Bluetooth: Validate data size before accessing mgmt commands
[GitHub/mt8127/android_kernel_alcatel_ttab.git] / net / bluetooth / sco.c
CommitLineData
8e87d142 1/*
1da177e4
LT
2 BlueZ - Bluetooth protocol stack for Linux
3 Copyright (C) 2000-2001 Qualcomm Incorporated
4
5 Written 2000,2001 by Maxim Krasnyansky <maxk@qualcomm.com>
6
7 This program is free software; you can redistribute it and/or modify
8 it under the terms of the GNU General Public License version 2 as
9 published by the Free Software Foundation;
10
11 THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS
12 OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
13 FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT OF THIRD PARTY RIGHTS.
14 IN NO EVENT SHALL THE COPYRIGHT HOLDER(S) AND AUTHOR(S) BE LIABLE FOR ANY
8e87d142
YH
15 CLAIM, OR ANY SPECIAL INDIRECT OR CONSEQUENTIAL DAMAGES, OR ANY DAMAGES
16 WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
17 ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
1da177e4
LT
18 OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
19
8e87d142
YH
20 ALL LIABILITY, INCLUDING LIABILITY FOR INFRINGEMENT OF ANY PATENTS,
21 COPYRIGHTS, TRADEMARKS OR OTHER RIGHTS, RELATING TO USE OF THIS
1da177e4
LT
22 SOFTWARE IS DISCLAIMED.
23*/
24
25/* Bluetooth SCO sockets. */
26
1da177e4
LT
27#include <linux/module.h>
28
29#include <linux/types.h>
30#include <linux/errno.h>
31#include <linux/kernel.h>
1da177e4
LT
32#include <linux/sched.h>
33#include <linux/slab.h>
34#include <linux/poll.h>
35#include <linux/fcntl.h>
36#include <linux/init.h>
37#include <linux/interrupt.h>
38#include <linux/socket.h>
39#include <linux/skbuff.h>
be9d1227 40#include <linux/device.h>
aef7d97c
MH
41#include <linux/debugfs.h>
42#include <linux/seq_file.h>
1da177e4
LT
43#include <linux/list.h>
44#include <net/sock.h>
45
46#include <asm/system.h>
735cbc47 47#include <linux/uaccess.h>
1da177e4
LT
48
49#include <net/bluetooth/bluetooth.h>
50#include <net/bluetooth/hci_core.h>
51#include <net/bluetooth/sco.h>
52
735cbc47 53static int disable_esco;
1da177e4 54
90ddc4f0 55static const struct proto_ops sco_sock_ops;
1da177e4
LT
56
57static struct bt_sock_list sco_sk_list = {
d5fb2962 58 .lock = __RW_LOCK_UNLOCKED(sco_sk_list.lock)
1da177e4
LT
59};
60
61static void __sco_chan_add(struct sco_conn *conn, struct sock *sk, struct sock *parent);
62static void sco_chan_del(struct sock *sk, int err);
63
64static int sco_conn_del(struct hci_conn *conn, int err);
65
66static void sco_sock_close(struct sock *sk);
67static void sco_sock_kill(struct sock *sk);
68
69/* ---- SCO timers ---- */
70static void sco_sock_timeout(unsigned long arg)
71{
72 struct sock *sk = (struct sock *) arg;
73
74 BT_DBG("sock %p state %d", sk, sk->sk_state);
75
76 bh_lock_sock(sk);
77 sk->sk_err = ETIMEDOUT;
78 sk->sk_state_change(sk);
79 bh_unlock_sock(sk);
80
81 sco_sock_kill(sk);
82 sock_put(sk);
83}
84
85static void sco_sock_set_timer(struct sock *sk, long timeout)
86{
87 BT_DBG("sock %p state %d timeout %ld", sk, sk->sk_state, timeout);
88 sk_reset_timer(sk, &sk->sk_timer, jiffies + timeout);
89}
90
91static void sco_sock_clear_timer(struct sock *sk)
92{
93 BT_DBG("sock %p state %d", sk, sk->sk_state);
94 sk_stop_timer(sk, &sk->sk_timer);
