xref: /openbmc/linux/net/bluetooth/l2cap_core.c (revision 069cb270)
10a708f8fSGustavo F. Padovan /*
20a708f8fSGustavo F. Padovan    BlueZ - Bluetooth protocol stack for Linux
30a708f8fSGustavo F. Padovan    Copyright (C) 2000-2001 Qualcomm Incorporated
40a708f8fSGustavo F. Padovan    Copyright (C) 2009-2010 Gustavo F. Padovan <gustavo@padovan.org>
50a708f8fSGustavo F. Padovan    Copyright (C) 2010 Google Inc.
6590051deSGustavo F. Padovan    Copyright (C) 2011 ProFUSION Embedded Systems
7422e925bSMat Martineau    Copyright (c) 2012 Code Aurora Forum.  All rights reserved.
80a708f8fSGustavo F. Padovan 
90a708f8fSGustavo F. Padovan    Written 2000,2001 by Maxim Krasnyansky <maxk@qualcomm.com>
100a708f8fSGustavo F. Padovan 
110a708f8fSGustavo F. Padovan    This program is free software; you can redistribute it and/or modify
120a708f8fSGustavo F. Padovan    it under the terms of the GNU General Public License version 2 as
130a708f8fSGustavo F. Padovan    published by the Free Software Foundation;
140a708f8fSGustavo F. Padovan 
150a708f8fSGustavo F. Padovan    THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS
160a708f8fSGustavo F. Padovan    OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
170a708f8fSGustavo F. Padovan    FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT OF THIRD PARTY RIGHTS.
180a708f8fSGustavo F. Padovan    IN NO EVENT SHALL THE COPYRIGHT HOLDER(S) AND AUTHOR(S) BE LIABLE FOR ANY
190a708f8fSGustavo F. Padovan    CLAIM, OR ANY SPECIAL INDIRECT OR CONSEQUENTIAL DAMAGES, OR ANY DAMAGES
200a708f8fSGustavo F. Padovan    WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
210a708f8fSGustavo F. Padovan    ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
220a708f8fSGustavo F. Padovan    OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
230a708f8fSGustavo F. Padovan 
240a708f8fSGustavo F. Padovan    ALL LIABILITY, INCLUDING LIABILITY FOR INFRINGEMENT OF ANY PATENTS,
250a708f8fSGustavo F. Padovan    COPYRIGHTS, TRADEMARKS OR OTHER RIGHTS, RELATING TO USE OF THIS
260a708f8fSGustavo F. Padovan    SOFTWARE IS DISCLAIMED.
270a708f8fSGustavo F. Padovan */
280a708f8fSGustavo F. Padovan 
29bb58f747SGustavo F. Padovan /* Bluetooth L2CAP core. */
300a708f8fSGustavo F. Padovan 
310a708f8fSGustavo F. Padovan #include <linux/module.h>
320a708f8fSGustavo F. Padovan 
330a708f8fSGustavo F. Padovan #include <linux/debugfs.h>
340a708f8fSGustavo F. Padovan #include <linux/crc16.h>
350a708f8fSGustavo F. Padovan 
360a708f8fSGustavo F. Padovan #include <net/bluetooth/bluetooth.h>
370a708f8fSGustavo F. Padovan #include <net/bluetooth/hci_core.h>
380a708f8fSGustavo F. Padovan #include <net/bluetooth/l2cap.h>
397ef9fbf0SMarcel Holtmann 
40ac4b7236SMarcel Holtmann #include "smp.h"
417024728eSMarcel Holtmann #include "a2mp.h"
427ef9fbf0SMarcel Holtmann #include "amp.h"
430a708f8fSGustavo F. Padovan 
440f1bfe4eSJohan Hedberg #define LE_FLOWCTL_MAX_CREDITS 65535
450f1bfe4eSJohan Hedberg 
46d1de6d46SMat Martineau bool disable_ertm;
470a708f8fSGustavo F. Padovan 
48547d1032SMarcel Holtmann static u32 l2cap_feat_mask = L2CAP_FEAT_FIXED_CHAN | L2CAP_FEAT_UCD;
49a6801ca9SMarcel Holtmann static u8 l2cap_fixed_chan[8] = { L2CAP_FC_SIG_BREDR | L2CAP_FC_CONNLESS, };
500a708f8fSGustavo F. Padovan 
51b5ad8b7fSJohannes Berg static LIST_HEAD(chan_list);
52b5ad8b7fSJohannes Berg static DEFINE_RWLOCK(chan_list_lock);
530a708f8fSGustavo F. Padovan 
54f15b8ecfSJohan Hedberg static u16 le_max_credits = L2CAP_LE_MAX_CREDITS;
55f15b8ecfSJohan Hedberg static u16 le_default_mps = L2CAP_LE_DEFAULT_MPS;
56f15b8ecfSJohan Hedberg 
570a708f8fSGustavo F. Padovan static struct sk_buff *l2cap_build_cmd(struct l2cap_conn *conn,
580a708f8fSGustavo F. Padovan 				       u8 code, u8 ident, u16 dlen, void *data);
594519de9aSGustavo F. Padovan static void l2cap_send_cmd(struct l2cap_conn *conn, u8 ident, u8 code, u16 len,
604519de9aSGustavo F. Padovan 			   void *data);
61710f9b0aSGustavo F. Padovan static int l2cap_build_conf_req(struct l2cap_chan *chan, void *data);
625e4e3972SAndrei Emeltchenko static void l2cap_send_disconn_req(struct l2cap_chan *chan, int err);
630a708f8fSGustavo F. Padovan 
64d660366dSGustavo Padovan static void l2cap_tx(struct l2cap_chan *chan, struct l2cap_ctrl *control,
65608bcc6dSMat Martineau 		     struct sk_buff_head *skbs, u8 event);
66608bcc6dSMat Martineau 
674f1654e0SMarcel Holtmann static inline __u8 bdaddr_type(struct hci_conn *hcon, __u8 type)
684f1654e0SMarcel Holtmann {
694f1654e0SMarcel Holtmann 	if (hcon->type == LE_LINK) {
704f1654e0SMarcel Holtmann 		if (type == ADDR_LE_DEV_PUBLIC)
714f1654e0SMarcel Holtmann 			return BDADDR_LE_PUBLIC;
724f1654e0SMarcel Holtmann 		else
734f1654e0SMarcel Holtmann 			return BDADDR_LE_RANDOM;
744f1654e0SMarcel Holtmann 	}
754f1654e0SMarcel Holtmann 
764f1654e0SMarcel Holtmann 	return BDADDR_BREDR;
774f1654e0SMarcel Holtmann }
784f1654e0SMarcel Holtmann 
790a708f8fSGustavo F. Padovan /* ---- L2CAP channels ---- */
8071ba0e56SGustavo F. Padovan 
812d792818SGustavo Padovan static struct l2cap_chan *__l2cap_get_chan_by_dcid(struct l2cap_conn *conn,
822d792818SGustavo Padovan 						   u16 cid)
830a708f8fSGustavo F. Padovan {
843df91ea2SAndrei Emeltchenko 	struct l2cap_chan *c;
85baa7e1faSGustavo F. Padovan 
863df91ea2SAndrei Emeltchenko 	list_for_each_entry(c, &conn->chan_l, list) {
873df91ea2SAndrei Emeltchenko 		if (c->dcid == cid)
883df91ea2SAndrei Emeltchenko 			return c;
890a708f8fSGustavo F. Padovan 	}
903df91ea2SAndrei Emeltchenko 	return NULL;
91baa7e1faSGustavo F. Padovan }
920a708f8fSGustavo F. Padovan 
932d792818SGustavo Padovan static struct l2cap_chan *__l2cap_get_chan_by_scid(struct l2cap_conn *conn,
942d792818SGustavo Padovan 						   u16 cid)
950a708f8fSGustavo F. Padovan {
963df91ea2SAndrei Emeltchenko 	struct l2cap_chan *c;
97baa7e1faSGustavo F. Padovan 
983df91ea2SAndrei Emeltchenko 	list_for_each_entry(c, &conn->chan_l, list) {
993df91ea2SAndrei Emeltchenko 		if (c->scid == cid)
1003df91ea2SAndrei Emeltchenko 			return c;
1010a708f8fSGustavo F. Padovan 	}
1023df91ea2SAndrei Emeltchenko 	return NULL;
103baa7e1faSGustavo F. Padovan }
1040a708f8fSGustavo F. Padovan 
1050a708f8fSGustavo F. Padovan /* Find channel with given SCID.
106ef191adeSMat Martineau  * Returns locked channel. */
1072d792818SGustavo Padovan static struct l2cap_chan *l2cap_get_chan_by_scid(struct l2cap_conn *conn,
1082d792818SGustavo Padovan 						 u16 cid)
1090a708f8fSGustavo F. Padovan {
11048454079SGustavo F. Padovan 	struct l2cap_chan *c;
111baa7e1faSGustavo F. Padovan 
1123df91ea2SAndrei Emeltchenko 	mutex_lock(&conn->chan_lock);
113baa7e1faSGustavo F. Padovan 	c = __l2cap_get_chan_by_scid(conn, cid);
114ef191adeSMat Martineau 	if (c)
115ef191adeSMat Martineau 		l2cap_chan_lock(c);
1163df91ea2SAndrei Emeltchenko 	mutex_unlock(&conn->chan_lock);
1173df91ea2SAndrei Emeltchenko 
11848454079SGustavo F. Padovan 	return c;
1190a708f8fSGustavo F. Padovan }
1200a708f8fSGustavo F. Padovan 
121b1a130b7SMat Martineau /* Find channel with given DCID.
122b1a130b7SMat Martineau  * Returns locked channel.
123b1a130b7SMat Martineau  */
124b1a130b7SMat Martineau static struct l2cap_chan *l2cap_get_chan_by_dcid(struct l2cap_conn *conn,
125b1a130b7SMat Martineau 						 u16 cid)
126b1a130b7SMat Martineau {
127b1a130b7SMat Martineau 	struct l2cap_chan *c;
128b1a130b7SMat Martineau 
129b1a130b7SMat Martineau 	mutex_lock(&conn->chan_lock);
130b1a130b7SMat Martineau 	c = __l2cap_get_chan_by_dcid(conn, cid);
131b1a130b7SMat Martineau 	if (c)
132b1a130b7SMat Martineau 		l2cap_chan_lock(c);
133b1a130b7SMat Martineau 	mutex_unlock(&conn->chan_lock);
134b1a130b7SMat Martineau 
135b1a130b7SMat Martineau 	return c;
136b1a130b7SMat Martineau }
137b1a130b7SMat Martineau 
1382d792818SGustavo Padovan static struct l2cap_chan *__l2cap_get_chan_by_ident(struct l2cap_conn *conn,
1392d792818SGustavo Padovan 						    u8 ident)
1400a708f8fSGustavo F. Padovan {
1413df91ea2SAndrei Emeltchenko 	struct l2cap_chan *c;
142baa7e1faSGustavo F. Padovan 
1433df91ea2SAndrei Emeltchenko 	list_for_each_entry(c, &conn->chan_l, list) {
1443df91ea2SAndrei Emeltchenko 		if (c->ident == ident)
1453df91ea2SAndrei Emeltchenko 			return c;
1460a708f8fSGustavo F. Padovan 	}
1473df91ea2SAndrei Emeltchenko 	return NULL;
148baa7e1faSGustavo F. Padovan }
1490a708f8fSGustavo F. Padovan 
1505b155ef9SMat Martineau static struct l2cap_chan *l2cap_get_chan_by_ident(struct l2cap_conn *conn,
1515b155ef9SMat Martineau 						  u8 ident)
1525b155ef9SMat Martineau {
1535b155ef9SMat Martineau 	struct l2cap_chan *c;
1545b155ef9SMat Martineau 
1555b155ef9SMat Martineau 	mutex_lock(&conn->chan_lock);
1565b155ef9SMat Martineau 	c = __l2cap_get_chan_by_ident(conn, ident);
1575b155ef9SMat Martineau 	if (c)
1585b155ef9SMat Martineau 		l2cap_chan_lock(c);
1595b155ef9SMat Martineau 	mutex_unlock(&conn->chan_lock);
1605b155ef9SMat Martineau 
1615b155ef9SMat Martineau 	return c;
1625b155ef9SMat Martineau }
1635b155ef9SMat Martineau 
16423691d75SGustavo F. Padovan static struct l2cap_chan *__l2cap_global_chan_by_addr(__le16 psm, bdaddr_t *src)
1659e4425ffSGustavo F. Padovan {
16623691d75SGustavo F. Padovan 	struct l2cap_chan *c;
1679e4425ffSGustavo F. Padovan 
16823691d75SGustavo F. Padovan 	list_for_each_entry(c, &chan_list, global_l) {
1697eafc59eSMarcel Holtmann 		if (c->sport == psm && !bacmp(&c->src, src))
17023691d75SGustavo F. Padovan 			return c;
1719e4425ffSGustavo F. Padovan 	}
172250938cbSSzymon Janc 	return NULL;
173250938cbSSzymon Janc }
1749e4425ffSGustavo F. Padovan 
1759e4425ffSGustavo F. Padovan int l2cap_add_psm(struct l2cap_chan *chan, bdaddr_t *src, __le16 psm)
1769e4425ffSGustavo F. Padovan {
17773b2ec18SGustavo F. Padovan 	int err;
17873b2ec18SGustavo F. Padovan 
179333055f2SGustavo F. Padovan 	write_lock(&chan_list_lock);
1809e4425ffSGustavo F. Padovan 
18123691d75SGustavo F. Padovan 	if (psm && __l2cap_global_chan_by_addr(psm, src)) {
18273b2ec18SGustavo F. Padovan 		err = -EADDRINUSE;
18373b2ec18SGustavo F. Padovan 		goto done;
1849e4425ffSGustavo F. Padovan 	}
1859e4425ffSGustavo F. Padovan 
18673b2ec18SGustavo F. Padovan 	if (psm) {
1879e4425ffSGustavo F. Padovan 		chan->psm = psm;
1889e4425ffSGustavo F. Padovan 		chan->sport = psm;
18973b2ec18SGustavo F. Padovan 		err = 0;
19073b2ec18SGustavo F. Padovan 	} else {
19173b2ec18SGustavo F. Padovan 		u16 p;
1929e4425ffSGustavo F. Padovan 
19373b2ec18SGustavo F. Padovan 		err = -EINVAL;
19473b2ec18SGustavo F. Padovan 		for (p = 0x1001; p < 0x1100; p += 2)
19523691d75SGustavo F. Padovan 			if (!__l2cap_global_chan_by_addr(cpu_to_le16(p), src)) {
19673b2ec18SGustavo F. Padovan 				chan->psm   = cpu_to_le16(p);
19773b2ec18SGustavo F. Padovan 				chan->sport = cpu_to_le16(p);
19873b2ec18SGustavo F. Padovan 				err = 0;
19973b2ec18SGustavo F. Padovan 				break;
20073b2ec18SGustavo F. Padovan 			}
20173b2ec18SGustavo F. Padovan 	}
20273b2ec18SGustavo F. Padovan 
20373b2ec18SGustavo F. Padovan done:
204333055f2SGustavo F. Padovan 	write_unlock(&chan_list_lock);
20573b2ec18SGustavo F. Padovan 	return err;
2069e4425ffSGustavo F. Padovan }
2076b8d4a6aSJukka Rissanen EXPORT_SYMBOL_GPL(l2cap_add_psm);
2089e4425ffSGustavo F. Padovan 
2099e4425ffSGustavo F. Padovan int l2cap_add_scid(struct l2cap_chan *chan,  __u16 scid)
2109e4425ffSGustavo F. Padovan {
211333055f2SGustavo F. Padovan 	write_lock(&chan_list_lock);
2129e4425ffSGustavo F. Padovan 
21314824308SJohan Hedberg 	/* Override the defaults (which are for conn-oriented) */
21414824308SJohan Hedberg 	chan->omtu = L2CAP_DEFAULT_MTU;
21514824308SJohan Hedberg 	chan->chan_type = L2CAP_CHAN_FIXED;
21614824308SJohan Hedberg 
2179e4425ffSGustavo F. Padovan 	chan->scid = scid;
2189e4425ffSGustavo F. Padovan 
219333055f2SGustavo F. Padovan 	write_unlock(&chan_list_lock);
2209e4425ffSGustavo F. Padovan 
2219e4425ffSGustavo F. Padovan 	return 0;
2229e4425ffSGustavo F. Padovan }
2239e4425ffSGustavo F. Padovan 
224baa7e1faSGustavo F. Padovan static u16 l2cap_alloc_cid(struct l2cap_conn *conn)
2250a708f8fSGustavo F. Padovan {
226e77af755SJohan Hedberg 	u16 cid, dyn_end;
2270a708f8fSGustavo F. Padovan 
228e77af755SJohan Hedberg 	if (conn->hcon->type == LE_LINK)
229e77af755SJohan Hedberg 		dyn_end = L2CAP_CID_LE_DYN_END;
230e77af755SJohan Hedberg 	else
231e77af755SJohan Hedberg 		dyn_end = L2CAP_CID_DYN_END;
232e77af755SJohan Hedberg 
233e77af755SJohan Hedberg 	for (cid = L2CAP_CID_DYN_START; cid < dyn_end; cid++) {
234baa7e1faSGustavo F. Padovan 		if (!__l2cap_get_chan_by_scid(conn, cid))
2350a708f8fSGustavo F. Padovan 			return cid;
2360a708f8fSGustavo F. Padovan 	}
2370a708f8fSGustavo F. Padovan 
2380a708f8fSGustavo F. Padovan 	return 0;
2390a708f8fSGustavo F. Padovan }
2400a708f8fSGustavo F. Padovan 
241f93fa273SGustavo Padovan static void l2cap_state_change(struct l2cap_chan *chan, int state)
24289bc500eSGustavo F. Padovan {
24342d2d87cSAndrei Emeltchenko 	BT_DBG("chan %p %s -> %s", chan, state_to_string(chan->state),
244badaaa00SGustavo F. Padovan 	       state_to_string(state));
245badaaa00SGustavo F. Padovan 
24689bc500eSGustavo F. Padovan 	chan->state = state;
24753f52121SGustavo Padovan 	chan->ops->state_change(chan, state, 0);
24889bc500eSGustavo F. Padovan }
24989bc500eSGustavo F. Padovan 
250f8e73017SGustavo Padovan static inline void l2cap_state_change_and_error(struct l2cap_chan *chan,
251f8e73017SGustavo Padovan 						int state, int err)
2522e0052e4SAndrei Emeltchenko {
253f8e73017SGustavo Padovan 	chan->state = state;
25453f52121SGustavo Padovan 	chan->ops->state_change(chan, chan->state, err);
2552e0052e4SAndrei Emeltchenko }
2562e0052e4SAndrei Emeltchenko 
2572e0052e4SAndrei Emeltchenko static inline void l2cap_chan_set_err(struct l2cap_chan *chan, int err)
2582e0052e4SAndrei Emeltchenko {
259f8e73017SGustavo Padovan 	chan->ops->state_change(chan, chan->state, err);
2602e0052e4SAndrei Emeltchenko }
2612e0052e4SAndrei Emeltchenko 
2624239d16fSMat Martineau static void __set_retrans_timer(struct l2cap_chan *chan)
2634239d16fSMat Martineau {
2644239d16fSMat Martineau 	if (!delayed_work_pending(&chan->monitor_timer) &&
2654239d16fSMat Martineau 	    chan->retrans_timeout) {
2664239d16fSMat Martineau 		l2cap_set_timer(chan, &chan->retrans_timer,
2674239d16fSMat Martineau 				msecs_to_jiffies(chan->retrans_timeout));
2684239d16fSMat Martineau 	}
2694239d16fSMat Martineau }
2704239d16fSMat Martineau 
2714239d16fSMat Martineau static void __set_monitor_timer(struct l2cap_chan *chan)
2724239d16fSMat Martineau {
2734239d16fSMat Martineau 	__clear_retrans_timer(chan);
2744239d16fSMat Martineau 	if (chan->monitor_timeout) {
2754239d16fSMat Martineau 		l2cap_set_timer(chan, &chan->monitor_timer,
2764239d16fSMat Martineau 				msecs_to_jiffies(chan->monitor_timeout));
2774239d16fSMat Martineau 	}
2784239d16fSMat Martineau }
2794239d16fSMat Martineau 
280608bcc6dSMat Martineau static struct sk_buff *l2cap_ertm_seq_in_queue(struct sk_buff_head *head,
281608bcc6dSMat Martineau 					       u16 seq)
282608bcc6dSMat Martineau {
283608bcc6dSMat Martineau 	struct sk_buff *skb;
284608bcc6dSMat Martineau 
285608bcc6dSMat Martineau 	skb_queue_walk(head, skb) {
286608bcc6dSMat Martineau 		if (bt_cb(skb)->control.txseq == seq)
287608bcc6dSMat Martineau 			return skb;
288608bcc6dSMat Martineau 	}
289608bcc6dSMat Martineau 
290608bcc6dSMat Martineau 	return NULL;
291608bcc6dSMat Martineau }
292608bcc6dSMat Martineau 
2933c588192SMat Martineau /* ---- L2CAP sequence number lists ---- */
2943c588192SMat Martineau 
2953c588192SMat Martineau /* For ERTM, ordered lists of sequence numbers must be tracked for
2963c588192SMat Martineau  * SREJ requests that are received and for frames that are to be
2973c588192SMat Martineau  * retransmitted. These seq_list functions implement a singly-linked
2983c588192SMat Martineau  * list in an array, where membership in the list can also be checked
2993c588192SMat Martineau  * in constant time. Items can also be added to the tail of the list
3003c588192SMat Martineau  * and removed from the head in constant time, without further memory
3013c588192SMat Martineau  * allocs or frees.
3023c588192SMat Martineau  */
3033c588192SMat Martineau 
3043c588192SMat Martineau static int l2cap_seq_list_init(struct l2cap_seq_list *seq_list, u16 size)
3053c588192SMat Martineau {
3063c588192SMat Martineau 	size_t alloc_size, i;
3073c588192SMat Martineau 
3083c588192SMat Martineau 	/* Allocated size is a power of 2 to map sequence numbers
3093c588192SMat Martineau 	 * (which may be up to 14 bits) in to a smaller array that is
3103c588192SMat Martineau 	 * sized for the negotiated ERTM transmit windows.
3113c588192SMat Martineau 	 */
3123c588192SMat Martineau 	alloc_size = roundup_pow_of_two(size);
3133c588192SMat Martineau 
3143c588192SMat Martineau 	seq_list->list = kmalloc(sizeof(u16) * alloc_size, GFP_KERNEL);
3153c588192SMat Martineau 	if (!seq_list->list)
3163c588192SMat Martineau 		return -ENOMEM;
3173c588192SMat Martineau 
3183c588192SMat Martineau 	seq_list->mask = alloc_size - 1;
3193c588192SMat Martineau 	seq_list->head = L2CAP_SEQ_LIST_CLEAR;
3203c588192SMat Martineau 	seq_list->tail = L2CAP_SEQ_LIST_CLEAR;
3213c588192SMat Martineau 	for (i = 0; i < alloc_size; i++)
3223c588192SMat Martineau 		seq_list->list[i] = L2CAP_SEQ_LIST_CLEAR;
3233c588192SMat Martineau 
3243c588192SMat Martineau 	return 0;
3253c588192SMat Martineau }
3263c588192SMat Martineau 
3273c588192SMat Martineau static inline void l2cap_seq_list_free(struct l2cap_seq_list *seq_list)
3283c588192SMat Martineau {
3293c588192SMat Martineau 	kfree(seq_list->list);
3303c588192SMat Martineau }
3313c588192SMat Martineau 
3323c588192SMat Martineau static inline bool l2cap_seq_list_contains(struct l2cap_seq_list *seq_list,
3333c588192SMat Martineau 					   u16 seq)
3343c588192SMat Martineau {
3353c588192SMat Martineau 	/* Constant-time check for list membership */
3363c588192SMat Martineau 	return seq_list->list[seq & seq_list->mask] != L2CAP_SEQ_LIST_CLEAR;
3373c588192SMat Martineau }
3383c588192SMat Martineau 
33903a0c5d6SJohan Hedberg static inline u16 l2cap_seq_list_pop(struct l2cap_seq_list *seq_list)
3403c588192SMat Martineau {
34103a0c5d6SJohan Hedberg 	u16 seq = seq_list->head;
3423c588192SMat Martineau 	u16 mask = seq_list->mask;
3433c588192SMat Martineau 
3443c588192SMat Martineau 	seq_list->head = seq_list->list[seq & mask];
3453c588192SMat Martineau 	seq_list->list[seq & mask] = L2CAP_SEQ_LIST_CLEAR;
3463c588192SMat Martineau 
3473c588192SMat Martineau 	if (seq_list->head == L2CAP_SEQ_LIST_TAIL) {
3483c588192SMat Martineau 		seq_list->head = L2CAP_SEQ_LIST_CLEAR;
3493c588192SMat Martineau 		seq_list->tail = L2CAP_SEQ_LIST_CLEAR;
3503c588192SMat Martineau 	}
3513c588192SMat Martineau 
3523c588192SMat Martineau 	return seq;
3533c588192SMat Martineau }
3543c588192SMat Martineau 
3553c588192SMat Martineau static void l2cap_seq_list_clear(struct l2cap_seq_list *seq_list)
3563c588192SMat Martineau {
3573c588192SMat Martineau 	u16 i;
358f522ae36SGustavo Padovan 
359f522ae36SGustavo Padovan 	if (seq_list->head == L2CAP_SEQ_LIST_CLEAR)
360f522ae36SGustavo Padovan 		return;
361f522ae36SGustavo Padovan 
3623c588192SMat Martineau 	for (i = 0; i <= seq_list->mask; i++)
3633c588192SMat Martineau 		seq_list->list[i] = L2CAP_SEQ_LIST_CLEAR;
3643c588192SMat Martineau 
3653c588192SMat Martineau 	seq_list->head = L2CAP_SEQ_LIST_CLEAR;
3663c588192SMat Martineau 	seq_list->tail = L2CAP_SEQ_LIST_CLEAR;
3673c588192SMat Martineau }
3683c588192SMat Martineau 
3693c588192SMat Martineau static void l2cap_seq_list_append(struct l2cap_seq_list *seq_list, u16 seq)
3703c588192SMat Martineau {
3713c588192SMat Martineau 	u16 mask = seq_list->mask;
3723c588192SMat Martineau 
3733c588192SMat Martineau 	/* All appends happen in constant time */
3743c588192SMat Martineau 
375f522ae36SGustavo Padovan 	if (seq_list->list[seq & mask] != L2CAP_SEQ_LIST_CLEAR)
376f522ae36SGustavo Padovan 		return;
377f522ae36SGustavo Padovan 
3783c588192SMat Martineau 	if (seq_list->tail == L2CAP_SEQ_LIST_CLEAR)
3793c588192SMat Martineau 		seq_list->head = seq;
3803c588192SMat Martineau 	else
3813c588192SMat Martineau 		seq_list->list[seq_list->tail & mask] = seq;
3823c588192SMat Martineau 
3833c588192SMat Martineau 	seq_list->tail = seq;
3843c588192SMat Martineau 	seq_list->list[seq & mask] = L2CAP_SEQ_LIST_TAIL;
3853c588192SMat Martineau }
3863c588192SMat Martineau 
387721c4181SGustavo F. Padovan static void l2cap_chan_timeout(struct work_struct *work)
388ab07801dSGustavo F. Padovan {
389721c4181SGustavo F. Padovan 	struct l2cap_chan *chan = container_of(work, struct l2cap_chan,
390721c4181SGustavo F. Padovan 					       chan_timer.work);
3913df91ea2SAndrei Emeltchenko 	struct l2cap_conn *conn = chan->conn;
392ab07801dSGustavo F. Padovan 	int reason;
393ab07801dSGustavo F. Padovan 
394e05dcc32SAndrei Emeltchenko 	BT_DBG("chan %p state %s", chan, state_to_string(chan->state));
395ab07801dSGustavo F. Padovan 
3963df91ea2SAndrei Emeltchenko 	mutex_lock(&conn->chan_lock);
3976be36555SAndrei Emeltchenko 	l2cap_chan_lock(chan);
398ab07801dSGustavo F. Padovan 
39989bc500eSGustavo F. Padovan 	if (chan->state == BT_CONNECTED || chan->state == BT_CONFIG)
400ab07801dSGustavo F. Padovan 		reason = ECONNREFUSED;
40189bc500eSGustavo F. Padovan 	else if (chan->state == BT_CONNECT &&
402ab07801dSGustavo F. Padovan 		 chan->sec_level != BT_SECURITY_SDP)
403ab07801dSGustavo F. Padovan 		reason = ECONNREFUSED;
404ab07801dSGustavo F. Padovan 	else
405ab07801dSGustavo F. Padovan 		reason = ETIMEDOUT;
406ab07801dSGustavo F. Padovan 
4070f852724SGustavo F. Padovan 	l2cap_chan_close(chan, reason);
408ab07801dSGustavo F. Padovan 
4096be36555SAndrei Emeltchenko 	l2cap_chan_unlock(chan);
410ab07801dSGustavo F. Padovan 
41180b98027SGustavo Padovan 	chan->ops->close(chan);
4123df91ea2SAndrei Emeltchenko 	mutex_unlock(&conn->chan_lock);
4133df91ea2SAndrei Emeltchenko 
414371fd835SUlisses Furquim 	l2cap_chan_put(chan);
415ab07801dSGustavo F. Padovan }
416ab07801dSGustavo F. Padovan 
417eef1d9b6SGustavo Padovan struct l2cap_chan *l2cap_chan_create(void)
4180a708f8fSGustavo F. Padovan {
41948454079SGustavo F. Padovan 	struct l2cap_chan *chan;
4200a708f8fSGustavo F. Padovan 
42148454079SGustavo F. Padovan 	chan = kzalloc(sizeof(*chan), GFP_ATOMIC);
42248454079SGustavo F. Padovan 	if (!chan)
42348454079SGustavo F. Padovan 		return NULL;
4240a708f8fSGustavo F. Padovan 
425c03b355eSAndrei Emeltchenko 	mutex_init(&chan->lock);
426c03b355eSAndrei Emeltchenko 
427333055f2SGustavo F. Padovan 	write_lock(&chan_list_lock);
42823691d75SGustavo F. Padovan 	list_add(&chan->global_l, &chan_list);
429333055f2SGustavo F. Padovan 	write_unlock(&chan_list_lock);
43023691d75SGustavo F. Padovan 
431721c4181SGustavo F. Padovan 	INIT_DELAYED_WORK(&chan->chan_timer, l2cap_chan_timeout);
432ab07801dSGustavo F. Padovan 
43389bc500eSGustavo F. Padovan 	chan->state = BT_OPEN;
43489bc500eSGustavo F. Padovan 
435144ad330SSyam Sidhardhan 	kref_init(&chan->kref);
43671ba0e56SGustavo F. Padovan 
4372827011fSMat Martineau 	/* This flag is cleared in l2cap_chan_ready() */
4382827011fSMat Martineau 	set_bit(CONF_NOT_COMPLETE, &chan->conf_state);
4392827011fSMat Martineau 
440eef1d9b6SGustavo Padovan 	BT_DBG("chan %p", chan);
441abc545b8SSzymon Janc 
44248454079SGustavo F. Padovan 	return chan;
4430a708f8fSGustavo F. Padovan }
4446b8d4a6aSJukka Rissanen EXPORT_SYMBOL_GPL(l2cap_chan_create);
4450a708f8fSGustavo F. Padovan 
446144ad330SSyam Sidhardhan static void l2cap_chan_destroy(struct kref *kref)
4476ff5abbfSGustavo F. Padovan {
448144ad330SSyam Sidhardhan 	struct l2cap_chan *chan = container_of(kref, struct l2cap_chan, kref);
449144ad330SSyam Sidhardhan 
4504af66c69SJaganath Kanakkassery 	BT_DBG("chan %p", chan);
4514af66c69SJaganath Kanakkassery 
452333055f2SGustavo F. Padovan 	write_lock(&chan_list_lock);
45323691d75SGustavo F. Padovan 	list_del(&chan->global_l);
454333055f2SGustavo F. Padovan 	write_unlock(&chan_list_lock);
45523691d75SGustavo F. Padovan 
4564af66c69SJaganath Kanakkassery 	kfree(chan);
4576ff5abbfSGustavo F. Padovan }
4586ff5abbfSGustavo F. Padovan 
45930648372SJaganath Kanakkassery void l2cap_chan_hold(struct l2cap_chan *c)
46030648372SJaganath Kanakkassery {
461144ad330SSyam Sidhardhan 	BT_DBG("chan %p orig refcnt %d", c, atomic_read(&c->kref.refcount));
46230648372SJaganath Kanakkassery 
463144ad330SSyam Sidhardhan 	kref_get(&c->kref);
46430648372SJaganath Kanakkassery }
46530648372SJaganath Kanakkassery 
46630648372SJaganath Kanakkassery void l2cap_chan_put(struct l2cap_chan *c)
46730648372SJaganath Kanakkassery {
468144ad330SSyam Sidhardhan 	BT_DBG("chan %p orig refcnt %d", c, atomic_read(&c->kref.refcount));
46930648372SJaganath Kanakkassery 
470144ad330SSyam Sidhardhan 	kref_put(&c->kref, l2cap_chan_destroy);
47130648372SJaganath Kanakkassery }
4726b8d4a6aSJukka Rissanen EXPORT_SYMBOL_GPL(l2cap_chan_put);
47330648372SJaganath Kanakkassery 
474bd4b1653SAndrei Emeltchenko void l2cap_chan_set_defaults(struct l2cap_chan *chan)
475bd4b1653SAndrei Emeltchenko {
476bd4b1653SAndrei Emeltchenko 	chan->fcs  = L2CAP_FCS_CRC16;
477bd4b1653SAndrei Emeltchenko 	chan->max_tx = L2CAP_DEFAULT_MAX_TX;
478bd4b1653SAndrei Emeltchenko 	chan->tx_win = L2CAP_DEFAULT_TX_WINDOW;
479bd4b1653SAndrei Emeltchenko 	chan->tx_win_max = L2CAP_DEFAULT_TX_WINDOW;
4806a5e8165SJukka Rissanen 	chan->remote_max_tx = chan->max_tx;
4816a5e8165SJukka Rissanen 	chan->remote_tx_win = chan->tx_win;
482c20f8e35SMat Martineau 	chan->ack_win = L2CAP_DEFAULT_TX_WINDOW;
483bd4b1653SAndrei Emeltchenko 	chan->sec_level = BT_SECURITY_LOW;
4846a5e8165SJukka Rissanen 	chan->flush_to = L2CAP_DEFAULT_FLUSH_TO;
4856a5e8165SJukka Rissanen 	chan->retrans_timeout = L2CAP_DEFAULT_RETRANS_TO;
4866a5e8165SJukka Rissanen 	chan->monitor_timeout = L2CAP_DEFAULT_MONITOR_TO;
4876a5e8165SJukka Rissanen 	chan->conf_state = 0;
488bd4b1653SAndrei Emeltchenko 
489bd4b1653SAndrei Emeltchenko 	set_bit(FLAG_FORCE_ACTIVE, &chan->flags);
490bd4b1653SAndrei Emeltchenko }
4916b8d4a6aSJukka Rissanen EXPORT_SYMBOL_GPL(l2cap_chan_set_defaults);
492bd4b1653SAndrei Emeltchenko 
4930ce43ce6SJohan Hedberg static void l2cap_le_flowctl_init(struct l2cap_chan *chan)
49438319713SJohan Hedberg {
4950ce43ce6SJohan Hedberg 	chan->sdu = NULL;
4960ce43ce6SJohan Hedberg 	chan->sdu_last_frag = NULL;
4970ce43ce6SJohan Hedberg 	chan->sdu_len = 0;
4980cd75f7eSJohan Hedberg 	chan->tx_credits = 0;
499f15b8ecfSJohan Hedberg 	chan->rx_credits = le_max_credits;
500d1d79413SJohan Hedberg 	chan->mps = min_t(u16, chan->imtu, le_default_mps);
5010ce43ce6SJohan Hedberg 
5020ce43ce6SJohan Hedberg 	skb_queue_head_init(&chan->tx_q);
50338319713SJohan Hedberg }
50438319713SJohan Hedberg 
50593c3e8f5SAndrei Emeltchenko void __l2cap_chan_add(struct l2cap_conn *conn, struct l2cap_chan *chan)
5060a708f8fSGustavo F. Padovan {
5070a708f8fSGustavo F. Padovan 	BT_DBG("conn %p, psm 0x%2.2x, dcid 0x%4.4x", conn,
508097db76cSAndrei Emeltchenko 	       __le16_to_cpu(chan->psm), chan->dcid);
5090a708f8fSGustavo F. Padovan 
5109f5a0d7bSAndrei Emeltchenko 	conn->disc_reason = HCI_ERROR_REMOTE_USER_TERM;
5110a708f8fSGustavo F. Padovan 
5128c1d787bSGustavo F. Padovan 	chan->conn = conn;
5130a708f8fSGustavo F. Padovan 
5145491120eSAndrei Emeltchenko 	switch (chan->chan_type) {
5155491120eSAndrei Emeltchenko 	case L2CAP_CHAN_CONN_ORIENTED:
5160a708f8fSGustavo F. Padovan 		/* Alloc CID for connection-oriented socket */
517fe4128e0SGustavo F. Padovan 		chan->scid = l2cap_alloc_cid(conn);
51821626e62SJohan Hedberg 		if (conn->hcon->type == ACL_LINK)
5190c1bc5c6SGustavo F. Padovan 			chan->omtu = L2CAP_DEFAULT_MTU;
5205491120eSAndrei Emeltchenko 		break;
5215491120eSAndrei Emeltchenko 
5225491120eSAndrei Emeltchenko 	case L2CAP_CHAN_CONN_LESS:
5230a708f8fSGustavo F. Padovan 		/* Connectionless socket */
524fe4128e0SGustavo F. Padovan 		chan->scid = L2CAP_CID_CONN_LESS;
525fe4128e0SGustavo F. Padovan 		chan->dcid = L2CAP_CID_CONN_LESS;
5260c1bc5c6SGustavo F. Padovan 		chan->omtu = L2CAP_DEFAULT_MTU;
5275491120eSAndrei Emeltchenko 		break;
5285491120eSAndrei Emeltchenko 
5292338a7e0SJohan Hedberg 	case L2CAP_CHAN_FIXED:
5302338a7e0SJohan Hedberg 		/* Caller will set CID and CID specific MTU values */
531416fa752SAndrei Emeltchenko 		break;
532416fa752SAndrei Emeltchenko 
5335491120eSAndrei Emeltchenko 	default:
5340a708f8fSGustavo F. Padovan 		/* Raw socket can send/recv signalling messages only */
535fe4128e0SGustavo F. Padovan 		chan->scid = L2CAP_CID_SIGNALING;
536fe4128e0SGustavo F. Padovan 		chan->dcid = L2CAP_CID_SIGNALING;
5370c1bc5c6SGustavo F. Padovan 		chan->omtu = L2CAP_DEFAULT_MTU;
5380a708f8fSGustavo F. Padovan 	}
5390a708f8fSGustavo F. Padovan 
5408f7975b1SAndrei Emeltchenko 	chan->local_id		= L2CAP_BESTEFFORT_ID;
5418f7975b1SAndrei Emeltchenko 	chan->local_stype	= L2CAP_SERV_BESTEFFORT;
5428f7975b1SAndrei Emeltchenko 	chan->local_msdu	= L2CAP_DEFAULT_MAX_SDU_SIZE;
5438f7975b1SAndrei Emeltchenko 	chan->local_sdu_itime	= L2CAP_DEFAULT_SDU_ITIME;
5448f7975b1SAndrei Emeltchenko 	chan->local_acc_lat	= L2CAP_DEFAULT_ACC_LAT;
5458936fa6dSAndrei Emeltchenko 	chan->local_flush_to	= L2CAP_EFS_DEFAULT_FLUSH_TO;
5468f7975b1SAndrei Emeltchenko 
547371fd835SUlisses Furquim 	l2cap_chan_hold(chan);
548baa7e1faSGustavo F. Padovan 
5495ee9891dSJohan Hedberg 	hci_conn_hold(conn->hcon);
5505ee9891dSJohan Hedberg 
5513df91ea2SAndrei Emeltchenko 	list_add(&chan->list, &conn->chan_l);
552643162a8SAndrei Emeltchenko }
553643162a8SAndrei Emeltchenko 
554466f8004SAndrei Emeltchenko void l2cap_chan_add(struct l2cap_conn *conn, struct l2cap_chan *chan)
555643162a8SAndrei Emeltchenko {
556643162a8SAndrei Emeltchenko 	mutex_lock(&conn->chan_lock);
557643162a8SAndrei Emeltchenko 	__l2cap_chan_add(conn, chan);
5583df91ea2SAndrei Emeltchenko 	mutex_unlock(&conn->chan_lock);
5590a708f8fSGustavo F. Padovan }
5600a708f8fSGustavo F. Padovan 
561466f8004SAndrei Emeltchenko void l2cap_chan_del(struct l2cap_chan *chan, int err)
5620a708f8fSGustavo F. Padovan {
5638c1d787bSGustavo F. Padovan 	struct l2cap_conn *conn = chan->conn;
5640a708f8fSGustavo F. Padovan 
565c9b66675SGustavo F. Padovan 	__clear_chan_timer(chan);
5660a708f8fSGustavo F. Padovan 
56749208c9cSGustavo F. Padovan 	BT_DBG("chan %p, conn %p, err %d", chan, conn, err);
5680a708f8fSGustavo F. Padovan 
56972847ce0SJohan Hedberg 	chan->ops->teardown(chan, err);
57072847ce0SJohan Hedberg 
5710a708f8fSGustavo F. Padovan 	if (conn) {
57256f60984SAndrei Emeltchenko 		struct amp_mgr *mgr = conn->hcon->amp_mgr;
573baa7e1faSGustavo F. Padovan 		/* Delete from channel list */
5743df91ea2SAndrei Emeltchenko 		list_del(&chan->list);
5753d57dc68SGustavo F. Padovan 
576371fd835SUlisses Furquim 		l2cap_chan_put(chan);
577baa7e1faSGustavo F. Padovan 
5788c1d787bSGustavo F. Padovan 		chan->conn = NULL;
5793cabbfdaSAndrei Emeltchenko 
5802338a7e0SJohan Hedberg 		if (chan->scid != L2CAP_CID_A2MP)
58176a68ba0SDavid Herrmann 			hci_conn_drop(conn->hcon);
58256f60984SAndrei Emeltchenko 
58356f60984SAndrei Emeltchenko 		if (mgr && mgr->bredr_chan == chan)
58456f60984SAndrei Emeltchenko 			mgr->bredr_chan = NULL;
5850a708f8fSGustavo F. Padovan 	}
5860a708f8fSGustavo F. Padovan 
587419e08c1SAndrei Emeltchenko 	if (chan->hs_hchan) {
588419e08c1SAndrei Emeltchenko 		struct hci_chan *hs_hchan = chan->hs_hchan;
589419e08c1SAndrei Emeltchenko 
590419e08c1SAndrei Emeltchenko 		BT_DBG("chan %p disconnect hs_hchan %p", chan, hs_hchan);
591419e08c1SAndrei Emeltchenko 		amp_disconnect_logical_link(hs_hchan);
592419e08c1SAndrei Emeltchenko 	}
593419e08c1SAndrei Emeltchenko 
5942827011fSMat Martineau 	if (test_bit(CONF_NOT_COMPLETE, &chan->conf_state))
5956ff5abbfSGustavo F. Padovan 		return;
5962ead70b8SGustavo F. Padovan 
597ee556f66SGustavo Padovan 	switch(chan->mode) {
598ee556f66SGustavo Padovan 	case L2CAP_MODE_BASIC:
599ee556f66SGustavo Padovan 		break;
6000a708f8fSGustavo F. Padovan 
60138319713SJohan Hedberg 	case L2CAP_MODE_LE_FLOWCTL:
602177f8f2bSJohan Hedberg 		skb_queue_purge(&chan->tx_q);
60338319713SJohan Hedberg 		break;
60438319713SJohan Hedberg 
605ee556f66SGustavo Padovan 	case L2CAP_MODE_ERTM:
6061a09bcb9SGustavo F. Padovan 		__clear_retrans_timer(chan);
6071a09bcb9SGustavo F. Padovan 		__clear_monitor_timer(chan);
6081a09bcb9SGustavo F. Padovan 		__clear_ack_timer(chan);
6090a708f8fSGustavo F. Padovan 
610f1c6775bSGustavo F. Padovan 		skb_queue_purge(&chan->srej_q);
6110a708f8fSGustavo F. Padovan 
6123c588192SMat Martineau 		l2cap_seq_list_free(&chan->srej_list);
6133c588192SMat Martineau 		l2cap_seq_list_free(&chan->retrans_list);
614ee556f66SGustavo Padovan 
615ee556f66SGustavo Padovan 		/* fall through */
616ee556f66SGustavo Padovan 
617ee556f66SGustavo Padovan 	case L2CAP_MODE_STREAMING:
618ee556f66SGustavo Padovan 		skb_queue_purge(&chan->tx_q);
619ee556f66SGustavo Padovan 		break;
6200a708f8fSGustavo F. Padovan 	}
621ee556f66SGustavo Padovan 
622ee556f66SGustavo Padovan 	return;
6230a708f8fSGustavo F. Padovan }
6246b8d4a6aSJukka Rissanen EXPORT_SYMBOL_GPL(l2cap_chan_del);
6250a708f8fSGustavo F. Padovan 
626387a33e3SJohan Hedberg void l2cap_conn_update_id_addr(struct hci_conn *hcon)
627387a33e3SJohan Hedberg {
628387a33e3SJohan Hedberg 	struct l2cap_conn *conn = hcon->l2cap_data;
629387a33e3SJohan Hedberg 	struct l2cap_chan *chan;
630387a33e3SJohan Hedberg 
631387a33e3SJohan Hedberg 	mutex_lock(&conn->chan_lock);
632387a33e3SJohan Hedberg 
633387a33e3SJohan Hedberg 	list_for_each_entry(chan, &conn->chan_l, list) {
634387a33e3SJohan Hedberg 		l2cap_chan_lock(chan);
635387a33e3SJohan Hedberg 		bacpy(&chan->dst, &hcon->dst);
636387a33e3SJohan Hedberg 		chan->dst_type = bdaddr_type(hcon, hcon->dst_type);
637387a33e3SJohan Hedberg 		l2cap_chan_unlock(chan);
638387a33e3SJohan Hedberg 	}
639387a33e3SJohan Hedberg 
640387a33e3SJohan Hedberg 	mutex_unlock(&conn->chan_lock);
641387a33e3SJohan Hedberg }
642387a33e3SJohan Hedberg 
64327e2d4c8SJohan Hedberg static void l2cap_chan_le_connect_reject(struct l2cap_chan *chan)
64427e2d4c8SJohan Hedberg {
64527e2d4c8SJohan Hedberg 	struct l2cap_conn *conn = chan->conn;
64627e2d4c8SJohan Hedberg 	struct l2cap_le_conn_rsp rsp;
64727e2d4c8SJohan Hedberg 	u16 result;
64827e2d4c8SJohan Hedberg 
64927e2d4c8SJohan Hedberg 	if (test_bit(FLAG_DEFER_SETUP, &chan->flags))
65027e2d4c8SJohan Hedberg 		result = L2CAP_CR_AUTHORIZATION;
65127e2d4c8SJohan Hedberg 	else
65227e2d4c8SJohan Hedberg 		result = L2CAP_CR_BAD_PSM;
65327e2d4c8SJohan Hedberg 
65427e2d4c8SJohan Hedberg 	l2cap_state_change(chan, BT_DISCONN);
65527e2d4c8SJohan Hedberg 
65627e2d4c8SJohan Hedberg 	rsp.dcid    = cpu_to_le16(chan->scid);
65727e2d4c8SJohan Hedberg 	rsp.mtu     = cpu_to_le16(chan->imtu);
6583916aed8SJohan Hedberg 	rsp.mps     = cpu_to_le16(chan->mps);
6590cd75f7eSJohan Hedberg 	rsp.credits = cpu_to_le16(chan->rx_credits);
66027e2d4c8SJohan Hedberg 	rsp.result  = cpu_to_le16(result);
66127e2d4c8SJohan Hedberg 
66227e2d4c8SJohan Hedberg 	l2cap_send_cmd(conn, chan->ident, L2CAP_LE_CONN_RSP, sizeof(rsp),
66327e2d4c8SJohan Hedberg 		       &rsp);
66427e2d4c8SJohan Hedberg }
66527e2d4c8SJohan Hedberg 
666791d60f7SJohan Hedberg static void l2cap_chan_connect_reject(struct l2cap_chan *chan)
667791d60f7SJohan Hedberg {
668791d60f7SJohan Hedberg 	struct l2cap_conn *conn = chan->conn;
669791d60f7SJohan Hedberg 	struct l2cap_conn_rsp rsp;
670791d60f7SJohan Hedberg 	u16 result;
671791d60f7SJohan Hedberg 
672791d60f7SJohan Hedberg 	if (test_bit(FLAG_DEFER_SETUP, &chan->flags))
673791d60f7SJohan Hedberg 		result = L2CAP_CR_SEC_BLOCK;
674791d60f7SJohan Hedberg 	else
675791d60f7SJohan Hedberg 		result = L2CAP_CR_BAD_PSM;
676791d60f7SJohan Hedberg 
677791d60f7SJohan Hedberg 	l2cap_state_change(chan, BT_DISCONN);
678791d60f7SJohan Hedberg 
679791d60f7SJohan Hedberg 	rsp.scid   = cpu_to_le16(chan->dcid);
680791d60f7SJohan Hedberg 	rsp.dcid   = cpu_to_le16(chan->scid);
681791d60f7SJohan Hedberg 	rsp.result = cpu_to_le16(result);
682dcf4adbfSJoe Perches 	rsp.status = cpu_to_le16(L2CAP_CS_NO_INFO);
683791d60f7SJohan Hedberg 
684791d60f7SJohan Hedberg 	l2cap_send_cmd(conn, chan->ident, L2CAP_CONN_RSP, sizeof(rsp), &rsp);
685791d60f7SJohan Hedberg }
686791d60f7SJohan Hedberg 
6870f852724SGustavo F. Padovan void l2cap_chan_close(struct l2cap_chan *chan, int reason)
6884519de9aSGustavo F. Padovan {
6894519de9aSGustavo F. Padovan 	struct l2cap_conn *conn = chan->conn;
6904519de9aSGustavo F. Padovan 
6917eafc59eSMarcel Holtmann 	BT_DBG("chan %p state %s", chan, state_to_string(chan->state));
6924519de9aSGustavo F. Padovan 
69389bc500eSGustavo F. Padovan 	switch (chan->state) {
6944519de9aSGustavo F. Padovan 	case BT_LISTEN:
695c0df7f6eSAndrei Emeltchenko 		chan->ops->teardown(chan, 0);
6964519de9aSGustavo F. Padovan 		break;
6974519de9aSGustavo F. Padovan 
6984519de9aSGustavo F. Padovan 	case BT_CONNECTED:
6994519de9aSGustavo F. Padovan 	case BT_CONFIG:
7007b25c9b3SJohan Hedberg 		if (chan->chan_type == L2CAP_CHAN_CONN_ORIENTED) {
7018d836d71SGustavo Padovan 			__set_chan_timer(chan, chan->ops->get_sndtimeo(chan));
7025e4e3972SAndrei Emeltchenko 			l2cap_send_disconn_req(chan, reason);
7034519de9aSGustavo F. Padovan 		} else
7044519de9aSGustavo F. Padovan 			l2cap_chan_del(chan, reason);
7054519de9aSGustavo F. Padovan 		break;
7064519de9aSGustavo F. Padovan 
7074519de9aSGustavo F. Padovan 	case BT_CONNECT2:
708791d60f7SJohan Hedberg 		if (chan->chan_type == L2CAP_CHAN_CONN_ORIENTED) {
709791d60f7SJohan Hedberg 			if (conn->hcon->type == ACL_LINK)
710791d60f7SJohan Hedberg 				l2cap_chan_connect_reject(chan);
71127e2d4c8SJohan Hedberg 			else if (conn->hcon->type == LE_LINK)
71227e2d4c8SJohan Hedberg 				l2cap_chan_le_connect_reject(chan);
7134519de9aSGustavo F. Padovan 		}
7144519de9aSGustavo F. Padovan 
7154519de9aSGustavo F. Padovan 		l2cap_chan_del(chan, reason);
7164519de9aSGustavo F. Padovan 		break;
7174519de9aSGustavo F. Padovan 
7184519de9aSGustavo F. Padovan 	case BT_CONNECT:
7194519de9aSGustavo F. Padovan 	case BT_DISCONN:
7204519de9aSGustavo F. Padovan 		l2cap_chan_del(chan, reason);
7214519de9aSGustavo F. Padovan 		break;
7224519de9aSGustavo F. Padovan 
7234519de9aSGustavo F. Padovan 	default:
724c0df7f6eSAndrei Emeltchenko 		chan->ops->teardown(chan, 0);
7254519de9aSGustavo F. Padovan 		break;
7264519de9aSGustavo F. Padovan 	}
7274519de9aSGustavo F. Padovan }
7286b8d4a6aSJukka Rissanen EXPORT_SYMBOL(l2cap_chan_close);
7294519de9aSGustavo F. Padovan 
7304343478fSGustavo F. Padovan static inline u8 l2cap_get_auth_type(struct l2cap_chan *chan)
7310a708f8fSGustavo F. Padovan {
7326a974b50SMarcel Holtmann 	switch (chan->chan_type) {
7336a974b50SMarcel Holtmann 	case L2CAP_CHAN_RAW:
7344343478fSGustavo F. Padovan 		switch (chan->sec_level) {
7350a708f8fSGustavo F. Padovan 		case BT_SECURITY_HIGH:
7367d513e92SMarcel Holtmann 		case BT_SECURITY_FIPS:
7370a708f8fSGustavo F. Padovan 			return HCI_AT_DEDICATED_BONDING_MITM;
7380a708f8fSGustavo F. Padovan 		case BT_SECURITY_MEDIUM:
7390a708f8fSGustavo F. Padovan 			return HCI_AT_DEDICATED_BONDING;
7400a708f8fSGustavo F. Padovan 		default:
7410a708f8fSGustavo F. Padovan 			return HCI_AT_NO_BONDING;
7420a708f8fSGustavo F. Padovan 		}
7436a974b50SMarcel Holtmann 		break;
7443124b843SMarcel Holtmann 	case L2CAP_CHAN_CONN_LESS:
745dcf4adbfSJoe Perches 		if (chan->psm == cpu_to_le16(L2CAP_PSM_3DSP)) {
7463124b843SMarcel Holtmann 			if (chan->sec_level == BT_SECURITY_LOW)
7473124b843SMarcel Holtmann 				chan->sec_level = BT_SECURITY_SDP;
7483124b843SMarcel Holtmann 		}
7497d513e92SMarcel Holtmann 		if (chan->sec_level == BT_SECURITY_HIGH ||
7507d513e92SMarcel Holtmann 		    chan->sec_level == BT_SECURITY_FIPS)
7513124b843SMarcel Holtmann 			return HCI_AT_NO_BONDING_MITM;
7523124b843SMarcel Holtmann 		else
7533124b843SMarcel Holtmann 			return HCI_AT_NO_BONDING;
7543124b843SMarcel Holtmann 		break;
7556a974b50SMarcel Holtmann 	case L2CAP_CHAN_CONN_ORIENTED:
756dcf4adbfSJoe Perches 		if (chan->psm == cpu_to_le16(L2CAP_PSM_SDP)) {
7574343478fSGustavo F. Padovan 			if (chan->sec_level == BT_SECURITY_LOW)
7584343478fSGustavo F. Padovan 				chan->sec_level = BT_SECURITY_SDP;
7590a708f8fSGustavo F. Padovan 
7607d513e92SMarcel Holtmann 			if (chan->sec_level == BT_SECURITY_HIGH ||
7617d513e92SMarcel Holtmann 			    chan->sec_level == BT_SECURITY_FIPS)
7620a708f8fSGustavo F. Padovan 				return HCI_AT_NO_BONDING_MITM;
7630a708f8fSGustavo F. Padovan 			else
7640a708f8fSGustavo F. Padovan 				return HCI_AT_NO_BONDING;
7656a974b50SMarcel Holtmann 		}
7666a974b50SMarcel Holtmann 		/* fall through */
7676a974b50SMarcel Holtmann 	default:
7684343478fSGustavo F. Padovan 		switch (chan->sec_level) {
7690a708f8fSGustavo F. Padovan 		case BT_SECURITY_HIGH:
7707d513e92SMarcel Holtmann 		case BT_SECURITY_FIPS:
7710a708f8fSGustavo F. Padovan 			return HCI_AT_GENERAL_BONDING_MITM;
7720a708f8fSGustavo F. Padovan 		case BT_SECURITY_MEDIUM:
7730a708f8fSGustavo F. Padovan 			return HCI_AT_GENERAL_BONDING;
7740a708f8fSGustavo F. Padovan 		default:
7750a708f8fSGustavo F. Padovan 			return HCI_AT_NO_BONDING;
7760a708f8fSGustavo F. Padovan 		}
7776a974b50SMarcel Holtmann 		break;
7780a708f8fSGustavo F. Padovan 	}
7790a708f8fSGustavo F. Padovan }
7800a708f8fSGustavo F. Padovan 
7810a708f8fSGustavo F. Padovan /* Service level security */
782e7cafc45SJohan Hedberg int l2cap_chan_check_security(struct l2cap_chan *chan, bool initiator)
7830a708f8fSGustavo F. Padovan {
7848c1d787bSGustavo F. Padovan 	struct l2cap_conn *conn = chan->conn;
7850a708f8fSGustavo F. Padovan 	__u8 auth_type;
7860a708f8fSGustavo F. Padovan 
787a17de2feSJohan Hedberg 	if (conn->hcon->type == LE_LINK)
788a17de2feSJohan Hedberg 		return smp_conn_security(conn->hcon, chan->sec_level);
789a17de2feSJohan Hedberg 
7904343478fSGustavo F. Padovan 	auth_type = l2cap_get_auth_type(chan);
7910a708f8fSGustavo F. Padovan 
792e7cafc45SJohan Hedberg 	return hci_conn_security(conn->hcon, chan->sec_level, auth_type,
793e7cafc45SJohan Hedberg 				 initiator);
7940a708f8fSGustavo F. Padovan }
7950a708f8fSGustavo F. Padovan 
796b5ad8b7fSJohannes Berg static u8 l2cap_get_ident(struct l2cap_conn *conn)
7970a708f8fSGustavo F. Padovan {
7980a708f8fSGustavo F. Padovan 	u8 id;
7990a708f8fSGustavo F. Padovan 
8000a708f8fSGustavo F. Padovan 	/* Get next available identificator.
8010a708f8fSGustavo F. Padovan 	 *    1 - 128 are used by kernel.
8020a708f8fSGustavo F. Padovan 	 *  129 - 199 are reserved.
8030a708f8fSGustavo F. Padovan 	 *  200 - 254 are used by utilities like l2ping, etc.
