Bluetooth: Fix discovery state machine
[GitHub/mt8127/android_kernel_alcatel_ttab.git] / net / bluetooth / hci_core.c
CommitLineData
8e87d142 1/*
1da177e4
LT
2 BlueZ - Bluetooth protocol stack for Linux
3 Copyright (C) 2000-2001 Qualcomm Incorporated
590051de 4 Copyright (C) 2011 ProFUSION Embedded Systems
1da177e4
LT
5
6 Written 2000,2001 by Maxim Krasnyansky <maxk@qualcomm.com>
7
8 This program is free software; you can redistribute it and/or modify
9 it under the terms of the GNU General Public License version 2 as
10 published by the Free Software Foundation;
11
12 THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS
13 OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
14 FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT OF THIRD PARTY RIGHTS.
15 IN NO EVENT SHALL THE COPYRIGHT HOLDER(S) AND AUTHOR(S) BE LIABLE FOR ANY
8e87d142
YH
16 CLAIM, OR ANY SPECIAL INDIRECT OR CONSEQUENTIAL DAMAGES, OR ANY DAMAGES
17 WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
18 ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
1da177e4
LT
19 OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
20
8e87d142
YH
21 ALL LIABILITY, INCLUDING LIABILITY FOR INFRINGEMENT OF ANY PATENTS,
22 COPYRIGHTS, TRADEMARKS OR OTHER RIGHTS, RELATING TO USE OF THIS
1da177e4
LT
23 SOFTWARE IS DISCLAIMED.
24*/
25
26/* Bluetooth HCI core. */
27
82453021 28#include <linux/jiffies.h>
1da177e4
LT
29#include <linux/module.h>
30#include <linux/kmod.h>
31
32#include <linux/types.h>
33#include <linux/errno.h>
34#include <linux/kernel.h>
1da177e4
LT
35#include <linux/sched.h>
36#include <linux/slab.h>
37#include <linux/poll.h>
38#include <linux/fcntl.h>
39#include <linux/init.h>
40#include <linux/skbuff.h>
f48fd9c8 41#include <linux/workqueue.h>
1da177e4
LT
42#include <linux/interrupt.h>
43#include <linux/notifier.h>
611b30f7 44#include <linux/rfkill.h>
6bd32326 45#include <linux/timer.h>
3a0259bb 46#include <linux/crypto.h>
1da177e4
LT
47#include <net/sock.h>
48
49#include <asm/system.h>
70f23020 50#include <linux/uaccess.h>
1da177e4
LT
51#include <asm/unaligned.h>
52
53#include <net/bluetooth/bluetooth.h>
54#include <net/bluetooth/hci_core.h>
55
ab81cbf9
JH
56#define AUTO_OFF_TIMEOUT 2000
57
8b281b9c 58bool enable_hs;
7784d78f 59
b78752cc 60static void hci_rx_work(struct work_struct *work);
c347b765 61static void hci_cmd_work(struct work_struct *work);
3eff45ea 62static void hci_tx_work(struct work_struct *work);
1da177e4 63
1da177e4
LT
64/* HCI device list */
65LIST_HEAD(hci_dev_list);
66DEFINE_RWLOCK(hci_dev_list_lock);
67
68/* HCI callback list */
69LIST_HEAD(hci_cb_list);
70DEFINE_RWLOCK(hci_cb_list_lock);
71
1da177e4 72/* HCI notifiers list */
e041c683 73static ATOMIC_NOTIFIER_HEAD(hci_notifier);
1da177e4
LT
74
75/* ---- HCI notifications ---- */
76
77int hci_register_notifier(struct notifier_block *nb)
78{
e041c683 79 return atomic_notifier_chain_register(&hci_notifier, nb);
1da177e4
LT
80}
81
82int hci_unregister_notifier(struct notifier_block *nb)
83{
e041c683 84 return atomic_notifier_chain_unregister(&hci_notifier, nb);
1da177e4
LT
85}
86
6516455d 87static void hci_notify(struct hci_dev *hdev, int event)
1da177e4 88{
e041c683 89 atomic_notifier_call_chain(&hci_notifier, event, hdev);
1da177e4
LT
90}
91
92/* ---- HCI requests ---- */
93
23bb5763 94void hci_req_complete(struct hci_dev *hdev, __u16 cmd, int result)
1da177e4 95{
23bb5763
JH
96 BT_DBG("%s command 0x%04x result 0x%2.2x", hdev->name, cmd, result);
97
a5040efa
JH
98 /* If this is the init phase check if the completed command matches
99 * the last init command, and if not just return.
100 */
101 if (test_bit(HCI_INIT, &hdev->flags) && hdev->init_last_cmd != cmd)
23bb5763 102 return;
1da177e4
LT
103
104 if (hdev->req_status == HCI_REQ_PEND) {
105 hdev->req_result = result;
106 hdev->req_status = HCI_REQ_DONE;
107 wake_up_interruptible(&hdev->req_wait_q);
108 }
109}
110
111static void hci_req_cancel(struct hci_dev *hdev, int err)
112{
113 BT_DBG("%s err 0x%2.2x", hdev->name, err);
114
115 if (hdev->req_status == HCI_REQ_PEND) {
116 hdev->req_result = err;
117 hdev->req_status = HCI_REQ_CANCELED;
118 wake_up_interruptible(&hdev->req_wait_q);
119 }
120}
121
122/* Execute request and wait for completion. */
8e87d142 123static int __hci_request(struct hci_dev *hdev, void (*req)(struct hci_dev *hdev, unsigned long opt),
01df8c31 124 unsigned long opt, __u32 timeout)
1da177e4
LT
125{
126 DECLARE_WAITQUEUE(wait, current);
127 int err = 0;
128
129 BT_DBG("%s start", hdev->name);
130
131 hdev->req_status = HCI_REQ_PEND;
132
133 add_wait_queue(&hdev->req_wait_q, &wait);
134 set_current_state(TASK_INTERRUPTIBLE);
135
136 req(hdev, opt);
137 schedule_timeout(timeout);
138
139 remove_wait_queue(&hdev->req_wait_q, &wait);
140
141 if (signal_pending(current))
142 return -EINTR;
143
144 switch (hdev->req_status) {
145 case HCI_REQ_DONE:
e175072f 146 err = -bt_to_errno(hdev->req_result);
1da177e4
LT
147 break;
148
149 case HCI_REQ_CANCELED:
150 err = -hdev->req_result;
151 break;
152
153 default:
154 err = -ETIMEDOUT;
155 break;
3ff50b79 156 }
1da177e4 157
a5040efa 158 hdev->req_status = hdev->req_result = 0;
1da177e4
LT
159
160 BT_DBG("%s end: err %d", hdev->name, err);
161
162 return err;
163}
164
165static inline int hci_request(struct hci_dev *hdev, void (*req)(struct hci_dev *hdev, unsigned long opt),
01df8c31 166 unsigned long opt, __u32 timeout)
1da177e4
LT
167{
168 int ret;
169
7c6a329e
MH
170 if (!test_bit(HCI_UP, &hdev->flags))
171 return -ENETDOWN;
172
1da177e4
LT
173 /* Serialize all requests */
174 hci_req_lock(hdev);
175 ret = __hci_request(hdev, req, opt, timeout);
176 hci_req_unlock(hdev);
177
178 return ret;
179}
180
181static void hci_reset_req(struct hci_dev *hdev, unsigned long opt)
182{
183 BT_DBG("%s %ld", hdev->name, opt);
184
185 /* Reset device */
f630cf0d 186 set_bit(HCI_RESET, &hdev->flags);
a9de9248 187 hci_send_cmd(hdev, HCI_OP_RESET, 0, NULL);
1da177e4
LT
188}
189
e61ef499 190static void bredr_init(struct hci_dev *hdev)
1da177e4 191{
b0916ea0 192 struct hci_cp_delete_stored_link_key cp;
1ebb9252 193 __le16 param;
89f2783d 194 __u8 flt_type;
1da177e4 195
2455a3ea
AE
196 hdev->flow_ctl_mode = HCI_FLOW_CTL_MODE_PACKET_BASED;
197
1da177e4
LT
198 /* Mandatory initialization */
199
200 /* Reset */
f630cf0d 201 if (!test_bit(HCI_QUIRK_NO_RESET, &hdev->quirks)) {
e61ef499
AE
202 set_bit(HCI_RESET, &hdev->flags);
203 hci_send_cmd(hdev, HCI_OP_RESET, 0, NULL);
f630cf0d 204 }
1da177e4
LT
205
206 /* Read Local Supported Features */
a9de9248 207 hci_send_cmd(hdev, HCI_OP_READ_LOCAL_FEATURES, 0, NULL);
1da177e4 208
1143e5a6 209 /* Read Local Version */
a9de9248 210 hci_send_cmd(hdev, HCI_OP_READ_LOCAL_VERSION, 0, NULL);
1143e5a6 211
1da177e4 212 /* Read Buffer Size (ACL mtu, max pkt, etc.) */
a9de9248 213 hci_send_cmd(hdev, HCI_OP_READ_BUFFER_SIZE, 0, NULL);
1da177e4 214
1da177e4 215 /* Read BD Address */
a9de9248
MH
216 hci_send_cmd(hdev, HCI_OP_READ_BD_ADDR, 0, NULL);
217
218 /* Read Class of Device */
219 hci_send_cmd(hdev, HCI_OP_READ_CLASS_OF_DEV, 0, NULL);
220
221 /* Read Local Name */
222 hci_send_cmd(hdev, HCI_OP_READ_LOCAL_NAME, 0, NULL);
1da177e4
LT
223
224 /* Read Voice Setting */
a9de9248 225 hci_send_cmd(hdev, HCI_OP_READ_VOICE_SETTING, 0, NULL);
1da177e4
LT
226
227 /* Optional initialization */
228
229 /* Clear Event Filters */
89f2783d 230 flt_type = HCI_FLT_CLEAR_ALL;
a9de9248 231 hci_send_cmd(hdev, HCI_OP_SET_EVENT_FLT, 1, &flt_type);
1da177e4 232
1da177e4 233 /* Connection accept timeout ~20 secs */
aca3192c 234 param = cpu_to_le16(0x7d00);
a9de9248 235 hci_send_cmd(hdev, HCI_OP_WRITE_CA_TIMEOUT, 2, &param);
b0916ea0
JH
236
237 bacpy(&cp.bdaddr, BDADDR_ANY);
238 cp.delete_all = 1;
239 hci_send_cmd(hdev, HCI_OP_DELETE_STORED_LINK_KEY, sizeof(cp), &cp);
1da177e4
LT
240}
241
e61ef499
AE
242static void amp_init(struct hci_dev *hdev)
243{
2455a3ea
AE
244 hdev->flow_ctl_mode = HCI_FLOW_CTL_MODE_BLOCK_BASED;
245
e61ef499
AE
246 /* Reset */
247 hci_send_cmd(hdev, HCI_OP_RESET, 0, NULL);
248
249 /* Read Local Version */
250 hci_send_cmd(hdev, HCI_OP_READ_LOCAL_VERSION, 0, NULL);
251}
252
253static void hci_init_req(struct hci_dev *hdev, unsigned long opt)
254{
255 struct sk_buff *skb;
256
257 BT_DBG("%s %ld", hdev->name, opt);
258
259 /* Driver initialization */
260
261 /* Special commands */
262 while ((skb = skb_dequeue(&hdev->driver_init))) {
263 bt_cb(skb)->pkt_type = HCI_COMMAND_PKT;
264 skb->dev = (void *) hdev;
265
266 skb_queue_tail(&hdev->cmd_q, skb);
267 queue_work(hdev->workqueue, &hdev->cmd_work);
268 }
269 skb_queue_purge(&hdev->driver_init);
270
271 switch (hdev->dev_type) {
272 case HCI_BREDR:
273 bredr_init(hdev);
274 break;
275
276 case HCI_AMP:
277 amp_init(hdev);
278 break;
279
280 default:
281 BT_ERR("Unknown device type %d", hdev->dev_type);
282 break;
283 }
284
285}
286
6ed58ec5
VT
287static void hci_le_init_req(struct hci_dev *hdev, unsigned long opt)
288{
289 BT_DBG("%s", hdev->name);
290
291 /* Read LE buffer size */
292 hci_send_cmd(hdev, HCI_OP_LE_READ_BUFFER_SIZE, 0, NULL);
293}
294
1da177e4
LT
295static void hci_scan_req(struct hci_dev *hdev, unsigned long opt)
296{
297 __u8 scan = opt;
298
299 BT_DBG("%s %x", hdev->name, scan);
300
301 /* Inquiry and Page scans */
a9de9248 302 hci_send_cmd(hdev, HCI_OP_WRITE_SCAN_ENABLE, 1, &scan);
1da177e4
LT
303}
304
305static void hci_auth_req(struct hci_dev *hdev, unsigned long opt)
306{
307 __u8 auth = opt;
308
309 BT_DBG("%s %x", hdev->name, auth);
310
311 /* Authentication */
a9de9248 312 hci_send_cmd(hdev, HCI_OP_WRITE_AUTH_ENABLE, 1, &auth);
1da177e4
LT
313}
314
315static void hci_encrypt_req(struct hci_dev *hdev, unsigned long opt)
316{
317 __u8 encrypt = opt;
318
319 BT_DBG("%s %x", hdev->name, encrypt);
320
e4e8e37c 321 /* Encryption */
a9de9248 322 hci_send_cmd(hdev, HCI_OP_WRITE_ENCRYPT_MODE, 1, &encrypt);
1da177e4
LT
323}
324
e4e8e37c
MH
325static void hci_linkpol_req(struct hci_dev *hdev, unsigned long opt)
326{
327 __le16 policy = cpu_to_le16(opt);
328
a418b893 329 BT_DBG("%s %x", hdev->name, policy);
e4e8e37c
MH
330
331 /* Default link policy */
332 hci_send_cmd(hdev, HCI_OP_WRITE_DEF_LINK_POLICY, 2, &policy);
333}
334
8e87d142 335/* Get HCI device by index.
