nfc: Fix the sockaddr length sanitization in llcp_sock_connect
[GitHub/LineageOS/android_kernel_motorola_exynos9610.git] / net / nfc / llcp_sock.c
CommitLineData
d646960f
SO
1/*
2 * Copyright (C) 2011 Intel Corporation. All rights reserved.
3 *
4 * This program is free software; you can redistribute it and/or modify
5 * it under the terms of the GNU General Public License as published by
6 * the Free Software Foundation; either version 2 of the License, or
7 * (at your option) any later version.
8 *
9 * This program is distributed in the hope that it will be useful,
10 * but WITHOUT ANY WARRANTY; without even the implied warranty of
11 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
12 * GNU General Public License for more details.
13 *
14 * You should have received a copy of the GNU General Public License
98b32dec 15 * along with this program; if not, see <http://www.gnu.org/licenses/>.
d646960f
SO
16 */
17
18#define pr_fmt(fmt) "llcp: %s: " fmt, __func__
19
20#include <linux/init.h>
21#include <linux/kernel.h>
22#include <linux/module.h>
23#include <linux/nfc.h>
174cd4b1 24#include <linux/sched/signal.h>
d646960f 25
30cc4587 26#include "nfc.h"
d646960f
SO
27#include "llcp.h"
28
ff353d86
SO
29static int sock_wait_state(struct sock *sk, int state, unsigned long timeo)
30{
31 DECLARE_WAITQUEUE(wait, current);
32 int err = 0;
33
34 pr_debug("sk %p", sk);
35
36 add_wait_queue(sk_sleep(sk), &wait);
37 set_current_state(TASK_INTERRUPTIBLE);
38
39 while (sk->sk_state != state) {
40 if (!timeo) {
41 err = -EINPROGRESS;
42 break;
43 }
44
45 if (signal_pending(current)) {
46 err = sock_intr_errno(timeo);
47 break;
48 }
49
50 release_sock(sk);
51 timeo = schedule_timeout(timeo);
52 lock_sock(sk);
53 set_current_state(TASK_INTERRUPTIBLE);
54
55 err = sock_error(sk);
56 if (err)
57 break;
58 }
59
60 __set_current_state(TASK_RUNNING);
61 remove_wait_queue(sk_sleep(sk), &wait);
62 return err;
63}
64
d646960f
SO
65static struct proto llcp_sock_proto = {
66 .name = "NFC_LLCP",
67 .owner = THIS_MODULE,
68 .obj_size = sizeof(struct nfc_llcp_sock),
69};
70
71static int llcp_sock_bind(struct socket *sock, struct sockaddr *addr, int alen)
72{
73 struct sock *sk = sock->sk;
74 struct nfc_llcp_sock *llcp_sock = nfc_llcp_sock(sk);
75 struct nfc_llcp_local *local;
76 struct nfc_dev *dev;
77 struct sockaddr_nfc_llcp llcp_addr;
78 int len, ret = 0;
79
d646960f
SO
80 if (!addr || addr->sa_family != AF_NFC)
81 return -EINVAL;
82
c66433dc
SO
83 pr_debug("sk %p addr %p family %d\n", sk, addr, addr->sa_family);
84
d646960f
SO
85 memset(&llcp_addr, 0, sizeof(llcp_addr));
86 len = min_t(unsigned int, sizeof(llcp_addr), alen);
87 memcpy(&llcp_addr, addr, len);
88
89 /* This is going to be a listening socket, dsap must be 0 */
90 if (llcp_addr.dsap != 0)
91 return -EINVAL;
92
93 lock_sock(sk);
94
95 if (sk->sk_state != LLCP_CLOSED) {
96 ret = -EBADFD;
97 goto error;
98 }
99
100 dev = nfc_get_device(llcp_addr.dev_idx);
101 if (dev == NULL) {
102 ret = -ENODEV;
103 goto error;
104 }
105
106 local = nfc_llcp_find_local(dev);
107 if (local == NULL) {
108 ret = -ENODEV;
109 goto put_dev;
110 }
111
112 llcp_sock->dev = dev;
c7aa1225 113 llcp_sock->local = nfc_llcp_local_get(local);
d646960f
SO
114 llcp_sock->nfc_protocol = llcp_addr.nfc_protocol;
115 llcp_sock->service_name_len = min_t(unsigned int,
427a2eb1
SO
116 llcp_addr.service_name_len,
117 NFC_LLCP_MAX_SERVICE_NAME);
