xref: /openbmc/linux/net/bluetooth/hci_sock.c (revision b7440a14f28492bac30d7d43fd982fd210c6e971)
11da177e4SLinus Torvalds /*
21da177e4SLinus Torvalds    BlueZ - Bluetooth protocol stack for Linux
31da177e4SLinus Torvalds    Copyright (C) 2000-2001 Qualcomm Incorporated
41da177e4SLinus Torvalds 
51da177e4SLinus Torvalds    Written 2000,2001 by Maxim Krasnyansky <maxk@qualcomm.com>
61da177e4SLinus Torvalds 
71da177e4SLinus Torvalds    This program is free software; you can redistribute it and/or modify
81da177e4SLinus Torvalds    it under the terms of the GNU General Public License version 2 as
91da177e4SLinus Torvalds    published by the Free Software Foundation;
101da177e4SLinus Torvalds 
111da177e4SLinus Torvalds    THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS
121da177e4SLinus Torvalds    OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
131da177e4SLinus Torvalds    FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT OF THIRD PARTY RIGHTS.
141da177e4SLinus Torvalds    IN NO EVENT SHALL THE COPYRIGHT HOLDER(S) AND AUTHOR(S) BE LIABLE FOR ANY
151da177e4SLinus Torvalds    CLAIM, OR ANY SPECIAL INDIRECT OR CONSEQUENTIAL DAMAGES, OR ANY DAMAGES
161da177e4SLinus Torvalds    WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
171da177e4SLinus Torvalds    ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
181da177e4SLinus Torvalds    OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
191da177e4SLinus Torvalds 
201da177e4SLinus Torvalds    ALL LIABILITY, INCLUDING LIABILITY FOR INFRINGEMENT OF ANY PATENTS,
211da177e4SLinus Torvalds    COPYRIGHTS, TRADEMARKS OR OTHER RIGHTS, RELATING TO USE OF THIS
221da177e4SLinus Torvalds    SOFTWARE IS DISCLAIMED.
231da177e4SLinus Torvalds */
241da177e4SLinus Torvalds 
251da177e4SLinus Torvalds /* Bluetooth HCI sockets. */
261da177e4SLinus Torvalds 
271da177e4SLinus Torvalds #include <linux/module.h>
281da177e4SLinus Torvalds 
291da177e4SLinus Torvalds #include <linux/types.h>
304fc268d2SRandy Dunlap #include <linux/capability.h>
311da177e4SLinus Torvalds #include <linux/errno.h>
321da177e4SLinus Torvalds #include <linux/kernel.h>
331da177e4SLinus Torvalds #include <linux/slab.h>
341da177e4SLinus Torvalds #include <linux/poll.h>
351da177e4SLinus Torvalds #include <linux/fcntl.h>
361da177e4SLinus Torvalds #include <linux/init.h>
371da177e4SLinus Torvalds #include <linux/skbuff.h>
381da177e4SLinus Torvalds #include <linux/workqueue.h>
391da177e4SLinus Torvalds #include <linux/interrupt.h>
40767c5eb5SMarcel Holtmann #include <linux/compat.h>
411da177e4SLinus Torvalds #include <linux/socket.h>
421da177e4SLinus Torvalds #include <linux/ioctl.h>
431da177e4SLinus Torvalds #include <net/sock.h>
441da177e4SLinus Torvalds 
451da177e4SLinus Torvalds #include <asm/system.h>
4670f23020SAndrei Emeltchenko #include <linux/uaccess.h>
471da177e4SLinus Torvalds #include <asm/unaligned.h>
481da177e4SLinus Torvalds 
491da177e4SLinus Torvalds #include <net/bluetooth/bluetooth.h>
501da177e4SLinus Torvalds #include <net/bluetooth/hci_core.h>
511da177e4SLinus Torvalds 
520381101fSJohan Hedberg static int enable_mgmt;
530381101fSJohan Hedberg 
541da177e4SLinus Torvalds /* ----- HCI socket interface ----- */
551da177e4SLinus Torvalds 
561da177e4SLinus Torvalds static inline int hci_test_bit(int nr, void *addr)
571da177e4SLinus Torvalds {
581da177e4SLinus Torvalds 	return *((__u32 *) addr + (nr >> 5)) & ((__u32) 1 << (nr & 31));
591da177e4SLinus Torvalds }
601da177e4SLinus Torvalds 
611da177e4SLinus Torvalds /* Security filter */
621da177e4SLinus Torvalds static struct hci_sec_filter hci_sec_filter = {
631da177e4SLinus Torvalds 	/* Packet types */
641da177e4SLinus Torvalds 	0x10,
651da177e4SLinus Torvalds 	/* Events */
66dd7f5527SMarcel Holtmann 	{ 0x1000d9fe, 0x0000b00c },
671da177e4SLinus Torvalds 	/* Commands */
681da177e4SLinus Torvalds 	{
691da177e4SLinus Torvalds 		{ 0x0 },
701da177e4SLinus Torvalds 		/* OGF_LINK_CTL */
717c631a67SMarcel Holtmann 		{ 0xbe000006, 0x00000001, 0x00000000, 0x00 },
721da177e4SLinus Torvalds 		/* OGF_LINK_POLICY */
737c631a67SMarcel Holtmann 		{ 0x00005200, 0x00000000, 0x00000000, 0x00 },
741da177e4SLinus Torvalds 		/* OGF_HOST_CTL */
757c631a67SMarcel Holtmann 		{ 0xaab00200, 0x2b402aaa, 0x05220154, 0x00 },
761da177e4SLinus Torvalds 		/* OGF_INFO_PARAM */
777c631a67SMarcel Holtmann 		{ 0x000002be, 0x00000000, 0x00000000, 0x00 },
781da177e4SLinus Torvalds 		/* OGF_STATUS_PARAM */
797c631a67SMarcel Holtmann 		{ 0x000000ea, 0x00000000, 0x00000000, 0x00 }
801da177e4SLinus Torvalds 	}
811da177e4SLinus Torvalds };
821da177e4SLinus Torvalds 
831da177e4SLinus Torvalds static struct bt_sock_list hci_sk_list = {
84d5fb2962SRobert P. J. Day 	.lock = __RW_LOCK_UNLOCKED(hci_sk_list.lock)
851da177e4SLinus Torvalds };
861da177e4SLinus Torvalds 
871da177e4SLinus Torvalds /* Send frame to RAW socket */
88eec8d2bcSJohan Hedberg void hci_send_to_sock(struct hci_dev *hdev, struct sk_buff *skb,
89eec8d2bcSJohan Hedberg 							struct sock *skip_sk)
901da177e4SLinus Torvalds {
911da177e4SLinus Torvalds 	struct sock *sk;
921da177e4SLinus Torvalds 	struct hlist_node *node;
931da177e4SLinus Torvalds 
941da177e4SLinus Torvalds 	BT_DBG("hdev %p len %d", hdev, skb->len);
951da177e4SLinus Torvalds 
961da177e4SLinus Torvalds 	read_lock(&hci_sk_list.lock);
971da177e4SLinus Torvalds 	sk_for_each(sk, node, &hci_sk_list.head) {
981da177e4SLinus Torvalds 		struct hci_filter *flt;
991da177e4SLinus Torvalds 		struct sk_buff *nskb;
1001da177e4SLinus Torvalds 
101eec8d2bcSJohan Hedberg 		if (sk == skip_sk)
102eec8d2bcSJohan Hedberg 			continue;
103eec8d2bcSJohan Hedberg 
1041da177e4SLinus Torvalds 		if (sk->sk_state != BT_BOUND || hci_pi(sk)->hdev != hdev)
1051da177e4SLinus Torvalds 			continue;
1061da177e4SLinus Torvalds 
1071da177e4SLinus Torvalds 		/* Don't send frame to the socket it came from */
1081da177e4SLinus Torvalds 		if (skb->sk == sk)
1091da177e4SLinus Torvalds 			continue;
1101da177e4SLinus Torvalds 
111a40c406cSJohan Hedberg 		if (bt_cb(skb)->channel != hci_pi(sk)->channel)
112a40c406cSJohan Hedberg 			continue;
113a40c406cSJohan Hedberg 
114a40c406cSJohan Hedberg 		if (bt_cb(skb)->channel == HCI_CHANNEL_CONTROL)
115a40c406cSJohan Hedberg 			goto clone;
116a40c406cSJohan Hedberg 
1171da177e4SLinus Torvalds 		/* Apply filter */
1181da177e4SLinus Torvalds 		flt = &hci_pi(sk)->filter;
1191da177e4SLinus Torvalds 
1200d48d939SMarcel Holtmann 		if (!test_bit((bt_cb(skb)->pkt_type == HCI_VENDOR_PKT) ?
