Bluetooth: Fix potential bad memory access with sysfs files
[GitHub/mt8127/android_kernel_alcatel_ttab.git] / net / bluetooth / sco.c
CommitLineData
8e87d142 1/*
1da177e4
LT
2 BlueZ - Bluetooth protocol stack for Linux
3 Copyright (C) 2000-2001 Qualcomm Incorporated
4
5 Written 2000,2001 by Maxim Krasnyansky <maxk@qualcomm.com>
6
7 This program is free software; you can redistribute it and/or modify
8 it under the terms of the GNU General Public License version 2 as
9 published by the Free Software Foundation;
10
11 THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS
12 OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
13 FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT OF THIRD PARTY RIGHTS.
14 IN NO EVENT SHALL THE COPYRIGHT HOLDER(S) AND AUTHOR(S) BE LIABLE FOR ANY
8e87d142
YH
15 CLAIM, OR ANY SPECIAL INDIRECT OR CONSEQUENTIAL DAMAGES, OR ANY DAMAGES
16 WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
17 ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
1da177e4
LT
18 OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
19
8e87d142
YH
20 ALL LIABILITY, INCLUDING LIABILITY FOR INFRINGEMENT OF ANY PATENTS,
21 COPYRIGHTS, TRADEMARKS OR OTHER RIGHTS, RELATING TO USE OF THIS
1da177e4
LT
22 SOFTWARE IS DISCLAIMED.
23*/
24
25/* Bluetooth SCO sockets. */
26
1da177e4
LT
27#include <linux/module.h>
28
29#include <linux/types.h>
30#include <linux/errno.h>
31#include <linux/kernel.h>
1da177e4
LT
32#include <linux/sched.h>
33#include <linux/slab.h>
34#include <linux/poll.h>
35#include <linux/fcntl.h>
36#include <linux/init.h>
37#include <linux/interrupt.h>
38#include <linux/socket.h>
39#include <linux/skbuff.h>
be9d1227 40#include <linux/device.h>
1da177e4
LT
41#include <linux/list.h>
42#include <net/sock.h>
43
44#include <asm/system.h>
45#include <asm/uaccess.h>
46
47#include <net/bluetooth/bluetooth.h>
48#include <net/bluetooth/hci_core.h>
49#include <net/bluetooth/sco.h>
50
7cb127d5
MH
51#define VERSION "0.6"
52
53static int disable_esco = 0;
1da177e4 54
90ddc4f0 55static const struct proto_ops sco_sock_ops;
1da177e4
LT
56
57static struct bt_sock_list sco_sk_list = {
d5fb2962 58 .lock = __RW_LOCK_UNLOCKED(sco_sk_list.lock)
1da177e4
LT
59};
60
61static void __sco_chan_add(struct sco_conn *conn, struct sock *sk, struct sock *parent);
62static void sco_chan_del(struct sock *sk, int err);
63
64static int sco_conn_del(struct hci_conn *conn, int err);
65
66static void sco_sock_close(struct sock *sk);
67static void sco_sock_kill(struct sock *sk);
68
69/* ---- SCO timers ---- */
70static void sco_sock_timeout(unsigned long arg)
71{
72 struct sock *sk = (struct sock *) arg;
73
74 BT_DBG("sock %p state %d", sk, sk->sk_state);
75
76 bh_lock_sock(sk);
77 sk->sk_err = ETIMEDOUT;
78 sk->sk_state_change(sk);
79 bh_unlock_sock(sk);
80
81 sco_sock_kill(sk);
82 sock_put(sk);
83}
84
85static void sco_sock_set_timer(struct sock *sk, long timeout)
86{
87 BT_DBG("sock %p state %d timeout %ld", sk, sk->sk_state, timeout);
88 sk_reset_timer(sk, &sk->sk_timer, jiffies + timeout);
89}
90
91static void sco_sock_clear_timer(struct sock *sk)
92{
93 BT_DBG("sock %p state %d", sk, sk->sk_state);
94 sk_stop_timer(sk, &sk->sk_timer);
95}
96
1da177e4
LT
97/* ---- SCO connections ---- */
98static struct sco_conn *sco_conn_add(struct hci_conn *hcon, __u8 status)
99{
100 struct hci_dev *hdev = hcon->hdev;
25ea6db0 101 struct sco_conn *conn = hcon->sco_data;
1da177e4 102
25ea6db0 103 if (conn || status)
1da177e4
LT
104 return conn;
105
25ea6db0
MH
106 conn = kzalloc(sizeof(struct sco_conn), GFP_ATOMIC);
107 if (!conn)
1da177e4 108 return NULL;
1da177e4
LT
109
110 spin_lock_init(&conn->lock);
111
112 hcon->sco_data = conn;
113 conn->hcon = hcon;
114
115 conn->src = &hdev->bdaddr;
116 conn->dst = &hcon->dst;
117
118 if (hdev->sco_mtu > 0)
119 conn->mtu = hdev->sco_mtu;
