Bluetooth: Add set_io_capability management command
[GitHub/mt8127/android_kernel_alcatel_ttab.git] / net / bluetooth / hci_conn.c
CommitLineData
8e87d142 1/*
1da177e4 2 BlueZ - Bluetooth protocol stack for Linux
2d0a0346 3 Copyright (c) 2000-2001, 2010, Code Aurora Forum. All rights reserved.
1da177e4
LT
4
5 Written 2000,2001 by Maxim Krasnyansky <maxk@qualcomm.com>
6
7 This program is free software; you can redistribute it and/or modify
8 it under the terms of the GNU General Public License version 2 as
9 published by the Free Software Foundation;
10
11 THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS
12 OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
13 FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT OF THIRD PARTY RIGHTS.
14 IN NO EVENT SHALL THE COPYRIGHT HOLDER(S) AND AUTHOR(S) BE LIABLE FOR ANY
8e87d142
YH
15 CLAIM, OR ANY SPECIAL INDIRECT OR CONSEQUENTIAL DAMAGES, OR ANY DAMAGES
16 WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
17 ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
1da177e4
LT
18 OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
19
8e87d142
YH
20 ALL LIABILITY, INCLUDING LIABILITY FOR INFRINGEMENT OF ANY PATENTS,
21 COPYRIGHTS, TRADEMARKS OR OTHER RIGHTS, RELATING TO USE OF THIS
1da177e4
LT
22 SOFTWARE IS DISCLAIMED.
23*/
24
25/* Bluetooth HCI connection handling. */
26
1da177e4
LT
27#include <linux/module.h>
28
29#include <linux/types.h>
30#include <linux/errno.h>
31#include <linux/kernel.h>
1da177e4
LT
32#include <linux/slab.h>
33#include <linux/poll.h>
34#include <linux/fcntl.h>
35#include <linux/init.h>
36#include <linux/skbuff.h>
37#include <linux/interrupt.h>
38#include <linux/notifier.h>
39#include <net/sock.h>
40
41#include <asm/system.h>
70f23020 42#include <linux/uaccess.h>
1da177e4
LT
43#include <asm/unaligned.h>
44
45#include <net/bluetooth/bluetooth.h>
46#include <net/bluetooth/hci_core.h>
47
4c67bc74 48void hci_acl_connect(struct hci_conn *conn)
1da177e4
LT
49{
50 struct hci_dev *hdev = conn->hdev;
51 struct inquiry_entry *ie;
52 struct hci_cp_create_conn cp;
53
54 BT_DBG("%p", conn);
55
56 conn->state = BT_CONNECT;
a8746417
MH
57 conn->out = 1;
58
1da177e4
LT
59 conn->link_mode = HCI_LM_MASTER;
60
4c67bc74
MH
61 conn->attempt++;
62
e4e8e37c
MH
63 conn->link_policy = hdev->link_policy;
64
1da177e4
LT
65 memset(&cp, 0, sizeof(cp));
66 bacpy(&cp.bdaddr, &conn->dst);
67 cp.pscan_rep_mode = 0x02;
68
70f23020
AE
69 ie = hci_inquiry_cache_lookup(hdev, &conn->dst);
70 if (ie) {
41a96212
MH
71 if (inquiry_entry_age(ie) <= INQUIRY_ENTRY_AGE_MAX) {
72 cp.pscan_rep_mode = ie->data.pscan_rep_mode;
73 cp.pscan_mode = ie->data.pscan_mode;
74 cp.clock_offset = ie->data.clock_offset |
75 cpu_to_le16(0x8000);
76 }
77
1da177e4 78 memcpy(conn->dev_class, ie->data.dev_class, 3);
41a96212 79 conn->ssp_mode = ie->data.ssp_mode;
1da177e4
LT
80 }
81
a8746417 82 cp.pkt_type = cpu_to_le16(conn->pkt_type);
1da177e4 83 if (lmp_rswitch_capable(hdev) && !(hdev->link_mode & HCI_LM_MASTER))