95}
96
1da177e4
LT
97/* ---- SCO connections ---- */
98static struct sco_conn *sco_conn_add(struct hci_conn *hcon, __u8 status)
99{
100 struct hci_dev *hdev = hcon->hdev;
25ea6db0 101 struct sco_conn *conn = hcon->sco_data;
1da177e4 102
25ea6db0 103 if (conn || status)
1da177e4
LT
104 return conn;
105
25ea6db0
MH
106 conn = kzalloc(sizeof(struct sco_conn), GFP_ATOMIC);
107 if (!conn)
1da177e4 108 return NULL;
1da177e4
LT
109
110 spin_lock_init(&conn->lock);
111
112 hcon->sco_data = conn;
113 conn->hcon = hcon;
114
115 conn->src = &hdev->bdaddr;
116 conn->dst = &hcon->dst;
117
118 if (hdev->sco_mtu > 0)
119 conn->mtu = hdev->sco_mtu;
120 else
121 conn->mtu = 60;
122
123 BT_DBG("hcon %p conn %p", hcon, conn);
25ea6db0 124
1da177e4
LT
125 return conn;
126}
127
128static inline struct sock *sco_chan_get(struct sco_conn *conn)
129{
130 struct sock *sk = NULL;
131 sco_conn_lock(conn);
132 sk = conn->sk;
133 sco_conn_unlock(conn);
134 return sk;
135}
136
137static int sco_conn_del(struct hci_conn *hcon, int err)
138{
735cbc47 139 struct sco_conn *conn = hcon->sco_data;
1da177e4
LT
140 struct sock *sk;
141
735cbc47 142 if (!conn)
1da177e4
LT
143 return 0;
144
145 BT_DBG("hcon %p conn %p, err %d", hcon, conn, err);
146
147 /* Kill socket */
735cbc47
AE
148 sk = sco_chan_get(conn);
149 if (sk) {
1da177e4
LT
150 bh_lock_sock(sk);
151 sco_sock_clear_timer(sk);
152 sco_chan_del(sk, err);
153 bh_unlock_sock(sk);
154 sco_sock_kill(sk);
155 }
156
157 hcon->sco_data = NULL;
158 kfree(conn);
159 return 0;
160}
161
162static inline int sco_chan_add(struct sco_conn *conn, struct sock *sk, struct sock *parent)
163{
164 int err = 0;
165
166 sco_conn_lock(conn);
b9dbdbc1 167 if (conn->sk)
1da177e4 168 err = -EBUSY;
b9dbdbc1 169 else
1da177e4 170 __sco_chan_add(conn, sk, parent);
b9dbdbc1 171
1da177e4
LT
172 sco_conn_unlock(conn);
173 return err;
174}
175
176static int sco_connect(struct sock *sk)
177{
178 bdaddr_t *src = &bt_sk(sk)->src;
179 bdaddr_t *dst = &bt_sk(sk)->dst;
180 struct sco_conn *conn;
181 struct hci_conn *hcon;
182 struct hci_dev *hdev;
b6a0dc82 183 int err, type;
1da177e4
LT
184
185 BT_DBG("%s -> %s", batostr(src), batostr(dst));
186
735cbc47
AE
187 hdev = hci_get_route(dst, src);
188 if (!hdev)
1da177e4
LT
189 return -EHOSTUNREACH;
190
191 hci_dev_lock_bh(hdev);
192
193 err = -ENOMEM;
194
7cb127d5
MH
195 if (lmp_esco_capable(hdev) && !disable_esco)
196 type = ESCO_LINK;
197 else
198 type = SCO_LINK;
b6a0dc82 199
8c1b2355 200 hcon = hci_connect(hdev, type, dst, BT_SECURITY_LOW, HCI_AT_NO_BONDING);
1da177e4
LT
201 if (!hcon)
202 goto done;
203
204 conn = sco_conn_add(hcon, 0);
205 if (!conn) {
206 hci_conn_put(hcon);
207 goto done;
208 }
209
210 /* Update source addr of the socket */
211 bacpy(src, conn->src);
212
213 err = sco_chan_add(conn, sk, NULL);
214 if (err)
215 goto done;
216
217 if (hcon->state == BT_CONNECTED) {
218 sco_sock_clear_timer(sk);
219 sk->sk_state = BT_CONNECTED;
220 } else {
221 sk->sk_state = BT_CONNECT;
222 sco_sock_set_timer(sk, sk->sk_sndtimeo);
223 }
b6a0dc82 224
1da177e4
LT
225done:
226 hci_dev_unlock_bh(hdev);
227 hci_dev_put(hdev);
228 return err;
229}
230
231static inline int sco_send_frame(struct sock *sk, struct msghdr *msg, int len)
232{