8040a708f8fSGustavo F. Padovan 	 */
8050a708f8fSGustavo F. Padovan 
8065a54e7c8SMarcel Holtmann 	mutex_lock(&conn->ident_lock);
8070a708f8fSGustavo F. Padovan 
8080a708f8fSGustavo F. Padovan 	if (++conn->tx_ident > 128)
8090a708f8fSGustavo F. Padovan 		conn->tx_ident = 1;
8100a708f8fSGustavo F. Padovan 
8110a708f8fSGustavo F. Padovan 	id = conn->tx_ident;
8120a708f8fSGustavo F. Padovan 
8135a54e7c8SMarcel Holtmann 	mutex_unlock(&conn->ident_lock);
8140a708f8fSGustavo F. Padovan 
8150a708f8fSGustavo F. Padovan 	return id;
8160a708f8fSGustavo F. Padovan }
8170a708f8fSGustavo F. Padovan 
8182d792818SGustavo Padovan static void l2cap_send_cmd(struct l2cap_conn *conn, u8 ident, u8 code, u16 len,
8192d792818SGustavo Padovan 			   void *data)
8200a708f8fSGustavo F. Padovan {
8210a708f8fSGustavo F. Padovan 	struct sk_buff *skb = l2cap_build_cmd(conn, code, ident, len, data);
8220a708f8fSGustavo F. Padovan 	u8 flags;
8230a708f8fSGustavo F. Padovan 
8240a708f8fSGustavo F. Padovan 	BT_DBG("code 0x%2.2x", code);
8250a708f8fSGustavo F. Padovan 
8260a708f8fSGustavo F. Padovan 	if (!skb)
8270a708f8fSGustavo F. Padovan 		return;
8280a708f8fSGustavo F. Padovan 
8290a708f8fSGustavo F. Padovan 	if (lmp_no_flush_capable(conn->hcon->hdev))
8300a708f8fSGustavo F. Padovan 		flags = ACL_START_NO_FLUSH;
8310a708f8fSGustavo F. Padovan 	else
8320a708f8fSGustavo F. Padovan 		flags = ACL_START;
8330a708f8fSGustavo F. Padovan 
83414b12d0bSJaikumar Ganesh 	bt_cb(skb)->force_active = BT_POWER_FORCE_ACTIVE_ON;
8355e59b791SLuiz Augusto von Dentz 	skb->priority = HCI_PRIO_MAX;
83614b12d0bSJaikumar Ganesh 
83773d80debSLuiz Augusto von Dentz 	hci_send_acl(conn->hchan, skb, flags);
8380a708f8fSGustavo F. Padovan }
8390a708f8fSGustavo F. Padovan 
84002b0fbb9SMat Martineau static bool __chan_is_moving(struct l2cap_chan *chan)
84102b0fbb9SMat Martineau {
84202b0fbb9SMat Martineau 	return chan->move_state != L2CAP_MOVE_STABLE &&
84302b0fbb9SMat Martineau 	       chan->move_state != L2CAP_MOVE_WAIT_PREPARE;
84402b0fbb9SMat Martineau }
84502b0fbb9SMat Martineau 
84673d80debSLuiz Augusto von Dentz static void l2cap_do_send(struct l2cap_chan *chan, struct sk_buff *skb)
84773d80debSLuiz Augusto von Dentz {
84873d80debSLuiz Augusto von Dentz 	struct hci_conn *hcon = chan->conn->hcon;
84973d80debSLuiz Augusto von Dentz 	u16 flags;
85073d80debSLuiz Augusto von Dentz 
85173d80debSLuiz Augusto von Dentz 	BT_DBG("chan %p, skb %p len %d priority %u", chan, skb, skb->len,
85273d80debSLuiz Augusto von Dentz 	       skb->priority);
85373d80debSLuiz Augusto von Dentz 
854d5f8a75dSMat Martineau 	if (chan->hs_hcon && !__chan_is_moving(chan)) {
855d5f8a75dSMat Martineau 		if (chan->hs_hchan)
856d5f8a75dSMat Martineau 			hci_send_acl(chan->hs_hchan, skb, ACL_COMPLETE);
857d5f8a75dSMat Martineau 		else
858d5f8a75dSMat Martineau 			kfree_skb(skb);
859d5f8a75dSMat Martineau 
860d5f8a75dSMat Martineau 		return;
861d5f8a75dSMat Martineau 	}
862d5f8a75dSMat Martineau 
86373d80debSLuiz Augusto von Dentz 	if (!test_bit(FLAG_FLUSHABLE, &chan->flags) &&
86473d80debSLuiz Augusto von Dentz 	    lmp_no_flush_capable(hcon->hdev))
86573d80debSLuiz Augusto von Dentz 		flags = ACL_START_NO_FLUSH;
86673d80debSLuiz Augusto von Dentz 	else
86773d80debSLuiz Augusto von Dentz 		flags = ACL_START;
86873d80debSLuiz Augusto von Dentz 
86973d80debSLuiz Augusto von Dentz 	bt_cb(skb)->force_active = test_bit(FLAG_FORCE_ACTIVE, &chan->flags);
87073d80debSLuiz Augusto von Dentz 	hci_send_acl(chan->conn->hchan, skb, flags);
8710a708f8fSGustavo F. Padovan }
8720a708f8fSGustavo F. Padovan 
873b5c6aaedSMat Martineau static void __unpack_enhanced_control(u16 enh, struct l2cap_ctrl *control)
874b5c6aaedSMat Martineau {
875b5c6aaedSMat Martineau 	control->reqseq = (enh & L2CAP_CTRL_REQSEQ) >> L2CAP_CTRL_REQSEQ_SHIFT;
876b5c6aaedSMat Martineau 	control->final = (enh & L2CAP_CTRL_FINAL) >> L2CAP_CTRL_FINAL_SHIFT;
877b5c6aaedSMat Martineau 
878b5c6aaedSMat Martineau 	if (enh & L2CAP_CTRL_FRAME_TYPE) {
879b5c6aaedSMat Martineau 		/* S-Frame */
880b5c6aaedSMat Martineau 		control->sframe = 1;
881b5c6aaedSMat Martineau 		control->poll = (enh & L2CAP_CTRL_POLL) >> L2CAP_CTRL_POLL_SHIFT;
882b5c6aaedSMat Martineau 		control->super = (enh & L2CAP_CTRL_SUPERVISE) >> L2CAP_CTRL_SUPER_SHIFT;
883b5c6aaedSMat Martineau 
884b5c6aaedSMat Martineau 		control->sar = 0;
885b5c6aaedSMat Martineau 		control->txseq = 0;
886b5c6aaedSMat Martineau 	} else {
887b5c6aaedSMat Martineau 		/* I-Frame */
888b5c6aaedSMat Martineau 		control->sframe = 0;
889b5c6aaedSMat Martineau 		control->sar = (enh & L2CAP_CTRL_SAR) >> L2CAP_CTRL_SAR_SHIFT;
890b5c6aaedSMat Martineau 		control->txseq = (enh & L2CAP_CTRL_TXSEQ) >> L2CAP_CTRL_TXSEQ_SHIFT;
891b5c6aaedSMat Martineau 
892b5c6aaedSMat Martineau 		control->poll = 0;
893b5c6aaedSMat Martineau 		control->super = 0;
894b5c6aaedSMat Martineau 	}
895b5c6aaedSMat Martineau }
896b5c6aaedSMat Martineau 
897b5c6aaedSMat Martineau static void __unpack_extended_control(u32 ext, struct l2cap_ctrl *control)
898b5c6aaedSMat Martineau {
899b5c6aaedSMat Martineau 	control->reqseq = (ext & L2CAP_EXT_CTRL_REQSEQ) >> L2CAP_EXT_CTRL_REQSEQ_SHIFT;
900b5c6aaedSMat Martineau 	control->final = (ext & L2CAP_EXT_CTRL_FINAL) >> L2CAP_EXT_CTRL_FINAL_SHIFT;
901b5c6aaedSMat Martineau 
902b5c6aaedSMat Martineau 	if (ext & L2CAP_EXT_CTRL_FRAME_TYPE) {
903b5c6aaedSMat Martineau 		/* S-Frame */
904b5c6aaedSMat Martineau 		control->sframe = 1;
905b5c6aaedSMat Martineau 		control->poll = (ext & L2CAP_EXT_CTRL_POLL) >> L2CAP_EXT_CTRL_POLL_SHIFT;
906b5c6aaedSMat Martineau 		control->super = (ext & L2CAP_EXT_CTRL_SUPERVISE) >> L2CAP_EXT_CTRL_SUPER_SHIFT;
907b5c6aaedSMat Martineau 
908b5c6aaedSMat Martineau 		control->sar = 0;
909b5c6aaedSMat Martineau 		control->txseq = 0;
910b5c6aaedSMat Martineau 	} else {
911b5c6aaedSMat Martineau 		/* I-Frame */
912b5c6aaedSMat Martineau 		control->sframe = 0;
913b5c6aaedSMat Martineau 		control->sar = (ext & L2CAP_EXT_CTRL_SAR) >> L2CAP_EXT_CTRL_SAR_SHIFT;
914b5c6aaedSMat Martineau 		control->txseq = (ext & L2CAP_EXT_CTRL_TXSEQ) >> L2CAP_EXT_CTRL_TXSEQ_SHIFT;
915b5c6aaedSMat Martineau 
916b5c6aaedSMat Martineau 		control->poll = 0;
917b5c6aaedSMat Martineau 		control->super = 0;
918b5c6aaedSMat Martineau 	}
919b5c6aaedSMat Martineau }
920b5c6aaedSMat Martineau 
921b5c6aaedSMat Martineau static inline void __unpack_control(struct l2cap_chan *chan,
922b5c6aaedSMat Martineau 				    struct sk_buff *skb)
923b5c6aaedSMat Martineau {
924b5c6aaedSMat Martineau 	if (test_bit(FLAG_EXT_CTRL, &chan->flags)) {
925b5c6aaedSMat Martineau 		__unpack_extended_control(get_unaligned_le32(skb->data),
926b5c6aaedSMat Martineau 					  &bt_cb(skb)->control);
927cec8ab6eSMat Martineau 		skb_pull(skb, L2CAP_EXT_CTRL_SIZE);
928b5c6aaedSMat Martineau 	} else {
929b5c6aaedSMat Martineau 		__unpack_enhanced_control(get_unaligned_le16(skb->data),
930b5c6aaedSMat Martineau 					  &bt_cb(skb)->control);
931cec8ab6eSMat Martineau 		skb_pull(skb, L2CAP_ENH_CTRL_SIZE);
932b5c6aaedSMat Martineau 	}
933b5c6aaedSMat Martineau }
934b5c6aaedSMat Martineau 
935b5c6aaedSMat Martineau static u32 __pack_extended_control(struct l2cap_ctrl *control)
936b5c6aaedSMat Martineau {
937b5c6aaedSMat Martineau 	u32 packed;
938b5c6aaedSMat Martineau 
939b5c6aaedSMat Martineau 	packed = control->reqseq << L2CAP_EXT_CTRL_REQSEQ_SHIFT;
940b5c6aaedSMat Martineau 	packed |= control->final << L2CAP_EXT_CTRL_FINAL_SHIFT;
941b5c6aaedSMat Martineau 
942b5c6aaedSMat Martineau 	if (control->sframe) {
943b5c6aaedSMat Martineau 		packed |= control->poll << L2CAP_EXT_CTRL_POLL_SHIFT;
944b5c6aaedSMat Martineau 		packed |= control->super << L2CAP_EXT_CTRL_SUPER_SHIFT;
945b5c6aaedSMat Martineau 		packed |= L2CAP_EXT_CTRL_FRAME_TYPE;
946b5c6aaedSMat Martineau 	} else {
947b5c6aaedSMat Martineau 		packed |= control->sar << L2CAP_EXT_CTRL_SAR_SHIFT;
948b5c6aaedSMat Martineau 		packed |= control->txseq << L2CAP_EXT_CTRL_TXSEQ_SHIFT;
949b5c6aaedSMat Martineau 	}
950b5c6aaedSMat Martineau 
951b5c6aaedSMat Martineau 	return packed;
952b5c6aaedSMat Martineau }
953b5c6aaedSMat Martineau 
954b5c6aaedSMat Martineau static u16 __pack_enhanced_control(struct l2cap_ctrl *control)
955b5c6aaedSMat Martineau {
956b5c6aaedSMat Martineau 	u16 packed;
957b5c6aaedSMat Martineau 
958b5c6aaedSMat Martineau 	packed = control->reqseq << L2CAP_CTRL_REQSEQ_SHIFT;
959b5c6aaedSMat Martineau 	packed |= control->final << L2CAP_CTRL_FINAL_SHIFT;
960b5c6aaedSMat Martineau 
961b5c6aaedSMat Martineau 	if (control->sframe) {
962b5c6aaedSMat Martineau 		packed |= control->poll << L2CAP_CTRL_POLL_SHIFT;
963b5c6aaedSMat Martineau 		packed |= control->super << L2CAP_CTRL_SUPER_SHIFT;
964b5c6aaedSMat Martineau 		packed |= L2CAP_CTRL_FRAME_TYPE;
965b5c6aaedSMat Martineau 	} else {
966b5c6aaedSMat Martineau 		packed |= control->sar << L2CAP_CTRL_SAR_SHIFT;
967b5c6aaedSMat Martineau 		packed |= control->txseq << L2CAP_CTRL_TXSEQ_SHIFT;
968b5c6aaedSMat Martineau 	}
969b5c6aaedSMat Martineau 
970b5c6aaedSMat Martineau 	return packed;
971b5c6aaedSMat Martineau }
972b5c6aaedSMat Martineau 
973b5c6aaedSMat Martineau static inline void __pack_control(struct l2cap_chan *chan,
974b5c6aaedSMat Martineau 				  struct l2cap_ctrl *control,
975b5c6aaedSMat Martineau 				  struct sk_buff *skb)
976b5c6aaedSMat Martineau {
977b5c6aaedSMat Martineau 	if (test_bit(FLAG_EXT_CTRL, &chan->flags)) {
978b5c6aaedSMat Martineau 		put_unaligned_le32(__pack_extended_control(control),
979b5c6aaedSMat Martineau 				   skb->data + L2CAP_HDR_SIZE);
980b5c6aaedSMat Martineau 	} else {
981b5c6aaedSMat Martineau 		put_unaligned_le16(__pack_enhanced_control(control),
982b5c6aaedSMat Martineau 				   skb->data + L2CAP_HDR_SIZE);
983b5c6aaedSMat Martineau 	}
984b5c6aaedSMat Martineau }
985b5c6aaedSMat Martineau 
986ba7aa64fSGustavo Padovan static inline unsigned int __ertm_hdr_size(struct l2cap_chan *chan)
987ba7aa64fSGustavo Padovan {
988ba7aa64fSGustavo Padovan 	if (test_bit(FLAG_EXT_CTRL, &chan->flags))
989ba7aa64fSGustavo Padovan 		return L2CAP_EXT_HDR_SIZE;
990ba7aa64fSGustavo Padovan 	else
991ba7aa64fSGustavo Padovan 		return L2CAP_ENH_HDR_SIZE;
992ba7aa64fSGustavo Padovan }
993ba7aa64fSGustavo Padovan 
994a67d7f6fSMat Martineau static struct sk_buff *l2cap_create_sframe_pdu(struct l2cap_chan *chan,
995a67d7f6fSMat Martineau 					       u32 control)
9960a708f8fSGustavo F. Padovan {
9970a708f8fSGustavo F. Padovan 	struct sk_buff *skb;
9980a708f8fSGustavo F. Padovan 	struct l2cap_hdr *lh;
999ba7aa64fSGustavo Padovan 	int hlen = __ertm_hdr_size(chan);
10000a708f8fSGustavo F. Padovan 
10010a708f8fSGustavo F. Padovan 	if (chan->fcs == L2CAP_FCS_CRC16)
100203a51213SAndrei Emeltchenko 		hlen += L2CAP_FCS_SIZE;
10030a708f8fSGustavo F. Padovan 
1004a67d7f6fSMat Martineau 	skb = bt_skb_alloc(hlen, GFP_KERNEL);
10050a708f8fSGustavo F. Padovan 
10060a708f8fSGustavo F. Padovan 	if (!skb)
1007a67d7f6fSMat Martineau 		return ERR_PTR(-ENOMEM);
10080a708f8fSGustavo F. Padovan 
10090a708f8fSGustavo F. Padovan 	lh = (struct l2cap_hdr *) skb_put(skb, L2CAP_HDR_SIZE);
10100a708f8fSGustavo F. Padovan 	lh->len = cpu_to_le16(hlen - L2CAP_HDR_SIZE);
1011fe4128e0SGustavo F. Padovan 	lh->cid = cpu_to_le16(chan->dcid);
101288843ab0SAndrei Emeltchenko 
1013a67d7f6fSMat Martineau 	if (test_bit(FLAG_EXT_CTRL, &chan->flags))
1014a67d7f6fSMat Martineau 		put_unaligned_le32(control, skb_put(skb, L2CAP_EXT_CTRL_SIZE));
1015a67d7f6fSMat Martineau 	else
1016a67d7f6fSMat Martineau 		put_unaligned_le16(control, skb_put(skb, L2CAP_ENH_CTRL_SIZE));
10170a708f8fSGustavo F. Padovan 
101847d1ec61SGustavo F. Padovan 	if (chan->fcs == L2CAP_FCS_CRC16) {
1019a67d7f6fSMat Martineau 		u16 fcs = crc16(0, (u8 *)skb->data, skb->len);
102003a51213SAndrei Emeltchenko 		put_unaligned_le16(fcs, skb_put(skb, L2CAP_FCS_SIZE));
10210a708f8fSGustavo F. Padovan 	}
10220a708f8fSGustavo F. Padovan 
102373d80debSLuiz Augusto von Dentz 	skb->priority = HCI_PRIO_MAX;
1024a67d7f6fSMat Martineau 	return skb;
1025a67d7f6fSMat Martineau }
1026a67d7f6fSMat Martineau 
1027a67d7f6fSMat Martineau static void l2cap_send_sframe(struct l2cap_chan *chan,
1028a67d7f6fSMat Martineau 			      struct l2cap_ctrl *control)
1029a67d7f6fSMat Martineau {
1030a67d7f6fSMat Martineau 	struct sk_buff *skb;
1031a67d7f6fSMat Martineau 	u32 control_field;
1032a67d7f6fSMat Martineau 
1033a67d7f6fSMat Martineau 	BT_DBG("chan %p, control %p", chan, control);
1034a67d7f6fSMat Martineau 
1035a67d7f6fSMat Martineau 	if (!control->sframe)
1036a67d7f6fSMat Martineau 		return;
1037a67d7f6fSMat Martineau 
1038b99e13adSMat Martineau 	if (__chan_is_moving(chan))
1039b99e13adSMat Martineau 		return;
1040b99e13adSMat Martineau 
1041a67d7f6fSMat Martineau 	if (test_and_clear_bit(CONN_SEND_FBIT, &chan->conn_state) &&
1042a67d7f6fSMat Martineau 	    !control->poll)
1043a67d7f6fSMat Martineau 		control->final = 1;
1044a67d7f6fSMat Martineau 
1045a67d7f6fSMat Martineau 	if (control->super == L2CAP_SUPER_RR)
1046a67d7f6fSMat Martineau 		clear_bit(CONN_RNR_SENT, &chan->conn_state);
1047a67d7f6fSMat Martineau 	else if (control->super == L2CAP_SUPER_RNR)
1048a67d7f6fSMat Martineau 		set_bit(CONN_RNR_SENT, &chan->conn_state);
1049a67d7f6fSMat Martineau 
1050a67d7f6fSMat Martineau 	if (control->super != L2CAP_SUPER_SREJ) {
1051a67d7f6fSMat Martineau 		chan->last_acked_seq = control->reqseq;
1052a67d7f6fSMat Martineau 		__clear_ack_timer(chan);
1053a67d7f6fSMat Martineau 	}
1054a67d7f6fSMat Martineau 
1055a67d7f6fSMat Martineau 	BT_DBG("reqseq %d, final %d, poll %d, super %d", control->reqseq,
1056a67d7f6fSMat Martineau 	       control->final, control->poll, control->super);
1057a67d7f6fSMat Martineau 
1058a67d7f6fSMat Martineau 	if (test_bit(FLAG_EXT_CTRL, &chan->flags))
1059a67d7f6fSMat Martineau 		control_field = __pack_extended_control(control);
1060a67d7f6fSMat Martineau 	else
1061a67d7f6fSMat Martineau 		control_field = __pack_enhanced_control(control);
1062a67d7f6fSMat Martineau 
1063a67d7f6fSMat Martineau 	skb = l2cap_create_sframe_pdu(chan, control_field);
1064a67d7f6fSMat Martineau 	if (!IS_ERR(skb))
106573d80debSLuiz Augusto von Dentz 		l2cap_do_send(chan, skb);
10660a708f8fSGustavo F. Padovan }
10670a708f8fSGustavo F. Padovan 
1068c9e3d5e0SMat Martineau static void l2cap_send_rr_or_rnr(struct l2cap_chan *chan, bool poll)
10690a708f8fSGustavo F. Padovan {
1070c9e3d5e0SMat Martineau 	struct l2cap_ctrl control;
10710a708f8fSGustavo F. Padovan 
1072c9e3d5e0SMat Martineau 	BT_DBG("chan %p, poll %d", chan, poll);
1073c9e3d5e0SMat Martineau 
1074c9e3d5e0SMat Martineau 	memset(&control, 0, sizeof(control));
1075c9e3d5e0SMat Martineau 	control.sframe = 1;
1076c9e3d5e0SMat Martineau 	control.poll = poll;
1077c9e3d5e0SMat Martineau 
1078c9e3d5e0SMat Martineau 	if (test_bit(CONN_LOCAL_BUSY, &chan->conn_state))
1079c9e3d5e0SMat Martineau 		control.super = L2CAP_SUPER_RNR;
1080c9e3d5e0SMat Martineau 	else
1081c9e3d5e0SMat Martineau 		control.super = L2CAP_SUPER_RR;
1082c9e3d5e0SMat Martineau 
1083c9e3d5e0SMat Martineau 	control.reqseq = chan->buffer_seq;
1084c9e3d5e0SMat Martineau 	l2cap_send_sframe(chan, &control);
10850a708f8fSGustavo F. Padovan }
10860a708f8fSGustavo F. Padovan 
1087b4450035SGustavo F. Padovan static inline int __l2cap_no_conn_pending(struct l2cap_chan *chan)
10880a708f8fSGustavo F. Padovan {
10895ff6f34dSJohan Hedberg 	if (chan->chan_type != L2CAP_CHAN_CONN_ORIENTED)
10905ff6f34dSJohan Hedberg 		return true;
10915ff6f34dSJohan Hedberg 
1092c1360a1cSGustavo F. Padovan 	return !test_bit(CONF_CONNECT_PEND, &chan->conf_state);
10930a708f8fSGustavo F. Padovan }
10940a708f8fSGustavo F. Padovan 
109593c3e8f5SAndrei Emeltchenko static bool __amp_capable(struct l2cap_chan *chan)
109693c3e8f5SAndrei Emeltchenko {
109793c3e8f5SAndrei Emeltchenko 	struct l2cap_conn *conn = chan->conn;
10981df7b17aSMarcel Holtmann 	struct hci_dev *hdev;
10991df7b17aSMarcel Holtmann 	bool amp_available = false;
110093c3e8f5SAndrei Emeltchenko 
11011df7b17aSMarcel Holtmann 	if (!conn->hs_enabled)
11021df7b17aSMarcel Holtmann 		return false;
11031df7b17aSMarcel Holtmann 
11041df7b17aSMarcel Holtmann 	if (!(conn->fixed_chan_mask & L2CAP_FC_A2MP))
11051df7b17aSMarcel Holtmann 		return false;
11061df7b17aSMarcel Holtmann 
11071df7b17aSMarcel Holtmann 	read_lock(&hci_dev_list_lock);
11081df7b17aSMarcel Holtmann 	list_for_each_entry(hdev, &hci_dev_list, list) {
11091df7b17aSMarcel Holtmann 		if (hdev->amp_type != AMP_TYPE_BREDR &&
11101df7b17aSMarcel Holtmann 		    test_bit(HCI_UP, &hdev->flags)) {
11111df7b17aSMarcel Holtmann 			amp_available = true;
11121df7b17aSMarcel Holtmann 			break;
11131df7b17aSMarcel Holtmann 		}
11141df7b17aSMarcel Holtmann 	}
11151df7b17aSMarcel Holtmann 	read_unlock(&hci_dev_list_lock);
11161df7b17aSMarcel Holtmann 
11171df7b17aSMarcel Holtmann 	if (chan->chan_policy == BT_CHANNEL_POLICY_AMP_PREFERRED)
11181df7b17aSMarcel Holtmann 		return amp_available;
1119848566b3SMarcel Holtmann 
112093c3e8f5SAndrei Emeltchenko 	return false;
112193c3e8f5SAndrei Emeltchenko }
112293c3e8f5SAndrei Emeltchenko 
11235ce66b59SAndrei Emeltchenko static bool l2cap_check_efs(struct l2cap_chan *chan)
11245ce66b59SAndrei Emeltchenko {
11255ce66b59SAndrei Emeltchenko 	/* Check EFS parameters */
11265ce66b59SAndrei Emeltchenko 	return true;
11275ce66b59SAndrei Emeltchenko }
11285ce66b59SAndrei Emeltchenko 
11292766be48SAndrei Emeltchenko void l2cap_send_conn_req(struct l2cap_chan *chan)
11309b27f350SAndrei Emeltchenko {
11319b27f350SAndrei Emeltchenko 	struct l2cap_conn *conn = chan->conn;
11329b27f350SAndrei Emeltchenko 	struct l2cap_conn_req req;
11339b27f350SAndrei Emeltchenko 
11349b27f350SAndrei Emeltchenko 	req.scid = cpu_to_le16(chan->scid);
11359b27f350SAndrei Emeltchenko 	req.psm  = chan->psm;
11369b27f350SAndrei Emeltchenko 
11379b27f350SAndrei Emeltchenko 	chan->ident = l2cap_get_ident(conn);
11389b27f350SAndrei Emeltchenko 
11399b27f350SAndrei Emeltchenko 	set_bit(CONF_CONNECT_PEND, &chan->conf_state);
11409b27f350SAndrei Emeltchenko 
11419b27f350SAndrei Emeltchenko 	l2cap_send_cmd(conn, chan->ident, L2CAP_CONN_REQ, sizeof(req), &req);
11429b27f350SAndrei Emeltchenko }
11439b27f350SAndrei Emeltchenko 
11448eb200bdSMat Martineau static void l2cap_send_create_chan_req(struct l2cap_chan *chan, u8 amp_id)
11458eb200bdSMat Martineau {
11468eb200bdSMat Martineau 	struct l2cap_create_chan_req req;
11478eb200bdSMat Martineau 	req.scid = cpu_to_le16(chan->scid);
11488eb200bdSMat Martineau 	req.psm  = chan->psm;
11498eb200bdSMat Martineau 	req.amp_id = amp_id;
11508eb200bdSMat Martineau 
11518eb200bdSMat Martineau 	chan->ident = l2cap_get_ident(chan->conn);
11528eb200bdSMat Martineau 
11538eb200bdSMat Martineau 	l2cap_send_cmd(chan->conn, chan->ident, L2CAP_CREATE_CHAN_REQ,
11548eb200bdSMat Martineau 		       sizeof(req), &req);
11558eb200bdSMat Martineau }
11568eb200bdSMat Martineau 
115702b0fbb9SMat Martineau static void l2cap_move_setup(struct l2cap_chan *chan)
115802b0fbb9SMat Martineau {
115902b0fbb9SMat Martineau 	struct sk_buff *skb;
116002b0fbb9SMat Martineau 
116102b0fbb9SMat Martineau 	BT_DBG("chan %p", chan);
116202b0fbb9SMat Martineau 
116302b0fbb9SMat Martineau 	if (chan->mode != L2CAP_MODE_ERTM)
116402b0fbb9SMat Martineau 		return;
116502b0fbb9SMat Martineau 
116602b0fbb9SMat Martineau 	__clear_retrans_timer(chan);
116702b0fbb9SMat Martineau 	__clear_monitor_timer(chan);
116802b0fbb9SMat Martineau 	__clear_ack_timer(chan);
116902b0fbb9SMat Martineau 
117002b0fbb9SMat Martineau 	chan->retry_count = 0;
117102b0fbb9SMat Martineau 	skb_queue_walk(&chan->tx_q, skb) {
117202b0fbb9SMat Martineau 		if (bt_cb(skb)->control.retries)
117302b0fbb9SMat Martineau 			bt_cb(skb)->control.retries = 1;
117402b0fbb9SMat Martineau 		else
117502b0fbb9SMat Martineau 			break;
117602b0fbb9SMat Martineau 	}
117702b0fbb9SMat Martineau 
117802b0fbb9SMat Martineau 	chan->expected_tx_seq = chan->buffer_seq;
117902b0fbb9SMat Martineau 
118002b0fbb9SMat Martineau 	clear_bit(CONN_REJ_ACT, &chan->conn_state);
118102b0fbb9SMat Martineau 	clear_bit(CONN_SREJ_ACT, &chan->conn_state);
118202b0fbb9SMat Martineau 	l2cap_seq_list_clear(&chan->retrans_list);
118302b0fbb9SMat Martineau 	l2cap_seq_list_clear(&chan->srej_list);
118402b0fbb9SMat Martineau 	skb_queue_purge(&chan->srej_q);
118502b0fbb9SMat Martineau 
118602b0fbb9SMat Martineau 	chan->tx_state = L2CAP_TX_STATE_XMIT;
118702b0fbb9SMat Martineau 	chan->rx_state = L2CAP_RX_STATE_MOVE;
118802b0fbb9SMat Martineau 
118902b0fbb9SMat Martineau 	set_bit(CONN_REMOTE_BUSY, &chan->conn_state);
119002b0fbb9SMat Martineau }
119102b0fbb9SMat Martineau 
11925f3847a4SMat Martineau static void l2cap_move_done(struct l2cap_chan *chan)
11935f3847a4SMat Martineau {
11945f3847a4SMat Martineau 	u8 move_role = chan->move_role;
11955f3847a4SMat Martineau 	BT_DBG("chan %p", chan);
11965f3847a4SMat Martineau 
11975f3847a4SMat Martineau 	chan->move_state = L2CAP_MOVE_STABLE;
11985f3847a4SMat Martineau 	chan->move_role = L2CAP_MOVE_ROLE_NONE;
11995f3847a4SMat Martineau 
12005f3847a4SMat Martineau 	if (chan->mode != L2CAP_MODE_ERTM)
12015f3847a4SMat Martineau 		return;
12025f3847a4SMat Martineau 
12035f3847a4SMat Martineau 	switch (move_role) {
12045f3847a4SMat Martineau 	case L2CAP_MOVE_ROLE_INITIATOR:
12055f3847a4SMat Martineau 		l2cap_tx(chan, NULL, NULL, L2CAP_EV_EXPLICIT_POLL);
12065f3847a4SMat Martineau 		chan->rx_state = L2CAP_RX_STATE_WAIT_F;
12075f3847a4SMat Martineau 		break;
12085f3847a4SMat Martineau 	case L2CAP_MOVE_ROLE_RESPONDER:
12095f3847a4SMat Martineau 		chan->rx_state = L2CAP_RX_STATE_WAIT_P;
12105f3847a4SMat Martineau 		break;
12115f3847a4SMat Martineau 	}
12125f3847a4SMat Martineau }
12135f3847a4SMat Martineau 
12149f0caeb1SVinicius Costa Gomes static void l2cap_chan_ready(struct l2cap_chan *chan)
12159f0caeb1SVinicius Costa Gomes {
12162827011fSMat Martineau 	/* This clears all conf flags, including CONF_NOT_COMPLETE */
12179f0caeb1SVinicius Costa Gomes 	chan->conf_state = 0;
12189f0caeb1SVinicius Costa Gomes 	__clear_chan_timer(chan);
12199f0caeb1SVinicius Costa Gomes 
12200ce43ce6SJohan Hedberg 	if (chan->mode == L2CAP_MODE_LE_FLOWCTL && !chan->tx_credits)
12210ce43ce6SJohan Hedberg 		chan->ops->suspend(chan);
1222177f8f2bSJohan Hedberg 
122354a59aa2SAndrei Emeltchenko 	chan->state = BT_CONNECTED;
12249f0caeb1SVinicius Costa Gomes 
122554a59aa2SAndrei Emeltchenko 	chan->ops->ready(chan);
12269f0caeb1SVinicius Costa Gomes }
12279f0caeb1SVinicius Costa Gomes 
1228f1496deeSJohan Hedberg static void l2cap_le_connect(struct l2cap_chan *chan)
1229f1496deeSJohan Hedberg {
1230f1496deeSJohan Hedberg 	struct l2cap_conn *conn = chan->conn;
1231f1496deeSJohan Hedberg 	struct l2cap_le_conn_req req;
1232f1496deeSJohan Hedberg 
1233595177f3SJohan Hedberg 	if (test_and_set_bit(FLAG_LE_CONN_REQ_SENT, &chan->flags))
1234595177f3SJohan Hedberg 		return;
1235595177f3SJohan Hedberg 
1236f1496deeSJohan Hedberg 	req.psm     = chan->psm;
1237f1496deeSJohan Hedberg 	req.scid    = cpu_to_le16(chan->scid);
1238f1496deeSJohan Hedberg 	req.mtu     = cpu_to_le16(chan->imtu);
12393916aed8SJohan Hedberg 	req.mps     = cpu_to_le16(chan->mps);
12400cd75f7eSJohan Hedberg 	req.credits = cpu_to_le16(chan->rx_credits);
1241f1496deeSJohan Hedberg 
1242f1496deeSJohan Hedberg 	chan->ident = l2cap_get_ident(conn);
1243f1496deeSJohan Hedberg 
1244f1496deeSJohan Hedberg 	l2cap_send_cmd(conn, chan->ident, L2CAP_LE_CONN_REQ,
1245f1496deeSJohan Hedberg 		       sizeof(req), &req);
1246f1496deeSJohan Hedberg }
1247f1496deeSJohan Hedberg 
1248f1496deeSJohan Hedberg static void l2cap_le_start(struct l2cap_chan *chan)
1249f1496deeSJohan Hedberg {
1250f1496deeSJohan Hedberg 	struct l2cap_conn *conn = chan->conn;
1251f1496deeSJohan Hedberg 
1252f1496deeSJohan Hedberg 	if (!smp_conn_security(conn->hcon, chan->sec_level))
1253f1496deeSJohan Hedberg 		return;
1254f1496deeSJohan Hedberg 
1255f1496deeSJohan Hedberg 	if (!chan->psm) {
1256f1496deeSJohan Hedberg 		l2cap_chan_ready(chan);
1257f1496deeSJohan Hedberg 		return;
1258f1496deeSJohan Hedberg 	}
1259f1496deeSJohan Hedberg 
1260f1496deeSJohan Hedberg 	if (chan->state == BT_CONNECT)
1261f1496deeSJohan Hedberg 		l2cap_le_connect(chan);
1262f1496deeSJohan Hedberg }
1263f1496deeSJohan Hedberg 
126493c3e8f5SAndrei Emeltchenko static void l2cap_start_connection(struct l2cap_chan *chan)
126593c3e8f5SAndrei Emeltchenko {
126693c3e8f5SAndrei Emeltchenko 	if (__amp_capable(chan)) {
126793c3e8f5SAndrei Emeltchenko 		BT_DBG("chan %p AMP capable: discover AMPs", chan);
126893c3e8f5SAndrei Emeltchenko 		a2mp_discover_amp(chan);
1269f1496deeSJohan Hedberg 	} else if (chan->conn->hcon->type == LE_LINK) {
1270f1496deeSJohan Hedberg 		l2cap_le_start(chan);
127193c3e8f5SAndrei Emeltchenko 	} else {
127293c3e8f5SAndrei Emeltchenko 		l2cap_send_conn_req(chan);
127393c3e8f5SAndrei Emeltchenko 	}
127493c3e8f5SAndrei Emeltchenko }
127593c3e8f5SAndrei Emeltchenko 
1276fc7f8a7eSGustavo F. Padovan static void l2cap_do_start(struct l2cap_chan *chan)
12770a708f8fSGustavo F. Padovan {
12788c1d787bSGustavo F. Padovan 	struct l2cap_conn *conn = chan->conn;
12790a708f8fSGustavo F. Padovan 
12809f0caeb1SVinicius Costa Gomes 	if (conn->hcon->type == LE_LINK) {
128196ac34fbSJohan Hedberg 		l2cap_le_start(chan);
12829f0caeb1SVinicius Costa Gomes 		return;
12839f0caeb1SVinicius Costa Gomes 	}
12849f0caeb1SVinicius Costa Gomes 
12850a708f8fSGustavo F. Padovan 	if (conn->info_state & L2CAP_INFO_FEAT_MASK_REQ_SENT) {
12860a708f8fSGustavo F. Padovan 		if (!(conn->info_state & L2CAP_INFO_FEAT_MASK_REQ_DONE))
12870a708f8fSGustavo F. Padovan 			return;
12880a708f8fSGustavo F. Padovan 
1289e7cafc45SJohan Hedberg 		if (l2cap_chan_check_security(chan, true) &&
129093c3e8f5SAndrei Emeltchenko 		    __l2cap_no_conn_pending(chan)) {
129193c3e8f5SAndrei Emeltchenko 			l2cap_start_connection(chan);
129293c3e8f5SAndrei Emeltchenko 		}
12930a708f8fSGustavo F. Padovan 	} else {
12940a708f8fSGustavo F. Padovan 		struct l2cap_info_req req;
1295dcf4adbfSJoe Perches 		req.type = cpu_to_le16(L2CAP_IT_FEAT_MASK);
12960a708f8fSGustavo F. Padovan 
12970a708f8fSGustavo F. Padovan 		conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_SENT;
12980a708f8fSGustavo F. Padovan 		conn->info_ident = l2cap_get_ident(conn);
12990a708f8fSGustavo F. Padovan 
1300ba13ccd9SMarcel Holtmann 		schedule_delayed_work(&conn->info_timer, L2CAP_INFO_TIMEOUT);
13010a708f8fSGustavo F. Padovan 
13022d792818SGustavo Padovan 		l2cap_send_cmd(conn, conn->info_ident, L2CAP_INFO_REQ,
13032d792818SGustavo Padovan 			       sizeof(req), &req);
13040a708f8fSGustavo F. Padovan 	}
13050a708f8fSGustavo F. Padovan }
13060a708f8fSGustavo F. Padovan 
13070a708f8fSGustavo F. Padovan static inline int l2cap_mode_supported(__u8 mode, __u32 feat_mask)
13080a708f8fSGustavo F. Padovan {
13090a708f8fSGustavo F. Padovan 	u32 local_feat_mask = l2cap_feat_mask;
13100a708f8fSGustavo F. Padovan 	if (!disable_ertm)
13110a708f8fSGustavo F. Padovan 		local_feat_mask |= L2CAP_FEAT_ERTM | L2CAP_FEAT_STREAMING;
13120a708f8fSGustavo F. Padovan 
13130a708f8fSGustavo F. Padovan 	switch (mode) {
13140a708f8fSGustavo F. Padovan 	case L2CAP_MODE_ERTM:
13150a708f8fSGustavo F. Padovan 		return L2CAP_FEAT_ERTM & feat_mask & local_feat_mask;
13160a708f8fSGustavo F. Padovan 	case L2CAP_MODE_STREAMING:
13170a708f8fSGustavo F. Padovan 		return L2CAP_FEAT_STREAMING & feat_mask & local_feat_mask;
13180a708f8fSGustavo F. Padovan 	default:
13190a708f8fSGustavo F. Padovan 		return 0x00;
13200a708f8fSGustavo F. Padovan 	}
13210a708f8fSGustavo F. Padovan }
13220a708f8fSGustavo F. Padovan 
13235e4e3972SAndrei Emeltchenko static void l2cap_send_disconn_req(struct l2cap_chan *chan, int err)
13240a708f8fSGustavo F. Padovan {
13255e4e3972SAndrei Emeltchenko 	struct l2cap_conn *conn = chan->conn;
13260a708f8fSGustavo F. Padovan 	struct l2cap_disconn_req req;
13270a708f8fSGustavo F. Padovan 
13280a708f8fSGustavo F. Padovan 	if (!conn)
13290a708f8fSGustavo F. Padovan 		return;
13300a708f8fSGustavo F. Padovan 
1331aad3d0e3SAndrei Emeltchenko 	if (chan->mode == L2CAP_MODE_ERTM && chan->state == BT_CONNECTED) {
13321a09bcb9SGustavo F. Padovan 		__clear_retrans_timer(chan);
13331a09bcb9SGustavo F. Padovan 		__clear_monitor_timer(chan);
13341a09bcb9SGustavo F. Padovan 		__clear_ack_timer(chan);
13350a708f8fSGustavo F. Padovan 	}
13360a708f8fSGustavo F. Padovan 
13372338a7e0SJohan Hedberg 	if (chan->scid == L2CAP_CID_A2MP) {
1338d117773cSGustavo Padovan 		l2cap_state_change(chan, BT_DISCONN);
1339416fa752SAndrei Emeltchenko 		return;
1340416fa752SAndrei Emeltchenko 	}
1341416fa752SAndrei Emeltchenko 
1342fe4128e0SGustavo F. Padovan 	req.dcid = cpu_to_le16(chan->dcid);
1343fe4128e0SGustavo F. Padovan 	req.scid = cpu_to_le16(chan->scid);
13442d792818SGustavo Padovan 	l2cap_send_cmd(conn, l2cap_get_ident(conn), L2CAP_DISCONN_REQ,
13452d792818SGustavo Padovan 		       sizeof(req), &req);
13460a708f8fSGustavo F. Padovan 
1347f8e73017SGustavo Padovan 	l2cap_state_change_and_error(chan, BT_DISCONN, err);
13480a708f8fSGustavo F. Padovan }
13490a708f8fSGustavo F. Padovan 
13500a708f8fSGustavo F. Padovan /* ---- L2CAP connections ---- */
13510a708f8fSGustavo F. Padovan static void l2cap_conn_start(struct l2cap_conn *conn)
13520a708f8fSGustavo F. Padovan {
13533df91ea2SAndrei Emeltchenko 	struct l2cap_chan *chan, *tmp;
13540a708f8fSGustavo F. Padovan 
13550a708f8fSGustavo F. Padovan 	BT_DBG("conn %p", conn);
13560a708f8fSGustavo F. Padovan 
13573df91ea2SAndrei Emeltchenko 	mutex_lock(&conn->chan_lock);
13580a708f8fSGustavo F. Padovan 
13593df91ea2SAndrei Emeltchenko 	list_for_each_entry_safe(chan, tmp, &conn->chan_l, list) {
13606be36555SAndrei Emeltchenko 		l2cap_chan_lock(chan);
13610a708f8fSGustavo F. Padovan 
1362715ec005SGustavo F. Padovan 		if (chan->chan_type != L2CAP_CHAN_CONN_ORIENTED) {
13636be36555SAndrei Emeltchenko 			l2cap_chan_unlock(chan);
13640a708f8fSGustavo F. Padovan 			continue;
13650a708f8fSGustavo F. Padovan 		}
13660a708f8fSGustavo F. Padovan 
136789bc500eSGustavo F. Padovan 		if (chan->state == BT_CONNECT) {
1368e7cafc45SJohan Hedberg 			if (!l2cap_chan_check_security(chan, true) ||
1369b4450035SGustavo F. Padovan 			    !__l2cap_no_conn_pending(chan)) {
13706be36555SAndrei Emeltchenko 				l2cap_chan_unlock(chan);
13710a708f8fSGustavo F. Padovan 				continue;
13720a708f8fSGustavo F. Padovan 			}
13730a708f8fSGustavo F. Padovan 
1374c1360a1cSGustavo F. Padovan 			if (!l2cap_mode_supported(chan->mode, conn->feat_mask)
1375c1360a1cSGustavo F. Padovan 			    && test_bit(CONF_STATE2_DEVICE,
1376c1360a1cSGustavo F. Padovan 					&chan->conf_state)) {
13770f852724SGustavo F. Padovan 				l2cap_chan_close(chan, ECONNRESET);
13786be36555SAndrei Emeltchenko 				l2cap_chan_unlock(chan);
13790a708f8fSGustavo F. Padovan 				continue;
13800a708f8fSGustavo F. Padovan 			}
13810a708f8fSGustavo F. Padovan 
138293c3e8f5SAndrei Emeltchenko 			l2cap_start_connection(chan);
13830a708f8fSGustavo F. Padovan 
138489bc500eSGustavo F. Padovan 		} else if (chan->state == BT_CONNECT2) {
13850a708f8fSGustavo F. Padovan 			struct l2cap_conn_rsp rsp;
13860a708f8fSGustavo F. Padovan 			char buf[128];
1387fe4128e0SGustavo F. Padovan 			rsp.scid = cpu_to_le16(chan->dcid);
1388fe4128e0SGustavo F. Padovan 			rsp.dcid = cpu_to_le16(chan->scid);
13890a708f8fSGustavo F. Padovan 
1390e7cafc45SJohan Hedberg 			if (l2cap_chan_check_security(chan, false)) {
1391bdc25783SMarcel Holtmann 				if (test_bit(FLAG_DEFER_SETUP, &chan->flags)) {
1392dcf4adbfSJoe Perches 					rsp.result = cpu_to_le16(L2CAP_CR_PEND);
1393dcf4adbfSJoe Perches 					rsp.status = cpu_to_le16(L2CAP_CS_AUTHOR_PEND);
13942dc4e510SGustavo Padovan 					chan->ops->defer(chan);
13950a708f8fSGustavo F. Padovan 
13960a708f8fSGustavo F. Padovan 				} else {
1397acdcabf5SGustavo Padovan 					l2cap_state_change(chan, BT_CONFIG);
1398dcf4adbfSJoe Perches 					rsp.result = cpu_to_le16(L2CAP_CR_SUCCESS);
1399dcf4adbfSJoe Perches 					rsp.status = cpu_to_le16(L2CAP_CS_NO_INFO);
14000a708f8fSGustavo F. Padovan 				}
14010a708f8fSGustavo F. Padovan 			} else {
1402dcf4adbfSJoe Perches 				rsp.result = cpu_to_le16(L2CAP_CR_PEND);
1403dcf4adbfSJoe Perches 				rsp.status = cpu_to_le16(L2CAP_CS_AUTHEN_PEND);
14040a708f8fSGustavo F. Padovan 			}
14050a708f8fSGustavo F. Padovan 
1406fc7f8a7eSGustavo F. Padovan 			l2cap_send_cmd(conn, chan->ident, L2CAP_CONN_RSP,
1407fc7f8a7eSGustavo F. Padovan 				       sizeof(rsp), &rsp);
14080a708f8fSGustavo F. Padovan 
1409c1360a1cSGustavo F. Padovan 			if (test_bit(CONF_REQ_SENT, &chan->conf_state) ||
14100a708f8fSGustavo F. Padovan 			    rsp.result != L2CAP_CR_SUCCESS) {
14116be36555SAndrei Emeltchenko 				l2cap_chan_unlock(chan);
14120a708f8fSGustavo F. Padovan 				continue;
14130a708f8fSGustavo F. Padovan 			}
14140a708f8fSGustavo F. Padovan 
1415c1360a1cSGustavo F. Padovan 			set_bit(CONF_REQ_SENT, &chan->conf_state);
14160a708f8fSGustavo F. Padovan 			l2cap_send_cmd(conn, l2cap_get_ident(conn), L2CAP_CONF_REQ,
141773ffa904SGustavo F. Padovan 				       l2cap_build_conf_req(chan, buf), buf);
141873ffa904SGustavo F. Padovan 			chan->num_conf_req++;
14190a708f8fSGustavo F. Padovan 		}
14200a708f8fSGustavo F. Padovan 
14216be36555SAndrei Emeltchenko 		l2cap_chan_unlock(chan);
14220a708f8fSGustavo F. Padovan 	}
14230a708f8fSGustavo F. Padovan 
14243df91ea2SAndrei Emeltchenko 	mutex_unlock(&conn->chan_lock);
14250a708f8fSGustavo F. Padovan }
14260a708f8fSGustavo F. Padovan 
1427b62f328bSVille Tervo static void l2cap_le_conn_ready(struct l2cap_conn *conn)
1428b62f328bSVille Tervo {
1429cc8dba2bSMarcel Holtmann 	struct hci_conn *hcon = conn->hcon;
1430dcc36c16SJohan Hedberg 	struct hci_dev *hdev = hcon->hdev;
1431b62f328bSVille Tervo 
1432e760ec12SJohan Hedberg 	BT_DBG("%s conn %p", hdev->name, conn);
1433b62f328bSVille Tervo 
1434e760ec12SJohan Hedberg 	/* For outgoing pairing which doesn't necessarily have an
1435e760ec12SJohan Hedberg 	 * associated socket (e.g. mgmt_pair_device).
1436e760ec12SJohan Hedberg 	 */
1437e760ec12SJohan Hedberg 	if (hcon->out)
1438e760ec12SJohan Hedberg 		smp_conn_security(hcon, hcon->pending_sec_level);
1439cc8dba2bSMarcel Holtmann 
144080afeb6cSMarcel Holtmann 	/* For LE slave connections, make sure the connection interval
144180afeb6cSMarcel Holtmann 	 * is in the range of the minium and maximum interval that has
144280afeb6cSMarcel Holtmann 	 * been configured for this connection. If not, then trigger
144380afeb6cSMarcel Holtmann 	 * the connection update procedure.
144480afeb6cSMarcel Holtmann 	 */
144540bef302SJohan Hedberg 	if (hcon->role == HCI_ROLE_SLAVE &&
144680afeb6cSMarcel Holtmann 	    (hcon->le_conn_interval < hcon->le_conn_min_interval ||
144780afeb6cSMarcel Holtmann 	     hcon->le_conn_interval > hcon->le_conn_max_interval)) {
144880afeb6cSMarcel Holtmann 		struct l2cap_conn_param_update_req req;
144980afeb6cSMarcel Holtmann 
145080afeb6cSMarcel Holtmann 		req.min = cpu_to_le16(hcon->le_conn_min_interval);
145180afeb6cSMarcel Holtmann 		req.max = cpu_to_le16(hcon->le_conn_max_interval);
145280afeb6cSMarcel Holtmann 		req.latency = cpu_to_le16(hcon->le_conn_latency);
145380afeb6cSMarcel Holtmann 		req.to_multiplier = cpu_to_le16(hcon->le_supv_timeout);
145480afeb6cSMarcel Holtmann 
145580afeb6cSMarcel Holtmann 		l2cap_send_cmd(conn, l2cap_get_ident(conn),
145680afeb6cSMarcel Holtmann 			       L2CAP_CONN_PARAM_UPDATE_REQ, sizeof(req), &req);
145780afeb6cSMarcel Holtmann 	}
1458b62f328bSVille Tervo }
1459b62f328bSVille Tervo 
14600a708f8fSGustavo F. Padovan static void l2cap_conn_ready(struct l2cap_conn *conn)
14610a708f8fSGustavo F. Padovan {
146248454079SGustavo F. Padovan 	struct l2cap_chan *chan;
1463cc110922SVinicius Costa Gomes 	struct hci_conn *hcon = conn->hcon;
14640a708f8fSGustavo F. Padovan 
14650a708f8fSGustavo F. Padovan 	BT_DBG("conn %p", conn);
14660a708f8fSGustavo F. Padovan 
1467e760ec12SJohan Hedberg 	mutex_lock(&conn->chan_lock);
1468e760ec12SJohan Hedberg 
14693df91ea2SAndrei Emeltchenko 	list_for_each_entry(chan, &conn->chan_l, list) {
1470baa7e1faSGustavo F. Padovan 
14716be36555SAndrei Emeltchenko 		l2cap_chan_lock(chan);
14720a708f8fSGustavo F. Padovan 
14732338a7e0SJohan Hedberg 		if (chan->scid == L2CAP_CID_A2MP) {
1474416fa752SAndrei Emeltchenko 			l2cap_chan_unlock(chan);
1475416fa752SAndrei Emeltchenko 			continue;
1476416fa752SAndrei Emeltchenko 		}
1477416fa752SAndrei Emeltchenko 
1478cc110922SVinicius Costa Gomes 		if (hcon->type == LE_LINK) {
1479f1496deeSJohan Hedberg 			l2cap_le_start(chan);
148063128451SVinicius Costa Gomes 		} else if (chan->chan_type != L2CAP_CHAN_CONN_ORIENTED) {
148174e75740SGustavo Padovan 			l2cap_chan_ready(chan);
1482b501d6a1SAnderson Briglia 
14831c244f79SGustavo Padovan 		} else if (chan->state == BT_CONNECT) {
1484fc7f8a7eSGustavo F. Padovan 			l2cap_do_start(chan);
14851c244f79SGustavo Padovan 		}
14860a708f8fSGustavo F. Padovan 
14876be36555SAndrei Emeltchenko 		l2cap_chan_unlock(chan);
14880a708f8fSGustavo F. Padovan 	}
14890a708f8fSGustavo F. Padovan 
14903df91ea2SAndrei Emeltchenko 	mutex_unlock(&conn->chan_lock);
149161a939c6SJohan Hedberg 
149279a05727SJohan Hedberg 	if (hcon->type == LE_LINK)
149379a05727SJohan Hedberg 		l2cap_le_conn_ready(conn);
149479a05727SJohan Hedberg 
149561a939c6SJohan Hedberg 	queue_work(hcon->hdev->workqueue, &conn->pending_rx_work);
14960a708f8fSGustavo F. Padovan }
14970a708f8fSGustavo F. Padovan 
14980a708f8fSGustavo F. Padovan /* Notify sockets that we cannot guaranty reliability anymore */
14990a708f8fSGustavo F. Padovan static void l2cap_conn_unreliable(struct l2cap_conn *conn, int err)
15000a708f8fSGustavo F. Padovan {
150148454079SGustavo F. Padovan 	struct l2cap_chan *chan;
15020a708f8fSGustavo F. Padovan 
15030a708f8fSGustavo F. Padovan 	BT_DBG("conn %p", conn);
15040a708f8fSGustavo F. Padovan 
15053df91ea2SAndrei Emeltchenko 	mutex_lock(&conn->chan_lock);
15060a708f8fSGustavo F. Padovan 
15073df91ea2SAndrei Emeltchenko 	list_for_each_entry(chan, &conn->chan_l, list) {
1508ecf61bdbSAndrei Emeltchenko 		if (test_bit(FLAG_FORCE_RELIABLE, &chan->flags))
15091d8b1fd5SGustavo Padovan 			l2cap_chan_set_err(chan, err);
15100a708f8fSGustavo F. Padovan 	}
15110a708f8fSGustavo F. Padovan 
15123df91ea2SAndrei Emeltchenko 	mutex_unlock(&conn->chan_lock);
15130a708f8fSGustavo F. Padovan }
15140a708f8fSGustavo F. Padovan 
1515f878fcadSGustavo F. Padovan static void l2cap_info_timeout(struct work_struct *work)
15160a708f8fSGustavo F. Padovan {
1517f878fcadSGustavo F. Padovan 	struct l2cap_conn *conn = container_of(work, struct l2cap_conn,
1518030013d8SGustavo F. Padovan 					       info_timer.work);
15190a708f8fSGustavo F. Padovan 
15200a708f8fSGustavo F. Padovan 	conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_DONE;
15210a708f8fSGustavo F. Padovan 	conn->info_ident = 0;
15220a708f8fSGustavo F. Padovan 
15230a708f8fSGustavo F. Padovan 	l2cap_conn_start(conn);
15240a708f8fSGustavo F. Padovan }
15250a708f8fSGustavo F. Padovan 
15262c8e1411SDavid Herrmann /*
15272c8e1411SDavid Herrmann  * l2cap_user
15282c8e1411SDavid Herrmann  * External modules can register l2cap_user objects on l2cap_conn. The ->probe
15292c8e1411SDavid Herrmann  * callback is called during registration. The ->remove callback is called
15302c8e1411SDavid Herrmann  * during unregistration.
15312c8e1411SDavid Herrmann  * An l2cap_user object can either be explicitly unregistered or when the
15322c8e1411SDavid Herrmann  * underlying l2cap_conn object is deleted. This guarantees that l2cap->hcon,
15332c8e1411SDavid Herrmann  * l2cap->hchan, .. are valid as long as the remove callback hasn't been called.
15342c8e1411SDavid Herrmann  * External modules must own a reference to the l2cap_conn object if they intend
15352c8e1411SDavid Herrmann  * to call l2cap_unregister_user(). The l2cap_conn object might get destroyed at
15362c8e1411SDavid Herrmann  * any time if they don't.
15372c8e1411SDavid Herrmann  */
15382c8e1411SDavid Herrmann 
15392c8e1411SDavid Herrmann int l2cap_register_user(struct l2cap_conn *conn, struct l2cap_user *user)
15402c8e1411SDavid Herrmann {
15412c8e1411SDavid Herrmann 	struct hci_dev *hdev = conn->hcon->hdev;
15422c8e1411SDavid Herrmann 	int ret;
15432c8e1411SDavid Herrmann 
15442c8e1411SDavid Herrmann 	/* We need to check whether l2cap_conn is registered. If it is not, we
15452c8e1411SDavid Herrmann 	 * must not register the l2cap_user. l2cap_conn_del() is unregisters
15462c8e1411SDavid Herrmann 	 * l2cap_conn objects, but doesn't provide its own locking. Instead, it
15472c8e1411SDavid Herrmann 	 * relies on the parent hci_conn object to be locked. This itself relies
15482c8e1411SDavid Herrmann 	 * on the hci_dev object to be locked. So we must lock the hci device
15492c8e1411SDavid Herrmann 	 * here, too. */
15502c8e1411SDavid Herrmann 
15512c8e1411SDavid Herrmann 	hci_dev_lock(hdev);
15522c8e1411SDavid Herrmann 
15532c8e1411SDavid Herrmann 	if (user->list.next || user->list.prev) {
15542c8e1411SDavid Herrmann 		ret = -EINVAL;
15552c8e1411SDavid Herrmann 		goto out_unlock;
15562c8e1411SDavid Herrmann 	}
15572c8e1411SDavid Herrmann 
15582c8e1411SDavid Herrmann 	/* conn->hchan is NULL after l2cap_conn_del() was called */
15592c8e1411SDavid Herrmann 	if (!conn->hchan) {
15602c8e1411SDavid Herrmann 		ret = -ENODEV;
15612c8e1411SDavid Herrmann 		goto out_unlock;
15622c8e1411SDavid Herrmann 	}
15632c8e1411SDavid Herrmann 
15642c8e1411SDavid Herrmann 	ret = user->probe(conn, user);
15652c8e1411SDavid Herrmann 	if (ret)
15662c8e1411SDavid Herrmann 		goto out_unlock;
15672c8e1411SDavid Herrmann 
15682c8e1411SDavid Herrmann 	list_add(&user->list, &conn->users);
15692c8e1411SDavid Herrmann 	ret = 0;
15702c8e1411SDavid Herrmann 
15712c8e1411SDavid Herrmann out_unlock:
15722c8e1411SDavid Herrmann 	hci_dev_unlock(hdev);
15732c8e1411SDavid Herrmann 	return ret;
15742c8e1411SDavid Herrmann }
15752c8e1411SDavid Herrmann EXPORT_SYMBOL(l2cap_register_user);
15762c8e1411SDavid Herrmann 
15772c8e1411SDavid Herrmann void l2cap_unregister_user(struct l2cap_conn *conn, struct l2cap_user *user)
15782c8e1411SDavid Herrmann {
15792c8e1411SDavid Herrmann 	struct hci_dev *hdev = conn->hcon->hdev;
15802c8e1411SDavid Herrmann 
15812c8e1411SDavid Herrmann 	hci_dev_lock(hdev);
15822c8e1411SDavid Herrmann 
15832c8e1411SDavid Herrmann 	if (!user->list.next || !user->list.prev)
15842c8e1411SDavid Herrmann 		goto out_unlock;
15852c8e1411SDavid Herrmann 
15862c8e1411SDavid Herrmann 	list_del(&user->list);
15872c8e1411SDavid Herrmann 	user->list.next = NULL;
15882c8e1411SDavid Herrmann 	user->list.prev = NULL;
15892c8e1411SDavid Herrmann 	user->remove(conn, user);
15902c8e1411SDavid Herrmann 
15912c8e1411SDavid Herrmann out_unlock:
15922c8e1411SDavid Herrmann 	hci_dev_unlock(hdev);
15932c8e1411SDavid Herrmann }
15942c8e1411SDavid Herrmann EXPORT_SYMBOL(l2cap_unregister_user);
15952c8e1411SDavid Herrmann 
15962c8e1411SDavid Herrmann static void l2cap_unregister_all_users(struct l2cap_conn *conn)
15972c8e1411SDavid Herrmann {
15982c8e1411SDavid Herrmann 	struct l2cap_user *user;
15992c8e1411SDavid Herrmann 
16002c8e1411SDavid Herrmann 	while (!list_empty(&conn->users)) {
16012c8e1411SDavid Herrmann 		user = list_first_entry(&conn->users, struct l2cap_user, list);
16022c8e1411SDavid Herrmann 		list_del(&user->list);
16032c8e1411SDavid Herrmann 		user->list.next = NULL;
16042c8e1411SDavid Herrmann 		user->list.prev = NULL;
16052c8e1411SDavid Herrmann 		user->remove(conn, user);
16062c8e1411SDavid Herrmann 	}
16072c8e1411SDavid Herrmann }
16082c8e1411SDavid Herrmann 
16095d3de7dfSVinicius Costa Gomes static void l2cap_conn_del(struct hci_conn *hcon, int err)
16105d3de7dfSVinicius Costa Gomes {
16115d3de7dfSVinicius Costa Gomes 	struct l2cap_conn *conn = hcon->l2cap_data;
16125d3de7dfSVinicius Costa Gomes 	struct l2cap_chan *chan, *l;
16135d3de7dfSVinicius Costa Gomes 
16145d3de7dfSVinicius Costa Gomes 	if (!conn)
16155d3de7dfSVinicius Costa Gomes 		return;
16165d3de7dfSVinicius Costa Gomes 
16175d3de7dfSVinicius Costa Gomes 	BT_DBG("hcon %p conn %p, err %d", hcon, conn, err);
16185d3de7dfSVinicius Costa Gomes 
16195d3de7dfSVinicius Costa Gomes 	kfree_skb(conn->rx_skb);
16205d3de7dfSVinicius Costa Gomes 
162161a939c6SJohan Hedberg 	skb_queue_purge(&conn->pending_rx);
16227ab56c3aSJukka Taimisto 
16237ab56c3aSJukka Taimisto 	/* We can not call flush_work(&conn->pending_rx_work) here since we
16247ab56c3aSJukka Taimisto 	 * might block if we are running on a worker from the same workqueue
16257ab56c3aSJukka Taimisto 	 * pending_rx_work is waiting on.
16267ab56c3aSJukka Taimisto 	 */
16277ab56c3aSJukka Taimisto 	if (work_pending(&conn->pending_rx_work))
16287ab56c3aSJukka Taimisto 		cancel_work_sync(&conn->pending_rx_work);
162961a939c6SJohan Hedberg 
1630dec5b492SJohan Hedberg 	if (work_pending(&conn->disconn_work))
1631dec5b492SJohan Hedberg 		cancel_work_sync(&conn->disconn_work);
1632dec5b492SJohan Hedberg 
16332c8e1411SDavid Herrmann 	l2cap_unregister_all_users(conn);
16342c8e1411SDavid Herrmann 
16353df91ea2SAndrei Emeltchenko 	mutex_lock(&conn->chan_lock);
16363df91ea2SAndrei Emeltchenko 
16375d3de7dfSVinicius Costa Gomes 	/* Kill channels */
16385d3de7dfSVinicius Costa Gomes 	list_for_each_entry_safe(chan, l, &conn->chan_l, list) {
163961d6ef3eSMat Martineau 		l2cap_chan_hold(chan);
16406be36555SAndrei Emeltchenko 		l2cap_chan_lock(chan);
16416be36555SAndrei Emeltchenko 
16425d3de7dfSVinicius Costa Gomes 		l2cap_chan_del(chan, err);
16436be36555SAndrei Emeltchenko 
16446be36555SAndrei Emeltchenko 		l2cap_chan_unlock(chan);
16456be36555SAndrei Emeltchenko 
164680b98027SGustavo Padovan 		chan->ops->close(chan);
164761d6ef3eSMat Martineau 		l2cap_chan_put(chan);
16485d3de7dfSVinicius Costa Gomes 	}
16495d3de7dfSVinicius Costa Gomes 
16503df91ea2SAndrei Emeltchenko 	mutex_unlock(&conn->chan_lock);
16513df91ea2SAndrei Emeltchenko 
165273d80debSLuiz Augusto von Dentz 	hci_chan_del(conn->hchan);
165373d80debSLuiz Augusto von Dentz 
16545d3de7dfSVinicius Costa Gomes 	if (conn->info_state & L2CAP_INFO_FEAT_MASK_REQ_SENT)
1655127074bfSUlisses Furquim 		cancel_delayed_work_sync(&conn->info_timer);
16565d3de7dfSVinicius Costa Gomes 
16575d3de7dfSVinicius Costa Gomes 	hcon->l2cap_data = NULL;
16589c903e37SDavid Herrmann 	conn->hchan = NULL;
16599c903e37SDavid Herrmann 	l2cap_conn_put(conn);
16605d3de7dfSVinicius Costa Gomes }
16615d3de7dfSVinicius Costa Gomes 
1662dec5b492SJohan Hedberg static void disconn_work(struct work_struct *work)
1663dec5b492SJohan Hedberg {
1664dec5b492SJohan Hedberg 	struct l2cap_conn *conn = container_of(work, struct l2cap_conn,
1665dec5b492SJohan Hedberg 					       disconn_work);
1666dec5b492SJohan Hedberg 
1667dec5b492SJohan Hedberg 	BT_DBG("conn %p", conn);
1668dec5b492SJohan Hedberg 
1669dec5b492SJohan Hedberg 	l2cap_conn_del(conn->hcon, conn->disconn_err);
1670dec5b492SJohan Hedberg }
1671dec5b492SJohan Hedberg 
1672dec5b492SJohan Hedberg void l2cap_conn_shutdown(struct l2cap_conn *conn, int err)
1673dec5b492SJohan Hedberg {
1674dec5b492SJohan Hedberg 	struct hci_dev *hdev = conn->hcon->hdev;
1675dec5b492SJohan Hedberg 
1676dec5b492SJohan Hedberg 	BT_DBG("conn %p err %d", conn, err);
1677dec5b492SJohan Hedberg 
1678dec5b492SJohan Hedberg 	conn->disconn_err = err;
1679dec5b492SJohan Hedberg 	queue_work(hdev->workqueue, &conn->disconn_work);
1680dec5b492SJohan Hedberg }
1681dec5b492SJohan Hedberg 
16829c903e37SDavid Herrmann static void l2cap_conn_free(struct kref *ref)
16839c903e37SDavid Herrmann {
16849c903e37SDavid Herrmann 	struct l2cap_conn *conn = container_of(ref, struct l2cap_conn, ref);
16859c903e37SDavid Herrmann 
16869c903e37SDavid Herrmann 	hci_conn_put(conn->hcon);
16879c903e37SDavid Herrmann 	kfree(conn);
16889c903e37SDavid Herrmann }
16899c903e37SDavid Herrmann 
16909c903e37SDavid Herrmann void l2cap_conn_get(struct l2cap_conn *conn)
16919c903e37SDavid Herrmann {
16929c903e37SDavid Herrmann 	kref_get(&conn->ref);
16939c903e37SDavid Herrmann }
16949c903e37SDavid Herrmann EXPORT_SYMBOL(l2cap_conn_get);
16959c903e37SDavid Herrmann 
16969c903e37SDavid Herrmann void l2cap_conn_put(struct l2cap_conn *conn)
16979c903e37SDavid Herrmann {
16989c903e37SDavid Herrmann 	kref_put(&conn->ref, l2cap_conn_free);
16999c903e37SDavid Herrmann }
17009c903e37SDavid Herrmann EXPORT_SYMBOL(l2cap_conn_put);
17019c903e37SDavid Herrmann 
17020a708f8fSGustavo F. Padovan /* ---- Socket interface ---- */
17030a708f8fSGustavo F. Padovan 
1704c2287681SIdo Yariv /* Find socket with psm and source / destination bdaddr.
17050a708f8fSGustavo F. Padovan  * Returns closest match.
17060a708f8fSGustavo F. Padovan  */
1707c2287681SIdo Yariv static struct l2cap_chan *l2cap_global_chan_by_psm(int state, __le16 psm,
1708c2287681SIdo Yariv 						   bdaddr_t *src,
1709bf20fd4eSJohan Hedberg 						   bdaddr_t *dst,
1710bf20fd4eSJohan Hedberg 						   u8 link_type)
17110a708f8fSGustavo F. Padovan {
171223691d75SGustavo F. Padovan 	struct l2cap_chan *c, *c1 = NULL;
17130a708f8fSGustavo F. Padovan 
171423691d75SGustavo F. Padovan 	read_lock(&chan_list_lock);
17150a708f8fSGustavo F. Padovan 
171623691d75SGustavo F. Padovan 	list_for_each_entry(c, &chan_list, global_l) {
171789bc500eSGustavo F. Padovan 		if (state && c->state != state)
17180a708f8fSGustavo F. Padovan 			continue;
17190a708f8fSGustavo F. Padovan 
1720bf20fd4eSJohan Hedberg 		if (link_type == ACL_LINK && c->src_type != BDADDR_BREDR)
1721bf20fd4eSJohan Hedberg 			continue;
1722bf20fd4eSJohan Hedberg 
1723bf20fd4eSJohan Hedberg 		if (link_type == LE_LINK && c->src_type == BDADDR_BREDR)
1724bf20fd4eSJohan Hedberg 			continue;
1725bf20fd4eSJohan Hedberg 
172623691d75SGustavo F. Padovan 		if (c->psm == psm) {
1727c2287681SIdo Yariv 			int src_match, dst_match;
1728c2287681SIdo Yariv 			int src_any, dst_any;
1729c2287681SIdo Yariv 
17300a708f8fSGustavo F. Padovan 			/* Exact match. */
17317eafc59eSMarcel Holtmann 			src_match = !bacmp(&c->src, src);
17327eafc59eSMarcel Holtmann 			dst_match = !bacmp(&c->dst, dst);
1733c2287681SIdo Yariv 			if (src_match && dst_match) {
1734a24cce14SJohan Hedberg 				l2cap_chan_hold(c);
1735a7567b20SJohannes Berg 				read_unlock(&chan_list_lock);
173623691d75SGustavo F. Padovan 				return c;
173723691d75SGustavo F. Padovan 			}
17380a708f8fSGustavo F. Padovan 
17390a708f8fSGustavo F. Padovan 			/* Closest match */
17407eafc59eSMarcel Holtmann 			src_any = !bacmp(&c->src, BDADDR_ANY);
17417eafc59eSMarcel Holtmann 			dst_any = !bacmp(&c->dst, BDADDR_ANY);
1742c2287681SIdo Yariv 			if ((src_match && dst_any) || (src_any && dst_match) ||
1743c2287681SIdo Yariv 			    (src_any && dst_any))
174423691d75SGustavo F. Padovan 				c1 = c;
17450a708f8fSGustavo F. Padovan 		}
17460a708f8fSGustavo F. Padovan 	}
17470a708f8fSGustavo F. Padovan 
1748a24cce14SJohan Hedberg 	if (c1)
1749a24cce14SJohan Hedberg 		l2cap_chan_hold(c1);
1750a24cce14SJohan Hedberg 
175123691d75SGustavo F. Padovan 	read_unlock(&chan_list_lock);
17520a708f8fSGustavo F. Padovan 
175323691d75SGustavo F. Padovan 	return c1;
17540a708f8fSGustavo F. Padovan }
17550a708f8fSGustavo F. Padovan 
1756721c4181SGustavo F. Padovan static void l2cap_monitor_timeout(struct work_struct *work)
17570a708f8fSGustavo F. Padovan {
1758721c4181SGustavo F. Padovan 	struct l2cap_chan *chan = container_of(work, struct l2cap_chan,
1759721c4181SGustavo F. Padovan 					       monitor_timer.work);
17600a708f8fSGustavo F. Padovan 
1761525cd185SGustavo F. Padovan 	BT_DBG("chan %p", chan);
17620a708f8fSGustavo F. Padovan 
17636be36555SAndrei Emeltchenko 	l2cap_chan_lock(chan);
17646be36555SAndrei Emeltchenko 
176580909e04SMat Martineau 	if (!chan->conn) {
17666be36555SAndrei Emeltchenko 		l2cap_chan_unlock(chan);
17678d7e1c7fSAndrei Emeltchenko 		l2cap_chan_put(chan);
17680a708f8fSGustavo F. Padovan 		return;
17690a708f8fSGustavo F. Padovan 	}
17700a708f8fSGustavo F. Padovan 
1771401bb1f7SAndrei Emeltchenko 	l2cap_tx(chan, NULL, NULL, L2CAP_EV_MONITOR_TO);
17720a708f8fSGustavo F. Padovan 
17736be36555SAndrei Emeltchenko 	l2cap_chan_unlock(chan);
17748d7e1c7fSAndrei Emeltchenko 	l2cap_chan_put(chan);
17750a708f8fSGustavo F. Padovan }
17760a708f8fSGustavo F. Padovan 
1777721c4181SGustavo F. Padovan static void l2cap_retrans_timeout(struct work_struct *work)
17780a708f8fSGustavo F. Padovan {
1779721c4181SGustavo F. Padovan 	struct l2cap_chan *chan = container_of(work, struct l2cap_chan,
1780721c4181SGustavo F. Padovan 					       retrans_timer.work);
17810a708f8fSGustavo F. Padovan 
178249208c9cSGustavo F. Padovan 	BT_DBG("chan %p", chan);
17830a708f8fSGustavo F. Padovan 
17846be36555SAndrei Emeltchenko 	l2cap_chan_lock(chan);
17856be36555SAndrei Emeltchenko 
178680909e04SMat Martineau 	if (!chan->conn) {
178780909e04SMat Martineau 		l2cap_chan_unlock(chan);
178880909e04SMat Martineau 		l2cap_chan_put(chan);
178980909e04SMat Martineau 		return;
179080909e04SMat Martineau 	}
17910a708f8fSGustavo F. Padovan 
1792401bb1f7SAndrei Emeltchenko 	l2cap_tx(chan, NULL, NULL, L2CAP_EV_RETRANS_TO);
17936be36555SAndrei Emeltchenko 	l2cap_chan_unlock(chan);
17948d7e1c7fSAndrei Emeltchenko 	l2cap_chan_put(chan);
17950a708f8fSGustavo F. Padovan }
17960a708f8fSGustavo F. Padovan 
1797d660366dSGustavo Padovan static void l2cap_streaming_send(struct l2cap_chan *chan,
17983733937dSMat Martineau 				 struct sk_buff_head *skbs)
17990a708f8fSGustavo F. Padovan {
18000a708f8fSGustavo F. Padovan 	struct sk_buff *skb;
18013733937dSMat Martineau 	struct l2cap_ctrl *control;
18020a708f8fSGustavo F. Padovan 
18033733937dSMat Martineau 	BT_DBG("chan %p, skbs %p", chan, skbs);
18043733937dSMat Martineau 
1805b99e13adSMat Martineau 	if (__chan_is_moving(chan))
1806b99e13adSMat Martineau 		return;
1807b99e13adSMat Martineau 
18083733937dSMat Martineau 	skb_queue_splice_tail_init(skbs, &chan->tx_q);
18093733937dSMat Martineau 
18103733937dSMat Martineau 	while (!skb_queue_empty(&chan->tx_q)) {
18113733937dSMat Martineau 
18123733937dSMat Martineau 		skb = skb_dequeue(&chan->tx_q);
18133733937dSMat Martineau 
18143733937dSMat Martineau 		bt_cb(skb)->control.retries = 1;
18153733937dSMat Martineau 		control = &bt_cb(skb)->control;
18163733937dSMat Martineau 
18173733937dSMat Martineau 		control->reqseq = 0;
18183733937dSMat Martineau 		control->txseq = chan->next_tx_seq;
18193733937dSMat Martineau 
18203733937dSMat Martineau 		__pack_control(chan, control, skb);
18210a708f8fSGustavo F. Padovan 
182247d1ec61SGustavo F. Padovan 		if (chan->fcs == L2CAP_FCS_CRC16) {
18233733937dSMat Martineau 			u16 fcs = crc16(0, (u8 *) skb->data, skb->len);
18243733937dSMat Martineau 			put_unaligned_le16(fcs, skb_put(skb, L2CAP_FCS_SIZE));
18250a708f8fSGustavo F. Padovan 		}
18260a708f8fSGustavo F. Padovan 
18274343478fSGustavo F. Padovan 		l2cap_do_send(chan, skb);
18280a708f8fSGustavo F. Padovan 
1829b4400672SAndrei Emeltchenko 		BT_DBG("Sent txseq %u", control->txseq);
18303733937dSMat Martineau 
1831836be934SAndrei Emeltchenko 		chan->next_tx_seq = __next_seq(chan, chan->next_tx_seq);
18323733937dSMat Martineau 		chan->frames_sent++;
18330a708f8fSGustavo F. Padovan 	}
18340a708f8fSGustavo F. Padovan }
18350a708f8fSGustavo F. Padovan 
183667c9e840SSzymon Janc static int l2cap_ertm_send(struct l2cap_chan *chan)
18370a708f8fSGustavo F. Padovan {
18380a708f8fSGustavo F. Padovan 	struct sk_buff *skb, *tx_skb;
183918a48e76SMat Martineau 	struct l2cap_ctrl *control;
184018a48e76SMat Martineau 	int sent = 0;
184118a48e76SMat Martineau 
184218a48e76SMat Martineau 	BT_DBG("chan %p", chan);
18430a708f8fSGustavo F. Padovan 
184489bc500eSGustavo F. Padovan 	if (chan->state != BT_CONNECTED)
18450a708f8fSGustavo F. Padovan 		return -ENOTCONN;
18460a708f8fSGustavo F. Padovan 
184794122bbeSMat Martineau 	if (test_bit(CONN_REMOTE_BUSY, &chan->conn_state))
184894122bbeSMat Martineau 		return 0;
184994122bbeSMat Martineau 
1850b99e13adSMat Martineau 	if (__chan_is_moving(chan))
1851b99e13adSMat Martineau 		return 0;
1852b99e13adSMat Martineau 
185318a48e76SMat Martineau 	while (chan->tx_send_head &&
185418a48e76SMat Martineau 	       chan->unacked_frames < chan->remote_tx_win &&
185518a48e76SMat Martineau 	       chan->tx_state == L2CAP_TX_STATE_XMIT) {
18560a708f8fSGustavo F. Padovan 
185718a48e76SMat Martineau 		skb = chan->tx_send_head;
18580a708f8fSGustavo F. Padovan 
185918a48e76SMat Martineau 		bt_cb(skb)->control.retries = 1;
186018a48e76SMat Martineau 		control = &bt_cb(skb)->control;
18610a708f8fSGustavo F. Padovan 
1862e2ab4353SGustavo F. Padovan 		if (test_and_clear_bit(CONN_SEND_FBIT, &chan->conn_state))
186318a48e76SMat Martineau 			control->final = 1;
1864e2ab4353SGustavo F. Padovan 
186518a48e76SMat Martineau 		control->reqseq = chan->buffer_seq;
186618a48e76SMat Martineau 		chan->last_acked_seq = chan->buffer_seq;
186718a48e76SMat Martineau 		control->txseq = chan->next_tx_seq;
18680a708f8fSGustavo F. Padovan 
186918a48e76SMat Martineau 		__pack_control(chan, control, skb);
18700a708f8fSGustavo F. Padovan 
187147d1ec61SGustavo F. Padovan 		if (chan->fcs == L2CAP_FCS_CRC16) {
187218a48e76SMat Martineau 			u16 fcs = crc16(0, (u8 *) skb->data, skb->len);
187318a48e76SMat Martineau 			put_unaligned_le16(fcs, skb_put(skb, L2CAP_FCS_SIZE));
18740a708f8fSGustavo F. Padovan 		}
18750a708f8fSGustavo F. Padovan 
187618a48e76SMat Martineau 		/* Clone after data has been modified. Data is assumed to be
187718a48e76SMat Martineau 		   read-only (for locking purposes) on cloned sk_buffs.
