NFC: Fix LLCP getname socket op
[GitHub/mt8127/android_kernel_alcatel_ttab.git] / net / nfc / llcp / llcp.c
CommitLineData
d646960f
SO
1/*
2 * Copyright (C) 2011 Intel Corporation. All rights reserved.
3 *
4 * This program is free software; you can redistribute it and/or modify
5 * it under the terms of the GNU General Public License as published by
6 * the Free Software Foundation; either version 2 of the License, or
7 * (at your option) any later version.
8 *
9 * This program is distributed in the hope that it will be useful,
10 * but WITHOUT ANY WARRANTY; without even the implied warranty of
11 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
12 * GNU General Public License for more details.
13 *
14 * You should have received a copy of the GNU General Public License
15 * along with this program; if not, write to the
16 * Free Software Foundation, Inc.,
17 * 59 Temple Place - Suite 330, Boston, MA 02111-1307, USA.
18 */
19
20#define pr_fmt(fmt) "llcp: %s: " fmt, __func__
21
22#include <linux/init.h>
23#include <linux/kernel.h>
24#include <linux/list.h>
25#include <linux/nfc.h>
26
27#include "../nfc.h"
28#include "llcp.h"
29
30static u8 llcp_magic[3] = {0x46, 0x66, 0x6d};
31
32static struct list_head llcp_devices;
33
a69f32af 34void nfc_llcp_sock_link(struct llcp_sock_list *l, struct sock *sk)
d646960f 35{
a69f32af
SO
36 write_lock(&l->lock);
37 sk_add_node(sk, &l->head);
38 write_unlock(&l->lock);
39}
d646960f 40
a69f32af
SO
41void nfc_llcp_sock_unlink(struct llcp_sock_list *l, struct sock *sk)
42{
43 write_lock(&l->lock);
44 sk_del_node_init(sk);
45 write_unlock(&l->lock);
46}
d646960f 47
a69f32af
SO
48static void nfc_llcp_socket_release(struct nfc_llcp_local *local)
49{
50 struct sock *sk;
51 struct hlist_node *node, *tmp;
52 struct nfc_llcp_sock *llcp_sock;
d646960f 53
a69f32af 54 write_lock(&local->sockets.lock);
40c75f81 55
a69f32af
SO
56 sk_for_each_safe(sk, node, tmp, &local->sockets.head) {
57 llcp_sock = nfc_llcp_sock(sk);
d646960f 58
a69f32af 59 lock_sock(sk);
d646960f 60
a69f32af
SO
61 if (sk->sk_state == LLCP_CONNECTED)
62 nfc_put_device(llcp_sock->dev);
d646960f 63
a69f32af 64 if (sk->sk_state == LLCP_LISTEN) {
d646960f
SO
65 struct nfc_llcp_sock *lsk, *n;
66 struct sock *accept_sk;
67
a69f32af 68 list_for_each_entry_safe(lsk, n, &llcp_sock->accept_queue,
427a2eb1 69 accept_queue) {
d646960f
SO
70 accept_sk = &lsk->sk;
71 lock_sock(accept_sk);
72
73 nfc_llcp_accept_unlink(accept_sk);
74
75 accept_sk->sk_state = LLCP_CLOSED;
d646960f
SO
76
77 release_sock(accept_sk);
78
79 sock_orphan(accept_sk);
80 }
81 }
82
a69f32af 83 sk->sk_state = LLCP_CLOSED;
d646960f 84
a69f32af 85 release_sock(sk);
d646960f 86
a69f32af 87 sock_orphan(sk);
40c75f81 88
a69f32af 89 sk_del_node_init(sk);
d646960f
SO
90 }
91
a69f32af 92 write_unlock(&local->sockets.lock);
d646960f
SO
93}
94
c7aa1225
SO
95struct nfc_llcp_local *nfc_llcp_local_get(struct nfc_llcp_local *local)
96{
97 kref_get(&local->ref);
98
99 return local;
100}
101
102static void local_release(struct kref *ref)
103{
104 struct nfc_llcp_local *local;
105
106 local = container_of(ref, struct nfc_llcp_local, ref);
107
108 list_del(&local->list);
109 nfc_llcp_socket_release(local);
110 del_timer_sync(&local->link_timer);
111 skb_queue_purge(&local->tx_queue);
112 destroy_workqueue(local->tx_wq);
113 destroy_workqueue(local->rx_wq);
07922bb1 114 destroy_workqueue(local->timeout_wq);
c7aa1225
SO
115 kfree_skb(local->rx_pending);
116 kfree(local);
117}
118
119int nfc_llcp_local_put(struct nfc_llcp_local *local)
120{
a69f32af
SO
121 WARN_ON(local == NULL);
122
123 if (local == NULL)
124 return 0;
125
c7aa1225
SO
126 return kref_put(&local->ref, local_release);