120 else
121 conn->mtu = 60;
122
123 BT_DBG("hcon %p conn %p", hcon, conn);
25ea6db0 124
1da177e4
LT
125 return conn;
126}
127
128static inline struct sock *sco_chan_get(struct sco_conn *conn)
129{
130 struct sock *sk = NULL;
131 sco_conn_lock(conn);
132 sk = conn->sk;
133 sco_conn_unlock(conn);
134 return sk;
135}
136
137static int sco_conn_del(struct hci_conn *hcon, int err)
138{
139 struct sco_conn *conn;
140 struct sock *sk;
141
8e87d142 142 if (!(conn = hcon->sco_data))
1da177e4
LT
143 return 0;
144
145 BT_DBG("hcon %p conn %p, err %d", hcon, conn, err);
146
147 /* Kill socket */
148 if ((sk = sco_chan_get(conn))) {
149 bh_lock_sock(sk);
150 sco_sock_clear_timer(sk);
151 sco_chan_del(sk, err);
152 bh_unlock_sock(sk);
153 sco_sock_kill(sk);
154 }
155
156 hcon->sco_data = NULL;
157 kfree(conn);
158 return 0;
159}
160
161static inline int sco_chan_add(struct sco_conn *conn, struct sock *sk, struct sock *parent)
162{
163 int err = 0;
164
165 sco_conn_lock(conn);
166 if (conn->sk) {
167 err = -EBUSY;
168 } else {
169 __sco_chan_add(conn, sk, parent);
170 }
171 sco_conn_unlock(conn);
172 return err;
173}
174
175static int sco_connect(struct sock *sk)
176{
177 bdaddr_t *src = &bt_sk(sk)->src;
178 bdaddr_t *dst = &bt_sk(sk)->dst;
179 struct sco_conn *conn;
180 struct hci_conn *hcon;
181 struct hci_dev *hdev;
b6a0dc82 182 int err, type;
1da177e4
LT
183
184 BT_DBG("%s -> %s", batostr(src), batostr(dst));
185
186 if (!(hdev = hci_get_route(dst, src)))
187 return -EHOSTUNREACH;
188
189 hci_dev_lock_bh(hdev);
190
191 err = -ENOMEM;
192
7cb127d5
MH
193 if (lmp_esco_capable(hdev) && !disable_esco)
194 type = ESCO_LINK;
195 else
196 type = SCO_LINK;
b6a0dc82 197
8c1b2355 198 hcon = hci_connect(hdev, type, dst, BT_SECURITY_LOW, HCI_AT_NO_BONDING);
1da177e4
LT
199 if (!hcon)
200 goto done;
201
202 conn = sco_conn_add(hcon, 0);
203 if (!conn) {
204 hci_conn_put(hcon);
205 goto done;
206 }
207
208 /* Update source addr of the socket */
209 bacpy(src, conn->src);
210
211 err = sco_chan_add(conn, sk, NULL);
212 if (err)
213 goto done;
214
215 if (hcon->state == BT_CONNECTED) {
216 sco_sock_clear_timer(sk);
217 sk->sk_state = BT_CONNECTED;
218 } else {
219 sk->sk_state = BT_CONNECT;
220 sco_sock_set_timer(sk, sk->sk_sndtimeo);
221 }
b6a0dc82 222
1da177e4
LT
223done:
224 hci_dev_unlock_bh(hdev);
225 hci_dev_put(hdev);
226 return err;
227}
228
229static inline int sco_send_frame(struct sock *sk, struct msghdr *msg, int len)
230{
231 struct sco_conn *conn = sco_pi(sk)->conn;
232 struct sk_buff *skb;
233 int err, count;
234
235 /* Check outgoing MTU */
236 if (len > conn->mtu)
237 return -EINVAL;
238
239 BT_DBG("sk %p len %d", sk, len);
240
241 count = min_t(unsigned int, conn->mtu, len);
242 if (!(skb = bt_skb_send_alloc(sk, count, msg->msg_flags & MSG_DONTWAIT, &err)))
243 return err;
244
245 if (memcpy_fromiovec(skb_put(skb, count), msg->msg_iov, count)) {
246 err = -EFAULT;
247 goto fail;
248 }
249
250 if ((err = hci_send_sco(conn->hcon, skb)) < 0)
cdee5751 251 return err;
1da177e4
LT
252
253 return count;
254
255fail:
256 kfree_skb(skb);
257 return err;
258}
259
260static inline void sco_recv_frame(struct sco_conn *conn, struct sk_buff *skb)
261{
262 struct sock *sk = sco_chan_get(conn);
263
264 if (!sk)
265 goto drop;
266
267 BT_DBG("sk %p len %d", sk, skb->len);
268
269 if (sk->sk_state != BT_CONNECTED)
270 goto drop;
271
272 if (!sock_queue_rcv_skb(sk, skb))
273 return;
274
275drop:
276 kfree_skb(skb);
277 return;
278}
279
280/* -------- Socket interface ---------- */
281static struct sock *__sco_get_sock_by_addr(bdaddr_t *ba)
282{
283 struct sock *sk;
284 struct hlist_node *node;
285
286 sk_for_each(sk, node, &sco_sk_list.head)
287 if (!bacmp(&bt_sk(sk)->src, ba))
288 goto found;
289 sk = NULL;
290found:
291 return sk;
292}
293
294/* Find socket listening on source bdaddr.