233 struct sco_conn *conn = sco_pi(sk)->conn;
234 struct sk_buff *skb;
235 int err, count;
236
237 /* Check outgoing MTU */
238 if (len > conn->mtu)
239 return -EINVAL;
240
241 BT_DBG("sk %p len %d", sk, len);
242
243 count = min_t(unsigned int, conn->mtu, len);
b9dbdbc1
GP
244 skb = bt_skb_send_alloc(sk, count,
245 msg->msg_flags & MSG_DONTWAIT, &err);
246 if (!skb)
1da177e4
LT
247 return err;
248
249 if (memcpy_fromiovec(skb_put(skb, count), msg->msg_iov, count)) {
b9dbdbc1
GP
250 kfree_skb(skb);
251 return -EFAULT;
1da177e4
LT
252 }
253
0d861d8b 254 hci_send_sco(conn->hcon, skb);
1da177e4
LT
255
256 return count;
1da177e4
LT
257}
258
259static inline void sco_recv_frame(struct sco_conn *conn, struct sk_buff *skb)
260{
261 struct sock *sk = sco_chan_get(conn);
262
263 if (!sk)
264 goto drop;
265
266 BT_DBG("sk %p len %d", sk, skb->len);
267
268 if (sk->sk_state != BT_CONNECTED)
269 goto drop;
270
271 if (!sock_queue_rcv_skb(sk, skb))
272 return;
273
274drop:
275 kfree_skb(skb);
1da177e4
LT
276}
277
278/* -------- Socket interface ---------- */
279static struct sock *__sco_get_sock_by_addr(bdaddr_t *ba)
280{
281 struct sock *sk;
282 struct hlist_node *node;
283
284 sk_for_each(sk, node, &sco_sk_list.head)
285 if (!bacmp(&bt_sk(sk)->src, ba))
286 goto found;
287 sk = NULL;
288found:
289 return sk;
290}
291
292/* Find socket listening on source bdaddr.
293 * Returns closest match.
294 */
295static struct sock *sco_get_sock_listen(bdaddr_t *src)
296{
297 struct sock *sk = NULL, *sk1 = NULL;
298 struct hlist_node *node;
299
300 read_lock(&sco_sk_list.lock);
301
302 sk_for_each(sk, node, &sco_sk_list.head) {
303 if (sk->sk_state != BT_LISTEN)
304 continue;
305
306 /* Exact match. */
307 if (!bacmp(&bt_sk(sk)->src, src))
308 break;
309
310 /* Closest match */
311 if (!bacmp(&bt_sk(sk)->src, BDADDR_ANY))
312 sk1 = sk;
313 }
314
315 read_unlock(&sco_sk_list.lock);
316
317 return node ? sk : sk1;
318}
319
320static void sco_sock_destruct(struct sock *sk)
321{
322 BT_DBG("sk %p", sk);
323
324 skb_queue_purge(&sk->sk_receive_queue);
325 skb_queue_purge(&sk->sk_write_queue);
326}
327
328static void sco_sock_cleanup_listen(struct sock *parent)
329{
330 struct sock *sk;
331
332 BT_DBG("parent %p", parent);
333
334 /* Close not yet accepted channels */
335 while ((sk = bt_accept_dequeue(parent, NULL))) {
336 sco_sock_close(sk);
337 sco_sock_kill(sk);
338 }
339
340 parent->sk_state = BT_CLOSED;
341 sock_set_flag(parent, SOCK_ZAPPED);
342}
343
344/* Kill socket (only if zapped and orphan)
345 * Must be called on unlocked socket.
346 */
347static void sco_sock_kill(struct sock *sk)
348{
349 if (!sock_flag(sk, SOCK_ZAPPED) || sk->sk_socket)
350 return;
351
352 BT_DBG("sk %p state %d", sk, sk->sk_state);
353
354 /* Kill poor orphan */
355 bt_sock_unlink(&sco_sk_list, sk);
356 sock_set_flag(sk, SOCK_DEAD);
357 sock_put(sk);
358}
359
fd0b3ff7 360static void __sco_sock_close(struct sock *sk)
1da177e4 361{
fd0b3ff7 362 BT_DBG("sk %p state %d socket %p", sk, sk->sk_state, sk->sk_socket);
1da177e4
LT
363
364 switch (sk->sk_state) {
365 case BT_LISTEN:
366 sco_sock_cleanup_listen(sk);
367 break;
368
369 case BT_CONNECTED:
370 case BT_CONFIG:
371 case BT_CONNECT:
372 case BT_DISCONN:
373 sco_chan_del(sk, ECONNRESET);
374 break;
375
