Bluetooth: Split error handling for L2CAP listen sockets
[GitHub/mt8127/android_kernel_alcatel_ttab.git] / net / bluetooth / sco.c
CommitLineData
8e87d142 1/*
1da177e4
LT
2 BlueZ - Bluetooth protocol stack for Linux
3 Copyright (C) 2000-2001 Qualcomm Incorporated
4
5 Written 2000,2001 by Maxim Krasnyansky <maxk@qualcomm.com>
6
7 This program is free software; you can redistribute it and/or modify
8 it under the terms of the GNU General Public License version 2 as
9 published by the Free Software Foundation;
10
11 THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS
12 OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
13 FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT OF THIRD PARTY RIGHTS.
14 IN NO EVENT SHALL THE COPYRIGHT HOLDER(S) AND AUTHOR(S) BE LIABLE FOR ANY
8e87d142
YH
15 CLAIM, OR ANY SPECIAL INDIRECT OR CONSEQUENTIAL DAMAGES, OR ANY DAMAGES
16 WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
17 ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
1da177e4
LT
18 OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
19
8e87d142
YH
20 ALL LIABILITY, INCLUDING LIABILITY FOR INFRINGEMENT OF ANY PATENTS,
21 COPYRIGHTS, TRADEMARKS OR OTHER RIGHTS, RELATING TO USE OF THIS
1da177e4
LT
22 SOFTWARE IS DISCLAIMED.
23*/
24
25/* Bluetooth SCO sockets. */
26
1da177e4
LT
27#include <linux/module.h>
28
29#include <linux/types.h>
30#include <linux/errno.h>
31#include <linux/kernel.h>
1da177e4
LT
32#include <linux/sched.h>
33#include <linux/slab.h>
34#include <linux/poll.h>
35#include <linux/fcntl.h>
36#include <linux/init.h>
37#include <linux/interrupt.h>
38#include <linux/socket.h>
39#include <linux/skbuff.h>
be9d1227 40#include <linux/device.h>
aef7d97c
MH
41#include <linux/debugfs.h>
42#include <linux/seq_file.h>
1da177e4 43#include <linux/list.h>
6230c9b4 44#include <linux/security.h>
1da177e4
LT
45#include <net/sock.h>
46
735cbc47 47#include <linux/uaccess.h>
1da177e4
LT
48
49#include <net/bluetooth/bluetooth.h>
50#include <net/bluetooth/hci_core.h>
51#include <net/bluetooth/sco.h>
52
eb939922 53static bool disable_esco;
1da177e4 54
90ddc4f0 55static const struct proto_ops sco_sock_ops;
1da177e4
LT
56
57static struct bt_sock_list sco_sk_list = {
d5fb2962 58 .lock = __RW_LOCK_UNLOCKED(sco_sk_list.lock)
1da177e4
LT
59};
60
61static void __sco_chan_add(struct sco_conn *conn, struct sock *sk, struct sock *parent);
62static void sco_chan_del(struct sock *sk, int err);
63
1da177e4
LT
64static void sco_sock_close(struct sock *sk);
65static void sco_sock_kill(struct sock *sk);
66
67/* ---- SCO timers ---- */
68static void sco_sock_timeout(unsigned long arg)
69{
70 struct sock *sk = (struct sock *) arg;
71
72 BT_DBG("sock %p state %d", sk, sk->sk_state);
73
74 bh_lock_sock(sk);
75 sk->sk_err = ETIMEDOUT;
76 sk->sk_state_change(sk);
77 bh_unlock_sock(sk);
78
79 sco_sock_kill(sk);
80 sock_put(sk);
81}
82
83static void sco_sock_set_timer(struct sock *sk, long timeout)
84{
85 BT_DBG("sock %p state %d timeout %ld", sk, sk->sk_state, timeout);