187818a48e76SMat Martineau 		 */
187918a48e76SMat Martineau 		tx_skb = skb_clone(skb, GFP_KERNEL);
188018a48e76SMat Martineau 
188118a48e76SMat Martineau 		if (!tx_skb)
188218a48e76SMat Martineau 			break;
18830a708f8fSGustavo F. Padovan 
18841a09bcb9SGustavo F. Padovan 		__set_retrans_timer(chan);
18850a708f8fSGustavo F. Padovan 
1886836be934SAndrei Emeltchenko 		chan->next_tx_seq = __next_seq(chan, chan->next_tx_seq);
18876a026610SGustavo F. Padovan 		chan->unacked_frames++;
18886a026610SGustavo F. Padovan 		chan->frames_sent++;
188918a48e76SMat Martineau 		sent++;
18900a708f8fSGustavo F. Padovan 
189158d35f87SGustavo F. Padovan 		if (skb_queue_is_last(&chan->tx_q, skb))
189258d35f87SGustavo F. Padovan 			chan->tx_send_head = NULL;
18930a708f8fSGustavo F. Padovan 		else
189458d35f87SGustavo F. Padovan 			chan->tx_send_head = skb_queue_next(&chan->tx_q, skb);
189518a48e76SMat Martineau 
189618a48e76SMat Martineau 		l2cap_do_send(chan, tx_skb);
1897b4400672SAndrei Emeltchenko 		BT_DBG("Sent txseq %u", control->txseq);
18980a708f8fSGustavo F. Padovan 	}
18990a708f8fSGustavo F. Padovan 
1900b4400672SAndrei Emeltchenko 	BT_DBG("Sent %d, %u unacked, %u in ERTM queue", sent,
1901b4400672SAndrei Emeltchenko 	       chan->unacked_frames, skb_queue_len(&chan->tx_q));
190218a48e76SMat Martineau 
190318a48e76SMat Martineau 	return sent;
19040a708f8fSGustavo F. Padovan }
19050a708f8fSGustavo F. Padovan 
1906e1fbd4c1SMat Martineau static void l2cap_ertm_resend(struct l2cap_chan *chan)
1907e1fbd4c1SMat Martineau {
1908e1fbd4c1SMat Martineau 	struct l2cap_ctrl control;
1909e1fbd4c1SMat Martineau 	struct sk_buff *skb;
1910e1fbd4c1SMat Martineau 	struct sk_buff *tx_skb;
1911e1fbd4c1SMat Martineau 	u16 seq;
1912e1fbd4c1SMat Martineau 
1913e1fbd4c1SMat Martineau 	BT_DBG("chan %p", chan);
1914e1fbd4c1SMat Martineau 
1915e1fbd4c1SMat Martineau 	if (test_bit(CONN_REMOTE_BUSY, &chan->conn_state))
1916e1fbd4c1SMat Martineau 		return;
1917e1fbd4c1SMat Martineau 
1918b99e13adSMat Martineau 	if (__chan_is_moving(chan))
1919b99e13adSMat Martineau 		return;
1920b99e13adSMat Martineau 
1921e1fbd4c1SMat Martineau 	while (chan->retrans_list.head != L2CAP_SEQ_LIST_CLEAR) {
1922e1fbd4c1SMat Martineau 		seq = l2cap_seq_list_pop(&chan->retrans_list);
1923e1fbd4c1SMat Martineau 
1924e1fbd4c1SMat Martineau 		skb = l2cap_ertm_seq_in_queue(&chan->tx_q, seq);
1925e1fbd4c1SMat Martineau 		if (!skb) {
1926e1fbd4c1SMat Martineau 			BT_DBG("Error: Can't retransmit seq %d, frame missing",
1927e1fbd4c1SMat Martineau 			       seq);
1928e1fbd4c1SMat Martineau 			continue;
1929e1fbd4c1SMat Martineau 		}
1930e1fbd4c1SMat Martineau 
1931e1fbd4c1SMat Martineau 		bt_cb(skb)->control.retries++;
1932e1fbd4c1SMat Martineau 		control = bt_cb(skb)->control;
1933e1fbd4c1SMat Martineau 
1934e1fbd4c1SMat Martineau 		if (chan->max_tx != 0 &&
1935e1fbd4c1SMat Martineau 		    bt_cb(skb)->control.retries > chan->max_tx) {
1936e1fbd4c1SMat Martineau 			BT_DBG("Retry limit exceeded (%d)", chan->max_tx);
19375e4e3972SAndrei Emeltchenko 			l2cap_send_disconn_req(chan, ECONNRESET);
1938e1fbd4c1SMat Martineau 			l2cap_seq_list_clear(&chan->retrans_list);
1939e1fbd4c1SMat Martineau 			break;
1940e1fbd4c1SMat Martineau 		}
1941e1fbd4c1SMat Martineau 
1942e1fbd4c1SMat Martineau 		control.reqseq = chan->buffer_seq;
1943e1fbd4c1SMat Martineau 		if (test_and_clear_bit(CONN_SEND_FBIT, &chan->conn_state))
1944e1fbd4c1SMat Martineau 			control.final = 1;
1945e1fbd4c1SMat Martineau 		else
1946e1fbd4c1SMat Martineau 			control.final = 0;
1947e1fbd4c1SMat Martineau 
1948e1fbd4c1SMat Martineau 		if (skb_cloned(skb)) {
1949e1fbd4c1SMat Martineau 			/* Cloned sk_buffs are read-only, so we need a
1950e1fbd4c1SMat Martineau 			 * writeable copy
1951e1fbd4c1SMat Martineau 			 */
19528bcde1f2SGustavo Padovan 			tx_skb = skb_copy(skb, GFP_KERNEL);
1953e1fbd4c1SMat Martineau 		} else {
19548bcde1f2SGustavo Padovan 			tx_skb = skb_clone(skb, GFP_KERNEL);
1955e1fbd4c1SMat Martineau 		}
1956e1fbd4c1SMat Martineau 
1957e1fbd4c1SMat Martineau 		if (!tx_skb) {
1958e1fbd4c1SMat Martineau 			l2cap_seq_list_clear(&chan->retrans_list);
1959e1fbd4c1SMat Martineau 			break;
1960e1fbd4c1SMat Martineau 		}
1961e1fbd4c1SMat Martineau 
1962e1fbd4c1SMat Martineau 		/* Update skb contents */
1963e1fbd4c1SMat Martineau 		if (test_bit(FLAG_EXT_CTRL, &chan->flags)) {
1964e1fbd4c1SMat Martineau 			put_unaligned_le32(__pack_extended_control(&control),
1965e1fbd4c1SMat Martineau 					   tx_skb->data + L2CAP_HDR_SIZE);
1966e1fbd4c1SMat Martineau 		} else {
1967e1fbd4c1SMat Martineau 			put_unaligned_le16(__pack_enhanced_control(&control),
1968e1fbd4c1SMat Martineau 					   tx_skb->data + L2CAP_HDR_SIZE);
1969e1fbd4c1SMat Martineau 		}
1970e1fbd4c1SMat Martineau 
1971e1fbd4c1SMat Martineau 		if (chan->fcs == L2CAP_FCS_CRC16) {
1972e1fbd4c1SMat Martineau 			u16 fcs = crc16(0, (u8 *) tx_skb->data, tx_skb->len);
1973e1fbd4c1SMat Martineau 			put_unaligned_le16(fcs, skb_put(tx_skb,
1974e1fbd4c1SMat Martineau 							L2CAP_FCS_SIZE));
1975e1fbd4c1SMat Martineau 		}
1976e1fbd4c1SMat Martineau 
1977e1fbd4c1SMat Martineau 		l2cap_do_send(chan, tx_skb);
1978e1fbd4c1SMat Martineau 
1979e1fbd4c1SMat Martineau 		BT_DBG("Resent txseq %d", control.txseq);
1980e1fbd4c1SMat Martineau 
1981e1fbd4c1SMat Martineau 		chan->last_acked_seq = chan->buffer_seq;
1982e1fbd4c1SMat Martineau 	}
1983e1fbd4c1SMat Martineau }
1984e1fbd4c1SMat Martineau 
1985f80842a8SMat Martineau static void l2cap_retransmit(struct l2cap_chan *chan,
1986f80842a8SMat Martineau 			     struct l2cap_ctrl *control)
1987f80842a8SMat Martineau {
1988f80842a8SMat Martineau 	BT_DBG("chan %p, control %p", chan, control);
1989f80842a8SMat Martineau 
1990f80842a8SMat Martineau 	l2cap_seq_list_append(&chan->retrans_list, control->reqseq);
1991f80842a8SMat Martineau 	l2cap_ertm_resend(chan);
1992f80842a8SMat Martineau }
1993f80842a8SMat Martineau 
1994d2a7ac5dSMat Martineau static void l2cap_retransmit_all(struct l2cap_chan *chan,
1995d2a7ac5dSMat Martineau 				 struct l2cap_ctrl *control)
1996d2a7ac5dSMat Martineau {
1997e1fbd4c1SMat Martineau 	struct sk_buff *skb;
1998e1fbd4c1SMat Martineau 
1999e1fbd4c1SMat Martineau 	BT_DBG("chan %p, control %p", chan, control);
2000e1fbd4c1SMat Martineau 
2001e1fbd4c1SMat Martineau 	if (control->poll)
2002e1fbd4c1SMat Martineau 		set_bit(CONN_SEND_FBIT, &chan->conn_state);
2003e1fbd4c1SMat Martineau 
2004e1fbd4c1SMat Martineau 	l2cap_seq_list_clear(&chan->retrans_list);
2005e1fbd4c1SMat Martineau 
2006e1fbd4c1SMat Martineau 	if (test_bit(CONN_REMOTE_BUSY, &chan->conn_state))
2007e1fbd4c1SMat Martineau 		return;
2008e1fbd4c1SMat Martineau 
2009e1fbd4c1SMat Martineau 	if (chan->unacked_frames) {
2010e1fbd4c1SMat Martineau 		skb_queue_walk(&chan->tx_q, skb) {
2011e1fbd4c1SMat Martineau 			if (bt_cb(skb)->control.txseq == control->reqseq ||
2012e1fbd4c1SMat Martineau 			    skb == chan->tx_send_head)
2013e1fbd4c1SMat Martineau 				break;
2014e1fbd4c1SMat Martineau 		}
2015e1fbd4c1SMat Martineau 
2016e1fbd4c1SMat Martineau 		skb_queue_walk_from(&chan->tx_q, skb) {
2017e1fbd4c1SMat Martineau 			if (skb == chan->tx_send_head)
2018e1fbd4c1SMat Martineau 				break;
2019e1fbd4c1SMat Martineau 
2020e1fbd4c1SMat Martineau 			l2cap_seq_list_append(&chan->retrans_list,
2021e1fbd4c1SMat Martineau 					      bt_cb(skb)->control.txseq);
2022e1fbd4c1SMat Martineau 		}
2023e1fbd4c1SMat Martineau 
2024e1fbd4c1SMat Martineau 		l2cap_ertm_resend(chan);
2025e1fbd4c1SMat Martineau 	}
2026d2a7ac5dSMat Martineau }
2027d2a7ac5dSMat Martineau 
2028b17e73bbSSzymon Janc static void l2cap_send_ack(struct l2cap_chan *chan)
2029b17e73bbSSzymon Janc {
20300a0aba42SMat Martineau 	struct l2cap_ctrl control;
20310a0aba42SMat Martineau 	u16 frames_to_ack = __seq_offset(chan, chan->buffer_seq,
20320a0aba42SMat Martineau 					 chan->last_acked_seq);
20330a0aba42SMat Martineau 	int threshold;
20340a0aba42SMat Martineau 
20350a0aba42SMat Martineau 	BT_DBG("chan %p last_acked_seq %d buffer_seq %d",
20360a0aba42SMat Martineau 	       chan, chan->last_acked_seq, chan->buffer_seq);
20370a0aba42SMat Martineau 
20380a0aba42SMat Martineau 	memset(&control, 0, sizeof(control));
20390a0aba42SMat Martineau 	control.sframe = 1;
20400a0aba42SMat Martineau 
20410a0aba42SMat Martineau 	if (test_bit(CONN_LOCAL_BUSY, &chan->conn_state) &&
20420a0aba42SMat Martineau 	    chan->rx_state == L2CAP_RX_STATE_RECV) {
2043b17e73bbSSzymon Janc 		__clear_ack_timer(chan);
20440a0aba42SMat Martineau 		control.super = L2CAP_SUPER_RNR;
20450a0aba42SMat Martineau 		control.reqseq = chan->buffer_seq;
20460a0aba42SMat Martineau 		l2cap_send_sframe(chan, &control);
20470a0aba42SMat Martineau 	} else {
20480a0aba42SMat Martineau 		if (!test_bit(CONN_REMOTE_BUSY, &chan->conn_state)) {
20490a0aba42SMat Martineau 			l2cap_ertm_send(chan);
20500a0aba42SMat Martineau 			/* If any i-frames were sent, they included an ack */
20510a0aba42SMat Martineau 			if (chan->buffer_seq == chan->last_acked_seq)
20520a0aba42SMat Martineau 				frames_to_ack = 0;
20530a0aba42SMat Martineau 		}
20540a0aba42SMat Martineau 
2055c20f8e35SMat Martineau 		/* Ack now if the window is 3/4ths full.
20560a0aba42SMat Martineau 		 * Calculate without mul or div
20570a0aba42SMat Martineau 		 */
2058c20f8e35SMat Martineau 		threshold = chan->ack_win;
20590a0aba42SMat Martineau 		threshold += threshold << 1;
20600a0aba42SMat Martineau 		threshold >>= 2;
20610a0aba42SMat Martineau 
2062b4400672SAndrei Emeltchenko 		BT_DBG("frames_to_ack %u, threshold %d", frames_to_ack,
20630a0aba42SMat Martineau 		       threshold);
20640a0aba42SMat Martineau 
20650a0aba42SMat Martineau 		if (frames_to_ack >= threshold) {
20660a0aba42SMat Martineau 			__clear_ack_timer(chan);
20670a0aba42SMat Martineau 			control.super = L2CAP_SUPER_RR;
20680a0aba42SMat Martineau 			control.reqseq = chan->buffer_seq;
20690a0aba42SMat Martineau 			l2cap_send_sframe(chan, &control);
20700a0aba42SMat Martineau 			frames_to_ack = 0;
20710a0aba42SMat Martineau 		}
20720a0aba42SMat Martineau 
20730a0aba42SMat Martineau 		if (frames_to_ack)
20740a0aba42SMat Martineau 			__set_ack_timer(chan);
20750a0aba42SMat Martineau 	}
2076b17e73bbSSzymon Janc }
2077b17e73bbSSzymon Janc 
207804124681SGustavo F. Padovan static inline int l2cap_skbuff_fromiovec(struct l2cap_chan *chan,
207904124681SGustavo F. Padovan 					 struct msghdr *msg, int len,
208004124681SGustavo F. Padovan 					 int count, struct sk_buff *skb)
20810a708f8fSGustavo F. Padovan {
20820952a57aSAndrei Emeltchenko 	struct l2cap_conn *conn = chan->conn;
20830a708f8fSGustavo F. Padovan 	struct sk_buff **frag;
208490338947SGustavo Padovan 	int sent = 0;
20850a708f8fSGustavo F. Padovan 
20860498878bSJukka Rissanen 	if (chan->ops->memcpy_fromiovec(chan, skb_put(skb, count),
20870498878bSJukka Rissanen 					msg->msg_iov, count))
20880a708f8fSGustavo F. Padovan 		return -EFAULT;
20890a708f8fSGustavo F. Padovan 
20900a708f8fSGustavo F. Padovan 	sent += count;
20910a708f8fSGustavo F. Padovan 	len  -= count;
20920a708f8fSGustavo F. Padovan 
20930a708f8fSGustavo F. Padovan 	/* Continuation fragments (no L2CAP header) */
20940a708f8fSGustavo F. Padovan 	frag = &skb_shinfo(skb)->frag_list;
20950a708f8fSGustavo F. Padovan 	while (len) {
2096fbe00700SGustavo Padovan 		struct sk_buff *tmp;
2097fbe00700SGustavo Padovan 
20980a708f8fSGustavo F. Padovan 		count = min_t(unsigned int, conn->mtu, len);
20990a708f8fSGustavo F. Padovan 
2100d9fbd02bSMarcel Holtmann 		tmp = chan->ops->alloc_skb(chan, 0, count,
210190338947SGustavo Padovan 					   msg->msg_flags & MSG_DONTWAIT);
2102fbe00700SGustavo Padovan 		if (IS_ERR(tmp))
2103fbe00700SGustavo Padovan 			return PTR_ERR(tmp);
21042f7719ceSAndrei Emeltchenko 
2105fbe00700SGustavo Padovan 		*frag = tmp;
2106fbe00700SGustavo Padovan 
21070498878bSJukka Rissanen 		if (chan->ops->memcpy_fromiovec(chan, skb_put(*frag, count),
21080498878bSJukka Rissanen 						msg->msg_iov, count))
21090a708f8fSGustavo F. Padovan 			return -EFAULT;
21100a708f8fSGustavo F. Padovan 
21110a708f8fSGustavo F. Padovan 		sent += count;
21120a708f8fSGustavo F. Padovan 		len  -= count;
21130a708f8fSGustavo F. Padovan 
21142d0ed3d5SGustavo Padovan 		skb->len += (*frag)->len;
21152d0ed3d5SGustavo Padovan 		skb->data_len += (*frag)->len;
21162d0ed3d5SGustavo Padovan 
21170a708f8fSGustavo F. Padovan 		frag = &(*frag)->next;
21180a708f8fSGustavo F. Padovan 	}
21190a708f8fSGustavo F. Padovan 
21200a708f8fSGustavo F. Padovan 	return sent;
21210a708f8fSGustavo F. Padovan }
21220a708f8fSGustavo F. Padovan 
21235e59b791SLuiz Augusto von Dentz static struct sk_buff *l2cap_create_connless_pdu(struct l2cap_chan *chan,
21248d46321cSMarcel Holtmann 						 struct msghdr *msg, size_t len)
21250a708f8fSGustavo F. Padovan {
21268c1d787bSGustavo F. Padovan 	struct l2cap_conn *conn = chan->conn;
21270a708f8fSGustavo F. Padovan 	struct sk_buff *skb;
212803a51213SAndrei Emeltchenko 	int err, count, hlen = L2CAP_HDR_SIZE + L2CAP_PSMLEN_SIZE;
21290a708f8fSGustavo F. Padovan 	struct l2cap_hdr *lh;
21300a708f8fSGustavo F. Padovan 
21318d46321cSMarcel Holtmann 	BT_DBG("chan %p psm 0x%2.2x len %zu", chan,
21328d46321cSMarcel Holtmann 	       __le16_to_cpu(chan->psm), len);
21330a708f8fSGustavo F. Padovan 
21340a708f8fSGustavo F. Padovan 	count = min_t(unsigned int, (conn->mtu - hlen), len);
21352f7719ceSAndrei Emeltchenko 
2136d9fbd02bSMarcel Holtmann 	skb = chan->ops->alloc_skb(chan, hlen, count,
213790338947SGustavo Padovan 				   msg->msg_flags & MSG_DONTWAIT);
213890338947SGustavo Padovan 	if (IS_ERR(skb))
213990338947SGustavo Padovan 		return skb;
21400a708f8fSGustavo F. Padovan 
21410a708f8fSGustavo F. Padovan 	/* Create L2CAP header */
21420a708f8fSGustavo F. Padovan 	lh = (struct l2cap_hdr *) skb_put(skb, L2CAP_HDR_SIZE);
2143fe4128e0SGustavo F. Padovan 	lh->cid = cpu_to_le16(chan->dcid);
2144daf6a78cSAndrei Emeltchenko 	lh->len = cpu_to_le16(len + L2CAP_PSMLEN_SIZE);
214543b1b8dfSMarcel Holtmann 	put_unaligned(chan->psm, (__le16 *) skb_put(skb, L2CAP_PSMLEN_SIZE));
21460a708f8fSGustavo F. Padovan 
21470952a57aSAndrei Emeltchenko 	err = l2cap_skbuff_fromiovec(chan, msg, len, count, skb);
21480a708f8fSGustavo F. Padovan 	if (unlikely(err < 0)) {
21490a708f8fSGustavo F. Padovan 		kfree_skb(skb);
21500a708f8fSGustavo F. Padovan 		return ERR_PTR(err);
21510a708f8fSGustavo F. Padovan 	}
21520a708f8fSGustavo F. Padovan 	return skb;
21530a708f8fSGustavo F. Padovan }
21540a708f8fSGustavo F. Padovan 
21555e59b791SLuiz Augusto von Dentz static struct sk_buff *l2cap_create_basic_pdu(struct l2cap_chan *chan,
21568d46321cSMarcel Holtmann 					      struct msghdr *msg, size_t len)
21570a708f8fSGustavo F. Padovan {
21588c1d787bSGustavo F. Padovan 	struct l2cap_conn *conn = chan->conn;
21590a708f8fSGustavo F. Padovan 	struct sk_buff *skb;
2160f2ba7faeSGustavo Padovan 	int err, count;
21610a708f8fSGustavo F. Padovan 	struct l2cap_hdr *lh;
21620a708f8fSGustavo F. Padovan 
2163b4400672SAndrei Emeltchenko 	BT_DBG("chan %p len %zu", chan, len);
21640a708f8fSGustavo F. Padovan 
2165f2ba7faeSGustavo Padovan 	count = min_t(unsigned int, (conn->mtu - L2CAP_HDR_SIZE), len);
21662f7719ceSAndrei Emeltchenko 
2167d9fbd02bSMarcel Holtmann 	skb = chan->ops->alloc_skb(chan, L2CAP_HDR_SIZE, count,
216890338947SGustavo Padovan 				   msg->msg_flags & MSG_DONTWAIT);
216990338947SGustavo Padovan 	if (IS_ERR(skb))
217090338947SGustavo Padovan 		return skb;
21710a708f8fSGustavo F. Padovan 
21720a708f8fSGustavo F. Padovan 	/* Create L2CAP header */
21730a708f8fSGustavo F. Padovan 	lh = (struct l2cap_hdr *) skb_put(skb, L2CAP_HDR_SIZE);
2174fe4128e0SGustavo F. Padovan 	lh->cid = cpu_to_le16(chan->dcid);
21756ff9b5efSGustavo Padovan 	lh->len = cpu_to_le16(len);
21760a708f8fSGustavo F. Padovan 
21770952a57aSAndrei Emeltchenko 	err = l2cap_skbuff_fromiovec(chan, msg, len, count, skb);
21780a708f8fSGustavo F. Padovan 	if (unlikely(err < 0)) {
21790a708f8fSGustavo F. Padovan 		kfree_skb(skb);
21800a708f8fSGustavo F. Padovan 		return ERR_PTR(err);
21810a708f8fSGustavo F. Padovan 	}
21820a708f8fSGustavo F. Padovan 	return skb;
21830a708f8fSGustavo F. Padovan }
21840a708f8fSGustavo F. Padovan 
2185ab0ff76dSLuiz Augusto von Dentz static struct sk_buff *l2cap_create_iframe_pdu(struct l2cap_chan *chan,
2186ab0ff76dSLuiz Augusto von Dentz 					       struct msghdr *msg, size_t len,
218794122bbeSMat Martineau 					       u16 sdulen)
21880a708f8fSGustavo F. Padovan {
21898c1d787bSGustavo F. Padovan 	struct l2cap_conn *conn = chan->conn;
21900a708f8fSGustavo F. Padovan 	struct sk_buff *skb;
2191e4ca6d98SAndrei Emeltchenko 	int err, count, hlen;
21920a708f8fSGustavo F. Padovan 	struct l2cap_hdr *lh;
21930a708f8fSGustavo F. Padovan 
2194b4400672SAndrei Emeltchenko 	BT_DBG("chan %p len %zu", chan, len);
21950a708f8fSGustavo F. Padovan 
21960a708f8fSGustavo F. Padovan 	if (!conn)
21970a708f8fSGustavo F. Padovan 		return ERR_PTR(-ENOTCONN);
21980a708f8fSGustavo F. Padovan 
2199ba7aa64fSGustavo Padovan 	hlen = __ertm_hdr_size(chan);
2200e4ca6d98SAndrei Emeltchenko 
22010a708f8fSGustavo F. Padovan 	if (sdulen)
220203a51213SAndrei Emeltchenko 		hlen += L2CAP_SDULEN_SIZE;
22030a708f8fSGustavo F. Padovan 
220447d1ec61SGustavo F. Padovan 	if (chan->fcs == L2CAP_FCS_CRC16)
220503a51213SAndrei Emeltchenko 		hlen += L2CAP_FCS_SIZE;
22060a708f8fSGustavo F. Padovan 
22070a708f8fSGustavo F. Padovan 	count = min_t(unsigned int, (conn->mtu - hlen), len);
22082f7719ceSAndrei Emeltchenko 
2209d9fbd02bSMarcel Holtmann 	skb = chan->ops->alloc_skb(chan, hlen, count,
221090338947SGustavo Padovan 				   msg->msg_flags & MSG_DONTWAIT);
221190338947SGustavo Padovan 	if (IS_ERR(skb))
221290338947SGustavo Padovan 		return skb;
22130a708f8fSGustavo F. Padovan 
22140a708f8fSGustavo F. Padovan 	/* Create L2CAP header */
22150a708f8fSGustavo F. Padovan 	lh = (struct l2cap_hdr *) skb_put(skb, L2CAP_HDR_SIZE);
2216fe4128e0SGustavo F. Padovan 	lh->cid = cpu_to_le16(chan->dcid);
22170a708f8fSGustavo F. Padovan 	lh->len = cpu_to_le16(len + (hlen - L2CAP_HDR_SIZE));
221888843ab0SAndrei Emeltchenko 
221918a48e76SMat Martineau 	/* Control header is populated later */
222018a48e76SMat Martineau 	if (test_bit(FLAG_EXT_CTRL, &chan->flags))
222118a48e76SMat Martineau 		put_unaligned_le32(0, skb_put(skb, L2CAP_EXT_CTRL_SIZE));
222218a48e76SMat Martineau 	else
222318a48e76SMat Martineau 		put_unaligned_le16(0, skb_put(skb, L2CAP_ENH_CTRL_SIZE));
222488843ab0SAndrei Emeltchenko 
22250a708f8fSGustavo F. Padovan 	if (sdulen)
222603a51213SAndrei Emeltchenko 		put_unaligned_le16(sdulen, skb_put(skb, L2CAP_SDULEN_SIZE));
22270a708f8fSGustavo F. Padovan 
22280952a57aSAndrei Emeltchenko 	err = l2cap_skbuff_fromiovec(chan, msg, len, count, skb);
22290a708f8fSGustavo F. Padovan 	if (unlikely(err < 0)) {
22300a708f8fSGustavo F. Padovan 		kfree_skb(skb);
22310a708f8fSGustavo F. Padovan 		return ERR_PTR(err);
22320a708f8fSGustavo F. Padovan 	}
22330a708f8fSGustavo F. Padovan 
223418a48e76SMat Martineau 	bt_cb(skb)->control.fcs = chan->fcs;
22353ce3514fSMat Martineau 	bt_cb(skb)->control.retries = 0;
22360a708f8fSGustavo F. Padovan 	return skb;
22370a708f8fSGustavo F. Padovan }
22380a708f8fSGustavo F. Padovan 
223994122bbeSMat Martineau static int l2cap_segment_sdu(struct l2cap_chan *chan,
224094122bbeSMat Martineau 			     struct sk_buff_head *seg_queue,
224194122bbeSMat Martineau 			     struct msghdr *msg, size_t len)
22420a708f8fSGustavo F. Padovan {
22430a708f8fSGustavo F. Padovan 	struct sk_buff *skb;
224494122bbeSMat Martineau 	u16 sdu_len;
224594122bbeSMat Martineau 	size_t pdu_len;
224694122bbeSMat Martineau 	u8 sar;
22470a708f8fSGustavo F. Padovan 
2248b4400672SAndrei Emeltchenko 	BT_DBG("chan %p, msg %p, len %zu", chan, msg, len);
22490a708f8fSGustavo F. Padovan 
225094122bbeSMat Martineau 	/* It is critical that ERTM PDUs fit in a single HCI fragment,
225194122bbeSMat Martineau 	 * so fragmented skbs are not used.  The HCI layer's handling
225294122bbeSMat Martineau 	 * of fragmented skbs is not compatible with ERTM's queueing.
225394122bbeSMat Martineau 	 */
225494122bbeSMat Martineau 
225594122bbeSMat Martineau 	/* PDU size is derived from the HCI MTU */
225694122bbeSMat Martineau 	pdu_len = chan->conn->mtu;
225794122bbeSMat Martineau 
2258a549574dSMat Martineau 	/* Constrain PDU size for BR/EDR connections */
2259a549574dSMat Martineau 	if (!chan->hs_hcon)
226094122bbeSMat Martineau 		pdu_len = min_t(size_t, pdu_len, L2CAP_BREDR_MAX_PAYLOAD);
226194122bbeSMat Martineau 
226294122bbeSMat Martineau 	/* Adjust for largest possible L2CAP overhead. */
226335d401dfSGustavo Padovan 	if (chan->fcs)
226435d401dfSGustavo Padovan 		pdu_len -= L2CAP_FCS_SIZE;
226535d401dfSGustavo Padovan 
2266ba7aa64fSGustavo Padovan 	pdu_len -= __ertm_hdr_size(chan);
226794122bbeSMat Martineau 
226894122bbeSMat Martineau 	/* Remote device may have requested smaller PDUs */
226994122bbeSMat Martineau 	pdu_len = min_t(size_t, pdu_len, chan->remote_mps);
227094122bbeSMat Martineau 
227194122bbeSMat Martineau 	if (len <= pdu_len) {
227294122bbeSMat Martineau 		sar = L2CAP_SAR_UNSEGMENTED;
227394122bbeSMat Martineau 		sdu_len = 0;
227494122bbeSMat Martineau 		pdu_len = len;
227594122bbeSMat Martineau 	} else {
227694122bbeSMat Martineau 		sar = L2CAP_SAR_START;
227794122bbeSMat Martineau 		sdu_len = len;
227894122bbeSMat Martineau 	}
22790a708f8fSGustavo F. Padovan 
22800a708f8fSGustavo F. Padovan 	while (len > 0) {
228194122bbeSMat Martineau 		skb = l2cap_create_iframe_pdu(chan, msg, pdu_len, sdu_len);
22820a708f8fSGustavo F. Padovan 
22830a708f8fSGustavo F. Padovan 		if (IS_ERR(skb)) {
228494122bbeSMat Martineau 			__skb_queue_purge(seg_queue);
22850a708f8fSGustavo F. Padovan 			return PTR_ERR(skb);
22860a708f8fSGustavo F. Padovan 		}
22870a708f8fSGustavo F. Padovan 
228894122bbeSMat Martineau 		bt_cb(skb)->control.sar = sar;
228994122bbeSMat Martineau 		__skb_queue_tail(seg_queue, skb);
22900a708f8fSGustavo F. Padovan 
229194122bbeSMat Martineau 		len -= pdu_len;
2292*069cb270SLukasz Rymanowski 		if (sdu_len)
229394122bbeSMat Martineau 			sdu_len = 0;
229494122bbeSMat Martineau 
229594122bbeSMat Martineau 		if (len <= pdu_len) {
229694122bbeSMat Martineau 			sar = L2CAP_SAR_END;
229794122bbeSMat Martineau 			pdu_len = len;
229894122bbeSMat Martineau 		} else {
229994122bbeSMat Martineau 			sar = L2CAP_SAR_CONTINUE;
230094122bbeSMat Martineau 		}
230194122bbeSMat Martineau 	}
230294122bbeSMat Martineau 
2303f0f62799SGustavo Padovan 	return 0;
23040a708f8fSGustavo F. Padovan }
23050a708f8fSGustavo F. Padovan 
2306177f8f2bSJohan Hedberg static struct sk_buff *l2cap_create_le_flowctl_pdu(struct l2cap_chan *chan,
2307177f8f2bSJohan Hedberg 						   struct msghdr *msg,
2308177f8f2bSJohan Hedberg 						   size_t len, u16 sdulen)
2309177f8f2bSJohan Hedberg {
2310177f8f2bSJohan Hedberg 	struct l2cap_conn *conn = chan->conn;
2311177f8f2bSJohan Hedberg 	struct sk_buff *skb;
2312177f8f2bSJohan Hedberg 	int err, count, hlen;
2313177f8f2bSJohan Hedberg 	struct l2cap_hdr *lh;
2314177f8f2bSJohan Hedberg 
2315177f8f2bSJohan Hedberg 	BT_DBG("chan %p len %zu", chan, len);
2316177f8f2bSJohan Hedberg 
2317177f8f2bSJohan Hedberg 	if (!conn)
2318177f8f2bSJohan Hedberg 		return ERR_PTR(-ENOTCONN);
2319177f8f2bSJohan Hedberg 
2320177f8f2bSJohan Hedberg 	hlen = L2CAP_HDR_SIZE;
2321177f8f2bSJohan Hedberg 
2322177f8f2bSJohan Hedberg 	if (sdulen)
2323177f8f2bSJohan Hedberg 		hlen += L2CAP_SDULEN_SIZE;
2324177f8f2bSJohan Hedberg 
2325177f8f2bSJohan Hedberg 	count = min_t(unsigned int, (conn->mtu - hlen), len);
2326177f8f2bSJohan Hedberg 
2327d9fbd02bSMarcel Holtmann 	skb = chan->ops->alloc_skb(chan, hlen, count,
2328177f8f2bSJohan Hedberg 				   msg->msg_flags & MSG_DONTWAIT);
2329177f8f2bSJohan Hedberg 	if (IS_ERR(skb))
2330177f8f2bSJohan Hedberg 		return skb;
2331177f8f2bSJohan Hedberg 
2332177f8f2bSJohan Hedberg 	/* Create L2CAP header */
2333177f8f2bSJohan Hedberg 	lh = (struct l2cap_hdr *) skb_put(skb, L2CAP_HDR_SIZE);
2334177f8f2bSJohan Hedberg 	lh->cid = cpu_to_le16(chan->dcid);
2335177f8f2bSJohan Hedberg 	lh->len = cpu_to_le16(len + (hlen - L2CAP_HDR_SIZE));
2336177f8f2bSJohan Hedberg 
2337177f8f2bSJohan Hedberg 	if (sdulen)
2338177f8f2bSJohan Hedberg 		put_unaligned_le16(sdulen, skb_put(skb, L2CAP_SDULEN_SIZE));
2339177f8f2bSJohan Hedberg 
2340177f8f2bSJohan Hedberg 	err = l2cap_skbuff_fromiovec(chan, msg, len, count, skb);
2341177f8f2bSJohan Hedberg 	if (unlikely(err < 0)) {
2342177f8f2bSJohan Hedberg 		kfree_skb(skb);
2343177f8f2bSJohan Hedberg 		return ERR_PTR(err);
2344177f8f2bSJohan Hedberg 	}
2345177f8f2bSJohan Hedberg 
2346177f8f2bSJohan Hedberg 	return skb;
2347177f8f2bSJohan Hedberg }
2348177f8f2bSJohan Hedberg 
2349177f8f2bSJohan Hedberg static int l2cap_segment_le_sdu(struct l2cap_chan *chan,
2350177f8f2bSJohan Hedberg 				struct sk_buff_head *seg_queue,
2351177f8f2bSJohan Hedberg 				struct msghdr *msg, size_t len)
2352177f8f2bSJohan Hedberg {
2353177f8f2bSJohan Hedberg 	struct sk_buff *skb;
2354177f8f2bSJohan Hedberg 	size_t pdu_len;
2355177f8f2bSJohan Hedberg 	u16 sdu_len;
2356177f8f2bSJohan Hedberg 
2357177f8f2bSJohan Hedberg 	BT_DBG("chan %p, msg %p, len %zu", chan, msg, len);
2358177f8f2bSJohan Hedberg 
2359177f8f2bSJohan Hedberg 	pdu_len = chan->conn->mtu - L2CAP_HDR_SIZE;
2360177f8f2bSJohan Hedberg 
2361177f8f2bSJohan Hedberg 	pdu_len = min_t(size_t, pdu_len, chan->remote_mps);
2362177f8f2bSJohan Hedberg 
2363177f8f2bSJohan Hedberg 	sdu_len = len;
2364177f8f2bSJohan Hedberg 	pdu_len -= L2CAP_SDULEN_SIZE;
2365177f8f2bSJohan Hedberg 
2366177f8f2bSJohan Hedberg 	while (len > 0) {
2367177f8f2bSJohan Hedberg 		if (len <= pdu_len)
2368177f8f2bSJohan Hedberg 			pdu_len = len;
2369177f8f2bSJohan Hedberg 
2370177f8f2bSJohan Hedberg 		skb = l2cap_create_le_flowctl_pdu(chan, msg, pdu_len, sdu_len);
2371177f8f2bSJohan Hedberg 		if (IS_ERR(skb)) {
2372177f8f2bSJohan Hedberg 			__skb_queue_purge(seg_queue);
2373177f8f2bSJohan Hedberg 			return PTR_ERR(skb);
2374177f8f2bSJohan Hedberg 		}
2375177f8f2bSJohan Hedberg 
2376177f8f2bSJohan Hedberg 		__skb_queue_tail(seg_queue, skb);
2377177f8f2bSJohan Hedberg 
2378177f8f2bSJohan Hedberg 		len -= pdu_len;
2379177f8f2bSJohan Hedberg 
2380177f8f2bSJohan Hedberg 		if (sdu_len) {
2381177f8f2bSJohan Hedberg 			sdu_len = 0;
2382177f8f2bSJohan Hedberg 			pdu_len += L2CAP_SDULEN_SIZE;
2383177f8f2bSJohan Hedberg 		}
2384177f8f2bSJohan Hedberg 	}
2385177f8f2bSJohan Hedberg 
2386177f8f2bSJohan Hedberg 	return 0;
2387177f8f2bSJohan Hedberg }
2388177f8f2bSJohan Hedberg 
23898d46321cSMarcel Holtmann int l2cap_chan_send(struct l2cap_chan *chan, struct msghdr *msg, size_t len)
23909a91a04aSGustavo F. Padovan {
23919a91a04aSGustavo F. Padovan 	struct sk_buff *skb;
23929a91a04aSGustavo F. Padovan 	int err;
239394122bbeSMat Martineau 	struct sk_buff_head seg_queue;
23949a91a04aSGustavo F. Padovan 
239531e8ce80SSeung-Woo Kim 	if (!chan->conn)
239631e8ce80SSeung-Woo Kim 		return -ENOTCONN;
239731e8ce80SSeung-Woo Kim 
23989a91a04aSGustavo F. Padovan 	/* Connectionless channel */
2399715ec005SGustavo F. Padovan 	if (chan->chan_type == L2CAP_CHAN_CONN_LESS) {
24008d46321cSMarcel Holtmann 		skb = l2cap_create_connless_pdu(chan, msg, len);
24019a91a04aSGustavo F. Padovan 		if (IS_ERR(skb))
24029a91a04aSGustavo F. Padovan 			return PTR_ERR(skb);
24039a91a04aSGustavo F. Padovan 
2404ede81a2aSAndrzej Kaczmarek 		/* Channel lock is released before requesting new skb and then
2405ede81a2aSAndrzej Kaczmarek 		 * reacquired thus we need to recheck channel state.
2406ede81a2aSAndrzej Kaczmarek 		 */
2407ede81a2aSAndrzej Kaczmarek 		if (chan->state != BT_CONNECTED) {
2408ede81a2aSAndrzej Kaczmarek 			kfree_skb(skb);
2409ede81a2aSAndrzej Kaczmarek 			return -ENOTCONN;
2410ede81a2aSAndrzej Kaczmarek 		}
2411ede81a2aSAndrzej Kaczmarek 
24129a91a04aSGustavo F. Padovan 		l2cap_do_send(chan, skb);
24139a91a04aSGustavo F. Padovan 		return len;
24149a91a04aSGustavo F. Padovan 	}
24159a91a04aSGustavo F. Padovan 
24169a91a04aSGustavo F. Padovan 	switch (chan->mode) {
241738319713SJohan Hedberg 	case L2CAP_MODE_LE_FLOWCTL:
2418177f8f2bSJohan Hedberg 		/* Check outgoing MTU */
2419177f8f2bSJohan Hedberg 		if (len > chan->omtu)
2420177f8f2bSJohan Hedberg 			return -EMSGSIZE;
2421177f8f2bSJohan Hedberg 
2422fad5fc89SJohan Hedberg 		if (!chan->tx_credits)
2423fad5fc89SJohan Hedberg 			return -EAGAIN;
2424fad5fc89SJohan Hedberg 
2425177f8f2bSJohan Hedberg 		__skb_queue_head_init(&seg_queue);
2426177f8f2bSJohan Hedberg 
2427177f8f2bSJohan Hedberg 		err = l2cap_segment_le_sdu(chan, &seg_queue, msg, len);
2428177f8f2bSJohan Hedberg 
2429177f8f2bSJohan Hedberg 		if (chan->state != BT_CONNECTED) {
2430177f8f2bSJohan Hedberg 			__skb_queue_purge(&seg_queue);
2431177f8f2bSJohan Hedberg 			err = -ENOTCONN;
2432177f8f2bSJohan Hedberg 		}
2433177f8f2bSJohan Hedberg 
2434177f8f2bSJohan Hedberg 		if (err)
2435177f8f2bSJohan Hedberg 			return err;
2436177f8f2bSJohan Hedberg 
2437177f8f2bSJohan Hedberg 		skb_queue_splice_tail_init(&seg_queue, &chan->tx_q);
2438177f8f2bSJohan Hedberg 
2439177f8f2bSJohan Hedberg 		while (chan->tx_credits && !skb_queue_empty(&chan->tx_q)) {
2440177f8f2bSJohan Hedberg 			l2cap_do_send(chan, skb_dequeue(&chan->tx_q));
2441177f8f2bSJohan Hedberg 			chan->tx_credits--;
2442177f8f2bSJohan Hedberg 		}
2443177f8f2bSJohan Hedberg 
2444177f8f2bSJohan Hedberg 		if (!chan->tx_credits)
2445177f8f2bSJohan Hedberg 			chan->ops->suspend(chan);
2446177f8f2bSJohan Hedberg 
2447177f8f2bSJohan Hedberg 		err = len;
2448177f8f2bSJohan Hedberg 
2449177f8f2bSJohan Hedberg 		break;
2450177f8f2bSJohan Hedberg 
2451fad5fc89SJohan Hedberg 	case L2CAP_MODE_BASIC:
24529a91a04aSGustavo F. Padovan 		/* Check outgoing MTU */
24539a91a04aSGustavo F. Padovan 		if (len > chan->omtu)
24549a91a04aSGustavo F. Padovan 			return -EMSGSIZE;
24559a91a04aSGustavo F. Padovan 
24569a91a04aSGustavo F. Padovan 		/* Create a basic PDU */
24578d46321cSMarcel Holtmann 		skb = l2cap_create_basic_pdu(chan, msg, len);
24589a91a04aSGustavo F. Padovan 		if (IS_ERR(skb))
24599a91a04aSGustavo F. Padovan 			return PTR_ERR(skb);
24609a91a04aSGustavo F. Padovan 
2461ede81a2aSAndrzej Kaczmarek 		/* Channel lock is released before requesting new skb and then
2462ede81a2aSAndrzej Kaczmarek 		 * reacquired thus we need to recheck channel state.
2463ede81a2aSAndrzej Kaczmarek 		 */
2464ede81a2aSAndrzej Kaczmarek 		if (chan->state != BT_CONNECTED) {
2465ede81a2aSAndrzej Kaczmarek 			kfree_skb(skb);
2466ede81a2aSAndrzej Kaczmarek 			return -ENOTCONN;
2467ede81a2aSAndrzej Kaczmarek 		}
2468ede81a2aSAndrzej Kaczmarek 
24699a91a04aSGustavo F. Padovan 		l2cap_do_send(chan, skb);
24709a91a04aSGustavo F. Padovan 		err = len;
24719a91a04aSGustavo F. Padovan 		break;
24729a91a04aSGustavo F. Padovan 
24739a91a04aSGustavo F. Padovan 	case L2CAP_MODE_ERTM:
24749a91a04aSGustavo F. Padovan 	case L2CAP_MODE_STREAMING:
247594122bbeSMat Martineau 		/* Check outgoing MTU */
247694122bbeSMat Martineau 		if (len > chan->omtu) {
247794122bbeSMat Martineau 			err = -EMSGSIZE;
24789a91a04aSGustavo F. Padovan 			break;
24799a91a04aSGustavo F. Padovan 		}
24809a91a04aSGustavo F. Padovan 
248194122bbeSMat Martineau 		__skb_queue_head_init(&seg_queue);
248294122bbeSMat Martineau 
248394122bbeSMat Martineau 		/* Do segmentation before calling in to the state machine,
248494122bbeSMat Martineau 		 * since it's possible to block while waiting for memory
248594122bbeSMat Martineau 		 * allocation.
248694122bbeSMat Martineau 		 */
248794122bbeSMat Martineau 		err = l2cap_segment_sdu(chan, &seg_queue, msg, len);
248894122bbeSMat Martineau 
248994122bbeSMat Martineau 		/* The channel could have been closed while segmenting,
249094122bbeSMat Martineau 		 * check that it is still connected.
249194122bbeSMat Martineau 		 */
249294122bbeSMat Martineau 		if (chan->state != BT_CONNECTED) {
249394122bbeSMat Martineau 			__skb_queue_purge(&seg_queue);
249494122bbeSMat Martineau 			err = -ENOTCONN;
24959a91a04aSGustavo F. Padovan 		}
24969a91a04aSGustavo F. Padovan 
249794122bbeSMat Martineau 		if (err)
249894122bbeSMat Martineau 			break;
249994122bbeSMat Martineau 
25003733937dSMat Martineau 		if (chan->mode == L2CAP_MODE_ERTM)
2501d660366dSGustavo Padovan 			l2cap_tx(chan, NULL, &seg_queue, L2CAP_EV_DATA_REQUEST);
25023733937dSMat Martineau 		else
2503d660366dSGustavo Padovan 			l2cap_streaming_send(chan, &seg_queue);
250494122bbeSMat Martineau 
25059a91a04aSGustavo F. Padovan 		err = len;
25069a91a04aSGustavo F. Padovan 
250794122bbeSMat Martineau 		/* If the skbs were not queued for sending, they'll still be in
250894122bbeSMat Martineau 		 * seg_queue and need to be purged.
250994122bbeSMat Martineau 		 */
251094122bbeSMat Martineau 		__skb_queue_purge(&seg_queue);
25119a91a04aSGustavo F. Padovan 		break;
25129a91a04aSGustavo F. Padovan 
25139a91a04aSGustavo F. Padovan 	default:
25149a91a04aSGustavo F. Padovan 		BT_DBG("bad state %1.1x", chan->mode);
25159a91a04aSGustavo F. Padovan 		err = -EBADFD;
25169a91a04aSGustavo F. Padovan 	}
25179a91a04aSGustavo F. Padovan 
25189a91a04aSGustavo F. Padovan 	return err;
25199a91a04aSGustavo F. Padovan }
25206b8d4a6aSJukka Rissanen EXPORT_SYMBOL_GPL(l2cap_chan_send);
25219a91a04aSGustavo F. Padovan 
2522d2a7ac5dSMat Martineau static void l2cap_send_srej(struct l2cap_chan *chan, u16 txseq)
2523d2a7ac5dSMat Martineau {
2524bed68bdeSMat Martineau 	struct l2cap_ctrl control;
2525bed68bdeSMat Martineau 	u16 seq;
2526bed68bdeSMat Martineau 
2527b4400672SAndrei Emeltchenko 	BT_DBG("chan %p, txseq %u", chan, txseq);
2528bed68bdeSMat Martineau 
2529bed68bdeSMat Martineau 	memset(&control, 0, sizeof(control));
2530bed68bdeSMat Martineau 	control.sframe = 1;
2531bed68bdeSMat Martineau 	control.super = L2CAP_SUPER_SREJ;
2532bed68bdeSMat Martineau 
2533bed68bdeSMat Martineau 	for (seq = chan->expected_tx_seq; seq != txseq;
2534bed68bdeSMat Martineau 	     seq = __next_seq(chan, seq)) {
2535bed68bdeSMat Martineau 		if (!l2cap_ertm_seq_in_queue(&chan->srej_q, seq)) {
2536bed68bdeSMat Martineau 			control.reqseq = seq;
2537bed68bdeSMat Martineau 			l2cap_send_sframe(chan, &control);
2538bed68bdeSMat Martineau 			l2cap_seq_list_append(&chan->srej_list, seq);
2539bed68bdeSMat Martineau 		}
2540bed68bdeSMat Martineau 	}
2541bed68bdeSMat Martineau 
2542bed68bdeSMat Martineau 	chan->expected_tx_seq = __next_seq(chan, txseq);
2543d2a7ac5dSMat Martineau }
2544d2a7ac5dSMat Martineau 
2545d2a7ac5dSMat Martineau static void l2cap_send_srej_tail(struct l2cap_chan *chan)
2546d2a7ac5dSMat Martineau {
2547bed68bdeSMat Martineau 	struct l2cap_ctrl control;
2548bed68bdeSMat Martineau 
2549bed68bdeSMat Martineau 	BT_DBG("chan %p", chan);
2550bed68bdeSMat Martineau 
2551bed68bdeSMat Martineau 	if (chan->srej_list.tail == L2CAP_SEQ_LIST_CLEAR)
2552bed68bdeSMat Martineau 		return;
2553bed68bdeSMat Martineau 
2554bed68bdeSMat Martineau 	memset(&control, 0, sizeof(control));
2555bed68bdeSMat Martineau 	control.sframe = 1;
2556bed68bdeSMat Martineau 	control.super = L2CAP_SUPER_SREJ;
2557bed68bdeSMat Martineau 	control.reqseq = chan->srej_list.tail;
2558bed68bdeSMat Martineau 	l2cap_send_sframe(chan, &control);
2559d2a7ac5dSMat Martineau }
2560d2a7ac5dSMat Martineau 
2561d2a7ac5dSMat Martineau static void l2cap_send_srej_list(struct l2cap_chan *chan, u16 txseq)
2562d2a7ac5dSMat Martineau {
2563bed68bdeSMat Martineau 	struct l2cap_ctrl control;
2564bed68bdeSMat Martineau 	u16 initial_head;
2565bed68bdeSMat Martineau 	u16 seq;
2566bed68bdeSMat Martineau 
2567b4400672SAndrei Emeltchenko 	BT_DBG("chan %p, txseq %u", chan, txseq);
2568bed68bdeSMat Martineau 
2569bed68bdeSMat Martineau 	memset(&control, 0, sizeof(control));
2570bed68bdeSMat Martineau 	control.sframe = 1;
2571bed68bdeSMat Martineau 	control.super = L2CAP_SUPER_SREJ;
2572bed68bdeSMat Martineau 
2573bed68bdeSMat Martineau 	/* Capture initial list head to allow only one pass through the list. */
2574bed68bdeSMat Martineau 	initial_head = chan->srej_list.head;
2575bed68bdeSMat Martineau 
2576bed68bdeSMat Martineau 	do {
2577bed68bdeSMat Martineau 		seq = l2cap_seq_list_pop(&chan->srej_list);
2578bed68bdeSMat Martineau 		if (seq == txseq || seq == L2CAP_SEQ_LIST_CLEAR)
2579bed68bdeSMat Martineau 			break;
2580bed68bdeSMat Martineau 
2581bed68bdeSMat Martineau 		control.reqseq = seq;
2582bed68bdeSMat Martineau 		l2cap_send_sframe(chan, &control);
2583bed68bdeSMat Martineau 		l2cap_seq_list_append(&chan->srej_list, seq);
2584bed68bdeSMat Martineau 	} while (chan->srej_list.head != initial_head);
2585d2a7ac5dSMat Martineau }
2586d2a7ac5dSMat Martineau 
2587608bcc6dSMat Martineau static void l2cap_process_reqseq(struct l2cap_chan *chan, u16 reqseq)
2588608bcc6dSMat Martineau {
2589608bcc6dSMat Martineau 	struct sk_buff *acked_skb;
2590608bcc6dSMat Martineau 	u16 ackseq;
2591608bcc6dSMat Martineau 
2592b4400672SAndrei Emeltchenko 	BT_DBG("chan %p, reqseq %u", chan, reqseq);
2593608bcc6dSMat Martineau 
2594608bcc6dSMat Martineau 	if (chan->unacked_frames == 0 || reqseq == chan->expected_ack_seq)
2595608bcc6dSMat Martineau 		return;
2596608bcc6dSMat Martineau 
2597b4400672SAndrei Emeltchenko 	BT_DBG("expected_ack_seq %u, unacked_frames %u",
2598608bcc6dSMat Martineau 	       chan->expected_ack_seq, chan->unacked_frames);
2599608bcc6dSMat Martineau 
2600608bcc6dSMat Martineau 	for (ackseq = chan->expected_ack_seq; ackseq != reqseq;
2601608bcc6dSMat Martineau 	     ackseq = __next_seq(chan, ackseq)) {
2602608bcc6dSMat Martineau 
2603608bcc6dSMat Martineau 		acked_skb = l2cap_ertm_seq_in_queue(&chan->tx_q, ackseq);
2604608bcc6dSMat Martineau 		if (acked_skb) {
2605608bcc6dSMat Martineau 			skb_unlink(acked_skb, &chan->tx_q);
2606608bcc6dSMat Martineau 			kfree_skb(acked_skb);
2607608bcc6dSMat Martineau 			chan->unacked_frames--;
2608608bcc6dSMat Martineau 		}
2609608bcc6dSMat Martineau 	}
2610608bcc6dSMat Martineau 
2611608bcc6dSMat Martineau 	chan->expected_ack_seq = reqseq;
2612608bcc6dSMat Martineau 
2613608bcc6dSMat Martineau 	if (chan->unacked_frames == 0)
2614608bcc6dSMat Martineau 		__clear_retrans_timer(chan);
2615608bcc6dSMat Martineau 
2616b4400672SAndrei Emeltchenko 	BT_DBG("unacked_frames %u", chan->unacked_frames);
2617608bcc6dSMat Martineau }
2618608bcc6dSMat Martineau 
2619608bcc6dSMat Martineau static void l2cap_abort_rx_srej_sent(struct l2cap_chan *chan)
2620608bcc6dSMat Martineau {
2621608bcc6dSMat Martineau 	BT_DBG("chan %p", chan);
2622608bcc6dSMat Martineau 
2623608bcc6dSMat Martineau 	chan->expected_tx_seq = chan->buffer_seq;
2624608bcc6dSMat Martineau 	l2cap_seq_list_clear(&chan->srej_list);
2625608bcc6dSMat Martineau 	skb_queue_purge(&chan->srej_q);
2626608bcc6dSMat Martineau 	chan->rx_state = L2CAP_RX_STATE_RECV;
2627608bcc6dSMat Martineau }
2628608bcc6dSMat Martineau 
2629d660366dSGustavo Padovan static void l2cap_tx_state_xmit(struct l2cap_chan *chan,
2630608bcc6dSMat Martineau 				struct l2cap_ctrl *control,
2631608bcc6dSMat Martineau 				struct sk_buff_head *skbs, u8 event)
2632608bcc6dSMat Martineau {
2633608bcc6dSMat Martineau 	BT_DBG("chan %p, control %p, skbs %p, event %d", chan, control, skbs,
2634608bcc6dSMat Martineau 	       event);
2635608bcc6dSMat Martineau 
2636608bcc6dSMat Martineau 	switch (event) {
2637608bcc6dSMat Martineau 	case L2CAP_EV_DATA_REQUEST:
2638608bcc6dSMat Martineau 		if (chan->tx_send_head == NULL)
2639608bcc6dSMat Martineau 			chan->tx_send_head = skb_peek(skbs);
2640608bcc6dSMat Martineau 
2641608bcc6dSMat Martineau 		skb_queue_splice_tail_init(skbs, &chan->tx_q);
2642608bcc6dSMat Martineau 		l2cap_ertm_send(chan);
2643608bcc6dSMat Martineau 		break;
2644608bcc6dSMat Martineau 	case L2CAP_EV_LOCAL_BUSY_DETECTED:
2645608bcc6dSMat Martineau 		BT_DBG("Enter LOCAL_BUSY");
2646608bcc6dSMat Martineau 		set_bit(CONN_LOCAL_BUSY, &chan->conn_state);
2647608bcc6dSMat Martineau 
2648608bcc6dSMat Martineau 		if (chan->rx_state == L2CAP_RX_STATE_SREJ_SENT) {
2649608bcc6dSMat Martineau 			/* The SREJ_SENT state must be aborted if we are to
2650608bcc6dSMat Martineau 			 * enter the LOCAL_BUSY state.
2651608bcc6dSMat Martineau 			 */
2652608bcc6dSMat Martineau 			l2cap_abort_rx_srej_sent(chan);
2653608bcc6dSMat Martineau 		}
2654608bcc6dSMat Martineau 
2655608bcc6dSMat Martineau 		l2cap_send_ack(chan);
2656608bcc6dSMat Martineau 
2657608bcc6dSMat Martineau 		break;
2658608bcc6dSMat Martineau 	case L2CAP_EV_LOCAL_BUSY_CLEAR:
2659608bcc6dSMat Martineau 		BT_DBG("Exit LOCAL_BUSY");
2660608bcc6dSMat Martineau 		clear_bit(CONN_LOCAL_BUSY, &chan->conn_state);
2661608bcc6dSMat Martineau 
2662608bcc6dSMat Martineau 		if (test_bit(CONN_RNR_SENT, &chan->conn_state)) {
2663608bcc6dSMat Martineau 			struct l2cap_ctrl local_control;
2664608bcc6dSMat Martineau 
2665608bcc6dSMat Martineau 			memset(&local_control, 0, sizeof(local_control));
2666608bcc6dSMat Martineau 			local_control.sframe = 1;
2667608bcc6dSMat Martineau 			local_control.super = L2CAP_SUPER_RR;
2668608bcc6dSMat Martineau 			local_control.poll = 1;
2669608bcc6dSMat Martineau 			local_control.reqseq = chan->buffer_seq;
2670a67d7f6fSMat Martineau 			l2cap_send_sframe(chan, &local_control);
2671608bcc6dSMat Martineau 
2672608bcc6dSMat Martineau 			chan->retry_count = 1;
2673608bcc6dSMat Martineau 			__set_monitor_timer(chan);
2674608bcc6dSMat Martineau 			chan->tx_state = L2CAP_TX_STATE_WAIT_F;
2675608bcc6dSMat Martineau 		}
2676608bcc6dSMat Martineau 		break;
2677608bcc6dSMat Martineau 	case L2CAP_EV_RECV_REQSEQ_AND_FBIT:
2678608bcc6dSMat Martineau 		l2cap_process_reqseq(chan, control->reqseq);
2679608bcc6dSMat Martineau 		break;
2680608bcc6dSMat Martineau 	case L2CAP_EV_EXPLICIT_POLL:
2681608bcc6dSMat Martineau 		l2cap_send_rr_or_rnr(chan, 1);
2682608bcc6dSMat Martineau 		chan->retry_count = 1;
2683608bcc6dSMat Martineau 		__set_monitor_timer(chan);
2684608bcc6dSMat Martineau 		__clear_ack_timer(chan);
2685608bcc6dSMat Martineau 		chan->tx_state = L2CAP_TX_STATE_WAIT_F;
2686608bcc6dSMat Martineau 		break;
2687608bcc6dSMat Martineau 	case L2CAP_EV_RETRANS_TO:
2688608bcc6dSMat Martineau 		l2cap_send_rr_or_rnr(chan, 1);
2689608bcc6dSMat Martineau 		chan->retry_count = 1;
2690608bcc6dSMat Martineau 		__set_monitor_timer(chan);
2691608bcc6dSMat Martineau 		chan->tx_state = L2CAP_TX_STATE_WAIT_F;
2692608bcc6dSMat Martineau 		break;
2693608bcc6dSMat Martineau 	case L2CAP_EV_RECV_FBIT:
2694608bcc6dSMat Martineau 		/* Nothing to process */
2695608bcc6dSMat Martineau 		break;
2696608bcc6dSMat Martineau 	default:
2697608bcc6dSMat Martineau 		break;
2698608bcc6dSMat Martineau 	}
2699608bcc6dSMat Martineau }
2700608bcc6dSMat Martineau 
2701d660366dSGustavo Padovan static void l2cap_tx_state_wait_f(struct l2cap_chan *chan,
2702608bcc6dSMat Martineau 				  struct l2cap_ctrl *control,
2703608bcc6dSMat Martineau 				  struct sk_buff_head *skbs, u8 event)
2704608bcc6dSMat Martineau {
2705608bcc6dSMat Martineau 	BT_DBG("chan %p, control %p, skbs %p, event %d", chan, control, skbs,
2706608bcc6dSMat Martineau 	       event);
2707608bcc6dSMat Martineau 
2708608bcc6dSMat Martineau 	switch (event) {
2709608bcc6dSMat Martineau 	case L2CAP_EV_DATA_REQUEST:
2710608bcc6dSMat Martineau 		if (chan->tx_send_head == NULL)
2711608bcc6dSMat Martineau 			chan->tx_send_head = skb_peek(skbs);
2712608bcc6dSMat Martineau 		/* Queue data, but don't send. */
2713608bcc6dSMat Martineau 		skb_queue_splice_tail_init(skbs, &chan->tx_q);
2714608bcc6dSMat Martineau 		break;
2715608bcc6dSMat Martineau 	case L2CAP_EV_LOCAL_BUSY_DETECTED:
2716608bcc6dSMat Martineau 		BT_DBG("Enter LOCAL_BUSY");
2717608bcc6dSMat Martineau 		set_bit(CONN_LOCAL_BUSY, &chan->conn_state);
2718608bcc6dSMat Martineau 
2719608bcc6dSMat Martineau 		if (chan->rx_state == L2CAP_RX_STATE_SREJ_SENT) {
2720608bcc6dSMat Martineau 			/* The SREJ_SENT state must be aborted if we are to
2721608bcc6dSMat Martineau 			 * enter the LOCAL_BUSY state.