376 default:
377 sock_set_flag(sk, SOCK_ZAPPED);
378 break;
3ff50b79 379 }
fd0b3ff7 380}
1da177e4 381
fd0b3ff7
MH
382/* Must be called on unlocked socket. */
383static void sco_sock_close(struct sock *sk)
384{
385 sco_sock_clear_timer(sk);
386 lock_sock(sk);
387 __sco_sock_close(sk);
1da177e4 388 release_sock(sk);
1da177e4
LT
389 sco_sock_kill(sk);
390}
391
392static void sco_sock_init(struct sock *sk, struct sock *parent)
393{
394 BT_DBG("sk %p", sk);
395
8e87d142 396 if (parent)
1da177e4
LT
397 sk->sk_type = parent->sk_type;
398}
399
400static struct proto sco_proto = {
401 .name = "SCO",
402 .owner = THIS_MODULE,
403 .obj_size = sizeof(struct sco_pinfo)
404};
405
1b8d7ae4 406static struct sock *sco_sock_alloc(struct net *net, struct socket *sock, int proto, gfp_t prio)
1da177e4
LT
407{
408 struct sock *sk;
409
6257ff21 410 sk = sk_alloc(net, PF_BLUETOOTH, prio, &sco_proto);
1da177e4
LT
411 if (!sk)
412 return NULL;
413
414 sock_init_data(sock, sk);
415 INIT_LIST_HEAD(&bt_sk(sk)->accept_q);
416
417 sk->sk_destruct = sco_sock_destruct;
418 sk->sk_sndtimeo = SCO_CONN_TIMEOUT;
419
420 sock_reset_flag(sk, SOCK_ZAPPED);
421
422 sk->sk_protocol = proto;
423 sk->sk_state = BT_OPEN;
424
b24b8a24 425 setup_timer(&sk->sk_timer, sco_sock_timeout, (unsigned long)sk);
1da177e4
LT
426
427 bt_sock_link(&sco_sk_list, sk);
428 return sk;
429}
430
3f378b68
EP
431static int sco_sock_create(struct net *net, struct socket *sock, int protocol,
432 int kern)
1da177e4
LT
433{
434 struct sock *sk;
435
436 BT_DBG("sock %p", sock);
437
438 sock->state = SS_UNCONNECTED;
439
440 if (sock->type != SOCK_SEQPACKET)
441 return -ESOCKTNOSUPPORT;
442
443 sock->ops = &sco_sock_ops;
444
1b8d7ae4 445 sk = sco_sock_alloc(net, sock, protocol, GFP_ATOMIC);
74da626a 446 if (!sk)
1da177e4
LT
447 return -ENOMEM;
448
449 sco_sock_init(sk, NULL);
450 return 0;
451}
452
453static int sco_sock_bind(struct socket *sock, struct sockaddr *addr, int addr_len)
454{
455 struct sockaddr_sco *sa = (struct sockaddr_sco *) addr;
456 struct sock *sk = sock->sk;
457 bdaddr_t *src = &sa->sco_bdaddr;
458 int err = 0;
459
460 BT_DBG("sk %p %s", sk, batostr(&sa->sco_bdaddr));
461
462 if (!addr || addr->sa_family != AF_BLUETOOTH)
463 return -EINVAL;
464
465 lock_sock(sk);
466
467 if (sk->sk_state != BT_OPEN) {
468 err = -EBADFD;
469 goto done;
470 }
471
472 write_lock_bh(&sco_sk_list.lock);
473
474 if (bacmp(src, BDADDR_ANY) && __sco_get_sock_by_addr(src)) {
475 err = -EADDRINUSE;
476 } else {
477 /* Save source address */
478 bacpy(&bt_sk(sk)->src, &sa->sco_bdaddr);
479 sk->sk_state = BT_BOUND;
480 }
481
482 write_unlock_bh(&sco_sk_list.lock);
483
484done:
485 release_sock(sk);
486 return err;
487}
488
489static int sco_sock_connect(struct socket *sock, struct sockaddr *addr, int alen, int flags)
490{
491 struct sockaddr_sco *sa = (struct sockaddr_sco *) addr;
492 struct sock *sk = sock->sk;
493 int err = 0;
494
495
496 BT_DBG("sk %p", sk);
497
6503d961
CG
498 if (alen < sizeof(struct sockaddr_sco) ||
499 addr->sa_family != AF_BLUETOOTH)
1da177e4
LT
500 return -EINVAL;
501
502 if (sk->sk_state != BT_OPEN && sk->sk_state != BT_BOUND)
503 return -EBADFD;
504
505 if (sk->sk_type != SOCK_SEQPACKET)
506 return -EINVAL;
507
508 lock_sock(sk);
509