b6a0dc82 84 cp.role_switch = 0x01;
1da177e4 85 else
b6a0dc82 86 cp.role_switch = 0x00;
4c67bc74 87
a9de9248 88 hci_send_cmd(hdev, HCI_OP_CREATE_CONN, sizeof(cp), &cp);
1da177e4
LT
89}
90
6ac59344
MH
91static void hci_acl_connect_cancel(struct hci_conn *conn)
92{
93 struct hci_cp_create_conn_cancel cp;
94
95 BT_DBG("%p", conn);
96
97 if (conn->hdev->hci_ver < 2)
98 return;
99
100 bacpy(&cp.bdaddr, &conn->dst);
a9de9248 101 hci_send_cmd(conn->hdev, HCI_OP_CREATE_CONN_CANCEL, sizeof(cp), &cp);
6ac59344
MH
102}
103
1da177e4
LT
104void hci_acl_disconn(struct hci_conn *conn, __u8 reason)
105{
106 struct hci_cp_disconnect cp;
107
108 BT_DBG("%p", conn);
109
110 conn->state = BT_DISCONN;
111
aca3192c 112 cp.handle = cpu_to_le16(conn->handle);
1da177e4 113 cp.reason = reason;
a9de9248 114 hci_send_cmd(conn->hdev, HCI_OP_DISCONNECT, sizeof(cp), &cp);
1da177e4
LT
115}
116
117void hci_add_sco(struct hci_conn *conn, __u16 handle)
118{
119 struct hci_dev *hdev = conn->hdev;
120 struct hci_cp_add_sco cp;
121
122 BT_DBG("%p", conn);
123
124 conn->state = BT_CONNECT;
125 conn->out = 1;
126
efc7688b
MH
127 conn->attempt++;
128
aca3192c 129 cp.handle = cpu_to_le16(handle);
a8746417 130 cp.pkt_type = cpu_to_le16(conn->pkt_type);
1da177e4 131
a9de9248 132 hci_send_cmd(hdev, HCI_OP_ADD_SCO, sizeof(cp), &cp);
1da177e4
LT
133}
134
b6a0dc82
MH
135void hci_setup_sync(struct hci_conn *conn, __u16 handle)
136{
137 struct hci_dev *hdev = conn->hdev;
138 struct hci_cp_setup_sync_conn cp;
139
140 BT_DBG("%p", conn);
141
142 conn->state = BT_CONNECT;
143 conn->out = 1;
144
efc7688b
MH
145 conn->attempt++;
146
b6a0dc82 147 cp.handle = cpu_to_le16(handle);
a8746417 148 cp.pkt_type = cpu_to_le16(conn->pkt_type);
b6a0dc82
MH
149
150 cp.tx_bandwidth = cpu_to_le32(0x00001f40);
151 cp.rx_bandwidth = cpu_to_le32(0x00001f40);
152 cp.max_latency = cpu_to_le16(0xffff);
153 cp.voice_setting = cpu_to_le16(hdev->voice_setting);
154 cp.retrans_effort = 0xff;
155
156 hci_send_cmd(hdev, HCI_OP_SETUP_SYNC_CONN, sizeof(cp), &cp);
157}
158
e73439d8
MH
159/* Device _must_ be locked */
160void hci_sco_setup(struct hci_conn *conn, __u8 status)
161{
162 struct hci_conn *sco = conn->link;
163
164 BT_DBG("%p", conn);
165
166 if (!sco)
167 return;
168
169 if (!status) {
170 if (lmp_esco_capable(conn->hdev))
171 hci_setup_sync(sco, conn->handle);
172 else
173 hci_add_sco(sco, conn->handle);
174 } else {
175 hci_proto_connect_cfm(sco, status);
176 hci_conn_del(sco);
177 }
178}
179
1da177e4
LT
180static void hci_conn_timeout(unsigned long arg)
181{
04837f64
MH
182 struct hci_conn *conn = (void *) arg;
183 struct hci_dev *hdev = conn->hdev;
2950f21a 184 __u8 reason;
1da177e4
LT
185
186 BT_DBG("conn %p state %d", conn, conn->state);
187
188 if (atomic_read(&conn->refcnt))
189 return;
190
191 hci_dev_lock(hdev);
6ac59344
MH
192
193 switch (conn->state) {
194 case BT_CONNECT:
769be974 195 case BT_CONNECT2:
1b0336bb 196 if (conn->type == ACL_LINK && conn->out)
b6a0dc82 197 hci_acl_connect_cancel(conn);
6ac59344 198 break;