295 * Returns closest match.
296 */
297static struct sock *sco_get_sock_listen(bdaddr_t *src)
298{
299 struct sock *sk = NULL, *sk1 = NULL;
300 struct hlist_node *node;
301
302 read_lock(&sco_sk_list.lock);
303
304 sk_for_each(sk, node, &sco_sk_list.head) {
305 if (sk->sk_state != BT_LISTEN)
306 continue;
307
308 /* Exact match. */
309 if (!bacmp(&bt_sk(sk)->src, src))
310 break;
311
312 /* Closest match */
313 if (!bacmp(&bt_sk(sk)->src, BDADDR_ANY))
314 sk1 = sk;
315 }
316
317 read_unlock(&sco_sk_list.lock);
318
319 return node ? sk : sk1;
320}
321
322static void sco_sock_destruct(struct sock *sk)
323{
324 BT_DBG("sk %p", sk);
325
326 skb_queue_purge(&sk->sk_receive_queue);
327 skb_queue_purge(&sk->sk_write_queue);
328}
329
330static void sco_sock_cleanup_listen(struct sock *parent)
331{
332 struct sock *sk;
333
334 BT_DBG("parent %p", parent);
335
336 /* Close not yet accepted channels */
337 while ((sk = bt_accept_dequeue(parent, NULL))) {
338 sco_sock_close(sk);
339 sco_sock_kill(sk);
340 }
341
342 parent->sk_state = BT_CLOSED;
343 sock_set_flag(parent, SOCK_ZAPPED);
344}
345
346/* Kill socket (only if zapped and orphan)
347 * Must be called on unlocked socket.
348 */
349static void sco_sock_kill(struct sock *sk)
350{
351 if (!sock_flag(sk, SOCK_ZAPPED) || sk->sk_socket)
352 return;
353
354 BT_DBG("sk %p state %d", sk, sk->sk_state);
355
356 /* Kill poor orphan */
357 bt_sock_unlink(&sco_sk_list, sk);
358 sock_set_flag(sk, SOCK_DEAD);
359 sock_put(sk);
360}
361
fd0b3ff7 362static void __sco_sock_close(struct sock *sk)
1da177e4 363{
fd0b3ff7 364 BT_DBG("sk %p state %d socket %p", sk, sk->sk_state, sk->sk_socket);
1da177e4
LT
365
366 switch (sk->sk_state) {
367 case BT_LISTEN:
368 sco_sock_cleanup_listen(sk);
369 break;
370
371 case BT_CONNECTED:
372 case BT_CONFIG:
373 case BT_CONNECT:
374 case BT_DISCONN:
375 sco_chan_del(sk, ECONNRESET);
376 break;
377
378 default:
379 sock_set_flag(sk, SOCK_ZAPPED);
380 break;
3ff50b79 381 }
fd0b3ff7 382}
1da177e4 383
fd0b3ff7
MH
384/* Must be called on unlocked socket. */
385static void sco_sock_close(struct sock *sk)
386{
387 sco_sock_clear_timer(sk);
388 lock_sock(sk);
389 __sco_sock_close(sk);
1da177e4 390 release_sock(sk);
1da177e4
LT
391 sco_sock_kill(sk);
392}
393
394static void sco_sock_init(struct sock *sk, struct sock *parent)
395{
396 BT_DBG("sk %p", sk);
397
8e87d142 398 if (parent)
1da177e4
LT
399 sk->sk_type = parent->sk_type;
400}
401
402static struct proto sco_proto = {
403 .name = "SCO",
404 .owner = THIS_MODULE,
405 .obj_size = sizeof(struct sco_pinfo)
406};
407
1b8d7ae4 408static struct sock *sco_sock_alloc(struct net *net, struct socket *sock, int proto, gfp_t prio)
1da177e4
LT
409{
410 struct sock *sk;
411
6257ff21 412 sk = sk_alloc(net, PF_BLUETOOTH, prio, &sco_proto);
1da177e4
LT
413 if (!sk)
414 return NULL;
415
416 sock_init_data(sock, sk);