510 /* Set destination address and psm */
511 bacpy(&bt_sk(sk)->dst, &sa->sco_bdaddr);
512
735cbc47
AE
513 err = sco_connect(sk);
514 if (err)
1da177e4
LT
515 goto done;
516
8e87d142 517 err = bt_sock_wait_state(sk, BT_CONNECTED,
1da177e4
LT
518 sock_sndtimeo(sk, flags & O_NONBLOCK));
519
520done:
521 release_sock(sk);
522 return err;
523}
524
525static int sco_sock_listen(struct socket *sock, int backlog)
526{
527 struct sock *sk = sock->sk;
528 int err = 0;
529
530 BT_DBG("sk %p backlog %d", sk, backlog);
531
532 lock_sock(sk);
533
534 if (sk->sk_state != BT_BOUND || sock->type != SOCK_SEQPACKET) {
535 err = -EBADFD;
536 goto done;
537 }
538
539 sk->sk_max_ack_backlog = backlog;
540 sk->sk_ack_backlog = 0;
541 sk->sk_state = BT_LISTEN;
542
543done:
544 release_sock(sk);
545 return err;
546}
547
548static int sco_sock_accept(struct socket *sock, struct socket *newsock, int flags)
549{
550 DECLARE_WAITQUEUE(wait, current);
551 struct sock *sk = sock->sk, *ch;
552 long timeo;
553 int err = 0;
554
555 lock_sock(sk);
556
557 if (sk->sk_state != BT_LISTEN) {
558 err = -EBADFD;
559 goto done;
560 }
561
562 timeo = sock_rcvtimeo(sk, flags & O_NONBLOCK);
563
564 BT_DBG("sk %p timeo %ld", sk, timeo);
565
566 /* Wait for an incoming connection. (wake-one). */
aa395145 567 add_wait_queue_exclusive(sk_sleep(sk), &wait);
1da177e4
LT
568 while (!(ch = bt_accept_dequeue(sk, newsock))) {
569 set_current_state(TASK_INTERRUPTIBLE);
570 if (!timeo) {
571 err = -EAGAIN;
572 break;
573 }
574
575 release_sock(sk);
576 timeo = schedule_timeout(timeo);
577 lock_sock(sk);
578
579 if (sk->sk_state != BT_LISTEN) {
580 err = -EBADFD;
581 break;
582 }
583
584 if (signal_pending(current)) {
585 err = sock_intr_errno(timeo);
586 break;
587 }
588 }
589 set_current_state(TASK_RUNNING);
aa395145 590 remove_wait_queue(sk_sleep(sk), &wait);
1da177e4
LT
591
592 if (err)
593 goto done;
594
595 newsock->state = SS_CONNECTED;
596
597 BT_DBG("new socket %p", ch);
598
599done:
600 release_sock(sk);
601 return err;
602}
603
604static int sco_sock_getname(struct socket *sock, struct sockaddr *addr, int *len, int peer)
605{
606 struct sockaddr_sco *sa = (struct sockaddr_sco *) addr;
607 struct sock *sk = sock->sk;
608
609 BT_DBG("sock %p, sk %p", sock, sk);
610
611 addr->sa_family = AF_BLUETOOTH;
612 *len = sizeof(struct sockaddr_sco);
613
614 if (peer)
615 bacpy(&sa->sco_bdaddr, &bt_sk(sk)->dst);
616 else
617 bacpy(&sa->sco_bdaddr, &bt_sk(sk)->src);
618
619 return 0;
620}
621
8e87d142 622static int sco_sock_sendmsg(struct kiocb *iocb, struct socket *sock,
1da177e4
LT
623 struct msghdr *msg, size_t len)
624{
625 struct sock *sk = sock->sk;
b9dbdbc1 626 int err;
1da177e4
LT
627
628 BT_DBG("sock %p, sk %p", sock, sk);
629
c1cbe4b7
BL
630 err = sock_error(sk);
631 if (err)
632 return err;
1da177e4
LT
633
634 if (msg->msg_flags & MSG_OOB)
635 return -EOPNOTSUPP;
636
637 lock_sock(sk);
638
639 if (sk->sk_state == BT_CONNECTED)
640 err = sco_send_frame(sk, msg, len);
641 else
642 err = -ENOTCONN;
643
644 release_sock(sk);
645 return err;
646}
647
b7058842 648static int sco_sock_setsockopt(struct socket *sock, int level, int optname, char __user *optval, unsigned int optlen)
1da177e4
LT
649{
650 struct sock *sk = sock->sk;
651 int err = 0;
