x00 },
741da177e4SLinus Torvalds 		/* OGF_HOST_CTL */
757c631a67SMarcel Holtmann 		{ 0xaab00200, 0x2b402aaa, 0x05220154, 0x00 },
761da177e4SLinus Torvalds 		/* OGF_INFO_PARAM */
777c631a67SMarcel Holtmann 		{ 0x000002be, 0x00000000, 0x00000000, 0x00 },
781da177e4SLinus Torvalds 		/* OGF_STATUS_PARAM */
797c631a67SMarcel Holtmann 		{ 0x000000ea, 0x00000000, 0x00000000, 0x00 }
801da177e4SLinus Torvalds 	}
811da177e4SLinus Torvalds };
821da177e4SLinus Torvalds 
831da177e4SLinus Torvalds static struct bt_sock_list hci_sk_list = {
84d5fb2962SRobert P. J. Day 	.lock = __RW_LOCK_UNLOCKED(hci_sk_list.lock)
851da177e4SLinus Torvalds };
861da177e4SLinus Torvalds 
871da177e4SLinus Torvalds /* Send frame to RAW socket */
88470fe1b5SMarcel Holtmann void hci_send_to_sock(struct hci_dev *hdev, struct sk_buff *skb)
891da177e4SLinus Torvalds {
901da177e4SLinus Torvalds 	struct sock *sk;
911da177e4SLinus Torvalds 	struct hlist_node *node;
921da177e4SLinus Torvalds 
931da177e4SLinus Torvalds 	BT_DBG("hdev %p len %d", hdev, skb->len);
941da177e4SLinus Torvalds 
951da177e4SLinus Torvalds 	read_lock(&hci_sk_list.lock);
96470fe1b5SMarcel Holtmann 
971da177e4SLinus Torvalds 	sk_for_each(sk, node, &hci_sk_list.head) {
981da177e4SLinus Torvalds 		struct hci_filter *flt;
991da177e4SLinus Torvalds 		struct sk_buff *nskb;
1001da177e4SLinus Torvalds 
1011da177e4SLinus Torvalds 		if (sk->sk_state != BT_BOUND || hci_pi(sk)->hdev != hdev)
1021da177e4SLinus Torvalds 			continue;
1031da177e4SLinus Torvalds 
1041da177e4SLinus Torvalds 		/* Don't send frame to the socket it came from */
1051da177e4SLinus Torvalds 		if (skb->sk == sk)
1061da177e4SLinus Torvalds 			continue;
1071da177e4SLinus Torvalds 
108470fe1b5SMarcel Holtmann 		if (hci_pi(sk)->channel != HCI_CHANNEL_RAW)
109a40c406cSJohan Hedberg 			continue;
110a40c406cSJohan Hedberg 
1111da177e4SLinus Torvalds 		/* Apply filter */
1121da177e4SLinus Torvalds 		flt = &hci_pi(sk)->filter;
1131da177e4SLinus Torvalds 
1140d48d939SMarcel Holtmann 		if (!test_bit((bt_cb(skb)->pkt_type == HCI_VENDOR_PKT) ?
1150d48d939SMarcel Holtmann 				0 : (bt_cb(skb)->pkt_type & HCI_FLT_TYPE_BITS), &flt->type_mask))
1161da177e4SLinus Torvalds 			continue;
1171da177e4SLinus Torvalds 
1180d48d939SMarcel Holtmann 		if (bt_cb(skb)->pkt_type == HCI_EVENT_PKT) {
1191da177e4SLinus Torvalds 			register int evt = (*(__u8 *)skb->data & HCI_FLT_EVENT_BITS);
1201da177e4SLinus Torvalds 
1211da177e4SLinus Torvalds 			if (!hci_test_bit(evt, &flt->event_mask))
1221da177e4SLinus Torvalds 				continue;
1231da177e4SLinus Torvalds 
1244498c80dSDavid S. Miller 			if (flt->opcode &&
1254498c80dSDavid S. Miller 			    ((evt == HCI_EV_CMD_COMPLETE &&
1264498c80dSDavid S. Miller 			      flt->opcode !=
127905f3ed6SAl Viro 			      get_unaligned((__le16 *)(skb->data + 3))) ||
1281da177e4SLinus Torvalds 			     (evt == HCI_EV_CMD_STATUS &&
1294498c80dSDavid S. Miller 			      flt->opcode !=
130905f3ed6SAl Viro 			      get_unaligned((__le16 *)(skb->data + 4)))))
1311da177e4SLinus Torvalds 				continue;
1321da177e4SLinus Torvalds 		}
1331da177e4SLinus Torvalds 
13470f23020SAndrei Emeltchenko 		nskb = skb_clone(skb, GFP_ATOMIC);
13570f23020SAndrei Emeltchenko 		if (!nskb)
1361da177e4SLinus Torvalds 			continue;
1371da177e4SLinus Torvalds 
1381da177e4SLinus Torvalds 		/* Put type byte before the data */
1390d48d939SMarcel Holtmann 		memcpy(skb_push(nskb, 1), &bt_cb(nskb)->pkt_type, 1);
1401da177e4SLinus Torvalds 
1411da177e4SLinus Torvalds 		if (sock_queue_rcv_skb(sk, nskb))
1421da177e4SLinus Torvalds 			kfree_skb(nskb);
1431da177e4SLinus Torvalds 	}
144470fe1b5SMarcel Holtmann 
145470fe1b5SMarcel Holtmann 	read_unlock(&hci_sk_list.lock);
146470fe1b5SMarcel Holtmann }
147470fe1b5SMarcel Holtmann 
148470fe1b5SMarcel Holtmann /* Send frame to control socket */
149470fe1b5SMarcel Holtmann void hci_send_to_control(struct sk_buff *skb, struct sock *skip_sk)
150470fe1b5SMarcel Holtmann {
151470fe1b5SMarcel Holtmann 	struct sock *sk;
152470fe1b5SMarcel Holtmann 	struct hlist_node *node;
153470fe1b5SMarcel Holtmann 
154470fe1b5SMarcel Holtmann 	BT_DBG("len %d", skb->len);
155470fe1b5SMarcel Holtmann 
156470fe1b5SMarcel Holtmann 	read_lock(&hci_sk_list.lock);
157470fe1b5SMarcel Holtmann 
158470fe1b5SMarcel Holtmann 	sk_for_each(sk, node, &hci_sk_list.head) {
159470fe1b5SMarcel Holtmann 		struct sk_buff *nskb;
160470fe1b5SMarcel Holtmann 
161470fe1b5SMarcel Holtmann 		/* Skip the original socket */
162470fe1b5SMarcel Holtmann 		if (sk == skip_sk)
163470fe1b5SMarcel Holtmann 			continue;
164470fe1b5SMarcel Holtmann 
165470fe1b5SMarcel Holtmann 		if (sk->sk_state != BT_BOUND)
166470fe1b5SMarcel Holtmann 			continue;
167470fe1b5SMarcel Holtmann 
168470fe1b5SMarcel Holtmann 		if (hci_pi(sk)->channel != HCI_CHANNEL_CONTROL)
169470fe1b5SMarcel Holtmann 			continue;
170470fe1b5SMarcel Holtmann 
