xref: /openbmc/linux/net/bluetooth/l2cap_core.c (revision 5ec1bbe5)
10a708f8fSGustavo F. Padovan /*
20a708f8fSGustavo F. Padovan    BlueZ - Bluetooth protocol stack for Linux
30a708f8fSGustavo F. Padovan    Copyright (C) 2000-2001 Qualcomm Incorporated
40a708f8fSGustavo F. Padovan    Copyright (C) 2009-2010 Gustavo F. Padovan <gustavo@padovan.org>
50a708f8fSGustavo F. Padovan    Copyright (C) 2010 Google Inc.
6590051deSGustavo F. Padovan    Copyright (C) 2011 ProFUSION Embedded Systems
7422e925bSMat Martineau    Copyright (c) 2012 Code Aurora Forum.  All rights reserved.
80a708f8fSGustavo F. Padovan 
90a708f8fSGustavo F. Padovan    Written 2000,2001 by Maxim Krasnyansky <maxk@qualcomm.com>
100a708f8fSGustavo F. Padovan 
110a708f8fSGustavo F. Padovan    This program is free software; you can redistribute it and/or modify
120a708f8fSGustavo F. Padovan    it under the terms of the GNU General Public License version 2 as
130a708f8fSGustavo F. Padovan    published by the Free Software Foundation;
140a708f8fSGustavo F. Padovan 
150a708f8fSGustavo F. Padovan    THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS
160a708f8fSGustavo F. Padovan    OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
170a708f8fSGustavo F. Padovan    FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT OF THIRD PARTY RIGHTS.
180a708f8fSGustavo F. Padovan    IN NO EVENT SHALL THE COPYRIGHT HOLDER(S) AND AUTHOR(S) BE LIABLE FOR ANY
190a708f8fSGustavo F. Padovan    CLAIM, OR ANY SPECIAL INDIRECT OR CONSEQUENTIAL DAMAGES, OR ANY DAMAGES
200a708f8fSGustavo F. Padovan    WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
210a708f8fSGustavo F. Padovan    ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
220a708f8fSGustavo F. Padovan    OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
230a708f8fSGustavo F. Padovan 
240a708f8fSGustavo F. Padovan    ALL LIABILITY, INCLUDING LIABILITY FOR INFRINGEMENT OF ANY PATENTS,
250a708f8fSGustavo F. Padovan    COPYRIGHTS, TRADEMARKS OR OTHER RIGHTS, RELATING TO USE OF THIS
260a708f8fSGustavo F. Padovan    SOFTWARE IS DISCLAIMED.
270a708f8fSGustavo F. Padovan */
280a708f8fSGustavo F. Padovan 
29bb58f747SGustavo F. Padovan /* Bluetooth L2CAP core. */
300a708f8fSGustavo F. Padovan 
310a708f8fSGustavo F. Padovan #include <linux/module.h>
320a708f8fSGustavo F. Padovan 
330a708f8fSGustavo F. Padovan #include <linux/debugfs.h>
340a708f8fSGustavo F. Padovan #include <linux/crc16.h>
350a708f8fSGustavo F. Padovan 
360a708f8fSGustavo F. Padovan #include <net/bluetooth/bluetooth.h>
370a708f8fSGustavo F. Padovan #include <net/bluetooth/hci_core.h>
380a708f8fSGustavo F. Padovan #include <net/bluetooth/l2cap.h>
397ef9fbf0SMarcel Holtmann 
40ac4b7236SMarcel Holtmann #include "smp.h"
417024728eSMarcel Holtmann #include "a2mp.h"
427ef9fbf0SMarcel Holtmann #include "amp.h"
430a708f8fSGustavo F. Padovan 
44d1de6d46SMat Martineau bool disable_ertm;
450a708f8fSGustavo F. Padovan 
46547d1032SMarcel Holtmann static u32 l2cap_feat_mask = L2CAP_FEAT_FIXED_CHAN | L2CAP_FEAT_UCD;
47d40bffbcSMarcel Holtmann static u8 l2cap_fixed_chan[8] = { L2CAP_FC_L2CAP | L2CAP_FC_CONNLESS, };
480a708f8fSGustavo F. Padovan 
49b5ad8b7fSJohannes Berg static LIST_HEAD(chan_list);
50b5ad8b7fSJohannes Berg static DEFINE_RWLOCK(chan_list_lock);
510a708f8fSGustavo F. Padovan 
520a708f8fSGustavo F. Padovan static struct sk_buff *l2cap_build_cmd(struct l2cap_conn *conn,
530a708f8fSGustavo F. Padovan 				       u8 code, u8 ident, u16 dlen, void *data);
544519de9aSGustavo F. Padovan static void l2cap_send_cmd(struct l2cap_conn *conn, u8 ident, u8 code, u16 len,
554519de9aSGustavo F. Padovan 			   void *data);
56710f9b0aSGustavo F. Padovan static int l2cap_build_conf_req(struct l2cap_chan *chan, void *data);
575e4e3972SAndrei Emeltchenko static void l2cap_send_disconn_req(struct l2cap_chan *chan, int err);
580a708f8fSGustavo F. Padovan 
59d660366dSGustavo Padovan static void l2cap_tx(struct l2cap_chan *chan, struct l2cap_ctrl *control,
60608bcc6dSMat Martineau 		     struct sk_buff_head *skbs, u8 event);
61608bcc6dSMat Martineau 
624f1654e0SMarcel Holtmann static inline __u8 bdaddr_type(struct hci_conn *hcon, __u8 type)
634f1654e0SMarcel Holtmann {
644f1654e0SMarcel Holtmann 	if (hcon->type == LE_LINK) {
654f1654e0SMarcel Holtmann 		if (type == ADDR_LE_DEV_PUBLIC)
664f1654e0SMarcel Holtmann 			return BDADDR_LE_PUBLIC;
674f1654e0SMarcel Holtmann 		else
684f1654e0SMarcel Holtmann 			return BDADDR_LE_RANDOM;
694f1654e0SMarcel Holtmann 	}
704f1654e0SMarcel Holtmann 
714f1654e0SMarcel Holtmann 	return BDADDR_BREDR;
724f1654e0SMarcel Holtmann }
734f1654e0SMarcel Holtmann 
740a708f8fSGustavo F. Padovan /* ---- L2CAP channels ---- */
7571ba0e56SGustavo F. Padovan 
762d792818SGustavo Padovan static struct l2cap_chan *__l2cap_get_chan_by_dcid(struct l2cap_conn *conn,
772d792818SGustavo Padovan 						   u16 cid)
780a708f8fSGustavo F. Padovan {
793df91ea2SAndrei Emeltchenko 	struct l2cap_chan *c;
80baa7e1faSGustavo F. Padovan 
813df91ea2SAndrei Emeltchenko 	list_for_each_entry(c, &conn->chan_l, list) {
823df91ea2SAndrei Emeltchenko 		if (c->dcid == cid)
833df91ea2SAndrei Emeltchenko 			return c;
840a708f8fSGustavo F. Padovan 	}
853df91ea2SAndrei Emeltchenko 	return NULL;
86baa7e1faSGustavo F. Padovan }
870a708f8fSGustavo F. Padovan 
882d792818SGustavo Padovan static struct l2cap_chan *__l2cap_get_chan_by_scid(struct l2cap_conn *conn,
892d792818SGustavo Padovan 						   u16 cid)
900a708f8fSGustavo F. Padovan {
913df91ea2SAndrei Emeltchenko 	struct l2cap_chan *c;
92baa7e1faSGustavo F. Padovan 
933df91ea2SAndrei Emeltchenko 	list_for_each_entry(c, &conn->chan_l, list) {
943df91ea2SAndrei Emeltchenko 		if (c->scid == cid)
953df91ea2SAndrei Emeltchenko 			return c;
960a708f8fSGustavo F. Padovan 	}
973df91ea2SAndrei Emeltchenko 	return NULL;
98baa7e1faSGustavo F. Padovan }
990a708f8fSGustavo F. Padovan 
1000a708f8fSGustavo F. Padovan /* Find channel with given SCID.
101ef191adeSMat Martineau  * Returns locked channel. */
1022d792818SGustavo Padovan static struct l2cap_chan *l2cap_get_chan_by_scid(struct l2cap_conn *conn,
1032d792818SGustavo Padovan 						 u16 cid)
1040a708f8fSGustavo F. Padovan {
10548454079SGustavo F. Padovan 	struct l2cap_chan *c;
106baa7e1faSGustavo F. Padovan 
1073df91ea2SAndrei Emeltchenko 	mutex_lock(&conn->chan_lock);
108baa7e1faSGustavo F. Padovan 	c = __l2cap_get_chan_by_scid(conn, cid);
109ef191adeSMat Martineau 	if (c)
110ef191adeSMat Martineau 		l2cap_chan_lock(c);
1113df91ea2SAndrei Emeltchenko 	mutex_unlock(&conn->chan_lock);
1123df91ea2SAndrei Emeltchenko 
11348454079SGustavo F. Padovan 	return c;
1140a708f8fSGustavo F. Padovan }
1150a708f8fSGustavo F. Padovan 
116b1a130b7SMat Martineau /* Find channel with given DCID.
117b1a130b7SMat Martineau  * Returns locked channel.
118b1a130b7SMat Martineau  */
119b1a130b7SMat Martineau static struct l2cap_chan *l2cap_get_chan_by_dcid(struct l2cap_conn *conn,
120b1a130b7SMat Martineau 						 u16 cid)
121b1a130b7SMat Martineau {
122b1a130b7SMat Martineau 	struct l2cap_chan *c;
123b1a130b7SMat Martineau 
124b1a130b7SMat Martineau 	mutex_lock(&conn->chan_lock);
125b1a130b7SMat Martineau 	c = __l2cap_get_chan_by_dcid(conn, cid);
126b1a130b7SMat Martineau 	if (c)
127b1a130b7SMat Martineau 		l2cap_chan_lock(c);
128b1a130b7SMat Martineau 	mutex_unlock(&conn->chan_lock);
129b1a130b7SMat Martineau 
130b1a130b7SMat Martineau 	return c;
131b1a130b7SMat Martineau }
132b1a130b7SMat Martineau 
1332d792818SGustavo Padovan static struct l2cap_chan *__l2cap_get_chan_by_ident(struct l2cap_conn *conn,
1342d792818SGustavo Padovan 						    u8 ident)
1350a708f8fSGustavo F. Padovan {
1363df91ea2SAndrei Emeltchenko 	struct l2cap_chan *c;
137baa7e1faSGustavo F. Padovan 
1383df91ea2SAndrei Emeltchenko 	list_for_each_entry(c, &conn->chan_l, list) {
1393df91ea2SAndrei Emeltchenko 		if (c->ident == ident)
1403df91ea2SAndrei Emeltchenko 			return c;
1410a708f8fSGustavo F. Padovan 	}
1423df91ea2SAndrei Emeltchenko 	return NULL;
143baa7e1faSGustavo F. Padovan }
1440a708f8fSGustavo F. Padovan 
1455b155ef9SMat Martineau static struct l2cap_chan *l2cap_get_chan_by_ident(struct l2cap_conn *conn,
1465b155ef9SMat Martineau 						  u8 ident)
1475b155ef9SMat Martineau {
1485b155ef9SMat Martineau 	struct l2cap_chan *c;
1495b155ef9SMat Martineau 
1505b155ef9SMat Martineau 	mutex_lock(&conn->chan_lock);
1515b155ef9SMat Martineau 	c = __l2cap_get_chan_by_ident(conn, ident);
1525b155ef9SMat Martineau 	if (c)
1535b155ef9SMat Martineau 		l2cap_chan_lock(c);
1545b155ef9SMat Martineau 	mutex_unlock(&conn->chan_lock);
1555b155ef9SMat Martineau 
1565b155ef9SMat Martineau 	return c;
1575b155ef9SMat Martineau }
1585b155ef9SMat Martineau 
15923691d75SGustavo F. Padovan static struct l2cap_chan *__l2cap_global_chan_by_addr(__le16 psm, bdaddr_t *src)
1609e4425ffSGustavo F. Padovan {
16123691d75SGustavo F. Padovan 	struct l2cap_chan *c;
1629e4425ffSGustavo F. Padovan 
16323691d75SGustavo F. Padovan 	list_for_each_entry(c, &chan_list, global_l) {
1647eafc59eSMarcel Holtmann 		if (c->sport == psm && !bacmp(&c->src, src))
16523691d75SGustavo F. Padovan 			return c;
1669e4425ffSGustavo F. Padovan 	}
167250938cbSSzymon Janc 	return NULL;
168250938cbSSzymon Janc }
1699e4425ffSGustavo F. Padovan 
1709e4425ffSGustavo F. Padovan int l2cap_add_psm(struct l2cap_chan *chan, bdaddr_t *src, __le16 psm)
1719e4425ffSGustavo F. Padovan {
17273b2ec18SGustavo F. Padovan 	int err;
17373b2ec18SGustavo F. Padovan 
174333055f2SGustavo F. Padovan 	write_lock(&chan_list_lock);
1759e4425ffSGustavo F. Padovan 
17623691d75SGustavo F. Padovan 	if (psm && __l2cap_global_chan_by_addr(psm, src)) {
17773b2ec18SGustavo F. Padovan 		err = -EADDRINUSE;
17873b2ec18SGustavo F. Padovan 		goto done;
1799e4425ffSGustavo F. Padovan 	}
1809e4425ffSGustavo F. Padovan 
18173b2ec18SGustavo F. Padovan 	if (psm) {
1829e4425ffSGustavo F. Padovan 		chan->psm = psm;
1839e4425ffSGustavo F. Padovan 		chan->sport = psm;
18473b2ec18SGustavo F. Padovan 		err = 0;
18573b2ec18SGustavo F. Padovan 	} else {
18673b2ec18SGustavo F. Padovan 		u16 p;
1879e4425ffSGustavo F. Padovan 
18873b2ec18SGustavo F. Padovan 		err = -EINVAL;
18973b2ec18SGustavo F. Padovan 		for (p = 0x1001; p < 0x1100; p += 2)
19023691d75SGustavo F. Padovan 			if (!__l2cap_global_chan_by_addr(cpu_to_le16(p), src)) {
19173b2ec18SGustavo F. Padovan 				chan->psm   = cpu_to_le16(p);
19273b2ec18SGustavo F. Padovan 				chan->sport = cpu_to_le16(p);
19373b2ec18SGustavo F. Padovan 				err = 0;
19473b2ec18SGustavo F. Padovan 				break;
19573b2ec18SGustavo F. Padovan 			}
19673b2ec18SGustavo F. Padovan 	}
19773b2ec18SGustavo F. Padovan 
19873b2ec18SGustavo F. Padovan done:
199333055f2SGustavo F. Padovan 	write_unlock(&chan_list_lock);
20073b2ec18SGustavo F. Padovan 	return err;
2019e4425ffSGustavo F. Padovan }
2029e4425ffSGustavo F. Padovan 
2039e4425ffSGustavo F. Padovan int l2cap_add_scid(struct l2cap_chan *chan,  __u16 scid)
2049e4425ffSGustavo F. Padovan {
205333055f2SGustavo F. Padovan 	write_lock(&chan_list_lock);
2069e4425ffSGustavo F. Padovan 
2079e4425ffSGustavo F. Padovan 	chan->scid = scid;
2089e4425ffSGustavo F. Padovan 
209333055f2SGustavo F. Padovan 	write_unlock(&chan_list_lock);
2109e4425ffSGustavo F. Padovan 
2119e4425ffSGustavo F. Padovan 	return 0;
2129e4425ffSGustavo F. Padovan }
2139e4425ffSGustavo F. Padovan 
214baa7e1faSGustavo F. Padovan static u16 l2cap_alloc_cid(struct l2cap_conn *conn)
2150a708f8fSGustavo F. Padovan {
2160a708f8fSGustavo F. Padovan 	u16 cid = L2CAP_CID_DYN_START;
2170a708f8fSGustavo F. Padovan 
2180a708f8fSGustavo F. Padovan 	for (; cid < L2CAP_CID_DYN_END; cid++) {
219baa7e1faSGustavo F. Padovan 		if (!__l2cap_get_chan_by_scid(conn, cid))
2200a708f8fSGustavo F. Padovan 			return cid;
2210a708f8fSGustavo F. Padovan 	}
2220a708f8fSGustavo F. Padovan 
2230a708f8fSGustavo F. Padovan 	return 0;
2240a708f8fSGustavo F. Padovan }
2250a708f8fSGustavo F. Padovan 
2260e587be7SAndrei Emeltchenko static void __l2cap_state_change(struct l2cap_chan *chan, int state)
22789bc500eSGustavo F. Padovan {
22842d2d87cSAndrei Emeltchenko 	BT_DBG("chan %p %s -> %s", chan, state_to_string(chan->state),
229badaaa00SGustavo F. Padovan 	       state_to_string(state));
230badaaa00SGustavo F. Padovan 
23189bc500eSGustavo F. Padovan 	chan->state = state;
23253f52121SGustavo Padovan 	chan->ops->state_change(chan, state, 0);
23389bc500eSGustavo F. Padovan }
23489bc500eSGustavo F. Padovan 
2350e587be7SAndrei Emeltchenko static void l2cap_state_change(struct l2cap_chan *chan, int state)
2360e587be7SAndrei Emeltchenko {
2370e587be7SAndrei Emeltchenko 	struct sock *sk = chan->sk;
2380e587be7SAndrei Emeltchenko 
2390e587be7SAndrei Emeltchenko 	lock_sock(sk);
2400e587be7SAndrei Emeltchenko 	__l2cap_state_change(chan, state);
2410e587be7SAndrei Emeltchenko 	release_sock(sk);
2420e587be7SAndrei Emeltchenko }
2430e587be7SAndrei Emeltchenko 
244f8e73017SGustavo Padovan static inline void l2cap_state_change_and_error(struct l2cap_chan *chan,
245f8e73017SGustavo Padovan 						int state, int err)
2462e0052e4SAndrei Emeltchenko {
247f8e73017SGustavo Padovan 	struct sock *sk = chan->sk;
248f8e73017SGustavo Padovan 
249f8e73017SGustavo Padovan 	lock_sock(sk);
250f8e73017SGustavo Padovan 	chan->state = state;
25153f52121SGustavo Padovan 	chan->ops->state_change(chan, chan->state, err);
252f8e73017SGustavo Padovan 	release_sock(sk);
2532e0052e4SAndrei Emeltchenko }
2542e0052e4SAndrei Emeltchenko 
2552e0052e4SAndrei Emeltchenko static inline void l2cap_chan_set_err(struct l2cap_chan *chan, int err)
2562e0052e4SAndrei Emeltchenko {
2572e0052e4SAndrei Emeltchenko 	struct sock *sk = chan->sk;
2582e0052e4SAndrei Emeltchenko 
2592e0052e4SAndrei Emeltchenko 	lock_sock(sk);
260f8e73017SGustavo Padovan 	chan->ops->state_change(chan, chan->state, err);
2612e0052e4SAndrei Emeltchenko 	release_sock(sk);
2622e0052e4SAndrei Emeltchenko }
2632e0052e4SAndrei Emeltchenko 
2644239d16fSMat Martineau static void __set_retrans_timer(struct l2cap_chan *chan)
2654239d16fSMat Martineau {
2664239d16fSMat Martineau 	if (!delayed_work_pending(&chan->monitor_timer) &&
2674239d16fSMat Martineau 	    chan->retrans_timeout) {
2684239d16fSMat Martineau 		l2cap_set_timer(chan, &chan->retrans_timer,
2694239d16fSMat Martineau 				msecs_to_jiffies(chan->retrans_timeout));
2704239d16fSMat Martineau 	}
2714239d16fSMat Martineau }
2724239d16fSMat Martineau 
2734239d16fSMat Martineau static void __set_monitor_timer(struct l2cap_chan *chan)
2744239d16fSMat Martineau {
2754239d16fSMat Martineau 	__clear_retrans_timer(chan);
2764239d16fSMat Martineau 	if (chan->monitor_timeout) {
2774239d16fSMat Martineau 		l2cap_set_timer(chan, &chan->monitor_timer,
2784239d16fSMat Martineau 				msecs_to_jiffies(chan->monitor_timeout));
2794239d16fSMat Martineau 	}
2804239d16fSMat Martineau }
2814239d16fSMat Martineau 
282608bcc6dSMat Martineau static struct sk_buff *l2cap_ertm_seq_in_queue(struct sk_buff_head *head,
283608bcc6dSMat Martineau 					       u16 seq)
284608bcc6dSMat Martineau {
285608bcc6dSMat Martineau 	struct sk_buff *skb;
286608bcc6dSMat Martineau 
287608bcc6dSMat Martineau 	skb_queue_walk(head, skb) {
288608bcc6dSMat Martineau 		if (bt_cb(skb)->control.txseq == seq)
289608bcc6dSMat Martineau 			return skb;
290608bcc6dSMat Martineau 	}
291608bcc6dSMat Martineau 
292608bcc6dSMat Martineau 	return NULL;
293608bcc6dSMat Martineau }
294608bcc6dSMat Martineau 
2953c588192SMat Martineau /* ---- L2CAP sequence number lists ---- */
2963c588192SMat Martineau 
2973c588192SMat Martineau /* For ERTM, ordered lists of sequence numbers must be tracked for
2983c588192SMat Martineau  * SREJ requests that are received and for frames that are to be
2993c588192SMat Martineau  * retransmitted. These seq_list functions implement a singly-linked
3003c588192SMat Martineau  * list in an array, where membership in the list can also be checked
3013c588192SMat Martineau  * in constant time. Items can also be added to the tail of the list
3023c588192SMat Martineau  * and removed from the head in constant time, without further memory
3033c588192SMat Martineau  * allocs or frees.
3043c588192SMat Martineau  */
3053c588192SMat Martineau 
3063c588192SMat Martineau static int l2cap_seq_list_init(struct l2cap_seq_list *seq_list, u16 size)
3073c588192SMat Martineau {
3083c588192SMat Martineau 	size_t alloc_size, i;
3093c588192SMat Martineau 
3103c588192SMat Martineau 	/* Allocated size is a power of 2 to map sequence numbers
3113c588192SMat Martineau 	 * (which may be up to 14 bits) in to a smaller array that is
3123c588192SMat Martineau 	 * sized for the negotiated ERTM transmit windows.
3133c588192SMat Martineau 	 */
3143c588192SMat Martineau 	alloc_size = roundup_pow_of_two(size);
3153c588192SMat Martineau 
3163c588192SMat Martineau 	seq_list->list = kmalloc(sizeof(u16) * alloc_size, GFP_KERNEL);
3173c588192SMat Martineau 	if (!seq_list->list)
3183c588192SMat Martineau 		return -ENOMEM;
3193c588192SMat Martineau 
3203c588192SMat Martineau 	seq_list->mask = alloc_size - 1;
3213c588192SMat Martineau 	seq_list->head = L2CAP_SEQ_LIST_CLEAR;
3223c588192SMat Martineau 	seq_list->tail = L2CAP_SEQ_LIST_CLEAR;
3233c588192SMat Martineau 	for (i = 0; i < alloc_size; i++)
3243c588192SMat Martineau 		seq_list->list[i] = L2CAP_SEQ_LIST_CLEAR;
3253c588192SMat Martineau 
3263c588192SMat Martineau 	return 0;
3273c588192SMat Martineau }
3283c588192SMat Martineau 
3293c588192SMat Martineau static inline void l2cap_seq_list_free(struct l2cap_seq_list *seq_list)
3303c588192SMat Martineau {
3313c588192SMat Martineau 	kfree(seq_list->list);
3323c588192SMat Martineau }
3333c588192SMat Martineau 
3343c588192SMat Martineau static inline bool l2cap_seq_list_contains(struct l2cap_seq_list *seq_list,
3353c588192SMat Martineau 					   u16 seq)
3363c588192SMat Martineau {
3373c588192SMat Martineau 	/* Constant-time check for list membership */
3383c588192SMat Martineau 	return seq_list->list[seq & seq_list->mask] != L2CAP_SEQ_LIST_CLEAR;
3393c588192SMat Martineau }
3403c588192SMat Martineau 
3413c588192SMat Martineau static u16 l2cap_seq_list_remove(struct l2cap_seq_list *seq_list, u16 seq)
3423c588192SMat Martineau {
3433c588192SMat Martineau 	u16 mask = seq_list->mask;
3443c588192SMat Martineau 
3453c588192SMat Martineau 	if (seq_list->head == L2CAP_SEQ_LIST_CLEAR) {
3463c588192SMat Martineau 		/* In case someone tries to pop the head of an empty list */
3473c588192SMat Martineau 		return L2CAP_SEQ_LIST_CLEAR;
3483c588192SMat Martineau 	} else if (seq_list->head == seq) {
3493c588192SMat Martineau 		/* Head can be removed in constant time */
3503c588192SMat Martineau 		seq_list->head = seq_list->list[seq & mask];
3513c588192SMat Martineau 		seq_list->list[seq & mask] = L2CAP_SEQ_LIST_CLEAR;
3523c588192SMat Martineau 
3533c588192SMat Martineau 		if (seq_list->head == L2CAP_SEQ_LIST_TAIL) {
3543c588192SMat Martineau 			seq_list->head = L2CAP_SEQ_LIST_CLEAR;
3553c588192SMat Martineau 			seq_list->tail = L2CAP_SEQ_LIST_CLEAR;
3563c588192SMat Martineau 		}
3573c588192SMat Martineau 	} else {
3583c588192SMat Martineau 		/* Walk the list to find the sequence number */
3593c588192SMat Martineau 		u16 prev = seq_list->head;
3603c588192SMat Martineau 		while (seq_list->list[prev & mask] != seq) {
3613c588192SMat Martineau 			prev = seq_list->list[prev & mask];
3623c588192SMat Martineau 			if (prev == L2CAP_SEQ_LIST_TAIL)
3633c588192SMat Martineau 				return L2CAP_SEQ_LIST_CLEAR;
3643c588192SMat Martineau 		}
3653c588192SMat Martineau 
3663c588192SMat Martineau 		/* Unlink the number from the list and clear it */
3673c588192SMat Martineau 		seq_list->list[prev & mask] = seq_list->list[seq & mask];
3683c588192SMat Martineau 		seq_list->list[seq & mask] = L2CAP_SEQ_LIST_CLEAR;
3693c588192SMat Martineau 		if (seq_list->tail == seq)
3703c588192SMat Martineau 			seq_list->tail = prev;
3713c588192SMat Martineau 	}
3723c588192SMat Martineau 	return seq;
3733c588192SMat Martineau }
3743c588192SMat Martineau 
3753c588192SMat Martineau static inline u16 l2cap_seq_list_pop(struct l2cap_seq_list *seq_list)
3763c588192SMat Martineau {
3773c588192SMat Martineau 	/* Remove the head in constant time */
3783c588192SMat Martineau 	return l2cap_seq_list_remove(seq_list, seq_list->head);
3793c588192SMat Martineau }
3803c588192SMat Martineau 
3813c588192SMat Martineau static void l2cap_seq_list_clear(struct l2cap_seq_list *seq_list)
3823c588192SMat Martineau {
3833c588192SMat Martineau 	u16 i;
384f522ae36SGustavo Padovan 
385f522ae36SGustavo Padovan 	if (seq_list->head == L2CAP_SEQ_LIST_CLEAR)
386f522ae36SGustavo Padovan 		return;
387f522ae36SGustavo Padovan 
3883c588192SMat Martineau 	for (i = 0; i <= seq_list->mask; i++)
3893c588192SMat Martineau 		seq_list->list[i] = L2CAP_SEQ_LIST_CLEAR;
3903c588192SMat Martineau 
3913c588192SMat Martineau 	seq_list->head = L2CAP_SEQ_LIST_CLEAR;
3923c588192SMat Martineau 	seq_list->tail = L2CAP_SEQ_LIST_CLEAR;
3933c588192SMat Martineau }
3943c588192SMat Martineau 
3953c588192SMat Martineau static void l2cap_seq_list_append(struct l2cap_seq_list *seq_list, u16 seq)
3963c588192SMat Martineau {
3973c588192SMat Martineau 	u16 mask = seq_list->mask;
3983c588192SMat Martineau 
3993c588192SMat Martineau 	/* All appends happen in constant time */
4003c588192SMat Martineau 
401f522ae36SGustavo Padovan 	if (seq_list->list[seq & mask] != L2CAP_SEQ_LIST_CLEAR)
402f522ae36SGustavo Padovan 		return;
403f522ae36SGustavo Padovan 
4043c588192SMat Martineau 	if (seq_list->tail == L2CAP_SEQ_LIST_CLEAR)
4053c588192SMat Martineau 		seq_list->head = seq;
4063c588192SMat Martineau 	else
4073c588192SMat Martineau 		seq_list->list[seq_list->tail & mask] = seq;
4083c588192SMat Martineau 
4093c588192SMat Martineau 	seq_list->tail = seq;
4103c588192SMat Martineau 	seq_list->list[seq & mask] = L2CAP_SEQ_LIST_TAIL;
4113c588192SMat Martineau }
4123c588192SMat Martineau 
413721c4181SGustavo F. Padovan static void l2cap_chan_timeout(struct work_struct *work)
414ab07801dSGustavo F. Padovan {
415721c4181SGustavo F. Padovan 	struct l2cap_chan *chan = container_of(work, struct l2cap_chan,
416721c4181SGustavo F. Padovan 					       chan_timer.work);
4173df91ea2SAndrei Emeltchenko 	struct l2cap_conn *conn = chan->conn;
418ab07801dSGustavo F. Padovan 	int reason;
419ab07801dSGustavo F. Padovan 
420e05dcc32SAndrei Emeltchenko 	BT_DBG("chan %p state %s", chan, state_to_string(chan->state));
421ab07801dSGustavo F. Padovan 
4223df91ea2SAndrei Emeltchenko 	mutex_lock(&conn->chan_lock);
4236be36555SAndrei Emeltchenko 	l2cap_chan_lock(chan);
424ab07801dSGustavo F. Padovan 
42589bc500eSGustavo F. Padovan 	if (chan->state == BT_CONNECTED || chan->state == BT_CONFIG)
426ab07801dSGustavo F. Padovan 		reason = ECONNREFUSED;
42789bc500eSGustavo F. Padovan 	else if (chan->state == BT_CONNECT &&
428ab07801dSGustavo F. Padovan 		 chan->sec_level != BT_SECURITY_SDP)
429ab07801dSGustavo F. Padovan 		reason = ECONNREFUSED;
430ab07801dSGustavo F. Padovan 	else
431ab07801dSGustavo F. Padovan 		reason = ETIMEDOUT;
432ab07801dSGustavo F. Padovan 
4330f852724SGustavo F. Padovan 	l2cap_chan_close(chan, reason);
434ab07801dSGustavo F. Padovan 
4356be36555SAndrei Emeltchenko 	l2cap_chan_unlock(chan);
436ab07801dSGustavo F. Padovan 
43780b98027SGustavo Padovan 	chan->ops->close(chan);
4383df91ea2SAndrei Emeltchenko 	mutex_unlock(&conn->chan_lock);
4393df91ea2SAndrei Emeltchenko 
440371fd835SUlisses Furquim 	l2cap_chan_put(chan);
441ab07801dSGustavo F. Padovan }
442ab07801dSGustavo F. Padovan 
443eef1d9b6SGustavo Padovan struct l2cap_chan *l2cap_chan_create(void)
4440a708f8fSGustavo F. Padovan {
44548454079SGustavo F. Padovan 	struct l2cap_chan *chan;
4460a708f8fSGustavo F. Padovan 
44748454079SGustavo F. Padovan 	chan = kzalloc(sizeof(*chan), GFP_ATOMIC);
44848454079SGustavo F. Padovan 	if (!chan)
44948454079SGustavo F. Padovan 		return NULL;
4500a708f8fSGustavo F. Padovan 
451c03b355eSAndrei Emeltchenko 	mutex_init(&chan->lock);
452c03b355eSAndrei Emeltchenko 
453333055f2SGustavo F. Padovan 	write_lock(&chan_list_lock);
45423691d75SGustavo F. Padovan 	list_add(&chan->global_l, &chan_list);
455333055f2SGustavo F. Padovan 	write_unlock(&chan_list_lock);
45623691d75SGustavo F. Padovan 
457721c4181SGustavo F. Padovan 	INIT_DELAYED_WORK(&chan->chan_timer, l2cap_chan_timeout);
458ab07801dSGustavo F. Padovan 
45989bc500eSGustavo F. Padovan 	chan->state = BT_OPEN;
46089bc500eSGustavo F. Padovan 
461144ad330SSyam Sidhardhan 	kref_init(&chan->kref);
46271ba0e56SGustavo F. Padovan 
4632827011fSMat Martineau 	/* This flag is cleared in l2cap_chan_ready() */
4642827011fSMat Martineau 	set_bit(CONF_NOT_COMPLETE, &chan->conf_state);
4652827011fSMat Martineau 
466eef1d9b6SGustavo Padovan 	BT_DBG("chan %p", chan);
467abc545b8SSzymon Janc 
46848454079SGustavo F. Padovan 	return chan;
4690a708f8fSGustavo F. Padovan }
4700a708f8fSGustavo F. Padovan 
471144ad330SSyam Sidhardhan static void l2cap_chan_destroy(struct kref *kref)
4726ff5abbfSGustavo F. Padovan {
473144ad330SSyam Sidhardhan 	struct l2cap_chan *chan = container_of(kref, struct l2cap_chan, kref);
474144ad330SSyam Sidhardhan 
4754af66c69SJaganath Kanakkassery 	BT_DBG("chan %p", chan);
4764af66c69SJaganath Kanakkassery 
477333055f2SGustavo F. Padovan 	write_lock(&chan_list_lock);
47823691d75SGustavo F. Padovan 	list_del(&chan->global_l);
479333055f2SGustavo F. Padovan 	write_unlock(&chan_list_lock);
48023691d75SGustavo F. Padovan 
4814af66c69SJaganath Kanakkassery 	kfree(chan);
4826ff5abbfSGustavo F. Padovan }
4836ff5abbfSGustavo F. Padovan 
48430648372SJaganath Kanakkassery void l2cap_chan_hold(struct l2cap_chan *c)
48530648372SJaganath Kanakkassery {
486144ad330SSyam Sidhardhan 	BT_DBG("chan %p orig refcnt %d", c, atomic_read(&c->kref.refcount));
48730648372SJaganath Kanakkassery 
488144ad330SSyam Sidhardhan 	kref_get(&c->kref);
48930648372SJaganath Kanakkassery }
49030648372SJaganath Kanakkassery 
49130648372SJaganath Kanakkassery void l2cap_chan_put(struct l2cap_chan *c)
49230648372SJaganath Kanakkassery {
493144ad330SSyam Sidhardhan 	BT_DBG("chan %p orig refcnt %d", c, atomic_read(&c->kref.refcount));
49430648372SJaganath Kanakkassery 
495144ad330SSyam Sidhardhan 	kref_put(&c->kref, l2cap_chan_destroy);
49630648372SJaganath Kanakkassery }
49730648372SJaganath Kanakkassery 
498bd4b1653SAndrei Emeltchenko void l2cap_chan_set_defaults(struct l2cap_chan *chan)
499bd4b1653SAndrei Emeltchenko {
500bd4b1653SAndrei Emeltchenko 	chan->fcs  = L2CAP_FCS_CRC16;
501bd4b1653SAndrei Emeltchenko 	chan->max_tx = L2CAP_DEFAULT_MAX_TX;
502bd4b1653SAndrei Emeltchenko 	chan->tx_win = L2CAP_DEFAULT_TX_WINDOW;
503bd4b1653SAndrei Emeltchenko 	chan->tx_win_max = L2CAP_DEFAULT_TX_WINDOW;
504c20f8e35SMat Martineau 	chan->ack_win = L2CAP_DEFAULT_TX_WINDOW;
505bd4b1653SAndrei Emeltchenko 	chan->sec_level = BT_SECURITY_LOW;
506bd4b1653SAndrei Emeltchenko 
507bd4b1653SAndrei Emeltchenko 	set_bit(FLAG_FORCE_ACTIVE, &chan->flags);
508bd4b1653SAndrei Emeltchenko }
509bd4b1653SAndrei Emeltchenko 
51093c3e8f5SAndrei Emeltchenko void __l2cap_chan_add(struct l2cap_conn *conn, struct l2cap_chan *chan)
5110a708f8fSGustavo F. Padovan {
5120a708f8fSGustavo F. Padovan 	BT_DBG("conn %p, psm 0x%2.2x, dcid 0x%4.4x", conn,
513097db76cSAndrei Emeltchenko 	       __le16_to_cpu(chan->psm), chan->dcid);
5140a708f8fSGustavo F. Padovan 
5159f5a0d7bSAndrei Emeltchenko 	conn->disc_reason = HCI_ERROR_REMOTE_USER_TERM;
5160a708f8fSGustavo F. Padovan 
5178c1d787bSGustavo F. Padovan 	chan->conn = conn;
5180a708f8fSGustavo F. Padovan 
5195491120eSAndrei Emeltchenko 	switch (chan->chan_type) {
5205491120eSAndrei Emeltchenko 	case L2CAP_CHAN_CONN_ORIENTED:
521b62f328bSVille Tervo 		if (conn->hcon->type == LE_LINK) {
522b62f328bSVille Tervo 			/* LE connection */
5236fcb06a2SAndre Guedes 			chan->omtu = L2CAP_DEFAULT_MTU;
5249f22398cSJohan Hedberg 			if (chan->dcid == L2CAP_CID_ATT)
525073d1cf3SJohan Hedberg 				chan->scid = L2CAP_CID_ATT;
5269f22398cSJohan Hedberg 			else
5279f22398cSJohan Hedberg 				chan->scid = l2cap_alloc_cid(conn);
528b62f328bSVille Tervo 		} else {
5290a708f8fSGustavo F. Padovan 			/* Alloc CID for connection-oriented socket */
530fe4128e0SGustavo F. Padovan 			chan->scid = l2cap_alloc_cid(conn);
5310c1bc5c6SGustavo F. Padovan 			chan->omtu = L2CAP_DEFAULT_MTU;
532b62f328bSVille Tervo 		}
5335491120eSAndrei Emeltchenko 		break;
5345491120eSAndrei Emeltchenko 
5355491120eSAndrei Emeltchenko 	case L2CAP_CHAN_CONN_LESS:
5360a708f8fSGustavo F. Padovan 		/* Connectionless socket */
537fe4128e0SGustavo F. Padovan 		chan->scid = L2CAP_CID_CONN_LESS;
538fe4128e0SGustavo F. Padovan 		chan->dcid = L2CAP_CID_CONN_LESS;
5390c1bc5c6SGustavo F. Padovan 		chan->omtu = L2CAP_DEFAULT_MTU;
5405491120eSAndrei Emeltchenko 		break;
5415491120eSAndrei Emeltchenko 
542416fa752SAndrei Emeltchenko 	case L2CAP_CHAN_CONN_FIX_A2MP:
543416fa752SAndrei Emeltchenko 		chan->scid = L2CAP_CID_A2MP;
544416fa752SAndrei Emeltchenko 		chan->dcid = L2CAP_CID_A2MP;
545416fa752SAndrei Emeltchenko 		chan->omtu = L2CAP_A2MP_DEFAULT_MTU;
546416fa752SAndrei Emeltchenko 		chan->imtu = L2CAP_A2MP_DEFAULT_MTU;
547416fa752SAndrei Emeltchenko 		break;
548416fa752SAndrei Emeltchenko 
5495491120eSAndrei Emeltchenko 	default:
5500a708f8fSGustavo F. Padovan 		/* Raw socket can send/recv signalling messages only */
551fe4128e0SGustavo F. Padovan 		chan->scid = L2CAP_CID_SIGNALING;
552fe4128e0SGustavo F. Padovan 		chan->dcid = L2CAP_CID_SIGNALING;
5530c1bc5c6SGustavo F. Padovan 		chan->omtu = L2CAP_DEFAULT_MTU;
5540a708f8fSGustavo F. Padovan 	}
5550a708f8fSGustavo F. Padovan 
5568f7975b1SAndrei Emeltchenko 	chan->local_id		= L2CAP_BESTEFFORT_ID;
5578f7975b1SAndrei Emeltchenko 	chan->local_stype	= L2CAP_SERV_BESTEFFORT;
5588f7975b1SAndrei Emeltchenko 	chan->local_msdu	= L2CAP_DEFAULT_MAX_SDU_SIZE;
5598f7975b1SAndrei Emeltchenko 	chan->local_sdu_itime	= L2CAP_DEFAULT_SDU_ITIME;
5608f7975b1SAndrei Emeltchenko 	chan->local_acc_lat	= L2CAP_DEFAULT_ACC_LAT;
5618936fa6dSAndrei Emeltchenko 	chan->local_flush_to	= L2CAP_EFS_DEFAULT_FLUSH_TO;
5628f7975b1SAndrei Emeltchenko 
563371fd835SUlisses Furquim 	l2cap_chan_hold(chan);
564baa7e1faSGustavo F. Padovan 
5655ee9891dSJohan Hedberg 	hci_conn_hold(conn->hcon);
5665ee9891dSJohan Hedberg 
5673df91ea2SAndrei Emeltchenko 	list_add(&chan->list, &conn->chan_l);
568643162a8SAndrei Emeltchenko }
569643162a8SAndrei Emeltchenko 
570466f8004SAndrei Emeltchenko void l2cap_chan_add(struct l2cap_conn *conn, struct l2cap_chan *chan)
571643162a8SAndrei Emeltchenko {
572643162a8SAndrei Emeltchenko 	mutex_lock(&conn->chan_lock);
573643162a8SAndrei Emeltchenko 	__l2cap_chan_add(conn, chan);
5743df91ea2SAndrei Emeltchenko 	mutex_unlock(&conn->chan_lock);
5750a708f8fSGustavo F. Padovan }
5760a708f8fSGustavo F. Padovan 
577466f8004SAndrei Emeltchenko void l2cap_chan_del(struct l2cap_chan *chan, int err)
5780a708f8fSGustavo F. Padovan {
5798c1d787bSGustavo F. Padovan 	struct l2cap_conn *conn = chan->conn;
5800a708f8fSGustavo F. Padovan 
581c9b66675SGustavo F. Padovan 	__clear_chan_timer(chan);
5820a708f8fSGustavo F. Padovan 
58349208c9cSGustavo F. Padovan 	BT_DBG("chan %p, conn %p, err %d", chan, conn, err);
5840a708f8fSGustavo F. Padovan 
5850a708f8fSGustavo F. Padovan 	if (conn) {
58656f60984SAndrei Emeltchenko 		struct amp_mgr *mgr = conn->hcon->amp_mgr;
587baa7e1faSGustavo F. Padovan 		/* Delete from channel list */
5883df91ea2SAndrei Emeltchenko 		list_del(&chan->list);
5893d57dc68SGustavo F. Padovan 
590371fd835SUlisses Furquim 		l2cap_chan_put(chan);
591baa7e1faSGustavo F. Padovan 
5928c1d787bSGustavo F. Padovan 		chan->conn = NULL;
5933cabbfdaSAndrei Emeltchenko 
5943cabbfdaSAndrei Emeltchenko 		if (chan->chan_type != L2CAP_CHAN_CONN_FIX_A2MP)
59576a68ba0SDavid Herrmann 			hci_conn_drop(conn->hcon);
59656f60984SAndrei Emeltchenko 
59756f60984SAndrei Emeltchenko 		if (mgr && mgr->bredr_chan == chan)
59856f60984SAndrei Emeltchenko 			mgr->bredr_chan = NULL;
5990a708f8fSGustavo F. Padovan 	}
6000a708f8fSGustavo F. Padovan 
601419e08c1SAndrei Emeltchenko 	if (chan->hs_hchan) {
602419e08c1SAndrei Emeltchenko 		struct hci_chan *hs_hchan = chan->hs_hchan;
603419e08c1SAndrei Emeltchenko 
604419e08c1SAndrei Emeltchenko 		BT_DBG("chan %p disconnect hs_hchan %p", chan, hs_hchan);
605419e08c1SAndrei Emeltchenko 		amp_disconnect_logical_link(hs_hchan);
606419e08c1SAndrei Emeltchenko 	}
607419e08c1SAndrei Emeltchenko 
608c0df7f6eSAndrei Emeltchenko 	chan->ops->teardown(chan, err);
6096be36555SAndrei Emeltchenko 
6102827011fSMat Martineau 	if (test_bit(CONF_NOT_COMPLETE, &chan->conf_state))
6116ff5abbfSGustavo F. Padovan 		return;
6122ead70b8SGustavo F. Padovan 
613ee556f66SGustavo Padovan 	switch(chan->mode) {
614ee556f66SGustavo Padovan 	case L2CAP_MODE_BASIC:
615ee556f66SGustavo Padovan 		break;
6160a708f8fSGustavo F. Padovan 
617ee556f66SGustavo Padovan 	case L2CAP_MODE_ERTM:
6181a09bcb9SGustavo F. Padovan 		__clear_retrans_timer(chan);
6191a09bcb9SGustavo F. Padovan 		__clear_monitor_timer(chan);
6201a09bcb9SGustavo F. Padovan 		__clear_ack_timer(chan);
6210a708f8fSGustavo F. Padovan 
622f1c6775bSGustavo F. Padovan 		skb_queue_purge(&chan->srej_q);
6230a708f8fSGustavo F. Padovan 
6243c588192SMat Martineau 		l2cap_seq_list_free(&chan->srej_list);
6253c588192SMat Martineau 		l2cap_seq_list_free(&chan->retrans_list);
626ee556f66SGustavo Padovan 
627ee556f66SGustavo Padovan 		/* fall through */
628ee556f66SGustavo Padovan 
629ee556f66SGustavo Padovan 	case L2CAP_MODE_STREAMING:
630ee556f66SGustavo Padovan 		skb_queue_purge(&chan->tx_q);
631ee556f66SGustavo Padovan 		break;
6320a708f8fSGustavo F. Padovan 	}
633ee556f66SGustavo Padovan 
634ee556f66SGustavo Padovan 	return;
6350a708f8fSGustavo F. Padovan }
6360a708f8fSGustavo F. Padovan 
6370f852724SGustavo F. Padovan void l2cap_chan_close(struct l2cap_chan *chan, int reason)
6384519de9aSGustavo F. Padovan {
6394519de9aSGustavo F. Padovan 	struct l2cap_conn *conn = chan->conn;
6404519de9aSGustavo F. Padovan 
6417eafc59eSMarcel Holtmann 	BT_DBG("chan %p state %s", chan, state_to_string(chan->state));
6424519de9aSGustavo F. Padovan 
64389bc500eSGustavo F. Padovan 	switch (chan->state) {
6444519de9aSGustavo F. Padovan 	case BT_LISTEN:
645c0df7f6eSAndrei Emeltchenko 		chan->ops->teardown(chan, 0);
6464519de9aSGustavo F. Padovan 		break;
6474519de9aSGustavo F. Padovan 
6484519de9aSGustavo F. Padovan 	case BT_CONNECTED:
6494519de9aSGustavo F. Padovan 	case BT_CONFIG:
650715ec005SGustavo F. Padovan 		if (chan->chan_type == L2CAP_CHAN_CONN_ORIENTED &&
6514519de9aSGustavo F. Padovan 		    conn->hcon->type == ACL_LINK) {
6528d836d71SGustavo Padovan 			__set_chan_timer(chan, chan->ops->get_sndtimeo(chan));
6535e4e3972SAndrei Emeltchenko 			l2cap_send_disconn_req(chan, reason);
6544519de9aSGustavo F. Padovan 		} else
6554519de9aSGustavo F. Padovan 			l2cap_chan_del(chan, reason);
6564519de9aSGustavo F. Padovan 		break;
6574519de9aSGustavo F. Padovan 
6584519de9aSGustavo F. Padovan 	case BT_CONNECT2:
659715ec005SGustavo F. Padovan 		if (chan->chan_type == L2CAP_CHAN_CONN_ORIENTED &&
6604519de9aSGustavo F. Padovan 		    conn->hcon->type == ACL_LINK) {
6614519de9aSGustavo F. Padovan 			struct l2cap_conn_rsp rsp;
6624519de9aSGustavo F. Padovan 			__u16 result;
6634519de9aSGustavo F. Padovan 
664bdc25783SMarcel Holtmann 			if (test_bit(FLAG_DEFER_SETUP, &chan->flags))
6654519de9aSGustavo F. Padovan 				result = L2CAP_CR_SEC_BLOCK;
6664519de9aSGustavo F. Padovan 			else
6674519de9aSGustavo F. Padovan 				result = L2CAP_CR_BAD_PSM;
668bdc25783SMarcel Holtmann 
66989bc500eSGustavo F. Padovan 			l2cap_state_change(chan, BT_DISCONN);
6704519de9aSGustavo F. Padovan 
6714519de9aSGustavo F. Padovan 			rsp.scid   = cpu_to_le16(chan->dcid);
6724519de9aSGustavo F. Padovan 			rsp.dcid   = cpu_to_le16(chan->scid);
6734519de9aSGustavo F. Padovan 			rsp.result = cpu_to_le16(result);
674ac73498cSAndrei Emeltchenko 			rsp.status = __constant_cpu_to_le16(L2CAP_CS_NO_INFO);
6754519de9aSGustavo F. Padovan 			l2cap_send_cmd(conn, chan->ident, L2CAP_CONN_RSP,
6764519de9aSGustavo F. Padovan 				       sizeof(rsp), &rsp);
6774519de9aSGustavo F. Padovan 		}
6784519de9aSGustavo F. Padovan 
6794519de9aSGustavo F. Padovan 		l2cap_chan_del(chan, reason);
6804519de9aSGustavo F. Padovan 		break;
6814519de9aSGustavo F. Padovan 
6824519de9aSGustavo F. Padovan 	case BT_CONNECT:
6834519de9aSGustavo F. Padovan 	case BT_DISCONN:
6844519de9aSGustavo F. Padovan 		l2cap_chan_del(chan, reason);
6854519de9aSGustavo F. Padovan 		break;
6864519de9aSGustavo F. Padovan 
6874519de9aSGustavo F. Padovan 	default:
688c0df7f6eSAndrei Emeltchenko 		chan->ops->teardown(chan, 0);
6894519de9aSGustavo F. Padovan 		break;
6904519de9aSGustavo F. Padovan 	}
6914519de9aSGustavo F. Padovan }
6924519de9aSGustavo F. Padovan 
6934343478fSGustavo F. Padovan static inline u8 l2cap_get_auth_type(struct l2cap_chan *chan)
6940a708f8fSGustavo F. Padovan {
6956a974b50SMarcel Holtmann 	switch (chan->chan_type) {
6966a974b50SMarcel Holtmann 	case L2CAP_CHAN_RAW:
6974343478fSGustavo F. Padovan 		switch (chan->sec_level) {
6980a708f8fSGustavo F. Padovan 		case BT_SECURITY_HIGH:
6990a708f8fSGustavo F. Padovan 			return HCI_AT_DEDICATED_BONDING_MITM;
7000a708f8fSGustavo F. Padovan 		case BT_SECURITY_MEDIUM:
7010a708f8fSGustavo F. Padovan 			return HCI_AT_DEDICATED_BONDING;
7020a708f8fSGustavo F. Padovan 		default:
7030a708f8fSGustavo F. Padovan 			return HCI_AT_NO_BONDING;
7040a708f8fSGustavo F. Padovan 		}
7056a974b50SMarcel Holtmann 		break;
7063124b843SMarcel Holtmann 	case L2CAP_CHAN_CONN_LESS:
7073124b843SMarcel Holtmann 		if (chan->psm == __constant_cpu_to_le16(L2CAP_PSM_3DSP)) {
7083124b843SMarcel Holtmann 			if (chan->sec_level == BT_SECURITY_LOW)
7093124b843SMarcel Holtmann 				chan->sec_level = BT_SECURITY_SDP;
7103124b843SMarcel Holtmann 		}
7113124b843SMarcel Holtmann 		if (chan->sec_level == BT_SECURITY_HIGH)
7123124b843SMarcel Holtmann 			return HCI_AT_NO_BONDING_MITM;
7133124b843SMarcel Holtmann 		else
7143124b843SMarcel Holtmann 			return HCI_AT_NO_BONDING;
7153124b843SMarcel Holtmann 		break;
7166a974b50SMarcel Holtmann 	case L2CAP_CHAN_CONN_ORIENTED:
7176a974b50SMarcel Holtmann 		if (chan->psm == __constant_cpu_to_le16(L2CAP_PSM_SDP)) {
7184343478fSGustavo F. Padovan 			if (chan->sec_level == BT_SECURITY_LOW)
7194343478fSGustavo F. Padovan 				chan->sec_level = BT_SECURITY_SDP;
7200a708f8fSGustavo F. Padovan 
7214343478fSGustavo F. Padovan 			if (chan->sec_level == BT_SECURITY_HIGH)
7220a708f8fSGustavo F. Padovan 				return HCI_AT_NO_BONDING_MITM;
7230a708f8fSGustavo F. Padovan 			else
7240a708f8fSGustavo F. Padovan 				return HCI_AT_NO_BONDING;
7256a974b50SMarcel Holtmann 		}
7266a974b50SMarcel Holtmann 		/* fall through */
7276a974b50SMarcel Holtmann 	default:
7284343478fSGustavo F. Padovan 		switch (chan->sec_level) {
7290a708f8fSGustavo F. Padovan 		case BT_SECURITY_HIGH:
7300a708f8fSGustavo F. Padovan 			return HCI_AT_GENERAL_BONDING_MITM;
7310a708f8fSGustavo F. Padovan 		case BT_SECURITY_MEDIUM:
7320a708f8fSGustavo F. Padovan 			return HCI_AT_GENERAL_BONDING;
7330a708f8fSGustavo F. Padovan 		default:
7340a708f8fSGustavo F. Padovan 			return HCI_AT_NO_BONDING;
7350a708f8fSGustavo F. Padovan 		}
7366a974b50SMarcel Holtmann 		break;
7370a708f8fSGustavo F. Padovan 	}
7380a708f8fSGustavo F. Padovan }
7390a708f8fSGustavo F. Padovan 
7400a708f8fSGustavo F. Padovan /* Service level security */
741d45fc423SGustavo F. Padovan int l2cap_chan_check_security(struct l2cap_chan *chan)
7420a708f8fSGustavo F. Padovan {
7438c1d787bSGustavo F. Padovan 	struct l2cap_conn *conn = chan->conn;
7440a708f8fSGustavo F. Padovan 	__u8 auth_type;
7450a708f8fSGustavo F. Padovan 
7464343478fSGustavo F. Padovan 	auth_type = l2cap_get_auth_type(chan);
7470a708f8fSGustavo F. Padovan 
7484343478fSGustavo F. Padovan 	return hci_conn_security(conn->hcon, chan->sec_level, auth_type);
7490a708f8fSGustavo F. Padovan }
7500a708f8fSGustavo F. Padovan 
751b5ad8b7fSJohannes Berg static u8 l2cap_get_ident(struct l2cap_conn *conn)
7520a708f8fSGustavo F. Padovan {
7530a708f8fSGustavo F. Padovan 	u8 id;
7540a708f8fSGustavo F. Padovan 
7550a708f8fSGustavo F. Padovan 	/* Get next available identificator.
7560a708f8fSGustavo F. Padovan 	 *    1 - 128 are used by kernel.
7570a708f8fSGustavo F. Padovan 	 *  129 - 199 are reserved.
7580a708f8fSGustavo F. Padovan 	 *  200 - 254 are used by utilities like l2ping, etc.
