Bluetooth: Implement link key handling for the management interface
[GitHub/mt8127/android_kernel_alcatel_ttab.git] / net / bluetooth / hci_event.c
CommitLineData
8e87d142 1/*
1da177e4 2 BlueZ - Bluetooth protocol stack for Linux
2d0a0346 3 Copyright (c) 2000-2001, 2010, Code Aurora Forum. All rights reserved.
1da177e4
LT
4
5 Written 2000,2001 by Maxim Krasnyansky <maxk@qualcomm.com>
6
7 This program is free software; you can redistribute it and/or modify
8 it under the terms of the GNU General Public License version 2 as
9 published by the Free Software Foundation;
10
11 THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS
12 OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
13 FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT OF THIRD PARTY RIGHTS.
14 IN NO EVENT SHALL THE COPYRIGHT HOLDER(S) AND AUTHOR(S) BE LIABLE FOR ANY
8e87d142
YH
15 CLAIM, OR ANY SPECIAL INDIRECT OR CONSEQUENTIAL DAMAGES, OR ANY DAMAGES
16 WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
17 ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
1da177e4
LT
18 OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
19
8e87d142
YH
20 ALL LIABILITY, INCLUDING LIABILITY FOR INFRINGEMENT OF ANY PATENTS,
21 COPYRIGHTS, TRADEMARKS OR OTHER RIGHTS, RELATING TO USE OF THIS
1da177e4
LT
22 SOFTWARE IS DISCLAIMED.
23*/
24
25/* Bluetooth HCI event handling. */
26
1da177e4
LT
27#include <linux/module.h>
28
29#include <linux/types.h>
30#include <linux/errno.h>
31#include <linux/kernel.h>
1da177e4
LT
32#include <linux/slab.h>
33#include <linux/poll.h>
34#include <linux/fcntl.h>
35#include <linux/init.h>
36#include <linux/skbuff.h>
37#include <linux/interrupt.h>
38#include <linux/notifier.h>
39#include <net/sock.h>
40
41#include <asm/system.h>
70f23020 42#include <linux/uaccess.h>
1da177e4
LT
43#include <asm/unaligned.h>
44
45#include <net/bluetooth/bluetooth.h>
46#include <net/bluetooth/hci_core.h>
47
1da177e4
LT
48/* Handle HCI Event packets */
49
a9de9248 50static void hci_cc_inquiry_cancel(struct hci_dev *hdev, struct sk_buff *skb)
1da177e4 51{
a9de9248 52 __u8 status = *((__u8 *) skb->data);
1da177e4 53
a9de9248 54 BT_DBG("%s status 0x%x", hdev->name, status);
1da177e4 55
a9de9248
MH
56 if (status)
57 return;
1da177e4 58
a9de9248 59 clear_bit(HCI_INQUIRY, &hdev->flags);
6bd57416 60
23bb5763 61 hci_req_complete(hdev, HCI_OP_INQUIRY_CANCEL, status);
a9de9248
MH
62
63 hci_conn_check_pending(hdev);
64}
6bd57416 65
a9de9248
MH
66static void hci_cc_exit_periodic_inq(struct hci_dev *hdev, struct sk_buff *skb)
67{
68 __u8 status = *((__u8 *) skb->data);
6bd57416 69
a9de9248 70 BT_DBG("%s status 0x%x", hdev->name, status);
6bd57416 71
a9de9248
MH
72 if (status)
73 return;
1da177e4 74
a9de9248
MH
75 clear_bit(HCI_INQUIRY, &hdev->flags);
76
77 hci_conn_check_pending(hdev);
78}
79
80static void hci_cc_remote_name_req_cancel(struct hci_dev *hdev, struct sk_buff *skb)
81{
82 BT_DBG("%s", hdev->name);
83}
84
85static void hci_cc_role_discovery(struct hci_dev *hdev, struct sk_buff *skb)
86{
87 struct hci_rp_role_discovery *rp = (void *) skb->data;
88 struct hci_conn *conn;
89
90 BT_DBG("%s status 0x%x", hdev->name, rp->status);
91
92 if (rp->status)
93 return;
94
95 hci_dev_lock(hdev);
96
97 conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(rp->handle));
98 if (conn) {
99 if (rp->role)
100 conn->link_mode &= ~HCI_LM_MASTER;
101 else
102 conn->link_mode |= HCI_LM_MASTER;
1da177e4 103 }
a9de9248
MH
104
105 hci_dev_unlock(hdev);
1da177e4
LT
106}
107
e4e8e37c
MH
108static void hci_cc_read_link_policy(struct hci_dev *hdev, struct sk_buff *skb)
109{
110 struct hci_rp_read_link_policy *rp = (void *) skb->data;
111 struct hci_conn *conn;
112
113 BT_DBG("%s status 0x%x", hdev->name, rp->status);
114
115 if (rp->status)
116 return;
117
118 hci_dev_lock(hdev);
119
120 conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(rp->handle));
121 if (conn)
122 conn->link_policy = __le16_to_cpu(rp->policy);
123
124 hci_dev_unlock(hdev);
125}
126
a9de9248 127static void hci_cc_write_link_policy(struct hci_dev *hdev, struct sk_buff *skb)
1da177e4 128{
a9de9248 129 struct hci_rp_write_link_policy *rp = (void *) skb->data;
1da177e4 130 struct hci_conn *conn;
04837f64 131 void *sent;
1da177e4 132
a9de9248 133 BT_DBG("%s status 0x%x", hdev->name, rp->status);
1da177e4 134
a9de9248
MH
135 if (rp->status)
136 return;
1da177e4 137
a9de9248
MH
138 sent = hci_sent_cmd_data(hdev, HCI_OP_WRITE_LINK_POLICY);
139 if (!sent)
140 return;
1da177e4 141
a9de9248 142 hci_dev_lock(hdev);
1da177e4 143
a9de9248 144 conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(rp->handle));
e4e8e37c 145 if (conn)
83985319 146 conn->link_policy = get_unaligned_le16(sent + 2);
1da177e4 147
a9de9248
MH
148 hci_dev_unlock(hdev);
149}
1da177e4 150
e4e8e37c
MH
151static void hci_cc_read_def_link_policy(struct hci_dev *hdev, struct sk_buff *skb)
152{
153 struct hci_rp_read_def_link_policy *rp = (void *) skb->data;
154
155 BT_DBG("%s status 0x%x", hdev->name, rp->status);
156
157 if (rp->status)
158 return;
159
160 hdev->link_policy = __le16_to_cpu(rp->policy);
161}
162
163static void hci_cc_write_def_link_policy(struct hci_dev *hdev, struct sk_buff *skb)
164{
165 __u8 status = *((__u8 *) skb->data);
166 void *sent;
167
168 BT_DBG("%s status 0x%x", hdev->name, status);
169
170 sent = hci_sent_cmd_data(hdev, HCI_OP_WRITE_DEF_LINK_POLICY);
171 if (!sent)
172 return;
173
174 if (!status)
175 hdev->link_policy = get_unaligned_le16(sent);
176
23bb5763 177 hci_req_complete(hdev, HCI_OP_WRITE_DEF_LINK_POLICY, status);
e4e8e37c
MH
178}
179
a9de9248
MH
180static void hci_cc_reset(struct hci_dev *hdev, struct sk_buff *skb)
181{
182 __u8 status = *((__u8 *) skb->data);
04837f64 183
a9de9248 184 BT_DBG("%s status 0x%x", hdev->name, status);
04837f64 185
23bb5763 186 hci_req_complete(hdev, HCI_OP_RESET, status);
a9de9248 187}
04837f64 188
a9de9248
MH
189static void hci_cc_write_local_name(struct hci_dev *hdev, struct sk_buff *skb)
190{
191 __u8 status = *((__u8 *) skb->data);
192 void *sent;
04837f64 193
a9de9248 194 BT_DBG("%s status 0x%x", hdev->name, status);
04837f64 195
f383f275
MH
196 if (status)
197 return;
198
a9de9248
MH
199 sent = hci_sent_cmd_data(hdev, HCI_OP_WRITE_LOCAL_NAME);
200 if (!sent)
201 return;
04837f64 202
f383f275 203 memcpy(hdev->dev_name, sent, 248);
a9de9248
MH
204}
205
206static void hci_cc_read_local_name(struct hci_dev *hdev, struct sk_buff *skb)
207{
208 struct hci_rp_read_local_name *rp = (void *) skb->data;
209
210 BT_DBG("%s status 0x%x", hdev->name, rp->status);
211
212 if (rp->status)
213 return;
214
215 memcpy(hdev->dev_name, rp->name, 248);
216}
217
218static void hci_cc_write_auth_enable(struct hci_dev *hdev, struct sk_buff *skb)
219{
220 __u8 status = *((__u8 *) skb->data);
221 void *sent;
222
223 BT_DBG("%s status 0x%x", hdev->name, status);
224
225 sent = hci_sent_cmd_data(hdev, HCI_OP_WRITE_AUTH_ENABLE);
226 if (!sent)
227 return;
228
229 if (!status) {
230 __u8 param = *((__u8 *) sent);
231
232 if (param == AUTH_ENABLED)
233 set_bit(HCI_AUTH, &hdev->flags);
234 else
235 clear_bit(HCI_AUTH, &hdev->flags);
1da177e4 236 }
a9de9248 237
23bb5763 238 hci_req_complete(hdev, HCI_OP_WRITE_AUTH_ENABLE, status);
1da177e4
LT
239}
240
a9de9248 241static void hci_cc_write_encrypt_mode(struct hci_dev *hdev, struct sk_buff *skb)
1da177e4 242{
a9de9248 243 __u8 status = *((__u8 *) skb->data);
1da177e4
LT
244 void *sent;
245
a9de9248 246 BT_DBG("%s status 0x%x", hdev->name, status);
1da177e4 247
a9de9248
MH
248 sent = hci_sent_cmd_data(hdev, HCI_OP_WRITE_ENCRYPT_MODE);
249 if (!sent)
250 return;
1da177e4 251
a9de9248
MH
252 if (!status) {
253 __u8 param = *((__u8 *) sent);
254
255 if (param)
256 set_bit(HCI_ENCRYPT, &hdev->flags);
257 else
258 clear_bit(HCI_ENCRYPT, &hdev->flags);
259 }
1da177e4 260
23bb5763 261 hci_req_complete(hdev, HCI_OP_WRITE_ENCRYPT_MODE, status);
a9de9248 262}
1da177e4 263
a9de9248
MH
264static void hci_cc_write_scan_enable(struct hci_dev *hdev, struct sk_buff *skb)
265{
266 __u8 status = *((__u8 *) skb->data);
267 void *sent;
1da177e4 268
a9de9248 269 BT_DBG("%s status 0x%x", hdev->name, status);
1da177e4 270
a9de9248
MH
271 sent = hci_sent_cmd_data(hdev, HCI_OP_WRITE_SCAN_ENABLE);
272 if (!sent)
273 return;
1da177e4 274
a9de9248
MH
275 if (!status) {
276 __u8 param = *((__u8 *) sent);
9fbcbb45 277 int old_pscan, old_iscan;
1da177e4 278
9fbcbb45
JH
279 old_pscan = test_and_clear_bit(HCI_PSCAN, &hdev->flags);
280 old_iscan = test_and_clear_bit(HCI_ISCAN, &hdev->flags);
1da177e4 281
73f22f62 282 if (param & SCAN_INQUIRY) {
a9de9248 283 set_bit(HCI_ISCAN, &hdev->flags);
9fbcbb45
JH
284 if (!old_iscan)
285 mgmt_discoverable(hdev->id, 1);
286 } else if (old_iscan)
73f22f62 287 mgmt_discoverable(hdev->id, 0);
1da177e4 288
9fbcbb45 289 if (param & SCAN_PAGE) {
