xref: /openbmc/linux/net/bluetooth/hci_sock.c (revision e0edf3733fb62f91bbb8ec3fab4a90b0ac2dd037)
11da177e4SLinus Torvalds /*
21da177e4SLinus Torvalds    BlueZ - Bluetooth protocol stack for Linux
31da177e4SLinus Torvalds    Copyright (C) 2000-2001 Qualcomm Incorporated
41da177e4SLinus Torvalds 
51da177e4SLinus Torvalds    Written 2000,2001 by Maxim Krasnyansky <maxk@qualcomm.com>
61da177e4SLinus Torvalds 
71da177e4SLinus Torvalds    This program is free software; you can redistribute it and/or modify
81da177e4SLinus Torvalds    it under the terms of the GNU General Public License version 2 as
91da177e4SLinus Torvalds    published by the Free Software Foundation;
101da177e4SLinus Torvalds 
111da177e4SLinus Torvalds    THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS
121da177e4SLinus Torvalds    OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
131da177e4SLinus Torvalds    FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT OF THIRD PARTY RIGHTS.
141da177e4SLinus Torvalds    IN NO EVENT SHALL THE COPYRIGHT HOLDER(S) AND AUTHOR(S) BE LIABLE FOR ANY
151da177e4SLinus Torvalds    CLAIM, OR ANY SPECIAL INDIRECT OR CONSEQUENTIAL DAMAGES, OR ANY DAMAGES
161da177e4SLinus Torvalds    WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
171da177e4SLinus Torvalds    ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
181da177e4SLinus Torvalds    OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
191da177e4SLinus Torvalds 
201da177e4SLinus Torvalds    ALL LIABILITY, INCLUDING LIABILITY FOR INFRINGEMENT OF ANY PATENTS,
211da177e4SLinus Torvalds    COPYRIGHTS, TRADEMARKS OR OTHER RIGHTS, RELATING TO USE OF THIS
221da177e4SLinus Torvalds    SOFTWARE IS DISCLAIMED.
231da177e4SLinus Torvalds */
241da177e4SLinus Torvalds 
251da177e4SLinus Torvalds /* Bluetooth HCI sockets. */
261da177e4SLinus Torvalds 
271da177e4SLinus Torvalds #include <linux/module.h>
281da177e4SLinus Torvalds 
291da177e4SLinus Torvalds #include <linux/types.h>
304fc268d2SRandy Dunlap #include <linux/capability.h>
311da177e4SLinus Torvalds #include <linux/errno.h>
321da177e4SLinus Torvalds #include <linux/kernel.h>
331da177e4SLinus Torvalds #include <linux/slab.h>
341da177e4SLinus Torvalds #include <linux/poll.h>
351da177e4SLinus Torvalds #include <linux/fcntl.h>
361da177e4SLinus Torvalds #include <linux/init.h>
371da177e4SLinus Torvalds #include <linux/skbuff.h>
381da177e4SLinus Torvalds #include <linux/workqueue.h>
391da177e4SLinus Torvalds #include <linux/interrupt.h>
40767c5eb5SMarcel Holtmann #include <linux/compat.h>
411da177e4SLinus Torvalds #include <linux/socket.h>
421da177e4SLinus Torvalds #include <linux/ioctl.h>
431da177e4SLinus Torvalds #include <net/sock.h>
441da177e4SLinus Torvalds 
451da177e4SLinus Torvalds #include <asm/system.h>
4670f23020SAndrei Emeltchenko #include <linux/uaccess.h>
471da177e4SLinus Torvalds #include <asm/unaligned.h>
481da177e4SLinus Torvalds 
491da177e4SLinus Torvalds #include <net/bluetooth/bluetooth.h>
501da177e4SLinus Torvalds #include <net/bluetooth/hci_core.h>
511da177e4SLinus Torvalds 
52eb939922SRusty Russell static bool enable_mgmt;
530381101fSJohan Hedberg 
541da177e4SLinus Torvalds /* ----- HCI socket interface ----- */
551da177e4SLinus Torvalds 
561da177e4SLinus Torvalds static inline int hci_test_bit(int nr, void *addr)
571da177e4SLinus Torvalds {
581da177e4SLinus Torvalds 	return *((__u32 *) addr + (nr >> 5)) & ((__u32) 1 << (nr & 31));
591da177e4SLinus Torvalds }
601da177e4SLinus Torvalds 
611da177e4SLinus Torvalds /* Security filter */
621da177e4SLinus Torvalds static struct hci_sec_filter hci_sec_filter = {
631da177e4SLinus Torvalds 	/* Packet types */
641da177e4SLinus Torvalds 	0x10,
651da177e4SLinus Torvalds 	/* Events */
66dd7f5527SMarcel Holtmann 	{ 0x1000d9fe, 0x0000b00c },
671da177e4SLinus Torvalds 	/* Commands */
681da177e4SLinus Torvalds 	{
691da177e4SLinus Torvalds 		{ 0x0 },
701da177e4SLinus Torvalds 		/* OGF_LINK_CTL */
717c631a67SMarcel Holtmann 		{ 0xbe000006, 0x00000001, 0x00000000, 0x00 },
721da177e4SLinus Torvalds 		/* OGF_LINK_POLICY */
737c631a67SMarcel Holtmann 		{ 0x00005200, 0x00000000, 0x00000000, 0x00 },
741da177e4SLinus Torvalds 		/* OGF_HOST_CTL */
757c631a67SMarcel Holtmann 		{ 0xaab00200, 0x2b402aaa, 0x05220154, 0x00 },
761da177e4SLinus Torvalds 		/* OGF_INFO_PARAM */
777c631a67SMarcel Holtmann 		{ 0x000002be, 0x00000000, 0x00000000, 0x00 },
781da177e4SLinus Torvalds 		/* OGF_STATUS_PARAM */
797c631a67SMarcel Holtmann 		{ 0x000000ea, 0x00000000, 0x00000000, 0x00 }
801da177e4SLinus Torvalds 	}
811da177e4SLinus Torvalds };
821da177e4SLinus Torvalds 
831da177e4SLinus Torvalds static struct bt_sock_list hci_sk_list = {
84d5fb2962SRobert P. J. Day 	.lock = __RW_LOCK_UNLOCKED(hci_sk_list.lock)
851da177e4SLinus Torvalds };
861da177e4SLinus Torvalds 
871da177e4SLinus Torvalds /* Send frame to RAW socket */
88470fe1b5SMarcel Holtmann void hci_send_to_sock(struct hci_dev *hdev, struct sk_buff *skb)
891da177e4SLinus Torvalds {
901da177e4SLinus Torvalds 	struct sock *sk;
911da177e4SLinus Torvalds 	struct hlist_node *node;
92*e0edf373SMarcel Holtmann 	struct sk_buff *skb_copy = NULL;
931da177e4SLinus Torvalds 
941da177e4SLinus Torvalds 	BT_DBG("hdev %p len %d", hdev, skb->len);
951da177e4SLinus Torvalds 
961da177e4SLinus Torvalds 	read_lock(&hci_sk_list.lock);
97470fe1b5SMarcel Holtmann 
981da177e4SLinus Torvalds 	sk_for_each(sk, node, &hci_sk_list.head) {
991da177e4SLinus Torvalds 		struct hci_filter *flt;
1001da177e4SLinus Torvalds 		struct sk_buff *nskb;
1011da177e4SLinus Torvalds 
1021da177e4SLinus Torvalds 		if (sk->sk_state != BT_BOUND || hci_pi(sk)->hdev != hdev)
1031da177e4SLinus Torvalds 			continue;
1041da177e4SLinus Torvalds 
1051da177e4SLinus Torvalds 		/* Don't send frame to the socket it came from */
1061da177e4SLinus Torvalds 		if (skb->sk == sk)
1071da177e4SLinus Torvalds 			continue;
1081da177e4SLinus Torvalds 
109470fe1b5SMarcel Holtmann 		if (hci_pi(sk)->channel != HCI_CHANNEL_RAW)
110a40c406cSJohan Hedberg 			continue;
111a40c406cSJohan Hedberg 
1121da177e4SLinus Torvalds 		/* Apply filter */
1131da177e4SLinus Torvalds 		flt = &hci_pi(sk)->filter;
1141da177e4SLinus Torvalds 
1150d48d939SMarcel Holtmann 		if (!test_bit((bt_cb(skb)->pkt_type == HCI_VENDOR_PKT) ?
