10a708f8fSGustavo F. Padovan /* 20a708f8fSGustavo F. Padovan BlueZ - Bluetooth protocol stack for Linux 30a708f8fSGustavo F. Padovan Copyright (C) 2000-2001 Qualcomm Incorporated 40a708f8fSGustavo F. Padovan Copyright (C) 2009-2010 Gustavo F. Padovan <gustavo@padovan.org> 50a708f8fSGustavo F. Padovan Copyright (C) 2010 Google Inc. 6590051deSGustavo F. Padovan Copyright (C) 2011 ProFUSION Embedded Systems 7422e925bSMat Martineau Copyright (c) 2012 Code Aurora Forum. All rights reserved. 80a708f8fSGustavo F. Padovan 90a708f8fSGustavo F. Padovan Written 2000,2001 by Maxim Krasnyansky <maxk@qualcomm.com> 100a708f8fSGustavo F. Padovan 110a708f8fSGustavo F. Padovan This program is free software; you can redistribute it and/or modify 120a708f8fSGustavo F. Padovan it under the terms of the GNU General Public License version 2 as 130a708f8fSGustavo F. Padovan published by the Free Software Foundation; 140a708f8fSGustavo F. Padovan 150a708f8fSGustavo F. Padovan THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS 160a708f8fSGustavo F. Padovan OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, 170a708f8fSGustavo F. Padovan FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT OF THIRD PARTY RIGHTS. 180a708f8fSGustavo F. Padovan IN NO EVENT SHALL THE COPYRIGHT HOLDER(S) AND AUTHOR(S) BE LIABLE FOR ANY 190a708f8fSGustavo F. Padovan CLAIM, OR ANY SPECIAL INDIRECT OR CONSEQUENTIAL DAMAGES, OR ANY DAMAGES 200a708f8fSGustavo F. Padovan WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN 210a708f8fSGustavo F. Padovan ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF 220a708f8fSGustavo F. Padovan OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. 230a708f8fSGustavo F. Padovan 240a708f8fSGustavo F. Padovan ALL LIABILITY, INCLUDING LIABILITY FOR INFRINGEMENT OF ANY PATENTS, 250a708f8fSGustavo F. Padovan COPYRIGHTS, TRADEMARKS OR OTHER RIGHTS, RELATING TO USE OF THIS 260a708f8fSGustavo F. Padovan SOFTWARE IS DISCLAIMED. 270a708f8fSGustavo F. Padovan */ 280a708f8fSGustavo F. Padovan 29bb58f747SGustavo F. Padovan /* Bluetooth L2CAP core. */ 300a708f8fSGustavo F. Padovan 310a708f8fSGustavo F. Padovan #include <linux/module.h> 320a708f8fSGustavo F. Padovan 330a708f8fSGustavo F. Padovan #include <linux/debugfs.h> 340a708f8fSGustavo F. Padovan #include <linux/crc16.h> 350a708f8fSGustavo F. Padovan 360a708f8fSGustavo F. Padovan #include <net/bluetooth/bluetooth.h> 370a708f8fSGustavo F. Padovan #include <net/bluetooth/hci_core.h> 380a708f8fSGustavo F. Padovan #include <net/bluetooth/l2cap.h> 397ef9fbf0SMarcel Holtmann 40*ac4b7236SMarcel Holtmann #include "smp.h" 417024728eSMarcel Holtmann #include "a2mp.h" 427ef9fbf0SMarcel Holtmann #include "amp.h" 430a708f8fSGustavo F. Padovan 44d1de6d46SMat Martineau bool disable_ertm; 450a708f8fSGustavo F. Padovan 460a708f8fSGustavo F. Padovan static u32 l2cap_feat_mask = L2CAP_FEAT_FIXED_CHAN; 4750a147cdSMat Martineau static u8 l2cap_fixed_chan[8] = { L2CAP_FC_L2CAP, }; 480a708f8fSGustavo F. Padovan 49b5ad8b7fSJohannes Berg static LIST_HEAD(chan_list); 50b5ad8b7fSJohannes Berg static DEFINE_RWLOCK(chan_list_lock); 510a708f8fSGustavo F. Padovan 520a708f8fSGustavo F. Padovan static struct sk_buff *l2cap_build_cmd(struct l2cap_conn *conn, 530a708f8fSGustavo F. Padovan u8 code, u8 ident, u16 dlen, void *data); 544519de9aSGustavo F. Padovan static void l2cap_send_cmd(struct l2cap_conn *conn, u8 ident, u8 code, u16 len, 554519de9aSGustavo F. Padovan void *data); 56710f9b0aSGustavo F. Padovan static int l2cap_build_conf_req(struct l2cap_chan *chan, void *data); 575e4e3972SAndrei Emeltchenko static void l2cap_send_disconn_req(struct l2cap_chan *chan, int err); 580a708f8fSGustavo F. Padovan 59d660366dSGustavo Padovan static void l2cap_tx(struct l2cap_chan *chan, struct l2cap_ctrl *control, 60608bcc6dSMat Martineau struct sk_buff_head *skbs, u8 event); 61608bcc6dSMat Martineau 620a708f8fSGustavo F. Padovan /* ---- L2CAP channels ---- */ 6371ba0e56SGustavo F. Padovan 642d792818SGustavo Padovan static struct l2cap_chan *__l2cap_get_chan_by_dcid(struct l2cap_conn *conn, 652d792818SGustavo Padovan u16 cid) 660a708f8fSGustavo F. Padovan { 673df91ea2SAndrei Emeltchenko struct l2cap_chan *c; 68baa7e1faSGustavo F. Padovan 693df91ea2SAndrei Emeltchenko list_for_each_entry(c, &conn->chan_l, list) { 703df91ea2SAndrei Emeltchenko if (c->dcid == cid) 713df91ea2SAndrei Emeltchenko return c; 720a708f8fSGustavo F. Padovan } 733df91ea2SAndrei Emeltchenko return NULL; 74baa7e1faSGustavo F. Padovan } 750a708f8fSGustavo F. Padovan 762d792818SGustavo Padovan static struct l2cap_chan *__l2cap_get_chan_by_scid(struct l2cap_conn *conn, 772d792818SGustavo Padovan u16 cid) 780a708f8fSGustavo F. Padovan { 793df91ea2SAndrei Emeltchenko struct l2cap_chan *c; 80baa7e1faSGustavo F. Padovan 813df91ea2SAndrei Emeltchenko list_for_each_entry(c, &conn->chan_l, list) { 823df91ea2SAndrei Emeltchenko if (c->scid == cid) 833df91ea2SAndrei Emeltchenko return c; 840a708f8fSGustavo F. Padovan } 853df91ea2SAndrei Emeltchenko return NULL; 86baa7e1faSGustavo F. Padovan } 870a708f8fSGustavo F. Padovan 880a708f8fSGustavo F. Padovan /* Find channel with given SCID. 89ef191adeSMat Martineau * Returns locked channel. */ 902d792818SGustavo Padovan static struct l2cap_chan *l2cap_get_chan_by_scid(struct l2cap_conn *conn, 912d792818SGustavo Padovan u16 cid) 920a708f8fSGustavo F. Padovan { 9348454079SGustavo F. Padovan struct l2cap_chan *c; 94baa7e1faSGustavo F. Padovan 953df91ea2SAndrei Emeltchenko mutex_lock(&conn->chan_lock); 96baa7e1faSGustavo F. Padovan c = __l2cap_get_chan_by_scid(conn, cid); 97ef191adeSMat Martineau if (c) 98ef191adeSMat Martineau l2cap_chan_lock(c); 993df91ea2SAndrei Emeltchenko mutex_unlock(&conn->chan_lock); 1003df91ea2SAndrei Emeltchenko 10148454079SGustavo F. Padovan return c; 1020a708f8fSGustavo F. Padovan } 1030a708f8fSGustavo F. Padovan 104b1a130b7SMat Martineau /* Find channel with given DCID. 105b1a130b7SMat Martineau * Returns locked channel. 106b1a130b7SMat Martineau */ 107b1a130b7SMat Martineau static struct l2cap_chan *l2cap_get_chan_by_dcid(struct l2cap_conn *conn, 108b1a130b7SMat Martineau u16 cid) 109b1a130b7SMat Martineau { 110b1a130b7SMat Martineau struct l2cap_chan *c; 111b1a130b7SMat Martineau 112b1a130b7SMat Martineau mutex_lock(&conn->chan_lock); 113b1a130b7SMat Martineau c = __l2cap_get_chan_by_dcid(conn, cid); 114b1a130b7SMat Martineau if (c) 115b1a130b7SMat Martineau l2cap_chan_lock(c); 116b1a130b7SMat Martineau mutex_unlock(&conn->chan_lock); 117b1a130b7SMat Martineau 118b1a130b7SMat Martineau return c; 119b1a130b7SMat Martineau } 120b1a130b7SMat Martineau 1212d792818SGustavo Padovan static struct l2cap_chan *__l2cap_get_chan_by_ident(struct l2cap_conn *conn, 1222d792818SGustavo Padovan u8 ident) 1230a708f8fSGustavo F. Padovan { 1243df91ea2SAndrei Emeltchenko struct l2cap_chan *c; 125baa7e1faSGustavo F. Padovan 1263df91ea2SAndrei Emeltchenko list_for_each_entry(c, &conn->chan_l, list) { 1273df91ea2SAndrei Emeltchenko if (c->ident == ident) 1283df91ea2SAndrei Emeltchenko return c; 1290a708f8fSGustavo F. Padovan } 1303df91ea2SAndrei Emeltchenko return NULL; 131baa7e1faSGustavo F. Padovan } 1320a708f8fSGustavo F. Padovan 1335b155ef9SMat Martineau static struct l2cap_chan *l2cap_get_chan_by_ident(struct l2cap_conn *conn, 1345b155ef9SMat Martineau u8 ident) 1355b155ef9SMat Martineau { 1365b155ef9SMat Martineau struct l2cap_chan *c; 1375b155ef9SMat Martineau 1385b155ef9SMat Martineau mutex_lock(&conn->chan_lock); 1395b155ef9SMat Martineau c = __l2cap_get_chan_by_ident(conn, ident); 1405b155ef9SMat Martineau if (c) 1415b155ef9SMat Martineau l2cap_chan_lock(c); 1425b155ef9SMat Martineau mutex_unlock(&conn->chan_lock); 1435b155ef9SMat Martineau 1445b155ef9SMat Martineau return c; 1455b155ef9SMat Martineau } 1465b155ef9SMat Martineau 14723691d75SGustavo F. Padovan static struct l2cap_chan *__l2cap_global_chan_by_addr(__le16 psm, bdaddr_t *src) 1489e4425ffSGustavo F. Padovan { 14923691d75SGustavo F. Padovan struct l2cap_chan *c; 1509e4425ffSGustavo F. Padovan 15123691d75SGustavo F. Padovan list_for_each_entry(c, &chan_list, global_l) { 15223691d75SGustavo F. Padovan if (c->sport == psm && !bacmp(&bt_sk(c->sk)->src, src)) 15323691d75SGustavo F. Padovan return c; 1549e4425ffSGustavo F. Padovan } 155250938cbSSzymon Janc return NULL; 156250938cbSSzymon Janc } 1579e4425ffSGustavo F. Padovan 1589e4425ffSGustavo F. Padovan int l2cap_add_psm(struct l2cap_chan *chan, bdaddr_t *src, __le16 psm) 1599e4425ffSGustavo F. Padovan { 16073b2ec18SGustavo F. Padovan int err; 16173b2ec18SGustavo F. Padovan 162333055f2SGustavo F. Padovan write_lock(&chan_list_lock); 1639e4425ffSGustavo F. Padovan 16423691d75SGustavo F. Padovan if (psm && __l2cap_global_chan_by_addr(psm, src)) { 16573b2ec18SGustavo F. Padovan err = -EADDRINUSE; 16673b2ec18SGustavo F. Padovan goto done; 1679e4425ffSGustavo F. Padovan } 1689e4425ffSGustavo F. Padovan 16973b2ec18SGustavo F. Padovan if (psm) { 1709e4425ffSGustavo F. Padovan chan->psm = psm; 1719e4425ffSGustavo F. Padovan chan->sport = psm; 17273b2ec18SGustavo F. Padovan err = 0; 17373b2ec18SGustavo F. Padovan } else { 17473b2ec18SGustavo F. Padovan u16 p; 1759e4425ffSGustavo F. Padovan 17673b2ec18SGustavo F. Padovan err = -EINVAL; 17773b2ec18SGustavo F. Padovan for (p = 0x1001; p < 0x1100; p += 2) 17823691d75SGustavo F. Padovan if (!__l2cap_global_chan_by_addr(cpu_to_le16(p), src)) { 17973b2ec18SGustavo F. Padovan chan->psm = cpu_to_le16(p); 18073b2ec18SGustavo F. Padovan chan->sport = cpu_to_le16(p); 18173b2ec18SGustavo F. Padovan err = 0; 18273b2ec18SGustavo F. Padovan break; 18373b2ec18SGustavo F. Padovan } 18473b2ec18SGustavo F. Padovan } 18573b2ec18SGustavo F. Padovan 18673b2ec18SGustavo F. Padovan done: 187333055f2SGustavo F. Padovan write_unlock(&chan_list_lock); 18873b2ec18SGustavo F. Padovan return err; 1899e4425ffSGustavo F. Padovan } 1909e4425ffSGustavo F. Padovan 1919e4425ffSGustavo F. Padovan int l2cap_add_scid(struct l2cap_chan *chan, __u16 scid) 1929e4425ffSGustavo F. Padovan { 193333055f2SGustavo F. Padovan write_lock(&chan_list_lock); 1949e4425ffSGustavo F. Padovan 1959e4425ffSGustavo F. Padovan chan->scid = scid; 1969e4425ffSGustavo F. Padovan 197333055f2SGustavo F. Padovan write_unlock(&chan_list_lock); 1989e4425ffSGustavo F. Padovan 1999e4425ffSGustavo F. Padovan return 0; 2009e4425ffSGustavo F. Padovan } 2019e4425ffSGustavo F. Padovan 202baa7e1faSGustavo F. Padovan static u16 l2cap_alloc_cid(struct l2cap_conn *conn) 2030a708f8fSGustavo F. Padovan { 2040a708f8fSGustavo F. Padovan u16 cid = L2CAP_CID_DYN_START; 2050a708f8fSGustavo F. Padovan 2060a708f8fSGustavo F. Padovan for (; cid < L2CAP_CID_DYN_END; cid++) { 207baa7e1faSGustavo F. Padovan if (!__l2cap_get_chan_by_scid(conn, cid)) 2080a708f8fSGustavo F. Padovan return cid; 2090a708f8fSGustavo F. Padovan } 2100a708f8fSGustavo F. Padovan 2110a708f8fSGustavo F. Padovan return 0; 2120a708f8fSGustavo F. Padovan } 2130a708f8fSGustavo F. Padovan 2140e587be7SAndrei Emeltchenko static void __l2cap_state_change(struct l2cap_chan *chan, int state) 21589bc500eSGustavo F. Padovan { 21642d2d87cSAndrei Emeltchenko BT_DBG("chan %p %s -> %s", chan, state_to_string(chan->state), 217badaaa00SGustavo F. Padovan state_to_string(state)); 218badaaa00SGustavo F. Padovan 21989bc500eSGustavo F. Padovan chan->state = state; 22080b98027SGustavo Padovan chan->ops->state_change(chan, state); 22189bc500eSGustavo F. Padovan } 22289bc500eSGustavo F. Padovan 2230e587be7SAndrei Emeltchenko static void l2cap_state_change(struct l2cap_chan *chan, int state) 2240e587be7SAndrei Emeltchenko { 2250e587be7SAndrei Emeltchenko struct sock *sk = chan->sk; 2260e587be7SAndrei Emeltchenko 2270e587be7SAndrei Emeltchenko lock_sock(sk); 2280e587be7SAndrei Emeltchenko __l2cap_state_change(chan, state); 2290e587be7SAndrei Emeltchenko release_sock(sk); 2300e587be7SAndrei Emeltchenko } 2310e587be7SAndrei Emeltchenko 2322e0052e4SAndrei Emeltchenko static inline void __l2cap_chan_set_err(struct l2cap_chan *chan, int err) 2332e0052e4SAndrei Emeltchenko { 2342e0052e4SAndrei Emeltchenko struct sock *sk = chan->sk; 2352e0052e4SAndrei Emeltchenko 2362e0052e4SAndrei Emeltchenko sk->sk_err = err; 2372e0052e4SAndrei Emeltchenko } 2382e0052e4SAndrei Emeltchenko 2392e0052e4SAndrei Emeltchenko static inline void l2cap_chan_set_err(struct l2cap_chan *chan, int err) 2402e0052e4SAndrei Emeltchenko { 2412e0052e4SAndrei Emeltchenko struct sock *sk = chan->sk; 2422e0052e4SAndrei Emeltchenko 2432e0052e4SAndrei Emeltchenko lock_sock(sk); 2442e0052e4SAndrei Emeltchenko __l2cap_chan_set_err(chan, err); 2452e0052e4SAndrei Emeltchenko release_sock(sk); 2462e0052e4SAndrei Emeltchenko } 2472e0052e4SAndrei Emeltchenko 2484239d16fSMat Martineau static void __set_retrans_timer(struct l2cap_chan *chan) 2494239d16fSMat Martineau { 2504239d16fSMat Martineau if (!delayed_work_pending(&chan->monitor_timer) && 2514239d16fSMat Martineau chan->retrans_timeout) { 2524239d16fSMat Martineau l2cap_set_timer(chan, &chan->retrans_timer, 2534239d16fSMat Martineau msecs_to_jiffies(chan->retrans_timeout)); 2544239d16fSMat Martineau } 2554239d16fSMat Martineau } 2564239d16fSMat Martineau 2574239d16fSMat Martineau static void __set_monitor_timer(struct l2cap_chan *chan) 2584239d16fSMat Martineau { 2594239d16fSMat Martineau __clear_retrans_timer(chan); 2604239d16fSMat Martineau if (chan->monitor_timeout) { 2614239d16fSMat Martineau l2cap_set_timer(chan, &chan->monitor_timer, 2624239d16fSMat Martineau msecs_to_jiffies(chan->monitor_timeout)); 2634239d16fSMat Martineau } 2644239d16fSMat Martineau } 2654239d16fSMat Martineau 266608bcc6dSMat Martineau static struct sk_buff *l2cap_ertm_seq_in_queue(struct sk_buff_head *head, 267608bcc6dSMat Martineau u16 seq) 268608bcc6dSMat Martineau { 269608bcc6dSMat Martineau struct sk_buff *skb; 270608bcc6dSMat Martineau 271608bcc6dSMat Martineau skb_queue_walk(head, skb) { 272608bcc6dSMat Martineau if (bt_cb(skb)->control.txseq == seq) 273608bcc6dSMat Martineau return skb; 274608bcc6dSMat Martineau } 275608bcc6dSMat Martineau 276608bcc6dSMat Martineau return NULL; 277608bcc6dSMat Martineau } 278608bcc6dSMat Martineau 2793c588192SMat Martineau /* ---- L2CAP sequence number lists ---- */ 2803c588192SMat Martineau 2813c588192SMat Martineau /* For ERTM, ordered lists of sequence numbers must be tracked for 2823c588192SMat Martineau * SREJ requests that are received and for frames that are to be 2833c588192SMat Martineau * retransmitted. These seq_list functions implement a singly-linked 2843c588192SMat Martineau * list in an array, where membership in the list can also be checked 2853c588192SMat Martineau * in constant time. Items can also be added to the tail of the list 2863c588192SMat Martineau * and removed from the head in constant time, without further memory 2873c588192SMat Martineau * allocs or frees. 2883c588192SMat Martineau */ 2893c588192SMat Martineau 2903c588192SMat Martineau static int l2cap_seq_list_init(struct l2cap_seq_list *seq_list, u16 size) 2913c588192SMat Martineau { 2923c588192SMat Martineau size_t alloc_size, i; 2933c588192SMat Martineau 2943c588192SMat Martineau /* Allocated size is a power of 2 to map sequence numbers 2953c588192SMat Martineau * (which may be up to 14 bits) in to a smaller array that is 2963c588192SMat Martineau * sized for the negotiated ERTM transmit windows. 2973c588192SMat Martineau */ 2983c588192SMat Martineau alloc_size = roundup_pow_of_two(size); 2993c588192SMat Martineau 3003c588192SMat Martineau seq_list->list = kmalloc(sizeof(u16) * alloc_size, GFP_KERNEL); 3013c588192SMat Martineau if (!seq_list->list) 3023c588192SMat Martineau return -ENOMEM; 3033c588192SMat Martineau 3043c588192SMat Martineau seq_list->mask = alloc_size - 1; 3053c588192SMat Martineau seq_list->head = L2CAP_SEQ_LIST_CLEAR; 3063c588192SMat Martineau seq_list->tail = L2CAP_SEQ_LIST_CLEAR; 3073c588192SMat Martineau for (i = 0; i < alloc_size; i++) 3083c588192SMat Martineau seq_list->list[i] = L2CAP_SEQ_LIST_CLEAR; 3093c588192SMat Martineau 3103c588192SMat Martineau return 0; 3113c588192SMat Martineau } 3123c588192SMat Martineau 3133c588192SMat Martineau static inline void l2cap_seq_list_free(struct l2cap_seq_list *seq_list) 3143c588192SMat Martineau { 3153c588192SMat Martineau kfree(seq_list->list); 3163c588192SMat Martineau } 3173c588192SMat Martineau 3183c588192SMat Martineau static inline bool l2cap_seq_list_contains(struct l2cap_seq_list *seq_list, 3193c588192SMat Martineau u16 seq) 3203c588192SMat Martineau { 3213c588192SMat Martineau /* Constant-time check for list membership */ 3223c588192SMat Martineau return seq_list->list[seq & seq_list->mask] != L2CAP_SEQ_LIST_CLEAR; 3233c588192SMat Martineau } 3243c588192SMat Martineau 3253c588192SMat Martineau static u16 l2cap_seq_list_remove(struct l2cap_seq_list *seq_list, u16 seq) 3263c588192SMat Martineau { 3273c588192SMat Martineau u16 mask = seq_list->mask; 3283c588192SMat Martineau 3293c588192SMat Martineau if (seq_list->head == L2CAP_SEQ_LIST_CLEAR) { 3303c588192SMat Martineau /* In case someone tries to pop the head of an empty list */ 3313c588192SMat Martineau return L2CAP_SEQ_LIST_CLEAR; 3323c588192SMat Martineau } else if (seq_list->head == seq) { 3333c588192SMat Martineau /* Head can be removed in constant time */ 3343c588192SMat Martineau seq_list->head = seq_list->list[seq & mask]; 3353c588192SMat Martineau seq_list->list[seq & mask] = L2CAP_SEQ_LIST_CLEAR; 3363c588192SMat Martineau 3373c588192SMat Martineau if (seq_list->head == L2CAP_SEQ_LIST_TAIL) { 3383c588192SMat Martineau seq_list->head = L2CAP_SEQ_LIST_CLEAR; 3393c588192SMat Martineau seq_list->tail = L2CAP_SEQ_LIST_CLEAR; 3403c588192SMat Martineau } 3413c588192SMat Martineau } else { 3423c588192SMat Martineau /* Walk the list to find the sequence number */ 3433c588192SMat Martineau u16 prev = seq_list->head; 3443c588192SMat Martineau while (seq_list->list[prev & mask] != seq) { 3453c588192SMat Martineau prev = seq_list->list[prev & mask]; 3463c588192SMat Martineau if (prev == L2CAP_SEQ_LIST_TAIL) 3473c588192SMat Martineau return L2CAP_SEQ_LIST_CLEAR; 3483c588192SMat Martineau } 3493c588192SMat Martineau 3503c588192SMat Martineau /* Unlink the number from the list and clear it */ 3513c588192SMat Martineau seq_list->list[prev & mask] = seq_list->list[seq & mask]; 3523c588192SMat Martineau seq_list->list[seq & mask] = L2CAP_SEQ_LIST_CLEAR; 3533c588192SMat Martineau if (seq_list->tail == seq) 3543c588192SMat Martineau seq_list->tail = prev; 3553c588192SMat Martineau } 3563c588192SMat Martineau return seq; 3573c588192SMat Martineau } 3583c588192SMat Martineau 3593c588192SMat Martineau static inline u16 l2cap_seq_list_pop(struct l2cap_seq_list *seq_list) 3603c588192SMat Martineau { 3613c588192SMat Martineau /* Remove the head in constant time */ 3623c588192SMat Martineau return l2cap_seq_list_remove(seq_list, seq_list->head); 3633c588192SMat Martineau } 3643c588192SMat Martineau 3653c588192SMat Martineau static void l2cap_seq_list_clear(struct l2cap_seq_list *seq_list) 3663c588192SMat Martineau { 3673c588192SMat Martineau u16 i; 368f522ae36SGustavo Padovan 369f522ae36SGustavo Padovan if (seq_list->head == L2CAP_SEQ_LIST_CLEAR) 370f522ae36SGustavo Padovan return; 371f522ae36SGustavo Padovan 3723c588192SMat Martineau for (i = 0; i <= seq_list->mask; i++) 3733c588192SMat Martineau seq_list->list[i] = L2CAP_SEQ_LIST_CLEAR; 3743c588192SMat Martineau 3753c588192SMat Martineau seq_list->head = L2CAP_SEQ_LIST_CLEAR; 3763c588192SMat Martineau seq_list->tail = L2CAP_SEQ_LIST_CLEAR; 3773c588192SMat Martineau } 3783c588192SMat Martineau 3793c588192SMat Martineau static void l2cap_seq_list_append(struct l2cap_seq_list *seq_list, u16 seq) 3803c588192SMat Martineau { 3813c588192SMat Martineau u16 mask = seq_list->mask; 3823c588192SMat Martineau 3833c588192SMat Martineau /* All appends happen in constant time */ 3843c588192SMat Martineau 385f522ae36SGustavo Padovan if (seq_list->list[seq & mask] != L2CAP_SEQ_LIST_CLEAR) 386f522ae36SGustavo Padovan return; 387f522ae36SGustavo Padovan 3883c588192SMat Martineau if (seq_list->tail == L2CAP_SEQ_LIST_CLEAR) 3893c588192SMat Martineau seq_list->head = seq; 3903c588192SMat Martineau else 3913c588192SMat Martineau seq_list->list[seq_list->tail & mask] = seq; 3923c588192SMat Martineau 3933c588192SMat Martineau seq_list->tail = seq; 3943c588192SMat Martineau seq_list->list[seq & mask] = L2CAP_SEQ_LIST_TAIL; 3953c588192SMat Martineau } 3963c588192SMat Martineau 397721c4181SGustavo F. Padovan static void l2cap_chan_timeout(struct work_struct *work) 398ab07801dSGustavo F. Padovan { 399721c4181SGustavo F. Padovan struct l2cap_chan *chan = container_of(work, struct l2cap_chan, 400721c4181SGustavo F. Padovan chan_timer.work); 4013df91ea2SAndrei Emeltchenko struct l2cap_conn *conn = chan->conn; 402ab07801dSGustavo F. Padovan int reason; 403ab07801dSGustavo F. Padovan 404e05dcc32SAndrei Emeltchenko BT_DBG("chan %p state %s", chan, state_to_string(chan->state)); 405ab07801dSGustavo F. Padovan 4063df91ea2SAndrei Emeltchenko mutex_lock(&conn->chan_lock); 4076be36555SAndrei Emeltchenko l2cap_chan_lock(chan); 408ab07801dSGustavo F. Padovan 40989bc500eSGustavo F. Padovan if (chan->state == BT_CONNECTED || chan->state == BT_CONFIG) 410ab07801dSGustavo F. Padovan reason = ECONNREFUSED; 41189bc500eSGustavo F. Padovan else if (chan->state == BT_CONNECT && 412ab07801dSGustavo F. Padovan chan->sec_level != BT_SECURITY_SDP) 413ab07801dSGustavo F. Padovan reason = ECONNREFUSED; 414ab07801dSGustavo F. Padovan else 415ab07801dSGustavo F. Padovan reason = ETIMEDOUT; 416ab07801dSGustavo F. Padovan 4170f852724SGustavo F. Padovan l2cap_chan_close(chan, reason); 418ab07801dSGustavo F. Padovan 4196be36555SAndrei Emeltchenko l2cap_chan_unlock(chan); 420ab07801dSGustavo F. Padovan 42180b98027SGustavo Padovan chan->ops->close(chan); 4223df91ea2SAndrei Emeltchenko mutex_unlock(&conn->chan_lock); 4233df91ea2SAndrei Emeltchenko 424371fd835SUlisses Furquim l2cap_chan_put(chan); 425ab07801dSGustavo F. Padovan } 426ab07801dSGustavo F. Padovan 427eef1d9b6SGustavo Padovan struct l2cap_chan *l2cap_chan_create(void) 4280a708f8fSGustavo F. Padovan { 42948454079SGustavo F. Padovan struct l2cap_chan *chan; 4300a708f8fSGustavo F. Padovan 43148454079SGustavo F. Padovan chan = kzalloc(sizeof(*chan), GFP_ATOMIC); 43248454079SGustavo F. Padovan if (!chan) 43348454079SGustavo F. Padovan return NULL; 4340a708f8fSGustavo F. Padovan 435c03b355eSAndrei Emeltchenko mutex_init(&chan->lock); 436c03b355eSAndrei Emeltchenko 437333055f2SGustavo F. Padovan write_lock(&chan_list_lock); 43823691d75SGustavo F. Padovan list_add(&chan->global_l, &chan_list); 439333055f2SGustavo F. Padovan write_unlock(&chan_list_lock); 44023691d75SGustavo F. Padovan 441721c4181SGustavo F. Padovan INIT_DELAYED_WORK(&chan->chan_timer, l2cap_chan_timeout); 442ab07801dSGustavo F. Padovan 44389bc500eSGustavo F. Padovan chan->state = BT_OPEN; 44489bc500eSGustavo F. Padovan 445144ad330SSyam Sidhardhan kref_init(&chan->kref); 44671ba0e56SGustavo F. Padovan 4472827011fSMat Martineau /* This flag is cleared in l2cap_chan_ready() */ 4482827011fSMat Martineau set_bit(CONF_NOT_COMPLETE, &chan->conf_state); 4492827011fSMat Martineau 450eef1d9b6SGustavo Padovan BT_DBG("chan %p", chan); 451abc545b8SSzymon Janc 45248454079SGustavo F. Padovan return chan; 4530a708f8fSGustavo F. Padovan } 4540a708f8fSGustavo F. Padovan 455144ad330SSyam Sidhardhan static void l2cap_chan_destroy(struct kref *kref) 4566ff5abbfSGustavo F. Padovan { 457144ad330SSyam Sidhardhan struct l2cap_chan *chan = container_of(kref, struct l2cap_chan, kref); 458144ad330SSyam Sidhardhan 4594af66c69SJaganath Kanakkassery BT_DBG("chan %p", chan); 4604af66c69SJaganath Kanakkassery 461333055f2SGustavo F. Padovan write_lock(&chan_list_lock); 46223691d75SGustavo F. Padovan list_del(&chan->global_l); 463333055f2SGustavo F. Padovan write_unlock(&chan_list_lock); 46423691d75SGustavo F. Padovan 4654af66c69SJaganath Kanakkassery kfree(chan); 4666ff5abbfSGustavo F. Padovan } 4676ff5abbfSGustavo F. Padovan 46830648372SJaganath Kanakkassery void l2cap_chan_hold(struct l2cap_chan *c) 46930648372SJaganath Kanakkassery { 470144ad330SSyam Sidhardhan BT_DBG("chan %p orig refcnt %d", c, atomic_read(&c->kref.refcount)); 47130648372SJaganath Kanakkassery 472144ad330SSyam Sidhardhan kref_get(&c->kref); 47330648372SJaganath Kanakkassery } 47430648372SJaganath Kanakkassery 47530648372SJaganath Kanakkassery void l2cap_chan_put(struct l2cap_chan *c) 47630648372SJaganath Kanakkassery { 477144ad330SSyam Sidhardhan BT_DBG("chan %p orig refcnt %d", c, atomic_read(&c->kref.refcount)); 47830648372SJaganath Kanakkassery 479144ad330SSyam Sidhardhan kref_put(&c->kref, l2cap_chan_destroy); 48030648372SJaganath Kanakkassery } 48130648372SJaganath Kanakkassery 482bd4b1653SAndrei Emeltchenko void l2cap_chan_set_defaults(struct l2cap_chan *chan) 483bd4b1653SAndrei Emeltchenko { 484bd4b1653SAndrei Emeltchenko chan->fcs = L2CAP_FCS_CRC16; 485bd4b1653SAndrei Emeltchenko chan->max_tx = L2CAP_DEFAULT_MAX_TX; 486bd4b1653SAndrei Emeltchenko chan->tx_win = L2CAP_DEFAULT_TX_WINDOW; 487bd4b1653SAndrei Emeltchenko chan->tx_win_max = L2CAP_DEFAULT_TX_WINDOW; 488c20f8e35SMat Martineau chan->ack_win = L2CAP_DEFAULT_TX_WINDOW; 489bd4b1653SAndrei Emeltchenko chan->sec_level = BT_SECURITY_LOW; 490bd4b1653SAndrei Emeltchenko 491bd4b1653SAndrei Emeltchenko set_bit(FLAG_FORCE_ACTIVE, &chan->flags); 492bd4b1653SAndrei Emeltchenko } 493bd4b1653SAndrei Emeltchenko 49493c3e8f5SAndrei Emeltchenko void __l2cap_chan_add(struct l2cap_conn *conn, struct l2cap_chan *chan) 4950a708f8fSGustavo F. Padovan { 4960a708f8fSGustavo F. Padovan BT_DBG("conn %p, psm 0x%2.2x, dcid 0x%4.4x", conn, 497097db76cSAndrei Emeltchenko __le16_to_cpu(chan->psm), chan->dcid); 4980a708f8fSGustavo F. Padovan 4999f5a0d7bSAndrei Emeltchenko conn->disc_reason = HCI_ERROR_REMOTE_USER_TERM; 5000a708f8fSGustavo F. Padovan 5018c1d787bSGustavo F. Padovan chan->conn = conn; 5020a708f8fSGustavo F. Padovan 5035491120eSAndrei Emeltchenko switch (chan->chan_type) { 5045491120eSAndrei Emeltchenko case L2CAP_CHAN_CONN_ORIENTED: 505b62f328bSVille Tervo if (conn->hcon->type == LE_LINK) { 506b62f328bSVille Tervo /* LE connection */ 5076fcb06a2SAndre Guedes chan->omtu = L2CAP_DEFAULT_MTU; 5089f22398cSJohan Hedberg if (chan->dcid == L2CAP_CID_ATT) 509073d1cf3SJohan Hedberg chan->scid = L2CAP_CID_ATT; 5109f22398cSJohan Hedberg else 5119f22398cSJohan Hedberg chan->scid = l2cap_alloc_cid(conn); 512b62f328bSVille Tervo } else { 5130a708f8fSGustavo F. Padovan /* Alloc CID for connection-oriented socket */ 514fe4128e0SGustavo F. Padovan chan->scid = l2cap_alloc_cid(conn); 5150c1bc5c6SGustavo F. Padovan chan->omtu = L2CAP_DEFAULT_MTU; 516b62f328bSVille Tervo } 5175491120eSAndrei Emeltchenko break; 5185491120eSAndrei Emeltchenko 5195491120eSAndrei Emeltchenko case L2CAP_CHAN_CONN_LESS: 5200a708f8fSGustavo F. Padovan /* Connectionless socket */ 521fe4128e0SGustavo F. Padovan chan->scid = L2CAP_CID_CONN_LESS; 522fe4128e0SGustavo F. Padovan chan->dcid = L2CAP_CID_CONN_LESS; 5230c1bc5c6SGustavo F. Padovan chan->omtu = L2CAP_DEFAULT_MTU; 5245491120eSAndrei Emeltchenko break; 5255491120eSAndrei Emeltchenko 526416fa752SAndrei Emeltchenko case L2CAP_CHAN_CONN_FIX_A2MP: 527416fa752SAndrei Emeltchenko chan->scid = L2CAP_CID_A2MP; 528416fa752SAndrei Emeltchenko chan->dcid = L2CAP_CID_A2MP; 529416fa752SAndrei Emeltchenko chan->omtu = L2CAP_A2MP_DEFAULT_MTU; 530416fa752SAndrei Emeltchenko chan->imtu = L2CAP_A2MP_DEFAULT_MTU; 531416fa752SAndrei Emeltchenko break; 532416fa752SAndrei Emeltchenko 5335491120eSAndrei Emeltchenko default: 5340a708f8fSGustavo F. Padovan /* Raw socket can send/recv signalling messages only */ 535fe4128e0SGustavo F. Padovan chan->scid = L2CAP_CID_SIGNALING; 536fe4128e0SGustavo F. Padovan chan->dcid = L2CAP_CID_SIGNALING; 5370c1bc5c6SGustavo F. Padovan chan->omtu = L2CAP_DEFAULT_MTU; 5380a708f8fSGustavo F. Padovan } 5390a708f8fSGustavo F. Padovan 5408f7975b1SAndrei Emeltchenko chan->local_id = L2CAP_BESTEFFORT_ID; 5418f7975b1SAndrei Emeltchenko chan->local_stype = L2CAP_SERV_BESTEFFORT; 5428f7975b1SAndrei Emeltchenko chan->local_msdu = L2CAP_DEFAULT_MAX_SDU_SIZE; 5438f7975b1SAndrei Emeltchenko chan->local_sdu_itime = L2CAP_DEFAULT_SDU_ITIME; 5448f7975b1SAndrei Emeltchenko chan->local_acc_lat = L2CAP_DEFAULT_ACC_LAT; 5458936fa6dSAndrei Emeltchenko chan->local_flush_to = L2CAP_EFS_DEFAULT_FLUSH_TO; 5468f7975b1SAndrei Emeltchenko 547371fd835SUlisses Furquim l2cap_chan_hold(chan); 548baa7e1faSGustavo F. Padovan 5495ee9891dSJohan Hedberg hci_conn_hold(conn->hcon); 5505ee9891dSJohan Hedberg 5513df91ea2SAndrei Emeltchenko list_add(&chan->list, &conn->chan_l); 552643162a8SAndrei Emeltchenko } 553643162a8SAndrei Emeltchenko 554466f8004SAndrei Emeltchenko void l2cap_chan_add(struct l2cap_conn *conn, struct l2cap_chan *chan) 555643162a8SAndrei Emeltchenko { 556643162a8SAndrei Emeltchenko mutex_lock(&conn->chan_lock); 557643162a8SAndrei Emeltchenko __l2cap_chan_add(conn, chan); 5583df91ea2SAndrei Emeltchenko mutex_unlock(&conn->chan_lock); 5590a708f8fSGustavo F. Padovan } 5600a708f8fSGustavo F. Padovan 561466f8004SAndrei Emeltchenko void l2cap_chan_del(struct l2cap_chan *chan, int err) 5620a708f8fSGustavo F. Padovan { 5638c1d787bSGustavo F. Padovan struct l2cap_conn *conn = chan->conn; 5640a708f8fSGustavo F. Padovan 565c9b66675SGustavo F. Padovan __clear_chan_timer(chan); 5660a708f8fSGustavo F. Padovan 56749208c9cSGustavo F. Padovan BT_DBG("chan %p, conn %p, err %d", chan, conn, err); 5680a708f8fSGustavo F. Padovan 5690a708f8fSGustavo F. Padovan if (conn) { 57056f60984SAndrei Emeltchenko struct amp_mgr *mgr = conn->hcon->amp_mgr; 571baa7e1faSGustavo F. Padovan /* Delete from channel list */ 5723df91ea2SAndrei Emeltchenko list_del(&chan->list); 5733d57dc68SGustavo F. Padovan 574371fd835SUlisses Furquim l2cap_chan_put(chan); 575baa7e1faSGustavo F. Padovan 5768c1d787bSGustavo F. Padovan chan->conn = NULL; 5773cabbfdaSAndrei Emeltchenko 5783cabbfdaSAndrei Emeltchenko if (chan->chan_type != L2CAP_CHAN_CONN_FIX_A2MP) 57976a68ba0SDavid Herrmann hci_conn_drop(conn->hcon); 58056f60984SAndrei Emeltchenko 58156f60984SAndrei Emeltchenko if (mgr && mgr->bredr_chan == chan) 58256f60984SAndrei Emeltchenko mgr->bredr_chan = NULL; 5830a708f8fSGustavo F. Padovan } 5840a708f8fSGustavo F. Padovan 585419e08c1SAndrei Emeltchenko if (chan->hs_hchan) { 586419e08c1SAndrei Emeltchenko struct hci_chan *hs_hchan = chan->hs_hchan; 587419e08c1SAndrei Emeltchenko 588419e08c1SAndrei Emeltchenko BT_DBG("chan %p disconnect hs_hchan %p", chan, hs_hchan); 589419e08c1SAndrei Emeltchenko amp_disconnect_logical_link(hs_hchan); 590419e08c1SAndrei Emeltchenko } 591419e08c1SAndrei Emeltchenko 592c0df7f6eSAndrei Emeltchenko chan->ops->teardown(chan, err); 5936be36555SAndrei Emeltchenko 5942827011fSMat Martineau if (test_bit(CONF_NOT_COMPLETE, &chan->conf_state)) 5956ff5abbfSGustavo F. Padovan return; 5962ead70b8SGustavo F. Padovan 597ee556f66SGustavo Padovan switch(chan->mode) { 598ee556f66SGustavo Padovan case L2CAP_MODE_BASIC: 599ee556f66SGustavo Padovan break; 6000a708f8fSGustavo F. Padovan 601ee556f66SGustavo Padovan case L2CAP_MODE_ERTM: 6021a09bcb9SGustavo F. Padovan __clear_retrans_timer(chan); 6031a09bcb9SGustavo F. Padovan __clear_monitor_timer(chan); 6041a09bcb9SGustavo F. Padovan __clear_ack_timer(chan); 6050a708f8fSGustavo F. Padovan 606f1c6775bSGustavo F. Padovan skb_queue_purge(&chan->srej_q); 6070a708f8fSGustavo F. Padovan 6083c588192SMat Martineau l2cap_seq_list_free(&chan->srej_list); 6093c588192SMat Martineau l2cap_seq_list_free(&chan->retrans_list); 610ee556f66SGustavo Padovan 611ee556f66SGustavo Padovan /* fall through */ 612ee556f66SGustavo Padovan 613ee556f66SGustavo Padovan case L2CAP_MODE_STREAMING: 614ee556f66SGustavo Padovan skb_queue_purge(&chan->tx_q); 615ee556f66SGustavo Padovan break; 6160a708f8fSGustavo F. Padovan } 617ee556f66SGustavo Padovan 618ee556f66SGustavo Padovan return; 6190a708f8fSGustavo F. Padovan } 6200a708f8fSGustavo F. Padovan 6210f852724SGustavo F. Padovan void l2cap_chan_close(struct l2cap_chan *chan, int reason) 6224519de9aSGustavo F. Padovan { 6234519de9aSGustavo F. Padovan struct l2cap_conn *conn = chan->conn; 6244519de9aSGustavo F. Padovan struct sock *sk = chan->sk; 6254519de9aSGustavo F. Padovan 6262d792818SGustavo Padovan BT_DBG("chan %p state %s sk %p", chan, state_to_string(chan->state), 6272d792818SGustavo Padovan sk); 6284519de9aSGustavo F. Padovan 62989bc500eSGustavo F. Padovan switch (chan->state) { 6304519de9aSGustavo F. Padovan case BT_LISTEN: 631c0df7f6eSAndrei Emeltchenko chan->ops->teardown(chan, 0); 6324519de9aSGustavo F. Padovan break; 6334519de9aSGustavo F. Padovan 6344519de9aSGustavo F. Padovan case BT_CONNECTED: 6354519de9aSGustavo F. Padovan case BT_CONFIG: 636715ec005SGustavo F. Padovan if (chan->chan_type == L2CAP_CHAN_CONN_ORIENTED && 6374519de9aSGustavo F. Padovan conn->hcon->type == ACL_LINK) { 638c9b66675SGustavo F. Padovan __set_chan_timer(chan, sk->sk_sndtimeo); 6395e4e3972SAndrei Emeltchenko l2cap_send_disconn_req(chan, reason); 6404519de9aSGustavo F. Padovan } else 6414519de9aSGustavo F. Padovan l2cap_chan_del(chan, reason); 6424519de9aSGustavo F. Padovan break; 6434519de9aSGustavo F. Padovan 6444519de9aSGustavo F. Padovan case BT_CONNECT2: 645715ec005SGustavo F. Padovan if (chan->chan_type == L2CAP_CHAN_CONN_ORIENTED && 6464519de9aSGustavo F. Padovan conn->hcon->type == ACL_LINK) { 6474519de9aSGustavo F. Padovan struct l2cap_conn_rsp rsp; 6484519de9aSGustavo F. Padovan __u16 result; 6494519de9aSGustavo F. Padovan 650c5daa683SGustavo Padovan if (test_bit(BT_SK_DEFER_SETUP, &bt_sk(sk)->flags)) 6514519de9aSGustavo F. Padovan result = L2CAP_CR_SEC_BLOCK; 6524519de9aSGustavo F. Padovan else 6534519de9aSGustavo F. Padovan result = L2CAP_CR_BAD_PSM; 65489bc500eSGustavo F. Padovan l2cap_state_change(chan, BT_DISCONN); 6554519de9aSGustavo F. Padovan 6564519de9aSGustavo F. Padovan rsp.scid = cpu_to_le16(chan->dcid); 6574519de9aSGustavo F. Padovan rsp.dcid = cpu_to_le16(chan->scid); 6584519de9aSGustavo F. Padovan rsp.result = cpu_to_le16(result); 659ac73498cSAndrei Emeltchenko rsp.status = __constant_cpu_to_le16(L2CAP_CS_NO_INFO); 6604519de9aSGustavo F. Padovan l2cap_send_cmd(conn, chan->ident, L2CAP_CONN_RSP, 6614519de9aSGustavo F. Padovan sizeof(rsp), &rsp); 6624519de9aSGustavo F. Padovan } 6634519de9aSGustavo F. Padovan 6644519de9aSGustavo F. Padovan l2cap_chan_del(chan, reason); 6654519de9aSGustavo F. Padovan break; 6664519de9aSGustavo F. Padovan 6674519de9aSGustavo F. Padovan case BT_CONNECT: 6684519de9aSGustavo F. Padovan case BT_DISCONN: 6694519de9aSGustavo F. Padovan l2cap_chan_del(chan, reason); 6704519de9aSGustavo F. Padovan break; 6714519de9aSGustavo F. Padovan 6724519de9aSGustavo F. Padovan default: 673c0df7f6eSAndrei Emeltchenko chan->ops->teardown(chan, 0); 6744519de9aSGustavo F. Padovan break; 6754519de9aSGustavo F. Padovan } 6764519de9aSGustavo F. Padovan } 6774519de9aSGustavo F. Padovan 6784343478fSGustavo F. Padovan static inline u8 l2cap_get_auth_type(struct l2cap_chan *chan) 6790a708f8fSGustavo F. Padovan { 680715ec005SGustavo F. Padovan if (chan->chan_type == L2CAP_CHAN_RAW) { 6814343478fSGustavo F. Padovan switch (chan->sec_level) { 6820a708f8fSGustavo F. Padovan case BT_SECURITY_HIGH: 6830a708f8fSGustavo F. Padovan return HCI_AT_DEDICATED_BONDING_MITM; 6840a708f8fSGustavo F. Padovan case BT_SECURITY_MEDIUM: 6850a708f8fSGustavo F. Padovan return HCI_AT_DEDICATED_BONDING; 6860a708f8fSGustavo F. Padovan default: 6870a708f8fSGustavo F. Padovan return HCI_AT_NO_BONDING; 6880a708f8fSGustavo F. Padovan } 6892983fd68SAndrei Emeltchenko } else if (chan->psm == __constant_cpu_to_le16(L2CAP_PSM_SDP)) { 6904343478fSGustavo F. Padovan if (chan->sec_level == BT_SECURITY_LOW) 6914343478fSGustavo F. Padovan chan->sec_level = BT_SECURITY_SDP; 6920a708f8fSGustavo F. Padovan 6934343478fSGustavo F. Padovan if (chan->sec_level == BT_SECURITY_HIGH) 6940a708f8fSGustavo F. Padovan return HCI_AT_NO_BONDING_MITM; 6950a708f8fSGustavo F. Padovan else 6960a708f8fSGustavo F. Padovan return HCI_AT_NO_BONDING; 6970a708f8fSGustavo F. Padovan } else { 6984343478fSGustavo F. Padovan switch (chan->sec_level) { 6990a708f8fSGustavo F. Padovan case BT_SECURITY_HIGH: 7000a708f8fSGustavo F. Padovan return HCI_AT_GENERAL_BONDING_MITM; 7010a708f8fSGustavo F. Padovan case BT_SECURITY_MEDIUM: 7020a708f8fSGustavo F. Padovan return HCI_AT_GENERAL_BONDING; 7030a708f8fSGustavo F. Padovan default: 7040a708f8fSGustavo F. Padovan return HCI_AT_NO_BONDING; 7050a708f8fSGustavo F. Padovan } 7060a708f8fSGustavo F. Padovan } 7070a708f8fSGustavo F. Padovan } 7080a708f8fSGustavo F. Padovan 7090a708f8fSGustavo F. Padovan /* Service level security */ 710d45fc423SGustavo F. Padovan int l2cap_chan_check_security(struct l2cap_chan *chan) 7110a708f8fSGustavo F. Padovan { 7128c1d787bSGustavo F. Padovan struct l2cap_conn *conn = chan->conn; 7130a708f8fSGustavo F. Padovan __u8 auth_type; 7140a708f8fSGustavo F. Padovan 7154343478fSGustavo F. Padovan auth_type = l2cap_get_auth_type(chan); 7160a708f8fSGustavo F. Padovan 7174343478fSGustavo F. Padovan return hci_conn_security(conn->hcon, chan->sec_level, auth_type); 7180a708f8fSGustavo F. Padovan } 7190a708f8fSGustavo F. Padovan 720b5ad8b7fSJohannes Berg static u8 l2cap_get_ident(struct l2cap_conn *conn) 7210a708f8fSGustavo F. Padovan { 7220a708f8fSGustavo F. Padovan u8 id; 7230a708f8fSGustavo F. Padovan 7240a708f8fSGustavo F. Padovan /* Get next available identificator. 7250a708f8fSGustavo F. Padovan * 1 - 128 are used by kernel. 7260a708f8fSGustavo F. Padovan * 129 - 199 are reserved. 7270a708f8fSGustavo F. Padovan * 200 - 254 are used by utilities like l2ping, etc. 7280a708f8fSGustavo F. Padovan */ 7290a708f8fSGustavo F. Padovan 730333055f2SGustavo F. Padovan spin_lock(&conn->lock); 7310a708f8fSGustavo F. Padovan 7320a708f8fSGustavo F. Padovan if (++conn->tx_ident > 128) 7330a708f8fSGustavo F. Padovan conn->tx_ident = 1; 7340a708f8fSGustavo F. Padovan 7350a708f8fSGustavo F. Padovan id = conn->tx_ident; 7360a708f8fSGustavo F. Padovan 737333055f2SGustavo F. Padovan spin_unlock(&conn->lock); 7380a708f8fSGustavo F. Padovan 7390a708f8fSGustavo F. Padovan return id; 7400a708f8fSGustavo F. Padovan } 7410a708f8fSGustavo F. Padovan 7422d792818SGustavo Padovan static void l2cap_send_cmd(struct l2cap_conn *conn, u8 ident, u8 code, u16 len, 7432d792818SGustavo Padovan void *data) 7440a708f8fSGustavo F. Padovan { 7450a708f8fSGustavo F. Padovan struct sk_buff *skb = l2cap_build_cmd(conn, code, ident, len, data); 7460a708f8fSGustavo F. Padovan u8 flags; 7470a708f8fSGustavo F. Padovan 7480a708f8fSGustavo F. Padovan BT_DBG("code 0x%2.2x", code); 7490a708f8fSGustavo F. Padovan 7500a708f8fSGustavo F. Padovan if (!skb) 7510a708f8fSGustavo F. Padovan return; 7520a708f8fSGustavo F. Padovan 7530a708f8fSGustavo F. Padovan if (lmp_no_flush_capable(conn->hcon->hdev)) 7540a708f8fSGustavo F. Padovan flags = ACL_START_NO_FLUSH; 7550a708f8fSGustavo F. Padovan else 7560a708f8fSGustavo F. Padovan flags = ACL_START; 7570a708f8fSGustavo F. Padovan 75814b12d0bSJaikumar Ganesh bt_cb(skb)->force_active = BT_POWER_FORCE_ACTIVE_ON; 7595e59b791SLuiz Augusto von Dentz skb->priority = HCI_PRIO_MAX; 76014b12d0bSJaikumar Ganesh 76173d80debSLuiz Augusto von Dentz hci_send_acl(conn->hchan, skb, flags); 7620a708f8fSGustavo F. Padovan } 7630a708f8fSGustavo F. Padovan 76402b0fbb9SMat Martineau static bool __chan_is_moving(struct l2cap_chan *chan) 76502b0fbb9SMat Martineau { 76602b0fbb9SMat Martineau return chan->move_state != L2CAP_MOVE_STABLE && 76702b0fbb9SMat Martineau chan->move_state != L2CAP_MOVE_WAIT_PREPARE; 76802b0fbb9SMat Martineau } 76902b0fbb9SMat Martineau 77073d80debSLuiz Augusto von Dentz static void l2cap_do_send(struct l2cap_chan *chan, struct sk_buff *skb) 77173d80debSLuiz Augusto von Dentz { 77273d80debSLuiz Augusto von Dentz struct hci_conn *hcon = chan->conn->hcon; 77373d80debSLuiz Augusto von Dentz u16 flags; 77473d80debSLuiz Augusto von Dentz 77573d80debSLuiz Augusto von Dentz BT_DBG("chan %p, skb %p len %d priority %u", chan, skb, skb->len, 77673d80debSLuiz Augusto von Dentz skb->priority); 77773d80debSLuiz Augusto von Dentz 778d5f8a75dSMat Martineau if (chan->hs_hcon && !