a9de9248 290 set_bit(HCI_PSCAN, &hdev->flags);
9fbcbb45
JH
291 if (!old_pscan)
292 mgmt_connectable(hdev->id, 1);
293 } else if (old_pscan)
294 mgmt_connectable(hdev->id, 0);
a9de9248 295 }
1da177e4 296
23bb5763 297 hci_req_complete(hdev, HCI_OP_WRITE_SCAN_ENABLE, status);
a9de9248 298}
1da177e4 299
a9de9248
MH
300static void hci_cc_read_class_of_dev(struct hci_dev *hdev, struct sk_buff *skb)
301{
302 struct hci_rp_read_class_of_dev *rp = (void *) skb->data;
1da177e4 303
a9de9248 304 BT_DBG("%s status 0x%x", hdev->name, rp->status);
1da177e4 305
a9de9248
MH
306 if (rp->status)
307 return;
1da177e4 308
a9de9248 309 memcpy(hdev->dev_class, rp->dev_class, 3);
1da177e4 310
a9de9248
MH
311 BT_DBG("%s class 0x%.2x%.2x%.2x", hdev->name,
312 hdev->dev_class[2], hdev->dev_class[1], hdev->dev_class[0]);
313}
1da177e4 314
a9de9248
MH
315static void hci_cc_write_class_of_dev(struct hci_dev *hdev, struct sk_buff *skb)
316{
317 __u8 status = *((__u8 *) skb->data);
318 void *sent;
1da177e4 319
a9de9248 320 BT_DBG("%s status 0x%x", hdev->name, status);
1da177e4 321
f383f275
MH
322 if (status)
323 return;
324
a9de9248
MH
325 sent = hci_sent_cmd_data(hdev, HCI_OP_WRITE_CLASS_OF_DEV);
326 if (!sent)
327 return;
1da177e4 328
f383f275 329 memcpy(hdev->dev_class, sent, 3);
a9de9248 330}
1da177e4 331
a9de9248
MH
332static void hci_cc_read_voice_setting(struct hci_dev *hdev, struct sk_buff *skb)
333{
334 struct hci_rp_read_voice_setting *rp = (void *) skb->data;
335 __u16 setting;
336
337 BT_DBG("%s status 0x%x", hdev->name, rp->status);
338
339 if (rp->status)
340 return;
341
342 setting = __le16_to_cpu(rp->voice_setting);
343
f383f275 344 if (hdev->voice_setting == setting)
a9de9248
MH
345 return;
346
347 hdev->voice_setting = setting;
348
349 BT_DBG("%s voice setting 0x%04x", hdev->name, setting);
350
351 if (hdev->notify) {
352 tasklet_disable(&hdev->tx_task);
353 hdev->notify(hdev, HCI_NOTIFY_VOICE_SETTING);
354 tasklet_enable(&hdev->tx_task);
355 }
356}
357
358static void hci_cc_write_voice_setting(struct hci_dev *hdev, struct sk_buff *skb)
359{
360 __u8 status = *((__u8 *) skb->data);
f383f275 361 __u16 setting;
a9de9248
MH
362 void *sent;
363
364 BT_DBG("%s status 0x%x", hdev->name, status);
1da177e4 365
f383f275
MH
366 if (status)
367 return;
368
a9de9248
MH
369 sent = hci_sent_cmd_data(hdev, HCI_OP_WRITE_VOICE_SETTING);
370 if (!sent)
371 return;
1da177e4 372
f383f275 373 setting = get_unaligned_le16(sent);
1da177e4 374
f383f275
MH
375 if (hdev->voice_setting == setting)
376 return;
377
378 hdev->voice_setting = setting;
1da177e4 379
f383f275 380 BT_DBG("%s voice setting 0x%04x", hdev->name, setting);
1da177e4 381
f383f275
MH
382 if (hdev->notify) {
383 tasklet_disable(&hdev->tx_task);
384 hdev->notify(hdev, HCI_NOTIFY_VOICE_SETTING);
385 tasklet_enable(&hdev->tx_task);
1da177e4
LT
386 }
387}
388
a9de9248 389static void hci_cc_host_buffer_size(struct hci_dev *hdev, struct sk_buff *skb)
1da177e4 390{
a9de9248 391 __u8 status = *((__u8 *) skb->data);
1da177e4 392
a9de9248 393 BT_DBG("%s status 0x%x", hdev->name, status);
1da177e4 394
23bb5763 395 hci_req_complete(hdev, HCI_OP_HOST_BUFFER_SIZE, status);
a9de9248 396}
1143e5a6 397
333140b5
MH
398static void hci_cc_read_ssp_mode(struct hci_dev *hdev, struct sk_buff *skb)
399{
400 struct hci_rp_read_ssp_mode *rp = (void *) skb->data;
401
402 BT_DBG("%s status 0x%x", hdev->name, rp->status);
403
404 if (rp->status)
405 return;
406
407 hdev->ssp_mode = rp->mode;
408}
409
410static void hci_cc_write_ssp_mode(struct hci_dev *hdev, struct sk_buff *skb)
411{
412 __u8 status = *((__u8 *) skb->data);
413 void *sent;
414
415 BT_DBG("%s status 0x%x", hdev->name, status);
416
417 if (status)
418 return;
419
420 sent = hci_sent_cmd_data(hdev, HCI_OP_WRITE_SSP_MODE);
421 if (!sent)
422 return;
423
424 hdev->ssp_mode = *((__u8 *) sent);
425}
426
d5859e22
JH
427static u8 hci_get_inquiry_mode(struct hci_dev *hdev)
428{
429 if (hdev->features[6] & LMP_EXT_INQ)
430 return 2;
431
432 if (hdev->features[3] & LMP_RSSI_INQ)
433 return 1;
434
435 if (hdev->manufacturer == 11 && hdev->hci_rev == 0x00 &&
436 hdev->lmp_subver == 0x0757)
437 return 1;
438
439 if (hdev->manufacturer == 15) {
440 if (hdev->hci_rev == 0x03 && hdev->lmp_subver == 0x6963)
441 return 1;
442 if (hdev->hci_rev == 0x09 && hdev->lmp_subver == 0x6963)
443 return 1;
444 if (hdev->hci_rev == 0x00 && hdev->lmp_subver == 0x6965)
445 return 1;
446 }
447
448 if (hdev->manufacturer == 31 && hdev->hci_rev == 0x2005 &&
449 hdev->lmp_subver == 0x1805)
450 return 1;
451
452 return 0;
453}
454
455static void hci_setup_inquiry_mode(struct hci_dev *hdev)
456{
457 u8 mode;
458
459 mode = hci_get_inquiry_mode(hdev);
460
461 hci_send_cmd(hdev, HCI_OP_WRITE_INQUIRY_MODE, 1, &mode);
462}
463
464static void hci_setup_event_mask(struct hci_dev *hdev)
465{
466 /* The second byte is 0xff instead of 0x9f (two reserved bits
467 * disabled) since a Broadcom 1.2 dongle doesn't respond to the
468 * command otherwise */
469 u8 events[8] = { 0xff, 0xff, 0xfb, 0xff, 0x00, 0x00, 0x00, 0x00 };
470
471 /* Events for 1.2 and newer controllers */
472 if (hdev->lmp_ver > 1) {
473 events[4] |= 0x01; /* Flow Specification Complete */
474 events[4] |= 0x02; /* Inquiry Result with RSSI */
475 events[4] |= 0x04; /* Read Remote Extended Features Complete */
476 events[5] |= 0x08; /* Synchronous Connection Complete */
477 events[5] |= 0x10; /* Synchronous Connection Changed */
478 }
479
480 if (hdev->features[3] & LMP_RSSI_INQ)
481 events[4] |= 0x04; /* Inquiry Result with RSSI */
482
483 if (hdev->features[5] & LMP_SNIFF_SUBR)
484 events[5] |= 0x20; /* Sniff Subrating */
485
486 if (hdev->features[5] & LMP_PAUSE_ENC)
487 events[5] |= 0x80; /* Encryption Key Refresh Complete */
488
489 if (hdev->features[6] & LMP_EXT_INQ)
490 events[5] |= 0x40; /* Extended Inquiry Result */
491
492 if (hdev->features[6] & LMP_NO_FLUSH)
493 events[7] |= 0x01; /* Enhanced Flush Complete */
494
495 if (hdev->features[7] & LMP_LSTO)
496 events[6] |= 0x80; /* Link Supervision Timeout Changed */
497
498 if (hdev->features[6] & LMP_SIMPLE_PAIR) {
499 events[6] |= 0x01; /* IO Capability Request */
500 events[6] |= 0x02; /* IO Capability Response */
501 events[6] |= 0x04; /* User Confirmation Request */
502 events[6] |= 0x08; /* User Passkey Request */
503 events[6] |= 0x10; /* Remote OOB Data Request */
504 events[6] |= 0x20; /* Simple Pairing Complete */
505 events[7] |= 0x04; /* User Passkey Notification */
506 events[7] |= 0x08; /* Keypress Notification */
507 events[7] |= 0x10; /* Remote Host Supported
508 * Features Notification */
509 }
510
511 if (hdev->features[4] & LMP_LE)
512 events[7] |= 0x20; /* LE Meta-Event */
513
514 hci_send_cmd(hdev, HCI_OP_SET_EVENT_MASK, sizeof(events), events);
515}
516
517static void hci_setup(struct hci_dev *hdev)
518{
519 hci_setup_event_mask(hdev);
520
521 if (hdev->lmp_ver > 1)
522 hci_send_cmd(hdev, HCI_OP_READ_LOCAL_COMMANDS, 0, NULL);
523
524 if (hdev->features[6] & LMP_SIMPLE_PAIR) {
525 u8 mode = 0x01;
526 hci_send_cmd(hdev, HCI_OP_WRITE_SSP_MODE, sizeof(mode), &mode);
527 }
528
529 if (hdev->features[3] & LMP_RSSI_INQ)
530 hci_setup_inquiry_mode(hdev);
531
532 if (hdev->features[7] & LMP_INQ_TX_PWR)
533 hci_send_cmd(hdev, HCI_OP_READ_INQ_RSP_TX_POWER, 0, NULL);
534}
535
a9de9248
MH
536static void hci_cc_read_local_version(struct hci_dev *hdev, struct sk_buff *skb)
537{
538 struct hci_rp_read_local_version *rp = (void *) skb->data;
1143e5a6 539
a9de9248 540 BT_DBG("%s status 0x%x", hdev->name, rp->status);
1143e5a6 541
a9de9248
MH
542 if (rp->status)
543 return;
1143e5a6 544
a9de9248 545 hdev->hci_ver = rp->hci_ver;
e4e8e37c 546 hdev->hci_rev = __le16_to_cpu(rp->hci_rev);
d5859e22 547 hdev->lmp_ver = rp->lmp_ver;
e4e8e37c 548 hdev->manufacturer = __le16_to_cpu(rp->manufacturer);
d5859e22 549 hdev->lmp_subver = __le16_to_cpu(rp->lmp_subver);
1143e5a6 550
a9de9248
MH
551 BT_DBG("%s manufacturer %d hci ver %d:%d", hdev->name,
552 hdev->manufacturer,
553 hdev->hci_ver, hdev->hci_rev);
d5859e22
JH
554
555 if (test_bit(HCI_INIT, &hdev->flags))
556 hci_setup(hdev);
557}
558
559static void hci_setup_link_policy(struct hci_dev *hdev)
560{
561 u16 link_policy = 0;
562
563 if (hdev->features[0] & LMP_RSWITCH)
564 link_policy |= HCI_LP_RSWITCH;
565 if (hdev->features[0] & LMP_HOLD)
566 link_policy |= HCI_LP_HOLD;
567 if (hdev->features[0] & LMP_SNIFF)
568 link_policy |= HCI_LP_SNIFF;
569 if (hdev->features[1] & LMP_PARK)
570 link_policy |= HCI_LP_PARK;
571
572 link_policy = cpu_to_le16(link_policy);
573 hci_send_cmd(hdev, HCI_OP_WRITE_DEF_LINK_POLICY,
574 sizeof(link_policy), &link_policy);
a9de9248 575}
1da177e4 576
a9de9248
MH
577static void hci_cc_read_local_commands(struct hci_dev *hdev, struct sk_buff *skb)
578{