7590a708f8fSGustavo F. Padovan 	 */
7600a708f8fSGustavo F. Padovan 
761333055f2SGustavo F. Padovan 	spin_lock(&conn->lock);
7620a708f8fSGustavo F. Padovan 
7630a708f8fSGustavo F. Padovan 	if (++conn->tx_ident > 128)
7640a708f8fSGustavo F. Padovan 		conn->tx_ident = 1;
7650a708f8fSGustavo F. Padovan 
7660a708f8fSGustavo F. Padovan 	id = conn->tx_ident;
7670a708f8fSGustavo F. Padovan 
768333055f2SGustavo F. Padovan 	spin_unlock(&conn->lock);
7690a708f8fSGustavo F. Padovan 
7700a708f8fSGustavo F. Padovan 	return id;
7710a708f8fSGustavo F. Padovan }
7720a708f8fSGustavo F. Padovan 
7732d792818SGustavo Padovan static void l2cap_send_cmd(struct l2cap_conn *conn, u8 ident, u8 code, u16 len,
7742d792818SGustavo Padovan 			   void *data)
7750a708f8fSGustavo F. Padovan {
7760a708f8fSGustavo F. Padovan 	struct sk_buff *skb = l2cap_build_cmd(conn, code, ident, len, data);
7770a708f8fSGustavo F. Padovan 	u8 flags;
7780a708f8fSGustavo F. Padovan 
7790a708f8fSGustavo F. Padovan 	BT_DBG("code 0x%2.2x", code);
7800a708f8fSGustavo F. Padovan 
7810a708f8fSGustavo F. Padovan 	if (!skb)
7820a708f8fSGustavo F. Padovan 		return;
7830a708f8fSGustavo F. Padovan 
7840a708f8fSGustavo F. Padovan 	if (lmp_no_flush_capable(conn->hcon->hdev))
7850a708f8fSGustavo F. Padovan 		flags = ACL_START_NO_FLUSH;
7860a708f8fSGustavo F. Padovan 	else
7870a708f8fSGustavo F. Padovan 		flags = ACL_START;
7880a708f8fSGustavo F. Padovan 
78914b12d0bSJaikumar Ganesh 	bt_cb(skb)->force_active = BT_POWER_FORCE_ACTIVE_ON;
7905e59b791SLuiz Augusto von Dentz 	skb->priority = HCI_PRIO_MAX;
79114b12d0bSJaikumar Ganesh 
79273d80debSLuiz Augusto von Dentz 	hci_send_acl(conn->hchan, skb, flags);
7930a708f8fSGustavo F. Padovan }
7940a708f8fSGustavo F. Padovan 
79502b0fbb9SMat Martineau static bool __chan_is_moving(struct l2cap_chan *chan)
79602b0fbb9SMat Martineau {
79702b0fbb9SMat Martineau 	return chan->move_state != L2CAP_MOVE_STABLE &&
79802b0fbb9SMat Martineau 	       chan->move_state != L2CAP_MOVE_WAIT_PREPARE;
79902b0fbb9SMat Martineau }
80002b0fbb9SMat Martineau 
80173d80debSLuiz Augusto von Dentz static void l2cap_do_send(struct l2cap_chan *chan, struct sk_buff *skb)
80273d80debSLuiz Augusto von Dentz {
80373d80debSLuiz Augusto von Dentz 	struct hci_conn *hcon = chan->conn->hcon;
80473d80debSLuiz Augusto von Dentz 	u16 flags;
80573d80debSLuiz Augusto von Dentz 
80673d80debSLuiz Augusto von Dentz 	BT_DBG("chan %p, skb %p len %d priority %u", chan, skb, skb->len,
80773d80debSLuiz Augusto von Dentz 	       skb->priority);
80873d80debSLuiz Augusto von Dentz 
809d5f8a75dSMat Martineau 	if (chan->hs_hcon && !__chan_is_moving(chan)) {
810d5f8a75dSMat Martineau 		if (chan->hs_hchan)
811d5f8a75dSMat Martineau 			hci_send_acl(chan->hs_hchan, skb, ACL_COMPLETE);
812d5f8a75dSMat Martineau 		else
813d5f8a75dSMat Martineau 			kfree_skb(skb);
814d5f8a75dSMat Martineau 
815d5f8a75dSMat Martineau 		return;
816d5f8a75dSMat Martineau 	}
817d5f8a75dSMat Martineau 
81873d80debSLuiz Augusto von Dentz 	if (!test_bit(FLAG_FLUSHABLE, &chan->flags) &&
81973d80debSLuiz Augusto von Dentz 	    lmp_no_flush_capable(hcon->hdev))
82073d80debSLuiz Augusto von Dentz 		flags = ACL_START_NO_FLUSH;
82173d80debSLuiz Augusto von Dentz 	else
82273d80debSLuiz Augusto von Dentz 		flags = ACL_START;
82373d80debSLuiz Augusto von Dentz 
82473d80debSLuiz Augusto von Dentz 	bt_cb(skb)->force_active = test_bit(FLAG_FORCE_ACTIVE, &chan->flags);
82573d80debSLuiz Augusto von Dentz 	hci_send_acl(chan->conn->hchan, skb, flags);
8260a708f8fSGustavo F. Padovan }
8270a708f8fSGustavo F. Padovan 
828b5c6aaedSMat Martineau static void __unpack_enhanced_control(u16 enh, struct l2cap_ctrl *control)
829b5c6aaedSMat Martineau {
830b5c6aaedSMat Martineau 	control->reqseq = (enh & L2CAP_CTRL_REQSEQ) >> L2CAP_CTRL_REQSEQ_SHIFT;
831b5c6aaedSMat Martineau 	control->final = (enh & L2CAP_CTRL_FINAL) >> L2CAP_CTRL_FINAL_SHIFT;
832b5c6aaedSMat Martineau 
833b5c6aaedSMat Martineau 	if (enh & L2CAP_CTRL_FRAME_TYPE) {
834b5c6aaedSMat Martineau 		/* S-Frame */
835b5c6aaedSMat Martineau 		control->sframe = 1;
836b5c6aaedSMat Martineau 		control->poll = (enh & L2CAP_CTRL_POLL) >> L2CAP_CTRL_POLL_SHIFT;
837b5c6aaedSMat Martineau 		control->super = (enh & L2CAP_CTRL_SUPERVISE) >> L2CAP_CTRL_SUPER_SHIFT;
838b5c6aaedSMat Martineau 
839b5c6aaedSMat Martineau 		control->sar = 0;
840b5c6aaedSMat Martineau 		control->txseq = 0;
841b5c6aaedSMat Martineau 	} else {
842b5c6aaedSMat Martineau 		/* I-Frame */
843b5c6aaedSMat Martineau 		control->sframe = 0;
844b5c6aaedSMat Martineau 		control->sar = (enh & L2CAP_CTRL_SAR) >> L2CAP_CTRL_SAR_SHIFT;
845b5c6aaedSMat Martineau 		control->txseq = (enh & L2CAP_CTRL_TXSEQ) >> L2CAP_CTRL_TXSEQ_SHIFT;
846b5c6aaedSMat Martineau 
847b5c6aaedSMat Martineau 		control->poll = 0;
848b5c6aaedSMat Martineau 		control->super = 0;
849b5c6aaedSMat Martineau 	}
850b5c6aaedSMat Martineau }
851b5c6aaedSMat Martineau 
852b5c6aaedSMat Martineau static void __unpack_extended_control(u32 ext, struct l2cap_ctrl *control)
853b5c6aaedSMat Martineau {
854b5c6aaedSMat Martineau 	control->reqseq = (ext & L2CAP_EXT_CTRL_REQSEQ) >> L2CAP_EXT_CTRL_REQSEQ_SHIFT;
855b5c6aaedSMat Martineau 	control->final = (ext & L2CAP_EXT_CTRL_FINAL) >> L2CAP_EXT_CTRL_FINAL_SHIFT;
856b5c6aaedSMat Martineau 
857b5c6aaedSMat Martineau 	if (ext & L2CAP_EXT_CTRL_FRAME_TYPE) {
858b5c6aaedSMat Martineau 		/* S-Frame */
859b5c6aaedSMat Martineau 		control->sframe = 1;
860b5c6aaedSMat Martineau 		control->poll = (ext & L2CAP_EXT_CTRL_POLL) >> L2CAP_EXT_CTRL_POLL_SHIFT;
861b5c6aaedSMat Martineau 		control->super = (ext & L2CAP_EXT_CTRL_SUPERVISE) >> L2CAP_EXT_CTRL_SUPER_SHIFT;
862b5c6aaedSMat Martineau 
863b5c6aaedSMat Martineau 		control->sar = 0;
864b5c6aaedSMat Martineau 		control->txseq = 0;
865b5c6aaedSMat Martineau 	} else {
866b5c6aaedSMat Martineau 		/* I-Frame */
867b5c6aaedSMat Martineau 		control->sframe = 0;
868b5c6aaedSMat Martineau 		control->sar = (ext & L2CAP_EXT_CTRL_SAR) >> L2CAP_EXT_CTRL_SAR_SHIFT;
869b5c6aaedSMat Martineau 		control->txseq = (ext & L2CAP_EXT_CTRL_TXSEQ) >> L2CAP_EXT_CTRL_TXSEQ_SHIFT;
870b5c6aaedSMat Martineau 
871b5c6aaedSMat Martineau 		control->poll = 0;
872b5c6aaedSMat Martineau 		control->super = 0;
873b5c6aaedSMat Martineau 	}
874b5c6aaedSMat Martineau }
875b5c6aaedSMat Martineau 
876b5c6aaedSMat Martineau static inline void __unpack_control(struct l2cap_chan *chan,
877b5c6aaedSMat Martineau 				    struct sk_buff *skb)
878b5c6aaedSMat Martineau {
879b5c6aaedSMat Martineau 	if (test_bit(FLAG_EXT_CTRL, &chan->flags)) {
880b5c6aaedSMat Martineau 		__unpack_extended_control(get_unaligned_le32(skb->data),
881b5c6aaedSMat Martineau 					  &bt_cb(skb)->control);
882cec8ab6eSMat Martineau 		skb_pull(skb, L2CAP_EXT_CTRL_SIZE);
883b5c6aaedSMat Martineau 	} else {
884b5c6aaedSMat Martineau 		__unpack_enhanced_control(get_unaligned_le16(skb->data),
885b5c6aaedSMat Martineau 					  &bt_cb(skb)->control);
886cec8ab6eSMat Martineau 		skb_pull(skb, L2CAP_ENH_CTRL_SIZE);
887b5c6aaedSMat Martineau 	}
888b5c6aaedSMat Martineau }
889b5c6aaedSMat Martineau 
890b5c6aaedSMat Martineau static u32 __pack_extended_control(struct l2cap_ctrl *control)
891b5c6aaedSMat Martineau {
892b5c6aaedSMat Martineau 	u32 packed;
893b5c6aaedSMat Martineau 
894b5c6aaedSMat Martineau 	packed = control->reqseq << L2CAP_EXT_CTRL_REQSEQ_SHIFT;
895b5c6aaedSMat Martineau 	packed |= control->final << L2CAP_EXT_CTRL_FINAL_SHIFT;
896b5c6aaedSMat Martineau 
897b5c6aaedSMat Martineau 	if (control->sframe) {
898b5c6aaedSMat Martineau 		packed |= control->poll << L2CAP_EXT_CTRL_POLL_SHIFT;
899b5c6aaedSMat Martineau 		packed |= control->super << L2CAP_EXT_CTRL_SUPER_SHIFT;
900b5c6aaedSMat Martineau 		packed |= L2CAP_EXT_CTRL_FRAME_TYPE;
901b5c6aaedSMat Martineau 	} else {
902b5c6aaedSMat Martineau 		packed |= control->sar << L2CAP_EXT_CTRL_SAR_SHIFT;
903b5c6aaedSMat Martineau 		packed |= control->txseq << L2CAP_EXT_CTRL_TXSEQ_SHIFT;
904b5c6aaedSMat Martineau 	}
905b5c6aaedSMat Martineau 
906b5c6aaedSMat Martineau 	return packed;
907b5c6aaedSMat Martineau }
908b5c6aaedSMat Martineau 
909b5c6aaedSMat Martineau static u16 __pack_enhanced_control(struct l2cap_ctrl *control)
910b5c6aaedSMat Martineau {
911b5c6aaedSMat Martineau 	u16 packed;
912b5c6aaedSMat Martineau 
913b5c6aaedSMat Martineau 	packed = control->reqseq << L2CAP_CTRL_REQSEQ_SHIFT;
914b5c6aaedSMat Martineau 	packed |= control->final << L2CAP_CTRL_FINAL_SHIFT;
915b5c6aaedSMat Martineau 
916b5c6aaedSMat Martineau 	if (control->sframe) {
917b5c6aaedSMat Martineau 		packed |= control->poll << L2CAP_CTRL_POLL_SHIFT;
918b5c6aaedSMat Martineau 		packed |= control->super << L2CAP_CTRL_SUPER_SHIFT;
919b5c6aaedSMat Martineau 		packed |= L2CAP_CTRL_FRAME_TYPE;
920b5c6aaedSMat Martineau 	} else {
921b5c6aaedSMat Martineau 		packed |= control->sar << L2CAP_CTRL_SAR_SHIFT;
922b5c6aaedSMat Martineau 		packed |= control->txseq << L2CAP_CTRL_TXSEQ_SHIFT;
923b5c6aaedSMat Martineau 	}
924b5c6aaedSMat Martineau 
925b5c6aaedSMat Martineau 	return packed;
926b5c6aaedSMat Martineau }
927b5c6aaedSMat Martineau 
928b5c6aaedSMat Martineau static inline void __pack_control(struct l2cap_chan *chan,
929b5c6aaedSMat Martineau 				  struct l2cap_ctrl *control,
930b5c6aaedSMat Martineau 				  struct sk_buff *skb)
931b5c6aaedSMat Martineau {
932b5c6aaedSMat Martineau 	if (test_bit(FLAG_EXT_CTRL, &chan->flags)) {
933b5c6aaedSMat Martineau 		put_unaligned_le32(__pack_extended_control(control),
934b5c6aaedSMat Martineau 				   skb->data + L2CAP_HDR_SIZE);
935b5c6aaedSMat Martineau 	} else {
936b5c6aaedSMat Martineau 		put_unaligned_le16(__pack_enhanced_control(control),
937b5c6aaedSMat Martineau 				   skb->data + L2CAP_HDR_SIZE);
938b5c6aaedSMat Martineau 	}
939b5c6aaedSMat Martineau }
940b5c6aaedSMat Martineau 
941ba7aa64fSGustavo Padovan static inline unsigned int __ertm_hdr_size(struct l2cap_chan *chan)
942ba7aa64fSGustavo Padovan {
943ba7aa64fSGustavo Padovan 	if (test_bit(FLAG_EXT_CTRL, &chan->flags))
944ba7aa64fSGustavo Padovan 		return L2CAP_EXT_HDR_SIZE;
945ba7aa64fSGustavo Padovan 	else
946ba7aa64fSGustavo Padovan 		return L2CAP_ENH_HDR_SIZE;
947ba7aa64fSGustavo Padovan }
948ba7aa64fSGustavo Padovan 
949a67d7f6fSMat Martineau static struct sk_buff *l2cap_create_sframe_pdu(struct l2cap_chan *chan,
950a67d7f6fSMat Martineau 					       u32 control)
9510a708f8fSGustavo F. Padovan {
9520a708f8fSGustavo F. Padovan 	struct sk_buff *skb;
9530a708f8fSGustavo F. Padovan 	struct l2cap_hdr *lh;
954ba7aa64fSGustavo Padovan 	int hlen = __ertm_hdr_size(chan);
9550a708f8fSGustavo F. Padovan 
9560a708f8fSGustavo F. Padovan 	if (chan->fcs == L2CAP_FCS_CRC16)
95703a51213SAndrei Emeltchenko 		hlen += L2CAP_FCS_SIZE;
9580a708f8fSGustavo F. Padovan 
959a67d7f6fSMat Martineau 	skb = bt_skb_alloc(hlen, GFP_KERNEL);
9600a708f8fSGustavo F. Padovan 
9610a708f8fSGustavo F. Padovan 	if (!skb)
962a67d7f6fSMat Martineau 		return ERR_PTR(-ENOMEM);
9630a708f8fSGustavo F. Padovan 
9640a708f8fSGustavo F. Padovan 	lh = (struct l2cap_hdr *) skb_put(skb, L2CAP_HDR_SIZE);
9650a708f8fSGustavo F. Padovan 	lh->len = cpu_to_le16(hlen - L2CAP_HDR_SIZE);
966fe4128e0SGustavo F. Padovan 	lh->cid = cpu_to_le16(chan->dcid);
96788843ab0SAndrei Emeltchenko 
968a67d7f6fSMat Martineau 	if (test_bit(FLAG_EXT_CTRL, &chan->flags))
969a67d7f6fSMat Martineau 		put_unaligned_le32(control, skb_put(skb, L2CAP_EXT_CTRL_SIZE));
970a67d7f6fSMat Martineau 	else
971a67d7f6fSMat Martineau 		put_unaligned_le16(control, skb_put(skb, L2CAP_ENH_CTRL_SIZE));
9720a708f8fSGustavo F. Padovan 
97347d1ec61SGustavo F. Padovan 	if (chan->fcs == L2CAP_FCS_CRC16) {
974a67d7f6fSMat Martineau 		u16 fcs = crc16(0, (u8 *)skb->data, skb->len);
97503a51213SAndrei Emeltchenko 		put_unaligned_le16(fcs, skb_put(skb, L2CAP_FCS_SIZE));
9760a708f8fSGustavo F. Padovan 	}
9770a708f8fSGustavo F. Padovan 
97873d80debSLuiz Augusto von Dentz 	skb->priority = HCI_PRIO_MAX;
979a67d7f6fSMat Martineau 	return skb;
980a67d7f6fSMat Martineau }
981a67d7f6fSMat Martineau 
982a67d7f6fSMat Martineau static void l2cap_send_sframe(struct l2cap_chan *chan,
983a67d7f6fSMat Martineau 			      struct l2cap_ctrl *control)
984a67d7f6fSMat Martineau {
985a67d7f6fSMat Martineau 	struct sk_buff *skb;
986a67d7f6fSMat Martineau 	u32 control_field;
987a67d7f6fSMat Martineau 
988a67d7f6fSMat Martineau 	BT_DBG("chan %p, control %p", chan, control);
989a67d7f6fSMat Martineau 
990a67d7f6fSMat Martineau 	if (!control->sframe)
991a67d7f6fSMat Martineau 		return;
992a67d7f6fSMat Martineau 
993b99e13adSMat Martineau 	if (__chan_is_moving(chan))
994b99e13adSMat Martineau 		return;
995b99e13adSMat Martineau 
996a67d7f6fSMat Martineau 	if (test_and_clear_bit(CONN_SEND_FBIT, &chan->conn_state) &&
997a67d7f6fSMat Martineau 	    !control->poll)
998a67d7f6fSMat Martineau 		control->final = 1;
999a67d7f6fSMat Martineau 
1000a67d7f6fSMat Martineau 	if (control->super == L2CAP_SUPER_RR)
1001a67d7f6fSMat Martineau 		clear_bit(CONN_RNR_SENT, &chan->conn_state);
1002a67d7f6fSMat Martineau 	else if (control->super == L2CAP_SUPER_RNR)
1003a67d7f6fSMat Martineau 		set_bit(CONN_RNR_SENT, &chan->conn_state);
1004a67d7f6fSMat Martineau 
1005a67d7f6fSMat Martineau 	if (control->super != L2CAP_SUPER_SREJ) {
1006a67d7f6fSMat Martineau 		chan->last_acked_seq = control->reqseq;
1007a67d7f6fSMat Martineau 		__clear_ack_timer(chan);
1008a67d7f6fSMat Martineau 	}
1009a67d7f6fSMat Martineau 
1010a67d7f6fSMat Martineau 	BT_DBG("reqseq %d, final %d, poll %d, super %d", control->reqseq,
1011a67d7f6fSMat Martineau 	       control->final, control->poll, control->super);
1012a67d7f6fSMat Martineau 
1013a67d7f6fSMat Martineau 	if (test_bit(FLAG_EXT_CTRL, &chan->flags))
1014a67d7f6fSMat Martineau 		control_field = __pack_extended_control(control);
1015a67d7f6fSMat Martineau 	else
1016a67d7f6fSMat Martineau 		control_field = __pack_enhanced_control(control);
1017a67d7f6fSMat Martineau 
1018a67d7f6fSMat Martineau 	skb = l2cap_create_sframe_pdu(chan, control_field);
1019a67d7f6fSMat Martineau 	if (!IS_ERR(skb))
102073d80debSLuiz Augusto von Dentz 		l2cap_do_send(chan, skb);
10210a708f8fSGustavo F. Padovan }
10220a708f8fSGustavo F. Padovan 
1023c9e3d5e0SMat Martineau static void l2cap_send_rr_or_rnr(struct l2cap_chan *chan, bool poll)
10240a708f8fSGustavo F. Padovan {
1025c9e3d5e0SMat Martineau 	struct l2cap_ctrl control;
10260a708f8fSGustavo F. Padovan 
1027c9e3d5e0SMat Martineau 	BT_DBG("chan %p, poll %d", chan, poll);
1028c9e3d5e0SMat Martineau 
1029c9e3d5e0SMat Martineau 	memset(&control, 0, sizeof(control));
1030c9e3d5e0SMat Martineau 	control.sframe = 1;
1031c9e3d5e0SMat Martineau 	control.poll = poll;
1032c9e3d5e0SMat Martineau 
1033c9e3d5e0SMat Martineau 	if (test_bit(CONN_LOCAL_BUSY, &chan->conn_state))
1034c9e3d5e0SMat Martineau 		control.super = L2CAP_SUPER_RNR;
1035c9e3d5e0SMat Martineau 	else
1036c9e3d5e0SMat Martineau 		control.super = L2CAP_SUPER_RR;
1037c9e3d5e0SMat Martineau 
1038c9e3d5e0SMat Martineau 	control.reqseq = chan->buffer_seq;
1039c9e3d5e0SMat Martineau 	l2cap_send_sframe(chan, &control);
10400a708f8fSGustavo F. Padovan }
10410a708f8fSGustavo F. Padovan 
1042b4450035SGustavo F. Padovan static inline int __l2cap_no_conn_pending(struct l2cap_chan *chan)
10430a708f8fSGustavo F. Padovan {
1044c1360a1cSGustavo F. Padovan 	return !test_bit(CONF_CONNECT_PEND, &chan->conf_state);
10450a708f8fSGustavo F. Padovan }
10460a708f8fSGustavo F. Padovan 
104793c3e8f5SAndrei Emeltchenko static bool __amp_capable(struct l2cap_chan *chan)
104893c3e8f5SAndrei Emeltchenko {
104993c3e8f5SAndrei Emeltchenko 	struct l2cap_conn *conn = chan->conn;
10501df7b17aSMarcel Holtmann 	struct hci_dev *hdev;
10511df7b17aSMarcel Holtmann 	bool amp_available = false;
105293c3e8f5SAndrei Emeltchenko 
10531df7b17aSMarcel Holtmann 	if (!conn->hs_enabled)
10541df7b17aSMarcel Holtmann 		return false;
10551df7b17aSMarcel Holtmann 
10561df7b17aSMarcel Holtmann 	if (!(conn->fixed_chan_mask & L2CAP_FC_A2MP))
10571df7b17aSMarcel Holtmann 		return false;
10581df7b17aSMarcel Holtmann 
10591df7b17aSMarcel Holtmann 	read_lock(&hci_dev_list_lock);
10601df7b17aSMarcel Holtmann 	list_for_each_entry(hdev, &hci_dev_list, list) {
10611df7b17aSMarcel Holtmann 		if (hdev->amp_type != AMP_TYPE_BREDR &&
10621df7b17aSMarcel Holtmann 		    test_bit(HCI_UP, &hdev->flags)) {
10631df7b17aSMarcel Holtmann 			amp_available = true;
10641df7b17aSMarcel Holtmann 			break;
10651df7b17aSMarcel Holtmann 		}
10661df7b17aSMarcel Holtmann 	}
10671df7b17aSMarcel Holtmann 	read_unlock(&hci_dev_list_lock);
10681df7b17aSMarcel Holtmann 
10691df7b17aSMarcel Holtmann 	if (chan->chan_policy == BT_CHANNEL_POLICY_AMP_PREFERRED)
10701df7b17aSMarcel Holtmann 		return amp_available;
1071848566b3SMarcel Holtmann 
107293c3e8f5SAndrei Emeltchenko 	return false;
107393c3e8f5SAndrei Emeltchenko }
107493c3e8f5SAndrei Emeltchenko 
10755ce66b59SAndrei Emeltchenko static bool l2cap_check_efs(struct l2cap_chan *chan)
10765ce66b59SAndrei Emeltchenko {
10775ce66b59SAndrei Emeltchenko 	/* Check EFS parameters */
10785ce66b59SAndrei Emeltchenko 	return true;
10795ce66b59SAndrei Emeltchenko }
10805ce66b59SAndrei Emeltchenko 
10812766be48SAndrei Emeltchenko void l2cap_send_conn_req(struct l2cap_chan *chan)
10829b27f350SAndrei Emeltchenko {
10839b27f350SAndrei Emeltchenko 	struct l2cap_conn *conn = chan->conn;
10849b27f350SAndrei Emeltchenko 	struct l2cap_conn_req req;
10859b27f350SAndrei Emeltchenko 
10869b27f350SAndrei Emeltchenko 	req.scid = cpu_to_le16(chan->scid);
10879b27f350SAndrei Emeltchenko 	req.psm  = chan->psm;
10889b27f350SAndrei Emeltchenko 
10899b27f350SAndrei Emeltchenko 	chan->ident = l2cap_get_ident(conn);
10909b27f350SAndrei Emeltchenko 
10919b27f350SAndrei Emeltchenko 	set_bit(CONF_CONNECT_PEND, &chan->conf_state);
10929b27f350SAndrei Emeltchenko 
10939b27f350SAndrei Emeltchenko 	l2cap_send_cmd(conn, chan->ident, L2CAP_CONN_REQ, sizeof(req), &req);
10949b27f350SAndrei Emeltchenko }
10959b27f350SAndrei Emeltchenko 
10968eb200bdSMat Martineau static void l2cap_send_create_chan_req(struct l2cap_chan *chan, u8 amp_id)
10978eb200bdSMat Martineau {
10988eb200bdSMat Martineau 	struct l2cap_create_chan_req req;
10998eb200bdSMat Martineau 	req.scid = cpu_to_le16(chan->scid);
11008eb200bdSMat Martineau 	req.psm  = chan->psm;
11018eb200bdSMat Martineau 	req.amp_id = amp_id;
11028eb200bdSMat Martineau 
11038eb200bdSMat Martineau 	chan->ident = l2cap_get_ident(chan->conn);
11048eb200bdSMat Martineau 
11058eb200bdSMat Martineau 	l2cap_send_cmd(chan->conn, chan->ident, L2CAP_CREATE_CHAN_REQ,
11068eb200bdSMat Martineau 		       sizeof(req), &req);
11078eb200bdSMat Martineau }
11088eb200bdSMat Martineau 
110902b0fbb9SMat Martineau static void l2cap_move_setup(struct l2cap_chan *chan)
111002b0fbb9SMat Martineau {
111102b0fbb9SMat Martineau 	struct sk_buff *skb;
111202b0fbb9SMat Martineau 
111302b0fbb9SMat Martineau 	BT_DBG("chan %p", chan);
111402b0fbb9SMat Martineau 
111502b0fbb9SMat Martineau 	if (chan->mode != L2CAP_MODE_ERTM)
111602b0fbb9SMat Martineau 		return;
111702b0fbb9SMat Martineau 
111802b0fbb9SMat Martineau 	__clear_retrans_timer(chan);
111902b0fbb9SMat Martineau 	__clear_monitor_timer(chan);
112002b0fbb9SMat Martineau 	__clear_ack_timer(chan);
112102b0fbb9SMat Martineau 
112202b0fbb9SMat Martineau 	chan->retry_count = 0;
112302b0fbb9SMat Martineau 	skb_queue_walk(&chan->tx_q, skb) {
112402b0fbb9SMat Martineau 		if (bt_cb(skb)->control.retries)
112502b0fbb9SMat Martineau 			bt_cb(skb)->control.retries = 1;
112602b0fbb9SMat Martineau 		else
112702b0fbb9SMat Martineau 			break;
112802b0fbb9SMat Martineau 	}
112902b0fbb9SMat Martineau 
113002b0fbb9SMat Martineau 	chan->expected_tx_seq = chan->buffer_seq;
113102b0fbb9SMat Martineau 
113202b0fbb9SMat Martineau 	clear_bit(CONN_REJ_ACT, &chan->conn_state);
113302b0fbb9SMat Martineau 	clear_bit(CONN_SREJ_ACT, &chan->conn_state);
113402b0fbb9SMat Martineau 	l2cap_seq_list_clear(&chan->retrans_list);
113502b0fbb9SMat Martineau 	l2cap_seq_list_clear(&chan->srej_list);
113602b0fbb9SMat Martineau 	skb_queue_purge(&chan->srej_q);
113702b0fbb9SMat Martineau 
113802b0fbb9SMat Martineau 	chan->tx_state = L2CAP_TX_STATE_XMIT;
113902b0fbb9SMat Martineau 	chan->rx_state = L2CAP_RX_STATE_MOVE;
114002b0fbb9SMat Martineau 
114102b0fbb9SMat Martineau 	set_bit(CONN_REMOTE_BUSY, &chan->conn_state);
114202b0fbb9SMat Martineau }
114302b0fbb9SMat Martineau 
11445f3847a4SMat Martineau static void l2cap_move_done(struct l2cap_chan *chan)
11455f3847a4SMat Martineau {
11465f3847a4SMat Martineau 	u8 move_role = chan->move_role;
11475f3847a4SMat Martineau 	BT_DBG("chan %p", chan);
11485f3847a4SMat Martineau 
11495f3847a4SMat Martineau 	chan->move_state = L2CAP_MOVE_STABLE;
11505f3847a4SMat Martineau 	chan->move_role = L2CAP_MOVE_ROLE_NONE;
11515f3847a4SMat Martineau 
11525f3847a4SMat Martineau 	if (chan->mode != L2CAP_MODE_ERTM)
11535f3847a4SMat Martineau 		return;
11545f3847a4SMat Martineau 
11555f3847a4SMat Martineau 	switch (move_role) {
11565f3847a4SMat Martineau 	case L2CAP_MOVE_ROLE_INITIATOR:
11575f3847a4SMat Martineau 		l2cap_tx(chan, NULL, NULL, L2CAP_EV_EXPLICIT_POLL);
11585f3847a4SMat Martineau 		chan->rx_state = L2CAP_RX_STATE_WAIT_F;
11595f3847a4SMat Martineau 		break;
11605f3847a4SMat Martineau 	case L2CAP_MOVE_ROLE_RESPONDER:
11615f3847a4SMat Martineau 		chan->rx_state = L2CAP_RX_STATE_WAIT_P;
11625f3847a4SMat Martineau 		break;
11635f3847a4SMat Martineau 	}
11645f3847a4SMat Martineau }
11655f3847a4SMat Martineau 
11669f0caeb1SVinicius Costa Gomes static void l2cap_chan_ready(struct l2cap_chan *chan)
11679f0caeb1SVinicius Costa Gomes {
11682827011fSMat Martineau 	/* This clears all conf flags, including CONF_NOT_COMPLETE */
11699f0caeb1SVinicius Costa Gomes 	chan->conf_state = 0;
11709f0caeb1SVinicius Costa Gomes 	__clear_chan_timer(chan);
11719f0caeb1SVinicius Costa Gomes 
117254a59aa2SAndrei Emeltchenko 	chan->state = BT_CONNECTED;
11739f0caeb1SVinicius Costa Gomes 
117454a59aa2SAndrei Emeltchenko 	chan->ops->ready(chan);
11759f0caeb1SVinicius Costa Gomes }
11769f0caeb1SVinicius Costa Gomes 
117793c3e8f5SAndrei Emeltchenko static void l2cap_start_connection(struct l2cap_chan *chan)
117893c3e8f5SAndrei Emeltchenko {
117993c3e8f5SAndrei Emeltchenko 	if (__amp_capable(chan)) {
118093c3e8f5SAndrei Emeltchenko 		BT_DBG("chan %p AMP capable: discover AMPs", chan);
118193c3e8f5SAndrei Emeltchenko 		a2mp_discover_amp(chan);
118293c3e8f5SAndrei Emeltchenko 	} else {
118393c3e8f5SAndrei Emeltchenko 		l2cap_send_conn_req(chan);
118493c3e8f5SAndrei Emeltchenko 	}
118593c3e8f5SAndrei Emeltchenko }
118693c3e8f5SAndrei Emeltchenko 
1187fc7f8a7eSGustavo F. Padovan static void l2cap_do_start(struct l2cap_chan *chan)
11880a708f8fSGustavo F. Padovan {
11898c1d787bSGustavo F. Padovan 	struct l2cap_conn *conn = chan->conn;
11900a708f8fSGustavo F. Padovan 
11919f0caeb1SVinicius Costa Gomes 	if (conn->hcon->type == LE_LINK) {
11929f0caeb1SVinicius Costa Gomes 		l2cap_chan_ready(chan);
11939f0caeb1SVinicius Costa Gomes 		return;
11949f0caeb1SVinicius Costa Gomes 	}
11959f0caeb1SVinicius Costa Gomes 
11960a708f8fSGustavo F. Padovan 	if (conn->info_state & L2CAP_INFO_FEAT_MASK_REQ_SENT) {
11970a708f8fSGustavo F. Padovan 		if (!(conn->info_state & L2CAP_INFO_FEAT_MASK_REQ_DONE))
11980a708f8fSGustavo F. Padovan 			return;
11990a708f8fSGustavo F. Padovan 
1200d45fc423SGustavo F. Padovan 		if (l2cap_chan_check_security(chan) &&
120193c3e8f5SAndrei Emeltchenko 		    __l2cap_no_conn_pending(chan)) {
120293c3e8f5SAndrei Emeltchenko 			l2cap_start_connection(chan);
120393c3e8f5SAndrei Emeltchenko 		}
12040a708f8fSGustavo F. Padovan 	} else {
12050a708f8fSGustavo F. Padovan 		struct l2cap_info_req req;
1206ac73498cSAndrei Emeltchenko 		req.type = __constant_cpu_to_le16(L2CAP_IT_FEAT_MASK);
12070a708f8fSGustavo F. Padovan 
12080a708f8fSGustavo F. Padovan 		conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_SENT;
12090a708f8fSGustavo F. Padovan 		conn->info_ident = l2cap_get_ident(conn);
12100a708f8fSGustavo F. Padovan 
1211ba13ccd9SMarcel Holtmann 		schedule_delayed_work(&conn->info_timer, L2CAP_INFO_TIMEOUT);
12120a708f8fSGustavo F. Padovan 
12132d792818SGustavo Padovan 		l2cap_send_cmd(conn, conn->info_ident, L2CAP_INFO_REQ,
12142d792818SGustavo Padovan 			       sizeof(req), &req);
12150a708f8fSGustavo F. Padovan 	}
12160a708f8fSGustavo F. Padovan }
12170a708f8fSGustavo F. Padovan 
12180a708f8fSGustavo F. Padovan static inline int l2cap_mode_supported(__u8 mode, __u32 feat_mask)
12190a708f8fSGustavo F. Padovan {
12200a708f8fSGustavo F. Padovan 	u32 local_feat_mask = l2cap_feat_mask;
12210a708f8fSGustavo F. Padovan 	if (!disable_ertm)
12220a708f8fSGustavo F. Padovan 		local_feat_mask |= L2CAP_FEAT_ERTM | L2CAP_FEAT_STREAMING;
12230a708f8fSGustavo F. Padovan 
12240a708f8fSGustavo F. Padovan 	switch (mode) {
12250a708f8fSGustavo F. Padovan 	case L2CAP_MODE_ERTM:
12260a708f8fSGustavo F. Padovan 		return L2CAP_FEAT_ERTM & feat_mask & local_feat_mask;
12270a708f8fSGustavo F. Padovan 	case L2CAP_MODE_STREAMING:
12280a708f8fSGustavo F. Padovan 		return L2CAP_FEAT_STREAMING & feat_mask & local_feat_mask;
12290a708f8fSGustavo F. Padovan 	default:
12300a708f8fSGustavo F. Padovan 		return 0x00;
12310a708f8fSGustavo F. Padovan 	}
12320a708f8fSGustavo F. Padovan }
12330a708f8fSGustavo F. Padovan 
12345e4e3972SAndrei Emeltchenko static void l2cap_send_disconn_req(struct l2cap_chan *chan, int err)
12350a708f8fSGustavo F. Padovan {
12365e4e3972SAndrei Emeltchenko 	struct l2cap_conn *conn = chan->conn;
12370a708f8fSGustavo F. Padovan 	struct l2cap_disconn_req req;
12380a708f8fSGustavo F. Padovan 
12390a708f8fSGustavo F. Padovan 	if (!conn)
12400a708f8fSGustavo F. Padovan 		return;
12410a708f8fSGustavo F. Padovan 
1242aad3d0e3SAndrei Emeltchenko 	if (chan->mode == L2CAP_MODE_ERTM && chan->state == BT_CONNECTED) {
12431a09bcb9SGustavo F. Padovan 		__clear_retrans_timer(chan);
12441a09bcb9SGustavo F. Padovan 		__clear_monitor_timer(chan);
12451a09bcb9SGustavo F. Padovan 		__clear_ack_timer(chan);
12460a708f8fSGustavo F. Padovan 	}
12470a708f8fSGustavo F. Padovan 
1248416fa752SAndrei Emeltchenko 	if (chan->chan_type == L2CAP_CHAN_CONN_FIX_A2MP) {
1249d117773cSGustavo Padovan 		l2cap_state_change(chan, BT_DISCONN);
1250416fa752SAndrei Emeltchenko 		return;
1251416fa752SAndrei Emeltchenko 	}
1252416fa752SAndrei Emeltchenko 
1253fe4128e0SGustavo F. Padovan 	req.dcid = cpu_to_le16(chan->dcid);
1254fe4128e0SGustavo F. Padovan 	req.scid = cpu_to_le16(chan->scid);
12552d792818SGustavo Padovan 	l2cap_send_cmd(conn, l2cap_get_ident(conn), L2CAP_DISCONN_REQ,
12562d792818SGustavo Padovan 		       sizeof(req), &req);
12570a708f8fSGustavo F. Padovan 
1258f8e73017SGustavo Padovan 	l2cap_state_change_and_error(chan, BT_DISCONN, err);
12590a708f8fSGustavo F. Padovan }
12600a708f8fSGustavo F. Padovan 
12610a708f8fSGustavo F. Padovan /* ---- L2CAP connections ---- */
12620a708f8fSGustavo F. Padovan static void l2cap_conn_start(struct l2cap_conn *conn)
12630a708f8fSGustavo F. Padovan {
12643df91ea2SAndrei Emeltchenko 	struct l2cap_chan *chan, *tmp;
12650a708f8fSGustavo F. Padovan 
12660a708f8fSGustavo F. Padovan 	BT_DBG("conn %p", conn);
12670a708f8fSGustavo F. Padovan 
12683df91ea2SAndrei Emeltchenko 	mutex_lock(&conn->chan_lock);
12690a708f8fSGustavo F. Padovan 
12703df91ea2SAndrei Emeltchenko 	list_for_each_entry_safe(chan, tmp, &conn->chan_l, list) {
12716be36555SAndrei Emeltchenko 		l2cap_chan_lock(chan);
12720a708f8fSGustavo F. Padovan 
1273715ec005SGustavo F. Padovan 		if (chan->chan_type != L2CAP_CHAN_CONN_ORIENTED) {
12746be36555SAndrei Emeltchenko 			l2cap_chan_unlock(chan);
12750a708f8fSGustavo F. Padovan 			continue;
12760a708f8fSGustavo F. Padovan 		}
12770a708f8fSGustavo F. Padovan 
127889bc500eSGustavo F. Padovan 		if (chan->state == BT_CONNECT) {
1279d45fc423SGustavo F. Padovan 			if (!l2cap_chan_check_security(chan) ||
1280b4450035SGustavo F. Padovan 			    !__l2cap_no_conn_pending(chan)) {
12816be36555SAndrei Emeltchenko 				l2cap_chan_unlock(chan);
12820a708f8fSGustavo F. Padovan 				continue;
12830a708f8fSGustavo F. Padovan 			}
12840a708f8fSGustavo F. Padovan 
1285c1360a1cSGustavo F. Padovan 			if (!l2cap_mode_supported(chan->mode, conn->feat_mask)
1286c1360a1cSGustavo F. Padovan 			    && test_bit(CONF_STATE2_DEVICE,
1287c1360a1cSGustavo F. Padovan 					&chan->conf_state)) {
12880f852724SGustavo F. Padovan 				l2cap_chan_close(chan, ECONNRESET);
12896be36555SAndrei Emeltchenko 				l2cap_chan_unlock(chan);
12900a708f8fSGustavo F. Padovan 				continue;
12910a708f8fSGustavo F. Padovan 			}
12920a708f8fSGustavo F. Padovan 
129393c3e8f5SAndrei Emeltchenko 			l2cap_start_connection(chan);
12940a708f8fSGustavo F. Padovan 
129589bc500eSGustavo F. Padovan 		} else if (chan->state == BT_CONNECT2) {
12960a708f8fSGustavo F. Padovan 			struct l2cap_conn_rsp rsp;
12970a708f8fSGustavo F. Padovan 			char buf[128];
1298fe4128e0SGustavo F. Padovan 			rsp.scid = cpu_to_le16(chan->dcid);
1299fe4128e0SGustavo F. Padovan 			rsp.dcid = cpu_to_le16(chan->scid);
13000a708f8fSGustavo F. Padovan 
1301d45fc423SGustavo F. Padovan 			if (l2cap_chan_check_security(chan)) {
1302bdc25783SMarcel Holtmann 				struct sock *sk = chan->sk;
1303bdc25783SMarcel Holtmann 
13046be36555SAndrei Emeltchenko 				lock_sock(sk);
1305bdc25783SMarcel Holtmann 				if (test_bit(FLAG_DEFER_SETUP, &chan->flags)) {
1306ac73498cSAndrei Emeltchenko 					rsp.result = __constant_cpu_to_le16(L2CAP_CR_PEND);
1307ac73498cSAndrei Emeltchenko 					rsp.status = __constant_cpu_to_le16(L2CAP_CS_AUTHOR_PEND);
13082dc4e510SGustavo Padovan 					chan->ops->defer(chan);
13090a708f8fSGustavo F. Padovan 
13100a708f8fSGustavo F. Padovan 				} else {
13110e587be7SAndrei Emeltchenko 					__l2cap_state_change(chan, BT_CONFIG);
1312ac73498cSAndrei Emeltchenko 					rsp.result = __constant_cpu_to_le16(L2CAP_CR_SUCCESS);
1313ac73498cSAndrei Emeltchenko 					rsp.status = __constant_cpu_to_le16(L2CAP_CS_NO_INFO);
13140a708f8fSGustavo F. Padovan 				}
13156be36555SAndrei Emeltchenko 				release_sock(sk);
13160a708f8fSGustavo F. Padovan 			} else {
1317ac73498cSAndrei Emeltchenko 				rsp.result = __constant_cpu_to_le16(L2CAP_CR_PEND);
1318ac73498cSAndrei Emeltchenko 				rsp.status = __constant_cpu_to_le16(L2CAP_CS_AUTHEN_PEND);
13190a708f8fSGustavo F. Padovan 			}
13200a708f8fSGustavo F. Padovan 
1321fc7f8a7eSGustavo F. Padovan 			l2cap_send_cmd(conn, chan->ident, L2CAP_CONN_RSP,
1322fc7f8a7eSGustavo F. Padovan 				       sizeof(rsp), &rsp);
13230a708f8fSGustavo F. Padovan 
1324c1360a1cSGustavo F. Padovan 			if (test_bit(CONF_REQ_SENT, &chan->conf_state) ||
13250a708f8fSGustavo F. Padovan 			    rsp.result != L2CAP_CR_SUCCESS) {
13266be36555SAndrei Emeltchenko 				l2cap_chan_unlock(chan);
13270a708f8fSGustavo F. Padovan 				continue;
13280a708f8fSGustavo F. Padovan 			}
13290a708f8fSGustavo F. Padovan 
1330c1360a1cSGustavo F. Padovan 			set_bit(CONF_REQ_SENT, &chan->conf_state);
13310a708f8fSGustavo F. Padovan 			l2cap_send_cmd(conn, l2cap_get_ident(conn), L2CAP_CONF_REQ,
133273ffa904SGustavo F. Padovan 				       l2cap_build_conf_req(chan, buf), buf);
133373ffa904SGustavo F. Padovan 			chan->num_conf_req++;
13340a708f8fSGustavo F. Padovan 		}
13350a708f8fSGustavo F. Padovan 
13366be36555SAndrei Emeltchenko 		l2cap_chan_unlock(chan);
13370a708f8fSGustavo F. Padovan 	}
13380a708f8fSGustavo F. Padovan 
13393df91ea2SAndrei Emeltchenko 	mutex_unlock(&conn->chan_lock);
13400a708f8fSGustavo F. Padovan }
13410a708f8fSGustavo F. Padovan 
1342c2287681SIdo Yariv /* Find socket with cid and source/destination bdaddr.
1343b62f328bSVille Tervo  * Returns closest match, locked.
1344b62f328bSVille Tervo  */
1345d9b88702SAndrei Emeltchenko static struct l2cap_chan *l2cap_global_chan_by_scid(int state, u16 cid,
1346c2287681SIdo Yariv 						    bdaddr_t *src,
1347c2287681SIdo Yariv 						    bdaddr_t *dst)
1348b62f328bSVille Tervo {
134923691d75SGustavo F. Padovan 	struct l2cap_chan *c, *c1 = NULL;
1350b62f328bSVille Tervo 
135123691d75SGustavo F. Padovan 	read_lock(&chan_list_lock);
1352b62f328bSVille Tervo 
135323691d75SGustavo F. Padovan 	list_for_each_entry(c, &chan_list, global_l) {
135489bc500eSGustavo F. Padovan 		if (state && c->state != state)
1355b62f328bSVille Tervo 			continue;
1356b62f328bSVille Tervo 
135723691d75SGustavo F. Padovan 		if (c->scid == cid) {
1358c2287681SIdo Yariv 			int src_match, dst_match;
1359c2287681SIdo Yariv 			int src_any, dst_any;
1360c2287681SIdo Yariv 
1361b62f328bSVille Tervo 			/* Exact match. */
13627eafc59eSMarcel Holtmann 			src_match = !bacmp(&c->src, src);
13637eafc59eSMarcel Holtmann 			dst_match = !bacmp(&c->dst, dst);
1364c2287681SIdo Yariv 			if (src_match && dst_match) {
136523691d75SGustavo F. Padovan 				read_unlock(&chan_list_lock);
136623691d75SGustavo F. Padovan 				return c;
136723691d75SGustavo F. Padovan 			}
1368b62f328bSVille Tervo 
1369b62f328bSVille Tervo 			/* Closest match */
13707eafc59eSMarcel Holtmann 			src_any = !bacmp(&c->src, BDADDR_ANY);
13717eafc59eSMarcel Holtmann 			dst_any = !bacmp(&c->dst, BDADDR_ANY);
1372c2287681SIdo Yariv 			if ((src_match && dst_any) || (src_any && dst_match) ||
1373c2287681SIdo Yariv 			    (src_any && dst_any))
137423691d75SGustavo F. Padovan 				c1 = c;
1375b62f328bSVille Tervo 		}
1376b62f328bSVille Tervo 	}
1377280f294fSGustavo F. Padovan 
137823691d75SGustavo F. Padovan 	read_unlock(&chan_list_lock);
1379b62f328bSVille Tervo 
138023691d75SGustavo F. Padovan 	return c1;
1381b62f328bSVille Tervo }
1382b62f328bSVille Tervo 
1383b62f328bSVille Tervo static void l2cap_le_conn_ready(struct l2cap_conn *conn)
1384b62f328bSVille Tervo {
138560bac184SJohan Hedberg 	struct sock *parent;
138623691d75SGustavo F. Padovan 	struct l2cap_chan *chan, *pchan;
1387b62f328bSVille Tervo 
1388b62f328bSVille Tervo 	BT_DBG("");
1389b62f328bSVille Tervo 
1390b62f328bSVille Tervo 	/* Check if we have socket listening on cid */
1391073d1cf3SJohan Hedberg 	pchan = l2cap_global_chan_by_scid(BT_LISTEN, L2CAP_CID_ATT,
13926f59b904SMarcel Holtmann 					  &conn->hcon->src, &conn->hcon->dst);
139323691d75SGustavo F. Padovan 	if (!pchan)
1394b62f328bSVille Tervo 		return;
1395b62f328bSVille Tervo 
139644f3b0fbSJohan Hedberg 	/* Client ATT sockets should override the server one */
139744f3b0fbSJohan Hedberg 	if (__l2cap_get_chan_by_dcid(conn, L2CAP_CID_ATT))
139844f3b0fbSJohan Hedberg 		return;
139944f3b0fbSJohan Hedberg 
140023691d75SGustavo F. Padovan 	parent = pchan->sk;
140123691d75SGustavo F. Padovan 
1402aa2ac881SGustavo F. Padovan 	lock_sock(parent);
140362f3a2cfSGustavo F. Padovan 
140480b98027SGustavo Padovan 	chan = pchan->ops->new_connection(pchan);
140580808e43SGustavo F. Padovan 	if (!chan)
1406b62f328bSVille Tervo 		goto clean;
1407b62f328bSVille Tervo 
14089f22398cSJohan Hedberg 	chan->dcid = L2CAP_CID_ATT;
14099f22398cSJohan Hedberg 
14107eafc59eSMarcel Holtmann 	bacpy(&chan->src, &conn->hcon->src);
14117eafc59eSMarcel Holtmann 	bacpy(&chan->dst, &conn->hcon->dst);
14124f1654e0SMarcel Holtmann 	chan->src_type = bdaddr_type(conn->hcon, conn->hcon->src_type);
14134f1654e0SMarcel Holtmann 	chan->dst_type = bdaddr_type(conn->hcon, conn->hcon->dst_type);
1414b62f328bSVille Tervo 
141544f3b0fbSJohan Hedberg 	__l2cap_chan_add(conn, chan);
141648454079SGustavo F. Padovan 
1417b62f328bSVille Tervo clean:
1418aa2ac881SGustavo F. Padovan 	release_sock(parent);
1419b62f328bSVille Tervo }
1420b62f328bSVille Tervo 
14210a708f8fSGustavo F. Padovan static void l2cap_conn_ready(struct l2cap_conn *conn)
14220a708f8fSGustavo F. Padovan {
142348454079SGustavo F. Padovan 	struct l2cap_chan *chan;
1424cc110922SVinicius Costa Gomes 	struct hci_conn *hcon = conn->hcon;
14250a708f8fSGustavo F. Padovan 
14260a708f8fSGustavo F. Padovan 	BT_DBG("conn %p", conn);
14270a708f8fSGustavo F. Padovan 
1428d8729922SJohan Hedberg 	/* For outgoing pairing which doesn't necessarily have an
1429d8729922SJohan Hedberg 	 * associated socket (e.g. mgmt_pair_device).
1430d8729922SJohan Hedberg 	 */
1431cc110922SVinicius Costa Gomes 	if (hcon->out && hcon->type == LE_LINK)
1432cc110922SVinicius Costa Gomes 		smp_conn_security(hcon, hcon->pending_sec_level);
1433160dc6acSVinicius Costa Gomes 
14343df91ea2SAndrei Emeltchenko 	mutex_lock(&conn->chan_lock);
14350a708f8fSGustavo F. Padovan 
143644f3b0fbSJohan Hedberg 	if (hcon->type == LE_LINK)
143744f3b0fbSJohan Hedberg 		l2cap_le_conn_ready(conn);
143844f3b0fbSJohan Hedberg 
14393df91ea2SAndrei Emeltchenko 	list_for_each_entry(chan, &conn->chan_l, list) {
1440baa7e1faSGustavo F. Padovan 
14416be36555SAndrei Emeltchenko 		l2cap_chan_lock(chan);
14420a708f8fSGustavo F. Padovan 
1443416fa752SAndrei Emeltchenko 		if (chan->chan_type == L2CAP_CHAN_CONN_FIX_A2MP) {
1444416fa752SAndrei Emeltchenko 			l2cap_chan_unlock(chan);
1445416fa752SAndrei Emeltchenko 			continue;
1446416fa752SAndrei Emeltchenko 		}
1447416fa752SAndrei Emeltchenko 
1448cc110922SVinicius Costa Gomes 		if (hcon->type == LE_LINK) {
1449cc110922SVinicius Costa Gomes 			if (smp_conn_security(hcon, chan->sec_level))
1450cf4cd009SAndrei Emeltchenko 				l2cap_chan_ready(chan);
1451acd7d370SVille Tervo 
145263128451SVinicius Costa Gomes 		} else if (chan->chan_type != L2CAP_CHAN_CONN_ORIENTED) {
14536be36555SAndrei Emeltchenko 			struct sock *sk = chan->sk;
1454c9b66675SGustavo F. Padovan 			__clear_chan_timer(chan);
14556be36555SAndrei Emeltchenko 			lock_sock(sk);
14560e587be7SAndrei Emeltchenko 			__l2cap_state_change(chan, BT_CONNECTED);
14570a708f8fSGustavo F. Padovan 			sk->sk_state_change(sk);
14586be36555SAndrei Emeltchenko 			release_sock(sk);
1459b501d6a1SAnderson Briglia 
14601c244f79SGustavo Padovan 		} else if (chan->state == BT_CONNECT) {
1461fc7f8a7eSGustavo F. Padovan 			l2cap_do_start(chan);
14621c244f79SGustavo Padovan 		}
14630a708f8fSGustavo F. Padovan 
14646be36555SAndrei Emeltchenko 		l2cap_chan_unlock(chan);
14650a708f8fSGustavo F. Padovan 	}
14660a708f8fSGustavo F. Padovan 
14673df91ea2SAndrei Emeltchenko 	mutex_unlock(&conn->chan_lock);
14680a708f8fSGustavo F. Padovan }
14690a708f8fSGustavo F. Padovan 
14700a708f8fSGustavo F. Padovan /* Notify sockets that we cannot guaranty reliability anymore */
14710a708f8fSGustavo F. Padovan static void l2cap_conn_unreliable(struct l2cap_conn *conn, int err)
14720a708f8fSGustavo F. Padovan {
147348454079SGustavo F. Padovan 	struct l2cap_chan *chan;
14740a708f8fSGustavo F. Padovan 
14750a708f8fSGustavo F. Padovan 	BT_DBG("conn %p", conn);
14760a708f8fSGustavo F. Padovan 
14773df91ea2SAndrei Emeltchenko 	mutex_lock(&conn->chan_lock);
14780a708f8fSGustavo F. Padovan 
14793df91ea2SAndrei Emeltchenko 	list_for_each_entry(chan, &conn->chan_l, list) {
1480ecf61bdbSAndrei Emeltchenko 		if (test_bit(FLAG_FORCE_RELIABLE, &chan->flags))
14811d8b1fd5SGustavo Padovan 			l2cap_chan_set_err(chan, err);
14820a708f8fSGustavo F. Padovan 	}
14830a708f8fSGustavo F. Padovan 
14843df91ea2SAndrei Emeltchenko 	mutex_unlock(&conn->chan_lock);
14850a708f8fSGustavo F. Padovan }
14860a708f8fSGustavo F. Padovan 
1487f878fcadSGustavo F. Padovan static void l2cap_info_timeout(struct work_struct *work)
14880a708f8fSGustavo F. Padovan {
1489f878fcadSGustavo F. Padovan 	struct l2cap_conn *conn = container_of(work, struct l2cap_conn,
1490030013d8SGustavo F. Padovan 					       info_timer.work);
14910a708f8fSGustavo F. Padovan 
14920a708f8fSGustavo F. Padovan 	conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_DONE;
14930a708f8fSGustavo F. Padovan 	conn->info_ident = 0;
14940a708f8fSGustavo F. Padovan 
14950a708f8fSGustavo F. Padovan 	l2cap_conn_start(conn);
14960a708f8fSGustavo F. Padovan }
14970a708f8fSGustavo F. Padovan 
14982c8e1411SDavid Herrmann /*
14992c8e1411SDavid Herrmann  * l2cap_user
15002c8e1411SDavid Herrmann  * External modules can register l2cap_user objects on l2cap_conn. The ->probe
15012c8e1411SDavid Herrmann  * callback is called during registration. The ->remove callback is called
15022c8e1411SDavid Herrmann  * during unregistration.
15032c8e1411SDavid Herrmann  * An l2cap_user object can either be explicitly unregistered or when the
15042c8e1411SDavid Herrmann  * underlying l2cap_conn object is deleted. This guarantees that l2cap->hcon,
15052c8e1411SDavid Herrmann  * l2cap->hchan, .. are valid as long as the remove callback hasn't been called.
15062c8e1411SDavid Herrmann  * External modules must own a reference to the l2cap_conn object if they intend
15072c8e1411SDavid Herrmann  * to call l2cap_unregister_user(). The l2cap_conn object might get destroyed at
15082c8e1411SDavid Herrmann  * any time if they don't.
15092c8e1411SDavid Herrmann  */
15102c8e1411SDavid Herrmann 
15112c8e1411SDavid Herrmann int l2cap_register_user(struct l2cap_conn *conn, struct l2cap_user *user)
15122c8e1411SDavid Herrmann {
15132c8e1411SDavid Herrmann 	struct hci_dev *hdev = conn->hcon->hdev;
15142c8e1411SDavid Herrmann 	int ret;
15152c8e1411SDavid Herrmann 
15162c8e1411SDavid Herrmann 	/* We need to check whether l2cap_conn is registered. If it is not, we
15172c8e1411SDavid Herrmann 	 * must not register the l2cap_user. l2cap_conn_del() is unregisters
15182c8e1411SDavid Herrmann 	 * l2cap_conn objects, but doesn't provide its own locking. Instead, it
15192c8e1411SDavid Herrmann 	 * relies on the parent hci_conn object to be locked. This itself relies
15202c8e1411SDavid Herrmann 	 * on the hci_dev object to be locked. So we must lock the hci device
15212c8e1411SDavid Herrmann 	 * here, too. */
15222c8e1411SDavid Herrmann 
15232c8e1411SDavid Herrmann 	hci_dev_lock(hdev);
15242c8e1411SDavid Herrmann 
15252c8e1411SDavid Herrmann 	if (user->list.next || user->list.prev) {
15262c8e1411SDavid Herrmann 		ret = -EINVAL;
15272c8e1411SDavid Herrmann 		goto out_unlock;
15282c8e1411SDavid Herrmann 	}
15292c8e1411SDavid Herrmann 
15302c8e1411SDavid Herrmann 	/* conn->hchan is NULL after l2cap_conn_del() was called */
15312c8e1411SDavid Herrmann 	if (!conn->hchan) {
15322c8e1411SDavid Herrmann 		ret = -ENODEV;
15332c8e1411SDavid Herrmann 		goto out_unlock;
15342c8e1411SDavid Herrmann 	}
15352c8e1411SDavid Herrmann 
15362c8e1411SDavid Herrmann 	ret = user->probe(conn, user);
15372c8e1411SDavid Herrmann 	if (ret)
15382c8e1411SDavid Herrmann 		goto out_unlock;
15392c8e1411SDavid Herrmann 
15402c8e1411SDavid Herrmann 	list_add(&user->list, &conn->users);
15412c8e1411SDavid Herrmann 	ret = 0;
15422c8e1411SDavid Herrmann 
15432c8e1411SDavid Herrmann out_unlock:
15442c8e1411SDavid Herrmann 	hci_dev_unlock(hdev);
15452c8e1411SDavid Herrmann 	return ret;
15462c8e1411SDavid Herrmann }
15472c8e1411SDavid Herrmann EXPORT_SYMBOL(l2cap_register_user);
15482c8e1411SDavid Herrmann 
15492c8e1411SDavid Herrmann void l2cap_unregister_user(struct l2cap_conn *conn, struct l2cap_user *user)
15502c8e1411SDavid Herrmann {
15512c8e1411SDavid Herrmann 	struct hci_dev *hdev = conn->hcon->hdev;
15522c8e1411SDavid Herrmann 
15532c8e1411SDavid Herrmann 	hci_dev_lock(hdev);
15542c8e1411SDavid Herrmann 
15552c8e1411SDavid Herrmann 	if (!user->list.next || !user->list.prev)
15562c8e1411SDavid Herrmann 		goto out_unlock;
15572c8e1411SDavid Herrmann 
15582c8e1411SDavid Herrmann 	list_del(&user->list);
15592c8e1411SDavid Herrmann 	user->list.next = NULL;
15602c8e1411SDavid Herrmann 	user->list.prev = NULL;
15612c8e1411SDavid Herrmann 	user->remove(conn, user);
15622c8e1411SDavid Herrmann 
15632c8e1411SDavid Herrmann out_unlock:
15642c8e1411SDavid Herrmann 	hci_dev_unlock(hdev);
15652c8e1411SDavid Herrmann }
15662c8e1411SDavid Herrmann EXPORT_SYMBOL(l2cap_unregister_user);
15672c8e1411SDavid Herrmann 
15682c8e1411SDavid Herrmann static void l2cap_unregister_all_users(struct l2cap_conn *conn)
15692c8e1411SDavid Herrmann {
15702c8e1411SDavid Herrmann 	struct l2cap_user *user;
15712c8e1411SDavid Herrmann 
15722c8e1411SDavid Herrmann 	while (!list_empty(&conn->users)) {
15732c8e1411SDavid Herrmann 		user = list_first_entry(&conn->users, struct l2cap_user, list);
15742c8e1411SDavid Herrmann 		list_del(&user->list);
15752c8e1411SDavid Herrmann 		user->list.next = NULL;
15762c8e1411SDavid Herrmann 		user->list.prev = NULL;
15772c8e1411SDavid Herrmann 		user->remove(conn, user);
15782c8e1411SDavid Herrmann 	}
15792c8e1411SDavid Herrmann }
15802c8e1411SDavid Herrmann 
15815d3de7dfSVinicius Costa Gomes static void l2cap_conn_del(struct hci_conn *hcon, int err)
15825d3de7dfSVinicius Costa Gomes {
15835d3de7dfSVinicius Costa Gomes 	struct l2cap_conn *conn = hcon->l2cap_data;
15845d3de7dfSVinicius Costa Gomes 	struct l2cap_chan *chan, *l;
15855d3de7dfSVinicius Costa Gomes 
15865d3de7dfSVinicius Costa Gomes 	if (!conn)
15875d3de7dfSVinicius Costa Gomes 		return;
15885d3de7dfSVinicius Costa Gomes 
15895d3de7dfSVinicius Costa Gomes 	BT_DBG("hcon %p conn %p, err %d", hcon, conn, err);
15905d3de7dfSVinicius Costa Gomes 
15915d3de7dfSVinicius Costa Gomes 	kfree_skb(conn->rx_skb);
15925d3de7dfSVinicius Costa Gomes 
15932c8e1411SDavid Herrmann 	l2cap_unregister_all_users(conn);
15942c8e1411SDavid Herrmann 
15953df91ea2SAndrei Emeltchenko 	mutex_lock(&conn->chan_lock);
15963df91ea2SAndrei Emeltchenko 
15975d3de7dfSVinicius Costa Gomes 	/* Kill channels */
15985d3de7dfSVinicius Costa Gomes 	list_for_each_entry_safe(chan, l, &conn->chan_l, list) {
159961d6ef3eSMat Martineau 		l2cap_chan_hold(chan);
16006be36555SAndrei Emeltchenko 		l2cap_chan_lock(chan);
16016be36555SAndrei Emeltchenko 
16025d3de7dfSVinicius Costa Gomes 		l2cap_chan_del(chan, err);
16036be36555SAndrei Emeltchenko 
16046be36555SAndrei Emeltchenko 		l2cap_chan_unlock(chan);
16056be36555SAndrei Emeltchenko 
160680b98027SGustavo Padovan 		chan->ops->close(chan);
160761d6ef3eSMat Martineau 		l2cap_chan_put(chan);
16085d3de7dfSVinicius Costa Gomes 	}
16095d3de7dfSVinicius Costa Gomes 
16103df91ea2SAndrei Emeltchenko 	mutex_unlock(&conn->chan_lock);
16113df91ea2SAndrei Emeltchenko 
161273d80debSLuiz Augusto von Dentz 	hci_chan_del(conn->hchan);
161373d80debSLuiz Augusto von Dentz 
16145d3de7dfSVinicius Costa Gomes 	if (conn->info_state & L2CAP_INFO_FEAT_MASK_REQ_SENT)
1615127074bfSUlisses Furquim 		cancel_delayed_work_sync(&conn->info_timer);
16165d3de7dfSVinicius Costa Gomes 
161751a8efd7SJohan Hedberg 	if (test_and_clear_bit(HCI_CONN_LE_SMP_PEND, &hcon->flags)) {
1618127074bfSUlisses Furquim 		cancel_delayed_work_sync(&conn->security_timer);
16198aab4757SVinicius Costa Gomes 		smp_chan_destroy(conn);
1620d26a2345SVinicius Costa Gomes 	}
16215d3de7dfSVinicius Costa Gomes 
16225d3de7dfSVinicius Costa Gomes 	hcon->l2cap_data = NULL;
16239c903e37SDavid Herrmann 	conn->hchan = NULL;
16249c903e37SDavid Herrmann 	l2cap_conn_put(conn);
16255d3de7dfSVinicius Costa Gomes }
16265d3de7dfSVinicius Costa Gomes 
16276c9d42a1SGustavo F. Padovan static void security_timeout(struct work_struct *work)
16285d3de7dfSVinicius Costa Gomes {
16296c9d42a1SGustavo F. Padovan 	struct l2cap_conn *conn = container_of(work, struct l2cap_conn,
16306c9d42a1SGustavo F. Padovan 					       security_timer.work);
16315d3de7dfSVinicius Costa Gomes 
1632d06cc416SJohan Hedberg 	BT_DBG("conn %p", conn);
1633d06cc416SJohan Hedberg 
1634d06cc416SJohan Hedberg 	if (test_and_clear_bit(HCI_CONN_LE_SMP_PEND, &conn->hcon->flags)) {
1635d06cc416SJohan Hedberg 		smp_chan_destroy(conn);
16365d3de7dfSVinicius Costa Gomes 		l2cap_conn_del(conn->hcon, ETIMEDOUT);
16375d3de7dfSVinicius Costa Gomes 	}
1638d06cc416SJohan Hedberg }
16395d3de7dfSVinicius Costa Gomes 
1640baf43251SClaudio Takahasi static struct l2cap_conn *l2cap_conn_add(struct hci_conn *hcon)
16410a708f8fSGustavo F. Padovan {
16420a708f8fSGustavo F. Padovan 	struct l2cap_conn *conn = hcon->l2cap_data;
164373d80debSLuiz Augusto von Dentz 	struct hci_chan *hchan;
16440a708f8fSGustavo F. Padovan 
1645baf43251SClaudio Takahasi 	if (conn)
16460a708f8fSGustavo F. Padovan 		return conn;
16470a708f8fSGustavo F. Padovan 
164873d80debSLuiz Augusto von Dentz 	hchan = hci_chan_create(hcon);
164973d80debSLuiz Augusto von Dentz 	if (!hchan)
16500a708f8fSGustavo F. Padovan 		return NULL;
16510a708f8fSGustavo F. Padovan 
16528bcde1f2SGustavo Padovan 	conn = kzalloc(sizeof(struct l2cap_conn), GFP_KERNEL);
165373d80debSLuiz Augusto von Dentz 	if (!conn) {
165473d80debSLuiz Augusto von Dentz 		hci_chan_del(hchan);
165573d80debSLuiz Augusto von Dentz 		return NULL;
165673d80debSLuiz Augusto von Dentz 	}
165773d80debSLuiz Augusto von Dentz 
16589c903e37SDavid Herrmann 	kref_init(&conn->ref);
16590a708f8fSGustavo F. Padovan 	hcon->l2cap_data = conn;
16600a708f8fSGustavo F. Padovan 	conn->hcon = hcon;
16619c903e37SDavid Herrmann 	hci_conn_get(conn->hcon);
166273d80debSLuiz Augusto von Dentz 	conn->hchan = hchan;
16630a708f8fSGustavo F. Padovan 
166473d80debSLuiz Augusto von Dentz 	BT_DBG("hcon %p conn %p hchan %p", hcon, conn, hchan);
16650a708f8fSGustavo F. Padovan 
1666dcc042d5SAndrei Emeltchenko 	switch (hcon->type) {
1667dcc042d5SAndrei Emeltchenko 	case LE_LINK:
1668dcc042d5SAndrei Emeltchenko 		if (hcon->hdev->le_mtu) {
1669acd7d370SVille Tervo 			conn->mtu = hcon->hdev->le_mtu;
1670dcc042d5SAndrei Emeltchenko 			break;
1671dcc042d5SAndrei Emeltchenko 		}
1672dcc042d5SAndrei Emeltchenko 		/* fall through */
1673dcc042d5SAndrei Emeltchenko 	default:
16740a708f8fSGustavo F. Padovan 		conn->mtu = hcon->hdev->acl_mtu;
1675dcc042d5SAndrei Emeltchenko 		break;
1676dcc042d5SAndrei Emeltchenko 	}
1677acd7d370SVille Tervo 
16780a708f8fSGustavo F. Padovan 	conn->feat_mask = 0;
16790a708f8fSGustavo F. Padovan 
1680848566b3SMarcel Holtmann 	if (hcon->type == ACL_LINK)
1681848566b3SMarcel Holtmann 		conn->hs_enabled = test_bit(HCI_HS_ENABLED,
1682848566b3SMarcel Holtmann 					    &hcon->hdev->dev_flags);
1683848566b3SMarcel Holtmann 
16840a708f8fSGustavo F. Padovan 	spin_lock_init(&conn->lock);
16853df91ea2SAndrei Emeltchenko 	mutex_init(&conn->chan_lock);
1686baa7e1faSGustavo F. Padovan 
1687baa7e1faSGustavo F. Padovan 	INIT_LIST_HEAD(&conn->chan_l);
16882c8e1411SDavid Herrmann 	INIT_LIST_HEAD(&conn->users);
16890a708f8fSGustavo F. Padovan 
16905d3de7dfSVinicius Costa Gomes 	if (hcon->type == LE_LINK)
16916c9d42a1SGustavo F. Padovan 		INIT_DELAYED_WORK(&conn->security_timer, security_timeout);
16925d3de7dfSVinicius Costa Gomes 	else
1693030013d8SGustavo F. Padovan 		INIT_DELAYED_WORK(&conn->info_timer, l2cap_info_timeout);
16940a708f8fSGustavo F. Padovan 
16959f5a0d7bSAndrei Emeltchenko 	conn->disc_reason = HCI_ERROR_REMOTE_USER_TERM;
16960a708f8fSGustavo F. Padovan 
16970a708f8fSGustavo F. Padovan 	return conn;
16980a708f8fSGustavo F. Padovan }
16990a708f8fSGustavo F. Padovan 
17009c903e37SDavid Herrmann static void l2cap_conn_free(struct kref *ref)
17019c903e37SDavid Herrmann {
17029c903e37SDavid Herrmann 	struct l2cap_conn *conn = container_of(ref, struct l2cap_conn, ref);
17039c903e37SDavid Herrmann 
17049c903e37SDavid Herrmann 	hci_conn_put(conn->hcon);
17059c903e37SDavid Herrmann 	kfree(conn);
17069c903e37SDavid Herrmann }
17079c903e37SDavid Herrmann 
17089c903e37SDavid Herrmann void l2cap_conn_get(struct l2cap_conn *conn)
17099c903e37SDavid Herrmann {
17109c903e37SDavid Herrmann 	kref_get(&conn->ref);
17119c903e37SDavid Herrmann }
17129c903e37SDavid Herrmann EXPORT_SYMBOL(l2cap_conn_get);
17139c903e37SDavid Herrmann 
17149c903e37SDavid Herrmann void l2cap_conn_put(struct l2cap_conn *conn)
17159c903e37SDavid Herrmann {
17169c903e37SDavid Herrmann 	kref_put(&conn->ref, l2cap_conn_free);
17179c903e37SDavid Herrmann }
17189c903e37SDavid Herrmann EXPORT_SYMBOL(l2cap_conn_put);
17199c903e37SDavid Herrmann 
17200a708f8fSGustavo F. Padovan /* ---- Socket interface ---- */
17210a708f8fSGustavo F. Padovan 
1722c2287681SIdo Yariv /* Find socket with psm and source / destination bdaddr.
17230a708f8fSGustavo F. Padovan  * Returns closest match.