769be974 199 case BT_CONFIG:
8e87d142 200 case BT_CONNECTED:
2950f21a
MH
201 reason = hci_proto_disconn_ind(conn);
202 hci_acl_disconn(conn, reason);
6ac59344
MH
203 break;
204 default:
1da177e4 205 conn->state = BT_CLOSED;
6ac59344
MH
206 break;
207 }
208
1da177e4 209 hci_dev_unlock(hdev);
1da177e4
LT
210}
211
04837f64 212static void hci_conn_idle(unsigned long arg)
1da177e4 213{
04837f64
MH
214 struct hci_conn *conn = (void *) arg;
215
216 BT_DBG("conn %p mode %d", conn, conn->mode);
217
218 hci_conn_enter_sniff_mode(conn);
1da177e4
LT
219}
220
221struct hci_conn *hci_conn_add(struct hci_dev *hdev, int type, bdaddr_t *dst)
222{
223 struct hci_conn *conn;
224
225 BT_DBG("%s dst %s", hdev->name, batostr(dst));
226
04837f64
MH
227 conn = kzalloc(sizeof(struct hci_conn), GFP_ATOMIC);
228 if (!conn)
1da177e4 229 return NULL;
1da177e4
LT
230
231 bacpy(&conn->dst, dst);
a8746417
MH
232 conn->hdev = hdev;
233 conn->type = type;
234 conn->mode = HCI_CM_ACTIVE;
235 conn->state = BT_OPEN;
93f19c9f 236 conn->auth_type = HCI_AT_GENERAL_BONDING;
17fa4b9d 237 conn->io_capability = hdev->io_capability;
1da177e4 238
04837f64 239 conn->power_save = 1;
052b30b0 240 conn->disc_timeout = HCI_DISCONN_TIMEOUT;
04837f64 241
a8746417
MH
242 switch (type) {
243 case ACL_LINK:
244 conn->pkt_type = hdev->pkt_type & ACL_PTYPE_MASK;
245 break;
246 case SCO_LINK:
247 if (lmp_esco_capable(hdev))
efc7688b
MH
248 conn->pkt_type = (hdev->esco_type & SCO_ESCO_MASK) |
249 (hdev->esco_type & EDR_ESCO_MASK);
a8746417
MH
250 else
251 conn->pkt_type = hdev->pkt_type & SCO_PTYPE_MASK;
252 break;
253 case ESCO_LINK:
efc7688b 254 conn->pkt_type = hdev->esco_type & ~EDR_ESCO_MASK;
a8746417
MH
255 break;
256 }
257
1da177e4 258 skb_queue_head_init(&conn->data_q);
04837f64 259
b24b8a24
PE
260 setup_timer(&conn->disc_timer, hci_conn_timeout, (unsigned long)conn);
261 setup_timer(&conn->idle_timer, hci_conn_idle, (unsigned long)conn);
1da177e4
LT
262
263 atomic_set(&conn->refcnt, 0);
264
265 hci_dev_hold(hdev);
266
267 tasklet_disable(&hdev->tx_task);
268
269 hci_conn_hash_add(hdev, conn);
270 if (hdev->notify)
271 hdev->notify(hdev, HCI_NOTIFY_CONN_ADD);
272
9eba32b8
MH
273 atomic_set(&conn->devref, 0);
274
a67e899c
MH
275 hci_conn_init_sysfs(conn);
276
1da177e4
LT
277 tasklet_enable(&hdev->tx_task);
278
279 return conn;
280}
281
282int hci_conn_del(struct hci_conn *conn)
283{
284 struct hci_dev *hdev = conn->hdev;
285
286 BT_DBG("%s conn %p handle %d", hdev->name, conn, conn->handle);
287
04837f64
MH
288 del_timer(&conn->idle_timer);
289
290 del_timer(&conn->disc_timer);
1da177e4 291
5b7f9909 292 if (conn->type == ACL_LINK) {
1da177e4
LT
293 struct hci_conn *sco = conn->link;
294 if (sco)
295 sco->link = NULL;
296
297 /* Unacked frames */
298 hdev->acl_cnt += conn->sent;
5b7f9909
MH
299 } else {
300 struct hci_conn *acl = conn->link;
301 if (acl) {
302 acl->link = NULL;
303 hci_conn_put(acl);
304 }
1da177e4
LT
305 }
306
307 tasklet_disable(&hdev->tx_task);
7d0db0a3 308
1da177e4
LT
