Bluetooth: sco: fix information leak to userspace
[GitHub/mt8127/android_kernel_alcatel_ttab.git] / net / bluetooth / sco.c
CommitLineData
8e87d142 1/*
1da177e4
LT
2 BlueZ - Bluetooth protocol stack for Linux
3 Copyright (C) 2000-2001 Qualcomm Incorporated
4
5 Written 2000,2001 by Maxim Krasnyansky <maxk@qualcomm.com>
6
7 This program is free software; you can redistribute it and/or modify
8 it under the terms of the GNU General Public License version 2 as
9 published by the Free Software Foundation;
10
11 THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS
12 OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
13 FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT OF THIRD PARTY RIGHTS.
14 IN NO EVENT SHALL THE COPYRIGHT HOLDER(S) AND AUTHOR(S) BE LIABLE FOR ANY
8e87d142
YH
15 CLAIM, OR ANY SPECIAL INDIRECT OR CONSEQUENTIAL DAMAGES, OR ANY DAMAGES
16 WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
17 ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
1da177e4
LT
18 OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
19
8e87d142
YH
20 ALL LIABILITY, INCLUDING LIABILITY FOR INFRINGEMENT OF ANY PATENTS,
21 COPYRIGHTS, TRADEMARKS OR OTHER RIGHTS, RELATING TO USE OF THIS
1da177e4
LT
22 SOFTWARE IS DISCLAIMED.
23*/
24
25/* Bluetooth SCO sockets. */
26
1da177e4
LT
27#include <linux/module.h>
28
29#include <linux/types.h>
30#include <linux/errno.h>
31#include <linux/kernel.h>
1da177e4
LT
32#include <linux/sched.h>
33#include <linux/slab.h>
34#include <linux/poll.h>
35#include <linux/fcntl.h>
36#include <linux/init.h>
37#include <linux/interrupt.h>
38#include <linux/socket.h>
39#include <linux/skbuff.h>
be9d1227 40#include <linux/device.h>
aef7d97c
MH
41#include <linux/debugfs.h>
42#include <linux/seq_file.h>
1da177e4
LT
43#include <linux/list.h>
44#include <net/sock.h>
45
46#include <asm/system.h>
735cbc47 47#include <linux/uaccess.h>
1da177e4
LT
48
49#include <net/bluetooth/bluetooth.h>
50#include <net/bluetooth/hci_core.h>
51#include <net/bluetooth/sco.h>
52
7cb127d5
MH
53#define VERSION "0.6"
54
735cbc47 55static int disable_esco;
1da177e4 56
90ddc4f0 57static const struct proto_ops sco_sock_ops;
1da177e4
LT
58
59static struct bt_sock_list sco_sk_list = {
d5fb2962 60 .lock = __RW_LOCK_UNLOCKED(sco_sk_list.lock)
1da177e4
LT
61};
62
63static void __sco_chan_add(struct sco_conn *conn, struct sock *sk, struct sock *parent);
64static void sco_chan_del(struct sock *sk, int err);
65
66static int sco_conn_del(struct hci_conn *conn, int err);
67
68static void sco_sock_close(struct sock *sk);
69static void sco_sock_kill(struct sock *sk);
70
71/* ---- SCO timers ---- */
72static void sco_sock_timeout(unsigned long arg)
73{
74 struct sock *sk = (struct sock *) arg;
75
76 BT_DBG("sock %p state %d", sk, sk->sk_state);
77
78 bh_lock_sock(sk);
79 sk->sk_err = ETIMEDOUT;
80 sk->sk_state_change(sk);
81 bh_unlock_sock(sk);
82
83 sco_sock_kill(sk);
84 sock_put(sk);
85}
86
87static void sco_sock_set_timer(struct sock *sk, long timeout)
88{
89 BT_DBG("sock %p state %d timeout %ld", sk, sk->sk_state, timeout);
90 sk_reset_timer(sk, &sk->sk_timer, jiffies + timeout);
91}
92
93static void sco_sock_clear_timer(struct sock *sk)
94{
95 BT_DBG("sock %p state %d", sk, sk->sk_state);
96 sk_stop_timer(sk, &sk->sk_timer);
97}
98
1da177e4
LT
99/* ---- SCO connections ---- */
100static struct sco_conn *sco_conn_add(struct hci_conn *hcon, __u8 status)
101{
102 struct hci_dev *hdev = hcon->hdev;
25ea6db0 103 struct sco_conn *conn = hcon->sco_data;
1da177e4 104
25ea6db0 105 if (conn || status)
1da177e4
LT
106 return conn;
107
25ea6db0
MH
108 conn = kzalloc(sizeof(struct sco_conn), GFP_ATOMIC);
109 if (!conn)
1da177e4 110 return NULL;
1da177e4
LT
111
112 spin_lock_init(&conn->lock);
113
114 hcon->sco_data = conn;
115 conn->hcon = hcon;
116
117 conn->src = &hdev->bdaddr;
118 conn->dst = &hcon->dst;
119
120 if (hdev->sco_mtu > 0)
121 conn->mtu = hdev->sco_mtu;
122 else
123 conn->mtu = 60;