417 INIT_LIST_HEAD(&bt_sk(sk)->accept_q);
418
419 sk->sk_destruct = sco_sock_destruct;
420 sk->sk_sndtimeo = SCO_CONN_TIMEOUT;
421
422 sock_reset_flag(sk, SOCK_ZAPPED);
423
424 sk->sk_protocol = proto;
425 sk->sk_state = BT_OPEN;
426
b24b8a24 427 setup_timer(&sk->sk_timer, sco_sock_timeout, (unsigned long)sk);
1da177e4
LT
428
429 bt_sock_link(&sco_sk_list, sk);
430 return sk;
431}
432
3f378b68
EP
433static int sco_sock_create(struct net *net, struct socket *sock, int protocol,
434 int kern)
1da177e4
LT
435{
436 struct sock *sk;
437
438 BT_DBG("sock %p", sock);
439
440 sock->state = SS_UNCONNECTED;
441
442 if (sock->type != SOCK_SEQPACKET)
443 return -ESOCKTNOSUPPORT;
444
445 sock->ops = &sco_sock_ops;
446
1b8d7ae4 447 sk = sco_sock_alloc(net, sock, protocol, GFP_ATOMIC);
74da626a 448 if (!sk)
1da177e4
LT
449 return -ENOMEM;
450
451 sco_sock_init(sk, NULL);
452 return 0;
453}
454
455static int sco_sock_bind(struct socket *sock, struct sockaddr *addr, int addr_len)
456{
457 struct sockaddr_sco *sa = (struct sockaddr_sco *) addr;
458 struct sock *sk = sock->sk;
459 bdaddr_t *src = &sa->sco_bdaddr;
460 int err = 0;
461
462 BT_DBG("sk %p %s", sk, batostr(&sa->sco_bdaddr));
463
464 if (!addr || addr->sa_family != AF_BLUETOOTH)
465 return -EINVAL;
466
467 lock_sock(sk);
468
469 if (sk->sk_state != BT_OPEN) {
470 err = -EBADFD;
471 goto done;
472 }
473
474 write_lock_bh(&sco_sk_list.lock);
475
476 if (bacmp(src, BDADDR_ANY) && __sco_get_sock_by_addr(src)) {
477 err = -EADDRINUSE;
478 } else {
479 /* Save source address */
480 bacpy(&bt_sk(sk)->src, &sa->sco_bdaddr);
481 sk->sk_state = BT_BOUND;
482 }
483
484 write_unlock_bh(&sco_sk_list.lock);
485
486done:
487 release_sock(sk);
488 return err;
489}
490
491static int sco_sock_connect(struct socket *sock, struct sockaddr *addr, int alen, int flags)
492{
493 struct sockaddr_sco *sa = (struct sockaddr_sco *) addr;
494 struct sock *sk = sock->sk;
495 int err = 0;
496
497
498 BT_DBG("sk %p", sk);
499
500 if (addr->sa_family != AF_BLUETOOTH || alen < sizeof(struct sockaddr_sco))
501 return -EINVAL;
502
503 if (sk->sk_state != BT_OPEN && sk->sk_state != BT_BOUND)
504 return -EBADFD;
505
506 if (sk->sk_type != SOCK_SEQPACKET)
507 return -EINVAL;
508
509 lock_sock(sk);
510
511 /* Set destination address and psm */
512 bacpy(&bt_sk(sk)->dst, &sa->sco_bdaddr);
513
514 if ((err = sco_connect(sk)))
515 goto done;
516
8e87d142 517 err = bt_sock_wait_state(sk, BT_CONNECTED,
1da177e4
LT
518 sock_sndtimeo(sk, flags & O_NONBLOCK));
519
520done:
521 release_sock(sk);
522 return err;
523}
524
525static int sco_sock_listen(struct socket *sock, int backlog)
526{
527 struct sock *sk = sock->sk;
528 int err = 0;
529
530 BT_DBG("sk %p backlog %d", sk, backlog);
531
532 lock_sock(sk);
533
534 if (sk->sk_state != BT_BOUND || sock->type != SOCK_SEQPACKET) {
535 err = -EBADFD;
536 goto done;
537 }
538