309 hci_conn_hash_del(hdev, conn);
310 if (hdev->notify)
311 hdev->notify(hdev, HCI_NOTIFY_CONN_DEL);
7d0db0a3 312
1da177e4 313 tasklet_enable(&hdev->tx_task);
7d0db0a3 314
1da177e4 315 skb_queue_purge(&conn->data_q);
1da177e4 316
9eba32b8 317 hci_conn_put_device(conn);
2ae9a6be 318
384943ec
MH
319 hci_dev_put(hdev);
320
1da177e4
LT
321 return 0;
322}
323
324struct hci_dev *hci_get_route(bdaddr_t *dst, bdaddr_t *src)
325{
326 int use_src = bacmp(src, BDADDR_ANY);
327 struct hci_dev *hdev = NULL;
328 struct list_head *p;
329
330 BT_DBG("%s -> %s", batostr(src), batostr(dst));
331
332 read_lock_bh(&hci_dev_list_lock);
333
334 list_for_each(p, &hci_dev_list) {
335 struct hci_dev *d = list_entry(p, struct hci_dev, list);
336
337 if (!test_bit(HCI_UP, &d->flags) || test_bit(HCI_RAW, &d->flags))
338 continue;
339
8e87d142 340 /* Simple routing:
1da177e4
LT
341 * No source address - find interface with bdaddr != dst
342 * Source address - find interface with bdaddr == src
343 */
344
345 if (use_src) {
346 if (!bacmp(&d->bdaddr, src)) {
347 hdev = d; break;
348 }
349 } else {
350 if (bacmp(&d->bdaddr, dst)) {
351 hdev = d; break;
352 }
353 }
354 }
355
356 if (hdev)
357 hdev = hci_dev_hold(hdev);
358
359 read_unlock_bh(&hci_dev_list_lock);
360 return hdev;
361}
362EXPORT_SYMBOL(hci_get_route);
363
364/* Create SCO or ACL connection.
365 * Device _must_ be locked */
8c1b2355 366struct hci_conn *hci_connect(struct hci_dev *hdev, int type, bdaddr_t *dst, __u8 sec_level, __u8 auth_type)
1da177e4
LT
367{
368 struct hci_conn *acl;
5b7f9909 369 struct hci_conn *sco;
1da177e4
LT
370
371 BT_DBG("%s dst %s", hdev->name, batostr(dst));
372
70f23020
AE
373 acl = hci_conn_hash_lookup_ba(hdev, ACL_LINK, dst);
374 if (!acl) {
375 acl = hci_conn_add(hdev, ACL_LINK, dst);
376 if (!acl)
1da177e4
LT
377 return NULL;
378 }
379
380 hci_conn_hold(acl);
381
09ab6f4c 382 if (acl->state == BT_OPEN || acl->state == BT_CLOSED) {
765c2a96
JH
383 acl->sec_level = BT_SECURITY_LOW;
384 acl->pending_sec_level = sec_level;
09ab6f4c 385 acl->auth_type = auth_type;
1da177e4 386 hci_acl_connect(acl);
09ab6f4c 387 }
1da177e4 388
5b7f9909
MH
389 if (type == ACL_LINK)
390 return acl;
1da177e4 391
70f23020
AE
392 sco = hci_conn_hash_lookup_ba(hdev, type, dst);
393 if (!sco) {
394 sco = hci_conn_add(hdev, type, dst);
395 if (!sco) {
5b7f9909
MH
396 hci_conn_put(acl);
397 return NULL;
1da177e4 398 }
5b7f9909 399 }
1da177e4 400
5b7f9909
MH
401 acl->link = sco;
402 sco->link = acl;
1da177e4 403
5b7f9909 404 hci_conn_hold(sco);
1da177e4 405
5b7f9909 406 if (acl->state == BT_CONNECTED &&
b6a0dc82 407 (sco->state == BT_OPEN || sco->state == BT_CLOSED)) {
c390216b
NP
408 acl->power_save = 1;
409 hci_conn_enter_active_mode(acl);
410
e73439d8
MH
411 if (test_bit(HCI_CONN_MODE_CHANGE_PEND, &acl->pend)) {
412 /* defer SCO setup until mode change completed */
413 set_bit(HCI_CONN_SCO_SETUP_PEND, &acl->pend);
414 return sco;
415 }
416
417 hci_sco_setup(acl, 0x00);
b6a0dc82 418 }
5b7f9909
MH
419
420 return sco;
1da177e4