17240a708f8fSGustavo F. Padovan  */
1725c2287681SIdo Yariv static struct l2cap_chan *l2cap_global_chan_by_psm(int state, __le16 psm,
1726c2287681SIdo Yariv 						   bdaddr_t *src,
1727c2287681SIdo Yariv 						   bdaddr_t *dst)
17280a708f8fSGustavo F. Padovan {
172923691d75SGustavo F. Padovan 	struct l2cap_chan *c, *c1 = NULL;
17300a708f8fSGustavo F. Padovan 
173123691d75SGustavo F. Padovan 	read_lock(&chan_list_lock);
17320a708f8fSGustavo F. Padovan 
173323691d75SGustavo F. Padovan 	list_for_each_entry(c, &chan_list, global_l) {
173489bc500eSGustavo F. Padovan 		if (state && c->state != state)
17350a708f8fSGustavo F. Padovan 			continue;
17360a708f8fSGustavo F. Padovan 
173723691d75SGustavo F. Padovan 		if (c->psm == psm) {
1738c2287681SIdo Yariv 			int src_match, dst_match;
1739c2287681SIdo Yariv 			int src_any, dst_any;
1740c2287681SIdo Yariv 
17410a708f8fSGustavo F. Padovan 			/* Exact match. */
17427eafc59eSMarcel Holtmann 			src_match = !bacmp(&c->src, src);
17437eafc59eSMarcel Holtmann 			dst_match = !bacmp(&c->dst, dst);
1744c2287681SIdo Yariv 			if (src_match && dst_match) {
1745a7567b20SJohannes Berg 				read_unlock(&chan_list_lock);
174623691d75SGustavo F. Padovan 				return c;
174723691d75SGustavo F. Padovan 			}
17480a708f8fSGustavo F. Padovan 
17490a708f8fSGustavo F. Padovan 			/* Closest match */
17507eafc59eSMarcel Holtmann 			src_any = !bacmp(&c->src, BDADDR_ANY);
17517eafc59eSMarcel Holtmann 			dst_any = !bacmp(&c->dst, BDADDR_ANY);
1752c2287681SIdo Yariv 			if ((src_match && dst_any) || (src_any && dst_match) ||
1753c2287681SIdo Yariv 			    (src_any && dst_any))
175423691d75SGustavo F. Padovan 				c1 = c;
17550a708f8fSGustavo F. Padovan 		}
17560a708f8fSGustavo F. Padovan 	}
17570a708f8fSGustavo F. Padovan 
175823691d75SGustavo F. Padovan 	read_unlock(&chan_list_lock);
17590a708f8fSGustavo F. Padovan 
176023691d75SGustavo F. Padovan 	return c1;
17610a708f8fSGustavo F. Padovan }
17620a708f8fSGustavo F. Padovan 
17638e9f9892SAndre Guedes int l2cap_chan_connect(struct l2cap_chan *chan, __le16 psm, u16 cid,
17648e9f9892SAndre Guedes 		       bdaddr_t *dst, u8 dst_type)
17650a708f8fSGustavo F. Padovan {
17660a708f8fSGustavo F. Padovan 	struct l2cap_conn *conn;
17670a708f8fSGustavo F. Padovan 	struct hci_conn *hcon;
17680a708f8fSGustavo F. Padovan 	struct hci_dev *hdev;
17690a708f8fSGustavo F. Padovan 	__u8 auth_type;
17700a708f8fSGustavo F. Padovan 	int err;
17710a708f8fSGustavo F. Padovan 
17727eafc59eSMarcel Holtmann 	BT_DBG("%pMR -> %pMR (type %u) psm 0x%2.2x", &chan->src, dst,
1773ab19516aSSyam Sidhardhan 	       dst_type, __le16_to_cpu(psm));
17740a708f8fSGustavo F. Padovan 
17757eafc59eSMarcel Holtmann 	hdev = hci_get_route(dst, &chan->src);
17760a708f8fSGustavo F. Padovan 	if (!hdev)
17770a708f8fSGustavo F. Padovan 		return -EHOSTUNREACH;
17780a708f8fSGustavo F. Padovan 
177909fd0de5SGustavo F. Padovan 	hci_dev_lock(hdev);
17800a708f8fSGustavo F. Padovan 
17816be36555SAndrei Emeltchenko 	l2cap_chan_lock(chan);
178203a00194SGustavo F. Padovan 
178303a00194SGustavo F. Padovan 	/* PSM must be odd and lsb of upper byte must be 0 */
178403a00194SGustavo F. Padovan 	if ((__le16_to_cpu(psm) & 0x0101) != 0x0001 && !cid &&
178503a00194SGustavo F. Padovan 	    chan->chan_type != L2CAP_CHAN_RAW) {
178603a00194SGustavo F. Padovan 		err = -EINVAL;
178703a00194SGustavo F. Padovan 		goto done;
178803a00194SGustavo F. Padovan 	}
178903a00194SGustavo F. Padovan 
179003a00194SGustavo F. Padovan 	if (chan->chan_type == L2CAP_CHAN_CONN_ORIENTED && !(psm || cid)) {
179103a00194SGustavo F. Padovan 		err = -EINVAL;
179203a00194SGustavo F. Padovan 		goto done;
179303a00194SGustavo F. Padovan 	}
179403a00194SGustavo F. Padovan 
179503a00194SGustavo F. Padovan 	switch (chan->mode) {
179603a00194SGustavo F. Padovan 	case L2CAP_MODE_BASIC:
179703a00194SGustavo F. Padovan 		break;
179803a00194SGustavo F. Padovan 	case L2CAP_MODE_ERTM:
179903a00194SGustavo F. Padovan 	case L2CAP_MODE_STREAMING:
180003a00194SGustavo F. Padovan 		if (!disable_ertm)
180103a00194SGustavo F. Padovan 			break;
180203a00194SGustavo F. Padovan 		/* fall through */
180303a00194SGustavo F. Padovan 	default:
180403a00194SGustavo F. Padovan 		err = -ENOTSUPP;
180503a00194SGustavo F. Padovan 		goto done;
180603a00194SGustavo F. Padovan 	}
180703a00194SGustavo F. Padovan 
18080797e01dSGustavo Padovan 	switch (chan->state) {
180903a00194SGustavo F. Padovan 	case BT_CONNECT:
181003a00194SGustavo F. Padovan 	case BT_CONNECT2:
181103a00194SGustavo F. Padovan 	case BT_CONFIG:
181203a00194SGustavo F. Padovan 		/* Already connecting */
181303a00194SGustavo F. Padovan 		err = 0;
181403a00194SGustavo F. Padovan 		goto done;
181503a00194SGustavo F. Padovan 
181603a00194SGustavo F. Padovan 	case BT_CONNECTED:
181703a00194SGustavo F. Padovan 		/* Already connected */
181803a00194SGustavo F. Padovan 		err = -EISCONN;
181903a00194SGustavo F. Padovan 		goto done;
182003a00194SGustavo F. Padovan 
182103a00194SGustavo F. Padovan 	case BT_OPEN:
182203a00194SGustavo F. Padovan 	case BT_BOUND:
182303a00194SGustavo F. Padovan 		/* Can connect */
182403a00194SGustavo F. Padovan 		break;
182503a00194SGustavo F. Padovan 
182603a00194SGustavo F. Padovan 	default:
182703a00194SGustavo F. Padovan 		err = -EBADFD;
182803a00194SGustavo F. Padovan 		goto done;
182903a00194SGustavo F. Padovan 	}
183003a00194SGustavo F. Padovan 
183103a00194SGustavo F. Padovan 	/* Set destination address and psm */
18327eafc59eSMarcel Holtmann 	bacpy(&chan->dst, dst);
18334f1654e0SMarcel Holtmann 	chan->dst_type = dst_type;
18346be36555SAndrei Emeltchenko 
183503a00194SGustavo F. Padovan 	chan->psm = psm;
183603a00194SGustavo F. Padovan 	chan->dcid = cid;
18370a708f8fSGustavo F. Padovan 
18384343478fSGustavo F. Padovan 	auth_type = l2cap_get_auth_type(chan);
18390a708f8fSGustavo F. Padovan 
1840f224ca5fSJohan Hedberg 	if (bdaddr_type_is_le(dst_type))
18418e9f9892SAndre Guedes 		hcon = hci_connect(hdev, LE_LINK, dst, dst_type,
18424343478fSGustavo F. Padovan 				   chan->sec_level, auth_type);
1843acd7d370SVille Tervo 	else
18448e9f9892SAndre Guedes 		hcon = hci_connect(hdev, ACL_LINK, dst, dst_type,
18454343478fSGustavo F. Padovan 				   chan->sec_level, auth_type);
1846acd7d370SVille Tervo 
184730e76272SVille Tervo 	if (IS_ERR(hcon)) {
184830e76272SVille Tervo 		err = PTR_ERR(hcon);
18490a708f8fSGustavo F. Padovan 		goto done;
185030e76272SVille Tervo 	}
18510a708f8fSGustavo F. Padovan 
1852baf43251SClaudio Takahasi 	conn = l2cap_conn_add(hcon);
18530a708f8fSGustavo F. Padovan 	if (!conn) {
185476a68ba0SDavid Herrmann 		hci_conn_drop(hcon);
185530e76272SVille Tervo 		err = -ENOMEM;
18560a708f8fSGustavo F. Padovan 		goto done;
18570a708f8fSGustavo F. Padovan 	}
18580a708f8fSGustavo F. Padovan 
1859141d5706SJohan Hedberg 	if (cid && __l2cap_get_chan_by_dcid(conn, cid)) {
186076a68ba0SDavid Herrmann 		hci_conn_drop(hcon);
1861141d5706SJohan Hedberg 		err = -EBUSY;
18629f0caeb1SVinicius Costa Gomes 		goto done;
18639f0caeb1SVinicius Costa Gomes 	}
18649f0caeb1SVinicius Costa Gomes 
18650a708f8fSGustavo F. Padovan 	/* Update source addr of the socket */
18667eafc59eSMarcel Holtmann 	bacpy(&chan->src, &hcon->src);
18674f1654e0SMarcel Holtmann 	chan->src_type = bdaddr_type(hcon, hcon->src_type);
18680a708f8fSGustavo F. Padovan 
18696be36555SAndrei Emeltchenko 	l2cap_chan_unlock(chan);
187048454079SGustavo F. Padovan 	l2cap_chan_add(conn, chan);
18716be36555SAndrei Emeltchenko 	l2cap_chan_lock(chan);
187248454079SGustavo F. Padovan 
18735ee9891dSJohan Hedberg 	/* l2cap_chan_add takes its own ref so we can drop this one */
18745ee9891dSJohan Hedberg 	hci_conn_drop(hcon);
18755ee9891dSJohan Hedberg 
18766be36555SAndrei Emeltchenko 	l2cap_state_change(chan, BT_CONNECT);
18778d836d71SGustavo Padovan 	__set_chan_timer(chan, chan->ops->get_sndtimeo(chan));
18780a708f8fSGustavo F. Padovan 
18790a708f8fSGustavo F. Padovan 	if (hcon->state == BT_CONNECTED) {
1880715ec005SGustavo F. Padovan 		if (chan->chan_type != L2CAP_CHAN_CONN_ORIENTED) {
1881c9b66675SGustavo F. Padovan 			__clear_chan_timer(chan);
1882d45fc423SGustavo F. Padovan 			if (l2cap_chan_check_security(chan))
18836be36555SAndrei Emeltchenko 				l2cap_state_change(chan, BT_CONNECTED);
18840a708f8fSGustavo F. Padovan 		} else
1885fc7f8a7eSGustavo F. Padovan 			l2cap_do_start(chan);
18860a708f8fSGustavo F. Padovan 	}
18870a708f8fSGustavo F. Padovan 
188830e76272SVille Tervo 	err = 0;
188930e76272SVille Tervo 
18900a708f8fSGustavo F. Padovan done:
18916be36555SAndrei Emeltchenko 	l2cap_chan_unlock(chan);
189209fd0de5SGustavo F. Padovan 	hci_dev_unlock(hdev);
18930a708f8fSGustavo F. Padovan 	hci_dev_put(hdev);
18940a708f8fSGustavo F. Padovan 	return err;
18950a708f8fSGustavo F. Padovan }
18960a708f8fSGustavo F. Padovan 
1897dcba0dbaSGustavo F. Padovan int __l2cap_wait_ack(struct sock *sk)
18980a708f8fSGustavo F. Padovan {
18998c1d787bSGustavo F. Padovan 	struct l2cap_chan *chan = l2cap_pi(sk)->chan;
19000a708f8fSGustavo F. Padovan 	DECLARE_WAITQUEUE(wait, current);
19010a708f8fSGustavo F. Padovan 	int err = 0;
19020a708f8fSGustavo F. Padovan 	int timeo = HZ/5;
19030a708f8fSGustavo F. Padovan 
19040a708f8fSGustavo F. Padovan 	add_wait_queue(sk_sleep(sk), &wait);
19050a708f8fSGustavo F. Padovan 	set_current_state(TASK_INTERRUPTIBLE);
1906a71a0cf4SPeter Hurley 	while (chan->unacked_frames > 0 && chan->conn) {
19070a708f8fSGustavo F. Padovan 		if (!timeo)
19080a708f8fSGustavo F. Padovan 			timeo = HZ/5;
19090a708f8fSGustavo F. Padovan 
19100a708f8fSGustavo F. Padovan 		if (signal_pending(current)) {
19110a708f8fSGustavo F. Padovan 			err = sock_intr_errno(timeo);
19120a708f8fSGustavo F. Padovan 			break;
19130a708f8fSGustavo F. Padovan 		}
19140a708f8fSGustavo F. Padovan 
19150a708f8fSGustavo F. Padovan 		release_sock(sk);
19160a708f8fSGustavo F. Padovan 		timeo = schedule_timeout(timeo);
19170a708f8fSGustavo F. Padovan 		lock_sock(sk);
1918a71a0cf4SPeter Hurley 		set_current_state(TASK_INTERRUPTIBLE);
19190a708f8fSGustavo F. Padovan 
19200a708f8fSGustavo F. Padovan 		err = sock_error(sk);
19210a708f8fSGustavo F. Padovan 		if (err)
19220a708f8fSGustavo F. Padovan 			break;
19230a708f8fSGustavo F. Padovan 	}
19240a708f8fSGustavo F. Padovan 	set_current_state(TASK_RUNNING);
19250a708f8fSGustavo F. Padovan 	remove_wait_queue(sk_sleep(sk), &wait);
19260a708f8fSGustavo F. Padovan 	return err;
19270a708f8fSGustavo F. Padovan }
19280a708f8fSGustavo F. Padovan 
1929721c4181SGustavo F. Padovan static void l2cap_monitor_timeout(struct work_struct *work)
19300a708f8fSGustavo F. Padovan {
1931721c4181SGustavo F. Padovan 	struct l2cap_chan *chan = container_of(work, struct l2cap_chan,
1932721c4181SGustavo F. Padovan 					       monitor_timer.work);
19330a708f8fSGustavo F. Padovan 
1934525cd185SGustavo F. Padovan 	BT_DBG("chan %p", chan);
19350a708f8fSGustavo F. Padovan 
19366be36555SAndrei Emeltchenko 	l2cap_chan_lock(chan);
19376be36555SAndrei Emeltchenko 
193880909e04SMat Martineau 	if (!chan->conn) {
19396be36555SAndrei Emeltchenko 		l2cap_chan_unlock(chan);
19408d7e1c7fSAndrei Emeltchenko 		l2cap_chan_put(chan);
19410a708f8fSGustavo F. Padovan 		return;
19420a708f8fSGustavo F. Padovan 	}
19430a708f8fSGustavo F. Padovan 
1944401bb1f7SAndrei Emeltchenko 	l2cap_tx(chan, NULL, NULL, L2CAP_EV_MONITOR_TO);
19450a708f8fSGustavo F. Padovan 
19466be36555SAndrei Emeltchenko 	l2cap_chan_unlock(chan);
19478d7e1c7fSAndrei Emeltchenko 	l2cap_chan_put(chan);
19480a708f8fSGustavo F. Padovan }
19490a708f8fSGustavo F. Padovan 
1950721c4181SGustavo F. Padovan static void l2cap_retrans_timeout(struct work_struct *work)
19510a708f8fSGustavo F. Padovan {
1952721c4181SGustavo F. Padovan 	struct l2cap_chan *chan = container_of(work, struct l2cap_chan,
1953721c4181SGustavo F. Padovan 					       retrans_timer.work);
19540a708f8fSGustavo F. Padovan 
195549208c9cSGustavo F. Padovan 	BT_DBG("chan %p", chan);
19560a708f8fSGustavo F. Padovan 
19576be36555SAndrei Emeltchenko 	l2cap_chan_lock(chan);
19586be36555SAndrei Emeltchenko 
195980909e04SMat Martineau 	if (!chan->conn) {
196080909e04SMat Martineau 		l2cap_chan_unlock(chan);
196180909e04SMat Martineau 		l2cap_chan_put(chan);
196280909e04SMat Martineau 		return;
196380909e04SMat Martineau 	}
19640a708f8fSGustavo F. Padovan 
1965401bb1f7SAndrei Emeltchenko 	l2cap_tx(chan, NULL, NULL, L2CAP_EV_RETRANS_TO);
19666be36555SAndrei Emeltchenko 	l2cap_chan_unlock(chan);
19678d7e1c7fSAndrei Emeltchenko 	l2cap_chan_put(chan);
19680a708f8fSGustavo F. Padovan }
19690a708f8fSGustavo F. Padovan 
1970d660366dSGustavo Padovan static void l2cap_streaming_send(struct l2cap_chan *chan,
19713733937dSMat Martineau 				 struct sk_buff_head *skbs)
19720a708f8fSGustavo F. Padovan {
19730a708f8fSGustavo F. Padovan 	struct sk_buff *skb;
19743733937dSMat Martineau 	struct l2cap_ctrl *control;
19750a708f8fSGustavo F. Padovan 
19763733937dSMat Martineau 	BT_DBG("chan %p, skbs %p", chan, skbs);
19773733937dSMat Martineau 
1978b99e13adSMat Martineau 	if (__chan_is_moving(chan))
1979b99e13adSMat Martineau 		return;
1980b99e13adSMat Martineau 
19813733937dSMat Martineau 	skb_queue_splice_tail_init(skbs, &chan->tx_q);
19823733937dSMat Martineau 
19833733937dSMat Martineau 	while (!skb_queue_empty(&chan->tx_q)) {
19843733937dSMat Martineau 
19853733937dSMat Martineau 		skb = skb_dequeue(&chan->tx_q);
19863733937dSMat Martineau 
19873733937dSMat Martineau 		bt_cb(skb)->control.retries = 1;
19883733937dSMat Martineau 		control = &bt_cb(skb)->control;
19893733937dSMat Martineau 
19903733937dSMat Martineau 		control->reqseq = 0;
19913733937dSMat Martineau 		control->txseq = chan->next_tx_seq;
19923733937dSMat Martineau 
19933733937dSMat Martineau 		__pack_control(chan, control, skb);
19940a708f8fSGustavo F. Padovan 
199547d1ec61SGustavo F. Padovan 		if (chan->fcs == L2CAP_FCS_CRC16) {
19963733937dSMat Martineau 			u16 fcs = crc16(0, (u8 *) skb->data, skb->len);
19973733937dSMat Martineau 			put_unaligned_le16(fcs, skb_put(skb, L2CAP_FCS_SIZE));
19980a708f8fSGustavo F. Padovan 		}
19990a708f8fSGustavo F. Padovan 
20004343478fSGustavo F. Padovan 		l2cap_do_send(chan, skb);
20010a708f8fSGustavo F. Padovan 
2002b4400672SAndrei Emeltchenko 		BT_DBG("Sent txseq %u", control->txseq);
20033733937dSMat Martineau 
2004836be934SAndrei Emeltchenko 		chan->next_tx_seq = __next_seq(chan, chan->next_tx_seq);
20053733937dSMat Martineau 		chan->frames_sent++;
20060a708f8fSGustavo F. Padovan 	}
20070a708f8fSGustavo F. Padovan }
20080a708f8fSGustavo F. Padovan 
200967c9e840SSzymon Janc static int l2cap_ertm_send(struct l2cap_chan *chan)
20100a708f8fSGustavo F. Padovan {
20110a708f8fSGustavo F. Padovan 	struct sk_buff *skb, *tx_skb;
201218a48e76SMat Martineau 	struct l2cap_ctrl *control;
201318a48e76SMat Martineau 	int sent = 0;
201418a48e76SMat Martineau 
201518a48e76SMat Martineau 	BT_DBG("chan %p", chan);
20160a708f8fSGustavo F. Padovan 
201789bc500eSGustavo F. Padovan 	if (chan->state != BT_CONNECTED)
20180a708f8fSGustavo F. Padovan 		return -ENOTCONN;
20190a708f8fSGustavo F. Padovan 
202094122bbeSMat Martineau 	if (test_bit(CONN_REMOTE_BUSY, &chan->conn_state))
202194122bbeSMat Martineau 		return 0;
202294122bbeSMat Martineau 
2023b99e13adSMat Martineau 	if (__chan_is_moving(chan))
2024b99e13adSMat Martineau 		return 0;
2025b99e13adSMat Martineau 
202618a48e76SMat Martineau 	while (chan->tx_send_head &&
202718a48e76SMat Martineau 	       chan->unacked_frames < chan->remote_tx_win &&
202818a48e76SMat Martineau 	       chan->tx_state == L2CAP_TX_STATE_XMIT) {
20290a708f8fSGustavo F. Padovan 
203018a48e76SMat Martineau 		skb = chan->tx_send_head;
20310a708f8fSGustavo F. Padovan 
203218a48e76SMat Martineau 		bt_cb(skb)->control.retries = 1;
203318a48e76SMat Martineau 		control = &bt_cb(skb)->control;
20340a708f8fSGustavo F. Padovan 
2035e2ab4353SGustavo F. Padovan 		if (test_and_clear_bit(CONN_SEND_FBIT, &chan->conn_state))
203618a48e76SMat Martineau 			control->final = 1;
2037e2ab4353SGustavo F. Padovan 
203818a48e76SMat Martineau 		control->reqseq = chan->buffer_seq;
203918a48e76SMat Martineau 		chan->last_acked_seq = chan->buffer_seq;
204018a48e76SMat Martineau 		control->txseq = chan->next_tx_seq;
20410a708f8fSGustavo F. Padovan 
204218a48e76SMat Martineau 		__pack_control(chan, control, skb);
20430a708f8fSGustavo F. Padovan 
204447d1ec61SGustavo F. Padovan 		if (chan->fcs == L2CAP_FCS_CRC16) {
204518a48e76SMat Martineau 			u16 fcs = crc16(0, (u8 *) skb->data, skb->len);
204618a48e76SMat Martineau 			put_unaligned_le16(fcs, skb_put(skb, L2CAP_FCS_SIZE));
20470a708f8fSGustavo F. Padovan 		}
20480a708f8fSGustavo F. Padovan 
204918a48e76SMat Martineau 		/* Clone after data has been modified. Data is assumed to be
205018a48e76SMat Martineau 		   read-only (for locking purposes) on cloned sk_buffs.
205118a48e76SMat Martineau 		 */
205218a48e76SMat Martineau 		tx_skb = skb_clone(skb, GFP_KERNEL);
205318a48e76SMat Martineau 
205418a48e76SMat Martineau 		if (!tx_skb)
205518a48e76SMat Martineau 			break;
20560a708f8fSGustavo F. Padovan 
20571a09bcb9SGustavo F. Padovan 		__set_retrans_timer(chan);
20580a708f8fSGustavo F. Padovan 
2059836be934SAndrei Emeltchenko 		chan->next_tx_seq = __next_seq(chan, chan->next_tx_seq);
20606a026610SGustavo F. Padovan 		chan->unacked_frames++;
20616a026610SGustavo F. Padovan 		chan->frames_sent++;
206218a48e76SMat Martineau 		sent++;
20630a708f8fSGustavo F. Padovan 
206458d35f87SGustavo F. Padovan 		if (skb_queue_is_last(&chan->tx_q, skb))
206558d35f87SGustavo F. Padovan 			chan->tx_send_head = NULL;
20660a708f8fSGustavo F. Padovan 		else
206758d35f87SGustavo F. Padovan 			chan->tx_send_head = skb_queue_next(&chan->tx_q, skb);
206818a48e76SMat Martineau 
206918a48e76SMat Martineau 		l2cap_do_send(chan, tx_skb);
2070b4400672SAndrei Emeltchenko 		BT_DBG("Sent txseq %u", control->txseq);
20710a708f8fSGustavo F. Padovan 	}
20720a708f8fSGustavo F. Padovan 
2073b4400672SAndrei Emeltchenko 	BT_DBG("Sent %d, %u unacked, %u in ERTM queue", sent,
2074b4400672SAndrei Emeltchenko 	       chan->unacked_frames, skb_queue_len(&chan->tx_q));
207518a48e76SMat Martineau 
207618a48e76SMat Martineau 	return sent;
20770a708f8fSGustavo F. Padovan }
20780a708f8fSGustavo F. Padovan 
2079e1fbd4c1SMat Martineau static void l2cap_ertm_resend(struct l2cap_chan *chan)
2080e1fbd4c1SMat Martineau {
2081e1fbd4c1SMat Martineau 	struct l2cap_ctrl control;
2082e1fbd4c1SMat Martineau 	struct sk_buff *skb;
2083e1fbd4c1SMat Martineau 	struct sk_buff *tx_skb;
2084e1fbd4c1SMat Martineau 	u16 seq;
2085e1fbd4c1SMat Martineau 
2086e1fbd4c1SMat Martineau 	BT_DBG("chan %p", chan);
2087e1fbd4c1SMat Martineau 
2088e1fbd4c1SMat Martineau 	if (test_bit(CONN_REMOTE_BUSY, &chan->conn_state))
2089e1fbd4c1SMat Martineau 		return;
2090e1fbd4c1SMat Martineau 
2091b99e13adSMat Martineau 	if (__chan_is_moving(chan))
2092b99e13adSMat Martineau 		return;
2093b99e13adSMat Martineau 
2094e1fbd4c1SMat Martineau 	while (chan->retrans_list.head != L2CAP_SEQ_LIST_CLEAR) {
2095e1fbd4c1SMat Martineau 		seq = l2cap_seq_list_pop(&chan->retrans_list);
2096e1fbd4c1SMat Martineau 
2097e1fbd4c1SMat Martineau 		skb = l2cap_ertm_seq_in_queue(&chan->tx_q, seq);
2098e1fbd4c1SMat Martineau 		if (!skb) {
2099e1fbd4c1SMat Martineau 			BT_DBG("Error: Can't retransmit seq %d, frame missing",
2100e1fbd4c1SMat Martineau 			       seq);
2101e1fbd4c1SMat Martineau 			continue;
2102e1fbd4c1SMat Martineau 		}
2103e1fbd4c1SMat Martineau 
2104e1fbd4c1SMat Martineau 		bt_cb(skb)->control.retries++;
2105e1fbd4c1SMat Martineau 		control = bt_cb(skb)->control;
2106e1fbd4c1SMat Martineau 
2107e1fbd4c1SMat Martineau 		if (chan->max_tx != 0 &&
2108e1fbd4c1SMat Martineau 		    bt_cb(skb)->control.retries > chan->max_tx) {
2109e1fbd4c1SMat Martineau 			BT_DBG("Retry limit exceeded (%d)", chan->max_tx);
21105e4e3972SAndrei Emeltchenko 			l2cap_send_disconn_req(chan, ECONNRESET);
2111e1fbd4c1SMat Martineau 			l2cap_seq_list_clear(&chan->retrans_list);
2112e1fbd4c1SMat Martineau 			break;
2113e1fbd4c1SMat Martineau 		}
2114e1fbd4c1SMat Martineau 
2115e1fbd4c1SMat Martineau 		control.reqseq = chan->buffer_seq;
2116e1fbd4c1SMat Martineau 		if (test_and_clear_bit(CONN_SEND_FBIT, &chan->conn_state))
2117e1fbd4c1SMat Martineau 			control.final = 1;
2118e1fbd4c1SMat Martineau 		else
2119e1fbd4c1SMat Martineau 			control.final = 0;
2120e1fbd4c1SMat Martineau 
2121e1fbd4c1SMat Martineau 		if (skb_cloned(skb)) {
2122e1fbd4c1SMat Martineau 			/* Cloned sk_buffs are read-only, so we need a
2123e1fbd4c1SMat Martineau 			 * writeable copy
2124e1fbd4c1SMat Martineau 			 */
21258bcde1f2SGustavo Padovan 			tx_skb = skb_copy(skb, GFP_KERNEL);
2126e1fbd4c1SMat Martineau 		} else {
21278bcde1f2SGustavo Padovan 			tx_skb = skb_clone(skb, GFP_KERNEL);
2128e1fbd4c1SMat Martineau 		}
2129e1fbd4c1SMat Martineau 
2130e1fbd4c1SMat Martineau 		if (!tx_skb) {
2131e1fbd4c1SMat Martineau 			l2cap_seq_list_clear(&chan->retrans_list);
2132e1fbd4c1SMat Martineau 			break;
2133e1fbd4c1SMat Martineau 		}
2134e1fbd4c1SMat Martineau 
2135e1fbd4c1SMat Martineau 		/* Update skb contents */
2136e1fbd4c1SMat Martineau 		if (test_bit(FLAG_EXT_CTRL, &chan->flags)) {
2137e1fbd4c1SMat Martineau 			put_unaligned_le32(__pack_extended_control(&control),
2138e1fbd4c1SMat Martineau 					   tx_skb->data + L2CAP_HDR_SIZE);
2139e1fbd4c1SMat Martineau 		} else {
2140e1fbd4c1SMat Martineau 			put_unaligned_le16(__pack_enhanced_control(&control),
2141e1fbd4c1SMat Martineau 					   tx_skb->data + L2CAP_HDR_SIZE);
2142e1fbd4c1SMat Martineau 		}
2143e1fbd4c1SMat Martineau 
2144e1fbd4c1SMat Martineau 		if (chan->fcs == L2CAP_FCS_CRC16) {
2145e1fbd4c1SMat Martineau 			u16 fcs = crc16(0, (u8 *) tx_skb->data, tx_skb->len);
2146e1fbd4c1SMat Martineau 			put_unaligned_le16(fcs, skb_put(tx_skb,
2147e1fbd4c1SMat Martineau 							L2CAP_FCS_SIZE));
2148e1fbd4c1SMat Martineau 		}
2149e1fbd4c1SMat Martineau 
2150e1fbd4c1SMat Martineau 		l2cap_do_send(chan, tx_skb);
2151e1fbd4c1SMat Martineau 
2152e1fbd4c1SMat Martineau 		BT_DBG("Resent txseq %d", control.txseq);
2153e1fbd4c1SMat Martineau 
2154e1fbd4c1SMat Martineau 		chan->last_acked_seq = chan->buffer_seq;
2155e1fbd4c1SMat Martineau 	}
2156e1fbd4c1SMat Martineau }
2157e1fbd4c1SMat Martineau 
2158f80842a8SMat Martineau static void l2cap_retransmit(struct l2cap_chan *chan,
2159f80842a8SMat Martineau 			     struct l2cap_ctrl *control)
2160f80842a8SMat Martineau {
2161f80842a8SMat Martineau 	BT_DBG("chan %p, control %p", chan, control);
2162f80842a8SMat Martineau 
2163f80842a8SMat Martineau 	l2cap_seq_list_append(&chan->retrans_list, control->reqseq);
2164f80842a8SMat Martineau 	l2cap_ertm_resend(chan);
2165f80842a8SMat Martineau }
2166f80842a8SMat Martineau 
2167d2a7ac5dSMat Martineau static void l2cap_retransmit_all(struct l2cap_chan *chan,
2168d2a7ac5dSMat Martineau 				 struct l2cap_ctrl *control)
2169d2a7ac5dSMat Martineau {
2170e1fbd4c1SMat Martineau 	struct sk_buff *skb;
2171e1fbd4c1SMat Martineau 
2172e1fbd4c1SMat Martineau 	BT_DBG("chan %p, control %p", chan, control);
2173e1fbd4c1SMat Martineau 
2174e1fbd4c1SMat Martineau 	if (control->poll)
2175e1fbd4c1SMat Martineau 		set_bit(CONN_SEND_FBIT, &chan->conn_state);
2176e1fbd4c1SMat Martineau 
2177e1fbd4c1SMat Martineau 	l2cap_seq_list_clear(&chan->retrans_list);
2178e1fbd4c1SMat Martineau 
2179e1fbd4c1SMat Martineau 	if (test_bit(CONN_REMOTE_BUSY, &chan->conn_state))
2180e1fbd4c1SMat Martineau 		return;
2181e1fbd4c1SMat Martineau 
2182e1fbd4c1SMat Martineau 	if (chan->unacked_frames) {
2183e1fbd4c1SMat Martineau 		skb_queue_walk(&chan->tx_q, skb) {
2184e1fbd4c1SMat Martineau 			if (bt_cb(skb)->control.txseq == control->reqseq ||
2185e1fbd4c1SMat Martineau 			    skb == chan->tx_send_head)
2186e1fbd4c1SMat Martineau 				break;
2187e1fbd4c1SMat Martineau 		}
2188e1fbd4c1SMat Martineau 
2189e1fbd4c1SMat Martineau 		skb_queue_walk_from(&chan->tx_q, skb) {
2190e1fbd4c1SMat Martineau 			if (skb == chan->tx_send_head)
2191e1fbd4c1SMat Martineau 				break;
2192e1fbd4c1SMat Martineau 
2193e1fbd4c1SMat Martineau 			l2cap_seq_list_append(&chan->retrans_list,
2194e1fbd4c1SMat Martineau 					      bt_cb(skb)->control.txseq);
2195e1fbd4c1SMat Martineau 		}
2196e1fbd4c1SMat Martineau 
2197e1fbd4c1SMat Martineau 		l2cap_ertm_resend(chan);
2198e1fbd4c1SMat Martineau 	}
2199d2a7ac5dSMat Martineau }
2200d2a7ac5dSMat Martineau 
2201b17e73bbSSzymon Janc static void l2cap_send_ack(struct l2cap_chan *chan)
2202b17e73bbSSzymon Janc {
22030a0aba42SMat Martineau 	struct l2cap_ctrl control;
22040a0aba42SMat Martineau 	u16 frames_to_ack = __seq_offset(chan, chan->buffer_seq,
22050a0aba42SMat Martineau 					 chan->last_acked_seq);
22060a0aba42SMat Martineau 	int threshold;
22070a0aba42SMat Martineau 
22080a0aba42SMat Martineau 	BT_DBG("chan %p last_acked_seq %d buffer_seq %d",
22090a0aba42SMat Martineau 	       chan, chan->last_acked_seq, chan->buffer_seq);
22100a0aba42SMat Martineau 
22110a0aba42SMat Martineau 	memset(&control, 0, sizeof(control));
22120a0aba42SMat Martineau 	control.sframe = 1;
22130a0aba42SMat Martineau 
22140a0aba42SMat Martineau 	if (test_bit(CONN_LOCAL_BUSY, &chan->conn_state) &&
22150a0aba42SMat Martineau 	    chan->rx_state == L2CAP_RX_STATE_RECV) {
2216b17e73bbSSzymon Janc 		__clear_ack_timer(chan);
22170a0aba42SMat Martineau 		control.super = L2CAP_SUPER_RNR;
22180a0aba42SMat Martineau 		control.reqseq = chan->buffer_seq;
22190a0aba42SMat Martineau 		l2cap_send_sframe(chan, &control);
22200a0aba42SMat Martineau 	} else {
22210a0aba42SMat Martineau 		if (!test_bit(CONN_REMOTE_BUSY, &chan->conn_state)) {
22220a0aba42SMat Martineau 			l2cap_ertm_send(chan);
22230a0aba42SMat Martineau 			/* If any i-frames were sent, they included an ack */
22240a0aba42SMat Martineau 			if (chan->buffer_seq == chan->last_acked_seq)
22250a0aba42SMat Martineau 				frames_to_ack = 0;
22260a0aba42SMat Martineau 		}
22270a0aba42SMat Martineau 
2228c20f8e35SMat Martineau 		/* Ack now if the window is 3/4ths full.
22290a0aba42SMat Martineau 		 * Calculate without mul or div
22300a0aba42SMat Martineau 		 */
2231c20f8e35SMat Martineau 		threshold = chan->ack_win;
22320a0aba42SMat Martineau 		threshold += threshold << 1;
22330a0aba42SMat Martineau 		threshold >>= 2;
22340a0aba42SMat Martineau 
2235b4400672SAndrei Emeltchenko 		BT_DBG("frames_to_ack %u, threshold %d", frames_to_ack,
22360a0aba42SMat Martineau 		       threshold);
22370a0aba42SMat Martineau 
22380a0aba42SMat Martineau 		if (frames_to_ack >= threshold) {
22390a0aba42SMat Martineau 			__clear_ack_timer(chan);
22400a0aba42SMat Martineau 			control.super = L2CAP_SUPER_RR;
22410a0aba42SMat Martineau 			control.reqseq = chan->buffer_seq;
22420a0aba42SMat Martineau 			l2cap_send_sframe(chan, &control);
22430a0aba42SMat Martineau 			frames_to_ack = 0;
22440a0aba42SMat Martineau 		}
22450a0aba42SMat Martineau 
22460a0aba42SMat Martineau 		if (frames_to_ack)
22470a0aba42SMat Martineau 			__set_ack_timer(chan);
22480a0aba42SMat Martineau 	}
2249b17e73bbSSzymon Janc }
2250b17e73bbSSzymon Janc 
225104124681SGustavo F. Padovan static inline int l2cap_skbuff_fromiovec(struct l2cap_chan *chan,
225204124681SGustavo F. Padovan 					 struct msghdr *msg, int len,
225304124681SGustavo F. Padovan 					 int count, struct sk_buff *skb)
22540a708f8fSGustavo F. Padovan {
22550952a57aSAndrei Emeltchenko 	struct l2cap_conn *conn = chan->conn;
22560a708f8fSGustavo F. Padovan 	struct sk_buff **frag;
225790338947SGustavo Padovan 	int sent = 0;
22580a708f8fSGustavo F. Padovan 
22590a708f8fSGustavo F. Padovan 	if (memcpy_fromiovec(skb_put(skb, count), msg->msg_iov, count))
22600a708f8fSGustavo F. Padovan 		return -EFAULT;
22610a708f8fSGustavo F. Padovan 
22620a708f8fSGustavo F. Padovan 	sent += count;
22630a708f8fSGustavo F. Padovan 	len  -= count;
22640a708f8fSGustavo F. Padovan 
22650a708f8fSGustavo F. Padovan 	/* Continuation fragments (no L2CAP header) */
22660a708f8fSGustavo F. Padovan 	frag = &skb_shinfo(skb)->frag_list;
22670a708f8fSGustavo F. Padovan 	while (len) {
2268fbe00700SGustavo Padovan 		struct sk_buff *tmp;
2269fbe00700SGustavo Padovan 
22700a708f8fSGustavo F. Padovan 		count = min_t(unsigned int, conn->mtu, len);
22710a708f8fSGustavo F. Padovan 
2272fbe00700SGustavo Padovan 		tmp = chan->ops->alloc_skb(chan, count,
227390338947SGustavo Padovan 					   msg->msg_flags & MSG_DONTWAIT);
2274fbe00700SGustavo Padovan 		if (IS_ERR(tmp))
2275fbe00700SGustavo Padovan 			return PTR_ERR(tmp);
22762f7719ceSAndrei Emeltchenko 
2277fbe00700SGustavo Padovan 		*frag = tmp;
2278fbe00700SGustavo Padovan 
22790a708f8fSGustavo F. Padovan 		if (memcpy_fromiovec(skb_put(*frag, count), msg->msg_iov, count))
22800a708f8fSGustavo F. Padovan 			return -EFAULT;
22810a708f8fSGustavo F. Padovan 
22825e59b791SLuiz Augusto von Dentz 		(*frag)->priority = skb->priority;
22835e59b791SLuiz Augusto von Dentz 
22840a708f8fSGustavo F. Padovan 		sent += count;
22850a708f8fSGustavo F. Padovan 		len  -= count;
22860a708f8fSGustavo F. Padovan 
22872d0ed3d5SGustavo Padovan 		skb->len += (*frag)->len;
22882d0ed3d5SGustavo Padovan 		skb->data_len += (*frag)->len;
22892d0ed3d5SGustavo Padovan 
22900a708f8fSGustavo F. Padovan 		frag = &(*frag)->next;
22910a708f8fSGustavo F. Padovan 	}
22920a708f8fSGustavo F. Padovan 
22930a708f8fSGustavo F. Padovan 	return sent;
22940a708f8fSGustavo F. Padovan }
22950a708f8fSGustavo F. Padovan 
22965e59b791SLuiz Augusto von Dentz static struct sk_buff *l2cap_create_connless_pdu(struct l2cap_chan *chan,
22975e59b791SLuiz Augusto von Dentz 						 struct msghdr *msg, size_t len,
22985e59b791SLuiz Augusto von Dentz 						 u32 priority)
22990a708f8fSGustavo F. Padovan {
23008c1d787bSGustavo F. Padovan 	struct l2cap_conn *conn = chan->conn;
23010a708f8fSGustavo F. Padovan 	struct sk_buff *skb;
230203a51213SAndrei Emeltchenko 	int err, count, hlen = L2CAP_HDR_SIZE + L2CAP_PSMLEN_SIZE;
23030a708f8fSGustavo F. Padovan 	struct l2cap_hdr *lh;
23040a708f8fSGustavo F. Padovan 
230543b1b8dfSMarcel Holtmann 	BT_DBG("chan %p psm 0x%2.2x len %zu priority %u", chan,
230643b1b8dfSMarcel Holtmann 	       __le16_to_cpu(chan->psm), len, priority);
23070a708f8fSGustavo F. Padovan 
23080a708f8fSGustavo F. Padovan 	count = min_t(unsigned int, (conn->mtu - hlen), len);
23092f7719ceSAndrei Emeltchenko 
23102f7719ceSAndrei Emeltchenko 	skb = chan->ops->alloc_skb(chan, count + hlen,
231190338947SGustavo Padovan 				   msg->msg_flags & MSG_DONTWAIT);
231290338947SGustavo Padovan 	if (IS_ERR(skb))
231390338947SGustavo Padovan 		return skb;
23140a708f8fSGustavo F. Padovan 
23155e59b791SLuiz Augusto von Dentz 	skb->priority = priority;
23165e59b791SLuiz Augusto von Dentz 
23170a708f8fSGustavo F. Padovan 	/* Create L2CAP header */
23180a708f8fSGustavo F. Padovan 	lh = (struct l2cap_hdr *) skb_put(skb, L2CAP_HDR_SIZE);
2319fe4128e0SGustavo F. Padovan 	lh->cid = cpu_to_le16(chan->dcid);
2320daf6a78cSAndrei Emeltchenko 	lh->len = cpu_to_le16(len + L2CAP_PSMLEN_SIZE);
232143b1b8dfSMarcel Holtmann 	put_unaligned(chan->psm, (__le16 *) skb_put(skb, L2CAP_PSMLEN_SIZE));
23220a708f8fSGustavo F. Padovan 
23230952a57aSAndrei Emeltchenko 	err = l2cap_skbuff_fromiovec(chan, msg, len, count, skb);
23240a708f8fSGustavo F. Padovan 	if (unlikely(err < 0)) {
23250a708f8fSGustavo F. Padovan 		kfree_skb(skb);
23260a708f8fSGustavo F. Padovan 		return ERR_PTR(err);
23270a708f8fSGustavo F. Padovan 	}
23280a708f8fSGustavo F. Padovan 	return skb;
23290a708f8fSGustavo F. Padovan }
23300a708f8fSGustavo F. Padovan 
23315e59b791SLuiz Augusto von Dentz static struct sk_buff *l2cap_create_basic_pdu(struct l2cap_chan *chan,
23325e59b791SLuiz Augusto von Dentz 					      struct msghdr *msg, size_t len,
23335e59b791SLuiz Augusto von Dentz 					      u32 priority)
23340a708f8fSGustavo F. Padovan {
23358c1d787bSGustavo F. Padovan 	struct l2cap_conn *conn = chan->conn;
23360a708f8fSGustavo F. Padovan 	struct sk_buff *skb;
2337f2ba7faeSGustavo Padovan 	int err, count;
23380a708f8fSGustavo F. Padovan 	struct l2cap_hdr *lh;
23390a708f8fSGustavo F. Padovan 
2340b4400672SAndrei Emeltchenko 	BT_DBG("chan %p len %zu", chan, len);
23410a708f8fSGustavo F. Padovan 
2342f2ba7faeSGustavo Padovan 	count = min_t(unsigned int, (conn->mtu - L2CAP_HDR_SIZE), len);
23432f7719ceSAndrei Emeltchenko 
2344f2ba7faeSGustavo Padovan 	skb = chan->ops->alloc_skb(chan, count + L2CAP_HDR_SIZE,
234590338947SGustavo Padovan 				   msg->msg_flags & MSG_DONTWAIT);
234690338947SGustavo Padovan 	if (IS_ERR(skb))
234790338947SGustavo Padovan 		return skb;
23480a708f8fSGustavo F. Padovan 
23495e59b791SLuiz Augusto von Dentz 	skb->priority = priority;
23505e59b791SLuiz Augusto von Dentz 
23510a708f8fSGustavo F. Padovan 	/* Create L2CAP header */
23520a708f8fSGustavo F. Padovan 	lh = (struct l2cap_hdr *) skb_put(skb, L2CAP_HDR_SIZE);
2353fe4128e0SGustavo F. Padovan 	lh->cid = cpu_to_le16(chan->dcid);
23546ff9b5efSGustavo Padovan 	lh->len = cpu_to_le16(len);
23550a708f8fSGustavo F. Padovan 
23560952a57aSAndrei Emeltchenko 	err = l2cap_skbuff_fromiovec(chan, msg, len, count, skb);
23570a708f8fSGustavo F. Padovan 	if (unlikely(err < 0)) {
23580a708f8fSGustavo F. Padovan 		kfree_skb(skb);
23590a708f8fSGustavo F. Padovan 		return ERR_PTR(err);
23600a708f8fSGustavo F. Padovan 	}
23610a708f8fSGustavo F. Padovan 	return skb;
23620a708f8fSGustavo F. Padovan }
23630a708f8fSGustavo F. Padovan 
2364ab0ff76dSLuiz Augusto von Dentz static struct sk_buff *l2cap_create_iframe_pdu(struct l2cap_chan *chan,
2365ab0ff76dSLuiz Augusto von Dentz 					       struct msghdr *msg, size_t len,
236694122bbeSMat Martineau 					       u16 sdulen)
23670a708f8fSGustavo F. Padovan {
23688c1d787bSGustavo F. Padovan 	struct l2cap_conn *conn = chan->conn;
23690a708f8fSGustavo F. Padovan 	struct sk_buff *skb;
2370e4ca6d98SAndrei Emeltchenko 	int err, count, hlen;
23710a708f8fSGustavo F. Padovan 	struct l2cap_hdr *lh;
23720a708f8fSGustavo F. Padovan 
2373b4400672SAndrei Emeltchenko 	BT_DBG("chan %p len %zu", chan, len);
23740a708f8fSGustavo F. Padovan 
23750a708f8fSGustavo F. Padovan 	if (!conn)
23760a708f8fSGustavo F. Padovan 		return ERR_PTR(-ENOTCONN);
23770a708f8fSGustavo F. Padovan 
2378ba7aa64fSGustavo Padovan 	hlen = __ertm_hdr_size(chan);
2379e4ca6d98SAndrei Emeltchenko 
23800a708f8fSGustavo F. Padovan 	if (sdulen)
238103a51213SAndrei Emeltchenko 		hlen += L2CAP_SDULEN_SIZE;
23820a708f8fSGustavo F. Padovan 
238347d1ec61SGustavo F. Padovan 	if (chan->fcs == L2CAP_FCS_CRC16)
238403a51213SAndrei Emeltchenko 		hlen += L2CAP_FCS_SIZE;
23850a708f8fSGustavo F. Padovan 
23860a708f8fSGustavo F. Padovan 	count = min_t(unsigned int, (conn->mtu - hlen), len);
23872f7719ceSAndrei Emeltchenko 
23882f7719ceSAndrei Emeltchenko 	skb = chan->ops->alloc_skb(chan, count + hlen,
238990338947SGustavo Padovan 				   msg->msg_flags & MSG_DONTWAIT);
239090338947SGustavo Padovan 	if (IS_ERR(skb))
239190338947SGustavo Padovan 		return skb;
23920a708f8fSGustavo F. Padovan 
23930a708f8fSGustavo F. Padovan 	/* Create L2CAP header */
23940a708f8fSGustavo F. Padovan 	lh = (struct l2cap_hdr *) skb_put(skb, L2CAP_HDR_SIZE);
2395fe4128e0SGustavo F. Padovan 	lh->cid = cpu_to_le16(chan->dcid);
23960a708f8fSGustavo F. Padovan 	lh->len = cpu_to_le16(len + (hlen - L2CAP_HDR_SIZE));
239788843ab0SAndrei Emeltchenko 
239818a48e76SMat Martineau 	/* Control header is populated later */
239918a48e76SMat Martineau 	if (test_bit(FLAG_EXT_CTRL, &chan->flags))
240018a48e76SMat Martineau 		put_unaligned_le32(0, skb_put(skb, L2CAP_EXT_CTRL_SIZE));
240118a48e76SMat Martineau 	else
240218a48e76SMat Martineau 		put_unaligned_le16(0, skb_put(skb, L2CAP_ENH_CTRL_SIZE));
240388843ab0SAndrei Emeltchenko 
24040a708f8fSGustavo F. Padovan 	if (sdulen)
240503a51213SAndrei Emeltchenko 		put_unaligned_le16(sdulen, skb_put(skb, L2CAP_SDULEN_SIZE));
24060a708f8fSGustavo F. Padovan 
24070952a57aSAndrei Emeltchenko 	err = l2cap_skbuff_fromiovec(chan, msg, len, count, skb);
24080a708f8fSGustavo F. Padovan 	if (unlikely(err < 0)) {
24090a708f8fSGustavo F. Padovan 		kfree_skb(skb);
24100a708f8fSGustavo F. Padovan 		return ERR_PTR(err);
24110a708f8fSGustavo F. Padovan 	}
24120a708f8fSGustavo F. Padovan 
241318a48e76SMat Martineau 	bt_cb(skb)->control.fcs = chan->fcs;
24143ce3514fSMat Martineau 	bt_cb(skb)->control.retries = 0;
24150a708f8fSGustavo F. Padovan 	return skb;
24160a708f8fSGustavo F. Padovan }
24170a708f8fSGustavo F. Padovan 
241894122bbeSMat Martineau static int l2cap_segment_sdu(struct l2cap_chan *chan,
241994122bbeSMat Martineau 			     struct sk_buff_head *seg_queue,
242094122bbeSMat Martineau 			     struct msghdr *msg, size_t len)
24210a708f8fSGustavo F. Padovan {
24220a708f8fSGustavo F. Padovan 	struct sk_buff *skb;
242394122bbeSMat Martineau 	u16 sdu_len;
242494122bbeSMat Martineau 	size_t pdu_len;
242594122bbeSMat Martineau 	u8 sar;
24260a708f8fSGustavo F. Padovan 
2427b4400672SAndrei Emeltchenko 	BT_DBG("chan %p, msg %p, len %zu", chan, msg, len);
24280a708f8fSGustavo F. Padovan 
242994122bbeSMat Martineau 	/* It is critical that ERTM PDUs fit in a single HCI fragment,
243094122bbeSMat Martineau 	 * so fragmented skbs are not used.  The HCI layer's handling
243194122bbeSMat Martineau 	 * of fragmented skbs is not compatible with ERTM's queueing.
243294122bbeSMat Martineau 	 */
243394122bbeSMat Martineau 
243494122bbeSMat Martineau 	/* PDU size is derived from the HCI MTU */
243594122bbeSMat Martineau 	pdu_len = chan->conn->mtu;
243694122bbeSMat Martineau 
2437a549574dSMat Martineau 	/* Constrain PDU size for BR/EDR connections */
2438a549574dSMat Martineau 	if (!chan->hs_hcon)
243994122bbeSMat Martineau 		pdu_len = min_t(size_t, pdu_len, L2CAP_BREDR_MAX_PAYLOAD);
244094122bbeSMat Martineau 
244194122bbeSMat Martineau 	/* Adjust for largest possible L2CAP overhead. */
244235d401dfSGustavo Padovan 	if (chan->fcs)
244335d401dfSGustavo Padovan 		pdu_len -= L2CAP_FCS_SIZE;
244435d401dfSGustavo Padovan 
2445ba7aa64fSGustavo Padovan 	pdu_len -= __ertm_hdr_size(chan);
244694122bbeSMat Martineau 
244794122bbeSMat Martineau 	/* Remote device may have requested smaller PDUs */
244894122bbeSMat Martineau 	pdu_len = min_t(size_t, pdu_len, chan->remote_mps);
244994122bbeSMat Martineau 
245094122bbeSMat Martineau 	if (len <= pdu_len) {
245194122bbeSMat Martineau 		sar = L2CAP_SAR_UNSEGMENTED;
245294122bbeSMat Martineau 		sdu_len = 0;
245394122bbeSMat Martineau 		pdu_len = len;
245494122bbeSMat Martineau 	} else {
245594122bbeSMat Martineau 		sar = L2CAP_SAR_START;
245694122bbeSMat Martineau 		sdu_len = len;
245794122bbeSMat Martineau 		pdu_len -= L2CAP_SDULEN_SIZE;
245894122bbeSMat Martineau 	}
24590a708f8fSGustavo F. Padovan 
24600a708f8fSGustavo F. Padovan 	while (len > 0) {
246194122bbeSMat Martineau 		skb = l2cap_create_iframe_pdu(chan, msg, pdu_len, sdu_len);
24620a708f8fSGustavo F. Padovan 
24630a708f8fSGustavo F. Padovan 		if (IS_ERR(skb)) {
246494122bbeSMat Martineau 			__skb_queue_purge(seg_queue);
24650a708f8fSGustavo F. Padovan 			return PTR_ERR(skb);
24660a708f8fSGustavo F. Padovan 		}
24670a708f8fSGustavo F. Padovan 
246894122bbeSMat Martineau 		bt_cb(skb)->control.sar = sar;
246994122bbeSMat Martineau 		__skb_queue_tail(seg_queue, skb);
24700a708f8fSGustavo F. Padovan 
247194122bbeSMat Martineau 		len -= pdu_len;
247294122bbeSMat Martineau 		if (sdu_len) {
247394122bbeSMat Martineau 			sdu_len = 0;
247494122bbeSMat Martineau 			pdu_len += L2CAP_SDULEN_SIZE;
247594122bbeSMat Martineau 		}
247694122bbeSMat Martineau 
247794122bbeSMat Martineau 		if (len <= pdu_len) {
247894122bbeSMat Martineau 			sar = L2CAP_SAR_END;
247994122bbeSMat Martineau 			pdu_len = len;
248094122bbeSMat Martineau 		} else {
248194122bbeSMat Martineau 			sar = L2CAP_SAR_CONTINUE;
248294122bbeSMat Martineau 		}
248394122bbeSMat Martineau 	}
248494122bbeSMat Martineau 
2485f0f62799SGustavo Padovan 	return 0;
24860a708f8fSGustavo F. Padovan }
24870a708f8fSGustavo F. Padovan 
24885e59b791SLuiz Augusto von Dentz int l2cap_chan_send(struct l2cap_chan *chan, struct msghdr *msg, size_t len,
24895e59b791SLuiz Augusto von Dentz 		    u32 priority)
24909a91a04aSGustavo F. Padovan {
24919a91a04aSGustavo F. Padovan 	struct sk_buff *skb;
24929a91a04aSGustavo F. Padovan 	int err;
249394122bbeSMat Martineau 	struct sk_buff_head seg_queue;
24949a91a04aSGustavo F. Padovan 
24959a91a04aSGustavo F. Padovan 	/* Connectionless channel */
2496715ec005SGustavo F. Padovan 	if (chan->chan_type == L2CAP_CHAN_CONN_LESS) {
24975e59b791SLuiz Augusto von Dentz 		skb = l2cap_create_connless_pdu(chan, msg, len, priority);
24989a91a04aSGustavo F. Padovan 		if (IS_ERR(skb))
24999a91a04aSGustavo F. Padovan 			return PTR_ERR(skb);
25009a91a04aSGustavo F. Padovan 
25019a91a04aSGustavo F. Padovan 		l2cap_do_send(chan, skb);
25029a91a04aSGustavo F. Padovan 		return len;
25039a91a04aSGustavo F. Padovan 	}
25049a91a04aSGustavo F. Padovan 
25059a91a04aSGustavo F. Padovan 	switch (chan->mode) {
25069a91a04aSGustavo F. Padovan 	case L2CAP_MODE_BASIC:
25079a91a04aSGustavo F. Padovan 		/* Check outgoing MTU */
25089a91a04aSGustavo F. Padovan 		if (len > chan->omtu)
25099a91a04aSGustavo F. Padovan 			return -EMSGSIZE;
25109a91a04aSGustavo F. Padovan 
25119a91a04aSGustavo F. Padovan 		/* Create a basic PDU */
25125e59b791SLuiz Augusto von Dentz 		skb = l2cap_create_basic_pdu(chan, msg, len, priority);
25139a91a04aSGustavo F. Padovan 		if (IS_ERR(skb))
25149a91a04aSGustavo F. Padovan 			return PTR_ERR(skb);
25159a91a04aSGustavo F. Padovan 
25169a91a04aSGustavo F. Padovan 		l2cap_do_send(chan, skb);
25179a91a04aSGustavo F. Padovan 		err = len;
25189a91a04aSGustavo F. Padovan 		break;
25199a91a04aSGustavo F. Padovan 
25209a91a04aSGustavo F. Padovan 	case L2CAP_MODE_ERTM:
25219a91a04aSGustavo F. Padovan 	case L2CAP_MODE_STREAMING:
252294122bbeSMat Martineau 		/* Check outgoing MTU */
252394122bbeSMat Martineau 		if (len > chan->omtu) {
252494122bbeSMat Martineau 			err = -EMSGSIZE;
25259a91a04aSGustavo F. Padovan 			break;
25269a91a04aSGustavo F. Padovan 		}
25279a91a04aSGustavo F. Padovan 
252894122bbeSMat Martineau 		__skb_queue_head_init(&seg_queue);
252994122bbeSMat Martineau 
253094122bbeSMat Martineau 		/* Do segmentation before calling in to the state machine,
253194122bbeSMat Martineau 		 * since it's possible to block while waiting for memory
253294122bbeSMat Martineau 		 * allocation.
253394122bbeSMat Martineau 		 */
253494122bbeSMat Martineau 		err = l2cap_segment_sdu(chan, &seg_queue, msg, len);
253594122bbeSMat Martineau 
253694122bbeSMat Martineau 		/* The channel could have been closed while segmenting,
253794122bbeSMat Martineau 		 * check that it is still connected.
253894122bbeSMat Martineau 		 */
253994122bbeSMat Martineau 		if (chan->state != BT_CONNECTED) {
254094122bbeSMat Martineau 			__skb_queue_purge(&seg_queue);
254194122bbeSMat Martineau 			err = -ENOTCONN;
25429a91a04aSGustavo F. Padovan 		}
25439a91a04aSGustavo F. Padovan 
254494122bbeSMat Martineau 		if (err)
254594122bbeSMat Martineau 			break;
254694122bbeSMat Martineau 
25473733937dSMat Martineau 		if (chan->mode == L2CAP_MODE_ERTM)
2548d660366dSGustavo Padovan 			l2cap_tx(chan, NULL, &seg_queue, L2CAP_EV_DATA_REQUEST);
25493733937dSMat Martineau 		else
2550d660366dSGustavo Padovan 			l2cap_streaming_send(chan, &seg_queue);
255194122bbeSMat Martineau 
25529a91a04aSGustavo F. Padovan 		err = len;
25539a91a04aSGustavo F. Padovan 
255494122bbeSMat Martineau 		/* If the skbs were not queued for sending, they'll still be in
255594122bbeSMat Martineau 		 * seg_queue and need to be purged.