539 sk->sk_max_ack_backlog = backlog;
540 sk->sk_ack_backlog = 0;
541 sk->sk_state = BT_LISTEN;
542
543done:
544 release_sock(sk);
545 return err;
546}
547
548static int sco_sock_accept(struct socket *sock, struct socket *newsock, int flags)
549{
550 DECLARE_WAITQUEUE(wait, current);
551 struct sock *sk = sock->sk, *ch;
552 long timeo;
553 int err = 0;
554
555 lock_sock(sk);
556
557 if (sk->sk_state != BT_LISTEN) {
558 err = -EBADFD;
559 goto done;
560 }
561
562 timeo = sock_rcvtimeo(sk, flags & O_NONBLOCK);
563
564 BT_DBG("sk %p timeo %ld", sk, timeo);
565
566 /* Wait for an incoming connection. (wake-one). */
567 add_wait_queue_exclusive(sk->sk_sleep, &wait);
568 while (!(ch = bt_accept_dequeue(sk, newsock))) {
569 set_current_state(TASK_INTERRUPTIBLE);
570 if (!timeo) {
571 err = -EAGAIN;
572 break;
573 }
574
575 release_sock(sk);
576 timeo = schedule_timeout(timeo);
577 lock_sock(sk);
578
579 if (sk->sk_state != BT_LISTEN) {
580 err = -EBADFD;
581 break;
582 }
583
584 if (signal_pending(current)) {
585 err = sock_intr_errno(timeo);
586 break;
587 }
588 }
589 set_current_state(TASK_RUNNING);
590 remove_wait_queue(sk->sk_sleep, &wait);
591
592 if (err)
593 goto done;
594
595 newsock->state = SS_CONNECTED;
596
597 BT_DBG("new socket %p", ch);
598
599done:
600 release_sock(sk);
601 return err;
602}
603
604static int sco_sock_getname(struct socket *sock, struct sockaddr *addr, int *len, int peer)
605{
606 struct sockaddr_sco *sa = (struct sockaddr_sco *) addr;
607 struct sock *sk = sock->sk;
608
609 BT_DBG("sock %p, sk %p", sock, sk);
610
611 addr->sa_family = AF_BLUETOOTH;
612 *len = sizeof(struct sockaddr_sco);
613
614 if (peer)
615 bacpy(&sa->sco_bdaddr, &bt_sk(sk)->dst);
616 else
617 bacpy(&sa->sco_bdaddr, &bt_sk(sk)->src);
618
619 return 0;
620}
621
8e87d142 622static int sco_sock_sendmsg(struct kiocb *iocb, struct socket *sock,
1da177e4
LT
623 struct msghdr *msg, size_t len)
624{
625 struct sock *sk = sock->sk;
626 int err = 0;
627
628 BT_DBG("sock %p, sk %p", sock, sk);
629
c1cbe4b7
BL
630 err = sock_error(sk);
631 if (err)
632 return err;
1da177e4
LT
633
634 if (msg->msg_flags & MSG_OOB)
635 return -EOPNOTSUPP;
636
637 lock_sock(sk);
638
639 if (sk->sk_state == BT_CONNECTED)
640 err = sco_send_frame(sk, msg, len);
641 else
642 err = -ENOTCONN;
643
644 release_sock(sk);
645 return err;
646}
647
b7058842 648static int sco_sock_setsockopt(struct socket *sock, int level, int optname, char __user *optval, unsigned int optlen)
1da177e4
LT
649{
650 struct sock *sk = sock->sk;
651 int err = 0;
652
653 BT_DBG("sk %p", sk);
654
655 lock_sock(sk);
656
657 switch (optname) {
658 default:
659 err = -ENOPROTOOPT;
660 break;
661 }
662
663 release_sock(sk);
664 return err;
665}
666
d58daf42 667static int sco_sock_getsockopt_old(struct socket *sock, int optname, char __user *optval, int __user *optlen)
1da177e4
LT
668{
