xref: /openbmc/linux/net/bluetooth/l2cap_core.c (revision 6a974b50)
10a708f8fSGustavo F. Padovan /*
20a708f8fSGustavo F. Padovan    BlueZ - Bluetooth protocol stack for Linux
30a708f8fSGustavo F. Padovan    Copyright (C) 2000-2001 Qualcomm Incorporated
40a708f8fSGustavo F. Padovan    Copyright (C) 2009-2010 Gustavo F. Padovan <gustavo@padovan.org>
50a708f8fSGustavo F. Padovan    Copyright (C) 2010 Google Inc.
6590051deSGustavo F. Padovan    Copyright (C) 2011 ProFUSION Embedded Systems
7422e925bSMat Martineau    Copyright (c) 2012 Code Aurora Forum.  All rights reserved.
80a708f8fSGustavo F. Padovan 
90a708f8fSGustavo F. Padovan    Written 2000,2001 by Maxim Krasnyansky <maxk@qualcomm.com>
100a708f8fSGustavo F. Padovan 
110a708f8fSGustavo F. Padovan    This program is free software; you can redistribute it and/or modify
120a708f8fSGustavo F. Padovan    it under the terms of the GNU General Public License version 2 as
130a708f8fSGustavo F. Padovan    published by the Free Software Foundation;
140a708f8fSGustavo F. Padovan 
150a708f8fSGustavo F. Padovan    THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS
160a708f8fSGustavo F. Padovan    OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
170a708f8fSGustavo F. Padovan    FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT OF THIRD PARTY RIGHTS.
180a708f8fSGustavo F. Padovan    IN NO EVENT SHALL THE COPYRIGHT HOLDER(S) AND AUTHOR(S) BE LIABLE FOR ANY
190a708f8fSGustavo F. Padovan    CLAIM, OR ANY SPECIAL INDIRECT OR CONSEQUENTIAL DAMAGES, OR ANY DAMAGES
200a708f8fSGustavo F. Padovan    WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
210a708f8fSGustavo F. Padovan    ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
220a708f8fSGustavo F. Padovan    OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
230a708f8fSGustavo F. Padovan 
240a708f8fSGustavo F. Padovan    ALL LIABILITY, INCLUDING LIABILITY FOR INFRINGEMENT OF ANY PATENTS,
250a708f8fSGustavo F. Padovan    COPYRIGHTS, TRADEMARKS OR OTHER RIGHTS, RELATING TO USE OF THIS
260a708f8fSGustavo F. Padovan    SOFTWARE IS DISCLAIMED.
270a708f8fSGustavo F. Padovan */
280a708f8fSGustavo F. Padovan 
29bb58f747SGustavo F. Padovan /* Bluetooth L2CAP core. */
300a708f8fSGustavo F. Padovan 
310a708f8fSGustavo F. Padovan #include <linux/module.h>
320a708f8fSGustavo F. Padovan 
330a708f8fSGustavo F. Padovan #include <linux/debugfs.h>
340a708f8fSGustavo F. Padovan #include <linux/crc16.h>
350a708f8fSGustavo F. Padovan 
360a708f8fSGustavo F. Padovan #include <net/bluetooth/bluetooth.h>
370a708f8fSGustavo F. Padovan #include <net/bluetooth/hci_core.h>
380a708f8fSGustavo F. Padovan #include <net/bluetooth/l2cap.h>
397ef9fbf0SMarcel Holtmann 
40ac4b7236SMarcel Holtmann #include "smp.h"
417024728eSMarcel Holtmann #include "a2mp.h"
427ef9fbf0SMarcel Holtmann #include "amp.h"
430a708f8fSGustavo F. Padovan 
44d1de6d46SMat Martineau bool disable_ertm;
450a708f8fSGustavo F. Padovan 
460a708f8fSGustavo F. Padovan static u32 l2cap_feat_mask = L2CAP_FEAT_FIXED_CHAN;
4750a147cdSMat Martineau static u8 l2cap_fixed_chan[8] = { L2CAP_FC_L2CAP, };
480a708f8fSGustavo F. Padovan 
49b5ad8b7fSJohannes Berg static LIST_HEAD(chan_list);
50b5ad8b7fSJohannes Berg static DEFINE_RWLOCK(chan_list_lock);
510a708f8fSGustavo F. Padovan 
520a708f8fSGustavo F. Padovan static struct sk_buff *l2cap_build_cmd(struct l2cap_conn *conn,
530a708f8fSGustavo F. Padovan 				       u8 code, u8 ident, u16 dlen, void *data);
544519de9aSGustavo F. Padovan static void l2cap_send_cmd(struct l2cap_conn *conn, u8 ident, u8 code, u16 len,
554519de9aSGustavo F. Padovan 			   void *data);
56710f9b0aSGustavo F. Padovan static int l2cap_build_conf_req(struct l2cap_chan *chan, void *data);
575e4e3972SAndrei Emeltchenko static void l2cap_send_disconn_req(struct l2cap_chan *chan, int err);
580a708f8fSGustavo F. Padovan 
59d660366dSGustavo Padovan static void l2cap_tx(struct l2cap_chan *chan, struct l2cap_ctrl *control,
60608bcc6dSMat Martineau 		     struct sk_buff_head *skbs, u8 event);
61608bcc6dSMat Martineau 
620a708f8fSGustavo F. Padovan /* ---- L2CAP channels ---- */
6371ba0e56SGustavo F. Padovan 
642d792818SGustavo Padovan static struct l2cap_chan *__l2cap_get_chan_by_dcid(struct l2cap_conn *conn,
652d792818SGustavo Padovan 						   u16 cid)
660a708f8fSGustavo F. Padovan {
673df91ea2SAndrei Emeltchenko 	struct l2cap_chan *c;
68baa7e1faSGustavo F. Padovan 
693df91ea2SAndrei Emeltchenko 	list_for_each_entry(c, &conn->chan_l, list) {
703df91ea2SAndrei Emeltchenko 		if (c->dcid == cid)
713df91ea2SAndrei Emeltchenko 			return c;
720a708f8fSGustavo F. Padovan 	}
733df91ea2SAndrei Emeltchenko 	return NULL;
74baa7e1faSGustavo F. Padovan }
750a708f8fSGustavo F. Padovan 
762d792818SGustavo Padovan static struct l2cap_chan *__l2cap_get_chan_by_scid(struct l2cap_conn *conn,
772d792818SGustavo Padovan 						   u16 cid)
780a708f8fSGustavo F. Padovan {
793df91ea2SAndrei Emeltchenko 	struct l2cap_chan *c;
80baa7e1faSGustavo F. Padovan 
813df91ea2SAndrei Emeltchenko 	list_for_each_entry(c, &conn->chan_l, list) {
823df91ea2SAndrei Emeltchenko 		if (c->scid == cid)
833df91ea2SAndrei Emeltchenko 			return c;
840a708f8fSGustavo F. Padovan 	}
853df91ea2SAndrei Emeltchenko 	return NULL;
86baa7e1faSGustavo F. Padovan }
870a708f8fSGustavo F. Padovan 
880a708f8fSGustavo F. Padovan /* Find channel with given SCID.
89ef191adeSMat Martineau  * Returns locked channel. */
902d792818SGustavo Padovan static struct l2cap_chan *l2cap_get_chan_by_scid(struct l2cap_conn *conn,
912d792818SGustavo Padovan 						 u16 cid)
920a708f8fSGustavo F. Padovan {
9348454079SGustavo F. Padovan 	struct l2cap_chan *c;
94baa7e1faSGustavo F. Padovan 
953df91ea2SAndrei Emeltchenko 	mutex_lock(&conn->chan_lock);
96baa7e1faSGustavo F. Padovan 	c = __l2cap_get_chan_by_scid(conn, cid);
97ef191adeSMat Martineau 	if (c)
98ef191adeSMat Martineau 		l2cap_chan_lock(c);
993df91ea2SAndrei Emeltchenko 	mutex_unlock(&conn->chan_lock);
1003df91ea2SAndrei Emeltchenko 
10148454079SGustavo F. Padovan 	return c;
1020a708f8fSGustavo F. Padovan }
1030a708f8fSGustavo F. Padovan 
104b1a130b7SMat Martineau /* Find channel with given DCID.
105b1a130b7SMat Martineau  * Returns locked channel.
106b1a130b7SMat Martineau  */
107b1a130b7SMat Martineau static struct l2cap_chan *l2cap_get_chan_by_dcid(struct l2cap_conn *conn,
108b1a130b7SMat Martineau 						 u16 cid)
109b1a130b7SMat Martineau {
110b1a130b7SMat Martineau 	struct l2cap_chan *c;
111b1a130b7SMat Martineau 
112b1a130b7SMat Martineau 	mutex_lock(&conn->chan_lock);
113b1a130b7SMat Martineau 	c = __l2cap_get_chan_by_dcid(conn, cid);
114b1a130b7SMat Martineau 	if (c)
115b1a130b7SMat Martineau 		l2cap_chan_lock(c);
116b1a130b7SMat Martineau 	mutex_unlock(&conn->chan_lock);
117b1a130b7SMat Martineau 
118b1a130b7SMat Martineau 	return c;
119b1a130b7SMat Martineau }
120b1a130b7SMat Martineau 
1212d792818SGustavo Padovan static struct l2cap_chan *__l2cap_get_chan_by_ident(struct l2cap_conn *conn,
1222d792818SGustavo Padovan 						    u8 ident)
1230a708f8fSGustavo F. Padovan {
1243df91ea2SAndrei Emeltchenko 	struct l2cap_chan *c;
125baa7e1faSGustavo F. Padovan 
1263df91ea2SAndrei Emeltchenko 	list_for_each_entry(c, &conn->chan_l, list) {
1273df91ea2SAndrei Emeltchenko 		if (c->ident == ident)
1283df91ea2SAndrei Emeltchenko 			return c;
1290a708f8fSGustavo F. Padovan 	}
1303df91ea2SAndrei Emeltchenko 	return NULL;
131baa7e1faSGustavo F. Padovan }
1320a708f8fSGustavo F. Padovan 
1335b155ef9SMat Martineau static struct l2cap_chan *l2cap_get_chan_by_ident(struct l2cap_conn *conn,
1345b155ef9SMat Martineau 						  u8 ident)
1355b155ef9SMat Martineau {
1365b155ef9SMat Martineau 	struct l2cap_chan *c;
1375b155ef9SMat Martineau 
1385b155ef9SMat Martineau 	mutex_lock(&conn->chan_lock);
1395b155ef9SMat Martineau 	c = __l2cap_get_chan_by_ident(conn, ident);
1405b155ef9SMat Martineau 	if (c)
1415b155ef9SMat Martineau 		l2cap_chan_lock(c);
1425b155ef9SMat Martineau 	mutex_unlock(&conn->chan_lock);
1435b155ef9SMat Martineau 
1445b155ef9SMat Martineau 	return c;
1455b155ef9SMat Martineau }
1465b155ef9SMat Martineau 
14723691d75SGustavo F. Padovan static struct l2cap_chan *__l2cap_global_chan_by_addr(__le16 psm, bdaddr_t *src)
1489e4425ffSGustavo F. Padovan {
14923691d75SGustavo F. Padovan 	struct l2cap_chan *c;
1509e4425ffSGustavo F. Padovan 
15123691d75SGustavo F. Padovan 	list_for_each_entry(c, &chan_list, global_l) {
15223691d75SGustavo F. Padovan 		if (c->sport == psm && !bacmp(&bt_sk(c->sk)->src, src))
15323691d75SGustavo F. Padovan 			return c;
1549e4425ffSGustavo F. Padovan 	}
155250938cbSSzymon Janc 	return NULL;
156250938cbSSzymon Janc }
1579e4425ffSGustavo F. Padovan 
1589e4425ffSGustavo F. Padovan int l2cap_add_psm(struct l2cap_chan *chan, bdaddr_t *src, __le16 psm)
1599e4425ffSGustavo F. Padovan {
16073b2ec18SGustavo F. Padovan 	int err;
16173b2ec18SGustavo F. Padovan 
162333055f2SGustavo F. Padovan 	write_lock(&chan_list_lock);
1639e4425ffSGustavo F. Padovan 
16423691d75SGustavo F. Padovan 	if (psm && __l2cap_global_chan_by_addr(psm, src)) {
16573b2ec18SGustavo F. Padovan 		err = -EADDRINUSE;
16673b2ec18SGustavo F. Padovan 		goto done;
1679e4425ffSGustavo F. Padovan 	}
1689e4425ffSGustavo F. Padovan 
16973b2ec18SGustavo F. Padovan 	if (psm) {
1709e4425ffSGustavo F. Padovan 		chan->psm = psm;
1719e4425ffSGustavo F. Padovan 		chan->sport = psm;
17273b2ec18SGustavo F. Padovan 		err = 0;
17373b2ec18SGustavo F. Padovan 	} else {
17473b2ec18SGustavo F. Padovan 		u16 p;
1759e4425ffSGustavo F. Padovan 
17673b2ec18SGustavo F. Padovan 		err = -EINVAL;
17773b2ec18SGustavo F. Padovan 		for (p = 0x1001; p < 0x1100; p += 2)
17823691d75SGustavo F. Padovan 			if (!__l2cap_global_chan_by_addr(cpu_to_le16(p), src)) {
17973b2ec18SGustavo F. Padovan 				chan->psm   = cpu_to_le16(p);
18073b2ec18SGustavo F. Padovan 				chan->sport = cpu_to_le16(p);
18173b2ec18SGustavo F. Padovan 				err = 0;
18273b2ec18SGustavo F. Padovan 				break;
18373b2ec18SGustavo F. Padovan 			}
18473b2ec18SGustavo F. Padovan 	}
18573b2ec18SGustavo F. Padovan 
18673b2ec18SGustavo F. Padovan done:
187333055f2SGustavo F. Padovan 	write_unlock(&chan_list_lock);
18873b2ec18SGustavo F. Padovan 	return err;
1899e4425ffSGustavo F. Padovan }
1909e4425ffSGustavo F. Padovan 
1919e4425ffSGustavo F. Padovan int l2cap_add_scid(struct l2cap_chan *chan,  __u16 scid)
1929e4425ffSGustavo F. Padovan {
193333055f2SGustavo F. Padovan 	write_lock(&chan_list_lock);
1949e4425ffSGustavo F. Padovan 
1959e4425ffSGustavo F. Padovan 	chan->scid = scid;
1969e4425ffSGustavo F. Padovan 
197333055f2SGustavo F. Padovan 	write_unlock(&chan_list_lock);
1989e4425ffSGustavo F. Padovan 
1999e4425ffSGustavo F. Padovan 	return 0;
2009e4425ffSGustavo F. Padovan }
2019e4425ffSGustavo F. Padovan 
202baa7e1faSGustavo F. Padovan static u16 l2cap_alloc_cid(struct l2cap_conn *conn)
2030a708f8fSGustavo F. Padovan {
2040a708f8fSGustavo F. Padovan 	u16 cid = L2CAP_CID_DYN_START;
2050a708f8fSGustavo F. Padovan 
2060a708f8fSGustavo F. Padovan 	for (; cid < L2CAP_CID_DYN_END; cid++) {
207baa7e1faSGustavo F. Padovan 		if (!__l2cap_get_chan_by_scid(conn, cid))
2080a708f8fSGustavo F. Padovan 			return cid;
2090a708f8fSGustavo F. Padovan 	}
2100a708f8fSGustavo F. Padovan 
2110a708f8fSGustavo F. Padovan 	return 0;
2120a708f8fSGustavo F. Padovan }
2130a708f8fSGustavo F. Padovan 
2140e587be7SAndrei Emeltchenko static void __l2cap_state_change(struct l2cap_chan *chan, int state)
21589bc500eSGustavo F. Padovan {
21642d2d87cSAndrei Emeltchenko 	BT_DBG("chan %p %s -> %s", chan, state_to_string(chan->state),
217badaaa00SGustavo F. Padovan 	       state_to_string(state));
218badaaa00SGustavo F. Padovan 
21989bc500eSGustavo F. Padovan 	chan->state = state;
22080b98027SGustavo Padovan 	chan->ops->state_change(chan, state);
22189bc500eSGustavo F. Padovan }
22289bc500eSGustavo F. Padovan 
2230e587be7SAndrei Emeltchenko static void l2cap_state_change(struct l2cap_chan *chan, int state)
2240e587be7SAndrei Emeltchenko {
2250e587be7SAndrei Emeltchenko 	struct sock *sk = chan->sk;
2260e587be7SAndrei Emeltchenko 
2270e587be7SAndrei Emeltchenko 	lock_sock(sk);
2280e587be7SAndrei Emeltchenko 	__l2cap_state_change(chan, state);
2290e587be7SAndrei Emeltchenko 	release_sock(sk);
2300e587be7SAndrei Emeltchenko }
2310e587be7SAndrei Emeltchenko 
2322e0052e4SAndrei Emeltchenko static inline void __l2cap_chan_set_err(struct l2cap_chan *chan, int err)
2332e0052e4SAndrei Emeltchenko {
2342e0052e4SAndrei Emeltchenko 	struct sock *sk = chan->sk;
2352e0052e4SAndrei Emeltchenko 
2362e0052e4SAndrei Emeltchenko 	sk->sk_err = err;
2372e0052e4SAndrei Emeltchenko }
2382e0052e4SAndrei Emeltchenko 
2392e0052e4SAndrei Emeltchenko static inline void l2cap_chan_set_err(struct l2cap_chan *chan, int err)
2402e0052e4SAndrei Emeltchenko {
2412e0052e4SAndrei Emeltchenko 	struct sock *sk = chan->sk;
2422e0052e4SAndrei Emeltchenko 
2432e0052e4SAndrei Emeltchenko 	lock_sock(sk);
2442e0052e4SAndrei Emeltchenko 	__l2cap_chan_set_err(chan, err);
2452e0052e4SAndrei Emeltchenko 	release_sock(sk);
2462e0052e4SAndrei Emeltchenko }
2472e0052e4SAndrei Emeltchenko 
2484239d16fSMat Martineau static void __set_retrans_timer(struct l2cap_chan *chan)
2494239d16fSMat Martineau {
2504239d16fSMat Martineau 	if (!delayed_work_pending(&chan->monitor_timer) &&
2514239d16fSMat Martineau 	    chan->retrans_timeout) {
2524239d16fSMat Martineau 		l2cap_set_timer(chan, &chan->retrans_timer,
2534239d16fSMat Martineau 				msecs_to_jiffies(chan->retrans_timeout));
2544239d16fSMat Martineau 	}
2554239d16fSMat Martineau }
2564239d16fSMat Martineau 
2574239d16fSMat Martineau static void __set_monitor_timer(struct l2cap_chan *chan)
2584239d16fSMat Martineau {
2594239d16fSMat Martineau 	__clear_retrans_timer(chan);
2604239d16fSMat Martineau 	if (chan->monitor_timeout) {
2614239d16fSMat Martineau 		l2cap_set_timer(chan, &chan->monitor_timer,
2624239d16fSMat Martineau 				msecs_to_jiffies(chan->monitor_timeout));
2634239d16fSMat Martineau 	}
2644239d16fSMat Martineau }
2654239d16fSMat Martineau 
266608bcc6dSMat Martineau static struct sk_buff *l2cap_ertm_seq_in_queue(struct sk_buff_head *head,
267608bcc6dSMat Martineau 					       u16 seq)
268608bcc6dSMat Martineau {
269608bcc6dSMat Martineau 	struct sk_buff *skb;
270608bcc6dSMat Martineau 
271608bcc6dSMat Martineau 	skb_queue_walk(head, skb) {
272608bcc6dSMat Martineau 		if (bt_cb(skb)->control.txseq == seq)
273608bcc6dSMat Martineau 			return skb;
274608bcc6dSMat Martineau 	}
275608bcc6dSMat Martineau 
276608bcc6dSMat Martineau 	return NULL;
277608bcc6dSMat Martineau }
278608bcc6dSMat Martineau 
2793c588192SMat Martineau /* ---- L2CAP sequence number lists ---- */
2803c588192SMat Martineau 
2813c588192SMat Martineau /* For ERTM, ordered lists of sequence numbers must be tracked for
2823c588192SMat Martineau  * SREJ requests that are received and for frames that are to be
2833c588192SMat Martineau  * retransmitted. These seq_list functions implement a singly-linked
2843c588192SMat Martineau  * list in an array, where membership in the list can also be checked
2853c588192SMat Martineau  * in constant time. Items can also be added to the tail of the list
2863c588192SMat Martineau  * and removed from the head in constant time, without further memory
2873c588192SMat Martineau  * allocs or frees.
2883c588192SMat Martineau  */
2893c588192SMat Martineau 
2903c588192SMat Martineau static int l2cap_seq_list_init(struct l2cap_seq_list *seq_list, u16 size)
2913c588192SMat Martineau {
2923c588192SMat Martineau 	size_t alloc_size, i;
2933c588192SMat Martineau 
2943c588192SMat Martineau 	/* Allocated size is a power of 2 to map sequence numbers
2953c588192SMat Martineau 	 * (which may be up to 14 bits) in to a smaller array that is
2963c588192SMat Martineau 	 * sized for the negotiated ERTM transmit windows.
2973c588192SMat Martineau 	 */
2983c588192SMat Martineau 	alloc_size = roundup_pow_of_two(size);
2993c588192SMat Martineau 
3003c588192SMat Martineau 	seq_list->list = kmalloc(sizeof(u16) * alloc_size, GFP_KERNEL);
3013c588192SMat Martineau 	if (!seq_list->list)
3023c588192SMat Martineau 		return -ENOMEM;
3033c588192SMat Martineau 
3043c588192SMat Martineau 	seq_list->mask = alloc_size - 1;
3053c588192SMat Martineau 	seq_list->head = L2CAP_SEQ_LIST_CLEAR;
3063c588192SMat Martineau 	seq_list->tail = L2CAP_SEQ_LIST_CLEAR;
3073c588192SMat Martineau 	for (i = 0; i < alloc_size; i++)
3083c588192SMat Martineau 		seq_list->list[i] = L2CAP_SEQ_LIST_CLEAR;
3093c588192SMat Martineau 
3103c588192SMat Martineau 	return 0;
3113c588192SMat Martineau }
3123c588192SMat Martineau 
3133c588192SMat Martineau static inline void l2cap_seq_list_free(struct l2cap_seq_list *seq_list)
3143c588192SMat Martineau {
3153c588192SMat Martineau 	kfree(seq_list->list);
3163c588192SMat Martineau }
3173c588192SMat Martineau 
3183c588192SMat Martineau static inline bool l2cap_seq_list_contains(struct l2cap_seq_list *seq_list,
3193c588192SMat Martineau 					   u16 seq)
3203c588192SMat Martineau {
3213c588192SMat Martineau 	/* Constant-time check for list membership */
3223c588192SMat Martineau 	return seq_list->list[seq & seq_list->mask] != L2CAP_SEQ_LIST_CLEAR;
3233c588192SMat Martineau }
3243c588192SMat Martineau 
3253c588192SMat Martineau static u16 l2cap_seq_list_remove(struct l2cap_seq_list *seq_list, u16 seq)
3263c588192SMat Martineau {
3273c588192SMat Martineau 	u16 mask = seq_list->mask;
3283c588192SMat Martineau 
3293c588192SMat Martineau 	if (seq_list->head == L2CAP_SEQ_LIST_CLEAR) {
3303c588192SMat Martineau 		/* In case someone tries to pop the head of an empty list */
3313c588192SMat Martineau 		return L2CAP_SEQ_LIST_CLEAR;
3323c588192SMat Martineau 	} else if (seq_list->head == seq) {
3333c588192SMat Martineau 		/* Head can be removed in constant time */
3343c588192SMat Martineau 		seq_list->head = seq_list->list[seq & mask];
3353c588192SMat Martineau 		seq_list->list[seq & mask] = L2CAP_SEQ_LIST_CLEAR;
3363c588192SMat Martineau 
3373c588192SMat Martineau 		if (seq_list->head == L2CAP_SEQ_LIST_TAIL) {
3383c588192SMat Martineau 			seq_list->head = L2CAP_SEQ_LIST_CLEAR;
3393c588192SMat Martineau 			seq_list->tail = L2CAP_SEQ_LIST_CLEAR;
3403c588192SMat Martineau 		}
3413c588192SMat Martineau 	} else {
3423c588192SMat Martineau 		/* Walk the list to find the sequence number */
3433c588192SMat Martineau 		u16 prev = seq_list->head;
3443c588192SMat Martineau 		while (seq_list->list[prev & mask] != seq) {
3453c588192SMat Martineau 			prev = seq_list->list[prev & mask];
3463c588192SMat Martineau 			if (prev == L2CAP_SEQ_LIST_TAIL)
3473c588192SMat Martineau 				return L2CAP_SEQ_LIST_CLEAR;
3483c588192SMat Martineau 		}
3493c588192SMat Martineau 
3503c588192SMat Martineau 		/* Unlink the number from the list and clear it */
3513c588192SMat Martineau 		seq_list->list[prev & mask] = seq_list->list[seq & mask];
3523c588192SMat Martineau 		seq_list->list[seq & mask] = L2CAP_SEQ_LIST_CLEAR;
3533c588192SMat Martineau 		if (seq_list->tail == seq)
3543c588192SMat Martineau 			seq_list->tail = prev;
3553c588192SMat Martineau 	}
3563c588192SMat Martineau 	return seq;
3573c588192SMat Martineau }
3583c588192SMat Martineau 
3593c588192SMat Martineau static inline u16 l2cap_seq_list_pop(struct l2cap_seq_list *seq_list)
3603c588192SMat Martineau {
3613c588192SMat Martineau 	/* Remove the head in constant time */
3623c588192SMat Martineau 	return l2cap_seq_list_remove(seq_list, seq_list->head);
3633c588192SMat Martineau }
3643c588192SMat Martineau 
3653c588192SMat Martineau static void l2cap_seq_list_clear(struct l2cap_seq_list *seq_list)
3663c588192SMat Martineau {
3673c588192SMat Martineau 	u16 i;
368f522ae36SGustavo Padovan 
369f522ae36SGustavo Padovan 	if (seq_list->head == L2CAP_SEQ_LIST_CLEAR)
370f522ae36SGustavo Padovan 		return;
371f522ae36SGustavo Padovan 
3723c588192SMat Martineau 	for (i = 0; i <= seq_list->mask; i++)
3733c588192SMat Martineau 		seq_list->list[i] = L2CAP_SEQ_LIST_CLEAR;
3743c588192SMat Martineau 
3753c588192SMat Martineau 	seq_list->head = L2CAP_SEQ_LIST_CLEAR;
3763c588192SMat Martineau 	seq_list->tail = L2CAP_SEQ_LIST_CLEAR;
3773c588192SMat Martineau }
3783c588192SMat Martineau 
3793c588192SMat Martineau static void l2cap_seq_list_append(struct l2cap_seq_list *seq_list, u16 seq)
3803c588192SMat Martineau {
3813c588192SMat Martineau 	u16 mask = seq_list->mask;
3823c588192SMat Martineau 
3833c588192SMat Martineau 	/* All appends happen in constant time */
3843c588192SMat Martineau 
385f522ae36SGustavo Padovan 	if (seq_list->list[seq & mask] != L2CAP_SEQ_LIST_CLEAR)
386f522ae36SGustavo Padovan 		return;
387f522ae36SGustavo Padovan 
3883c588192SMat Martineau 	if (seq_list->tail == L2CAP_SEQ_LIST_CLEAR)
3893c588192SMat Martineau 		seq_list->head = seq;
3903c588192SMat Martineau 	else
3913c588192SMat Martineau 		seq_list->list[seq_list->tail & mask] = seq;
3923c588192SMat Martineau 
3933c588192SMat Martineau 	seq_list->tail = seq;
3943c588192SMat Martineau 	seq_list->list[seq & mask] = L2CAP_SEQ_LIST_TAIL;
3953c588192SMat Martineau }
3963c588192SMat Martineau 
397721c4181SGustavo F. Padovan static void l2cap_chan_timeout(struct work_struct *work)
398ab07801dSGustavo F. Padovan {
399721c4181SGustavo F. Padovan 	struct l2cap_chan *chan = container_of(work, struct l2cap_chan,
400721c4181SGustavo F. Padovan 					       chan_timer.work);
4013df91ea2SAndrei Emeltchenko 	struct l2cap_conn *conn = chan->conn;
402ab07801dSGustavo F. Padovan 	int reason;
403ab07801dSGustavo F. Padovan 
404e05dcc32SAndrei Emeltchenko 	BT_DBG("chan %p state %s", chan, state_to_string(chan->state));
405ab07801dSGustavo F. Padovan 
4063df91ea2SAndrei Emeltchenko 	mutex_lock(&conn->chan_lock);
4076be36555SAndrei Emeltchenko 	l2cap_chan_lock(chan);
408ab07801dSGustavo F. Padovan 
40989bc500eSGustavo F. Padovan 	if (chan->state == BT_CONNECTED || chan->state == BT_CONFIG)
410ab07801dSGustavo F. Padovan 		reason = ECONNREFUSED;
41189bc500eSGustavo F. Padovan 	else if (chan->state == BT_CONNECT &&
412ab07801dSGustavo F. Padovan 		 chan->sec_level != BT_SECURITY_SDP)
413ab07801dSGustavo F. Padovan 		reason = ECONNREFUSED;
414ab07801dSGustavo F. Padovan 	else
415ab07801dSGustavo F. Padovan 		reason = ETIMEDOUT;
416ab07801dSGustavo F. Padovan 
4170f852724SGustavo F. Padovan 	l2cap_chan_close(chan, reason);
418ab07801dSGustavo F. Padovan 
4196be36555SAndrei Emeltchenko 	l2cap_chan_unlock(chan);
420ab07801dSGustavo F. Padovan 
42180b98027SGustavo Padovan 	chan->ops->close(chan);
4223df91ea2SAndrei Emeltchenko 	mutex_unlock(&conn->chan_lock);
4233df91ea2SAndrei Emeltchenko 
424371fd835SUlisses Furquim 	l2cap_chan_put(chan);
425ab07801dSGustavo F. Padovan }
426ab07801dSGustavo F. Padovan 
427eef1d9b6SGustavo Padovan struct l2cap_chan *l2cap_chan_create(void)
4280a708f8fSGustavo F. Padovan {
42948454079SGustavo F. Padovan 	struct l2cap_chan *chan;
4300a708f8fSGustavo F. Padovan 
43148454079SGustavo F. Padovan 	chan = kzalloc(sizeof(*chan), GFP_ATOMIC);
43248454079SGustavo F. Padovan 	if (!chan)
43348454079SGustavo F. Padovan 		return NULL;
4340a708f8fSGustavo F. Padovan 
435c03b355eSAndrei Emeltchenko 	mutex_init(&chan->lock);
436c03b355eSAndrei Emeltchenko 
437333055f2SGustavo F. Padovan 	write_lock(&chan_list_lock);
43823691d75SGustavo F. Padovan 	list_add(&chan->global_l, &chan_list);
439333055f2SGustavo F. Padovan 	write_unlock(&chan_list_lock);
44023691d75SGustavo F. Padovan 
441721c4181SGustavo F. Padovan 	INIT_DELAYED_WORK(&chan->chan_timer, l2cap_chan_timeout);
442ab07801dSGustavo F. Padovan 
44389bc500eSGustavo F. Padovan 	chan->state = BT_OPEN;
44489bc500eSGustavo F. Padovan 
445144ad330SSyam Sidhardhan 	kref_init(&chan->kref);
44671ba0e56SGustavo F. Padovan 
4472827011fSMat Martineau 	/* This flag is cleared in l2cap_chan_ready() */
4482827011fSMat Martineau 	set_bit(CONF_NOT_COMPLETE, &chan->conf_state);
4492827011fSMat Martineau 
450eef1d9b6SGustavo Padovan 	BT_DBG("chan %p", chan);
451abc545b8SSzymon Janc 
45248454079SGustavo F. Padovan 	return chan;
4530a708f8fSGustavo F. Padovan }
4540a708f8fSGustavo F. Padovan 
455144ad330SSyam Sidhardhan static void l2cap_chan_destroy(struct kref *kref)
4566ff5abbfSGustavo F. Padovan {
457144ad330SSyam Sidhardhan 	struct l2cap_chan *chan = container_of(kref, struct l2cap_chan, kref);
458144ad330SSyam Sidhardhan 
4594af66c69SJaganath Kanakkassery 	BT_DBG("chan %p", chan);
4604af66c69SJaganath Kanakkassery 
461333055f2SGustavo F. Padovan 	write_lock(&chan_list_lock);
46223691d75SGustavo F. Padovan 	list_del(&chan->global_l);
463333055f2SGustavo F. Padovan 	write_unlock(&chan_list_lock);
46423691d75SGustavo F. Padovan 
4654af66c69SJaganath Kanakkassery 	kfree(chan);
4666ff5abbfSGustavo F. Padovan }
4676ff5abbfSGustavo F. Padovan 
46830648372SJaganath Kanakkassery void l2cap_chan_hold(struct l2cap_chan *c)
46930648372SJaganath Kanakkassery {
470144ad330SSyam Sidhardhan 	BT_DBG("chan %p orig refcnt %d", c, atomic_read(&c->kref.refcount));
47130648372SJaganath Kanakkassery 
472144ad330SSyam Sidhardhan 	kref_get(&c->kref);
47330648372SJaganath Kanakkassery }
47430648372SJaganath Kanakkassery 
47530648372SJaganath Kanakkassery void l2cap_chan_put(struct l2cap_chan *c)
47630648372SJaganath Kanakkassery {
477144ad330SSyam Sidhardhan 	BT_DBG("chan %p orig refcnt %d", c, atomic_read(&c->kref.refcount));
47830648372SJaganath Kanakkassery 
479144ad330SSyam Sidhardhan 	kref_put(&c->kref, l2cap_chan_destroy);
48030648372SJaganath Kanakkassery }
48130648372SJaganath Kanakkassery 
482bd4b1653SAndrei Emeltchenko void l2cap_chan_set_defaults(struct l2cap_chan *chan)
483bd4b1653SAndrei Emeltchenko {
484bd4b1653SAndrei Emeltchenko 	chan->fcs  = L2CAP_FCS_CRC16;
485bd4b1653SAndrei Emeltchenko 	chan->max_tx = L2CAP_DEFAULT_MAX_TX;
486bd4b1653SAndrei Emeltchenko 	chan->tx_win = L2CAP_DEFAULT_TX_WINDOW;
487bd4b1653SAndrei Emeltchenko 	chan->tx_win_max = L2CAP_DEFAULT_TX_WINDOW;
488c20f8e35SMat Martineau 	chan->ack_win = L2CAP_DEFAULT_TX_WINDOW;
489bd4b1653SAndrei Emeltchenko 	chan->sec_level = BT_SECURITY_LOW;
490bd4b1653SAndrei Emeltchenko 
491bd4b1653SAndrei Emeltchenko 	set_bit(FLAG_FORCE_ACTIVE, &chan->flags);
492bd4b1653SAndrei Emeltchenko }
493bd4b1653SAndrei Emeltchenko 
49493c3e8f5SAndrei Emeltchenko void __l2cap_chan_add(struct l2cap_conn *conn, struct l2cap_chan *chan)
4950a708f8fSGustavo F. Padovan {
4960a708f8fSGustavo F. Padovan 	BT_DBG("conn %p, psm 0x%2.2x, dcid 0x%4.4x", conn,
497097db76cSAndrei Emeltchenko 	       __le16_to_cpu(chan->psm), chan->dcid);
4980a708f8fSGustavo F. Padovan 
4999f5a0d7bSAndrei Emeltchenko 	conn->disc_reason = HCI_ERROR_REMOTE_USER_TERM;
5000a708f8fSGustavo F. Padovan 
5018c1d787bSGustavo F. Padovan 	chan->conn = conn;
5020a708f8fSGustavo F. Padovan 
5035491120eSAndrei Emeltchenko 	switch (chan->chan_type) {
5045491120eSAndrei Emeltchenko 	case L2CAP_CHAN_CONN_ORIENTED:
505b62f328bSVille Tervo 		if (conn->hcon->type == LE_LINK) {
506b62f328bSVille Tervo 			/* LE connection */
5076fcb06a2SAndre Guedes 			chan->omtu = L2CAP_DEFAULT_MTU;
5089f22398cSJohan Hedberg 			if (chan->dcid == L2CAP_CID_ATT)
509073d1cf3SJohan Hedberg 				chan->scid = L2CAP_CID_ATT;
5109f22398cSJohan Hedberg 			else
5119f22398cSJohan Hedberg 				chan->scid = l2cap_alloc_cid(conn);
512b62f328bSVille Tervo 		} else {
5130a708f8fSGustavo F. Padovan 			/* Alloc CID for connection-oriented socket */
514fe4128e0SGustavo F. Padovan 			chan->scid = l2cap_alloc_cid(conn);
5150c1bc5c6SGustavo F. Padovan 			chan->omtu = L2CAP_DEFAULT_MTU;
516b62f328bSVille Tervo 		}
5175491120eSAndrei Emeltchenko 		break;
5185491120eSAndrei Emeltchenko 
5195491120eSAndrei Emeltchenko 	case L2CAP_CHAN_CONN_LESS:
5200a708f8fSGustavo F. Padovan 		/* Connectionless socket */
521fe4128e0SGustavo F. Padovan 		chan->scid = L2CAP_CID_CONN_LESS;
522fe4128e0SGustavo F. Padovan 		chan->dcid = L2CAP_CID_CONN_LESS;
5230c1bc5c6SGustavo F. Padovan 		chan->omtu = L2CAP_DEFAULT_MTU;
5245491120eSAndrei Emeltchenko 		break;
5255491120eSAndrei Emeltchenko 
526416fa752SAndrei Emeltchenko 	case L2CAP_CHAN_CONN_FIX_A2MP:
527416fa752SAndrei Emeltchenko 		chan->scid = L2CAP_CID_A2MP;
528416fa752SAndrei Emeltchenko 		chan->dcid = L2CAP_CID_A2MP;
529416fa752SAndrei Emeltchenko 		chan->omtu = L2CAP_A2MP_DEFAULT_MTU;
530416fa752SAndrei Emeltchenko 		chan->imtu = L2CAP_A2MP_DEFAULT_MTU;
531416fa752SAndrei Emeltchenko 		break;
532416fa752SAndrei Emeltchenko 
5335491120eSAndrei Emeltchenko 	default:
5340a708f8fSGustavo F. Padovan 		/* Raw socket can send/recv signalling messages only */
535fe4128e0SGustavo F. Padovan 		chan->scid = L2CAP_CID_SIGNALING;
536fe4128e0SGustavo F. Padovan 		chan->dcid = L2CAP_CID_SIGNALING;
5370c1bc5c6SGustavo F. Padovan 		chan->omtu = L2CAP_DEFAULT_MTU;
5380a708f8fSGustavo F. Padovan 	}
5390a708f8fSGustavo F. Padovan 
5408f7975b1SAndrei Emeltchenko 	chan->local_id		= L2CAP_BESTEFFORT_ID;
5418f7975b1SAndrei Emeltchenko 	chan->local_stype	= L2CAP_SERV_BESTEFFORT;
5428f7975b1SAndrei Emeltchenko 	chan->local_msdu	= L2CAP_DEFAULT_MAX_SDU_SIZE;
5438f7975b1SAndrei Emeltchenko 	chan->local_sdu_itime	= L2CAP_DEFAULT_SDU_ITIME;
5448f7975b1SAndrei Emeltchenko 	chan->local_acc_lat	= L2CAP_DEFAULT_ACC_LAT;
5458936fa6dSAndrei Emeltchenko 	chan->local_flush_to	= L2CAP_EFS_DEFAULT_FLUSH_TO;
5468f7975b1SAndrei Emeltchenko 
547371fd835SUlisses Furquim 	l2cap_chan_hold(chan);
548baa7e1faSGustavo F. Padovan 
5495ee9891dSJohan Hedberg 	hci_conn_hold(conn->hcon);
5505ee9891dSJohan Hedberg 
5513df91ea2SAndrei Emeltchenko 	list_add(&chan->list, &conn->chan_l);
552643162a8SAndrei Emeltchenko }
553643162a8SAndrei Emeltchenko 
554466f8004SAndrei Emeltchenko void l2cap_chan_add(struct l2cap_conn *conn, struct l2cap_chan *chan)
555643162a8SAndrei Emeltchenko {
556643162a8SAndrei Emeltchenko 	mutex_lock(&conn->chan_lock);
557643162a8SAndrei Emeltchenko 	__l2cap_chan_add(conn, chan);
5583df91ea2SAndrei Emeltchenko 	mutex_unlock(&conn->chan_lock);
5590a708f8fSGustavo F. Padovan }
5600a708f8fSGustavo F. Padovan 
561466f8004SAndrei Emeltchenko void l2cap_chan_del(struct l2cap_chan *chan, int err)
5620a708f8fSGustavo F. Padovan {
5638c1d787bSGustavo F. Padovan 	struct l2cap_conn *conn = chan->conn;
5640a708f8fSGustavo F. Padovan 
565c9b66675SGustavo F. Padovan 	__clear_chan_timer(chan);
5660a708f8fSGustavo F. Padovan 
56749208c9cSGustavo F. Padovan 	BT_DBG("chan %p, conn %p, err %d", chan, conn, err);
5680a708f8fSGustavo F. Padovan 
5690a708f8fSGustavo F. Padovan 	if (conn) {
57056f60984SAndrei Emeltchenko 		struct amp_mgr *mgr = conn->hcon->amp_mgr;
571baa7e1faSGustavo F. Padovan 		/* Delete from channel list */
5723df91ea2SAndrei Emeltchenko 		list_del(&chan->list);
5733d57dc68SGustavo F. Padovan 
574371fd835SUlisses Furquim 		l2cap_chan_put(chan);
575baa7e1faSGustavo F. Padovan 
5768c1d787bSGustavo F. Padovan 		chan->conn = NULL;
5773cabbfdaSAndrei Emeltchenko 
5783cabbfdaSAndrei Emeltchenko 		if (chan->chan_type != L2CAP_CHAN_CONN_FIX_A2MP)
57976a68ba0SDavid Herrmann 			hci_conn_drop(conn->hcon);
58056f60984SAndrei Emeltchenko 
58156f60984SAndrei Emeltchenko 		if (mgr && mgr->bredr_chan == chan)
58256f60984SAndrei Emeltchenko 			mgr->bredr_chan = NULL;
5830a708f8fSGustavo F. Padovan 	}
5840a708f8fSGustavo F. Padovan 
585419e08c1SAndrei Emeltchenko 	if (chan->hs_hchan) {
586419e08c1SAndrei Emeltchenko 		struct hci_chan *hs_hchan = chan->hs_hchan;
587419e08c1SAndrei Emeltchenko 
588419e08c1SAndrei Emeltchenko 		BT_DBG("chan %p disconnect hs_hchan %p", chan, hs_hchan);
589419e08c1SAndrei Emeltchenko 		amp_disconnect_logical_link(hs_hchan);
590419e08c1SAndrei Emeltchenko 	}
591419e08c1SAndrei Emeltchenko 
592c0df7f6eSAndrei Emeltchenko 	chan->ops->teardown(chan, err);
5936be36555SAndrei Emeltchenko 
5942827011fSMat Martineau 	if (test_bit(CONF_NOT_COMPLETE, &chan->conf_state))
5956ff5abbfSGustavo F. Padovan 		return;
5962ead70b8SGustavo F. Padovan 
597ee556f66SGustavo Padovan 	switch(chan->mode) {
598ee556f66SGustavo Padovan 	case L2CAP_MODE_BASIC:
599ee556f66SGustavo Padovan 		break;
6000a708f8fSGustavo F. Padovan 
601ee556f66SGustavo Padovan 	case L2CAP_MODE_ERTM:
6021a09bcb9SGustavo F. Padovan 		__clear_retrans_timer(chan);
6031a09bcb9SGustavo F. Padovan 		__clear_monitor_timer(chan);
6041a09bcb9SGustavo F. Padovan 		__clear_ack_timer(chan);
6050a708f8fSGustavo F. Padovan 
606f1c6775bSGustavo F. Padovan 		skb_queue_purge(&chan->srej_q);
6070a708f8fSGustavo F. Padovan 
6083c588192SMat Martineau 		l2cap_seq_list_free(&chan->srej_list);
6093c588192SMat Martineau 		l2cap_seq_list_free(&chan->retrans_list);
610ee556f66SGustavo Padovan 
611ee556f66SGustavo Padovan 		/* fall through */
612ee556f66SGustavo Padovan 
613ee556f66SGustavo Padovan 	case L2CAP_MODE_STREAMING:
614ee556f66SGustavo Padovan 		skb_queue_purge(&chan->tx_q);
615ee556f66SGustavo Padovan 		break;
6160a708f8fSGustavo F. Padovan 	}
617ee556f66SGustavo Padovan 
618ee556f66SGustavo Padovan 	return;
6190a708f8fSGustavo F. Padovan }
6200a708f8fSGustavo F. Padovan 
6210f852724SGustavo F. Padovan void l2cap_chan_close(struct l2cap_chan *chan, int reason)
6224519de9aSGustavo F. Padovan {
6234519de9aSGustavo F. Padovan 	struct l2cap_conn *conn = chan->conn;
6244519de9aSGustavo F. Padovan 	struct sock *sk = chan->sk;
6254519de9aSGustavo F. Padovan 
6262d792818SGustavo Padovan 	BT_DBG("chan %p state %s sk %p", chan, state_to_string(chan->state),
6272d792818SGustavo Padovan 	       sk);
6284519de9aSGustavo F. Padovan 
62989bc500eSGustavo F. Padovan 	switch (chan->state) {
6304519de9aSGustavo F. Padovan 	case BT_LISTEN:
631c0df7f6eSAndrei Emeltchenko 		chan->ops->teardown(chan, 0);
6324519de9aSGustavo F. Padovan 		break;
6334519de9aSGustavo F. Padovan 
6344519de9aSGustavo F. Padovan 	case BT_CONNECTED:
6354519de9aSGustavo F. Padovan 	case BT_CONFIG:
636715ec005SGustavo F. Padovan 		if (chan->chan_type == L2CAP_CHAN_CONN_ORIENTED &&
6374519de9aSGustavo F. Padovan 		    conn->hcon->type == ACL_LINK) {
638c9b66675SGustavo F. Padovan 			__set_chan_timer(chan, sk->sk_sndtimeo);
6395e4e3972SAndrei Emeltchenko 			l2cap_send_disconn_req(chan, reason);
6404519de9aSGustavo F. Padovan 		} else
6414519de9aSGustavo F. Padovan 			l2cap_chan_del(chan, reason);
6424519de9aSGustavo F. Padovan 		break;
6434519de9aSGustavo F. Padovan 
6444519de9aSGustavo F. Padovan 	case BT_CONNECT2:
645715ec005SGustavo F. Padovan 		if (chan->chan_type == L2CAP_CHAN_CONN_ORIENTED &&
6464519de9aSGustavo F. Padovan 		    conn->hcon->type == ACL_LINK) {
6474519de9aSGustavo F. Padovan 			struct l2cap_conn_rsp rsp;
6484519de9aSGustavo F. Padovan 			__u16 result;
6494519de9aSGustavo F. Padovan 
650c5daa683SGustavo Padovan 			if (test_bit(BT_SK_DEFER_SETUP, &bt_sk(sk)->flags))
6514519de9aSGustavo F. Padovan 				result = L2CAP_CR_SEC_BLOCK;
6524519de9aSGustavo F. Padovan 			else
6534519de9aSGustavo F. Padovan 				result = L2CAP_CR_BAD_PSM;
65489bc500eSGustavo F. Padovan 			l2cap_state_change(chan, BT_DISCONN);
6554519de9aSGustavo F. Padovan 
6564519de9aSGustavo F. Padovan 			rsp.scid   = cpu_to_le16(chan->dcid);
6574519de9aSGustavo F. Padovan 			rsp.dcid   = cpu_to_le16(chan->scid);
6584519de9aSGustavo F. Padovan 			rsp.result = cpu_to_le16(result);
659ac73498cSAndrei Emeltchenko 			rsp.status = __constant_cpu_to_le16(L2CAP_CS_NO_INFO);
6604519de9aSGustavo F. Padovan 			l2cap_send_cmd(conn, chan->ident, L2CAP_CONN_RSP,
6614519de9aSGustavo F. Padovan 				       sizeof(rsp), &rsp);
6624519de9aSGustavo F. Padovan 		}
6634519de9aSGustavo F. Padovan 
6644519de9aSGustavo F. Padovan 		l2cap_chan_del(chan, reason);
6654519de9aSGustavo F. Padovan 		break;
6664519de9aSGustavo F. Padovan 
6674519de9aSGustavo F. Padovan 	case BT_CONNECT:
6684519de9aSGustavo F. Padovan 	case BT_DISCONN:
6694519de9aSGustavo F. Padovan 		l2cap_chan_del(chan, reason);
6704519de9aSGustavo F. Padovan 		break;
6714519de9aSGustavo F. Padovan 
6724519de9aSGustavo F. Padovan 	default:
673c0df7f6eSAndrei Emeltchenko 		chan->ops->teardown(chan, 0);
6744519de9aSGustavo F. Padovan 		break;
6754519de9aSGustavo F. Padovan 	}
6764519de9aSGustavo F. Padovan }
6774519de9aSGustavo F. Padovan 
6784343478fSGustavo F. Padovan static inline u8 l2cap_get_auth_type(struct l2cap_chan *chan)
6790a708f8fSGustavo F. Padovan {
680*6a974b50SMarcel Holtmann 	switch (chan->chan_type) {
681*6a974b50SMarcel Holtmann 	case L2CAP_CHAN_RAW:
6824343478fSGustavo F. Padovan 		switch (chan->sec_level) {
6830a708f8fSGustavo F. Padovan 		case BT_SECURITY_HIGH:
6840a708f8fSGustavo F. Padovan 			return HCI_AT_DEDICATED_BONDING_MITM;
6850a708f8fSGustavo F. Padovan 		case BT_SECURITY_MEDIUM:
6860a708f8fSGustavo F. Padovan 			return HCI_AT_DEDICATED_BONDING;
6870a708f8fSGustavo F. Padovan 		default:
6880a708f8fSGustavo F. Padovan 			return HCI_AT_NO_BONDING;
6890a708f8fSGustavo F. Padovan 		}
690*6a974b50SMarcel Holtmann 		break;
691*6a974b50SMarcel Holtmann 	case L2CAP_CHAN_CONN_ORIENTED:
692*6a974b50SMarcel Holtmann 		if (chan->psm == __constant_cpu_to_le16(L2CAP_PSM_SDP)) {
6934343478fSGustavo F. Padovan 			if (chan->sec_level == BT_SECURITY_LOW)
6944343478fSGustavo F. Padovan 				chan->sec_level = BT_SECURITY_SDP;
6950a708f8fSGustavo F. Padovan 
6964343478fSGustavo F. Padovan 			if (chan->sec_level == BT_SECURITY_HIGH)
6970a708f8fSGustavo F. Padovan 				return HCI_AT_NO_BONDING_MITM;
6980a708f8fSGustavo F. Padovan 			else
6990a708f8fSGustavo F. Padovan 				return HCI_AT_NO_BONDING;
700*6a974b50SMarcel Holtmann 		}
701*6a974b50SMarcel Holtmann 		/* fall through */
702*6a974b50SMarcel Holtmann 	default:
7034343478fSGustavo F. Padovan 		switch (chan->sec_level) {
7040a708f8fSGustavo F. Padovan 		case BT_SECURITY_HIGH:
7050a708f8fSGustavo F. Padovan 			return HCI_AT_GENERAL_BONDING_MITM;
7060a708f8fSGustavo F. Padovan 		case BT_SECURITY_MEDIUM:
7070a708f8fSGustavo F. Padovan 			return HCI_AT_GENERAL_BONDING;
7080a708f8fSGustavo F. Padovan 		default:
7090a708f8fSGustavo F. Padovan 			return HCI_AT_NO_BONDING;
7100a708f8fSGustavo F. Padovan 		}
711*6a974b50SMarcel Holtmann 		break;
7120a708f8fSGustavo F. Padovan 	}
7130a708f8fSGustavo F. Padovan }
7140a708f8fSGustavo F. Padovan 
7150a708f8fSGustavo F. Padovan /* Service level security */
716d45fc423SGustavo F. Padovan int l2cap_chan_check_security(struct l2cap_chan *chan)
7170a708f8fSGustavo F. Padovan {
7188c1d787bSGustavo F. Padovan 	struct l2cap_conn *conn = chan->conn;
7190a708f8fSGustavo F. Padovan 	__u8 auth_type;
7200a708f8fSGustavo F. Padovan 
7214343478fSGustavo F. Padovan 	auth_type = l2cap_get_auth_type(chan);
7220a708f8fSGustavo F. Padovan 
7234343478fSGustavo F. Padovan 	return hci_conn_security(conn->hcon, chan->sec_level, auth_type);
7240a708f8fSGustavo F. Padovan }
7250a708f8fSGustavo F. Padovan 
726b5ad8b7fSJohannes Berg static u8 l2cap_get_ident(struct l2cap_conn *conn)
7270a708f8fSGustavo F. Padovan {
7280a708f8fSGustavo F. Padovan 	u8 id;
7290a708f8fSGustavo F. Padovan 
7300a708f8fSGustavo F. Padovan 	/* Get next available identificator.
7310a708f8fSGustavo F. Padovan 	 *    1 - 128 are used by kernel.
7320a708f8fSGustavo F. Padovan 	 *  129 - 199 are reserved.
7330a708f8fSGustavo F. Padovan 	 *  200 - 254 are used by utilities like l2ping, etc.
