Bluetooth: use kfree_skb() instead of kfree()
[GitHub/mt8127/android_kernel_alcatel_ttab.git] / net / bluetooth / hci_core.c
CommitLineData
8e87d142 1/*
1da177e4
LT
2 BlueZ - Bluetooth protocol stack for Linux
3 Copyright (C) 2000-2001 Qualcomm Incorporated
590051de 4 Copyright (C) 2011 ProFUSION Embedded Systems
1da177e4
LT
5
6 Written 2000,2001 by Maxim Krasnyansky <maxk@qualcomm.com>
7
8 This program is free software; you can redistribute it and/or modify
9 it under the terms of the GNU General Public License version 2 as
10 published by the Free Software Foundation;
11
12 THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS
13 OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
14 FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT OF THIRD PARTY RIGHTS.
15 IN NO EVENT SHALL THE COPYRIGHT HOLDER(S) AND AUTHOR(S) BE LIABLE FOR ANY
8e87d142
YH
16 CLAIM, OR ANY SPECIAL INDIRECT OR CONSEQUENTIAL DAMAGES, OR ANY DAMAGES
17 WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
18 ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
1da177e4
LT
19 OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
20
8e87d142
YH
21 ALL LIABILITY, INCLUDING LIABILITY FOR INFRINGEMENT OF ANY PATENTS,
22 COPYRIGHTS, TRADEMARKS OR OTHER RIGHTS, RELATING TO USE OF THIS
1da177e4
LT
23 SOFTWARE IS DISCLAIMED.
24*/
25
26/* Bluetooth HCI core. */
27
82453021 28#include <linux/jiffies.h>
1da177e4
LT
29#include <linux/module.h>
30#include <linux/kmod.h>
31
32#include <linux/types.h>
33#include <linux/errno.h>
34#include <linux/kernel.h>
1da177e4
LT
35#include <linux/sched.h>
36#include <linux/slab.h>
37#include <linux/poll.h>
38#include <linux/fcntl.h>
39#include <linux/init.h>
40#include <linux/skbuff.h>
f48fd9c8 41#include <linux/workqueue.h>
1da177e4 42#include <linux/interrupt.h>
611b30f7 43#include <linux/rfkill.h>
6bd32326 44#include <linux/timer.h>
3a0259bb 45#include <linux/crypto.h>
1da177e4
LT
46#include <net/sock.h>
47
48#include <asm/system.h>
70f23020 49#include <linux/uaccess.h>
1da177e4
LT
50#include <asm/unaligned.h>
51
52#include <net/bluetooth/bluetooth.h>
53#include <net/bluetooth/hci_core.h>
54
ab81cbf9
JH
55#define AUTO_OFF_TIMEOUT 2000
56
b78752cc 57static void hci_rx_work(struct work_struct *work);
c347b765 58static void hci_cmd_work(struct work_struct *work);
3eff45ea 59static void hci_tx_work(struct work_struct *work);
1da177e4 60
1da177e4
LT
61/* HCI device list */
62LIST_HEAD(hci_dev_list);
63DEFINE_RWLOCK(hci_dev_list_lock);
64
65/* HCI callback list */
66LIST_HEAD(hci_cb_list);
67DEFINE_RWLOCK(hci_cb_list_lock);
68
1da177e4
LT
69/* ---- HCI notifications ---- */
70
6516455d 71static void hci_notify(struct hci_dev *hdev, int event)
1da177e4 72{
040030ef 73 hci_sock_dev_event(hdev, event);
1da177e4
LT
74}
75
76/* ---- HCI requests ---- */
77
23bb5763 78void hci_req_complete(struct hci_dev *hdev, __u16 cmd, int result)
1da177e4 79{
23bb5763
JH
80 BT_DBG("%s command 0x%04x result 0x%2.2x", hdev->name, cmd, result);
81
a5040efa
JH
82 /* If this is the init phase check if the completed command matches
83 * the last init command, and if not just return.
84 */
85 if (test_bit(HCI_INIT, &hdev->flags) && hdev->init_last_cmd != cmd)
23bb5763 86 return;
1da177e4
LT
87
88 if (hdev->req_status == HCI_REQ_PEND) {
89 hdev->req_result = result;
90 hdev->req_status = HCI_REQ_DONE;
91 wake_up_interruptible(&hdev->req_wait_q);
92 }
93}
94
95static void hci_req_cancel(struct hci_dev *hdev, int err)
96{
97 BT_DBG("%s err 0x%2.2x", hdev->name, err);
98
99 if (hdev->req_status == HCI_REQ_PEND) {
100 hdev->req_result = err;
101 hdev->req_status = HCI_REQ_CANCELED;
102 wake_up_interruptible(&hdev->req_wait_q);
103 }
104}
105
106/* Execute request and wait for completion. */
8e87d142 107static int __hci_request(struct hci_dev *hdev, void (*req)(struct hci_dev *hdev, unsigned long opt),
01df8c31 108 unsigned long opt, __u32 timeout)
1da177e4
LT
109{
110 DECLARE_WAITQUEUE(wait, current);
111 int err = 0;
112
113 BT_DBG("%s start", hdev->name);
114
115 hdev->req_status = HCI_REQ_PEND;
116
117 add_wait_queue(&hdev->req_wait_q, &wait);
118 set_current_state(TASK_INTERRUPTIBLE);
119
120 req(hdev, opt);
121 schedule_timeout(timeout);
122
123 remove_wait_queue(&hdev->req_wait_q, &wait);
124
125 if (signal_pending(current))
126 return -EINTR;
127
128 switch (hdev->req_status) {
129 case HCI_REQ_DONE:
e175072f 130 err = -bt_to_errno(hdev->req_result);
1da177e4
LT
131 break;
132
133 case HCI_REQ_CANCELED:
134 err = -hdev->req_result;
135 break;
136
137 default:
138 err = -ETIMEDOUT;
139 break;
3ff50b79 140 }
1da177e4 141
a5040efa 142 hdev->req_status = hdev->req_result = 0;
1da177e4
LT
143
144 BT_DBG("%s end: err %d", hdev->name, err);
145
146 return err;
147}
148
149static inline int hci_request(struct hci_dev *hdev, void (*req)(struct hci_dev *hdev, unsigned long opt),
01df8c31 150 unsigned long opt, __u32 timeout)
1da177e4
LT
151{
152 int ret;
153
7c6a329e
MH
154 if (!test_bit(HCI_UP, &hdev->flags))
155 return -ENETDOWN;
156
1da177e4
LT
157 /* Serialize all requests */
158 hci_req_lock(hdev);
159 ret = __hci_request(hdev, req, opt, timeout);
160 hci_req_unlock(hdev);
161
162 return ret;
163}
164
165static void hci_reset_req(struct hci_dev *hdev, unsigned long opt)
166{
167 BT_DBG("%s %ld", hdev->name, opt);
168
169 /* Reset device */
f630cf0d 170 set_bit(HCI_RESET, &hdev->flags);
a9de9248 171 hci_send_cmd(hdev, HCI_OP_RESET, 0, NULL);
1da177e4
LT
172}
173
e61ef499 174static void bredr_init(struct hci_dev *hdev)
1da177e4 175{
b0916ea0 176 struct hci_cp_delete_stored_link_key cp;
1ebb9252 177 __le16 param;
89f2783d 178 __u8 flt_type;
1da177e4 179
2455a3ea
AE
180 hdev->flow_ctl_mode = HCI_FLOW_CTL_MODE_PACKET_BASED;
181
1da177e4
LT
182 /* Mandatory initialization */
183
184 /* Reset */
f630cf0d 185 if (!test_bit(HCI_QUIRK_NO_RESET, &hdev->quirks)) {
e61ef499
AE
186 set_bit(HCI_RESET, &hdev->flags);
187 hci_send_cmd(hdev, HCI_OP_RESET, 0, NULL);
f630cf0d 188 }
1da177e4
LT
189
190 /* Read Local Supported Features */
a9de9248 191 hci_send_cmd(hdev, HCI_OP_READ_LOCAL_FEATURES, 0, NULL);
1da177e4 192
1143e5a6 193 /* Read Local Version */
a9de9248 194 hci_send_cmd(hdev, HCI_OP_READ_LOCAL_VERSION, 0, NULL);
1143e5a6 195
1da177e4 196 /* Read Buffer Size (ACL mtu, max pkt, etc.) */
a9de9248 197 hci_send_cmd(hdev, HCI_OP_READ_BUFFER_SIZE, 0, NULL);
1da177e4 198
1da177e4 199 /* Read BD Address */
a9de9248
MH
200 hci_send_cmd(hdev, HCI_OP_READ_BD_ADDR, 0, NULL);
201
202 /* Read Class of Device */
203 hci_send_cmd(hdev, HCI_OP_READ_CLASS_OF_DEV, 0, NULL);
204
205 /* Read Local Name */
206 hci_send_cmd(hdev, HCI_OP_READ_LOCAL_NAME, 0, NULL);
1da177e4
LT
207
208 /* Read Voice Setting */
a9de9248 209 hci_send_cmd(hdev, HCI_OP_READ_VOICE_SETTING, 0, NULL);
1da177e4
LT
210
211 /* Optional initialization */
212
213 /* Clear Event Filters */
89f2783d 214 flt_type = HCI_FLT_CLEAR_ALL;
a9de9248 215 hci_send_cmd(hdev, HCI_OP_SET_EVENT_FLT, 1, &flt_type);
1da177e4 216
1da177e4 217 /* Connection accept timeout ~20 secs */
aca3192c 218 param = cpu_to_le16(0x7d00);
a9de9248 219 hci_send_cmd(hdev, HCI_OP_WRITE_CA_TIMEOUT, 2, &param);
b0916ea0
JH
220
221 bacpy(&cp.bdaddr, BDADDR_ANY);
222 cp.delete_all = 1;
223 hci_send_cmd(hdev, HCI_OP_DELETE_STORED_LINK_KEY, sizeof(cp), &cp);
1da177e4
LT
224}
225
e61ef499
AE
226static void amp_init(struct hci_dev *hdev)
227{
2455a3ea
AE
228 hdev->flow_ctl_mode = HCI_FLOW_CTL_MODE_BLOCK_BASED;
229
e61ef499
AE
230 /* Reset */
231 hci_send_cmd(hdev, HCI_OP_RESET, 0, NULL);
232
233 /* Read Local Version */
234 hci_send_cmd(hdev, HCI_OP_READ_LOCAL_VERSION, 0, NULL);
235}
236
237static void hci_init_req(struct hci_dev *hdev, unsigned long opt)
238{
239 struct sk_buff *skb;
240
241 BT_DBG("%s %ld", hdev->name, opt);
242
243 /* Driver initialization */
244
245 /* Special commands */
246 while ((skb = skb_dequeue(&hdev->driver_init))) {
247 bt_cb(skb)->pkt_type = HCI_COMMAND_PKT;
248 skb->dev = (void *) hdev;
249
250 skb_queue_tail(&hdev->cmd_q, skb);
251 queue_work(hdev->workqueue, &hdev->cmd_work);
252 }
253 skb_queue_purge(&hdev->driver_init);
254
255 switch (hdev->dev_type) {
256 case HCI_BREDR:
257 bredr_init(hdev);
258 break;
259
260 case HCI_AMP:
261 amp_init(hdev);
262 break;
263
264 default:
265 BT_ERR("Unknown device type %d", hdev->dev_type);
266 break;
267 }
268
269}
270
6ed58ec5
VT
271static void hci_le_init_req(struct hci_dev *hdev, unsigned long opt)
272{
273 BT_DBG("%s", hdev->name);
274
275 /* Read LE buffer size */
276 hci_send_cmd(hdev, HCI_OP_LE_READ_BUFFER_SIZE, 0, NULL);
277}
278
1da177e4
LT
279static void hci_scan_req(struct hci_dev *hdev, unsigned long opt)
280{
281 __u8 scan = opt;
282
283 BT_DBG("%s %x", hdev->name, scan);
284
285 /* Inquiry and Page scans */
a9de9248 286 hci_send_cmd(hdev, HCI_OP_WRITE_SCAN_ENABLE, 1, &scan);
1da177e4
LT
287}
288
289static void hci_auth_req(struct hci_dev *hdev, unsigned long opt)
290{
291 __u8 auth = opt;
292
293 BT_DBG("%s %x", hdev->name, auth);
294
295 /* Authentication */
a9de9248 296 hci_send_cmd(hdev, HCI_OP_WRITE_AUTH_ENABLE, 1, &auth);
1da177e4
LT
297}
298
299static void hci_encrypt_req(struct hci_dev *hdev, unsigned long opt)
300{
301 __u8 encrypt = opt;
302
303 BT_DBG("%s %x", hdev->name, encrypt);
304
e4e8e37c 305 /* Encryption */
a9de9248 306 hci_send_cmd(hdev, HCI_OP_WRITE_ENCRYPT_MODE, 1, &encrypt);
1da177e4
LT
307}
308
e4e8e37c
MH
309static void hci_linkpol_req(struct hci_dev *hdev, unsigned long opt)
310{
311 __le16 policy = cpu_to_le16(opt);
312
a418b893 313 BT_DBG("%s %x", hdev->name, policy);
e4e8e37c
MH
314
315 /* Default link policy */
316 hci_send_cmd(hdev, HCI_OP_WRITE_DEF_LINK_POLICY, 2, &policy);
317}
318
8e87d142 319/* Get HCI device by index.