255694122bbeSMat Martineau 		 */
255794122bbeSMat Martineau 		__skb_queue_purge(&seg_queue);
25589a91a04aSGustavo F. Padovan 		break;
25599a91a04aSGustavo F. Padovan 
25609a91a04aSGustavo F. Padovan 	default:
25619a91a04aSGustavo F. Padovan 		BT_DBG("bad state %1.1x", chan->mode);
25629a91a04aSGustavo F. Padovan 		err = -EBADFD;
25639a91a04aSGustavo F. Padovan 	}
25649a91a04aSGustavo F. Padovan 
25659a91a04aSGustavo F. Padovan 	return err;
25669a91a04aSGustavo F. Padovan }
25679a91a04aSGustavo F. Padovan 
2568d2a7ac5dSMat Martineau static void l2cap_send_srej(struct l2cap_chan *chan, u16 txseq)
2569d2a7ac5dSMat Martineau {
2570bed68bdeSMat Martineau 	struct l2cap_ctrl control;
2571bed68bdeSMat Martineau 	u16 seq;
2572bed68bdeSMat Martineau 
2573b4400672SAndrei Emeltchenko 	BT_DBG("chan %p, txseq %u", chan, txseq);
2574bed68bdeSMat Martineau 
2575bed68bdeSMat Martineau 	memset(&control, 0, sizeof(control));
2576bed68bdeSMat Martineau 	control.sframe = 1;
2577bed68bdeSMat Martineau 	control.super = L2CAP_SUPER_SREJ;
2578bed68bdeSMat Martineau 
2579bed68bdeSMat Martineau 	for (seq = chan->expected_tx_seq; seq != txseq;
2580bed68bdeSMat Martineau 	     seq = __next_seq(chan, seq)) {
2581bed68bdeSMat Martineau 		if (!l2cap_ertm_seq_in_queue(&chan->srej_q, seq)) {
2582bed68bdeSMat Martineau 			control.reqseq = seq;
2583bed68bdeSMat Martineau 			l2cap_send_sframe(chan, &control);
2584bed68bdeSMat Martineau 			l2cap_seq_list_append(&chan->srej_list, seq);
2585bed68bdeSMat Martineau 		}
2586bed68bdeSMat Martineau 	}
2587bed68bdeSMat Martineau 
2588bed68bdeSMat Martineau 	chan->expected_tx_seq = __next_seq(chan, txseq);
2589d2a7ac5dSMat Martineau }
2590d2a7ac5dSMat Martineau 
2591d2a7ac5dSMat Martineau static void l2cap_send_srej_tail(struct l2cap_chan *chan)
2592d2a7ac5dSMat Martineau {
2593bed68bdeSMat Martineau 	struct l2cap_ctrl control;
2594bed68bdeSMat Martineau 
2595bed68bdeSMat Martineau 	BT_DBG("chan %p", chan);
2596bed68bdeSMat Martineau 
2597bed68bdeSMat Martineau 	if (chan->srej_list.tail == L2CAP_SEQ_LIST_CLEAR)
2598bed68bdeSMat Martineau 		return;
2599bed68bdeSMat Martineau 
2600bed68bdeSMat Martineau 	memset(&control, 0, sizeof(control));
2601bed68bdeSMat Martineau 	control.sframe = 1;
2602bed68bdeSMat Martineau 	control.super = L2CAP_SUPER_SREJ;
2603bed68bdeSMat Martineau 	control.reqseq = chan->srej_list.tail;
2604bed68bdeSMat Martineau 	l2cap_send_sframe(chan, &control);
2605d2a7ac5dSMat Martineau }
2606d2a7ac5dSMat Martineau 
2607d2a7ac5dSMat Martineau static void l2cap_send_srej_list(struct l2cap_chan *chan, u16 txseq)
2608d2a7ac5dSMat Martineau {
2609bed68bdeSMat Martineau 	struct l2cap_ctrl control;
2610bed68bdeSMat Martineau 	u16 initial_head;
2611bed68bdeSMat Martineau 	u16 seq;
2612bed68bdeSMat Martineau 
2613b4400672SAndrei Emeltchenko 	BT_DBG("chan %p, txseq %u", chan, txseq);
2614bed68bdeSMat Martineau 
2615bed68bdeSMat Martineau 	memset(&control, 0, sizeof(control));
2616bed68bdeSMat Martineau 	control.sframe = 1;
2617bed68bdeSMat Martineau 	control.super = L2CAP_SUPER_SREJ;
2618bed68bdeSMat Martineau 
2619bed68bdeSMat Martineau 	/* Capture initial list head to allow only one pass through the list. */
2620bed68bdeSMat Martineau 	initial_head = chan->srej_list.head;
2621bed68bdeSMat Martineau 
2622bed68bdeSMat Martineau 	do {
2623bed68bdeSMat Martineau 		seq = l2cap_seq_list_pop(&chan->srej_list);
2624bed68bdeSMat Martineau 		if (seq == txseq || seq == L2CAP_SEQ_LIST_CLEAR)
2625bed68bdeSMat Martineau 			break;
2626bed68bdeSMat Martineau 
2627bed68bdeSMat Martineau 		control.reqseq = seq;
2628bed68bdeSMat Martineau 		l2cap_send_sframe(chan, &control);
2629bed68bdeSMat Martineau 		l2cap_seq_list_append(&chan->srej_list, seq);
2630bed68bdeSMat Martineau 	} while (chan->srej_list.head != initial_head);
2631d2a7ac5dSMat Martineau }
2632d2a7ac5dSMat Martineau 
2633608bcc6dSMat Martineau static void l2cap_process_reqseq(struct l2cap_chan *chan, u16 reqseq)
2634608bcc6dSMat Martineau {
2635608bcc6dSMat Martineau 	struct sk_buff *acked_skb;
2636608bcc6dSMat Martineau 	u16 ackseq;
2637608bcc6dSMat Martineau 
2638b4400672SAndrei Emeltchenko 	BT_DBG("chan %p, reqseq %u", chan, reqseq);
2639608bcc6dSMat Martineau 
2640608bcc6dSMat Martineau 	if (chan->unacked_frames == 0 || reqseq == chan->expected_ack_seq)
2641608bcc6dSMat Martineau 		return;
2642608bcc6dSMat Martineau 
2643b4400672SAndrei Emeltchenko 	BT_DBG("expected_ack_seq %u, unacked_frames %u",
2644608bcc6dSMat Martineau 	       chan->expected_ack_seq, chan->unacked_frames);
2645608bcc6dSMat Martineau 
2646608bcc6dSMat Martineau 	for (ackseq = chan->expected_ack_seq; ackseq != reqseq;
2647608bcc6dSMat Martineau 	     ackseq = __next_seq(chan, ackseq)) {
2648608bcc6dSMat Martineau 
2649608bcc6dSMat Martineau 		acked_skb = l2cap_ertm_seq_in_queue(&chan->tx_q, ackseq);
2650608bcc6dSMat Martineau 		if (acked_skb) {
2651608bcc6dSMat Martineau 			skb_unlink(acked_skb, &chan->tx_q);
2652608bcc6dSMat Martineau 			kfree_skb(acked_skb);
2653608bcc6dSMat Martineau 			chan->unacked_frames--;
2654608bcc6dSMat Martineau 		}
2655608bcc6dSMat Martineau 	}
2656608bcc6dSMat Martineau 
2657608bcc6dSMat Martineau 	chan->expected_ack_seq = reqseq;
2658608bcc6dSMat Martineau 
2659608bcc6dSMat Martineau 	if (chan->unacked_frames == 0)
2660608bcc6dSMat Martineau 		__clear_retrans_timer(chan);
2661608bcc6dSMat Martineau 
2662b4400672SAndrei Emeltchenko 	BT_DBG("unacked_frames %u", chan->unacked_frames);
2663608bcc6dSMat Martineau }
2664608bcc6dSMat Martineau 
2665608bcc6dSMat Martineau static void l2cap_abort_rx_srej_sent(struct l2cap_chan *chan)
2666608bcc6dSMat Martineau {
2667608bcc6dSMat Martineau 	BT_DBG("chan %p", chan);
2668608bcc6dSMat Martineau 
2669608bcc6dSMat Martineau 	chan->expected_tx_seq = chan->buffer_seq;
2670608bcc6dSMat Martineau 	l2cap_seq_list_clear(&chan->srej_list);
2671608bcc6dSMat Martineau 	skb_queue_purge(&chan->srej_q);
2672608bcc6dSMat Martineau 	chan->rx_state = L2CAP_RX_STATE_RECV;
2673608bcc6dSMat Martineau }
2674608bcc6dSMat Martineau 
2675d660366dSGustavo Padovan static void l2cap_tx_state_xmit(struct l2cap_chan *chan,
2676608bcc6dSMat Martineau 				struct l2cap_ctrl *control,
2677608bcc6dSMat Martineau 				struct sk_buff_head *skbs, u8 event)
2678608bcc6dSMat Martineau {
2679608bcc6dSMat Martineau 	BT_DBG("chan %p, control %p, skbs %p, event %d", chan, control, skbs,
2680608bcc6dSMat Martineau 	       event);
2681608bcc6dSMat Martineau 
2682608bcc6dSMat Martineau 	switch (event) {
2683608bcc6dSMat Martineau 	case L2CAP_EV_DATA_REQUEST:
2684608bcc6dSMat Martineau 		if (chan->tx_send_head == NULL)
2685608bcc6dSMat Martineau 			chan->tx_send_head = skb_peek(skbs);
2686608bcc6dSMat Martineau 
2687608bcc6dSMat Martineau 		skb_queue_splice_tail_init(skbs, &chan->tx_q);
2688608bcc6dSMat Martineau 		l2cap_ertm_send(chan);
2689608bcc6dSMat Martineau 		break;
2690608bcc6dSMat Martineau 	case L2CAP_EV_LOCAL_BUSY_DETECTED:
2691608bcc6dSMat Martineau 		BT_DBG("Enter LOCAL_BUSY");
2692608bcc6dSMat Martineau 		set_bit(CONN_LOCAL_BUSY, &chan->conn_state);
2693608bcc6dSMat Martineau 
2694608bcc6dSMat Martineau 		if (chan->rx_state == L2CAP_RX_STATE_SREJ_SENT) {
2695608bcc6dSMat Martineau 			/* The SREJ_SENT state must be aborted if we are to
2696608bcc6dSMat Martineau 			 * enter the LOCAL_BUSY state.
2697608bcc6dSMat Martineau 			 */
2698608bcc6dSMat Martineau 			l2cap_abort_rx_srej_sent(chan);
2699608bcc6dSMat Martineau 		}
2700608bcc6dSMat Martineau 
2701608bcc6dSMat Martineau 		l2cap_send_ack(chan);
2702608bcc6dSMat Martineau 
2703608bcc6dSMat Martineau 		break;
2704608bcc6dSMat Martineau 	case L2CAP_EV_LOCAL_BUSY_CLEAR:
2705608bcc6dSMat Martineau 		BT_DBG("Exit LOCAL_BUSY");
2706608bcc6dSMat Martineau 		clear_bit(CONN_LOCAL_BUSY, &chan->conn_state);
2707608bcc6dSMat Martineau 
2708608bcc6dSMat Martineau 		if (test_bit(CONN_RNR_SENT, &chan->conn_state)) {
2709608bcc6dSMat Martineau 			struct l2cap_ctrl local_control;
2710608bcc6dSMat Martineau 
2711608bcc6dSMat Martineau 			memset(&local_control, 0, sizeof(local_control));
2712608bcc6dSMat Martineau 			local_control.sframe = 1;
2713608bcc6dSMat Martineau 			local_control.super = L2CAP_SUPER_RR;
2714608bcc6dSMat Martineau 			local_control.poll = 1;
2715608bcc6dSMat Martineau 			local_control.reqseq = chan->buffer_seq;
2716a67d7f6fSMat Martineau 			l2cap_send_sframe(chan, &local_control);
2717608bcc6dSMat Martineau 
2718608bcc6dSMat Martineau 			chan->retry_count = 1;
2719608bcc6dSMat Martineau 			__set_monitor_timer(chan);
2720608bcc6dSMat Martineau 			chan->tx_state = L2CAP_TX_STATE_WAIT_F;
2721608bcc6dSMat Martineau 		}
2722608bcc6dSMat Martineau 		break;
2723608bcc6dSMat Martineau 	case L2CAP_EV_RECV_REQSEQ_AND_FBIT:
2724608bcc6dSMat Martineau 		l2cap_process_reqseq(chan, control->reqseq);
2725608bcc6dSMat Martineau 		break;
2726608bcc6dSMat Martineau 	case L2CAP_EV_EXPLICIT_POLL:
2727608bcc6dSMat Martineau 		l2cap_send_rr_or_rnr(chan, 1);
2728608bcc6dSMat Martineau 		chan->retry_count = 1;
2729608bcc6dSMat Martineau 		__set_monitor_timer(chan);
2730608bcc6dSMat Martineau 		__clear_ack_timer(chan);
2731608bcc6dSMat Martineau 		chan->tx_state = L2CAP_TX_STATE_WAIT_F;
2732608bcc6dSMat Martineau 		break;
2733608bcc6dSMat Martineau 	case L2CAP_EV_RETRANS_TO:
2734608bcc6dSMat Martineau 		l2cap_send_rr_or_rnr(chan, 1);
2735608bcc6dSMat Martineau 		chan->retry_count = 1;
2736608bcc6dSMat Martineau 		__set_monitor_timer(chan);
2737608bcc6dSMat Martineau 		chan->tx_state = L2CAP_TX_STATE_WAIT_F;
2738608bcc6dSMat Martineau 		break;
2739608bcc6dSMat Martineau 	case L2CAP_EV_RECV_FBIT:
2740608bcc6dSMat Martineau 		/* Nothing to process */
2741608bcc6dSMat Martineau 		break;
2742608bcc6dSMat Martineau 	default:
2743608bcc6dSMat Martineau 		break;
2744608bcc6dSMat Martineau 	}
2745608bcc6dSMat Martineau }
2746608bcc6dSMat Martineau 
2747d660366dSGustavo Padovan static void l2cap_tx_state_wait_f(struct l2cap_chan *chan,
2748608bcc6dSMat Martineau 				  struct l2cap_ctrl *control,
2749608bcc6dSMat Martineau 				  struct sk_buff_head *skbs, u8 event)
2750608bcc6dSMat Martineau {
2751608bcc6dSMat Martineau 	BT_DBG("chan %p, control %p, skbs %p, event %d", chan, control, skbs,
2752608bcc6dSMat Martineau 	       event);
2753608bcc6dSMat Martineau 
2754608bcc6dSMat Martineau 	switch (event) {
2755608bcc6dSMat Martineau 	case L2CAP_EV_DATA_REQUEST:
2756608bcc6dSMat Martineau 		if (chan->tx_send_head == NULL)
2757608bcc6dSMat Martineau 			chan->tx_send_head = skb_peek(skbs);
2758608bcc6dSMat Martineau 		/* Queue data, but don't send. */
2759608bcc6dSMat Martineau 		skb_queue_splice_tail_init(skbs, &chan->tx_q);
2760608bcc6dSMat Martineau 		break;
2761608bcc6dSMat Martineau 	case L2CAP_EV_LOCAL_BUSY_DETECTED:
2762608bcc6dSMat Martineau 		BT_DBG("Enter LOCAL_BUSY");
2763608bcc6dSMat Martineau 		set_bit(CONN_LOCAL_BUSY, &chan->conn_state);
2764608bcc6dSMat Martineau 
2765608bcc6dSMat Martineau 		if (chan->rx_state == L2CAP_RX_STATE_SREJ_SENT) {
2766608bcc6dSMat Martineau 			/* The SREJ_SENT state must be aborted if we are to
2767608bcc6dSMat Martineau 			 * enter the LOCAL_BUSY state.
2768608bcc6dSMat Martineau 			 */
2769608bcc6dSMat Martineau 			l2cap_abort_rx_srej_sent(chan);
2770608bcc6dSMat Martineau 		}
2771608bcc6dSMat Martineau 
2772608bcc6dSMat Martineau 		l2cap_send_ack(chan);
2773608bcc6dSMat Martineau 
2774608bcc6dSMat Martineau 		break;
2775608bcc6dSMat Martineau 	case L2CAP_EV_LOCAL_BUSY_CLEAR:
2776608bcc6dSMat Martineau 		BT_DBG("Exit LOCAL_BUSY");
2777608bcc6dSMat Martineau 		clear_bit(CONN_LOCAL_BUSY, &chan->conn_state);
2778608bcc6dSMat Martineau 
2779608bcc6dSMat Martineau 		if (test_bit(CONN_RNR_SENT, &chan->conn_state)) {
2780608bcc6dSMat Martineau 			struct l2cap_ctrl local_control;
2781608bcc6dSMat Martineau 			memset(&local_control, 0, sizeof(local_control));
2782608bcc6dSMat Martineau 			local_control.sframe = 1;
2783608bcc6dSMat Martineau 			local_control.super = L2CAP_SUPER_RR;
2784608bcc6dSMat Martineau 			local_control.poll = 1;
2785608bcc6dSMat Martineau 			local_control.reqseq = chan->buffer_seq;
2786a67d7f6fSMat Martineau 			l2cap_send_sframe(chan, &local_control);
2787608bcc6dSMat Martineau 
2788608bcc6dSMat Martineau 			chan->retry_count = 1;
2789608bcc6dSMat Martineau 			__set_monitor_timer(chan);
2790608bcc6dSMat Martineau 			chan->tx_state = L2CAP_TX_STATE_WAIT_F;
2791608bcc6dSMat Martineau 		}
2792608bcc6dSMat Martineau 		break;
2793608bcc6dSMat Martineau 	case L2CAP_EV_RECV_REQSEQ_AND_FBIT:
2794608bcc6dSMat Martineau 		l2cap_process_reqseq(chan, control->reqseq);
2795608bcc6dSMat Martineau 
2796608bcc6dSMat Martineau 		/* Fall through */
2797608bcc6dSMat Martineau 
2798608bcc6dSMat Martineau 	case L2CAP_EV_RECV_FBIT:
2799608bcc6dSMat Martineau 		if (control && control->final) {
2800608bcc6dSMat Martineau 			__clear_monitor_timer(chan);
2801608bcc6dSMat Martineau 			if (chan->unacked_frames > 0)
2802608bcc6dSMat Martineau 				__set_retrans_timer(chan);
2803608bcc6dSMat Martineau 			chan->retry_count = 0;
2804608bcc6dSMat Martineau 			chan->tx_state = L2CAP_TX_STATE_XMIT;
2805608bcc6dSMat Martineau 			BT_DBG("recv fbit tx_state 0x2.2%x", chan->tx_state);
2806608bcc6dSMat Martineau 		}
2807608bcc6dSMat Martineau 		break;
2808608bcc6dSMat Martineau 	case L2CAP_EV_EXPLICIT_POLL:
2809608bcc6dSMat Martineau 		/* Ignore */
2810608bcc6dSMat Martineau 		break;
2811608bcc6dSMat Martineau 	case L2CAP_EV_MONITOR_TO:
2812608bcc6dSMat Martineau 		if (chan->max_tx == 0 || chan->retry_count < chan->max_tx) {
2813608bcc6dSMat Martineau 			l2cap_send_rr_or_rnr(chan, 1);
2814608bcc6dSMat Martineau 			__set_monitor_timer(chan);
2815608bcc6dSMat Martineau 			chan->retry_count++;
2816608bcc6dSMat Martineau 		} else {
28175e4e3972SAndrei Emeltchenko 			l2cap_send_disconn_req(chan, ECONNABORTED);
2818608bcc6dSMat Martineau 		}
2819608bcc6dSMat Martineau 		break;
2820608bcc6dSMat Martineau 	default:
2821608bcc6dSMat Martineau 		break;
2822608bcc6dSMat Martineau 	}
2823608bcc6dSMat Martineau }
2824608bcc6dSMat Martineau 
2825d660366dSGustavo Padovan static void l2cap_tx(struct l2cap_chan *chan, struct l2cap_ctrl *control,
2826608bcc6dSMat Martineau 		     struct sk_buff_head *skbs, u8 event)
2827608bcc6dSMat Martineau {
2828608bcc6dSMat Martineau 	BT_DBG("chan %p, control %p, skbs %p, event %d, state %d",
2829608bcc6dSMat Martineau 	       chan, control, skbs, event, chan->tx_state);
2830608bcc6dSMat Martineau 
2831608bcc6dSMat Martineau 	switch (chan->tx_state) {
2832608bcc6dSMat Martineau 	case L2CAP_TX_STATE_XMIT:
2833d660366dSGustavo Padovan 		l2cap_tx_state_xmit(chan, control, skbs, event);
2834608bcc6dSMat Martineau 		break;
2835608bcc6dSMat Martineau 	case L2CAP_TX_STATE_WAIT_F:
2836d660366dSGustavo Padovan 		l2cap_tx_state_wait_f(chan, control, skbs, event);
2837608bcc6dSMat Martineau 		break;
2838608bcc6dSMat Martineau 	default:
2839608bcc6dSMat Martineau 		/* Ignore event */
2840608bcc6dSMat Martineau 		break;
2841608bcc6dSMat Martineau 	}
2842608bcc6dSMat Martineau }
2843608bcc6dSMat Martineau 
28444b51dae9SMat Martineau static void l2cap_pass_to_tx(struct l2cap_chan *chan,
28454b51dae9SMat Martineau 			     struct l2cap_ctrl *control)
28464b51dae9SMat Martineau {
28474b51dae9SMat Martineau 	BT_DBG("chan %p, control %p", chan, control);
2848401bb1f7SAndrei Emeltchenko 	l2cap_tx(chan, control, NULL, L2CAP_EV_RECV_REQSEQ_AND_FBIT);
28494b51dae9SMat Martineau }
28504b51dae9SMat Martineau 
2851f80842a8SMat Martineau static void l2cap_pass_to_tx_fbit(struct l2cap_chan *chan,
2852f80842a8SMat Martineau 				  struct l2cap_ctrl *control)
2853f80842a8SMat Martineau {
2854f80842a8SMat Martineau 	BT_DBG("chan %p, control %p", chan, control);
2855401bb1f7SAndrei Emeltchenko 	l2cap_tx(chan, control, NULL, L2CAP_EV_RECV_FBIT);
2856f80842a8SMat Martineau }
2857f80842a8SMat Martineau 
28580a708f8fSGustavo F. Padovan /* Copy frame to all raw sockets on that connection */
28590a708f8fSGustavo F. Padovan static void l2cap_raw_recv(struct l2cap_conn *conn, struct sk_buff *skb)
28600a708f8fSGustavo F. Padovan {
28610a708f8fSGustavo F. Padovan 	struct sk_buff *nskb;
286248454079SGustavo F. Padovan 	struct l2cap_chan *chan;
28630a708f8fSGustavo F. Padovan 
28640a708f8fSGustavo F. Padovan 	BT_DBG("conn %p", conn);
28650a708f8fSGustavo F. Padovan 
28663df91ea2SAndrei Emeltchenko 	mutex_lock(&conn->chan_lock);
28673d57dc68SGustavo F. Padovan 
28683df91ea2SAndrei Emeltchenko 	list_for_each_entry(chan, &conn->chan_l, list) {
286948454079SGustavo F. Padovan 		struct sock *sk = chan->sk;
2870715ec005SGustavo F. Padovan 		if (chan->chan_type != L2CAP_CHAN_RAW)
28710a708f8fSGustavo F. Padovan 			continue;
28720a708f8fSGustavo F. Padovan 
28730a708f8fSGustavo F. Padovan 		/* Don't send frame to the socket it came from */
28740a708f8fSGustavo F. Padovan 		if (skb->sk == sk)
28750a708f8fSGustavo F. Padovan 			continue;
28768bcde1f2SGustavo Padovan 		nskb = skb_clone(skb, GFP_KERNEL);
28770a708f8fSGustavo F. Padovan 		if (!nskb)
28780a708f8fSGustavo F. Padovan 			continue;
28790a708f8fSGustavo F. Padovan 
288080b98027SGustavo Padovan 		if (chan->ops->recv(chan, nskb))
28810a708f8fSGustavo F. Padovan 			kfree_skb(nskb);
28820a708f8fSGustavo F. Padovan 	}
28833d57dc68SGustavo F. Padovan 
28843df91ea2SAndrei Emeltchenko 	mutex_unlock(&conn->chan_lock);
28850a708f8fSGustavo F. Padovan }
28860a708f8fSGustavo F. Padovan 
28870a708f8fSGustavo F. Padovan /* ---- L2CAP signalling commands ---- */
2888b4400672SAndrei Emeltchenko static struct sk_buff *l2cap_build_cmd(struct l2cap_conn *conn, u8 code,
2889b4400672SAndrei Emeltchenko 				       u8 ident, u16 dlen, void *data)
28900a708f8fSGustavo F. Padovan {
28910a708f8fSGustavo F. Padovan 	struct sk_buff *skb, **frag;
28920a708f8fSGustavo F. Padovan 	struct l2cap_cmd_hdr *cmd;
28930a708f8fSGustavo F. Padovan 	struct l2cap_hdr *lh;
28940a708f8fSGustavo F. Padovan 	int len, count;
28950a708f8fSGustavo F. Padovan 
2896b4400672SAndrei Emeltchenko 	BT_DBG("conn %p, code 0x%2.2x, ident 0x%2.2x, len %u",
28970a708f8fSGustavo F. Padovan 	       conn, code, ident, dlen);
28980a708f8fSGustavo F. Padovan 
2899300b962eSAnderson Lizardo 	if (conn->mtu < L2CAP_HDR_SIZE + L2CAP_CMD_HDR_SIZE)
2900300b962eSAnderson Lizardo 		return NULL;
2901300b962eSAnderson Lizardo 
29020a708f8fSGustavo F. Padovan 	len = L2CAP_HDR_SIZE + L2CAP_CMD_HDR_SIZE + dlen;
29030a708f8fSGustavo F. Padovan 	count = min_t(unsigned int, conn->mtu, len);
29040a708f8fSGustavo F. Padovan 
29058bcde1f2SGustavo Padovan 	skb = bt_skb_alloc(count, GFP_KERNEL);
29060a708f8fSGustavo F. Padovan 	if (!skb)
29070a708f8fSGustavo F. Padovan 		return NULL;
29080a708f8fSGustavo F. Padovan 
29090a708f8fSGustavo F. Padovan 	lh = (struct l2cap_hdr *) skb_put(skb, L2CAP_HDR_SIZE);
29100a708f8fSGustavo F. Padovan 	lh->len = cpu_to_le16(L2CAP_CMD_HDR_SIZE + dlen);
29113300d9a9SClaudio Takahasi 
29123300d9a9SClaudio Takahasi 	if (conn->hcon->type == LE_LINK)
2913ac73498cSAndrei Emeltchenko 		lh->cid = __constant_cpu_to_le16(L2CAP_CID_LE_SIGNALING);
29143300d9a9SClaudio Takahasi 	else
2915ac73498cSAndrei Emeltchenko 		lh->cid = __constant_cpu_to_le16(L2CAP_CID_SIGNALING);
29160a708f8fSGustavo F. Padovan 
29170a708f8fSGustavo F. Padovan 	cmd = (struct l2cap_cmd_hdr *) skb_put(skb, L2CAP_CMD_HDR_SIZE);
29180a708f8fSGustavo F. Padovan 	cmd->code  = code;
29190a708f8fSGustavo F. Padovan 	cmd->ident = ident;
29200a708f8fSGustavo F. Padovan 	cmd->len   = cpu_to_le16(dlen);
29210a708f8fSGustavo F. Padovan 
29220a708f8fSGustavo F. Padovan 	if (dlen) {
29230a708f8fSGustavo F. Padovan 		count -= L2CAP_HDR_SIZE + L2CAP_CMD_HDR_SIZE;
29240a708f8fSGustavo F. Padovan 		memcpy(skb_put(skb, count), data, count);
29250a708f8fSGustavo F. Padovan 		data += count;
29260a708f8fSGustavo F. Padovan 	}
29270a708f8fSGustavo F. Padovan 
29280a708f8fSGustavo F. Padovan 	len -= skb->len;
29290a708f8fSGustavo F. Padovan 
29300a708f8fSGustavo F. Padovan 	/* Continuation fragments (no L2CAP header) */
29310a708f8fSGustavo F. Padovan 	frag = &skb_shinfo(skb)->frag_list;
29320a708f8fSGustavo F. Padovan 	while (len) {
29330a708f8fSGustavo F. Padovan 		count = min_t(unsigned int, conn->mtu, len);
29340a708f8fSGustavo F. Padovan 
29358bcde1f2SGustavo Padovan 		*frag = bt_skb_alloc(count, GFP_KERNEL);
29360a708f8fSGustavo F. Padovan 		if (!*frag)
29370a708f8fSGustavo F. Padovan 			goto fail;
29380a708f8fSGustavo F. Padovan 
29390a708f8fSGustavo F. Padovan 		memcpy(skb_put(*frag, count), data, count);
29400a708f8fSGustavo F. Padovan 
29410a708f8fSGustavo F. Padovan 		len  -= count;
29420a708f8fSGustavo F. Padovan 		data += count;
29430a708f8fSGustavo F. Padovan 
29440a708f8fSGustavo F. Padovan 		frag = &(*frag)->next;
29450a708f8fSGustavo F. Padovan 	}
29460a708f8fSGustavo F. Padovan 
29470a708f8fSGustavo F. Padovan 	return skb;
29480a708f8fSGustavo F. Padovan 
29490a708f8fSGustavo F. Padovan fail:
29500a708f8fSGustavo F. Padovan 	kfree_skb(skb);
29510a708f8fSGustavo F. Padovan 	return NULL;
29520a708f8fSGustavo F. Padovan }
29530a708f8fSGustavo F. Padovan 
29542d792818SGustavo Padovan static inline int l2cap_get_conf_opt(void **ptr, int *type, int *olen,
29552d792818SGustavo Padovan 				     unsigned long *val)
29560a708f8fSGustavo F. Padovan {
29570a708f8fSGustavo F. Padovan 	struct l2cap_conf_opt *opt = *ptr;
29580a708f8fSGustavo F. Padovan 	int len;
29590a708f8fSGustavo F. Padovan 
29600a708f8fSGustavo F. Padovan 	len = L2CAP_CONF_OPT_SIZE + opt->len;
29610a708f8fSGustavo F. Padovan 	*ptr += len;
29620a708f8fSGustavo F. Padovan 
29630a708f8fSGustavo F. Padovan 	*type = opt->type;
29640a708f8fSGustavo F. Padovan 	*olen = opt->len;
29650a708f8fSGustavo F. Padovan 
29660a708f8fSGustavo F. Padovan 	switch (opt->len) {
29670a708f8fSGustavo F. Padovan 	case 1:
29680a708f8fSGustavo F. Padovan 		*val = *((u8 *) opt->val);
29690a708f8fSGustavo F. Padovan 		break;
29700a708f8fSGustavo F. Padovan 
29710a708f8fSGustavo F. Padovan 	case 2:
29720a708f8fSGustavo F. Padovan 		*val = get_unaligned_le16(opt->val);
29730a708f8fSGustavo F. Padovan 		break;
29740a708f8fSGustavo F. Padovan 
29750a708f8fSGustavo F. Padovan 	case 4:
29760a708f8fSGustavo F. Padovan 		*val = get_unaligned_le32(opt->val);
29770a708f8fSGustavo F. Padovan 		break;
29780a708f8fSGustavo F. Padovan 
29790a708f8fSGustavo F. Padovan 	default:
29800a708f8fSGustavo F. Padovan 		*val = (unsigned long) opt->val;
29810a708f8fSGustavo F. Padovan 		break;
29820a708f8fSGustavo F. Padovan 	}
29830a708f8fSGustavo F. Padovan 
2984b4400672SAndrei Emeltchenko 	BT_DBG("type 0x%2.2x len %u val 0x%lx", *type, opt->len, *val);
29850a708f8fSGustavo F. Padovan 	return len;
29860a708f8fSGustavo F. Padovan }
29870a708f8fSGustavo F. Padovan 
29880a708f8fSGustavo F. Padovan static void l2cap_add_conf_opt(void **ptr, u8 type, u8 len, unsigned long val)
29890a708f8fSGustavo F. Padovan {
29900a708f8fSGustavo F. Padovan 	struct l2cap_conf_opt *opt = *ptr;
29910a708f8fSGustavo F. Padovan 
2992b4400672SAndrei Emeltchenko 	BT_DBG("type 0x%2.2x len %u val 0x%lx", type, len, val);
29930a708f8fSGustavo F. Padovan 
29940a708f8fSGustavo F. Padovan 	opt->type = type;
29950a708f8fSGustavo F. Padovan 	opt->len  = len;
29960a708f8fSGustavo F. Padovan 
29970a708f8fSGustavo F. Padovan 	switch (len) {
29980a708f8fSGustavo F. Padovan 	case 1:
29990a708f8fSGustavo F. Padovan 		*((u8 *) opt->val)  = val;
30000a708f8fSGustavo F. Padovan 		break;
30010a708f8fSGustavo F. Padovan 
30020a708f8fSGustavo F. Padovan 	case 2:
30030a708f8fSGustavo F. Padovan 		put_unaligned_le16(val, opt->val);
30040a708f8fSGustavo F. Padovan 		break;
30050a708f8fSGustavo F. Padovan 
30060a708f8fSGustavo F. Padovan 	case 4:
30070a708f8fSGustavo F. Padovan 		put_unaligned_le32(val, opt->val);
30080a708f8fSGustavo F. Padovan 		break;
30090a708f8fSGustavo F. Padovan 
30100a708f8fSGustavo F. Padovan 	default:
30110a708f8fSGustavo F. Padovan 		memcpy(opt->val, (void *) val, len);
30120a708f8fSGustavo F. Padovan 		break;
30130a708f8fSGustavo F. Padovan 	}
30140a708f8fSGustavo F. Padovan 
30150a708f8fSGustavo F. Padovan 	*ptr += L2CAP_CONF_OPT_SIZE + len;
30160a708f8fSGustavo F. Padovan }
30170a708f8fSGustavo F. Padovan 
3018f89cef09SAndrei Emeltchenko static void l2cap_add_opt_efs(void **ptr, struct l2cap_chan *chan)
3019f89cef09SAndrei Emeltchenko {
3020f89cef09SAndrei Emeltchenko 	struct l2cap_conf_efs efs;
3021f89cef09SAndrei Emeltchenko 
3022f89cef09SAndrei Emeltchenko 	switch (chan->mode) {
3023f89cef09SAndrei Emeltchenko 	case L2CAP_MODE_ERTM:
3024f89cef09SAndrei Emeltchenko 		efs.id		= chan->local_id;
3025f89cef09SAndrei Emeltchenko 		efs.stype	= chan->local_stype;
3026f89cef09SAndrei Emeltchenko 		efs.msdu	= cpu_to_le16(chan->local_msdu);
3027f89cef09SAndrei Emeltchenko 		efs.sdu_itime	= cpu_to_le32(chan->local_sdu_itime);
3028ac73498cSAndrei Emeltchenko 		efs.acc_lat	= __constant_cpu_to_le32(L2CAP_DEFAULT_ACC_LAT);
30298936fa6dSAndrei Emeltchenko 		efs.flush_to	= __constant_cpu_to_le32(L2CAP_EFS_DEFAULT_FLUSH_TO);
3030f89cef09SAndrei Emeltchenko 		break;
3031f89cef09SAndrei Emeltchenko 
3032f89cef09SAndrei Emeltchenko 	case L2CAP_MODE_STREAMING:
3033f89cef09SAndrei Emeltchenko 		efs.id		= 1;
3034f89cef09SAndrei Emeltchenko 		efs.stype	= L2CAP_SERV_BESTEFFORT;
3035f89cef09SAndrei Emeltchenko 		efs.msdu	= cpu_to_le16(chan->local_msdu);
3036f89cef09SAndrei Emeltchenko 		efs.sdu_itime	= cpu_to_le32(chan->local_sdu_itime);
3037f89cef09SAndrei Emeltchenko 		efs.acc_lat	= 0;
3038f89cef09SAndrei Emeltchenko 		efs.flush_to	= 0;
3039f89cef09SAndrei Emeltchenko 		break;
3040f89cef09SAndrei Emeltchenko 
3041f89cef09SAndrei Emeltchenko 	default:
3042f89cef09SAndrei Emeltchenko 		return;
3043f89cef09SAndrei Emeltchenko 	}
3044f89cef09SAndrei Emeltchenko 
3045f89cef09SAndrei Emeltchenko 	l2cap_add_conf_opt(ptr, L2CAP_CONF_EFS, sizeof(efs),
3046f89cef09SAndrei Emeltchenko 			   (unsigned long) &efs);
3047f89cef09SAndrei Emeltchenko }
3048f89cef09SAndrei Emeltchenko 
3049721c4181SGustavo F. Padovan static void l2cap_ack_timeout(struct work_struct *work)
30500a708f8fSGustavo F. Padovan {
3051721c4181SGustavo F. Padovan 	struct l2cap_chan *chan = container_of(work, struct l2cap_chan,
3052721c4181SGustavo F. Padovan 					       ack_timer.work);
30530362520bSMat Martineau 	u16 frames_to_ack;
30540a708f8fSGustavo F. Padovan 
30552fb9b3d4SGustavo F. Padovan 	BT_DBG("chan %p", chan);
30562fb9b3d4SGustavo F. Padovan 
30576be36555SAndrei Emeltchenko 	l2cap_chan_lock(chan);
30586be36555SAndrei Emeltchenko 
30590362520bSMat Martineau 	frames_to_ack = __seq_offset(chan, chan->buffer_seq,
30600362520bSMat Martineau 				     chan->last_acked_seq);
30610362520bSMat Martineau 
30620362520bSMat Martineau 	if (frames_to_ack)
30630362520bSMat Martineau 		l2cap_send_rr_or_rnr(chan, 0);
30646be36555SAndrei Emeltchenko 
30656be36555SAndrei Emeltchenko 	l2cap_chan_unlock(chan);
306609bfb2eeSSzymon Janc 	l2cap_chan_put(chan);
30670a708f8fSGustavo F. Padovan }
30680a708f8fSGustavo F. Padovan 
3069466f8004SAndrei Emeltchenko int l2cap_ertm_init(struct l2cap_chan *chan)
30700a708f8fSGustavo F. Padovan {
30713c588192SMat Martineau 	int err;
30723c588192SMat Martineau 
3073105bdf9eSMat Martineau 	chan->next_tx_seq = 0;
3074105bdf9eSMat Martineau 	chan->expected_tx_seq = 0;
307542e5c802SGustavo F. Padovan 	chan->expected_ack_seq = 0;
30766a026610SGustavo F. Padovan 	chan->unacked_frames = 0;
307742e5c802SGustavo F. Padovan 	chan->buffer_seq = 0;
30786a026610SGustavo F. Padovan 	chan->frames_sent = 0;
3079105bdf9eSMat Martineau 	chan->last_acked_seq = 0;
3080105bdf9eSMat Martineau 	chan->sdu = NULL;
3081105bdf9eSMat Martineau 	chan->sdu_last_frag = NULL;
3082105bdf9eSMat Martineau 	chan->sdu_len = 0;
3083105bdf9eSMat Martineau 
3084d34c34fbSMat Martineau 	skb_queue_head_init(&chan->tx_q);
3085d34c34fbSMat Martineau 
30866ed971caSMarcel Holtmann 	chan->local_amp_id = AMP_ID_BREDR;
30876ed971caSMarcel Holtmann 	chan->move_id = AMP_ID_BREDR;
308808333283SMat Martineau 	chan->move_state = L2CAP_MOVE_STABLE;
308908333283SMat Martineau 	chan->move_role = L2CAP_MOVE_ROLE_NONE;
309008333283SMat Martineau 
3091105bdf9eSMat Martineau 	if (chan->mode != L2CAP_MODE_ERTM)
3092105bdf9eSMat Martineau 		return 0;
3093105bdf9eSMat Martineau 
3094105bdf9eSMat Martineau 	chan->rx_state = L2CAP_RX_STATE_RECV;
3095105bdf9eSMat Martineau 	chan->tx_state = L2CAP_TX_STATE_XMIT;
30960a708f8fSGustavo F. Padovan 
3097721c4181SGustavo F. Padovan 	INIT_DELAYED_WORK(&chan->retrans_timer, l2cap_retrans_timeout);
3098721c4181SGustavo F. Padovan 	INIT_DELAYED_WORK(&chan->monitor_timer, l2cap_monitor_timeout);
3099721c4181SGustavo F. Padovan 	INIT_DELAYED_WORK(&chan->ack_timer, l2cap_ack_timeout);
31000a708f8fSGustavo F. Padovan 
3101f1c6775bSGustavo F. Padovan 	skb_queue_head_init(&chan->srej_q);
31020a708f8fSGustavo F. Padovan 
31033c588192SMat Martineau 	err = l2cap_seq_list_init(&chan->srej_list, chan->tx_win);
31043c588192SMat Martineau 	if (err < 0)
31053c588192SMat Martineau 		return err;
31063c588192SMat Martineau 
31079dc9affcSMat Martineau 	err = l2cap_seq_list_init(&chan->retrans_list, chan->remote_tx_win);
31089dc9affcSMat Martineau 	if (err < 0)
31099dc9affcSMat Martineau 		l2cap_seq_list_free(&chan->srej_list);
31109dc9affcSMat Martineau 
31119dc9affcSMat Martineau 	return err;
31120a708f8fSGustavo F. Padovan }
31130a708f8fSGustavo F. Padovan 
31140a708f8fSGustavo F. Padovan static inline __u8 l2cap_select_mode(__u8 mode, __u16 remote_feat_mask)
31150a708f8fSGustavo F. Padovan {
31160a708f8fSGustavo F. Padovan 	switch (mode) {
31170a708f8fSGustavo F. Padovan 	case L2CAP_MODE_STREAMING:
31180a708f8fSGustavo F. Padovan 	case L2CAP_MODE_ERTM:
31190a708f8fSGustavo F. Padovan 		if (l2cap_mode_supported(mode, remote_feat_mask))
31200a708f8fSGustavo F. Padovan 			return mode;
31210a708f8fSGustavo F. Padovan 		/* fall through */
31220a708f8fSGustavo F. Padovan 	default:
31230a708f8fSGustavo F. Padovan 		return L2CAP_MODE_BASIC;
31240a708f8fSGustavo F. Padovan 	}
31250a708f8fSGustavo F. Padovan }
31260a708f8fSGustavo F. Padovan 
3127848566b3SMarcel Holtmann static inline bool __l2cap_ews_supported(struct l2cap_conn *conn)
31286327eb98SAndrei Emeltchenko {
3129848566b3SMarcel Holtmann 	return conn->hs_enabled && conn->feat_mask & L2CAP_FEAT_EXT_WINDOW;
31306327eb98SAndrei Emeltchenko }
31316327eb98SAndrei Emeltchenko 
3132848566b3SMarcel Holtmann static inline bool __l2cap_efs_supported(struct l2cap_conn *conn)
3133f89cef09SAndrei Emeltchenko {
3134848566b3SMarcel Holtmann 	return conn->hs_enabled && conn->feat_mask & L2CAP_FEAT_EXT_FLOW;
3135f89cef09SAndrei Emeltchenko }
3136f89cef09SAndrei Emeltchenko 
313736c86c85SMat Martineau static void __l2cap_set_ertm_timeouts(struct l2cap_chan *chan,
313836c86c85SMat Martineau 				      struct l2cap_conf_rfc *rfc)
313936c86c85SMat Martineau {
31406ed971caSMarcel Holtmann 	if (chan->local_amp_id != AMP_ID_BREDR && chan->hs_hcon) {
314136c86c85SMat Martineau 		u64 ertm_to = chan->hs_hcon->hdev->amp_be_flush_to;
314236c86c85SMat Martineau 
314336c86c85SMat Martineau 		/* Class 1 devices have must have ERTM timeouts
314436c86c85SMat Martineau 		 * exceeding the Link Supervision Timeout.  The
314536c86c85SMat Martineau 		 * default Link Supervision Timeout for AMP
314636c86c85SMat Martineau 		 * controllers is 10 seconds.
314736c86c85SMat Martineau 		 *
314836c86c85SMat Martineau 		 * Class 1 devices use 0xffffffff for their
314936c86c85SMat Martineau 		 * best-effort flush timeout, so the clamping logic
315036c86c85SMat Martineau 		 * will result in a timeout that meets the above
315136c86c85SMat Martineau 		 * requirement.  ERTM timeouts are 16-bit values, so
315236c86c85SMat Martineau 		 * the maximum timeout is 65.535 seconds.
315336c86c85SMat Martineau 		 */
315436c86c85SMat Martineau 
315536c86c85SMat Martineau 		/* Convert timeout to milliseconds and round */
315636c86c85SMat Martineau 		ertm_to = DIV_ROUND_UP_ULL(ertm_to, 1000);
315736c86c85SMat Martineau 
315836c86c85SMat Martineau 		/* This is the recommended formula for class 2 devices
315936c86c85SMat Martineau 		 * that start ERTM timers when packets are sent to the
316036c86c85SMat Martineau 		 * controller.
316136c86c85SMat Martineau 		 */
316236c86c85SMat Martineau 		ertm_to = 3 * ertm_to + 500;
316336c86c85SMat Martineau 
316436c86c85SMat Martineau 		if (ertm_to > 0xffff)
316536c86c85SMat Martineau 			ertm_to = 0xffff;
316636c86c85SMat Martineau 
316736c86c85SMat Martineau 		rfc->retrans_timeout = cpu_to_le16((u16) ertm_to);
316836c86c85SMat Martineau 		rfc->monitor_timeout = rfc->retrans_timeout;
316936c86c85SMat Martineau 	} else {
317036c86c85SMat Martineau 		rfc->retrans_timeout = __constant_cpu_to_le16(L2CAP_DEFAULT_RETRANS_TO);
317136c86c85SMat Martineau 		rfc->monitor_timeout = __constant_cpu_to_le16(L2CAP_DEFAULT_MONITOR_TO);
317236c86c85SMat Martineau 	}
317336c86c85SMat Martineau }
317436c86c85SMat Martineau 
31756327eb98SAndrei Emeltchenko static inline void l2cap_txwin_setup(struct l2cap_chan *chan)
31766327eb98SAndrei Emeltchenko {
31776327eb98SAndrei Emeltchenko 	if (chan->tx_win > L2CAP_DEFAULT_TX_WINDOW &&
3178848566b3SMarcel Holtmann 	    __l2cap_ews_supported(chan->conn)) {
31796327eb98SAndrei Emeltchenko 		/* use extended control field */
31806327eb98SAndrei Emeltchenko 		set_bit(FLAG_EXT_CTRL, &chan->flags);
3181836be934SAndrei Emeltchenko 		chan->tx_win_max = L2CAP_DEFAULT_EXT_WINDOW;
3182836be934SAndrei Emeltchenko 	} else {
31836327eb98SAndrei Emeltchenko 		chan->tx_win = min_t(u16, chan->tx_win,
31846327eb98SAndrei Emeltchenko 				     L2CAP_DEFAULT_TX_WINDOW);
3185836be934SAndrei Emeltchenko 		chan->tx_win_max = L2CAP_DEFAULT_TX_WINDOW;
3186836be934SAndrei Emeltchenko 	}
3187c20f8e35SMat Martineau 	chan->ack_win = chan->tx_win;
31886327eb98SAndrei Emeltchenko }
31896327eb98SAndrei Emeltchenko 
3190710f9b0aSGustavo F. Padovan static int l2cap_build_conf_req(struct l2cap_chan *chan, void *data)
31910a708f8fSGustavo F. Padovan {
31920a708f8fSGustavo F. Padovan 	struct l2cap_conf_req *req = data;
31930c1bc5c6SGustavo F. Padovan 	struct l2cap_conf_rfc rfc = { .mode = chan->mode };
31940a708f8fSGustavo F. Padovan 	void *ptr = req->data;
3195c8f79162SAndrei Emeltchenko 	u16 size;
31960a708f8fSGustavo F. Padovan 
319749208c9cSGustavo F. Padovan 	BT_DBG("chan %p", chan);
31980a708f8fSGustavo F. Padovan 
319973ffa904SGustavo F. Padovan 	if (chan->num_conf_req || chan->num_conf_rsp)
32000a708f8fSGustavo F. Padovan 		goto done;
32010a708f8fSGustavo F. Padovan 
32020c1bc5c6SGustavo F. Padovan 	switch (chan->mode) {
32030a708f8fSGustavo F. Padovan 	case L2CAP_MODE_STREAMING:
32040a708f8fSGustavo F. Padovan 	case L2CAP_MODE_ERTM:
3205c1360a1cSGustavo F. Padovan 		if (test_bit(CONF_STATE2_DEVICE, &chan->conf_state))
32060a708f8fSGustavo F. Padovan 			break;
32070a708f8fSGustavo F. Padovan 
3208848566b3SMarcel Holtmann 		if (__l2cap_efs_supported(chan->conn))
3209f89cef09SAndrei Emeltchenko 			set_bit(FLAG_EFS_ENABLE, &chan->flags);
3210f89cef09SAndrei Emeltchenko 
32110a708f8fSGustavo F. Padovan 		/* fall through */
32120a708f8fSGustavo F. Padovan 	default:
32138c1d787bSGustavo F. Padovan 		chan->mode = l2cap_select_mode(rfc.mode, chan->conn->feat_mask);
32140a708f8fSGustavo F. Padovan 		break;
32150a708f8fSGustavo F. Padovan 	}
32160a708f8fSGustavo F. Padovan 
32170a708f8fSGustavo F. Padovan done:
32180c1bc5c6SGustavo F. Padovan 	if (chan->imtu != L2CAP_DEFAULT_MTU)
32190c1bc5c6SGustavo F. Padovan 		l2cap_add_conf_opt(&ptr, L2CAP_CONF_MTU, 2, chan->imtu);
32200a708f8fSGustavo F. Padovan 
32210c1bc5c6SGustavo F. Padovan 	switch (chan->mode) {
32220a708f8fSGustavo F. Padovan 	case L2CAP_MODE_BASIC:
32238c1d787bSGustavo F. Padovan 		if (!(chan->conn->feat_mask & L2CAP_FEAT_ERTM) &&
32248c1d787bSGustavo F. Padovan 		    !(chan->conn->feat_mask & L2CAP_FEAT_STREAMING))
32250a708f8fSGustavo F. Padovan 			break;
32260a708f8fSGustavo F. Padovan 
32270a708f8fSGustavo F. Padovan 		rfc.mode            = L2CAP_MODE_BASIC;
32280a708f8fSGustavo F. Padovan 		rfc.txwin_size      = 0;
32290a708f8fSGustavo F. Padovan 		rfc.max_transmit    = 0;
32300a708f8fSGustavo F. Padovan 		rfc.retrans_timeout = 0;
32310a708f8fSGustavo F. Padovan 		rfc.monitor_timeout = 0;
32320a708f8fSGustavo F. Padovan 		rfc.max_pdu_size    = 0;
32330a708f8fSGustavo F. Padovan 
32340a708f8fSGustavo F. Padovan 		l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC, sizeof(rfc),
32350a708f8fSGustavo F. Padovan 				   (unsigned long) &rfc);
32360a708f8fSGustavo F. Padovan 		break;
32370a708f8fSGustavo F. Padovan 
32380a708f8fSGustavo F. Padovan 	case L2CAP_MODE_ERTM:
32390a708f8fSGustavo F. Padovan 		rfc.mode            = L2CAP_MODE_ERTM;
324047d1ec61SGustavo F. Padovan 		rfc.max_transmit    = chan->max_tx;
324136c86c85SMat Martineau 
324236c86c85SMat Martineau 		__l2cap_set_ertm_timeouts(chan, &rfc);
3243c8f79162SAndrei Emeltchenko 
3244c8f79162SAndrei Emeltchenko 		size = min_t(u16, L2CAP_DEFAULT_MAX_PDU_SIZE, chan->conn->mtu -
32452d792818SGustavo Padovan 			     L2CAP_EXT_HDR_SIZE - L2CAP_SDULEN_SIZE -
3246c8f79162SAndrei Emeltchenko 			     L2CAP_FCS_SIZE);
3247c8f79162SAndrei Emeltchenko 		rfc.max_pdu_size = cpu_to_le16(size);
32480a708f8fSGustavo F. Padovan 
32496327eb98SAndrei Emeltchenko 		l2cap_txwin_setup(chan);
32506327eb98SAndrei Emeltchenko 
32516327eb98SAndrei Emeltchenko 		rfc.txwin_size = min_t(u16, chan->tx_win,
32526327eb98SAndrei Emeltchenko 				       L2CAP_DEFAULT_TX_WINDOW);
32530a708f8fSGustavo F. Padovan 
32540a708f8fSGustavo F. Padovan 		l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC, sizeof(rfc),
32550a708f8fSGustavo F. Padovan 				   (unsigned long) &rfc);
32560a708f8fSGustavo F. Padovan 
3257f89cef09SAndrei Emeltchenko 		if (test_bit(FLAG_EFS_ENABLE, &chan->flags))
3258f89cef09SAndrei Emeltchenko 			l2cap_add_opt_efs(&ptr, chan);
3259f89cef09SAndrei Emeltchenko 
32606327eb98SAndrei Emeltchenko 		if (test_bit(FLAG_EXT_CTRL, &chan->flags))
32616327eb98SAndrei Emeltchenko 			l2cap_add_conf_opt(&ptr, L2CAP_CONF_EWS, 2,
32626327eb98SAndrei Emeltchenko 					   chan->tx_win);
326360918918SAndrei Emeltchenko 
326460918918SAndrei Emeltchenko 		if (chan->conn->feat_mask & L2CAP_FEAT_FCS)
326560918918SAndrei Emeltchenko 			if (chan->fcs == L2CAP_FCS_NONE ||
3266f2592d3eSAndrei Emeltchenko 			    test_bit(CONF_RECV_NO_FCS, &chan->conf_state)) {
326760918918SAndrei Emeltchenko 				chan->fcs = L2CAP_FCS_NONE;
326860918918SAndrei Emeltchenko 				l2cap_add_conf_opt(&ptr, L2CAP_CONF_FCS, 1,
326960918918SAndrei Emeltchenko 						   chan->fcs);
327060918918SAndrei Emeltchenko 			}
32710a708f8fSGustavo F. Padovan 		break;
32720a708f8fSGustavo F. Padovan 
32730a708f8fSGustavo F. Padovan 	case L2CAP_MODE_STREAMING:
3274273759e2SMat Martineau 		l2cap_txwin_setup(chan);
32750a708f8fSGustavo F. Padovan 		rfc.mode            = L2CAP_MODE_STREAMING;
32760a708f8fSGustavo F. Padovan 		rfc.txwin_size      = 0;
32770a708f8fSGustavo F. Padovan 		rfc.max_transmit    = 0;
32780a708f8fSGustavo F. Padovan 		rfc.retrans_timeout = 0;
32790a708f8fSGustavo F. Padovan 		rfc.monitor_timeout = 0;
3280c8f79162SAndrei Emeltchenko 
3281c8f79162SAndrei Emeltchenko 		size = min_t(u16, L2CAP_DEFAULT_MAX_PDU_SIZE, chan->conn->mtu -
32822d792818SGustavo Padovan 			     L2CAP_EXT_HDR_SIZE - L2CAP_SDULEN_SIZE -
3283c8f79162SAndrei Emeltchenko 			     L2CAP_FCS_SIZE);
3284c8f79162SAndrei Emeltchenko 		rfc.max_pdu_size = cpu_to_le16(size);
32850a708f8fSGustavo F. Padovan 
32860a708f8fSGustavo F. Padovan 		l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC, sizeof(rfc),
32870a708f8fSGustavo F. Padovan 				   (unsigned long) &rfc);
32880a708f8fSGustavo F. Padovan 
3289f89cef09SAndrei Emeltchenko 		if (test_bit(FLAG_EFS_ENABLE, &chan->flags))
3290f89cef09SAndrei Emeltchenko 			l2cap_add_opt_efs(&ptr, chan);
3291f89cef09SAndrei Emeltchenko 
329260918918SAndrei Emeltchenko 		if (chan->conn->feat_mask & L2CAP_FEAT_FCS)
329347d1ec61SGustavo F. Padovan 			if (chan->fcs == L2CAP_FCS_NONE ||
3294f2592d3eSAndrei Emeltchenko 			    test_bit(CONF_RECV_NO_FCS, &chan->conf_state)) {
329547d1ec61SGustavo F. Padovan 				chan->fcs = L2CAP_FCS_NONE;
329660918918SAndrei Emeltchenko 				l2cap_add_conf_opt(&ptr, L2CAP_CONF_FCS, 1,
329760918918SAndrei Emeltchenko 						   chan->fcs);
32980a708f8fSGustavo F. Padovan 			}
32990a708f8fSGustavo F. Padovan 		break;
33000a708f8fSGustavo F. Padovan 	}
33010a708f8fSGustavo F. Padovan 
3302fe4128e0SGustavo F. Padovan 	req->dcid  = cpu_to_le16(chan->dcid);
330359e54bd1SAndrei Emeltchenko 	req->flags = __constant_cpu_to_le16(0);
33040a708f8fSGustavo F. Padovan 
33050a708f8fSGustavo F. Padovan 	return ptr - data;
33060a708f8fSGustavo F. Padovan }
33070a708f8fSGustavo F. Padovan 
330873ffa904SGustavo F. Padovan static int l2cap_parse_conf_req(struct l2cap_chan *chan, void *data)
33090a708f8fSGustavo F. Padovan {
33100a708f8fSGustavo F. Padovan 	struct l2cap_conf_rsp *rsp = data;
33110a708f8fSGustavo F. Padovan 	void *ptr = rsp->data;
331273ffa904SGustavo F. Padovan 	void *req = chan->conf_req;
331373ffa904SGustavo F. Padovan 	int len = chan->conf_len;
33140a708f8fSGustavo F. Padovan 	int type, hint, olen;
33150a708f8fSGustavo F. Padovan 	unsigned long val;
33160a708f8fSGustavo F. Padovan 	struct l2cap_conf_rfc rfc = { .mode = L2CAP_MODE_BASIC };
331742dceae2SAndrei Emeltchenko 	struct l2cap_conf_efs efs;
331842dceae2SAndrei Emeltchenko 	u8 remote_efs = 0;
33190a708f8fSGustavo F. Padovan 	u16 mtu = L2CAP_DEFAULT_MTU;
33200a708f8fSGustavo F. Padovan 	u16 result = L2CAP_CONF_SUCCESS;
3321c8f79162SAndrei Emeltchenko 	u16 size;
33220a708f8fSGustavo F. Padovan 
332373ffa904SGustavo F. Padovan 	BT_DBG("chan %p", chan);
33240a708f8fSGustavo F. Padovan 
33250a708f8fSGustavo F. Padovan 	while (len >= L2CAP_CONF_OPT_SIZE) {
33260a708f8fSGustavo F. Padovan 		len -= l2cap_get_conf_opt(&req, &type, &olen, &val);
33270a708f8fSGustavo F. Padovan 
33280a708f8fSGustavo F. Padovan 		hint  = type & L2CAP_CONF_HINT;
33290a708f8fSGustavo F. Padovan 		type &= L2CAP_CONF_MASK;
33300a708f8fSGustavo F. Padovan 
33310a708f8fSGustavo F. Padovan 		switch (type) {
33320a708f8fSGustavo F. Padovan 		case L2CAP_CONF_MTU:
33330a708f8fSGustavo F. Padovan 			mtu = val;
33340a708f8fSGustavo F. Padovan 			break;
33350a708f8fSGustavo F. Padovan 
33360a708f8fSGustavo F. Padovan 		case L2CAP_CONF_FLUSH_TO:
33370c1bc5c6SGustavo F. Padovan 			chan->flush_to = val;
33380a708f8fSGustavo F. Padovan 			break;
33390a708f8fSGustavo F. Padovan 
33400a708f8fSGustavo F. Padovan 		case L2CAP_CONF_QOS:
33410a708f8fSGustavo F. Padovan 			break;
33420a708f8fSGustavo F. Padovan 
33430a708f8fSGustavo F. Padovan 		case L2CAP_CONF_RFC:
33440a708f8fSGustavo F. Padovan 			if (olen == sizeof(rfc))
33450a708f8fSGustavo F. Padovan 				memcpy(&rfc, (void *) val, olen);
33460a708f8fSGustavo F. Padovan 			break;
33470a708f8fSGustavo F. Padovan 
33480a708f8fSGustavo F. Padovan 		case L2CAP_CONF_FCS:
33490a708f8fSGustavo F. Padovan 			if (val == L2CAP_FCS_NONE)
3350f2592d3eSAndrei Emeltchenko 				set_bit(CONF_RECV_NO_FCS, &chan->conf_state);
335142dceae2SAndrei Emeltchenko 			break;
33520a708f8fSGustavo F. Padovan 
335342dceae2SAndrei Emeltchenko 		case L2CAP_CONF_EFS:
335442dceae2SAndrei Emeltchenko 			remote_efs = 1;
335542dceae2SAndrei Emeltchenko 			if (olen == sizeof(efs))
335642dceae2SAndrei Emeltchenko 				memcpy(&efs, (void *) val, olen);
33570a708f8fSGustavo F. Padovan 			break;
33580a708f8fSGustavo F. Padovan 
33596327eb98SAndrei Emeltchenko 		case L2CAP_CONF_EWS:
3360848566b3SMarcel Holtmann 			if (!chan->conn->hs_enabled)
33616327eb98SAndrei Emeltchenko 				return -ECONNREFUSED;
33626327eb98SAndrei Emeltchenko 
33636327eb98SAndrei Emeltchenko 			set_bit(FLAG_EXT_CTRL, &chan->flags);
33646327eb98SAndrei Emeltchenko 			set_bit(CONF_EWS_RECV, &chan->conf_state);
3365836be934SAndrei Emeltchenko 			chan->tx_win_max = L2CAP_DEFAULT_EXT_WINDOW;
33666327eb98SAndrei Emeltchenko 			chan->remote_tx_win = val;
33670a708f8fSGustavo F. Padovan 			break;
33680a708f8fSGustavo F. Padovan 
33690a708f8fSGustavo F. Padovan 		default:
33700a708f8fSGustavo F. Padovan 			if (hint)
33710a708f8fSGustavo F. Padovan 				break;
33720a708f8fSGustavo F. Padovan 
33730a708f8fSGustavo F. Padovan 			result = L2CAP_CONF_UNKNOWN;
33740a708f8fSGustavo F. Padovan 			*((u8 *) ptr++) = type;
33750a708f8fSGustavo F. Padovan 			break;
33760a708f8fSGustavo F. Padovan 		}
33770a708f8fSGustavo F. Padovan 	}
33780a708f8fSGustavo F. Padovan 
337973ffa904SGustavo F. Padovan 	if (chan->num_conf_rsp || chan->num_conf_req > 1)
33800a708f8fSGustavo F. Padovan 		goto done;
33810a708f8fSGustavo F. Padovan 
33820c1bc5c6SGustavo F. Padovan 	switch (chan->mode) {
33830a708f8fSGustavo F. Padovan 	case L2CAP_MODE_STREAMING:
33840a708f8fSGustavo F. Padovan 	case L2CAP_MODE_ERTM:
3385c1360a1cSGustavo F. Padovan 		if (!test_bit(CONF_STATE2_DEVICE, &chan->conf_state)) {
33860c1bc5c6SGustavo F. Padovan 			chan->mode = l2cap_select_mode(rfc.mode,
33878c1d787bSGustavo F. Padovan 						       chan->conn->feat_mask);
33880a708f8fSGustavo F. Padovan 			break;
33890a708f8fSGustavo F. Padovan 		}
33900a708f8fSGustavo F. Padovan 
339142dceae2SAndrei Emeltchenko 		if (remote_efs) {
3392848566b3SMarcel Holtmann 			if (__l2cap_efs_supported(chan->conn))
339342dceae2SAndrei Emeltchenko 				set_bit(FLAG_EFS_ENABLE, &chan->flags);
339442dceae2SAndrei Emeltchenko 			else
339542dceae2SAndrei Emeltchenko 				return -ECONNREFUSED;
339642dceae2SAndrei Emeltchenko 		}
339742dceae2SAndrei Emeltchenko 
33980c1bc5c6SGustavo F. Padovan 		if (chan->mode != rfc.mode)
33990a708f8fSGustavo F. Padovan 			return -ECONNREFUSED;
34000a708f8fSGustavo F. Padovan 
34010a708f8fSGustavo F. Padovan 		break;
34020a708f8fSGustavo F. Padovan 	}
34030a708f8fSGustavo F. Padovan 
34040a708f8fSGustavo F. Padovan done:
34050c1bc5c6SGustavo F. Padovan 	if (chan->mode != rfc.mode) {
34060a708f8fSGustavo F. Padovan 		result = L2CAP_CONF_UNACCEPT;
34070c1bc5c6SGustavo F. Padovan 		rfc.mode = chan->mode;
34080a708f8fSGustavo F. Padovan 
340973ffa904SGustavo F. Padovan 		if (chan->num_conf_rsp == 1)
34100a708f8fSGustavo F. Padovan 			return -ECONNREFUSED;
34110a708f8fSGustavo F. Padovan 
34122d792818SGustavo Padovan 		l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC, sizeof(rfc),
34132d792818SGustavo Padovan 				   (unsigned long) &rfc);
34140a708f8fSGustavo F. Padovan 	}
34150a708f8fSGustavo F. Padovan 
34160a708f8fSGustavo F. Padovan 	if (result == L2CAP_CONF_SUCCESS) {
34170a708f8fSGustavo F. Padovan 		/* Configure output options and let the other side know
34180a708f8fSGustavo F. Padovan 		 * which ones we don't like. */
34190a708f8fSGustavo F. Padovan 
34200a708f8fSGustavo F. Padovan 		if (mtu < L2CAP_DEFAULT_MIN_MTU)
34210a708f8fSGustavo F. Padovan 			result = L2CAP_CONF_UNACCEPT;
34220a708f8fSGustavo F. Padovan 		else {
34230c1bc5c6SGustavo F. Padovan 			chan->omtu = mtu;
3424c1360a1cSGustavo F. Padovan 			set_bit(CONF_MTU_DONE, &chan->conf_state);
34250a708f8fSGustavo F. Padovan 		}
34260c1bc5c6SGustavo F. Padovan 		l2cap_add_conf_opt(&ptr, L2CAP_CONF_MTU, 2, chan->omtu);
34270a708f8fSGustavo F. Padovan 
342842dceae2SAndrei Emeltchenko 		if (remote_efs) {
342942dceae2SAndrei Emeltchenko 			if (chan->local_stype != L2CAP_SERV_NOTRAFIC &&
343042dceae2SAndrei Emeltchenko 			    efs.stype != L2CAP_SERV_NOTRAFIC &&
343142dceae2SAndrei Emeltchenko 			    efs.stype != chan->local_stype) {
343242dceae2SAndrei Emeltchenko 
343342dceae2SAndrei Emeltchenko 				result = L2CAP_CONF_UNACCEPT;
343442dceae2SAndrei Emeltchenko 
343542dceae2SAndrei Emeltchenko 				if (chan->num_conf_req >= 1)
343642dceae2SAndrei Emeltchenko 					return -ECONNREFUSED;
343742dceae2SAndrei Emeltchenko 
343842dceae2SAndrei Emeltchenko 				l2cap_add_conf_opt(&ptr, L2CAP_CONF_EFS,
343942dceae2SAndrei Emeltchenko 						   sizeof(efs),
344042dceae2SAndrei Emeltchenko 						   (unsigned long) &efs);
34410e8b207eSAndrei Emeltchenko 			} else {
34423e6b3b95SGustavo F. Padovan 				/* Send PENDING Conf Rsp */
34430e8b207eSAndrei Emeltchenko 				result = L2CAP_CONF_PENDING;
34440e8b207eSAndrei Emeltchenko 				set_bit(CONF_LOC_CONF_PEND, &chan->conf_state);
344542dceae2SAndrei Emeltchenko 			}
344642dceae2SAndrei Emeltchenko 		}
344742dceae2SAndrei Emeltchenko 
34480a708f8fSGustavo F. Padovan 		switch (rfc.mode) {
34490a708f8fSGustavo F. Padovan 		case L2CAP_MODE_BASIC:
345047d1ec61SGustavo F. Padovan 			chan->fcs = L2CAP_FCS_NONE;
3451c1360a1cSGustavo F. Padovan 			set_bit(CONF_MODE_DONE, &chan->conf_state);
34520a708f8fSGustavo F. Padovan 			break;
34530a708f8fSGustavo F. Padovan 
34540a708f8fSGustavo F. Padovan 		case L2CAP_MODE_ERTM:
34556327eb98SAndrei Emeltchenko 			if (!test_bit(CONF_EWS_RECV, &chan->conf_state))
34562c03a7a4SGustavo F. Padovan 				chan->remote_tx_win = rfc.txwin_size;
34576327eb98SAndrei Emeltchenko 			else
34586327eb98SAndrei Emeltchenko 				rfc.txwin_size = L2CAP_DEFAULT_TX_WINDOW;
34596327eb98SAndrei Emeltchenko 
34602c03a7a4SGustavo F. Padovan 			chan->remote_max_tx = rfc.max_transmit;
34610a708f8fSGustavo F. Padovan 
3462c8f79162SAndrei Emeltchenko 			size = min_t(u16, le16_to_cpu(rfc.max_pdu_size),
34632d792818SGustavo Padovan 				     chan->conn->mtu - L2CAP_EXT_HDR_SIZE -
34642d792818SGustavo Padovan 				     L2CAP_SDULEN_SIZE - L2CAP_FCS_SIZE);
3465c8f79162SAndrei Emeltchenko 			rfc.max_pdu_size = cpu_to_le16(size);
3466c8f79162SAndrei Emeltchenko 			chan->remote_mps = size;
34670a708f8fSGustavo F. Padovan 
346836c86c85SMat Martineau 			__l2cap_set_ertm_timeouts(chan, &rfc);
34690a708f8fSGustavo F. Padovan 
3470c1360a1cSGustavo F. Padovan 			set_bit(CONF_MODE_DONE, &chan->conf_state);
34710a708f8fSGustavo F. Padovan 
34720a708f8fSGustavo F. Padovan 			l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC,
34730a708f8fSGustavo F. Padovan 					   sizeof(rfc), (unsigned long) &rfc);
34740a708f8fSGustavo F. Padovan 
347542dceae2SAndrei Emeltchenko 			if (test_bit(FLAG_EFS_ENABLE, &chan->flags)) {
347642dceae2SAndrei Emeltchenko 				chan->remote_id = efs.id;
347742dceae2SAndrei Emeltchenko 				chan->remote_stype = efs.stype;
347842dceae2SAndrei Emeltchenko 				chan->remote_msdu = le16_to_cpu(efs.msdu);
347942dceae2SAndrei Emeltchenko 				chan->remote_flush_to =
348042dceae2SAndrei Emeltchenko 					le32_to_cpu(efs.flush_to);
348142dceae2SAndrei Emeltchenko 				chan->remote_acc_lat =
348242dceae2SAndrei Emeltchenko 					le32_to_cpu(efs.acc_lat);
348342dceae2SAndrei Emeltchenko 				chan->remote_sdu_itime =
348442dceae2SAndrei Emeltchenko 					le32_to_cpu(efs.sdu_itime);
348542dceae2SAndrei Emeltchenko 				l2cap_add_conf_opt(&ptr, L2CAP_CONF_EFS,
34862d792818SGustavo Padovan 						   sizeof(efs),
34872d792818SGustavo Padovan 						   (unsigned long) &efs);
348842dceae2SAndrei Emeltchenko 			}
34890a708f8fSGustavo F. Padovan 			break;
34900a708f8fSGustavo F. Padovan 
34910a708f8fSGustavo F. Padovan 		case L2CAP_MODE_STREAMING:
3492c8f79162SAndrei Emeltchenko 			size = min_t(u16, le16_to_cpu(rfc.max_pdu_size),
34932d792818SGustavo Padovan 				     chan->conn->mtu - L2CAP_EXT_HDR_SIZE -
34942d792818SGustavo Padovan 				     L2CAP_SDULEN_SIZE - L2CAP_FCS_SIZE);
3495c8f79162SAndrei Emeltchenko 			rfc.max_pdu_size = cpu_to_le16(size);
3496c8f79162SAndrei Emeltchenko 			chan->remote_mps = size;
34970a708f8fSGustavo F. Padovan 
3498c1360a1cSGustavo F. Padovan 			set_bit(CONF_MODE_DONE, &chan->conf_state);
34990a708f8fSGustavo F. Padovan 
35002d792818SGustavo Padovan 			l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC, sizeof(rfc),
35012d792818SGustavo Padovan 					   (unsigned long) &rfc);
35020a708f8fSGustavo F. Padovan 
35030a708f8fSGustavo F. Padovan 			break;
35040a708f8fSGustavo F. Padovan 
35050a708f8fSGustavo F. Padovan 		default:
35060a708f8fSGustavo F. Padovan 			result = L2CAP_CONF_UNACCEPT;
35070a708f8fSGustavo F. Padovan 
35080a708f8fSGustavo F. Padovan 			memset(&rfc, 0, sizeof(rfc));
35090c1bc5c6SGustavo F. Padovan 			rfc.mode = chan->mode;
35100a708f8fSGustavo F. Padovan 		}
35110a708f8fSGustavo F. Padovan 
35120a708f8fSGustavo F. Padovan 		if (result == L2CAP_CONF_SUCCESS)
3513c1360a1cSGustavo F. Padovan 			set_bit(CONF_OUTPUT_DONE, &chan->conf_state);
35140a708f8fSGustavo F. Padovan 	}
3515fe4128e0SGustavo F. Padovan 	rsp->scid   = cpu_to_le16(chan->dcid);
35160a708f8fSGustavo F. Padovan 	rsp->result = cpu_to_le16(result);
351759e54bd1SAndrei Emeltchenko 	rsp->flags  = __constant_cpu_to_le16(0);
35180a708f8fSGustavo F. Padovan 
35190a708f8fSGustavo F. Padovan 	return ptr - data;
35200a708f8fSGustavo F. Padovan }
35210a708f8fSGustavo F. Padovan 
35222d792818SGustavo Padovan static int l2cap_parse_conf_rsp(struct l2cap_chan *chan, void *rsp, int len,
35232d792818SGustavo Padovan 				void *data, u16 *result)
35240a708f8fSGustavo F. Padovan {
35250a708f8fSGustavo F. Padovan 	struct l2cap_conf_req *req = data;
35260a708f8fSGustavo F. Padovan 	void *ptr = req->data;
35270a708f8fSGustavo F. Padovan 	int type, olen;
35280a708f8fSGustavo F. Padovan 	unsigned long val;
352936e999a8SMat Martineau 	struct l2cap_conf_rfc rfc = { .mode = L2CAP_MODE_BASIC };
353066af7aafSAndrei Emeltchenko 	struct l2cap_conf_efs efs;
35310a708f8fSGustavo F. Padovan 
3532fe4128e0SGustavo F. Padovan 	BT_DBG("chan %p, rsp %p, len %d, req %p", chan, rsp, len, data);
35330a708f8fSGustavo F. Padovan 
35340a708f8fSGustavo F. Padovan 	while (len >= L2CAP_CONF_OPT_SIZE) {
35350a708f8fSGustavo F. Padovan 		len -= l2cap_get_conf_opt(&rsp, &type, &olen, &val);
35360a708f8fSGustavo F. Padovan 
35370a708f8fSGustavo F. Padovan 		switch (type) {
35380a708f8fSGustavo F. Padovan 		case L2CAP_CONF_MTU:
35390a708f8fSGustavo F. Padovan 			if (val < L2CAP_DEFAULT_MIN_MTU) {
35400a708f8fSGustavo F. Padovan 				*result = L2CAP_CONF_UNACCEPT;
35410c1bc5c6SGustavo F. Padovan 				chan->imtu = L2CAP_DEFAULT_MIN_MTU;
35420a708f8fSGustavo F. Padovan 			} else
35430c1bc5c6SGustavo F. Padovan 				chan->imtu = val;
35440c1bc5c6SGustavo F. Padovan 			l2cap_add_conf_opt(&ptr, L2CAP_CONF_MTU, 2, chan->imtu);
35450a708f8fSGustavo F. Padovan 			break;
35460a708f8fSGustavo F. Padovan 
35470a708f8fSGustavo F. Padovan 		case L2CAP_CONF_FLUSH_TO:
35480c1bc5c6SGustavo F. Padovan 			chan->flush_to = val;
35490a708f8fSGustavo F. Padovan 			l2cap_add_conf_opt(&ptr, L2CAP_CONF_FLUSH_TO,
35500c1bc5c6SGustavo F. Padovan 					   2, chan->flush_to);
35510a708f8fSGustavo F. Padovan 			break;
35520a708f8fSGustavo F. Padovan 
35530a708f8fSGustavo F. Padovan 		case L2CAP_CONF_RFC:
35540a708f8fSGustavo F. Padovan 			if (olen == sizeof(rfc))
35550a708f8fSGustavo F. Padovan 				memcpy(&rfc, (void *)val, olen);
35560a708f8fSGustavo F. Padovan 
3557c1360a1cSGustavo F. Padovan 			if (test_bit(CONF_STATE2_DEVICE, &chan->conf_state) &&
35580c1bc5c6SGustavo F. Padovan 			    rfc.mode != chan->mode)
35590a708f8fSGustavo F. Padovan 				return -ECONNREFUSED;
35600a708f8fSGustavo F. Padovan 
356147d1ec61SGustavo F. Padovan 			chan->fcs = 0;
35620a708f8fSGustavo F. Padovan 
35630a708f8fSGustavo F. Padovan 			l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC,
35640a708f8fSGustavo F. Padovan 					   sizeof(rfc), (unsigned long) &rfc);
35650a708f8fSGustavo F. Padovan 			break;
35666327eb98SAndrei Emeltchenko 
35676327eb98SAndrei Emeltchenko 		case L2CAP_CONF_EWS:
3568c20f8e35SMat Martineau 			chan->ack_win = min_t(u16, val, chan->ack_win);
35693e6b3b95SGustavo F. Padovan 			l2cap_add_conf_opt(&ptr, L2CAP_CONF_EWS, 2,
35703e6b3b95SGustavo F. Padovan 					   chan->tx_win);
35716327eb98SAndrei Emeltchenko 			break;
357266af7aafSAndrei Emeltchenko 
357366af7aafSAndrei Emeltchenko 		case L2CAP_CONF_EFS:
357466af7aafSAndrei Emeltchenko 			if (olen == sizeof(efs))
357566af7aafSAndrei Emeltchenko 				memcpy(&efs, (void *)val, olen);
357666af7aafSAndrei Emeltchenko 
357766af7aafSAndrei Emeltchenko 			if (chan->local_stype != L2CAP_SERV_NOTRAFIC &&
357866af7aafSAndrei Emeltchenko 			    efs.stype != L2CAP_SERV_NOTRAFIC &&
357966af7aafSAndrei Emeltchenko 			    efs.stype != chan->local_stype)
358066af7aafSAndrei Emeltchenko 				return -ECONNREFUSED;
358166af7aafSAndrei Emeltchenko 
35822d792818SGustavo Padovan 			l2cap_add_conf_opt(&ptr, L2CAP_CONF_EFS, sizeof(efs),
35832d792818SGustavo Padovan 					   (unsigned long) &efs);
358466af7aafSAndrei Emeltchenko 			break;
3585cbabee78SAndrei Emeltchenko 
3586cbabee78SAndrei Emeltchenko 		case L2CAP_CONF_FCS:
3587cbabee78SAndrei Emeltchenko 			if (*result == L2CAP_CONF_PENDING)
3588cbabee78SAndrei Emeltchenko 				if (val == L2CAP_FCS_NONE)
3589f2592d3eSAndrei Emeltchenko 					set_bit(CONF_RECV_NO_FCS,
3590cbabee78SAndrei Emeltchenko 						&chan->conf_state);
3591cbabee78SAndrei Emeltchenko 			break;
35920a708f8fSGustavo F. Padovan 		}
35930a708f8fSGustavo F. Padovan 	}
35940a708f8fSGustavo F. Padovan 
35950c1bc5c6SGustavo F. Padovan 	if (chan->mode == L2CAP_MODE_BASIC && chan->mode != rfc.mode)
35960a708f8fSGustavo F. Padovan 		return -ECONNREFUSED;
35970a708f8fSGustavo F. Padovan 
35980c1bc5c6SGustavo F. Padovan 	chan->mode = rfc.mode;
35990a708f8fSGustavo F. Padovan 
36000e8b207eSAndrei Emeltchenko 	if (*result == L2CAP_CONF_SUCCESS || *result == L2CAP_CONF_PENDING) {
36010a708f8fSGustavo F. Padovan 		switch (rfc.mode) {
36020a708f8fSGustavo F. Padovan 		case L2CAP_MODE_ERTM:
360347d1ec61SGustavo F. Padovan 			chan->retrans_timeout = le16_to_cpu(rfc.retrans_timeout);
360447d1ec61SGustavo F. Padovan 			chan->monitor_timeout = le16_to_cpu(rfc.monitor_timeout);
360547d1ec61SGustavo F. Padovan 			chan->mps    = le16_to_cpu(rfc.max_pdu_size);
3606c20f8e35SMat Martineau 			if (!test_bit(FLAG_EXT_CTRL, &chan->flags))
3607c20f8e35SMat Martineau 				chan->ack_win = min_t(u16, chan->ack_win,
3608c20f8e35SMat Martineau 						      rfc.txwin_size);
360966af7aafSAndrei Emeltchenko 
361066af7aafSAndrei Emeltchenko 			if (test_bit(FLAG_EFS_ENABLE, &chan->flags)) {
361166af7aafSAndrei Emeltchenko 				chan->local_msdu = le16_to_cpu(efs.msdu);
361266af7aafSAndrei Emeltchenko 				chan->local_sdu_itime =
361366af7aafSAndrei Emeltchenko 					le32_to_cpu(efs.sdu_itime);
361466af7aafSAndrei Emeltchenko 				chan->local_acc_lat = le32_to_cpu(efs.acc_lat);
361566af7aafSAndrei Emeltchenko 				chan->local_flush_to =
361666af7aafSAndrei Emeltchenko 					le32_to_cpu(efs.flush_to);
361766af7aafSAndrei Emeltchenko 			}
36180a708f8fSGustavo F. Padovan 			break;
361966af7aafSAndrei Emeltchenko 
36200a708f8fSGustavo F. Padovan 		case L2CAP_MODE_STREAMING:
362147d1ec61SGustavo F. Padovan 			chan->mps    = le16_to_cpu(rfc.max_pdu_size);
36220a708f8fSGustavo F. Padovan 		}
36230a708f8fSGustavo F. Padovan 	}
36240a708f8fSGustavo F. Padovan 
3625fe4128e0SGustavo F. Padovan 	req->dcid   = cpu_to_le16(chan->dcid);
362659e54bd1SAndrei Emeltchenko 	req->flags  = __constant_cpu_to_le16(0);
36270a708f8fSGustavo F. Padovan 
36280a708f8fSGustavo F. Padovan 	return ptr - data;
36290a708f8fSGustavo F. Padovan }
36300a708f8fSGustavo F. Padovan 
36312d792818SGustavo Padovan static int l2cap_build_conf_rsp(struct l2cap_chan *chan, void *data,
36322d792818SGustavo Padovan 				u16 result, u16 flags)
36330a708f8fSGustavo F. Padovan {
36340a708f8fSGustavo F. Padovan 	struct l2cap_conf_rsp *rsp = data;
36350a708f8fSGustavo F. Padovan 	void *ptr = rsp->data;
36360a708f8fSGustavo F. Padovan 
3637fe4128e0SGustavo F. Padovan 	BT_DBG("chan %p", chan);
36380a708f8fSGustavo F. Padovan 
3639fe4128e0SGustavo F. Padovan 	rsp->scid   = cpu_to_le16(chan->dcid);
36400a708f8fSGustavo F. Padovan 	rsp->result = cpu_to_le16(result);
36410a708f8fSGustavo F. Padovan 	rsp->flags  = cpu_to_le16(flags);
36420a708f8fSGustavo F. Padovan 
36430a708f8fSGustavo F. Padovan 	return ptr - data;
36440a708f8fSGustavo F. Padovan }
36450a708f8fSGustavo F. Padovan 
36468c1d787bSGustavo F. Padovan void __l2cap_connect_rsp_defer(struct l2cap_chan *chan)
3647710f9b0aSGustavo F. Padovan {
3648710f9b0aSGustavo F. Padovan 	struct l2cap_conn_rsp rsp;
36498c1d787bSGustavo F. Padovan 	struct l2cap_conn *conn = chan->conn;
3650710f9b0aSGustavo F. Padovan 	u8 buf[128];
3651439f34acSAndrei Emeltchenko 	u8 rsp_code;
3652710f9b0aSGustavo F. Padovan 
3653fe4128e0SGustavo F. Padovan 	rsp.scid   = cpu_to_le16(chan->dcid);
3654fe4128e0SGustavo F. Padovan 	rsp.dcid   = cpu_to_le16(chan->scid);
3655ac73498cSAndrei Emeltchenko 	rsp.result = __constant_cpu_to_le16(L2CAP_CR_SUCCESS);
3656ac73498cSAndrei Emeltchenko 	rsp.status = __constant_cpu_to_le16(L2CAP_CS_NO_INFO);
3657439f34acSAndrei Emeltchenko 
3658439f34acSAndrei Emeltchenko 	if (chan->hs_hcon)
3659439f34acSAndrei Emeltchenko 		rsp_code = L2CAP_CREATE_CHAN_RSP;
3660439f34acSAndrei Emeltchenko 	else
3661439f34acSAndrei Emeltchenko 		rsp_code = L2CAP_CONN_RSP;
3662439f34acSAndrei Emeltchenko 
3663439f34acSAndrei Emeltchenko 	BT_DBG("chan %p rsp_code %u", chan, rsp_code);
3664439f34acSAndrei Emeltchenko 
3665439f34acSAndrei Emeltchenko 	l2cap_send_cmd(conn, chan->ident, rsp_code, sizeof(rsp), &rsp);
3666710f9b0aSGustavo F. Padovan 
3667c1360a1cSGustavo F. Padovan 	if (test_and_set_bit(CONF_REQ_SENT, &chan->conf_state))
3668710f9b0aSGustavo F. Padovan 		return;
3669710f9b0aSGustavo F. Padovan 
3670710f9b0aSGustavo F. Padovan 	l2cap_send_cmd(conn, l2cap_get_ident(conn), L2CAP_CONF_REQ,
3671710f9b0aSGustavo F. Padovan 		       l2cap_build_conf_req(chan, buf), buf);
3672710f9b0aSGustavo F. Padovan 	chan->num_conf_req++;
3673710f9b0aSGustavo F. Padovan }
3674710f9b0aSGustavo F. Padovan 
367547d1ec61SGustavo F. Padovan static void l2cap_conf_rfc_get(struct l2cap_chan *chan, void *rsp, int len)
36760a708f8fSGustavo F. Padovan {
36770a708f8fSGustavo F. Padovan 	int type, olen;
36780a708f8fSGustavo F. Padovan 	unsigned long val;
3679c20f8e35SMat Martineau 	/* Use sane default values in case a misbehaving remote device
3680c20f8e35SMat Martineau 	 * did not send an RFC or extended window size option.