171470fe1b5SMarcel Holtmann 		nskb = skb_clone(skb, GFP_ATOMIC);
172470fe1b5SMarcel Holtmann 		if (!nskb)
173470fe1b5SMarcel Holtmann 			continue;
174470fe1b5SMarcel Holtmann 
175470fe1b5SMarcel Holtmann 		if (sock_queue_rcv_skb(sk, nskb))
176470fe1b5SMarcel Holtmann 			kfree_skb(nskb);
177470fe1b5SMarcel Holtmann 	}
178470fe1b5SMarcel Holtmann 
1791da177e4SLinus Torvalds 	read_unlock(&hci_sk_list.lock);
1801da177e4SLinus Torvalds }
1811da177e4SLinus Torvalds 
1821da177e4SLinus Torvalds static int hci_sock_release(struct socket *sock)
1831da177e4SLinus Torvalds {
1841da177e4SLinus Torvalds 	struct sock *sk = sock->sk;
1857b005bd3SMarcel Holtmann 	struct hci_dev *hdev;
1861da177e4SLinus Torvalds 
1871da177e4SLinus Torvalds 	BT_DBG("sock %p sk %p", sock, sk);
1881da177e4SLinus Torvalds 
1891da177e4SLinus Torvalds 	if (!sk)
1901da177e4SLinus Torvalds 		return 0;
1911da177e4SLinus Torvalds 
1927b005bd3SMarcel Holtmann 	hdev = hci_pi(sk)->hdev;
1937b005bd3SMarcel Holtmann 
1941da177e4SLinus Torvalds 	bt_sock_unlink(&hci_sk_list, sk);
1951da177e4SLinus Torvalds 
1961da177e4SLinus Torvalds 	if (hdev) {
1971da177e4SLinus Torvalds 		atomic_dec(&hdev->promisc);
1981da177e4SLinus Torvalds 		hci_dev_put(hdev);
1991da177e4SLinus Torvalds 	}
2001da177e4SLinus Torvalds 
2011da177e4SLinus Torvalds 	sock_orphan(sk);
2021da177e4SLinus Torvalds 
2031da177e4SLinus Torvalds 	skb_queue_purge(&sk->sk_receive_queue);
2041da177e4SLinus Torvalds 	skb_queue_purge(&sk->sk_write_queue);
2051da177e4SLinus Torvalds 
2061da177e4SLinus Torvalds 	sock_put(sk);
2071da177e4SLinus Torvalds 	return 0;
2081da177e4SLinus Torvalds }
2091da177e4SLinus Torvalds 
210b2a66aadSAntti Julku static int hci_sock_blacklist_add(struct hci_dev *hdev, void __user *arg)
211f0358568SJohan Hedberg {
212f0358568SJohan Hedberg 	bdaddr_t bdaddr;
2135e762444SAntti Julku 	int err;
214f0358568SJohan Hedberg 
215f0358568SJohan Hedberg 	if (copy_from_user(&bdaddr, arg, sizeof(bdaddr)))
216f0358568SJohan Hedberg 		return -EFAULT;
217f0358568SJohan Hedberg 
21809fd0de5SGustavo F. Padovan 	hci_dev_lock(hdev);
2195e762444SAntti Julku 
22088c1fe4bSJohan Hedberg 	err = hci_blacklist_add(hdev, &bdaddr, 0);
2215e762444SAntti Julku 
22209fd0de5SGustavo F. Padovan 	hci_dev_unlock(hdev);
2235e762444SAntti Julku 
2245e762444SAntti Julku 	return err;
225f0358568SJohan Hedberg }
226f0358568SJohan Hedberg 
227b2a66aadSAntti Julku static int hci_sock_blacklist_del(struct hci_dev *hdev, void __user *arg)
228f0358568SJohan Hedberg {
229f0358568SJohan Hedberg 	bdaddr_t bdaddr;
2305e762444SAntti Julku 	int err;
231f0358568SJohan Hedberg 
232f0358568SJohan Hedberg 	if (copy_from_user(&bdaddr, arg, sizeof(bdaddr)))
233f0358568SJohan Hedberg 		return -EFAULT;
234f0358568SJohan Hedberg 
23509fd0de5SGustavo F. Padovan 	hci_dev_lock(hdev);
2365e762444SAntti Julku 
23788c1fe4bSJohan Hedberg 	err = hci_blacklist_del(hdev, &bdaddr, 0);
2385e762444SAntti Julku 
23909fd0de5SGustavo F. Padovan 	hci_dev_unlock(hdev);
2405e762444SAntti Julku 
2415e762444SAntti Julku 	return err;
242f0358568SJohan Hedberg }
243f0358568SJohan Hedberg 
2441da177e4SLinus Torvalds /* Ioctls that require bound socket */
2451da177e4SLinus Torvalds static inline int hci_sock_bound_ioctl(struct sock *sk, unsigned int cmd, unsigned long arg)
2461da177e4SLinus Torvalds {
2471da177e4SLinus Torvalds 	struct hci_dev *hdev = hci_pi(sk)->hdev;
2481da177e4SLinus Torvalds 
2491da177e4SLinus Torvalds 	if (!hdev)
2501da177e4SLinus Torvalds 		return -EBADFD;
2511da177e4SLinus Torvalds 
2521da177e4SLinus Torvalds 	switch (cmd) {
2531da177e4SLinus Torvalds 	case HCISETRAW:
2541da177e4SLinus Torvalds 		if (!capable(CAP_NET_ADMIN))
2551da177e4SLinus Torvalds 			return -EACCES;
2561da177e4SLinus Torvalds 
2571da177e4SLinus Torvalds 		if (test_bit(HCI_QUIRK_RAW_DEVICE, &hdev->quirks))
2581da177e4SLinus Torvalds 			return -EPERM;
2591da177e4SLinus Torvalds 
2601da177e4SLinus Torvalds 		if (arg)
2611da177e4SLinus Torvalds 			set_bit(HCI_RAW, &hdev->flags);
2621da177e4SLinus Torvalds 		else
2631da177e4SLinus Torvalds 			clear_bit(HCI_RAW, &hdev->flags);
2641da177e4SLinus Torvalds 
2651da177e4SLinus Torvalds 		return 0;
2661da177e4SLinus Torvalds 
2671da177e4SLinus Torvalds 	case HCIGETCONNINFO:
2681da177e4SLinus Torvalds 		return hci_get_conn_info(hdev, (void __user *) arg);
2691da177e4SLinus Torvalds 
27040be492fSMarcel Holtmann 	case HCIGETAUTHINFO:
27140be492fSMarcel Holtmann 		return hci_get_auth_info(hdev, (void __user *) arg);
27240be492fSMarcel Holtmann 
273f0358568SJohan Hedberg 	case HCIBLOCKADDR:
274f0358568SJohan Hedberg 		if (!capable(CAP_NET_ADMIN))
275f0358568SJohan Hedberg 			return -EACCES;
276b2a66aadSAntti Julku 		return hci_sock_blacklist_add(hdev, (void __user *) arg);
277f0358568SJohan Hedberg 
278f0358568SJohan Hedberg 	case HCIUNBLOCKADDR:
279f0358568SJohan Hedberg 		if (!capable(CAP_NET_ADMIN))
280f0358568SJohan Hedberg 			return -EACCES;
281b2a66aadSAntti Julku 		return hci_sock_blacklist_del(hdev, (void __user *) arg);
282f0358568SJohan Hedberg 
2831da177e4SLinus Torvalds 	default:
2841da177e4SLinus Torvalds 		if (hdev->ioctl)
2851da177e4SLinus Torvalds 			return hdev->ioctl(hdev, cmd, arg);
2861da177e4SLinus Torvalds 		return -EINVAL;
2871da177e4SLinus Torvalds 	}
2881da177e4SLinus Torvalds }
2891da177e4SLinus Torvalds 
2901da177e4SLinus Torvalds static int hci_sock_ioctl(struct socket *sock, unsigned int cmd, unsigned long arg)
2911da177e4SLinus Torvalds {
2921da177e4SLinus Torvalds 	struct sock *sk = sock->sk;
2931da177e4SLinus Torvalds 	void __user *argp = (void __user *) arg;
2941da177e4SLinus Torvalds 	int err;
2951da177e4SLinus Torvalds 
2961da177e4SLinus Torvalds 	BT_DBG("cmd %x arg %lx", cmd, arg);
2971da177e4SLinus Torvalds 
2981da177e4SLinus Torvalds 	switch (cmd) {
2991da177e4SLinus Torvalds 	case HCIGETDEVLIST:
3001da177e4SLinus Torvalds 		return hci_get_dev_list(argp);
3011da177e4SLinus Torvalds 
3021da177e4SLinus Torvalds 	case HCIGETDEVINFO:
3031da177e4SLinus Torvalds 		return hci_get_dev_info(argp);
3041da177e4SLinus Torvalds 
3051da177e4SLinus Torvalds 	case HCIGETCONNLIST:
3061da177e4SLinus Torvalds 		return hci_get_conn_list(argp);
3071da177e4SLinus Torvalds 
3081da177e4SLinus Torvalds 	case HCIDEVUP:
3091da177e4SLinus Torvalds 		if (!capable(CAP_NET_ADMIN))
3101da177e4SLinus Torvalds 			return -EACCES;
3111da177e4SLinus Torvalds 		return hci_dev_open(arg);
3121da177e4SLinus Torvalds 
3131da177e4SLinus Torvalds 	case HCIDEVDOWN:
3141da177e4SLinus Torvalds 		if (!capable(CAP_NET_ADMIN))
3151da177e4SLinus Torvalds 			return -EACCES;
3161da177e4SLinus Torvalds 		return hci_dev_close(arg);
3171da177e4SLinus Torvalds 
3181da177e4SLinus Torvalds 	case HCIDEVRESET:
3191da177e4SLinus Torvalds 		if (!capable(CAP_NET_ADMIN))
3201da177e4SLinus Torvalds 			return -EACCES;
3211da177e4SLinus Torvalds 		return hci_dev_reset(arg);
3221da177e4SLinus Torvalds 
3231da177e4SLinus Torvalds 	case HCIDEVRESTAT:
3241da177e4SLinus Torvalds 		if (!capable(CAP_NET_ADMIN))
3251da177e4SLinus Torvalds 			return -EACCES;
3261da177e4SLinus Torvalds 		return hci_dev_reset_stat(arg);
3271da177e4SLinus Torvalds 
3281da177e4SLinus Torvalds 	case HCISETSCAN:
3291da177e4SLinus Torvalds 	case HCISETAUTH:
3301da177e4SLinus Torvalds 	case HCISETENCRYPT:
3311da177e4SLinus Torvalds 	case HCISETPTYPE:
3321da177e4SLinus Torvalds 	case HCISETLINKPOL:
3331da177e4SLinus Torvalds 	case HCISETLINKMODE:
3341da177e4SLinus Torvalds 	case HCISETACLMTU:
3351da177e4SLinus Torvalds 	case HCISETSCOMTU:
3361da177e4SLinus Torvalds 		if (!capable(CAP_NET_ADMIN))
3371da177e4SLinus Torvalds 			return -EACCES;
3381da177e4SLinus Torvalds 		return hci_dev_cmd(cmd, argp);
3391da177e4SLinus Torvalds 
3401da177e4SLinus Torvalds 	case HCIINQUIRY:
3411da177e4SLinus Torvalds 		return hci_inquiry(argp);
3421da177e4SLinus Torvalds 
3431da177e4SLinus Torvalds 	default:
3441da177e4SLinus Torvalds 		lock_sock(sk);
3451da177e4SLinus Torvalds 		err = hci_sock_bound_ioctl(sk, cmd, arg);
3461da177e4SLinus Torvalds 		release_sock(sk);
3471da177e4SLinus Torvalds 		return err;
3481da177e4SLinus Torvalds 	}
3491da177e4SLinus Torvalds }
3501da177e4SLinus Torvalds 
3511da177e4SLinus Torvalds static int hci_sock_bind(struct socket *sock, struct sockaddr *addr, int addr_len)
3521da177e4SLinus Torvalds {
3530381101fSJohan Hedberg 	struct sockaddr_hci haddr;
3541da177e4SLinus Torvalds 	struct sock *sk = sock->sk;
3551da177e4SLinus Torvalds 	struct hci_dev *hdev = NULL;
3560381101fSJohan Hedberg 	int len, err = 0;
3571da177e4SLinus Torvalds 
3581da177e4SLinus Torvalds 	BT_DBG("sock %p sk %p", sock, sk);
3591da177e4SLinus Torvalds 
3600381101fSJohan Hedberg 	if (!addr)
3610381101fSJohan Hedberg 		return -EINVAL;
3620381101fSJohan Hedberg 
3630381101fSJohan Hedberg 	memset(&haddr, 0, sizeof(haddr));
3640381101fSJohan Hedberg 	len = min_t(unsigned int, sizeof(haddr), addr_len);
3650381101fSJohan Hedberg 	memcpy(&haddr, addr, len);
3660381101fSJohan Hedberg 
3670381101fSJohan Hedberg 	if (haddr.hci_family != AF_BLUETOOTH)
3680381101fSJohan Hedberg 		return -EINVAL;
3690381101fSJohan Hedberg 
3701da177e4SLinus Torvalds 	lock_sock(sk);
3711da177e4SLinus Torvalds 
372*7cc2ade2SMarcel Holtmann 	if (sk->sk_state == BT_BOUND) {
373*7cc2ade2SMarcel Holtmann 		err = -EALREADY;
374*7cc2ade2SMarcel Holtmann 		goto done;
375*7cc2ade2SMarcel Holtmann 	}
376*7cc2ade2SMarcel Holtmann 
377*7cc2ade2SMarcel Holtmann 	switch (haddr.hci_channel) {
378*7cc2ade2SMarcel Holtmann 	case HCI_CHANNEL_RAW:
379*7cc2ade2SMarcel Holtmann 		if (hci_pi(sk)->hdev) {
3801da177e4SLinus Torvalds 			err = -EALREADY;
3811da177e4SLinus Torvalds 			goto done;
3821da177e4SLinus Torvalds 		}
3831da177e4SLinus Torvalds 