652
653 BT_DBG("sk %p", sk);
654
655 lock_sock(sk);
656
657 switch (optname) {
658 default:
659 err = -ENOPROTOOPT;
660 break;
661 }
662
663 release_sock(sk);
664 return err;
665}
666
d58daf42 667static int sco_sock_getsockopt_old(struct socket *sock, int optname, char __user *optval, int __user *optlen)
1da177e4
LT
668{
669 struct sock *sk = sock->sk;
670 struct sco_options opts;
671 struct sco_conninfo cinfo;
8e87d142 672 int len, err = 0;
1da177e4
LT
673
674 BT_DBG("sk %p", sk);
675
676 if (get_user(len, optlen))
677 return -EFAULT;
678
679 lock_sock(sk);
680
681 switch (optname) {
682 case SCO_OPTIONS:
683 if (sk->sk_state != BT_CONNECTED) {
684 err = -ENOTCONN;
685 break;
686 }
687
688 opts.mtu = sco_pi(sk)->conn->mtu;
689
690 BT_DBG("mtu %d", opts.mtu);
691
692 len = min_t(unsigned int, len, sizeof(opts));
693 if (copy_to_user(optval, (char *)&opts, len))
694 err = -EFAULT;
695
696 break;
697
698 case SCO_CONNINFO:
699 if (sk->sk_state != BT_CONNECTED) {
700 err = -ENOTCONN;
701 break;
702 }
703
c4c896e1 704 memset(&cinfo, 0, sizeof(cinfo));
1da177e4
LT
705 cinfo.hci_handle = sco_pi(sk)->conn->hcon->handle;
706 memcpy(cinfo.dev_class, sco_pi(sk)->conn->hcon->dev_class, 3);
707
708 len = min_t(unsigned int, len, sizeof(cinfo));
709 if (copy_to_user(optval, (char *)&cinfo, len))
710 err = -EFAULT;
711
712 break;
713
714 default:
715 err = -ENOPROTOOPT;
716 break;
717 }
718
719 release_sock(sk);
720 return err;
721}
722
d58daf42
MH
723static int sco_sock_getsockopt(struct socket *sock, int level, int optname, char __user *optval, int __user *optlen)
724{
725 struct sock *sk = sock->sk;
726 int len, err = 0;
727
728 BT_DBG("sk %p", sk);
729
730 if (level == SOL_SCO)
731 return sco_sock_getsockopt_old(sock, optname, optval, optlen);
732
733 if (get_user(len, optlen))
734 return -EFAULT;
735
736 lock_sock(sk);
737
738 switch (optname) {
739 default:
740 err = -ENOPROTOOPT;
741 break;
742 }
743
744 release_sock(sk);
745 return err;
746}
747
fd0b3ff7
MH
748static int sco_sock_shutdown(struct socket *sock, int how)
749{
750 struct sock *sk = sock->sk;
751 int err = 0;
752
753 BT_DBG("sock %p, sk %p", sock, sk);
754
755 if (!sk)
756 return 0;
757
758 lock_sock(sk);
759 if (!sk->sk_shutdown) {
760 sk->sk_shutdown = SHUTDOWN_MASK;
761 sco_sock_clear_timer(sk);
762 __sco_sock_close(sk);
763
764 if (sock_flag(sk, SOCK_LINGER) && sk->sk_lingertime)
765 err = bt_sock_wait_state(sk, BT_CLOSED,
766 sk->sk_lingertime);
767 }
768 release_sock(sk);
769 return err;
770}
771
1da177e4
LT
772static int sco_sock_release(struct socket *sock)
773{
774 struct sock *sk = sock->sk;
775 int err = 0;
776
777 BT_DBG("sock %p, sk %p", sock, sk);
778
779 if (!sk)
780 return 0;
781
782 sco_sock_close(sk);
783
784 if (sock_flag(sk, SOCK_LINGER) && sk->sk_lingertime) {
785 lock_sock(sk);
786 err = bt_sock_wait_state(sk, BT_CLOSED, sk->sk_lingertime);
787 release_sock(sk);
788 }
789
790 sock_orphan(sk);
791 sco_sock_kill(sk);
792 return err;
793}
794
795static void __sco_chan_add(struct sco_conn *conn, struct sock *sk, struct sock *parent)
796{
797 BT_DBG("conn %p", conn);
798
799 sco_pi(sk)->conn = conn;
800 conn->sk = sk;
801
802 if (parent)
803 bt_accept_enqueue(parent, sk);
804}
805
8e87d142 806/* Delete channel.