d646960f 118 llcp_sock->service_name = kmemdup(llcp_addr.service_name,
427a2eb1
SO
119 llcp_sock->service_name_len,
120 GFP_KERNEL);
d646960f
SO
121
122 llcp_sock->ssap = nfc_llcp_get_sdp_ssap(local, llcp_sock);
8b7e8eda
SO
123 if (llcp_sock->ssap == LLCP_SAP_MAX) {
124 ret = -EADDRINUSE;
d646960f 125 goto put_dev;
8b7e8eda 126 }
d646960f 127
cbbf4721
SO
128 llcp_sock->reserved_ssap = llcp_sock->ssap;
129
a69f32af 130 nfc_llcp_sock_link(&local->sockets, sk);
d646960f
SO
131
132 pr_debug("Socket bound to SAP %d\n", llcp_sock->ssap);
133
134 sk->sk_state = LLCP_BOUND;
135
136put_dev:
137 nfc_put_device(dev);
138
139error:
140 release_sock(sk);
141 return ret;
142}
143
4463523b
TE
144static int llcp_raw_sock_bind(struct socket *sock, struct sockaddr *addr,
145 int alen)
146{
147 struct sock *sk = sock->sk;
148 struct nfc_llcp_sock *llcp_sock = nfc_llcp_sock(sk);
149 struct nfc_llcp_local *local;
150 struct nfc_dev *dev;
151 struct sockaddr_nfc_llcp llcp_addr;
152 int len, ret = 0;
153
154 if (!addr || addr->sa_family != AF_NFC)
155 return -EINVAL;
156
157 pr_debug("sk %p addr %p family %d\n", sk, addr, addr->sa_family);
158
159 memset(&llcp_addr, 0, sizeof(llcp_addr));
160 len = min_t(unsigned int, sizeof(llcp_addr), alen);
161 memcpy(&llcp_addr, addr, len);
162
163 lock_sock(sk);
164
165 if (sk->sk_state != LLCP_CLOSED) {
166 ret = -EBADFD;
167 goto error;
168 }
169
170 dev = nfc_get_device(llcp_addr.dev_idx);
171 if (dev == NULL) {
172 ret = -ENODEV;
173 goto error;
174 }
175
176 local = nfc_llcp_find_local(dev);
177 if (local == NULL) {
178 ret = -ENODEV;
179 goto put_dev;
180 }
181
182 llcp_sock->dev = dev;
183 llcp_sock->local = nfc_llcp_local_get(local);
184 llcp_sock->nfc_protocol = llcp_addr.nfc_protocol;
185
186 nfc_llcp_sock_link(&local->raw_sockets, sk);
187
188 sk->sk_state = LLCP_BOUND;
189
190put_dev:
191 nfc_put_device(dev);
192
193error:
194 release_sock(sk);
195 return ret;
196}
197
d646960f
SO
198static int llcp_sock_listen(struct socket *sock, int backlog)
199{
200 struct sock *sk = sock->sk;
201 int ret = 0;
202
203 pr_debug("sk %p backlog %d\n", sk, backlog);
204
205 lock_sock(sk);
206
874934f4
SJ
207 if ((sock->type != SOCK_SEQPACKET && sock->type != SOCK_STREAM) ||
208 sk->sk_state != LLCP_BOUND) {
d646960f
SO
209 ret = -EBADFD;
210 goto error;
211 }
212
213 sk->sk_max_ack_backlog = backlog;
214 sk->sk_ack_backlog = 0;
215
216 pr_debug("Socket listening\n");
217 sk->sk_state = LLCP_LISTEN;
218
219error:
220 release_sock(sk);
221
222 return ret;
223}
224
26fd76ca
SO
225static int nfc_llcp_setsockopt(struct socket *sock, int level, int optname,
226 char __user *optval, unsigned int optlen)
227{
228 struct sock *sk = sock->sk;
229 struct nfc_llcp_sock *llcp_sock = nfc_llcp_sock(sk);
230 u32 opt;
231 int err = 0;
232
233 pr_debug("%p optname %d\n", sk, optname);
234
235 if (level != SOL_NFC)
236 return -ENOPROTOOPT;
237
238 lock_sock(sk);
239
240 switch (optname) {
241 case NFC_LLCP_RW:
242 if (sk->sk_state == LLCP_CONNECTED ||
243 sk->sk_state == LLCP_BOUND ||
244 sk->sk_state == LLCP_LISTEN) {
245 err = -EINVAL;
246 break;
247 }
248
249 if (get_user(opt, (u32 __user *) optval)) {
250 err = -EFAULT;
251 break;
252 }
253
254 if (opt > LLCP_MAX_RW) {
255 err = -EINVAL;
256 break;
257 }
258
259 llcp_sock->rw = (u8) opt;
260
261 break;
262
263 case NFC_LLCP_MIUX:
264 if (sk->sk_state == LLCP_CONNECTED ||
265 sk->sk_state == LLCP_BOUND ||
266 sk->sk_state == LLCP_LISTEN) {
267 err = -EINVAL;