124
125 BT_DBG("hcon %p conn %p", hcon, conn);
25ea6db0 126
1da177e4
LT
127 return conn;
128}
129
130static inline struct sock *sco_chan_get(struct sco_conn *conn)
131{
132 struct sock *sk = NULL;
133 sco_conn_lock(conn);
134 sk = conn->sk;
135 sco_conn_unlock(conn);
136 return sk;
137}
138
139static int sco_conn_del(struct hci_conn *hcon, int err)
140{
735cbc47 141 struct sco_conn *conn = hcon->sco_data;
1da177e4
LT
142 struct sock *sk;
143
735cbc47 144 if (!conn)
1da177e4
LT
145 return 0;
146
147 BT_DBG("hcon %p conn %p, err %d", hcon, conn, err);
148
149 /* Kill socket */
735cbc47
AE
150 sk = sco_chan_get(conn);
151 if (sk) {
1da177e4
LT
152 bh_lock_sock(sk);
153 sco_sock_clear_timer(sk);
154 sco_chan_del(sk, err);
155 bh_unlock_sock(sk);
156 sco_sock_kill(sk);
157 }
158
159 hcon->sco_data = NULL;
160 kfree(conn);
161 return 0;
162}
163
164static inline int sco_chan_add(struct sco_conn *conn, struct sock *sk, struct sock *parent)
165{
166 int err = 0;
167
168 sco_conn_lock(conn);
b9dbdbc1 169 if (conn->sk)
1da177e4 170 err = -EBUSY;
b9dbdbc1 171 else
1da177e4 172 __sco_chan_add(conn, sk, parent);
b9dbdbc1 173
1da177e4
LT
174 sco_conn_unlock(conn);
175 return err;
176}
177
178static int sco_connect(struct sock *sk)
179{
180 bdaddr_t *src = &bt_sk(sk)->src;
181 bdaddr_t *dst = &bt_sk(sk)->dst;
182 struct sco_conn *conn;
183 struct hci_conn *hcon;
184 struct hci_dev *hdev;
b6a0dc82 185 int err, type;
1da177e4
LT
186
187 BT_DBG("%s -> %s", batostr(src), batostr(dst));
188
735cbc47
AE
189 hdev = hci_get_route(dst, src);
190 if (!hdev)
1da177e4
LT
191 return -EHOSTUNREACH;
192
193 hci_dev_lock_bh(hdev);
194
195 err = -ENOMEM;
196
7cb127d5
MH
197 if (lmp_esco_capable(hdev) && !disable_esco)
198 type = ESCO_LINK;
199 else
200 type = SCO_LINK;
b6a0dc82 201
8c1b2355 202 hcon = hci_connect(hdev, type, dst, BT_SECURITY_LOW, HCI_AT_NO_BONDING);
1da177e4
LT
203 if (!hcon)
204 goto done;
205
206 conn = sco_conn_add(hcon, 0);
207 if (!conn) {
208 hci_conn_put(hcon);
209 goto done;
210 }
211
212 /* Update source addr of the socket */
213 bacpy(src, conn->src);
214
215 err = sco_chan_add(conn, sk, NULL);
216 if (err)
217 goto done;
218
219 if (hcon->state == BT_CONNECTED) {
220 sco_sock_clear_timer(sk);
221 sk->sk_state = BT_CONNECTED;
222 } else {
223 sk->sk_state = BT_CONNECT;
224 sco_sock_set_timer(sk, sk->sk_sndtimeo);
225 }
b6a0dc82 226
1da177e4
LT
227done:
228 hci_dev_unlock_bh(hdev);
229 hci_dev_put(hdev);
230 return err;
231}
232
233static inline int sco_send_frame(struct sock *sk, struct msghdr *msg, int len)
234{
235 struct sco_conn *conn = sco_pi(sk)->conn;
236 struct sk_buff *skb;
237 int err, count;
238
239 /* Check outgoing MTU */
240 if (len > conn->mtu)
241 return -EINVAL;
242
243 BT_DBG("sk %p len %d", sk, len);
244
245 count = min_t(unsigned int, conn->mtu, len);
b9dbdbc1
GP
246 skb = bt_skb_send_alloc(sk, count,
247 msg->msg_flags & MSG_DONTWAIT, &err);
248 if (!skb)
1da177e4
LT
249 return err;
250
251 if (memcpy_fromiovec(skb_put(skb, count), msg->msg_iov, count)) {
b9dbdbc1
GP
252 kfree_skb(skb);
253 return -EFAULT;
1da177e4
LT
254 }
255
0d861d8b 256 hci_send_sco(conn->hcon, skb);
1da177e4
LT
257
258 return count;
1da177e4
LT
259}
260
261static inline void sco_recv_frame(struct sco_conn *conn, struct sk_buff *skb)
262{
263 struct sock *sk = sco_chan_get(conn);
264
265 if (!sk)
266 goto drop;
267
268 BT_DBG("sk %p len %d", sk, skb->len);
269
270 if (sk->sk_state != BT_CONNECTED)
271 goto drop;
272
273 if (!sock_queue_rcv_skb(sk, skb))
274 return;
275
276drop:
277 kfree_skb(skb);
1da177e4
LT
278}
279
280/* -------- Socket interface ---------- */
281static struct sock *__sco_get_sock_by_addr(bdaddr_t *ba)
282{
283 struct sock *sk;
284 struct hlist_node *node;
285
286 sk_for_each(sk, node, &sco_sk_list.head)
287 if (!bacmp(&bt_sk(sk)->src, ba))
288 goto found;
289 sk = NULL;
290found:
291 return sk;
292}
293
294/* Find socket listening on source bdaddr.