__chan_is_moving(chan)) { 779d5f8a75dSMat Martineau if (chan->hs_hchan) 780d5f8a75dSMat Martineau hci_send_acl(chan->hs_hchan, skb, ACL_COMPLETE); 781d5f8a75dSMat Martineau else 782d5f8a75dSMat Martineau kfree_skb(skb); 783d5f8a75dSMat Martineau 784d5f8a75dSMat Martineau return; 785d5f8a75dSMat Martineau } 786d5f8a75dSMat Martineau 78773d80debSLuiz Augusto von Dentz if (!test_bit(FLAG_FLUSHABLE, &chan->flags) && 78873d80debSLuiz Augusto von Dentz lmp_no_flush_capable(hcon->hdev)) 78973d80debSLuiz Augusto von Dentz flags = ACL_START_NO_FLUSH; 79073d80debSLuiz Augusto von Dentz else 79173d80debSLuiz Augusto von Dentz flags = ACL_START; 79273d80debSLuiz Augusto von Dentz 79373d80debSLuiz Augusto von Dentz bt_cb(skb)->force_active = test_bit(FLAG_FORCE_ACTIVE, &chan->flags); 79473d80debSLuiz Augusto von Dentz hci_send_acl(chan->conn->hchan, skb, flags); 7950a708f8fSGustavo F. Padovan } 7960a708f8fSGustavo F. Padovan 797b5c6aaedSMat Martineau static void __unpack_enhanced_control(u16 enh, struct l2cap_ctrl *control) 798b5c6aaedSMat Martineau { 799b5c6aaedSMat Martineau control->reqseq = (enh & L2CAP_CTRL_REQSEQ) >> L2CAP_CTRL_REQSEQ_SHIFT; 800b5c6aaedSMat Martineau control->final = (enh & L2CAP_CTRL_FINAL) >> L2CAP_CTRL_FINAL_SHIFT; 801b5c6aaedSMat Martineau 802b5c6aaedSMat Martineau if (enh & L2CAP_CTRL_FRAME_TYPE) { 803b5c6aaedSMat Martineau /* S-Frame */ 804b5c6aaedSMat Martineau control->sframe = 1; 805b5c6aaedSMat Martineau control->poll = (enh & L2CAP_CTRL_POLL) >> L2CAP_CTRL_POLL_SHIFT; 806b5c6aaedSMat Martineau control->super = (enh & L2CAP_CTRL_SUPERVISE) >> L2CAP_CTRL_SUPER_SHIFT; 807b5c6aaedSMat Martineau 808b5c6aaedSMat Martineau control->sar = 0; 809b5c6aaedSMat Martineau control->txseq = 0; 810b5c6aaedSMat Martineau } else { 811b5c6aaedSMat Martineau /* I-Frame */ 812b5c6aaedSMat Martineau control->sframe = 0; 813b5c6aaedSMat Martineau control->sar = (enh & L2CAP_CTRL_SAR) >> L2CAP_CTRL_SAR_SHIFT; 814b5c6aaedSMat Martineau control->txseq = (enh & L2CAP_CTRL_TXSEQ) >> L2CAP_CTRL_TXSEQ_SHIFT; 815b5c6aaedSMat Martineau 816b5c6aaedSMat Martineau control->poll = 0; 817b5c6aaedSMat Martineau control->super = 0; 818b5c6aaedSMat Martineau } 819b5c6aaedSMat Martineau } 820b5c6aaedSMat Martineau 821b5c6aaedSMat Martineau static void __unpack_extended_control(u32 ext, struct l2cap_ctrl *control) 822b5c6aaedSMat Martineau { 823b5c6aaedSMat Martineau control->reqseq = (ext & L2CAP_EXT_CTRL_REQSEQ) >> L2CAP_EXT_CTRL_REQSEQ_SHIFT; 824b5c6aaedSMat Martineau control->final = (ext & L2CAP_EXT_CTRL_FINAL) >> L2CAP_EXT_CTRL_FINAL_SHIFT; 825b5c6aaedSMat Martineau 826b5c6aaedSMat Martineau if (ext & L2CAP_EXT_CTRL_FRAME_TYPE) { 827b5c6aaedSMat Martineau /* S-Frame */ 828b5c6aaedSMat Martineau control->sframe = 1; 829b5c6aaedSMat Martineau control->poll = (ext & L2CAP_EXT_CTRL_POLL) >> L2CAP_EXT_CTRL_POLL_SHIFT; 830b5c6aaedSMat Martineau control->super = (ext & L2CAP_EXT_CTRL_SUPERVISE) >> L2CAP_EXT_CTRL_SUPER_SHIFT; 831b5c6aaedSMat Martineau 832b5c6aaedSMat Martineau control->sar = 0; 833b5c6aaedSMat Martineau control->txseq = 0; 834b5c6aaedSMat Martineau } else { 835b5c6aaedSMat Martineau /* I-Frame */ 836b5c6aaedSMat Martineau control->sframe = 0; 837b5c6aaedSMat Martineau control->sar = (ext & L2CAP_EXT_CTRL_SAR) >> L2CAP_EXT_CTRL_SAR_SHIFT; 838b5c6aaedSMat Martineau control->txseq = (ext & L2CAP_EXT_CTRL_TXSEQ) >> L2CAP_EXT_CTRL_TXSEQ_SHIFT; 839b5c6aaedSMat Martineau 840b5c6aaedSMat Martineau control->poll = 0; 841b5c6aaedSMat Martineau control->super = 0; 842b5c6aaedSMat Martineau } 843b5c6aaedSMat Martineau } 844b5c6aaedSMat Martineau 845b5c6aaedSMat Martineau static inline void __unpack_control(struct l2cap_chan *chan, 846b5c6aaedSMat Martineau struct sk_buff *skb) 847b5c6aaedSMat Martineau { 848b5c6aaedSMat Martineau if (test_bit(FLAG_EXT_CTRL, &chan->flags)) { 849b5c6aaedSMat Martineau __unpack_extended_control(get_unaligned_le32(skb->data), 850b5c6aaedSMat Martineau &bt_cb(skb)->control); 851cec8ab6eSMat Martineau skb_pull(skb, L2CAP_EXT_CTRL_SIZE); 852b5c6aaedSMat Martineau } else { 853b5c6aaedSMat Martineau __unpack_enhanced_control(get_unaligned_le16(skb->data), 854b5c6aaedSMat Martineau &bt_cb(skb)->control); 855cec8ab6eSMat Martineau skb_pull(skb, L2CAP_ENH_CTRL_SIZE); 856b5c6aaedSMat Martineau } 857b5c6aaedSMat Martineau } 858b5c6aaedSMat Martineau 859b5c6aaedSMat Martineau static u32 __pack_extended_control(struct l2cap_ctrl *control) 860b5c6aaedSMat Martineau { 861b5c6aaedSMat Martineau u32 packed; 862b5c6aaedSMat Martineau 863b5c6aaedSMat Martineau packed = control->reqseq << L2CAP_EXT_CTRL_REQSEQ_SHIFT; 864b5c6aaedSMat Martineau packed |= control->final << L2CAP_EXT_CTRL_FINAL_SHIFT; 865b5c6aaedSMat Martineau 866b5c6aaedSMat Martineau if (control->sframe) { 867b5c6aaedSMat Martineau packed |= control->poll << L2CAP_EXT_CTRL_POLL_SHIFT; 868b5c6aaedSMat Martineau packed |= control->super << L2CAP_EXT_CTRL_SUPER_SHIFT; 869b5c6aaedSMat Martineau packed |= L2CAP_EXT_CTRL_FRAME_TYPE; 870b5c6aaedSMat Martineau } else { 871b5c6aaedSMat Martineau packed |= control->sar << L2CAP_EXT_CTRL_SAR_SHIFT; 872b5c6aaedSMat Martineau packed |= control->txseq << L2CAP_EXT_CTRL_TXSEQ_SHIFT; 873b5c6aaedSMat Martineau } 874b5c6aaedSMat Martineau 875b5c6aaedSMat Martineau return packed; 876b5c6aaedSMat Martineau } 877b5c6aaedSMat Martineau 878b5c6aaedSMat Martineau static u16 __pack_enhanced_control(struct l2cap_ctrl *control) 879b5c6aaedSMat Martineau { 880b5c6aaedSMat Martineau u16 packed; 881b5c6aaedSMat Martineau 882b5c6aaedSMat Martineau packed = control->reqseq << L2CAP_CTRL_REQSEQ_SHIFT; 883b5c6aaedSMat Martineau packed |= control->final << L2CAP_CTRL_FINAL_SHIFT; 884b5c6aaedSMat Martineau 885b5c6aaedSMat Martineau if (control->sframe) { 886b5c6aaedSMat Martineau packed |= control->poll << L2CAP_CTRL_POLL_SHIFT; 887b5c6aaedSMat Martineau packed |= control->super << L2CAP_CTRL_SUPER_SHIFT; 888b5c6aaedSMat Martineau packed |= L2CAP_CTRL_FRAME_TYPE; 889b5c6aaedSMat Martineau } else { 890b5c6aaedSMat Martineau packed |= control->sar << L2CAP_CTRL_SAR_SHIFT; 891b5c6aaedSMat Martineau packed |= control->txseq << L2CAP_CTRL_TXSEQ_SHIFT; 892b5c6aaedSMat Martineau } 893b5c6aaedSMat Martineau 894b5c6aaedSMat Martineau return packed; 895b5c6aaedSMat Martineau } 896b5c6aaedSMat Martineau 897b5c6aaedSMat Martineau static inline void __pack_control(struct l2cap_chan *chan, 898b5c6aaedSMat Martineau struct l2cap_ctrl *control, 899b5c6aaedSMat Martineau struct sk_buff *skb) 900b5c6aaedSMat Martineau { 901b5c6aaedSMat Martineau if (test_bit(FLAG_EXT_CTRL, &chan->flags)) { 902b5c6aaedSMat Martineau put_unaligned_le32(__pack_extended_control(control), 903b5c6aaedSMat Martineau skb->data + L2CAP_HDR_SIZE); 904b5c6aaedSMat Martineau } else { 905b5c6aaedSMat Martineau put_unaligned_le16(__pack_enhanced_control(control), 906b5c6aaedSMat Martineau skb->data + L2CAP_HDR_SIZE); 907b5c6aaedSMat Martineau } 908b5c6aaedSMat Martineau } 909b5c6aaedSMat Martineau 910ba7aa64fSGustavo Padovan static inline unsigned int __ertm_hdr_size(struct l2cap_chan *chan) 911ba7aa64fSGustavo Padovan { 912ba7aa64fSGustavo Padovan if (test_bit(FLAG_EXT_CTRL, &chan->flags)) 913ba7aa64fSGustavo Padovan return L2CAP_EXT_HDR_SIZE; 914ba7aa64fSGustavo Padovan else 915ba7aa64fSGustavo Padovan return L2CAP_ENH_HDR_SIZE; 916ba7aa64fSGustavo Padovan } 917ba7aa64fSGustavo Padovan 918a67d7f6fSMat Martineau static struct sk_buff *l2cap_create_sframe_pdu(struct l2cap_chan *chan, 919a67d7f6fSMat Martineau u32 control) 9200a708f8fSGustavo F. Padovan { 9210a708f8fSGustavo F. Padovan struct sk_buff *skb; 9220a708f8fSGustavo F. Padovan struct l2cap_hdr *lh; 923ba7aa64fSGustavo Padovan int hlen = __ertm_hdr_size(chan); 9240a708f8fSGustavo F. Padovan 9250a708f8fSGustavo F. Padovan if (chan->fcs == L2CAP_FCS_CRC16) 92603a51213SAndrei Emeltchenko hlen += L2CAP_FCS_SIZE; 9270a708f8fSGustavo F. Padovan 928a67d7f6fSMat Martineau skb = bt_skb_alloc(hlen, GFP_KERNEL); 9290a708f8fSGustavo F. Padovan 9300a708f8fSGustavo F. Padovan if (!skb) 931a67d7f6fSMat Martineau return ERR_PTR(-ENOMEM); 9320a708f8fSGustavo F. Padovan 9330a708f8fSGustavo F. Padovan lh = (struct l2cap_hdr *) skb_put(skb, L2CAP_HDR_SIZE); 9340a708f8fSGustavo F. Padovan lh->len = cpu_to_le16(hlen - L2CAP_HDR_SIZE); 935fe4128e0SGustavo F. Padovan lh->cid = cpu_to_le16(chan->dcid); 93688843ab0SAndrei Emeltchenko 937a67d7f6fSMat Martineau if (test_bit(FLAG_EXT_CTRL, &chan->flags)) 938a67d7f6fSMat Martineau put_unaligned_le32(control, skb_put(skb, L2CAP_EXT_CTRL_SIZE)); 939a67d7f6fSMat Martineau else 940a67d7f6fSMat Martineau put_unaligned_le16(control, skb_put(skb, L2CAP_ENH_CTRL_SIZE)); 9410a708f8fSGustavo F. Padovan 94247d1ec61SGustavo F. Padovan if (chan->fcs == L2CAP_FCS_CRC16) { 943a67d7f6fSMat Martineau u16 fcs = crc16(0, (u8 *)skb->data, skb->len); 94403a51213SAndrei Emeltchenko put_unaligned_le16(fcs, skb_put(skb, L2CAP_FCS_SIZE)); 9450a708f8fSGustavo F. Padovan } 9460a708f8fSGustavo F. Padovan 94773d80debSLuiz Augusto von Dentz skb->priority = HCI_PRIO_MAX; 948a67d7f6fSMat Martineau return skb; 949a67d7f6fSMat Martineau } 950a67d7f6fSMat Martineau 951a67d7f6fSMat Martineau static void l2cap_send_sframe(struct l2cap_chan *chan, 952a67d7f6fSMat Martineau struct l2cap_ctrl *control) 953a67d7f6fSMat Martineau { 954a67d7f6fSMat Martineau struct sk_buff *skb; 955a67d7f6fSMat Martineau u32 control_field; 956a67d7f6fSMat Martineau 957a67d7f6fSMat Martineau BT_DBG("chan %p, control %p", chan, control); 958a67d7f6fSMat Martineau 959a67d7f6fSMat Martineau if (!control->sframe) 960a67d7f6fSMat Martineau return; 961a67d7f6fSMat Martineau 962b99e13adSMat Martineau if (__chan_is_moving(chan)) 963b99e13adSMat Martineau return; 964b99e13adSMat Martineau 965a67d7f6fSMat Martineau if (test_and_clear_bit(CONN_SEND_FBIT, &chan->conn_state) && 966a67d7f6fSMat Martineau !control->poll) 967a67d7f6fSMat Martineau control->final = 1; 968a67d7f6fSMat Martineau 969a67d7f6fSMat Martineau if (control->super == L2CAP_SUPER_RR) 970a67d7f6fSMat Martineau clear_bit(CONN_RNR_SENT, &chan->conn_state); 971a67d7f6fSMat Martineau else if (control->super == L2CAP_SUPER_RNR) 972a67d7f6fSMat Martineau set_bit(CONN_RNR_SENT, &chan->conn_state); 973a67d7f6fSMat Martineau 974a67d7f6fSMat Martineau if (control->super != L2CAP_SUPER_SREJ) { 975a67d7f6fSMat Martineau chan->last_acked_seq = control->reqseq; 976a67d7f6fSMat Martineau __clear_ack_timer(chan); 977a67d7f6fSMat Martineau } 978a67d7f6fSMat Martineau 979a67d7f6fSMat Martineau BT_DBG("reqseq %d, final %d, poll %d, super %d", control->reqseq, 980a67d7f6fSMat Martineau control->final, control->poll, control->super); 981a67d7f6fSMat Martineau 982a67d7f6fSMat Martineau if (test_bit(FLAG_EXT_CTRL, &chan->flags)) 983a67d7f6fSMat Martineau control_field = __pack_extended_control(control); 984a67d7f6fSMat Martineau else 985a67d7f6fSMat Martineau control_field = __pack_enhanced_control(control); 986a67d7f6fSMat Martineau 987a67d7f6fSMat Martineau skb = l2cap_create_sframe_pdu(chan, control_field); 988a67d7f6fSMat Martineau if (!IS_ERR(skb)) 98973d80debSLuiz Augusto von Dentz l2cap_do_send(chan, skb); 9900a708f8fSGustavo F. Padovan } 9910a708f8fSGustavo F. Padovan 992c9e3d5e0SMat Martineau static void l2cap_send_rr_or_rnr(struct l2cap_chan *chan, bool poll) 9930a708f8fSGustavo F. Padovan { 994c9e3d5e0SMat Martineau struct l2cap_ctrl control; 9950a708f8fSGustavo F. Padovan 996c9e3d5e0SMat Martineau BT_DBG("chan %p, poll %d", chan, poll); 997c9e3d5e0SMat Martineau 998c9e3d5e0SMat Martineau memset(&control, 0, sizeof(control)); 999c9e3d5e0SMat Martineau control.sframe = 1; 1000c9e3d5e0SMat Martineau control.poll = poll; 1001c9e3d5e0SMat Martineau 1002c9e3d5e0SMat Martineau if (test_bit(CONN_LOCAL_BUSY, &chan->conn_state)) 1003c9e3d5e0SMat Martineau control.super = L2CAP_SUPER_RNR; 1004c9e3d5e0SMat Martineau else 1005c9e3d5e0SMat Martineau control.super = L2CAP_SUPER_RR; 1006c9e3d5e0SMat Martineau 1007c9e3d5e0SMat Martineau control.reqseq = chan->buffer_seq; 1008c9e3d5e0SMat Martineau l2cap_send_sframe(chan, &control); 10090a708f8fSGustavo F. Padovan } 10100a708f8fSGustavo F. Padovan 1011b4450035SGustavo F. Padovan static inline int __l2cap_no_conn_pending(struct l2cap_chan *chan) 10120a708f8fSGustavo F. Padovan { 1013c1360a1cSGustavo F. Padovan return !test_bit(CONF_CONNECT_PEND, &chan->conf_state); 10140a708f8fSGustavo F. Padovan } 10150a708f8fSGustavo F. Padovan 101693c3e8f5SAndrei Emeltchenko static bool __amp_capable(struct l2cap_chan *chan) 101793c3e8f5SAndrei Emeltchenko { 101893c3e8f5SAndrei Emeltchenko struct l2cap_conn *conn = chan->conn; 10191df7b17aSMarcel Holtmann struct hci_dev *hdev; 10201df7b17aSMarcel Holtmann bool amp_available = false; 102193c3e8f5SAndrei Emeltchenko 10221df7b17aSMarcel Holtmann if (!conn->hs_enabled) 10231df7b17aSMarcel Holtmann return false; 10241df7b17aSMarcel Holtmann 10251df7b17aSMarcel Holtmann if (!(conn->fixed_chan_mask & L2CAP_FC_A2MP)) 10261df7b17aSMarcel Holtmann return false; 10271df7b17aSMarcel Holtmann 10281df7b17aSMarcel Holtmann read_lock(&hci_dev_list_lock); 10291df7b17aSMarcel Holtmann list_for_each_entry(hdev, &hci_dev_list, list) { 10301df7b17aSMarcel Holtmann if (hdev->amp_type != AMP_TYPE_BREDR && 10311df7b17aSMarcel Holtmann test_bit(HCI_UP, &hdev->flags)) { 10321df7b17aSMarcel Holtmann amp_available = true; 10331df7b17aSMarcel Holtmann break; 10341df7b17aSMarcel Holtmann } 10351df7b17aSMarcel Holtmann } 10361df7b17aSMarcel Holtmann read_unlock(&hci_dev_list_lock); 10371df7b17aSMarcel Holtmann 10381df7b17aSMarcel Holtmann if (chan->chan_policy == BT_CHANNEL_POLICY_AMP_PREFERRED) 10391df7b17aSMarcel Holtmann return amp_available; 1040848566b3SMarcel Holtmann 104193c3e8f5SAndrei Emeltchenko return false; 104293c3e8f5SAndrei Emeltchenko } 104393c3e8f5SAndrei Emeltchenko 10445ce66b59SAndrei Emeltchenko static bool l2cap_check_efs(struct l2cap_chan *chan) 10455ce66b59SAndrei Emeltchenko { 10465ce66b59SAndrei Emeltchenko /* Check EFS parameters */ 10475ce66b59SAndrei Emeltchenko return true; 10485ce66b59SAndrei Emeltchenko } 10495ce66b59SAndrei Emeltchenko 10502766be48SAndrei Emeltchenko void l2cap_send_conn_req(struct l2cap_chan *chan) 10519b27f350SAndrei Emeltchenko { 10529b27f350SAndrei Emeltchenko struct l2cap_conn *conn = chan->conn; 10539b27f350SAndrei Emeltchenko struct l2cap_conn_req req; 10549b27f350SAndrei Emeltchenko 10559b27f350SAndrei Emeltchenko req.scid = cpu_to_le16(chan->scid); 10569b27f350SAndrei Emeltchenko req.psm = chan->psm; 10579b27f350SAndrei Emeltchenko 10589b27f350SAndrei Emeltchenko chan->ident = l2cap_get_ident(conn); 10599b27f350SAndrei Emeltchenko 10609b27f350SAndrei Emeltchenko set_bit(CONF_CONNECT_PEND, &chan->conf_state); 10619b27f350SAndrei Emeltchenko 10629b27f350SAndrei Emeltchenko l2cap_send_cmd(conn, chan->ident, L2CAP_CONN_REQ, sizeof(req), &req); 10639b27f350SAndrei Emeltchenko } 10649b27f350SAndrei Emeltchenko 10658eb200bdSMat Martineau static void l2cap_send_create_chan_req(struct l2cap_chan *chan, u8 amp_id) 10668eb200bdSMat Martineau { 10678eb200bdSMat Martineau struct l2cap_create_chan_req req; 10688eb200bdSMat Martineau req.scid = cpu_to_le16(chan->scid); 10698eb200bdSMat Martineau req.psm = chan->psm; 10708eb200bdSMat Martineau req.amp_id = amp_id; 10718eb200bdSMat Martineau 10728eb200bdSMat Martineau chan->ident = l2cap_get_ident(chan->conn); 10738eb200bdSMat Martineau 10748eb200bdSMat Martineau l2cap_send_cmd(chan->conn, chan->ident, L2CAP_CREATE_CHAN_REQ, 10758eb200bdSMat Martineau sizeof(req), &req); 10768eb200bdSMat Martineau } 10778eb200bdSMat Martineau 107802b0fbb9SMat Martineau static void l2cap_move_setup(struct l2cap_chan *chan) 107902b0fbb9SMat Martineau { 108002b0fbb9SMat Martineau struct sk_buff *skb; 108102b0fbb9SMat Martineau 108202b0fbb9SMat Martineau BT_DBG("chan %p", chan); 108302b0fbb9SMat Martineau 108402b0fbb9SMat Martineau if (chan->mode != L2CAP_MODE_ERTM) 108502b0fbb9SMat Martineau return; 108602b0fbb9SMat Martineau 108702b0fbb9SMat Martineau __clear_retrans_timer(chan); 108802b0fbb9SMat Martineau __clear_monitor_timer(chan); 108902b0fbb9SMat Martineau __clear_ack_timer(chan); 109002b0fbb9SMat Martineau 109102b0fbb9SMat Martineau chan->retry_count = 0; 109202b0fbb9SMat Martineau skb_queue_walk(&chan->tx_q, skb) { 109302b0fbb9SMat Martineau if (bt_cb(skb)->control.retries) 109402b0fbb9SMat Martineau bt_cb(skb)->control.retries = 1; 109502b0fbb9SMat Martineau else 109602b0fbb9SMat Martineau break; 109702b0fbb9SMat Martineau } 109802b0fbb9SMat Martineau 109902b0fbb9SMat Martineau chan->expected_tx_seq = chan->buffer_seq; 110002b0fbb9SMat Martineau 110102b0fbb9SMat Martineau clear_bit(CONN_REJ_ACT, &chan->conn_state); 110202b0fbb9SMat Martineau clear_bit(CONN_SREJ_ACT, &chan->conn_state); 110302b0fbb9SMat Martineau l2cap_seq_list_clear(&chan->retrans_list); 110402b0fbb9SMat Martineau l2cap_seq_list_clear(&chan->srej_list); 110502b0fbb9SMat Martineau skb_queue_purge(&chan->srej_q); 110602b0fbb9SMat Martineau 110702b0fbb9SMat Martineau chan->tx_state = L2CAP_TX_STATE_XMIT; 110802b0fbb9SMat Martineau chan->rx_state = L2CAP_RX_STATE_MOVE; 110902b0fbb9SMat Martineau 111002b0fbb9SMat Martineau set_bit(CONN_REMOTE_BUSY, &chan->conn_state); 111102b0fbb9SMat Martineau } 111202b0fbb9SMat Martineau 11135f3847a4SMat Martineau static void l2cap_move_done(struct l2cap_chan *chan) 11145f3847a4SMat Martineau { 11155f3847a4SMat Martineau u8 move_role = chan->move_role; 11165f3847a4SMat Martineau BT_DBG("chan %p", chan); 11175f3847a4SMat Martineau 11185f3847a4SMat Martineau chan->move_state = L2CAP_MOVE_STABLE; 11195f3847a4SMat Martineau chan->move_role = L2CAP_MOVE_ROLE_NONE; 11205f3847a4SMat Martineau 11215f3847a4SMat Martineau if (chan->mode != L2CAP_MODE_ERTM) 11225f3847a4SMat Martineau return; 11235f3847a4SMat Martineau 11245f3847a4SMat Martineau switch (move_role) { 11255f3847a4SMat Martineau case L2CAP_MOVE_ROLE_INITIATOR: 11265f3847a4SMat Martineau l2cap_tx(chan, NULL, NULL, L2CAP_EV_EXPLICIT_POLL); 11275f3847a4SMat Martineau chan->rx_state = L2CAP_RX_STATE_WAIT_F; 11285f3847a4SMat Martineau break; 11295f3847a4SMat Martineau case L2CAP_MOVE_ROLE_RESPONDER: 11305f3847a4SMat Martineau chan->rx_state = L2CAP_RX_STATE_WAIT_P; 11315f3847a4SMat Martineau break; 11325f3847a4SMat Martineau } 11335f3847a4SMat Martineau } 11345f3847a4SMat Martineau 11359f0caeb1SVinicius Costa Gomes static void l2cap_chan_ready(struct l2cap_chan *chan) 11369f0caeb1SVinicius Costa Gomes { 11372827011fSMat Martineau /* This clears all conf flags, including CONF_NOT_COMPLETE */ 11389f0caeb1SVinicius Costa Gomes chan->conf_state = 0; 11399f0caeb1SVinicius Costa Gomes __clear_chan_timer(chan); 11409f0caeb1SVinicius Costa Gomes 114154a59aa2SAndrei Emeltchenko chan->state = BT_CONNECTED; 11429f0caeb1SVinicius Costa Gomes 114354a59aa2SAndrei Emeltchenko chan->ops->ready(chan); 11449f0caeb1SVinicius Costa Gomes } 11459f0caeb1SVinicius Costa Gomes 114693c3e8f5SAndrei Emeltchenko static void l2cap_start_connection(struct l2cap_chan *chan) 114793c3e8f5SAndrei Emeltchenko { 114893c3e8f5SAndrei Emeltchenko if (__amp_capable(chan)) { 114993c3e8f5SAndrei Emeltchenko BT_DBG("chan %p AMP capable: discover AMPs", chan); 115093c3e8f5SAndrei Emeltchenko a2mp_discover_amp(chan); 115193c3e8f5SAndrei Emeltchenko } else { 115293c3e8f5SAndrei Emeltchenko l2cap_send_conn_req(chan); 115393c3e8f5SAndrei Emeltchenko } 115493c3e8f5SAndrei Emeltchenko } 115593c3e8f5SAndrei Emeltchenko 1156fc7f8a7eSGustavo F. Padovan static void l2cap_do_start(struct l2cap_chan *chan) 11570a708f8fSGustavo F. Padovan { 11588c1d787bSGustavo F. Padovan struct l2cap_conn *conn = chan->conn; 11590a708f8fSGustavo F. Padovan 11609f0caeb1SVinicius Costa Gomes if (conn->hcon->type == LE_LINK) { 11619f0caeb1SVinicius Costa Gomes l2cap_chan_ready(chan); 11629f0caeb1SVinicius Costa Gomes return; 11639f0caeb1SVinicius Costa Gomes } 11649f0caeb1SVinicius Costa Gomes 11650a708f8fSGustavo F. Padovan if (conn->info_state & L2CAP_INFO_FEAT_MASK_REQ_SENT) { 11660a708f8fSGustavo F. Padovan if (!(conn->info_state & L2CAP_INFO_FEAT_MASK_REQ_DONE)) 11670a708f8fSGustavo F. Padovan return; 11680a708f8fSGustavo F. Padovan 1169d45fc423SGustavo F. Padovan if (l2cap_chan_check_security(chan) && 117093c3e8f5SAndrei Emeltchenko __l2cap_no_conn_pending(chan)) { 117193c3e8f5SAndrei Emeltchenko l2cap_start_connection(chan); 117293c3e8f5SAndrei Emeltchenko } 11730a708f8fSGustavo F. Padovan } else { 11740a708f8fSGustavo F. Padovan struct l2cap_info_req req; 1175ac73498cSAndrei Emeltchenko req.type = __constant_cpu_to_le16(L2CAP_IT_FEAT_MASK); 11760a708f8fSGustavo F. Padovan 11770a708f8fSGustavo F. Padovan conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_SENT; 11780a708f8fSGustavo F. Padovan conn->info_ident = l2cap_get_ident(conn); 11790a708f8fSGustavo F. Padovan 1180ba13ccd9SMarcel Holtmann schedule_delayed_work(&conn->info_timer, L2CAP_INFO_TIMEOUT); 11810a708f8fSGustavo F. Padovan 11822d792818SGustavo Padovan l2cap_send_cmd(conn, conn->info_ident, L2CAP_INFO_REQ, 11832d792818SGustavo Padovan sizeof(req), &req); 11840a708f8fSGustavo F. Padovan } 11850a708f8fSGustavo F. Padovan } 11860a708f8fSGustavo F. Padovan 11870a708f8fSGustavo F. Padovan static inline int l2cap_mode_supported(__u8 mode, __u32 feat_mask) 11880a708f8fSGustavo F. Padovan { 11890a708f8fSGustavo F. Padovan u32 local_feat_mask = l2cap_feat_mask; 11900a708f8fSGustavo F. Padovan if (!disable_ertm) 11910a708f8fSGustavo F. Padovan local_feat_mask |= L2CAP_FEAT_ERTM | L2CAP_FEAT_STREAMING; 11920a708f8fSGustavo F. Padovan 11930a708f8fSGustavo F. Padovan switch (mode) { 11940a708f8fSGustavo F. Padovan case L2CAP_MODE_ERTM: 11950a708f8fSGustavo F. Padovan return L2CAP_FEAT_ERTM & feat_mask & local_feat_mask; 11960a708f8fSGustavo F. Padovan case L2CAP_MODE_STREAMING: 11970a708f8fSGustavo F. Padovan return L2CAP_FEAT_STREAMING & feat_mask & local_feat_mask; 11980a708f8fSGustavo F. Padovan default: 11990a708f8fSGustavo F. Padovan return 0x00; 12000a708f8fSGustavo F. Padovan } 12010a708f8fSGustavo F. Padovan } 12020a708f8fSGustavo F. Padovan 12035e4e3972SAndrei Emeltchenko static void l2cap_send_disconn_req(struct l2cap_chan *chan, int err) 12040a708f8fSGustavo F. Padovan { 12056be36555SAndrei Emeltchenko struct sock *sk = chan->sk; 12065e4e3972SAndrei Emeltchenko struct l2cap_conn *conn = chan->conn; 12070a708f8fSGustavo F. Padovan struct l2cap_disconn_req req; 12080a708f8fSGustavo F. Padovan 12090a708f8fSGustavo F. Padovan if (!conn) 12100a708f8fSGustavo F. Padovan return; 12110a708f8fSGustavo F. Padovan 1212aad3d0e3SAndrei Emeltchenko if (chan->mode == L2CAP_MODE_ERTM && chan->state == BT_CONNECTED) { 12131a09bcb9SGustavo F. Padovan __clear_retrans_timer(chan); 12141a09bcb9SGustavo F. Padovan __clear_monitor_timer(chan); 12151a09bcb9SGustavo F. Padovan __clear_ack_timer(chan); 12160a708f8fSGustavo F. Padovan } 12170a708f8fSGustavo F. Padovan 1218416fa752SAndrei Emeltchenko if (chan->chan_type == L2CAP_CHAN_CONN_FIX_A2MP) { 1219d117773cSGustavo Padovan l2cap_state_change(chan, BT_DISCONN); 1220416fa752SAndrei Emeltchenko return; 1221416fa752SAndrei Emeltchenko } 1222416fa752SAndrei Emeltchenko 1223fe4128e0SGustavo F. Padovan req.dcid = cpu_to_le16(chan->dcid); 1224fe4128e0SGustavo F. Padovan req.scid = cpu_to_le16(chan->scid); 12252d792818SGustavo Padovan l2cap_send_cmd(conn, l2cap_get_ident(conn), L2CAP_DISCONN_REQ, 12262d792818SGustavo Padovan sizeof(req), &req); 12270a708f8fSGustavo F. Padovan 12286be36555SAndrei Emeltchenko lock_sock(sk); 12290e587be7SAndrei Emeltchenko __l2cap_state_change(chan, BT_DISCONN); 12302e0052e4SAndrei Emeltchenko __l2cap_chan_set_err(chan, err); 12316be36555SAndrei Emeltchenko release_sock(sk); 12320a708f8fSGustavo F. Padovan } 12330a708f8fSGustavo F. Padovan 12340a708f8fSGustavo F. Padovan /* ---- L2CAP connections ---- */ 12350a708f8fSGustavo F. Padovan static void l2cap_conn_start(struct l2cap_conn *conn) 12360a708f8fSGustavo F. Padovan { 12373df91ea2SAndrei Emeltchenko struct l2cap_chan *chan, *tmp; 12380a708f8fSGustavo F. Padovan 12390a708f8fSGustavo F. Padovan BT_DBG("conn %p", conn); 12400a708f8fSGustavo F. Padovan 12413df91ea2SAndrei Emeltchenko mutex_lock(&conn->chan_lock); 12420a708f8fSGustavo F. Padovan 12433df91ea2SAndrei Emeltchenko list_for_each_entry_safe(chan, tmp, &conn->chan_l, list) { 124448454079SGustavo F. Padovan struct sock *sk = chan->sk; 1245baa7e1faSGustavo F. Padovan 12466be36555SAndrei Emeltchenko l2cap_chan_lock(chan); 12470a708f8fSGustavo F. Padovan 1248715ec005SGustavo F. Padovan if (chan->chan_type != L2CAP_CHAN_CONN_ORIENTED) { 12496be36555SAndrei Emeltchenko l2cap_chan_unlock(chan); 12500a708f8fSGustavo F. Padovan continue; 12510a708f8fSGustavo F. Padovan } 12520a708f8fSGustavo F. Padovan 125389bc500eSGustavo F. Padovan if (chan->state == BT_CONNECT) { 1254d45fc423SGustavo F. Padovan if (!l2cap_chan_check_security(chan) || 1255b4450035SGustavo F. Padovan !__l2cap_no_conn_pending(chan)) { 12566be36555SAndrei Emeltchenko l2cap_chan_unlock(chan); 12570a708f8fSGustavo F. Padovan continue; 12580a708f8fSGustavo F. Padovan } 12590a708f8fSGustavo F. Padovan 1260c1360a1cSGustavo F. Padovan if (!l2cap_mode_supported(chan->mode, conn->feat_mask) 1261c1360a1cSGustavo F. Padovan && test_bit(CONF_STATE2_DEVICE, 1262c1360a1cSGustavo F. Padovan &chan->conf_state)) { 12630f852724SGustavo F. Padovan l2cap_chan_close(chan, ECONNRESET); 12646be36555SAndrei Emeltchenko l2cap_chan_unlock(chan); 12650a708f8fSGustavo F. Padovan continue; 12660a708f8fSGustavo F. Padovan } 12670a708f8fSGustavo F. Padovan 126893c3e8f5SAndrei Emeltchenko l2cap_start_connection(chan); 12690a708f8fSGustavo F. Padovan 127089bc500eSGustavo F. Padovan } else if (chan->state == BT_CONNECT2) { 12710a708f8fSGustavo F. Padovan struct l2cap_conn_rsp rsp; 12720a708f8fSGustavo F. Padovan char buf[128]; 1273fe4128e0SGustavo F. Padovan rsp.scid = cpu_to_le16(chan->dcid); 1274fe4128e0SGustavo F. Padovan rsp.dcid = cpu_to_le16(chan->scid); 12750a708f8fSGustavo F. Padovan 1276d45fc423SGustavo F. Padovan if (l2cap_chan_check_security(chan)) { 12776be36555SAndrei Emeltchenko lock_sock(sk); 1278c5daa683SGustavo Padovan if (test_bit(BT_SK_DEFER_SETUP, 1279c5daa683SGustavo Padovan &bt_sk(sk)->flags)) { 1280ac73498cSAndrei Emeltchenko rsp.result = __constant_cpu_to_le16(L2CAP_CR_PEND); 1281ac73498cSAndrei Emeltchenko rsp.status = __constant_cpu_to_le16(L2CAP_CS_AUTHOR_PEND); 12822dc4e510SGustavo Padovan chan->ops->defer(chan); 12830a708f8fSGustavo F. Padovan 12840a708f8fSGustavo F. Padovan } else { 12850e587be7SAndrei Emeltchenko __l2cap_state_change(chan, BT_CONFIG); 1286ac73498cSAndrei Emeltchenko rsp.result = __constant_cpu_to_le16(L2CAP_CR_SUCCESS); 1287ac73498cSAndrei Emeltchenko rsp.status = __constant_cpu_to_le16(L2CAP_CS_NO_INFO); 12880a708f8fSGustavo F. Padovan } 12896be36555SAndrei Emeltchenko release_sock(sk); 12900a708f8fSGustavo F. Padovan } else { 1291ac73498cSAndrei Emeltchenko rsp.result = __constant_cpu_to_le16(L2CAP_CR_PEND); 1292ac73498cSAndrei Emeltchenko rsp.status = __constant_cpu_to_le16(L2CAP_CS_AUTHEN_PEND); 12930a708f8fSGustavo F. Padovan } 12940a708f8fSGustavo F. Padovan 1295fc7f8a7eSGustavo F. Padovan l2cap_send_cmd(conn, chan->ident, L2CAP_CONN_RSP, 1296fc7f8a7eSGustavo F. Padovan sizeof(rsp), &rsp); 12970a708f8fSGustavo F. Padovan 1298c1360a1cSGustavo F. Padovan if (test_bit(CONF_REQ_SENT, &chan->conf_state) || 12990a708f8fSGustavo F. Padovan rsp.result != L2CAP_CR_SUCCESS) { 13006be36555SAndrei Emeltchenko l2cap_chan_unlock(chan); 13010a708f8fSGustavo F. Padovan continue; 13020a708f8fSGustavo F. Padovan } 13030a708f8fSGustavo F. Padovan 1304c1360a1cSGustavo F. Padovan set_bit(CONF_REQ_SENT, &chan->conf_state); 13050a708f8fSGustavo F. Padovan l2cap_send_cmd(conn, l2cap_get_ident(conn), L2CAP_CONF_REQ, 130673ffa904SGustavo F. Padovan l2cap_build_conf_req(chan, buf), buf); 130773ffa904SGustavo F. Padovan chan->num_conf_req++; 13080a708f8fSGustavo F. Padovan } 13090a708f8fSGustavo F. Padovan 13106be36555SAndrei Emeltchenko l2cap_chan_unlock(chan); 13110a708f8fSGustavo F. Padovan } 13120a708f8fSGustavo F. Padovan 13133df91ea2SAndrei Emeltchenko mutex_unlock(&conn->chan_lock); 13140a708f8fSGustavo F. Padovan } 13150a708f8fSGustavo F. Padovan 1316c2287681SIdo Yariv /* Find socket with cid and source/destination bdaddr. 1317b62f328bSVille Tervo * Returns closest match, locked. 1318b62f328bSVille Tervo */ 1319d9b88702SAndrei Emeltchenko static struct l2cap_chan *l2cap_global_chan_by_scid(int state, u16 cid, 1320c2287681SIdo Yariv bdaddr_t *src, 1321c2287681SIdo Yariv bdaddr_t *dst) 1322b62f328bSVille Tervo { 132323691d75SGustavo F. Padovan struct l2cap_chan *c, *c1 = NULL; 1324b62f328bSVille Tervo 132523691d75SGustavo F. Padovan read_lock(&chan_list_lock); 1326b62f328bSVille Tervo 132723691d75SGustavo F. Padovan list_for_each_entry(c, &chan_list, global_l) { 132823691d75SGustavo F. Padovan struct sock *sk = c->sk; 1329fe4128e0SGustavo F. Padovan 133089bc500eSGustavo F. Padovan if (state && c->state != state) 1331b62f328bSVille Tervo continue; 1332b62f328bSVille Tervo 133323691d75SGustavo F. Padovan if (c->scid == cid) { 1334c2287681SIdo Yariv int src_match, dst_match; 1335c2287681SIdo Yariv int src_any, dst_any; 1336c2287681SIdo Yariv 1337b62f328bSVille Tervo /* Exact match. */ 1338c2287681SIdo Yariv src_match = !bacmp(&bt_sk(sk)->src, src); 1339c2287681SIdo Yariv dst_match = !bacmp(&bt_sk(sk)->dst, dst); 1340c2287681SIdo Yariv if (src_match && dst_match) { 134123691d75SGustavo F. Padovan read_unlock(&chan_list_lock); 134223691d75SGustavo F. Padovan return c; 134323691d75SGustavo F. Padovan } 1344b62f328bSVille Tervo 1345b62f328bSVille Tervo /* Closest match */ 1346c2287681SIdo Yariv src_any = !bacmp(&bt_sk(sk)->src, BDADDR_ANY); 1347c2287681SIdo Yariv dst_any = !bacmp(&bt_sk(sk)->dst, BDADDR_ANY); 1348c2287681SIdo Yariv if ((src_match && dst_any) || (src_any && dst_match) || 1349c2287681SIdo Yariv (src_any && dst_any)) 135023691d75SGustavo F. Padovan c1 = c; 1351b62f328bSVille Tervo } 1352b62f328bSVille Tervo } 1353280f294fSGustavo F. Padovan 135423691d75SGustavo F. Padovan read_unlock(&chan_list_lock); 1355b62f328bSVille Tervo 135623691d75SGustavo F. Padovan return c1; 1357b62f328bSVille Tervo } 1358b62f328bSVille Tervo 1359b62f328bSVille Tervo static void l2cap_le_conn_ready(struct l2cap_conn *conn) 1360b62f328bSVille Tervo { 136160bac184SJohan Hedberg struct sock *parent; 136223691d75SGustavo F. Padovan struct l2cap_chan *chan, *pchan; 1363b62f328bSVille Tervo 1364b62f328bSVille Tervo BT_DBG(""); 1365b62f328bSVille Tervo 1366b62f328bSVille Tervo /* Check if we have socket listening on cid */ 1367073d1cf3SJohan Hedberg pchan = l2cap_global_chan_by_scid(BT_LISTEN, L2CAP_CID_ATT, 1368c2287681SIdo Yariv conn->src, conn->dst); 136923691d75SGustavo F. Padovan if (!pchan) 1370b62f328bSVille Tervo return; 1371b62f328bSVille Tervo 137244f3b0fbSJohan Hedberg /* Client ATT sockets should override the server one */ 137344f3b0fbSJohan Hedberg if (__l2cap_get_chan_by_dcid(conn, L2CAP_CID_ATT)) 137444f3b0fbSJohan Hedberg return; 137544f3b0fbSJohan Hedberg 137623691d75SGustavo F. Padovan parent = pchan->sk; 137723691d75SGustavo F. Padovan 1378aa2ac881SGustavo F. Padovan lock_sock(parent); 137962f3a2cfSGustavo F. Padovan 138080b98027SGustavo Padovan chan = pchan->ops->new_connection(pchan); 138180808e43SGustavo F. Padovan if (!chan) 1382b62f328bSVille Tervo goto clean; 1383b62f328bSVille Tervo 13849f22398cSJohan Hedberg chan->dcid = L2CAP_CID_ATT; 13859f22398cSJohan Hedberg 138660bac184SJohan Hedberg bacpy(&bt_sk(chan->sk)->src, conn->src); 138760bac184SJohan Hedberg bacpy(&bt_sk(chan->sk)->dst, conn->dst); 1388b62f328bSVille Tervo 138944f3b0fbSJohan Hedberg __l2cap_chan_add(conn, chan); 139048454079SGustavo F. Padovan 1391b62f328bSVille Tervo clean: 1392aa2ac881SGustavo F. Padovan release_sock(parent); 1393b62f328bSVille Tervo } 1394b62f328bSVille Tervo 13950a708f8fSGustavo F. Padovan static void l2cap_conn_ready(struct l2cap_conn *conn) 13960a708f8fSGustavo F. Padovan { 139748454079SGustavo F. Padovan struct l2cap_chan *chan; 1398cc110922SVinicius Costa Gomes struct hci_conn *hcon = conn->hcon; 13990a708f8fSGustavo F. Padovan 14000a708f8fSGustavo F. Padovan BT_DBG("conn %p", conn); 14010a708f8fSGustavo F. Padovan 1402d8729922SJohan Hedberg /* For outgoing pairing which doesn't necessarily have an 1403d8729922SJohan Hedberg * associated socket (e.g. mgmt_pair_device). 1404d8729922SJohan Hedberg */ 1405cc110922SVinicius Costa Gomes if (hcon->out && hcon->type == LE_LINK) 1406cc110922SVinicius Costa Gomes smp_conn_security(hcon, hcon->pending_sec_level); 1407160dc6acSVinicius Costa Gomes 14083df91ea2SAndrei Emeltchenko mutex_lock(&conn->chan_lock); 14090a708f8fSGustavo F. Padovan 141044f3b0fbSJohan Hedberg if (hcon->type == LE_LINK) 141144f3b0fbSJohan Hedberg l2cap_le_conn_ready(conn); 141244f3b0fbSJohan Hedberg 14133df91ea2SAndrei Emeltchenko list_for_each_entry(chan, &conn->chan_l, list) { 1414baa7e1faSGustavo F. Padovan 14156be36555SAndrei Emeltchenko l2cap_chan_lock(chan); 14160a708f8fSGustavo F. Padovan 1417416fa752SAndrei Emeltchenko if (chan->chan_type == L2CAP_CHAN_CONN_FIX_A2MP) { 1418416fa752SAndrei Emeltchenko l2cap_chan_unlock(chan); 1419416fa752SAndrei Emeltchenko continue; 1420416fa752SAndrei Emeltchenko } 1421416fa752SAndrei Emeltchenko 1422cc110922SVinicius Costa Gomes if (hcon->type == LE_LINK) { 1423cc110922SVinicius Costa Gomes if (smp_conn_security(hcon, chan->sec_level)) 1424cf4cd009SAndrei Emeltchenko l2cap_chan_ready(chan); 1425acd7d370SVille Tervo 142663128451SVinicius Costa Gomes } else if (chan->chan_type != L2CAP_CHAN_CONN_ORIENTED) { 14276be36555SAndrei Emeltchenko struct sock *sk = chan->sk; 1428c9b66675SGustavo F. Padovan __clear_chan_timer(chan); 14296be36555SAndrei Emeltchenko lock_sock(sk); 14300e587be7SAndrei Emeltchenko __l2cap_state_change(chan, BT_CONNECTED); 14310a708f8fSGustavo F. Padovan sk->sk_state_change(sk); 14326be36555SAndrei Emeltchenko release_sock(sk); 1433b501d6a1SAnderson Briglia 14341c244f79SGustavo Padovan } else if (chan->state == BT_CONNECT) { 1435fc7f8a7eSGustavo F. Padovan l2cap_do_start(chan); 14361c244f79SGustavo Padovan } 14370a708f8fSGustavo F. Padovan 14386be36555SAndrei Emeltchenko l2cap_chan_unlock(chan); 14390a708f8fSGustavo F. Padovan } 14400a708f8fSGustavo F. Padovan 14413df91ea2SAndrei Emeltchenko mutex_unlock(&conn->chan_lock); 14420a708f8fSGustavo F. Padovan } 14430a708f8fSGustavo F. Padovan 14440a708f8fSGustavo F. Padovan /* Notify sockets that we cannot guaranty reliability anymore */ 14450a708f8fSGustavo F. Padovan static void l2cap_conn_unreliable(struct l2cap_conn *conn, int err) 14460a708f8fSGustavo F. Padovan { 144748454079SGustavo F. Padovan struct l2cap_chan *chan; 14480a708f8fSGustavo F. Padovan 14490a708f8fSGustavo F. Padovan BT_DBG("conn %p", conn); 14500a708f8fSGustavo F. Padovan 14513df91ea2SAndrei Emeltchenko mutex_lock(&conn->chan_lock); 14520a708f8fSGustavo F. Padovan 14533df91ea2SAndrei Emeltchenko list_for_each_entry(chan, &conn->chan_l, list) { 1454ecf61bdbSAndrei Emeltchenko if (test_bit(FLAG_FORCE_RELIABLE, &chan->flags)) 14551d8b1fd5SGustavo Padovan l2cap_chan_set_err(chan, err); 14560a708f8fSGustavo F. Padovan } 14570a708f8fSGustavo F. Padovan 14583df91ea2SAndrei Emeltchenko mutex_unlock(&conn->chan_lock); 14590a708f8fSGustavo F. Padovan } 14600a708f8fSGustavo F. Padovan 1461f878fcadSGustavo F. Padovan static void l2cap_info_timeout(struct work_struct *work) 14620a708f8fSGustavo F. Padovan { 1463f878fcadSGustavo F. Padovan struct l2cap_conn *conn = container_of(work, struct l2cap_conn, 1464030013d8SGustavo F. Padovan info_timer.work); 14650a708f8fSGustavo F. Padovan 14660a708f8fSGustavo F. Padovan conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_DONE; 14670a708f8fSGustavo F. Padovan conn->info_ident = 0; 14680a708f8fSGustavo F. Padovan 14690a708f8fSGustavo F. Padovan l2cap_conn_start(conn); 14700a708f8fSGustavo F. Padovan } 14710a708f8fSGustavo F. Padovan 14722c8e1411SDavid Herrmann /* 14732c8e1411SDavid Herrmann * l2cap_user 14742c8e1411SDavid Herrmann * External modules can register l2cap_user objects on l2cap_conn. The ->probe 14752c8e1411SDavid Herrmann * callback is called during registration. The ->remove callback is called 14762c8e1411SDavid Herrmann * during unregistration. 14772c8e1411SDavid Herrmann * An l2cap_user object can either be explicitly unregistered or when the 14782c8e1411SDavid Herrmann * underlying l2cap_conn object is deleted. This guarantees that l2cap->hcon, 14792c8e1411SDavid Herrmann * l2cap->hchan, .. are valid as long as the remove callback hasn't been called. 14802c8e1411SDavid Herrmann * External modules must own a reference to the l2cap_conn object if they intend 14812c8e1411SDavid Herrmann * to call l2cap_unregister_user(). The l2cap_conn object might get destroyed at 14822c8e1411SDavid Herrmann * any time if they don't. 14832c8e1411SDavid Herrmann */ 14842c8e1411SDavid Herrmann 14852c8e1411SDavid Herrmann int l2cap_register_user(struct l2cap_conn *conn, struct l2cap_user *user) 14862c8e1411SDavid Herrmann { 14872c8e1411SDavid Herrmann struct hci_dev *hdev = conn->hcon->hdev; 14882c8e1411SDavid Herrmann int ret; 14892c8e1411SDavid Herrmann 14902c8e1411SDavid Herrmann /* We need to check whether l2cap_conn is registered. If it is not, we 14912c8e1411SDavid Herrmann * must not register the l2cap_user. l2cap_conn_del() is unregisters 14922c8e1411SDavid Herrmann * l2cap_conn objects, but doesn't provide its own locking. Instead, it 14932c8e1411SDavid Herrmann * relies on the parent hci_conn object to be locked. This itself relies 14942c8e1411SDavid Herrmann * on the hci_dev object to be locked. So we must lock the hci device 14952c8e1411SDavid Herrmann * here, too. */ 14962c8e1411SDavid Herrmann 14972c8e1411SDavid Herrmann hci_dev_lock(hdev); 14982c8e1411SDavid Herrmann 14992c8e1411SDavid Herrmann if (user->list.next || user->list.prev) { 15002c8e1411SDavid Herrmann ret = -EINVAL; 15012c8e1411SDavid Herrmann goto out_unlock; 15022c8e1411SDavid Herrmann } 15032c8e1411SDavid Herrmann 15042c8e1411SDavid Herrmann /* conn->hchan is NULL after l2cap_conn_del() was called */ 15052c8e1411SDavid Herrmann if (!conn->hchan) { 15062c8e1411SDavid Herrmann ret = -ENODEV; 15072c8e1411SDavid Herrmann goto out_unlock; 15082c8e1411SDavid Herrmann } 15092c8e1411SDavid Herrmann 15102c8e1411SDavid Herrmann ret = user->probe(conn, user); 15112c8e1411SDavid Herrmann if (ret) 15122c8e1411SDavid Herrmann goto out_unlock; 15132c8e1411SDavid Herrmann 15142c8e1411SDavid Herrmann list_add(&user->list, &conn->users); 15152c8e1411SDavid Herrmann ret = 0; 15162c8e1411SDavid Herrmann 15172c8e1411SDavid Herrmann out_unlock: 15182c8e1411SDavid Herrmann hci_dev_unlock(hdev); 15192c8e1411SDavid Herrmann return ret; 15202c8e1411SDavid Herrmann } 15212c8e1411SDavid Herrmann EXPORT_SYMBOL(l2cap_register_user); 15222c8e1411SDavid Herrmann 15232c8e1411SDavid Herrmann void l2cap_unregister_user(struct l2cap_conn *conn, struct l2cap_user *user) 15242c8e1411SDavid Herrmann { 15252c8e1411SDavid Herrmann struct hci_dev *hdev = conn->hcon->hdev; 15262c8e1411SDavid Herrmann 15272c8e1411SDavid Herrmann hci_dev_lock(hdev); 15282c8e1411SDavid Herrmann 15292c8e1411SDavid Herrmann if (!user->list.next || !user->list.prev) 15302c8e1411SDavid Herrmann goto out_unlock; 15312c8e1411SDavid Herrmann 15322c8e1411SDavid Herrmann list_del(&user->list); 15332c8e1411SDavid Herrmann user->list.next = NULL; 15342c8e1411SDavid Herrmann user->list.prev = NULL; 15352c8e1411SDavid Herrmann user->remove(conn, user); 15362c8e1411SDavid Herrmann 15372c8e1411SDavid Herrmann out_unlock: 15382c8e1411SDavid Herrmann hci_dev_unlock(hdev); 15392c8e1411SDavid Herrmann } 15402c8e1411SDavid Herrmann EXPORT_SYMBOL(l2cap_unregister_user); 15412c8e1411SDavid Herrmann 15422c8e1411SDavid Herrmann static void l2cap_unregister_all_users(struct l2cap_conn *conn) 15432c8e1411SDavid Herrmann { 15442c8e1411SDavid Herrmann struct l2cap_user *user; 15452c8e1411SDavid Herrmann 15462c8e1411SDavid Herrmann while (!list_empty(&conn->users)) { 15472c8e1411SDavid Herrmann user = list_first_entry(&conn->users, struct l2cap_user, list); 15482c8e1411SDavid Herrmann list_del(&user->list); 15492c8e1411SDavid Herrmann user->list.next = NULL; 15502c8e1411SDavid Herrmann user->list.prev = NULL; 15512c8e1411SDavid Herrmann user->remove(conn, user); 15522c8e1411SDavid Herrmann } 15532c8e1411SDavid Herrmann } 15542c8e1411SDavid Herrmann 15555d3de7dfSVinicius Costa Gomes static void l2cap_conn_del(struct hci_conn *hcon, int err) 15565d3de7dfSVinicius Costa Gomes { 15575d3de7dfSVinicius Costa Gomes struct l2cap_conn *conn = hcon->l2cap_data; 15585d3de7dfSVinicius Costa Gomes struct l2cap_chan *chan, *l; 15595d3de7dfSVinicius Costa Gomes 15605d3de7dfSVinicius Costa Gomes if (!conn) 15615d3de7dfSVinicius Costa Gomes return; 15625d3de7dfSVinicius Costa Gomes 15635d3de7dfSVinicius Costa Gomes BT_DBG("hcon %p conn %p, err %d", hcon, conn, err); 15645d3de7dfSVinicius Costa Gomes 15655d3de7dfSVinicius Costa Gomes kfree_skb(conn->rx_skb); 15665d3de7dfSVinicius Costa Gomes 15672c8e1411SDavid Herrmann l2cap_unregister_all_users(conn); 15682c8e1411SDavid Herrmann 15693df91ea2SAndrei Emeltchenko mutex_lock(&conn->chan_lock); 15703df91ea2SAndrei Emeltchenko 15715d3de7dfSVinicius Costa Gomes /* Kill channels */ 15725d3de7dfSVinicius Costa Gomes list_for_each_entry_safe(chan, l, &conn->chan_l, list) { 157361d6ef3eSMat Martineau l2cap_chan_hold(chan); 15746be36555SAndrei Emeltchenko l2cap_chan_lock(chan); 15756be36555SAndrei Emeltchenko 15765d3de7dfSVinicius Costa Gomes l2cap_chan_del(chan, err); 15776be36555SAndrei Emeltchenko 15786be36555SAndrei Emeltchenko l2cap_chan_unlock(chan); 15796be36555SAndrei Emeltchenko 158080b98027SGustavo Padovan chan->ops->close(chan); 158161d6ef3eSMat Martineau l2cap_chan_put(chan); 15825d3de7dfSVinicius Costa Gomes } 15835d3de7dfSVinicius Costa Gomes 15843df91ea2SAndrei Emeltchenko mutex_unlock(&conn->chan_lock); 15853df91ea2SAndrei Emeltchenko 158673d80debSLuiz Augusto von Dentz hci_chan_del(conn->hchan); 158773d80debSLuiz Augusto von Dentz 15885d3de7dfSVinicius Costa Gomes if (conn->info_state & L2CAP_INFO_FEAT_MASK_REQ_SENT) 1589127074bfSUlisses Furquim cancel_delayed_work_sync(&conn->info_timer); 15905d3de7dfSVinicius Costa Gomes 159151a8efd7SJohan Hedberg if (test_and_clear_bit(HCI_CONN_LE_SMP_PEND, &hcon->flags)) { 1592127074bfSUlisses Furquim cancel_delayed_work_sync(&conn->security_timer); 15938aab4757SVinicius Costa Gomes smp_chan_destroy(conn); 1594d26a2345SVinicius Costa Gomes } 15955d3de7dfSVinicius Costa Gomes 15965d3de7dfSVinicius Costa Gomes hcon->l2cap_data = NULL; 15979c903e37SDavid Herrmann conn->hchan = NULL; 15989c903e37SDavid Herrmann l2cap_conn_put(conn); 15995d3de7dfSVinicius Costa Gomes } 16005d3de7dfSVinicius Costa Gomes 16016c9d42a1SGustavo F. Padovan static void security_timeout(struct work_struct *work) 16025d3de7dfSVinicius Costa Gomes { 16036c9d42a1SGustavo F. Padovan struct l2cap_conn *conn = container_of(work, struct l2cap_conn, 16046c9d42a1SGustavo F. Padovan security_timer.work); 16055d3de7dfSVinicius Costa Gomes 1606d06cc416SJohan Hedberg BT_DBG("conn %p", conn); 1607d06cc416SJohan Hedberg 1608d06cc416SJohan Hedberg if (test_and_clear_bit(HCI_CONN_LE_SMP_PEND, &conn->hcon->flags)) { 1609d06cc416SJohan Hedberg smp_chan_destroy(conn); 16105d3de7dfSVinicius Costa Gomes l2cap_conn_del(conn->hcon, ETIMEDOUT); 16115d3de7dfSVinicius Costa Gomes } 1612d06cc416SJohan Hedberg } 16135d3de7dfSVinicius Costa Gomes 1614baf43251SClaudio Takahasi static struct l2cap_conn *l2cap_conn_add(struct hci_conn *hcon) 16150a708f8fSGustavo F. Padovan { 16160a708f8fSGustavo F. Padovan struct l2cap_conn *conn = hcon->l2cap_data; 161773d80debSLuiz Augusto von Dentz struct hci_chan *hchan; 16180a708f8fSGustavo F. Padovan 1619baf43251SClaudio Takahasi if (conn) 16200a708f8fSGustavo F. Padovan return conn; 16210a708f8fSGustavo F. Padovan 162273d80debSLuiz Augusto von Dentz hchan = hci_chan_create(hcon); 162373d80debSLuiz Augusto von Dentz if (!hchan) 16240a708f8fSGustavo F. Padovan return NULL; 16250a708f8fSGustavo F. Padovan 16268bcde1f2SGustavo Padovan conn = kzalloc(sizeof(struct l2cap_conn), GFP_KERNEL); 162773d80debSLuiz Augusto von Dentz if (!conn) { 162873d80debSLuiz Augusto von Dentz hci_chan_del(hchan); 162973d80debSLuiz Augusto von Dentz return NULL; 163073d80debSLuiz Augusto von Dentz } 163173d80debSLuiz Augusto von Dentz 16329c903e37SDavid Herrmann kref_init(&conn->ref); 16330a708f8fSGustavo F. Padovan hcon->l2cap_data = conn; 16340a708f8fSGustavo F. Padovan conn->hcon = hcon; 16359c903e37SDavid Herrmann hci_conn_get(conn->hcon); 163673d80debSLuiz Augusto von Dentz conn->hchan = hchan; 16370a708f8fSGustavo F. Padovan 163873d80debSLuiz Augusto von Dentz BT_DBG("hcon %p conn %p hchan %p", hcon, conn, hchan); 16390a708f8fSGustavo F. Padovan 1640dcc042d5SAndrei Emeltchenko switch (hcon->type) { 1641dcc042d5SAndrei Emeltchenko case LE_LINK: 1642dcc042d5SAndrei Emeltchenko if (hcon->hdev->le_mtu) { 1643acd7d370SVille Tervo conn->mtu = hcon->hdev->le_mtu; 1644dcc042d5SAndrei Emeltchenko break; 1645dcc042d5SAndrei Emeltchenko } 1646dcc042d5SAndrei Emeltchenko /* fall through */ 1647dcc042d5SAndrei Emeltchenko default: 16480a708f8fSGustavo F. Padovan conn->mtu = hcon->hdev->acl_mtu; 1649dcc042d5SAndrei Emeltchenko break; 1650dcc042d5SAndrei Emeltchenko } 1651acd7d370SVille Tervo 16520a708f8fSGustavo F. Padovan conn->src = &hcon->hdev->bdaddr; 16530a708f8fSGustavo F. Padovan conn->dst = &hcon->dst; 16540a708f8fSGustavo F. Padovan 16550a708f8fSGustavo F. Padovan conn->feat_mask = 0; 16560a708f8fSGustavo F. Padovan 1657848566b3SMarcel Holtmann if (hcon->type == ACL_LINK) 1658848566b3SMarcel Holtmann conn->hs_enabled = test_bit(HCI_HS_ENABLED, 1659848566b3SMarcel Holtmann &hcon->hdev->dev_flags); 1660848566b3SMarcel Holtmann 16610a708f8fSGustavo F. Padovan spin_lock_init(&conn->lock); 16623df91ea2SAndrei Emeltchenko mutex_init(&conn->chan_lock); 1663baa7e1faSGustavo F. Padovan 1664baa7e1faSGustavo F. Padovan INIT_LIST_HEAD(&conn->chan_l); 16652c8e1411SDavid Herrmann INIT_LIST_HEAD(&conn->users); 16660a708f8fSGustavo F. Padovan 16675d3de7dfSVinicius Costa Gomes if (hcon->type == LE_LINK) 16686c9d42a1SGustavo F. Padovan INIT_DELAYED_WORK(&conn->security_timer, security_timeout); 16695d3de7dfSVinicius Costa Gomes else 1670030013d8SGustavo F. Padovan INIT_DELAYED_WORK(&conn->info_timer, l2cap_info_timeout); 16710a708f8fSGustavo F. Padovan 16729f5a0d7bSAndrei Emeltchenko conn->disc_reason = HCI_ERROR_REMOTE_USER_TERM; 16730a708f8fSGustavo F. Padovan 16740a708f8fSGustavo F. Padovan return conn; 16750a708f8fSGustavo F. Padovan } 16760a708f8fSGustavo F. Padovan 16779c903e37SDavid Herrmann static void l2cap_conn_free(struct kref *ref) 16789c903e37SDavid Herrmann { 16799c903e37SDavid Herrmann struct l2cap_conn *conn = container_of(ref, struct l2cap_conn, ref); 16809c903e37SDavid Herrmann 16819c903e37SDavid Herrmann hci_conn_put(conn->hcon); 16829c903e37SDavid Herrmann kfree(conn); 16839c903e37SDavid Herrmann } 16849c903e37SDavid Herrmann 16859c903e37SDavid Herrmann void l2cap_conn_get(struct l2cap_conn *conn) 16869c903e37SDavid Herrmann { 16879c903e37SDavid Herrmann kref_get(&conn->ref); 16889c903e37SDavid Herrmann } 16899c903e37SDavid Herrmann EXPORT_SYMBOL(l2cap_conn_get); 16909c903e37SDavid Herrmann 16919c903e37SDavid Herrmann void l2cap_conn_put(struct l2cap_conn *conn) 16929c903e37SDavid Herrmann { 16939c903e37SDavid Herrmann kref_put(&conn->ref, l2cap_conn_free); 16949c903e37SDavid Herrmann } 16959c903e37SDavid Herrmann EXPORT_SYMBOL(l2cap_conn_put); 16969c903e37SDavid Herrmann 16970a708f8fSGustavo F. Padovan /* ---- Socket interface ---- */ 16980a708f8fSGustavo F. Padovan 1699c2287681SIdo Yariv /* Find socket with psm and source / destination bdaddr. 17000a708f8fSGustavo F. Padovan * Returns closest match. 