7340a708f8fSGustavo F. Padovan 	 */
7350a708f8fSGustavo F. Padovan 
736333055f2SGustavo F. Padovan 	spin_lock(&conn->lock);
7370a708f8fSGustavo F. Padovan 
7380a708f8fSGustavo F. Padovan 	if (++conn->tx_ident > 128)
7390a708f8fSGustavo F. Padovan 		conn->tx_ident = 1;
7400a708f8fSGustavo F. Padovan 
7410a708f8fSGustavo F. Padovan 	id = conn->tx_ident;
7420a708f8fSGustavo F. Padovan 
743333055f2SGustavo F. Padovan 	spin_unlock(&conn->lock);
7440a708f8fSGustavo F. Padovan 
7450a708f8fSGustavo F. Padovan 	return id;
7460a708f8fSGustavo F. Padovan }
7470a708f8fSGustavo F. Padovan 
7482d792818SGustavo Padovan static void l2cap_send_cmd(struct l2cap_conn *conn, u8 ident, u8 code, u16 len,
7492d792818SGustavo Padovan 			   void *data)
7500a708f8fSGustavo F. Padovan {
7510a708f8fSGustavo F. Padovan 	struct sk_buff *skb = l2cap_build_cmd(conn, code, ident, len, data);
7520a708f8fSGustavo F. Padovan 	u8 flags;
7530a708f8fSGustavo F. Padovan 
7540a708f8fSGustavo F. Padovan 	BT_DBG("code 0x%2.2x", code);
7550a708f8fSGustavo F. Padovan 
7560a708f8fSGustavo F. Padovan 	if (!skb)
7570a708f8fSGustavo F. Padovan 		return;
7580a708f8fSGustavo F. Padovan 
7590a708f8fSGustavo F. Padovan 	if (lmp_no_flush_capable(conn->hcon->hdev))
7600a708f8fSGustavo F. Padovan 		flags = ACL_START_NO_FLUSH;
7610a708f8fSGustavo F. Padovan 	else
7620a708f8fSGustavo F. Padovan 		flags = ACL_START;
7630a708f8fSGustavo F. Padovan 
76414b12d0bSJaikumar Ganesh 	bt_cb(skb)->force_active = BT_POWER_FORCE_ACTIVE_ON;
7655e59b791SLuiz Augusto von Dentz 	skb->priority = HCI_PRIO_MAX;
76614b12d0bSJaikumar Ganesh 
76773d80debSLuiz Augusto von Dentz 	hci_send_acl(conn->hchan, skb, flags);
7680a708f8fSGustavo F. Padovan }
7690a708f8fSGustavo F. Padovan 
77002b0fbb9SMat Martineau static bool __chan_is_moving(struct l2cap_chan *chan)
77102b0fbb9SMat Martineau {
77202b0fbb9SMat Martineau 	return chan->move_state != L2CAP_MOVE_STABLE &&
77302b0fbb9SMat Martineau 	       chan->move_state != L2CAP_MOVE_WAIT_PREPARE;
77402b0fbb9SMat Martineau }
77502b0fbb9SMat Martineau 
77673d80debSLuiz Augusto von Dentz static void l2cap_do_send(struct l2cap_chan *chan, struct sk_buff *skb)
77773d80debSLuiz Augusto von Dentz {
77873d80debSLuiz Augusto von Dentz 	struct hci_conn *hcon = chan->conn->hcon;
77973d80debSLuiz Augusto von Dentz 	u16 flags;
78073d80debSLuiz Augusto von Dentz 
78173d80debSLuiz Augusto von Dentz 	BT_DBG("chan %p, skb %p len %d priority %u", chan, skb, skb->len,
78273d80debSLuiz Augusto von Dentz 	       skb->priority);
78373d80debSLuiz Augusto von Dentz 
784d5f8a75dSMat Martineau 	if (chan->hs_hcon && !__chan_is_moving(chan)) {
785d5f8a75dSMat Martineau 		if (chan->hs_hchan)
786d5f8a75dSMat Martineau 			hci_send_acl(chan->hs_hchan, skb, ACL_COMPLETE);
787d5f8a75dSMat Martineau 		else
788d5f8a75dSMat Martineau 			kfree_skb(skb);
789d5f8a75dSMat Martineau 
790d5f8a75dSMat Martineau 		return;
791d5f8a75dSMat Martineau 	}
792d5f8a75dSMat Martineau 
79373d80debSLuiz Augusto von Dentz 	if (!test_bit(FLAG_FLUSHABLE, &chan->flags) &&
79473d80debSLuiz Augusto von Dentz 	    lmp_no_flush_capable(hcon->hdev))
79573d80debSLuiz Augusto von Dentz 		flags = ACL_START_NO_FLUSH;
79673d80debSLuiz Augusto von Dentz 	else
79773d80debSLuiz Augusto von Dentz 		flags = ACL_START;
79873d80debSLuiz Augusto von Dentz 
79973d80debSLuiz Augusto von Dentz 	bt_cb(skb)->force_active = test_bit(FLAG_FORCE_ACTIVE, &chan->flags);
80073d80debSLuiz Augusto von Dentz 	hci_send_acl(chan->conn->hchan, skb, flags);
8010a708f8fSGustavo F. Padovan }
8020a708f8fSGustavo F. Padovan 
803b5c6aaedSMat Martineau static void __unpack_enhanced_control(u16 enh, struct l2cap_ctrl *control)
804b5c6aaedSMat Martineau {
805b5c6aaedSMat Martineau 	control->reqseq = (enh & L2CAP_CTRL_REQSEQ) >> L2CAP_CTRL_REQSEQ_SHIFT;
806b5c6aaedSMat Martineau 	control->final = (enh & L2CAP_CTRL_FINAL) >> L2CAP_CTRL_FINAL_SHIFT;
807b5c6aaedSMat Martineau 
808b5c6aaedSMat Martineau 	if (enh & L2CAP_CTRL_FRAME_TYPE) {
809b5c6aaedSMat Martineau 		/* S-Frame */
810b5c6aaedSMat Martineau 		control->sframe = 1;
811b5c6aaedSMat Martineau 		control->poll = (enh & L2CAP_CTRL_POLL) >> L2CAP_CTRL_POLL_SHIFT;
812b5c6aaedSMat Martineau 		control->super = (enh & L2CAP_CTRL_SUPERVISE) >> L2CAP_CTRL_SUPER_SHIFT;
813b5c6aaedSMat Martineau 
814b5c6aaedSMat Martineau 		control->sar = 0;
815b5c6aaedSMat Martineau 		control->txseq = 0;
816b5c6aaedSMat Martineau 	} else {
817b5c6aaedSMat Martineau 		/* I-Frame */
818b5c6aaedSMat Martineau 		control->sframe = 0;
819b5c6aaedSMat Martineau 		control->sar = (enh & L2CAP_CTRL_SAR) >> L2CAP_CTRL_SAR_SHIFT;
820b5c6aaedSMat Martineau 		control->txseq = (enh & L2CAP_CTRL_TXSEQ) >> L2CAP_CTRL_TXSEQ_SHIFT;
821b5c6aaedSMat Martineau 
822b5c6aaedSMat Martineau 		control->poll = 0;
823b5c6aaedSMat Martineau 		control->super = 0;
824b5c6aaedSMat Martineau 	}
825b5c6aaedSMat Martineau }
826b5c6aaedSMat Martineau 
827b5c6aaedSMat Martineau static void __unpack_extended_control(u32 ext, struct l2cap_ctrl *control)
828b5c6aaedSMat Martineau {
829b5c6aaedSMat Martineau 	control->reqseq = (ext & L2CAP_EXT_CTRL_REQSEQ) >> L2CAP_EXT_CTRL_REQSEQ_SHIFT;
830b5c6aaedSMat Martineau 	control->final = (ext & L2CAP_EXT_CTRL_FINAL) >> L2CAP_EXT_CTRL_FINAL_SHIFT;
831b5c6aaedSMat Martineau 
832b5c6aaedSMat Martineau 	if (ext & L2CAP_EXT_CTRL_FRAME_TYPE) {
833b5c6aaedSMat Martineau 		/* S-Frame */
834b5c6aaedSMat Martineau 		control->sframe = 1;
835b5c6aaedSMat Martineau 		control->poll = (ext & L2CAP_EXT_CTRL_POLL) >> L2CAP_EXT_CTRL_POLL_SHIFT;
836b5c6aaedSMat Martineau 		control->super = (ext & L2CAP_EXT_CTRL_SUPERVISE) >> L2CAP_EXT_CTRL_SUPER_SHIFT;
837b5c6aaedSMat Martineau 
838b5c6aaedSMat Martineau 		control->sar = 0;
839b5c6aaedSMat Martineau 		control->txseq = 0;
840b5c6aaedSMat Martineau 	} else {
841b5c6aaedSMat Martineau 		/* I-Frame */
842b5c6aaedSMat Martineau 		control->sframe = 0;
843b5c6aaedSMat Martineau 		control->sar = (ext & L2CAP_EXT_CTRL_SAR) >> L2CAP_EXT_CTRL_SAR_SHIFT;
844b5c6aaedSMat Martineau 		control->txseq = (ext & L2CAP_EXT_CTRL_TXSEQ) >> L2CAP_EXT_CTRL_TXSEQ_SHIFT;
845b5c6aaedSMat Martineau 
846b5c6aaedSMat Martineau 		control->poll = 0;
847b5c6aaedSMat Martineau 		control->super = 0;
848b5c6aaedSMat Martineau 	}
849b5c6aaedSMat Martineau }
850b5c6aaedSMat Martineau 
851b5c6aaedSMat Martineau static inline void __unpack_control(struct l2cap_chan *chan,
852b5c6aaedSMat Martineau 				    struct sk_buff *skb)
853b5c6aaedSMat Martineau {
854b5c6aaedSMat Martineau 	if (test_bit(FLAG_EXT_CTRL, &chan->flags)) {
855b5c6aaedSMat Martineau 		__unpack_extended_control(get_unaligned_le32(skb->data),
856b5c6aaedSMat Martineau 					  &bt_cb(skb)->control);
857cec8ab6eSMat Martineau 		skb_pull(skb, L2CAP_EXT_CTRL_SIZE);
858b5c6aaedSMat Martineau 	} else {
859b5c6aaedSMat Martineau 		__unpack_enhanced_control(get_unaligned_le16(skb->data),
860b5c6aaedSMat Martineau 					  &bt_cb(skb)->control);
861cec8ab6eSMat Martineau 		skb_pull(skb, L2CAP_ENH_CTRL_SIZE);
862b5c6aaedSMat Martineau 	}
863b5c6aaedSMat Martineau }
864b5c6aaedSMat Martineau 
865b5c6aaedSMat Martineau static u32 __pack_extended_control(struct l2cap_ctrl *control)
866b5c6aaedSMat Martineau {
867b5c6aaedSMat Martineau 	u32 packed;
868b5c6aaedSMat Martineau 
869b5c6aaedSMat Martineau 	packed = control->reqseq << L2CAP_EXT_CTRL_REQSEQ_SHIFT;
870b5c6aaedSMat Martineau 	packed |= control->final << L2CAP_EXT_CTRL_FINAL_SHIFT;
871b5c6aaedSMat Martineau 
872b5c6aaedSMat Martineau 	if (control->sframe) {
873b5c6aaedSMat Martineau 		packed |= control->poll << L2CAP_EXT_CTRL_POLL_SHIFT;
874b5c6aaedSMat Martineau 		packed |= control->super << L2CAP_EXT_CTRL_SUPER_SHIFT;
875b5c6aaedSMat Martineau 		packed |= L2CAP_EXT_CTRL_FRAME_TYPE;
876b5c6aaedSMat Martineau 	} else {
877b5c6aaedSMat Martineau 		packed |= control->sar << L2CAP_EXT_CTRL_SAR_SHIFT;
878b5c6aaedSMat Martineau 		packed |= control->txseq << L2CAP_EXT_CTRL_TXSEQ_SHIFT;
879b5c6aaedSMat Martineau 	}
880b5c6aaedSMat Martineau 
881b5c6aaedSMat Martineau 	return packed;
882b5c6aaedSMat Martineau }
883b5c6aaedSMat Martineau 
884b5c6aaedSMat Martineau static u16 __pack_enhanced_control(struct l2cap_ctrl *control)
885b5c6aaedSMat Martineau {
886b5c6aaedSMat Martineau 	u16 packed;
887b5c6aaedSMat Martineau 
888b5c6aaedSMat Martineau 	packed = control->reqseq << L2CAP_CTRL_REQSEQ_SHIFT;
889b5c6aaedSMat Martineau 	packed |= control->final << L2CAP_CTRL_FINAL_SHIFT;
890b5c6aaedSMat Martineau 
891b5c6aaedSMat Martineau 	if (control->sframe) {
892b5c6aaedSMat Martineau 		packed |= control->poll << L2CAP_CTRL_POLL_SHIFT;
893b5c6aaedSMat Martineau 		packed |= control->super << L2CAP_CTRL_SUPER_SHIFT;
894b5c6aaedSMat Martineau 		packed |= L2CAP_CTRL_FRAME_TYPE;
895b5c6aaedSMat Martineau 	} else {
896b5c6aaedSMat Martineau 		packed |= control->sar << L2CAP_CTRL_SAR_SHIFT;
897b5c6aaedSMat Martineau 		packed |= control->txseq << L2CAP_CTRL_TXSEQ_SHIFT;
898b5c6aaedSMat Martineau 	}
899b5c6aaedSMat Martineau 
900b5c6aaedSMat Martineau 	return packed;
901b5c6aaedSMat Martineau }
902b5c6aaedSMat Martineau 
903b5c6aaedSMat Martineau static inline void __pack_control(struct l2cap_chan *chan,
904b5c6aaedSMat Martineau 				  struct l2cap_ctrl *control,
905b5c6aaedSMat Martineau 				  struct sk_buff *skb)
906b5c6aaedSMat Martineau {
907b5c6aaedSMat Martineau 	if (test_bit(FLAG_EXT_CTRL, &chan->flags)) {
908b5c6aaedSMat Martineau 		put_unaligned_le32(__pack_extended_control(control),
909b5c6aaedSMat Martineau 				   skb->data + L2CAP_HDR_SIZE);
910b5c6aaedSMat Martineau 	} else {
911b5c6aaedSMat Martineau 		put_unaligned_le16(__pack_enhanced_control(control),
912b5c6aaedSMat Martineau 				   skb->data + L2CAP_HDR_SIZE);
913b5c6aaedSMat Martineau 	}
914b5c6aaedSMat Martineau }
915b5c6aaedSMat Martineau 
916ba7aa64fSGustavo Padovan static inline unsigned int __ertm_hdr_size(struct l2cap_chan *chan)
917ba7aa64fSGustavo Padovan {
918ba7aa64fSGustavo Padovan 	if (test_bit(FLAG_EXT_CTRL, &chan->flags))
919ba7aa64fSGustavo Padovan 		return L2CAP_EXT_HDR_SIZE;
920ba7aa64fSGustavo Padovan 	else
921ba7aa64fSGustavo Padovan 		return L2CAP_ENH_HDR_SIZE;
922ba7aa64fSGustavo Padovan }
923ba7aa64fSGustavo Padovan 
924a67d7f6fSMat Martineau static struct sk_buff *l2cap_create_sframe_pdu(struct l2cap_chan *chan,
925a67d7f6fSMat Martineau 					       u32 control)
9260a708f8fSGustavo F. Padovan {
9270a708f8fSGustavo F. Padovan 	struct sk_buff *skb;
9280a708f8fSGustavo F. Padovan 	struct l2cap_hdr *lh;
929ba7aa64fSGustavo Padovan 	int hlen = __ertm_hdr_size(chan);
9300a708f8fSGustavo F. Padovan 
9310a708f8fSGustavo F. Padovan 	if (chan->fcs == L2CAP_FCS_CRC16)
93203a51213SAndrei Emeltchenko 		hlen += L2CAP_FCS_SIZE;
9330a708f8fSGustavo F. Padovan 
934a67d7f6fSMat Martineau 	skb = bt_skb_alloc(hlen, GFP_KERNEL);
9350a708f8fSGustavo F. Padovan 
9360a708f8fSGustavo F. Padovan 	if (!skb)
937a67d7f6fSMat Martineau 		return ERR_PTR(-ENOMEM);
9380a708f8fSGustavo F. Padovan 
9390a708f8fSGustavo F. Padovan 	lh = (struct l2cap_hdr *) skb_put(skb, L2CAP_HDR_SIZE);
9400a708f8fSGustavo F. Padovan 	lh->len = cpu_to_le16(hlen - L2CAP_HDR_SIZE);
941fe4128e0SGustavo F. Padovan 	lh->cid = cpu_to_le16(chan->dcid);
94288843ab0SAndrei Emeltchenko 
943a67d7f6fSMat Martineau 	if (test_bit(FLAG_EXT_CTRL, &chan->flags))
944a67d7f6fSMat Martineau 		put_unaligned_le32(control, skb_put(skb, L2CAP_EXT_CTRL_SIZE));
945a67d7f6fSMat Martineau 	else
946a67d7f6fSMat Martineau 		put_unaligned_le16(control, skb_put(skb, L2CAP_ENH_CTRL_SIZE));
9470a708f8fSGustavo F. Padovan 
94847d1ec61SGustavo F. Padovan 	if (chan->fcs == L2CAP_FCS_CRC16) {
949a67d7f6fSMat Martineau 		u16 fcs = crc16(0, (u8 *)skb->data, skb->len);
95003a51213SAndrei Emeltchenko 		put_unaligned_le16(fcs, skb_put(skb, L2CAP_FCS_SIZE));
9510a708f8fSGustavo F. Padovan 	}
9520a708f8fSGustavo F. Padovan 
95373d80debSLuiz Augusto von Dentz 	skb->priority = HCI_PRIO_MAX;
954a67d7f6fSMat Martineau 	return skb;
955a67d7f6fSMat Martineau }
956a67d7f6fSMat Martineau 
957a67d7f6fSMat Martineau static void l2cap_send_sframe(struct l2cap_chan *chan,
958a67d7f6fSMat Martineau 			      struct l2cap_ctrl *control)
959a67d7f6fSMat Martineau {
960a67d7f6fSMat Martineau 	struct sk_buff *skb;
961a67d7f6fSMat Martineau 	u32 control_field;
962a67d7f6fSMat Martineau 
963a67d7f6fSMat Martineau 	BT_DBG("chan %p, control %p", chan, control);
964a67d7f6fSMat Martineau 
965a67d7f6fSMat Martineau 	if (!control->sframe)
966a67d7f6fSMat Martineau 		return;
967a67d7f6fSMat Martineau 
968b99e13adSMat Martineau 	if (__chan_is_moving(chan))
969b99e13adSMat Martineau 		return;
970b99e13adSMat Martineau 
971a67d7f6fSMat Martineau 	if (test_and_clear_bit(CONN_SEND_FBIT, &chan->conn_state) &&
972a67d7f6fSMat Martineau 	    !control->poll)
973a67d7f6fSMat Martineau 		control->final = 1;
974a67d7f6fSMat Martineau 
975a67d7f6fSMat Martineau 	if (control->super == L2CAP_SUPER_RR)
976a67d7f6fSMat Martineau 		clear_bit(CONN_RNR_SENT, &chan->conn_state);
977a67d7f6fSMat Martineau 	else if (control->super == L2CAP_SUPER_RNR)
978a67d7f6fSMat Martineau 		set_bit(CONN_RNR_SENT, &chan->conn_state);
979a67d7f6fSMat Martineau 
980a67d7f6fSMat Martineau 	if (control->super != L2CAP_SUPER_SREJ) {
981a67d7f6fSMat Martineau 		chan->last_acked_seq = control->reqseq;
982a67d7f6fSMat Martineau 		__clear_ack_timer(chan);
983a67d7f6fSMat Martineau 	}
984a67d7f6fSMat Martineau 
985a67d7f6fSMat Martineau 	BT_DBG("reqseq %d, final %d, poll %d, super %d", control->reqseq,
986a67d7f6fSMat Martineau 	       control->final, control->poll, control->super);
987a67d7f6fSMat Martineau 
988a67d7f6fSMat Martineau 	if (test_bit(FLAG_EXT_CTRL, &chan->flags))
989a67d7f6fSMat Martineau 		control_field = __pack_extended_control(control);
990a67d7f6fSMat Martineau 	else
991a67d7f6fSMat Martineau 		control_field = __pack_enhanced_control(control);
992a67d7f6fSMat Martineau 
993a67d7f6fSMat Martineau 	skb = l2cap_create_sframe_pdu(chan, control_field);
994a67d7f6fSMat Martineau 	if (!IS_ERR(skb))
99573d80debSLuiz Augusto von Dentz 		l2cap_do_send(chan, skb);
9960a708f8fSGustavo F. Padovan }
9970a708f8fSGustavo F. Padovan 
998c9e3d5e0SMat Martineau static void l2cap_send_rr_or_rnr(struct l2cap_chan *chan, bool poll)
9990a708f8fSGustavo F. Padovan {
1000c9e3d5e0SMat Martineau 	struct l2cap_ctrl control;
10010a708f8fSGustavo F. Padovan 
1002c9e3d5e0SMat Martineau 	BT_DBG("chan %p, poll %d", chan, poll);
1003c9e3d5e0SMat Martineau 
1004c9e3d5e0SMat Martineau 	memset(&control, 0, sizeof(control));
1005c9e3d5e0SMat Martineau 	control.sframe = 1;
1006c9e3d5e0SMat Martineau 	control.poll = poll;
1007c9e3d5e0SMat Martineau 
1008c9e3d5e0SMat Martineau 	if (test_bit(CONN_LOCAL_BUSY, &chan->conn_state))
1009c9e3d5e0SMat Martineau 		control.super = L2CAP_SUPER_RNR;
1010c9e3d5e0SMat Martineau 	else
1011c9e3d5e0SMat Martineau 		control.super = L2CAP_SUPER_RR;
1012c9e3d5e0SMat Martineau 
1013c9e3d5e0SMat Martineau 	control.reqseq = chan->buffer_seq;
1014c9e3d5e0SMat Martineau 	l2cap_send_sframe(chan, &control);
10150a708f8fSGustavo F. Padovan }
10160a708f8fSGustavo F. Padovan 
1017b4450035SGustavo F. Padovan static inline int __l2cap_no_conn_pending(struct l2cap_chan *chan)
10180a708f8fSGustavo F. Padovan {
1019c1360a1cSGustavo F. Padovan 	return !test_bit(CONF_CONNECT_PEND, &chan->conf_state);
10200a708f8fSGustavo F. Padovan }
10210a708f8fSGustavo F. Padovan 
102293c3e8f5SAndrei Emeltchenko static bool __amp_capable(struct l2cap_chan *chan)
102393c3e8f5SAndrei Emeltchenko {
102493c3e8f5SAndrei Emeltchenko 	struct l2cap_conn *conn = chan->conn;
10251df7b17aSMarcel Holtmann 	struct hci_dev *hdev;
10261df7b17aSMarcel Holtmann 	bool amp_available = false;
102793c3e8f5SAndrei Emeltchenko 
10281df7b17aSMarcel Holtmann 	if (!conn->hs_enabled)
10291df7b17aSMarcel Holtmann 		return false;
10301df7b17aSMarcel Holtmann 
10311df7b17aSMarcel Holtmann 	if (!(conn->fixed_chan_mask & L2CAP_FC_A2MP))
10321df7b17aSMarcel Holtmann 		return false;
10331df7b17aSMarcel Holtmann 
10341df7b17aSMarcel Holtmann 	read_lock(&hci_dev_list_lock);
10351df7b17aSMarcel Holtmann 	list_for_each_entry(hdev, &hci_dev_list, list) {
10361df7b17aSMarcel Holtmann 		if (hdev->amp_type != AMP_TYPE_BREDR &&
10371df7b17aSMarcel Holtmann 		    test_bit(HCI_UP, &hdev->flags)) {
10381df7b17aSMarcel Holtmann 			amp_available = true;
10391df7b17aSMarcel Holtmann 			break;
10401df7b17aSMarcel Holtmann 		}
10411df7b17aSMarcel Holtmann 	}
10421df7b17aSMarcel Holtmann 	read_unlock(&hci_dev_list_lock);
10431df7b17aSMarcel Holtmann 
10441df7b17aSMarcel Holtmann 	if (chan->chan_policy == BT_CHANNEL_POLICY_AMP_PREFERRED)
10451df7b17aSMarcel Holtmann 		return amp_available;
1046848566b3SMarcel Holtmann 
104793c3e8f5SAndrei Emeltchenko 	return false;
104893c3e8f5SAndrei Emeltchenko }
104993c3e8f5SAndrei Emeltchenko 
10505ce66b59SAndrei Emeltchenko static bool l2cap_check_efs(struct l2cap_chan *chan)
10515ce66b59SAndrei Emeltchenko {
10525ce66b59SAndrei Emeltchenko 	/* Check EFS parameters */
10535ce66b59SAndrei Emeltchenko 	return true;
10545ce66b59SAndrei Emeltchenko }
10555ce66b59SAndrei Emeltchenko 
10562766be48SAndrei Emeltchenko void l2cap_send_conn_req(struct l2cap_chan *chan)
10579b27f350SAndrei Emeltchenko {
10589b27f350SAndrei Emeltchenko 	struct l2cap_conn *conn = chan->conn;
10599b27f350SAndrei Emeltchenko 	struct l2cap_conn_req req;
10609b27f350SAndrei Emeltchenko 
10619b27f350SAndrei Emeltchenko 	req.scid = cpu_to_le16(chan->scid);
10629b27f350SAndrei Emeltchenko 	req.psm  = chan->psm;
10639b27f350SAndrei Emeltchenko 
10649b27f350SAndrei Emeltchenko 	chan->ident = l2cap_get_ident(conn);
10659b27f350SAndrei Emeltchenko 
10669b27f350SAndrei Emeltchenko 	set_bit(CONF_CONNECT_PEND, &chan->conf_state);
10679b27f350SAndrei Emeltchenko 
10689b27f350SAndrei Emeltchenko 	l2cap_send_cmd(conn, chan->ident, L2CAP_CONN_REQ, sizeof(req), &req);
10699b27f350SAndrei Emeltchenko }
10709b27f350SAndrei Emeltchenko 
10718eb200bdSMat Martineau static void l2cap_send_create_chan_req(struct l2cap_chan *chan, u8 amp_id)
10728eb200bdSMat Martineau {
10738eb200bdSMat Martineau 	struct l2cap_create_chan_req req;
10748eb200bdSMat Martineau 	req.scid = cpu_to_le16(chan->scid);
10758eb200bdSMat Martineau 	req.psm  = chan->psm;
10768eb200bdSMat Martineau 	req.amp_id = amp_id;
10778eb200bdSMat Martineau 
10788eb200bdSMat Martineau 	chan->ident = l2cap_get_ident(chan->conn);
10798eb200bdSMat Martineau 
10808eb200bdSMat Martineau 	l2cap_send_cmd(chan->conn, chan->ident, L2CAP_CREATE_CHAN_REQ,
10818eb200bdSMat Martineau 		       sizeof(req), &req);
10828eb200bdSMat Martineau }
10838eb200bdSMat Martineau 
108402b0fbb9SMat Martineau static void l2cap_move_setup(struct l2cap_chan *chan)
108502b0fbb9SMat Martineau {
108602b0fbb9SMat Martineau 	struct sk_buff *skb;
108702b0fbb9SMat Martineau 
108802b0fbb9SMat Martineau 	BT_DBG("chan %p", chan);
108902b0fbb9SMat Martineau 
109002b0fbb9SMat Martineau 	if (chan->mode != L2CAP_MODE_ERTM)
109102b0fbb9SMat Martineau 		return;
109202b0fbb9SMat Martineau 
109302b0fbb9SMat Martineau 	__clear_retrans_timer(chan);
109402b0fbb9SMat Martineau 	__clear_monitor_timer(chan);
109502b0fbb9SMat Martineau 	__clear_ack_timer(chan);
109602b0fbb9SMat Martineau 
109702b0fbb9SMat Martineau 	chan->retry_count = 0;
109802b0fbb9SMat Martineau 	skb_queue_walk(&chan->tx_q, skb) {
109902b0fbb9SMat Martineau 		if (bt_cb(skb)->control.retries)
110002b0fbb9SMat Martineau 			bt_cb(skb)->control.retries = 1;
110102b0fbb9SMat Martineau 		else
110202b0fbb9SMat Martineau 			break;
110302b0fbb9SMat Martineau 	}
110402b0fbb9SMat Martineau 
110502b0fbb9SMat Martineau 	chan->expected_tx_seq = chan->buffer_seq;
110602b0fbb9SMat Martineau 
110702b0fbb9SMat Martineau 	clear_bit(CONN_REJ_ACT, &chan->conn_state);
110802b0fbb9SMat Martineau 	clear_bit(CONN_SREJ_ACT, &chan->conn_state);
110902b0fbb9SMat Martineau 	l2cap_seq_list_clear(&chan->retrans_list);
111002b0fbb9SMat Martineau 	l2cap_seq_list_clear(&chan->srej_list);
111102b0fbb9SMat Martineau 	skb_queue_purge(&chan->srej_q);
111202b0fbb9SMat Martineau 
111302b0fbb9SMat Martineau 	chan->tx_state = L2CAP_TX_STATE_XMIT;
111402b0fbb9SMat Martineau 	chan->rx_state = L2CAP_RX_STATE_MOVE;
111502b0fbb9SMat Martineau 
111602b0fbb9SMat Martineau 	set_bit(CONN_REMOTE_BUSY, &chan->conn_state);
111702b0fbb9SMat Martineau }
111802b0fbb9SMat Martineau 
11195f3847a4SMat Martineau static void l2cap_move_done(struct l2cap_chan *chan)
11205f3847a4SMat Martineau {
11215f3847a4SMat Martineau 	u8 move_role = chan->move_role;
11225f3847a4SMat Martineau 	BT_DBG("chan %p", chan);
11235f3847a4SMat Martineau 
11245f3847a4SMat Martineau 	chan->move_state = L2CAP_MOVE_STABLE;
11255f3847a4SMat Martineau 	chan->move_role = L2CAP_MOVE_ROLE_NONE;
11265f3847a4SMat Martineau 
11275f3847a4SMat Martineau 	if (chan->mode != L2CAP_MODE_ERTM)
11285f3847a4SMat Martineau 		return;
11295f3847a4SMat Martineau 
11305f3847a4SMat Martineau 	switch (move_role) {
11315f3847a4SMat Martineau 	case L2CAP_MOVE_ROLE_INITIATOR:
11325f3847a4SMat Martineau 		l2cap_tx(chan, NULL, NULL, L2CAP_EV_EXPLICIT_POLL);
11335f3847a4SMat Martineau 		chan->rx_state = L2CAP_RX_STATE_WAIT_F;
11345f3847a4SMat Martineau 		break;
11355f3847a4SMat Martineau 	case L2CAP_MOVE_ROLE_RESPONDER:
11365f3847a4SMat Martineau 		chan->rx_state = L2CAP_RX_STATE_WAIT_P;
11375f3847a4SMat Martineau 		break;
11385f3847a4SMat Martineau 	}
11395f3847a4SMat Martineau }
11405f3847a4SMat Martineau 
11419f0caeb1SVinicius Costa Gomes static void l2cap_chan_ready(struct l2cap_chan *chan)
11429f0caeb1SVinicius Costa Gomes {
11432827011fSMat Martineau 	/* This clears all conf flags, including CONF_NOT_COMPLETE */
11449f0caeb1SVinicius Costa Gomes 	chan->conf_state = 0;
11459f0caeb1SVinicius Costa Gomes 	__clear_chan_timer(chan);
11469f0caeb1SVinicius Costa Gomes 
114754a59aa2SAndrei Emeltchenko 	chan->state = BT_CONNECTED;
11489f0caeb1SVinicius Costa Gomes 
114954a59aa2SAndrei Emeltchenko 	chan->ops->ready(chan);
11509f0caeb1SVinicius Costa Gomes }
11519f0caeb1SVinicius Costa Gomes 
115293c3e8f5SAndrei Emeltchenko static void l2cap_start_connection(struct l2cap_chan *chan)
115393c3e8f5SAndrei Emeltchenko {
115493c3e8f5SAndrei Emeltchenko 	if (__amp_capable(chan)) {
115593c3e8f5SAndrei Emeltchenko 		BT_DBG("chan %p AMP capable: discover AMPs", chan);
115693c3e8f5SAndrei Emeltchenko 		a2mp_discover_amp(chan);
115793c3e8f5SAndrei Emeltchenko 	} else {
115893c3e8f5SAndrei Emeltchenko 		l2cap_send_conn_req(chan);
115993c3e8f5SAndrei Emeltchenko 	}
116093c3e8f5SAndrei Emeltchenko }
116193c3e8f5SAndrei Emeltchenko 
1162fc7f8a7eSGustavo F. Padovan static void l2cap_do_start(struct l2cap_chan *chan)
11630a708f8fSGustavo F. Padovan {
11648c1d787bSGustavo F. Padovan 	struct l2cap_conn *conn = chan->conn;
11650a708f8fSGustavo F. Padovan 
11669f0caeb1SVinicius Costa Gomes 	if (conn->hcon->type == LE_LINK) {
11679f0caeb1SVinicius Costa Gomes 		l2cap_chan_ready(chan);
11689f0caeb1SVinicius Costa Gomes 		return;
11699f0caeb1SVinicius Costa Gomes 	}
11709f0caeb1SVinicius Costa Gomes 
11710a708f8fSGustavo F. Padovan 	if (conn->info_state & L2CAP_INFO_FEAT_MASK_REQ_SENT) {
11720a708f8fSGustavo F. Padovan 		if (!(conn->info_state & L2CAP_INFO_FEAT_MASK_REQ_DONE))
11730a708f8fSGustavo F. Padovan 			return;
11740a708f8fSGustavo F. Padovan 
1175d45fc423SGustavo F. Padovan 		if (l2cap_chan_check_security(chan) &&
117693c3e8f5SAndrei Emeltchenko 		    __l2cap_no_conn_pending(chan)) {
117793c3e8f5SAndrei Emeltchenko 			l2cap_start_connection(chan);
117893c3e8f5SAndrei Emeltchenko 		}
11790a708f8fSGustavo F. Padovan 	} else {
11800a708f8fSGustavo F. Padovan 		struct l2cap_info_req req;
1181ac73498cSAndrei Emeltchenko 		req.type = __constant_cpu_to_le16(L2CAP_IT_FEAT_MASK);
11820a708f8fSGustavo F. Padovan 
11830a708f8fSGustavo F. Padovan 		conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_SENT;
11840a708f8fSGustavo F. Padovan 		conn->info_ident = l2cap_get_ident(conn);
11850a708f8fSGustavo F. Padovan 
1186ba13ccd9SMarcel Holtmann 		schedule_delayed_work(&conn->info_timer, L2CAP_INFO_TIMEOUT);
11870a708f8fSGustavo F. Padovan 
11882d792818SGustavo Padovan 		l2cap_send_cmd(conn, conn->info_ident, L2CAP_INFO_REQ,
11892d792818SGustavo Padovan 			       sizeof(req), &req);
11900a708f8fSGustavo F. Padovan 	}
11910a708f8fSGustavo F. Padovan }
11920a708f8fSGustavo F. Padovan 
11930a708f8fSGustavo F. Padovan static inline int l2cap_mode_supported(__u8 mode, __u32 feat_mask)
11940a708f8fSGustavo F. Padovan {
11950a708f8fSGustavo F. Padovan 	u32 local_feat_mask = l2cap_feat_mask;
11960a708f8fSGustavo F. Padovan 	if (!disable_ertm)
11970a708f8fSGustavo F. Padovan 		local_feat_mask |= L2CAP_FEAT_ERTM | L2CAP_FEAT_STREAMING;
11980a708f8fSGustavo F. Padovan 
11990a708f8fSGustavo F. Padovan 	switch (mode) {
12000a708f8fSGustavo F. Padovan 	case L2CAP_MODE_ERTM:
12010a708f8fSGustavo F. Padovan 		return L2CAP_FEAT_ERTM & feat_mask & local_feat_mask;
12020a708f8fSGustavo F. Padovan 	case L2CAP_MODE_STREAMING:
12030a708f8fSGustavo F. Padovan 		return L2CAP_FEAT_STREAMING & feat_mask & local_feat_mask;
12040a708f8fSGustavo F. Padovan 	default:
12050a708f8fSGustavo F. Padovan 		return 0x00;
12060a708f8fSGustavo F. Padovan 	}
12070a708f8fSGustavo F. Padovan }
12080a708f8fSGustavo F. Padovan 
12095e4e3972SAndrei Emeltchenko static void l2cap_send_disconn_req(struct l2cap_chan *chan, int err)
12100a708f8fSGustavo F. Padovan {
12116be36555SAndrei Emeltchenko 	struct sock *sk = chan->sk;
12125e4e3972SAndrei Emeltchenko 	struct l2cap_conn *conn = chan->conn;
12130a708f8fSGustavo F. Padovan 	struct l2cap_disconn_req req;
12140a708f8fSGustavo F. Padovan 
12150a708f8fSGustavo F. Padovan 	if (!conn)
12160a708f8fSGustavo F. Padovan 		return;
12170a708f8fSGustavo F. Padovan 
1218aad3d0e3SAndrei Emeltchenko 	if (chan->mode == L2CAP_MODE_ERTM && chan->state == BT_CONNECTED) {
12191a09bcb9SGustavo F. Padovan 		__clear_retrans_timer(chan);
12201a09bcb9SGustavo F. Padovan 		__clear_monitor_timer(chan);
12211a09bcb9SGustavo F. Padovan 		__clear_ack_timer(chan);
12220a708f8fSGustavo F. Padovan 	}
12230a708f8fSGustavo F. Padovan 
1224416fa752SAndrei Emeltchenko 	if (chan->chan_type == L2CAP_CHAN_CONN_FIX_A2MP) {
1225d117773cSGustavo Padovan 		l2cap_state_change(chan, BT_DISCONN);
1226416fa752SAndrei Emeltchenko 		return;
1227416fa752SAndrei Emeltchenko 	}
1228416fa752SAndrei Emeltchenko 
1229fe4128e0SGustavo F. Padovan 	req.dcid = cpu_to_le16(chan->dcid);
1230fe4128e0SGustavo F. Padovan 	req.scid = cpu_to_le16(chan->scid);
12312d792818SGustavo Padovan 	l2cap_send_cmd(conn, l2cap_get_ident(conn), L2CAP_DISCONN_REQ,
12322d792818SGustavo Padovan 		       sizeof(req), &req);
12330a708f8fSGustavo F. Padovan 
12346be36555SAndrei Emeltchenko 	lock_sock(sk);
12350e587be7SAndrei Emeltchenko 	__l2cap_state_change(chan, BT_DISCONN);
12362e0052e4SAndrei Emeltchenko 	__l2cap_chan_set_err(chan, err);
12376be36555SAndrei Emeltchenko 	release_sock(sk);
12380a708f8fSGustavo F. Padovan }
12390a708f8fSGustavo F. Padovan 
12400a708f8fSGustavo F. Padovan /* ---- L2CAP connections ---- */
12410a708f8fSGustavo F. Padovan static void l2cap_conn_start(struct l2cap_conn *conn)
12420a708f8fSGustavo F. Padovan {
12433df91ea2SAndrei Emeltchenko 	struct l2cap_chan *chan, *tmp;
12440a708f8fSGustavo F. Padovan 
12450a708f8fSGustavo F. Padovan 	BT_DBG("conn %p", conn);
12460a708f8fSGustavo F. Padovan 
12473df91ea2SAndrei Emeltchenko 	mutex_lock(&conn->chan_lock);
12480a708f8fSGustavo F. Padovan 
12493df91ea2SAndrei Emeltchenko 	list_for_each_entry_safe(chan, tmp, &conn->chan_l, list) {
125048454079SGustavo F. Padovan 		struct sock *sk = chan->sk;
1251baa7e1faSGustavo F. Padovan 
12526be36555SAndrei Emeltchenko 		l2cap_chan_lock(chan);
12530a708f8fSGustavo F. Padovan 
1254715ec005SGustavo F. Padovan 		if (chan->chan_type != L2CAP_CHAN_CONN_ORIENTED) {
12556be36555SAndrei Emeltchenko 			l2cap_chan_unlock(chan);
12560a708f8fSGustavo F. Padovan 			continue;
12570a708f8fSGustavo F. Padovan 		}
12580a708f8fSGustavo F. Padovan 
125989bc500eSGustavo F. Padovan 		if (chan->state == BT_CONNECT) {
1260d45fc423SGustavo F. Padovan 			if (!l2cap_chan_check_security(chan) ||
1261b4450035SGustavo F. Padovan 			    !__l2cap_no_conn_pending(chan)) {
12626be36555SAndrei Emeltchenko 				l2cap_chan_unlock(chan);
12630a708f8fSGustavo F. Padovan 				continue;
12640a708f8fSGustavo F. Padovan 			}
12650a708f8fSGustavo F. Padovan 
1266c1360a1cSGustavo F. Padovan 			if (!l2cap_mode_supported(chan->mode, conn->feat_mask)
1267c1360a1cSGustavo F. Padovan 			    && test_bit(CONF_STATE2_DEVICE,
1268c1360a1cSGustavo F. Padovan 					&chan->conf_state)) {
12690f852724SGustavo F. Padovan 				l2cap_chan_close(chan, ECONNRESET);
12706be36555SAndrei Emeltchenko 				l2cap_chan_unlock(chan);
12710a708f8fSGustavo F. Padovan 				continue;
12720a708f8fSGustavo F. Padovan 			}
12730a708f8fSGustavo F. Padovan 
127493c3e8f5SAndrei Emeltchenko 			l2cap_start_connection(chan);
12750a708f8fSGustavo F. Padovan 
127689bc500eSGustavo F. Padovan 		} else if (chan->state == BT_CONNECT2) {
12770a708f8fSGustavo F. Padovan 			struct l2cap_conn_rsp rsp;
12780a708f8fSGustavo F. Padovan 			char buf[128];
1279fe4128e0SGustavo F. Padovan 			rsp.scid = cpu_to_le16(chan->dcid);
1280fe4128e0SGustavo F. Padovan 			rsp.dcid = cpu_to_le16(chan->scid);
12810a708f8fSGustavo F. Padovan 
1282d45fc423SGustavo F. Padovan 			if (l2cap_chan_check_security(chan)) {
12836be36555SAndrei Emeltchenko 				lock_sock(sk);
1284c5daa683SGustavo Padovan 				if (test_bit(BT_SK_DEFER_SETUP,
1285c5daa683SGustavo Padovan 					     &bt_sk(sk)->flags)) {
1286ac73498cSAndrei Emeltchenko 					rsp.result = __constant_cpu_to_le16(L2CAP_CR_PEND);
1287ac73498cSAndrei Emeltchenko 					rsp.status = __constant_cpu_to_le16(L2CAP_CS_AUTHOR_PEND);
12882dc4e510SGustavo Padovan 					chan->ops->defer(chan);
12890a708f8fSGustavo F. Padovan 
12900a708f8fSGustavo F. Padovan 				} else {
12910e587be7SAndrei Emeltchenko 					__l2cap_state_change(chan, BT_CONFIG);
1292ac73498cSAndrei Emeltchenko 					rsp.result = __constant_cpu_to_le16(L2CAP_CR_SUCCESS);
1293ac73498cSAndrei Emeltchenko 					rsp.status = __constant_cpu_to_le16(L2CAP_CS_NO_INFO);
12940a708f8fSGustavo F. Padovan 				}
12956be36555SAndrei Emeltchenko 				release_sock(sk);
12960a708f8fSGustavo F. Padovan 			} else {
1297ac73498cSAndrei Emeltchenko 				rsp.result = __constant_cpu_to_le16(L2CAP_CR_PEND);
1298ac73498cSAndrei Emeltchenko 				rsp.status = __constant_cpu_to_le16(L2CAP_CS_AUTHEN_PEND);
12990a708f8fSGustavo F. Padovan 			}
13000a708f8fSGustavo F. Padovan 
1301fc7f8a7eSGustavo F. Padovan 			l2cap_send_cmd(conn, chan->ident, L2CAP_CONN_RSP,
1302fc7f8a7eSGustavo F. Padovan 				       sizeof(rsp), &rsp);
13030a708f8fSGustavo F. Padovan 
1304c1360a1cSGustavo F. Padovan 			if (test_bit(CONF_REQ_SENT, &chan->conf_state) ||
13050a708f8fSGustavo F. Padovan 			    rsp.result != L2CAP_CR_SUCCESS) {
13066be36555SAndrei Emeltchenko 				l2cap_chan_unlock(chan);
13070a708f8fSGustavo F. Padovan 				continue;
13080a708f8fSGustavo F. Padovan 			}
13090a708f8fSGustavo F. Padovan 
1310c1360a1cSGustavo F. Padovan 			set_bit(CONF_REQ_SENT, &chan->conf_state);
13110a708f8fSGustavo F. Padovan 			l2cap_send_cmd(conn, l2cap_get_ident(conn), L2CAP_CONF_REQ,
131273ffa904SGustavo F. Padovan 				       l2cap_build_conf_req(chan, buf), buf);
131373ffa904SGustavo F. Padovan 			chan->num_conf_req++;
13140a708f8fSGustavo F. Padovan 		}
13150a708f8fSGustavo F. Padovan 
13166be36555SAndrei Emeltchenko 		l2cap_chan_unlock(chan);
13170a708f8fSGustavo F. Padovan 	}
13180a708f8fSGustavo F. Padovan 
13193df91ea2SAndrei Emeltchenko 	mutex_unlock(&conn->chan_lock);
13200a708f8fSGustavo F. Padovan }
13210a708f8fSGustavo F. Padovan 
1322c2287681SIdo Yariv /* Find socket with cid and source/destination bdaddr.
1323b62f328bSVille Tervo  * Returns closest match, locked.
1324b62f328bSVille Tervo  */
1325d9b88702SAndrei Emeltchenko static struct l2cap_chan *l2cap_global_chan_by_scid(int state, u16 cid,
1326c2287681SIdo Yariv 						    bdaddr_t *src,
1327c2287681SIdo Yariv 						    bdaddr_t *dst)
1328b62f328bSVille Tervo {
132923691d75SGustavo F. Padovan 	struct l2cap_chan *c, *c1 = NULL;
1330b62f328bSVille Tervo 
133123691d75SGustavo F. Padovan 	read_lock(&chan_list_lock);
1332b62f328bSVille Tervo 
133323691d75SGustavo F. Padovan 	list_for_each_entry(c, &chan_list, global_l) {
133423691d75SGustavo F. Padovan 		struct sock *sk = c->sk;
1335fe4128e0SGustavo F. Padovan 
133689bc500eSGustavo F. Padovan 		if (state && c->state != state)
1337b62f328bSVille Tervo 			continue;
1338b62f328bSVille Tervo 
133923691d75SGustavo F. Padovan 		if (c->scid == cid) {
1340c2287681SIdo Yariv 			int src_match, dst_match;
1341c2287681SIdo Yariv 			int src_any, dst_any;
1342c2287681SIdo Yariv 
1343b62f328bSVille Tervo 			/* Exact match. */
1344c2287681SIdo Yariv 			src_match = !bacmp(&bt_sk(sk)->src, src);
1345c2287681SIdo Yariv 			dst_match = !bacmp(&bt_sk(sk)->dst, dst);
1346c2287681SIdo Yariv 			if (src_match && dst_match) {
134723691d75SGustavo F. Padovan 				read_unlock(&chan_list_lock);
134823691d75SGustavo F. Padovan 				return c;
134923691d75SGustavo F. Padovan 			}
1350b62f328bSVille Tervo 
1351b62f328bSVille Tervo 			/* Closest match */
1352c2287681SIdo Yariv 			src_any = !bacmp(&bt_sk(sk)->src, BDADDR_ANY);
1353c2287681SIdo Yariv 			dst_any = !bacmp(&bt_sk(sk)->dst, BDADDR_ANY);
1354c2287681SIdo Yariv 			if ((src_match && dst_any) || (src_any && dst_match) ||
1355c2287681SIdo Yariv 			    (src_any && dst_any))
135623691d75SGustavo F. Padovan 				c1 = c;
1357b62f328bSVille Tervo 		}
1358b62f328bSVille Tervo 	}
1359280f294fSGustavo F. Padovan 
136023691d75SGustavo F. Padovan 	read_unlock(&chan_list_lock);
1361b62f328bSVille Tervo 
136223691d75SGustavo F. Padovan 	return c1;
1363b62f328bSVille Tervo }
1364b62f328bSVille Tervo 
1365b62f328bSVille Tervo static void l2cap_le_conn_ready(struct l2cap_conn *conn)
1366b62f328bSVille Tervo {
136760bac184SJohan Hedberg 	struct sock *parent;
136823691d75SGustavo F. Padovan 	struct l2cap_chan *chan, *pchan;
1369b62f328bSVille Tervo 
1370b62f328bSVille Tervo 	BT_DBG("");
1371b62f328bSVille Tervo 
1372b62f328bSVille Tervo 	/* Check if we have socket listening on cid */
1373073d1cf3SJohan Hedberg 	pchan = l2cap_global_chan_by_scid(BT_LISTEN, L2CAP_CID_ATT,
1374c2287681SIdo Yariv 					  conn->src, conn->dst);
137523691d75SGustavo F. Padovan 	if (!pchan)
1376b62f328bSVille Tervo 		return;
1377b62f328bSVille Tervo 
137844f3b0fbSJohan Hedberg 	/* Client ATT sockets should override the server one */
137944f3b0fbSJohan Hedberg 	if (__l2cap_get_chan_by_dcid(conn, L2CAP_CID_ATT))
138044f3b0fbSJohan Hedberg 		return;
138144f3b0fbSJohan Hedberg 
138223691d75SGustavo F. Padovan 	parent = pchan->sk;
138323691d75SGustavo F. Padovan 
1384aa2ac881SGustavo F. Padovan 	lock_sock(parent);
138562f3a2cfSGustavo F. Padovan 
138680b98027SGustavo Padovan 	chan = pchan->ops->new_connection(pchan);
138780808e43SGustavo F. Padovan 	if (!chan)
1388b62f328bSVille Tervo 		goto clean;
1389b62f328bSVille Tervo 
13909f22398cSJohan Hedberg 	chan->dcid = L2CAP_CID_ATT;
13919f22398cSJohan Hedberg 
139260bac184SJohan Hedberg 	bacpy(&bt_sk(chan->sk)->src, conn->src);
139360bac184SJohan Hedberg 	bacpy(&bt_sk(chan->sk)->dst, conn->dst);
1394b62f328bSVille Tervo 
139544f3b0fbSJohan Hedberg 	__l2cap_chan_add(conn, chan);
139648454079SGustavo F. Padovan 
1397b62f328bSVille Tervo clean:
1398aa2ac881SGustavo F. Padovan 	release_sock(parent);
1399b62f328bSVille Tervo }
1400b62f328bSVille Tervo 
14010a708f8fSGustavo F. Padovan static void l2cap_conn_ready(struct l2cap_conn *conn)
14020a708f8fSGustavo F. Padovan {
140348454079SGustavo F. Padovan 	struct l2cap_chan *chan;
1404cc110922SVinicius Costa Gomes 	struct hci_conn *hcon = conn->hcon;
14050a708f8fSGustavo F. Padovan 
14060a708f8fSGustavo F. Padovan 	BT_DBG("conn %p", conn);
14070a708f8fSGustavo F. Padovan 
1408d8729922SJohan Hedberg 	/* For outgoing pairing which doesn't necessarily have an
1409d8729922SJohan Hedberg 	 * associated socket (e.g. mgmt_pair_device).
1410d8729922SJohan Hedberg 	 */
1411cc110922SVinicius Costa Gomes 	if (hcon->out && hcon->type == LE_LINK)
1412cc110922SVinicius Costa Gomes 		smp_conn_security(hcon, hcon->pending_sec_level);
1413160dc6acSVinicius Costa Gomes 
14143df91ea2SAndrei Emeltchenko 	mutex_lock(&conn->chan_lock);
14150a708f8fSGustavo F. Padovan 
141644f3b0fbSJohan Hedberg 	if (hcon->type == LE_LINK)
141744f3b0fbSJohan Hedberg 		l2cap_le_conn_ready(conn);
141844f3b0fbSJohan Hedberg 
14193df91ea2SAndrei Emeltchenko 	list_for_each_entry(chan, &conn->chan_l, list) {
1420baa7e1faSGustavo F. Padovan 
14216be36555SAndrei Emeltchenko 		l2cap_chan_lock(chan);
14220a708f8fSGustavo F. Padovan 
1423416fa752SAndrei Emeltchenko 		if (chan->chan_type == L2CAP_CHAN_CONN_FIX_A2MP) {
1424416fa752SAndrei Emeltchenko 			l2cap_chan_unlock(chan);
1425416fa752SAndrei Emeltchenko 			continue;
1426416fa752SAndrei Emeltchenko 		}
1427416fa752SAndrei Emeltchenko 
1428cc110922SVinicius Costa Gomes 		if (hcon->type == LE_LINK) {
1429cc110922SVinicius Costa Gomes 			if (smp_conn_security(hcon, chan->sec_level))
1430cf4cd009SAndrei Emeltchenko 				l2cap_chan_ready(chan);
1431acd7d370SVille Tervo 
143263128451SVinicius Costa Gomes 		} else if (chan->chan_type != L2CAP_CHAN_CONN_ORIENTED) {
14336be36555SAndrei Emeltchenko 			struct sock *sk = chan->sk;
1434c9b66675SGustavo F. Padovan 			__clear_chan_timer(chan);
14356be36555SAndrei Emeltchenko 			lock_sock(sk);
14360e587be7SAndrei Emeltchenko 			__l2cap_state_change(chan, BT_CONNECTED);
14370a708f8fSGustavo F. Padovan 			sk->sk_state_change(sk);
14386be36555SAndrei Emeltchenko 			release_sock(sk);
1439b501d6a1SAnderson Briglia 
14401c244f79SGustavo Padovan 		} else if (chan->state == BT_CONNECT) {
1441fc7f8a7eSGustavo F. Padovan 			l2cap_do_start(chan);
14421c244f79SGustavo Padovan 		}
14430a708f8fSGustavo F. Padovan 
14446be36555SAndrei Emeltchenko 		l2cap_chan_unlock(chan);
14450a708f8fSGustavo F. Padovan 	}
14460a708f8fSGustavo F. Padovan 
14473df91ea2SAndrei Emeltchenko 	mutex_unlock(&conn->chan_lock);
14480a708f8fSGustavo F. Padovan }
14490a708f8fSGustavo F. Padovan 
14500a708f8fSGustavo F. Padovan /* Notify sockets that we cannot guaranty reliability anymore */
14510a708f8fSGustavo F. Padovan static void l2cap_conn_unreliable(struct l2cap_conn *conn, int err)
14520a708f8fSGustavo F. Padovan {
145348454079SGustavo F. Padovan 	struct l2cap_chan *chan;
14540a708f8fSGustavo F. Padovan 
14550a708f8fSGustavo F. Padovan 	BT_DBG("conn %p", conn);
14560a708f8fSGustavo F. Padovan 
14573df91ea2SAndrei Emeltchenko 	mutex_lock(&conn->chan_lock);
14580a708f8fSGustavo F. Padovan 
14593df91ea2SAndrei Emeltchenko 	list_for_each_entry(chan, &conn->chan_l, list) {
1460ecf61bdbSAndrei Emeltchenko 		if (test_bit(FLAG_FORCE_RELIABLE, &chan->flags))
14611d8b1fd5SGustavo Padovan 			l2cap_chan_set_err(chan, err);
14620a708f8fSGustavo F. Padovan 	}
14630a708f8fSGustavo F. Padovan 
14643df91ea2SAndrei Emeltchenko 	mutex_unlock(&conn->chan_lock);
14650a708f8fSGustavo F. Padovan }
14660a708f8fSGustavo F. Padovan 
1467f878fcadSGustavo F. Padovan static void l2cap_info_timeout(struct work_struct *work)
14680a708f8fSGustavo F. Padovan {
1469f878fcadSGustavo F. Padovan 	struct l2cap_conn *conn = container_of(work, struct l2cap_conn,
1470030013d8SGustavo F. Padovan 					       info_timer.work);
14710a708f8fSGustavo F. Padovan 
14720a708f8fSGustavo F. Padovan 	conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_DONE;
14730a708f8fSGustavo F. Padovan 	conn->info_ident = 0;
14740a708f8fSGustavo F. Padovan 
14750a708f8fSGustavo F. Padovan 	l2cap_conn_start(conn);
14760a708f8fSGustavo F. Padovan }
14770a708f8fSGustavo F. Padovan 
14782c8e1411SDavid Herrmann /*
14792c8e1411SDavid Herrmann  * l2cap_user
14802c8e1411SDavid Herrmann  * External modules can register l2cap_user objects on l2cap_conn. The ->probe
14812c8e1411SDavid Herrmann  * callback is called during registration. The ->remove callback is called
14822c8e1411SDavid Herrmann  * during unregistration.
14832c8e1411SDavid Herrmann  * An l2cap_user object can either be explicitly unregistered or when the
14842c8e1411SDavid Herrmann  * underlying l2cap_conn object is deleted. This guarantees that l2cap->hcon,
14852c8e1411SDavid Herrmann  * l2cap->hchan, .. are valid as long as the remove callback hasn't been called.
14862c8e1411SDavid Herrmann  * External modules must own a reference to the l2cap_conn object if they intend
14872c8e1411SDavid Herrmann  * to call l2cap_unregister_user(). The l2cap_conn object might get destroyed at
14882c8e1411SDavid Herrmann  * any time if they don't.
14892c8e1411SDavid Herrmann  */
14902c8e1411SDavid Herrmann 
14912c8e1411SDavid Herrmann int l2cap_register_user(struct l2cap_conn *conn, struct l2cap_user *user)
14922c8e1411SDavid Herrmann {
14932c8e1411SDavid Herrmann 	struct hci_dev *hdev = conn->hcon->hdev;
14942c8e1411SDavid Herrmann 	int ret;
14952c8e1411SDavid Herrmann 
14962c8e1411SDavid Herrmann 	/* We need to check whether l2cap_conn is registered. If it is not, we
14972c8e1411SDavid Herrmann 	 * must not register the l2cap_user. l2cap_conn_del() is unregisters
14982c8e1411SDavid Herrmann 	 * l2cap_conn objects, but doesn't provide its own locking. Instead, it
14992c8e1411SDavid Herrmann 	 * relies on the parent hci_conn object to be locked. This itself relies
15002c8e1411SDavid Herrmann 	 * on the hci_dev object to be locked. So we must lock the hci device
15012c8e1411SDavid Herrmann 	 * here, too. */
15022c8e1411SDavid Herrmann 
15032c8e1411SDavid Herrmann 	hci_dev_lock(hdev);
15042c8e1411SDavid Herrmann 
15052c8e1411SDavid Herrmann 	if (user->list.next || user->list.prev) {
15062c8e1411SDavid Herrmann 		ret = -EINVAL;
15072c8e1411SDavid Herrmann 		goto out_unlock;
15082c8e1411SDavid Herrmann 	}
15092c8e1411SDavid Herrmann 
15102c8e1411SDavid Herrmann 	/* conn->hchan is NULL after l2cap_conn_del() was called */
15112c8e1411SDavid Herrmann 	if (!conn->hchan) {
15122c8e1411SDavid Herrmann 		ret = -ENODEV;
15132c8e1411SDavid Herrmann 		goto out_unlock;
15142c8e1411SDavid Herrmann 	}
15152c8e1411SDavid Herrmann 
15162c8e1411SDavid Herrmann 	ret = user->probe(conn, user);
15172c8e1411SDavid Herrmann 	if (ret)
15182c8e1411SDavid Herrmann 		goto out_unlock;
15192c8e1411SDavid Herrmann 
15202c8e1411SDavid Herrmann 	list_add(&user->list, &conn->users);
15212c8e1411SDavid Herrmann 	ret = 0;
15222c8e1411SDavid Herrmann 
15232c8e1411SDavid Herrmann out_unlock:
15242c8e1411SDavid Herrmann 	hci_dev_unlock(hdev);
15252c8e1411SDavid Herrmann 	return ret;
15262c8e1411SDavid Herrmann }
15272c8e1411SDavid Herrmann EXPORT_SYMBOL(l2cap_register_user);
15282c8e1411SDavid Herrmann 
15292c8e1411SDavid Herrmann void l2cap_unregister_user(struct l2cap_conn *conn, struct l2cap_user *user)
15302c8e1411SDavid Herrmann {
15312c8e1411SDavid Herrmann 	struct hci_dev *hdev = conn->hcon->hdev;
15322c8e1411SDavid Herrmann 
15332c8e1411SDavid Herrmann 	hci_dev_lock(hdev);
15342c8e1411SDavid Herrmann 
15352c8e1411SDavid Herrmann 	if (!user->list.next || !user->list.prev)
15362c8e1411SDavid Herrmann 		goto out_unlock;
15372c8e1411SDavid Herrmann 
15382c8e1411SDavid Herrmann 	list_del(&user->list);
15392c8e1411SDavid Herrmann 	user->list.next = NULL;
15402c8e1411SDavid Herrmann 	user->list.prev = NULL;
15412c8e1411SDavid Herrmann 	user->remove(conn, user);
15422c8e1411SDavid Herrmann 
15432c8e1411SDavid Herrmann out_unlock:
15442c8e1411SDavid Herrmann 	hci_dev_unlock(hdev);
15452c8e1411SDavid Herrmann }
15462c8e1411SDavid Herrmann EXPORT_SYMBOL(l2cap_unregister_user);
15472c8e1411SDavid Herrmann 
15482c8e1411SDavid Herrmann static void l2cap_unregister_all_users(struct l2cap_conn *conn)
15492c8e1411SDavid Herrmann {
15502c8e1411SDavid Herrmann 	struct l2cap_user *user;
15512c8e1411SDavid Herrmann 
15522c8e1411SDavid Herrmann 	while (!list_empty(&conn->users)) {
15532c8e1411SDavid Herrmann 		user = list_first_entry(&conn->users, struct l2cap_user, list);
15542c8e1411SDavid Herrmann 		list_del(&user->list);
15552c8e1411SDavid Herrmann 		user->list.next = NULL;
15562c8e1411SDavid Herrmann 		user->list.prev = NULL;
15572c8e1411SDavid Herrmann 		user->remove(conn, user);
15582c8e1411SDavid Herrmann 	}
15592c8e1411SDavid Herrmann }
15602c8e1411SDavid Herrmann 
15615d3de7dfSVinicius Costa Gomes static void l2cap_conn_del(struct hci_conn *hcon, int err)
15625d3de7dfSVinicius Costa Gomes {
15635d3de7dfSVinicius Costa Gomes 	struct l2cap_conn *conn = hcon->l2cap_data;
15645d3de7dfSVinicius Costa Gomes 	struct l2cap_chan *chan, *l;
15655d3de7dfSVinicius Costa Gomes 
15665d3de7dfSVinicius Costa Gomes 	if (!conn)
15675d3de7dfSVinicius Costa Gomes 		return;
15685d3de7dfSVinicius Costa Gomes 
15695d3de7dfSVinicius Costa Gomes 	BT_DBG("hcon %p conn %p, err %d", hcon, conn, err);
15705d3de7dfSVinicius Costa Gomes 
15715d3de7dfSVinicius Costa Gomes 	kfree_skb(conn->rx_skb);
15725d3de7dfSVinicius Costa Gomes 
15732c8e1411SDavid Herrmann 	l2cap_unregister_all_users(conn);
15742c8e1411SDavid Herrmann 
15753df91ea2SAndrei Emeltchenko 	mutex_lock(&conn->chan_lock);
15763df91ea2SAndrei Emeltchenko 
15775d3de7dfSVinicius Costa Gomes 	/* Kill channels */
15785d3de7dfSVinicius Costa Gomes 	list_for_each_entry_safe(chan, l, &conn->chan_l, list) {
157961d6ef3eSMat Martineau 		l2cap_chan_hold(chan);
15806be36555SAndrei Emeltchenko 		l2cap_chan_lock(chan);
15816be36555SAndrei Emeltchenko 
15825d3de7dfSVinicius Costa Gomes 		l2cap_chan_del(chan, err);
15836be36555SAndrei Emeltchenko 
15846be36555SAndrei Emeltchenko 		l2cap_chan_unlock(chan);
15856be36555SAndrei Emeltchenko 
158680b98027SGustavo Padovan 		chan->ops->close(chan);
158761d6ef3eSMat Martineau 		l2cap_chan_put(chan);
15885d3de7dfSVinicius Costa Gomes 	}
15895d3de7dfSVinicius Costa Gomes 
15903df91ea2SAndrei Emeltchenko 	mutex_unlock(&conn->chan_lock);
15913df91ea2SAndrei Emeltchenko 
159273d80debSLuiz Augusto von Dentz 	hci_chan_del(conn->hchan);
159373d80debSLuiz Augusto von Dentz 
15945d3de7dfSVinicius Costa Gomes 	if (conn->info_state & L2CAP_INFO_FEAT_MASK_REQ_SENT)
1595127074bfSUlisses Furquim 		cancel_delayed_work_sync(&conn->info_timer);
15965d3de7dfSVinicius Costa Gomes 
159751a8efd7SJohan Hedberg 	if (test_and_clear_bit(HCI_CONN_LE_SMP_PEND, &hcon->flags)) {
1598127074bfSUlisses Furquim 		cancel_delayed_work_sync(&conn->security_timer);
15998aab4757SVinicius Costa Gomes 		smp_chan_destroy(conn);
1600d26a2345SVinicius Costa Gomes 	}
16015d3de7dfSVinicius Costa Gomes 
16025d3de7dfSVinicius Costa Gomes 	hcon->l2cap_data = NULL;
16039c903e37SDavid Herrmann 	conn->hchan = NULL;
16049c903e37SDavid Herrmann 	l2cap_conn_put(conn);
16055d3de7dfSVinicius Costa Gomes }
16065d3de7dfSVinicius Costa Gomes 
16076c9d42a1SGustavo F. Padovan static void security_timeout(struct work_struct *work)
16085d3de7dfSVinicius Costa Gomes {
16096c9d42a1SGustavo F. Padovan 	struct l2cap_conn *conn = container_of(work, struct l2cap_conn,
16106c9d42a1SGustavo F. Padovan 					       security_timer.work);
16115d3de7dfSVinicius Costa Gomes 
1612d06cc416SJohan Hedberg 	BT_DBG("conn %p", conn);
1613d06cc416SJohan Hedberg 
1614d06cc416SJohan Hedberg 	if (test_and_clear_bit(HCI_CONN_LE_SMP_PEND, &conn->hcon->flags)) {
1615d06cc416SJohan Hedberg 		smp_chan_destroy(conn);
16165d3de7dfSVinicius Costa Gomes 		l2cap_conn_del(conn->hcon, ETIMEDOUT);
16175d3de7dfSVinicius Costa Gomes 	}
1618d06cc416SJohan Hedberg }
16195d3de7dfSVinicius Costa Gomes 
1620baf43251SClaudio Takahasi static struct l2cap_conn *l2cap_conn_add(struct hci_conn *hcon)
16210a708f8fSGustavo F. Padovan {
16220a708f8fSGustavo F. Padovan 	struct l2cap_conn *conn = hcon->l2cap_data;
162373d80debSLuiz Augusto von Dentz 	struct hci_chan *hchan;
16240a708f8fSGustavo F. Padovan 
1625baf43251SClaudio Takahasi 	if (conn)
16260a708f8fSGustavo F. Padovan 		return conn;
16270a708f8fSGustavo F. Padovan 
162873d80debSLuiz Augusto von Dentz 	hchan = hci_chan_create(hcon);
162973d80debSLuiz Augusto von Dentz 	if (!hchan)
16300a708f8fSGustavo F. Padovan 		return NULL;
16310a708f8fSGustavo F. Padovan 
16328bcde1f2SGustavo Padovan 	conn = kzalloc(sizeof(struct l2cap_conn), GFP_KERNEL);
163373d80debSLuiz Augusto von Dentz 	if (!conn) {
163473d80debSLuiz Augusto von Dentz 		hci_chan_del(hchan);
163573d80debSLuiz Augusto von Dentz 		return NULL;
163673d80debSLuiz Augusto von Dentz 	}
163773d80debSLuiz Augusto von Dentz 
16389c903e37SDavid Herrmann 	kref_init(&conn->ref);
16390a708f8fSGustavo F. Padovan 	hcon->l2cap_data = conn;
16400a708f8fSGustavo F. Padovan 	conn->hcon = hcon;
16419c903e37SDavid Herrmann 	hci_conn_get(conn->hcon);
164273d80debSLuiz Augusto von Dentz 	conn->hchan = hchan;
16430a708f8fSGustavo F. Padovan 
164473d80debSLuiz Augusto von Dentz 	BT_DBG("hcon %p conn %p hchan %p", hcon, conn, hchan);
16450a708f8fSGustavo F. Padovan 
1646dcc042d5SAndrei Emeltchenko 	switch (hcon->type) {
1647dcc042d5SAndrei Emeltchenko 	case LE_LINK:
1648dcc042d5SAndrei Emeltchenko 		if (hcon->hdev->le_mtu) {
1649acd7d370SVille Tervo 			conn->mtu = hcon->hdev->le_mtu;
1650dcc042d5SAndrei Emeltchenko 			break;
1651dcc042d5SAndrei Emeltchenko 		}
1652dcc042d5SAndrei Emeltchenko 		/* fall through */
1653dcc042d5SAndrei Emeltchenko 	default:
16540a708f8fSGustavo F. Padovan 		conn->mtu = hcon->hdev->acl_mtu;
1655dcc042d5SAndrei Emeltchenko 		break;
1656dcc042d5SAndrei Emeltchenko 	}
1657acd7d370SVille Tervo 
16580a708f8fSGustavo F. Padovan 	conn->src = &hcon->hdev->bdaddr;
16590a708f8fSGustavo F. Padovan 	conn->dst = &hcon->dst;
16600a708f8fSGustavo F. Padovan 
16610a708f8fSGustavo F. Padovan 	conn->feat_mask = 0;
16620a708f8fSGustavo F. Padovan 
1663848566b3SMarcel Holtmann 	if (hcon->type == ACL_LINK)
1664848566b3SMarcel Holtmann 		conn->hs_enabled = test_bit(HCI_HS_ENABLED,
1665848566b3SMarcel Holtmann 					    &hcon->hdev->dev_flags);
1666848566b3SMarcel Holtmann 
16670a708f8fSGustavo F. Padovan 	spin_lock_init(&conn->lock);
16683df91ea2SAndrei Emeltchenko 	mutex_init(&conn->chan_lock);
1669baa7e1faSGustavo F. Padovan 
1670baa7e1faSGustavo F. Padovan 	INIT_LIST_HEAD(&conn->chan_l);
16712c8e1411SDavid Herrmann 	INIT_LIST_HEAD(&conn->users);
16720a708f8fSGustavo F. Padovan 
16735d3de7dfSVinicius Costa Gomes 	if (hcon->type == LE_LINK)
16746c9d42a1SGustavo F. Padovan 		INIT_DELAYED_WORK(&conn->security_timer, security_timeout);
16755d3de7dfSVinicius Costa Gomes 	else
1676030013d8SGustavo F. Padovan 		INIT_DELAYED_WORK(&conn->info_timer, l2cap_info_timeout);
16770a708f8fSGustavo F. Padovan 
16789f5a0d7bSAndrei Emeltchenko 	conn->disc_reason = HCI_ERROR_REMOTE_USER_TERM;
16790a708f8fSGustavo F. Padovan 
16800a708f8fSGustavo F. Padovan 	return conn;
16810a708f8fSGustavo F. Padovan }
16820a708f8fSGustavo F. Padovan 
16839c903e37SDavid Herrmann static void l2cap_conn_free(struct kref *ref)
16849c903e37SDavid Herrmann {
16859c903e37SDavid Herrmann 	struct l2cap_conn *conn = container_of(ref, struct l2cap_conn, ref);
16869c903e37SDavid Herrmann 
16879c903e37SDavid Herrmann 	hci_conn_put(conn->hcon);
16889c903e37SDavid Herrmann 	kfree(conn);
16899c903e37SDavid Herrmann }
16909c903e37SDavid Herrmann 
16919c903e37SDavid Herrmann void l2cap_conn_get(struct l2cap_conn *conn)
16929c903e37SDavid Herrmann {
16939c903e37SDavid Herrmann 	kref_get(&conn->ref);
16949c903e37SDavid Herrmann }
16959c903e37SDavid Herrmann EXPORT_SYMBOL(l2cap_conn_get);
16969c903e37SDavid Herrmann 
16979c903e37SDavid Herrmann void l2cap_conn_put(struct l2cap_conn *conn)
16989c903e37SDavid Herrmann {
16999c903e37SDavid Herrmann 	kref_put(&conn->ref, l2cap_conn_free);
17009c903e37SDavid Herrmann }
17019c903e37SDavid Herrmann EXPORT_SYMBOL(l2cap_conn_put);
17029c903e37SDavid Herrmann 
17030a708f8fSGustavo F. Padovan /* ---- Socket interface ---- */
17040a708f8fSGustavo F. Padovan 
1705c2287681SIdo Yariv /* Find socket with psm and source / destination bdaddr.
17060a708f8fSGustavo F. Padovan  * Returns closest match.