268 break;
269 }
270
271 if (get_user(opt, (u32 __user *) optval)) {
272 err = -EFAULT;
273 break;
274 }
275
276 if (opt > LLCP_MAX_MIUX) {
277 err = -EINVAL;
278 break;
279 }
280
5eef6669 281 llcp_sock->miux = cpu_to_be16((u16) opt);
26fd76ca
SO
282
283 break;
284
285 default:
286 err = -ENOPROTOOPT;
287 break;
288 }
289
290 release_sock(sk);
291
06d44f80
SO
292 pr_debug("%p rw %d miux %d\n", llcp_sock,
293 llcp_sock->rw, llcp_sock->miux);
294
26fd76ca
SO
295 return err;
296}
297
298static int nfc_llcp_getsockopt(struct socket *sock, int level, int optname,
299 char __user *optval, int __user *optlen)
300{
00e856db 301 struct nfc_llcp_local *local;
26fd76ca
SO
302 struct sock *sk = sock->sk;
303 struct nfc_llcp_sock *llcp_sock = nfc_llcp_sock(sk);
304 int len, err = 0;
064f370c 305 u16 miux, remote_miu;
00e856db 306 u8 rw;
26fd76ca
SO
307
308 pr_debug("%p optname %d\n", sk, optname);
309
310 if (level != SOL_NFC)
311 return -ENOPROTOOPT;
312
313 if (get_user(len, optlen))
314 return -EFAULT;
315
00e856db
SO
316 local = llcp_sock->local;
317 if (!local)
318 return -ENODEV;
319
26fd76ca
SO
320 len = min_t(u32, len, sizeof(u32));
321
322 lock_sock(sk);
323
324 switch (optname) {
325 case NFC_LLCP_RW:
00e856db
SO
326 rw = llcp_sock->rw > LLCP_MAX_RW ? local->rw : llcp_sock->rw;
327 if (put_user(rw, (u32 __user *) optval))
26fd76ca
SO
328 err = -EFAULT;
329
330 break;
331
332 case NFC_LLCP_MIUX:
00e856db
SO
333 miux = be16_to_cpu(llcp_sock->miux) > LLCP_MAX_MIUX ?
334 be16_to_cpu(local->miux) : be16_to_cpu(llcp_sock->miux);
335
336 if (put_user(miux, (u32 __user *) optval))
26fd76ca
SO
337 err = -EFAULT;
338
339 break;
340
064f370c
TE
341 case NFC_LLCP_REMOTE_MIU:
342 remote_miu = llcp_sock->remote_miu > LLCP_MAX_MIU ?
343 local->remote_miu : llcp_sock->remote_miu;
344
345 if (put_user(remote_miu, (u32 __user *) optval))
346 err = -EFAULT;
347
348 break;
349
350 case NFC_LLCP_REMOTE_LTO:
351 if (put_user(local->remote_lto / 10, (u32 __user *) optval))
352 err = -EFAULT;
353
354 break;
355
356 case NFC_LLCP_REMOTE_RW:
357 if (put_user(llcp_sock->remote_rw, (u32 __user *) optval))
26fd76ca
SO
358 err = -EFAULT;
359
360 break;
361
362 default:
363 err = -ENOPROTOOPT;
364 break;
365 }
366
367 release_sock(sk);
368
369 if (put_user(len, optlen))
370 return -EFAULT;
371
372 return err;
373}
374
d646960f
SO
375void nfc_llcp_accept_unlink(struct sock *sk)
376{
377 struct nfc_llcp_sock *llcp_sock = nfc_llcp_sock(sk);
378
379 pr_debug("state %d\n", sk->sk_state);
380
381 list_del_init(&llcp_sock->accept_queue);
382 sk_acceptq_removed(llcp_sock->parent);
383 llcp_sock->parent = NULL;
384
385 sock_put(sk);
386}
387
388void nfc_llcp_accept_enqueue(struct sock *parent, struct sock *sk)
389{
390 struct nfc_llcp_sock *llcp_sock = nfc_llcp_sock(sk);
391 struct nfc_llcp_sock *llcp_sock_parent = nfc_llcp_sock(parent);
392
393 /* Lock will be free from unlink */
394 sock_hold(sk);
395
396 list_add_tail(&llcp_sock->accept_queue,
427a2eb1 397 &llcp_sock_parent->accept_queue);
d646960f
SO
398 llcp_sock->parent = parent;
399 sk_acceptq_added(parent);
400}
401
402struct sock *nfc_llcp_accept_dequeue(struct sock *parent,
427a2eb1 403 struct socket *newsock)
d646960f
SO
404{
405 struct nfc_llcp_sock *lsk, *n, *llcp_parent;
406 struct sock *sk;
407
408 llcp_parent = nfc_llcp_sock(parent);
409
410 list_for_each_entry_safe(lsk, n, &llcp_parent->accept_queue,
427a2eb1 411 accept_queue) {
d646960f
SO