LT
421}
422EXPORT_SYMBOL(hci_connect);
423
e7c29cb1
MH
424/* Check link security requirement */
425int hci_conn_check_link_mode(struct hci_conn *conn)
426{
427 BT_DBG("conn %p", conn);
428
429 if (conn->ssp_mode > 0 && conn->hdev->ssp_mode > 0 &&
430 !(conn->link_mode & HCI_LM_ENCRYPT))
431 return 0;
432
433 return 1;
434}
435EXPORT_SYMBOL(hci_conn_check_link_mode);
436
1da177e4 437/* Authenticate remote device */
0684e5f9 438static int hci_conn_auth(struct hci_conn *conn, __u8 sec_level, __u8 auth_type)
1da177e4
LT
439{
440 BT_DBG("conn %p", conn);
441
765c2a96
JH
442 if (conn->pending_sec_level > sec_level)
443 sec_level = conn->pending_sec_level;
444
96a31833 445 if (sec_level > conn->sec_level)
765c2a96 446 conn->pending_sec_level = sec_level;
96a31833 447 else if (conn->link_mode & HCI_LM_AUTH)
1da177e4
LT
448 return 1;
449
65cf686e
JH
450 /* Make sure we preserve an existing MITM requirement*/
451 auth_type |= (conn->auth_type & 0x01);
452
96a31833
MH
453 conn->auth_type = auth_type;
454
1da177e4
LT
455 if (!test_and_set_bit(HCI_CONN_AUTH_PEND, &conn->pend)) {
456 struct hci_cp_auth_requested cp;
aca3192c 457 cp.handle = cpu_to_le16(conn->handle);
40be492f
MH
458 hci_send_cmd(conn->hdev, HCI_OP_AUTH_REQUESTED,
459 sizeof(cp), &cp);
1da177e4 460 }
8c1b2355 461
1da177e4
LT
462 return 0;
463}
1da177e4 464
8c1b2355 465/* Enable security */
0684e5f9 466int hci_conn_security(struct hci_conn *conn, __u8 sec_level, __u8 auth_type)
1da177e4
LT
467{
468 BT_DBG("conn %p", conn);
469
8c1b2355
MH
470 if (sec_level == BT_SECURITY_SDP)
471 return 1;
472
3fdca1e1
MH
473 if (sec_level == BT_SECURITY_LOW &&
474 (!conn->ssp_mode || !conn->hdev->ssp_mode))
475 return 1;
8c1b2355 476
1da177e4 477 if (conn->link_mode & HCI_LM_ENCRYPT)
0684e5f9 478 return hci_conn_auth(conn, sec_level, auth_type);
1da177e4
LT
479
480 if (test_and_set_bit(HCI_CONN_ENCRYPT_PEND, &conn->pend))
481 return 0;
482
0684e5f9 483 if (hci_conn_auth(conn, sec_level, auth_type)) {
1da177e4 484 struct hci_cp_set_conn_encrypt cp;
aca3192c 485 cp.handle = cpu_to_le16(conn->handle);
8e87d142 486 cp.encrypt = 1;
40be492f
MH
487 hci_send_cmd(conn->hdev, HCI_OP_SET_CONN_ENCRYPT,
488 sizeof(cp), &cp);
1da177e4 489 }
8c1b2355 490
1da177e4
LT
491 return 0;
492}
8c1b2355 493EXPORT_SYMBOL(hci_conn_security);
1da177e4
LT
494
495/* Change link key */
496int hci_conn_change_link_key(struct hci_conn *conn)
497{
498 BT_DBG("conn %p", conn);
499
500 if (!test_and_set_bit(HCI_CONN_AUTH_PEND, &conn->pend)) {
501 struct hci_cp_change_conn_link_key cp;
aca3192c 502 cp.handle = cpu_to_le16(conn->handle);
40be492f
MH
503 hci_send_cmd(conn->hdev, HCI_OP_CHANGE_CONN_LINK_KEY,
504 sizeof(cp), &cp);
1da177e4 505 }
8c1b2355 506
1da177e4
LT
507 return 0;
508}
509EXPORT_SYMBOL(hci_conn_change_link_key);
510
511/* Switch role */
8c1b2355 512int hci_conn_switch_role(struct hci_conn *conn, __u8 role)
1da177e4
LT
513{
514 BT_DBG("conn %p", conn);
515
516 if (!role && conn->link_mode & HCI_LM_MASTER)
517 return 1;
518