3681c20f8e35SMat Martineau 	 */
3682c20f8e35SMat Martineau 	u16 txwin_ext = chan->ack_win;
3683c20f8e35SMat Martineau 	struct l2cap_conf_rfc rfc = {
3684c20f8e35SMat Martineau 		.mode = chan->mode,
3685c20f8e35SMat Martineau 		.retrans_timeout = __constant_cpu_to_le16(L2CAP_DEFAULT_RETRANS_TO),
3686c20f8e35SMat Martineau 		.monitor_timeout = __constant_cpu_to_le16(L2CAP_DEFAULT_MONITOR_TO),
3687c20f8e35SMat Martineau 		.max_pdu_size = cpu_to_le16(chan->imtu),
3688c20f8e35SMat Martineau 		.txwin_size = min_t(u16, chan->ack_win, L2CAP_DEFAULT_TX_WINDOW),
3689c20f8e35SMat Martineau 	};
36900a708f8fSGustavo F. Padovan 
369147d1ec61SGustavo F. Padovan 	BT_DBG("chan %p, rsp %p, len %d", chan, rsp, len);
36920a708f8fSGustavo F. Padovan 
36930c1bc5c6SGustavo F. Padovan 	if ((chan->mode != L2CAP_MODE_ERTM) && (chan->mode != L2CAP_MODE_STREAMING))
36940a708f8fSGustavo F. Padovan 		return;
36950a708f8fSGustavo F. Padovan 
36960a708f8fSGustavo F. Padovan 	while (len >= L2CAP_CONF_OPT_SIZE) {
36970a708f8fSGustavo F. Padovan 		len -= l2cap_get_conf_opt(&rsp, &type, &olen, &val);
36980a708f8fSGustavo F. Padovan 
3699c20f8e35SMat Martineau 		switch (type) {
3700c20f8e35SMat Martineau 		case L2CAP_CONF_RFC:
3701c20f8e35SMat Martineau 			if (olen == sizeof(rfc))
37020a708f8fSGustavo F. Padovan 				memcpy(&rfc, (void *)val, olen);
3703c20f8e35SMat Martineau 			break;
3704c20f8e35SMat Martineau 		case L2CAP_CONF_EWS:
3705c20f8e35SMat Martineau 			txwin_ext = val;
3706c20f8e35SMat Martineau 			break;
3707c20f8e35SMat Martineau 		}
37080a708f8fSGustavo F. Padovan 	}
37090a708f8fSGustavo F. Padovan 
37100a708f8fSGustavo F. Padovan 	switch (rfc.mode) {
37110a708f8fSGustavo F. Padovan 	case L2CAP_MODE_ERTM:
371247d1ec61SGustavo F. Padovan 		chan->retrans_timeout = le16_to_cpu(rfc.retrans_timeout);
371347d1ec61SGustavo F. Padovan 		chan->monitor_timeout = le16_to_cpu(rfc.monitor_timeout);
371447d1ec61SGustavo F. Padovan 		chan->mps = le16_to_cpu(rfc.max_pdu_size);
3715c20f8e35SMat Martineau 		if (test_bit(FLAG_EXT_CTRL, &chan->flags))
3716c20f8e35SMat Martineau 			chan->ack_win = min_t(u16, chan->ack_win, txwin_ext);
3717c20f8e35SMat Martineau 		else
3718c20f8e35SMat Martineau 			chan->ack_win = min_t(u16, chan->ack_win,
3719c20f8e35SMat Martineau 					      rfc.txwin_size);
37200a708f8fSGustavo F. Padovan 		break;
37210a708f8fSGustavo F. Padovan 	case L2CAP_MODE_STREAMING:
372247d1ec61SGustavo F. Padovan 		chan->mps    = le16_to_cpu(rfc.max_pdu_size);
37230a708f8fSGustavo F. Padovan 	}
37240a708f8fSGustavo F. Padovan }
37250a708f8fSGustavo F. Padovan 
37262d792818SGustavo Padovan static inline int l2cap_command_rej(struct l2cap_conn *conn,
3727cb3b3152SJohan Hedberg 				    struct l2cap_cmd_hdr *cmd, u16 cmd_len,
3728cb3b3152SJohan Hedberg 				    u8 *data)
37290a708f8fSGustavo F. Padovan {
3730e2fd318eSIlia Kolomisnky 	struct l2cap_cmd_rej_unk *rej = (struct l2cap_cmd_rej_unk *) data;
37310a708f8fSGustavo F. Padovan 
3732cb3b3152SJohan Hedberg 	if (cmd_len < sizeof(*rej))
3733cb3b3152SJohan Hedberg 		return -EPROTO;
3734cb3b3152SJohan Hedberg 
3735e2fd318eSIlia Kolomisnky 	if (rej->reason != L2CAP_REJ_NOT_UNDERSTOOD)
37360a708f8fSGustavo F. Padovan 		return 0;
37370a708f8fSGustavo F. Padovan 
37380a708f8fSGustavo F. Padovan 	if ((conn->info_state & L2CAP_INFO_FEAT_MASK_REQ_SENT) &&
37390a708f8fSGustavo F. Padovan 	    cmd->ident == conn->info_ident) {
374017cd3f37SUlisses Furquim 		cancel_delayed_work(&conn->info_timer);
37410a708f8fSGustavo F. Padovan 
37420a708f8fSGustavo F. Padovan 		conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_DONE;
37430a708f8fSGustavo F. Padovan 		conn->info_ident = 0;
37440a708f8fSGustavo F. Padovan 
37450a708f8fSGustavo F. Padovan 		l2cap_conn_start(conn);
37460a708f8fSGustavo F. Padovan 	}
37470a708f8fSGustavo F. Padovan 
37480a708f8fSGustavo F. Padovan 	return 0;
37490a708f8fSGustavo F. Padovan }
37500a708f8fSGustavo F. Padovan 
37511700915fSMat Martineau static struct l2cap_chan *l2cap_connect(struct l2cap_conn *conn,
37521700915fSMat Martineau 					struct l2cap_cmd_hdr *cmd,
37534c89b6aaSMat Martineau 					u8 *data, u8 rsp_code, u8 amp_id)
37540a708f8fSGustavo F. Padovan {
37550a708f8fSGustavo F. Padovan 	struct l2cap_conn_req *req = (struct l2cap_conn_req *) data;
37560a708f8fSGustavo F. Padovan 	struct l2cap_conn_rsp rsp;
375723691d75SGustavo F. Padovan 	struct l2cap_chan *chan = NULL, *pchan;
37580a708f8fSGustavo F. Padovan 	struct sock *parent, *sk = NULL;
37590a708f8fSGustavo F. Padovan 	int result, status = L2CAP_CS_NO_INFO;
37600a708f8fSGustavo F. Padovan 
37610a708f8fSGustavo F. Padovan 	u16 dcid = 0, scid = __le16_to_cpu(req->scid);
37620a708f8fSGustavo F. Padovan 	__le16 psm = req->psm;
37630a708f8fSGustavo F. Padovan 
3764097db76cSAndrei Emeltchenko 	BT_DBG("psm 0x%2.2x scid 0x%4.4x", __le16_to_cpu(psm), scid);
37650a708f8fSGustavo F. Padovan 
37660a708f8fSGustavo F. Padovan 	/* Check if we have socket listening on psm */
37676f59b904SMarcel Holtmann 	pchan = l2cap_global_chan_by_psm(BT_LISTEN, psm, &conn->hcon->src,
376898e0f7eaSMarcel Holtmann 					 &conn->hcon->dst);
376923691d75SGustavo F. Padovan 	if (!pchan) {
37700a708f8fSGustavo F. Padovan 		result = L2CAP_CR_BAD_PSM;
37710a708f8fSGustavo F. Padovan 		goto sendresp;
37720a708f8fSGustavo F. Padovan 	}
37730a708f8fSGustavo F. Padovan 
377423691d75SGustavo F. Padovan 	parent = pchan->sk;
377523691d75SGustavo F. Padovan 
37763df91ea2SAndrei Emeltchenko 	mutex_lock(&conn->chan_lock);
3777aa2ac881SGustavo F. Padovan 	lock_sock(parent);
37780a708f8fSGustavo F. Padovan 
37790a708f8fSGustavo F. Padovan 	/* Check if the ACL is secure enough (if not SDP) */
37802983fd68SAndrei Emeltchenko 	if (psm != __constant_cpu_to_le16(L2CAP_PSM_SDP) &&
37810a708f8fSGustavo F. Padovan 	    !hci_conn_check_link_mode(conn->hcon)) {
37829f5a0d7bSAndrei Emeltchenko 		conn->disc_reason = HCI_ERROR_AUTH_FAILURE;
37830a708f8fSGustavo F. Padovan 		result = L2CAP_CR_SEC_BLOCK;
37840a708f8fSGustavo F. Padovan 		goto response;
37850a708f8fSGustavo F. Padovan 	}
37860a708f8fSGustavo F. Padovan 
37870a708f8fSGustavo F. Padovan 	result = L2CAP_CR_NO_MEM;
37880a708f8fSGustavo F. Padovan 
37892dfa1003SGustavo Padovan 	/* Check if we already have channel with that dcid */
37902dfa1003SGustavo Padovan 	if (__l2cap_get_chan_by_dcid(conn, scid))
37912dfa1003SGustavo Padovan 		goto response;
37922dfa1003SGustavo Padovan 
379380b98027SGustavo Padovan 	chan = pchan->ops->new_connection(pchan);
379480808e43SGustavo F. Padovan 	if (!chan)
37950a708f8fSGustavo F. Padovan 		goto response;
37960a708f8fSGustavo F. Padovan 
379780808e43SGustavo F. Padovan 	sk = chan->sk;
379880808e43SGustavo F. Padovan 
3799330b6c15SSyam Sidhardhan 	/* For certain devices (ex: HID mouse), support for authentication,
3800330b6c15SSyam Sidhardhan 	 * pairing and bonding is optional. For such devices, inorder to avoid
3801330b6c15SSyam Sidhardhan 	 * the ACL alive for too long after L2CAP disconnection, reset the ACL
3802330b6c15SSyam Sidhardhan 	 * disc_timeout back to HCI_DISCONN_TIMEOUT during L2CAP connect.
3803330b6c15SSyam Sidhardhan 	 */
3804330b6c15SSyam Sidhardhan 	conn->hcon->disc_timeout = HCI_DISCONN_TIMEOUT;
3805330b6c15SSyam Sidhardhan 
38067eafc59eSMarcel Holtmann 	bacpy(&chan->src, &conn->hcon->src);
38077eafc59eSMarcel Holtmann 	bacpy(&chan->dst, &conn->hcon->dst);
38084f1654e0SMarcel Holtmann 	chan->src_type = bdaddr_type(conn->hcon, conn->hcon->src_type);
38094f1654e0SMarcel Holtmann 	chan->dst_type = bdaddr_type(conn->hcon, conn->hcon->dst_type);
3810fe4128e0SGustavo F. Padovan 	chan->psm  = psm;
3811fe4128e0SGustavo F. Padovan 	chan->dcid = scid;
38121700915fSMat Martineau 	chan->local_amp_id = amp_id;
38130a708f8fSGustavo F. Padovan 
38146be36555SAndrei Emeltchenko 	__l2cap_chan_add(conn, chan);
381548454079SGustavo F. Padovan 
3816fe4128e0SGustavo F. Padovan 	dcid = chan->scid;
38170a708f8fSGustavo F. Padovan 
38188d836d71SGustavo Padovan 	__set_chan_timer(chan, chan->ops->get_sndtimeo(chan));
38190a708f8fSGustavo F. Padovan 
3820fc7f8a7eSGustavo F. Padovan 	chan->ident = cmd->ident;
38210a708f8fSGustavo F. Padovan 
38220a708f8fSGustavo F. Padovan 	if (conn->info_state & L2CAP_INFO_FEAT_MASK_REQ_DONE) {
3823d45fc423SGustavo F. Padovan 		if (l2cap_chan_check_security(chan)) {
3824bdc25783SMarcel Holtmann 			if (test_bit(FLAG_DEFER_SETUP, &chan->flags)) {
38250e587be7SAndrei Emeltchenko 				__l2cap_state_change(chan, BT_CONNECT2);
38260a708f8fSGustavo F. Padovan 				result = L2CAP_CR_PEND;
38270a708f8fSGustavo F. Padovan 				status = L2CAP_CS_AUTHOR_PEND;
38282dc4e510SGustavo Padovan 				chan->ops->defer(chan);
38290a708f8fSGustavo F. Padovan 			} else {
38301700915fSMat Martineau 				/* Force pending result for AMP controllers.
38311700915fSMat Martineau 				 * The connection will succeed after the
38321700915fSMat Martineau 				 * physical link is up.
38331700915fSMat Martineau 				 */
38346ed971caSMarcel Holtmann 				if (amp_id == AMP_ID_BREDR) {
38350e587be7SAndrei Emeltchenko 					__l2cap_state_change(chan, BT_CONFIG);
38360a708f8fSGustavo F. Padovan 					result = L2CAP_CR_SUCCESS;
38376ed971caSMarcel Holtmann 				} else {
38386ed971caSMarcel Holtmann 					__l2cap_state_change(chan, BT_CONNECT2);
38396ed971caSMarcel Holtmann 					result = L2CAP_CR_PEND;
38401700915fSMat Martineau 				}
38410a708f8fSGustavo F. Padovan 				status = L2CAP_CS_NO_INFO;
38420a708f8fSGustavo F. Padovan 			}
38430a708f8fSGustavo F. Padovan 		} else {
38440e587be7SAndrei Emeltchenko 			__l2cap_state_change(chan, BT_CONNECT2);
38450a708f8fSGustavo F. Padovan 			result = L2CAP_CR_PEND;
38460a708f8fSGustavo F. Padovan 			status = L2CAP_CS_AUTHEN_PEND;
38470a708f8fSGustavo F. Padovan 		}
38480a708f8fSGustavo F. Padovan 	} else {
38490e587be7SAndrei Emeltchenko 		__l2cap_state_change(chan, BT_CONNECT2);
38500a708f8fSGustavo F. Padovan 		result = L2CAP_CR_PEND;
38510a708f8fSGustavo F. Padovan 		status = L2CAP_CS_NO_INFO;
38520a708f8fSGustavo F. Padovan 	}
38530a708f8fSGustavo F. Padovan 
38540a708f8fSGustavo F. Padovan response:
3855aa2ac881SGustavo F. Padovan 	release_sock(parent);
38563df91ea2SAndrei Emeltchenko 	mutex_unlock(&conn->chan_lock);
38570a708f8fSGustavo F. Padovan 
38580a708f8fSGustavo F. Padovan sendresp:
38590a708f8fSGustavo F. Padovan 	rsp.scid   = cpu_to_le16(scid);
38600a708f8fSGustavo F. Padovan 	rsp.dcid   = cpu_to_le16(dcid);
38610a708f8fSGustavo F. Padovan 	rsp.result = cpu_to_le16(result);
38620a708f8fSGustavo F. Padovan 	rsp.status = cpu_to_le16(status);
38634c89b6aaSMat Martineau 	l2cap_send_cmd(conn, cmd->ident, rsp_code, sizeof(rsp), &rsp);
38640a708f8fSGustavo F. Padovan 
38650a708f8fSGustavo F. Padovan 	if (result == L2CAP_CR_PEND && status == L2CAP_CS_NO_INFO) {
38660a708f8fSGustavo F. Padovan 		struct l2cap_info_req info;
3867ac73498cSAndrei Emeltchenko 		info.type = __constant_cpu_to_le16(L2CAP_IT_FEAT_MASK);
38680a708f8fSGustavo F. Padovan 
38690a708f8fSGustavo F. Padovan 		conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_SENT;
38700a708f8fSGustavo F. Padovan 		conn->info_ident = l2cap_get_ident(conn);
38710a708f8fSGustavo F. Padovan 
3872ba13ccd9SMarcel Holtmann 		schedule_delayed_work(&conn->info_timer, L2CAP_INFO_TIMEOUT);
38730a708f8fSGustavo F. Padovan 
38742d792818SGustavo Padovan 		l2cap_send_cmd(conn, conn->info_ident, L2CAP_INFO_REQ,
38752d792818SGustavo Padovan 			       sizeof(info), &info);
38760a708f8fSGustavo F. Padovan 	}
38770a708f8fSGustavo F. Padovan 
3878c1360a1cSGustavo F. Padovan 	if (chan && !test_bit(CONF_REQ_SENT, &chan->conf_state) &&
38790a708f8fSGustavo F. Padovan 	    result == L2CAP_CR_SUCCESS) {
38800a708f8fSGustavo F. Padovan 		u8 buf[128];
3881c1360a1cSGustavo F. Padovan 		set_bit(CONF_REQ_SENT, &chan->conf_state);
38820a708f8fSGustavo F. Padovan 		l2cap_send_cmd(conn, l2cap_get_ident(conn), L2CAP_CONF_REQ,
388373ffa904SGustavo F. Padovan 			       l2cap_build_conf_req(chan, buf), buf);
388473ffa904SGustavo F. Padovan 		chan->num_conf_req++;
38850a708f8fSGustavo F. Padovan 	}
38861700915fSMat Martineau 
38871700915fSMat Martineau 	return chan;
38884c89b6aaSMat Martineau }
38890a708f8fSGustavo F. Padovan 
38904c89b6aaSMat Martineau static int l2cap_connect_req(struct l2cap_conn *conn,
3891cb3b3152SJohan Hedberg 			     struct l2cap_cmd_hdr *cmd, u16 cmd_len, u8 *data)
38924c89b6aaSMat Martineau {
38937b064edaSJaganath Kanakkassery 	struct hci_dev *hdev = conn->hcon->hdev;
38947b064edaSJaganath Kanakkassery 	struct hci_conn *hcon = conn->hcon;
38957b064edaSJaganath Kanakkassery 
3896cb3b3152SJohan Hedberg 	if (cmd_len < sizeof(struct l2cap_conn_req))
3897cb3b3152SJohan Hedberg 		return -EPROTO;
3898cb3b3152SJohan Hedberg 
38997b064edaSJaganath Kanakkassery 	hci_dev_lock(hdev);
39007b064edaSJaganath Kanakkassery 	if (test_bit(HCI_MGMT, &hdev->dev_flags) &&
39017b064edaSJaganath Kanakkassery 	    !test_and_set_bit(HCI_CONN_MGMT_CONNECTED, &hcon->flags))
39027b064edaSJaganath Kanakkassery 		mgmt_device_connected(hdev, &hcon->dst, hcon->type,
39037b064edaSJaganath Kanakkassery 				      hcon->dst_type, 0, NULL, 0,
39047b064edaSJaganath Kanakkassery 				      hcon->dev_class);
39057b064edaSJaganath Kanakkassery 	hci_dev_unlock(hdev);
39067b064edaSJaganath Kanakkassery 
3907300229f9SGustavo Padovan 	l2cap_connect(conn, cmd, data, L2CAP_CONN_RSP, 0);
39080a708f8fSGustavo F. Padovan 	return 0;
39090a708f8fSGustavo F. Padovan }
39100a708f8fSGustavo F. Padovan 
39115909cf30SMat Martineau static int l2cap_connect_create_rsp(struct l2cap_conn *conn,
3912cb3b3152SJohan Hedberg 				    struct l2cap_cmd_hdr *cmd, u16 cmd_len,
3913cb3b3152SJohan Hedberg 				    u8 *data)
39140a708f8fSGustavo F. Padovan {
39150a708f8fSGustavo F. Padovan 	struct l2cap_conn_rsp *rsp = (struct l2cap_conn_rsp *) data;
39160a708f8fSGustavo F. Padovan 	u16 scid, dcid, result, status;
391748454079SGustavo F. Padovan 	struct l2cap_chan *chan;
39180a708f8fSGustavo F. Padovan 	u8 req[128];
39193df91ea2SAndrei Emeltchenko 	int err;
39200a708f8fSGustavo F. Padovan 
3921cb3b3152SJohan Hedberg 	if (cmd_len < sizeof(*rsp))
3922cb3b3152SJohan Hedberg 		return -EPROTO;
3923cb3b3152SJohan Hedberg 
39240a708f8fSGustavo F. Padovan 	scid   = __le16_to_cpu(rsp->scid);
39250a708f8fSGustavo F. Padovan 	dcid   = __le16_to_cpu(rsp->dcid);
39260a708f8fSGustavo F. Padovan 	result = __le16_to_cpu(rsp->result);
39270a708f8fSGustavo F. Padovan 	status = __le16_to_cpu(rsp->status);
39280a708f8fSGustavo F. Padovan 
39291b009c98SAndrei Emeltchenko 	BT_DBG("dcid 0x%4.4x scid 0x%4.4x result 0x%2.2x status 0x%2.2x",
39301b009c98SAndrei Emeltchenko 	       dcid, scid, result, status);
39310a708f8fSGustavo F. Padovan 
39323df91ea2SAndrei Emeltchenko 	mutex_lock(&conn->chan_lock);
39333df91ea2SAndrei Emeltchenko 
39340a708f8fSGustavo F. Padovan 	if (scid) {
39353df91ea2SAndrei Emeltchenko 		chan = __l2cap_get_chan_by_scid(conn, scid);
39363df91ea2SAndrei Emeltchenko 		if (!chan) {
393721870b52SJohan Hedberg 			err = -EBADSLT;
39383df91ea2SAndrei Emeltchenko 			goto unlock;
39393df91ea2SAndrei Emeltchenko 		}
39400a708f8fSGustavo F. Padovan 	} else {
39413df91ea2SAndrei Emeltchenko 		chan = __l2cap_get_chan_by_ident(conn, cmd->ident);
39423df91ea2SAndrei Emeltchenko 		if (!chan) {
394321870b52SJohan Hedberg 			err = -EBADSLT;
39443df91ea2SAndrei Emeltchenko 			goto unlock;
39453df91ea2SAndrei Emeltchenko 		}
39460a708f8fSGustavo F. Padovan 	}
39470a708f8fSGustavo F. Padovan 
39483df91ea2SAndrei Emeltchenko 	err = 0;
39493df91ea2SAndrei Emeltchenko 
39506be36555SAndrei Emeltchenko 	l2cap_chan_lock(chan);
395148454079SGustavo F. Padovan 
39520a708f8fSGustavo F. Padovan 	switch (result) {
39530a708f8fSGustavo F. Padovan 	case L2CAP_CR_SUCCESS:
395489bc500eSGustavo F. Padovan 		l2cap_state_change(chan, BT_CONFIG);
3955fc7f8a7eSGustavo F. Padovan 		chan->ident = 0;
3956fe4128e0SGustavo F. Padovan 		chan->dcid = dcid;
3957c1360a1cSGustavo F. Padovan 		clear_bit(CONF_CONNECT_PEND, &chan->conf_state);
39580a708f8fSGustavo F. Padovan 
3959c1360a1cSGustavo F. Padovan 		if (test_and_set_bit(CONF_REQ_SENT, &chan->conf_state))
39600a708f8fSGustavo F. Padovan 			break;
39610a708f8fSGustavo F. Padovan 
39620a708f8fSGustavo F. Padovan 		l2cap_send_cmd(conn, l2cap_get_ident(conn), L2CAP_CONF_REQ,
396373ffa904SGustavo F. Padovan 			       l2cap_build_conf_req(chan, req), req);
396473ffa904SGustavo F. Padovan 		chan->num_conf_req++;
39650a708f8fSGustavo F. Padovan 		break;
39660a708f8fSGustavo F. Padovan 
39670a708f8fSGustavo F. Padovan 	case L2CAP_CR_PEND:
3968c1360a1cSGustavo F. Padovan 		set_bit(CONF_CONNECT_PEND, &chan->conf_state);
39690a708f8fSGustavo F. Padovan 		break;
39700a708f8fSGustavo F. Padovan 
39710a708f8fSGustavo F. Padovan 	default:
397248454079SGustavo F. Padovan 		l2cap_chan_del(chan, ECONNREFUSED);
39730a708f8fSGustavo F. Padovan 		break;
39740a708f8fSGustavo F. Padovan 	}
39750a708f8fSGustavo F. Padovan 
39766be36555SAndrei Emeltchenko 	l2cap_chan_unlock(chan);
39773df91ea2SAndrei Emeltchenko 
39783df91ea2SAndrei Emeltchenko unlock:
39793df91ea2SAndrei Emeltchenko 	mutex_unlock(&conn->chan_lock);
39803df91ea2SAndrei Emeltchenko 
39813df91ea2SAndrei Emeltchenko 	return err;
39820a708f8fSGustavo F. Padovan }
39830a708f8fSGustavo F. Padovan 
398447d1ec61SGustavo F. Padovan static inline void set_default_fcs(struct l2cap_chan *chan)
39850a708f8fSGustavo F. Padovan {
39860a708f8fSGustavo F. Padovan 	/* FCS is enabled only in ERTM or streaming mode, if one or both
39870a708f8fSGustavo F. Padovan 	 * sides request it.
39880a708f8fSGustavo F. Padovan 	 */
39890c1bc5c6SGustavo F. Padovan 	if (chan->mode != L2CAP_MODE_ERTM && chan->mode != L2CAP_MODE_STREAMING)
399047d1ec61SGustavo F. Padovan 		chan->fcs = L2CAP_FCS_NONE;
3991f2592d3eSAndrei Emeltchenko 	else if (!test_bit(CONF_RECV_NO_FCS, &chan->conf_state))
399247d1ec61SGustavo F. Padovan 		chan->fcs = L2CAP_FCS_CRC16;
39930a708f8fSGustavo F. Padovan }
39940a708f8fSGustavo F. Padovan 
399529d8a590SAndrei Emeltchenko static void l2cap_send_efs_conf_rsp(struct l2cap_chan *chan, void *data,
399629d8a590SAndrei Emeltchenko 				    u8 ident, u16 flags)
399729d8a590SAndrei Emeltchenko {
399829d8a590SAndrei Emeltchenko 	struct l2cap_conn *conn = chan->conn;
399929d8a590SAndrei Emeltchenko 
400029d8a590SAndrei Emeltchenko 	BT_DBG("conn %p chan %p ident %d flags 0x%4.4x", conn, chan, ident,
400129d8a590SAndrei Emeltchenko 	       flags);
400229d8a590SAndrei Emeltchenko 
400329d8a590SAndrei Emeltchenko 	clear_bit(CONF_LOC_CONF_PEND, &chan->conf_state);
400429d8a590SAndrei Emeltchenko 	set_bit(CONF_OUTPUT_DONE, &chan->conf_state);
400529d8a590SAndrei Emeltchenko 
400629d8a590SAndrei Emeltchenko 	l2cap_send_cmd(conn, ident, L2CAP_CONF_RSP,
400729d8a590SAndrei Emeltchenko 		       l2cap_build_conf_rsp(chan, data,
400829d8a590SAndrei Emeltchenko 					    L2CAP_CONF_SUCCESS, flags), data);
400929d8a590SAndrei Emeltchenko }
401029d8a590SAndrei Emeltchenko 
40112d792818SGustavo Padovan static inline int l2cap_config_req(struct l2cap_conn *conn,
40122d792818SGustavo Padovan 				   struct l2cap_cmd_hdr *cmd, u16 cmd_len,
40132d792818SGustavo Padovan 				   u8 *data)
40140a708f8fSGustavo F. Padovan {
40150a708f8fSGustavo F. Padovan 	struct l2cap_conf_req *req = (struct l2cap_conf_req *) data;
40160a708f8fSGustavo F. Padovan 	u16 dcid, flags;
40170a708f8fSGustavo F. Padovan 	u8 rsp[64];
401848454079SGustavo F. Padovan 	struct l2cap_chan *chan;
40193c588192SMat Martineau 	int len, err = 0;
40200a708f8fSGustavo F. Padovan 
4021cb3b3152SJohan Hedberg 	if (cmd_len < sizeof(*req))
4022cb3b3152SJohan Hedberg 		return -EPROTO;
4023cb3b3152SJohan Hedberg 
40240a708f8fSGustavo F. Padovan 	dcid  = __le16_to_cpu(req->dcid);
40250a708f8fSGustavo F. Padovan 	flags = __le16_to_cpu(req->flags);
40260a708f8fSGustavo F. Padovan 
40270a708f8fSGustavo F. Padovan 	BT_DBG("dcid 0x%4.4x flags 0x%2.2x", dcid, flags);
40280a708f8fSGustavo F. Padovan 
4029baa7e1faSGustavo F. Padovan 	chan = l2cap_get_chan_by_scid(conn, dcid);
403048454079SGustavo F. Padovan 	if (!chan)
403121870b52SJohan Hedberg 		return -EBADSLT;
40320a708f8fSGustavo F. Padovan 
4033033b1142SDavid S. Miller 	if (chan->state != BT_CONFIG && chan->state != BT_CONNECT2) {
4034e2fd318eSIlia Kolomisnky 		struct l2cap_cmd_rej_cid rej;
40350a708f8fSGustavo F. Padovan 
4036ac73498cSAndrei Emeltchenko 		rej.reason = __constant_cpu_to_le16(L2CAP_REJ_INVALID_CID);
4037e2fd318eSIlia Kolomisnky 		rej.scid = cpu_to_le16(chan->scid);
4038e2fd318eSIlia Kolomisnky 		rej.dcid = cpu_to_le16(chan->dcid);
4039e2fd318eSIlia Kolomisnky 
40400a708f8fSGustavo F. Padovan 		l2cap_send_cmd(conn, cmd->ident, L2CAP_COMMAND_REJ,
40410a708f8fSGustavo F. Padovan 			       sizeof(rej), &rej);
40420a708f8fSGustavo F. Padovan 		goto unlock;
40430a708f8fSGustavo F. Padovan 	}
40440a708f8fSGustavo F. Padovan 
40450a708f8fSGustavo F. Padovan 	/* Reject if config buffer is too small. */
40460a708f8fSGustavo F. Padovan 	len = cmd_len - sizeof(*req);
4047cb3b3152SJohan Hedberg 	if (chan->conf_len + len > sizeof(chan->conf_req)) {
40480a708f8fSGustavo F. Padovan 		l2cap_send_cmd(conn, cmd->ident, L2CAP_CONF_RSP,
4049fe4128e0SGustavo F. Padovan 			       l2cap_build_conf_rsp(chan, rsp,
40500a708f8fSGustavo F. Padovan 			       L2CAP_CONF_REJECT, flags), rsp);
40510a708f8fSGustavo F. Padovan 		goto unlock;
40520a708f8fSGustavo F. Padovan 	}
40530a708f8fSGustavo F. Padovan 
40540a708f8fSGustavo F. Padovan 	/* Store config. */
405573ffa904SGustavo F. Padovan 	memcpy(chan->conf_req + chan->conf_len, req->data, len);
405673ffa904SGustavo F. Padovan 	chan->conf_len += len;
40570a708f8fSGustavo F. Padovan 
405859e54bd1SAndrei Emeltchenko 	if (flags & L2CAP_CONF_FLAG_CONTINUATION) {
40590a708f8fSGustavo F. Padovan 		/* Incomplete config. Send empty response. */
40600a708f8fSGustavo F. Padovan 		l2cap_send_cmd(conn, cmd->ident, L2CAP_CONF_RSP,
4061fe4128e0SGustavo F. Padovan 			       l2cap_build_conf_rsp(chan, rsp,
40625325e5bbSAndrei Emeltchenko 			       L2CAP_CONF_SUCCESS, flags), rsp);
40630a708f8fSGustavo F. Padovan 		goto unlock;
40640a708f8fSGustavo F. Padovan 	}
40650a708f8fSGustavo F. Padovan 
40660a708f8fSGustavo F. Padovan 	/* Complete config. */
406773ffa904SGustavo F. Padovan 	len = l2cap_parse_conf_req(chan, rsp);
40680a708f8fSGustavo F. Padovan 	if (len < 0) {
40695e4e3972SAndrei Emeltchenko 		l2cap_send_disconn_req(chan, ECONNRESET);
40700a708f8fSGustavo F. Padovan 		goto unlock;
40710a708f8fSGustavo F. Padovan 	}
40720a708f8fSGustavo F. Padovan 
40731500109bSMat Martineau 	chan->ident = cmd->ident;
40740a708f8fSGustavo F. Padovan 	l2cap_send_cmd(conn, cmd->ident, L2CAP_CONF_RSP, len, rsp);
407573ffa904SGustavo F. Padovan 	chan->num_conf_rsp++;
40760a708f8fSGustavo F. Padovan 
40770a708f8fSGustavo F. Padovan 	/* Reset config buffer. */
407873ffa904SGustavo F. Padovan 	chan->conf_len = 0;
40790a708f8fSGustavo F. Padovan 
4080c1360a1cSGustavo F. Padovan 	if (!test_bit(CONF_OUTPUT_DONE, &chan->conf_state))
40810a708f8fSGustavo F. Padovan 		goto unlock;
40820a708f8fSGustavo F. Padovan 
4083c1360a1cSGustavo F. Padovan 	if (test_bit(CONF_INPUT_DONE, &chan->conf_state)) {
408447d1ec61SGustavo F. Padovan 		set_default_fcs(chan);
40850a708f8fSGustavo F. Padovan 
4086105bdf9eSMat Martineau 		if (chan->mode == L2CAP_MODE_ERTM ||
4087105bdf9eSMat Martineau 		    chan->mode == L2CAP_MODE_STREAMING)
40883c588192SMat Martineau 			err = l2cap_ertm_init(chan);
40890a708f8fSGustavo F. Padovan 
40903c588192SMat Martineau 		if (err < 0)
40915e4e3972SAndrei Emeltchenko 			l2cap_send_disconn_req(chan, -err);
40923c588192SMat Martineau 		else
4093cf4cd009SAndrei Emeltchenko 			l2cap_chan_ready(chan);
40943c588192SMat Martineau 
40950a708f8fSGustavo F. Padovan 		goto unlock;
40960a708f8fSGustavo F. Padovan 	}
40970a708f8fSGustavo F. Padovan 
4098c1360a1cSGustavo F. Padovan 	if (!test_and_set_bit(CONF_REQ_SENT, &chan->conf_state)) {
40990a708f8fSGustavo F. Padovan 		u8 buf[64];
41000a708f8fSGustavo F. Padovan 		l2cap_send_cmd(conn, l2cap_get_ident(conn), L2CAP_CONF_REQ,
410173ffa904SGustavo F. Padovan 			       l2cap_build_conf_req(chan, buf), buf);
410273ffa904SGustavo F. Padovan 		chan->num_conf_req++;
41030a708f8fSGustavo F. Padovan 	}
41040a708f8fSGustavo F. Padovan 
41050e8b207eSAndrei Emeltchenko 	/* Got Conf Rsp PENDING from remote side and asume we sent
41060e8b207eSAndrei Emeltchenko 	   Conf Rsp PENDING in the code above */
41070e8b207eSAndrei Emeltchenko 	if (test_bit(CONF_REM_CONF_PEND, &chan->conf_state) &&
41080e8b207eSAndrei Emeltchenko 	    test_bit(CONF_LOC_CONF_PEND, &chan->conf_state)) {
41090e8b207eSAndrei Emeltchenko 
41100e8b207eSAndrei Emeltchenko 		/* check compatibility */
41110e8b207eSAndrei Emeltchenko 
411279de886dSAndrei Emeltchenko 		/* Send rsp for BR/EDR channel */
4113f351bc72SAndrei Emeltchenko 		if (!chan->hs_hcon)
411429d8a590SAndrei Emeltchenko 			l2cap_send_efs_conf_rsp(chan, rsp, cmd->ident, flags);
411579de886dSAndrei Emeltchenko 		else
411679de886dSAndrei Emeltchenko 			chan->ident = cmd->ident;
41170e8b207eSAndrei Emeltchenko 	}
41180e8b207eSAndrei Emeltchenko 
41190a708f8fSGustavo F. Padovan unlock:
41206be36555SAndrei Emeltchenko 	l2cap_chan_unlock(chan);
41213c588192SMat Martineau 	return err;
41220a708f8fSGustavo F. Padovan }
41230a708f8fSGustavo F. Padovan 
41242d792818SGustavo Padovan static inline int l2cap_config_rsp(struct l2cap_conn *conn,
4125cb3b3152SJohan Hedberg 				   struct l2cap_cmd_hdr *cmd, u16 cmd_len,
4126cb3b3152SJohan Hedberg 				   u8 *data)
41270a708f8fSGustavo F. Padovan {
41280a708f8fSGustavo F. Padovan 	struct l2cap_conf_rsp *rsp = (struct l2cap_conf_rsp *)data;
41290a708f8fSGustavo F. Padovan 	u16 scid, flags, result;
413048454079SGustavo F. Padovan 	struct l2cap_chan *chan;
4131cb3b3152SJohan Hedberg 	int len = cmd_len - sizeof(*rsp);
41323c588192SMat Martineau 	int err = 0;
41330a708f8fSGustavo F. Padovan 
4134cb3b3152SJohan Hedberg 	if (cmd_len < sizeof(*rsp))
4135cb3b3152SJohan Hedberg 		return -EPROTO;
4136cb3b3152SJohan Hedberg 
41370a708f8fSGustavo F. Padovan 	scid   = __le16_to_cpu(rsp->scid);
41380a708f8fSGustavo F. Padovan 	flags  = __le16_to_cpu(rsp->flags);
41390a708f8fSGustavo F. Padovan 	result = __le16_to_cpu(rsp->result);
41400a708f8fSGustavo F. Padovan 
414161386cbaSAndrei Emeltchenko 	BT_DBG("scid 0x%4.4x flags 0x%2.2x result 0x%2.2x len %d", scid, flags,
414261386cbaSAndrei Emeltchenko 	       result, len);
41430a708f8fSGustavo F. Padovan 
4144baa7e1faSGustavo F. Padovan 	chan = l2cap_get_chan_by_scid(conn, scid);
414548454079SGustavo F. Padovan 	if (!chan)
41460a708f8fSGustavo F. Padovan 		return 0;
41470a708f8fSGustavo F. Padovan 
41480a708f8fSGustavo F. Padovan 	switch (result) {
41490a708f8fSGustavo F. Padovan 	case L2CAP_CONF_SUCCESS:
415047d1ec61SGustavo F. Padovan 		l2cap_conf_rfc_get(chan, rsp->data, len);
41510e8b207eSAndrei Emeltchenko 		clear_bit(CONF_REM_CONF_PEND, &chan->conf_state);
41520a708f8fSGustavo F. Padovan 		break;
41530a708f8fSGustavo F. Padovan 
41540e8b207eSAndrei Emeltchenko 	case L2CAP_CONF_PENDING:
41550e8b207eSAndrei Emeltchenko 		set_bit(CONF_REM_CONF_PEND, &chan->conf_state);
41560e8b207eSAndrei Emeltchenko 
41570e8b207eSAndrei Emeltchenko 		if (test_bit(CONF_LOC_CONF_PEND, &chan->conf_state)) {
41580e8b207eSAndrei Emeltchenko 			char buf[64];
41590e8b207eSAndrei Emeltchenko 
41600e8b207eSAndrei Emeltchenko 			len = l2cap_parse_conf_rsp(chan, rsp->data, len,
41610e8b207eSAndrei Emeltchenko 						   buf, &result);
41620e8b207eSAndrei Emeltchenko 			if (len < 0) {
41635e4e3972SAndrei Emeltchenko 				l2cap_send_disconn_req(chan, ECONNRESET);
41640e8b207eSAndrei Emeltchenko 				goto done;
41650e8b207eSAndrei Emeltchenko 			}
41660e8b207eSAndrei Emeltchenko 
4167f351bc72SAndrei Emeltchenko 			if (!chan->hs_hcon) {
416879de886dSAndrei Emeltchenko 				l2cap_send_efs_conf_rsp(chan, buf, cmd->ident,
416979de886dSAndrei Emeltchenko 							0);
41705ce66b59SAndrei Emeltchenko 			} else {
41715ce66b59SAndrei Emeltchenko 				if (l2cap_check_efs(chan)) {
41725ce66b59SAndrei Emeltchenko 					amp_create_logical_link(chan);
417379de886dSAndrei Emeltchenko 					chan->ident = cmd->ident;
41740e8b207eSAndrei Emeltchenko 				}
41755ce66b59SAndrei Emeltchenko 			}
41765ce66b59SAndrei Emeltchenko 		}
41770e8b207eSAndrei Emeltchenko 		goto done;
41780e8b207eSAndrei Emeltchenko 
41790a708f8fSGustavo F. Padovan 	case L2CAP_CONF_UNACCEPT:
418073ffa904SGustavo F. Padovan 		if (chan->num_conf_rsp <= L2CAP_CONF_MAX_CONF_RSP) {
41810a708f8fSGustavo F. Padovan 			char req[64];
41820a708f8fSGustavo F. Padovan 
41830a708f8fSGustavo F. Padovan 			if (len > sizeof(req) - sizeof(struct l2cap_conf_req)) {
41845e4e3972SAndrei Emeltchenko 				l2cap_send_disconn_req(chan, ECONNRESET);
41850a708f8fSGustavo F. Padovan 				goto done;
41860a708f8fSGustavo F. Padovan 			}
41870a708f8fSGustavo F. Padovan 
41880a708f8fSGustavo F. Padovan 			/* throw out any old stored conf requests */
41890a708f8fSGustavo F. Padovan 			result = L2CAP_CONF_SUCCESS;
4190b4450035SGustavo F. Padovan 			len = l2cap_parse_conf_rsp(chan, rsp->data, len,
4191b4450035SGustavo F. Padovan 						   req, &result);
41920a708f8fSGustavo F. Padovan 			if (len < 0) {
41935e4e3972SAndrei Emeltchenko 				l2cap_send_disconn_req(chan, ECONNRESET);
41940a708f8fSGustavo F. Padovan 				goto done;
41950a708f8fSGustavo F. Padovan 			}
41960a708f8fSGustavo F. Padovan 
41970a708f8fSGustavo F. Padovan 			l2cap_send_cmd(conn, l2cap_get_ident(conn),
41980a708f8fSGustavo F. Padovan 				       L2CAP_CONF_REQ, len, req);
419973ffa904SGustavo F. Padovan 			chan->num_conf_req++;
42000a708f8fSGustavo F. Padovan 			if (result != L2CAP_CONF_SUCCESS)
42010a708f8fSGustavo F. Padovan 				goto done;
42020a708f8fSGustavo F. Padovan 			break;
42030a708f8fSGustavo F. Padovan 		}
42040a708f8fSGustavo F. Padovan 
42050a708f8fSGustavo F. Padovan 	default:
42066be36555SAndrei Emeltchenko 		l2cap_chan_set_err(chan, ECONNRESET);
42072e0052e4SAndrei Emeltchenko 
4208ba13ccd9SMarcel Holtmann 		__set_chan_timer(chan, L2CAP_DISC_REJ_TIMEOUT);
42095e4e3972SAndrei Emeltchenko 		l2cap_send_disconn_req(chan, ECONNRESET);
42100a708f8fSGustavo F. Padovan 		goto done;
42110a708f8fSGustavo F. Padovan 	}
42120a708f8fSGustavo F. Padovan 
421359e54bd1SAndrei Emeltchenko 	if (flags & L2CAP_CONF_FLAG_CONTINUATION)
42140a708f8fSGustavo F. Padovan 		goto done;
42150a708f8fSGustavo F. Padovan 
4216c1360a1cSGustavo F. Padovan 	set_bit(CONF_INPUT_DONE, &chan->conf_state);
42170a708f8fSGustavo F. Padovan 
4218c1360a1cSGustavo F. Padovan 	if (test_bit(CONF_OUTPUT_DONE, &chan->conf_state)) {
421947d1ec61SGustavo F. Padovan 		set_default_fcs(chan);
42200a708f8fSGustavo F. Padovan 
4221105bdf9eSMat Martineau 		if (chan->mode == L2CAP_MODE_ERTM ||
4222105bdf9eSMat Martineau 		    chan->mode == L2CAP_MODE_STREAMING)
42233c588192SMat Martineau 			err = l2cap_ertm_init(chan);
42240a708f8fSGustavo F. Padovan 
42253c588192SMat Martineau 		if (err < 0)
42265e4e3972SAndrei Emeltchenko 			l2cap_send_disconn_req(chan, -err);
42273c588192SMat Martineau 		else
4228cf4cd009SAndrei Emeltchenko 			l2cap_chan_ready(chan);
42290a708f8fSGustavo F. Padovan 	}
42300a708f8fSGustavo F. Padovan 
42310a708f8fSGustavo F. Padovan done:
42326be36555SAndrei Emeltchenko 	l2cap_chan_unlock(chan);
42333c588192SMat Martineau 	return err;
42340a708f8fSGustavo F. Padovan }
42350a708f8fSGustavo F. Padovan 
42362d792818SGustavo Padovan static inline int l2cap_disconnect_req(struct l2cap_conn *conn,
4237cb3b3152SJohan Hedberg 				       struct l2cap_cmd_hdr *cmd, u16 cmd_len,
4238cb3b3152SJohan Hedberg 				       u8 *data)
42390a708f8fSGustavo F. Padovan {
42400a708f8fSGustavo F. Padovan 	struct l2cap_disconn_req *req = (struct l2cap_disconn_req *) data;
42410a708f8fSGustavo F. Padovan 	struct l2cap_disconn_rsp rsp;
42420a708f8fSGustavo F. Padovan 	u16 dcid, scid;
424348454079SGustavo F. Padovan 	struct l2cap_chan *chan;
42440a708f8fSGustavo F. Padovan 
4245cb3b3152SJohan Hedberg 	if (cmd_len != sizeof(*req))
4246cb3b3152SJohan Hedberg 		return -EPROTO;
4247cb3b3152SJohan Hedberg 
42480a708f8fSGustavo F. Padovan 	scid = __le16_to_cpu(req->scid);
42490a708f8fSGustavo F. Padovan 	dcid = __le16_to_cpu(req->dcid);
42500a708f8fSGustavo F. Padovan 
42510a708f8fSGustavo F. Padovan 	BT_DBG("scid 0x%4.4x dcid 0x%4.4x", scid, dcid);
42520a708f8fSGustavo F. Padovan 
42533df91ea2SAndrei Emeltchenko 	mutex_lock(&conn->chan_lock);
42543df91ea2SAndrei Emeltchenko 
42553df91ea2SAndrei Emeltchenko 	chan = __l2cap_get_chan_by_scid(conn, dcid);
42563df91ea2SAndrei Emeltchenko 	if (!chan) {
42573df91ea2SAndrei Emeltchenko 		mutex_unlock(&conn->chan_lock);
4258c4ea249fSJohan Hedberg 		return -EBADSLT;
42593df91ea2SAndrei Emeltchenko 	}
42600a708f8fSGustavo F. Padovan 
42616be36555SAndrei Emeltchenko 	l2cap_chan_lock(chan);
42626be36555SAndrei Emeltchenko 
4263fe4128e0SGustavo F. Padovan 	rsp.dcid = cpu_to_le16(chan->scid);
4264fe4128e0SGustavo F. Padovan 	rsp.scid = cpu_to_le16(chan->dcid);
42650a708f8fSGustavo F. Padovan 	l2cap_send_cmd(conn, cmd->ident, L2CAP_DISCONN_RSP, sizeof(rsp), &rsp);
42660a708f8fSGustavo F. Padovan 
42675ec1bbe5SGustavo Padovan 	chan->ops->set_shutdown(chan);
42680a708f8fSGustavo F. Padovan 
426961d6ef3eSMat Martineau 	l2cap_chan_hold(chan);
427048454079SGustavo F. Padovan 	l2cap_chan_del(chan, ECONNRESET);
42716be36555SAndrei Emeltchenko 
42726be36555SAndrei Emeltchenko 	l2cap_chan_unlock(chan);
42730a708f8fSGustavo F. Padovan 
427480b98027SGustavo Padovan 	chan->ops->close(chan);
427561d6ef3eSMat Martineau 	l2cap_chan_put(chan);
42763df91ea2SAndrei Emeltchenko 
42773df91ea2SAndrei Emeltchenko 	mutex_unlock(&conn->chan_lock);
42783df91ea2SAndrei Emeltchenko 
42790a708f8fSGustavo F. Padovan 	return 0;
42800a708f8fSGustavo F. Padovan }
42810a708f8fSGustavo F. Padovan 
42822d792818SGustavo Padovan static inline int l2cap_disconnect_rsp(struct l2cap_conn *conn,
4283cb3b3152SJohan Hedberg 				       struct l2cap_cmd_hdr *cmd, u16 cmd_len,
4284cb3b3152SJohan Hedberg 				       u8 *data)
42850a708f8fSGustavo F. Padovan {
42860a708f8fSGustavo F. Padovan 	struct l2cap_disconn_rsp *rsp = (struct l2cap_disconn_rsp *) data;
42870a708f8fSGustavo F. Padovan 	u16 dcid, scid;
428848454079SGustavo F. Padovan 	struct l2cap_chan *chan;
42890a708f8fSGustavo F. Padovan 
4290cb3b3152SJohan Hedberg 	if (cmd_len != sizeof(*rsp))
4291cb3b3152SJohan Hedberg 		return -EPROTO;
4292cb3b3152SJohan Hedberg 
42930a708f8fSGustavo F. Padovan 	scid = __le16_to_cpu(rsp->scid);
42940a708f8fSGustavo F. Padovan 	dcid = __le16_to_cpu(rsp->dcid);
42950a708f8fSGustavo F. Padovan 
42960a708f8fSGustavo F. Padovan 	BT_DBG("dcid 0x%4.4x scid 0x%4.4x", dcid, scid);
42970a708f8fSGustavo F. Padovan 
42983df91ea2SAndrei Emeltchenko 	mutex_lock(&conn->chan_lock);
42993df91ea2SAndrei Emeltchenko 
43003df91ea2SAndrei Emeltchenko 	chan = __l2cap_get_chan_by_scid(conn, scid);
43013df91ea2SAndrei Emeltchenko 	if (!chan) {
43023df91ea2SAndrei Emeltchenko 		mutex_unlock(&conn->chan_lock);
43030a708f8fSGustavo F. Padovan 		return 0;
43043df91ea2SAndrei Emeltchenko 	}
43050a708f8fSGustavo F. Padovan 
43066be36555SAndrei Emeltchenko 	l2cap_chan_lock(chan);
430748454079SGustavo F. Padovan 
430861d6ef3eSMat Martineau 	l2cap_chan_hold(chan);
430948454079SGustavo F. Padovan 	l2cap_chan_del(chan, 0);
43106be36555SAndrei Emeltchenko 
43116be36555SAndrei Emeltchenko 	l2cap_chan_unlock(chan);
43120a708f8fSGustavo F. Padovan 
431380b98027SGustavo Padovan 	chan->ops->close(chan);
431461d6ef3eSMat Martineau 	l2cap_chan_put(chan);
43153df91ea2SAndrei Emeltchenko 
43163df91ea2SAndrei Emeltchenko 	mutex_unlock(&conn->chan_lock);
43173df91ea2SAndrei Emeltchenko 
43180a708f8fSGustavo F. Padovan 	return 0;
43190a708f8fSGustavo F. Padovan }
43200a708f8fSGustavo F. Padovan 
43212d792818SGustavo Padovan static inline int l2cap_information_req(struct l2cap_conn *conn,
4322cb3b3152SJohan Hedberg 					struct l2cap_cmd_hdr *cmd, u16 cmd_len,
4323cb3b3152SJohan Hedberg 					u8 *data)
43240a708f8fSGustavo F. Padovan {
43250a708f8fSGustavo F. Padovan 	struct l2cap_info_req *req = (struct l2cap_info_req *) data;
43260a708f8fSGustavo F. Padovan 	u16 type;
43270a708f8fSGustavo F. Padovan 
4328cb3b3152SJohan Hedberg 	if (cmd_len != sizeof(*req))
4329cb3b3152SJohan Hedberg 		return -EPROTO;
4330cb3b3152SJohan Hedberg 
43310a708f8fSGustavo F. Padovan 	type = __le16_to_cpu(req->type);
43320a708f8fSGustavo F. Padovan 
43330a708f8fSGustavo F. Padovan 	BT_DBG("type 0x%4.4x", type);
43340a708f8fSGustavo F. Padovan 
43350a708f8fSGustavo F. Padovan 	if (type == L2CAP_IT_FEAT_MASK) {
43360a708f8fSGustavo F. Padovan 		u8 buf[8];
43370a708f8fSGustavo F. Padovan 		u32 feat_mask = l2cap_feat_mask;
43380a708f8fSGustavo F. Padovan 		struct l2cap_info_rsp *rsp = (struct l2cap_info_rsp *) buf;