127}
128
b9a76f1d
SO
129static void nfc_llcp_clear_sdp(struct nfc_llcp_local *local)
130{
131 mutex_lock(&local->sdp_lock);
132
133 local->local_wks = 0;
134 local->local_sdp = 0;
135 local->local_sap = 0;
136
137 mutex_unlock(&local->sdp_lock);
138}
139
d646960f
SO
140static void nfc_llcp_timeout_work(struct work_struct *work)
141{
142 struct nfc_llcp_local *local = container_of(work, struct nfc_llcp_local,
427a2eb1 143 timeout_work);
d646960f
SO
144
145 nfc_dep_link_down(local->dev);
146}
147
148static void nfc_llcp_symm_timer(unsigned long data)
149{
150 struct nfc_llcp_local *local = (struct nfc_llcp_local *) data;
151
152 pr_err("SYMM timeout\n");
153
154 queue_work(local->timeout_wq, &local->timeout_work);
155}
156
157struct nfc_llcp_local *nfc_llcp_find_local(struct nfc_dev *dev)
158{
159 struct nfc_llcp_local *local, *n;
160
161 list_for_each_entry_safe(local, n, &llcp_devices, list)
162 if (local->dev == dev)
163 return local;
164
165 pr_debug("No device found\n");
166
167 return NULL;
168}
169
170static char *wks[] = {
171 NULL,
172 NULL, /* SDP */
173 "urn:nfc:sn:ip",
174 "urn:nfc:sn:obex",
175 "urn:nfc:sn:snep",
176};
177
178static int nfc_llcp_wks_sap(char *service_name, size_t service_name_len)
179{
180 int sap, num_wks;
181
182 pr_debug("%s\n", service_name);
183
184 if (service_name == NULL)
185 return -EINVAL;
186
187 num_wks = ARRAY_SIZE(wks);
188
427a2eb1 189 for (sap = 0; sap < num_wks; sap++) {
d646960f
SO
190 if (wks[sap] == NULL)
191 continue;
192
193 if (strncmp(wks[sap], service_name, service_name_len) == 0)
194 return sap;
195 }
196
197 return -EINVAL;
198}
199
200u8 nfc_llcp_get_sdp_ssap(struct nfc_llcp_local *local,
427a2eb1 201 struct nfc_llcp_sock *sock)
d646960f
SO
202{
203 mutex_lock(&local->sdp_lock);
204
205 if (sock->service_name != NULL && sock->service_name_len > 0) {
206 int ssap = nfc_llcp_wks_sap(sock->service_name,
427a2eb1 207 sock->service_name_len);
d646960f
SO
208
209 if (ssap > 0) {
210 pr_debug("WKS %d\n", ssap);
211
212 /* This is a WKS, let's check if it's free */
213 if (local->local_wks & BIT(ssap)) {
214 mutex_unlock(&local->sdp_lock);
215
216 return LLCP_SAP_MAX;
217 }
218
1762c17c 219 set_bit(ssap, &local->local_wks);
d646960f
SO
220 mutex_unlock(&local->sdp_lock);
221
222 return ssap;
223 }
224
225 /*
226 * This is not a well known service,
227 * we should try to find a local SDP free spot
228 */
229 ssap = find_first_zero_bit(&local->local_sdp, LLCP_SDP_NUM_SAP);
230 if (ssap == LLCP_SDP_NUM_SAP) {
231 mutex_unlock(&local->sdp_lock);
232
233 return LLCP_SAP_MAX;
234 }
235
236 pr_debug("SDP ssap %d\n", LLCP_WKS_NUM_SAP + ssap);
237
1762c17c 238 set_bit(ssap, &local->local_sdp);
d646960f
SO
239 mutex_unlock(&local->sdp_lock);
240
241 return LLCP_WKS_NUM_SAP + ssap;
242
243 } else if (sock->ssap != 0) {
244 if (sock->ssap < LLCP_WKS_NUM_SAP) {
1762c17c
SO
245 if (!test_bit(sock->ssap, &local->local_wks)) {
246 set_bit(sock->ssap, &local->local_wks);
d646960f
SO
247 mutex_unlock(&local->sdp_lock);
248
249 return sock->ssap;
250 }
251
252 } else if (sock->ssap < LLCP_SDP_NUM_SAP) {
1762c17c
SO
253 if (!test_bit(sock->ssap - LLCP_WKS_NUM_SAP,
254 &local->local_sdp)) {
255 set_bit(sock->ssap - LLCP_WKS_NUM_SAP,
256 &local->local_sdp);
d646960f
SO
257 mutex_unlock(&local->sdp_lock);
258
259 return sock->ssap;
260 }
261 }
262 }
263
264 mutex_unlock(&local->sdp_lock);
265
266 return LLCP_SAP_MAX;
267}
268
269u8 nfc_llcp_get_local_ssap(struct nfc_llcp_local *local)
270{
271 u8 local_ssap;
272
273 mutex_lock(&local->sdp_lock);
274
275 local_ssap = find_first_zero_bit(&local->local_sap, LLCP_LOCAL_NUM_SAP);
276 if (local_ssap == LLCP_LOCAL_NUM_SAP) {