1da177e4
LT
336 * Device is held on return. */
337struct hci_dev *hci_dev_get(int index)
338{
8035ded4 339 struct hci_dev *hdev = NULL, *d;
1da177e4
LT
340
341 BT_DBG("%d", index);
342
343 if (index < 0)
344 return NULL;
345
346 read_lock(&hci_dev_list_lock);
8035ded4 347 list_for_each_entry(d, &hci_dev_list, list) {
1da177e4
LT
348 if (d->id == index) {
349 hdev = hci_dev_hold(d);
350 break;
351 }
352 }
353 read_unlock(&hci_dev_list_lock);
354 return hdev;
355}
1da177e4
LT
356
357/* ---- Inquiry support ---- */
ff9ef578 358
30dc78e1
JH
359bool hci_discovery_active(struct hci_dev *hdev)
360{
361 struct discovery_state *discov = &hdev->discovery;
362
6fbe195d
AG
363 switch (discov->state) {
364 case DISCOVERY_INQUIRY:
365 case DISCOVERY_LE_SCAN:
366 case DISCOVERY_RESOLVING:
30dc78e1
JH
367 return true;
368
6fbe195d
AG
369 default:
370 return false;
371 }
30dc78e1
JH
372}
373
ff9ef578
JH
374void hci_discovery_set_state(struct hci_dev *hdev, int state)
375{
376 BT_DBG("%s state %u -> %u", hdev->name, hdev->discovery.state, state);
377
378 if (hdev->discovery.state == state)
379 return;
380
381 switch (state) {
382 case DISCOVERY_STOPPED:
383 mgmt_discovering(hdev, 0);
384 break;
385 case DISCOVERY_STARTING:
386 break;
30dc78e1 387 case DISCOVERY_INQUIRY:
c599008f 388 case DISCOVERY_LE_SCAN:
ff9ef578
JH
389 mgmt_discovering(hdev, 1);
390 break;
30dc78e1
JH
391 case DISCOVERY_RESOLVING:
392 break;
ff9ef578
JH
393 case DISCOVERY_STOPPING:
394 break;
395 }
396
397 hdev->discovery.state = state;
398}
399
1da177e4
LT
400static void inquiry_cache_flush(struct hci_dev *hdev)
401{
30883512 402 struct discovery_state *cache = &hdev->discovery;
b57c1a56 403 struct inquiry_entry *p, *n;
1da177e4 404
561aafbc
JH
405 list_for_each_entry_safe(p, n, &cache->all, all) {
406 list_del(&p->all);
b57c1a56 407 kfree(p);
1da177e4 408 }
561aafbc
JH
409
410 INIT_LIST_HEAD(&cache->unknown);
411 INIT_LIST_HEAD(&cache->resolve);
ff9ef578 412 cache->state = DISCOVERY_STOPPED;
1da177e4
LT
413}
414
415struct inquiry_entry *hci_inquiry_cache_lookup(struct hci_dev *hdev, bdaddr_t *bdaddr)
416{
30883512 417 struct discovery_state *cache = &hdev->discovery;
1da177e4
LT
418 struct inquiry_entry *e;
419
420 BT_DBG("cache %p, %s", cache, batostr(bdaddr));
421
561aafbc
JH
422 list_for_each_entry(e, &cache->all, all) {
423 if (!bacmp(&e->data.bdaddr, bdaddr))
424 return e;
425 }
426
427 return NULL;
428}
429
430struct inquiry_entry *hci_inquiry_cache_lookup_unknown(struct hci_dev *hdev,
431 bdaddr_t *bdaddr)
432{
30883512 433 struct discovery_state *cache = &hdev->discovery;
561aafbc
JH
434 struct inquiry_entry *e;
435
436 BT_DBG("cache %p, %s", cache, batostr(bdaddr));
437
438 list_for_each_entry(e, &cache->unknown, list) {
1da177e4 439 if (!bacmp(&e->data.bdaddr, bdaddr))
b57c1a56
JH
440 return e;
441 }
442
443 return NULL;
1da177e4
LT
444}
445
30dc78e1
JH
446struct inquiry_entry *hci_inquiry_cache_lookup_resolve(struct hci_dev *hdev,
447 bdaddr_t *bdaddr,
448 int state)
449{
450 struct discovery_state *cache = &hdev->discovery;
451 struct inquiry_entry *e;
452
453 BT_DBG("cache %p bdaddr %s state %d", cache, batostr(bdaddr), state);
454
455 list_for_each_entry(e, &cache->resolve, list) {
456 if (!bacmp(bdaddr, BDADDR_ANY) && e->name_state == state)
457 return e;
458 if (!bacmp(&e->data.bdaddr, bdaddr))
459 return e;
460 }
461
462 return NULL;
463}
464
a3d4e20a
JH
465void hci_inquiry_cache_update_resolve(struct hci_dev *hdev,
466 struct inquiry_entry *ie)
467{
468 struct discovery_state *cache = &hdev->discovery;
469 struct list_head *pos = &cache->resolve;
470 struct inquiry_entry *p;
471
472 list_del(&ie->list);
473
474 list_for_each_entry(p, &cache->resolve, list) {
475 if (p->name_state != NAME_PENDING &&
476 abs(p->data.rssi) >= abs(ie->data.rssi))
477 break;
478 pos = &p->list;
479 }
480
481 list_add(&ie->list, pos);
482}
483
3175405b 484bool hci_inquiry_cache_update(struct hci_dev *hdev, struct inquiry_data *data,
561aafbc 485 bool name_known)
1da177e4 486{
30883512 487 struct discovery_state *cache = &hdev->discovery;
70f23020 488 struct inquiry_entry *ie;
1da177e4
LT
489
490 BT_DBG("cache %p, %s", cache, batostr(&data->bdaddr));
491
70f23020 492 ie = hci_inquiry_cache_lookup(hdev, &data->bdaddr);
a3d4e20a
JH
493 if (ie) {
494 if (ie->name_state == NAME_NEEDED &&
495 data->rssi != ie->data.rssi) {
496 ie->data.rssi = data->rssi;
497 hci_inquiry_cache_update_resolve(hdev, ie);
498 }
499
561aafbc 500 goto update;
a3d4e20a 501 }
561aafbc
JH
502
503 /* Entry not in the cache. Add new one. */
504 ie = kzalloc(sizeof(struct inquiry_entry), GFP_ATOMIC);
505 if (!ie)
3175405b 506 return false;
561aafbc
JH
507
508 list_add(&ie->all, &cache->all);
509
510 if (name_known) {
511 ie->name_state = NAME_KNOWN;
512 } else {
513 ie->name_state = NAME_NOT_KNOWN;
514 list_add(&ie->list, &cache->unknown);
515 }
70f23020 516
561aafbc
JH
517update:
518 if (name_known && ie->name_state != NAME_KNOWN &&
519 ie->name_state != NAME_PENDING) {
520 ie->name_state = NAME_KNOWN;
521 list_del(&ie->list);
1da177e4
LT
522 }
523
70f23020
AE
524 memcpy(&ie->data, data, sizeof(*data));
525 ie->timestamp = jiffies;
1da177e4 526 cache->timestamp = jiffies;
3175405b
JH
527
528 if (ie->name_state == NAME_NOT_KNOWN)
529 return false;
530
531 return true;
1da177e4
LT
532}
533
534static int inquiry_cache_dump(struct hci_dev *hdev, int num, __u8 *buf)
535{
30883512 536 struct discovery_state *cache = &hdev->discovery;
1da177e4
LT
537 struct inquiry_info *info = (struct inquiry_info *) buf;
538 struct inquiry_entry *e;
539 int copied = 0;
540
561aafbc 541 list_for_each_entry(e, &cache->all, all) {
1da177e4 542 struct inquiry_data *data = &e->data;
b57c1a56
JH
543
544 if (copied >= num)
545 break;
546
1da177e4
LT
547 bacpy(&info->bdaddr, &data->bdaddr);
548 info->pscan_rep_mode = data->pscan_rep_mode;
549 info->pscan_period_mode = data->pscan_period_mode;
550 info->pscan_mode = data->pscan_mode;
551 memcpy(info->dev_class, data->dev_class, 3);
552 info->clock_offset = data->clock_offset;
b57c1a56 553
1da177e4 554 info++;
b57c1a56 555 copied++;
1da177e4
LT
556 }
557
558 BT_DBG("cache %p, copied %d", cache, copied);
559 return copied;
560}
561
562static void hci_inq_req(struct hci_dev *hdev, unsigned long opt)
563{
564 struct hci_inquiry_req *ir = (struct hci_inquiry_req *) opt;
565 struct hci_cp_inquiry cp;
566
567 BT_DBG("%s", hdev->name);
568
569 if (test_bit(HCI_INQUIRY, &hdev->flags))
570 return;
571
572 /* Start Inquiry */
573 memcpy(&cp.lap, &ir->lap, 3);
574 cp.length = ir->length;
575 cp.num_rsp = ir->num_rsp;
a9de9248 576 hci_send_cmd(hdev, HCI_OP_INQUIRY, sizeof(cp), &cp);
1da177e4
LT
577}
578
579int hci_inquiry(void __user *arg)
580{
581 __u8 __user *ptr = arg;
582 struct hci_inquiry_req ir;
583 struct hci_dev *hdev;
584 int err = 0, do_inquiry = 0, max_rsp;
585 long timeo;
586 __u8 *buf;
587
588 if (copy_from_user(&ir, ptr, sizeof(ir)))
589 return -EFAULT;
590
5a08ecce
AE
591 hdev = hci_dev_get(ir.dev_id);
592 if (!hdev)
1da177e4
LT
593 return -ENODEV;
594
09fd0de5 595 hci_dev_lock(hdev);
8e87d142 596 if (inquiry_cache_age(hdev) > INQUIRY_CACHE_AGE_MAX ||
70f23020
AE
597 inquiry_cache_empty(hdev) ||
598 ir.flags & IREQ_CACHE_FLUSH) {
1da177e4
LT
599 inquiry_cache_flush(hdev);
600 do_inquiry = 1;
601 }
09fd0de5 602 hci_dev_unlock(hdev);
1da177e4 603
04837f64 604 timeo = ir.length * msecs_to_jiffies(2000);
70f23020
AE
605
606 if (do_inquiry) {
607 err = hci_request(hdev, hci_inq_req, (unsigned long)&ir, timeo);
608 if (err < 0)
609 goto done;
610 }
1da177e4
LT
611
612 /* for unlimited number of responses we will use buffer with 255 entries */
613 max_rsp = (ir.num_rsp == 0) ? 255 : ir.num_rsp;
614
615 /* cache_dump can't sleep. Therefore we allocate temp buffer and then
616 * copy it to the user space.
617 */
01df8c31 618 buf = kmalloc(sizeof(struct inquiry_info) * max_rsp, GFP_KERNEL);
70f23020 619 if (!buf) {
1da177e4
LT
620 err = -ENOMEM;
621 goto done;
622 }
623
09fd0de5 624 hci_dev_lock(hdev);
1da177e4 625 ir.num_rsp = inquiry_cache_dump(hdev, max_rsp, buf);
09fd0de5 626 hci_dev_unlock(hdev);
1da177e4
LT
627
628 BT_DBG("num_rsp %d", ir.num_rsp);
629
630 if (!copy_to_user(ptr, &ir, sizeof(ir))) {
631 ptr += sizeof(ir);
632 if (copy_to_user(ptr, buf, sizeof(struct inquiry_info) *
633 ir.num_rsp))
634 err = -EFAULT;
8e87d142 635 } else
1da177e4
LT
636 err = -EFAULT;
637
638 kfree(buf);
639
640done:
641 hci_dev_put(hdev);
642 return err;
643}
644
645/* ---- HCI ioctl helpers ---- */
646
647int hci_dev_open(__u16 dev)
648{
649 struct hci_dev *hdev;
650 int ret = 0;
651
5a08ecce
AE
652 hdev = hci_dev_get(dev);
653 if (!hdev)
1da177e4
LT
654 return -ENODEV;
655
656 BT_DBG("%s %p", hdev->name, hdev);
657
658 hci_req_lock(hdev);
659
611b30f7
MH
660 if (hdev->rfkill && rfkill_blocked(hdev->rfkill)) {
661 ret = -ERFKILL;
662 goto done;
663 }
664
1da177e4
LT
665 if (test_bit(HCI_UP, &hdev->flags)) {
666 ret = -EALREADY;
667 goto done;
668 }
669
670 if (test_bit(HCI_QUIRK_RAW_DEVICE, &hdev->quirks))
671 set_bit(HCI_RAW, &hdev->flags);
672
07e3b94a
AE
673 /* Treat all non BR/EDR controllers as raw devices if
674 enable_hs is not set */
675 if (hdev->dev_type != HCI_BREDR && !enable_hs)
943da25d
MH
676 set_bit(HCI_RAW, &hdev->flags);
677
1da177e4
LT
678 if (hdev->open(hdev)) {
679 ret = -EIO;
680 goto done;
681 }
682
683 if (!test_bit(HCI_RAW, &hdev->flags)) {
684 atomic_set(&hdev->cmd_cnt, 1);
685 set_bit(HCI_INIT, &hdev->flags);
a5040efa 686 hdev->init_last_cmd = 0;
1da177e4 687
04837f64
MH
688 ret = __hci_request(hdev, hci_init_req, 0,
689 msecs_to_jiffies(HCI_INIT_TIMEOUT));
1da177e4 690
eead27da 691 if (lmp_host_le_capable(hdev))
6ed58ec5
VT
692 ret = __hci_request(hdev, hci_le_init_req, 0,
693 msecs_to_jiffies(HCI_INIT_TIMEOUT));
694
1da177e4
LT
695 clear_bit(HCI_INIT, &hdev->flags);
696 }
697
698 if (!ret) {
699 hci_dev_hold(hdev);
700 set_bit(HCI_UP, &hdev->flags);
701 hci_notify(hdev, HCI_DEV_UP);
a8b2d5c2 702 if (!test_bit(HCI_SETUP, &hdev->dev_flags)) {
09fd0de5 703 hci_dev_lock(hdev);
744cf19e 704 mgmt_powered(hdev, 1);
09fd0de5 705 hci_dev_unlock(hdev);