1da177e4
LT
320 * Device is held on return. */
321struct hci_dev *hci_dev_get(int index)
322{
8035ded4 323 struct hci_dev *hdev = NULL, *d;
1da177e4
LT
324
325 BT_DBG("%d", index);
326
327 if (index < 0)
328 return NULL;
329
330 read_lock(&hci_dev_list_lock);
8035ded4 331 list_for_each_entry(d, &hci_dev_list, list) {
1da177e4
LT
332 if (d->id == index) {
333 hdev = hci_dev_hold(d);
334 break;
335 }
336 }
337 read_unlock(&hci_dev_list_lock);
338 return hdev;
339}
1da177e4
LT
340
341/* ---- Inquiry support ---- */
ff9ef578 342
30dc78e1
JH
343bool hci_discovery_active(struct hci_dev *hdev)
344{
345 struct discovery_state *discov = &hdev->discovery;
346
6fbe195d 347 switch (discov->state) {
343f935b 348 case DISCOVERY_FINDING:
6fbe195d 349 case DISCOVERY_RESOLVING:
30dc78e1
JH
350 return true;
351
6fbe195d
AG
352 default:
353 return false;
354 }
30dc78e1
JH
355}
356
ff9ef578
JH
357void hci_discovery_set_state(struct hci_dev *hdev, int state)
358{
359 BT_DBG("%s state %u -> %u", hdev->name, hdev->discovery.state, state);
360
361 if (hdev->discovery.state == state)
362 return;
363
364 switch (state) {
365 case DISCOVERY_STOPPED:
7b99b659
AG
366 if (hdev->discovery.state != DISCOVERY_STARTING)
367 mgmt_discovering(hdev, 0);
f963e8e9 368 hdev->discovery.type = 0;
ff9ef578
JH
369 break;
370 case DISCOVERY_STARTING:
371 break;
343f935b 372 case DISCOVERY_FINDING:
ff9ef578
JH
373 mgmt_discovering(hdev, 1);
374 break;
30dc78e1
JH
375 case DISCOVERY_RESOLVING:
376 break;
ff9ef578
JH
377 case DISCOVERY_STOPPING:
378 break;
379 }
380
381 hdev->discovery.state = state;
382}
383
1da177e4
LT
384static void inquiry_cache_flush(struct hci_dev *hdev)
385{
30883512 386 struct discovery_state *cache = &hdev->discovery;
b57c1a56 387 struct inquiry_entry *p, *n;
1da177e4 388
561aafbc
JH
389 list_for_each_entry_safe(p, n, &cache->all, all) {
390 list_del(&p->all);
b57c1a56 391 kfree(p);
1da177e4 392 }
561aafbc
JH
393
394 INIT_LIST_HEAD(&cache->unknown);
395 INIT_LIST_HEAD(&cache->resolve);
ff9ef578 396 cache->state = DISCOVERY_STOPPED;
1da177e4
LT
397}
398
399struct inquiry_entry *hci_inquiry_cache_lookup(struct hci_dev *hdev, bdaddr_t *bdaddr)
400{
30883512 401 struct discovery_state *cache = &hdev->discovery;
1da177e4
LT
402 struct inquiry_entry *e;
403
404 BT_DBG("cache %p, %s", cache, batostr(bdaddr));
405
561aafbc
JH
406 list_for_each_entry(e, &cache->all, all) {
407 if (!bacmp(&e->data.bdaddr, bdaddr))
408 return e;
409 }
410
411 return NULL;
412}
413
414struct inquiry_entry *hci_inquiry_cache_lookup_unknown(struct hci_dev *hdev,
415 bdaddr_t *bdaddr)
416{
30883512 417 struct discovery_state *cache = &hdev->discovery;
561aafbc
JH
418 struct inquiry_entry *e;
419
420 BT_DBG("cache %p, %s", cache, batostr(bdaddr));
421
422 list_for_each_entry(e, &cache->unknown, list) {
1da177e4 423 if (!bacmp(&e->data.bdaddr, bdaddr))
b57c1a56
JH
424 return e;
425 }
426
427 return NULL;
1da177e4
LT
428}
429
30dc78e1
JH
430struct inquiry_entry *hci_inquiry_cache_lookup_resolve(struct hci_dev *hdev,
431 bdaddr_t *bdaddr,
432 int state)
433{
434 struct discovery_state *cache = &hdev->discovery;
435 struct inquiry_entry *e;
436
437 BT_DBG("cache %p bdaddr %s state %d", cache, batostr(bdaddr), state);
438
439 list_for_each_entry(e, &cache->resolve, list) {
440 if (!bacmp(bdaddr, BDADDR_ANY) && e->name_state == state)
441 return e;
442 if (!bacmp(&e->data.bdaddr, bdaddr))
443 return e;
444 }
445
446 return NULL;
447}
448
a3d4e20a
JH
449void hci_inquiry_cache_update_resolve(struct hci_dev *hdev,
450 struct inquiry_entry *ie)
451{
452 struct discovery_state *cache = &hdev->discovery;
453 struct list_head *pos = &cache->resolve;
454 struct inquiry_entry *p;
455
456 list_del(&ie->list);
457
458 list_for_each_entry(p, &cache->resolve, list) {
459 if (p->name_state != NAME_PENDING &&
460 abs(p->data.rssi) >= abs(ie->data.rssi))
461 break;
462 pos = &p->list;
463 }
464
465 list_add(&ie->list, pos);
466}
467
3175405b 468bool hci_inquiry_cache_update(struct hci_dev *hdev, struct inquiry_data *data,
388fc8fa 469 bool name_known, bool *ssp)
1da177e4 470{
30883512 471 struct discovery_state *cache = &hdev->discovery;
70f23020 472 struct inquiry_entry *ie;
1da177e4
LT
473
474 BT_DBG("cache %p, %s", cache, batostr(&data->bdaddr));
475
388fc8fa
JH
476 if (ssp)
477 *ssp = data->ssp_mode;
478
70f23020 479 ie = hci_inquiry_cache_lookup(hdev, &data->bdaddr);
a3d4e20a 480 if (ie) {
388fc8fa
JH
481 if (ie->data.ssp_mode && ssp)
482 *ssp = true;
483
a3d4e20a
JH
484 if (ie->name_state == NAME_NEEDED &&
485 data->rssi != ie->data.rssi) {
486 ie->data.rssi = data->rssi;
487 hci_inquiry_cache_update_resolve(hdev, ie);
488 }
489
561aafbc 490 goto update;
a3d4e20a 491 }
561aafbc
JH
492
493 /* Entry not in the cache. Add new one. */
494 ie = kzalloc(sizeof(struct inquiry_entry), GFP_ATOMIC);
495 if (!ie)
3175405b 496 return false;
561aafbc
JH
497
498 list_add(&ie->all, &cache->all);
499
500 if (name_known) {
501 ie->name_state = NAME_KNOWN;
502 } else {
503 ie->name_state = NAME_NOT_KNOWN;
504 list_add(&ie->list, &cache->unknown);
505 }
70f23020 506
561aafbc
JH
507update:
508 if (name_known && ie->name_state != NAME_KNOWN &&
509 ie->name_state != NAME_PENDING) {
510 ie->name_state = NAME_KNOWN;
511 list_del(&ie->list);
1da177e4
LT
512 }
513
70f23020
AE
514 memcpy(&ie->data, data, sizeof(*data));
515 ie->timestamp = jiffies;
1da177e4 516 cache->timestamp = jiffies;
3175405b
JH
517
518 if (ie->name_state == NAME_NOT_KNOWN)
519 return false;
520
521 return true;
1da177e4
LT
522}
523
524static int inquiry_cache_dump(struct hci_dev *hdev, int num, __u8 *buf)
525{
30883512 526 struct discovery_state *cache = &hdev->discovery;
1da177e4
LT
527 struct inquiry_info *info = (struct inquiry_info *) buf;
528 struct inquiry_entry *e;
529 int copied = 0;
530
561aafbc 531 list_for_each_entry(e, &cache->all, all) {
1da177e4 532 struct inquiry_data *data = &e->data;
b57c1a56
JH
533
534 if (copied >= num)
535 break;
536
1da177e4
LT
537 bacpy(&info->bdaddr, &data->bdaddr);
538 info->pscan_rep_mode = data->pscan_rep_mode;
539 info->pscan_period_mode = data->pscan_period_mode;
540 info->pscan_mode = data->pscan_mode;
541 memcpy(info->dev_class, data->dev_class, 3);
542 info->clock_offset = data->clock_offset;
b57c1a56 543
1da177e4 544 info++;
b57c1a56 545 copied++;
1da177e4
LT
546 }
547
548 BT_DBG("cache %p, copied %d", cache, copied);
549 return copied;
550}
551
552static void hci_inq_req(struct hci_dev *hdev, unsigned long opt)
553{
554 struct hci_inquiry_req *ir = (struct hci_inquiry_req *) opt;
555 struct hci_cp_inquiry cp;
556
557 BT_DBG("%s", hdev->name);
558
559 if (test_bit(HCI_INQUIRY, &hdev->flags))
560 return;
561
562 /* Start Inquiry */
563 memcpy(&cp.lap, &ir->lap, 3);
564 cp.length = ir->length;
565 cp.num_rsp = ir->num_rsp;
a9de9248 566 hci_send_cmd(hdev, HCI_OP_INQUIRY, sizeof(cp), &cp);
1da177e4
LT
567}
568
569int hci_inquiry(void __user *arg)
570{
571 __u8 __user *ptr = arg;
572 struct hci_inquiry_req ir;
573 struct hci_dev *hdev;
574 int err = 0, do_inquiry = 0, max_rsp;
575 long timeo;
576 __u8 *buf;
577
578 if (copy_from_user(&ir, ptr, sizeof(ir)))
579 return -EFAULT;
580
5a08ecce
AE
581 hdev = hci_dev_get(ir.dev_id);
582 if (!hdev)
1da177e4
LT
583 return -ENODEV;
584
09fd0de5 585 hci_dev_lock(hdev);
8e87d142 586 if (inquiry_cache_age(hdev) > INQUIRY_CACHE_AGE_MAX ||
70f23020
AE
587 inquiry_cache_empty(hdev) ||
588 ir.flags & IREQ_CACHE_FLUSH) {
1da177e4
LT
589 inquiry_cache_flush(hdev);
590 do_inquiry = 1;
591 }
09fd0de5 592 hci_dev_unlock(hdev);
1da177e4 593
04837f64 594 timeo = ir.length * msecs_to_jiffies(2000);
70f23020
AE
595
596 if (do_inquiry) {
597 err = hci_request(hdev, hci_inq_req, (unsigned long)&ir, timeo);
598 if (err < 0)
599 goto done;
600 }
1da177e4
LT
601
602 /* for unlimited number of responses we will use buffer with 255 entries */
603 max_rsp = (ir.num_rsp == 0) ? 255 : ir.num_rsp;
604
605 /* cache_dump can't sleep. Therefore we allocate temp buffer and then
606 * copy it to the user space.
607 */
01df8c31 608 buf = kmalloc(sizeof(struct inquiry_info) * max_rsp, GFP_KERNEL);
70f23020 609 if (!buf) {
1da177e4
LT
610 err = -ENOMEM;
611 goto done;
612 }
613
09fd0de5 614 hci_dev_lock(hdev);
1da177e4 615 ir.num_rsp = inquiry_cache_dump(hdev, max_rsp, buf);
09fd0de5 616 hci_dev_unlock(hdev);
1da177e4
LT
617
618 BT_DBG("num_rsp %d", ir.num_rsp);
619
620 if (!copy_to_user(ptr, &ir, sizeof(ir))) {
621 ptr += sizeof(ir);
622 if (copy_to_user(ptr, buf, sizeof(struct inquiry_info) *
623 ir.num_rsp))
624 err = -EFAULT;
8e87d142 625 } else
1da177e4
LT
626 err = -EFAULT;
627
628 kfree(buf);
629
630done:
631 hci_dev_put(hdev);
632 return err;
633}
634
635/* ---- HCI ioctl helpers ---- */
636
637int hci_dev_open(__u16 dev)
638{
639 struct hci_dev *hdev;
640 int ret = 0;
641
5a08ecce
AE
642 hdev = hci_dev_get(dev);
643 if (!hdev)
1da177e4
LT
644 return -ENODEV;
645
646 BT_DBG("%s %p", hdev->name, hdev);
647
648 hci_req_lock(hdev);
649
611b30f7
MH
650 if (hdev->rfkill && rfkill_blocked(hdev->rfkill)) {
651 ret = -ERFKILL;
652 goto done;
653 }
654
1da177e4
LT
655 if (test_bit(HCI_UP, &hdev->flags)) {
656 ret = -EALREADY;
657 goto done;
658 }
659
660 if (test_bit(HCI_QUIRK_RAW_DEVICE, &hdev->quirks))
661 set_bit(HCI_RAW, &hdev->flags);
662
07e3b94a
AE
663 /* Treat all non BR/EDR controllers as raw devices if
664 enable_hs is not set */
665 if (hdev->dev_type != HCI_BREDR && !enable_hs)
943da25d
MH
666 set_bit(HCI_RAW, &hdev->flags);
667
1da177e4
LT
668 if (hdev->open(hdev)) {
669 ret = -EIO;
670 goto done;
671 }
672
673 if (!test_bit(HCI_RAW, &hdev->flags)) {
674 atomic_set(&hdev->cmd_cnt, 1);
675 set_bit(HCI_INIT, &hdev->flags);
a5040efa 676 hdev->init_last_cmd = 0;
1da177e4 677
04837f64
MH
678 ret = __hci_request(hdev, hci_init_req, 0,
679 msecs_to_jiffies(HCI_INIT_TIMEOUT));
1da177e4 680
eead27da 681 if (lmp_host_le_capable(hdev))
6ed58ec5
VT
682 ret = __hci_request(hdev, hci_le_init_req, 0,
683 msecs_to_jiffies(HCI_INIT_TIMEOUT));
684
1da177e4
LT
685 clear_bit(HCI_INIT, &hdev->flags);
686 }
687
688 if (!ret) {
689 hci_dev_hold(hdev);
690 set_bit(HCI_UP, &hdev->flags);
691 hci_notify(hdev, HCI_DEV_UP);