3840381101fSJohan Hedberg 		if (haddr.hci_dev != HCI_DEV_NONE) {
3850381101fSJohan Hedberg 			hdev = hci_dev_get(haddr.hci_dev);
38670f23020SAndrei Emeltchenko 			if (!hdev) {
3871da177e4SLinus Torvalds 				err = -ENODEV;
3881da177e4SLinus Torvalds 				goto done;
3891da177e4SLinus Torvalds 			}
3901da177e4SLinus Torvalds 
3911da177e4SLinus Torvalds 			atomic_inc(&hdev->promisc);
3921da177e4SLinus Torvalds 		}
3931da177e4SLinus Torvalds 
3941da177e4SLinus Torvalds 		hci_pi(sk)->hdev = hdev;
395*7cc2ade2SMarcel Holtmann 		break;
396*7cc2ade2SMarcel Holtmann 
397*7cc2ade2SMarcel Holtmann 	case HCI_CHANNEL_CONTROL:
398*7cc2ade2SMarcel Holtmann 		if (haddr.hci_dev != HCI_DEV_NONE || !enable_mgmt) {
399*7cc2ade2SMarcel Holtmann 			err = -EINVAL;
400*7cc2ade2SMarcel Holtmann 			goto done;
401*7cc2ade2SMarcel Holtmann 		}
402*7cc2ade2SMarcel Holtmann 
403*7cc2ade2SMarcel Holtmann 		set_bit(HCI_PI_MGMT_INIT, &hci_pi(sk)->flags);
404*7cc2ade2SMarcel Holtmann 		break;
405*7cc2ade2SMarcel Holtmann 
406*7cc2ade2SMarcel Holtmann 	default:
407*7cc2ade2SMarcel Holtmann 		err = -EINVAL;
408*7cc2ade2SMarcel Holtmann 		goto done;
409*7cc2ade2SMarcel Holtmann 	}
410*7cc2ade2SMarcel Holtmann 
411*7cc2ade2SMarcel Holtmann 
412*7cc2ade2SMarcel Holtmann 	hci_pi(sk)->channel = haddr.hci_channel;
4131da177e4SLinus Torvalds 	sk->sk_state = BT_BOUND;
4141da177e4SLinus Torvalds 
4151da177e4SLinus Torvalds done:
4161da177e4SLinus Torvalds 	release_sock(sk);
4171da177e4SLinus Torvalds 	return err;
4181da177e4SLinus Torvalds }
4191da177e4SLinus Torvalds 
4201da177e4SLinus Torvalds static int hci_sock_getname(struct socket *sock, struct sockaddr *addr, int *addr_len, int peer)
4211da177e4SLinus Torvalds {
4221da177e4SLinus Torvalds 	struct sockaddr_hci *haddr = (struct sockaddr_hci *) addr;
4231da177e4SLinus Torvalds 	struct sock *sk = sock->sk;
4247b005bd3SMarcel Holtmann 	struct hci_dev *hdev = hci_pi(sk)->hdev;
4251da177e4SLinus Torvalds 
4261da177e4SLinus Torvalds 	BT_DBG("sock %p sk %p", sock, sk);
4271da177e4SLinus Torvalds 
4287b005bd3SMarcel Holtmann 	if (!hdev)
4297b005bd3SMarcel Holtmann 		return -EBADFD;
4307b005bd3SMarcel Holtmann 
4311da177e4SLinus Torvalds 	lock_sock(sk);
4321da177e4SLinus Torvalds 
4331da177e4SLinus Torvalds 	*addr_len = sizeof(*haddr);
4341da177e4SLinus Torvalds 	haddr->hci_family = AF_BLUETOOTH;
4357b005bd3SMarcel Holtmann 	haddr->hci_dev    = hdev->id;
4361da177e4SLinus Torvalds 
4371da177e4SLinus Torvalds 	release_sock(sk);
4381da177e4SLinus Torvalds 	return 0;
4391da177e4SLinus Torvalds }
4401da177e4SLinus Torvalds 
4411da177e4SLinus Torvalds static inline void hci_sock_cmsg(struct sock *sk, struct msghdr *msg, struct sk_buff *skb)
4421da177e4SLinus Torvalds {
4431da177e4SLinus Torvalds 	__u32 mask = hci_pi(sk)->cmsg_mask;
4441da177e4SLinus Torvalds 
4450d48d939SMarcel Holtmann 	if (mask & HCI_CMSG_DIR) {
4460d48d939SMarcel Holtmann 		int incoming = bt_cb(skb)->incoming;
4470d48d939SMarcel Holtmann 		put_cmsg(msg, SOL_HCI, HCI_CMSG_DIR, sizeof(incoming), &incoming);
4480d48d939SMarcel Holtmann 	}
4491da177e4SLinus Torvalds 
450a61bbcf2SPatrick McHardy 	if (mask & HCI_CMSG_TSTAMP) {
451f6e623a6SJohann Felix Soden #ifdef CONFIG_COMPAT
452f6e623a6SJohann Felix Soden 		struct compat_timeval ctv;
453f6e623a6SJohann Felix Soden #endif
454a61bbcf2SPatrick McHardy 		struct timeval tv;
455767c5eb5SMarcel Holtmann 		void *data;
456767c5eb5SMarcel Holtmann 		int len;
457a61bbcf2SPatrick McHardy 
458a61bbcf2SPatrick McHardy 		skb_get_timestamp(skb, &tv);
459767c5eb5SMarcel Holtmann 
4601da97f83SDavid S. Miller 		data = &tv;
4611da97f83SDavid S. Miller 		len = sizeof(tv);
4621da97f83SDavid S. Miller #ifdef CONFIG_COMPAT
463767c5eb5SMarcel Holtmann 		if (msg->msg_flags & MSG_CMSG_COMPAT) {
464767c5eb5SMarcel Holtmann 			ctv.tv_sec = tv.tv_sec;
465767c5eb5SMarcel Holtmann 			ctv.tv_usec = tv.tv_usec;
466767c5eb5SMarcel Holtmann 			data = &ctv;
467767c5eb5SMarcel Holtmann 			len = sizeof(ctv);
468767c5eb5SMarcel Holtmann 		}
4691da97f83SDavid S. Miller #endif
470767c5eb5SMarcel Holtmann 
471767c5eb5SMarcel Holtmann 		put_cmsg(msg, SOL_HCI, HCI_CMSG_TSTAMP, len, data);
472a61bbcf2SPatrick McHardy 	}
4731da177e4SLinus Torvalds }
4741da177e4SLinus Torvalds 
4751da177e4SLinus Torvalds static int hci_sock_recvmsg(struct kiocb *iocb, struct socket *sock,
4761da177e4SLinus Torvalds 				struct msghdr *msg, size_t len, int flags)
4771da177e4SLinus Torvalds {
4781da177e4SLinus Torvalds 	int noblock = flags & MSG_DONTWAIT;
4791da177e4SLinus Torvalds 	struct sock *sk = sock->sk;
4801da177e4SLinus Torvalds 	struct sk_buff *skb;
4811da177e4SLinus Torvalds 	int copied, err;
4821da177e4SLinus Torvalds 
4831da177e4SLinus Torvalds 	BT_DBG("sock %p, sk %p", sock, sk);
4841da177e4SLinus Torvalds 
4851da177e4SLinus Torvalds 	if (flags & (MSG_OOB))
4861da177e4SLinus Torvalds 		return -EOPNOTSUPP;