17070a708f8fSGustavo F. Padovan  */
1708c2287681SIdo Yariv static struct l2cap_chan *l2cap_global_chan_by_psm(int state, __le16 psm,
1709c2287681SIdo Yariv 						   bdaddr_t *src,
1710c2287681SIdo Yariv 						   bdaddr_t *dst)
17110a708f8fSGustavo F. Padovan {
171223691d75SGustavo F. Padovan 	struct l2cap_chan *c, *c1 = NULL;
17130a708f8fSGustavo F. Padovan 
171423691d75SGustavo F. Padovan 	read_lock(&chan_list_lock);
17150a708f8fSGustavo F. Padovan 
171623691d75SGustavo F. Padovan 	list_for_each_entry(c, &chan_list, global_l) {
171723691d75SGustavo F. Padovan 		struct sock *sk = c->sk;
1718fe4128e0SGustavo F. Padovan 
171989bc500eSGustavo F. Padovan 		if (state && c->state != state)
17200a708f8fSGustavo F. Padovan 			continue;
17210a708f8fSGustavo F. Padovan 
172223691d75SGustavo F. Padovan 		if (c->psm == psm) {
1723c2287681SIdo Yariv 			int src_match, dst_match;
1724c2287681SIdo Yariv 			int src_any, dst_any;
1725c2287681SIdo Yariv 
17260a708f8fSGustavo F. Padovan 			/* Exact match. */
1727c2287681SIdo Yariv 			src_match = !bacmp(&bt_sk(sk)->src, src);
1728c2287681SIdo Yariv 			dst_match = !bacmp(&bt_sk(sk)->dst, dst);
1729c2287681SIdo Yariv 			if (src_match && dst_match) {
1730a7567b20SJohannes Berg 				read_unlock(&chan_list_lock);
173123691d75SGustavo F. Padovan 				return c;
173223691d75SGustavo F. Padovan 			}
17330a708f8fSGustavo F. Padovan 
17340a708f8fSGustavo F. Padovan 			/* Closest match */
1735c2287681SIdo Yariv 			src_any = !bacmp(&bt_sk(sk)->src, BDADDR_ANY);
1736c2287681SIdo Yariv 			dst_any = !bacmp(&bt_sk(sk)->dst, BDADDR_ANY);
1737c2287681SIdo Yariv 			if ((src_match && dst_any) || (src_any && dst_match) ||
1738c2287681SIdo Yariv 			    (src_any && dst_any))
173923691d75SGustavo F. Padovan 				c1 = c;
17400a708f8fSGustavo F. Padovan 		}
17410a708f8fSGustavo F. Padovan 	}
17420a708f8fSGustavo F. Padovan 
174323691d75SGustavo F. Padovan 	read_unlock(&chan_list_lock);
17440a708f8fSGustavo F. Padovan 
174523691d75SGustavo F. Padovan 	return c1;
17460a708f8fSGustavo F. Padovan }
17470a708f8fSGustavo F. Padovan 
17488e9f9892SAndre Guedes int l2cap_chan_connect(struct l2cap_chan *chan, __le16 psm, u16 cid,
17498e9f9892SAndre Guedes 		       bdaddr_t *dst, u8 dst_type)
17500a708f8fSGustavo F. Padovan {
17515d41ce1dSGustavo F. Padovan 	struct sock *sk = chan->sk;
17520a708f8fSGustavo F. Padovan 	bdaddr_t *src = &bt_sk(sk)->src;
17530a708f8fSGustavo F. Padovan 	struct l2cap_conn *conn;
17540a708f8fSGustavo F. Padovan 	struct hci_conn *hcon;
17550a708f8fSGustavo F. Padovan 	struct hci_dev *hdev;
17560a708f8fSGustavo F. Padovan 	__u8 auth_type;
17570a708f8fSGustavo F. Padovan 	int err;
17580a708f8fSGustavo F. Padovan 
17596ed93dc6SAndrei Emeltchenko 	BT_DBG("%pMR -> %pMR (type %u) psm 0x%2.2x", src, dst,
1760ab19516aSSyam Sidhardhan 	       dst_type, __le16_to_cpu(psm));
17610a708f8fSGustavo F. Padovan 
17620a708f8fSGustavo F. Padovan 	hdev = hci_get_route(dst, src);
17630a708f8fSGustavo F. Padovan 	if (!hdev)
17640a708f8fSGustavo F. Padovan 		return -EHOSTUNREACH;
17650a708f8fSGustavo F. Padovan 
176609fd0de5SGustavo F. Padovan 	hci_dev_lock(hdev);
17670a708f8fSGustavo F. Padovan 
17686be36555SAndrei Emeltchenko 	l2cap_chan_lock(chan);
176903a00194SGustavo F. Padovan 
177003a00194SGustavo F. Padovan 	/* PSM must be odd and lsb of upper byte must be 0 */
177103a00194SGustavo F. Padovan 	if ((__le16_to_cpu(psm) & 0x0101) != 0x0001 && !cid &&
177203a00194SGustavo F. Padovan 	    chan->chan_type != L2CAP_CHAN_RAW) {
177303a00194SGustavo F. Padovan 		err = -EINVAL;
177403a00194SGustavo F. Padovan 		goto done;
177503a00194SGustavo F. Padovan 	}
177603a00194SGustavo F. Padovan 
177703a00194SGustavo F. Padovan 	if (chan->chan_type == L2CAP_CHAN_CONN_ORIENTED && !(psm || cid)) {
177803a00194SGustavo F. Padovan 		err = -EINVAL;
177903a00194SGustavo F. Padovan 		goto done;
178003a00194SGustavo F. Padovan 	}
178103a00194SGustavo F. Padovan 
178203a00194SGustavo F. Padovan 	switch (chan->mode) {
178303a00194SGustavo F. Padovan 	case L2CAP_MODE_BASIC:
178403a00194SGustavo F. Padovan 		break;
178503a00194SGustavo F. Padovan 	case L2CAP_MODE_ERTM:
178603a00194SGustavo F. Padovan 	case L2CAP_MODE_STREAMING:
178703a00194SGustavo F. Padovan 		if (!disable_ertm)
178803a00194SGustavo F. Padovan 			break;
178903a00194SGustavo F. Padovan 		/* fall through */
179003a00194SGustavo F. Padovan 	default:
179103a00194SGustavo F. Padovan 		err = -ENOTSUPP;
179203a00194SGustavo F. Padovan 		goto done;
179303a00194SGustavo F. Padovan 	}
179403a00194SGustavo F. Padovan 
17950797e01dSGustavo Padovan 	switch (chan->state) {
179603a00194SGustavo F. Padovan 	case BT_CONNECT:
179703a00194SGustavo F. Padovan 	case BT_CONNECT2:
179803a00194SGustavo F. Padovan 	case BT_CONFIG:
179903a00194SGustavo F. Padovan 		/* Already connecting */
180003a00194SGustavo F. Padovan 		err = 0;
180103a00194SGustavo F. Padovan 		goto done;
180203a00194SGustavo F. Padovan 
180303a00194SGustavo F. Padovan 	case BT_CONNECTED:
180403a00194SGustavo F. Padovan 		/* Already connected */
180503a00194SGustavo F. Padovan 		err = -EISCONN;
180603a00194SGustavo F. Padovan 		goto done;
180703a00194SGustavo F. Padovan 
180803a00194SGustavo F. Padovan 	case BT_OPEN:
180903a00194SGustavo F. Padovan 	case BT_BOUND:
181003a00194SGustavo F. Padovan 		/* Can connect */
181103a00194SGustavo F. Padovan 		break;
181203a00194SGustavo F. Padovan 
181303a00194SGustavo F. Padovan 	default:
181403a00194SGustavo F. Padovan 		err = -EBADFD;
181503a00194SGustavo F. Padovan 		goto done;
181603a00194SGustavo F. Padovan 	}
181703a00194SGustavo F. Padovan 
181803a00194SGustavo F. Padovan 	/* Set destination address and psm */
18190797e01dSGustavo Padovan 	lock_sock(sk);
18209219b2a0SGustavo F. Padovan 	bacpy(&bt_sk(sk)->dst, dst);
18216be36555SAndrei Emeltchenko 	release_sock(sk);
18226be36555SAndrei Emeltchenko 
182303a00194SGustavo F. Padovan 	chan->psm = psm;
182403a00194SGustavo F. Padovan 	chan->dcid = cid;
18250a708f8fSGustavo F. Padovan 
18264343478fSGustavo F. Padovan 	auth_type = l2cap_get_auth_type(chan);
18270a708f8fSGustavo F. Padovan 
1828f224ca5fSJohan Hedberg 	if (bdaddr_type_is_le(dst_type))
18298e9f9892SAndre Guedes 		hcon = hci_connect(hdev, LE_LINK, dst, dst_type,
18304343478fSGustavo F. Padovan 				   chan->sec_level, auth_type);
1831acd7d370SVille Tervo 	else
18328e9f9892SAndre Guedes 		hcon = hci_connect(hdev, ACL_LINK, dst, dst_type,
18334343478fSGustavo F. Padovan 				   chan->sec_level, auth_type);
1834acd7d370SVille Tervo 
183530e76272SVille Tervo 	if (IS_ERR(hcon)) {
183630e76272SVille Tervo 		err = PTR_ERR(hcon);
18370a708f8fSGustavo F. Padovan 		goto done;
183830e76272SVille Tervo 	}
18390a708f8fSGustavo F. Padovan 
1840baf43251SClaudio Takahasi 	conn = l2cap_conn_add(hcon);
18410a708f8fSGustavo F. Padovan 	if (!conn) {
184276a68ba0SDavid Herrmann 		hci_conn_drop(hcon);
184330e76272SVille Tervo 		err = -ENOMEM;
18440a708f8fSGustavo F. Padovan 		goto done;
18450a708f8fSGustavo F. Padovan 	}
18460a708f8fSGustavo F. Padovan 
1847141d5706SJohan Hedberg 	if (cid && __l2cap_get_chan_by_dcid(conn, cid)) {
184876a68ba0SDavid Herrmann 		hci_conn_drop(hcon);
1849141d5706SJohan Hedberg 		err = -EBUSY;
18509f0caeb1SVinicius Costa Gomes 		goto done;
18519f0caeb1SVinicius Costa Gomes 	}
18529f0caeb1SVinicius Costa Gomes 
18530a708f8fSGustavo F. Padovan 	/* Update source addr of the socket */
18540a708f8fSGustavo F. Padovan 	bacpy(src, conn->src);
18550a708f8fSGustavo F. Padovan 
18566be36555SAndrei Emeltchenko 	l2cap_chan_unlock(chan);
185748454079SGustavo F. Padovan 	l2cap_chan_add(conn, chan);
18586be36555SAndrei Emeltchenko 	l2cap_chan_lock(chan);
185948454079SGustavo F. Padovan 
18605ee9891dSJohan Hedberg 	/* l2cap_chan_add takes its own ref so we can drop this one */
18615ee9891dSJohan Hedberg 	hci_conn_drop(hcon);
18625ee9891dSJohan Hedberg 
18636be36555SAndrei Emeltchenko 	l2cap_state_change(chan, BT_CONNECT);
1864c9b66675SGustavo F. Padovan 	__set_chan_timer(chan, sk->sk_sndtimeo);
18650a708f8fSGustavo F. Padovan 
18660a708f8fSGustavo F. Padovan 	if (hcon->state == BT_CONNECTED) {
1867715ec005SGustavo F. Padovan 		if (chan->chan_type != L2CAP_CHAN_CONN_ORIENTED) {
1868c9b66675SGustavo F. Padovan 			__clear_chan_timer(chan);
1869d45fc423SGustavo F. Padovan 			if (l2cap_chan_check_security(chan))
18706be36555SAndrei Emeltchenko 				l2cap_state_change(chan, BT_CONNECTED);
18710a708f8fSGustavo F. Padovan 		} else
1872fc7f8a7eSGustavo F. Padovan 			l2cap_do_start(chan);
18730a708f8fSGustavo F. Padovan 	}
18740a708f8fSGustavo F. Padovan 
187530e76272SVille Tervo 	err = 0;
187630e76272SVille Tervo 
18770a708f8fSGustavo F. Padovan done:
18786be36555SAndrei Emeltchenko 	l2cap_chan_unlock(chan);
187909fd0de5SGustavo F. Padovan 	hci_dev_unlock(hdev);
18800a708f8fSGustavo F. Padovan 	hci_dev_put(hdev);
18810a708f8fSGustavo F. Padovan 	return err;
18820a708f8fSGustavo F. Padovan }
18830a708f8fSGustavo F. Padovan 
1884dcba0dbaSGustavo F. Padovan int __l2cap_wait_ack(struct sock *sk)
18850a708f8fSGustavo F. Padovan {
18868c1d787bSGustavo F. Padovan 	struct l2cap_chan *chan = l2cap_pi(sk)->chan;
18870a708f8fSGustavo F. Padovan 	DECLARE_WAITQUEUE(wait, current);
18880a708f8fSGustavo F. Padovan 	int err = 0;
18890a708f8fSGustavo F. Padovan 	int timeo = HZ/5;
18900a708f8fSGustavo F. Padovan 
18910a708f8fSGustavo F. Padovan 	add_wait_queue(sk_sleep(sk), &wait);
18920a708f8fSGustavo F. Padovan 	set_current_state(TASK_INTERRUPTIBLE);
1893a71a0cf4SPeter Hurley 	while (chan->unacked_frames > 0 && chan->conn) {
18940a708f8fSGustavo F. Padovan 		if (!timeo)
18950a708f8fSGustavo F. Padovan 			timeo = HZ/5;
18960a708f8fSGustavo F. Padovan 
18970a708f8fSGustavo F. Padovan 		if (signal_pending(current)) {
18980a708f8fSGustavo F. Padovan 			err = sock_intr_errno(timeo);
18990a708f8fSGustavo F. Padovan 			break;
19000a708f8fSGustavo F. Padovan 		}
19010a708f8fSGustavo F. Padovan 
19020a708f8fSGustavo F. Padovan 		release_sock(sk);
19030a708f8fSGustavo F. Padovan 		timeo = schedule_timeout(timeo);
19040a708f8fSGustavo F. Padovan 		lock_sock(sk);
1905a71a0cf4SPeter Hurley 		set_current_state(TASK_INTERRUPTIBLE);
19060a708f8fSGustavo F. Padovan 
19070a708f8fSGustavo F. Padovan 		err = sock_error(sk);
19080a708f8fSGustavo F. Padovan 		if (err)
19090a708f8fSGustavo F. Padovan 			break;
19100a708f8fSGustavo F. Padovan 	}
19110a708f8fSGustavo F. Padovan 	set_current_state(TASK_RUNNING);
19120a708f8fSGustavo F. Padovan 	remove_wait_queue(sk_sleep(sk), &wait);
19130a708f8fSGustavo F. Padovan 	return err;
19140a708f8fSGustavo F. Padovan }
19150a708f8fSGustavo F. Padovan 
1916721c4181SGustavo F. Padovan static void l2cap_monitor_timeout(struct work_struct *work)
19170a708f8fSGustavo F. Padovan {
1918721c4181SGustavo F. Padovan 	struct l2cap_chan *chan = container_of(work, struct l2cap_chan,
1919721c4181SGustavo F. Padovan 					       monitor_timer.work);
19200a708f8fSGustavo F. Padovan 
1921525cd185SGustavo F. Padovan 	BT_DBG("chan %p", chan);
19220a708f8fSGustavo F. Padovan 
19236be36555SAndrei Emeltchenko 	l2cap_chan_lock(chan);
19246be36555SAndrei Emeltchenko 
192580909e04SMat Martineau 	if (!chan->conn) {
19266be36555SAndrei Emeltchenko 		l2cap_chan_unlock(chan);
19278d7e1c7fSAndrei Emeltchenko 		l2cap_chan_put(chan);
19280a708f8fSGustavo F. Padovan 		return;
19290a708f8fSGustavo F. Padovan 	}
19300a708f8fSGustavo F. Padovan 
1931401bb1f7SAndrei Emeltchenko 	l2cap_tx(chan, NULL, NULL, L2CAP_EV_MONITOR_TO);
19320a708f8fSGustavo F. Padovan 
19336be36555SAndrei Emeltchenko 	l2cap_chan_unlock(chan);
19348d7e1c7fSAndrei Emeltchenko 	l2cap_chan_put(chan);
19350a708f8fSGustavo F. Padovan }
19360a708f8fSGustavo F. Padovan 
1937721c4181SGustavo F. Padovan static void l2cap_retrans_timeout(struct work_struct *work)
19380a708f8fSGustavo F. Padovan {
1939721c4181SGustavo F. Padovan 	struct l2cap_chan *chan = container_of(work, struct l2cap_chan,
1940721c4181SGustavo F. Padovan 					       retrans_timer.work);
19410a708f8fSGustavo F. Padovan 
194249208c9cSGustavo F. Padovan 	BT_DBG("chan %p", chan);
19430a708f8fSGustavo F. Padovan 
19446be36555SAndrei Emeltchenko 	l2cap_chan_lock(chan);
19456be36555SAndrei Emeltchenko 
194680909e04SMat Martineau 	if (!chan->conn) {
194780909e04SMat Martineau 		l2cap_chan_unlock(chan);
194880909e04SMat Martineau 		l2cap_chan_put(chan);
194980909e04SMat Martineau 		return;
195080909e04SMat Martineau 	}
19510a708f8fSGustavo F. Padovan 
1952401bb1f7SAndrei Emeltchenko 	l2cap_tx(chan, NULL, NULL, L2CAP_EV_RETRANS_TO);
19536be36555SAndrei Emeltchenko 	l2cap_chan_unlock(chan);
19548d7e1c7fSAndrei Emeltchenko 	l2cap_chan_put(chan);
19550a708f8fSGustavo F. Padovan }
19560a708f8fSGustavo F. Padovan 
1957d660366dSGustavo Padovan static void l2cap_streaming_send(struct l2cap_chan *chan,
19583733937dSMat Martineau 				 struct sk_buff_head *skbs)
19590a708f8fSGustavo F. Padovan {
19600a708f8fSGustavo F. Padovan 	struct sk_buff *skb;
19613733937dSMat Martineau 	struct l2cap_ctrl *control;
19620a708f8fSGustavo F. Padovan 
19633733937dSMat Martineau 	BT_DBG("chan %p, skbs %p", chan, skbs);
19643733937dSMat Martineau 
1965b99e13adSMat Martineau 	if (__chan_is_moving(chan))
1966b99e13adSMat Martineau 		return;
1967b99e13adSMat Martineau 
19683733937dSMat Martineau 	skb_queue_splice_tail_init(skbs, &chan->tx_q);
19693733937dSMat Martineau 
19703733937dSMat Martineau 	while (!skb_queue_empty(&chan->tx_q)) {
19713733937dSMat Martineau 
19723733937dSMat Martineau 		skb = skb_dequeue(&chan->tx_q);
19733733937dSMat Martineau 
19743733937dSMat Martineau 		bt_cb(skb)->control.retries = 1;
19753733937dSMat Martineau 		control = &bt_cb(skb)->control;
19763733937dSMat Martineau 
19773733937dSMat Martineau 		control->reqseq = 0;
19783733937dSMat Martineau 		control->txseq = chan->next_tx_seq;
19793733937dSMat Martineau 
19803733937dSMat Martineau 		__pack_control(chan, control, skb);
19810a708f8fSGustavo F. Padovan 
198247d1ec61SGustavo F. Padovan 		if (chan->fcs == L2CAP_FCS_CRC16) {
19833733937dSMat Martineau 			u16 fcs = crc16(0, (u8 *) skb->data, skb->len);
19843733937dSMat Martineau 			put_unaligned_le16(fcs, skb_put(skb, L2CAP_FCS_SIZE));
19850a708f8fSGustavo F. Padovan 		}
19860a708f8fSGustavo F. Padovan 
19874343478fSGustavo F. Padovan 		l2cap_do_send(chan, skb);
19880a708f8fSGustavo F. Padovan 
1989b4400672SAndrei Emeltchenko 		BT_DBG("Sent txseq %u", control->txseq);
19903733937dSMat Martineau 
1991836be934SAndrei Emeltchenko 		chan->next_tx_seq = __next_seq(chan, chan->next_tx_seq);
19923733937dSMat Martineau 		chan->frames_sent++;
19930a708f8fSGustavo F. Padovan 	}
19940a708f8fSGustavo F. Padovan }
19950a708f8fSGustavo F. Padovan 
199667c9e840SSzymon Janc static int l2cap_ertm_send(struct l2cap_chan *chan)
19970a708f8fSGustavo F. Padovan {
19980a708f8fSGustavo F. Padovan 	struct sk_buff *skb, *tx_skb;
199918a48e76SMat Martineau 	struct l2cap_ctrl *control;
200018a48e76SMat Martineau 	int sent = 0;
200118a48e76SMat Martineau 
200218a48e76SMat Martineau 	BT_DBG("chan %p", chan);
20030a708f8fSGustavo F. Padovan 
200489bc500eSGustavo F. Padovan 	if (chan->state != BT_CONNECTED)
20050a708f8fSGustavo F. Padovan 		return -ENOTCONN;
20060a708f8fSGustavo F. Padovan 
200794122bbeSMat Martineau 	if (test_bit(CONN_REMOTE_BUSY, &chan->conn_state))
200894122bbeSMat Martineau 		return 0;
200994122bbeSMat Martineau 
2010b99e13adSMat Martineau 	if (__chan_is_moving(chan))
2011b99e13adSMat Martineau 		return 0;
2012b99e13adSMat Martineau 
201318a48e76SMat Martineau 	while (chan->tx_send_head &&
201418a48e76SMat Martineau 	       chan->unacked_frames < chan->remote_tx_win &&
201518a48e76SMat Martineau 	       chan->tx_state == L2CAP_TX_STATE_XMIT) {
20160a708f8fSGustavo F. Padovan 
201718a48e76SMat Martineau 		skb = chan->tx_send_head;
20180a708f8fSGustavo F. Padovan 
201918a48e76SMat Martineau 		bt_cb(skb)->control.retries = 1;
202018a48e76SMat Martineau 		control = &bt_cb(skb)->control;
20210a708f8fSGustavo F. Padovan 
2022e2ab4353SGustavo F. Padovan 		if (test_and_clear_bit(CONN_SEND_FBIT, &chan->conn_state))
202318a48e76SMat Martineau 			control->final = 1;
2024e2ab4353SGustavo F. Padovan 
202518a48e76SMat Martineau 		control->reqseq = chan->buffer_seq;
202618a48e76SMat Martineau 		chan->last_acked_seq = chan->buffer_seq;
202718a48e76SMat Martineau 		control->txseq = chan->next_tx_seq;
20280a708f8fSGustavo F. Padovan 
202918a48e76SMat Martineau 		__pack_control(chan, control, skb);
20300a708f8fSGustavo F. Padovan 
203147d1ec61SGustavo F. Padovan 		if (chan->fcs == L2CAP_FCS_CRC16) {
203218a48e76SMat Martineau 			u16 fcs = crc16(0, (u8 *) skb->data, skb->len);
203318a48e76SMat Martineau 			put_unaligned_le16(fcs, skb_put(skb, L2CAP_FCS_SIZE));
20340a708f8fSGustavo F. Padovan 		}
20350a708f8fSGustavo F. Padovan 
203618a48e76SMat Martineau 		/* Clone after data has been modified. Data is assumed to be
203718a48e76SMat Martineau 		   read-only (for locking purposes) on cloned sk_buffs.
203818a48e76SMat Martineau 		 */
203918a48e76SMat Martineau 		tx_skb = skb_clone(skb, GFP_KERNEL);
204018a48e76SMat Martineau 
204118a48e76SMat Martineau 		if (!tx_skb)
204218a48e76SMat Martineau 			break;
20430a708f8fSGustavo F. Padovan 
20441a09bcb9SGustavo F. Padovan 		__set_retrans_timer(chan);
20450a708f8fSGustavo F. Padovan 
2046836be934SAndrei Emeltchenko 		chan->next_tx_seq = __next_seq(chan, chan->next_tx_seq);
20476a026610SGustavo F. Padovan 		chan->unacked_frames++;
20486a026610SGustavo F. Padovan 		chan->frames_sent++;
204918a48e76SMat Martineau 		sent++;
20500a708f8fSGustavo F. Padovan 
205158d35f87SGustavo F. Padovan 		if (skb_queue_is_last(&chan->tx_q, skb))
205258d35f87SGustavo F. Padovan 			chan->tx_send_head = NULL;
20530a708f8fSGustavo F. Padovan 		else
205458d35f87SGustavo F. Padovan 			chan->tx_send_head = skb_queue_next(&chan->tx_q, skb);
205518a48e76SMat Martineau 
205618a48e76SMat Martineau 		l2cap_do_send(chan, tx_skb);
2057b4400672SAndrei Emeltchenko 		BT_DBG("Sent txseq %u", control->txseq);
20580a708f8fSGustavo F. Padovan 	}
20590a708f8fSGustavo F. Padovan 
2060b4400672SAndrei Emeltchenko 	BT_DBG("Sent %d, %u unacked, %u in ERTM queue", sent,
2061b4400672SAndrei Emeltchenko 	       chan->unacked_frames, skb_queue_len(&chan->tx_q));
206218a48e76SMat Martineau 
206318a48e76SMat Martineau 	return sent;
20640a708f8fSGustavo F. Padovan }
20650a708f8fSGustavo F. Padovan 
2066e1fbd4c1SMat Martineau static void l2cap_ertm_resend(struct l2cap_chan *chan)
2067e1fbd4c1SMat Martineau {
2068e1fbd4c1SMat Martineau 	struct l2cap_ctrl control;
2069e1fbd4c1SMat Martineau 	struct sk_buff *skb;
2070e1fbd4c1SMat Martineau 	struct sk_buff *tx_skb;
2071e1fbd4c1SMat Martineau 	u16 seq;
2072e1fbd4c1SMat Martineau 
2073e1fbd4c1SMat Martineau 	BT_DBG("chan %p", chan);
2074e1fbd4c1SMat Martineau 
2075e1fbd4c1SMat Martineau 	if (test_bit(CONN_REMOTE_BUSY, &chan->conn_state))
2076e1fbd4c1SMat Martineau 		return;
2077e1fbd4c1SMat Martineau 
2078b99e13adSMat Martineau 	if (__chan_is_moving(chan))
2079b99e13adSMat Martineau 		return;
2080b99e13adSMat Martineau 
2081e1fbd4c1SMat Martineau 	while (chan->retrans_list.head != L2CAP_SEQ_LIST_CLEAR) {
2082e1fbd4c1SMat Martineau 		seq = l2cap_seq_list_pop(&chan->retrans_list);
2083e1fbd4c1SMat Martineau 
2084e1fbd4c1SMat Martineau 		skb = l2cap_ertm_seq_in_queue(&chan->tx_q, seq);
2085e1fbd4c1SMat Martineau 		if (!skb) {
2086e1fbd4c1SMat Martineau 			BT_DBG("Error: Can't retransmit seq %d, frame missing",
2087e1fbd4c1SMat Martineau 			       seq);
2088e1fbd4c1SMat Martineau 			continue;
2089e1fbd4c1SMat Martineau 		}
2090e1fbd4c1SMat Martineau 
2091e1fbd4c1SMat Martineau 		bt_cb(skb)->control.retries++;
2092e1fbd4c1SMat Martineau 		control = bt_cb(skb)->control;
2093e1fbd4c1SMat Martineau 
2094e1fbd4c1SMat Martineau 		if (chan->max_tx != 0 &&
2095e1fbd4c1SMat Martineau 		    bt_cb(skb)->control.retries > chan->max_tx) {
2096e1fbd4c1SMat Martineau 			BT_DBG("Retry limit exceeded (%d)", chan->max_tx);
20975e4e3972SAndrei Emeltchenko 			l2cap_send_disconn_req(chan, ECONNRESET);
2098e1fbd4c1SMat Martineau 			l2cap_seq_list_clear(&chan->retrans_list);
2099e1fbd4c1SMat Martineau 			break;
2100e1fbd4c1SMat Martineau 		}
2101e1fbd4c1SMat Martineau 
2102e1fbd4c1SMat Martineau 		control.reqseq = chan->buffer_seq;
2103e1fbd4c1SMat Martineau 		if (test_and_clear_bit(CONN_SEND_FBIT, &chan->conn_state))
2104e1fbd4c1SMat Martineau 			control.final = 1;
2105e1fbd4c1SMat Martineau 		else
2106e1fbd4c1SMat Martineau 			control.final = 0;
2107e1fbd4c1SMat Martineau 
2108e1fbd4c1SMat Martineau 		if (skb_cloned(skb)) {
2109e1fbd4c1SMat Martineau 			/* Cloned sk_buffs are read-only, so we need a
2110e1fbd4c1SMat Martineau 			 * writeable copy
2111e1fbd4c1SMat Martineau 			 */
21128bcde1f2SGustavo Padovan 			tx_skb = skb_copy(skb, GFP_KERNEL);
2113e1fbd4c1SMat Martineau 		} else {
21148bcde1f2SGustavo Padovan 			tx_skb = skb_clone(skb, GFP_KERNEL);
2115e1fbd4c1SMat Martineau 		}
2116e1fbd4c1SMat Martineau 
2117e1fbd4c1SMat Martineau 		if (!tx_skb) {
2118e1fbd4c1SMat Martineau 			l2cap_seq_list_clear(&chan->retrans_list);
2119e1fbd4c1SMat Martineau 			break;
2120e1fbd4c1SMat Martineau 		}
2121e1fbd4c1SMat Martineau 
2122e1fbd4c1SMat Martineau 		/* Update skb contents */
2123e1fbd4c1SMat Martineau 		if (test_bit(FLAG_EXT_CTRL, &chan->flags)) {
2124e1fbd4c1SMat Martineau 			put_unaligned_le32(__pack_extended_control(&control),
2125e1fbd4c1SMat Martineau 					   tx_skb->data + L2CAP_HDR_SIZE);
2126e1fbd4c1SMat Martineau 		} else {
2127e1fbd4c1SMat Martineau 			put_unaligned_le16(__pack_enhanced_control(&control),
2128e1fbd4c1SMat Martineau 					   tx_skb->data + L2CAP_HDR_SIZE);
2129e1fbd4c1SMat Martineau 		}
2130e1fbd4c1SMat Martineau 
2131e1fbd4c1SMat Martineau 		if (chan->fcs == L2CAP_FCS_CRC16) {
2132e1fbd4c1SMat Martineau 			u16 fcs = crc16(0, (u8 *) tx_skb->data, tx_skb->len);
2133e1fbd4c1SMat Martineau 			put_unaligned_le16(fcs, skb_put(tx_skb,
2134e1fbd4c1SMat Martineau 							L2CAP_FCS_SIZE));
2135e1fbd4c1SMat Martineau 		}
2136e1fbd4c1SMat Martineau 
2137e1fbd4c1SMat Martineau 		l2cap_do_send(chan, tx_skb);
2138e1fbd4c1SMat Martineau 
2139e1fbd4c1SMat Martineau 		BT_DBG("Resent txseq %d", control.txseq);
2140e1fbd4c1SMat Martineau 
2141e1fbd4c1SMat Martineau 		chan->last_acked_seq = chan->buffer_seq;
2142e1fbd4c1SMat Martineau 	}
2143e1fbd4c1SMat Martineau }
2144e1fbd4c1SMat Martineau 
2145f80842a8SMat Martineau static void l2cap_retransmit(struct l2cap_chan *chan,
2146f80842a8SMat Martineau 			     struct l2cap_ctrl *control)
2147f80842a8SMat Martineau {
2148f80842a8SMat Martineau 	BT_DBG("chan %p, control %p", chan, control);
2149f80842a8SMat Martineau 
2150f80842a8SMat Martineau 	l2cap_seq_list_append(&chan->retrans_list, control->reqseq);
2151f80842a8SMat Martineau 	l2cap_ertm_resend(chan);
2152f80842a8SMat Martineau }
2153f80842a8SMat Martineau 
2154d2a7ac5dSMat Martineau static void l2cap_retransmit_all(struct l2cap_chan *chan,
2155d2a7ac5dSMat Martineau 				 struct l2cap_ctrl *control)
2156d2a7ac5dSMat Martineau {
2157e1fbd4c1SMat Martineau 	struct sk_buff *skb;
2158e1fbd4c1SMat Martineau 
2159e1fbd4c1SMat Martineau 	BT_DBG("chan %p, control %p", chan, control);
2160e1fbd4c1SMat Martineau 
2161e1fbd4c1SMat Martineau 	if (control->poll)
2162e1fbd4c1SMat Martineau 		set_bit(CONN_SEND_FBIT, &chan->conn_state);
2163e1fbd4c1SMat Martineau 
2164e1fbd4c1SMat Martineau 	l2cap_seq_list_clear(&chan->retrans_list);
2165e1fbd4c1SMat Martineau 
2166e1fbd4c1SMat Martineau 	if (test_bit(CONN_REMOTE_BUSY, &chan->conn_state))
2167e1fbd4c1SMat Martineau 		return;
2168e1fbd4c1SMat Martineau 
2169e1fbd4c1SMat Martineau 	if (chan->unacked_frames) {
2170e1fbd4c1SMat Martineau 		skb_queue_walk(&chan->tx_q, skb) {
2171e1fbd4c1SMat Martineau 			if (bt_cb(skb)->control.txseq == control->reqseq ||
2172e1fbd4c1SMat Martineau 			    skb == chan->tx_send_head)
2173e1fbd4c1SMat Martineau 				break;
2174e1fbd4c1SMat Martineau 		}
2175e1fbd4c1SMat Martineau 
2176e1fbd4c1SMat Martineau 		skb_queue_walk_from(&chan->tx_q, skb) {
2177e1fbd4c1SMat Martineau 			if (skb == chan->tx_send_head)
2178e1fbd4c1SMat Martineau 				break;
2179e1fbd4c1SMat Martineau 
2180e1fbd4c1SMat Martineau 			l2cap_seq_list_append(&chan->retrans_list,
2181e1fbd4c1SMat Martineau 					      bt_cb(skb)->control.txseq);
2182e1fbd4c1SMat Martineau 		}
2183e1fbd4c1SMat Martineau 
2184e1fbd4c1SMat Martineau 		l2cap_ertm_resend(chan);
2185e1fbd4c1SMat Martineau 	}
2186d2a7ac5dSMat Martineau }
2187d2a7ac5dSMat Martineau 
2188b17e73bbSSzymon Janc static void l2cap_send_ack(struct l2cap_chan *chan)
2189b17e73bbSSzymon Janc {
21900a0aba42SMat Martineau 	struct l2cap_ctrl control;
21910a0aba42SMat Martineau 	u16 frames_to_ack = __seq_offset(chan, chan->buffer_seq,
21920a0aba42SMat Martineau 					 chan->last_acked_seq);
21930a0aba42SMat Martineau 	int threshold;
21940a0aba42SMat Martineau 
21950a0aba42SMat Martineau 	BT_DBG("chan %p last_acked_seq %d buffer_seq %d",
21960a0aba42SMat Martineau 	       chan, chan->last_acked_seq, chan->buffer_seq);
21970a0aba42SMat Martineau 
21980a0aba42SMat Martineau 	memset(&control, 0, sizeof(control));
21990a0aba42SMat Martineau 	control.sframe = 1;
22000a0aba42SMat Martineau 
22010a0aba42SMat Martineau 	if (test_bit(CONN_LOCAL_BUSY, &chan->conn_state) &&
22020a0aba42SMat Martineau 	    chan->rx_state == L2CAP_RX_STATE_RECV) {
2203b17e73bbSSzymon Janc 		__clear_ack_timer(chan);
22040a0aba42SMat Martineau 		control.super = L2CAP_SUPER_RNR;
22050a0aba42SMat Martineau 		control.reqseq = chan->buffer_seq;
22060a0aba42SMat Martineau 		l2cap_send_sframe(chan, &control);
22070a0aba42SMat Martineau 	} else {
22080a0aba42SMat Martineau 		if (!test_bit(CONN_REMOTE_BUSY, &chan->conn_state)) {
22090a0aba42SMat Martineau 			l2cap_ertm_send(chan);
22100a0aba42SMat Martineau 			/* If any i-frames were sent, they included an ack */
22110a0aba42SMat Martineau 			if (chan->buffer_seq == chan->last_acked_seq)
22120a0aba42SMat Martineau 				frames_to_ack = 0;
22130a0aba42SMat Martineau 		}
22140a0aba42SMat Martineau 
2215c20f8e35SMat Martineau 		/* Ack now if the window is 3/4ths full.
22160a0aba42SMat Martineau 		 * Calculate without mul or div
22170a0aba42SMat Martineau 		 */
2218c20f8e35SMat Martineau 		threshold = chan->ack_win;
22190a0aba42SMat Martineau 		threshold += threshold << 1;
22200a0aba42SMat Martineau 		threshold >>= 2;
22210a0aba42SMat Martineau 
2222b4400672SAndrei Emeltchenko 		BT_DBG("frames_to_ack %u, threshold %d", frames_to_ack,
22230a0aba42SMat Martineau 		       threshold);
22240a0aba42SMat Martineau 
22250a0aba42SMat Martineau 		if (frames_to_ack >= threshold) {
22260a0aba42SMat Martineau 			__clear_ack_timer(chan);
22270a0aba42SMat Martineau 			control.super = L2CAP_SUPER_RR;
22280a0aba42SMat Martineau 			control.reqseq = chan->buffer_seq;
22290a0aba42SMat Martineau 			l2cap_send_sframe(chan, &control);
22300a0aba42SMat Martineau 			frames_to_ack = 0;
22310a0aba42SMat Martineau 		}
22320a0aba42SMat Martineau 
22330a0aba42SMat Martineau 		if (frames_to_ack)
22340a0aba42SMat Martineau 			__set_ack_timer(chan);
22350a0aba42SMat Martineau 	}
2236b17e73bbSSzymon Janc }
2237b17e73bbSSzymon Janc 
223804124681SGustavo F. Padovan static inline int l2cap_skbuff_fromiovec(struct l2cap_chan *chan,
223904124681SGustavo F. Padovan 					 struct msghdr *msg, int len,
224004124681SGustavo F. Padovan 					 int count, struct sk_buff *skb)
22410a708f8fSGustavo F. Padovan {
22420952a57aSAndrei Emeltchenko 	struct l2cap_conn *conn = chan->conn;
22430a708f8fSGustavo F. Padovan 	struct sk_buff **frag;
224490338947SGustavo Padovan 	int sent = 0;
22450a708f8fSGustavo F. Padovan 
22460a708f8fSGustavo F. Padovan 	if (memcpy_fromiovec(skb_put(skb, count), msg->msg_iov, count))
22470a708f8fSGustavo F. Padovan 		return -EFAULT;
22480a708f8fSGustavo F. Padovan 
22490a708f8fSGustavo F. Padovan 	sent += count;
22500a708f8fSGustavo F. Padovan 	len  -= count;
22510a708f8fSGustavo F. Padovan 
22520a708f8fSGustavo F. Padovan 	/* Continuation fragments (no L2CAP header) */
22530a708f8fSGustavo F. Padovan 	frag = &skb_shinfo(skb)->frag_list;
22540a708f8fSGustavo F. Padovan 	while (len) {
2255fbe00700SGustavo Padovan 		struct sk_buff *tmp;
2256fbe00700SGustavo Padovan 
22570a708f8fSGustavo F. Padovan 		count = min_t(unsigned int, conn->mtu, len);
22580a708f8fSGustavo F. Padovan 
2259fbe00700SGustavo Padovan 		tmp = chan->ops->alloc_skb(chan, count,
226090338947SGustavo Padovan 					   msg->msg_flags & MSG_DONTWAIT);
2261fbe00700SGustavo Padovan 		if (IS_ERR(tmp))
2262fbe00700SGustavo Padovan 			return PTR_ERR(tmp);
22632f7719ceSAndrei Emeltchenko 
2264fbe00700SGustavo Padovan 		*frag = tmp;
2265fbe00700SGustavo Padovan 
22660a708f8fSGustavo F. Padovan 		if (memcpy_fromiovec(skb_put(*frag, count), msg->msg_iov, count))
22670a708f8fSGustavo F. Padovan 			return -EFAULT;
22680a708f8fSGustavo F. Padovan 
22695e59b791SLuiz Augusto von Dentz 		(*frag)->priority = skb->priority;
22705e59b791SLuiz Augusto von Dentz 
22710a708f8fSGustavo F. Padovan 		sent += count;
22720a708f8fSGustavo F. Padovan 		len  -= count;
22730a708f8fSGustavo F. Padovan 
22742d0ed3d5SGustavo Padovan 		skb->len += (*frag)->len;
22752d0ed3d5SGustavo Padovan 		skb->data_len += (*frag)->len;
22762d0ed3d5SGustavo Padovan 
22770a708f8fSGustavo F. Padovan 		frag = &(*frag)->next;
22780a708f8fSGustavo F. Padovan 	}
22790a708f8fSGustavo F. Padovan 
22800a708f8fSGustavo F. Padovan 	return sent;
22810a708f8fSGustavo F. Padovan }
22820a708f8fSGustavo F. Padovan 
22835e59b791SLuiz Augusto von Dentz static struct sk_buff *l2cap_create_connless_pdu(struct l2cap_chan *chan,
22845e59b791SLuiz Augusto von Dentz 						 struct msghdr *msg, size_t len,
22855e59b791SLuiz Augusto von Dentz 						 u32 priority)
22860a708f8fSGustavo F. Padovan {
22878c1d787bSGustavo F. Padovan 	struct l2cap_conn *conn = chan->conn;
22880a708f8fSGustavo F. Padovan 	struct sk_buff *skb;
228903a51213SAndrei Emeltchenko 	int err, count, hlen = L2CAP_HDR_SIZE + L2CAP_PSMLEN_SIZE;
22900a708f8fSGustavo F. Padovan 	struct l2cap_hdr *lh;
22910a708f8fSGustavo F. Padovan 
229243b1b8dfSMarcel Holtmann 	BT_DBG("chan %p psm 0x%2.2x len %zu priority %u", chan,
229343b1b8dfSMarcel Holtmann 	       __le16_to_cpu(chan->psm), len, priority);
22940a708f8fSGustavo F. Padovan 
22950a708f8fSGustavo F. Padovan 	count = min_t(unsigned int, (conn->mtu - hlen), len);
22962f7719ceSAndrei Emeltchenko 
22972f7719ceSAndrei Emeltchenko 	skb = chan->ops->alloc_skb(chan, count + hlen,
229890338947SGustavo Padovan 				   msg->msg_flags & MSG_DONTWAIT);
229990338947SGustavo Padovan 	if (IS_ERR(skb))
230090338947SGustavo Padovan 		return skb;
23010a708f8fSGustavo F. Padovan 
23025e59b791SLuiz Augusto von Dentz 	skb->priority = priority;
23035e59b791SLuiz Augusto von Dentz 
23040a708f8fSGustavo F. Padovan 	/* Create L2CAP header */
23050a708f8fSGustavo F. Padovan 	lh = (struct l2cap_hdr *) skb_put(skb, L2CAP_HDR_SIZE);
2306fe4128e0SGustavo F. Padovan 	lh->cid = cpu_to_le16(chan->dcid);
2307daf6a78cSAndrei Emeltchenko 	lh->len = cpu_to_le16(len + L2CAP_PSMLEN_SIZE);
230843b1b8dfSMarcel Holtmann 	put_unaligned(chan->psm, (__le16 *) skb_put(skb, L2CAP_PSMLEN_SIZE));
23090a708f8fSGustavo F. Padovan 
23100952a57aSAndrei Emeltchenko 	err = l2cap_skbuff_fromiovec(chan, msg, len, count, skb);
23110a708f8fSGustavo F. Padovan 	if (unlikely(err < 0)) {
23120a708f8fSGustavo F. Padovan 		kfree_skb(skb);
23130a708f8fSGustavo F. Padovan 		return ERR_PTR(err);
23140a708f8fSGustavo F. Padovan 	}
23150a708f8fSGustavo F. Padovan 	return skb;
23160a708f8fSGustavo F. Padovan }
23170a708f8fSGustavo F. Padovan 
23185e59b791SLuiz Augusto von Dentz static struct sk_buff *l2cap_create_basic_pdu(struct l2cap_chan *chan,
23195e59b791SLuiz Augusto von Dentz 					      struct msghdr *msg, size_t len,
23205e59b791SLuiz Augusto von Dentz 					      u32 priority)
23210a708f8fSGustavo F. Padovan {
23228c1d787bSGustavo F. Padovan 	struct l2cap_conn *conn = chan->conn;
23230a708f8fSGustavo F. Padovan 	struct sk_buff *skb;
2324f2ba7faeSGustavo Padovan 	int err, count;
23250a708f8fSGustavo F. Padovan 	struct l2cap_hdr *lh;
23260a708f8fSGustavo F. Padovan 
2327b4400672SAndrei Emeltchenko 	BT_DBG("chan %p len %zu", chan, len);
23280a708f8fSGustavo F. Padovan 
2329f2ba7faeSGustavo Padovan 	count = min_t(unsigned int, (conn->mtu - L2CAP_HDR_SIZE), len);
23302f7719ceSAndrei Emeltchenko 
2331f2ba7faeSGustavo Padovan 	skb = chan->ops->alloc_skb(chan, count + L2CAP_HDR_SIZE,
233290338947SGustavo Padovan 				   msg->msg_flags & MSG_DONTWAIT);
233390338947SGustavo Padovan 	if (IS_ERR(skb))
233490338947SGustavo Padovan 		return skb;
23350a708f8fSGustavo F. Padovan 
23365e59b791SLuiz Augusto von Dentz 	skb->priority = priority;
23375e59b791SLuiz Augusto von Dentz 
23380a708f8fSGustavo F. Padovan 	/* Create L2CAP header */
23390a708f8fSGustavo F. Padovan 	lh = (struct l2cap_hdr *) skb_put(skb, L2CAP_HDR_SIZE);
2340fe4128e0SGustavo F. Padovan 	lh->cid = cpu_to_le16(chan->dcid);
23416ff9b5efSGustavo Padovan 	lh->len = cpu_to_le16(len);
23420a708f8fSGustavo F. Padovan 
23430952a57aSAndrei Emeltchenko 	err = l2cap_skbuff_fromiovec(chan, msg, len, count, skb);
23440a708f8fSGustavo F. Padovan 	if (unlikely(err < 0)) {
23450a708f8fSGustavo F. Padovan 		kfree_skb(skb);
23460a708f8fSGustavo F. Padovan 		return ERR_PTR(err);
23470a708f8fSGustavo F. Padovan 	}
23480a708f8fSGustavo F. Padovan 	return skb;
23490a708f8fSGustavo F. Padovan }
23500a708f8fSGustavo F. Padovan 
2351ab0ff76dSLuiz Augusto von Dentz static struct sk_buff *l2cap_create_iframe_pdu(struct l2cap_chan *chan,
2352ab0ff76dSLuiz Augusto von Dentz 					       struct msghdr *msg, size_t len,
235394122bbeSMat Martineau 					       u16 sdulen)
23540a708f8fSGustavo F. Padovan {
23558c1d787bSGustavo F. Padovan 	struct l2cap_conn *conn = chan->conn;
23560a708f8fSGustavo F. Padovan 	struct sk_buff *skb;
2357e4ca6d98SAndrei Emeltchenko 	int err, count, hlen;
23580a708f8fSGustavo F. Padovan 	struct l2cap_hdr *lh;
23590a708f8fSGustavo F. Padovan 
2360b4400672SAndrei Emeltchenko 	BT_DBG("chan %p len %zu", chan, len);
23610a708f8fSGustavo F. Padovan 
23620a708f8fSGustavo F. Padovan 	if (!conn)
23630a708f8fSGustavo F. Padovan 		return ERR_PTR(-ENOTCONN);
23640a708f8fSGustavo F. Padovan 
2365ba7aa64fSGustavo Padovan 	hlen = __ertm_hdr_size(chan);
2366e4ca6d98SAndrei Emeltchenko 
23670a708f8fSGustavo F. Padovan 	if (sdulen)
236803a51213SAndrei Emeltchenko 		hlen += L2CAP_SDULEN_SIZE;
23690a708f8fSGustavo F. Padovan 
237047d1ec61SGustavo F. Padovan 	if (chan->fcs == L2CAP_FCS_CRC16)
237103a51213SAndrei Emeltchenko 		hlen += L2CAP_FCS_SIZE;
23720a708f8fSGustavo F. Padovan 
23730a708f8fSGustavo F. Padovan 	count = min_t(unsigned int, (conn->mtu - hlen), len);
23742f7719ceSAndrei Emeltchenko 
23752f7719ceSAndrei Emeltchenko 	skb = chan->ops->alloc_skb(chan, count + hlen,
237690338947SGustavo Padovan 				   msg->msg_flags & MSG_DONTWAIT);
237790338947SGustavo Padovan 	if (IS_ERR(skb))
237890338947SGustavo Padovan 		return skb;
23790a708f8fSGustavo F. Padovan 
23800a708f8fSGustavo F. Padovan 	/* Create L2CAP header */
23810a708f8fSGustavo F. Padovan 	lh = (struct l2cap_hdr *) skb_put(skb, L2CAP_HDR_SIZE);
2382fe4128e0SGustavo F. Padovan 	lh->cid = cpu_to_le16(chan->dcid);
23830a708f8fSGustavo F. Padovan 	lh->len = cpu_to_le16(len + (hlen - L2CAP_HDR_SIZE));
238488843ab0SAndrei Emeltchenko 
238518a48e76SMat Martineau 	/* Control header is populated later */
238618a48e76SMat Martineau 	if (test_bit(FLAG_EXT_CTRL, &chan->flags))
238718a48e76SMat Martineau 		put_unaligned_le32(0, skb_put(skb, L2CAP_EXT_CTRL_SIZE));
238818a48e76SMat Martineau 	else
238918a48e76SMat Martineau 		put_unaligned_le16(0, skb_put(skb, L2CAP_ENH_CTRL_SIZE));
239088843ab0SAndrei Emeltchenko 
23910a708f8fSGustavo F. Padovan 	if (sdulen)
239203a51213SAndrei Emeltchenko 		put_unaligned_le16(sdulen, skb_put(skb, L2CAP_SDULEN_SIZE));
23930a708f8fSGustavo F. Padovan 
23940952a57aSAndrei Emeltchenko 	err = l2cap_skbuff_fromiovec(chan, msg, len, count, skb);
23950a708f8fSGustavo F. Padovan 	if (unlikely(err < 0)) {
23960a708f8fSGustavo F. Padovan 		kfree_skb(skb);
23970a708f8fSGustavo F. Padovan 		return ERR_PTR(err);
23980a708f8fSGustavo F. Padovan 	}
23990a708f8fSGustavo F. Padovan 
240018a48e76SMat Martineau 	bt_cb(skb)->control.fcs = chan->fcs;
24013ce3514fSMat Martineau 	bt_cb(skb)->control.retries = 0;
24020a708f8fSGustavo F. Padovan 	return skb;
24030a708f8fSGustavo F. Padovan }
24040a708f8fSGustavo F. Padovan 
240594122bbeSMat Martineau static int l2cap_segment_sdu(struct l2cap_chan *chan,
240694122bbeSMat Martineau 			     struct sk_buff_head *seg_queue,
240794122bbeSMat Martineau 			     struct msghdr *msg, size_t len)
24080a708f8fSGustavo F. Padovan {
24090a708f8fSGustavo F. Padovan 	struct sk_buff *skb;
241094122bbeSMat Martineau 	u16 sdu_len;
241194122bbeSMat Martineau 	size_t pdu_len;
241294122bbeSMat Martineau 	u8 sar;
24130a708f8fSGustavo F. Padovan 
2414b4400672SAndrei Emeltchenko 	BT_DBG("chan %p, msg %p, len %zu", chan, msg, len);
24150a708f8fSGustavo F. Padovan 
241694122bbeSMat Martineau 	/* It is critical that ERTM PDUs fit in a single HCI fragment,
241794122bbeSMat Martineau 	 * so fragmented skbs are not used.  The HCI layer's handling
241894122bbeSMat Martineau 	 * of fragmented skbs is not compatible with ERTM's queueing.
241994122bbeSMat Martineau 	 */
242094122bbeSMat Martineau 
242194122bbeSMat Martineau 	/* PDU size is derived from the HCI MTU */
242294122bbeSMat Martineau 	pdu_len = chan->conn->mtu;
242394122bbeSMat Martineau 
2424a549574dSMat Martineau 	/* Constrain PDU size for BR/EDR connections */
2425a549574dSMat Martineau 	if (!chan->hs_hcon)
242694122bbeSMat Martineau 		pdu_len = min_t(size_t, pdu_len, L2CAP_BREDR_MAX_PAYLOAD);
242794122bbeSMat Martineau 
242894122bbeSMat Martineau 	/* Adjust for largest possible L2CAP overhead. */
242935d401dfSGustavo Padovan 	if (chan->fcs)
243035d401dfSGustavo Padovan 		pdu_len -= L2CAP_FCS_SIZE;
243135d401dfSGustavo Padovan 
2432ba7aa64fSGustavo Padovan 	pdu_len -= __ertm_hdr_size(chan);
243394122bbeSMat Martineau 
243494122bbeSMat Martineau 	/* Remote device may have requested smaller PDUs */
243594122bbeSMat Martineau 	pdu_len = min_t(size_t, pdu_len, chan->remote_mps);
243694122bbeSMat Martineau 
243794122bbeSMat Martineau 	if (len <= pdu_len) {
243894122bbeSMat Martineau 		sar = L2CAP_SAR_UNSEGMENTED;
243994122bbeSMat Martineau 		sdu_len = 0;
244094122bbeSMat Martineau 		pdu_len = len;
244194122bbeSMat Martineau 	} else {
244294122bbeSMat Martineau 		sar = L2CAP_SAR_START;
244394122bbeSMat Martineau 		sdu_len = len;
244494122bbeSMat Martineau 		pdu_len -= L2CAP_SDULEN_SIZE;
244594122bbeSMat Martineau 	}
24460a708f8fSGustavo F. Padovan 
24470a708f8fSGustavo F. Padovan 	while (len > 0) {
244894122bbeSMat Martineau 		skb = l2cap_create_iframe_pdu(chan, msg, pdu_len, sdu_len);
24490a708f8fSGustavo F. Padovan 
24500a708f8fSGustavo F. Padovan 		if (IS_ERR(skb)) {
245194122bbeSMat Martineau 			__skb_queue_purge(seg_queue);
24520a708f8fSGustavo F. Padovan 			return PTR_ERR(skb);
24530a708f8fSGustavo F. Padovan 		}
24540a708f8fSGustavo F. Padovan 
245594122bbeSMat Martineau 		bt_cb(skb)->control.sar = sar;
245694122bbeSMat Martineau 		__skb_queue_tail(seg_queue, skb);
24570a708f8fSGustavo F. Padovan 
245894122bbeSMat Martineau 		len -= pdu_len;
245994122bbeSMat Martineau 		if (sdu_len) {
246094122bbeSMat Martineau 			sdu_len = 0;
246194122bbeSMat Martineau 			pdu_len += L2CAP_SDULEN_SIZE;
246294122bbeSMat Martineau 		}
246394122bbeSMat Martineau 
246494122bbeSMat Martineau 		if (len <= pdu_len) {
246594122bbeSMat Martineau 			sar = L2CAP_SAR_END;
246694122bbeSMat Martineau 			pdu_len = len;
246794122bbeSMat Martineau 		} else {
246894122bbeSMat Martineau 			sar = L2CAP_SAR_CONTINUE;
246994122bbeSMat Martineau 		}
247094122bbeSMat Martineau 	}
247194122bbeSMat Martineau 
2472f0f62799SGustavo Padovan 	return 0;
24730a708f8fSGustavo F. Padovan }
24740a708f8fSGustavo F. Padovan 
24755e59b791SLuiz Augusto von Dentz int l2cap_chan_send(struct l2cap_chan *chan, struct msghdr *msg, size_t len,
24765e59b791SLuiz Augusto von Dentz 		    u32 priority)
24779a91a04aSGustavo F. Padovan {
24789a91a04aSGustavo F. Padovan 	struct sk_buff *skb;
24799a91a04aSGustavo F. Padovan 	int err;
248094122bbeSMat Martineau 	struct sk_buff_head seg_queue;
24819a91a04aSGustavo F. Padovan 
24829a91a04aSGustavo F. Padovan 	/* Connectionless channel */
2483715ec005SGustavo F. Padovan 	if (chan->chan_type == L2CAP_CHAN_CONN_LESS) {
24845e59b791SLuiz Augusto von Dentz 		skb = l2cap_create_connless_pdu(chan, msg, len, priority);
24859a91a04aSGustavo F. Padovan 		if (IS_ERR(skb))
24869a91a04aSGustavo F. Padovan 			return PTR_ERR(skb);
24879a91a04aSGustavo F. Padovan 
24889a91a04aSGustavo F. Padovan 		l2cap_do_send(chan, skb);
24899a91a04aSGustavo F. Padovan 		return len;
24909a91a04aSGustavo F. Padovan 	}
24919a91a04aSGustavo F. Padovan 
24929a91a04aSGustavo F. Padovan 	switch (chan->mode) {
24939a91a04aSGustavo F. Padovan 	case L2CAP_MODE_BASIC:
24949a91a04aSGustavo F. Padovan 		/* Check outgoing MTU */
24959a91a04aSGustavo F. Padovan 		if (len > chan->omtu)
24969a91a04aSGustavo F. Padovan 			return -EMSGSIZE;
24979a91a04aSGustavo F. Padovan 
24989a91a04aSGustavo F. Padovan 		/* Create a basic PDU */
24995e59b791SLuiz Augusto von Dentz 		skb = l2cap_create_basic_pdu(chan, msg, len, priority);
25009a91a04aSGustavo F. Padovan 		if (IS_ERR(skb))
25019a91a04aSGustavo F. Padovan 			return PTR_ERR(skb);
25029a91a04aSGustavo F. Padovan 
25039a91a04aSGustavo F. Padovan 		l2cap_do_send(chan, skb);
25049a91a04aSGustavo F. Padovan 		err = len;
25059a91a04aSGustavo F. Padovan 		break;
25069a91a04aSGustavo F. Padovan 
25079a91a04aSGustavo F. Padovan 	case L2CAP_MODE_ERTM:
25089a91a04aSGustavo F. Padovan 	case L2CAP_MODE_STREAMING:
250994122bbeSMat Martineau 		/* Check outgoing MTU */
251094122bbeSMat Martineau 		if (len > chan->omtu) {
251194122bbeSMat Martineau 			err = -EMSGSIZE;
25129a91a04aSGustavo F. Padovan 			break;
25139a91a04aSGustavo F. Padovan 		}
25149a91a04aSGustavo F. Padovan 
251594122bbeSMat Martineau 		__skb_queue_head_init(&seg_queue);
251694122bbeSMat Martineau 
251794122bbeSMat Martineau 		/* Do segmentation before calling in to the state machine,
251894122bbeSMat Martineau 		 * since it's possible to block while waiting for memory
251994122bbeSMat Martineau 		 * allocation.
252094122bbeSMat Martineau 		 */
252194122bbeSMat Martineau 		err = l2cap_segment_sdu(chan, &seg_queue, msg, len);
252294122bbeSMat Martineau 
252394122bbeSMat Martineau 		/* The channel could have been closed while segmenting,
252494122bbeSMat Martineau 		 * check that it is still connected.
252594122bbeSMat Martineau 		 */
252694122bbeSMat Martineau 		if (chan->state != BT_CONNECTED) {
252794122bbeSMat Martineau 			__skb_queue_purge(&seg_queue);
252894122bbeSMat Martineau 			err = -ENOTCONN;
25299a91a04aSGustavo F. Padovan 		}
25309a91a04aSGustavo F. Padovan 
253194122bbeSMat Martineau 		if (err)
253294122bbeSMat Martineau 			break;
253394122bbeSMat Martineau 
25343733937dSMat Martineau 		if (chan->mode == L2CAP_MODE_ERTM)
2535d660366dSGustavo Padovan 			l2cap_tx(chan, NULL, &seg_queue, L2CAP_EV_DATA_REQUEST);
25363733937dSMat Martineau 		else
2537d660366dSGustavo Padovan 			l2cap_streaming_send(chan, &seg_queue);
253894122bbeSMat Martineau 
25399a91a04aSGustavo F. Padovan 		err = len;
25409a91a04aSGustavo F. Padovan 
254194122bbeSMat Martineau 		/* If the skbs were not queued for sending, they'll still be in
254294122bbeSMat Martineau 		 * seg_queue and need to be purged.
254394122bbeSMat Martineau 		 */
254494122bbeSMat Martineau 		__skb_queue_purge(&seg_queue);
25459a91a04aSGustavo F. Padovan 		break;
25469a91a04aSGustavo F. Padovan 
25479a91a04aSGustavo F. Padovan 	default:
25489a91a04aSGustavo F. Padovan 		BT_DBG("bad state %1.1x", chan->mode);
25499a91a04aSGustavo F. Padovan 		err = -EBADFD;
25509a91a04aSGustavo F. Padovan 	}
25519a91a04aSGustavo F. Padovan 
25529a91a04aSGustavo F. Padovan 	return err;
25539a91a04aSGustavo F. Padovan }
25549a91a04aSGustavo F. Padovan 
2555d2a7ac5dSMat Martineau static void l2cap_send_srej(struct l2cap_chan *chan, u16 txseq)
2556d2a7ac5dSMat Martineau {
2557bed68bdeSMat Martineau 	struct l2cap_ctrl control;
2558bed68bdeSMat Martineau 	u16 seq;
2559bed68bdeSMat Martineau 
2560b4400672SAndrei Emeltchenko 	BT_DBG("chan %p, txseq %u", chan, txseq);
2561bed68bdeSMat Martineau 
2562bed68bdeSMat Martineau 	memset(&control, 0, sizeof(control));
2563bed68bdeSMat Martineau 	control.sframe = 1;
2564bed68bdeSMat Martineau 	control.super = L2CAP_SUPER_SREJ;
2565bed68bdeSMat Martineau 
2566bed68bdeSMat Martineau 	for (seq = chan->expected_tx_seq; seq != txseq;
2567bed68bdeSMat Martineau 	     seq = __next_seq(chan, seq)) {
2568bed68bdeSMat Martineau 		if (!l2cap_ertm_seq_in_queue(&chan->srej_q, seq)) {
2569bed68bdeSMat Martineau 			control.reqseq = seq;
2570bed68bdeSMat Martineau 			l2cap_send_sframe(chan, &control);
2571bed68bdeSMat Martineau 			l2cap_seq_list_append(&chan->srej_list, seq);
2572bed68bdeSMat Martineau 		}
2573bed68bdeSMat Martineau 	}
2574bed68bdeSMat Martineau 
2575bed68bdeSMat Martineau 	chan->expected_tx_seq = __next_seq(chan, txseq);
2576d2a7ac5dSMat Martineau }
2577d2a7ac5dSMat Martineau 
2578d2a7ac5dSMat Martineau static void l2cap_send_srej_tail(struct l2cap_chan *chan)
2579d2a7ac5dSMat Martineau {
2580bed68bdeSMat Martineau 	struct l2cap_ctrl control;
2581bed68bdeSMat Martineau 
2582bed68bdeSMat Martineau 	BT_DBG("chan %p", chan);
2583bed68bdeSMat Martineau 
2584bed68bdeSMat Martineau 	if (chan->srej_list.tail == L2CAP_SEQ_LIST_CLEAR)
2585bed68bdeSMat Martineau 		return;
2586bed68bdeSMat Martineau 
2587bed68bdeSMat Martineau 	memset(&control, 0, sizeof(control));
2588bed68bdeSMat Martineau 	control.sframe = 1;
2589bed68bdeSMat Martineau 	control.super = L2CAP_SUPER_SREJ;
2590bed68bdeSMat Martineau 	control.reqseq = chan->srej_list.tail;
2591bed68bdeSMat Martineau 	l2cap_send_sframe(chan, &control);
2592d2a7ac5dSMat Martineau }
2593d2a7ac5dSMat Martineau 
2594d2a7ac5dSMat Martineau static void l2cap_send_srej_list(struct l2cap_chan *chan, u16 txseq)
2595d2a7ac5dSMat Martineau {
2596bed68bdeSMat Martineau 	struct l2cap_ctrl control;
2597bed68bdeSMat Martineau 	u16 initial_head;
2598bed68bdeSMat Martineau 	u16 seq;
2599bed68bdeSMat Martineau 
2600b4400672SAndrei Emeltchenko 	BT_DBG("chan %p, txseq %u", chan, txseq);
2601bed68bdeSMat Martineau 
2602bed68bdeSMat Martineau 	memset(&control, 0, sizeof(control));
2603bed68bdeSMat Martineau 	control.sframe = 1;
2604bed68bdeSMat Martineau 	control.super = L2CAP_SUPER_SREJ;
2605bed68bdeSMat Martineau 
2606bed68bdeSMat Martineau 	/* Capture initial list head to allow only one pass through the list. */
2607bed68bdeSMat Martineau 	initial_head = chan->srej_list.head;
2608bed68bdeSMat Martineau 
2609bed68bdeSMat Martineau 	do {
2610bed68bdeSMat Martineau 		seq = l2cap_seq_list_pop(&chan->srej_list);
2611bed68bdeSMat Martineau 		if (seq == txseq || seq == L2CAP_SEQ_LIST_CLEAR)
2612bed68bdeSMat Martineau 			break;
2613bed68bdeSMat Martineau 
2614bed68bdeSMat Martineau 		control.reqseq = seq;
2615bed68bdeSMat Martineau 		l2cap_send_sframe(chan, &control);
2616bed68bdeSMat Martineau 		l2cap_seq_list_append(&chan->srej_list, seq);
2617bed68bdeSMat Martineau 	} while (chan->srej_list.head != initial_head);
2618d2a7ac5dSMat Martineau }
2619d2a7ac5dSMat Martineau 
2620608bcc6dSMat Martineau static void l2cap_process_reqseq(struct l2cap_chan *chan, u16 reqseq)
2621608bcc6dSMat Martineau {
2622608bcc6dSMat Martineau 	struct sk_buff *acked_skb;
2623608bcc6dSMat Martineau 	u16 ackseq;
2624608bcc6dSMat Martineau 
2625b4400672SAndrei Emeltchenko 	BT_DBG("chan %p, reqseq %u", chan, reqseq);
2626608bcc6dSMat Martineau 
2627608bcc6dSMat Martineau 	if (chan->unacked_frames == 0 || reqseq == chan->expected_ack_seq)
2628608bcc6dSMat Martineau 		return;
2629608bcc6dSMat Martineau 
2630b4400672SAndrei Emeltchenko 	BT_DBG("expected_ack_seq %u, unacked_frames %u",
2631608bcc6dSMat Martineau 	       chan->expected_ack_seq, chan->unacked_frames);
2632608bcc6dSMat Martineau 
2633608bcc6dSMat Martineau 	for (ackseq = chan->expected_ack_seq; ackseq != reqseq;
2634608bcc6dSMat Martineau 	     ackseq = __next_seq(chan, ackseq)) {
2635608bcc6dSMat Martineau 
2636608bcc6dSMat Martineau 		acked_skb = l2cap_ertm_seq_in_queue(&chan->tx_q, ackseq);
2637608bcc6dSMat Martineau 		if (acked_skb) {
2638608bcc6dSMat Martineau 			skb_unlink(acked_skb, &chan->tx_q);
2639608bcc6dSMat Martineau 			kfree_skb(acked_skb);
2640608bcc6dSMat Martineau 			chan->unacked_frames--;
2641608bcc6dSMat Martineau 		}
2642608bcc6dSMat Martineau 	}
2643608bcc6dSMat Martineau 
2644608bcc6dSMat Martineau 	chan->expected_ack_seq = reqseq;
2645608bcc6dSMat Martineau 
2646608bcc6dSMat Martineau 	if (chan->unacked_frames == 0)
2647608bcc6dSMat Martineau 		__clear_retrans_timer(chan);
2648608bcc6dSMat Martineau 
2649b4400672SAndrei Emeltchenko 	BT_DBG("unacked_frames %u", chan->unacked_frames);
2650608bcc6dSMat Martineau }
2651608bcc6dSMat Martineau 
2652608bcc6dSMat Martineau static void l2cap_abort_rx_srej_sent(struct l2cap_chan *chan)
2653608bcc6dSMat Martineau {
2654608bcc6dSMat Martineau 	BT_DBG("chan %p", chan);
2655608bcc6dSMat Martineau 
2656608bcc6dSMat Martineau 	chan->expected_tx_seq = chan->buffer_seq;
2657608bcc6dSMat Martineau 	l2cap_seq_list_clear(&chan->srej_list);
2658608bcc6dSMat Martineau 	skb_queue_purge(&chan->srej_q);
2659608bcc6dSMat Martineau 	chan->rx_state = L2CAP_RX_STATE_RECV;
2660608bcc6dSMat Martineau }
2661608bcc6dSMat Martineau 
2662d660366dSGustavo Padovan static void l2cap_tx_state_xmit(struct l2cap_chan *chan,
2663608bcc6dSMat Martineau 				struct l2cap_ctrl *control,
2664608bcc6dSMat Martineau 				struct sk_buff_head *skbs, u8 event)
2665608bcc6dSMat Martineau {
2666608bcc6dSMat Martineau 	BT_DBG("chan %p, control %p, skbs %p, event %d", chan, control, skbs,
2667608bcc6dSMat Martineau 	       event);
2668608bcc6dSMat Martineau 
2669608bcc6dSMat Martineau 	switch (event) {
2670608bcc6dSMat Martineau 	case L2CAP_EV_DATA_REQUEST:
2671608bcc6dSMat Martineau 		if (chan->tx_send_head == NULL)
2672608bcc6dSMat Martineau 			chan->tx_send_head = skb_peek(skbs);
2673608bcc6dSMat Martineau 
2674608bcc6dSMat Martineau 		skb_queue_splice_tail_init(skbs, &chan->tx_q);
2675608bcc6dSMat Martineau 		l2cap_ertm_send(chan);
2676608bcc6dSMat Martineau 		break;
2677608bcc6dSMat Martineau 	case L2CAP_EV_LOCAL_BUSY_DETECTED:
2678608bcc6dSMat Martineau 		BT_DBG("Enter LOCAL_BUSY");
2679608bcc6dSMat Martineau 		set_bit(CONN_LOCAL_BUSY, &chan->conn_state);
2680608bcc6dSMat Martineau 
2681608bcc6dSMat Martineau 		if (chan->rx_state == L2CAP_RX_STATE_SREJ_SENT) {
2682608bcc6dSMat Martineau 			/* The SREJ_SENT state must be aborted if we are to
2683608bcc6dSMat Martineau 			 * enter the LOCAL_BUSY state.