a8b2d5c2 692 if (!test_bit(HCI_SETUP, &hdev->dev_flags)) {
09fd0de5 693 hci_dev_lock(hdev);
744cf19e 694 mgmt_powered(hdev, 1);
09fd0de5 695 hci_dev_unlock(hdev);
56e5cb86 696 }
8e87d142 697 } else {
1da177e4 698 /* Init failed, cleanup */
3eff45ea 699 flush_work(&hdev->tx_work);
c347b765 700 flush_work(&hdev->cmd_work);
b78752cc 701 flush_work(&hdev->rx_work);
1da177e4
LT
702
703 skb_queue_purge(&hdev->cmd_q);
704 skb_queue_purge(&hdev->rx_q);
705
706 if (hdev->flush)
707 hdev->flush(hdev);
708
709 if (hdev->sent_cmd) {
710 kfree_skb(hdev->sent_cmd);
711 hdev->sent_cmd = NULL;
712 }
713
714 hdev->close(hdev);
715 hdev->flags = 0;
716 }
717
718done:
719 hci_req_unlock(hdev);
720 hci_dev_put(hdev);
721 return ret;
722}
723
724static int hci_dev_do_close(struct hci_dev *hdev)
725{
726 BT_DBG("%s %p", hdev->name, hdev);
727
28b75a89
AG
728 cancel_work_sync(&hdev->le_scan);
729
1da177e4
LT
730 hci_req_cancel(hdev, ENODEV);
731 hci_req_lock(hdev);
732
733 if (!test_and_clear_bit(HCI_UP, &hdev->flags)) {
b79f44c1 734 del_timer_sync(&hdev->cmd_timer);
1da177e4
LT
735 hci_req_unlock(hdev);
736 return 0;
737 }
738
3eff45ea
GP
739 /* Flush RX and TX works */
740 flush_work(&hdev->tx_work);
b78752cc 741 flush_work(&hdev->rx_work);
1da177e4 742
16ab91ab 743 if (hdev->discov_timeout > 0) {
e0f9309f 744 cancel_delayed_work(&hdev->discov_off);
16ab91ab 745 hdev->discov_timeout = 0;
5e5282bb 746 clear_bit(HCI_DISCOVERABLE, &hdev->dev_flags);
16ab91ab
JH
747 }
748
a8b2d5c2 749 if (test_and_clear_bit(HCI_SERVICE_CACHE, &hdev->dev_flags))
7d78525d
JH
750 cancel_delayed_work(&hdev->service_cache);
751
7ba8b4be
AG
752 cancel_delayed_work_sync(&hdev->le_scan_disable);
753
09fd0de5 754 hci_dev_lock(hdev);
1da177e4
LT
755 inquiry_cache_flush(hdev);
756 hci_conn_hash_flush(hdev);
09fd0de5 757 hci_dev_unlock(hdev);
1da177e4
LT
758
759 hci_notify(hdev, HCI_DEV_DOWN);
760
761 if (hdev->flush)
762 hdev->flush(hdev);
763
764 /* Reset device */
765 skb_queue_purge(&hdev->cmd_q);
766 atomic_set(&hdev->cmd_cnt, 1);
8af59467
JH
767 if (!test_bit(HCI_RAW, &hdev->flags) &&
768 test_bit(HCI_QUIRK_NO_RESET, &hdev->quirks)) {
1da177e4 769 set_bit(HCI_INIT, &hdev->flags);
04837f64 770 __hci_request(hdev, hci_reset_req, 0,
cad44c2b 771 msecs_to_jiffies(250));
1da177e4
LT
772 clear_bit(HCI_INIT, &hdev->flags);
773 }
774
c347b765
GP
775 /* flush cmd work */
776 flush_work(&hdev->cmd_work);
1da177e4
LT
777
778 /* Drop queues */
779 skb_queue_purge(&hdev->rx_q);
780 skb_queue_purge(&hdev->cmd_q);
781 skb_queue_purge(&hdev->raw_q);
782
783 /* Drop last sent command */
784 if (hdev->sent_cmd) {
b79f44c1 785 del_timer_sync(&hdev->cmd_timer);
1da177e4
LT
786 kfree_skb(hdev->sent_cmd);
787 hdev->sent_cmd = NULL;
788 }
789
790 /* After this point our queues are empty
791 * and no tasks are scheduled. */
792 hdev->close(hdev);
793
8ee56540
MH
794 if (!test_and_clear_bit(HCI_AUTO_OFF, &hdev->dev_flags)) {
795 hci_dev_lock(hdev);
796 mgmt_powered(hdev, 0);
797 hci_dev_unlock(hdev);
798 }
5add6af8 799
1da177e4
LT
800 /* Clear flags */
801 hdev->flags = 0;
802
e59fda8d 803 memset(hdev->eir, 0, sizeof(hdev->eir));
09b3c3fb 804 memset(hdev->dev_class, 0, sizeof(hdev->dev_class));
e59fda8d 805
1da177e4
LT
806 hci_req_unlock(hdev);
807
808 hci_dev_put(hdev);
809 return 0;
810}
811
812int hci_dev_close(__u16 dev)
813{
814 struct hci_dev *hdev;
815 int err;
816
70f23020
AE
817 hdev = hci_dev_get(dev);
818 if (!hdev)
1da177e4 819 return -ENODEV;
8ee56540
MH
820
821 if (test_and_clear_bit(HCI_AUTO_OFF, &hdev->dev_flags))
822 cancel_delayed_work(&hdev->power_off);
823
1da177e4 824 err = hci_dev_do_close(hdev);
8ee56540 825
1da177e4
LT
826 hci_dev_put(hdev);
827 return err;
828}
829
830int hci_dev_reset(__u16 dev)
831{
832 struct hci_dev *hdev;
833 int ret = 0;
834
70f23020
AE
835 hdev = hci_dev_get(dev);
836 if (!hdev)
1da177e4
LT
837 return -ENODEV;
838
839 hci_req_lock(hdev);
1da177e4
LT
840
841 if (!test_bit(HCI_UP, &hdev->flags))
842 goto done;
843
844 /* Drop queues */
845 skb_queue_purge(&hdev->rx_q);
846 skb_queue_purge(&hdev->cmd_q);
847
09fd0de5 848 hci_dev_lock(hdev);
1da177e4
LT
849 inquiry_cache_flush(hdev);
850 hci_conn_hash_flush(hdev);
09fd0de5 851 hci_dev_unlock(hdev);
1da177e4
LT
852
853 if (hdev->flush)
854 hdev->flush(hdev);
855
8e87d142 856 atomic_set(&hdev->cmd_cnt, 1);
6ed58ec5 857 hdev->acl_cnt = 0; hdev->sco_cnt = 0; hdev->le_cnt = 0;
1da177e4
LT
858
859 if (!test_bit(HCI_RAW, &hdev->flags))
04837f64
MH
860 ret = __hci_request(hdev, hci_reset_req, 0,
861 msecs_to_jiffies(HCI_INIT_TIMEOUT));
1da177e4
LT
862
863done:
1da177e4
LT
864 hci_req_unlock(hdev);
865 hci_dev_put(hdev);
866 return ret;
867}
868
869int hci_dev_reset_stat(__u16 dev)
870{
871 struct hci_dev *hdev;
872 int ret = 0;
873
70f23020
AE
874 hdev = hci_dev_get(dev);
875 if (!hdev)
1da177e4
LT
876 return -ENODEV;
877
878 memset(&hdev->stat, 0, sizeof(struct hci_dev_stats));
879
880 hci_dev_put(hdev);
881
882 return ret;
883}
884
885int hci_dev_cmd(unsigned int cmd, void __user *arg)
886{
887 struct hci_dev *hdev;
888 struct hci_dev_req dr;
889 int err = 0;
890
891 if (copy_from_user(&dr, arg, sizeof(dr)))
892 return -EFAULT;
893
70f23020
AE
894 hdev = hci_dev_get(dr.dev_id);
895 if (!hdev)
1da177e4
LT
896 return -ENODEV;
897
898 switch (cmd) {
899 case HCISETAUTH:
04837f64
MH
900 err = hci_request(hdev, hci_auth_req, dr.dev_opt,
901 msecs_to_jiffies(HCI_INIT_TIMEOUT));
1da177e4
LT
902 break;
903
904 case HCISETENCRYPT:
905 if (!lmp_encrypt_capable(hdev)) {
906 err = -EOPNOTSUPP;
907 break;
908 }
909
910 if (!test_bit(HCI_AUTH, &hdev->flags)) {
911 /* Auth must be enabled first */
04837f64
MH
912 err = hci_request(hdev, hci_auth_req, dr.dev_opt,
913 msecs_to_jiffies(HCI_INIT_TIMEOUT));
1da177e4
LT
914 if (err)
915 break;
916 }
917
04837f64
MH
918 err = hci_request(hdev, hci_encrypt_req, dr.dev_opt,
919 msecs_to_jiffies(HCI_INIT_TIMEOUT));
1da177e4
LT
920 break;
921
922 case HCISETSCAN:
04837f64
MH
923 err = hci_request(hdev, hci_scan_req, dr.dev_opt,
924 msecs_to_jiffies(HCI_INIT_TIMEOUT));
1da177e4
LT
925 break;
926
1da177e4 927 case HCISETLINKPOL:
e4e8e37c
MH
928 err = hci_request(hdev, hci_linkpol_req, dr.dev_opt,
929 msecs_to_jiffies(HCI_INIT_TIMEOUT));
1da177e4
LT
930 break;
931
932 case HCISETLINKMODE:
e4e8e37c
MH
933 hdev->link_mode = ((__u16) dr.dev_opt) &
934 (HCI_LM_MASTER | HCI_LM_ACCEPT);
935 break;
936
937 case HCISETPTYPE:
938 hdev->pkt_type = (__u16) dr.dev_opt;
1da177e4
LT
939 break;
940
941 case HCISETACLMTU:
e4e8e37c
MH
942 hdev->acl_mtu = *((__u16 *) &dr.dev_opt + 1);
943 hdev->acl_pkts = *((__u16 *) &dr.dev_opt + 0);
1da177e4
LT
944 break;
945
946 case HCISETSCOMTU:
e4e8e37c
MH
947 hdev->sco_mtu = *((__u16 *) &dr.dev_opt + 1);
948 hdev->sco_pkts = *((__u16 *) &dr.dev_opt + 0);
1da177e4
LT
949 break;
950
951 default:
952 err = -EINVAL;
953 break;
954 }
e4e8e37c 955
1da177e4
LT
956 hci_dev_put(hdev);
957 return err;
958}
959
960int hci_get_dev_list(void __user *arg)
961{
8035ded4 962 struct hci_dev *hdev;
1da177e4
LT
963 struct hci_dev_list_req *dl;
964 struct hci_dev_req *dr;
1da177e4
LT
965 int n = 0, size, err;
966 __u16 dev_num;
967
968 if (get_user(dev_num, (__u16 __user *) arg))
969 return -EFAULT;
970
971 if (!dev_num || dev_num > (PAGE_SIZE * 2) / sizeof(*dr))
972 return -EINVAL;
973
974 size = sizeof(*dl) + dev_num * sizeof(*dr);
975
70f23020
AE
976 dl = kzalloc(size, GFP_KERNEL);
977 if (!dl)
1da177e4
LT
978 return -ENOMEM;
979
980 dr = dl->dev_req;
981
f20d09d5 982 read_lock(&hci_dev_list_lock);
8035ded4 983 list_for_each_entry(hdev, &hci_dev_list, list) {
a8b2d5c2 984 if (test_and_clear_bit(HCI_AUTO_OFF, &hdev->dev_flags))
e0f9309f 985 cancel_delayed_work(&hdev->power_off);
c542a06c 986
a8b2d5c2
JH
987 if (!test_bit(HCI_MGMT, &hdev->dev_flags))
988 set_bit(HCI_PAIRABLE, &hdev->dev_flags);
c542a06c 989
1da177e4
LT
990 (dr + n)->dev_id = hdev->id;
991 (dr + n)->dev_opt = hdev->flags;
c542a06c 992
1da177e4
LT
993 if (++n >= dev_num)
994 break;
995 }
f20d09d5 996 read_unlock(&hci_dev_list_lock);
1da177e4
LT
997
998 dl->dev_num = n;
999 size = sizeof(*dl) + n * sizeof(*dr);
1000
1001 err = copy_to_user(arg, dl, size);
1002 kfree(dl);
1003
1004 return err ? -EFAULT : 0;
1005}
1006
1007int hci_get_dev_info(void __user *arg)
1008{
1009 struct hci_dev *hdev;
1010 struct hci_dev_info di;
1011 int err = 0;
1012
1013 if (copy_from_user(&di, arg, sizeof(di)))
1014 return -EFAULT;
1015
70f23020
AE
1016 hdev = hci_dev_get(di.dev_id);
1017 if (!hdev)
1da177e4
LT
1018 return -ENODEV;
1019
a8b2d5c2 1020 if (test_and_clear_bit(HCI_AUTO_OFF, &hdev->dev_flags))
3243553f 1021 cancel_delayed_work_sync(&hdev->power_off);
ab81cbf9 1022
a8b2d5c2
JH
1023 if (!test_bit(HCI_MGMT, &hdev->dev_flags))
1024 set_bit(HCI_PAIRABLE, &hdev->dev_flags);
c542a06c 1025
1da177e4
LT
1026 strcpy(di.name, hdev->name);
1027 di.bdaddr = hdev->bdaddr;
943da25d 1028 di.type = (hdev->bus & 0x0f) | (hdev->dev_type << 4);
1da177e4
LT
1029 di.flags = hdev->flags;
1030 di.pkt_type = hdev->pkt_type;
1031 di.acl_mtu = hdev->acl_mtu;
1032 di.acl_pkts = hdev->acl_pkts;
1033 di.sco_mtu = hdev->sco_mtu;
1034 di.sco_pkts = hdev->sco_pkts;
1035 di.link_policy = hdev->link_policy;
1036 di.link_mode = hdev->link_mode;
1037
1038 memcpy(&di.stat, &hdev->stat, sizeof(di.stat));
1039 memcpy(&di.features, &hdev->features, sizeof(di.features));
1040
1041 if (copy_to_user(arg, &di, sizeof(di)))
1042 err = -EFAULT;
1043
1044 hci_dev_put(hdev);
1045
1046 return err;
1047}
1048
1049/* ---- Interface to HCI drivers ---- */
1050
611b30f7
MH
1051static int hci_rfkill_set_block(void *data, bool blocked)
1052{
1053 struct hci_dev *hdev = data;
1054
1055 BT_DBG("%p name %s blocked %d", hdev, hdev->name, blocked);
1056
1057 if (!blocked)
1058 return 0;
1059
1060 hci_dev_do_close(hdev);
1061
1062 return 0;
1063}
1064
1065static const struct rfkill_ops hci_rfkill_ops = {
1066 .set_block = hci_rfkill_set_block,
1067};
1068
1da177e4
LT
1069/* Alloc HCI device */
1070struct hci_dev *hci_alloc_dev(void)
1071{
1072 struct hci_dev *hdev;
1073
25ea6db0 1074 hdev = kzalloc(sizeof(struct hci_dev), GFP_KERNEL);
1da177e4
LT
1075 if (!hdev)
1076 return NULL;
1077
0ac7e700 1078 hci_init_sysfs(hdev);
1da177e4
LT