86 sk_reset_timer(sk, &sk->sk_timer, jiffies + timeout);
87}
88
89static void sco_sock_clear_timer(struct sock *sk)
90{
91 BT_DBG("sock %p state %d", sk, sk->sk_state);
92 sk_stop_timer(sk, &sk->sk_timer);
93}
94
1da177e4
LT
95/* ---- SCO connections ---- */
96static struct sco_conn *sco_conn_add(struct hci_conn *hcon, __u8 status)
97{
98 struct hci_dev *hdev = hcon->hdev;
25ea6db0 99 struct sco_conn *conn = hcon->sco_data;
1da177e4 100
25ea6db0 101 if (conn || status)
1da177e4
LT
102 return conn;
103
25ea6db0
MH
104 conn = kzalloc(sizeof(struct sco_conn), GFP_ATOMIC);
105 if (!conn)
1da177e4 106 return NULL;
1da177e4
LT
107
108 spin_lock_init(&conn->lock);
109
110 hcon->sco_data = conn;
111 conn->hcon = hcon;
112
113 conn->src = &hdev->bdaddr;
114 conn->dst = &hcon->dst;
115
116 if (hdev->sco_mtu > 0)
117 conn->mtu = hdev->sco_mtu;
118 else
119 conn->mtu = 60;
120
121 BT_DBG("hcon %p conn %p", hcon, conn);
25ea6db0 122
1da177e4
LT
123 return conn;
124}
125
126static inline struct sock *sco_chan_get(struct sco_conn *conn)
127{
128 struct sock *sk = NULL;
129 sco_conn_lock(conn);
130 sk = conn->sk;
131 sco_conn_unlock(conn);
132 return sk;
133}
134
135static int sco_conn_del(struct hci_conn *hcon, int err)
136{
735cbc47 137 struct sco_conn *conn = hcon->sco_data;
1da177e4
LT
138 struct sock *sk;
139
735cbc47 140 if (!conn)
1da177e4
LT
141 return 0;
142
143 BT_DBG("hcon %p conn %p, err %d", hcon, conn, err);
144
145 /* Kill socket */
735cbc47
AE
146 sk = sco_chan_get(conn);
147 if (sk) {
1da177e4
LT
148 bh_lock_sock(sk);
149 sco_sock_clear_timer(sk);
150 sco_chan_del(sk, err);
151 bh_unlock_sock(sk);
152 sco_sock_kill(sk);
153 }
154
155 hcon->sco_data = NULL;
156 kfree(conn);
157 return 0;
158}
159
160static inline int sco_chan_add(struct sco_conn *conn, struct sock *sk, struct sock *parent)
161{
162 int err = 0;
163
164 sco_conn_lock(conn);
b9dbdbc1 165 if (conn->sk)
1da177e4 166 err = -EBUSY;
b9dbdbc1 167 else
1da177e4 168 __sco_chan_add(conn, sk, parent);
b9dbdbc1 169
1da177e4
LT
170 sco_conn_unlock(conn);
171 return err;
172}
173
174static int sco_connect(struct sock *sk)
175{
176 bdaddr_t *src = &bt_sk(sk)->src;
177 bdaddr_t *dst = &bt_sk(sk)->dst;
178 struct sco_conn *conn;
179 struct hci_conn *hcon;
180 struct hci_dev *hdev;
b6a0dc82 181 int err, type;
1da177e4
LT
182
183 BT_DBG("%s -> %s", batostr(src), batostr(dst));
184
735cbc47
AE
185 hdev = hci_get_route(dst, src);
186 if (!hdev)
1da177e4
LT
187 return -EHOSTUNREACH;
188
09fd0de5 189 hci_dev_lock(hdev);
1da177e4 190
7cb127d5
MH
191 if (lmp_esco_capable(hdev) && !disable_esco)
192 type = ESCO_LINK;
193 else
194 type = SCO_LINK;
b6a0dc82 195
8c1b2355 196 hcon = hci_connect(hdev, type, dst, BT_SECURITY_LOW, HCI_AT_NO_BONDING);
30e76272
VT
197 if (IS_ERR(hcon)) {
198 err = PTR_ERR(hcon);
1da177e4 199 goto done;
30e76272 200 }
1da177e4
LT
201
202 conn = sco_conn_add(hcon, 0);
203 if (!conn) {
204 hci_conn_put(hcon);
30e76272 205 err = -ENOMEM;
1da177e4
LT
206 goto done;
207 }
208
209 /* Update source addr of the socket */
210 bacpy(src, conn->src);