277 mutex_unlock(&local->sdp_lock);
278 return LLCP_SAP_MAX;
279 }
280
1762c17c 281 set_bit(local_ssap, &local->local_sap);
d646960f
SO
282
283 mutex_unlock(&local->sdp_lock);
284
285 return local_ssap + LLCP_LOCAL_SAP_OFFSET;
286}
287
288void nfc_llcp_put_ssap(struct nfc_llcp_local *local, u8 ssap)
289{
290 u8 local_ssap;
291 unsigned long *sdp;
292
293 if (ssap < LLCP_WKS_NUM_SAP) {
294 local_ssap = ssap;
295 sdp = &local->local_wks;
296 } else if (ssap < LLCP_LOCAL_NUM_SAP) {
297 local_ssap = ssap - LLCP_WKS_NUM_SAP;
298 sdp = &local->local_sdp;
299 } else if (ssap < LLCP_MAX_SAP) {
300 local_ssap = ssap - LLCP_LOCAL_NUM_SAP;
301 sdp = &local->local_sap;
302 } else {
303 return;
304 }
305
306 mutex_lock(&local->sdp_lock);
307
1762c17c 308 clear_bit(local_ssap, sdp);
d646960f
SO
309
310 mutex_unlock(&local->sdp_lock);
311}
312
47807d3d 313u8 *nfc_llcp_general_bytes(struct nfc_dev *dev, size_t *general_bytes_len)
d646960f
SO
314{
315 struct nfc_llcp_local *local;
316
317 local = nfc_llcp_find_local(dev);
318 if (local == NULL) {
319 *general_bytes_len = 0;
320 return NULL;
321 }
322
323 *general_bytes_len = local->gb_len;
324
325 return local->gb;
326}
327
328static int nfc_llcp_build_gb(struct nfc_llcp_local *local)
329{
330 u8 *gb_cur, *version_tlv, version, version_length;
331 u8 *lto_tlv, lto, lto_length;
332 u8 *wks_tlv, wks_length;
56d5876a
SO
333 u8 *miux_tlv, miux_length;
334 __be16 miux;
d646960f
SO
335 u8 gb_len = 0;
336
337 version = LLCP_VERSION_11;
338 version_tlv = nfc_llcp_build_tlv(LLCP_TLV_VERSION, &version,
427a2eb1 339 1, &version_length);
d646960f
SO
340 gb_len += version_length;
341
342 /* 1500 ms */
343 lto = 150;
91b0ade1 344 lto_tlv = nfc_llcp_build_tlv(LLCP_TLV_LTO, &lto, 1, &lto_length);
d646960f
SO
345 gb_len += lto_length;
346
347 pr_debug("Local wks 0x%lx\n", local->local_wks);
348 wks_tlv = nfc_llcp_build_tlv(LLCP_TLV_WKS, (u8 *)&local->local_wks, 2,
427a2eb1 349 &wks_length);
d646960f
SO
350 gb_len += wks_length;
351
56d5876a
SO
352 miux = cpu_to_be16(LLCP_MAX_MIUX);
353 miux_tlv = nfc_llcp_build_tlv(LLCP_TLV_MIUX, (u8 *)&miux, 0,
354 &miux_length);
355 gb_len += miux_length;
356
d646960f
SO
357 gb_len += ARRAY_SIZE(llcp_magic);
358
359 if (gb_len > NFC_MAX_GT_LEN) {
360 kfree(version_tlv);
361 return -EINVAL;
362 }
363
364 gb_cur = local->gb;
365
366 memcpy(gb_cur, llcp_magic, ARRAY_SIZE(llcp_magic));
367 gb_cur += ARRAY_SIZE(llcp_magic);
368
369 memcpy(gb_cur, version_tlv, version_length);
370 gb_cur += version_length;
371
372 memcpy(gb_cur, lto_tlv, lto_length);
373 gb_cur += lto_length;
374
375 memcpy(gb_cur, wks_tlv, wks_length);
376 gb_cur += wks_length;
377
56d5876a
SO
378 memcpy(gb_cur, miux_tlv, miux_length);
379 gb_cur += miux_length;
380
d646960f
SO
381 kfree(version_tlv);
382 kfree(lto_tlv);
383
384 local->gb_len = gb_len;
385
386 return 0;
387}
388
389int nfc_llcp_set_remote_gb(struct nfc_dev *dev, u8 *gb, u8 gb_len)
390{
391 struct nfc_llcp_local *local = nfc_llcp_find_local(dev);
392
393 if (local == NULL) {
394 pr_err("No LLCP device\n");
395 return -ENODEV;
396 }
397
398 memset(local->remote_gb, 0, NFC_MAX_GT_LEN);
399 memcpy(local->remote_gb, gb, gb_len);
400 local->remote_gb_len = gb_len;
401
427a2eb1 402 if (local->remote_gb == NULL || local->remote_gb_len == 0)
d646960f
SO
403 return -ENODEV;
404
405 if (memcmp(local->remote_gb, llcp_magic, 3)) {
406 pr_err("MAC does not support LLCP\n");
407 return -EINVAL;
408 }
409
7a06e586
SO
410 return nfc_llcp_parse_gb_tlv(local,
411 &local->remote_gb[3],
412 local->remote_gb_len - 3);
d646960f
SO
413}
414
d646960f
SO
415static u8 nfc_llcp_dsap(struct sk_buff *pdu)
416{