2684608bcc6dSMat Martineau 			 */
2685608bcc6dSMat Martineau 			l2cap_abort_rx_srej_sent(chan);
2686608bcc6dSMat Martineau 		}
2687608bcc6dSMat Martineau 
2688608bcc6dSMat Martineau 		l2cap_send_ack(chan);
2689608bcc6dSMat Martineau 
2690608bcc6dSMat Martineau 		break;
2691608bcc6dSMat Martineau 	case L2CAP_EV_LOCAL_BUSY_CLEAR:
2692608bcc6dSMat Martineau 		BT_DBG("Exit LOCAL_BUSY");
2693608bcc6dSMat Martineau 		clear_bit(CONN_LOCAL_BUSY, &chan->conn_state);
2694608bcc6dSMat Martineau 
2695608bcc6dSMat Martineau 		if (test_bit(CONN_RNR_SENT, &chan->conn_state)) {
2696608bcc6dSMat Martineau 			struct l2cap_ctrl local_control;
2697608bcc6dSMat Martineau 
2698608bcc6dSMat Martineau 			memset(&local_control, 0, sizeof(local_control));
2699608bcc6dSMat Martineau 			local_control.sframe = 1;
2700608bcc6dSMat Martineau 			local_control.super = L2CAP_SUPER_RR;
2701608bcc6dSMat Martineau 			local_control.poll = 1;
2702608bcc6dSMat Martineau 			local_control.reqseq = chan->buffer_seq;
2703a67d7f6fSMat Martineau 			l2cap_send_sframe(chan, &local_control);
2704608bcc6dSMat Martineau 
2705608bcc6dSMat Martineau 			chan->retry_count = 1;
2706608bcc6dSMat Martineau 			__set_monitor_timer(chan);
2707608bcc6dSMat Martineau 			chan->tx_state = L2CAP_TX_STATE_WAIT_F;
2708608bcc6dSMat Martineau 		}
2709608bcc6dSMat Martineau 		break;
2710608bcc6dSMat Martineau 	case L2CAP_EV_RECV_REQSEQ_AND_FBIT:
2711608bcc6dSMat Martineau 		l2cap_process_reqseq(chan, control->reqseq);
2712608bcc6dSMat Martineau 		break;
2713608bcc6dSMat Martineau 	case L2CAP_EV_EXPLICIT_POLL:
2714608bcc6dSMat Martineau 		l2cap_send_rr_or_rnr(chan, 1);
2715608bcc6dSMat Martineau 		chan->retry_count = 1;
2716608bcc6dSMat Martineau 		__set_monitor_timer(chan);
2717608bcc6dSMat Martineau 		__clear_ack_timer(chan);
2718608bcc6dSMat Martineau 		chan->tx_state = L2CAP_TX_STATE_WAIT_F;
2719608bcc6dSMat Martineau 		break;
2720608bcc6dSMat Martineau 	case L2CAP_EV_RETRANS_TO:
2721608bcc6dSMat Martineau 		l2cap_send_rr_or_rnr(chan, 1);
2722608bcc6dSMat Martineau 		chan->retry_count = 1;
2723608bcc6dSMat Martineau 		__set_monitor_timer(chan);
2724608bcc6dSMat Martineau 		chan->tx_state = L2CAP_TX_STATE_WAIT_F;
2725608bcc6dSMat Martineau 		break;
2726608bcc6dSMat Martineau 	case L2CAP_EV_RECV_FBIT:
2727608bcc6dSMat Martineau 		/* Nothing to process */
2728608bcc6dSMat Martineau 		break;
2729608bcc6dSMat Martineau 	default:
2730608bcc6dSMat Martineau 		break;
2731608bcc6dSMat Martineau 	}
2732608bcc6dSMat Martineau }
2733608bcc6dSMat Martineau 
2734d660366dSGustavo Padovan static void l2cap_tx_state_wait_f(struct l2cap_chan *chan,
2735608bcc6dSMat Martineau 				  struct l2cap_ctrl *control,
2736608bcc6dSMat Martineau 				  struct sk_buff_head *skbs, u8 event)
2737608bcc6dSMat Martineau {
2738608bcc6dSMat Martineau 	BT_DBG("chan %p, control %p, skbs %p, event %d", chan, control, skbs,
2739608bcc6dSMat Martineau 	       event);
2740608bcc6dSMat Martineau 
2741608bcc6dSMat Martineau 	switch (event) {
2742608bcc6dSMat Martineau 	case L2CAP_EV_DATA_REQUEST:
2743608bcc6dSMat Martineau 		if (chan->tx_send_head == NULL)
2744608bcc6dSMat Martineau 			chan->tx_send_head = skb_peek(skbs);
2745608bcc6dSMat Martineau 		/* Queue data, but don't send. */
2746608bcc6dSMat Martineau 		skb_queue_splice_tail_init(skbs, &chan->tx_q);
2747608bcc6dSMat Martineau 		break;
2748608bcc6dSMat Martineau 	case L2CAP_EV_LOCAL_BUSY_DETECTED:
2749608bcc6dSMat Martineau 		BT_DBG("Enter LOCAL_BUSY");
2750608bcc6dSMat Martineau 		set_bit(CONN_LOCAL_BUSY, &chan->conn_state);
2751608bcc6dSMat Martineau 
2752608bcc6dSMat Martineau 		if (chan->rx_state == L2CAP_RX_STATE_SREJ_SENT) {
2753608bcc6dSMat Martineau 			/* The SREJ_SENT state must be aborted if we are to
2754608bcc6dSMat Martineau 			 * enter the LOCAL_BUSY state.
2755608bcc6dSMat Martineau 			 */
2756608bcc6dSMat Martineau 			l2cap_abort_rx_srej_sent(chan);
2757608bcc6dSMat Martineau 		}
2758608bcc6dSMat Martineau 
2759608bcc6dSMat Martineau 		l2cap_send_ack(chan);
2760608bcc6dSMat Martineau 
2761608bcc6dSMat Martineau 		break;
2762608bcc6dSMat Martineau 	case L2CAP_EV_LOCAL_BUSY_CLEAR:
2763608bcc6dSMat Martineau 		BT_DBG("Exit LOCAL_BUSY");
2764608bcc6dSMat Martineau 		clear_bit(CONN_LOCAL_BUSY, &chan->conn_state);
2765608bcc6dSMat Martineau 
2766608bcc6dSMat Martineau 		if (test_bit(CONN_RNR_SENT, &chan->conn_state)) {
2767608bcc6dSMat Martineau 			struct l2cap_ctrl local_control;
2768608bcc6dSMat Martineau 			memset(&local_control, 0, sizeof(local_control));
2769608bcc6dSMat Martineau 			local_control.sframe = 1;
2770608bcc6dSMat Martineau 			local_control.super = L2CAP_SUPER_RR;
2771608bcc6dSMat Martineau 			local_control.poll = 1;
2772608bcc6dSMat Martineau 			local_control.reqseq = chan->buffer_seq;
2773a67d7f6fSMat Martineau 			l2cap_send_sframe(chan, &local_control);
2774608bcc6dSMat Martineau 
2775608bcc6dSMat Martineau 			chan->retry_count = 1;
2776608bcc6dSMat Martineau 			__set_monitor_timer(chan);
2777608bcc6dSMat Martineau 			chan->tx_state = L2CAP_TX_STATE_WAIT_F;
2778608bcc6dSMat Martineau 		}
2779608bcc6dSMat Martineau 		break;
2780608bcc6dSMat Martineau 	case L2CAP_EV_RECV_REQSEQ_AND_FBIT:
2781608bcc6dSMat Martineau 		l2cap_process_reqseq(chan, control->reqseq);
2782608bcc6dSMat Martineau 
2783608bcc6dSMat Martineau 		/* Fall through */
2784608bcc6dSMat Martineau 
2785608bcc6dSMat Martineau 	case L2CAP_EV_RECV_FBIT:
2786608bcc6dSMat Martineau 		if (control && control->final) {
2787608bcc6dSMat Martineau 			__clear_monitor_timer(chan);
2788608bcc6dSMat Martineau 			if (chan->unacked_frames > 0)
2789608bcc6dSMat Martineau 				__set_retrans_timer(chan);
2790608bcc6dSMat Martineau 			chan->retry_count = 0;
2791608bcc6dSMat Martineau 			chan->tx_state = L2CAP_TX_STATE_XMIT;
2792608bcc6dSMat Martineau 			BT_DBG("recv fbit tx_state 0x2.2%x", chan->tx_state);
2793608bcc6dSMat Martineau 		}
2794608bcc6dSMat Martineau 		break;
2795608bcc6dSMat Martineau 	case L2CAP_EV_EXPLICIT_POLL:
2796608bcc6dSMat Martineau 		/* Ignore */
2797608bcc6dSMat Martineau 		break;
2798608bcc6dSMat Martineau 	case L2CAP_EV_MONITOR_TO:
2799608bcc6dSMat Martineau 		if (chan->max_tx == 0 || chan->retry_count < chan->max_tx) {
2800608bcc6dSMat Martineau 			l2cap_send_rr_or_rnr(chan, 1);
2801608bcc6dSMat Martineau 			__set_monitor_timer(chan);
2802608bcc6dSMat Martineau 			chan->retry_count++;
2803608bcc6dSMat Martineau 		} else {
28045e4e3972SAndrei Emeltchenko 			l2cap_send_disconn_req(chan, ECONNABORTED);
2805608bcc6dSMat Martineau 		}
2806608bcc6dSMat Martineau 		break;
2807608bcc6dSMat Martineau 	default:
2808608bcc6dSMat Martineau 		break;
2809608bcc6dSMat Martineau 	}
2810608bcc6dSMat Martineau }
2811608bcc6dSMat Martineau 
2812d660366dSGustavo Padovan static void l2cap_tx(struct l2cap_chan *chan, struct l2cap_ctrl *control,
2813608bcc6dSMat Martineau 		     struct sk_buff_head *skbs, u8 event)
2814608bcc6dSMat Martineau {
2815608bcc6dSMat Martineau 	BT_DBG("chan %p, control %p, skbs %p, event %d, state %d",
2816608bcc6dSMat Martineau 	       chan, control, skbs, event, chan->tx_state);
2817608bcc6dSMat Martineau 
2818608bcc6dSMat Martineau 	switch (chan->tx_state) {
2819608bcc6dSMat Martineau 	case L2CAP_TX_STATE_XMIT:
2820d660366dSGustavo Padovan 		l2cap_tx_state_xmit(chan, control, skbs, event);
2821608bcc6dSMat Martineau 		break;
2822608bcc6dSMat Martineau 	case L2CAP_TX_STATE_WAIT_F:
2823d660366dSGustavo Padovan 		l2cap_tx_state_wait_f(chan, control, skbs, event);
2824608bcc6dSMat Martineau 		break;
2825608bcc6dSMat Martineau 	default:
2826608bcc6dSMat Martineau 		/* Ignore event */
2827608bcc6dSMat Martineau 		break;
2828608bcc6dSMat Martineau 	}
2829608bcc6dSMat Martineau }
2830608bcc6dSMat Martineau 
28314b51dae9SMat Martineau static void l2cap_pass_to_tx(struct l2cap_chan *chan,
28324b51dae9SMat Martineau 			     struct l2cap_ctrl *control)
28334b51dae9SMat Martineau {
28344b51dae9SMat Martineau 	BT_DBG("chan %p, control %p", chan, control);
2835401bb1f7SAndrei Emeltchenko 	l2cap_tx(chan, control, NULL, L2CAP_EV_RECV_REQSEQ_AND_FBIT);
28364b51dae9SMat Martineau }
28374b51dae9SMat Martineau 
2838f80842a8SMat Martineau static void l2cap_pass_to_tx_fbit(struct l2cap_chan *chan,
2839f80842a8SMat Martineau 				  struct l2cap_ctrl *control)
2840f80842a8SMat Martineau {
2841f80842a8SMat Martineau 	BT_DBG("chan %p, control %p", chan, control);
2842401bb1f7SAndrei Emeltchenko 	l2cap_tx(chan, control, NULL, L2CAP_EV_RECV_FBIT);
2843f80842a8SMat Martineau }
2844f80842a8SMat Martineau 
28450a708f8fSGustavo F. Padovan /* Copy frame to all raw sockets on that connection */
28460a708f8fSGustavo F. Padovan static void l2cap_raw_recv(struct l2cap_conn *conn, struct sk_buff *skb)
28470a708f8fSGustavo F. Padovan {
28480a708f8fSGustavo F. Padovan 	struct sk_buff *nskb;
284948454079SGustavo F. Padovan 	struct l2cap_chan *chan;
28500a708f8fSGustavo F. Padovan 
28510a708f8fSGustavo F. Padovan 	BT_DBG("conn %p", conn);
28520a708f8fSGustavo F. Padovan 
28533df91ea2SAndrei Emeltchenko 	mutex_lock(&conn->chan_lock);
28543d57dc68SGustavo F. Padovan 
28553df91ea2SAndrei Emeltchenko 	list_for_each_entry(chan, &conn->chan_l, list) {
285648454079SGustavo F. Padovan 		struct sock *sk = chan->sk;
2857715ec005SGustavo F. Padovan 		if (chan->chan_type != L2CAP_CHAN_RAW)
28580a708f8fSGustavo F. Padovan 			continue;
28590a708f8fSGustavo F. Padovan 
28600a708f8fSGustavo F. Padovan 		/* Don't send frame to the socket it came from */
28610a708f8fSGustavo F. Padovan 		if (skb->sk == sk)
28620a708f8fSGustavo F. Padovan 			continue;
28638bcde1f2SGustavo Padovan 		nskb = skb_clone(skb, GFP_KERNEL);
28640a708f8fSGustavo F. Padovan 		if (!nskb)
28650a708f8fSGustavo F. Padovan 			continue;
28660a708f8fSGustavo F. Padovan 
286780b98027SGustavo Padovan 		if (chan->ops->recv(chan, nskb))
28680a708f8fSGustavo F. Padovan 			kfree_skb(nskb);
28690a708f8fSGustavo F. Padovan 	}
28703d57dc68SGustavo F. Padovan 
28713df91ea2SAndrei Emeltchenko 	mutex_unlock(&conn->chan_lock);
28720a708f8fSGustavo F. Padovan }
28730a708f8fSGustavo F. Padovan 
28740a708f8fSGustavo F. Padovan /* ---- L2CAP signalling commands ---- */
2875b4400672SAndrei Emeltchenko static struct sk_buff *l2cap_build_cmd(struct l2cap_conn *conn, u8 code,
2876b4400672SAndrei Emeltchenko 				       u8 ident, u16 dlen, void *data)
28770a708f8fSGustavo F. Padovan {
28780a708f8fSGustavo F. Padovan 	struct sk_buff *skb, **frag;
28790a708f8fSGustavo F. Padovan 	struct l2cap_cmd_hdr *cmd;
28800a708f8fSGustavo F. Padovan 	struct l2cap_hdr *lh;
28810a708f8fSGustavo F. Padovan 	int len, count;
28820a708f8fSGustavo F. Padovan 
2883b4400672SAndrei Emeltchenko 	BT_DBG("conn %p, code 0x%2.2x, ident 0x%2.2x, len %u",
28840a708f8fSGustavo F. Padovan 	       conn, code, ident, dlen);
28850a708f8fSGustavo F. Padovan 
2886300b962eSAnderson Lizardo 	if (conn->mtu < L2CAP_HDR_SIZE + L2CAP_CMD_HDR_SIZE)
2887300b962eSAnderson Lizardo 		return NULL;
2888300b962eSAnderson Lizardo 
28890a708f8fSGustavo F. Padovan 	len = L2CAP_HDR_SIZE + L2CAP_CMD_HDR_SIZE + dlen;
28900a708f8fSGustavo F. Padovan 	count = min_t(unsigned int, conn->mtu, len);
28910a708f8fSGustavo F. Padovan 
28928bcde1f2SGustavo Padovan 	skb = bt_skb_alloc(count, GFP_KERNEL);
28930a708f8fSGustavo F. Padovan 	if (!skb)
28940a708f8fSGustavo F. Padovan 		return NULL;
28950a708f8fSGustavo F. Padovan 
28960a708f8fSGustavo F. Padovan 	lh = (struct l2cap_hdr *) skb_put(skb, L2CAP_HDR_SIZE);
28970a708f8fSGustavo F. Padovan 	lh->len = cpu_to_le16(L2CAP_CMD_HDR_SIZE + dlen);
28983300d9a9SClaudio Takahasi 
28993300d9a9SClaudio Takahasi 	if (conn->hcon->type == LE_LINK)
2900ac73498cSAndrei Emeltchenko 		lh->cid = __constant_cpu_to_le16(L2CAP_CID_LE_SIGNALING);
29013300d9a9SClaudio Takahasi 	else
2902ac73498cSAndrei Emeltchenko 		lh->cid = __constant_cpu_to_le16(L2CAP_CID_SIGNALING);
29030a708f8fSGustavo F. Padovan 
29040a708f8fSGustavo F. Padovan 	cmd = (struct l2cap_cmd_hdr *) skb_put(skb, L2CAP_CMD_HDR_SIZE);
29050a708f8fSGustavo F. Padovan 	cmd->code  = code;
29060a708f8fSGustavo F. Padovan 	cmd->ident = ident;
29070a708f8fSGustavo F. Padovan 	cmd->len   = cpu_to_le16(dlen);
29080a708f8fSGustavo F. Padovan 
29090a708f8fSGustavo F. Padovan 	if (dlen) {
29100a708f8fSGustavo F. Padovan 		count -= L2CAP_HDR_SIZE + L2CAP_CMD_HDR_SIZE;
29110a708f8fSGustavo F. Padovan 		memcpy(skb_put(skb, count), data, count);
29120a708f8fSGustavo F. Padovan 		data += count;
29130a708f8fSGustavo F. Padovan 	}
29140a708f8fSGustavo F. Padovan 
29150a708f8fSGustavo F. Padovan 	len -= skb->len;
29160a708f8fSGustavo F. Padovan 
29170a708f8fSGustavo F. Padovan 	/* Continuation fragments (no L2CAP header) */
29180a708f8fSGustavo F. Padovan 	frag = &skb_shinfo(skb)->frag_list;
29190a708f8fSGustavo F. Padovan 	while (len) {
29200a708f8fSGustavo F. Padovan 		count = min_t(unsigned int, conn->mtu, len);
29210a708f8fSGustavo F. Padovan 
29228bcde1f2SGustavo Padovan 		*frag = bt_skb_alloc(count, GFP_KERNEL);
29230a708f8fSGustavo F. Padovan 		if (!*frag)
29240a708f8fSGustavo F. Padovan 			goto fail;
29250a708f8fSGustavo F. Padovan 
29260a708f8fSGustavo F. Padovan 		memcpy(skb_put(*frag, count), data, count);
29270a708f8fSGustavo F. Padovan 
29280a708f8fSGustavo F. Padovan 		len  -= count;
29290a708f8fSGustavo F. Padovan 		data += count;
29300a708f8fSGustavo F. Padovan 
29310a708f8fSGustavo F. Padovan 		frag = &(*frag)->next;
29320a708f8fSGustavo F. Padovan 	}
29330a708f8fSGustavo F. Padovan 
29340a708f8fSGustavo F. Padovan 	return skb;
29350a708f8fSGustavo F. Padovan 
29360a708f8fSGustavo F. Padovan fail:
29370a708f8fSGustavo F. Padovan 	kfree_skb(skb);
29380a708f8fSGustavo F. Padovan 	return NULL;
29390a708f8fSGustavo F. Padovan }
29400a708f8fSGustavo F. Padovan 
29412d792818SGustavo Padovan static inline int l2cap_get_conf_opt(void **ptr, int *type, int *olen,
29422d792818SGustavo Padovan 				     unsigned long *val)
29430a708f8fSGustavo F. Padovan {
29440a708f8fSGustavo F. Padovan 	struct l2cap_conf_opt *opt = *ptr;
29450a708f8fSGustavo F. Padovan 	int len;
29460a708f8fSGustavo F. Padovan 
29470a708f8fSGustavo F. Padovan 	len = L2CAP_CONF_OPT_SIZE + opt->len;
29480a708f8fSGustavo F. Padovan 	*ptr += len;
29490a708f8fSGustavo F. Padovan 
29500a708f8fSGustavo F. Padovan 	*type = opt->type;
29510a708f8fSGustavo F. Padovan 	*olen = opt->len;
29520a708f8fSGustavo F. Padovan 
29530a708f8fSGustavo F. Padovan 	switch (opt->len) {
29540a708f8fSGustavo F. Padovan 	case 1:
29550a708f8fSGustavo F. Padovan 		*val = *((u8 *) opt->val);
29560a708f8fSGustavo F. Padovan 		break;
29570a708f8fSGustavo F. Padovan 
29580a708f8fSGustavo F. Padovan 	case 2:
29590a708f8fSGustavo F. Padovan 		*val = get_unaligned_le16(opt->val);
29600a708f8fSGustavo F. Padovan 		break;
29610a708f8fSGustavo F. Padovan 
29620a708f8fSGustavo F. Padovan 	case 4:
29630a708f8fSGustavo F. Padovan 		*val = get_unaligned_le32(opt->val);
29640a708f8fSGustavo F. Padovan 		break;
29650a708f8fSGustavo F. Padovan 
29660a708f8fSGustavo F. Padovan 	default:
29670a708f8fSGustavo F. Padovan 		*val = (unsigned long) opt->val;
29680a708f8fSGustavo F. Padovan 		break;
29690a708f8fSGustavo F. Padovan 	}
29700a708f8fSGustavo F. Padovan 
2971b4400672SAndrei Emeltchenko 	BT_DBG("type 0x%2.2x len %u val 0x%lx", *type, opt->len, *val);
29720a708f8fSGustavo F. Padovan 	return len;
29730a708f8fSGustavo F. Padovan }
29740a708f8fSGustavo F. Padovan 
29750a708f8fSGustavo F. Padovan static void l2cap_add_conf_opt(void **ptr, u8 type, u8 len, unsigned long val)
29760a708f8fSGustavo F. Padovan {
29770a708f8fSGustavo F. Padovan 	struct l2cap_conf_opt *opt = *ptr;
29780a708f8fSGustavo F. Padovan 
2979b4400672SAndrei Emeltchenko 	BT_DBG("type 0x%2.2x len %u val 0x%lx", type, len, val);
29800a708f8fSGustavo F. Padovan 
29810a708f8fSGustavo F. Padovan 	opt->type = type;
29820a708f8fSGustavo F. Padovan 	opt->len  = len;
29830a708f8fSGustavo F. Padovan 
29840a708f8fSGustavo F. Padovan 	switch (len) {
29850a708f8fSGustavo F. Padovan 	case 1:
29860a708f8fSGustavo F. Padovan 		*((u8 *) opt->val)  = val;
29870a708f8fSGustavo F. Padovan 		break;
29880a708f8fSGustavo F. Padovan 
29890a708f8fSGustavo F. Padovan 	case 2:
29900a708f8fSGustavo F. Padovan 		put_unaligned_le16(val, opt->val);
29910a708f8fSGustavo F. Padovan 		break;
29920a708f8fSGustavo F. Padovan 
29930a708f8fSGustavo F. Padovan 	case 4:
29940a708f8fSGustavo F. Padovan 		put_unaligned_le32(val, opt->val);
29950a708f8fSGustavo F. Padovan 		break;
29960a708f8fSGustavo F. Padovan 
29970a708f8fSGustavo F. Padovan 	default:
29980a708f8fSGustavo F. Padovan 		memcpy(opt->val, (void *) val, len);
29990a708f8fSGustavo F. Padovan 		break;
30000a708f8fSGustavo F. Padovan 	}
30010a708f8fSGustavo F. Padovan 
30020a708f8fSGustavo F. Padovan 	*ptr += L2CAP_CONF_OPT_SIZE + len;
30030a708f8fSGustavo F. Padovan }
30040a708f8fSGustavo F. Padovan 
3005f89cef09SAndrei Emeltchenko static void l2cap_add_opt_efs(void **ptr, struct l2cap_chan *chan)
3006f89cef09SAndrei Emeltchenko {
3007f89cef09SAndrei Emeltchenko 	struct l2cap_conf_efs efs;
3008f89cef09SAndrei Emeltchenko 
3009f89cef09SAndrei Emeltchenko 	switch (chan->mode) {
3010f89cef09SAndrei Emeltchenko 	case L2CAP_MODE_ERTM:
3011f89cef09SAndrei Emeltchenko 		efs.id		= chan->local_id;
3012f89cef09SAndrei Emeltchenko 		efs.stype	= chan->local_stype;
3013f89cef09SAndrei Emeltchenko 		efs.msdu	= cpu_to_le16(chan->local_msdu);
3014f89cef09SAndrei Emeltchenko 		efs.sdu_itime	= cpu_to_le32(chan->local_sdu_itime);
3015ac73498cSAndrei Emeltchenko 		efs.acc_lat	= __constant_cpu_to_le32(L2CAP_DEFAULT_ACC_LAT);
30168936fa6dSAndrei Emeltchenko 		efs.flush_to	= __constant_cpu_to_le32(L2CAP_EFS_DEFAULT_FLUSH_TO);
3017f89cef09SAndrei Emeltchenko 		break;
3018f89cef09SAndrei Emeltchenko 
3019f89cef09SAndrei Emeltchenko 	case L2CAP_MODE_STREAMING:
3020f89cef09SAndrei Emeltchenko 		efs.id		= 1;
3021f89cef09SAndrei Emeltchenko 		efs.stype	= L2CAP_SERV_BESTEFFORT;
3022f89cef09SAndrei Emeltchenko 		efs.msdu	= cpu_to_le16(chan->local_msdu);
3023f89cef09SAndrei Emeltchenko 		efs.sdu_itime	= cpu_to_le32(chan->local_sdu_itime);
3024f89cef09SAndrei Emeltchenko 		efs.acc_lat	= 0;
3025f89cef09SAndrei Emeltchenko 		efs.flush_to	= 0;
3026f89cef09SAndrei Emeltchenko 		break;
3027f89cef09SAndrei Emeltchenko 
3028f89cef09SAndrei Emeltchenko 	default:
3029f89cef09SAndrei Emeltchenko 		return;
3030f89cef09SAndrei Emeltchenko 	}
3031f89cef09SAndrei Emeltchenko 
3032f89cef09SAndrei Emeltchenko 	l2cap_add_conf_opt(ptr, L2CAP_CONF_EFS, sizeof(efs),
3033f89cef09SAndrei Emeltchenko 			   (unsigned long) &efs);
3034f89cef09SAndrei Emeltchenko }
3035f89cef09SAndrei Emeltchenko 
3036721c4181SGustavo F. Padovan static void l2cap_ack_timeout(struct work_struct *work)
30370a708f8fSGustavo F. Padovan {
3038721c4181SGustavo F. Padovan 	struct l2cap_chan *chan = container_of(work, struct l2cap_chan,
3039721c4181SGustavo F. Padovan 					       ack_timer.work);
30400362520bSMat Martineau 	u16 frames_to_ack;
30410a708f8fSGustavo F. Padovan 
30422fb9b3d4SGustavo F. Padovan 	BT_DBG("chan %p", chan);
30432fb9b3d4SGustavo F. Padovan 
30446be36555SAndrei Emeltchenko 	l2cap_chan_lock(chan);
30456be36555SAndrei Emeltchenko 
30460362520bSMat Martineau 	frames_to_ack = __seq_offset(chan, chan->buffer_seq,
30470362520bSMat Martineau 				     chan->last_acked_seq);
30480362520bSMat Martineau 
30490362520bSMat Martineau 	if (frames_to_ack)
30500362520bSMat Martineau 		l2cap_send_rr_or_rnr(chan, 0);
30516be36555SAndrei Emeltchenko 
30526be36555SAndrei Emeltchenko 	l2cap_chan_unlock(chan);
305309bfb2eeSSzymon Janc 	l2cap_chan_put(chan);
30540a708f8fSGustavo F. Padovan }
30550a708f8fSGustavo F. Padovan 
3056466f8004SAndrei Emeltchenko int l2cap_ertm_init(struct l2cap_chan *chan)
30570a708f8fSGustavo F. Padovan {
30583c588192SMat Martineau 	int err;
30593c588192SMat Martineau 
3060105bdf9eSMat Martineau 	chan->next_tx_seq = 0;
3061105bdf9eSMat Martineau 	chan->expected_tx_seq = 0;
306242e5c802SGustavo F. Padovan 	chan->expected_ack_seq = 0;
30636a026610SGustavo F. Padovan 	chan->unacked_frames = 0;
306442e5c802SGustavo F. Padovan 	chan->buffer_seq = 0;
30656a026610SGustavo F. Padovan 	chan->frames_sent = 0;
3066105bdf9eSMat Martineau 	chan->last_acked_seq = 0;
3067105bdf9eSMat Martineau 	chan->sdu = NULL;
3068105bdf9eSMat Martineau 	chan->sdu_last_frag = NULL;
3069105bdf9eSMat Martineau 	chan->sdu_len = 0;
3070105bdf9eSMat Martineau 
3071d34c34fbSMat Martineau 	skb_queue_head_init(&chan->tx_q);
3072d34c34fbSMat Martineau 
30736ed971caSMarcel Holtmann 	chan->local_amp_id = AMP_ID_BREDR;
30746ed971caSMarcel Holtmann 	chan->move_id = AMP_ID_BREDR;
307508333283SMat Martineau 	chan->move_state = L2CAP_MOVE_STABLE;
307608333283SMat Martineau 	chan->move_role = L2CAP_MOVE_ROLE_NONE;
307708333283SMat Martineau 
3078105bdf9eSMat Martineau 	if (chan->mode != L2CAP_MODE_ERTM)
3079105bdf9eSMat Martineau 		return 0;
3080105bdf9eSMat Martineau 
3081105bdf9eSMat Martineau 	chan->rx_state = L2CAP_RX_STATE_RECV;
3082105bdf9eSMat Martineau 	chan->tx_state = L2CAP_TX_STATE_XMIT;
30830a708f8fSGustavo F. Padovan 
3084721c4181SGustavo F. Padovan 	INIT_DELAYED_WORK(&chan->retrans_timer, l2cap_retrans_timeout);
3085721c4181SGustavo F. Padovan 	INIT_DELAYED_WORK(&chan->monitor_timer, l2cap_monitor_timeout);
3086721c4181SGustavo F. Padovan 	INIT_DELAYED_WORK(&chan->ack_timer, l2cap_ack_timeout);
30870a708f8fSGustavo F. Padovan 
3088f1c6775bSGustavo F. Padovan 	skb_queue_head_init(&chan->srej_q);
30890a708f8fSGustavo F. Padovan 
30903c588192SMat Martineau 	err = l2cap_seq_list_init(&chan->srej_list, chan->tx_win);
30913c588192SMat Martineau 	if (err < 0)
30923c588192SMat Martineau 		return err;
30933c588192SMat Martineau 
30949dc9affcSMat Martineau 	err = l2cap_seq_list_init(&chan->retrans_list, chan->remote_tx_win);
30959dc9affcSMat Martineau 	if (err < 0)
30969dc9affcSMat Martineau 		l2cap_seq_list_free(&chan->srej_list);
30979dc9affcSMat Martineau 
30989dc9affcSMat Martineau 	return err;
30990a708f8fSGustavo F. Padovan }
31000a708f8fSGustavo F. Padovan 
31010a708f8fSGustavo F. Padovan static inline __u8 l2cap_select_mode(__u8 mode, __u16 remote_feat_mask)
31020a708f8fSGustavo F. Padovan {
31030a708f8fSGustavo F. Padovan 	switch (mode) {
31040a708f8fSGustavo F. Padovan 	case L2CAP_MODE_STREAMING:
31050a708f8fSGustavo F. Padovan 	case L2CAP_MODE_ERTM:
31060a708f8fSGustavo F. Padovan 		if (l2cap_mode_supported(mode, remote_feat_mask))
31070a708f8fSGustavo F. Padovan 			return mode;
31080a708f8fSGustavo F. Padovan 		/* fall through */
31090a708f8fSGustavo F. Padovan 	default:
31100a708f8fSGustavo F. Padovan 		return L2CAP_MODE_BASIC;
31110a708f8fSGustavo F. Padovan 	}
31120a708f8fSGustavo F. Padovan }
31130a708f8fSGustavo F. Padovan 
3114848566b3SMarcel Holtmann static inline bool __l2cap_ews_supported(struct l2cap_conn *conn)
31156327eb98SAndrei Emeltchenko {
3116848566b3SMarcel Holtmann 	return conn->hs_enabled && conn->feat_mask & L2CAP_FEAT_EXT_WINDOW;
31176327eb98SAndrei Emeltchenko }
31186327eb98SAndrei Emeltchenko 
3119848566b3SMarcel Holtmann static inline bool __l2cap_efs_supported(struct l2cap_conn *conn)
3120f89cef09SAndrei Emeltchenko {
3121848566b3SMarcel Holtmann 	return conn->hs_enabled && conn->feat_mask & L2CAP_FEAT_EXT_FLOW;
3122f89cef09SAndrei Emeltchenko }
3123f89cef09SAndrei Emeltchenko 
312436c86c85SMat Martineau static void __l2cap_set_ertm_timeouts(struct l2cap_chan *chan,
312536c86c85SMat Martineau 				      struct l2cap_conf_rfc *rfc)
312636c86c85SMat Martineau {
31276ed971caSMarcel Holtmann 	if (chan->local_amp_id != AMP_ID_BREDR && chan->hs_hcon) {
312836c86c85SMat Martineau 		u64 ertm_to = chan->hs_hcon->hdev->amp_be_flush_to;
312936c86c85SMat Martineau 
313036c86c85SMat Martineau 		/* Class 1 devices have must have ERTM timeouts
313136c86c85SMat Martineau 		 * exceeding the Link Supervision Timeout.  The
313236c86c85SMat Martineau 		 * default Link Supervision Timeout for AMP
313336c86c85SMat Martineau 		 * controllers is 10 seconds.
313436c86c85SMat Martineau 		 *
313536c86c85SMat Martineau 		 * Class 1 devices use 0xffffffff for their
313636c86c85SMat Martineau 		 * best-effort flush timeout, so the clamping logic
313736c86c85SMat Martineau 		 * will result in a timeout that meets the above
313836c86c85SMat Martineau 		 * requirement.  ERTM timeouts are 16-bit values, so
313936c86c85SMat Martineau 		 * the maximum timeout is 65.535 seconds.
314036c86c85SMat Martineau 		 */
314136c86c85SMat Martineau 
314236c86c85SMat Martineau 		/* Convert timeout to milliseconds and round */
314336c86c85SMat Martineau 		ertm_to = DIV_ROUND_UP_ULL(ertm_to, 1000);
314436c86c85SMat Martineau 
314536c86c85SMat Martineau 		/* This is the recommended formula for class 2 devices
314636c86c85SMat Martineau 		 * that start ERTM timers when packets are sent to the
314736c86c85SMat Martineau 		 * controller.
314836c86c85SMat Martineau 		 */
314936c86c85SMat Martineau 		ertm_to = 3 * ertm_to + 500;
315036c86c85SMat Martineau 
315136c86c85SMat Martineau 		if (ertm_to > 0xffff)
315236c86c85SMat Martineau 			ertm_to = 0xffff;
315336c86c85SMat Martineau 
315436c86c85SMat Martineau 		rfc->retrans_timeout = cpu_to_le16((u16) ertm_to);
315536c86c85SMat Martineau 		rfc->monitor_timeout = rfc->retrans_timeout;
315636c86c85SMat Martineau 	} else {
315736c86c85SMat Martineau 		rfc->retrans_timeout = __constant_cpu_to_le16(L2CAP_DEFAULT_RETRANS_TO);
315836c86c85SMat Martineau 		rfc->monitor_timeout = __constant_cpu_to_le16(L2CAP_DEFAULT_MONITOR_TO);
315936c86c85SMat Martineau 	}
316036c86c85SMat Martineau }
316136c86c85SMat Martineau 
31626327eb98SAndrei Emeltchenko static inline void l2cap_txwin_setup(struct l2cap_chan *chan)
31636327eb98SAndrei Emeltchenko {
31646327eb98SAndrei Emeltchenko 	if (chan->tx_win > L2CAP_DEFAULT_TX_WINDOW &&
3165848566b3SMarcel Holtmann 	    __l2cap_ews_supported(chan->conn)) {
31666327eb98SAndrei Emeltchenko 		/* use extended control field */
31676327eb98SAndrei Emeltchenko 		set_bit(FLAG_EXT_CTRL, &chan->flags);
3168836be934SAndrei Emeltchenko 		chan->tx_win_max = L2CAP_DEFAULT_EXT_WINDOW;
3169836be934SAndrei Emeltchenko 	} else {
31706327eb98SAndrei Emeltchenko 		chan->tx_win = min_t(u16, chan->tx_win,
31716327eb98SAndrei Emeltchenko 				     L2CAP_DEFAULT_TX_WINDOW);
3172836be934SAndrei Emeltchenko 		chan->tx_win_max = L2CAP_DEFAULT_TX_WINDOW;
3173836be934SAndrei Emeltchenko 	}
3174c20f8e35SMat Martineau 	chan->ack_win = chan->tx_win;
31756327eb98SAndrei Emeltchenko }
31766327eb98SAndrei Emeltchenko 
3177710f9b0aSGustavo F. Padovan static int l2cap_build_conf_req(struct l2cap_chan *chan, void *data)
31780a708f8fSGustavo F. Padovan {
31790a708f8fSGustavo F. Padovan 	struct l2cap_conf_req *req = data;
31800c1bc5c6SGustavo F. Padovan 	struct l2cap_conf_rfc rfc = { .mode = chan->mode };
31810a708f8fSGustavo F. Padovan 	void *ptr = req->data;
3182c8f79162SAndrei Emeltchenko 	u16 size;
31830a708f8fSGustavo F. Padovan 
318449208c9cSGustavo F. Padovan 	BT_DBG("chan %p", chan);
31850a708f8fSGustavo F. Padovan 
318673ffa904SGustavo F. Padovan 	if (chan->num_conf_req || chan->num_conf_rsp)
31870a708f8fSGustavo F. Padovan 		goto done;
31880a708f8fSGustavo F. Padovan 
31890c1bc5c6SGustavo F. Padovan 	switch (chan->mode) {
31900a708f8fSGustavo F. Padovan 	case L2CAP_MODE_STREAMING:
31910a708f8fSGustavo F. Padovan 	case L2CAP_MODE_ERTM:
3192c1360a1cSGustavo F. Padovan 		if (test_bit(CONF_STATE2_DEVICE, &chan->conf_state))
31930a708f8fSGustavo F. Padovan 			break;
31940a708f8fSGustavo F. Padovan 
3195848566b3SMarcel Holtmann 		if (__l2cap_efs_supported(chan->conn))
3196f89cef09SAndrei Emeltchenko 			set_bit(FLAG_EFS_ENABLE, &chan->flags);
3197f89cef09SAndrei Emeltchenko 
31980a708f8fSGustavo F. Padovan 		/* fall through */
31990a708f8fSGustavo F. Padovan 	default:
32008c1d787bSGustavo F. Padovan 		chan->mode = l2cap_select_mode(rfc.mode, chan->conn->feat_mask);
32010a708f8fSGustavo F. Padovan 		break;
32020a708f8fSGustavo F. Padovan 	}
32030a708f8fSGustavo F. Padovan 
32040a708f8fSGustavo F. Padovan done:
32050c1bc5c6SGustavo F. Padovan 	if (chan->imtu != L2CAP_DEFAULT_MTU)
32060c1bc5c6SGustavo F. Padovan 		l2cap_add_conf_opt(&ptr, L2CAP_CONF_MTU, 2, chan->imtu);
32070a708f8fSGustavo F. Padovan 
32080c1bc5c6SGustavo F. Padovan 	switch (chan->mode) {
32090a708f8fSGustavo F. Padovan 	case L2CAP_MODE_BASIC:
32108c1d787bSGustavo F. Padovan 		if (!(chan->conn->feat_mask & L2CAP_FEAT_ERTM) &&
32118c1d787bSGustavo F. Padovan 		    !(chan->conn->feat_mask & L2CAP_FEAT_STREAMING))
32120a708f8fSGustavo F. Padovan 			break;
32130a708f8fSGustavo F. Padovan 
32140a708f8fSGustavo F. Padovan 		rfc.mode            = L2CAP_MODE_BASIC;
32150a708f8fSGustavo F. Padovan 		rfc.txwin_size      = 0;
32160a708f8fSGustavo F. Padovan 		rfc.max_transmit    = 0;
32170a708f8fSGustavo F. Padovan 		rfc.retrans_timeout = 0;
32180a708f8fSGustavo F. Padovan 		rfc.monitor_timeout = 0;
32190a708f8fSGustavo F. Padovan 		rfc.max_pdu_size    = 0;
32200a708f8fSGustavo F. Padovan 
32210a708f8fSGustavo F. Padovan 		l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC, sizeof(rfc),
32220a708f8fSGustavo F. Padovan 				   (unsigned long) &rfc);
32230a708f8fSGustavo F. Padovan 		break;
32240a708f8fSGustavo F. Padovan 
32250a708f8fSGustavo F. Padovan 	case L2CAP_MODE_ERTM:
32260a708f8fSGustavo F. Padovan 		rfc.mode            = L2CAP_MODE_ERTM;
322747d1ec61SGustavo F. Padovan 		rfc.max_transmit    = chan->max_tx;
322836c86c85SMat Martineau 
322936c86c85SMat Martineau 		__l2cap_set_ertm_timeouts(chan, &rfc);
3230c8f79162SAndrei Emeltchenko 
3231c8f79162SAndrei Emeltchenko 		size = min_t(u16, L2CAP_DEFAULT_MAX_PDU_SIZE, chan->conn->mtu -
32322d792818SGustavo Padovan 			     L2CAP_EXT_HDR_SIZE - L2CAP_SDULEN_SIZE -
3233c8f79162SAndrei Emeltchenko 			     L2CAP_FCS_SIZE);
3234c8f79162SAndrei Emeltchenko 		rfc.max_pdu_size = cpu_to_le16(size);
32350a708f8fSGustavo F. Padovan 
32366327eb98SAndrei Emeltchenko 		l2cap_txwin_setup(chan);
32376327eb98SAndrei Emeltchenko 
32386327eb98SAndrei Emeltchenko 		rfc.txwin_size = min_t(u16, chan->tx_win,
32396327eb98SAndrei Emeltchenko 				       L2CAP_DEFAULT_TX_WINDOW);
32400a708f8fSGustavo F. Padovan 
32410a708f8fSGustavo F. Padovan 		l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC, sizeof(rfc),
32420a708f8fSGustavo F. Padovan 				   (unsigned long) &rfc);
32430a708f8fSGustavo F. Padovan 
3244f89cef09SAndrei Emeltchenko 		if (test_bit(FLAG_EFS_ENABLE, &chan->flags))
3245f89cef09SAndrei Emeltchenko 			l2cap_add_opt_efs(&ptr, chan);
3246f89cef09SAndrei Emeltchenko 
32476327eb98SAndrei Emeltchenko 		if (test_bit(FLAG_EXT_CTRL, &chan->flags))
32486327eb98SAndrei Emeltchenko 			l2cap_add_conf_opt(&ptr, L2CAP_CONF_EWS, 2,
32496327eb98SAndrei Emeltchenko 					   chan->tx_win);
325060918918SAndrei Emeltchenko 
325160918918SAndrei Emeltchenko 		if (chan->conn->feat_mask & L2CAP_FEAT_FCS)
325260918918SAndrei Emeltchenko 			if (chan->fcs == L2CAP_FCS_NONE ||
3253f2592d3eSAndrei Emeltchenko 			    test_bit(CONF_RECV_NO_FCS, &chan->conf_state)) {
325460918918SAndrei Emeltchenko 				chan->fcs = L2CAP_FCS_NONE;
325560918918SAndrei Emeltchenko 				l2cap_add_conf_opt(&ptr, L2CAP_CONF_FCS, 1,
325660918918SAndrei Emeltchenko 						   chan->fcs);
325760918918SAndrei Emeltchenko 			}
32580a708f8fSGustavo F. Padovan 		break;
32590a708f8fSGustavo F. Padovan 
32600a708f8fSGustavo F. Padovan 	case L2CAP_MODE_STREAMING:
3261273759e2SMat Martineau 		l2cap_txwin_setup(chan);
32620a708f8fSGustavo F. Padovan 		rfc.mode            = L2CAP_MODE_STREAMING;
32630a708f8fSGustavo F. Padovan 		rfc.txwin_size      = 0;
32640a708f8fSGustavo F. Padovan 		rfc.max_transmit    = 0;
32650a708f8fSGustavo F. Padovan 		rfc.retrans_timeout = 0;
32660a708f8fSGustavo F. Padovan 		rfc.monitor_timeout = 0;
3267c8f79162SAndrei Emeltchenko 
3268c8f79162SAndrei Emeltchenko 		size = min_t(u16, L2CAP_DEFAULT_MAX_PDU_SIZE, chan->conn->mtu -
32692d792818SGustavo Padovan 			     L2CAP_EXT_HDR_SIZE - L2CAP_SDULEN_SIZE -
3270c8f79162SAndrei Emeltchenko 			     L2CAP_FCS_SIZE);
3271c8f79162SAndrei Emeltchenko 		rfc.max_pdu_size = cpu_to_le16(size);
32720a708f8fSGustavo F. Padovan 
32730a708f8fSGustavo F. Padovan 		l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC, sizeof(rfc),
32740a708f8fSGustavo F. Padovan 				   (unsigned long) &rfc);
32750a708f8fSGustavo F. Padovan 
3276f89cef09SAndrei Emeltchenko 		if (test_bit(FLAG_EFS_ENABLE, &chan->flags))
3277f89cef09SAndrei Emeltchenko 			l2cap_add_opt_efs(&ptr, chan);
3278f89cef09SAndrei Emeltchenko 
327960918918SAndrei Emeltchenko 		if (chan->conn->feat_mask & L2CAP_FEAT_FCS)
328047d1ec61SGustavo F. Padovan 			if (chan->fcs == L2CAP_FCS_NONE ||
3281f2592d3eSAndrei Emeltchenko 			    test_bit(CONF_RECV_NO_FCS, &chan->conf_state)) {
328247d1ec61SGustavo F. Padovan 				chan->fcs = L2CAP_FCS_NONE;
328360918918SAndrei Emeltchenko 				l2cap_add_conf_opt(&ptr, L2CAP_CONF_FCS, 1,
328460918918SAndrei Emeltchenko 						   chan->fcs);
32850a708f8fSGustavo F. Padovan 			}
32860a708f8fSGustavo F. Padovan 		break;
32870a708f8fSGustavo F. Padovan 	}
32880a708f8fSGustavo F. Padovan 
3289fe4128e0SGustavo F. Padovan 	req->dcid  = cpu_to_le16(chan->dcid);
329059e54bd1SAndrei Emeltchenko 	req->flags = __constant_cpu_to_le16(0);
32910a708f8fSGustavo F. Padovan 
32920a708f8fSGustavo F. Padovan 	return ptr - data;
32930a708f8fSGustavo F. Padovan }
32940a708f8fSGustavo F. Padovan 
329573ffa904SGustavo F. Padovan static int l2cap_parse_conf_req(struct l2cap_chan *chan, void *data)
32960a708f8fSGustavo F. Padovan {
32970a708f8fSGustavo F. Padovan 	struct l2cap_conf_rsp *rsp = data;
32980a708f8fSGustavo F. Padovan 	void *ptr = rsp->data;
329973ffa904SGustavo F. Padovan 	void *req = chan->conf_req;
330073ffa904SGustavo F. Padovan 	int len = chan->conf_len;
33010a708f8fSGustavo F. Padovan 	int type, hint, olen;
33020a708f8fSGustavo F. Padovan 	unsigned long val;
33030a708f8fSGustavo F. Padovan 	struct l2cap_conf_rfc rfc = { .mode = L2CAP_MODE_BASIC };
330442dceae2SAndrei Emeltchenko 	struct l2cap_conf_efs efs;
330542dceae2SAndrei Emeltchenko 	u8 remote_efs = 0;
33060a708f8fSGustavo F. Padovan 	u16 mtu = L2CAP_DEFAULT_MTU;
33070a708f8fSGustavo F. Padovan 	u16 result = L2CAP_CONF_SUCCESS;
3308c8f79162SAndrei Emeltchenko 	u16 size;
33090a708f8fSGustavo F. Padovan 
331073ffa904SGustavo F. Padovan 	BT_DBG("chan %p", chan);
33110a708f8fSGustavo F. Padovan 
33120a708f8fSGustavo F. Padovan 	while (len >= L2CAP_CONF_OPT_SIZE) {
33130a708f8fSGustavo F. Padovan 		len -= l2cap_get_conf_opt(&req, &type, &olen, &val);
33140a708f8fSGustavo F. Padovan 
33150a708f8fSGustavo F. Padovan 		hint  = type & L2CAP_CONF_HINT;
33160a708f8fSGustavo F. Padovan 		type &= L2CAP_CONF_MASK;
33170a708f8fSGustavo F. Padovan 
33180a708f8fSGustavo F. Padovan 		switch (type) {
33190a708f8fSGustavo F. Padovan 		case L2CAP_CONF_MTU:
33200a708f8fSGustavo F. Padovan 			mtu = val;
33210a708f8fSGustavo F. Padovan 			break;
33220a708f8fSGustavo F. Padovan 
33230a708f8fSGustavo F. Padovan 		case L2CAP_CONF_FLUSH_TO:
33240c1bc5c6SGustavo F. Padovan 			chan->flush_to = val;
33250a708f8fSGustavo F. Padovan 			break;
33260a708f8fSGustavo F. Padovan 
33270a708f8fSGustavo F. Padovan 		case L2CAP_CONF_QOS:
33280a708f8fSGustavo F. Padovan 			break;
33290a708f8fSGustavo F. Padovan 
33300a708f8fSGustavo F. Padovan 		case L2CAP_CONF_RFC:
33310a708f8fSGustavo F. Padovan 			if (olen == sizeof(rfc))
33320a708f8fSGustavo F. Padovan 				memcpy(&rfc, (void *) val, olen);
33330a708f8fSGustavo F. Padovan 			break;
33340a708f8fSGustavo F. Padovan 
33350a708f8fSGustavo F. Padovan 		case L2CAP_CONF_FCS:
33360a708f8fSGustavo F. Padovan 			if (val == L2CAP_FCS_NONE)
3337f2592d3eSAndrei Emeltchenko 				set_bit(CONF_RECV_NO_FCS, &chan->conf_state);
333842dceae2SAndrei Emeltchenko 			break;
33390a708f8fSGustavo F. Padovan 
334042dceae2SAndrei Emeltchenko 		case L2CAP_CONF_EFS:
334142dceae2SAndrei Emeltchenko 			remote_efs = 1;
334242dceae2SAndrei Emeltchenko 			if (olen == sizeof(efs))
334342dceae2SAndrei Emeltchenko 				memcpy(&efs, (void *) val, olen);
33440a708f8fSGustavo F. Padovan 			break;
33450a708f8fSGustavo F. Padovan 
33466327eb98SAndrei Emeltchenko 		case L2CAP_CONF_EWS:
3347848566b3SMarcel Holtmann 			if (!chan->conn->hs_enabled)
33486327eb98SAndrei Emeltchenko 				return -ECONNREFUSED;
33496327eb98SAndrei Emeltchenko 
33506327eb98SAndrei Emeltchenko 			set_bit(FLAG_EXT_CTRL, &chan->flags);
33516327eb98SAndrei Emeltchenko 			set_bit(CONF_EWS_RECV, &chan->conf_state);
3352836be934SAndrei Emeltchenko 			chan->tx_win_max = L2CAP_DEFAULT_EXT_WINDOW;
33536327eb98SAndrei Emeltchenko 			chan->remote_tx_win = val;
33540a708f8fSGustavo F. Padovan 			break;
33550a708f8fSGustavo F. Padovan 
33560a708f8fSGustavo F. Padovan 		default:
33570a708f8fSGustavo F. Padovan 			if (hint)
33580a708f8fSGustavo F. Padovan 				break;
33590a708f8fSGustavo F. Padovan 
33600a708f8fSGustavo F. Padovan 			result = L2CAP_CONF_UNKNOWN;
33610a708f8fSGustavo F. Padovan 			*((u8 *) ptr++) = type;
33620a708f8fSGustavo F. Padovan 			break;
33630a708f8fSGustavo F. Padovan 		}
33640a708f8fSGustavo F. Padovan 	}
33650a708f8fSGustavo F. Padovan 
336673ffa904SGustavo F. Padovan 	if (chan->num_conf_rsp || chan->num_conf_req > 1)
33670a708f8fSGustavo F. Padovan 		goto done;
33680a708f8fSGustavo F. Padovan 
33690c1bc5c6SGustavo F. Padovan 	switch (chan->mode) {
33700a708f8fSGustavo F. Padovan 	case L2CAP_MODE_STREAMING:
33710a708f8fSGustavo F. Padovan 	case L2CAP_MODE_ERTM:
3372c1360a1cSGustavo F. Padovan 		if (!test_bit(CONF_STATE2_DEVICE, &chan->conf_state)) {
33730c1bc5c6SGustavo F. Padovan 			chan->mode = l2cap_select_mode(rfc.mode,
33748c1d787bSGustavo F. Padovan 						       chan->conn->feat_mask);
33750a708f8fSGustavo F. Padovan 			break;
33760a708f8fSGustavo F. Padovan 		}
33770a708f8fSGustavo F. Padovan 
337842dceae2SAndrei Emeltchenko 		if (remote_efs) {
3379848566b3SMarcel Holtmann 			if (__l2cap_efs_supported(chan->conn))
338042dceae2SAndrei Emeltchenko 				set_bit(FLAG_EFS_ENABLE, &chan->flags);
338142dceae2SAndrei Emeltchenko 			else
338242dceae2SAndrei Emeltchenko 				return -ECONNREFUSED;
338342dceae2SAndrei Emeltchenko 		}
338442dceae2SAndrei Emeltchenko 
33850c1bc5c6SGustavo F. Padovan 		if (chan->mode != rfc.mode)
33860a708f8fSGustavo F. Padovan 			return -ECONNREFUSED;
33870a708f8fSGustavo F. Padovan 
33880a708f8fSGustavo F. Padovan 		break;
33890a708f8fSGustavo F. Padovan 	}
33900a708f8fSGustavo F. Padovan 
33910a708f8fSGustavo F. Padovan done:
33920c1bc5c6SGustavo F. Padovan 	if (chan->mode != rfc.mode) {
33930a708f8fSGustavo F. Padovan 		result = L2CAP_CONF_UNACCEPT;
33940c1bc5c6SGustavo F. Padovan 		rfc.mode = chan->mode;
33950a708f8fSGustavo F. Padovan 
339673ffa904SGustavo F. Padovan 		if (chan->num_conf_rsp == 1)
33970a708f8fSGustavo F. Padovan 			return -ECONNREFUSED;
33980a708f8fSGustavo F. Padovan 
33992d792818SGustavo Padovan 		l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC, sizeof(rfc),
34002d792818SGustavo Padovan 				   (unsigned long) &rfc);
34010a708f8fSGustavo F. Padovan 	}
34020a708f8fSGustavo F. Padovan 
34030a708f8fSGustavo F. Padovan 	if (result == L2CAP_CONF_SUCCESS) {
34040a708f8fSGustavo F. Padovan 		/* Configure output options and let the other side know
34050a708f8fSGustavo F. Padovan 		 * which ones we don't like. */
34060a708f8fSGustavo F. Padovan 
34070a708f8fSGustavo F. Padovan 		if (mtu < L2CAP_DEFAULT_MIN_MTU)
34080a708f8fSGustavo F. Padovan 			result = L2CAP_CONF_UNACCEPT;
34090a708f8fSGustavo F. Padovan 		else {
34100c1bc5c6SGustavo F. Padovan 			chan->omtu = mtu;
3411c1360a1cSGustavo F. Padovan 			set_bit(CONF_MTU_DONE, &chan->conf_state);
34120a708f8fSGustavo F. Padovan 		}
34130c1bc5c6SGustavo F. Padovan 		l2cap_add_conf_opt(&ptr, L2CAP_CONF_MTU, 2, chan->omtu);
34140a708f8fSGustavo F. Padovan 
341542dceae2SAndrei Emeltchenko 		if (remote_efs) {
341642dceae2SAndrei Emeltchenko 			if (chan->local_stype != L2CAP_SERV_NOTRAFIC &&
341742dceae2SAndrei Emeltchenko 			    efs.stype != L2CAP_SERV_NOTRAFIC &&
341842dceae2SAndrei Emeltchenko 			    efs.stype != chan->local_stype) {
341942dceae2SAndrei Emeltchenko 
342042dceae2SAndrei Emeltchenko 				result = L2CAP_CONF_UNACCEPT;
342142dceae2SAndrei Emeltchenko 
342242dceae2SAndrei Emeltchenko 				if (chan->num_conf_req >= 1)
342342dceae2SAndrei Emeltchenko 					return -ECONNREFUSED;
342442dceae2SAndrei Emeltchenko 
342542dceae2SAndrei Emeltchenko 				l2cap_add_conf_opt(&ptr, L2CAP_CONF_EFS,
342642dceae2SAndrei Emeltchenko 						   sizeof(efs),
342742dceae2SAndrei Emeltchenko 						   (unsigned long) &efs);
34280e8b207eSAndrei Emeltchenko 			} else {
34293e6b3b95SGustavo F. Padovan 				/* Send PENDING Conf Rsp */
34300e8b207eSAndrei Emeltchenko 				result = L2CAP_CONF_PENDING;
34310e8b207eSAndrei Emeltchenko 				set_bit(CONF_LOC_CONF_PEND, &chan->conf_state);
343242dceae2SAndrei Emeltchenko 			}
343342dceae2SAndrei Emeltchenko 		}
343442dceae2SAndrei Emeltchenko 
34350a708f8fSGustavo F. Padovan 		switch (rfc.mode) {
34360a708f8fSGustavo F. Padovan 		case L2CAP_MODE_BASIC:
343747d1ec61SGustavo F. Padovan 			chan->fcs = L2CAP_FCS_NONE;
3438c1360a1cSGustavo F. Padovan 			set_bit(CONF_MODE_DONE, &chan->conf_state);
34390a708f8fSGustavo F. Padovan 			break;
34400a708f8fSGustavo F. Padovan 
34410a708f8fSGustavo F. Padovan 		case L2CAP_MODE_ERTM:
34426327eb98SAndrei Emeltchenko 			if (!test_bit(CONF_EWS_RECV, &chan->conf_state))
34432c03a7a4SGustavo F. Padovan 				chan->remote_tx_win = rfc.txwin_size;
34446327eb98SAndrei Emeltchenko 			else
34456327eb98SAndrei Emeltchenko 				rfc.txwin_size = L2CAP_DEFAULT_TX_WINDOW;
34466327eb98SAndrei Emeltchenko 
34472c03a7a4SGustavo F. Padovan 			chan->remote_max_tx = rfc.max_transmit;
34480a708f8fSGustavo F. Padovan 
3449c8f79162SAndrei Emeltchenko 			size = min_t(u16, le16_to_cpu(rfc.max_pdu_size),
34502d792818SGustavo Padovan 				     chan->conn->mtu - L2CAP_EXT_HDR_SIZE -
34512d792818SGustavo Padovan 				     L2CAP_SDULEN_SIZE - L2CAP_FCS_SIZE);
3452c8f79162SAndrei Emeltchenko 			rfc.max_pdu_size = cpu_to_le16(size);
3453c8f79162SAndrei Emeltchenko 			chan->remote_mps = size;
34540a708f8fSGustavo F. Padovan 
345536c86c85SMat Martineau 			__l2cap_set_ertm_timeouts(chan, &rfc);
34560a708f8fSGustavo F. Padovan 
3457c1360a1cSGustavo F. Padovan 			set_bit(CONF_MODE_DONE, &chan->conf_state);
34580a708f8fSGustavo F. Padovan 
34590a708f8fSGustavo F. Padovan 			l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC,
34600a708f8fSGustavo F. Padovan 					   sizeof(rfc), (unsigned long) &rfc);
34610a708f8fSGustavo F. Padovan 
346242dceae2SAndrei Emeltchenko 			if (test_bit(FLAG_EFS_ENABLE, &chan->flags)) {
346342dceae2SAndrei Emeltchenko 				chan->remote_id = efs.id;
346442dceae2SAndrei Emeltchenko 				chan->remote_stype = efs.stype;
346542dceae2SAndrei Emeltchenko 				chan->remote_msdu = le16_to_cpu(efs.msdu);
346642dceae2SAndrei Emeltchenko 				chan->remote_flush_to =
346742dceae2SAndrei Emeltchenko 					le32_to_cpu(efs.flush_to);
346842dceae2SAndrei Emeltchenko 				chan->remote_acc_lat =
346942dceae2SAndrei Emeltchenko 					le32_to_cpu(efs.acc_lat);
347042dceae2SAndrei Emeltchenko 				chan->remote_sdu_itime =
347142dceae2SAndrei Emeltchenko 					le32_to_cpu(efs.sdu_itime);
347242dceae2SAndrei Emeltchenko 				l2cap_add_conf_opt(&ptr, L2CAP_CONF_EFS,
34732d792818SGustavo Padovan 						   sizeof(efs),
34742d792818SGustavo Padovan 						   (unsigned long) &efs);
347542dceae2SAndrei Emeltchenko 			}
34760a708f8fSGustavo F. Padovan 			break;
34770a708f8fSGustavo F. Padovan 
34780a708f8fSGustavo F. Padovan 		case L2CAP_MODE_STREAMING:
3479c8f79162SAndrei Emeltchenko 			size = min_t(u16, le16_to_cpu(rfc.max_pdu_size),
34802d792818SGustavo Padovan 				     chan->conn->mtu - L2CAP_EXT_HDR_SIZE -
34812d792818SGustavo Padovan 				     L2CAP_SDULEN_SIZE - L2CAP_FCS_SIZE);
3482c8f79162SAndrei Emeltchenko 			rfc.max_pdu_size = cpu_to_le16(size);
3483c8f79162SAndrei Emeltchenko 			chan->remote_mps = size;
34840a708f8fSGustavo F. Padovan 
3485c1360a1cSGustavo F. Padovan 			set_bit(CONF_MODE_DONE, &chan->conf_state);
34860a708f8fSGustavo F. Padovan 
34872d792818SGustavo Padovan 			l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC, sizeof(rfc),
34882d792818SGustavo Padovan 					   (unsigned long) &rfc);
34890a708f8fSGustavo F. Padovan 
34900a708f8fSGustavo F. Padovan 			break;
34910a708f8fSGustavo F. Padovan 
34920a708f8fSGustavo F. Padovan 		default:
34930a708f8fSGustavo F. Padovan 			result = L2CAP_CONF_UNACCEPT;
34940a708f8fSGustavo F. Padovan 
34950a708f8fSGustavo F. Padovan 			memset(&rfc, 0, sizeof(rfc));
34960c1bc5c6SGustavo F. Padovan 			rfc.mode = chan->mode;
34970a708f8fSGustavo F. Padovan 		}
34980a708f8fSGustavo F. Padovan 
34990a708f8fSGustavo F. Padovan 		if (result == L2CAP_CONF_SUCCESS)
3500c1360a1cSGustavo F. Padovan 			set_bit(CONF_OUTPUT_DONE, &chan->conf_state);
35010a708f8fSGustavo F. Padovan 	}
3502fe4128e0SGustavo F. Padovan 	rsp->scid   = cpu_to_le16(chan->dcid);
35030a708f8fSGustavo F. Padovan 	rsp->result = cpu_to_le16(result);
350459e54bd1SAndrei Emeltchenko 	rsp->flags  = __constant_cpu_to_le16(0);
35050a708f8fSGustavo F. Padovan 
35060a708f8fSGustavo F. Padovan 	return ptr - data;
35070a708f8fSGustavo F. Padovan }
35080a708f8fSGustavo F. Padovan 
35092d792818SGustavo Padovan static int l2cap_parse_conf_rsp(struct l2cap_chan *chan, void *rsp, int len,
35102d792818SGustavo Padovan 				void *data, u16 *result)
35110a708f8fSGustavo F. Padovan {
35120a708f8fSGustavo F. Padovan 	struct l2cap_conf_req *req = data;
35130a708f8fSGustavo F. Padovan 	void *ptr = req->data;
35140a708f8fSGustavo F. Padovan 	int type, olen;
35150a708f8fSGustavo F. Padovan 	unsigned long val;
351636e999a8SMat Martineau 	struct l2cap_conf_rfc rfc = { .mode = L2CAP_MODE_BASIC };
351766af7aafSAndrei Emeltchenko 	struct l2cap_conf_efs efs;
35180a708f8fSGustavo F. Padovan 
3519fe4128e0SGustavo F. Padovan 	BT_DBG("chan %p, rsp %p, len %d, req %p", chan, rsp, len, data);
35200a708f8fSGustavo F. Padovan 
35210a708f8fSGustavo F. Padovan 	while (len >= L2CAP_CONF_OPT_SIZE) {
35220a708f8fSGustavo F. Padovan 		len -= l2cap_get_conf_opt(&rsp, &type, &olen, &val);
35230a708f8fSGustavo F. Padovan 
35240a708f8fSGustavo F. Padovan 		switch (type) {
35250a708f8fSGustavo F. Padovan 		case L2CAP_CONF_MTU:
35260a708f8fSGustavo F. Padovan 			if (val < L2CAP_DEFAULT_MIN_MTU) {
35270a708f8fSGustavo F. Padovan 				*result = L2CAP_CONF_UNACCEPT;
35280c1bc5c6SGustavo F. Padovan 				chan->imtu = L2CAP_DEFAULT_MIN_MTU;
35290a708f8fSGustavo F. Padovan 			} else
35300c1bc5c6SGustavo F. Padovan 				chan->imtu = val;
35310c1bc5c6SGustavo F. Padovan 			l2cap_add_conf_opt(&ptr, L2CAP_CONF_MTU, 2, chan->imtu);
35320a708f8fSGustavo F. Padovan 			break;
35330a708f8fSGustavo F. Padovan 
35340a708f8fSGustavo F. Padovan 		case L2CAP_CONF_FLUSH_TO:
35350c1bc5c6SGustavo F. Padovan 			chan->flush_to = val;
35360a708f8fSGustavo F. Padovan 			l2cap_add_conf_opt(&ptr, L2CAP_CONF_FLUSH_TO,
35370c1bc5c6SGustavo F. Padovan 					   2, chan->flush_to);
35380a708f8fSGustavo F. Padovan 			break;
35390a708f8fSGustavo F. Padovan 
35400a708f8fSGustavo F. Padovan 		case L2CAP_CONF_RFC:
35410a708f8fSGustavo F. Padovan 			if (olen == sizeof(rfc))
35420a708f8fSGustavo F. Padovan 				memcpy(&rfc, (void *)val, olen);
35430a708f8fSGustavo F. Padovan 
3544c1360a1cSGustavo F. Padovan 			if (test_bit(CONF_STATE2_DEVICE, &chan->conf_state) &&
35450c1bc5c6SGustavo F. Padovan 			    rfc.mode != chan->mode)
35460a708f8fSGustavo F. Padovan 				return -ECONNREFUSED;
35470a708f8fSGustavo F. Padovan 
354847d1ec61SGustavo F. Padovan 			chan->fcs = 0;
35490a708f8fSGustavo F. Padovan 
35500a708f8fSGustavo F. Padovan 			l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC,
35510a708f8fSGustavo F. Padovan 					   sizeof(rfc), (unsigned long) &rfc);
35520a708f8fSGustavo F. Padovan 			break;
35536327eb98SAndrei Emeltchenko 
35546327eb98SAndrei Emeltchenko 		case L2CAP_CONF_EWS:
3555c20f8e35SMat Martineau 			chan->ack_win = min_t(u16, val, chan->ack_win);
35563e6b3b95SGustavo F. Padovan 			l2cap_add_conf_opt(&ptr, L2CAP_CONF_EWS, 2,
35573e6b3b95SGustavo F. Padovan 					   chan->tx_win);
35586327eb98SAndrei Emeltchenko 			break;
355966af7aafSAndrei Emeltchenko 
356066af7aafSAndrei Emeltchenko 		case L2CAP_CONF_EFS:
356166af7aafSAndrei Emeltchenko 			if (olen == sizeof(efs))
356266af7aafSAndrei Emeltchenko 				memcpy(&efs, (void *)val, olen);
356366af7aafSAndrei Emeltchenko 
356466af7aafSAndrei Emeltchenko 			if (chan->local_stype != L2CAP_SERV_NOTRAFIC &&
356566af7aafSAndrei Emeltchenko 			    efs.stype != L2CAP_SERV_NOTRAFIC &&
356666af7aafSAndrei Emeltchenko 			    efs.stype != chan->local_stype)
356766af7aafSAndrei Emeltchenko 				return -ECONNREFUSED;
356866af7aafSAndrei Emeltchenko 
35692d792818SGustavo Padovan 			l2cap_add_conf_opt(&ptr, L2CAP_CONF_EFS, sizeof(efs),
35702d792818SGustavo Padovan 					   (unsigned long) &efs);
357166af7aafSAndrei Emeltchenko 			break;
3572cbabee78SAndrei Emeltchenko 
3573cbabee78SAndrei Emeltchenko 		case L2CAP_CONF_FCS:
3574cbabee78SAndrei Emeltchenko 			if (*result == L2CAP_CONF_PENDING)
3575cbabee78SAndrei Emeltchenko 				if (val == L2CAP_FCS_NONE)
3576f2592d3eSAndrei Emeltchenko 					set_bit(CONF_RECV_NO_FCS,
3577cbabee78SAndrei Emeltchenko 						&chan->conf_state);
3578cbabee78SAndrei Emeltchenko 			break;
35790a708f8fSGustavo F. Padovan 		}
35800a708f8fSGustavo F. Padovan 	}
35810a708f8fSGustavo F. Padovan 
35820c1bc5c6SGustavo F. Padovan 	if (chan->mode == L2CAP_MODE_BASIC && chan->mode != rfc.mode)
35830a708f8fSGustavo F. Padovan 		return -ECONNREFUSED;
35840a708f8fSGustavo F. Padovan 
35850c1bc5c6SGustavo F. Padovan 	chan->mode = rfc.mode;
35860a708f8fSGustavo F. Padovan 
35870e8b207eSAndrei Emeltchenko 	if (*result == L2CAP_CONF_SUCCESS || *result == L2CAP_CONF_PENDING) {
35880a708f8fSGustavo F. Padovan 		switch (rfc.mode) {
35890a708f8fSGustavo F. Padovan 		case L2CAP_MODE_ERTM:
359047d1ec61SGustavo F. Padovan 			chan->retrans_timeout = le16_to_cpu(rfc.retrans_timeout);
359147d1ec61SGustavo F. Padovan 			chan->monitor_timeout = le16_to_cpu(rfc.monitor_timeout);
359247d1ec61SGustavo F. Padovan 			chan->mps    = le16_to_cpu(rfc.max_pdu_size);
3593c20f8e35SMat Martineau 			if (!test_bit(FLAG_EXT_CTRL, &chan->flags))
3594c20f8e35SMat Martineau 				chan->ack_win = min_t(u16, chan->ack_win,
3595c20f8e35SMat Martineau 						      rfc.txwin_size);
359666af7aafSAndrei Emeltchenko 
359766af7aafSAndrei Emeltchenko 			if (test_bit(FLAG_EFS_ENABLE, &chan->flags)) {
359866af7aafSAndrei Emeltchenko 				chan->local_msdu = le16_to_cpu(efs.msdu);
359966af7aafSAndrei Emeltchenko 				chan->local_sdu_itime =
360066af7aafSAndrei Emeltchenko 					le32_to_cpu(efs.sdu_itime);
360166af7aafSAndrei Emeltchenko 				chan->local_acc_lat = le32_to_cpu(efs.acc_lat);
360266af7aafSAndrei Emeltchenko 				chan->local_flush_to =
360366af7aafSAndrei Emeltchenko 					le32_to_cpu(efs.flush_to);
360466af7aafSAndrei Emeltchenko 			}
36050a708f8fSGustavo F. Padovan 			break;
360666af7aafSAndrei Emeltchenko 
36070a708f8fSGustavo F. Padovan 		case L2CAP_MODE_STREAMING:
360847d1ec61SGustavo F. Padovan 			chan->mps    = le16_to_cpu(rfc.max_pdu_size);
36090a708f8fSGustavo F. Padovan 		}
36100a708f8fSGustavo F. Padovan 	}
36110a708f8fSGustavo F. Padovan 
3612fe4128e0SGustavo F. Padovan 	req->dcid   = cpu_to_le16(chan->dcid);
361359e54bd1SAndrei Emeltchenko 	req->flags  = __constant_cpu_to_le16(0);
36140a708f8fSGustavo F. Padovan 
36150a708f8fSGustavo F. Padovan 	return ptr - data;
36160a708f8fSGustavo F. Padovan }
36170a708f8fSGustavo F. Padovan 
36182d792818SGustavo Padovan static int l2cap_build_conf_rsp(struct l2cap_chan *chan, void *data,
36192d792818SGustavo Padovan 				u16 result, u16 flags)
36200a708f8fSGustavo F. Padovan {
36210a708f8fSGustavo F. Padovan 	struct l2cap_conf_rsp *rsp = data;
36220a708f8fSGustavo F. Padovan 	void *ptr = rsp->data;
36230a708f8fSGustavo F. Padovan 
3624fe4128e0SGustavo F. Padovan 	BT_DBG("chan %p", chan);
36250a708f8fSGustavo F. Padovan 
3626fe4128e0SGustavo F. Padovan 	rsp->scid   = cpu_to_le16(chan->dcid);
36270a708f8fSGustavo F. Padovan 	rsp->result = cpu_to_le16(result);
36280a708f8fSGustavo F. Padovan 	rsp->flags  = cpu_to_le16(flags);
36290a708f8fSGustavo F. Padovan 
36300a708f8fSGustavo F. Padovan 	return ptr - data;
36310a708f8fSGustavo F. Padovan }
36320a708f8fSGustavo F. Padovan 
36338c1d787bSGustavo F. Padovan void __l2cap_connect_rsp_defer(struct l2cap_chan *chan)
3634710f9b0aSGustavo F. Padovan {
3635710f9b0aSGustavo F. Padovan 	struct l2cap_conn_rsp rsp;
36368c1d787bSGustavo F. Padovan 	struct l2cap_conn *conn = chan->conn;
3637710f9b0aSGustavo F. Padovan 	u8 buf[128];
3638439f34acSAndrei Emeltchenko 	u8 rsp_code;
3639710f9b0aSGustavo F. Padovan 
3640fe4128e0SGustavo F. Padovan 	rsp.scid   = cpu_to_le16(chan->dcid);
3641fe4128e0SGustavo F. Padovan 	rsp.dcid   = cpu_to_le16(chan->scid);
3642ac73498cSAndrei Emeltchenko 	rsp.result = __constant_cpu_to_le16(L2CAP_CR_SUCCESS);
3643ac73498cSAndrei Emeltchenko 	rsp.status = __constant_cpu_to_le16(L2CAP_CS_NO_INFO);
3644439f34acSAndrei Emeltchenko 
3645439f34acSAndrei Emeltchenko 	if (chan->hs_hcon)
3646439f34acSAndrei Emeltchenko 		rsp_code = L2CAP_CREATE_CHAN_RSP;
3647439f34acSAndrei Emeltchenko 	else
3648439f34acSAndrei Emeltchenko 		rsp_code = L2CAP_CONN_RSP;
3649439f34acSAndrei Emeltchenko 
3650439f34acSAndrei Emeltchenko 	BT_DBG("chan %p rsp_code %u", chan, rsp_code);
3651439f34acSAndrei Emeltchenko 
3652439f34acSAndrei Emeltchenko 	l2cap_send_cmd(conn, chan->ident, rsp_code, sizeof(rsp), &rsp);
3653710f9b0aSGustavo F. Padovan 
3654c1360a1cSGustavo F. Padovan 	if (test_and_set_bit(CONF_REQ_SENT, &chan->conf_state))
3655710f9b0aSGustavo F. Padovan 		return;
3656710f9b0aSGustavo F. Padovan 
3657710f9b0aSGustavo F. Padovan 	l2cap_send_cmd(conn, l2cap_get_ident(conn), L2CAP_CONF_REQ,
3658710f9b0aSGustavo F. Padovan 		       l2cap_build_conf_req(chan, buf), buf);
3659710f9b0aSGustavo F. Padovan 	chan->num_conf_req++;
3660710f9b0aSGustavo F. Padovan }
3661710f9b0aSGustavo F. Padovan 
366247d1ec61SGustavo F. Padovan static void l2cap_conf_rfc_get(struct l2cap_chan *chan, void *rsp, int len)
36630a708f8fSGustavo F. Padovan {
36640a708f8fSGustavo F. Padovan 	int type, olen;
36650a708f8fSGustavo F. Padovan 	unsigned long val;
3666c20f8e35SMat Martineau 	/* Use sane default values in case a misbehaving remote device
3667c20f8e35SMat Martineau 	 * did not send an RFC or extended window size option.