17010a708f8fSGustavo F. Padovan */ 1702c2287681SIdo Yariv static struct l2cap_chan *l2cap_global_chan_by_psm(int state, __le16 psm, 1703c2287681SIdo Yariv bdaddr_t *src, 1704c2287681SIdo Yariv bdaddr_t *dst) 17050a708f8fSGustavo F. Padovan { 170623691d75SGustavo F. Padovan struct l2cap_chan *c, *c1 = NULL; 17070a708f8fSGustavo F. Padovan 170823691d75SGustavo F. Padovan read_lock(&chan_list_lock); 17090a708f8fSGustavo F. Padovan 171023691d75SGustavo F. Padovan list_for_each_entry(c, &chan_list, global_l) { 171123691d75SGustavo F. Padovan struct sock *sk = c->sk; 1712fe4128e0SGustavo F. Padovan 171389bc500eSGustavo F. Padovan if (state && c->state != state) 17140a708f8fSGustavo F. Padovan continue; 17150a708f8fSGustavo F. Padovan 171623691d75SGustavo F. Padovan if (c->psm == psm) { 1717c2287681SIdo Yariv int src_match, dst_match; 1718c2287681SIdo Yariv int src_any, dst_any; 1719c2287681SIdo Yariv 17200a708f8fSGustavo F. Padovan /* Exact match. */ 1721c2287681SIdo Yariv src_match = !bacmp(&bt_sk(sk)->src, src); 1722c2287681SIdo Yariv dst_match = !bacmp(&bt_sk(sk)->dst, dst); 1723c2287681SIdo Yariv if (src_match && dst_match) { 1724a7567b20SJohannes Berg read_unlock(&chan_list_lock); 172523691d75SGustavo F. Padovan return c; 172623691d75SGustavo F. Padovan } 17270a708f8fSGustavo F. Padovan 17280a708f8fSGustavo F. Padovan /* Closest match */ 1729c2287681SIdo Yariv src_any = !bacmp(&bt_sk(sk)->src, BDADDR_ANY); 1730c2287681SIdo Yariv dst_any = !bacmp(&bt_sk(sk)->dst, BDADDR_ANY); 1731c2287681SIdo Yariv if ((src_match && dst_any) || (src_any && dst_match) || 1732c2287681SIdo Yariv (src_any && dst_any)) 173323691d75SGustavo F. Padovan c1 = c; 17340a708f8fSGustavo F. Padovan } 17350a708f8fSGustavo F. Padovan } 17360a708f8fSGustavo F. Padovan 173723691d75SGustavo F. Padovan read_unlock(&chan_list_lock); 17380a708f8fSGustavo F. Padovan 173923691d75SGustavo F. Padovan return c1; 17400a708f8fSGustavo F. Padovan } 17410a708f8fSGustavo F. Padovan 17428e9f9892SAndre Guedes int l2cap_chan_connect(struct l2cap_chan *chan, __le16 psm, u16 cid, 17438e9f9892SAndre Guedes bdaddr_t *dst, u8 dst_type) 17440a708f8fSGustavo F. Padovan { 17455d41ce1dSGustavo F. Padovan struct sock *sk = chan->sk; 17460a708f8fSGustavo F. Padovan bdaddr_t *src = &bt_sk(sk)->src; 17470a708f8fSGustavo F. Padovan struct l2cap_conn *conn; 17480a708f8fSGustavo F. Padovan struct hci_conn *hcon; 17490a708f8fSGustavo F. Padovan struct hci_dev *hdev; 17500a708f8fSGustavo F. Padovan __u8 auth_type; 17510a708f8fSGustavo F. Padovan int err; 17520a708f8fSGustavo F. Padovan 17536ed93dc6SAndrei Emeltchenko BT_DBG("%pMR -> %pMR (type %u) psm 0x%2.2x", src, dst, 1754ab19516aSSyam Sidhardhan dst_type, __le16_to_cpu(psm)); 17550a708f8fSGustavo F. Padovan 17560a708f8fSGustavo F. Padovan hdev = hci_get_route(dst, src); 17570a708f8fSGustavo F. Padovan if (!hdev) 17580a708f8fSGustavo F. Padovan return -EHOSTUNREACH; 17590a708f8fSGustavo F. Padovan 176009fd0de5SGustavo F. Padovan hci_dev_lock(hdev); 17610a708f8fSGustavo F. Padovan 17626be36555SAndrei Emeltchenko l2cap_chan_lock(chan); 176303a00194SGustavo F. Padovan 176403a00194SGustavo F. Padovan /* PSM must be odd and lsb of upper byte must be 0 */ 176503a00194SGustavo F. Padovan if ((__le16_to_cpu(psm) & 0x0101) != 0x0001 && !cid && 176603a00194SGustavo F. Padovan chan->chan_type != L2CAP_CHAN_RAW) { 176703a00194SGustavo F. Padovan err = -EINVAL; 176803a00194SGustavo F. Padovan goto done; 176903a00194SGustavo F. Padovan } 177003a00194SGustavo F. Padovan 177103a00194SGustavo F. Padovan if (chan->chan_type == L2CAP_CHAN_CONN_ORIENTED && !(psm || cid)) { 177203a00194SGustavo F. Padovan err = -EINVAL; 177303a00194SGustavo F. Padovan goto done; 177403a00194SGustavo F. Padovan } 177503a00194SGustavo F. Padovan 177603a00194SGustavo F. Padovan switch (chan->mode) { 177703a00194SGustavo F. Padovan case L2CAP_MODE_BASIC: 177803a00194SGustavo F. Padovan break; 177903a00194SGustavo F. Padovan case L2CAP_MODE_ERTM: 178003a00194SGustavo F. Padovan case L2CAP_MODE_STREAMING: 178103a00194SGustavo F. Padovan if (!disable_ertm) 178203a00194SGustavo F. Padovan break; 178303a00194SGustavo F. Padovan /* fall through */ 178403a00194SGustavo F. Padovan default: 178503a00194SGustavo F. Padovan err = -ENOTSUPP; 178603a00194SGustavo F. Padovan goto done; 178703a00194SGustavo F. Padovan } 178803a00194SGustavo F. Padovan 17890797e01dSGustavo Padovan switch (chan->state) { 179003a00194SGustavo F. Padovan case BT_CONNECT: 179103a00194SGustavo F. Padovan case BT_CONNECT2: 179203a00194SGustavo F. Padovan case BT_CONFIG: 179303a00194SGustavo F. Padovan /* Already connecting */ 179403a00194SGustavo F. Padovan err = 0; 179503a00194SGustavo F. Padovan goto done; 179603a00194SGustavo F. Padovan 179703a00194SGustavo F. Padovan case BT_CONNECTED: 179803a00194SGustavo F. Padovan /* Already connected */ 179903a00194SGustavo F. Padovan err = -EISCONN; 180003a00194SGustavo F. Padovan goto done; 180103a00194SGustavo F. Padovan 180203a00194SGustavo F. Padovan case BT_OPEN: 180303a00194SGustavo F. Padovan case BT_BOUND: 180403a00194SGustavo F. Padovan /* Can connect */ 180503a00194SGustavo F. Padovan break; 180603a00194SGustavo F. Padovan 180703a00194SGustavo F. Padovan default: 180803a00194SGustavo F. Padovan err = -EBADFD; 180903a00194SGustavo F. Padovan goto done; 181003a00194SGustavo F. Padovan } 181103a00194SGustavo F. Padovan 181203a00194SGustavo F. Padovan /* Set destination address and psm */ 18130797e01dSGustavo Padovan lock_sock(sk); 18149219b2a0SGustavo F. Padovan bacpy(&bt_sk(sk)->dst, dst); 18156be36555SAndrei Emeltchenko release_sock(sk); 18166be36555SAndrei Emeltchenko 181703a00194SGustavo F. Padovan chan->psm = psm; 181803a00194SGustavo F. Padovan chan->dcid = cid; 18190a708f8fSGustavo F. Padovan 18204343478fSGustavo F. Padovan auth_type = l2cap_get_auth_type(chan); 18210a708f8fSGustavo F. Padovan 1822f224ca5fSJohan Hedberg if (bdaddr_type_is_le(dst_type)) 18238e9f9892SAndre Guedes hcon = hci_connect(hdev, LE_LINK, dst, dst_type, 18244343478fSGustavo F. Padovan chan->sec_level, auth_type); 1825acd7d370SVille Tervo else 18268e9f9892SAndre Guedes hcon = hci_connect(hdev, ACL_LINK, dst, dst_type, 18274343478fSGustavo F. Padovan chan->sec_level, auth_type); 1828acd7d370SVille Tervo 182930e76272SVille Tervo if (IS_ERR(hcon)) { 183030e76272SVille Tervo err = PTR_ERR(hcon); 18310a708f8fSGustavo F. Padovan goto done; 183230e76272SVille Tervo } 18330a708f8fSGustavo F. Padovan 1834baf43251SClaudio Takahasi conn = l2cap_conn_add(hcon); 18350a708f8fSGustavo F. Padovan if (!conn) { 183676a68ba0SDavid Herrmann hci_conn_drop(hcon); 183730e76272SVille Tervo err = -ENOMEM; 18380a708f8fSGustavo F. Padovan goto done; 18390a708f8fSGustavo F. Padovan } 18400a708f8fSGustavo F. Padovan 1841141d5706SJohan Hedberg if (cid && __l2cap_get_chan_by_dcid(conn, cid)) { 184276a68ba0SDavid Herrmann hci_conn_drop(hcon); 1843141d5706SJohan Hedberg err = -EBUSY; 18449f0caeb1SVinicius Costa Gomes goto done; 18459f0caeb1SVinicius Costa Gomes } 18469f0caeb1SVinicius Costa Gomes 18470a708f8fSGustavo F. Padovan /* Update source addr of the socket */ 18480a708f8fSGustavo F. Padovan bacpy(src, conn->src); 18490a708f8fSGustavo F. Padovan 18506be36555SAndrei Emeltchenko l2cap_chan_unlock(chan); 185148454079SGustavo F. Padovan l2cap_chan_add(conn, chan); 18526be36555SAndrei Emeltchenko l2cap_chan_lock(chan); 185348454079SGustavo F. Padovan 18545ee9891dSJohan Hedberg /* l2cap_chan_add takes its own ref so we can drop this one */ 18555ee9891dSJohan Hedberg hci_conn_drop(hcon); 18565ee9891dSJohan Hedberg 18576be36555SAndrei Emeltchenko l2cap_state_change(chan, BT_CONNECT); 1858c9b66675SGustavo F. Padovan __set_chan_timer(chan, sk->sk_sndtimeo); 18590a708f8fSGustavo F. Padovan 18600a708f8fSGustavo F. Padovan if (hcon->state == BT_CONNECTED) { 1861715ec005SGustavo F. Padovan if (chan->chan_type != L2CAP_CHAN_CONN_ORIENTED) { 1862c9b66675SGustavo F. Padovan __clear_chan_timer(chan); 1863d45fc423SGustavo F. Padovan if (l2cap_chan_check_security(chan)) 18646be36555SAndrei Emeltchenko l2cap_state_change(chan, BT_CONNECTED); 18650a708f8fSGustavo F. Padovan } else 1866fc7f8a7eSGustavo F. Padovan l2cap_do_start(chan); 18670a708f8fSGustavo F. Padovan } 18680a708f8fSGustavo F. Padovan 186930e76272SVille Tervo err = 0; 187030e76272SVille Tervo 18710a708f8fSGustavo F. Padovan done: 18726be36555SAndrei Emeltchenko l2cap_chan_unlock(chan); 187309fd0de5SGustavo F. Padovan hci_dev_unlock(hdev); 18740a708f8fSGustavo F. Padovan hci_dev_put(hdev); 18750a708f8fSGustavo F. Padovan return err; 18760a708f8fSGustavo F. Padovan } 18770a708f8fSGustavo F. Padovan 1878dcba0dbaSGustavo F. Padovan int __l2cap_wait_ack(struct sock *sk) 18790a708f8fSGustavo F. Padovan { 18808c1d787bSGustavo F. Padovan struct l2cap_chan *chan = l2cap_pi(sk)->chan; 18810a708f8fSGustavo F. Padovan DECLARE_WAITQUEUE(wait, current); 18820a708f8fSGustavo F. Padovan int err = 0; 18830a708f8fSGustavo F. Padovan int timeo = HZ/5; 18840a708f8fSGustavo F. Padovan 18850a708f8fSGustavo F. Padovan add_wait_queue(sk_sleep(sk), &wait); 18860a708f8fSGustavo F. Padovan set_current_state(TASK_INTERRUPTIBLE); 1887a71a0cf4SPeter Hurley while (chan->unacked_frames > 0 && chan->conn) { 18880a708f8fSGustavo F. Padovan if (!timeo) 18890a708f8fSGustavo F. Padovan timeo = HZ/5; 18900a708f8fSGustavo F. Padovan 18910a708f8fSGustavo F. Padovan if (signal_pending(current)) { 18920a708f8fSGustavo F. Padovan err = sock_intr_errno(timeo); 18930a708f8fSGustavo F. Padovan break; 18940a708f8fSGustavo F. Padovan } 18950a708f8fSGustavo F. Padovan 18960a708f8fSGustavo F. Padovan release_sock(sk); 18970a708f8fSGustavo F. Padovan timeo = schedule_timeout(timeo); 18980a708f8fSGustavo F. Padovan lock_sock(sk); 1899a71a0cf4SPeter Hurley set_current_state(TASK_INTERRUPTIBLE); 19000a708f8fSGustavo F. Padovan 19010a708f8fSGustavo F. Padovan err = sock_error(sk); 19020a708f8fSGustavo F. Padovan if (err) 19030a708f8fSGustavo F. Padovan break; 19040a708f8fSGustavo F. Padovan } 19050a708f8fSGustavo F. Padovan set_current_state(TASK_RUNNING); 19060a708f8fSGustavo F. Padovan remove_wait_queue(sk_sleep(sk), &wait); 19070a708f8fSGustavo F. Padovan return err; 19080a708f8fSGustavo F. Padovan } 19090a708f8fSGustavo F. Padovan 1910721c4181SGustavo F. Padovan static void l2cap_monitor_timeout(struct work_struct *work) 19110a708f8fSGustavo F. Padovan { 1912721c4181SGustavo F. Padovan struct l2cap_chan *chan = container_of(work, struct l2cap_chan, 1913721c4181SGustavo F. Padovan monitor_timer.work); 19140a708f8fSGustavo F. Padovan 1915525cd185SGustavo F. Padovan BT_DBG("chan %p", chan); 19160a708f8fSGustavo F. Padovan 19176be36555SAndrei Emeltchenko l2cap_chan_lock(chan); 19186be36555SAndrei Emeltchenko 191980909e04SMat Martineau if (!chan->conn) { 19206be36555SAndrei Emeltchenko l2cap_chan_unlock(chan); 19218d7e1c7fSAndrei Emeltchenko l2cap_chan_put(chan); 19220a708f8fSGustavo F. Padovan return; 19230a708f8fSGustavo F. Padovan } 19240a708f8fSGustavo F. Padovan 1925401bb1f7SAndrei Emeltchenko l2cap_tx(chan, NULL, NULL, L2CAP_EV_MONITOR_TO); 19260a708f8fSGustavo F. Padovan 19276be36555SAndrei Emeltchenko l2cap_chan_unlock(chan); 19288d7e1c7fSAndrei Emeltchenko l2cap_chan_put(chan); 19290a708f8fSGustavo F. Padovan } 19300a708f8fSGustavo F. Padovan 1931721c4181SGustavo F. Padovan static void l2cap_retrans_timeout(struct work_struct *work) 19320a708f8fSGustavo F. Padovan { 1933721c4181SGustavo F. Padovan struct l2cap_chan *chan = container_of(work, struct l2cap_chan, 1934721c4181SGustavo F. Padovan retrans_timer.work); 19350a708f8fSGustavo F. Padovan 193649208c9cSGustavo F. Padovan BT_DBG("chan %p", chan); 19370a708f8fSGustavo F. Padovan 19386be36555SAndrei Emeltchenko l2cap_chan_lock(chan); 19396be36555SAndrei Emeltchenko 194080909e04SMat Martineau if (!chan->conn) { 194180909e04SMat Martineau l2cap_chan_unlock(chan); 194280909e04SMat Martineau l2cap_chan_put(chan); 194380909e04SMat Martineau return; 194480909e04SMat Martineau } 19450a708f8fSGustavo F. Padovan 1946401bb1f7SAndrei Emeltchenko l2cap_tx(chan, NULL, NULL, L2CAP_EV_RETRANS_TO); 19476be36555SAndrei Emeltchenko l2cap_chan_unlock(chan); 19488d7e1c7fSAndrei Emeltchenko l2cap_chan_put(chan); 19490a708f8fSGustavo F. Padovan } 19500a708f8fSGustavo F. Padovan 1951d660366dSGustavo Padovan static void l2cap_streaming_send(struct l2cap_chan *chan, 19523733937dSMat Martineau struct sk_buff_head *skbs) 19530a708f8fSGustavo F. Padovan { 19540a708f8fSGustavo F. Padovan struct sk_buff *skb; 19553733937dSMat Martineau struct l2cap_ctrl *control; 19560a708f8fSGustavo F. Padovan 19573733937dSMat Martineau BT_DBG("chan %p, skbs %p", chan, skbs); 19583733937dSMat Martineau 1959b99e13adSMat Martineau if (__chan_is_moving(chan)) 1960b99e13adSMat Martineau return; 1961b99e13adSMat Martineau 19623733937dSMat Martineau skb_queue_splice_tail_init(skbs, &chan->tx_q); 19633733937dSMat Martineau 19643733937dSMat Martineau while (!skb_queue_empty(&chan->tx_q)) { 19653733937dSMat Martineau 19663733937dSMat Martineau skb = skb_dequeue(&chan->tx_q); 19673733937dSMat Martineau 19683733937dSMat Martineau bt_cb(skb)->control.retries = 1; 19693733937dSMat Martineau control = &bt_cb(skb)->control; 19703733937dSMat Martineau 19713733937dSMat Martineau control->reqseq = 0; 19723733937dSMat Martineau control->txseq = chan->next_tx_seq; 19733733937dSMat Martineau 19743733937dSMat Martineau __pack_control(chan, control, skb); 19750a708f8fSGustavo F. Padovan 197647d1ec61SGustavo F. Padovan if (chan->fcs == L2CAP_FCS_CRC16) { 19773733937dSMat Martineau u16 fcs = crc16(0, (u8 *) skb->data, skb->len); 19783733937dSMat Martineau put_unaligned_le16(fcs, skb_put(skb, L2CAP_FCS_SIZE)); 19790a708f8fSGustavo F. Padovan } 19800a708f8fSGustavo F. Padovan 19814343478fSGustavo F. Padovan l2cap_do_send(chan, skb); 19820a708f8fSGustavo F. Padovan 1983b4400672SAndrei Emeltchenko BT_DBG("Sent txseq %u", control->txseq); 19843733937dSMat Martineau 1985836be934SAndrei Emeltchenko chan->next_tx_seq = __next_seq(chan, chan->next_tx_seq); 19863733937dSMat Martineau chan->frames_sent++; 19870a708f8fSGustavo F. Padovan } 19880a708f8fSGustavo F. Padovan } 19890a708f8fSGustavo F. Padovan 199067c9e840SSzymon Janc static int l2cap_ertm_send(struct l2cap_chan *chan) 19910a708f8fSGustavo F. Padovan { 19920a708f8fSGustavo F. Padovan struct sk_buff *skb, *tx_skb; 199318a48e76SMat Martineau struct l2cap_ctrl *control; 199418a48e76SMat Martineau int sent = 0; 199518a48e76SMat Martineau 199618a48e76SMat Martineau BT_DBG("chan %p", chan); 19970a708f8fSGustavo F. Padovan 199889bc500eSGustavo F. Padovan if (chan->state != BT_CONNECTED) 19990a708f8fSGustavo F. Padovan return -ENOTCONN; 20000a708f8fSGustavo F. Padovan 200194122bbeSMat Martineau if (test_bit(CONN_REMOTE_BUSY, &chan->conn_state)) 200294122bbeSMat Martineau return 0; 200394122bbeSMat Martineau 2004b99e13adSMat Martineau if (__chan_is_moving(chan)) 2005b99e13adSMat Martineau return 0; 2006b99e13adSMat Martineau 200718a48e76SMat Martineau while (chan->tx_send_head && 200818a48e76SMat Martineau chan->unacked_frames < chan->remote_tx_win && 200918a48e76SMat Martineau chan->tx_state == L2CAP_TX_STATE_XMIT) { 20100a708f8fSGustavo F. Padovan 201118a48e76SMat Martineau skb = chan->tx_send_head; 20120a708f8fSGustavo F. Padovan 201318a48e76SMat Martineau bt_cb(skb)->control.retries = 1; 201418a48e76SMat Martineau control = &bt_cb(skb)->control; 20150a708f8fSGustavo F. Padovan 2016e2ab4353SGustavo F. Padovan if (test_and_clear_bit(CONN_SEND_FBIT, &chan->conn_state)) 201718a48e76SMat Martineau control->final = 1; 2018e2ab4353SGustavo F. Padovan 201918a48e76SMat Martineau control->reqseq = chan->buffer_seq; 202018a48e76SMat Martineau chan->last_acked_seq = chan->buffer_seq; 202118a48e76SMat Martineau control->txseq = chan->next_tx_seq; 20220a708f8fSGustavo F. Padovan 202318a48e76SMat Martineau __pack_control(chan, control, skb); 20240a708f8fSGustavo F. Padovan 202547d1ec61SGustavo F. Padovan if (chan->fcs == L2CAP_FCS_CRC16) { 202618a48e76SMat Martineau u16 fcs = crc16(0, (u8 *) skb->data, skb->len); 202718a48e76SMat Martineau put_unaligned_le16(fcs, skb_put(skb, L2CAP_FCS_SIZE)); 20280a708f8fSGustavo F. Padovan } 20290a708f8fSGustavo F. Padovan 203018a48e76SMat Martineau /* Clone after data has been modified. Data is assumed to be 203118a48e76SMat Martineau read-only (for locking purposes) on cloned sk_buffs. 203218a48e76SMat Martineau */ 203318a48e76SMat Martineau tx_skb = skb_clone(skb, GFP_KERNEL); 203418a48e76SMat Martineau 203518a48e76SMat Martineau if (!tx_skb) 203618a48e76SMat Martineau break; 20370a708f8fSGustavo F. Padovan 20381a09bcb9SGustavo F. Padovan __set_retrans_timer(chan); 20390a708f8fSGustavo F. Padovan 2040836be934SAndrei Emeltchenko chan->next_tx_seq = __next_seq(chan, chan->next_tx_seq); 20416a026610SGustavo F. Padovan chan->unacked_frames++; 20426a026610SGustavo F. Padovan chan->frames_sent++; 204318a48e76SMat Martineau sent++; 20440a708f8fSGustavo F. Padovan 204558d35f87SGustavo F. Padovan if (skb_queue_is_last(&chan->tx_q, skb)) 204658d35f87SGustavo F. Padovan chan->tx_send_head = NULL; 20470a708f8fSGustavo F. Padovan else 204858d35f87SGustavo F. Padovan chan->tx_send_head = skb_queue_next(&chan->tx_q, skb); 204918a48e76SMat Martineau 205018a48e76SMat Martineau l2cap_do_send(chan, tx_skb); 2051b4400672SAndrei Emeltchenko BT_DBG("Sent txseq %u", control->txseq); 20520a708f8fSGustavo F. Padovan } 20530a708f8fSGustavo F. Padovan 2054b4400672SAndrei Emeltchenko BT_DBG("Sent %d, %u unacked, %u in ERTM queue", sent, 2055b4400672SAndrei Emeltchenko chan->unacked_frames, skb_queue_len(&chan->tx_q)); 205618a48e76SMat Martineau 205718a48e76SMat Martineau return sent; 20580a708f8fSGustavo F. Padovan } 20590a708f8fSGustavo F. Padovan 2060e1fbd4c1SMat Martineau static void l2cap_ertm_resend(struct l2cap_chan *chan) 2061e1fbd4c1SMat Martineau { 2062e1fbd4c1SMat Martineau struct l2cap_ctrl control; 2063e1fbd4c1SMat Martineau struct sk_buff *skb; 2064e1fbd4c1SMat Martineau struct sk_buff *tx_skb; 2065e1fbd4c1SMat Martineau u16 seq; 2066e1fbd4c1SMat Martineau 2067e1fbd4c1SMat Martineau BT_DBG("chan %p", chan); 2068e1fbd4c1SMat Martineau 2069e1fbd4c1SMat Martineau if (test_bit(CONN_REMOTE_BUSY, &chan->conn_state)) 2070e1fbd4c1SMat Martineau return; 2071e1fbd4c1SMat Martineau 2072b99e13adSMat Martineau if (__chan_is_moving(chan)) 2073b99e13adSMat Martineau return; 2074b99e13adSMat Martineau 2075e1fbd4c1SMat Martineau while (chan->retrans_list.head != L2CAP_SEQ_LIST_CLEAR) { 2076e1fbd4c1SMat Martineau seq = l2cap_seq_list_pop(&chan->retrans_list); 2077e1fbd4c1SMat Martineau 2078e1fbd4c1SMat Martineau skb = l2cap_ertm_seq_in_queue(&chan->tx_q, seq); 2079e1fbd4c1SMat Martineau if (!skb) { 2080e1fbd4c1SMat Martineau BT_DBG("Error: Can't retransmit seq %d, frame missing", 2081e1fbd4c1SMat Martineau seq); 2082e1fbd4c1SMat Martineau continue; 2083e1fbd4c1SMat Martineau } 2084e1fbd4c1SMat Martineau 2085e1fbd4c1SMat Martineau bt_cb(skb)->control.retries++; 2086e1fbd4c1SMat Martineau control = bt_cb(skb)->control; 2087e1fbd4c1SMat Martineau 2088e1fbd4c1SMat Martineau if (chan->max_tx != 0 && 2089e1fbd4c1SMat Martineau bt_cb(skb)->control.retries > chan->max_tx) { 2090e1fbd4c1SMat Martineau BT_DBG("Retry limit exceeded (%d)", chan->max_tx); 20915e4e3972SAndrei Emeltchenko l2cap_send_disconn_req(chan, ECONNRESET); 2092e1fbd4c1SMat Martineau l2cap_seq_list_clear(&chan->retrans_list); 2093e1fbd4c1SMat Martineau break; 2094e1fbd4c1SMat Martineau } 2095e1fbd4c1SMat Martineau 2096e1fbd4c1SMat Martineau control.reqseq = chan->buffer_seq; 2097e1fbd4c1SMat Martineau if (test_and_clear_bit(CONN_SEND_FBIT, &chan->conn_state)) 2098e1fbd4c1SMat Martineau control.final = 1; 2099e1fbd4c1SMat Martineau else 2100e1fbd4c1SMat Martineau control.final = 0; 2101e1fbd4c1SMat Martineau 2102e1fbd4c1SMat Martineau if (skb_cloned(skb)) { 2103e1fbd4c1SMat Martineau /* Cloned sk_buffs are read-only, so we need a 2104e1fbd4c1SMat Martineau * writeable copy 2105e1fbd4c1SMat Martineau */ 21068bcde1f2SGustavo Padovan tx_skb = skb_copy(skb, GFP_KERNEL); 2107e1fbd4c1SMat Martineau } else { 21088bcde1f2SGustavo Padovan tx_skb = skb_clone(skb, GFP_KERNEL); 2109e1fbd4c1SMat Martineau } 2110e1fbd4c1SMat Martineau 2111e1fbd4c1SMat Martineau if (!tx_skb) { 2112e1fbd4c1SMat Martineau l2cap_seq_list_clear(&chan->retrans_list); 2113e1fbd4c1SMat Martineau break; 2114e1fbd4c1SMat Martineau } 2115e1fbd4c1SMat Martineau 2116e1fbd4c1SMat Martineau /* Update skb contents */ 2117e1fbd4c1SMat Martineau if (test_bit(FLAG_EXT_CTRL, &chan->flags)) { 2118e1fbd4c1SMat Martineau put_unaligned_le32(__pack_extended_control(&control), 2119e1fbd4c1SMat Martineau tx_skb->data + L2CAP_HDR_SIZE); 2120e1fbd4c1SMat Martineau } else { 2121e1fbd4c1SMat Martineau put_unaligned_le16(__pack_enhanced_control(&control), 2122e1fbd4c1SMat Martineau tx_skb->data + L2CAP_HDR_SIZE); 2123e1fbd4c1SMat Martineau } 2124e1fbd4c1SMat Martineau 2125e1fbd4c1SMat Martineau if (chan->fcs == L2CAP_FCS_CRC16) { 2126e1fbd4c1SMat Martineau u16 fcs = crc16(0, (u8 *) tx_skb->data, tx_skb->len); 2127e1fbd4c1SMat Martineau put_unaligned_le16(fcs, skb_put(tx_skb, 2128e1fbd4c1SMat Martineau L2CAP_FCS_SIZE)); 2129e1fbd4c1SMat Martineau } 2130e1fbd4c1SMat Martineau 2131e1fbd4c1SMat Martineau l2cap_do_send(chan, tx_skb); 2132e1fbd4c1SMat Martineau 2133e1fbd4c1SMat Martineau BT_DBG("Resent txseq %d", control.txseq); 2134e1fbd4c1SMat Martineau 2135e1fbd4c1SMat Martineau chan->last_acked_seq = chan->buffer_seq; 2136e1fbd4c1SMat Martineau } 2137e1fbd4c1SMat Martineau } 2138e1fbd4c1SMat Martineau 2139f80842a8SMat Martineau static void l2cap_retransmit(struct l2cap_chan *chan, 2140f80842a8SMat Martineau struct l2cap_ctrl *control) 2141f80842a8SMat Martineau { 2142f80842a8SMat Martineau BT_DBG("chan %p, control %p", chan, control); 2143f80842a8SMat Martineau 2144f80842a8SMat Martineau l2cap_seq_list_append(&chan->retrans_list, control->reqseq); 2145f80842a8SMat Martineau l2cap_ertm_resend(chan); 2146f80842a8SMat Martineau } 2147f80842a8SMat Martineau 2148d2a7ac5dSMat Martineau static void l2cap_retransmit_all(struct l2cap_chan *chan, 2149d2a7ac5dSMat Martineau struct l2cap_ctrl *control) 2150d2a7ac5dSMat Martineau { 2151e1fbd4c1SMat Martineau struct sk_buff *skb; 2152e1fbd4c1SMat Martineau 2153e1fbd4c1SMat Martineau BT_DBG("chan %p, control %p", chan, control); 2154e1fbd4c1SMat Martineau 2155e1fbd4c1SMat Martineau if (control->poll) 2156e1fbd4c1SMat Martineau set_bit(CONN_SEND_FBIT, &chan->conn_state); 2157e1fbd4c1SMat Martineau 2158e1fbd4c1SMat Martineau l2cap_seq_list_clear(&chan->retrans_list); 2159e1fbd4c1SMat Martineau 2160e1fbd4c1SMat Martineau if (test_bit(CONN_REMOTE_BUSY, &chan->conn_state)) 2161e1fbd4c1SMat Martineau return; 2162e1fbd4c1SMat Martineau 2163e1fbd4c1SMat Martineau if (chan->unacked_frames) { 2164e1fbd4c1SMat Martineau skb_queue_walk(&chan->tx_q, skb) { 2165e1fbd4c1SMat Martineau if (bt_cb(skb)->control.txseq == control->reqseq || 2166e1fbd4c1SMat Martineau skb == chan->tx_send_head) 2167e1fbd4c1SMat Martineau break; 2168e1fbd4c1SMat Martineau } 2169e1fbd4c1SMat Martineau 2170e1fbd4c1SMat Martineau skb_queue_walk_from(&chan->tx_q, skb) { 2171e1fbd4c1SMat Martineau if (skb == chan->tx_send_head) 2172e1fbd4c1SMat Martineau break; 2173e1fbd4c1SMat Martineau 2174e1fbd4c1SMat Martineau l2cap_seq_list_append(&chan->retrans_list, 2175e1fbd4c1SMat Martineau bt_cb(skb)->control.txseq); 2176e1fbd4c1SMat Martineau } 2177e1fbd4c1SMat Martineau 2178e1fbd4c1SMat Martineau l2cap_ertm_resend(chan); 2179e1fbd4c1SMat Martineau } 2180d2a7ac5dSMat Martineau } 2181d2a7ac5dSMat Martineau 2182b17e73bbSSzymon Janc static void l2cap_send_ack(struct l2cap_chan *chan) 2183b17e73bbSSzymon Janc { 21840a0aba42SMat Martineau struct l2cap_ctrl control; 21850a0aba42SMat Martineau u16 frames_to_ack = __seq_offset(chan, chan->buffer_seq, 21860a0aba42SMat Martineau chan->last_acked_seq); 21870a0aba42SMat Martineau int threshold; 21880a0aba42SMat Martineau 21890a0aba42SMat Martineau BT_DBG("chan %p last_acked_seq %d buffer_seq %d", 21900a0aba42SMat Martineau chan, chan->last_acked_seq, chan->buffer_seq); 21910a0aba42SMat Martineau 21920a0aba42SMat Martineau memset(&control, 0, sizeof(control)); 21930a0aba42SMat Martineau control.sframe = 1; 21940a0aba42SMat Martineau 21950a0aba42SMat Martineau if (test_bit(CONN_LOCAL_BUSY, &chan->conn_state) && 21960a0aba42SMat Martineau chan->rx_state == L2CAP_RX_STATE_RECV) { 2197b17e73bbSSzymon Janc __clear_ack_timer(chan); 21980a0aba42SMat Martineau control.super = L2CAP_SUPER_RNR; 21990a0aba42SMat Martineau control.reqseq = chan->buffer_seq; 22000a0aba42SMat Martineau l2cap_send_sframe(chan, &control); 22010a0aba42SMat Martineau } else { 22020a0aba42SMat Martineau if (!test_bit(CONN_REMOTE_BUSY, &chan->conn_state)) { 22030a0aba42SMat Martineau l2cap_ertm_send(chan); 22040a0aba42SMat Martineau /* If any i-frames were sent, they included an ack */ 22050a0aba42SMat Martineau if (chan->buffer_seq == chan->last_acked_seq) 22060a0aba42SMat Martineau frames_to_ack = 0; 22070a0aba42SMat Martineau } 22080a0aba42SMat Martineau 2209c20f8e35SMat Martineau /* Ack now if the window is 3/4ths full. 22100a0aba42SMat Martineau * Calculate without mul or div 22110a0aba42SMat Martineau */ 2212c20f8e35SMat Martineau threshold = chan->ack_win; 22130a0aba42SMat Martineau threshold += threshold << 1; 22140a0aba42SMat Martineau threshold >>= 2; 22150a0aba42SMat Martineau 2216b4400672SAndrei Emeltchenko BT_DBG("frames_to_ack %u, threshold %d", frames_to_ack, 22170a0aba42SMat Martineau threshold); 22180a0aba42SMat Martineau 22190a0aba42SMat Martineau if (frames_to_ack >= threshold) { 22200a0aba42SMat Martineau __clear_ack_timer(chan); 22210a0aba42SMat Martineau control.super = L2CAP_SUPER_RR; 22220a0aba42SMat Martineau control.reqseq = chan->buffer_seq; 22230a0aba42SMat Martineau l2cap_send_sframe(chan, &control); 22240a0aba42SMat Martineau frames_to_ack = 0; 22250a0aba42SMat Martineau } 22260a0aba42SMat Martineau 22270a0aba42SMat Martineau if (frames_to_ack) 22280a0aba42SMat Martineau __set_ack_timer(chan); 22290a0aba42SMat Martineau } 2230b17e73bbSSzymon Janc } 2231b17e73bbSSzymon Janc 223204124681SGustavo F. Padovan static inline int l2cap_skbuff_fromiovec(struct l2cap_chan *chan, 223304124681SGustavo F. Padovan struct msghdr *msg, int len, 223404124681SGustavo F. Padovan int count, struct sk_buff *skb) 22350a708f8fSGustavo F. Padovan { 22360952a57aSAndrei Emeltchenko struct l2cap_conn *conn = chan->conn; 22370a708f8fSGustavo F. Padovan struct sk_buff **frag; 223890338947SGustavo Padovan int sent = 0; 22390a708f8fSGustavo F. Padovan 22400a708f8fSGustavo F. Padovan if (memcpy_fromiovec(skb_put(skb, count), msg->msg_iov, count)) 22410a708f8fSGustavo F. Padovan return -EFAULT; 22420a708f8fSGustavo F. Padovan 22430a708f8fSGustavo F. Padovan sent += count; 22440a708f8fSGustavo F. Padovan len -= count; 22450a708f8fSGustavo F. Padovan 22460a708f8fSGustavo F. Padovan /* Continuation fragments (no L2CAP header) */ 22470a708f8fSGustavo F. Padovan frag = &skb_shinfo(skb)->frag_list; 22480a708f8fSGustavo F. Padovan while (len) { 2249fbe00700SGustavo Padovan struct sk_buff *tmp; 2250fbe00700SGustavo Padovan 22510a708f8fSGustavo F. Padovan count = min_t(unsigned int, conn->mtu, len); 22520a708f8fSGustavo F. Padovan 2253fbe00700SGustavo Padovan tmp = chan->ops->alloc_skb(chan, count, 225490338947SGustavo Padovan msg->msg_flags & MSG_DONTWAIT); 2255fbe00700SGustavo Padovan if (IS_ERR(tmp)) 2256fbe00700SGustavo Padovan return PTR_ERR(tmp); 22572f7719ceSAndrei Emeltchenko 2258fbe00700SGustavo Padovan *frag = tmp; 2259fbe00700SGustavo Padovan 22600a708f8fSGustavo F. Padovan if (memcpy_fromiovec(skb_put(*frag, count), msg->msg_iov, count)) 22610a708f8fSGustavo F. Padovan return -EFAULT; 22620a708f8fSGustavo F. Padovan 22635e59b791SLuiz Augusto von Dentz (*frag)->priority = skb->priority; 22645e59b791SLuiz Augusto von Dentz 22650a708f8fSGustavo F. Padovan sent += count; 22660a708f8fSGustavo F. Padovan len -= count; 22670a708f8fSGustavo F. Padovan 22682d0ed3d5SGustavo Padovan skb->len += (*frag)->len; 22692d0ed3d5SGustavo Padovan skb->data_len += (*frag)->len; 22702d0ed3d5SGustavo Padovan 22710a708f8fSGustavo F. Padovan frag = &(*frag)->next; 22720a708f8fSGustavo F. Padovan } 22730a708f8fSGustavo F. Padovan 22740a708f8fSGustavo F. Padovan return sent; 22750a708f8fSGustavo F. Padovan } 22760a708f8fSGustavo F. Padovan 22775e59b791SLuiz Augusto von Dentz static struct sk_buff *l2cap_create_connless_pdu(struct l2cap_chan *chan, 22785e59b791SLuiz Augusto von Dentz struct msghdr *msg, size_t len, 22795e59b791SLuiz Augusto von Dentz u32 priority) 22800a708f8fSGustavo F. Padovan { 22818c1d787bSGustavo F. Padovan struct l2cap_conn *conn = chan->conn; 22820a708f8fSGustavo F. Padovan struct sk_buff *skb; 228303a51213SAndrei Emeltchenko int err, count, hlen = L2CAP_HDR_SIZE + L2CAP_PSMLEN_SIZE; 22840a708f8fSGustavo F. Padovan struct l2cap_hdr *lh; 22850a708f8fSGustavo F. Padovan 2286b4400672SAndrei Emeltchenko BT_DBG("chan %p len %zu priority %u", chan, len, priority); 22870a708f8fSGustavo F. Padovan 22880a708f8fSGustavo F. Padovan count = min_t(unsigned int, (conn->mtu - hlen), len); 22892f7719ceSAndrei Emeltchenko 22902f7719ceSAndrei Emeltchenko skb = chan->ops->alloc_skb(chan, count + hlen, 229190338947SGustavo Padovan msg->msg_flags & MSG_DONTWAIT); 229290338947SGustavo Padovan if (IS_ERR(skb)) 229390338947SGustavo Padovan return skb; 22940a708f8fSGustavo F. Padovan 22955e59b791SLuiz Augusto von Dentz skb->priority = priority; 22965e59b791SLuiz Augusto von Dentz 22970a708f8fSGustavo F. Padovan /* Create L2CAP header */ 22980a708f8fSGustavo F. Padovan lh = (struct l2cap_hdr *) skb_put(skb, L2CAP_HDR_SIZE); 2299fe4128e0SGustavo F. Padovan lh->cid = cpu_to_le16(chan->dcid); 2300daf6a78cSAndrei Emeltchenko lh->len = cpu_to_le16(len + L2CAP_PSMLEN_SIZE); 2301daf6a78cSAndrei Emeltchenko put_unaligned(chan->psm, skb_put(skb, L2CAP_PSMLEN_SIZE)); 23020a708f8fSGustavo F. Padovan 23030952a57aSAndrei Emeltchenko err = l2cap_skbuff_fromiovec(chan, msg, len, count, skb); 23040a708f8fSGustavo F. Padovan if (unlikely(err < 0)) { 23050a708f8fSGustavo F. Padovan kfree_skb(skb); 23060a708f8fSGustavo F. Padovan return ERR_PTR(err); 23070a708f8fSGustavo F. Padovan } 23080a708f8fSGustavo F. Padovan return skb; 23090a708f8fSGustavo F. Padovan } 23100a708f8fSGustavo F. Padovan 23115e59b791SLuiz Augusto von Dentz static struct sk_buff *l2cap_create_basic_pdu(struct l2cap_chan *chan, 23125e59b791SLuiz Augusto von Dentz struct msghdr *msg, size_t len, 23135e59b791SLuiz Augusto von Dentz u32 priority) 23140a708f8fSGustavo F. Padovan { 23158c1d787bSGustavo F. Padovan struct l2cap_conn *conn = chan->conn; 23160a708f8fSGustavo F. Padovan struct sk_buff *skb; 2317f2ba7faeSGustavo Padovan int err, count; 23180a708f8fSGustavo F. Padovan struct l2cap_hdr *lh; 23190a708f8fSGustavo F. Padovan 2320b4400672SAndrei Emeltchenko BT_DBG("chan %p len %zu", chan, len); 23210a708f8fSGustavo F. Padovan 2322f2ba7faeSGustavo Padovan count = min_t(unsigned int, (conn->mtu - L2CAP_HDR_SIZE), len); 23232f7719ceSAndrei Emeltchenko 2324f2ba7faeSGustavo Padovan skb = chan->ops->alloc_skb(chan, count + L2CAP_HDR_SIZE, 232590338947SGustavo Padovan msg->msg_flags & MSG_DONTWAIT); 232690338947SGustavo Padovan if (IS_ERR(skb)) 232790338947SGustavo Padovan return skb; 23280a708f8fSGustavo F. Padovan 23295e59b791SLuiz Augusto von Dentz skb->priority = priority; 23305e59b791SLuiz Augusto von Dentz 23310a708f8fSGustavo F. Padovan /* Create L2CAP header */ 23320a708f8fSGustavo F. Padovan lh = (struct l2cap_hdr *) skb_put(skb, L2CAP_HDR_SIZE); 2333fe4128e0SGustavo F. Padovan lh->cid = cpu_to_le16(chan->dcid); 23346ff9b5efSGustavo Padovan lh->len = cpu_to_le16(len); 23350a708f8fSGustavo F. Padovan 23360952a57aSAndrei Emeltchenko err = l2cap_skbuff_fromiovec(chan, msg, len, count, skb); 23370a708f8fSGustavo F. Padovan if (unlikely(err < 0)) { 23380a708f8fSGustavo F. Padovan kfree_skb(skb); 23390a708f8fSGustavo F. Padovan return ERR_PTR(err); 23400a708f8fSGustavo F. Padovan } 23410a708f8fSGustavo F. Padovan return skb; 23420a708f8fSGustavo F. Padovan } 23430a708f8fSGustavo F. Padovan 2344ab0ff76dSLuiz Augusto von Dentz static struct sk_buff *l2cap_create_iframe_pdu(struct l2cap_chan *chan, 2345ab0ff76dSLuiz Augusto von Dentz struct msghdr *msg, size_t len, 234694122bbeSMat Martineau u16 sdulen) 23470a708f8fSGustavo F. Padovan { 23488c1d787bSGustavo F. Padovan struct l2cap_conn *conn = chan->conn; 23490a708f8fSGustavo F. Padovan struct sk_buff *skb; 2350e4ca6d98SAndrei Emeltchenko int err, count, hlen; 23510a708f8fSGustavo F. Padovan struct l2cap_hdr *lh; 23520a708f8fSGustavo F. Padovan 2353b4400672SAndrei Emeltchenko BT_DBG("chan %p len %zu", chan, len); 23540a708f8fSGustavo F. Padovan 23550a708f8fSGustavo F. Padovan if (!conn) 23560a708f8fSGustavo F. Padovan return ERR_PTR(-ENOTCONN); 23570a708f8fSGustavo F. Padovan 2358ba7aa64fSGustavo Padovan hlen = __ertm_hdr_size(chan); 2359e4ca6d98SAndrei Emeltchenko 23600a708f8fSGustavo F. Padovan if (sdulen) 236103a51213SAndrei Emeltchenko hlen += L2CAP_SDULEN_SIZE; 23620a708f8fSGustavo F. Padovan 236347d1ec61SGustavo F. Padovan if (chan->fcs == L2CAP_FCS_CRC16) 236403a51213SAndrei Emeltchenko hlen += L2CAP_FCS_SIZE; 23650a708f8fSGustavo F. Padovan 23660a708f8fSGustavo F. Padovan count = min_t(unsigned int, (conn->mtu - hlen), len); 23672f7719ceSAndrei Emeltchenko 23682f7719ceSAndrei Emeltchenko skb = chan->ops->alloc_skb(chan, count + hlen, 236990338947SGustavo Padovan msg->msg_flags & MSG_DONTWAIT); 237090338947SGustavo Padovan if (IS_ERR(skb)) 237190338947SGustavo Padovan return skb; 23720a708f8fSGustavo F. Padovan 23730a708f8fSGustavo F. Padovan /* Create L2CAP header */ 23740a708f8fSGustavo F. Padovan lh = (struct l2cap_hdr *) skb_put(skb, L2CAP_HDR_SIZE); 2375fe4128e0SGustavo F. Padovan lh->cid = cpu_to_le16(chan->dcid); 23760a708f8fSGustavo F. Padovan lh->len = cpu_to_le16(len + (hlen - L2CAP_HDR_SIZE)); 237788843ab0SAndrei Emeltchenko 237818a48e76SMat Martineau /* Control header is populated later */ 237918a48e76SMat Martineau if (test_bit(FLAG_EXT_CTRL, &chan->flags)) 238018a48e76SMat Martineau put_unaligned_le32(0, skb_put(skb, L2CAP_EXT_CTRL_SIZE)); 238118a48e76SMat Martineau else 238218a48e76SMat Martineau put_unaligned_le16(0, skb_put(skb, L2CAP_ENH_CTRL_SIZE)); 238388843ab0SAndrei Emeltchenko 23840a708f8fSGustavo F. Padovan if (sdulen) 238503a51213SAndrei Emeltchenko put_unaligned_le16(sdulen, skb_put(skb, L2CAP_SDULEN_SIZE)); 23860a708f8fSGustavo F. Padovan 23870952a57aSAndrei Emeltchenko err = l2cap_skbuff_fromiovec(chan, msg, len, count, skb); 23880a708f8fSGustavo F. Padovan if (unlikely(err < 0)) { 23890a708f8fSGustavo F. Padovan kfree_skb(skb); 23900a708f8fSGustavo F. Padovan return ERR_PTR(err); 23910a708f8fSGustavo F. Padovan } 23920a708f8fSGustavo F. Padovan 239318a48e76SMat Martineau bt_cb(skb)->control.fcs = chan->fcs; 23943ce3514fSMat Martineau bt_cb(skb)->control.retries = 0; 23950a708f8fSGustavo F. Padovan return skb; 23960a708f8fSGustavo F. Padovan } 23970a708f8fSGustavo F. Padovan 239894122bbeSMat Martineau static int l2cap_segment_sdu(struct l2cap_chan *chan, 239994122bbeSMat Martineau struct sk_buff_head *seg_queue, 240094122bbeSMat Martineau struct msghdr *msg, size_t len) 24010a708f8fSGustavo F. Padovan { 24020a708f8fSGustavo F. Padovan struct sk_buff *skb; 240394122bbeSMat Martineau u16 sdu_len; 240494122bbeSMat Martineau size_t pdu_len; 240594122bbeSMat Martineau u8 sar; 24060a708f8fSGustavo F. Padovan 2407b4400672SAndrei Emeltchenko BT_DBG("chan %p, msg %p, len %zu", chan, msg, len); 24080a708f8fSGustavo F. Padovan 240994122bbeSMat Martineau /* It is critical that ERTM PDUs fit in a single HCI fragment, 241094122bbeSMat Martineau * so fragmented skbs are not used. The HCI layer's handling 241194122bbeSMat Martineau * of fragmented skbs is not compatible with ERTM's queueing. 241294122bbeSMat Martineau */ 241394122bbeSMat Martineau 241494122bbeSMat Martineau /* PDU size is derived from the HCI MTU */ 241594122bbeSMat Martineau pdu_len = chan->conn->mtu; 241694122bbeSMat Martineau 2417a549574dSMat Martineau /* Constrain PDU size for BR/EDR connections */ 2418a549574dSMat Martineau if (!chan->hs_hcon) 241994122bbeSMat Martineau pdu_len = min_t(size_t, pdu_len, L2CAP_BREDR_MAX_PAYLOAD); 242094122bbeSMat Martineau 242194122bbeSMat Martineau /* Adjust for largest possible L2CAP overhead. */ 242235d401dfSGustavo Padovan if (chan->fcs) 242335d401dfSGustavo Padovan pdu_len -= L2CAP_FCS_SIZE; 242435d401dfSGustavo Padovan 2425ba7aa64fSGustavo Padovan pdu_len -= __ertm_hdr_size(chan); 242694122bbeSMat Martineau 242794122bbeSMat Martineau /* Remote device may have requested smaller PDUs */ 242894122bbeSMat Martineau pdu_len = min_t(size_t, pdu_len, chan->remote_mps); 242994122bbeSMat Martineau 243094122bbeSMat Martineau if (len <= pdu_len) { 243194122bbeSMat Martineau sar = L2CAP_SAR_UNSEGMENTED; 243294122bbeSMat Martineau sdu_len = 0; 243394122bbeSMat Martineau pdu_len = len; 243494122bbeSMat Martineau } else { 243594122bbeSMat Martineau sar = L2CAP_SAR_START; 243694122bbeSMat Martineau sdu_len = len; 243794122bbeSMat Martineau pdu_len -= L2CAP_SDULEN_SIZE; 243894122bbeSMat Martineau } 24390a708f8fSGustavo F. Padovan 24400a708f8fSGustavo F. Padovan while (len > 0) { 244194122bbeSMat Martineau skb = l2cap_create_iframe_pdu(chan, msg, pdu_len, sdu_len); 24420a708f8fSGustavo F. Padovan 24430a708f8fSGustavo F. Padovan if (IS_ERR(skb)) { 244494122bbeSMat Martineau __skb_queue_purge(seg_queue); 24450a708f8fSGustavo F. Padovan return PTR_ERR(skb); 24460a708f8fSGustavo F. Padovan } 24470a708f8fSGustavo F. Padovan 244894122bbeSMat Martineau bt_cb(skb)->control.sar = sar; 244994122bbeSMat Martineau __skb_queue_tail(seg_queue, skb); 24500a708f8fSGustavo F. Padovan 245194122bbeSMat Martineau len -= pdu_len; 245294122bbeSMat Martineau if (sdu_len) { 245394122bbeSMat Martineau sdu_len = 0; 245494122bbeSMat Martineau pdu_len += L2CAP_SDULEN_SIZE; 245594122bbeSMat Martineau } 245694122bbeSMat Martineau 245794122bbeSMat Martineau if (len <= pdu_len) { 245894122bbeSMat Martineau sar = L2CAP_SAR_END; 245994122bbeSMat Martineau pdu_len = len; 246094122bbeSMat Martineau } else { 246194122bbeSMat Martineau sar = L2CAP_SAR_CONTINUE; 246294122bbeSMat Martineau } 246394122bbeSMat Martineau } 246494122bbeSMat Martineau 2465f0f62799SGustavo Padovan return 0; 24660a708f8fSGustavo F. Padovan } 24670a708f8fSGustavo F. Padovan 24685e59b791SLuiz Augusto von Dentz int l2cap_chan_send(struct l2cap_chan *chan, struct msghdr *msg, size_t len, 24695e59b791SLuiz Augusto von Dentz u32 priority) 24709a91a04aSGustavo F. Padovan { 24719a91a04aSGustavo F. Padovan struct sk_buff *skb; 24729a91a04aSGustavo F. Padovan int err; 247394122bbeSMat Martineau struct sk_buff_head seg_queue; 24749a91a04aSGustavo F. Padovan 24759a91a04aSGustavo F. Padovan /* Connectionless channel */ 2476715ec005SGustavo F. Padovan if (chan->chan_type == L2CAP_CHAN_CONN_LESS) { 24775e59b791SLuiz Augusto von Dentz skb = l2cap_create_connless_pdu(chan, msg, len, priority); 24789a91a04aSGustavo F. Padovan if (IS_ERR(skb)) 24799a91a04aSGustavo F. Padovan return PTR_ERR(skb); 24809a91a04aSGustavo F. Padovan 24819a91a04aSGustavo F. Padovan l2cap_do_send(chan, skb); 24829a91a04aSGustavo F. Padovan return len; 24839a91a04aSGustavo F. Padovan } 24849a91a04aSGustavo F. Padovan 24859a91a04aSGustavo F. Padovan switch (chan->mode) { 24869a91a04aSGustavo F. Padovan case L2CAP_MODE_BASIC: 24879a91a04aSGustavo F. Padovan /* Check outgoing MTU */ 24889a91a04aSGustavo F. Padovan if (len > chan->omtu) 24899a91a04aSGustavo F. Padovan return -EMSGSIZE; 24909a91a04aSGustavo F. Padovan 24919a91a04aSGustavo F. Padovan /* Create a basic PDU */ 24925e59b791SLuiz Augusto von Dentz skb = l2cap_create_basic_pdu(chan, msg, len, priority); 24939a91a04aSGustavo F. Padovan if (IS_ERR(skb)) 24949a91a04aSGustavo F. Padovan return PTR_ERR(skb); 24959a91a04aSGustavo F. Padovan 24969a91a04aSGustavo F. Padovan l2cap_do_send(chan, skb); 24979a91a04aSGustavo F. Padovan err = len; 24989a91a04aSGustavo F. Padovan break; 24999a91a04aSGustavo F. Padovan 25009a91a04aSGustavo F. Padovan case L2CAP_MODE_ERTM: 25019a91a04aSGustavo F. Padovan case L2CAP_MODE_STREAMING: 250294122bbeSMat Martineau /* Check outgoing MTU */ 250394122bbeSMat Martineau if (len > chan->omtu) { 250494122bbeSMat Martineau err = -EMSGSIZE; 25059a91a04aSGustavo F. Padovan break; 25069a91a04aSGustavo F. Padovan } 25079a91a04aSGustavo F. Padovan 250894122bbeSMat Martineau __skb_queue_head_init(&seg_queue); 250994122bbeSMat Martineau 251094122bbeSMat Martineau /* Do segmentation before calling in to the state machine, 251194122bbeSMat Martineau * since it's possible to block while waiting for memory 251294122bbeSMat Martineau * allocation. 251394122bbeSMat Martineau */ 251494122bbeSMat Martineau err = l2cap_segment_sdu(chan, &seg_queue, msg, len); 251594122bbeSMat Martineau 251694122bbeSMat Martineau /* The channel could have been closed while segmenting, 251794122bbeSMat Martineau * check that it is still connected. 251894122bbeSMat Martineau */ 251994122bbeSMat Martineau if (chan->state != BT_CONNECTED) { 252094122bbeSMat Martineau __skb_queue_purge(&seg_queue); 252194122bbeSMat Martineau err = -ENOTCONN; 25229a91a04aSGustavo F. Padovan } 25239a91a04aSGustavo F. Padovan 252494122bbeSMat Martineau if (err) 252594122bbeSMat Martineau break; 252694122bbeSMat Martineau 25273733937dSMat Martineau if (chan->mode == L2CAP_MODE_ERTM) 2528d660366dSGustavo Padovan l2cap_tx(chan, NULL, &seg_queue, L2CAP_EV_DATA_REQUEST); 25293733937dSMat Martineau else 2530d660366dSGustavo Padovan l2cap_streaming_send(chan, &seg_queue); 253194122bbeSMat Martineau 25329a91a04aSGustavo F. Padovan err = len; 25339a91a04aSGustavo F. Padovan 253494122bbeSMat Martineau /* If the skbs were not queued for sending, they'll still be in 253594122bbeSMat Martineau * seg_queue and need to be purged. 