417 return (pdu->data[0] & 0xfc) >> 2;
418}
419
420static u8 nfc_llcp_ptype(struct sk_buff *pdu)
421{
422 return ((pdu->data[0] & 0x03) << 2) | ((pdu->data[1] & 0xc0) >> 6);
423}
424
425static u8 nfc_llcp_ssap(struct sk_buff *pdu)
426{
427 return pdu->data[1] & 0x3f;
428}
429
430static u8 nfc_llcp_ns(struct sk_buff *pdu)
431{
432 return pdu->data[2] >> 4;
433}
434
435static u8 nfc_llcp_nr(struct sk_buff *pdu)
436{
437 return pdu->data[2] & 0xf;
438}
439
440static void nfc_llcp_set_nrns(struct nfc_llcp_sock *sock, struct sk_buff *pdu)
441{
279cf174 442 pdu->data[2] = (sock->send_n << 4) | (sock->recv_n);
d646960f
SO
443 sock->send_n = (sock->send_n + 1) % 16;
444 sock->recv_ack_n = (sock->recv_n - 1) % 16;
445}
446
84457960
SO
447static void nfc_llcp_tx_work(struct work_struct *work)
448{
449 struct nfc_llcp_local *local = container_of(work, struct nfc_llcp_local,
450 tx_work);
451 struct sk_buff *skb;
452 struct sock *sk;
453 struct nfc_llcp_sock *llcp_sock;
454
455 skb = skb_dequeue(&local->tx_queue);
456 if (skb != NULL) {
457 sk = skb->sk;
458 llcp_sock = nfc_llcp_sock(sk);
459 if (llcp_sock != NULL) {
460 int ret;
461
462 pr_debug("Sending pending skb\n");
463 print_hex_dump(KERN_DEBUG, "LLCP Tx: ",
464 DUMP_PREFIX_OFFSET, 16, 1,
465 skb->data, skb->len, true);
466
467 ret = nfc_data_exchange(local->dev, local->target_idx,
468 skb, nfc_llcp_recv, local);
469
470 if (!ret && nfc_llcp_ptype(skb) == LLCP_PDU_I) {
471 skb = skb_get(skb);
472 skb_queue_tail(&llcp_sock->tx_pending_queue,
473 skb);
474 }
475 } else {
476 nfc_llcp_send_symm(local->dev);
477 }
478 } else {
479 nfc_llcp_send_symm(local->dev);
480 }
481
482 mod_timer(&local->link_timer,
483 jiffies + msecs_to_jiffies(2 * local->remote_lto));
484}
485
a69f32af
SO
486static struct nfc_llcp_sock *nfc_llcp_connecting_sock_get(struct nfc_llcp_local *local,
487 u8 ssap)
488{
489 struct sock *sk;
490 struct nfc_llcp_sock *llcp_sock;
491 struct hlist_node *node;
492
493 read_lock(&local->connecting_sockets.lock);
494
495 sk_for_each(sk, node, &local->connecting_sockets.head) {
496 llcp_sock = nfc_llcp_sock(sk);
497
5a0f6f3b
SO
498 if (llcp_sock->ssap == ssap) {
499 sock_hold(&llcp_sock->sk);
a69f32af 500 goto out;
5a0f6f3b 501 }
a69f32af
SO
502 }
503
504 llcp_sock = NULL;
505
506out:
507 read_unlock(&local->connecting_sockets.lock);
508
a69f32af
SO
509 return llcp_sock;
510}
511
d646960f 512static struct nfc_llcp_sock *nfc_llcp_sock_get(struct nfc_llcp_local *local,
427a2eb1 513 u8 ssap, u8 dsap)
d646960f 514{
a69f32af
SO
515 struct sock *sk;
516 struct hlist_node *node;
517 struct nfc_llcp_sock *llcp_sock;
d646960f 518
ff353d86
SO
519 pr_debug("ssap dsap %d %d\n", ssap, dsap);
520
d646960f
SO
521 if (ssap == 0 && dsap == 0)
522 return NULL;
523
a69f32af
SO
524 read_lock(&local->sockets.lock);
525
526 llcp_sock = NULL;
d646960f 527
a69f32af
SO
528 sk_for_each(sk, node, &local->sockets.head) {
529 llcp_sock = nfc_llcp_sock(sk);
d646960f 530
a69f32af
SO
531 if (llcp_sock->ssap == ssap &&
532 llcp_sock->dsap == dsap)
533 break;
d646960f
SO
534 }
535
a69f32af
SO
536 read_unlock(&local->sockets.lock);
537
538 if (llcp_sock == NULL)
539 return NULL;
540
541 sock_hold(&llcp_sock->sk);
542
543 return llcp_sock;
544}
545
546static struct nfc_llcp_sock *nfc_llcp_sock_get_sn(struct nfc_llcp_local *local,
547 u8 *sn, size_t sn_len)
548{
549 struct sock *sk;
550 struct hlist_node *node;
551 struct nfc_llcp_sock *llcp_sock;
552
553 pr_debug("sn %zd\n", sn_len);
554
555 if (sn == NULL || sn_len == 0)
556 return NULL;
557
558 read_lock(&local->sockets.lock);
559
560 llcp_sock = NULL;
561
562 sk_for_each(sk, node, &local->sockets.head) {
563 llcp_sock = nfc_llcp_sock(sk);