412 sk = &lsk->sk;
413 lock_sock(sk);
414
415 if (sk->sk_state == LLCP_CLOSED) {
416 release_sock(sk);
417 nfc_llcp_accept_unlink(sk);
418 continue;
419 }
420
421 if (sk->sk_state == LLCP_CONNECTED || !newsock) {
39a352a5
SO
422 list_del_init(&lsk->accept_queue);
423 sock_put(sk);
424
d646960f
SO
425 if (newsock)
426 sock_graft(sk, newsock);
427
428 release_sock(sk);
429
430 pr_debug("Returning sk state %d\n", sk->sk_state);
431
b141e811
SO
432 sk_acceptq_removed(parent);
433
d646960f
SO
434 return sk;
435 }
436
437 release_sock(sk);
438 }
439
440 return NULL;
441}
442
443static int llcp_sock_accept(struct socket *sock, struct socket *newsock,
cdfbabfb 444 int flags, bool kern)
d646960f
SO
445{
446 DECLARE_WAITQUEUE(wait, current);
447 struct sock *sk = sock->sk, *new_sk;
448 long timeo;
449 int ret = 0;
450
451 pr_debug("parent %p\n", sk);
452
453 lock_sock_nested(sk, SINGLE_DEPTH_NESTING);
454
455 if (sk->sk_state != LLCP_LISTEN) {
456 ret = -EBADFD;
457 goto error;
458 }
459
460 timeo = sock_rcvtimeo(sk, flags & O_NONBLOCK);
461
462 /* Wait for an incoming connection. */
463 add_wait_queue_exclusive(sk_sleep(sk), &wait);
464 while (!(new_sk = nfc_llcp_accept_dequeue(sk, newsock))) {
465 set_current_state(TASK_INTERRUPTIBLE);
466
467 if (!timeo) {
468 ret = -EAGAIN;
469 break;
470 }
471
472 if (signal_pending(current)) {
473 ret = sock_intr_errno(timeo);
474 break;
475 }
476
477 release_sock(sk);
478 timeo = schedule_timeout(timeo);
479 lock_sock_nested(sk, SINGLE_DEPTH_NESTING);
480 }
481 __set_current_state(TASK_RUNNING);
482 remove_wait_queue(sk_sleep(sk), &wait);
483
484 if (ret)
485 goto error;
486
487 newsock->state = SS_CONNECTED;
488
489 pr_debug("new socket %p\n", new_sk);
490
491error:
492 release_sock(sk);
493
494 return ret;
495}
496
12e5bdfe 497static int llcp_sock_getname(struct socket *sock, struct sockaddr *uaddr,
d646960f
SO
498 int *len, int peer)
499{
d646960f
SO
500 struct sock *sk = sock->sk;
501 struct nfc_llcp_sock *llcp_sock = nfc_llcp_sock(sk);
12e5bdfe 502 DECLARE_SOCKADDR(struct sockaddr_nfc_llcp *, llcp_addr, uaddr);
d646960f 503
fe3c094a
SO
504 if (llcp_sock == NULL || llcp_sock->dev == NULL)
505 return -EBADFD;
506
12e5bdfe
SO
507 pr_debug("%p %d %d %d\n", sk, llcp_sock->target_idx,
508 llcp_sock->dsap, llcp_sock->ssap);
d646960f 509
5ffedc6e 510 memset(llcp_addr, 0, sizeof(*llcp_addr));
d646960f
SO
511 *len = sizeof(struct sockaddr_nfc_llcp);
512
03c05355
CW
513 lock_sock(sk);
514 if (!llcp_sock->dev) {
515 release_sock(sk);
516 return -EBADFD;
517 }
5ffedc6e 518 llcp_addr->sa_family = AF_NFC;
d646960f 519 llcp_addr->dev_idx = llcp_sock->dev->idx;
12e5bdfe 520 llcp_addr->target_idx = llcp_sock->target_idx;
5ffedc6e 521 llcp_addr->nfc_protocol = llcp_sock->nfc_protocol;
d646960f
SO
522 llcp_addr->dsap = llcp_sock->dsap;
523 llcp_addr->ssap = llcp_sock->ssap;
524 llcp_addr->service_name_len = llcp_sock->service_name_len;
525 memcpy(llcp_addr->service_name, llcp_sock->service_name,
427a2eb1 526 llcp_addr->service_name_len);
03c05355 527 release_sock(sk);
d646960f
SO
528
529 return 0;
530}
531
532static inline unsigned int llcp_accept_poll(struct sock *parent)
533{
413df10b 534 struct nfc_llcp_sock *llcp_sock, *parent_sock;
d646960f
SO
535 struct sock *sk;
536
537 parent_sock = nfc_llcp_sock(parent);
538
413df10b
AL
539 list_for_each_entry(llcp_sock, &parent_sock->accept_queue,
540 accept_queue) {
d646960f
SO
541 sk = &llcp_sock->sk;
542