1160d48d939SMarcel Holtmann 				0 : (bt_cb(skb)->pkt_type & HCI_FLT_TYPE_BITS), &flt->type_mask))
1171da177e4SLinus Torvalds 			continue;
1181da177e4SLinus Torvalds 
1190d48d939SMarcel Holtmann 		if (bt_cb(skb)->pkt_type == HCI_EVENT_PKT) {
1201da177e4SLinus Torvalds 			register int evt = (*(__u8 *)skb->data & HCI_FLT_EVENT_BITS);
1211da177e4SLinus Torvalds 
1221da177e4SLinus Torvalds 			if (!hci_test_bit(evt, &flt->event_mask))
1231da177e4SLinus Torvalds 				continue;
1241da177e4SLinus Torvalds 
1254498c80dSDavid S. Miller 			if (flt->opcode &&
1264498c80dSDavid S. Miller 			    ((evt == HCI_EV_CMD_COMPLETE &&
1274498c80dSDavid S. Miller 			      flt->opcode !=
128905f3ed6SAl Viro 			      get_unaligned((__le16 *)(skb->data + 3))) ||
1291da177e4SLinus Torvalds 			     (evt == HCI_EV_CMD_STATUS &&
1304498c80dSDavid S. Miller 			      flt->opcode !=
131905f3ed6SAl Viro 			      get_unaligned((__le16 *)(skb->data + 4)))))
1321da177e4SLinus Torvalds 				continue;
1331da177e4SLinus Torvalds 		}
1341da177e4SLinus Torvalds 
135*e0edf373SMarcel Holtmann 		if (!skb_copy) {
136*e0edf373SMarcel Holtmann 			/* Create a private copy with headroom */
137*e0edf373SMarcel Holtmann 			skb_copy = __pskb_copy(skb, 1, GFP_ATOMIC);
138*e0edf373SMarcel Holtmann 			if (!skb_copy)
1391da177e4SLinus Torvalds 				continue;
1401da177e4SLinus Torvalds 
1411da177e4SLinus Torvalds 			/* Put type byte before the data */
142*e0edf373SMarcel Holtmann 			memcpy(skb_push(skb_copy, 1), &bt_cb(skb)->pkt_type, 1);
143*e0edf373SMarcel Holtmann 		}
144*e0edf373SMarcel Holtmann 
145*e0edf373SMarcel Holtmann 		nskb = skb_clone(skb_copy, GFP_ATOMIC);
146*e0edf373SMarcel Holtmann 		if (!nskb)
147*e0edf373SMarcel Holtmann 			continue;
1481da177e4SLinus Torvalds 
1491da177e4SLinus Torvalds 		if (sock_queue_rcv_skb(sk, nskb))
1501da177e4SLinus Torvalds 			kfree_skb(nskb);
1511da177e4SLinus Torvalds 	}
152470fe1b5SMarcel Holtmann 
153470fe1b5SMarcel Holtmann 	read_unlock(&hci_sk_list.lock);
154*e0edf373SMarcel Holtmann 
155*e0edf373SMarcel Holtmann 	kfree_skb(skb_copy);
156470fe1b5SMarcel Holtmann }
157470fe1b5SMarcel Holtmann 
158470fe1b5SMarcel Holtmann /* Send frame to control socket */
159470fe1b5SMarcel Holtmann void hci_send_to_control(struct sk_buff *skb, struct sock *skip_sk)
160470fe1b5SMarcel Holtmann {
161470fe1b5SMarcel Holtmann 	struct sock *sk;
162470fe1b5SMarcel Holtmann 	struct hlist_node *node;
163470fe1b5SMarcel Holtmann 
164470fe1b5SMarcel Holtmann 	BT_DBG("len %d", skb->len);
165470fe1b5SMarcel Holtmann 
166470fe1b5SMarcel Holtmann 	read_lock(&hci_sk_list.lock);
167470fe1b5SMarcel Holtmann 
168470fe1b5SMarcel Holtmann 	sk_for_each(sk, node, &hci_sk_list.head) {
169470fe1b5SMarcel Holtmann 		struct sk_buff *nskb;
170470fe1b5SMarcel Holtmann 
171470fe1b5SMarcel Holtmann 		/* Skip the original socket */
172470fe1b5SMarcel Holtmann 		if (sk == skip_sk)
173470fe1b5SMarcel Holtmann 			continue;
174470fe1b5SMarcel Holtmann 
175470fe1b5SMarcel Holtmann 		if (sk->sk_state != BT_BOUND)
176470fe1b5SMarcel Holtmann 			continue;
177470fe1b5SMarcel Holtmann 
178470fe1b5SMarcel Holtmann 		if (hci_pi(sk)->channel != HCI_CHANNEL_CONTROL)
179470fe1b5SMarcel Holtmann 			continue;
180470fe1b5SMarcel Holtmann 
181470fe1b5SMarcel Holtmann 		nskb = skb_clone(skb, GFP_ATOMIC);
182470fe1b5SMarcel Holtmann 		if (!nskb)
183470fe1b5SMarcel Holtmann 			continue;
184470fe1b5SMarcel Holtmann 
185470fe1b5SMarcel Holtmann 		if (sock_queue_rcv_skb(sk, nskb))
186470fe1b5SMarcel Holtmann 			kfree_skb(nskb);
187470fe1b5SMarcel Holtmann 	}
188470fe1b5SMarcel Holtmann 
1891da177e4SLinus Torvalds 	read_unlock(&hci_sk_list.lock);
1901da177e4SLinus Torvalds }
1911da177e4SLinus Torvalds 
1921da177e4SLinus Torvalds static int hci_sock_release(struct socket *sock)
1931da177e4SLinus Torvalds {
1941da177e4SLinus Torvalds 	struct sock *sk = sock->sk;
1957b005bd3SMarcel Holtmann 	struct hci_dev *hdev;
1961da177e4SLinus Torvalds 
1971da177e4SLinus Torvalds 	BT_DBG("sock %p sk %p", sock, sk);
1981da177e4SLinus Torvalds 
1991da177e4SLinus Torvalds 	if (!sk)
2001da177e4SLinus Torvalds 		return 0;
2011da177e4SLinus Torvalds 
2027b005bd3SMarcel Holtmann 	hdev = hci_pi(sk)->hdev;
2037b005bd3SMarcel Holtmann 
2041da177e4SLinus Torvalds 	bt_sock_unlink(&hci_sk_list, sk);
2051da177e4SLinus Torvalds 
2061da177e4SLinus Torvalds 	if (hdev) {
2071da177e4SLinus Torvalds 		atomic_dec(&hdev->promisc);
2081da177e4SLinus Torvalds 		hci_dev_put(hdev);
2091da177e4SLinus Torvalds 	}
2101da177e4SLinus Torvalds 
2111da177e4SLinus Torvalds 	sock_orphan(sk);
2121da177e4SLinus Torvalds 
2131da177e4SLinus Torvalds 	skb_queue_purge(&sk->sk_receive_queue);
2141da177e4SLinus Torvalds 	skb_queue_purge(&sk->sk_write_queue);
2151da177e4SLinus Torvalds 
2161da177e4SLinus Torvalds 	sock_put(sk);
2171da177e4SLinus Torvalds 	return 0;
2181da177e4SLinus Torvalds }
2191da177e4SLinus Torvalds 
220b2a66aadSAntti Julku static int hci_sock_blacklist_add(struct hci_dev *hdev, void __user *arg)
221f0358568SJohan Hedberg {
222f0358568SJohan Hedberg 	bdaddr_t bdaddr;
2235e762444SAntti Julku 	int err;
224f0358568SJohan Hedberg 
225f0358568SJohan Hedberg 	if (copy_from_user(&bdaddr, arg, sizeof(bdaddr)))
226f0358568SJohan Hedberg 		return -EFAULT;
227f0358568SJohan Hedberg 
22809fd0de5SGustavo F. Padovan 	hci_dev_lock(hdev);