56e5cb86 706 }
8e87d142 707 } else {
1da177e4 708 /* Init failed, cleanup */
3eff45ea 709 flush_work(&hdev->tx_work);
c347b765 710 flush_work(&hdev->cmd_work);
b78752cc 711 flush_work(&hdev->rx_work);
1da177e4
LT
712
713 skb_queue_purge(&hdev->cmd_q);
714 skb_queue_purge(&hdev->rx_q);
715
716 if (hdev->flush)
717 hdev->flush(hdev);
718
719 if (hdev->sent_cmd) {
720 kfree_skb(hdev->sent_cmd);
721 hdev->sent_cmd = NULL;
722 }
723
724 hdev->close(hdev);
725 hdev->flags = 0;
726 }
727
728done:
729 hci_req_unlock(hdev);
730 hci_dev_put(hdev);
731 return ret;
732}
733
734static int hci_dev_do_close(struct hci_dev *hdev)
735{
736 BT_DBG("%s %p", hdev->name, hdev);
737
28b75a89
AG
738 cancel_work_sync(&hdev->le_scan);
739
1da177e4
LT
740 hci_req_cancel(hdev, ENODEV);
741 hci_req_lock(hdev);
742
743 if (!test_and_clear_bit(HCI_UP, &hdev->flags)) {
b79f44c1 744 del_timer_sync(&hdev->cmd_timer);
1da177e4
LT
745 hci_req_unlock(hdev);
746 return 0;
747 }
748
3eff45ea
GP
749 /* Flush RX and TX works */
750 flush_work(&hdev->tx_work);
b78752cc 751 flush_work(&hdev->rx_work);
1da177e4 752
16ab91ab 753 if (hdev->discov_timeout > 0) {
e0f9309f 754 cancel_delayed_work(&hdev->discov_off);
16ab91ab
JH
755 hdev->discov_timeout = 0;
756 }
757
a8b2d5c2 758 if (test_and_clear_bit(HCI_AUTO_OFF, &hdev->dev_flags))
e0f9309f 759 cancel_delayed_work(&hdev->power_off);
3243553f 760
a8b2d5c2 761 if (test_and_clear_bit(HCI_SERVICE_CACHE, &hdev->dev_flags))
7d78525d
JH
762 cancel_delayed_work(&hdev->service_cache);
763
7ba8b4be
AG
764 cancel_delayed_work_sync(&hdev->le_scan_disable);
765
09fd0de5 766 hci_dev_lock(hdev);
1da177e4
LT
767 inquiry_cache_flush(hdev);
768 hci_conn_hash_flush(hdev);
09fd0de5 769 hci_dev_unlock(hdev);
1da177e4
LT
770
771 hci_notify(hdev, HCI_DEV_DOWN);
772
773 if (hdev->flush)
774 hdev->flush(hdev);
775
776 /* Reset device */
777 skb_queue_purge(&hdev->cmd_q);
778 atomic_set(&hdev->cmd_cnt, 1);
8af59467
JH
779 if (!test_bit(HCI_RAW, &hdev->flags) &&
780 test_bit(HCI_QUIRK_NO_RESET, &hdev->quirks)) {
1da177e4 781 set_bit(HCI_INIT, &hdev->flags);
04837f64 782 __hci_request(hdev, hci_reset_req, 0,
cad44c2b 783 msecs_to_jiffies(250));
1da177e4
LT
784 clear_bit(HCI_INIT, &hdev->flags);
785 }
786
c347b765
GP
787 /* flush cmd work */
788 flush_work(&hdev->cmd_work);
1da177e4
LT
789
790 /* Drop queues */
791 skb_queue_purge(&hdev->rx_q);
792 skb_queue_purge(&hdev->cmd_q);
793 skb_queue_purge(&hdev->raw_q);
794
795 /* Drop last sent command */
796 if (hdev->sent_cmd) {
b79f44c1 797 del_timer_sync(&hdev->cmd_timer);
1da177e4
LT
798 kfree_skb(hdev->sent_cmd);
799 hdev->sent_cmd = NULL;
800 }
801
802 /* After this point our queues are empty
803 * and no tasks are scheduled. */
804 hdev->close(hdev);
805
09fd0de5 806 hci_dev_lock(hdev);
744cf19e 807 mgmt_powered(hdev, 0);
09fd0de5 808 hci_dev_unlock(hdev);
5add6af8 809
1da177e4
LT
810 /* Clear flags */
811 hdev->flags = 0;
812
813 hci_req_unlock(hdev);
814
815 hci_dev_put(hdev);
816 return 0;
817}
818
819int hci_dev_close(__u16 dev)
820{
821 struct hci_dev *hdev;
822 int err;
823
70f23020
AE
824 hdev = hci_dev_get(dev);
825 if (!hdev)
1da177e4
LT
826 return -ENODEV;
827 err = hci_dev_do_close(hdev);
828 hci_dev_put(hdev);
829 return err;
830}
831
832int hci_dev_reset(__u16 dev)
833{
834 struct hci_dev *hdev;
835 int ret = 0;
836
70f23020
AE
837 hdev = hci_dev_get(dev);
838 if (!hdev)
1da177e4
LT
839 return -ENODEV;
840
841 hci_req_lock(hdev);
1da177e4
LT
842
843 if (!test_bit(HCI_UP, &hdev->flags))
844 goto done;
845
846 /* Drop queues */
847 skb_queue_purge(&hdev->rx_q);
848 skb_queue_purge(&hdev->cmd_q);
849
09fd0de5 850 hci_dev_lock(hdev);
1da177e4
LT
851 inquiry_cache_flush(hdev);
852 hci_conn_hash_flush(hdev);
09fd0de5 853 hci_dev_unlock(hdev);
1da177e4
LT
854
855 if (hdev->flush)
856 hdev->flush(hdev);
857
8e87d142 858 atomic_set(&hdev->cmd_cnt, 1);
6ed58ec5 859 hdev->acl_cnt = 0; hdev->sco_cnt = 0; hdev->le_cnt = 0;
1da177e4
LT
860
861 if (!test_bit(HCI_RAW, &hdev->flags))
04837f64
MH
862 ret = __hci_request(hdev, hci_reset_req, 0,
863 msecs_to_jiffies(HCI_INIT_TIMEOUT));
1da177e4
LT
864
865done:
1da177e4
LT
866 hci_req_unlock(hdev);
867 hci_dev_put(hdev);
868 return ret;
869}
870
871int hci_dev_reset_stat(__u16 dev)
872{
873 struct hci_dev *hdev;
874 int ret = 0;
875
70f23020
AE
876 hdev = hci_dev_get(dev);
877 if (!hdev)
1da177e4
LT
878 return -ENODEV;
879
880 memset(&hdev->stat, 0, sizeof(struct hci_dev_stats));
881
882 hci_dev_put(hdev);
883
884 return ret;
885}
886
887int hci_dev_cmd(unsigned int cmd, void __user *arg)
888{
889 struct hci_dev *hdev;
890 struct hci_dev_req dr;
891 int err = 0;
892
893 if (copy_from_user(&dr, arg, sizeof(dr)))
894 return -EFAULT;
895
70f23020
AE
896 hdev = hci_dev_get(dr.dev_id);
897 if (!hdev)
1da177e4
LT
898 return -ENODEV;
899
900 switch (cmd) {
901 case HCISETAUTH:
04837f64
MH
902 err = hci_request(hdev, hci_auth_req, dr.dev_opt,
903 msecs_to_jiffies(HCI_INIT_TIMEOUT));
1da177e4
LT
904 break;
905
906 case HCISETENCRYPT:
907 if (!lmp_encrypt_capable(hdev)) {
908 err = -EOPNOTSUPP;
909 break;
910 }
911
912 if (!test_bit(HCI_AUTH, &hdev->flags)) {
913 /* Auth must be enabled first */
04837f64
MH
914 err = hci_request(hdev, hci_auth_req, dr.dev_opt,
915 msecs_to_jiffies(HCI_INIT_TIMEOUT));
1da177e4
LT
916 if (err)
917 break;
918 }
919
04837f64
MH
920 err = hci_request(hdev, hci_encrypt_req, dr.dev_opt,
921 msecs_to_jiffies(HCI_INIT_TIMEOUT));
1da177e4
LT
922 break;
923
924 case HCISETSCAN:
04837f64
MH
925 err = hci_request(hdev, hci_scan_req, dr.dev_opt,
926 msecs_to_jiffies(HCI_INIT_TIMEOUT));
1da177e4
LT
927 break;
928
1da177e4 929 case HCISETLINKPOL:
e4e8e37c
MH
930 err = hci_request(hdev, hci_linkpol_req, dr.dev_opt,
931 msecs_to_jiffies(HCI_INIT_TIMEOUT));
1da177e4
LT
932 break;
933
934 case HCISETLINKMODE:
e4e8e37c
MH
935 hdev->link_mode = ((__u16) dr.dev_opt) &
936 (HCI_LM_MASTER | HCI_LM_ACCEPT);
937 break;
938
939 case HCISETPTYPE:
940 hdev->pkt_type = (__u16) dr.dev_opt;
1da177e4
LT
941 break;
942
943 case HCISETACLMTU:
e4e8e37c
MH
944 hdev->acl_mtu = *((__u16 *) &dr.dev_opt + 1);
945 hdev->acl_pkts = *((__u16 *) &dr.dev_opt + 0);
1da177e4
LT
946 break;
947
948 case HCISETSCOMTU:
e4e8e37c
MH
949 hdev->sco_mtu = *((__u16 *) &dr.dev_opt + 1);
950 hdev->sco_pkts = *((__u16 *) &dr.dev_opt + 0);
1da177e4
LT
951 break;
952
953 default:
954 err = -EINVAL;
955 break;
956 }
e4e8e37c 957
1da177e4
LT
958 hci_dev_put(hdev);
959 return err;
960}
961
962int hci_get_dev_list(void __user *arg)
963{
8035ded4 964 struct hci_dev *hdev;
1da177e4
LT
965 struct hci_dev_list_req *dl;
966 struct hci_dev_req *dr;
1da177e4
LT
967 int n = 0, size, err;
968 __u16 dev_num;
969
970 if (get_user(dev_num, (__u16 __user *) arg))
971 return -EFAULT;
972
973 if (!dev_num || dev_num > (PAGE_SIZE * 2) / sizeof(*dr))
974 return -EINVAL;
975
976 size = sizeof(*dl) + dev_num * sizeof(*dr);
977
70f23020
AE
978 dl = kzalloc(size, GFP_KERNEL);
979 if (!dl)
1da177e4
LT
980 return -ENOMEM;
981
982 dr = dl->dev_req;
983
f20d09d5 984 read_lock(&hci_dev_list_lock);
8035ded4 985 list_for_each_entry(hdev, &hci_dev_list, list) {
a8b2d5c2 986 if (test_and_clear_bit(HCI_AUTO_OFF, &hdev->dev_flags))
e0f9309f 987 cancel_delayed_work(&hdev->power_off);
c542a06c 988
a8b2d5c2
JH
989 if (!test_bit(HCI_MGMT, &hdev->dev_flags))
990 set_bit(HCI_PAIRABLE, &hdev->dev_flags);
c542a06c 991
1da177e4
LT
992 (dr + n)->dev_id = hdev->id;
993 (dr + n)->dev_opt = hdev->flags;
c542a06c 994
1da177e4
LT
995 if (++n >= dev_num)
996 break;
997 }
f20d09d5 998 read_unlock(&hci_dev_list_lock);
1da177e4
LT
999
1000 dl->dev_num = n;
1001 size = sizeof(*dl) + n * sizeof(*dr);
1002
1003 err = copy_to_user(arg, dl, size);
1004 kfree(dl);
1005
1006 return err ? -EFAULT : 0;
1007}
1008
1009int hci_get_dev_info(void __user *arg)
1010{
1011 struct hci_dev *hdev;
1012 struct hci_dev_info di;
1013 int err = 0;
1014
1015 if (copy_from_user(&di, arg, sizeof(di)))
1016 return -EFAULT;
1017
70f23020
AE
1018 hdev = hci_dev_get(di.dev_id);
1019 if (!hdev)
1da177e4
LT
1020 return -ENODEV;
1021
a8b2d5c2 1022 if (test_and_clear_bit(HCI_AUTO_OFF, &hdev->dev_flags))
3243553f 1023 cancel_delayed_work_sync(&hdev->power_off);
ab81cbf9 1024
a8b2d5c2
JH
1025 if (!test_bit(HCI_MGMT, &hdev->dev_flags))
1026 set_bit(HCI_PAIRABLE, &hdev->dev_flags);
c542a06c 1027
1da177e4
LT
1028 strcpy(di.name, hdev->name);
1029 di.bdaddr = hdev->bdaddr;
943da25d 1030 di.type = (hdev->bus & 0x0f) | (hdev->dev_type << 4);
1da177e4
LT
1031 di.flags = hdev->flags;
1032 di.pkt_type = hdev->pkt_type;
1033 di.acl_mtu = hdev->acl_mtu;
1034 di.acl_pkts = hdev->acl_pkts;
1035 di.sco_mtu = hdev->sco_mtu;
1036 di.sco_pkts = hdev->sco_pkts;
1037 di.link_policy = hdev->link_policy;
1038 di.link_mode = hdev->link_mode;
1039
1040 memcpy(&di.stat, &hdev->stat, sizeof(di.stat));
1041 memcpy(&di.features, &hdev->features, sizeof(di.features));
1042
1043 if (copy_to_user(arg, &di, sizeof(di)))
1044 err = -EFAULT;
1045
1046 hci_dev_put(hdev);
1047
1048 return err;
1049}
1050
1051/* ---- Interface to HCI drivers ---- */
1052
611b30f7
MH
1053static int hci_rfkill_set_block(void *data, bool blocked)
1054{
1055 struct hci_dev *hdev = data;
1056
1057 BT_DBG("%p name %s blocked %d", hdev, hdev->name, blocked);
1058
1059 if (!blocked)
1060 return 0;
1061
1062 hci_dev_do_close(hdev);
1063
1064 return 0;
1065}
1066
1067static const struct rfkill_ops hci_rfkill_ops = {
1068 .set_block = hci_rfkill_set_block,
1069};
1070
1da177e4
LT
1071/* Alloc HCI device */
1072struct hci_dev *hci_alloc_dev(void)
1073{
1074 struct hci_dev *hdev;
1075
25ea6db0 1076 hdev = kzalloc(sizeof(struct hci_dev), GFP_KERNEL);
1da177e4
LT
1077 if (!hdev)
1078 return NULL;
1079
0ac7e700 1080 hci_init_sysfs(hdev);
1da177e4
LT
1081 skb_queue_head_init(&hdev->driver_init);
1082
1083 return hdev;
1084}
1085EXPORT_SYMBOL(hci_alloc_dev);
1086
1087/* Free HCI device */
1088void hci_free_dev(struct hci_dev *hdev)
1089{
1090 skb_queue_purge(&hdev->driver_init);
1091
a91f2e39
MH
1092 /* will free via device release */
1093 put_device(&hdev->dev);
1da177e4
LT
1094}
1095EXPORT_SYMBOL(hci_free_dev);