519 if (!test_and_set_bit(HCI_CONN_RSWITCH_PEND, &conn->pend)) {
520 struct hci_cp_switch_role cp;
521 bacpy(&cp.bdaddr, &conn->dst);
522 cp.role = role;
a9de9248 523 hci_send_cmd(conn->hdev, HCI_OP_SWITCH_ROLE, sizeof(cp), &cp);
1da177e4 524 }
8c1b2355 525
1da177e4
LT
526 return 0;
527}
528EXPORT_SYMBOL(hci_conn_switch_role);
529
04837f64
MH
530/* Enter active mode */
531void hci_conn_enter_active_mode(struct hci_conn *conn)
532{
533 struct hci_dev *hdev = conn->hdev;
534
535 BT_DBG("conn %p mode %d", conn, conn->mode);
536
537 if (test_bit(HCI_RAW, &hdev->flags))
538 return;
539
540 if (conn->mode != HCI_CM_SNIFF || !conn->power_save)
541 goto timer;
542
543 if (!test_and_set_bit(HCI_CONN_MODE_CHANGE_PEND, &conn->pend)) {
544 struct hci_cp_exit_sniff_mode cp;
aca3192c 545 cp.handle = cpu_to_le16(conn->handle);
a9de9248 546 hci_send_cmd(hdev, HCI_OP_EXIT_SNIFF_MODE, sizeof(cp), &cp);
04837f64
MH
547 }
548
549timer:
550 if (hdev->idle_timeout > 0)
551 mod_timer(&conn->idle_timer,
552 jiffies + msecs_to_jiffies(hdev->idle_timeout));
553}
554
555/* Enter sniff mode */
556void hci_conn_enter_sniff_mode(struct hci_conn *conn)
557{
558 struct hci_dev *hdev = conn->hdev;
559
560 BT_DBG("conn %p mode %d", conn, conn->mode);
561
562 if (test_bit(HCI_RAW, &hdev->flags))
563 return;
564
565 if (!lmp_sniff_capable(hdev) || !lmp_sniff_capable(conn))
566 return;
567
568 if (conn->mode != HCI_CM_ACTIVE || !(conn->link_policy & HCI_LP_SNIFF))
569 return;
570
571 if (lmp_sniffsubr_capable(hdev) && lmp_sniffsubr_capable(conn)) {
572 struct hci_cp_sniff_subrate cp;
aca3192c
YH
573 cp.handle = cpu_to_le16(conn->handle);
574 cp.max_latency = cpu_to_le16(0);
575 cp.min_remote_timeout = cpu_to_le16(0);
576 cp.min_local_timeout = cpu_to_le16(0);
a9de9248 577 hci_send_cmd(hdev, HCI_OP_SNIFF_SUBRATE, sizeof(cp), &cp);
04837f64
MH
578 }
579
580 if (!test_and_set_bit(HCI_CONN_MODE_CHANGE_PEND, &conn->pend)) {
581 struct hci_cp_sniff_mode cp;
aca3192c
YH
582 cp.handle = cpu_to_le16(conn->handle);
583 cp.max_interval = cpu_to_le16(hdev->sniff_max_interval);
584 cp.min_interval = cpu_to_le16(hdev->sniff_min_interval);
585 cp.attempt = cpu_to_le16(4);
586 cp.timeout = cpu_to_le16(1);
a9de9248 587 hci_send_cmd(hdev, HCI_OP_SNIFF_MODE, sizeof(cp), &cp);
04837f64
MH
588 }
589}
590
1da177e4
LT
591/* Drop all connection on the device */
592void hci_conn_hash_flush(struct hci_dev *hdev)
593{
594 struct hci_conn_hash *h = &hdev->conn_hash;
595 struct list_head *p;
596
597 BT_DBG("hdev %s", hdev->name);
598
599 p = h->list.next;
600 while (p != &h->list) {
601 struct hci_conn *c;
602
603 c = list_entry(p, struct hci_conn, list);
604 p = p->next;
605
606 c->state = BT_CLOSED;
607
2950f21a 608 hci_proto_disconn_cfm(c, 0x16);
1da177e4
LT
609 hci_conn_del(c);
610 }
611}
612
a9de9248
MH
613/* Check pending connect attempts */
614void hci_conn_check_pending(struct hci_dev *hdev)
615{
616 struct hci_conn *conn;
617
618 BT_DBG("hdev %s", hdev->name);
619
620 hci_dev_lock(hdev);
621