1079 skb_queue_head_init(&hdev->driver_init);
1080
1081 return hdev;
1082}
1083EXPORT_SYMBOL(hci_alloc_dev);
1084
1085/* Free HCI device */
1086void hci_free_dev(struct hci_dev *hdev)
1087{
1088 skb_queue_purge(&hdev->driver_init);
1089
a91f2e39
MH
1090 /* will free via device release */
1091 put_device(&hdev->dev);
1da177e4
LT
1092}
1093EXPORT_SYMBOL(hci_free_dev);
1094
ab81cbf9
JH
1095static void hci_power_on(struct work_struct *work)
1096{
1097 struct hci_dev *hdev = container_of(work, struct hci_dev, power_on);
1098
1099 BT_DBG("%s", hdev->name);
1100
1101 if (hci_dev_open(hdev->id) < 0)
1102 return;
1103
a8b2d5c2 1104 if (test_bit(HCI_AUTO_OFF, &hdev->dev_flags))
80b7ab33 1105 schedule_delayed_work(&hdev->power_off,
3243553f 1106 msecs_to_jiffies(AUTO_OFF_TIMEOUT));
ab81cbf9 1107
a8b2d5c2 1108 if (test_and_clear_bit(HCI_SETUP, &hdev->dev_flags))
744cf19e 1109 mgmt_index_added(hdev);
ab81cbf9
JH
1110}
1111
1112static void hci_power_off(struct work_struct *work)
1113{
3243553f
JH
1114 struct hci_dev *hdev = container_of(work, struct hci_dev,
1115 power_off.work);
ab81cbf9
JH
1116
1117 BT_DBG("%s", hdev->name);
1118
8ee56540 1119 hci_dev_do_close(hdev);
ab81cbf9
JH
1120}
1121
16ab91ab
JH
1122static void hci_discov_off(struct work_struct *work)
1123{
1124 struct hci_dev *hdev;
1125 u8 scan = SCAN_PAGE;
1126
1127 hdev = container_of(work, struct hci_dev, discov_off.work);
1128
1129 BT_DBG("%s", hdev->name);
1130
09fd0de5 1131 hci_dev_lock(hdev);
16ab91ab
JH
1132
1133 hci_send_cmd(hdev, HCI_OP_WRITE_SCAN_ENABLE, sizeof(scan), &scan);
1134
1135 hdev->discov_timeout = 0;
1136
09fd0de5 1137 hci_dev_unlock(hdev);
16ab91ab
JH
1138}
1139
2aeb9a1a
JH
1140int hci_uuids_clear(struct hci_dev *hdev)
1141{
1142 struct list_head *p, *n;
1143
1144 list_for_each_safe(p, n, &hdev->uuids) {
1145 struct bt_uuid *uuid;
1146
1147 uuid = list_entry(p, struct bt_uuid, list);
1148
1149 list_del(p);
1150 kfree(uuid);
1151 }
1152
1153 return 0;
1154}
1155
55ed8ca1
JH
1156int hci_link_keys_clear(struct hci_dev *hdev)
1157{
1158 struct list_head *p, *n;
1159
1160 list_for_each_safe(p, n, &hdev->link_keys) {
1161 struct link_key *key;
1162
1163 key = list_entry(p, struct link_key, list);
1164
1165 list_del(p);
1166 kfree(key);
1167 }
1168
1169 return 0;
1170}
1171
b899efaf
VCG
1172int hci_smp_ltks_clear(struct hci_dev *hdev)
1173{
1174 struct smp_ltk *k, *tmp;
1175
1176 list_for_each_entry_safe(k, tmp, &hdev->long_term_keys, list) {
1177 list_del(&k->list);
1178 kfree(k);
1179 }
1180
1181 return 0;
1182}
1183
55ed8ca1
JH
1184struct link_key *hci_find_link_key(struct hci_dev *hdev, bdaddr_t *bdaddr)
1185{
8035ded4 1186 struct link_key *k;
55ed8ca1 1187
8035ded4 1188 list_for_each_entry(k, &hdev->link_keys, list)
55ed8ca1
JH
1189 if (bacmp(bdaddr, &k->bdaddr) == 0)
1190 return k;
55ed8ca1
JH
1191
1192 return NULL;
1193}
1194
d25e28ab
JH
1195static int hci_persistent_key(struct hci_dev *hdev, struct hci_conn *conn,
1196 u8 key_type, u8 old_key_type)
1197{
1198 /* Legacy key */
1199 if (key_type < 0x03)
1200 return 1;
1201
1202 /* Debug keys are insecure so don't store them persistently */
1203 if (key_type == HCI_LK_DEBUG_COMBINATION)
1204 return 0;
1205
1206 /* Changed combination key and there's no previous one */
1207 if (key_type == HCI_LK_CHANGED_COMBINATION && old_key_type == 0xff)
1208 return 0;
1209
1210 /* Security mode 3 case */
1211 if (!conn)
1212 return 1;
1213
1214 /* Neither local nor remote side had no-bonding as requirement */
1215 if (conn->auth_type > 0x01 && conn->remote_auth > 0x01)
1216 return 1;
1217
1218 /* Local side had dedicated bonding as requirement */
1219 if (conn->auth_type == 0x02 || conn->auth_type == 0x03)
1220 return 1;
1221
1222 /* Remote side had dedicated bonding as requirement */
1223 if (conn->remote_auth == 0x02 || conn->remote_auth == 0x03)
1224 return 1;
1225
1226 /* If none of the above criteria match, then don't store the key
1227 * persistently */
1228 return 0;
1229}
1230
c9839a11 1231struct smp_ltk *hci_find_ltk(struct hci_dev *hdev, __le16 ediv, u8 rand[8])
75d262c2 1232{
c9839a11 1233 struct smp_ltk *k;
75d262c2 1234
c9839a11
VCG
1235 list_for_each_entry(k, &hdev->long_term_keys, list) {
1236 if (k->ediv != ediv ||
1237 memcmp(rand, k->rand, sizeof(k->rand)))
75d262c2
VCG
1238 continue;
1239
c9839a11 1240 return k;
75d262c2
VCG
1241 }
1242
1243 return NULL;
1244}
1245EXPORT_SYMBOL(hci_find_ltk);
1246
c9839a11
VCG
1247struct smp_ltk *hci_find_ltk_by_addr(struct hci_dev *hdev, bdaddr_t *bdaddr,
1248 u8 addr_type)
75d262c2 1249{
c9839a11 1250 struct smp_ltk *k;
75d262c2 1251
c9839a11
VCG
1252 list_for_each_entry(k, &hdev->long_term_keys, list)
1253 if (addr_type == k->bdaddr_type &&
1254 bacmp(bdaddr, &k->bdaddr) == 0)
75d262c2
VCG
1255 return k;
1256
1257 return NULL;
1258}
c9839a11 1259EXPORT_SYMBOL(hci_find_ltk_by_addr);
75d262c2 1260
d25e28ab
JH
1261int hci_add_link_key(struct hci_dev *hdev, struct hci_conn *conn, int new_key,
1262 bdaddr_t *bdaddr, u8 *val, u8 type, u8 pin_len)
55ed8ca1
JH
1263{
1264 struct link_key *key, *old_key;
4df378a1 1265 u8 old_key_type, persistent;
55ed8ca1
JH
1266
1267 old_key = hci_find_link_key(hdev, bdaddr);
1268 if (old_key) {
1269 old_key_type = old_key->type;
1270 key = old_key;
1271 } else {
12adcf3a 1272 old_key_type = conn ? conn->key_type : 0xff;
55ed8ca1
JH
1273 key = kzalloc(sizeof(*key), GFP_ATOMIC);
1274 if (!key)
1275 return -ENOMEM;
1276 list_add(&key->list, &hdev->link_keys);
1277 }
1278
1279 BT_DBG("%s key for %s type %u", hdev->name, batostr(bdaddr), type);
1280
d25e28ab
JH
1281 /* Some buggy controller combinations generate a changed
1282 * combination key for legacy pairing even when there's no
1283 * previous key */
1284 if (type == HCI_LK_CHANGED_COMBINATION &&
1285 (!conn || conn->remote_auth == 0xff) &&
655fe6ec 1286 old_key_type == 0xff) {
d25e28ab 1287 type = HCI_LK_COMBINATION;
655fe6ec
JH
1288 if (conn)
1289 conn->key_type = type;
1290 }
d25e28ab 1291
55ed8ca1
JH
1292 bacpy(&key->bdaddr, bdaddr);
1293 memcpy(key->val, val, 16);
55ed8ca1
JH
1294 key->pin_len = pin_len;
1295
b6020ba0 1296 if (type == HCI_LK_CHANGED_COMBINATION)
55ed8ca1 1297 key->type = old_key_type;
4748fed2
JH
1298 else
1299 key->type = type;
1300
4df378a1
JH
1301 if (!new_key)
1302 return 0;
1303
1304 persistent = hci_persistent_key(hdev, conn, type, old_key_type);
1305
744cf19e 1306 mgmt_new_link_key(hdev, key, persistent);
4df378a1
JH
1307
1308 if (!persistent) {
1309 list_del(&key->list);
1310 kfree(key);
1311 }
55ed8ca1
JH
1312
1313 return 0;
1314}
1315
c9839a11
VCG
1316int hci_add_ltk(struct hci_dev *hdev, bdaddr_t *bdaddr, u8 addr_type, u8 type,
1317 int new_key, u8 authenticated, u8 tk[16],
1318 u8 enc_size, u16 ediv, u8 rand[8])
75d262c2 1319{
c9839a11 1320 struct smp_ltk *key, *old_key;
75d262c2 1321
c9839a11
VCG
1322 if (!(type & HCI_SMP_STK) && !(type & HCI_SMP_LTK))
1323 return 0;
75d262c2 1324
c9839a11
VCG
1325 old_key = hci_find_ltk_by_addr(hdev, bdaddr, addr_type);
1326 if (old_key)
75d262c2 1327 key = old_key;
c9839a11
VCG
1328 else {
1329 key = kzalloc(sizeof(*key), GFP_ATOMIC);
75d262c2
VCG
1330 if (!key)
1331 return -ENOMEM;
c9839a11 1332 list_add(&key->list, &hdev->long_term_keys);
75d262c2
VCG
1333 }
1334
75d262c2 1335 bacpy(&key->bdaddr, bdaddr);
c9839a11
VCG
1336 key->bdaddr_type = addr_type;
1337 memcpy(key->val, tk, sizeof(key->val));
1338 key->authenticated = authenticated;
1339 key->ediv = ediv;
1340 key->enc_size = enc_size;
1341 key->type = type;
1342 memcpy(key->rand, rand, sizeof(key->rand));
75d262c2 1343
c9839a11
VCG
1344 if (!new_key)
1345 return 0;
75d262c2 1346
261cc5aa
VCG
1347 if (type & HCI_SMP_LTK)
1348 mgmt_new_ltk(hdev, key, 1);
1349
75d262c2
VCG
1350 return 0;
1351}
1352
55ed8ca1
JH
1353int hci_remove_link_key(struct hci_dev *hdev, bdaddr_t *bdaddr)
1354{
1355 struct link_key *key;
1356
1357 key = hci_find_link_key(hdev, bdaddr);
1358 if (!key)
1359 return -ENOENT;
1360
1361 BT_DBG("%s removing %s", hdev->name, batostr(bdaddr));
1362
1363 list_del(&key->list);
1364 kfree(key);
1365
1366 return 0;
1367}
1368
b899efaf
VCG
1369int hci_remove_ltk(struct hci_dev *hdev, bdaddr_t *bdaddr)
1370{
1371 struct smp_ltk *k, *tmp;
1372
1373 list_for_each_entry_safe(k, tmp, &hdev->long_term_keys, list) {
1374 if (bacmp(bdaddr, &k->bdaddr))
1375 continue;
1376
1377 BT_DBG("%s removing %s", hdev->name, batostr(bdaddr));
1378
1379 list_del(&k->list);
1380 kfree(k);
1381 }
1382
1383 return 0;
1384}
1385
6bd32326
VT
1386/* HCI command timer function */
1387static void hci_cmd_timer(unsigned long arg)
1388{
1389 struct hci_dev *hdev = (void *) arg;
1390
1391 BT_ERR("%s command tx timeout", hdev->name);
1392 atomic_set(&hdev->cmd_cnt, 1);
c347b765 1393 queue_work(hdev->workqueue, &hdev->cmd_work);
6bd32326
VT
1394}
1395
2763eda6
SJ
1396struct oob_data *hci_find_remote_oob_data(struct hci_dev *hdev,
1397 bdaddr_t *bdaddr)
1398{
1399 struct oob_data *data;
1400
1401 list_for_each_entry(data, &hdev->remote_oob_data, list)
1402 if (bacmp(bdaddr, &data->bdaddr) == 0)
1403 return data;
1404
1405 return NULL;
1406}
1407
1408int hci_remove_remote_oob_data(struct hci_dev *hdev, bdaddr_t *bdaddr)
1409{
1410 struct oob_data *data;
1411
1412 data = hci_find_remote_oob_data(hdev, bdaddr);
1413 if (!data)
1414 return -ENOENT;
1415
1416 BT_DBG("%s removing %s", hdev->name, batostr(bdaddr));
1417
1418 list_del(&data->list);
1419 kfree(data);
1420
1421 return 0;
1422}
1423
1424int hci_remote_oob_data_clear(struct hci_dev *hdev)
1425{
1426 struct oob_data *data, *n;
1427
1428 list_for_each_entry_safe(data, n, &hdev->remote_oob_data, list) {
1429 list_del(&data->list);
1430 kfree(data);
1431 }
1432
1433 return 0;
1434}
1435
1436int hci_add_remote_oob_data(struct hci_dev *hdev, bdaddr_t *bdaddr, u8 *hash,
1437 u8 *randomizer)
1438{
1439 struct oob_data *data;
1440
1441 data = hci_find_remote_oob_data(hdev, bdaddr);
1442
1443 if (!data) {
1444 data = kmalloc(sizeof(*data), GFP_ATOMIC);
1445 if (!data)
1446 return -ENOMEM;
1447
1448 bacpy(&data->bdaddr, bdaddr);
1449 list_add(&data->list, &hdev->remote_oob_data);
1450 }
1451
1452 memcpy(data->hash, hash, sizeof(data->hash));
1453 memcpy(data->randomizer, randomizer, sizeof(data->randomizer));