564
565 if (llcp_sock->sk.sk_state != LLCP_LISTEN)
566 continue;
567
568 if (llcp_sock->service_name == NULL ||
569 llcp_sock->service_name_len == 0)
570 continue;
571
572 if (llcp_sock->service_name_len != sn_len)
573 continue;
574
575 if (memcmp(sn, llcp_sock->service_name, sn_len) == 0)
576 break;
d646960f
SO
577 }
578
a69f32af 579 read_unlock(&local->sockets.lock);
d646960f 580
a69f32af
SO
581 if (llcp_sock == NULL)
582 return NULL;
d646960f 583
a69f32af
SO
584 sock_hold(&llcp_sock->sk);
585
586 return llcp_sock;
d646960f
SO
587}
588
589static void nfc_llcp_sock_put(struct nfc_llcp_sock *sock)
590{
591 sock_put(&sock->sk);
592}
593
594static u8 *nfc_llcp_connect_sn(struct sk_buff *skb, size_t *sn_len)
595{
596 u8 *tlv = &skb->data[2], type, length;
597 size_t tlv_array_len = skb->len - LLCP_HEADER_SIZE, offset = 0;
598
599 while (offset < tlv_array_len) {
600 type = tlv[0];
601 length = tlv[1];
602
603 pr_debug("type 0x%x length %d\n", type, length);
604
605 if (type == LLCP_TLV_SN) {
606 *sn_len = length;
607 return &tlv[2];
608 }
609
610 offset += length + 2;
611 tlv += length + 2;
612 }
613
614 return NULL;
615}
616
617static void nfc_llcp_recv_connect(struct nfc_llcp_local *local,
427a2eb1 618 struct sk_buff *skb)
d646960f
SO
619{
620 struct sock *new_sk, *parent;
621 struct nfc_llcp_sock *sock, *new_sock;
a69f32af 622 u8 dsap, ssap, reason;
d646960f
SO
623
624 dsap = nfc_llcp_dsap(skb);
625 ssap = nfc_llcp_ssap(skb);
626
627 pr_debug("%d %d\n", dsap, ssap);
628
d646960f 629 if (dsap != LLCP_SAP_SDP) {
a69f32af
SO
630 sock = nfc_llcp_sock_get(local, dsap, LLCP_SAP_SDP);
631 if (sock == NULL || sock->sk.sk_state != LLCP_LISTEN) {
d646960f
SO
632 reason = LLCP_DM_NOBOUND;
633 goto fail;
634 }
d646960f
SO
635 } else {
636 u8 *sn;
637 size_t sn_len;
638
639 sn = nfc_llcp_connect_sn(skb, &sn_len);
640 if (sn == NULL) {
641 reason = LLCP_DM_NOBOUND;
642 goto fail;
643 }
644
645 pr_debug("Service name length %zu\n", sn_len);
646
a69f32af
SO
647 sock = nfc_llcp_sock_get_sn(local, sn, sn_len);
648 if (sock == NULL) {
649 reason = LLCP_DM_NOBOUND;
650 goto fail;
d646960f 651 }
d646960f
SO
652 }
653
a69f32af 654 lock_sock(&sock->sk);
d646960f 655
d646960f
SO
656 parent = &sock->sk;
657
658 if (sk_acceptq_is_full(parent)) {
659 reason = LLCP_DM_REJ;
660 release_sock(&sock->sk);
661 sock_put(&sock->sk);
662 goto fail;
663 }
664
427a2eb1 665 new_sk = nfc_llcp_sock_alloc(NULL, parent->sk_type, GFP_ATOMIC);
d646960f
SO
666 if (new_sk == NULL) {
667 reason = LLCP_DM_REJ;
668 release_sock(&sock->sk);
669 sock_put(&sock->sk);
670 goto fail;
671 }
672
673 new_sock = nfc_llcp_sock(new_sk);
674 new_sock->dev = local->dev;
c7aa1225 675 new_sock->local = nfc_llcp_local_get(local);
93d7e490 676 new_sock->miu = local->remote_miu;
d646960f 677 new_sock->nfc_protocol = sock->nfc_protocol;
a69f32af 678 new_sock->ssap = sock->ssap;
d646960f 679 new_sock->dsap = ssap;
025f1520 680 new_sock->target_idx = local->target_idx;
d646960f
SO
681 new_sock->parent = parent;
682
7a06e586
SO
683 nfc_llcp_parse_connection_tlv(new_sock, &skb->data[LLCP_HEADER_SIZE],
684 skb->len - LLCP_HEADER_SIZE);
685
d646960f
SO
686 pr_debug("new sock %p sk %p\n", new_sock, &new_sock->sk);
687
a69f32af 688 nfc_llcp_sock_link(&local->sockets, new_sk);
d646960f
SO
689
690 nfc_llcp_accept_enqueue(&sock->sk, new_sk);
691
692 nfc_get_device(local->dev->idx);
693
694 new_sk->sk_state = LLCP_CONNECTED;
695
696 /* Wake the listening processes */
697 parent->sk_data_ready(parent, 0);
698
699 /* Send CC */
700 nfc_llcp_send_cc(new_sock);
701
702 release_sock(&sock->sk);
703 sock_put(&sock->sk);
704
705 return;
706
707fail:
708 /* Send DM */