2722608bcc6dSMat Martineau 			 */
2723608bcc6dSMat Martineau 			l2cap_abort_rx_srej_sent(chan);
2724608bcc6dSMat Martineau 		}
2725608bcc6dSMat Martineau 
2726608bcc6dSMat Martineau 		l2cap_send_ack(chan);
2727608bcc6dSMat Martineau 
2728608bcc6dSMat Martineau 		break;
2729608bcc6dSMat Martineau 	case L2CAP_EV_LOCAL_BUSY_CLEAR:
2730608bcc6dSMat Martineau 		BT_DBG("Exit LOCAL_BUSY");
2731608bcc6dSMat Martineau 		clear_bit(CONN_LOCAL_BUSY, &chan->conn_state);
2732608bcc6dSMat Martineau 
2733608bcc6dSMat Martineau 		if (test_bit(CONN_RNR_SENT, &chan->conn_state)) {
2734608bcc6dSMat Martineau 			struct l2cap_ctrl local_control;
2735608bcc6dSMat Martineau 			memset(&local_control, 0, sizeof(local_control));
2736608bcc6dSMat Martineau 			local_control.sframe = 1;
2737608bcc6dSMat Martineau 			local_control.super = L2CAP_SUPER_RR;
2738608bcc6dSMat Martineau 			local_control.poll = 1;
2739608bcc6dSMat Martineau 			local_control.reqseq = chan->buffer_seq;
2740a67d7f6fSMat Martineau 			l2cap_send_sframe(chan, &local_control);
2741608bcc6dSMat Martineau 
2742608bcc6dSMat Martineau 			chan->retry_count = 1;
2743608bcc6dSMat Martineau 			__set_monitor_timer(chan);
2744608bcc6dSMat Martineau 			chan->tx_state = L2CAP_TX_STATE_WAIT_F;
2745608bcc6dSMat Martineau 		}
2746608bcc6dSMat Martineau 		break;
2747608bcc6dSMat Martineau 	case L2CAP_EV_RECV_REQSEQ_AND_FBIT:
2748608bcc6dSMat Martineau 		l2cap_process_reqseq(chan, control->reqseq);
2749608bcc6dSMat Martineau 
2750608bcc6dSMat Martineau 		/* Fall through */
2751608bcc6dSMat Martineau 
2752608bcc6dSMat Martineau 	case L2CAP_EV_RECV_FBIT:
2753608bcc6dSMat Martineau 		if (control && control->final) {
2754608bcc6dSMat Martineau 			__clear_monitor_timer(chan);
2755608bcc6dSMat Martineau 			if (chan->unacked_frames > 0)
2756608bcc6dSMat Martineau 				__set_retrans_timer(chan);
2757608bcc6dSMat Martineau 			chan->retry_count = 0;
2758608bcc6dSMat Martineau 			chan->tx_state = L2CAP_TX_STATE_XMIT;
2759608bcc6dSMat Martineau 			BT_DBG("recv fbit tx_state 0x2.2%x", chan->tx_state);
2760608bcc6dSMat Martineau 		}
2761608bcc6dSMat Martineau 		break;
2762608bcc6dSMat Martineau 	case L2CAP_EV_EXPLICIT_POLL:
2763608bcc6dSMat Martineau 		/* Ignore */
2764608bcc6dSMat Martineau 		break;
2765608bcc6dSMat Martineau 	case L2CAP_EV_MONITOR_TO:
2766608bcc6dSMat Martineau 		if (chan->max_tx == 0 || chan->retry_count < chan->max_tx) {
2767608bcc6dSMat Martineau 			l2cap_send_rr_or_rnr(chan, 1);
2768608bcc6dSMat Martineau 			__set_monitor_timer(chan);
2769608bcc6dSMat Martineau 			chan->retry_count++;
2770608bcc6dSMat Martineau 		} else {
27715e4e3972SAndrei Emeltchenko 			l2cap_send_disconn_req(chan, ECONNABORTED);
2772608bcc6dSMat Martineau 		}
2773608bcc6dSMat Martineau 		break;
2774608bcc6dSMat Martineau 	default:
2775608bcc6dSMat Martineau 		break;
2776608bcc6dSMat Martineau 	}
2777608bcc6dSMat Martineau }
2778608bcc6dSMat Martineau 
2779d660366dSGustavo Padovan static void l2cap_tx(struct l2cap_chan *chan, struct l2cap_ctrl *control,
2780608bcc6dSMat Martineau 		     struct sk_buff_head *skbs, u8 event)
2781608bcc6dSMat Martineau {
2782608bcc6dSMat Martineau 	BT_DBG("chan %p, control %p, skbs %p, event %d, state %d",
2783608bcc6dSMat Martineau 	       chan, control, skbs, event, chan->tx_state);
2784608bcc6dSMat Martineau 
2785608bcc6dSMat Martineau 	switch (chan->tx_state) {
2786608bcc6dSMat Martineau 	case L2CAP_TX_STATE_XMIT:
2787d660366dSGustavo Padovan 		l2cap_tx_state_xmit(chan, control, skbs, event);
2788608bcc6dSMat Martineau 		break;
2789608bcc6dSMat Martineau 	case L2CAP_TX_STATE_WAIT_F:
2790d660366dSGustavo Padovan 		l2cap_tx_state_wait_f(chan, control, skbs, event);
2791608bcc6dSMat Martineau 		break;
2792608bcc6dSMat Martineau 	default:
2793608bcc6dSMat Martineau 		/* Ignore event */
2794608bcc6dSMat Martineau 		break;
2795608bcc6dSMat Martineau 	}
2796608bcc6dSMat Martineau }
2797608bcc6dSMat Martineau 
27984b51dae9SMat Martineau static void l2cap_pass_to_tx(struct l2cap_chan *chan,
27994b51dae9SMat Martineau 			     struct l2cap_ctrl *control)
28004b51dae9SMat Martineau {
28014b51dae9SMat Martineau 	BT_DBG("chan %p, control %p", chan, control);
2802401bb1f7SAndrei Emeltchenko 	l2cap_tx(chan, control, NULL, L2CAP_EV_RECV_REQSEQ_AND_FBIT);
28034b51dae9SMat Martineau }
28044b51dae9SMat Martineau 
2805f80842a8SMat Martineau static void l2cap_pass_to_tx_fbit(struct l2cap_chan *chan,
2806f80842a8SMat Martineau 				  struct l2cap_ctrl *control)
2807f80842a8SMat Martineau {
2808f80842a8SMat Martineau 	BT_DBG("chan %p, control %p", chan, control);
2809401bb1f7SAndrei Emeltchenko 	l2cap_tx(chan, control, NULL, L2CAP_EV_RECV_FBIT);
2810f80842a8SMat Martineau }
2811f80842a8SMat Martineau 
28120a708f8fSGustavo F. Padovan /* Copy frame to all raw sockets on that connection */
28130a708f8fSGustavo F. Padovan static void l2cap_raw_recv(struct l2cap_conn *conn, struct sk_buff *skb)
28140a708f8fSGustavo F. Padovan {
28150a708f8fSGustavo F. Padovan 	struct sk_buff *nskb;
281648454079SGustavo F. Padovan 	struct l2cap_chan *chan;
28170a708f8fSGustavo F. Padovan 
28180a708f8fSGustavo F. Padovan 	BT_DBG("conn %p", conn);
28190a708f8fSGustavo F. Padovan 
28203df91ea2SAndrei Emeltchenko 	mutex_lock(&conn->chan_lock);
28213d57dc68SGustavo F. Padovan 
28223df91ea2SAndrei Emeltchenko 	list_for_each_entry(chan, &conn->chan_l, list) {
2823715ec005SGustavo F. Padovan 		if (chan->chan_type != L2CAP_CHAN_RAW)
28240a708f8fSGustavo F. Padovan 			continue;
28250a708f8fSGustavo F. Padovan 
28267f5396a7SGustavo Padovan 		/* Don't send frame to the channel it came from */
28277f5396a7SGustavo Padovan 		if (bt_cb(skb)->chan == chan)
28280a708f8fSGustavo F. Padovan 			continue;
28297f5396a7SGustavo Padovan 
28308bcde1f2SGustavo Padovan 		nskb = skb_clone(skb, GFP_KERNEL);
28310a708f8fSGustavo F. Padovan 		if (!nskb)
28320a708f8fSGustavo F. Padovan 			continue;
283380b98027SGustavo Padovan 		if (chan->ops->recv(chan, nskb))
28340a708f8fSGustavo F. Padovan 			kfree_skb(nskb);
28350a708f8fSGustavo F. Padovan 	}
28363d57dc68SGustavo F. Padovan 
28373df91ea2SAndrei Emeltchenko 	mutex_unlock(&conn->chan_lock);
28380a708f8fSGustavo F. Padovan }
28390a708f8fSGustavo F. Padovan 
28400a708f8fSGustavo F. Padovan /* ---- L2CAP signalling commands ---- */
2841b4400672SAndrei Emeltchenko static struct sk_buff *l2cap_build_cmd(struct l2cap_conn *conn, u8 code,
2842b4400672SAndrei Emeltchenko 				       u8 ident, u16 dlen, void *data)
28430a708f8fSGustavo F. Padovan {
28440a708f8fSGustavo F. Padovan 	struct sk_buff *skb, **frag;
28450a708f8fSGustavo F. Padovan 	struct l2cap_cmd_hdr *cmd;
28460a708f8fSGustavo F. Padovan 	struct l2cap_hdr *lh;
28470a708f8fSGustavo F. Padovan 	int len, count;
28480a708f8fSGustavo F. Padovan 
2849b4400672SAndrei Emeltchenko 	BT_DBG("conn %p, code 0x%2.2x, ident 0x%2.2x, len %u",
28500a708f8fSGustavo F. Padovan 	       conn, code, ident, dlen);
28510a708f8fSGustavo F. Padovan 
2852300b962eSAnderson Lizardo 	if (conn->mtu < L2CAP_HDR_SIZE + L2CAP_CMD_HDR_SIZE)
2853300b962eSAnderson Lizardo 		return NULL;
2854300b962eSAnderson Lizardo 
28550a708f8fSGustavo F. Padovan 	len = L2CAP_HDR_SIZE + L2CAP_CMD_HDR_SIZE + dlen;
28560a708f8fSGustavo F. Padovan 	count = min_t(unsigned int, conn->mtu, len);
28570a708f8fSGustavo F. Padovan 
28588bcde1f2SGustavo Padovan 	skb = bt_skb_alloc(count, GFP_KERNEL);
28590a708f8fSGustavo F. Padovan 	if (!skb)
28600a708f8fSGustavo F. Padovan 		return NULL;
28610a708f8fSGustavo F. Padovan 
28620a708f8fSGustavo F. Padovan 	lh = (struct l2cap_hdr *) skb_put(skb, L2CAP_HDR_SIZE);
28630a708f8fSGustavo F. Padovan 	lh->len = cpu_to_le16(L2CAP_CMD_HDR_SIZE + dlen);
28643300d9a9SClaudio Takahasi 
28653300d9a9SClaudio Takahasi 	if (conn->hcon->type == LE_LINK)
2866dcf4adbfSJoe Perches 		lh->cid = cpu_to_le16(L2CAP_CID_LE_SIGNALING);
28673300d9a9SClaudio Takahasi 	else
2868dcf4adbfSJoe Perches 		lh->cid = cpu_to_le16(L2CAP_CID_SIGNALING);
28690a708f8fSGustavo F. Padovan 
28700a708f8fSGustavo F. Padovan 	cmd = (struct l2cap_cmd_hdr *) skb_put(skb, L2CAP_CMD_HDR_SIZE);
28710a708f8fSGustavo F. Padovan 	cmd->code  = code;
28720a708f8fSGustavo F. Padovan 	cmd->ident = ident;
28730a708f8fSGustavo F. Padovan 	cmd->len   = cpu_to_le16(dlen);
28740a708f8fSGustavo F. Padovan 
28750a708f8fSGustavo F. Padovan 	if (dlen) {
28760a708f8fSGustavo F. Padovan 		count -= L2CAP_HDR_SIZE + L2CAP_CMD_HDR_SIZE;
28770a708f8fSGustavo F. Padovan 		memcpy(skb_put(skb, count), data, count);
28780a708f8fSGustavo F. Padovan 		data += count;
28790a708f8fSGustavo F. Padovan 	}
28800a708f8fSGustavo F. Padovan 
28810a708f8fSGustavo F. Padovan 	len -= skb->len;
28820a708f8fSGustavo F. Padovan 
28830a708f8fSGustavo F. Padovan 	/* Continuation fragments (no L2CAP header) */
28840a708f8fSGustavo F. Padovan 	frag = &skb_shinfo(skb)->frag_list;
28850a708f8fSGustavo F. Padovan 	while (len) {
28860a708f8fSGustavo F. Padovan 		count = min_t(unsigned int, conn->mtu, len);
28870a708f8fSGustavo F. Padovan 
28888bcde1f2SGustavo Padovan 		*frag = bt_skb_alloc(count, GFP_KERNEL);
28890a708f8fSGustavo F. Padovan 		if (!*frag)
28900a708f8fSGustavo F. Padovan 			goto fail;
28910a708f8fSGustavo F. Padovan 
28920a708f8fSGustavo F. Padovan 		memcpy(skb_put(*frag, count), data, count);
28930a708f8fSGustavo F. Padovan 
28940a708f8fSGustavo F. Padovan 		len  -= count;
28950a708f8fSGustavo F. Padovan 		data += count;
28960a708f8fSGustavo F. Padovan 
28970a708f8fSGustavo F. Padovan 		frag = &(*frag)->next;
28980a708f8fSGustavo F. Padovan 	}
28990a708f8fSGustavo F. Padovan 
29000a708f8fSGustavo F. Padovan 	return skb;
29010a708f8fSGustavo F. Padovan 
29020a708f8fSGustavo F. Padovan fail:
29030a708f8fSGustavo F. Padovan 	kfree_skb(skb);
29040a708f8fSGustavo F. Padovan 	return NULL;
29050a708f8fSGustavo F. Padovan }
29060a708f8fSGustavo F. Padovan 
29072d792818SGustavo Padovan static inline int l2cap_get_conf_opt(void **ptr, int *type, int *olen,
29082d792818SGustavo Padovan 				     unsigned long *val)
29090a708f8fSGustavo F. Padovan {
29100a708f8fSGustavo F. Padovan 	struct l2cap_conf_opt *opt = *ptr;
29110a708f8fSGustavo F. Padovan 	int len;
29120a708f8fSGustavo F. Padovan 
29130a708f8fSGustavo F. Padovan 	len = L2CAP_CONF_OPT_SIZE + opt->len;
29140a708f8fSGustavo F. Padovan 	*ptr += len;
29150a708f8fSGustavo F. Padovan 
29160a708f8fSGustavo F. Padovan 	*type = opt->type;
29170a708f8fSGustavo F. Padovan 	*olen = opt->len;
29180a708f8fSGustavo F. Padovan 
29190a708f8fSGustavo F. Padovan 	switch (opt->len) {
29200a708f8fSGustavo F. Padovan 	case 1:
29210a708f8fSGustavo F. Padovan 		*val = *((u8 *) opt->val);
29220a708f8fSGustavo F. Padovan 		break;
29230a708f8fSGustavo F. Padovan 
29240a708f8fSGustavo F. Padovan 	case 2:
29250a708f8fSGustavo F. Padovan 		*val = get_unaligned_le16(opt->val);
29260a708f8fSGustavo F. Padovan 		break;
29270a708f8fSGustavo F. Padovan 
29280a708f8fSGustavo F. Padovan 	case 4:
29290a708f8fSGustavo F. Padovan 		*val = get_unaligned_le32(opt->val);
29300a708f8fSGustavo F. Padovan 		break;
29310a708f8fSGustavo F. Padovan 
29320a708f8fSGustavo F. Padovan 	default:
29330a708f8fSGustavo F. Padovan 		*val = (unsigned long) opt->val;
29340a708f8fSGustavo F. Padovan 		break;
29350a708f8fSGustavo F. Padovan 	}
29360a708f8fSGustavo F. Padovan 
2937b4400672SAndrei Emeltchenko 	BT_DBG("type 0x%2.2x len %u val 0x%lx", *type, opt->len, *val);
29380a708f8fSGustavo F. Padovan 	return len;
29390a708f8fSGustavo F. Padovan }
29400a708f8fSGustavo F. Padovan 
29410a708f8fSGustavo F. Padovan static void l2cap_add_conf_opt(void **ptr, u8 type, u8 len, unsigned long val)
29420a708f8fSGustavo F. Padovan {
29430a708f8fSGustavo F. Padovan 	struct l2cap_conf_opt *opt = *ptr;
29440a708f8fSGustavo F. Padovan 
2945b4400672SAndrei Emeltchenko 	BT_DBG("type 0x%2.2x len %u val 0x%lx", type, len, val);
29460a708f8fSGustavo F. Padovan 
29470a708f8fSGustavo F. Padovan 	opt->type = type;
29480a708f8fSGustavo F. Padovan 	opt->len  = len;
29490a708f8fSGustavo F. Padovan 
29500a708f8fSGustavo F. Padovan 	switch (len) {
29510a708f8fSGustavo F. Padovan 	case 1:
29520a708f8fSGustavo F. Padovan 		*((u8 *) opt->val)  = val;
29530a708f8fSGustavo F. Padovan 		break;
29540a708f8fSGustavo F. Padovan 
29550a708f8fSGustavo F. Padovan 	case 2:
29560a708f8fSGustavo F. Padovan 		put_unaligned_le16(val, opt->val);
29570a708f8fSGustavo F. Padovan 		break;
29580a708f8fSGustavo F. Padovan 
29590a708f8fSGustavo F. Padovan 	case 4:
29600a708f8fSGustavo F. Padovan 		put_unaligned_le32(val, opt->val);
29610a708f8fSGustavo F. Padovan 		break;
29620a708f8fSGustavo F. Padovan 
29630a708f8fSGustavo F. Padovan 	default:
29640a708f8fSGustavo F. Padovan 		memcpy(opt->val, (void *) val, len);
29650a708f8fSGustavo F. Padovan 		break;
29660a708f8fSGustavo F. Padovan 	}
29670a708f8fSGustavo F. Padovan 
29680a708f8fSGustavo F. Padovan 	*ptr += L2CAP_CONF_OPT_SIZE + len;
29690a708f8fSGustavo F. Padovan }
29700a708f8fSGustavo F. Padovan 
2971f89cef09SAndrei Emeltchenko static void l2cap_add_opt_efs(void **ptr, struct l2cap_chan *chan)
2972f89cef09SAndrei Emeltchenko {
2973f89cef09SAndrei Emeltchenko 	struct l2cap_conf_efs efs;
2974f89cef09SAndrei Emeltchenko 
2975f89cef09SAndrei Emeltchenko 	switch (chan->mode) {
2976f89cef09SAndrei Emeltchenko 	case L2CAP_MODE_ERTM:
2977f89cef09SAndrei Emeltchenko 		efs.id		= chan->local_id;
2978f89cef09SAndrei Emeltchenko 		efs.stype	= chan->local_stype;
2979f89cef09SAndrei Emeltchenko 		efs.msdu	= cpu_to_le16(chan->local_msdu);
2980f89cef09SAndrei Emeltchenko 		efs.sdu_itime	= cpu_to_le32(chan->local_sdu_itime);
2981dcf4adbfSJoe Perches 		efs.acc_lat	= cpu_to_le32(L2CAP_DEFAULT_ACC_LAT);
2982dcf4adbfSJoe Perches 		efs.flush_to	= cpu_to_le32(L2CAP_EFS_DEFAULT_FLUSH_TO);
2983f89cef09SAndrei Emeltchenko 		break;
2984f89cef09SAndrei Emeltchenko 
2985f89cef09SAndrei Emeltchenko 	case L2CAP_MODE_STREAMING:
2986f89cef09SAndrei Emeltchenko 		efs.id		= 1;
2987f89cef09SAndrei Emeltchenko 		efs.stype	= L2CAP_SERV_BESTEFFORT;
2988f89cef09SAndrei Emeltchenko 		efs.msdu	= cpu_to_le16(chan->local_msdu);
2989f89cef09SAndrei Emeltchenko 		efs.sdu_itime	= cpu_to_le32(chan->local_sdu_itime);
2990f89cef09SAndrei Emeltchenko 		efs.acc_lat	= 0;
2991f89cef09SAndrei Emeltchenko 		efs.flush_to	= 0;
2992f89cef09SAndrei Emeltchenko 		break;
2993f89cef09SAndrei Emeltchenko 
2994f89cef09SAndrei Emeltchenko 	default:
2995f89cef09SAndrei Emeltchenko 		return;
2996f89cef09SAndrei Emeltchenko 	}
2997f89cef09SAndrei Emeltchenko 
2998f89cef09SAndrei Emeltchenko 	l2cap_add_conf_opt(ptr, L2CAP_CONF_EFS, sizeof(efs),
2999f89cef09SAndrei Emeltchenko 			   (unsigned long) &efs);
3000f89cef09SAndrei Emeltchenko }
3001f89cef09SAndrei Emeltchenko 
3002721c4181SGustavo F. Padovan static void l2cap_ack_timeout(struct work_struct *work)
30030a708f8fSGustavo F. Padovan {
3004721c4181SGustavo F. Padovan 	struct l2cap_chan *chan = container_of(work, struct l2cap_chan,
3005721c4181SGustavo F. Padovan 					       ack_timer.work);
30060362520bSMat Martineau 	u16 frames_to_ack;
30070a708f8fSGustavo F. Padovan 
30082fb9b3d4SGustavo F. Padovan 	BT_DBG("chan %p", chan);
30092fb9b3d4SGustavo F. Padovan 
30106be36555SAndrei Emeltchenko 	l2cap_chan_lock(chan);
30116be36555SAndrei Emeltchenko 
30120362520bSMat Martineau 	frames_to_ack = __seq_offset(chan, chan->buffer_seq,
30130362520bSMat Martineau 				     chan->last_acked_seq);
30140362520bSMat Martineau 
30150362520bSMat Martineau 	if (frames_to_ack)
30160362520bSMat Martineau 		l2cap_send_rr_or_rnr(chan, 0);
30176be36555SAndrei Emeltchenko 
30186be36555SAndrei Emeltchenko 	l2cap_chan_unlock(chan);
301909bfb2eeSSzymon Janc 	l2cap_chan_put(chan);
30200a708f8fSGustavo F. Padovan }
30210a708f8fSGustavo F. Padovan 
3022466f8004SAndrei Emeltchenko int l2cap_ertm_init(struct l2cap_chan *chan)
30230a708f8fSGustavo F. Padovan {
30243c588192SMat Martineau 	int err;
30253c588192SMat Martineau 
3026105bdf9eSMat Martineau 	chan->next_tx_seq = 0;
3027105bdf9eSMat Martineau 	chan->expected_tx_seq = 0;
302842e5c802SGustavo F. Padovan 	chan->expected_ack_seq = 0;
30296a026610SGustavo F. Padovan 	chan->unacked_frames = 0;
303042e5c802SGustavo F. Padovan 	chan->buffer_seq = 0;
30316a026610SGustavo F. Padovan 	chan->frames_sent = 0;
3032105bdf9eSMat Martineau 	chan->last_acked_seq = 0;
3033105bdf9eSMat Martineau 	chan->sdu = NULL;
3034105bdf9eSMat Martineau 	chan->sdu_last_frag = NULL;
3035105bdf9eSMat Martineau 	chan->sdu_len = 0;
3036105bdf9eSMat Martineau 
3037d34c34fbSMat Martineau 	skb_queue_head_init(&chan->tx_q);
3038d34c34fbSMat Martineau 
30396ed971caSMarcel Holtmann 	chan->local_amp_id = AMP_ID_BREDR;
30406ed971caSMarcel Holtmann 	chan->move_id = AMP_ID_BREDR;
304108333283SMat Martineau 	chan->move_state = L2CAP_MOVE_STABLE;
304208333283SMat Martineau 	chan->move_role = L2CAP_MOVE_ROLE_NONE;
304308333283SMat Martineau 
3044105bdf9eSMat Martineau 	if (chan->mode != L2CAP_MODE_ERTM)
3045105bdf9eSMat Martineau 		return 0;
3046105bdf9eSMat Martineau 
3047105bdf9eSMat Martineau 	chan->rx_state = L2CAP_RX_STATE_RECV;
3048105bdf9eSMat Martineau 	chan->tx_state = L2CAP_TX_STATE_XMIT;
30490a708f8fSGustavo F. Padovan 
3050721c4181SGustavo F. Padovan 	INIT_DELAYED_WORK(&chan->retrans_timer, l2cap_retrans_timeout);
3051721c4181SGustavo F. Padovan 	INIT_DELAYED_WORK(&chan->monitor_timer, l2cap_monitor_timeout);
3052721c4181SGustavo F. Padovan 	INIT_DELAYED_WORK(&chan->ack_timer, l2cap_ack_timeout);
30530a708f8fSGustavo F. Padovan 
3054f1c6775bSGustavo F. Padovan 	skb_queue_head_init(&chan->srej_q);
30550a708f8fSGustavo F. Padovan 
30563c588192SMat Martineau 	err = l2cap_seq_list_init(&chan->srej_list, chan->tx_win);
30573c588192SMat Martineau 	if (err < 0)
30583c588192SMat Martineau 		return err;
30593c588192SMat Martineau 
30609dc9affcSMat Martineau 	err = l2cap_seq_list_init(&chan->retrans_list, chan->remote_tx_win);
30619dc9affcSMat Martineau 	if (err < 0)
30629dc9affcSMat Martineau 		l2cap_seq_list_free(&chan->srej_list);
30639dc9affcSMat Martineau 
30649dc9affcSMat Martineau 	return err;
30650a708f8fSGustavo F. Padovan }
30660a708f8fSGustavo F. Padovan 
30670a708f8fSGustavo F. Padovan static inline __u8 l2cap_select_mode(__u8 mode, __u16 remote_feat_mask)
30680a708f8fSGustavo F. Padovan {
30690a708f8fSGustavo F. Padovan 	switch (mode) {
30700a708f8fSGustavo F. Padovan 	case L2CAP_MODE_STREAMING:
30710a708f8fSGustavo F. Padovan 	case L2CAP_MODE_ERTM:
30720a708f8fSGustavo F. Padovan 		if (l2cap_mode_supported(mode, remote_feat_mask))
30730a708f8fSGustavo F. Padovan 			return mode;
30740a708f8fSGustavo F. Padovan 		/* fall through */
30750a708f8fSGustavo F. Padovan 	default:
30760a708f8fSGustavo F. Padovan 		return L2CAP_MODE_BASIC;
30770a708f8fSGustavo F. Padovan 	}
30780a708f8fSGustavo F. Padovan }
30790a708f8fSGustavo F. Padovan 
3080848566b3SMarcel Holtmann static inline bool __l2cap_ews_supported(struct l2cap_conn *conn)
30816327eb98SAndrei Emeltchenko {
3082848566b3SMarcel Holtmann 	return conn->hs_enabled && conn->feat_mask & L2CAP_FEAT_EXT_WINDOW;
30836327eb98SAndrei Emeltchenko }
30846327eb98SAndrei Emeltchenko 
3085848566b3SMarcel Holtmann static inline bool __l2cap_efs_supported(struct l2cap_conn *conn)
3086f89cef09SAndrei Emeltchenko {
3087848566b3SMarcel Holtmann 	return conn->hs_enabled && conn->feat_mask & L2CAP_FEAT_EXT_FLOW;
3088f89cef09SAndrei Emeltchenko }
3089f89cef09SAndrei Emeltchenko 
309036c86c85SMat Martineau static void __l2cap_set_ertm_timeouts(struct l2cap_chan *chan,
309136c86c85SMat Martineau 				      struct l2cap_conf_rfc *rfc)
309236c86c85SMat Martineau {
30936ed971caSMarcel Holtmann 	if (chan->local_amp_id != AMP_ID_BREDR && chan->hs_hcon) {
309436c86c85SMat Martineau 		u64 ertm_to = chan->hs_hcon->hdev->amp_be_flush_to;
309536c86c85SMat Martineau 
309636c86c85SMat Martineau 		/* Class 1 devices have must have ERTM timeouts
309736c86c85SMat Martineau 		 * exceeding the Link Supervision Timeout.  The
309836c86c85SMat Martineau 		 * default Link Supervision Timeout for AMP
309936c86c85SMat Martineau 		 * controllers is 10 seconds.
310036c86c85SMat Martineau 		 *
310136c86c85SMat Martineau 		 * Class 1 devices use 0xffffffff for their
310236c86c85SMat Martineau 		 * best-effort flush timeout, so the clamping logic
310336c86c85SMat Martineau 		 * will result in a timeout that meets the above
310436c86c85SMat Martineau 		 * requirement.  ERTM timeouts are 16-bit values, so
310536c86c85SMat Martineau 		 * the maximum timeout is 65.535 seconds.
310636c86c85SMat Martineau 		 */
310736c86c85SMat Martineau 
310836c86c85SMat Martineau 		/* Convert timeout to milliseconds and round */
310936c86c85SMat Martineau 		ertm_to = DIV_ROUND_UP_ULL(ertm_to, 1000);
311036c86c85SMat Martineau 
311136c86c85SMat Martineau 		/* This is the recommended formula for class 2 devices
311236c86c85SMat Martineau 		 * that start ERTM timers when packets are sent to the
311336c86c85SMat Martineau 		 * controller.
311436c86c85SMat Martineau 		 */
311536c86c85SMat Martineau 		ertm_to = 3 * ertm_to + 500;
311636c86c85SMat Martineau 
311736c86c85SMat Martineau 		if (ertm_to > 0xffff)
311836c86c85SMat Martineau 			ertm_to = 0xffff;
311936c86c85SMat Martineau 
312036c86c85SMat Martineau 		rfc->retrans_timeout = cpu_to_le16((u16) ertm_to);
312136c86c85SMat Martineau 		rfc->monitor_timeout = rfc->retrans_timeout;
312236c86c85SMat Martineau 	} else {
3123dcf4adbfSJoe Perches 		rfc->retrans_timeout = cpu_to_le16(L2CAP_DEFAULT_RETRANS_TO);
3124dcf4adbfSJoe Perches 		rfc->monitor_timeout = cpu_to_le16(L2CAP_DEFAULT_MONITOR_TO);
312536c86c85SMat Martineau 	}
312636c86c85SMat Martineau }
312736c86c85SMat Martineau 
31286327eb98SAndrei Emeltchenko static inline void l2cap_txwin_setup(struct l2cap_chan *chan)
31296327eb98SAndrei Emeltchenko {
31306327eb98SAndrei Emeltchenko 	if (chan->tx_win > L2CAP_DEFAULT_TX_WINDOW &&
3131848566b3SMarcel Holtmann 	    __l2cap_ews_supported(chan->conn)) {
31326327eb98SAndrei Emeltchenko 		/* use extended control field */
31336327eb98SAndrei Emeltchenko 		set_bit(FLAG_EXT_CTRL, &chan->flags);
3134836be934SAndrei Emeltchenko 		chan->tx_win_max = L2CAP_DEFAULT_EXT_WINDOW;
3135836be934SAndrei Emeltchenko 	} else {
31366327eb98SAndrei Emeltchenko 		chan->tx_win = min_t(u16, chan->tx_win,
31376327eb98SAndrei Emeltchenko 				     L2CAP_DEFAULT_TX_WINDOW);
3138836be934SAndrei Emeltchenko 		chan->tx_win_max = L2CAP_DEFAULT_TX_WINDOW;
3139836be934SAndrei Emeltchenko 	}
3140c20f8e35SMat Martineau 	chan->ack_win = chan->tx_win;
31416327eb98SAndrei Emeltchenko }
31426327eb98SAndrei Emeltchenko 
3143710f9b0aSGustavo F. Padovan static int l2cap_build_conf_req(struct l2cap_chan *chan, void *data)
31440a708f8fSGustavo F. Padovan {
31450a708f8fSGustavo F. Padovan 	struct l2cap_conf_req *req = data;
31460c1bc5c6SGustavo F. Padovan 	struct l2cap_conf_rfc rfc = { .mode = chan->mode };
31470a708f8fSGustavo F. Padovan 	void *ptr = req->data;
3148c8f79162SAndrei Emeltchenko 	u16 size;
31490a708f8fSGustavo F. Padovan 
315049208c9cSGustavo F. Padovan 	BT_DBG("chan %p", chan);
31510a708f8fSGustavo F. Padovan 
315273ffa904SGustavo F. Padovan 	if (chan->num_conf_req || chan->num_conf_rsp)
31530a708f8fSGustavo F. Padovan 		goto done;
31540a708f8fSGustavo F. Padovan 
31550c1bc5c6SGustavo F. Padovan 	switch (chan->mode) {
31560a708f8fSGustavo F. Padovan 	case L2CAP_MODE_STREAMING:
31570a708f8fSGustavo F. Padovan 	case L2CAP_MODE_ERTM:
3158c1360a1cSGustavo F. Padovan 		if (test_bit(CONF_STATE2_DEVICE, &chan->conf_state))
31590a708f8fSGustavo F. Padovan 			break;
31600a708f8fSGustavo F. Padovan 
3161848566b3SMarcel Holtmann 		if (__l2cap_efs_supported(chan->conn))
3162f89cef09SAndrei Emeltchenko 			set_bit(FLAG_EFS_ENABLE, &chan->flags);
3163f89cef09SAndrei Emeltchenko 
31640a708f8fSGustavo F. Padovan 		/* fall through */
31650a708f8fSGustavo F. Padovan 	default:
31668c1d787bSGustavo F. Padovan 		chan->mode = l2cap_select_mode(rfc.mode, chan->conn->feat_mask);
31670a708f8fSGustavo F. Padovan 		break;
31680a708f8fSGustavo F. Padovan 	}
31690a708f8fSGustavo F. Padovan 
31700a708f8fSGustavo F. Padovan done:
31710c1bc5c6SGustavo F. Padovan 	if (chan->imtu != L2CAP_DEFAULT_MTU)
31720c1bc5c6SGustavo F. Padovan 		l2cap_add_conf_opt(&ptr, L2CAP_CONF_MTU, 2, chan->imtu);
31730a708f8fSGustavo F. Padovan 
31740c1bc5c6SGustavo F. Padovan 	switch (chan->mode) {
31750a708f8fSGustavo F. Padovan 	case L2CAP_MODE_BASIC:
31766fea7ad1SMarcel Holtmann 		if (disable_ertm)
31776fea7ad1SMarcel Holtmann 			break;
31786fea7ad1SMarcel Holtmann 
31798c1d787bSGustavo F. Padovan 		if (!(chan->conn->feat_mask & L2CAP_FEAT_ERTM) &&
31808c1d787bSGustavo F. Padovan 		    !(chan->conn->feat_mask & L2CAP_FEAT_STREAMING))
31810a708f8fSGustavo F. Padovan 			break;
31820a708f8fSGustavo F. Padovan 
31830a708f8fSGustavo F. Padovan 		rfc.mode            = L2CAP_MODE_BASIC;
31840a708f8fSGustavo F. Padovan 		rfc.txwin_size      = 0;
31850a708f8fSGustavo F. Padovan 		rfc.max_transmit    = 0;
31860a708f8fSGustavo F. Padovan 		rfc.retrans_timeout = 0;
31870a708f8fSGustavo F. Padovan 		rfc.monitor_timeout = 0;
31880a708f8fSGustavo F. Padovan 		rfc.max_pdu_size    = 0;
31890a708f8fSGustavo F. Padovan 
31900a708f8fSGustavo F. Padovan 		l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC, sizeof(rfc),
31910a708f8fSGustavo F. Padovan 				   (unsigned long) &rfc);
31920a708f8fSGustavo F. Padovan 		break;
31930a708f8fSGustavo F. Padovan 
31940a708f8fSGustavo F. Padovan 	case L2CAP_MODE_ERTM:
31950a708f8fSGustavo F. Padovan 		rfc.mode            = L2CAP_MODE_ERTM;
319647d1ec61SGustavo F. Padovan 		rfc.max_transmit    = chan->max_tx;
319736c86c85SMat Martineau 
319836c86c85SMat Martineau 		__l2cap_set_ertm_timeouts(chan, &rfc);
3199c8f79162SAndrei Emeltchenko 
3200c8f79162SAndrei Emeltchenko 		size = min_t(u16, L2CAP_DEFAULT_MAX_PDU_SIZE, chan->conn->mtu -
32012d792818SGustavo Padovan 			     L2CAP_EXT_HDR_SIZE - L2CAP_SDULEN_SIZE -
3202c8f79162SAndrei Emeltchenko 			     L2CAP_FCS_SIZE);
3203c8f79162SAndrei Emeltchenko 		rfc.max_pdu_size = cpu_to_le16(size);
32040a708f8fSGustavo F. Padovan 
32056327eb98SAndrei Emeltchenko 		l2cap_txwin_setup(chan);
32066327eb98SAndrei Emeltchenko 
32076327eb98SAndrei Emeltchenko 		rfc.txwin_size = min_t(u16, chan->tx_win,
32086327eb98SAndrei Emeltchenko 				       L2CAP_DEFAULT_TX_WINDOW);
32090a708f8fSGustavo F. Padovan 
32100a708f8fSGustavo F. Padovan 		l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC, sizeof(rfc),
32110a708f8fSGustavo F. Padovan 				   (unsigned long) &rfc);
32120a708f8fSGustavo F. Padovan 
3213f89cef09SAndrei Emeltchenko 		if (test_bit(FLAG_EFS_ENABLE, &chan->flags))
3214f89cef09SAndrei Emeltchenko 			l2cap_add_opt_efs(&ptr, chan);
3215f89cef09SAndrei Emeltchenko 
32166327eb98SAndrei Emeltchenko 		if (test_bit(FLAG_EXT_CTRL, &chan->flags))
32176327eb98SAndrei Emeltchenko 			l2cap_add_conf_opt(&ptr, L2CAP_CONF_EWS, 2,
32186327eb98SAndrei Emeltchenko 					   chan->tx_win);
321960918918SAndrei Emeltchenko 
322060918918SAndrei Emeltchenko 		if (chan->conn->feat_mask & L2CAP_FEAT_FCS)
322160918918SAndrei Emeltchenko 			if (chan->fcs == L2CAP_FCS_NONE ||
3222f2592d3eSAndrei Emeltchenko 			    test_bit(CONF_RECV_NO_FCS, &chan->conf_state)) {
322360918918SAndrei Emeltchenko 				chan->fcs = L2CAP_FCS_NONE;
322460918918SAndrei Emeltchenko 				l2cap_add_conf_opt(&ptr, L2CAP_CONF_FCS, 1,
322560918918SAndrei Emeltchenko 						   chan->fcs);
322660918918SAndrei Emeltchenko 			}
32270a708f8fSGustavo F. Padovan 		break;
32280a708f8fSGustavo F. Padovan 
32290a708f8fSGustavo F. Padovan 	case L2CAP_MODE_STREAMING:
3230273759e2SMat Martineau 		l2cap_txwin_setup(chan);
32310a708f8fSGustavo F. Padovan 		rfc.mode            = L2CAP_MODE_STREAMING;
32320a708f8fSGustavo F. Padovan 		rfc.txwin_size      = 0;
32330a708f8fSGustavo F. Padovan 		rfc.max_transmit    = 0;
32340a708f8fSGustavo F. Padovan 		rfc.retrans_timeout = 0;
32350a708f8fSGustavo F. Padovan 		rfc.monitor_timeout = 0;
3236c8f79162SAndrei Emeltchenko 
3237c8f79162SAndrei Emeltchenko 		size = min_t(u16, L2CAP_DEFAULT_MAX_PDU_SIZE, chan->conn->mtu -
32382d792818SGustavo Padovan 			     L2CAP_EXT_HDR_SIZE - L2CAP_SDULEN_SIZE -
3239c8f79162SAndrei Emeltchenko 			     L2CAP_FCS_SIZE);
3240c8f79162SAndrei Emeltchenko 		rfc.max_pdu_size = cpu_to_le16(size);
32410a708f8fSGustavo F. Padovan 
32420a708f8fSGustavo F. Padovan 		l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC, sizeof(rfc),
32430a708f8fSGustavo F. Padovan 				   (unsigned long) &rfc);
32440a708f8fSGustavo F. Padovan 
3245f89cef09SAndrei Emeltchenko 		if (test_bit(FLAG_EFS_ENABLE, &chan->flags))
3246f89cef09SAndrei Emeltchenko 			l2cap_add_opt_efs(&ptr, chan);
3247f89cef09SAndrei Emeltchenko 
324860918918SAndrei Emeltchenko 		if (chan->conn->feat_mask & L2CAP_FEAT_FCS)
324947d1ec61SGustavo F. Padovan 			if (chan->fcs == L2CAP_FCS_NONE ||
3250f2592d3eSAndrei Emeltchenko 			    test_bit(CONF_RECV_NO_FCS, &chan->conf_state)) {
325147d1ec61SGustavo F. Padovan 				chan->fcs = L2CAP_FCS_NONE;
325260918918SAndrei Emeltchenko 				l2cap_add_conf_opt(&ptr, L2CAP_CONF_FCS, 1,
325360918918SAndrei Emeltchenko 						   chan->fcs);
32540a708f8fSGustavo F. Padovan 			}
32550a708f8fSGustavo F. Padovan 		break;
32560a708f8fSGustavo F. Padovan 	}
32570a708f8fSGustavo F. Padovan 
3258fe4128e0SGustavo F. Padovan 	req->dcid  = cpu_to_le16(chan->dcid);
3259dcf4adbfSJoe Perches 	req->flags = cpu_to_le16(0);
32600a708f8fSGustavo F. Padovan 
32610a708f8fSGustavo F. Padovan 	return ptr - data;
32620a708f8fSGustavo F. Padovan }
32630a708f8fSGustavo F. Padovan 
326473ffa904SGustavo F. Padovan static int l2cap_parse_conf_req(struct l2cap_chan *chan, void *data)
32650a708f8fSGustavo F. Padovan {
32660a708f8fSGustavo F. Padovan 	struct l2cap_conf_rsp *rsp = data;
32670a708f8fSGustavo F. Padovan 	void *ptr = rsp->data;
326873ffa904SGustavo F. Padovan 	void *req = chan->conf_req;
326973ffa904SGustavo F. Padovan 	int len = chan->conf_len;
32700a708f8fSGustavo F. Padovan 	int type, hint, olen;
32710a708f8fSGustavo F. Padovan 	unsigned long val;
32720a708f8fSGustavo F. Padovan 	struct l2cap_conf_rfc rfc = { .mode = L2CAP_MODE_BASIC };
327342dceae2SAndrei Emeltchenko 	struct l2cap_conf_efs efs;
327442dceae2SAndrei Emeltchenko 	u8 remote_efs = 0;
32750a708f8fSGustavo F. Padovan 	u16 mtu = L2CAP_DEFAULT_MTU;
32760a708f8fSGustavo F. Padovan 	u16 result = L2CAP_CONF_SUCCESS;
3277c8f79162SAndrei Emeltchenko 	u16 size;
32780a708f8fSGustavo F. Padovan 
327973ffa904SGustavo F. Padovan 	BT_DBG("chan %p", chan);
32800a708f8fSGustavo F. Padovan 
32810a708f8fSGustavo F. Padovan 	while (len >= L2CAP_CONF_OPT_SIZE) {
32820a708f8fSGustavo F. Padovan 		len -= l2cap_get_conf_opt(&req, &type, &olen, &val);
32830a708f8fSGustavo F. Padovan 
32840a708f8fSGustavo F. Padovan 		hint  = type & L2CAP_CONF_HINT;
32850a708f8fSGustavo F. Padovan 		type &= L2CAP_CONF_MASK;
32860a708f8fSGustavo F. Padovan 
32870a708f8fSGustavo F. Padovan 		switch (type) {
32880a708f8fSGustavo F. Padovan 		case L2CAP_CONF_MTU:
32890a708f8fSGustavo F. Padovan 			mtu = val;
32900a708f8fSGustavo F. Padovan 			break;
32910a708f8fSGustavo F. Padovan 
32920a708f8fSGustavo F. Padovan 		case L2CAP_CONF_FLUSH_TO:
32930c1bc5c6SGustavo F. Padovan 			chan->flush_to = val;
32940a708f8fSGustavo F. Padovan 			break;
32950a708f8fSGustavo F. Padovan 
32960a708f8fSGustavo F. Padovan 		case L2CAP_CONF_QOS:
32970a708f8fSGustavo F. Padovan 			break;
32980a708f8fSGustavo F. Padovan 
32990a708f8fSGustavo F. Padovan 		case L2CAP_CONF_RFC:
33000a708f8fSGustavo F. Padovan 			if (olen == sizeof(rfc))
33010a708f8fSGustavo F. Padovan 				memcpy(&rfc, (void *) val, olen);
33020a708f8fSGustavo F. Padovan 			break;
33030a708f8fSGustavo F. Padovan 
33040a708f8fSGustavo F. Padovan 		case L2CAP_CONF_FCS:
33050a708f8fSGustavo F. Padovan 			if (val == L2CAP_FCS_NONE)
3306f2592d3eSAndrei Emeltchenko 				set_bit(CONF_RECV_NO_FCS, &chan->conf_state);
330742dceae2SAndrei Emeltchenko 			break;
33080a708f8fSGustavo F. Padovan 
330942dceae2SAndrei Emeltchenko 		case L2CAP_CONF_EFS:
331042dceae2SAndrei Emeltchenko 			remote_efs = 1;
331142dceae2SAndrei Emeltchenko 			if (olen == sizeof(efs))
331242dceae2SAndrei Emeltchenko 				memcpy(&efs, (void *) val, olen);
33130a708f8fSGustavo F. Padovan 			break;
33140a708f8fSGustavo F. Padovan 
33156327eb98SAndrei Emeltchenko 		case L2CAP_CONF_EWS:
3316848566b3SMarcel Holtmann 			if (!chan->conn->hs_enabled)
33176327eb98SAndrei Emeltchenko 				return -ECONNREFUSED;
33186327eb98SAndrei Emeltchenko 
33196327eb98SAndrei Emeltchenko 			set_bit(FLAG_EXT_CTRL, &chan->flags);
33206327eb98SAndrei Emeltchenko 			set_bit(CONF_EWS_RECV, &chan->conf_state);
3321836be934SAndrei Emeltchenko 			chan->tx_win_max = L2CAP_DEFAULT_EXT_WINDOW;
33226327eb98SAndrei Emeltchenko 			chan->remote_tx_win = val;
33230a708f8fSGustavo F. Padovan 			break;
33240a708f8fSGustavo F. Padovan 
33250a708f8fSGustavo F. Padovan 		default:
33260a708f8fSGustavo F. Padovan 			if (hint)
33270a708f8fSGustavo F. Padovan 				break;
33280a708f8fSGustavo F. Padovan 
33290a708f8fSGustavo F. Padovan 			result = L2CAP_CONF_UNKNOWN;
33300a708f8fSGustavo F. Padovan 			*((u8 *) ptr++) = type;
33310a708f8fSGustavo F. Padovan 			break;
33320a708f8fSGustavo F. Padovan 		}
33330a708f8fSGustavo F. Padovan 	}
33340a708f8fSGustavo F. Padovan 
333573ffa904SGustavo F. Padovan 	if (chan->num_conf_rsp || chan->num_conf_req > 1)
33360a708f8fSGustavo F. Padovan 		goto done;
33370a708f8fSGustavo F. Padovan 
33380c1bc5c6SGustavo F. Padovan 	switch (chan->mode) {
33390a708f8fSGustavo F. Padovan 	case L2CAP_MODE_STREAMING:
33400a708f8fSGustavo F. Padovan 	case L2CAP_MODE_ERTM:
3341c1360a1cSGustavo F. Padovan 		if (!test_bit(CONF_STATE2_DEVICE, &chan->conf_state)) {
33420c1bc5c6SGustavo F. Padovan 			chan->mode = l2cap_select_mode(rfc.mode,
33438c1d787bSGustavo F. Padovan 						       chan->conn->feat_mask);
33440a708f8fSGustavo F. Padovan 			break;
33450a708f8fSGustavo F. Padovan 		}
33460a708f8fSGustavo F. Padovan 
334742dceae2SAndrei Emeltchenko 		if (remote_efs) {
3348848566b3SMarcel Holtmann 			if (__l2cap_efs_supported(chan->conn))
334942dceae2SAndrei Emeltchenko 				set_bit(FLAG_EFS_ENABLE, &chan->flags);
335042dceae2SAndrei Emeltchenko 			else
335142dceae2SAndrei Emeltchenko 				return -ECONNREFUSED;
335242dceae2SAndrei Emeltchenko 		}
335342dceae2SAndrei Emeltchenko 
33540c1bc5c6SGustavo F. Padovan 		if (chan->mode != rfc.mode)
33550a708f8fSGustavo F. Padovan 			return -ECONNREFUSED;
33560a708f8fSGustavo F. Padovan 
33570a708f8fSGustavo F. Padovan 		break;
33580a708f8fSGustavo F. Padovan 	}
33590a708f8fSGustavo F. Padovan 
33600a708f8fSGustavo F. Padovan done:
33610c1bc5c6SGustavo F. Padovan 	if (chan->mode != rfc.mode) {
33620a708f8fSGustavo F. Padovan 		result = L2CAP_CONF_UNACCEPT;
33630c1bc5c6SGustavo F. Padovan 		rfc.mode = chan->mode;
33640a708f8fSGustavo F. Padovan 
336573ffa904SGustavo F. Padovan 		if (chan->num_conf_rsp == 1)
33660a708f8fSGustavo F. Padovan 			return -ECONNREFUSED;
33670a708f8fSGustavo F. Padovan 
33682d792818SGustavo Padovan 		l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC, sizeof(rfc),
33692d792818SGustavo Padovan 				   (unsigned long) &rfc);
33700a708f8fSGustavo F. Padovan 	}
33710a708f8fSGustavo F. Padovan 
33720a708f8fSGustavo F. Padovan 	if (result == L2CAP_CONF_SUCCESS) {
33730a708f8fSGustavo F. Padovan 		/* Configure output options and let the other side know
33740a708f8fSGustavo F. Padovan 		 * which ones we don't like. */
33750a708f8fSGustavo F. Padovan 
33760a708f8fSGustavo F. Padovan 		if (mtu < L2CAP_DEFAULT_MIN_MTU)
33770a708f8fSGustavo F. Padovan 			result = L2CAP_CONF_UNACCEPT;
33780a708f8fSGustavo F. Padovan 		else {
33790c1bc5c6SGustavo F. Padovan 			chan->omtu = mtu;
3380c1360a1cSGustavo F. Padovan 			set_bit(CONF_MTU_DONE, &chan->conf_state);
33810a708f8fSGustavo F. Padovan 		}
33820c1bc5c6SGustavo F. Padovan 		l2cap_add_conf_opt(&ptr, L2CAP_CONF_MTU, 2, chan->omtu);
33830a708f8fSGustavo F. Padovan 
338442dceae2SAndrei Emeltchenko 		if (remote_efs) {
338542dceae2SAndrei Emeltchenko 			if (chan->local_stype != L2CAP_SERV_NOTRAFIC &&
338642dceae2SAndrei Emeltchenko 			    efs.stype != L2CAP_SERV_NOTRAFIC &&
338742dceae2SAndrei Emeltchenko 			    efs.stype != chan->local_stype) {
338842dceae2SAndrei Emeltchenko 
338942dceae2SAndrei Emeltchenko 				result = L2CAP_CONF_UNACCEPT;
339042dceae2SAndrei Emeltchenko 
339142dceae2SAndrei Emeltchenko 				if (chan->num_conf_req >= 1)
339242dceae2SAndrei Emeltchenko 					return -ECONNREFUSED;
339342dceae2SAndrei Emeltchenko 
339442dceae2SAndrei Emeltchenko 				l2cap_add_conf_opt(&ptr, L2CAP_CONF_EFS,
339542dceae2SAndrei Emeltchenko 						   sizeof(efs),
339642dceae2SAndrei Emeltchenko 						   (unsigned long) &efs);
33970e8b207eSAndrei Emeltchenko 			} else {
33983e6b3b95SGustavo F. Padovan 				/* Send PENDING Conf Rsp */
33990e8b207eSAndrei Emeltchenko 				result = L2CAP_CONF_PENDING;
34000e8b207eSAndrei Emeltchenko 				set_bit(CONF_LOC_CONF_PEND, &chan->conf_state);
340142dceae2SAndrei Emeltchenko 			}
340242dceae2SAndrei Emeltchenko 		}
340342dceae2SAndrei Emeltchenko 
34040a708f8fSGustavo F. Padovan 		switch (rfc.mode) {
34050a708f8fSGustavo F. Padovan 		case L2CAP_MODE_BASIC:
340647d1ec61SGustavo F. Padovan 			chan->fcs = L2CAP_FCS_NONE;
3407c1360a1cSGustavo F. Padovan 			set_bit(CONF_MODE_DONE, &chan->conf_state);
34080a708f8fSGustavo F. Padovan 			break;
34090a708f8fSGustavo F. Padovan 
34100a708f8fSGustavo F. Padovan 		case L2CAP_MODE_ERTM:
34116327eb98SAndrei Emeltchenko 			if (!test_bit(CONF_EWS_RECV, &chan->conf_state))
34122c03a7a4SGustavo F. Padovan 				chan->remote_tx_win = rfc.txwin_size;
34136327eb98SAndrei Emeltchenko 			else
34146327eb98SAndrei Emeltchenko 				rfc.txwin_size = L2CAP_DEFAULT_TX_WINDOW;
34156327eb98SAndrei Emeltchenko 
34162c03a7a4SGustavo F. Padovan 			chan->remote_max_tx = rfc.max_transmit;
34170a708f8fSGustavo F. Padovan 
3418c8f79162SAndrei Emeltchenko 			size = min_t(u16, le16_to_cpu(rfc.max_pdu_size),
34192d792818SGustavo Padovan 				     chan->conn->mtu - L2CAP_EXT_HDR_SIZE -
34202d792818SGustavo Padovan 				     L2CAP_SDULEN_SIZE - L2CAP_FCS_SIZE);
3421c8f79162SAndrei Emeltchenko 			rfc.max_pdu_size = cpu_to_le16(size);
3422c8f79162SAndrei Emeltchenko 			chan->remote_mps = size;
34230a708f8fSGustavo F. Padovan 
342436c86c85SMat Martineau 			__l2cap_set_ertm_timeouts(chan, &rfc);
34250a708f8fSGustavo F. Padovan 
3426c1360a1cSGustavo F. Padovan 			set_bit(CONF_MODE_DONE, &chan->conf_state);
34270a708f8fSGustavo F. Padovan 
34280a708f8fSGustavo F. Padovan 			l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC,
34290a708f8fSGustavo F. Padovan 					   sizeof(rfc), (unsigned long) &rfc);
34300a708f8fSGustavo F. Padovan 
343142dceae2SAndrei Emeltchenko 			if (test_bit(FLAG_EFS_ENABLE, &chan->flags)) {
343242dceae2SAndrei Emeltchenko 				chan->remote_id = efs.id;
343342dceae2SAndrei Emeltchenko 				chan->remote_stype = efs.stype;
343442dceae2SAndrei Emeltchenko 				chan->remote_msdu = le16_to_cpu(efs.msdu);
343542dceae2SAndrei Emeltchenko 				chan->remote_flush_to =
343642dceae2SAndrei Emeltchenko 					le32_to_cpu(efs.flush_to);
343742dceae2SAndrei Emeltchenko 				chan->remote_acc_lat =
343842dceae2SAndrei Emeltchenko 					le32_to_cpu(efs.acc_lat);
343942dceae2SAndrei Emeltchenko 				chan->remote_sdu_itime =
344042dceae2SAndrei Emeltchenko 					le32_to_cpu(efs.sdu_itime);
344142dceae2SAndrei Emeltchenko 				l2cap_add_conf_opt(&ptr, L2CAP_CONF_EFS,
34422d792818SGustavo Padovan 						   sizeof(efs),
34432d792818SGustavo Padovan 						   (unsigned long) &efs);
344442dceae2SAndrei Emeltchenko 			}
34450a708f8fSGustavo F. Padovan 			break;
34460a708f8fSGustavo F. Padovan 
34470a708f8fSGustavo F. Padovan 		case L2CAP_MODE_STREAMING:
3448c8f79162SAndrei Emeltchenko 			size = min_t(u16, le16_to_cpu(rfc.max_pdu_size),
34492d792818SGustavo Padovan 				     chan->conn->mtu - L2CAP_EXT_HDR_SIZE -
34502d792818SGustavo Padovan 				     L2CAP_SDULEN_SIZE - L2CAP_FCS_SIZE);
3451c8f79162SAndrei Emeltchenko 			rfc.max_pdu_size = cpu_to_le16(size);
3452c8f79162SAndrei Emeltchenko 			chan->remote_mps = size;
34530a708f8fSGustavo F. Padovan 
3454c1360a1cSGustavo F. Padovan 			set_bit(CONF_MODE_DONE, &chan->conf_state);
34550a708f8fSGustavo F. Padovan 
34562d792818SGustavo Padovan 			l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC, sizeof(rfc),
34572d792818SGustavo Padovan 					   (unsigned long) &rfc);
34580a708f8fSGustavo F. Padovan 
34590a708f8fSGustavo F. Padovan 			break;
34600a708f8fSGustavo F. Padovan 
34610a708f8fSGustavo F. Padovan 		default:
34620a708f8fSGustavo F. Padovan 			result = L2CAP_CONF_UNACCEPT;
34630a708f8fSGustavo F. Padovan 
34640a708f8fSGustavo F. Padovan 			memset(&rfc, 0, sizeof(rfc));
34650c1bc5c6SGustavo F. Padovan 			rfc.mode = chan->mode;
34660a708f8fSGustavo F. Padovan 		}
34670a708f8fSGustavo F. Padovan 
34680a708f8fSGustavo F. Padovan 		if (result == L2CAP_CONF_SUCCESS)
3469c1360a1cSGustavo F. Padovan 			set_bit(CONF_OUTPUT_DONE, &chan->conf_state);
34700a708f8fSGustavo F. Padovan 	}
3471fe4128e0SGustavo F. Padovan 	rsp->scid   = cpu_to_le16(chan->dcid);
34720a708f8fSGustavo F. Padovan 	rsp->result = cpu_to_le16(result);
3473dcf4adbfSJoe Perches 	rsp->flags  = cpu_to_le16(0);
34740a708f8fSGustavo F. Padovan 
34750a708f8fSGustavo F. Padovan 	return ptr - data;
34760a708f8fSGustavo F. Padovan }
34770a708f8fSGustavo F. Padovan 
34782d792818SGustavo Padovan static int l2cap_parse_conf_rsp(struct l2cap_chan *chan, void *rsp, int len,
34792d792818SGustavo Padovan 				void *data, u16 *result)
34800a708f8fSGustavo F. Padovan {
34810a708f8fSGustavo F. Padovan 	struct l2cap_conf_req *req = data;
34820a708f8fSGustavo F. Padovan 	void *ptr = req->data;
34830a708f8fSGustavo F. Padovan 	int type, olen;
34840a708f8fSGustavo F. Padovan 	unsigned long val;
348536e999a8SMat Martineau 	struct l2cap_conf_rfc rfc = { .mode = L2CAP_MODE_BASIC };
348666af7aafSAndrei Emeltchenko 	struct l2cap_conf_efs efs;
34870a708f8fSGustavo F. Padovan 
3488fe4128e0SGustavo F. Padovan 	BT_DBG("chan %p, rsp %p, len %d, req %p", chan, rsp, len, data);
34890a708f8fSGustavo F. Padovan 
34900a708f8fSGustavo F. Padovan 	while (len >= L2CAP_CONF_OPT_SIZE) {
34910a708f8fSGustavo F. Padovan 		len -= l2cap_get_conf_opt(&rsp, &type, &olen, &val);
34920a708f8fSGustavo F. Padovan 
34930a708f8fSGustavo F. Padovan 		switch (type) {
34940a708f8fSGustavo F. Padovan 		case L2CAP_CONF_MTU:
34950a708f8fSGustavo F. Padovan 			if (val < L2CAP_DEFAULT_MIN_MTU) {
34960a708f8fSGustavo F. Padovan 				*result = L2CAP_CONF_UNACCEPT;
34970c1bc5c6SGustavo F. Padovan 				chan->imtu = L2CAP_DEFAULT_MIN_MTU;
34980a708f8fSGustavo F. Padovan 			} else
34990c1bc5c6SGustavo F. Padovan 				chan->imtu = val;
35000c1bc5c6SGustavo F. Padovan 			l2cap_add_conf_opt(&ptr, L2CAP_CONF_MTU, 2, chan->imtu);
35010a708f8fSGustavo F. Padovan 			break;
35020a708f8fSGustavo F. Padovan 
35030a708f8fSGustavo F. Padovan 		case L2CAP_CONF_FLUSH_TO:
35040c1bc5c6SGustavo F. Padovan 			chan->flush_to = val;
35050a708f8fSGustavo F. Padovan 			l2cap_add_conf_opt(&ptr, L2CAP_CONF_FLUSH_TO,
35060c1bc5c6SGustavo F. Padovan 					   2, chan->flush_to);
35070a708f8fSGustavo F. Padovan 			break;
35080a708f8fSGustavo F. Padovan 
35090a708f8fSGustavo F. Padovan 		case L2CAP_CONF_RFC:
35100a708f8fSGustavo F. Padovan 			if (olen == sizeof(rfc))
35110a708f8fSGustavo F. Padovan 				memcpy(&rfc, (void *)val, olen);
35120a708f8fSGustavo F. Padovan 
3513c1360a1cSGustavo F. Padovan 			if (test_bit(CONF_STATE2_DEVICE, &chan->conf_state) &&
35140c1bc5c6SGustavo F. Padovan 			    rfc.mode != chan->mode)
35150a708f8fSGustavo F. Padovan 				return -ECONNREFUSED;
35160a708f8fSGustavo F. Padovan 
351747d1ec61SGustavo F. Padovan 			chan->fcs = 0;
35180a708f8fSGustavo F. Padovan 
35190a708f8fSGustavo F. Padovan 			l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC,
35200a708f8fSGustavo F. Padovan 					   sizeof(rfc), (unsigned long) &rfc);
35210a708f8fSGustavo F. Padovan 			break;
35226327eb98SAndrei Emeltchenko 
35236327eb98SAndrei Emeltchenko 		case L2CAP_CONF_EWS:
3524c20f8e35SMat Martineau 			chan->ack_win = min_t(u16, val, chan->ack_win);
35253e6b3b95SGustavo F. Padovan 			l2cap_add_conf_opt(&ptr, L2CAP_CONF_EWS, 2,
35263e6b3b95SGustavo F. Padovan 					   chan->tx_win);
35276327eb98SAndrei Emeltchenko 			break;
352866af7aafSAndrei Emeltchenko 
352966af7aafSAndrei Emeltchenko 		case L2CAP_CONF_EFS:
353066af7aafSAndrei Emeltchenko 			if (olen == sizeof(efs))
353166af7aafSAndrei Emeltchenko 				memcpy(&efs, (void *)val, olen);
353266af7aafSAndrei Emeltchenko 
353366af7aafSAndrei Emeltchenko 			if (chan->local_stype != L2CAP_SERV_NOTRAFIC &&
353466af7aafSAndrei Emeltchenko 			    efs.stype != L2CAP_SERV_NOTRAFIC &&
353566af7aafSAndrei Emeltchenko 			    efs.stype != chan->local_stype)
353666af7aafSAndrei Emeltchenko 				return -ECONNREFUSED;
353766af7aafSAndrei Emeltchenko 
35382d792818SGustavo Padovan 			l2cap_add_conf_opt(&ptr, L2CAP_CONF_EFS, sizeof(efs),
35392d792818SGustavo Padovan 					   (unsigned long) &efs);
354066af7aafSAndrei Emeltchenko 			break;
3541cbabee78SAndrei Emeltchenko 
3542cbabee78SAndrei Emeltchenko 		case L2CAP_CONF_FCS:
3543cbabee78SAndrei Emeltchenko 			if (*result == L2CAP_CONF_PENDING)
3544cbabee78SAndrei Emeltchenko 				if (val == L2CAP_FCS_NONE)
3545f2592d3eSAndrei Emeltchenko 					set_bit(CONF_RECV_NO_FCS,
3546cbabee78SAndrei Emeltchenko 						&chan->conf_state);
3547cbabee78SAndrei Emeltchenko 			break;
35480a708f8fSGustavo F. Padovan 		}
35490a708f8fSGustavo F. Padovan 	}
35500a708f8fSGustavo F. Padovan 
35510c1bc5c6SGustavo F. Padovan 	if (chan->mode == L2CAP_MODE_BASIC && chan->mode != rfc.mode)
35520a708f8fSGustavo F. Padovan 		return -ECONNREFUSED;
35530a708f8fSGustavo F. Padovan 
35540c1bc5c6SGustavo F. Padovan 	chan->mode = rfc.mode;
35550a708f8fSGustavo F. Padovan 
35560e8b207eSAndrei Emeltchenko 	if (*result == L2CAP_CONF_SUCCESS || *result == L2CAP_CONF_PENDING) {
35570a708f8fSGustavo F. Padovan 		switch (rfc.mode) {
35580a708f8fSGustavo F. Padovan 		case L2CAP_MODE_ERTM:
355947d1ec61SGustavo F. Padovan 			chan->retrans_timeout = le16_to_cpu(rfc.retrans_timeout);
356047d1ec61SGustavo F. Padovan 			chan->monitor_timeout = le16_to_cpu(rfc.monitor_timeout);
356147d1ec61SGustavo F. Padovan 			chan->mps    = le16_to_cpu(rfc.max_pdu_size);
3562c20f8e35SMat Martineau 			if (!test_bit(FLAG_EXT_CTRL, &chan->flags))
3563c20f8e35SMat Martineau 				chan->ack_win = min_t(u16, chan->ack_win,
3564c20f8e35SMat Martineau 						      rfc.txwin_size);
356566af7aafSAndrei Emeltchenko 
356666af7aafSAndrei Emeltchenko 			if (test_bit(FLAG_EFS_ENABLE, &chan->flags)) {
356766af7aafSAndrei Emeltchenko 				chan->local_msdu = le16_to_cpu(efs.msdu);
356866af7aafSAndrei Emeltchenko 				chan->local_sdu_itime =
356966af7aafSAndrei Emeltchenko 					le32_to_cpu(efs.sdu_itime);
357066af7aafSAndrei Emeltchenko 				chan->local_acc_lat = le32_to_cpu(efs.acc_lat);
357166af7aafSAndrei Emeltchenko 				chan->local_flush_to =
357266af7aafSAndrei Emeltchenko 					le32_to_cpu(efs.flush_to);
357366af7aafSAndrei Emeltchenko 			}
35740a708f8fSGustavo F. Padovan 			break;
357566af7aafSAndrei Emeltchenko 
35760a708f8fSGustavo F. Padovan 		case L2CAP_MODE_STREAMING:
357747d1ec61SGustavo F. Padovan 			chan->mps    = le16_to_cpu(rfc.max_pdu_size);
35780a708f8fSGustavo F. Padovan 		}
35790a708f8fSGustavo F. Padovan 	}
35800a708f8fSGustavo F. Padovan 
3581fe4128e0SGustavo F. Padovan 	req->dcid   = cpu_to_le16(chan->dcid);
3582dcf4adbfSJoe Perches 	req->flags  = cpu_to_le16(0);
35830a708f8fSGustavo F. Padovan 
35840a708f8fSGustavo F. Padovan 	return ptr - data;
35850a708f8fSGustavo F. Padovan }
35860a708f8fSGustavo F. Padovan 
35872d792818SGustavo Padovan static int l2cap_build_conf_rsp(struct l2cap_chan *chan, void *data,
35882d792818SGustavo Padovan 				u16 result, u16 flags)
35890a708f8fSGustavo F. Padovan {
35900a708f8fSGustavo F. Padovan 	struct l2cap_conf_rsp *rsp = data;
35910a708f8fSGustavo F. Padovan 	void *ptr = rsp->data;
35920a708f8fSGustavo F. Padovan 
3593fe4128e0SGustavo F. Padovan 	BT_DBG("chan %p", chan);
35940a708f8fSGustavo F. Padovan 
3595fe4128e0SGustavo F. Padovan 	rsp->scid   = cpu_to_le16(chan->dcid);
35960a708f8fSGustavo F. Padovan 	rsp->result = cpu_to_le16(result);
35970a708f8fSGustavo F. Padovan 	rsp->flags  = cpu_to_le16(flags);
35980a708f8fSGustavo F. Padovan 
35990a708f8fSGustavo F. Padovan 	return ptr - data;
36000a708f8fSGustavo F. Padovan }
36010a708f8fSGustavo F. Padovan 
360227e2d4c8SJohan Hedberg void __l2cap_le_connect_rsp_defer(struct l2cap_chan *chan)
360327e2d4c8SJohan Hedberg {
360427e2d4c8SJohan Hedberg 	struct l2cap_le_conn_rsp rsp;
360527e2d4c8SJohan Hedberg 	struct l2cap_conn *conn = chan->conn;
360627e2d4c8SJohan Hedberg 
360727e2d4c8SJohan Hedberg 	BT_DBG("chan %p", chan);
360827e2d4c8SJohan Hedberg 
360927e2d4c8SJohan Hedberg 	rsp.dcid    = cpu_to_le16(chan->scid);
361027e2d4c8SJohan Hedberg 	rsp.mtu     = cpu_to_le16(chan->imtu);
36113916aed8SJohan Hedberg 	rsp.mps     = cpu_to_le16(chan->mps);
36120cd75f7eSJohan Hedberg 	rsp.credits = cpu_to_le16(chan->rx_credits);
3613dcf4adbfSJoe Perches 	rsp.result  = cpu_to_le16(L2CAP_CR_SUCCESS);
361427e2d4c8SJohan Hedberg 
361527e2d4c8SJohan Hedberg 	l2cap_send_cmd(conn, chan->ident, L2CAP_LE_CONN_RSP, sizeof(rsp),
361627e2d4c8SJohan Hedberg 		       &rsp);
361727e2d4c8SJohan Hedberg }
361827e2d4c8SJohan Hedberg 
36198c1d787bSGustavo F. Padovan void __l2cap_connect_rsp_defer(struct l2cap_chan *chan)
3620710f9b0aSGustavo F. Padovan {
3621710f9b0aSGustavo F. Padovan 	struct l2cap_conn_rsp rsp;
36228c1d787bSGustavo F. Padovan 	struct l2cap_conn *conn = chan->conn;
3623710f9b0aSGustavo F. Padovan 	u8 buf[128];
3624439f34acSAndrei Emeltchenko 	u8 rsp_code;
3625710f9b0aSGustavo F. Padovan 
3626fe4128e0SGustavo F. Padovan 	rsp.scid   = cpu_to_le16(chan->dcid);
3627fe4128e0SGustavo F. Padovan 	rsp.dcid   = cpu_to_le16(chan->scid);
3628dcf4adbfSJoe Perches 	rsp.result = cpu_to_le16(L2CAP_CR_SUCCESS);
3629dcf4adbfSJoe Perches 	rsp.status = cpu_to_le16(L2CAP_CS_NO_INFO);
3630439f34acSAndrei Emeltchenko 
3631439f34acSAndrei Emeltchenko 	if (chan->hs_hcon)
3632439f34acSAndrei Emeltchenko 		rsp_code = L2CAP_CREATE_CHAN_RSP;
3633439f34acSAndrei Emeltchenko 	else
3634439f34acSAndrei Emeltchenko 		rsp_code = L2CAP_CONN_RSP;
3635439f34acSAndrei Emeltchenko 
3636439f34acSAndrei Emeltchenko 	BT_DBG("chan %p rsp_code %u", chan, rsp_code);
3637439f34acSAndrei Emeltchenko 
3638439f34acSAndrei Emeltchenko 	l2cap_send_cmd(conn, chan->ident, rsp_code, sizeof(rsp), &rsp);
3639710f9b0aSGustavo F. Padovan 
3640c1360a1cSGustavo F. Padovan 	if (test_and_set_bit(CONF_REQ_SENT, &chan->conf_state))
3641710f9b0aSGustavo F. Padovan 		return;
3642710f9b0aSGustavo F. Padovan 
3643710f9b0aSGustavo F. Padovan 	l2cap_send_cmd(conn, l2cap_get_ident(conn), L2CAP_CONF_REQ,
3644710f9b0aSGustavo F. Padovan 		       l2cap_build_conf_req(chan, buf), buf);
3645710f9b0aSGustavo F. Padovan 	chan->num_conf_req++;
3646710f9b0aSGustavo F. Padovan }
3647710f9b0aSGustavo F. Padovan 
364847d1ec61SGustavo F. Padovan static void l2cap_conf_rfc_get(struct l2cap_chan *chan, void *rsp, int len)
36490a708f8fSGustavo F. Padovan {
36500a708f8fSGustavo F. Padovan 	int type, olen;
36510a708f8fSGustavo F. Padovan 	unsigned long val;
3652c20f8e35SMat Martineau 	/* Use sane default values in case a misbehaving remote device
3653c20f8e35SMat Martineau 	 * did not send an RFC or extended window size option.
3654c20f8e35SMat Martineau 	 */
3655c20f8e35SMat Martineau 	u16 txwin_ext = chan->ack_win;
3656c20f8e35SMat Martineau 	struct l2cap_conf_rfc rfc = {
3657c20f8e35SMat Martineau 		.mode = chan->mode,
3658dcf4adbfSJoe Perches 		.retrans_timeout = cpu_to_le16(L2CAP_DEFAULT_RETRANS_TO),
3659dcf4adbfSJoe Perches 		.monitor_timeout = cpu_to_le16(L2CAP_DEFAULT_MONITOR_TO),
3660c20f8e35SMat Martineau 		.max_pdu_size = cpu_to_le16(chan->imtu),
3661c20f8e35SMat Martineau 		.txwin_size = min_t(u16, chan->ack_win, L2CAP_DEFAULT_TX_WINDOW),
3662c20f8e35SMat Martineau 	};
36630a708f8fSGustavo F. Padovan 
366447d1ec61SGustavo F. Padovan 	BT_DBG("chan %p, rsp %p, len %d", chan, rsp, len);
36650a708f8fSGustavo F. Padovan 
36660c1bc5c6SGustavo F. Padovan 	if ((chan->mode != L2CAP_MODE_ERTM) && (chan->mode != L2CAP_MODE_STREAMING))
36670a708f8fSGustavo F. Padovan 		return;
36680a708f8fSGustavo F. Padovan 
36690a708f8fSGustavo F. Padovan 	while (len >= L2CAP_CONF_OPT_SIZE) {
36700a708f8fSGustavo F. Padovan 		len -= l2cap_get_conf_opt(&rsp, &type, &olen, &val);
36710a708f8fSGustavo F. Padovan 
3672c20f8e35SMat Martineau 		switch (type) {
3673c20f8e35SMat Martineau 		case L2CAP_CONF_RFC:
3674c20f8e35SMat Martineau 			if (olen == sizeof(rfc))
36750a708f8fSGustavo F. Padovan 				memcpy(&rfc, (void *)val, olen);
3676c20f8e35SMat Martineau 			break;
3677c20f8e35SMat Martineau 		case L2CAP_CONF_EWS:
3678c20f8e35SMat Martineau 			txwin_ext = val;
3679c20f8e35SMat Martineau 			break;
3680c20f8e35SMat Martineau 		}
36810a708f8fSGustavo F. Padovan 	}
36820a708f8fSGustavo F. Padovan 
36830a708f8fSGustavo F. Padovan 	switch (rfc.mode) {
36840a708f8fSGustavo F. Padovan 	case L2CAP_MODE_ERTM:
368547d1ec61SGustavo F. Padovan 		chan->retrans_timeout = le16_to_cpu(rfc.retrans_timeout);
368647d1ec61SGustavo F. Padovan 		chan->monitor_timeout = le16_to_cpu(rfc.monitor_timeout);
368747d1ec61SGustavo F. Padovan 		chan->mps = le16_to_cpu(rfc.max_pdu_size);
3688c20f8e35SMat Martineau 		if (test_bit(FLAG_EXT_CTRL, &chan->flags))
3689c20f8e35SMat Martineau 			chan->ack_win = min_t(u16, chan->ack_win, txwin_ext);
3690c20f8e35SMat Martineau 		else
3691c20f8e35SMat Martineau 			chan->ack_win = min_t(u16, chan->ack_win,
3692c20f8e35SMat Martineau 					      rfc.txwin_size);
36930a708f8fSGustavo F. Padovan 		break;
36940a708f8fSGustavo F. Padovan 	case L2CAP_MODE_STREAMING:
369547d1ec61SGustavo F. Padovan 		chan->mps    = le16_to_cpu(rfc.max_pdu_size);
36960a708f8fSGustavo F. Padovan 	}
36970a708f8fSGustavo F. Padovan }
36980a708f8fSGustavo F. Padovan 
36992d792818SGustavo Padovan static inline int l2cap_command_rej(struct l2cap_conn *conn,
3700cb3b3152SJohan Hedberg 				    struct l2cap_cmd_hdr *cmd, u16 cmd_len,
3701cb3b3152SJohan Hedberg 				    u8 *data)
37020a708f8fSGustavo F. Padovan {
3703e2fd318eSIlia Kolomisnky 	struct l2cap_cmd_rej_unk *rej = (struct l2cap_cmd_rej_unk *) data;
37040a708f8fSGustavo F. Padovan 
3705cb3b3152SJohan Hedberg 	if (cmd_len < sizeof(*rej))
3706cb3b3152SJohan Hedberg 		return -EPROTO;
3707cb3b3152SJohan Hedberg 
3708e2fd318eSIlia Kolomisnky 	if (rej->reason != L2CAP_REJ_NOT_UNDERSTOOD)
37090a708f8fSGustavo F. Padovan 		return 0;
37100a708f8fSGustavo F. Padovan 
37110a708f8fSGustavo F. Padovan 	if ((conn->info_state & L2CAP_INFO_FEAT_MASK_REQ_SENT) &&
37120a708f8fSGustavo F. Padovan 	    cmd->ident == conn->info_ident) {
371317cd3f37SUlisses Furquim 		cancel_delayed_work(&conn->info_timer);
37140a708f8fSGustavo F. Padovan 
37150a708f8fSGustavo F. Padovan 		conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_DONE;
37160a708f8fSGustavo F. Padovan 		conn->info_ident = 0;
37170a708f8fSGustavo F. Padovan 
37180a708f8fSGustavo F. Padovan 		l2cap_conn_start(conn);
37190a708f8fSGustavo F. Padovan 	}
37200a708f8fSGustavo F. Padovan 
37210a708f8fSGustavo F. Padovan 	return 0;
37220a708f8fSGustavo F. Padovan }
37230a708f8fSGustavo F. Padovan 
37241700915fSMat Martineau static struct l2cap_chan *l2cap_connect(struct l2cap_conn *conn,
37251700915fSMat Martineau 					struct l2cap_cmd_hdr *cmd,
37264c89b6aaSMat Martineau 					u8 *data, u8 rsp_code, u8 amp_id)
37270a708f8fSGustavo F. Padovan {
37280a708f8fSGustavo F. Padovan 	struct l2cap_conn_req *req = (struct l2cap_conn_req *) data;
37290a708f8fSGustavo F. Padovan 	struct l2cap_conn_rsp rsp;
373023691d75SGustavo F. Padovan 	struct l2cap_chan *chan = NULL, *pchan;
37310a708f8fSGustavo F. Padovan 	int result, status = L2CAP_CS_NO_INFO;
37320a708f8fSGustavo F. Padovan 
37330a708f8fSGustavo F. Padovan 	u16 dcid = 0, scid = __le16_to_cpu(req->scid);
37340a708f8fSGustavo F. Padovan 	__le16 psm = req->psm;
37350a708f8fSGustavo F. Padovan 
3736097db76cSAndrei Emeltchenko 	BT_DBG("psm 0x%2.2x scid 0x%4.4x", __le16_to_cpu(psm), scid);
37370a708f8fSGustavo F. Padovan 
37380a708f8fSGustavo F. Padovan 	/* Check if we have socket listening on psm */
37396f59b904SMarcel Holtmann 	pchan = l2cap_global_chan_by_psm(BT_LISTEN, psm, &conn->hcon->src,
3740bf20fd4eSJohan Hedberg 					 &conn->hcon->dst, ACL_LINK);
374123691d75SGustavo F. Padovan 	if (!pchan) {
37420a708f8fSGustavo F. Padovan 		result = L2CAP_CR_BAD_PSM;
37430a708f8fSGustavo F. Padovan 		goto sendresp;
37440a708f8fSGustavo F. Padovan 	}
37450a708f8fSGustavo F. Padovan 
37463df91ea2SAndrei Emeltchenko 	mutex_lock(&conn->chan_lock);
37478ffb9290SGustavo Padovan 	l2cap_chan_lock(pchan);
37480a708f8fSGustavo F. Padovan 
37490a708f8fSGustavo F. Padovan 	/* Check if the ACL is secure enough (if not SDP) */
3750dcf4adbfSJoe Perches 	if (psm != cpu_to_le16(L2CAP_PSM_SDP) &&
37510a708f8fSGustavo F. Padovan 	    !hci_conn_check_link_mode(conn->hcon)) {
37529f5a0d7bSAndrei Emeltchenko 		conn->disc_reason = HCI_ERROR_AUTH_FAILURE;
37530a708f8fSGustavo F. Padovan 		result = L2CAP_CR_SEC_BLOCK;
37540a708f8fSGustavo F. Padovan 		goto response;
37550a708f8fSGustavo F. Padovan 	}
37560a708f8fSGustavo F. Padovan 
37570a708f8fSGustavo F. Padovan 	result = L2CAP_CR_NO_MEM;
37580a708f8fSGustavo F. Padovan 
37592dfa1003SGustavo Padovan 	/* Check if we already have channel with that dcid */
37602dfa1003SGustavo Padovan 	if (__l2cap_get_chan_by_dcid(conn, scid))
37612dfa1003SGustavo Padovan 		goto response;
37622dfa1003SGustavo Padovan 
376380b98027SGustavo Padovan 	chan = pchan->ops->new_connection(pchan);
376480808e43SGustavo F. Padovan 	if (!chan)
37650a708f8fSGustavo F. Padovan 		goto response;
37660a708f8fSGustavo F. Padovan 
3767330b6c15SSyam Sidhardhan 	/* For certain devices (ex: HID mouse), support for authentication,
3768330b6c15SSyam Sidhardhan 	 * pairing and bonding is optional. For such devices, inorder to avoid
3769330b6c15SSyam Sidhardhan 	 * the ACL alive for too long after L2CAP disconnection, reset the ACL
3770330b6c15SSyam Sidhardhan 	 * disc_timeout back to HCI_DISCONN_TIMEOUT during L2CAP connect.