4871da177e4SLinus Torvalds 
4881da177e4SLinus Torvalds 	if (sk->sk_state == BT_CLOSED)
4891da177e4SLinus Torvalds 		return 0;
4901da177e4SLinus Torvalds 
49170f23020SAndrei Emeltchenko 	skb = skb_recv_datagram(sk, flags, noblock, &err);
49270f23020SAndrei Emeltchenko 	if (!skb)
4931da177e4SLinus Torvalds 		return err;
4941da177e4SLinus Torvalds 
4951da177e4SLinus Torvalds 	msg->msg_namelen = 0;
4961da177e4SLinus Torvalds 
4971da177e4SLinus Torvalds 	copied = skb->len;
4981da177e4SLinus Torvalds 	if (len < copied) {
4991da177e4SLinus Torvalds 		msg->msg_flags |= MSG_TRUNC;
5001da177e4SLinus Torvalds 		copied = len;
5011da177e4SLinus Torvalds 	}
5021da177e4SLinus Torvalds 
503badff6d0SArnaldo Carvalho de Melo 	skb_reset_transport_header(skb);
5041da177e4SLinus Torvalds 	err = skb_copy_datagram_iovec(skb, 0, msg->msg_iov, copied);
5051da177e4SLinus Torvalds 
5063a208627SMarcel Holtmann 	switch (hci_pi(sk)->channel) {
5073a208627SMarcel Holtmann 	case HCI_CHANNEL_RAW:
5081da177e4SLinus Torvalds 		hci_sock_cmsg(sk, msg, skb);
5093a208627SMarcel Holtmann 		break;
5103a208627SMarcel Holtmann 	}
5111da177e4SLinus Torvalds 
5121da177e4SLinus Torvalds 	skb_free_datagram(sk, skb);
5131da177e4SLinus Torvalds 
5141da177e4SLinus Torvalds 	return err ? : copied;
5151da177e4SLinus Torvalds }
5161da177e4SLinus Torvalds 
5171da177e4SLinus Torvalds static int hci_sock_sendmsg(struct kiocb *iocb, struct socket *sock,
5181da177e4SLinus Torvalds 			    struct msghdr *msg, size_t len)
5191da177e4SLinus Torvalds {
5201da177e4SLinus Torvalds 	struct sock *sk = sock->sk;
5211da177e4SLinus Torvalds 	struct hci_dev *hdev;
5221da177e4SLinus Torvalds 	struct sk_buff *skb;
5231da177e4SLinus Torvalds 	int err;
5241da177e4SLinus Torvalds 
5251da177e4SLinus Torvalds 	BT_DBG("sock %p sk %p", sock, sk);
5261da177e4SLinus Torvalds 
5271da177e4SLinus Torvalds 	if (msg->msg_flags & MSG_OOB)
5281da177e4SLinus Torvalds 		return -EOPNOTSUPP;
5291da177e4SLinus Torvalds 
5301da177e4SLinus Torvalds 	if (msg->msg_flags & ~(MSG_DONTWAIT|MSG_NOSIGNAL|MSG_ERRQUEUE))
5311da177e4SLinus Torvalds 		return -EINVAL;
5321da177e4SLinus Torvalds 
5331da177e4SLinus Torvalds 	if (len < 4 || len > HCI_MAX_FRAME_SIZE)
5341da177e4SLinus Torvalds 		return -EINVAL;
5351da177e4SLinus Torvalds 
5361da177e4SLinus Torvalds 	lock_sock(sk);
5371da177e4SLinus Torvalds 
5380381101fSJohan Hedberg 	switch (hci_pi(sk)->channel) {
5390381101fSJohan Hedberg 	case HCI_CHANNEL_RAW:
5400381101fSJohan Hedberg 		break;
5410381101fSJohan Hedberg 	case HCI_CHANNEL_CONTROL:
5420381101fSJohan Hedberg 		err = mgmt_control(sk, msg, len);
5430381101fSJohan Hedberg 		goto done;
5440381101fSJohan Hedberg 	default:
5450381101fSJohan Hedberg 		err = -EINVAL;
5460381101fSJohan Hedberg 		goto done;
5470381101fSJohan Hedberg 	}
5480381101fSJohan Hedberg 
54970f23020SAndrei Emeltchenko 	hdev = hci_pi(sk)->hdev;
55070f23020SAndrei Emeltchenko 	if (!hdev) {
5511da177e4SLinus Torvalds 		err = -EBADFD;
5521da177e4SLinus Torvalds 		goto done;
5531da177e4SLinus Torvalds 	}
5541da177e4SLinus Torvalds 
5557e21addcSMarcel Holtmann 	if (!test_bit(HCI_UP, &hdev->flags)) {
5567e21addcSMarcel Holtmann 		err = -ENETDOWN;
5577e21addcSMarcel Holtmann 		goto done;
5587e21addcSMarcel Holtmann 	}
5597e21addcSMarcel Holtmann 
56070f23020SAndrei Emeltchenko 	skb = bt_skb_send_alloc(sk, len, msg->msg_flags & MSG_DONTWAIT, &err);
56170f23020SAndrei Emeltchenko 	if (!skb)
5621da177e4SLinus Torvalds 		goto done;
5631da177e4SLinus Torvalds 
5641da177e4SLinus Torvalds 	if (memcpy_fromiovec(skb_put(skb, len), msg->msg_iov, len)) {
5651da177e4SLinus Torvalds 		err = -EFAULT;
5661da177e4SLinus Torvalds 		goto drop;
5671da177e4SLinus Torvalds 	}
5681da177e4SLinus Torvalds 
5690d48d939SMarcel Holtmann 	bt_cb(skb)->pkt_type = *((unsigned char *) skb->data);
5701da177e4SLinus Torvalds 	skb_pull(skb, 1);
5711da177e4SLinus Torvalds 	skb->dev = (void *) hdev;
5721da177e4SLinus Torvalds 
5730d48d939SMarcel Holtmann 	if (bt_cb(skb)->pkt_type == HCI_COMMAND_PKT) {
57483985319SHarvey Harrison 		u16 opcode = get_unaligned_le16(skb->data);
5751da177e4SLinus Torvalds 		u16 ogf = hci_opcode_ogf(opcode);
5761da177e4SLinus Torvalds 		u16 ocf = hci_opcode_ocf(opcode);
5771da177e4SLinus Torvalds 
5781da177e4SLinus Torvalds 		if (((ogf > HCI_SFLT_MAX_OGF) ||
5791da177e4SLinus Torvalds 				!hci_test_bit(ocf & HCI_FLT_OCF_BITS, &hci_sec_filter.ocf_mask[ogf])) &&
5801da177e4SLinus Torvalds 					!capable(CAP_NET_RAW)) {
5811da177e4SLinus Torvalds 			err = -EPERM;
5821da177e4SLinus Torvalds 			goto drop;
5831da177e4SLinus Torvalds 		}
5841da177e4SLinus Torvalds 
585a9de9248SMarcel Holtmann 		if (test_bit(HCI_RAW, &hdev->flags) || (ogf == 0x3f)) {
5861da177e4SLinus Torvalds 			skb_queue_tail(&hdev->raw_q, skb);
5873eff45eaSGustavo F. Padovan 			queue_work(hdev->workqueue, &hdev->tx_work);