1210d48d939SMarcel Holtmann 				0 : (bt_cb(skb)->pkt_type & HCI_FLT_TYPE_BITS), &flt->type_mask))
1221da177e4SLinus Torvalds 			continue;
1231da177e4SLinus Torvalds 
1240d48d939SMarcel Holtmann 		if (bt_cb(skb)->pkt_type == HCI_EVENT_PKT) {
1251da177e4SLinus Torvalds 			register int evt = (*(__u8 *)skb->data & HCI_FLT_EVENT_BITS);
1261da177e4SLinus Torvalds 
1271da177e4SLinus Torvalds 			if (!hci_test_bit(evt, &flt->event_mask))
1281da177e4SLinus Torvalds 				continue;
1291da177e4SLinus Torvalds 
1304498c80dSDavid S. Miller 			if (flt->opcode &&
1314498c80dSDavid S. Miller 			    ((evt == HCI_EV_CMD_COMPLETE &&
1324498c80dSDavid S. Miller 			      flt->opcode !=
133905f3ed6SAl Viro 			      get_unaligned((__le16 *)(skb->data + 3))) ||
1341da177e4SLinus Torvalds 			     (evt == HCI_EV_CMD_STATUS &&
1354498c80dSDavid S. Miller 			      flt->opcode !=
136905f3ed6SAl Viro 			      get_unaligned((__le16 *)(skb->data + 4)))))
1371da177e4SLinus Torvalds 				continue;
1381da177e4SLinus Torvalds 		}
1391da177e4SLinus Torvalds 
140a40c406cSJohan Hedberg clone:
14170f23020SAndrei Emeltchenko 		nskb = skb_clone(skb, GFP_ATOMIC);
14270f23020SAndrei Emeltchenko 		if (!nskb)
1431da177e4SLinus Torvalds 			continue;
1441da177e4SLinus Torvalds 
1451da177e4SLinus Torvalds 		/* Put type byte before the data */
146a40c406cSJohan Hedberg 		if (bt_cb(skb)->channel == HCI_CHANNEL_RAW)
1470d48d939SMarcel Holtmann 			memcpy(skb_push(nskb, 1), &bt_cb(nskb)->pkt_type, 1);
1481da177e4SLinus Torvalds 
1491da177e4SLinus Torvalds 		if (sock_queue_rcv_skb(sk, nskb))
1501da177e4SLinus Torvalds 			kfree_skb(nskb);
1511da177e4SLinus Torvalds 	}
1521da177e4SLinus Torvalds 	read_unlock(&hci_sk_list.lock);
1531da177e4SLinus Torvalds }
1541da177e4SLinus Torvalds 
1551da177e4SLinus Torvalds static int hci_sock_release(struct socket *sock)
1561da177e4SLinus Torvalds {
1571da177e4SLinus Torvalds 	struct sock *sk = sock->sk;
1587b005bd3SMarcel Holtmann 	struct hci_dev *hdev;
1591da177e4SLinus Torvalds 
1601da177e4SLinus Torvalds 	BT_DBG("sock %p sk %p", sock, sk);
1611da177e4SLinus Torvalds 
1621da177e4SLinus Torvalds 	if (!sk)
1631da177e4SLinus Torvalds 		return 0;
1641da177e4SLinus Torvalds 
1657b005bd3SMarcel Holtmann 	hdev = hci_pi(sk)->hdev;
1667b005bd3SMarcel Holtmann 
1671da177e4SLinus Torvalds 	bt_sock_unlink(&hci_sk_list, sk);
1681da177e4SLinus Torvalds 
1691da177e4SLinus Torvalds 	if (hdev) {
1701da177e4SLinus Torvalds 		atomic_dec(&hdev->promisc);
1711da177e4SLinus Torvalds 		hci_dev_put(hdev);
1721da177e4SLinus Torvalds 	}
1731da177e4SLinus Torvalds 
1741da177e4SLinus Torvalds 	sock_orphan(sk);
1751da177e4SLinus Torvalds 
1761da177e4SLinus Torvalds 	skb_queue_purge(&sk->sk_receive_queue);
1771da177e4SLinus Torvalds 	skb_queue_purge(&sk->sk_write_queue);
1781da177e4SLinus Torvalds 
1791da177e4SLinus Torvalds 	sock_put(sk);
1801da177e4SLinus Torvalds 	return 0;
1811da177e4SLinus Torvalds }
1821da177e4SLinus Torvalds 
183f0358568SJohan Hedberg struct bdaddr_list *hci_blacklist_lookup(struct hci_dev *hdev, bdaddr_t *bdaddr)
184f0358568SJohan Hedberg {
185f0358568SJohan Hedberg 	struct list_head *p;
186f0358568SJohan Hedberg 
187ea4bd8baSDavid Miller 	list_for_each(p, &hdev->blacklist) {
188f0358568SJohan Hedberg 		struct bdaddr_list *b;
189f0358568SJohan Hedberg 
190f0358568SJohan Hedberg 		b = list_entry(p, struct bdaddr_list, list);
191f0358568SJohan Hedberg 
192f0358568SJohan Hedberg 		if (bacmp(bdaddr, &b->bdaddr) == 0)
193f0358568SJohan Hedberg 			return b;
194f0358568SJohan Hedberg 	}
195f0358568SJohan Hedberg 
196f0358568SJohan Hedberg 	return NULL;
197f0358568SJohan Hedberg }
198f0358568SJohan Hedberg 
199f0358568SJohan Hedberg static int hci_blacklist_add(struct hci_dev *hdev, void __user *arg)
200f0358568SJohan Hedberg {
201f0358568SJohan Hedberg 	bdaddr_t bdaddr;
202f0358568SJohan Hedberg 	struct bdaddr_list *entry;
203f0358568SJohan Hedberg 
204f0358568SJohan Hedberg 	if (copy_from_user(&bdaddr, arg, sizeof(bdaddr)))
205f0358568SJohan Hedberg 		return -EFAULT;
206f0358568SJohan Hedberg 
207f0358568SJohan Hedberg 	if (bacmp(&bdaddr, BDADDR_ANY) == 0)
208f0358568SJohan Hedberg 		return -EBADF;
209f0358568SJohan Hedberg 
210f0358568SJohan Hedberg 	if (hci_blacklist_lookup(hdev, &bdaddr))
211f0358568SJohan Hedberg 		return -EEXIST;
212f0358568SJohan Hedberg 
213f0358568SJohan Hedberg 	entry = kzalloc(sizeof(struct bdaddr_list), GFP_KERNEL);
214f0358568SJohan Hedberg 	if (!entry)
215f0358568SJohan Hedberg 		return -ENOMEM;
216f0358568SJohan Hedberg 
217f0358568SJohan Hedberg 	bacpy(&entry->bdaddr, &bdaddr);
218f0358568SJohan Hedberg 
219ea4bd8baSDavid Miller 	list_add(&entry->list, &hdev->blacklist);
220f0358568SJohan Hedberg 
221f0358568SJohan Hedberg 	return 0;
222f0358568SJohan Hedberg }
223f0358568SJohan Hedberg 
224f0358568SJohan Hedberg int hci_blacklist_clear(struct hci_dev *hdev)
225f0358568SJohan Hedberg {
226f0358568SJohan Hedberg 	struct list_head *p, *n;
227f0358568SJohan Hedberg 
228ea4bd8baSDavid Miller 	list_for_each_safe(p, n, &hdev->blacklist) {
229f0358568SJohan Hedberg 		struct bdaddr_list *b;