1096
ab81cbf9
JH
1097static void hci_power_on(struct work_struct *work)
1098{
1099 struct hci_dev *hdev = container_of(work, struct hci_dev, power_on);
1100
1101 BT_DBG("%s", hdev->name);
1102
1103 if (hci_dev_open(hdev->id) < 0)
1104 return;
1105
a8b2d5c2 1106 if (test_bit(HCI_AUTO_OFF, &hdev->dev_flags))
80b7ab33 1107 schedule_delayed_work(&hdev->power_off,
3243553f 1108 msecs_to_jiffies(AUTO_OFF_TIMEOUT));
ab81cbf9 1109
a8b2d5c2 1110 if (test_and_clear_bit(HCI_SETUP, &hdev->dev_flags))
744cf19e 1111 mgmt_index_added(hdev);
ab81cbf9
JH
1112}
1113
1114static void hci_power_off(struct work_struct *work)
1115{
3243553f
JH
1116 struct hci_dev *hdev = container_of(work, struct hci_dev,
1117 power_off.work);
ab81cbf9
JH
1118
1119 BT_DBG("%s", hdev->name);
1120
a8b2d5c2 1121 clear_bit(HCI_AUTO_OFF, &hdev->dev_flags);
ab81cbf9 1122
3243553f 1123 hci_dev_close(hdev->id);
ab81cbf9
JH
1124}
1125
16ab91ab
JH
1126static void hci_discov_off(struct work_struct *work)
1127{
1128 struct hci_dev *hdev;
1129 u8 scan = SCAN_PAGE;
1130
1131 hdev = container_of(work, struct hci_dev, discov_off.work);
1132
1133 BT_DBG("%s", hdev->name);
1134
09fd0de5 1135 hci_dev_lock(hdev);
16ab91ab
JH
1136
1137 hci_send_cmd(hdev, HCI_OP_WRITE_SCAN_ENABLE, sizeof(scan), &scan);
1138
1139 hdev->discov_timeout = 0;
1140
09fd0de5 1141 hci_dev_unlock(hdev);
16ab91ab
JH
1142}
1143
2aeb9a1a
JH
1144int hci_uuids_clear(struct hci_dev *hdev)
1145{
1146 struct list_head *p, *n;
1147
1148 list_for_each_safe(p, n, &hdev->uuids) {
1149 struct bt_uuid *uuid;
1150
1151 uuid = list_entry(p, struct bt_uuid, list);
1152
1153 list_del(p);
1154 kfree(uuid);
1155 }
1156
1157 return 0;
1158}
1159
55ed8ca1
JH
1160int hci_link_keys_clear(struct hci_dev *hdev)
1161{
1162 struct list_head *p, *n;
1163
1164 list_for_each_safe(p, n, &hdev->link_keys) {
1165 struct link_key *key;
1166
1167 key = list_entry(p, struct link_key, list);
1168
1169 list_del(p);
1170 kfree(key);
1171 }
1172
1173 return 0;
1174}
1175
b899efaf
VCG
1176int hci_smp_ltks_clear(struct hci_dev *hdev)
1177{
1178 struct smp_ltk *k, *tmp;
1179
1180 list_for_each_entry_safe(k, tmp, &hdev->long_term_keys, list) {
1181 list_del(&k->list);
1182 kfree(k);
1183 }
1184
1185 return 0;
1186}
1187
55ed8ca1
JH
1188struct link_key *hci_find_link_key(struct hci_dev *hdev, bdaddr_t *bdaddr)
1189{
8035ded4 1190 struct link_key *k;
55ed8ca1 1191
8035ded4 1192 list_for_each_entry(k, &hdev->link_keys, list)
55ed8ca1
JH
1193 if (bacmp(bdaddr, &k->bdaddr) == 0)
1194 return k;
55ed8ca1
JH
1195
1196 return NULL;
1197}
1198
d25e28ab
JH
1199static int hci_persistent_key(struct hci_dev *hdev, struct hci_conn *conn,
1200 u8 key_type, u8 old_key_type)
1201{
1202 /* Legacy key */
1203 if (key_type < 0x03)
1204 return 1;
1205
1206 /* Debug keys are insecure so don't store them persistently */
1207 if (key_type == HCI_LK_DEBUG_COMBINATION)
1208 return 0;
1209
1210 /* Changed combination key and there's no previous one */
1211 if (key_type == HCI_LK_CHANGED_COMBINATION && old_key_type == 0xff)
1212 return 0;
1213
1214 /* Security mode 3 case */
1215 if (!conn)
1216 return 1;
1217
1218 /* Neither local nor remote side had no-bonding as requirement */
1219 if (conn->auth_type > 0x01 && conn->remote_auth > 0x01)
1220 return 1;
1221
1222 /* Local side had dedicated bonding as requirement */
1223 if (conn->auth_type == 0x02 || conn->auth_type == 0x03)
1224 return 1;
1225
1226 /* Remote side had dedicated bonding as requirement */
1227 if (conn->remote_auth == 0x02 || conn->remote_auth == 0x03)
1228 return 1;
1229
1230 /* If none of the above criteria match, then don't store the key
1231 * persistently */
1232 return 0;
1233}
1234
c9839a11 1235struct smp_ltk *hci_find_ltk(struct hci_dev *hdev, __le16 ediv, u8 rand[8])
75d262c2 1236{
c9839a11 1237 struct smp_ltk *k;
75d262c2 1238
c9839a11
VCG
1239 list_for_each_entry(k, &hdev->long_term_keys, list) {
1240 if (k->ediv != ediv ||
1241 memcmp(rand, k->rand, sizeof(k->rand)))
75d262c2
VCG
1242 continue;
1243
c9839a11 1244 return k;
75d262c2
VCG
1245 }
1246
1247 return NULL;
1248}
1249EXPORT_SYMBOL(hci_find_ltk);
1250
c9839a11
VCG
1251struct smp_ltk *hci_find_ltk_by_addr(struct hci_dev *hdev, bdaddr_t *bdaddr,
1252 u8 addr_type)
75d262c2 1253{
c9839a11 1254 struct smp_ltk *k;
75d262c2 1255
c9839a11
VCG
1256 list_for_each_entry(k, &hdev->long_term_keys, list)
1257 if (addr_type == k->bdaddr_type &&
1258 bacmp(bdaddr, &k->bdaddr) == 0)
75d262c2
VCG
1259 return k;
1260
1261 return NULL;
1262}
c9839a11 1263EXPORT_SYMBOL(hci_find_ltk_by_addr);
75d262c2 1264
d25e28ab
JH
1265int hci_add_link_key(struct hci_dev *hdev, struct hci_conn *conn, int new_key,
1266 bdaddr_t *bdaddr, u8 *val, u8 type, u8 pin_len)
55ed8ca1
JH
1267{
1268 struct link_key *key, *old_key;
4df378a1 1269 u8 old_key_type, persistent;
55ed8ca1
JH
1270
1271 old_key = hci_find_link_key(hdev, bdaddr);
1272 if (old_key) {
1273 old_key_type = old_key->type;
1274 key = old_key;
1275 } else {
12adcf3a 1276 old_key_type = conn ? conn->key_type : 0xff;
55ed8ca1
JH
1277 key = kzalloc(sizeof(*key), GFP_ATOMIC);
1278 if (!key)
1279 return -ENOMEM;
1280 list_add(&key->list, &hdev->link_keys);
1281 }
1282
1283 BT_DBG("%s key for %s type %u", hdev->name, batostr(bdaddr), type);
1284
d25e28ab
JH
1285 /* Some buggy controller combinations generate a changed
1286 * combination key for legacy pairing even when there's no
1287 * previous key */
1288 if (type == HCI_LK_CHANGED_COMBINATION &&
1289 (!conn || conn->remote_auth == 0xff) &&
655fe6ec 1290 old_key_type == 0xff) {
d25e28ab 1291 type = HCI_LK_COMBINATION;
655fe6ec
JH
1292 if (conn)
1293 conn->key_type = type;
1294 }
d25e28ab 1295
55ed8ca1
JH
1296 bacpy(&key->bdaddr, bdaddr);
1297 memcpy(key->val, val, 16);
55ed8ca1
JH
1298 key->pin_len = pin_len;
1299
b6020ba0 1300 if (type == HCI_LK_CHANGED_COMBINATION)
55ed8ca1 1301 key->type = old_key_type;
4748fed2
JH
1302 else
1303 key->type = type;
1304
4df378a1
JH
1305 if (!new_key)
1306 return 0;
1307
1308 persistent = hci_persistent_key(hdev, conn, type, old_key_type);
1309
744cf19e 1310 mgmt_new_link_key(hdev, key, persistent);
4df378a1
JH
1311
1312 if (!persistent) {
1313 list_del(&key->list);
1314 kfree(key);
1315 }
55ed8ca1
JH
1316
1317 return 0;
1318}
1319
c9839a11
VCG
1320int hci_add_ltk(struct hci_dev *hdev, bdaddr_t *bdaddr, u8 addr_type, u8 type,
1321 int new_key, u8 authenticated, u8 tk[16],
1322 u8 enc_size, u16 ediv, u8 rand[8])
75d262c2 1323{
c9839a11 1324 struct smp_ltk *key, *old_key;
75d262c2 1325
c9839a11
VCG
1326 if (!(type & HCI_SMP_STK) && !(type & HCI_SMP_LTK))
1327 return 0;
75d262c2 1328
c9839a11
VCG
1329 old_key = hci_find_ltk_by_addr(hdev, bdaddr, addr_type);
1330 if (old_key)
75d262c2 1331 key = old_key;
c9839a11
VCG
1332 else {
1333 key = kzalloc(sizeof(*key), GFP_ATOMIC);
75d262c2
VCG
1334 if (!key)
1335 return -ENOMEM;
c9839a11 1336 list_add(&key->list, &hdev->long_term_keys);
75d262c2
VCG
1337 }
1338
75d262c2 1339 bacpy(&key->bdaddr, bdaddr);
c9839a11
VCG
1340 key->bdaddr_type = addr_type;
1341 memcpy(key->val, tk, sizeof(key->val));
1342 key->authenticated = authenticated;
1343 key->ediv = ediv;
1344 key->enc_size = enc_size;
1345 key->type = type;
1346 memcpy(key->rand, rand, sizeof(key->rand));
75d262c2 1347
c9839a11
VCG
1348 if (!new_key)
1349 return 0;
75d262c2 1350
261cc5aa
VCG
1351 if (type & HCI_SMP_LTK)
1352 mgmt_new_ltk(hdev, key, 1);
1353
75d262c2
VCG
1354 return 0;
1355}
1356
55ed8ca1
JH
1357int hci_remove_link_key(struct hci_dev *hdev, bdaddr_t *bdaddr)
1358{
1359 struct link_key *key;
1360
1361 key = hci_find_link_key(hdev, bdaddr);
1362 if (!key)
1363 return -ENOENT;
1364
1365 BT_DBG("%s removing %s", hdev->name, batostr(bdaddr));
1366
1367 list_del(&key->list);
1368 kfree(key);
1369
1370 return 0;
1371}
1372
b899efaf
VCG
1373int hci_remove_ltk(struct hci_dev *hdev, bdaddr_t *bdaddr)
1374{
1375 struct smp_ltk *k, *tmp;
1376
1377 list_for_each_entry_safe(k, tmp, &hdev->long_term_keys, list) {
1378 if (bacmp(bdaddr, &k->bdaddr))
1379 continue;
1380
1381 BT_DBG("%s removing %s", hdev->name, batostr(bdaddr));
1382
1383 list_del(&k->list);
1384 kfree(k);
1385 }
1386
1387 return 0;
1388}
1389
6bd32326
VT
1390/* HCI command timer function */
1391static void hci_cmd_timer(unsigned long arg)
1392{
1393 struct hci_dev *hdev = (void *) arg;
1394
1395 BT_ERR("%s command tx timeout", hdev->name);
1396 atomic_set(&hdev->cmd_cnt, 1);
c347b765 1397 queue_work(hdev->workqueue, &hdev->cmd_work);
6bd32326
VT
1398}
1399
2763eda6
SJ
1400struct oob_data *hci_find_remote_oob_data(struct hci_dev *hdev,
1401 bdaddr_t *bdaddr)
1402{
1403 struct oob_data *data;
1404
1405 list_for_each_entry(data, &hdev->remote_oob_data, list)
1406 if (bacmp(bdaddr, &data->bdaddr) == 0)
1407 return data;
1408
1409 return NULL;
1410}
1411
1412int hci_remove_remote_oob_data(struct hci_dev *hdev, bdaddr_t *bdaddr)
1413{
1414 struct oob_data *data;
1415
1416 data = hci_find_remote_oob_data(hdev, bdaddr);
1417 if (!data)
1418 return -ENOENT;
1419
1420 BT_DBG("%s removing %s", hdev->name, batostr(bdaddr));
1421
1422 list_del(&data->list);
1423 kfree(data);
1424
1425 return 0;
1426}
1427
1428int hci_remote_oob_data_clear(struct hci_dev *hdev)
1429{
1430 struct oob_data *data, *n;
1431
1432 list_for_each_entry_safe(data, n, &hdev->remote_oob_data, list) {
1433 list_del(&data->list);
1434 kfree(data);
1435 }
1436
1437 return 0;
1438}
1439
1440int hci_add_remote_oob_data(struct hci_dev *hdev, bdaddr_t *bdaddr, u8 *hash,
1441 u8 *randomizer)
1442{
1443 struct oob_data *data;
1444
1445 data = hci_find_remote_oob_data(hdev, bdaddr);
1446
1447 if (!data) {
1448 data = kmalloc(sizeof(*data), GFP_ATOMIC);
1449 if (!data)
1450 return -ENOMEM;
1451
1452 bacpy(&data->bdaddr, bdaddr);
1453 list_add(&data->list, &hdev->remote_oob_data);
1454 }
1455
1456 memcpy(data->hash, hash, sizeof(data->hash));
1457 memcpy(data->randomizer, randomizer, sizeof(data->randomizer));
1458
1459 BT_DBG("%s for %s", hdev->name, batostr(bdaddr));
1460
1461 return 0;
1462}
1463
b2a66aad
AJ
1464struct bdaddr_list *hci_blacklist_lookup(struct hci_dev *hdev,
1465 bdaddr_t *bdaddr)