709 nfc_llcp_send_dm(local, dsap, ssap, reason);
710
711 return;
712
713}
714
d094afa1 715int nfc_llcp_queue_i_frames(struct nfc_llcp_sock *sock)
4722d2b7 716{
d094afa1 717 int nr_frames = 0;
4722d2b7
SO
718 struct nfc_llcp_local *local = sock->local;
719
720 pr_debug("Remote ready %d tx queue len %d remote rw %d",
427a2eb1 721 sock->remote_ready, skb_queue_len(&sock->tx_pending_queue),
7a06e586 722 sock->rw);
4722d2b7
SO
723
724 /* Try to queue some I frames for transmission */
725 while (sock->remote_ready &&
7a06e586 726 skb_queue_len(&sock->tx_pending_queue) < sock->rw) {
84457960 727 struct sk_buff *pdu;
4722d2b7
SO
728
729 pdu = skb_dequeue(&sock->tx_queue);
730 if (pdu == NULL)
731 break;
732
733 /* Update N(S)/N(R) */
734 nfc_llcp_set_nrns(sock, pdu);
735
4722d2b7 736 skb_queue_tail(&local->tx_queue, pdu);
d094afa1 737 nr_frames++;
4722d2b7 738 }
d094afa1
SO
739
740 return nr_frames;
4722d2b7
SO
741}
742
d646960f 743static void nfc_llcp_recv_hdlc(struct nfc_llcp_local *local,
427a2eb1 744 struct sk_buff *skb)
d646960f
SO
745{
746 struct nfc_llcp_sock *llcp_sock;
747 struct sock *sk;
748 u8 dsap, ssap, ptype, ns, nr;
749
750 ptype = nfc_llcp_ptype(skb);
751 dsap = nfc_llcp_dsap(skb);
752 ssap = nfc_llcp_ssap(skb);
753 ns = nfc_llcp_ns(skb);
754 nr = nfc_llcp_nr(skb);
755
756 pr_debug("%d %d R %d S %d\n", dsap, ssap, nr, ns);
757
758 llcp_sock = nfc_llcp_sock_get(local, dsap, ssap);
759 if (llcp_sock == NULL) {
760 nfc_llcp_send_dm(local, dsap, ssap, LLCP_DM_NOCONN);
761 return;
762 }
763
764 sk = &llcp_sock->sk;
765 lock_sock(sk);
766 if (sk->sk_state == LLCP_CLOSED) {
767 release_sock(sk);
768 nfc_llcp_sock_put(llcp_sock);
769 }
770
d646960f
SO
771 /* Pass the payload upstream */
772 if (ptype == LLCP_PDU_I) {
773 pr_debug("I frame, queueing on %p\n", &llcp_sock->sk);
774
53aef920
SO
775 if (ns == llcp_sock->recv_n)
776 llcp_sock->recv_n = (llcp_sock->recv_n + 1) % 16;
777 else
778 pr_err("Received out of sequence I PDU\n");
779
d646960f
SO
780 skb_pull(skb, LLCP_HEADER_SIZE + LLCP_SEQUENCE_SIZE);
781 if (sock_queue_rcv_skb(&llcp_sock->sk, skb)) {
782 pr_err("receive queue is full\n");
783 skb_queue_head(&llcp_sock->tx_backlog_queue, skb);
784 }
785 }
786
787 /* Remove skbs from the pending queue */
788 if (llcp_sock->send_ack_n != nr) {
789 struct sk_buff *s, *tmp;
790
791 llcp_sock->send_ack_n = nr;
792
84457960
SO
793 /* Remove and free all skbs until ns == nr */
794 skb_queue_walk_safe(&llcp_sock->tx_pending_queue, s, tmp) {
795 skb_unlink(s, &llcp_sock->tx_pending_queue);
796 kfree_skb(s);
797
798 if (nfc_llcp_ns(s) == nr)
799 break;
800 }
801
802 /* Re-queue the remaining skbs for transmission */
803 skb_queue_reverse_walk_safe(&llcp_sock->tx_pending_queue,
804 s, tmp) {
805 skb_unlink(s, &llcp_sock->tx_pending_queue);
806 skb_queue_head(&local->tx_queue, s);
807 }
d646960f
SO
808 }
809
53aef920
SO
810 if (ptype == LLCP_PDU_RR)
811 llcp_sock->remote_ready = true;
427a2eb1 812 else if (ptype == LLCP_PDU_RNR)
53aef920
SO
813 llcp_sock->remote_ready = false;
814
56af2568 815 if (nfc_llcp_queue_i_frames(llcp_sock) == 0 && ptype == LLCP_PDU_I)
d094afa1 816 nfc_llcp_send_rr(llcp_sock);
d646960f
SO
817
818 release_sock(sk);
819 nfc_llcp_sock_put(llcp_sock);
820}
821
822static void nfc_llcp_recv_disc(struct nfc_llcp_local *local,
427a2eb1 823 struct sk_buff *skb)
d646960f
SO
824{
825 struct nfc_llcp_sock *llcp_sock;
826 struct sock *sk;
827 u8 dsap, ssap;
828
829 dsap = nfc_llcp_dsap(skb);
830 ssap = nfc_llcp_ssap(skb);
831
832 llcp_sock = nfc_llcp_sock_get(local, dsap, ssap);
833 if (llcp_sock == NULL) {
834 nfc_llcp_send_dm(local, dsap, ssap, LLCP_DM_NOCONN);
835 return;
836 }
837
838 sk = &llcp_sock->sk;