230f0358568SJohan Hedberg 
231f0358568SJohan Hedberg 		b = list_entry(p, struct bdaddr_list, list);
232f0358568SJohan Hedberg 
233f0358568SJohan Hedberg 		list_del(p);
234f0358568SJohan Hedberg 		kfree(b);
235f0358568SJohan Hedberg 	}
236f0358568SJohan Hedberg 
237f0358568SJohan Hedberg 	return 0;
238f0358568SJohan Hedberg }
239f0358568SJohan Hedberg 
240f0358568SJohan Hedberg static int hci_blacklist_del(struct hci_dev *hdev, void __user *arg)
241f0358568SJohan Hedberg {
242f0358568SJohan Hedberg 	bdaddr_t bdaddr;
243f0358568SJohan Hedberg 	struct bdaddr_list *entry;
244f0358568SJohan Hedberg 
245f0358568SJohan Hedberg 	if (copy_from_user(&bdaddr, arg, sizeof(bdaddr)))
246f0358568SJohan Hedberg 		return -EFAULT;
247f0358568SJohan Hedberg 
248f0358568SJohan Hedberg 	if (bacmp(&bdaddr, BDADDR_ANY) == 0)
249f0358568SJohan Hedberg 		return hci_blacklist_clear(hdev);
250f0358568SJohan Hedberg 
251f0358568SJohan Hedberg 	entry = hci_blacklist_lookup(hdev, &bdaddr);
252f0358568SJohan Hedberg 	if (!entry)
253f0358568SJohan Hedberg 		return -ENOENT;
254f0358568SJohan Hedberg 
255f0358568SJohan Hedberg 	list_del(&entry->list);
256f0358568SJohan Hedberg 	kfree(entry);
257f0358568SJohan Hedberg 
258f0358568SJohan Hedberg 	return 0;
259f0358568SJohan Hedberg }
260f0358568SJohan Hedberg 
2611da177e4SLinus Torvalds /* Ioctls that require bound socket */
2621da177e4SLinus Torvalds static inline int hci_sock_bound_ioctl(struct sock *sk, unsigned int cmd, unsigned long arg)
2631da177e4SLinus Torvalds {
2641da177e4SLinus Torvalds 	struct hci_dev *hdev = hci_pi(sk)->hdev;
2651da177e4SLinus Torvalds 
2661da177e4SLinus Torvalds 	if (!hdev)
2671da177e4SLinus Torvalds 		return -EBADFD;
2681da177e4SLinus Torvalds 
2691da177e4SLinus Torvalds 	switch (cmd) {
2701da177e4SLinus Torvalds 	case HCISETRAW:
2711da177e4SLinus Torvalds 		if (!capable(CAP_NET_ADMIN))
2721da177e4SLinus Torvalds 			return -EACCES;
2731da177e4SLinus Torvalds 
2741da177e4SLinus Torvalds 		if (test_bit(HCI_QUIRK_RAW_DEVICE, &hdev->quirks))
2751da177e4SLinus Torvalds 			return -EPERM;
2761da177e4SLinus Torvalds 
2771da177e4SLinus Torvalds 		if (arg)
2781da177e4SLinus Torvalds 			set_bit(HCI_RAW, &hdev->flags);
2791da177e4SLinus Torvalds 		else
2801da177e4SLinus Torvalds 			clear_bit(HCI_RAW, &hdev->flags);
2811da177e4SLinus Torvalds 
2821da177e4SLinus Torvalds 		return 0;
2831da177e4SLinus Torvalds 
2841da177e4SLinus Torvalds 	case HCIGETCONNINFO:
2851da177e4SLinus Torvalds 		return hci_get_conn_info(hdev, (void __user *) arg);
2861da177e4SLinus Torvalds 
28740be492fSMarcel Holtmann 	case HCIGETAUTHINFO:
28840be492fSMarcel Holtmann 		return hci_get_auth_info(hdev, (void __user *) arg);
28940be492fSMarcel Holtmann 
290f0358568SJohan Hedberg 	case HCIBLOCKADDR:
291f0358568SJohan Hedberg 		if (!capable(CAP_NET_ADMIN))
292f0358568SJohan Hedberg 			return -EACCES;
293f0358568SJohan Hedberg 		return hci_blacklist_add(hdev, (void __user *) arg);
294f0358568SJohan Hedberg 
295f0358568SJohan Hedberg 	case HCIUNBLOCKADDR:
296f0358568SJohan Hedberg 		if (!capable(CAP_NET_ADMIN))
297f0358568SJohan Hedberg 			return -EACCES;
298f0358568SJohan Hedberg 		return hci_blacklist_del(hdev, (void __user *) arg);
299f0358568SJohan Hedberg 
3001da177e4SLinus Torvalds 	default:
3011da177e4SLinus Torvalds 		if (hdev->ioctl)
3021da177e4SLinus Torvalds 			return hdev->ioctl(hdev, cmd, arg);
3031da177e4SLinus Torvalds 		return -EINVAL;
3041da177e4SLinus Torvalds 	}
3051da177e4SLinus Torvalds }
3061da177e4SLinus Torvalds 
3071da177e4SLinus Torvalds static int hci_sock_ioctl(struct socket *sock, unsigned int cmd, unsigned long arg)
3081da177e4SLinus Torvalds {
3091da177e4SLinus Torvalds 	struct sock *sk = sock->sk;
3101da177e4SLinus Torvalds 	void __user *argp = (void __user *) arg;
3111da177e4SLinus Torvalds 	int err;
3121da177e4SLinus Torvalds 
3131da177e4SLinus Torvalds 	BT_DBG("cmd %x arg %lx", cmd, arg);
3141da177e4SLinus Torvalds 
3151da177e4SLinus Torvalds 	switch (cmd) {
3161da177e4SLinus Torvalds 	case HCIGETDEVLIST:
3171da177e4SLinus Torvalds 		return hci_get_dev_list(argp);
3181da177e4SLinus Torvalds 
3191da177e4SLinus Torvalds 	case HCIGETDEVINFO:
3201da177e4SLinus Torvalds 		return hci_get_dev_info(argp);
3211da177e4SLinus Torvalds 
3221da177e4SLinus Torvalds 	case HCIGETCONNLIST:
3231da177e4SLinus Torvalds 		return hci_get_conn_list(argp);
3241da177e4SLinus Torvalds 
3251da177e4SLinus Torvalds 	case HCIDEVUP:
3261da177e4SLinus Torvalds 		if (!capable(CAP_NET_ADMIN))
3271da177e4SLinus Torvalds 			return -EACCES;
3281da177e4SLinus Torvalds 		return hci_dev_open(arg);
3291da177e4SLinus Torvalds 
3301da177e4SLinus Torvalds 	case HCIDEVDOWN:
3311da177e4SLinus Torvalds 		if (!capable(CAP_NET_ADMIN))
3321da177e4SLinus Torvalds 			return -EACCES;
3331da177e4SLinus Torvalds 		return hci_dev_close(arg);
3341da177e4SLinus Torvalds 
3351da177e4SLinus Torvalds 	case HCIDEVRESET:
3361da177e4SLinus Torvalds 		if (!capable(CAP_NET_ADMIN))
3371da177e4SLinus Torvalds 			return -EACCES;
3381da177e4SLinus Torvalds 		return hci_dev_reset(arg);
3391da177e4SLinus Torvalds 