295 * Returns closest match.
296 */
297static struct sock *sco_get_sock_listen(bdaddr_t *src)
298{
299 struct sock *sk = NULL, *sk1 = NULL;
300 struct hlist_node *node;
301
302 read_lock(&sco_sk_list.lock);
303
304 sk_for_each(sk, node, &sco_sk_list.head) {
305 if (sk->sk_state != BT_LISTEN)
306 continue;
307
308 /* Exact match. */
309 if (!bacmp(&bt_sk(sk)->src, src))
310 break;
311
312 /* Closest match */
313 if (!bacmp(&bt_sk(sk)->src, BDADDR_ANY))
314 sk1 = sk;
315 }
316
317 read_unlock(&sco_sk_list.lock);
318
319 return node ? sk : sk1;
320}
321
322static void sco_sock_destruct(struct sock *sk)
323{
324 BT_DBG("sk %p", sk);
325
326 skb_queue_purge(&sk->sk_receive_queue);
327 skb_queue_purge(&sk->sk_write_queue);
328}
329
330static void sco_sock_cleanup_listen(struct sock *parent)
331{
332 struct sock *sk;
333
334 BT_DBG("parent %p", parent);
335
336 /* Close not yet accepted channels */
337 while ((sk = bt_accept_dequeue(parent, NULL))) {
338 sco_sock_close(sk);
339 sco_sock_kill(sk);
340 }
341
342 parent->sk_state = BT_CLOSED;
343 sock_set_flag(parent, SOCK_ZAPPED);
344}
345
346/* Kill socket (only if zapped and orphan)
347 * Must be called on unlocked socket.
348 */
349static void sco_sock_kill(struct sock *sk)
350{
351 if (!sock_flag(sk, SOCK_ZAPPED) || sk->sk_socket)
352 return;
353
354 BT_DBG("sk %p state %d", sk, sk->sk_state);
355
356 /* Kill poor orphan */
357 bt_sock_unlink(&sco_sk_list, sk);
358 sock_set_flag(sk, SOCK_DEAD);
359 sock_put(sk);
360}
361
fd0b3ff7 362static void __sco_sock_close(struct sock *sk)
1da177e4 363{
fd0b3ff7 364 BT_DBG("sk %p state %d socket %p", sk, sk->sk_state, sk->sk_socket);
1da177e4
LT
365
366 switch (sk->sk_state) {
367 case BT_LISTEN:
368 sco_sock_cleanup_listen(sk);
369 break;
370
371 case BT_CONNECTED:
372 case BT_CONFIG:
373 case BT_CONNECT:
374 case BT_DISCONN:
375 sco_chan_del(sk, ECONNRESET);
376 break;
377
378 default:
379 sock_set_flag(sk, SOCK_ZAPPED);
380 break;
3ff50b79 381 }
fd0b3ff7 382}
1da177e4 383
fd0b3ff7
MH
384/* Must be called on unlocked socket. */
385static void sco_sock_close(struct sock *sk)
386{
387 sco_sock_clear_timer(sk);
388 lock_sock(sk);
389 __sco_sock_close(sk);
1da177e4 390 release_sock(sk);
1da177e4
LT
391 sco_sock_kill(sk);
392}
393
394static void sco_sock_init(struct sock *sk, struct sock *parent)
395{
396 BT_DBG("sk %p", sk);
397
8e87d142 398 if (parent)
1da177e4
LT
399 sk->sk_type = parent->sk_type;
400}
401
402static struct proto sco_proto = {
403 .name = "SCO",
404 .owner = THIS_MODULE,
405 .obj_size = sizeof(struct sco_pinfo)
406};
407
1b8d7ae4 408static struct sock *sco_sock_alloc(struct net *net, struct socket *sock, int proto, gfp_t prio)
1da177e4
LT
409{
410 struct sock *sk;
411
6257ff21 412 sk = sk_alloc(net, PF_BLUETOOTH, prio, &sco_proto);
1da177e4
LT
413 if (!sk)
414 return NULL;
415
416 sock_init_data(sock, sk);
417 INIT_LIST_HEAD(&bt_sk(sk)->accept_q);
418