579 struct hci_rp_read_local_commands *rp = (void *) skb->data;
1da177e4 580
a9de9248 581 BT_DBG("%s status 0x%x", hdev->name, rp->status);
1da177e4 582
a9de9248 583 if (rp->status)
d5859e22 584 goto done;
1da177e4 585
a9de9248 586 memcpy(hdev->commands, rp->commands, sizeof(hdev->commands));
d5859e22
JH
587
588 if (test_bit(HCI_INIT, &hdev->flags) && (hdev->commands[5] & 0x10))
589 hci_setup_link_policy(hdev);
590
591done:
592 hci_req_complete(hdev, HCI_OP_READ_LOCAL_COMMANDS, rp->status);
a9de9248 593}
1da177e4 594
a9de9248
MH
595static void hci_cc_read_local_features(struct hci_dev *hdev, struct sk_buff *skb)
596{
597 struct hci_rp_read_local_features *rp = (void *) skb->data;
5b7f9909 598
a9de9248 599 BT_DBG("%s status 0x%x", hdev->name, rp->status);
1da177e4 600
a9de9248
MH
601 if (rp->status)
602 return;
5b7f9909 603
a9de9248 604 memcpy(hdev->features, rp->features, 8);
5b7f9909 605
a9de9248
MH
606 /* Adjust default settings according to features
607 * supported by device. */
1da177e4 608
a9de9248
MH
609 if (hdev->features[0] & LMP_3SLOT)
610 hdev->pkt_type |= (HCI_DM3 | HCI_DH3);
1da177e4 611
a9de9248
MH
612 if (hdev->features[0] & LMP_5SLOT)
613 hdev->pkt_type |= (HCI_DM5 | HCI_DH5);
1da177e4 614
a9de9248
MH
615 if (hdev->features[1] & LMP_HV2) {
616 hdev->pkt_type |= (HCI_HV2);
617 hdev->esco_type |= (ESCO_HV2);
618 }
1da177e4 619
a9de9248
MH
620 if (hdev->features[1] & LMP_HV3) {
621 hdev->pkt_type |= (HCI_HV3);
622 hdev->esco_type |= (ESCO_HV3);
623 }
1da177e4 624
a9de9248
MH
625 if (hdev->features[3] & LMP_ESCO)
626 hdev->esco_type |= (ESCO_EV3);
da1f5198 627
a9de9248
MH
628 if (hdev->features[4] & LMP_EV4)
629 hdev->esco_type |= (ESCO_EV4);
da1f5198 630
a9de9248
MH
631 if (hdev->features[4] & LMP_EV5)
632 hdev->esco_type |= (ESCO_EV5);
1da177e4 633
efc7688b
MH
634 if (hdev->features[5] & LMP_EDR_ESCO_2M)
635 hdev->esco_type |= (ESCO_2EV3);
636
637 if (hdev->features[5] & LMP_EDR_ESCO_3M)
638 hdev->esco_type |= (ESCO_3EV3);
639
640 if (hdev->features[5] & LMP_EDR_3S_ESCO)
641 hdev->esco_type |= (ESCO_2EV5 | ESCO_3EV5);
642
a9de9248
MH
643 BT_DBG("%s features 0x%.2x%.2x%.2x%.2x%.2x%.2x%.2x%.2x", hdev->name,
644 hdev->features[0], hdev->features[1],
645 hdev->features[2], hdev->features[3],
646 hdev->features[4], hdev->features[5],
647 hdev->features[6], hdev->features[7]);
648}
1da177e4 649
a9de9248
MH
650static void hci_cc_read_buffer_size(struct hci_dev *hdev, struct sk_buff *skb)
651{
652 struct hci_rp_read_buffer_size *rp = (void *) skb->data;
1da177e4 653
a9de9248 654 BT_DBG("%s status 0x%x", hdev->name, rp->status);
1da177e4 655
a9de9248
MH
656 if (rp->status)
657 return;
1da177e4 658
a9de9248
MH
659 hdev->acl_mtu = __le16_to_cpu(rp->acl_mtu);
660 hdev->sco_mtu = rp->sco_mtu;
661 hdev->acl_pkts = __le16_to_cpu(rp->acl_max_pkt);
662 hdev->sco_pkts = __le16_to_cpu(rp->sco_max_pkt);
663
664 if (test_bit(HCI_QUIRK_FIXUP_BUFFER_SIZE, &hdev->quirks)) {
665 hdev->sco_mtu = 64;
666 hdev->sco_pkts = 8;
1da177e4 667 }
a9de9248
MH
668
669 hdev->acl_cnt = hdev->acl_pkts;
670 hdev->sco_cnt = hdev->sco_pkts;
671
672 BT_DBG("%s acl mtu %d:%d sco mtu %d:%d", hdev->name,
673 hdev->acl_mtu, hdev->acl_pkts,
674 hdev->sco_mtu, hdev->sco_pkts);
675}
676
677static void hci_cc_read_bd_addr(struct hci_dev *hdev, struct sk_buff *skb)
678{
679 struct hci_rp_read_bd_addr *rp = (void *) skb->data;
680
681 BT_DBG("%s status 0x%x", hdev->name, rp->status);
682
683 if (!rp->status)
684 bacpy(&hdev->bdaddr, &rp->bdaddr);
685
23bb5763
JH
686 hci_req_complete(hdev, HCI_OP_READ_BD_ADDR, rp->status);
687}
688
689static void hci_cc_write_ca_timeout(struct hci_dev *hdev, struct sk_buff *skb)
690{
691 __u8 status = *((__u8 *) skb->data);
692
693 BT_DBG("%s status 0x%x", hdev->name, status);
694
695 hci_req_complete(hdev, HCI_OP_WRITE_CA_TIMEOUT, status);
a9de9248
MH
696}
697
b0916ea0
JH
698static void hci_cc_delete_stored_link_key(struct hci_dev *hdev,
699 struct sk_buff *skb)
700{
701 __u8 status = *((__u8 *) skb->data);
702
703 BT_DBG("%s status 0x%x", hdev->name, status);
704
705 hci_req_complete(hdev, HCI_OP_DELETE_STORED_LINK_KEY, status);
706}
707
d5859e22
JH
708static void hci_cc_set_event_mask(struct hci_dev *hdev, struct sk_buff *skb)
709{
710 __u8 status = *((__u8 *) skb->data);
711
712 BT_DBG("%s status 0x%x", hdev->name, status);
713
714 hci_req_complete(hdev, HCI_OP_SET_EVENT_MASK, status);
715}
716
717static void hci_cc_write_inquiry_mode(struct hci_dev *hdev,
718 struct sk_buff *skb)
719{
720 __u8 status = *((__u8 *) skb->data);
721
722 BT_DBG("%s status 0x%x", hdev->name, status);
723
724 hci_req_complete(hdev, HCI_OP_WRITE_INQUIRY_MODE, status);
725}
726
727static void hci_cc_read_inq_rsp_tx_power(struct hci_dev *hdev,
728 struct sk_buff *skb)
729{
730 __u8 status = *((__u8 *) skb->data);
731
732 BT_DBG("%s status 0x%x", hdev->name, status);
733
734 hci_req_complete(hdev, HCI_OP_READ_INQ_RSP_TX_POWER, status);
735}
736
737static void hci_cc_set_event_flt(struct hci_dev *hdev, struct sk_buff *skb)
738{
739 __u8 status = *((__u8 *) skb->data);
740
741 BT_DBG("%s status 0x%x", hdev->name, status);
742
743 hci_req_complete(hdev, HCI_OP_SET_EVENT_FLT, status);
744}
745
a9de9248
MH
746static inline void hci_cs_inquiry(struct hci_dev *hdev, __u8 status)
747{
748 BT_DBG("%s status 0x%x", hdev->name, status);
749
750 if (status) {
23bb5763 751 hci_req_complete(hdev, HCI_OP_INQUIRY, status);
a9de9248
MH
752
753 hci_conn_check_pending(hdev);
754 } else
755 set_bit(HCI_INQUIRY, &hdev->flags);
1da177e4
LT
756}
757
1da177e4
LT
758static inline void hci_cs_create_conn(struct hci_dev *hdev, __u8 status)
759{
a9de9248 760 struct hci_cp_create_conn *cp;
1da177e4 761 struct hci_conn *conn;
1da177e4 762
a9de9248
MH
763 BT_DBG("%s status 0x%x", hdev->name, status);
764
765 cp = hci_sent_cmd_data(hdev, HCI_OP_CREATE_CONN);
1da177e4
LT
766 if (!cp)
767 return;
768
769 hci_dev_lock(hdev);
770
771 conn = hci_conn_hash_lookup_ba(hdev, ACL_LINK, &cp->bdaddr);
772
a9de9248 773 BT_DBG("%s bdaddr %s conn %p", hdev->name, batostr(&cp->bdaddr), conn);
1da177e4
LT
774
775 if (status) {
776 if (conn && conn->state == BT_CONNECT) {
4c67bc74
MH
777 if (status != 0x0c || conn->attempt > 2) {
778 conn->state = BT_CLOSED;
779 hci_proto_connect_cfm(conn, status);
780 hci_conn_del(conn);
781 } else
782 conn->state = BT_CONNECT2;
1da177e4
LT
783 }
784 } else {
785 if (!conn) {
786 conn = hci_conn_add(hdev, ACL_LINK, &cp->bdaddr);
787 if (conn) {
788 conn->out = 1;
789 conn->link_mode |= HCI_LM_MASTER;
790 } else
893ef971 791 BT_ERR("No memory for new connection");
1da177e4
LT
792 }
793 }
794
795 hci_dev_unlock(hdev);
796}
797
a9de9248 798static void hci_cs_add_sco(struct hci_dev *hdev, __u8 status)
1da177e4 799{
a9de9248
MH
800 struct hci_cp_add_sco *cp;
801 struct hci_conn *acl, *sco;
802 __u16 handle;
1da177e4 803
b6a0dc82
MH
804 BT_DBG("%s status 0x%x", hdev->name, status);
805
a9de9248
MH
806 if (!status)
807 return;
1da177e4 808
a9de9248
MH
809 cp = hci_sent_cmd_data(hdev, HCI_OP_ADD_SCO);
810 if (!cp)
811 return;
1da177e4 812
a9de9248 813 handle = __le16_to_cpu(cp->handle);
1da177e4 814
a9de9248 815 BT_DBG("%s handle %d", hdev->name, handle);
1da177e4 816
a9de9248 817 hci_dev_lock(hdev);
1da177e4 818
a9de9248
MH
819 acl = hci_conn_hash_lookup_handle(hdev, handle);
820 if (acl && (sco = acl->link)) {
821 sco->state = BT_CLOSED;
1da177e4 822
a9de9248
MH
823 hci_proto_connect_cfm(sco, status);
824 hci_conn_del(sco);
825 }
1da177e4 826
a9de9248
MH
827 hci_dev_unlock(hdev);
828}
1da177e4 829
f8558555
MH
830static void hci_cs_auth_requested(struct hci_dev *hdev, __u8 status)
831{
832 struct hci_cp_auth_requested *cp;
833 struct hci_conn *conn;
834
835 BT_DBG("%s status 0x%x", hdev->name, status);
836
837 if (!status)
838 return;
839
840 cp = hci_sent_cmd_data(hdev, HCI_OP_AUTH_REQUESTED);
841 if (!cp)
842 return;
843
844 hci_dev_lock(hdev);
845
846 conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(cp->handle));
847 if (conn) {
848 if (conn->state == BT_CONFIG) {
849 hci_proto_connect_cfm(conn, status);
850 hci_conn_put(conn);
851 }
852 }
853
854 hci_dev_unlock(hdev);
855}
856
857static void hci_cs_set_conn_encrypt(struct hci_dev *hdev, __u8 status)
858{
859 struct hci_cp_set_conn_encrypt *cp;
860 struct hci_conn *conn;
861
862 BT_DBG("%s status 0x%x", hdev->name, status);
863
864 if (!status)
865 return;
866
867 cp = hci_sent_cmd_data(hdev, HCI_OP_SET_CONN_ENCRYPT);
868 if (!cp)
869 return;
870
871 hci_dev_lock(hdev);
872
873 conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(cp->handle));
874 if (conn) {
875 if (conn->state == BT_CONFIG) {
876 hci_proto_connect_cfm(conn, status);
877 hci_conn_put(conn);
878 }
879 }
880
881 hci_dev_unlock(hdev);
882}
883
127178d2 884static int hci_outgoing_auth_needed(struct hci_dev *hdev,
392599b9
JH
885 struct hci_conn *conn)