2295e762444SAntti Julku 
23088c1fe4bSJohan Hedberg 	err = hci_blacklist_add(hdev, &bdaddr, 0);
2315e762444SAntti Julku 
23209fd0de5SGustavo F. Padovan 	hci_dev_unlock(hdev);
2335e762444SAntti Julku 
2345e762444SAntti Julku 	return err;
235f0358568SJohan Hedberg }
236f0358568SJohan Hedberg 
237b2a66aadSAntti Julku static int hci_sock_blacklist_del(struct hci_dev *hdev, void __user *arg)
238f0358568SJohan Hedberg {
239f0358568SJohan Hedberg 	bdaddr_t bdaddr;
2405e762444SAntti Julku 	int err;
241f0358568SJohan Hedberg 
242f0358568SJohan Hedberg 	if (copy_from_user(&bdaddr, arg, sizeof(bdaddr)))
243f0358568SJohan Hedberg 		return -EFAULT;
244f0358568SJohan Hedberg 
24509fd0de5SGustavo F. Padovan 	hci_dev_lock(hdev);
2465e762444SAntti Julku 
24788c1fe4bSJohan Hedberg 	err = hci_blacklist_del(hdev, &bdaddr, 0);
2485e762444SAntti Julku 
24909fd0de5SGustavo F. Padovan 	hci_dev_unlock(hdev);
2505e762444SAntti Julku 
2515e762444SAntti Julku 	return err;
252f0358568SJohan Hedberg }
253f0358568SJohan Hedberg 
2541da177e4SLinus Torvalds /* Ioctls that require bound socket */
2551da177e4SLinus Torvalds static inline int hci_sock_bound_ioctl(struct sock *sk, unsigned int cmd, unsigned long arg)
2561da177e4SLinus Torvalds {
2571da177e4SLinus Torvalds 	struct hci_dev *hdev = hci_pi(sk)->hdev;
2581da177e4SLinus Torvalds 
2591da177e4SLinus Torvalds 	if (!hdev)
2601da177e4SLinus Torvalds 		return -EBADFD;
2611da177e4SLinus Torvalds 
2621da177e4SLinus Torvalds 	switch (cmd) {
2631da177e4SLinus Torvalds 	case HCISETRAW:
2641da177e4SLinus Torvalds 		if (!capable(CAP_NET_ADMIN))
2651da177e4SLinus Torvalds 			return -EACCES;
2661da177e4SLinus Torvalds 
2671da177e4SLinus Torvalds 		if (test_bit(HCI_QUIRK_RAW_DEVICE, &hdev->quirks))
2681da177e4SLinus Torvalds 			return -EPERM;
2691da177e4SLinus Torvalds 
2701da177e4SLinus Torvalds 		if (arg)
2711da177e4SLinus Torvalds 			set_bit(HCI_RAW, &hdev->flags);
2721da177e4SLinus Torvalds 		else
2731da177e4SLinus Torvalds 			clear_bit(HCI_RAW, &hdev->flags);
2741da177e4SLinus Torvalds 
2751da177e4SLinus Torvalds 		return 0;
2761da177e4SLinus Torvalds 
2771da177e4SLinus Torvalds 	case HCIGETCONNINFO:
2781da177e4SLinus Torvalds 		return hci_get_conn_info(hdev, (void __user *) arg);
2791da177e4SLinus Torvalds 
28040be492fSMarcel Holtmann 	case HCIGETAUTHINFO:
28140be492fSMarcel Holtmann 		return hci_get_auth_info(hdev, (void __user *) arg);
28240be492fSMarcel Holtmann 
283f0358568SJohan Hedberg 	case HCIBLOCKADDR:
284f0358568SJohan Hedberg 		if (!capable(CAP_NET_ADMIN))
285f0358568SJohan Hedberg 			return -EACCES;
286b2a66aadSAntti Julku 		return hci_sock_blacklist_add(hdev, (void __user *) arg);
287f0358568SJohan Hedberg 
288f0358568SJohan Hedberg 	case HCIUNBLOCKADDR:
289f0358568SJohan Hedberg 		if (!capable(CAP_NET_ADMIN))
290f0358568SJohan Hedberg 			return -EACCES;
291b2a66aadSAntti Julku 		return hci_sock_blacklist_del(hdev, (void __user *) arg);
292f0358568SJohan Hedberg 
2931da177e4SLinus Torvalds 	default:
2941da177e4SLinus Torvalds 		if (hdev->ioctl)
2951da177e4SLinus Torvalds 			return hdev->ioctl(hdev, cmd, arg);
2961da177e4SLinus Torvalds 		return -EINVAL;
2971da177e4SLinus Torvalds 	}
2981da177e4SLinus Torvalds }
2991da177e4SLinus Torvalds 
3001da177e4SLinus Torvalds static int hci_sock_ioctl(struct socket *sock, unsigned int cmd, unsigned long arg)
3011da177e4SLinus Torvalds {
3021da177e4SLinus Torvalds 	struct sock *sk = sock->sk;
3031da177e4SLinus Torvalds 	void __user *argp = (void __user *) arg;
3041da177e4SLinus Torvalds 	int err;
3051da177e4SLinus Torvalds 
3061da177e4SLinus Torvalds 	BT_DBG("cmd %x arg %lx", cmd, arg);
3071da177e4SLinus Torvalds 
3081da177e4SLinus Torvalds 	switch (cmd) {
3091da177e4SLinus Torvalds 	case HCIGETDEVLIST:
3101da177e4SLinus Torvalds 		return hci_get_dev_list(argp);
3111da177e4SLinus Torvalds 
3121da177e4SLinus Torvalds 	case HCIGETDEVINFO:
3131da177e4SLinus Torvalds 		return hci_get_dev_info(argp);
3141da177e4SLinus Torvalds 
3151da177e4SLinus Torvalds 	case HCIGETCONNLIST:
3161da177e4SLinus Torvalds 		return hci_get_conn_list(argp);
3171da177e4SLinus Torvalds 
3181da177e4SLinus Torvalds 	case HCIDEVUP:
3191da177e4SLinus Torvalds 		if (!capable(CAP_NET_ADMIN))
3201da177e4SLinus Torvalds 			return -EACCES;
3211da177e4SLinus Torvalds 		return hci_dev_open(arg);
3221da177e4SLinus Torvalds 
3231da177e4SLinus Torvalds 	case HCIDEVDOWN:
3241da177e4SLinus Torvalds 		if (!capable(CAP_NET_ADMIN))
3251da177e4SLinus Torvalds 			return -EACCES;
3261da177e4SLinus Torvalds 		return hci_dev_close(arg);
3271da177e4SLinus Torvalds 
3281da177e4SLinus Torvalds 	case HCIDEVRESET:
3291da177e4SLinus Torvalds 		if (!capable(CAP_NET_ADMIN))
3301da177e4SLinus Torvalds 			return -EACCES;
3311da177e4SLinus Torvalds 		return hci_dev_reset(arg);
3321da177e4SLinus Torvalds 
3331da177e4SLinus Torvalds 	case HCIDEVRESTAT:
3341da177e4SLinus Torvalds 		if (!capable(CAP_NET_ADMIN))
3351da177e4SLinus Torvalds 			return -EACCES;
3361da177e4SLinus Torvalds 		return hci_dev_reset_stat(arg);
3371da177e4SLinus Torvalds 
3381da177e4SLinus Torvalds 	case HCISETSCAN:
3391da177e4SLinus Torvalds 	case HCISETAUTH:
3401da177e4SLinus Torvalds 	case HCISETENCRYPT:
3411da177e4SLinus Torvalds 	case HCISETPTYPE:
3421da177e4SLinus Torvalds 	case HCISETLINKPOL:
3431da177e4SLinus Torvalds 	case HCISETLINKMODE:
3441da177e4SLinus Torvalds 	case HCISETACLMTU:
3451da177e4SLinus Torvalds 	case HCISETSCOMTU:
3461da177e4SLinus Torvalds 		if (!capable(CAP_NET_ADMIN))
3471da177e4SLinus Torvalds 			return -EACCES;
3481da177e4SLinus Torvalds 		return hci_dev_cmd(cmd, argp);
3491da177e4SLinus Torvalds 
3501da177e4SLinus Torvalds 	case HCIINQUIRY:
3511da177e4SLinus Torvalds 		return hci_inquiry(argp);
3521da177e4SLinus Torvalds 
3531da177e4SLinus Torvalds 	default:
3541da177e4SLinus Torvalds 		lock_sock(sk);
3551da177e4SLinus Torvalds 		err = hci_sock_bound_ioctl(sk, cmd, arg);
3561da177e4SLinus Torvalds 		release_sock(sk);
3571da177e4SLinus Torvalds 		return err;
3581da177e4SLinus Torvalds 	}
3591da177e4SLinus Torvalds }
3601da177e4SLinus Torvalds 
3611da177e4SLinus Torvalds static int hci_sock_bind(struct socket *sock, struct sockaddr *addr, int addr_len)
3621da177e4SLinus Torvalds {
3630381101fSJohan Hedberg 	struct sockaddr_hci haddr;
3641da177e4SLinus Torvalds 	struct sock *sk = sock->sk;
3651da177e4SLinus Torvalds 	struct hci_dev *hdev = NULL;
3660381101fSJohan Hedberg 	int len, err = 0;
3671da177e4SLinus Torvalds 
3681da177e4SLinus Torvalds 	BT_DBG("sock %p sk %p", sock, sk);
3691da177e4SLinus Torvalds 
3700381101fSJohan Hedberg 	if (!addr)
3710381101fSJohan Hedberg 		return -EINVAL;
3720381101fSJohan Hedberg 
3730381101fSJohan Hedberg 	memset(&haddr, 0, sizeof(haddr));
3740381101fSJohan Hedberg 	len = min_t(unsigned int, sizeof(haddr), addr_len);
3750381101fSJohan Hedberg 	memcpy(&haddr, addr, len);
3760381101fSJohan Hedberg 
3770381101fSJohan Hedberg 	if (haddr.hci_family != AF_BLUETOOTH)
3780381101fSJohan Hedberg 		return -EINVAL;
3790381101fSJohan Hedberg 
3801da177e4SLinus Torvalds 	lock_sock(sk);
3811da177e4SLinus Torvalds 
3827cc2ade2SMarcel Holtmann 	if (sk->sk_state == BT_BOUND) {
3837cc2ade2SMarcel Holtmann 		err = -EALREADY;
3847cc2ade2SMarcel Holtmann 		goto done;
3857cc2ade2SMarcel Holtmann 	}
3867cc2ade2SMarcel Holtmann 
3877cc2ade2SMarcel Holtmann 	switch (haddr.hci_channel) {
3887cc2ade2SMarcel Holtmann 	case HCI_CHANNEL_RAW:
3897cc2ade2SMarcel Holtmann 		if (hci_pi(sk)->hdev) {
3901da177e4SLinus Torvalds 			err = -EALREADY;
3911da177e4SLinus Torvalds 			goto done;
3921da177e4SLinus Torvalds 		}
3931da177e4SLinus Torvalds 
3940381101fSJohan Hedberg 		if (haddr.hci_dev != HCI_DEV_NONE) {
3950381101fSJohan Hedberg 			hdev = hci_dev_get(haddr.hci_dev);
39670f23020SAndrei Emeltchenko 			if (!hdev) {
3971da177e4SLinus Torvalds 				err = -ENODEV;
3981da177e4SLinus Torvalds 				goto done;
3991da177e4SLinus Torvalds 			}
4001da177e4SLinus Torvalds 
4011da177e4SLinus Torvalds 			atomic_inc(&hdev->promisc);
4021da177e4SLinus Torvalds 		}
4031da177e4SLinus Torvalds 
4041da177e4SLinus Torvalds 		hci_pi(sk)->hdev = hdev;
4057cc2ade2SMarcel Holtmann 		break;
4067cc2ade2SMarcel Holtmann 
4077cc2ade2SMarcel Holtmann 	case HCI_CHANNEL_CONTROL:
4087cc2ade2SMarcel Holtmann 		if (haddr.hci_dev != HCI_DEV_NONE || !enable_mgmt) {
4097cc2ade2SMarcel Holtmann 			err = -EINVAL;
4107cc2ade2SMarcel Holtmann 			goto done;
4117cc2ade2SMarcel Holtmann 		}
4127cc2ade2SMarcel Holtmann 
4137cc2ade2SMarcel Holtmann 		set_bit(HCI_PI_MGMT_INIT, &hci_pi(sk)->flags);
4147cc2ade2SMarcel Holtmann 		break;
4157cc2ade2SMarcel Holtmann 
4167cc2ade2SMarcel Holtmann 	default:
4177cc2ade2SMarcel Holtmann 		err = -EINVAL;
4187cc2ade2SMarcel Holtmann 		goto done;
4197cc2ade2SMarcel Holtmann 	}
4207cc2ade2SMarcel Holtmann 
4217cc2ade2SMarcel Holtmann 
4227cc2ade2SMarcel Holtmann 	hci_pi(sk)->channel = haddr.hci_channel;
4231da177e4SLinus Torvalds 	sk->sk_state = BT_BOUND;
4241da177e4SLinus Torvalds 
4251da177e4SLinus Torvalds done:
4261da177e4SLinus Torvalds 	release_sock(sk);
4271da177e4SLinus Torvalds 	return err;
4281da177e4SLinus Torvalds }
4291da177e4SLinus Torvalds 
4301da177e4SLinus Torvalds static int hci_sock_getname(struct socket *sock, struct sockaddr *addr, int *addr_len, int peer)
4311da177e4SLinus Torvalds {
4321da177e4SLinus Torvalds 	struct sockaddr_hci *haddr = (struct sockaddr_hci *) addr;
4331da177e4SLinus Torvalds 	struct sock *sk = sock->sk;
4347b005bd3SMarcel Holtmann 	struct hci_dev *hdev = hci_pi(sk)->hdev;
4351da177e4SLinus Torvalds 
4361da177e4SLinus Torvalds 	BT_DBG("sock %p sk %p", sock, sk);
4371da177e4SLinus Torvalds 
4387b005bd3SMarcel Holtmann 	if (!hdev)
4397b005bd3SMarcel Holtmann 		return -EBADFD;
4407b005bd3SMarcel Holtmann 
4411da177e4SLinus Torvalds 	lock_sock(sk);
4421da177e4SLinus Torvalds 
4431da177e4SLinus Torvalds 	*addr_len = sizeof(*haddr);
4441da177e4SLinus Torvalds 	haddr->hci_family = AF_BLUETOOTH;
4457b005bd3SMarcel Holtmann 	haddr->hci_dev    = hdev->id;
4461da177e4SLinus Torvalds 
4471da177e4SLinus Torvalds 	release_sock(sk);
4481da177e4SLinus Torvalds 	return 0;
4491da177e4SLinus Torvalds }
4501da177e4SLinus Torvalds 
4511da177e4SLinus Torvalds static inline void hci_sock_cmsg(struct sock *sk, struct msghdr *msg, struct sk_buff *skb)
4521da177e4SLinus Torvalds {
4531da177e4SLinus Torvalds 	__u32 mask = hci_pi(sk)->cmsg_mask;
4541da177e4SLinus Torvalds 
4550d48d939SMarcel Holtmann 	if (mask & HCI_CMSG_DIR) {
4560d48d939SMarcel Holtmann 		int incoming = bt_cb(skb)->incoming;
4570d48d939SMarcel Holtmann 		put_cmsg(msg, SOL_HCI, HCI_CMSG_DIR, sizeof(incoming), &incoming);