211
212 err = sco_chan_add(conn, sk, NULL);
213 if (err)
214 goto done;
215
216 if (hcon->state == BT_CONNECTED) {
217 sco_sock_clear_timer(sk);
218 sk->sk_state = BT_CONNECTED;
219 } else {
220 sk->sk_state = BT_CONNECT;
221 sco_sock_set_timer(sk, sk->sk_sndtimeo);
222 }
b6a0dc82 223
1da177e4 224done:
09fd0de5 225 hci_dev_unlock(hdev);
1da177e4
LT
226 hci_dev_put(hdev);
227 return err;
228}
229
230static inline int sco_send_frame(struct sock *sk, struct msghdr *msg, int len)
231{
232 struct sco_conn *conn = sco_pi(sk)->conn;
233 struct sk_buff *skb;
088ce088 234 int err;
1da177e4
LT
235
236 /* Check outgoing MTU */
237 if (len > conn->mtu)
238 return -EINVAL;
239
240 BT_DBG("sk %p len %d", sk, len);
241
088ce088 242 skb = bt_skb_send_alloc(sk, len, msg->msg_flags & MSG_DONTWAIT, &err);
b9dbdbc1 243 if (!skb)
1da177e4
LT
244 return err;
245
088ce088 246 if (memcpy_fromiovec(skb_put(skb, len), msg->msg_iov, len)) {
b9dbdbc1
GP
247 kfree_skb(skb);
248 return -EFAULT;
1da177e4
LT
249 }
250
0d861d8b 251 hci_send_sco(conn->hcon, skb);
1da177e4 252
088ce088 253 return len;
1da177e4
LT
254}
255
256static inline void sco_recv_frame(struct sco_conn *conn, struct sk_buff *skb)
257{
258 struct sock *sk = sco_chan_get(conn);
259
260 if (!sk)
261 goto drop;
262
263 BT_DBG("sk %p len %d", sk, skb->len);
264
265 if (sk->sk_state != BT_CONNECTED)
266 goto drop;
267
268 if (!sock_queue_rcv_skb(sk, skb))
269 return;
270
271drop:
272 kfree_skb(skb);
1da177e4
LT
273}
274
275/* -------- Socket interface ---------- */
276static struct sock *__sco_get_sock_by_addr(bdaddr_t *ba)
277{
278 struct sock *sk;
279 struct hlist_node *node;
280
281 sk_for_each(sk, node, &sco_sk_list.head)
282 if (!bacmp(&bt_sk(sk)->src, ba))
283 goto found;
284 sk = NULL;
285found:
286 return sk;
287}
288
289/* Find socket listening on source bdaddr.
290 * Returns closest match.
291 */
292static struct sock *sco_get_sock_listen(bdaddr_t *src)
293{
294 struct sock *sk = NULL, *sk1 = NULL;
295 struct hlist_node *node;
296
297 read_lock(&sco_sk_list.lock);
298
299 sk_for_each(sk, node, &sco_sk_list.head) {
300 if (sk->sk_state != BT_LISTEN)
301 continue;
302
303 /* Exact match. */
304 if (!bacmp(&bt_sk(sk)->src, src))
305 break;
306
307 /* Closest match */
308 if (!bacmp(&bt_sk(sk)->src, BDADDR_ANY))
309 sk1 = sk;
310 }
311
312 read_unlock(&sco_sk_list.lock);
313
314 return node ? sk : sk1;
315}
316
317static void sco_sock_destruct(struct sock *sk)
318{
319 BT_DBG("sk %p", sk);
320
321 skb_queue_purge(&sk->sk_receive_queue);
322 skb_queue_purge(&sk->sk_write_queue);
323}
324
325static void sco_sock_cleanup_listen(struct sock *parent)
326{
327 struct sock *sk;
328
329 BT_DBG("parent %p", parent);
330
331 /* Close not yet accepted channels */
332 while ((sk = bt_accept_dequeue(parent, NULL))) {
333 sco_sock_close(sk);
334 sco_sock_kill(sk);
335 }
336
337 parent->sk_state = BT_CLOSED;
338 sock_set_flag(parent, SOCK_ZAPPED);
339}
340
341/* Kill socket (only if zapped and orphan)
342 * Must be called on unlocked socket.