1da177e4
LT
807 * Must be called on the locked socket. */
808static void sco_chan_del(struct sock *sk, int err)
809{
810 struct sco_conn *conn;
811
812 conn = sco_pi(sk)->conn;
813
814 BT_DBG("sk %p, conn %p, err %d", sk, conn, err);
815
8e87d142 816 if (conn) {
1da177e4
LT
817 sco_conn_lock(conn);
818 conn->sk = NULL;
819 sco_pi(sk)->conn = NULL;
820 sco_conn_unlock(conn);
821 hci_conn_put(conn->hcon);
822 }
823
824 sk->sk_state = BT_CLOSED;
825 sk->sk_err = err;
826 sk->sk_state_change(sk);
827
828 sock_set_flag(sk, SOCK_ZAPPED);
829}
830
831static void sco_conn_ready(struct sco_conn *conn)
832{
735cbc47
AE
833 struct sock *parent;
834 struct sock *sk = conn->sk;
1da177e4
LT
835
836 BT_DBG("conn %p", conn);
837
838 sco_conn_lock(conn);
839
735cbc47 840 if (sk) {
1da177e4
LT
841 sco_sock_clear_timer(sk);
842 bh_lock_sock(sk);
843 sk->sk_state = BT_CONNECTED;
844 sk->sk_state_change(sk);
845 bh_unlock_sock(sk);
846 } else {
847 parent = sco_get_sock_listen(conn->src);
848 if (!parent)
849 goto done;
850
851 bh_lock_sock(parent);
852
b9dbdbc1
GP
853 sk = sco_sock_alloc(sock_net(parent), NULL,
854 BTPROTO_SCO, GFP_ATOMIC);
1da177e4
LT
855 if (!sk) {
856 bh_unlock_sock(parent);
857 goto done;
858 }
859
860 sco_sock_init(sk, parent);
861
862 bacpy(&bt_sk(sk)->src, conn->src);
863 bacpy(&bt_sk(sk)->dst, conn->dst);
864
865 hci_conn_hold(conn->hcon);
866 __sco_chan_add(conn, sk, parent);
867
868 sk->sk_state = BT_CONNECTED;
869
870 /* Wake up parent */
871 parent->sk_data_ready(parent, 1);
872
873 bh_unlock_sock(parent);
874 }
875
876done:
877 sco_conn_unlock(conn);
878}
879
880/* ----- SCO interface with lower layer (HCI) ----- */
881static int sco_connect_ind(struct hci_dev *hdev, bdaddr_t *bdaddr, __u8 type)
882{
71aeeaa1
MH
883 register struct sock *sk;
884 struct hlist_node *node;
885 int lm = 0;
886
887 if (type != SCO_LINK && type != ESCO_LINK)
c89ad737 888 return -EINVAL;
71aeeaa1 889
1da177e4
LT
890 BT_DBG("hdev %s, bdaddr %s", hdev->name, batostr(bdaddr));
891
71aeeaa1
MH
892 /* Find listening sockets */
893 read_lock(&sco_sk_list.lock);
894 sk_for_each(sk, node, &sco_sk_list.head) {
895 if (sk->sk_state != BT_LISTEN)
896 continue;
897
898 if (!bacmp(&bt_sk(sk)->src, &hdev->bdaddr) ||
899 !bacmp(&bt_sk(sk)->src, BDADDR_ANY)) {
900 lm |= HCI_LM_ACCEPT;
901 break;
902 }
903 }
904 read_unlock(&sco_sk_list.lock);
905
906 return lm;
1da177e4
LT
907}
908
909static int sco_connect_cfm(struct hci_conn *hcon, __u8 status)
910{
911 BT_DBG("hcon %p bdaddr %s status %d", hcon, batostr(&hcon->dst), status);
912
b6a0dc82 913 if (hcon->type != SCO_LINK && hcon->type != ESCO_LINK)
c89ad737 914 return -EINVAL;
1da177e4
LT
915
916 if (!status) {
917 struct sco_conn *conn;
918
919 conn = sco_conn_add(hcon, status);
920 if (conn)
921 sco_conn_ready(conn);
8e87d142 922 } else
1da177e4
LT
923 sco_conn_del(hcon, bt_err(status));
924
925 return 0;
926}
927
2950f21a 928static int sco_disconn_cfm(struct hci_conn *hcon, __u8 reason)
1da177e4
LT
929{
930 BT_DBG("hcon %p reason %d", hcon, reason);
931
b6a0dc82 932 if (hcon->type != SCO_LINK && hcon->type != ESCO_LINK)
c89ad737 933 return -EINVAL;
1da177e4
LT
934
935 sco_conn_del(hcon, bt_err(reason));
b6a0dc82 936
1da177e4
LT
937 return 0;
938}
939
940static int sco_recv_scodata(struct hci_conn *hcon, struct sk_buff *skb)
941{
942 struct sco_conn *conn = hcon->sco_data;
943
944 if (!conn)
945 goto drop;
946
947 BT_DBG("conn %p len %d", conn, skb->len);
948
949 if (skb->len) {
950 sco_recv_frame(conn, skb);