253694122bbeSMat Martineau */ 253794122bbeSMat Martineau __skb_queue_purge(&seg_queue); 25389a91a04aSGustavo F. Padovan break; 25399a91a04aSGustavo F. Padovan 25409a91a04aSGustavo F. Padovan default: 25419a91a04aSGustavo F. Padovan BT_DBG("bad state %1.1x", chan->mode); 25429a91a04aSGustavo F. Padovan err = -EBADFD; 25439a91a04aSGustavo F. Padovan } 25449a91a04aSGustavo F. Padovan 25459a91a04aSGustavo F. Padovan return err; 25469a91a04aSGustavo F. Padovan } 25479a91a04aSGustavo F. Padovan 2548d2a7ac5dSMat Martineau static void l2cap_send_srej(struct l2cap_chan *chan, u16 txseq) 2549d2a7ac5dSMat Martineau { 2550bed68bdeSMat Martineau struct l2cap_ctrl control; 2551bed68bdeSMat Martineau u16 seq; 2552bed68bdeSMat Martineau 2553b4400672SAndrei Emeltchenko BT_DBG("chan %p, txseq %u", chan, txseq); 2554bed68bdeSMat Martineau 2555bed68bdeSMat Martineau memset(&control, 0, sizeof(control)); 2556bed68bdeSMat Martineau control.sframe = 1; 2557bed68bdeSMat Martineau control.super = L2CAP_SUPER_SREJ; 2558bed68bdeSMat Martineau 2559bed68bdeSMat Martineau for (seq = chan->expected_tx_seq; seq != txseq; 2560bed68bdeSMat Martineau seq = __next_seq(chan, seq)) { 2561bed68bdeSMat Martineau if (!l2cap_ertm_seq_in_queue(&chan->srej_q, seq)) { 2562bed68bdeSMat Martineau control.reqseq = seq; 2563bed68bdeSMat Martineau l2cap_send_sframe(chan, &control); 2564bed68bdeSMat Martineau l2cap_seq_list_append(&chan->srej_list, seq); 2565bed68bdeSMat Martineau } 2566bed68bdeSMat Martineau } 2567bed68bdeSMat Martineau 2568bed68bdeSMat Martineau chan->expected_tx_seq = __next_seq(chan, txseq); 2569d2a7ac5dSMat Martineau } 2570d2a7ac5dSMat Martineau 2571d2a7ac5dSMat Martineau static void l2cap_send_srej_tail(struct l2cap_chan *chan) 2572d2a7ac5dSMat Martineau { 2573bed68bdeSMat Martineau struct l2cap_ctrl control; 2574bed68bdeSMat Martineau 2575bed68bdeSMat Martineau BT_DBG("chan %p", chan); 2576bed68bdeSMat Martineau 2577bed68bdeSMat Martineau if (chan->srej_list.tail == L2CAP_SEQ_LIST_CLEAR) 2578bed68bdeSMat Martineau return; 2579bed68bdeSMat Martineau 2580bed68bdeSMat Martineau memset(&control, 0, sizeof(control)); 2581bed68bdeSMat Martineau control.sframe = 1; 2582bed68bdeSMat Martineau control.super = L2CAP_SUPER_SREJ; 2583bed68bdeSMat Martineau control.reqseq = chan->srej_list.tail; 2584bed68bdeSMat Martineau l2cap_send_sframe(chan, &control); 2585d2a7ac5dSMat Martineau } 2586d2a7ac5dSMat Martineau 2587d2a7ac5dSMat Martineau static void l2cap_send_srej_list(struct l2cap_chan *chan, u16 txseq) 2588d2a7ac5dSMat Martineau { 2589bed68bdeSMat Martineau struct l2cap_ctrl control; 2590bed68bdeSMat Martineau u16 initial_head; 2591bed68bdeSMat Martineau u16 seq; 2592bed68bdeSMat Martineau 2593b4400672SAndrei Emeltchenko BT_DBG("chan %p, txseq %u", chan, txseq); 2594bed68bdeSMat Martineau 2595bed68bdeSMat Martineau memset(&control, 0, sizeof(control)); 2596bed68bdeSMat Martineau control.sframe = 1; 2597bed68bdeSMat Martineau control.super = L2CAP_SUPER_SREJ; 2598bed68bdeSMat Martineau 2599bed68bdeSMat Martineau /* Capture initial list head to allow only one pass through the list. */ 2600bed68bdeSMat Martineau initial_head = chan->srej_list.head; 2601bed68bdeSMat Martineau 2602bed68bdeSMat Martineau do { 2603bed68bdeSMat Martineau seq = l2cap_seq_list_pop(&chan->srej_list); 2604bed68bdeSMat Martineau if (seq == txseq || seq == L2CAP_SEQ_LIST_CLEAR) 2605bed68bdeSMat Martineau break; 2606bed68bdeSMat Martineau 2607bed68bdeSMat Martineau control.reqseq = seq; 2608bed68bdeSMat Martineau l2cap_send_sframe(chan, &control); 2609bed68bdeSMat Martineau l2cap_seq_list_append(&chan->srej_list, seq); 2610bed68bdeSMat Martineau } while (chan->srej_list.head != initial_head); 2611d2a7ac5dSMat Martineau } 2612d2a7ac5dSMat Martineau 2613608bcc6dSMat Martineau static void l2cap_process_reqseq(struct l2cap_chan *chan, u16 reqseq) 2614608bcc6dSMat Martineau { 2615608bcc6dSMat Martineau struct sk_buff *acked_skb; 2616608bcc6dSMat Martineau u16 ackseq; 2617608bcc6dSMat Martineau 2618b4400672SAndrei Emeltchenko BT_DBG("chan %p, reqseq %u", chan, reqseq); 2619608bcc6dSMat Martineau 2620608bcc6dSMat Martineau if (chan->unacked_frames == 0 || reqseq == chan->expected_ack_seq) 2621608bcc6dSMat Martineau return; 2622608bcc6dSMat Martineau 2623b4400672SAndrei Emeltchenko BT_DBG("expected_ack_seq %u, unacked_frames %u", 2624608bcc6dSMat Martineau chan->expected_ack_seq, chan->unacked_frames); 2625608bcc6dSMat Martineau 2626608bcc6dSMat Martineau for (ackseq = chan->expected_ack_seq; ackseq != reqseq; 2627608bcc6dSMat Martineau ackseq = __next_seq(chan, ackseq)) { 2628608bcc6dSMat Martineau 2629608bcc6dSMat Martineau acked_skb = l2cap_ertm_seq_in_queue(&chan->tx_q, ackseq); 2630608bcc6dSMat Martineau if (acked_skb) { 2631608bcc6dSMat Martineau skb_unlink(acked_skb, &chan->tx_q); 2632608bcc6dSMat Martineau kfree_skb(acked_skb); 2633608bcc6dSMat Martineau chan->unacked_frames--; 2634608bcc6dSMat Martineau } 2635608bcc6dSMat Martineau } 2636608bcc6dSMat Martineau 2637608bcc6dSMat Martineau chan->expected_ack_seq = reqseq; 2638608bcc6dSMat Martineau 2639608bcc6dSMat Martineau if (chan->unacked_frames == 0) 2640608bcc6dSMat Martineau __clear_retrans_timer(chan); 2641608bcc6dSMat Martineau 2642b4400672SAndrei Emeltchenko BT_DBG("unacked_frames %u", chan->unacked_frames); 2643608bcc6dSMat Martineau } 2644608bcc6dSMat Martineau 2645608bcc6dSMat Martineau static void l2cap_abort_rx_srej_sent(struct l2cap_chan *chan) 2646608bcc6dSMat Martineau { 2647608bcc6dSMat Martineau BT_DBG("chan %p", chan); 2648608bcc6dSMat Martineau 2649608bcc6dSMat Martineau chan->expected_tx_seq = chan->buffer_seq; 2650608bcc6dSMat Martineau l2cap_seq_list_clear(&chan->srej_list); 2651608bcc6dSMat Martineau skb_queue_purge(&chan->srej_q); 2652608bcc6dSMat Martineau chan->rx_state = L2CAP_RX_STATE_RECV; 2653608bcc6dSMat Martineau } 2654608bcc6dSMat Martineau 2655d660366dSGustavo Padovan static void l2cap_tx_state_xmit(struct l2cap_chan *chan, 2656608bcc6dSMat Martineau struct l2cap_ctrl *control, 2657608bcc6dSMat Martineau struct sk_buff_head *skbs, u8 event) 2658608bcc6dSMat Martineau { 2659608bcc6dSMat Martineau BT_DBG("chan %p, control %p, skbs %p, event %d", chan, control, skbs, 2660608bcc6dSMat Martineau event); 2661608bcc6dSMat Martineau 2662608bcc6dSMat Martineau switch (event) { 2663608bcc6dSMat Martineau case L2CAP_EV_DATA_REQUEST: 2664608bcc6dSMat Martineau if (chan->tx_send_head == NULL) 2665608bcc6dSMat Martineau chan->tx_send_head = skb_peek(skbs); 2666608bcc6dSMat Martineau 2667608bcc6dSMat Martineau skb_queue_splice_tail_init(skbs, &chan->tx_q); 2668608bcc6dSMat Martineau l2cap_ertm_send(chan); 2669608bcc6dSMat Martineau break; 2670608bcc6dSMat Martineau case L2CAP_EV_LOCAL_BUSY_DETECTED: 2671608bcc6dSMat Martineau BT_DBG("Enter LOCAL_BUSY"); 2672608bcc6dSMat Martineau set_bit(CONN_LOCAL_BUSY, &chan->conn_state); 2673608bcc6dSMat Martineau 2674608bcc6dSMat Martineau if (chan->rx_state == L2CAP_RX_STATE_SREJ_SENT) { 2675608bcc6dSMat Martineau /* The SREJ_SENT state must be aborted if we are to 2676608bcc6dSMat Martineau * enter the LOCAL_BUSY state. 2677608bcc6dSMat Martineau */ 2678608bcc6dSMat Martineau l2cap_abort_rx_srej_sent(chan); 2679608bcc6dSMat Martineau } 2680608bcc6dSMat Martineau 2681608bcc6dSMat Martineau l2cap_send_ack(chan); 2682608bcc6dSMat Martineau 2683608bcc6dSMat Martineau break; 2684608bcc6dSMat Martineau case L2CAP_EV_LOCAL_BUSY_CLEAR: 2685608bcc6dSMat Martineau BT_DBG("Exit LOCAL_BUSY"); 2686608bcc6dSMat Martineau clear_bit(CONN_LOCAL_BUSY, &chan->conn_state); 2687608bcc6dSMat Martineau 2688608bcc6dSMat Martineau if (test_bit(CONN_RNR_SENT, &chan->conn_state)) { 2689608bcc6dSMat Martineau struct l2cap_ctrl local_control; 2690608bcc6dSMat Martineau 2691608bcc6dSMat Martineau memset(&local_control, 0, sizeof(local_control)); 2692608bcc6dSMat Martineau local_control.sframe = 1; 2693608bcc6dSMat Martineau local_control.super = L2CAP_SUPER_RR; 2694608bcc6dSMat Martineau local_control.poll = 1; 2695608bcc6dSMat Martineau local_control.reqseq = chan->buffer_seq; 2696a67d7f6fSMat Martineau l2cap_send_sframe(chan, &local_control); 2697608bcc6dSMat Martineau 2698608bcc6dSMat Martineau chan->retry_count = 1; 2699608bcc6dSMat Martineau __set_monitor_timer(chan); 2700608bcc6dSMat Martineau chan->tx_state = L2CAP_TX_STATE_WAIT_F; 2701608bcc6dSMat Martineau } 2702608bcc6dSMat Martineau break; 2703608bcc6dSMat Martineau case L2CAP_EV_RECV_REQSEQ_AND_FBIT: 2704608bcc6dSMat Martineau l2cap_process_reqseq(chan, control->reqseq); 2705608bcc6dSMat Martineau break; 2706608bcc6dSMat Martineau case L2CAP_EV_EXPLICIT_POLL: 2707608bcc6dSMat Martineau l2cap_send_rr_or_rnr(chan, 1); 2708608bcc6dSMat Martineau chan->retry_count = 1; 2709608bcc6dSMat Martineau __set_monitor_timer(chan); 2710608bcc6dSMat Martineau __clear_ack_timer(chan); 2711608bcc6dSMat Martineau chan->tx_state = L2CAP_TX_STATE_WAIT_F; 2712608bcc6dSMat Martineau break; 2713608bcc6dSMat Martineau case L2CAP_EV_RETRANS_TO: 2714608bcc6dSMat Martineau l2cap_send_rr_or_rnr(chan, 1); 2715608bcc6dSMat Martineau chan->retry_count = 1; 2716608bcc6dSMat Martineau __set_monitor_timer(chan); 2717608bcc6dSMat Martineau chan->tx_state = L2CAP_TX_STATE_WAIT_F; 2718608bcc6dSMat Martineau break; 2719608bcc6dSMat Martineau case L2CAP_EV_RECV_FBIT: 2720608bcc6dSMat Martineau /* Nothing to process */ 2721608bcc6dSMat Martineau break; 2722608bcc6dSMat Martineau default: 2723608bcc6dSMat Martineau break; 2724608bcc6dSMat Martineau } 2725608bcc6dSMat Martineau } 2726608bcc6dSMat Martineau 2727d660366dSGustavo Padovan static void l2cap_tx_state_wait_f(struct l2cap_chan *chan, 2728608bcc6dSMat Martineau struct l2cap_ctrl *control, 2729608bcc6dSMat Martineau struct sk_buff_head *skbs, u8 event) 2730608bcc6dSMat Martineau { 2731608bcc6dSMat Martineau BT_DBG("chan %p, control %p, skbs %p, event %d", chan, control, skbs, 2732608bcc6dSMat Martineau event); 2733608bcc6dSMat Martineau 2734608bcc6dSMat Martineau switch (event) { 2735608bcc6dSMat Martineau case L2CAP_EV_DATA_REQUEST: 2736608bcc6dSMat Martineau if (chan->tx_send_head == NULL) 2737608bcc6dSMat Martineau chan->tx_send_head = skb_peek(skbs); 2738608bcc6dSMat Martineau /* Queue data, but don't send. */ 2739608bcc6dSMat Martineau skb_queue_splice_tail_init(skbs, &chan->tx_q); 2740608bcc6dSMat Martineau break; 2741608bcc6dSMat Martineau case L2CAP_EV_LOCAL_BUSY_DETECTED: 2742608bcc6dSMat Martineau BT_DBG("Enter LOCAL_BUSY"); 2743608bcc6dSMat Martineau set_bit(CONN_LOCAL_BUSY, &chan->conn_state); 2744608bcc6dSMat Martineau 2745608bcc6dSMat Martineau if (chan->rx_state == L2CAP_RX_STATE_SREJ_SENT) { 2746608bcc6dSMat Martineau /* The SREJ_SENT state must be aborted if we are to 2747608bcc6dSMat Martineau * enter the LOCAL_BUSY state. 2748608bcc6dSMat Martineau */ 2749608bcc6dSMat Martineau l2cap_abort_rx_srej_sent(chan); 2750608bcc6dSMat Martineau } 2751608bcc6dSMat Martineau 2752608bcc6dSMat Martineau l2cap_send_ack(chan); 2753608bcc6dSMat Martineau 2754608bcc6dSMat Martineau break; 2755608bcc6dSMat Martineau case L2CAP_EV_LOCAL_BUSY_CLEAR: 2756608bcc6dSMat Martineau BT_DBG("Exit LOCAL_BUSY"); 2757608bcc6dSMat Martineau clear_bit(CONN_LOCAL_BUSY, &chan->conn_state); 2758608bcc6dSMat Martineau 2759608bcc6dSMat Martineau if (test_bit(CONN_RNR_SENT, &chan->conn_state)) { 2760608bcc6dSMat Martineau struct l2cap_ctrl local_control; 2761608bcc6dSMat Martineau memset(&local_control, 0, sizeof(local_control)); 2762608bcc6dSMat Martineau local_control.sframe = 1; 2763608bcc6dSMat Martineau local_control.super = L2CAP_SUPER_RR; 2764608bcc6dSMat Martineau local_control.poll = 1; 2765608bcc6dSMat Martineau local_control.reqseq = chan->buffer_seq; 2766a67d7f6fSMat Martineau l2cap_send_sframe(chan, &local_control); 2767608bcc6dSMat Martineau 2768608bcc6dSMat Martineau chan->retry_count = 1; 2769608bcc6dSMat Martineau __set_monitor_timer(chan); 2770608bcc6dSMat Martineau chan->tx_state = L2CAP_TX_STATE_WAIT_F; 2771608bcc6dSMat Martineau } 2772608bcc6dSMat Martineau break; 2773608bcc6dSMat Martineau case L2CAP_EV_RECV_REQSEQ_AND_FBIT: 2774608bcc6dSMat Martineau l2cap_process_reqseq(chan, control->reqseq); 2775608bcc6dSMat Martineau 2776608bcc6dSMat Martineau /* Fall through */ 2777608bcc6dSMat Martineau 2778608bcc6dSMat Martineau case L2CAP_EV_RECV_FBIT: 2779608bcc6dSMat Martineau if (control && control->final) { 2780608bcc6dSMat Martineau __clear_monitor_timer(chan); 2781608bcc6dSMat Martineau if (chan->unacked_frames > 0) 2782608bcc6dSMat Martineau __set_retrans_timer(chan); 2783608bcc6dSMat Martineau chan->retry_count = 0; 2784608bcc6dSMat Martineau chan->tx_state = L2CAP_TX_STATE_XMIT; 2785608bcc6dSMat Martineau BT_DBG("recv fbit tx_state 0x2.2%x", chan->tx_state); 2786608bcc6dSMat Martineau } 2787608bcc6dSMat Martineau break; 2788608bcc6dSMat Martineau case L2CAP_EV_EXPLICIT_POLL: 2789608bcc6dSMat Martineau /* Ignore */ 2790608bcc6dSMat Martineau break; 2791608bcc6dSMat Martineau case L2CAP_EV_MONITOR_TO: 2792608bcc6dSMat Martineau if (chan->max_tx == 0 || chan->retry_count < chan->max_tx) { 2793608bcc6dSMat Martineau l2cap_send_rr_or_rnr(chan, 1); 2794608bcc6dSMat Martineau __set_monitor_timer(chan); 2795608bcc6dSMat Martineau chan->retry_count++; 2796608bcc6dSMat Martineau } else { 27975e4e3972SAndrei Emeltchenko l2cap_send_disconn_req(chan, ECONNABORTED); 2798608bcc6dSMat Martineau } 2799608bcc6dSMat Martineau break; 2800608bcc6dSMat Martineau default: 2801608bcc6dSMat Martineau break; 2802608bcc6dSMat Martineau } 2803608bcc6dSMat Martineau } 2804608bcc6dSMat Martineau 2805d660366dSGustavo Padovan static void l2cap_tx(struct l2cap_chan *chan, struct l2cap_ctrl *control, 2806608bcc6dSMat Martineau struct sk_buff_head *skbs, u8 event) 2807608bcc6dSMat Martineau { 2808608bcc6dSMat Martineau BT_DBG("chan %p, control %p, skbs %p, event %d, state %d", 2809608bcc6dSMat Martineau chan, control, skbs, event, chan->tx_state); 2810608bcc6dSMat Martineau 2811608bcc6dSMat Martineau switch (chan->tx_state) { 2812608bcc6dSMat Martineau case L2CAP_TX_STATE_XMIT: 2813d660366dSGustavo Padovan l2cap_tx_state_xmit(chan, control, skbs, event); 2814608bcc6dSMat Martineau break; 2815608bcc6dSMat Martineau case L2CAP_TX_STATE_WAIT_F: 2816d660366dSGustavo Padovan l2cap_tx_state_wait_f(chan, control, skbs, event); 2817608bcc6dSMat Martineau break; 2818608bcc6dSMat Martineau default: 2819608bcc6dSMat Martineau /* Ignore event */ 2820608bcc6dSMat Martineau break; 2821608bcc6dSMat Martineau } 2822608bcc6dSMat Martineau } 2823608bcc6dSMat Martineau 28244b51dae9SMat Martineau static void l2cap_pass_to_tx(struct l2cap_chan *chan, 28254b51dae9SMat Martineau struct l2cap_ctrl *control) 28264b51dae9SMat Martineau { 28274b51dae9SMat Martineau BT_DBG("chan %p, control %p", chan, control); 2828401bb1f7SAndrei Emeltchenko l2cap_tx(chan, control, NULL, L2CAP_EV_RECV_REQSEQ_AND_FBIT); 28294b51dae9SMat Martineau } 28304b51dae9SMat Martineau 2831f80842a8SMat Martineau static void l2cap_pass_to_tx_fbit(struct l2cap_chan *chan, 2832f80842a8SMat Martineau struct l2cap_ctrl *control) 2833f80842a8SMat Martineau { 2834f80842a8SMat Martineau BT_DBG("chan %p, control %p", chan, control); 2835401bb1f7SAndrei Emeltchenko l2cap_tx(chan, control, NULL, L2CAP_EV_RECV_FBIT); 2836f80842a8SMat Martineau } 2837f80842a8SMat Martineau 28380a708f8fSGustavo F. Padovan /* Copy frame to all raw sockets on that connection */ 28390a708f8fSGustavo F. Padovan static void l2cap_raw_recv(struct l2cap_conn *conn, struct sk_buff *skb) 28400a708f8fSGustavo F. Padovan { 28410a708f8fSGustavo F. Padovan struct sk_buff *nskb; 284248454079SGustavo F. Padovan struct l2cap_chan *chan; 28430a708f8fSGustavo F. Padovan 28440a708f8fSGustavo F. Padovan BT_DBG("conn %p", conn); 28450a708f8fSGustavo F. Padovan 28463df91ea2SAndrei Emeltchenko mutex_lock(&conn->chan_lock); 28473d57dc68SGustavo F. Padovan 28483df91ea2SAndrei Emeltchenko list_for_each_entry(chan, &conn->chan_l, list) { 284948454079SGustavo F. Padovan struct sock *sk = chan->sk; 2850715ec005SGustavo F. Padovan if (chan->chan_type != L2CAP_CHAN_RAW) 28510a708f8fSGustavo F. Padovan continue; 28520a708f8fSGustavo F. Padovan 28530a708f8fSGustavo F. Padovan /* Don't send frame to the socket it came from */ 28540a708f8fSGustavo F. Padovan if (skb->sk == sk) 28550a708f8fSGustavo F. Padovan continue; 28568bcde1f2SGustavo Padovan nskb = skb_clone(skb, GFP_KERNEL); 28570a708f8fSGustavo F. Padovan if (!nskb) 28580a708f8fSGustavo F. Padovan continue; 28590a708f8fSGustavo F. Padovan 286080b98027SGustavo Padovan if (chan->ops->recv(chan, nskb)) 28610a708f8fSGustavo F. Padovan kfree_skb(nskb); 28620a708f8fSGustavo F. Padovan } 28633d57dc68SGustavo F. Padovan 28643df91ea2SAndrei Emeltchenko mutex_unlock(&conn->chan_lock); 28650a708f8fSGustavo F. Padovan } 28660a708f8fSGustavo F. Padovan 28670a708f8fSGustavo F. Padovan /* ---- L2CAP signalling commands ---- */ 2868b4400672SAndrei Emeltchenko static struct sk_buff *l2cap_build_cmd(struct l2cap_conn *conn, u8 code, 2869b4400672SAndrei Emeltchenko u8 ident, u16 dlen, void *data) 28700a708f8fSGustavo F. Padovan { 28710a708f8fSGustavo F. Padovan struct sk_buff *skb, **frag; 28720a708f8fSGustavo F. Padovan struct l2cap_cmd_hdr *cmd; 28730a708f8fSGustavo F. Padovan struct l2cap_hdr *lh; 28740a708f8fSGustavo F. Padovan int len, count; 28750a708f8fSGustavo F. Padovan 2876b4400672SAndrei Emeltchenko BT_DBG("conn %p, code 0x%2.2x, ident 0x%2.2x, len %u", 28770a708f8fSGustavo F. Padovan conn, code, ident, dlen); 28780a708f8fSGustavo F. Padovan 2879300b962eSAnderson Lizardo if (conn->mtu < L2CAP_HDR_SIZE + L2CAP_CMD_HDR_SIZE) 2880300b962eSAnderson Lizardo return NULL; 2881300b962eSAnderson Lizardo 28820a708f8fSGustavo F. Padovan len = L2CAP_HDR_SIZE + L2CAP_CMD_HDR_SIZE + dlen; 28830a708f8fSGustavo F. Padovan count = min_t(unsigned int, conn->mtu, len); 28840a708f8fSGustavo F. Padovan 28858bcde1f2SGustavo Padovan skb = bt_skb_alloc(count, GFP_KERNEL); 28860a708f8fSGustavo F. Padovan if (!skb) 28870a708f8fSGustavo F. Padovan return NULL; 28880a708f8fSGustavo F. Padovan 28890a708f8fSGustavo F. Padovan lh = (struct l2cap_hdr *) skb_put(skb, L2CAP_HDR_SIZE); 28900a708f8fSGustavo F. Padovan lh->len = cpu_to_le16(L2CAP_CMD_HDR_SIZE + dlen); 28913300d9a9SClaudio Takahasi 28923300d9a9SClaudio Takahasi if (conn->hcon->type == LE_LINK) 2893ac73498cSAndrei Emeltchenko lh->cid = __constant_cpu_to_le16(L2CAP_CID_LE_SIGNALING); 28943300d9a9SClaudio Takahasi else 2895ac73498cSAndrei Emeltchenko lh->cid = __constant_cpu_to_le16(L2CAP_CID_SIGNALING); 28960a708f8fSGustavo F. Padovan 28970a708f8fSGustavo F. Padovan cmd = (struct l2cap_cmd_hdr *) skb_put(skb, L2CAP_CMD_HDR_SIZE); 28980a708f8fSGustavo F. Padovan cmd->code = code; 28990a708f8fSGustavo F. Padovan cmd->ident = ident; 29000a708f8fSGustavo F. Padovan cmd->len = cpu_to_le16(dlen); 29010a708f8fSGustavo F. Padovan 29020a708f8fSGustavo F. Padovan if (dlen) { 29030a708f8fSGustavo F. Padovan count -= L2CAP_HDR_SIZE + L2CAP_CMD_HDR_SIZE; 29040a708f8fSGustavo F. Padovan memcpy(skb_put(skb, count), data, count); 29050a708f8fSGustavo F. Padovan data += count; 29060a708f8fSGustavo F. Padovan } 29070a708f8fSGustavo F. Padovan 29080a708f8fSGustavo F. Padovan len -= skb->len; 29090a708f8fSGustavo F. Padovan 29100a708f8fSGustavo F. Padovan /* Continuation fragments (no L2CAP header) */ 29110a708f8fSGustavo F. Padovan frag = &skb_shinfo(skb)->frag_list; 29120a708f8fSGustavo F. Padovan while (len) { 29130a708f8fSGustavo F. Padovan count = min_t(unsigned int, conn->mtu, len); 29140a708f8fSGustavo F. Padovan 29158bcde1f2SGustavo Padovan *frag = bt_skb_alloc(count, GFP_KERNEL); 29160a708f8fSGustavo F. Padovan if (!*frag) 29170a708f8fSGustavo F. Padovan goto fail; 29180a708f8fSGustavo F. Padovan 29190a708f8fSGustavo F. Padovan memcpy(skb_put(*frag, count), data, count); 29200a708f8fSGustavo F. Padovan 29210a708f8fSGustavo F. Padovan len -= count; 29220a708f8fSGustavo F. Padovan data += count; 29230a708f8fSGustavo F. Padovan 29240a708f8fSGustavo F. Padovan frag = &(*frag)->next; 29250a708f8fSGustavo F. Padovan } 29260a708f8fSGustavo F. Padovan 29270a708f8fSGustavo F. Padovan return skb; 29280a708f8fSGustavo F. Padovan 29290a708f8fSGustavo F. Padovan fail: 29300a708f8fSGustavo F. Padovan kfree_skb(skb); 29310a708f8fSGustavo F. Padovan return NULL; 29320a708f8fSGustavo F. Padovan } 29330a708f8fSGustavo F. Padovan 29342d792818SGustavo Padovan static inline int l2cap_get_conf_opt(void **ptr, int *type, int *olen, 29352d792818SGustavo Padovan unsigned long *val) 29360a708f8fSGustavo F. Padovan { 29370a708f8fSGustavo F. Padovan struct l2cap_conf_opt *opt = *ptr; 29380a708f8fSGustavo F. Padovan int len; 29390a708f8fSGustavo F. Padovan 29400a708f8fSGustavo F. Padovan len = L2CAP_CONF_OPT_SIZE + opt->len; 29410a708f8fSGustavo F. Padovan *ptr += len; 29420a708f8fSGustavo F. Padovan 29430a708f8fSGustavo F. Padovan *type = opt->type; 29440a708f8fSGustavo F. Padovan *olen = opt->len; 29450a708f8fSGustavo F. Padovan 29460a708f8fSGustavo F. Padovan switch (opt->len) { 29470a708f8fSGustavo F. Padovan case 1: 29480a708f8fSGustavo F. Padovan *val = *((u8 *) opt->val); 29490a708f8fSGustavo F. Padovan break; 29500a708f8fSGustavo F. Padovan 29510a708f8fSGustavo F. Padovan case 2: 29520a708f8fSGustavo F. Padovan *val = get_unaligned_le16(opt->val); 29530a708f8fSGustavo F. Padovan break; 29540a708f8fSGustavo F. Padovan 29550a708f8fSGustavo F. Padovan case 4: 29560a708f8fSGustavo F. Padovan *val = get_unaligned_le32(opt->val); 29570a708f8fSGustavo F. Padovan break; 29580a708f8fSGustavo F. Padovan 29590a708f8fSGustavo F. Padovan default: 29600a708f8fSGustavo F. Padovan *val = (unsigned long) opt->val; 29610a708f8fSGustavo F. Padovan break; 29620a708f8fSGustavo F. Padovan } 29630a708f8fSGustavo F. Padovan 2964b4400672SAndrei Emeltchenko BT_DBG("type 0x%2.2x len %u val 0x%lx", *type, opt->len, *val); 29650a708f8fSGustavo F. Padovan return len; 29660a708f8fSGustavo F. Padovan } 29670a708f8fSGustavo F. Padovan 29680a708f8fSGustavo F. Padovan static void l2cap_add_conf_opt(void **ptr, u8 type, u8 len, unsigned long val) 29690a708f8fSGustavo F. Padovan { 29700a708f8fSGustavo F. Padovan struct l2cap_conf_opt *opt = *ptr; 29710a708f8fSGustavo F. Padovan 2972b4400672SAndrei Emeltchenko BT_DBG("type 0x%2.2x len %u val 0x%lx", type, len, val); 29730a708f8fSGustavo F. Padovan 29740a708f8fSGustavo F. Padovan opt->type = type; 29750a708f8fSGustavo F. Padovan opt->len = len; 29760a708f8fSGustavo F. Padovan 29770a708f8fSGustavo F. Padovan switch (len) { 29780a708f8fSGustavo F. Padovan case 1: 29790a708f8fSGustavo F. Padovan *((u8 *) opt->val) = val; 29800a708f8fSGustavo F. Padovan break; 29810a708f8fSGustavo F. Padovan 29820a708f8fSGustavo F. Padovan case 2: 29830a708f8fSGustavo F. Padovan put_unaligned_le16(val, opt->val); 29840a708f8fSGustavo F. Padovan break; 29850a708f8fSGustavo F. Padovan 29860a708f8fSGustavo F. Padovan case 4: 29870a708f8fSGustavo F. Padovan put_unaligned_le32(val, opt->val); 29880a708f8fSGustavo F. Padovan break; 29890a708f8fSGustavo F. Padovan 29900a708f8fSGustavo F. Padovan default: 29910a708f8fSGustavo F. Padovan memcpy(opt->val, (void *) val, len); 29920a708f8fSGustavo F. Padovan break; 29930a708f8fSGustavo F. Padovan } 29940a708f8fSGustavo F. Padovan 29950a708f8fSGustavo F. Padovan *ptr += L2CAP_CONF_OPT_SIZE + len; 29960a708f8fSGustavo F. Padovan } 29970a708f8fSGustavo F. Padovan 2998f89cef09SAndrei Emeltchenko static void l2cap_add_opt_efs(void **ptr, struct l2cap_chan *chan) 2999f89cef09SAndrei Emeltchenko { 3000f89cef09SAndrei Emeltchenko struct l2cap_conf_efs efs; 3001f89cef09SAndrei Emeltchenko 3002f89cef09SAndrei Emeltchenko switch (chan->mode) { 3003f89cef09SAndrei Emeltchenko case L2CAP_MODE_ERTM: 3004f89cef09SAndrei Emeltchenko efs.id = chan->local_id; 3005f89cef09SAndrei Emeltchenko efs.stype = chan->local_stype; 3006f89cef09SAndrei Emeltchenko efs.msdu = cpu_to_le16(chan->local_msdu); 3007f89cef09SAndrei Emeltchenko efs.sdu_itime = cpu_to_le32(chan->local_sdu_itime); 3008ac73498cSAndrei Emeltchenko efs.acc_lat = __constant_cpu_to_le32(L2CAP_DEFAULT_ACC_LAT); 30098936fa6dSAndrei Emeltchenko efs.flush_to = __constant_cpu_to_le32(L2CAP_EFS_DEFAULT_FLUSH_TO); 3010f89cef09SAndrei Emeltchenko break; 3011f89cef09SAndrei Emeltchenko 3012f89cef09SAndrei Emeltchenko case L2CAP_MODE_STREAMING: 3013f89cef09SAndrei Emeltchenko efs.id = 1; 3014f89cef09SAndrei Emeltchenko efs.stype = L2CAP_SERV_BESTEFFORT; 3015f89cef09SAndrei Emeltchenko efs.msdu = cpu_to_le16(chan->local_msdu); 3016f89cef09SAndrei Emeltchenko efs.sdu_itime = cpu_to_le32(chan->local_sdu_itime); 3017f89cef09SAndrei Emeltchenko efs.acc_lat = 0; 3018f89cef09SAndrei Emeltchenko efs.flush_to = 0; 3019f89cef09SAndrei Emeltchenko break; 3020f89cef09SAndrei Emeltchenko 3021f89cef09SAndrei Emeltchenko default: 3022f89cef09SAndrei Emeltchenko return; 3023f89cef09SAndrei Emeltchenko } 3024f89cef09SAndrei Emeltchenko 3025f89cef09SAndrei Emeltchenko l2cap_add_conf_opt(ptr, L2CAP_CONF_EFS, sizeof(efs), 3026f89cef09SAndrei Emeltchenko (unsigned long) &efs); 3027f89cef09SAndrei Emeltchenko } 3028f89cef09SAndrei Emeltchenko 3029721c4181SGustavo F. Padovan static void l2cap_ack_timeout(struct work_struct *work) 30300a708f8fSGustavo F. Padovan { 3031721c4181SGustavo F. Padovan struct l2cap_chan *chan = container_of(work, struct l2cap_chan, 3032721c4181SGustavo F. Padovan ack_timer.work); 30330362520bSMat Martineau u16 frames_to_ack; 30340a708f8fSGustavo F. Padovan 30352fb9b3d4SGustavo F. Padovan BT_DBG("chan %p", chan); 30362fb9b3d4SGustavo F. Padovan 30376be36555SAndrei Emeltchenko l2cap_chan_lock(chan); 30386be36555SAndrei Emeltchenko 30390362520bSMat Martineau frames_to_ack = __seq_offset(chan, chan->buffer_seq, 30400362520bSMat Martineau chan->last_acked_seq); 30410362520bSMat Martineau 30420362520bSMat Martineau if (frames_to_ack) 30430362520bSMat Martineau l2cap_send_rr_or_rnr(chan, 0); 30446be36555SAndrei Emeltchenko 30456be36555SAndrei Emeltchenko l2cap_chan_unlock(chan); 304609bfb2eeSSzymon Janc l2cap_chan_put(chan); 30470a708f8fSGustavo F. Padovan } 30480a708f8fSGustavo F. Padovan 3049466f8004SAndrei Emeltchenko int l2cap_ertm_init(struct l2cap_chan *chan) 30500a708f8fSGustavo F. Padovan { 30513c588192SMat Martineau int err; 30523c588192SMat Martineau 3053105bdf9eSMat Martineau chan->next_tx_seq = 0; 3054105bdf9eSMat Martineau chan->expected_tx_seq = 0; 305542e5c802SGustavo F. Padovan chan->expected_ack_seq = 0; 30566a026610SGustavo F. Padovan chan->unacked_frames = 0; 305742e5c802SGustavo F. Padovan chan->buffer_seq = 0; 30586a026610SGustavo F. Padovan chan->frames_sent = 0; 3059105bdf9eSMat Martineau chan->last_acked_seq = 0; 3060105bdf9eSMat Martineau chan->sdu = NULL; 3061105bdf9eSMat Martineau chan->sdu_last_frag = NULL; 3062105bdf9eSMat Martineau chan->sdu_len = 0; 3063105bdf9eSMat Martineau 3064d34c34fbSMat Martineau skb_queue_head_init(&chan->tx_q); 3065d34c34fbSMat Martineau 30666ed971caSMarcel Holtmann chan->local_amp_id = AMP_ID_BREDR; 30676ed971caSMarcel Holtmann chan->move_id = AMP_ID_BREDR; 306808333283SMat Martineau chan->move_state = L2CAP_MOVE_STABLE; 306908333283SMat Martineau chan->move_role = L2CAP_MOVE_ROLE_NONE; 307008333283SMat Martineau 3071105bdf9eSMat Martineau if (chan->mode != L2CAP_MODE_ERTM) 3072105bdf9eSMat Martineau return 0; 3073105bdf9eSMat Martineau 3074105bdf9eSMat Martineau chan->rx_state = L2CAP_RX_STATE_RECV; 3075105bdf9eSMat Martineau chan->tx_state = L2CAP_TX_STATE_XMIT; 30760a708f8fSGustavo F. Padovan 3077721c4181SGustavo F. Padovan INIT_DELAYED_WORK(&chan->retrans_timer, l2cap_retrans_timeout); 3078721c4181SGustavo F. Padovan INIT_DELAYED_WORK(&chan->monitor_timer, l2cap_monitor_timeout); 3079721c4181SGustavo F. Padovan INIT_DELAYED_WORK(&chan->ack_timer, l2cap_ack_timeout); 30800a708f8fSGustavo F. Padovan 3081f1c6775bSGustavo F. Padovan skb_queue_head_init(&chan->srej_q); 30820a708f8fSGustavo F. Padovan 30833c588192SMat Martineau err = l2cap_seq_list_init(&chan->srej_list, chan->tx_win); 30843c588192SMat Martineau if (err < 0) 30853c588192SMat Martineau return err; 30863c588192SMat Martineau 30879dc9affcSMat Martineau err = l2cap_seq_list_init(&chan->retrans_list, chan->remote_tx_win); 30889dc9affcSMat Martineau if (err < 0) 30899dc9affcSMat Martineau l2cap_seq_list_free(&chan->srej_list); 30909dc9affcSMat Martineau 30919dc9affcSMat Martineau return err; 30920a708f8fSGustavo F. Padovan } 30930a708f8fSGustavo F. Padovan 30940a708f8fSGustavo F. Padovan static inline __u8 l2cap_select_mode(__u8 mode, __u16 remote_feat_mask) 30950a708f8fSGustavo F. Padovan { 30960a708f8fSGustavo F. Padovan switch (mode) { 30970a708f8fSGustavo F. Padovan case L2CAP_MODE_STREAMING: 30980a708f8fSGustavo F. Padovan case L2CAP_MODE_ERTM: 30990a708f8fSGustavo F. Padovan if (l2cap_mode_supported(mode, remote_feat_mask)) 31000a708f8fSGustavo F. Padovan return mode; 31010a708f8fSGustavo F. Padovan /* fall through */ 31020a708f8fSGustavo F. Padovan default: 31030a708f8fSGustavo F. Padovan return L2CAP_MODE_BASIC; 31040a708f8fSGustavo F. Padovan } 31050a708f8fSGustavo F. Padovan } 31060a708f8fSGustavo F. Padovan 3107848566b3SMarcel Holtmann static inline bool __l2cap_ews_supported(struct l2cap_conn *conn) 31086327eb98SAndrei Emeltchenko { 3109848566b3SMarcel Holtmann return conn->hs_enabled && conn->feat_mask & L2CAP_FEAT_EXT_WINDOW; 31106327eb98SAndrei Emeltchenko } 31116327eb98SAndrei Emeltchenko 3112848566b3SMarcel Holtmann static inline bool __l2cap_efs_supported(struct l2cap_conn *conn) 3113f89cef09SAndrei Emeltchenko { 3114848566b3SMarcel Holtmann return conn->hs_enabled && conn->feat_mask & L2CAP_FEAT_EXT_FLOW; 3115f89cef09SAndrei Emeltchenko } 3116f89cef09SAndrei Emeltchenko 311736c86c85SMat Martineau static void __l2cap_set_ertm_timeouts(struct l2cap_chan *chan, 311836c86c85SMat Martineau struct l2cap_conf_rfc *rfc) 311936c86c85SMat Martineau { 31206ed971caSMarcel Holtmann if (chan->local_amp_id != AMP_ID_BREDR && chan->hs_hcon) { 312136c86c85SMat Martineau u64 ertm_to = chan->hs_hcon->hdev->amp_be_flush_to; 312236c86c85SMat Martineau 312336c86c85SMat Martineau /* Class 1 devices have must have ERTM timeouts 312436c86c85SMat Martineau * exceeding the Link Supervision Timeout. The 312536c86c85SMat Martineau * default Link Supervision Timeout for AMP 312636c86c85SMat Martineau * controllers is 10 seconds. 312736c86c85SMat Martineau * 312836c86c85SMat Martineau * Class 1 devices use 0xffffffff for their 312936c86c85SMat Martineau * best-effort flush timeout, so the clamping logic 313036c86c85SMat Martineau * will result in a timeout that meets the above 313136c86c85SMat Martineau * requirement. ERTM timeouts are 16-bit values, so 313236c86c85SMat Martineau * the maximum timeout is 65.535 seconds. 313336c86c85SMat Martineau */ 313436c86c85SMat Martineau 313536c86c85SMat Martineau /* Convert timeout to milliseconds and round */ 313636c86c85SMat Martineau ertm_to = DIV_ROUND_UP_ULL(ertm_to, 1000); 313736c86c85SMat Martineau 313836c86c85SMat Martineau /* This is the recommended formula for class 2 devices 313936c86c85SMat Martineau * that start ERTM timers when packets are sent to the 314036c86c85SMat Martineau * controller. 314136c86c85SMat Martineau */ 314236c86c85SMat Martineau ertm_to = 3 * ertm_to + 500; 314336c86c85SMat Martineau 314436c86c85SMat Martineau if (ertm_to > 0xffff) 314536c86c85SMat Martineau ertm_to = 0xffff; 314636c86c85SMat Martineau 314736c86c85SMat Martineau rfc->retrans_timeout = cpu_to_le16((u16) ertm_to); 314836c86c85SMat Martineau rfc->monitor_timeout = rfc->retrans_timeout; 314936c86c85SMat Martineau } else { 315036c86c85SMat Martineau rfc->retrans_timeout = __constant_cpu_to_le16(L2CAP_DEFAULT_RETRANS_TO); 315136c86c85SMat Martineau rfc->monitor_timeout = __constant_cpu_to_le16(L2CAP_DEFAULT_MONITOR_TO); 315236c86c85SMat Martineau } 315336c86c85SMat Martineau } 315436c86c85SMat Martineau 31556327eb98SAndrei Emeltchenko static inline void l2cap_txwin_setup(struct l2cap_chan *chan) 31566327eb98SAndrei Emeltchenko { 31576327eb98SAndrei Emeltchenko if (chan->tx_win > L2CAP_DEFAULT_TX_WINDOW && 3158848566b3SMarcel Holtmann __l2cap_ews_supported(chan->conn)) { 31596327eb98SAndrei Emeltchenko /* use extended control field */ 31606327eb98SAndrei Emeltchenko set_bit(FLAG_EXT_CTRL, &chan->flags); 3161836be934SAndrei Emeltchenko chan->tx_win_max = L2CAP_DEFAULT_EXT_WINDOW; 3162836be934SAndrei Emeltchenko } else { 31636327eb98SAndrei Emeltchenko chan->tx_win = min_t(u16, chan->tx_win, 31646327eb98SAndrei Emeltchenko L2CAP_DEFAULT_TX_WINDOW); 3165836be934SAndrei Emeltchenko chan->tx_win_max = L2CAP_DEFAULT_TX_WINDOW; 3166836be934SAndrei Emeltchenko } 3167c20f8e35SMat Martineau chan->ack_win = chan->tx_win; 31686327eb98SAndrei Emeltchenko } 31696327eb98SAndrei Emeltchenko 3170710f9b0aSGustavo F. Padovan static int l2cap_build_conf_req(struct l2cap_chan *chan, void *data) 31710a708f8fSGustavo F. Padovan { 31720a708f8fSGustavo F. Padovan struct l2cap_conf_req *req = data; 31730c1bc5c6SGustavo F. Padovan struct l2cap_conf_rfc rfc = { .mode = chan->mode }; 31740a708f8fSGustavo F. Padovan void *ptr = req->data; 3175c8f79162SAndrei Emeltchenko u16 size; 31760a708f8fSGustavo F. Padovan 317749208c9cSGustavo F. Padovan BT_DBG("chan %p", chan); 31780a708f8fSGustavo F. Padovan 317973ffa904SGustavo F. Padovan if (chan->num_conf_req || chan->num_conf_rsp) 31800a708f8fSGustavo F. Padovan goto done; 31810a708f8fSGustavo F. Padovan 31820c1bc5c6SGustavo F. Padovan switch (chan->mode) { 31830a708f8fSGustavo F. Padovan case L2CAP_MODE_STREAMING: 31840a708f8fSGustavo F. Padovan case L2CAP_MODE_ERTM: 3185c1360a1cSGustavo F. Padovan if (test_bit(CONF_STATE2_DEVICE, &chan->conf_state)) 31860a708f8fSGustavo F. Padovan break; 31870a708f8fSGustavo F. Padovan 3188848566b3SMarcel Holtmann if (__l2cap_efs_supported(chan->conn)) 3189f89cef09SAndrei Emeltchenko set_bit(FLAG_EFS_ENABLE, &chan->flags); 3190f89cef09SAndrei Emeltchenko 31910a708f8fSGustavo F. Padovan /* fall through */ 31920a708f8fSGustavo F. Padovan default: 31938c1d787bSGustavo F. Padovan chan->mode = l2cap_select_mode(rfc.mode, chan->conn->feat_mask); 31940a708f8fSGustavo F. Padovan break; 31950a708f8fSGustavo F. Padovan } 31960a708f8fSGustavo F. Padovan 31970a708f8fSGustavo F. Padovan done: 31980c1bc5c6SGustavo F. Padovan if (chan->imtu != L2CAP_DEFAULT_MTU) 31990c1bc5c6SGustavo F. Padovan l2cap_add_conf_opt(&ptr, L2CAP_CONF_MTU, 2, chan->imtu); 32000a708f8fSGustavo F. Padovan 32010c1bc5c6SGustavo F. Padovan switch (chan->mode) { 32020a708f8fSGustavo F. Padovan case L2CAP_MODE_BASIC: 32038c1d787bSGustavo F. Padovan if (!(chan->conn->feat_mask & L2CAP_FEAT_ERTM) && 32048c1d787bSGustavo F. Padovan !(chan->conn->feat_mask & L2CAP_FEAT_STREAMING)) 32050a708f8fSGustavo F. Padovan break; 32060a708f8fSGustavo F. Padovan 32070a708f8fSGustavo F. Padovan rfc.mode = L2CAP_MODE_BASIC; 32080a708f8fSGustavo F. Padovan rfc.txwin_size = 0; 32090a708f8fSGustavo F. Padovan rfc.max_transmit = 0; 32100a708f8fSGustavo F. Padovan rfc.retrans_timeout = 0; 32110a708f8fSGustavo F. Padovan rfc.monitor_timeout = 0; 32120a708f8fSGustavo F. Padovan rfc.max_pdu_size = 0; 32130a708f8fSGustavo F. Padovan 32140a708f8fSGustavo F. Padovan l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC, sizeof(rfc), 32150a708f8fSGustavo F. Padovan (unsigned long) &rfc); 32160a708f8fSGustavo F. Padovan break; 32170a708f8fSGustavo F. Padovan 32180a708f8fSGustavo F. Padovan case L2CAP_MODE_ERTM: 32190a708f8fSGustavo F. Padovan rfc.mode = L2CAP_MODE_ERTM; 322047d1ec61SGustavo F. Padovan rfc.max_transmit = chan->max_tx; 322136c86c85SMat Martineau 322236c86c85SMat Martineau __l2cap_set_ertm_timeouts(chan, &rfc); 3223c8f79162SAndrei Emeltchenko 3224c8f79162SAndrei Emeltchenko size = min_t(u16, L2CAP_DEFAULT_MAX_PDU_SIZE, chan->conn->mtu - 32252d792818SGustavo Padovan L2CAP_EXT_HDR_SIZE - L2CAP_SDULEN_SIZE - 3226c8f79162SAndrei Emeltchenko L2CAP_FCS_SIZE); 3227c8f79162SAndrei Emeltchenko rfc.max_pdu_size = cpu_to_le16(size); 32280a708f8fSGustavo F. Padovan 32296327eb98SAndrei Emeltchenko l2cap_txwin_setup(chan); 32306327eb98SAndrei Emeltchenko 32316327eb98SAndrei Emeltchenko rfc.txwin_size = min_t(u16, chan->tx_win, 32326327eb98SAndrei Emeltchenko L2CAP_DEFAULT_TX_WINDOW); 32330a708f8fSGustavo F. Padovan 32340a708f8fSGustavo F. Padovan l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC, sizeof(rfc), 32350a708f8fSGustavo F. Padovan (unsigned long) &rfc); 32360a708f8fSGustavo F. Padovan 3237f89cef09SAndrei Emeltchenko if (test_bit(FLAG_EFS_ENABLE, &chan->flags)) 3238f89cef09SAndrei Emeltchenko l2cap_add_opt_efs(&ptr, chan); 3239f89cef09SAndrei Emeltchenko 32406327eb98SAndrei Emeltchenko if (test_bit(FLAG_EXT_CTRL, &chan->flags)) 32416327eb98SAndrei Emeltchenko l2cap_add_conf_opt(&ptr, L2CAP_CONF_EWS, 2, 32426327eb98SAndrei Emeltchenko chan->tx_win); 324360918918SAndrei Emeltchenko 324460918918SAndrei Emeltchenko if (chan->conn->feat_mask & L2CAP_FEAT_FCS) 324560918918SAndrei Emeltchenko if (chan->fcs == L2CAP_FCS_NONE || 3246f2592d3eSAndrei Emeltchenko test_bit(CONF_RECV_NO_FCS, &chan->conf_state)) { 324760918918SAndrei Emeltchenko chan->fcs = L2CAP_FCS_NONE; 324860918918SAndrei Emeltchenko l2cap_add_conf_opt(&ptr, L2CAP_CONF_FCS, 1, 324960918918SAndrei Emeltchenko chan->fcs); 325060918918SAndrei Emeltchenko } 32510a708f8fSGustavo F. Padovan break; 32520a708f8fSGustavo F. Padovan 32530a708f8fSGustavo F. Padovan case L2CAP_MODE_STREAMING: 3254273759e2SMat Martineau l2cap_txwin_setup(chan); 32550a708f8fSGustavo F. Padovan rfc.mode = L2CAP_MODE_STREAMING; 32560a708f8fSGustavo F. Padovan rfc.txwin_size = 0; 32570a708f8fSGustavo F. Padovan rfc.max_transmit = 0; 32580a708f8fSGustavo F. Padovan rfc.retrans_timeout = 0; 32590a708f8fSGustavo F. Padovan rfc.monitor_timeout = 0; 3260c8f79162SAndrei Emeltchenko 3261c8f79162SAndrei Emeltchenko size = min_t(u16, L2CAP_DEFAULT_MAX_PDU_SIZE, chan->conn->mtu - 32622d792818SGustavo Padovan L2CAP_EXT_HDR_SIZE - L2CAP_SDULEN_SIZE - 3263c8f79162SAndrei Emeltchenko L2CAP_FCS_SIZE); 3264c8f79162SAndrei Emeltchenko rfc.max_pdu_size = cpu_to_le16(size); 32650a708f8fSGustavo F. Padovan 32660a708f8fSGustavo F. Padovan l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC, sizeof(rfc), 32670a708f8fSGustavo F. Padovan (unsigned long) &rfc); 32680a708f8fSGustavo F. Padovan 3269f89cef09SAndrei Emeltchenko if (test_bit(FLAG_EFS_ENABLE, &chan->flags)) 3270f89cef09SAndrei Emeltchenko l2cap_add_opt_efs(&ptr, chan); 3271f89cef09SAndrei Emeltchenko 327260918918SAndrei Emeltchenko if (chan->conn->feat_mask & L2CAP_FEAT_FCS) 327347d1ec61SGustavo F. Padovan if (chan->fcs == L2CAP_FCS_NONE || 3274f2592d3eSAndrei Emeltchenko test_bit(CONF_RECV_NO_FCS, &chan->conf_state)) { 327547d1ec61SGustavo F. Padovan chan->fcs = L2CAP_FCS_NONE; 327660918918SAndrei Emeltchenko l2cap_add_conf_opt(&ptr, L2CAP_CONF_FCS, 1, 327760918918SAndrei Emeltchenko chan->fcs); 32780a708f8fSGustavo F. Padovan } 32790a708f8fSGustavo F. Padovan break; 32800a708f8fSGustavo F. Padovan } 32810a708f8fSGustavo F. Padovan 3282fe4128e0SGustavo F. Padovan req->dcid = cpu_to_le16(chan->dcid); 328359e54bd1SAndrei Emeltchenko req->flags = __constant_cpu_to_le16(0); 32840a708f8fSGustavo F. Padovan 32850a708f8fSGustavo F. Padovan return ptr - data; 32860a708f8fSGustavo F. Padovan } 32870a708f8fSGustavo F. Padovan 328873ffa904SGustavo F. Padovan static int l2cap_parse_conf_req(struct l2cap_chan *chan, void *data) 32890a708f8fSGustavo F. Padovan { 32900a708f8fSGustavo F. Padovan struct l2cap_conf_rsp *rsp = data; 32910a708f8fSGustavo F. Padovan void *ptr = rsp->data; 329273ffa904SGustavo F. Padovan void *req = chan->conf_req; 329373ffa904SGustavo F. Padovan int len = chan->conf_len; 32940a708f8fSGustavo F. Padovan int type, hint, olen; 32950a708f8fSGustavo F. Padovan unsigned long val; 32960a708f8fSGustavo F. Padovan struct l2cap_conf_rfc rfc = { .mode = L2CAP_MODE_BASIC }; 329742dceae2SAndrei Emeltchenko struct l2cap_conf_efs efs; 329842dceae2SAndrei Emeltchenko u8 remote_efs = 0; 32990a708f8fSGustavo F. Padovan u16 mtu = L2CAP_DEFAULT_MTU; 33000a708f8fSGustavo F. Padovan u16 result = L2CAP_CONF_SUCCESS; 3301c8f79162SAndrei Emeltchenko u16 size; 33020a708f8fSGustavo F. Padovan 330373ffa904SGustavo F. Padovan BT_DBG("chan %p", chan); 33040a708f8fSGustavo F. Padovan 33050a708f8fSGustavo F. Padovan while (len >= L2CAP_CONF_OPT_SIZE) { 33060a708f8fSGustavo F. Padovan len -= l2cap_get_conf_opt(&req, &type, &olen, &val); 33070a708f8fSGustavo F. Padovan 33080a708f8fSGustavo F. Padovan hint = type & L2CAP_CONF_HINT; 33090a708f8fSGustavo F. Padovan type &= L2CAP_CONF_MASK; 33100a708f8fSGustavo F. Padovan 33110a708f8fSGustavo F. Padovan switch (type) { 33120a708f8fSGustavo F. Padovan case L2CAP_CONF_MTU: 33130a708f8fSGustavo F. Padovan mtu = val; 33140a708f8fSGustavo F. Padovan break; 33150a708f8fSGustavo F. Padovan 33160a708f8fSGustavo F. Padovan case L2CAP_CONF_FLUSH_TO: 33170c1bc5c6SGustavo F. Padovan chan->flush_to = val; 33180a708f8fSGustavo F. Padovan break; 33190a708f8fSGustavo F. Padovan 33200a708f8fSGustavo F. Padovan case L2CAP_CONF_QOS: 33210a708f8fSGustavo F. Padovan break; 33220a708f8fSGustavo F. Padovan 33230a708f8fSGustavo F. Padovan case L2CAP_CONF_RFC: 33240a708f8fSGustavo F. Padovan if (olen == sizeof(rfc)) 33250a708f8fSGustavo F. Padovan memcpy(&rfc, (void *) val, olen); 33260a708f8fSGustavo F. Padovan break; 33270a708f8fSGustavo F. Padovan 33280a708f8fSGustavo F. Padovan case L2CAP_CONF_FCS: 33290a708f8fSGustavo F. Padovan if (val == L2CAP_FCS_NONE) 3330f2592d3eSAndrei Emeltchenko set_bit(CONF_RECV_NO_FCS, &chan->conf_state); 333142dceae2SAndrei Emeltchenko break; 33320a708f8fSGustavo F. Padovan 333342dceae2SAndrei Emeltchenko case L2CAP_CONF_EFS: 333442dceae2SAndrei Emeltchenko remote_efs = 1; 333542dceae2SAndrei Emeltchenko if (olen == sizeof(efs)) 333642dceae2SAndrei Emeltchenko memcpy(&efs, (void *) val, olen); 33370a708f8fSGustavo F. Padovan break; 33380a708f8fSGustavo F. Padovan 33396327eb98SAndrei Emeltchenko case L2CAP_CONF_EWS: 3340848566b3SMarcel Holtmann if (!chan->conn->hs_enabled) 33416327eb98SAndrei Emeltchenko return -ECONNREFUSED; 33426327eb98SAndrei Emeltchenko 33436327eb98SAndrei Emeltchenko set_bit(FLAG_EXT_CTRL, &chan->flags); 33446327eb98SAndrei Emeltchenko set_bit(CONF_EWS_RECV, &chan->conf_state); 3345836be934SAndrei Emeltchenko chan->tx_win_max = L2CAP_DEFAULT_EXT_WINDOW; 33466327eb98SAndrei Emeltchenko chan->remote_tx_win = val; 33470a708f8fSGustavo F. Padovan break; 33480a708f8fSGustavo F. Padovan 33490a708f8fSGustavo F. Padovan default: 33500a708f8fSGustavo F. Padovan if (hint) 33510a708f8fSGustavo F. Padovan break; 33520a708f8fSGustavo F. Padovan 33530a708f8fSGustavo F. Padovan result = L2CAP_CONF_UNKNOWN; 33540a708f8fSGustavo F. Padovan *((u8 *) ptr++) = type; 33550a708f8fSGustavo F. Padovan break; 33560a708f8fSGustavo F. Padovan } 33570a708f8fSGustavo F. Padovan } 33580a708f8fSGustavo F. Padovan 335973ffa904SGustavo F. Padovan if (chan->num_conf_rsp || chan->num_conf_req > 1) 33600a708f8fSGustavo F. Padovan goto done; 33610a708f8fSGustavo F. Padovan 33620c1bc5c6SGustavo F. Padovan switch (chan->mode) { 33630a708f8fSGustavo F. Padovan case L2CAP_MODE_STREAMING: 33640a708f8fSGustavo F. Padovan case L2CAP_MODE_ERTM: 3365c1360a1cSGustavo F. Padovan if (!test_bit(CONF_STATE2_DEVICE, &chan->conf_state)) { 33660c1bc5c6SGustavo F. Padovan chan->mode = l2cap_select_mode(rfc.mode, 33678c1d787bSGustavo F. Padovan chan->conn->feat_mask); 33680a708f8fSGustavo F. Padovan break; 33690a708f8fSGustavo F. Padovan } 33700a708f8fSGustavo F. Padovan 337142dceae2SAndrei Emeltchenko if (remote_efs) { 3372848566b3SMarcel Holtmann if (__l2cap_efs_supported(chan->conn)) 337342dceae2SAndrei Emeltchenko set_bit(FLAG_EFS_ENABLE, &chan->flags); 337442dceae2SAndrei Emeltchenko else 337542dceae2SAndrei Emeltchenko return -ECONNREFUSED; 337642dceae2SAndrei Emeltchenko } 337742dceae2SAndrei Emeltchenko 33780c1bc5c6SGustavo F. Padovan if (chan->mode != rfc.mode) 33790a708f8fSGustavo F. Padovan return -ECONNREFUSED; 33800a708f8fSGustavo F. Padovan 33810a708f8fSGustavo F. Padovan break; 33820a708f8fSGustavo F. Padovan } 33830a708f8fSGustavo F. Padovan 33840a708f8fSGustavo F. Padovan done: 33850c1bc5c6SGustavo F. Padovan if (chan->mode != rfc.mode) { 33860a708f8fSGustavo F. Padovan result = L2CAP_CONF_UNACCEPT; 33870c1bc5c6SGustavo F. Padovan rfc.mode = chan->mode; 33880a708f8fSGustavo F. Padovan 338973ffa904SGustavo F. Padovan if (chan->num_conf_rsp == 1) 33900a708f8fSGustavo F. Padovan return -ECONNREFUSED; 33910a708f8fSGustavo F. Padovan 33922d792818SGustavo Padovan l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC, sizeof(rfc), 33932d792818SGustavo Padovan (unsigned long) &rfc); 33940a708f8fSGustavo F. Padovan } 33950a708f8fSGustavo F. Padovan 33960a708f8fSGustavo F. Padovan if (result == L2CAP_CONF_SUCCESS) { 33970a708f8fSGustavo F. Padovan /* Configure output options and let the other side know 33980a708f8fSGustavo F. Padovan * which ones we don't like. */ 33990a708f8fSGustavo F. Padovan 34000a708f8fSGustavo F. Padovan if (mtu < L2CAP_DEFAULT_MIN_MTU) 34010a708f8fSGustavo F. Padovan result = L2CAP_CONF_UNACCEPT; 34020a708f8fSGustavo F. Padovan else { 34030c1bc5c6SGustavo F. Padovan chan->omtu = mtu; 3404c1360a1cSGustavo F. Padovan set_bit(CONF_MTU_DONE, &chan->conf_state); 34050a708f8fSGustavo F. Padovan } 34060c1bc5c6SGustavo F. Padovan l2cap_add_conf_opt(&ptr, L2CAP_CONF_MTU, 2, chan->omtu); 34070a708f8fSGustavo F. Padovan 340842dceae2SAndrei Emeltchenko if (remote_efs) { 340942dceae2SAndrei Emeltchenko if (chan->local_stype != L2CAP_SERV_NOTRAFIC && 341042dceae2SAndrei Emeltchenko efs.stype != L2CAP_SERV_NOTRAFIC && 341142dceae2SAndrei Emeltchenko efs.stype != chan->local_stype) { 341242dceae2SAndrei Emeltchenko 341342dceae2SAndrei Emeltchenko result = L2CAP_CONF_UNACCEPT; 341442dceae2SAndrei Emeltchenko 341542dceae2SAndrei Emeltchenko if (chan->num_conf_req >= 1) 341642dceae2SAndrei Emeltchenko return -ECONNREFUSED; 341742dceae2SAndrei Emeltchenko 341842dceae2SAndrei Emeltchenko l2cap_add_conf_opt(&ptr, L2CAP_CONF_EFS, 341942dceae2SAndrei Emeltchenko sizeof(efs), 342042dceae2SAndrei Emeltchenko (unsigned long) &efs); 34210e8b207eSAndrei Emeltchenko } else { 34223e6b3b95SGustavo F. Padovan /* Send PENDING Conf Rsp */ 34230e8b207eSAndrei Emeltchenko result = L2CAP_CONF_PENDING; 34240e8b207eSAndrei Emeltchenko set_bit(CONF_LOC_CONF_PEND, &chan->conf_state); 342542dceae2SAndrei Emeltchenko } 342642dceae2SAndrei Emeltchenko } 342742dceae2SAndrei Emeltchenko 34280a708f8fSGustavo F. Padovan switch (rfc.mode) { 34290a708f8fSGustavo F. Padovan case L2CAP_MODE_BASIC: 343047d1ec61SGustavo F. Padovan chan->fcs = L2CAP_FCS_NONE; 3431c1360a1cSGustavo F. Padovan set_bit(CONF_MODE_DONE, &chan->conf_state); 34320a708f8fSGustavo F. Padovan break; 34330a708f8fSGustavo F. Padovan 34340a708f8fSGustavo F. Padovan case L2CAP_MODE_ERTM: 34356327eb98SAndrei Emeltchenko if (!test_bit(CONF_EWS_RECV, &chan->conf_state)) 34362c03a7a4SGustavo F. Padovan chan->remote_tx_win = rfc.txwin_size; 34376327eb98SAndrei Emeltchenko else 34386327eb98SAndrei Emeltchenko rfc.txwin_size = L2CAP_DEFAULT_TX_WINDOW; 34396327eb98SAndrei Emeltchenko 34402c03a7a4SGustavo F. Padovan chan->remote_max_tx = rfc.max_transmit; 34410a708f8fSGustavo F. Padovan 3442c8f79162SAndrei Emeltchenko size = min_t(u16, le16_to_cpu(rfc.max_pdu_size), 34432d792818SGustavo Padovan chan->conn->mtu - L2CAP_EXT_HDR_SIZE - 34442d792818SGustavo Padovan L2CAP_SDULEN_SIZE - L2CAP_FCS_SIZE); 3445c8f79162SAndrei Emeltchenko rfc.max_pdu_size = cpu_to_le16(size); 3446c8f79162SAndrei Emeltchenko chan->remote_mps = size; 34470a708f8fSGustavo F. Padovan 344836c86c85SMat Martineau __l2cap_set_ertm_timeouts(chan, &rfc); 34490a708f8fSGustavo F. Padovan 3450c1360a1cSGustavo F. Padovan set_bit(CONF_MODE_DONE, &chan->conf_state); 34510a708f8fSGustavo F. Padovan 34520a708f8fSGustavo F. Padovan l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC, 34530a708f8fSGustavo F. Padovan sizeof(rfc), (unsigned long) &rfc); 34540a708f8fSGustavo F. Padovan 345542dceae2SAndrei Emeltchenko if (test_bit(FLAG_EFS_ENABLE, &chan->flags)) { 345642dceae2SAndrei Emeltchenko chan->remote_id = efs.id; 345742dceae2SAndrei Emeltchenko chan->remote_stype = efs.stype; 345842dceae2SAndrei Emeltchenko chan->remote_msdu = le16_to_cpu(efs.msdu); 345942dceae2SAndrei Emeltchenko chan->remote_flush_to = 346042dceae2SAndrei Emeltchenko le32_to_cpu(efs.flush_to); 346142dceae2SAndrei Emeltchenko chan->remote_acc_lat = 346242dceae2SAndrei Emeltchenko le32_to_cpu(efs.acc_lat); 346342dceae2SAndrei Emeltchenko chan->remote_sdu_itime = 346442dceae2SAndrei Emeltchenko le32_to_cpu(efs.sdu_itime); 346542dceae2SAndrei Emeltchenko l2cap_add_conf_opt(&ptr, L2CAP_CONF_EFS, 34662d792818SGustavo Padovan sizeof(efs), 34672d792818SGustavo Padovan (unsigned long) &efs); 346842dceae2SAndrei Emeltchenko } 34690a708f8fSGustavo F. Padovan break; 34700a708f8fSGustavo F. Padovan 34710a708f8fSGustavo F. Padovan case L2CAP_MODE_STREAMING: 3472c8f79162SAndrei Emeltchenko size = min_t(u16, le16_to_cpu(rfc.max_pdu_size), 34732d792818SGustavo Padovan chan->conn->mtu - L2CAP_EXT_HDR_SIZE - 34742d792818SGustavo Padovan L2CAP_SDULEN_SIZE - L2CAP_FCS_SIZE); 3475c8f79162SAndrei Emeltchenko rfc.max_pdu_size = cpu_to_le16(size); 3476c8f79162SAndrei Emeltchenko chan->remote_mps = size; 34770a708f8fSGustavo F. Padovan 3478c1360a1cSGustavo F. Padovan set_bit(CONF_MODE_DONE, &chan->conf_state); 34790a708f8fSGustavo F. Padovan 34802d792818SGustavo Padovan l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC, sizeof(rfc), 34812d792818SGustavo Padovan (unsigned long) &rfc); 34820a708f8fSGustavo F. Padovan 34830a708f8fSGustavo F. Padovan break; 34840a708f8fSGustavo F. Padovan 34850a708f8fSGustavo F. Padovan default: 34860a708f8fSGustavo F. Padovan result = L2CAP_CONF_UNACCEPT; 34870a708f8fSGustavo F. Padovan 34880a708f8fSGustavo F. Padovan memset(&rfc, 0, sizeof(rfc)); 34890c1bc5c6SGustavo F. Padovan rfc.mode = chan->mode; 34900a708f8fSGustavo F. Padovan } 34910a708f8fSGustavo F. Padovan 34920a708f8fSGustavo F. Padovan if (result == L2CAP_CONF_SUCCESS) 3493c1360a1cSGustavo F. Padovan set_bit(CONF_OUTPUT_DONE, &chan->conf_state); 34940a708f8fSGustavo F. Padovan } 3495fe4128e0SGustavo F. Padovan rsp->scid = cpu_to_le16(chan->dcid); 34960a708f8fSGustavo F. Padovan rsp->result = cpu_to_le16(result); 349759e54bd1SAndrei Emeltchenko rsp->flags = __constant_cpu_to_le16(0); 34980a708f8fSGustavo F. Padovan 34990a708f8fSGustavo F. Padovan return ptr - data; 35000a708f8fSGustavo F. Padovan } 35010a708f8fSGustavo F. Padovan 35022d792818SGustavo Padovan static int l2cap_parse_conf_rsp(struct l2cap_chan *chan, void *rsp, int len, 35032d792818SGustavo Padovan void *data, u16 *result) 35040a708f8fSGustavo F. Padovan { 35050a708f8fSGustavo F. Padovan struct l2cap_conf_req *req = data; 35060a708f8fSGustavo F. Padovan void *ptr = req->data; 35070a708f8fSGustavo F. Padovan int type, olen; 35080a708f8fSGustavo F. Padovan unsigned long val; 350936e999a8SMat Martineau struct l2cap_conf_rfc rfc = { .mode = L2CAP_MODE_BASIC }; 351066af7aafSAndrei Emeltchenko struct l2cap_conf_efs efs; 35110a708f8fSGustavo F. Padovan 3512fe4128e0SGustavo F. Padovan BT_DBG("chan %p, rsp %p, len %d, req %p", chan, rsp, len, data); 35130a708f8fSGustavo F. Padovan 35140a708f8fSGustavo F. Padovan while (len >= L2CAP_CONF_OPT_SIZE) { 35150a708f8fSGustavo F. Padovan len -= l2cap_get_conf_opt(&rsp, &type, &olen, &val); 35160a708f8fSGustavo F. Padovan 35170a708f8fSGustavo F. Padovan switch (type) { 35180a708f8fSGustavo F. Padovan case L2CAP_CONF_MTU: 35190a708f8fSGustavo F. Padovan if (val < L2CAP_DEFAULT_MIN_MTU) { 35200a708f8fSGustavo F. Padovan *result = L2CAP_CONF_UNACCEPT; 35210c1bc5c6SGustavo F. Padovan chan->imtu = L2CAP_DEFAULT_MIN_MTU; 35220a708f8fSGustavo F. Padovan } else 35230c1bc5c6SGustavo F. Padovan chan->imtu = val; 35240c1bc5c6SGustavo F. Padovan l2cap_add_conf_opt(&ptr, L2CAP_CONF_MTU, 2, chan->imtu); 35250a708f8fSGustavo F. Padovan break; 35260a708f8fSGustavo F. Padovan 35270a708f8fSGustavo F. Padovan case L2CAP_CONF_FLUSH_TO: 35280c1bc5c6SGustavo F. Padovan chan->flush_to = val; 35290a708f8fSGustavo F. Padovan l2cap_add_conf_opt(&ptr, L2CAP_CONF_FLUSH_TO, 35300c1bc5c6SGustavo F. Padovan 2, chan->flush_to); 35310a708f8fSGustavo F. Padovan break; 35320a708f8fSGustavo F. Padovan 35330a708f8fSGustavo F. Padovan case L2CAP_CONF_RFC: 35340a708f8fSGustavo F. Padovan if (olen == sizeof(rfc)) 35350a708f8fSGustavo F. Padovan memcpy(&rfc, (void *)val, olen); 35360a708f8fSGustavo F. Padovan 3537c1360a1cSGustavo F. Padovan if (test_bit(CONF_STATE2_DEVICE, &chan->conf_state) && 35380c1bc5c6SGustavo F. Padovan rfc.mode != chan->mode) 35390a708f8fSGustavo F. Padovan return -ECONNREFUSED; 35400a708f8fSGustavo F. Padovan 354147d1ec61SGustavo F. Padovan chan->fcs = 0; 35420a708f8fSGustavo F. Padovan 35430a708f8fSGustavo F. Padovan l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC, 35440a708f8fSGustavo F. Padovan sizeof(rfc), (unsigned long) &rfc); 35450a708f8fSGustavo F. Padovan break; 35466327eb98SAndrei Emeltchenko 35476327eb98SAndrei Emeltchenko case L2CAP_CONF_EWS: 3548c20f8e35SMat Martineau chan->ack_win = min_t(u16, val, chan->ack_win); 35493e6b3b95SGustavo F. Padovan l2cap_add_conf_opt(&ptr, L2CAP_CONF_EWS, 2, 35503e6b3b95SGustavo F. Padovan chan->tx_win); 35516327eb98SAndrei Emeltchenko break; 355266af7aafSAndrei Emeltchenko 355366af7aafSAndrei Emeltchenko case L2CAP_CONF_EFS: 355466af7aafSAndrei Emeltchenko if (olen == sizeof(efs)) 355566af7aafSAndrei Emeltchenko memcpy(&efs, (void *)val, olen); 355666af7aafSAndrei Emeltchenko 355766af7aafSAndrei Emeltchenko if (chan->local_stype != L2CAP_SERV_NOTRAFIC && 355866af7aafSAndrei Emeltchenko efs.stype != L2CAP_SERV_NOTRAFIC && 355966af7aafSAndrei Emeltchenko efs.stype != chan->local_stype) 356066af7aafSAndrei Emeltchenko return -ECONNREFUSED; 356166af7aafSAndrei Emeltchenko 35622d792818SGustavo Padovan l2cap_add_conf_opt(&ptr, L2CAP_CONF_EFS, sizeof(efs), 35632d792818SGustavo Padovan (unsigned long) &efs); 356466af7aafSAndrei Emeltchenko break; 3565cbabee78SAndrei Emeltchenko 3566cbabee78SAndrei Emeltchenko case L2CAP_CONF_FCS: 3567cbabee78SAndrei Emeltchenko if (*result == L2CAP_CONF_PENDING) 3568cbabee78SAndrei Emeltchenko if (val == L2CAP_FCS_NONE) 3569f2592d3eSAndrei Emeltchenko set_bit(CONF_RECV_NO_FCS, 3570cbabee78SAndrei Emeltchenko &chan->conf_state); 3571cbabee78SAndrei Emeltchenko break; 35720a708f8fSGustavo F. Padovan } 35730a708f8fSGustavo F. Padovan } 35740a708f8fSGustavo F. Padovan 35750c1bc5c6SGustavo F. Padovan if (chan->mode == L2CAP_MODE_BASIC && chan->mode != rfc.mode) 35760a708f8fSGustavo F. Padovan return -ECONNREFUSED; 35770a708f8fSGustavo F. Padovan 35780c1bc5c6SGustavo F. Padovan chan->mode = rfc.mode; 35790a708f8fSGustavo F. Padovan 35800e8b207eSAndrei Emeltchenko if (*result == L2CAP_CONF_SUCCESS || *result == L2CAP_CONF_PENDING) { 35810a708f8fSGustavo F. Padovan switch (rfc.mode) { 35820a708f8fSGustavo F. Padovan case L2CAP_MODE_ERTM: 358347d1ec61SGustavo F. Padovan chan->retrans_timeout = le16_to_cpu(rfc.retrans_timeout); 358447d1ec61SGustavo F. Padovan chan->monitor_timeout = le16_to_cpu(rfc.monitor_timeout); 358547d1ec61SGustavo F. Padovan chan->mps = le16_to_cpu(rfc.max_pdu_size); 3586c20f8e35SMat Martineau if (!test_bit(FLAG_EXT_CTRL, &chan->flags)) 3587c20f8e35SMat Martineau chan->ack_win = min_t(u16, chan->ack_win, 3588c20f8e35SMat Martineau rfc.txwin_size); 358966af7aafSAndrei Emeltchenko 359066af7aafSAndrei Emeltchenko if (test_bit(FLAG_EFS_ENABLE, &chan->flags)) { 359166af7aafSAndrei Emeltchenko chan->local_msdu = le16_to_cpu(efs.msdu); 359266af7aafSAndrei Emeltchenko chan->local_sdu_itime = 359366af7aafSAndrei Emeltchenko le32_to_cpu(efs.sdu_itime); 359466af7aafSAndrei Emeltchenko chan->local_acc_lat = le32_to_cpu(efs.acc_lat); 359566af7aafSAndrei Emeltchenko chan->local_flush_to = 359666af7aafSAndrei Emeltchenko le32_to_cpu(efs.flush_to); 359766af7aafSAndrei Emeltchenko } 35980a708f8fSGustavo F. Padovan break; 359966af7aafSAndrei Emeltchenko 36000a708f8fSGustavo F. Padovan case L2CAP_MODE_STREAMING: 360147d1ec61SGustavo F. Padovan chan->mps = le16_to_cpu(rfc.max_pdu_size); 36020a708f8fSGustavo F. Padovan } 36030a708f8fSGustavo F. Padovan } 36040a708f8fSGustavo F. Padovan 3605fe4128e0SGustavo F. Padovan req->dcid = cpu_to_le16(chan->dcid); 360659e54bd1SAndrei Emeltchenko req->flags = __constant_cpu_to_le16(0); 36070a708f8fSGustavo F. Padovan 36080a708f8fSGustavo F. Padovan return ptr - data; 36090a708f8fSGustavo F. Padovan } 36100a708f8fSGustavo F. Padovan 36112d792818SGustavo Padovan static int l2cap_build_conf_rsp(struct l2cap_chan *chan, void *data, 36122d792818SGustavo Padovan u16 result, u16 flags) 36130a708f8fSGustavo F. Padovan { 36140a708f8fSGustavo F. Padovan struct l2cap_conf_rsp *rsp = data; 36150a708f8fSGustavo F. Padovan void *ptr = rsp->data; 36160a708f8fSGustavo F. Padovan 3617fe4128e0SGustavo F. Padovan BT_DBG("chan %p", chan); 36180a708f8fSGustavo F. Padovan 3619fe4128e0SGustavo F. Padovan rsp->scid = cpu_to_le16(chan->dcid); 36200a708f8fSGustavo F. Padovan rsp->result = cpu_to_le16(result); 36210a708f8fSGustavo F. Padovan rsp->flags = cpu_to_le16(flags); 36220a708f8fSGustavo F. Padovan 36230a708f8fSGustavo F. Padovan return ptr - data; 36240a708f8fSGustavo F. Padovan } 36250a708f8fSGustavo F. Padovan 36268c1d787bSGustavo F. Padovan void __l2cap_connect_rsp_defer(struct l2cap_chan *chan) 3627710f9b0aSGustavo F. Padovan { 3628710f9b0aSGustavo F. Padovan struct l2cap_conn_rsp rsp; 36298c1d787bSGustavo F. Padovan struct l2cap_conn *conn = chan->conn; 3630710f9b0aSGustavo F. Padovan u8 buf[128]; 3631439f34acSAndrei Emeltchenko u8 rsp_code; 3632710f9b0aSGustavo F. Padovan 3633fe4128e0SGustavo F. Padovan rsp.scid = cpu_to_le16(chan->dcid); 3634fe4128e0SGustavo F. Padovan rsp.dcid = cpu_to_le16(chan->scid); 3635ac73498cSAndrei Emeltchenko rsp.result = __constant_cpu_to_le16(L2CAP_CR_SUCCESS); 3636ac73498cSAndrei Emeltchenko rsp.status = __constant_cpu_to_le16(L2CAP_CS_NO_INFO); 3637439f34acSAndrei Emeltchenko 3638439f34acSAndrei Emeltchenko if (chan->hs_hcon) 3639439f34acSAndrei Emeltchenko rsp_code = L2CAP_CREATE_CHAN_RSP; 3640439f34acSAndrei Emeltchenko else 3641439f34acSAndrei Emeltchenko rsp_code = L2CAP_CONN_RSP; 3642439f34acSAndrei Emeltchenko 3643439f34acSAndrei Emeltchenko BT_DBG("chan %p rsp_code %u", chan, rsp_code); 3644439f34acSAndrei Emeltchenko 3645439f34acSAndrei Emeltchenko l2cap_send_cmd(conn, chan->ident, rsp_code, sizeof(rsp), &rsp); 3646710f9b0aSGustavo F. Padovan 3647c1360a1cSGustavo F. Padovan if (test_and_set_bit(CONF_REQ_SENT, &chan->conf_state)) 3648710f9b0aSGustavo F. Padovan return; 3649710f9b0aSGustavo F. Padovan 3650710f9b0aSGustavo F. Padovan l2cap_send_cmd(conn, l2cap_get_ident(conn), L2CAP_CONF_REQ, 3651710f9b0aSGustavo F. Padovan l2cap_build_conf_req(chan, buf), buf); 3652710f9b0aSGustavo F. Padovan chan->num_conf_req++; 3653710f9b0aSGustavo F. Padovan } 3654710f9b0aSGustavo F. Padovan 365547d1ec61SGustavo F. Padovan static void l2cap_conf_rfc_get(struct l2cap_chan *chan, void *rsp, int len) 36560a708f8fSGustavo F. Padovan { 36570a708f8fSGustavo F. Padovan int type, olen; 36580a708f8fSGustavo F. Padovan unsigned long val; 3659c20f8e35SMat Martineau /* Use sane default values in case a misbehaving remote device 3660c20f8e35SMat Martineau * did not send an RFC or extended window size option. 3661c20f8e35SMat Martineau */ 3662c20f8e35SMat Martineau u16 txwin_ext = chan->ack_win; 3663c20f8e35SMat Martineau struct l2cap_conf_rfc rfc = { 3664c20f8e35SMat Martineau .mode = chan->mode, 3665c20f8e35SMat Martineau .retrans_timeout = __constant_cpu_to_le16(L2CAP_DEFAULT_RETRANS_TO), 3666c20f8e35SMat Martineau .monitor_timeout = __constant_cpu_to_le16(L2CAP_DEFAULT_MONITOR_TO), 3667c20f8e35SMat Martineau .max_pdu_size = cpu_to_le16(chan->imtu), 3668c20f8e35SMat Martineau .txwin_size = min_t(u16, chan->ack_win, L2CAP_DEFAULT_TX_WINDOW), 3669c20f8e35SMat Martineau }; 36700a708f8fSGustavo F. Padovan 367147d1ec61SGustavo F. Padovan BT_DBG("chan %p, rsp %p, len %d", chan, rsp, len); 36720a708f8fSGustavo F. Padovan 36730c1bc5c6SGustavo F. Padovan if ((chan->mode != L2CAP_MODE_ERTM) && (chan->mode != L2CAP_MODE_STREAMING)) 36740a708f8fSGustavo F. Padovan return; 36750a708f8fSGustavo F. Padovan 36760a708f8fSGustavo F. Padovan while (len >= L2CAP_CONF_OPT_SIZE) { 36770a708f8fSGustavo F. Padovan len -= l2cap_get_conf_opt(&rsp, &type, &olen, &val); 36780a708f8fSGustavo F. Padovan 3679c20f8e35SMat Martineau switch (type) { 3680c20f8e35SMat Martineau case L2CAP_CONF_RFC: 3681c20f8e35SMat Martineau if (olen == sizeof(rfc)) 36820a708f8fSGustavo F. Padovan memcpy(&rfc, (void *)val, olen); 3683c20f8e35SMat Martineau break; 3684c20f8e35SMat Martineau case L2CAP_CONF_EWS: 3685c20f8e35SMat Martineau txwin_ext = val; 3686c20f8e35SMat Martineau break; 3687c20f8e35SMat Martineau } 36880a708f8fSGustavo F. Padovan } 36890a708f8fSGustavo F. Padovan 36900a708f8fSGustavo F. Padovan switch (rfc.mode) { 36910a708f8fSGustavo F. Padovan case L2CAP_MODE_ERTM: 369247d1ec61SGustavo F. Padovan chan->retrans_timeout = le16_to_cpu(rfc.retrans_timeout); 369347d1ec61SGustavo F. Padovan chan->monitor_timeout = le16_to_cpu(rfc.monitor_timeout); 369447d1ec61SGustavo F. Padovan chan->mps = le16_to_cpu(rfc.max_pdu_size); 3695c20f8e35SMat Martineau if (test_bit(FLAG_EXT_CTRL, &chan->flags)) 3696c20f8e35SMat Martineau chan->ack_win = min_t(u16, chan->ack_win, txwin_ext); 3697c20f8e35SMat Martineau else 3698c20f8e35SMat Martineau chan->ack_win = min_t(u16, chan->ack_win, 3699c20f8e35SMat Martineau rfc.txwin_size); 37000a708f8fSGustavo F. Padovan break; 37010a708f8fSGustavo F. Padovan case L2CAP_MODE_STREAMING: 370247d1ec61SGustavo F. Padovan chan->mps = le16_to_cpu(rfc.max_pdu_size); 37030a708f8fSGustavo F. Padovan } 37040a708f8fSGustavo F. Padovan } 37050a708f8fSGustavo F. Padovan 37062d792818SGustavo Padovan static inline int l2cap_command_rej(struct l2cap_conn *conn, 3707cb3b3152SJohan Hedberg struct l2cap_cmd_hdr *cmd, u16 cmd_len, 3708cb3b3152SJohan Hedberg u8 *data) 37090a708f8fSGustavo F. Padovan { 3710e2fd318eSIlia Kolomisnky struct l2cap_cmd_rej_unk *rej = (struct l2cap_cmd_rej_unk *) data; 37110a708f8fSGustavo F. Padovan 3712cb3b3152SJohan Hedberg if (cmd_len < sizeof(*rej)) 3713cb3b3152SJohan Hedberg return -EPROTO; 3714cb3b3152SJohan Hedberg 3715e2fd318eSIlia Kolomisnky if (rej->reason != L2CAP_REJ_NOT_UNDERSTOOD) 37160a708f8fSGustavo F. Padovan return 0; 37170a708f8fSGustavo F. Padovan 37180a708f8fSGustavo F. Padovan if ((conn->info_state & L2CAP_INFO_FEAT_MASK_REQ_SENT) && 37190a708f8fSGustavo F. Padovan cmd->ident == conn->info_ident) { 372017cd3f37SUlisses Furquim cancel_delayed_work(&conn->info_timer); 37210a708f8fSGustavo F. Padovan 37220a708f8fSGustavo F. Padovan conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_DONE; 37230a708f8fSGustavo F. Padovan conn->info_ident = 0; 37240a708f8fSGustavo F. Padovan 37250a708f8fSGustavo F. Padovan l2cap_conn_start(conn); 37260a708f8fSGustavo F. Padovan } 37270a708f8fSGustavo F. Padovan 37280a708f8fSGustavo F. Padovan return 0; 37290a708f8fSGustavo F. Padovan } 37300a708f8fSGustavo F. Padovan 37311700915fSMat Martineau static struct l2cap_chan *l2cap_connect(struct l2cap_conn *conn, 37321700915fSMat Martineau struct l2cap_cmd_hdr *cmd, 37334c89b6aaSMat Martineau u8 *data, u8 rsp_code, u8 amp_id) 37340a708f8fSGustavo F. Padovan { 37350a708f8fSGustavo F. Padovan struct l2cap_conn_req *req = (struct l2cap_conn_req *) data; 37360a708f8fSGustavo F. Padovan struct l2cap_conn_rsp rsp; 373723691d75SGustavo F. Padovan struct l2cap_chan *chan = NULL, *pchan; 37380a708f8fSGustavo F. Padovan struct sock *parent, *sk = NULL; 37390a708f8fSGustavo F. Padovan int result, status = L2CAP_CS_NO_INFO; 37400a708f8fSGustavo F. Padovan 37410a708f8fSGustavo F. Padovan u16 dcid = 0, scid = __le16_to_cpu(req->scid); 37420a708f8fSGustavo F. Padovan __le16 psm = req->psm; 37430a708f8fSGustavo F. Padovan 3744097db76cSAndrei Emeltchenko BT_DBG("psm 0x%2.2x scid 0x%4.4x", __le16_to_cpu(psm), scid); 37450a708f8fSGustavo F. Padovan 37460a708f8fSGustavo F. Padovan /* Check if we have socket listening on psm */ 3747c2287681SIdo Yariv pchan = l2cap_global_chan_by_psm(BT_LISTEN, psm, conn->src, conn->dst); 374823691d75SGustavo F. Padovan if (!pchan) { 37490a708f8fSGustavo F. Padovan result = L2CAP_CR_BAD_PSM; 37500a708f8fSGustavo F. Padovan goto sendresp; 37510a708f8fSGustavo F. Padovan } 37520a708f8fSGustavo F. Padovan 375323691d75SGustavo F. Padovan parent = pchan->sk; 375423691d75SGustavo F. Padovan 37553df91ea2SAndrei Emeltchenko mutex_lock(&conn->chan_lock); 3756aa2ac881SGustavo F. Padovan lock_sock(parent); 37570a708f8fSGustavo F. Padovan 37580a708f8fSGustavo F. Padovan /* Check if the ACL is secure enough (if not SDP) */ 37592983fd68SAndrei Emeltchenko if (psm != __constant_cpu_to_le16(L2CAP_PSM_SDP) && 37600a708f8fSGustavo F. Padovan !hci_conn_check_link_mode(conn->hcon)) { 37619f5a0d7bSAndrei Emeltchenko conn->disc_reason = HCI_ERROR_AUTH_FAILURE; 37620a708f8fSGustavo F. Padovan result = L2CAP_CR_SEC_BLOCK; 37630a708f8fSGustavo F. Padovan goto response; 37640a708f8fSGustavo F. Padovan } 37650a708f8fSGustavo F. Padovan 37660a708f8fSGustavo F. Padovan result = L2CAP_CR_NO_MEM; 37670a708f8fSGustavo F. Padovan 37682dfa1003SGustavo Padovan /* Check if we already have channel with that dcid */ 37692dfa1003SGustavo Padovan if (__l2cap_get_chan_by_dcid(conn, scid)) 37702dfa1003SGustavo Padovan goto response; 37712dfa1003SGustavo Padovan 377280b98027SGustavo Padovan chan = pchan->ops->new_connection(pchan); 377380808e43SGustavo F. Padovan if (!chan) 37740a708f8fSGustavo F. Padovan goto response; 37750a708f8fSGustavo F. Padovan 377680808e43SGustavo F. Padovan sk = chan->sk; 377780808e43SGustavo F. Padovan 3778330b6c15SSyam Sidhardhan /* For certain devices (ex: HID mouse), support for authentication, 3779330b6c15SSyam Sidhardhan * pairing and bonding is optional. For such devices, inorder to avoid 3780330b6c15SSyam Sidhardhan * the ACL alive for too long after L2CAP disconnection, reset the ACL 3781330b6c15SSyam Sidhardhan * disc_timeout back to HCI_DISCONN_TIMEOUT during L2CAP connect. 3782330b6c15SSyam Sidhardhan */ 3783330b6c15SSyam Sidhardhan conn->hcon->disc_timeout = HCI_DISCONN_TIMEOUT; 3784330b6c15SSyam Sidhardhan 37850a708f8fSGustavo F. Padovan bacpy(&bt_sk(sk)->src, conn->src); 37860a708f8fSGustavo F. Padovan bacpy(&bt_sk(sk)->dst, conn->dst); 3787fe4128e0SGustavo F. Padovan chan->psm = psm; 3788fe4128e0SGustavo F. Padovan chan->dcid = scid; 37891700915fSMat Martineau chan->local_amp_id = amp_id; 37900a708f8fSGustavo F. Padovan 37916be36555SAndrei Emeltchenko __l2cap_chan_add(conn, chan); 379248454079SGustavo F. Padovan 3793fe4128e0SGustavo F. Padovan dcid = chan->scid; 37940a708f8fSGustavo F. Padovan 3795c9b66675SGustavo F. Padovan __set_chan_timer(chan, sk->sk_sndtimeo); 37960a708f8fSGustavo F. Padovan 3797fc7f8a7eSGustavo F. Padovan chan->ident = cmd->ident; 37980a708f8fSGustavo F. Padovan 37990a708f8fSGustavo F. Padovan if (conn->info_state & L2CAP_INFO_FEAT_MASK_REQ_DONE) { 3800d45fc423SGustavo F. Padovan if (l2cap_chan_check_security(chan)) { 3801c5daa683SGustavo Padovan if (test_bit(BT_SK_DEFER_SETUP, &bt_sk(sk)->flags)) { 38020e587be7SAndrei Emeltchenko __l2cap_state_change(chan, BT_CONNECT2); 38030a708f8fSGustavo F. Padovan result = L2CAP_CR_PEND; 38040a708f8fSGustavo F. Padovan status = L2CAP_CS_AUTHOR_PEND; 38052dc4e510SGustavo Padovan chan->ops->defer(chan); 38060a708f8fSGustavo F. Padovan } else { 38071700915fSMat Martineau /* Force pending result for AMP controllers. 38081700915fSMat Martineau * The connection will succeed after the 38091700915fSMat Martineau * physical link is up. 38101700915fSMat Martineau */ 38116ed971caSMarcel Holtmann if (amp_id == AMP_ID_BREDR) { 38120e587be7SAndrei Emeltchenko __l2cap_state_change(chan, BT_CONFIG); 38130a708f8fSGustavo F. Padovan result = L2CAP_CR_SUCCESS; 38146ed971caSMarcel Holtmann } else { 38156ed971caSMarcel Holtmann __l2cap_state_change(chan, BT_CONNECT2); 38166ed971caSMarcel Holtmann result = L2CAP_CR_PEND; 38171700915fSMat Martineau } 38180a708f8fSGustavo F. Padovan status = L2CAP_CS_NO_INFO; 38190a708f8fSGustavo F. Padovan } 38200a708f8fSGustavo F. Padovan } else { 38210e587be7SAndrei Emeltchenko __l2cap_state_change(chan, BT_CONNECT2); 38220a708f8fSGustavo F. Padovan result = L2CAP_CR_PEND; 38230a708f8fSGustavo F. Padovan status = L2CAP_CS_AUTHEN_PEND; 38240a708f8fSGustavo F. Padovan } 38250a708f8fSGustavo F. Padovan } else { 38260e587be7SAndrei Emeltchenko __l2cap_state_change(chan, BT_CONNECT2); 38270a708f8fSGustavo F. Padovan result = L2CAP_CR_PEND; 38280a708f8fSGustavo F. Padovan status = L2CAP_CS_NO_INFO; 38290a708f8fSGustavo F. Padovan } 38300a708f8fSGustavo F. Padovan 38310a708f8fSGustavo F. Padovan response: 3832aa2ac881SGustavo F. Padovan release_sock(parent); 38333df91ea2SAndrei Emeltchenko mutex_unlock(&conn->chan_lock); 38340a708f8fSGustavo F. Padovan 38350a708f8fSGustavo F. Padovan sendresp: 38360a708f8fSGustavo F. Padovan rsp.scid = cpu_to_le16(scid); 38370a708f8fSGustavo F. Padovan rsp.dcid = cpu_to_le16(dcid); 38380a708f8fSGustavo F. Padovan rsp.result = cpu_to_le16(result); 38390a708f8fSGustavo F. Padovan rsp.status = cpu_to_le16(status); 38404c89b6aaSMat Martineau l2cap_send_cmd(conn, cmd->ident, rsp_code, sizeof(rsp), &rsp); 38410a708f8fSGustavo F. Padovan 38420a708f8fSGustavo F. Padovan if (result == L2CAP_CR_PEND && status == L2CAP_CS_NO_INFO) { 38430a708f8fSGustavo F. Padovan struct l2cap_info_req info; 3844ac73498cSAndrei Emeltchenko info.type = __constant_cpu_to_le16(L2CAP_IT_FEAT_MASK); 38450a708f8fSGustavo F. Padovan 38460a708f8fSGustavo F. Padovan conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_SENT; 38470a708f8fSGustavo F. Padovan conn->info_ident = l2cap_get_ident(conn); 38480a708f8fSGustavo F. Padovan 3849ba13ccd9SMarcel Holtmann schedule_delayed_work(&conn->info_timer, L2CAP_INFO_TIMEOUT); 38500a708f8fSGustavo F. Padovan 38512d792818SGustavo Padovan l2cap_send_cmd(conn, conn->info_ident, L2CAP_INFO_REQ, 38522d792818SGustavo Padovan sizeof(info), &info); 38530a708f8fSGustavo F. Padovan } 38540a708f8fSGustavo F. Padovan 3855c1360a1cSGustavo F. Padovan if (chan && !test_bit(CONF_REQ_SENT, &chan->conf_state) && 38560a708f8fSGustavo F. Padovan result == L2CAP_CR_SUCCESS) { 38570a708f8fSGustavo F. Padovan u8 buf[128]; 3858c1360a1cSGustavo F. Padovan set_bit(CONF_REQ_SENT, &chan->conf_state); 38590a708f8fSGustavo F. Padovan l2cap_send_cmd(conn, l2cap_get_ident(conn), L2CAP_CONF_REQ, 386073ffa904SGustavo F. Padovan l2cap_build_conf_req(chan, buf), buf); 386173ffa904SGustavo F. Padovan chan->num_conf_req++; 38620a708f8fSGustavo F. Padovan } 38631700915fSMat Martineau 38641700915fSMat Martineau return chan; 38654c89b6aaSMat Martineau } 38660a708f8fSGustavo F. Padovan 38674c89b6aaSMat Martineau static int l2cap_connect_req(struct l2cap_conn *conn, 3868cb3b3152SJohan Hedberg struct l2cap_cmd_hdr *cmd, u16 cmd_len, u8 *data) 38694c89b6aaSMat Martineau { 38707b064edaSJaganath Kanakkassery struct hci_dev *hdev = conn->hcon->hdev; 38717b064edaSJaganath Kanakkassery struct hci_conn *hcon = conn->hcon; 38727b064edaSJaganath Kanakkassery 3873cb3b3152SJohan Hedberg if (cmd_len < sizeof(struct l2cap_conn_req)) 3874cb3b3152SJohan Hedberg return -EPROTO; 3875cb3b3152SJohan Hedberg 38767b064edaSJaganath Kanakkassery hci_dev_lock(hdev); 38777b064edaSJaganath Kanakkassery if (test_bit(HCI_MGMT, &hdev->dev_flags) && 38787b064edaSJaganath Kanakkassery !test_and_set_bit(HCI_CONN_MGMT_CONNECTED, &hcon->flags)) 38797b064edaSJaganath Kanakkassery mgmt_device_connected(hdev, &hcon->dst, hcon->type, 38807b064edaSJaganath Kanakkassery hcon->dst_type, 0, NULL, 0, 38817b064edaSJaganath Kanakkassery hcon->dev_class); 38827b064edaSJaganath Kanakkassery hci_dev_unlock(hdev); 38837b064edaSJaganath Kanakkassery 3884300229f9SGustavo Padovan l2cap_connect(conn, cmd, data, L2CAP_CONN_RSP, 0); 38850a708f8fSGustavo F. Padovan return 0; 38860a708f8fSGustavo F. Padovan } 38870a708f8fSGustavo F. Padovan 38885909cf30SMat Martineau static int l2cap_connect_create_rsp(struct l2cap_conn *conn, 3889cb3b3152SJohan Hedberg struct l2cap_cmd_hdr *cmd, u16 cmd_len, 3890cb3b3152SJohan Hedberg u8 *data) 38910a708f8fSGustavo F. Padovan { 38920a708f8fSGustavo F. Padovan struct l2cap_conn_rsp *rsp = (struct l2cap_conn_rsp *) data; 38930a708f8fSGustavo F. Padovan u16 scid, dcid, result, status; 389448454079SGustavo F. Padovan struct l2cap_chan *chan; 38950a708f8fSGustavo F. Padovan u8 req[128]; 38963df91ea2SAndrei Emeltchenko int err; 38970a708f8fSGustavo F. Padovan 3898cb3b3152SJohan Hedberg if (cmd_len < sizeof(*rsp)) 3899cb3b3152SJohan Hedberg return -EPROTO; 3900cb3b3152SJohan Hedberg 39010a708f8fSGustavo F. Padovan scid = __le16_to_cpu(rsp->scid); 39020a708f8fSGustavo F. Padovan dcid = __le16_to_cpu(rsp->dcid); 39030a708f8fSGustavo F. Padovan result = __le16_to_cpu(rsp->result); 39040a708f8fSGustavo F. Padovan status = __le16_to_cpu(rsp->status); 39050a708f8fSGustavo F. Padovan 39061b009c98SAndrei Emeltchenko BT_DBG("dcid 0x%4.4x scid 0x%4.4x result 0x%2.2x status 0x%2.2x", 39071b009c98SAndrei Emeltchenko dcid, scid, result, status); 39080a708f8fSGustavo F. Padovan 39093df91ea2SAndrei Emeltchenko mutex_lock(&conn->chan_lock); 39103df91ea2SAndrei Emeltchenko 39110a708f8fSGustavo F. Padovan if (scid) { 39123df91ea2SAndrei Emeltchenko chan = __l2cap_get_chan_by_scid(conn, scid); 39133df91ea2SAndrei Emeltchenko if (!chan) { 391421870b52SJohan Hedberg err = -EBADSLT; 39153df91ea2SAndrei Emeltchenko goto unlock; 39163df91ea2SAndrei Emeltchenko } 39170a708f8fSGustavo F. Padovan } else { 39183df91ea2SAndrei Emeltchenko chan = __l2cap_get_chan_by_ident(conn, cmd->ident); 39193df91ea2SAndrei Emeltchenko if (!chan) { 392021870b52SJohan Hedberg err = -EBADSLT; 39213df91ea2SAndrei Emeltchenko goto unlock; 39223df91ea2SAndrei Emeltchenko } 39230a708f8fSGustavo F. Padovan } 39240a708f8fSGustavo F. Padovan 39253df91ea2SAndrei Emeltchenko err = 0; 39263df91ea2SAndrei Emeltchenko 39276be36555SAndrei Emeltchenko l2cap_chan_lock(chan); 392848454079SGustavo F. Padovan 39290a708f8fSGustavo F. Padovan switch (result) { 39300a708f8fSGustavo F. Padovan case L2CAP_CR_SUCCESS: 393189bc500eSGustavo F. Padovan l2cap_state_change(chan, BT_CONFIG); 3932fc7f8a7eSGustavo F. Padovan chan->ident = 0; 3933fe4128e0SGustavo F. Padovan chan->dcid = dcid; 3934c1360a1cSGustavo F. Padovan clear_bit(CONF_CONNECT_PEND, &chan->conf_state); 39350a708f8fSGustavo F. Padovan 3936c1360a1cSGustavo F. Padovan if (test_and_set_bit(CONF_REQ_SENT, &chan->conf_state)) 39370a708f8fSGustavo F. Padovan break; 39380a708f8fSGustavo F. Padovan 39390a708f8fSGustavo F. Padovan l2cap_send_cmd(conn, l2cap_get_ident(conn), L2CAP_CONF_REQ, 394073ffa904SGustavo F. Padovan l2cap_build_conf_req(chan, req), req); 394173ffa904SGustavo F. Padovan chan->num_conf_req++; 39420a708f8fSGustavo F. Padovan break; 39430a708f8fSGustavo F. Padovan 39440a708f8fSGustavo F. Padovan case L2CAP_CR_PEND: 3945c1360a1cSGustavo F. Padovan set_bit(CONF_CONNECT_PEND, &chan->conf_state); 39460a708f8fSGustavo F. Padovan break; 39470a708f8fSGustavo F. Padovan 39480a708f8fSGustavo F. Padovan default: 394948454079SGustavo F. Padovan l2cap_chan_del(chan, ECONNREFUSED); 39500a708f8fSGustavo F. Padovan break; 39510a708f8fSGustavo F. Padovan } 39520a708f8fSGustavo F. Padovan 39536be36555SAndrei Emeltchenko l2cap_chan_unlock(chan); 39543df91ea2SAndrei Emeltchenko 39553df91ea2SAndrei Emeltchenko unlock: 39563df91ea2SAndrei Emeltchenko mutex_unlock(&conn->chan_lock); 39573df91ea2SAndrei Emeltchenko 39583df91ea2SAndrei Emeltchenko return err; 39590a708f8fSGustavo F. Padovan } 39600a708f8fSGustavo F. Padovan 396147d1ec61SGustavo F. Padovan static inline void set_default_fcs(struct l2cap_chan *chan) 39620a708f8fSGustavo F. Padovan { 39630a708f8fSGustavo F. Padovan /* FCS is enabled only in ERTM or streaming mode, if one or both 39640a708f8fSGustavo F. Padovan * sides request it. 39650a708f8fSGustavo F. Padovan */ 39660c1bc5c6SGustavo F. Padovan if (chan->mode != L2CAP_MODE_ERTM && chan->mode != L2CAP_MODE_STREAMING) 396747d1ec61SGustavo F. Padovan chan->fcs = L2CAP_FCS_NONE; 3968f2592d3eSAndrei Emeltchenko else if (!test_bit(CONF_RECV_NO_FCS, &chan->conf_state)) 396947d1ec61SGustavo F. Padovan chan->fcs = L2CAP_FCS_CRC16; 39700a708f8fSGustavo F. Padovan } 39710a708f8fSGustavo F. Padovan 397229d8a590SAndrei Emeltchenko static void l2cap_send_efs_conf_rsp(struct l2cap_chan *chan, void *data, 397329d8a590SAndrei Emeltchenko u8 ident, u16 flags) 397429d8a590SAndrei Emeltchenko { 397529d8a590SAndrei Emeltchenko struct l2cap_conn *conn = chan->conn; 397629d8a590SAndrei Emeltchenko 397729d8a590SAndrei Emeltchenko BT_DBG("conn %p chan %p ident %d flags 0x%4.4x", conn, chan, ident, 397829d8a590SAndrei Emeltchenko flags); 397929d8a590SAndrei Emeltchenko 398029d8a590SAndrei Emeltchenko clear_bit(CONF_LOC_CONF_PEND, &chan->conf_state); 398129d8a590SAndrei Emeltchenko set_bit(CONF_OUTPUT_DONE, &chan->conf_state); 398229d8a590SAndrei Emeltchenko 398329d8a590SAndrei Emeltchenko l2cap_send_cmd(conn, ident, L2CAP_CONF_RSP, 398429d8a590SAndrei Emeltchenko l2cap_build_conf_rsp(chan, data, 398529d8a590SAndrei Emeltchenko L2CAP_CONF_SUCCESS, flags), data); 398629d8a590SAndrei Emeltchenko } 398729d8a590SAndrei Emeltchenko 39882d792818SGustavo Padovan static inline int l2cap_config_req(struct l2cap_conn *conn, 39892d792818SGustavo Padovan struct l2cap_cmd_hdr *cmd, u16 cmd_len, 39902d792818SGustavo Padovan u8 *data) 39910a708f8fSGustavo F. Padovan { 39920a708f8fSGustavo F. Padovan struct l2cap_conf_req *req = (struct l2cap_conf_req *) data; 39930a708f8fSGustavo F. Padovan u16 dcid, flags; 39940a708f8fSGustavo F. Padovan u8 rsp[64]; 399548454079SGustavo F. Padovan struct l2cap_chan *chan; 39963c588192SMat Martineau int len, err = 0; 39970a708f8fSGustavo F. Padovan 3998cb3b3152SJohan Hedberg if (cmd_len < sizeof(*req)) 3999cb3b3152SJohan Hedberg return -EPROTO; 4000cb3b3152SJohan Hedberg 40010a708f8fSGustavo F. Padovan dcid = __le16_to_cpu(req->dcid); 40020a708f8fSGustavo F. Padovan flags = __le16_to_cpu(req->flags); 40030a708f8fSGustavo F. Padovan 40040a708f8fSGustavo F. Padovan BT_DBG("dcid 0x%4.4x flags 0x%2.2x", dcid, flags); 40050a708f8fSGustavo F. Padovan 4006baa7e1faSGustavo F. Padovan chan = l2cap_get_chan_by_scid(conn, dcid); 400748454079SGustavo F. Padovan if (!chan) 400821870b52SJohan Hedberg return -EBADSLT; 40090a708f8fSGustavo F. Padovan 4010033b1142SDavid S. Miller if (chan->state != BT_CONFIG && chan->state != BT_CONNECT2) { 4011e2fd318eSIlia Kolomisnky struct l2cap_cmd_rej_cid rej; 40120a708f8fSGustavo F. Padovan 4013ac73498cSAndrei Emeltchenko rej.reason = __constant_cpu_to_le16(L2CAP_REJ_INVALID_CID); 4014e2fd318eSIlia Kolomisnky rej.scid = cpu_to_le16(chan->scid); 4015e2fd318eSIlia Kolomisnky rej.dcid = cpu_to_le16(chan->dcid); 4016e2fd318eSIlia Kolomisnky 40170a708f8fSGustavo F. Padovan l2cap_send_cmd(conn, cmd->ident, L2CAP_COMMAND_REJ, 40180a708f8fSGustavo F. Padovan sizeof(rej), &rej); 40190a708f8fSGustavo F. Padovan goto unlock; 40200a708f8fSGustavo F. Padovan } 40210a708f8fSGustavo F. Padovan 40220a708f8fSGustavo F. Padovan /* Reject if config buffer is too small. */ 40230a708f8fSGustavo F. Padovan len = cmd_len - sizeof(*req); 4024cb3b3152SJohan Hedberg if (chan->conf_len + len > sizeof(chan->conf_req)) { 40250a708f8fSGustavo F. Padovan l2cap_send_cmd(conn, cmd->ident, L2CAP_CONF_RSP, 4026fe4128e0SGustavo F. Padovan l2cap_build_conf_rsp(chan, rsp, 40270a708f8fSGustavo F. Padovan L2CAP_CONF_REJECT, flags), rsp); 40280a708f8fSGustavo F. Padovan goto unlock; 40290a708f8fSGustavo F. Padovan } 40300a708f8fSGustavo F. Padovan 40310a708f8fSGustavo F. Padovan /* Store config. */ 403273ffa904SGustavo F. Padovan memcpy(chan->conf_req + chan->conf_len, req->data, len); 403373ffa904SGustavo F. Padovan chan->conf_len += len; 40340a708f8fSGustavo F. Padovan 403559e54bd1SAndrei Emeltchenko if (flags & L2CAP_CONF_FLAG_CONTINUATION) { 40360a708f8fSGustavo F. Padovan /* Incomplete config. Send empty response. */ 40370a708f8fSGustavo F. Padovan l2cap_send_cmd(conn, cmd->ident, L2CAP_CONF_RSP, 4038fe4128e0SGustavo F. Padovan l2cap_build_conf_rsp(chan, rsp, 40395325e5bbSAndrei Emeltchenko L2CAP_CONF_SUCCESS, flags), rsp); 40400a708f8fSGustavo F. Padovan goto unlock; 40410a708f8fSGustavo F. Padovan } 40420a708f8fSGustavo F. Padovan 40430a708f8fSGustavo F. Padovan /* Complete config. */ 404473ffa904SGustavo F. Padovan len = l2cap_parse_conf_req(chan, rsp); 40450a708f8fSGustavo F. Padovan if (len < 0) { 40465e4e3972SAndrei Emeltchenko l2cap_send_disconn_req(chan, ECONNRESET); 40470a708f8fSGustavo F. Padovan goto unlock; 40480a708f8fSGustavo F. Padovan } 40490a708f8fSGustavo F. Padovan 40501500109bSMat Martineau chan->ident = cmd->ident; 40510a708f8fSGustavo F. Padovan l2cap_send_cmd(conn, cmd->ident, L2CAP_CONF_RSP, len, rsp); 405273ffa904SGustavo F. Padovan chan->num_conf_rsp++; 40530a708f8fSGustavo F. Padovan 40540a708f8fSGustavo F. Padovan /* Reset config buffer. */ 405573ffa904SGustavo F. Padovan chan->conf_len = 0; 40560a708f8fSGustavo F. Padovan 4057c1360a1cSGustavo F. Padovan if (!test_bit(CONF_OUTPUT_DONE, &chan->conf_state)) 40580a708f8fSGustavo F. Padovan goto unlock; 40590a708f8fSGustavo F. Padovan 4060c1360a1cSGustavo F. Padovan if (test_bit(CONF_INPUT_DONE, &chan->conf_state)) { 406147d1ec61SGustavo F. Padovan set_default_fcs(chan); 40620a708f8fSGustavo F. Padovan 4063105bdf9eSMat Martineau if (chan->mode == L2CAP_MODE_ERTM || 4064105bdf9eSMat Martineau chan->mode == L2CAP_MODE_STREAMING) 40653c588192SMat Martineau err = l2cap_ertm_init(chan); 40660a708f8fSGustavo F. Padovan 40673c588192SMat Martineau if (err < 0) 40685e4e3972SAndrei Emeltchenko l2cap_send_disconn_req(chan, -err); 40693c588192SMat Martineau else 4070cf4cd009SAndrei Emeltchenko l2cap_chan_ready(chan); 40713c588192SMat Martineau 40720a708f8fSGustavo F. Padovan goto unlock; 40730a708f8fSGustavo F. Padovan } 40740a708f8fSGustavo F. Padovan 4075c1360a1cSGustavo F. Padovan if (!test_and_set_bit(CONF_REQ_SENT, &chan->conf_state)) { 40760a708f8fSGustavo F. Padovan u8 buf[64]; 40770a708f8fSGustavo F. Padovan l2cap_send_cmd(conn, l2cap_get_ident(conn), L2CAP_CONF_REQ, 407873ffa904SGustavo F. Padovan l2cap_build_conf_req(chan, buf), buf); 407973ffa904SGustavo F. Padovan chan->num_conf_req++; 40800a708f8fSGustavo F. Padovan } 40810a708f8fSGustavo F. Padovan 40820e8b207eSAndrei Emeltchenko /* Got Conf Rsp PENDING from remote side and asume we sent 40830e8b207eSAndrei Emeltchenko Conf Rsp PENDING in the code above */ 40840e8b207eSAndrei Emeltchenko if (test_bit(CONF_REM_CONF_PEND, &chan->conf_state) && 40850e8b207eSAndrei Emeltchenko test_bit(CONF_LOC_CONF_PEND, &chan->conf_state)) { 40860e8b207eSAndrei Emeltchenko 40870e8b207eSAndrei Emeltchenko /* check compatibility */ 40880e8b207eSAndrei Emeltchenko 408979de886dSAndrei Emeltchenko /* Send rsp for BR/EDR channel */ 4090f351bc72SAndrei Emeltchenko if (!chan->hs_hcon) 409129d8a590SAndrei Emeltchenko l2cap_send_efs_conf_rsp(chan, rsp, cmd->ident, flags); 409279de886dSAndrei Emeltchenko else 409379de886dSAndrei Emeltchenko chan->ident = cmd->ident; 40940e8b207eSAndrei Emeltchenko } 40950e8b207eSAndrei Emeltchenko 40960a708f8fSGustavo F. Padovan unlock: 40976be36555SAndrei Emeltchenko l2cap_chan_unlock(chan); 40983c588192SMat Martineau return err; 40990a708f8fSGustavo F. Padovan } 41000a708f8fSGustavo F. Padovan 41012d792818SGustavo Padovan static inline int l2cap_config_rsp(struct l2cap_conn *conn, 4102cb3b3152SJohan Hedberg struct l2cap_cmd_hdr *cmd, u16 cmd_len, 4103cb3b3152SJohan Hedberg u8 *data) 41040a708f8fSGustavo F. Padovan { 41050a708f8fSGustavo F. Padovan struct l2cap_conf_rsp *rsp = (struct l2cap_conf_rsp *)data; 41060a708f8fSGustavo F. Padovan u16 scid, flags, result; 410748454079SGustavo F. Padovan struct l2cap_chan *chan; 4108cb3b3152SJohan Hedberg int len = cmd_len - sizeof(*rsp); 41093c588192SMat Martineau int err = 0; 41100a708f8fSGustavo F. Padovan 4111cb3b3152SJohan Hedberg if (cmd_len < sizeof(*rsp)) 4112cb3b3152SJohan Hedberg return -EPROTO; 4113cb3b3152SJohan Hedberg 41140a708f8fSGustavo F. Padovan scid = __le16_to_cpu(rsp->scid); 41150a708f8fSGustavo F. Padovan flags = __le16_to_cpu(rsp->flags); 41160a708f8fSGustavo F. Padovan result = __le16_to_cpu(rsp->result); 41170a708f8fSGustavo F. Padovan 411861386cbaSAndrei Emeltchenko BT_DBG("scid 0x%4.4x flags 0x%2.2x result 0x%2.2x len %d", scid, flags, 411961386cbaSAndrei Emeltchenko result, len); 41200a708f8fSGustavo F. Padovan 4121baa7e1faSGustavo F. Padovan chan = l2cap_get_chan_by_scid(conn, scid); 412248454079SGustavo F. Padovan if (!chan) 41230a708f8fSGustavo F. Padovan return 0; 41240a708f8fSGustavo F. Padovan 41250a708f8fSGustavo F. Padovan switch (result) { 41260a708f8fSGustavo F. Padovan case L2CAP_CONF_SUCCESS: 412747d1ec61SGustavo F. Padovan l2cap_conf_rfc_get(chan, rsp->data, len); 41280e8b207eSAndrei Emeltchenko clear_bit(CONF_REM_CONF_PEND, &chan->conf_state); 41290a708f8fSGustavo F. Padovan break; 41300a708f8fSGustavo F. Padovan 41310e8b207eSAndrei Emeltchenko case L2CAP_CONF_PENDING: 41320e8b207eSAndrei Emeltchenko set_bit(CONF_REM_CONF_PEND, &chan->conf_state); 41330e8b207eSAndrei Emeltchenko 41340e8b207eSAndrei Emeltchenko if (test_bit(CONF_LOC_CONF_PEND, &chan->conf_state)) { 41350e8b207eSAndrei Emeltchenko char buf[64]; 41360e8b207eSAndrei Emeltchenko 41370e8b207eSAndrei Emeltchenko len = l2cap_parse_conf_rsp(chan, rsp->data, len, 41380e8b207eSAndrei Emeltchenko buf, &result); 41390e8b207eSAndrei Emeltchenko if (len < 0) { 41405e4e3972SAndrei Emeltchenko l2cap_send_disconn_req(chan, ECONNRESET); 41410e8b207eSAndrei Emeltchenko goto done; 41420e8b207eSAndrei Emeltchenko } 41430e8b207eSAndrei Emeltchenko 4144f351bc72SAndrei Emeltchenko if (!chan->hs_hcon) { 414579de886dSAndrei Emeltchenko l2cap_send_efs_conf_rsp(chan, buf, cmd->ident, 414679de886dSAndrei Emeltchenko 0); 41475ce66b59SAndrei Emeltchenko } else { 41485ce66b59SAndrei Emeltchenko if (l2cap_check_efs(chan)) { 41495ce66b59SAndrei Emeltchenko amp_create_logical_link(chan); 415079de886dSAndrei Emeltchenko chan->ident = cmd->ident; 41510e8b207eSAndrei Emeltchenko } 41525ce66b59SAndrei Emeltchenko } 41535ce66b59SAndrei Emeltchenko } 41540e8b207eSAndrei Emeltchenko goto done; 41550e8b207eSAndrei Emeltchenko 41560a708f8fSGustavo F. Padovan case L2CAP_CONF_UNACCEPT: 415773ffa904SGustavo F. Padovan if (chan->num_conf_rsp <= L2CAP_CONF_MAX_CONF_RSP) { 41580a708f8fSGustavo F. Padovan char req[64]; 41590a708f8fSGustavo F. Padovan 41600a708f8fSGustavo F. Padovan if (len > sizeof(req) - sizeof(struct l2cap_conf_req)) { 41615e4e3972SAndrei Emeltchenko l2cap_send_disconn_req(chan, ECONNRESET); 41620a708f8fSGustavo F. Padovan goto done; 41630a708f8fSGustavo F. Padovan } 41640a708f8fSGustavo F. Padovan 41650a708f8fSGustavo F. Padovan /* throw out any old stored conf requests */ 41660a708f8fSGustavo F. Padovan result = L2CAP_CONF_SUCCESS; 4167b4450035SGustavo F. Padovan len = l2cap_parse_conf_rsp(chan, rsp->data, len, 4168b4450035SGustavo F. Padovan req, &result); 41690a708f8fSGustavo F. Padovan if (len < 0) { 41705e4e3972SAndrei Emeltchenko l2cap_send_disconn_req(chan, ECONNRESET); 41710a708f8fSGustavo F. Padovan goto done; 41720a708f8fSGustavo F. Padovan } 41730a708f8fSGustavo F. Padovan 41740a708f8fSGustavo F. Padovan l2cap_send_cmd(conn, l2cap_get_ident(conn), 41750a708f8fSGustavo F. Padovan L2CAP_CONF_REQ, len, req); 417673ffa904SGustavo F. Padovan chan->num_conf_req++; 41770a708f8fSGustavo F. Padovan if (result != L2CAP_CONF_SUCCESS) 41780a708f8fSGustavo F. Padovan goto done; 41790a708f8fSGustavo F. Padovan break; 41800a708f8fSGustavo F. Padovan } 41810a708f8fSGustavo F. Padovan 41820a708f8fSGustavo F. Padovan default: 41836be36555SAndrei Emeltchenko l2cap_chan_set_err(chan, ECONNRESET); 41842e0052e4SAndrei Emeltchenko 4185ba13ccd9SMarcel Holtmann __set_chan_timer(chan, L2CAP_DISC_REJ_TIMEOUT); 41865e4e3972SAndrei Emeltchenko l2cap_send_disconn_req(chan, ECONNRESET); 41870a708f8fSGustavo F. Padovan goto done; 41880a708f8fSGustavo F. Padovan } 41890a708f8fSGustavo F. Padovan 419059e54bd1SAndrei Emeltchenko if (flags & L2CAP_CONF_FLAG_CONTINUATION) 41910a708f8fSGustavo F. Padovan goto done; 41920a708f8fSGustavo F. Padovan 4193c1360a1cSGustavo F. Padovan set_bit(CONF_INPUT_DONE, &chan->conf_state); 41940a708f8fSGustavo F. Padovan 4195c1360a1cSGustavo F. Padovan if (test_bit(CONF_OUTPUT_DONE, &chan->conf_state)) { 419647d1ec61SGustavo F. Padovan set_default_fcs(chan); 41970a708f8fSGustavo F. Padovan 4198105bdf9eSMat Martineau if (chan->mode == L2CAP_MODE_ERTM || 4199105bdf9eSMat Martineau chan->mode == L2CAP_MODE_STREAMING) 42003c588192SMat Martineau err = l2cap_ertm_init(chan); 42010a708f8fSGustavo F. Padovan 42023c588192SMat Martineau if (err < 0) 42035e4e3972SAndrei Emeltchenko l2cap_send_disconn_req(chan, -err); 42043c588192SMat Martineau else 4205cf4cd009SAndrei Emeltchenko l2cap_chan_ready(chan); 42060a708f8fSGustavo F. Padovan } 42070a708f8fSGustavo F. Padovan 42080a708f8fSGustavo F. Padovan done: 42096be36555SAndrei Emeltchenko l2cap_chan_unlock(chan); 42103c588192SMat Martineau return err; 42110a708f8fSGustavo F. Padovan } 42120a708f8fSGustavo F. Padovan 42132d792818SGustavo Padovan static inline int l2cap_disconnect_req(struct l2cap_conn *conn, 4214cb3b3152SJohan Hedberg struct l2cap_cmd_hdr *cmd, u16 cmd_len, 4215cb3b3152SJohan Hedberg u8 *data) 42160a708f8fSGustavo F. Padovan { 42170a708f8fSGustavo F. Padovan struct l2cap_disconn_req *req = (struct l2cap_disconn_req *) data; 42180a708f8fSGustavo F. Padovan struct l2cap_disconn_rsp rsp; 42190a708f8fSGustavo F. Padovan u16 dcid, scid; 422048454079SGustavo F. Padovan struct l2cap_chan *chan; 42210a708f8fSGustavo F. Padovan struct sock *sk; 42220a708f8fSGustavo F. Padovan 4223cb3b3152SJohan Hedberg if (cmd_len != sizeof(*req)) 4224cb3b3152SJohan Hedberg return -EPROTO; 4225cb3b3152SJohan Hedberg 42260a708f8fSGustavo F. Padovan scid = __le16_to_cpu(req->scid); 42270a708f8fSGustavo F. Padovan dcid = __le16_to_cpu(req->dcid); 42280a708f8fSGustavo F. Padovan 42290a708f8fSGustavo F. Padovan BT_DBG("scid 0x%4.4x dcid 0x%4.4x", scid, dcid); 42300a708f8fSGustavo F. Padovan 42313df91ea2SAndrei Emeltchenko mutex_lock(&conn->chan_lock); 42323df91ea2SAndrei Emeltchenko 42333df91ea2SAndrei Emeltchenko chan = __l2cap_get_chan_by_scid(conn, dcid); 42343df91ea2SAndrei Emeltchenko if (!chan) { 42353df91ea2SAndrei Emeltchenko mutex_unlock(&conn->chan_lock); 4236c4ea249fSJohan Hedberg return -EBADSLT; 42373df91ea2SAndrei Emeltchenko } 42380a708f8fSGustavo F. Padovan 42396be36555SAndrei Emeltchenko l2cap_chan_lock(chan); 42406be36555SAndrei Emeltchenko 424148454079SGustavo F. Padovan sk = chan->sk; 424248454079SGustavo F. Padovan 4243fe4128e0SGustavo F. Padovan rsp.dcid = cpu_to_le16(chan->scid); 4244fe4128e0SGustavo F. Padovan rsp.scid = cpu_to_le16(chan->dcid); 42450a708f8fSGustavo F. Padovan l2cap_send_cmd(conn, cmd->ident, L2CAP_DISCONN_RSP, sizeof(rsp), &rsp); 42460a708f8fSGustavo F. Padovan 42476be36555SAndrei Emeltchenko lock_sock(sk); 42480a708f8fSGustavo F. Padovan sk->sk_shutdown = SHUTDOWN_MASK; 42496be36555SAndrei Emeltchenko release_sock(sk); 42500a708f8fSGustavo F. Padovan 425161d6ef3eSMat Martineau l2cap_chan_hold(chan); 425248454079SGustavo F. Padovan l2cap_chan_del(chan, ECONNRESET); 42536be36555SAndrei Emeltchenko 