5881da177e4SLinus Torvalds 		} else {
5891da177e4SLinus Torvalds 			skb_queue_tail(&hdev->cmd_q, skb);
590c347b765SGustavo F. Padovan 			queue_work(hdev->workqueue, &hdev->cmd_work);
5911da177e4SLinus Torvalds 		}
5921da177e4SLinus Torvalds 	} else {
5931da177e4SLinus Torvalds 		if (!capable(CAP_NET_RAW)) {
5941da177e4SLinus Torvalds 			err = -EPERM;
5951da177e4SLinus Torvalds 			goto drop;
5961da177e4SLinus Torvalds 		}
5971da177e4SLinus Torvalds 
5981da177e4SLinus Torvalds 		skb_queue_tail(&hdev->raw_q, skb);
5993eff45eaSGustavo F. Padovan 		queue_work(hdev->workqueue, &hdev->tx_work);
6001da177e4SLinus Torvalds 	}
6011da177e4SLinus Torvalds 
6021da177e4SLinus Torvalds 	err = len;
6031da177e4SLinus Torvalds 
6041da177e4SLinus Torvalds done:
6051da177e4SLinus Torvalds 	release_sock(sk);
6061da177e4SLinus Torvalds 	return err;
6071da177e4SLinus Torvalds 
6081da177e4SLinus Torvalds drop:
6091da177e4SLinus Torvalds 	kfree_skb(skb);
6101da177e4SLinus Torvalds 	goto done;
6111da177e4SLinus Torvalds }
6121da177e4SLinus Torvalds 
613b7058842SDavid S. Miller static int hci_sock_setsockopt(struct socket *sock, int level, int optname, char __user *optval, unsigned int len)
6141da177e4SLinus Torvalds {
6151da177e4SLinus Torvalds 	struct hci_ufilter uf = { .opcode = 0 };
6161da177e4SLinus Torvalds 	struct sock *sk = sock->sk;
6171da177e4SLinus Torvalds 	int err = 0, opt = 0;
6181da177e4SLinus Torvalds 
6191da177e4SLinus Torvalds 	BT_DBG("sk %p, opt %d", sk, optname);
6201da177e4SLinus Torvalds 
6211da177e4SLinus Torvalds 	lock_sock(sk);
6221da177e4SLinus Torvalds 
6232f39cdb7SMarcel Holtmann 	if (hci_pi(sk)->channel != HCI_CHANNEL_RAW) {
6242f39cdb7SMarcel Holtmann 		err = -EINVAL;
6252f39cdb7SMarcel Holtmann 		goto done;
6262f39cdb7SMarcel Holtmann 	}
6272f39cdb7SMarcel Holtmann 
6281da177e4SLinus Torvalds 	switch (optname) {
6291da177e4SLinus Torvalds 	case HCI_DATA_DIR:
6301da177e4SLinus Torvalds 		if (get_user(opt, (int __user *)optval)) {
6311da177e4SLinus Torvalds 			err = -EFAULT;
6321da177e4SLinus Torvalds 			break;
6331da177e4SLinus Torvalds 		}
6341da177e4SLinus Torvalds 
6351da177e4SLinus Torvalds 		if (opt)
6361da177e4SLinus Torvalds 			hci_pi(sk)->cmsg_mask |= HCI_CMSG_DIR;
6371da177e4SLinus Torvalds 		else
6381da177e4SLinus Torvalds 			hci_pi(sk)->cmsg_mask &= ~HCI_CMSG_DIR;
6391da177e4SLinus Torvalds 		break;
6401da177e4SLinus Torvalds 
6411da177e4SLinus Torvalds 	case HCI_TIME_STAMP:
6421da177e4SLinus Torvalds 		if (get_user(opt, (int __user *)optval)) {
6431da177e4SLinus Torvalds 			err = -EFAULT;
6441da177e4SLinus Torvalds 			break;
6451da177e4SLinus Torvalds 		}
6461da177e4SLinus Torvalds 
6471da177e4SLinus Torvalds 		if (opt)
6481da177e4SLinus Torvalds 			hci_pi(sk)->cmsg_mask |= HCI_CMSG_TSTAMP;
6491da177e4SLinus Torvalds 		else
6501da177e4SLinus Torvalds 			hci_pi(sk)->cmsg_mask &= ~HCI_CMSG_TSTAMP;
6511da177e4SLinus Torvalds 		break;
6521da177e4SLinus Torvalds 
6531da177e4SLinus Torvalds 	case HCI_FILTER:
6540878b666SMarcel Holtmann 		{
6550878b666SMarcel Holtmann 			struct hci_filter *f = &hci_pi(sk)->filter;
6560878b666SMarcel Holtmann 
6570878b666SMarcel Holtmann 			uf.type_mask = f->type_mask;
6580878b666SMarcel Holtmann 			uf.opcode    = f->opcode;
6590878b666SMarcel Holtmann 			uf.event_mask[0] = *((u32 *) f->event_mask + 0);
6600878b666SMarcel Holtmann 			uf.event_mask[1] = *((u32 *) f->event_mask + 1);
6610878b666SMarcel Holtmann 		}
6620878b666SMarcel Holtmann 
6631da177e4SLinus Torvalds 		len = min_t(unsigned int, len, sizeof(uf));
6641da177e4SLinus Torvalds 		if (copy_from_user(&uf, optval, len)) {
6651da177e4SLinus Torvalds 			err = -EFAULT;
6661da177e4SLinus Torvalds 			break;
6671da177e4SLinus Torvalds 		}
6681da177e4SLinus Torvalds 
6691da177e4SLinus Torvalds 		if (!capable(CAP_NET_RAW)) {
6701da177e4SLinus Torvalds 			uf.type_mask &= hci_sec_filter.type_mask;
6711da177e4SLinus Torvalds 			uf.event_mask[0] &= *((u32 *) hci_sec_filter.event_mask + 0);
6721da177e4SLinus Torvalds 			uf.event_mask[1] &= *((u32 *) hci_sec_filter.event_mask + 1);
6731da177e4SLinus Torvalds 		}
6741da177e4SLinus Torvalds 
6751da177e4SLinus Torvalds 		{
6761da177e4SLinus Torvalds 			struct hci_filter *f = &hci_pi(sk)->filter;
6771da177e4SLinus Torvalds 
6781da177e4SLinus Torvalds 			f->type_mask = uf.type_mask;
6791da177e4SLinus Torvalds 			f->opcode    = uf.opcode;
6801da177e4SLinus Torvalds 			*((u32 *) f->event_mask + 0) = uf.event_mask[0];
6811da177e4SLinus Torvalds 			*((u32 *) f->event_mask + 1) = uf.event_mask[1];
6821da177e4SLinus Torvalds 		}
6831da177e4SLinus Torvalds 		break;
6841da177e4SLinus Torvalds 
6851da177e4SLinus Torvalds 	default:
6861da177e4SLinus Torvalds 		err = -ENOPROTOOPT;
6871da177e4SLinus Torvalds 		break;
6881da177e4SLinus Torvalds 	}
6891da177e4SLinus Torvalds 
6902f39cdb7SMarcel Holtmann done:
6911da177e4SLinus Torvalds 	release_sock(sk);
6921da177e4SLinus Torvalds 	return err;
6931da177e4SLinus Torvalds }
6941da177e4SLinus Torvalds 
6951da177e4SLinus Torvalds static int hci_sock_getsockopt(struct socket *sock, int level, int optname, char __user *optval, int __user *optlen)
6961da177e4SLinus Torvalds {
6971da177e4SLinus Torvalds 	struct hci_ufilter uf;
6981da177e4SLinus Torvalds 	struct sock *sk = sock->sk;
699cedc5469SMarcel Holtmann 	int len, opt, err = 0;
700cedc5469SMarcel Holtmann 
701cedc5469SMarcel Holtmann 	BT_DBG("sk %p, opt %d", sk, optname);
7021da177e4SLinus Torvalds 
7031da177e4SLinus Torvalds 	if (get_user(len, optlen))
7041da177e4SLinus Torvalds 		return -EFAULT;
7051da177e4SLinus Torvalds 
706cedc5469SMarcel Holtmann 	lock_sock(sk);
707cedc5469SMarcel Holtmann 
708cedc5469SMarcel Holtmann 	if (hci_pi(sk)->channel != HCI_CHANNEL_RAW) {
709cedc5469SMarcel Holtmann 		err = -EINVAL;
710cedc5469SMarcel Holtmann 		goto done;
711cedc5469SMarcel Holtmann 	}
712cedc5469SMarcel Holtmann 
7131da177e4SLinus Torvalds 	switch (optname) {
7141da177e4SLinus Torvalds 	case HCI_DATA_DIR:
7151da177e4SLinus Torvalds 		if (hci_pi(sk)->cmsg_mask & HCI_CMSG_DIR)
7161da177e4SLinus Torvalds 			opt = 1;
7171da177e4SLinus Torvalds 		else
7181da177e4SLinus Torvalds 			opt = 0;
7191da177e4SLinus Torvalds 
7201da177e4SLinus Torvalds 		if (put_user(opt, optval))
721cedc5469SMarcel Holtmann 			err = -EFAULT;
7221da177e4SLinus Torvalds 		break;
7231da177e4SLinus Torvalds 
7241da177e4SLinus Torvalds 	case HCI_TIME_STAMP:
7251da177e4SLinus Torvalds 		if (hci_pi(sk)->cmsg_mask & HCI_CMSG_TSTAMP)
7261da177e4SLinus Torvalds 			opt = 1;
7271da177e4SLinus Torvalds 		else
7281da177e4SLinus Torvalds 			opt = 0;
7291da177e4SLinus Torvalds 
7301da177e4SLinus Torvalds 		if (put_user(opt, optval))
731cedc5469SMarcel Holtmann 			err = -EFAULT;
7321da177e4SLinus Torvalds 		break;
7331da177e4SLinus Torvalds 
7341da177e4SLinus Torvalds 	case HCI_FILTER:
7351da177e4SLinus Torvalds 		{
7361da177e4SLinus Torvalds 			struct hci_filter *f = &hci_pi(sk)->filter;
7371da177e4SLinus Torvalds 
7381da177e4SLinus Torvalds 			uf.type_mask = f->type_mask;
7391da177e4SLinus Torvalds 			uf.opcode    = f->opcode;
7401da177e4SLinus Torvalds 			uf.event_mask[0] = *((u32 *) f->event_mask + 0);
7411da177e4SLinus Torvalds 			uf.event_mask[1] = *((u32 *) f->event_mask + 1);
7421da177e4SLinus Torvalds 		}
7431da177e4SLinus Torvalds 
7441da177e4SLinus Torvalds 		len = min_t(unsigned int, len, sizeof(uf));
7451da177e4SLinus Torvalds 		if (copy_to_user(optval, &uf, len))
746cedc5469SMarcel Holtmann 			err = -EFAULT;
7471da177e4SLinus Torvalds 		break;
7481da177e4SLinus Torvalds 
7491da177e4SLinus Torvalds 	default:
750cedc5469SMarcel Holtmann 		err = -ENOPROTOOPT;
7511da177e4SLinus Torvalds 		break;
7521da177e4SLinus Torvalds 	}
7531da177e4SLinus Torvalds 
754cedc5469SMarcel Holtmann done:
755cedc5469SMarcel Holtmann 	release_sock(sk);
756cedc5469SMarcel Holtmann 	return err;
7571da177e4SLinus Torvalds }
7581da177e4SLinus Torvalds 
75990ddc4f0SEric Dumazet static const struct proto_ops hci_sock_ops = {
7601da177e4SLinus Torvalds 	.family		= PF_BLUETOOTH,
7611da177e4SLinus Torvalds 	.owner		= THIS_MODULE,
7621da177e4SLinus Torvalds 	.release	= hci_sock_release,
7631da177e4SLinus Torvalds 	.bind		= hci_sock_bind,
7641da177e4SLinus Torvalds 	.getname	= hci_sock_getname,
7651da177e4SLinus Torvalds 	.sendmsg	= hci_sock_sendmsg,
7661da177e4SLinus Torvalds 	.recvmsg	= hci_sock_recvmsg,
7671da177e4SLinus Torvalds 	.ioctl		= hci_sock_ioctl,
7681da177e4SLinus Torvalds 	.poll		= datagram_poll,
7691da177e4SLinus Torvalds 	.listen		= sock_no_listen,
7701da177e4SLinus Torvalds 	.shutdown	= sock_no_shutdown,
7711da177e4SLinus Torvalds 	.setsockopt	= hci_sock_setsockopt,
7721da177e4SLinus Torvalds 	.getsockopt	= hci_sock_getsockopt,
7731da177e4SLinus Torvalds 	.connect	= sock_no_connect,
7741da177e4SLinus Torvalds 	.socketpair	= sock_no_socketpair,
7751da177e4SLinus Torvalds 	.accept		= sock_no_accept,
7761da177e4SLinus Torvalds 	.mmap		= sock_no_mmap
7771da177e4SLinus Torvalds };
7781da177e4SLinus Torvalds 
7791da177e4SLinus Torvalds static struct proto hci_sk_proto = {
7801da177e4SLinus Torvalds 	.name		= "HCI",
7811da177e4SLinus Torvalds 	.owner		= THIS_MODULE,
7821da177e4SLinus Torvalds 	.obj_size	= sizeof(struct hci_pinfo)
7831da177e4SLinus Torvalds };
7841da177e4SLinus Torvalds 
7853f378b68SEric Paris static int hci_sock_create(struct net *net, struct socket *sock, int protocol,
7863f378b68SEric Paris 			   int kern)
7871da177e4SLinus Torvalds {
7881da177e4SLinus Torvalds 	struct sock *sk;
7891da177e4SLinus Torvalds 
7901da177e4SLinus Torvalds 	BT_DBG("sock %p", sock);
7911da177e4SLinus Torvalds 
7921da177e4SLinus Torvalds 	if (sock->type != SOCK_RAW)
7931da177e4SLinus Torvalds 		return -ESOCKTNOSUPPORT;