4339ac73498cSAndrei Emeltchenko 		rsp->type   = __constant_cpu_to_le16(L2CAP_IT_FEAT_MASK);
4340ac73498cSAndrei Emeltchenko 		rsp->result = __constant_cpu_to_le16(L2CAP_IR_SUCCESS);
43410a708f8fSGustavo F. Padovan 		if (!disable_ertm)
43420a708f8fSGustavo F. Padovan 			feat_mask |= L2CAP_FEAT_ERTM | L2CAP_FEAT_STREAMING
43430a708f8fSGustavo F. Padovan 				| L2CAP_FEAT_FCS;
4344848566b3SMarcel Holtmann 		if (conn->hs_enabled)
43456327eb98SAndrei Emeltchenko 			feat_mask |= L2CAP_FEAT_EXT_FLOW
43466327eb98SAndrei Emeltchenko 				| L2CAP_FEAT_EXT_WINDOW;
4347a5fd6f30SAndrei Emeltchenko 
43480a708f8fSGustavo F. Padovan 		put_unaligned_le32(feat_mask, rsp->data);
43492d792818SGustavo Padovan 		l2cap_send_cmd(conn, cmd->ident, L2CAP_INFO_RSP, sizeof(buf),
43502d792818SGustavo Padovan 			       buf);
43510a708f8fSGustavo F. Padovan 	} else if (type == L2CAP_IT_FIXED_CHAN) {
43520a708f8fSGustavo F. Padovan 		u8 buf[12];
43530a708f8fSGustavo F. Padovan 		struct l2cap_info_rsp *rsp = (struct l2cap_info_rsp *) buf;
435450a147cdSMat Martineau 
4355848566b3SMarcel Holtmann 		if (conn->hs_enabled)
435650a147cdSMat Martineau 			l2cap_fixed_chan[0] |= L2CAP_FC_A2MP;
435750a147cdSMat Martineau 		else
435850a147cdSMat Martineau 			l2cap_fixed_chan[0] &= ~L2CAP_FC_A2MP;
435950a147cdSMat Martineau 
4360ac73498cSAndrei Emeltchenko 		rsp->type   = __constant_cpu_to_le16(L2CAP_IT_FIXED_CHAN);
4361ac73498cSAndrei Emeltchenko 		rsp->result = __constant_cpu_to_le16(L2CAP_IR_SUCCESS);
4362c6337ea6SAndrei Emeltchenko 		memcpy(rsp->data, l2cap_fixed_chan, sizeof(l2cap_fixed_chan));
43632d792818SGustavo Padovan 		l2cap_send_cmd(conn, cmd->ident, L2CAP_INFO_RSP, sizeof(buf),
43642d792818SGustavo Padovan 			       buf);
43650a708f8fSGustavo F. Padovan 	} else {
43660a708f8fSGustavo F. Padovan 		struct l2cap_info_rsp rsp;
43670a708f8fSGustavo F. Padovan 		rsp.type   = cpu_to_le16(type);
4368ac73498cSAndrei Emeltchenko 		rsp.result = __constant_cpu_to_le16(L2CAP_IR_NOTSUPP);
43692d792818SGustavo Padovan 		l2cap_send_cmd(conn, cmd->ident, L2CAP_INFO_RSP, sizeof(rsp),
43702d792818SGustavo Padovan 			       &rsp);
43710a708f8fSGustavo F. Padovan 	}
43720a708f8fSGustavo F. Padovan 
43730a708f8fSGustavo F. Padovan 	return 0;
43740a708f8fSGustavo F. Padovan }
43750a708f8fSGustavo F. Padovan 
43762d792818SGustavo Padovan static inline int l2cap_information_rsp(struct l2cap_conn *conn,
4377cb3b3152SJohan Hedberg 					struct l2cap_cmd_hdr *cmd, u16 cmd_len,
4378cb3b3152SJohan Hedberg 					u8 *data)
43790a708f8fSGustavo F. Padovan {
43800a708f8fSGustavo F. Padovan 	struct l2cap_info_rsp *rsp = (struct l2cap_info_rsp *) data;
43810a708f8fSGustavo F. Padovan 	u16 type, result;
43820a708f8fSGustavo F. Padovan 
43833f6fa3d4SJaganath Kanakkassery 	if (cmd_len < sizeof(*rsp))
4384cb3b3152SJohan Hedberg 		return -EPROTO;
4385cb3b3152SJohan Hedberg 
43860a708f8fSGustavo F. Padovan 	type   = __le16_to_cpu(rsp->type);
43870a708f8fSGustavo F. Padovan 	result = __le16_to_cpu(rsp->result);
43880a708f8fSGustavo F. Padovan 
43890a708f8fSGustavo F. Padovan 	BT_DBG("type 0x%4.4x result 0x%2.2x", type, result);
43900a708f8fSGustavo F. Padovan 
4391e90165beSAndrei Emeltchenko 	/* L2CAP Info req/rsp are unbound to channels, add extra checks */
4392e90165beSAndrei Emeltchenko 	if (cmd->ident != conn->info_ident ||
4393e90165beSAndrei Emeltchenko 	    conn->info_state & L2CAP_INFO_FEAT_MASK_REQ_DONE)
4394e90165beSAndrei Emeltchenko 		return 0;
4395e90165beSAndrei Emeltchenko 
439617cd3f37SUlisses Furquim 	cancel_delayed_work(&conn->info_timer);
43970a708f8fSGustavo F. Padovan 
43980a708f8fSGustavo F. Padovan 	if (result != L2CAP_IR_SUCCESS) {
43990a708f8fSGustavo F. Padovan 		conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_DONE;
44000a708f8fSGustavo F. Padovan 		conn->info_ident = 0;
44010a708f8fSGustavo F. Padovan 
44020a708f8fSGustavo F. Padovan 		l2cap_conn_start(conn);
44030a708f8fSGustavo F. Padovan 
44040a708f8fSGustavo F. Padovan 		return 0;
44050a708f8fSGustavo F. Padovan 	}
44060a708f8fSGustavo F. Padovan 
4407978c93b9SAndrei Emeltchenko 	switch (type) {
4408978c93b9SAndrei Emeltchenko 	case L2CAP_IT_FEAT_MASK:
44090a708f8fSGustavo F. Padovan 		conn->feat_mask = get_unaligned_le32(rsp->data);
44100a708f8fSGustavo F. Padovan 
44110a708f8fSGustavo F. Padovan 		if (conn->feat_mask & L2CAP_FEAT_FIXED_CHAN) {
44120a708f8fSGustavo F. Padovan 			struct l2cap_info_req req;
4413ac73498cSAndrei Emeltchenko 			req.type = __constant_cpu_to_le16(L2CAP_IT_FIXED_CHAN);
44140a708f8fSGustavo F. Padovan 
44150a708f8fSGustavo F. Padovan 			conn->info_ident = l2cap_get_ident(conn);
44160a708f8fSGustavo F. Padovan 
44170a708f8fSGustavo F. Padovan 			l2cap_send_cmd(conn, conn->info_ident,
44180a708f8fSGustavo F. Padovan 				       L2CAP_INFO_REQ, sizeof(req), &req);
44190a708f8fSGustavo F. Padovan 		} else {
44200a708f8fSGustavo F. Padovan 			conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_DONE;
44210a708f8fSGustavo F. Padovan 			conn->info_ident = 0;
44220a708f8fSGustavo F. Padovan 
44230a708f8fSGustavo F. Padovan 			l2cap_conn_start(conn);
44240a708f8fSGustavo F. Padovan 		}
4425978c93b9SAndrei Emeltchenko 		break;
4426978c93b9SAndrei Emeltchenko 
4427978c93b9SAndrei Emeltchenko 	case L2CAP_IT_FIXED_CHAN:
4428978c93b9SAndrei Emeltchenko 		conn->fixed_chan_mask = rsp->data[0];
44290a708f8fSGustavo F. Padovan 		conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_DONE;
44300a708f8fSGustavo F. Padovan 		conn->info_ident = 0;
44310a708f8fSGustavo F. Padovan 
44320a708f8fSGustavo F. Padovan 		l2cap_conn_start(conn);
4433978c93b9SAndrei Emeltchenko 		break;
44340a708f8fSGustavo F. Padovan 	}
44350a708f8fSGustavo F. Padovan 
44360a708f8fSGustavo F. Padovan 	return 0;
44370a708f8fSGustavo F. Padovan }
44380a708f8fSGustavo F. Padovan 
44391700915fSMat Martineau static int l2cap_create_channel_req(struct l2cap_conn *conn,
44402d792818SGustavo Padovan 				    struct l2cap_cmd_hdr *cmd,
44412d792818SGustavo Padovan 				    u16 cmd_len, void *data)
4442f94ff6ffSMat Martineau {
4443f94ff6ffSMat Martineau 	struct l2cap_create_chan_req *req = data;
44446e1df6a6SAndrei Emeltchenko 	struct l2cap_create_chan_rsp rsp;
44451700915fSMat Martineau 	struct l2cap_chan *chan;
44466e1df6a6SAndrei Emeltchenko 	struct hci_dev *hdev;
4447f94ff6ffSMat Martineau 	u16 psm, scid;
4448f94ff6ffSMat Martineau 
4449f94ff6ffSMat Martineau 	if (cmd_len != sizeof(*req))
4450f94ff6ffSMat Martineau 		return -EPROTO;
4451f94ff6ffSMat Martineau 
4452848566b3SMarcel Holtmann 	if (!conn->hs_enabled)
4453f94ff6ffSMat Martineau 		return -EINVAL;
4454f94ff6ffSMat Martineau 
4455f94ff6ffSMat Martineau 	psm = le16_to_cpu(req->psm);
4456f94ff6ffSMat Martineau 	scid = le16_to_cpu(req->scid);
4457f94ff6ffSMat Martineau 
4458ad0ac6caSAndrei Emeltchenko 	BT_DBG("psm 0x%2.2x, scid 0x%4.4x, amp_id %d", psm, scid, req->amp_id);
4459f94ff6ffSMat Martineau 
44606e1df6a6SAndrei Emeltchenko 	/* For controller id 0 make BR/EDR connection */
44616ed971caSMarcel Holtmann 	if (req->amp_id == AMP_ID_BREDR) {
44626e1df6a6SAndrei Emeltchenko 		l2cap_connect(conn, cmd, data, L2CAP_CREATE_CHAN_RSP,
44636e1df6a6SAndrei Emeltchenko 			      req->amp_id);
44646e1df6a6SAndrei Emeltchenko 		return 0;
44656e1df6a6SAndrei Emeltchenko 	}
44661700915fSMat Martineau 
44671700915fSMat Martineau 	/* Validate AMP controller id */
44681700915fSMat Martineau 	hdev = hci_dev_get(req->amp_id);
44696e1df6a6SAndrei Emeltchenko 	if (!hdev)
44706e1df6a6SAndrei Emeltchenko 		goto error;
44711700915fSMat Martineau 
44726e1df6a6SAndrei Emeltchenko 	if (hdev->dev_type != HCI_AMP || !test_bit(HCI_UP, &hdev->flags)) {
44736e1df6a6SAndrei Emeltchenko 		hci_dev_put(hdev);
44746e1df6a6SAndrei Emeltchenko 		goto error;
44756e1df6a6SAndrei Emeltchenko 	}
44766e1df6a6SAndrei Emeltchenko 
44776e1df6a6SAndrei Emeltchenko 	chan = l2cap_connect(conn, cmd, data, L2CAP_CREATE_CHAN_RSP,
44786e1df6a6SAndrei Emeltchenko 			     req->amp_id);
44796e1df6a6SAndrei Emeltchenko 	if (chan) {
44806e1df6a6SAndrei Emeltchenko 		struct amp_mgr *mgr = conn->hcon->amp_mgr;
44816e1df6a6SAndrei Emeltchenko 		struct hci_conn *hs_hcon;
44826e1df6a6SAndrei Emeltchenko 
448398e0f7eaSMarcel Holtmann 		hs_hcon = hci_conn_hash_lookup_ba(hdev, AMP_LINK,
448498e0f7eaSMarcel Holtmann 						  &conn->hcon->dst);
44856e1df6a6SAndrei Emeltchenko 		if (!hs_hcon) {
44866e1df6a6SAndrei Emeltchenko 			hci_dev_put(hdev);
448721870b52SJohan Hedberg 			return -EBADSLT;
44886e1df6a6SAndrei Emeltchenko 		}
44896e1df6a6SAndrei Emeltchenko 
44906e1df6a6SAndrei Emeltchenko 		BT_DBG("mgr %p bredr_chan %p hs_hcon %p", mgr, chan, hs_hcon);
44916e1df6a6SAndrei Emeltchenko 
44926e1df6a6SAndrei Emeltchenko 		mgr->bredr_chan = chan;
44936e1df6a6SAndrei Emeltchenko 		chan->hs_hcon = hs_hcon;
4494fd45bf4cSAndrei Emeltchenko 		chan->fcs = L2CAP_FCS_NONE;
44956e1df6a6SAndrei Emeltchenko 		conn->mtu = hdev->block_mtu;
44966e1df6a6SAndrei Emeltchenko 	}
44976e1df6a6SAndrei Emeltchenko 
44986e1df6a6SAndrei Emeltchenko 	hci_dev_put(hdev);
44996e1df6a6SAndrei Emeltchenko 
45006e1df6a6SAndrei Emeltchenko 	return 0;
45016e1df6a6SAndrei Emeltchenko 
45026e1df6a6SAndrei Emeltchenko error:
4503f94ff6ffSMat Martineau 	rsp.dcid = 0;
4504f94ff6ffSMat Martineau 	rsp.scid = cpu_to_le16(scid);
45051700915fSMat Martineau 	rsp.result = __constant_cpu_to_le16(L2CAP_CR_BAD_AMP);
45068ce0c498SAndrei Emeltchenko 	rsp.status = __constant_cpu_to_le16(L2CAP_CS_NO_INFO);
4507f94ff6ffSMat Martineau 
4508f94ff6ffSMat Martineau 	l2cap_send_cmd(conn, cmd->ident, L2CAP_CREATE_CHAN_RSP,
4509f94ff6ffSMat Martineau 		       sizeof(rsp), &rsp);
4510f94ff6ffSMat Martineau 
4511dc280801SJohan Hedberg 	return 0;
4512f94ff6ffSMat Martineau }
4513f94ff6ffSMat Martineau 
45148eb200bdSMat Martineau static void l2cap_send_move_chan_req(struct l2cap_chan *chan, u8 dest_amp_id)
45158eb200bdSMat Martineau {
45168eb200bdSMat Martineau 	struct l2cap_move_chan_req req;
45178eb200bdSMat Martineau 	u8 ident;
45188eb200bdSMat Martineau 
45198eb200bdSMat Martineau 	BT_DBG("chan %p, dest_amp_id %d", chan, dest_amp_id);
45208eb200bdSMat Martineau 
45218eb200bdSMat Martineau 	ident = l2cap_get_ident(chan->conn);
45228eb200bdSMat Martineau 	chan->ident = ident;
45238eb200bdSMat Martineau 
45248eb200bdSMat Martineau 	req.icid = cpu_to_le16(chan->scid);
45258eb200bdSMat Martineau 	req.dest_amp_id = dest_amp_id;
45268eb200bdSMat Martineau 
45278eb200bdSMat Martineau 	l2cap_send_cmd(chan->conn, ident, L2CAP_MOVE_CHAN_REQ, sizeof(req),
45288eb200bdSMat Martineau 		       &req);
45298eb200bdSMat Martineau 
45308eb200bdSMat Martineau 	__set_chan_timer(chan, L2CAP_MOVE_TIMEOUT);
45318eb200bdSMat Martineau }
45328eb200bdSMat Martineau 
45331500109bSMat Martineau static void l2cap_send_move_chan_rsp(struct l2cap_chan *chan, u16 result)
45348d5a04a1SMat Martineau {
45358d5a04a1SMat Martineau 	struct l2cap_move_chan_rsp rsp;
45368d5a04a1SMat Martineau 
45371500109bSMat Martineau 	BT_DBG("chan %p, result 0x%4.4x", chan, result);
45388d5a04a1SMat Martineau 
45391500109bSMat Martineau 	rsp.icid = cpu_to_le16(chan->dcid);
45408d5a04a1SMat Martineau 	rsp.result = cpu_to_le16(result);
45418d5a04a1SMat Martineau 
45421500109bSMat Martineau 	l2cap_send_cmd(chan->conn, chan->ident, L2CAP_MOVE_CHAN_RSP,
45431500109bSMat Martineau 		       sizeof(rsp), &rsp);
45448d5a04a1SMat Martineau }
45458d5a04a1SMat Martineau 
45465b155ef9SMat Martineau static void l2cap_send_move_chan_cfm(struct l2cap_chan *chan, u16 result)
45478d5a04a1SMat Martineau {
45488d5a04a1SMat Martineau 	struct l2cap_move_chan_cfm cfm;
45498d5a04a1SMat Martineau 
45505b155ef9SMat Martineau 	BT_DBG("chan %p, result 0x%4.4x", chan, result);
45518d5a04a1SMat Martineau 
45525b155ef9SMat Martineau 	chan->ident = l2cap_get_ident(chan->conn);
45538d5a04a1SMat Martineau 
45545b155ef9SMat Martineau 	cfm.icid = cpu_to_le16(chan->scid);
45558d5a04a1SMat Martineau 	cfm.result = cpu_to_le16(result);
45568d5a04a1SMat Martineau 
45575b155ef9SMat Martineau 	l2cap_send_cmd(chan->conn, chan->ident, L2CAP_MOVE_CHAN_CFM,
45585b155ef9SMat Martineau 		       sizeof(cfm), &cfm);
45595b155ef9SMat Martineau 
45605b155ef9SMat Martineau 	__set_chan_timer(chan, L2CAP_MOVE_TIMEOUT);
45615b155ef9SMat Martineau }
45625b155ef9SMat Martineau 
45635b155ef9SMat Martineau static void l2cap_send_move_chan_cfm_icid(struct l2cap_conn *conn, u16 icid)
45645b155ef9SMat Martineau {
45655b155ef9SMat Martineau 	struct l2cap_move_chan_cfm cfm;
45665b155ef9SMat Martineau 
45675b155ef9SMat Martineau 	BT_DBG("conn %p, icid 0x%4.4x", conn, icid);
45685b155ef9SMat Martineau 
45695b155ef9SMat Martineau 	cfm.icid = cpu_to_le16(icid);
45705b155ef9SMat Martineau 	cfm.result = __constant_cpu_to_le16(L2CAP_MC_UNCONFIRMED);
45715b155ef9SMat Martineau 
45725b155ef9SMat Martineau 	l2cap_send_cmd(conn, l2cap_get_ident(conn), L2CAP_MOVE_CHAN_CFM,
45735b155ef9SMat Martineau 		       sizeof(cfm), &cfm);
45748d5a04a1SMat Martineau }
45758d5a04a1SMat Martineau 
45768d5a04a1SMat Martineau static void l2cap_send_move_chan_cfm_rsp(struct l2cap_conn *conn, u8 ident,
45778d5a04a1SMat Martineau 					 u16 icid)
45788d5a04a1SMat Martineau {
45798d5a04a1SMat Martineau 	struct l2cap_move_chan_cfm_rsp rsp;
45808d5a04a1SMat Martineau 
4581ad0ac6caSAndrei Emeltchenko 	BT_DBG("icid 0x%4.4x", icid);
45828d5a04a1SMat Martineau 
45838d5a04a1SMat Martineau 	rsp.icid = cpu_to_le16(icid);
45848d5a04a1SMat Martineau 	l2cap_send_cmd(conn, ident, L2CAP_MOVE_CHAN_CFM_RSP, sizeof(rsp), &rsp);
45858d5a04a1SMat Martineau }
45868d5a04a1SMat Martineau 
45875f3847a4SMat Martineau static void __release_logical_link(struct l2cap_chan *chan)
45885f3847a4SMat Martineau {
45895f3847a4SMat Martineau 	chan->hs_hchan = NULL;
45905f3847a4SMat Martineau 	chan->hs_hcon = NULL;
45915f3847a4SMat Martineau 
45925f3847a4SMat Martineau 	/* Placeholder - release the logical link */
45935f3847a4SMat Martineau }
45945f3847a4SMat Martineau 
45951500109bSMat Martineau static void l2cap_logical_fail(struct l2cap_chan *chan)
45961500109bSMat Martineau {
45971500109bSMat Martineau 	/* Logical link setup failed */
45981500109bSMat Martineau 	if (chan->state != BT_CONNECTED) {
45991500109bSMat Martineau 		/* Create channel failure, disconnect */
46005e4e3972SAndrei Emeltchenko 		l2cap_send_disconn_req(chan, ECONNRESET);
46011500109bSMat Martineau 		return;
46021500109bSMat Martineau 	}
46031500109bSMat Martineau 
46041500109bSMat Martineau 	switch (chan->move_role) {
46051500109bSMat Martineau 	case L2CAP_MOVE_ROLE_RESPONDER:
46061500109bSMat Martineau 		l2cap_move_done(chan);
46071500109bSMat Martineau 		l2cap_send_move_chan_rsp(chan, L2CAP_MR_NOT_SUPP);
46081500109bSMat Martineau 		break;
46091500109bSMat Martineau 	case L2CAP_MOVE_ROLE_INITIATOR:
46101500109bSMat Martineau 		if (chan->move_state == L2CAP_MOVE_WAIT_LOGICAL_COMP ||
46111500109bSMat Martineau 		    chan->move_state == L2CAP_MOVE_WAIT_LOGICAL_CFM) {
46121500109bSMat Martineau 			/* Remote has only sent pending or
46131500109bSMat Martineau 			 * success responses, clean up
46141500109bSMat Martineau 			 */
46151500109bSMat Martineau 			l2cap_move_done(chan);
46161500109bSMat Martineau 		}
46171500109bSMat Martineau 
46181500109bSMat Martineau 		/* Other amp move states imply that the move
46191500109bSMat Martineau 		 * has already aborted
46201500109bSMat Martineau 		 */
46211500109bSMat Martineau 		l2cap_send_move_chan_cfm(chan, L2CAP_MC_UNCONFIRMED);
46221500109bSMat Martineau 		break;
46231500109bSMat Martineau 	}
46241500109bSMat Martineau }
46251500109bSMat Martineau 
46261500109bSMat Martineau static void l2cap_logical_finish_create(struct l2cap_chan *chan,
46271500109bSMat Martineau 					struct hci_chan *hchan)
46281500109bSMat Martineau {
46291500109bSMat Martineau 	struct l2cap_conf_rsp rsp;
46301500109bSMat Martineau 
4631336178a3SAndrei Emeltchenko 	chan->hs_hchan = hchan;
46321500109bSMat Martineau 	chan->hs_hcon->l2cap_data = chan->conn;
46331500109bSMat Martineau 
463435ba9561SAndrei Emeltchenko 	l2cap_send_efs_conf_rsp(chan, &rsp, chan->ident, 0);
46351500109bSMat Martineau 
46361500109bSMat Martineau 	if (test_bit(CONF_INPUT_DONE, &chan->conf_state)) {
4637fe79c6feSAndrei Emeltchenko 		int err;
46381500109bSMat Martineau 
46391500109bSMat Martineau 		set_default_fcs(chan);
46401500109bSMat Martineau 
46411500109bSMat Martineau 		err = l2cap_ertm_init(chan);
46421500109bSMat Martineau 		if (err < 0)
46435e4e3972SAndrei Emeltchenko 			l2cap_send_disconn_req(chan, -err);
46441500109bSMat Martineau 		else
46451500109bSMat Martineau 			l2cap_chan_ready(chan);
46461500109bSMat Martineau 	}
46471500109bSMat Martineau }
46481500109bSMat Martineau 
46491500109bSMat Martineau static void l2cap_logical_finish_move(struct l2cap_chan *chan,
46501500109bSMat Martineau 				      struct hci_chan *hchan)
46511500109bSMat Martineau {
46521500109bSMat Martineau 	chan->hs_hcon = hchan->conn;
46531500109bSMat Martineau 	chan->hs_hcon->l2cap_data = chan->conn;
46541500109bSMat Martineau 
46551500109bSMat Martineau 	BT_DBG("move_state %d", chan->move_state);
46561500109bSMat Martineau 
46571500109bSMat Martineau 	switch (chan->move_state) {
46581500109bSMat Martineau 	case L2CAP_MOVE_WAIT_LOGICAL_COMP:
46591500109bSMat Martineau 		/* Move confirm will be sent after a success
46601500109bSMat Martineau 		 * response is received
46611500109bSMat Martineau 		 */
46621500109bSMat Martineau 		chan->move_state = L2CAP_MOVE_WAIT_RSP_SUCCESS;
46631500109bSMat Martineau 		break;
46641500109bSMat Martineau 	case L2CAP_MOVE_WAIT_LOGICAL_CFM:
46651500109bSMat Martineau 		if (test_bit(CONN_LOCAL_BUSY, &chan->conn_state)) {
46661500109bSMat Martineau 			chan->move_state = L2CAP_MOVE_WAIT_LOCAL_BUSY;
46671500109bSMat Martineau 		} else if (chan->move_role == L2CAP_MOVE_ROLE_INITIATOR) {
46681500109bSMat Martineau 			chan->move_state = L2CAP_MOVE_WAIT_CONFIRM_RSP;
46691500109bSMat Martineau 			l2cap_send_move_chan_cfm(chan, L2CAP_MC_CONFIRMED);
46701500109bSMat Martineau 		} else if (chan->move_role == L2CAP_MOVE_ROLE_RESPONDER) {
46711500109bSMat Martineau 			chan->move_state = L2CAP_MOVE_WAIT_CONFIRM;
46721500109bSMat Martineau 			l2cap_send_move_chan_rsp(chan, L2CAP_MR_SUCCESS);
46731500109bSMat Martineau 		}
46741500109bSMat Martineau 		break;
46751500109bSMat Martineau 	default:
46761500109bSMat Martineau 		/* Move was not in expected state, free the channel */
46771500109bSMat Martineau 		__release_logical_link(chan);
46781500109bSMat Martineau 
46791500109bSMat Martineau 		chan->move_state = L2CAP_MOVE_STABLE;
46801500109bSMat Martineau 	}
46811500109bSMat Martineau }
46821500109bSMat Martineau 
46831500109bSMat Martineau /* Call with chan locked */
468427695fb4SAndrei Emeltchenko void l2cap_logical_cfm(struct l2cap_chan *chan, struct hci_chan *hchan,
46855b155ef9SMat Martineau 		       u8 status)
46865b155ef9SMat Martineau {
46871500109bSMat Martineau 	BT_DBG("chan %p, hchan %p, status %d", chan, hchan, status);
46881500109bSMat Martineau 
46891500109bSMat Martineau 	if (status) {
46901500109bSMat Martineau 		l2cap_logical_fail(chan);
46911500109bSMat Martineau 		__release_logical_link(chan);
46925b155ef9SMat Martineau 		return;
46935b155ef9SMat Martineau 	}
46945b155ef9SMat Martineau 
46951500109bSMat Martineau 	if (chan->state != BT_CONNECTED) {
46961500109bSMat Martineau 		/* Ignore logical link if channel is on BR/EDR */
46976ed971caSMarcel Holtmann 		if (chan->local_amp_id != AMP_ID_BREDR)
46981500109bSMat Martineau 			l2cap_logical_finish_create(chan, hchan);
46991500109bSMat Martineau 	} else {
47001500109bSMat Martineau 		l2cap_logical_finish_move(chan, hchan);
47011500109bSMat Martineau 	}
47021500109bSMat Martineau }
47031500109bSMat Martineau 
47043f7a56c4SMat Martineau void l2cap_move_start(struct l2cap_chan *chan)
47053f7a56c4SMat Martineau {
47063f7a56c4SMat Martineau 	BT_DBG("chan %p", chan);
47073f7a56c4SMat Martineau 
47086ed971caSMarcel Holtmann 	if (chan->local_amp_id == AMP_ID_BREDR) {
47093f7a56c4SMat Martineau 		if (chan->chan_policy != BT_CHANNEL_POLICY_AMP_PREFERRED)
47103f7a56c4SMat Martineau 			return;
47113f7a56c4SMat Martineau 		chan->move_role = L2CAP_MOVE_ROLE_INITIATOR;
47123f7a56c4SMat Martineau 		chan->move_state = L2CAP_MOVE_WAIT_PREPARE;
47133f7a56c4SMat Martineau 		/* Placeholder - start physical link setup */
47143f7a56c4SMat Martineau 	} else {
47153f7a56c4SMat Martineau 		chan->move_role = L2CAP_MOVE_ROLE_INITIATOR;
47163f7a56c4SMat Martineau 		chan->move_state = L2CAP_MOVE_WAIT_RSP_SUCCESS;
47173f7a56c4SMat Martineau 		chan->move_id = 0;
47183f7a56c4SMat Martineau 		l2cap_move_setup(chan);
47193f7a56c4SMat Martineau 		l2cap_send_move_chan_req(chan, 0);
47203f7a56c4SMat Martineau 	}
47213f7a56c4SMat Martineau }
47223f7a56c4SMat Martineau 
47238eb200bdSMat Martineau static void l2cap_do_create(struct l2cap_chan *chan, int result,
47248eb200bdSMat Martineau 			    u8 local_amp_id, u8 remote_amp_id)
47258eb200bdSMat Martineau {
472662748ca1SAndrei Emeltchenko 	BT_DBG("chan %p state %s %u -> %u", chan, state_to_string(chan->state),
472762748ca1SAndrei Emeltchenko 	       local_amp_id, remote_amp_id);
472862748ca1SAndrei Emeltchenko 
472912d6cc60SAndrei Emeltchenko 	chan->fcs = L2CAP_FCS_NONE;
473012d6cc60SAndrei Emeltchenko 
473162748ca1SAndrei Emeltchenko 	/* Outgoing channel on AMP */
473262748ca1SAndrei Emeltchenko 	if (chan->state == BT_CONNECT) {
473362748ca1SAndrei Emeltchenko 		if (result == L2CAP_CR_SUCCESS) {
473462748ca1SAndrei Emeltchenko 			chan->local_amp_id = local_amp_id;
473562748ca1SAndrei Emeltchenko 			l2cap_send_create_chan_req(chan, remote_amp_id);
473662748ca1SAndrei Emeltchenko 		} else {
473762748ca1SAndrei Emeltchenko 			/* Revert to BR/EDR connect */
473862748ca1SAndrei Emeltchenko 			l2cap_send_conn_req(chan);
473962748ca1SAndrei Emeltchenko 		}
474062748ca1SAndrei Emeltchenko 
474162748ca1SAndrei Emeltchenko 		return;
474262748ca1SAndrei Emeltchenko 	}
474362748ca1SAndrei Emeltchenko 
474462748ca1SAndrei Emeltchenko 	/* Incoming channel on AMP */
474562748ca1SAndrei Emeltchenko 	if (__l2cap_no_conn_pending(chan)) {
47468eb200bdSMat Martineau 		struct l2cap_conn_rsp rsp;
47478eb200bdSMat Martineau 		char buf[128];
47488eb200bdSMat Martineau 		rsp.scid = cpu_to_le16(chan->dcid);
47498eb200bdSMat Martineau 		rsp.dcid = cpu_to_le16(chan->scid);
47508eb200bdSMat Martineau 
47518eb200bdSMat Martineau 		if (result == L2CAP_CR_SUCCESS) {
47528eb200bdSMat Martineau 			/* Send successful response */
475362cd50e2SAndrei Emeltchenko 			rsp.result = __constant_cpu_to_le16(L2CAP_CR_SUCCESS);
475462cd50e2SAndrei Emeltchenko 			rsp.status = __constant_cpu_to_le16(L2CAP_CS_NO_INFO);
47558eb200bdSMat Martineau 		} else {
47568eb200bdSMat Martineau 			/* Send negative response */
475762cd50e2SAndrei Emeltchenko 			rsp.result = __constant_cpu_to_le16(L2CAP_CR_NO_MEM);
475862cd50e2SAndrei Emeltchenko 			rsp.status = __constant_cpu_to_le16(L2CAP_CS_NO_INFO);
47598eb200bdSMat Martineau 		}
47608eb200bdSMat Martineau 
47618eb200bdSMat Martineau 		l2cap_send_cmd(chan->conn, chan->ident, L2CAP_CREATE_CHAN_RSP,
47628eb200bdSMat Martineau 			       sizeof(rsp), &rsp);
47638eb200bdSMat Martineau 
47648eb200bdSMat Martineau 		if (result == L2CAP_CR_SUCCESS) {
47658eb200bdSMat Martineau 			__l2cap_state_change(chan, BT_CONFIG);
47668eb200bdSMat Martineau 			set_bit(CONF_REQ_SENT, &chan->conf_state);
47678eb200bdSMat Martineau 			l2cap_send_cmd(chan->conn, l2cap_get_ident(chan->conn),
47688eb200bdSMat Martineau 				       L2CAP_CONF_REQ,
47698eb200bdSMat Martineau 				       l2cap_build_conf_req(chan, buf), buf);
47708eb200bdSMat Martineau 			chan->num_conf_req++;
47718eb200bdSMat Martineau 		}
47728eb200bdSMat Martineau 	}
47738eb200bdSMat Martineau }
47748eb200bdSMat Martineau 
47758eb200bdSMat Martineau static void l2cap_do_move_initiate(struct l2cap_chan *chan, u8 local_amp_id,
47768eb200bdSMat Martineau 				   u8 remote_amp_id)
47778eb200bdSMat Martineau {
47788eb200bdSMat Martineau 	l2cap_move_setup(chan);
47798eb200bdSMat Martineau 	chan->move_id = local_amp_id;
47808eb200bdSMat Martineau 	chan->move_state = L2CAP_MOVE_WAIT_RSP;
47818eb200bdSMat Martineau 
47828eb200bdSMat Martineau 	l2cap_send_move_chan_req(chan, remote_amp_id);
47838eb200bdSMat Martineau }
47848eb200bdSMat Martineau 
47858eb200bdSMat Martineau static void l2cap_do_move_respond(struct l2cap_chan *chan, int result)
47868eb200bdSMat Martineau {
47878eb200bdSMat Martineau 	struct hci_chan *hchan = NULL;
47888eb200bdSMat Martineau 
47898eb200bdSMat Martineau 	/* Placeholder - get hci_chan for logical link */
47908eb200bdSMat Martineau 
47918eb200bdSMat Martineau 	if (hchan) {
47928eb200bdSMat Martineau 		if (hchan->state == BT_CONNECTED) {
47938eb200bdSMat Martineau 			/* Logical link is ready to go */
47948eb200bdSMat Martineau 			chan->hs_hcon = hchan->conn;
47958eb200bdSMat Martineau 			chan->hs_hcon->l2cap_data = chan->conn;
47968eb200bdSMat Martineau 			chan->move_state = L2CAP_MOVE_WAIT_CONFIRM;
47978eb200bdSMat Martineau 			l2cap_send_move_chan_rsp(chan, L2CAP_MR_SUCCESS);
47988eb200bdSMat Martineau 
47998eb200bdSMat Martineau 			l2cap_logical_cfm(chan, hchan, L2CAP_MR_SUCCESS);
48008eb200bdSMat Martineau 		} else {
48018eb200bdSMat Martineau 			/* Wait for logical link to be ready */
48028eb200bdSMat Martineau 			chan->move_state = L2CAP_MOVE_WAIT_LOGICAL_CFM;
48038eb200bdSMat Martineau 		}
48048eb200bdSMat Martineau 	} else {
48058eb200bdSMat Martineau 		/* Logical link not available */
48068eb200bdSMat Martineau 		l2cap_send_move_chan_rsp(chan, L2CAP_MR_NOT_ALLOWED);
48078eb200bdSMat Martineau 	}
48088eb200bdSMat Martineau }
48098eb200bdSMat Martineau 
48108eb200bdSMat Martineau static void l2cap_do_move_cancel(struct l2cap_chan *chan, int result)
48118eb200bdSMat Martineau {
48128eb200bdSMat Martineau 	if (chan->move_role == L2CAP_MOVE_ROLE_RESPONDER) {
48138eb200bdSMat Martineau 		u8 rsp_result;
48148eb200bdSMat Martineau 		if (result == -EINVAL)
48158eb200bdSMat Martineau 			rsp_result = L2CAP_MR_BAD_ID;
48168eb200bdSMat Martineau 		else
48178eb200bdSMat Martineau 			rsp_result = L2CAP_MR_NOT_ALLOWED;
48188eb200bdSMat Martineau 
48198eb200bdSMat Martineau 		l2cap_send_move_chan_rsp(chan, rsp_result);
48208eb200bdSMat Martineau 	}
48218eb200bdSMat Martineau 
48228eb200bdSMat Martineau 	chan->move_role = L2CAP_MOVE_ROLE_NONE;
48238eb200bdSMat Martineau 	chan->move_state = L2CAP_MOVE_STABLE;
48248eb200bdSMat Martineau 
48258eb200bdSMat Martineau 	/* Restart data transmission */
48268eb200bdSMat Martineau 	l2cap_ertm_send(chan);
48278eb200bdSMat Martineau }
48288eb200bdSMat Martineau 
4829a514b17fSAndrei Emeltchenko /* Invoke with locked chan */
4830a514b17fSAndrei Emeltchenko void __l2cap_physical_cfm(struct l2cap_chan *chan, int result)
48318eb200bdSMat Martineau {
4832770bfefaSAndrei Emeltchenko 	u8 local_amp_id = chan->local_amp_id;
4833fffadc08SAndrei Emeltchenko 	u8 remote_amp_id = chan->remote_amp_id;
4834770bfefaSAndrei Emeltchenko 
48358eb200bdSMat Martineau 	BT_DBG("chan %p, result %d, local_amp_id %d, remote_amp_id %d",
48368eb200bdSMat Martineau 	       chan, result, local_amp_id, remote_amp_id);
48378eb200bdSMat Martineau 
48388eb200bdSMat Martineau 	if (chan->state == BT_DISCONN || chan->state == BT_CLOSED) {
48398eb200bdSMat Martineau 		l2cap_chan_unlock(chan);
48408eb200bdSMat Martineau 		return;
48418eb200bdSMat Martineau 	}
48428eb200bdSMat Martineau 
48438eb200bdSMat Martineau 	if (chan->state != BT_CONNECTED) {
48448eb200bdSMat Martineau 		l2cap_do_create(chan, result, local_amp_id, remote_amp_id);
48458eb200bdSMat Martineau 	} else if (result != L2CAP_MR_SUCCESS) {
48468eb200bdSMat Martineau 		l2cap_do_move_cancel(chan, result);
48478eb200bdSMat Martineau 	} else {
48488eb200bdSMat Martineau 		switch (chan->move_role) {
48498eb200bdSMat Martineau 		case L2CAP_MOVE_ROLE_INITIATOR:
48508eb200bdSMat Martineau 			l2cap_do_move_initiate(chan, local_amp_id,
48518eb200bdSMat Martineau 					       remote_amp_id);
48528eb200bdSMat Martineau 			break;
48538eb200bdSMat Martineau 		case L2CAP_MOVE_ROLE_RESPONDER:
48548eb200bdSMat Martineau 			l2cap_do_move_respond(chan, result);
48558eb200bdSMat Martineau 			break;
48568eb200bdSMat Martineau 		default:
48578eb200bdSMat Martineau 			l2cap_do_move_cancel(chan, result);
48588eb200bdSMat Martineau 			break;
48598eb200bdSMat Martineau 		}
48608eb200bdSMat Martineau 	}
48618eb200bdSMat Martineau }
48628eb200bdSMat Martineau 
48638d5a04a1SMat Martineau static inline int l2cap_move_channel_req(struct l2cap_conn *conn,
4864ad0ac6caSAndrei Emeltchenko 					 struct l2cap_cmd_hdr *cmd,
4865ad0ac6caSAndrei Emeltchenko 					 u16 cmd_len, void *data)
48668d5a04a1SMat Martineau {
48678d5a04a1SMat Martineau 	struct l2cap_move_chan_req *req = data;
48681500109bSMat Martineau 	struct l2cap_move_chan_rsp rsp;
486902b0fbb9SMat Martineau 	struct l2cap_chan *chan;
48708d5a04a1SMat Martineau 	u16 icid = 0;
48718d5a04a1SMat Martineau 	u16 result = L2CAP_MR_NOT_ALLOWED;
48728d5a04a1SMat Martineau 
48738d5a04a1SMat Martineau 	if (cmd_len != sizeof(*req))
48748d5a04a1SMat Martineau 		return -EPROTO;
48758d5a04a1SMat Martineau 
48768d5a04a1SMat Martineau 	icid = le16_to_cpu(req->icid);
48778d5a04a1SMat Martineau 
4878ad0ac6caSAndrei Emeltchenko 	BT_DBG("icid 0x%4.4x, dest_amp_id %d", icid, req->dest_amp_id);
48798d5a04a1SMat Martineau 
4880848566b3SMarcel Holtmann 	if (!conn->hs_enabled)
48818d5a04a1SMat Martineau 		return -EINVAL;
48828d5a04a1SMat Martineau 
488302b0fbb9SMat Martineau 	chan = l2cap_get_chan_by_dcid(conn, icid);
488402b0fbb9SMat Martineau 	if (!chan) {
48851500109bSMat Martineau 		rsp.icid = cpu_to_le16(icid);
48861500109bSMat Martineau 		rsp.result = __constant_cpu_to_le16(L2CAP_MR_NOT_ALLOWED);
48871500109bSMat Martineau 		l2cap_send_cmd(conn, cmd->ident, L2CAP_MOVE_CHAN_RSP,
48881500109bSMat Martineau 			       sizeof(rsp), &rsp);
488902b0fbb9SMat Martineau 		return 0;
489002b0fbb9SMat Martineau 	}
489102b0fbb9SMat Martineau 
48921500109bSMat Martineau 	chan->ident = cmd->ident;
48931500109bSMat Martineau 
489402b0fbb9SMat Martineau 	if (chan->scid < L2CAP_CID_DYN_START ||
489502b0fbb9SMat Martineau 	    chan->chan_policy == BT_CHANNEL_POLICY_BREDR_ONLY ||
489602b0fbb9SMat Martineau 	    (chan->mode != L2CAP_MODE_ERTM &&
489702b0fbb9SMat Martineau 	     chan->mode != L2CAP_MODE_STREAMING)) {
489802b0fbb9SMat Martineau 		result = L2CAP_MR_NOT_ALLOWED;
489902b0fbb9SMat Martineau 		goto send_move_response;
490002b0fbb9SMat Martineau 	}
490102b0fbb9SMat Martineau 
490202b0fbb9SMat Martineau 	if (chan->local_amp_id == req->dest_amp_id) {
490302b0fbb9SMat Martineau 		result = L2CAP_MR_SAME_ID;
490402b0fbb9SMat Martineau 		goto send_move_response;
490502b0fbb9SMat Martineau 	}
490602b0fbb9SMat Martineau 
49076ed971caSMarcel Holtmann 	if (req->dest_amp_id != AMP_ID_BREDR) {
490802b0fbb9SMat Martineau 		struct hci_dev *hdev;
490902b0fbb9SMat Martineau 		hdev = hci_dev_get(req->dest_amp_id);
491002b0fbb9SMat Martineau 		if (!hdev || hdev->dev_type != HCI_AMP ||
491102b0fbb9SMat Martineau 		    !test_bit(HCI_UP, &hdev->flags)) {
491202b0fbb9SMat Martineau 			if (hdev)
491302b0fbb9SMat Martineau 				hci_dev_put(hdev);
491402b0fbb9SMat Martineau 
491502b0fbb9SMat Martineau 			result = L2CAP_MR_BAD_ID;
491602b0fbb9SMat Martineau 			goto send_move_response;
491702b0fbb9SMat Martineau 		}
491802b0fbb9SMat Martineau 		hci_dev_put(hdev);
491902b0fbb9SMat Martineau 	}
492002b0fbb9SMat Martineau 
492102b0fbb9SMat Martineau 	/* Detect a move collision.  Only send a collision response
492202b0fbb9SMat Martineau 	 * if this side has "lost", otherwise proceed with the move.
492302b0fbb9SMat Martineau 	 * The winner has the larger bd_addr.
492402b0fbb9SMat Martineau 	 */
492502b0fbb9SMat Martineau 	if ((__chan_is_moving(chan) ||
492602b0fbb9SMat Martineau 	     chan->move_role != L2CAP_MOVE_ROLE_NONE) &&
49276f59b904SMarcel Holtmann 	    bacmp(&conn->hcon->src, &conn->hcon->dst) > 0) {
492802b0fbb9SMat Martineau 		result = L2CAP_MR_COLLISION;
492902b0fbb9SMat Martineau 		goto send_move_response;
493002b0fbb9SMat Martineau 	}
493102b0fbb9SMat Martineau 
493202b0fbb9SMat Martineau 	chan->move_role = L2CAP_MOVE_ROLE_RESPONDER;
493302b0fbb9SMat Martineau 	l2cap_move_setup(chan);
493402b0fbb9SMat Martineau 	chan->move_id = req->dest_amp_id;
493502b0fbb9SMat Martineau 	icid = chan->dcid;
493602b0fbb9SMat Martineau 
49376ed971caSMarcel Holtmann 	if (req->dest_amp_id == AMP_ID_BREDR) {
493802b0fbb9SMat Martineau 		/* Moving to BR/EDR */
493902b0fbb9SMat Martineau 		if (test_bit(CONN_LOCAL_BUSY, &chan->conn_state)) {
494002b0fbb9SMat Martineau 			chan->move_state = L2CAP_MOVE_WAIT_LOCAL_BUSY;
494102b0fbb9SMat Martineau 			result = L2CAP_MR_PEND;
494202b0fbb9SMat Martineau 		} else {
494302b0fbb9SMat Martineau 			chan->move_state = L2CAP_MOVE_WAIT_CONFIRM;
494402b0fbb9SMat Martineau 			result = L2CAP_MR_SUCCESS;
494502b0fbb9SMat Martineau 		}
494602b0fbb9SMat Martineau 	} else {
494702b0fbb9SMat Martineau 		chan->move_state = L2CAP_MOVE_WAIT_PREPARE;
494802b0fbb9SMat Martineau 		/* Placeholder - uncomment when amp functions are available */
494902b0fbb9SMat Martineau 		/*amp_accept_physical(chan, req->dest_amp_id);*/
495002b0fbb9SMat Martineau 		result = L2CAP_MR_PEND;
495102b0fbb9SMat Martineau 	}
495202b0fbb9SMat Martineau 
495302b0fbb9SMat Martineau send_move_response:
49541500109bSMat Martineau 	l2cap_send_move_chan_rsp(chan, result);
49558d5a04a1SMat Martineau 
495602b0fbb9SMat Martineau 	l2cap_chan_unlock(chan);
495702b0fbb9SMat Martineau 
49588d5a04a1SMat Martineau 	return 0;
49598d5a04a1SMat Martineau }
49608d5a04a1SMat Martineau 
49615b155ef9SMat Martineau static void l2cap_move_continue(struct l2cap_conn *conn, u16 icid, u16 result)
49625b155ef9SMat Martineau {
49635b155ef9SMat Martineau 	struct l2cap_chan *chan;
49645b155ef9SMat Martineau 	struct hci_chan *hchan = NULL;
49655b155ef9SMat Martineau 
49665b155ef9SMat Martineau 	chan = l2cap_get_chan_by_scid(conn, icid);
49675b155ef9SMat Martineau 	if (!chan) {
49685b155ef9SMat Martineau 		l2cap_send_move_chan_cfm_icid(conn, icid);
49695b155ef9SMat Martineau 		return;
49705b155ef9SMat Martineau 	}
49715b155ef9SMat Martineau 
49725b155ef9SMat Martineau 	__clear_chan_timer(chan);
49735b155ef9SMat Martineau 	if (result == L2CAP_MR_PEND)
49745b155ef9SMat Martineau 		__set_chan_timer(chan, L2CAP_MOVE_ERTX_TIMEOUT);
49755b155ef9SMat Martineau 
49765b155ef9SMat Martineau 	switch (chan->move_state) {
49775b155ef9SMat Martineau 	case L2CAP_MOVE_WAIT_LOGICAL_COMP:
49785b155ef9SMat Martineau 		/* Move confirm will be sent when logical link
49795b155ef9SMat Martineau 		 * is complete.
49805b155ef9SMat Martineau 		 */
49815b155ef9SMat Martineau 		chan->move_state = L2CAP_MOVE_WAIT_LOGICAL_CFM;
49825b155ef9SMat Martineau 		break;
49835b155ef9SMat Martineau 	case L2CAP_MOVE_WAIT_RSP_SUCCESS:
49845b155ef9SMat Martineau 		if (result == L2CAP_MR_PEND) {
49855b155ef9SMat Martineau 			break;
49865b155ef9SMat Martineau 		} else if (test_bit(CONN_LOCAL_BUSY,
49875b155ef9SMat Martineau 				    &chan->conn_state)) {
49885b155ef9SMat Martineau 			chan->move_state = L2CAP_MOVE_WAIT_LOCAL_BUSY;
49895b155ef9SMat Martineau 		} else {
49905b155ef9SMat Martineau 			/* Logical link is up or moving to BR/EDR,
49915b155ef9SMat Martineau 			 * proceed with move
49925b155ef9SMat Martineau 			 */
49935b155ef9SMat Martineau 			chan->move_state = L2CAP_MOVE_WAIT_CONFIRM_RSP;
49945b155ef9SMat Martineau 			l2cap_send_move_chan_cfm(chan, L2CAP_MC_CONFIRMED);
49955b155ef9SMat Martineau 		}
49965b155ef9SMat Martineau 		break;
49975b155ef9SMat Martineau 	case L2CAP_MOVE_WAIT_RSP:
49985b155ef9SMat Martineau 		/* Moving to AMP */
49995b155ef9SMat Martineau 		if (result == L2CAP_MR_SUCCESS) {
50005b155ef9SMat Martineau 			/* Remote is ready, send confirm immediately
50015b155ef9SMat Martineau 			 * after logical link is ready
50025b155ef9SMat Martineau 			 */
50035b155ef9SMat Martineau 			chan->move_state = L2CAP_MOVE_WAIT_LOGICAL_CFM;
50045b155ef9SMat Martineau 		} else {
50055b155ef9SMat Martineau 			/* Both logical link and move success
50065b155ef9SMat Martineau 			 * are required to confirm
50075b155ef9SMat Martineau 			 */
50085b155ef9SMat Martineau 			chan->move_state = L2CAP_MOVE_WAIT_LOGICAL_COMP;
50095b155ef9SMat Martineau 		}
50105b155ef9SMat Martineau 
50115b155ef9SMat Martineau 		/* Placeholder - get hci_chan for logical link */
50125b155ef9SMat Martineau 		if (!hchan) {
50135b155ef9SMat Martineau 			/* Logical link not available */
50145b155ef9SMat Martineau 			l2cap_send_move_chan_cfm(chan, L2CAP_MC_UNCONFIRMED);
50155b155ef9SMat Martineau 			break;
50165b155ef9SMat Martineau 		}
50175b155ef9SMat Martineau 
50185b155ef9SMat Martineau 		/* If the logical link is not yet connected, do not
50195b155ef9SMat Martineau 		 * send confirmation.