886{
392599b9
JH
887 if (conn->state != BT_CONFIG || !conn->out)
888 return 0;
889
765c2a96 890 if (conn->pending_sec_level == BT_SECURITY_SDP)
392599b9
JH
891 return 0;
892
893 /* Only request authentication for SSP connections or non-SSP
894 * devices with sec_level HIGH */
895 if (!(hdev->ssp_mode > 0 && conn->ssp_mode > 0) &&
765c2a96 896 conn->pending_sec_level != BT_SECURITY_HIGH)
392599b9
JH
897 return 0;
898
392599b9
JH
899 return 1;
900}
901
a9de9248
MH
902static void hci_cs_remote_name_req(struct hci_dev *hdev, __u8 status)
903{
127178d2
JH
904 struct hci_cp_remote_name_req *cp;
905 struct hci_conn *conn;
906
a9de9248 907 BT_DBG("%s status 0x%x", hdev->name, status);
127178d2
JH
908
909 /* If successful wait for the name req complete event before
910 * checking for the need to do authentication */
911 if (!status)
912 return;
913
914 cp = hci_sent_cmd_data(hdev, HCI_OP_REMOTE_NAME_REQ);
915 if (!cp)
916 return;
917
918 hci_dev_lock(hdev);
919
920 conn = hci_conn_hash_lookup_ba(hdev, ACL_LINK, &cp->bdaddr);
921 if (conn && hci_outgoing_auth_needed(hdev, conn)) {
922 struct hci_cp_auth_requested cp;
923 cp.handle = __cpu_to_le16(conn->handle);
924 hci_send_cmd(hdev, HCI_OP_AUTH_REQUESTED, sizeof(cp), &cp);
925 }
926
927 hci_dev_unlock(hdev);
a9de9248 928}
1da177e4 929
769be974
MH
930static void hci_cs_read_remote_features(struct hci_dev *hdev, __u8 status)
931{
932 struct hci_cp_read_remote_features *cp;
933 struct hci_conn *conn;
934
935 BT_DBG("%s status 0x%x", hdev->name, status);
936
937 if (!status)
938 return;
939
940 cp = hci_sent_cmd_data(hdev, HCI_OP_READ_REMOTE_FEATURES);
941 if (!cp)
942 return;
943
944 hci_dev_lock(hdev);
945
946 conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(cp->handle));
947 if (conn) {
948 if (conn->state == BT_CONFIG) {
769be974
MH
949 hci_proto_connect_cfm(conn, status);
950 hci_conn_put(conn);
951 }
952 }
953
954 hci_dev_unlock(hdev);
955}
956
957static void hci_cs_read_remote_ext_features(struct hci_dev *hdev, __u8 status)
958{
959 struct hci_cp_read_remote_ext_features *cp;
960 struct hci_conn *conn;
961
962 BT_DBG("%s status 0x%x", hdev->name, status);
963
964 if (!status)
965 return;
966
967 cp = hci_sent_cmd_data(hdev, HCI_OP_READ_REMOTE_EXT_FEATURES);
968 if (!cp)
969 return;
970
971 hci_dev_lock(hdev);
972
973 conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(cp->handle));
974 if (conn) {
975 if (conn->state == BT_CONFIG) {
769be974
MH
976 hci_proto_connect_cfm(conn, status);
977 hci_conn_put(conn);
978 }
979 }
980
981 hci_dev_unlock(hdev);
982}
983
a9de9248
MH
984static void hci_cs_setup_sync_conn(struct hci_dev *hdev, __u8 status)
985{
b6a0dc82
MH
986 struct hci_cp_setup_sync_conn *cp;
987 struct hci_conn *acl, *sco;
988 __u16 handle;
989
a9de9248 990 BT_DBG("%s status 0x%x", hdev->name, status);
b6a0dc82
MH
991
992 if (!status)
993 return;
994
995 cp = hci_sent_cmd_data(hdev, HCI_OP_SETUP_SYNC_CONN);
996 if (!cp)
997 return;
998
999 handle = __le16_to_cpu(cp->handle);
1000
1001 BT_DBG("%s handle %d", hdev->name, handle);
1002
1003 hci_dev_lock(hdev);
1004
1005 acl = hci_conn_hash_lookup_handle(hdev, handle);
1006 if (acl && (sco = acl->link)) {
1007 sco->state = BT_CLOSED;
1008
1009 hci_proto_connect_cfm(sco, status);
1010 hci_conn_del(sco);
1011 }
1012
1013 hci_dev_unlock(hdev);
1da177e4
LT
1014}
1015
a9de9248 1016static void hci_cs_sniff_mode(struct hci_dev *hdev, __u8 status)
1da177e4 1017{
a9de9248
MH
1018 struct hci_cp_sniff_mode *cp;
1019 struct hci_conn *conn;
1da177e4 1020
a9de9248 1021 BT_DBG("%s status 0x%x", hdev->name, status);
04837f64 1022
a9de9248
MH
1023 if (!status)
1024 return;
04837f64 1025
a9de9248
MH
1026 cp = hci_sent_cmd_data(hdev, HCI_OP_SNIFF_MODE);
1027 if (!cp)
1028 return;
04837f64 1029
a9de9248 1030 hci_dev_lock(hdev);
04837f64 1031
a9de9248 1032 conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(cp->handle));
e73439d8 1033 if (conn) {
a9de9248 1034 clear_bit(HCI_CONN_MODE_CHANGE_PEND, &conn->pend);
04837f64 1035
e73439d8
MH
1036 if (test_and_clear_bit(HCI_CONN_SCO_SETUP_PEND, &conn->pend))
1037 hci_sco_setup(conn, status);
1038 }
1039
a9de9248
MH
1040 hci_dev_unlock(hdev);
1041}
04837f64 1042
a9de9248
MH
1043static void hci_cs_exit_sniff_mode(struct hci_dev *hdev, __u8 status)
1044{
1045 struct hci_cp_exit_sniff_mode *cp;
1046 struct hci_conn *conn;
04837f64 1047
a9de9248 1048 BT_DBG("%s status 0x%x", hdev->name, status);
04837f64 1049
a9de9248
MH
1050 if (!status)
1051 return;
04837f64 1052
a9de9248
MH
1053 cp = hci_sent_cmd_data(hdev, HCI_OP_EXIT_SNIFF_MODE);
1054 if (!cp)
1055 return;
04837f64 1056
a9de9248 1057 hci_dev_lock(hdev);
1da177e4 1058
a9de9248 1059 conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(cp->handle));
e73439d8 1060 if (conn) {
a9de9248 1061 clear_bit(HCI_CONN_MODE_CHANGE_PEND, &conn->pend);
1da177e4 1062
e73439d8
MH
1063 if (test_and_clear_bit(HCI_CONN_SCO_SETUP_PEND, &conn->pend))
1064 hci_sco_setup(conn, status);
1065 }
1066
a9de9248 1067 hci_dev_unlock(hdev);
1da177e4
LT
1068}
1069
1da177e4
LT
1070static inline void hci_inquiry_complete_evt(struct hci_dev *hdev, struct sk_buff *skb)
1071{
1072 __u8 status = *((__u8 *) skb->data);
1073
1074 BT_DBG("%s status %d", hdev->name, status);
1075
1076 clear_bit(HCI_INQUIRY, &hdev->flags);
6bd57416 1077
23bb5763 1078 hci_req_complete(hdev, HCI_OP_INQUIRY, status);
6bd57416 1079
a9de9248 1080 hci_conn_check_pending(hdev);
1da177e4
LT
1081}
1082
1da177e4
LT
1083static inline void hci_inquiry_result_evt(struct hci_dev *hdev, struct sk_buff *skb)
1084{
45bb4bf0 1085 struct inquiry_data data;
a9de9248 1086 struct inquiry_info *info = (void *) (skb->data + 1);
1da177e4
LT
1087 int num_rsp = *((__u8 *) skb->data);
1088
1089 BT_DBG("%s num_rsp %d", hdev->name, num_rsp);
1090
45bb4bf0
MH
1091 if (!num_rsp)
1092 return;
1093
1da177e4 1094 hci_dev_lock(hdev);
45bb4bf0 1095
1da177e4 1096 for (; num_rsp; num_rsp--) {
1da177e4
LT
1097 bacpy(&data.bdaddr, &info->bdaddr);
1098 data.pscan_rep_mode = info->pscan_rep_mode;
1099 data.pscan_period_mode = info->pscan_period_mode;
1100 data.pscan_mode = info->pscan_mode;
1101 memcpy(data.dev_class, info->dev_class, 3);
1102 data.clock_offset = info->clock_offset;
1103 data.rssi = 0x00;
41a96212 1104 data.ssp_mode = 0x00;
1da177e4
LT
1105 info++;
1106 hci_inquiry_cache_update(hdev, &data);
1107 }
45bb4bf0 1108
1da177e4
LT
1109 hci_dev_unlock(hdev);
1110}
1111
1da177e4
LT
1112static inline void hci_conn_complete_evt(struct hci_dev *hdev, struct sk_buff *skb)
1113{
a9de9248
MH
1114 struct hci_ev_conn_complete *ev = (void *) skb->data;
1115 struct hci_conn *conn;
1da177e4
LT
1116
1117 BT_DBG("%s", hdev->name);
1118
1119 hci_dev_lock(hdev);
1120
1121 conn = hci_conn_hash_lookup_ba(hdev, ev->link_type, &ev->bdaddr);
9499237a
MH
1122 if (!conn) {
1123 if (ev->link_type != SCO_LINK)
1124 goto unlock;
1125
1126 conn = hci_conn_hash_lookup_ba(hdev, ESCO_LINK, &ev->bdaddr);
1127 if (!conn)
1128 goto unlock;
1129
1130 conn->type = SCO_LINK;
1131 }
1da177e4
LT
1132
1133 if (!ev->status) {
1134 conn->handle = __le16_to_cpu(ev->handle);
769be974
MH
1135
1136 if (conn->type == ACL_LINK) {
1137 conn->state = BT_CONFIG;
1138 hci_conn_hold(conn);
052b30b0 1139 conn->disc_timeout = HCI_DISCONN_TIMEOUT;
769be974
MH
1140 } else
1141 conn->state = BT_CONNECTED;
1da177e4 1142
9eba32b8 1143 hci_conn_hold_device(conn);
7d0db0a3
MH
1144 hci_conn_add_sysfs(conn);
1145
1da177e4
LT
1146 if (test_bit(HCI_AUTH, &hdev->flags))
1147 conn->link_mode |= HCI_LM_AUTH;
1148
1149 if (test_bit(HCI_ENCRYPT, &hdev->flags))
1150 conn->link_mode |= HCI_LM_ENCRYPT;
1151
04837f64
MH
1152 /* Get remote features */
1153 if (conn->type == ACL_LINK) {
1154 struct hci_cp_read_remote_features cp;
1155 cp.handle = ev->handle;
769be974
MH
1156 hci_send_cmd(hdev, HCI_OP_READ_REMOTE_FEATURES,
1157 sizeof(cp), &cp);
04837f64
MH
1158 }
1159
1da177e4 1160 /* Set packet type for incoming connection */
a8746417 1161 if (!conn->out && hdev->hci_ver < 3) {
1da177e4
LT
1162 struct hci_cp_change_conn_ptype cp;
1163 cp.handle = ev->handle;
a8746417
MH
1164 cp.pkt_type = cpu_to_le16(conn->pkt_type);
1165 hci_send_cmd(hdev, HCI_OP_CHANGE_CONN_PTYPE,
1166 sizeof(cp), &cp);
1da177e4
LT
1167 }
1168 } else
1169 conn->state = BT_CLOSED;
1170
e73439d8
MH
1171 if (conn->type == ACL_LINK)
1172 hci_sco_setup(conn, ev->status);
1da177e4 1173
769be974
MH
1174 if (ev->status) {
1175 hci_proto_connect_cfm(conn, ev->status);
1da177e4 1176 hci_conn_del(conn);
c89b6e6b
MH
1177 } else if (ev->link_type != ACL_LINK)
1178 hci_proto_connect_cfm(conn, ev->status);
1da177e4 1179
a9de9248 1180unlock:
1da177e4 1181 hci_dev_unlock(hdev);
1da177e4 1182
a9de9248 1183 hci_conn_check_pending(hdev);
1da177e4
LT
1184}
1185
a9de9248 1186static inline void hci_conn_request_evt(struct hci_dev *hdev, struct sk_buff *skb)