7941da177e4SLinus Torvalds 
7951da177e4SLinus Torvalds 	sock->ops = &hci_sock_ops;
7961da177e4SLinus Torvalds 
7976257ff21SPavel Emelyanov 	sk = sk_alloc(net, PF_BLUETOOTH, GFP_ATOMIC, &hci_sk_proto);
7981da177e4SLinus Torvalds 	if (!sk)
7991da177e4SLinus Torvalds 		return -ENOMEM;
8001da177e4SLinus Torvalds 
8011da177e4SLinus Torvalds 	sock_init_data(sock, sk);
8021da177e4SLinus Torvalds 
8031da177e4SLinus Torvalds 	sock_reset_flag(sk, SOCK_ZAPPED);
8041da177e4SLinus Torvalds 
8051da177e4SLinus Torvalds 	sk->sk_protocol = protocol;
8061da177e4SLinus Torvalds 
8071da177e4SLinus Torvalds 	sock->state = SS_UNCONNECTED;
8081da177e4SLinus Torvalds 	sk->sk_state = BT_OPEN;
8091da177e4SLinus Torvalds 
8101da177e4SLinus Torvalds 	bt_sock_link(&hci_sk_list, sk);
8111da177e4SLinus Torvalds 	return 0;
8121da177e4SLinus Torvalds }
8131da177e4SLinus Torvalds 
8141da177e4SLinus Torvalds static int hci_sock_dev_event(struct notifier_block *this, unsigned long event, void *ptr)
8151da177e4SLinus Torvalds {
8161da177e4SLinus Torvalds 	struct hci_dev *hdev = (struct hci_dev *) ptr;
8171da177e4SLinus Torvalds 	struct hci_ev_si_device ev;
8181da177e4SLinus Torvalds 
8191da177e4SLinus Torvalds 	BT_DBG("hdev %s event %ld", hdev->name, event);
8201da177e4SLinus Torvalds 
8211da177e4SLinus Torvalds 	/* Send event to sockets */
8221da177e4SLinus Torvalds 	ev.event  = event;
8231da177e4SLinus Torvalds 	ev.dev_id = hdev->id;
8241da177e4SLinus Torvalds 	hci_si_event(NULL, HCI_EV_SI_DEVICE, sizeof(ev), &ev);
8251da177e4SLinus Torvalds 
8261da177e4SLinus Torvalds 	if (event == HCI_DEV_UNREG) {
8271da177e4SLinus Torvalds 		struct sock *sk;
8281da177e4SLinus Torvalds 		struct hlist_node *node;
8291da177e4SLinus Torvalds 
8301da177e4SLinus Torvalds 		/* Detach sockets from device */
8311da177e4SLinus Torvalds 		read_lock(&hci_sk_list.lock);
8321da177e4SLinus Torvalds 		sk_for_each(sk, node, &hci_sk_list.head) {
8334ce61d1cSSatyam Sharma 			bh_lock_sock_nested(sk);
8341da177e4SLinus Torvalds 			if (hci_pi(sk)->hdev == hdev) {
8351da177e4SLinus Torvalds 				hci_pi(sk)->hdev = NULL;
8361da177e4SLinus Torvalds 				sk->sk_err = EPIPE;
8371da177e4SLinus Torvalds 				sk->sk_state = BT_OPEN;
8381da177e4SLinus Torvalds 				sk->sk_state_change(sk);
8391da177e4SLinus Torvalds 
8401da177e4SLinus Torvalds 				hci_dev_put(hdev);
8411da177e4SLinus Torvalds 			}
8424ce61d1cSSatyam Sharma 			bh_unlock_sock(sk);
8431da177e4SLinus Torvalds 		}
8441da177e4SLinus Torvalds 		read_unlock(&hci_sk_list.lock);
8451da177e4SLinus Torvalds 	}
8461da177e4SLinus Torvalds 
8471da177e4SLinus Torvalds 	return NOTIFY_DONE;
8481da177e4SLinus Torvalds }
8491da177e4SLinus Torvalds 
850ec1b4cf7SStephen Hemminger static const struct net_proto_family hci_sock_family_ops = {
8511da177e4SLinus Torvalds 	.family	= PF_BLUETOOTH,
8521da177e4SLinus Torvalds 	.owner	= THIS_MODULE,
8531da177e4SLinus Torvalds 	.create	= hci_sock_create,
8541da177e4SLinus Torvalds };
8551da177e4SLinus Torvalds 
8561da177e4SLinus Torvalds static struct notifier_block hci_sock_nblock = {
8571da177e4SLinus Torvalds 	.notifier_call = hci_sock_dev_event
8581da177e4SLinus Torvalds };
8591da177e4SLinus Torvalds 
8601da177e4SLinus Torvalds int __init hci_sock_init(void)
8611da177e4SLinus Torvalds {
8621da177e4SLinus Torvalds 	int err;
8631da177e4SLinus Torvalds 
8641da177e4SLinus Torvalds 	err = proto_register(&hci_sk_proto, 0);
8651da177e4SLinus Torvalds 	if (err < 0)
8661da177e4SLinus Torvalds 		return err;
8671da177e4SLinus Torvalds 
8681da177e4SLinus Torvalds 	err = bt_sock_register(BTPROTO_HCI, &hci_sock_family_ops);
8691da177e4SLinus Torvalds 	if (err < 0)
8701da177e4SLinus Torvalds 		goto error;
8711da177e4SLinus Torvalds 
8721da177e4SLinus Torvalds 	hci_register_notifier(&hci_sock_nblock);
8731da177e4SLinus Torvalds 
8741da177e4SLinus Torvalds 	BT_INFO("HCI socket layer initialized");
8751da177e4SLinus Torvalds 
8761da177e4SLinus Torvalds 	return 0;
8771da177e4SLinus Torvalds 
8781da177e4SLinus Torvalds error:
8791da177e4SLinus Torvalds 	BT_ERR("HCI socket registration failed");
8801da177e4SLinus Torvalds 	proto_unregister(&hci_sk_proto);
8811da177e4SLinus Torvalds 	return err;
8821da177e4SLinus Torvalds }
8831da177e4SLinus Torvalds 
884b7440a14SAnand Gadiyar void hci_sock_cleanup(void)
8851da177e4SLinus Torvalds {
8861da177e4SLinus Torvalds 	if (bt_sock_unregister(BTPROTO_HCI) < 0)
8871da177e4SLinus Torvalds 		BT_ERR("HCI socket unregistration failed");
8881da177e4SLinus Torvalds 
8891da177e4SLinus Torvalds 	hci_unregister_notifier(&hci_sock_nblock);
8901da177e4SLinus Torvalds 
8911da177e4SLinus Torvalds 	proto_unregister(&hci_sk_proto);
8921da177e4SLinus Torvalds }
8930381101fSJohan Hedberg 
8940381101fSJohan Hedberg module_param(enable_mgmt, bool, 0644);
8950381101fSJohan Hedberg MODULE_PARM_DESC(enable_mgmt, "Enable Management interface");
896