1454
1455 BT_DBG("%s for %s", hdev->name, batostr(bdaddr));
1456
1457 return 0;
1458}
1459
b2a66aad
AJ
1460struct bdaddr_list *hci_blacklist_lookup(struct hci_dev *hdev,
1461 bdaddr_t *bdaddr)
1462{
8035ded4 1463 struct bdaddr_list *b;
b2a66aad 1464
8035ded4 1465 list_for_each_entry(b, &hdev->blacklist, list)
b2a66aad
AJ
1466 if (bacmp(bdaddr, &b->bdaddr) == 0)
1467 return b;
b2a66aad
AJ
1468
1469 return NULL;
1470}
1471
1472int hci_blacklist_clear(struct hci_dev *hdev)
1473{
1474 struct list_head *p, *n;
1475
1476 list_for_each_safe(p, n, &hdev->blacklist) {
1477 struct bdaddr_list *b;
1478
1479 b = list_entry(p, struct bdaddr_list, list);
1480
1481 list_del(p);
1482 kfree(b);
1483 }
1484
1485 return 0;
1486}
1487
88c1fe4b 1488int hci_blacklist_add(struct hci_dev *hdev, bdaddr_t *bdaddr, u8 type)
b2a66aad
AJ
1489{
1490 struct bdaddr_list *entry;
b2a66aad
AJ
1491
1492 if (bacmp(bdaddr, BDADDR_ANY) == 0)
1493 return -EBADF;
1494
5e762444
AJ
1495 if (hci_blacklist_lookup(hdev, bdaddr))
1496 return -EEXIST;
b2a66aad
AJ
1497
1498 entry = kzalloc(sizeof(struct bdaddr_list), GFP_KERNEL);
5e762444
AJ
1499 if (!entry)
1500 return -ENOMEM;
b2a66aad
AJ
1501
1502 bacpy(&entry->bdaddr, bdaddr);
1503
1504 list_add(&entry->list, &hdev->blacklist);
1505
88c1fe4b 1506 return mgmt_device_blocked(hdev, bdaddr, type);
b2a66aad
AJ
1507}
1508
88c1fe4b 1509int hci_blacklist_del(struct hci_dev *hdev, bdaddr_t *bdaddr, u8 type)
b2a66aad
AJ
1510{
1511 struct bdaddr_list *entry;
b2a66aad 1512
1ec918ce 1513 if (bacmp(bdaddr, BDADDR_ANY) == 0)
5e762444 1514 return hci_blacklist_clear(hdev);
b2a66aad
AJ
1515
1516 entry = hci_blacklist_lookup(hdev, bdaddr);
1ec918ce 1517 if (!entry)
5e762444 1518 return -ENOENT;
b2a66aad
AJ
1519
1520 list_del(&entry->list);
1521 kfree(entry);
1522
88c1fe4b 1523 return mgmt_device_unblocked(hdev, bdaddr, type);
b2a66aad
AJ
1524}
1525
db323f2f 1526static void hci_clear_adv_cache(struct work_struct *work)
35815085 1527{
db323f2f
GP
1528 struct hci_dev *hdev = container_of(work, struct hci_dev,
1529 adv_work.work);
35815085
AG
1530
1531 hci_dev_lock(hdev);
1532
1533 hci_adv_entries_clear(hdev);
1534
1535 hci_dev_unlock(hdev);
1536}
1537
76c8686f
AG
1538int hci_adv_entries_clear(struct hci_dev *hdev)
1539{
1540 struct adv_entry *entry, *tmp;
1541
1542 list_for_each_entry_safe(entry, tmp, &hdev->adv_entries, list) {
1543 list_del(&entry->list);
1544 kfree(entry);
1545 }
1546
1547 BT_DBG("%s adv cache cleared", hdev->name);
1548
1549 return 0;
1550}
1551
1552struct adv_entry *hci_find_adv_entry(struct hci_dev *hdev, bdaddr_t *bdaddr)
1553{
1554 struct adv_entry *entry;
1555
1556 list_for_each_entry(entry, &hdev->adv_entries, list)
1557 if (bacmp(bdaddr, &entry->bdaddr) == 0)
1558 return entry;
1559
1560 return NULL;
1561}
1562
1563static inline int is_connectable_adv(u8 evt_type)
1564{
1565 if (evt_type == ADV_IND || evt_type == ADV_DIRECT_IND)
1566 return 1;
1567
1568 return 0;
1569}
1570
1571int hci_add_adv_entry(struct hci_dev *hdev,
1572 struct hci_ev_le_advertising_info *ev)
1573{
1574 struct adv_entry *entry;
1575
1576 if (!is_connectable_adv(ev->evt_type))
1577 return -EINVAL;
1578
1579 /* Only new entries should be added to adv_entries. So, if
1580 * bdaddr was found, don't add it. */
1581 if (hci_find_adv_entry(hdev, &ev->bdaddr))
1582 return 0;
1583
4777bfde 1584 entry = kzalloc(sizeof(*entry), GFP_KERNEL);
76c8686f
AG
1585 if (!entry)
1586 return -ENOMEM;
1587
1588 bacpy(&entry->bdaddr, &ev->bdaddr);
1589 entry->bdaddr_type = ev->bdaddr_type;
1590
1591 list_add(&entry->list, &hdev->adv_entries);
1592
1593 BT_DBG("%s adv entry added: address %s type %u", hdev->name,
1594 batostr(&entry->bdaddr), entry->bdaddr_type);
1595
1596 return 0;
1597}
1598
7ba8b4be
AG
1599static void le_scan_param_req(struct hci_dev *hdev, unsigned long opt)
1600{
1601 struct le_scan_params *param = (struct le_scan_params *) opt;
1602 struct hci_cp_le_set_scan_param cp;
1603
1604 memset(&cp, 0, sizeof(cp));
1605 cp.type = param->type;
1606 cp.interval = cpu_to_le16(param->interval);
1607 cp.window = cpu_to_le16(param->window);
1608
1609 hci_send_cmd(hdev, HCI_OP_LE_SET_SCAN_PARAM, sizeof(cp), &cp);
1610}
1611
1612static void le_scan_enable_req(struct hci_dev *hdev, unsigned long opt)
1613{
1614 struct hci_cp_le_set_scan_enable cp;
1615
1616 memset(&cp, 0, sizeof(cp));
1617 cp.enable = 1;
1618
1619 hci_send_cmd(hdev, HCI_OP_LE_SET_SCAN_ENABLE, sizeof(cp), &cp);
1620}
1621
1622static int hci_do_le_scan(struct hci_dev *hdev, u8 type, u16 interval,
1623 u16 window, int timeout)
1624{
1625 long timeo = msecs_to_jiffies(3000);
1626 struct le_scan_params param;
1627 int err;
1628
1629 BT_DBG("%s", hdev->name);
1630
1631 if (test_bit(HCI_LE_SCAN, &hdev->dev_flags))
1632 return -EINPROGRESS;
1633
1634 param.type = type;
1635 param.interval = interval;
1636 param.window = window;
1637
1638 hci_req_lock(hdev);
1639
1640 err = __hci_request(hdev, le_scan_param_req, (unsigned long) &param,
1641 timeo);
1642 if (!err)
1643 err = __hci_request(hdev, le_scan_enable_req, 0, timeo);
1644
1645 hci_req_unlock(hdev);
1646
1647 if (err < 0)
1648 return err;
1649
1650 schedule_delayed_work(&hdev->le_scan_disable,
1651 msecs_to_jiffies(timeout));
1652
1653 return 0;
1654}
1655
1656static void le_scan_disable_work(struct work_struct *work)
1657{
1658 struct hci_dev *hdev = container_of(work, struct hci_dev,
1659 le_scan_disable.work);
1660 struct hci_cp_le_set_scan_enable cp;
1661
1662 BT_DBG("%s", hdev->name);
1663
1664 memset(&cp, 0, sizeof(cp));
1665
1666 hci_send_cmd(hdev, HCI_OP_LE_SET_SCAN_ENABLE, sizeof(cp), &cp);
1667}
1668
28b75a89
AG
1669static void le_scan_work(struct work_struct *work)
1670{
1671 struct hci_dev *hdev = container_of(work, struct hci_dev, le_scan);
1672 struct le_scan_params *param = &hdev->le_scan_params;
1673
1674 BT_DBG("%s", hdev->name);
1675
1676 hci_do_le_scan(hdev, param->type, param->interval,
1677 param->window, param->timeout);
1678}
1679
1680int hci_le_scan(struct hci_dev *hdev, u8 type, u16 interval, u16 window,
1681 int timeout)
1682{
1683 struct le_scan_params *param = &hdev->le_scan_params;
1684
1685 BT_DBG("%s", hdev->name);
1686
1687 if (work_busy(&hdev->le_scan))
1688 return -EINPROGRESS;
1689
1690 param->type = type;
1691 param->interval = interval;
1692 param->window = window;
1693 param->timeout = timeout;
1694
1695 queue_work(system_long_wq, &hdev->le_scan);
1696
1697 return 0;
1698}
1699
1da177e4
LT
1700/* Register HCI device */
1701int hci_register_dev(struct hci_dev *hdev)
1702{
1703 struct list_head *head = &hci_dev_list, *p;
08add513 1704 int i, id, error;
1da177e4 1705
e9b9cfa1 1706 BT_DBG("%p name %s bus %d", hdev, hdev->name, hdev->bus);
1da177e4 1707
010666a1 1708 if (!hdev->open || !hdev->close)
1da177e4
LT
1709 return -EINVAL;
1710
08add513
MM
1711 /* Do not allow HCI_AMP devices to register at index 0,
1712 * so the index can be used as the AMP controller ID.
1713 */
1714 id = (hdev->dev_type == HCI_BREDR) ? 0 : 1;
1715
f20d09d5 1716 write_lock(&hci_dev_list_lock);
1da177e4
LT
1717
1718 /* Find first available device id */
1719 list_for_each(p, &hci_dev_list) {
1720 if (list_entry(p, struct hci_dev, list)->id != id)
1721 break;
1722 head = p; id++;
1723 }
8e87d142 1724
1da177e4
LT
1725 sprintf(hdev->name, "hci%d", id);
1726 hdev->id = id;
c6feeb28 1727 list_add_tail(&hdev->list, head);
1da177e4 1728
09fd0de5 1729 mutex_init(&hdev->lock);
1da177e4
LT
1730
1731 hdev->flags = 0;
d23264a8 1732 hdev->dev_flags = 0;
1da177e4 1733 hdev->pkt_type = (HCI_DM1 | HCI_DH1 | HCI_HV1);
5b7f9909 1734 hdev->esco_type = (ESCO_HV1);
1da177e4 1735 hdev->link_mode = (HCI_LM_ACCEPT);
17fa4b9d 1736 hdev->io_capability = 0x03; /* No Input No Output */
1da177e4 1737
04837f64
MH
1738 hdev->idle_timeout = 0;
1739 hdev->sniff_max_interval = 800;
1740 hdev->sniff_min_interval = 80;
1741
b78752cc 1742 INIT_WORK(&hdev->rx_work, hci_rx_work);
c347b765 1743 INIT_WORK(&hdev->cmd_work, hci_cmd_work);
3eff45ea 1744 INIT_WORK(&hdev->tx_work, hci_tx_work);
b78752cc 1745
1da177e4
LT
1746
1747 skb_queue_head_init(&hdev->rx_q);
1748 skb_queue_head_init(&hdev->cmd_q);
1749 skb_queue_head_init(&hdev->raw_q);
1750
6bd32326
VT
1751 setup_timer(&hdev->cmd_timer, hci_cmd_timer, (unsigned long) hdev);
1752
cd4c5391 1753 for (i = 0; i < NUM_REASSEMBLY; i++)
ef222013
MH
1754 hdev->reassembly[i] = NULL;
1755
1da177e4 1756 init_waitqueue_head(&hdev->req_wait_q);
a6a67efd 1757 mutex_init(&hdev->req_lock);
1da177e4 1758
30883512 1759 discovery_init(hdev);
1da177e4
LT
1760
1761 hci_conn_hash_init(hdev);
1762
2e58ef3e
JH
1763 INIT_LIST_HEAD(&hdev->mgmt_pending);
1764
ea4bd8ba 1765 INIT_LIST_HEAD(&hdev->blacklist);
f0358568 1766
2aeb9a1a
JH
1767 INIT_LIST_HEAD(&hdev->uuids);
1768
55ed8ca1 1769 INIT_LIST_HEAD(&hdev->link_keys);
b899efaf 1770 INIT_LIST_HEAD(&hdev->long_term_keys);
55ed8ca1 1771
2763eda6
SJ
1772 INIT_LIST_HEAD(&hdev->remote_oob_data);
1773
76c8686f
AG
1774 INIT_LIST_HEAD(&hdev->adv_entries);
1775
db323f2f 1776 INIT_DELAYED_WORK(&hdev->adv_work, hci_clear_adv_cache);
ab81cbf9 1777 INIT_WORK(&hdev->power_on, hci_power_on);
3243553f 1778 INIT_DELAYED_WORK(&hdev->power_off, hci_power_off);
ab81cbf9 1779
16ab91ab
JH
1780 INIT_DELAYED_WORK(&hdev->discov_off, hci_discov_off);
1781
1da177e4
LT
1782 memset(&hdev->stat, 0, sizeof(struct hci_dev_stats));
1783
1784 atomic_set(&hdev->promisc, 0);
1785
28b75a89
AG
1786 INIT_WORK(&hdev->le_scan, le_scan_work);
1787
7ba8b4be
AG
1788 INIT_DELAYED_WORK(&hdev->le_scan_disable, le_scan_disable_work);
1789
f20d09d5 1790 write_unlock(&hci_dev_list_lock);
1da177e4 1791
32845eb1
GP
1792 hdev->workqueue = alloc_workqueue(hdev->name, WQ_HIGHPRI | WQ_UNBOUND |
1793 WQ_MEM_RECLAIM, 1);
33ca954d
DH
1794 if (!hdev->workqueue) {
1795 error = -ENOMEM;
1796 goto err;
1797 }
f48fd9c8 1798
33ca954d
DH
1799 error = hci_add_sysfs(hdev);
1800 if (error < 0)
1801 goto err_wqueue;
1da177e4 1802
611b30f7
MH
1803 hdev->rfkill = rfkill_alloc(hdev->name, &hdev->dev,
1804 RFKILL_TYPE_BLUETOOTH, &hci_rfkill_ops, hdev);
1805 if (hdev->rfkill) {
1806 if (rfkill_register(hdev->rfkill) < 0) {
1807 rfkill_destroy(hdev->rfkill);
1808 hdev->rfkill = NULL;
1809 }
1810 }
1811
a8b2d5c2