42546be36555SAndrei Emeltchenko l2cap_chan_unlock(chan); 42550a708f8fSGustavo F. Padovan 425680b98027SGustavo Padovan chan->ops->close(chan); 425761d6ef3eSMat Martineau l2cap_chan_put(chan); 42583df91ea2SAndrei Emeltchenko 42593df91ea2SAndrei Emeltchenko mutex_unlock(&conn->chan_lock); 42603df91ea2SAndrei Emeltchenko 42610a708f8fSGustavo F. Padovan return 0; 42620a708f8fSGustavo F. Padovan } 42630a708f8fSGustavo F. Padovan 42642d792818SGustavo Padovan static inline int l2cap_disconnect_rsp(struct l2cap_conn *conn, 4265cb3b3152SJohan Hedberg struct l2cap_cmd_hdr *cmd, u16 cmd_len, 4266cb3b3152SJohan Hedberg u8 *data) 42670a708f8fSGustavo F. Padovan { 42680a708f8fSGustavo F. Padovan struct l2cap_disconn_rsp *rsp = (struct l2cap_disconn_rsp *) data; 42690a708f8fSGustavo F. Padovan u16 dcid, scid; 427048454079SGustavo F. Padovan struct l2cap_chan *chan; 42710a708f8fSGustavo F. Padovan 4272cb3b3152SJohan Hedberg if (cmd_len != sizeof(*rsp)) 4273cb3b3152SJohan Hedberg return -EPROTO; 4274cb3b3152SJohan Hedberg 42750a708f8fSGustavo F. Padovan scid = __le16_to_cpu(rsp->scid); 42760a708f8fSGustavo F. Padovan dcid = __le16_to_cpu(rsp->dcid); 42770a708f8fSGustavo F. Padovan 42780a708f8fSGustavo F. Padovan BT_DBG("dcid 0x%4.4x scid 0x%4.4x", dcid, scid); 42790a708f8fSGustavo F. Padovan 42803df91ea2SAndrei Emeltchenko mutex_lock(&conn->chan_lock); 42813df91ea2SAndrei Emeltchenko 42823df91ea2SAndrei Emeltchenko chan = __l2cap_get_chan_by_scid(conn, scid); 42833df91ea2SAndrei Emeltchenko if (!chan) { 42843df91ea2SAndrei Emeltchenko mutex_unlock(&conn->chan_lock); 42850a708f8fSGustavo F. Padovan return 0; 42863df91ea2SAndrei Emeltchenko } 42870a708f8fSGustavo F. Padovan 42886be36555SAndrei Emeltchenko l2cap_chan_lock(chan); 428948454079SGustavo F. Padovan 429061d6ef3eSMat Martineau l2cap_chan_hold(chan); 429148454079SGustavo F. Padovan l2cap_chan_del(chan, 0); 42926be36555SAndrei Emeltchenko 42936be36555SAndrei Emeltchenko l2cap_chan_unlock(chan); 42940a708f8fSGustavo F. Padovan 429580b98027SGustavo Padovan chan->ops->close(chan); 429661d6ef3eSMat Martineau l2cap_chan_put(chan); 42973df91ea2SAndrei Emeltchenko 42983df91ea2SAndrei Emeltchenko mutex_unlock(&conn->chan_lock); 42993df91ea2SAndrei Emeltchenko 43000a708f8fSGustavo F. Padovan return 0; 43010a708f8fSGustavo F. Padovan } 43020a708f8fSGustavo F. Padovan 43032d792818SGustavo Padovan static inline int l2cap_information_req(struct l2cap_conn *conn, 4304cb3b3152SJohan Hedberg struct l2cap_cmd_hdr *cmd, u16 cmd_len, 4305cb3b3152SJohan Hedberg u8 *data) 43060a708f8fSGustavo F. Padovan { 43070a708f8fSGustavo F. Padovan struct l2cap_info_req *req = (struct l2cap_info_req *) data; 43080a708f8fSGustavo F. Padovan u16 type; 43090a708f8fSGustavo F. Padovan 4310cb3b3152SJohan Hedberg if (cmd_len != sizeof(*req)) 4311cb3b3152SJohan Hedberg return -EPROTO; 4312cb3b3152SJohan Hedberg 43130a708f8fSGustavo F. Padovan type = __le16_to_cpu(req->type); 43140a708f8fSGustavo F. Padovan 43150a708f8fSGustavo F. Padovan BT_DBG("type 0x%4.4x", type); 43160a708f8fSGustavo F. Padovan 43170a708f8fSGustavo F. Padovan if (type == L2CAP_IT_FEAT_MASK) { 43180a708f8fSGustavo F. Padovan u8 buf[8]; 43190a708f8fSGustavo F. Padovan u32 feat_mask = l2cap_feat_mask; 43200a708f8fSGustavo F. Padovan struct l2cap_info_rsp *rsp = (struct l2cap_info_rsp *) buf; 4321ac73498cSAndrei Emeltchenko rsp->type = __constant_cpu_to_le16(L2CAP_IT_FEAT_MASK); 4322ac73498cSAndrei Emeltchenko rsp->result = __constant_cpu_to_le16(L2CAP_IR_SUCCESS); 43230a708f8fSGustavo F. Padovan if (!disable_ertm) 43240a708f8fSGustavo F. Padovan feat_mask |= L2CAP_FEAT_ERTM | L2CAP_FEAT_STREAMING 43250a708f8fSGustavo F. Padovan | L2CAP_FEAT_FCS; 4326848566b3SMarcel Holtmann if (conn->hs_enabled) 43276327eb98SAndrei Emeltchenko feat_mask |= L2CAP_FEAT_EXT_FLOW 43286327eb98SAndrei Emeltchenko | L2CAP_FEAT_EXT_WINDOW; 4329a5fd6f30SAndrei Emeltchenko 43300a708f8fSGustavo F. Padovan put_unaligned_le32(feat_mask, rsp->data); 43312d792818SGustavo Padovan l2cap_send_cmd(conn, cmd->ident, L2CAP_INFO_RSP, sizeof(buf), 43322d792818SGustavo Padovan buf); 43330a708f8fSGustavo F. Padovan } else if (type == L2CAP_IT_FIXED_CHAN) { 43340a708f8fSGustavo F. Padovan u8 buf[12]; 43350a708f8fSGustavo F. Padovan struct l2cap_info_rsp *rsp = (struct l2cap_info_rsp *) buf; 433650a147cdSMat Martineau 4337848566b3SMarcel Holtmann if (conn->hs_enabled) 433850a147cdSMat Martineau l2cap_fixed_chan[0] |= L2CAP_FC_A2MP; 433950a147cdSMat Martineau else 434050a147cdSMat Martineau l2cap_fixed_chan[0] &= ~L2CAP_FC_A2MP; 434150a147cdSMat Martineau 4342ac73498cSAndrei Emeltchenko rsp->type = __constant_cpu_to_le16(L2CAP_IT_FIXED_CHAN); 4343ac73498cSAndrei Emeltchenko rsp->result = __constant_cpu_to_le16(L2CAP_IR_SUCCESS); 4344c6337ea6SAndrei Emeltchenko memcpy(rsp->data, l2cap_fixed_chan, sizeof(l2cap_fixed_chan)); 43452d792818SGustavo Padovan l2cap_send_cmd(conn, cmd->ident, L2CAP_INFO_RSP, sizeof(buf), 43462d792818SGustavo Padovan buf); 43470a708f8fSGustavo F. Padovan } else { 43480a708f8fSGustavo F. Padovan struct l2cap_info_rsp rsp; 43490a708f8fSGustavo F. Padovan rsp.type = cpu_to_le16(type); 4350ac73498cSAndrei Emeltchenko rsp.result = __constant_cpu_to_le16(L2CAP_IR_NOTSUPP); 43512d792818SGustavo Padovan l2cap_send_cmd(conn, cmd->ident, L2CAP_INFO_RSP, sizeof(rsp), 43522d792818SGustavo Padovan &rsp); 43530a708f8fSGustavo F. Padovan } 43540a708f8fSGustavo F. Padovan 43550a708f8fSGustavo F. Padovan return 0; 43560a708f8fSGustavo F. Padovan } 43570a708f8fSGustavo F. Padovan 43582d792818SGustavo Padovan static inline int l2cap_information_rsp(struct l2cap_conn *conn, 4359cb3b3152SJohan Hedberg struct l2cap_cmd_hdr *cmd, u16 cmd_len, 4360cb3b3152SJohan Hedberg u8 *data) 43610a708f8fSGustavo F. Padovan { 43620a708f8fSGustavo F. Padovan struct l2cap_info_rsp *rsp = (struct l2cap_info_rsp *) data; 43630a708f8fSGustavo F. Padovan u16 type, result; 43640a708f8fSGustavo F. Padovan 43653f6fa3d4SJaganath Kanakkassery if (cmd_len < sizeof(*rsp)) 4366cb3b3152SJohan Hedberg return -EPROTO; 4367cb3b3152SJohan Hedberg 43680a708f8fSGustavo F. Padovan type = __le16_to_cpu(rsp->type); 43690a708f8fSGustavo F. Padovan result = __le16_to_cpu(rsp->result); 43700a708f8fSGustavo F. Padovan 43710a708f8fSGustavo F. Padovan BT_DBG("type 0x%4.4x result 0x%2.2x", type, result); 43720a708f8fSGustavo F. Padovan 4373e90165beSAndrei Emeltchenko /* L2CAP Info req/rsp are unbound to channels, add extra checks */ 4374e90165beSAndrei Emeltchenko if (cmd->ident != conn->info_ident || 4375e90165beSAndrei Emeltchenko conn->info_state & L2CAP_INFO_FEAT_MASK_REQ_DONE) 4376e90165beSAndrei Emeltchenko return 0; 4377e90165beSAndrei Emeltchenko 437817cd3f37SUlisses Furquim cancel_delayed_work(&conn->info_timer); 43790a708f8fSGustavo F. Padovan 43800a708f8fSGustavo F. Padovan if (result != L2CAP_IR_SUCCESS) { 43810a708f8fSGustavo F. Padovan conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_DONE; 43820a708f8fSGustavo F. Padovan conn->info_ident = 0; 43830a708f8fSGustavo F. Padovan 43840a708f8fSGustavo F. Padovan l2cap_conn_start(conn); 43850a708f8fSGustavo F. Padovan 43860a708f8fSGustavo F. Padovan return 0; 43870a708f8fSGustavo F. Padovan } 43880a708f8fSGustavo F. Padovan 4389978c93b9SAndrei Emeltchenko switch (type) { 4390978c93b9SAndrei Emeltchenko case L2CAP_IT_FEAT_MASK: 43910a708f8fSGustavo F. Padovan conn->feat_mask = get_unaligned_le32(rsp->data); 43920a708f8fSGustavo F. Padovan 43930a708f8fSGustavo F. Padovan if (conn->feat_mask & L2CAP_FEAT_FIXED_CHAN) { 43940a708f8fSGustavo F. Padovan struct l2cap_info_req req; 4395ac73498cSAndrei Emeltchenko req.type = __constant_cpu_to_le16(L2CAP_IT_FIXED_CHAN); 43960a708f8fSGustavo F. Padovan 43970a708f8fSGustavo F. Padovan conn->info_ident = l2cap_get_ident(conn); 43980a708f8fSGustavo F. Padovan 43990a708f8fSGustavo F. Padovan l2cap_send_cmd(conn, conn->info_ident, 44000a708f8fSGustavo F. Padovan L2CAP_INFO_REQ, sizeof(req), &req); 44010a708f8fSGustavo F. Padovan } else { 44020a708f8fSGustavo F. Padovan conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_DONE; 44030a708f8fSGustavo F. Padovan conn->info_ident = 0; 44040a708f8fSGustavo F. Padovan 44050a708f8fSGustavo F. Padovan l2cap_conn_start(conn); 44060a708f8fSGustavo F. Padovan } 4407978c93b9SAndrei Emeltchenko break; 4408978c93b9SAndrei Emeltchenko 4409978c93b9SAndrei Emeltchenko case L2CAP_IT_FIXED_CHAN: 4410978c93b9SAndrei Emeltchenko conn->fixed_chan_mask = rsp->data[0]; 44110a708f8fSGustavo F. Padovan conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_DONE; 44120a708f8fSGustavo F. Padovan conn->info_ident = 0; 44130a708f8fSGustavo F. Padovan 44140a708f8fSGustavo F. Padovan l2cap_conn_start(conn); 4415978c93b9SAndrei Emeltchenko break; 44160a708f8fSGustavo F. Padovan } 44170a708f8fSGustavo F. Padovan 44180a708f8fSGustavo F. Padovan return 0; 44190a708f8fSGustavo F. Padovan } 44200a708f8fSGustavo F. Padovan 44211700915fSMat Martineau static int l2cap_create_channel_req(struct l2cap_conn *conn, 44222d792818SGustavo Padovan struct l2cap_cmd_hdr *cmd, 44232d792818SGustavo Padovan u16 cmd_len, void *data) 4424f94ff6ffSMat Martineau { 4425f94ff6ffSMat Martineau struct l2cap_create_chan_req *req = data; 44266e1df6a6SAndrei Emeltchenko struct l2cap_create_chan_rsp rsp; 44271700915fSMat Martineau struct l2cap_chan *chan; 44286e1df6a6SAndrei Emeltchenko struct hci_dev *hdev; 4429f94ff6ffSMat Martineau u16 psm, scid; 4430f94ff6ffSMat Martineau 4431f94ff6ffSMat Martineau if (cmd_len != sizeof(*req)) 4432f94ff6ffSMat Martineau return -EPROTO; 4433f94ff6ffSMat Martineau 4434848566b3SMarcel Holtmann if (!conn->hs_enabled) 4435f94ff6ffSMat Martineau return -EINVAL; 4436f94ff6ffSMat Martineau 4437f94ff6ffSMat Martineau psm = le16_to_cpu(req->psm); 4438f94ff6ffSMat Martineau scid = le16_to_cpu(req->scid); 4439f94ff6ffSMat Martineau 4440ad0ac6caSAndrei Emeltchenko BT_DBG("psm 0x%2.2x, scid 0x%4.4x, amp_id %d", psm, scid, req->amp_id); 4441f94ff6ffSMat Martineau 44426e1df6a6SAndrei Emeltchenko /* For controller id 0 make BR/EDR connection */ 44436ed971caSMarcel Holtmann if (req->amp_id == AMP_ID_BREDR) { 44446e1df6a6SAndrei Emeltchenko l2cap_connect(conn, cmd, data, L2CAP_CREATE_CHAN_RSP, 44456e1df6a6SAndrei Emeltchenko req->amp_id); 44466e1df6a6SAndrei Emeltchenko return 0; 44476e1df6a6SAndrei Emeltchenko } 44481700915fSMat Martineau 44491700915fSMat Martineau /* Validate AMP controller id */ 44501700915fSMat Martineau hdev = hci_dev_get(req->amp_id); 44516e1df6a6SAndrei Emeltchenko if (!hdev) 44526e1df6a6SAndrei Emeltchenko goto error; 44531700915fSMat Martineau 44546e1df6a6SAndrei Emeltchenko if (hdev->dev_type != HCI_AMP || !test_bit(HCI_UP, &hdev->flags)) { 44556e1df6a6SAndrei Emeltchenko hci_dev_put(hdev); 44566e1df6a6SAndrei Emeltchenko goto error; 44576e1df6a6SAndrei Emeltchenko } 44586e1df6a6SAndrei Emeltchenko 44596e1df6a6SAndrei Emeltchenko chan = l2cap_connect(conn, cmd, data, L2CAP_CREATE_CHAN_RSP, 44606e1df6a6SAndrei Emeltchenko req->amp_id); 44616e1df6a6SAndrei Emeltchenko if (chan) { 44626e1df6a6SAndrei Emeltchenko struct amp_mgr *mgr = conn->hcon->amp_mgr; 44636e1df6a6SAndrei Emeltchenko struct hci_conn *hs_hcon; 44646e1df6a6SAndrei Emeltchenko 44656e1df6a6SAndrei Emeltchenko hs_hcon = hci_conn_hash_lookup_ba(hdev, AMP_LINK, conn->dst); 44666e1df6a6SAndrei Emeltchenko if (!hs_hcon) { 44676e1df6a6SAndrei Emeltchenko hci_dev_put(hdev); 446821870b52SJohan Hedberg return -EBADSLT; 44696e1df6a6SAndrei Emeltchenko } 44706e1df6a6SAndrei Emeltchenko 44716e1df6a6SAndrei Emeltchenko BT_DBG("mgr %p bredr_chan %p hs_hcon %p", mgr, chan, hs_hcon); 44726e1df6a6SAndrei Emeltchenko 44736e1df6a6SAndrei Emeltchenko mgr->bredr_chan = chan; 44746e1df6a6SAndrei Emeltchenko chan->hs_hcon = hs_hcon; 4475fd45bf4cSAndrei Emeltchenko chan->fcs = L2CAP_FCS_NONE; 44766e1df6a6SAndrei Emeltchenko conn->mtu = hdev->block_mtu; 44776e1df6a6SAndrei Emeltchenko } 44786e1df6a6SAndrei Emeltchenko 44796e1df6a6SAndrei Emeltchenko hci_dev_put(hdev); 44806e1df6a6SAndrei Emeltchenko 44816e1df6a6SAndrei Emeltchenko return 0; 44826e1df6a6SAndrei Emeltchenko 44836e1df6a6SAndrei Emeltchenko error: 4484f94ff6ffSMat Martineau rsp.dcid = 0; 4485f94ff6ffSMat Martineau rsp.scid = cpu_to_le16(scid); 44861700915fSMat Martineau rsp.result = __constant_cpu_to_le16(L2CAP_CR_BAD_AMP); 44878ce0c498SAndrei Emeltchenko rsp.status = __constant_cpu_to_le16(L2CAP_CS_NO_INFO); 4488f94ff6ffSMat Martineau 4489f94ff6ffSMat Martineau l2cap_send_cmd(conn, cmd->ident, L2CAP_CREATE_CHAN_RSP, 4490f94ff6ffSMat Martineau sizeof(rsp), &rsp); 4491f94ff6ffSMat Martineau 4492dc280801SJohan Hedberg return 0; 4493f94ff6ffSMat Martineau } 4494f94ff6ffSMat Martineau 44958eb200bdSMat Martineau static void l2cap_send_move_chan_req(struct l2cap_chan *chan, u8 dest_amp_id) 44968eb200bdSMat Martineau { 44978eb200bdSMat Martineau struct l2cap_move_chan_req req; 44988eb200bdSMat Martineau u8 ident; 44998eb200bdSMat Martineau 45008eb200bdSMat Martineau BT_DBG("chan %p, dest_amp_id %d", chan, dest_amp_id); 45018eb200bdSMat Martineau 45028eb200bdSMat Martineau ident = l2cap_get_ident(chan->conn); 45038eb200bdSMat Martineau chan->ident = ident; 45048eb200bdSMat Martineau 45058eb200bdSMat Martineau req.icid = cpu_to_le16(chan->scid); 45068eb200bdSMat Martineau req.dest_amp_id = dest_amp_id; 45078eb200bdSMat Martineau 45088eb200bdSMat Martineau l2cap_send_cmd(chan->conn, ident, L2CAP_MOVE_CHAN_REQ, sizeof(req), 45098eb200bdSMat Martineau &req); 45108eb200bdSMat Martineau 45118eb200bdSMat Martineau __set_chan_timer(chan, L2CAP_MOVE_TIMEOUT); 45128eb200bdSMat Martineau } 45138eb200bdSMat Martineau 45141500109bSMat Martineau static void l2cap_send_move_chan_rsp(struct l2cap_chan *chan, u16 result) 45158d5a04a1SMat Martineau { 45168d5a04a1SMat Martineau struct l2cap_move_chan_rsp rsp; 45178d5a04a1SMat Martineau 45181500109bSMat Martineau BT_DBG("chan %p, result 0x%4.4x", chan, result); 45198d5a04a1SMat Martineau 45201500109bSMat Martineau rsp.icid = cpu_to_le16(chan->dcid); 45218d5a04a1SMat Martineau rsp.result = cpu_to_le16(result); 45228d5a04a1SMat Martineau 45231500109bSMat Martineau l2cap_send_cmd(chan->conn, chan->ident, L2CAP_MOVE_CHAN_RSP, 45241500109bSMat Martineau sizeof(rsp), &rsp); 45258d5a04a1SMat Martineau } 45268d5a04a1SMat Martineau 45275b155ef9SMat Martineau static void l2cap_send_move_chan_cfm(struct l2cap_chan *chan, u16 result) 45288d5a04a1SMat Martineau { 45298d5a04a1SMat Martineau struct l2cap_move_chan_cfm cfm; 45308d5a04a1SMat Martineau 45315b155ef9SMat Martineau BT_DBG("chan %p, result 0x%4.4x", chan, result); 45328d5a04a1SMat Martineau 45335b155ef9SMat Martineau chan->ident = l2cap_get_ident(chan->conn); 45348d5a04a1SMat Martineau 45355b155ef9SMat Martineau cfm.icid = cpu_to_le16(chan->scid); 45368d5a04a1SMat Martineau cfm.result = cpu_to_le16(result); 45378d5a04a1SMat Martineau 45385b155ef9SMat Martineau l2cap_send_cmd(chan->conn, chan->ident, L2CAP_MOVE_CHAN_CFM, 45395b155ef9SMat Martineau sizeof(cfm), &cfm); 45405b155ef9SMat Martineau 45415b155ef9SMat Martineau __set_chan_timer(chan, L2CAP_MOVE_TIMEOUT); 45425b155ef9SMat Martineau } 45435b155ef9SMat Martineau 45445b155ef9SMat Martineau static void l2cap_send_move_chan_cfm_icid(struct l2cap_conn *conn, u16 icid) 45455b155ef9SMat Martineau { 45465b155ef9SMat Martineau struct l2cap_move_chan_cfm cfm; 45475b155ef9SMat Martineau 45485b155ef9SMat Martineau BT_DBG("conn %p, icid 0x%4.4x", conn, icid); 45495b155ef9SMat Martineau 45505b155ef9SMat Martineau cfm.icid = cpu_to_le16(icid); 45515b155ef9SMat Martineau cfm.result = __constant_cpu_to_le16(L2CAP_MC_UNCONFIRMED); 45525b155ef9SMat Martineau 45535b155ef9SMat Martineau l2cap_send_cmd(conn, l2cap_get_ident(conn), L2CAP_MOVE_CHAN_CFM, 45545b155ef9SMat Martineau sizeof(cfm), &cfm); 45558d5a04a1SMat Martineau } 45568d5a04a1SMat Martineau 45578d5a04a1SMat Martineau static void l2cap_send_move_chan_cfm_rsp(struct l2cap_conn *conn, u8 ident, 45588d5a04a1SMat Martineau u16 icid) 45598d5a04a1SMat Martineau { 45608d5a04a1SMat Martineau struct l2cap_move_chan_cfm_rsp rsp; 45618d5a04a1SMat Martineau 4562ad0ac6caSAndrei Emeltchenko BT_DBG("icid 0x%4.4x", icid); 45638d5a04a1SMat Martineau 45648d5a04a1SMat Martineau rsp.icid = cpu_to_le16(icid); 45658d5a04a1SMat Martineau l2cap_send_cmd(conn, ident, L2CAP_MOVE_CHAN_CFM_RSP, sizeof(rsp), &rsp); 45668d5a04a1SMat Martineau } 45678d5a04a1SMat Martineau 45685f3847a4SMat Martineau static void __release_logical_link(struct l2cap_chan *chan) 45695f3847a4SMat Martineau { 45705f3847a4SMat Martineau chan->hs_hchan = NULL; 45715f3847a4SMat Martineau chan->hs_hcon = NULL; 45725f3847a4SMat Martineau 45735f3847a4SMat Martineau /* Placeholder - release the logical link */ 45745f3847a4SMat Martineau } 45755f3847a4SMat Martineau 45761500109bSMat Martineau static void l2cap_logical_fail(struct l2cap_chan *chan) 45771500109bSMat Martineau { 45781500109bSMat Martineau /* Logical link setup failed */ 45791500109bSMat Martineau if (chan->state != BT_CONNECTED) { 45801500109bSMat Martineau /* Create channel failure, disconnect */ 45815e4e3972SAndrei Emeltchenko l2cap_send_disconn_req(chan, ECONNRESET); 45821500109bSMat Martineau return; 45831500109bSMat Martineau } 45841500109bSMat Martineau 45851500109bSMat Martineau switch (chan->move_role) { 45861500109bSMat Martineau case L2CAP_MOVE_ROLE_RESPONDER: 45871500109bSMat Martineau l2cap_move_done(chan); 45881500109bSMat Martineau l2cap_send_move_chan_rsp(chan, L2CAP_MR_NOT_SUPP); 45891500109bSMat Martineau break; 45901500109bSMat Martineau case L2CAP_MOVE_ROLE_INITIATOR: 45911500109bSMat Martineau if (chan->move_state == L2CAP_MOVE_WAIT_LOGICAL_COMP || 45921500109bSMat Martineau chan->move_state == L2CAP_MOVE_WAIT_LOGICAL_CFM) { 45931500109bSMat Martineau /* Remote has only sent pending or 45941500109bSMat Martineau * success responses, clean up 45951500109bSMat Martineau */ 45961500109bSMat Martineau l2cap_move_done(chan); 45971500109bSMat Martineau } 45981500109bSMat Martineau 45991500109bSMat Martineau /* Other amp move states imply that the move 46001500109bSMat Martineau * has already aborted 46011500109bSMat Martineau */ 46021500109bSMat Martineau l2cap_send_move_chan_cfm(chan, L2CAP_MC_UNCONFIRMED); 46031500109bSMat Martineau break; 46041500109bSMat Martineau } 46051500109bSMat Martineau } 46061500109bSMat Martineau 46071500109bSMat Martineau static void l2cap_logical_finish_create(struct l2cap_chan *chan, 46081500109bSMat Martineau struct hci_chan *hchan) 46091500109bSMat Martineau { 46101500109bSMat Martineau struct l2cap_conf_rsp rsp; 46111500109bSMat Martineau 4612336178a3SAndrei Emeltchenko chan->hs_hchan = hchan; 46131500109bSMat Martineau chan->hs_hcon->l2cap_data = chan->conn; 46141500109bSMat Martineau 461535ba9561SAndrei Emeltchenko l2cap_send_efs_conf_rsp(chan, &rsp, chan->ident, 0); 46161500109bSMat Martineau 46171500109bSMat Martineau if (test_bit(CONF_INPUT_DONE, &chan->conf_state)) { 4618fe79c6feSAndrei Emeltchenko int err; 46191500109bSMat Martineau 46201500109bSMat Martineau set_default_fcs(chan); 46211500109bSMat Martineau 46221500109bSMat Martineau err = l2cap_ertm_init(chan); 46231500109bSMat Martineau if (err < 0) 46245e4e3972SAndrei Emeltchenko l2cap_send_disconn_req(chan, -err); 46251500109bSMat Martineau else 46261500109bSMat Martineau l2cap_chan_ready(chan); 46271500109bSMat Martineau } 46281500109bSMat Martineau } 46291500109bSMat Martineau 46301500109bSMat Martineau static void l2cap_logical_finish_move(struct l2cap_chan *chan, 46311500109bSMat Martineau struct hci_chan *hchan) 46321500109bSMat Martineau { 46331500109bSMat Martineau chan->hs_hcon = hchan->conn; 46341500109bSMat Martineau chan->hs_hcon->l2cap_data = chan->conn; 46351500109bSMat Martineau 46361500109bSMat Martineau BT_DBG("move_state %d", chan->move_state); 46371500109bSMat Martineau 46381500109bSMat Martineau switch (chan->move_state) { 46391500109bSMat Martineau case L2CAP_MOVE_WAIT_LOGICAL_COMP: 46401500109bSMat Martineau /* Move confirm will be sent after a success 46411500109bSMat Martineau * response is received 46421500109bSMat Martineau */ 46431500109bSMat Martineau chan->move_state = L2CAP_MOVE_WAIT_RSP_SUCCESS; 46441500109bSMat Martineau break; 46451500109bSMat Martineau case L2CAP_MOVE_WAIT_LOGICAL_CFM: 46461500109bSMat Martineau if (test_bit(CONN_LOCAL_BUSY, &chan->conn_state)) { 46471500109bSMat Martineau chan->move_state = L2CAP_MOVE_WAIT_LOCAL_BUSY; 46481500109bSMat Martineau } else if (chan->move_role == L2CAP_MOVE_ROLE_INITIATOR) { 46491500109bSMat Martineau chan->move_state = L2CAP_MOVE_WAIT_CONFIRM_RSP; 46501500109bSMat Martineau l2cap_send_move_chan_cfm(chan, L2CAP_MC_CONFIRMED); 46511500109bSMat Martineau } else if (chan->move_role == L2CAP_MOVE_ROLE_RESPONDER) { 46521500109bSMat Martineau chan->move_state = L2CAP_MOVE_WAIT_CONFIRM; 46531500109bSMat Martineau l2cap_send_move_chan_rsp(chan, L2CAP_MR_SUCCESS); 46541500109bSMat Martineau } 46551500109bSMat Martineau break; 46561500109bSMat Martineau default: 46571500109bSMat Martineau /* Move was not in expected state, free the channel */ 46581500109bSMat Martineau __release_logical_link(chan); 46591500109bSMat Martineau 46601500109bSMat Martineau chan->move_state = L2CAP_MOVE_STABLE; 46611500109bSMat Martineau } 46621500109bSMat Martineau } 46631500109bSMat Martineau 46641500109bSMat Martineau /* Call with chan locked */ 466527695fb4SAndrei Emeltchenko void l2cap_logical_cfm(struct l2cap_chan *chan, struct hci_chan *hchan, 46665b155ef9SMat Martineau u8 status) 46675b155ef9SMat Martineau { 46681500109bSMat Martineau BT_DBG("chan %p, hchan %p, status %d", chan, hchan, status); 46691500109bSMat Martineau 46701500109bSMat Martineau if (status) { 46711500109bSMat Martineau l2cap_logical_fail(chan); 46721500109bSMat Martineau __release_logical_link(chan); 46735b155ef9SMat Martineau return; 46745b155ef9SMat Martineau } 46755b155ef9SMat Martineau 46761500109bSMat Martineau if (chan->state != BT_CONNECTED) { 46771500109bSMat Martineau /* Ignore logical link if channel is on BR/EDR */ 46786ed971caSMarcel Holtmann if (chan->local_amp_id != AMP_ID_BREDR) 46791500109bSMat Martineau l2cap_logical_finish_create(chan, hchan); 46801500109bSMat Martineau } else { 46811500109bSMat Martineau l2cap_logical_finish_move(chan, hchan); 46821500109bSMat Martineau } 46831500109bSMat Martineau } 46841500109bSMat Martineau 46853f7a56c4SMat Martineau void l2cap_move_start(struct l2cap_chan *chan) 46863f7a56c4SMat Martineau { 46873f7a56c4SMat Martineau BT_DBG("chan %p", chan); 46883f7a56c4SMat Martineau 46896ed971caSMarcel Holtmann if (chan->local_amp_id == AMP_ID_BREDR) { 46903f7a56c4SMat Martineau if (chan->chan_policy != BT_CHANNEL_POLICY_AMP_PREFERRED) 46913f7a56c4SMat Martineau return; 46923f7a56c4SMat Martineau chan->move_role = L2CAP_MOVE_ROLE_INITIATOR; 46933f7a56c4SMat Martineau chan->move_state = L2CAP_MOVE_WAIT_PREPARE; 46943f7a56c4SMat Martineau /* Placeholder - start physical link setup */ 46953f7a56c4SMat Martineau } else { 46963f7a56c4SMat Martineau chan->move_role = L2CAP_MOVE_ROLE_INITIATOR; 46973f7a56c4SMat Martineau chan->move_state = L2CAP_MOVE_WAIT_RSP_SUCCESS; 46983f7a56c4SMat Martineau chan->move_id = 0; 46993f7a56c4SMat Martineau l2cap_move_setup(chan); 47003f7a56c4SMat Martineau l2cap_send_move_chan_req(chan, 0); 47013f7a56c4SMat Martineau } 47023f7a56c4SMat Martineau } 47033f7a56c4SMat Martineau 47048eb200bdSMat Martineau static void l2cap_do_create(struct l2cap_chan *chan, int result, 47058eb200bdSMat Martineau u8 local_amp_id, u8 remote_amp_id) 47068eb200bdSMat Martineau { 470762748ca1SAndrei Emeltchenko BT_DBG("chan %p state %s %u -> %u", chan, state_to_string(chan->state), 470862748ca1SAndrei Emeltchenko local_amp_id, remote_amp_id); 470962748ca1SAndrei Emeltchenko 471012d6cc60SAndrei Emeltchenko chan->fcs = L2CAP_FCS_NONE; 471112d6cc60SAndrei Emeltchenko 471262748ca1SAndrei Emeltchenko /* Outgoing channel on AMP */ 471362748ca1SAndrei Emeltchenko if (chan->state == BT_CONNECT) { 471462748ca1SAndrei Emeltchenko if (result == L2CAP_CR_SUCCESS) { 471562748ca1SAndrei Emeltchenko chan->local_amp_id = local_amp_id; 471662748ca1SAndrei Emeltchenko l2cap_send_create_chan_req(chan, remote_amp_id); 471762748ca1SAndrei Emeltchenko } else { 471862748ca1SAndrei Emeltchenko /* Revert to BR/EDR connect */ 471962748ca1SAndrei Emeltchenko l2cap_send_conn_req(chan); 472062748ca1SAndrei Emeltchenko } 472162748ca1SAndrei Emeltchenko 472262748ca1SAndrei Emeltchenko return; 472362748ca1SAndrei Emeltchenko } 472462748ca1SAndrei Emeltchenko 472562748ca1SAndrei Emeltchenko /* Incoming channel on AMP */ 472662748ca1SAndrei Emeltchenko if (__l2cap_no_conn_pending(chan)) { 47278eb200bdSMat Martineau struct l2cap_conn_rsp rsp; 47288eb200bdSMat Martineau char buf[128]; 47298eb200bdSMat Martineau rsp.scid = cpu_to_le16(chan->dcid); 47308eb200bdSMat Martineau rsp.dcid = cpu_to_le16(chan->scid); 47318eb200bdSMat Martineau 47328eb200bdSMat Martineau if (result == L2CAP_CR_SUCCESS) { 47338eb200bdSMat Martineau /* Send successful response */ 473462cd50e2SAndrei Emeltchenko rsp.result = __constant_cpu_to_le16(L2CAP_CR_SUCCESS); 473562cd50e2SAndrei Emeltchenko rsp.status = __constant_cpu_to_le16(L2CAP_CS_NO_INFO); 47368eb200bdSMat Martineau } else { 47378eb200bdSMat Martineau /* Send negative response */ 473862cd50e2SAndrei Emeltchenko rsp.result = __constant_cpu_to_le16(L2CAP_CR_NO_MEM); 473962cd50e2SAndrei Emeltchenko rsp.status = __constant_cpu_to_le16(L2CAP_CS_NO_INFO); 47408eb200bdSMat Martineau } 47418eb200bdSMat Martineau 47428eb200bdSMat Martineau l2cap_send_cmd(chan->conn, chan->ident, L2CAP_CREATE_CHAN_RSP, 47438eb200bdSMat Martineau sizeof(rsp), &rsp); 47448eb200bdSMat Martineau 47458eb200bdSMat Martineau if (result == L2CAP_CR_SUCCESS) { 47468eb200bdSMat Martineau __l2cap_state_change(chan, BT_CONFIG); 47478eb200bdSMat Martineau set_bit(CONF_REQ_SENT, &chan->conf_state); 47488eb200bdSMat Martineau l2cap_send_cmd(chan->conn, l2cap_get_ident(chan->conn), 47498eb200bdSMat Martineau L2CAP_CONF_REQ, 47508eb200bdSMat Martineau l2cap_build_conf_req(chan, buf), buf); 47518eb200bdSMat Martineau chan->num_conf_req++; 47528eb200bdSMat Martineau } 47538eb200bdSMat Martineau } 47548eb200bdSMat Martineau } 47558eb200bdSMat Martineau 47568eb200bdSMat Martineau static void l2cap_do_move_initiate(struct l2cap_chan *chan, u8 local_amp_id, 47578eb200bdSMat Martineau u8 remote_amp_id) 47588eb200bdSMat Martineau { 47598eb200bdSMat Martineau l2cap_move_setup(chan); 47608eb200bdSMat Martineau chan->move_id = local_amp_id; 47618eb200bdSMat Martineau chan->move_state = L2CAP_MOVE_WAIT_RSP; 47628eb200bdSMat Martineau 47638eb200bdSMat Martineau l2cap_send_move_chan_req(chan, remote_amp_id); 47648eb200bdSMat Martineau } 47658eb200bdSMat Martineau 47668eb200bdSMat Martineau static void l2cap_do_move_respond(struct l2cap_chan *chan, int result) 47678eb200bdSMat Martineau { 47688eb200bdSMat Martineau struct hci_chan *hchan = NULL; 47698eb200bdSMat Martineau 47708eb200bdSMat Martineau /* Placeholder - get hci_chan for logical link */ 47718eb200bdSMat Martineau 47728eb200bdSMat Martineau if (hchan) { 47738eb200bdSMat Martineau if (hchan->state == BT_CONNECTED) { 47748eb200bdSMat Martineau /* Logical link is ready to go */ 47758eb200bdSMat Martineau chan->hs_hcon = hchan->conn; 47768eb200bdSMat Martineau chan->hs_hcon->l2cap_data = chan->conn; 47778eb200bdSMat Martineau chan->move_state = L2CAP_MOVE_WAIT_CONFIRM; 47788eb200bdSMat Martineau l2cap_send_move_chan_rsp(chan, L2CAP_MR_SUCCESS); 47798eb200bdSMat Martineau 47808eb200bdSMat Martineau l2cap_logical_cfm(chan, hchan, L2CAP_MR_SUCCESS); 47818eb200bdSMat Martineau } else { 47828eb200bdSMat Martineau /* Wait for logical link to be ready */ 47838eb200bdSMat Martineau chan->move_state = L2CAP_MOVE_WAIT_LOGICAL_CFM; 47848eb200bdSMat Martineau } 47858eb200bdSMat Martineau } else { 47868eb200bdSMat Martineau /* Logical link not available */ 47878eb200bdSMat Martineau l2cap_send_move_chan_rsp(chan, L2CAP_MR_NOT_ALLOWED); 47888eb200bdSMat Martineau } 47898eb200bdSMat Martineau } 47908eb200bdSMat Martineau 47918eb200bdSMat Martineau static void l2cap_do_move_cancel(struct l2cap_chan *chan, int result) 47928eb200bdSMat Martineau { 47938eb200bdSMat Martineau if (chan->move_role == L2CAP_MOVE_ROLE_RESPONDER) { 47948eb200bdSMat Martineau u8 rsp_result; 47958eb200bdSMat Martineau if (result == -EINVAL) 47968eb200bdSMat Martineau rsp_result = L2CAP_MR_BAD_ID; 47978eb200bdSMat Martineau else 47988eb200bdSMat Martineau rsp_result = L2CAP_MR_NOT_ALLOWED; 47998eb200bdSMat Martineau 48008eb200bdSMat Martineau l2cap_send_move_chan_rsp(chan, rsp_result); 48018eb200bdSMat Martineau } 48028eb200bdSMat Martineau 48038eb200bdSMat Martineau chan->move_role = L2CAP_MOVE_ROLE_NONE; 48048eb200bdSMat Martineau chan->move_state = L2CAP_MOVE_STABLE; 48058eb200bdSMat Martineau 48068eb200bdSMat Martineau /* Restart data transmission */ 48078eb200bdSMat Martineau l2cap_ertm_send(chan); 48088eb200bdSMat Martineau } 48098eb200bdSMat Martineau 4810a514b17fSAndrei Emeltchenko /* Invoke with locked chan */ 4811a514b17fSAndrei Emeltchenko void __l2cap_physical_cfm(struct l2cap_chan *chan, int result) 48128eb200bdSMat Martineau { 4813770bfefaSAndrei Emeltchenko u8 local_amp_id = chan->local_amp_id; 4814fffadc08SAndrei Emeltchenko u8 remote_amp_id = chan->remote_amp_id; 4815770bfefaSAndrei Emeltchenko 48168eb200bdSMat Martineau BT_DBG("chan %p, result %d, local_amp_id %d, remote_amp_id %d", 48178eb200bdSMat Martineau chan, result, local_amp_id, remote_amp_id); 48188eb200bdSMat Martineau 48198eb200bdSMat Martineau if (chan->state == BT_DISCONN || chan->state == BT_CLOSED) { 48208eb200bdSMat Martineau l2cap_chan_unlock(chan); 48218eb200bdSMat Martineau return; 48228eb200bdSMat Martineau } 48238eb200bdSMat Martineau 48248eb200bdSMat Martineau if (chan->state != BT_CONNECTED) { 48258eb200bdSMat Martineau l2cap_do_create(chan, result, local_amp_id, remote_amp_id); 48268eb200bdSMat Martineau } else if (result != L2CAP_MR_SUCCESS) { 48278eb200bdSMat Martineau l2cap_do_move_cancel(chan, result); 48288eb200bdSMat Martineau } else { 48298eb200bdSMat Martineau switch (chan->move_role) { 48308eb200bdSMat Martineau case L2CAP_MOVE_ROLE_INITIATOR: 48318eb200bdSMat Martineau l2cap_do_move_initiate(chan, local_amp_id, 48328eb200bdSMat Martineau remote_amp_id); 48338eb200bdSMat Martineau break; 48348eb200bdSMat Martineau case L2CAP_MOVE_ROLE_RESPONDER: 48358eb200bdSMat Martineau l2cap_do_move_respond(chan, result); 48368eb200bdSMat Martineau break; 48378eb200bdSMat Martineau default: 48388eb200bdSMat Martineau l2cap_do_move_cancel(chan, result); 48398eb200bdSMat Martineau break; 48408eb200bdSMat Martineau } 48418eb200bdSMat Martineau } 48428eb200bdSMat Martineau } 48438eb200bdSMat Martineau 48448d5a04a1SMat Martineau static inline int l2cap_move_channel_req(struct l2cap_conn *conn, 4845ad0ac6caSAndrei Emeltchenko struct l2cap_cmd_hdr *cmd, 4846ad0ac6caSAndrei Emeltchenko u16 cmd_len, void *data) 48478d5a04a1SMat Martineau { 48488d5a04a1SMat Martineau struct l2cap_move_chan_req *req = data; 48491500109bSMat Martineau struct l2cap_move_chan_rsp rsp; 485002b0fbb9SMat Martineau struct l2cap_chan *chan; 48518d5a04a1SMat Martineau u16 icid = 0; 48528d5a04a1SMat Martineau u16 result = L2CAP_MR_NOT_ALLOWED; 48538d5a04a1SMat Martineau 48548d5a04a1SMat Martineau if (cmd_len != sizeof(*req)) 48558d5a04a1SMat Martineau return -EPROTO; 48568d5a04a1SMat Martineau 48578d5a04a1SMat Martineau icid = le16_to_cpu(req->icid); 48588d5a04a1SMat Martineau 4859ad0ac6caSAndrei Emeltchenko BT_DBG("icid 0x%4.4x, dest_amp_id %d", icid, req->dest_amp_id); 48608d5a04a1SMat Martineau 4861848566b3SMarcel Holtmann if (!conn->hs_enabled) 48628d5a04a1SMat Martineau return -EINVAL; 48638d5a04a1SMat Martineau 486402b0fbb9SMat Martineau chan = l2cap_get_chan_by_dcid(conn, icid); 486502b0fbb9SMat Martineau if (!chan) { 48661500109bSMat Martineau rsp.icid = cpu_to_le16(icid); 48671500109bSMat Martineau rsp.result = __constant_cpu_to_le16(L2CAP_MR_NOT_ALLOWED); 48681500109bSMat Martineau l2cap_send_cmd(conn, cmd->ident, L2CAP_MOVE_CHAN_RSP, 48691500109bSMat Martineau sizeof(rsp), &rsp); 487002b0fbb9SMat Martineau return 0; 487102b0fbb9SMat Martineau } 487202b0fbb9SMat Martineau 48731500109bSMat Martineau chan->ident = cmd->ident; 48741500109bSMat Martineau 487502b0fbb9SMat Martineau if (chan->scid < L2CAP_CID_DYN_START || 487602b0fbb9SMat Martineau chan->chan_policy == BT_CHANNEL_POLICY_BREDR_ONLY || 487702b0fbb9SMat Martineau (chan->mode != L2CAP_MODE_ERTM && 487802b0fbb9SMat Martineau chan->mode != L2CAP_MODE_STREAMING)) { 487902b0fbb9SMat Martineau result = L2CAP_MR_NOT_ALLOWED; 488002b0fbb9SMat Martineau goto send_move_response; 488102b0fbb9SMat Martineau } 488202b0fbb9SMat Martineau 488302b0fbb9SMat Martineau if (chan->local_amp_id == req->dest_amp_id) { 488402b0fbb9SMat Martineau result = L2CAP_MR_SAME_ID; 488502b0fbb9SMat Martineau goto send_move_response; 488602b0fbb9SMat Martineau } 488702b0fbb9SMat Martineau 48886ed971caSMarcel Holtmann if (req->dest_amp_id != AMP_ID_BREDR) { 488902b0fbb9SMat Martineau struct hci_dev *hdev; 489002b0fbb9SMat Martineau hdev = hci_dev_get(req->dest_amp_id); 489102b0fbb9SMat Martineau if (!hdev || hdev->dev_type != HCI_AMP || 489202b0fbb9SMat Martineau !test_bit(HCI_UP, &hdev->flags)) { 489302b0fbb9SMat Martineau if (hdev) 489402b0fbb9SMat Martineau hci_dev_put(hdev); 489502b0fbb9SMat Martineau 489602b0fbb9SMat Martineau result = L2CAP_MR_BAD_ID; 489702b0fbb9SMat Martineau goto send_move_response; 489802b0fbb9SMat Martineau } 489902b0fbb9SMat Martineau hci_dev_put(hdev); 490002b0fbb9SMat Martineau } 490102b0fbb9SMat Martineau 490202b0fbb9SMat Martineau /* Detect a move collision. Only send a collision response 490302b0fbb9SMat Martineau * if this side has "lost", otherwise proceed with the move. 490402b0fbb9SMat Martineau * The winner has the larger bd_addr. 490502b0fbb9SMat Martineau */ 490602b0fbb9SMat Martineau if ((__chan_is_moving(chan) || 490702b0fbb9SMat Martineau chan->move_role != L2CAP_MOVE_ROLE_NONE) && 490802b0fbb9SMat Martineau bacmp(conn->src, conn->dst) > 0) { 490902b0fbb9SMat Martineau result = L2CAP_MR_COLLISION; 491002b0fbb9SMat Martineau goto send_move_response; 491102b0fbb9SMat Martineau } 491202b0fbb9SMat Martineau 491302b0fbb9SMat Martineau chan->move_role = L2CAP_MOVE_ROLE_RESPONDER; 491402b0fbb9SMat Martineau l2cap_move_setup(chan); 491502b0fbb9SMat Martineau chan->move_id = req->dest_amp_id; 491602b0fbb9SMat Martineau icid = chan->dcid; 491702b0fbb9SMat Martineau 49186ed971caSMarcel Holtmann if (req->dest_amp_id == AMP_ID_BREDR) { 491902b0fbb9SMat Martineau /* Moving to BR/EDR */ 492002b0fbb9SMat Martineau if (test_bit(CONN_LOCAL_BUSY, &chan->conn_state)) { 492102b0fbb9SMat Martineau chan->move_state = L2CAP_MOVE_WAIT_LOCAL_BUSY; 492202b0fbb9SMat Martineau result = L2CAP_MR_PEND; 492302b0fbb9SMat Martineau } else { 492402b0fbb9SMat Martineau chan->move_state = L2CAP_MOVE_WAIT_CONFIRM; 492502b0fbb9SMat Martineau result = L2CAP_MR_SUCCESS; 492602b0fbb9SMat Martineau } 492702b0fbb9SMat Martineau } else { 492802b0fbb9SMat Martineau chan->move_state = L2CAP_MOVE_WAIT_PREPARE; 492902b0fbb9SMat Martineau /* Placeholder - uncomment when amp functions are available */ 493002b0fbb9SMat Martineau /*amp_accept_physical(chan, req->dest_amp_id);*/ 493102b0fbb9SMat Martineau result = L2CAP_MR_PEND; 493202b0fbb9SMat Martineau } 493302b0fbb9SMat Martineau 493402b0fbb9SMat Martineau send_move_response: 49351500109bSMat Martineau l2cap_send_move_chan_rsp(chan, result); 49368d5a04a1SMat Martineau 493702b0fbb9SMat Martineau l2cap_chan_unlock(chan); 493802b0fbb9SMat Martineau 49398d5a04a1SMat Martineau return 0; 49408d5a04a1SMat Martineau } 49418d5a04a1SMat Martineau 49425b155ef9SMat Martineau static void l2cap_move_continue(struct l2cap_conn *conn, u16 icid, u16 result) 49435b155ef9SMat Martineau { 49445b155ef9SMat Martineau struct l2cap_chan *chan; 49455b155ef9SMat Martineau struct hci_chan *hchan = NULL; 49465b155ef9SMat Martineau 49475b155ef9SMat Martineau chan = l2cap_get_chan_by_scid(conn, icid); 49485b155ef9SMat Martineau if (!chan) { 49495b155ef9SMat Martineau l2cap_send_move_chan_cfm_icid(conn, icid); 49505b155ef9SMat Martineau return; 49515b155ef9SMat Martineau } 49525b155ef9SMat Martineau 49535b155ef9SMat Martineau __clear_chan_timer(chan); 49545b155ef9SMat Martineau if (result == L2CAP_MR_PEND) 49555b155ef9SMat Martineau __set_chan_timer(chan, L2CAP_MOVE_ERTX_TIMEOUT); 49565b155ef9SMat Martineau 49575b155ef9SMat Martineau switch (chan->move_state) { 49585b155ef9SMat Martineau case L2CAP_MOVE_WAIT_LOGICAL_COMP: 49595b155ef9SMat Martineau /* Move confirm will be sent when logical link 49605b155ef9SMat Martineau * is complete. 49615b155ef9SMat Martineau */ 49625b155ef9SMat Martineau chan->move_state = L2CAP_MOVE_WAIT_LOGICAL_CFM; 49635b155ef9SMat Martineau break; 49645b155ef9SMat Martineau case L2CAP_MOVE_WAIT_RSP_SUCCESS: 49655b155ef9SMat Martineau if (result == L2CAP_MR_PEND) { 49665b155ef9SMat Martineau break; 49675b155ef9SMat Martineau } else if (test_bit(CONN_LOCAL_BUSY, 49685b155ef9SMat Martineau &chan->conn_state)) { 49695b155ef9SMat Martineau chan->move_state = L2CAP_MOVE_WAIT_LOCAL_BUSY; 49705b155ef9SMat Martineau } else { 49715b155ef9SMat Martineau /* Logical link is up or moving to BR/EDR, 49725b155ef9SMat Martineau * proceed with move 49735b155ef9SMat Martineau */ 49745b155ef9SMat Martineau chan->move_state = L2CAP_MOVE_WAIT_CONFIRM_RSP; 49755b155ef9SMat Martineau l2cap_send_move_chan_cfm(chan, L2CAP_MC_CONFIRMED); 49765b155ef9SMat Martineau } 49775b155ef9SMat Martineau break; 49785b155ef9SMat Martineau case L2CAP_MOVE_WAIT_RSP: 49795b155ef9SMat Martineau /* Moving to AMP */ 49805b155ef9SMat Martineau if (result == L2CAP_MR_SUCCESS) { 49815b155ef9SMat Martineau /* Remote is ready, send confirm immediately 49825b155ef9SMat Martineau * after logical link is ready 49835b155ef9SMat Martineau */ 49845b155ef9SMat Martineau chan->move_state = L2CAP_MOVE_WAIT_LOGICAL_CFM; 49855b155ef9SMat Martineau } else { 49865b155ef9SMat Martineau /* Both logical link and move success 49875b155ef9SMat Martineau * are required to confirm 49885b155ef9SMat Martineau */ 49895b155ef9SMat Martineau chan->move_state = L2CAP_MOVE_WAIT_LOGICAL_COMP; 49905b155ef9SMat Martineau } 49915b155ef9SMat Martineau 49925b155ef9SMat Martineau /* Placeholder - get hci_chan for logical link */ 49935b155ef9SMat Martineau if (!hchan) { 49945b155ef9SMat Martineau /* Logical link not available */ 49955b155ef9SMat Martineau l2cap_send_move_chan_cfm(chan, L2CAP_MC_UNCONFIRMED); 49965b155ef9SMat Martineau break; 49975b155ef9SMat Martineau } 49985b155ef9SMat Martineau 49995b155ef9SMat Martineau /* If the logical link is not yet connected, do not 50005b155ef9SMat Martineau * send confirmation. 50015b155ef9SMat Martineau */ 50025b155ef9SMat Martineau if (hchan->state != BT_CONNECTED) 50035b155ef9SMat Martineau break; 50045b155ef9SMat Martineau 50055b155ef9SMat Martineau /* Logical link is already ready to go */ 50065b155ef9SMat Martineau 50075b155ef9SMat Martineau chan->hs_hcon = hchan->conn; 50085b155ef9SMat Martineau chan->hs_hcon->l2cap_data = chan->conn; 50095b155ef9SMat Martineau 50105b155ef9SMat Martineau if (result == L2CAP_MR_SUCCESS) { 50115b155ef9SMat Martineau /* Can confirm now */ 50125b155ef9SMat Martineau l2cap_send_move_chan_cfm(chan, L2CAP_MC_CONFIRMED); 50135b155ef9SMat Martineau } else { 50145b155ef9SMat Martineau /* Now only need move success 50155b155ef9SMat Martineau * to confirm 50165b155ef9SMat Martineau */ 50175b155ef9SMat Martineau chan->move_state = L2CAP_MOVE_WAIT_RSP_SUCCESS; 50185b155ef9SMat Martineau } 50195b155ef9SMat Martineau 50205b155ef9SMat Martineau l2cap_logical_cfm(chan, hchan, L2CAP_MR_SUCCESS); 50215b155ef9SMat Martineau break; 50225b155ef9SMat Martineau default: 50235b155ef9SMat Martineau /* Any other amp move state means the move failed. */ 50245b155ef9SMat Martineau chan->move_id = chan->local_amp_id; 50255b155ef9SMat Martineau l2cap_move_done(chan); 50265b155ef9SMat Martineau l2cap_send_move_chan_cfm(chan, L2CAP_MC_UNCONFIRMED); 50275b155ef9SMat Martineau } 50285b155ef9SMat Martineau 50295b155ef9SMat Martineau l2cap_chan_unlock(chan); 50305b155ef9SMat Martineau } 50315b155ef9SMat Martineau 50325b155ef9SMat Martineau static void l2cap_move_fail(struct l2cap_conn *conn, u8 ident, u16 icid, 50335b155ef9SMat Martineau u16 result) 50345b155ef9SMat Martineau { 50355b155ef9SMat Martineau struct l2cap_chan *chan; 50365b155ef9SMat Martineau 50375b155ef9SMat Martineau chan = l2cap_get_chan_by_ident(conn, ident); 50385b155ef9SMat Martineau if (!chan) { 50395b155ef9SMat Martineau /* Could not locate channel, icid is best guess */ 50405b155ef9SMat Martineau l2cap_send_move_chan_cfm_icid(conn, icid); 50415b155ef9SMat Martineau return; 50425b155ef9SMat Martineau } 50435b155ef9SMat Martineau 50445b155ef9SMat Martineau __clear_chan_timer(chan); 50455b155ef9SMat Martineau 50465b155ef9SMat Martineau if (chan->move_role == L2CAP_MOVE_ROLE_INITIATOR) { 50475b155ef9SMat Martineau if (result == L2CAP_MR_COLLISION) { 50485b155ef9SMat Martineau chan->move_role = L2CAP_MOVE_ROLE_RESPONDER; 50495b155ef9SMat Martineau } else { 50505b155ef9SMat Martineau /* Cleanup - cancel move */ 50515b155ef9SMat Martineau chan->move_id = chan->local_amp_id; 50525b155ef9SMat Martineau l2cap_move_done(chan); 50535b155ef9SMat Martineau } 50545b155ef9SMat Martineau } 50555b155ef9SMat Martineau 50565b155ef9SMat Martineau l2cap_send_move_chan_cfm(chan, L2CAP_MC_UNCONFIRMED); 50575b155ef9SMat Martineau 50585b155ef9SMat Martineau l2cap_chan_unlock(chan); 50595b155ef9SMat Martineau } 50605b155ef9SMat Martineau 50615b155ef9SMat Martineau static int l2cap_move_channel_rsp(struct l2cap_conn *conn, 5062ad0ac6caSAndrei Emeltchenko struct l2cap_cmd_hdr *cmd, 5063ad0ac6caSAndrei Emeltchenko u16 cmd_len, void *data) 50648d5a04a1SMat Martineau { 50658d5a04a1SMat Martineau struct l2cap_move_chan_rsp *rsp = data; 50668d5a04a1SMat Martineau u16 icid, result; 50678d5a04a1SMat Martineau 50688d5a04a1SMat Martineau if (cmd_len != sizeof(*rsp)) 50698d5a04a1SMat Martineau return -EPROTO; 50708d5a04a1SMat Martineau 50718d5a04a1SMat Martineau icid = le16_to_cpu(rsp->icid); 50728d5a04a1SMat Martineau result = le16_to_cpu(rsp->result); 50738d5a04a1SMat Martineau 5074ad0ac6caSAndrei Emeltchenko BT_DBG("icid 0x%4.4x, result 0x%4.4x", icid, result); 50758d5a04a1SMat Martineau 50765b155ef9SMat Martineau if (result == L2CAP_MR_SUCCESS || result == L2CAP_MR_PEND) 50775b155ef9SMat Martineau l2cap_move_continue(conn, icid, result); 50785b155ef9SMat Martineau else 50795b155ef9SMat Martineau l2cap_move_fail(conn, cmd->ident, icid, result); 50808d5a04a1SMat Martineau 50818d5a04a1SMat Martineau return 0; 50828d5a04a1SMat Martineau } 50838d5a04a1SMat Martineau 50845f3847a4SMat Martineau static int l2cap_move_channel_confirm(struct l2cap_conn *conn, 5085ad0ac6caSAndrei Emeltchenko struct l2cap_cmd_hdr *cmd, 5086ad0ac6caSAndrei Emeltchenko u16 cmd_len, void *data) 50878d5a04a1SMat Martineau { 50888d5a04a1SMat Martineau struct l2cap_move_chan_cfm *cfm = data; 50895f3847a4SMat Martineau struct l2cap_chan *chan; 50908d5a04a1SMat Martineau u16 icid, result; 50918d5a04a1SMat Martineau 50928d5a04a1SMat Martineau if (cmd_len != sizeof(*cfm)) 50938d5a04a1SMat Martineau return -EPROTO; 50948d5a04a1SMat Martineau 50958d5a04a1SMat Martineau icid = le16_to_cpu(cfm->icid); 50968d5a04a1SMat Martineau result = le16_to_cpu(cfm->result); 50978d5a04a1SMat Martineau 5098ad0ac6caSAndrei Emeltchenko BT_DBG("icid 0x%4.4x, result 0x%4.4x", icid, result); 50998d5a04a1SMat Martineau 51005f3847a4SMat Martineau chan = l2cap_get_chan_by_dcid(conn, icid); 51015f3847a4SMat Martineau if (!chan) { 51025f3847a4SMat Martineau /* Spec requires a response even if the icid was not found */ 51038d5a04a1SMat Martineau l2cap_send_move_chan_cfm_rsp(conn, cmd->ident, icid); 51045f3847a4SMat Martineau return 0; 51055f3847a4SMat Martineau } 51065f3847a4SMat Martineau 51075f3847a4SMat Martineau if (chan->move_state == L2CAP_MOVE_WAIT_CONFIRM) { 51085f3847a4SMat Martineau if (result == L2CAP_MC_CONFIRMED) { 51095f3847a4SMat Martineau chan->local_amp_id = chan->move_id; 51106ed971caSMarcel Holtmann if (chan->local_amp_id == AMP_ID_BREDR) 51115f3847a4SMat Martineau __release_logical_link(chan); 51125f3847a4SMat Martineau } else { 51135f3847a4SMat Martineau chan->move_id = chan->local_amp_id; 51145f3847a4SMat Martineau } 51155f3847a4SMat Martineau 51165f3847a4SMat Martineau l2cap_move_done(chan); 51175f3847a4SMat Martineau } 51185f3847a4SMat Martineau 51195f3847a4SMat Martineau l2cap_send_move_chan_cfm_rsp(conn, cmd->ident, icid); 51205f3847a4SMat Martineau 51215f3847a4SMat Martineau l2cap_chan_unlock(chan); 51228d5a04a1SMat Martineau 51238d5a04a1SMat Martineau return 0; 51248d5a04a1SMat Martineau } 51258d5a04a1SMat Martineau 51268d5a04a1SMat Martineau static inline int l2cap_move_channel_confirm_rsp(struct l2cap_conn *conn, 5127ad0ac6caSAndrei Emeltchenko struct l2cap_cmd_hdr *cmd, 5128ad0ac6caSAndrei Emeltchenko u16 cmd_len, void *data) 51298d5a04a1SMat Martineau { 51308d5a04a1SMat Martineau struct l2cap_move_chan_cfm_rsp *rsp = data; 51313fd71a0aSMat Martineau struct l2cap_chan *chan; 51328d5a04a1SMat Martineau u16 icid; 51338d5a04a1SMat Martineau 51348d5a04a1SMat Martineau if (cmd_len != sizeof(*rsp)) 51358d5a04a1SMat Martineau return -EPROTO; 51368d5a04a1SMat Martineau 51378d5a04a1SMat Martineau icid = le16_to_cpu(rsp->icid); 51388d5a04a1SMat Martineau 5139ad0ac6caSAndrei Emeltchenko BT_DBG("icid 0x%4.4x", icid); 51408d5a04a1SMat Martineau 51413fd71a0aSMat Martineau chan = l2cap_get_chan_by_scid(conn, icid); 51423fd71a0aSMat Martineau if (!chan) 51433fd71a0aSMat Martineau return 0; 51443fd71a0aSMat Martineau 51453fd71a0aSMat Martineau __clear_chan_timer(chan); 51463fd71a0aSMat Martineau 51473fd71a0aSMat Martineau if (chan->move_state == L2CAP_MOVE_WAIT_CONFIRM_RSP) { 51483fd71a0aSMat Martineau chan->local_amp_id = chan->move_id; 51493fd71a0aSMat Martineau 51506ed971caSMarcel Holtmann if (chan->local_amp_id == AMP_ID_BREDR && chan->hs_hchan) 51513fd71a0aSMat Martineau __release_logical_link(chan); 51523fd71a0aSMat Martineau 51533fd71a0aSMat Martineau l2cap_move_done(chan); 51543fd71a0aSMat Martineau } 51553fd71a0aSMat Martineau 51563fd71a0aSMat Martineau l2cap_chan_unlock(chan); 51573fd71a0aSMat Martineau 51588d5a04a1SMat Martineau return 0; 51598d5a04a1SMat Martineau } 51608d5a04a1SMat Martineau 5161e2174ca4SGustavo F. Padovan static inline int l2cap_check_conn_param(u16 min, u16 max, u16 latency, 5162de73115aSClaudio Takahasi u16 to_multiplier) 5163de73115aSClaudio Takahasi { 5164de73115aSClaudio Takahasi u16 max_latency; 5165de73115aSClaudio Takahasi 5166de73115aSClaudio Takahasi if (min > max || min < 6 || max > 3200) 5167de73115aSClaudio Takahasi return -EINVAL; 5168de73115aSClaudio Takahasi 5169de73115aSClaudio Takahasi if (to_multiplier < 10 || to_multiplier > 3200) 5170de73115aSClaudio Takahasi return -EINVAL; 5171de73115aSClaudio Takahasi 5172de73115aSClaudio Takahasi if (max >= to_multiplier * 8) 5173de73115aSClaudio Takahasi return -EINVAL; 5174de73115aSClaudio Takahasi 5175de73115aSClaudio Takahasi max_latency = (to_multiplier * 8 / max) - 1; 5176de73115aSClaudio Takahasi if (latency > 499 || latency > max_latency) 5177de73115aSClaudio Takahasi return -EINVAL; 5178de73115aSClaudio Takahasi 5179de73115aSClaudio Takahasi return 0; 5180de73115aSClaudio Takahasi } 5181de73115aSClaudio Takahasi 5182de73115aSClaudio Takahasi static inline int l2cap_conn_param_update_req(struct l2cap_conn *conn, 51832d792818SGustavo Padovan struct l2cap_cmd_hdr *cmd, 51842d792818SGustavo Padovan u8 *data) 5185de73115aSClaudio Takahasi { 5186de73115aSClaudio Takahasi struct hci_conn *hcon = conn->hcon; 5187de73115aSClaudio Takahasi struct l2cap_conn_param_update_req *req; 5188de73115aSClaudio Takahasi struct l2cap_conn_param_update_rsp rsp; 5189de73115aSClaudio Takahasi u16 min, max, latency, to_multiplier, cmd_len; 51902ce603ebSClaudio Takahasi int err; 5191de73115aSClaudio Takahasi 5192de73115aSClaudio Takahasi if (!