343 */
344static void sco_sock_kill(struct sock *sk)
345{
346 if (!sock_flag(sk, SOCK_ZAPPED) || sk->sk_socket)
347 return;
348
349 BT_DBG("sk %p state %d", sk, sk->sk_state);
350
351 /* Kill poor orphan */
352 bt_sock_unlink(&sco_sk_list, sk);
353 sock_set_flag(sk, SOCK_DEAD);
354 sock_put(sk);
355}
356
fd0b3ff7 357static void __sco_sock_close(struct sock *sk)
1da177e4 358{
fd0b3ff7 359 BT_DBG("sk %p state %d socket %p", sk, sk->sk_state, sk->sk_socket);
1da177e4
LT
360
361 switch (sk->sk_state) {
362 case BT_LISTEN:
363 sco_sock_cleanup_listen(sk);
364 break;
365
366 case BT_CONNECTED:
367 case BT_CONFIG:
4a77708b
LAD
368 if (sco_pi(sk)->conn) {
369 sk->sk_state = BT_DISCONN;
370 sco_sock_set_timer(sk, SCO_DISCONN_TIMEOUT);
371 hci_conn_put(sco_pi(sk)->conn->hcon);
372 sco_pi(sk)->conn->hcon = NULL;
373 } else
374 sco_chan_del(sk, ECONNRESET);
375 break;
376
1da177e4
LT
377 case BT_CONNECT:
378 case BT_DISCONN:
379 sco_chan_del(sk, ECONNRESET);
380 break;
381
382 default:
383 sock_set_flag(sk, SOCK_ZAPPED);
384 break;
3ff50b79 385 }
fd0b3ff7 386}
1da177e4 387
fd0b3ff7
MH
388/* Must be called on unlocked socket. */
389static void sco_sock_close(struct sock *sk)
390{
391 sco_sock_clear_timer(sk);
392 lock_sock(sk);
393 __sco_sock_close(sk);
1da177e4 394 release_sock(sk);
1da177e4
LT
395 sco_sock_kill(sk);
396}
397
398static void sco_sock_init(struct sock *sk, struct sock *parent)
399{
400 BT_DBG("sk %p", sk);
401
6230c9b4 402 if (parent) {
1da177e4 403 sk->sk_type = parent->sk_type;
6230c9b4
PM
404 security_sk_clone(parent, sk);
405 }
1da177e4
LT
406}
407
408static struct proto sco_proto = {
409 .name = "SCO",
410 .owner = THIS_MODULE,
411 .obj_size = sizeof(struct sco_pinfo)
412};
413
1b8d7ae4 414static struct sock *sco_sock_alloc(struct net *net, struct socket *sock, int proto, gfp_t prio)
1da177e4
LT
415{
416 struct sock *sk;
417
6257ff21 418 sk = sk_alloc(net, PF_BLUETOOTH, prio, &sco_proto);
1da177e4
LT
419 if (!sk)
420 return NULL;
421
422 sock_init_data(sock, sk);
423 INIT_LIST_HEAD(&bt_sk(sk)->accept_q);
424
425 sk->sk_destruct = sco_sock_destruct;
426 sk->sk_sndtimeo = SCO_CONN_TIMEOUT;
427
428 sock_reset_flag(sk, SOCK_ZAPPED);
429
430 sk->sk_protocol = proto;
431 sk->sk_state = BT_OPEN;
432
b24b8a24 433 setup_timer(&sk->sk_timer, sco_sock_timeout, (unsigned long)sk);
1da177e4
LT
434
435 bt_sock_link(&sco_sk_list, sk);
436 return sk;
437}
438
3f378b68
EP
439static int sco_sock_create(struct net *net, struct socket *sock, int protocol,
440 int kern)
1da177e4
LT
441{
442 struct sock *sk;
443
444 BT_DBG("sock %p", sock);
445
446 sock->state = SS_UNCONNECTED;
447
448 if (sock->type != SOCK_SEQPACKET)
449 return -ESOCKTNOSUPPORT;
450
451 sock->ops = &sco_sock_ops;
452
1b8d7ae4 453 sk = sco_sock_alloc(net, sock, protocol, GFP_ATOMIC);
74da626a 454 if (!sk)
1da177e4
LT
455 return -ENOMEM;
456
457 sco_sock_init(sk, NULL);
458 return 0;
459}
460
461static int sco_sock_bind(struct socket *sock, struct sockaddr *addr, int addr_len)
462{
463 struct sockaddr_sco *sa = (struct sockaddr_sco *) addr;
464 struct sock *sk = sock->sk;
465 bdaddr_t *src = &sa->sco_bdaddr;
466 int err = 0;
467
468 BT_DBG("sk %p %s", sk, batostr(&sa->sco_bdaddr));
469
470 if (!addr || addr->sa_family != AF_BLUETOOTH)
471 return -EINVAL;
472
473 lock_sock(sk);
474
475 if (sk->sk_state != BT_OPEN) {
476 err = -EBADFD;
477 goto done;
478 }
479
ee65d19e 480 write_lock(&sco_sk_list.lock);
1da177e4
LT
481
482 if (bacmp(src, BDADDR_ANY) && __sco_get_sock_by_addr(src)) {
483 err = -EADDRINUSE;
484 } else {
485 /* Save source address */
486 bacpy(&bt_sk(sk)->src, &sa->sco_bdaddr);
487 sk->sk_state = BT_BOUND;