543 if (sk->sk_state == LLCP_CONNECTED)
544 return POLLIN | POLLRDNORM;
545 }
546
547 return 0;
548}
549
550static unsigned int llcp_sock_poll(struct file *file, struct socket *sock,
427a2eb1 551 poll_table *wait)
d646960f
SO
552{
553 struct sock *sk = sock->sk;
554 unsigned int mask = 0;
555
556 pr_debug("%p\n", sk);
557
558 sock_poll_wait(file, sk_sleep(sk), wait);
559
560 if (sk->sk_state == LLCP_LISTEN)
561 return llcp_accept_poll(sk);
562
563 if (sk->sk_err || !skb_queue_empty(&sk->sk_error_queue))
7d4c04fc 564 mask |= POLLERR |
8facd5fb 565 (sock_flag(sk, SOCK_SELECT_ERR_QUEUE) ? POLLPRI : 0);
d646960f
SO
566
567 if (!skb_queue_empty(&sk->sk_receive_queue))
4260c13b 568 mask |= POLLIN | POLLRDNORM;
d646960f
SO
569
570 if (sk->sk_state == LLCP_CLOSED)
571 mask |= POLLHUP;
572
4260c13b
SO
573 if (sk->sk_shutdown & RCV_SHUTDOWN)
574 mask |= POLLRDHUP | POLLIN | POLLRDNORM;
575
576 if (sk->sk_shutdown == SHUTDOWN_MASK)
577 mask |= POLLHUP;
578
b4011239 579 if (sock_writeable(sk) && sk->sk_state == LLCP_CONNECTED)
4260c13b
SO
580 mask |= POLLOUT | POLLWRNORM | POLLWRBAND;
581 else
9cd3e072 582 sk_set_bit(SOCKWQ_ASYNC_NOSPACE, sk);
4260c13b
SO
583
584 pr_debug("mask 0x%x\n", mask);
585
d646960f
SO
586 return mask;
587}
588
589static int llcp_sock_release(struct socket *sock)
590{
591 struct sock *sk = sock->sk;
592 struct nfc_llcp_local *local;
593 struct nfc_llcp_sock *llcp_sock = nfc_llcp_sock(sk);
40c75f81 594 int err = 0;
d646960f
SO
595
596 if (!sk)
597 return 0;
598
599 pr_debug("%p\n", sk);
600
601 local = llcp_sock->local;
40c75f81
SO
602 if (local == NULL) {
603 err = -ENODEV;
604 goto out;
605 }
d646960f 606
d646960f
SO
607 lock_sock(sk);
608
609 /* Send a DISC */
610 if (sk->sk_state == LLCP_CONNECTED)
58e3dd15 611 nfc_llcp_send_disconnect(llcp_sock);
d646960f
SO
612
613 if (sk->sk_state == LLCP_LISTEN) {
614 struct nfc_llcp_sock *lsk, *n;
615 struct sock *accept_sk;
616
617 list_for_each_entry_safe(lsk, n, &llcp_sock->accept_queue,
427a2eb1 618 accept_queue) {
d646960f
SO
619 accept_sk = &lsk->sk;
620 lock_sock(accept_sk);
621
58e3dd15 622 nfc_llcp_send_disconnect(lsk);
d646960f
SO
623 nfc_llcp_accept_unlink(accept_sk);
624
625 release_sock(accept_sk);
d646960f
SO
626 }
627 }
628
cbbf4721
SO
629 if (llcp_sock->reserved_ssap < LLCP_SAP_MAX)
630 nfc_llcp_put_ssap(llcp_sock->local, llcp_sock->ssap);
d646960f 631
d646960f
SO
632 release_sock(sk);
633
17f7ae16
TE
634 /* Keep this sock alive and therefore do not remove it from the sockets
635 * list until the DISC PDU has been actually sent. Otherwise we would
636 * reply with DM PDUs before sending the DISC one.
637 */
638 if (sk->sk_state == LLCP_DISCONNECTING)
639 return err;
640
4463523b
TE
641 if (sock->type == SOCK_RAW)
642 nfc_llcp_sock_unlink(&local->raw_sockets, sk);
643 else
644 nfc_llcp_sock_unlink(&local->sockets, sk);
a69f32af 645
40c75f81 646out:
d646960f
SO
647 sock_orphan(sk);
648 sock_put(sk);
649
40c75f81 650 return err;
d646960f
SO
651}
652
653static int llcp_sock_connect(struct socket *sock, struct sockaddr *_addr,
427a2eb1 654 int len, int flags)
d646960f
SO
655{
656 struct sock *sk = sock->sk;
657 struct nfc_llcp_sock *llcp_sock = nfc_llcp_sock(sk);
658 struct sockaddr_nfc_llcp *addr = (struct sockaddr_nfc_llcp *)_addr;
659 struct nfc_dev *dev;
660 struct nfc_llcp_local *local;
661 int ret = 0;
662
663 pr_debug("sock %p sk %p flags 0x%x\n", sock, sk, flags);
664
608c4adf 665 if (!addr || len < sizeof(*addr) || addr->sa_family != AF_NFC)