3401da177e4SLinus Torvalds 	case HCIDEVRESTAT:
3411da177e4SLinus Torvalds 		if (!capable(CAP_NET_ADMIN))
3421da177e4SLinus Torvalds 			return -EACCES;
3431da177e4SLinus Torvalds 		return hci_dev_reset_stat(arg);
3441da177e4SLinus Torvalds 
3451da177e4SLinus Torvalds 	case HCISETSCAN:
3461da177e4SLinus Torvalds 	case HCISETAUTH:
3471da177e4SLinus Torvalds 	case HCISETENCRYPT:
3481da177e4SLinus Torvalds 	case HCISETPTYPE:
3491da177e4SLinus Torvalds 	case HCISETLINKPOL:
3501da177e4SLinus Torvalds 	case HCISETLINKMODE:
3511da177e4SLinus Torvalds 	case HCISETACLMTU:
3521da177e4SLinus Torvalds 	case HCISETSCOMTU:
3531da177e4SLinus Torvalds 		if (!capable(CAP_NET_ADMIN))
3541da177e4SLinus Torvalds 			return -EACCES;
3551da177e4SLinus Torvalds 		return hci_dev_cmd(cmd, argp);
3561da177e4SLinus Torvalds 
3571da177e4SLinus Torvalds 	case HCIINQUIRY:
3581da177e4SLinus Torvalds 		return hci_inquiry(argp);
3591da177e4SLinus Torvalds 
3601da177e4SLinus Torvalds 	default:
3611da177e4SLinus Torvalds 		lock_sock(sk);
3621da177e4SLinus Torvalds 		err = hci_sock_bound_ioctl(sk, cmd, arg);
3631da177e4SLinus Torvalds 		release_sock(sk);
3641da177e4SLinus Torvalds 		return err;
3651da177e4SLinus Torvalds 	}
3661da177e4SLinus Torvalds }
3671da177e4SLinus Torvalds 
3681da177e4SLinus Torvalds static int hci_sock_bind(struct socket *sock, struct sockaddr *addr, int addr_len)
3691da177e4SLinus Torvalds {
3700381101fSJohan Hedberg 	struct sockaddr_hci haddr;
3711da177e4SLinus Torvalds 	struct sock *sk = sock->sk;
3721da177e4SLinus Torvalds 	struct hci_dev *hdev = NULL;
3730381101fSJohan Hedberg 	int len, err = 0;
3741da177e4SLinus Torvalds 
3751da177e4SLinus Torvalds 	BT_DBG("sock %p sk %p", sock, sk);
3761da177e4SLinus Torvalds 
3770381101fSJohan Hedberg 	if (!addr)
3780381101fSJohan Hedberg 		return -EINVAL;
3790381101fSJohan Hedberg 
3800381101fSJohan Hedberg 	memset(&haddr, 0, sizeof(haddr));
3810381101fSJohan Hedberg 	len = min_t(unsigned int, sizeof(haddr), addr_len);
3820381101fSJohan Hedberg 	memcpy(&haddr, addr, len);
3830381101fSJohan Hedberg 
3840381101fSJohan Hedberg 	if (haddr.hci_family != AF_BLUETOOTH)
3850381101fSJohan Hedberg 		return -EINVAL;
3860381101fSJohan Hedberg 
38717f9cc31SGustavo F. Padovan 	if (haddr.hci_channel > HCI_CHANNEL_CONTROL)
38817f9cc31SGustavo F. Padovan 		return -EINVAL;
38917f9cc31SGustavo F. Padovan 
39017f9cc31SGustavo F. Padovan 	if (haddr.hci_channel == HCI_CHANNEL_CONTROL && !enable_mgmt)
3911da177e4SLinus Torvalds 		return -EINVAL;
3921da177e4SLinus Torvalds 
3931da177e4SLinus Torvalds 	lock_sock(sk);
3941da177e4SLinus Torvalds 
3950381101fSJohan Hedberg 	if (sk->sk_state == BT_BOUND || hci_pi(sk)->hdev) {
3961da177e4SLinus Torvalds 		err = -EALREADY;
3971da177e4SLinus Torvalds 		goto done;
3981da177e4SLinus Torvalds 	}
3991da177e4SLinus Torvalds 
4000381101fSJohan Hedberg 	if (haddr.hci_dev != HCI_DEV_NONE) {
4010381101fSJohan Hedberg 		hdev = hci_dev_get(haddr.hci_dev);
40270f23020SAndrei Emeltchenko 		if (!hdev) {
4031da177e4SLinus Torvalds 			err = -ENODEV;
4041da177e4SLinus Torvalds 			goto done;
4051da177e4SLinus Torvalds 		}
4061da177e4SLinus Torvalds 
4071da177e4SLinus Torvalds 		atomic_inc(&hdev->promisc);
4081da177e4SLinus Torvalds 	}
4091da177e4SLinus Torvalds 
4100381101fSJohan Hedberg 	hci_pi(sk)->channel = haddr.hci_channel;
4111da177e4SLinus Torvalds 	hci_pi(sk)->hdev = hdev;
4121da177e4SLinus Torvalds 	sk->sk_state = BT_BOUND;
4131da177e4SLinus Torvalds 
4141da177e4SLinus Torvalds done:
4151da177e4SLinus Torvalds 	release_sock(sk);
4161da177e4SLinus Torvalds 	return err;
4171da177e4SLinus Torvalds }
4181da177e4SLinus Torvalds 
4191da177e4SLinus Torvalds static int hci_sock_getname(struct socket *sock, struct sockaddr *addr, int *addr_len, int peer)
4201da177e4SLinus Torvalds {
4211da177e4SLinus Torvalds 	struct sockaddr_hci *haddr = (struct sockaddr_hci *) addr;
4221da177e4SLinus Torvalds 	struct sock *sk = sock->sk;
4237b005bd3SMarcel Holtmann 	struct hci_dev *hdev = hci_pi(sk)->hdev;
4241da177e4SLinus Torvalds 
4251da177e4SLinus Torvalds 	BT_DBG("sock %p sk %p", sock, sk);
4261da177e4SLinus Torvalds 
4277b005bd3SMarcel Holtmann 	if (!hdev)
4287b005bd3SMarcel Holtmann 		return -EBADFD;
4297b005bd3SMarcel Holtmann 
4301da177e4SLinus Torvalds 	lock_sock(sk);
4311da177e4SLinus Torvalds 
4321da177e4SLinus Torvalds 	*addr_len = sizeof(*haddr);
4331da177e4SLinus Torvalds 	haddr->hci_family = AF_BLUETOOTH;
4347b005bd3SMarcel Holtmann 	haddr->hci_dev    = hdev->id;
4351da177e4SLinus Torvalds 
4361da177e4SLinus Torvalds 	release_sock(sk);
4371da177e4SLinus Torvalds 	return 0;
4381da177e4SLinus Torvalds }
4391da177e4SLinus Torvalds 
4401da177e4SLinus Torvalds static inline void hci_sock_cmsg(struct sock *sk, struct msghdr *msg, struct sk_buff *skb)
4411da177e4SLinus Torvalds {
4421da177e4SLinus Torvalds 	__u32 mask = hci_pi(sk)->cmsg_mask;
4431da177e4SLinus Torvalds 
4440d48d939SMarcel Holtmann 	if (mask & HCI_CMSG_DIR) {
4450d48d939SMarcel Holtmann 		int incoming = bt_cb(skb)->incoming;
4460d48d939SMarcel Holtmann 		put_cmsg(msg, SOL_HCI, HCI_CMSG_DIR, sizeof(incoming), &incoming);