669 struct sock *sk = sock->sk;
670 struct sco_options opts;
671 struct sco_conninfo cinfo;
8e87d142 672 int len, err = 0;
1da177e4
LT
673
674 BT_DBG("sk %p", sk);
675
676 if (get_user(len, optlen))
677 return -EFAULT;
678
679 lock_sock(sk);
680
681 switch (optname) {
682 case SCO_OPTIONS:
683 if (sk->sk_state != BT_CONNECTED) {
684 err = -ENOTCONN;
685 break;
686 }
687
688 opts.mtu = sco_pi(sk)->conn->mtu;
689
690 BT_DBG("mtu %d", opts.mtu);
691
692 len = min_t(unsigned int, len, sizeof(opts));
693 if (copy_to_user(optval, (char *)&opts, len))
694 err = -EFAULT;
695
696 break;
697
698 case SCO_CONNINFO:
699 if (sk->sk_state != BT_CONNECTED) {
700 err = -ENOTCONN;
701 break;
702 }
703
704 cinfo.hci_handle = sco_pi(sk)->conn->hcon->handle;
705 memcpy(cinfo.dev_class, sco_pi(sk)->conn->hcon->dev_class, 3);
706
707 len = min_t(unsigned int, len, sizeof(cinfo));
708 if (copy_to_user(optval, (char *)&cinfo, len))
709 err = -EFAULT;
710
711 break;
712
713 default:
714 err = -ENOPROTOOPT;
715 break;
716 }
717
718 release_sock(sk);
719 return err;
720}
721
d58daf42
MH
722static int sco_sock_getsockopt(struct socket *sock, int level, int optname, char __user *optval, int __user *optlen)
723{
724 struct sock *sk = sock->sk;
725 int len, err = 0;
726
727 BT_DBG("sk %p", sk);
728
729 if (level == SOL_SCO)
730 return sco_sock_getsockopt_old(sock, optname, optval, optlen);
731
732 if (get_user(len, optlen))
733 return -EFAULT;
734
735 lock_sock(sk);
736
737 switch (optname) {
738 default:
739 err = -ENOPROTOOPT;
740 break;
741 }
742
743 release_sock(sk);
744 return err;
745}
746
fd0b3ff7
MH
747static int sco_sock_shutdown(struct socket *sock, int how)
748{
749 struct sock *sk = sock->sk;
750 int err = 0;
751
752 BT_DBG("sock %p, sk %p", sock, sk);
753
754 if (!sk)
755 return 0;
756
757 lock_sock(sk);
758 if (!sk->sk_shutdown) {
759 sk->sk_shutdown = SHUTDOWN_MASK;
760 sco_sock_clear_timer(sk);
761 __sco_sock_close(sk);
762
763 if (sock_flag(sk, SOCK_LINGER) && sk->sk_lingertime)
764 err = bt_sock_wait_state(sk, BT_CLOSED,
765 sk->sk_lingertime);
766 }
767 release_sock(sk);
768 return err;
769}
770
1da177e4
LT
771static int sco_sock_release(struct socket *sock)
772{
773 struct sock *sk = sock->sk;
774 int err = 0;
775
776 BT_DBG("sock %p, sk %p", sock, sk);
777
778 if (!sk)
779 return 0;
780
781 sco_sock_close(sk);
782
783 if (sock_flag(sk, SOCK_LINGER) && sk->sk_lingertime) {
784 lock_sock(sk);
785 err = bt_sock_wait_state(sk, BT_CLOSED, sk->sk_lingertime);
786 release_sock(sk);
787 }
788
789 sock_orphan(sk);
790 sco_sock_kill(sk);
791 return err;
792}
793
794static void __sco_chan_add(struct sco_conn *conn, struct sock *sk, struct sock *parent)
795{
796 BT_DBG("conn %p", conn);
797
798 sco_pi(sk)->conn = conn;
799 conn->sk = sk;
800
801 if (parent)
802 bt_accept_enqueue(parent, sk);
803}
804
8e87d142 805/* Delete channel.