d646960f 666 return -EINVAL;
d646960f 667
32418cfe 668 if (addr->service_name_len == 0 && addr->dsap == 0)
d646960f 669 return -EINVAL;
d646960f
SO
670
671 pr_debug("addr dev_idx=%u target_idx=%u protocol=%u\n", addr->dev_idx,
427a2eb1 672 addr->target_idx, addr->nfc_protocol);
d646960f
SO
673
674 lock_sock(sk);
675
676 if (sk->sk_state == LLCP_CONNECTED) {
677 ret = -EISCONN;
678 goto error;
679 }
680
681 dev = nfc_get_device(addr->dev_idx);
682 if (dev == NULL) {
683 ret = -ENODEV;
684 goto error;
685 }
686
687 local = nfc_llcp_find_local(dev);
688 if (local == NULL) {
689 ret = -ENODEV;
690 goto put_dev;
691 }
692
693 device_lock(&dev->dev);
694 if (dev->dep_link_up == false) {
695 ret = -ENOLINK;
696 device_unlock(&dev->dev);
697 goto put_dev;
698 }
699 device_unlock(&dev->dev);
700
701 if (local->rf_mode == NFC_RF_INITIATOR &&
427a2eb1 702 addr->target_idx != local->target_idx) {
d646960f
SO
703 ret = -ENOLINK;
704 goto put_dev;
705 }
706
707 llcp_sock->dev = dev;
c7aa1225 708 llcp_sock->local = nfc_llcp_local_get(local);
d646960f
SO
709 llcp_sock->ssap = nfc_llcp_get_local_ssap(local);
710 if (llcp_sock->ssap == LLCP_SAP_MAX) {
711 ret = -ENOMEM;
712 goto put_dev;
713 }
cbbf4721
SO
714
715 llcp_sock->reserved_ssap = llcp_sock->ssap;
716
d646960f
SO
717 if (addr->service_name_len == 0)
718 llcp_sock->dsap = addr->dsap;
719 else
720 llcp_sock->dsap = LLCP_SAP_SDP;
721 llcp_sock->nfc_protocol = addr->nfc_protocol;
722 llcp_sock->service_name_len = min_t(unsigned int,
427a2eb1
SO
723 addr->service_name_len,
724 NFC_LLCP_MAX_SERVICE_NAME);
d646960f 725 llcp_sock->service_name = kmemdup(addr->service_name,
427a2eb1
SO
726 llcp_sock->service_name_len,
727 GFP_KERNEL);
d646960f 728
a69f32af 729 nfc_llcp_sock_link(&local->connecting_sockets, sk);
d646960f
SO
730
731 ret = nfc_llcp_send_connect(llcp_sock);
732 if (ret)
a69f32af 733 goto sock_unlink;
d646960f 734
b4011239
SO
735 sk->sk_state = LLCP_CONNECTING;
736
ff353d86
SO
737 ret = sock_wait_state(sk, LLCP_CONNECTED,
738 sock_sndtimeo(sk, flags & O_NONBLOCK));
b4011239 739 if (ret && ret != -EINPROGRESS)
a69f32af 740 goto sock_unlink;
d646960f
SO
741
742 release_sock(sk);
ff353d86 743
b4011239 744 return ret;
d646960f 745
a69f32af
SO
746sock_unlink:
747 nfc_llcp_put_ssap(local, llcp_sock->ssap);
748
749 nfc_llcp_sock_unlink(&local->connecting_sockets, sk);
750
d646960f
SO
751put_dev:
752 nfc_put_device(dev);
753
754error:
755 release_sock(sk);
756 return ret;
757}
758
1b784140
YX
759static int llcp_sock_sendmsg(struct socket *sock, struct msghdr *msg,
760 size_t len)
53a0ac2e
SO
761{
762 struct sock *sk = sock->sk;
763 struct nfc_llcp_sock *llcp_sock = nfc_llcp_sock(sk);
764 int ret;
765
766 pr_debug("sock %p sk %p", sock, sk);
767
768 ret = sock_error(sk);
769 if (ret)
770 return ret;
771
772 if (msg->msg_flags & MSG_OOB)
773 return -EOPNOTSUPP;
774
775 lock_sock(sk);
776
b874dec2 777 if (sk->sk_type == SOCK_DGRAM) {
342dfc30
SH
778 DECLARE_SOCKADDR(struct sockaddr_nfc_llcp *, addr,
779 msg->msg_name);
b874dec2
SO
780
781 if (msg->msg_namelen < sizeof(*addr)) {
782 release_sock(sk);
b874dec2
SO
783 return -EINVAL;
784 }
785
786 release_sock(sk);
787
788 return nfc_llcp_send_ui_frame(llcp_sock, addr->dsap, addr->ssap,
789 msg, len);
790 }
791
53a0ac2e
SO
792 if (sk->sk_state != LLCP_CONNECTED) {
793 release_sock(sk);
794 return -ENOTCONN;
795 }
796
797 release_sock(sk);
798