419 sk->sk_destruct = sco_sock_destruct;
420 sk->sk_sndtimeo = SCO_CONN_TIMEOUT;
421
422 sock_reset_flag(sk, SOCK_ZAPPED);
423
424 sk->sk_protocol = proto;
425 sk->sk_state = BT_OPEN;
426
b24b8a24 427 setup_timer(&sk->sk_timer, sco_sock_timeout, (unsigned long)sk);
1da177e4
LT
428
429 bt_sock_link(&sco_sk_list, sk);
430 return sk;
431}
432
3f378b68
EP
433static int sco_sock_create(struct net *net, struct socket *sock, int protocol,
434 int kern)
1da177e4
LT
435{
436 struct sock *sk;
437
438 BT_DBG("sock %p", sock);
439
440 sock->state = SS_UNCONNECTED;
441
442 if (sock->type != SOCK_SEQPACKET)
443 return -ESOCKTNOSUPPORT;
444
445 sock->ops = &sco_sock_ops;
446
1b8d7ae4 447 sk = sco_sock_alloc(net, sock, protocol, GFP_ATOMIC);
74da626a 448 if (!sk)
1da177e4
LT
449 return -ENOMEM;
450
451 sco_sock_init(sk, NULL);
452 return 0;
453}
454
455static int sco_sock_bind(struct socket *sock, struct sockaddr *addr, int addr_len)
456{
457 struct sockaddr_sco *sa = (struct sockaddr_sco *) addr;
458 struct sock *sk = sock->sk;
459 bdaddr_t *src = &sa->sco_bdaddr;
460 int err = 0;
461
462 BT_DBG("sk %p %s", sk, batostr(&sa->sco_bdaddr));
463
464 if (!addr || addr->sa_family != AF_BLUETOOTH)
465 return -EINVAL;
466
467 lock_sock(sk);
468
469 if (sk->sk_state != BT_OPEN) {
470 err = -EBADFD;
471 goto done;
472 }
473
474 write_lock_bh(&sco_sk_list.lock);
475
476 if (bacmp(src, BDADDR_ANY) && __sco_get_sock_by_addr(src)) {
477 err = -EADDRINUSE;
478 } else {
479 /* Save source address */
480 bacpy(&bt_sk(sk)->src, &sa->sco_bdaddr);
481 sk->sk_state = BT_BOUND;
482 }
483
484 write_unlock_bh(&sco_sk_list.lock);
485
486done:
487 release_sock(sk);
488 return err;
489}
490
491static int sco_sock_connect(struct socket *sock, struct sockaddr *addr, int alen, int flags)
492{
493 struct sockaddr_sco *sa = (struct sockaddr_sco *) addr;
494 struct sock *sk = sock->sk;
495 int err = 0;
496
497
498 BT_DBG("sk %p", sk);
499
6503d961
CG
500 if (alen < sizeof(struct sockaddr_sco) ||
501 addr->sa_family != AF_BLUETOOTH)
1da177e4
LT
502 return -EINVAL;
503
504 if (sk->sk_state != BT_OPEN && sk->sk_state != BT_BOUND)
505 return -EBADFD;
506
507 if (sk->sk_type != SOCK_SEQPACKET)
508 return -EINVAL;
509
510 lock_sock(sk);
511
512 /* Set destination address and psm */
513 bacpy(&bt_sk(sk)->dst, &sa->sco_bdaddr);
514
735cbc47
AE
515 err = sco_connect(sk);
516 if (err)
1da177e4
LT
517 goto done;
518
8e87d142 519 err = bt_sock_wait_state(sk, BT_CONNECTED,
1da177e4
LT
520 sock_sndtimeo(sk, flags & O_NONBLOCK));
521
522done:
523 release_sock(sk);
524 return err;
525}
526
527static int sco_sock_listen(struct socket *sock, int backlog)
528{
529 struct sock *sk = sock->sk;
530 int err = 0;
531
532 BT_DBG("sk %p backlog %d", sk, backlog);
533
534 lock_sock(sk);
535
536 if (sk->sk_state != BT_BOUND || sock->type != SOCK_SEQPACKET) {
537 err = -EBADFD;
538 goto done;
539 }
540
541 sk->sk_max_ack_backlog = backlog;