3771330b6c15SSyam Sidhardhan 	 */
3772330b6c15SSyam Sidhardhan 	conn->hcon->disc_timeout = HCI_DISCONN_TIMEOUT;
3773330b6c15SSyam Sidhardhan 
37747eafc59eSMarcel Holtmann 	bacpy(&chan->src, &conn->hcon->src);
37757eafc59eSMarcel Holtmann 	bacpy(&chan->dst, &conn->hcon->dst);
37764f1654e0SMarcel Holtmann 	chan->src_type = bdaddr_type(conn->hcon, conn->hcon->src_type);
37774f1654e0SMarcel Holtmann 	chan->dst_type = bdaddr_type(conn->hcon, conn->hcon->dst_type);
3778fe4128e0SGustavo F. Padovan 	chan->psm  = psm;
3779fe4128e0SGustavo F. Padovan 	chan->dcid = scid;
37801700915fSMat Martineau 	chan->local_amp_id = amp_id;
37810a708f8fSGustavo F. Padovan 
37826be36555SAndrei Emeltchenko 	__l2cap_chan_add(conn, chan);
378348454079SGustavo F. Padovan 
3784fe4128e0SGustavo F. Padovan 	dcid = chan->scid;
37850a708f8fSGustavo F. Padovan 
37868d836d71SGustavo Padovan 	__set_chan_timer(chan, chan->ops->get_sndtimeo(chan));
37870a708f8fSGustavo F. Padovan 
3788fc7f8a7eSGustavo F. Padovan 	chan->ident = cmd->ident;
37890a708f8fSGustavo F. Padovan 
37900a708f8fSGustavo F. Padovan 	if (conn->info_state & L2CAP_INFO_FEAT_MASK_REQ_DONE) {
3791e7cafc45SJohan Hedberg 		if (l2cap_chan_check_security(chan, false)) {
3792bdc25783SMarcel Holtmann 			if (test_bit(FLAG_DEFER_SETUP, &chan->flags)) {
3793f93fa273SGustavo Padovan 				l2cap_state_change(chan, BT_CONNECT2);
37940a708f8fSGustavo F. Padovan 				result = L2CAP_CR_PEND;
37950a708f8fSGustavo F. Padovan 				status = L2CAP_CS_AUTHOR_PEND;
37962dc4e510SGustavo Padovan 				chan->ops->defer(chan);
37970a708f8fSGustavo F. Padovan 			} else {
37981700915fSMat Martineau 				/* Force pending result for AMP controllers.
37991700915fSMat Martineau 				 * The connection will succeed after the
38001700915fSMat Martineau 				 * physical link is up.
38011700915fSMat Martineau 				 */
38026ed971caSMarcel Holtmann 				if (amp_id == AMP_ID_BREDR) {
3803f93fa273SGustavo Padovan 					l2cap_state_change(chan, BT_CONFIG);
38040a708f8fSGustavo F. Padovan 					result = L2CAP_CR_SUCCESS;
38056ed971caSMarcel Holtmann 				} else {
3806f93fa273SGustavo Padovan 					l2cap_state_change(chan, BT_CONNECT2);
38076ed971caSMarcel Holtmann 					result = L2CAP_CR_PEND;
38081700915fSMat Martineau 				}
38090a708f8fSGustavo F. Padovan 				status = L2CAP_CS_NO_INFO;
38100a708f8fSGustavo F. Padovan 			}
38110a708f8fSGustavo F. Padovan 		} else {
3812f93fa273SGustavo Padovan 			l2cap_state_change(chan, BT_CONNECT2);
38130a708f8fSGustavo F. Padovan 			result = L2CAP_CR_PEND;
38140a708f8fSGustavo F. Padovan 			status = L2CAP_CS_AUTHEN_PEND;
38150a708f8fSGustavo F. Padovan 		}
38160a708f8fSGustavo F. Padovan 	} else {
3817f93fa273SGustavo Padovan 		l2cap_state_change(chan, BT_CONNECT2);
38180a708f8fSGustavo F. Padovan 		result = L2CAP_CR_PEND;
38190a708f8fSGustavo F. Padovan 		status = L2CAP_CS_NO_INFO;
38200a708f8fSGustavo F. Padovan 	}
38210a708f8fSGustavo F. Padovan 
38220a708f8fSGustavo F. Padovan response:
38238ffb9290SGustavo Padovan 	l2cap_chan_unlock(pchan);
38243df91ea2SAndrei Emeltchenko 	mutex_unlock(&conn->chan_lock);
3825a24cce14SJohan Hedberg 	l2cap_chan_put(pchan);
38260a708f8fSGustavo F. Padovan 
38270a708f8fSGustavo F. Padovan sendresp:
38280a708f8fSGustavo F. Padovan 	rsp.scid   = cpu_to_le16(scid);
38290a708f8fSGustavo F. Padovan 	rsp.dcid   = cpu_to_le16(dcid);
38300a708f8fSGustavo F. Padovan 	rsp.result = cpu_to_le16(result);
38310a708f8fSGustavo F. Padovan 	rsp.status = cpu_to_le16(status);
38324c89b6aaSMat Martineau 	l2cap_send_cmd(conn, cmd->ident, rsp_code, sizeof(rsp), &rsp);
38330a708f8fSGustavo F. Padovan 
38340a708f8fSGustavo F. Padovan 	if (result == L2CAP_CR_PEND && status == L2CAP_CS_NO_INFO) {
38350a708f8fSGustavo F. Padovan 		struct l2cap_info_req info;
3836dcf4adbfSJoe Perches 		info.type = cpu_to_le16(L2CAP_IT_FEAT_MASK);
38370a708f8fSGustavo F. Padovan 
38380a708f8fSGustavo F. Padovan 		conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_SENT;
38390a708f8fSGustavo F. Padovan 		conn->info_ident = l2cap_get_ident(conn);
38400a708f8fSGustavo F. Padovan 
3841ba13ccd9SMarcel Holtmann 		schedule_delayed_work(&conn->info_timer, L2CAP_INFO_TIMEOUT);
38420a708f8fSGustavo F. Padovan 
38432d792818SGustavo Padovan 		l2cap_send_cmd(conn, conn->info_ident, L2CAP_INFO_REQ,
38442d792818SGustavo Padovan 			       sizeof(info), &info);
38450a708f8fSGustavo F. Padovan 	}
38460a708f8fSGustavo F. Padovan 
3847c1360a1cSGustavo F. Padovan 	if (chan && !test_bit(CONF_REQ_SENT, &chan->conf_state) &&
38480a708f8fSGustavo F. Padovan 	    result == L2CAP_CR_SUCCESS) {
38490a708f8fSGustavo F. Padovan 		u8 buf[128];
3850c1360a1cSGustavo F. Padovan 		set_bit(CONF_REQ_SENT, &chan->conf_state);
38510a708f8fSGustavo F. Padovan 		l2cap_send_cmd(conn, l2cap_get_ident(conn), L2CAP_CONF_REQ,
385273ffa904SGustavo F. Padovan 			       l2cap_build_conf_req(chan, buf), buf);
385373ffa904SGustavo F. Padovan 		chan->num_conf_req++;
38540a708f8fSGustavo F. Padovan 	}
38551700915fSMat Martineau 
38561700915fSMat Martineau 	return chan;
38574c89b6aaSMat Martineau }
38580a708f8fSGustavo F. Padovan 
38594c89b6aaSMat Martineau static int l2cap_connect_req(struct l2cap_conn *conn,
3860cb3b3152SJohan Hedberg 			     struct l2cap_cmd_hdr *cmd, u16 cmd_len, u8 *data)
38614c89b6aaSMat Martineau {
38627b064edaSJaganath Kanakkassery 	struct hci_dev *hdev = conn->hcon->hdev;
38637b064edaSJaganath Kanakkassery 	struct hci_conn *hcon = conn->hcon;
38647b064edaSJaganath Kanakkassery 
3865cb3b3152SJohan Hedberg 	if (cmd_len < sizeof(struct l2cap_conn_req))
3866cb3b3152SJohan Hedberg 		return -EPROTO;
3867cb3b3152SJohan Hedberg 
38687b064edaSJaganath Kanakkassery 	hci_dev_lock(hdev);
38697b064edaSJaganath Kanakkassery 	if (test_bit(HCI_MGMT, &hdev->dev_flags) &&
38707b064edaSJaganath Kanakkassery 	    !test_and_set_bit(HCI_CONN_MGMT_CONNECTED, &hcon->flags))
38717b064edaSJaganath Kanakkassery 		mgmt_device_connected(hdev, &hcon->dst, hcon->type,
38727b064edaSJaganath Kanakkassery 				      hcon->dst_type, 0, NULL, 0,
38737b064edaSJaganath Kanakkassery 				      hcon->dev_class);
38747b064edaSJaganath Kanakkassery 	hci_dev_unlock(hdev);
38757b064edaSJaganath Kanakkassery 
3876300229f9SGustavo Padovan 	l2cap_connect(conn, cmd, data, L2CAP_CONN_RSP, 0);
38770a708f8fSGustavo F. Padovan 	return 0;
38780a708f8fSGustavo F. Padovan }
38790a708f8fSGustavo F. Padovan 
38805909cf30SMat Martineau static int l2cap_connect_create_rsp(struct l2cap_conn *conn,
3881cb3b3152SJohan Hedberg 				    struct l2cap_cmd_hdr *cmd, u16 cmd_len,
3882cb3b3152SJohan Hedberg 				    u8 *data)
38830a708f8fSGustavo F. Padovan {
38840a708f8fSGustavo F. Padovan 	struct l2cap_conn_rsp *rsp = (struct l2cap_conn_rsp *) data;
38850a708f8fSGustavo F. Padovan 	u16 scid, dcid, result, status;
388648454079SGustavo F. Padovan 	struct l2cap_chan *chan;
38870a708f8fSGustavo F. Padovan 	u8 req[128];
38883df91ea2SAndrei Emeltchenko 	int err;
38890a708f8fSGustavo F. Padovan 
3890cb3b3152SJohan Hedberg 	if (cmd_len < sizeof(*rsp))
3891cb3b3152SJohan Hedberg 		return -EPROTO;
3892cb3b3152SJohan Hedberg 
38930a708f8fSGustavo F. Padovan 	scid   = __le16_to_cpu(rsp->scid);
38940a708f8fSGustavo F. Padovan 	dcid   = __le16_to_cpu(rsp->dcid);
38950a708f8fSGustavo F. Padovan 	result = __le16_to_cpu(rsp->result);
38960a708f8fSGustavo F. Padovan 	status = __le16_to_cpu(rsp->status);
38970a708f8fSGustavo F. Padovan 
38981b009c98SAndrei Emeltchenko 	BT_DBG("dcid 0x%4.4x scid 0x%4.4x result 0x%2.2x status 0x%2.2x",
38991b009c98SAndrei Emeltchenko 	       dcid, scid, result, status);
39000a708f8fSGustavo F. Padovan 
39013df91ea2SAndrei Emeltchenko 	mutex_lock(&conn->chan_lock);
39023df91ea2SAndrei Emeltchenko 
39030a708f8fSGustavo F. Padovan 	if (scid) {
39043df91ea2SAndrei Emeltchenko 		chan = __l2cap_get_chan_by_scid(conn, scid);
39053df91ea2SAndrei Emeltchenko 		if (!chan) {
390621870b52SJohan Hedberg 			err = -EBADSLT;
39073df91ea2SAndrei Emeltchenko 			goto unlock;
39083df91ea2SAndrei Emeltchenko 		}
39090a708f8fSGustavo F. Padovan 	} else {
39103df91ea2SAndrei Emeltchenko 		chan = __l2cap_get_chan_by_ident(conn, cmd->ident);
39113df91ea2SAndrei Emeltchenko 		if (!chan) {
391221870b52SJohan Hedberg 			err = -EBADSLT;
39133df91ea2SAndrei Emeltchenko 			goto unlock;
39143df91ea2SAndrei Emeltchenko 		}
39150a708f8fSGustavo F. Padovan 	}
39160a708f8fSGustavo F. Padovan 
39173df91ea2SAndrei Emeltchenko 	err = 0;
39183df91ea2SAndrei Emeltchenko 
39196be36555SAndrei Emeltchenko 	l2cap_chan_lock(chan);
392048454079SGustavo F. Padovan 
39210a708f8fSGustavo F. Padovan 	switch (result) {
39220a708f8fSGustavo F. Padovan 	case L2CAP_CR_SUCCESS:
392389bc500eSGustavo F. Padovan 		l2cap_state_change(chan, BT_CONFIG);
3924fc7f8a7eSGustavo F. Padovan 		chan->ident = 0;
3925fe4128e0SGustavo F. Padovan 		chan->dcid = dcid;
3926c1360a1cSGustavo F. Padovan 		clear_bit(CONF_CONNECT_PEND, &chan->conf_state);
39270a708f8fSGustavo F. Padovan 
3928c1360a1cSGustavo F. Padovan 		if (test_and_set_bit(CONF_REQ_SENT, &chan->conf_state))
39290a708f8fSGustavo F. Padovan 			break;
39300a708f8fSGustavo F. Padovan 
39310a708f8fSGustavo F. Padovan 		l2cap_send_cmd(conn, l2cap_get_ident(conn), L2CAP_CONF_REQ,
393273ffa904SGustavo F. Padovan 			       l2cap_build_conf_req(chan, req), req);
393373ffa904SGustavo F. Padovan 		chan->num_conf_req++;
39340a708f8fSGustavo F. Padovan 		break;
39350a708f8fSGustavo F. Padovan 
39360a708f8fSGustavo F. Padovan 	case L2CAP_CR_PEND:
3937c1360a1cSGustavo F. Padovan 		set_bit(CONF_CONNECT_PEND, &chan->conf_state);
39380a708f8fSGustavo F. Padovan 		break;
39390a708f8fSGustavo F. Padovan 
39400a708f8fSGustavo F. Padovan 	default:
394148454079SGustavo F. Padovan 		l2cap_chan_del(chan, ECONNREFUSED);
39420a708f8fSGustavo F. Padovan 		break;
39430a708f8fSGustavo F. Padovan 	}
39440a708f8fSGustavo F. Padovan 
39456be36555SAndrei Emeltchenko 	l2cap_chan_unlock(chan);
39463df91ea2SAndrei Emeltchenko 
39473df91ea2SAndrei Emeltchenko unlock:
39483df91ea2SAndrei Emeltchenko 	mutex_unlock(&conn->chan_lock);
39493df91ea2SAndrei Emeltchenko 
39503df91ea2SAndrei Emeltchenko 	return err;
39510a708f8fSGustavo F. Padovan }
39520a708f8fSGustavo F. Padovan 
395347d1ec61SGustavo F. Padovan static inline void set_default_fcs(struct l2cap_chan *chan)
39540a708f8fSGustavo F. Padovan {
39550a708f8fSGustavo F. Padovan 	/* FCS is enabled only in ERTM or streaming mode, if one or both
39560a708f8fSGustavo F. Padovan 	 * sides request it.
39570a708f8fSGustavo F. Padovan 	 */
39580c1bc5c6SGustavo F. Padovan 	if (chan->mode != L2CAP_MODE_ERTM && chan->mode != L2CAP_MODE_STREAMING)
395947d1ec61SGustavo F. Padovan 		chan->fcs = L2CAP_FCS_NONE;
3960f2592d3eSAndrei Emeltchenko 	else if (!test_bit(CONF_RECV_NO_FCS, &chan->conf_state))
396147d1ec61SGustavo F. Padovan 		chan->fcs = L2CAP_FCS_CRC16;
39620a708f8fSGustavo F. Padovan }
39630a708f8fSGustavo F. Padovan 
396429d8a590SAndrei Emeltchenko static void l2cap_send_efs_conf_rsp(struct l2cap_chan *chan, void *data,
396529d8a590SAndrei Emeltchenko 				    u8 ident, u16 flags)
396629d8a590SAndrei Emeltchenko {
396729d8a590SAndrei Emeltchenko 	struct l2cap_conn *conn = chan->conn;
396829d8a590SAndrei Emeltchenko 
396929d8a590SAndrei Emeltchenko 	BT_DBG("conn %p chan %p ident %d flags 0x%4.4x", conn, chan, ident,
397029d8a590SAndrei Emeltchenko 	       flags);
397129d8a590SAndrei Emeltchenko 
397229d8a590SAndrei Emeltchenko 	clear_bit(CONF_LOC_CONF_PEND, &chan->conf_state);
397329d8a590SAndrei Emeltchenko 	set_bit(CONF_OUTPUT_DONE, &chan->conf_state);
397429d8a590SAndrei Emeltchenko 
397529d8a590SAndrei Emeltchenko 	l2cap_send_cmd(conn, ident, L2CAP_CONF_RSP,
397629d8a590SAndrei Emeltchenko 		       l2cap_build_conf_rsp(chan, data,
397729d8a590SAndrei Emeltchenko 					    L2CAP_CONF_SUCCESS, flags), data);
397829d8a590SAndrei Emeltchenko }
397929d8a590SAndrei Emeltchenko 
3980662d652dSJohan Hedberg static void cmd_reject_invalid_cid(struct l2cap_conn *conn, u8 ident,
3981662d652dSJohan Hedberg 				   u16 scid, u16 dcid)
3982662d652dSJohan Hedberg {
3983662d652dSJohan Hedberg 	struct l2cap_cmd_rej_cid rej;
3984662d652dSJohan Hedberg 
3985dcf4adbfSJoe Perches 	rej.reason = cpu_to_le16(L2CAP_REJ_INVALID_CID);
3986662d652dSJohan Hedberg 	rej.scid = __cpu_to_le16(scid);
3987662d652dSJohan Hedberg 	rej.dcid = __cpu_to_le16(dcid);
3988662d652dSJohan Hedberg 
3989662d652dSJohan Hedberg 	l2cap_send_cmd(conn, ident, L2CAP_COMMAND_REJ, sizeof(rej), &rej);
3990662d652dSJohan Hedberg }
3991662d652dSJohan Hedberg 
39922d792818SGustavo Padovan static inline int l2cap_config_req(struct l2cap_conn *conn,
39932d792818SGustavo Padovan 				   struct l2cap_cmd_hdr *cmd, u16 cmd_len,
39942d792818SGustavo Padovan 				   u8 *data)
39950a708f8fSGustavo F. Padovan {
39960a708f8fSGustavo F. Padovan 	struct l2cap_conf_req *req = (struct l2cap_conf_req *) data;
39970a708f8fSGustavo F. Padovan 	u16 dcid, flags;
39980a708f8fSGustavo F. Padovan 	u8 rsp[64];
399948454079SGustavo F. Padovan 	struct l2cap_chan *chan;
40003c588192SMat Martineau 	int len, err = 0;
40010a708f8fSGustavo F. Padovan 
4002cb3b3152SJohan Hedberg 	if (cmd_len < sizeof(*req))
4003cb3b3152SJohan Hedberg 		return -EPROTO;
4004cb3b3152SJohan Hedberg 
40050a708f8fSGustavo F. Padovan 	dcid  = __le16_to_cpu(req->dcid);
40060a708f8fSGustavo F. Padovan 	flags = __le16_to_cpu(req->flags);
40070a708f8fSGustavo F. Padovan 
40080a708f8fSGustavo F. Padovan 	BT_DBG("dcid 0x%4.4x flags 0x%2.2x", dcid, flags);
40090a708f8fSGustavo F. Padovan 
4010baa7e1faSGustavo F. Padovan 	chan = l2cap_get_chan_by_scid(conn, dcid);
4011662d652dSJohan Hedberg 	if (!chan) {
4012662d652dSJohan Hedberg 		cmd_reject_invalid_cid(conn, cmd->ident, dcid, 0);
4013662d652dSJohan Hedberg 		return 0;
4014662d652dSJohan Hedberg 	}
40150a708f8fSGustavo F. Padovan 
4016033b1142SDavid S. Miller 	if (chan->state != BT_CONFIG && chan->state != BT_CONNECT2) {
4017662d652dSJohan Hedberg 		cmd_reject_invalid_cid(conn, cmd->ident, chan->scid,
4018662d652dSJohan Hedberg 				       chan->dcid);
40190a708f8fSGustavo F. Padovan 		goto unlock;
40200a708f8fSGustavo F. Padovan 	}
40210a708f8fSGustavo F. Padovan 
40220a708f8fSGustavo F. Padovan 	/* Reject if config buffer is too small. */
40230a708f8fSGustavo F. Padovan 	len = cmd_len - sizeof(*req);
4024cb3b3152SJohan Hedberg 	if (chan->conf_len + len > sizeof(chan->conf_req)) {
40250a708f8fSGustavo F. Padovan 		l2cap_send_cmd(conn, cmd->ident, L2CAP_CONF_RSP,
4026fe4128e0SGustavo F. Padovan 			       l2cap_build_conf_rsp(chan, rsp,
40270a708f8fSGustavo F. Padovan 			       L2CAP_CONF_REJECT, flags), rsp);
40280a708f8fSGustavo F. Padovan 		goto unlock;
40290a708f8fSGustavo F. Padovan 	}
40300a708f8fSGustavo F. Padovan 
40310a708f8fSGustavo F. Padovan 	/* Store config. */
403273ffa904SGustavo F. Padovan 	memcpy(chan->conf_req + chan->conf_len, req->data, len);
403373ffa904SGustavo F. Padovan 	chan->conf_len += len;
40340a708f8fSGustavo F. Padovan 
403559e54bd1SAndrei Emeltchenko 	if (flags & L2CAP_CONF_FLAG_CONTINUATION) {
40360a708f8fSGustavo F. Padovan 		/* Incomplete config. Send empty response. */
40370a708f8fSGustavo F. Padovan 		l2cap_send_cmd(conn, cmd->ident, L2CAP_CONF_RSP,
4038fe4128e0SGustavo F. Padovan 			       l2cap_build_conf_rsp(chan, rsp,
40395325e5bbSAndrei Emeltchenko 			       L2CAP_CONF_SUCCESS, flags), rsp);
40400a708f8fSGustavo F. Padovan 		goto unlock;
40410a708f8fSGustavo F. Padovan 	}
40420a708f8fSGustavo F. Padovan 
40430a708f8fSGustavo F. Padovan 	/* Complete config. */
404473ffa904SGustavo F. Padovan 	len = l2cap_parse_conf_req(chan, rsp);
40450a708f8fSGustavo F. Padovan 	if (len < 0) {
40465e4e3972SAndrei Emeltchenko 		l2cap_send_disconn_req(chan, ECONNRESET);
40470a708f8fSGustavo F. Padovan 		goto unlock;
40480a708f8fSGustavo F. Padovan 	}
40490a708f8fSGustavo F. Padovan 
40501500109bSMat Martineau 	chan->ident = cmd->ident;
40510a708f8fSGustavo F. Padovan 	l2cap_send_cmd(conn, cmd->ident, L2CAP_CONF_RSP, len, rsp);
405273ffa904SGustavo F. Padovan 	chan->num_conf_rsp++;
40530a708f8fSGustavo F. Padovan 
40540a708f8fSGustavo F. Padovan 	/* Reset config buffer. */
405573ffa904SGustavo F. Padovan 	chan->conf_len = 0;
40560a708f8fSGustavo F. Padovan 
4057c1360a1cSGustavo F. Padovan 	if (!test_bit(CONF_OUTPUT_DONE, &chan->conf_state))
40580a708f8fSGustavo F. Padovan 		goto unlock;
40590a708f8fSGustavo F. Padovan 
4060c1360a1cSGustavo F. Padovan 	if (test_bit(CONF_INPUT_DONE, &chan->conf_state)) {
406147d1ec61SGustavo F. Padovan 		set_default_fcs(chan);
40620a708f8fSGustavo F. Padovan 
4063105bdf9eSMat Martineau 		if (chan->mode == L2CAP_MODE_ERTM ||
4064105bdf9eSMat Martineau 		    chan->mode == L2CAP_MODE_STREAMING)
40653c588192SMat Martineau 			err = l2cap_ertm_init(chan);
40660a708f8fSGustavo F. Padovan 
40673c588192SMat Martineau 		if (err < 0)
40685e4e3972SAndrei Emeltchenko 			l2cap_send_disconn_req(chan, -err);
40693c588192SMat Martineau 		else
4070cf4cd009SAndrei Emeltchenko 			l2cap_chan_ready(chan);
40713c588192SMat Martineau 
40720a708f8fSGustavo F. Padovan 		goto unlock;
40730a708f8fSGustavo F. Padovan 	}
40740a708f8fSGustavo F. Padovan 
4075c1360a1cSGustavo F. Padovan 	if (!test_and_set_bit(CONF_REQ_SENT, &chan->conf_state)) {
40760a708f8fSGustavo F. Padovan 		u8 buf[64];
40770a708f8fSGustavo F. Padovan 		l2cap_send_cmd(conn, l2cap_get_ident(conn), L2CAP_CONF_REQ,
407873ffa904SGustavo F. Padovan 			       l2cap_build_conf_req(chan, buf), buf);
407973ffa904SGustavo F. Padovan 		chan->num_conf_req++;
40800a708f8fSGustavo F. Padovan 	}
40810a708f8fSGustavo F. Padovan 
40820e8b207eSAndrei Emeltchenko 	/* Got Conf Rsp PENDING from remote side and asume we sent
40830e8b207eSAndrei Emeltchenko 	   Conf Rsp PENDING in the code above */
40840e8b207eSAndrei Emeltchenko 	if (test_bit(CONF_REM_CONF_PEND, &chan->conf_state) &&
40850e8b207eSAndrei Emeltchenko 	    test_bit(CONF_LOC_CONF_PEND, &chan->conf_state)) {
40860e8b207eSAndrei Emeltchenko 
40870e8b207eSAndrei Emeltchenko 		/* check compatibility */
40880e8b207eSAndrei Emeltchenko 
408979de886dSAndrei Emeltchenko 		/* Send rsp for BR/EDR channel */
4090f351bc72SAndrei Emeltchenko 		if (!chan->hs_hcon)
409129d8a590SAndrei Emeltchenko 			l2cap_send_efs_conf_rsp(chan, rsp, cmd->ident, flags);
409279de886dSAndrei Emeltchenko 		else
409379de886dSAndrei Emeltchenko 			chan->ident = cmd->ident;
40940e8b207eSAndrei Emeltchenko 	}
40950e8b207eSAndrei Emeltchenko 
40960a708f8fSGustavo F. Padovan unlock:
40976be36555SAndrei Emeltchenko 	l2cap_chan_unlock(chan);
40983c588192SMat Martineau 	return err;
40990a708f8fSGustavo F. Padovan }
41000a708f8fSGustavo F. Padovan 
41012d792818SGustavo Padovan static inline int l2cap_config_rsp(struct l2cap_conn *conn,
4102cb3b3152SJohan Hedberg 				   struct l2cap_cmd_hdr *cmd, u16 cmd_len,
4103cb3b3152SJohan Hedberg 				   u8 *data)
41040a708f8fSGustavo F. Padovan {
41050a708f8fSGustavo F. Padovan 	struct l2cap_conf_rsp *rsp = (struct l2cap_conf_rsp *)data;
41060a708f8fSGustavo F. Padovan 	u16 scid, flags, result;
410748454079SGustavo F. Padovan 	struct l2cap_chan *chan;
4108cb3b3152SJohan Hedberg 	int len = cmd_len - sizeof(*rsp);
41093c588192SMat Martineau 	int err = 0;
41100a708f8fSGustavo F. Padovan 
4111cb3b3152SJohan Hedberg 	if (cmd_len < sizeof(*rsp))
4112cb3b3152SJohan Hedberg 		return -EPROTO;
4113cb3b3152SJohan Hedberg 
41140a708f8fSGustavo F. Padovan 	scid   = __le16_to_cpu(rsp->scid);
41150a708f8fSGustavo F. Padovan 	flags  = __le16_to_cpu(rsp->flags);
41160a708f8fSGustavo F. Padovan 	result = __le16_to_cpu(rsp->result);
41170a708f8fSGustavo F. Padovan 
411861386cbaSAndrei Emeltchenko 	BT_DBG("scid 0x%4.4x flags 0x%2.2x result 0x%2.2x len %d", scid, flags,
411961386cbaSAndrei Emeltchenko 	       result, len);
41200a708f8fSGustavo F. Padovan 
4121baa7e1faSGustavo F. Padovan 	chan = l2cap_get_chan_by_scid(conn, scid);
412248454079SGustavo F. Padovan 	if (!chan)
41230a708f8fSGustavo F. Padovan 		return 0;
41240a708f8fSGustavo F. Padovan 
41250a708f8fSGustavo F. Padovan 	switch (result) {
41260a708f8fSGustavo F. Padovan 	case L2CAP_CONF_SUCCESS:
412747d1ec61SGustavo F. Padovan 		l2cap_conf_rfc_get(chan, rsp->data, len);
41280e8b207eSAndrei Emeltchenko 		clear_bit(CONF_REM_CONF_PEND, &chan->conf_state);
41290a708f8fSGustavo F. Padovan 		break;
41300a708f8fSGustavo F. Padovan 
41310e8b207eSAndrei Emeltchenko 	case L2CAP_CONF_PENDING:
41320e8b207eSAndrei Emeltchenko 		set_bit(CONF_REM_CONF_PEND, &chan->conf_state);
41330e8b207eSAndrei Emeltchenko 
41340e8b207eSAndrei Emeltchenko 		if (test_bit(CONF_LOC_CONF_PEND, &chan->conf_state)) {
41350e8b207eSAndrei Emeltchenko 			char buf[64];
41360e8b207eSAndrei Emeltchenko 
41370e8b207eSAndrei Emeltchenko 			len = l2cap_parse_conf_rsp(chan, rsp->data, len,
41380e8b207eSAndrei Emeltchenko 						   buf, &result);
41390e8b207eSAndrei Emeltchenko 			if (len < 0) {
41405e4e3972SAndrei Emeltchenko 				l2cap_send_disconn_req(chan, ECONNRESET);
41410e8b207eSAndrei Emeltchenko 				goto done;
41420e8b207eSAndrei Emeltchenko 			}
41430e8b207eSAndrei Emeltchenko 
4144f351bc72SAndrei Emeltchenko 			if (!chan->hs_hcon) {
414579de886dSAndrei Emeltchenko 				l2cap_send_efs_conf_rsp(chan, buf, cmd->ident,
414679de886dSAndrei Emeltchenko 							0);
41475ce66b59SAndrei Emeltchenko 			} else {
41485ce66b59SAndrei Emeltchenko 				if (l2cap_check_efs(chan)) {
41495ce66b59SAndrei Emeltchenko 					amp_create_logical_link(chan);
415079de886dSAndrei Emeltchenko 					chan->ident = cmd->ident;
41510e8b207eSAndrei Emeltchenko 				}
41525ce66b59SAndrei Emeltchenko 			}
41535ce66b59SAndrei Emeltchenko 		}
41540e8b207eSAndrei Emeltchenko 		goto done;
41550e8b207eSAndrei Emeltchenko 
41560a708f8fSGustavo F. Padovan 	case L2CAP_CONF_UNACCEPT:
415773ffa904SGustavo F. Padovan 		if (chan->num_conf_rsp <= L2CAP_CONF_MAX_CONF_RSP) {
41580a708f8fSGustavo F. Padovan 			char req[64];
41590a708f8fSGustavo F. Padovan 
41600a708f8fSGustavo F. Padovan 			if (len > sizeof(req) - sizeof(struct l2cap_conf_req)) {
41615e4e3972SAndrei Emeltchenko 				l2cap_send_disconn_req(chan, ECONNRESET);
41620a708f8fSGustavo F. Padovan 				goto done;
41630a708f8fSGustavo F. Padovan 			}
41640a708f8fSGustavo F. Padovan 
41650a708f8fSGustavo F. Padovan 			/* throw out any old stored conf requests */
41660a708f8fSGustavo F. Padovan 			result = L2CAP_CONF_SUCCESS;
4167b4450035SGustavo F. Padovan 			len = l2cap_parse_conf_rsp(chan, rsp->data, len,
4168b4450035SGustavo F. Padovan 						   req, &result);
41690a708f8fSGustavo F. Padovan 			if (len < 0) {
41705e4e3972SAndrei Emeltchenko 				l2cap_send_disconn_req(chan, ECONNRESET);
41710a708f8fSGustavo F. Padovan 				goto done;
41720a708f8fSGustavo F. Padovan 			}
41730a708f8fSGustavo F. Padovan 
41740a708f8fSGustavo F. Padovan 			l2cap_send_cmd(conn, l2cap_get_ident(conn),
41750a708f8fSGustavo F. Padovan 				       L2CAP_CONF_REQ, len, req);
417673ffa904SGustavo F. Padovan 			chan->num_conf_req++;
41770a708f8fSGustavo F. Padovan 			if (result != L2CAP_CONF_SUCCESS)
41780a708f8fSGustavo F. Padovan 				goto done;
41790a708f8fSGustavo F. Padovan 			break;
41800a708f8fSGustavo F. Padovan 		}
41810a708f8fSGustavo F. Padovan 
41820a708f8fSGustavo F. Padovan 	default:
41836be36555SAndrei Emeltchenko 		l2cap_chan_set_err(chan, ECONNRESET);
41842e0052e4SAndrei Emeltchenko 
4185ba13ccd9SMarcel Holtmann 		__set_chan_timer(chan, L2CAP_DISC_REJ_TIMEOUT);
41865e4e3972SAndrei Emeltchenko 		l2cap_send_disconn_req(chan, ECONNRESET);
41870a708f8fSGustavo F. Padovan 		goto done;
41880a708f8fSGustavo F. Padovan 	}
41890a708f8fSGustavo F. Padovan 
419059e54bd1SAndrei Emeltchenko 	if (flags & L2CAP_CONF_FLAG_CONTINUATION)
41910a708f8fSGustavo F. Padovan 		goto done;
41920a708f8fSGustavo F. Padovan 
4193c1360a1cSGustavo F. Padovan 	set_bit(CONF_INPUT_DONE, &chan->conf_state);
41940a708f8fSGustavo F. Padovan 
4195c1360a1cSGustavo F. Padovan 	if (test_bit(CONF_OUTPUT_DONE, &chan->conf_state)) {
419647d1ec61SGustavo F. Padovan 		set_default_fcs(chan);
41970a708f8fSGustavo F. Padovan 
4198105bdf9eSMat Martineau 		if (chan->mode == L2CAP_MODE_ERTM ||
4199105bdf9eSMat Martineau 		    chan->mode == L2CAP_MODE_STREAMING)
42003c588192SMat Martineau 			err = l2cap_ertm_init(chan);
42010a708f8fSGustavo F. Padovan 
42023c588192SMat Martineau 		if (err < 0)
42035e4e3972SAndrei Emeltchenko 			l2cap_send_disconn_req(chan, -err);
42043c588192SMat Martineau 		else
4205cf4cd009SAndrei Emeltchenko 			l2cap_chan_ready(chan);
42060a708f8fSGustavo F. Padovan 	}
42070a708f8fSGustavo F. Padovan 
42080a708f8fSGustavo F. Padovan done:
42096be36555SAndrei Emeltchenko 	l2cap_chan_unlock(chan);
42103c588192SMat Martineau 	return err;
42110a708f8fSGustavo F. Padovan }
42120a708f8fSGustavo F. Padovan 
42132d792818SGustavo Padovan static inline int l2cap_disconnect_req(struct l2cap_conn *conn,
4214cb3b3152SJohan Hedberg 				       struct l2cap_cmd_hdr *cmd, u16 cmd_len,
4215cb3b3152SJohan Hedberg 				       u8 *data)
42160a708f8fSGustavo F. Padovan {
42170a708f8fSGustavo F. Padovan 	struct l2cap_disconn_req *req = (struct l2cap_disconn_req *) data;
42180a708f8fSGustavo F. Padovan 	struct l2cap_disconn_rsp rsp;
42190a708f8fSGustavo F. Padovan 	u16 dcid, scid;
422048454079SGustavo F. Padovan 	struct l2cap_chan *chan;
42210a708f8fSGustavo F. Padovan 
4222cb3b3152SJohan Hedberg 	if (cmd_len != sizeof(*req))
4223cb3b3152SJohan Hedberg 		return -EPROTO;
4224cb3b3152SJohan Hedberg 
42250a708f8fSGustavo F. Padovan 	scid = __le16_to_cpu(req->scid);
42260a708f8fSGustavo F. Padovan 	dcid = __le16_to_cpu(req->dcid);
42270a708f8fSGustavo F. Padovan 
42280a708f8fSGustavo F. Padovan 	BT_DBG("scid 0x%4.4x dcid 0x%4.4x", scid, dcid);
42290a708f8fSGustavo F. Padovan 
42303df91ea2SAndrei Emeltchenko 	mutex_lock(&conn->chan_lock);
42313df91ea2SAndrei Emeltchenko 
42323df91ea2SAndrei Emeltchenko 	chan = __l2cap_get_chan_by_scid(conn, dcid);
42333df91ea2SAndrei Emeltchenko 	if (!chan) {
42343df91ea2SAndrei Emeltchenko 		mutex_unlock(&conn->chan_lock);
4235662d652dSJohan Hedberg 		cmd_reject_invalid_cid(conn, cmd->ident, dcid, scid);
4236662d652dSJohan Hedberg 		return 0;
42373df91ea2SAndrei Emeltchenko 	}
42380a708f8fSGustavo F. Padovan 
42396be36555SAndrei Emeltchenko 	l2cap_chan_lock(chan);
42406be36555SAndrei Emeltchenko 
4241fe4128e0SGustavo F. Padovan 	rsp.dcid = cpu_to_le16(chan->scid);
4242fe4128e0SGustavo F. Padovan 	rsp.scid = cpu_to_le16(chan->dcid);
42430a708f8fSGustavo F. Padovan 	l2cap_send_cmd(conn, cmd->ident, L2CAP_DISCONN_RSP, sizeof(rsp), &rsp);
42440a708f8fSGustavo F. Padovan 
42455ec1bbe5SGustavo Padovan 	chan->ops->set_shutdown(chan);
42460a708f8fSGustavo F. Padovan 
424761d6ef3eSMat Martineau 	l2cap_chan_hold(chan);
424848454079SGustavo F. Padovan 	l2cap_chan_del(chan, ECONNRESET);
42496be36555SAndrei Emeltchenko 
42506be36555SAndrei Emeltchenko 	l2cap_chan_unlock(chan);
42510a708f8fSGustavo F. Padovan 
425280b98027SGustavo Padovan 	chan->ops->close(chan);
425361d6ef3eSMat Martineau 	l2cap_chan_put(chan);
42543df91ea2SAndrei Emeltchenko 
42553df91ea2SAndrei Emeltchenko 	mutex_unlock(&conn->chan_lock);
42563df91ea2SAndrei Emeltchenko 
42570a708f8fSGustavo F. Padovan 	return 0;
42580a708f8fSGustavo F. Padovan }
42590a708f8fSGustavo F. Padovan 
42602d792818SGustavo Padovan static inline int l2cap_disconnect_rsp(struct l2cap_conn *conn,
4261cb3b3152SJohan Hedberg 				       struct l2cap_cmd_hdr *cmd, u16 cmd_len,
4262cb3b3152SJohan Hedberg 				       u8 *data)
42630a708f8fSGustavo F. Padovan {
42640a708f8fSGustavo F. Padovan 	struct l2cap_disconn_rsp *rsp = (struct l2cap_disconn_rsp *) data;
42650a708f8fSGustavo F. Padovan 	u16 dcid, scid;
426648454079SGustavo F. Padovan 	struct l2cap_chan *chan;
42670a708f8fSGustavo F. Padovan 
4268cb3b3152SJohan Hedberg 	if (cmd_len != sizeof(*rsp))
4269cb3b3152SJohan Hedberg 		return -EPROTO;
4270cb3b3152SJohan Hedberg 
42710a708f8fSGustavo F. Padovan 	scid = __le16_to_cpu(rsp->scid);
42720a708f8fSGustavo F. Padovan 	dcid = __le16_to_cpu(rsp->dcid);
42730a708f8fSGustavo F. Padovan 
42740a708f8fSGustavo F. Padovan 	BT_DBG("dcid 0x%4.4x scid 0x%4.4x", dcid, scid);
42750a708f8fSGustavo F. Padovan 
42763df91ea2SAndrei Emeltchenko 	mutex_lock(&conn->chan_lock);
42773df91ea2SAndrei Emeltchenko 
42783df91ea2SAndrei Emeltchenko 	chan = __l2cap_get_chan_by_scid(conn, scid);
42793df91ea2SAndrei Emeltchenko 	if (!chan) {
42803df91ea2SAndrei Emeltchenko 		mutex_unlock(&conn->chan_lock);
42810a708f8fSGustavo F. Padovan 		return 0;
42823df91ea2SAndrei Emeltchenko 	}
42830a708f8fSGustavo F. Padovan 
42846be36555SAndrei Emeltchenko 	l2cap_chan_lock(chan);
428548454079SGustavo F. Padovan 
428661d6ef3eSMat Martineau 	l2cap_chan_hold(chan);
428748454079SGustavo F. Padovan 	l2cap_chan_del(chan, 0);
42886be36555SAndrei Emeltchenko 
42896be36555SAndrei Emeltchenko 	l2cap_chan_unlock(chan);
42900a708f8fSGustavo F. Padovan 
429180b98027SGustavo Padovan 	chan->ops->close(chan);
429261d6ef3eSMat Martineau 	l2cap_chan_put(chan);
42933df91ea2SAndrei Emeltchenko 
42943df91ea2SAndrei Emeltchenko 	mutex_unlock(&conn->chan_lock);
42953df91ea2SAndrei Emeltchenko 
42960a708f8fSGustavo F. Padovan 	return 0;
42970a708f8fSGustavo F. Padovan }
42980a708f8fSGustavo F. Padovan 
42992d792818SGustavo Padovan static inline int l2cap_information_req(struct l2cap_conn *conn,
4300cb3b3152SJohan Hedberg 					struct l2cap_cmd_hdr *cmd, u16 cmd_len,
4301cb3b3152SJohan Hedberg 					u8 *data)
43020a708f8fSGustavo F. Padovan {
43030a708f8fSGustavo F. Padovan 	struct l2cap_info_req *req = (struct l2cap_info_req *) data;
43040a708f8fSGustavo F. Padovan 	u16 type;
43050a708f8fSGustavo F. Padovan 
4306cb3b3152SJohan Hedberg 	if (cmd_len != sizeof(*req))
4307cb3b3152SJohan Hedberg 		return -EPROTO;
4308cb3b3152SJohan Hedberg 
43090a708f8fSGustavo F. Padovan 	type = __le16_to_cpu(req->type);
43100a708f8fSGustavo F. Padovan 
43110a708f8fSGustavo F. Padovan 	BT_DBG("type 0x%4.4x", type);
43120a708f8fSGustavo F. Padovan 
43130a708f8fSGustavo F. Padovan 	if (type == L2CAP_IT_FEAT_MASK) {
43140a708f8fSGustavo F. Padovan 		u8 buf[8];
43150a708f8fSGustavo F. Padovan 		u32 feat_mask = l2cap_feat_mask;
43160a708f8fSGustavo F. Padovan 		struct l2cap_info_rsp *rsp = (struct l2cap_info_rsp *) buf;
4317dcf4adbfSJoe Perches 		rsp->type   = cpu_to_le16(L2CAP_IT_FEAT_MASK);
4318dcf4adbfSJoe Perches 		rsp->result = cpu_to_le16(L2CAP_IR_SUCCESS);
43190a708f8fSGustavo F. Padovan 		if (!disable_ertm)
43200a708f8fSGustavo F. Padovan 			feat_mask |= L2CAP_FEAT_ERTM | L2CAP_FEAT_STREAMING
43210a708f8fSGustavo F. Padovan 				| L2CAP_FEAT_FCS;
4322848566b3SMarcel Holtmann 		if (conn->hs_enabled)
43236327eb98SAndrei Emeltchenko 			feat_mask |= L2CAP_FEAT_EXT_FLOW
43246327eb98SAndrei Emeltchenko 				| L2CAP_FEAT_EXT_WINDOW;
4325a5fd6f30SAndrei Emeltchenko 
43260a708f8fSGustavo F. Padovan 		put_unaligned_le32(feat_mask, rsp->data);
43272d792818SGustavo Padovan 		l2cap_send_cmd(conn, cmd->ident, L2CAP_INFO_RSP, sizeof(buf),
43282d792818SGustavo Padovan 			       buf);
43290a708f8fSGustavo F. Padovan 	} else if (type == L2CAP_IT_FIXED_CHAN) {
43300a708f8fSGustavo F. Padovan 		u8 buf[12];
43310a708f8fSGustavo F. Padovan 		struct l2cap_info_rsp *rsp = (struct l2cap_info_rsp *) buf;
433250a147cdSMat Martineau 
4333848566b3SMarcel Holtmann 		if (conn->hs_enabled)
433450a147cdSMat Martineau 			l2cap_fixed_chan[0] |= L2CAP_FC_A2MP;
433550a147cdSMat Martineau 		else
433650a147cdSMat Martineau 			l2cap_fixed_chan[0] &= ~L2CAP_FC_A2MP;
433750a147cdSMat Martineau 
4338dcf4adbfSJoe Perches 		rsp->type   = cpu_to_le16(L2CAP_IT_FIXED_CHAN);
4339dcf4adbfSJoe Perches 		rsp->result = cpu_to_le16(L2CAP_IR_SUCCESS);
4340c6337ea6SAndrei Emeltchenko 		memcpy(rsp->data, l2cap_fixed_chan, sizeof(l2cap_fixed_chan));
43412d792818SGustavo Padovan 		l2cap_send_cmd(conn, cmd->ident, L2CAP_INFO_RSP, sizeof(buf),
43422d792818SGustavo Padovan 			       buf);
43430a708f8fSGustavo F. Padovan 	} else {
43440a708f8fSGustavo F. Padovan 		struct l2cap_info_rsp rsp;
43450a708f8fSGustavo F. Padovan 		rsp.type   = cpu_to_le16(type);
4346dcf4adbfSJoe Perches 		rsp.result = cpu_to_le16(L2CAP_IR_NOTSUPP);
43472d792818SGustavo Padovan 		l2cap_send_cmd(conn, cmd->ident, L2CAP_INFO_RSP, sizeof(rsp),
43482d792818SGustavo Padovan 			       &rsp);
43490a708f8fSGustavo F. Padovan 	}
43500a708f8fSGustavo F. Padovan 
43510a708f8fSGustavo F. Padovan 	return 0;
43520a708f8fSGustavo F. Padovan }
43530a708f8fSGustavo F. Padovan 
43542d792818SGustavo Padovan static inline int l2cap_information_rsp(struct l2cap_conn *conn,
4355cb3b3152SJohan Hedberg 					struct l2cap_cmd_hdr *cmd, u16 cmd_len,
4356cb3b3152SJohan Hedberg 					u8 *data)
43570a708f8fSGustavo F. Padovan {
43580a708f8fSGustavo F. Padovan 	struct l2cap_info_rsp *rsp = (struct l2cap_info_rsp *) data;
43590a708f8fSGustavo F. Padovan 	u16 type, result;
43600a708f8fSGustavo F. Padovan 
43613f6fa3d4SJaganath Kanakkassery 	if (cmd_len < sizeof(*rsp))
4362cb3b3152SJohan Hedberg 		return -EPROTO;
4363cb3b3152SJohan Hedberg 
43640a708f8fSGustavo F. Padovan 	type   = __le16_to_cpu(rsp->type);
43650a708f8fSGustavo F. Padovan 	result = __le16_to_cpu(rsp->result);
43660a708f8fSGustavo F. Padovan 
43670a708f8fSGustavo F. Padovan 	BT_DBG("type 0x%4.4x result 0x%2.2x", type, result);
43680a708f8fSGustavo F. Padovan 
4369e90165beSAndrei Emeltchenko 	/* L2CAP Info req/rsp are unbound to channels, add extra checks */
4370e90165beSAndrei Emeltchenko 	if (cmd->ident != conn->info_ident ||
4371e90165beSAndrei Emeltchenko 	    conn->info_state & L2CAP_INFO_FEAT_MASK_REQ_DONE)
4372e90165beSAndrei Emeltchenko 		return 0;
4373e90165beSAndrei Emeltchenko 
437417cd3f37SUlisses Furquim 	cancel_delayed_work(&conn->info_timer);
43750a708f8fSGustavo F. Padovan 
43760a708f8fSGustavo F. Padovan 	if (result != L2CAP_IR_SUCCESS) {
43770a708f8fSGustavo F. Padovan 		conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_DONE;
43780a708f8fSGustavo F. Padovan 		conn->info_ident = 0;
43790a708f8fSGustavo F. Padovan 
43800a708f8fSGustavo F. Padovan 		l2cap_conn_start(conn);
43810a708f8fSGustavo F. Padovan 
43820a708f8fSGustavo F. Padovan 		return 0;
43830a708f8fSGustavo F. Padovan 	}
43840a708f8fSGustavo F. Padovan 
4385978c93b9SAndrei Emeltchenko 	switch (type) {
4386978c93b9SAndrei Emeltchenko 	case L2CAP_IT_FEAT_MASK:
43870a708f8fSGustavo F. Padovan 		conn->feat_mask = get_unaligned_le32(rsp->data);
43880a708f8fSGustavo F. Padovan 
43890a708f8fSGustavo F. Padovan 		if (conn->feat_mask & L2CAP_FEAT_FIXED_CHAN) {
43900a708f8fSGustavo F. Padovan 			struct l2cap_info_req req;
4391dcf4adbfSJoe Perches 			req.type = cpu_to_le16(L2CAP_IT_FIXED_CHAN);
43920a708f8fSGustavo F. Padovan 
43930a708f8fSGustavo F. Padovan 			conn->info_ident = l2cap_get_ident(conn);
43940a708f8fSGustavo F. Padovan 
43950a708f8fSGustavo F. Padovan 			l2cap_send_cmd(conn, conn->info_ident,
43960a708f8fSGustavo F. Padovan 				       L2CAP_INFO_REQ, sizeof(req), &req);
43970a708f8fSGustavo F. Padovan 		} else {
43980a708f8fSGustavo F. Padovan 			conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_DONE;
43990a708f8fSGustavo F. Padovan 			conn->info_ident = 0;
44000a708f8fSGustavo F. Padovan 
44010a708f8fSGustavo F. Padovan 			l2cap_conn_start(conn);
44020a708f8fSGustavo F. Padovan 		}
4403978c93b9SAndrei Emeltchenko 		break;
4404978c93b9SAndrei Emeltchenko 
4405978c93b9SAndrei Emeltchenko 	case L2CAP_IT_FIXED_CHAN:
4406978c93b9SAndrei Emeltchenko 		conn->fixed_chan_mask = rsp->data[0];
44070a708f8fSGustavo F. Padovan 		conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_DONE;
44080a708f8fSGustavo F. Padovan 		conn->info_ident = 0;
44090a708f8fSGustavo F. Padovan 
44100a708f8fSGustavo F. Padovan 		l2cap_conn_start(conn);
4411978c93b9SAndrei Emeltchenko 		break;
44120a708f8fSGustavo F. Padovan 	}
44130a708f8fSGustavo F. Padovan 
44140a708f8fSGustavo F. Padovan 	return 0;
44150a708f8fSGustavo F. Padovan }
44160a708f8fSGustavo F. Padovan 
44171700915fSMat Martineau static int l2cap_create_channel_req(struct l2cap_conn *conn,
44182d792818SGustavo Padovan 				    struct l2cap_cmd_hdr *cmd,
44192d792818SGustavo Padovan 				    u16 cmd_len, void *data)
4420f94ff6ffSMat Martineau {
4421f94ff6ffSMat Martineau 	struct l2cap_create_chan_req *req = data;
44226e1df6a6SAndrei Emeltchenko 	struct l2cap_create_chan_rsp rsp;
44231700915fSMat Martineau 	struct l2cap_chan *chan;
44246e1df6a6SAndrei Emeltchenko 	struct hci_dev *hdev;
4425f94ff6ffSMat Martineau 	u16 psm, scid;
4426f94ff6ffSMat Martineau 
4427f94ff6ffSMat Martineau 	if (cmd_len != sizeof(*req))
4428f94ff6ffSMat Martineau 		return -EPROTO;
4429f94ff6ffSMat Martineau 
4430848566b3SMarcel Holtmann 	if (!conn->hs_enabled)
4431f94ff6ffSMat Martineau 		return -EINVAL;
4432f94ff6ffSMat Martineau 
4433f94ff6ffSMat Martineau 	psm = le16_to_cpu(req->psm);
4434f94ff6ffSMat Martineau 	scid = le16_to_cpu(req->scid);
4435f94ff6ffSMat Martineau 
4436ad0ac6caSAndrei Emeltchenko 	BT_DBG("psm 0x%2.2x, scid 0x%4.4x, amp_id %d", psm, scid, req->amp_id);
4437f94ff6ffSMat Martineau 
44386e1df6a6SAndrei Emeltchenko 	/* For controller id 0 make BR/EDR connection */
44396ed971caSMarcel Holtmann 	if (req->amp_id == AMP_ID_BREDR) {
44406e1df6a6SAndrei Emeltchenko 		l2cap_connect(conn, cmd, data, L2CAP_CREATE_CHAN_RSP,
44416e1df6a6SAndrei Emeltchenko 			      req->amp_id);
44426e1df6a6SAndrei Emeltchenko 		return 0;
44436e1df6a6SAndrei Emeltchenko 	}
44441700915fSMat Martineau 
44451700915fSMat Martineau 	/* Validate AMP controller id */
44461700915fSMat Martineau 	hdev = hci_dev_get(req->amp_id);
44476e1df6a6SAndrei Emeltchenko 	if (!hdev)
44486e1df6a6SAndrei Emeltchenko 		goto error;
44491700915fSMat Martineau 
44506e1df6a6SAndrei Emeltchenko 	if (hdev->dev_type != HCI_AMP || !test_bit(HCI_UP, &hdev->flags)) {
44516e1df6a6SAndrei Emeltchenko 		hci_dev_put(hdev);
44526e1df6a6SAndrei Emeltchenko 		goto error;
44536e1df6a6SAndrei Emeltchenko 	}
44546e1df6a6SAndrei Emeltchenko 
44556e1df6a6SAndrei Emeltchenko 	chan = l2cap_connect(conn, cmd, data, L2CAP_CREATE_CHAN_RSP,
44566e1df6a6SAndrei Emeltchenko 			     req->amp_id);
44576e1df6a6SAndrei Emeltchenko 	if (chan) {
44586e1df6a6SAndrei Emeltchenko 		struct amp_mgr *mgr = conn->hcon->amp_mgr;
44596e1df6a6SAndrei Emeltchenko 		struct hci_conn *hs_hcon;
44606e1df6a6SAndrei Emeltchenko 
446198e0f7eaSMarcel Holtmann 		hs_hcon = hci_conn_hash_lookup_ba(hdev, AMP_LINK,
446298e0f7eaSMarcel Holtmann 						  &conn->hcon->dst);
44636e1df6a6SAndrei Emeltchenko 		if (!hs_hcon) {
44646e1df6a6SAndrei Emeltchenko 			hci_dev_put(hdev);
4465662d652dSJohan Hedberg 			cmd_reject_invalid_cid(conn, cmd->ident, chan->scid,
4466662d652dSJohan Hedberg 					       chan->dcid);
4467662d652dSJohan Hedberg 			return 0;
44686e1df6a6SAndrei Emeltchenko 		}
44696e1df6a6SAndrei Emeltchenko 
44706e1df6a6SAndrei Emeltchenko 		BT_DBG("mgr %p bredr_chan %p hs_hcon %p", mgr, chan, hs_hcon);
44716e1df6a6SAndrei Emeltchenko 
44726e1df6a6SAndrei Emeltchenko 		mgr->bredr_chan = chan;
44736e1df6a6SAndrei Emeltchenko 		chan->hs_hcon = hs_hcon;
4474fd45bf4cSAndrei Emeltchenko 		chan->fcs = L2CAP_FCS_NONE;
44756e1df6a6SAndrei Emeltchenko 		conn->mtu = hdev->block_mtu;
44766e1df6a6SAndrei Emeltchenko 	}
44776e1df6a6SAndrei Emeltchenko 
44786e1df6a6SAndrei Emeltchenko 	hci_dev_put(hdev);
44796e1df6a6SAndrei Emeltchenko 
44806e1df6a6SAndrei Emeltchenko 	return 0;
44816e1df6a6SAndrei Emeltchenko 
44826e1df6a6SAndrei Emeltchenko error:
4483f94ff6ffSMat Martineau 	rsp.dcid = 0;
4484f94ff6ffSMat Martineau 	rsp.scid = cpu_to_le16(scid);
4485dcf4adbfSJoe Perches 	rsp.result = cpu_to_le16(L2CAP_CR_BAD_AMP);
4486dcf4adbfSJoe Perches 	rsp.status = cpu_to_le16(L2CAP_CS_NO_INFO);
4487f94ff6ffSMat Martineau 
4488f94ff6ffSMat Martineau 	l2cap_send_cmd(conn, cmd->ident, L2CAP_CREATE_CHAN_RSP,
4489f94ff6ffSMat Martineau 		       sizeof(rsp), &rsp);
4490f94ff6ffSMat Martineau 
4491dc280801SJohan Hedberg 	return 0;
4492f94ff6ffSMat Martineau }
4493f94ff6ffSMat Martineau 
44948eb200bdSMat Martineau static void l2cap_send_move_chan_req(struct l2cap_chan *chan, u8 dest_amp_id)
44958eb200bdSMat Martineau {
44968eb200bdSMat Martineau 	struct l2cap_move_chan_req req;
44978eb200bdSMat Martineau 	u8 ident;
44988eb200bdSMat Martineau 
44998eb200bdSMat Martineau 	BT_DBG("chan %p, dest_amp_id %d", chan, dest_amp_id);
45008eb200bdSMat Martineau 
45018eb200bdSMat Martineau 	ident = l2cap_get_ident(chan->conn);
45028eb200bdSMat Martineau 	chan->ident = ident;
45038eb200bdSMat Martineau 
45048eb200bdSMat Martineau 	req.icid = cpu_to_le16(chan->scid);
45058eb200bdSMat Martineau 	req.dest_amp_id = dest_amp_id;
45068eb200bdSMat Martineau 
45078eb200bdSMat Martineau 	l2cap_send_cmd(chan->conn, ident, L2CAP_MOVE_CHAN_REQ, sizeof(req),
45088eb200bdSMat Martineau 		       &req);
45098eb200bdSMat Martineau 
45108eb200bdSMat Martineau 	__set_chan_timer(chan, L2CAP_MOVE_TIMEOUT);
45118eb200bdSMat Martineau }
45128eb200bdSMat Martineau 
45131500109bSMat Martineau static void l2cap_send_move_chan_rsp(struct l2cap_chan *chan, u16 result)
45148d5a04a1SMat Martineau {
45158d5a04a1SMat Martineau 	struct l2cap_move_chan_rsp rsp;
45168d5a04a1SMat Martineau 
45171500109bSMat Martineau 	BT_DBG("chan %p, result 0x%4.4x", chan, result);
45188d5a04a1SMat Martineau 
45191500109bSMat Martineau 	rsp.icid = cpu_to_le16(chan->dcid);
45208d5a04a1SMat Martineau 	rsp.result = cpu_to_le16(result);
45218d5a04a1SMat Martineau 
45221500109bSMat Martineau 	l2cap_send_cmd(chan->conn, chan->ident, L2CAP_MOVE_CHAN_RSP,
45231500109bSMat Martineau 		       sizeof(rsp), &rsp);
45248d5a04a1SMat Martineau }
45258d5a04a1SMat Martineau 
45265b155ef9SMat Martineau static void l2cap_send_move_chan_cfm(struct l2cap_chan *chan, u16 result)
45278d5a04a1SMat Martineau {
45288d5a04a1SMat Martineau 	struct l2cap_move_chan_cfm cfm;
45298d5a04a1SMat Martineau 
45305b155ef9SMat Martineau 	BT_DBG("chan %p, result 0x%4.4x", chan, result);
45318d5a04a1SMat Martineau 
45325b155ef9SMat Martineau 	chan->ident = l2cap_get_ident(chan->conn);
45338d5a04a1SMat Martineau 
45345b155ef9SMat Martineau 	cfm.icid = cpu_to_le16(chan->scid);
45358d5a04a1SMat Martineau 	cfm.result = cpu_to_le16(result);
45368d5a04a1SMat Martineau 
45375b155ef9SMat Martineau 	l2cap_send_cmd(chan->conn, chan->ident, L2CAP_MOVE_CHAN_CFM,
45385b155ef9SMat Martineau 		       sizeof(cfm), &cfm);
45395b155ef9SMat Martineau 
45405b155ef9SMat Martineau 	__set_chan_timer(chan, L2CAP_MOVE_TIMEOUT);
45415b155ef9SMat Martineau }
45425b155ef9SMat Martineau 
45435b155ef9SMat Martineau static void l2cap_send_move_chan_cfm_icid(struct l2cap_conn *conn, u16 icid)
45445b155ef9SMat Martineau {
45455b155ef9SMat Martineau 	struct l2cap_move_chan_cfm cfm;
45465b155ef9SMat Martineau 
45475b155ef9SMat Martineau 	BT_DBG("conn %p, icid 0x%4.4x", conn, icid);
45485b155ef9SMat Martineau 
45495b155ef9SMat Martineau 	cfm.icid = cpu_to_le16(icid);
4550dcf4adbfSJoe Perches 	cfm.result = cpu_to_le16(L2CAP_MC_UNCONFIRMED);
45515b155ef9SMat Martineau 
45525b155ef9SMat Martineau 	l2cap_send_cmd(conn, l2cap_get_ident(conn), L2CAP_MOVE_CHAN_CFM,
45535b155ef9SMat Martineau 		       sizeof(cfm), &cfm);
45548d5a04a1SMat Martineau }
45558d5a04a1SMat Martineau 
45568d5a04a1SMat Martineau static void l2cap_send_move_chan_cfm_rsp(struct l2cap_conn *conn, u8 ident,
45578d5a04a1SMat Martineau 					 u16 icid)
45588d5a04a1SMat Martineau {
45598d5a04a1SMat Martineau 	struct l2cap_move_chan_cfm_rsp rsp;
45608d5a04a1SMat Martineau 
4561ad0ac6caSAndrei Emeltchenko 	BT_DBG("icid 0x%4.4x", icid);
45628d5a04a1SMat Martineau 
45638d5a04a1SMat Martineau 	rsp.icid = cpu_to_le16(icid);
45648d5a04a1SMat Martineau 	l2cap_send_cmd(conn, ident, L2CAP_MOVE_CHAN_CFM_RSP, sizeof(rsp), &rsp);
45658d5a04a1SMat Martineau }
45668d5a04a1SMat Martineau 
45675f3847a4SMat Martineau static void __release_logical_link(struct l2cap_chan *chan)
45685f3847a4SMat Martineau {
45695f3847a4SMat Martineau 	chan->hs_hchan = NULL;
45705f3847a4SMat Martineau 	chan->hs_hcon = NULL;
45715f3847a4SMat Martineau 
45725f3847a4SMat Martineau 	/* Placeholder - release the logical link */
45735f3847a4SMat Martineau }
45745f3847a4SMat Martineau 
45751500109bSMat Martineau static void l2cap_logical_fail(struct l2cap_chan *chan)
45761500109bSMat Martineau {
45771500109bSMat Martineau 	/* Logical link setup failed */
45781500109bSMat Martineau 	if (chan->state != BT_CONNECTED) {
45791500109bSMat Martineau 		/* Create channel failure, disconnect */
45805e4e3972SAndrei Emeltchenko 		l2cap_send_disconn_req(chan, ECONNRESET);
45811500109bSMat Martineau 		return;
45821500109bSMat Martineau 	}
45831500109bSMat Martineau 
45841500109bSMat Martineau 	switch (chan->move_role) {
45851500109bSMat Martineau 	case L2CAP_MOVE_ROLE_RESPONDER:
45861500109bSMat Martineau 		l2cap_move_done(chan);
45871500109bSMat Martineau 		l2cap_send_move_chan_rsp(chan, L2CAP_MR_NOT_SUPP);
45881500109bSMat Martineau 		break;
45891500109bSMat Martineau 	case L2CAP_MOVE_ROLE_INITIATOR:
45901500109bSMat Martineau 		if (chan->move_state == L2CAP_MOVE_WAIT_LOGICAL_COMP ||
45911500109bSMat Martineau 		    chan->move_state == L2CAP_MOVE_WAIT_LOGICAL_CFM) {
45921500109bSMat Martineau 			/* Remote has only sent pending or
45931500109bSMat Martineau 			 * success responses, clean up
45941500109bSMat Martineau 			 */
45951500109bSMat Martineau 			l2cap_move_done(chan);
45961500109bSMat Martineau 		}
45971500109bSMat Martineau 
45981500109bSMat Martineau 		/* Other amp move states imply that the move
45991500109bSMat Martineau 		 * has already aborted
46001500109bSMat Martineau 		 */
46011500109bSMat Martineau 		l2cap_send_move_chan_cfm(chan, L2CAP_MC_UNCONFIRMED);
46021500109bSMat Martineau 		break;
46031500109bSMat Martineau 	}
46041500109bSMat Martineau }
46051500109bSMat Martineau 
46061500109bSMat Martineau static void l2cap_logical_finish_create(struct l2cap_chan *chan,
46071500109bSMat Martineau 					struct hci_chan *hchan)
46081500109bSMat Martineau {
46091500109bSMat Martineau 	struct l2cap_conf_rsp rsp;
46101500109bSMat Martineau 
4611336178a3SAndrei Emeltchenko 	chan->hs_hchan = hchan;
46121500109bSMat Martineau 	chan->hs_hcon->l2cap_data = chan->conn;
46131500109bSMat Martineau 
461435ba9561SAndrei Emeltchenko 	l2cap_send_efs_conf_rsp(chan, &rsp, chan->ident, 0);
46151500109bSMat Martineau 
46161500109bSMat Martineau 	if (test_bit(CONF_INPUT_DONE, &chan->conf_state)) {
4617fe79c6feSAndrei Emeltchenko 		int err;
46181500109bSMat Martineau 
46191500109bSMat Martineau 		set_default_fcs(chan);
46201500109bSMat Martineau 
46211500109bSMat Martineau 		err = l2cap_ertm_init(chan);
46221500109bSMat Martineau 		if (err < 0)
46235e4e3972SAndrei Emeltchenko 			l2cap_send_disconn_req(chan, -err);
46241500109bSMat Martineau 		else
46251500109bSMat Martineau 			l2cap_chan_ready(chan);
46261500109bSMat Martineau 	}
46271500109bSMat Martineau }
46281500109bSMat Martineau 
46291500109bSMat Martineau static void l2cap_logical_finish_move(struct l2cap_chan *chan,
46301500109bSMat Martineau 				      struct hci_chan *hchan)
46311500109bSMat Martineau {
46321500109bSMat Martineau 	chan->hs_hcon = hchan->conn;
46331500109bSMat Martineau 	chan->hs_hcon->l2cap_data = chan->conn;
46341500109bSMat Martineau 
46351500109bSMat Martineau 	BT_DBG("move_state %d", chan->move_state);
46361500109bSMat Martineau 
46371500109bSMat Martineau 	switch (chan->move_state) {
46381500109bSMat Martineau 	case L2CAP_MOVE_WAIT_LOGICAL_COMP:
46391500109bSMat Martineau 		/* Move confirm will be sent after a success
46401500109bSMat Martineau 		 * response is received
46411500109bSMat Martineau 		 */
46421500109bSMat Martineau 		chan->move_state = L2CAP_MOVE_WAIT_RSP_SUCCESS;
46431500109bSMat Martineau 		break;
46441500109bSMat Martineau 	case L2CAP_MOVE_WAIT_LOGICAL_CFM:
46451500109bSMat Martineau 		if (test_bit(CONN_LOCAL_BUSY, &chan->conn_state)) {
46461500109bSMat Martineau 			chan->move_state = L2CAP_MOVE_WAIT_LOCAL_BUSY;
46471500109bSMat Martineau 		} else if (chan->move_role == L2CAP_MOVE_ROLE_INITIATOR) {
46481500109bSMat Martineau 			chan->move_state = L2CAP_MOVE_WAIT_CONFIRM_RSP;
46491500109bSMat Martineau 			l2cap_send_move_chan_cfm(chan, L2CAP_MC_CONFIRMED);
46501500109bSMat Martineau 		} else if (chan->move_role == L2CAP_MOVE_ROLE_RESPONDER) {
46511500109bSMat Martineau 			chan->move_state = L2CAP_MOVE_WAIT_CONFIRM;
46521500109bSMat Martineau 			l2cap_send_move_chan_rsp(chan, L2CAP_MR_SUCCESS);
46531500109bSMat Martineau 		}
46541500109bSMat Martineau 		break;
46551500109bSMat Martineau 	default:
46561500109bSMat Martineau 		/* Move was not in expected state, free the channel */
46571500109bSMat Martineau 		__release_logical_link(chan);
46581500109bSMat Martineau 
46591500109bSMat Martineau 		chan->move_state = L2CAP_MOVE_STABLE;
46601500109bSMat Martineau 	}
46611500109bSMat Martineau }
46621500109bSMat Martineau 
46631500109bSMat Martineau /* Call with chan locked */
466427695fb4SAndrei Emeltchenko void l2cap_logical_cfm(struct l2cap_chan *chan, struct hci_chan *hchan,
46655b155ef9SMat Martineau 		       u8 status)
46665b155ef9SMat Martineau {
46671500109bSMat Martineau 	BT_DBG("chan %p, hchan %p, status %d", chan, hchan, status);
46681500109bSMat Martineau 
46691500109bSMat Martineau 	if (status) {
46701500109bSMat Martineau 		l2cap_logical_fail(chan);
46711500109bSMat Martineau 		__release_logical_link(chan);
46725b155ef9SMat Martineau 		return;
46735b155ef9SMat Martineau 	}
46745b155ef9SMat Martineau 
46751500109bSMat Martineau 	if (chan->state != BT_CONNECTED) {
46761500109bSMat Martineau 		/* Ignore logical link if channel is on BR/EDR */
46776ed971caSMarcel Holtmann 		if (chan->local_amp_id != AMP_ID_BREDR)
46781500109bSMat Martineau 			l2cap_logical_finish_create(chan, hchan);
46791500109bSMat Martineau 	} else {
46801500109bSMat Martineau 		l2cap_logical_finish_move(chan, hchan);
46811500109bSMat Martineau 	}
46821500109bSMat Martineau }
46831500109bSMat Martineau 
46843f7a56c4SMat Martineau void l2cap_move_start(struct l2cap_chan *chan)
46853f7a56c4SMat Martineau {
46863f7a56c4SMat Martineau 	BT_DBG("chan %p", chan);
46873f7a56c4SMat Martineau 
46886ed971caSMarcel Holtmann 	if (chan->local_amp_id == AMP_ID_BREDR) {
46893f7a56c4SMat Martineau 		if (chan->chan_policy != BT_CHANNEL_POLICY_AMP_PREFERRED)
46903f7a56c4SMat Martineau 			return;
46913f7a56c4SMat Martineau 		chan->move_role = L2CAP_MOVE_ROLE_INITIATOR;
46923f7a56c4SMat Martineau 		chan->move_state = L2CAP_MOVE_WAIT_PREPARE;
46933f7a56c4SMat Martineau 		/* Placeholder - start physical link setup */
46943f7a56c4SMat Martineau 	} else {
46953f7a56c4SMat Martineau 		chan->move_role = L2CAP_MOVE_ROLE_INITIATOR;
46963f7a56c4SMat Martineau 		chan->move_state = L2CAP_MOVE_WAIT_RSP_SUCCESS;
46973f7a56c4SMat Martineau 		chan->move_id = 0;
46983f7a56c4SMat Martineau 		l2cap_move_setup(chan);
46993f7a56c4SMat Martineau 		l2cap_send_move_chan_req(chan, 0);
47003f7a56c4SMat Martineau 	}
47013f7a56c4SMat Martineau }
47023f7a56c4SMat Martineau 
47038eb200bdSMat Martineau static void l2cap_do_create(struct l2cap_chan *chan, int result,
47048eb200bdSMat Martineau 			    u8 local_amp_id, u8 remote_amp_id)
47058eb200bdSMat Martineau {
470662748ca1SAndrei Emeltchenko 	BT_DBG("chan %p state %s %u -> %u", chan, state_to_string(chan->state),
470762748ca1SAndrei Emeltchenko 	       local_amp_id, remote_amp_id);
470862748ca1SAndrei Emeltchenko 
470912d6cc60SAndrei Emeltchenko 	chan->fcs = L2CAP_FCS_NONE;
471012d6cc60SAndrei Emeltchenko 
471162748ca1SAndrei Emeltchenko 	/* Outgoing channel on AMP */
471262748ca1SAndrei Emeltchenko 	if (chan->state == BT_CONNECT) {
471362748ca1SAndrei Emeltchenko 		if (result == L2CAP_CR_SUCCESS) {
471462748ca1SAndrei Emeltchenko 			chan->local_amp_id = local_amp_id;
471562748ca1SAndrei Emeltchenko 			l2cap_send_create_chan_req(chan, remote_amp_id);
471662748ca1SAndrei Emeltchenko 		} else {
471762748ca1SAndrei Emeltchenko 			/* Revert to BR/EDR connect */
471862748ca1SAndrei Emeltchenko 			l2cap_send_conn_req(chan);
471962748ca1SAndrei Emeltchenko 		}
472062748ca1SAndrei Emeltchenko 
472162748ca1SAndrei Emeltchenko 		return;
472262748ca1SAndrei Emeltchenko 	}
472362748ca1SAndrei Emeltchenko 
472462748ca1SAndrei Emeltchenko 	/* Incoming channel on AMP */
472562748ca1SAndrei Emeltchenko 	if (__l2cap_no_conn_pending(chan)) {
47268eb200bdSMat Martineau 		struct l2cap_conn_rsp rsp;
47278eb200bdSMat Martineau 		char buf[128];
47288eb200bdSMat Martineau 		rsp.scid = cpu_to_le16(chan->dcid);
47298eb200bdSMat Martineau 		rsp.dcid = cpu_to_le16(chan->scid);
47308eb200bdSMat Martineau 
47318eb200bdSMat Martineau 		if (result == L2CAP_CR_SUCCESS) {
47328eb200bdSMat Martineau 			/* Send successful response */
4733dcf4adbfSJoe Perches 			rsp.result = cpu_to_le16(L2CAP_CR_SUCCESS);
4734dcf4adbfSJoe Perches 			rsp.status = cpu_to_le16(L2CAP_CS_NO_INFO);
47358eb200bdSMat Martineau 		} else {
47368eb200bdSMat Martineau 			/* Send negative response */
4737dcf4adbfSJoe Perches 			rsp.result = cpu_to_le16(L2CAP_CR_NO_MEM);
4738dcf4adbfSJoe Perches 			rsp.status = cpu_to_le16(L2CAP_CS_NO_INFO);
47398eb200bdSMat Martineau 		}
47408eb200bdSMat Martineau 
47418eb200bdSMat Martineau 		l2cap_send_cmd(chan->conn, chan->ident, L2CAP_CREATE_CHAN_RSP,
47428eb200bdSMat Martineau 			       sizeof(rsp), &rsp);
47438eb200bdSMat Martineau 
47448eb200bdSMat Martineau 		if (result == L2CAP_CR_SUCCESS) {
4745f93fa273SGustavo Padovan 			l2cap_state_change(chan, BT_CONFIG);
47468eb200bdSMat Martineau 			set_bit(CONF_REQ_SENT, &chan->conf_state);
47478eb200bdSMat Martineau 			l2cap_send_cmd(chan->conn, l2cap_get_ident(chan->conn),
47488eb200bdSMat Martineau 				       L2CAP_CONF_REQ,
47498eb200bdSMat Martineau 				       l2cap_build_conf_req(chan, buf), buf);
47508eb200bdSMat Martineau 			chan->num_conf_req++;
47518eb200bdSMat Martineau 		}
47528eb200bdSMat Martineau 	}
47538eb200bdSMat Martineau }
47548eb200bdSMat Martineau 
47558eb200bdSMat Martineau static void l2cap_do_move_initiate(struct l2cap_chan *chan, u8 local_amp_id,
47568eb200bdSMat Martineau 				   u8 remote_amp_id)
47578eb200bdSMat Martineau {
47588eb200bdSMat Martineau 	l2cap_move_setup(chan);
47598eb200bdSMat Martineau 	chan->move_id = local_amp_id;
47608eb200bdSMat Martineau 	chan->move_state = L2CAP_MOVE_WAIT_RSP;
47618eb200bdSMat Martineau 
47628eb200bdSMat Martineau 	l2cap_send_move_chan_req(chan, remote_amp_id);
47638eb200bdSMat Martineau }
47648eb200bdSMat Martineau 
47658eb200bdSMat Martineau static void l2cap_do_move_respond(struct l2cap_chan *chan, int result)
47668eb200bdSMat Martineau {
47678eb200bdSMat Martineau 	struct hci_chan *hchan = NULL;
47688eb200bdSMat Martineau 
47698eb200bdSMat Martineau 	/* Placeholder - get hci_chan for logical link */
47708eb200bdSMat Martineau 
47718eb200bdSMat Martineau 	if (hchan) {
47728eb200bdSMat Martineau 		if (hchan->state == BT_CONNECTED) {
47738eb200bdSMat Martineau 			/* Logical link is ready to go */
47748eb200bdSMat Martineau 			chan->hs_hcon = hchan->conn;
47758eb200bdSMat Martineau 			chan->hs_hcon->l2cap_data = chan->conn;
47768eb200bdSMat Martineau 			chan->move_state = L2CAP_MOVE_WAIT_CONFIRM;
47778eb200bdSMat Martineau 			l2cap_send_move_chan_rsp(chan, L2CAP_MR_SUCCESS);
47788eb200bdSMat Martineau 
47798eb200bdSMat Martineau 			l2cap_logical_cfm(chan, hchan, L2CAP_MR_SUCCESS);
47808eb200bdSMat Martineau 		} else {
47818eb200bdSMat Martineau 			/* Wait for logical link to be ready */
47828eb200bdSMat Martineau 			chan->move_state = L2CAP_MOVE_WAIT_LOGICAL_CFM;
47838eb200bdSMat Martineau 		}
47848eb200bdSMat Martineau 	} else {
47858eb200bdSMat Martineau 		/* Logical link not available */
47868eb200bdSMat Martineau 		l2cap_send_move_chan_rsp(chan, L2CAP_MR_NOT_ALLOWED);
47878eb200bdSMat Martineau 	}
47888eb200bdSMat Martineau }
47898eb200bdSMat Martineau 
47908eb200bdSMat Martineau static void l2cap_do_move_cancel(struct l2cap_chan *chan, int result)
47918eb200bdSMat Martineau {
47928eb200bdSMat Martineau 	if (chan->move_role == L2CAP_MOVE_ROLE_RESPONDER) {
47938eb200bdSMat Martineau 		u8 rsp_result;
47948eb200bdSMat Martineau 		if (result == -EINVAL)
47958eb200bdSMat Martineau 			rsp_result = L2CAP_MR_BAD_ID;
47968eb200bdSMat Martineau 		else
47978eb200bdSMat Martineau 			rsp_result = L2CAP_MR_NOT_ALLOWED;
47988eb200bdSMat Martineau 
47998eb200bdSMat Martineau 		l2cap_send_move_chan_rsp(chan, rsp_result);
48008eb200bdSMat Martineau 	}
48018eb200bdSMat Martineau 
48028eb200bdSMat Martineau 	chan->move_role = L2CAP_MOVE_ROLE_NONE;
48038eb200bdSMat Martineau 	chan->move_state = L2CAP_MOVE_STABLE;
48048eb200bdSMat Martineau 
48058eb200bdSMat Martineau 	/* Restart data transmission */
48068eb200bdSMat Martineau 	l2cap_ertm_send(chan);
48078eb200bdSMat Martineau }
48088eb200bdSMat Martineau 
4809a514b17fSAndrei Emeltchenko /* Invoke with locked chan */
4810a514b17fSAndrei Emeltchenko void __l2cap_physical_cfm(struct l2cap_chan *chan, int result)
48118eb200bdSMat Martineau {
4812770bfefaSAndrei Emeltchenko 	u8 local_amp_id = chan->local_amp_id;
4813fffadc08SAndrei Emeltchenko 	u8 remote_amp_id = chan->remote_amp_id;
4814770bfefaSAndrei Emeltchenko 
48158eb200bdSMat Martineau 	BT_DBG("chan %p, result %d, local_amp_id %d, remote_amp_id %d",
48168eb200bdSMat Martineau 	       chan, result, local_amp_id, remote_amp_id);
48178eb200bdSMat Martineau 
48188eb200bdSMat Martineau 	if (chan->state == BT_DISCONN || chan->state == BT_CLOSED) {
48198eb200bdSMat Martineau 		l2cap_chan_unlock(chan);
48208eb200bdSMat Martineau 		return;
48218eb200bdSMat Martineau 	}
48228eb200bdSMat Martineau 
48238eb200bdSMat Martineau 	if (chan->state != BT_CONNECTED) {
48248eb200bdSMat Martineau 		l2cap_do_create(chan, result, local_amp_id, remote_amp_id);
48258eb200bdSMat Martineau 	} else if (result != L2CAP_MR_SUCCESS) {
48268eb200bdSMat Martineau 		l2cap_do_move_cancel(chan, result);
48278eb200bdSMat Martineau 	} else {
48288eb200bdSMat Martineau 		switch (chan->move_role) {
48298eb200bdSMat Martineau 		case L2CAP_MOVE_ROLE_INITIATOR:
48308eb200bdSMat Martineau 			l2cap_do_move_initiate(chan, local_amp_id,
48318eb200bdSMat Martineau 					       remote_amp_id);
48328eb200bdSMat Martineau 			break;
48338eb200bdSMat Martineau 		case L2CAP_MOVE_ROLE_RESPONDER:
48348eb200bdSMat Martineau 			l2cap_do_move_respond(chan, result);
48358eb200bdSMat Martineau 			break;
48368eb200bdSMat Martineau 		default:
48378eb200bdSMat Martineau 			l2cap_do_move_cancel(chan, result);
48388eb200bdSMat Martineau 			break;
48398eb200bdSMat Martineau 		}
48408eb200bdSMat Martineau 	}
48418eb200bdSMat Martineau }
48428eb200bdSMat Martineau 
48438d5a04a1SMat Martineau static inline int l2cap_move_channel_req(struct l2cap_conn *conn,
4844ad0ac6caSAndrei Emeltchenko 					 struct l2cap_cmd_hdr *cmd,
4845ad0ac6caSAndrei Emeltchenko 					 u16 cmd_len, void *data)
48468d5a04a1SMat Martineau {
48478d5a04a1SMat Martineau 	struct l2cap_move_chan_req *req = data;
48481500109bSMat Martineau 	struct l2cap_move_chan_rsp rsp;
484902b0fbb9SMat Martineau 	struct l2cap_chan *chan;
48508d5a04a1SMat Martineau 	u16 icid = 0;
48518d5a04a1SMat Martineau 	u16 result = L2CAP_MR_NOT_ALLOWED;
48528d5a04a1SMat Martineau 
48538d5a04a1SMat Martineau 	if (cmd_len != sizeof(*req))
48548d5a04a1SMat Martineau 		return -EPROTO;
48558d5a04a1SMat Martineau 
48568d5a04a1SMat Martineau 	icid = le16_to_cpu(req->icid);
48578d5a04a1SMat Martineau 
4858ad0ac6caSAndrei Emeltchenko 	BT_DBG("icid 0x%4.4x, dest_amp_id %d", icid, req->dest_amp_id);
48598d5a04a1SMat Martineau 
4860848566b3SMarcel Holtmann 	if (!conn->hs_enabled)
48618d5a04a1SMat Martineau 		return -EINVAL;
48628d5a04a1SMat Martineau 
486302b0fbb9SMat Martineau 	chan = l2cap_get_chan_by_dcid(conn, icid);
486402b0fbb9SMat Martineau 	if (!chan) {
48651500109bSMat Martineau 		rsp.icid = cpu_to_le16(icid);
4866dcf4adbfSJoe Perches 		rsp.result = cpu_to_le16(L2CAP_MR_NOT_ALLOWED);
48671500109bSMat Martineau 		l2cap_send_cmd(conn, cmd->ident, L2CAP_MOVE_CHAN_RSP,
48681500109bSMat Martineau 			       sizeof(rsp), &rsp);
486902b0fbb9SMat Martineau 		return 0;
487002b0fbb9SMat Martineau 	}
487102b0fbb9SMat Martineau 
48721500109bSMat Martineau 	chan->ident = cmd->ident;
48731500109bSMat Martineau 
487402b0fbb9SMat Martineau 	if (chan->scid < L2CAP_CID_DYN_START ||
487502b0fbb9SMat Martineau 	    chan->chan_policy == BT_CHANNEL_POLICY_BREDR_ONLY ||
487602b0fbb9SMat Martineau 	    (chan->mode != L2CAP_MODE_ERTM &&
487702b0fbb9SMat Martineau 	     chan->mode != L2CAP_MODE_STREAMING)) {
487802b0fbb9SMat Martineau 		result = L2CAP_MR_NOT_ALLOWED;
487902b0fbb9SMat Martineau 		goto send_move_response;
488002b0fbb9SMat Martineau 	}
488102b0fbb9SMat Martineau 
488202b0fbb9SMat Martineau 	if (chan->local_amp_id == req->dest_amp_id) {
488302b0fbb9SMat Martineau 		result = L2CAP_MR_SAME_ID;
488402b0fbb9SMat Martineau 		goto send_move_response;
488502b0fbb9SMat Martineau 	}
488602b0fbb9SMat Martineau 
48876ed971caSMarcel Holtmann 	if (req->dest_amp_id != AMP_ID_BREDR) {
488802b0fbb9SMat Martineau 		struct hci_dev *hdev;
488902b0fbb9SMat Martineau 		hdev = hci_dev_get(req->dest_amp_id);
489002b0fbb9SMat Martineau 		if (!hdev || hdev->dev_type != HCI_AMP ||
489102b0fbb9SMat Martineau 		    !test_bit(HCI_UP, &hdev->flags)) {
489202b0fbb9SMat Martineau 			if (hdev)
489302b0fbb9SMat Martineau 				hci_dev_put(hdev);
489402b0fbb9SMat Martineau 
489502b0fbb9SMat Martineau 			result = L2CAP_MR_BAD_ID;
489602b0fbb9SMat Martineau 			goto send_move_response;
489702b0fbb9SMat Martineau 		}
489802b0fbb9SMat Martineau 		hci_dev_put(hdev);
489902b0fbb9SMat Martineau 	}
490002b0fbb9SMat Martineau 
490102b0fbb9SMat Martineau 	/* Detect a move collision.  Only send a collision response
490202b0fbb9SMat Martineau 	 * if this side has "lost", otherwise proceed with the move.