1466{
8035ded4 1467 struct bdaddr_list *b;
b2a66aad 1468
8035ded4 1469 list_for_each_entry(b, &hdev->blacklist, list)
b2a66aad
AJ
1470 if (bacmp(bdaddr, &b->bdaddr) == 0)
1471 return b;
b2a66aad
AJ
1472
1473 return NULL;
1474}
1475
1476int hci_blacklist_clear(struct hci_dev *hdev)
1477{
1478 struct list_head *p, *n;
1479
1480 list_for_each_safe(p, n, &hdev->blacklist) {
1481 struct bdaddr_list *b;
1482
1483 b = list_entry(p, struct bdaddr_list, list);
1484
1485 list_del(p);
1486 kfree(b);
1487 }
1488
1489 return 0;
1490}
1491
88c1fe4b 1492int hci_blacklist_add(struct hci_dev *hdev, bdaddr_t *bdaddr, u8 type)
b2a66aad
AJ
1493{
1494 struct bdaddr_list *entry;
b2a66aad
AJ
1495
1496 if (bacmp(bdaddr, BDADDR_ANY) == 0)
1497 return -EBADF;
1498
5e762444
AJ
1499 if (hci_blacklist_lookup(hdev, bdaddr))
1500 return -EEXIST;
b2a66aad
AJ
1501
1502 entry = kzalloc(sizeof(struct bdaddr_list), GFP_KERNEL);
5e762444
AJ
1503 if (!entry)
1504 return -ENOMEM;
b2a66aad
AJ
1505
1506 bacpy(&entry->bdaddr, bdaddr);
1507
1508 list_add(&entry->list, &hdev->blacklist);
1509
88c1fe4b 1510 return mgmt_device_blocked(hdev, bdaddr, type);
b2a66aad
AJ
1511}
1512
88c1fe4b 1513int hci_blacklist_del(struct hci_dev *hdev, bdaddr_t *bdaddr, u8 type)
b2a66aad
AJ
1514{
1515 struct bdaddr_list *entry;
b2a66aad 1516
1ec918ce 1517 if (bacmp(bdaddr, BDADDR_ANY) == 0)
5e762444 1518 return hci_blacklist_clear(hdev);
b2a66aad
AJ
1519
1520 entry = hci_blacklist_lookup(hdev, bdaddr);
1ec918ce 1521 if (!entry)
5e762444 1522 return -ENOENT;
b2a66aad
AJ
1523
1524 list_del(&entry->list);
1525 kfree(entry);
1526
88c1fe4b 1527 return mgmt_device_unblocked(hdev, bdaddr, type);
b2a66aad
AJ
1528}
1529
db323f2f 1530static void hci_clear_adv_cache(struct work_struct *work)
35815085 1531{
db323f2f
GP
1532 struct hci_dev *hdev = container_of(work, struct hci_dev,
1533 adv_work.work);
35815085
AG
1534
1535 hci_dev_lock(hdev);
1536
1537 hci_adv_entries_clear(hdev);
1538
1539 hci_dev_unlock(hdev);
1540}
1541
76c8686f
AG
1542int hci_adv_entries_clear(struct hci_dev *hdev)
1543{
1544 struct adv_entry *entry, *tmp;
1545
1546 list_for_each_entry_safe(entry, tmp, &hdev->adv_entries, list) {
1547 list_del(&entry->list);
1548 kfree(entry);
1549 }
1550
1551 BT_DBG("%s adv cache cleared", hdev->name);
1552
1553 return 0;
1554}
1555
1556struct adv_entry *hci_find_adv_entry(struct hci_dev *hdev, bdaddr_t *bdaddr)
1557{
1558 struct adv_entry *entry;
1559
1560 list_for_each_entry(entry, &hdev->adv_entries, list)
1561 if (bacmp(bdaddr, &entry->bdaddr) == 0)
1562 return entry;
1563
1564 return NULL;
1565}
1566
1567static inline int is_connectable_adv(u8 evt_type)
1568{
1569 if (evt_type == ADV_IND || evt_type == ADV_DIRECT_IND)
1570 return 1;
1571
1572 return 0;
1573}
1574
1575int hci_add_adv_entry(struct hci_dev *hdev,
1576 struct hci_ev_le_advertising_info *ev)
1577{
1578 struct adv_entry *entry;
1579
1580 if (!is_connectable_adv(ev->evt_type))
1581 return -EINVAL;
1582
1583 /* Only new entries should be added to adv_entries. So, if
1584 * bdaddr was found, don't add it. */
1585 if (hci_find_adv_entry(hdev, &ev->bdaddr))
1586 return 0;
1587
4777bfde 1588 entry = kzalloc(sizeof(*entry), GFP_KERNEL);
76c8686f
AG
1589 if (!entry)
1590 return -ENOMEM;
1591
1592 bacpy(&entry->bdaddr, &ev->bdaddr);
1593 entry->bdaddr_type = ev->bdaddr_type;
1594
1595 list_add(&entry->list, &hdev->adv_entries);
1596
1597 BT_DBG("%s adv entry added: address %s type %u", hdev->name,
1598 batostr(&entry->bdaddr), entry->bdaddr_type);
1599
1600 return 0;
1601}
1602
7ba8b4be
AG
1603static void le_scan_param_req(struct hci_dev *hdev, unsigned long opt)
1604{
1605 struct le_scan_params *param = (struct le_scan_params *) opt;
1606 struct hci_cp_le_set_scan_param cp;
1607
1608 memset(&cp, 0, sizeof(cp));
1609 cp.type = param->type;
1610 cp.interval = cpu_to_le16(param->interval);
1611 cp.window = cpu_to_le16(param->window);
1612
1613 hci_send_cmd(hdev, HCI_OP_LE_SET_SCAN_PARAM, sizeof(cp), &cp);
1614}
1615
1616static void le_scan_enable_req(struct hci_dev *hdev, unsigned long opt)
1617{
1618 struct hci_cp_le_set_scan_enable cp;
1619
1620 memset(&cp, 0, sizeof(cp));
1621 cp.enable = 1;
1622
1623 hci_send_cmd(hdev, HCI_OP_LE_SET_SCAN_ENABLE, sizeof(cp), &cp);
1624}
1625
1626static int hci_do_le_scan(struct hci_dev *hdev, u8 type, u16 interval,
1627 u16 window, int timeout)
1628{
1629 long timeo = msecs_to_jiffies(3000);
1630 struct le_scan_params param;
1631 int err;
1632
1633 BT_DBG("%s", hdev->name);
1634
1635 if (test_bit(HCI_LE_SCAN, &hdev->dev_flags))
1636 return -EINPROGRESS;
1637
1638 param.type = type;
1639 param.interval = interval;
1640 param.window = window;
1641
1642 hci_req_lock(hdev);
1643
1644 err = __hci_request(hdev, le_scan_param_req, (unsigned long) &param,
1645 timeo);
1646 if (!err)
1647 err = __hci_request(hdev, le_scan_enable_req, 0, timeo);
1648
1649 hci_req_unlock(hdev);
1650
1651 if (err < 0)
1652 return err;
1653
1654 schedule_delayed_work(&hdev->le_scan_disable,
1655 msecs_to_jiffies(timeout));
1656
1657 return 0;
1658}
1659
1660static void le_scan_disable_work(struct work_struct *work)
1661{
1662 struct hci_dev *hdev = container_of(work, struct hci_dev,
1663 le_scan_disable.work);
1664 struct hci_cp_le_set_scan_enable cp;
1665
1666 BT_DBG("%s", hdev->name);
1667
1668 memset(&cp, 0, sizeof(cp));
1669
1670 hci_send_cmd(hdev, HCI_OP_LE_SET_SCAN_ENABLE, sizeof(cp), &cp);
1671}
1672
28b75a89
AG
1673static void le_scan_work(struct work_struct *work)
1674{
1675 struct hci_dev *hdev = container_of(work, struct hci_dev, le_scan);
1676 struct le_scan_params *param = &hdev->le_scan_params;
1677
1678 BT_DBG("%s", hdev->name);
1679
1680 hci_do_le_scan(hdev, param->type, param->interval,
1681 param->window, param->timeout);
1682}
1683
1684int hci_le_scan(struct hci_dev *hdev, u8 type, u16 interval, u16 window,
1685 int timeout)
1686{
1687 struct le_scan_params *param = &hdev->le_scan_params;
1688
1689 BT_DBG("%s", hdev->name);
1690
1691 if (work_busy(&hdev->le_scan))
1692 return -EINPROGRESS;
1693
1694 param->type = type;
1695 param->interval = interval;
1696 param->window = window;
1697 param->timeout = timeout;
1698
1699 queue_work(system_long_wq, &hdev->le_scan);
1700
1701 return 0;
1702}
1703
1da177e4
LT
1704/* Register HCI device */
1705int hci_register_dev(struct hci_dev *hdev)
1706{
1707 struct list_head *head = &hci_dev_list, *p;
08add513 1708 int i, id, error;
1da177e4 1709
e9b9cfa1 1710 BT_DBG("%p name %s bus %d", hdev, hdev->name, hdev->bus);
1da177e4 1711
010666a1 1712 if (!hdev->open || !hdev->close)
1da177e4
LT
1713 return -EINVAL;
1714
08add513
MM
1715 /* Do not allow HCI_AMP devices to register at index 0,
1716 * so the index can be used as the AMP controller ID.
1717 */
1718 id = (hdev->dev_type == HCI_BREDR) ? 0 : 1;
1719
f20d09d5 1720 write_lock(&hci_dev_list_lock);
1da177e4
LT
1721
1722 /* Find first available device id */
1723 list_for_each(p, &hci_dev_list) {
1724 if (list_entry(p, struct hci_dev, list)->id != id)
1725 break;
1726 head = p; id++;
1727 }
8e87d142 1728
1da177e4
LT
1729 sprintf(hdev->name, "hci%d", id);
1730 hdev->id = id;
c6feeb28 1731 list_add_tail(&hdev->list, head);
1da177e4 1732
09fd0de5 1733 mutex_init(&hdev->lock);
1da177e4
LT
1734
1735 hdev->flags = 0;
d23264a8 1736 hdev->dev_flags = 0;
1da177e4 1737 hdev->pkt_type = (HCI_DM1 | HCI_DH1 | HCI_HV1);
5b7f9909 1738 hdev->esco_type = (ESCO_HV1);
1da177e4 1739 hdev->link_mode = (HCI_LM_ACCEPT);
17fa4b9d 1740 hdev->io_capability = 0x03; /* No Input No Output */
1da177e4 1741
04837f64
MH
1742 hdev->idle_timeout = 0;
1743 hdev->sniff_max_interval = 800;
1744 hdev->sniff_min_interval = 80;
1745
b78752cc 1746 INIT_WORK(&hdev->rx_work, hci_rx_work);
c347b765 1747 INIT_WORK(&hdev->cmd_work, hci_cmd_work);
3eff45ea 1748 INIT_WORK(&hdev->tx_work, hci_tx_work);
b78752cc 1749
1da177e4
LT
1750
1751 skb_queue_head_init(&hdev->rx_q);
1752 skb_queue_head_init(&hdev->cmd_q);
1753 skb_queue_head_init(&hdev->raw_q);
1754
6bd32326
VT
1755 setup_timer(&hdev->cmd_timer, hci_cmd_timer, (unsigned long) hdev);
1756
cd4c5391 1757 for (i = 0; i < NUM_REASSEMBLY; i++)
ef222013
MH
1758 hdev->reassembly[i] = NULL;
1759
1da177e4 1760 init_waitqueue_head(&hdev->req_wait_q);
a6a67efd 1761 mutex_init(&hdev->req_lock);
1da177e4 1762
30883512 1763 discovery_init(hdev);
1da177e4
LT
1764
1765 hci_conn_hash_init(hdev);
1766
2e58ef3e
JH
1767 INIT_LIST_HEAD(&hdev->mgmt_pending);
1768
ea4bd8ba 1769 INIT_LIST_HEAD(&hdev->blacklist);
f0358568 1770
2aeb9a1a
JH
1771 INIT_LIST_HEAD(&hdev->uuids);
1772
55ed8ca1 1773 INIT_LIST_HEAD(&hdev->link_keys);
b899efaf 1774 INIT_LIST_HEAD(&hdev->long_term_keys);
55ed8ca1 1775
2763eda6
SJ
1776 INIT_LIST_HEAD(&hdev->remote_oob_data);
1777
76c8686f
AG
1778 INIT_LIST_HEAD(&hdev->adv_entries);
1779
db323f2f 1780 INIT_DELAYED_WORK(&hdev->adv_work, hci_clear_adv_cache);
ab81cbf9 1781 INIT_WORK(&hdev->power_on, hci_power_on);
3243553f 1782 INIT_DELAYED_WORK(&hdev->power_off, hci_power_off);
ab81cbf9 1783
16ab91ab
JH
1784 INIT_DELAYED_WORK(&hdev->discov_off, hci_discov_off);
1785
1da177e4
LT
1786 memset(&hdev->stat, 0, sizeof(struct hci_dev_stats));
1787
1788 atomic_set(&hdev->promisc, 0);
1789
28b75a89
AG
1790 INIT_WORK(&hdev->le_scan, le_scan_work);
1791
7ba8b4be
AG
1792 INIT_DELAYED_WORK(&hdev->le_scan_disable, le_scan_disable_work);
1793
f20d09d5 1794 write_unlock(&hci_dev_list_lock);
1da177e4 1795
32845eb1
GP
1796 hdev->workqueue = alloc_workqueue(hdev->name, WQ_HIGHPRI | WQ_UNBOUND |
1797 WQ_MEM_RECLAIM, 1);
33ca954d
DH
1798 if (!hdev->workqueue) {
1799 error = -ENOMEM;
1800 goto err;
1801 }
f48fd9c8 1802
33ca954d
DH
1803 error = hci_add_sysfs(hdev);
1804 if (error < 0)
1805 goto err_wqueue;
1da177e4 1806
611b30f7
MH
1807 hdev->rfkill = rfkill_alloc(hdev->name, &hdev->dev,
1808 RFKILL_TYPE_BLUETOOTH, &hci_rfkill_ops, hdev);
1809 if (hdev->rfkill) {
1810 if (rfkill_register(hdev->rfkill) < 0) {
1811 rfkill_destroy(hdev->rfkill);
1812 hdev->rfkill = NULL;
1813 }
1814 }
1815
a8b2d5c2
JH
1816 set_bit(HCI_AUTO_OFF, &hdev->dev_flags);
1817 set_bit(HCI_SETUP, &hdev->dev_flags);