951 return 0;
952 }
953
954drop:
8e87d142 955 kfree_skb(skb);
1da177e4
LT
956 return 0;
957}
958
aef7d97c 959static int sco_debugfs_show(struct seq_file *f, void *p)
1da177e4
LT
960{
961 struct sock *sk;
962 struct hlist_node *node;
1da177e4
LT
963
964 read_lock_bh(&sco_sk_list.lock);
965
be9d1227 966 sk_for_each(sk, node, &sco_sk_list.head) {
aef7d97c
MH
967 seq_printf(f, "%s %s %d\n", batostr(&bt_sk(sk)->src),
968 batostr(&bt_sk(sk)->dst), sk->sk_state);
be9d1227 969 }
1da177e4 970
1da177e4 971 read_unlock_bh(&sco_sk_list.lock);
1da177e4 972
aef7d97c 973 return 0;
1da177e4
LT
974}
975
aef7d97c
MH
976static int sco_debugfs_open(struct inode *inode, struct file *file)
977{
978 return single_open(file, sco_debugfs_show, inode->i_private);
979}
980
981static const struct file_operations sco_debugfs_fops = {
982 .open = sco_debugfs_open,
983 .read = seq_read,
984 .llseek = seq_lseek,
985 .release = single_release,
986};
987
988static struct dentry *sco_debugfs;
1da177e4 989
90ddc4f0 990static const struct proto_ops sco_sock_ops = {
1da177e4
LT
991 .family = PF_BLUETOOTH,
992 .owner = THIS_MODULE,
993 .release = sco_sock_release,
994 .bind = sco_sock_bind,
995 .connect = sco_sock_connect,
996 .listen = sco_sock_listen,
997 .accept = sco_sock_accept,
998 .getname = sco_sock_getname,
999 .sendmsg = sco_sock_sendmsg,
1000 .recvmsg = bt_sock_recvmsg,
1001 .poll = bt_sock_poll,
3241ad82 1002 .ioctl = bt_sock_ioctl,
1da177e4
LT
1003 .mmap = sock_no_mmap,
1004 .socketpair = sock_no_socketpair,
fd0b3ff7 1005 .shutdown = sco_sock_shutdown,
1da177e4
LT
1006 .setsockopt = sco_sock_setsockopt,
1007 .getsockopt = sco_sock_getsockopt
1008};
1009
ec1b4cf7 1010static const struct net_proto_family sco_sock_family_ops = {
1da177e4
LT
1011 .family = PF_BLUETOOTH,
1012 .owner = THIS_MODULE,
1013 .create = sco_sock_create,
1014};
1015
1016static struct hci_proto sco_hci_proto = {
1017 .name = "SCO",
1018 .id = HCI_PROTO_SCO,
1019 .connect_ind = sco_connect_ind,
1020 .connect_cfm = sco_connect_cfm,
2950f21a 1021 .disconn_cfm = sco_disconn_cfm,
1da177e4
LT
1022 .recv_scodata = sco_recv_scodata
1023};
1024
64274518 1025int __init sco_init(void)
1da177e4
LT
1026{
1027 int err;
1028
1029 err = proto_register(&sco_proto, 0);
1030 if (err < 0)
1031 return err;
1032
1033 err = bt_sock_register(BTPROTO_SCO, &sco_sock_family_ops);
1034 if (err < 0) {
1035 BT_ERR("SCO socket registration failed");
1036 goto error;
1037 }
1038
1039 err = hci_register_proto(&sco_hci_proto);
1040 if (err < 0) {
1041 BT_ERR("SCO protocol registration failed");
1042 bt_sock_unregister(BTPROTO_SCO);
1043 goto error;
1044 }
1045
aef7d97c
MH
1046 if (bt_debugfs) {
1047 sco_debugfs = debugfs_create_file("sco", 0444,
1048 bt_debugfs, NULL, &sco_debugfs_fops);
1049 if (!sco_debugfs)
1050 BT_ERR("Failed to create SCO debug file");
1051 }
1da177e4 1052
1da177e4
LT
1053 BT_INFO("SCO socket layer initialized");
1054
1055 return 0;
1056
1057error:
1058 proto_unregister(&sco_proto);
1059 return err;
1060}
1061
64274518 1062void __exit sco_exit(void)
1da177e4 1063{
aef7d97c 1064 debugfs_remove(sco_debugfs);
1da177e4
LT
1065
1066 if (bt_sock_unregister(BTPROTO_SCO) < 0)
1067 BT_ERR("SCO socket unregistration failed");
1068
1069 if (hci_unregister_proto(&sco_hci_proto) < 0)
1070 BT_ERR("SCO protocol unregistration failed");
1071
1072 proto_unregister(&sco_proto);
1073}
1074
7cb127d5
MH
1075module_param(disable_esco, bool, 0644);
1076MODULE_PARM_DESC(disable_esco, "Disable eSCO connection creation");