490302b0fbb9SMat Martineau 	 * The winner has the larger bd_addr.
490402b0fbb9SMat Martineau 	 */
490502b0fbb9SMat Martineau 	if ((__chan_is_moving(chan) ||
490602b0fbb9SMat Martineau 	     chan->move_role != L2CAP_MOVE_ROLE_NONE) &&
49076f59b904SMarcel Holtmann 	    bacmp(&conn->hcon->src, &conn->hcon->dst) > 0) {
490802b0fbb9SMat Martineau 		result = L2CAP_MR_COLLISION;
490902b0fbb9SMat Martineau 		goto send_move_response;
491002b0fbb9SMat Martineau 	}
491102b0fbb9SMat Martineau 
491202b0fbb9SMat Martineau 	chan->move_role = L2CAP_MOVE_ROLE_RESPONDER;
491302b0fbb9SMat Martineau 	l2cap_move_setup(chan);
491402b0fbb9SMat Martineau 	chan->move_id = req->dest_amp_id;
491502b0fbb9SMat Martineau 	icid = chan->dcid;
491602b0fbb9SMat Martineau 
49176ed971caSMarcel Holtmann 	if (req->dest_amp_id == AMP_ID_BREDR) {
491802b0fbb9SMat Martineau 		/* Moving to BR/EDR */
491902b0fbb9SMat Martineau 		if (test_bit(CONN_LOCAL_BUSY, &chan->conn_state)) {
492002b0fbb9SMat Martineau 			chan->move_state = L2CAP_MOVE_WAIT_LOCAL_BUSY;
492102b0fbb9SMat Martineau 			result = L2CAP_MR_PEND;
492202b0fbb9SMat Martineau 		} else {
492302b0fbb9SMat Martineau 			chan->move_state = L2CAP_MOVE_WAIT_CONFIRM;
492402b0fbb9SMat Martineau 			result = L2CAP_MR_SUCCESS;
492502b0fbb9SMat Martineau 		}
492602b0fbb9SMat Martineau 	} else {
492702b0fbb9SMat Martineau 		chan->move_state = L2CAP_MOVE_WAIT_PREPARE;
492802b0fbb9SMat Martineau 		/* Placeholder - uncomment when amp functions are available */
492902b0fbb9SMat Martineau 		/*amp_accept_physical(chan, req->dest_amp_id);*/
493002b0fbb9SMat Martineau 		result = L2CAP_MR_PEND;
493102b0fbb9SMat Martineau 	}
493202b0fbb9SMat Martineau 
493302b0fbb9SMat Martineau send_move_response:
49341500109bSMat Martineau 	l2cap_send_move_chan_rsp(chan, result);
49358d5a04a1SMat Martineau 
493602b0fbb9SMat Martineau 	l2cap_chan_unlock(chan);
493702b0fbb9SMat Martineau 
49388d5a04a1SMat Martineau 	return 0;
49398d5a04a1SMat Martineau }
49408d5a04a1SMat Martineau 
49415b155ef9SMat Martineau static void l2cap_move_continue(struct l2cap_conn *conn, u16 icid, u16 result)
49425b155ef9SMat Martineau {
49435b155ef9SMat Martineau 	struct l2cap_chan *chan;
49445b155ef9SMat Martineau 	struct hci_chan *hchan = NULL;
49455b155ef9SMat Martineau 
49465b155ef9SMat Martineau 	chan = l2cap_get_chan_by_scid(conn, icid);
49475b155ef9SMat Martineau 	if (!chan) {
49485b155ef9SMat Martineau 		l2cap_send_move_chan_cfm_icid(conn, icid);
49495b155ef9SMat Martineau 		return;
49505b155ef9SMat Martineau 	}
49515b155ef9SMat Martineau 
49525b155ef9SMat Martineau 	__clear_chan_timer(chan);
49535b155ef9SMat Martineau 	if (result == L2CAP_MR_PEND)
49545b155ef9SMat Martineau 		__set_chan_timer(chan, L2CAP_MOVE_ERTX_TIMEOUT);
49555b155ef9SMat Martineau 
49565b155ef9SMat Martineau 	switch (chan->move_state) {
49575b155ef9SMat Martineau 	case L2CAP_MOVE_WAIT_LOGICAL_COMP:
49585b155ef9SMat Martineau 		/* Move confirm will be sent when logical link
49595b155ef9SMat Martineau 		 * is complete.
49605b155ef9SMat Martineau 		 */
49615b155ef9SMat Martineau 		chan->move_state = L2CAP_MOVE_WAIT_LOGICAL_CFM;
49625b155ef9SMat Martineau 		break;
49635b155ef9SMat Martineau 	case L2CAP_MOVE_WAIT_RSP_SUCCESS:
49645b155ef9SMat Martineau 		if (result == L2CAP_MR_PEND) {
49655b155ef9SMat Martineau 			break;
49665b155ef9SMat Martineau 		} else if (test_bit(CONN_LOCAL_BUSY,
49675b155ef9SMat Martineau 				    &chan->conn_state)) {
49685b155ef9SMat Martineau 			chan->move_state = L2CAP_MOVE_WAIT_LOCAL_BUSY;
49695b155ef9SMat Martineau 		} else {
49705b155ef9SMat Martineau 			/* Logical link is up or moving to BR/EDR,
49715b155ef9SMat Martineau 			 * proceed with move
49725b155ef9SMat Martineau 			 */
49735b155ef9SMat Martineau 			chan->move_state = L2CAP_MOVE_WAIT_CONFIRM_RSP;
49745b155ef9SMat Martineau 			l2cap_send_move_chan_cfm(chan, L2CAP_MC_CONFIRMED);
49755b155ef9SMat Martineau 		}
49765b155ef9SMat Martineau 		break;
49775b155ef9SMat Martineau 	case L2CAP_MOVE_WAIT_RSP:
49785b155ef9SMat Martineau 		/* Moving to AMP */
49795b155ef9SMat Martineau 		if (result == L2CAP_MR_SUCCESS) {
49805b155ef9SMat Martineau 			/* Remote is ready, send confirm immediately
49815b155ef9SMat Martineau 			 * after logical link is ready
49825b155ef9SMat Martineau 			 */
49835b155ef9SMat Martineau 			chan->move_state = L2CAP_MOVE_WAIT_LOGICAL_CFM;
49845b155ef9SMat Martineau 		} else {
49855b155ef9SMat Martineau 			/* Both logical link and move success
49865b155ef9SMat Martineau 			 * are required to confirm
49875b155ef9SMat Martineau 			 */
49885b155ef9SMat Martineau 			chan->move_state = L2CAP_MOVE_WAIT_LOGICAL_COMP;
49895b155ef9SMat Martineau 		}
49905b155ef9SMat Martineau 
49915b155ef9SMat Martineau 		/* Placeholder - get hci_chan for logical link */
49925b155ef9SMat Martineau 		if (!hchan) {
49935b155ef9SMat Martineau 			/* Logical link not available */
49945b155ef9SMat Martineau 			l2cap_send_move_chan_cfm(chan, L2CAP_MC_UNCONFIRMED);
49955b155ef9SMat Martineau 			break;
49965b155ef9SMat Martineau 		}
49975b155ef9SMat Martineau 
49985b155ef9SMat Martineau 		/* If the logical link is not yet connected, do not
49995b155ef9SMat Martineau 		 * send confirmation.
50005b155ef9SMat Martineau 		 */
50015b155ef9SMat Martineau 		if (hchan->state != BT_CONNECTED)
50025b155ef9SMat Martineau 			break;
50035b155ef9SMat Martineau 
50045b155ef9SMat Martineau 		/* Logical link is already ready to go */
50055b155ef9SMat Martineau 
50065b155ef9SMat Martineau 		chan->hs_hcon = hchan->conn;
50075b155ef9SMat Martineau 		chan->hs_hcon->l2cap_data = chan->conn;
50085b155ef9SMat Martineau 
50095b155ef9SMat Martineau 		if (result == L2CAP_MR_SUCCESS) {
50105b155ef9SMat Martineau 			/* Can confirm now */
50115b155ef9SMat Martineau 			l2cap_send_move_chan_cfm(chan, L2CAP_MC_CONFIRMED);
50125b155ef9SMat Martineau 		} else {
50135b155ef9SMat Martineau 			/* Now only need move success
50145b155ef9SMat Martineau 			 * to confirm
50155b155ef9SMat Martineau 			 */
50165b155ef9SMat Martineau 			chan->move_state = L2CAP_MOVE_WAIT_RSP_SUCCESS;
50175b155ef9SMat Martineau 		}
50185b155ef9SMat Martineau 
50195b155ef9SMat Martineau 		l2cap_logical_cfm(chan, hchan, L2CAP_MR_SUCCESS);
50205b155ef9SMat Martineau 		break;
50215b155ef9SMat Martineau 	default:
50225b155ef9SMat Martineau 		/* Any other amp move state means the move failed. */
50235b155ef9SMat Martineau 		chan->move_id = chan->local_amp_id;
50245b155ef9SMat Martineau 		l2cap_move_done(chan);
50255b155ef9SMat Martineau 		l2cap_send_move_chan_cfm(chan, L2CAP_MC_UNCONFIRMED);
50265b155ef9SMat Martineau 	}
50275b155ef9SMat Martineau 
50285b155ef9SMat Martineau 	l2cap_chan_unlock(chan);
50295b155ef9SMat Martineau }
50305b155ef9SMat Martineau 
50315b155ef9SMat Martineau static void l2cap_move_fail(struct l2cap_conn *conn, u8 ident, u16 icid,
50325b155ef9SMat Martineau 			    u16 result)
50335b155ef9SMat Martineau {
50345b155ef9SMat Martineau 	struct l2cap_chan *chan;
50355b155ef9SMat Martineau 
50365b155ef9SMat Martineau 	chan = l2cap_get_chan_by_ident(conn, ident);
50375b155ef9SMat Martineau 	if (!chan) {
50385b155ef9SMat Martineau 		/* Could not locate channel, icid is best guess */
50395b155ef9SMat Martineau 		l2cap_send_move_chan_cfm_icid(conn, icid);
50405b155ef9SMat Martineau 		return;
50415b155ef9SMat Martineau 	}
50425b155ef9SMat Martineau 
50435b155ef9SMat Martineau 	__clear_chan_timer(chan);
50445b155ef9SMat Martineau 
50455b155ef9SMat Martineau 	if (chan->move_role == L2CAP_MOVE_ROLE_INITIATOR) {
50465b155ef9SMat Martineau 		if (result == L2CAP_MR_COLLISION) {
50475b155ef9SMat Martineau 			chan->move_role = L2CAP_MOVE_ROLE_RESPONDER;
50485b155ef9SMat Martineau 		} else {
50495b155ef9SMat Martineau 			/* Cleanup - cancel move */
50505b155ef9SMat Martineau 			chan->move_id = chan->local_amp_id;
50515b155ef9SMat Martineau 			l2cap_move_done(chan);
50525b155ef9SMat Martineau 		}
50535b155ef9SMat Martineau 	}
50545b155ef9SMat Martineau 
50555b155ef9SMat Martineau 	l2cap_send_move_chan_cfm(chan, L2CAP_MC_UNCONFIRMED);
50565b155ef9SMat Martineau 
50575b155ef9SMat Martineau 	l2cap_chan_unlock(chan);
50585b155ef9SMat Martineau }
50595b155ef9SMat Martineau 
50605b155ef9SMat Martineau static int l2cap_move_channel_rsp(struct l2cap_conn *conn,
5061ad0ac6caSAndrei Emeltchenko 				  struct l2cap_cmd_hdr *cmd,
5062ad0ac6caSAndrei Emeltchenko 				  u16 cmd_len, void *data)
50638d5a04a1SMat Martineau {
50648d5a04a1SMat Martineau 	struct l2cap_move_chan_rsp *rsp = data;
50658d5a04a1SMat Martineau 	u16 icid, result;
50668d5a04a1SMat Martineau 
50678d5a04a1SMat Martineau 	if (cmd_len != sizeof(*rsp))
50688d5a04a1SMat Martineau 		return -EPROTO;
50698d5a04a1SMat Martineau 
50708d5a04a1SMat Martineau 	icid = le16_to_cpu(rsp->icid);
50718d5a04a1SMat Martineau 	result = le16_to_cpu(rsp->result);
50728d5a04a1SMat Martineau 
5073ad0ac6caSAndrei Emeltchenko 	BT_DBG("icid 0x%4.4x, result 0x%4.4x", icid, result);
50748d5a04a1SMat Martineau 
50755b155ef9SMat Martineau 	if (result == L2CAP_MR_SUCCESS || result == L2CAP_MR_PEND)
50765b155ef9SMat Martineau 		l2cap_move_continue(conn, icid, result);
50775b155ef9SMat Martineau 	else
50785b155ef9SMat Martineau 		l2cap_move_fail(conn, cmd->ident, icid, result);
50798d5a04a1SMat Martineau 
50808d5a04a1SMat Martineau 	return 0;
50818d5a04a1SMat Martineau }
50828d5a04a1SMat Martineau 
50835f3847a4SMat Martineau static int l2cap_move_channel_confirm(struct l2cap_conn *conn,
5084ad0ac6caSAndrei Emeltchenko 				      struct l2cap_cmd_hdr *cmd,
5085ad0ac6caSAndrei Emeltchenko 				      u16 cmd_len, void *data)
50868d5a04a1SMat Martineau {
50878d5a04a1SMat Martineau 	struct l2cap_move_chan_cfm *cfm = data;
50885f3847a4SMat Martineau 	struct l2cap_chan *chan;
50898d5a04a1SMat Martineau 	u16 icid, result;
50908d5a04a1SMat Martineau 
50918d5a04a1SMat Martineau 	if (cmd_len != sizeof(*cfm))
50928d5a04a1SMat Martineau 		return -EPROTO;
50938d5a04a1SMat Martineau 
50948d5a04a1SMat Martineau 	icid = le16_to_cpu(cfm->icid);
50958d5a04a1SMat Martineau 	result = le16_to_cpu(cfm->result);
50968d5a04a1SMat Martineau 
5097ad0ac6caSAndrei Emeltchenko 	BT_DBG("icid 0x%4.4x, result 0x%4.4x", icid, result);
50988d5a04a1SMat Martineau 
50995f3847a4SMat Martineau 	chan = l2cap_get_chan_by_dcid(conn, icid);
51005f3847a4SMat Martineau 	if (!chan) {
51015f3847a4SMat Martineau 		/* Spec requires a response even if the icid was not found */
51028d5a04a1SMat Martineau 		l2cap_send_move_chan_cfm_rsp(conn, cmd->ident, icid);
51035f3847a4SMat Martineau 		return 0;
51045f3847a4SMat Martineau 	}
51055f3847a4SMat Martineau 
51065f3847a4SMat Martineau 	if (chan->move_state == L2CAP_MOVE_WAIT_CONFIRM) {
51075f3847a4SMat Martineau 		if (result == L2CAP_MC_CONFIRMED) {
51085f3847a4SMat Martineau 			chan->local_amp_id = chan->move_id;
51096ed971caSMarcel Holtmann 			if (chan->local_amp_id == AMP_ID_BREDR)
51105f3847a4SMat Martineau 				__release_logical_link(chan);
51115f3847a4SMat Martineau 		} else {
51125f3847a4SMat Martineau 			chan->move_id = chan->local_amp_id;
51135f3847a4SMat Martineau 		}
51145f3847a4SMat Martineau 
51155f3847a4SMat Martineau 		l2cap_move_done(chan);
51165f3847a4SMat Martineau 	}
51175f3847a4SMat Martineau 
51185f3847a4SMat Martineau 	l2cap_send_move_chan_cfm_rsp(conn, cmd->ident, icid);
51195f3847a4SMat Martineau 
51205f3847a4SMat Martineau 	l2cap_chan_unlock(chan);
51218d5a04a1SMat Martineau 
51228d5a04a1SMat Martineau 	return 0;
51238d5a04a1SMat Martineau }
51248d5a04a1SMat Martineau 
51258d5a04a1SMat Martineau static inline int l2cap_move_channel_confirm_rsp(struct l2cap_conn *conn,
5126ad0ac6caSAndrei Emeltchenko 						 struct l2cap_cmd_hdr *cmd,
5127ad0ac6caSAndrei Emeltchenko 						 u16 cmd_len, void *data)
51288d5a04a1SMat Martineau {
51298d5a04a1SMat Martineau 	struct l2cap_move_chan_cfm_rsp *rsp = data;
51303fd71a0aSMat Martineau 	struct l2cap_chan *chan;
51318d5a04a1SMat Martineau 	u16 icid;
51328d5a04a1SMat Martineau 
51338d5a04a1SMat Martineau 	if (cmd_len != sizeof(*rsp))
51348d5a04a1SMat Martineau 		return -EPROTO;
51358d5a04a1SMat Martineau 
51368d5a04a1SMat Martineau 	icid = le16_to_cpu(rsp->icid);
51378d5a04a1SMat Martineau 
5138ad0ac6caSAndrei Emeltchenko 	BT_DBG("icid 0x%4.4x", icid);
51398d5a04a1SMat Martineau 
51403fd71a0aSMat Martineau 	chan = l2cap_get_chan_by_scid(conn, icid);
51413fd71a0aSMat Martineau 	if (!chan)
51423fd71a0aSMat Martineau 		return 0;
51433fd71a0aSMat Martineau 
51443fd71a0aSMat Martineau 	__clear_chan_timer(chan);
51453fd71a0aSMat Martineau 
51463fd71a0aSMat Martineau 	if (chan->move_state == L2CAP_MOVE_WAIT_CONFIRM_RSP) {
51473fd71a0aSMat Martineau 		chan->local_amp_id = chan->move_id;
51483fd71a0aSMat Martineau 
51496ed971caSMarcel Holtmann 		if (chan->local_amp_id == AMP_ID_BREDR && chan->hs_hchan)
51503fd71a0aSMat Martineau 			__release_logical_link(chan);
51513fd71a0aSMat Martineau 
51523fd71a0aSMat Martineau 		l2cap_move_done(chan);
51533fd71a0aSMat Martineau 	}
51543fd71a0aSMat Martineau 
51553fd71a0aSMat Martineau 	l2cap_chan_unlock(chan);
51563fd71a0aSMat Martineau 
51578d5a04a1SMat Martineau 	return 0;
51588d5a04a1SMat Martineau }
51598d5a04a1SMat Martineau 
5160de73115aSClaudio Takahasi static inline int l2cap_conn_param_update_req(struct l2cap_conn *conn,
51612d792818SGustavo Padovan 					      struct l2cap_cmd_hdr *cmd,
5162203e639eSJohan Hedberg 					      u16 cmd_len, u8 *data)
5163de73115aSClaudio Takahasi {
5164de73115aSClaudio Takahasi 	struct hci_conn *hcon = conn->hcon;
5165de73115aSClaudio Takahasi 	struct l2cap_conn_param_update_req *req;
5166de73115aSClaudio Takahasi 	struct l2cap_conn_param_update_rsp rsp;
5167203e639eSJohan Hedberg 	u16 min, max, latency, to_multiplier;
51682ce603ebSClaudio Takahasi 	int err;
5169de73115aSClaudio Takahasi 
517040bef302SJohan Hedberg 	if (hcon->role != HCI_ROLE_MASTER)
5171de73115aSClaudio Takahasi 		return -EINVAL;
5172de73115aSClaudio Takahasi 
5173de73115aSClaudio Takahasi 	if (cmd_len != sizeof(struct l2cap_conn_param_update_req))
5174de73115aSClaudio Takahasi 		return -EPROTO;
5175de73115aSClaudio Takahasi 
5176de73115aSClaudio Takahasi 	req = (struct l2cap_conn_param_update_req *) data;
5177de73115aSClaudio Takahasi 	min		= __le16_to_cpu(req->min);
5178de73115aSClaudio Takahasi 	max		= __le16_to_cpu(req->max);
5179de73115aSClaudio Takahasi 	latency		= __le16_to_cpu(req->latency);
5180de73115aSClaudio Takahasi 	to_multiplier	= __le16_to_cpu(req->to_multiplier);
5181de73115aSClaudio Takahasi 
5182de73115aSClaudio Takahasi 	BT_DBG("min 0x%4.4x max 0x%4.4x latency: 0x%4.4x Timeout: 0x%4.4x",
5183de73115aSClaudio Takahasi 	       min, max, latency, to_multiplier);
5184de73115aSClaudio Takahasi 
5185de73115aSClaudio Takahasi 	memset(&rsp, 0, sizeof(rsp));
51862ce603ebSClaudio Takahasi 
5187d4905f24SAndre Guedes 	err = hci_check_conn_params(min, max, latency, to_multiplier);
51882ce603ebSClaudio Takahasi 	if (err)
5189dcf4adbfSJoe Perches 		rsp.result = cpu_to_le16(L2CAP_CONN_PARAM_REJECTED);
5190de73115aSClaudio Takahasi 	else
5191dcf4adbfSJoe Perches 		rsp.result = cpu_to_le16(L2CAP_CONN_PARAM_ACCEPTED);
5192de73115aSClaudio Takahasi 
5193de73115aSClaudio Takahasi 	l2cap_send_cmd(conn, cmd->ident, L2CAP_CONN_PARAM_UPDATE_RSP,
5194de73115aSClaudio Takahasi 		       sizeof(rsp), &rsp);
5195de73115aSClaudio Takahasi 
5196ffb5a827SAndre Guedes 	if (!err) {
5197f4869e2aSJohan Hedberg 		u8 store_hint;
5198ffb5a827SAndre Guedes 
5199f4869e2aSJohan Hedberg 		store_hint = hci_le_conn_update(hcon, min, max, latency,
5200f4869e2aSJohan Hedberg 						to_multiplier);
5201f4869e2aSJohan Hedberg 		mgmt_new_conn_param(hcon->hdev, &hcon->dst, hcon->dst_type,
5202f4869e2aSJohan Hedberg 				    store_hint, min, max, latency,
5203f4869e2aSJohan Hedberg 				    to_multiplier);
5204f4869e2aSJohan Hedberg 
5205ffb5a827SAndre Guedes 	}
52062ce603ebSClaudio Takahasi 
5207de73115aSClaudio Takahasi 	return 0;
5208de73115aSClaudio Takahasi }
5209de73115aSClaudio Takahasi 
5210f1496deeSJohan Hedberg static int l2cap_le_connect_rsp(struct l2cap_conn *conn,
5211f1496deeSJohan Hedberg 				struct l2cap_cmd_hdr *cmd, u16 cmd_len,
5212f1496deeSJohan Hedberg 				u8 *data)
5213f1496deeSJohan Hedberg {
5214f1496deeSJohan Hedberg 	struct l2cap_le_conn_rsp *rsp = (struct l2cap_le_conn_rsp *) data;
5215f1496deeSJohan Hedberg 	u16 dcid, mtu, mps, credits, result;
5216f1496deeSJohan Hedberg 	struct l2cap_chan *chan;
5217f1496deeSJohan Hedberg 	int err;
5218f1496deeSJohan Hedberg 
5219f1496deeSJohan Hedberg 	if (cmd_len < sizeof(*rsp))
5220f1496deeSJohan Hedberg 		return -EPROTO;
5221f1496deeSJohan Hedberg 
5222f1496deeSJohan Hedberg 	dcid    = __le16_to_cpu(rsp->dcid);
5223f1496deeSJohan Hedberg 	mtu     = __le16_to_cpu(rsp->mtu);
5224f1496deeSJohan Hedberg 	mps     = __le16_to_cpu(rsp->mps);
5225f1496deeSJohan Hedberg 	credits = __le16_to_cpu(rsp->credits);
5226f1496deeSJohan Hedberg 	result  = __le16_to_cpu(rsp->result);
5227f1496deeSJohan Hedberg 
5228f1496deeSJohan Hedberg 	if (result == L2CAP_CR_SUCCESS && (mtu < 23 || mps < 23))
5229f1496deeSJohan Hedberg 		return -EPROTO;
5230f1496deeSJohan Hedberg 
5231f1496deeSJohan Hedberg 	BT_DBG("dcid 0x%4.4x mtu %u mps %u credits %u result 0x%2.2x",
5232f1496deeSJohan Hedberg 	       dcid, mtu, mps, credits, result);
5233f1496deeSJohan Hedberg 
5234f1496deeSJohan Hedberg 	mutex_lock(&conn->chan_lock);
5235f1496deeSJohan Hedberg 
5236f1496deeSJohan Hedberg 	chan = __l2cap_get_chan_by_ident(conn, cmd->ident);
5237f1496deeSJohan Hedberg 	if (!chan) {
5238f1496deeSJohan Hedberg 		err = -EBADSLT;
5239f1496deeSJohan Hedberg 		goto unlock;
5240f1496deeSJohan Hedberg 	}
5241f1496deeSJohan Hedberg 
5242f1496deeSJohan Hedberg 	err = 0;
5243f1496deeSJohan Hedberg 
5244f1496deeSJohan Hedberg 	l2cap_chan_lock(chan);
5245f1496deeSJohan Hedberg 
5246f1496deeSJohan Hedberg 	switch (result) {
5247f1496deeSJohan Hedberg 	case L2CAP_CR_SUCCESS:
5248f1496deeSJohan Hedberg 		chan->ident = 0;
5249f1496deeSJohan Hedberg 		chan->dcid = dcid;
5250f1496deeSJohan Hedberg 		chan->omtu = mtu;
5251f1496deeSJohan Hedberg 		chan->remote_mps = mps;
52520cd75f7eSJohan Hedberg 		chan->tx_credits = credits;
5253f1496deeSJohan Hedberg 		l2cap_chan_ready(chan);
5254f1496deeSJohan Hedberg 		break;
5255f1496deeSJohan Hedberg 
5256f1496deeSJohan Hedberg 	default:
5257f1496deeSJohan Hedberg 		l2cap_chan_del(chan, ECONNREFUSED);
5258f1496deeSJohan Hedberg 		break;
5259f1496deeSJohan Hedberg 	}
5260f1496deeSJohan Hedberg 
5261f1496deeSJohan Hedberg 	l2cap_chan_unlock(chan);
5262f1496deeSJohan Hedberg 
5263f1496deeSJohan Hedberg unlock:
5264f1496deeSJohan Hedberg 	mutex_unlock(&conn->chan_lock);
5265f1496deeSJohan Hedberg 
5266f1496deeSJohan Hedberg 	return err;
5267f1496deeSJohan Hedberg }
5268f1496deeSJohan Hedberg 
52693300d9a9SClaudio Takahasi static inline int l2cap_bredr_sig_cmd(struct l2cap_conn *conn,
52702d792818SGustavo Padovan 				      struct l2cap_cmd_hdr *cmd, u16 cmd_len,
52712d792818SGustavo Padovan 				      u8 *data)
52723300d9a9SClaudio Takahasi {
52733300d9a9SClaudio Takahasi 	int err = 0;
52743300d9a9SClaudio Takahasi 
52753300d9a9SClaudio Takahasi 	switch (cmd->code) {
52763300d9a9SClaudio Takahasi 	case L2CAP_COMMAND_REJ:
5277cb3b3152SJohan Hedberg 		l2cap_command_rej(conn, cmd, cmd_len, data);
52783300d9a9SClaudio Takahasi 		break;
52793300d9a9SClaudio Takahasi 
52803300d9a9SClaudio Takahasi 	case L2CAP_CONN_REQ:
5281cb3b3152SJohan Hedberg 		err = l2cap_connect_req(conn, cmd, cmd_len, data);
52823300d9a9SClaudio Takahasi 		break;
52833300d9a9SClaudio Takahasi 
52843300d9a9SClaudio Takahasi 	case L2CAP_CONN_RSP:
5285f5a2598dSMat Martineau 	case L2CAP_CREATE_CHAN_RSP:
52869245e737SJohan Hedberg 		l2cap_connect_create_rsp(conn, cmd, cmd_len, data);
52873300d9a9SClaudio Takahasi 		break;
52883300d9a9SClaudio Takahasi 
52893300d9a9SClaudio Takahasi 	case L2CAP_CONF_REQ:
52903300d9a9SClaudio Takahasi 		err = l2cap_config_req(conn, cmd, cmd_len, data);
52913300d9a9SClaudio Takahasi 		break;
52923300d9a9SClaudio Takahasi 
52933300d9a9SClaudio Takahasi 	case L2CAP_CONF_RSP:
52949245e737SJohan Hedberg 		l2cap_config_rsp(conn, cmd, cmd_len, data);
52953300d9a9SClaudio Takahasi 		break;
52963300d9a9SClaudio Takahasi 
52973300d9a9SClaudio Takahasi 	case L2CAP_DISCONN_REQ:
5298cb3b3152SJohan Hedberg 		err = l2cap_disconnect_req(conn, cmd, cmd_len, data);
52993300d9a9SClaudio Takahasi 		break;
53003300d9a9SClaudio Takahasi 
53013300d9a9SClaudio Takahasi 	case L2CAP_DISCONN_RSP:
53029245e737SJohan Hedberg 		l2cap_disconnect_rsp(conn, cmd, cmd_len, data);
53033300d9a9SClaudio Takahasi 		break;
53043300d9a9SClaudio Takahasi 
53053300d9a9SClaudio Takahasi 	case L2CAP_ECHO_REQ:
53063300d9a9SClaudio Takahasi 		l2cap_send_cmd(conn, cmd->ident, L2CAP_ECHO_RSP, cmd_len, data);
53073300d9a9SClaudio Takahasi 		break;
53083300d9a9SClaudio Takahasi 
53093300d9a9SClaudio Takahasi 	case L2CAP_ECHO_RSP:
53103300d9a9SClaudio Takahasi 		break;
53113300d9a9SClaudio Takahasi 
53123300d9a9SClaudio Takahasi 	case L2CAP_INFO_REQ:
5313cb3b3152SJohan Hedberg 		err = l2cap_information_req(conn, cmd, cmd_len, data);
53143300d9a9SClaudio Takahasi 		break;
53153300d9a9SClaudio Takahasi 
53163300d9a9SClaudio Takahasi 	case L2CAP_INFO_RSP:
53179245e737SJohan Hedberg 		l2cap_information_rsp(conn, cmd, cmd_len, data);
53183300d9a9SClaudio Takahasi 		break;
53193300d9a9SClaudio Takahasi 
5320f94ff6ffSMat Martineau 	case L2CAP_CREATE_CHAN_REQ:
5321f94ff6ffSMat Martineau 		err = l2cap_create_channel_req(conn, cmd, cmd_len, data);
5322f94ff6ffSMat Martineau 		break;
5323f94ff6ffSMat Martineau 
53248d5a04a1SMat Martineau 	case L2CAP_MOVE_CHAN_REQ:
53258d5a04a1SMat Martineau 		err = l2cap_move_channel_req(conn, cmd, cmd_len, data);
53268d5a04a1SMat Martineau 		break;
53278d5a04a1SMat Martineau 
53288d5a04a1SMat Martineau 	case L2CAP_MOVE_CHAN_RSP:
53299245e737SJohan Hedberg 		l2cap_move_channel_rsp(conn, cmd, cmd_len, data);
53308d5a04a1SMat Martineau 		break;
53318d5a04a1SMat Martineau 
53328d5a04a1SMat Martineau 	case L2CAP_MOVE_CHAN_CFM:
53338d5a04a1SMat Martineau 		err = l2cap_move_channel_confirm(conn, cmd, cmd_len, data);
53348d5a04a1SMat Martineau 		break;
53358d5a04a1SMat Martineau 
53368d5a04a1SMat Martineau 	case L2CAP_MOVE_CHAN_CFM_RSP:
53379245e737SJohan Hedberg 		l2cap_move_channel_confirm_rsp(conn, cmd, cmd_len, data);
53388d5a04a1SMat Martineau 		break;
53398d5a04a1SMat Martineau 
53403300d9a9SClaudio Takahasi 	default:
53413300d9a9SClaudio Takahasi 		BT_ERR("Unknown BR/EDR signaling command 0x%2.2x", cmd->code);
53423300d9a9SClaudio Takahasi 		err = -EINVAL;
53433300d9a9SClaudio Takahasi 		break;
53443300d9a9SClaudio Takahasi 	}
53453300d9a9SClaudio Takahasi 
53463300d9a9SClaudio Takahasi 	return err;
53473300d9a9SClaudio Takahasi }
53483300d9a9SClaudio Takahasi 
534927e2d4c8SJohan Hedberg static int l2cap_le_connect_req(struct l2cap_conn *conn,
535027e2d4c8SJohan Hedberg 				struct l2cap_cmd_hdr *cmd, u16 cmd_len,
535127e2d4c8SJohan Hedberg 				u8 *data)
535227e2d4c8SJohan Hedberg {
535327e2d4c8SJohan Hedberg 	struct l2cap_le_conn_req *req = (struct l2cap_le_conn_req *) data;
535427e2d4c8SJohan Hedberg 	struct l2cap_le_conn_rsp rsp;
535527e2d4c8SJohan Hedberg 	struct l2cap_chan *chan, *pchan;
53560cd75f7eSJohan Hedberg 	u16 dcid, scid, credits, mtu, mps;
535727e2d4c8SJohan Hedberg 	__le16 psm;
535827e2d4c8SJohan Hedberg 	u8 result;
535927e2d4c8SJohan Hedberg 
536027e2d4c8SJohan Hedberg 	if (cmd_len != sizeof(*req))
536127e2d4c8SJohan Hedberg 		return -EPROTO;
536227e2d4c8SJohan Hedberg 
536327e2d4c8SJohan Hedberg 	scid = __le16_to_cpu(req->scid);
536427e2d4c8SJohan Hedberg 	mtu  = __le16_to_cpu(req->mtu);
536527e2d4c8SJohan Hedberg 	mps  = __le16_to_cpu(req->mps);
536627e2d4c8SJohan Hedberg 	psm  = req->psm;
536727e2d4c8SJohan Hedberg 	dcid = 0;
53680cd75f7eSJohan Hedberg 	credits = 0;
536927e2d4c8SJohan Hedberg 
537027e2d4c8SJohan Hedberg 	if (mtu < 23 || mps < 23)
537127e2d4c8SJohan Hedberg 		return -EPROTO;
537227e2d4c8SJohan Hedberg 
537327e2d4c8SJohan Hedberg 	BT_DBG("psm 0x%2.2x scid 0x%4.4x mtu %u mps %u", __le16_to_cpu(psm),
537427e2d4c8SJohan Hedberg 	       scid, mtu, mps);
537527e2d4c8SJohan Hedberg 
537627e2d4c8SJohan Hedberg 	/* Check if we have socket listening on psm */
537727e2d4c8SJohan Hedberg 	pchan = l2cap_global_chan_by_psm(BT_LISTEN, psm, &conn->hcon->src,
537827e2d4c8SJohan Hedberg 					 &conn->hcon->dst, LE_LINK);
537927e2d4c8SJohan Hedberg 	if (!pchan) {
538027e2d4c8SJohan Hedberg 		result = L2CAP_CR_BAD_PSM;
538127e2d4c8SJohan Hedberg 		chan = NULL;
538227e2d4c8SJohan Hedberg 		goto response;
538327e2d4c8SJohan Hedberg 	}
538427e2d4c8SJohan Hedberg 
538527e2d4c8SJohan Hedberg 	mutex_lock(&conn->chan_lock);
538627e2d4c8SJohan Hedberg 	l2cap_chan_lock(pchan);
538727e2d4c8SJohan Hedberg 
538827e2d4c8SJohan Hedberg 	if (!smp_sufficient_security(conn->hcon, pchan->sec_level)) {
538927e2d4c8SJohan Hedberg 		result = L2CAP_CR_AUTHENTICATION;
539027e2d4c8SJohan Hedberg 		chan = NULL;
539127e2d4c8SJohan Hedberg 		goto response_unlock;
539227e2d4c8SJohan Hedberg 	}
539327e2d4c8SJohan Hedberg 
539427e2d4c8SJohan Hedberg 	/* Check if we already have channel with that dcid */
539527e2d4c8SJohan Hedberg 	if (__l2cap_get_chan_by_dcid(conn, scid)) {
539627e2d4c8SJohan Hedberg 		result = L2CAP_CR_NO_MEM;
539727e2d4c8SJohan Hedberg 		chan = NULL;
539827e2d4c8SJohan Hedberg 		goto response_unlock;
539927e2d4c8SJohan Hedberg 	}
540027e2d4c8SJohan Hedberg 
540127e2d4c8SJohan Hedberg 	chan = pchan->ops->new_connection(pchan);
540227e2d4c8SJohan Hedberg 	if (!chan) {
540327e2d4c8SJohan Hedberg 		result = L2CAP_CR_NO_MEM;
540427e2d4c8SJohan Hedberg 		goto response_unlock;
540527e2d4c8SJohan Hedberg 	}
540627e2d4c8SJohan Hedberg 
54070ce43ce6SJohan Hedberg 	l2cap_le_flowctl_init(chan);
54080ce43ce6SJohan Hedberg 
540927e2d4c8SJohan Hedberg 	bacpy(&chan->src, &conn->hcon->src);
541027e2d4c8SJohan Hedberg 	bacpy(&chan->dst, &conn->hcon->dst);
541127e2d4c8SJohan Hedberg 	chan->src_type = bdaddr_type(conn->hcon, conn->hcon->src_type);
541227e2d4c8SJohan Hedberg 	chan->dst_type = bdaddr_type(conn->hcon, conn->hcon->dst_type);
541327e2d4c8SJohan Hedberg 	chan->psm  = psm;
541427e2d4c8SJohan Hedberg 	chan->dcid = scid;
541527e2d4c8SJohan Hedberg 	chan->omtu = mtu;
541627e2d4c8SJohan Hedberg 	chan->remote_mps = mps;
54170cd75f7eSJohan Hedberg 	chan->tx_credits = __le16_to_cpu(req->credits);
541827e2d4c8SJohan Hedberg 
541927e2d4c8SJohan Hedberg 	__l2cap_chan_add(conn, chan);
542027e2d4c8SJohan Hedberg 	dcid = chan->scid;
54210cd75f7eSJohan Hedberg 	credits = chan->rx_credits;
542227e2d4c8SJohan Hedberg 
542327e2d4c8SJohan Hedberg 	__set_chan_timer(chan, chan->ops->get_sndtimeo(chan));
542427e2d4c8SJohan Hedberg 
542527e2d4c8SJohan Hedberg 	chan->ident = cmd->ident;
542627e2d4c8SJohan Hedberg 
542727e2d4c8SJohan Hedberg 	if (test_bit(FLAG_DEFER_SETUP, &chan->flags)) {
542827e2d4c8SJohan Hedberg 		l2cap_state_change(chan, BT_CONNECT2);
542927e2d4c8SJohan Hedberg 		result = L2CAP_CR_PEND;
543027e2d4c8SJohan Hedberg 		chan->ops->defer(chan);
543127e2d4c8SJohan Hedberg 	} else {
543227e2d4c8SJohan Hedberg 		l2cap_chan_ready(chan);
543327e2d4c8SJohan Hedberg 		result = L2CAP_CR_SUCCESS;
543427e2d4c8SJohan Hedberg 	}
543527e2d4c8SJohan Hedberg 
543627e2d4c8SJohan Hedberg response_unlock:
543727e2d4c8SJohan Hedberg 	l2cap_chan_unlock(pchan);
543827e2d4c8SJohan Hedberg 	mutex_unlock(&conn->chan_lock);
5439a24cce14SJohan Hedberg 	l2cap_chan_put(pchan);
544027e2d4c8SJohan Hedberg 
544127e2d4c8SJohan Hedberg 	if (result == L2CAP_CR_PEND)
544227e2d4c8SJohan Hedberg 		return 0;
544327e2d4c8SJohan Hedberg 
544427e2d4c8SJohan Hedberg response:
544527e2d4c8SJohan Hedberg 	if (chan) {
544627e2d4c8SJohan Hedberg 		rsp.mtu = cpu_to_le16(chan->imtu);
54473916aed8SJohan Hedberg 		rsp.mps = cpu_to_le16(chan->mps);
544827e2d4c8SJohan Hedberg 	} else {
544927e2d4c8SJohan Hedberg 		rsp.mtu = 0;
545027e2d4c8SJohan Hedberg 		rsp.mps = 0;
545127e2d4c8SJohan Hedberg 	}
545227e2d4c8SJohan Hedberg 
545327e2d4c8SJohan Hedberg 	rsp.dcid    = cpu_to_le16(dcid);
54540cd75f7eSJohan Hedberg 	rsp.credits = cpu_to_le16(credits);
545527e2d4c8SJohan Hedberg 	rsp.result  = cpu_to_le16(result);
545627e2d4c8SJohan Hedberg 
545727e2d4c8SJohan Hedberg 	l2cap_send_cmd(conn, cmd->ident, L2CAP_LE_CONN_RSP, sizeof(rsp), &rsp);
545827e2d4c8SJohan Hedberg 
545927e2d4c8SJohan Hedberg 	return 0;
546027e2d4c8SJohan Hedberg }
546127e2d4c8SJohan Hedberg 
5462fad5fc89SJohan Hedberg static inline int l2cap_le_credits(struct l2cap_conn *conn,
5463fad5fc89SJohan Hedberg 				   struct l2cap_cmd_hdr *cmd, u16 cmd_len,
5464fad5fc89SJohan Hedberg 				   u8 *data)
5465fad5fc89SJohan Hedberg {
5466fad5fc89SJohan Hedberg 	struct l2cap_le_credits *pkt;
5467fad5fc89SJohan Hedberg 	struct l2cap_chan *chan;
54680f1bfe4eSJohan Hedberg 	u16 cid, credits, max_credits;
5469fad5fc89SJohan Hedberg 
5470fad5fc89SJohan Hedberg 	if (cmd_len != sizeof(*pkt))
5471fad5fc89SJohan Hedberg 		return -EPROTO;
5472fad5fc89SJohan Hedberg 
5473fad5fc89SJohan Hedberg 	pkt = (struct l2cap_le_credits *) data;
5474fad5fc89SJohan Hedberg 	cid	= __le16_to_cpu(pkt->cid);
5475fad5fc89SJohan Hedberg 	credits	= __le16_to_cpu(pkt->credits);
5476fad5fc89SJohan Hedberg 
5477fad5fc89SJohan Hedberg 	BT_DBG("cid 0x%4.4x credits 0x%4.4x", cid, credits);
5478fad5fc89SJohan Hedberg 
5479fad5fc89SJohan Hedberg 	chan = l2cap_get_chan_by_dcid(conn, cid);
5480fad5fc89SJohan Hedberg 	if (!chan)
5481fad5fc89SJohan Hedberg 		return -EBADSLT;
5482fad5fc89SJohan Hedberg 
54830f1bfe4eSJohan Hedberg 	max_credits = LE_FLOWCTL_MAX_CREDITS - chan->tx_credits;
54840f1bfe4eSJohan Hedberg 	if (credits > max_credits) {
54850f1bfe4eSJohan Hedberg 		BT_ERR("LE credits overflow");
54860f1bfe4eSJohan Hedberg 		l2cap_send_disconn_req(chan, ECONNRESET);
54870f1bfe4eSJohan Hedberg 
54880f1bfe4eSJohan Hedberg 		/* Return 0 so that we don't trigger an unnecessary
54890f1bfe4eSJohan Hedberg 		 * command reject packet.