JH
1812 set_bit(HCI_AUTO_OFF, &hdev->dev_flags);
1813 set_bit(HCI_SETUP, &hdev->dev_flags);
7f971041 1814 schedule_work(&hdev->power_on);
ab81cbf9 1815
1da177e4 1816 hci_notify(hdev, HCI_DEV_REG);
dc946bd8 1817 hci_dev_hold(hdev);
1da177e4
LT
1818
1819 return id;
f48fd9c8 1820
33ca954d
DH
1821err_wqueue:
1822 destroy_workqueue(hdev->workqueue);
1823err:
f20d09d5 1824 write_lock(&hci_dev_list_lock);
f48fd9c8 1825 list_del(&hdev->list);
f20d09d5 1826 write_unlock(&hci_dev_list_lock);
f48fd9c8 1827
33ca954d 1828 return error;
1da177e4
LT
1829}
1830EXPORT_SYMBOL(hci_register_dev);
1831
1832/* Unregister HCI device */
59735631 1833void hci_unregister_dev(struct hci_dev *hdev)
1da177e4 1834{
ef222013
MH
1835 int i;
1836
c13854ce 1837 BT_DBG("%p name %s bus %d", hdev, hdev->name, hdev->bus);
1da177e4 1838
f20d09d5 1839 write_lock(&hci_dev_list_lock);
1da177e4 1840 list_del(&hdev->list);
f20d09d5 1841 write_unlock(&hci_dev_list_lock);
1da177e4
LT
1842
1843 hci_dev_do_close(hdev);
1844
cd4c5391 1845 for (i = 0; i < NUM_REASSEMBLY; i++)
ef222013
MH
1846 kfree_skb(hdev->reassembly[i]);
1847
ab81cbf9 1848 if (!test_bit(HCI_INIT, &hdev->flags) &&
a8b2d5c2 1849 !test_bit(HCI_SETUP, &hdev->dev_flags)) {
09fd0de5 1850 hci_dev_lock(hdev);
744cf19e 1851 mgmt_index_removed(hdev);
09fd0de5 1852 hci_dev_unlock(hdev);
56e5cb86 1853 }
ab81cbf9 1854
2e58ef3e
JH
1855 /* mgmt_index_removed should take care of emptying the
1856 * pending list */
1857 BUG_ON(!list_empty(&hdev->mgmt_pending));
1858
1da177e4
LT
1859 hci_notify(hdev, HCI_DEV_UNREG);
1860
611b30f7
MH
1861 if (hdev->rfkill) {
1862 rfkill_unregister(hdev->rfkill);
1863 rfkill_destroy(hdev->rfkill);
1864 }
1865
ce242970 1866 hci_del_sysfs(hdev);
147e2d59 1867
db323f2f 1868 cancel_delayed_work_sync(&hdev->adv_work);
c6f3c5f7 1869
f48fd9c8
MH
1870 destroy_workqueue(hdev->workqueue);
1871
09fd0de5 1872 hci_dev_lock(hdev);
e2e0cacb 1873 hci_blacklist_clear(hdev);
2aeb9a1a 1874 hci_uuids_clear(hdev);
55ed8ca1 1875 hci_link_keys_clear(hdev);
b899efaf 1876 hci_smp_ltks_clear(hdev);
2763eda6 1877 hci_remote_oob_data_clear(hdev);
76c8686f 1878 hci_adv_entries_clear(hdev);
09fd0de5 1879 hci_dev_unlock(hdev);
e2e0cacb 1880
dc946bd8 1881 hci_dev_put(hdev);
1da177e4
LT
1882}
1883EXPORT_SYMBOL(hci_unregister_dev);
1884
1885/* Suspend HCI device */
1886int hci_suspend_dev(struct hci_dev *hdev)
1887{
1888 hci_notify(hdev, HCI_DEV_SUSPEND);
1889 return 0;
1890}
1891EXPORT_SYMBOL(hci_suspend_dev);
1892
1893/* Resume HCI device */
1894int hci_resume_dev(struct hci_dev *hdev)
1895{
1896 hci_notify(hdev, HCI_DEV_RESUME);
1897 return 0;
1898}
1899EXPORT_SYMBOL(hci_resume_dev);
1900
76bca880
MH
1901/* Receive frame from HCI drivers */
1902int hci_recv_frame(struct sk_buff *skb)
1903{
1904 struct hci_dev *hdev = (struct hci_dev *) skb->dev;
1905 if (!hdev || (!test_bit(HCI_UP, &hdev->flags)
1906 && !test_bit(HCI_INIT, &hdev->flags))) {
1907 kfree_skb(skb);
1908 return -ENXIO;
1909 }
1910
1911 /* Incomming skb */
1912 bt_cb(skb)->incoming = 1;
1913
1914 /* Time stamp */
1915 __net_timestamp(skb);
1916
76bca880 1917 skb_queue_tail(&hdev->rx_q, skb);
b78752cc 1918 queue_work(hdev->workqueue, &hdev->rx_work);
c78ae283 1919
76bca880
MH
1920 return 0;
1921}
1922EXPORT_SYMBOL(hci_recv_frame);
1923
33e882a5 1924static int hci_reassembly(struct hci_dev *hdev, int type, void *data,
1e429f38 1925 int count, __u8 index)
33e882a5
SS
1926{
1927 int len = 0;
1928 int hlen = 0;
1929 int remain = count;
1930 struct sk_buff *skb;
1931 struct bt_skb_cb *scb;
1932
1933 if ((type < HCI_ACLDATA_PKT || type > HCI_EVENT_PKT) ||
1934 index >= NUM_REASSEMBLY)
1935 return -EILSEQ;
1936
1937 skb = hdev->reassembly[index];
1938
1939 if (!skb) {
1940 switch (type) {
1941 case HCI_ACLDATA_PKT:
1942 len = HCI_MAX_FRAME_SIZE;
1943 hlen = HCI_ACL_HDR_SIZE;
1944 break;
1945 case HCI_EVENT_PKT:
1946 len = HCI_MAX_EVENT_SIZE;
1947 hlen = HCI_EVENT_HDR_SIZE;
1948 break;
1949 case HCI_SCODATA_PKT:
1950 len = HCI_MAX_SCO_SIZE;
1951 hlen = HCI_SCO_HDR_SIZE;
1952 break;
1953 }
1954
1e429f38 1955 skb = bt_skb_alloc(len, GFP_ATOMIC);
33e882a5
SS
1956 if (!skb)
1957 return -ENOMEM;
1958
1959 scb = (void *) skb->cb;
1960 scb->expect = hlen;
1961 scb->pkt_type = type;
1962
1963 skb->dev = (void *) hdev;
1964 hdev->reassembly[index] = skb;
1965 }
1966
1967 while (count) {
1968 scb = (void *) skb->cb;
70c1f20b 1969 len = min_t(__u16, scb->expect, count);
33e882a5
SS
1970
1971 memcpy(skb_put(skb, len), data, len);
1972
1973 count -= len;
1974 data += len;
1975 scb->expect -= len;
1976 remain = count;
1977
1978 switch (type) {
1979 case HCI_EVENT_PKT:
1980 if (skb->len == HCI_EVENT_HDR_SIZE) {
1981 struct hci_event_hdr *h = hci_event_hdr(skb);
1982 scb->expect = h->plen;
1983
1984 if (skb_tailroom(skb) < scb->expect) {
1985 kfree_skb(skb);
1986 hdev->reassembly[index] = NULL;
1987 return -ENOMEM;
1988 }
1989 }
1990 break;
1991
1992 case HCI_ACLDATA_PKT:
1993 if (skb->len == HCI_ACL_HDR_SIZE) {
1994 struct hci_acl_hdr *h = hci_acl_hdr(skb);
1995 scb->expect = __le16_to_cpu(h->dlen);
1996
1997 if (skb_tailroom(skb) < scb->expect) {
1998 kfree_skb(skb);
1999 hdev->reassembly[index] = NULL;
2000 return -ENOMEM;
2001 }
2002 }
2003 break;
2004
2005 case HCI_SCODATA_PKT:
2006 if (skb->len == HCI_SCO_HDR_SIZE) {
2007 struct hci_sco_hdr *h = hci_sco_hdr(skb);
2008 scb->expect = h->dlen;
2009
2010 if (skb_tailroom(skb) < scb->expect) {
2011 kfree_skb(skb);
2012 hdev->reassembly[index] = NULL;
2013 return -ENOMEM;
2014 }
2015 }
2016 break;
2017 }
2018
2019 if (scb->expect == 0) {
2020 /* Complete frame */
2021
2022 bt_cb(skb)->pkt_type = type;
2023 hci_recv_frame(skb);
2024
2025 hdev->reassembly[index] = NULL;
2026 return remain;
2027 }
2028 }
2029
2030 return remain;
2031}
2032
ef222013
MH
2033int hci_recv_fragment(struct hci_dev *hdev, int type, void *data, int count)
2034{
f39a3c06
SS
2035 int rem = 0;
2036
ef222013
MH
2037 if (type < HCI_ACLDATA_PKT || type > HCI_EVENT_PKT)
2038 return -EILSEQ;
2039
da5f6c37 2040 while (count) {
1e429f38 2041 rem = hci_reassembly(hdev, type, data, count, type - 1);
f39a3c06
SS
2042 if (rem < 0)
2043 return rem;
ef222013 2044
f39a3c06
SS
2045 data += (count - rem);
2046 count = rem;
f81c6224 2047 }
ef222013 2048
f39a3c06 2049 return rem;
ef222013
MH
2050}
2051EXPORT_SYMBOL(hci_recv_fragment);
2052
99811510
SS
2053#define STREAM_REASSEMBLY 0
2054
2055int hci_recv_stream_fragment(struct hci_dev *hdev, void *data, int count)
2056{
2057 int type;
2058 int rem = 0;
2059
da5f6c37 2060 while (count) {
99811510
SS
2061 struct sk_buff *skb = hdev->reassembly[STREAM_REASSEMBLY];
2062
2063 if (!skb) {
2064 struct { char type; } *pkt;
2065
2066 /* Start of the frame */
2067 pkt = data;
2068 type = pkt->type;
2069
2070 data++;
2071 count--;
2072 } else
2073 type = bt_cb(skb)->pkt_type;
2074
1e429f38
GP
2075 rem = hci_reassembly(hdev, type, data, count,
2076 STREAM_REASSEMBLY);
99811510
SS
2077 if (rem < 0)
2078 return rem;
2079
2080 data += (count - rem);
2081 count = rem;
f81c6224 2082 }
99811510
SS
2083
2084 return rem;
2085}
2086EXPORT_SYMBOL(hci_recv_stream_fragment);
2087
1da177e4
LT
2088/* ---- Interface to upper protocols ---- */
2089
1da177e4
LT
2090int hci_register_cb(struct hci_cb *cb)
2091{
2092 BT_DBG("%p name %s", cb, cb->name);
2093
f20d09d5 2094 write_lock(&hci_cb_list_lock);
1da177e4 2095 list_add(&cb->list, &hci_cb_list);
f20d09d5 2096 write_unlock(&hci_cb_list_lock);
1da177e4
LT
2097
2098 return 0;
2099}
2100EXPORT_SYMBOL(hci_register_cb);
2101
2102int hci_unregister_cb(struct hci_cb *cb)
2103{
2104 BT_DBG("%p name %s", cb, cb->name);
2105
f20d09d5 2106 write_lock(&hci_cb_list_lock);
1da177e4 2107 list_del(&cb->list);
f20d09d5 2108 write_unlock(&hci_cb_list_lock);
1da177e4
LT
2109
2110 return 0;
2111}
2112EXPORT_SYMBOL(hci_unregister_cb);
2113
2114static int hci_send_frame(struct sk_buff *skb)
2115{
2116 struct hci_dev *hdev = (struct hci_dev *) skb->dev;
2117
2118 if (!hdev) {
2119 kfree_skb(skb);
2120 return -ENODEV;
2121 }
2122
0d48d939 2123 BT_DBG("%s type %d len %d", hdev->name, bt_cb(skb)->pkt_type, skb->len);
1da177e4 2124
cd82e61c
MH
2125 /* Time stamp */
2126 __net_timestamp(skb);
1da177e4 2127
cd82e61c
MH
2128 /* Send copy to monitor */
2129 hci_send_to_monitor(hdev, skb);
2130
2131 if (atomic_read(&hdev->promisc)) {
2132 /* Send copy to the sockets */
470fe1b5 2133 hci_send_to_sock(hdev, skb);
1da177e4
LT
2134 }
2135
2136 /* Get rid of skb owner, prior to sending to the driver. */
2137 skb_orphan(skb);
2138
2139 return hdev->send(skb);
2140}
2141
2142/* Send HCI command */
a9de9248 2143int hci_send_cmd(struct hci_dev *hdev, __u16 opcode, __u32 plen, void *param)
1da177e4
LT
2144{
2145 int len = HCI_COMMAND_HDR_SIZE + plen;
2146 struct hci_command_hdr *hdr;
2147 struct sk_buff *skb;
2148
a9de9248 2149 BT_DBG("%s opcode 0x%x plen %d", hdev->name, opcode, plen);
1da177e4
LT
2150
2151 skb = bt_skb_alloc(len, GFP_ATOMIC);
2152 if (!skb) {
ef222013 2153 BT_ERR("%s no memory for command", hdev->name);
1da177e4
LT
2154 return -ENOMEM;
2155 }
2156
2157 hdr = (struct hci_command_hdr *) skb_put(skb, HCI_COMMAND_HDR_SIZE);
a9de9248 2158 hdr->opcode = cpu_to_le16(opcode);
1da177e4
LT
2159 hdr->plen = plen;
2160
2161 if (plen)
2162 memcpy(skb_put(skb, plen), param, plen);
2163
2164 BT_DBG("skb len %d", skb->len);
2165
0d48d939 2166 bt_cb(skb)->pkt_type = HCI_COMMAND_PKT;
1da177e4 2167 skb->dev = (void *) hdev;
c78ae283 2168
a5040efa
JH
2169 if (test_bit(HCI_INIT, &hdev->flags))
2170 hdev->init_last_cmd = opcode;
2171
1da177e4 2172 skb_queue_tail(&hdev->cmd_q, skb);
c347b765 2173 queue_work(hdev->workqueue, &hdev->cmd_work);
1da177e4
LT
2174
2175 return 0;
2176}
1da177e4
LT
2177
2178/* Get data from the previously sent command */
a9de9248 2179void *hci_sent_cmd_data(struct hci_dev *hdev, __u16 opcode)
1da177e4
LT
2180{
2181 struct hci_command_hdr *hdr;
2182
2183 if (!hdev->sent_cmd)
2184 return NULL;
2185
2186 hdr = (void *) hdev->sent_cmd->data;
2187
a9de9248 2188 if (hdr->opcode != cpu_to_le16(opcode))
1da177e4
LT
2189 return NULL;
2190
a9de9248 2191 BT_DBG("%s opcode 0x%x", hdev->name, opcode);
1da177e4
LT
2192
2193 return hdev->sent_cmd->data + HCI_COMMAND_HDR_SIZE;