542 sk->sk_ack_backlog = 0;
543 sk->sk_state = BT_LISTEN;
544
545done:
546 release_sock(sk);
547 return err;
548}
549
550static int sco_sock_accept(struct socket *sock, struct socket *newsock, int flags)
551{
552 DECLARE_WAITQUEUE(wait, current);
553 struct sock *sk = sock->sk, *ch;
554 long timeo;
555 int err = 0;
556
557 lock_sock(sk);
558
559 if (sk->sk_state != BT_LISTEN) {
560 err = -EBADFD;
561 goto done;
562 }
563
564 timeo = sock_rcvtimeo(sk, flags & O_NONBLOCK);
565
566 BT_DBG("sk %p timeo %ld", sk, timeo);
567
568 /* Wait for an incoming connection. (wake-one). */
aa395145 569 add_wait_queue_exclusive(sk_sleep(sk), &wait);
1da177e4
LT
570 while (!(ch = bt_accept_dequeue(sk, newsock))) {
571 set_current_state(TASK_INTERRUPTIBLE);
572 if (!timeo) {
573 err = -EAGAIN;
574 break;
575 }
576
577 release_sock(sk);
578 timeo = schedule_timeout(timeo);
579 lock_sock(sk);
580
581 if (sk->sk_state != BT_LISTEN) {
582 err = -EBADFD;
583 break;
584 }
585
586 if (signal_pending(current)) {
587 err = sock_intr_errno(timeo);
588 break;
589 }
590 }
591 set_current_state(TASK_RUNNING);
aa395145 592 remove_wait_queue(sk_sleep(sk), &wait);
1da177e4
LT
593
594 if (err)
595 goto done;
596
597 newsock->state = SS_CONNECTED;
598
599 BT_DBG("new socket %p", ch);
600
601done:
602 release_sock(sk);
603 return err;
604}
605
606static int sco_sock_getname(struct socket *sock, struct sockaddr *addr, int *len, int peer)
607{
608 struct sockaddr_sco *sa = (struct sockaddr_sco *) addr;
609 struct sock *sk = sock->sk;
610
611 BT_DBG("sock %p, sk %p", sock, sk);
612
613 addr->sa_family = AF_BLUETOOTH;
614 *len = sizeof(struct sockaddr_sco);
615
616 if (peer)
617 bacpy(&sa->sco_bdaddr, &bt_sk(sk)->dst);
618 else
619 bacpy(&sa->sco_bdaddr, &bt_sk(sk)->src);
620
621 return 0;
622}
623
8e87d142 624static int sco_sock_sendmsg(struct kiocb *iocb, struct socket *sock,
1da177e4
LT
625 struct msghdr *msg, size_t len)
626{
627 struct sock *sk = sock->sk;
b9dbdbc1 628 int err;
1da177e4
LT
629
630 BT_DBG("sock %p, sk %p", sock, sk);
631
c1cbe4b7
BL
632 err = sock_error(sk);
633 if (err)
634 return err;
1da177e4
LT
635
636 if (msg->msg_flags & MSG_OOB)
637 return -EOPNOTSUPP;
638
639 lock_sock(sk);
640
641 if (sk->sk_state == BT_CONNECTED)
642 err = sco_send_frame(sk, msg, len);
643 else
644 err = -ENOTCONN;
645
646 release_sock(sk);
647 return err;
648}
649
b7058842 650static int sco_sock_setsockopt(struct socket *sock, int level, int optname, char __user *optval, unsigned int optlen)
1da177e4
LT
651{
652 struct sock *sk = sock->sk;
653 int err = 0;
654
655 BT_DBG("sk %p", sk);
656
657 lock_sock(sk);
658
659 switch (optname) {
660 default:
661 err = -ENOPROTOOPT;
662 break;
663 }
664
665 release_sock(sk);
666 return err;
667}
668
d58daf42 669static int sco_sock_getsockopt_old(struct socket *sock, int optname, char __user *optval, int __user *optlen)
1da177e4
LT
670{