4580d48d939SMarcel Holtmann 	}
4591da177e4SLinus Torvalds 
460a61bbcf2SPatrick McHardy 	if (mask & HCI_CMSG_TSTAMP) {
461f6e623a6SJohann Felix Soden #ifdef CONFIG_COMPAT
462f6e623a6SJohann Felix Soden 		struct compat_timeval ctv;
463f6e623a6SJohann Felix Soden #endif
464a61bbcf2SPatrick McHardy 		struct timeval tv;
465767c5eb5SMarcel Holtmann 		void *data;
466767c5eb5SMarcel Holtmann 		int len;
467a61bbcf2SPatrick McHardy 
468a61bbcf2SPatrick McHardy 		skb_get_timestamp(skb, &tv);
469767c5eb5SMarcel Holtmann 
4701da97f83SDavid S. Miller 		data = &tv;
4711da97f83SDavid S. Miller 		len = sizeof(tv);
4721da97f83SDavid S. Miller #ifdef CONFIG_COMPAT
473767c5eb5SMarcel Holtmann 		if (msg->msg_flags & MSG_CMSG_COMPAT) {
474767c5eb5SMarcel Holtmann 			ctv.tv_sec = tv.tv_sec;
475767c5eb5SMarcel Holtmann 			ctv.tv_usec = tv.tv_usec;
476767c5eb5SMarcel Holtmann 			data = &ctv;
477767c5eb5SMarcel Holtmann 			len = sizeof(ctv);
478767c5eb5SMarcel Holtmann 		}
4791da97f83SDavid S. Miller #endif
480767c5eb5SMarcel Holtmann 
481767c5eb5SMarcel Holtmann 		put_cmsg(msg, SOL_HCI, HCI_CMSG_TSTAMP, len, data);
482a61bbcf2SPatrick McHardy 	}
4831da177e4SLinus Torvalds }
4841da177e4SLinus Torvalds 
4851da177e4SLinus Torvalds static int hci_sock_recvmsg(struct kiocb *iocb, struct socket *sock,
4861da177e4SLinus Torvalds 				struct msghdr *msg, size_t len, int flags)
4871da177e4SLinus Torvalds {
4881da177e4SLinus Torvalds 	int noblock = flags & MSG_DONTWAIT;
4891da177e4SLinus Torvalds 	struct sock *sk = sock->sk;
4901da177e4SLinus Torvalds 	struct sk_buff *skb;
4911da177e4SLinus Torvalds 	int copied, err;
4921da177e4SLinus Torvalds 
4931da177e4SLinus Torvalds 	BT_DBG("sock %p, sk %p", sock, sk);
4941da177e4SLinus Torvalds 
4951da177e4SLinus Torvalds 	if (flags & (MSG_OOB))
4961da177e4SLinus Torvalds 		return -EOPNOTSUPP;
4971da177e4SLinus Torvalds 
4981da177e4SLinus Torvalds 	if (sk->sk_state == BT_CLOSED)
4991da177e4SLinus Torvalds 		return 0;
5001da177e4SLinus Torvalds 
50170f23020SAndrei Emeltchenko 	skb = skb_recv_datagram(sk, flags, noblock, &err);
50270f23020SAndrei Emeltchenko 	if (!skb)
5031da177e4SLinus Torvalds 		return err;
5041da177e4SLinus Torvalds 
5051da177e4SLinus Torvalds 	msg->msg_namelen = 0;
5061da177e4SLinus Torvalds 
5071da177e4SLinus Torvalds 	copied = skb->len;
5081da177e4SLinus Torvalds 	if (len < copied) {
5091da177e4SLinus Torvalds 		msg->msg_flags |= MSG_TRUNC;
5101da177e4SLinus Torvalds 		copied = len;
5111da177e4SLinus Torvalds 	}
5121da177e4SLinus Torvalds 
513badff6d0SArnaldo Carvalho de Melo 	skb_reset_transport_header(skb);
5141da177e4SLinus Torvalds 	err = skb_copy_datagram_iovec(skb, 0, msg->msg_iov, copied);
5151da177e4SLinus Torvalds 
5163a208627SMarcel Holtmann 	switch (hci_pi(sk)->channel) {
5173a208627SMarcel Holtmann 	case HCI_CHANNEL_RAW:
5181da177e4SLinus Torvalds 		hci_sock_cmsg(sk, msg, skb);
5193a208627SMarcel Holtmann 		break;
5203a208627SMarcel Holtmann 	}
5211da177e4SLinus Torvalds 
5221da177e4SLinus Torvalds 	skb_free_datagram(sk, skb);
5231da177e4SLinus Torvalds 
5241da177e4SLinus Torvalds 	return err ? : copied;
5251da177e4SLinus Torvalds }
5261da177e4SLinus Torvalds 
5271da177e4SLinus Torvalds static int hci_sock_sendmsg(struct kiocb *iocb, struct socket *sock,
5281da177e4SLinus Torvalds 			    struct msghdr *msg, size_t len)
5291da177e4SLinus Torvalds {
5301da177e4SLinus Torvalds 	struct sock *sk = sock->sk;
5311da177e4SLinus Torvalds 	struct hci_dev *hdev;
5321da177e4SLinus Torvalds 	struct sk_buff *skb;
5331da177e4SLinus Torvalds 	int err;
5341da177e4SLinus Torvalds 
5351da177e4SLinus Torvalds 	BT_DBG("sock %p sk %p", sock, sk);
5361da177e4SLinus Torvalds 
5371da177e4SLinus Torvalds 	if (msg->msg_flags & MSG_OOB)
5381da177e4SLinus Torvalds 		return -EOPNOTSUPP;
5391da177e4SLinus Torvalds 
5401da177e4SLinus Torvalds 	if (msg->msg_flags & ~(MSG_DONTWAIT|MSG_NOSIGNAL|MSG_ERRQUEUE))
5411da177e4SLinus Torvalds 		return -EINVAL;
5421da177e4SLinus Torvalds 
5431da177e4SLinus Torvalds 	if (len < 4 || len > HCI_MAX_FRAME_SIZE)
5441da177e4SLinus Torvalds 		return -EINVAL;
5451da177e4SLinus Torvalds 
5461da177e4SLinus Torvalds 	lock_sock(sk);
5471da177e4SLinus Torvalds 
5480381101fSJohan Hedberg 	switch (hci_pi(sk)->channel) {
5490381101fSJohan Hedberg 	case HCI_CHANNEL_RAW:
5500381101fSJohan Hedberg 		break;
5510381101fSJohan Hedberg 	case HCI_CHANNEL_CONTROL:
5520381101fSJohan Hedberg 		err = mgmt_control(sk, msg, len);
5530381101fSJohan Hedberg 		goto done;
5540381101fSJohan Hedberg 	default:
5550381101fSJohan Hedberg 		err = -EINVAL;
5560381101fSJohan Hedberg 		goto done;
5570381101fSJohan Hedberg 	}
5580381101fSJohan Hedberg 
55970f23020SAndrei Emeltchenko 	hdev = hci_pi(sk)->hdev;
56070f23020SAndrei Emeltchenko 	if (!hdev) {
5611da177e4SLinus Torvalds 		err = -EBADFD;
5621da177e4SLinus Torvalds 		goto done;
5631da177e4SLinus Torvalds 	}
5641da177e4SLinus Torvalds 
5657e21addcSMarcel Holtmann 	if (!test_bit(HCI_UP, &hdev->flags)) {
5667e21addcSMarcel Holtmann 		err = -ENETDOWN;
5677e21addcSMarcel Holtmann 		goto done;
5687e21addcSMarcel Holtmann 	}
5697e21addcSMarcel Holtmann 
57070f23020SAndrei Emeltchenko 	skb = bt_skb_send_alloc(sk, len, msg->msg_flags & MSG_DONTWAIT, &err);
57170f23020SAndrei Emeltchenko 	if (!skb)
5721da177e4SLinus Torvalds 		goto done;