3668c20f8e35SMat Martineau 	 */
3669c20f8e35SMat Martineau 	u16 txwin_ext = chan->ack_win;
3670c20f8e35SMat Martineau 	struct l2cap_conf_rfc rfc = {
3671c20f8e35SMat Martineau 		.mode = chan->mode,
3672c20f8e35SMat Martineau 		.retrans_timeout = __constant_cpu_to_le16(L2CAP_DEFAULT_RETRANS_TO),
3673c20f8e35SMat Martineau 		.monitor_timeout = __constant_cpu_to_le16(L2CAP_DEFAULT_MONITOR_TO),
3674c20f8e35SMat Martineau 		.max_pdu_size = cpu_to_le16(chan->imtu),
3675c20f8e35SMat Martineau 		.txwin_size = min_t(u16, chan->ack_win, L2CAP_DEFAULT_TX_WINDOW),
3676c20f8e35SMat Martineau 	};
36770a708f8fSGustavo F. Padovan 
367847d1ec61SGustavo F. Padovan 	BT_DBG("chan %p, rsp %p, len %d", chan, rsp, len);
36790a708f8fSGustavo F. Padovan 
36800c1bc5c6SGustavo F. Padovan 	if ((chan->mode != L2CAP_MODE_ERTM) && (chan->mode != L2CAP_MODE_STREAMING))
36810a708f8fSGustavo F. Padovan 		return;
36820a708f8fSGustavo F. Padovan 
36830a708f8fSGustavo F. Padovan 	while (len >= L2CAP_CONF_OPT_SIZE) {
36840a708f8fSGustavo F. Padovan 		len -= l2cap_get_conf_opt(&rsp, &type, &olen, &val);
36850a708f8fSGustavo F. Padovan 
3686c20f8e35SMat Martineau 		switch (type) {
3687c20f8e35SMat Martineau 		case L2CAP_CONF_RFC:
3688c20f8e35SMat Martineau 			if (olen == sizeof(rfc))
36890a708f8fSGustavo F. Padovan 				memcpy(&rfc, (void *)val, olen);
3690c20f8e35SMat Martineau 			break;
3691c20f8e35SMat Martineau 		case L2CAP_CONF_EWS:
3692c20f8e35SMat Martineau 			txwin_ext = val;
3693c20f8e35SMat Martineau 			break;
3694c20f8e35SMat Martineau 		}
36950a708f8fSGustavo F. Padovan 	}
36960a708f8fSGustavo F. Padovan 
36970a708f8fSGustavo F. Padovan 	switch (rfc.mode) {
36980a708f8fSGustavo F. Padovan 	case L2CAP_MODE_ERTM:
369947d1ec61SGustavo F. Padovan 		chan->retrans_timeout = le16_to_cpu(rfc.retrans_timeout);
370047d1ec61SGustavo F. Padovan 		chan->monitor_timeout = le16_to_cpu(rfc.monitor_timeout);
370147d1ec61SGustavo F. Padovan 		chan->mps = le16_to_cpu(rfc.max_pdu_size);
3702c20f8e35SMat Martineau 		if (test_bit(FLAG_EXT_CTRL, &chan->flags))
3703c20f8e35SMat Martineau 			chan->ack_win = min_t(u16, chan->ack_win, txwin_ext);
3704c20f8e35SMat Martineau 		else
3705c20f8e35SMat Martineau 			chan->ack_win = min_t(u16, chan->ack_win,
3706c20f8e35SMat Martineau 					      rfc.txwin_size);
37070a708f8fSGustavo F. Padovan 		break;
37080a708f8fSGustavo F. Padovan 	case L2CAP_MODE_STREAMING:
370947d1ec61SGustavo F. Padovan 		chan->mps    = le16_to_cpu(rfc.max_pdu_size);
37100a708f8fSGustavo F. Padovan 	}
37110a708f8fSGustavo F. Padovan }
37120a708f8fSGustavo F. Padovan 
37132d792818SGustavo Padovan static inline int l2cap_command_rej(struct l2cap_conn *conn,
3714cb3b3152SJohan Hedberg 				    struct l2cap_cmd_hdr *cmd, u16 cmd_len,
3715cb3b3152SJohan Hedberg 				    u8 *data)
37160a708f8fSGustavo F. Padovan {
3717e2fd318eSIlia Kolomisnky 	struct l2cap_cmd_rej_unk *rej = (struct l2cap_cmd_rej_unk *) data;
37180a708f8fSGustavo F. Padovan 
3719cb3b3152SJohan Hedberg 	if (cmd_len < sizeof(*rej))
3720cb3b3152SJohan Hedberg 		return -EPROTO;
3721cb3b3152SJohan Hedberg 
3722e2fd318eSIlia Kolomisnky 	if (rej->reason != L2CAP_REJ_NOT_UNDERSTOOD)
37230a708f8fSGustavo F. Padovan 		return 0;
37240a708f8fSGustavo F. Padovan 
37250a708f8fSGustavo F. Padovan 	if ((conn->info_state & L2CAP_INFO_FEAT_MASK_REQ_SENT) &&
37260a708f8fSGustavo F. Padovan 	    cmd->ident == conn->info_ident) {
372717cd3f37SUlisses Furquim 		cancel_delayed_work(&conn->info_timer);
37280a708f8fSGustavo F. Padovan 
37290a708f8fSGustavo F. Padovan 		conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_DONE;
37300a708f8fSGustavo F. Padovan 		conn->info_ident = 0;
37310a708f8fSGustavo F. Padovan 
37320a708f8fSGustavo F. Padovan 		l2cap_conn_start(conn);
37330a708f8fSGustavo F. Padovan 	}
37340a708f8fSGustavo F. Padovan 
37350a708f8fSGustavo F. Padovan 	return 0;
37360a708f8fSGustavo F. Padovan }
37370a708f8fSGustavo F. Padovan 
37381700915fSMat Martineau static struct l2cap_chan *l2cap_connect(struct l2cap_conn *conn,
37391700915fSMat Martineau 					struct l2cap_cmd_hdr *cmd,
37404c89b6aaSMat Martineau 					u8 *data, u8 rsp_code, u8 amp_id)
37410a708f8fSGustavo F. Padovan {
37420a708f8fSGustavo F. Padovan 	struct l2cap_conn_req *req = (struct l2cap_conn_req *) data;
37430a708f8fSGustavo F. Padovan 	struct l2cap_conn_rsp rsp;
374423691d75SGustavo F. Padovan 	struct l2cap_chan *chan = NULL, *pchan;
37450a708f8fSGustavo F. Padovan 	struct sock *parent, *sk = NULL;
37460a708f8fSGustavo F. Padovan 	int result, status = L2CAP_CS_NO_INFO;
37470a708f8fSGustavo F. Padovan 
37480a708f8fSGustavo F. Padovan 	u16 dcid = 0, scid = __le16_to_cpu(req->scid);
37490a708f8fSGustavo F. Padovan 	__le16 psm = req->psm;
37500a708f8fSGustavo F. Padovan 
3751097db76cSAndrei Emeltchenko 	BT_DBG("psm 0x%2.2x scid 0x%4.4x", __le16_to_cpu(psm), scid);
37520a708f8fSGustavo F. Padovan 
37530a708f8fSGustavo F. Padovan 	/* Check if we have socket listening on psm */
3754c2287681SIdo Yariv 	pchan = l2cap_global_chan_by_psm(BT_LISTEN, psm, conn->src, conn->dst);
375523691d75SGustavo F. Padovan 	if (!pchan) {
37560a708f8fSGustavo F. Padovan 		result = L2CAP_CR_BAD_PSM;
37570a708f8fSGustavo F. Padovan 		goto sendresp;
37580a708f8fSGustavo F. Padovan 	}
37590a708f8fSGustavo F. Padovan 
376023691d75SGustavo F. Padovan 	parent = pchan->sk;
376123691d75SGustavo F. Padovan 
37623df91ea2SAndrei Emeltchenko 	mutex_lock(&conn->chan_lock);
3763aa2ac881SGustavo F. Padovan 	lock_sock(parent);
37640a708f8fSGustavo F. Padovan 
37650a708f8fSGustavo F. Padovan 	/* Check if the ACL is secure enough (if not SDP) */
37662983fd68SAndrei Emeltchenko 	if (psm != __constant_cpu_to_le16(L2CAP_PSM_SDP) &&
37670a708f8fSGustavo F. Padovan 	    !hci_conn_check_link_mode(conn->hcon)) {
37689f5a0d7bSAndrei Emeltchenko 		conn->disc_reason = HCI_ERROR_AUTH_FAILURE;
37690a708f8fSGustavo F. Padovan 		result = L2CAP_CR_SEC_BLOCK;
37700a708f8fSGustavo F. Padovan 		goto response;
37710a708f8fSGustavo F. Padovan 	}
37720a708f8fSGustavo F. Padovan 
37730a708f8fSGustavo F. Padovan 	result = L2CAP_CR_NO_MEM;
37740a708f8fSGustavo F. Padovan 
37752dfa1003SGustavo Padovan 	/* Check if we already have channel with that dcid */
37762dfa1003SGustavo Padovan 	if (__l2cap_get_chan_by_dcid(conn, scid))
37772dfa1003SGustavo Padovan 		goto response;
37782dfa1003SGustavo Padovan 
377980b98027SGustavo Padovan 	chan = pchan->ops->new_connection(pchan);
378080808e43SGustavo F. Padovan 	if (!chan)
37810a708f8fSGustavo F. Padovan 		goto response;
37820a708f8fSGustavo F. Padovan 
378380808e43SGustavo F. Padovan 	sk = chan->sk;
378480808e43SGustavo F. Padovan 
3785330b6c15SSyam Sidhardhan 	/* For certain devices (ex: HID mouse), support for authentication,
3786330b6c15SSyam Sidhardhan 	 * pairing and bonding is optional. For such devices, inorder to avoid
3787330b6c15SSyam Sidhardhan 	 * the ACL alive for too long after L2CAP disconnection, reset the ACL
3788330b6c15SSyam Sidhardhan 	 * disc_timeout back to HCI_DISCONN_TIMEOUT during L2CAP connect.
3789330b6c15SSyam Sidhardhan 	 */
3790330b6c15SSyam Sidhardhan 	conn->hcon->disc_timeout = HCI_DISCONN_TIMEOUT;
3791330b6c15SSyam Sidhardhan 
37920a708f8fSGustavo F. Padovan 	bacpy(&bt_sk(sk)->src, conn->src);
37930a708f8fSGustavo F. Padovan 	bacpy(&bt_sk(sk)->dst, conn->dst);
3794fe4128e0SGustavo F. Padovan 	chan->psm  = psm;
3795fe4128e0SGustavo F. Padovan 	chan->dcid = scid;
37961700915fSMat Martineau 	chan->local_amp_id = amp_id;
37970a708f8fSGustavo F. Padovan 
37986be36555SAndrei Emeltchenko 	__l2cap_chan_add(conn, chan);
379948454079SGustavo F. Padovan 
3800fe4128e0SGustavo F. Padovan 	dcid = chan->scid;
38010a708f8fSGustavo F. Padovan 
3802c9b66675SGustavo F. Padovan 	__set_chan_timer(chan, sk->sk_sndtimeo);
38030a708f8fSGustavo F. Padovan 
3804fc7f8a7eSGustavo F. Padovan 	chan->ident = cmd->ident;
38050a708f8fSGustavo F. Padovan 
38060a708f8fSGustavo F. Padovan 	if (conn->info_state & L2CAP_INFO_FEAT_MASK_REQ_DONE) {
3807d45fc423SGustavo F. Padovan 		if (l2cap_chan_check_security(chan)) {
3808c5daa683SGustavo Padovan 			if (test_bit(BT_SK_DEFER_SETUP, &bt_sk(sk)->flags)) {
38090e587be7SAndrei Emeltchenko 				__l2cap_state_change(chan, BT_CONNECT2);
38100a708f8fSGustavo F. Padovan 				result = L2CAP_CR_PEND;
38110a708f8fSGustavo F. Padovan 				status = L2CAP_CS_AUTHOR_PEND;
38122dc4e510SGustavo Padovan 				chan->ops->defer(chan);
38130a708f8fSGustavo F. Padovan 			} else {
38141700915fSMat Martineau 				/* Force pending result for AMP controllers.
38151700915fSMat Martineau 				 * The connection will succeed after the
38161700915fSMat Martineau 				 * physical link is up.
38171700915fSMat Martineau 				 */
38186ed971caSMarcel Holtmann 				if (amp_id == AMP_ID_BREDR) {
38190e587be7SAndrei Emeltchenko 					__l2cap_state_change(chan, BT_CONFIG);
38200a708f8fSGustavo F. Padovan 					result = L2CAP_CR_SUCCESS;
38216ed971caSMarcel Holtmann 				} else {
38226ed971caSMarcel Holtmann 					__l2cap_state_change(chan, BT_CONNECT2);
38236ed971caSMarcel Holtmann 					result = L2CAP_CR_PEND;
38241700915fSMat Martineau 				}
38250a708f8fSGustavo F. Padovan 				status = L2CAP_CS_NO_INFO;
38260a708f8fSGustavo F. Padovan 			}
38270a708f8fSGustavo F. Padovan 		} else {
38280e587be7SAndrei Emeltchenko 			__l2cap_state_change(chan, BT_CONNECT2);
38290a708f8fSGustavo F. Padovan 			result = L2CAP_CR_PEND;
38300a708f8fSGustavo F. Padovan 			status = L2CAP_CS_AUTHEN_PEND;
38310a708f8fSGustavo F. Padovan 		}
38320a708f8fSGustavo F. Padovan 	} else {
38330e587be7SAndrei Emeltchenko 		__l2cap_state_change(chan, BT_CONNECT2);
38340a708f8fSGustavo F. Padovan 		result = L2CAP_CR_PEND;
38350a708f8fSGustavo F. Padovan 		status = L2CAP_CS_NO_INFO;
38360a708f8fSGustavo F. Padovan 	}
38370a708f8fSGustavo F. Padovan 
38380a708f8fSGustavo F. Padovan response:
3839aa2ac881SGustavo F. Padovan 	release_sock(parent);
38403df91ea2SAndrei Emeltchenko 	mutex_unlock(&conn->chan_lock);
38410a708f8fSGustavo F. Padovan 
38420a708f8fSGustavo F. Padovan sendresp:
38430a708f8fSGustavo F. Padovan 	rsp.scid   = cpu_to_le16(scid);
38440a708f8fSGustavo F. Padovan 	rsp.dcid   = cpu_to_le16(dcid);
38450a708f8fSGustavo F. Padovan 	rsp.result = cpu_to_le16(result);
38460a708f8fSGustavo F. Padovan 	rsp.status = cpu_to_le16(status);
38474c89b6aaSMat Martineau 	l2cap_send_cmd(conn, cmd->ident, rsp_code, sizeof(rsp), &rsp);
38480a708f8fSGustavo F. Padovan 
38490a708f8fSGustavo F. Padovan 	if (result == L2CAP_CR_PEND && status == L2CAP_CS_NO_INFO) {
38500a708f8fSGustavo F. Padovan 		struct l2cap_info_req info;
3851ac73498cSAndrei Emeltchenko 		info.type = __constant_cpu_to_le16(L2CAP_IT_FEAT_MASK);
38520a708f8fSGustavo F. Padovan 
38530a708f8fSGustavo F. Padovan 		conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_SENT;
38540a708f8fSGustavo F. Padovan 		conn->info_ident = l2cap_get_ident(conn);
38550a708f8fSGustavo F. Padovan 
3856ba13ccd9SMarcel Holtmann 		schedule_delayed_work(&conn->info_timer, L2CAP_INFO_TIMEOUT);
38570a708f8fSGustavo F. Padovan 
38582d792818SGustavo Padovan 		l2cap_send_cmd(conn, conn->info_ident, L2CAP_INFO_REQ,
38592d792818SGustavo Padovan 			       sizeof(info), &info);
38600a708f8fSGustavo F. Padovan 	}
38610a708f8fSGustavo F. Padovan 
3862c1360a1cSGustavo F. Padovan 	if (chan && !test_bit(CONF_REQ_SENT, &chan->conf_state) &&
38630a708f8fSGustavo F. Padovan 	    result == L2CAP_CR_SUCCESS) {
38640a708f8fSGustavo F. Padovan 		u8 buf[128];
3865c1360a1cSGustavo F. Padovan 		set_bit(CONF_REQ_SENT, &chan->conf_state);
38660a708f8fSGustavo F. Padovan 		l2cap_send_cmd(conn, l2cap_get_ident(conn), L2CAP_CONF_REQ,
386773ffa904SGustavo F. Padovan 			       l2cap_build_conf_req(chan, buf), buf);
386873ffa904SGustavo F. Padovan 		chan->num_conf_req++;
38690a708f8fSGustavo F. Padovan 	}
38701700915fSMat Martineau 
38711700915fSMat Martineau 	return chan;
38724c89b6aaSMat Martineau }
38730a708f8fSGustavo F. Padovan 
38744c89b6aaSMat Martineau static int l2cap_connect_req(struct l2cap_conn *conn,
3875cb3b3152SJohan Hedberg 			     struct l2cap_cmd_hdr *cmd, u16 cmd_len, u8 *data)
38764c89b6aaSMat Martineau {
38777b064edaSJaganath Kanakkassery 	struct hci_dev *hdev = conn->hcon->hdev;
38787b064edaSJaganath Kanakkassery 	struct hci_conn *hcon = conn->hcon;
38797b064edaSJaganath Kanakkassery 
3880cb3b3152SJohan Hedberg 	if (cmd_len < sizeof(struct l2cap_conn_req))
3881cb3b3152SJohan Hedberg 		return -EPROTO;
3882cb3b3152SJohan Hedberg 
38837b064edaSJaganath Kanakkassery 	hci_dev_lock(hdev);
38847b064edaSJaganath Kanakkassery 	if (test_bit(HCI_MGMT, &hdev->dev_flags) &&
38857b064edaSJaganath Kanakkassery 	    !test_and_set_bit(HCI_CONN_MGMT_CONNECTED, &hcon->flags))
38867b064edaSJaganath Kanakkassery 		mgmt_device_connected(hdev, &hcon->dst, hcon->type,
38877b064edaSJaganath Kanakkassery 				      hcon->dst_type, 0, NULL, 0,
38887b064edaSJaganath Kanakkassery 				      hcon->dev_class);
38897b064edaSJaganath Kanakkassery 	hci_dev_unlock(hdev);
38907b064edaSJaganath Kanakkassery 
3891300229f9SGustavo Padovan 	l2cap_connect(conn, cmd, data, L2CAP_CONN_RSP, 0);
38920a708f8fSGustavo F. Padovan 	return 0;
38930a708f8fSGustavo F. Padovan }
38940a708f8fSGustavo F. Padovan 
38955909cf30SMat Martineau static int l2cap_connect_create_rsp(struct l2cap_conn *conn,
3896cb3b3152SJohan Hedberg 				    struct l2cap_cmd_hdr *cmd, u16 cmd_len,
3897cb3b3152SJohan Hedberg 				    u8 *data)
38980a708f8fSGustavo F. Padovan {
38990a708f8fSGustavo F. Padovan 	struct l2cap_conn_rsp *rsp = (struct l2cap_conn_rsp *) data;
39000a708f8fSGustavo F. Padovan 	u16 scid, dcid, result, status;
390148454079SGustavo F. Padovan 	struct l2cap_chan *chan;
39020a708f8fSGustavo F. Padovan 	u8 req[128];
39033df91ea2SAndrei Emeltchenko 	int err;
39040a708f8fSGustavo F. Padovan 
3905cb3b3152SJohan Hedberg 	if (cmd_len < sizeof(*rsp))
3906cb3b3152SJohan Hedberg 		return -EPROTO;
3907cb3b3152SJohan Hedberg 
39080a708f8fSGustavo F. Padovan 	scid   = __le16_to_cpu(rsp->scid);
39090a708f8fSGustavo F. Padovan 	dcid   = __le16_to_cpu(rsp->dcid);
39100a708f8fSGustavo F. Padovan 	result = __le16_to_cpu(rsp->result);
39110a708f8fSGustavo F. Padovan 	status = __le16_to_cpu(rsp->status);
39120a708f8fSGustavo F. Padovan 
39131b009c98SAndrei Emeltchenko 	BT_DBG("dcid 0x%4.4x scid 0x%4.4x result 0x%2.2x status 0x%2.2x",
39141b009c98SAndrei Emeltchenko 	       dcid, scid, result, status);
39150a708f8fSGustavo F. Padovan 
39163df91ea2SAndrei Emeltchenko 	mutex_lock(&conn->chan_lock);
39173df91ea2SAndrei Emeltchenko 
39180a708f8fSGustavo F. Padovan 	if (scid) {
39193df91ea2SAndrei Emeltchenko 		chan = __l2cap_get_chan_by_scid(conn, scid);
39203df91ea2SAndrei Emeltchenko 		if (!chan) {
392121870b52SJohan Hedberg 			err = -EBADSLT;
39223df91ea2SAndrei Emeltchenko 			goto unlock;
39233df91ea2SAndrei Emeltchenko 		}
39240a708f8fSGustavo F. Padovan 	} else {
39253df91ea2SAndrei Emeltchenko 		chan = __l2cap_get_chan_by_ident(conn, cmd->ident);
39263df91ea2SAndrei Emeltchenko 		if (!chan) {
392721870b52SJohan Hedberg 			err = -EBADSLT;
39283df91ea2SAndrei Emeltchenko 			goto unlock;
39293df91ea2SAndrei Emeltchenko 		}
39300a708f8fSGustavo F. Padovan 	}
39310a708f8fSGustavo F. Padovan 
39323df91ea2SAndrei Emeltchenko 	err = 0;
39333df91ea2SAndrei Emeltchenko 
39346be36555SAndrei Emeltchenko 	l2cap_chan_lock(chan);
393548454079SGustavo F. Padovan 
39360a708f8fSGustavo F. Padovan 	switch (result) {
39370a708f8fSGustavo F. Padovan 	case L2CAP_CR_SUCCESS:
393889bc500eSGustavo F. Padovan 		l2cap_state_change(chan, BT_CONFIG);
3939fc7f8a7eSGustavo F. Padovan 		chan->ident = 0;
3940fe4128e0SGustavo F. Padovan 		chan->dcid = dcid;
3941c1360a1cSGustavo F. Padovan 		clear_bit(CONF_CONNECT_PEND, &chan->conf_state);
39420a708f8fSGustavo F. Padovan 
3943c1360a1cSGustavo F. Padovan 		if (test_and_set_bit(CONF_REQ_SENT, &chan->conf_state))
39440a708f8fSGustavo F. Padovan 			break;
39450a708f8fSGustavo F. Padovan 
39460a708f8fSGustavo F. Padovan 		l2cap_send_cmd(conn, l2cap_get_ident(conn), L2CAP_CONF_REQ,
394773ffa904SGustavo F. Padovan 			       l2cap_build_conf_req(chan, req), req);
394873ffa904SGustavo F. Padovan 		chan->num_conf_req++;
39490a708f8fSGustavo F. Padovan 		break;
39500a708f8fSGustavo F. Padovan 
39510a708f8fSGustavo F. Padovan 	case L2CAP_CR_PEND:
3952c1360a1cSGustavo F. Padovan 		set_bit(CONF_CONNECT_PEND, &chan->conf_state);
39530a708f8fSGustavo F. Padovan 		break;
39540a708f8fSGustavo F. Padovan 
39550a708f8fSGustavo F. Padovan 	default:
395648454079SGustavo F. Padovan 		l2cap_chan_del(chan, ECONNREFUSED);
39570a708f8fSGustavo F. Padovan 		break;
39580a708f8fSGustavo F. Padovan 	}
39590a708f8fSGustavo F. Padovan 
39606be36555SAndrei Emeltchenko 	l2cap_chan_unlock(chan);
39613df91ea2SAndrei Emeltchenko 
39623df91ea2SAndrei Emeltchenko unlock:
39633df91ea2SAndrei Emeltchenko 	mutex_unlock(&conn->chan_lock);
39643df91ea2SAndrei Emeltchenko 
39653df91ea2SAndrei Emeltchenko 	return err;
39660a708f8fSGustavo F. Padovan }
39670a708f8fSGustavo F. Padovan 
396847d1ec61SGustavo F. Padovan static inline void set_default_fcs(struct l2cap_chan *chan)
39690a708f8fSGustavo F. Padovan {
39700a708f8fSGustavo F. Padovan 	/* FCS is enabled only in ERTM or streaming mode, if one or both
39710a708f8fSGustavo F. Padovan 	 * sides request it.
39720a708f8fSGustavo F. Padovan 	 */
39730c1bc5c6SGustavo F. Padovan 	if (chan->mode != L2CAP_MODE_ERTM && chan->mode != L2CAP_MODE_STREAMING)
397447d1ec61SGustavo F. Padovan 		chan->fcs = L2CAP_FCS_NONE;
3975f2592d3eSAndrei Emeltchenko 	else if (!test_bit(CONF_RECV_NO_FCS, &chan->conf_state))
397647d1ec61SGustavo F. Padovan 		chan->fcs = L2CAP_FCS_CRC16;
39770a708f8fSGustavo F. Padovan }
39780a708f8fSGustavo F. Padovan 
397929d8a590SAndrei Emeltchenko static void l2cap_send_efs_conf_rsp(struct l2cap_chan *chan, void *data,
398029d8a590SAndrei Emeltchenko 				    u8 ident, u16 flags)
398129d8a590SAndrei Emeltchenko {
398229d8a590SAndrei Emeltchenko 	struct l2cap_conn *conn = chan->conn;
398329d8a590SAndrei Emeltchenko 
398429d8a590SAndrei Emeltchenko 	BT_DBG("conn %p chan %p ident %d flags 0x%4.4x", conn, chan, ident,
398529d8a590SAndrei Emeltchenko 	       flags);
398629d8a590SAndrei Emeltchenko 
398729d8a590SAndrei Emeltchenko 	clear_bit(CONF_LOC_CONF_PEND, &chan->conf_state);
398829d8a590SAndrei Emeltchenko 	set_bit(CONF_OUTPUT_DONE, &chan->conf_state);
398929d8a590SAndrei Emeltchenko 
399029d8a590SAndrei Emeltchenko 	l2cap_send_cmd(conn, ident, L2CAP_CONF_RSP,
399129d8a590SAndrei Emeltchenko 		       l2cap_build_conf_rsp(chan, data,
399229d8a590SAndrei Emeltchenko 					    L2CAP_CONF_SUCCESS, flags), data);
399329d8a590SAndrei Emeltchenko }
399429d8a590SAndrei Emeltchenko 
39952d792818SGustavo Padovan static inline int l2cap_config_req(struct l2cap_conn *conn,
39962d792818SGustavo Padovan 				   struct l2cap_cmd_hdr *cmd, u16 cmd_len,
39972d792818SGustavo Padovan 				   u8 *data)
39980a708f8fSGustavo F. Padovan {
39990a708f8fSGustavo F. Padovan 	struct l2cap_conf_req *req = (struct l2cap_conf_req *) data;
40000a708f8fSGustavo F. Padovan 	u16 dcid, flags;
40010a708f8fSGustavo F. Padovan 	u8 rsp[64];
400248454079SGustavo F. Padovan 	struct l2cap_chan *chan;
40033c588192SMat Martineau 	int len, err = 0;
40040a708f8fSGustavo F. Padovan 
4005cb3b3152SJohan Hedberg 	if (cmd_len < sizeof(*req))
4006cb3b3152SJohan Hedberg 		return -EPROTO;
4007cb3b3152SJohan Hedberg 
40080a708f8fSGustavo F. Padovan 	dcid  = __le16_to_cpu(req->dcid);
40090a708f8fSGustavo F. Padovan 	flags = __le16_to_cpu(req->flags);
40100a708f8fSGustavo F. Padovan 
40110a708f8fSGustavo F. Padovan 	BT_DBG("dcid 0x%4.4x flags 0x%2.2x", dcid, flags);
40120a708f8fSGustavo F. Padovan 
4013baa7e1faSGustavo F. Padovan 	chan = l2cap_get_chan_by_scid(conn, dcid);
401448454079SGustavo F. Padovan 	if (!chan)
401521870b52SJohan Hedberg 		return -EBADSLT;
40160a708f8fSGustavo F. Padovan 
4017033b1142SDavid S. Miller 	if (chan->state != BT_CONFIG && chan->state != BT_CONNECT2) {
4018e2fd318eSIlia Kolomisnky 		struct l2cap_cmd_rej_cid rej;
40190a708f8fSGustavo F. Padovan 
4020ac73498cSAndrei Emeltchenko 		rej.reason = __constant_cpu_to_le16(L2CAP_REJ_INVALID_CID);
4021e2fd318eSIlia Kolomisnky 		rej.scid = cpu_to_le16(chan->scid);
4022e2fd318eSIlia Kolomisnky 		rej.dcid = cpu_to_le16(chan->dcid);
4023e2fd318eSIlia Kolomisnky 
40240a708f8fSGustavo F. Padovan 		l2cap_send_cmd(conn, cmd->ident, L2CAP_COMMAND_REJ,
40250a708f8fSGustavo F. Padovan 			       sizeof(rej), &rej);
40260a708f8fSGustavo F. Padovan 		goto unlock;
40270a708f8fSGustavo F. Padovan 	}
40280a708f8fSGustavo F. Padovan 
40290a708f8fSGustavo F. Padovan 	/* Reject if config buffer is too small. */
40300a708f8fSGustavo F. Padovan 	len = cmd_len - sizeof(*req);
4031cb3b3152SJohan Hedberg 	if (chan->conf_len + len > sizeof(chan->conf_req)) {
40320a708f8fSGustavo F. Padovan 		l2cap_send_cmd(conn, cmd->ident, L2CAP_CONF_RSP,
4033fe4128e0SGustavo F. Padovan 			       l2cap_build_conf_rsp(chan, rsp,
40340a708f8fSGustavo F. Padovan 			       L2CAP_CONF_REJECT, flags), rsp);
40350a708f8fSGustavo F. Padovan 		goto unlock;
40360a708f8fSGustavo F. Padovan 	}
40370a708f8fSGustavo F. Padovan 
40380a708f8fSGustavo F. Padovan 	/* Store config. */
403973ffa904SGustavo F. Padovan 	memcpy(chan->conf_req + chan->conf_len, req->data, len);
404073ffa904SGustavo F. Padovan 	chan->conf_len += len;
40410a708f8fSGustavo F. Padovan 
404259e54bd1SAndrei Emeltchenko 	if (flags & L2CAP_CONF_FLAG_CONTINUATION) {
40430a708f8fSGustavo F. Padovan 		/* Incomplete config. Send empty response. */
40440a708f8fSGustavo F. Padovan 		l2cap_send_cmd(conn, cmd->ident, L2CAP_CONF_RSP,
4045fe4128e0SGustavo F. Padovan 			       l2cap_build_conf_rsp(chan, rsp,
40465325e5bbSAndrei Emeltchenko 			       L2CAP_CONF_SUCCESS, flags), rsp);
40470a708f8fSGustavo F. Padovan 		goto unlock;
40480a708f8fSGustavo F. Padovan 	}
40490a708f8fSGustavo F. Padovan 
40500a708f8fSGustavo F. Padovan 	/* Complete config. */
405173ffa904SGustavo F. Padovan 	len = l2cap_parse_conf_req(chan, rsp);
40520a708f8fSGustavo F. Padovan 	if (len < 0) {
40535e4e3972SAndrei Emeltchenko 		l2cap_send_disconn_req(chan, ECONNRESET);
40540a708f8fSGustavo F. Padovan 		goto unlock;
40550a708f8fSGustavo F. Padovan 	}
40560a708f8fSGustavo F. Padovan 
40571500109bSMat Martineau 	chan->ident = cmd->ident;
40580a708f8fSGustavo F. Padovan 	l2cap_send_cmd(conn, cmd->ident, L2CAP_CONF_RSP, len, rsp);
405973ffa904SGustavo F. Padovan 	chan->num_conf_rsp++;
40600a708f8fSGustavo F. Padovan 
40610a708f8fSGustavo F. Padovan 	/* Reset config buffer. */
406273ffa904SGustavo F. Padovan 	chan->conf_len = 0;
40630a708f8fSGustavo F. Padovan 
4064c1360a1cSGustavo F. Padovan 	if (!test_bit(CONF_OUTPUT_DONE, &chan->conf_state))
40650a708f8fSGustavo F. Padovan 		goto unlock;
40660a708f8fSGustavo F. Padovan 
4067c1360a1cSGustavo F. Padovan 	if (test_bit(CONF_INPUT_DONE, &chan->conf_state)) {
406847d1ec61SGustavo F. Padovan 		set_default_fcs(chan);
40690a708f8fSGustavo F. Padovan 
4070105bdf9eSMat Martineau 		if (chan->mode == L2CAP_MODE_ERTM ||
4071105bdf9eSMat Martineau 		    chan->mode == L2CAP_MODE_STREAMING)
40723c588192SMat Martineau 			err = l2cap_ertm_init(chan);
40730a708f8fSGustavo F. Padovan 
40743c588192SMat Martineau 		if (err < 0)
40755e4e3972SAndrei Emeltchenko 			l2cap_send_disconn_req(chan, -err);
40763c588192SMat Martineau 		else
4077cf4cd009SAndrei Emeltchenko 			l2cap_chan_ready(chan);
40783c588192SMat Martineau 
40790a708f8fSGustavo F. Padovan 		goto unlock;
40800a708f8fSGustavo F. Padovan 	}
40810a708f8fSGustavo F. Padovan 
4082c1360a1cSGustavo F. Padovan 	if (!test_and_set_bit(CONF_REQ_SENT, &chan->conf_state)) {
40830a708f8fSGustavo F. Padovan 		u8 buf[64];
40840a708f8fSGustavo F. Padovan 		l2cap_send_cmd(conn, l2cap_get_ident(conn), L2CAP_CONF_REQ,
408573ffa904SGustavo F. Padovan 			       l2cap_build_conf_req(chan, buf), buf);
408673ffa904SGustavo F. Padovan 		chan->num_conf_req++;
40870a708f8fSGustavo F. Padovan 	}
40880a708f8fSGustavo F. Padovan 
40890e8b207eSAndrei Emeltchenko 	/* Got Conf Rsp PENDING from remote side and asume we sent
40900e8b207eSAndrei Emeltchenko 	   Conf Rsp PENDING in the code above */
40910e8b207eSAndrei Emeltchenko 	if (test_bit(CONF_REM_CONF_PEND, &chan->conf_state) &&
40920e8b207eSAndrei Emeltchenko 	    test_bit(CONF_LOC_CONF_PEND, &chan->conf_state)) {
40930e8b207eSAndrei Emeltchenko 
40940e8b207eSAndrei Emeltchenko 		/* check compatibility */
40950e8b207eSAndrei Emeltchenko 
409679de886dSAndrei Emeltchenko 		/* Send rsp for BR/EDR channel */
4097f351bc72SAndrei Emeltchenko 		if (!chan->hs_hcon)
409829d8a590SAndrei Emeltchenko 			l2cap_send_efs_conf_rsp(chan, rsp, cmd->ident, flags);
409979de886dSAndrei Emeltchenko 		else
410079de886dSAndrei Emeltchenko 			chan->ident = cmd->ident;
41010e8b207eSAndrei Emeltchenko 	}
41020e8b207eSAndrei Emeltchenko 
41030a708f8fSGustavo F. Padovan unlock:
41046be36555SAndrei Emeltchenko 	l2cap_chan_unlock(chan);
41053c588192SMat Martineau 	return err;
41060a708f8fSGustavo F. Padovan }
41070a708f8fSGustavo F. Padovan 
41082d792818SGustavo Padovan static inline int l2cap_config_rsp(struct l2cap_conn *conn,
4109cb3b3152SJohan Hedberg 				   struct l2cap_cmd_hdr *cmd, u16 cmd_len,
4110cb3b3152SJohan Hedberg 				   u8 *data)
41110a708f8fSGustavo F. Padovan {
41120a708f8fSGustavo F. Padovan 	struct l2cap_conf_rsp *rsp = (struct l2cap_conf_rsp *)data;
41130a708f8fSGustavo F. Padovan 	u16 scid, flags, result;
411448454079SGustavo F. Padovan 	struct l2cap_chan *chan;
4115cb3b3152SJohan Hedberg 	int len = cmd_len - sizeof(*rsp);
41163c588192SMat Martineau 	int err = 0;
41170a708f8fSGustavo F. Padovan 
4118cb3b3152SJohan Hedberg 	if (cmd_len < sizeof(*rsp))
4119cb3b3152SJohan Hedberg 		return -EPROTO;
4120cb3b3152SJohan Hedberg 
41210a708f8fSGustavo F. Padovan 	scid   = __le16_to_cpu(rsp->scid);
41220a708f8fSGustavo F. Padovan 	flags  = __le16_to_cpu(rsp->flags);
41230a708f8fSGustavo F. Padovan 	result = __le16_to_cpu(rsp->result);
41240a708f8fSGustavo F. Padovan 
412561386cbaSAndrei Emeltchenko 	BT_DBG("scid 0x%4.4x flags 0x%2.2x result 0x%2.2x len %d", scid, flags,
412661386cbaSAndrei Emeltchenko 	       result, len);
41270a708f8fSGustavo F. Padovan 
4128baa7e1faSGustavo F. Padovan 	chan = l2cap_get_chan_by_scid(conn, scid);
412948454079SGustavo F. Padovan 	if (!chan)
41300a708f8fSGustavo F. Padovan 		return 0;
41310a708f8fSGustavo F. Padovan 
41320a708f8fSGustavo F. Padovan 	switch (result) {
41330a708f8fSGustavo F. Padovan 	case L2CAP_CONF_SUCCESS:
413447d1ec61SGustavo F. Padovan 		l2cap_conf_rfc_get(chan, rsp->data, len);
41350e8b207eSAndrei Emeltchenko 		clear_bit(CONF_REM_CONF_PEND, &chan->conf_state);
41360a708f8fSGustavo F. Padovan 		break;
41370a708f8fSGustavo F. Padovan 
41380e8b207eSAndrei Emeltchenko 	case L2CAP_CONF_PENDING:
41390e8b207eSAndrei Emeltchenko 		set_bit(CONF_REM_CONF_PEND, &chan->conf_state);
41400e8b207eSAndrei Emeltchenko 
41410e8b207eSAndrei Emeltchenko 		if (test_bit(CONF_LOC_CONF_PEND, &chan->conf_state)) {
41420e8b207eSAndrei Emeltchenko 			char buf[64];
41430e8b207eSAndrei Emeltchenko 
41440e8b207eSAndrei Emeltchenko 			len = l2cap_parse_conf_rsp(chan, rsp->data, len,
41450e8b207eSAndrei Emeltchenko 						   buf, &result);
41460e8b207eSAndrei Emeltchenko 			if (len < 0) {
41475e4e3972SAndrei Emeltchenko 				l2cap_send_disconn_req(chan, ECONNRESET);
41480e8b207eSAndrei Emeltchenko 				goto done;
41490e8b207eSAndrei Emeltchenko 			}
41500e8b207eSAndrei Emeltchenko 
4151f351bc72SAndrei Emeltchenko 			if (!chan->hs_hcon) {
415279de886dSAndrei Emeltchenko 				l2cap_send_efs_conf_rsp(chan, buf, cmd->ident,
415379de886dSAndrei Emeltchenko 							0);
41545ce66b59SAndrei Emeltchenko 			} else {
41555ce66b59SAndrei Emeltchenko 				if (l2cap_check_efs(chan)) {
41565ce66b59SAndrei Emeltchenko 					amp_create_logical_link(chan);
415779de886dSAndrei Emeltchenko 					chan->ident = cmd->ident;
41580e8b207eSAndrei Emeltchenko 				}
41595ce66b59SAndrei Emeltchenko 			}
41605ce66b59SAndrei Emeltchenko 		}
41610e8b207eSAndrei Emeltchenko 		goto done;
41620e8b207eSAndrei Emeltchenko 
41630a708f8fSGustavo F. Padovan 	case L2CAP_CONF_UNACCEPT:
416473ffa904SGustavo F. Padovan 		if (chan->num_conf_rsp <= L2CAP_CONF_MAX_CONF_RSP) {
41650a708f8fSGustavo F. Padovan 			char req[64];
41660a708f8fSGustavo F. Padovan 
41670a708f8fSGustavo F. Padovan 			if (len > sizeof(req) - sizeof(struct l2cap_conf_req)) {
41685e4e3972SAndrei Emeltchenko 				l2cap_send_disconn_req(chan, ECONNRESET);
41690a708f8fSGustavo F. Padovan 				goto done;
41700a708f8fSGustavo F. Padovan 			}
41710a708f8fSGustavo F. Padovan 
41720a708f8fSGustavo F. Padovan 			/* throw out any old stored conf requests */
41730a708f8fSGustavo F. Padovan 			result = L2CAP_CONF_SUCCESS;
4174b4450035SGustavo F. Padovan 			len = l2cap_parse_conf_rsp(chan, rsp->data, len,
4175b4450035SGustavo F. Padovan 						   req, &result);
41760a708f8fSGustavo F. Padovan 			if (len < 0) {
41775e4e3972SAndrei Emeltchenko 				l2cap_send_disconn_req(chan, ECONNRESET);
41780a708f8fSGustavo F. Padovan 				goto done;
41790a708f8fSGustavo F. Padovan 			}
41800a708f8fSGustavo F. Padovan 
41810a708f8fSGustavo F. Padovan 			l2cap_send_cmd(conn, l2cap_get_ident(conn),
41820a708f8fSGustavo F. Padovan 				       L2CAP_CONF_REQ, len, req);
418373ffa904SGustavo F. Padovan 			chan->num_conf_req++;
41840a708f8fSGustavo F. Padovan 			if (result != L2CAP_CONF_SUCCESS)
41850a708f8fSGustavo F. Padovan 				goto done;
41860a708f8fSGustavo F. Padovan 			break;
41870a708f8fSGustavo F. Padovan 		}
41880a708f8fSGustavo F. Padovan 
41890a708f8fSGustavo F. Padovan 	default:
41906be36555SAndrei Emeltchenko 		l2cap_chan_set_err(chan, ECONNRESET);
41912e0052e4SAndrei Emeltchenko 
4192ba13ccd9SMarcel Holtmann 		__set_chan_timer(chan, L2CAP_DISC_REJ_TIMEOUT);
41935e4e3972SAndrei Emeltchenko 		l2cap_send_disconn_req(chan, ECONNRESET);
41940a708f8fSGustavo F. Padovan 		goto done;
41950a708f8fSGustavo F. Padovan 	}
41960a708f8fSGustavo F. Padovan 
419759e54bd1SAndrei Emeltchenko 	if (flags & L2CAP_CONF_FLAG_CONTINUATION)
41980a708f8fSGustavo F. Padovan 		goto done;
41990a708f8fSGustavo F. Padovan 
4200c1360a1cSGustavo F. Padovan 	set_bit(CONF_INPUT_DONE, &chan->conf_state);
42010a708f8fSGustavo F. Padovan 
4202c1360a1cSGustavo F. Padovan 	if (test_bit(CONF_OUTPUT_DONE, &chan->conf_state)) {
420347d1ec61SGustavo F. Padovan 		set_default_fcs(chan);
42040a708f8fSGustavo F. Padovan 
4205105bdf9eSMat Martineau 		if (chan->mode == L2CAP_MODE_ERTM ||
4206105bdf9eSMat Martineau 		    chan->mode == L2CAP_MODE_STREAMING)
42073c588192SMat Martineau 			err = l2cap_ertm_init(chan);
42080a708f8fSGustavo F. Padovan 
42093c588192SMat Martineau 		if (err < 0)
42105e4e3972SAndrei Emeltchenko 			l2cap_send_disconn_req(chan, -err);
42113c588192SMat Martineau 		else
4212cf4cd009SAndrei Emeltchenko 			l2cap_chan_ready(chan);
42130a708f8fSGustavo F. Padovan 	}
42140a708f8fSGustavo F. Padovan 
42150a708f8fSGustavo F. Padovan done:
42166be36555SAndrei Emeltchenko 	l2cap_chan_unlock(chan);
42173c588192SMat Martineau 	return err;
42180a708f8fSGustavo F. Padovan }
42190a708f8fSGustavo F. Padovan 
42202d792818SGustavo Padovan static inline int l2cap_disconnect_req(struct l2cap_conn *conn,
4221cb3b3152SJohan Hedberg 				       struct l2cap_cmd_hdr *cmd, u16 cmd_len,
4222cb3b3152SJohan Hedberg 				       u8 *data)
42230a708f8fSGustavo F. Padovan {
42240a708f8fSGustavo F. Padovan 	struct l2cap_disconn_req *req = (struct l2cap_disconn_req *) data;
42250a708f8fSGustavo F. Padovan 	struct l2cap_disconn_rsp rsp;
42260a708f8fSGustavo F. Padovan 	u16 dcid, scid;
422748454079SGustavo F. Padovan 	struct l2cap_chan *chan;
42280a708f8fSGustavo F. Padovan 	struct sock *sk;
42290a708f8fSGustavo F. Padovan 
4230cb3b3152SJohan Hedberg 	if (cmd_len != sizeof(*req))
4231cb3b3152SJohan Hedberg 		return -EPROTO;
4232cb3b3152SJohan Hedberg 
42330a708f8fSGustavo F. Padovan 	scid = __le16_to_cpu(req->scid);
42340a708f8fSGustavo F. Padovan 	dcid = __le16_to_cpu(req->dcid);
42350a708f8fSGustavo F. Padovan 
42360a708f8fSGustavo F. Padovan 	BT_DBG("scid 0x%4.4x dcid 0x%4.4x", scid, dcid);
42370a708f8fSGustavo F. Padovan 
42383df91ea2SAndrei Emeltchenko 	mutex_lock(&conn->chan_lock);
42393df91ea2SAndrei Emeltchenko 
42403df91ea2SAndrei Emeltchenko 	chan = __l2cap_get_chan_by_scid(conn, dcid);
42413df91ea2SAndrei Emeltchenko 	if (!chan) {
42423df91ea2SAndrei Emeltchenko 		mutex_unlock(&conn->chan_lock);
4243c4ea249fSJohan Hedberg 		return -EBADSLT;
42443df91ea2SAndrei Emeltchenko 	}
42450a708f8fSGustavo F. Padovan 
42466be36555SAndrei Emeltchenko 	l2cap_chan_lock(chan);
42476be36555SAndrei Emeltchenko 
424848454079SGustavo F. Padovan 	sk = chan->sk;
424948454079SGustavo F. Padovan 
4250fe4128e0SGustavo F. Padovan 	rsp.dcid = cpu_to_le16(chan->scid);
4251fe4128e0SGustavo F. Padovan 	rsp.scid = cpu_to_le16(chan->dcid);
42520a708f8fSGustavo F. Padovan 	l2cap_send_cmd(conn, cmd->ident, L2CAP_DISCONN_RSP, sizeof(rsp), &rsp);
42530a708f8fSGustavo F. Padovan 
42546be36555SAndrei Emeltchenko 	lock_sock(sk);
42550a708f8fSGustavo F. Padovan 	sk->sk_shutdown = SHUTDOWN_MASK;
42566be36555SAndrei Emeltchenko 	release_sock(sk);
42570a708f8fSGustavo F. Padovan 
425861d6ef3eSMat Martineau 	l2cap_chan_hold(chan);
425948454079SGustavo F. Padovan 	l2cap_chan_del(chan, ECONNRESET);
42606be36555SAndrei Emeltchenko 
42616be36555SAndrei Emeltchenko 	l2cap_chan_unlock(chan);
42620a708f8fSGustavo F. Padovan 
426380b98027SGustavo Padovan 	chan->ops->close(chan);
426461d6ef3eSMat Martineau 	l2cap_chan_put(chan);
42653df91ea2SAndrei Emeltchenko 
42663df91ea2SAndrei Emeltchenko 	mutex_unlock(&conn->chan_lock);
42673df91ea2SAndrei Emeltchenko 
42680a708f8fSGustavo F. Padovan 	return 0;
42690a708f8fSGustavo F. Padovan }
42700a708f8fSGustavo F. Padovan 
42712d792818SGustavo Padovan static inline int l2cap_disconnect_rsp(struct l2cap_conn *conn,
4272cb3b3152SJohan Hedberg 				       struct l2cap_cmd_hdr *cmd, u16 cmd_len,
4273cb3b3152SJohan Hedberg 				       u8 *data)
42740a708f8fSGustavo F. Padovan {
42750a708f8fSGustavo F. Padovan 	struct l2cap_disconn_rsp *rsp = (struct l2cap_disconn_rsp *) data;
42760a708f8fSGustavo F. Padovan 	u16 dcid, scid;
427748454079SGustavo F. Padovan 	struct l2cap_chan *chan;
42780a708f8fSGustavo F. Padovan 
4279cb3b3152SJohan Hedberg 	if (cmd_len != sizeof(*rsp))
4280cb3b3152SJohan Hedberg 		return -EPROTO;
4281cb3b3152SJohan Hedberg 
42820a708f8fSGustavo F. Padovan 	scid = __le16_to_cpu(rsp->scid);
42830a708f8fSGustavo F. Padovan 	dcid = __le16_to_cpu(rsp->dcid);
42840a708f8fSGustavo F. Padovan 
42850a708f8fSGustavo F. Padovan 	BT_DBG("dcid 0x%4.4x scid 0x%4.4x", dcid, scid);
42860a708f8fSGustavo F. Padovan 
42873df91ea2SAndrei Emeltchenko 	mutex_lock(&conn->chan_lock);
42883df91ea2SAndrei Emeltchenko 
42893df91ea2SAndrei Emeltchenko 	chan = __l2cap_get_chan_by_scid(conn, scid);
42903df91ea2SAndrei Emeltchenko 	if (!chan) {
42913df91ea2SAndrei Emeltchenko 		mutex_unlock(&conn->chan_lock);
42920a708f8fSGustavo F. Padovan 		return 0;
42933df91ea2SAndrei Emeltchenko 	}
42940a708f8fSGustavo F. Padovan 
42956be36555SAndrei Emeltchenko 	l2cap_chan_lock(chan);
429648454079SGustavo F. Padovan 
429761d6ef3eSMat Martineau 	l2cap_chan_hold(chan);
429848454079SGustavo F. Padovan 	l2cap_chan_del(chan, 0);
42996be36555SAndrei Emeltchenko 
43006be36555SAndrei Emeltchenko 	l2cap_chan_unlock(chan);
43010a708f8fSGustavo F. Padovan 
430280b98027SGustavo Padovan 	chan->ops->close(chan);
430361d6ef3eSMat Martineau 	l2cap_chan_put(chan);
43043df91ea2SAndrei Emeltchenko 
43053df91ea2SAndrei Emeltchenko 	mutex_unlock(&conn->chan_lock);
43063df91ea2SAndrei Emeltchenko 
43070a708f8fSGustavo F. Padovan 	return 0;
43080a708f8fSGustavo F. Padovan }
43090a708f8fSGustavo F. Padovan 
43102d792818SGustavo Padovan static inline int l2cap_information_req(struct l2cap_conn *conn,
4311cb3b3152SJohan Hedberg 					struct l2cap_cmd_hdr *cmd, u16 cmd_len,
4312cb3b3152SJohan Hedberg 					u8 *data)
43130a708f8fSGustavo F. Padovan {
43140a708f8fSGustavo F. Padovan 	struct l2cap_info_req *req = (struct l2cap_info_req *) data;
43150a708f8fSGustavo F. Padovan 	u16 type;
43160a708f8fSGustavo F. Padovan 
4317cb3b3152SJohan Hedberg 	if (cmd_len != sizeof(*req))
4318cb3b3152SJohan Hedberg 		return -EPROTO;
4319cb3b3152SJohan Hedberg 
43200a708f8fSGustavo F. Padovan 	type = __le16_to_cpu(req->type);
43210a708f8fSGustavo F. Padovan 
43220a708f8fSGustavo F. Padovan 	BT_DBG("type 0x%4.4x", type);
43230a708f8fSGustavo F. Padovan 
43240a708f8fSGustavo F. Padovan 	if (type == L2CAP_IT_FEAT_MASK) {
43250a708f8fSGustavo F. Padovan 		u8 buf[8];
43260a708f8fSGustavo F. Padovan 		u32 feat_mask = l2cap_feat_mask;
43270a708f8fSGustavo F. Padovan 		struct l2cap_info_rsp *rsp = (struct l2cap_info_rsp *) buf;