4470d48d939SMarcel Holtmann 	}
4481da177e4SLinus Torvalds 
449a61bbcf2SPatrick McHardy 	if (mask & HCI_CMSG_TSTAMP) {
450f6e623a6SJohann Felix Soden #ifdef CONFIG_COMPAT
451f6e623a6SJohann Felix Soden 		struct compat_timeval ctv;
452f6e623a6SJohann Felix Soden #endif
453a61bbcf2SPatrick McHardy 		struct timeval tv;
454767c5eb5SMarcel Holtmann 		void *data;
455767c5eb5SMarcel Holtmann 		int len;
456a61bbcf2SPatrick McHardy 
457a61bbcf2SPatrick McHardy 		skb_get_timestamp(skb, &tv);
458767c5eb5SMarcel Holtmann 
4591da97f83SDavid S. Miller 		data = &tv;
4601da97f83SDavid S. Miller 		len = sizeof(tv);
4611da97f83SDavid S. Miller #ifdef CONFIG_COMPAT
462767c5eb5SMarcel Holtmann 		if (msg->msg_flags & MSG_CMSG_COMPAT) {
463767c5eb5SMarcel Holtmann 			ctv.tv_sec = tv.tv_sec;
464767c5eb5SMarcel Holtmann 			ctv.tv_usec = tv.tv_usec;
465767c5eb5SMarcel Holtmann 			data = &ctv;
466767c5eb5SMarcel Holtmann 			len = sizeof(ctv);
467767c5eb5SMarcel Holtmann 		}
4681da97f83SDavid S. Miller #endif
469767c5eb5SMarcel Holtmann 
470767c5eb5SMarcel Holtmann 		put_cmsg(msg, SOL_HCI, HCI_CMSG_TSTAMP, len, data);
471a61bbcf2SPatrick McHardy 	}
4721da177e4SLinus Torvalds }
4731da177e4SLinus Torvalds 
4741da177e4SLinus Torvalds static int hci_sock_recvmsg(struct kiocb *iocb, struct socket *sock,
4751da177e4SLinus Torvalds 				struct msghdr *msg, size_t len, int flags)
4761da177e4SLinus Torvalds {
4771da177e4SLinus Torvalds 	int noblock = flags & MSG_DONTWAIT;
4781da177e4SLinus Torvalds 	struct sock *sk = sock->sk;
4791da177e4SLinus Torvalds 	struct sk_buff *skb;
4801da177e4SLinus Torvalds 	int copied, err;
4811da177e4SLinus Torvalds 
4821da177e4SLinus Torvalds 	BT_DBG("sock %p, sk %p", sock, sk);
4831da177e4SLinus Torvalds 
4841da177e4SLinus Torvalds 	if (flags & (MSG_OOB))
4851da177e4SLinus Torvalds 		return -EOPNOTSUPP;
4861da177e4SLinus Torvalds 
4871da177e4SLinus Torvalds 	if (sk->sk_state == BT_CLOSED)
4881da177e4SLinus Torvalds 		return 0;
4891da177e4SLinus Torvalds 
49070f23020SAndrei Emeltchenko 	skb = skb_recv_datagram(sk, flags, noblock, &err);
49170f23020SAndrei Emeltchenko 	if (!skb)
4921da177e4SLinus Torvalds 		return err;
4931da177e4SLinus Torvalds 
4941da177e4SLinus Torvalds 	msg->msg_namelen = 0;
4951da177e4SLinus Torvalds 
4961da177e4SLinus Torvalds 	copied = skb->len;
4971da177e4SLinus Torvalds 	if (len < copied) {
4981da177e4SLinus Torvalds 		msg->msg_flags |= MSG_TRUNC;
4991da177e4SLinus Torvalds 		copied = len;
5001da177e4SLinus Torvalds 	}
5011da177e4SLinus Torvalds 
502badff6d0SArnaldo Carvalho de Melo 	skb_reset_transport_header(skb);
5031da177e4SLinus Torvalds 	err = skb_copy_datagram_iovec(skb, 0, msg->msg_iov, copied);
5041da177e4SLinus Torvalds 
5051da177e4SLinus Torvalds 	hci_sock_cmsg(sk, msg, skb);
5061da177e4SLinus Torvalds 
5071da177e4SLinus Torvalds 	skb_free_datagram(sk, skb);
5081da177e4SLinus Torvalds 
5091da177e4SLinus Torvalds 	return err ? : copied;
5101da177e4SLinus Torvalds }
5111da177e4SLinus Torvalds 
5121da177e4SLinus Torvalds static int hci_sock_sendmsg(struct kiocb *iocb, struct socket *sock,
5131da177e4SLinus Torvalds 			    struct msghdr *msg, size_t len)
5141da177e4SLinus Torvalds {
5151da177e4SLinus Torvalds 	struct sock *sk = sock->sk;
5161da177e4SLinus Torvalds 	struct hci_dev *hdev;
5171da177e4SLinus Torvalds 	struct sk_buff *skb;
5181da177e4SLinus Torvalds 	int err;
5191da177e4SLinus Torvalds 
5201da177e4SLinus Torvalds 	BT_DBG("sock %p sk %p", sock, sk);
5211da177e4SLinus Torvalds 
5221da177e4SLinus Torvalds 	if (msg->msg_flags & MSG_OOB)
5231da177e4SLinus Torvalds 		return -EOPNOTSUPP;
5241da177e4SLinus Torvalds 
5251da177e4SLinus Torvalds 	if (msg->msg_flags & ~(MSG_DONTWAIT|MSG_NOSIGNAL|MSG_ERRQUEUE))
5261da177e4SLinus Torvalds 		return -EINVAL;
5271da177e4SLinus Torvalds 
5281da177e4SLinus Torvalds 	if (len < 4 || len > HCI_MAX_FRAME_SIZE)
5291da177e4SLinus Torvalds 		return -EINVAL;
5301da177e4SLinus Torvalds 
5311da177e4SLinus Torvalds 	lock_sock(sk);
5321da177e4SLinus Torvalds 
5330381101fSJohan Hedberg 	switch (hci_pi(sk)->channel) {
5340381101fSJohan Hedberg 	case HCI_CHANNEL_RAW:
5350381101fSJohan Hedberg 		break;
5360381101fSJohan Hedberg 	case HCI_CHANNEL_CONTROL:
5370381101fSJohan Hedberg 		err = mgmt_control(sk, msg, len);
5380381101fSJohan Hedberg 		goto done;
5390381101fSJohan Hedberg 	default:
5400381101fSJohan Hedberg 		err = -EINVAL;
5410381101fSJohan Hedberg 		goto done;
5420381101fSJohan Hedberg 	}
5430381101fSJohan Hedberg 
54470f23020SAndrei Emeltchenko 	hdev = hci_pi(sk)->hdev;
54570f23020SAndrei Emeltchenko 	if (!hdev) {
5461da177e4SLinus Torvalds 		err = -EBADFD;
5471da177e4SLinus Torvalds 		goto done;
5481da177e4SLinus Torvalds 	}
5491da177e4SLinus Torvalds 
5507e21addcSMarcel Holtmann 	if (!test_bit(HCI_UP, &hdev->flags)) {
5517e21addcSMarcel Holtmann 		err = -ENETDOWN;
5527e21addcSMarcel Holtmann 		goto done;
5537e21addcSMarcel Holtmann 	}
5547e21addcSMarcel Holtmann 
55570f23020SAndrei Emeltchenko 	skb = bt_skb_send_alloc(sk, len, msg->msg_flags & MSG_DONTWAIT, &err);
55670f23020SAndrei Emeltchenko 	if (!skb)