50205b155ef9SMat Martineau 		 */
50215b155ef9SMat Martineau 		if (hchan->state != BT_CONNECTED)
50225b155ef9SMat Martineau 			break;
50235b155ef9SMat Martineau 
50245b155ef9SMat Martineau 		/* Logical link is already ready to go */
50255b155ef9SMat Martineau 
50265b155ef9SMat Martineau 		chan->hs_hcon = hchan->conn;
50275b155ef9SMat Martineau 		chan->hs_hcon->l2cap_data = chan->conn;
50285b155ef9SMat Martineau 
50295b155ef9SMat Martineau 		if (result == L2CAP_MR_SUCCESS) {
50305b155ef9SMat Martineau 			/* Can confirm now */
50315b155ef9SMat Martineau 			l2cap_send_move_chan_cfm(chan, L2CAP_MC_CONFIRMED);
50325b155ef9SMat Martineau 		} else {
50335b155ef9SMat Martineau 			/* Now only need move success
50345b155ef9SMat Martineau 			 * to confirm
50355b155ef9SMat Martineau 			 */
50365b155ef9SMat Martineau 			chan->move_state = L2CAP_MOVE_WAIT_RSP_SUCCESS;
50375b155ef9SMat Martineau 		}
50385b155ef9SMat Martineau 
50395b155ef9SMat Martineau 		l2cap_logical_cfm(chan, hchan, L2CAP_MR_SUCCESS);
50405b155ef9SMat Martineau 		break;
50415b155ef9SMat Martineau 	default:
50425b155ef9SMat Martineau 		/* Any other amp move state means the move failed. */
50435b155ef9SMat Martineau 		chan->move_id = chan->local_amp_id;
50445b155ef9SMat Martineau 		l2cap_move_done(chan);
50455b155ef9SMat Martineau 		l2cap_send_move_chan_cfm(chan, L2CAP_MC_UNCONFIRMED);
50465b155ef9SMat Martineau 	}
50475b155ef9SMat Martineau 
50485b155ef9SMat Martineau 	l2cap_chan_unlock(chan);
50495b155ef9SMat Martineau }
50505b155ef9SMat Martineau 
50515b155ef9SMat Martineau static void l2cap_move_fail(struct l2cap_conn *conn, u8 ident, u16 icid,
50525b155ef9SMat Martineau 			    u16 result)
50535b155ef9SMat Martineau {
50545b155ef9SMat Martineau 	struct l2cap_chan *chan;
50555b155ef9SMat Martineau 
50565b155ef9SMat Martineau 	chan = l2cap_get_chan_by_ident(conn, ident);
50575b155ef9SMat Martineau 	if (!chan) {
50585b155ef9SMat Martineau 		/* Could not locate channel, icid is best guess */
50595b155ef9SMat Martineau 		l2cap_send_move_chan_cfm_icid(conn, icid);
50605b155ef9SMat Martineau 		return;
50615b155ef9SMat Martineau 	}
50625b155ef9SMat Martineau 
50635b155ef9SMat Martineau 	__clear_chan_timer(chan);
50645b155ef9SMat Martineau 
50655b155ef9SMat Martineau 	if (chan->move_role == L2CAP_MOVE_ROLE_INITIATOR) {
50665b155ef9SMat Martineau 		if (result == L2CAP_MR_COLLISION) {
50675b155ef9SMat Martineau 			chan->move_role = L2CAP_MOVE_ROLE_RESPONDER;
50685b155ef9SMat Martineau 		} else {
50695b155ef9SMat Martineau 			/* Cleanup - cancel move */
50705b155ef9SMat Martineau 			chan->move_id = chan->local_amp_id;
50715b155ef9SMat Martineau 			l2cap_move_done(chan);
50725b155ef9SMat Martineau 		}
50735b155ef9SMat Martineau 	}
50745b155ef9SMat Martineau 
50755b155ef9SMat Martineau 	l2cap_send_move_chan_cfm(chan, L2CAP_MC_UNCONFIRMED);
50765b155ef9SMat Martineau 
50775b155ef9SMat Martineau 	l2cap_chan_unlock(chan);
50785b155ef9SMat Martineau }
50795b155ef9SMat Martineau 
50805b155ef9SMat Martineau static int l2cap_move_channel_rsp(struct l2cap_conn *conn,
5081ad0ac6caSAndrei Emeltchenko 				  struct l2cap_cmd_hdr *cmd,
5082ad0ac6caSAndrei Emeltchenko 				  u16 cmd_len, void *data)
50838d5a04a1SMat Martineau {
50848d5a04a1SMat Martineau 	struct l2cap_move_chan_rsp *rsp = data;
50858d5a04a1SMat Martineau 	u16 icid, result;
50868d5a04a1SMat Martineau 
50878d5a04a1SMat Martineau 	if (cmd_len != sizeof(*rsp))
50888d5a04a1SMat Martineau 		return -EPROTO;
50898d5a04a1SMat Martineau 
50908d5a04a1SMat Martineau 	icid = le16_to_cpu(rsp->icid);
50918d5a04a1SMat Martineau 	result = le16_to_cpu(rsp->result);
50928d5a04a1SMat Martineau 
5093ad0ac6caSAndrei Emeltchenko 	BT_DBG("icid 0x%4.4x, result 0x%4.4x", icid, result);
50948d5a04a1SMat Martineau 
50955b155ef9SMat Martineau 	if (result == L2CAP_MR_SUCCESS || result == L2CAP_MR_PEND)
50965b155ef9SMat Martineau 		l2cap_move_continue(conn, icid, result);
50975b155ef9SMat Martineau 	else
50985b155ef9SMat Martineau 		l2cap_move_fail(conn, cmd->ident, icid, result);
50998d5a04a1SMat Martineau 
51008d5a04a1SMat Martineau 	return 0;
51018d5a04a1SMat Martineau }
51028d5a04a1SMat Martineau 
51035f3847a4SMat Martineau static int l2cap_move_channel_confirm(struct l2cap_conn *conn,
5104ad0ac6caSAndrei Emeltchenko 				      struct l2cap_cmd_hdr *cmd,
5105ad0ac6caSAndrei Emeltchenko 				      u16 cmd_len, void *data)
51068d5a04a1SMat Martineau {
51078d5a04a1SMat Martineau 	struct l2cap_move_chan_cfm *cfm = data;
51085f3847a4SMat Martineau 	struct l2cap_chan *chan;
51098d5a04a1SMat Martineau 	u16 icid, result;
51108d5a04a1SMat Martineau 
51118d5a04a1SMat Martineau 	if (cmd_len != sizeof(*cfm))
51128d5a04a1SMat Martineau 		return -EPROTO;
51138d5a04a1SMat Martineau 
51148d5a04a1SMat Martineau 	icid = le16_to_cpu(cfm->icid);
51158d5a04a1SMat Martineau 	result = le16_to_cpu(cfm->result);
51168d5a04a1SMat Martineau 
5117ad0ac6caSAndrei Emeltchenko 	BT_DBG("icid 0x%4.4x, result 0x%4.4x", icid, result);
51188d5a04a1SMat Martineau 
51195f3847a4SMat Martineau 	chan = l2cap_get_chan_by_dcid(conn, icid);
51205f3847a4SMat Martineau 	if (!chan) {
51215f3847a4SMat Martineau 		/* Spec requires a response even if the icid was not found */
51228d5a04a1SMat Martineau 		l2cap_send_move_chan_cfm_rsp(conn, cmd->ident, icid);
51235f3847a4SMat Martineau 		return 0;
51245f3847a4SMat Martineau 	}
51255f3847a4SMat Martineau 
51265f3847a4SMat Martineau 	if (chan->move_state == L2CAP_MOVE_WAIT_CONFIRM) {
51275f3847a4SMat Martineau 		if (result == L2CAP_MC_CONFIRMED) {
51285f3847a4SMat Martineau 			chan->local_amp_id = chan->move_id;
51296ed971caSMarcel Holtmann 			if (chan->local_amp_id == AMP_ID_BREDR)
51305f3847a4SMat Martineau 				__release_logical_link(chan);
51315f3847a4SMat Martineau 		} else {
51325f3847a4SMat Martineau 			chan->move_id = chan->local_amp_id;
51335f3847a4SMat Martineau 		}
51345f3847a4SMat Martineau 
51355f3847a4SMat Martineau 		l2cap_move_done(chan);
51365f3847a4SMat Martineau 	}
51375f3847a4SMat Martineau 
51385f3847a4SMat Martineau 	l2cap_send_move_chan_cfm_rsp(conn, cmd->ident, icid);
51395f3847a4SMat Martineau 
51405f3847a4SMat Martineau 	l2cap_chan_unlock(chan);
51418d5a04a1SMat Martineau 
51428d5a04a1SMat Martineau 	return 0;
51438d5a04a1SMat Martineau }
51448d5a04a1SMat Martineau 
51458d5a04a1SMat Martineau static inline int l2cap_move_channel_confirm_rsp(struct l2cap_conn *conn,
5146ad0ac6caSAndrei Emeltchenko 						 struct l2cap_cmd_hdr *cmd,
5147ad0ac6caSAndrei Emeltchenko 						 u16 cmd_len, void *data)
51488d5a04a1SMat Martineau {
51498d5a04a1SMat Martineau 	struct l2cap_move_chan_cfm_rsp *rsp = data;
51503fd71a0aSMat Martineau 	struct l2cap_chan *chan;
51518d5a04a1SMat Martineau 	u16 icid;
51528d5a04a1SMat Martineau 
51538d5a04a1SMat Martineau 	if (cmd_len != sizeof(*rsp))
51548d5a04a1SMat Martineau 		return -EPROTO;
51558d5a04a1SMat Martineau 
51568d5a04a1SMat Martineau 	icid = le16_to_cpu(rsp->icid);
51578d5a04a1SMat Martineau 
5158ad0ac6caSAndrei Emeltchenko 	BT_DBG("icid 0x%4.4x", icid);
51598d5a04a1SMat Martineau 
51603fd71a0aSMat Martineau 	chan = l2cap_get_chan_by_scid(conn, icid);
51613fd71a0aSMat Martineau 	if (!chan)
51623fd71a0aSMat Martineau 		return 0;
51633fd71a0aSMat Martineau 
51643fd71a0aSMat Martineau 	__clear_chan_timer(chan);
51653fd71a0aSMat Martineau 
51663fd71a0aSMat Martineau 	if (chan->move_state == L2CAP_MOVE_WAIT_CONFIRM_RSP) {
51673fd71a0aSMat Martineau 		chan->local_amp_id = chan->move_id;
51683fd71a0aSMat Martineau 
51696ed971caSMarcel Holtmann 		if (chan->local_amp_id == AMP_ID_BREDR && chan->hs_hchan)
51703fd71a0aSMat Martineau 			__release_logical_link(chan);
51713fd71a0aSMat Martineau 
51723fd71a0aSMat Martineau 		l2cap_move_done(chan);
51733fd71a0aSMat Martineau 	}
51743fd71a0aSMat Martineau 
51753fd71a0aSMat Martineau 	l2cap_chan_unlock(chan);
51763fd71a0aSMat Martineau 
51778d5a04a1SMat Martineau 	return 0;
51788d5a04a1SMat Martineau }
51798d5a04a1SMat Martineau 
5180e2174ca4SGustavo F. Padovan static inline int l2cap_check_conn_param(u16 min, u16 max, u16 latency,
5181de73115aSClaudio Takahasi 					 u16 to_multiplier)
5182de73115aSClaudio Takahasi {
5183de73115aSClaudio Takahasi 	u16 max_latency;
5184de73115aSClaudio Takahasi 
5185de73115aSClaudio Takahasi 	if (min > max || min < 6 || max > 3200)
5186de73115aSClaudio Takahasi 		return -EINVAL;
5187de73115aSClaudio Takahasi 
5188de73115aSClaudio Takahasi 	if (to_multiplier < 10 || to_multiplier > 3200)
5189de73115aSClaudio Takahasi 		return -EINVAL;
5190de73115aSClaudio Takahasi 
5191de73115aSClaudio Takahasi 	if (max >= to_multiplier * 8)
5192de73115aSClaudio Takahasi 		return -EINVAL;
5193de73115aSClaudio Takahasi 
5194de73115aSClaudio Takahasi 	max_latency = (to_multiplier * 8 / max) - 1;
5195de73115aSClaudio Takahasi 	if (latency > 499 || latency > max_latency)
5196de73115aSClaudio Takahasi 		return -EINVAL;
5197de73115aSClaudio Takahasi 
5198de73115aSClaudio Takahasi 	return 0;
5199de73115aSClaudio Takahasi }
5200de73115aSClaudio Takahasi 
5201de73115aSClaudio Takahasi static inline int l2cap_conn_param_update_req(struct l2cap_conn *conn,
52022d792818SGustavo Padovan 					      struct l2cap_cmd_hdr *cmd,
52032d792818SGustavo Padovan 					      u8 *data)
5204de73115aSClaudio Takahasi {
5205de73115aSClaudio Takahasi 	struct hci_conn *hcon = conn->hcon;
5206de73115aSClaudio Takahasi 	struct l2cap_conn_param_update_req *req;
5207de73115aSClaudio Takahasi 	struct l2cap_conn_param_update_rsp rsp;
5208de73115aSClaudio Takahasi 	u16 min, max, latency, to_multiplier, cmd_len;
52092ce603ebSClaudio Takahasi 	int err;
5210de73115aSClaudio Takahasi 
5211de73115aSClaudio Takahasi 	if (!(hcon->link_mode & HCI_LM_MASTER))
5212de73115aSClaudio Takahasi 		return -EINVAL;
5213de73115aSClaudio Takahasi 
5214de73115aSClaudio Takahasi 	cmd_len = __le16_to_cpu(cmd->len);
5215de73115aSClaudio Takahasi 	if (cmd_len != sizeof(struct l2cap_conn_param_update_req))
5216de73115aSClaudio Takahasi 		return -EPROTO;
5217de73115aSClaudio Takahasi 
5218de73115aSClaudio Takahasi 	req = (struct l2cap_conn_param_update_req *) data;
5219de73115aSClaudio Takahasi 	min		= __le16_to_cpu(req->min);
5220de73115aSClaudio Takahasi 	max		= __le16_to_cpu(req->max);
5221de73115aSClaudio Takahasi 	latency		= __le16_to_cpu(req->latency);
5222de73115aSClaudio Takahasi 	to_multiplier	= __le16_to_cpu(req->to_multiplier);
5223de73115aSClaudio Takahasi 
5224de73115aSClaudio Takahasi 	BT_DBG("min 0x%4.4x max 0x%4.4x latency: 0x%4.4x Timeout: 0x%4.4x",
5225de73115aSClaudio Takahasi 	       min, max, latency, to_multiplier);
5226de73115aSClaudio Takahasi 
5227de73115aSClaudio Takahasi 	memset(&rsp, 0, sizeof(rsp));
52282ce603ebSClaudio Takahasi 
52292ce603ebSClaudio Takahasi 	err = l2cap_check_conn_param(min, max, latency, to_multiplier);
52302ce603ebSClaudio Takahasi 	if (err)
5231ac73498cSAndrei Emeltchenko 		rsp.result = __constant_cpu_to_le16(L2CAP_CONN_PARAM_REJECTED);
5232de73115aSClaudio Takahasi 	else
5233ac73498cSAndrei Emeltchenko 		rsp.result = __constant_cpu_to_le16(L2CAP_CONN_PARAM_ACCEPTED);
5234de73115aSClaudio Takahasi 
5235de73115aSClaudio Takahasi 	l2cap_send_cmd(conn, cmd->ident, L2CAP_CONN_PARAM_UPDATE_RSP,
5236de73115aSClaudio Takahasi 		       sizeof(rsp), &rsp);
5237de73115aSClaudio Takahasi 
52382ce603ebSClaudio Takahasi 	if (!err)
52392ce603ebSClaudio Takahasi 		hci_le_conn_update(hcon, min, max, latency, to_multiplier);
52402ce603ebSClaudio Takahasi 
5241de73115aSClaudio Takahasi 	return 0;
5242de73115aSClaudio Takahasi }
5243de73115aSClaudio Takahasi 
52443300d9a9SClaudio Takahasi static inline int l2cap_bredr_sig_cmd(struct l2cap_conn *conn,
52452d792818SGustavo Padovan 				      struct l2cap_cmd_hdr *cmd, u16 cmd_len,
52462d792818SGustavo Padovan 				      u8 *data)
52473300d9a9SClaudio Takahasi {
52483300d9a9SClaudio Takahasi 	int err = 0;
52493300d9a9SClaudio Takahasi 
52503300d9a9SClaudio Takahasi 	switch (cmd->code) {
52513300d9a9SClaudio Takahasi 	case L2CAP_COMMAND_REJ:
5252cb3b3152SJohan Hedberg 		l2cap_command_rej(conn, cmd, cmd_len, data);
52533300d9a9SClaudio Takahasi 		break;
52543300d9a9SClaudio Takahasi 
52553300d9a9SClaudio Takahasi 	case L2CAP_CONN_REQ:
5256cb3b3152SJohan Hedberg 		err = l2cap_connect_req(conn, cmd, cmd_len, data);
52573300d9a9SClaudio Takahasi 		break;
52583300d9a9SClaudio Takahasi 
52593300d9a9SClaudio Takahasi 	case L2CAP_CONN_RSP:
5260f5a2598dSMat Martineau 	case L2CAP_CREATE_CHAN_RSP:
52619245e737SJohan Hedberg 		l2cap_connect_create_rsp(conn, cmd, cmd_len, data);
52623300d9a9SClaudio Takahasi 		break;
52633300d9a9SClaudio Takahasi 
52643300d9a9SClaudio Takahasi 	case L2CAP_CONF_REQ:
52653300d9a9SClaudio Takahasi 		err = l2cap_config_req(conn, cmd, cmd_len, data);
52663300d9a9SClaudio Takahasi 		break;
52673300d9a9SClaudio Takahasi 
52683300d9a9SClaudio Takahasi 	case L2CAP_CONF_RSP:
52699245e737SJohan Hedberg 		l2cap_config_rsp(conn, cmd, cmd_len, data);
52703300d9a9SClaudio Takahasi 		break;
52713300d9a9SClaudio Takahasi 
52723300d9a9SClaudio Takahasi 	case L2CAP_DISCONN_REQ:
5273cb3b3152SJohan Hedberg 		err = l2cap_disconnect_req(conn, cmd, cmd_len, data);
52743300d9a9SClaudio Takahasi 		break;
52753300d9a9SClaudio Takahasi 
52763300d9a9SClaudio Takahasi 	case L2CAP_DISCONN_RSP:
52779245e737SJohan Hedberg 		l2cap_disconnect_rsp(conn, cmd, cmd_len, data);
52783300d9a9SClaudio Takahasi 		break;
52793300d9a9SClaudio Takahasi 
52803300d9a9SClaudio Takahasi 	case L2CAP_ECHO_REQ:
52813300d9a9SClaudio Takahasi 		l2cap_send_cmd(conn, cmd->ident, L2CAP_ECHO_RSP, cmd_len, data);
52823300d9a9SClaudio Takahasi 		break;
52833300d9a9SClaudio Takahasi 
52843300d9a9SClaudio Takahasi 	case L2CAP_ECHO_RSP:
52853300d9a9SClaudio Takahasi 		break;
52863300d9a9SClaudio Takahasi 
52873300d9a9SClaudio Takahasi 	case L2CAP_INFO_REQ:
5288cb3b3152SJohan Hedberg 		err = l2cap_information_req(conn, cmd, cmd_len, data);
52893300d9a9SClaudio Takahasi 		break;
52903300d9a9SClaudio Takahasi 
52913300d9a9SClaudio Takahasi 	case L2CAP_INFO_RSP:
52929245e737SJohan Hedberg 		l2cap_information_rsp(conn, cmd, cmd_len, data);
52933300d9a9SClaudio Takahasi 		break;
52943300d9a9SClaudio Takahasi 
5295f94ff6ffSMat Martineau 	case L2CAP_CREATE_CHAN_REQ:
5296f94ff6ffSMat Martineau 		err = l2cap_create_channel_req(conn, cmd, cmd_len, data);
5297f94ff6ffSMat Martineau 		break;
5298f94ff6ffSMat Martineau 
52998d5a04a1SMat Martineau 	case L2CAP_MOVE_CHAN_REQ:
53008d5a04a1SMat Martineau 		err = l2cap_move_channel_req(conn, cmd, cmd_len, data);
53018d5a04a1SMat Martineau 		break;
53028d5a04a1SMat Martineau 
53038d5a04a1SMat Martineau 	case L2CAP_MOVE_CHAN_RSP:
53049245e737SJohan Hedberg 		l2cap_move_channel_rsp(conn, cmd, cmd_len, data);
53058d5a04a1SMat Martineau 		break;
53068d5a04a1SMat Martineau 
53078d5a04a1SMat Martineau 	case L2CAP_MOVE_CHAN_CFM:
53088d5a04a1SMat Martineau 		err = l2cap_move_channel_confirm(conn, cmd, cmd_len, data);
53098d5a04a1SMat Martineau 		break;
53108d5a04a1SMat Martineau 
53118d5a04a1SMat Martineau 	case L2CAP_MOVE_CHAN_CFM_RSP:
53129245e737SJohan Hedberg 		l2cap_move_channel_confirm_rsp(conn, cmd, cmd_len, data);
53138d5a04a1SMat Martineau 		break;
53148d5a04a1SMat Martineau 
53153300d9a9SClaudio Takahasi 	default:
53163300d9a9SClaudio Takahasi 		BT_ERR("Unknown BR/EDR signaling command 0x%2.2x", cmd->code);
53173300d9a9SClaudio Takahasi 		err = -EINVAL;
53183300d9a9SClaudio Takahasi 		break;
53193300d9a9SClaudio Takahasi 	}
53203300d9a9SClaudio Takahasi 
53213300d9a9SClaudio Takahasi 	return err;
53223300d9a9SClaudio Takahasi }
53233300d9a9SClaudio Takahasi 
53243300d9a9SClaudio Takahasi static inline int l2cap_le_sig_cmd(struct l2cap_conn *conn,
53253300d9a9SClaudio Takahasi 				   struct l2cap_cmd_hdr *cmd, u8 *data)
53263300d9a9SClaudio Takahasi {
53273300d9a9SClaudio Takahasi 	switch (cmd->code) {
53283300d9a9SClaudio Takahasi 	case L2CAP_COMMAND_REJ:
53293300d9a9SClaudio Takahasi 		return 0;
53303300d9a9SClaudio Takahasi 
53313300d9a9SClaudio Takahasi 	case L2CAP_CONN_PARAM_UPDATE_REQ:
5332de73115aSClaudio Takahasi 		return l2cap_conn_param_update_req(conn, cmd, data);
53333300d9a9SClaudio Takahasi 
53343300d9a9SClaudio Takahasi 	case L2CAP_CONN_PARAM_UPDATE_RSP:
53353300d9a9SClaudio Takahasi 		return 0;
53363300d9a9SClaudio Takahasi 
53373300d9a9SClaudio Takahasi 	default:
53383300d9a9SClaudio Takahasi 		BT_ERR("Unknown LE signaling command 0x%2.2x", cmd->code);
53393300d9a9SClaudio Takahasi 		return -EINVAL;
53403300d9a9SClaudio Takahasi 	}
53413300d9a9SClaudio Takahasi }
53423300d9a9SClaudio Takahasi 
53437c2005d6SJohan Hedberg static __le16 l2cap_err_to_reason(int err)
53447c2005d6SJohan Hedberg {
53457c2005d6SJohan Hedberg 	switch (err) {
53467c2005d6SJohan Hedberg 	case -EBADSLT:
53477c2005d6SJohan Hedberg 		return __constant_cpu_to_le16(L2CAP_REJ_INVALID_CID);
53487c2005d6SJohan Hedberg 	case -EMSGSIZE:
53497c2005d6SJohan Hedberg 		return __constant_cpu_to_le16(L2CAP_REJ_MTU_EXCEEDED);
53507c2005d6SJohan Hedberg 	case -EINVAL:
53517c2005d6SJohan Hedberg 	case -EPROTO:
53527c2005d6SJohan Hedberg 	default:
53537c2005d6SJohan Hedberg 		return __constant_cpu_to_le16(L2CAP_REJ_NOT_UNDERSTOOD);
53547c2005d6SJohan Hedberg 	}
53557c2005d6SJohan Hedberg }
53567c2005d6SJohan Hedberg 
5357c5623556SJohan Hedberg static inline void l2cap_le_sig_channel(struct l2cap_conn *conn,
5358c5623556SJohan Hedberg 					struct sk_buff *skb)
5359c5623556SJohan Hedberg {
536069c4e4e8SJohan Hedberg 	struct hci_conn *hcon = conn->hcon;
53614f3e219dSMarcel Holtmann 	struct l2cap_cmd_hdr *cmd;
53624f3e219dSMarcel Holtmann 	u16 len;
5363c5623556SJohan Hedberg 	int err;
5364c5623556SJohan Hedberg 
536569c4e4e8SJohan Hedberg 	if (hcon->type != LE_LINK)
53663b166295SMarcel Holtmann 		goto drop;
536769c4e4e8SJohan Hedberg 
53684f3e219dSMarcel Holtmann 	if (skb->len < L2CAP_CMD_HDR_SIZE)
53694f3e219dSMarcel Holtmann 		goto drop;
5370c5623556SJohan Hedberg 
53714f3e219dSMarcel Holtmann 	cmd = (void *) skb->data;
53724f3e219dSMarcel Holtmann 	skb_pull(skb, L2CAP_CMD_HDR_SIZE);
5373c5623556SJohan Hedberg 
53744f3e219dSMarcel Holtmann 	len = le16_to_cpu(cmd->len);
5375c5623556SJohan Hedberg 
53764f3e219dSMarcel Holtmann 	BT_DBG("code 0x%2.2x len %d id 0x%2.2x", cmd->code, len, cmd->ident);
53774f3e219dSMarcel Holtmann 
53784f3e219dSMarcel Holtmann 	if (len != skb->len || !cmd->ident) {
5379c5623556SJohan Hedberg 		BT_DBG("corrupted command");
53804f3e219dSMarcel Holtmann 		goto drop;
5381c5623556SJohan Hedberg 	}
5382c5623556SJohan Hedberg 
53834f3e219dSMarcel Holtmann 	err = l2cap_le_sig_cmd(conn, cmd, skb->data);
5384c5623556SJohan Hedberg 	if (err) {
5385c5623556SJohan Hedberg 		struct l2cap_cmd_rej_unk rej;
5386c5623556SJohan Hedberg 
5387c5623556SJohan Hedberg 		BT_ERR("Wrong link type (%d)", err);
5388c5623556SJohan Hedberg 
53897c2005d6SJohan Hedberg 		rej.reason = l2cap_err_to_reason(err);
53904f3e219dSMarcel Holtmann 		l2cap_send_cmd(conn, cmd->ident, L2CAP_COMMAND_REJ,
5391c5623556SJohan Hedberg 			       sizeof(rej), &rej);
5392c5623556SJohan Hedberg 	}
5393c5623556SJohan Hedberg 
53943b166295SMarcel Holtmann drop:
5395c5623556SJohan Hedberg 	kfree_skb(skb);
5396c5623556SJohan Hedberg }
5397c5623556SJohan Hedberg 
53983300d9a9SClaudio Takahasi static inline void l2cap_sig_channel(struct l2cap_conn *conn,
53993300d9a9SClaudio Takahasi 				     struct sk_buff *skb)
54000a708f8fSGustavo F. Padovan {
540169c4e4e8SJohan Hedberg 	struct hci_conn *hcon = conn->hcon;
54020a708f8fSGustavo F. Padovan 	u8 *data = skb->data;
54030a708f8fSGustavo F. Padovan 	int len = skb->len;
54040a708f8fSGustavo F. Padovan 	struct l2cap_cmd_hdr cmd;
54053300d9a9SClaudio Takahasi 	int err;
54060a708f8fSGustavo F. Padovan 
54070a708f8fSGustavo F. Padovan 	l2cap_raw_recv(conn, skb);
54080a708f8fSGustavo F. Padovan 
540969c4e4e8SJohan Hedberg 	if (hcon->type != ACL_LINK)
54103b166295SMarcel Holtmann 		goto drop;
541169c4e4e8SJohan Hedberg 
54120a708f8fSGustavo F. Padovan 	while (len >= L2CAP_CMD_HDR_SIZE) {
54130a708f8fSGustavo F. Padovan 		u16 cmd_len;
54140a708f8fSGustavo F. Padovan 		memcpy(&cmd, data, L2CAP_CMD_HDR_SIZE);
54150a708f8fSGustavo F. Padovan 		data += L2CAP_CMD_HDR_SIZE;
54160a708f8fSGustavo F. Padovan 		len  -= L2CAP_CMD_HDR_SIZE;
54170a708f8fSGustavo F. Padovan 
54180a708f8fSGustavo F. Padovan 		cmd_len = le16_to_cpu(cmd.len);
54190a708f8fSGustavo F. Padovan 
54202d792818SGustavo Padovan 		BT_DBG("code 0x%2.2x len %d id 0x%2.2x", cmd.code, cmd_len,
54212d792818SGustavo Padovan 		       cmd.ident);
54220a708f8fSGustavo F. Padovan 
54230a708f8fSGustavo F. Padovan 		if (cmd_len > len || !cmd.ident) {
54240a708f8fSGustavo F. Padovan 			BT_DBG("corrupted command");
54250a708f8fSGustavo F. Padovan 			break;
54260a708f8fSGustavo F. Padovan 		}
54270a708f8fSGustavo F. Padovan 
54283300d9a9SClaudio Takahasi 		err = l2cap_bredr_sig_cmd(conn, &cmd, cmd_len, data);
54290a708f8fSGustavo F. Padovan 		if (err) {
5430e2fd318eSIlia Kolomisnky 			struct l2cap_cmd_rej_unk rej;
54312c6d1a2eSGustavo F. Padovan 
54322c6d1a2eSGustavo F. Padovan 			BT_ERR("Wrong link type (%d)", err);
54330a708f8fSGustavo F. Padovan 
54347c2005d6SJohan Hedberg 			rej.reason = l2cap_err_to_reason(err);
54352d792818SGustavo Padovan 			l2cap_send_cmd(conn, cmd.ident, L2CAP_COMMAND_REJ,
54362d792818SGustavo Padovan 				       sizeof(rej), &rej);
54370a708f8fSGustavo F. Padovan 		}
54380a708f8fSGustavo F. Padovan 
54390a708f8fSGustavo F. Padovan 		data += cmd_len;
54400a708f8fSGustavo F. Padovan 		len  -= cmd_len;
54410a708f8fSGustavo F. Padovan 	}
54420a708f8fSGustavo F. Padovan 
54433b166295SMarcel Holtmann drop:
54440a708f8fSGustavo F. Padovan 	kfree_skb(skb);
54450a708f8fSGustavo F. Padovan }
54460a708f8fSGustavo F. Padovan 
544747d1ec61SGustavo F. Padovan static int l2cap_check_fcs(struct l2cap_chan *chan,  struct sk_buff *skb)
54480a708f8fSGustavo F. Padovan {
54490a708f8fSGustavo F. Padovan 	u16 our_fcs, rcv_fcs;
5450e4ca6d98SAndrei Emeltchenko 	int hdr_size;
5451e4ca6d98SAndrei Emeltchenko 
5452e4ca6d98SAndrei Emeltchenko 	if (test_bit(FLAG_EXT_CTRL, &chan->flags))
5453e4ca6d98SAndrei Emeltchenko 		hdr_size = L2CAP_EXT_HDR_SIZE;
5454e4ca6d98SAndrei Emeltchenko 	else
5455e4ca6d98SAndrei Emeltchenko 		hdr_size = L2CAP_ENH_HDR_SIZE;
54560a708f8fSGustavo F. Padovan 
545747d1ec61SGustavo F. Padovan 	if (chan->fcs == L2CAP_FCS_CRC16) {
545803a51213SAndrei Emeltchenko 		skb_trim(skb, skb->len - L2CAP_FCS_SIZE);
54590a708f8fSGustavo F. Padovan 		rcv_fcs = get_unaligned_le16(skb->data + skb->len);
54600a708f8fSGustavo F. Padovan 		our_fcs = crc16(0, skb->data - hdr_size, skb->len + hdr_size);
54610a708f8fSGustavo F. Padovan 
54620a708f8fSGustavo F. Padovan 		if (our_fcs != rcv_fcs)
54630a708f8fSGustavo F. Padovan 			return -EBADMSG;
54640a708f8fSGustavo F. Padovan 	}
54650a708f8fSGustavo F. Padovan 	return 0;
54660a708f8fSGustavo F. Padovan }
54670a708f8fSGustavo F. Padovan 
54686ea00485SMat Martineau static void l2cap_send_i_or_rr_or_rnr(struct l2cap_chan *chan)
54690a708f8fSGustavo F. Padovan {
5470e31f7633SMat Martineau 	struct l2cap_ctrl control;
54710a708f8fSGustavo F. Padovan 
5472e31f7633SMat Martineau 	BT_DBG("chan %p", chan);
54730a708f8fSGustavo F. Padovan 
5474e31f7633SMat Martineau 	memset(&control, 0, sizeof(control));
5475e31f7633SMat Martineau 	control.sframe = 1;
5476e31f7633SMat Martineau 	control.final = 1;
5477e31f7633SMat Martineau 	control.reqseq = chan->buffer_seq;
5478e31f7633SMat Martineau 	set_bit(CONN_SEND_FBIT, &chan->conn_state);
54790a708f8fSGustavo F. Padovan 
5480e2ab4353SGustavo F. Padovan 	if (test_bit(CONN_LOCAL_BUSY, &chan->conn_state)) {
5481e31f7633SMat Martineau 		control.super = L2CAP_SUPER_RNR;
5482e31f7633SMat Martineau 		l2cap_send_sframe(chan, &control);
54830a708f8fSGustavo F. Padovan 	}
54840a708f8fSGustavo F. Padovan 
5485e31f7633SMat Martineau 	if (test_and_clear_bit(CONN_REMOTE_BUSY, &chan->conn_state) &&
5486e31f7633SMat Martineau 	    chan->unacked_frames > 0)
5487e31f7633SMat Martineau 		__set_retrans_timer(chan);
54880a708f8fSGustavo F. Padovan 
5489e31f7633SMat Martineau 	/* Send pending iframes */
5490525cd185SGustavo F. Padovan 	l2cap_ertm_send(chan);
54910a708f8fSGustavo F. Padovan 
5492e2ab4353SGustavo F. Padovan 	if (!test_bit(CONN_LOCAL_BUSY, &chan->conn_state) &&
5493e31f7633SMat Martineau 	    test_bit(CONN_SEND_FBIT, &chan->conn_state)) {
5494e31f7633SMat Martineau 		/* F-bit wasn't sent in an s-frame or i-frame yet, so
5495e31f7633SMat Martineau 		 * send it now.
5496e31f7633SMat Martineau 		 */
5497e31f7633SMat Martineau 		control.super = L2CAP_SUPER_RR;
5498e31f7633SMat Martineau 		l2cap_send_sframe(chan, &control);
54990a708f8fSGustavo F. Padovan 	}
55000a708f8fSGustavo F. Padovan }
55010a708f8fSGustavo F. Padovan 
55022d792818SGustavo Padovan static void append_skb_frag(struct sk_buff *skb, struct sk_buff *new_frag,
55032d792818SGustavo Padovan 			    struct sk_buff **last_frag)
55040a708f8fSGustavo F. Padovan {
550584084a31SMat Martineau 	/* skb->len reflects data in skb as well as all fragments
550684084a31SMat Martineau 	 * skb->data_len reflects only data in fragments
550784084a31SMat Martineau 	 */
550884084a31SMat Martineau 	if (!skb_has_frag_list(skb))
550984084a31SMat Martineau 		skb_shinfo(skb)->frag_list = new_frag;
551084084a31SMat Martineau 
551184084a31SMat Martineau 	new_frag->next = NULL;
551284084a31SMat Martineau 
551384084a31SMat Martineau 	(*last_frag)->next = new_frag;
551484084a31SMat Martineau 	*last_frag = new_frag;
551584084a31SMat Martineau 
551684084a31SMat Martineau 	skb->len += new_frag->len;
551784084a31SMat Martineau 	skb->data_len += new_frag->len;
551884084a31SMat Martineau 	skb->truesize += new_frag->truesize;
551984084a31SMat Martineau }
552084084a31SMat Martineau 
55214b51dae9SMat Martineau static int l2cap_reassemble_sdu(struct l2cap_chan *chan, struct sk_buff *skb,
55224b51dae9SMat Martineau 				struct l2cap_ctrl *control)
552384084a31SMat Martineau {
552484084a31SMat Martineau 	int err = -EINVAL;
55250a708f8fSGustavo F. Padovan 
55264b51dae9SMat Martineau 	switch (control->sar) {
55277e0ef6eeSAndrei Emeltchenko 	case L2CAP_SAR_UNSEGMENTED:
552884084a31SMat Martineau 		if (chan->sdu)
552984084a31SMat Martineau 			break;
55300a708f8fSGustavo F. Padovan 
553180b98027SGustavo Padovan 		err = chan->ops->recv(chan, skb);
553284084a31SMat Martineau 		break;
55330a708f8fSGustavo F. Padovan 
55347e0ef6eeSAndrei Emeltchenko 	case L2CAP_SAR_START:
553584084a31SMat Martineau 		if (chan->sdu)
553684084a31SMat Martineau 			break;
55370a708f8fSGustavo F. Padovan 
55386f61fd47SGustavo F. Padovan 		chan->sdu_len = get_unaligned_le16(skb->data);
553903a51213SAndrei Emeltchenko 		skb_pull(skb, L2CAP_SDULEN_SIZE);
55400a708f8fSGustavo F. Padovan 
554184084a31SMat Martineau 		if (chan->sdu_len > chan->imtu) {
554284084a31SMat Martineau 			err = -EMSGSIZE;
554384084a31SMat Martineau 			break;
554484084a31SMat Martineau 		}
55450a708f8fSGustavo F. Padovan 
554684084a31SMat Martineau 		if (skb->len >= chan->sdu_len)
554784084a31SMat Martineau 			break;
554884084a31SMat Martineau 
554984084a31SMat Martineau 		chan->sdu = skb;
555084084a31SMat Martineau 		chan->sdu_last_frag = skb;
555184084a31SMat Martineau 
555284084a31SMat Martineau 		skb = NULL;
555384084a31SMat Martineau 		err = 0;
55540a708f8fSGustavo F. Padovan 		break;
55550a708f8fSGustavo F. Padovan 
55567e0ef6eeSAndrei Emeltchenko 	case L2CAP_SAR_CONTINUE:
55576f61fd47SGustavo F. Padovan 		if (!chan->sdu)
555884084a31SMat Martineau 			break;
55590a708f8fSGustavo F. Padovan 
556084084a31SMat Martineau 		append_skb_frag(chan->sdu, skb,
556184084a31SMat Martineau 				&chan->sdu_last_frag);
556284084a31SMat Martineau 		skb = NULL;
55630a708f8fSGustavo F. Padovan 
556484084a31SMat Martineau 		if (chan->sdu->len >= chan->sdu_len)
556584084a31SMat Martineau 			break;
55660a708f8fSGustavo F. Padovan 
556784084a31SMat Martineau 		err = 0;
55680a708f8fSGustavo F. Padovan 		break;
55690a708f8fSGustavo F. Padovan 
55707e0ef6eeSAndrei Emeltchenko 	case L2CAP_SAR_END:
55716f61fd47SGustavo F. Padovan 		if (!chan->sdu)
557284084a31SMat Martineau 			break;
55730a708f8fSGustavo F. Padovan 
557484084a31SMat Martineau 		append_skb_frag(chan->sdu, skb,
557584084a31SMat Martineau 				&chan->sdu_last_frag);
557684084a31SMat Martineau 		skb = NULL;
55770a708f8fSGustavo F. Padovan 
557884084a31SMat Martineau 		if (chan->sdu->len != chan->sdu_len)
557984084a31SMat Martineau 			break;
55800a708f8fSGustavo F. Padovan 
558180b98027SGustavo Padovan 		err = chan->ops->recv(chan, chan->sdu);
55820a708f8fSGustavo F. Padovan 
558384084a31SMat Martineau 		if (!err) {
558484084a31SMat Martineau 			/* Reassembly complete */
558584084a31SMat Martineau 			chan->sdu = NULL;
558684084a31SMat Martineau 			chan->sdu_last_frag = NULL;
558784084a31SMat Martineau 			chan->sdu_len = 0;
55880a708f8fSGustavo F. Padovan 		}
55890a708f8fSGustavo F. Padovan 		break;
55900a708f8fSGustavo F. Padovan 	}
55910a708f8fSGustavo F. Padovan 
559284084a31SMat Martineau 	if (err) {
55930a708f8fSGustavo F. Padovan 		kfree_skb(skb);
55946f61fd47SGustavo F. Padovan 		kfree_skb(chan->sdu);
55956f61fd47SGustavo F. Padovan 		chan->sdu = NULL;
559684084a31SMat Martineau 		chan->sdu_last_frag = NULL;
559784084a31SMat Martineau 		chan->sdu_len = 0;
559884084a31SMat Martineau 	}
55990a708f8fSGustavo F. Padovan 
560084084a31SMat Martineau 	return err;
56010a708f8fSGustavo F. Padovan }
56020a708f8fSGustavo F. Padovan 
560332b32735SMat Martineau static int l2cap_resegment(struct l2cap_chan *chan)
560432b32735SMat Martineau {
560532b32735SMat Martineau 	/* Placeholder */
560632b32735SMat Martineau 	return 0;
560732b32735SMat Martineau }
560832b32735SMat Martineau 
5609e328140fSMat Martineau void l2cap_chan_busy(struct l2cap_chan *chan, int busy)
56100a708f8fSGustavo F. Padovan {
561161aa4f5bSMat Martineau 	u8 event;
561261aa4f5bSMat Martineau 
561361aa4f5bSMat Martineau 	if (chan->mode != L2CAP_MODE_ERTM)
561461aa4f5bSMat Martineau 		return;
561561aa4f5bSMat Martineau 
561661aa4f5bSMat Martineau 	event = busy ? L2CAP_EV_LOCAL_BUSY_DETECTED : L2CAP_EV_LOCAL_BUSY_CLEAR;
5617401bb1f7SAndrei Emeltchenko 	l2cap_tx(chan, NULL, NULL, event);
56180a708f8fSGustavo F. Padovan }
56190a708f8fSGustavo F. Padovan 
5620d2a7ac5dSMat Martineau static int l2cap_rx_queued_iframes(struct l2cap_chan *chan)
5621d2a7ac5dSMat Martineau {
562263838725SMat Martineau 	int err = 0;
562363838725SMat Martineau 	/* Pass sequential frames to l2cap_reassemble_sdu()
562463838725SMat Martineau 	 * until a gap is encountered.
562563838725SMat Martineau 	 */
562663838725SMat Martineau 
562763838725SMat Martineau 	BT_DBG("chan %p", chan);
562863838725SMat Martineau 
562963838725SMat Martineau 	while (!test_bit(CONN_LOCAL_BUSY, &chan->conn_state)) {
563063838725SMat Martineau 		struct sk_buff *skb;
563163838725SMat Martineau 		BT_DBG("Searching for skb with txseq %d (queue len %d)",
563263838725SMat Martineau 		       chan->buffer_seq, skb_queue_len(&chan->srej_q));
563363838725SMat Martineau 
563463838725SMat Martineau 		skb = l2cap_ertm_seq_in_queue(&chan->srej_q, chan->buffer_seq);
563563838725SMat Martineau 
563663838725SMat Martineau 		if (!skb)
563763838725SMat Martineau 			break;
563863838725SMat Martineau 
563963838725SMat Martineau 		skb_unlink(skb, &chan->srej_q);
564063838725SMat Martineau 		chan->buffer_seq = __next_seq(chan, chan->buffer_seq);
564163838725SMat Martineau 		err = l2cap_reassemble_sdu(chan, skb, &bt_cb(skb)->control);
564263838725SMat Martineau 		if (err)
564363838725SMat Martineau 			break;
564463838725SMat Martineau 	}
564563838725SMat Martineau 
564663838725SMat Martineau 	if (skb_queue_empty(&chan->srej_q)) {
564763838725SMat Martineau 		chan->rx_state = L2CAP_RX_STATE_RECV;
564863838725SMat Martineau 		l2cap_send_ack(chan);
564963838725SMat Martineau 	}
565063838725SMat Martineau 
565163838725SMat Martineau 	return err;
5652d2a7ac5dSMat Martineau }
5653d2a7ac5dSMat Martineau 
5654d2a7ac5dSMat Martineau static void l2cap_handle_srej(struct l2cap_chan *chan,
5655d2a7ac5dSMat Martineau 			      struct l2cap_ctrl *control)
5656d2a7ac5dSMat Martineau {
5657f80842a8SMat Martineau 	struct sk_buff *skb;
5658f80842a8SMat Martineau 
5659f80842a8SMat Martineau 	BT_DBG("chan %p, control %p", chan, control);
5660f80842a8SMat Martineau 
5661f80842a8SMat Martineau 	if (control->reqseq == chan->next_tx_seq) {
5662f80842a8SMat Martineau 		BT_DBG("Invalid reqseq %d, disconnecting", control->reqseq);
56635e4e3972SAndrei Emeltchenko 		l2cap_send_disconn_req(chan, ECONNRESET);
5664f80842a8SMat Martineau 		return;
5665f80842a8SMat Martineau 	}
5666f80842a8SMat Martineau 
5667f80842a8SMat Martineau 	skb = l2cap_ertm_seq_in_queue(&chan->tx_q, control->reqseq);
5668f80842a8SMat Martineau 
5669f80842a8SMat Martineau 	if (skb == NULL) {
5670f80842a8SMat Martineau 		BT_DBG("Seq %d not available for retransmission",
5671f80842a8SMat Martineau 		       control->reqseq);
5672f80842a8SMat Martineau 		return;
5673f80842a8SMat Martineau 	}
5674f80842a8SMat Martineau 
5675f80842a8SMat Martineau 	if (chan->max_tx != 0 && bt_cb(skb)->control.retries >= chan->max_tx) {
5676f80842a8SMat Martineau 		BT_DBG("Retry limit exceeded (%d)", chan->max_tx);
56775e4e3972SAndrei Emeltchenko 		l2cap_send_disconn_req(chan, ECONNRESET);
5678f80842a8SMat Martineau 		return;
5679f80842a8SMat Martineau 	}
5680f80842a8SMat Martineau 
5681f80842a8SMat Martineau 	clear_bit(CONN_REMOTE_BUSY, &chan->conn_state);
5682f80842a8SMat Martineau 
5683f80842a8SMat Martineau 	if (control->poll) {
5684f80842a8SMat Martineau 		l2cap_pass_to_tx(chan, control);
5685f80842a8SMat Martineau 
5686f80842a8SMat Martineau 		set_bit(CONN_SEND_FBIT, &chan->conn_state);
5687f80842a8SMat Martineau 		l2cap_retransmit(chan, control);
5688f80842a8SMat Martineau 		l2cap_ertm_send(chan);
5689f80842a8SMat Martineau 
5690f80842a8SMat Martineau 		if (chan->tx_state == L2CAP_TX_STATE_WAIT_F) {
5691f80842a8SMat Martineau 			set_bit(CONN_SREJ_ACT, &chan->conn_state);
5692f80842a8SMat Martineau 			chan->srej_save_reqseq = control->reqseq;
5693f80842a8SMat Martineau 		}
5694f80842a8SMat Martineau 	} else {
5695f80842a8SMat Martineau 		l2cap_pass_to_tx_fbit(chan, control);
5696f80842a8SMat Martineau 
5697f80842a8SMat Martineau 		if (control->final) {
5698f80842a8SMat Martineau 			if (chan->srej_save_reqseq != control->reqseq ||
5699f80842a8SMat Martineau 			    !test_and_clear_bit(CONN_SREJ_ACT,
5700f80842a8SMat Martineau 						&chan->conn_state))
5701f80842a8SMat Martineau 				l2cap_retransmit(chan, control);
5702f80842a8SMat Martineau 		} else {
5703f80842a8SMat Martineau 			l2cap_retransmit(chan, control);
5704f80842a8SMat Martineau 			if (chan->tx_state == L2CAP_TX_STATE_WAIT_F) {
5705f80842a8SMat Martineau 				set_bit(CONN_SREJ_ACT, &chan->conn_state);
5706f80842a8SMat Martineau 				chan->srej_save_reqseq = control->reqseq;
5707f80842a8SMat Martineau 			}
5708f80842a8SMat Martineau 		}
5709f80842a8SMat Martineau 	}
5710d2a7ac5dSMat Martineau }
5711d2a7ac5dSMat Martineau 
5712d2a7ac5dSMat Martineau static void l2cap_handle_rej(struct l2cap_chan *chan,
5713d2a7ac5dSMat Martineau 			     struct l2cap_ctrl *control)
5714d2a7ac5dSMat Martineau {
5715fcd289dfSMat Martineau 	struct sk_buff *skb;
5716fcd289dfSMat Martineau 
5717fcd289dfSMat Martineau 	BT_DBG("chan %p, control %p", chan, control);
5718fcd289dfSMat Martineau 
5719fcd289dfSMat Martineau 	if (control->reqseq == chan->next_tx_seq) {
5720fcd289dfSMat Martineau 		BT_DBG("Invalid reqseq %d, disconnecting", control->reqseq);
57215e4e3972SAndrei Emeltchenko 		l2cap_send_disconn_req(chan, ECONNRESET);
5722fcd289dfSMat Martineau 		return;
5723fcd289dfSMat Martineau 	}
5724fcd289dfSMat Martineau 
5725fcd289dfSMat Martineau 	skb = l2cap_ertm_seq_in_queue(&chan->tx_q, control->reqseq);
5726fcd289dfSMat Martineau 
5727fcd289dfSMat Martineau 	if (chan->max_tx && skb &&
5728fcd289dfSMat Martineau 	    bt_cb(skb)->control.retries >= chan->max_tx) {
5729fcd289dfSMat Martineau 		BT_DBG("Retry limit exceeded (%d)", chan->max_tx);
57305e4e3972SAndrei Emeltchenko 		l2cap_send_disconn_req(chan, ECONNRESET);
5731fcd289dfSMat Martineau 		return;
5732fcd289dfSMat Martineau 	}
5733fcd289dfSMat Martineau 
5734fcd289dfSMat Martineau 	clear_bit(CONN_REMOTE_BUSY, &chan->conn_state);
5735fcd289dfSMat Martineau 
5736fcd289dfSMat Martineau 	l2cap_pass_to_tx(chan, control);
5737fcd289dfSMat Martineau 
5738fcd289dfSMat Martineau 	if (control->final) {
5739fcd289dfSMat Martineau 		if (!test_and_clear_bit(CONN_REJ_ACT, &chan->conn_state))
5740fcd289dfSMat Martineau 			l2cap_retransmit_all(chan, control);
5741fcd289dfSMat Martineau 	} else {
5742fcd289dfSMat Martineau 		l2cap_retransmit_all(chan, control);
5743fcd289dfSMat Martineau 		l2cap_ertm_send(chan);
5744fcd289dfSMat Martineau 		if (chan->tx_state == L2CAP_TX_STATE_WAIT_F)
5745fcd289dfSMat Martineau 			set_bit(CONN_REJ_ACT, &chan->conn_state);
5746fcd289dfSMat Martineau 	}
5747d2a7ac5dSMat Martineau }
5748d2a7ac5dSMat Martineau 
57494b51dae9SMat Martineau static u8 l2cap_classify_txseq(struct l2cap_chan *chan, u16 txseq)
57504b51dae9SMat Martineau {
57514b51dae9SMat Martineau 	BT_DBG("chan %p, txseq %d", chan, txseq);
57524b51dae9SMat Martineau 
57534b51dae9SMat Martineau 	BT_DBG("last_acked_seq %d, expected_tx_seq %d", chan->last_acked_seq,
57544b51dae9SMat Martineau 	       chan->expected_tx_seq);
57554b51dae9SMat Martineau 
57564b51dae9SMat Martineau 	if (chan->rx_state == L2CAP_RX_STATE_SREJ_SENT) {
57574b51dae9SMat Martineau 		if (__seq_offset(chan, txseq, chan->last_acked_seq) >=
57584b51dae9SMat Martineau 		    chan->tx_win) {
57594b51dae9SMat Martineau 			/* See notes below regarding "double poll" and
57604b51dae9SMat Martineau 			 * invalid packets.
57614b51dae9SMat Martineau 			 */
57624b51dae9SMat Martineau 			if (chan->tx_win <= ((chan->tx_win_max + 1) >> 1)) {
57634b51dae9SMat Martineau 				BT_DBG("Invalid/Ignore - after SREJ");
57644b51dae9SMat Martineau 				return L2CAP_TXSEQ_INVALID_IGNORE;
57654b51dae9SMat Martineau 			} else {
57664b51dae9SMat Martineau 				BT_DBG("Invalid - in window after SREJ sent");
57674b51dae9SMat Martineau 				return L2CAP_TXSEQ_INVALID;
57684b51dae9SMat Martineau 			}
57694b51dae9SMat Martineau 		}
57704b51dae9SMat Martineau 
57714b51dae9SMat Martineau 		if (chan->srej_list.head == txseq) {
57724b51dae9SMat Martineau 			BT_DBG("Expected SREJ");
57734b51dae9SMat Martineau 			return L2CAP_TXSEQ_EXPECTED_SREJ;
57744b51dae9SMat Martineau 		}
57754b51dae9SMat Martineau 
57764b51dae9SMat Martineau 		if (l2cap_ertm_seq_in_queue(&chan->srej_q, txseq)) {
57774b51dae9SMat Martineau 			BT_DBG("Duplicate SREJ - txseq already stored");
57784b51dae9SMat Martineau 			return L2CAP_TXSEQ_DUPLICATE_SREJ;
57794b51dae9SMat Martineau 		}
57804b51dae9SMat Martineau 
57814b51dae9SMat Martineau 		if (l2cap_seq_list_contains(&chan->srej_list, txseq)) {
57824b51dae9SMat Martineau 			BT_DBG("Unexpected SREJ - not requested");
57834b51dae9SMat Martineau 			return L2CAP_TXSEQ_UNEXPECTED_SREJ;
57844b51dae9SMat Martineau 		}
57854b51dae9SMat Martineau 	}
57864b51dae9SMat Martineau 
57874b51dae9SMat Martineau 	if (chan->expected_tx_seq == txseq) {
57884b51dae9SMat Martineau 		if (__seq_offset(chan, txseq, chan->last_acked_seq) >=
57894b51dae9SMat Martineau 		    chan->tx_win) {
57904b51dae9SMat Martineau 			BT_DBG("Invalid - txseq outside tx window");
57914b51dae9SMat Martineau 			return L2CAP_TXSEQ_INVALID;
57924b51dae9SMat Martineau 		} else {
57934b51dae9SMat Martineau 			BT_DBG("Expected");
57944b51dae9SMat Martineau 			return L2CAP_TXSEQ_EXPECTED;
57954b51dae9SMat Martineau 		}
57964b51dae9SMat Martineau 	}
57974b51dae9SMat Martineau 
57984b51dae9SMat Martineau 	if (__seq_offset(chan, txseq, chan->last_acked_seq) <
57992d792818SGustavo Padovan 	    __seq_offset(chan, chan->expected_tx_seq, chan->last_acked_seq)) {
58004b51dae9SMat Martineau 		BT_DBG("Duplicate - expected_tx_seq later than txseq");
58014b51dae9SMat Martineau 		return L2CAP_TXSEQ_DUPLICATE;
58024b51dae9SMat Martineau 	}
58034b51dae9SMat Martineau 
58044b51dae9SMat Martineau 	if (__seq_offset(chan, txseq, chan->last_acked_seq) >= chan->tx_win) {
58054b51dae9SMat Martineau 		/* A source of invalid packets is a "double poll" condition,
58064b51dae9SMat Martineau 		 * where delays cause us to send multiple poll packets.  If
58074b51dae9SMat Martineau 		 * the remote stack receives and processes both polls,
58084b51dae9SMat Martineau 		 * sequence numbers can wrap around in such a way that a
58094b51dae9SMat Martineau 		 * resent frame has a sequence number that looks like new data
58104b51dae9SMat Martineau 		 * with a sequence gap.  This would trigger an erroneous SREJ
58114b51dae9SMat Martineau 		 * request.
58124b51dae9SMat Martineau 		 *
58134b51dae9SMat Martineau 		 * Fortunately, this is impossible with a tx window that's
58144b51dae9SMat Martineau 		 * less than half of the maximum sequence number, which allows
58154b51dae9SMat Martineau 		 * invalid frames to be safely ignored.
58164b51dae9SMat Martineau 		 *
58174b51dae9SMat Martineau 		 * With tx window sizes greater than half of the tx window
58184b51dae9SMat Martineau 		 * maximum, the frame is invalid and cannot be ignored.  This
58194b51dae9SMat Martineau 		 * causes a disconnect.
58204b51dae9SMat Martineau 		 */
58214b51dae9SMat Martineau 
58224b51dae9SMat Martineau 		if (chan->tx_win <= ((chan->tx_win_max + 1) >> 1)) {
58234b51dae9SMat Martineau 			BT_DBG("Invalid/Ignore - txseq outside tx window");
58244b51dae9SMat Martineau 			return L2CAP_TXSEQ_INVALID_IGNORE;
58254b51dae9SMat Martineau 		} else {
58264b51dae9SMat Martineau 			BT_DBG("Invalid - txseq outside tx window");
58274b51dae9SMat Martineau 			return L2CAP_TXSEQ_INVALID;
58284b51dae9SMat Martineau 		}
58294b51dae9SMat Martineau 	} else {
58304b51dae9SMat Martineau 		BT_DBG("Unexpected - txseq indicates missing frames");
58314b51dae9SMat Martineau 		return L2CAP_TXSEQ_UNEXPECTED;
58324b51dae9SMat Martineau 	}
58334b51dae9SMat Martineau }
58344b51dae9SMat Martineau 
5835d2a7ac5dSMat Martineau static int l2cap_rx_state_recv(struct l2cap_chan *chan,
5836d2a7ac5dSMat Martineau 			       struct l2cap_ctrl *control,
5837d2a7ac5dSMat Martineau 			       struct sk_buff *skb, u8 event)
5838d2a7ac5dSMat Martineau {
5839d2a7ac5dSMat Martineau 	int err = 0;
5840941247f9SPeter Senna Tschudin 	bool skb_in_use = false;
5841d2a7ac5dSMat Martineau 
5842d2a7ac5dSMat Martineau 	BT_DBG("chan %p, control %p, skb %p, event %d", chan, control, skb,
5843d2a7ac5dSMat Martineau 	       event);
5844d2a7ac5dSMat Martineau 
5845d2a7ac5dSMat Martineau 	switch (event) {
5846d2a7ac5dSMat Martineau 	case L2CAP_EV_RECV_IFRAME:
5847d2a7ac5dSMat Martineau 		switch (l2cap_classify_txseq(chan, control->txseq)) {
5848d2a7ac5dSMat Martineau 		case L2CAP_TXSEQ_EXPECTED:
5849d2a7ac5dSMat Martineau 			l2cap_pass_to_tx(chan, control);
5850d2a7ac5dSMat Martineau 
5851d2a7ac5dSMat Martineau 			if (test_bit(CONN_LOCAL_BUSY, &chan->conn_state)) {
5852d2a7ac5dSMat Martineau 				BT_DBG("Busy, discarding expected seq %d",
5853d2a7ac5dSMat Martineau 				       control->txseq);
5854d2a7ac5dSMat Martineau 				break;
5855d2a7ac5dSMat Martineau 			}
5856d2a7ac5dSMat Martineau 
5857d2a7ac5dSMat Martineau 			chan->expected_tx_seq = __next_seq(chan,
5858d2a7ac5dSMat Martineau 							   control->txseq);
5859d2a7ac5dSMat Martineau 
5860d2a7ac5dSMat Martineau 			chan->buffer_seq = chan->expected_tx_seq;
5861941247f9SPeter Senna Tschudin 			skb_in_use = true;
5862d2a7ac5dSMat Martineau 
5863d2a7ac5dSMat Martineau 			err = l2cap_reassemble_sdu(chan, skb, control);
5864d2a7ac5dSMat Martineau 			if (err)
5865d2a7ac5dSMat Martineau 				break;
5866d2a7ac5dSMat Martineau 
5867d2a7ac5dSMat Martineau 			if (control->final) {
5868d2a7ac5dSMat Martineau 				if (!test_and_clear_bit(CONN_REJ_ACT,
5869d2a7ac5dSMat Martineau 							&chan->conn_state)) {
5870d2a7ac5dSMat Martineau 					control->final = 0;
5871d2a7ac5dSMat Martineau 					l2cap_retransmit_all(chan, control);
5872d2a7ac5dSMat Martineau 					l2cap_ertm_send(chan);
5873d2a7ac5dSMat Martineau 				}
5874d2a7ac5dSMat Martineau 			}
5875d2a7ac5dSMat Martineau 
5876d2a7ac5dSMat Martineau 			if (!test_bit(CONN_LOCAL_BUSY, &chan->conn_state))
5877d2a7ac5dSMat Martineau 				l2cap_send_ack(chan);
5878d2a7ac5dSMat Martineau 			break;
5879d2a7ac5dSMat Martineau 		case L2CAP_TXSEQ_UNEXPECTED:
5880d2a7ac5dSMat Martineau 			l2cap_pass_to_tx(chan, control);
5881d2a7ac5dSMat Martineau 
5882d2a7ac5dSMat Martineau 			/* Can't issue SREJ frames in the local busy state.
5883d2a7ac5dSMat Martineau 			 * Drop this frame, it will be seen as missing
5884d2a7ac5dSMat Martineau 			 * when local busy is exited.
5885d2a7ac5dSMat Martineau 			 */
5886d2a7ac5dSMat Martineau 			if (test_bit(CONN_LOCAL_BUSY, &chan->conn_state)) {
5887d2a7ac5dSMat Martineau 				BT_DBG("Busy, discarding unexpected seq %d",
5888d2a7ac5dSMat Martineau 				       control->txseq);
5889d2a7ac5dSMat Martineau 				break;
5890d2a7ac5dSMat Martineau 			}
5891d2a7ac5dSMat Martineau 
5892d2a7ac5dSMat Martineau 			/* There was a gap in the sequence, so an SREJ
5893d2a7ac5dSMat Martineau 			 * must be sent for each missing frame.  The
5894d2a7ac5dSMat Martineau 			 * current frame is stored for later use.
5895d2a7ac5dSMat Martineau 			 */
5896d2a7ac5dSMat Martineau 			skb_queue_tail(&chan->srej_q, skb);
5897941247f9SPeter Senna Tschudin 			skb_in_use = true;
5898d2a7ac5dSMat Martineau 			BT_DBG("Queued %p (queue len %d)", skb,
5899d2a7ac5dSMat Martineau 			       skb_queue_len(&chan->srej_q));
5900d2a7ac5dSMat Martineau 
5901d2a7ac5dSMat Martineau 			clear_bit(CONN_SREJ_ACT, &chan->conn_state);
5902d2a7ac5dSMat Martineau 			l2cap_seq_list_clear(&chan->srej_list);
5903d2a7ac5dSMat Martineau 			l2cap_send_srej(chan, control->txseq);
5904d2a7ac5dSMat Martineau 
5905d2a7ac5dSMat Martineau 			chan->rx_state = L2CAP_RX_STATE_SREJ_SENT;
5906d2a7ac5dSMat Martineau 			break;
5907d2a7ac5dSMat Martineau 		case L2CAP_TXSEQ_DUPLICATE:
5908d2a7ac5dSMat Martineau 			l2cap_pass_to_tx(chan, control);
5909d2a7ac5dSMat Martineau 			break;
5910d2a7ac5dSMat Martineau 		case L2CAP_TXSEQ_INVALID_IGNORE:
5911d2a7ac5dSMat Martineau 			break;
5912d2a7ac5dSMat Martineau 		case L2CAP_TXSEQ_INVALID:
5913d2a7ac5dSMat Martineau 		default:
59145e4e3972SAndrei Emeltchenko 			l2cap_send_disconn_req(chan, ECONNRESET);
5915d2a7ac5dSMat Martineau 			break;
5916d2a7ac5dSMat Martineau 		}
5917d2a7ac5dSMat Martineau 		break;
5918d2a7ac5dSMat Martineau 	case L2CAP_EV_RECV_RR:
5919d2a7ac5dSMat Martineau 		l2cap_pass_to_tx(chan, control);
5920d2a7ac5dSMat Martineau 		if (control->final) {
5921d2a7ac5dSMat Martineau 			clear_bit(CONN_REMOTE_BUSY, &chan->conn_state);
5922d2a7ac5dSMat Martineau 
5923e6a3ee6eSMat Martineau 			if (!test_and_clear_bit(CONN_REJ_ACT, &chan->conn_state) &&
5924e6a3ee6eSMat Martineau 			    !__chan_is_moving(chan)) {
5925d2a7ac5dSMat Martineau 				control->final = 0;
5926d2a7ac5dSMat Martineau 				l2cap_retransmit_all(chan, control);
5927d2a7ac5dSMat Martineau 			}
5928d2a7ac5dSMat Martineau 
5929d2a7ac5dSMat Martineau 			l2cap_ertm_send(chan);
5930d2a7ac5dSMat Martineau 		} else if (control->poll) {
5931d2a7ac5dSMat Martineau 			l2cap_send_i_or_rr_or_rnr(chan);
5932d2a7ac5dSMat Martineau 		} else {
5933d2a7ac5dSMat Martineau 			if (test_and_clear_bit(CONN_REMOTE_BUSY,
5934d2a7ac5dSMat Martineau 					       &chan->conn_state) &&
5935d2a7ac5dSMat Martineau 			    chan->unacked_frames)
5936d2a7ac5dSMat Martineau 				__set_retrans_timer(chan);
5937d2a7ac5dSMat Martineau 
5938d2a7ac5dSMat Martineau 			l2cap_ertm_send(chan);
5939d2a7ac5dSMat Martineau 		}
5940d2a7ac5dSMat Martineau 		break;
5941d2a7ac5dSMat Martineau 	case L2CAP_EV_RECV_RNR:
5942d2a7ac5dSMat Martineau 		set_bit(CONN_REMOTE_BUSY, &chan->conn_state);
5943d2a7ac5dSMat Martineau 		l2cap_pass_to_tx(chan, control);
5944d2a7ac5dSMat Martineau 		if (control && control->poll) {
5945d2a7ac5dSMat Martineau 			set_bit(CONN_SEND_FBIT, &chan->conn_state);
5946d2a7ac5dSMat Martineau 			l2cap_send_rr_or_rnr(chan, 0);
5947d2a7ac5dSMat Martineau 		}
5948d2a7ac5dSMat Martineau 		__clear_retrans_timer(chan);
5949d2a7ac5dSMat Martineau 		l2cap_seq_list_clear(&chan->retrans_list);
5950d2a7ac5dSMat Martineau 		break;
5951d2a7ac5dSMat Martineau 	case L2CAP_EV_RECV_REJ:
5952d2a7ac5dSMat Martineau 		l2cap_handle_rej(chan, control);
5953d2a7ac5dSMat Martineau 		break;
5954d2a7ac5dSMat Martineau 	case L2CAP_EV_RECV_SREJ:
5955d2a7ac5dSMat Martineau 		l2cap_handle_srej(chan, control);
5956d2a7ac5dSMat Martineau 		break;
5957d2a7ac5dSMat Martineau 	default:
5958d2a7ac5dSMat Martineau 		break;
5959d2a7ac5dSMat Martineau 	}
5960d2a7ac5dSMat Martineau 
5961d2a7ac5dSMat Martineau 	if (skb && !skb_in_use) {
5962d2a7ac5dSMat Martineau 		BT_DBG("Freeing %p", skb);
5963d2a7ac5dSMat Martineau 		kfree_skb(skb);
5964d2a7ac5dSMat Martineau 	}
5965d2a7ac5dSMat Martineau 
5966d2a7ac5dSMat Martineau 	return err;
5967d2a7ac5dSMat Martineau }
5968d2a7ac5dSMat Martineau 
5969d2a7ac5dSMat Martineau static int l2cap_rx_state_srej_sent(struct l2cap_chan *chan,
5970d2a7ac5dSMat Martineau 				    struct l2cap_ctrl *control,
5971d2a7ac5dSMat Martineau 				    struct sk_buff *skb, u8 event)
5972d2a7ac5dSMat Martineau {
5973d2a7ac5dSMat Martineau 	int err = 0;
5974d2a7ac5dSMat Martineau 	u16 txseq = control->txseq;
5975941247f9SPeter Senna Tschudin 	bool skb_in_use = false;
5976d2a7ac5dSMat Martineau 
5977d2a7ac5dSMat Martineau 	BT_DBG("chan %p, control %p, skb %p, event %d", chan, control, skb,
5978d2a7ac5dSMat Martineau 	       event);
5979d2a7ac5dSMat Martineau 
5980d2a7ac5dSMat Martineau 	switch (event) {
5981d2a7ac5dSMat Martineau 	case L2CAP_EV_RECV_IFRAME:
5982d2a7ac5dSMat Martineau 		switch (l2cap_classify_txseq(chan, txseq)) {
5983d2a7ac5dSMat Martineau 		case L2CAP_TXSEQ_EXPECTED:
5984d2a7ac5dSMat Martineau 			/* Keep frame for reassembly later */
5985d2a7ac5dSMat Martineau 			l2cap_pass_to_tx(chan, control);
5986d2a7ac5dSMat Martineau 			skb_queue_tail(&chan->srej_q, skb);
5987941247f9SPeter Senna Tschudin 			skb_in_use = true;
5988d2a7ac5dSMat Martineau 			BT_DBG("Queued %p (queue len %d)", skb,
5989d2a7ac5dSMat Martineau 			       skb_queue_len(&chan->srej_q));
5990d2a7ac5dSMat Martineau 
5991d2a7ac5dSMat Martineau 			chan->expected_tx_seq = __next_seq(chan, txseq);
5992d2a7ac5dSMat Martineau 			break;
5993d2a7ac5dSMat Martineau 		case L2CAP_TXSEQ_EXPECTED_SREJ:
5994d2a7ac5dSMat Martineau 			l2cap_seq_list_pop(&chan->srej_list);
5995d2a7ac5dSMat Martineau 
5996d2a7ac5dSMat Martineau 			l2cap_pass_to_tx(chan, control);
5997d2a7ac5dSMat Martineau 			skb_queue_tail(&chan->srej_q, skb);
5998941247f9SPeter Senna Tschudin 			skb_in_use = true;
5999d2a7ac5dSMat Martineau 			BT_DBG("Queued %p (queue len %d)", skb,
6000d2a7ac5dSMat Martineau 			       skb_queue_len(&chan->srej_q));
6001d2a7ac5dSMat Martineau 
6002d2a7ac5dSMat Martineau 			err = l2cap_rx_queued_iframes(chan);
6003d2a7ac5dSMat Martineau 			if (err)
6004d2a7ac5dSMat Martineau 				break;
6005d2a7ac5dSMat Martineau 
6006d2a7ac5dSMat Martineau 			break;
6007d2a7ac5dSMat Martineau 		case L2CAP_TXSEQ_UNEXPECTED:
6008d2a7ac5dSMat Martineau 			/* Got a frame that can't be reassembled yet.
6009d2a7ac5dSMat Martineau 			 * Save it for later, and send SREJs to cover
6010d2a7ac5dSMat Martineau 			 * the missing frames.