1da177e4 1187{
a9de9248
MH
1188 struct hci_ev_conn_request *ev = (void *) skb->data;
1189 int mask = hdev->link_mode;
1da177e4 1190
a9de9248
MH
1191 BT_DBG("%s bdaddr %s type 0x%x", hdev->name,
1192 batostr(&ev->bdaddr), ev->link_type);
1da177e4 1193
a9de9248 1194 mask |= hci_proto_connect_ind(hdev, &ev->bdaddr, ev->link_type);
1da177e4 1195
f0358568 1196 if ((mask & HCI_LM_ACCEPT) && !hci_blacklist_lookup(hdev, &ev->bdaddr)) {
a9de9248 1197 /* Connection accepted */
c7bdd502 1198 struct inquiry_entry *ie;
1da177e4 1199 struct hci_conn *conn;
1da177e4 1200
a9de9248 1201 hci_dev_lock(hdev);
b6a0dc82 1202
cc11b9c1
AE
1203 ie = hci_inquiry_cache_lookup(hdev, &ev->bdaddr);
1204 if (ie)
c7bdd502
MH
1205 memcpy(ie->data.dev_class, ev->dev_class, 3);
1206
a9de9248
MH
1207 conn = hci_conn_hash_lookup_ba(hdev, ev->link_type, &ev->bdaddr);
1208 if (!conn) {
cc11b9c1
AE
1209 conn = hci_conn_add(hdev, ev->link_type, &ev->bdaddr);
1210 if (!conn) {
893ef971 1211 BT_ERR("No memory for new connection");
a9de9248
MH
1212 hci_dev_unlock(hdev);
1213 return;
1da177e4
LT
1214 }
1215 }
b6a0dc82 1216
a9de9248
MH
1217 memcpy(conn->dev_class, ev->dev_class, 3);
1218 conn->state = BT_CONNECT;
b6a0dc82 1219
a9de9248 1220 hci_dev_unlock(hdev);
1da177e4 1221
b6a0dc82
MH
1222 if (ev->link_type == ACL_LINK || !lmp_esco_capable(hdev)) {
1223 struct hci_cp_accept_conn_req cp;
1da177e4 1224
b6a0dc82
MH
1225 bacpy(&cp.bdaddr, &ev->bdaddr);
1226
1227 if (lmp_rswitch_capable(hdev) && (mask & HCI_LM_MASTER))
1228 cp.role = 0x00; /* Become master */
1229 else
1230 cp.role = 0x01; /* Remain slave */
1231
1232 hci_send_cmd(hdev, HCI_OP_ACCEPT_CONN_REQ,
1233 sizeof(cp), &cp);
1234 } else {
1235 struct hci_cp_accept_sync_conn_req cp;
1236
1237 bacpy(&cp.bdaddr, &ev->bdaddr);
a8746417 1238 cp.pkt_type = cpu_to_le16(conn->pkt_type);
b6a0dc82
MH
1239
1240 cp.tx_bandwidth = cpu_to_le32(0x00001f40);
1241 cp.rx_bandwidth = cpu_to_le32(0x00001f40);
1242 cp.max_latency = cpu_to_le16(0xffff);
1243 cp.content_format = cpu_to_le16(hdev->voice_setting);
1244 cp.retrans_effort = 0xff;
1da177e4 1245
b6a0dc82
MH
1246 hci_send_cmd(hdev, HCI_OP_ACCEPT_SYNC_CONN_REQ,
1247 sizeof(cp), &cp);
1248 }
a9de9248
MH
1249 } else {
1250 /* Connection rejected */
1251 struct hci_cp_reject_conn_req cp;
1da177e4 1252
a9de9248
MH
1253 bacpy(&cp.bdaddr, &ev->bdaddr);
1254 cp.reason = 0x0f;
1255 hci_send_cmd(hdev, HCI_OP_REJECT_CONN_REQ, sizeof(cp), &cp);
1da177e4 1256 }
1da177e4
LT
1257}
1258
a9de9248 1259static inline void hci_disconn_complete_evt(struct hci_dev *hdev, struct sk_buff *skb)
04837f64 1260{
a9de9248 1261 struct hci_ev_disconn_complete *ev = (void *) skb->data;
04837f64
MH
1262 struct hci_conn *conn;
1263
1264 BT_DBG("%s status %d", hdev->name, ev->status);
1265
a9de9248
MH
1266 if (ev->status)
1267 return;
1268
04837f64
MH
1269 hci_dev_lock(hdev);
1270
1271 conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(ev->handle));
1272 if (conn) {
a9de9248 1273 conn->state = BT_CLOSED;
7d0db0a3 1274
2950f21a 1275 hci_proto_disconn_cfm(conn, ev->reason);
a9de9248 1276 hci_conn_del(conn);
04837f64
MH
1277 }
1278
1279 hci_dev_unlock(hdev);
1280}
1281
1da177e4
LT
1282static inline void hci_auth_complete_evt(struct hci_dev *hdev, struct sk_buff *skb)
1283{
a9de9248 1284 struct hci_ev_auth_complete *ev = (void *) skb->data;
04837f64 1285 struct hci_conn *conn;
1da177e4
LT
1286
1287 BT_DBG("%s status %d", hdev->name, ev->status);
1288
1289 hci_dev_lock(hdev);
1290
04837f64 1291 conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(ev->handle));
1da177e4 1292 if (conn) {
765c2a96 1293 if (!ev->status) {
1da177e4 1294 conn->link_mode |= HCI_LM_AUTH;
765c2a96
JH
1295 conn->sec_level = conn->pending_sec_level;
1296 } else
da213f41 1297 conn->sec_level = BT_SECURITY_LOW;
1da177e4
LT
1298
1299 clear_bit(HCI_CONN_AUTH_PEND, &conn->pend);
1300
f8558555
MH
1301 if (conn->state == BT_CONFIG) {
1302 if (!ev->status && hdev->ssp_mode > 0 &&
1303 conn->ssp_mode > 0) {
1304 struct hci_cp_set_conn_encrypt cp;
1305 cp.handle = ev->handle;
1306 cp.encrypt = 0x01;
1307 hci_send_cmd(hdev, HCI_OP_SET_CONN_ENCRYPT,
1308 sizeof(cp), &cp);
1309 } else {
1310 conn->state = BT_CONNECTED;
1311 hci_proto_connect_cfm(conn, ev->status);
1312 hci_conn_put(conn);
1313 }
052b30b0 1314 } else {
f8558555 1315 hci_auth_cfm(conn, ev->status);
1da177e4 1316
052b30b0
MH
1317 hci_conn_hold(conn);
1318 conn->disc_timeout = HCI_DISCONN_TIMEOUT;
1319 hci_conn_put(conn);
1320 }
1321
1da177e4
LT
1322 if (test_bit(HCI_CONN_ENCRYPT_PEND, &conn->pend)) {
1323 if (!ev->status) {
1324 struct hci_cp_set_conn_encrypt cp;
f8558555
MH
1325 cp.handle = ev->handle;
1326 cp.encrypt = 0x01;
1327 hci_send_cmd(hdev, HCI_OP_SET_CONN_ENCRYPT,
1328 sizeof(cp), &cp);
1da177e4
LT
1329 } else {
1330 clear_bit(HCI_CONN_ENCRYPT_PEND, &conn->pend);
1331 hci_encrypt_cfm(conn, ev->status, 0x00);
1332 }
1333 }
1334 }
1335
1336 hci_dev_unlock(hdev);
1337}
1338
a9de9248 1339static inline void hci_remote_name_evt(struct hci_dev *hdev, struct sk_buff *skb)
1da177e4 1340{
127178d2
JH
1341 struct hci_ev_remote_name *ev = (void *) skb->data;
1342 struct hci_conn *conn;
1343
a9de9248 1344 BT_DBG("%s", hdev->name);
1da177e4 1345
a9de9248 1346 hci_conn_check_pending(hdev);
127178d2
JH
1347
1348 hci_dev_lock(hdev);
1349
1350 conn = hci_conn_hash_lookup_ba(hdev, ACL_LINK, &ev->bdaddr);
1351 if (conn && hci_outgoing_auth_needed(hdev, conn)) {
1352 struct hci_cp_auth_requested cp;
1353 cp.handle = __cpu_to_le16(conn->handle);
1354 hci_send_cmd(hdev, HCI_OP_AUTH_REQUESTED, sizeof(cp), &cp);
1355 }
1356
1357 hci_dev_unlock(hdev);
a9de9248
MH
1358}
1359
1360static inline void hci_encrypt_change_evt(struct hci_dev *hdev, struct sk_buff *skb)
1361{
1362 struct hci_ev_encrypt_change *ev = (void *) skb->data;
1363 struct hci_conn *conn;
1364
1365 BT_DBG("%s status %d", hdev->name, ev->status);
1da177e4
LT
1366
1367 hci_dev_lock(hdev);
1368
04837f64 1369 conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(ev->handle));
1da177e4
LT
1370 if (conn) {
1371 if (!ev->status) {
ae293196
MH
1372 if (ev->encrypt) {
1373 /* Encryption implies authentication */
1374 conn->link_mode |= HCI_LM_AUTH;
1da177e4 1375 conn->link_mode |= HCI_LM_ENCRYPT;
ae293196 1376 } else
1da177e4
LT
1377 conn->link_mode &= ~HCI_LM_ENCRYPT;
1378 }
1379
1380 clear_bit(HCI_CONN_ENCRYPT_PEND, &conn->pend);
1381
f8558555
MH
1382 if (conn->state == BT_CONFIG) {
1383 if (!ev->status)
1384 conn->state = BT_CONNECTED;
1385
1386 hci_proto_connect_cfm(conn, ev->status);
1387 hci_conn_put(conn);
1388 } else
1389 hci_encrypt_cfm(conn, ev->status, ev->encrypt);
1da177e4
LT
1390 }
1391
1392 hci_dev_unlock(hdev);
1393}
1394
a9de9248 1395static inline void hci_change_link_key_complete_evt(struct hci_dev *hdev, struct sk_buff *skb)
1da177e4 1396{
a9de9248 1397 struct hci_ev_change_link_key_complete *ev = (void *) skb->data;
04837f64 1398 struct hci_conn *conn;
1da177e4
LT
1399
1400 BT_DBG("%s status %d", hdev->name, ev->status);
1401
1402 hci_dev_lock(hdev);
1403
04837f64 1404 conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(ev->handle));
1da177e4
LT
1405 if (conn) {
1406 if (!ev->status)
1407 conn->link_mode |= HCI_LM_SECURE;
1408
1409 clear_bit(HCI_CONN_AUTH_PEND, &conn->pend);
1410
1411 hci_key_change_cfm(conn, ev->status);
1412 }
1413
1414 hci_dev_unlock(hdev);
1415}
1416
a9de9248 1417static inline void hci_remote_features_evt(struct hci_dev *hdev, struct sk_buff *skb)
1da177e4 1418{
a9de9248
MH
1419 struct hci_ev_remote_features *ev = (void *) skb->data;
1420 struct hci_conn *conn;
1421
1422 BT_DBG("%s status %d", hdev->name, ev->status);
1423
a9de9248
MH
1424 hci_dev_lock(hdev);
1425
1426 conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(ev->handle));
ccd556fe
JH
1427 if (!conn)
1428 goto unlock;
769be974 1429
ccd556fe
JH
1430 if (!ev->status)
1431 memcpy(conn->features, ev->features, 8);
1432
1433 if (conn->state != BT_CONFIG)
1434 goto unlock;
1435
1436 if (!ev->status && lmp_ssp_capable(hdev) && lmp_ssp_capable(conn)) {
1437 struct hci_cp_read_remote_ext_features cp;
1438 cp.handle = ev->handle;
1439 cp.page = 0x01;
1440 hci_send_cmd(hdev, HCI_OP_READ_REMOTE_EXT_FEATURES,
bdb7524a 1441 sizeof(cp), &cp);
392599b9
JH
1442 goto unlock;
1443 }
1444
127178d2
JH
1445 if (!ev->status) {
1446 struct hci_cp_remote_name_req cp;
1447 memset(&cp, 0, sizeof(cp));
1448 bacpy(&cp.bdaddr, &conn->dst);
1449 cp.pscan_rep_mode = 0x02;
1450 hci_send_cmd(hdev, HCI_OP_REMOTE_NAME_REQ, sizeof(cp), &cp);
1451 }
392599b9 1452
127178d2 1453 if (!hci_outgoing_auth_needed(hdev, conn)) {
ccd556fe
JH
1454 conn->state = BT_CONNECTED;
1455 hci_proto_connect_cfm(conn, ev->status);
1456 hci_conn_put(conn);
769be974 1457 }
a9de9248 1458
ccd556fe 1459unlock:
a9de9248 1460 hci_dev_unlock(hdev);