5571da177e4SLinus Torvalds 		goto done;
5581da177e4SLinus Torvalds 
5591da177e4SLinus Torvalds 	if (memcpy_fromiovec(skb_put(skb, len), msg->msg_iov, len)) {
5601da177e4SLinus Torvalds 		err = -EFAULT;
5611da177e4SLinus Torvalds 		goto drop;
5621da177e4SLinus Torvalds 	}
5631da177e4SLinus Torvalds 
5640d48d939SMarcel Holtmann 	bt_cb(skb)->pkt_type = *((unsigned char *) skb->data);
5651da177e4SLinus Torvalds 	skb_pull(skb, 1);
5661da177e4SLinus Torvalds 	skb->dev = (void *) hdev;
5671da177e4SLinus Torvalds 
5680d48d939SMarcel Holtmann 	if (bt_cb(skb)->pkt_type == HCI_COMMAND_PKT) {
56983985319SHarvey Harrison 		u16 opcode = get_unaligned_le16(skb->data);
5701da177e4SLinus Torvalds 		u16 ogf = hci_opcode_ogf(opcode);
5711da177e4SLinus Torvalds 		u16 ocf = hci_opcode_ocf(opcode);
5721da177e4SLinus Torvalds 
5731da177e4SLinus Torvalds 		if (((ogf > HCI_SFLT_MAX_OGF) ||
5741da177e4SLinus Torvalds 				!hci_test_bit(ocf & HCI_FLT_OCF_BITS, &hci_sec_filter.ocf_mask[ogf])) &&
5751da177e4SLinus Torvalds 					!capable(CAP_NET_RAW)) {
5761da177e4SLinus Torvalds 			err = -EPERM;
5771da177e4SLinus Torvalds 			goto drop;
5781da177e4SLinus Torvalds 		}
5791da177e4SLinus Torvalds 
580a9de9248SMarcel Holtmann 		if (test_bit(HCI_RAW, &hdev->flags) || (ogf == 0x3f)) {
5811da177e4SLinus Torvalds 			skb_queue_tail(&hdev->raw_q, skb);
582c78ae283SMarcel Holtmann 			tasklet_schedule(&hdev->tx_task);
5831da177e4SLinus Torvalds 		} else {
5841da177e4SLinus Torvalds 			skb_queue_tail(&hdev->cmd_q, skb);
585c78ae283SMarcel Holtmann 			tasklet_schedule(&hdev->cmd_task);
5861da177e4SLinus Torvalds 		}
5871da177e4SLinus Torvalds 	} else {
5881da177e4SLinus Torvalds 		if (!capable(CAP_NET_RAW)) {
5891da177e4SLinus Torvalds 			err = -EPERM;
5901da177e4SLinus Torvalds 			goto drop;
5911da177e4SLinus Torvalds 		}
5921da177e4SLinus Torvalds 
5931da177e4SLinus Torvalds 		skb_queue_tail(&hdev->raw_q, skb);
594c78ae283SMarcel Holtmann 		tasklet_schedule(&hdev->tx_task);
5951da177e4SLinus Torvalds 	}
5961da177e4SLinus Torvalds 
5971da177e4SLinus Torvalds 	err = len;
5981da177e4SLinus Torvalds 
5991da177e4SLinus Torvalds done:
6001da177e4SLinus Torvalds 	release_sock(sk);
6011da177e4SLinus Torvalds 	return err;
6021da177e4SLinus Torvalds 
6031da177e4SLinus Torvalds drop:
6041da177e4SLinus Torvalds 	kfree_skb(skb);
6051da177e4SLinus Torvalds 	goto done;
6061da177e4SLinus Torvalds }
6071da177e4SLinus Torvalds 
608b7058842SDavid S. Miller static int hci_sock_setsockopt(struct socket *sock, int level, int optname, char __user *optval, unsigned int len)
6091da177e4SLinus Torvalds {
6101da177e4SLinus Torvalds 	struct hci_ufilter uf = { .opcode = 0 };
6111da177e4SLinus Torvalds 	struct sock *sk = sock->sk;
6121da177e4SLinus Torvalds 	int err = 0, opt = 0;
6131da177e4SLinus Torvalds 
6141da177e4SLinus Torvalds 	BT_DBG("sk %p, opt %d", sk, optname);
6151da177e4SLinus Torvalds 
6161da177e4SLinus Torvalds 	lock_sock(sk);
6171da177e4SLinus Torvalds 
6181da177e4SLinus Torvalds 	switch (optname) {
6191da177e4SLinus Torvalds 	case HCI_DATA_DIR:
6201da177e4SLinus Torvalds 		if (get_user(opt, (int __user *)optval)) {
6211da177e4SLinus Torvalds 			err = -EFAULT;
6221da177e4SLinus Torvalds 			break;
6231da177e4SLinus Torvalds 		}
6241da177e4SLinus Torvalds 
6251da177e4SLinus Torvalds 		if (opt)
6261da177e4SLinus Torvalds 			hci_pi(sk)->cmsg_mask |= HCI_CMSG_DIR;
6271da177e4SLinus Torvalds 		else
6281da177e4SLinus Torvalds 			hci_pi(sk)->cmsg_mask &= ~HCI_CMSG_DIR;
6291da177e4SLinus Torvalds 		break;
6301da177e4SLinus Torvalds 
6311da177e4SLinus Torvalds 	case HCI_TIME_STAMP:
6321da177e4SLinus Torvalds 		if (get_user(opt, (int __user *)optval)) {
6331da177e4SLinus Torvalds 			err = -EFAULT;
6341da177e4SLinus Torvalds 			break;
6351da177e4SLinus Torvalds 		}
6361da177e4SLinus Torvalds 
6371da177e4SLinus Torvalds 		if (opt)
6381da177e4SLinus Torvalds 			hci_pi(sk)->cmsg_mask |= HCI_CMSG_TSTAMP;
6391da177e4SLinus Torvalds 		else
6401da177e4SLinus Torvalds 			hci_pi(sk)->cmsg_mask &= ~HCI_CMSG_TSTAMP;
6411da177e4SLinus Torvalds 		break;
6421da177e4SLinus Torvalds 
6431da177e4SLinus Torvalds 	case HCI_FILTER:
6440878b666SMarcel Holtmann 		{
6450878b666SMarcel Holtmann 			struct hci_filter *f = &hci_pi(sk)->filter;
6460878b666SMarcel Holtmann 
6470878b666SMarcel Holtmann 			uf.type_mask = f->type_mask;
6480878b666SMarcel Holtmann 			uf.opcode    = f->opcode;
6490878b666SMarcel Holtmann 			uf.event_mask[0] = *((u32 *) f->event_mask + 0);
6500878b666SMarcel Holtmann 			uf.event_mask[1] = *((u32 *) f->event_mask + 1);
6510878b666SMarcel Holtmann 		}
6520878b666SMarcel Holtmann 
6531da177e4SLinus Torvalds 		len = min_t(unsigned int, len, sizeof(uf));
6541da177e4SLinus Torvalds 		if (copy_from_user(&uf, optval, len)) {
6551da177e4SLinus Torvalds 			err = -EFAULT;
6561da177e4SLinus Torvalds 			break;
6571da177e4SLinus Torvalds 		}
6581da177e4SLinus Torvalds 
6591da177e4SLinus Torvalds 		if (!capable(CAP_NET_RAW)) {
6601da177e4SLinus Torvalds 			uf.type_mask &= hci_sec_filter.type_mask;
6611da177e4SLinus Torvalds 			uf.event_mask[0] &= *((u32 *) hci_sec_filter.event_mask + 0);