2194}
2195
2196/* Send ACL data */
2197static void hci_add_acl_hdr(struct sk_buff *skb, __u16 handle, __u16 flags)
2198{
2199 struct hci_acl_hdr *hdr;
2200 int len = skb->len;
2201
badff6d0
ACM
2202 skb_push(skb, HCI_ACL_HDR_SIZE);
2203 skb_reset_transport_header(skb);
9c70220b 2204 hdr = (struct hci_acl_hdr *)skb_transport_header(skb);
aca3192c
YH
2205 hdr->handle = cpu_to_le16(hci_handle_pack(handle, flags));
2206 hdr->dlen = cpu_to_le16(len);
1da177e4
LT
2207}
2208
73d80deb
LAD
2209static void hci_queue_acl(struct hci_conn *conn, struct sk_buff_head *queue,
2210 struct sk_buff *skb, __u16 flags)
1da177e4
LT
2211{
2212 struct hci_dev *hdev = conn->hdev;
2213 struct sk_buff *list;
2214
70f23020
AE
2215 list = skb_shinfo(skb)->frag_list;
2216 if (!list) {
1da177e4
LT
2217 /* Non fragmented */
2218 BT_DBG("%s nonfrag skb %p len %d", hdev->name, skb, skb->len);
2219
73d80deb 2220 skb_queue_tail(queue, skb);
1da177e4
LT
2221 } else {
2222 /* Fragmented */
2223 BT_DBG("%s frag %p len %d", hdev->name, skb, skb->len);
2224
2225 skb_shinfo(skb)->frag_list = NULL;
2226
2227 /* Queue all fragments atomically */
af3e6359 2228 spin_lock(&queue->lock);
1da177e4 2229
73d80deb 2230 __skb_queue_tail(queue, skb);
e702112f
AE
2231
2232 flags &= ~ACL_START;
2233 flags |= ACL_CONT;
1da177e4
LT
2234 do {
2235 skb = list; list = list->next;
8e87d142 2236
1da177e4 2237 skb->dev = (void *) hdev;
0d48d939 2238 bt_cb(skb)->pkt_type = HCI_ACLDATA_PKT;
e702112f 2239 hci_add_acl_hdr(skb, conn->handle, flags);
1da177e4
LT
2240
2241 BT_DBG("%s frag %p len %d", hdev->name, skb, skb->len);
2242
73d80deb 2243 __skb_queue_tail(queue, skb);
1da177e4
LT
2244 } while (list);
2245
af3e6359 2246 spin_unlock(&queue->lock);
1da177e4 2247 }
73d80deb
LAD
2248}
2249
2250void hci_send_acl(struct hci_chan *chan, struct sk_buff *skb, __u16 flags)
2251{
2252 struct hci_conn *conn = chan->conn;
2253 struct hci_dev *hdev = conn->hdev;
2254
2255 BT_DBG("%s chan %p flags 0x%x", hdev->name, chan, flags);
2256
2257 skb->dev = (void *) hdev;
2258 bt_cb(skb)->pkt_type = HCI_ACLDATA_PKT;
2259 hci_add_acl_hdr(skb, conn->handle, flags);
2260
2261 hci_queue_acl(conn, &chan->data_q, skb, flags);
1da177e4 2262
3eff45ea 2263 queue_work(hdev->workqueue, &hdev->tx_work);
1da177e4
LT
2264}
2265EXPORT_SYMBOL(hci_send_acl);
2266
2267/* Send SCO data */
0d861d8b 2268void hci_send_sco(struct hci_conn *conn, struct sk_buff *skb)
1da177e4
LT
2269{
2270 struct hci_dev *hdev = conn->hdev;
2271 struct hci_sco_hdr hdr;
2272
2273 BT_DBG("%s len %d", hdev->name, skb->len);
2274
aca3192c 2275 hdr.handle = cpu_to_le16(conn->handle);
1da177e4
LT
2276 hdr.dlen = skb->len;
2277
badff6d0
ACM
2278 skb_push(skb, HCI_SCO_HDR_SIZE);
2279 skb_reset_transport_header(skb);
9c70220b 2280 memcpy(skb_transport_header(skb), &hdr, HCI_SCO_HDR_SIZE);
1da177e4
LT
2281
2282 skb->dev = (void *) hdev;
0d48d939 2283 bt_cb(skb)->pkt_type = HCI_SCODATA_PKT;
c78ae283 2284
1da177e4 2285 skb_queue_tail(&conn->data_q, skb);
3eff45ea 2286 queue_work(hdev->workqueue, &hdev->tx_work);
1da177e4
LT
2287}
2288EXPORT_SYMBOL(hci_send_sco);
2289
2290/* ---- HCI TX task (outgoing data) ---- */
2291
2292/* HCI Connection scheduler */
2293static inline struct hci_conn *hci_low_sent(struct hci_dev *hdev, __u8 type, int *quote)
2294{
2295 struct hci_conn_hash *h = &hdev->conn_hash;
8035ded4 2296 struct hci_conn *conn = NULL, *c;
1da177e4 2297 int num = 0, min = ~0;
1da177e4 2298
8e87d142 2299 /* We don't have to lock device here. Connections are always
1da177e4 2300 * added and removed with TX task disabled. */
bf4c6325
GP
2301
2302 rcu_read_lock();
2303
2304 list_for_each_entry_rcu(c, &h->list, list) {
769be974 2305 if (c->type != type || skb_queue_empty(&c->data_q))
1da177e4 2306 continue;
769be974
MH
2307
2308 if (c->state != BT_CONNECTED && c->state != BT_CONFIG)
2309 continue;
2310
1da177e4
LT
2311 num++;
2312
2313 if (c->sent < min) {
2314 min = c->sent;
2315 conn = c;
2316 }
52087a79
LAD
2317
2318 if (hci_conn_num(hdev, type) == num)
2319 break;
1da177e4
LT
2320 }
2321
bf4c6325
GP
2322 rcu_read_unlock();
2323
1da177e4 2324 if (conn) {
6ed58ec5
VT
2325 int cnt, q;
2326
2327 switch (conn->type) {
2328 case ACL_LINK:
2329 cnt = hdev->acl_cnt;
2330 break;
2331 case SCO_LINK:
2332 case ESCO_LINK:
2333 cnt = hdev->sco_cnt;
2334 break;
2335 case LE_LINK:
2336 cnt = hdev->le_mtu ? hdev->le_cnt : hdev->acl_cnt;
2337 break;
2338 default:
2339 cnt = 0;
2340 BT_ERR("Unknown link type");
2341 }
2342
2343 q = cnt / num;
1da177e4
LT
2344 *quote = q ? q : 1;
2345 } else
2346 *quote = 0;
2347
2348 BT_DBG("conn %p quote %d", conn, *quote);
2349 return conn;
2350}
2351
bae1f5d9 2352static inline void hci_link_tx_to(struct hci_dev *hdev, __u8 type)
1da177e4
LT
2353{
2354 struct hci_conn_hash *h = &hdev->conn_hash;
8035ded4 2355 struct hci_conn *c;
1da177e4 2356
bae1f5d9 2357 BT_ERR("%s link tx timeout", hdev->name);
1da177e4 2358
bf4c6325
GP
2359 rcu_read_lock();
2360
1da177e4 2361 /* Kill stalled connections */
bf4c6325 2362 list_for_each_entry_rcu(c, &h->list, list) {
bae1f5d9
VT
2363 if (c->type == type && c->sent) {
2364 BT_ERR("%s killing stalled connection %s",
1da177e4
LT
2365 hdev->name, batostr(&c->dst));
2366 hci_acl_disconn(c, 0x13);
2367 }
2368 }
bf4c6325
GP
2369
2370 rcu_read_unlock();
1da177e4
LT
2371}
2372
73d80deb
LAD
2373static inline struct hci_chan *hci_chan_sent(struct hci_dev *hdev, __u8 type,
2374 int *quote)
1da177e4 2375{
73d80deb
LAD
2376 struct hci_conn_hash *h = &hdev->conn_hash;
2377 struct hci_chan *chan = NULL;
2378 int num = 0, min = ~0, cur_prio = 0;
1da177e4 2379 struct hci_conn *conn;
73d80deb
LAD
2380 int cnt, q, conn_num = 0;
2381
2382 BT_DBG("%s", hdev->name);
2383
bf4c6325
GP
2384 rcu_read_lock();
2385
2386 list_for_each_entry_rcu(conn, &h->list, list) {
73d80deb
LAD
2387 struct hci_chan *tmp;
2388
2389 if (conn->type != type)
2390 continue;
2391
2392 if (conn->state != BT_CONNECTED && conn->state != BT_CONFIG)
2393 continue;
2394
2395 conn_num++;
2396
8192edef 2397 list_for_each_entry_rcu(tmp, &conn->chan_list, list) {
73d80deb
LAD
2398 struct sk_buff *skb;
2399
2400 if (skb_queue_empty(&tmp->data_q))
2401 continue;
2402
2403 skb = skb_peek(&tmp->data_q);
2404 if (skb->priority < cur_prio)
2405 continue;
2406
2407 if (skb->priority > cur_prio) {
2408 num = 0;
2409 min = ~0;
2410 cur_prio = skb->priority;
2411 }
2412
2413 num++;
2414
2415 if (conn->sent < min) {
2416 min = conn->sent;
2417 chan = tmp;
2418 }
2419 }
2420
2421 if (hci_conn_num(hdev, type) == conn_num)
2422 break;
2423 }
2424
bf4c6325
GP
2425 rcu_read_unlock();
2426
73d80deb
LAD
2427 if (!chan)
2428 return NULL;
2429
2430 switch (chan->conn->type) {
2431 case ACL_LINK:
2432 cnt = hdev->acl_cnt;
2433 break;
2434 case SCO_LINK:
2435 case ESCO_LINK:
2436 cnt = hdev->sco_cnt;
2437 break;
2438 case LE_LINK:
2439 cnt = hdev->le_mtu ? hdev->le_cnt : hdev->acl_cnt;
2440 break;
2441 default:
2442 cnt = 0;
2443 BT_ERR("Unknown link type");
2444 }
2445
2446 q = cnt / num;
2447 *quote = q ? q : 1;
2448 BT_DBG("chan %p quote %d", chan, *quote);
2449 return chan;
2450}
2451
02b20f0b
LAD
2452static void hci_prio_recalculate(struct hci_dev *hdev, __u8 type)
2453{
2454 struct hci_conn_hash *h = &hdev->conn_hash;
2455 struct hci_conn *conn;
2456 int num = 0;
2457
2458 BT_DBG("%s", hdev->name);
2459
bf4c6325
GP
2460 rcu_read_lock();
2461
2462 list_for_each_entry_rcu(conn, &h->list, list) {
02b20f0b
LAD
2463 struct hci_chan *chan;
2464
2465 if (conn->type != type)
2466 continue;
2467
2468 if (conn->state != BT_CONNECTED && conn->state != BT_CONFIG)
2469 continue;
2470
2471 num++;
2472
8192edef 2473 list_for_each_entry_rcu(chan, &conn->chan_list, list) {
02b20f0b
LAD
2474 struct sk_buff *skb;
2475
2476 if (chan->sent) {
2477 chan->sent = 0;
2478 continue;
2479 }
2480
2481 if (skb_queue_empty(&chan->data_q))
2482 continue;
2483
2484 skb = skb_peek(&chan->data_q);
2485 if (skb->priority >= HCI_PRIO_MAX - 1)
2486 continue;
2487
2488 skb->priority = HCI_PRIO_MAX - 1;
2489
2490 BT_DBG("chan %p skb %p promoted to %d", chan, skb,
2491 skb->priority);
2492 }
2493
2494 if (hci_conn_num(hdev, type) == num)
2495 break;
2496 }
bf4c6325
GP
2497
2498 rcu_read_unlock();
2499
02b20f0b
LAD
2500}
2501
b71d385a
AE
2502static inline int __get_blocks(struct hci_dev *hdev, struct sk_buff *skb)
2503{
2504 /* Calculate count of blocks used by this packet */
2505 return DIV_ROUND_UP(skb->len - HCI_ACL_HDR_SIZE, hdev->block_len);
2506}
2507
63d2bc1b 2508static inline void __check_timeout(struct hci_dev *hdev, unsigned int cnt)
73d80deb 2509{
1da177e4
LT
2510 if (!test_bit(HCI_RAW, &hdev->flags)) {
2511 /* ACL tx timeout must be longer than maximum
2512 * link supervision timeout (40.9 seconds) */
63d2bc1b 2513 if (!cnt && time_after(jiffies, hdev->acl_last_tx +
cc48dc0a 2514 msecs_to_jiffies(HCI_ACL_TX_TIMEOUT)))
bae1f5d9 2515 hci_link_tx_to(hdev, ACL_LINK);
1da177e4 2516 }
63d2bc1b 2517}
1da177e4 2518
63d2bc1b
AE
2519static inline void hci_sched_acl_pkt(struct hci_dev *hdev)
2520{
2521 unsigned int cnt = hdev->acl_cnt;
2522 struct hci_chan *chan;
2523 struct sk_buff *skb;
2524 int quote;
2525
2526 __check_timeout(hdev, cnt);
04837f64 2527
73d80deb
LAD
2528 while (hdev->acl_cnt &&
2529 (chan = hci_chan_sent(hdev, ACL_LINK, &quote))) {
ec1cce24
LAD
2530 u32 priority = (skb_peek(&chan->data_q))->priority;
2531 while (quote-- && (skb = skb_peek(&chan->data_q))) {
73d80deb
LAD
2532 BT_DBG("chan %p skb %p len %d priority %u", chan, skb,
2533 skb->len, skb->priority);
2534
ec1cce24
LAD
2535 /* Stop if priority has changed */
2536 if (skb->priority < priority)
2537 break;
2538
2539 skb = skb_dequeue(&chan->data_q);
2540
73d80deb
LAD
2541 hci_conn_enter_active_mode(chan->conn,
2542 bt_cb(skb)->force_active);
04837f64 2543
1da177e4
LT
2544 hci_send_frame(skb);
2545 hdev->acl_last_tx = jiffies;
2546
2547 hdev->acl_cnt--;
73d80deb
LAD
2548 chan->sent++;
2549 chan->conn->sent++;
1da177e4
LT
2550 }
2551 }
02b20f0b
LAD
2552
2553 if (cnt != hdev->acl_cnt)
2554 hci_prio_recalculate(hdev, ACL_LINK);
1da177e4
LT
2555}
2556
b71d385a
AE
2557static inline void hci_sched_acl_blk(struct hci_dev *hdev)
2558{
63d2bc1b 2559 unsigned int cnt = hdev->block_cnt;