799 return nfc_llcp_send_i_frame(llcp_sock, msg, len);
800}
801
1b784140
YX
802static int llcp_sock_recvmsg(struct socket *sock, struct msghdr *msg,
803 size_t len, int flags)
d646960f
SO
804{
805 int noblock = flags & MSG_DONTWAIT;
806 struct sock *sk = sock->sk;
807 unsigned int copied, rlen;
808 struct sk_buff *skb, *cskb;
809 int err = 0;
810
811 pr_debug("%p %zu\n", sk, len);
812
813 lock_sock(sk);
814
815 if (sk->sk_state == LLCP_CLOSED &&
427a2eb1 816 skb_queue_empty(&sk->sk_receive_queue)) {
d646960f
SO
817 release_sock(sk);
818 return 0;
819 }
820
821 release_sock(sk);
822
823 if (flags & (MSG_OOB))
824 return -EOPNOTSUPP;
825
826 skb = skb_recv_datagram(sk, flags, noblock, &err);
827 if (!skb) {
828 pr_err("Recv datagram failed state %d %d %d",
427a2eb1 829 sk->sk_state, err, sock_error(sk));
d646960f
SO
830
831 if (sk->sk_shutdown & RCV_SHUTDOWN)
832 return 0;
833
834 return err;
835 }
836
427a2eb1 837 rlen = skb->len; /* real length of skb */
d646960f
SO
838 copied = min_t(unsigned int, rlen, len);
839
840 cskb = skb;
51f3d02b 841 if (skb_copy_datagram_msg(cskb, 0, msg, copied)) {
d646960f
SO
842 if (!(flags & MSG_PEEK))
843 skb_queue_head(&sk->sk_receive_queue, skb);
844 return -EFAULT;
845 }
846
2c2d45bd
TE
847 sock_recv_timestamp(msg, sk, skb);
848
31ca61a8
SO
849 if (sk->sk_type == SOCK_DGRAM && msg->msg_name) {
850 struct nfc_llcp_ui_cb *ui_cb = nfc_llcp_ui_skb_cb(skb);
342dfc30
SH
851 DECLARE_SOCKADDR(struct sockaddr_nfc_llcp *, sockaddr,
852 msg->msg_name);
31ca61a8 853
fad2e371 854 msg->msg_namelen = sizeof(struct sockaddr_nfc_llcp);
31ca61a8 855
fad2e371 856 pr_debug("Datagram socket %d %d\n", ui_cb->dsap, ui_cb->ssap);
31ca61a8 857
d26d6504 858 memset(sockaddr, 0, sizeof(*sockaddr));
fad2e371
SO
859 sockaddr->sa_family = AF_NFC;
860 sockaddr->nfc_protocol = NFC_PROTO_NFC_DEP;
861 sockaddr->dsap = ui_cb->dsap;
862 sockaddr->ssap = ui_cb->ssap;
31ca61a8
SO
863 }
864
d646960f
SO
865 /* Mark read part of skb as used */
866 if (!(flags & MSG_PEEK)) {
867
868 /* SOCK_STREAM: re-queue skb if it contains unreceived data */
31ca61a8
SO
869 if (sk->sk_type == SOCK_STREAM ||
870 sk->sk_type == SOCK_DGRAM ||
871 sk->sk_type == SOCK_RAW) {
d646960f
SO
872 skb_pull(skb, copied);
873 if (skb->len) {
874 skb_queue_head(&sk->sk_receive_queue, skb);
875 goto done;
876 }
877 }
878
879 kfree_skb(skb);
880 }
881
882 /* XXX Queue backlogged skbs */
883
884done:
885 /* SOCK_SEQPACKET: return real length if MSG_TRUNC is set */
886 if (sk->sk_type == SOCK_SEQPACKET && (flags & MSG_TRUNC))
887 copied = rlen;
888
889 return copied;
890}
891
892static const struct proto_ops llcp_sock_ops = {
893 .family = PF_NFC,
894 .owner = THIS_MODULE,
895 .bind = llcp_sock_bind,
896 .connect = llcp_sock_connect,
897 .release = llcp_sock_release,
898 .socketpair = sock_no_socketpair,
899 .accept = llcp_sock_accept,
900 .getname = llcp_sock_getname,
901 .poll = llcp_sock_poll,
902 .ioctl = sock_no_ioctl,
903 .listen = llcp_sock_listen,
904 .shutdown = sock_no_shutdown,
26fd76ca
SO
905 .setsockopt = nfc_llcp_setsockopt,
906 .getsockopt = nfc_llcp_getsockopt,
53a0ac2e 907 .sendmsg = llcp_sock_sendmsg,
d646960f
SO
908 .recvmsg = llcp_sock_recvmsg,
909 .mmap = sock_no_mmap,
910};
911
4463523b
TE
912static const struct proto_ops llcp_rawsock_ops = {
913 .family = PF_NFC,
914 .owner = THIS_MODULE,
915 .bind = llcp_raw_sock_bind,
916 .connect = sock_no_connect,
917 .release = llcp_sock_release,
918 .socketpair = sock_no_socketpair,