6621da177e4SLinus Torvalds 			uf.event_mask[1] &= *((u32 *) hci_sec_filter.event_mask + 1);
6631da177e4SLinus Torvalds 		}
6641da177e4SLinus Torvalds 
6651da177e4SLinus Torvalds 		{
6661da177e4SLinus Torvalds 			struct hci_filter *f = &hci_pi(sk)->filter;
6671da177e4SLinus Torvalds 
6681da177e4SLinus Torvalds 			f->type_mask = uf.type_mask;
6691da177e4SLinus Torvalds 			f->opcode    = uf.opcode;
6701da177e4SLinus Torvalds 			*((u32 *) f->event_mask + 0) = uf.event_mask[0];
6711da177e4SLinus Torvalds 			*((u32 *) f->event_mask + 1) = uf.event_mask[1];
6721da177e4SLinus Torvalds 		}
6731da177e4SLinus Torvalds 		break;
6741da177e4SLinus Torvalds 
6751da177e4SLinus Torvalds 	default:
6761da177e4SLinus Torvalds 		err = -ENOPROTOOPT;
6771da177e4SLinus Torvalds 		break;
6781da177e4SLinus Torvalds 	}
6791da177e4SLinus Torvalds 
6801da177e4SLinus Torvalds 	release_sock(sk);
6811da177e4SLinus Torvalds 	return err;
6821da177e4SLinus Torvalds }
6831da177e4SLinus Torvalds 
6841da177e4SLinus Torvalds static int hci_sock_getsockopt(struct socket *sock, int level, int optname, char __user *optval, int __user *optlen)
6851da177e4SLinus Torvalds {
6861da177e4SLinus Torvalds 	struct hci_ufilter uf;
6871da177e4SLinus Torvalds 	struct sock *sk = sock->sk;
6881da177e4SLinus Torvalds 	int len, opt;
6891da177e4SLinus Torvalds 
6901da177e4SLinus Torvalds 	if (get_user(len, optlen))
6911da177e4SLinus Torvalds 		return -EFAULT;
6921da177e4SLinus Torvalds 
6931da177e4SLinus Torvalds 	switch (optname) {
6941da177e4SLinus Torvalds 	case HCI_DATA_DIR:
6951da177e4SLinus Torvalds 		if (hci_pi(sk)->cmsg_mask & HCI_CMSG_DIR)
6961da177e4SLinus Torvalds 			opt = 1;
6971da177e4SLinus Torvalds 		else
6981da177e4SLinus Torvalds 			opt = 0;
6991da177e4SLinus Torvalds 
7001da177e4SLinus Torvalds 		if (put_user(opt, optval))
7011da177e4SLinus Torvalds 			return -EFAULT;
7021da177e4SLinus Torvalds 		break;
7031da177e4SLinus Torvalds 
7041da177e4SLinus Torvalds 	case HCI_TIME_STAMP:
7051da177e4SLinus Torvalds 		if (hci_pi(sk)->cmsg_mask & HCI_CMSG_TSTAMP)
7061da177e4SLinus Torvalds 			opt = 1;
7071da177e4SLinus Torvalds 		else
7081da177e4SLinus Torvalds 			opt = 0;
7091da177e4SLinus Torvalds 
7101da177e4SLinus Torvalds 		if (put_user(opt, optval))
7111da177e4SLinus Torvalds 			return -EFAULT;
7121da177e4SLinus Torvalds 		break;
7131da177e4SLinus Torvalds 
7141da177e4SLinus Torvalds 	case HCI_FILTER:
7151da177e4SLinus Torvalds 		{
7161da177e4SLinus Torvalds 			struct hci_filter *f = &hci_pi(sk)->filter;
7171da177e4SLinus Torvalds 
7181da177e4SLinus Torvalds 			uf.type_mask = f->type_mask;
7191da177e4SLinus Torvalds 			uf.opcode    = f->opcode;
7201da177e4SLinus Torvalds 			uf.event_mask[0] = *((u32 *) f->event_mask + 0);
7211da177e4SLinus Torvalds 			uf.event_mask[1] = *((u32 *) f->event_mask + 1);
7221da177e4SLinus Torvalds 		}
7231da177e4SLinus Torvalds 
7241da177e4SLinus Torvalds 		len = min_t(unsigned int, len, sizeof(uf));
7251da177e4SLinus Torvalds 		if (copy_to_user(optval, &uf, len))
7261da177e4SLinus Torvalds 			return -EFAULT;
7271da177e4SLinus Torvalds 		break;
7281da177e4SLinus Torvalds 
7291da177e4SLinus Torvalds 	default:
7301da177e4SLinus Torvalds 		return -ENOPROTOOPT;
7311da177e4SLinus Torvalds 		break;
7321da177e4SLinus Torvalds 	}
7331da177e4SLinus Torvalds 
7341da177e4SLinus Torvalds 	return 0;
7351da177e4SLinus Torvalds }
7361da177e4SLinus Torvalds 
73790ddc4f0SEric Dumazet static const struct proto_ops hci_sock_ops = {
7381da177e4SLinus Torvalds 	.family		= PF_BLUETOOTH,
7391da177e4SLinus Torvalds 	.owner		= THIS_MODULE,
7401da177e4SLinus Torvalds 	.release	= hci_sock_release,
7411da177e4SLinus Torvalds 	.bind		= hci_sock_bind,
7421da177e4SLinus Torvalds 	.getname	= hci_sock_getname,
7431da177e4SLinus Torvalds 	.sendmsg	= hci_sock_sendmsg,
7441da177e4SLinus Torvalds 	.recvmsg	= hci_sock_recvmsg,
7451da177e4SLinus Torvalds 	.ioctl		= hci_sock_ioctl,
7461da177e4SLinus Torvalds 	.poll		= datagram_poll,
7471da177e4SLinus Torvalds 	.listen		= sock_no_listen,
7481da177e4SLinus Torvalds 	.shutdown	= sock_no_shutdown,
7491da177e4SLinus Torvalds 	.setsockopt	= hci_sock_setsockopt,
7501da177e4SLinus Torvalds 	.getsockopt	= hci_sock_getsockopt,
7511da177e4SLinus Torvalds 	.connect	= sock_no_connect,
7521da177e4SLinus Torvalds 	.socketpair	= sock_no_socketpair,
7531da177e4SLinus Torvalds 	.accept		= sock_no_accept,
7541da177e4SLinus Torvalds 	.mmap		= sock_no_mmap
7551da177e4SLinus Torvalds };
7561da177e4SLinus Torvalds 
7571da177e4SLinus Torvalds static struct proto hci_sk_proto = {
7581da177e4SLinus Torvalds 	.name		= "HCI",
7591da177e4SLinus Torvalds 	.owner		= THIS_MODULE,
7601da177e4SLinus Torvalds 	.obj_size	= sizeof(struct hci_pinfo)
7611da177e4SLinus Torvalds };
7621da177e4SLinus Torvalds 
7633f378b68SEric Paris static int hci_sock_create(struct net *net, struct socket *sock, int protocol,
7643f378b68SEric Paris 			   int kern)
7651da177e4SLinus Torvalds {
7661da177e4SLinus Torvalds 	struct sock *sk;
7671da177e4SLinus Torvalds 
7681da177e4SLinus Torvalds 	BT_DBG("sock %p", sock);