488 }
489
ee65d19e 490 write_unlock(&sco_sk_list.lock);
1da177e4
LT
491
492done:
493 release_sock(sk);
494 return err;
495}
496
497static int sco_sock_connect(struct socket *sock, struct sockaddr *addr, int alen, int flags)
498{
499 struct sockaddr_sco *sa = (struct sockaddr_sco *) addr;
500 struct sock *sk = sock->sk;
501 int err = 0;
502
503
504 BT_DBG("sk %p", sk);
505
6503d961
CG
506 if (alen < sizeof(struct sockaddr_sco) ||
507 addr->sa_family != AF_BLUETOOTH)
1da177e4
LT
508 return -EINVAL;
509
510 if (sk->sk_state != BT_OPEN && sk->sk_state != BT_BOUND)
511 return -EBADFD;
512
513 if (sk->sk_type != SOCK_SEQPACKET)
514 return -EINVAL;
515
516 lock_sock(sk);
517
518 /* Set destination address and psm */
519 bacpy(&bt_sk(sk)->dst, &sa->sco_bdaddr);
520
735cbc47
AE
521 err = sco_connect(sk);
522 if (err)
1da177e4
LT
523 goto done;
524
8e87d142 525 err = bt_sock_wait_state(sk, BT_CONNECTED,
1da177e4
LT
526 sock_sndtimeo(sk, flags & O_NONBLOCK));
527
528done:
529 release_sock(sk);
530 return err;
531}
532
533static int sco_sock_listen(struct socket *sock, int backlog)
534{
535 struct sock *sk = sock->sk;
536 int err = 0;
537
538 BT_DBG("sk %p backlog %d", sk, backlog);
539
540 lock_sock(sk);
541
542 if (sk->sk_state != BT_BOUND || sock->type != SOCK_SEQPACKET) {
543 err = -EBADFD;
544 goto done;
545 }
546
547 sk->sk_max_ack_backlog = backlog;
548 sk->sk_ack_backlog = 0;
549 sk->sk_state = BT_LISTEN;
550
551done:
552 release_sock(sk);
553 return err;
554}
555
556static int sco_sock_accept(struct socket *sock, struct socket *newsock, int flags)
557{
558 DECLARE_WAITQUEUE(wait, current);
559 struct sock *sk = sock->sk, *ch;
560 long timeo;
561 int err = 0;
562
563 lock_sock(sk);
564
1da177e4
LT
565 timeo = sock_rcvtimeo(sk, flags & O_NONBLOCK);
566
567 BT_DBG("sk %p timeo %ld", sk, timeo);
568
569 /* Wait for an incoming connection. (wake-one). */
aa395145 570 add_wait_queue_exclusive(sk_sleep(sk), &wait);
552b0d3c 571 while (1) {
1da177e4 572 set_current_state(TASK_INTERRUPTIBLE);
552b0d3c
PH
573
574 if (sk->sk_state != BT_LISTEN) {
575 err = -EBADFD;
1da177e4
LT
576 break;
577 }
578
552b0d3c
PH
579 ch = bt_accept_dequeue(sk, newsock);
580 if (ch)
581 break;
1da177e4 582
552b0d3c
PH
583 if (!timeo) {
584 err = -EAGAIN;
1da177e4
LT
585 break;
586 }
587
588 if (signal_pending(current)) {
589 err = sock_intr_errno(timeo);
590 break;
591 }
552b0d3c
PH
592
593 release_sock(sk);
594 timeo = schedule_timeout(timeo);
595 lock_sock(sk);
1da177e4 596 }
552b0d3c 597 __set_current_state(TASK_RUNNING);
aa395145 598 remove_wait_queue(sk_sleep(sk), &wait);
1da177e4
LT
599
600 if (err)
601 goto done;
602
603 newsock->state = SS_CONNECTED;
604
605 BT_DBG("new socket %p", ch);
606
607done:
608 release_sock(sk);
609 return err;
610}
611
612static int sco_sock_getname(struct socket *sock, struct sockaddr *addr, int *len, int peer)
613{
614 struct sockaddr_sco *sa = (struct sockaddr_sco *) addr;
615 struct sock *sk = sock->sk;
616
617 BT_DBG("sock %p, sk %p", sock, sk);
618
619 addr->sa_family = AF_BLUETOOTH;
620 *len = sizeof(struct sockaddr_sco);
621
622 if (peer)
623 bacpy(&sa->sco_bdaddr, &bt_sk(sk)->dst);
624 else
625 bacpy(&sa->sco_bdaddr, &bt_sk(sk)->src);
626
627 return 0;
628}
629
8e87d142 630static int sco_sock_sendmsg(struct kiocb *iocb, struct socket *sock,
1da177e4
LT
631 struct msghdr *msg, size_t len)
632{
633 struct sock *sk = sock->sk;
b9dbdbc1 634 int err;
1da177e4
LT
635
636 BT_DBG("sock %p, sk %p", sock, sk);
637
c1cbe4b7
BL
638 err = sock_error(sk);
639 if (err)
640 return err;
1da177e4
LT
641
642 if (msg->msg_flags & MSG_OOB)
643 return -EOPNOTSUPP;