4328ac73498cSAndrei Emeltchenko 		rsp->type   = __constant_cpu_to_le16(L2CAP_IT_FEAT_MASK);
4329ac73498cSAndrei Emeltchenko 		rsp->result = __constant_cpu_to_le16(L2CAP_IR_SUCCESS);
43300a708f8fSGustavo F. Padovan 		if (!disable_ertm)
43310a708f8fSGustavo F. Padovan 			feat_mask |= L2CAP_FEAT_ERTM | L2CAP_FEAT_STREAMING
43320a708f8fSGustavo F. Padovan 				| L2CAP_FEAT_FCS;
4333848566b3SMarcel Holtmann 		if (conn->hs_enabled)
43346327eb98SAndrei Emeltchenko 			feat_mask |= L2CAP_FEAT_EXT_FLOW
43356327eb98SAndrei Emeltchenko 				| L2CAP_FEAT_EXT_WINDOW;
4336a5fd6f30SAndrei Emeltchenko 
43370a708f8fSGustavo F. Padovan 		put_unaligned_le32(feat_mask, rsp->data);
43382d792818SGustavo Padovan 		l2cap_send_cmd(conn, cmd->ident, L2CAP_INFO_RSP, sizeof(buf),
43392d792818SGustavo Padovan 			       buf);
43400a708f8fSGustavo F. Padovan 	} else if (type == L2CAP_IT_FIXED_CHAN) {
43410a708f8fSGustavo F. Padovan 		u8 buf[12];
43420a708f8fSGustavo F. Padovan 		struct l2cap_info_rsp *rsp = (struct l2cap_info_rsp *) buf;
434350a147cdSMat Martineau 
4344848566b3SMarcel Holtmann 		if (conn->hs_enabled)
434550a147cdSMat Martineau 			l2cap_fixed_chan[0] |= L2CAP_FC_A2MP;
434650a147cdSMat Martineau 		else
434750a147cdSMat Martineau 			l2cap_fixed_chan[0] &= ~L2CAP_FC_A2MP;
434850a147cdSMat Martineau 
4349ac73498cSAndrei Emeltchenko 		rsp->type   = __constant_cpu_to_le16(L2CAP_IT_FIXED_CHAN);
4350ac73498cSAndrei Emeltchenko 		rsp->result = __constant_cpu_to_le16(L2CAP_IR_SUCCESS);
4351c6337ea6SAndrei Emeltchenko 		memcpy(rsp->data, l2cap_fixed_chan, sizeof(l2cap_fixed_chan));
43522d792818SGustavo Padovan 		l2cap_send_cmd(conn, cmd->ident, L2CAP_INFO_RSP, sizeof(buf),
43532d792818SGustavo Padovan 			       buf);
43540a708f8fSGustavo F. Padovan 	} else {
43550a708f8fSGustavo F. Padovan 		struct l2cap_info_rsp rsp;
43560a708f8fSGustavo F. Padovan 		rsp.type   = cpu_to_le16(type);
4357ac73498cSAndrei Emeltchenko 		rsp.result = __constant_cpu_to_le16(L2CAP_IR_NOTSUPP);
43582d792818SGustavo Padovan 		l2cap_send_cmd(conn, cmd->ident, L2CAP_INFO_RSP, sizeof(rsp),
43592d792818SGustavo Padovan 			       &rsp);
43600a708f8fSGustavo F. Padovan 	}
43610a708f8fSGustavo F. Padovan 
43620a708f8fSGustavo F. Padovan 	return 0;
43630a708f8fSGustavo F. Padovan }
43640a708f8fSGustavo F. Padovan 
43652d792818SGustavo Padovan static inline int l2cap_information_rsp(struct l2cap_conn *conn,
4366cb3b3152SJohan Hedberg 					struct l2cap_cmd_hdr *cmd, u16 cmd_len,
4367cb3b3152SJohan Hedberg 					u8 *data)
43680a708f8fSGustavo F. Padovan {
43690a708f8fSGustavo F. Padovan 	struct l2cap_info_rsp *rsp = (struct l2cap_info_rsp *) data;
43700a708f8fSGustavo F. Padovan 	u16 type, result;
43710a708f8fSGustavo F. Padovan 
43723f6fa3d4SJaganath Kanakkassery 	if (cmd_len < sizeof(*rsp))
4373cb3b3152SJohan Hedberg 		return -EPROTO;
4374cb3b3152SJohan Hedberg 
43750a708f8fSGustavo F. Padovan 	type   = __le16_to_cpu(rsp->type);
43760a708f8fSGustavo F. Padovan 	result = __le16_to_cpu(rsp->result);
43770a708f8fSGustavo F. Padovan 
43780a708f8fSGustavo F. Padovan 	BT_DBG("type 0x%4.4x result 0x%2.2x", type, result);
43790a708f8fSGustavo F. Padovan 
4380e90165beSAndrei Emeltchenko 	/* L2CAP Info req/rsp are unbound to channels, add extra checks */
4381e90165beSAndrei Emeltchenko 	if (cmd->ident != conn->info_ident ||
4382e90165beSAndrei Emeltchenko 	    conn->info_state & L2CAP_INFO_FEAT_MASK_REQ_DONE)
4383e90165beSAndrei Emeltchenko 		return 0;
4384e90165beSAndrei Emeltchenko 
438517cd3f37SUlisses Furquim 	cancel_delayed_work(&conn->info_timer);
43860a708f8fSGustavo F. Padovan 
43870a708f8fSGustavo F. Padovan 	if (result != L2CAP_IR_SUCCESS) {
43880a708f8fSGustavo F. Padovan 		conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_DONE;
43890a708f8fSGustavo F. Padovan 		conn->info_ident = 0;
43900a708f8fSGustavo F. Padovan 
43910a708f8fSGustavo F. Padovan 		l2cap_conn_start(conn);
43920a708f8fSGustavo F. Padovan 
43930a708f8fSGustavo F. Padovan 		return 0;
43940a708f8fSGustavo F. Padovan 	}
43950a708f8fSGustavo F. Padovan 
4396978c93b9SAndrei Emeltchenko 	switch (type) {
4397978c93b9SAndrei Emeltchenko 	case L2CAP_IT_FEAT_MASK:
43980a708f8fSGustavo F. Padovan 		conn->feat_mask = get_unaligned_le32(rsp->data);
43990a708f8fSGustavo F. Padovan 
44000a708f8fSGustavo F. Padovan 		if (conn->feat_mask & L2CAP_FEAT_FIXED_CHAN) {
44010a708f8fSGustavo F. Padovan 			struct l2cap_info_req req;
4402ac73498cSAndrei Emeltchenko 			req.type = __constant_cpu_to_le16(L2CAP_IT_FIXED_CHAN);
44030a708f8fSGustavo F. Padovan 
44040a708f8fSGustavo F. Padovan 			conn->info_ident = l2cap_get_ident(conn);
44050a708f8fSGustavo F. Padovan 
44060a708f8fSGustavo F. Padovan 			l2cap_send_cmd(conn, conn->info_ident,
44070a708f8fSGustavo F. Padovan 				       L2CAP_INFO_REQ, sizeof(req), &req);
44080a708f8fSGustavo F. Padovan 		} else {
44090a708f8fSGustavo F. Padovan 			conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_DONE;
44100a708f8fSGustavo F. Padovan 			conn->info_ident = 0;
44110a708f8fSGustavo F. Padovan 
44120a708f8fSGustavo F. Padovan 			l2cap_conn_start(conn);
44130a708f8fSGustavo F. Padovan 		}
4414978c93b9SAndrei Emeltchenko 		break;
4415978c93b9SAndrei Emeltchenko 
4416978c93b9SAndrei Emeltchenko 	case L2CAP_IT_FIXED_CHAN:
4417978c93b9SAndrei Emeltchenko 		conn->fixed_chan_mask = rsp->data[0];
44180a708f8fSGustavo F. Padovan 		conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_DONE;
44190a708f8fSGustavo F. Padovan 		conn->info_ident = 0;
44200a708f8fSGustavo F. Padovan 
44210a708f8fSGustavo F. Padovan 		l2cap_conn_start(conn);
4422978c93b9SAndrei Emeltchenko 		break;
44230a708f8fSGustavo F. Padovan 	}
44240a708f8fSGustavo F. Padovan 
44250a708f8fSGustavo F. Padovan 	return 0;
44260a708f8fSGustavo F. Padovan }
44270a708f8fSGustavo F. Padovan 
44281700915fSMat Martineau static int l2cap_create_channel_req(struct l2cap_conn *conn,
44292d792818SGustavo Padovan 				    struct l2cap_cmd_hdr *cmd,
44302d792818SGustavo Padovan 				    u16 cmd_len, void *data)
4431f94ff6ffSMat Martineau {
4432f94ff6ffSMat Martineau 	struct l2cap_create_chan_req *req = data;
44336e1df6a6SAndrei Emeltchenko 	struct l2cap_create_chan_rsp rsp;
44341700915fSMat Martineau 	struct l2cap_chan *chan;
44356e1df6a6SAndrei Emeltchenko 	struct hci_dev *hdev;
4436f94ff6ffSMat Martineau 	u16 psm, scid;
4437f94ff6ffSMat Martineau 
4438f94ff6ffSMat Martineau 	if (cmd_len != sizeof(*req))
4439f94ff6ffSMat Martineau 		return -EPROTO;
4440f94ff6ffSMat Martineau 
4441848566b3SMarcel Holtmann 	if (!conn->hs_enabled)
4442f94ff6ffSMat Martineau 		return -EINVAL;
4443f94ff6ffSMat Martineau 
4444f94ff6ffSMat Martineau 	psm = le16_to_cpu(req->psm);
4445f94ff6ffSMat Martineau 	scid = le16_to_cpu(req->scid);
4446f94ff6ffSMat Martineau 
4447ad0ac6caSAndrei Emeltchenko 	BT_DBG("psm 0x%2.2x, scid 0x%4.4x, amp_id %d", psm, scid, req->amp_id);
4448f94ff6ffSMat Martineau 
44496e1df6a6SAndrei Emeltchenko 	/* For controller id 0 make BR/EDR connection */
44506ed971caSMarcel Holtmann 	if (req->amp_id == AMP_ID_BREDR) {
44516e1df6a6SAndrei Emeltchenko 		l2cap_connect(conn, cmd, data, L2CAP_CREATE_CHAN_RSP,
44526e1df6a6SAndrei Emeltchenko 			      req->amp_id);
44536e1df6a6SAndrei Emeltchenko 		return 0;
44546e1df6a6SAndrei Emeltchenko 	}
44551700915fSMat Martineau 
44561700915fSMat Martineau 	/* Validate AMP controller id */
44571700915fSMat Martineau 	hdev = hci_dev_get(req->amp_id);
44586e1df6a6SAndrei Emeltchenko 	if (!hdev)
44596e1df6a6SAndrei Emeltchenko 		goto error;
44601700915fSMat Martineau 
44616e1df6a6SAndrei Emeltchenko 	if (hdev->dev_type != HCI_AMP || !test_bit(HCI_UP, &hdev->flags)) {
44626e1df6a6SAndrei Emeltchenko 		hci_dev_put(hdev);
44636e1df6a6SAndrei Emeltchenko 		goto error;
44646e1df6a6SAndrei Emeltchenko 	}
44656e1df6a6SAndrei Emeltchenko 
44666e1df6a6SAndrei Emeltchenko 	chan = l2cap_connect(conn, cmd, data, L2CAP_CREATE_CHAN_RSP,
44676e1df6a6SAndrei Emeltchenko 			     req->amp_id);
44686e1df6a6SAndrei Emeltchenko 	if (chan) {
44696e1df6a6SAndrei Emeltchenko 		struct amp_mgr *mgr = conn->hcon->amp_mgr;
44706e1df6a6SAndrei Emeltchenko 		struct hci_conn *hs_hcon;
44716e1df6a6SAndrei Emeltchenko 
44726e1df6a6SAndrei Emeltchenko 		hs_hcon = hci_conn_hash_lookup_ba(hdev, AMP_LINK, conn->dst);
44736e1df6a6SAndrei Emeltchenko 		if (!hs_hcon) {
44746e1df6a6SAndrei Emeltchenko 			hci_dev_put(hdev);
447521870b52SJohan Hedberg 			return -EBADSLT;
44766e1df6a6SAndrei Emeltchenko 		}
44776e1df6a6SAndrei Emeltchenko 
44786e1df6a6SAndrei Emeltchenko 		BT_DBG("mgr %p bredr_chan %p hs_hcon %p", mgr, chan, hs_hcon);
44796e1df6a6SAndrei Emeltchenko 
44806e1df6a6SAndrei Emeltchenko 		mgr->bredr_chan = chan;
44816e1df6a6SAndrei Emeltchenko 		chan->hs_hcon = hs_hcon;
4482fd45bf4cSAndrei Emeltchenko 		chan->fcs = L2CAP_FCS_NONE;
44836e1df6a6SAndrei Emeltchenko 		conn->mtu = hdev->block_mtu;
44846e1df6a6SAndrei Emeltchenko 	}
44856e1df6a6SAndrei Emeltchenko 
44866e1df6a6SAndrei Emeltchenko 	hci_dev_put(hdev);
44876e1df6a6SAndrei Emeltchenko 
44886e1df6a6SAndrei Emeltchenko 	return 0;
44896e1df6a6SAndrei Emeltchenko 
44906e1df6a6SAndrei Emeltchenko error:
4491f94ff6ffSMat Martineau 	rsp.dcid = 0;
4492f94ff6ffSMat Martineau 	rsp.scid = cpu_to_le16(scid);
44931700915fSMat Martineau 	rsp.result = __constant_cpu_to_le16(L2CAP_CR_BAD_AMP);
44948ce0c498SAndrei Emeltchenko 	rsp.status = __constant_cpu_to_le16(L2CAP_CS_NO_INFO);
4495f94ff6ffSMat Martineau 
4496f94ff6ffSMat Martineau 	l2cap_send_cmd(conn, cmd->ident, L2CAP_CREATE_CHAN_RSP,
4497f94ff6ffSMat Martineau 		       sizeof(rsp), &rsp);
4498f94ff6ffSMat Martineau 
4499dc280801SJohan Hedberg 	return 0;
4500f94ff6ffSMat Martineau }
4501f94ff6ffSMat Martineau 
45028eb200bdSMat Martineau static void l2cap_send_move_chan_req(struct l2cap_chan *chan, u8 dest_amp_id)
45038eb200bdSMat Martineau {
45048eb200bdSMat Martineau 	struct l2cap_move_chan_req req;
45058eb200bdSMat Martineau 	u8 ident;
45068eb200bdSMat Martineau 
45078eb200bdSMat Martineau 	BT_DBG("chan %p, dest_amp_id %d", chan, dest_amp_id);
45088eb200bdSMat Martineau 
45098eb200bdSMat Martineau 	ident = l2cap_get_ident(chan->conn);
45108eb200bdSMat Martineau 	chan->ident = ident;
45118eb200bdSMat Martineau 
45128eb200bdSMat Martineau 	req.icid = cpu_to_le16(chan->scid);
45138eb200bdSMat Martineau 	req.dest_amp_id = dest_amp_id;
45148eb200bdSMat Martineau 
45158eb200bdSMat Martineau 	l2cap_send_cmd(chan->conn, ident, L2CAP_MOVE_CHAN_REQ, sizeof(req),
45168eb200bdSMat Martineau 		       &req);
45178eb200bdSMat Martineau 
45188eb200bdSMat Martineau 	__set_chan_timer(chan, L2CAP_MOVE_TIMEOUT);
45198eb200bdSMat Martineau }
45208eb200bdSMat Martineau 
45211500109bSMat Martineau static void l2cap_send_move_chan_rsp(struct l2cap_chan *chan, u16 result)
45228d5a04a1SMat Martineau {
45238d5a04a1SMat Martineau 	struct l2cap_move_chan_rsp rsp;
45248d5a04a1SMat Martineau 
45251500109bSMat Martineau 	BT_DBG("chan %p, result 0x%4.4x", chan, result);
45268d5a04a1SMat Martineau 
45271500109bSMat Martineau 	rsp.icid = cpu_to_le16(chan->dcid);
45288d5a04a1SMat Martineau 	rsp.result = cpu_to_le16(result);
45298d5a04a1SMat Martineau 
45301500109bSMat Martineau 	l2cap_send_cmd(chan->conn, chan->ident, L2CAP_MOVE_CHAN_RSP,
45311500109bSMat Martineau 		       sizeof(rsp), &rsp);
45328d5a04a1SMat Martineau }
45338d5a04a1SMat Martineau 
45345b155ef9SMat Martineau static void l2cap_send_move_chan_cfm(struct l2cap_chan *chan, u16 result)
45358d5a04a1SMat Martineau {
45368d5a04a1SMat Martineau 	struct l2cap_move_chan_cfm cfm;
45378d5a04a1SMat Martineau 
45385b155ef9SMat Martineau 	BT_DBG("chan %p, result 0x%4.4x", chan, result);
45398d5a04a1SMat Martineau 
45405b155ef9SMat Martineau 	chan->ident = l2cap_get_ident(chan->conn);
45418d5a04a1SMat Martineau 
45425b155ef9SMat Martineau 	cfm.icid = cpu_to_le16(chan->scid);
45438d5a04a1SMat Martineau 	cfm.result = cpu_to_le16(result);
45448d5a04a1SMat Martineau 
45455b155ef9SMat Martineau 	l2cap_send_cmd(chan->conn, chan->ident, L2CAP_MOVE_CHAN_CFM,
45465b155ef9SMat Martineau 		       sizeof(cfm), &cfm);
45475b155ef9SMat Martineau 
45485b155ef9SMat Martineau 	__set_chan_timer(chan, L2CAP_MOVE_TIMEOUT);
45495b155ef9SMat Martineau }
45505b155ef9SMat Martineau 
45515b155ef9SMat Martineau static void l2cap_send_move_chan_cfm_icid(struct l2cap_conn *conn, u16 icid)
45525b155ef9SMat Martineau {
45535b155ef9SMat Martineau 	struct l2cap_move_chan_cfm cfm;
45545b155ef9SMat Martineau 
45555b155ef9SMat Martineau 	BT_DBG("conn %p, icid 0x%4.4x", conn, icid);
45565b155ef9SMat Martineau 
45575b155ef9SMat Martineau 	cfm.icid = cpu_to_le16(icid);
45585b155ef9SMat Martineau 	cfm.result = __constant_cpu_to_le16(L2CAP_MC_UNCONFIRMED);
45595b155ef9SMat Martineau 
45605b155ef9SMat Martineau 	l2cap_send_cmd(conn, l2cap_get_ident(conn), L2CAP_MOVE_CHAN_CFM,
45615b155ef9SMat Martineau 		       sizeof(cfm), &cfm);
45628d5a04a1SMat Martineau }
45638d5a04a1SMat Martineau 
45648d5a04a1SMat Martineau static void l2cap_send_move_chan_cfm_rsp(struct l2cap_conn *conn, u8 ident,
45658d5a04a1SMat Martineau 					 u16 icid)
45668d5a04a1SMat Martineau {
45678d5a04a1SMat Martineau 	struct l2cap_move_chan_cfm_rsp rsp;
45688d5a04a1SMat Martineau 
4569ad0ac6caSAndrei Emeltchenko 	BT_DBG("icid 0x%4.4x", icid);
45708d5a04a1SMat Martineau 
45718d5a04a1SMat Martineau 	rsp.icid = cpu_to_le16(icid);
45728d5a04a1SMat Martineau 	l2cap_send_cmd(conn, ident, L2CAP_MOVE_CHAN_CFM_RSP, sizeof(rsp), &rsp);
45738d5a04a1SMat Martineau }
45748d5a04a1SMat Martineau 
45755f3847a4SMat Martineau static void __release_logical_link(struct l2cap_chan *chan)
45765f3847a4SMat Martineau {
45775f3847a4SMat Martineau 	chan->hs_hchan = NULL;
45785f3847a4SMat Martineau 	chan->hs_hcon = NULL;
45795f3847a4SMat Martineau 
45805f3847a4SMat Martineau 	/* Placeholder - release the logical link */
45815f3847a4SMat Martineau }
45825f3847a4SMat Martineau 
45831500109bSMat Martineau static void l2cap_logical_fail(struct l2cap_chan *chan)
45841500109bSMat Martineau {
45851500109bSMat Martineau 	/* Logical link setup failed */
45861500109bSMat Martineau 	if (chan->state != BT_CONNECTED) {
45871500109bSMat Martineau 		/* Create channel failure, disconnect */
45885e4e3972SAndrei Emeltchenko 		l2cap_send_disconn_req(chan, ECONNRESET);
45891500109bSMat Martineau 		return;
45901500109bSMat Martineau 	}
45911500109bSMat Martineau 
45921500109bSMat Martineau 	switch (chan->move_role) {
45931500109bSMat Martineau 	case L2CAP_MOVE_ROLE_RESPONDER:
45941500109bSMat Martineau 		l2cap_move_done(chan);
45951500109bSMat Martineau 		l2cap_send_move_chan_rsp(chan, L2CAP_MR_NOT_SUPP);
45961500109bSMat Martineau 		break;
45971500109bSMat Martineau 	case L2CAP_MOVE_ROLE_INITIATOR:
45981500109bSMat Martineau 		if (chan->move_state == L2CAP_MOVE_WAIT_LOGICAL_COMP ||
45991500109bSMat Martineau 		    chan->move_state == L2CAP_MOVE_WAIT_LOGICAL_CFM) {
46001500109bSMat Martineau 			/* Remote has only sent pending or
46011500109bSMat Martineau 			 * success responses, clean up
46021500109bSMat Martineau 			 */
46031500109bSMat Martineau 			l2cap_move_done(chan);
46041500109bSMat Martineau 		}
46051500109bSMat Martineau 
46061500109bSMat Martineau 		/* Other amp move states imply that the move
46071500109bSMat Martineau 		 * has already aborted
46081500109bSMat Martineau 		 */
46091500109bSMat Martineau 		l2cap_send_move_chan_cfm(chan, L2CAP_MC_UNCONFIRMED);
46101500109bSMat Martineau 		break;
46111500109bSMat Martineau 	}
46121500109bSMat Martineau }
46131500109bSMat Martineau 
46141500109bSMat Martineau static void l2cap_logical_finish_create(struct l2cap_chan *chan,
46151500109bSMat Martineau 					struct hci_chan *hchan)
46161500109bSMat Martineau {
46171500109bSMat Martineau 	struct l2cap_conf_rsp rsp;
46181500109bSMat Martineau 
4619336178a3SAndrei Emeltchenko 	chan->hs_hchan = hchan;
46201500109bSMat Martineau 	chan->hs_hcon->l2cap_data = chan->conn;
46211500109bSMat Martineau 
462235ba9561SAndrei Emeltchenko 	l2cap_send_efs_conf_rsp(chan, &rsp, chan->ident, 0);
46231500109bSMat Martineau 
46241500109bSMat Martineau 	if (test_bit(CONF_INPUT_DONE, &chan->conf_state)) {
4625fe79c6feSAndrei Emeltchenko 		int err;
46261500109bSMat Martineau 
46271500109bSMat Martineau 		set_default_fcs(chan);
46281500109bSMat Martineau 
46291500109bSMat Martineau 		err = l2cap_ertm_init(chan);
46301500109bSMat Martineau 		if (err < 0)
46315e4e3972SAndrei Emeltchenko 			l2cap_send_disconn_req(chan, -err);
46321500109bSMat Martineau 		else
46331500109bSMat Martineau 			l2cap_chan_ready(chan);
46341500109bSMat Martineau 	}
46351500109bSMat Martineau }
46361500109bSMat Martineau 
46371500109bSMat Martineau static void l2cap_logical_finish_move(struct l2cap_chan *chan,
46381500109bSMat Martineau 				      struct hci_chan *hchan)
46391500109bSMat Martineau {
46401500109bSMat Martineau 	chan->hs_hcon = hchan->conn;
46411500109bSMat Martineau 	chan->hs_hcon->l2cap_data = chan->conn;
46421500109bSMat Martineau 
46431500109bSMat Martineau 	BT_DBG("move_state %d", chan->move_state);
46441500109bSMat Martineau 
46451500109bSMat Martineau 	switch (chan->move_state) {
46461500109bSMat Martineau 	case L2CAP_MOVE_WAIT_LOGICAL_COMP:
46471500109bSMat Martineau 		/* Move confirm will be sent after a success
46481500109bSMat Martineau 		 * response is received
46491500109bSMat Martineau 		 */
46501500109bSMat Martineau 		chan->move_state = L2CAP_MOVE_WAIT_RSP_SUCCESS;
46511500109bSMat Martineau 		break;
46521500109bSMat Martineau 	case L2CAP_MOVE_WAIT_LOGICAL_CFM:
46531500109bSMat Martineau 		if (test_bit(CONN_LOCAL_BUSY, &chan->conn_state)) {
46541500109bSMat Martineau 			chan->move_state = L2CAP_MOVE_WAIT_LOCAL_BUSY;
46551500109bSMat Martineau 		} else if (chan->move_role == L2CAP_MOVE_ROLE_INITIATOR) {
46561500109bSMat Martineau 			chan->move_state = L2CAP_MOVE_WAIT_CONFIRM_RSP;
46571500109bSMat Martineau 			l2cap_send_move_chan_cfm(chan, L2CAP_MC_CONFIRMED);
46581500109bSMat Martineau 		} else if (chan->move_role == L2CAP_MOVE_ROLE_RESPONDER) {
46591500109bSMat Martineau 			chan->move_state = L2CAP_MOVE_WAIT_CONFIRM;
46601500109bSMat Martineau 			l2cap_send_move_chan_rsp(chan, L2CAP_MR_SUCCESS);
46611500109bSMat Martineau 		}
46621500109bSMat Martineau 		break;
46631500109bSMat Martineau 	default:
46641500109bSMat Martineau 		/* Move was not in expected state, free the channel */
46651500109bSMat Martineau 		__release_logical_link(chan);
46661500109bSMat Martineau 
46671500109bSMat Martineau 		chan->move_state = L2CAP_MOVE_STABLE;
46681500109bSMat Martineau 	}
46691500109bSMat Martineau }
46701500109bSMat Martineau 
46711500109bSMat Martineau /* Call with chan locked */
467227695fb4SAndrei Emeltchenko void l2cap_logical_cfm(struct l2cap_chan *chan, struct hci_chan *hchan,
46735b155ef9SMat Martineau 		       u8 status)
46745b155ef9SMat Martineau {
46751500109bSMat Martineau 	BT_DBG("chan %p, hchan %p, status %d", chan, hchan, status);
46761500109bSMat Martineau 
46771500109bSMat Martineau 	if (status) {
46781500109bSMat Martineau 		l2cap_logical_fail(chan);
46791500109bSMat Martineau 		__release_logical_link(chan);
46805b155ef9SMat Martineau 		return;
46815b155ef9SMat Martineau 	}
46825b155ef9SMat Martineau 
46831500109bSMat Martineau 	if (chan->state != BT_CONNECTED) {
46841500109bSMat Martineau 		/* Ignore logical link if channel is on BR/EDR */
46856ed971caSMarcel Holtmann 		if (chan->local_amp_id != AMP_ID_BREDR)
46861500109bSMat Martineau 			l2cap_logical_finish_create(chan, hchan);
46871500109bSMat Martineau 	} else {
46881500109bSMat Martineau 		l2cap_logical_finish_move(chan, hchan);
46891500109bSMat Martineau 	}
46901500109bSMat Martineau }
46911500109bSMat Martineau 
46923f7a56c4SMat Martineau void l2cap_move_start(struct l2cap_chan *chan)
46933f7a56c4SMat Martineau {
46943f7a56c4SMat Martineau 	BT_DBG("chan %p", chan);
46953f7a56c4SMat Martineau 
46966ed971caSMarcel Holtmann 	if (chan->local_amp_id == AMP_ID_BREDR) {
46973f7a56c4SMat Martineau 		if (chan->chan_policy != BT_CHANNEL_POLICY_AMP_PREFERRED)
46983f7a56c4SMat Martineau 			return;
46993f7a56c4SMat Martineau 		chan->move_role = L2CAP_MOVE_ROLE_INITIATOR;
47003f7a56c4SMat Martineau 		chan->move_state = L2CAP_MOVE_WAIT_PREPARE;
47013f7a56c4SMat Martineau 		/* Placeholder - start physical link setup */
47023f7a56c4SMat Martineau 	} else {
47033f7a56c4SMat Martineau 		chan->move_role = L2CAP_MOVE_ROLE_INITIATOR;
47043f7a56c4SMat Martineau 		chan->move_state = L2CAP_MOVE_WAIT_RSP_SUCCESS;
47053f7a56c4SMat Martineau 		chan->move_id = 0;
47063f7a56c4SMat Martineau 		l2cap_move_setup(chan);
47073f7a56c4SMat Martineau 		l2cap_send_move_chan_req(chan, 0);
47083f7a56c4SMat Martineau 	}
47093f7a56c4SMat Martineau }
47103f7a56c4SMat Martineau 
47118eb200bdSMat Martineau static void l2cap_do_create(struct l2cap_chan *chan, int result,
47128eb200bdSMat Martineau 			    u8 local_amp_id, u8 remote_amp_id)
47138eb200bdSMat Martineau {
471462748ca1SAndrei Emeltchenko 	BT_DBG("chan %p state %s %u -> %u", chan, state_to_string(chan->state),
471562748ca1SAndrei Emeltchenko 	       local_amp_id, remote_amp_id);
471662748ca1SAndrei Emeltchenko 
471712d6cc60SAndrei Emeltchenko 	chan->fcs = L2CAP_FCS_NONE;
471812d6cc60SAndrei Emeltchenko 
471962748ca1SAndrei Emeltchenko 	/* Outgoing channel on AMP */
472062748ca1SAndrei Emeltchenko 	if (chan->state == BT_CONNECT) {
472162748ca1SAndrei Emeltchenko 		if (result == L2CAP_CR_SUCCESS) {
472262748ca1SAndrei Emeltchenko 			chan->local_amp_id = local_amp_id;
472362748ca1SAndrei Emeltchenko 			l2cap_send_create_chan_req(chan, remote_amp_id);
472462748ca1SAndrei Emeltchenko 		} else {
472562748ca1SAndrei Emeltchenko 			/* Revert to BR/EDR connect */
472662748ca1SAndrei Emeltchenko 			l2cap_send_conn_req(chan);
472762748ca1SAndrei Emeltchenko 		}
472862748ca1SAndrei Emeltchenko 
472962748ca1SAndrei Emeltchenko 		return;
473062748ca1SAndrei Emeltchenko 	}
473162748ca1SAndrei Emeltchenko 
473262748ca1SAndrei Emeltchenko 	/* Incoming channel on AMP */
473362748ca1SAndrei Emeltchenko 	if (__l2cap_no_conn_pending(chan)) {
47348eb200bdSMat Martineau 		struct l2cap_conn_rsp rsp;
47358eb200bdSMat Martineau 		char buf[128];
47368eb200bdSMat Martineau 		rsp.scid = cpu_to_le16(chan->dcid);
47378eb200bdSMat Martineau 		rsp.dcid = cpu_to_le16(chan->scid);
47388eb200bdSMat Martineau 
47398eb200bdSMat Martineau 		if (result == L2CAP_CR_SUCCESS) {
47408eb200bdSMat Martineau 			/* Send successful response */
474162cd50e2SAndrei Emeltchenko 			rsp.result = __constant_cpu_to_le16(L2CAP_CR_SUCCESS);
474262cd50e2SAndrei Emeltchenko 			rsp.status = __constant_cpu_to_le16(L2CAP_CS_NO_INFO);
47438eb200bdSMat Martineau 		} else {
47448eb200bdSMat Martineau 			/* Send negative response */
474562cd50e2SAndrei Emeltchenko 			rsp.result = __constant_cpu_to_le16(L2CAP_CR_NO_MEM);
474662cd50e2SAndrei Emeltchenko 			rsp.status = __constant_cpu_to_le16(L2CAP_CS_NO_INFO);
47478eb200bdSMat Martineau 		}
47488eb200bdSMat Martineau 
47498eb200bdSMat Martineau 		l2cap_send_cmd(chan->conn, chan->ident, L2CAP_CREATE_CHAN_RSP,
47508eb200bdSMat Martineau 			       sizeof(rsp), &rsp);
47518eb200bdSMat Martineau 
47528eb200bdSMat Martineau 		if (result == L2CAP_CR_SUCCESS) {
47538eb200bdSMat Martineau 			__l2cap_state_change(chan, BT_CONFIG);
47548eb200bdSMat Martineau 			set_bit(CONF_REQ_SENT, &chan->conf_state);
47558eb200bdSMat Martineau 			l2cap_send_cmd(chan->conn, l2cap_get_ident(chan->conn),
47568eb200bdSMat Martineau 				       L2CAP_CONF_REQ,
47578eb200bdSMat Martineau 				       l2cap_build_conf_req(chan, buf), buf);
47588eb200bdSMat Martineau 			chan->num_conf_req++;
47598eb200bdSMat Martineau 		}
47608eb200bdSMat Martineau 	}
47618eb200bdSMat Martineau }
47628eb200bdSMat Martineau 
47638eb200bdSMat Martineau static void l2cap_do_move_initiate(struct l2cap_chan *chan, u8 local_amp_id,
47648eb200bdSMat Martineau 				   u8 remote_amp_id)
47658eb200bdSMat Martineau {
47668eb200bdSMat Martineau 	l2cap_move_setup(chan);
47678eb200bdSMat Martineau 	chan->move_id = local_amp_id;
47688eb200bdSMat Martineau 	chan->move_state = L2CAP_MOVE_WAIT_RSP;
47698eb200bdSMat Martineau 
47708eb200bdSMat Martineau 	l2cap_send_move_chan_req(chan, remote_amp_id);
47718eb200bdSMat Martineau }
47728eb200bdSMat Martineau 
47738eb200bdSMat Martineau static void l2cap_do_move_respond(struct l2cap_chan *chan, int result)
47748eb200bdSMat Martineau {
47758eb200bdSMat Martineau 	struct hci_chan *hchan = NULL;
47768eb200bdSMat Martineau 
47778eb200bdSMat Martineau 	/* Placeholder - get hci_chan for logical link */
47788eb200bdSMat Martineau 
47798eb200bdSMat Martineau 	if (hchan) {
47808eb200bdSMat Martineau 		if (hchan->state == BT_CONNECTED) {
47818eb200bdSMat Martineau 			/* Logical link is ready to go */
47828eb200bdSMat Martineau 			chan->hs_hcon = hchan->conn;
47838eb200bdSMat Martineau 			chan->hs_hcon->l2cap_data = chan->conn;
47848eb200bdSMat Martineau 			chan->move_state = L2CAP_MOVE_WAIT_CONFIRM;
47858eb200bdSMat Martineau 			l2cap_send_move_chan_rsp(chan, L2CAP_MR_SUCCESS);
47868eb200bdSMat Martineau 
47878eb200bdSMat Martineau 			l2cap_logical_cfm(chan, hchan, L2CAP_MR_SUCCESS);
47888eb200bdSMat Martineau 		} else {
47898eb200bdSMat Martineau 			/* Wait for logical link to be ready */
47908eb200bdSMat Martineau 			chan->move_state = L2CAP_MOVE_WAIT_LOGICAL_CFM;
47918eb200bdSMat Martineau 		}
47928eb200bdSMat Martineau 	} else {
47938eb200bdSMat Martineau 		/* Logical link not available */
47948eb200bdSMat Martineau 		l2cap_send_move_chan_rsp(chan, L2CAP_MR_NOT_ALLOWED);
47958eb200bdSMat Martineau 	}
47968eb200bdSMat Martineau }
47978eb200bdSMat Martineau 
47988eb200bdSMat Martineau static void l2cap_do_move_cancel(struct l2cap_chan *chan, int result)
47998eb200bdSMat Martineau {
48008eb200bdSMat Martineau 	if (chan->move_role == L2CAP_MOVE_ROLE_RESPONDER) {
48018eb200bdSMat Martineau 		u8 rsp_result;
48028eb200bdSMat Martineau 		if (result == -EINVAL)
48038eb200bdSMat Martineau 			rsp_result = L2CAP_MR_BAD_ID;
48048eb200bdSMat Martineau 		else
48058eb200bdSMat Martineau 			rsp_result = L2CAP_MR_NOT_ALLOWED;
48068eb200bdSMat Martineau 
48078eb200bdSMat Martineau 		l2cap_send_move_chan_rsp(chan, rsp_result);
48088eb200bdSMat Martineau 	}
48098eb200bdSMat Martineau 
48108eb200bdSMat Martineau 	chan->move_role = L2CAP_MOVE_ROLE_NONE;
48118eb200bdSMat Martineau 	chan->move_state = L2CAP_MOVE_STABLE;
48128eb200bdSMat Martineau 
48138eb200bdSMat Martineau 	/* Restart data transmission */
48148eb200bdSMat Martineau 	l2cap_ertm_send(chan);
48158eb200bdSMat Martineau }
48168eb200bdSMat Martineau 
4817a514b17fSAndrei Emeltchenko /* Invoke with locked chan */
4818a514b17fSAndrei Emeltchenko void __l2cap_physical_cfm(struct l2cap_chan *chan, int result)
48198eb200bdSMat Martineau {
4820770bfefaSAndrei Emeltchenko 	u8 local_amp_id = chan->local_amp_id;
4821fffadc08SAndrei Emeltchenko 	u8 remote_amp_id = chan->remote_amp_id;
4822770bfefaSAndrei Emeltchenko 
48238eb200bdSMat Martineau 	BT_DBG("chan %p, result %d, local_amp_id %d, remote_amp_id %d",
48248eb200bdSMat Martineau 	       chan, result, local_amp_id, remote_amp_id);
48258eb200bdSMat Martineau 
48268eb200bdSMat Martineau 	if (chan->state == BT_DISCONN || chan->state == BT_CLOSED) {
48278eb200bdSMat Martineau 		l2cap_chan_unlock(chan);
48288eb200bdSMat Martineau 		return;
48298eb200bdSMat Martineau 	}
48308eb200bdSMat Martineau 
48318eb200bdSMat Martineau 	if (chan->state != BT_CONNECTED) {
48328eb200bdSMat Martineau 		l2cap_do_create(chan, result, local_amp_id, remote_amp_id);
48338eb200bdSMat Martineau 	} else if (result != L2CAP_MR_SUCCESS) {
48348eb200bdSMat Martineau 		l2cap_do_move_cancel(chan, result);
48358eb200bdSMat Martineau 	} else {
48368eb200bdSMat Martineau 		switch (chan->move_role) {
48378eb200bdSMat Martineau 		case L2CAP_MOVE_ROLE_INITIATOR:
48388eb200bdSMat Martineau 			l2cap_do_move_initiate(chan, local_amp_id,
48398eb200bdSMat Martineau 					       remote_amp_id);
48408eb200bdSMat Martineau 			break;
48418eb200bdSMat Martineau 		case L2CAP_MOVE_ROLE_RESPONDER:
48428eb200bdSMat Martineau 			l2cap_do_move_respond(chan, result);
48438eb200bdSMat Martineau 			break;
48448eb200bdSMat Martineau 		default:
48458eb200bdSMat Martineau 			l2cap_do_move_cancel(chan, result);
48468eb200bdSMat Martineau 			break;
48478eb200bdSMat Martineau 		}
48488eb200bdSMat Martineau 	}
48498eb200bdSMat Martineau }
48508eb200bdSMat Martineau 
48518d5a04a1SMat Martineau static inline int l2cap_move_channel_req(struct l2cap_conn *conn,
4852ad0ac6caSAndrei Emeltchenko 					 struct l2cap_cmd_hdr *cmd,
4853ad0ac6caSAndrei Emeltchenko 					 u16 cmd_len, void *data)
48548d5a04a1SMat Martineau {
48558d5a04a1SMat Martineau 	struct l2cap_move_chan_req *req = data;
48561500109bSMat Martineau 	struct l2cap_move_chan_rsp rsp;
485702b0fbb9SMat Martineau 	struct l2cap_chan *chan;
48588d5a04a1SMat Martineau 	u16 icid = 0;
48598d5a04a1SMat Martineau 	u16 result = L2CAP_MR_NOT_ALLOWED;
48608d5a04a1SMat Martineau 
48618d5a04a1SMat Martineau 	if (cmd_len != sizeof(*req))
48628d5a04a1SMat Martineau 		return -EPROTO;
48638d5a04a1SMat Martineau 
48648d5a04a1SMat Martineau 	icid = le16_to_cpu(req->icid);
48658d5a04a1SMat Martineau 
4866ad0ac6caSAndrei Emeltchenko 	BT_DBG("icid 0x%4.4x, dest_amp_id %d", icid, req->dest_amp_id);
48678d5a04a1SMat Martineau 
4868848566b3SMarcel Holtmann 	if (!conn->hs_enabled)
48698d5a04a1SMat Martineau 		return -EINVAL;
48708d5a04a1SMat Martineau 
487102b0fbb9SMat Martineau 	chan = l2cap_get_chan_by_dcid(conn, icid);
487202b0fbb9SMat Martineau 	if (!chan) {
48731500109bSMat Martineau 		rsp.icid = cpu_to_le16(icid);
48741500109bSMat Martineau 		rsp.result = __constant_cpu_to_le16(L2CAP_MR_NOT_ALLOWED);
48751500109bSMat Martineau 		l2cap_send_cmd(conn, cmd->ident, L2CAP_MOVE_CHAN_RSP,
48761500109bSMat Martineau 			       sizeof(rsp), &rsp);
487702b0fbb9SMat Martineau 		return 0;
487802b0fbb9SMat Martineau 	}
487902b0fbb9SMat Martineau 
48801500109bSMat Martineau 	chan->ident = cmd->ident;
48811500109bSMat Martineau 
488202b0fbb9SMat Martineau 	if (chan->scid < L2CAP_CID_DYN_START ||
488302b0fbb9SMat Martineau 	    chan->chan_policy == BT_CHANNEL_POLICY_BREDR_ONLY ||
488402b0fbb9SMat Martineau 	    (chan->mode != L2CAP_MODE_ERTM &&
488502b0fbb9SMat Martineau 	     chan->mode != L2CAP_MODE_STREAMING)) {
488602b0fbb9SMat Martineau 		result = L2CAP_MR_NOT_ALLOWED;
488702b0fbb9SMat Martineau 		goto send_move_response;
488802b0fbb9SMat Martineau 	}
488902b0fbb9SMat Martineau 
489002b0fbb9SMat Martineau 	if (chan->local_amp_id == req->dest_amp_id) {
489102b0fbb9SMat Martineau 		result = L2CAP_MR_SAME_ID;
489202b0fbb9SMat Martineau 		goto send_move_response;
489302b0fbb9SMat Martineau 	}
489402b0fbb9SMat Martineau 
48956ed971caSMarcel Holtmann 	if (req->dest_amp_id != AMP_ID_BREDR) {
489602b0fbb9SMat Martineau 		struct hci_dev *hdev;
489702b0fbb9SMat Martineau 		hdev = hci_dev_get(req->dest_amp_id);
489802b0fbb9SMat Martineau 		if (!hdev || hdev->dev_type != HCI_AMP ||
489902b0fbb9SMat Martineau 		    !test_bit(HCI_UP, &hdev->flags)) {
490002b0fbb9SMat Martineau 			if (hdev)
490102b0fbb9SMat Martineau 				hci_dev_put(hdev);
490202b0fbb9SMat Martineau 
490302b0fbb9SMat Martineau 			result = L2CAP_MR_BAD_ID;
490402b0fbb9SMat Martineau 			goto send_move_response;
490502b0fbb9SMat Martineau 		}
490602b0fbb9SMat Martineau 		hci_dev_put(hdev);
490702b0fbb9SMat Martineau 	}
490802b0fbb9SMat Martineau 
490902b0fbb9SMat Martineau 	/* Detect a move collision.  Only send a collision response
491002b0fbb9SMat Martineau 	 * if this side has "lost", otherwise proceed with the move.
491102b0fbb9SMat Martineau 	 * The winner has the larger bd_addr.
491202b0fbb9SMat Martineau 	 */
491302b0fbb9SMat Martineau 	if ((__chan_is_moving(chan) ||
491402b0fbb9SMat Martineau 	     chan->move_role != L2CAP_MOVE_ROLE_NONE) &&
491502b0fbb9SMat Martineau 	    bacmp(conn->src, conn->dst) > 0) {
491602b0fbb9SMat Martineau 		result = L2CAP_MR_COLLISION;
491702b0fbb9SMat Martineau 		goto send_move_response;
491802b0fbb9SMat Martineau 	}
491902b0fbb9SMat Martineau 
492002b0fbb9SMat Martineau 	chan->move_role = L2CAP_MOVE_ROLE_RESPONDER;
492102b0fbb9SMat Martineau 	l2cap_move_setup(chan);
492202b0fbb9SMat Martineau 	chan->move_id = req->dest_amp_id;
492302b0fbb9SMat Martineau 	icid = chan->dcid;
492402b0fbb9SMat Martineau 
49256ed971caSMarcel Holtmann 	if (req->dest_amp_id == AMP_ID_BREDR) {
492602b0fbb9SMat Martineau 		/* Moving to BR/EDR */
492702b0fbb9SMat Martineau 		if (test_bit(CONN_LOCAL_BUSY, &chan->conn_state)) {
492802b0fbb9SMat Martineau 			chan->move_state = L2CAP_MOVE_WAIT_LOCAL_BUSY;
492902b0fbb9SMat Martineau 			result = L2CAP_MR_PEND;
493002b0fbb9SMat Martineau 		} else {
493102b0fbb9SMat Martineau 			chan->move_state = L2CAP_MOVE_WAIT_CONFIRM;
493202b0fbb9SMat Martineau 			result = L2CAP_MR_SUCCESS;
493302b0fbb9SMat Martineau 		}
493402b0fbb9SMat Martineau 	} else {
493502b0fbb9SMat Martineau 		chan->move_state = L2CAP_MOVE_WAIT_PREPARE;
493602b0fbb9SMat Martineau 		/* Placeholder - uncomment when amp functions are available */
493702b0fbb9SMat Martineau 		/*amp_accept_physical(chan, req->dest_amp_id);*/
493802b0fbb9SMat Martineau 		result = L2CAP_MR_PEND;
493902b0fbb9SMat Martineau 	}
494002b0fbb9SMat Martineau 
494102b0fbb9SMat Martineau send_move_response:
49421500109bSMat Martineau 	l2cap_send_move_chan_rsp(chan, result);
49438d5a04a1SMat Martineau 
494402b0fbb9SMat Martineau 	l2cap_chan_unlock(chan);
494502b0fbb9SMat Martineau 
49468d5a04a1SMat Martineau 	return 0;
49478d5a04a1SMat Martineau }
49488d5a04a1SMat Martineau 
49495b155ef9SMat Martineau static void l2cap_move_continue(struct l2cap_conn *conn, u16 icid, u16 result)
49505b155ef9SMat Martineau {
49515b155ef9SMat Martineau 	struct l2cap_chan *chan;
49525b155ef9SMat Martineau 	struct hci_chan *hchan = NULL;
49535b155ef9SMat Martineau 
49545b155ef9SMat Martineau 	chan = l2cap_get_chan_by_scid(conn, icid);
49555b155ef9SMat Martineau 	if (!chan) {
49565b155ef9SMat Martineau 		l2cap_send_move_chan_cfm_icid(conn, icid);
49575b155ef9SMat Martineau 		return;
49585b155ef9SMat Martineau 	}
49595b155ef9SMat Martineau 
49605b155ef9SMat Martineau 	__clear_chan_timer(chan);
49615b155ef9SMat Martineau 	if (result == L2CAP_MR_PEND)
49625b155ef9SMat Martineau 		__set_chan_timer(chan, L2CAP_MOVE_ERTX_TIMEOUT);
49635b155ef9SMat Martineau 
49645b155ef9SMat Martineau 	switch (chan->move_state) {
49655b155ef9SMat Martineau 	case L2CAP_MOVE_WAIT_LOGICAL_COMP:
49665b155ef9SMat Martineau 		/* Move confirm will be sent when logical link
49675b155ef9SMat Martineau 		 * is complete.
49685b155ef9SMat Martineau 		 */
49695b155ef9SMat Martineau 		chan->move_state = L2CAP_MOVE_WAIT_LOGICAL_CFM;
49705b155ef9SMat Martineau 		break;
49715b155ef9SMat Martineau 	case L2CAP_MOVE_WAIT_RSP_SUCCESS:
49725b155ef9SMat Martineau 		if (result == L2CAP_MR_PEND) {
49735b155ef9SMat Martineau 			break;
49745b155ef9SMat Martineau 		} else if (test_bit(CONN_LOCAL_BUSY,
49755b155ef9SMat Martineau 				    &chan->conn_state)) {
49765b155ef9SMat Martineau 			chan->move_state = L2CAP_MOVE_WAIT_LOCAL_BUSY;
49775b155ef9SMat Martineau 		} else {
49785b155ef9SMat Martineau 			/* Logical link is up or moving to BR/EDR,
49795b155ef9SMat Martineau 			 * proceed with move
49805b155ef9SMat Martineau 			 */
49815b155ef9SMat Martineau 			chan->move_state = L2CAP_MOVE_WAIT_CONFIRM_RSP;
49825b155ef9SMat Martineau 			l2cap_send_move_chan_cfm(chan, L2CAP_MC_CONFIRMED);
49835b155ef9SMat Martineau 		}
49845b155ef9SMat Martineau 		break;
49855b155ef9SMat Martineau 	case L2CAP_MOVE_WAIT_RSP:
49865b155ef9SMat Martineau 		/* Moving to AMP */
49875b155ef9SMat Martineau 		if (result == L2CAP_MR_SUCCESS) {
49885b155ef9SMat Martineau 			/* Remote is ready, send confirm immediately
49895b155ef9SMat Martineau 			 * after logical link is ready
49905b155ef9SMat Martineau 			 */
49915b155ef9SMat Martineau 			chan->move_state = L2CAP_MOVE_WAIT_LOGICAL_CFM;
49925b155ef9SMat Martineau 		} else {
49935b155ef9SMat Martineau 			/* Both logical link and move success
49945b155ef9SMat Martineau 			 * are required to confirm
49955b155ef9SMat Martineau 			 */
49965b155ef9SMat Martineau 			chan->move_state = L2CAP_MOVE_WAIT_LOGICAL_COMP;
49975b155ef9SMat Martineau 		}
49985b155ef9SMat Martineau 
49995b155ef9SMat Martineau 		/* Placeholder - get hci_chan for logical link */
50005b155ef9SMat Martineau 		if (!hchan) {
50015b155ef9SMat Martineau 			/* Logical link not available */
50025b155ef9SMat Martineau 			l2cap_send_move_chan_cfm(chan, L2CAP_MC_UNCONFIRMED);
50035b155ef9SMat Martineau 			break;
50045b155ef9SMat Martineau 		}
50055b155ef9SMat Martineau 
50065b155ef9SMat Martineau 		/* If the logical link is not yet connected, do not
50075b155ef9SMat Martineau 		 * send confirmation.