5731da177e4SLinus Torvalds 
5741da177e4SLinus Torvalds 	if (memcpy_fromiovec(skb_put(skb, len), msg->msg_iov, len)) {
5751da177e4SLinus Torvalds 		err = -EFAULT;
5761da177e4SLinus Torvalds 		goto drop;
5771da177e4SLinus Torvalds 	}
5781da177e4SLinus Torvalds 
5790d48d939SMarcel Holtmann 	bt_cb(skb)->pkt_type = *((unsigned char *) skb->data);
5801da177e4SLinus Torvalds 	skb_pull(skb, 1);
5811da177e4SLinus Torvalds 	skb->dev = (void *) hdev;
5821da177e4SLinus Torvalds 
5830d48d939SMarcel Holtmann 	if (bt_cb(skb)->pkt_type == HCI_COMMAND_PKT) {
58483985319SHarvey Harrison 		u16 opcode = get_unaligned_le16(skb->data);
5851da177e4SLinus Torvalds 		u16 ogf = hci_opcode_ogf(opcode);
5861da177e4SLinus Torvalds 		u16 ocf = hci_opcode_ocf(opcode);
5871da177e4SLinus Torvalds 
5881da177e4SLinus Torvalds 		if (((ogf > HCI_SFLT_MAX_OGF) ||
5891da177e4SLinus Torvalds 				!hci_test_bit(ocf & HCI_FLT_OCF_BITS, &hci_sec_filter.ocf_mask[ogf])) &&
5901da177e4SLinus Torvalds 					!capable(CAP_NET_RAW)) {
5911da177e4SLinus Torvalds 			err = -EPERM;
5921da177e4SLinus Torvalds 			goto drop;
5931da177e4SLinus Torvalds 		}
5941da177e4SLinus Torvalds 
595a9de9248SMarcel Holtmann 		if (test_bit(HCI_RAW, &hdev->flags) || (ogf == 0x3f)) {
5961da177e4SLinus Torvalds 			skb_queue_tail(&hdev->raw_q, skb);
5973eff45eaSGustavo F. Padovan 			queue_work(hdev->workqueue, &hdev->tx_work);
5981da177e4SLinus Torvalds 		} else {
5991da177e4SLinus Torvalds 			skb_queue_tail(&hdev->cmd_q, skb);
600c347b765SGustavo F. Padovan 			queue_work(hdev->workqueue, &hdev->cmd_work);
6011da177e4SLinus Torvalds 		}
6021da177e4SLinus Torvalds 	} else {
6031da177e4SLinus Torvalds 		if (!capable(CAP_NET_RAW)) {
6041da177e4SLinus Torvalds 			err = -EPERM;
6051da177e4SLinus Torvalds 			goto drop;
6061da177e4SLinus Torvalds 		}
6071da177e4SLinus Torvalds 
6081da177e4SLinus Torvalds 		skb_queue_tail(&hdev->raw_q, skb);
6093eff45eaSGustavo F. Padovan 		queue_work(hdev->workqueue, &hdev->tx_work);
6101da177e4SLinus Torvalds 	}
6111da177e4SLinus Torvalds 
6121da177e4SLinus Torvalds 	err = len;
6131da177e4SLinus Torvalds 
6141da177e4SLinus Torvalds done:
6151da177e4SLinus Torvalds 	release_sock(sk);
6161da177e4SLinus Torvalds 	return err;
6171da177e4SLinus Torvalds 
6181da177e4SLinus Torvalds drop:
6191da177e4SLinus Torvalds 	kfree_skb(skb);
6201da177e4SLinus Torvalds 	goto done;
6211da177e4SLinus Torvalds }
6221da177e4SLinus Torvalds 
623b7058842SDavid S. Miller static int hci_sock_setsockopt(struct socket *sock, int level, int optname, char __user *optval, unsigned int len)
6241da177e4SLinus Torvalds {
6251da177e4SLinus Torvalds 	struct hci_ufilter uf = { .opcode = 0 };
6261da177e4SLinus Torvalds 	struct sock *sk = sock->sk;
6271da177e4SLinus Torvalds 	int err = 0, opt = 0;
6281da177e4SLinus Torvalds 
6291da177e4SLinus Torvalds 	BT_DBG("sk %p, opt %d", sk, optname);
6301da177e4SLinus Torvalds 
6311da177e4SLinus Torvalds 	lock_sock(sk);
6321da177e4SLinus Torvalds 
6332f39cdb7SMarcel Holtmann 	if (hci_pi(sk)->channel != HCI_CHANNEL_RAW) {
6342f39cdb7SMarcel Holtmann 		err = -EINVAL;
6352f39cdb7SMarcel Holtmann 		goto done;
6362f39cdb7SMarcel Holtmann 	}
6372f39cdb7SMarcel Holtmann 
6381da177e4SLinus Torvalds 	switch (optname) {
6391da177e4SLinus Torvalds 	case HCI_DATA_DIR:
6401da177e4SLinus Torvalds 		if (get_user(opt, (int __user *)optval)) {
6411da177e4SLinus Torvalds 			err = -EFAULT;
6421da177e4SLinus Torvalds 			break;
6431da177e4SLinus Torvalds 		}
6441da177e4SLinus Torvalds 
6451da177e4SLinus Torvalds 		if (opt)
6461da177e4SLinus Torvalds 			hci_pi(sk)->cmsg_mask |= HCI_CMSG_DIR;
6471da177e4SLinus Torvalds 		else
6481da177e4SLinus Torvalds 			hci_pi(sk)->cmsg_mask &= ~HCI_CMSG_DIR;
6491da177e4SLinus Torvalds 		break;
6501da177e4SLinus Torvalds 
6511da177e4SLinus Torvalds 	case HCI_TIME_STAMP:
6521da177e4SLinus Torvalds 		if (get_user(opt, (int __user *)optval)) {
6531da177e4SLinus Torvalds 			err = -EFAULT;
6541da177e4SLinus Torvalds 			break;
6551da177e4SLinus Torvalds 		}
6561da177e4SLinus Torvalds 
6571da177e4SLinus Torvalds 		if (opt)
6581da177e4SLinus Torvalds 			hci_pi(sk)->cmsg_mask |= HCI_CMSG_TSTAMP;
6591da177e4SLinus Torvalds 		else
6601da177e4SLinus Torvalds 			hci_pi(sk)->cmsg_mask &= ~HCI_CMSG_TSTAMP;
6611da177e4SLinus Torvalds 		break;
6621da177e4SLinus Torvalds 
6631da177e4SLinus Torvalds 	case HCI_FILTER:
6640878b666SMarcel Holtmann 		{
6650878b666SMarcel Holtmann 			struct hci_filter *f = &hci_pi(sk)->filter;
6660878b666SMarcel Holtmann 
6670878b666SMarcel Holtmann 			uf.type_mask = f->type_mask;
6680878b666SMarcel Holtmann 			uf.opcode    = f->opcode;
6690878b666SMarcel Holtmann 			uf.event_mask[0] = *((u32 *) f->event_mask + 0);
6700878b666SMarcel Holtmann 			uf.event_mask[1] = *((u32 *) f->event_mask + 1);
6710878b666SMarcel Holtmann 		}
6720878b666SMarcel Holtmann 
6731da177e4SLinus Torvalds 		len = min_t(unsigned int, len, sizeof(uf));
6741da177e4SLinus Torvalds 		if (copy_from_user(&uf, optval, len)) {
6751da177e4SLinus Torvalds 			err = -EFAULT;
6761da177e4SLinus Torvalds 			break;
6771da177e4SLinus Torvalds 		}
6781da177e4SLinus Torvalds 
6791da177e4SLinus Torvalds 		if (!capable(CAP_NET_RAW)) {
6801da177e4SLinus Torvalds 			uf.type_mask &= hci_sec_filter.type_mask;
6811da177e4SLinus Torvalds 			uf.event_mask[0] &= *((u32 *) hci_sec_filter.event_mask + 0);