1da177e4
LT
1461}
1462
a9de9248 1463static inline void hci_remote_version_evt(struct hci_dev *hdev, struct sk_buff *skb)
1da177e4 1464{
a9de9248 1465 BT_DBG("%s", hdev->name);
1da177e4
LT
1466}
1467
a9de9248 1468static inline void hci_qos_setup_complete_evt(struct hci_dev *hdev, struct sk_buff *skb)
1da177e4 1469{
a9de9248 1470 BT_DBG("%s", hdev->name);
1da177e4
LT
1471}
1472
a9de9248
MH
1473static inline void hci_cmd_complete_evt(struct hci_dev *hdev, struct sk_buff *skb)
1474{
1475 struct hci_ev_cmd_complete *ev = (void *) skb->data;
1476 __u16 opcode;
1477
1478 skb_pull(skb, sizeof(*ev));
1479
1480 opcode = __le16_to_cpu(ev->opcode);
1481
1482 switch (opcode) {
1483 case HCI_OP_INQUIRY_CANCEL:
1484 hci_cc_inquiry_cancel(hdev, skb);
1485 break;
1486
1487 case HCI_OP_EXIT_PERIODIC_INQ:
1488 hci_cc_exit_periodic_inq(hdev, skb);
1489 break;
1490
1491 case HCI_OP_REMOTE_NAME_REQ_CANCEL:
1492 hci_cc_remote_name_req_cancel(hdev, skb);
1493 break;
1494
1495 case HCI_OP_ROLE_DISCOVERY:
1496 hci_cc_role_discovery(hdev, skb);
1497 break;
1498
e4e8e37c
MH
1499 case HCI_OP_READ_LINK_POLICY:
1500 hci_cc_read_link_policy(hdev, skb);
1501 break;
1502
a9de9248
MH
1503 case HCI_OP_WRITE_LINK_POLICY:
1504 hci_cc_write_link_policy(hdev, skb);
1505 break;
1506
e4e8e37c
MH
1507 case HCI_OP_READ_DEF_LINK_POLICY:
1508 hci_cc_read_def_link_policy(hdev, skb);
1509 break;
1510
1511 case HCI_OP_WRITE_DEF_LINK_POLICY:
1512 hci_cc_write_def_link_policy(hdev, skb);
1513 break;
1514
a9de9248
MH
1515 case HCI_OP_RESET:
1516 hci_cc_reset(hdev, skb);
1517 break;
1518
1519 case HCI_OP_WRITE_LOCAL_NAME:
1520 hci_cc_write_local_name(hdev, skb);
1521 break;
1522
1523 case HCI_OP_READ_LOCAL_NAME:
1524 hci_cc_read_local_name(hdev, skb);
1525 break;
1526
1527 case HCI_OP_WRITE_AUTH_ENABLE:
1528 hci_cc_write_auth_enable(hdev, skb);
1529 break;
1530
1531 case HCI_OP_WRITE_ENCRYPT_MODE:
1532 hci_cc_write_encrypt_mode(hdev, skb);
1533 break;
1534
1535 case HCI_OP_WRITE_SCAN_ENABLE:
1536 hci_cc_write_scan_enable(hdev, skb);
1537 break;
1538
1539 case HCI_OP_READ_CLASS_OF_DEV:
1540 hci_cc_read_class_of_dev(hdev, skb);
1541 break;
1542
1543 case HCI_OP_WRITE_CLASS_OF_DEV:
1544 hci_cc_write_class_of_dev(hdev, skb);
1545 break;
1546
1547 case HCI_OP_READ_VOICE_SETTING:
1548 hci_cc_read_voice_setting(hdev, skb);
1549 break;
1550
1551 case HCI_OP_WRITE_VOICE_SETTING:
1552 hci_cc_write_voice_setting(hdev, skb);
1553 break;
1554
1555 case HCI_OP_HOST_BUFFER_SIZE:
1556 hci_cc_host_buffer_size(hdev, skb);
1557 break;
1558
333140b5
MH
1559 case HCI_OP_READ_SSP_MODE:
1560 hci_cc_read_ssp_mode(hdev, skb);
1561 break;
1562
1563 case HCI_OP_WRITE_SSP_MODE:
1564 hci_cc_write_ssp_mode(hdev, skb);
1565 break;
1566
a9de9248
MH
1567 case HCI_OP_READ_LOCAL_VERSION:
1568 hci_cc_read_local_version(hdev, skb);
1569 break;
1570
1571 case HCI_OP_READ_LOCAL_COMMANDS:
1572 hci_cc_read_local_commands(hdev, skb);
1573 break;
1574
1575 case HCI_OP_READ_LOCAL_FEATURES:
1576 hci_cc_read_local_features(hdev, skb);
1577 break;
1578
1579 case HCI_OP_READ_BUFFER_SIZE:
1580 hci_cc_read_buffer_size(hdev, skb);
1581 break;
1582
1583 case HCI_OP_READ_BD_ADDR:
1584 hci_cc_read_bd_addr(hdev, skb);
1585 break;
1586
23bb5763
JH
1587 case HCI_OP_WRITE_CA_TIMEOUT:
1588 hci_cc_write_ca_timeout(hdev, skb);
1589 break;
1590
b0916ea0
JH
1591 case HCI_OP_DELETE_STORED_LINK_KEY:
1592 hci_cc_delete_stored_link_key(hdev, skb);
1593 break;
1594
d5859e22
JH
1595 case HCI_OP_SET_EVENT_MASK:
1596 hci_cc_set_event_mask(hdev, skb);
1597 break;
1598
1599 case HCI_OP_WRITE_INQUIRY_MODE:
1600 hci_cc_write_inquiry_mode(hdev, skb);
1601 break;
1602
1603 case HCI_OP_READ_INQ_RSP_TX_POWER:
1604 hci_cc_read_inq_rsp_tx_power(hdev, skb);
1605 break;
1606
1607 case HCI_OP_SET_EVENT_FLT:
1608 hci_cc_set_event_flt(hdev, skb);
1609 break;
1610
a9de9248
MH
1611 default:
1612 BT_DBG("%s opcode 0x%x", hdev->name, opcode);
1613 break;
1614 }
1615
1616 if (ev->ncmd) {
1617 atomic_set(&hdev->cmd_cnt, 1);
1618 if (!skb_queue_empty(&hdev->cmd_q))
c78ae283 1619 tasklet_schedule(&hdev->cmd_task);
a9de9248
MH
1620 }
1621}
1622
1623static inline void hci_cmd_status_evt(struct hci_dev *hdev, struct sk_buff *skb)
1624{
1625 struct hci_ev_cmd_status *ev = (void *) skb->data;
1626 __u16 opcode;
1627
1628 skb_pull(skb, sizeof(*ev));
1629
1630 opcode = __le16_to_cpu(ev->opcode);
1631
1632 switch (opcode) {
1633 case HCI_OP_INQUIRY:
1634 hci_cs_inquiry(hdev, ev->status);
1635 break;
1636
1637 case HCI_OP_CREATE_CONN:
1638 hci_cs_create_conn(hdev, ev->status);
1639 break;
1640
1641 case HCI_OP_ADD_SCO:
1642 hci_cs_add_sco(hdev, ev->status);
1643 break;
1644
f8558555
MH
1645 case HCI_OP_AUTH_REQUESTED:
1646 hci_cs_auth_requested(hdev, ev->status);
1647 break;
1648
1649 case HCI_OP_SET_CONN_ENCRYPT:
1650 hci_cs_set_conn_encrypt(hdev, ev->status);
1651 break;
1652
a9de9248
MH
1653 case HCI_OP_REMOTE_NAME_REQ:
1654 hci_cs_remote_name_req(hdev, ev->status);
1655 break;
1656
769be974
MH
1657 case HCI_OP_READ_REMOTE_FEATURES:
1658 hci_cs_read_remote_features(hdev, ev->status);
1659 break;
1660
1661 case HCI_OP_READ_REMOTE_EXT_FEATURES:
1662 hci_cs_read_remote_ext_features(hdev, ev->status);
1663 break;
1664
a9de9248
MH
1665 case HCI_OP_SETUP_SYNC_CONN:
1666 hci_cs_setup_sync_conn(hdev, ev->status);
1667 break;
1668
1669 case HCI_OP_SNIFF_MODE:
1670 hci_cs_sniff_mode(hdev, ev->status);
1671 break;
1672
1673 case HCI_OP_EXIT_SNIFF_MODE:
1674 hci_cs_exit_sniff_mode(hdev, ev->status);
1675 break;
1676
1677 default:
1678 BT_DBG("%s opcode 0x%x", hdev->name, opcode);
1679 break;
1680 }
1681
1682 if (ev->ncmd) {
1683 atomic_set(&hdev->cmd_cnt, 1);
1684 if (!skb_queue_empty(&hdev->cmd_q))
c78ae283 1685 tasklet_schedule(&hdev->cmd_task);
a9de9248
MH
1686 }
1687}
1688
1689static inline void hci_role_change_evt(struct hci_dev *hdev, struct sk_buff *skb)
1690{
1691 struct hci_ev_role_change *ev = (void *) skb->data;
1692 struct hci_conn *conn;
1693
1694 BT_DBG("%s status %d", hdev->name, ev->status);
1695
1696 hci_dev_lock(hdev);
1697
1698 conn = hci_conn_hash_lookup_ba(hdev, ACL_LINK, &ev->bdaddr);
1699 if (conn) {
1700 if (!ev->status) {
1701 if (ev->role)
1702 conn->link_mode &= ~HCI_LM_MASTER;
1703 else
1704 conn->link_mode |= HCI_LM_MASTER;
1705 }
1706
1707 clear_bit(HCI_CONN_RSWITCH_PEND, &conn->pend);
1708
1709 hci_role_switch_cfm(conn, ev->status, ev->role);
1710 }
1711
1712 hci_dev_unlock(hdev);
1713}
1714
1715static inline void hci_num_comp_pkts_evt(struct hci_dev *hdev, struct sk_buff *skb)
1716{
1717 struct hci_ev_num_comp_pkts *ev = (void *) skb->data;
1718 __le16 *ptr;
1719 int i;
1720
1721 skb_pull(skb, sizeof(*ev));
1722
1723 BT_DBG("%s num_hndl %d", hdev->name, ev->num_hndl);
1724
1725 if (skb->len < ev->num_hndl * 4) {
1726 BT_DBG("%s bad parameters", hdev->name);
1727 return;
1728 }
1729
1730 tasklet_disable(&hdev->tx_task);
1731
1732 for (i = 0, ptr = (__le16 *) skb->data; i < ev->num_hndl; i++) {
1733 struct hci_conn *conn;
1734 __u16 handle, count;
1735
83985319
HH
1736 handle = get_unaligned_le16(ptr++);
1737 count = get_unaligned_le16(ptr++);
a9de9248
MH
1738
1739 conn = hci_conn_hash_lookup_handle(hdev, handle);
1740 if (conn) {
1741 conn->sent -= count;
1742
1743 if (conn->type == ACL_LINK) {
70f23020
AE
1744 hdev->acl_cnt += count;
1745 if (hdev->acl_cnt > hdev->acl_pkts)
a9de9248
MH
1746 hdev->acl_cnt = hdev->acl_pkts;
1747 } else {
70f23020
AE
1748 hdev->sco_cnt += count;
1749 if (hdev->sco_cnt > hdev->sco_pkts)
a9de9248
MH
1750 hdev->sco_cnt = hdev->sco_pkts;
1751 }
1752 }
1753 }
1754
c78ae283 1755 tasklet_schedule(&hdev->tx_task);
a9de9248
MH
1756
1757 tasklet_enable(&hdev->tx_task);
1758}
1759
1760static inline void hci_mode_change_evt(struct hci_dev *hdev, struct sk_buff *skb)
04837f64 1761{
a9de9248 1762 struct hci_ev_mode_change *ev = (void *) skb->data;
04837f64
MH
1763 struct hci_conn *conn;
1764
1765 BT_DBG("%s status %d", hdev->name, ev->status);
1766
1767 hci_dev_lock(hdev);
1768
1769 conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(ev->handle));
a9de9248
MH
1770 if (conn) {
1771 conn->mode = ev->mode;
1772 conn->interval = __le16_to_cpu(ev->interval);
1773
1774 if (!test_and_clear_bit(HCI_CONN_MODE_CHANGE_PEND, &conn->pend)) {
1775 if (conn->mode == HCI_CM_ACTIVE)
1776 conn->power_save = 1;
1777 else
1778 conn->power_save = 0;
1779 }
e73439d8
MH
1780
1781 if (test_and_clear_bit(HCI_CONN_SCO_SETUP_PEND, &conn->pend))
1782 hci_sco_setup(conn, ev->status);
04837f64
MH
1783 }
1784
1785 hci_dev_unlock(hdev);
1786}
1787
a9de9248
MH
1788static inline void hci_pin_code_request_evt(struct hci_dev *hdev, struct sk_buff *skb)
1789{
052b30b0
MH
1790 struct hci_ev_pin_code_req *ev = (void *) skb->data;
1791 struct hci_conn *conn;
1792
a9de9248 1793 BT_DBG("%s", hdev->name);
052b30b0
MH
1794
1795 hci_dev_lock(hdev);