919 .accept = sock_no_accept,
920 .getname = llcp_sock_getname,
921 .poll = llcp_sock_poll,
922 .ioctl = sock_no_ioctl,
923 .listen = sock_no_listen,
924 .shutdown = sock_no_shutdown,
925 .setsockopt = sock_no_setsockopt,
926 .getsockopt = sock_no_getsockopt,
927 .sendmsg = sock_no_sendmsg,
928 .recvmsg = llcp_sock_recvmsg,
929 .mmap = sock_no_mmap,
930};
931
d646960f
SO
932static void llcp_sock_destruct(struct sock *sk)
933{
934 struct nfc_llcp_sock *llcp_sock = nfc_llcp_sock(sk);
935
936 pr_debug("%p\n", sk);
937
938 if (sk->sk_state == LLCP_CONNECTED)
939 nfc_put_device(llcp_sock->dev);
940
941 skb_queue_purge(&sk->sk_receive_queue);
942
943 nfc_llcp_sock_free(llcp_sock);
944
945 if (!sock_flag(sk, SOCK_DEAD)) {
946 pr_err("Freeing alive NFC LLCP socket %p\n", sk);
947 return;
948 }
949}
950
11aa9c28 951struct sock *nfc_llcp_sock_alloc(struct socket *sock, int type, gfp_t gfp, int kern)
d646960f
SO
952{
953 struct sock *sk;
954 struct nfc_llcp_sock *llcp_sock;
955
11aa9c28 956 sk = sk_alloc(&init_net, PF_NFC, gfp, &llcp_sock_proto, kern);
d646960f
SO
957 if (!sk)
958 return NULL;
959
960 llcp_sock = nfc_llcp_sock(sk);
961
962 sock_init_data(sock, sk);
963 sk->sk_state = LLCP_CLOSED;
964 sk->sk_protocol = NFC_SOCKPROTO_LLCP;
965 sk->sk_type = type;
966 sk->sk_destruct = llcp_sock_destruct;
967
968 llcp_sock->ssap = 0;
969 llcp_sock->dsap = LLCP_SAP_SDP;
06d44f80 970 llcp_sock->rw = LLCP_MAX_RW + 1;
5eef6669 971 llcp_sock->miux = cpu_to_be16(LLCP_MAX_MIUX + 1);
d646960f
SO
972 llcp_sock->send_n = llcp_sock->send_ack_n = 0;
973 llcp_sock->recv_n = llcp_sock->recv_ack_n = 0;
974 llcp_sock->remote_ready = 1;
cbbf4721 975 llcp_sock->reserved_ssap = LLCP_SAP_MAX;
abd18d43 976 nfc_llcp_socket_remote_param_init(llcp_sock);
d646960f
SO
977 skb_queue_head_init(&llcp_sock->tx_queue);
978 skb_queue_head_init(&llcp_sock->tx_pending_queue);
d646960f
SO
979 INIT_LIST_HEAD(&llcp_sock->accept_queue);
980
981 if (sock != NULL)
982 sock->state = SS_UNCONNECTED;
983
984 return sk;
985}
986
987void nfc_llcp_sock_free(struct nfc_llcp_sock *sock)
988{
989 kfree(sock->service_name);
990
991 skb_queue_purge(&sock->tx_queue);
992 skb_queue_purge(&sock->tx_pending_queue);
d646960f
SO
993
994 list_del_init(&sock->accept_queue);
40c75f81 995
d646960f 996 sock->parent = NULL;
c7aa1225
SO
997
998 nfc_llcp_local_put(sock->local);
d646960f
SO
999}
1000
1001static int llcp_sock_create(struct net *net, struct socket *sock,
11aa9c28 1002 const struct nfc_protocol *nfc_proto, int kern)
d646960f
SO
1003{
1004 struct sock *sk;
1005
1006 pr_debug("%p\n", sock);
1007
4463523b
TE
1008 if (sock->type != SOCK_STREAM &&
1009 sock->type != SOCK_DGRAM &&
1010 sock->type != SOCK_RAW)
d646960f
SO
1011 return -ESOCKTNOSUPPORT;
1012
4463523b
TE
1013 if (sock->type == SOCK_RAW)
1014 sock->ops = &llcp_rawsock_ops;
1015 else
1016 sock->ops = &llcp_sock_ops;
d646960f 1017
11aa9c28 1018 sk = nfc_llcp_sock_alloc(sock, sock->type, GFP_ATOMIC, kern);
d646960f
SO
1019 if (sk == NULL)
1020 return -ENOMEM;
1021
1022 return 0;
1023}
1024
1025static const struct nfc_protocol llcp_nfc_proto = {
1026 .id = NFC_SOCKPROTO_LLCP,
1027 .proto = &llcp_sock_proto,
1028 .owner = THIS_MODULE,
1029 .create = llcp_sock_create
1030};
1031
1032int __init nfc_llcp_sock_init(void)
1033{
1034 return nfc_proto_register(&llcp_nfc_proto);
1035}
1036
1037void nfc_llcp_sock_exit(void)
1038{
1039 nfc_proto_unregister(&llcp_nfc_proto);
1040}