(hcon->link_mode & HCI_LM_MASTER)) 5193de73115aSClaudio Takahasi return -EINVAL; 5194de73115aSClaudio Takahasi 5195de73115aSClaudio Takahasi cmd_len = __le16_to_cpu(cmd->len); 5196de73115aSClaudio Takahasi if (cmd_len != sizeof(struct l2cap_conn_param_update_req)) 5197de73115aSClaudio Takahasi return -EPROTO; 5198de73115aSClaudio Takahasi 5199de73115aSClaudio Takahasi req = (struct l2cap_conn_param_update_req *) data; 5200de73115aSClaudio Takahasi min = __le16_to_cpu(req->min); 5201de73115aSClaudio Takahasi max = __le16_to_cpu(req->max); 5202de73115aSClaudio Takahasi latency = __le16_to_cpu(req->latency); 5203de73115aSClaudio Takahasi to_multiplier = __le16_to_cpu(req->to_multiplier); 5204de73115aSClaudio Takahasi 5205de73115aSClaudio Takahasi BT_DBG("min 0x%4.4x max 0x%4.4x latency: 0x%4.4x Timeout: 0x%4.4x", 5206de73115aSClaudio Takahasi min, max, latency, to_multiplier); 5207de73115aSClaudio Takahasi 5208de73115aSClaudio Takahasi memset(&rsp, 0, sizeof(rsp)); 52092ce603ebSClaudio Takahasi 52102ce603ebSClaudio Takahasi err = l2cap_check_conn_param(min, max, latency, to_multiplier); 52112ce603ebSClaudio Takahasi if (err) 5212ac73498cSAndrei Emeltchenko rsp.result = __constant_cpu_to_le16(L2CAP_CONN_PARAM_REJECTED); 5213de73115aSClaudio Takahasi else 5214ac73498cSAndrei Emeltchenko rsp.result = __constant_cpu_to_le16(L2CAP_CONN_PARAM_ACCEPTED); 5215de73115aSClaudio Takahasi 5216de73115aSClaudio Takahasi l2cap_send_cmd(conn, cmd->ident, L2CAP_CONN_PARAM_UPDATE_RSP, 5217de73115aSClaudio Takahasi sizeof(rsp), &rsp); 5218de73115aSClaudio Takahasi 52192ce603ebSClaudio Takahasi if (!err) 52202ce603ebSClaudio Takahasi hci_le_conn_update(hcon, min, max, latency, to_multiplier); 52212ce603ebSClaudio Takahasi 5222de73115aSClaudio Takahasi return 0; 5223de73115aSClaudio Takahasi } 5224de73115aSClaudio Takahasi 52253300d9a9SClaudio Takahasi static inline int l2cap_bredr_sig_cmd(struct l2cap_conn *conn, 52262d792818SGustavo Padovan struct l2cap_cmd_hdr *cmd, u16 cmd_len, 52272d792818SGustavo Padovan u8 *data) 52283300d9a9SClaudio Takahasi { 52293300d9a9SClaudio Takahasi int err = 0; 52303300d9a9SClaudio Takahasi 52313300d9a9SClaudio Takahasi switch (cmd->code) { 52323300d9a9SClaudio Takahasi case L2CAP_COMMAND_REJ: 5233cb3b3152SJohan Hedberg l2cap_command_rej(conn, cmd, cmd_len, data); 52343300d9a9SClaudio Takahasi break; 52353300d9a9SClaudio Takahasi 52363300d9a9SClaudio Takahasi case L2CAP_CONN_REQ: 5237cb3b3152SJohan Hedberg err = l2cap_connect_req(conn, cmd, cmd_len, data); 52383300d9a9SClaudio Takahasi break; 52393300d9a9SClaudio Takahasi 52403300d9a9SClaudio Takahasi case L2CAP_CONN_RSP: 5241f5a2598dSMat Martineau case L2CAP_CREATE_CHAN_RSP: 52429245e737SJohan Hedberg l2cap_connect_create_rsp(conn, cmd, cmd_len, data); 52433300d9a9SClaudio Takahasi break; 52443300d9a9SClaudio Takahasi 52453300d9a9SClaudio Takahasi case L2CAP_CONF_REQ: 52463300d9a9SClaudio Takahasi err = l2cap_config_req(conn, cmd, cmd_len, data); 52473300d9a9SClaudio Takahasi break; 52483300d9a9SClaudio Takahasi 52493300d9a9SClaudio Takahasi case L2CAP_CONF_RSP: 52509245e737SJohan Hedberg l2cap_config_rsp(conn, cmd, cmd_len, data); 52513300d9a9SClaudio Takahasi break; 52523300d9a9SClaudio Takahasi 52533300d9a9SClaudio Takahasi case L2CAP_DISCONN_REQ: 5254cb3b3152SJohan Hedberg err = l2cap_disconnect_req(conn, cmd, cmd_len, data); 52553300d9a9SClaudio Takahasi break; 52563300d9a9SClaudio Takahasi 52573300d9a9SClaudio Takahasi case L2CAP_DISCONN_RSP: 52589245e737SJohan Hedberg l2cap_disconnect_rsp(conn, cmd, cmd_len, data); 52593300d9a9SClaudio Takahasi break; 52603300d9a9SClaudio Takahasi 52613300d9a9SClaudio Takahasi case L2CAP_ECHO_REQ: 52623300d9a9SClaudio Takahasi l2cap_send_cmd(conn, cmd->ident, L2CAP_ECHO_RSP, cmd_len, data); 52633300d9a9SClaudio Takahasi break; 52643300d9a9SClaudio Takahasi 52653300d9a9SClaudio Takahasi case L2CAP_ECHO_RSP: 52663300d9a9SClaudio Takahasi break; 52673300d9a9SClaudio Takahasi 52683300d9a9SClaudio Takahasi case L2CAP_INFO_REQ: 5269cb3b3152SJohan Hedberg err = l2cap_information_req(conn, cmd, cmd_len, data); 52703300d9a9SClaudio Takahasi break; 52713300d9a9SClaudio Takahasi 52723300d9a9SClaudio Takahasi case L2CAP_INFO_RSP: 52739245e737SJohan Hedberg l2cap_information_rsp(conn, cmd, cmd_len, data); 52743300d9a9SClaudio Takahasi break; 52753300d9a9SClaudio Takahasi 5276f94ff6ffSMat Martineau case L2CAP_CREATE_CHAN_REQ: 5277f94ff6ffSMat Martineau err = l2cap_create_channel_req(conn, cmd, cmd_len, data); 5278f94ff6ffSMat Martineau break; 5279f94ff6ffSMat Martineau 52808d5a04a1SMat Martineau case L2CAP_MOVE_CHAN_REQ: 52818d5a04a1SMat Martineau err = l2cap_move_channel_req(conn, cmd, cmd_len, data); 52828d5a04a1SMat Martineau break; 52838d5a04a1SMat Martineau 52848d5a04a1SMat Martineau case L2CAP_MOVE_CHAN_RSP: 52859245e737SJohan Hedberg l2cap_move_channel_rsp(conn, cmd, cmd_len, data); 52868d5a04a1SMat Martineau break; 52878d5a04a1SMat Martineau 52888d5a04a1SMat Martineau case L2CAP_MOVE_CHAN_CFM: 52898d5a04a1SMat Martineau err = l2cap_move_channel_confirm(conn, cmd, cmd_len, data); 52908d5a04a1SMat Martineau break; 52918d5a04a1SMat Martineau 52928d5a04a1SMat Martineau case L2CAP_MOVE_CHAN_CFM_RSP: 52939245e737SJohan Hedberg l2cap_move_channel_confirm_rsp(conn, cmd, cmd_len, data); 52948d5a04a1SMat Martineau break; 52958d5a04a1SMat Martineau 52963300d9a9SClaudio Takahasi default: 52973300d9a9SClaudio Takahasi BT_ERR("Unknown BR/EDR signaling command 0x%2.2x", cmd->code); 52983300d9a9SClaudio Takahasi err = -EINVAL; 52993300d9a9SClaudio Takahasi break; 53003300d9a9SClaudio Takahasi } 53013300d9a9SClaudio Takahasi 53023300d9a9SClaudio Takahasi return err; 53033300d9a9SClaudio Takahasi } 53043300d9a9SClaudio Takahasi 53053300d9a9SClaudio Takahasi static inline int l2cap_le_sig_cmd(struct l2cap_conn *conn, 53063300d9a9SClaudio Takahasi struct l2cap_cmd_hdr *cmd, u8 *data) 53073300d9a9SClaudio Takahasi { 53083300d9a9SClaudio Takahasi switch (cmd->code) { 53093300d9a9SClaudio Takahasi case L2CAP_COMMAND_REJ: 53103300d9a9SClaudio Takahasi return 0; 53113300d9a9SClaudio Takahasi 53123300d9a9SClaudio Takahasi case L2CAP_CONN_PARAM_UPDATE_REQ: 5313de73115aSClaudio Takahasi return l2cap_conn_param_update_req(conn, cmd, data); 53143300d9a9SClaudio Takahasi 53153300d9a9SClaudio Takahasi case L2CAP_CONN_PARAM_UPDATE_RSP: 53163300d9a9SClaudio Takahasi return 0; 53173300d9a9SClaudio Takahasi 53183300d9a9SClaudio Takahasi default: 53193300d9a9SClaudio Takahasi BT_ERR("Unknown LE signaling command 0x%2.2x", cmd->code); 53203300d9a9SClaudio Takahasi return -EINVAL; 53213300d9a9SClaudio Takahasi } 53223300d9a9SClaudio Takahasi } 53233300d9a9SClaudio Takahasi 53247c2005d6SJohan Hedberg static __le16 l2cap_err_to_reason(int err) 53257c2005d6SJohan Hedberg { 53267c2005d6SJohan Hedberg switch (err) { 53277c2005d6SJohan Hedberg case -EBADSLT: 53287c2005d6SJohan Hedberg return __constant_cpu_to_le16(L2CAP_REJ_INVALID_CID); 53297c2005d6SJohan Hedberg case -EMSGSIZE: 53307c2005d6SJohan Hedberg return __constant_cpu_to_le16(L2CAP_REJ_MTU_EXCEEDED); 53317c2005d6SJohan Hedberg case -EINVAL: 53327c2005d6SJohan Hedberg case -EPROTO: 53337c2005d6SJohan Hedberg default: 53347c2005d6SJohan Hedberg return __constant_cpu_to_le16(L2CAP_REJ_NOT_UNDERSTOOD); 53357c2005d6SJohan Hedberg } 53367c2005d6SJohan Hedberg } 53377c2005d6SJohan Hedberg 5338c5623556SJohan Hedberg static inline void l2cap_le_sig_channel(struct l2cap_conn *conn, 5339c5623556SJohan Hedberg struct sk_buff *skb) 5340c5623556SJohan Hedberg { 534169c4e4e8SJohan Hedberg struct hci_conn *hcon = conn->hcon; 53424f3e219dSMarcel Holtmann struct l2cap_cmd_hdr *cmd; 53434f3e219dSMarcel Holtmann u16 len; 5344c5623556SJohan Hedberg int err; 5345c5623556SJohan Hedberg 534669c4e4e8SJohan Hedberg if (hcon->type != LE_LINK) 53473b166295SMarcel Holtmann goto drop; 534869c4e4e8SJohan Hedberg 53494f3e219dSMarcel Holtmann if (skb->len < L2CAP_CMD_HDR_SIZE) 53504f3e219dSMarcel Holtmann goto drop; 5351c5623556SJohan Hedberg 53524f3e219dSMarcel Holtmann cmd = (void *) skb->data; 53534f3e219dSMarcel Holtmann skb_pull(skb, L2CAP_CMD_HDR_SIZE); 5354c5623556SJohan Hedberg 53554f3e219dSMarcel Holtmann len = le16_to_cpu(cmd->len); 5356c5623556SJohan Hedberg 53574f3e219dSMarcel Holtmann BT_DBG("code 0x%2.2x len %d id 0x%2.2x", cmd->code, len, cmd->ident); 53584f3e219dSMarcel Holtmann 53594f3e219dSMarcel Holtmann if (len != skb->len || !cmd->ident) { 5360c5623556SJohan Hedberg BT_DBG("corrupted command"); 53614f3e219dSMarcel Holtmann goto drop; 5362c5623556SJohan Hedberg } 5363c5623556SJohan Hedberg 53644f3e219dSMarcel Holtmann err = l2cap_le_sig_cmd(conn, cmd, skb->data); 5365c5623556SJohan Hedberg if (err) { 5366c5623556SJohan Hedberg struct l2cap_cmd_rej_unk rej; 5367c5623556SJohan Hedberg 5368c5623556SJohan Hedberg BT_ERR("Wrong link type (%d)", err); 5369c5623556SJohan Hedberg 53707c2005d6SJohan Hedberg rej.reason = l2cap_err_to_reason(err); 53714f3e219dSMarcel Holtmann l2cap_send_cmd(conn, cmd->ident, L2CAP_COMMAND_REJ, 5372c5623556SJohan Hedberg sizeof(rej), &rej); 5373c5623556SJohan Hedberg } 5374c5623556SJohan Hedberg 53753b166295SMarcel Holtmann drop: 5376c5623556SJohan Hedberg kfree_skb(skb); 5377c5623556SJohan Hedberg } 5378c5623556SJohan Hedberg 53793300d9a9SClaudio Takahasi static inline void l2cap_sig_channel(struct l2cap_conn *conn, 53803300d9a9SClaudio Takahasi struct sk_buff *skb) 53810a708f8fSGustavo F. Padovan { 538269c4e4e8SJohan Hedberg struct hci_conn *hcon = conn->hcon; 53830a708f8fSGustavo F. Padovan u8 *data = skb->data; 53840a708f8fSGustavo F. Padovan int len = skb->len; 53850a708f8fSGustavo F. Padovan struct l2cap_cmd_hdr cmd; 53863300d9a9SClaudio Takahasi int err; 53870a708f8fSGustavo F. Padovan 53880a708f8fSGustavo F. Padovan l2cap_raw_recv(conn, skb); 53890a708f8fSGustavo F. Padovan 539069c4e4e8SJohan Hedberg if (hcon->type != ACL_LINK) 53913b166295SMarcel Holtmann goto drop; 539269c4e4e8SJohan Hedberg 53930a708f8fSGustavo F. Padovan while (len >= L2CAP_CMD_HDR_SIZE) { 53940a708f8fSGustavo F. Padovan u16 cmd_len; 53950a708f8fSGustavo F. Padovan memcpy(&cmd, data, L2CAP_CMD_HDR_SIZE); 53960a708f8fSGustavo F. Padovan data += L2CAP_CMD_HDR_SIZE; 53970a708f8fSGustavo F. Padovan len -= L2CAP_CMD_HDR_SIZE; 53980a708f8fSGustavo F. Padovan 53990a708f8fSGustavo F. Padovan cmd_len = le16_to_cpu(cmd.len); 54000a708f8fSGustavo F. Padovan 54012d792818SGustavo Padovan BT_DBG("code 0x%2.2x len %d id 0x%2.2x", cmd.code, cmd_len, 54022d792818SGustavo Padovan cmd.ident); 54030a708f8fSGustavo F. Padovan 54040a708f8fSGustavo F. Padovan if (cmd_len > len || !cmd.ident) { 54050a708f8fSGustavo F. Padovan BT_DBG("corrupted command"); 54060a708f8fSGustavo F. Padovan break; 54070a708f8fSGustavo F. Padovan } 54080a708f8fSGustavo F. Padovan 54093300d9a9SClaudio Takahasi err = l2cap_bredr_sig_cmd(conn, &cmd, cmd_len, data); 54100a708f8fSGustavo F. Padovan if (err) { 5411e2fd318eSIlia Kolomisnky struct l2cap_cmd_rej_unk rej; 54122c6d1a2eSGustavo F. Padovan 54132c6d1a2eSGustavo F. Padovan BT_ERR("Wrong link type (%d)", err); 54140a708f8fSGustavo F. Padovan 54157c2005d6SJohan Hedberg rej.reason = l2cap_err_to_reason(err); 54162d792818SGustavo Padovan l2cap_send_cmd(conn, cmd.ident, L2CAP_COMMAND_REJ, 54172d792818SGustavo Padovan sizeof(rej), &rej); 54180a708f8fSGustavo F. Padovan } 54190a708f8fSGustavo F. Padovan 54200a708f8fSGustavo F. Padovan data += cmd_len; 54210a708f8fSGustavo F. Padovan len -= cmd_len; 54220a708f8fSGustavo F. Padovan } 54230a708f8fSGustavo F. Padovan 54243b166295SMarcel Holtmann drop: 54250a708f8fSGustavo F. Padovan kfree_skb(skb); 54260a708f8fSGustavo F. Padovan } 54270a708f8fSGustavo F. Padovan 542847d1ec61SGustavo F. Padovan static int l2cap_check_fcs(struct l2cap_chan *chan, struct sk_buff *skb) 54290a708f8fSGustavo F. Padovan { 54300a708f8fSGustavo F. Padovan u16 our_fcs, rcv_fcs; 5431e4ca6d98SAndrei Emeltchenko int hdr_size; 5432e4ca6d98SAndrei Emeltchenko 5433e4ca6d98SAndrei Emeltchenko if (test_bit(FLAG_EXT_CTRL, &chan->flags)) 5434e4ca6d98SAndrei Emeltchenko hdr_size = L2CAP_EXT_HDR_SIZE; 5435e4ca6d98SAndrei Emeltchenko else 5436e4ca6d98SAndrei Emeltchenko hdr_size = L2CAP_ENH_HDR_SIZE; 54370a708f8fSGustavo F. Padovan 543847d1ec61SGustavo F. Padovan if (chan->fcs == L2CAP_FCS_CRC16) { 543903a51213SAndrei Emeltchenko skb_trim(skb, skb->len - L2CAP_FCS_SIZE); 54400a708f8fSGustavo F. Padovan rcv_fcs = get_unaligned_le16(skb->data + skb->len); 54410a708f8fSGustavo F. Padovan our_fcs = crc16(0, skb->data - hdr_size, skb->len + hdr_size); 54420a708f8fSGustavo F. Padovan 54430a708f8fSGustavo F. Padovan if (our_fcs != rcv_fcs) 54440a708f8fSGustavo F. Padovan return -EBADMSG; 54450a708f8fSGustavo F. Padovan } 54460a708f8fSGustavo F. Padovan return 0; 54470a708f8fSGustavo F. Padovan } 54480a708f8fSGustavo F. Padovan 54496ea00485SMat Martineau static void l2cap_send_i_or_rr_or_rnr(struct l2cap_chan *chan) 54500a708f8fSGustavo F. Padovan { 5451e31f7633SMat Martineau struct l2cap_ctrl control; 54520a708f8fSGustavo F. Padovan 5453e31f7633SMat Martineau BT_DBG("chan %p", chan); 54540a708f8fSGustavo F. Padovan 5455e31f7633SMat Martineau memset(&control, 0, sizeof(control)); 5456e31f7633SMat Martineau control.sframe = 1; 5457e31f7633SMat Martineau control.final = 1; 5458e31f7633SMat Martineau control.reqseq = chan->buffer_seq; 5459e31f7633SMat Martineau set_bit(CONN_SEND_FBIT, &chan->conn_state); 54600a708f8fSGustavo F. Padovan 5461e2ab4353SGustavo F. Padovan if (test_bit(CONN_LOCAL_BUSY, &chan->conn_state)) { 5462e31f7633SMat Martineau control.super = L2CAP_SUPER_RNR; 5463e31f7633SMat Martineau l2cap_send_sframe(chan, &control); 54640a708f8fSGustavo F. Padovan } 54650a708f8fSGustavo F. Padovan 5466e31f7633SMat Martineau if (test_and_clear_bit(CONN_REMOTE_BUSY, &chan->conn_state) && 5467e31f7633SMat Martineau chan->unacked_frames > 0) 5468e31f7633SMat Martineau __set_retrans_timer(chan); 54690a708f8fSGustavo F. Padovan 5470e31f7633SMat Martineau /* Send pending iframes */ 5471525cd185SGustavo F. Padovan l2cap_ertm_send(chan); 54720a708f8fSGustavo F. Padovan 5473e2ab4353SGustavo F. Padovan if (!test_bit(CONN_LOCAL_BUSY, &chan->conn_state) && 5474e31f7633SMat Martineau test_bit(CONN_SEND_FBIT, &chan->conn_state)) { 5475e31f7633SMat Martineau /* F-bit wasn't sent in an s-frame or i-frame yet, so 5476e31f7633SMat Martineau * send it now. 5477e31f7633SMat Martineau */ 5478e31f7633SMat Martineau control.super = L2CAP_SUPER_RR; 5479e31f7633SMat Martineau l2cap_send_sframe(chan, &control); 54800a708f8fSGustavo F. Padovan } 54810a708f8fSGustavo F. Padovan } 54820a708f8fSGustavo F. Padovan 54832d792818SGustavo Padovan static void append_skb_frag(struct sk_buff *skb, struct sk_buff *new_frag, 54842d792818SGustavo Padovan struct sk_buff **last_frag) 54850a708f8fSGustavo F. Padovan { 548684084a31SMat Martineau /* skb->len reflects data in skb as well as all fragments 548784084a31SMat Martineau * skb->data_len reflects only data in fragments 548884084a31SMat Martineau */ 548984084a31SMat Martineau if (!skb_has_frag_list(skb)) 549084084a31SMat Martineau skb_shinfo(skb)->frag_list = new_frag; 549184084a31SMat Martineau 549284084a31SMat Martineau new_frag->next = NULL; 549384084a31SMat Martineau 549484084a31SMat Martineau (*last_frag)->next = new_frag; 549584084a31SMat Martineau *last_frag = new_frag; 549684084a31SMat Martineau 549784084a31SMat Martineau skb->len += new_frag->len; 549884084a31SMat Martineau skb->data_len += new_frag->len; 549984084a31SMat Martineau skb->truesize += new_frag->truesize; 550084084a31SMat Martineau } 550184084a31SMat Martineau 55024b51dae9SMat Martineau static int l2cap_reassemble_sdu(struct l2cap_chan *chan, struct sk_buff *skb, 55034b51dae9SMat Martineau struct l2cap_ctrl *control) 550484084a31SMat Martineau { 550584084a31SMat Martineau int err = -EINVAL; 55060a708f8fSGustavo F. Padovan 55074b51dae9SMat Martineau switch (control->sar) { 55087e0ef6eeSAndrei Emeltchenko case L2CAP_SAR_UNSEGMENTED: 550984084a31SMat Martineau if (chan->sdu) 551084084a31SMat Martineau break; 55110a708f8fSGustavo F. Padovan 551280b98027SGustavo Padovan err = chan->ops->recv(chan, skb); 551384084a31SMat Martineau break; 55140a708f8fSGustavo F. Padovan 55157e0ef6eeSAndrei Emeltchenko case L2CAP_SAR_START: 551684084a31SMat Martineau if (chan->sdu) 551784084a31SMat Martineau break; 55180a708f8fSGustavo F. Padovan 55196f61fd47SGustavo F. Padovan chan->sdu_len = get_unaligned_le16(skb->data); 552003a51213SAndrei Emeltchenko skb_pull(skb, L2CAP_SDULEN_SIZE); 55210a708f8fSGustavo F. Padovan 552284084a31SMat Martineau if (chan->sdu_len > chan->imtu) { 552384084a31SMat Martineau err = -EMSGSIZE; 552484084a31SMat Martineau break; 552584084a31SMat Martineau } 55260a708f8fSGustavo F. Padovan 552784084a31SMat Martineau if (skb->len >= chan->sdu_len) 552884084a31SMat Martineau break; 552984084a31SMat Martineau 553084084a31SMat Martineau chan->sdu = skb; 553184084a31SMat Martineau chan->sdu_last_frag = skb; 553284084a31SMat Martineau 553384084a31SMat Martineau skb = NULL; 553484084a31SMat Martineau err = 0; 55350a708f8fSGustavo F. Padovan break; 55360a708f8fSGustavo F. Padovan 55377e0ef6eeSAndrei Emeltchenko case L2CAP_SAR_CONTINUE: 55386f61fd47SGustavo F. Padovan if (!chan->sdu) 553984084a31SMat Martineau break; 55400a708f8fSGustavo F. Padovan 554184084a31SMat Martineau append_skb_frag(chan->sdu, skb, 554284084a31SMat Martineau &chan->sdu_last_frag); 554384084a31SMat Martineau skb = NULL; 55440a708f8fSGustavo F. Padovan 554584084a31SMat Martineau if (chan->sdu->len >= chan->sdu_len) 554684084a31SMat Martineau break; 55470a708f8fSGustavo F. Padovan 554884084a31SMat Martineau err = 0; 55490a708f8fSGustavo F. Padovan break; 55500a708f8fSGustavo F. Padovan 55517e0ef6eeSAndrei Emeltchenko case L2CAP_SAR_END: 55526f61fd47SGustavo F. Padovan if (!chan->sdu) 555384084a31SMat Martineau break; 55540a708f8fSGustavo F. Padovan 555584084a31SMat Martineau append_skb_frag(chan->sdu, skb, 555684084a31SMat Martineau &chan->sdu_last_frag); 555784084a31SMat Martineau skb = NULL; 55580a708f8fSGustavo F. Padovan 555984084a31SMat Martineau if (chan->sdu->len != chan->sdu_len) 556084084a31SMat Martineau break; 55610a708f8fSGustavo F. Padovan 556280b98027SGustavo Padovan err = chan->ops->recv(chan, chan->sdu); 55630a708f8fSGustavo F. Padovan 556484084a31SMat Martineau if (!err) { 556584084a31SMat Martineau /* Reassembly complete */ 556684084a31SMat Martineau chan->sdu = NULL; 556784084a31SMat Martineau chan->sdu_last_frag = NULL; 556884084a31SMat Martineau chan->sdu_len = 0; 55690a708f8fSGustavo F. Padovan } 55700a708f8fSGustavo F. Padovan break; 55710a708f8fSGustavo F. Padovan } 55720a708f8fSGustavo F. Padovan 557384084a31SMat Martineau if (err) { 55740a708f8fSGustavo F. Padovan kfree_skb(skb); 55756f61fd47SGustavo F. Padovan kfree_skb(chan->sdu); 55766f61fd47SGustavo F. Padovan chan->sdu = NULL; 557784084a31SMat Martineau chan->sdu_last_frag = NULL; 557884084a31SMat Martineau chan->sdu_len = 0; 557984084a31SMat Martineau } 55800a708f8fSGustavo F. Padovan 558184084a31SMat Martineau return err; 55820a708f8fSGustavo F. Padovan } 55830a708f8fSGustavo F. Padovan 558432b32735SMat Martineau static int l2cap_resegment(struct l2cap_chan *chan) 558532b32735SMat Martineau { 558632b32735SMat Martineau /* Placeholder */ 558732b32735SMat Martineau return 0; 558832b32735SMat Martineau } 558932b32735SMat Martineau 5590e328140fSMat Martineau void l2cap_chan_busy(struct l2cap_chan *chan, int busy) 55910a708f8fSGustavo F. Padovan { 559261aa4f5bSMat Martineau u8 event; 559361aa4f5bSMat Martineau 559461aa4f5bSMat Martineau if (chan->mode != L2CAP_MODE_ERTM) 559561aa4f5bSMat Martineau return; 559661aa4f5bSMat Martineau 559761aa4f5bSMat Martineau event = busy ? L2CAP_EV_LOCAL_BUSY_DETECTED : L2CAP_EV_LOCAL_BUSY_CLEAR; 5598401bb1f7SAndrei Emeltchenko l2cap_tx(chan, NULL, NULL, event); 55990a708f8fSGustavo F. Padovan } 56000a708f8fSGustavo F. Padovan 5601d2a7ac5dSMat Martineau static int l2cap_rx_queued_iframes(struct l2cap_chan *chan) 5602d2a7ac5dSMat Martineau { 560363838725SMat Martineau int err = 0; 560463838725SMat Martineau /* Pass sequential frames to l2cap_reassemble_sdu() 560563838725SMat Martineau * until a gap is encountered. 560663838725SMat Martineau */ 560763838725SMat Martineau 560863838725SMat Martineau BT_DBG("chan %p", chan); 560963838725SMat Martineau 561063838725SMat Martineau while (!test_bit(CONN_LOCAL_BUSY, &chan->conn_state)) { 561163838725SMat Martineau struct sk_buff *skb; 561263838725SMat Martineau BT_DBG("Searching for skb with txseq %d (queue len %d)", 561363838725SMat Martineau chan->buffer_seq, skb_queue_len(&chan->srej_q)); 561463838725SMat Martineau 561563838725SMat Martineau skb = l2cap_ertm_seq_in_queue(&chan->srej_q, chan->buffer_seq); 561663838725SMat Martineau 561763838725SMat Martineau if (!skb) 561863838725SMat Martineau break; 561963838725SMat Martineau 562063838725SMat Martineau skb_unlink(skb, &chan->srej_q); 562163838725SMat Martineau chan->buffer_seq = __next_seq(chan, chan->buffer_seq); 562263838725SMat Martineau err = l2cap_reassemble_sdu(chan, skb, &bt_cb(skb)->control); 562363838725SMat Martineau if (err) 562463838725SMat Martineau break; 562563838725SMat Martineau } 562663838725SMat Martineau 562763838725SMat Martineau if (skb_queue_empty(&chan->srej_q)) { 562863838725SMat Martineau chan->rx_state = L2CAP_RX_STATE_RECV; 562963838725SMat Martineau l2cap_send_ack(chan); 563063838725SMat Martineau } 563163838725SMat Martineau 563263838725SMat Martineau return err; 5633d2a7ac5dSMat Martineau } 5634d2a7ac5dSMat Martineau 5635d2a7ac5dSMat Martineau static void l2cap_handle_srej(struct l2cap_chan *chan, 5636d2a7ac5dSMat Martineau struct l2cap_ctrl *control) 5637d2a7ac5dSMat Martineau { 5638f80842a8SMat Martineau struct sk_buff *skb; 5639f80842a8SMat Martineau 5640f80842a8SMat Martineau BT_DBG("chan %p, control %p", chan, control); 5641f80842a8SMat Martineau 5642f80842a8SMat Martineau if (control->reqseq == chan->next_tx_seq) { 5643f80842a8SMat Martineau BT_DBG("Invalid reqseq %d, disconnecting", control->reqseq); 56445e4e3972SAndrei Emeltchenko l2cap_send_disconn_req(chan, ECONNRESET); 5645f80842a8SMat Martineau return; 5646f80842a8SMat Martineau } 5647f80842a8SMat Martineau 5648f80842a8SMat Martineau skb = l2cap_ertm_seq_in_queue(&chan->tx_q, control->reqseq); 5649f80842a8SMat Martineau 5650f80842a8SMat Martineau if (skb == NULL) { 5651f80842a8SMat Martineau BT_DBG("Seq %d not available for retransmission", 5652f80842a8SMat Martineau control->reqseq); 5653f80842a8SMat Martineau return; 5654f80842a8SMat Martineau } 5655f80842a8SMat Martineau 5656f80842a8SMat Martineau if (chan->max_tx != 0 && bt_cb(skb)->control.retries >= chan->max_tx) { 5657f80842a8SMat Martineau BT_DBG("Retry limit exceeded (%d)", chan->max_tx); 56585e4e3972SAndrei Emeltchenko l2cap_send_disconn_req(chan, ECONNRESET); 5659f80842a8SMat Martineau return; 5660f80842a8SMat Martineau } 5661f80842a8SMat Martineau 5662f80842a8SMat Martineau clear_bit(CONN_REMOTE_BUSY, &chan->conn_state); 5663f80842a8SMat Martineau 5664f80842a8SMat Martineau if (control->poll) { 5665f80842a8SMat Martineau l2cap_pass_to_tx(chan, control); 5666f80842a8SMat Martineau 5667f80842a8SMat Martineau set_bit(CONN_SEND_FBIT, &chan->conn_state); 5668f80842a8SMat Martineau l2cap_retransmit(chan, control); 5669f80842a8SMat Martineau l2cap_ertm_send(chan); 5670f80842a8SMat Martineau 5671f80842a8SMat Martineau if (chan->tx_state == L2CAP_TX_STATE_WAIT_F) { 5672f80842a8SMat Martineau set_bit(CONN_SREJ_ACT, &chan->conn_state); 5673f80842a8SMat Martineau chan->srej_save_reqseq = control->reqseq; 5674f80842a8SMat Martineau } 5675f80842a8SMat Martineau } else { 5676f80842a8SMat Martineau l2cap_pass_to_tx_fbit(chan, control); 5677f80842a8SMat Martineau 5678f80842a8SMat Martineau if (control->final) { 5679f80842a8SMat Martineau if (chan->srej_save_reqseq != control->reqseq || 5680f80842a8SMat Martineau !test_and_clear_bit(CONN_SREJ_ACT, 5681f80842a8SMat Martineau &chan->conn_state)) 5682f80842a8SMat Martineau l2cap_retransmit(chan, control); 5683f80842a8SMat Martineau } else { 5684f80842a8SMat Martineau l2cap_retransmit(chan, control); 5685f80842a8SMat Martineau if (chan->tx_state == L2CAP_TX_STATE_WAIT_F) { 5686f80842a8SMat Martineau set_bit(CONN_SREJ_ACT, &chan->conn_state); 5687f80842a8SMat Martineau chan->srej_save_reqseq = control->reqseq; 5688f80842a8SMat Martineau } 5689f80842a8SMat Martineau } 5690f80842a8SMat Martineau } 5691d2a7ac5dSMat Martineau } 5692d2a7ac5dSMat Martineau 5693d2a7ac5dSMat Martineau static void l2cap_handle_rej(struct l2cap_chan *chan, 5694d2a7ac5dSMat Martineau struct l2cap_ctrl *control) 5695d2a7ac5dSMat Martineau { 5696fcd289dfSMat Martineau struct sk_buff *skb; 5697fcd289dfSMat Martineau 5698fcd289dfSMat Martineau BT_DBG("chan %p, control %p", chan, control); 5699fcd289dfSMat Martineau 5700fcd289dfSMat Martineau if (control->reqseq == chan->next_tx_seq) { 5701fcd289dfSMat Martineau BT_DBG("Invalid reqseq %d, disconnecting", control->reqseq); 57025e4e3972SAndrei Emeltchenko l2cap_send_disconn_req(chan, ECONNRESET); 5703fcd289dfSMat Martineau return; 5704fcd289dfSMat Martineau } 5705fcd289dfSMat Martineau 5706fcd289dfSMat Martineau skb = l2cap_ertm_seq_in_queue(&chan->tx_q, control->reqseq); 5707fcd289dfSMat Martineau 5708fcd289dfSMat Martineau if (chan->max_tx && skb && 5709fcd289dfSMat Martineau bt_cb(skb)->control.retries >= chan->max_tx) { 5710fcd289dfSMat Martineau BT_DBG("Retry limit exceeded (%d)", chan->max_tx); 57115e4e3972SAndrei Emeltchenko l2cap_send_disconn_req(chan, ECONNRESET); 5712fcd289dfSMat Martineau return; 5713fcd289dfSMat Martineau } 5714fcd289dfSMat Martineau 5715fcd289dfSMat Martineau clear_bit(CONN_REMOTE_BUSY, &chan->conn_state); 5716fcd289dfSMat Martineau 5717fcd289dfSMat Martineau l2cap_pass_to_tx(chan, control); 5718fcd289dfSMat Martineau 5719fcd289dfSMat Martineau if (control->final) { 5720fcd289dfSMat Martineau if (!test_and_clear_bit(CONN_REJ_ACT, &chan->conn_state)) 5721fcd289dfSMat Martineau l2cap_retransmit_all(chan, control); 5722fcd289dfSMat Martineau } else { 5723fcd289dfSMat Martineau l2cap_retransmit_all(chan, control); 5724fcd289dfSMat Martineau l2cap_ertm_send(chan); 5725fcd289dfSMat Martineau if (chan->tx_state == L2CAP_TX_STATE_WAIT_F) 5726fcd289dfSMat Martineau set_bit(CONN_REJ_ACT, &chan->conn_state); 5727fcd289dfSMat Martineau } 5728d2a7ac5dSMat Martineau } 5729d2a7ac5dSMat Martineau 57304b51dae9SMat Martineau static u8 l2cap_classify_txseq(struct l2cap_chan *chan, u16 txseq) 57314b51dae9SMat Martineau { 57324b51dae9SMat Martineau BT_DBG("chan %p, txseq %d", chan, txseq); 57334b51dae9SMat Martineau 57344b51dae9SMat Martineau BT_DBG("last_acked_seq %d, expected_tx_seq %d", chan->last_acked_seq, 57354b51dae9SMat Martineau chan->expected_tx_seq); 57364b51dae9SMat Martineau 57374b51dae9SMat Martineau if (chan->rx_state == L2CAP_RX_STATE_SREJ_SENT) { 57384b51dae9SMat Martineau if (__seq_offset(chan, txseq, chan->last_acked_seq) >= 57394b51dae9SMat Martineau chan->tx_win) { 57404b51dae9SMat Martineau /* See notes below regarding "double poll" and 57414b51dae9SMat Martineau * invalid packets. 57424b51dae9SMat Martineau */ 57434b51dae9SMat Martineau if (chan->tx_win <= ((chan->tx_win_max + 1) >> 1)) { 57444b51dae9SMat Martineau BT_DBG("Invalid/Ignore - after SREJ"); 57454b51dae9SMat Martineau return L2CAP_TXSEQ_INVALID_IGNORE; 57464b51dae9SMat Martineau } else { 57474b51dae9SMat Martineau BT_DBG("Invalid - in window after SREJ sent"); 57484b51dae9SMat Martineau return L2CAP_TXSEQ_INVALID; 57494b51dae9SMat Martineau } 57504b51dae9SMat Martineau } 57514b51dae9SMat Martineau 57524b51dae9SMat Martineau if (chan->srej_list.head == txseq) { 57534b51dae9SMat Martineau BT_DBG("Expected SREJ"); 57544b51dae9SMat Martineau return L2CAP_TXSEQ_EXPECTED_SREJ; 57554b51dae9SMat Martineau } 57564b51dae9SMat Martineau 57574b51dae9SMat Martineau if (l2cap_ertm_seq_in_queue(&chan->srej_q, txseq)) { 57584b51dae9SMat Martineau BT_DBG("Duplicate SREJ - txseq already stored"); 57594b51dae9SMat Martineau return L2CAP_TXSEQ_DUPLICATE_SREJ; 57604b51dae9SMat Martineau } 57614b51dae9SMat Martineau 57624b51dae9SMat Martineau if (l2cap_seq_list_contains(&chan->srej_list, txseq)) { 57634b51dae9SMat Martineau BT_DBG("Unexpected SREJ - not requested"); 57644b51dae9SMat Martineau return L2CAP_TXSEQ_UNEXPECTED_SREJ; 57654b51dae9SMat Martineau } 57664b51dae9SMat Martineau } 57674b51dae9SMat Martineau 57684b51dae9SMat Martineau if (chan->expected_tx_seq == txseq) { 57694b51dae9SMat Martineau if (__seq_offset(chan, txseq, chan->last_acked_seq) >= 57704b51dae9SMat Martineau chan->tx_win) { 57714b51dae9SMat Martineau BT_DBG("Invalid - txseq outside tx window"); 57724b51dae9SMat Martineau return L2CAP_TXSEQ_INVALID; 57734b51dae9SMat Martineau } else { 57744b51dae9SMat Martineau BT_DBG("Expected"); 57754b51dae9SMat Martineau return L2CAP_TXSEQ_EXPECTED; 57764b51dae9SMat Martineau } 57774b51dae9SMat Martineau } 57784b51dae9SMat Martineau 57794b51dae9SMat Martineau if (__seq_offset(chan, txseq, chan->last_acked_seq) < 57802d792818SGustavo Padovan __seq_offset(chan, chan->expected_tx_seq, chan->last_acked_seq)) { 57814b51dae9SMat Martineau BT_DBG("Duplicate - expected_tx_seq later than txseq"); 57824b51dae9SMat Martineau return L2CAP_TXSEQ_DUPLICATE; 57834b51dae9SMat Martineau } 57844b51dae9SMat Martineau 57854b51dae9SMat Martineau if (__seq_offset(chan, txseq, chan->last_acked_seq) >= chan->tx_win) { 57864b51dae9SMat Martineau /* A source of invalid packets is a "double poll" condition, 57874b51dae9SMat Martineau * where delays cause us to send multiple poll packets. If 57884b51dae9SMat Martineau * the remote stack receives and processes both polls, 57894b51dae9SMat Martineau * sequence numbers can wrap around in such a way that a 57904b51dae9SMat Martineau * resent frame has a sequence number that looks like new data 57914b51dae9SMat Martineau * with a sequence gap. This would trigger an erroneous SREJ 57924b51dae9SMat Martineau * request. 57934b51dae9SMat Martineau * 57944b51dae9SMat Martineau * Fortunately, this is impossible with a tx window that's 57954b51dae9SMat Martineau * less than half of the maximum sequence number, which allows 57964b51dae9SMat Martineau * invalid frames to be safely ignored. 57974b51dae9SMat Martineau * 57984b51dae9SMat Martineau * With tx window sizes greater than half of the tx window 57994b51dae9SMat Martineau * maximum, the frame is invalid and cannot be ignored. This 58004b51dae9SMat Martineau * causes a disconnect. 58014b51dae9SMat Martineau */ 58024b51dae9SMat Martineau 58034b51dae9SMat Martineau if (chan->tx_win <= ((chan->tx_win_max + 1) >> 1)) { 58044b51dae9SMat Martineau BT_DBG("Invalid/Ignore - txseq outside tx window"); 58054b51dae9SMat Martineau return L2CAP_TXSEQ_INVALID_IGNORE; 58064b51dae9SMat Martineau } else { 58074b51dae9SMat Martineau BT_DBG("Invalid - txseq outside tx window"); 58084b51dae9SMat Martineau return L2CAP_TXSEQ_INVALID; 58094b51dae9SMat Martineau } 58104b51dae9SMat Martineau } else { 58114b51dae9SMat Martineau BT_DBG("Unexpected - txseq indicates missing frames"); 58124b51dae9SMat Martineau return L2CAP_TXSEQ_UNEXPECTED; 58134b51dae9SMat Martineau } 58144b51dae9SMat Martineau } 58154b51dae9SMat Martineau 5816d2a7ac5dSMat Martineau static int l2cap_rx_state_recv(struct l2cap_chan *chan, 5817d2a7ac5dSMat Martineau struct l2cap_ctrl *control, 5818d2a7ac5dSMat Martineau struct sk_buff *skb, u8 event) 5819d2a7ac5dSMat Martineau { 5820d2a7ac5dSMat Martineau int err = 0; 5821941247f9SPeter Senna Tschudin bool skb_in_use = false; 5822d2a7ac5dSMat Martineau 5823d2a7ac5dSMat Martineau BT_DBG("chan %p, control %p, skb %p, event %d", chan, control, skb, 5824d2a7ac5dSMat Martineau event); 5825d2a7ac5dSMat Martineau 5826d2a7ac5dSMat Martineau switch (event) { 5827d2a7ac5dSMat Martineau case L2CAP_EV_RECV_IFRAME: 5828d2a7ac5dSMat Martineau switch (l2cap_classify_txseq(chan, control->txseq)) { 5829d2a7ac5dSMat Martineau case L2CAP_TXSEQ_EXPECTED: 5830d2a7ac5dSMat Martineau l2cap_pass_to_tx(chan, control); 5831d2a7ac5dSMat Martineau 5832d2a7ac5dSMat Martineau if (test_bit(CONN_LOCAL_BUSY, &chan->conn_state)) { 5833d2a7ac5dSMat Martineau BT_DBG("Busy, discarding expected seq %d", 5834d2a7ac5dSMat Martineau control->txseq); 5835d2a7ac5dSMat Martineau break; 5836d2a7ac5dSMat Martineau } 5837d2a7ac5dSMat Martineau 5838d2a7ac5dSMat Martineau chan->expected_tx_seq = __next_seq(chan, 5839d2a7ac5dSMat Martineau control->txseq); 5840d2a7ac5dSMat Martineau 5841d2a7ac5dSMat Martineau chan->buffer_seq = chan->expected_tx_seq; 5842941247f9SPeter Senna Tschudin skb_in_use = true; 5843d2a7ac5dSMat Martineau 5844d2a7ac5dSMat Martineau err = l2cap_reassemble_sdu(chan, skb, control); 5845d2a7ac5dSMat Martineau if (err) 5846d2a7ac5dSMat Martineau break; 5847d2a7ac5dSMat Martineau 5848d2a7ac5dSMat Martineau if (control->final) { 5849d2a7ac5dSMat Martineau if (!test_and_clear_bit(CONN_REJ_ACT, 5850d2a7ac5dSMat Martineau &chan->conn_state)) { 5851d2a7ac5dSMat Martineau control->final = 0; 5852d2a7ac5dSMat Martineau l2cap_retransmit_all(chan, control); 5853d2a7ac5dSMat Martineau l2cap_ertm_send(chan); 5854d2a7ac5dSMat Martineau } 5855d2a7ac5dSMat Martineau } 5856d2a7ac5dSMat Martineau 5857d2a7ac5dSMat Martineau if (!test_bit(CONN_LOCAL_BUSY, &chan->conn_state)) 5858d2a7ac5dSMat Martineau l2cap_send_ack(chan); 5859d2a7ac5dSMat Martineau break; 5860d2a7ac5dSMat Martineau case L2CAP_TXSEQ_UNEXPECTED: 5861d2a7ac5dSMat Martineau l2cap_pass_to_tx(chan, control); 5862d2a7ac5dSMat Martineau 5863d2a7ac5dSMat Martineau /* Can't issue SREJ frames in the local busy state. 5864d2a7ac5dSMat Martineau * Drop this frame, it will be seen as missing 5865d2a7ac5dSMat Martineau * when local busy is exited. 5866d2a7ac5dSMat Martineau */ 5867d2a7ac5dSMat Martineau if (test_bit(CONN_LOCAL_BUSY, &chan->conn_state)) { 5868d2a7ac5dSMat Martineau BT_DBG("Busy, discarding unexpected seq %d", 5869d2a7ac5dSMat Martineau control->txseq); 5870d2a7ac5dSMat Martineau break; 5871d2a7ac5dSMat Martineau } 5872d2a7ac5dSMat Martineau 5873d2a7ac5dSMat Martineau /* There was a gap in the sequence, so an SREJ 5874d2a7ac5dSMat Martineau * must be sent for each missing frame. The 5875d2a7ac5dSMat Martineau * current frame is stored for later use. 5876d2a7ac5dSMat Martineau */ 5877d2a7ac5dSMat Martineau skb_queue_tail(&chan->srej_q, skb); 5878941247f9SPeter Senna Tschudin skb_in_use = true; 5879d2a7ac5dSMat Martineau BT_DBG("Queued %p (queue len %d)", skb, 5880d2a7ac5dSMat Martineau skb_queue_len(&chan->srej_q)); 5881d2a7ac5dSMat Martineau 5882d2a7ac5dSMat Martineau clear_bit(CONN_SREJ_ACT, &chan->conn_state); 5883d2a7ac5dSMat Martineau l2cap_seq_list_clear(&chan->srej_list); 5884d2a7ac5dSMat Martineau l2cap_send_srej(chan, control->txseq); 5885d2a7ac5dSMat Martineau 5886d2a7ac5dSMat Martineau chan->rx_state = L2CAP_RX_STATE_SREJ_SENT; 5887d2a7ac5dSMat Martineau break; 5888d2a7ac5dSMat Martineau case L2CAP_TXSEQ_DUPLICATE: 5889d2a7ac5dSMat Martineau l2cap_pass_to_tx(chan, control); 5890d2a7ac5dSMat Martineau break; 5891d2a7ac5dSMat Martineau case L2CAP_TXSEQ_INVALID_IGNORE: 5892d2a7ac5dSMat Martineau break; 5893d2a7ac5dSMat Martineau case L2CAP_TXSEQ_INVALID: 5894d2a7ac5dSMat Martineau default: 58955e4e3972SAndrei Emeltchenko l2cap_send_disconn_req(chan, ECONNRESET); 5896d2a7ac5dSMat Martineau break; 5897d2a7ac5dSMat Martineau } 5898d2a7ac5dSMat Martineau break; 5899d2a7ac5dSMat Martineau case L2CAP_EV_RECV_RR: 5900d2a7ac5dSMat Martineau l2cap_pass_to_tx(chan, control); 5901d2a7ac5dSMat Martineau if (control->final) { 5902d2a7ac5dSMat Martineau clear_bit(CONN_REMOTE_BUSY, &chan->conn_state); 5903d2a7ac5dSMat Martineau 5904e6a3ee6eSMat Martineau if (!test_and_clear_bit(CONN_REJ_ACT, &chan->conn_state) && 5905e6a3ee6eSMat Martineau !__chan_is_moving(chan)) { 5906d2a7ac5dSMat Martineau control->final = 0; 5907d2a7ac5dSMat Martineau l2cap_retransmit_all(chan, control); 5908d2a7ac5dSMat Martineau } 5909d2a7ac5dSMat Martineau 5910d2a7ac5dSMat Martineau l2cap_ertm_send(chan); 5911d2a7ac5dSMat Martineau } else if (control->poll) { 5912d2a7ac5dSMat Martineau l2cap_send_i_or_rr_or_rnr(chan); 5913d2a7ac5dSMat Martineau } else { 5914d2a7ac5dSMat Martineau if (test_and_clear_bit(CONN_REMOTE_BUSY, 5915d2a7ac5dSMat Martineau &chan->conn_state) && 5916d2a7ac5dSMat Martineau chan->unacked_frames) 5917d2a7ac5dSMat Martineau __set_retrans_timer(chan); 5918d2a7ac5dSMat Martineau 5919d2a7ac5dSMat Martineau l2cap_ertm_send(chan); 5920d2a7ac5dSMat Martineau } 5921d2a7ac5dSMat Martineau break; 5922d2a7ac5dSMat Martineau case L2CAP_EV_RECV_RNR: 5923d2a7ac5dSMat Martineau set_bit(CONN_REMOTE_BUSY, &chan->conn_state); 5924d2a7ac5dSMat Martineau l2cap_pass_to_tx(chan, control); 5925d2a7ac5dSMat Martineau if (control && control->poll) { 5926d2a7ac5dSMat Martineau set_bit(CONN_SEND_FBIT, &chan->conn_state); 5927d2a7ac5dSMat Martineau l2cap_send_rr_or_rnr(chan, 0); 5928d2a7ac5dSMat Martineau } 5929d2a7ac5dSMat Martineau __clear_retrans_timer(chan); 5930d2a7ac5dSMat Martineau l2cap_seq_list_clear(&chan->retrans_list); 5931d2a7ac5dSMat Martineau break; 5932d2a7ac5dSMat Martineau case L2CAP_EV_RECV_REJ: 5933d2a7ac5dSMat Martineau l2cap_handle_rej(chan, control); 5934d2a7ac5dSMat Martineau break; 5935d2a7ac5dSMat Martineau case L2CAP_EV_RECV_SREJ: 5936d2a7ac5dSMat Martineau l2cap_handle_srej(chan, control); 5937d2a7ac5dSMat Martineau break; 5938d2a7ac5dSMat Martineau default: 5939d2a7ac5dSMat Martineau break; 5940d2a7ac5dSMat Martineau } 5941d2a7ac5dSMat Martineau 5942d2a7ac5dSMat Martineau if (skb && !skb_in_use) { 5943d2a7ac5dSMat Martineau BT_DBG("Freeing %p", skb); 5944d2a7ac5dSMat Martineau kfree_skb(skb); 5945d2a7ac5dSMat Martineau } 5946d2a7ac5dSMat Martineau 5947d2a7ac5dSMat Martineau return err; 5948d2a7ac5dSMat Martineau } 5949d2a7ac5dSMat Martineau 5950d2a7ac5dSMat Martineau static int l2cap_rx_state_srej_sent(struct l2cap_chan *chan, 5951d2a7ac5dSMat Martineau struct l2cap_ctrl *control, 5952d2a7ac5dSMat Martineau struct sk_buff *skb, u8 event) 5953d2a7ac5dSMat Martineau { 5954d2a7ac5dSMat Martineau int err = 0; 5955d2a7ac5dSMat Martineau u16 txseq = control->txseq; 5956941247f9SPeter Senna Tschudin bool skb_in_use = false; 5957d2a7ac5dSMat Martineau 5958d2a7ac5dSMat Martineau BT_DBG("chan %p, control %p, skb %p, event %d", chan, control, skb, 5959d2a7ac5dSMat Martineau event); 5960d2a7ac5dSMat Martineau 5961d2a7ac5dSMat Martineau switch (event) { 5962d2a7ac5dSMat Martineau case L2CAP_EV_RECV_IFRAME: 5963d2a7ac5dSMat Martineau switch (l2cap_classify_txseq(chan, txseq)) { 5964d2a7ac5dSMat Martineau case L2CAP_TXSEQ_EXPECTED: 5965d2a7ac5dSMat Martineau /* Keep frame for reassembly later */ 5966d2a7ac5dSMat Martineau l2cap_pass_to_tx(chan, control); 5967d2a7ac5dSMat Martineau skb_queue_tail(&chan->srej_q, skb); 5968941247f9SPeter Senna Tschudin skb_in_use = true; 5969d2a7ac5dSMat Martineau BT_DBG("Queued %p (queue len %d)", skb, 5970d2a7ac5dSMat Martineau skb_queue_len(&chan->srej_q)); 5971d2a7ac5dSMat Martineau 5972d2a7ac5dSMat Martineau chan->expected_tx_seq = __next_seq(chan, txseq); 5973d2a7ac5dSMat Martineau break; 5974d2a7ac5dSMat Martineau case L2CAP_TXSEQ_EXPECTED_SREJ: 5975d2a7ac5dSMat Martineau l2cap_seq_list_pop(&chan->srej_list); 5976d2a7ac5dSMat Martineau 5977d2a7ac5dSMat Martineau l2cap_pass_to_tx(chan, control); 5978d2a7ac5dSMat Martineau skb_queue_tail(&chan->srej_q, skb); 5979941247f9SPeter Senna Tschudin skb_in_use = true; 5980d2a7ac5dSMat Martineau BT_DBG("Queued %p (queue len %d)", skb, 5981d2a7ac5dSMat Martineau skb_queue_len(&chan->srej_q)); 5982d2a7ac5dSMat Martineau 5983d2a7ac5dSMat Martineau err = l2cap_rx_queued_iframes(chan); 5984d2a7ac5dSMat Martineau if (err) 5985d2a7ac5dSMat Martineau break; 5986d2a7ac5dSMat Martineau 5987d2a7ac5dSMat Martineau break; 5988d2a7ac5dSMat Martineau case L2CAP_TXSEQ_UNEXPECTED: 5989d2a7ac5dSMat Martineau /* Got a frame that can't be reassembled yet. 5990d2a7ac5dSMat Martineau * Save it for later, and send SREJs to cover 5991d2a7ac5dSMat Martineau * the missing frames. 5992d2a7ac5dSMat Martineau */ 5993d2a7ac5dSMat Martineau skb_queue_tail(&chan->srej_q, skb); 5994941247f9SPeter Senna Tschudin skb_in_use = true; 5995d2a7ac5dSMat Martineau BT_DBG("Queued %p (queue len %d)", skb, 5996d2a7ac5dSMat Martineau skb_queue_len(&chan->srej_q)); 5997d2a7ac5dSMat Martineau 5998d2a7ac5dSMat Martineau l2cap_pass_to_tx(chan, control); 5999d2a7ac5dSMat Martineau l2cap_send_srej(chan, control->txseq); 6000d2a7ac5dSMat Martineau break; 6001d2a7ac5dSMat Martineau case L2CAP_TXSEQ_UNEXPECTED_SREJ: 6002d2a7ac5dSMat Martineau /* This frame was requested with an SREJ, but 6003d2a7ac5dSMat Martineau * some expected retransmitted frames are 6004d2a7ac5dSMat Martineau * missing. Request retransmission of missing 6005d2a7ac5dSMat Martineau * SREJ'd frames. 