6821da177e4SLinus Torvalds 			uf.event_mask[1] &= *((u32 *) hci_sec_filter.event_mask + 1);
6831da177e4SLinus Torvalds 		}
6841da177e4SLinus Torvalds 
6851da177e4SLinus Torvalds 		{
6861da177e4SLinus Torvalds 			struct hci_filter *f = &hci_pi(sk)->filter;
6871da177e4SLinus Torvalds 
6881da177e4SLinus Torvalds 			f->type_mask = uf.type_mask;
6891da177e4SLinus Torvalds 			f->opcode    = uf.opcode;
6901da177e4SLinus Torvalds 			*((u32 *) f->event_mask + 0) = uf.event_mask[0];
6911da177e4SLinus Torvalds 			*((u32 *) f->event_mask + 1) = uf.event_mask[1];
6921da177e4SLinus Torvalds 		}
6931da177e4SLinus Torvalds 		break;
6941da177e4SLinus Torvalds 
6951da177e4SLinus Torvalds 	default:
6961da177e4SLinus Torvalds 		err = -ENOPROTOOPT;
6971da177e4SLinus Torvalds 		break;
6981da177e4SLinus Torvalds 	}
6991da177e4SLinus Torvalds 
7002f39cdb7SMarcel Holtmann done:
7011da177e4SLinus Torvalds 	release_sock(sk);
7021da177e4SLinus Torvalds 	return err;
7031da177e4SLinus Torvalds }
7041da177e4SLinus Torvalds 
7051da177e4SLinus Torvalds static int hci_sock_getsockopt(struct socket *sock, int level, int optname, char __user *optval, int __user *optlen)
7061da177e4SLinus Torvalds {
7071da177e4SLinus Torvalds 	struct hci_ufilter uf;
7081da177e4SLinus Torvalds 	struct sock *sk = sock->sk;
709cedc5469SMarcel Holtmann 	int len, opt, err = 0;
710cedc5469SMarcel Holtmann 
711cedc5469SMarcel Holtmann 	BT_DBG("sk %p, opt %d", sk, optname);
7121da177e4SLinus Torvalds 
7131da177e4SLinus Torvalds 	if (get_user(len, optlen))
7141da177e4SLinus Torvalds 		return -EFAULT;
7151da177e4SLinus Torvalds 
716cedc5469SMarcel Holtmann 	lock_sock(sk);
717cedc5469SMarcel Holtmann 
718cedc5469SMarcel Holtmann 	if (hci_pi(sk)->channel != HCI_CHANNEL_RAW) {
719cedc5469SMarcel Holtmann 		err = -EINVAL;
720cedc5469SMarcel Holtmann 		goto done;
721cedc5469SMarcel Holtmann 	}
722cedc5469SMarcel Holtmann 
7231da177e4SLinus Torvalds 	switch (optname) {
7241da177e4SLinus Torvalds 	case HCI_DATA_DIR:
7251da177e4SLinus Torvalds 		if (hci_pi(sk)->cmsg_mask & HCI_CMSG_DIR)
7261da177e4SLinus Torvalds 			opt = 1;
7271da177e4SLinus Torvalds 		else
7281da177e4SLinus Torvalds 			opt = 0;
7291da177e4SLinus Torvalds 
7301da177e4SLinus Torvalds 		if (put_user(opt, optval))
731cedc5469SMarcel Holtmann 			err = -EFAULT;
7321da177e4SLinus Torvalds 		break;
7331da177e4SLinus Torvalds 
7341da177e4SLinus Torvalds 	case HCI_TIME_STAMP:
7351da177e4SLinus Torvalds 		if (hci_pi(sk)->cmsg_mask & HCI_CMSG_TSTAMP)
7361da177e4SLinus Torvalds 			opt = 1;
7371da177e4SLinus Torvalds 		else
7381da177e4SLinus Torvalds 			opt = 0;
7391da177e4SLinus Torvalds 
7401da177e4SLinus Torvalds 		if (put_user(opt, optval))
741cedc5469SMarcel Holtmann 			err = -EFAULT;
7421da177e4SLinus Torvalds 		break;
7431da177e4SLinus Torvalds 
7441da177e4SLinus Torvalds 	case HCI_FILTER:
7451da177e4SLinus Torvalds 		{
7461da177e4SLinus Torvalds 			struct hci_filter *f = &hci_pi(sk)->filter;
7471da177e4SLinus Torvalds 
7481da177e4SLinus Torvalds 			uf.type_mask = f->type_mask;
7491da177e4SLinus Torvalds 			uf.opcode    = f->opcode;
7501da177e4SLinus Torvalds 			uf.event_mask[0] = *((u32 *) f->event_mask + 0);
7511da177e4SLinus Torvalds 			uf.event_mask[1] = *((u32 *) f->event_mask + 1);
7521da177e4SLinus Torvalds 		}
7531da177e4SLinus Torvalds 
7541da177e4SLinus Torvalds 		len = min_t(unsigned int, len, sizeof(uf));
7551da177e4SLinus Torvalds 		if (copy_to_user(optval, &uf, len))
756cedc5469SMarcel Holtmann 			err = -EFAULT;
7571da177e4SLinus Torvalds 		break;
7581da177e4SLinus Torvalds 
7591da177e4SLinus Torvalds 	default:
760cedc5469SMarcel Holtmann 		err = -ENOPROTOOPT;
7611da177e4SLinus Torvalds 		break;
7621da177e4SLinus Torvalds 	}
7631da177e4SLinus Torvalds 
764cedc5469SMarcel Holtmann done:
765cedc5469SMarcel Holtmann 	release_sock(sk);
766cedc5469SMarcel Holtmann 	return err;
7671da177e4SLinus Torvalds }
7681da177e4SLinus Torvalds 
76990ddc4f0SEric Dumazet static const struct proto_ops hci_sock_ops = {
7701da177e4SLinus Torvalds 	.family		= PF_BLUETOOTH,
7711da177e4SLinus Torvalds 	.owner		= THIS_MODULE,
7721da177e4SLinus Torvalds 	.release	= hci_sock_release,
7731da177e4SLinus Torvalds 	.bind		= hci_sock_bind,
7741da177e4SLinus Torvalds 	.getname	= hci_sock_getname,
7751da177e4SLinus Torvalds 	.sendmsg	= hci_sock_sendmsg,
7761da177e4SLinus Torvalds 	.recvmsg	= hci_sock_recvmsg,
7771da177e4SLinus Torvalds 	.ioctl		= hci_sock_ioctl,
7781da177e4SLinus Torvalds 	.poll		= datagram_poll,
7791da177e4SLinus Torvalds 	.listen		= sock_no_listen,
7801da177e4SLinus Torvalds 	.shutdown	= sock_no_shutdown,
7811da177e4SLinus Torvalds 	.setsockopt	= hci_sock_setsockopt,
7821da177e4SLinus Torvalds 	.getsockopt	= hci_sock_getsockopt,
7831da177e4SLinus Torvalds 	.connect	= sock_no_connect,
7841da177e4SLinus Torvalds 	.socketpair	= sock_no_socketpair,
7851da177e4SLinus Torvalds 	.accept		= sock_no_accept,
7861da177e4SLinus Torvalds 	.mmap		= sock_no_mmap
7871da177e4SLinus Torvalds };
7881da177e4SLinus Torvalds 
7891da177e4SLinus Torvalds static struct proto hci_sk_proto = {
7901da177e4SLinus Torvalds 	.name		= "HCI",
7911da177e4SLinus Torvalds 	.owner		= THIS_MODULE,
7921da177e4SLinus Torvalds 	.obj_size	= sizeof(struct hci_pinfo)
7931da177e4SLinus Torvalds };