6011d2a7ac5dSMat Martineau 			 */
6012d2a7ac5dSMat Martineau 			skb_queue_tail(&chan->srej_q, skb);
6013941247f9SPeter Senna Tschudin 			skb_in_use = true;
6014d2a7ac5dSMat Martineau 			BT_DBG("Queued %p (queue len %d)", skb,
6015d2a7ac5dSMat Martineau 			       skb_queue_len(&chan->srej_q));
6016d2a7ac5dSMat Martineau 
6017d2a7ac5dSMat Martineau 			l2cap_pass_to_tx(chan, control);
6018d2a7ac5dSMat Martineau 			l2cap_send_srej(chan, control->txseq);
6019d2a7ac5dSMat Martineau 			break;
6020d2a7ac5dSMat Martineau 		case L2CAP_TXSEQ_UNEXPECTED_SREJ:
6021d2a7ac5dSMat Martineau 			/* This frame was requested with an SREJ, but
6022d2a7ac5dSMat Martineau 			 * some expected retransmitted frames are
6023d2a7ac5dSMat Martineau 			 * missing.  Request retransmission of missing
6024d2a7ac5dSMat Martineau 			 * SREJ'd frames.
6025d2a7ac5dSMat Martineau 			 */
6026d2a7ac5dSMat Martineau 			skb_queue_tail(&chan->srej_q, skb);
6027941247f9SPeter Senna Tschudin 			skb_in_use = true;
6028d2a7ac5dSMat Martineau 			BT_DBG("Queued %p (queue len %d)", skb,
6029d2a7ac5dSMat Martineau 			       skb_queue_len(&chan->srej_q));
6030d2a7ac5dSMat Martineau 
6031d2a7ac5dSMat Martineau 			l2cap_pass_to_tx(chan, control);
6032d2a7ac5dSMat Martineau 			l2cap_send_srej_list(chan, control->txseq);
6033d2a7ac5dSMat Martineau 			break;
6034d2a7ac5dSMat Martineau 		case L2CAP_TXSEQ_DUPLICATE_SREJ:
6035d2a7ac5dSMat Martineau 			/* We've already queued this frame.  Drop this copy. */
6036d2a7ac5dSMat Martineau 			l2cap_pass_to_tx(chan, control);
6037d2a7ac5dSMat Martineau 			break;
6038d2a7ac5dSMat Martineau 		case L2CAP_TXSEQ_DUPLICATE:
6039d2a7ac5dSMat Martineau 			/* Expecting a later sequence number, so this frame
6040d2a7ac5dSMat Martineau 			 * was already received.  Ignore it completely.
6041d2a7ac5dSMat Martineau 			 */
6042d2a7ac5dSMat Martineau 			break;
6043d2a7ac5dSMat Martineau 		case L2CAP_TXSEQ_INVALID_IGNORE:
6044d2a7ac5dSMat Martineau 			break;
6045d2a7ac5dSMat Martineau 		case L2CAP_TXSEQ_INVALID:
6046d2a7ac5dSMat Martineau 		default:
60475e4e3972SAndrei Emeltchenko 			l2cap_send_disconn_req(chan, ECONNRESET);
6048d2a7ac5dSMat Martineau 			break;
6049d2a7ac5dSMat Martineau 		}
6050d2a7ac5dSMat Martineau 		break;
6051d2a7ac5dSMat Martineau 	case L2CAP_EV_RECV_RR:
6052d2a7ac5dSMat Martineau 		l2cap_pass_to_tx(chan, control);
6053d2a7ac5dSMat Martineau 		if (control->final) {
6054d2a7ac5dSMat Martineau 			clear_bit(CONN_REMOTE_BUSY, &chan->conn_state);
6055d2a7ac5dSMat Martineau 
6056d2a7ac5dSMat Martineau 			if (!test_and_clear_bit(CONN_REJ_ACT,
6057d2a7ac5dSMat Martineau 						&chan->conn_state)) {
6058d2a7ac5dSMat Martineau 				control->final = 0;
6059d2a7ac5dSMat Martineau 				l2cap_retransmit_all(chan, control);
6060d2a7ac5dSMat Martineau 			}
6061d2a7ac5dSMat Martineau 
6062d2a7ac5dSMat Martineau 			l2cap_ertm_send(chan);
6063d2a7ac5dSMat Martineau 		} else if (control->poll) {
6064d2a7ac5dSMat Martineau 			if (test_and_clear_bit(CONN_REMOTE_BUSY,
6065d2a7ac5dSMat Martineau 					       &chan->conn_state) &&
6066d2a7ac5dSMat Martineau 			    chan->unacked_frames) {
6067d2a7ac5dSMat Martineau 				__set_retrans_timer(chan);
6068d2a7ac5dSMat Martineau 			}
6069d2a7ac5dSMat Martineau 
6070d2a7ac5dSMat Martineau 			set_bit(CONN_SEND_FBIT, &chan->conn_state);
6071d2a7ac5dSMat Martineau 			l2cap_send_srej_tail(chan);
6072d2a7ac5dSMat Martineau 		} else {
6073d2a7ac5dSMat Martineau 			if (test_and_clear_bit(CONN_REMOTE_BUSY,
6074d2a7ac5dSMat Martineau 					       &chan->conn_state) &&
6075d2a7ac5dSMat Martineau 			    chan->unacked_frames)
6076d2a7ac5dSMat Martineau 				__set_retrans_timer(chan);
6077d2a7ac5dSMat Martineau 
6078d2a7ac5dSMat Martineau 			l2cap_send_ack(chan);
6079d2a7ac5dSMat Martineau 		}
6080d2a7ac5dSMat Martineau 		break;
6081d2a7ac5dSMat Martineau 	case L2CAP_EV_RECV_RNR:
6082d2a7ac5dSMat Martineau 		set_bit(CONN_REMOTE_BUSY, &chan->conn_state);
6083d2a7ac5dSMat Martineau 		l2cap_pass_to_tx(chan, control);
6084d2a7ac5dSMat Martineau 		if (control->poll) {
6085d2a7ac5dSMat Martineau 			l2cap_send_srej_tail(chan);
6086d2a7ac5dSMat Martineau 		} else {
6087d2a7ac5dSMat Martineau 			struct l2cap_ctrl rr_control;
6088d2a7ac5dSMat Martineau 			memset(&rr_control, 0, sizeof(rr_control));
6089d2a7ac5dSMat Martineau 			rr_control.sframe = 1;
6090d2a7ac5dSMat Martineau 			rr_control.super = L2CAP_SUPER_RR;
6091d2a7ac5dSMat Martineau 			rr_control.reqseq = chan->buffer_seq;
6092d2a7ac5dSMat Martineau 			l2cap_send_sframe(chan, &rr_control);
6093d2a7ac5dSMat Martineau 		}
6094d2a7ac5dSMat Martineau 
6095d2a7ac5dSMat Martineau 		break;
6096d2a7ac5dSMat Martineau 	case L2CAP_EV_RECV_REJ:
6097d2a7ac5dSMat Martineau 		l2cap_handle_rej(chan, control);
6098d2a7ac5dSMat Martineau 		break;
6099d2a7ac5dSMat Martineau 	case L2CAP_EV_RECV_SREJ:
6100d2a7ac5dSMat Martineau 		l2cap_handle_srej(chan, control);
6101d2a7ac5dSMat Martineau 		break;
6102d2a7ac5dSMat Martineau 	}
6103d2a7ac5dSMat Martineau 
6104d2a7ac5dSMat Martineau 	if (skb && !skb_in_use) {
6105d2a7ac5dSMat Martineau 		BT_DBG("Freeing %p", skb);
6106d2a7ac5dSMat Martineau 		kfree_skb(skb);
6107d2a7ac5dSMat Martineau 	}
6108d2a7ac5dSMat Martineau 
6109d2a7ac5dSMat Martineau 	return err;
6110d2a7ac5dSMat Martineau }
6111d2a7ac5dSMat Martineau 
611232b32735SMat Martineau static int l2cap_finish_move(struct l2cap_chan *chan)
611332b32735SMat Martineau {
611432b32735SMat Martineau 	BT_DBG("chan %p", chan);
611532b32735SMat Martineau 
611632b32735SMat Martineau 	chan->rx_state = L2CAP_RX_STATE_RECV;
611732b32735SMat Martineau 
611832b32735SMat Martineau 	if (chan->hs_hcon)
611932b32735SMat Martineau 		chan->conn->mtu = chan->hs_hcon->hdev->block_mtu;
612032b32735SMat Martineau 	else
612132b32735SMat Martineau 		chan->conn->mtu = chan->conn->hcon->hdev->acl_mtu;
612232b32735SMat Martineau 
612332b32735SMat Martineau 	return l2cap_resegment(chan);
612432b32735SMat Martineau }
612532b32735SMat Martineau 
612632b32735SMat Martineau static int l2cap_rx_state_wait_p(struct l2cap_chan *chan,
612732b32735SMat Martineau 				 struct l2cap_ctrl *control,
612832b32735SMat Martineau 				 struct sk_buff *skb, u8 event)
612932b32735SMat Martineau {
613032b32735SMat Martineau 	int err;
613132b32735SMat Martineau 
613232b32735SMat Martineau 	BT_DBG("chan %p, control %p, skb %p, event %d", chan, control, skb,
613332b32735SMat Martineau 	       event);
613432b32735SMat Martineau 
613532b32735SMat Martineau 	if (!control->poll)
613632b32735SMat Martineau 		return -EPROTO;
613732b32735SMat Martineau 
613832b32735SMat Martineau 	l2cap_process_reqseq(chan, control->reqseq);
613932b32735SMat Martineau 
614032b32735SMat Martineau 	if (!skb_queue_empty(&chan->tx_q))
614132b32735SMat Martineau 		chan->tx_send_head = skb_peek(&chan->tx_q);
614232b32735SMat Martineau 	else
614332b32735SMat Martineau 		chan->tx_send_head = NULL;
614432b32735SMat Martineau 
614532b32735SMat Martineau 	/* Rewind next_tx_seq to the point expected
614632b32735SMat Martineau 	 * by the receiver.
614732b32735SMat Martineau 	 */
614832b32735SMat Martineau 	chan->next_tx_seq = control->reqseq;
614932b32735SMat Martineau 	chan->unacked_frames = 0;
615032b32735SMat Martineau 
615132b32735SMat Martineau 	err = l2cap_finish_move(chan);
615232b32735SMat Martineau 	if (err)
615332b32735SMat Martineau 		return err;
615432b32735SMat Martineau 
615532b32735SMat Martineau 	set_bit(CONN_SEND_FBIT, &chan->conn_state);
615632b32735SMat Martineau 	l2cap_send_i_or_rr_or_rnr(chan);
615732b32735SMat Martineau 
615832b32735SMat Martineau 	if (event == L2CAP_EV_RECV_IFRAME)
615932b32735SMat Martineau 		return -EPROTO;
616032b32735SMat Martineau 
616132b32735SMat Martineau 	return l2cap_rx_state_recv(chan, control, NULL, event);
616232b32735SMat Martineau }
616332b32735SMat Martineau 
616432b32735SMat Martineau static int l2cap_rx_state_wait_f(struct l2cap_chan *chan,
616532b32735SMat Martineau 				 struct l2cap_ctrl *control,
616632b32735SMat Martineau 				 struct sk_buff *skb, u8 event)
616732b32735SMat Martineau {
616832b32735SMat Martineau 	int err;
616932b32735SMat Martineau 
617032b32735SMat Martineau 	if (!control->final)
617132b32735SMat Martineau 		return -EPROTO;
617232b32735SMat Martineau 
617332b32735SMat Martineau 	clear_bit(CONN_REMOTE_BUSY, &chan->conn_state);
617432b32735SMat Martineau 
617532b32735SMat Martineau 	chan->rx_state = L2CAP_RX_STATE_RECV;
617632b32735SMat Martineau 	l2cap_process_reqseq(chan, control->reqseq);
617732b32735SMat Martineau 
617832b32735SMat Martineau 	if (!skb_queue_empty(&chan->tx_q))
617932b32735SMat Martineau 		chan->tx_send_head = skb_peek(&chan->tx_q);
618032b32735SMat Martineau 	else
618132b32735SMat Martineau 		chan->tx_send_head = NULL;
618232b32735SMat Martineau 
618332b32735SMat Martineau 	/* Rewind next_tx_seq to the point expected
618432b32735SMat Martineau 	 * by the receiver.
618532b32735SMat Martineau 	 */
618632b32735SMat Martineau 	chan->next_tx_seq = control->reqseq;
618732b32735SMat Martineau 	chan->unacked_frames = 0;
618832b32735SMat Martineau 
618932b32735SMat Martineau 	if (chan->hs_hcon)
619032b32735SMat Martineau 		chan->conn->mtu = chan->hs_hcon->hdev->block_mtu;
619132b32735SMat Martineau 	else
619232b32735SMat Martineau 		chan->conn->mtu = chan->conn->hcon->hdev->acl_mtu;
619332b32735SMat Martineau 
619432b32735SMat Martineau 	err = l2cap_resegment(chan);
619532b32735SMat Martineau 
619632b32735SMat Martineau 	if (!err)
619732b32735SMat Martineau 		err = l2cap_rx_state_recv(chan, control, skb, event);
619832b32735SMat Martineau 
619932b32735SMat Martineau 	return err;
620032b32735SMat Martineau }
620132b32735SMat Martineau 
6202d2a7ac5dSMat Martineau static bool __valid_reqseq(struct l2cap_chan *chan, u16 reqseq)
6203d2a7ac5dSMat Martineau {
6204d2a7ac5dSMat Martineau 	/* Make sure reqseq is for a packet that has been sent but not acked */
6205d2a7ac5dSMat Martineau 	u16 unacked;
6206d2a7ac5dSMat Martineau 
6207d2a7ac5dSMat Martineau 	unacked = __seq_offset(chan, chan->next_tx_seq, chan->expected_ack_seq);
6208d2a7ac5dSMat Martineau 	return __seq_offset(chan, chan->next_tx_seq, reqseq) <= unacked;
6209d2a7ac5dSMat Martineau }
6210d2a7ac5dSMat Martineau 
6211cec8ab6eSMat Martineau static int l2cap_rx(struct l2cap_chan *chan, struct l2cap_ctrl *control,
6212cec8ab6eSMat Martineau 		    struct sk_buff *skb, u8 event)
62130a708f8fSGustavo F. Padovan {
6214d2a7ac5dSMat Martineau 	int err = 0;
6215d2a7ac5dSMat Martineau 
6216d2a7ac5dSMat Martineau 	BT_DBG("chan %p, control %p, skb %p, event %d, state %d", chan,
6217d2a7ac5dSMat Martineau 	       control, skb, event, chan->rx_state);
6218d2a7ac5dSMat Martineau 
6219d2a7ac5dSMat Martineau 	if (__valid_reqseq(chan, control->reqseq)) {
6220d2a7ac5dSMat Martineau 		switch (chan->rx_state) {
6221d2a7ac5dSMat Martineau 		case L2CAP_RX_STATE_RECV:
6222d2a7ac5dSMat Martineau 			err = l2cap_rx_state_recv(chan, control, skb, event);
6223d2a7ac5dSMat Martineau 			break;
6224d2a7ac5dSMat Martineau 		case L2CAP_RX_STATE_SREJ_SENT:
6225d2a7ac5dSMat Martineau 			err = l2cap_rx_state_srej_sent(chan, control, skb,
6226d2a7ac5dSMat Martineau 						       event);
6227d2a7ac5dSMat Martineau 			break;
622832b32735SMat Martineau 		case L2CAP_RX_STATE_WAIT_P:
622932b32735SMat Martineau 			err = l2cap_rx_state_wait_p(chan, control, skb, event);
623032b32735SMat Martineau 			break;
623132b32735SMat Martineau 		case L2CAP_RX_STATE_WAIT_F:
623232b32735SMat Martineau 			err = l2cap_rx_state_wait_f(chan, control, skb, event);
623332b32735SMat Martineau 			break;
6234d2a7ac5dSMat Martineau 		default:
6235d2a7ac5dSMat Martineau 			/* shut it down */
6236d2a7ac5dSMat Martineau 			break;
6237d2a7ac5dSMat Martineau 		}
6238d2a7ac5dSMat Martineau 	} else {
6239d2a7ac5dSMat Martineau 		BT_DBG("Invalid reqseq %d (next_tx_seq %d, expected_ack_seq %d",
6240d2a7ac5dSMat Martineau 		       control->reqseq, chan->next_tx_seq,
6241d2a7ac5dSMat Martineau 		       chan->expected_ack_seq);
62425e4e3972SAndrei Emeltchenko 		l2cap_send_disconn_req(chan, ECONNRESET);
6243d2a7ac5dSMat Martineau 	}
6244d2a7ac5dSMat Martineau 
6245d2a7ac5dSMat Martineau 	return err;
6246cec8ab6eSMat Martineau }
6247cec8ab6eSMat Martineau 
6248cec8ab6eSMat Martineau static int l2cap_stream_rx(struct l2cap_chan *chan, struct l2cap_ctrl *control,
6249cec8ab6eSMat Martineau 			   struct sk_buff *skb)
6250cec8ab6eSMat Martineau {
62514b51dae9SMat Martineau 	int err = 0;
62524b51dae9SMat Martineau 
62534b51dae9SMat Martineau 	BT_DBG("chan %p, control %p, skb %p, state %d", chan, control, skb,
62544b51dae9SMat Martineau 	       chan->rx_state);
62554b51dae9SMat Martineau 
62564b51dae9SMat Martineau 	if (l2cap_classify_txseq(chan, control->txseq) ==
62574b51dae9SMat Martineau 	    L2CAP_TXSEQ_EXPECTED) {
62584b51dae9SMat Martineau 		l2cap_pass_to_tx(chan, control);
62594b51dae9SMat Martineau 
62604b51dae9SMat Martineau 		BT_DBG("buffer_seq %d->%d", chan->buffer_seq,
62614b51dae9SMat Martineau 		       __next_seq(chan, chan->buffer_seq));
62624b51dae9SMat Martineau 
62634b51dae9SMat Martineau 		chan->buffer_seq = __next_seq(chan, chan->buffer_seq);
62644b51dae9SMat Martineau 
62654b51dae9SMat Martineau 		l2cap_reassemble_sdu(chan, skb, control);
62664b51dae9SMat Martineau 	} else {
62674b51dae9SMat Martineau 		if (chan->sdu) {
62684b51dae9SMat Martineau 			kfree_skb(chan->sdu);
62694b51dae9SMat Martineau 			chan->sdu = NULL;
62704b51dae9SMat Martineau 		}
62714b51dae9SMat Martineau 		chan->sdu_last_frag = NULL;
62724b51dae9SMat Martineau 		chan->sdu_len = 0;
62734b51dae9SMat Martineau 
62744b51dae9SMat Martineau 		if (skb) {
62754b51dae9SMat Martineau 			BT_DBG("Freeing %p", skb);
62764b51dae9SMat Martineau 			kfree_skb(skb);
62774b51dae9SMat Martineau 		}
62784b51dae9SMat Martineau 	}
62794b51dae9SMat Martineau 
62804b51dae9SMat Martineau 	chan->last_acked_seq = control->txseq;
62814b51dae9SMat Martineau 	chan->expected_tx_seq = __next_seq(chan, control->txseq);
62824b51dae9SMat Martineau 
62834b51dae9SMat Martineau 	return err;
6284cec8ab6eSMat Martineau }
6285cec8ab6eSMat Martineau 
6286cec8ab6eSMat Martineau static int l2cap_data_rcv(struct l2cap_chan *chan, struct sk_buff *skb)
6287cec8ab6eSMat Martineau {
6288cec8ab6eSMat Martineau 	struct l2cap_ctrl *control = &bt_cb(skb)->control;
6289cec8ab6eSMat Martineau 	u16 len;
6290cec8ab6eSMat Martineau 	u8 event;
62910a708f8fSGustavo F. Padovan 
6292b76bbd66SMat Martineau 	__unpack_control(chan, skb);
6293b76bbd66SMat Martineau 
62940a708f8fSGustavo F. Padovan 	len = skb->len;
62950a708f8fSGustavo F. Padovan 
62960a708f8fSGustavo F. Padovan 	/*
62970a708f8fSGustavo F. Padovan 	 * We can just drop the corrupted I-frame here.
62980a708f8fSGustavo F. Padovan 	 * Receiver will miss it and start proper recovery
6299cec8ab6eSMat Martineau 	 * procedures and ask for retransmission.
63000a708f8fSGustavo F. Padovan 	 */
630147d1ec61SGustavo F. Padovan 	if (l2cap_check_fcs(chan, skb))
63020a708f8fSGustavo F. Padovan 		goto drop;
63030a708f8fSGustavo F. Padovan 
6304cec8ab6eSMat Martineau 	if (!control->sframe && control->sar == L2CAP_SAR_START)
630503a51213SAndrei Emeltchenko 		len -= L2CAP_SDULEN_SIZE;
63060a708f8fSGustavo F. Padovan 
630747d1ec61SGustavo F. Padovan 	if (chan->fcs == L2CAP_FCS_CRC16)
630803a51213SAndrei Emeltchenko 		len -= L2CAP_FCS_SIZE;
63090a708f8fSGustavo F. Padovan 
631047d1ec61SGustavo F. Padovan 	if (len > chan->mps) {
63115e4e3972SAndrei Emeltchenko 		l2cap_send_disconn_req(chan, ECONNRESET);
63120a708f8fSGustavo F. Padovan 		goto drop;
63130a708f8fSGustavo F. Padovan 	}
63140a708f8fSGustavo F. Padovan 
6315cec8ab6eSMat Martineau 	if (!control->sframe) {
6316cec8ab6eSMat Martineau 		int err;
63170a708f8fSGustavo F. Padovan 
6318cec8ab6eSMat Martineau 		BT_DBG("iframe sar %d, reqseq %d, final %d, txseq %d",
6319cec8ab6eSMat Martineau 		       control->sar, control->reqseq, control->final,
6320cec8ab6eSMat Martineau 		       control->txseq);
6321836be934SAndrei Emeltchenko 
6322cec8ab6eSMat Martineau 		/* Validate F-bit - F=0 always valid, F=1 only
6323cec8ab6eSMat Martineau 		 * valid in TX WAIT_F
6324cec8ab6eSMat Martineau 		 */
6325cec8ab6eSMat Martineau 		if (control->final && chan->tx_state != L2CAP_TX_STATE_WAIT_F)
63260a708f8fSGustavo F. Padovan 			goto drop;
63270a708f8fSGustavo F. Padovan 
6328cec8ab6eSMat Martineau 		if (chan->mode != L2CAP_MODE_STREAMING) {
6329cec8ab6eSMat Martineau 			event = L2CAP_EV_RECV_IFRAME;
6330cec8ab6eSMat Martineau 			err = l2cap_rx(chan, control, skb, event);
63310a708f8fSGustavo F. Padovan 		} else {
6332cec8ab6eSMat Martineau 			err = l2cap_stream_rx(chan, control, skb);
6333cec8ab6eSMat Martineau 		}
6334cec8ab6eSMat Martineau 
6335cec8ab6eSMat Martineau 		if (err)
63365e4e3972SAndrei Emeltchenko 			l2cap_send_disconn_req(chan, ECONNRESET);
6337cec8ab6eSMat Martineau 	} else {
6338cec8ab6eSMat Martineau 		const u8 rx_func_to_event[4] = {
6339cec8ab6eSMat Martineau 			L2CAP_EV_RECV_RR, L2CAP_EV_RECV_REJ,
6340cec8ab6eSMat Martineau 			L2CAP_EV_RECV_RNR, L2CAP_EV_RECV_SREJ
6341cec8ab6eSMat Martineau 		};
6342cec8ab6eSMat Martineau 
6343cec8ab6eSMat Martineau 		/* Only I-frames are expected in streaming mode */
6344cec8ab6eSMat Martineau 		if (chan->mode == L2CAP_MODE_STREAMING)
6345cec8ab6eSMat Martineau 			goto drop;
6346cec8ab6eSMat Martineau 
6347cec8ab6eSMat Martineau 		BT_DBG("sframe reqseq %d, final %d, poll %d, super %d",
6348cec8ab6eSMat Martineau 		       control->reqseq, control->final, control->poll,
6349cec8ab6eSMat Martineau 		       control->super);
6350cec8ab6eSMat Martineau 
63510a708f8fSGustavo F. Padovan 		if (len != 0) {
63521bb166e6SAndrei Emeltchenko 			BT_ERR("Trailing bytes: %d in sframe", len);
63535e4e3972SAndrei Emeltchenko 			l2cap_send_disconn_req(chan, ECONNRESET);
63540a708f8fSGustavo F. Padovan 			goto drop;
63550a708f8fSGustavo F. Padovan 		}
63560a708f8fSGustavo F. Padovan 
6357cec8ab6eSMat Martineau 		/* Validate F and P bits */
6358cec8ab6eSMat Martineau 		if (control->final && (control->poll ||
6359cec8ab6eSMat Martineau 				       chan->tx_state != L2CAP_TX_STATE_WAIT_F))
6360cec8ab6eSMat Martineau 			goto drop;
6361cec8ab6eSMat Martineau 
6362cec8ab6eSMat Martineau 		event = rx_func_to_event[control->super];
6363cec8ab6eSMat Martineau 		if (l2cap_rx(chan, control, skb, event))
63645e4e3972SAndrei Emeltchenko 			l2cap_send_disconn_req(chan, ECONNRESET);
63650a708f8fSGustavo F. Padovan 	}
63660a708f8fSGustavo F. Padovan 
63670a708f8fSGustavo F. Padovan 	return 0;
63680a708f8fSGustavo F. Padovan 
63690a708f8fSGustavo F. Padovan drop:
63700a708f8fSGustavo F. Padovan 	kfree_skb(skb);
63710a708f8fSGustavo F. Padovan 	return 0;
63720a708f8fSGustavo F. Padovan }
63730a708f8fSGustavo F. Padovan 
637413ca56e0SAndrei Emeltchenko static void l2cap_data_channel(struct l2cap_conn *conn, u16 cid,
637513ca56e0SAndrei Emeltchenko 			       struct sk_buff *skb)
63760a708f8fSGustavo F. Padovan {
637748454079SGustavo F. Padovan 	struct l2cap_chan *chan;
63780a708f8fSGustavo F. Padovan 
6379baa7e1faSGustavo F. Padovan 	chan = l2cap_get_chan_by_scid(conn, cid);
638048454079SGustavo F. Padovan 	if (!chan) {
638197e8e89dSAndrei Emeltchenko 		if (cid == L2CAP_CID_A2MP) {
638297e8e89dSAndrei Emeltchenko 			chan = a2mp_channel_create(conn, skb);
638397e8e89dSAndrei Emeltchenko 			if (!chan) {
638497e8e89dSAndrei Emeltchenko 				kfree_skb(skb);
638513ca56e0SAndrei Emeltchenko 				return;
638697e8e89dSAndrei Emeltchenko 			}
638797e8e89dSAndrei Emeltchenko 
638897e8e89dSAndrei Emeltchenko 			l2cap_chan_lock(chan);
638997e8e89dSAndrei Emeltchenko 		} else {
63900a708f8fSGustavo F. Padovan 			BT_DBG("unknown cid 0x%4.4x", cid);
63916be36555SAndrei Emeltchenko 			/* Drop packet and return */
63923379013bSDan Carpenter 			kfree_skb(skb);
639313ca56e0SAndrei Emeltchenko 			return;
63940a708f8fSGustavo F. Padovan 		}
639597e8e89dSAndrei Emeltchenko 	}
63960a708f8fSGustavo F. Padovan 
639749208c9cSGustavo F. Padovan 	BT_DBG("chan %p, len %d", chan, skb->len);
63980a708f8fSGustavo F. Padovan 
639989bc500eSGustavo F. Padovan 	if (chan->state != BT_CONNECTED)
64000a708f8fSGustavo F. Padovan 		goto drop;
64010a708f8fSGustavo F. Padovan 
64020c1bc5c6SGustavo F. Padovan 	switch (chan->mode) {
64030a708f8fSGustavo F. Padovan 	case L2CAP_MODE_BASIC:
64040a708f8fSGustavo F. Padovan 		/* If socket recv buffers overflows we drop data here
64050a708f8fSGustavo F. Padovan 		 * which is *bad* because L2CAP has to be reliable.
64060a708f8fSGustavo F. Padovan 		 * But we don't have any other choice. L2CAP doesn't
64070a708f8fSGustavo F. Padovan 		 * provide flow control mechanism. */
64080a708f8fSGustavo F. Padovan 
64090c1bc5c6SGustavo F. Padovan 		if (chan->imtu < skb->len)
64100a708f8fSGustavo F. Padovan 			goto drop;
64110a708f8fSGustavo F. Padovan 
641280b98027SGustavo Padovan 		if (!chan->ops->recv(chan, skb))
64130a708f8fSGustavo F. Padovan 			goto done;
64140a708f8fSGustavo F. Padovan 		break;
64150a708f8fSGustavo F. Padovan 
64160a708f8fSGustavo F. Padovan 	case L2CAP_MODE_ERTM:
64170a708f8fSGustavo F. Padovan 	case L2CAP_MODE_STREAMING:
6418cec8ab6eSMat Martineau 		l2cap_data_rcv(chan, skb);
64190a708f8fSGustavo F. Padovan 		goto done;
64200a708f8fSGustavo F. Padovan 
64210a708f8fSGustavo F. Padovan 	default:
64220c1bc5c6SGustavo F. Padovan 		BT_DBG("chan %p: bad mode 0x%2.2x", chan, chan->mode);
64230a708f8fSGustavo F. Padovan 		break;
64240a708f8fSGustavo F. Padovan 	}
64250a708f8fSGustavo F. Padovan 
64260a708f8fSGustavo F. Padovan drop:
64270a708f8fSGustavo F. Padovan 	kfree_skb(skb);
64280a708f8fSGustavo F. Padovan 
64290a708f8fSGustavo F. Padovan done:
64306be36555SAndrei Emeltchenko 	l2cap_chan_unlock(chan);
64310a708f8fSGustavo F. Padovan }
64320a708f8fSGustavo F. Padovan 
643384104b24SAndrei Emeltchenko static void l2cap_conless_channel(struct l2cap_conn *conn, __le16 psm,
643484104b24SAndrei Emeltchenko 				  struct sk_buff *skb)
64350a708f8fSGustavo F. Padovan {
6436ae4fd2d3SMarcel Holtmann 	struct hci_conn *hcon = conn->hcon;
643723691d75SGustavo F. Padovan 	struct l2cap_chan *chan;
64380a708f8fSGustavo F. Padovan 
6439ae4fd2d3SMarcel Holtmann 	if (hcon->type != ACL_LINK)
6440ae4fd2d3SMarcel Holtmann 		goto drop;
6441ae4fd2d3SMarcel Holtmann 
64426f59b904SMarcel Holtmann 	chan = l2cap_global_chan_by_psm(0, psm, &conn->hcon->src,
644398e0f7eaSMarcel Holtmann 					&conn->hcon->dst);
644423691d75SGustavo F. Padovan 	if (!chan)
64450a708f8fSGustavo F. Padovan 		goto drop;
64460a708f8fSGustavo F. Padovan 
64475b4cedaaSAndrei Emeltchenko 	BT_DBG("chan %p, len %d", chan, skb->len);
64480a708f8fSGustavo F. Padovan 
644989bc500eSGustavo F. Padovan 	if (chan->state != BT_BOUND && chan->state != BT_CONNECTED)
64500a708f8fSGustavo F. Padovan 		goto drop;
64510a708f8fSGustavo F. Padovan 
6452e13e21dcSVinicius Costa Gomes 	if (chan->imtu < skb->len)
64530a708f8fSGustavo F. Padovan 		goto drop;
64540a708f8fSGustavo F. Padovan 
64552edf870dSMarcel Holtmann 	/* Store remote BD_ADDR and PSM for msg_name */
64562edf870dSMarcel Holtmann 	bacpy(&bt_cb(skb)->bdaddr, &conn->hcon->dst);
64572edf870dSMarcel Holtmann 	bt_cb(skb)->psm = psm;
64582edf870dSMarcel Holtmann 
645980b98027SGustavo Padovan 	if (!chan->ops->recv(chan, skb))
646084104b24SAndrei Emeltchenko 		return;
64610a708f8fSGustavo F. Padovan 
64620a708f8fSGustavo F. Padovan drop:
64630a708f8fSGustavo F. Padovan 	kfree_skb(skb);
64640a708f8fSGustavo F. Padovan }
64650a708f8fSGustavo F. Padovan 
646672f78356SMarcel Holtmann static void l2cap_att_channel(struct l2cap_conn *conn,
6467d9b88702SAndrei Emeltchenko 			      struct sk_buff *skb)
64689f69bda6SGustavo F. Padovan {
6469b99707d7SMarcel Holtmann 	struct hci_conn *hcon = conn->hcon;
647023691d75SGustavo F. Padovan 	struct l2cap_chan *chan;
64719f69bda6SGustavo F. Padovan 
6472b99707d7SMarcel Holtmann 	if (hcon->type != LE_LINK)
6473b99707d7SMarcel Holtmann 		goto drop;
6474b99707d7SMarcel Holtmann 
6475af1c0134SJohan Hedberg 	chan = l2cap_global_chan_by_scid(BT_CONNECTED, L2CAP_CID_ATT,
64766f59b904SMarcel Holtmann 					 &conn->hcon->src, &conn->hcon->dst);
647723691d75SGustavo F. Padovan 	if (!chan)
64789f69bda6SGustavo F. Padovan 		goto drop;
64799f69bda6SGustavo F. Padovan 
64805b4cedaaSAndrei Emeltchenko 	BT_DBG("chan %p, len %d", chan, skb->len);
64819f69bda6SGustavo F. Padovan 
6482e13e21dcSVinicius Costa Gomes 	if (chan->imtu < skb->len)
64839f69bda6SGustavo F. Padovan 		goto drop;
64849f69bda6SGustavo F. Padovan 
648580b98027SGustavo Padovan 	if (!chan->ops->recv(chan, skb))
64866810fca7SAndrei Emeltchenko 		return;
64879f69bda6SGustavo F. Padovan 
64889f69bda6SGustavo F. Padovan drop:
64899f69bda6SGustavo F. Padovan 	kfree_skb(skb);
64909f69bda6SGustavo F. Padovan }
64919f69bda6SGustavo F. Padovan 
64920a708f8fSGustavo F. Padovan static void l2cap_recv_frame(struct l2cap_conn *conn, struct sk_buff *skb)
64930a708f8fSGustavo F. Padovan {
64940a708f8fSGustavo F. Padovan 	struct l2cap_hdr *lh = (void *) skb->data;
64950a708f8fSGustavo F. Padovan 	u16 cid, len;
64960a708f8fSGustavo F. Padovan 	__le16 psm;
64970a708f8fSGustavo F. Padovan 
64980a708f8fSGustavo F. Padovan 	skb_pull(skb, L2CAP_HDR_SIZE);
64990a708f8fSGustavo F. Padovan 	cid = __le16_to_cpu(lh->cid);
65000a708f8fSGustavo F. Padovan 	len = __le16_to_cpu(lh->len);
65010a708f8fSGustavo F. Padovan 
65020a708f8fSGustavo F. Padovan 	if (len != skb->len) {
65030a708f8fSGustavo F. Padovan 		kfree_skb(skb);
65040a708f8fSGustavo F. Padovan 		return;
65050a708f8fSGustavo F. Padovan 	}
65060a708f8fSGustavo F. Padovan 
65070a708f8fSGustavo F. Padovan 	BT_DBG("len %d, cid 0x%4.4x", len, cid);
65080a708f8fSGustavo F. Padovan 
65090a708f8fSGustavo F. Padovan 	switch (cid) {
65100a708f8fSGustavo F. Padovan 	case L2CAP_CID_SIGNALING:
65110a708f8fSGustavo F. Padovan 		l2cap_sig_channel(conn, skb);
65120a708f8fSGustavo F. Padovan 		break;
65130a708f8fSGustavo F. Padovan 
65140a708f8fSGustavo F. Padovan 	case L2CAP_CID_CONN_LESS:
6515097db76cSAndrei Emeltchenko 		psm = get_unaligned((__le16 *) skb->data);
65160181a70fSAndrei Emeltchenko 		skb_pull(skb, L2CAP_PSMLEN_SIZE);
65170a708f8fSGustavo F. Padovan 		l2cap_conless_channel(conn, psm, skb);
65180a708f8fSGustavo F. Padovan 		break;
65190a708f8fSGustavo F. Padovan 
6520073d1cf3SJohan Hedberg 	case L2CAP_CID_ATT:
652172f78356SMarcel Holtmann 		l2cap_att_channel(conn, skb);
65229f69bda6SGustavo F. Padovan 		break;
65239f69bda6SGustavo F. Padovan 
6524a2877629SMarcel Holtmann 	case L2CAP_CID_LE_SIGNALING:
6525a2877629SMarcel Holtmann 		l2cap_le_sig_channel(conn, skb);
6526a2877629SMarcel Holtmann 		break;
6527a2877629SMarcel Holtmann 
6528b501d6a1SAnderson Briglia 	case L2CAP_CID_SMP:
6529b501d6a1SAnderson Briglia 		if (smp_sig_channel(conn, skb))
6530b501d6a1SAnderson Briglia 			l2cap_conn_del(conn->hcon, EACCES);
6531b501d6a1SAnderson Briglia 		break;
6532b501d6a1SAnderson Briglia 
65330a708f8fSGustavo F. Padovan 	default:
65340a708f8fSGustavo F. Padovan 		l2cap_data_channel(conn, cid, skb);
65350a708f8fSGustavo F. Padovan 		break;
65360a708f8fSGustavo F. Padovan 	}
65370a708f8fSGustavo F. Padovan }
65380a708f8fSGustavo F. Padovan 
65390a708f8fSGustavo F. Padovan /* ---- L2CAP interface with lower layer (HCI) ---- */
65400a708f8fSGustavo F. Padovan 
6541686ebf28SUlisses Furquim int l2cap_connect_ind(struct hci_dev *hdev, bdaddr_t *bdaddr)
65420a708f8fSGustavo F. Padovan {
65430a708f8fSGustavo F. Padovan 	int exact = 0, lm1 = 0, lm2 = 0;
654423691d75SGustavo F. Padovan 	struct l2cap_chan *c;
65450a708f8fSGustavo F. Padovan 
65466ed93dc6SAndrei Emeltchenko 	BT_DBG("hdev %s, bdaddr %pMR", hdev->name, bdaddr);
65470a708f8fSGustavo F. Padovan 
65480a708f8fSGustavo F. Padovan 	/* Find listening sockets and check their link_mode */
654923691d75SGustavo F. Padovan 	read_lock(&chan_list_lock);
655023691d75SGustavo F. Padovan 	list_for_each_entry(c, &chan_list, global_l) {
655189bc500eSGustavo F. Padovan 		if (c->state != BT_LISTEN)
65520a708f8fSGustavo F. Padovan 			continue;
65530a708f8fSGustavo F. Padovan 
65547eafc59eSMarcel Holtmann 		if (!bacmp(&c->src, &hdev->bdaddr)) {
65550a708f8fSGustavo F. Padovan 			lm1 |= HCI_LM_ACCEPT;
655643bd0f32SAndrei Emeltchenko 			if (test_bit(FLAG_ROLE_SWITCH, &c->flags))
65570a708f8fSGustavo F. Padovan 				lm1 |= HCI_LM_MASTER;
65580a708f8fSGustavo F. Padovan 			exact++;
65597eafc59eSMarcel Holtmann 		} else if (!bacmp(&c->src, BDADDR_ANY)) {
65600a708f8fSGustavo F. Padovan 			lm2 |= HCI_LM_ACCEPT;
656143bd0f32SAndrei Emeltchenko 			if (test_bit(FLAG_ROLE_SWITCH, &c->flags))
65620a708f8fSGustavo F. Padovan 				lm2 |= HCI_LM_MASTER;
65630a708f8fSGustavo F. Padovan 		}
65640a708f8fSGustavo F. Padovan 	}
656523691d75SGustavo F. Padovan 	read_unlock(&chan_list_lock);
65660a708f8fSGustavo F. Padovan 
65670a708f8fSGustavo F. Padovan 	return exact ? lm1 : lm2;
65680a708f8fSGustavo F. Padovan }
65690a708f8fSGustavo F. Padovan 
65709e664631SAndrei Emeltchenko void l2cap_connect_cfm(struct hci_conn *hcon, u8 status)
65710a708f8fSGustavo F. Padovan {
65720a708f8fSGustavo F. Padovan 	struct l2cap_conn *conn;
65730a708f8fSGustavo F. Padovan 
65746ed93dc6SAndrei Emeltchenko 	BT_DBG("hcon %p bdaddr %pMR status %d", hcon, &hcon->dst, status);
65750a708f8fSGustavo F. Padovan 
65760a708f8fSGustavo F. Padovan 	if (!status) {
6577baf43251SClaudio Takahasi 		conn = l2cap_conn_add(hcon);
65780a708f8fSGustavo F. Padovan 		if (conn)
65790a708f8fSGustavo F. Padovan 			l2cap_conn_ready(conn);
6580ba6fc317SAndrei Emeltchenko 	} else {
6581e175072fSJoe Perches 		l2cap_conn_del(hcon, bt_to_errno(status));
6582ba6fc317SAndrei Emeltchenko 	}
65830a708f8fSGustavo F. Padovan }
65840a708f8fSGustavo F. Padovan 
6585686ebf28SUlisses Furquim int l2cap_disconn_ind(struct hci_conn *hcon)
65860a708f8fSGustavo F. Padovan {
65870a708f8fSGustavo F. Padovan 	struct l2cap_conn *conn = hcon->l2cap_data;
65880a708f8fSGustavo F. Padovan 
65890a708f8fSGustavo F. Padovan 	BT_DBG("hcon %p", hcon);
65900a708f8fSGustavo F. Padovan 
6591686ebf28SUlisses Furquim 	if (!conn)
65929f5a0d7bSAndrei Emeltchenko 		return HCI_ERROR_REMOTE_USER_TERM;
65930a708f8fSGustavo F. Padovan 	return conn->disc_reason;
65940a708f8fSGustavo F. Padovan }
65950a708f8fSGustavo F. Padovan 
65969e664631SAndrei Emeltchenko void l2cap_disconn_cfm(struct hci_conn *hcon, u8 reason)
65970a708f8fSGustavo F. Padovan {
65980a708f8fSGustavo F. Padovan 	BT_DBG("hcon %p reason %d", hcon, reason);
65990a708f8fSGustavo F. Padovan 
6600e175072fSJoe Perches 	l2cap_conn_del(hcon, bt_to_errno(reason));
66010a708f8fSGustavo F. Padovan }
66020a708f8fSGustavo F. Padovan 
66034343478fSGustavo F. Padovan static inline void l2cap_check_encryption(struct l2cap_chan *chan, u8 encrypt)
66040a708f8fSGustavo F. Padovan {
6605715ec005SGustavo F. Padovan 	if (chan->chan_type != L2CAP_CHAN_CONN_ORIENTED)
66060a708f8fSGustavo F. Padovan 		return;
66070a708f8fSGustavo F. Padovan 
66080a708f8fSGustavo F. Padovan 	if (encrypt == 0x00) {
66094343478fSGustavo F. Padovan 		if (chan->sec_level == BT_SECURITY_MEDIUM) {
6610ba13ccd9SMarcel Holtmann 			__set_chan_timer(chan, L2CAP_ENC_TIMEOUT);
66114343478fSGustavo F. Padovan 		} else if (chan->sec_level == BT_SECURITY_HIGH)
66120f852724SGustavo F. Padovan 			l2cap_chan_close(chan, ECONNREFUSED);
66130a708f8fSGustavo F. Padovan 	} else {
66144343478fSGustavo F. Padovan 		if (chan->sec_level == BT_SECURITY_MEDIUM)
6615c9b66675SGustavo F. Padovan 			__clear_chan_timer(chan);
66160a708f8fSGustavo F. Padovan 	}
66170a708f8fSGustavo F. Padovan }
66180a708f8fSGustavo F. Padovan 
6619686ebf28SUlisses Furquim int l2cap_security_cfm(struct hci_conn *hcon, u8 status, u8 encrypt)
66200a708f8fSGustavo F. Padovan {
66210a708f8fSGustavo F. Padovan 	struct l2cap_conn *conn = hcon->l2cap_data;
662248454079SGustavo F. Padovan 	struct l2cap_chan *chan;
66230a708f8fSGustavo F. Padovan 
66240a708f8fSGustavo F. Padovan 	if (!conn)
66250a708f8fSGustavo F. Padovan 		return 0;
66260a708f8fSGustavo F. Padovan 
662789d8b407SAndrei Emeltchenko 	BT_DBG("conn %p status 0x%2.2x encrypt %u", conn, status, encrypt);
66280a708f8fSGustavo F. Padovan 
6629160dc6acSVinicius Costa Gomes 	if (hcon->type == LE_LINK) {
663035d4adccSHemant Gupta 		if (!status && encrypt)
6631160dc6acSVinicius Costa Gomes 			smp_distribute_keys(conn, 0);
663217cd3f37SUlisses Furquim 		cancel_delayed_work(&conn->security_timer);
6633160dc6acSVinicius Costa Gomes 	}
6634160dc6acSVinicius Costa Gomes 
66353df91ea2SAndrei Emeltchenko 	mutex_lock(&conn->chan_lock);
66360a708f8fSGustavo F. Padovan 
66373df91ea2SAndrei Emeltchenko 	list_for_each_entry(chan, &conn->chan_l, list) {
66386be36555SAndrei Emeltchenko 		l2cap_chan_lock(chan);
66390a708f8fSGustavo F. Padovan 
664089d8b407SAndrei Emeltchenko 		BT_DBG("chan %p scid 0x%4.4x state %s", chan, chan->scid,
664189d8b407SAndrei Emeltchenko 		       state_to_string(chan->state));
6642f1cb9af5SVinicius Costa Gomes 
664378eb2f98SAndrei Emeltchenko 		if (chan->chan_type == L2CAP_CHAN_CONN_FIX_A2MP) {
664478eb2f98SAndrei Emeltchenko 			l2cap_chan_unlock(chan);
664578eb2f98SAndrei Emeltchenko 			continue;
664678eb2f98SAndrei Emeltchenko 		}
664778eb2f98SAndrei Emeltchenko 
6648073d1cf3SJohan Hedberg 		if (chan->scid == L2CAP_CID_ATT) {
6649f1cb9af5SVinicius Costa Gomes 			if (!status && encrypt) {
6650f1cb9af5SVinicius Costa Gomes 				chan->sec_level = hcon->sec_level;
6651cf4cd009SAndrei Emeltchenko 				l2cap_chan_ready(chan);
6652f1cb9af5SVinicius Costa Gomes 			}
6653f1cb9af5SVinicius Costa Gomes 
66546be36555SAndrei Emeltchenko 			l2cap_chan_unlock(chan);
6655f1cb9af5SVinicius Costa Gomes 			continue;
6656f1cb9af5SVinicius Costa Gomes 		}
6657f1cb9af5SVinicius Costa Gomes 
665896eff46eSAndrei Emeltchenko 		if (!__l2cap_no_conn_pending(chan)) {
66596be36555SAndrei Emeltchenko 			l2cap_chan_unlock(chan);
66600a708f8fSGustavo F. Padovan 			continue;
66610a708f8fSGustavo F. Padovan 		}
66620a708f8fSGustavo F. Padovan 
666389bc500eSGustavo F. Padovan 		if (!status && (chan->state == BT_CONNECTED ||
666489bc500eSGustavo F. Padovan 				chan->state == BT_CONFIG)) {
6665d97c899bSMarcel Holtmann 			chan->ops->resume(chan);
66664343478fSGustavo F. Padovan 			l2cap_check_encryption(chan, encrypt);
66676be36555SAndrei Emeltchenko 			l2cap_chan_unlock(chan);
66680a708f8fSGustavo F. Padovan 			continue;
66690a708f8fSGustavo F. Padovan 		}
66700a708f8fSGustavo F. Padovan 
667189bc500eSGustavo F. Padovan 		if (chan->state == BT_CONNECT) {
66720a708f8fSGustavo F. Padovan 			if (!status) {
667393c3e8f5SAndrei Emeltchenko 				l2cap_start_connection(chan);
66740a708f8fSGustavo F. Padovan 			} else {
6675ba13ccd9SMarcel Holtmann 				__set_chan_timer(chan, L2CAP_DISC_TIMEOUT);
66760a708f8fSGustavo F. Padovan 			}
667789bc500eSGustavo F. Padovan 		} else if (chan->state == BT_CONNECT2) {
66786be36555SAndrei Emeltchenko 			struct sock *sk = chan->sk;
66790a708f8fSGustavo F. Padovan 			struct l2cap_conn_rsp rsp;
6680df3c3931SJohan Hedberg 			__u16 res, stat;
66810a708f8fSGustavo F. Padovan 
66826be36555SAndrei Emeltchenko 			lock_sock(sk);
66836be36555SAndrei Emeltchenko 
66840a708f8fSGustavo F. Padovan 			if (!status) {
6685bdc25783SMarcel Holtmann 				if (test_bit(FLAG_DEFER_SETUP, &chan->flags)) {
6686df3c3931SJohan Hedberg 					res = L2CAP_CR_PEND;
6687df3c3931SJohan Hedberg 					stat = L2CAP_CS_AUTHOR_PEND;
66882dc4e510SGustavo Padovan 					chan->ops->defer(chan);
6689df3c3931SJohan Hedberg 				} else {
66900e587be7SAndrei Emeltchenko 					__l2cap_state_change(chan, BT_CONFIG);
6691df3c3931SJohan Hedberg 					res = L2CAP_CR_SUCCESS;
6692df3c3931SJohan Hedberg 					stat = L2CAP_CS_NO_INFO;
6693df3c3931SJohan Hedberg 				}
66940a708f8fSGustavo F. Padovan 			} else {
66950e587be7SAndrei Emeltchenko 				__l2cap_state_change(chan, BT_DISCONN);
6696ba13ccd9SMarcel Holtmann 				__set_chan_timer(chan, L2CAP_DISC_TIMEOUT);
6697df3c3931SJohan Hedberg 				res = L2CAP_CR_SEC_BLOCK;
6698df3c3931SJohan Hedberg 				stat = L2CAP_CS_NO_INFO;
66990a708f8fSGustavo F. Padovan 			}
67000a708f8fSGustavo F. Padovan 
67016be36555SAndrei Emeltchenko 			release_sock(sk);
67026be36555SAndrei Emeltchenko 
6703fe4128e0SGustavo F. Padovan 			rsp.scid   = cpu_to_le16(chan->dcid);
6704fe4128e0SGustavo F. Padovan 			rsp.dcid   = cpu_to_le16(chan->scid);
6705df3c3931SJohan Hedberg 			rsp.result = cpu_to_le16(res);
6706df3c3931SJohan Hedberg 			rsp.status = cpu_to_le16(stat);
6707fc7f8a7eSGustavo F. Padovan 			l2cap_send_cmd(conn, chan->ident, L2CAP_CONN_RSP,
6708fc7f8a7eSGustavo F. Padovan 				       sizeof(rsp), &rsp);
67092d369359SMat Martineau 
67102d369359SMat Martineau 			if (!test_bit(CONF_REQ_SENT, &chan->conf_state) &&
67112d369359SMat Martineau 			    res == L2CAP_CR_SUCCESS) {
67122d369359SMat Martineau 				char buf[128];
67132d369359SMat Martineau 				set_bit(CONF_REQ_SENT, &chan->conf_state);
67142d369359SMat Martineau 				l2cap_send_cmd(conn, l2cap_get_ident(conn),
67152d369359SMat Martineau 					       L2CAP_CONF_REQ,
67162d369359SMat Martineau 					       l2cap_build_conf_req(chan, buf),
67172d369359SMat Martineau 					       buf);
67182d369359SMat Martineau 				chan->num_conf_req++;
67192d369359SMat Martineau 			}
67200a708f8fSGustavo F. Padovan 		}
67210a708f8fSGustavo F. Padovan 
67226be36555SAndrei Emeltchenko 		l2cap_chan_unlock(chan);
67230a708f8fSGustavo F. Padovan 	}
67240a708f8fSGustavo F. Padovan 
67253df91ea2SAndrei Emeltchenko 	mutex_unlock(&conn->chan_lock);
67260a708f8fSGustavo F. Padovan 
67270a708f8fSGustavo F. Padovan 	return 0;
67280a708f8fSGustavo F. Padovan }
67290a708f8fSGustavo F. Padovan 
6730686ebf28SUlisses Furquim int l2cap_recv_acldata(struct hci_conn *hcon, struct sk_buff *skb, u16 flags)
67310a708f8fSGustavo F. Padovan {
67320a708f8fSGustavo F. Padovan 	struct l2cap_conn *conn = hcon->l2cap_data;
6733d73a0988SAndrei Emeltchenko 	struct l2cap_hdr *hdr;
6734d73a0988SAndrei Emeltchenko 	int len;
67350a708f8fSGustavo F. Padovan 
67361d13a254SAndrei Emeltchenko 	/* For AMP controller do not create l2cap conn */
67371d13a254SAndrei Emeltchenko 	if (!conn && hcon->hdev->dev_type != HCI_BREDR)
67381d13a254SAndrei Emeltchenko 		goto drop;
67390a708f8fSGustavo F. Padovan 
67400a708f8fSGustavo F. Padovan 	if (!conn)
6741baf43251SClaudio Takahasi 		conn = l2cap_conn_add(hcon);
67420a708f8fSGustavo F. Padovan 
67430a708f8fSGustavo F. Padovan 	if (!conn)
67440a708f8fSGustavo F. Padovan 		goto drop;
67450a708f8fSGustavo F. Padovan 
67460a708f8fSGustavo F. Padovan 	BT_DBG("conn %p len %d flags 0x%x", conn, skb->len, flags);
67470a708f8fSGustavo F. Padovan 
6748d73a0988SAndrei Emeltchenko 	switch (flags) {
6749d73a0988SAndrei Emeltchenko 	case ACL_START:
6750d73a0988SAndrei Emeltchenko 	case ACL_START_NO_FLUSH:
6751d73a0988SAndrei Emeltchenko 	case ACL_COMPLETE:
67520a708f8fSGustavo F. Padovan 		if (conn->rx_len) {
67530a708f8fSGustavo F. Padovan 			BT_ERR("Unexpected start frame (len %d)", skb->len);
67540a708f8fSGustavo F. Padovan 			kfree_skb(conn->rx_skb);
67550a708f8fSGustavo F. Padovan 			conn->rx_skb = NULL;
67560a708f8fSGustavo F. Padovan 			conn->rx_len = 0;
67570a708f8fSGustavo F. Padovan 			l2cap_conn_unreliable(conn, ECOMM);
67580a708f8fSGustavo F. Padovan 		}
67590a708f8fSGustavo F. Padovan 
67600a708f8fSGustavo F. Padovan 		/* Start fragment always begin with Basic L2CAP header */
67610a708f8fSGustavo F. Padovan 		if (skb->len < L2CAP_HDR_SIZE) {
67620a708f8fSGustavo F. Padovan 			BT_ERR("Frame is too short (len %d)", skb->len);
67630a708f8fSGustavo F. Padovan 			l2cap_conn_unreliable(conn, ECOMM);
67640a708f8fSGustavo F. Padovan 			goto drop;
67650a708f8fSGustavo F. Padovan 		}
67660a708f8fSGustavo F. Padovan 
67670a708f8fSGustavo F. Padovan 		hdr = (struct l2cap_hdr *) skb->data;
67680a708f8fSGustavo F. Padovan 		len = __le16_to_cpu(hdr->len) + L2CAP_HDR_SIZE;
67690a708f8fSGustavo F. Padovan 
67700a708f8fSGustavo F. Padovan 		if (len == skb->len) {
67710a708f8fSGustavo F. Padovan 			/* Complete frame received */
67720a708f8fSGustavo F. Padovan 			l2cap_recv_frame(conn, skb);
67730a708f8fSGustavo F. Padovan 			return 0;
67740a708f8fSGustavo F. Padovan 		}
67750a708f8fSGustavo F. Padovan 
67760a708f8fSGustavo F. Padovan 		BT_DBG("Start: total len %d, frag len %d", len, skb->len);
67770a708f8fSGustavo F. Padovan 
67780a708f8fSGustavo F. Padovan 		if (skb->len > len) {
67790a708f8fSGustavo F. Padovan 			BT_ERR("Frame is too long (len %d, expected len %d)",
67800a708f8fSGustavo F. Padovan 			       skb->len, len);
67810a708f8fSGustavo F. Padovan 			l2cap_conn_unreliable(conn, ECOMM);
67820a708f8fSGustavo F. Padovan 			goto drop;
67830a708f8fSGustavo F. Padovan 		}
67840a708f8fSGustavo F. Padovan 
67850a708f8fSGustavo F. Padovan 		/* Allocate skb for the complete frame (with header) */
67868bcde1f2SGustavo Padovan 		conn->rx_skb = bt_skb_alloc(len, GFP_KERNEL);
67870a708f8fSGustavo F. Padovan 		if (!conn->rx_skb)
67880a708f8fSGustavo F. Padovan 			goto drop;
67890a708f8fSGustavo F. Padovan 
67900a708f8fSGustavo F. Padovan 		skb_copy_from_linear_data(skb, skb_put(conn->rx_skb, skb->len),
67910a708f8fSGustavo F. Padovan 					  skb->len);
67920a708f8fSGustavo F. Padovan 		conn->rx_len = len - skb->len;
6793d73a0988SAndrei Emeltchenko 		break;
6794d73a0988SAndrei Emeltchenko 
6795d73a0988SAndrei Emeltchenko 	case ACL_CONT:
67960a708f8fSGustavo F. Padovan 		BT_DBG("Cont: frag len %d (expecting %d)", skb->len, conn->rx_len);
67970a708f8fSGustavo F. Padovan 
67980a708f8fSGustavo F. Padovan 		if (!conn->rx_len) {
67990a708f8fSGustavo F. Padovan 			BT_ERR("Unexpected continuation frame (len %d)", skb->len);
68000a708f8fSGustavo F. Padovan 			l2cap_conn_unreliable(conn, ECOMM);
68010a708f8fSGustavo F. Padovan 			goto drop;
68020a708f8fSGustavo F. Padovan 		}
68030a708f8fSGustavo F. Padovan 
68040a708f8fSGustavo F. Padovan 		if (skb->len > conn->rx_len) {
68050a708f8fSGustavo F. Padovan 			BT_ERR("Fragment is too long (len %d, expected %d)",
68060a708f8fSGustavo F. Padovan 			       skb->len, conn->rx_len);
68070a708f8fSGustavo F. Padovan 			kfree_skb(conn->rx_skb);
68080a708f8fSGustavo F. Padovan 			conn->rx_skb = NULL;
68090a708f8fSGustavo F. Padovan 			conn->rx_len = 0;
68100a708f8fSGustavo F. Padovan 			l2cap_conn_unreliable(conn, ECOMM);
68110a708f8fSGustavo F. Padovan 			goto drop;
68120a708f8fSGustavo F. Padovan 		}
68130a708f8fSGustavo F. Padovan 
68140a708f8fSGustavo F. Padovan 		skb_copy_from_linear_data(skb, skb_put(conn->rx_skb, skb->len),
68150a708f8fSGustavo F. Padovan 					  skb->len);
68160a708f8fSGustavo F. Padovan 		conn->rx_len -= skb->len;
68170a708f8fSGustavo F. Padovan 
68180a708f8fSGustavo F. Padovan 		if (!conn->rx_len) {
6819c4e5bafaSJohan Hedberg 			/* Complete frame received. l2cap_recv_frame
6820c4e5bafaSJohan Hedberg 			 * takes ownership of the skb so set the global
6821c4e5bafaSJohan Hedberg 			 * rx_skb pointer to NULL first.
6822c4e5bafaSJohan Hedberg 			 */
6823c4e5bafaSJohan Hedberg 			struct sk_buff *rx_skb = conn->rx_skb;
68240a708f8fSGustavo F. Padovan 			conn->rx_skb = NULL;
6825c4e5bafaSJohan Hedberg 			l2cap_recv_frame(conn, rx_skb);
68260a708f8fSGustavo F. Padovan 		}
6827d73a0988SAndrei Emeltchenko 		break;
68280a708f8fSGustavo F. Padovan 	}
68290a708f8fSGustavo F. Padovan 
68300a708f8fSGustavo F. Padovan drop:
68310a708f8fSGustavo F. Padovan 	kfree_skb(skb);
68320a708f8fSGustavo F. Padovan 	return 0;
68330a708f8fSGustavo F. Padovan }
68340a708f8fSGustavo F. Padovan 
68350a708f8fSGustavo F. Padovan static int l2cap_debugfs_show(struct seq_file *f, void *p)
68360a708f8fSGustavo F. Padovan {
683723691d75SGustavo F. Padovan 	struct l2cap_chan *c;
68380a708f8fSGustavo F. Padovan 
6839333055f2SGustavo F. Padovan 	read_lock(&chan_list_lock);
68400a708f8fSGustavo F. Padovan 
684123691d75SGustavo F. Padovan 	list_for_each_entry(c, &chan_list, global_l) {
6842fcb73338SAndrei Emeltchenko 		seq_printf(f, "%pMR %pMR %d %d 0x%4.4x 0x%4.4x %d %d %d %d\n",
68437eafc59eSMarcel Holtmann 			   &c->src, &c->dst,
684489bc500eSGustavo F. Padovan 			   c->state, __le16_to_cpu(c->psm),
684523691d75SGustavo F. Padovan 			   c->scid, c->dcid, c->imtu, c->omtu,
684623691d75SGustavo F. Padovan 			   c->sec_level, c->mode);
68470a708f8fSGustavo F. Padovan 	}
68480a708f8fSGustavo F. Padovan 
6849333055f2SGustavo F. Padovan 	read_unlock(&chan_list_lock);
68500a708f8fSGustavo F. Padovan 
68510a708f8fSGustavo F. Padovan 	return 0;
68520a708f8fSGustavo F. Padovan }
68530a708f8fSGustavo F. Padovan 
68540a708f8fSGustavo F. Padovan static int l2cap_debugfs_open(struct inode *inode, struct file *file)
68550a708f8fSGustavo F. Padovan {
68560a708f8fSGustavo F. Padovan 	return single_open(file, l2cap_debugfs_show, inode->i_private);
68570a708f8fSGustavo F. Padovan }
68580a708f8fSGustavo F. Padovan 
68590a708f8fSGustavo F. Padovan static const struct file_operations l2cap_debugfs_fops = {
68600a708f8fSGustavo F. Padovan 	.open		= l2cap_debugfs_open,
68610a708f8fSGustavo F. Padovan 	.read		= seq_read,
68620a708f8fSGustavo F. Padovan 	.llseek		= seq_lseek,
68630a708f8fSGustavo F. Padovan 	.release	= single_release,
68640a708f8fSGustavo F. Padovan };
68650a708f8fSGustavo F. Padovan 
68660a708f8fSGustavo F. Padovan static struct dentry *l2cap_debugfs;
68670a708f8fSGustavo F. Padovan 
686864274518SGustavo F. Padovan int __init l2cap_init(void)
68690a708f8fSGustavo F. Padovan {
68700a708f8fSGustavo F. Padovan 	int err;
68710a708f8fSGustavo F. Padovan 
6872bb58f747SGustavo F. Padovan 	err = l2cap_init_sockets();
68730a708f8fSGustavo F. Padovan 	if (err < 0)
68740a708f8fSGustavo F. Padovan 		return err;
68750a708f8fSGustavo F. Padovan 
68760a708f8fSGustavo F. Padovan 	if (bt_debugfs) {
68772d792818SGustavo Padovan 		l2cap_debugfs = debugfs_create_file("l2cap", 0444, bt_debugfs,
68782d792818SGustavo Padovan 						    NULL, &l2cap_debugfs_fops);
68790a708f8fSGustavo F. Padovan 		if (!l2cap_debugfs)
68800a708f8fSGustavo F. Padovan 			BT_ERR("Failed to create L2CAP debug file");
68810a708f8fSGustavo F. Padovan 	}
68820a708f8fSGustavo F. Padovan 
68830a708f8fSGustavo F. Padovan 	return 0;
68840a708f8fSGustavo F. Padovan }
68850a708f8fSGustavo F. Padovan 
688664274518SGustavo F. Padovan void l2cap_exit(void)
68870a708f8fSGustavo F. Padovan {
68880a708f8fSGustavo F. Padovan 	debugfs_remove(l2cap_debugfs);
6889bb58f747SGustavo F. Padovan 	l2cap_cleanup_sockets();
68900a708f8fSGustavo F. Padovan }
68910a708f8fSGustavo F. Padovan 
68920a708f8fSGustavo F. Padovan module_param(disable_ertm, bool, 0644);
68930a708f8fSGustavo F. Padovan MODULE_PARM_DESC(disable_ertm, "Disable enhanced retransmission mode");
6894