50085b155ef9SMat Martineau 		 */
50095b155ef9SMat Martineau 		if (hchan->state != BT_CONNECTED)
50105b155ef9SMat Martineau 			break;
50115b155ef9SMat Martineau 
50125b155ef9SMat Martineau 		/* Logical link is already ready to go */
50135b155ef9SMat Martineau 
50145b155ef9SMat Martineau 		chan->hs_hcon = hchan->conn;
50155b155ef9SMat Martineau 		chan->hs_hcon->l2cap_data = chan->conn;
50165b155ef9SMat Martineau 
50175b155ef9SMat Martineau 		if (result == L2CAP_MR_SUCCESS) {
50185b155ef9SMat Martineau 			/* Can confirm now */
50195b155ef9SMat Martineau 			l2cap_send_move_chan_cfm(chan, L2CAP_MC_CONFIRMED);
50205b155ef9SMat Martineau 		} else {
50215b155ef9SMat Martineau 			/* Now only need move success
50225b155ef9SMat Martineau 			 * to confirm
50235b155ef9SMat Martineau 			 */
50245b155ef9SMat Martineau 			chan->move_state = L2CAP_MOVE_WAIT_RSP_SUCCESS;
50255b155ef9SMat Martineau 		}
50265b155ef9SMat Martineau 
50275b155ef9SMat Martineau 		l2cap_logical_cfm(chan, hchan, L2CAP_MR_SUCCESS);
50285b155ef9SMat Martineau 		break;
50295b155ef9SMat Martineau 	default:
50305b155ef9SMat Martineau 		/* Any other amp move state means the move failed. */
50315b155ef9SMat Martineau 		chan->move_id = chan->local_amp_id;
50325b155ef9SMat Martineau 		l2cap_move_done(chan);
50335b155ef9SMat Martineau 		l2cap_send_move_chan_cfm(chan, L2CAP_MC_UNCONFIRMED);
50345b155ef9SMat Martineau 	}
50355b155ef9SMat Martineau 
50365b155ef9SMat Martineau 	l2cap_chan_unlock(chan);
50375b155ef9SMat Martineau }
50385b155ef9SMat Martineau 
50395b155ef9SMat Martineau static void l2cap_move_fail(struct l2cap_conn *conn, u8 ident, u16 icid,
50405b155ef9SMat Martineau 			    u16 result)
50415b155ef9SMat Martineau {
50425b155ef9SMat Martineau 	struct l2cap_chan *chan;
50435b155ef9SMat Martineau 
50445b155ef9SMat Martineau 	chan = l2cap_get_chan_by_ident(conn, ident);
50455b155ef9SMat Martineau 	if (!chan) {
50465b155ef9SMat Martineau 		/* Could not locate channel, icid is best guess */
50475b155ef9SMat Martineau 		l2cap_send_move_chan_cfm_icid(conn, icid);
50485b155ef9SMat Martineau 		return;
50495b155ef9SMat Martineau 	}
50505b155ef9SMat Martineau 
50515b155ef9SMat Martineau 	__clear_chan_timer(chan);
50525b155ef9SMat Martineau 
50535b155ef9SMat Martineau 	if (chan->move_role == L2CAP_MOVE_ROLE_INITIATOR) {
50545b155ef9SMat Martineau 		if (result == L2CAP_MR_COLLISION) {
50555b155ef9SMat Martineau 			chan->move_role = L2CAP_MOVE_ROLE_RESPONDER;
50565b155ef9SMat Martineau 		} else {
50575b155ef9SMat Martineau 			/* Cleanup - cancel move */
50585b155ef9SMat Martineau 			chan->move_id = chan->local_amp_id;
50595b155ef9SMat Martineau 			l2cap_move_done(chan);
50605b155ef9SMat Martineau 		}
50615b155ef9SMat Martineau 	}
50625b155ef9SMat Martineau 
50635b155ef9SMat Martineau 	l2cap_send_move_chan_cfm(chan, L2CAP_MC_UNCONFIRMED);
50645b155ef9SMat Martineau 
50655b155ef9SMat Martineau 	l2cap_chan_unlock(chan);
50665b155ef9SMat Martineau }
50675b155ef9SMat Martineau 
50685b155ef9SMat Martineau static int l2cap_move_channel_rsp(struct l2cap_conn *conn,
5069ad0ac6caSAndrei Emeltchenko 				  struct l2cap_cmd_hdr *cmd,
5070ad0ac6caSAndrei Emeltchenko 				  u16 cmd_len, void *data)
50718d5a04a1SMat Martineau {
50728d5a04a1SMat Martineau 	struct l2cap_move_chan_rsp *rsp = data;
50738d5a04a1SMat Martineau 	u16 icid, result;
50748d5a04a1SMat Martineau 
50758d5a04a1SMat Martineau 	if (cmd_len != sizeof(*rsp))
50768d5a04a1SMat Martineau 		return -EPROTO;
50778d5a04a1SMat Martineau 
50788d5a04a1SMat Martineau 	icid = le16_to_cpu(rsp->icid);
50798d5a04a1SMat Martineau 	result = le16_to_cpu(rsp->result);
50808d5a04a1SMat Martineau 
5081ad0ac6caSAndrei Emeltchenko 	BT_DBG("icid 0x%4.4x, result 0x%4.4x", icid, result);
50828d5a04a1SMat Martineau 
50835b155ef9SMat Martineau 	if (result == L2CAP_MR_SUCCESS || result == L2CAP_MR_PEND)
50845b155ef9SMat Martineau 		l2cap_move_continue(conn, icid, result);
50855b155ef9SMat Martineau 	else
50865b155ef9SMat Martineau 		l2cap_move_fail(conn, cmd->ident, icid, result);
50878d5a04a1SMat Martineau 
50888d5a04a1SMat Martineau 	return 0;
50898d5a04a1SMat Martineau }
50908d5a04a1SMat Martineau 
50915f3847a4SMat Martineau static int l2cap_move_channel_confirm(struct l2cap_conn *conn,
5092ad0ac6caSAndrei Emeltchenko 				      struct l2cap_cmd_hdr *cmd,
5093ad0ac6caSAndrei Emeltchenko 				      u16 cmd_len, void *data)
50948d5a04a1SMat Martineau {
50958d5a04a1SMat Martineau 	struct l2cap_move_chan_cfm *cfm = data;
50965f3847a4SMat Martineau 	struct l2cap_chan *chan;
50978d5a04a1SMat Martineau 	u16 icid, result;
50988d5a04a1SMat Martineau 
50998d5a04a1SMat Martineau 	if (cmd_len != sizeof(*cfm))
51008d5a04a1SMat Martineau 		return -EPROTO;
51018d5a04a1SMat Martineau 
51028d5a04a1SMat Martineau 	icid = le16_to_cpu(cfm->icid);
51038d5a04a1SMat Martineau 	result = le16_to_cpu(cfm->result);
51048d5a04a1SMat Martineau 
5105ad0ac6caSAndrei Emeltchenko 	BT_DBG("icid 0x%4.4x, result 0x%4.4x", icid, result);
51068d5a04a1SMat Martineau 
51075f3847a4SMat Martineau 	chan = l2cap_get_chan_by_dcid(conn, icid);
51085f3847a4SMat Martineau 	if (!chan) {
51095f3847a4SMat Martineau 		/* Spec requires a response even if the icid was not found */
51108d5a04a1SMat Martineau 		l2cap_send_move_chan_cfm_rsp(conn, cmd->ident, icid);
51115f3847a4SMat Martineau 		return 0;
51125f3847a4SMat Martineau 	}
51135f3847a4SMat Martineau 
51145f3847a4SMat Martineau 	if (chan->move_state == L2CAP_MOVE_WAIT_CONFIRM) {
51155f3847a4SMat Martineau 		if (result == L2CAP_MC_CONFIRMED) {
51165f3847a4SMat Martineau 			chan->local_amp_id = chan->move_id;
51176ed971caSMarcel Holtmann 			if (chan->local_amp_id == AMP_ID_BREDR)
51185f3847a4SMat Martineau 				__release_logical_link(chan);
51195f3847a4SMat Martineau 		} else {
51205f3847a4SMat Martineau 			chan->move_id = chan->local_amp_id;
51215f3847a4SMat Martineau 		}
51225f3847a4SMat Martineau 
51235f3847a4SMat Martineau 		l2cap_move_done(chan);
51245f3847a4SMat Martineau 	}
51255f3847a4SMat Martineau 
51265f3847a4SMat Martineau 	l2cap_send_move_chan_cfm_rsp(conn, cmd->ident, icid);
51275f3847a4SMat Martineau 
51285f3847a4SMat Martineau 	l2cap_chan_unlock(chan);
51298d5a04a1SMat Martineau 
51308d5a04a1SMat Martineau 	return 0;
51318d5a04a1SMat Martineau }
51328d5a04a1SMat Martineau 
51338d5a04a1SMat Martineau static inline int l2cap_move_channel_confirm_rsp(struct l2cap_conn *conn,
5134ad0ac6caSAndrei Emeltchenko 						 struct l2cap_cmd_hdr *cmd,
5135ad0ac6caSAndrei Emeltchenko 						 u16 cmd_len, void *data)
51368d5a04a1SMat Martineau {
51378d5a04a1SMat Martineau 	struct l2cap_move_chan_cfm_rsp *rsp = data;
51383fd71a0aSMat Martineau 	struct l2cap_chan *chan;
51398d5a04a1SMat Martineau 	u16 icid;
51408d5a04a1SMat Martineau 
51418d5a04a1SMat Martineau 	if (cmd_len != sizeof(*rsp))
51428d5a04a1SMat Martineau 		return -EPROTO;
51438d5a04a1SMat Martineau 
51448d5a04a1SMat Martineau 	icid = le16_to_cpu(rsp->icid);
51458d5a04a1SMat Martineau 
5146ad0ac6caSAndrei Emeltchenko 	BT_DBG("icid 0x%4.4x", icid);
51478d5a04a1SMat Martineau 
51483fd71a0aSMat Martineau 	chan = l2cap_get_chan_by_scid(conn, icid);
51493fd71a0aSMat Martineau 	if (!chan)
51503fd71a0aSMat Martineau 		return 0;
51513fd71a0aSMat Martineau 
51523fd71a0aSMat Martineau 	__clear_chan_timer(chan);
51533fd71a0aSMat Martineau 
51543fd71a0aSMat Martineau 	if (chan->move_state == L2CAP_MOVE_WAIT_CONFIRM_RSP) {
51553fd71a0aSMat Martineau 		chan->local_amp_id = chan->move_id;
51563fd71a0aSMat Martineau 
51576ed971caSMarcel Holtmann 		if (chan->local_amp_id == AMP_ID_BREDR && chan->hs_hchan)
51583fd71a0aSMat Martineau 			__release_logical_link(chan);
51593fd71a0aSMat Martineau 
51603fd71a0aSMat Martineau 		l2cap_move_done(chan);
51613fd71a0aSMat Martineau 	}
51623fd71a0aSMat Martineau 
51633fd71a0aSMat Martineau 	l2cap_chan_unlock(chan);
51643fd71a0aSMat Martineau 
51658d5a04a1SMat Martineau 	return 0;
51668d5a04a1SMat Martineau }
51678d5a04a1SMat Martineau 
5168e2174ca4SGustavo F. Padovan static inline int l2cap_check_conn_param(u16 min, u16 max, u16 latency,
5169de73115aSClaudio Takahasi 					 u16 to_multiplier)
5170de73115aSClaudio Takahasi {
5171de73115aSClaudio Takahasi 	u16 max_latency;
5172de73115aSClaudio Takahasi 
5173de73115aSClaudio Takahasi 	if (min > max || min < 6 || max > 3200)
5174de73115aSClaudio Takahasi 		return -EINVAL;
5175de73115aSClaudio Takahasi 
5176de73115aSClaudio Takahasi 	if (to_multiplier < 10 || to_multiplier > 3200)
5177de73115aSClaudio Takahasi 		return -EINVAL;
5178de73115aSClaudio Takahasi 
5179de73115aSClaudio Takahasi 	if (max >= to_multiplier * 8)
5180de73115aSClaudio Takahasi 		return -EINVAL;
5181de73115aSClaudio Takahasi 
5182de73115aSClaudio Takahasi 	max_latency = (to_multiplier * 8 / max) - 1;
5183de73115aSClaudio Takahasi 	if (latency > 499 || latency > max_latency)
5184de73115aSClaudio Takahasi 		return -EINVAL;
5185de73115aSClaudio Takahasi 
5186de73115aSClaudio Takahasi 	return 0;
5187de73115aSClaudio Takahasi }
5188de73115aSClaudio Takahasi 
5189de73115aSClaudio Takahasi static inline int l2cap_conn_param_update_req(struct l2cap_conn *conn,
51902d792818SGustavo Padovan 					      struct l2cap_cmd_hdr *cmd,
51912d792818SGustavo Padovan 					      u8 *data)
5192de73115aSClaudio Takahasi {
5193de73115aSClaudio Takahasi 	struct hci_conn *hcon = conn->hcon;
5194de73115aSClaudio Takahasi 	struct l2cap_conn_param_update_req *req;
5195de73115aSClaudio Takahasi 	struct l2cap_conn_param_update_rsp rsp;
5196de73115aSClaudio Takahasi 	u16 min, max, latency, to_multiplier, cmd_len;
51972ce603ebSClaudio Takahasi 	int err;
5198de73115aSClaudio Takahasi 
5199de73115aSClaudio Takahasi 	if (!(hcon->link_mode & HCI_LM_MASTER))
5200de73115aSClaudio Takahasi 		return -EINVAL;
5201de73115aSClaudio Takahasi 
5202de73115aSClaudio Takahasi 	cmd_len = __le16_to_cpu(cmd->len);
5203de73115aSClaudio Takahasi 	if (cmd_len != sizeof(struct l2cap_conn_param_update_req))
5204de73115aSClaudio Takahasi 		return -EPROTO;
5205de73115aSClaudio Takahasi 
5206de73115aSClaudio Takahasi 	req = (struct l2cap_conn_param_update_req *) data;
5207de73115aSClaudio Takahasi 	min		= __le16_to_cpu(req->min);
5208de73115aSClaudio Takahasi 	max		= __le16_to_cpu(req->max);
5209de73115aSClaudio Takahasi 	latency		= __le16_to_cpu(req->latency);
5210de73115aSClaudio Takahasi 	to_multiplier	= __le16_to_cpu(req->to_multiplier);
5211de73115aSClaudio Takahasi 
5212de73115aSClaudio Takahasi 	BT_DBG("min 0x%4.4x max 0x%4.4x latency: 0x%4.4x Timeout: 0x%4.4x",
5213de73115aSClaudio Takahasi 	       min, max, latency, to_multiplier);
5214de73115aSClaudio Takahasi 
5215de73115aSClaudio Takahasi 	memset(&rsp, 0, sizeof(rsp));
52162ce603ebSClaudio Takahasi 
52172ce603ebSClaudio Takahasi 	err = l2cap_check_conn_param(min, max, latency, to_multiplier);
52182ce603ebSClaudio Takahasi 	if (err)
5219ac73498cSAndrei Emeltchenko 		rsp.result = __constant_cpu_to_le16(L2CAP_CONN_PARAM_REJECTED);
5220de73115aSClaudio Takahasi 	else
5221ac73498cSAndrei Emeltchenko 		rsp.result = __constant_cpu_to_le16(L2CAP_CONN_PARAM_ACCEPTED);
5222de73115aSClaudio Takahasi 
5223de73115aSClaudio Takahasi 	l2cap_send_cmd(conn, cmd->ident, L2CAP_CONN_PARAM_UPDATE_RSP,
5224de73115aSClaudio Takahasi 		       sizeof(rsp), &rsp);
5225de73115aSClaudio Takahasi 
52262ce603ebSClaudio Takahasi 	if (!err)
52272ce603ebSClaudio Takahasi 		hci_le_conn_update(hcon, min, max, latency, to_multiplier);
52282ce603ebSClaudio Takahasi 
5229de73115aSClaudio Takahasi 	return 0;
5230de73115aSClaudio Takahasi }
5231de73115aSClaudio Takahasi 
52323300d9a9SClaudio Takahasi static inline int l2cap_bredr_sig_cmd(struct l2cap_conn *conn,
52332d792818SGustavo Padovan 				      struct l2cap_cmd_hdr *cmd, u16 cmd_len,
52342d792818SGustavo Padovan 				      u8 *data)
52353300d9a9SClaudio Takahasi {
52363300d9a9SClaudio Takahasi 	int err = 0;
52373300d9a9SClaudio Takahasi 
52383300d9a9SClaudio Takahasi 	switch (cmd->code) {
52393300d9a9SClaudio Takahasi 	case L2CAP_COMMAND_REJ:
5240cb3b3152SJohan Hedberg 		l2cap_command_rej(conn, cmd, cmd_len, data);
52413300d9a9SClaudio Takahasi 		break;
52423300d9a9SClaudio Takahasi 
52433300d9a9SClaudio Takahasi 	case L2CAP_CONN_REQ:
5244cb3b3152SJohan Hedberg 		err = l2cap_connect_req(conn, cmd, cmd_len, data);
52453300d9a9SClaudio Takahasi 		break;
52463300d9a9SClaudio Takahasi 
52473300d9a9SClaudio Takahasi 	case L2CAP_CONN_RSP:
5248f5a2598dSMat Martineau 	case L2CAP_CREATE_CHAN_RSP:
52499245e737SJohan Hedberg 		l2cap_connect_create_rsp(conn, cmd, cmd_len, data);
52503300d9a9SClaudio Takahasi 		break;
52513300d9a9SClaudio Takahasi 
52523300d9a9SClaudio Takahasi 	case L2CAP_CONF_REQ:
52533300d9a9SClaudio Takahasi 		err = l2cap_config_req(conn, cmd, cmd_len, data);
52543300d9a9SClaudio Takahasi 		break;
52553300d9a9SClaudio Takahasi 
52563300d9a9SClaudio Takahasi 	case L2CAP_CONF_RSP:
52579245e737SJohan Hedberg 		l2cap_config_rsp(conn, cmd, cmd_len, data);
52583300d9a9SClaudio Takahasi 		break;
52593300d9a9SClaudio Takahasi 
52603300d9a9SClaudio Takahasi 	case L2CAP_DISCONN_REQ:
5261cb3b3152SJohan Hedberg 		err = l2cap_disconnect_req(conn, cmd, cmd_len, data);
52623300d9a9SClaudio Takahasi 		break;
52633300d9a9SClaudio Takahasi 
52643300d9a9SClaudio Takahasi 	case L2CAP_DISCONN_RSP:
52659245e737SJohan Hedberg 		l2cap_disconnect_rsp(conn, cmd, cmd_len, data);
52663300d9a9SClaudio Takahasi 		break;
52673300d9a9SClaudio Takahasi 
52683300d9a9SClaudio Takahasi 	case L2CAP_ECHO_REQ:
52693300d9a9SClaudio Takahasi 		l2cap_send_cmd(conn, cmd->ident, L2CAP_ECHO_RSP, cmd_len, data);
52703300d9a9SClaudio Takahasi 		break;
52713300d9a9SClaudio Takahasi 
52723300d9a9SClaudio Takahasi 	case L2CAP_ECHO_RSP:
52733300d9a9SClaudio Takahasi 		break;
52743300d9a9SClaudio Takahasi 
52753300d9a9SClaudio Takahasi 	case L2CAP_INFO_REQ:
5276cb3b3152SJohan Hedberg 		err = l2cap_information_req(conn, cmd, cmd_len, data);
52773300d9a9SClaudio Takahasi 		break;
52783300d9a9SClaudio Takahasi 
52793300d9a9SClaudio Takahasi 	case L2CAP_INFO_RSP:
52809245e737SJohan Hedberg 		l2cap_information_rsp(conn, cmd, cmd_len, data);
52813300d9a9SClaudio Takahasi 		break;
52823300d9a9SClaudio Takahasi 
5283f94ff6ffSMat Martineau 	case L2CAP_CREATE_CHAN_REQ:
5284f94ff6ffSMat Martineau 		err = l2cap_create_channel_req(conn, cmd, cmd_len, data);
5285f94ff6ffSMat Martineau 		break;
5286f94ff6ffSMat Martineau 
52878d5a04a1SMat Martineau 	case L2CAP_MOVE_CHAN_REQ:
52888d5a04a1SMat Martineau 		err = l2cap_move_channel_req(conn, cmd, cmd_len, data);
52898d5a04a1SMat Martineau 		break;
52908d5a04a1SMat Martineau 
52918d5a04a1SMat Martineau 	case L2CAP_MOVE_CHAN_RSP:
52929245e737SJohan Hedberg 		l2cap_move_channel_rsp(conn, cmd, cmd_len, data);
52938d5a04a1SMat Martineau 		break;
52948d5a04a1SMat Martineau 
52958d5a04a1SMat Martineau 	case L2CAP_MOVE_CHAN_CFM:
52968d5a04a1SMat Martineau 		err = l2cap_move_channel_confirm(conn, cmd, cmd_len, data);
52978d5a04a1SMat Martineau 		break;
52988d5a04a1SMat Martineau 
52998d5a04a1SMat Martineau 	case L2CAP_MOVE_CHAN_CFM_RSP:
53009245e737SJohan Hedberg 		l2cap_move_channel_confirm_rsp(conn, cmd, cmd_len, data);
53018d5a04a1SMat Martineau 		break;
53028d5a04a1SMat Martineau 
53033300d9a9SClaudio Takahasi 	default:
53043300d9a9SClaudio Takahasi 		BT_ERR("Unknown BR/EDR signaling command 0x%2.2x", cmd->code);
53053300d9a9SClaudio Takahasi 		err = -EINVAL;
53063300d9a9SClaudio Takahasi 		break;
53073300d9a9SClaudio Takahasi 	}
53083300d9a9SClaudio Takahasi 
53093300d9a9SClaudio Takahasi 	return err;
53103300d9a9SClaudio Takahasi }
53113300d9a9SClaudio Takahasi 
53123300d9a9SClaudio Takahasi static inline int l2cap_le_sig_cmd(struct l2cap_conn *conn,
53133300d9a9SClaudio Takahasi 				   struct l2cap_cmd_hdr *cmd, u8 *data)
53143300d9a9SClaudio Takahasi {
53153300d9a9SClaudio Takahasi 	switch (cmd->code) {
53163300d9a9SClaudio Takahasi 	case L2CAP_COMMAND_REJ:
53173300d9a9SClaudio Takahasi 		return 0;
53183300d9a9SClaudio Takahasi 
53193300d9a9SClaudio Takahasi 	case L2CAP_CONN_PARAM_UPDATE_REQ:
5320de73115aSClaudio Takahasi 		return l2cap_conn_param_update_req(conn, cmd, data);
53213300d9a9SClaudio Takahasi 
53223300d9a9SClaudio Takahasi 	case L2CAP_CONN_PARAM_UPDATE_RSP:
53233300d9a9SClaudio Takahasi 		return 0;
53243300d9a9SClaudio Takahasi 
53253300d9a9SClaudio Takahasi 	default:
53263300d9a9SClaudio Takahasi 		BT_ERR("Unknown LE signaling command 0x%2.2x", cmd->code);
53273300d9a9SClaudio Takahasi 		return -EINVAL;
53283300d9a9SClaudio Takahasi 	}
53293300d9a9SClaudio Takahasi }
53303300d9a9SClaudio Takahasi 
53317c2005d6SJohan Hedberg static __le16 l2cap_err_to_reason(int err)
53327c2005d6SJohan Hedberg {
53337c2005d6SJohan Hedberg 	switch (err) {
53347c2005d6SJohan Hedberg 	case -EBADSLT:
53357c2005d6SJohan Hedberg 		return __constant_cpu_to_le16(L2CAP_REJ_INVALID_CID);
53367c2005d6SJohan Hedberg 	case -EMSGSIZE:
53377c2005d6SJohan Hedberg 		return __constant_cpu_to_le16(L2CAP_REJ_MTU_EXCEEDED);
53387c2005d6SJohan Hedberg 	case -EINVAL:
53397c2005d6SJohan Hedberg 	case -EPROTO:
53407c2005d6SJohan Hedberg 	default:
53417c2005d6SJohan Hedberg 		return __constant_cpu_to_le16(L2CAP_REJ_NOT_UNDERSTOOD);
53427c2005d6SJohan Hedberg 	}
53437c2005d6SJohan Hedberg }
53447c2005d6SJohan Hedberg 
5345c5623556SJohan Hedberg static inline void l2cap_le_sig_channel(struct l2cap_conn *conn,
5346c5623556SJohan Hedberg 					struct sk_buff *skb)
5347c5623556SJohan Hedberg {
534869c4e4e8SJohan Hedberg 	struct hci_conn *hcon = conn->hcon;
53494f3e219dSMarcel Holtmann 	struct l2cap_cmd_hdr *cmd;
53504f3e219dSMarcel Holtmann 	u16 len;
5351c5623556SJohan Hedberg 	int err;
5352c5623556SJohan Hedberg 
535369c4e4e8SJohan Hedberg 	if (hcon->type != LE_LINK)
53543b166295SMarcel Holtmann 		goto drop;
535569c4e4e8SJohan Hedberg 
53564f3e219dSMarcel Holtmann 	if (skb->len < L2CAP_CMD_HDR_SIZE)
53574f3e219dSMarcel Holtmann 		goto drop;
5358c5623556SJohan Hedberg 
53594f3e219dSMarcel Holtmann 	cmd = (void *) skb->data;
53604f3e219dSMarcel Holtmann 	skb_pull(skb, L2CAP_CMD_HDR_SIZE);
5361c5623556SJohan Hedberg 
53624f3e219dSMarcel Holtmann 	len = le16_to_cpu(cmd->len);
5363c5623556SJohan Hedberg 
53644f3e219dSMarcel Holtmann 	BT_DBG("code 0x%2.2x len %d id 0x%2.2x", cmd->code, len, cmd->ident);
53654f3e219dSMarcel Holtmann 
53664f3e219dSMarcel Holtmann 	if (len != skb->len || !cmd->ident) {
5367c5623556SJohan Hedberg 		BT_DBG("corrupted command");
53684f3e219dSMarcel Holtmann 		goto drop;
5369c5623556SJohan Hedberg 	}
5370c5623556SJohan Hedberg 
53714f3e219dSMarcel Holtmann 	err = l2cap_le_sig_cmd(conn, cmd, skb->data);
5372c5623556SJohan Hedberg 	if (err) {
5373c5623556SJohan Hedberg 		struct l2cap_cmd_rej_unk rej;
5374c5623556SJohan Hedberg 
5375c5623556SJohan Hedberg 		BT_ERR("Wrong link type (%d)", err);
5376c5623556SJohan Hedberg 
53777c2005d6SJohan Hedberg 		rej.reason = l2cap_err_to_reason(err);
53784f3e219dSMarcel Holtmann 		l2cap_send_cmd(conn, cmd->ident, L2CAP_COMMAND_REJ,
5379c5623556SJohan Hedberg 			       sizeof(rej), &rej);
5380c5623556SJohan Hedberg 	}
5381c5623556SJohan Hedberg 
53823b166295SMarcel Holtmann drop:
5383c5623556SJohan Hedberg 	kfree_skb(skb);
5384c5623556SJohan Hedberg }
5385c5623556SJohan Hedberg 
53863300d9a9SClaudio Takahasi static inline void l2cap_sig_channel(struct l2cap_conn *conn,
53873300d9a9SClaudio Takahasi 				     struct sk_buff *skb)
53880a708f8fSGustavo F. Padovan {
538969c4e4e8SJohan Hedberg 	struct hci_conn *hcon = conn->hcon;
53900a708f8fSGustavo F. Padovan 	u8 *data = skb->data;
53910a708f8fSGustavo F. Padovan 	int len = skb->len;
53920a708f8fSGustavo F. Padovan 	struct l2cap_cmd_hdr cmd;
53933300d9a9SClaudio Takahasi 	int err;
53940a708f8fSGustavo F. Padovan 
53950a708f8fSGustavo F. Padovan 	l2cap_raw_recv(conn, skb);
53960a708f8fSGustavo F. Padovan 
539769c4e4e8SJohan Hedberg 	if (hcon->type != ACL_LINK)
53983b166295SMarcel Holtmann 		goto drop;
539969c4e4e8SJohan Hedberg 
54000a708f8fSGustavo F. Padovan 	while (len >= L2CAP_CMD_HDR_SIZE) {
54010a708f8fSGustavo F. Padovan 		u16 cmd_len;
54020a708f8fSGustavo F. Padovan 		memcpy(&cmd, data, L2CAP_CMD_HDR_SIZE);
54030a708f8fSGustavo F. Padovan 		data += L2CAP_CMD_HDR_SIZE;
54040a708f8fSGustavo F. Padovan 		len  -= L2CAP_CMD_HDR_SIZE;
54050a708f8fSGustavo F. Padovan 
54060a708f8fSGustavo F. Padovan 		cmd_len = le16_to_cpu(cmd.len);
54070a708f8fSGustavo F. Padovan 
54082d792818SGustavo Padovan 		BT_DBG("code 0x%2.2x len %d id 0x%2.2x", cmd.code, cmd_len,
54092d792818SGustavo Padovan 		       cmd.ident);
54100a708f8fSGustavo F. Padovan 
54110a708f8fSGustavo F. Padovan 		if (cmd_len > len || !cmd.ident) {
54120a708f8fSGustavo F. Padovan 			BT_DBG("corrupted command");
54130a708f8fSGustavo F. Padovan 			break;
54140a708f8fSGustavo F. Padovan 		}
54150a708f8fSGustavo F. Padovan 
54163300d9a9SClaudio Takahasi 		err = l2cap_bredr_sig_cmd(conn, &cmd, cmd_len, data);
54170a708f8fSGustavo F. Padovan 		if (err) {
5418e2fd318eSIlia Kolomisnky 			struct l2cap_cmd_rej_unk rej;
54192c6d1a2eSGustavo F. Padovan 
54202c6d1a2eSGustavo F. Padovan 			BT_ERR("Wrong link type (%d)", err);
54210a708f8fSGustavo F. Padovan 
54227c2005d6SJohan Hedberg 			rej.reason = l2cap_err_to_reason(err);
54232d792818SGustavo Padovan 			l2cap_send_cmd(conn, cmd.ident, L2CAP_COMMAND_REJ,
54242d792818SGustavo Padovan 				       sizeof(rej), &rej);
54250a708f8fSGustavo F. Padovan 		}
54260a708f8fSGustavo F. Padovan 
54270a708f8fSGustavo F. Padovan 		data += cmd_len;
54280a708f8fSGustavo F. Padovan 		len  -= cmd_len;
54290a708f8fSGustavo F. Padovan 	}
54300a708f8fSGustavo F. Padovan 
54313b166295SMarcel Holtmann drop:
54320a708f8fSGustavo F. Padovan 	kfree_skb(skb);
54330a708f8fSGustavo F. Padovan }
54340a708f8fSGustavo F. Padovan 
543547d1ec61SGustavo F. Padovan static int l2cap_check_fcs(struct l2cap_chan *chan,  struct sk_buff *skb)
54360a708f8fSGustavo F. Padovan {
54370a708f8fSGustavo F. Padovan 	u16 our_fcs, rcv_fcs;
5438e4ca6d98SAndrei Emeltchenko 	int hdr_size;
5439e4ca6d98SAndrei Emeltchenko 
5440e4ca6d98SAndrei Emeltchenko 	if (test_bit(FLAG_EXT_CTRL, &chan->flags))
5441e4ca6d98SAndrei Emeltchenko 		hdr_size = L2CAP_EXT_HDR_SIZE;
5442e4ca6d98SAndrei Emeltchenko 	else
5443e4ca6d98SAndrei Emeltchenko 		hdr_size = L2CAP_ENH_HDR_SIZE;
54440a708f8fSGustavo F. Padovan 
544547d1ec61SGustavo F. Padovan 	if (chan->fcs == L2CAP_FCS_CRC16) {
544603a51213SAndrei Emeltchenko 		skb_trim(skb, skb->len - L2CAP_FCS_SIZE);
54470a708f8fSGustavo F. Padovan 		rcv_fcs = get_unaligned_le16(skb->data + skb->len);
54480a708f8fSGustavo F. Padovan 		our_fcs = crc16(0, skb->data - hdr_size, skb->len + hdr_size);
54490a708f8fSGustavo F. Padovan 
54500a708f8fSGustavo F. Padovan 		if (our_fcs != rcv_fcs)
54510a708f8fSGustavo F. Padovan 			return -EBADMSG;
54520a708f8fSGustavo F. Padovan 	}
54530a708f8fSGustavo F. Padovan 	return 0;
54540a708f8fSGustavo F. Padovan }
54550a708f8fSGustavo F. Padovan 
54566ea00485SMat Martineau static void l2cap_send_i_or_rr_or_rnr(struct l2cap_chan *chan)
54570a708f8fSGustavo F. Padovan {
5458e31f7633SMat Martineau 	struct l2cap_ctrl control;
54590a708f8fSGustavo F. Padovan 
5460e31f7633SMat Martineau 	BT_DBG("chan %p", chan);
54610a708f8fSGustavo F. Padovan 
5462e31f7633SMat Martineau 	memset(&control, 0, sizeof(control));
5463e31f7633SMat Martineau 	control.sframe = 1;
5464e31f7633SMat Martineau 	control.final = 1;
5465e31f7633SMat Martineau 	control.reqseq = chan->buffer_seq;
5466e31f7633SMat Martineau 	set_bit(CONN_SEND_FBIT, &chan->conn_state);
54670a708f8fSGustavo F. Padovan 
5468e2ab4353SGustavo F. Padovan 	if (test_bit(CONN_LOCAL_BUSY, &chan->conn_state)) {
5469e31f7633SMat Martineau 		control.super = L2CAP_SUPER_RNR;
5470e31f7633SMat Martineau 		l2cap_send_sframe(chan, &control);
54710a708f8fSGustavo F. Padovan 	}
54720a708f8fSGustavo F. Padovan 
5473e31f7633SMat Martineau 	if (test_and_clear_bit(CONN_REMOTE_BUSY, &chan->conn_state) &&
5474e31f7633SMat Martineau 	    chan->unacked_frames > 0)
5475e31f7633SMat Martineau 		__set_retrans_timer(chan);
54760a708f8fSGustavo F. Padovan 
5477e31f7633SMat Martineau 	/* Send pending iframes */
5478525cd185SGustavo F. Padovan 	l2cap_ertm_send(chan);
54790a708f8fSGustavo F. Padovan 
5480e2ab4353SGustavo F. Padovan 	if (!test_bit(CONN_LOCAL_BUSY, &chan->conn_state) &&
5481e31f7633SMat Martineau 	    test_bit(CONN_SEND_FBIT, &chan->conn_state)) {
5482e31f7633SMat Martineau 		/* F-bit wasn't sent in an s-frame or i-frame yet, so
5483e31f7633SMat Martineau 		 * send it now.
5484e31f7633SMat Martineau 		 */
5485e31f7633SMat Martineau 		control.super = L2CAP_SUPER_RR;
5486e31f7633SMat Martineau 		l2cap_send_sframe(chan, &control);
54870a708f8fSGustavo F. Padovan 	}
54880a708f8fSGustavo F. Padovan }
54890a708f8fSGustavo F. Padovan 
54902d792818SGustavo Padovan static void append_skb_frag(struct sk_buff *skb, struct sk_buff *new_frag,
54912d792818SGustavo Padovan 			    struct sk_buff **last_frag)
54920a708f8fSGustavo F. Padovan {
549384084a31SMat Martineau 	/* skb->len reflects data in skb as well as all fragments
549484084a31SMat Martineau 	 * skb->data_len reflects only data in fragments
549584084a31SMat Martineau 	 */
549684084a31SMat Martineau 	if (!skb_has_frag_list(skb))
549784084a31SMat Martineau 		skb_shinfo(skb)->frag_list = new_frag;
549884084a31SMat Martineau 
549984084a31SMat Martineau 	new_frag->next = NULL;
550084084a31SMat Martineau 
550184084a31SMat Martineau 	(*last_frag)->next = new_frag;
550284084a31SMat Martineau 	*last_frag = new_frag;
550384084a31SMat Martineau 
550484084a31SMat Martineau 	skb->len += new_frag->len;
550584084a31SMat Martineau 	skb->data_len += new_frag->len;
550684084a31SMat Martineau 	skb->truesize += new_frag->truesize;
550784084a31SMat Martineau }
550884084a31SMat Martineau 
55094b51dae9SMat Martineau static int l2cap_reassemble_sdu(struct l2cap_chan *chan, struct sk_buff *skb,
55104b51dae9SMat Martineau 				struct l2cap_ctrl *control)
551184084a31SMat Martineau {
551284084a31SMat Martineau 	int err = -EINVAL;
55130a708f8fSGustavo F. Padovan 
55144b51dae9SMat Martineau 	switch (control->sar) {
55157e0ef6eeSAndrei Emeltchenko 	case L2CAP_SAR_UNSEGMENTED:
551684084a31SMat Martineau 		if (chan->sdu)
551784084a31SMat Martineau 			break;
55180a708f8fSGustavo F. Padovan 
551980b98027SGustavo Padovan 		err = chan->ops->recv(chan, skb);
552084084a31SMat Martineau 		break;
55210a708f8fSGustavo F. Padovan 
55227e0ef6eeSAndrei Emeltchenko 	case L2CAP_SAR_START:
552384084a31SMat Martineau 		if (chan->sdu)
552484084a31SMat Martineau 			break;
55250a708f8fSGustavo F. Padovan 
55266f61fd47SGustavo F. Padovan 		chan->sdu_len = get_unaligned_le16(skb->data);
552703a51213SAndrei Emeltchenko 		skb_pull(skb, L2CAP_SDULEN_SIZE);
55280a708f8fSGustavo F. Padovan 
552984084a31SMat Martineau 		if (chan->sdu_len > chan->imtu) {
553084084a31SMat Martineau 			err = -EMSGSIZE;
553184084a31SMat Martineau 			break;
553284084a31SMat Martineau 		}
55330a708f8fSGustavo F. Padovan 
553484084a31SMat Martineau 		if (skb->len >= chan->sdu_len)
553584084a31SMat Martineau 			break;
553684084a31SMat Martineau 
553784084a31SMat Martineau 		chan->sdu = skb;
553884084a31SMat Martineau 		chan->sdu_last_frag = skb;
553984084a31SMat Martineau 
554084084a31SMat Martineau 		skb = NULL;
554184084a31SMat Martineau 		err = 0;
55420a708f8fSGustavo F. Padovan 		break;
55430a708f8fSGustavo F. Padovan 
55447e0ef6eeSAndrei Emeltchenko 	case L2CAP_SAR_CONTINUE:
55456f61fd47SGustavo F. Padovan 		if (!chan->sdu)
554684084a31SMat Martineau 			break;
55470a708f8fSGustavo F. Padovan 
554884084a31SMat Martineau 		append_skb_frag(chan->sdu, skb,
554984084a31SMat Martineau 				&chan->sdu_last_frag);
555084084a31SMat Martineau 		skb = NULL;
55510a708f8fSGustavo F. Padovan 
555284084a31SMat Martineau 		if (chan->sdu->len >= chan->sdu_len)
555384084a31SMat Martineau 			break;
55540a708f8fSGustavo F. Padovan 
555584084a31SMat Martineau 		err = 0;
55560a708f8fSGustavo F. Padovan 		break;
55570a708f8fSGustavo F. Padovan 
55587e0ef6eeSAndrei Emeltchenko 	case L2CAP_SAR_END:
55596f61fd47SGustavo F. Padovan 		if (!chan->sdu)
556084084a31SMat Martineau 			break;
55610a708f8fSGustavo F. Padovan 
556284084a31SMat Martineau 		append_skb_frag(chan->sdu, skb,
556384084a31SMat Martineau 				&chan->sdu_last_frag);
556484084a31SMat Martineau 		skb = NULL;
55650a708f8fSGustavo F. Padovan 
556684084a31SMat Martineau 		if (chan->sdu->len != chan->sdu_len)
556784084a31SMat Martineau 			break;
55680a708f8fSGustavo F. Padovan 
556980b98027SGustavo Padovan 		err = chan->ops->recv(chan, chan->sdu);
55700a708f8fSGustavo F. Padovan 
557184084a31SMat Martineau 		if (!err) {
557284084a31SMat Martineau 			/* Reassembly complete */
557384084a31SMat Martineau 			chan->sdu = NULL;
557484084a31SMat Martineau 			chan->sdu_last_frag = NULL;
557584084a31SMat Martineau 			chan->sdu_len = 0;
55760a708f8fSGustavo F. Padovan 		}
55770a708f8fSGustavo F. Padovan 		break;
55780a708f8fSGustavo F. Padovan 	}
55790a708f8fSGustavo F. Padovan 
558084084a31SMat Martineau 	if (err) {
55810a708f8fSGustavo F. Padovan 		kfree_skb(skb);
55826f61fd47SGustavo F. Padovan 		kfree_skb(chan->sdu);
55836f61fd47SGustavo F. Padovan 		chan->sdu = NULL;
558484084a31SMat Martineau 		chan->sdu_last_frag = NULL;
558584084a31SMat Martineau 		chan->sdu_len = 0;
558684084a31SMat Martineau 	}
55870a708f8fSGustavo F. Padovan 
558884084a31SMat Martineau 	return err;
55890a708f8fSGustavo F. Padovan }
55900a708f8fSGustavo F. Padovan 
559132b32735SMat Martineau static int l2cap_resegment(struct l2cap_chan *chan)
559232b32735SMat Martineau {
559332b32735SMat Martineau 	/* Placeholder */
559432b32735SMat Martineau 	return 0;
559532b32735SMat Martineau }
559632b32735SMat Martineau 
5597e328140fSMat Martineau void l2cap_chan_busy(struct l2cap_chan *chan, int busy)
55980a708f8fSGustavo F. Padovan {
559961aa4f5bSMat Martineau 	u8 event;
560061aa4f5bSMat Martineau 
560161aa4f5bSMat Martineau 	if (chan->mode != L2CAP_MODE_ERTM)
560261aa4f5bSMat Martineau 		return;
560361aa4f5bSMat Martineau 
560461aa4f5bSMat Martineau 	event = busy ? L2CAP_EV_LOCAL_BUSY_DETECTED : L2CAP_EV_LOCAL_BUSY_CLEAR;
5605401bb1f7SAndrei Emeltchenko 	l2cap_tx(chan, NULL, NULL, event);
56060a708f8fSGustavo F. Padovan }
56070a708f8fSGustavo F. Padovan 
5608d2a7ac5dSMat Martineau static int l2cap_rx_queued_iframes(struct l2cap_chan *chan)
5609d2a7ac5dSMat Martineau {
561063838725SMat Martineau 	int err = 0;
561163838725SMat Martineau 	/* Pass sequential frames to l2cap_reassemble_sdu()
561263838725SMat Martineau 	 * until a gap is encountered.
561363838725SMat Martineau 	 */
561463838725SMat Martineau 
561563838725SMat Martineau 	BT_DBG("chan %p", chan);
561663838725SMat Martineau 
561763838725SMat Martineau 	while (!test_bit(CONN_LOCAL_BUSY, &chan->conn_state)) {
561863838725SMat Martineau 		struct sk_buff *skb;
561963838725SMat Martineau 		BT_DBG("Searching for skb with txseq %d (queue len %d)",
562063838725SMat Martineau 		       chan->buffer_seq, skb_queue_len(&chan->srej_q));
562163838725SMat Martineau 
562263838725SMat Martineau 		skb = l2cap_ertm_seq_in_queue(&chan->srej_q, chan->buffer_seq);
562363838725SMat Martineau 
562463838725SMat Martineau 		if (!skb)
562563838725SMat Martineau 			break;
562663838725SMat Martineau 
562763838725SMat Martineau 		skb_unlink(skb, &chan->srej_q);
562863838725SMat Martineau 		chan->buffer_seq = __next_seq(chan, chan->buffer_seq);
562963838725SMat Martineau 		err = l2cap_reassemble_sdu(chan, skb, &bt_cb(skb)->control);
563063838725SMat Martineau 		if (err)
563163838725SMat Martineau 			break;
563263838725SMat Martineau 	}
563363838725SMat Martineau 
563463838725SMat Martineau 	if (skb_queue_empty(&chan->srej_q)) {
563563838725SMat Martineau 		chan->rx_state = L2CAP_RX_STATE_RECV;
563663838725SMat Martineau 		l2cap_send_ack(chan);
563763838725SMat Martineau 	}
563863838725SMat Martineau 
563963838725SMat Martineau 	return err;
5640d2a7ac5dSMat Martineau }
5641d2a7ac5dSMat Martineau 
5642d2a7ac5dSMat Martineau static void l2cap_handle_srej(struct l2cap_chan *chan,
5643d2a7ac5dSMat Martineau 			      struct l2cap_ctrl *control)
5644d2a7ac5dSMat Martineau {
5645f80842a8SMat Martineau 	struct sk_buff *skb;
5646f80842a8SMat Martineau 
5647f80842a8SMat Martineau 	BT_DBG("chan %p, control %p", chan, control);
5648f80842a8SMat Martineau 
5649f80842a8SMat Martineau 	if (control->reqseq == chan->next_tx_seq) {
5650f80842a8SMat Martineau 		BT_DBG("Invalid reqseq %d, disconnecting", control->reqseq);
56515e4e3972SAndrei Emeltchenko 		l2cap_send_disconn_req(chan, ECONNRESET);
5652f80842a8SMat Martineau 		return;
5653f80842a8SMat Martineau 	}
5654f80842a8SMat Martineau 
5655f80842a8SMat Martineau 	skb = l2cap_ertm_seq_in_queue(&chan->tx_q, control->reqseq);
5656f80842a8SMat Martineau 
5657f80842a8SMat Martineau 	if (skb == NULL) {
5658f80842a8SMat Martineau 		BT_DBG("Seq %d not available for retransmission",
5659f80842a8SMat Martineau 		       control->reqseq);
5660f80842a8SMat Martineau 		return;
5661f80842a8SMat Martineau 	}
5662f80842a8SMat Martineau 
5663f80842a8SMat Martineau 	if (chan->max_tx != 0 && bt_cb(skb)->control.retries >= chan->max_tx) {
5664f80842a8SMat Martineau 		BT_DBG("Retry limit exceeded (%d)", chan->max_tx);
56655e4e3972SAndrei Emeltchenko 		l2cap_send_disconn_req(chan, ECONNRESET);
5666f80842a8SMat Martineau 		return;
5667f80842a8SMat Martineau 	}
5668f80842a8SMat Martineau 
5669f80842a8SMat Martineau 	clear_bit(CONN_REMOTE_BUSY, &chan->conn_state);
5670f80842a8SMat Martineau 
5671f80842a8SMat Martineau 	if (control->poll) {
5672f80842a8SMat Martineau 		l2cap_pass_to_tx(chan, control);
5673f80842a8SMat Martineau 
5674f80842a8SMat Martineau 		set_bit(CONN_SEND_FBIT, &chan->conn_state);
5675f80842a8SMat Martineau 		l2cap_retransmit(chan, control);
5676f80842a8SMat Martineau 		l2cap_ertm_send(chan);
5677f80842a8SMat Martineau 
5678f80842a8SMat Martineau 		if (chan->tx_state == L2CAP_TX_STATE_WAIT_F) {
5679f80842a8SMat Martineau 			set_bit(CONN_SREJ_ACT, &chan->conn_state);
5680f80842a8SMat Martineau 			chan->srej_save_reqseq = control->reqseq;
5681f80842a8SMat Martineau 		}
5682f80842a8SMat Martineau 	} else {
5683f80842a8SMat Martineau 		l2cap_pass_to_tx_fbit(chan, control);
5684f80842a8SMat Martineau 
5685f80842a8SMat Martineau 		if (control->final) {
5686f80842a8SMat Martineau 			if (chan->srej_save_reqseq != control->reqseq ||
5687f80842a8SMat Martineau 			    !test_and_clear_bit(CONN_SREJ_ACT,
5688f80842a8SMat Martineau 						&chan->conn_state))
5689f80842a8SMat Martineau 				l2cap_retransmit(chan, control);
5690f80842a8SMat Martineau 		} else {
5691f80842a8SMat Martineau 			l2cap_retransmit(chan, control);
5692f80842a8SMat Martineau 			if (chan->tx_state == L2CAP_TX_STATE_WAIT_F) {
5693f80842a8SMat Martineau 				set_bit(CONN_SREJ_ACT, &chan->conn_state);
5694f80842a8SMat Martineau 				chan->srej_save_reqseq = control->reqseq;
5695f80842a8SMat Martineau 			}
5696f80842a8SMat Martineau 		}
5697f80842a8SMat Martineau 	}
5698d2a7ac5dSMat Martineau }
5699d2a7ac5dSMat Martineau 
5700d2a7ac5dSMat Martineau static void l2cap_handle_rej(struct l2cap_chan *chan,
5701d2a7ac5dSMat Martineau 			     struct l2cap_ctrl *control)
5702d2a7ac5dSMat Martineau {
5703fcd289dfSMat Martineau 	struct sk_buff *skb;
5704fcd289dfSMat Martineau 
5705fcd289dfSMat Martineau 	BT_DBG("chan %p, control %p", chan, control);
5706fcd289dfSMat Martineau 
5707fcd289dfSMat Martineau 	if (control->reqseq == chan->next_tx_seq) {
5708fcd289dfSMat Martineau 		BT_DBG("Invalid reqseq %d, disconnecting", control->reqseq);
57095e4e3972SAndrei Emeltchenko 		l2cap_send_disconn_req(chan, ECONNRESET);
5710fcd289dfSMat Martineau 		return;
5711fcd289dfSMat Martineau 	}
5712fcd289dfSMat Martineau 
5713fcd289dfSMat Martineau 	skb = l2cap_ertm_seq_in_queue(&chan->tx_q, control->reqseq);
5714fcd289dfSMat Martineau 
5715fcd289dfSMat Martineau 	if (chan->max_tx && skb &&
5716fcd289dfSMat Martineau 	    bt_cb(skb)->control.retries >= chan->max_tx) {
5717fcd289dfSMat Martineau 		BT_DBG("Retry limit exceeded (%d)", chan->max_tx);
57185e4e3972SAndrei Emeltchenko 		l2cap_send_disconn_req(chan, ECONNRESET);
5719fcd289dfSMat Martineau 		return;
5720fcd289dfSMat Martineau 	}
5721fcd289dfSMat Martineau 
5722fcd289dfSMat Martineau 	clear_bit(CONN_REMOTE_BUSY, &chan->conn_state);
5723fcd289dfSMat Martineau 
5724fcd289dfSMat Martineau 	l2cap_pass_to_tx(chan, control);
5725fcd289dfSMat Martineau 
5726fcd289dfSMat Martineau 	if (control->final) {
5727fcd289dfSMat Martineau 		if (!test_and_clear_bit(CONN_REJ_ACT, &chan->conn_state))
5728fcd289dfSMat Martineau 			l2cap_retransmit_all(chan, control);
5729fcd289dfSMat Martineau 	} else {
5730fcd289dfSMat Martineau 		l2cap_retransmit_all(chan, control);
5731fcd289dfSMat Martineau 		l2cap_ertm_send(chan);
5732fcd289dfSMat Martineau 		if (chan->tx_state == L2CAP_TX_STATE_WAIT_F)
5733fcd289dfSMat Martineau 			set_bit(CONN_REJ_ACT, &chan->conn_state);
5734fcd289dfSMat Martineau 	}
5735d2a7ac5dSMat Martineau }
5736d2a7ac5dSMat Martineau 
57374b51dae9SMat Martineau static u8 l2cap_classify_txseq(struct l2cap_chan *chan, u16 txseq)
57384b51dae9SMat Martineau {
57394b51dae9SMat Martineau 	BT_DBG("chan %p, txseq %d", chan, txseq);
57404b51dae9SMat Martineau 
57414b51dae9SMat Martineau 	BT_DBG("last_acked_seq %d, expected_tx_seq %d", chan->last_acked_seq,
57424b51dae9SMat Martineau 	       chan->expected_tx_seq);
57434b51dae9SMat Martineau 
57444b51dae9SMat Martineau 	if (chan->rx_state == L2CAP_RX_STATE_SREJ_SENT) {
57454b51dae9SMat Martineau 		if (__seq_offset(chan, txseq, chan->last_acked_seq) >=
57464b51dae9SMat Martineau 		    chan->tx_win) {
57474b51dae9SMat Martineau 			/* See notes below regarding "double poll" and
57484b51dae9SMat Martineau 			 * invalid packets.
57494b51dae9SMat Martineau 			 */
57504b51dae9SMat Martineau 			if (chan->tx_win <= ((chan->tx_win_max + 1) >> 1)) {
57514b51dae9SMat Martineau 				BT_DBG("Invalid/Ignore - after SREJ");
57524b51dae9SMat Martineau 				return L2CAP_TXSEQ_INVALID_IGNORE;
57534b51dae9SMat Martineau 			} else {
57544b51dae9SMat Martineau 				BT_DBG("Invalid - in window after SREJ sent");
57554b51dae9SMat Martineau 				return L2CAP_TXSEQ_INVALID;
57564b51dae9SMat Martineau 			}
57574b51dae9SMat Martineau 		}
57584b51dae9SMat Martineau 
57594b51dae9SMat Martineau 		if (chan->srej_list.head == txseq) {
57604b51dae9SMat Martineau 			BT_DBG("Expected SREJ");
57614b51dae9SMat Martineau 			return L2CAP_TXSEQ_EXPECTED_SREJ;
57624b51dae9SMat Martineau 		}
57634b51dae9SMat Martineau 
57644b51dae9SMat Martineau 		if (l2cap_ertm_seq_in_queue(&chan->srej_q, txseq)) {
57654b51dae9SMat Martineau 			BT_DBG("Duplicate SREJ - txseq already stored");
57664b51dae9SMat Martineau 			return L2CAP_TXSEQ_DUPLICATE_SREJ;
57674b51dae9SMat Martineau 		}
57684b51dae9SMat Martineau 
57694b51dae9SMat Martineau 		if (l2cap_seq_list_contains(&chan->srej_list, txseq)) {
57704b51dae9SMat Martineau 			BT_DBG("Unexpected SREJ - not requested");
57714b51dae9SMat Martineau 			return L2CAP_TXSEQ_UNEXPECTED_SREJ;
57724b51dae9SMat Martineau 		}
57734b51dae9SMat Martineau 	}
57744b51dae9SMat Martineau 
57754b51dae9SMat Martineau 	if (chan->expected_tx_seq == txseq) {
57764b51dae9SMat Martineau 		if (__seq_offset(chan, txseq, chan->last_acked_seq) >=
57774b51dae9SMat Martineau 		    chan->tx_win) {
57784b51dae9SMat Martineau 			BT_DBG("Invalid - txseq outside tx window");
57794b51dae9SMat Martineau 			return L2CAP_TXSEQ_INVALID;
57804b51dae9SMat Martineau 		} else {
57814b51dae9SMat Martineau 			BT_DBG("Expected");
57824b51dae9SMat Martineau 			return L2CAP_TXSEQ_EXPECTED;
57834b51dae9SMat Martineau 		}
57844b51dae9SMat Martineau 	}
57854b51dae9SMat Martineau 
57864b51dae9SMat Martineau 	if (__seq_offset(chan, txseq, chan->last_acked_seq) <
57872d792818SGustavo Padovan 	    __seq_offset(chan, chan->expected_tx_seq, chan->last_acked_seq)) {
57884b51dae9SMat Martineau 		BT_DBG("Duplicate - expected_tx_seq later than txseq");
57894b51dae9SMat Martineau 		return L2CAP_TXSEQ_DUPLICATE;
57904b51dae9SMat Martineau 	}
57914b51dae9SMat Martineau 
57924b51dae9SMat Martineau 	if (__seq_offset(chan, txseq, chan->last_acked_seq) >= chan->tx_win) {
57934b51dae9SMat Martineau 		/* A source of invalid packets is a "double poll" condition,
57944b51dae9SMat Martineau 		 * where delays cause us to send multiple poll packets.  If
57954b51dae9SMat Martineau 		 * the remote stack receives and processes both polls,
57964b51dae9SMat Martineau 		 * sequence numbers can wrap around in such a way that a
57974b51dae9SMat Martineau 		 * resent frame has a sequence number that looks like new data
57984b51dae9SMat Martineau 		 * with a sequence gap.  This would trigger an erroneous SREJ
57994b51dae9SMat Martineau 		 * request.
58004b51dae9SMat Martineau 		 *
58014b51dae9SMat Martineau 		 * Fortunately, this is impossible with a tx window that's
58024b51dae9SMat Martineau 		 * less than half of the maximum sequence number, which allows
58034b51dae9SMat Martineau 		 * invalid frames to be safely ignored.
58044b51dae9SMat Martineau 		 *
58054b51dae9SMat Martineau 		 * With tx window sizes greater than half of the tx window
58064b51dae9SMat Martineau 		 * maximum, the frame is invalid and cannot be ignored.  This
58074b51dae9SMat Martineau 		 * causes a disconnect.
58084b51dae9SMat Martineau 		 */
58094b51dae9SMat Martineau 
58104b51dae9SMat Martineau 		if (chan->tx_win <= ((chan->tx_win_max + 1) >> 1)) {
58114b51dae9SMat Martineau 			BT_DBG("Invalid/Ignore - txseq outside tx window");
58124b51dae9SMat Martineau 			return L2CAP_TXSEQ_INVALID_IGNORE;
58134b51dae9SMat Martineau 		} else {
58144b51dae9SMat Martineau 			BT_DBG("Invalid - txseq outside tx window");
58154b51dae9SMat Martineau 			return L2CAP_TXSEQ_INVALID;
58164b51dae9SMat Martineau 		}
58174b51dae9SMat Martineau 	} else {
58184b51dae9SMat Martineau 		BT_DBG("Unexpected - txseq indicates missing frames");
58194b51dae9SMat Martineau 		return L2CAP_TXSEQ_UNEXPECTED;
58204b51dae9SMat Martineau 	}
58214b51dae9SMat Martineau }
58224b51dae9SMat Martineau 
5823d2a7ac5dSMat Martineau static int l2cap_rx_state_recv(struct l2cap_chan *chan,
5824d2a7ac5dSMat Martineau 			       struct l2cap_ctrl *control,
5825d2a7ac5dSMat Martineau 			       struct sk_buff *skb, u8 event)
5826d2a7ac5dSMat Martineau {
5827d2a7ac5dSMat Martineau 	int err = 0;
5828941247f9SPeter Senna Tschudin 	bool skb_in_use = false;
5829d2a7ac5dSMat Martineau 
5830d2a7ac5dSMat Martineau 	BT_DBG("chan %p, control %p, skb %p, event %d", chan, control, skb,
5831d2a7ac5dSMat Martineau 	       event);
5832d2a7ac5dSMat Martineau 
5833d2a7ac5dSMat Martineau 	switch (event) {
5834d2a7ac5dSMat Martineau 	case L2CAP_EV_RECV_IFRAME:
5835d2a7ac5dSMat Martineau 		switch (l2cap_classify_txseq(chan, control->txseq)) {
5836d2a7ac5dSMat Martineau 		case L2CAP_TXSEQ_EXPECTED:
5837d2a7ac5dSMat Martineau 			l2cap_pass_to_tx(chan, control);
5838d2a7ac5dSMat Martineau 
5839d2a7ac5dSMat Martineau 			if (test_bit(CONN_LOCAL_BUSY, &chan->conn_state)) {
5840d2a7ac5dSMat Martineau 				BT_DBG("Busy, discarding expected seq %d",
5841d2a7ac5dSMat Martineau 				       control->txseq);
5842d2a7ac5dSMat Martineau 				break;
5843d2a7ac5dSMat Martineau 			}
5844d2a7ac5dSMat Martineau 
5845d2a7ac5dSMat Martineau 			chan->expected_tx_seq = __next_seq(chan,
5846d2a7ac5dSMat Martineau 							   control->txseq);
5847d2a7ac5dSMat Martineau 
5848d2a7ac5dSMat Martineau 			chan->buffer_seq = chan->expected_tx_seq;
5849941247f9SPeter Senna Tschudin 			skb_in_use = true;
5850d2a7ac5dSMat Martineau 
5851d2a7ac5dSMat Martineau 			err = l2cap_reassemble_sdu(chan, skb, control);
5852d2a7ac5dSMat Martineau 			if (err)
5853d2a7ac5dSMat Martineau 				break;
5854d2a7ac5dSMat Martineau 
5855d2a7ac5dSMat Martineau 			if (control->final) {
5856d2a7ac5dSMat Martineau 				if (!test_and_clear_bit(CONN_REJ_ACT,
5857d2a7ac5dSMat Martineau 							&chan->conn_state)) {
5858d2a7ac5dSMat Martineau 					control->final = 0;
5859d2a7ac5dSMat Martineau 					l2cap_retransmit_all(chan, control);
5860d2a7ac5dSMat Martineau 					l2cap_ertm_send(chan);
5861d2a7ac5dSMat Martineau 				}
5862d2a7ac5dSMat Martineau 			}
5863d2a7ac5dSMat Martineau 
5864d2a7ac5dSMat Martineau 			if (!test_bit(CONN_LOCAL_BUSY, &chan->conn_state))
5865d2a7ac5dSMat Martineau 				l2cap_send_ack(chan);
5866d2a7ac5dSMat Martineau 			break;
5867d2a7ac5dSMat Martineau 		case L2CAP_TXSEQ_UNEXPECTED:
5868d2a7ac5dSMat Martineau 			l2cap_pass_to_tx(chan, control);
5869d2a7ac5dSMat Martineau 
5870d2a7ac5dSMat Martineau 			/* Can't issue SREJ frames in the local busy state.
5871d2a7ac5dSMat Martineau 			 * Drop this frame, it will be seen as missing
5872d2a7ac5dSMat Martineau 			 * when local busy is exited.
5873d2a7ac5dSMat Martineau 			 */
5874d2a7ac5dSMat Martineau 			if (test_bit(CONN_LOCAL_BUSY, &chan->conn_state)) {
5875d2a7ac5dSMat Martineau 				BT_DBG("Busy, discarding unexpected seq %d",
5876d2a7ac5dSMat Martineau 				       control->txseq);
5877d2a7ac5dSMat Martineau 				break;
5878d2a7ac5dSMat Martineau 			}
5879d2a7ac5dSMat Martineau 
5880d2a7ac5dSMat Martineau 			/* There was a gap in the sequence, so an SREJ
5881d2a7ac5dSMat Martineau 			 * must be sent for each missing frame.  The
5882d2a7ac5dSMat Martineau 			 * current frame is stored for later use.
5883d2a7ac5dSMat Martineau 			 */
5884d2a7ac5dSMat Martineau 			skb_queue_tail(&chan->srej_q, skb);
5885941247f9SPeter Senna Tschudin 			skb_in_use = true;
5886d2a7ac5dSMat Martineau 			BT_DBG("Queued %p (queue len %d)", skb,
5887d2a7ac5dSMat Martineau 			       skb_queue_len(&chan->srej_q));
5888d2a7ac5dSMat Martineau 
5889d2a7ac5dSMat Martineau 			clear_bit(CONN_SREJ_ACT, &chan->conn_state);
5890d2a7ac5dSMat Martineau 			l2cap_seq_list_clear(&chan->srej_list);
5891d2a7ac5dSMat Martineau 			l2cap_send_srej(chan, control->txseq);
5892d2a7ac5dSMat Martineau 
5893d2a7ac5dSMat Martineau 			chan->rx_state = L2CAP_RX_STATE_SREJ_SENT;
5894d2a7ac5dSMat Martineau 			break;
5895d2a7ac5dSMat Martineau 		case L2CAP_TXSEQ_DUPLICATE:
5896d2a7ac5dSMat Martineau 			l2cap_pass_to_tx(chan, control);
5897d2a7ac5dSMat Martineau 			break;
5898d2a7ac5dSMat Martineau 		case L2CAP_TXSEQ_INVALID_IGNORE:
5899d2a7ac5dSMat Martineau 			break;
5900d2a7ac5dSMat Martineau 		case L2CAP_TXSEQ_INVALID:
5901d2a7ac5dSMat Martineau 		default:
59025e4e3972SAndrei Emeltchenko 			l2cap_send_disconn_req(chan, ECONNRESET);
5903d2a7ac5dSMat Martineau 			break;
5904d2a7ac5dSMat Martineau 		}
5905d2a7ac5dSMat Martineau 		break;
5906d2a7ac5dSMat Martineau 	case L2CAP_EV_RECV_RR:
5907d2a7ac5dSMat Martineau 		l2cap_pass_to_tx(chan, control);
5908d2a7ac5dSMat Martineau 		if (control->final) {
5909d2a7ac5dSMat Martineau 			clear_bit(CONN_REMOTE_BUSY, &chan->conn_state);
5910d2a7ac5dSMat Martineau 
5911e6a3ee6eSMat Martineau 			if (!test_and_clear_bit(CONN_REJ_ACT, &chan->conn_state) &&
5912e6a3ee6eSMat Martineau 			    !__chan_is_moving(chan)) {
5913d2a7ac5dSMat Martineau 				control->final = 0;
5914d2a7ac5dSMat Martineau 				l2cap_retransmit_all(chan, control);
5915d2a7ac5dSMat Martineau 			}
5916d2a7ac5dSMat Martineau 
5917d2a7ac5dSMat Martineau 			l2cap_ertm_send(chan);
5918d2a7ac5dSMat Martineau 		} else if (control->poll) {
5919d2a7ac5dSMat Martineau 			l2cap_send_i_or_rr_or_rnr(chan);
5920d2a7ac5dSMat Martineau 		} else {
5921d2a7ac5dSMat Martineau 			if (test_and_clear_bit(CONN_REMOTE_BUSY,
5922d2a7ac5dSMat Martineau 					       &chan->conn_state) &&
5923d2a7ac5dSMat Martineau 			    chan->unacked_frames)
5924d2a7ac5dSMat Martineau 				__set_retrans_timer(chan);
5925d2a7ac5dSMat Martineau 
5926d2a7ac5dSMat Martineau 			l2cap_ertm_send(chan);
5927d2a7ac5dSMat Martineau 		}
5928d2a7ac5dSMat Martineau 		break;
5929d2a7ac5dSMat Martineau 	case L2CAP_EV_RECV_RNR:
5930d2a7ac5dSMat Martineau 		set_bit(CONN_REMOTE_BUSY, &chan->conn_state);
5931d2a7ac5dSMat Martineau 		l2cap_pass_to_tx(chan, control);
5932d2a7ac5dSMat Martineau 		if (control && control->poll) {
5933d2a7ac5dSMat Martineau 			set_bit(CONN_SEND_FBIT, &chan->conn_state);
5934d2a7ac5dSMat Martineau 			l2cap_send_rr_or_rnr(chan, 0);
5935d2a7ac5dSMat Martineau 		}
5936d2a7ac5dSMat Martineau 		__clear_retrans_timer(chan);
5937d2a7ac5dSMat Martineau 		l2cap_seq_list_clear(&chan->retrans_list);
5938d2a7ac5dSMat Martineau 		break;
5939d2a7ac5dSMat Martineau 	case L2CAP_EV_RECV_REJ:
5940d2a7ac5dSMat Martineau 		l2cap_handle_rej(chan, control);
5941d2a7ac5dSMat Martineau 		break;
5942d2a7ac5dSMat Martineau 	case L2CAP_EV_RECV_SREJ:
5943d2a7ac5dSMat Martineau 		l2cap_handle_srej(chan, control);
5944d2a7ac5dSMat Martineau 		break;
5945d2a7ac5dSMat Martineau 	default:
5946d2a7ac5dSMat Martineau 		break;
5947d2a7ac5dSMat Martineau 	}
5948d2a7ac5dSMat Martineau 
5949d2a7ac5dSMat Martineau 	if (skb && !skb_in_use) {
5950d2a7ac5dSMat Martineau 		BT_DBG("Freeing %p", skb);
5951d2a7ac5dSMat Martineau 		kfree_skb(skb);
5952d2a7ac5dSMat Martineau 	}
5953d2a7ac5dSMat Martineau 
5954d2a7ac5dSMat Martineau 	return err;
5955d2a7ac5dSMat Martineau }
5956d2a7ac5dSMat Martineau 
5957d2a7ac5dSMat Martineau static int l2cap_rx_state_srej_sent(struct l2cap_chan *chan,
5958d2a7ac5dSMat Martineau 				    struct l2cap_ctrl *control,
5959d2a7ac5dSMat Martineau 				    struct sk_buff *skb, u8 event)
5960d2a7ac5dSMat Martineau {
5961d2a7ac5dSMat Martineau 	int err = 0;
5962d2a7ac5dSMat Martineau 	u16 txseq = control->txseq;
5963941247f9SPeter Senna Tschudin 	bool skb_in_use = false;
5964d2a7ac5dSMat Martineau 
5965d2a7ac5dSMat Martineau 	BT_DBG("chan %p, control %p, skb %p, event %d", chan, control, skb,
5966d2a7ac5dSMat Martineau 	       event);
5967d2a7ac5dSMat Martineau 
5968d2a7ac5dSMat Martineau 	switch (event) {
5969d2a7ac5dSMat Martineau 	case L2CAP_EV_RECV_IFRAME:
5970d2a7ac5dSMat Martineau 		switch (l2cap_classify_txseq(chan, txseq)) {
5971d2a7ac5dSMat Martineau 		case L2CAP_TXSEQ_EXPECTED:
5972d2a7ac5dSMat Martineau 			/* Keep frame for reassembly later */
5973d2a7ac5dSMat Martineau 			l2cap_pass_to_tx(chan, control);
5974d2a7ac5dSMat Martineau 			skb_queue_tail(&chan->srej_q, skb);
5975941247f9SPeter Senna Tschudin 			skb_in_use = true;
5976d2a7ac5dSMat Martineau 			BT_DBG("Queued %p (queue len %d)", skb,
5977d2a7ac5dSMat Martineau 			       skb_queue_len(&chan->srej_q));
5978d2a7ac5dSMat Martineau 
5979d2a7ac5dSMat Martineau 			chan->expected_tx_seq = __next_seq(chan, txseq);
5980d2a7ac5dSMat Martineau 			break;
5981d2a7ac5dSMat Martineau 		case L2CAP_TXSEQ_EXPECTED_SREJ:
5982d2a7ac5dSMat Martineau 			l2cap_seq_list_pop(&chan->srej_list);
5983d2a7ac5dSMat Martineau 
5984d2a7ac5dSMat Martineau 			l2cap_pass_to_tx(chan, control);
5985d2a7ac5dSMat Martineau 			skb_queue_tail(&chan->srej_q, skb);
5986941247f9SPeter Senna Tschudin 			skb_in_use = true;
5987d2a7ac5dSMat Martineau 			BT_DBG("Queued %p (queue len %d)", skb,
5988d2a7ac5dSMat Martineau 			       skb_queue_len(&chan->srej_q));
5989d2a7ac5dSMat Martineau 
5990d2a7ac5dSMat Martineau 			err = l2cap_rx_queued_iframes(chan);
5991d2a7ac5dSMat Martineau 			if (err)
5992d2a7ac5dSMat Martineau 				break;
5993d2a7ac5dSMat Martineau 
5994d2a7ac5dSMat Martineau 			break;
5995d2a7ac5dSMat Martineau 		case L2CAP_TXSEQ_UNEXPECTED:
5996d2a7ac5dSMat Martineau 			/* Got a frame that can't be reassembled yet.
5997d2a7ac5dSMat Martineau 			 * Save it for later, and send SREJs to cover
5998d2a7ac5dSMat Martineau 			 * the missing frames.
5999d2a7ac5dSMat Martineau 			 */
6000d2a7ac5dSMat Martineau 			skb_queue_tail(&chan->srej_q, skb);
6001941247f9SPeter Senna Tschudin 			skb_in_use = true;
6002d2a7ac5dSMat Martineau 			BT_DBG("Queued %p (queue len %d)", skb,
6003d2a7ac5dSMat Martineau 			       skb_queue_len(&chan->srej_q));
6004d2a7ac5dSMat Martineau 
6005d2a7ac5dSMat Martineau 			l2cap_pass_to_tx(chan, control);
6006d2a7ac5dSMat Martineau 			l2cap_send_srej(chan, control->txseq);
6007d2a7ac5dSMat Martineau 			break;
6008d2a7ac5dSMat Martineau 		case L2CAP_TXSEQ_UNEXPECTED_SREJ:
6009d2a7ac5dSMat Martineau 			/* This frame was requested with an SREJ, but
6010d2a7ac5dSMat Martineau 			 * some expected retransmitted frames are
6011d2a7ac5dSMat Martineau 			 * missing.  Request retransmission of missing
6012d2a7ac5dSMat Martineau 			 * SREJ'd frames.