6006d2a7ac5dSMat Martineau */ 6007d2a7ac5dSMat Martineau skb_queue_tail(&chan->srej_q, skb); 6008941247f9SPeter Senna Tschudin skb_in_use = true; 6009d2a7ac5dSMat Martineau BT_DBG("Queued %p (queue len %d)", skb, 6010d2a7ac5dSMat Martineau skb_queue_len(&chan->srej_q)); 6011d2a7ac5dSMat Martineau 6012d2a7ac5dSMat Martineau l2cap_pass_to_tx(chan, control); 6013d2a7ac5dSMat Martineau l2cap_send_srej_list(chan, control->txseq); 6014d2a7ac5dSMat Martineau break; 6015d2a7ac5dSMat Martineau case L2CAP_TXSEQ_DUPLICATE_SREJ: 6016d2a7ac5dSMat Martineau /* We've already queued this frame. Drop this copy. */ 6017d2a7ac5dSMat Martineau l2cap_pass_to_tx(chan, control); 6018d2a7ac5dSMat Martineau break; 6019d2a7ac5dSMat Martineau case L2CAP_TXSEQ_DUPLICATE: 6020d2a7ac5dSMat Martineau /* Expecting a later sequence number, so this frame 6021d2a7ac5dSMat Martineau * was already received. Ignore it completely. 6022d2a7ac5dSMat Martineau */ 6023d2a7ac5dSMat Martineau break; 6024d2a7ac5dSMat Martineau case L2CAP_TXSEQ_INVALID_IGNORE: 6025d2a7ac5dSMat Martineau break; 6026d2a7ac5dSMat Martineau case L2CAP_TXSEQ_INVALID: 6027d2a7ac5dSMat Martineau default: 60285e4e3972SAndrei Emeltchenko l2cap_send_disconn_req(chan, ECONNRESET); 6029d2a7ac5dSMat Martineau break; 6030d2a7ac5dSMat Martineau } 6031d2a7ac5dSMat Martineau break; 6032d2a7ac5dSMat Martineau case L2CAP_EV_RECV_RR: 6033d2a7ac5dSMat Martineau l2cap_pass_to_tx(chan, control); 6034d2a7ac5dSMat Martineau if (control->final) { 6035d2a7ac5dSMat Martineau clear_bit(CONN_REMOTE_BUSY, &chan->conn_state); 6036d2a7ac5dSMat Martineau 6037d2a7ac5dSMat Martineau if (!test_and_clear_bit(CONN_REJ_ACT, 6038d2a7ac5dSMat Martineau &chan->conn_state)) { 6039d2a7ac5dSMat Martineau control->final = 0; 6040d2a7ac5dSMat Martineau l2cap_retransmit_all(chan, control); 6041d2a7ac5dSMat Martineau } 6042d2a7ac5dSMat Martineau 6043d2a7ac5dSMat Martineau l2cap_ertm_send(chan); 6044d2a7ac5dSMat Martineau } else if (control->poll) { 6045d2a7ac5dSMat Martineau if (test_and_clear_bit(CONN_REMOTE_BUSY, 6046d2a7ac5dSMat Martineau &chan->conn_state) && 6047d2a7ac5dSMat Martineau chan->unacked_frames) { 6048d2a7ac5dSMat Martineau __set_retrans_timer(chan); 6049d2a7ac5dSMat Martineau } 6050d2a7ac5dSMat Martineau 6051d2a7ac5dSMat Martineau set_bit(CONN_SEND_FBIT, &chan->conn_state); 6052d2a7ac5dSMat Martineau l2cap_send_srej_tail(chan); 6053d2a7ac5dSMat Martineau } else { 6054d2a7ac5dSMat Martineau if (test_and_clear_bit(CONN_REMOTE_BUSY, 6055d2a7ac5dSMat Martineau &chan->conn_state) && 6056d2a7ac5dSMat Martineau chan->unacked_frames) 6057d2a7ac5dSMat Martineau __set_retrans_timer(chan); 6058d2a7ac5dSMat Martineau 6059d2a7ac5dSMat Martineau l2cap_send_ack(chan); 6060d2a7ac5dSMat Martineau } 6061d2a7ac5dSMat Martineau break; 6062d2a7ac5dSMat Martineau case L2CAP_EV_RECV_RNR: 6063d2a7ac5dSMat Martineau set_bit(CONN_REMOTE_BUSY, &chan->conn_state); 6064d2a7ac5dSMat Martineau l2cap_pass_to_tx(chan, control); 6065d2a7ac5dSMat Martineau if (control->poll) { 6066d2a7ac5dSMat Martineau l2cap_send_srej_tail(chan); 6067d2a7ac5dSMat Martineau } else { 6068d2a7ac5dSMat Martineau struct l2cap_ctrl rr_control; 6069d2a7ac5dSMat Martineau memset(&rr_control, 0, sizeof(rr_control)); 6070d2a7ac5dSMat Martineau rr_control.sframe = 1; 6071d2a7ac5dSMat Martineau rr_control.super = L2CAP_SUPER_RR; 6072d2a7ac5dSMat Martineau rr_control.reqseq = chan->buffer_seq; 6073d2a7ac5dSMat Martineau l2cap_send_sframe(chan, &rr_control); 6074d2a7ac5dSMat Martineau } 6075d2a7ac5dSMat Martineau 6076d2a7ac5dSMat Martineau break; 6077d2a7ac5dSMat Martineau case L2CAP_EV_RECV_REJ: 6078d2a7ac5dSMat Martineau l2cap_handle_rej(chan, control); 6079d2a7ac5dSMat Martineau break; 6080d2a7ac5dSMat Martineau case L2CAP_EV_RECV_SREJ: 6081d2a7ac5dSMat Martineau l2cap_handle_srej(chan, control); 6082d2a7ac5dSMat Martineau break; 6083d2a7ac5dSMat Martineau } 6084d2a7ac5dSMat Martineau 6085d2a7ac5dSMat Martineau if (skb && !skb_in_use) { 6086d2a7ac5dSMat Martineau BT_DBG("Freeing %p", skb); 6087d2a7ac5dSMat Martineau kfree_skb(skb); 6088d2a7ac5dSMat Martineau } 6089d2a7ac5dSMat Martineau 6090d2a7ac5dSMat Martineau return err; 6091d2a7ac5dSMat Martineau } 6092d2a7ac5dSMat Martineau 609332b32735SMat Martineau static int l2cap_finish_move(struct l2cap_chan *chan) 609432b32735SMat Martineau { 609532b32735SMat Martineau BT_DBG("chan %p", chan); 609632b32735SMat Martineau 609732b32735SMat Martineau chan->rx_state = L2CAP_RX_STATE_RECV; 609832b32735SMat Martineau 609932b32735SMat Martineau if (chan->hs_hcon) 610032b32735SMat Martineau chan->conn->mtu = chan->hs_hcon->hdev->block_mtu; 610132b32735SMat Martineau else 610232b32735SMat Martineau chan->conn->mtu = chan->conn->hcon->hdev->acl_mtu; 610332b32735SMat Martineau 610432b32735SMat Martineau return l2cap_resegment(chan); 610532b32735SMat Martineau } 610632b32735SMat Martineau 610732b32735SMat Martineau static int l2cap_rx_state_wait_p(struct l2cap_chan *chan, 610832b32735SMat Martineau struct l2cap_ctrl *control, 610932b32735SMat Martineau struct sk_buff *skb, u8 event) 611032b32735SMat Martineau { 611132b32735SMat Martineau int err; 611232b32735SMat Martineau 611332b32735SMat Martineau BT_DBG("chan %p, control %p, skb %p, event %d", chan, control, skb, 611432b32735SMat Martineau event); 611532b32735SMat Martineau 611632b32735SMat Martineau if (!control->poll) 611732b32735SMat Martineau return -EPROTO; 611832b32735SMat Martineau 611932b32735SMat Martineau l2cap_process_reqseq(chan, control->reqseq); 612032b32735SMat Martineau 612132b32735SMat Martineau if (!skb_queue_empty(&chan->tx_q)) 612232b32735SMat Martineau chan->tx_send_head = skb_peek(&chan->tx_q); 612332b32735SMat Martineau else 612432b32735SMat Martineau chan->tx_send_head = NULL; 612532b32735SMat Martineau 612632b32735SMat Martineau /* Rewind next_tx_seq to the point expected 612732b32735SMat Martineau * by the receiver. 612832b32735SMat Martineau */ 612932b32735SMat Martineau chan->next_tx_seq = control->reqseq; 613032b32735SMat Martineau chan->unacked_frames = 0; 613132b32735SMat Martineau 613232b32735SMat Martineau err = l2cap_finish_move(chan); 613332b32735SMat Martineau if (err) 613432b32735SMat Martineau return err; 613532b32735SMat Martineau 613632b32735SMat Martineau set_bit(CONN_SEND_FBIT, &chan->conn_state); 613732b32735SMat Martineau l2cap_send_i_or_rr_or_rnr(chan); 613832b32735SMat Martineau 613932b32735SMat Martineau if (event == L2CAP_EV_RECV_IFRAME) 614032b32735SMat Martineau return -EPROTO; 614132b32735SMat Martineau 614232b32735SMat Martineau return l2cap_rx_state_recv(chan, control, NULL, event); 614332b32735SMat Martineau } 614432b32735SMat Martineau 614532b32735SMat Martineau static int l2cap_rx_state_wait_f(struct l2cap_chan *chan, 614632b32735SMat Martineau struct l2cap_ctrl *control, 614732b32735SMat Martineau struct sk_buff *skb, u8 event) 614832b32735SMat Martineau { 614932b32735SMat Martineau int err; 615032b32735SMat Martineau 615132b32735SMat Martineau if (!control->final) 615232b32735SMat Martineau return -EPROTO; 615332b32735SMat Martineau 615432b32735SMat Martineau clear_bit(CONN_REMOTE_BUSY, &chan->conn_state); 615532b32735SMat Martineau 615632b32735SMat Martineau chan->rx_state = L2CAP_RX_STATE_RECV; 615732b32735SMat Martineau l2cap_process_reqseq(chan, control->reqseq); 615832b32735SMat Martineau 615932b32735SMat Martineau if (!skb_queue_empty(&chan->tx_q)) 616032b32735SMat Martineau chan->tx_send_head = skb_peek(&chan->tx_q); 616132b32735SMat Martineau else 616232b32735SMat Martineau chan->tx_send_head = NULL; 616332b32735SMat Martineau 616432b32735SMat Martineau /* Rewind next_tx_seq to the point expected 616532b32735SMat Martineau * by the receiver. 616632b32735SMat Martineau */ 616732b32735SMat Martineau chan->next_tx_seq = control->reqseq; 616832b32735SMat Martineau chan->unacked_frames = 0; 616932b32735SMat Martineau 617032b32735SMat Martineau if (chan->hs_hcon) 617132b32735SMat Martineau chan->conn->mtu = chan->hs_hcon->hdev->block_mtu; 617232b32735SMat Martineau else 617332b32735SMat Martineau chan->conn->mtu = chan->conn->hcon->hdev->acl_mtu; 617432b32735SMat Martineau 617532b32735SMat Martineau err = l2cap_resegment(chan); 617632b32735SMat Martineau 617732b32735SMat Martineau if (!err) 617832b32735SMat Martineau err = l2cap_rx_state_recv(chan, control, skb, event); 617932b32735SMat Martineau 618032b32735SMat Martineau return err; 618132b32735SMat Martineau } 618232b32735SMat Martineau 6183d2a7ac5dSMat Martineau static bool __valid_reqseq(struct l2cap_chan *chan, u16 reqseq) 6184d2a7ac5dSMat Martineau { 6185d2a7ac5dSMat Martineau /* Make sure reqseq is for a packet that has been sent but not acked */ 6186d2a7ac5dSMat Martineau u16 unacked; 6187d2a7ac5dSMat Martineau 6188d2a7ac5dSMat Martineau unacked = __seq_offset(chan, chan->next_tx_seq, chan->expected_ack_seq); 6189d2a7ac5dSMat Martineau return __seq_offset(chan, chan->next_tx_seq, reqseq) <= unacked; 6190d2a7ac5dSMat Martineau } 6191d2a7ac5dSMat Martineau 6192cec8ab6eSMat Martineau static int l2cap_rx(struct l2cap_chan *chan, struct l2cap_ctrl *control, 6193cec8ab6eSMat Martineau struct sk_buff *skb, u8 event) 61940a708f8fSGustavo F. Padovan { 6195d2a7ac5dSMat Martineau int err = 0; 6196d2a7ac5dSMat Martineau 6197d2a7ac5dSMat Martineau BT_DBG("chan %p, control %p, skb %p, event %d, state %d", chan, 6198d2a7ac5dSMat Martineau control, skb, event, chan->rx_state); 6199d2a7ac5dSMat Martineau 6200d2a7ac5dSMat Martineau if (__valid_reqseq(chan, control->reqseq)) { 6201d2a7ac5dSMat Martineau switch (chan->rx_state) { 6202d2a7ac5dSMat Martineau case L2CAP_RX_STATE_RECV: 6203d2a7ac5dSMat Martineau err = l2cap_rx_state_recv(chan, control, skb, event); 6204d2a7ac5dSMat Martineau break; 6205d2a7ac5dSMat Martineau case L2CAP_RX_STATE_SREJ_SENT: 6206d2a7ac5dSMat Martineau err = l2cap_rx_state_srej_sent(chan, control, skb, 6207d2a7ac5dSMat Martineau event); 6208d2a7ac5dSMat Martineau break; 620932b32735SMat Martineau case L2CAP_RX_STATE_WAIT_P: 621032b32735SMat Martineau err = l2cap_rx_state_wait_p(chan, control, skb, event); 621132b32735SMat Martineau break; 621232b32735SMat Martineau case L2CAP_RX_STATE_WAIT_F: 621332b32735SMat Martineau err = l2cap_rx_state_wait_f(chan, control, skb, event); 621432b32735SMat Martineau break; 6215d2a7ac5dSMat Martineau default: 6216d2a7ac5dSMat Martineau /* shut it down */ 6217d2a7ac5dSMat Martineau break; 6218d2a7ac5dSMat Martineau } 6219d2a7ac5dSMat Martineau } else { 6220d2a7ac5dSMat Martineau BT_DBG("Invalid reqseq %d (next_tx_seq %d, expected_ack_seq %d", 6221d2a7ac5dSMat Martineau control->reqseq, chan->next_tx_seq, 6222d2a7ac5dSMat Martineau chan->expected_ack_seq); 62235e4e3972SAndrei Emeltchenko l2cap_send_disconn_req(chan, ECONNRESET); 6224d2a7ac5dSMat Martineau } 6225d2a7ac5dSMat Martineau 6226d2a7ac5dSMat Martineau return err; 6227cec8ab6eSMat Martineau } 6228cec8ab6eSMat Martineau 6229cec8ab6eSMat Martineau static int l2cap_stream_rx(struct l2cap_chan *chan, struct l2cap_ctrl *control, 6230cec8ab6eSMat Martineau struct sk_buff *skb) 6231cec8ab6eSMat Martineau { 62324b51dae9SMat Martineau int err = 0; 62334b51dae9SMat Martineau 62344b51dae9SMat Martineau BT_DBG("chan %p, control %p, skb %p, state %d", chan, control, skb, 62354b51dae9SMat Martineau chan->rx_state); 62364b51dae9SMat Martineau 62374b51dae9SMat Martineau if (l2cap_classify_txseq(chan, control->txseq) == 62384b51dae9SMat Martineau L2CAP_TXSEQ_EXPECTED) { 62394b51dae9SMat Martineau l2cap_pass_to_tx(chan, control); 62404b51dae9SMat Martineau 62414b51dae9SMat Martineau BT_DBG("buffer_seq %d->%d", chan->buffer_seq, 62424b51dae9SMat Martineau __next_seq(chan, chan->buffer_seq)); 62434b51dae9SMat Martineau 62444b51dae9SMat Martineau chan->buffer_seq = __next_seq(chan, chan->buffer_seq); 62454b51dae9SMat Martineau 62464b51dae9SMat Martineau l2cap_reassemble_sdu(chan, skb, control); 62474b51dae9SMat Martineau } else { 62484b51dae9SMat Martineau if (chan->sdu) { 62494b51dae9SMat Martineau kfree_skb(chan->sdu); 62504b51dae9SMat Martineau chan->sdu = NULL; 62514b51dae9SMat Martineau } 62524b51dae9SMat Martineau chan->sdu_last_frag = NULL; 62534b51dae9SMat Martineau chan->sdu_len = 0; 62544b51dae9SMat Martineau 62554b51dae9SMat Martineau if (skb) { 62564b51dae9SMat Martineau BT_DBG("Freeing %p", skb); 62574b51dae9SMat Martineau kfree_skb(skb); 62584b51dae9SMat Martineau } 62594b51dae9SMat Martineau } 62604b51dae9SMat Martineau 62614b51dae9SMat Martineau chan->last_acked_seq = control->txseq; 62624b51dae9SMat Martineau chan->expected_tx_seq = __next_seq(chan, control->txseq); 62634b51dae9SMat Martineau 62644b51dae9SMat Martineau return err; 6265cec8ab6eSMat Martineau } 6266cec8ab6eSMat Martineau 6267cec8ab6eSMat Martineau static int l2cap_data_rcv(struct l2cap_chan *chan, struct sk_buff *skb) 6268cec8ab6eSMat Martineau { 6269cec8ab6eSMat Martineau struct l2cap_ctrl *control = &bt_cb(skb)->control; 6270cec8ab6eSMat Martineau u16 len; 6271cec8ab6eSMat Martineau u8 event; 62720a708f8fSGustavo F. Padovan 6273b76bbd66SMat Martineau __unpack_control(chan, skb); 6274b76bbd66SMat Martineau 62750a708f8fSGustavo F. Padovan len = skb->len; 62760a708f8fSGustavo F. Padovan 62770a708f8fSGustavo F. Padovan /* 62780a708f8fSGustavo F. Padovan * We can just drop the corrupted I-frame here. 62790a708f8fSGustavo F. Padovan * Receiver will miss it and start proper recovery 6280cec8ab6eSMat Martineau * procedures and ask for retransmission. 62810a708f8fSGustavo F. Padovan */ 628247d1ec61SGustavo F. Padovan if (l2cap_check_fcs(chan, skb)) 62830a708f8fSGustavo F. Padovan goto drop; 62840a708f8fSGustavo F. Padovan 6285cec8ab6eSMat Martineau if (!control->sframe && control->sar == L2CAP_SAR_START) 628603a51213SAndrei Emeltchenko len -= L2CAP_SDULEN_SIZE; 62870a708f8fSGustavo F. Padovan 628847d1ec61SGustavo F. Padovan if (chan->fcs == L2CAP_FCS_CRC16) 628903a51213SAndrei Emeltchenko len -= L2CAP_FCS_SIZE; 62900a708f8fSGustavo F. Padovan 629147d1ec61SGustavo F. Padovan if (len > chan->mps) { 62925e4e3972SAndrei Emeltchenko l2cap_send_disconn_req(chan, ECONNRESET); 62930a708f8fSGustavo F. Padovan goto drop; 62940a708f8fSGustavo F. Padovan } 62950a708f8fSGustavo F. Padovan 6296cec8ab6eSMat Martineau if (!control->sframe) { 6297cec8ab6eSMat Martineau int err; 62980a708f8fSGustavo F. Padovan 6299cec8ab6eSMat Martineau BT_DBG("iframe sar %d, reqseq %d, final %d, txseq %d", 6300cec8ab6eSMat Martineau control->sar, control->reqseq, control->final, 6301cec8ab6eSMat Martineau control->txseq); 6302836be934SAndrei Emeltchenko 6303cec8ab6eSMat Martineau /* Validate F-bit - F=0 always valid, F=1 only 6304cec8ab6eSMat Martineau * valid in TX WAIT_F 6305cec8ab6eSMat Martineau */ 6306cec8ab6eSMat Martineau if (control->final && chan->tx_state != L2CAP_TX_STATE_WAIT_F) 63070a708f8fSGustavo F. Padovan goto drop; 63080a708f8fSGustavo F. Padovan 6309cec8ab6eSMat Martineau if (chan->mode != L2CAP_MODE_STREAMING) { 6310cec8ab6eSMat Martineau event = L2CAP_EV_RECV_IFRAME; 6311cec8ab6eSMat Martineau err = l2cap_rx(chan, control, skb, event); 63120a708f8fSGustavo F. Padovan } else { 6313cec8ab6eSMat Martineau err = l2cap_stream_rx(chan, control, skb); 6314cec8ab6eSMat Martineau } 6315cec8ab6eSMat Martineau 6316cec8ab6eSMat Martineau if (err) 63175e4e3972SAndrei Emeltchenko l2cap_send_disconn_req(chan, ECONNRESET); 6318cec8ab6eSMat Martineau } else { 6319cec8ab6eSMat Martineau const u8 rx_func_to_event[4] = { 6320cec8ab6eSMat Martineau L2CAP_EV_RECV_RR, L2CAP_EV_RECV_REJ, 6321cec8ab6eSMat Martineau L2CAP_EV_RECV_RNR, L2CAP_EV_RECV_SREJ 6322cec8ab6eSMat Martineau }; 6323cec8ab6eSMat Martineau 6324cec8ab6eSMat Martineau /* Only I-frames are expected in streaming mode */ 6325cec8ab6eSMat Martineau if (chan->mode == L2CAP_MODE_STREAMING) 6326cec8ab6eSMat Martineau goto drop; 6327cec8ab6eSMat Martineau 6328cec8ab6eSMat Martineau BT_DBG("sframe reqseq %d, final %d, poll %d, super %d", 6329cec8ab6eSMat Martineau control->reqseq, control->final, control->poll, 6330cec8ab6eSMat Martineau control->super); 6331cec8ab6eSMat Martineau 63320a708f8fSGustavo F. Padovan if (len != 0) { 63331bb166e6SAndrei Emeltchenko BT_ERR("Trailing bytes: %d in sframe", len); 63345e4e3972SAndrei Emeltchenko l2cap_send_disconn_req(chan, ECONNRESET); 63350a708f8fSGustavo F. Padovan goto drop; 63360a708f8fSGustavo F. Padovan } 63370a708f8fSGustavo F. Padovan 6338cec8ab6eSMat Martineau /* Validate F and P bits */ 6339cec8ab6eSMat Martineau if (control->final && (control->poll || 6340cec8ab6eSMat Martineau chan->tx_state != L2CAP_TX_STATE_WAIT_F)) 6341cec8ab6eSMat Martineau goto drop; 6342cec8ab6eSMat Martineau 6343cec8ab6eSMat Martineau event = rx_func_to_event[control->super]; 6344cec8ab6eSMat Martineau if (l2cap_rx(chan, control, skb, event)) 63455e4e3972SAndrei Emeltchenko l2cap_send_disconn_req(chan, ECONNRESET); 63460a708f8fSGustavo F. Padovan } 63470a708f8fSGustavo F. Padovan 63480a708f8fSGustavo F. Padovan return 0; 63490a708f8fSGustavo F. Padovan 63500a708f8fSGustavo F. Padovan drop: 63510a708f8fSGustavo F. Padovan kfree_skb(skb); 63520a708f8fSGustavo F. Padovan return 0; 63530a708f8fSGustavo F. Padovan } 63540a708f8fSGustavo F. Padovan 635513ca56e0SAndrei Emeltchenko static void l2cap_data_channel(struct l2cap_conn *conn, u16 cid, 635613ca56e0SAndrei Emeltchenko struct sk_buff *skb) 63570a708f8fSGustavo F. Padovan { 635848454079SGustavo F. Padovan struct l2cap_chan *chan; 63590a708f8fSGustavo F. Padovan 6360baa7e1faSGustavo F. Padovan chan = l2cap_get_chan_by_scid(conn, cid); 636148454079SGustavo F. Padovan if (!chan) { 636297e8e89dSAndrei Emeltchenko if (cid == L2CAP_CID_A2MP) { 636397e8e89dSAndrei Emeltchenko chan = a2mp_channel_create(conn, skb); 636497e8e89dSAndrei Emeltchenko if (!chan) { 636597e8e89dSAndrei Emeltchenko kfree_skb(skb); 636613ca56e0SAndrei Emeltchenko return; 636797e8e89dSAndrei Emeltchenko } 636897e8e89dSAndrei Emeltchenko 636997e8e89dSAndrei Emeltchenko l2cap_chan_lock(chan); 637097e8e89dSAndrei Emeltchenko } else { 63710a708f8fSGustavo F. Padovan BT_DBG("unknown cid 0x%4.4x", cid); 63726be36555SAndrei Emeltchenko /* Drop packet and return */ 63733379013bSDan Carpenter kfree_skb(skb); 637413ca56e0SAndrei Emeltchenko return; 63750a708f8fSGustavo F. Padovan } 637697e8e89dSAndrei Emeltchenko } 63770a708f8fSGustavo F. Padovan 637849208c9cSGustavo F. Padovan BT_DBG("chan %p, len %d", chan, skb->len); 63790a708f8fSGustavo F. Padovan 638089bc500eSGustavo F. Padovan if (chan->state != BT_CONNECTED) 63810a708f8fSGustavo F. Padovan goto drop; 63820a708f8fSGustavo F. Padovan 63830c1bc5c6SGustavo F. Padovan switch (chan->mode) { 63840a708f8fSGustavo F. Padovan case L2CAP_MODE_BASIC: 63850a708f8fSGustavo F. Padovan /* If socket recv buffers overflows we drop data here 63860a708f8fSGustavo F. Padovan * which is *bad* because L2CAP has to be reliable. 63870a708f8fSGustavo F. Padovan * But we don't have any other choice. L2CAP doesn't 63880a708f8fSGustavo F. Padovan * provide flow control mechanism. */ 63890a708f8fSGustavo F. Padovan 63900c1bc5c6SGustavo F. Padovan if (chan->imtu < skb->len) 63910a708f8fSGustavo F. Padovan goto drop; 63920a708f8fSGustavo F. Padovan 639380b98027SGustavo Padovan if (!chan->ops->recv(chan, skb)) 63940a708f8fSGustavo F. Padovan goto done; 63950a708f8fSGustavo F. Padovan break; 63960a708f8fSGustavo F. Padovan 63970a708f8fSGustavo F. Padovan case L2CAP_MODE_ERTM: 63980a708f8fSGustavo F. Padovan case L2CAP_MODE_STREAMING: 6399cec8ab6eSMat Martineau l2cap_data_rcv(chan, skb); 64000a708f8fSGustavo F. Padovan goto done; 64010a708f8fSGustavo F. Padovan 64020a708f8fSGustavo F. Padovan default: 64030c1bc5c6SGustavo F. Padovan BT_DBG("chan %p: bad mode 0x%2.2x", chan, chan->mode); 64040a708f8fSGustavo F. Padovan break; 64050a708f8fSGustavo F. Padovan } 64060a708f8fSGustavo F. Padovan 64070a708f8fSGustavo F. Padovan drop: 64080a708f8fSGustavo F. Padovan kfree_skb(skb); 64090a708f8fSGustavo F. Padovan 64100a708f8fSGustavo F. Padovan done: 64116be36555SAndrei Emeltchenko l2cap_chan_unlock(chan); 64120a708f8fSGustavo F. Padovan } 64130a708f8fSGustavo F. Padovan 641484104b24SAndrei Emeltchenko static void l2cap_conless_channel(struct l2cap_conn *conn, __le16 psm, 641584104b24SAndrei Emeltchenko struct sk_buff *skb) 64160a708f8fSGustavo F. Padovan { 6417ae4fd2d3SMarcel Holtmann struct hci_conn *hcon = conn->hcon; 641823691d75SGustavo F. Padovan struct l2cap_chan *chan; 64190a708f8fSGustavo F. Padovan 6420ae4fd2d3SMarcel Holtmann if (hcon->type != ACL_LINK) 6421ae4fd2d3SMarcel Holtmann goto drop; 6422ae4fd2d3SMarcel Holtmann 6423c2287681SIdo Yariv chan = l2cap_global_chan_by_psm(0, psm, conn->src, conn->dst); 642423691d75SGustavo F. Padovan if (!chan) 64250a708f8fSGustavo F. Padovan goto drop; 64260a708f8fSGustavo F. Padovan 64275b4cedaaSAndrei Emeltchenko BT_DBG("chan %p, len %d", chan, skb->len); 64280a708f8fSGustavo F. Padovan 642989bc500eSGustavo F. Padovan if (chan->state != BT_BOUND && chan->state != BT_CONNECTED) 64300a708f8fSGustavo F. Padovan goto drop; 64310a708f8fSGustavo F. Padovan 6432e13e21dcSVinicius Costa Gomes if (chan->imtu < skb->len) 64330a708f8fSGustavo F. Padovan goto drop; 64340a708f8fSGustavo F. Padovan 643580b98027SGustavo Padovan if (!chan->ops->recv(chan, skb)) 643684104b24SAndrei Emeltchenko return; 64370a708f8fSGustavo F. Padovan 64380a708f8fSGustavo F. Padovan drop: 64390a708f8fSGustavo F. Padovan kfree_skb(skb); 64400a708f8fSGustavo F. Padovan } 64410a708f8fSGustavo F. Padovan 644272f78356SMarcel Holtmann static void l2cap_att_channel(struct l2cap_conn *conn, 6443d9b88702SAndrei Emeltchenko struct sk_buff *skb) 64449f69bda6SGustavo F. Padovan { 6445b99707d7SMarcel Holtmann struct hci_conn *hcon = conn->hcon; 644623691d75SGustavo F. Padovan struct l2cap_chan *chan; 64479f69bda6SGustavo F. Padovan 6448b99707d7SMarcel Holtmann if (hcon->type != LE_LINK) 6449b99707d7SMarcel Holtmann goto drop; 6450b99707d7SMarcel Holtmann 6451af1c0134SJohan Hedberg chan = l2cap_global_chan_by_scid(BT_CONNECTED, L2CAP_CID_ATT, 645272f78356SMarcel Holtmann conn->src, conn->dst); 645323691d75SGustavo F. Padovan if (!chan) 64549f69bda6SGustavo F. Padovan goto drop; 64559f69bda6SGustavo F. Padovan 64565b4cedaaSAndrei Emeltchenko BT_DBG("chan %p, len %d", chan, skb->len); 64579f69bda6SGustavo F. Padovan 6458e13e21dcSVinicius Costa Gomes if (chan->imtu < skb->len) 64599f69bda6SGustavo F. Padovan goto drop; 64609f69bda6SGustavo F. Padovan 646180b98027SGustavo Padovan if (!chan->ops->recv(chan, skb)) 64626810fca7SAndrei Emeltchenko return; 64639f69bda6SGustavo F. Padovan 64649f69bda6SGustavo F. Padovan drop: 64659f69bda6SGustavo F. Padovan kfree_skb(skb); 64669f69bda6SGustavo F. Padovan } 64679f69bda6SGustavo F. Padovan 64680a708f8fSGustavo F. Padovan static void l2cap_recv_frame(struct l2cap_conn *conn, struct sk_buff *skb) 64690a708f8fSGustavo F. Padovan { 64700a708f8fSGustavo F. Padovan struct l2cap_hdr *lh = (void *) skb->data; 64710a708f8fSGustavo F. Padovan u16 cid, len; 64720a708f8fSGustavo F. Padovan __le16 psm; 64730a708f8fSGustavo F. Padovan 64740a708f8fSGustavo F. Padovan skb_pull(skb, L2CAP_HDR_SIZE); 64750a708f8fSGustavo F. Padovan cid = __le16_to_cpu(lh->cid); 64760a708f8fSGustavo F. Padovan len = __le16_to_cpu(lh->len); 64770a708f8fSGustavo F. Padovan 64780a708f8fSGustavo F. Padovan if (len != skb->len) { 64790a708f8fSGustavo F. Padovan kfree_skb(skb); 64800a708f8fSGustavo F. Padovan return; 64810a708f8fSGustavo F. Padovan } 64820a708f8fSGustavo F. Padovan 64830a708f8fSGustavo F. Padovan BT_DBG("len %d, cid 0x%4.4x", len, cid); 64840a708f8fSGustavo F. Padovan 64850a708f8fSGustavo F. Padovan switch (cid) { 64860a708f8fSGustavo F. Padovan case L2CAP_CID_SIGNALING: 64870a708f8fSGustavo F. Padovan l2cap_sig_channel(conn, skb); 64880a708f8fSGustavo F. Padovan break; 64890a708f8fSGustavo F. Padovan 64900a708f8fSGustavo F. Padovan case L2CAP_CID_CONN_LESS: 6491097db76cSAndrei Emeltchenko psm = get_unaligned((__le16 *) skb->data); 64920181a70fSAndrei Emeltchenko skb_pull(skb, L2CAP_PSMLEN_SIZE); 64930a708f8fSGustavo F. Padovan l2cap_conless_channel(conn, psm, skb); 64940a708f8fSGustavo F. Padovan break; 64950a708f8fSGustavo F. Padovan 6496073d1cf3SJohan Hedberg case L2CAP_CID_ATT: 649772f78356SMarcel Holtmann l2cap_att_channel(conn, skb); 64989f69bda6SGustavo F. Padovan break; 64999f69bda6SGustavo F. Padovan 6500a2877629SMarcel Holtmann case L2CAP_CID_LE_SIGNALING: 6501a2877629SMarcel Holtmann l2cap_le_sig_channel(conn, skb); 6502a2877629SMarcel Holtmann break; 6503a2877629SMarcel Holtmann 6504b501d6a1SAnderson Briglia case L2CAP_CID_SMP: 6505b501d6a1SAnderson Briglia if (smp_sig_channel(conn, skb)) 6506b501d6a1SAnderson Briglia l2cap_conn_del(conn->hcon, EACCES); 6507b501d6a1SAnderson Briglia break; 6508b501d6a1SAnderson Briglia 65090a708f8fSGustavo F. Padovan default: 65100a708f8fSGustavo F. Padovan l2cap_data_channel(conn, cid, skb); 65110a708f8fSGustavo F. Padovan break; 65120a708f8fSGustavo F. Padovan } 65130a708f8fSGustavo F. Padovan } 65140a708f8fSGustavo F. Padovan 65150a708f8fSGustavo F. Padovan /* ---- L2CAP interface with lower layer (HCI) ---- */ 65160a708f8fSGustavo F. Padovan 6517686ebf28SUlisses Furquim int l2cap_connect_ind(struct hci_dev *hdev, bdaddr_t *bdaddr) 65180a708f8fSGustavo F. Padovan { 65190a708f8fSGustavo F. Padovan int exact = 0, lm1 = 0, lm2 = 0; 652023691d75SGustavo F. Padovan struct l2cap_chan *c; 65210a708f8fSGustavo F. Padovan 65226ed93dc6SAndrei Emeltchenko BT_DBG("hdev %s, bdaddr %pMR", hdev->name, bdaddr); 65230a708f8fSGustavo F. Padovan 65240a708f8fSGustavo F. Padovan /* Find listening sockets and check their link_mode */ 652523691d75SGustavo F. Padovan read_lock(&chan_list_lock); 652623691d75SGustavo F. Padovan list_for_each_entry(c, &chan_list, global_l) { 652723691d75SGustavo F. Padovan struct sock *sk = c->sk; 65284343478fSGustavo F. Padovan 652989bc500eSGustavo F. Padovan if (c->state != BT_LISTEN) 65300a708f8fSGustavo F. Padovan continue; 65310a708f8fSGustavo F. Padovan 65320a708f8fSGustavo F. Padovan if (!bacmp(&bt_sk(sk)->src, &hdev->bdaddr)) { 65330a708f8fSGustavo F. Padovan lm1 |= HCI_LM_ACCEPT; 653443bd0f32SAndrei Emeltchenko if (test_bit(FLAG_ROLE_SWITCH, &c->flags)) 65350a708f8fSGustavo F. Padovan lm1 |= HCI_LM_MASTER; 65360a708f8fSGustavo F. Padovan exact++; 65370a708f8fSGustavo F. Padovan } else if (!bacmp(&bt_sk(sk)->src, BDADDR_ANY)) { 65380a708f8fSGustavo F. Padovan lm2 |= HCI_LM_ACCEPT; 653943bd0f32SAndrei Emeltchenko if (test_bit(FLAG_ROLE_SWITCH, &c->flags)) 65400a708f8fSGustavo F. Padovan lm2 |= HCI_LM_MASTER; 65410a708f8fSGustavo F. Padovan } 65420a708f8fSGustavo F. Padovan } 654323691d75SGustavo F. Padovan read_unlock(&chan_list_lock); 65440a708f8fSGustavo F. Padovan 65450a708f8fSGustavo F. Padovan return exact ? lm1 : lm2; 65460a708f8fSGustavo F. Padovan } 65470a708f8fSGustavo F. Padovan 65489e664631SAndrei Emeltchenko void l2cap_connect_cfm(struct hci_conn *hcon, u8 status) 65490a708f8fSGustavo F. Padovan { 65500a708f8fSGustavo F. Padovan struct l2cap_conn *conn; 65510a708f8fSGustavo F. Padovan 65526ed93dc6SAndrei Emeltchenko BT_DBG("hcon %p bdaddr %pMR status %d", hcon, &hcon->dst, status); 65530a708f8fSGustavo F. Padovan 65540a708f8fSGustavo F. Padovan if (!status) { 6555baf43251SClaudio Takahasi conn = l2cap_conn_add(hcon); 65560a708f8fSGustavo F. Padovan if (conn) 65570a708f8fSGustavo F. Padovan l2cap_conn_ready(conn); 6558ba6fc317SAndrei Emeltchenko } else { 6559e175072fSJoe Perches l2cap_conn_del(hcon, bt_to_errno(status)); 6560ba6fc317SAndrei Emeltchenko } 65610a708f8fSGustavo F. Padovan } 65620a708f8fSGustavo F. Padovan 6563686ebf28SUlisses Furquim int l2cap_disconn_ind(struct hci_conn *hcon) 65640a708f8fSGustavo F. Padovan { 65650a708f8fSGustavo F. Padovan struct l2cap_conn *conn = hcon->l2cap_data; 65660a708f8fSGustavo F. Padovan 65670a708f8fSGustavo F. Padovan BT_DBG("hcon %p", hcon); 65680a708f8fSGustavo F. Padovan 6569686ebf28SUlisses Furquim if (!conn) 65709f5a0d7bSAndrei Emeltchenko return HCI_ERROR_REMOTE_USER_TERM; 65710a708f8fSGustavo F. Padovan return conn->disc_reason; 65720a708f8fSGustavo F. Padovan } 65730a708f8fSGustavo F. Padovan 65749e664631SAndrei Emeltchenko void l2cap_disconn_cfm(struct hci_conn *hcon, u8 reason) 65750a708f8fSGustavo F. Padovan { 65760a708f8fSGustavo F. Padovan BT_DBG("hcon %p reason %d", hcon, reason); 65770a708f8fSGustavo F. Padovan 6578e175072fSJoe Perches l2cap_conn_del(hcon, bt_to_errno(reason)); 65790a708f8fSGustavo F. Padovan } 65800a708f8fSGustavo F. Padovan 65814343478fSGustavo F. Padovan static inline void l2cap_check_encryption(struct l2cap_chan *chan, u8 encrypt) 65820a708f8fSGustavo F. Padovan { 6583715ec005SGustavo F. Padovan if (chan->chan_type != L2CAP_CHAN_CONN_ORIENTED) 65840a708f8fSGustavo F. Padovan return; 65850a708f8fSGustavo F. Padovan 65860a708f8fSGustavo F. Padovan if (encrypt == 0x00) { 65874343478fSGustavo F. Padovan if (chan->sec_level == BT_SECURITY_MEDIUM) { 6588ba13ccd9SMarcel Holtmann __set_chan_timer(chan, L2CAP_ENC_TIMEOUT); 65894343478fSGustavo F. Padovan } else if (chan->sec_level == BT_SECURITY_HIGH) 65900f852724SGustavo F. Padovan l2cap_chan_close(chan, ECONNREFUSED); 65910a708f8fSGustavo F. Padovan } else { 65924343478fSGustavo F. Padovan if (chan->sec_level == BT_SECURITY_MEDIUM) 6593c9b66675SGustavo F. Padovan __clear_chan_timer(chan); 65940a708f8fSGustavo F. Padovan } 65950a708f8fSGustavo F. Padovan } 65960a708f8fSGustavo F. Padovan 6597686ebf28SUlisses Furquim int l2cap_security_cfm(struct hci_conn *hcon, u8 status, u8 encrypt) 65980a708f8fSGustavo F. Padovan { 65990a708f8fSGustavo F. Padovan struct l2cap_conn *conn = hcon->l2cap_data; 660048454079SGustavo F. Padovan struct l2cap_chan *chan; 66010a708f8fSGustavo F. Padovan 66020a708f8fSGustavo F. Padovan if (!conn) 66030a708f8fSGustavo F. Padovan return 0; 66040a708f8fSGustavo F. Padovan 660589d8b407SAndrei Emeltchenko BT_DBG("conn %p status 0x%2.2x encrypt %u", conn, status, encrypt); 66060a708f8fSGustavo F. Padovan 6607160dc6acSVinicius Costa Gomes if (hcon->type == LE_LINK) { 660835d4adccSHemant Gupta if (!status && encrypt) 6609160dc6acSVinicius Costa Gomes smp_distribute_keys(conn, 0); 661017cd3f37SUlisses Furquim cancel_delayed_work(&conn->security_timer); 6611160dc6acSVinicius Costa Gomes } 6612160dc6acSVinicius Costa Gomes 66133df91ea2SAndrei Emeltchenko mutex_lock(&conn->chan_lock); 66140a708f8fSGustavo F. Padovan 66153df91ea2SAndrei Emeltchenko list_for_each_entry(chan, &conn->chan_l, list) { 66166be36555SAndrei Emeltchenko l2cap_chan_lock(chan); 66170a708f8fSGustavo F. Padovan 661889d8b407SAndrei Emeltchenko BT_DBG("chan %p scid 0x%4.4x state %s", chan, chan->scid, 661989d8b407SAndrei Emeltchenko state_to_string(chan->state)); 6620f1cb9af5SVinicius Costa Gomes 662178eb2f98SAndrei Emeltchenko if (chan->chan_type == L2CAP_CHAN_CONN_FIX_A2MP) { 662278eb2f98SAndrei Emeltchenko l2cap_chan_unlock(chan); 662378eb2f98SAndrei Emeltchenko continue; 662478eb2f98SAndrei Emeltchenko } 662578eb2f98SAndrei Emeltchenko 6626073d1cf3SJohan Hedberg if (chan->scid == L2CAP_CID_ATT) { 6627f1cb9af5SVinicius Costa Gomes if (!status && encrypt) { 6628f1cb9af5SVinicius Costa Gomes chan->sec_level = hcon->sec_level; 6629cf4cd009SAndrei Emeltchenko l2cap_chan_ready(chan); 6630f1cb9af5SVinicius Costa Gomes } 6631f1cb9af5SVinicius Costa Gomes 66326be36555SAndrei Emeltchenko l2cap_chan_unlock(chan); 6633f1cb9af5SVinicius Costa Gomes continue; 6634f1cb9af5SVinicius Costa Gomes } 6635f1cb9af5SVinicius Costa Gomes 663696eff46eSAndrei Emeltchenko if (!__l2cap_no_conn_pending(chan)) { 66376be36555SAndrei Emeltchenko l2cap_chan_unlock(chan); 66380a708f8fSGustavo F. Padovan continue; 66390a708f8fSGustavo F. Padovan } 66400a708f8fSGustavo F. Padovan 664189bc500eSGustavo F. Padovan if (!status && (chan->state == BT_CONNECTED || 664289bc500eSGustavo F. Padovan chan->state == BT_CONFIG)) { 6643a7d7723aSGustavo Padovan struct sock *sk = chan->sk; 6644a7d7723aSGustavo Padovan 6645c5daa683SGustavo Padovan clear_bit(BT_SK_SUSPEND, &bt_sk(sk)->flags); 6646a7d7723aSGustavo Padovan sk->sk_state_change(sk); 6647a7d7723aSGustavo Padovan 66484343478fSGustavo F. Padovan l2cap_check_encryption(chan, encrypt); 66496be36555SAndrei Emeltchenko l2cap_chan_unlock(chan); 66500a708f8fSGustavo F. Padovan continue; 66510a708f8fSGustavo F. Padovan } 66520a708f8fSGustavo F. Padovan 665389bc500eSGustavo F. Padovan if (chan->state == BT_CONNECT) { 66540a708f8fSGustavo F. Padovan if (!status) { 665593c3e8f5SAndrei Emeltchenko l2cap_start_connection(chan); 66560a708f8fSGustavo F. Padovan } else { 6657ba13ccd9SMarcel Holtmann __set_chan_timer(chan, L2CAP_DISC_TIMEOUT); 66580a708f8fSGustavo F. Padovan } 665989bc500eSGustavo F. Padovan } else if (chan->state == BT_CONNECT2) { 66606be36555SAndrei Emeltchenko struct sock *sk = chan->sk; 66610a708f8fSGustavo F. Padovan struct l2cap_conn_rsp rsp; 6662df3c3931SJohan Hedberg __u16 res, stat; 66630a708f8fSGustavo F. Padovan 66646be36555SAndrei Emeltchenko lock_sock(sk); 66656be36555SAndrei Emeltchenko 66660a708f8fSGustavo F. Padovan if (!status) { 6667c5daa683SGustavo Padovan if (test_bit(BT_SK_DEFER_SETUP, 6668c5daa683SGustavo Padovan &bt_sk(sk)->flags)) { 6669df3c3931SJohan Hedberg res = L2CAP_CR_PEND; 6670df3c3931SJohan Hedberg stat = L2CAP_CS_AUTHOR_PEND; 66712dc4e510SGustavo Padovan chan->ops->defer(chan); 6672df3c3931SJohan Hedberg } else { 66730e587be7SAndrei Emeltchenko __l2cap_state_change(chan, BT_CONFIG); 6674df3c3931SJohan Hedberg res = L2CAP_CR_SUCCESS; 6675df3c3931SJohan Hedberg stat = L2CAP_CS_NO_INFO; 6676df3c3931SJohan Hedberg } 66770a708f8fSGustavo F. Padovan } else { 66780e587be7SAndrei Emeltchenko __l2cap_state_change(chan, BT_DISCONN); 6679ba13ccd9SMarcel Holtmann __set_chan_timer(chan, L2CAP_DISC_TIMEOUT); 6680df3c3931SJohan Hedberg res = L2CAP_CR_SEC_BLOCK; 6681df3c3931SJohan Hedberg stat = L2CAP_CS_NO_INFO; 66820a708f8fSGustavo F. Padovan } 66830a708f8fSGustavo F. Padovan 66846be36555SAndrei Emeltchenko release_sock(sk); 66856be36555SAndrei Emeltchenko 6686fe4128e0SGustavo F. Padovan rsp.scid = cpu_to_le16(chan->dcid); 6687fe4128e0SGustavo F. Padovan rsp.dcid = cpu_to_le16(chan->scid); 6688df3c3931SJohan Hedberg rsp.result = cpu_to_le16(res); 6689df3c3931SJohan Hedberg rsp.status = cpu_to_le16(stat); 6690fc7f8a7eSGustavo F. Padovan l2cap_send_cmd(conn, chan->ident, L2CAP_CONN_RSP, 6691fc7f8a7eSGustavo F. Padovan sizeof(rsp), &rsp); 66922d369359SMat Martineau 66932d369359SMat Martineau if (!test_bit(CONF_REQ_SENT, &chan->conf_state) && 66942d369359SMat Martineau res == L2CAP_CR_SUCCESS) { 66952d369359SMat Martineau char buf[128]; 66962d369359SMat Martineau set_bit(CONF_REQ_SENT, &chan->conf_state); 66972d369359SMat Martineau l2cap_send_cmd(conn, l2cap_get_ident(conn), 66982d369359SMat Martineau L2CAP_CONF_REQ, 66992d369359SMat Martineau l2cap_build_conf_req(chan, buf), 67002d369359SMat Martineau buf); 67012d369359SMat Martineau chan->num_conf_req++; 67022d369359SMat Martineau } 67030a708f8fSGustavo F. Padovan } 67040a708f8fSGustavo F. Padovan 67056be36555SAndrei Emeltchenko l2cap_chan_unlock(chan); 67060a708f8fSGustavo F. Padovan } 67070a708f8fSGustavo F. Padovan 67083df91ea2SAndrei Emeltchenko mutex_unlock(&conn->chan_lock); 67090a708f8fSGustavo F. Padovan 67100a708f8fSGustavo F. Padovan return 0; 67110a708f8fSGustavo F. Padovan } 67120a708f8fSGustavo F. Padovan 6713686ebf28SUlisses Furquim int l2cap_recv_acldata(struct hci_conn *hcon, struct sk_buff *skb, u16 flags) 67140a708f8fSGustavo F. Padovan { 67150a708f8fSGustavo F. Padovan struct l2cap_conn *conn = hcon->l2cap_data; 6716d73a0988SAndrei Emeltchenko struct l2cap_hdr *hdr; 6717d73a0988SAndrei Emeltchenko int len; 67180a708f8fSGustavo F. Padovan 67191d13a254SAndrei Emeltchenko /* For AMP controller do not create l2cap conn */ 67201d13a254SAndrei Emeltchenko if (!conn && hcon->hdev->dev_type != HCI_BREDR) 67211d13a254SAndrei Emeltchenko goto drop; 67220a708f8fSGustavo F. Padovan 67230a708f8fSGustavo F. Padovan if (!conn) 6724baf43251SClaudio Takahasi conn = l2cap_conn_add(hcon); 67250a708f8fSGustavo F. Padovan 67260a708f8fSGustavo F. Padovan if (!conn) 67270a708f8fSGustavo F. Padovan goto drop; 67280a708f8fSGustavo F. Padovan 67290a708f8fSGustavo F. Padovan BT_DBG("conn %p len %d flags 0x%x", conn, skb->len, flags); 67300a708f8fSGustavo F. Padovan 6731d73a0988SAndrei Emeltchenko switch (flags) { 6732d73a0988SAndrei Emeltchenko case ACL_START: 6733d73a0988SAndrei Emeltchenko case ACL_START_NO_FLUSH: 6734d73a0988SAndrei Emeltchenko case ACL_COMPLETE: 67350a708f8fSGustavo F. Padovan if (conn->rx_len) { 67360a708f8fSGustavo F. Padovan BT_ERR("Unexpected start frame (len %d)", skb->len); 67370a708f8fSGustavo F. Padovan kfree_skb(conn->rx_skb); 67380a708f8fSGustavo F. Padovan conn->rx_skb = NULL; 67390a708f8fSGustavo F. Padovan conn->rx_len = 0; 67400a708f8fSGustavo F. Padovan l2cap_conn_unreliable(conn, ECOMM); 67410a708f8fSGustavo F. Padovan } 67420a708f8fSGustavo F. Padovan 67430a708f8fSGustavo F. Padovan /* Start fragment always begin with Basic L2CAP header */ 67440a708f8fSGustavo F. Padovan if (skb->len < L2CAP_HDR_SIZE) { 67450a708f8fSGustavo F. Padovan BT_ERR("Frame is too short (len %d)", skb->len); 67460a708f8fSGustavo F. Padovan l2cap_conn_unreliable(conn, ECOMM); 67470a708f8fSGustavo F. Padovan goto drop; 67480a708f8fSGustavo F. Padovan } 67490a708f8fSGustavo F. Padovan 67500a708f8fSGustavo F. Padovan hdr = (struct l2cap_hdr *) skb->data; 67510a708f8fSGustavo F. Padovan len = __le16_to_cpu(hdr->len) + L2CAP_HDR_SIZE; 67520a708f8fSGustavo F. Padovan 67530a708f8fSGustavo F. Padovan if (len == skb->len) { 67540a708f8fSGustavo F. Padovan /* Complete frame received */ 67550a708f8fSGustavo F. Padovan l2cap_recv_frame(conn, skb); 67560a708f8fSGustavo F. Padovan return 0; 67570a708f8fSGustavo F. Padovan } 67580a708f8fSGustavo F. Padovan 67590a708f8fSGustavo F. Padovan BT_DBG("Start: total len %d, frag len %d", len, skb->len); 67600a708f8fSGustavo F. Padovan 67610a708f8fSGustavo F. Padovan if (skb->len > len) { 67620a708f8fSGustavo F. Padovan BT_ERR("Frame is too long (len %d, expected len %d)", 67630a708f8fSGustavo F. Padovan skb->len, len); 67640a708f8fSGustavo F. Padovan l2cap_conn_unreliable(conn, ECOMM); 67650a708f8fSGustavo F. Padovan goto drop; 67660a708f8fSGustavo F. Padovan } 67670a708f8fSGustavo F. Padovan 67680a708f8fSGustavo F. Padovan /* Allocate skb for the complete frame (with header) */ 67698bcde1f2SGustavo Padovan conn->rx_skb = bt_skb_alloc(len, GFP_KERNEL); 67700a708f8fSGustavo F. Padovan if (!conn->rx_skb) 67710a708f8fSGustavo F. Padovan goto drop; 67720a708f8fSGustavo F. Padovan 67730a708f8fSGustavo F. Padovan skb_copy_from_linear_data(skb, skb_put(conn->rx_skb, skb->len), 67740a708f8fSGustavo F. Padovan skb->len); 67750a708f8fSGustavo F. Padovan conn->rx_len = len - skb->len; 6776d73a0988SAndrei Emeltchenko break; 6777d73a0988SAndrei Emeltchenko 6778d73a0988SAndrei Emeltchenko case ACL_CONT: 67790a708f8fSGustavo F. Padovan BT_DBG("Cont: frag len %d (expecting %d)", skb->len, conn->rx_len); 67800a708f8fSGustavo F. Padovan 67810a708f8fSGustavo F. Padovan if (!conn->rx_len) { 67820a708f8fSGustavo F. Padovan BT_ERR("Unexpected continuation frame (len %d)", skb->len); 67830a708f8fSGustavo F. Padovan l2cap_conn_unreliable(conn, ECOMM); 67840a708f8fSGustavo F. Padovan goto drop; 67850a708f8fSGustavo F. Padovan } 67860a708f8fSGustavo F. Padovan 67870a708f8fSGustavo F. Padovan if (skb->len > conn->rx_len) { 67880a708f8fSGustavo F. Padovan BT_ERR("Fragment is too long (len %d, expected %d)", 67890a708f8fSGustavo F. Padovan skb->len, conn->rx_len); 67900a708f8fSGustavo F. Padovan kfree_skb(conn->rx_skb); 67910a708f8fSGustavo F. Padovan conn->rx_skb = NULL; 67920a708f8fSGustavo F. Padovan conn->rx_len = 0; 67930a708f8fSGustavo F. Padovan l2cap_conn_unreliable(conn, ECOMM); 67940a708f8fSGustavo F. Padovan goto drop; 67950a708f8fSGustavo F. Padovan } 67960a708f8fSGustavo F. Padovan 67970a708f8fSGustavo F. Padovan skb_copy_from_linear_data(skb, skb_put(conn->rx_skb, skb->len), 67980a708f8fSGustavo F. Padovan skb->len); 67990a708f8fSGustavo F. Padovan conn->rx_len -= skb->len; 68000a708f8fSGustavo F. Padovan 68010a708f8fSGustavo F. Padovan if (!conn->rx_len) { 6802c4e5bafaSJohan Hedberg /* Complete frame received. l2cap_recv_frame 6803c4e5bafaSJohan Hedberg * takes ownership of the skb so set the global 6804c4e5bafaSJohan Hedberg * rx_skb pointer to NULL first. 6805c4e5bafaSJohan Hedberg */ 6806c4e5bafaSJohan Hedberg struct sk_buff *rx_skb = conn->rx_skb; 68070a708f8fSGustavo F. Padovan conn->rx_skb = NULL; 6808c4e5bafaSJohan Hedberg l2cap_recv_frame(conn, rx_skb); 68090a708f8fSGustavo F. Padovan } 6810d73a0988SAndrei Emeltchenko break; 68110a708f8fSGustavo F. Padovan } 68120a708f8fSGustavo F. Padovan 68130a708f8fSGustavo F. Padovan drop: 68140a708f8fSGustavo F. Padovan kfree_skb(skb); 68150a708f8fSGustavo F. Padovan return 0; 68160a708f8fSGustavo F. Padovan } 68170a708f8fSGustavo F. Padovan 68180a708f8fSGustavo F. Padovan static int l2cap_debugfs_show(struct seq_file *f, void *p) 68190a708f8fSGustavo F. Padovan { 682023691d75SGustavo F. Padovan struct l2cap_chan *c; 68210a708f8fSGustavo F. Padovan 6822333055f2SGustavo F. Padovan read_lock(&chan_list_lock); 68230a708f8fSGustavo F. Padovan 682423691d75SGustavo F. Padovan list_for_each_entry(c, &chan_list, global_l) { 682523691d75SGustavo F. Padovan struct sock *sk = c->sk; 68260a708f8fSGustavo F. Padovan 6827fcb73338SAndrei Emeltchenko seq_printf(f, "%pMR %pMR %d %d 0x%4.4x 0x%4.4x %d %d %d %d\n", 6828fcb73338SAndrei Emeltchenko &bt_sk(sk)->src, &bt_sk(sk)->dst, 682989bc500eSGustavo F. Padovan c->state, __le16_to_cpu(c->psm), 683023691d75SGustavo F. Padovan c->scid, c->dcid, c->imtu, c->omtu, 683123691d75SGustavo F. Padovan c->sec_level, c->mode); 68320a708f8fSGustavo F. Padovan } 68330a708f8fSGustavo F. Padovan 6834333055f2SGustavo F. Padovan read_unlock(&chan_list_lock); 68350a708f8fSGustavo F. Padovan 68360a708f8fSGustavo F. Padovan return 0; 68370a708f8fSGustavo F. Padovan } 68380a708f8fSGustavo F. Padovan 68390a708f8fSGustavo F. Padovan static int l2cap_debugfs_open(struct inode *inode, struct file *file) 68400a708f8fSGustavo F. Padovan { 68410a708f8fSGustavo F. Padovan return single_open(file, l2cap_debugfs_show, inode->i_private); 68420a708f8fSGustavo F. Padovan } 68430a708f8fSGustavo F. Padovan 68440a708f8fSGustavo F. Padovan static const struct file_operations l2cap_debugfs_fops = { 68450a708f8fSGustavo F. Padovan .open = l2cap_debugfs_open, 68460a708f8fSGustavo F. Padovan .read = seq_read, 68470a708f8fSGustavo F. Padovan .llseek = seq_lseek, 68480a708f8fSGustavo F. Padovan .release = single_release, 68490a708f8fSGustavo F. Padovan }; 68500a708f8fSGustavo F. Padovan 68510a708f8fSGustavo F. Padovan static struct dentry *l2cap_debugfs; 68520a708f8fSGustavo F. Padovan 685364274518SGustavo F. Padovan int __init l2cap_init(void) 68540a708f8fSGustavo F. Padovan { 68550a708f8fSGustavo F. Padovan int err; 68560a708f8fSGustavo F. Padovan 6857bb58f747SGustavo F. Padovan err = l2cap_init_sockets(); 68580a708f8fSGustavo F. Padovan if (err < 0) 68590a708f8fSGustavo F. Padovan return err; 68600a708f8fSGustavo F. Padovan 68610a708f8fSGustavo F. Padovan if (bt_debugfs) { 68622d792818SGustavo Padovan l2cap_debugfs = debugfs_create_file("l2cap", 0444, bt_debugfs, 68632d792818SGustavo Padovan NULL, &l2cap_debugfs_fops); 68640a708f8fSGustavo F. Padovan if (!l2cap_debugfs) 68650a708f8fSGustavo F. Padovan BT_ERR("Failed to create L2CAP debug file"); 68660a708f8fSGustavo F. Padovan } 68670a708f8fSGustavo F. Padovan 68680a708f8fSGustavo F. Padovan return 0; 68690a708f8fSGustavo F. Padovan } 68700a708f8fSGustavo F. Padovan 687164274518SGustavo F. Padovan void l2cap_exit(void) 68720a708f8fSGustavo F. Padovan { 68730a708f8fSGustavo F. Padovan debugfs_remove(l2cap_debugfs); 6874bb58f747SGustavo F. Padovan l2cap_cleanup_sockets(); 68750a708f8fSGustavo F. Padovan } 68760a708f8fSGustavo F. Padovan 68770a708f8fSGustavo F. Padovan module_param(disable_ertm, bool, 0644); 68780a708f8fSGustavo F. Padovan MODULE_PARM_DESC(disable_ertm, "Disable enhanced retransmission mode"); 6879