671 struct sock *sk = sock->sk;
672 struct sco_options opts;
673 struct sco_conninfo cinfo;
8e87d142 674 int len, err = 0;
1da177e4
LT
675
676 BT_DBG("sk %p", sk);
677
678 if (get_user(len, optlen))
679 return -EFAULT;
680
681 lock_sock(sk);
682
683 switch (optname) {
684 case SCO_OPTIONS:
685 if (sk->sk_state != BT_CONNECTED) {
686 err = -ENOTCONN;
687 break;
688 }
689
690 opts.mtu = sco_pi(sk)->conn->mtu;
691
692 BT_DBG("mtu %d", opts.mtu);
693
694 len = min_t(unsigned int, len, sizeof(opts));
695 if (copy_to_user(optval, (char *)&opts, len))
696 err = -EFAULT;
697
698 break;
699
700 case SCO_CONNINFO:
701 if (sk->sk_state != BT_CONNECTED) {
702 err = -ENOTCONN;
703 break;
704 }
705
c4c896e1 706 memset(&cinfo, 0, sizeof(cinfo));
1da177e4
LT
707 cinfo.hci_handle = sco_pi(sk)->conn->hcon->handle;
708 memcpy(cinfo.dev_class, sco_pi(sk)->conn->hcon->dev_class, 3);
709
710 len = min_t(unsigned int, len, sizeof(cinfo));
711 if (copy_to_user(optval, (char *)&cinfo, len))
712 err = -EFAULT;
713
714 break;
715
716 default:
717 err = -ENOPROTOOPT;
718 break;
719 }
720
721 release_sock(sk);
722 return err;
723}
724
d58daf42
MH
725static int sco_sock_getsockopt(struct socket *sock, int level, int optname, char __user *optval, int __user *optlen)
726{
727 struct sock *sk = sock->sk;
728 int len, err = 0;
729
730 BT_DBG("sk %p", sk);
731
732 if (level == SOL_SCO)
733 return sco_sock_getsockopt_old(sock, optname, optval, optlen);
734
735 if (get_user(len, optlen))
736 return -EFAULT;
737
738 lock_sock(sk);
739
740 switch (optname) {
741 default:
742 err = -ENOPROTOOPT;
743 break;
744 }
745
746 release_sock(sk);
747 return err;
748}
749
fd0b3ff7
MH
750static int sco_sock_shutdown(struct socket *sock, int how)
751{
752 struct sock *sk = sock->sk;
753 int err = 0;
754
755 BT_DBG("sock %p, sk %p", sock, sk);
756
757 if (!sk)
758 return 0;
759
760 lock_sock(sk);
761 if (!sk->sk_shutdown) {
762 sk->sk_shutdown = SHUTDOWN_MASK;
763 sco_sock_clear_timer(sk);
764 __sco_sock_close(sk);
765
766 if (sock_flag(sk, SOCK_LINGER) && sk->sk_lingertime)
767 err = bt_sock_wait_state(sk, BT_CLOSED,
768 sk->sk_lingertime);
769 }
770 release_sock(sk);
771 return err;
772}
773
1da177e4
LT
774static int sco_sock_release(struct socket *sock)
775{
776 struct sock *sk = sock->sk;
777 int err = 0;
778
779 BT_DBG("sock %p, sk %p", sock, sk);
780
781 if (!sk)
782 return 0;
783
784 sco_sock_close(sk);
785
786 if (sock_flag(sk, SOCK_LINGER) && sk->sk_lingertime) {
787 lock_sock(sk);
788 err = bt_sock_wait_state(sk, BT_CLOSED, sk->sk_lingertime);
789 release_sock(sk);
790 }
791
792 sock_orphan(sk);
793 sco_sock_kill(sk);
794 return err;
795}
796
797static void __sco_chan_add(struct sco_conn *conn, struct sock *sk, struct sock *parent)
798{
799 BT_DBG("conn %p", conn);
800
801 sco_pi(sk)->conn = conn;
802 conn->sk = sk;
803
804 if (parent)
805 bt_accept_enqueue(parent, sk);
806}
807
8e87d142 808/* Delete channel.