644
645 lock_sock(sk);
646
647 if (sk->sk_state == BT_CONNECTED)
648 err = sco_send_frame(sk, msg, len);
649 else
650 err = -ENOTCONN;
651
652 release_sock(sk);
653 return err;
654}
655
b7058842 656static int sco_sock_setsockopt(struct socket *sock, int level, int optname, char __user *optval, unsigned int optlen)
1da177e4
LT
657{
658 struct sock *sk = sock->sk;
659 int err = 0;
660
661 BT_DBG("sk %p", sk);
662
663 lock_sock(sk);
664
665 switch (optname) {
666 default:
667 err = -ENOPROTOOPT;
668 break;
669 }
670
671 release_sock(sk);
672 return err;
673}
674
d58daf42 675static int sco_sock_getsockopt_old(struct socket *sock, int optname, char __user *optval, int __user *optlen)
1da177e4
LT
676{
677 struct sock *sk = sock->sk;
678 struct sco_options opts;
679 struct sco_conninfo cinfo;
8e87d142 680 int len, err = 0;
1da177e4
LT
681
682 BT_DBG("sk %p", sk);
683
684 if (get_user(len, optlen))
685 return -EFAULT;
686
687 lock_sock(sk);
688
689 switch (optname) {
690 case SCO_OPTIONS:
691 if (sk->sk_state != BT_CONNECTED) {
692 err = -ENOTCONN;
693 break;
694 }
695
696 opts.mtu = sco_pi(sk)->conn->mtu;
697
698 BT_DBG("mtu %d", opts.mtu);
699
700 len = min_t(unsigned int, len, sizeof(opts));
701 if (copy_to_user(optval, (char *)&opts, len))
702 err = -EFAULT;
703
704 break;
705
706 case SCO_CONNINFO:
707 if (sk->sk_state != BT_CONNECTED) {
708 err = -ENOTCONN;
709 break;
710 }
711
c4c896e1 712 memset(&cinfo, 0, sizeof(cinfo));
1da177e4
LT
713 cinfo.hci_handle = sco_pi(sk)->conn->hcon->handle;
714 memcpy(cinfo.dev_class, sco_pi(sk)->conn->hcon->dev_class, 3);
715
716 len = min_t(unsigned int, len, sizeof(cinfo));
717 if (copy_to_user(optval, (char *)&cinfo, len))
718 err = -EFAULT;
719
720 break;
721
722 default:
723 err = -ENOPROTOOPT;
724 break;
725 }
726
727 release_sock(sk);
728 return err;
729}
730
d58daf42
MH
731static int sco_sock_getsockopt(struct socket *sock, int level, int optname, char __user *optval, int __user *optlen)
732{
733 struct sock *sk = sock->sk;
734 int len, err = 0;
735
736 BT_DBG("sk %p", sk);
737
738 if (level == SOL_SCO)
739 return sco_sock_getsockopt_old(sock, optname, optval, optlen);
740
741 if (get_user(len, optlen))
742 return -EFAULT;
743
744 lock_sock(sk);
745
746 switch (optname) {
747 default:
748 err = -ENOPROTOOPT;
749 break;
750 }
751
752 release_sock(sk);
753 return err;
754}
755
fd0b3ff7
MH
756static int sco_sock_shutdown(struct socket *sock, int how)
757{
758 struct sock *sk = sock->sk;
759 int err = 0;
760
761 BT_DBG("sock %p, sk %p", sock, sk);
762
763 if (!sk)
764 return 0;
765
766 lock_sock(sk);
767 if (!sk->sk_shutdown) {
768 sk->sk_shutdown = SHUTDOWN_MASK;
769 sco_sock_clear_timer(sk);
770 __sco_sock_close(sk);
771
772 if (sock_flag(sk, SOCK_LINGER) && sk->sk_lingertime)
773 err = bt_sock_wait_state(sk, BT_CLOSED,
774 sk->sk_lingertime);
775 }
776 release_sock(sk);
777 return err;
778}
779
1da177e4
LT
780static int sco_sock_release(struct socket *sock)
781{
782 struct sock *sk = sock->sk;
783 int err = 0;
784
785 BT_DBG("sock %p, sk %p", sock, sk);
786
787 if (!sk)
788 return 0;
789
790 sco_sock_close(sk);
791
792 if (sock_flag(sk, SOCK_LINGER) && sk->sk_lingertime) {
793 lock_sock(sk);
794 err = bt_sock_wait_state(sk, BT_CLOSED, sk->sk_lingertime);
795 release_sock(sk);
796 }
797
798 sock_orphan(sk);
799 sco_sock_kill(sk);
800 return err;
801}
802
803static void __sco_chan_add(struct sco_conn *conn, struct sock *sk, struct sock *parent)
804{
805 BT_DBG("conn %p", conn);
806
807 sco_pi(sk)->conn = conn;
808 conn->sk = sk;
809
810 if (parent)
811 bt_accept_enqueue(parent, sk);
812}
813
8e87d142 814/* Delete channel.