7f971041 1818 schedule_work(&hdev->power_on);
ab81cbf9 1819
1da177e4 1820 hci_notify(hdev, HCI_DEV_REG);
dc946bd8 1821 hci_dev_hold(hdev);
1da177e4
LT
1822
1823 return id;
f48fd9c8 1824
33ca954d
DH
1825err_wqueue:
1826 destroy_workqueue(hdev->workqueue);
1827err:
f20d09d5 1828 write_lock(&hci_dev_list_lock);
f48fd9c8 1829 list_del(&hdev->list);
f20d09d5 1830 write_unlock(&hci_dev_list_lock);
f48fd9c8 1831
33ca954d 1832 return error;
1da177e4
LT
1833}
1834EXPORT_SYMBOL(hci_register_dev);
1835
1836/* Unregister HCI device */
59735631 1837void hci_unregister_dev(struct hci_dev *hdev)
1da177e4 1838{
ef222013
MH
1839 int i;
1840
c13854ce 1841 BT_DBG("%p name %s bus %d", hdev, hdev->name, hdev->bus);
1da177e4 1842
f20d09d5 1843 write_lock(&hci_dev_list_lock);
1da177e4 1844 list_del(&hdev->list);
f20d09d5 1845 write_unlock(&hci_dev_list_lock);
1da177e4
LT
1846
1847 hci_dev_do_close(hdev);
1848
cd4c5391 1849 for (i = 0; i < NUM_REASSEMBLY; i++)
ef222013
MH
1850 kfree_skb(hdev->reassembly[i]);
1851
ab81cbf9 1852 if (!test_bit(HCI_INIT, &hdev->flags) &&
a8b2d5c2 1853 !test_bit(HCI_SETUP, &hdev->dev_flags)) {
09fd0de5 1854 hci_dev_lock(hdev);
744cf19e 1855 mgmt_index_removed(hdev);
09fd0de5 1856 hci_dev_unlock(hdev);
56e5cb86 1857 }
ab81cbf9 1858
2e58ef3e
JH
1859 /* mgmt_index_removed should take care of emptying the
1860 * pending list */
1861 BUG_ON(!list_empty(&hdev->mgmt_pending));
1862
1da177e4
LT
1863 hci_notify(hdev, HCI_DEV_UNREG);
1864
611b30f7
MH
1865 if (hdev->rfkill) {
1866 rfkill_unregister(hdev->rfkill);
1867 rfkill_destroy(hdev->rfkill);
1868 }
1869
ce242970 1870 hci_del_sysfs(hdev);
147e2d59 1871
db323f2f 1872 cancel_delayed_work_sync(&hdev->adv_work);
c6f3c5f7 1873
f48fd9c8
MH
1874 destroy_workqueue(hdev->workqueue);
1875
09fd0de5 1876 hci_dev_lock(hdev);
e2e0cacb 1877 hci_blacklist_clear(hdev);
2aeb9a1a 1878 hci_uuids_clear(hdev);
55ed8ca1 1879 hci_link_keys_clear(hdev);
b899efaf 1880 hci_smp_ltks_clear(hdev);
2763eda6 1881 hci_remote_oob_data_clear(hdev);
76c8686f 1882 hci_adv_entries_clear(hdev);
09fd0de5 1883 hci_dev_unlock(hdev);
e2e0cacb 1884
dc946bd8 1885 hci_dev_put(hdev);
1da177e4
LT
1886}
1887EXPORT_SYMBOL(hci_unregister_dev);
1888
1889/* Suspend HCI device */
1890int hci_suspend_dev(struct hci_dev *hdev)
1891{
1892 hci_notify(hdev, HCI_DEV_SUSPEND);
1893 return 0;
1894}
1895EXPORT_SYMBOL(hci_suspend_dev);
1896
1897/* Resume HCI device */
1898int hci_resume_dev(struct hci_dev *hdev)
1899{
1900 hci_notify(hdev, HCI_DEV_RESUME);
1901 return 0;
1902}
1903EXPORT_SYMBOL(hci_resume_dev);
1904
76bca880
MH
1905/* Receive frame from HCI drivers */
1906int hci_recv_frame(struct sk_buff *skb)
1907{
1908 struct hci_dev *hdev = (struct hci_dev *) skb->dev;
1909 if (!hdev || (!test_bit(HCI_UP, &hdev->flags)
1910 && !test_bit(HCI_INIT, &hdev->flags))) {
1911 kfree_skb(skb);
1912 return -ENXIO;
1913 }
1914
1915 /* Incomming skb */
1916 bt_cb(skb)->incoming = 1;
1917
1918 /* Time stamp */
1919 __net_timestamp(skb);
1920
76bca880 1921 skb_queue_tail(&hdev->rx_q, skb);
b78752cc 1922 queue_work(hdev->workqueue, &hdev->rx_work);
c78ae283 1923
76bca880
MH
1924 return 0;
1925}
1926EXPORT_SYMBOL(hci_recv_frame);
1927
33e882a5 1928static int hci_reassembly(struct hci_dev *hdev, int type, void *data,
1e429f38 1929 int count, __u8 index)
33e882a5
SS
1930{
1931 int len = 0;
1932 int hlen = 0;
1933 int remain = count;
1934 struct sk_buff *skb;
1935 struct bt_skb_cb *scb;
1936
1937 if ((type < HCI_ACLDATA_PKT || type > HCI_EVENT_PKT) ||
1938 index >= NUM_REASSEMBLY)
1939 return -EILSEQ;
1940
1941 skb = hdev->reassembly[index];
1942
1943 if (!skb) {
1944 switch (type) {
1945 case HCI_ACLDATA_PKT:
1946 len = HCI_MAX_FRAME_SIZE;
1947 hlen = HCI_ACL_HDR_SIZE;
1948 break;
1949 case HCI_EVENT_PKT:
1950 len = HCI_MAX_EVENT_SIZE;
1951 hlen = HCI_EVENT_HDR_SIZE;
1952 break;
1953 case HCI_SCODATA_PKT:
1954 len = HCI_MAX_SCO_SIZE;
1955 hlen = HCI_SCO_HDR_SIZE;
1956 break;
1957 }
1958
1e429f38 1959 skb = bt_skb_alloc(len, GFP_ATOMIC);
33e882a5
SS
1960 if (!skb)
1961 return -ENOMEM;
1962
1963 scb = (void *) skb->cb;
1964 scb->expect = hlen;
1965 scb->pkt_type = type;
1966
1967 skb->dev = (void *) hdev;
1968 hdev->reassembly[index] = skb;
1969 }
1970
1971 while (count) {
1972 scb = (void *) skb->cb;
1973 len = min(scb->expect, (__u16)count);
1974
1975 memcpy(skb_put(skb, len), data, len);
1976
1977 count -= len;
1978 data += len;
1979 scb->expect -= len;
1980 remain = count;
1981
1982 switch (type) {
1983 case HCI_EVENT_PKT:
1984 if (skb->len == HCI_EVENT_HDR_SIZE) {
1985 struct hci_event_hdr *h = hci_event_hdr(skb);
1986 scb->expect = h->plen;
1987
1988 if (skb_tailroom(skb) < scb->expect) {
1989 kfree_skb(skb);
1990 hdev->reassembly[index] = NULL;
1991 return -ENOMEM;
1992 }
1993 }
1994 break;
1995
1996 case HCI_ACLDATA_PKT:
1997 if (skb->len == HCI_ACL_HDR_SIZE) {
1998 struct hci_acl_hdr *h = hci_acl_hdr(skb);
1999 scb->expect = __le16_to_cpu(h->dlen);
2000
2001 if (skb_tailroom(skb) < scb->expect) {
2002 kfree_skb(skb);
2003 hdev->reassembly[index] = NULL;
2004 return -ENOMEM;
2005 }
2006 }
2007 break;
2008
2009 case HCI_SCODATA_PKT:
2010 if (skb->len == HCI_SCO_HDR_SIZE) {
2011 struct hci_sco_hdr *h = hci_sco_hdr(skb);
2012 scb->expect = h->dlen;
2013
2014 if (skb_tailroom(skb) < scb->expect) {
2015 kfree_skb(skb);
2016 hdev->reassembly[index] = NULL;
2017 return -ENOMEM;
2018 }
2019 }
2020 break;
2021 }
2022
2023 if (scb->expect == 0) {
2024 /* Complete frame */
2025
2026 bt_cb(skb)->pkt_type = type;
2027 hci_recv_frame(skb);
2028
2029 hdev->reassembly[index] = NULL;
2030 return remain;
2031 }
2032 }
2033
2034 return remain;
2035}
2036
ef222013
MH
2037int hci_recv_fragment(struct hci_dev *hdev, int type, void *data, int count)
2038{
f39a3c06
SS
2039 int rem = 0;
2040
ef222013
MH
2041 if (type < HCI_ACLDATA_PKT || type > HCI_EVENT_PKT)
2042 return -EILSEQ;
2043
da5f6c37 2044 while (count) {
1e429f38 2045 rem = hci_reassembly(hdev, type, data, count, type - 1);
f39a3c06
SS
2046 if (rem < 0)
2047 return rem;
ef222013 2048
f39a3c06
SS
2049 data += (count - rem);
2050 count = rem;
f81c6224 2051 }
ef222013 2052
f39a3c06 2053 return rem;
ef222013
MH
2054}
2055EXPORT_SYMBOL(hci_recv_fragment);
2056
99811510
SS
2057#define STREAM_REASSEMBLY 0
2058
2059int hci_recv_stream_fragment(struct hci_dev *hdev, void *data, int count)
2060{
2061 int type;
2062 int rem = 0;
2063
da5f6c37 2064 while (count) {
99811510
SS
2065 struct sk_buff *skb = hdev->reassembly[STREAM_REASSEMBLY];
2066
2067 if (!skb) {
2068 struct { char type; } *pkt;
2069
2070 /* Start of the frame */
2071 pkt = data;
2072 type = pkt->type;
2073
2074 data++;
2075 count--;
2076 } else
2077 type = bt_cb(skb)->pkt_type;
2078
1e429f38
GP
2079 rem = hci_reassembly(hdev, type, data, count,
2080 STREAM_REASSEMBLY);
99811510
SS
2081 if (rem < 0)
2082 return rem;
2083
2084 data += (count - rem);
2085 count = rem;
f81c6224 2086 }
99811510
SS
2087
2088 return rem;
2089}
2090EXPORT_SYMBOL(hci_recv_stream_fragment);
2091
1da177e4
LT
2092/* ---- Interface to upper protocols ---- */
2093
1da177e4
LT
2094int hci_register_cb(struct hci_cb *cb)
2095{
2096 BT_DBG("%p name %s", cb, cb->name);
2097
f20d09d5 2098 write_lock(&hci_cb_list_lock);
1da177e4 2099 list_add(&cb->list, &hci_cb_list);
f20d09d5 2100 write_unlock(&hci_cb_list_lock);
1da177e4
LT
2101
2102 return 0;
2103}
2104EXPORT_SYMBOL(hci_register_cb);
2105
2106int hci_unregister_cb(struct hci_cb *cb)
2107{
2108 BT_DBG("%p name %s", cb, cb->name);
2109
f20d09d5 2110 write_lock(&hci_cb_list_lock);
1da177e4 2111 list_del(&cb->list);
f20d09d5 2112 write_unlock(&hci_cb_list_lock);
1da177e4
LT
2113
2114 return 0;
2115}
2116EXPORT_SYMBOL(hci_unregister_cb);
2117
2118static int hci_send_frame(struct sk_buff *skb)
2119{
2120 struct hci_dev *hdev = (struct hci_dev *) skb->dev;
2121
2122 if (!hdev) {
2123 kfree_skb(skb);
2124 return -ENODEV;
2125 }
2126
0d48d939 2127 BT_DBG("%s type %d len %d", hdev->name, bt_cb(skb)->pkt_type, skb->len);
1da177e4
LT
2128
2129 if (atomic_read(&hdev->promisc)) {
2130 /* Time stamp */
a61bbcf2 2131 __net_timestamp(skb);
1da177e4 2132
eec8d2bc 2133 hci_send_to_sock(hdev, skb, NULL);
1da177e4
LT
2134 }
2135
2136 /* Get rid of skb owner, prior to sending to the driver. */
2137 skb_orphan(skb);
2138
2139 return hdev->send(skb);
2140}
2141
2142/* Send HCI command */
a9de9248 2143int hci_send_cmd(struct hci_dev *hdev, __u16 opcode, __u32 plen, void *param)
1da177e4
LT
2144{
2145 int len = HCI_COMMAND_HDR_SIZE + plen;
2146 struct hci_command_hdr *hdr;
2147 struct sk_buff *skb;
2148
a9de9248 2149 BT_DBG("%s opcode 0x%x plen %d", hdev->name, opcode, plen);
1da177e4
LT
2150
2151 skb = bt_skb_alloc(len, GFP_ATOMIC);
2152 if (!skb) {
ef222013 2153 BT_ERR("%s no memory for command", hdev->name);
1da177e4
LT
2154 return -ENOMEM;
2155 }
2156
2157 hdr = (struct hci_command_hdr *) skb_put(skb, HCI_COMMAND_HDR_SIZE);
a9de9248 2158 hdr->opcode = cpu_to_le16(opcode);
1da177e4
LT
2159 hdr->plen = plen;
2160
2161 if (plen)
2162 memcpy(skb_put(skb, plen), param, plen);
2163
2164 BT_DBG("skb len %d", skb->len);
2165
0d48d939 2166 bt_cb(skb)->pkt_type = HCI_COMMAND_PKT;
1da177e4 2167 skb->dev = (void *) hdev;
c78ae283 2168
a5040efa
JH
2169 if (test_bit(HCI_INIT, &hdev->flags))
2170 hdev->init_last_cmd = opcode;
2171
1da177e4 2172 skb_queue_tail(&hdev->cmd_q, skb);
c347b765 2173 queue_work(hdev->workqueue, &hdev->cmd_work);
1da177e4
LT
2174
2175 return 0;
2176}
1da177e4
LT
2177
2178/* Get data from the previously sent command */
a9de9248 2179void *hci_sent_cmd_data(struct hci_dev *hdev, __u16 opcode)
1da177e4
LT
2180{
2181 struct hci_command_hdr *hdr;
2182
2183 if (!hdev->sent_cmd)
2184 return NULL;
2185
2186 hdr = (void *) hdev->sent_cmd->data;
2187
a9de9248 2188 if (hdr->opcode != cpu_to_le16(opcode))
1da177e4
LT
2189 return NULL;
2190
a9de9248 2191 BT_DBG("%s opcode 0x%x", hdev->name, opcode);
1da177e4
LT
2192
2193 return hdev->sent_cmd->data + HCI_COMMAND_HDR_SIZE;
2194}
2195
2196/* Send ACL data */
2197static void hci_add_acl_hdr(struct sk_buff *skb, __u16 handle, __u16 flags)
2198{
2199 struct hci_acl_hdr *hdr;
2200 int len = skb->len;