839 lock_sock(sk);
840 if (sk->sk_state == LLCP_CLOSED) {
841 release_sock(sk);
842 nfc_llcp_sock_put(llcp_sock);
843 }
844
d646960f
SO
845 if (sk->sk_state == LLCP_CONNECTED) {
846 nfc_put_device(local->dev);
847 sk->sk_state = LLCP_CLOSED;
848 sk->sk_state_change(sk);
849 }
850
851 nfc_llcp_send_dm(local, dsap, ssap, LLCP_DM_DISC);
852
853 release_sock(sk);
854 nfc_llcp_sock_put(llcp_sock);
855}
856
427a2eb1 857static void nfc_llcp_recv_cc(struct nfc_llcp_local *local, struct sk_buff *skb)
d646960f
SO
858{
859 struct nfc_llcp_sock *llcp_sock;
ff353d86 860 struct sock *sk;
d646960f
SO
861 u8 dsap, ssap;
862
d646960f
SO
863 dsap = nfc_llcp_dsap(skb);
864 ssap = nfc_llcp_ssap(skb);
865
a69f32af 866 llcp_sock = nfc_llcp_connecting_sock_get(local, dsap);
d646960f
SO
867 if (llcp_sock == NULL) {
868 pr_err("Invalid CC\n");
869 nfc_llcp_send_dm(local, dsap, ssap, LLCP_DM_NOCONN);
870
871 return;
872 }
873
ff353d86 874 sk = &llcp_sock->sk;
d646960f 875
a69f32af
SO
876 /* Unlink from connecting and link to the client array */
877 nfc_llcp_sock_unlink(&local->connecting_sockets, sk);
878 nfc_llcp_sock_link(&local->sockets, sk);
879 llcp_sock->dsap = ssap;
880
7a06e586
SO
881 nfc_llcp_parse_connection_tlv(llcp_sock, &skb->data[LLCP_HEADER_SIZE],
882 skb->len - LLCP_HEADER_SIZE);
d646960f 883
ff353d86
SO
884 sk->sk_state = LLCP_CONNECTED;
885 sk->sk_state_change(sk);
886
d646960f
SO
887 nfc_llcp_sock_put(llcp_sock);
888}
889
890static void nfc_llcp_rx_work(struct work_struct *work)
891{
892 struct nfc_llcp_local *local = container_of(work, struct nfc_llcp_local,
427a2eb1 893 rx_work);
d646960f
SO
894 u8 dsap, ssap, ptype;
895 struct sk_buff *skb;
896
897 skb = local->rx_pending;
898 if (skb == NULL) {
899 pr_debug("No pending SKB\n");
900 return;
901 }
902
903 ptype = nfc_llcp_ptype(skb);
904 dsap = nfc_llcp_dsap(skb);
905 ssap = nfc_llcp_ssap(skb);
906
907 pr_debug("ptype 0x%x dsap 0x%x ssap 0x%x\n", ptype, dsap, ssap);
908
4be646ec
SO
909 if (ptype != LLCP_PDU_SYMM)
910 print_hex_dump(KERN_DEBUG, "LLCP Rx: ", DUMP_PREFIX_OFFSET,
911 16, 1, skb->data, skb->len, true);
912
d646960f
SO
913 switch (ptype) {
914 case LLCP_PDU_SYMM:
915 pr_debug("SYMM\n");
916 break;
917
918 case LLCP_PDU_CONNECT:
919 pr_debug("CONNECT\n");
920 nfc_llcp_recv_connect(local, skb);
921 break;
922
923 case LLCP_PDU_DISC:
924 pr_debug("DISC\n");
925 nfc_llcp_recv_disc(local, skb);
926 break;
927
928 case LLCP_PDU_CC:
929 pr_debug("CC\n");
930 nfc_llcp_recv_cc(local, skb);
931 break;
932
933 case LLCP_PDU_I:
934 case LLCP_PDU_RR:
53aef920 935 case LLCP_PDU_RNR:
d646960f
SO
936 pr_debug("I frame\n");
937 nfc_llcp_recv_hdlc(local, skb);
938 break;
939
940 }
941
942 queue_work(local->tx_wq, &local->tx_work);
943 kfree_skb(local->rx_pending);
944 local->rx_pending = NULL;
945
946 return;
947}
948
949void nfc_llcp_recv(void *data, struct sk_buff *skb, int err)
950{
951 struct nfc_llcp_local *local = (struct nfc_llcp_local *) data;
952
953 pr_debug("Received an LLCP PDU\n");
954 if (err < 0) {
427a2eb1 955 pr_err("err %d\n", err);
d646960f
SO
956 return;
957 }
958
959 local->rx_pending = skb_get(skb);
960 del_timer(&local->link_timer);
961 queue_work(local->rx_wq, &local->rx_work);
962
963 return;
964}
965
73167ced
SO
966int nfc_llcp_data_received(struct nfc_dev *dev, struct sk_buff *skb)
967{
968 struct nfc_llcp_local *local;
969
970 local = nfc_llcp_find_local(dev);
971 if (local == NULL)
972 return -ENODEV;
973
974 local->rx_pending = skb_get(skb);
975 del_timer(&local->link_timer);
976 queue_work(local->rx_wq, &local->rx_work);
977
978 return 0;
979}
980
d646960f
SO
981void nfc_llcp_mac_is_down(struct nfc_dev *dev)
982{