1da177e4
LT
809 * Must be called on the locked socket. */
810static void sco_chan_del(struct sock *sk, int err)
811{
812 struct sco_conn *conn;
813
814 conn = sco_pi(sk)->conn;
815
816 BT_DBG("sk %p, conn %p, err %d", sk, conn, err);
817
8e87d142 818 if (conn) {
1da177e4
LT
819 sco_conn_lock(conn);
820 conn->sk = NULL;
821 sco_pi(sk)->conn = NULL;
822 sco_conn_unlock(conn);
823 hci_conn_put(conn->hcon);
824 }
825
826 sk->sk_state = BT_CLOSED;
827 sk->sk_err = err;
828 sk->sk_state_change(sk);
829
830 sock_set_flag(sk, SOCK_ZAPPED);
831}
832
833static void sco_conn_ready(struct sco_conn *conn)
834{
735cbc47
AE
835 struct sock *parent;
836 struct sock *sk = conn->sk;
1da177e4
LT
837
838 BT_DBG("conn %p", conn);
839
840 sco_conn_lock(conn);
841
735cbc47 842 if (sk) {
1da177e4
LT
843 sco_sock_clear_timer(sk);
844 bh_lock_sock(sk);
845 sk->sk_state = BT_CONNECTED;
846 sk->sk_state_change(sk);
847 bh_unlock_sock(sk);
848 } else {
849 parent = sco_get_sock_listen(conn->src);
850 if (!parent)
851 goto done;
852
853 bh_lock_sock(parent);
854
b9dbdbc1
GP
855 sk = sco_sock_alloc(sock_net(parent), NULL,
856 BTPROTO_SCO, GFP_ATOMIC);
1da177e4
LT
857 if (!sk) {
858 bh_unlock_sock(parent);
859 goto done;
860 }
861
862 sco_sock_init(sk, parent);
863
864 bacpy(&bt_sk(sk)->src, conn->src);
865 bacpy(&bt_sk(sk)->dst, conn->dst);
866
867 hci_conn_hold(conn->hcon);
868 __sco_chan_add(conn, sk, parent);
869
870 sk->sk_state = BT_CONNECTED;
871
872 /* Wake up parent */
873 parent->sk_data_ready(parent, 1);
874
875 bh_unlock_sock(parent);
876 }
877
878done:
879 sco_conn_unlock(conn);
880}
881
882/* ----- SCO interface with lower layer (HCI) ----- */
883static int sco_connect_ind(struct hci_dev *hdev, bdaddr_t *bdaddr, __u8 type)
884{
71aeeaa1
MH
885 register struct sock *sk;
886 struct hlist_node *node;
887 int lm = 0;
888
889 if (type != SCO_LINK && type != ESCO_LINK)
c89ad737 890 return -EINVAL;
71aeeaa1 891
1da177e4
LT
892 BT_DBG("hdev %s, bdaddr %s", hdev->name, batostr(bdaddr));
893
71aeeaa1
MH
894 /* Find listening sockets */
895 read_lock(&sco_sk_list.lock);
896 sk_for_each(sk, node, &sco_sk_list.head) {
897 if (sk->sk_state != BT_LISTEN)
898 continue;
899
900 if (!bacmp(&bt_sk(sk)->src, &hdev->bdaddr) ||
901 !bacmp(&bt_sk(sk)->src, BDADDR_ANY)) {
902 lm |= HCI_LM_ACCEPT;
903 break;
904 }
905 }
906 read_unlock(&sco_sk_list.lock);
907
908 return lm;
1da177e4
LT
909}
910
911static int sco_connect_cfm(struct hci_conn *hcon, __u8 status)
912{
913 BT_DBG("hcon %p bdaddr %s status %d", hcon, batostr(&hcon->dst), status);
914
b6a0dc82 915 if (hcon->type != SCO_LINK && hcon->type != ESCO_LINK)
c89ad737 916 return -EINVAL;
1da177e4
LT
917
918 if (!status) {
919 struct sco_conn *conn;
920
921 conn = sco_conn_add(hcon, status);
922 if (conn)
923 sco_conn_ready(conn);
8e87d142 924 } else
1da177e4
LT
925 sco_conn_del(hcon, bt_err(status));
926
927 return 0;
928}
929
2950f21a 930static int sco_disconn_cfm(struct hci_conn *hcon, __u8 reason)
1da177e4
LT
931{
932 BT_DBG("hcon %p reason %d", hcon, reason);
933
b6a0dc82 934 if (hcon->type != SCO_LINK && hcon->type != ESCO_LINK)
c89ad737 935 return -EINVAL;
1da177e4
LT
936
937 sco_conn_del(hcon, bt_err(reason));
b6a0dc82 938
1da177e4
LT
939 return 0;
940}
941
942static int sco_recv_scodata(struct hci_conn *hcon, struct sk_buff *skb)
943{
944 struct sco_conn *conn = hcon->sco_data;
945
946 if (!conn)
947 goto drop;
948
949 BT_DBG("conn %p len %d", conn, skb->len);
950
951 if (skb->len) {
952 sco_recv_frame(conn, skb);
953 return 0;
954 }
955
956drop:
8e87d142 957 kfree_skb(skb);
1da177e4
LT
958 return 0;
959}
960
aef7d97c 961static int sco_debugfs_show(struct seq_file *f, void *p)