1da177e4
LT
806 * Must be called on the locked socket. */
807static void sco_chan_del(struct sock *sk, int err)
808{
809 struct sco_conn *conn;
810
811 conn = sco_pi(sk)->conn;
812
813 BT_DBG("sk %p, conn %p, err %d", sk, conn, err);
814
8e87d142 815 if (conn) {
1da177e4
LT
816 sco_conn_lock(conn);
817 conn->sk = NULL;
818 sco_pi(sk)->conn = NULL;
819 sco_conn_unlock(conn);
820 hci_conn_put(conn->hcon);
821 }
822
823 sk->sk_state = BT_CLOSED;
824 sk->sk_err = err;
825 sk->sk_state_change(sk);
826
827 sock_set_flag(sk, SOCK_ZAPPED);
828}
829
830static void sco_conn_ready(struct sco_conn *conn)
831{
832 struct sock *parent, *sk;
833
834 BT_DBG("conn %p", conn);
835
836 sco_conn_lock(conn);
837
838 if ((sk = conn->sk)) {
839 sco_sock_clear_timer(sk);
840 bh_lock_sock(sk);
841 sk->sk_state = BT_CONNECTED;
842 sk->sk_state_change(sk);
843 bh_unlock_sock(sk);
844 } else {
845 parent = sco_get_sock_listen(conn->src);
846 if (!parent)
847 goto done;
848
849 bh_lock_sock(parent);
850
3b1e0a65 851 sk = sco_sock_alloc(sock_net(parent), NULL, BTPROTO_SCO, GFP_ATOMIC);
1da177e4
LT
852 if (!sk) {
853 bh_unlock_sock(parent);
854 goto done;
855 }
856
857 sco_sock_init(sk, parent);
858
859 bacpy(&bt_sk(sk)->src, conn->src);
860 bacpy(&bt_sk(sk)->dst, conn->dst);
861
862 hci_conn_hold(conn->hcon);
863 __sco_chan_add(conn, sk, parent);
864
865 sk->sk_state = BT_CONNECTED;
866
867 /* Wake up parent */
868 parent->sk_data_ready(parent, 1);
869
870 bh_unlock_sock(parent);
871 }
872
873done:
874 sco_conn_unlock(conn);
875}
876
877/* ----- SCO interface with lower layer (HCI) ----- */
878static int sco_connect_ind(struct hci_dev *hdev, bdaddr_t *bdaddr, __u8 type)
879{
71aeeaa1
MH
880 register struct sock *sk;
881 struct hlist_node *node;
882 int lm = 0;
883
884 if (type != SCO_LINK && type != ESCO_LINK)
885 return 0;
886
1da177e4
LT
887 BT_DBG("hdev %s, bdaddr %s", hdev->name, batostr(bdaddr));
888
71aeeaa1
MH
889 /* Find listening sockets */
890 read_lock(&sco_sk_list.lock);
891 sk_for_each(sk, node, &sco_sk_list.head) {
892 if (sk->sk_state != BT_LISTEN)
893 continue;
894
895 if (!bacmp(&bt_sk(sk)->src, &hdev->bdaddr) ||
896 !bacmp(&bt_sk(sk)->src, BDADDR_ANY)) {
897 lm |= HCI_LM_ACCEPT;
898 break;
899 }
900 }
901 read_unlock(&sco_sk_list.lock);
902
903 return lm;
1da177e4
LT
904}
905
906static int sco_connect_cfm(struct hci_conn *hcon, __u8 status)
907{
908 BT_DBG("hcon %p bdaddr %s status %d", hcon, batostr(&hcon->dst), status);
909
b6a0dc82 910 if (hcon->type != SCO_LINK && hcon->type != ESCO_LINK)
1da177e4
LT
911 return 0;
912
913 if (!status) {
914 struct sco_conn *conn;
915
916 conn = sco_conn_add(hcon, status);
917 if (conn)
918 sco_conn_ready(conn);
8e87d142 919 } else
1da177e4
LT
920 sco_conn_del(hcon, bt_err(status));
921
922 return 0;
923}
924
2950f21a 925static int sco_disconn_cfm(struct hci_conn *hcon, __u8 reason)
1da177e4
LT
926{
927 BT_DBG("hcon %p reason %d", hcon, reason);
928
b6a0dc82 929 if (hcon->type != SCO_LINK && hcon->type != ESCO_LINK)
1da177e4
LT
930 return 0;
931
932 sco_conn_del(hcon, bt_err(reason));
b6a0dc82 933
1da177e4
LT
934 return 0;
935}
936
937static int sco_recv_scodata(struct hci_conn *hcon, struct sk_buff *skb)
938{
939 struct sco_conn *conn = hcon->sco_data;
940
941 if (!conn)
942 goto drop;
943
944 BT_DBG("conn %p len %d", conn, skb->len);
945
946 if (skb->len) {
947 sco_recv_frame(conn, skb);
948 return 0;
949 }
950
951drop:
8e87d142 952 kfree_skb(skb);
1da177e4
LT
953 return 0;
954}
955
28812fe1
AK
956static ssize_t sco_sysfs_show(struct class *dev,