1796
1797 conn = hci_conn_hash_lookup_ba(hdev, ACL_LINK, &ev->bdaddr);
3d7a9d1c 1798 if (conn && conn->state == BT_CONNECTED) {
052b30b0
MH
1799 hci_conn_hold(conn);
1800 conn->disc_timeout = HCI_PAIRING_TIMEOUT;
1801 hci_conn_put(conn);
1802 }
1803
03b555e1
JH
1804 if (!test_bit(HCI_PAIRABLE, &hdev->flags))
1805 hci_send_cmd(hdev, HCI_OP_PIN_CODE_NEG_REPLY,
1806 sizeof(ev->bdaddr), &ev->bdaddr);
1807
052b30b0 1808 hci_dev_unlock(hdev);
a9de9248
MH
1809}
1810
1811static inline void hci_link_key_request_evt(struct hci_dev *hdev, struct sk_buff *skb)
1812{
55ed8ca1
JH
1813 struct hci_ev_link_key_req *ev = (void *) skb->data;
1814 struct hci_cp_link_key_reply cp;
1815 struct hci_conn *conn;
1816 struct link_key *key;
1817
a9de9248 1818 BT_DBG("%s", hdev->name);
55ed8ca1
JH
1819
1820 if (!test_bit(HCI_LINK_KEYS, &hdev->flags))
1821 return;
1822
1823 hci_dev_lock(hdev);
1824
1825 key = hci_find_link_key(hdev, &ev->bdaddr);
1826 if (!key) {
1827 BT_DBG("%s link key not found for %s", hdev->name,
1828 batostr(&ev->bdaddr));
1829 goto not_found;
1830 }
1831
1832 BT_DBG("%s found key type %u for %s", hdev->name, key->type,
1833 batostr(&ev->bdaddr));
1834
1835 if (!test_bit(HCI_DEBUG_KEYS, &hdev->flags) && key->type == 0x03) {
1836 BT_DBG("%s ignoring debug key", hdev->name);
1837 goto not_found;
1838 }
1839
1840 conn = hci_conn_hash_lookup_ba(hdev, ACL_LINK, &ev->bdaddr);
1841
1842 if (key->type == 0x04 && conn && conn->auth_type != 0xff &&
1843 (conn->auth_type & 0x01)) {
1844 BT_DBG("%s ignoring unauthenticated key", hdev->name);
1845 goto not_found;
1846 }
1847
1848 bacpy(&cp.bdaddr, &ev->bdaddr);
1849 memcpy(cp.link_key, key->val, 16);
1850
1851 hci_send_cmd(hdev, HCI_OP_LINK_KEY_REPLY, sizeof(cp), &cp);
1852
1853 hci_dev_unlock(hdev);
1854
1855 return;
1856
1857not_found:
1858 hci_send_cmd(hdev, HCI_OP_LINK_KEY_NEG_REPLY, 6, &ev->bdaddr);
1859 hci_dev_unlock(hdev);
a9de9248
MH
1860}
1861
1862static inline void hci_link_key_notify_evt(struct hci_dev *hdev, struct sk_buff *skb)
1863{
052b30b0
MH
1864 struct hci_ev_link_key_notify *ev = (void *) skb->data;
1865 struct hci_conn *conn;
55ed8ca1 1866 u8 pin_len = 0;
052b30b0 1867
a9de9248 1868 BT_DBG("%s", hdev->name);
052b30b0
MH
1869
1870 hci_dev_lock(hdev);
1871
1872 conn = hci_conn_hash_lookup_ba(hdev, ACL_LINK, &ev->bdaddr);
1873 if (conn) {
1874 hci_conn_hold(conn);
1875 conn->disc_timeout = HCI_DISCONN_TIMEOUT;
1876 hci_conn_put(conn);
1877 }
1878
55ed8ca1
JH
1879 if (test_bit(HCI_LINK_KEYS, &hdev->flags))
1880 hci_add_link_key(hdev, 1, &ev->bdaddr, ev->link_key,
1881 ev->key_type, pin_len);
1882
052b30b0 1883 hci_dev_unlock(hdev);
a9de9248
MH
1884}
1885
1da177e4
LT
1886static inline void hci_clock_offset_evt(struct hci_dev *hdev, struct sk_buff *skb)
1887{
a9de9248 1888 struct hci_ev_clock_offset *ev = (void *) skb->data;
04837f64 1889 struct hci_conn *conn;
1da177e4
LT
1890
1891 BT_DBG("%s status %d", hdev->name, ev->status);
1892
1893 hci_dev_lock(hdev);
1894
04837f64 1895 conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(ev->handle));
1da177e4
LT
1896 if (conn && !ev->status) {
1897 struct inquiry_entry *ie;
1898
cc11b9c1
AE
1899 ie = hci_inquiry_cache_lookup(hdev, &conn->dst);
1900 if (ie) {
1da177e4
LT
1901 ie->data.clock_offset = ev->clock_offset;
1902 ie->timestamp = jiffies;
1903 }
1904 }
1905
1906 hci_dev_unlock(hdev);
1907}
1908
a8746417
MH
1909static inline void hci_pkt_type_change_evt(struct hci_dev *hdev, struct sk_buff *skb)
1910{
1911 struct hci_ev_pkt_type_change *ev = (void *) skb->data;
1912 struct hci_conn *conn;
1913
1914 BT_DBG("%s status %d", hdev->name, ev->status);
1915
1916 hci_dev_lock(hdev);
1917
1918 conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(ev->handle));
1919 if (conn && !ev->status)
1920 conn->pkt_type = __le16_to_cpu(ev->pkt_type);
1921
1922 hci_dev_unlock(hdev);
1923}
1924
85a1e930
MH
1925static inline void hci_pscan_rep_mode_evt(struct hci_dev *hdev, struct sk_buff *skb)
1926{
a9de9248 1927 struct hci_ev_pscan_rep_mode *ev = (void *) skb->data;
85a1e930
MH
1928 struct inquiry_entry *ie;
1929
1930 BT_DBG("%s", hdev->name);
1931
1932 hci_dev_lock(hdev);
1933
cc11b9c1
AE
1934 ie = hci_inquiry_cache_lookup(hdev, &ev->bdaddr);
1935 if (ie) {
85a1e930
MH
1936 ie->data.pscan_rep_mode = ev->pscan_rep_mode;
1937 ie->timestamp = jiffies;
1938 }
1939
1940 hci_dev_unlock(hdev);
1941}
1942
a9de9248
MH
1943static inline void hci_inquiry_result_with_rssi_evt(struct hci_dev *hdev, struct sk_buff *skb)
1944{
1945 struct inquiry_data data;
1946 int num_rsp = *((__u8 *) skb->data);
1947
1948 BT_DBG("%s num_rsp %d", hdev->name, num_rsp);
1949
1950 if (!num_rsp)
1951 return;
1952
1953 hci_dev_lock(hdev);
1954
1955 if ((skb->len - 1) / num_rsp != sizeof(struct inquiry_info_with_rssi)) {
1956 struct inquiry_info_with_rssi_and_pscan_mode *info = (void *) (skb->data + 1);
1957
1958 for (; num_rsp; num_rsp--) {
1959 bacpy(&data.bdaddr, &info->bdaddr);
1960 data.pscan_rep_mode = info->pscan_rep_mode;
1961 data.pscan_period_mode = info->pscan_period_mode;
1962 data.pscan_mode = info->pscan_mode;
1963 memcpy(data.dev_class, info->dev_class, 3);
1964 data.clock_offset = info->clock_offset;
1965 data.rssi = info->rssi;
41a96212 1966 data.ssp_mode = 0x00;
a9de9248
MH
1967 info++;
1968 hci_inquiry_cache_update(hdev, &data);
1969 }
1970 } else {
1971 struct inquiry_info_with_rssi *info = (void *) (skb->data + 1);
1972
1973 for (; num_rsp; num_rsp--) {
1974 bacpy(&data.bdaddr, &info->bdaddr);
1975 data.pscan_rep_mode = info->pscan_rep_mode;
1976 data.pscan_period_mode = info->pscan_period_mode;
1977 data.pscan_mode = 0x00;
1978 memcpy(data.dev_class, info->dev_class, 3);
1979 data.clock_offset = info->clock_offset;
1980 data.rssi = info->rssi;
41a96212 1981 data.ssp_mode = 0x00;
a9de9248
MH
1982 info++;
1983 hci_inquiry_cache_update(hdev, &data);
1984 }
1985 }
1986
1987 hci_dev_unlock(hdev);
1988}
1989
1990static inline void hci_remote_ext_features_evt(struct hci_dev *hdev, struct sk_buff *skb)
1991{
41a96212
MH
1992 struct hci_ev_remote_ext_features *ev = (void *) skb->data;
1993 struct hci_conn *conn;
1994
a9de9248 1995 BT_DBG("%s", hdev->name);
41a96212 1996
41a96212
MH
1997 hci_dev_lock(hdev);
1998
1999 conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(ev->handle));
ccd556fe
JH
2000 if (!conn)
2001 goto unlock;
41a96212 2002
ccd556fe
JH
2003 if (!ev->status && ev->page == 0x01) {
2004 struct inquiry_entry *ie;
41a96212 2005
cc11b9c1
AE
2006 ie = hci_inquiry_cache_lookup(hdev, &conn->dst);
2007 if (ie)
ccd556fe 2008 ie->data.ssp_mode = (ev->features[0] & 0x01);
769be974 2009
ccd556fe
JH
2010 conn->ssp_mode = (ev->features[0] & 0x01);
2011 }
2012
2013 if (conn->state != BT_CONFIG)
2014 goto unlock;
2015
127178d2
JH
2016 if (!ev->status) {
2017 struct hci_cp_remote_name_req cp;
2018 memset(&cp, 0, sizeof(cp));
2019 bacpy(&cp.bdaddr, &conn->dst);
2020 cp.pscan_rep_mode = 0x02;
2021 hci_send_cmd(hdev, HCI_OP_REMOTE_NAME_REQ, sizeof(cp), &cp);
2022 }
392599b9 2023
127178d2 2024 if (!hci_outgoing_auth_needed(hdev, conn)) {
ccd556fe
JH
2025 conn->state = BT_CONNECTED;
2026 hci_proto_connect_cfm(conn, ev->status);
2027 hci_conn_put(conn);
41a96212
MH
2028 }
2029
ccd556fe 2030unlock:
41a96212 2031 hci_dev_unlock(hdev);
a9de9248
MH
2032}
2033
2034static inline void hci_sync_conn_complete_evt(struct hci_dev *hdev, struct sk_buff *skb)
2035{
b6a0dc82
MH
2036 struct hci_ev_sync_conn_complete *ev = (void *) skb->data;
2037 struct hci_conn *conn;
2038
2039 BT_DBG("%s status %d", hdev->name, ev->status);
2040
2041 hci_dev_lock(hdev);
2042
2043 conn = hci_conn_hash_lookup_ba(hdev, ev->link_type, &ev->bdaddr);
9dc0a3af
MH
2044 if (!conn) {
2045 if (ev->link_type == ESCO_LINK)
2046 goto unlock;
2047
2048 conn = hci_conn_hash_lookup_ba(hdev, ESCO_LINK, &ev->bdaddr);
2049 if (!conn)
2050 goto unlock;
2051
2052 conn->type = SCO_LINK;
2053 }
b6a0dc82 2054
732547f9
MH
2055 switch (ev->status) {
2056 case 0x00:
b6a0dc82
MH
2057 conn->handle = __le16_to_cpu(ev->handle);
2058 conn->state = BT_CONNECTED;
7d0db0a3 2059
9eba32b8 2060 hci_conn_hold_device(conn);
7d0db0a3 2061 hci_conn_add_sysfs(conn);
732547f9
MH
2062 break;
2063
705e5711 2064 case 0x11: /* Unsupported Feature or Parameter Value */
732547f9 2065 case 0x1c: /* SCO interval rejected */
1038a00b 2066 case 0x1a: /* Unsupported Remote Feature */
732547f9
MH
2067 case 0x1f: /* Unspecified error */
2068 if (conn->out && conn->attempt < 2) {
2069 conn->pkt_type = (hdev->esco_type & SCO_ESCO_MASK) |
2070 (hdev->esco_type & EDR_ESCO_MASK);
2071 hci_setup_sync(conn, conn->link->handle);
2072 goto unlock;
2073 }
2074 /* fall through */
2075
2076 default:
b6a0dc82 2077 conn->state = BT_CLOSED;
732547f9
MH
2078 break;
2079 }
b6a0dc82
MH
2080
2081 hci_proto_connect_cfm(conn, ev->status);