7691da177e4SLinus Torvalds 
7701da177e4SLinus Torvalds 	if (sock->type != SOCK_RAW)
7711da177e4SLinus Torvalds 		return -ESOCKTNOSUPPORT;
7721da177e4SLinus Torvalds 
7731da177e4SLinus Torvalds 	sock->ops = &hci_sock_ops;
7741da177e4SLinus Torvalds 
7756257ff21SPavel Emelyanov 	sk = sk_alloc(net, PF_BLUETOOTH, GFP_ATOMIC, &hci_sk_proto);
7761da177e4SLinus Torvalds 	if (!sk)
7771da177e4SLinus Torvalds 		return -ENOMEM;
7781da177e4SLinus Torvalds 
7791da177e4SLinus Torvalds 	sock_init_data(sock, sk);
7801da177e4SLinus Torvalds 
7811da177e4SLinus Torvalds 	sock_reset_flag(sk, SOCK_ZAPPED);
7821da177e4SLinus Torvalds 
7831da177e4SLinus Torvalds 	sk->sk_protocol = protocol;
7841da177e4SLinus Torvalds 
7851da177e4SLinus Torvalds 	sock->state = SS_UNCONNECTED;
7861da177e4SLinus Torvalds 	sk->sk_state = BT_OPEN;
7871da177e4SLinus Torvalds 
7881da177e4SLinus Torvalds 	bt_sock_link(&hci_sk_list, sk);
7891da177e4SLinus Torvalds 	return 0;
7901da177e4SLinus Torvalds }
7911da177e4SLinus Torvalds 
7921da177e4SLinus Torvalds static int hci_sock_dev_event(struct notifier_block *this, unsigned long event, void *ptr)
7931da177e4SLinus Torvalds {
7941da177e4SLinus Torvalds 	struct hci_dev *hdev = (struct hci_dev *) ptr;
7951da177e4SLinus Torvalds 	struct hci_ev_si_device ev;
7961da177e4SLinus Torvalds 
7971da177e4SLinus Torvalds 	BT_DBG("hdev %s event %ld", hdev->name, event);
7981da177e4SLinus Torvalds 
7991da177e4SLinus Torvalds 	/* Send event to sockets */
8001da177e4SLinus Torvalds 	ev.event  = event;
8011da177e4SLinus Torvalds 	ev.dev_id = hdev->id;
8021da177e4SLinus Torvalds 	hci_si_event(NULL, HCI_EV_SI_DEVICE, sizeof(ev), &ev);
8031da177e4SLinus Torvalds 
8041da177e4SLinus Torvalds 	if (event == HCI_DEV_UNREG) {
8051da177e4SLinus Torvalds 		struct sock *sk;
8061da177e4SLinus Torvalds 		struct hlist_node *node;
8071da177e4SLinus Torvalds 
8081da177e4SLinus Torvalds 		/* Detach sockets from device */
8091da177e4SLinus Torvalds 		read_lock(&hci_sk_list.lock);
8101da177e4SLinus Torvalds 		sk_for_each(sk, node, &hci_sk_list.head) {
8114ce61d1cSSatyam Sharma 			local_bh_disable();
8124ce61d1cSSatyam Sharma 			bh_lock_sock_nested(sk);
8131da177e4SLinus Torvalds 			if (hci_pi(sk)->hdev == hdev) {
8141da177e4SLinus Torvalds 				hci_pi(sk)->hdev = NULL;
8151da177e4SLinus Torvalds 				sk->sk_err = EPIPE;
8161da177e4SLinus Torvalds 				sk->sk_state = BT_OPEN;
8171da177e4SLinus Torvalds 				sk->sk_state_change(sk);
8181da177e4SLinus Torvalds 
8191da177e4SLinus Torvalds 				hci_dev_put(hdev);
8201da177e4SLinus Torvalds 			}
8214ce61d1cSSatyam Sharma 			bh_unlock_sock(sk);
8224ce61d1cSSatyam Sharma 			local_bh_enable();
8231da177e4SLinus Torvalds 		}
8241da177e4SLinus Torvalds 		read_unlock(&hci_sk_list.lock);
8251da177e4SLinus Torvalds 	}
8261da177e4SLinus Torvalds 
8271da177e4SLinus Torvalds 	return NOTIFY_DONE;
8281da177e4SLinus Torvalds }
8291da177e4SLinus Torvalds 
830ec1b4cf7SStephen Hemminger static const struct net_proto_family hci_sock_family_ops = {
8311da177e4SLinus Torvalds 	.family	= PF_BLUETOOTH,
8321da177e4SLinus Torvalds 	.owner	= THIS_MODULE,
8331da177e4SLinus Torvalds 	.create	= hci_sock_create,
8341da177e4SLinus Torvalds };
8351da177e4SLinus Torvalds 
8361da177e4SLinus Torvalds static struct notifier_block hci_sock_nblock = {
8371da177e4SLinus Torvalds 	.notifier_call = hci_sock_dev_event
8381da177e4SLinus Torvalds };
8391da177e4SLinus Torvalds 
8401da177e4SLinus Torvalds int __init hci_sock_init(void)
8411da177e4SLinus Torvalds {
8421da177e4SLinus Torvalds 	int err;
8431da177e4SLinus Torvalds 
8441da177e4SLinus Torvalds 	err = proto_register(&hci_sk_proto, 0);
8451da177e4SLinus Torvalds 	if (err < 0)
8461da177e4SLinus Torvalds 		return err;
8471da177e4SLinus Torvalds 
8481da177e4SLinus Torvalds 	err = bt_sock_register(BTPROTO_HCI, &hci_sock_family_ops);
8491da177e4SLinus Torvalds 	if (err < 0)
8501da177e4SLinus Torvalds 		goto error;
8511da177e4SLinus Torvalds 
8521da177e4SLinus Torvalds 	hci_register_notifier(&hci_sock_nblock);
8531da177e4SLinus Torvalds 
8541da177e4SLinus Torvalds 	BT_INFO("HCI socket layer initialized");
8551da177e4SLinus Torvalds 
8561da177e4SLinus Torvalds 	return 0;
8571da177e4SLinus Torvalds 
8581da177e4SLinus Torvalds error:
8591da177e4SLinus Torvalds 	BT_ERR("HCI socket registration failed");
8601da177e4SLinus Torvalds 	proto_unregister(&hci_sk_proto);
8611da177e4SLinus Torvalds 	return err;
8621da177e4SLinus Torvalds }
8631da177e4SLinus Torvalds 
864*b7440a14SAnand Gadiyar void hci_sock_cleanup(void)
8651da177e4SLinus Torvalds {
8661da177e4SLinus Torvalds 	if (bt_sock_unregister(BTPROTO_HCI) < 0)
8671da177e4SLinus Torvalds 		BT_ERR("HCI socket unregistration failed");
8681da177e4SLinus Torvalds 
8691da177e4SLinus Torvalds 	hci_unregister_notifier(&hci_sock_nblock);
8701da177e4SLinus Torvalds 
8711da177e4SLinus Torvalds 	proto_unregister(&hci_sk_proto);
8721da177e4SLinus Torvalds }
8730381101fSJohan Hedberg 
8740381101fSJohan Hedberg module_param(enable_mgmt, bool, 0644);
8750381101fSJohan Hedberg MODULE_PARM_DESC(enable_mgmt, "Enable Management interface");
876