2201
badff6d0
ACM
2202 skb_push(skb, HCI_ACL_HDR_SIZE);
2203 skb_reset_transport_header(skb);
9c70220b 2204 hdr = (struct hci_acl_hdr *)skb_transport_header(skb);
aca3192c
YH
2205 hdr->handle = cpu_to_le16(hci_handle_pack(handle, flags));
2206 hdr->dlen = cpu_to_le16(len);
1da177e4
LT
2207}
2208
73d80deb
LAD
2209static void hci_queue_acl(struct hci_conn *conn, struct sk_buff_head *queue,
2210 struct sk_buff *skb, __u16 flags)
1da177e4
LT
2211{
2212 struct hci_dev *hdev = conn->hdev;
2213 struct sk_buff *list;
2214
70f23020
AE
2215 list = skb_shinfo(skb)->frag_list;
2216 if (!list) {
1da177e4
LT
2217 /* Non fragmented */
2218 BT_DBG("%s nonfrag skb %p len %d", hdev->name, skb, skb->len);
2219
73d80deb 2220 skb_queue_tail(queue, skb);
1da177e4
LT
2221 } else {
2222 /* Fragmented */
2223 BT_DBG("%s frag %p len %d", hdev->name, skb, skb->len);
2224
2225 skb_shinfo(skb)->frag_list = NULL;
2226
2227 /* Queue all fragments atomically */
af3e6359 2228 spin_lock(&queue->lock);
1da177e4 2229
73d80deb 2230 __skb_queue_tail(queue, skb);
e702112f
AE
2231
2232 flags &= ~ACL_START;
2233 flags |= ACL_CONT;
1da177e4
LT
2234 do {
2235 skb = list; list = list->next;
8e87d142 2236
1da177e4 2237 skb->dev = (void *) hdev;
0d48d939 2238 bt_cb(skb)->pkt_type = HCI_ACLDATA_PKT;
e702112f 2239 hci_add_acl_hdr(skb, conn->handle, flags);
1da177e4
LT
2240
2241 BT_DBG("%s frag %p len %d", hdev->name, skb, skb->len);
2242
73d80deb 2243 __skb_queue_tail(queue, skb);
1da177e4
LT
2244 } while (list);
2245
af3e6359 2246 spin_unlock(&queue->lock);
1da177e4 2247 }
73d80deb
LAD
2248}
2249
2250void hci_send_acl(struct hci_chan *chan, struct sk_buff *skb, __u16 flags)
2251{
2252 struct hci_conn *conn = chan->conn;
2253 struct hci_dev *hdev = conn->hdev;
2254
2255 BT_DBG("%s chan %p flags 0x%x", hdev->name, chan, flags);
2256
2257 skb->dev = (void *) hdev;
2258 bt_cb(skb)->pkt_type = HCI_ACLDATA_PKT;
2259 hci_add_acl_hdr(skb, conn->handle, flags);
2260
2261 hci_queue_acl(conn, &chan->data_q, skb, flags);
1da177e4 2262
3eff45ea 2263 queue_work(hdev->workqueue, &hdev->tx_work);
1da177e4
LT
2264}
2265EXPORT_SYMBOL(hci_send_acl);
2266
2267/* Send SCO data */
0d861d8b 2268void hci_send_sco(struct hci_conn *conn, struct sk_buff *skb)
1da177e4
LT
2269{
2270 struct hci_dev *hdev = conn->hdev;
2271 struct hci_sco_hdr hdr;
2272
2273 BT_DBG("%s len %d", hdev->name, skb->len);
2274
aca3192c 2275 hdr.handle = cpu_to_le16(conn->handle);
1da177e4
LT
2276 hdr.dlen = skb->len;
2277
badff6d0
ACM
2278 skb_push(skb, HCI_SCO_HDR_SIZE);
2279 skb_reset_transport_header(skb);
9c70220b 2280 memcpy(skb_transport_header(skb), &hdr, HCI_SCO_HDR_SIZE);
1da177e4
LT
2281
2282 skb->dev = (void *) hdev;
0d48d939 2283 bt_cb(skb)->pkt_type = HCI_SCODATA_PKT;
c78ae283 2284
1da177e4 2285 skb_queue_tail(&conn->data_q, skb);
3eff45ea 2286 queue_work(hdev->workqueue, &hdev->tx_work);
1da177e4
LT
2287}
2288EXPORT_SYMBOL(hci_send_sco);
2289
2290/* ---- HCI TX task (outgoing data) ---- */
2291
2292/* HCI Connection scheduler */
2293static inline struct hci_conn *hci_low_sent(struct hci_dev *hdev, __u8 type, int *quote)
2294{
2295 struct hci_conn_hash *h = &hdev->conn_hash;
8035ded4 2296 struct hci_conn *conn = NULL, *c;
1da177e4 2297 int num = 0, min = ~0;
1da177e4 2298
8e87d142 2299 /* We don't have to lock device here. Connections are always
1da177e4 2300 * added and removed with TX task disabled. */
bf4c6325
GP
2301
2302 rcu_read_lock();
2303
2304 list_for_each_entry_rcu(c, &h->list, list) {
769be974 2305 if (c->type != type || skb_queue_empty(&c->data_q))
1da177e4 2306 continue;
769be974
MH
2307
2308 if (c->state != BT_CONNECTED && c->state != BT_CONFIG)
2309 continue;
2310
1da177e4
LT
2311 num++;
2312
2313 if (c->sent < min) {
2314 min = c->sent;
2315 conn = c;
2316 }
52087a79
LAD
2317
2318 if (hci_conn_num(hdev, type) == num)
2319 break;
1da177e4
LT
2320 }
2321
bf4c6325
GP
2322 rcu_read_unlock();
2323
1da177e4 2324 if (conn) {
6ed58ec5
VT
2325 int cnt, q;
2326
2327 switch (conn->type) {
2328 case ACL_LINK:
2329 cnt = hdev->acl_cnt;
2330 break;
2331 case SCO_LINK:
2332 case ESCO_LINK:
2333 cnt = hdev->sco_cnt;
2334 break;
2335 case LE_LINK:
2336 cnt = hdev->le_mtu ? hdev->le_cnt : hdev->acl_cnt;
2337 break;
2338 default:
2339 cnt = 0;
2340 BT_ERR("Unknown link type");
2341 }
2342
2343 q = cnt / num;
1da177e4
LT
2344 *quote = q ? q : 1;
2345 } else
2346 *quote = 0;
2347
2348 BT_DBG("conn %p quote %d", conn, *quote);
2349 return conn;
2350}
2351
bae1f5d9 2352static inline void hci_link_tx_to(struct hci_dev *hdev, __u8 type)
1da177e4
LT
2353{
2354 struct hci_conn_hash *h = &hdev->conn_hash;
8035ded4 2355 struct hci_conn *c;
1da177e4 2356
bae1f5d9 2357 BT_ERR("%s link tx timeout", hdev->name);
1da177e4 2358
bf4c6325
GP
2359 rcu_read_lock();
2360
1da177e4 2361 /* Kill stalled connections */
bf4c6325 2362 list_for_each_entry_rcu(c, &h->list, list) {
bae1f5d9
VT
2363 if (c->type == type && c->sent) {
2364 BT_ERR("%s killing stalled connection %s",
1da177e4
LT
2365 hdev->name, batostr(&c->dst));
2366 hci_acl_disconn(c, 0x13);
2367 }
2368 }
bf4c6325
GP
2369
2370 rcu_read_unlock();
1da177e4
LT
2371}
2372
73d80deb
LAD
2373static inline struct hci_chan *hci_chan_sent(struct hci_dev *hdev, __u8 type,
2374 int *quote)
1da177e4 2375{
73d80deb
LAD
2376 struct hci_conn_hash *h = &hdev->conn_hash;
2377 struct hci_chan *chan = NULL;
2378 int num = 0, min = ~0, cur_prio = 0;
1da177e4 2379 struct hci_conn *conn;
73d80deb
LAD
2380 int cnt, q, conn_num = 0;
2381
2382 BT_DBG("%s", hdev->name);
2383
bf4c6325
GP
2384 rcu_read_lock();
2385
2386 list_for_each_entry_rcu(conn, &h->list, list) {
73d80deb
LAD
2387 struct hci_chan *tmp;
2388
2389 if (conn->type != type)
2390 continue;
2391
2392 if (conn->state != BT_CONNECTED && conn->state != BT_CONFIG)
2393 continue;
2394
2395 conn_num++;
2396
8192edef 2397 list_for_each_entry_rcu(tmp, &conn->chan_list, list) {
73d80deb
LAD
2398 struct sk_buff *skb;
2399
2400 if (skb_queue_empty(&tmp->data_q))
2401 continue;
2402
2403 skb = skb_peek(&tmp->data_q);
2404 if (skb->priority < cur_prio)
2405 continue;
2406
2407 if (skb->priority > cur_prio) {
2408 num = 0;
2409 min = ~0;
2410 cur_prio = skb->priority;
2411 }
2412
2413 num++;
2414
2415 if (conn->sent < min) {
2416 min = conn->sent;
2417 chan = tmp;
2418 }
2419 }
2420
2421 if (hci_conn_num(hdev, type) == conn_num)
2422 break;
2423 }
2424
bf4c6325
GP
2425 rcu_read_unlock();
2426
73d80deb
LAD
2427 if (!chan)
2428 return NULL;
2429
2430 switch (chan->conn->type) {
2431 case ACL_LINK:
2432 cnt = hdev->acl_cnt;
2433 break;
2434 case SCO_LINK:
2435 case ESCO_LINK:
2436 cnt = hdev->sco_cnt;
2437 break;
2438 case LE_LINK:
2439 cnt = hdev->le_mtu ? hdev->le_cnt : hdev->acl_cnt;
2440 break;
2441 default:
2442 cnt = 0;
2443 BT_ERR("Unknown link type");
2444 }
2445
2446 q = cnt / num;
2447 *quote = q ? q : 1;
2448 BT_DBG("chan %p quote %d", chan, *quote);
2449 return chan;
2450}
2451
02b20f0b
LAD
2452static void hci_prio_recalculate(struct hci_dev *hdev, __u8 type)
2453{
2454 struct hci_conn_hash *h = &hdev->conn_hash;
2455 struct hci_conn *conn;
2456 int num = 0;
2457
2458 BT_DBG("%s", hdev->name);
2459
bf4c6325
GP
2460 rcu_read_lock();
2461
2462 list_for_each_entry_rcu(conn, &h->list, list) {
02b20f0b
LAD
2463 struct hci_chan *chan;
2464
2465 if (conn->type != type)
2466 continue;
2467
2468 if (conn->state != BT_CONNECTED && conn->state != BT_CONFIG)
2469 continue;
2470
2471 num++;
2472
8192edef 2473 list_for_each_entry_rcu(chan, &conn->chan_list, list) {
02b20f0b
LAD
2474 struct sk_buff *skb;
2475
2476 if (chan->sent) {
2477 chan->sent = 0;
2478 continue;
2479 }
2480
2481 if (skb_queue_empty(&chan->data_q))
2482 continue;
2483
2484 skb = skb_peek(&chan->data_q);
2485 if (skb->priority >= HCI_PRIO_MAX - 1)
2486 continue;
2487
2488 skb->priority = HCI_PRIO_MAX - 1;
2489
2490 BT_DBG("chan %p skb %p promoted to %d", chan, skb,
2491 skb->priority);
2492 }
2493
2494 if (hci_conn_num(hdev, type) == num)
2495 break;
2496 }
bf4c6325
GP
2497
2498 rcu_read_unlock();
2499
02b20f0b
LAD
2500}
2501
b71d385a
AE
2502static inline int __get_blocks(struct hci_dev *hdev, struct sk_buff *skb)
2503{
2504 /* Calculate count of blocks used by this packet */
2505 return DIV_ROUND_UP(skb->len - HCI_ACL_HDR_SIZE, hdev->block_len);
2506}
2507
63d2bc1b 2508static inline void __check_timeout(struct hci_dev *hdev, unsigned int cnt)
73d80deb 2509{
1da177e4
LT
2510 if (!test_bit(HCI_RAW, &hdev->flags)) {
2511 /* ACL tx timeout must be longer than maximum
2512 * link supervision timeout (40.9 seconds) */
63d2bc1b 2513 if (!cnt && time_after(jiffies, hdev->acl_last_tx +
cc48dc0a 2514 msecs_to_jiffies(HCI_ACL_TX_TIMEOUT)))
bae1f5d9 2515 hci_link_tx_to(hdev, ACL_LINK);
1da177e4 2516 }
63d2bc1b 2517}
1da177e4 2518
63d2bc1b
AE
2519static inline void hci_sched_acl_pkt(struct hci_dev *hdev)
2520{
2521 unsigned int cnt = hdev->acl_cnt;
2522 struct hci_chan *chan;
2523 struct sk_buff *skb;
2524 int quote;
2525
2526 __check_timeout(hdev, cnt);
04837f64 2527
73d80deb
LAD
2528 while (hdev->acl_cnt &&
2529 (chan = hci_chan_sent(hdev, ACL_LINK, &quote))) {
ec1cce24
LAD
2530 u32 priority = (skb_peek(&chan->data_q))->priority;
2531 while (quote-- && (skb = skb_peek(&chan->data_q))) {
73d80deb
LAD
2532 BT_DBG("chan %p skb %p len %d priority %u", chan, skb,
2533 skb->len, skb->priority);
2534
ec1cce24
LAD
2535 /* Stop if priority has changed */
2536 if (skb->priority < priority)
2537 break;
2538
2539 skb = skb_dequeue(&chan->data_q);
2540
73d80deb
LAD
2541 hci_conn_enter_active_mode(chan->conn,
2542 bt_cb(skb)->force_active);
04837f64 2543
1da177e4
LT
2544 hci_send_frame(skb);
2545 hdev->acl_last_tx = jiffies;
2546
2547 hdev->acl_cnt--;
73d80deb
LAD
2548 chan->sent++;
2549 chan->conn->sent++;
1da177e4
LT
2550 }
2551 }
02b20f0b
LAD
2552
2553 if (cnt != hdev->acl_cnt)
2554 hci_prio_recalculate(hdev, ACL_LINK);
1da177e4
LT
2555}
2556
b71d385a
AE
2557static inline void hci_sched_acl_blk(struct hci_dev *hdev)
2558{
63d2bc1b 2559 unsigned int cnt = hdev->block_cnt;
b71d385a
AE
2560 struct hci_chan *chan;
2561 struct sk_buff *skb;
2562 int quote;
b71d385a 2563