2082 if (ev->status)
2083 hci_conn_del(conn);
2084
2085unlock:
2086 hci_dev_unlock(hdev);
a9de9248
MH
2087}
2088
2089static inline void hci_sync_conn_changed_evt(struct hci_dev *hdev, struct sk_buff *skb)
2090{
2091 BT_DBG("%s", hdev->name);
2092}
2093
04837f64
MH
2094static inline void hci_sniff_subrate_evt(struct hci_dev *hdev, struct sk_buff *skb)
2095{
a9de9248 2096 struct hci_ev_sniff_subrate *ev = (void *) skb->data;
04837f64
MH
2097 struct hci_conn *conn;
2098
2099 BT_DBG("%s status %d", hdev->name, ev->status);
2100
2101 hci_dev_lock(hdev);
2102
2103 conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(ev->handle));
2104 if (conn) {
2105 }
2106
2107 hci_dev_unlock(hdev);
2108}
2109
a9de9248 2110static inline void hci_extended_inquiry_result_evt(struct hci_dev *hdev, struct sk_buff *skb)
1da177e4 2111{
a9de9248
MH
2112 struct inquiry_data data;
2113 struct extended_inquiry_info *info = (void *) (skb->data + 1);
2114 int num_rsp = *((__u8 *) skb->data);
1da177e4 2115
a9de9248 2116 BT_DBG("%s num_rsp %d", hdev->name, num_rsp);
1da177e4 2117
a9de9248
MH
2118 if (!num_rsp)
2119 return;
1da177e4 2120
a9de9248
MH
2121 hci_dev_lock(hdev);
2122
2123 for (; num_rsp; num_rsp--) {
2124 bacpy(&data.bdaddr, &info->bdaddr);
2125 data.pscan_rep_mode = info->pscan_rep_mode;
2126 data.pscan_period_mode = info->pscan_period_mode;
2127 data.pscan_mode = 0x00;
2128 memcpy(data.dev_class, info->dev_class, 3);
2129 data.clock_offset = info->clock_offset;
2130 data.rssi = info->rssi;
41a96212 2131 data.ssp_mode = 0x01;
a9de9248
MH
2132 info++;
2133 hci_inquiry_cache_update(hdev, &data);
2134 }
2135
2136 hci_dev_unlock(hdev);
2137}
1da177e4 2138
0493684e
MH
2139static inline void hci_io_capa_request_evt(struct hci_dev *hdev, struct sk_buff *skb)
2140{
2141 struct hci_ev_io_capa_request *ev = (void *) skb->data;
2142 struct hci_conn *conn;
2143
2144 BT_DBG("%s", hdev->name);
2145
2146 hci_dev_lock(hdev);
2147
2148 conn = hci_conn_hash_lookup_ba(hdev, ACL_LINK, &ev->bdaddr);
03b555e1
JH
2149 if (!conn)
2150 goto unlock;
2151
2152 hci_conn_hold(conn);
2153
2154 if (!test_bit(HCI_MGMT, &hdev->flags))
2155 goto unlock;
2156
2157 if (test_bit(HCI_PAIRABLE, &hdev->flags) ||
2158 (conn->remote_auth & ~0x01) == HCI_AT_NO_BONDING) {
2159 /* FIXME: Do IO capa response based on information
2160 * provided through the management interface */
2161 } else {
2162 struct hci_cp_io_capability_neg_reply cp;
2163
2164 bacpy(&cp.bdaddr, &ev->bdaddr);
2165 cp.reason = 0x16; /* Pairing not allowed */
0493684e 2166
03b555e1
JH
2167 hci_send_cmd(hdev, HCI_OP_IO_CAPABILITY_NEG_REPLY,
2168 sizeof(cp), &cp);
2169 }
2170
2171unlock:
2172 hci_dev_unlock(hdev);
2173}
2174
2175static inline void hci_io_capa_reply_evt(struct hci_dev *hdev, struct sk_buff *skb)
2176{
2177 struct hci_ev_io_capa_reply *ev = (void *) skb->data;
2178 struct hci_conn *conn;
2179
2180 BT_DBG("%s", hdev->name);
2181
2182 hci_dev_lock(hdev);
2183
2184 conn = hci_conn_hash_lookup_ba(hdev, ACL_LINK, &ev->bdaddr);
2185 if (!conn)
2186 goto unlock;
2187
2188 hci_conn_hold(conn);
2189
2190 conn->remote_cap = ev->capability;
2191 conn->remote_oob = ev->oob_data;
2192 conn->remote_auth = ev->authentication;
2193
2194unlock:
0493684e
MH
2195 hci_dev_unlock(hdev);
2196}
2197
2198static inline void hci_simple_pair_complete_evt(struct hci_dev *hdev, struct sk_buff *skb)
2199{
2200 struct hci_ev_simple_pair_complete *ev = (void *) skb->data;
2201 struct hci_conn *conn;
2202
2203 BT_DBG("%s", hdev->name);
2204
2205 hci_dev_lock(hdev);
2206
2207 conn = hci_conn_hash_lookup_ba(hdev, ACL_LINK, &ev->bdaddr);
2208 if (conn)
2209 hci_conn_put(conn);
2210
2211 hci_dev_unlock(hdev);
2212}
2213
41a96212
MH
2214static inline void hci_remote_host_features_evt(struct hci_dev *hdev, struct sk_buff *skb)
2215{
2216 struct hci_ev_remote_host_features *ev = (void *) skb->data;
2217 struct inquiry_entry *ie;
2218
2219 BT_DBG("%s", hdev->name);
2220
2221 hci_dev_lock(hdev);
2222
cc11b9c1
AE
2223 ie = hci_inquiry_cache_lookup(hdev, &ev->bdaddr);
2224 if (ie)
41a96212
MH
2225 ie->data.ssp_mode = (ev->features[0] & 0x01);
2226
2227 hci_dev_unlock(hdev);
2228}
2229
a9de9248
MH
2230void hci_event_packet(struct hci_dev *hdev, struct sk_buff *skb)
2231{
2232 struct hci_event_hdr *hdr = (void *) skb->data;
2233 __u8 event = hdr->evt;
2234
2235 skb_pull(skb, HCI_EVENT_HDR_SIZE);
2236
2237 switch (event) {
1da177e4
LT
2238 case HCI_EV_INQUIRY_COMPLETE:
2239 hci_inquiry_complete_evt(hdev, skb);
2240 break;
2241
2242 case HCI_EV_INQUIRY_RESULT:
2243 hci_inquiry_result_evt(hdev, skb);
2244 break;
2245
a9de9248
MH
2246 case HCI_EV_CONN_COMPLETE:
2247 hci_conn_complete_evt(hdev, skb);
21d9e30e
MH
2248 break;
2249
1da177e4
LT
2250 case HCI_EV_CONN_REQUEST:
2251 hci_conn_request_evt(hdev, skb);
2252 break;
2253
1da177e4
LT
2254 case HCI_EV_DISCONN_COMPLETE:
2255 hci_disconn_complete_evt(hdev, skb);
2256 break;
2257
1da177e4
LT
2258 case HCI_EV_AUTH_COMPLETE:
2259 hci_auth_complete_evt(hdev, skb);
2260 break;
2261
a9de9248
MH
2262 case HCI_EV_REMOTE_NAME:
2263 hci_remote_name_evt(hdev, skb);
2264 break;
2265
1da177e4
LT
2266 case HCI_EV_ENCRYPT_CHANGE:
2267 hci_encrypt_change_evt(hdev, skb);
2268 break;
2269
a9de9248
MH
2270 case HCI_EV_CHANGE_LINK_KEY_COMPLETE:
2271 hci_change_link_key_complete_evt(hdev, skb);
2272 break;
2273
2274 case HCI_EV_REMOTE_FEATURES:
2275 hci_remote_features_evt(hdev, skb);
2276 break;
2277
2278 case HCI_EV_REMOTE_VERSION:
2279 hci_remote_version_evt(hdev, skb);
2280 break;
2281
2282 case HCI_EV_QOS_SETUP_COMPLETE:
2283 hci_qos_setup_complete_evt(hdev, skb);
2284 break;
2285
2286 case HCI_EV_CMD_COMPLETE:
2287 hci_cmd_complete_evt(hdev, skb);
2288 break;
2289
2290 case HCI_EV_CMD_STATUS:
2291 hci_cmd_status_evt(hdev, skb);
2292 break;
2293
2294 case HCI_EV_ROLE_CHANGE:
2295 hci_role_change_evt(hdev, skb);
2296 break;
2297
2298 case HCI_EV_NUM_COMP_PKTS:
2299 hci_num_comp_pkts_evt(hdev, skb);
2300 break;
2301
2302 case HCI_EV_MODE_CHANGE:
2303 hci_mode_change_evt(hdev, skb);
1da177e4
LT
2304 break;
2305
2306 case HCI_EV_PIN_CODE_REQ:
2307 hci_pin_code_request_evt(hdev, skb);
2308 break;
2309
2310 case HCI_EV_LINK_KEY_REQ:
2311 hci_link_key_request_evt(hdev, skb);
2312 break;
2313
2314 case HCI_EV_LINK_KEY_NOTIFY:
2315 hci_link_key_notify_evt(hdev, skb);
2316 break;
2317
2318 case HCI_EV_CLOCK_OFFSET:
2319 hci_clock_offset_evt(hdev, skb);
2320 break;
2321
a8746417
MH
2322 case HCI_EV_PKT_TYPE_CHANGE:
2323 hci_pkt_type_change_evt(hdev, skb);
2324 break;
2325
85a1e930
MH
2326 case HCI_EV_PSCAN_REP_MODE:
2327 hci_pscan_rep_mode_evt(hdev, skb);
2328 break;
2329
a9de9248
MH
2330 case HCI_EV_INQUIRY_RESULT_WITH_RSSI:
2331 hci_inquiry_result_with_rssi_evt(hdev, skb);
04837f64
MH
2332 break;
2333
a9de9248
MH
2334 case HCI_EV_REMOTE_EXT_FEATURES:
2335 hci_remote_ext_features_evt(hdev, skb);
1da177e4
LT
2336 break;
2337
a9de9248
MH
2338 case HCI_EV_SYNC_CONN_COMPLETE:
2339 hci_sync_conn_complete_evt(hdev, skb);
2340 break;
1da177e4 2341
a9de9248
MH
2342 case HCI_EV_SYNC_CONN_CHANGED:
2343 hci_sync_conn_changed_evt(hdev, skb);
2344 break;
1da177e4 2345
a9de9248
MH
2346 case HCI_EV_SNIFF_SUBRATE:
2347 hci_sniff_subrate_evt(hdev, skb);
2348 break;
1da177e4 2349
a9de9248
MH
2350 case HCI_EV_EXTENDED_INQUIRY_RESULT:
2351 hci_extended_inquiry_result_evt(hdev, skb);
2352 break;
1da177e4 2353
0493684e
MH
2354 case HCI_EV_IO_CAPA_REQUEST:
2355 hci_io_capa_request_evt(hdev, skb);
2356 break;
2357
03b555e1
JH
2358 case HCI_EV_IO_CAPA_REPLY:
2359 hci_io_capa_reply_evt(hdev, skb);
2360 break;
2361
0493684e
MH
2362 case HCI_EV_SIMPLE_PAIR_COMPLETE:
2363 hci_simple_pair_complete_evt(hdev, skb);
2364 break;
2365
41a96212
MH
2366 case HCI_EV_REMOTE_HOST_FEATURES:
2367 hci_remote_host_features_evt(hdev, skb);
2368 break;
2369
a9de9248
MH
2370 default:
2371 BT_DBG("%s event 0x%x", hdev->name, event);
1da177e4
LT
2372 break;
2373 }
2374
2375 kfree_skb(skb);
2376 hdev->stat.evt_rx++;
2377}
2378
2379/* Generate internal stack event */
2380void hci_si_event(struct hci_dev *hdev, int type, int dlen, void *data)
2381{
2382 struct hci_event_hdr *hdr;
2383 struct hci_ev_stack_internal *ev;
2384 struct sk_buff *skb;
2385
2386 skb = bt_skb_alloc(HCI_EVENT_HDR_SIZE + sizeof(*ev) + dlen, GFP_ATOMIC);
2387 if (!skb)
2388 return;
2389
2390 hdr = (void *) skb_put(skb, HCI_EVENT_HDR_SIZE);
2391 hdr->evt = HCI_EV_STACK_INTERNAL;
2392 hdr->plen = sizeof(*ev) + dlen;
2393
2394 ev = (void *) skb_put(skb, sizeof(*ev) + dlen);
2395 ev->type = type;
2396 memcpy(ev->data, data, dlen);
2397
576c7d85 2398 bt_cb(skb)->incoming = 1;
a61bbcf2 2399 __net_timestamp(skb);
576c7d85 2400
0d48d939 2401 bt_cb(skb)->pkt_type = HCI_EVENT_PKT;
1da177e4 2402 skb->dev = (void *) hdev;
eec8d2bc 2403 hci_send_to_sock(hdev, skb, NULL);
1da177e4
LT
2404 kfree_skb(skb);
2405}