957 struct class_attribute *attr,
958 char *buf)
1da177e4
LT
959{
960 struct sock *sk;
961 struct hlist_node *node;
be9d1227 962 char *str = buf;
101545f6 963 int size = PAGE_SIZE;
1da177e4
LT
964
965 read_lock_bh(&sco_sk_list.lock);
966
be9d1227 967 sk_for_each(sk, node, &sco_sk_list.head) {
101545f6
MH
968 int len;
969
970 len = snprintf(str, size, "%s %s %d\n",
be9d1227
MH
971 batostr(&bt_sk(sk)->src), batostr(&bt_sk(sk)->dst),
972 sk->sk_state);
101545f6
MH
973
974 size -= len;
975 if (size <= 0)
976 break;
977
978 str += len;
be9d1227 979 }
1da177e4 980
1da177e4 981 read_unlock_bh(&sco_sk_list.lock);
1da177e4 982
be9d1227 983 return (str - buf);
1da177e4
LT
984}
985
be9d1227 986static CLASS_ATTR(sco, S_IRUGO, sco_sysfs_show, NULL);
1da177e4 987
90ddc4f0 988static const struct proto_ops sco_sock_ops = {
1da177e4
LT
989 .family = PF_BLUETOOTH,
990 .owner = THIS_MODULE,
991 .release = sco_sock_release,
992 .bind = sco_sock_bind,
993 .connect = sco_sock_connect,
994 .listen = sco_sock_listen,
995 .accept = sco_sock_accept,
996 .getname = sco_sock_getname,
997 .sendmsg = sco_sock_sendmsg,
998 .recvmsg = bt_sock_recvmsg,
999 .poll = bt_sock_poll,
3241ad82 1000 .ioctl = bt_sock_ioctl,
1da177e4
LT
1001 .mmap = sock_no_mmap,
1002 .socketpair = sock_no_socketpair,
fd0b3ff7 1003 .shutdown = sco_sock_shutdown,
1da177e4
LT
1004 .setsockopt = sco_sock_setsockopt,
1005 .getsockopt = sco_sock_getsockopt
1006};
1007
ec1b4cf7 1008static const struct net_proto_family sco_sock_family_ops = {
1da177e4
LT
1009 .family = PF_BLUETOOTH,
1010 .owner = THIS_MODULE,
1011 .create = sco_sock_create,
1012};
1013
1014static struct hci_proto sco_hci_proto = {
1015 .name = "SCO",
1016 .id = HCI_PROTO_SCO,
1017 .connect_ind = sco_connect_ind,
1018 .connect_cfm = sco_connect_cfm,
2950f21a 1019 .disconn_cfm = sco_disconn_cfm,
1da177e4
LT
1020 .recv_scodata = sco_recv_scodata
1021};
1022
1023static int __init sco_init(void)
1024{
1025 int err;
1026
1027 err = proto_register(&sco_proto, 0);
1028 if (err < 0)
1029 return err;
1030
1031 err = bt_sock_register(BTPROTO_SCO, &sco_sock_family_ops);
1032 if (err < 0) {
1033 BT_ERR("SCO socket registration failed");
1034 goto error;
1035 }
1036
1037 err = hci_register_proto(&sco_hci_proto);
1038 if (err < 0) {
1039 BT_ERR("SCO protocol registration failed");
1040 bt_sock_unregister(BTPROTO_SCO);
1041 goto error;
1042 }
1043
df5c37ea
MH
1044 if (class_create_file(bt_class, &class_attr_sco) < 0)
1045 BT_ERR("Failed to create SCO info file");
1da177e4
LT
1046
1047 BT_INFO("SCO (Voice Link) ver %s", VERSION);
1048 BT_INFO("SCO socket layer initialized");
1049
1050 return 0;
1051
1052error:
1053 proto_unregister(&sco_proto);
1054 return err;
1055}
1056
1057static void __exit sco_exit(void)
1058{
a91f2e39 1059 class_remove_file(bt_class, &class_attr_sco);
1da177e4
LT
1060
1061 if (bt_sock_unregister(BTPROTO_SCO) < 0)
1062 BT_ERR("SCO socket unregistration failed");
1063
1064 if (hci_unregister_proto(&sco_hci_proto) < 0)
1065 BT_ERR("SCO protocol unregistration failed");
1066
1067 proto_unregister(&sco_proto);
1068}
1069
1070module_init(sco_init);
1071module_exit(sco_exit);
1072
7cb127d5
MH
1073module_param(disable_esco, bool, 0644);
1074MODULE_PARM_DESC(disable_esco, "Disable eSCO connection creation");
1075
63fbd24e 1076MODULE_AUTHOR("Marcel Holtmann <marcel@holtmann.org>");
1da177e4
LT
1077MODULE_DESCRIPTION("Bluetooth SCO ver " VERSION);
1078MODULE_VERSION(VERSION);
1079MODULE_LICENSE("GPL");
1080MODULE_ALIAS("bt-proto-2");