b71d385a
AE
2560 struct hci_chan *chan;
2561 struct sk_buff *skb;
2562 int quote;
b71d385a 2563
63d2bc1b 2564 __check_timeout(hdev, cnt);
b71d385a
AE
2565
2566 while (hdev->block_cnt > 0 &&
2567 (chan = hci_chan_sent(hdev, ACL_LINK, &quote))) {
2568 u32 priority = (skb_peek(&chan->data_q))->priority;
2569 while (quote > 0 && (skb = skb_peek(&chan->data_q))) {
2570 int blocks;
2571
2572 BT_DBG("chan %p skb %p len %d priority %u", chan, skb,
2573 skb->len, skb->priority);
2574
2575 /* Stop if priority has changed */
2576 if (skb->priority < priority)
2577 break;
2578
2579 skb = skb_dequeue(&chan->data_q);
2580
2581 blocks = __get_blocks(hdev, skb);
2582 if (blocks > hdev->block_cnt)
2583 return;
2584
2585 hci_conn_enter_active_mode(chan->conn,
2586 bt_cb(skb)->force_active);
2587
2588 hci_send_frame(skb);
2589 hdev->acl_last_tx = jiffies;
2590
2591 hdev->block_cnt -= blocks;
2592 quote -= blocks;
2593
2594 chan->sent += blocks;
2595 chan->conn->sent += blocks;
2596 }
2597 }
2598
2599 if (cnt != hdev->block_cnt)
2600 hci_prio_recalculate(hdev, ACL_LINK);
2601}
2602
2603static inline void hci_sched_acl(struct hci_dev *hdev)
2604{
2605 BT_DBG("%s", hdev->name);
2606
2607 if (!hci_conn_num(hdev, ACL_LINK))
2608 return;
2609
2610 switch (hdev->flow_ctl_mode) {
2611 case HCI_FLOW_CTL_MODE_PACKET_BASED:
2612 hci_sched_acl_pkt(hdev);
2613 break;
2614
2615 case HCI_FLOW_CTL_MODE_BLOCK_BASED:
2616 hci_sched_acl_blk(hdev);
2617 break;
2618 }
2619}
2620
1da177e4
LT
2621/* Schedule SCO */
2622static inline void hci_sched_sco(struct hci_dev *hdev)
2623{
2624 struct hci_conn *conn;
2625 struct sk_buff *skb;
2626 int quote;
2627
2628 BT_DBG("%s", hdev->name);
2629
52087a79
LAD
2630 if (!hci_conn_num(hdev, SCO_LINK))
2631 return;
2632
1da177e4
LT
2633 while (hdev->sco_cnt && (conn = hci_low_sent(hdev, SCO_LINK, &quote))) {
2634 while (quote-- && (skb = skb_dequeue(&conn->data_q))) {
2635 BT_DBG("skb %p len %d", skb, skb->len);
2636 hci_send_frame(skb);
2637
2638 conn->sent++;
2639 if (conn->sent == ~0)
2640 conn->sent = 0;
2641 }
2642 }
2643}
2644
b6a0dc82
MH
2645static inline void hci_sched_esco(struct hci_dev *hdev)
2646{
2647 struct hci_conn *conn;
2648 struct sk_buff *skb;
2649 int quote;
2650
2651 BT_DBG("%s", hdev->name);
2652
52087a79
LAD
2653 if (!hci_conn_num(hdev, ESCO_LINK))
2654 return;
2655
b6a0dc82
MH
2656 while (hdev->sco_cnt && (conn = hci_low_sent(hdev, ESCO_LINK, &quote))) {
2657 while (quote-- && (skb = skb_dequeue(&conn->data_q))) {
2658 BT_DBG("skb %p len %d", skb, skb->len);
2659 hci_send_frame(skb);
2660
2661 conn->sent++;
2662 if (conn->sent == ~0)
2663 conn->sent = 0;
2664 }
2665 }
2666}
2667
6ed58ec5
VT
2668static inline void hci_sched_le(struct hci_dev *hdev)
2669{
73d80deb 2670 struct hci_chan *chan;
6ed58ec5 2671 struct sk_buff *skb;
02b20f0b 2672 int quote, cnt, tmp;
6ed58ec5
VT
2673
2674 BT_DBG("%s", hdev->name);
2675
52087a79
LAD
2676 if (!hci_conn_num(hdev, LE_LINK))
2677 return;
2678
6ed58ec5
VT
2679 if (!test_bit(HCI_RAW, &hdev->flags)) {
2680 /* LE tx timeout must be longer than maximum
2681 * link supervision timeout (40.9 seconds) */
bae1f5d9 2682 if (!hdev->le_cnt && hdev->le_pkts &&
6ed58ec5 2683 time_after(jiffies, hdev->le_last_tx + HZ * 45))
bae1f5d9 2684 hci_link_tx_to(hdev, LE_LINK);
6ed58ec5
VT
2685 }
2686
2687 cnt = hdev->le_pkts ? hdev->le_cnt : hdev->acl_cnt;
02b20f0b 2688 tmp = cnt;
73d80deb 2689 while (cnt && (chan = hci_chan_sent(hdev, LE_LINK, &quote))) {
ec1cce24
LAD
2690 u32 priority = (skb_peek(&chan->data_q))->priority;
2691 while (quote-- && (skb = skb_peek(&chan->data_q))) {
73d80deb
LAD
2692 BT_DBG("chan %p skb %p len %d priority %u", chan, skb,
2693 skb->len, skb->priority);
6ed58ec5 2694
ec1cce24
LAD
2695 /* Stop if priority has changed */
2696 if (skb->priority < priority)
2697 break;
2698
2699 skb = skb_dequeue(&chan->data_q);
2700
6ed58ec5
VT
2701 hci_send_frame(skb);
2702 hdev->le_last_tx = jiffies;
2703
2704 cnt--;
73d80deb
LAD
2705 chan->sent++;
2706 chan->conn->sent++;
6ed58ec5
VT
2707 }
2708 }
73d80deb 2709
6ed58ec5
VT
2710 if (hdev->le_pkts)
2711 hdev->le_cnt = cnt;
2712 else
2713 hdev->acl_cnt = cnt;
02b20f0b
LAD
2714
2715 if (cnt != tmp)
2716 hci_prio_recalculate(hdev, LE_LINK);
6ed58ec5
VT
2717}
2718
3eff45ea 2719static void hci_tx_work(struct work_struct *work)
1da177e4 2720{
3eff45ea 2721 struct hci_dev *hdev = container_of(work, struct hci_dev, tx_work);
1da177e4
LT
2722 struct sk_buff *skb;
2723
6ed58ec5
VT
2724 BT_DBG("%s acl %d sco %d le %d", hdev->name, hdev->acl_cnt,
2725 hdev->sco_cnt, hdev->le_cnt);
1da177e4
LT
2726
2727 /* Schedule queues and send stuff to HCI driver */
2728
2729 hci_sched_acl(hdev);
2730
2731 hci_sched_sco(hdev);
2732
b6a0dc82
MH
2733 hci_sched_esco(hdev);
2734
6ed58ec5
VT
2735 hci_sched_le(hdev);
2736
1da177e4
LT
2737 /* Send next queued raw (unknown type) packet */
2738 while ((skb = skb_dequeue(&hdev->raw_q)))
2739 hci_send_frame(skb);
1da177e4
LT
2740}
2741
25985edc 2742/* ----- HCI RX task (incoming data processing) ----- */
1da177e4
LT
2743
2744/* ACL data packet */
2745static inline void hci_acldata_packet(struct hci_dev *hdev, struct sk_buff *skb)
2746{
2747 struct hci_acl_hdr *hdr = (void *) skb->data;
2748 struct hci_conn *conn;
2749 __u16 handle, flags;
2750
2751 skb_pull(skb, HCI_ACL_HDR_SIZE);
2752
2753 handle = __le16_to_cpu(hdr->handle);
2754 flags = hci_flags(handle);
2755 handle = hci_handle(handle);
2756
2757 BT_DBG("%s len %d handle 0x%x flags 0x%x", hdev->name, skb->len, handle, flags);
2758
2759 hdev->stat.acl_rx++;
2760
2761 hci_dev_lock(hdev);
2762 conn = hci_conn_hash_lookup_handle(hdev, handle);
2763 hci_dev_unlock(hdev);
8e87d142 2764
1da177e4 2765 if (conn) {
65983fc7 2766 hci_conn_enter_active_mode(conn, BT_POWER_FORCE_ACTIVE_OFF);
04837f64 2767
1da177e4 2768 /* Send to upper protocol */
686ebf28
UF
2769 l2cap_recv_acldata(conn, skb, flags);
2770 return;
1da177e4 2771 } else {
8e87d142 2772 BT_ERR("%s ACL packet for unknown connection handle %d",
1da177e4
LT
2773 hdev->name, handle);
2774 }
2775
2776 kfree_skb(skb);
2777}
2778
2779/* SCO data packet */
2780static inline void hci_scodata_packet(struct hci_dev *hdev, struct sk_buff *skb)
2781{
2782 struct hci_sco_hdr *hdr = (void *) skb->data;
2783 struct hci_conn *conn;
2784 __u16 handle;
2785
2786 skb_pull(skb, HCI_SCO_HDR_SIZE);
2787
2788 handle = __le16_to_cpu(hdr->handle);
2789
2790 BT_DBG("%s len %d handle 0x%x", hdev->name, skb->len, handle);
2791
2792 hdev->stat.sco_rx++;
2793
2794 hci_dev_lock(hdev);
2795 conn = hci_conn_hash_lookup_handle(hdev, handle);
2796 hci_dev_unlock(hdev);
2797
2798 if (conn) {
1da177e4 2799 /* Send to upper protocol */
686ebf28
UF
2800 sco_recv_scodata(conn, skb);
2801 return;
1da177e4 2802 } else {
8e87d142 2803 BT_ERR("%s SCO packet for unknown connection handle %d",
1da177e4
LT
2804 hdev->name, handle);
2805 }
2806
2807 kfree_skb(skb);
2808}
2809
b78752cc 2810static void hci_rx_work(struct work_struct *work)
1da177e4 2811{
b78752cc 2812 struct hci_dev *hdev = container_of(work, struct hci_dev, rx_work);
1da177e4
LT
2813 struct sk_buff *skb;
2814
2815 BT_DBG("%s", hdev->name);
2816
1da177e4 2817 while ((skb = skb_dequeue(&hdev->rx_q))) {
cd82e61c
MH
2818 /* Send copy to monitor */
2819 hci_send_to_monitor(hdev, skb);
2820
1da177e4
LT
2821 if (atomic_read(&hdev->promisc)) {
2822 /* Send copy to the sockets */
470fe1b5 2823 hci_send_to_sock(hdev, skb);
1da177e4
LT
2824 }
2825
2826 if (test_bit(HCI_RAW, &hdev->flags)) {
2827 kfree_skb(skb);
2828 continue;
2829 }
2830
2831 if (test_bit(HCI_INIT, &hdev->flags)) {
2832 /* Don't process data packets in this states. */
0d48d939 2833 switch (bt_cb(skb)->pkt_type) {
1da177e4
LT
2834 case HCI_ACLDATA_PKT:
2835 case HCI_SCODATA_PKT:
2836 kfree_skb(skb);
2837 continue;
3ff50b79 2838 }
1da177e4
LT
2839 }
2840
2841 /* Process frame */
0d48d939 2842 switch (bt_cb(skb)->pkt_type) {
1da177e4 2843 case HCI_EVENT_PKT:
b78752cc 2844 BT_DBG("%s Event packet", hdev->name);
1da177e4
LT
2845 hci_event_packet(hdev, skb);
2846 break;
2847
2848 case HCI_ACLDATA_PKT:
2849 BT_DBG("%s ACL data packet", hdev->name);
2850 hci_acldata_packet(hdev, skb);
2851 break;
2852
2853 case HCI_SCODATA_PKT:
2854 BT_DBG("%s SCO data packet", hdev->name);
2855 hci_scodata_packet(hdev, skb);
2856 break;
2857
2858 default:
2859 kfree_skb(skb);
2860 break;
2861 }
2862 }
1da177e4
LT
2863}
2864
c347b765 2865static void hci_cmd_work(struct work_struct *work)
1da177e4 2866{
c347b765 2867 struct hci_dev *hdev = container_of(work, struct hci_dev, cmd_work);
1da177e4
LT
2868 struct sk_buff *skb;
2869
2870 BT_DBG("%s cmd %d", hdev->name, atomic_read(&hdev->cmd_cnt));
2871
1da177e4 2872 /* Send queued commands */
5a08ecce
AE
2873 if (atomic_read(&hdev->cmd_cnt)) {
2874 skb = skb_dequeue(&hdev->cmd_q);
2875 if (!skb)
2876 return;
2877
7585b97a 2878 kfree_skb(hdev->sent_cmd);
1da177e4 2879
70f23020
AE
2880 hdev->sent_cmd = skb_clone(skb, GFP_ATOMIC);
2881 if (hdev->sent_cmd) {
1da177e4
LT
2882 atomic_dec(&hdev->cmd_cnt);
2883 hci_send_frame(skb);
7bdb8a5c
SJ
2884 if (test_bit(HCI_RESET, &hdev->flags))
2885 del_timer(&hdev->cmd_timer);
2886 else
2887 mod_timer(&hdev->cmd_timer,
6bd32326 2888 jiffies + msecs_to_jiffies(HCI_CMD_TIMEOUT));
1da177e4
LT
2889 } else {
2890 skb_queue_head(&hdev->cmd_q, skb);
c347b765 2891 queue_work(hdev->workqueue, &hdev->cmd_work);
1da177e4
LT
2892 }
2893 }
2894}
2519a1fc
AG
2895
2896int hci_do_inquiry(struct hci_dev *hdev, u8 length)
2897{
2898 /* General inquiry access code (GIAC) */
2899 u8 lap[3] = { 0x33, 0x8b, 0x9e };
2900 struct hci_cp_inquiry cp;
2901
2902 BT_DBG("%s", hdev->name);
2903
2904 if (test_bit(HCI_INQUIRY, &hdev->flags))
2905 return -EINPROGRESS;
2906
4663262c
JH
2907 inquiry_cache_flush(hdev);
2908
2519a1fc
AG
2909 memset(&cp, 0, sizeof(cp));
2910 memcpy(&cp.lap, lap, sizeof(cp.lap));
2911 cp.length = length;
2912
2913 return hci_send_cmd(hdev, HCI_OP_INQUIRY, sizeof(cp), &cp);
2914}
023d5049
AG
2915
2916int hci_cancel_inquiry(struct hci_dev *hdev)
2917{
2918 BT_DBG("%s", hdev->name);
2919
2920 if (!test_bit(HCI_INQUIRY, &hdev->flags))
2921 return -EPERM;
2922
2923 return hci_send_cmd(hdev, HCI_OP_INQUIRY_CANCEL, 0, NULL);
2924}