622 conn = hci_conn_hash_lookup_state(hdev, ACL_LINK, BT_CONNECT2);
623 if (conn)
624 hci_acl_connect(conn);
625
626 hci_dev_unlock(hdev);
627}
628
9eba32b8
MH
629void hci_conn_hold_device(struct hci_conn *conn)
630{
631 atomic_inc(&conn->devref);
632}
633EXPORT_SYMBOL(hci_conn_hold_device);
634
635void hci_conn_put_device(struct hci_conn *conn)
636{
637 if (atomic_dec_and_test(&conn->devref))
638 hci_conn_del_sysfs(conn);
639}
640EXPORT_SYMBOL(hci_conn_put_device);
641
1da177e4
LT
642int hci_get_conn_list(void __user *arg)
643{
644 struct hci_conn_list_req req, *cl;
645 struct hci_conn_info *ci;
646 struct hci_dev *hdev;
647 struct list_head *p;
648 int n = 0, size, err;
649
650 if (copy_from_user(&req, arg, sizeof(req)))
651 return -EFAULT;
652
653 if (!req.conn_num || req.conn_num > (PAGE_SIZE * 2) / sizeof(*ci))
654 return -EINVAL;
655
656 size = sizeof(req) + req.conn_num * sizeof(*ci);
657
70f23020
AE
658 cl = kmalloc(size, GFP_KERNEL);
659 if (!cl)
1da177e4
LT
660 return -ENOMEM;
661
70f23020
AE
662 hdev = hci_dev_get(req.dev_id);
663 if (!hdev) {
1da177e4
LT
664 kfree(cl);
665 return -ENODEV;
666 }
667
668 ci = cl->conn_info;
669
670 hci_dev_lock_bh(hdev);
671 list_for_each(p, &hdev->conn_hash.list) {
672 register struct hci_conn *c;
673 c = list_entry(p, struct hci_conn, list);
674
675 bacpy(&(ci + n)->bdaddr, &c->dst);
676 (ci + n)->handle = c->handle;
677 (ci + n)->type = c->type;
678 (ci + n)->out = c->out;
679 (ci + n)->state = c->state;
680 (ci + n)->link_mode = c->link_mode;
681 if (++n >= req.conn_num)
682 break;
683 }
684 hci_dev_unlock_bh(hdev);
685
686 cl->dev_id = hdev->id;
687 cl->conn_num = n;
688 size = sizeof(req) + n * sizeof(*ci);
689
690 hci_dev_put(hdev);
691
692 err = copy_to_user(arg, cl, size);
693 kfree(cl);
694
695 return err ? -EFAULT : 0;
696}
697
698int hci_get_conn_info(struct hci_dev *hdev, void __user *arg)
699{
700 struct hci_conn_info_req req;
701 struct hci_conn_info ci;
702 struct hci_conn *conn;
703 char __user *ptr = arg + sizeof(req);
704
705 if (copy_from_user(&req, arg, sizeof(req)))
706 return -EFAULT;
707
708 hci_dev_lock_bh(hdev);
709 conn = hci_conn_hash_lookup_ba(hdev, req.type, &req.bdaddr);
710 if (conn) {
711 bacpy(&ci.bdaddr, &conn->dst);
712 ci.handle = conn->handle;
713 ci.type = conn->type;
714 ci.out = conn->out;
715 ci.state = conn->state;
716 ci.link_mode = conn->link_mode;
717 }
718 hci_dev_unlock_bh(hdev);
719
720 if (!conn)
721 return -ENOENT;
722
723 return copy_to_user(ptr, &ci, sizeof(ci)) ? -EFAULT : 0;
724}
40be492f
MH
725
726int hci_get_auth_info(struct hci_dev *hdev, void __user *arg)
727{
728 struct hci_auth_info_req req;
729 struct hci_conn *conn;
730
731 if (copy_from_user(&req, arg, sizeof(req)))
732 return -EFAULT;
733
734 hci_dev_lock_bh(hdev);
735 conn = hci_conn_hash_lookup_ba(hdev, ACL_LINK, &req.bdaddr);
736 if (conn)
737 req.type = conn->auth_type;
738 hci_dev_unlock_bh(hdev);
739
740 if (!conn)
741 return -ENOENT;
742
743 return copy_to_user(arg, &req, sizeof(req)) ? -EFAULT : 0;
744}