1da177e4
LT
815 * Must be called on the locked socket. */
816static void sco_chan_del(struct sock *sk, int err)
817{
818 struct sco_conn *conn;
819
820 conn = sco_pi(sk)->conn;
821
822 BT_DBG("sk %p, conn %p, err %d", sk, conn, err);
823
8e87d142 824 if (conn) {
1da177e4
LT
825 sco_conn_lock(conn);
826 conn->sk = NULL;
827 sco_pi(sk)->conn = NULL;
828 sco_conn_unlock(conn);
4a77708b
LAD
829
830 if (conn->hcon)
831 hci_conn_put(conn->hcon);
1da177e4
LT
832 }
833
834 sk->sk_state = BT_CLOSED;
835 sk->sk_err = err;
836 sk->sk_state_change(sk);
837
838 sock_set_flag(sk, SOCK_ZAPPED);
839}
840
841static void sco_conn_ready(struct sco_conn *conn)
842{
735cbc47
AE
843 struct sock *parent;
844 struct sock *sk = conn->sk;
1da177e4
LT
845
846 BT_DBG("conn %p", conn);
847
848 sco_conn_lock(conn);
849
735cbc47 850 if (sk) {
1da177e4
LT
851 sco_sock_clear_timer(sk);
852 bh_lock_sock(sk);
853 sk->sk_state = BT_CONNECTED;
854 sk->sk_state_change(sk);
855 bh_unlock_sock(sk);
856 } else {
857 parent = sco_get_sock_listen(conn->src);
858 if (!parent)
859 goto done;
860
861 bh_lock_sock(parent);
862
b9dbdbc1
GP
863 sk = sco_sock_alloc(sock_net(parent), NULL,
864 BTPROTO_SCO, GFP_ATOMIC);
1da177e4
LT
865 if (!sk) {
866 bh_unlock_sock(parent);
867 goto done;
868 }
869
870 sco_sock_init(sk, parent);
871
872 bacpy(&bt_sk(sk)->src, conn->src);
873 bacpy(&bt_sk(sk)->dst, conn->dst);
874
875 hci_conn_hold(conn->hcon);
876 __sco_chan_add(conn, sk, parent);
877
878 sk->sk_state = BT_CONNECTED;
879
880 /* Wake up parent */
881 parent->sk_data_ready(parent, 1);
882
883 bh_unlock_sock(parent);
884 }
885
886done:
887 sco_conn_unlock(conn);
888}
889
890/* ----- SCO interface with lower layer (HCI) ----- */
686ebf28 891int sco_connect_ind(struct hci_dev *hdev, bdaddr_t *bdaddr)
1da177e4 892{
71aeeaa1
MH
893 register struct sock *sk;
894 struct hlist_node *node;
895 int lm = 0;
896
1da177e4
LT
897 BT_DBG("hdev %s, bdaddr %s", hdev->name, batostr(bdaddr));
898
71aeeaa1
MH
899 /* Find listening sockets */
900 read_lock(&sco_sk_list.lock);
901 sk_for_each(sk, node, &sco_sk_list.head) {
902 if (sk->sk_state != BT_LISTEN)
903 continue;
904
905 if (!bacmp(&bt_sk(sk)->src, &hdev->bdaddr) ||
906 !bacmp(&bt_sk(sk)->src, BDADDR_ANY)) {
907 lm |= HCI_LM_ACCEPT;
908 break;
909 }
910 }
911 read_unlock(&sco_sk_list.lock);
912
913 return lm;
1da177e4
LT
914}
915
686ebf28 916int sco_connect_cfm(struct hci_conn *hcon, __u8 status)
1da177e4
LT
917{
918 BT_DBG("hcon %p bdaddr %s status %d", hcon, batostr(&hcon->dst), status);
1da177e4
LT
919 if (!status) {
920 struct sco_conn *conn;
921
922 conn = sco_conn_add(hcon, status);
923 if (conn)
924 sco_conn_ready(conn);
8e87d142 925 } else
e175072f 926 sco_conn_del(hcon, bt_to_errno(status));
1da177e4
LT
927
928 return 0;
929}
930
686ebf28 931int sco_disconn_cfm(struct hci_conn *hcon, __u8 reason)
1da177e4
LT
932{
933 BT_DBG("hcon %p reason %d", hcon, reason);
934
e175072f 935 sco_conn_del(hcon, bt_to_errno(reason));
1da177e4
LT
936 return 0;
937}
938
686ebf28 939int sco_recv_scodata(struct hci_conn *hcon, struct sk_buff *skb)
1da177e4
LT
940{