983 struct nfc_llcp_local *local;
984
985 local = nfc_llcp_find_local(dev);
986 if (local == NULL)
987 return;
988
b9a76f1d
SO
989 nfc_llcp_clear_sdp(local);
990
d646960f
SO
991 /* Close and purge all existing sockets */
992 nfc_llcp_socket_release(local);
993}
994
995void nfc_llcp_mac_is_up(struct nfc_dev *dev, u32 target_idx,
996 u8 comm_mode, u8 rf_mode)
997{
998 struct nfc_llcp_local *local;
999
1000 pr_debug("rf mode %d\n", rf_mode);
1001
1002 local = nfc_llcp_find_local(dev);
1003 if (local == NULL)
1004 return;
1005
1006 local->target_idx = target_idx;
1007 local->comm_mode = comm_mode;
1008 local->rf_mode = rf_mode;
1009
1010 if (rf_mode == NFC_RF_INITIATOR) {
1011 pr_debug("Queueing Tx work\n");
1012
1013 queue_work(local->tx_wq, &local->tx_work);
1014 } else {
1015 mod_timer(&local->link_timer,
427a2eb1 1016 jiffies + msecs_to_jiffies(local->remote_lto));
d646960f
SO
1017 }
1018}
1019
1020int nfc_llcp_register_device(struct nfc_dev *ndev)
1021{
1022 struct device *dev = &ndev->dev;
1023 struct nfc_llcp_local *local;
1024 char name[32];
1025 int err;
1026
1027 local = kzalloc(sizeof(struct nfc_llcp_local), GFP_KERNEL);
1028 if (local == NULL)
1029 return -ENOMEM;
1030
1031 local->dev = ndev;
1032 INIT_LIST_HEAD(&local->list);
c7aa1225 1033 kref_init(&local->ref);
d646960f 1034 mutex_init(&local->sdp_lock);
d646960f
SO
1035 init_timer(&local->link_timer);
1036 local->link_timer.data = (unsigned long) local;
1037 local->link_timer.function = nfc_llcp_symm_timer;
1038
1039 skb_queue_head_init(&local->tx_queue);
1040 INIT_WORK(&local->tx_work, nfc_llcp_tx_work);
1041 snprintf(name, sizeof(name), "%s_llcp_tx_wq", dev_name(dev));
427a2eb1
SO
1042 local->tx_wq =
1043 alloc_workqueue(name,
1044 WQ_NON_REENTRANT | WQ_UNBOUND | WQ_MEM_RECLAIM,
1045 1);
d646960f
SO
1046 if (local->tx_wq == NULL) {
1047 err = -ENOMEM;
1048 goto err_local;
1049 }
1050
1051 local->rx_pending = NULL;
1052 INIT_WORK(&local->rx_work, nfc_llcp_rx_work);
1053 snprintf(name, sizeof(name), "%s_llcp_rx_wq", dev_name(dev));
427a2eb1
SO
1054 local->rx_wq =
1055 alloc_workqueue(name,
1056 WQ_NON_REENTRANT | WQ_UNBOUND | WQ_MEM_RECLAIM,
1057 1);
d646960f
SO
1058 if (local->rx_wq == NULL) {
1059 err = -ENOMEM;
1060 goto err_tx_wq;
1061 }
1062
1063 INIT_WORK(&local->timeout_work, nfc_llcp_timeout_work);
1064 snprintf(name, sizeof(name), "%s_llcp_timeout_wq", dev_name(dev));
427a2eb1
SO
1065 local->timeout_wq =
1066 alloc_workqueue(name,
1067 WQ_NON_REENTRANT | WQ_UNBOUND | WQ_MEM_RECLAIM,
1068 1);
d646960f
SO
1069 if (local->timeout_wq == NULL) {
1070 err = -ENOMEM;
1071 goto err_rx_wq;
1072 }
1073
a69f32af
SO
1074 local->sockets.lock = __RW_LOCK_UNLOCKED(local->sockets.lock);
1075 local->connecting_sockets.lock = __RW_LOCK_UNLOCKED(local->connecting_sockets.lock);
1076
d646960f
SO
1077 nfc_llcp_build_gb(local);
1078
1079 local->remote_miu = LLCP_DEFAULT_MIU;
1080 local->remote_lto = LLCP_DEFAULT_LTO;
d646960f
SO
1081
1082 list_add(&llcp_devices, &local->list);
1083
1084 return 0;
1085
1086err_rx_wq:
1087 destroy_workqueue(local->rx_wq);
1088
1089err_tx_wq:
1090 destroy_workqueue(local->tx_wq);
1091
1092err_local:
1093 kfree(local);
1094
1095 return 0;
1096}
1097
1098void nfc_llcp_unregister_device(struct nfc_dev *dev)
1099{
1100 struct nfc_llcp_local *local = nfc_llcp_find_local(dev);
1101
1102 if (local == NULL) {
1103 pr_debug("No such device\n");
1104 return;
1105 }
1106
c7aa1225 1107 nfc_llcp_local_put(local);
d646960f
SO
1108}
1109
1110int __init nfc_llcp_init(void)
1111{
1112 INIT_LIST_HEAD(&llcp_devices);
1113
1114 return nfc_llcp_sock_init();
1115}
1116
1117void nfc_llcp_exit(void)
1118{
1119 nfc_llcp_sock_exit();
1120}