63d2bc1b 2564 __check_timeout(hdev, cnt);
b71d385a
AE
2565
2566 while (hdev->block_cnt > 0 &&
2567 (chan = hci_chan_sent(hdev, ACL_LINK, &quote))) {
2568 u32 priority = (skb_peek(&chan->data_q))->priority;
2569 while (quote > 0 && (skb = skb_peek(&chan->data_q))) {
2570 int blocks;
2571
2572 BT_DBG("chan %p skb %p len %d priority %u", chan, skb,
2573 skb->len, skb->priority);
2574
2575 /* Stop if priority has changed */
2576 if (skb->priority < priority)
2577 break;
2578
2579 skb = skb_dequeue(&chan->data_q);
2580
2581 blocks = __get_blocks(hdev, skb);
2582 if (blocks > hdev->block_cnt)
2583 return;
2584
2585 hci_conn_enter_active_mode(chan->conn,
2586 bt_cb(skb)->force_active);
2587
2588 hci_send_frame(skb);
2589 hdev->acl_last_tx = jiffies;
2590
2591 hdev->block_cnt -= blocks;
2592 quote -= blocks;
2593
2594 chan->sent += blocks;
2595 chan->conn->sent += blocks;
2596 }
2597 }
2598
2599 if (cnt != hdev->block_cnt)
2600 hci_prio_recalculate(hdev, ACL_LINK);
2601}
2602
2603static inline void hci_sched_acl(struct hci_dev *hdev)
2604{
2605 BT_DBG("%s", hdev->name);
2606
2607 if (!hci_conn_num(hdev, ACL_LINK))
2608 return;
2609
2610 switch (hdev->flow_ctl_mode) {
2611 case HCI_FLOW_CTL_MODE_PACKET_BASED:
2612 hci_sched_acl_pkt(hdev);
2613 break;
2614
2615 case HCI_FLOW_CTL_MODE_BLOCK_BASED:
2616 hci_sched_acl_blk(hdev);
2617 break;
2618 }
2619}
2620
1da177e4
LT
2621/* Schedule SCO */
2622static inline void hci_sched_sco(struct hci_dev *hdev)
2623{
2624 struct hci_conn *conn;
2625 struct sk_buff *skb;
2626 int quote;
2627
2628 BT_DBG("%s", hdev->name);
2629
52087a79
LAD
2630 if (!hci_conn_num(hdev, SCO_LINK))
2631 return;
2632
1da177e4
LT
2633 while (hdev->sco_cnt && (conn = hci_low_sent(hdev, SCO_LINK, &quote))) {
2634 while (quote-- && (skb = skb_dequeue(&conn->data_q))) {
2635 BT_DBG("skb %p len %d", skb, skb->len);
2636 hci_send_frame(skb);
2637
2638 conn->sent++;
2639 if (conn->sent == ~0)
2640 conn->sent = 0;
2641 }
2642 }
2643}
2644
b6a0dc82
MH
2645static inline void hci_sched_esco(struct hci_dev *hdev)
2646{
2647 struct hci_conn *conn;
2648 struct sk_buff *skb;
2649 int quote;
2650
2651 BT_DBG("%s", hdev->name);
2652
52087a79
LAD
2653 if (!hci_conn_num(hdev, ESCO_LINK))
2654 return;
2655
b6a0dc82
MH
2656 while (hdev->sco_cnt && (conn = hci_low_sent(hdev, ESCO_LINK, &quote))) {
2657 while (quote-- && (skb = skb_dequeue(&conn->data_q))) {
2658 BT_DBG("skb %p len %d", skb, skb->len);
2659 hci_send_frame(skb);
2660
2661 conn->sent++;
2662 if (conn->sent == ~0)
2663 conn->sent = 0;
2664 }
2665 }
2666}
2667
6ed58ec5
VT
2668static inline void hci_sched_le(struct hci_dev *hdev)
2669{
73d80deb 2670 struct hci_chan *chan;
6ed58ec5 2671 struct sk_buff *skb;
02b20f0b 2672 int quote, cnt, tmp;
6ed58ec5
VT
2673
2674 BT_DBG("%s", hdev->name);
2675
52087a79
LAD
2676 if (!hci_conn_num(hdev, LE_LINK))
2677 return;
2678
6ed58ec5
VT
2679 if (!test_bit(HCI_RAW, &hdev->flags)) {
2680 /* LE tx timeout must be longer than maximum
2681 * link supervision timeout (40.9 seconds) */
bae1f5d9 2682 if (!hdev->le_cnt && hdev->le_pkts &&
6ed58ec5 2683 time_after(jiffies, hdev->le_last_tx + HZ * 45))
bae1f5d9 2684 hci_link_tx_to(hdev, LE_LINK);
6ed58ec5
VT
2685 }
2686
2687 cnt = hdev->le_pkts ? hdev->le_cnt : hdev->acl_cnt;
02b20f0b 2688 tmp = cnt;
73d80deb 2689 while (cnt && (chan = hci_chan_sent(hdev, LE_LINK, &quote))) {
ec1cce24
LAD
2690 u32 priority = (skb_peek(&chan->data_q))->priority;
2691 while (quote-- && (skb = skb_peek(&chan->data_q))) {
73d80deb
LAD
2692 BT_DBG("chan %p skb %p len %d priority %u", chan, skb,
2693 skb->len, skb->priority);
6ed58ec5 2694
ec1cce24
LAD
2695 /* Stop if priority has changed */
2696 if (skb->priority < priority)
2697 break;
2698
2699 skb = skb_dequeue(&chan->data_q);
2700
6ed58ec5
VT
2701 hci_send_frame(skb);
2702 hdev->le_last_tx = jiffies;
2703
2704 cnt--;
73d80deb
LAD
2705 chan->sent++;
2706 chan->conn->sent++;
6ed58ec5
VT
2707 }
2708 }
73d80deb 2709
6ed58ec5
VT
2710 if (hdev->le_pkts)
2711 hdev->le_cnt = cnt;
2712 else
2713 hdev->acl_cnt = cnt;
02b20f0b
LAD
2714
2715 if (cnt != tmp)
2716 hci_prio_recalculate(hdev, LE_LINK);
6ed58ec5
VT
2717}
2718
3eff45ea 2719static void hci_tx_work(struct work_struct *work)
1da177e4 2720{
3eff45ea 2721 struct hci_dev *hdev = container_of(work, struct hci_dev, tx_work);
1da177e4
LT
2722 struct sk_buff *skb;
2723
6ed58ec5
VT
2724 BT_DBG("%s acl %d sco %d le %d", hdev->name, hdev->acl_cnt,
2725 hdev->sco_cnt, hdev->le_cnt);
1da177e4
LT
2726
2727 /* Schedule queues and send stuff to HCI driver */
2728
2729 hci_sched_acl(hdev);
2730
2731 hci_sched_sco(hdev);
2732
b6a0dc82
MH
2733 hci_sched_esco(hdev);
2734
6ed58ec5
VT
2735 hci_sched_le(hdev);
2736
1da177e4
LT
2737 /* Send next queued raw (unknown type) packet */
2738 while ((skb = skb_dequeue(&hdev->raw_q)))
2739 hci_send_frame(skb);
1da177e4
LT
2740}
2741
25985edc 2742/* ----- HCI RX task (incoming data processing) ----- */
1da177e4
LT
2743
2744/* ACL data packet */
2745static inline void hci_acldata_packet(struct hci_dev *hdev, struct sk_buff *skb)
2746{
2747 struct hci_acl_hdr *hdr = (void *) skb->data;
2748 struct hci_conn *conn;
2749 __u16 handle, flags;
2750
2751 skb_pull(skb, HCI_ACL_HDR_SIZE);
2752
2753 handle = __le16_to_cpu(hdr->handle);
2754 flags = hci_flags(handle);
2755 handle = hci_handle(handle);
2756
2757 BT_DBG("%s len %d handle 0x%x flags 0x%x", hdev->name, skb->len, handle, flags);
2758
2759 hdev->stat.acl_rx++;
2760
2761 hci_dev_lock(hdev);
2762 conn = hci_conn_hash_lookup_handle(hdev, handle);
2763 hci_dev_unlock(hdev);
8e87d142 2764
1da177e4 2765 if (conn) {
65983fc7 2766 hci_conn_enter_active_mode(conn, BT_POWER_FORCE_ACTIVE_OFF);
04837f64 2767
1da177e4 2768 /* Send to upper protocol */
686ebf28
UF
2769 l2cap_recv_acldata(conn, skb, flags);
2770 return;
1da177e4 2771 } else {
8e87d142 2772 BT_ERR("%s ACL packet for unknown connection handle %d",
1da177e4
LT
2773 hdev->name, handle);
2774 }
2775
2776 kfree_skb(skb);
2777}
2778
2779/* SCO data packet */
2780static inline void hci_scodata_packet(struct hci_dev *hdev, struct sk_buff *skb)
2781{
2782 struct hci_sco_hdr *hdr = (void *) skb->data;
2783 struct hci_conn *conn;
2784 __u16 handle;
2785
2786 skb_pull(skb, HCI_SCO_HDR_SIZE);
2787
2788 handle = __le16_to_cpu(hdr->handle);
2789
2790 BT_DBG("%s len %d handle 0x%x", hdev->name, skb->len, handle);
2791
2792 hdev->stat.sco_rx++;
2793
2794 hci_dev_lock(hdev);
2795 conn = hci_conn_hash_lookup_handle(hdev, handle);
2796 hci_dev_unlock(hdev);
2797
2798 if (conn) {
1da177e4 2799 /* Send to upper protocol */
686ebf28
UF
2800 sco_recv_scodata(conn, skb);
2801 return;
1da177e4 2802 } else {
8e87d142 2803 BT_ERR("%s SCO packet for unknown connection handle %d",
1da177e4
LT
2804 hdev->name, handle);
2805 }
2806
2807 kfree_skb(skb);
2808}
2809
b78752cc 2810static void hci_rx_work(struct work_struct *work)
1da177e4 2811{
b78752cc 2812 struct hci_dev *hdev = container_of(work, struct hci_dev, rx_work);
1da177e4
LT
2813 struct sk_buff *skb;
2814
2815 BT_DBG("%s", hdev->name);
2816
1da177e4
LT
2817 while ((skb = skb_dequeue(&hdev->rx_q))) {
2818 if (atomic_read(&hdev->promisc)) {
2819 /* Send copy to the sockets */
eec8d2bc 2820 hci_send_to_sock(hdev, skb, NULL);
1da177e4
LT
2821 }
2822
2823 if (test_bit(HCI_RAW, &hdev->flags)) {
2824 kfree_skb(skb);
2825 continue;
2826 }
2827
2828 if (test_bit(HCI_INIT, &hdev->flags)) {
2829 /* Don't process data packets in this states. */
0d48d939 2830 switch (bt_cb(skb)->pkt_type) {
1da177e4
LT
2831 case HCI_ACLDATA_PKT:
2832 case HCI_SCODATA_PKT:
2833 kfree_skb(skb);
2834 continue;
3ff50b79 2835 }
1da177e4
LT
2836 }
2837
2838 /* Process frame */
0d48d939 2839 switch (bt_cb(skb)->pkt_type) {
1da177e4 2840 case HCI_EVENT_PKT:
b78752cc 2841 BT_DBG("%s Event packet", hdev->name);
1da177e4
LT
2842 hci_event_packet(hdev, skb);
2843 break;
2844
2845 case HCI_ACLDATA_PKT:
2846 BT_DBG("%s ACL data packet", hdev->name);
2847 hci_acldata_packet(hdev, skb);
2848 break;
2849
2850 case HCI_SCODATA_PKT:
2851 BT_DBG("%s SCO data packet", hdev->name);
2852 hci_scodata_packet(hdev, skb);
2853 break;
2854
2855 default:
2856 kfree_skb(skb);
2857 break;
2858 }
2859 }
1da177e4
LT
2860}
2861
c347b765 2862static void hci_cmd_work(struct work_struct *work)
1da177e4 2863{
c347b765 2864 struct hci_dev *hdev = container_of(work, struct hci_dev, cmd_work);
1da177e4
LT
2865 struct sk_buff *skb;
2866
2867 BT_DBG("%s cmd %d", hdev->name, atomic_read(&hdev->cmd_cnt));
2868
1da177e4 2869 /* Send queued commands */
5a08ecce
AE
2870 if (atomic_read(&hdev->cmd_cnt)) {
2871 skb = skb_dequeue(&hdev->cmd_q);
2872 if (!skb)
2873 return;
2874
7585b97a 2875 kfree_skb(hdev->sent_cmd);
1da177e4 2876
70f23020
AE
2877 hdev->sent_cmd = skb_clone(skb, GFP_ATOMIC);
2878 if (hdev->sent_cmd) {
1da177e4
LT
2879 atomic_dec(&hdev->cmd_cnt);
2880 hci_send_frame(skb);
7bdb8a5c
SJ
2881 if (test_bit(HCI_RESET, &hdev->flags))
2882 del_timer(&hdev->cmd_timer);
2883 else
2884 mod_timer(&hdev->cmd_timer,
6bd32326 2885 jiffies + msecs_to_jiffies(HCI_CMD_TIMEOUT));
1da177e4
LT
2886 } else {
2887 skb_queue_head(&hdev->cmd_q, skb);
c347b765 2888 queue_work(hdev->workqueue, &hdev->cmd_work);
1da177e4
LT
2889 }
2890 }
2891}
2519a1fc
AG
2892
2893int hci_do_inquiry(struct hci_dev *hdev, u8 length)
2894{
2895 /* General inquiry access code (GIAC) */
2896 u8 lap[3] = { 0x33, 0x8b, 0x9e };
2897 struct hci_cp_inquiry cp;
2898
2899 BT_DBG("%s", hdev->name);
2900
2901 if (test_bit(HCI_INQUIRY, &hdev->flags))
2902 return -EINPROGRESS;
2903
4663262c
JH
2904 inquiry_cache_flush(hdev);
2905
2519a1fc
AG
2906 memset(&cp, 0, sizeof(cp));
2907 memcpy(&cp.lap, lap, sizeof(cp.lap));
2908 cp.length = length;
2909
2910 return hci_send_cmd(hdev, HCI_OP_INQUIRY, sizeof(cp), &cp);
2911}
023d5049
AG
2912
2913int hci_cancel_inquiry(struct hci_dev *hdev)
2914{
2915 BT_DBG("%s", hdev->name);
2916
2917 if (!test_bit(HCI_INQUIRY, &hdev->flags))
2918 return -EPERM;
2919
2920 return hci_send_cmd(hdev, HCI_OP_INQUIRY_CANCEL, 0, NULL);
2921}
7784d78f
AE
2922
2923module_param(enable_hs, bool, 0644);
2924MODULE_PARM_DESC(enable_hs, "Enable High Speed");