6013d2a7ac5dSMat Martineau 			 */
6014d2a7ac5dSMat Martineau 			skb_queue_tail(&chan->srej_q, skb);
6015941247f9SPeter Senna Tschudin 			skb_in_use = true;
6016d2a7ac5dSMat Martineau 			BT_DBG("Queued %p (queue len %d)", skb,
6017d2a7ac5dSMat Martineau 			       skb_queue_len(&chan->srej_q));
6018d2a7ac5dSMat Martineau 
6019d2a7ac5dSMat Martineau 			l2cap_pass_to_tx(chan, control);
6020d2a7ac5dSMat Martineau 			l2cap_send_srej_list(chan, control->txseq);
6021d2a7ac5dSMat Martineau 			break;
6022d2a7ac5dSMat Martineau 		case L2CAP_TXSEQ_DUPLICATE_SREJ:
6023d2a7ac5dSMat Martineau 			/* We've already queued this frame.  Drop this copy. */
6024d2a7ac5dSMat Martineau 			l2cap_pass_to_tx(chan, control);
6025d2a7ac5dSMat Martineau 			break;
6026d2a7ac5dSMat Martineau 		case L2CAP_TXSEQ_DUPLICATE:
6027d2a7ac5dSMat Martineau 			/* Expecting a later sequence number, so this frame
6028d2a7ac5dSMat Martineau 			 * was already received.  Ignore it completely.
6029d2a7ac5dSMat Martineau 			 */
6030d2a7ac5dSMat Martineau 			break;
6031d2a7ac5dSMat Martineau 		case L2CAP_TXSEQ_INVALID_IGNORE:
6032d2a7ac5dSMat Martineau 			break;
6033d2a7ac5dSMat Martineau 		case L2CAP_TXSEQ_INVALID:
6034d2a7ac5dSMat Martineau 		default:
60355e4e3972SAndrei Emeltchenko 			l2cap_send_disconn_req(chan, ECONNRESET);
6036d2a7ac5dSMat Martineau 			break;
6037d2a7ac5dSMat Martineau 		}
6038d2a7ac5dSMat Martineau 		break;
6039d2a7ac5dSMat Martineau 	case L2CAP_EV_RECV_RR:
6040d2a7ac5dSMat Martineau 		l2cap_pass_to_tx(chan, control);
6041d2a7ac5dSMat Martineau 		if (control->final) {
6042d2a7ac5dSMat Martineau 			clear_bit(CONN_REMOTE_BUSY, &chan->conn_state);
6043d2a7ac5dSMat Martineau 
6044d2a7ac5dSMat Martineau 			if (!test_and_clear_bit(CONN_REJ_ACT,
6045d2a7ac5dSMat Martineau 						&chan->conn_state)) {
6046d2a7ac5dSMat Martineau 				control->final = 0;
6047d2a7ac5dSMat Martineau 				l2cap_retransmit_all(chan, control);
6048d2a7ac5dSMat Martineau 			}
6049d2a7ac5dSMat Martineau 
6050d2a7ac5dSMat Martineau 			l2cap_ertm_send(chan);
6051d2a7ac5dSMat Martineau 		} else if (control->poll) {
6052d2a7ac5dSMat Martineau 			if (test_and_clear_bit(CONN_REMOTE_BUSY,
6053d2a7ac5dSMat Martineau 					       &chan->conn_state) &&
6054d2a7ac5dSMat Martineau 			    chan->unacked_frames) {
6055d2a7ac5dSMat Martineau 				__set_retrans_timer(chan);
6056d2a7ac5dSMat Martineau 			}
6057d2a7ac5dSMat Martineau 
6058d2a7ac5dSMat Martineau 			set_bit(CONN_SEND_FBIT, &chan->conn_state);
6059d2a7ac5dSMat Martineau 			l2cap_send_srej_tail(chan);
6060d2a7ac5dSMat Martineau 		} else {
6061d2a7ac5dSMat Martineau 			if (test_and_clear_bit(CONN_REMOTE_BUSY,
6062d2a7ac5dSMat Martineau 					       &chan->conn_state) &&
6063d2a7ac5dSMat Martineau 			    chan->unacked_frames)
6064d2a7ac5dSMat Martineau 				__set_retrans_timer(chan);
6065d2a7ac5dSMat Martineau 
6066d2a7ac5dSMat Martineau 			l2cap_send_ack(chan);
6067d2a7ac5dSMat Martineau 		}
6068d2a7ac5dSMat Martineau 		break;
6069d2a7ac5dSMat Martineau 	case L2CAP_EV_RECV_RNR:
6070d2a7ac5dSMat Martineau 		set_bit(CONN_REMOTE_BUSY, &chan->conn_state);
6071d2a7ac5dSMat Martineau 		l2cap_pass_to_tx(chan, control);
6072d2a7ac5dSMat Martineau 		if (control->poll) {
6073d2a7ac5dSMat Martineau 			l2cap_send_srej_tail(chan);
6074d2a7ac5dSMat Martineau 		} else {
6075d2a7ac5dSMat Martineau 			struct l2cap_ctrl rr_control;
6076d2a7ac5dSMat Martineau 			memset(&rr_control, 0, sizeof(rr_control));
6077d2a7ac5dSMat Martineau 			rr_control.sframe = 1;
6078d2a7ac5dSMat Martineau 			rr_control.super = L2CAP_SUPER_RR;
6079d2a7ac5dSMat Martineau 			rr_control.reqseq = chan->buffer_seq;
6080d2a7ac5dSMat Martineau 			l2cap_send_sframe(chan, &rr_control);
6081d2a7ac5dSMat Martineau 		}
6082d2a7ac5dSMat Martineau 
6083d2a7ac5dSMat Martineau 		break;
6084d2a7ac5dSMat Martineau 	case L2CAP_EV_RECV_REJ:
6085d2a7ac5dSMat Martineau 		l2cap_handle_rej(chan, control);
6086d2a7ac5dSMat Martineau 		break;
6087d2a7ac5dSMat Martineau 	case L2CAP_EV_RECV_SREJ:
6088d2a7ac5dSMat Martineau 		l2cap_handle_srej(chan, control);
6089d2a7ac5dSMat Martineau 		break;
6090d2a7ac5dSMat Martineau 	}
6091d2a7ac5dSMat Martineau 
6092d2a7ac5dSMat Martineau 	if (skb && !skb_in_use) {
6093d2a7ac5dSMat Martineau 		BT_DBG("Freeing %p", skb);
6094d2a7ac5dSMat Martineau 		kfree_skb(skb);
6095d2a7ac5dSMat Martineau 	}
6096d2a7ac5dSMat Martineau 
6097d2a7ac5dSMat Martineau 	return err;
6098d2a7ac5dSMat Martineau }
6099d2a7ac5dSMat Martineau 
610032b32735SMat Martineau static int l2cap_finish_move(struct l2cap_chan *chan)
610132b32735SMat Martineau {
610232b32735SMat Martineau 	BT_DBG("chan %p", chan);
610332b32735SMat Martineau 
610432b32735SMat Martineau 	chan->rx_state = L2CAP_RX_STATE_RECV;
610532b32735SMat Martineau 
610632b32735SMat Martineau 	if (chan->hs_hcon)
610732b32735SMat Martineau 		chan->conn->mtu = chan->hs_hcon->hdev->block_mtu;
610832b32735SMat Martineau 	else
610932b32735SMat Martineau 		chan->conn->mtu = chan->conn->hcon->hdev->acl_mtu;
611032b32735SMat Martineau 
611132b32735SMat Martineau 	return l2cap_resegment(chan);
611232b32735SMat Martineau }
611332b32735SMat Martineau 
611432b32735SMat Martineau static int l2cap_rx_state_wait_p(struct l2cap_chan *chan,
611532b32735SMat Martineau 				 struct l2cap_ctrl *control,
611632b32735SMat Martineau 				 struct sk_buff *skb, u8 event)
611732b32735SMat Martineau {
611832b32735SMat Martineau 	int err;
611932b32735SMat Martineau 
612032b32735SMat Martineau 	BT_DBG("chan %p, control %p, skb %p, event %d", chan, control, skb,
612132b32735SMat Martineau 	       event);
612232b32735SMat Martineau 
612332b32735SMat Martineau 	if (!control->poll)
612432b32735SMat Martineau 		return -EPROTO;
612532b32735SMat Martineau 
612632b32735SMat Martineau 	l2cap_process_reqseq(chan, control->reqseq);
612732b32735SMat Martineau 
612832b32735SMat Martineau 	if (!skb_queue_empty(&chan->tx_q))
612932b32735SMat Martineau 		chan->tx_send_head = skb_peek(&chan->tx_q);
613032b32735SMat Martineau 	else
613132b32735SMat Martineau 		chan->tx_send_head = NULL;
613232b32735SMat Martineau 
613332b32735SMat Martineau 	/* Rewind next_tx_seq to the point expected
613432b32735SMat Martineau 	 * by the receiver.
613532b32735SMat Martineau 	 */
613632b32735SMat Martineau 	chan->next_tx_seq = control->reqseq;
613732b32735SMat Martineau 	chan->unacked_frames = 0;
613832b32735SMat Martineau 
613932b32735SMat Martineau 	err = l2cap_finish_move(chan);
614032b32735SMat Martineau 	if (err)
614132b32735SMat Martineau 		return err;
614232b32735SMat Martineau 
614332b32735SMat Martineau 	set_bit(CONN_SEND_FBIT, &chan->conn_state);
614432b32735SMat Martineau 	l2cap_send_i_or_rr_or_rnr(chan);
614532b32735SMat Martineau 
614632b32735SMat Martineau 	if (event == L2CAP_EV_RECV_IFRAME)
614732b32735SMat Martineau 		return -EPROTO;
614832b32735SMat Martineau 
614932b32735SMat Martineau 	return l2cap_rx_state_recv(chan, control, NULL, event);
615032b32735SMat Martineau }
615132b32735SMat Martineau 
615232b32735SMat Martineau static int l2cap_rx_state_wait_f(struct l2cap_chan *chan,
615332b32735SMat Martineau 				 struct l2cap_ctrl *control,
615432b32735SMat Martineau 				 struct sk_buff *skb, u8 event)
615532b32735SMat Martineau {
615632b32735SMat Martineau 	int err;
615732b32735SMat Martineau 
615832b32735SMat Martineau 	if (!control->final)
615932b32735SMat Martineau 		return -EPROTO;
616032b32735SMat Martineau 
616132b32735SMat Martineau 	clear_bit(CONN_REMOTE_BUSY, &chan->conn_state);
616232b32735SMat Martineau 
616332b32735SMat Martineau 	chan->rx_state = L2CAP_RX_STATE_RECV;
616432b32735SMat Martineau 	l2cap_process_reqseq(chan, control->reqseq);
616532b32735SMat Martineau 
616632b32735SMat Martineau 	if (!skb_queue_empty(&chan->tx_q))
616732b32735SMat Martineau 		chan->tx_send_head = skb_peek(&chan->tx_q);
616832b32735SMat Martineau 	else
616932b32735SMat Martineau 		chan->tx_send_head = NULL;
617032b32735SMat Martineau 
617132b32735SMat Martineau 	/* Rewind next_tx_seq to the point expected
617232b32735SMat Martineau 	 * by the receiver.
617332b32735SMat Martineau 	 */
617432b32735SMat Martineau 	chan->next_tx_seq = control->reqseq;
617532b32735SMat Martineau 	chan->unacked_frames = 0;
617632b32735SMat Martineau 
617732b32735SMat Martineau 	if (chan->hs_hcon)
617832b32735SMat Martineau 		chan->conn->mtu = chan->hs_hcon->hdev->block_mtu;
617932b32735SMat Martineau 	else
618032b32735SMat Martineau 		chan->conn->mtu = chan->conn->hcon->hdev->acl_mtu;
618132b32735SMat Martineau 
618232b32735SMat Martineau 	err = l2cap_resegment(chan);
618332b32735SMat Martineau 
618432b32735SMat Martineau 	if (!err)
618532b32735SMat Martineau 		err = l2cap_rx_state_recv(chan, control, skb, event);
618632b32735SMat Martineau 
618732b32735SMat Martineau 	return err;
618832b32735SMat Martineau }
618932b32735SMat Martineau 
6190d2a7ac5dSMat Martineau static bool __valid_reqseq(struct l2cap_chan *chan, u16 reqseq)
6191d2a7ac5dSMat Martineau {
6192d2a7ac5dSMat Martineau 	/* Make sure reqseq is for a packet that has been sent but not acked */
6193d2a7ac5dSMat Martineau 	u16 unacked;
6194d2a7ac5dSMat Martineau 
6195d2a7ac5dSMat Martineau 	unacked = __seq_offset(chan, chan->next_tx_seq, chan->expected_ack_seq);
6196d2a7ac5dSMat Martineau 	return __seq_offset(chan, chan->next_tx_seq, reqseq) <= unacked;
6197d2a7ac5dSMat Martineau }
6198d2a7ac5dSMat Martineau 
6199cec8ab6eSMat Martineau static int l2cap_rx(struct l2cap_chan *chan, struct l2cap_ctrl *control,
6200cec8ab6eSMat Martineau 		    struct sk_buff *skb, u8 event)
62010a708f8fSGustavo F. Padovan {
6202d2a7ac5dSMat Martineau 	int err = 0;
6203d2a7ac5dSMat Martineau 
6204d2a7ac5dSMat Martineau 	BT_DBG("chan %p, control %p, skb %p, event %d, state %d", chan,
6205d2a7ac5dSMat Martineau 	       control, skb, event, chan->rx_state);
6206d2a7ac5dSMat Martineau 
6207d2a7ac5dSMat Martineau 	if (__valid_reqseq(chan, control->reqseq)) {
6208d2a7ac5dSMat Martineau 		switch (chan->rx_state) {
6209d2a7ac5dSMat Martineau 		case L2CAP_RX_STATE_RECV:
6210d2a7ac5dSMat Martineau 			err = l2cap_rx_state_recv(chan, control, skb, event);
6211d2a7ac5dSMat Martineau 			break;
6212d2a7ac5dSMat Martineau 		case L2CAP_RX_STATE_SREJ_SENT:
6213d2a7ac5dSMat Martineau 			err = l2cap_rx_state_srej_sent(chan, control, skb,
6214d2a7ac5dSMat Martineau 						       event);
6215d2a7ac5dSMat Martineau 			break;
621632b32735SMat Martineau 		case L2CAP_RX_STATE_WAIT_P:
621732b32735SMat Martineau 			err = l2cap_rx_state_wait_p(chan, control, skb, event);
621832b32735SMat Martineau 			break;
621932b32735SMat Martineau 		case L2CAP_RX_STATE_WAIT_F:
622032b32735SMat Martineau 			err = l2cap_rx_state_wait_f(chan, control, skb, event);
622132b32735SMat Martineau 			break;
6222d2a7ac5dSMat Martineau 		default:
6223d2a7ac5dSMat Martineau 			/* shut it down */
6224d2a7ac5dSMat Martineau 			break;
6225d2a7ac5dSMat Martineau 		}
6226d2a7ac5dSMat Martineau 	} else {
6227d2a7ac5dSMat Martineau 		BT_DBG("Invalid reqseq %d (next_tx_seq %d, expected_ack_seq %d",
6228d2a7ac5dSMat Martineau 		       control->reqseq, chan->next_tx_seq,
6229d2a7ac5dSMat Martineau 		       chan->expected_ack_seq);
62305e4e3972SAndrei Emeltchenko 		l2cap_send_disconn_req(chan, ECONNRESET);
6231d2a7ac5dSMat Martineau 	}
6232d2a7ac5dSMat Martineau 
6233d2a7ac5dSMat Martineau 	return err;
6234cec8ab6eSMat Martineau }
6235cec8ab6eSMat Martineau 
6236cec8ab6eSMat Martineau static int l2cap_stream_rx(struct l2cap_chan *chan, struct l2cap_ctrl *control,
6237cec8ab6eSMat Martineau 			   struct sk_buff *skb)
6238cec8ab6eSMat Martineau {
62394b51dae9SMat Martineau 	int err = 0;
62404b51dae9SMat Martineau 
62414b51dae9SMat Martineau 	BT_DBG("chan %p, control %p, skb %p, state %d", chan, control, skb,
62424b51dae9SMat Martineau 	       chan->rx_state);
62434b51dae9SMat Martineau 
62444b51dae9SMat Martineau 	if (l2cap_classify_txseq(chan, control->txseq) ==
62454b51dae9SMat Martineau 	    L2CAP_TXSEQ_EXPECTED) {
62464b51dae9SMat Martineau 		l2cap_pass_to_tx(chan, control);
62474b51dae9SMat Martineau 
62484b51dae9SMat Martineau 		BT_DBG("buffer_seq %d->%d", chan->buffer_seq,
62494b51dae9SMat Martineau 		       __next_seq(chan, chan->buffer_seq));
62504b51dae9SMat Martineau 
62514b51dae9SMat Martineau 		chan->buffer_seq = __next_seq(chan, chan->buffer_seq);
62524b51dae9SMat Martineau 
62534b51dae9SMat Martineau 		l2cap_reassemble_sdu(chan, skb, control);
62544b51dae9SMat Martineau 	} else {
62554b51dae9SMat Martineau 		if (chan->sdu) {
62564b51dae9SMat Martineau 			kfree_skb(chan->sdu);
62574b51dae9SMat Martineau 			chan->sdu = NULL;
62584b51dae9SMat Martineau 		}
62594b51dae9SMat Martineau 		chan->sdu_last_frag = NULL;
62604b51dae9SMat Martineau 		chan->sdu_len = 0;
62614b51dae9SMat Martineau 
62624b51dae9SMat Martineau 		if (skb) {
62634b51dae9SMat Martineau 			BT_DBG("Freeing %p", skb);
62644b51dae9SMat Martineau 			kfree_skb(skb);
62654b51dae9SMat Martineau 		}
62664b51dae9SMat Martineau 	}
62674b51dae9SMat Martineau 
62684b51dae9SMat Martineau 	chan->last_acked_seq = control->txseq;
62694b51dae9SMat Martineau 	chan->expected_tx_seq = __next_seq(chan, control->txseq);
62704b51dae9SMat Martineau 
62714b51dae9SMat Martineau 	return err;
6272cec8ab6eSMat Martineau }
6273cec8ab6eSMat Martineau 
6274cec8ab6eSMat Martineau static int l2cap_data_rcv(struct l2cap_chan *chan, struct sk_buff *skb)
6275cec8ab6eSMat Martineau {
6276cec8ab6eSMat Martineau 	struct l2cap_ctrl *control = &bt_cb(skb)->control;
6277cec8ab6eSMat Martineau 	u16 len;
6278cec8ab6eSMat Martineau 	u8 event;
62790a708f8fSGustavo F. Padovan 
6280b76bbd66SMat Martineau 	__unpack_control(chan, skb);
6281b76bbd66SMat Martineau 
62820a708f8fSGustavo F. Padovan 	len = skb->len;
62830a708f8fSGustavo F. Padovan 
62840a708f8fSGustavo F. Padovan 	/*
62850a708f8fSGustavo F. Padovan 	 * We can just drop the corrupted I-frame here.
62860a708f8fSGustavo F. Padovan 	 * Receiver will miss it and start proper recovery
6287cec8ab6eSMat Martineau 	 * procedures and ask for retransmission.
62880a708f8fSGustavo F. Padovan 	 */
628947d1ec61SGustavo F. Padovan 	if (l2cap_check_fcs(chan, skb))
62900a708f8fSGustavo F. Padovan 		goto drop;
62910a708f8fSGustavo F. Padovan 
6292cec8ab6eSMat Martineau 	if (!control->sframe && control->sar == L2CAP_SAR_START)
629303a51213SAndrei Emeltchenko 		len -= L2CAP_SDULEN_SIZE;
62940a708f8fSGustavo F. Padovan 
629547d1ec61SGustavo F. Padovan 	if (chan->fcs == L2CAP_FCS_CRC16)
629603a51213SAndrei Emeltchenko 		len -= L2CAP_FCS_SIZE;
62970a708f8fSGustavo F. Padovan 
629847d1ec61SGustavo F. Padovan 	if (len > chan->mps) {
62995e4e3972SAndrei Emeltchenko 		l2cap_send_disconn_req(chan, ECONNRESET);
63000a708f8fSGustavo F. Padovan 		goto drop;
63010a708f8fSGustavo F. Padovan 	}
63020a708f8fSGustavo F. Padovan 
6303cec8ab6eSMat Martineau 	if (!control->sframe) {
6304cec8ab6eSMat Martineau 		int err;
63050a708f8fSGustavo F. Padovan 
6306cec8ab6eSMat Martineau 		BT_DBG("iframe sar %d, reqseq %d, final %d, txseq %d",
6307cec8ab6eSMat Martineau 		       control->sar, control->reqseq, control->final,
6308cec8ab6eSMat Martineau 		       control->txseq);
6309836be934SAndrei Emeltchenko 
6310cec8ab6eSMat Martineau 		/* Validate F-bit - F=0 always valid, F=1 only
6311cec8ab6eSMat Martineau 		 * valid in TX WAIT_F
6312cec8ab6eSMat Martineau 		 */
6313cec8ab6eSMat Martineau 		if (control->final && chan->tx_state != L2CAP_TX_STATE_WAIT_F)
63140a708f8fSGustavo F. Padovan 			goto drop;
63150a708f8fSGustavo F. Padovan 
6316cec8ab6eSMat Martineau 		if (chan->mode != L2CAP_MODE_STREAMING) {
6317cec8ab6eSMat Martineau 			event = L2CAP_EV_RECV_IFRAME;
6318cec8ab6eSMat Martineau 			err = l2cap_rx(chan, control, skb, event);
63190a708f8fSGustavo F. Padovan 		} else {
6320cec8ab6eSMat Martineau 			err = l2cap_stream_rx(chan, control, skb);
6321cec8ab6eSMat Martineau 		}
6322cec8ab6eSMat Martineau 
6323cec8ab6eSMat Martineau 		if (err)
63245e4e3972SAndrei Emeltchenko 			l2cap_send_disconn_req(chan, ECONNRESET);
6325cec8ab6eSMat Martineau 	} else {
6326cec8ab6eSMat Martineau 		const u8 rx_func_to_event[4] = {
6327cec8ab6eSMat Martineau 			L2CAP_EV_RECV_RR, L2CAP_EV_RECV_REJ,
6328cec8ab6eSMat Martineau 			L2CAP_EV_RECV_RNR, L2CAP_EV_RECV_SREJ
6329cec8ab6eSMat Martineau 		};
6330cec8ab6eSMat Martineau 
6331cec8ab6eSMat Martineau 		/* Only I-frames are expected in streaming mode */
6332cec8ab6eSMat Martineau 		if (chan->mode == L2CAP_MODE_STREAMING)
6333cec8ab6eSMat Martineau 			goto drop;
6334cec8ab6eSMat Martineau 
6335cec8ab6eSMat Martineau 		BT_DBG("sframe reqseq %d, final %d, poll %d, super %d",
6336cec8ab6eSMat Martineau 		       control->reqseq, control->final, control->poll,
6337cec8ab6eSMat Martineau 		       control->super);
6338cec8ab6eSMat Martineau 
63390a708f8fSGustavo F. Padovan 		if (len != 0) {
63401bb166e6SAndrei Emeltchenko 			BT_ERR("Trailing bytes: %d in sframe", len);
63415e4e3972SAndrei Emeltchenko 			l2cap_send_disconn_req(chan, ECONNRESET);
63420a708f8fSGustavo F. Padovan 			goto drop;
63430a708f8fSGustavo F. Padovan 		}
63440a708f8fSGustavo F. Padovan 
6345cec8ab6eSMat Martineau 		/* Validate F and P bits */
6346cec8ab6eSMat Martineau 		if (control->final && (control->poll ||
6347cec8ab6eSMat Martineau 				       chan->tx_state != L2CAP_TX_STATE_WAIT_F))
6348cec8ab6eSMat Martineau 			goto drop;
6349cec8ab6eSMat Martineau 
6350cec8ab6eSMat Martineau 		event = rx_func_to_event[control->super];
6351cec8ab6eSMat Martineau 		if (l2cap_rx(chan, control, skb, event))
63525e4e3972SAndrei Emeltchenko 			l2cap_send_disconn_req(chan, ECONNRESET);
63530a708f8fSGustavo F. Padovan 	}
63540a708f8fSGustavo F. Padovan 
63550a708f8fSGustavo F. Padovan 	return 0;
63560a708f8fSGustavo F. Padovan 
63570a708f8fSGustavo F. Padovan drop:
63580a708f8fSGustavo F. Padovan 	kfree_skb(skb);
63590a708f8fSGustavo F. Padovan 	return 0;
63600a708f8fSGustavo F. Padovan }
63610a708f8fSGustavo F. Padovan 
636213ca56e0SAndrei Emeltchenko static void l2cap_data_channel(struct l2cap_conn *conn, u16 cid,
636313ca56e0SAndrei Emeltchenko 			       struct sk_buff *skb)
63640a708f8fSGustavo F. Padovan {
636548454079SGustavo F. Padovan 	struct l2cap_chan *chan;
63660a708f8fSGustavo F. Padovan 
6367baa7e1faSGustavo F. Padovan 	chan = l2cap_get_chan_by_scid(conn, cid);
636848454079SGustavo F. Padovan 	if (!chan) {
636997e8e89dSAndrei Emeltchenko 		if (cid == L2CAP_CID_A2MP) {
637097e8e89dSAndrei Emeltchenko 			chan = a2mp_channel_create(conn, skb);
637197e8e89dSAndrei Emeltchenko 			if (!chan) {
637297e8e89dSAndrei Emeltchenko 				kfree_skb(skb);
637313ca56e0SAndrei Emeltchenko 				return;
637497e8e89dSAndrei Emeltchenko 			}
637597e8e89dSAndrei Emeltchenko 
637697e8e89dSAndrei Emeltchenko 			l2cap_chan_lock(chan);
637797e8e89dSAndrei Emeltchenko 		} else {
63780a708f8fSGustavo F. Padovan 			BT_DBG("unknown cid 0x%4.4x", cid);
63796be36555SAndrei Emeltchenko 			/* Drop packet and return */
63803379013bSDan Carpenter 			kfree_skb(skb);
638113ca56e0SAndrei Emeltchenko 			return;
63820a708f8fSGustavo F. Padovan 		}
638397e8e89dSAndrei Emeltchenko 	}
63840a708f8fSGustavo F. Padovan 
638549208c9cSGustavo F. Padovan 	BT_DBG("chan %p, len %d", chan, skb->len);
63860a708f8fSGustavo F. Padovan 
638789bc500eSGustavo F. Padovan 	if (chan->state != BT_CONNECTED)
63880a708f8fSGustavo F. Padovan 		goto drop;
63890a708f8fSGustavo F. Padovan 
63900c1bc5c6SGustavo F. Padovan 	switch (chan->mode) {
63910a708f8fSGustavo F. Padovan 	case L2CAP_MODE_BASIC:
63920a708f8fSGustavo F. Padovan 		/* If socket recv buffers overflows we drop data here
63930a708f8fSGustavo F. Padovan 		 * which is *bad* because L2CAP has to be reliable.
63940a708f8fSGustavo F. Padovan 		 * But we don't have any other choice. L2CAP doesn't
63950a708f8fSGustavo F. Padovan 		 * provide flow control mechanism. */
63960a708f8fSGustavo F. Padovan 
63970c1bc5c6SGustavo F. Padovan 		if (chan->imtu < skb->len)
63980a708f8fSGustavo F. Padovan 			goto drop;
63990a708f8fSGustavo F. Padovan 
640080b98027SGustavo Padovan 		if (!chan->ops->recv(chan, skb))
64010a708f8fSGustavo F. Padovan 			goto done;
64020a708f8fSGustavo F. Padovan 		break;
64030a708f8fSGustavo F. Padovan 
64040a708f8fSGustavo F. Padovan 	case L2CAP_MODE_ERTM:
64050a708f8fSGustavo F. Padovan 	case L2CAP_MODE_STREAMING:
6406cec8ab6eSMat Martineau 		l2cap_data_rcv(chan, skb);
64070a708f8fSGustavo F. Padovan 		goto done;
64080a708f8fSGustavo F. Padovan 
64090a708f8fSGustavo F. Padovan 	default:
64100c1bc5c6SGustavo F. Padovan 		BT_DBG("chan %p: bad mode 0x%2.2x", chan, chan->mode);
64110a708f8fSGustavo F. Padovan 		break;
64120a708f8fSGustavo F. Padovan 	}
64130a708f8fSGustavo F. Padovan 
64140a708f8fSGustavo F. Padovan drop:
64150a708f8fSGustavo F. Padovan 	kfree_skb(skb);
64160a708f8fSGustavo F. Padovan 
64170a708f8fSGustavo F. Padovan done:
64186be36555SAndrei Emeltchenko 	l2cap_chan_unlock(chan);
64190a708f8fSGustavo F. Padovan }
64200a708f8fSGustavo F. Padovan 
642184104b24SAndrei Emeltchenko static void l2cap_conless_channel(struct l2cap_conn *conn, __le16 psm,
642284104b24SAndrei Emeltchenko 				  struct sk_buff *skb)
64230a708f8fSGustavo F. Padovan {
6424ae4fd2d3SMarcel Holtmann 	struct hci_conn *hcon = conn->hcon;
642523691d75SGustavo F. Padovan 	struct l2cap_chan *chan;
64260a708f8fSGustavo F. Padovan 
6427ae4fd2d3SMarcel Holtmann 	if (hcon->type != ACL_LINK)
6428ae4fd2d3SMarcel Holtmann 		goto drop;
6429ae4fd2d3SMarcel Holtmann 
6430c2287681SIdo Yariv 	chan = l2cap_global_chan_by_psm(0, psm, conn->src, conn->dst);
643123691d75SGustavo F. Padovan 	if (!chan)
64320a708f8fSGustavo F. Padovan 		goto drop;
64330a708f8fSGustavo F. Padovan 
64345b4cedaaSAndrei Emeltchenko 	BT_DBG("chan %p, len %d", chan, skb->len);
64350a708f8fSGustavo F. Padovan 
643689bc500eSGustavo F. Padovan 	if (chan->state != BT_BOUND && chan->state != BT_CONNECTED)
64370a708f8fSGustavo F. Padovan 		goto drop;
64380a708f8fSGustavo F. Padovan 
6439e13e21dcSVinicius Costa Gomes 	if (chan->imtu < skb->len)
64400a708f8fSGustavo F. Padovan 		goto drop;
64410a708f8fSGustavo F. Padovan 
644280b98027SGustavo Padovan 	if (!chan->ops->recv(chan, skb))
644384104b24SAndrei Emeltchenko 		return;
64440a708f8fSGustavo F. Padovan 
64450a708f8fSGustavo F. Padovan drop:
64460a708f8fSGustavo F. Padovan 	kfree_skb(skb);
64470a708f8fSGustavo F. Padovan }
64480a708f8fSGustavo F. Padovan 
644972f78356SMarcel Holtmann static void l2cap_att_channel(struct l2cap_conn *conn,
6450d9b88702SAndrei Emeltchenko 			      struct sk_buff *skb)
64519f69bda6SGustavo F. Padovan {
6452b99707d7SMarcel Holtmann 	struct hci_conn *hcon = conn->hcon;
645323691d75SGustavo F. Padovan 	struct l2cap_chan *chan;
64549f69bda6SGustavo F. Padovan 
6455b99707d7SMarcel Holtmann 	if (hcon->type != LE_LINK)
6456b99707d7SMarcel Holtmann 		goto drop;
6457b99707d7SMarcel Holtmann 
6458af1c0134SJohan Hedberg 	chan = l2cap_global_chan_by_scid(BT_CONNECTED, L2CAP_CID_ATT,
645972f78356SMarcel Holtmann 					 conn->src, conn->dst);
646023691d75SGustavo F. Padovan 	if (!chan)
64619f69bda6SGustavo F. Padovan 		goto drop;
64629f69bda6SGustavo F. Padovan 
64635b4cedaaSAndrei Emeltchenko 	BT_DBG("chan %p, len %d", chan, skb->len);
64649f69bda6SGustavo F. Padovan 
6465e13e21dcSVinicius Costa Gomes 	if (chan->imtu < skb->len)
64669f69bda6SGustavo F. Padovan 		goto drop;
64679f69bda6SGustavo F. Padovan 
646880b98027SGustavo Padovan 	if (!chan->ops->recv(chan, skb))
64696810fca7SAndrei Emeltchenko 		return;
64709f69bda6SGustavo F. Padovan 
64719f69bda6SGustavo F. Padovan drop:
64729f69bda6SGustavo F. Padovan 	kfree_skb(skb);
64739f69bda6SGustavo F. Padovan }
64749f69bda6SGustavo F. Padovan 
64750a708f8fSGustavo F. Padovan static void l2cap_recv_frame(struct l2cap_conn *conn, struct sk_buff *skb)
64760a708f8fSGustavo F. Padovan {
64770a708f8fSGustavo F. Padovan 	struct l2cap_hdr *lh = (void *) skb->data;
64780a708f8fSGustavo F. Padovan 	u16 cid, len;
64790a708f8fSGustavo F. Padovan 	__le16 psm;
64800a708f8fSGustavo F. Padovan 
64810a708f8fSGustavo F. Padovan 	skb_pull(skb, L2CAP_HDR_SIZE);
64820a708f8fSGustavo F. Padovan 	cid = __le16_to_cpu(lh->cid);
64830a708f8fSGustavo F. Padovan 	len = __le16_to_cpu(lh->len);
64840a708f8fSGustavo F. Padovan 
64850a708f8fSGustavo F. Padovan 	if (len != skb->len) {
64860a708f8fSGustavo F. Padovan 		kfree_skb(skb);
64870a708f8fSGustavo F. Padovan 		return;
64880a708f8fSGustavo F. Padovan 	}
64890a708f8fSGustavo F. Padovan 
64900a708f8fSGustavo F. Padovan 	BT_DBG("len %d, cid 0x%4.4x", len, cid);
64910a708f8fSGustavo F. Padovan 
64920a708f8fSGustavo F. Padovan 	switch (cid) {
64930a708f8fSGustavo F. Padovan 	case L2CAP_CID_SIGNALING:
64940a708f8fSGustavo F. Padovan 		l2cap_sig_channel(conn, skb);
64950a708f8fSGustavo F. Padovan 		break;
64960a708f8fSGustavo F. Padovan 
64970a708f8fSGustavo F. Padovan 	case L2CAP_CID_CONN_LESS:
6498097db76cSAndrei Emeltchenko 		psm = get_unaligned((__le16 *) skb->data);
64990181a70fSAndrei Emeltchenko 		skb_pull(skb, L2CAP_PSMLEN_SIZE);
65000a708f8fSGustavo F. Padovan 		l2cap_conless_channel(conn, psm, skb);
65010a708f8fSGustavo F. Padovan 		break;
65020a708f8fSGustavo F. Padovan 
6503073d1cf3SJohan Hedberg 	case L2CAP_CID_ATT:
650472f78356SMarcel Holtmann 		l2cap_att_channel(conn, skb);
65059f69bda6SGustavo F. Padovan 		break;
65069f69bda6SGustavo F. Padovan 
6507a2877629SMarcel Holtmann 	case L2CAP_CID_LE_SIGNALING:
6508a2877629SMarcel Holtmann 		l2cap_le_sig_channel(conn, skb);
6509a2877629SMarcel Holtmann 		break;
6510a2877629SMarcel Holtmann 
6511b501d6a1SAnderson Briglia 	case L2CAP_CID_SMP:
6512b501d6a1SAnderson Briglia 		if (smp_sig_channel(conn, skb))
6513b501d6a1SAnderson Briglia 			l2cap_conn_del(conn->hcon, EACCES);
6514b501d6a1SAnderson Briglia 		break;
6515b501d6a1SAnderson Briglia 
65160a708f8fSGustavo F. Padovan 	default:
65170a708f8fSGustavo F. Padovan 		l2cap_data_channel(conn, cid, skb);
65180a708f8fSGustavo F. Padovan 		break;
65190a708f8fSGustavo F. Padovan 	}
65200a708f8fSGustavo F. Padovan }
65210a708f8fSGustavo F. Padovan 
65220a708f8fSGustavo F. Padovan /* ---- L2CAP interface with lower layer (HCI) ---- */
65230a708f8fSGustavo F. Padovan 
6524686ebf28SUlisses Furquim int l2cap_connect_ind(struct hci_dev *hdev, bdaddr_t *bdaddr)
65250a708f8fSGustavo F. Padovan {
65260a708f8fSGustavo F. Padovan 	int exact = 0, lm1 = 0, lm2 = 0;
652723691d75SGustavo F. Padovan 	struct l2cap_chan *c;
65280a708f8fSGustavo F. Padovan 
65296ed93dc6SAndrei Emeltchenko 	BT_DBG("hdev %s, bdaddr %pMR", hdev->name, bdaddr);
65300a708f8fSGustavo F. Padovan 
65310a708f8fSGustavo F. Padovan 	/* Find listening sockets and check their link_mode */
653223691d75SGustavo F. Padovan 	read_lock(&chan_list_lock);
653323691d75SGustavo F. Padovan 	list_for_each_entry(c, &chan_list, global_l) {
653423691d75SGustavo F. Padovan 		struct sock *sk = c->sk;
65354343478fSGustavo F. Padovan 
653689bc500eSGustavo F. Padovan 		if (c->state != BT_LISTEN)
65370a708f8fSGustavo F. Padovan 			continue;
65380a708f8fSGustavo F. Padovan 
65390a708f8fSGustavo F. Padovan 		if (!bacmp(&bt_sk(sk)->src, &hdev->bdaddr)) {
65400a708f8fSGustavo F. Padovan 			lm1 |= HCI_LM_ACCEPT;
654143bd0f32SAndrei Emeltchenko 			if (test_bit(FLAG_ROLE_SWITCH, &c->flags))
65420a708f8fSGustavo F. Padovan 				lm1 |= HCI_LM_MASTER;
65430a708f8fSGustavo F. Padovan 			exact++;
65440a708f8fSGustavo F. Padovan 		} else if (!bacmp(&bt_sk(sk)->src, BDADDR_ANY)) {
65450a708f8fSGustavo F. Padovan 			lm2 |= HCI_LM_ACCEPT;
654643bd0f32SAndrei Emeltchenko 			if (test_bit(FLAG_ROLE_SWITCH, &c->flags))
65470a708f8fSGustavo F. Padovan 				lm2 |= HCI_LM_MASTER;
65480a708f8fSGustavo F. Padovan 		}
65490a708f8fSGustavo F. Padovan 	}
655023691d75SGustavo F. Padovan 	read_unlock(&chan_list_lock);
65510a708f8fSGustavo F. Padovan 
65520a708f8fSGustavo F. Padovan 	return exact ? lm1 : lm2;
65530a708f8fSGustavo F. Padovan }
65540a708f8fSGustavo F. Padovan 
65559e664631SAndrei Emeltchenko void l2cap_connect_cfm(struct hci_conn *hcon, u8 status)
65560a708f8fSGustavo F. Padovan {
65570a708f8fSGustavo F. Padovan 	struct l2cap_conn *conn;
65580a708f8fSGustavo F. Padovan 
65596ed93dc6SAndrei Emeltchenko 	BT_DBG("hcon %p bdaddr %pMR status %d", hcon, &hcon->dst, status);
65600a708f8fSGustavo F. Padovan 
65610a708f8fSGustavo F. Padovan 	if (!status) {
6562baf43251SClaudio Takahasi 		conn = l2cap_conn_add(hcon);
65630a708f8fSGustavo F. Padovan 		if (conn)
65640a708f8fSGustavo F. Padovan 			l2cap_conn_ready(conn);
6565ba6fc317SAndrei Emeltchenko 	} else {
6566e175072fSJoe Perches 		l2cap_conn_del(hcon, bt_to_errno(status));
6567ba6fc317SAndrei Emeltchenko 	}
65680a708f8fSGustavo F. Padovan }
65690a708f8fSGustavo F. Padovan 
6570686ebf28SUlisses Furquim int l2cap_disconn_ind(struct hci_conn *hcon)
65710a708f8fSGustavo F. Padovan {
65720a708f8fSGustavo F. Padovan 	struct l2cap_conn *conn = hcon->l2cap_data;
65730a708f8fSGustavo F. Padovan 
65740a708f8fSGustavo F. Padovan 	BT_DBG("hcon %p", hcon);
65750a708f8fSGustavo F. Padovan 
6576686ebf28SUlisses Furquim 	if (!conn)
65779f5a0d7bSAndrei Emeltchenko 		return HCI_ERROR_REMOTE_USER_TERM;
65780a708f8fSGustavo F. Padovan 	return conn->disc_reason;
65790a708f8fSGustavo F. Padovan }
65800a708f8fSGustavo F. Padovan 
65819e664631SAndrei Emeltchenko void l2cap_disconn_cfm(struct hci_conn *hcon, u8 reason)
65820a708f8fSGustavo F. Padovan {
65830a708f8fSGustavo F. Padovan 	BT_DBG("hcon %p reason %d", hcon, reason);
65840a708f8fSGustavo F. Padovan 
6585e175072fSJoe Perches 	l2cap_conn_del(hcon, bt_to_errno(reason));
65860a708f8fSGustavo F. Padovan }
65870a708f8fSGustavo F. Padovan 
65884343478fSGustavo F. Padovan static inline void l2cap_check_encryption(struct l2cap_chan *chan, u8 encrypt)
65890a708f8fSGustavo F. Padovan {
6590715ec005SGustavo F. Padovan 	if (chan->chan_type != L2CAP_CHAN_CONN_ORIENTED)
65910a708f8fSGustavo F. Padovan 		return;
65920a708f8fSGustavo F. Padovan 
65930a708f8fSGustavo F. Padovan 	if (encrypt == 0x00) {
65944343478fSGustavo F. Padovan 		if (chan->sec_level == BT_SECURITY_MEDIUM) {
6595ba13ccd9SMarcel Holtmann 			__set_chan_timer(chan, L2CAP_ENC_TIMEOUT);
65964343478fSGustavo F. Padovan 		} else if (chan->sec_level == BT_SECURITY_HIGH)
65970f852724SGustavo F. Padovan 			l2cap_chan_close(chan, ECONNREFUSED);
65980a708f8fSGustavo F. Padovan 	} else {
65994343478fSGustavo F. Padovan 		if (chan->sec_level == BT_SECURITY_MEDIUM)
6600c9b66675SGustavo F. Padovan 			__clear_chan_timer(chan);
66010a708f8fSGustavo F. Padovan 	}
66020a708f8fSGustavo F. Padovan }
66030a708f8fSGustavo F. Padovan 
6604686ebf28SUlisses Furquim int l2cap_security_cfm(struct hci_conn *hcon, u8 status, u8 encrypt)
66050a708f8fSGustavo F. Padovan {
66060a708f8fSGustavo F. Padovan 	struct l2cap_conn *conn = hcon->l2cap_data;
660748454079SGustavo F. Padovan 	struct l2cap_chan *chan;
66080a708f8fSGustavo F. Padovan 
66090a708f8fSGustavo F. Padovan 	if (!conn)
66100a708f8fSGustavo F. Padovan 		return 0;
66110a708f8fSGustavo F. Padovan 
661289d8b407SAndrei Emeltchenko 	BT_DBG("conn %p status 0x%2.2x encrypt %u", conn, status, encrypt);
66130a708f8fSGustavo F. Padovan 
6614160dc6acSVinicius Costa Gomes 	if (hcon->type == LE_LINK) {
661535d4adccSHemant Gupta 		if (!status && encrypt)
6616160dc6acSVinicius Costa Gomes 			smp_distribute_keys(conn, 0);
661717cd3f37SUlisses Furquim 		cancel_delayed_work(&conn->security_timer);
6618160dc6acSVinicius Costa Gomes 	}
6619160dc6acSVinicius Costa Gomes 
66203df91ea2SAndrei Emeltchenko 	mutex_lock(&conn->chan_lock);
66210a708f8fSGustavo F. Padovan 
66223df91ea2SAndrei Emeltchenko 	list_for_each_entry(chan, &conn->chan_l, list) {
66236be36555SAndrei Emeltchenko 		l2cap_chan_lock(chan);
66240a708f8fSGustavo F. Padovan 
662589d8b407SAndrei Emeltchenko 		BT_DBG("chan %p scid 0x%4.4x state %s", chan, chan->scid,
662689d8b407SAndrei Emeltchenko 		       state_to_string(chan->state));
6627f1cb9af5SVinicius Costa Gomes 
662878eb2f98SAndrei Emeltchenko 		if (chan->chan_type == L2CAP_CHAN_CONN_FIX_A2MP) {
662978eb2f98SAndrei Emeltchenko 			l2cap_chan_unlock(chan);
663078eb2f98SAndrei Emeltchenko 			continue;
663178eb2f98SAndrei Emeltchenko 		}
663278eb2f98SAndrei Emeltchenko 
6633073d1cf3SJohan Hedberg 		if (chan->scid == L2CAP_CID_ATT) {
6634f1cb9af5SVinicius Costa Gomes 			if (!status && encrypt) {
6635f1cb9af5SVinicius Costa Gomes 				chan->sec_level = hcon->sec_level;
6636cf4cd009SAndrei Emeltchenko 				l2cap_chan_ready(chan);
6637f1cb9af5SVinicius Costa Gomes 			}
6638f1cb9af5SVinicius Costa Gomes 
66396be36555SAndrei Emeltchenko 			l2cap_chan_unlock(chan);
6640f1cb9af5SVinicius Costa Gomes 			continue;
6641f1cb9af5SVinicius Costa Gomes 		}
6642f1cb9af5SVinicius Costa Gomes 
664396eff46eSAndrei Emeltchenko 		if (!__l2cap_no_conn_pending(chan)) {
66446be36555SAndrei Emeltchenko 			l2cap_chan_unlock(chan);
66450a708f8fSGustavo F. Padovan 			continue;
66460a708f8fSGustavo F. Padovan 		}
66470a708f8fSGustavo F. Padovan 
664889bc500eSGustavo F. Padovan 		if (!status && (chan->state == BT_CONNECTED ||
664989bc500eSGustavo F. Padovan 				chan->state == BT_CONFIG)) {
6650a7d7723aSGustavo Padovan 			struct sock *sk = chan->sk;
6651a7d7723aSGustavo Padovan 
6652c5daa683SGustavo Padovan 			clear_bit(BT_SK_SUSPEND, &bt_sk(sk)->flags);
6653a7d7723aSGustavo Padovan 			sk->sk_state_change(sk);
6654a7d7723aSGustavo Padovan 
66554343478fSGustavo F. Padovan 			l2cap_check_encryption(chan, encrypt);
66566be36555SAndrei Emeltchenko 			l2cap_chan_unlock(chan);
66570a708f8fSGustavo F. Padovan 			continue;
66580a708f8fSGustavo F. Padovan 		}
66590a708f8fSGustavo F. Padovan 
666089bc500eSGustavo F. Padovan 		if (chan->state == BT_CONNECT) {
66610a708f8fSGustavo F. Padovan 			if (!status) {
666293c3e8f5SAndrei Emeltchenko 				l2cap_start_connection(chan);
66630a708f8fSGustavo F. Padovan 			} else {
6664ba13ccd9SMarcel Holtmann 				__set_chan_timer(chan, L2CAP_DISC_TIMEOUT);
66650a708f8fSGustavo F. Padovan 			}
666689bc500eSGustavo F. Padovan 		} else if (chan->state == BT_CONNECT2) {
66676be36555SAndrei Emeltchenko 			struct sock *sk = chan->sk;
66680a708f8fSGustavo F. Padovan 			struct l2cap_conn_rsp rsp;
6669df3c3931SJohan Hedberg 			__u16 res, stat;
66700a708f8fSGustavo F. Padovan 
66716be36555SAndrei Emeltchenko 			lock_sock(sk);
66726be36555SAndrei Emeltchenko 
66730a708f8fSGustavo F. Padovan 			if (!status) {
6674c5daa683SGustavo Padovan 				if (test_bit(BT_SK_DEFER_SETUP,
6675c5daa683SGustavo Padovan 					     &bt_sk(sk)->flags)) {
6676df3c3931SJohan Hedberg 					res = L2CAP_CR_PEND;
6677df3c3931SJohan Hedberg 					stat = L2CAP_CS_AUTHOR_PEND;
66782dc4e510SGustavo Padovan 					chan->ops->defer(chan);
6679df3c3931SJohan Hedberg 				} else {
66800e587be7SAndrei Emeltchenko 					__l2cap_state_change(chan, BT_CONFIG);
6681df3c3931SJohan Hedberg 					res = L2CAP_CR_SUCCESS;
6682df3c3931SJohan Hedberg 					stat = L2CAP_CS_NO_INFO;
6683df3c3931SJohan Hedberg 				}
66840a708f8fSGustavo F. Padovan 			} else {
66850e587be7SAndrei Emeltchenko 				__l2cap_state_change(chan, BT_DISCONN);
6686ba13ccd9SMarcel Holtmann 				__set_chan_timer(chan, L2CAP_DISC_TIMEOUT);
6687df3c3931SJohan Hedberg 				res = L2CAP_CR_SEC_BLOCK;
6688df3c3931SJohan Hedberg 				stat = L2CAP_CS_NO_INFO;
66890a708f8fSGustavo F. Padovan 			}
66900a708f8fSGustavo F. Padovan 
66916be36555SAndrei Emeltchenko 			release_sock(sk);
66926be36555SAndrei Emeltchenko 
6693fe4128e0SGustavo F. Padovan 			rsp.scid   = cpu_to_le16(chan->dcid);
6694fe4128e0SGustavo F. Padovan 			rsp.dcid   = cpu_to_le16(chan->scid);
6695df3c3931SJohan Hedberg 			rsp.result = cpu_to_le16(res);
6696df3c3931SJohan Hedberg 			rsp.status = cpu_to_le16(stat);
6697fc7f8a7eSGustavo F. Padovan 			l2cap_send_cmd(conn, chan->ident, L2CAP_CONN_RSP,
6698fc7f8a7eSGustavo F. Padovan 				       sizeof(rsp), &rsp);
66992d369359SMat Martineau 
67002d369359SMat Martineau 			if (!test_bit(CONF_REQ_SENT, &chan->conf_state) &&
67012d369359SMat Martineau 			    res == L2CAP_CR_SUCCESS) {
67022d369359SMat Martineau 				char buf[128];
67032d369359SMat Martineau 				set_bit(CONF_REQ_SENT, &chan->conf_state);
67042d369359SMat Martineau 				l2cap_send_cmd(conn, l2cap_get_ident(conn),
67052d369359SMat Martineau 					       L2CAP_CONF_REQ,
67062d369359SMat Martineau 					       l2cap_build_conf_req(chan, buf),
67072d369359SMat Martineau 					       buf);
67082d369359SMat Martineau 				chan->num_conf_req++;
67092d369359SMat Martineau 			}
67100a708f8fSGustavo F. Padovan 		}
67110a708f8fSGustavo F. Padovan 
67126be36555SAndrei Emeltchenko 		l2cap_chan_unlock(chan);
67130a708f8fSGustavo F. Padovan 	}
67140a708f8fSGustavo F. Padovan 
67153df91ea2SAndrei Emeltchenko 	mutex_unlock(&conn->chan_lock);
67160a708f8fSGustavo F. Padovan 
67170a708f8fSGustavo F. Padovan 	return 0;
67180a708f8fSGustavo F. Padovan }
67190a708f8fSGustavo F. Padovan 
6720686ebf28SUlisses Furquim int l2cap_recv_acldata(struct hci_conn *hcon, struct sk_buff *skb, u16 flags)
67210a708f8fSGustavo F. Padovan {
67220a708f8fSGustavo F. Padovan 	struct l2cap_conn *conn = hcon->l2cap_data;
6723d73a0988SAndrei Emeltchenko 	struct l2cap_hdr *hdr;
6724d73a0988SAndrei Emeltchenko 	int len;
67250a708f8fSGustavo F. Padovan 
67261d13a254SAndrei Emeltchenko 	/* For AMP controller do not create l2cap conn */
67271d13a254SAndrei Emeltchenko 	if (!conn && hcon->hdev->dev_type != HCI_BREDR)
67281d13a254SAndrei Emeltchenko 		goto drop;
67290a708f8fSGustavo F. Padovan 
67300a708f8fSGustavo F. Padovan 	if (!conn)
6731baf43251SClaudio Takahasi 		conn = l2cap_conn_add(hcon);
67320a708f8fSGustavo F. Padovan 
67330a708f8fSGustavo F. Padovan 	if (!conn)
67340a708f8fSGustavo F. Padovan 		goto drop;
67350a708f8fSGustavo F. Padovan 
67360a708f8fSGustavo F. Padovan 	BT_DBG("conn %p len %d flags 0x%x", conn, skb->len, flags);
67370a708f8fSGustavo F. Padovan 
6738d73a0988SAndrei Emeltchenko 	switch (flags) {
6739d73a0988SAndrei Emeltchenko 	case ACL_START:
6740d73a0988SAndrei Emeltchenko 	case ACL_START_NO_FLUSH:
6741d73a0988SAndrei Emeltchenko 	case ACL_COMPLETE:
67420a708f8fSGustavo F. Padovan 		if (conn->rx_len) {
67430a708f8fSGustavo F. Padovan 			BT_ERR("Unexpected start frame (len %d)", skb->len);
67440a708f8fSGustavo F. Padovan 			kfree_skb(conn->rx_skb);
67450a708f8fSGustavo F. Padovan 			conn->rx_skb = NULL;
67460a708f8fSGustavo F. Padovan 			conn->rx_len = 0;
67470a708f8fSGustavo F. Padovan 			l2cap_conn_unreliable(conn, ECOMM);
67480a708f8fSGustavo F. Padovan 		}
67490a708f8fSGustavo F. Padovan 
67500a708f8fSGustavo F. Padovan 		/* Start fragment always begin with Basic L2CAP header */
67510a708f8fSGustavo F. Padovan 		if (skb->len < L2CAP_HDR_SIZE) {
67520a708f8fSGustavo F. Padovan 			BT_ERR("Frame is too short (len %d)", skb->len);
67530a708f8fSGustavo F. Padovan 			l2cap_conn_unreliable(conn, ECOMM);
67540a708f8fSGustavo F. Padovan 			goto drop;
67550a708f8fSGustavo F. Padovan 		}
67560a708f8fSGustavo F. Padovan 
67570a708f8fSGustavo F. Padovan 		hdr = (struct l2cap_hdr *) skb->data;
67580a708f8fSGustavo F. Padovan 		len = __le16_to_cpu(hdr->len) + L2CAP_HDR_SIZE;
67590a708f8fSGustavo F. Padovan 
67600a708f8fSGustavo F. Padovan 		if (len == skb->len) {
67610a708f8fSGustavo F. Padovan 			/* Complete frame received */
67620a708f8fSGustavo F. Padovan 			l2cap_recv_frame(conn, skb);
67630a708f8fSGustavo F. Padovan 			return 0;
67640a708f8fSGustavo F. Padovan 		}
67650a708f8fSGustavo F. Padovan 
67660a708f8fSGustavo F. Padovan 		BT_DBG("Start: total len %d, frag len %d", len, skb->len);
67670a708f8fSGustavo F. Padovan 
67680a708f8fSGustavo F. Padovan 		if (skb->len > len) {
67690a708f8fSGustavo F. Padovan 			BT_ERR("Frame is too long (len %d, expected len %d)",
67700a708f8fSGustavo F. Padovan 			       skb->len, len);
67710a708f8fSGustavo F. Padovan 			l2cap_conn_unreliable(conn, ECOMM);
67720a708f8fSGustavo F. Padovan 			goto drop;
67730a708f8fSGustavo F. Padovan 		}
67740a708f8fSGustavo F. Padovan 
67750a708f8fSGustavo F. Padovan 		/* Allocate skb for the complete frame (with header) */
67768bcde1f2SGustavo Padovan 		conn->rx_skb = bt_skb_alloc(len, GFP_KERNEL);
67770a708f8fSGustavo F. Padovan 		if (!conn->rx_skb)
67780a708f8fSGustavo F. Padovan 			goto drop;
67790a708f8fSGustavo F. Padovan 
67800a708f8fSGustavo F. Padovan 		skb_copy_from_linear_data(skb, skb_put(conn->rx_skb, skb->len),
67810a708f8fSGustavo F. Padovan 					  skb->len);
67820a708f8fSGustavo F. Padovan 		conn->rx_len = len - skb->len;
6783d73a0988SAndrei Emeltchenko 		break;
6784d73a0988SAndrei Emeltchenko 
6785d73a0988SAndrei Emeltchenko 	case ACL_CONT:
67860a708f8fSGustavo F. Padovan 		BT_DBG("Cont: frag len %d (expecting %d)", skb->len, conn->rx_len);
67870a708f8fSGustavo F. Padovan 
67880a708f8fSGustavo F. Padovan 		if (!conn->rx_len) {
67890a708f8fSGustavo F. Padovan 			BT_ERR("Unexpected continuation frame (len %d)", skb->len);
67900a708f8fSGustavo F. Padovan 			l2cap_conn_unreliable(conn, ECOMM);
67910a708f8fSGustavo F. Padovan 			goto drop;
67920a708f8fSGustavo F. Padovan 		}
67930a708f8fSGustavo F. Padovan 
67940a708f8fSGustavo F. Padovan 		if (skb->len > conn->rx_len) {
67950a708f8fSGustavo F. Padovan 			BT_ERR("Fragment is too long (len %d, expected %d)",
67960a708f8fSGustavo F. Padovan 			       skb->len, conn->rx_len);
67970a708f8fSGustavo F. Padovan 			kfree_skb(conn->rx_skb);
67980a708f8fSGustavo F. Padovan 			conn->rx_skb = NULL;
67990a708f8fSGustavo F. Padovan 			conn->rx_len = 0;
68000a708f8fSGustavo F. Padovan 			l2cap_conn_unreliable(conn, ECOMM);
68010a708f8fSGustavo F. Padovan 			goto drop;
68020a708f8fSGustavo F. Padovan 		}
68030a708f8fSGustavo F. Padovan 
68040a708f8fSGustavo F. Padovan 		skb_copy_from_linear_data(skb, skb_put(conn->rx_skb, skb->len),
68050a708f8fSGustavo F. Padovan 					  skb->len);
68060a708f8fSGustavo F. Padovan 		conn->rx_len -= skb->len;
68070a708f8fSGustavo F. Padovan 
68080a708f8fSGustavo F. Padovan 		if (!conn->rx_len) {
6809c4e5bafaSJohan Hedberg 			/* Complete frame received. l2cap_recv_frame
6810c4e5bafaSJohan Hedberg 			 * takes ownership of the skb so set the global
6811c4e5bafaSJohan Hedberg 			 * rx_skb pointer to NULL first.
6812c4e5bafaSJohan Hedberg 			 */
6813c4e5bafaSJohan Hedberg 			struct sk_buff *rx_skb = conn->rx_skb;
68140a708f8fSGustavo F. Padovan 			conn->rx_skb = NULL;
6815c4e5bafaSJohan Hedberg 			l2cap_recv_frame(conn, rx_skb);
68160a708f8fSGustavo F. Padovan 		}
6817d73a0988SAndrei Emeltchenko 		break;
68180a708f8fSGustavo F. Padovan 	}
68190a708f8fSGustavo F. Padovan 
68200a708f8fSGustavo F. Padovan drop:
68210a708f8fSGustavo F. Padovan 	kfree_skb(skb);
68220a708f8fSGustavo F. Padovan 	return 0;
68230a708f8fSGustavo F. Padovan }
68240a708f8fSGustavo F. Padovan 
68250a708f8fSGustavo F. Padovan static int l2cap_debugfs_show(struct seq_file *f, void *p)
68260a708f8fSGustavo F. Padovan {
682723691d75SGustavo F. Padovan 	struct l2cap_chan *c;
68280a708f8fSGustavo F. Padovan 
6829333055f2SGustavo F. Padovan 	read_lock(&chan_list_lock);
68300a708f8fSGustavo F. Padovan 
683123691d75SGustavo F. Padovan 	list_for_each_entry(c, &chan_list, global_l) {
683223691d75SGustavo F. Padovan 		struct sock *sk = c->sk;
68330a708f8fSGustavo F. Padovan 
6834fcb73338SAndrei Emeltchenko 		seq_printf(f, "%pMR %pMR %d %d 0x%4.4x 0x%4.4x %d %d %d %d\n",
6835fcb73338SAndrei Emeltchenko 			   &bt_sk(sk)->src, &bt_sk(sk)->dst,
683689bc500eSGustavo F. Padovan 			   c->state, __le16_to_cpu(c->psm),
683723691d75SGustavo F. Padovan 			   c->scid, c->dcid, c->imtu, c->omtu,
683823691d75SGustavo F. Padovan 			   c->sec_level, c->mode);
68390a708f8fSGustavo F. Padovan 	}
68400a708f8fSGustavo F. Padovan 
6841333055f2SGustavo F. Padovan 	read_unlock(&chan_list_lock);
68420a708f8fSGustavo F. Padovan 
68430a708f8fSGustavo F. Padovan 	return 0;
68440a708f8fSGustavo F. Padovan }
68450a708f8fSGustavo F. Padovan 
68460a708f8fSGustavo F. Padovan static int l2cap_debugfs_open(struct inode *inode, struct file *file)
68470a708f8fSGustavo F. Padovan {
68480a708f8fSGustavo F. Padovan 	return single_open(file, l2cap_debugfs_show, inode->i_private);
68490a708f8fSGustavo F. Padovan }
68500a708f8fSGustavo F. Padovan 
68510a708f8fSGustavo F. Padovan static const struct file_operations l2cap_debugfs_fops = {
68520a708f8fSGustavo F. Padovan 	.open		= l2cap_debugfs_open,
68530a708f8fSGustavo F. Padovan 	.read		= seq_read,
68540a708f8fSGustavo F. Padovan 	.llseek		= seq_lseek,
68550a708f8fSGustavo F. Padovan 	.release	= single_release,
68560a708f8fSGustavo F. Padovan };
68570a708f8fSGustavo F. Padovan 
68580a708f8fSGustavo F. Padovan static struct dentry *l2cap_debugfs;
68590a708f8fSGustavo F. Padovan 
686064274518SGustavo F. Padovan int __init l2cap_init(void)
68610a708f8fSGustavo F. Padovan {
68620a708f8fSGustavo F. Padovan 	int err;
68630a708f8fSGustavo F. Padovan 
6864bb58f747SGustavo F. Padovan 	err = l2cap_init_sockets();
68650a708f8fSGustavo F. Padovan 	if (err < 0)
68660a708f8fSGustavo F. Padovan 		return err;
68670a708f8fSGustavo F. Padovan 
68680a708f8fSGustavo F. Padovan 	if (bt_debugfs) {
68692d792818SGustavo Padovan 		l2cap_debugfs = debugfs_create_file("l2cap", 0444, bt_debugfs,
68702d792818SGustavo Padovan 						    NULL, &l2cap_debugfs_fops);
68710a708f8fSGustavo F. Padovan 		if (!l2cap_debugfs)
68720a708f8fSGustavo F. Padovan 			BT_ERR("Failed to create L2CAP debug file");
68730a708f8fSGustavo F. Padovan 	}
68740a708f8fSGustavo F. Padovan 
68750a708f8fSGustavo F. Padovan 	return 0;
68760a708f8fSGustavo F. Padovan }
68770a708f8fSGustavo F. Padovan 
687864274518SGustavo F. Padovan void l2cap_exit(void)
68790a708f8fSGustavo F. Padovan {
68800a708f8fSGustavo F. Padovan 	debugfs_remove(l2cap_debugfs);
6881bb58f747SGustavo F. Padovan 	l2cap_cleanup_sockets();
68820a708f8fSGustavo F. Padovan }
68830a708f8fSGustavo F. Padovan 
68840a708f8fSGustavo F. Padovan module_param(disable_ertm, bool, 0644);
68850a708f8fSGustavo F. Padovan MODULE_PARM_DESC(disable_ertm, "Disable enhanced retransmission mode");
6886