7941da177e4SLinus Torvalds 
7953f378b68SEric Paris static int hci_sock_create(struct net *net, struct socket *sock, int protocol,
7963f378b68SEric Paris 			   int kern)
7971da177e4SLinus Torvalds {
7981da177e4SLinus Torvalds 	struct sock *sk;
7991da177e4SLinus Torvalds 
8001da177e4SLinus Torvalds 	BT_DBG("sock %p", sock);
8011da177e4SLinus Torvalds 
8021da177e4SLinus Torvalds 	if (sock->type != SOCK_RAW)
8031da177e4SLinus Torvalds 		return -ESOCKTNOSUPPORT;
8041da177e4SLinus Torvalds 
8051da177e4SLinus Torvalds 	sock->ops = &hci_sock_ops;
8061da177e4SLinus Torvalds 
8076257ff21SPavel Emelyanov 	sk = sk_alloc(net, PF_BLUETOOTH, GFP_ATOMIC, &hci_sk_proto);
8081da177e4SLinus Torvalds 	if (!sk)
8091da177e4SLinus Torvalds 		return -ENOMEM;
8101da177e4SLinus Torvalds 
8111da177e4SLinus Torvalds 	sock_init_data(sock, sk);
8121da177e4SLinus Torvalds 
8131da177e4SLinus Torvalds 	sock_reset_flag(sk, SOCK_ZAPPED);
8141da177e4SLinus Torvalds 
8151da177e4SLinus Torvalds 	sk->sk_protocol = protocol;
8161da177e4SLinus Torvalds 
8171da177e4SLinus Torvalds 	sock->state = SS_UNCONNECTED;
8181da177e4SLinus Torvalds 	sk->sk_state = BT_OPEN;
8191da177e4SLinus Torvalds 
8201da177e4SLinus Torvalds 	bt_sock_link(&hci_sk_list, sk);
8211da177e4SLinus Torvalds 	return 0;
8221da177e4SLinus Torvalds }
8231da177e4SLinus Torvalds 
8241da177e4SLinus Torvalds static int hci_sock_dev_event(struct notifier_block *this, unsigned long event, void *ptr)
8251da177e4SLinus Torvalds {
8261da177e4SLinus Torvalds 	struct hci_dev *hdev = (struct hci_dev *) ptr;
8271da177e4SLinus Torvalds 	struct hci_ev_si_device ev;
8281da177e4SLinus Torvalds 
8291da177e4SLinus Torvalds 	BT_DBG("hdev %s event %ld", hdev->name, event);
8301da177e4SLinus Torvalds 
8311da177e4SLinus Torvalds 	/* Send event to sockets */
8321da177e4SLinus Torvalds 	ev.event  = event;
8331da177e4SLinus Torvalds 	ev.dev_id = hdev->id;
8341da177e4SLinus Torvalds 	hci_si_event(NULL, HCI_EV_SI_DEVICE, sizeof(ev), &ev);
8351da177e4SLinus Torvalds 
8361da177e4SLinus Torvalds 	if (event == HCI_DEV_UNREG) {
8371da177e4SLinus Torvalds 		struct sock *sk;
8381da177e4SLinus Torvalds 		struct hlist_node *node;
8391da177e4SLinus Torvalds 
8401da177e4SLinus Torvalds 		/* Detach sockets from device */
8411da177e4SLinus Torvalds 		read_lock(&hci_sk_list.lock);
8421da177e4SLinus Torvalds 		sk_for_each(sk, node, &hci_sk_list.head) {
8434ce61d1cSSatyam Sharma 			bh_lock_sock_nested(sk);
8441da177e4SLinus Torvalds 			if (hci_pi(sk)->hdev == hdev) {
8451da177e4SLinus Torvalds 				hci_pi(sk)->hdev = NULL;
8461da177e4SLinus Torvalds 				sk->sk_err = EPIPE;
8471da177e4SLinus Torvalds 				sk->sk_state = BT_OPEN;
8481da177e4SLinus Torvalds 				sk->sk_state_change(sk);
8491da177e4SLinus Torvalds 
8501da177e4SLinus Torvalds 				hci_dev_put(hdev);
8511da177e4SLinus Torvalds 			}
8524ce61d1cSSatyam Sharma 			bh_unlock_sock(sk);
8531da177e4SLinus Torvalds 		}
8541da177e4SLinus Torvalds 		read_unlock(&hci_sk_list.lock);
8551da177e4SLinus Torvalds 	}
8561da177e4SLinus Torvalds 
8571da177e4SLinus Torvalds 	return NOTIFY_DONE;
8581da177e4SLinus Torvalds }
8591da177e4SLinus Torvalds 
860ec1b4cf7SStephen Hemminger static const struct net_proto_family hci_sock_family_ops = {
8611da177e4SLinus Torvalds 	.family	= PF_BLUETOOTH,
8621da177e4SLinus Torvalds 	.owner	= THIS_MODULE,
8631da177e4SLinus Torvalds 	.create	= hci_sock_create,
8641da177e4SLinus Torvalds };
8651da177e4SLinus Torvalds 
8661da177e4SLinus Torvalds static struct notifier_block hci_sock_nblock = {
8671da177e4SLinus Torvalds 	.notifier_call = hci_sock_dev_event
8681da177e4SLinus Torvalds };
8691da177e4SLinus Torvalds 
8701da177e4SLinus Torvalds int __init hci_sock_init(void)
8711da177e4SLinus Torvalds {
8721da177e4SLinus Torvalds 	int err;
8731da177e4SLinus Torvalds 
8741da177e4SLinus Torvalds 	err = proto_register(&hci_sk_proto, 0);
8751da177e4SLinus Torvalds 	if (err < 0)
8761da177e4SLinus Torvalds 		return err;
8771da177e4SLinus Torvalds 
8781da177e4SLinus Torvalds 	err = bt_sock_register(BTPROTO_HCI, &hci_sock_family_ops);
8791da177e4SLinus Torvalds 	if (err < 0)
8801da177e4SLinus Torvalds 		goto error;
8811da177e4SLinus Torvalds 
8821da177e4SLinus Torvalds 	hci_register_notifier(&hci_sock_nblock);
8831da177e4SLinus Torvalds 
8841da177e4SLinus Torvalds 	BT_INFO("HCI socket layer initialized");
8851da177e4SLinus Torvalds 
8861da177e4SLinus Torvalds 	return 0;
8871da177e4SLinus Torvalds 
8881da177e4SLinus Torvalds error:
8891da177e4SLinus Torvalds 	BT_ERR("HCI socket registration failed");
8901da177e4SLinus Torvalds 	proto_unregister(&hci_sk_proto);
8911da177e4SLinus Torvalds 	return err;
8921da177e4SLinus Torvalds }
8931da177e4SLinus Torvalds 
894b7440a14SAnand Gadiyar void hci_sock_cleanup(void)
8951da177e4SLinus Torvalds {
8961da177e4SLinus Torvalds 	if (bt_sock_unregister(BTPROTO_HCI) < 0)
8971da177e4SLinus Torvalds 		BT_ERR("HCI socket unregistration failed");
8981da177e4SLinus Torvalds 
8991da177e4SLinus Torvalds 	hci_unregister_notifier(&hci_sock_nblock);
9001da177e4SLinus Torvalds 
9011da177e4SLinus Torvalds 	proto_unregister(&hci_sk_proto);
9021da177e4SLinus Torvalds }
9030381101fSJohan Hedberg 
9040381101fSJohan Hedberg module_param(enable_mgmt, bool, 0644);
9050381101fSJohan Hedberg MODULE_PARM_DESC(enable_mgmt, "Enable Management interface");
906