941 struct sco_conn *conn = hcon->sco_data;
942
943 if (!conn)
944 goto drop;
945
946 BT_DBG("conn %p len %d", conn, skb->len);
947
948 if (skb->len) {
949 sco_recv_frame(conn, skb);
950 return 0;
951 }
952
953drop:
8e87d142 954 kfree_skb(skb);
1da177e4
LT
955 return 0;
956}
957
aef7d97c 958static int sco_debugfs_show(struct seq_file *f, void *p)
1da177e4
LT
959{
960 struct sock *sk;
961 struct hlist_node *node;
1da177e4 962
ee65d19e 963 read_lock(&sco_sk_list.lock);
1da177e4 964
be9d1227 965 sk_for_each(sk, node, &sco_sk_list.head) {
aef7d97c
MH
966 seq_printf(f, "%s %s %d\n", batostr(&bt_sk(sk)->src),
967 batostr(&bt_sk(sk)->dst), sk->sk_state);
be9d1227 968 }
1da177e4 969
ee65d19e 970 read_unlock(&sco_sk_list.lock);
1da177e4 971
aef7d97c 972 return 0;
1da177e4
LT
973}
974
aef7d97c
MH
975static int sco_debugfs_open(struct inode *inode, struct file *file)
976{
977 return single_open(file, sco_debugfs_show, inode->i_private);
978}
979
980static const struct file_operations sco_debugfs_fops = {
981 .open = sco_debugfs_open,
982 .read = seq_read,
983 .llseek = seq_lseek,
984 .release = single_release,
985};
986
987static struct dentry *sco_debugfs;
1da177e4 988
90ddc4f0 989static const struct proto_ops sco_sock_ops = {
1da177e4
LT
990 .family = PF_BLUETOOTH,
991 .owner = THIS_MODULE,
992 .release = sco_sock_release,
993 .bind = sco_sock_bind,
994 .connect = sco_sock_connect,
995 .listen = sco_sock_listen,
996 .accept = sco_sock_accept,
997 .getname = sco_sock_getname,
998 .sendmsg = sco_sock_sendmsg,
999 .recvmsg = bt_sock_recvmsg,
1000 .poll = bt_sock_poll,
3241ad82 1001 .ioctl = bt_sock_ioctl,
1da177e4
LT
1002 .mmap = sock_no_mmap,
1003 .socketpair = sock_no_socketpair,
fd0b3ff7 1004 .shutdown = sco_sock_shutdown,
1da177e4
LT
1005 .setsockopt = sco_sock_setsockopt,
1006 .getsockopt = sco_sock_getsockopt
1007};
1008
ec1b4cf7 1009static const struct net_proto_family sco_sock_family_ops = {
1da177e4
LT
1010 .family = PF_BLUETOOTH,
1011 .owner = THIS_MODULE,
1012 .create = sco_sock_create,
1013};
1014
64274518 1015int __init sco_init(void)
1da177e4
LT
1016{
1017 int err;
1018
1019 err = proto_register(&sco_proto, 0);
1020 if (err < 0)
1021 return err;
1022
1023 err = bt_sock_register(BTPROTO_SCO, &sco_sock_family_ops);
1024 if (err < 0) {
1025 BT_ERR("SCO socket registration failed");
1026 goto error;
1027 }
1028
aef7d97c
MH
1029 if (bt_debugfs) {
1030 sco_debugfs = debugfs_create_file("sco", 0444,
1031 bt_debugfs, NULL, &sco_debugfs_fops);
1032 if (!sco_debugfs)
1033 BT_ERR("Failed to create SCO debug file");
1034 }
1da177e4 1035
1da177e4
LT
1036 BT_INFO("SCO socket layer initialized");
1037
1038 return 0;
1039
1040error:
1041 proto_unregister(&sco_proto);
1042 return err;
1043}
1044
64274518 1045void __exit sco_exit(void)
1da177e4 1046{
aef7d97c 1047 debugfs_remove(sco_debugfs);
1da177e4
LT
1048
1049 if (bt_sock_unregister(BTPROTO_SCO) < 0)
1050 BT_ERR("SCO socket unregistration failed");
1051
1da177e4
LT
1052 proto_unregister(&sco_proto);
1053}
1054
7cb127d5
MH
1055module_param(disable_esco, bool, 0644);
1056MODULE_PARM_DESC(disable_esco, "Disable eSCO connection creation");