54900f1bfe4eSJohan Hedberg 		 */
54910f1bfe4eSJohan Hedberg 		return 0;
54920f1bfe4eSJohan Hedberg 	}
54930f1bfe4eSJohan Hedberg 
5494fad5fc89SJohan Hedberg 	chan->tx_credits += credits;
5495fad5fc89SJohan Hedberg 
5496fad5fc89SJohan Hedberg 	while (chan->tx_credits && !skb_queue_empty(&chan->tx_q)) {
5497fad5fc89SJohan Hedberg 		l2cap_do_send(chan, skb_dequeue(&chan->tx_q));
5498fad5fc89SJohan Hedberg 		chan->tx_credits--;
5499fad5fc89SJohan Hedberg 	}
5500fad5fc89SJohan Hedberg 
5501fad5fc89SJohan Hedberg 	if (chan->tx_credits)
5502fad5fc89SJohan Hedberg 		chan->ops->resume(chan);
5503fad5fc89SJohan Hedberg 
5504fad5fc89SJohan Hedberg 	l2cap_chan_unlock(chan);
5505fad5fc89SJohan Hedberg 
5506fad5fc89SJohan Hedberg 	return 0;
5507fad5fc89SJohan Hedberg }
5508fad5fc89SJohan Hedberg 
550971fb4197SJohan Hedberg static inline int l2cap_le_command_rej(struct l2cap_conn *conn,
551071fb4197SJohan Hedberg 				       struct l2cap_cmd_hdr *cmd, u16 cmd_len,
551171fb4197SJohan Hedberg 				       u8 *data)
551271fb4197SJohan Hedberg {
551371fb4197SJohan Hedberg 	struct l2cap_cmd_rej_unk *rej = (struct l2cap_cmd_rej_unk *) data;
551471fb4197SJohan Hedberg 	struct l2cap_chan *chan;
551571fb4197SJohan Hedberg 
551671fb4197SJohan Hedberg 	if (cmd_len < sizeof(*rej))
551771fb4197SJohan Hedberg 		return -EPROTO;
551871fb4197SJohan Hedberg 
551971fb4197SJohan Hedberg 	mutex_lock(&conn->chan_lock);
552071fb4197SJohan Hedberg 
552171fb4197SJohan Hedberg 	chan = __l2cap_get_chan_by_ident(conn, cmd->ident);
552271fb4197SJohan Hedberg 	if (!chan)
552371fb4197SJohan Hedberg 		goto done;
552471fb4197SJohan Hedberg 
552571fb4197SJohan Hedberg 	l2cap_chan_lock(chan);
552671fb4197SJohan Hedberg 	l2cap_chan_del(chan, ECONNREFUSED);
552771fb4197SJohan Hedberg 	l2cap_chan_unlock(chan);
552871fb4197SJohan Hedberg 
552971fb4197SJohan Hedberg done:
553071fb4197SJohan Hedberg 	mutex_unlock(&conn->chan_lock);
553171fb4197SJohan Hedberg 	return 0;
553271fb4197SJohan Hedberg }
553371fb4197SJohan Hedberg 
55343300d9a9SClaudio Takahasi static inline int l2cap_le_sig_cmd(struct l2cap_conn *conn,
5535203e639eSJohan Hedberg 				   struct l2cap_cmd_hdr *cmd, u16 cmd_len,
5536203e639eSJohan Hedberg 				   u8 *data)
55373300d9a9SClaudio Takahasi {
5538b5ecba64SJohan Hedberg 	int err = 0;
5539b5ecba64SJohan Hedberg 
55403300d9a9SClaudio Takahasi 	switch (cmd->code) {
55413300d9a9SClaudio Takahasi 	case L2CAP_COMMAND_REJ:
554271fb4197SJohan Hedberg 		l2cap_le_command_rej(conn, cmd, cmd_len, data);
5543b5ecba64SJohan Hedberg 		break;
55443300d9a9SClaudio Takahasi 
55453300d9a9SClaudio Takahasi 	case L2CAP_CONN_PARAM_UPDATE_REQ:
5546b5ecba64SJohan Hedberg 		err = l2cap_conn_param_update_req(conn, cmd, cmd_len, data);
5547b5ecba64SJohan Hedberg 		break;
55483300d9a9SClaudio Takahasi 
55493300d9a9SClaudio Takahasi 	case L2CAP_CONN_PARAM_UPDATE_RSP:
5550b5ecba64SJohan Hedberg 		break;
55513300d9a9SClaudio Takahasi 
5552f1496deeSJohan Hedberg 	case L2CAP_LE_CONN_RSP:
5553f1496deeSJohan Hedberg 		l2cap_le_connect_rsp(conn, cmd, cmd_len, data);
5554b5ecba64SJohan Hedberg 		break;
5555f1496deeSJohan Hedberg 
555627e2d4c8SJohan Hedberg 	case L2CAP_LE_CONN_REQ:
5557b5ecba64SJohan Hedberg 		err = l2cap_le_connect_req(conn, cmd, cmd_len, data);
5558b5ecba64SJohan Hedberg 		break;
555927e2d4c8SJohan Hedberg 
5560fad5fc89SJohan Hedberg 	case L2CAP_LE_CREDITS:
5561fad5fc89SJohan Hedberg 		err = l2cap_le_credits(conn, cmd, cmd_len, data);
5562fad5fc89SJohan Hedberg 		break;
5563fad5fc89SJohan Hedberg 
55643defe01aSJohan Hedberg 	case L2CAP_DISCONN_REQ:
5565b5ecba64SJohan Hedberg 		err = l2cap_disconnect_req(conn, cmd, cmd_len, data);
5566b5ecba64SJohan Hedberg 		break;
55673defe01aSJohan Hedberg 
55683defe01aSJohan Hedberg 	case L2CAP_DISCONN_RSP:
55693defe01aSJohan Hedberg 		l2cap_disconnect_rsp(conn, cmd, cmd_len, data);
5570b5ecba64SJohan Hedberg 		break;
55713defe01aSJohan Hedberg 
55723300d9a9SClaudio Takahasi 	default:
55733300d9a9SClaudio Takahasi 		BT_ERR("Unknown LE signaling command 0x%2.2x", cmd->code);
5574b5ecba64SJohan Hedberg 		err = -EINVAL;
5575b5ecba64SJohan Hedberg 		break;
55763300d9a9SClaudio Takahasi 	}
5577b5ecba64SJohan Hedberg 
5578b5ecba64SJohan Hedberg 	return err;
55793300d9a9SClaudio Takahasi }
55803300d9a9SClaudio Takahasi 
5581c5623556SJohan Hedberg static inline void l2cap_le_sig_channel(struct l2cap_conn *conn,
5582c5623556SJohan Hedberg 					struct sk_buff *skb)
5583c5623556SJohan Hedberg {
558469c4e4e8SJohan Hedberg 	struct hci_conn *hcon = conn->hcon;
55854f3e219dSMarcel Holtmann 	struct l2cap_cmd_hdr *cmd;
55864f3e219dSMarcel Holtmann 	u16 len;
5587c5623556SJohan Hedberg 	int err;
5588c5623556SJohan Hedberg 
558969c4e4e8SJohan Hedberg 	if (hcon->type != LE_LINK)
55903b166295SMarcel Holtmann 		goto drop;
559169c4e4e8SJohan Hedberg 
55924f3e219dSMarcel Holtmann 	if (skb->len < L2CAP_CMD_HDR_SIZE)
55934f3e219dSMarcel Holtmann 		goto drop;
5594c5623556SJohan Hedberg 
55954f3e219dSMarcel Holtmann 	cmd = (void *) skb->data;
55964f3e219dSMarcel Holtmann 	skb_pull(skb, L2CAP_CMD_HDR_SIZE);
5597c5623556SJohan Hedberg 
55984f3e219dSMarcel Holtmann 	len = le16_to_cpu(cmd->len);
5599c5623556SJohan Hedberg 
56004f3e219dSMarcel Holtmann 	BT_DBG("code 0x%2.2x len %d id 0x%2.2x", cmd->code, len, cmd->ident);
56014f3e219dSMarcel Holtmann 
56024f3e219dSMarcel Holtmann 	if (len != skb->len || !cmd->ident) {
5603c5623556SJohan Hedberg 		BT_DBG("corrupted command");
56044f3e219dSMarcel Holtmann 		goto drop;
5605c5623556SJohan Hedberg 	}
5606c5623556SJohan Hedberg 
5607203e639eSJohan Hedberg 	err = l2cap_le_sig_cmd(conn, cmd, len, skb->data);
5608c5623556SJohan Hedberg 	if (err) {
5609c5623556SJohan Hedberg 		struct l2cap_cmd_rej_unk rej;
5610c5623556SJohan Hedberg 
5611c5623556SJohan Hedberg 		BT_ERR("Wrong link type (%d)", err);
5612c5623556SJohan Hedberg 
5613dcf4adbfSJoe Perches 		rej.reason = cpu_to_le16(L2CAP_REJ_NOT_UNDERSTOOD);
56144f3e219dSMarcel Holtmann 		l2cap_send_cmd(conn, cmd->ident, L2CAP_COMMAND_REJ,
5615c5623556SJohan Hedberg 			       sizeof(rej), &rej);
5616c5623556SJohan Hedberg 	}
5617c5623556SJohan Hedberg 
56183b166295SMarcel Holtmann drop:
5619c5623556SJohan Hedberg 	kfree_skb(skb);
5620c5623556SJohan Hedberg }
5621c5623556SJohan Hedberg 
56223300d9a9SClaudio Takahasi static inline void l2cap_sig_channel(struct l2cap_conn *conn,
56233300d9a9SClaudio Takahasi 				     struct sk_buff *skb)
56240a708f8fSGustavo F. Padovan {
562569c4e4e8SJohan Hedberg 	struct hci_conn *hcon = conn->hcon;
56260a708f8fSGustavo F. Padovan 	u8 *data = skb->data;
56270a708f8fSGustavo F. Padovan 	int len = skb->len;
56280a708f8fSGustavo F. Padovan 	struct l2cap_cmd_hdr cmd;
56293300d9a9SClaudio Takahasi 	int err;
56300a708f8fSGustavo F. Padovan 
56310a708f8fSGustavo F. Padovan 	l2cap_raw_recv(conn, skb);
56320a708f8fSGustavo F. Padovan 
563369c4e4e8SJohan Hedberg 	if (hcon->type != ACL_LINK)
56343b166295SMarcel Holtmann 		goto drop;
563569c4e4e8SJohan Hedberg 
56360a708f8fSGustavo F. Padovan 	while (len >= L2CAP_CMD_HDR_SIZE) {
56370a708f8fSGustavo F. Padovan 		u16 cmd_len;
56380a708f8fSGustavo F. Padovan 		memcpy(&cmd, data, L2CAP_CMD_HDR_SIZE);
56390a708f8fSGustavo F. Padovan 		data += L2CAP_CMD_HDR_SIZE;
56400a708f8fSGustavo F. Padovan 		len  -= L2CAP_CMD_HDR_SIZE;
56410a708f8fSGustavo F. Padovan 
56420a708f8fSGustavo F. Padovan 		cmd_len = le16_to_cpu(cmd.len);
56430a708f8fSGustavo F. Padovan 
56442d792818SGustavo Padovan 		BT_DBG("code 0x%2.2x len %d id 0x%2.2x", cmd.code, cmd_len,
56452d792818SGustavo Padovan 		       cmd.ident);
56460a708f8fSGustavo F. Padovan 
56470a708f8fSGustavo F. Padovan 		if (cmd_len > len || !cmd.ident) {
56480a708f8fSGustavo F. Padovan 			BT_DBG("corrupted command");
56490a708f8fSGustavo F. Padovan 			break;
56500a708f8fSGustavo F. Padovan 		}
56510a708f8fSGustavo F. Padovan 
56523300d9a9SClaudio Takahasi 		err = l2cap_bredr_sig_cmd(conn, &cmd, cmd_len, data);
56530a708f8fSGustavo F. Padovan 		if (err) {
5654e2fd318eSIlia Kolomisnky 			struct l2cap_cmd_rej_unk rej;
56552c6d1a2eSGustavo F. Padovan 
56562c6d1a2eSGustavo F. Padovan 			BT_ERR("Wrong link type (%d)", err);
56570a708f8fSGustavo F. Padovan 
5658dcf4adbfSJoe Perches 			rej.reason = cpu_to_le16(L2CAP_REJ_NOT_UNDERSTOOD);
56592d792818SGustavo Padovan 			l2cap_send_cmd(conn, cmd.ident, L2CAP_COMMAND_REJ,
56602d792818SGustavo Padovan 				       sizeof(rej), &rej);
56610a708f8fSGustavo F. Padovan 		}
56620a708f8fSGustavo F. Padovan 
56630a708f8fSGustavo F. Padovan 		data += cmd_len;
56640a708f8fSGustavo F. Padovan 		len  -= cmd_len;
56650a708f8fSGustavo F. Padovan 	}
56660a708f8fSGustavo F. Padovan 
56673b166295SMarcel Holtmann drop:
56680a708f8fSGustavo F. Padovan 	kfree_skb(skb);
56690a708f8fSGustavo F. Padovan }
56700a708f8fSGustavo F. Padovan 
567147d1ec61SGustavo F. Padovan static int l2cap_check_fcs(struct l2cap_chan *chan,  struct sk_buff *skb)
56720a708f8fSGustavo F. Padovan {
56730a708f8fSGustavo F. Padovan 	u16 our_fcs, rcv_fcs;
5674e4ca6d98SAndrei Emeltchenko 	int hdr_size;
5675e4ca6d98SAndrei Emeltchenko 
5676e4ca6d98SAndrei Emeltchenko 	if (test_bit(FLAG_EXT_CTRL, &chan->flags))
5677e4ca6d98SAndrei Emeltchenko 		hdr_size = L2CAP_EXT_HDR_SIZE;
5678e4ca6d98SAndrei Emeltchenko 	else
5679e4ca6d98SAndrei Emeltchenko 		hdr_size = L2CAP_ENH_HDR_SIZE;
56800a708f8fSGustavo F. Padovan 
568147d1ec61SGustavo F. Padovan 	if (chan->fcs == L2CAP_FCS_CRC16) {
568203a51213SAndrei Emeltchenko 		skb_trim(skb, skb->len - L2CAP_FCS_SIZE);
56830a708f8fSGustavo F. Padovan 		rcv_fcs = get_unaligned_le16(skb->data + skb->len);
56840a708f8fSGustavo F. Padovan 		our_fcs = crc16(0, skb->data - hdr_size, skb->len + hdr_size);
56850a708f8fSGustavo F. Padovan 
56860a708f8fSGustavo F. Padovan 		if (our_fcs != rcv_fcs)
56870a708f8fSGustavo F. Padovan 			return -EBADMSG;
56880a708f8fSGustavo F. Padovan 	}
56890a708f8fSGustavo F. Padovan 	return 0;
56900a708f8fSGustavo F. Padovan }
56910a708f8fSGustavo F. Padovan 
56926ea00485SMat Martineau static void l2cap_send_i_or_rr_or_rnr(struct l2cap_chan *chan)
56930a708f8fSGustavo F. Padovan {
5694e31f7633SMat Martineau 	struct l2cap_ctrl control;
56950a708f8fSGustavo F. Padovan 
5696e31f7633SMat Martineau 	BT_DBG("chan %p", chan);
56970a708f8fSGustavo F. Padovan 
5698e31f7633SMat Martineau 	memset(&control, 0, sizeof(control));
5699e31f7633SMat Martineau 	control.sframe = 1;
5700e31f7633SMat Martineau 	control.final = 1;
5701e31f7633SMat Martineau 	control.reqseq = chan->buffer_seq;
5702e31f7633SMat Martineau 	set_bit(CONN_SEND_FBIT, &chan->conn_state);
57030a708f8fSGustavo F. Padovan 
5704e2ab4353SGustavo F. Padovan 	if (test_bit(CONN_LOCAL_BUSY, &chan->conn_state)) {
5705e31f7633SMat Martineau 		control.super = L2CAP_SUPER_RNR;
5706e31f7633SMat Martineau 		l2cap_send_sframe(chan, &control);
57070a708f8fSGustavo F. Padovan 	}
57080a708f8fSGustavo F. Padovan 
5709e31f7633SMat Martineau 	if (test_and_clear_bit(CONN_REMOTE_BUSY, &chan->conn_state) &&
5710e31f7633SMat Martineau 	    chan->unacked_frames > 0)
5711e31f7633SMat Martineau 		__set_retrans_timer(chan);
57120a708f8fSGustavo F. Padovan 
5713e31f7633SMat Martineau 	/* Send pending iframes */
5714525cd185SGustavo F. Padovan 	l2cap_ertm_send(chan);
57150a708f8fSGustavo F. Padovan 
5716e2ab4353SGustavo F. Padovan 	if (!test_bit(CONN_LOCAL_BUSY, &chan->conn_state) &&
5717e31f7633SMat Martineau 	    test_bit(CONN_SEND_FBIT, &chan->conn_state)) {
5718e31f7633SMat Martineau 		/* F-bit wasn't sent in an s-frame or i-frame yet, so
5719e31f7633SMat Martineau 		 * send it now.
5720e31f7633SMat Martineau 		 */
5721e31f7633SMat Martineau 		control.super = L2CAP_SUPER_RR;
5722e31f7633SMat Martineau 		l2cap_send_sframe(chan, &control);
57230a708f8fSGustavo F. Padovan 	}
57240a708f8fSGustavo F. Padovan }
57250a708f8fSGustavo F. Padovan 
57262d792818SGustavo Padovan static void append_skb_frag(struct sk_buff *skb, struct sk_buff *new_frag,
57272d792818SGustavo Padovan 			    struct sk_buff **last_frag)
57280a708f8fSGustavo F. Padovan {
572984084a31SMat Martineau 	/* skb->len reflects data in skb as well as all fragments
573084084a31SMat Martineau 	 * skb->data_len reflects only data in fragments
573184084a31SMat Martineau 	 */
573284084a31SMat Martineau 	if (!skb_has_frag_list(skb))
573384084a31SMat Martineau 		skb_shinfo(skb)->frag_list = new_frag;
573484084a31SMat Martineau 
573584084a31SMat Martineau 	new_frag->next = NULL;
573684084a31SMat Martineau 
573784084a31SMat Martineau 	(*last_frag)->next = new_frag;
573884084a31SMat Martineau 	*last_frag = new_frag;
573984084a31SMat Martineau 
574084084a31SMat Martineau 	skb->len += new_frag->len;
574184084a31SMat Martineau 	skb->data_len += new_frag->len;
574284084a31SMat Martineau 	skb->truesize += new_frag->truesize;
574384084a31SMat Martineau }
574484084a31SMat Martineau 
57454b51dae9SMat Martineau static int l2cap_reassemble_sdu(struct l2cap_chan *chan, struct sk_buff *skb,
57464b51dae9SMat Martineau 				struct l2cap_ctrl *control)
574784084a31SMat Martineau {
574884084a31SMat Martineau 	int err = -EINVAL;
57490a708f8fSGustavo F. Padovan 
57504b51dae9SMat Martineau 	switch (control->sar) {
57517e0ef6eeSAndrei Emeltchenko 	case L2CAP_SAR_UNSEGMENTED:
575284084a31SMat Martineau 		if (chan->sdu)
575384084a31SMat Martineau 			break;
57540a708f8fSGustavo F. Padovan 
575580b98027SGustavo Padovan 		err = chan->ops->recv(chan, skb);
575684084a31SMat Martineau 		break;
57570a708f8fSGustavo F. Padovan 
57587e0ef6eeSAndrei Emeltchenko 	case L2CAP_SAR_START:
575984084a31SMat Martineau 		if (chan->sdu)
576084084a31SMat Martineau 			break;
57610a708f8fSGustavo F. Padovan 
57626f61fd47SGustavo F. Padovan 		chan->sdu_len = get_unaligned_le16(skb->data);
576303a51213SAndrei Emeltchenko 		skb_pull(skb, L2CAP_SDULEN_SIZE);
57640a708f8fSGustavo F. Padovan 
576584084a31SMat Martineau 		if (chan->sdu_len > chan->imtu) {
576684084a31SMat Martineau 			err = -EMSGSIZE;
576784084a31SMat Martineau 			break;
576884084a31SMat Martineau 		}
57690a708f8fSGustavo F. Padovan 
577084084a31SMat Martineau 		if (skb->len >= chan->sdu_len)
577184084a31SMat Martineau 			break;
577284084a31SMat Martineau 
577384084a31SMat Martineau 		chan->sdu = skb;
577484084a31SMat Martineau 		chan->sdu_last_frag = skb;
577584084a31SMat Martineau 
577684084a31SMat Martineau 		skb = NULL;
577784084a31SMat Martineau 		err = 0;
57780a708f8fSGustavo F. Padovan 		break;
57790a708f8fSGustavo F. Padovan 
57807e0ef6eeSAndrei Emeltchenko 	case L2CAP_SAR_CONTINUE:
57816f61fd47SGustavo F. Padovan 		if (!chan->sdu)
578284084a31SMat Martineau 			break;
57830a708f8fSGustavo F. Padovan 
578484084a31SMat Martineau 		append_skb_frag(chan->sdu, skb,
578584084a31SMat Martineau 				&chan->sdu_last_frag);
578684084a31SMat Martineau 		skb = NULL;
57870a708f8fSGustavo F. Padovan 
578884084a31SMat Martineau 		if (chan->sdu->len >= chan->sdu_len)
578984084a31SMat Martineau 			break;
57900a708f8fSGustavo F. Padovan 
579184084a31SMat Martineau 		err = 0;
57920a708f8fSGustavo F. Padovan 		break;
57930a708f8fSGustavo F. Padovan 
57947e0ef6eeSAndrei Emeltchenko 	case L2CAP_SAR_END:
57956f61fd47SGustavo F. Padovan 		if (!chan->sdu)
579684084a31SMat Martineau 			break;
57970a708f8fSGustavo F. Padovan 
579884084a31SMat Martineau 		append_skb_frag(chan->sdu, skb,
579984084a31SMat Martineau 				&chan->sdu_last_frag);
580084084a31SMat Martineau 		skb = NULL;
58010a708f8fSGustavo F. Padovan 
580284084a31SMat Martineau 		if (chan->sdu->len != chan->sdu_len)
580384084a31SMat Martineau 			break;
58040a708f8fSGustavo F. Padovan 
580580b98027SGustavo Padovan 		err = chan->ops->recv(chan, chan->sdu);
58060a708f8fSGustavo F. Padovan 
580784084a31SMat Martineau 		if (!err) {
580884084a31SMat Martineau 			/* Reassembly complete */
580984084a31SMat Martineau 			chan->sdu = NULL;
581084084a31SMat Martineau 			chan->sdu_last_frag = NULL;
581184084a31SMat Martineau 			chan->sdu_len = 0;
58120a708f8fSGustavo F. Padovan 		}
58130a708f8fSGustavo F. Padovan 		break;
58140a708f8fSGustavo F. Padovan 	}
58150a708f8fSGustavo F. Padovan 
581684084a31SMat Martineau 	if (err) {
58170a708f8fSGustavo F. Padovan 		kfree_skb(skb);
58186f61fd47SGustavo F. Padovan 		kfree_skb(chan->sdu);
58196f61fd47SGustavo F. Padovan 		chan->sdu = NULL;
582084084a31SMat Martineau 		chan->sdu_last_frag = NULL;
582184084a31SMat Martineau 		chan->sdu_len = 0;
582284084a31SMat Martineau 	}
58230a708f8fSGustavo F. Padovan 
582484084a31SMat Martineau 	return err;
58250a708f8fSGustavo F. Padovan }
58260a708f8fSGustavo F. Padovan 
582732b32735SMat Martineau static int l2cap_resegment(struct l2cap_chan *chan)
582832b32735SMat Martineau {
582932b32735SMat Martineau 	/* Placeholder */
583032b32735SMat Martineau 	return 0;
583132b32735SMat Martineau }
583232b32735SMat Martineau 
5833e328140fSMat Martineau void l2cap_chan_busy(struct l2cap_chan *chan, int busy)
58340a708f8fSGustavo F. Padovan {
583561aa4f5bSMat Martineau 	u8 event;
583661aa4f5bSMat Martineau 
583761aa4f5bSMat Martineau 	if (chan->mode != L2CAP_MODE_ERTM)
583861aa4f5bSMat Martineau 		return;
583961aa4f5bSMat Martineau 
584061aa4f5bSMat Martineau 	event = busy ? L2CAP_EV_LOCAL_BUSY_DETECTED : L2CAP_EV_LOCAL_BUSY_CLEAR;
5841401bb1f7SAndrei Emeltchenko 	l2cap_tx(chan, NULL, NULL, event);
58420a708f8fSGustavo F. Padovan }
58430a708f8fSGustavo F. Padovan 
5844d2a7ac5dSMat Martineau static int l2cap_rx_queued_iframes(struct l2cap_chan *chan)
5845d2a7ac5dSMat Martineau {
584663838725SMat Martineau 	int err = 0;
584763838725SMat Martineau 	/* Pass sequential frames to l2cap_reassemble_sdu()
584863838725SMat Martineau 	 * until a gap is encountered.
584963838725SMat Martineau 	 */
585063838725SMat Martineau 
585163838725SMat Martineau 	BT_DBG("chan %p", chan);
585263838725SMat Martineau 
585363838725SMat Martineau 	while (!test_bit(CONN_LOCAL_BUSY, &chan->conn_state)) {
585463838725SMat Martineau 		struct sk_buff *skb;
585563838725SMat Martineau 		BT_DBG("Searching for skb with txseq %d (queue len %d)",
585663838725SMat Martineau 		       chan->buffer_seq, skb_queue_len(&chan->srej_q));
585763838725SMat Martineau 
585863838725SMat Martineau 		skb = l2cap_ertm_seq_in_queue(&chan->srej_q, chan->buffer_seq);
585963838725SMat Martineau 
586063838725SMat Martineau 		if (!skb)
586163838725SMat Martineau 			break;
586263838725SMat Martineau 
586363838725SMat Martineau 		skb_unlink(skb, &chan->srej_q);
586463838725SMat Martineau 		chan->buffer_seq = __next_seq(chan, chan->buffer_seq);
586563838725SMat Martineau 		err = l2cap_reassemble_sdu(chan, skb, &bt_cb(skb)->control);
586663838725SMat Martineau 		if (err)
586763838725SMat Martineau 			break;
586863838725SMat Martineau 	}
586963838725SMat Martineau 
587063838725SMat Martineau 	if (skb_queue_empty(&chan->srej_q)) {
587163838725SMat Martineau 		chan->rx_state = L2CAP_RX_STATE_RECV;
587263838725SMat Martineau 		l2cap_send_ack(chan);
587363838725SMat Martineau 	}
587463838725SMat Martineau 
587563838725SMat Martineau 	return err;
5876d2a7ac5dSMat Martineau }
5877d2a7ac5dSMat Martineau 
5878d2a7ac5dSMat Martineau static void l2cap_handle_srej(struct l2cap_chan *chan,
5879d2a7ac5dSMat Martineau 			      struct l2cap_ctrl *control)
5880d2a7ac5dSMat Martineau {
5881f80842a8SMat Martineau 	struct sk_buff *skb;
5882f80842a8SMat Martineau 
5883f80842a8SMat Martineau 	BT_DBG("chan %p, control %p", chan, control);
5884f80842a8SMat Martineau 
5885f80842a8SMat Martineau 	if (control->reqseq == chan->next_tx_seq) {
5886f80842a8SMat Martineau 		BT_DBG("Invalid reqseq %d, disconnecting", control->reqseq);
58875e4e3972SAndrei Emeltchenko 		l2cap_send_disconn_req(chan, ECONNRESET);
5888f80842a8SMat Martineau 		return;
5889f80842a8SMat Martineau 	}
5890f80842a8SMat Martineau 
5891f80842a8SMat Martineau 	skb = l2cap_ertm_seq_in_queue(&chan->tx_q, control->reqseq);
5892f80842a8SMat Martineau 
5893f80842a8SMat Martineau 	if (skb == NULL) {
5894f80842a8SMat Martineau 		BT_DBG("Seq %d not available for retransmission",
5895f80842a8SMat Martineau 		       control->reqseq);
5896f80842a8SMat Martineau 		return;
5897f80842a8SMat Martineau 	}
5898f80842a8SMat Martineau 
5899f80842a8SMat Martineau 	if (chan->max_tx != 0 && bt_cb(skb)->control.retries >= chan->max_tx) {
5900f80842a8SMat Martineau 		BT_DBG("Retry limit exceeded (%d)", chan->max_tx);
59015e4e3972SAndrei Emeltchenko 		l2cap_send_disconn_req(chan, ECONNRESET);
5902f80842a8SMat Martineau 		return;
5903f80842a8SMat Martineau 	}
5904f80842a8SMat Martineau 
5905f80842a8SMat Martineau 	clear_bit(CONN_REMOTE_BUSY, &chan->conn_state);
5906f80842a8SMat Martineau 
5907f80842a8SMat Martineau 	if (control->poll) {
5908f80842a8SMat Martineau 		l2cap_pass_to_tx(chan, control);
5909f80842a8SMat Martineau 
5910f80842a8SMat Martineau 		set_bit(CONN_SEND_FBIT, &chan->conn_state);
5911f80842a8SMat Martineau 		l2cap_retransmit(chan, control);
5912f80842a8SMat Martineau 		l2cap_ertm_send(chan);
5913f80842a8SMat Martineau 
5914f80842a8SMat Martineau 		if (chan->tx_state == L2CAP_TX_STATE_WAIT_F) {
5915f80842a8SMat Martineau 			set_bit(CONN_SREJ_ACT, &chan->conn_state);
5916f80842a8SMat Martineau 			chan->srej_save_reqseq = control->reqseq;
5917f80842a8SMat Martineau 		}
5918f80842a8SMat Martineau 	} else {
5919f80842a8SMat Martineau 		l2cap_pass_to_tx_fbit(chan, control);
5920f80842a8SMat Martineau 
5921f80842a8SMat Martineau 		if (control->final) {
5922f80842a8SMat Martineau 			if (chan->srej_save_reqseq != control->reqseq ||
5923f80842a8SMat Martineau 			    !test_and_clear_bit(CONN_SREJ_ACT,
5924f80842a8SMat Martineau 						&chan->conn_state))
5925f80842a8SMat Martineau 				l2cap_retransmit(chan, control);
5926f80842a8SMat Martineau 		} else {
5927f80842a8SMat Martineau 			l2cap_retransmit(chan, control);
5928f80842a8SMat Martineau 			if (chan->tx_state == L2CAP_TX_STATE_WAIT_F) {
5929f80842a8SMat Martineau 				set_bit(CONN_SREJ_ACT, &chan->conn_state);
5930f80842a8SMat Martineau 				chan->srej_save_reqseq = control->reqseq;
5931f80842a8SMat Martineau 			}
5932f80842a8SMat Martineau 		}
5933f80842a8SMat Martineau 	}
5934d2a7ac5dSMat Martineau }
5935d2a7ac5dSMat Martineau 
5936d2a7ac5dSMat Martineau static void l2cap_handle_rej(struct l2cap_chan *chan,
5937d2a7ac5dSMat Martineau 			     struct l2cap_ctrl *control)
5938d2a7ac5dSMat Martineau {
5939fcd289dfSMat Martineau 	struct sk_buff *skb;
5940fcd289dfSMat Martineau 
5941fcd289dfSMat Martineau 	BT_DBG("chan %p, control %p", chan, control);
5942fcd289dfSMat Martineau 
5943fcd289dfSMat Martineau 	if (control->reqseq == chan->next_tx_seq) {
5944fcd289dfSMat Martineau 		BT_DBG("Invalid reqseq %d, disconnecting", control->reqseq);
59455e4e3972SAndrei Emeltchenko 		l2cap_send_disconn_req(chan, ECONNRESET);
5946fcd289dfSMat Martineau 		return;
5947fcd289dfSMat Martineau 	}
5948fcd289dfSMat Martineau 
5949fcd289dfSMat Martineau 	skb = l2cap_ertm_seq_in_queue(&chan->tx_q, control->reqseq);
5950fcd289dfSMat Martineau 
5951fcd289dfSMat Martineau 	if (chan->max_tx && skb &&
5952fcd289dfSMat Martineau 	    bt_cb(skb)->control.retries >= chan->max_tx) {
5953fcd289dfSMat Martineau 		BT_DBG("Retry limit exceeded (%d)", chan->max_tx);
59545e4e3972SAndrei Emeltchenko 		l2cap_send_disconn_req(chan, ECONNRESET);
5955fcd289dfSMat Martineau 		return;
5956fcd289dfSMat Martineau 	}
5957fcd289dfSMat Martineau 
5958fcd289dfSMat Martineau 	clear_bit(CONN_REMOTE_BUSY, &chan->conn_state);
5959fcd289dfSMat Martineau 
5960fcd289dfSMat Martineau 	l2cap_pass_to_tx(chan, control);
5961fcd289dfSMat Martineau 
5962fcd289dfSMat Martineau 	if (control->final) {
5963fcd289dfSMat Martineau 		if (!test_and_clear_bit(CONN_REJ_ACT, &chan->conn_state))
5964fcd289dfSMat Martineau 			l2cap_retransmit_all(chan, control);
5965fcd289dfSMat Martineau 	} else {
5966fcd289dfSMat Martineau 		l2cap_retransmit_all(chan, control);
5967fcd289dfSMat Martineau 		l2cap_ertm_send(chan);
5968fcd289dfSMat Martineau 		if (chan->tx_state == L2CAP_TX_STATE_WAIT_F)
5969fcd289dfSMat Martineau 			set_bit(CONN_REJ_ACT, &chan->conn_state);
5970fcd289dfSMat Martineau 	}
5971d2a7ac5dSMat Martineau }
5972d2a7ac5dSMat Martineau 
59734b51dae9SMat Martineau static u8 l2cap_classify_txseq(struct l2cap_chan *chan, u16 txseq)
59744b51dae9SMat Martineau {
59754b51dae9SMat Martineau 	BT_DBG("chan %p, txseq %d", chan, txseq);
59764b51dae9SMat Martineau 
59774b51dae9SMat Martineau 	BT_DBG("last_acked_seq %d, expected_tx_seq %d", chan->last_acked_seq,
59784b51dae9SMat Martineau 	       chan->expected_tx_seq);
59794b51dae9SMat Martineau 
59804b51dae9SMat Martineau 	if (chan->rx_state == L2CAP_RX_STATE_SREJ_SENT) {
59814b51dae9SMat Martineau 		if (__seq_offset(chan, txseq, chan->last_acked_seq) >=
59824b51dae9SMat Martineau 		    chan->tx_win) {
59834b51dae9SMat Martineau 			/* See notes below regarding "double poll" and
59844b51dae9SMat Martineau 			 * invalid packets.
59854b51dae9SMat Martineau 			 */
59864b51dae9SMat Martineau 			if (chan->tx_win <= ((chan->tx_win_max + 1) >> 1)) {
59874b51dae9SMat Martineau 				BT_DBG("Invalid/Ignore - after SREJ");
59884b51dae9SMat Martineau 				return L2CAP_TXSEQ_INVALID_IGNORE;
59894b51dae9SMat Martineau 			} else {
59904b51dae9SMat Martineau 				BT_DBG("Invalid - in window after SREJ sent");
59914b51dae9SMat Martineau 				return L2CAP_TXSEQ_INVALID;
59924b51dae9SMat Martineau 			}
59934b51dae9SMat Martineau 		}
59944b51dae9SMat Martineau 
59954b51dae9SMat Martineau 		if (chan->srej_list.head == txseq) {
59964b51dae9SMat Martineau 			BT_DBG("Expected SREJ");
59974b51dae9SMat Martineau 			return L2CAP_TXSEQ_EXPECTED_SREJ;
59984b51dae9SMat Martineau 		}
59994b51dae9SMat Martineau 
60004b51dae9SMat Martineau 		if (l2cap_ertm_seq_in_queue(&chan->srej_q, txseq)) {
60014b51dae9SMat Martineau 			BT_DBG("Duplicate SREJ - txseq already stored");
60024b51dae9SMat Martineau 			return L2CAP_TXSEQ_DUPLICATE_SREJ;
60034b51dae9SMat Martineau 		}
60044b51dae9SMat Martineau 
60054b51dae9SMat Martineau 		if (l2cap_seq_list_contains(&chan->srej_list, txseq)) {
60064b51dae9SMat Martineau 			BT_DBG("Unexpected SREJ - not requested");
60074b51dae9SMat Martineau 			return L2CAP_TXSEQ_UNEXPECTED_SREJ;
60084b51dae9SMat Martineau 		}
60094b51dae9SMat Martineau 	}
60104b51dae9SMat Martineau 
60114b51dae9SMat Martineau 	if (chan->expected_tx_seq == txseq) {
60124b51dae9SMat Martineau 		if (__seq_offset(chan, txseq, chan->last_acked_seq) >=
60134b51dae9SMat Martineau 		    chan->tx_win) {
60144b51dae9SMat Martineau 			BT_DBG("Invalid - txseq outside tx window");
60154b51dae9SMat Martineau 			return L2CAP_TXSEQ_INVALID;
60164b51dae9SMat Martineau 		} else {
60174b51dae9SMat Martineau 			BT_DBG("Expected");
60184b51dae9SMat Martineau 			return L2CAP_TXSEQ_EXPECTED;
60194b51dae9SMat Martineau 		}
60204b51dae9SMat Martineau 	}
60214b51dae9SMat Martineau 
60224b51dae9SMat Martineau 	if (__seq_offset(chan, txseq, chan->last_acked_seq) <
60232d792818SGustavo Padovan 	    __seq_offset(chan, chan->expected_tx_seq, chan->last_acked_seq)) {
60244b51dae9SMat Martineau 		BT_DBG("Duplicate - expected_tx_seq later than txseq");
60254b51dae9SMat Martineau 		return L2CAP_TXSEQ_DUPLICATE;
60264b51dae9SMat Martineau 	}
60274b51dae9SMat Martineau 
60284b51dae9SMat Martineau 	if (__seq_offset(chan, txseq, chan->last_acked_seq) >= chan->tx_win) {
60294b51dae9SMat Martineau 		/* A source of invalid packets is a "double poll" condition,
60304b51dae9SMat Martineau 		 * where delays cause us to send multiple poll packets.  If
60314b51dae9SMat Martineau 		 * the remote stack receives and processes both polls,
60324b51dae9SMat Martineau 		 * sequence numbers can wrap around in such a way that a
60334b51dae9SMat Martineau 		 * resent frame has a sequence number that looks like new data
60344b51dae9SMat Martineau 		 * with a sequence gap.  This would trigger an erroneous SREJ
60354b51dae9SMat Martineau 		 * request.
60364b51dae9SMat Martineau 		 *
60374b51dae9SMat Martineau 		 * Fortunately, this is impossible with a tx window that's
60384b51dae9SMat Martineau 		 * less than half of the maximum sequence number, which allows
60394b51dae9SMat Martineau 		 * invalid frames to be safely ignored.
60404b51dae9SMat Martineau 		 *
60414b51dae9SMat Martineau 		 * With tx window sizes greater than half of the tx window
60424b51dae9SMat Martineau 		 * maximum, the frame is invalid and cannot be ignored.  This
60434b51dae9SMat Martineau 		 * causes a disconnect.
60444b51dae9SMat Martineau 		 */
60454b51dae9SMat Martineau 
60464b51dae9SMat Martineau 		if (chan->tx_win <= ((chan->tx_win_max + 1) >> 1)) {
60474b51dae9SMat Martineau 			BT_DBG("Invalid/Ignore - txseq outside tx window");
60484b51dae9SMat Martineau 			return L2CAP_TXSEQ_INVALID_IGNORE;
60494b51dae9SMat Martineau 		} else {
60504b51dae9SMat Martineau 			BT_DBG("Invalid - txseq outside tx window");
60514b51dae9SMat Martineau 			return L2CAP_TXSEQ_INVALID;
60524b51dae9SMat Martineau 		}
60534b51dae9SMat Martineau 	} else {
60544b51dae9SMat Martineau 		BT_DBG("Unexpected - txseq indicates missing frames");
60554b51dae9SMat Martineau 		return L2CAP_TXSEQ_UNEXPECTED;
60564b51dae9SMat Martineau 	}
60574b51dae9SMat Martineau }
60584b51dae9SMat Martineau 
6059d2a7ac5dSMat Martineau static int l2cap_rx_state_recv(struct l2cap_chan *chan,
6060d2a7ac5dSMat Martineau 			       struct l2cap_ctrl *control,
6061d2a7ac5dSMat Martineau 			       struct sk_buff *skb, u8 event)
6062d2a7ac5dSMat Martineau {
6063d2a7ac5dSMat Martineau 	int err = 0;
6064941247f9SPeter Senna Tschudin 	bool skb_in_use = false;
6065d2a7ac5dSMat Martineau 
6066d2a7ac5dSMat Martineau 	BT_DBG("chan %p, control %p, skb %p, event %d", chan, control, skb,
6067d2a7ac5dSMat Martineau 	       event);
6068d2a7ac5dSMat Martineau 
6069d2a7ac5dSMat Martineau 	switch (event) {
6070d2a7ac5dSMat Martineau 	case L2CAP_EV_RECV_IFRAME:
6071d2a7ac5dSMat Martineau 		switch (l2cap_classify_txseq(chan, control->txseq)) {
6072d2a7ac5dSMat Martineau 		case L2CAP_TXSEQ_EXPECTED:
6073d2a7ac5dSMat Martineau 			l2cap_pass_to_tx(chan, control);
6074d2a7ac5dSMat Martineau 
6075d2a7ac5dSMat Martineau 			if (test_bit(CONN_LOCAL_BUSY, &chan->conn_state)) {
6076d2a7ac5dSMat Martineau 				BT_DBG("Busy, discarding expected seq %d",
6077d2a7ac5dSMat Martineau 				       control->txseq);
6078d2a7ac5dSMat Martineau 				break;
6079d2a7ac5dSMat Martineau 			}
6080d2a7ac5dSMat Martineau 
6081d2a7ac5dSMat Martineau 			chan->expected_tx_seq = __next_seq(chan,
6082d2a7ac5dSMat Martineau 							   control->txseq);
6083d2a7ac5dSMat Martineau 
6084d2a7ac5dSMat Martineau 			chan->buffer_seq = chan->expected_tx_seq;
6085941247f9SPeter Senna Tschudin 			skb_in_use = true;
6086d2a7ac5dSMat Martineau 
6087d2a7ac5dSMat Martineau 			err = l2cap_reassemble_sdu(chan, skb, control);
6088d2a7ac5dSMat Martineau 			if (err)
6089d2a7ac5dSMat Martineau 				break;
6090d2a7ac5dSMat Martineau 
6091d2a7ac5dSMat Martineau 			if (control->final) {
6092d2a7ac5dSMat Martineau 				if (!test_and_clear_bit(CONN_REJ_ACT,
6093d2a7ac5dSMat Martineau 							&chan->conn_state)) {
6094d2a7ac5dSMat Martineau 					control->final = 0;
6095d2a7ac5dSMat Martineau 					l2cap_retransmit_all(chan, control);
6096d2a7ac5dSMat Martineau 					l2cap_ertm_send(chan);
6097d2a7ac5dSMat Martineau 				}
6098d2a7ac5dSMat Martineau 			}
6099d2a7ac5dSMat Martineau 
6100d2a7ac5dSMat Martineau 			if (!test_bit(CONN_LOCAL_BUSY, &chan->conn_state))
6101d2a7ac5dSMat Martineau 				l2cap_send_ack(chan);
6102d2a7ac5dSMat Martineau 			break;
6103d2a7ac5dSMat Martineau 		case L2CAP_TXSEQ_UNEXPECTED:
6104d2a7ac5dSMat Martineau 			l2cap_pass_to_tx(chan, control);
6105d2a7ac5dSMat Martineau 
6106d2a7ac5dSMat Martineau 			/* Can't issue SREJ frames in the local busy state.
6107d2a7ac5dSMat Martineau 			 * Drop this frame, it will be seen as missing
6108d2a7ac5dSMat Martineau 			 * when local busy is exited.
6109d2a7ac5dSMat Martineau 			 */
6110d2a7ac5dSMat Martineau 			if (test_bit(CONN_LOCAL_BUSY, &chan->conn_state)) {
6111d2a7ac5dSMat Martineau 				BT_DBG("Busy, discarding unexpected seq %d",
6112d2a7ac5dSMat Martineau 				       control->txseq);
6113d2a7ac5dSMat Martineau 				break;
6114d2a7ac5dSMat Martineau 			}
6115d2a7ac5dSMat Martineau 
6116d2a7ac5dSMat Martineau 			/* There was a gap in the sequence, so an SREJ
6117d2a7ac5dSMat Martineau 			 * must be sent for each missing frame.  The
6118d2a7ac5dSMat Martineau 			 * current frame is stored for later use.
6119d2a7ac5dSMat Martineau 			 */
6120d2a7ac5dSMat Martineau 			skb_queue_tail(&chan->srej_q, skb);
6121941247f9SPeter Senna Tschudin 			skb_in_use = true;
6122d2a7ac5dSMat Martineau 			BT_DBG("Queued %p (queue len %d)", skb,
6123d2a7ac5dSMat Martineau 			       skb_queue_len(&chan->srej_q));
6124d2a7ac5dSMat Martineau 
6125d2a7ac5dSMat Martineau 			clear_bit(CONN_SREJ_ACT, &chan->conn_state);
6126d2a7ac5dSMat Martineau 			l2cap_seq_list_clear(&chan->srej_list);
6127d2a7ac5dSMat Martineau 			l2cap_send_srej(chan, control->txseq);
6128d2a7ac5dSMat Martineau 
6129d2a7ac5dSMat Martineau 			chan->rx_state = L2CAP_RX_STATE_SREJ_SENT;
6130d2a7ac5dSMat Martineau 			break;
6131d2a7ac5dSMat Martineau 		case L2CAP_TXSEQ_DUPLICATE:
6132d2a7ac5dSMat Martineau 			l2cap_pass_to_tx(chan, control);
6133d2a7ac5dSMat Martineau 			break;
6134d2a7ac5dSMat Martineau 		case L2CAP_TXSEQ_INVALID_IGNORE:
6135d2a7ac5dSMat Martineau 			break;
6136d2a7ac5dSMat Martineau 		case L2CAP_TXSEQ_INVALID:
6137d2a7ac5dSMat Martineau 		default:
61385e4e3972SAndrei Emeltchenko 			l2cap_send_disconn_req(chan, ECONNRESET);
6139d2a7ac5dSMat Martineau 			break;
6140d2a7ac5dSMat Martineau 		}
6141d2a7ac5dSMat Martineau 		break;
6142d2a7ac5dSMat Martineau 	case L2CAP_EV_RECV_RR:
6143d2a7ac5dSMat Martineau 		l2cap_pass_to_tx(chan, control);
6144d2a7ac5dSMat Martineau 		if (control->final) {
6145d2a7ac5dSMat Martineau 			clear_bit(CONN_REMOTE_BUSY, &chan->conn_state);
6146d2a7ac5dSMat Martineau 
6147e6a3ee6eSMat Martineau 			if (!test_and_clear_bit(CONN_REJ_ACT, &chan->conn_state) &&
6148e6a3ee6eSMat Martineau 			    !__chan_is_moving(chan)) {
6149d2a7ac5dSMat Martineau 				control->final = 0;
6150d2a7ac5dSMat Martineau 				l2cap_retransmit_all(chan, control);
6151d2a7ac5dSMat Martineau 			}
6152d2a7ac5dSMat Martineau 
6153d2a7ac5dSMat Martineau 			l2cap_ertm_send(chan);
6154d2a7ac5dSMat Martineau 		} else if (control->poll) {
6155d2a7ac5dSMat Martineau 			l2cap_send_i_or_rr_or_rnr(chan);
6156d2a7ac5dSMat Martineau 		} else {
6157d2a7ac5dSMat Martineau 			if (test_and_clear_bit(CONN_REMOTE_BUSY,
6158d2a7ac5dSMat Martineau 					       &chan->conn_state) &&
6159d2a7ac5dSMat Martineau 			    chan->unacked_frames)
6160d2a7ac5dSMat Martineau 				__set_retrans_timer(chan);
6161d2a7ac5dSMat Martineau 
6162d2a7ac5dSMat Martineau 			l2cap_ertm_send(chan);
6163d2a7ac5dSMat Martineau 		}
6164d2a7ac5dSMat Martineau 		break;
6165d2a7ac5dSMat Martineau 	case L2CAP_EV_RECV_RNR:
6166d2a7ac5dSMat Martineau 		set_bit(CONN_REMOTE_BUSY, &chan->conn_state);
6167d2a7ac5dSMat Martineau 		l2cap_pass_to_tx(chan, control);
6168d2a7ac5dSMat Martineau 		if (control && control->poll) {
6169d2a7ac5dSMat Martineau 			set_bit(CONN_SEND_FBIT, &chan->conn_state);
6170d2a7ac5dSMat Martineau 			l2cap_send_rr_or_rnr(chan, 0);
6171d2a7ac5dSMat Martineau 		}
6172d2a7ac5dSMat Martineau 		__clear_retrans_timer(chan);
6173d2a7ac5dSMat Martineau 		l2cap_seq_list_clear(&chan->retrans_list);
6174d2a7ac5dSMat Martineau 		break;
6175d2a7ac5dSMat Martineau 	case L2CAP_EV_RECV_REJ:
6176d2a7ac5dSMat Martineau 		l2cap_handle_rej(chan, control);
6177d2a7ac5dSMat Martineau 		break;
6178d2a7ac5dSMat Martineau 	case L2CAP_EV_RECV_SREJ:
6179d2a7ac5dSMat Martineau 		l2cap_handle_srej(chan, control);
6180d2a7ac5dSMat Martineau 		break;
6181d2a7ac5dSMat Martineau 	default:
6182d2a7ac5dSMat Martineau 		break;
6183d2a7ac5dSMat Martineau 	}
6184d2a7ac5dSMat Martineau 
6185d2a7ac5dSMat Martineau 	if (skb && !skb_in_use) {
6186d2a7ac5dSMat Martineau 		BT_DBG("Freeing %p", skb);
6187d2a7ac5dSMat Martineau 		kfree_skb(skb);
6188d2a7ac5dSMat Martineau 	}
6189d2a7ac5dSMat Martineau 
6190d2a7ac5dSMat Martineau 	return err;
6191d2a7ac5dSMat Martineau }
6192d2a7ac5dSMat Martineau 
6193d2a7ac5dSMat Martineau static int l2cap_rx_state_srej_sent(struct l2cap_chan *chan,
6194d2a7ac5dSMat Martineau 				    struct l2cap_ctrl *control,
6195d2a7ac5dSMat Martineau 				    struct sk_buff *skb, u8 event)
6196d2a7ac5dSMat Martineau {
6197d2a7ac5dSMat Martineau 	int err = 0;
6198d2a7ac5dSMat Martineau 	u16 txseq = control->txseq;
6199941247f9SPeter Senna Tschudin 	bool skb_in_use = false;
6200d2a7ac5dSMat Martineau 
6201d2a7ac5dSMat Martineau 	BT_DBG("chan %p, control %p, skb %p, event %d", chan, control, skb,
6202d2a7ac5dSMat Martineau 	       event);
6203d2a7ac5dSMat Martineau 
6204d2a7ac5dSMat Martineau 	switch (event) {
6205d2a7ac5dSMat Martineau 	case L2CAP_EV_RECV_IFRAME:
6206d2a7ac5dSMat Martineau 		switch (l2cap_classify_txseq(chan, txseq)) {
6207d2a7ac5dSMat Martineau 		case L2CAP_TXSEQ_EXPECTED:
6208d2a7ac5dSMat Martineau 			/* Keep frame for reassembly later */
6209d2a7ac5dSMat Martineau 			l2cap_pass_to_tx(chan, control);
6210d2a7ac5dSMat Martineau 			skb_queue_tail(&chan->srej_q, skb);
6211941247f9SPeter Senna Tschudin 			skb_in_use = true;
6212d2a7ac5dSMat Martineau 			BT_DBG("Queued %p (queue len %d)", skb,
6213d2a7ac5dSMat Martineau 			       skb_queue_len(&chan->srej_q));
6214d2a7ac5dSMat Martineau 
6215d2a7ac5dSMat Martineau 			chan->expected_tx_seq = __next_seq(chan, txseq);
6216d2a7ac5dSMat Martineau 			break;
6217d2a7ac5dSMat Martineau 		case L2CAP_TXSEQ_EXPECTED_SREJ:
6218d2a7ac5dSMat Martineau 			l2cap_seq_list_pop(&chan->srej_list);
6219d2a7ac5dSMat Martineau 
6220d2a7ac5dSMat Martineau 			l2cap_pass_to_tx(chan, control);
6221d2a7ac5dSMat Martineau 			skb_queue_tail(&chan->srej_q, skb);
6222941247f9SPeter Senna Tschudin 			skb_in_use = true;
6223d2a7ac5dSMat Martineau 			BT_DBG("Queued %p (queue len %d)", skb,
6224d2a7ac5dSMat Martineau 			       skb_queue_len(&chan->srej_q));
6225d2a7ac5dSMat Martineau 
6226d2a7ac5dSMat Martineau 			err = l2cap_rx_queued_iframes(chan);
6227d2a7ac5dSMat Martineau 			if (err)
6228d2a7ac5dSMat Martineau 				break;
6229d2a7ac5dSMat Martineau 
6230d2a7ac5dSMat Martineau 			break;
6231d2a7ac5dSMat Martineau 		case L2CAP_TXSEQ_UNEXPECTED:
6232d2a7ac5dSMat Martineau 			/* Got a frame that can't be reassembled yet.
6233d2a7ac5dSMat Martineau 			 * Save it for later, and send SREJs to cover
6234d2a7ac5dSMat Martineau 			 * the missing frames.
6235d2a7ac5dSMat Martineau 			 */
6236d2a7ac5dSMat Martineau 			skb_queue_tail(&chan->srej_q, skb);
6237941247f9SPeter Senna Tschudin 			skb_in_use = true;
6238d2a7ac5dSMat Martineau 			BT_DBG("Queued %p (queue len %d)", skb,
6239d2a7ac5dSMat Martineau 			       skb_queue_len(&chan->srej_q));
6240d2a7ac5dSMat Martineau 
6241d2a7ac5dSMat Martineau 			l2cap_pass_to_tx(chan, control);
6242d2a7ac5dSMat Martineau 			l2cap_send_srej(chan, control->txseq);
6243d2a7ac5dSMat Martineau 			break;
6244d2a7ac5dSMat Martineau 		case L2CAP_TXSEQ_UNEXPECTED_SREJ:
6245d2a7ac5dSMat Martineau 			/* This frame was requested with an SREJ, but
6246d2a7ac5dSMat Martineau 			 * some expected retransmitted frames are
6247d2a7ac5dSMat Martineau 			 * missing.  Request retransmission of missing
6248d2a7ac5dSMat Martineau 			 * SREJ'd frames.
6249d2a7ac5dSMat Martineau 			 */
6250d2a7ac5dSMat Martineau 			skb_queue_tail(&chan->srej_q, skb);
6251941247f9SPeter Senna Tschudin 			skb_in_use = true;
6252d2a7ac5dSMat Martineau 			BT_DBG("Queued %p (queue len %d)", skb,
6253d2a7ac5dSMat Martineau 			       skb_queue_len(&chan->srej_q));
6254d2a7ac5dSMat Martineau 
6255d2a7ac5dSMat Martineau 			l2cap_pass_to_tx(chan, control);
6256d2a7ac5dSMat Martineau 			l2cap_send_srej_list(chan, control->txseq);
6257d2a7ac5dSMat Martineau 			break;
6258d2a7ac5dSMat Martineau 		case L2CAP_TXSEQ_DUPLICATE_SREJ:
6259d2a7ac5dSMat Martineau 			/* We've already queued this frame.  Drop this copy. */
6260d2a7ac5dSMat Martineau 			l2cap_pass_to_tx(chan, control);
6261d2a7ac5dSMat Martineau 			break;
6262d2a7ac5dSMat Martineau 		case L2CAP_TXSEQ_DUPLICATE:
6263d2a7ac5dSMat Martineau 			/* Expecting a later sequence number, so this frame
6264d2a7ac5dSMat Martineau 			 * was already received.  Ignore it completely.
6265d2a7ac5dSMat Martineau 			 */
6266d2a7ac5dSMat Martineau 			break;
6267d2a7ac5dSMat Martineau 		case L2CAP_TXSEQ_INVALID_IGNORE:
6268d2a7ac5dSMat Martineau 			break;
6269d2a7ac5dSMat Martineau 		case L2CAP_TXSEQ_INVALID:
6270d2a7ac5dSMat Martineau 		default:
62715e4e3972SAndrei Emeltchenko 			l2cap_send_disconn_req(chan, ECONNRESET);
6272d2a7ac5dSMat Martineau 			break;
6273d2a7ac5dSMat Martineau 		}
6274d2a7ac5dSMat Martineau 		break;
6275d2a7ac5dSMat Martineau 	case L2CAP_EV_RECV_RR:
6276d2a7ac5dSMat Martineau 		l2cap_pass_to_tx(chan, control);
6277d2a7ac5dSMat Martineau 		if (control->final) {
6278d2a7ac5dSMat Martineau 			clear_bit(CONN_REMOTE_BUSY, &chan->conn_state);
6279d2a7ac5dSMat Martineau 
6280d2a7ac5dSMat Martineau 			if (!test_and_clear_bit(CONN_REJ_ACT,
6281d2a7ac5dSMat Martineau 						&chan->conn_state)) {
6282d2a7ac5dSMat Martineau 				control->final = 0;
6283d2a7ac5dSMat Martineau 				l2cap_retransmit_all(chan, control);
6284d2a7ac5dSMat Martineau 			}
6285d2a7ac5dSMat Martineau 
6286d2a7ac5dSMat Martineau 			l2cap_ertm_send(chan);
6287d2a7ac5dSMat Martineau 		} else if (control->poll) {
6288d2a7ac5dSMat Martineau 			if (test_and_clear_bit(CONN_REMOTE_BUSY,
6289d2a7ac5dSMat Martineau 					       &chan->conn_state) &&
6290d2a7ac5dSMat Martineau 			    chan->unacked_frames) {
6291d2a7ac5dSMat Martineau 				__set_retrans_timer(chan);
6292d2a7ac5dSMat Martineau 			}
6293d2a7ac5dSMat Martineau 
6294d2a7ac5dSMat Martineau 			set_bit(CONN_SEND_FBIT, &chan->conn_state);
6295d2a7ac5dSMat Martineau 			l2cap_send_srej_tail(chan);
6296d2a7ac5dSMat Martineau 		} else {
6297d2a7ac5dSMat Martineau 			if (test_and_clear_bit(CONN_REMOTE_BUSY,
6298d2a7ac5dSMat Martineau 					       &chan->conn_state) &&
6299d2a7ac5dSMat Martineau 			    chan->unacked_frames)
6300d2a7ac5dSMat Martineau 				__set_retrans_timer(chan);
6301d2a7ac5dSMat Martineau 
6302d2a7ac5dSMat Martineau 			l2cap_send_ack(chan);
6303d2a7ac5dSMat Martineau 		}
6304d2a7ac5dSMat Martineau 		break;
6305d2a7ac5dSMat Martineau 	case L2CAP_EV_RECV_RNR:
6306d2a7ac5dSMat Martineau 		set_bit(CONN_REMOTE_BUSY, &chan->conn_state);
6307d2a7ac5dSMat Martineau 		l2cap_pass_to_tx(chan, control);
6308d2a7ac5dSMat Martineau 		if (control->poll) {
6309d2a7ac5dSMat Martineau 			l2cap_send_srej_tail(chan);
6310d2a7ac5dSMat Martineau 		} else {
6311d2a7ac5dSMat Martineau 			struct l2cap_ctrl rr_control;
6312d2a7ac5dSMat Martineau 			memset(&rr_control, 0, sizeof(rr_control));
6313d2a7ac5dSMat Martineau 			rr_control.sframe = 1;
6314d2a7ac5dSMat Martineau 			rr_control.super = L2CAP_SUPER_RR;
6315d2a7ac5dSMat Martineau 			rr_control.reqseq = chan->buffer_seq;
6316d2a7ac5dSMat Martineau 			l2cap_send_sframe(chan, &rr_control);
6317d2a7ac5dSMat Martineau 		}
6318d2a7ac5dSMat Martineau 
6319d2a7ac5dSMat Martineau 		break;
6320d2a7ac5dSMat Martineau 	case L2CAP_EV_RECV_REJ:
6321d2a7ac5dSMat Martineau 		l2cap_handle_rej(chan, control);
6322d2a7ac5dSMat Martineau 		break;
6323d2a7ac5dSMat Martineau 	case L2CAP_EV_RECV_SREJ:
6324d2a7ac5dSMat Martineau 		l2cap_handle_srej(chan, control);
6325d2a7ac5dSMat Martineau 		break;
6326d2a7ac5dSMat Martineau 	}
6327d2a7ac5dSMat Martineau 
6328d2a7ac5dSMat Martineau 	if (skb && !skb_in_use) {
6329d2a7ac5dSMat Martineau 		BT_DBG("Freeing %p", skb);
6330d2a7ac5dSMat Martineau 		kfree_skb(skb);
6331d2a7ac5dSMat Martineau 	}
6332d2a7ac5dSMat Martineau 
6333d2a7ac5dSMat Martineau 	return err;
6334d2a7ac5dSMat Martineau }
6335d2a7ac5dSMat Martineau 
633632b32735SMat Martineau static int l2cap_finish_move(struct l2cap_chan *chan)
633732b32735SMat Martineau {
633832b32735SMat Martineau 	BT_DBG("chan %p", chan);
633932b32735SMat Martineau 
634032b32735SMat Martineau 	chan->rx_state = L2CAP_RX_STATE_RECV;
634132b32735SMat Martineau 
634232b32735SMat Martineau 	if (chan->hs_hcon)
634332b32735SMat Martineau 		chan->conn->mtu = chan->hs_hcon->hdev->block_mtu;
634432b32735SMat Martineau 	else
634532b32735SMat Martineau 		chan->conn->mtu = chan->conn->hcon->hdev->acl_mtu;
634632b32735SMat Martineau 
634732b32735SMat Martineau 	return l2cap_resegment(chan);
634832b32735SMat Martineau }
634932b32735SMat Martineau 
635032b32735SMat Martineau static int l2cap_rx_state_wait_p(struct l2cap_chan *chan,
635132b32735SMat Martineau 				 struct l2cap_ctrl *control,
635232b32735SMat Martineau 				 struct sk_buff *skb, u8 event)
635332b32735SMat Martineau {
635432b32735SMat Martineau 	int err;
635532b32735SMat Martineau 
635632b32735SMat Martineau 	BT_DBG("chan %p, control %p, skb %p, event %d", chan, control, skb,
635732b32735SMat Martineau 	       event);
635832b32735SMat Martineau 
635932b32735SMat Martineau 	if (!control->poll)
636032b32735SMat Martineau 		return -EPROTO;
636132b32735SMat Martineau 
636232b32735SMat Martineau 	l2cap_process_reqseq(chan, control->reqseq);
636332b32735SMat Martineau 
636432b32735SMat Martineau 	if (!skb_queue_empty(&chan->tx_q))
636532b32735SMat Martineau 		chan->tx_send_head = skb_peek(&chan->tx_q);
636632b32735SMat Martineau 	else
636732b32735SMat Martineau 		chan->tx_send_head = NULL;
636832b32735SMat Martineau 
636932b32735SMat Martineau 	/* Rewind next_tx_seq to the point expected
637032b32735SMat Martineau 	 * by the receiver.
637132b32735SMat Martineau 	 */
637232b32735SMat Martineau 	chan->next_tx_seq = control->reqseq;
637332b32735SMat Martineau 	chan->unacked_frames = 0;
637432b32735SMat Martineau 
637532b32735SMat Martineau 	err = l2cap_finish_move(chan);
637632b32735SMat Martineau 	if (err)
637732b32735SMat Martineau 		return err;
637832b32735SMat Martineau 
637932b32735SMat Martineau 	set_bit(CONN_SEND_FBIT, &chan->conn_state);
638032b32735SMat Martineau 	l2cap_send_i_or_rr_or_rnr(chan);
638132b32735SMat Martineau 
638232b32735SMat Martineau 	if (event == L2CAP_EV_RECV_IFRAME)
638332b32735SMat Martineau 		return -EPROTO;
638432b32735SMat Martineau 
638532b32735SMat Martineau 	return l2cap_rx_state_recv(chan, control, NULL, event);
638632b32735SMat Martineau }
638732b32735SMat Martineau 
638832b32735SMat Martineau static int l2cap_rx_state_wait_f(struct l2cap_chan *chan,
638932b32735SMat Martineau 				 struct l2cap_ctrl *control,
639032b32735SMat Martineau 				 struct sk_buff *skb, u8 event)
639132b32735SMat Martineau {
639232b32735SMat Martineau 	int err;
639332b32735SMat Martineau 
639432b32735SMat Martineau 	if (!control->final)
639532b32735SMat Martineau 		return -EPROTO;
639632b32735SMat Martineau 
639732b32735SMat Martineau 	clear_bit(CONN_REMOTE_BUSY, &chan->conn_state);
639832b32735SMat Martineau 
639932b32735SMat Martineau 	chan->rx_state = L2CAP_RX_STATE_RECV;
640032b32735SMat Martineau 	l2cap_process_reqseq(chan, control->reqseq);
640132b32735SMat Martineau 
640232b32735SMat Martineau 	if (!skb_queue_empty(&chan->tx_q))
640332b32735SMat Martineau 		chan->tx_send_head = skb_peek(&chan->tx_q);
640432b32735SMat Martineau 	else
640532b32735SMat Martineau 		chan->tx_send_head = NULL;
640632b32735SMat Martineau 
640732b32735SMat Martineau 	/* Rewind next_tx_seq to the point expected
640832b32735SMat Martineau 	 * by the receiver.
640932b32735SMat Martineau 	 */
641032b32735SMat Martineau 	chan->next_tx_seq = control->reqseq;
641132b32735SMat Martineau 	chan->unacked_frames = 0;
641232b32735SMat Martineau 
641332b32735SMat Martineau 	if (chan->hs_hcon)
641432b32735SMat Martineau 		chan->conn->mtu = chan->hs_hcon->hdev->block_mtu;
641532b32735SMat Martineau 	else
641632b32735SMat Martineau 		chan->conn->mtu = chan->conn->hcon->hdev->acl_mtu;
641732b32735SMat Martineau 
641832b32735SMat Martineau 	err = l2cap_resegment(chan);
641932b32735SMat Martineau 
642032b32735SMat Martineau 	if (!err)
642132b32735SMat Martineau 		err = l2cap_rx_state_recv(chan, control, skb, event);
642232b32735SMat Martineau 
642332b32735SMat Martineau 	return err;
642432b32735SMat Martineau }
642532b32735SMat Martineau 
6426d2a7ac5dSMat Martineau static bool __valid_reqseq(struct l2cap_chan *chan, u16 reqseq)
6427d2a7ac5dSMat Martineau {
6428d2a7ac5dSMat Martineau 	/* Make sure reqseq is for a packet that has been sent but not acked */
6429d2a7ac5dSMat Martineau 	u16 unacked;
6430d2a7ac5dSMat Martineau 
6431d2a7ac5dSMat Martineau 	unacked = __seq_offset(chan, chan->next_tx_seq, chan->expected_ack_seq);
6432d2a7ac5dSMat Martineau 	return __seq_offset(chan, chan->next_tx_seq, reqseq) <= unacked;
6433d2a7ac5dSMat Martineau }
6434d2a7ac5dSMat Martineau 
6435cec8ab6eSMat Martineau static int l2cap_rx(struct l2cap_chan *chan, struct l2cap_ctrl *control,
6436cec8ab6eSMat Martineau 		    struct sk_buff *skb, u8 event)
64370a708f8fSGustavo F. Padovan {
6438d2a7ac5dSMat Martineau 	int err = 0;
6439d2a7ac5dSMat Martineau 
6440d2a7ac5dSMat Martineau 	BT_DBG("chan %p, control %p, skb %p, event %d, state %d", chan,
6441d2a7ac5dSMat Martineau 	       control, skb, event, chan->rx_state);
6442d2a7ac5dSMat Martineau 
6443d2a7ac5dSMat Martineau 	if (__valid_reqseq(chan, control->reqseq)) {
6444d2a7ac5dSMat Martineau 		switch (chan->rx_state) {
6445d2a7ac5dSMat Martineau 		case L2CAP_RX_STATE_RECV:
6446d2a7ac5dSMat Martineau 			err = l2cap_rx_state_recv(chan, control, skb, event);
6447d2a7ac5dSMat Martineau 			break;
6448d2a7ac5dSMat Martineau 		case L2CAP_RX_STATE_SREJ_SENT:
6449d2a7ac5dSMat Martineau 			err = l2cap_rx_state_srej_sent(chan, control, skb,
6450d2a7ac5dSMat Martineau 						       event);
6451d2a7ac5dSMat Martineau 			break;
645232b32735SMat Martineau 		case L2CAP_RX_STATE_WAIT_P:
645332b32735SMat Martineau 			err = l2cap_rx_state_wait_p(chan, control, skb, event);
645432b32735SMat Martineau 			break;
645532b32735SMat Martineau 		case L2CAP_RX_STATE_WAIT_F:
645632b32735SMat Martineau 			err = l2cap_rx_state_wait_f(chan, control, skb, event);
645732b32735SMat Martineau 			break;
6458d2a7ac5dSMat Martineau 		default:
6459d2a7ac5dSMat Martineau 			/* shut it down */
6460d2a7ac5dSMat Martineau 			break;
6461d2a7ac5dSMat Martineau 		}
6462d2a7ac5dSMat Martineau 	} else {
6463d2a7ac5dSMat Martineau 		BT_DBG("Invalid reqseq %d (next_tx_seq %d, expected_ack_seq %d",
6464d2a7ac5dSMat Martineau 		       control->reqseq, chan->next_tx_seq,
6465d2a7ac5dSMat Martineau 		       chan->expected_ack_seq);
64665e4e3972SAndrei Emeltchenko 		l2cap_send_disconn_req(chan, ECONNRESET);
6467d2a7ac5dSMat Martineau 	}
6468d2a7ac5dSMat Martineau 
6469d2a7ac5dSMat Martineau 	return err;
6470cec8ab6eSMat Martineau }
6471cec8ab6eSMat Martineau 
6472cec8ab6eSMat Martineau static int l2cap_stream_rx(struct l2cap_chan *chan, struct l2cap_ctrl *control,
6473cec8ab6eSMat Martineau 			   struct sk_buff *skb)
6474cec8ab6eSMat Martineau {
64754b51dae9SMat Martineau 	int err = 0;
64764b51dae9SMat Martineau 
64774b51dae9SMat Martineau 	BT_DBG("chan %p, control %p, skb %p, state %d", chan, control, skb,
64784b51dae9SMat Martineau 	       chan->rx_state);
64794b51dae9SMat Martineau 
64804b51dae9SMat Martineau 	if (l2cap_classify_txseq(chan, control->txseq) ==
64814b51dae9SMat Martineau 	    L2CAP_TXSEQ_EXPECTED) {
64824b51dae9SMat Martineau 		l2cap_pass_to_tx(chan, control);
64834b51dae9SMat Martineau 
64844b51dae9SMat Martineau 		BT_DBG("buffer_seq %d->%d", chan->buffer_seq,
64854b51dae9SMat Martineau 		       __next_seq(chan, chan->buffer_seq));
64864b51dae9SMat Martineau 
64874b51dae9SMat Martineau 		chan->buffer_seq = __next_seq(chan, chan->buffer_seq);
64884b51dae9SMat Martineau 
64894b51dae9SMat Martineau 		l2cap_reassemble_sdu(chan, skb, control);
64904b51dae9SMat Martineau 	} else {
64914b51dae9SMat Martineau 		if (chan->sdu) {
64924b51dae9SMat Martineau 			kfree_skb(chan->sdu);
64934b51dae9SMat Martineau 			chan->sdu = NULL;
64944b51dae9SMat Martineau 		}
64954b51dae9SMat Martineau 		chan->sdu_last_frag = NULL;
64964b51dae9SMat Martineau 		chan->sdu_len = 0;
64974b51dae9SMat Martineau 
64984b51dae9SMat Martineau 		if (skb) {
64994b51dae9SMat Martineau 			BT_DBG("Freeing %p", skb);
65004b51dae9SMat Martineau 			kfree_skb(skb);
65014b51dae9SMat Martineau 		}
65024b51dae9SMat Martineau 	}
65034b51dae9SMat Martineau 
65044b51dae9SMat Martineau 	chan->last_acked_seq = control->txseq;
65054b51dae9SMat Martineau 	chan->expected_tx_seq = __next_seq(chan, control->txseq);
65064b51dae9SMat Martineau 
65074b51dae9SMat Martineau 	return err;
6508cec8ab6eSMat Martineau }
6509cec8ab6eSMat Martineau 
6510cec8ab6eSMat Martineau static int l2cap_data_rcv(struct l2cap_chan *chan, struct sk_buff *skb)
6511cec8ab6eSMat Martineau {
6512cec8ab6eSMat Martineau 	struct l2cap_ctrl *control = &bt_cb(skb)->control;
6513cec8ab6eSMat Martineau 	u16 len;
6514cec8ab6eSMat Martineau 	u8 event;
65150a708f8fSGustavo F. Padovan 
6516b76bbd66SMat Martineau 	__unpack_control(chan, skb);
6517b76bbd66SMat Martineau 
65180a708f8fSGustavo F. Padovan 	len = skb->len;
65190a708f8fSGustavo F. Padovan 
65200a708f8fSGustavo F. Padovan 	/*
65210a708f8fSGustavo F. Padovan 	 * We can just drop the corrupted I-frame here.
65220a708f8fSGustavo F. Padovan 	 * Receiver will miss it and start proper recovery
6523cec8ab6eSMat Martineau 	 * procedures and ask for retransmission.
65240a708f8fSGustavo F. Padovan 	 */
652547d1ec61SGustavo F. Padovan 	if (l2cap_check_fcs(chan, skb))
65260a708f8fSGustavo F. Padovan 		goto drop;
65270a708f8fSGustavo F. Padovan 
6528cec8ab6eSMat Martineau 	if (!control->sframe && control->sar == L2CAP_SAR_START)
652903a51213SAndrei Emeltchenko 		len -= L2CAP_SDULEN_SIZE;
65300a708f8fSGustavo F. Padovan 
653147d1ec61SGustavo F. Padovan 	if (chan->fcs == L2CAP_FCS_CRC16)
653203a51213SAndrei Emeltchenko 		len -= L2CAP_FCS_SIZE;
65330a708f8fSGustavo F. Padovan 
653447d1ec61SGustavo F. Padovan 	if (len > chan->mps) {
65355e4e3972SAndrei Emeltchenko 		l2cap_send_disconn_req(chan, ECONNRESET);
65360a708f8fSGustavo F. Padovan 		goto drop;
65370a708f8fSGustavo F. Padovan 	}
65380a708f8fSGustavo F. Padovan 
6539cec8ab6eSMat Martineau 	if (!control->sframe) {
6540cec8ab6eSMat Martineau 		int err;
65410a708f8fSGustavo F. Padovan 
6542cec8ab6eSMat Martineau 		BT_DBG("iframe sar %d, reqseq %d, final %d, txseq %d",
6543cec8ab6eSMat Martineau 		       control->sar, control->reqseq, control->final,
6544cec8ab6eSMat Martineau 		       control->txseq);
6545836be934SAndrei Emeltchenko 
6546cec8ab6eSMat Martineau 		/* Validate F-bit - F=0 always valid, F=1 only
6547cec8ab6eSMat Martineau 		 * valid in TX WAIT_F
6548cec8ab6eSMat Martineau 		 */
6549cec8ab6eSMat Martineau 		if (control->final && chan->tx_state != L2CAP_TX_STATE_WAIT_F)
65500a708f8fSGustavo F. Padovan 			goto drop;
65510a708f8fSGustavo F. Padovan 
6552cec8ab6eSMat Martineau 		if (chan->mode != L2CAP_MODE_STREAMING) {
6553cec8ab6eSMat Martineau 			event = L2CAP_EV_RECV_IFRAME;
6554cec8ab6eSMat Martineau 			err = l2cap_rx(chan, control, skb, event);
65550a708f8fSGustavo F. Padovan 		} else {
6556cec8ab6eSMat Martineau 			err = l2cap_stream_rx(chan, control, skb);
6557cec8ab6eSMat Martineau 		}
6558cec8ab6eSMat Martineau 
6559cec8ab6eSMat Martineau 		if (err)
65605e4e3972SAndrei Emeltchenko 			l2cap_send_disconn_req(chan, ECONNRESET);
6561cec8ab6eSMat Martineau 	} else {
6562cec8ab6eSMat Martineau 		const u8 rx_func_to_event[4] = {
6563cec8ab6eSMat Martineau 			L2CAP_EV_RECV_RR, L2CAP_EV_RECV_REJ,
6564cec8ab6eSMat Martineau 			L2CAP_EV_RECV_RNR, L2CAP_EV_RECV_SREJ
6565cec8ab6eSMat Martineau 		};
6566cec8ab6eSMat Martineau 
6567cec8ab6eSMat Martineau 		/* Only I-frames are expected in streaming mode */
6568cec8ab6eSMat Martineau 		if (chan->mode == L2CAP_MODE_STREAMING)
6569cec8ab6eSMat Martineau 			goto drop;
6570cec8ab6eSMat Martineau 
6571cec8ab6eSMat Martineau 		BT_DBG("sframe reqseq %d, final %d, poll %d, super %d",
6572cec8ab6eSMat Martineau 		       control->reqseq, control->final, control->poll,
6573cec8ab6eSMat Martineau 		       control->super);
6574cec8ab6eSMat Martineau 
65750a708f8fSGustavo F. Padovan 		if (len != 0) {
65761bb166e6SAndrei Emeltchenko 			BT_ERR("Trailing bytes: %d in sframe", len);
65775e4e3972SAndrei Emeltchenko 			l2cap_send_disconn_req(chan, ECONNRESET);
65780a708f8fSGustavo F. Padovan 			goto drop;
65790a708f8fSGustavo F. Padovan 		}
65800a708f8fSGustavo F. Padovan 
6581cec8ab6eSMat Martineau 		/* Validate F and P bits */
6582cec8ab6eSMat Martineau 		if (control->final && (control->poll ||
6583cec8ab6eSMat Martineau 				       chan->tx_state != L2CAP_TX_STATE_WAIT_F))
6584cec8ab6eSMat Martineau 			goto drop;
6585cec8ab6eSMat Martineau 
6586cec8ab6eSMat Martineau 		event = rx_func_to_event[control->super];
6587cec8ab6eSMat Martineau 		if (l2cap_rx(chan, control, skb, event))
65885e4e3972SAndrei Emeltchenko 			l2cap_send_disconn_req(chan, ECONNRESET);
65890a708f8fSGustavo F. Padovan 	}
65900a708f8fSGustavo F. Padovan 
65910a708f8fSGustavo F. Padovan 	return 0;
65920a708f8fSGustavo F. Padovan 
65930a708f8fSGustavo F. Padovan drop:
65940a708f8fSGustavo F. Padovan 	kfree_skb(skb);
65950a708f8fSGustavo F. Padovan 	return 0;
65960a708f8fSGustavo F. Padovan }
65970a708f8fSGustavo F. Padovan 
6598b1c325c2SJohan Hedberg static void l2cap_chan_le_send_credits(struct l2cap_chan *chan)
6599b1c325c2SJohan Hedberg {
6600b1c325c2SJohan Hedberg 	struct l2cap_conn *conn = chan->conn;
6601b1c325c2SJohan Hedberg 	struct l2cap_le_credits pkt;
6602b1c325c2SJohan Hedberg 	u16 return_credits;
6603b1c325c2SJohan Hedberg 
6604b1c325c2SJohan Hedberg 	/* We return more credits to the sender only after the amount of
6605b1c325c2SJohan Hedberg 	 * credits falls below half of the initial amount.