1da177e4
LT
962{
963 struct sock *sk;
964 struct hlist_node *node;
1da177e4
LT
965
966 read_lock_bh(&sco_sk_list.lock);
967
be9d1227 968 sk_for_each(sk, node, &sco_sk_list.head) {
aef7d97c
MH
969 seq_printf(f, "%s %s %d\n", batostr(&bt_sk(sk)->src),
970 batostr(&bt_sk(sk)->dst), sk->sk_state);
be9d1227 971 }
1da177e4 972
1da177e4 973 read_unlock_bh(&sco_sk_list.lock);
1da177e4 974
aef7d97c 975 return 0;
1da177e4
LT
976}
977
aef7d97c
MH
978static int sco_debugfs_open(struct inode *inode, struct file *file)
979{
980 return single_open(file, sco_debugfs_show, inode->i_private);
981}
982
983static const struct file_operations sco_debugfs_fops = {
984 .open = sco_debugfs_open,
985 .read = seq_read,
986 .llseek = seq_lseek,
987 .release = single_release,
988};
989
990static struct dentry *sco_debugfs;
1da177e4 991
90ddc4f0 992static const struct proto_ops sco_sock_ops = {
1da177e4
LT
993 .family = PF_BLUETOOTH,
994 .owner = THIS_MODULE,
995 .release = sco_sock_release,
996 .bind = sco_sock_bind,
997 .connect = sco_sock_connect,
998 .listen = sco_sock_listen,
999 .accept = sco_sock_accept,
1000 .getname = sco_sock_getname,
1001 .sendmsg = sco_sock_sendmsg,
1002 .recvmsg = bt_sock_recvmsg,
1003 .poll = bt_sock_poll,
3241ad82 1004 .ioctl = bt_sock_ioctl,
1da177e4
LT
1005 .mmap = sock_no_mmap,
1006 .socketpair = sock_no_socketpair,
fd0b3ff7 1007 .shutdown = sco_sock_shutdown,
1da177e4
LT
1008 .setsockopt = sco_sock_setsockopt,
1009 .getsockopt = sco_sock_getsockopt
1010};
1011
ec1b4cf7 1012static const struct net_proto_family sco_sock_family_ops = {
1da177e4
LT
1013 .family = PF_BLUETOOTH,
1014 .owner = THIS_MODULE,
1015 .create = sco_sock_create,
1016};
1017
1018static struct hci_proto sco_hci_proto = {
1019 .name = "SCO",
1020 .id = HCI_PROTO_SCO,
1021 .connect_ind = sco_connect_ind,
1022 .connect_cfm = sco_connect_cfm,
2950f21a 1023 .disconn_cfm = sco_disconn_cfm,
1da177e4
LT
1024 .recv_scodata = sco_recv_scodata
1025};
1026
1027static int __init sco_init(void)
1028{
1029 int err;
1030
1031 err = proto_register(&sco_proto, 0);
1032 if (err < 0)
1033 return err;
1034
1035 err = bt_sock_register(BTPROTO_SCO, &sco_sock_family_ops);
1036 if (err < 0) {
1037 BT_ERR("SCO socket registration failed");
1038 goto error;
1039 }
1040
1041 err = hci_register_proto(&sco_hci_proto);
1042 if (err < 0) {
1043 BT_ERR("SCO protocol registration failed");
1044 bt_sock_unregister(BTPROTO_SCO);
1045 goto error;
1046 }
1047
aef7d97c
MH
1048 if (bt_debugfs) {
1049 sco_debugfs = debugfs_create_file("sco", 0444,
1050 bt_debugfs, NULL, &sco_debugfs_fops);
1051 if (!sco_debugfs)
1052 BT_ERR("Failed to create SCO debug file");
1053 }
1da177e4
LT
1054
1055 BT_INFO("SCO (Voice Link) ver %s", VERSION);
1056 BT_INFO("SCO socket layer initialized");
1057
1058 return 0;
1059
1060error:
1061 proto_unregister(&sco_proto);
1062 return err;
1063}
1064
1065static void __exit sco_exit(void)
1066{
aef7d97c 1067 debugfs_remove(sco_debugfs);
1da177e4
LT
1068
1069 if (bt_sock_unregister(BTPROTO_SCO) < 0)
1070 BT_ERR("SCO socket unregistration failed");
1071
1072 if (hci_unregister_proto(&sco_hci_proto) < 0)
1073 BT_ERR("SCO protocol unregistration failed");
1074
1075 proto_unregister(&sco_proto);
1076}
1077
1078module_init(sco_init);
1079module_exit(sco_exit);
1080
7cb127d5
MH
1081module_param(disable_esco, bool, 0644);
1082MODULE_PARM_DESC(disable_esco, "Disable eSCO connection creation");
1083
63fbd24e 1084MODULE_AUTHOR("Marcel Holtmann <marcel@holtmann.org>");
1da177e4
LT
1085MODULE_DESCRIPTION("Bluetooth SCO ver " VERSION);
1086MODULE_VERSION(VERSION);
1087MODULE_LICENSE("GPL");
1088MODULE_ALIAS("bt-proto-2");