6606b1c325c2SJohan Hedberg 	 */
6607f15b8ecfSJohan Hedberg 	if (chan->rx_credits >= (le_max_credits + 1) / 2)
6608b1c325c2SJohan Hedberg 		return;
6609b1c325c2SJohan Hedberg 
6610f15b8ecfSJohan Hedberg 	return_credits = le_max_credits - chan->rx_credits;
6611b1c325c2SJohan Hedberg 
6612b1c325c2SJohan Hedberg 	BT_DBG("chan %p returning %u credits to sender", chan, return_credits);
6613b1c325c2SJohan Hedberg 
6614b1c325c2SJohan Hedberg 	chan->rx_credits += return_credits;
6615b1c325c2SJohan Hedberg 
6616b1c325c2SJohan Hedberg 	pkt.cid     = cpu_to_le16(chan->scid);
6617b1c325c2SJohan Hedberg 	pkt.credits = cpu_to_le16(return_credits);
6618b1c325c2SJohan Hedberg 
6619b1c325c2SJohan Hedberg 	chan->ident = l2cap_get_ident(conn);
6620b1c325c2SJohan Hedberg 
6621b1c325c2SJohan Hedberg 	l2cap_send_cmd(conn, chan->ident, L2CAP_LE_CREDITS, sizeof(pkt), &pkt);
6622b1c325c2SJohan Hedberg }
6623b1c325c2SJohan Hedberg 
6624fad5fc89SJohan Hedberg static int l2cap_le_data_rcv(struct l2cap_chan *chan, struct sk_buff *skb)
6625fad5fc89SJohan Hedberg {
6626aac23bf6SJohan Hedberg 	int err;
6627fad5fc89SJohan Hedberg 
6628aac23bf6SJohan Hedberg 	if (!chan->rx_credits) {
6629aac23bf6SJohan Hedberg 		BT_ERR("No credits to receive LE L2CAP data");
6630dfd9774cSJohan Hedberg 		l2cap_send_disconn_req(chan, ECONNRESET);
6631fad5fc89SJohan Hedberg 		return -ENOBUFS;
6632aac23bf6SJohan Hedberg 	}
6633aac23bf6SJohan Hedberg 
6634aac23bf6SJohan Hedberg 	if (chan->imtu < skb->len) {
6635aac23bf6SJohan Hedberg 		BT_ERR("Too big LE L2CAP PDU");
6636aac23bf6SJohan Hedberg 		return -ENOBUFS;
6637aac23bf6SJohan Hedberg 	}
6638fad5fc89SJohan Hedberg 
6639fad5fc89SJohan Hedberg 	chan->rx_credits--;
6640fad5fc89SJohan Hedberg 	BT_DBG("rx_credits %u -> %u", chan->rx_credits + 1, chan->rx_credits);
6641fad5fc89SJohan Hedberg 
6642fad5fc89SJohan Hedberg 	l2cap_chan_le_send_credits(chan);
6643fad5fc89SJohan Hedberg 
6644aac23bf6SJohan Hedberg 	err = 0;
6645aac23bf6SJohan Hedberg 
6646aac23bf6SJohan Hedberg 	if (!chan->sdu) {
6647aac23bf6SJohan Hedberg 		u16 sdu_len;
6648aac23bf6SJohan Hedberg 
6649aac23bf6SJohan Hedberg 		sdu_len = get_unaligned_le16(skb->data);
6650aac23bf6SJohan Hedberg 		skb_pull(skb, L2CAP_SDULEN_SIZE);
6651aac23bf6SJohan Hedberg 
6652aac23bf6SJohan Hedberg 		BT_DBG("Start of new SDU. sdu_len %u skb->len %u imtu %u",
6653aac23bf6SJohan Hedberg 		       sdu_len, skb->len, chan->imtu);
6654aac23bf6SJohan Hedberg 
6655aac23bf6SJohan Hedberg 		if (sdu_len > chan->imtu) {
6656aac23bf6SJohan Hedberg 			BT_ERR("Too big LE L2CAP SDU length received");
6657aac23bf6SJohan Hedberg 			err = -EMSGSIZE;
6658aac23bf6SJohan Hedberg 			goto failed;
6659aac23bf6SJohan Hedberg 		}
6660aac23bf6SJohan Hedberg 
6661aac23bf6SJohan Hedberg 		if (skb->len > sdu_len) {
6662aac23bf6SJohan Hedberg 			BT_ERR("Too much LE L2CAP data received");
6663aac23bf6SJohan Hedberg 			err = -EINVAL;
6664aac23bf6SJohan Hedberg 			goto failed;
6665aac23bf6SJohan Hedberg 		}
6666aac23bf6SJohan Hedberg 
6667aac23bf6SJohan Hedberg 		if (skb->len == sdu_len)
6668fad5fc89SJohan Hedberg 			return chan->ops->recv(chan, skb);
6669aac23bf6SJohan Hedberg 
6670aac23bf6SJohan Hedberg 		chan->sdu = skb;
6671aac23bf6SJohan Hedberg 		chan->sdu_len = sdu_len;
6672aac23bf6SJohan Hedberg 		chan->sdu_last_frag = skb;
6673aac23bf6SJohan Hedberg 
6674aac23bf6SJohan Hedberg 		return 0;
6675aac23bf6SJohan Hedberg 	}
6676aac23bf6SJohan Hedberg 
6677aac23bf6SJohan Hedberg 	BT_DBG("SDU fragment. chan->sdu->len %u skb->len %u chan->sdu_len %u",
6678aac23bf6SJohan Hedberg 	       chan->sdu->len, skb->len, chan->sdu_len);
6679aac23bf6SJohan Hedberg 
6680aac23bf6SJohan Hedberg 	if (chan->sdu->len + skb->len > chan->sdu_len) {
6681aac23bf6SJohan Hedberg 		BT_ERR("Too much LE L2CAP data received");
6682aac23bf6SJohan Hedberg 		err = -EINVAL;
6683aac23bf6SJohan Hedberg 		goto failed;
6684aac23bf6SJohan Hedberg 	}
6685aac23bf6SJohan Hedberg 
6686aac23bf6SJohan Hedberg 	append_skb_frag(chan->sdu, skb, &chan->sdu_last_frag);
6687aac23bf6SJohan Hedberg 	skb = NULL;
6688aac23bf6SJohan Hedberg 
6689aac23bf6SJohan Hedberg 	if (chan->sdu->len == chan->sdu_len) {
6690aac23bf6SJohan Hedberg 		err = chan->ops->recv(chan, chan->sdu);
6691aac23bf6SJohan Hedberg 		if (!err) {
6692aac23bf6SJohan Hedberg 			chan->sdu = NULL;
6693aac23bf6SJohan Hedberg 			chan->sdu_last_frag = NULL;
6694aac23bf6SJohan Hedberg 			chan->sdu_len = 0;
6695aac23bf6SJohan Hedberg 		}
6696aac23bf6SJohan Hedberg 	}
6697aac23bf6SJohan Hedberg 
6698aac23bf6SJohan Hedberg failed:
6699aac23bf6SJohan Hedberg 	if (err) {
6700aac23bf6SJohan Hedberg 		kfree_skb(skb);
6701aac23bf6SJohan Hedberg 		kfree_skb(chan->sdu);
6702aac23bf6SJohan Hedberg 		chan->sdu = NULL;
6703aac23bf6SJohan Hedberg 		chan->sdu_last_frag = NULL;
6704aac23bf6SJohan Hedberg 		chan->sdu_len = 0;
6705aac23bf6SJohan Hedberg 	}
6706aac23bf6SJohan Hedberg 
6707aac23bf6SJohan Hedberg 	/* We can't return an error here since we took care of the skb
6708aac23bf6SJohan Hedberg 	 * freeing internally. An error return would cause the caller to
6709aac23bf6SJohan Hedberg 	 * do a double-free of the skb.
6710aac23bf6SJohan Hedberg 	 */
6711aac23bf6SJohan Hedberg 	return 0;
6712fad5fc89SJohan Hedberg }
6713fad5fc89SJohan Hedberg 
671413ca56e0SAndrei Emeltchenko static void l2cap_data_channel(struct l2cap_conn *conn, u16 cid,
671513ca56e0SAndrei Emeltchenko 			       struct sk_buff *skb)
67160a708f8fSGustavo F. Padovan {
671748454079SGustavo F. Padovan 	struct l2cap_chan *chan;
67180a708f8fSGustavo F. Padovan 
6719baa7e1faSGustavo F. Padovan 	chan = l2cap_get_chan_by_scid(conn, cid);
672048454079SGustavo F. Padovan 	if (!chan) {
672197e8e89dSAndrei Emeltchenko 		if (cid == L2CAP_CID_A2MP) {
672297e8e89dSAndrei Emeltchenko 			chan = a2mp_channel_create(conn, skb);
672397e8e89dSAndrei Emeltchenko 			if (!chan) {
672497e8e89dSAndrei Emeltchenko 				kfree_skb(skb);
672513ca56e0SAndrei Emeltchenko 				return;
672697e8e89dSAndrei Emeltchenko 			}
672797e8e89dSAndrei Emeltchenko 
672897e8e89dSAndrei Emeltchenko 			l2cap_chan_lock(chan);
672997e8e89dSAndrei Emeltchenko 		} else {
67300a708f8fSGustavo F. Padovan 			BT_DBG("unknown cid 0x%4.4x", cid);
67316be36555SAndrei Emeltchenko 			/* Drop packet and return */
67323379013bSDan Carpenter 			kfree_skb(skb);
673313ca56e0SAndrei Emeltchenko 			return;
67340a708f8fSGustavo F. Padovan 		}
673597e8e89dSAndrei Emeltchenko 	}
67360a708f8fSGustavo F. Padovan 
673749208c9cSGustavo F. Padovan 	BT_DBG("chan %p, len %d", chan, skb->len);
67380a708f8fSGustavo F. Padovan 
673989bc500eSGustavo F. Padovan 	if (chan->state != BT_CONNECTED)
67400a708f8fSGustavo F. Padovan 		goto drop;
67410a708f8fSGustavo F. Padovan 
67420c1bc5c6SGustavo F. Padovan 	switch (chan->mode) {
674338319713SJohan Hedberg 	case L2CAP_MODE_LE_FLOWCTL:
6744fad5fc89SJohan Hedberg 		if (l2cap_le_data_rcv(chan, skb) < 0)
6745fad5fc89SJohan Hedberg 			goto drop;
6746fad5fc89SJohan Hedberg 
6747fad5fc89SJohan Hedberg 		goto done;
6748fad5fc89SJohan Hedberg 
67490a708f8fSGustavo F. Padovan 	case L2CAP_MODE_BASIC:
67500a708f8fSGustavo F. Padovan 		/* If socket recv buffers overflows we drop data here
67510a708f8fSGustavo F. Padovan 		 * which is *bad* because L2CAP has to be reliable.
67520a708f8fSGustavo F. Padovan 		 * But we don't have any other choice. L2CAP doesn't
67530a708f8fSGustavo F. Padovan 		 * provide flow control mechanism. */
67540a708f8fSGustavo F. Padovan 
67552c96e03dSSzymon Janc 		if (chan->imtu < skb->len) {
67562c96e03dSSzymon Janc 			BT_ERR("Dropping L2CAP data: receive buffer overflow");
67570a708f8fSGustavo F. Padovan 			goto drop;
67582c96e03dSSzymon Janc 		}
67590a708f8fSGustavo F. Padovan 
676080b98027SGustavo Padovan 		if (!chan->ops->recv(chan, skb))
67610a708f8fSGustavo F. Padovan 			goto done;
67620a708f8fSGustavo F. Padovan 		break;
67630a708f8fSGustavo F. Padovan 
67640a708f8fSGustavo F. Padovan 	case L2CAP_MODE_ERTM:
67650a708f8fSGustavo F. Padovan 	case L2CAP_MODE_STREAMING:
6766cec8ab6eSMat Martineau 		l2cap_data_rcv(chan, skb);
67670a708f8fSGustavo F. Padovan 		goto done;
67680a708f8fSGustavo F. Padovan 
67690a708f8fSGustavo F. Padovan 	default:
67700c1bc5c6SGustavo F. Padovan 		BT_DBG("chan %p: bad mode 0x%2.2x", chan, chan->mode);
67710a708f8fSGustavo F. Padovan 		break;
67720a708f8fSGustavo F. Padovan 	}
67730a708f8fSGustavo F. Padovan 
67740a708f8fSGustavo F. Padovan drop:
67750a708f8fSGustavo F. Padovan 	kfree_skb(skb);
67760a708f8fSGustavo F. Padovan 
67770a708f8fSGustavo F. Padovan done:
67786be36555SAndrei Emeltchenko 	l2cap_chan_unlock(chan);
67790a708f8fSGustavo F. Padovan }
67800a708f8fSGustavo F. Padovan 
678184104b24SAndrei Emeltchenko static void l2cap_conless_channel(struct l2cap_conn *conn, __le16 psm,
678284104b24SAndrei Emeltchenko 				  struct sk_buff *skb)
67830a708f8fSGustavo F. Padovan {
6784ae4fd2d3SMarcel Holtmann 	struct hci_conn *hcon = conn->hcon;
678523691d75SGustavo F. Padovan 	struct l2cap_chan *chan;
67860a708f8fSGustavo F. Padovan 
6787ae4fd2d3SMarcel Holtmann 	if (hcon->type != ACL_LINK)
6788a24cce14SJohan Hedberg 		goto free_skb;
6789ae4fd2d3SMarcel Holtmann 
6790bf20fd4eSJohan Hedberg 	chan = l2cap_global_chan_by_psm(0, psm, &hcon->src, &hcon->dst,
6791bf20fd4eSJohan Hedberg 					ACL_LINK);
679223691d75SGustavo F. Padovan 	if (!chan)
6793a24cce14SJohan Hedberg 		goto free_skb;
67940a708f8fSGustavo F. Padovan 
67955b4cedaaSAndrei Emeltchenko 	BT_DBG("chan %p, len %d", chan, skb->len);
67960a708f8fSGustavo F. Padovan 
679789bc500eSGustavo F. Padovan 	if (chan->state != BT_BOUND && chan->state != BT_CONNECTED)
67980a708f8fSGustavo F. Padovan 		goto drop;
67990a708f8fSGustavo F. Padovan 
6800e13e21dcSVinicius Costa Gomes 	if (chan->imtu < skb->len)
68010a708f8fSGustavo F. Padovan 		goto drop;
68020a708f8fSGustavo F. Padovan 
68032edf870dSMarcel Holtmann 	/* Store remote BD_ADDR and PSM for msg_name */
680406ae3314SMarcel Holtmann 	bacpy(&bt_cb(skb)->bdaddr, &hcon->dst);
68052edf870dSMarcel Holtmann 	bt_cb(skb)->psm = psm;
68062edf870dSMarcel Holtmann 
6807a24cce14SJohan Hedberg 	if (!chan->ops->recv(chan, skb)) {
6808a24cce14SJohan Hedberg 		l2cap_chan_put(chan);
680984104b24SAndrei Emeltchenko 		return;
6810a24cce14SJohan Hedberg 	}
68110a708f8fSGustavo F. Padovan 
68120a708f8fSGustavo F. Padovan drop:
6813a24cce14SJohan Hedberg 	l2cap_chan_put(chan);
6814a24cce14SJohan Hedberg free_skb:
68150a708f8fSGustavo F. Padovan 	kfree_skb(skb);
68160a708f8fSGustavo F. Padovan }
68170a708f8fSGustavo F. Padovan 
68180a708f8fSGustavo F. Padovan static void l2cap_recv_frame(struct l2cap_conn *conn, struct sk_buff *skb)
68190a708f8fSGustavo F. Padovan {
68200a708f8fSGustavo F. Padovan 	struct l2cap_hdr *lh = (void *) skb->data;
682161a939c6SJohan Hedberg 	struct hci_conn *hcon = conn->hcon;
68220a708f8fSGustavo F. Padovan 	u16 cid, len;
68230a708f8fSGustavo F. Padovan 	__le16 psm;
68240a708f8fSGustavo F. Padovan 
682561a939c6SJohan Hedberg 	if (hcon->state != BT_CONNECTED) {
682661a939c6SJohan Hedberg 		BT_DBG("queueing pending rx skb");
682761a939c6SJohan Hedberg 		skb_queue_tail(&conn->pending_rx, skb);
682861a939c6SJohan Hedberg 		return;
682961a939c6SJohan Hedberg 	}
683061a939c6SJohan Hedberg 
68310a708f8fSGustavo F. Padovan 	skb_pull(skb, L2CAP_HDR_SIZE);
68320a708f8fSGustavo F. Padovan 	cid = __le16_to_cpu(lh->cid);
68330a708f8fSGustavo F. Padovan 	len = __le16_to_cpu(lh->len);
68340a708f8fSGustavo F. Padovan 
68350a708f8fSGustavo F. Padovan 	if (len != skb->len) {
68360a708f8fSGustavo F. Padovan 		kfree_skb(skb);
68370a708f8fSGustavo F. Padovan 		return;
68380a708f8fSGustavo F. Padovan 	}
68390a708f8fSGustavo F. Padovan 
68409e1d7e15SJohan Hedberg 	/* Since we can't actively block incoming LE connections we must
68419e1d7e15SJohan Hedberg 	 * at least ensure that we ignore incoming data from them.
68429e1d7e15SJohan Hedberg 	 */
68439e1d7e15SJohan Hedberg 	if (hcon->type == LE_LINK &&
6844dcc36c16SJohan Hedberg 	    hci_bdaddr_list_lookup(&hcon->hdev->blacklist, &hcon->dst,
6845e493150eSJohan Hedberg 				   bdaddr_type(hcon, hcon->dst_type))) {
6846e493150eSJohan Hedberg 		kfree_skb(skb);
6847e493150eSJohan Hedberg 		return;
6848e493150eSJohan Hedberg 	}
6849e493150eSJohan Hedberg 
68500a708f8fSGustavo F. Padovan 	BT_DBG("len %d, cid 0x%4.4x", len, cid);
68510a708f8fSGustavo F. Padovan 
68520a708f8fSGustavo F. Padovan 	switch (cid) {
68530a708f8fSGustavo F. Padovan 	case L2CAP_CID_SIGNALING:
68540a708f8fSGustavo F. Padovan 		l2cap_sig_channel(conn, skb);
68550a708f8fSGustavo F. Padovan 		break;
68560a708f8fSGustavo F. Padovan 
68570a708f8fSGustavo F. Padovan 	case L2CAP_CID_CONN_LESS:
6858097db76cSAndrei Emeltchenko 		psm = get_unaligned((__le16 *) skb->data);
68590181a70fSAndrei Emeltchenko 		skb_pull(skb, L2CAP_PSMLEN_SIZE);
68600a708f8fSGustavo F. Padovan 		l2cap_conless_channel(conn, psm, skb);
68610a708f8fSGustavo F. Padovan 		break;
68620a708f8fSGustavo F. Padovan 
6863a2877629SMarcel Holtmann 	case L2CAP_CID_LE_SIGNALING:
6864a2877629SMarcel Holtmann 		l2cap_le_sig_channel(conn, skb);
6865a2877629SMarcel Holtmann 		break;
6866a2877629SMarcel Holtmann 
68670a708f8fSGustavo F. Padovan 	default:
68680a708f8fSGustavo F. Padovan 		l2cap_data_channel(conn, cid, skb);
68690a708f8fSGustavo F. Padovan 		break;
68700a708f8fSGustavo F. Padovan 	}
68710a708f8fSGustavo F. Padovan }
68720a708f8fSGustavo F. Padovan 
687361a939c6SJohan Hedberg static void process_pending_rx(struct work_struct *work)
687461a939c6SJohan Hedberg {
687561a939c6SJohan Hedberg 	struct l2cap_conn *conn = container_of(work, struct l2cap_conn,
687661a939c6SJohan Hedberg 					       pending_rx_work);
687761a939c6SJohan Hedberg 	struct sk_buff *skb;
687861a939c6SJohan Hedberg 
687961a939c6SJohan Hedberg 	BT_DBG("");
688061a939c6SJohan Hedberg 
688161a939c6SJohan Hedberg 	while ((skb = skb_dequeue(&conn->pending_rx)))
688261a939c6SJohan Hedberg 		l2cap_recv_frame(conn, skb);
688361a939c6SJohan Hedberg }
688461a939c6SJohan Hedberg 
6885162b49e7SJohan Hedberg static struct l2cap_conn *l2cap_conn_add(struct hci_conn *hcon)
6886162b49e7SJohan Hedberg {
6887162b49e7SJohan Hedberg 	struct l2cap_conn *conn = hcon->l2cap_data;
6888162b49e7SJohan Hedberg 	struct hci_chan *hchan;
6889162b49e7SJohan Hedberg 
6890162b49e7SJohan Hedberg 	if (conn)
6891162b49e7SJohan Hedberg 		return conn;
6892162b49e7SJohan Hedberg 
6893162b49e7SJohan Hedberg 	hchan = hci_chan_create(hcon);
6894162b49e7SJohan Hedberg 	if (!hchan)
6895162b49e7SJohan Hedberg 		return NULL;
6896162b49e7SJohan Hedberg 
689727f70f3eSJohan Hedberg 	conn = kzalloc(sizeof(*conn), GFP_KERNEL);
6898162b49e7SJohan Hedberg 	if (!conn) {
6899162b49e7SJohan Hedberg 		hci_chan_del(hchan);
6900162b49e7SJohan Hedberg 		return NULL;
6901162b49e7SJohan Hedberg 	}
6902162b49e7SJohan Hedberg 
6903162b49e7SJohan Hedberg 	kref_init(&conn->ref);
6904162b49e7SJohan Hedberg 	hcon->l2cap_data = conn;
6905162b49e7SJohan Hedberg 	conn->hcon = hcon;
6906162b49e7SJohan Hedberg 	hci_conn_get(conn->hcon);
6907162b49e7SJohan Hedberg 	conn->hchan = hchan;
6908162b49e7SJohan Hedberg 
6909162b49e7SJohan Hedberg 	BT_DBG("hcon %p conn %p hchan %p", hcon, conn, hchan);
6910162b49e7SJohan Hedberg 
6911162b49e7SJohan Hedberg 	switch (hcon->type) {
6912162b49e7SJohan Hedberg 	case LE_LINK:
6913162b49e7SJohan Hedberg 		if (hcon->hdev->le_mtu) {
6914162b49e7SJohan Hedberg 			conn->mtu = hcon->hdev->le_mtu;
6915162b49e7SJohan Hedberg 			break;
6916162b49e7SJohan Hedberg 		}
6917162b49e7SJohan Hedberg 		/* fall through */
6918162b49e7SJohan Hedberg 	default:
6919162b49e7SJohan Hedberg 		conn->mtu = hcon->hdev->acl_mtu;
6920162b49e7SJohan Hedberg 		break;
6921162b49e7SJohan Hedberg 	}
6922162b49e7SJohan Hedberg 
6923162b49e7SJohan Hedberg 	conn->feat_mask = 0;
6924162b49e7SJohan Hedberg 
6925162b49e7SJohan Hedberg 	if (hcon->type == ACL_LINK)
6926162b49e7SJohan Hedberg 		conn->hs_enabled = test_bit(HCI_HS_ENABLED,
6927162b49e7SJohan Hedberg 					    &hcon->hdev->dev_flags);
6928162b49e7SJohan Hedberg 
69295a54e7c8SMarcel Holtmann 	mutex_init(&conn->ident_lock);
6930162b49e7SJohan Hedberg 	mutex_init(&conn->chan_lock);
6931162b49e7SJohan Hedberg 
6932162b49e7SJohan Hedberg 	INIT_LIST_HEAD(&conn->chan_l);
6933162b49e7SJohan Hedberg 	INIT_LIST_HEAD(&conn->users);
6934162b49e7SJohan Hedberg 
6935162b49e7SJohan Hedberg 	INIT_DELAYED_WORK(&conn->info_timer, l2cap_info_timeout);
6936162b49e7SJohan Hedberg 
6937dec5b492SJohan Hedberg 	INIT_WORK(&conn->disconn_work, disconn_work);
6938dec5b492SJohan Hedberg 
693961a939c6SJohan Hedberg 	skb_queue_head_init(&conn->pending_rx);
694061a939c6SJohan Hedberg 	INIT_WORK(&conn->pending_rx_work, process_pending_rx);
694161a939c6SJohan Hedberg 
6942162b49e7SJohan Hedberg 	conn->disc_reason = HCI_ERROR_REMOTE_USER_TERM;
6943162b49e7SJohan Hedberg 
6944162b49e7SJohan Hedberg 	return conn;
6945162b49e7SJohan Hedberg }
6946162b49e7SJohan Hedberg 
6947162b49e7SJohan Hedberg static bool is_valid_psm(u16 psm, u8 dst_type) {
6948162b49e7SJohan Hedberg 	if (!psm)
6949162b49e7SJohan Hedberg 		return false;
6950162b49e7SJohan Hedberg 
6951162b49e7SJohan Hedberg 	if (bdaddr_type_is_le(dst_type))
6952162b49e7SJohan Hedberg 		return (psm <= 0x00ff);
6953162b49e7SJohan Hedberg 
6954162b49e7SJohan Hedberg 	/* PSM must be odd and lsb of upper byte must be 0 */
6955162b49e7SJohan Hedberg 	return ((psm & 0x0101) == 0x0001);
6956162b49e7SJohan Hedberg }
6957162b49e7SJohan Hedberg 
6958162b49e7SJohan Hedberg int l2cap_chan_connect(struct l2cap_chan *chan, __le16 psm, u16 cid,
6959162b49e7SJohan Hedberg 		       bdaddr_t *dst, u8 dst_type)
6960162b49e7SJohan Hedberg {
6961162b49e7SJohan Hedberg 	struct l2cap_conn *conn;
6962162b49e7SJohan Hedberg 	struct hci_conn *hcon;
6963162b49e7SJohan Hedberg 	struct hci_dev *hdev;
6964162b49e7SJohan Hedberg 	int err;
6965162b49e7SJohan Hedberg 
6966162b49e7SJohan Hedberg 	BT_DBG("%pMR -> %pMR (type %u) psm 0x%2.2x", &chan->src, dst,
6967162b49e7SJohan Hedberg 	       dst_type, __le16_to_cpu(psm));
6968162b49e7SJohan Hedberg 
6969162b49e7SJohan Hedberg 	hdev = hci_get_route(dst, &chan->src);
6970162b49e7SJohan Hedberg 	if (!hdev)
6971162b49e7SJohan Hedberg 		return -EHOSTUNREACH;
6972162b49e7SJohan Hedberg 
6973162b49e7SJohan Hedberg 	hci_dev_lock(hdev);
6974162b49e7SJohan Hedberg 
6975162b49e7SJohan Hedberg 	l2cap_chan_lock(chan);
6976162b49e7SJohan Hedberg 
6977162b49e7SJohan Hedberg 	if (!is_valid_psm(__le16_to_cpu(psm), dst_type) && !cid &&
6978162b49e7SJohan Hedberg 	    chan->chan_type != L2CAP_CHAN_RAW) {
6979162b49e7SJohan Hedberg 		err = -EINVAL;
6980162b49e7SJohan Hedberg 		goto done;
6981162b49e7SJohan Hedberg 	}
6982162b49e7SJohan Hedberg 
698321626e62SJohan Hedberg 	if (chan->chan_type == L2CAP_CHAN_CONN_ORIENTED && !psm) {
698421626e62SJohan Hedberg 		err = -EINVAL;
698521626e62SJohan Hedberg 		goto done;
698621626e62SJohan Hedberg 	}
698721626e62SJohan Hedberg 
698821626e62SJohan Hedberg 	if (chan->chan_type == L2CAP_CHAN_FIXED && !cid) {
6989162b49e7SJohan Hedberg 		err = -EINVAL;
6990162b49e7SJohan Hedberg 		goto done;
6991162b49e7SJohan Hedberg 	}
6992162b49e7SJohan Hedberg 
6993162b49e7SJohan Hedberg 	switch (chan->mode) {
6994162b49e7SJohan Hedberg 	case L2CAP_MODE_BASIC:
6995162b49e7SJohan Hedberg 		break;
6996162b49e7SJohan Hedberg 	case L2CAP_MODE_LE_FLOWCTL:
6997162b49e7SJohan Hedberg 		l2cap_le_flowctl_init(chan);
6998162b49e7SJohan Hedberg 		break;
6999162b49e7SJohan Hedberg 	case L2CAP_MODE_ERTM:
7000162b49e7SJohan Hedberg 	case L2CAP_MODE_STREAMING:
7001162b49e7SJohan Hedberg 		if (!disable_ertm)
7002162b49e7SJohan Hedberg 			break;
7003162b49e7SJohan Hedberg 		/* fall through */
7004162b49e7SJohan Hedberg 	default:
7005beb19e4cSJohan Hedberg 		err = -EOPNOTSUPP;
7006162b49e7SJohan Hedberg 		goto done;
7007162b49e7SJohan Hedberg 	}
7008162b49e7SJohan Hedberg 
7009162b49e7SJohan Hedberg 	switch (chan->state) {
7010162b49e7SJohan Hedberg 	case BT_CONNECT:
7011162b49e7SJohan Hedberg 	case BT_CONNECT2:
7012162b49e7SJohan Hedberg 	case BT_CONFIG:
7013162b49e7SJohan Hedberg 		/* Already connecting */
7014162b49e7SJohan Hedberg 		err = 0;
7015162b49e7SJohan Hedberg 		goto done;
7016162b49e7SJohan Hedberg 
7017162b49e7SJohan Hedberg 	case BT_CONNECTED:
7018162b49e7SJohan Hedberg 		/* Already connected */
7019162b49e7SJohan Hedberg 		err = -EISCONN;
7020162b49e7SJohan Hedberg 		goto done;
7021162b49e7SJohan Hedberg 
7022162b49e7SJohan Hedberg 	case BT_OPEN:
7023162b49e7SJohan Hedberg 	case BT_BOUND:
7024162b49e7SJohan Hedberg 		/* Can connect */
7025162b49e7SJohan Hedberg 		break;
7026162b49e7SJohan Hedberg 
7027162b49e7SJohan Hedberg 	default:
7028162b49e7SJohan Hedberg 		err = -EBADFD;
7029162b49e7SJohan Hedberg 		goto done;
7030162b49e7SJohan Hedberg 	}
7031162b49e7SJohan Hedberg 
7032162b49e7SJohan Hedberg 	/* Set destination address and psm */
7033162b49e7SJohan Hedberg 	bacpy(&chan->dst, dst);
7034162b49e7SJohan Hedberg 	chan->dst_type = dst_type;
7035162b49e7SJohan Hedberg 
7036162b49e7SJohan Hedberg 	chan->psm = psm;
7037162b49e7SJohan Hedberg 	chan->dcid = cid;
7038162b49e7SJohan Hedberg 
70396f77d8c7SAndre Guedes 	if (bdaddr_type_is_le(dst_type)) {
7040e804d25dSJohan Hedberg 		u8 role;
7041cdd6275eSJohan Hedberg 
70426f77d8c7SAndre Guedes 		/* Convert from L2CAP channel address type to HCI address type
70436f77d8c7SAndre Guedes 		 */
70446f77d8c7SAndre Guedes 		if (dst_type == BDADDR_LE_PUBLIC)
70456f77d8c7SAndre Guedes 			dst_type = ADDR_LE_DEV_PUBLIC;
70466f77d8c7SAndre Guedes 		else
70476f77d8c7SAndre Guedes 			dst_type = ADDR_LE_DEV_RANDOM;
70486f77d8c7SAndre Guedes 
7049e804d25dSJohan Hedberg 		if (test_bit(HCI_ADVERTISING, &hdev->dev_flags))
7050e804d25dSJohan Hedberg 			role = HCI_ROLE_SLAVE;
7051e804d25dSJohan Hedberg 		else
7052e804d25dSJohan Hedberg 			role = HCI_ROLE_MASTER;
7053cdd6275eSJohan Hedberg 
705404a6c589SAndre Guedes 		hcon = hci_connect_le(hdev, dst, dst_type, chan->sec_level,
7055e804d25dSJohan Hedberg 				      HCI_LE_CONN_TIMEOUT, role);
70566f77d8c7SAndre Guedes 	} else {
7057d93375a8SJohan Hedberg 		u8 auth_type = l2cap_get_auth_type(chan);
705804a6c589SAndre Guedes 		hcon = hci_connect_acl(hdev, dst, chan->sec_level, auth_type);
70596f77d8c7SAndre Guedes 	}
7060162b49e7SJohan Hedberg 
7061162b49e7SJohan Hedberg 	if (IS_ERR(hcon)) {
7062162b49e7SJohan Hedberg 		err = PTR_ERR(hcon);
7063162b49e7SJohan Hedberg 		goto done;
7064162b49e7SJohan Hedberg 	}
7065162b49e7SJohan Hedberg 
7066162b49e7SJohan Hedberg 	conn = l2cap_conn_add(hcon);
7067162b49e7SJohan Hedberg 	if (!conn) {
7068162b49e7SJohan Hedberg 		hci_conn_drop(hcon);
7069162b49e7SJohan Hedberg 		err = -ENOMEM;
7070162b49e7SJohan Hedberg 		goto done;
7071162b49e7SJohan Hedberg 	}
7072162b49e7SJohan Hedberg 
7073162b49e7SJohan Hedberg 	if (cid && __l2cap_get_chan_by_dcid(conn, cid)) {
7074162b49e7SJohan Hedberg 		hci_conn_drop(hcon);
7075162b49e7SJohan Hedberg 		err = -EBUSY;
7076162b49e7SJohan Hedberg 		goto done;
7077162b49e7SJohan Hedberg 	}
7078162b49e7SJohan Hedberg 
7079162b49e7SJohan Hedberg 	/* Update source addr of the socket */
7080162b49e7SJohan Hedberg 	bacpy(&chan->src, &hcon->src);
7081162b49e7SJohan Hedberg 	chan->src_type = bdaddr_type(hcon, hcon->src_type);
7082162b49e7SJohan Hedberg 
7083162b49e7SJohan Hedberg 	l2cap_chan_unlock(chan);
7084162b49e7SJohan Hedberg 	l2cap_chan_add(conn, chan);
7085162b49e7SJohan Hedberg 	l2cap_chan_lock(chan);
7086162b49e7SJohan Hedberg 
7087162b49e7SJohan Hedberg 	/* l2cap_chan_add takes its own ref so we can drop this one */
7088162b49e7SJohan Hedberg 	hci_conn_drop(hcon);
7089162b49e7SJohan Hedberg 
7090162b49e7SJohan Hedberg 	l2cap_state_change(chan, BT_CONNECT);
7091162b49e7SJohan Hedberg 	__set_chan_timer(chan, chan->ops->get_sndtimeo(chan));
7092162b49e7SJohan Hedberg 
709361202e4dSJohan Hedberg 	/* Release chan->sport so that it can be reused by other
709461202e4dSJohan Hedberg 	 * sockets (as it's only used for listening sockets).
709561202e4dSJohan Hedberg 	 */
709661202e4dSJohan Hedberg 	write_lock(&chan_list_lock);
709761202e4dSJohan Hedberg 	chan->sport = 0;
709861202e4dSJohan Hedberg 	write_unlock(&chan_list_lock);
709961202e4dSJohan Hedberg 
7100162b49e7SJohan Hedberg 	if (hcon->state == BT_CONNECTED) {
7101162b49e7SJohan Hedberg 		if (chan->chan_type != L2CAP_CHAN_CONN_ORIENTED) {
7102162b49e7SJohan Hedberg 			__clear_chan_timer(chan);
7103e7cafc45SJohan Hedberg 			if (l2cap_chan_check_security(chan, true))
7104162b49e7SJohan Hedberg 				l2cap_state_change(chan, BT_CONNECTED);
7105162b49e7SJohan Hedberg 		} else
7106162b49e7SJohan Hedberg 			l2cap_do_start(chan);
7107162b49e7SJohan Hedberg 	}
7108162b49e7SJohan Hedberg 
7109162b49e7SJohan Hedberg 	err = 0;
7110162b49e7SJohan Hedberg 
7111162b49e7SJohan Hedberg done:
7112162b49e7SJohan Hedberg 	l2cap_chan_unlock(chan);
7113162b49e7SJohan Hedberg 	hci_dev_unlock(hdev);
7114162b49e7SJohan Hedberg 	hci_dev_put(hdev);
7115162b49e7SJohan Hedberg 	return err;
7116162b49e7SJohan Hedberg }
71176b8d4a6aSJukka Rissanen EXPORT_SYMBOL_GPL(l2cap_chan_connect);
7118162b49e7SJohan Hedberg 
71190a708f8fSGustavo F. Padovan /* ---- L2CAP interface with lower layer (HCI) ---- */
71200a708f8fSGustavo F. Padovan 
7121686ebf28SUlisses Furquim int l2cap_connect_ind(struct hci_dev *hdev, bdaddr_t *bdaddr)
71220a708f8fSGustavo F. Padovan {
71230a708f8fSGustavo F. Padovan 	int exact = 0, lm1 = 0, lm2 = 0;
712423691d75SGustavo F. Padovan 	struct l2cap_chan *c;
71250a708f8fSGustavo F. Padovan 
71266ed93dc6SAndrei Emeltchenko 	BT_DBG("hdev %s, bdaddr %pMR", hdev->name, bdaddr);
71270a708f8fSGustavo F. Padovan 
71280a708f8fSGustavo F. Padovan 	/* Find listening sockets and check their link_mode */
712923691d75SGustavo F. Padovan 	read_lock(&chan_list_lock);
713023691d75SGustavo F. Padovan 	list_for_each_entry(c, &chan_list, global_l) {
713189bc500eSGustavo F. Padovan 		if (c->state != BT_LISTEN)
71320a708f8fSGustavo F. Padovan 			continue;
71330a708f8fSGustavo F. Padovan 
71347eafc59eSMarcel Holtmann 		if (!bacmp(&c->src, &hdev->bdaddr)) {
71350a708f8fSGustavo F. Padovan 			lm1 |= HCI_LM_ACCEPT;
713643bd0f32SAndrei Emeltchenko 			if (test_bit(FLAG_ROLE_SWITCH, &c->flags))
71370a708f8fSGustavo F. Padovan 				lm1 |= HCI_LM_MASTER;
71380a708f8fSGustavo F. Padovan 			exact++;
71397eafc59eSMarcel Holtmann 		} else if (!bacmp(&c->src, BDADDR_ANY)) {
71400a708f8fSGustavo F. Padovan 			lm2 |= HCI_LM_ACCEPT;
714143bd0f32SAndrei Emeltchenko 			if (test_bit(FLAG_ROLE_SWITCH, &c->flags))
71420a708f8fSGustavo F. Padovan 				lm2 |= HCI_LM_MASTER;
71430a708f8fSGustavo F. Padovan 		}
71440a708f8fSGustavo F. Padovan 	}
714523691d75SGustavo F. Padovan 	read_unlock(&chan_list_lock);
71460a708f8fSGustavo F. Padovan 
71470a708f8fSGustavo F. Padovan 	return exact ? lm1 : lm2;
71480a708f8fSGustavo F. Padovan }
71490a708f8fSGustavo F. Padovan 
7150e760ec12SJohan Hedberg /* Find the next fixed channel in BT_LISTEN state, continue iteration
7151e760ec12SJohan Hedberg  * from an existing channel in the list or from the beginning of the
7152e760ec12SJohan Hedberg  * global list (by passing NULL as first parameter).
7153e760ec12SJohan Hedberg  */
7154e760ec12SJohan Hedberg static struct l2cap_chan *l2cap_global_fixed_chan(struct l2cap_chan *c,
715554a1b626SJohan Hedberg 						  bdaddr_t *src, u8 link_type)
7156e760ec12SJohan Hedberg {
7157e760ec12SJohan Hedberg 	read_lock(&chan_list_lock);
7158e760ec12SJohan Hedberg 
7159e760ec12SJohan Hedberg 	if (c)
7160e760ec12SJohan Hedberg 		c = list_next_entry(c, global_l);
7161e760ec12SJohan Hedberg 	else
7162e760ec12SJohan Hedberg 		c = list_entry(chan_list.next, typeof(*c), global_l);
7163e760ec12SJohan Hedberg 
7164e760ec12SJohan Hedberg 	list_for_each_entry_from(c, &chan_list, global_l) {
7165e760ec12SJohan Hedberg 		if (c->chan_type != L2CAP_CHAN_FIXED)
7166e760ec12SJohan Hedberg 			continue;
7167e760ec12SJohan Hedberg 		if (c->state != BT_LISTEN)
7168e760ec12SJohan Hedberg 			continue;
7169e760ec12SJohan Hedberg 		if (bacmp(&c->src, src) && bacmp(&c->src, BDADDR_ANY))
7170e760ec12SJohan Hedberg 			continue;
717154a1b626SJohan Hedberg 		if (link_type == ACL_LINK && c->src_type != BDADDR_BREDR)
717254a1b626SJohan Hedberg 			continue;
717354a1b626SJohan Hedberg 		if (link_type == LE_LINK && c->src_type == BDADDR_BREDR)
717454a1b626SJohan Hedberg 			continue;
7175e760ec12SJohan Hedberg 
7176e760ec12SJohan Hedberg 		l2cap_chan_hold(c);
7177e760ec12SJohan Hedberg 		read_unlock(&chan_list_lock);
7178e760ec12SJohan Hedberg 		return c;
7179e760ec12SJohan Hedberg 	}
7180e760ec12SJohan Hedberg 
7181e760ec12SJohan Hedberg 	read_unlock(&chan_list_lock);
7182e760ec12SJohan Hedberg 
7183e760ec12SJohan Hedberg 	return NULL;
7184e760ec12SJohan Hedberg }
7185e760ec12SJohan Hedberg 
71869e664631SAndrei Emeltchenko void l2cap_connect_cfm(struct hci_conn *hcon, u8 status)
71870a708f8fSGustavo F. Padovan {
7188e760ec12SJohan Hedberg 	struct hci_dev *hdev = hcon->hdev;
71890a708f8fSGustavo F. Padovan 	struct l2cap_conn *conn;
7190e760ec12SJohan Hedberg 	struct l2cap_chan *pchan;
7191e760ec12SJohan Hedberg 	u8 dst_type;
71920a708f8fSGustavo F. Padovan 
71936ed93dc6SAndrei Emeltchenko 	BT_DBG("hcon %p bdaddr %pMR status %d", hcon, &hcon->dst, status);
71940a708f8fSGustavo F. Padovan 
7195dc0f5088SJohan Hedberg 	if (status) {
7196e175072fSJoe Perches 		l2cap_conn_del(hcon, bt_to_errno(status));
7197dc0f5088SJohan Hedberg 		return;
7198ba6fc317SAndrei Emeltchenko 	}
7199dc0f5088SJohan Hedberg 
7200dc0f5088SJohan Hedberg 	conn = l2cap_conn_add(hcon);
7201dc0f5088SJohan Hedberg 	if (!conn)
7202dc0f5088SJohan Hedberg 		return;
7203dc0f5088SJohan Hedberg 
7204e760ec12SJohan Hedberg 	dst_type = bdaddr_type(hcon, hcon->dst_type);
7205e760ec12SJohan Hedberg 
7206e760ec12SJohan Hedberg 	/* If device is blocked, do not create channels for it */
7207e760ec12SJohan Hedberg 	if (hci_bdaddr_list_lookup(&hdev->blacklist, &hcon->dst, dst_type))
7208e760ec12SJohan Hedberg 		return;
7209e760ec12SJohan Hedberg 
7210e760ec12SJohan Hedberg 	/* Find fixed channels and notify them of the new connection. We
7211e760ec12SJohan Hedberg 	 * use multiple individual lookups, continuing each time where
7212e760ec12SJohan Hedberg 	 * we left off, because the list lock would prevent calling the
7213e760ec12SJohan Hedberg 	 * potentially sleeping l2cap_chan_lock() function.
7214e760ec12SJohan Hedberg 	 */
721554a1b626SJohan Hedberg 	pchan = l2cap_global_fixed_chan(NULL, &hdev->bdaddr, hcon->type);
7216e760ec12SJohan Hedberg 	while (pchan) {
7217e760ec12SJohan Hedberg 		struct l2cap_chan *chan, *next;
7218e760ec12SJohan Hedberg 
7219e760ec12SJohan Hedberg 		/* Client fixed channels should override server ones */
7220e760ec12SJohan Hedberg 		if (__l2cap_get_chan_by_dcid(conn, pchan->scid))
7221e760ec12SJohan Hedberg 			goto next;
7222e760ec12SJohan Hedberg 
7223e760ec12SJohan Hedberg 		l2cap_chan_lock(pchan);
7224e760ec12SJohan Hedberg 		chan = pchan->ops->new_connection(pchan);
7225e760ec12SJohan Hedberg 		if (chan) {
7226e760ec12SJohan Hedberg 			bacpy(&chan->src, &hcon->src);
7227e760ec12SJohan Hedberg 			bacpy(&chan->dst, &hcon->dst);
7228e760ec12SJohan Hedberg 			chan->src_type = bdaddr_type(hcon, hcon->src_type);
7229e760ec12SJohan Hedberg 			chan->dst_type = dst_type;
7230e760ec12SJohan Hedberg 
7231e760ec12SJohan Hedberg 			__l2cap_chan_add(conn, chan);
7232e760ec12SJohan Hedberg 		}
7233e760ec12SJohan Hedberg 
7234e760ec12SJohan Hedberg 		l2cap_chan_unlock(pchan);
7235e760ec12SJohan Hedberg next:
723654a1b626SJohan Hedberg 		next = l2cap_global_fixed_chan(pchan, &hdev->bdaddr,
723754a1b626SJohan Hedberg 					       hcon->type);
7238e760ec12SJohan Hedberg 		l2cap_chan_put(pchan);
7239e760ec12SJohan Hedberg 		pchan = next;
7240e760ec12SJohan Hedberg 	}
7241e760ec12SJohan Hedberg 
7242dc0f5088SJohan Hedberg 	l2cap_conn_ready(conn);
72430a708f8fSGustavo F. Padovan }
72440a708f8fSGustavo F. Padovan 
7245686ebf28SUlisses Furquim int l2cap_disconn_ind(struct hci_conn *hcon)
72460a708f8fSGustavo F. Padovan {
72470a708f8fSGustavo F. Padovan 	struct l2cap_conn *conn = hcon->l2cap_data;
72480a708f8fSGustavo F. Padovan 
72490a708f8fSGustavo F. Padovan 	BT_DBG("hcon %p", hcon);
72500a708f8fSGustavo F. Padovan 
7251686ebf28SUlisses Furquim 	if (!conn)
72529f5a0d7bSAndrei Emeltchenko 		return HCI_ERROR_REMOTE_USER_TERM;
72530a708f8fSGustavo F. Padovan 	return conn->disc_reason;
72540a708f8fSGustavo F. Padovan }
72550a708f8fSGustavo F. Padovan 
72569e664631SAndrei Emeltchenko void l2cap_disconn_cfm(struct hci_conn *hcon, u8 reason)
72570a708f8fSGustavo F. Padovan {
72580a708f8fSGustavo F. Padovan 	BT_DBG("hcon %p reason %d", hcon, reason);
72590a708f8fSGustavo F. Padovan 
7260e175072fSJoe Perches 	l2cap_conn_del(hcon, bt_to_errno(reason));
72610a708f8fSGustavo F. Padovan }
72620a708f8fSGustavo F. Padovan 
72634343478fSGustavo F. Padovan static inline void l2cap_check_encryption(struct l2cap_chan *chan, u8 encrypt)
72640a708f8fSGustavo F. Padovan {
7265715ec005SGustavo F. Padovan 	if (chan->chan_type != L2CAP_CHAN_CONN_ORIENTED)
72660a708f8fSGustavo F. Padovan 		return;
72670a708f8fSGustavo F. Padovan 
72680a708f8fSGustavo F. Padovan 	if (encrypt == 0x00) {
72694343478fSGustavo F. Padovan 		if (chan->sec_level == BT_SECURITY_MEDIUM) {
7270ba13ccd9SMarcel Holtmann 			__set_chan_timer(chan, L2CAP_ENC_TIMEOUT);
72717d513e92SMarcel Holtmann 		} else if (chan->sec_level == BT_SECURITY_HIGH ||
72727d513e92SMarcel Holtmann 			   chan->sec_level == BT_SECURITY_FIPS)
72730f852724SGustavo F. Padovan 			l2cap_chan_close(chan, ECONNREFUSED);
72740a708f8fSGustavo F. Padovan 	} else {
72754343478fSGustavo F. Padovan 		if (chan->sec_level == BT_SECURITY_MEDIUM)
7276c9b66675SGustavo F. Padovan 			__clear_chan_timer(chan);
72770a708f8fSGustavo F. Padovan 	}
72780a708f8fSGustavo F. Padovan }
72790a708f8fSGustavo F. Padovan 
7280686ebf28SUlisses Furquim int l2cap_security_cfm(struct hci_conn *hcon, u8 status, u8 encrypt)
72810a708f8fSGustavo F. Padovan {
72820a708f8fSGustavo F. Padovan 	struct l2cap_conn *conn = hcon->l2cap_data;
728348454079SGustavo F. Padovan 	struct l2cap_chan *chan;
72840a708f8fSGustavo F. Padovan 
72850a708f8fSGustavo F. Padovan 	if (!conn)
72860a708f8fSGustavo F. Padovan 		return 0;
72870a708f8fSGustavo F. Padovan 
728889d8b407SAndrei Emeltchenko 	BT_DBG("conn %p status 0x%2.2x encrypt %u", conn, status, encrypt);
72890a708f8fSGustavo F. Padovan 
72903df91ea2SAndrei Emeltchenko 	mutex_lock(&conn->chan_lock);
72910a708f8fSGustavo F. Padovan 
72923df91ea2SAndrei Emeltchenko 	list_for_each_entry(chan, &conn->chan_l, list) {
72936be36555SAndrei Emeltchenko 		l2cap_chan_lock(chan);
72940a708f8fSGustavo F. Padovan 
729589d8b407SAndrei Emeltchenko 		BT_DBG("chan %p scid 0x%4.4x state %s", chan, chan->scid,
729689d8b407SAndrei Emeltchenko 		       state_to_string(chan->state));
7297f1cb9af5SVinicius Costa Gomes 
72982338a7e0SJohan Hedberg 		if (chan->scid == L2CAP_CID_A2MP) {
729978eb2f98SAndrei Emeltchenko 			l2cap_chan_unlock(chan);
730078eb2f98SAndrei Emeltchenko 			continue;
730178eb2f98SAndrei Emeltchenko 		}
730278eb2f98SAndrei Emeltchenko 
7303191eb398SJohan Hedberg 		if (!status && encrypt)
7304f1cb9af5SVinicius Costa Gomes 			chan->sec_level = hcon->sec_level;
7305f1cb9af5SVinicius Costa Gomes 
730696eff46eSAndrei Emeltchenko 		if (!__l2cap_no_conn_pending(chan)) {
73076be36555SAndrei Emeltchenko 			l2cap_chan_unlock(chan);
73080a708f8fSGustavo F. Padovan 			continue;
73090a708f8fSGustavo F. Padovan 		}
73100a708f8fSGustavo F. Padovan 
731189bc500eSGustavo F. Padovan 		if (!status && (chan->state == BT_CONNECTED ||
731289bc500eSGustavo F. Padovan 				chan->state == BT_CONFIG)) {
7313d97c899bSMarcel Holtmann 			chan->ops->resume(chan);
73144343478fSGustavo F. Padovan 			l2cap_check_encryption(chan, encrypt);
73156be36555SAndrei Emeltchenko 			l2cap_chan_unlock(chan);
73160a708f8fSGustavo F. Padovan 			continue;
73170a708f8fSGustavo F. Padovan 		}
73180a708f8fSGustavo F. Padovan 
731989bc500eSGustavo F. Padovan 		if (chan->state == BT_CONNECT) {
73206d3c15daSJohan Hedberg 			if (!status)
732193c3e8f5SAndrei Emeltchenko 				l2cap_start_connection(chan);
73226d3c15daSJohan Hedberg 			else
7323ba13ccd9SMarcel Holtmann 				__set_chan_timer(chan, L2CAP_DISC_TIMEOUT);
732489bc500eSGustavo F. Padovan 		} else if (chan->state == BT_CONNECT2) {
73250a708f8fSGustavo F. Padovan 			struct l2cap_conn_rsp rsp;
7326df3c3931SJohan Hedberg 			__u16 res, stat;
73270a708f8fSGustavo F. Padovan 
73280a708f8fSGustavo F. Padovan 			if (!status) {
7329bdc25783SMarcel Holtmann 				if (test_bit(FLAG_DEFER_SETUP, &chan->flags)) {
7330df3c3931SJohan Hedberg 					res = L2CAP_CR_PEND;
7331df3c3931SJohan Hedberg 					stat = L2CAP_CS_AUTHOR_PEND;
73322dc4e510SGustavo Padovan 					chan->ops->defer(chan);
7333df3c3931SJohan Hedberg 				} else {
7334acdcabf5SGustavo Padovan 					l2cap_state_change(chan, BT_CONFIG);
7335df3c3931SJohan Hedberg 					res = L2CAP_CR_SUCCESS;
7336df3c3931SJohan Hedberg 					stat = L2CAP_CS_NO_INFO;
7337df3c3931SJohan Hedberg 				}
73380a708f8fSGustavo F. Padovan 			} else {
7339acdcabf5SGustavo Padovan 				l2cap_state_change(chan, BT_DISCONN);
7340ba13ccd9SMarcel Holtmann 				__set_chan_timer(chan, L2CAP_DISC_TIMEOUT);
7341df3c3931SJohan Hedberg 				res = L2CAP_CR_SEC_BLOCK;
7342df3c3931SJohan Hedberg 				stat = L2CAP_CS_NO_INFO;
73430a708f8fSGustavo F. Padovan 			}
73440a708f8fSGustavo F. Padovan 
7345fe4128e0SGustavo F. Padovan 			rsp.scid   = cpu_to_le16(chan->dcid);
7346fe4128e0SGustavo F. Padovan 			rsp.dcid   = cpu_to_le16(chan->scid);
7347df3c3931SJohan Hedberg 			rsp.result = cpu_to_le16(res);
7348df3c3931SJohan Hedberg 			rsp.status = cpu_to_le16(stat);
7349fc7f8a7eSGustavo F. Padovan 			l2cap_send_cmd(conn, chan->ident, L2CAP_CONN_RSP,
7350fc7f8a7eSGustavo F. Padovan 				       sizeof(rsp), &rsp);
73512d369359SMat Martineau 
73522d369359SMat Martineau 			if (!test_bit(CONF_REQ_SENT, &chan->conf_state) &&
73532d369359SMat Martineau 			    res == L2CAP_CR_SUCCESS) {
73542d369359SMat Martineau 				char buf[128];
73552d369359SMat Martineau 				set_bit(CONF_REQ_SENT, &chan->conf_state);
73562d369359SMat Martineau 				l2cap_send_cmd(conn, l2cap_get_ident(conn),
73572d369359SMat Martineau 					       L2CAP_CONF_REQ,
73582d369359SMat Martineau 					       l2cap_build_conf_req(chan, buf),
73592d369359SMat Martineau 					       buf);
73602d369359SMat Martineau 				chan->num_conf_req++;
73612d369359SMat Martineau 			}
73620a708f8fSGustavo F. Padovan 		}
73630a708f8fSGustavo F. Padovan 
73646be36555SAndrei Emeltchenko 		l2cap_chan_unlock(chan);
73650a708f8fSGustavo F. Padovan 	}
73660a708f8fSGustavo F. Padovan 
73673df91ea2SAndrei Emeltchenko 	mutex_unlock(&conn->chan_lock);
73680a708f8fSGustavo F. Padovan 
73690a708f8fSGustavo F. Padovan 	return 0;
73700a708f8fSGustavo F. Padovan }
73710a708f8fSGustavo F. Padovan 
7372686ebf28SUlisses Furquim int l2cap_recv_acldata(struct hci_conn *hcon, struct sk_buff *skb, u16 flags)
73730a708f8fSGustavo F. Padovan {
73740a708f8fSGustavo F. Padovan 	struct l2cap_conn *conn = hcon->l2cap_data;
7375d73a0988SAndrei Emeltchenko 	struct l2cap_hdr *hdr;
7376d73a0988SAndrei Emeltchenko 	int len;
73770a708f8fSGustavo F. Padovan 
73781d13a254SAndrei Emeltchenko 	/* For AMP controller do not create l2cap conn */
73791d13a254SAndrei Emeltchenko 	if (!conn && hcon->hdev->dev_type != HCI_BREDR)
73801d13a254SAndrei Emeltchenko 		goto drop;
73810a708f8fSGustavo F. Padovan 
73820a708f8fSGustavo F. Padovan 	if (!conn)
7383baf43251SClaudio Takahasi 		conn = l2cap_conn_add(hcon);
73840a708f8fSGustavo F. Padovan 
73850a708f8fSGustavo F. Padovan 	if (!conn)
73860a708f8fSGustavo F. Padovan 		goto drop;
73870a708f8fSGustavo F. Padovan 
73880a708f8fSGustavo F. Padovan 	BT_DBG("conn %p len %d flags 0x%x", conn, skb->len, flags);
73890a708f8fSGustavo F. Padovan 
7390d73a0988SAndrei Emeltchenko 	switch (flags) {
7391d73a0988SAndrei Emeltchenko 	case ACL_START:
7392d73a0988SAndrei Emeltchenko 	case ACL_START_NO_FLUSH:
7393d73a0988SAndrei Emeltchenko 	case ACL_COMPLETE:
73940a708f8fSGustavo F. Padovan 		if (conn->rx_len) {
73950a708f8fSGustavo F. Padovan 			BT_ERR("Unexpected start frame (len %d)", skb->len);
73960a708f8fSGustavo F. Padovan 			kfree_skb(conn->rx_skb);
73970a708f8fSGustavo F. Padovan 			conn->rx_skb = NULL;
73980a708f8fSGustavo F. Padovan 			conn->rx_len = 0;
73990a708f8fSGustavo F. Padovan 			l2cap_conn_unreliable(conn, ECOMM);
74000a708f8fSGustavo F. Padovan 		}
74010a708f8fSGustavo F. Padovan 
74020a708f8fSGustavo F. Padovan 		/* Start fragment always begin with Basic L2CAP header */
74030a708f8fSGustavo F. Padovan 		if (skb->len < L2CAP_HDR_SIZE) {
74040a708f8fSGustavo F. Padovan 			BT_ERR("Frame is too short (len %d)", skb->len);
74050a708f8fSGustavo F. Padovan 			l2cap_conn_unreliable(conn, ECOMM);
74060a708f8fSGustavo F. Padovan 			goto drop;
74070a708f8fSGustavo F. Padovan 		}
74080a708f8fSGustavo F. Padovan 
74090a708f8fSGustavo F. Padovan 		hdr = (struct l2cap_hdr *) skb->data;
74100a708f8fSGustavo F. Padovan 		len = __le16_to_cpu(hdr->len) + L2CAP_HDR_SIZE;
74110a708f8fSGustavo F. Padovan 
74120a708f8fSGustavo F. Padovan 		if (len == skb->len) {
74130a708f8fSGustavo F. Padovan 			/* Complete frame received */
74140a708f8fSGustavo F. Padovan 			l2cap_recv_frame(conn, skb);
74150a708f8fSGustavo F. Padovan 			return 0;
74160a708f8fSGustavo F. Padovan 		}
74170a708f8fSGustavo F. Padovan 
74180a708f8fSGustavo F. Padovan 		BT_DBG("Start: total len %d, frag len %d", len, skb->len);
74190a708f8fSGustavo F. Padovan 
74200a708f8fSGustavo F. Padovan 		if (skb->len > len) {
74210a708f8fSGustavo F. Padovan 			BT_ERR("Frame is too long (len %d, expected len %d)",
74220a708f8fSGustavo F. Padovan 			       skb->len, len);
74230a708f8fSGustavo F. Padovan 			l2cap_conn_unreliable(conn, ECOMM);
74240a708f8fSGustavo F. Padovan 			goto drop;
74250a708f8fSGustavo F. Padovan 		}
74260a708f8fSGustavo F. Padovan 
74270a708f8fSGustavo F. Padovan 		/* Allocate skb for the complete frame (with header) */
74288bcde1f2SGustavo Padovan 		conn->rx_skb = bt_skb_alloc(len, GFP_KERNEL);
74290a708f8fSGustavo F. Padovan 		if (!conn->rx_skb)
74300a708f8fSGustavo F. Padovan 			goto drop;
74310a708f8fSGustavo F. Padovan 
74320a708f8fSGustavo F. Padovan 		skb_copy_from_linear_data(skb, skb_put(conn->rx_skb, skb->len),
74330a708f8fSGustavo F. Padovan 					  skb->len);
74340a708f8fSGustavo F. Padovan 		conn->rx_len = len - skb->len;
7435d73a0988SAndrei Emeltchenko 		break;
7436d73a0988SAndrei Emeltchenko 
7437d73a0988SAndrei Emeltchenko 	case ACL_CONT:
74380a708f8fSGustavo F. Padovan 		BT_DBG("Cont: frag len %d (expecting %d)", skb->len, conn->rx_len);
74390a708f8fSGustavo F. Padovan 
74400a708f8fSGustavo F. Padovan 		if (!conn->rx_len) {
74410a708f8fSGustavo F. Padovan 			BT_ERR("Unexpected continuation frame (len %d)", skb->len);
74420a708f8fSGustavo F. Padovan 			l2cap_conn_unreliable(conn, ECOMM);
74430a708f8fSGustavo F. Padovan 			goto drop;
74440a708f8fSGustavo F. Padovan 		}
74450a708f8fSGustavo F. Padovan 
74460a708f8fSGustavo F. Padovan 		if (skb->len > conn->rx_len) {
74470a708f8fSGustavo F. Padovan 			BT_ERR("Fragment is too long (len %d, expected %d)",
74480a708f8fSGustavo F. Padovan 			       skb->len, conn->rx_len);
74490a708f8fSGustavo F. Padovan 			kfree_skb(conn->rx_skb);
74500a708f8fSGustavo F. Padovan 			conn->rx_skb = NULL;
74510a708f8fSGustavo F. Padovan 			conn->rx_len = 0;
74520a708f8fSGustavo F. Padovan 			l2cap_conn_unreliable(conn, ECOMM);
74530a708f8fSGustavo F. Padovan 			goto drop;
74540a708f8fSGustavo F. Padovan 		}
74550a708f8fSGustavo F. Padovan 
74560a708f8fSGustavo F. Padovan 		skb_copy_from_linear_data(skb, skb_put(conn->rx_skb, skb->len),
74570a708f8fSGustavo F. Padovan 					  skb->len);
74580a708f8fSGustavo F. Padovan 		conn->rx_len -= skb->len;
74590a708f8fSGustavo F. Padovan 
74600a708f8fSGustavo F. Padovan 		if (!conn->rx_len) {
7461c4e5bafaSJohan Hedberg 			/* Complete frame received. l2cap_recv_frame
7462c4e5bafaSJohan Hedberg 			 * takes ownership of the skb so set the global
7463c4e5bafaSJohan Hedberg 			 * rx_skb pointer to NULL first.
7464c4e5bafaSJohan Hedberg 			 */
7465c4e5bafaSJohan Hedberg 			struct sk_buff *rx_skb = conn->rx_skb;
74660a708f8fSGustavo F. Padovan 			conn->rx_skb = NULL;
7467c4e5bafaSJohan Hedberg 			l2cap_recv_frame(conn, rx_skb);
74680a708f8fSGustavo F. Padovan 		}
7469d73a0988SAndrei Emeltchenko 		break;
74700a708f8fSGustavo F. Padovan 	}
74710a708f8fSGustavo F. Padovan 
74720a708f8fSGustavo F. Padovan drop:
74730a708f8fSGustavo F. Padovan 	kfree_skb(skb);
74740a708f8fSGustavo F. Padovan 	return 0;
74750a708f8fSGustavo F. Padovan }
74760a708f8fSGustavo F. Padovan 
74770a708f8fSGustavo F. Padovan static int l2cap_debugfs_show(struct seq_file *f, void *p)
74780a708f8fSGustavo F. Padovan {
747923691d75SGustavo F. Padovan 	struct l2cap_chan *c;
74800a708f8fSGustavo F. Padovan 
7481333055f2SGustavo F. Padovan 	read_lock(&chan_list_lock);
74820a708f8fSGustavo F. Padovan 
748323691d75SGustavo F. Padovan 	list_for_each_entry(c, &chan_list, global_l) {
7484fcb73338SAndrei Emeltchenko 		seq_printf(f, "%pMR %pMR %d %d 0x%4.4x 0x%4.4x %d %d %d %d\n",
74857eafc59eSMarcel Holtmann 			   &c->src, &c->dst,
748689bc500eSGustavo F. Padovan 			   c->state, __le16_to_cpu(c->psm),
748723691d75SGustavo F. Padovan 			   c->scid, c->dcid, c->imtu, c->omtu,
748823691d75SGustavo F. Padovan 			   c->sec_level, c->mode);
74890a708f8fSGustavo F. Padovan 	}
74900a708f8fSGustavo F. Padovan 
7491333055f2SGustavo F. Padovan 	read_unlock(&chan_list_lock);
74920a708f8fSGustavo F. Padovan 
74930a708f8fSGustavo F. Padovan 	return 0;
74940a708f8fSGustavo F. Padovan }
74950a708f8fSGustavo F. Padovan 
74960a708f8fSGustavo F. Padovan static int l2cap_debugfs_open(struct inode *inode, struct file *file)
74970a708f8fSGustavo F. Padovan {
74980a708f8fSGustavo F. Padovan 	return single_open(file, l2cap_debugfs_show, inode->i_private);
74990a708f8fSGustavo F. Padovan }
75000a708f8fSGustavo F. Padovan 
75010a708f8fSGustavo F. Padovan static const struct file_operations l2cap_debugfs_fops = {
75020a708f8fSGustavo F. Padovan 	.open		= l2cap_debugfs_open,
75030a708f8fSGustavo F. Padovan 	.read		= seq_read,
75040a708f8fSGustavo F. Padovan 	.llseek		= seq_lseek,
75050a708f8fSGustavo F. Padovan 	.release	= single_release,
75060a708f8fSGustavo F. Padovan };
75070a708f8fSGustavo F. Padovan 
75080a708f8fSGustavo F. Padovan static struct dentry *l2cap_debugfs;
75090a708f8fSGustavo F. Padovan 
751064274518SGustavo F. Padovan int __init l2cap_init(void)
75110a708f8fSGustavo F. Padovan {
75120a708f8fSGustavo F. Padovan 	int err;
75130a708f8fSGustavo F. Padovan 
7514bb58f747SGustavo F. Padovan 	err = l2cap_init_sockets();
75150a708f8fSGustavo F. Padovan 	if (err < 0)
75160a708f8fSGustavo F. Padovan 		return err;
75170a708f8fSGustavo F. Padovan 
75181120e4bfSMarcel Holtmann 	if (IS_ERR_OR_NULL(bt_debugfs))
75191120e4bfSMarcel Holtmann 		return 0;
75201120e4bfSMarcel Holtmann 
75212d792818SGustavo Padovan 	l2cap_debugfs = debugfs_create_file("l2cap", 0444, bt_debugfs,
75222d792818SGustavo Padovan 					    NULL, &l2cap_debugfs_fops);
75230a708f8fSGustavo F. Padovan 
752440b9397aSSamuel Ortiz 	debugfs_create_u16("l2cap_le_max_credits", 0644, bt_debugfs,
7525f15b8ecfSJohan Hedberg 			   &le_max_credits);
752640b9397aSSamuel Ortiz 	debugfs_create_u16("l2cap_le_default_mps", 0644, bt_debugfs,
7527f15b8ecfSJohan Hedberg 			   &le_default_mps);
7528f15b8ecfSJohan Hedberg 
75290a708f8fSGustavo F. Padovan 	return 0;
75300a708f8fSGustavo F. Padovan }
75310a708f8fSGustavo F. Padovan 
753264274518SGustavo F. Padovan void l2cap_exit(void)
75330a708f8fSGustavo F. Padovan {
75340a708f8fSGustavo F. Padovan 	debugfs_remove(l2cap_debugfs);
7535bb58f747SGustavo F. Padovan 	l2cap_cleanup_sockets();
75360a708f8fSGustavo F. Padovan }
75370a708f8fSGustavo F. Padovan 
75380a708f8fSGustavo F. Padovan module_param(disable_ertm, bool, 0644);
75390a708f8fSGustavo F. Padovan MODULE_PARM_DESC(disable_ertm, "Disable enhanced retransmission mode");
7540