1 // SPDX-License-Identifier: GPL-2.0
2 /*
3 BlueZ - Bluetooth protocol stack for Linux
4 Copyright (c) 2000-2001, 2010, Code Aurora Forum. All rights reserved.
5 Copyright 2023-2024 NXP
6
7 Written 2000,2001 by Maxim Krasnyansky <maxk@qualcomm.com>
8
9 THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS
10 OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
11 FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT OF THIRD PARTY RIGHTS.
12 IN NO EVENT SHALL THE COPYRIGHT HOLDER(S) AND AUTHOR(S) BE LIABLE FOR ANY
13 CLAIM, OR ANY SPECIAL INDIRECT OR CONSEQUENTIAL DAMAGES, OR ANY DAMAGES
14 WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
15 ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
16 OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
17
18 ALL LIABILITY, INCLUDING LIABILITY FOR INFRINGEMENT OF ANY PATENTS,
19 COPYRIGHTS, TRADEMARKS OR OTHER RIGHTS, RELATING TO USE OF THIS
20 SOFTWARE IS DISCLAIMED.
21 */
22
23 /* Bluetooth HCI event handling. */
24
25 #include <linux/unaligned.h>
26 #include <linux/crypto.h>
27 #include <crypto/algapi.h>
28
29 #include <net/bluetooth/bluetooth.h>
30 #include <net/bluetooth/hci_core.h>
31 #include <net/bluetooth/mgmt.h>
32
33 #include "hci_debugfs.h"
34 #include "hci_codec.h"
35 #include "smp.h"
36 #include "msft.h"
37 #include "eir.h"
38
39 #define ZERO_KEY "\x00\x00\x00\x00\x00\x00\x00\x00" \
40 "\x00\x00\x00\x00\x00\x00\x00\x00"
41
42 /* Handle HCI Event packets */
43
hci_ev_skb_pull(struct hci_dev * hdev,struct sk_buff * skb,u8 ev,size_t len)44 static void *hci_ev_skb_pull(struct hci_dev *hdev, struct sk_buff *skb,
45 u8 ev, size_t len)
46 {
47 void *data;
48
49 data = skb_pull_data(skb, len);
50 if (!data)
51 bt_dev_err(hdev, "Malformed Event: 0x%2.2x", ev);
52
53 return data;
54 }
55
hci_cc_skb_pull(struct hci_dev * hdev,struct sk_buff * skb,u16 op,size_t len)56 static void *hci_cc_skb_pull(struct hci_dev *hdev, struct sk_buff *skb,
57 u16 op, size_t len)
58 {
59 void *data;
60
61 data = skb_pull_data(skb, len);
62 if (!data)
63 bt_dev_err(hdev, "Malformed Command Complete: 0x%4.4x", op);
64
65 return data;
66 }
67
hci_le_ev_skb_pull(struct hci_dev * hdev,struct sk_buff * skb,u8 ev,size_t len)68 static void *hci_le_ev_skb_pull(struct hci_dev *hdev, struct sk_buff *skb,
69 u8 ev, size_t len)
70 {
71 void *data;
72
73 data = skb_pull_data(skb, len);
74 if (!data)
75 bt_dev_err(hdev, "Malformed LE Event: 0x%2.2x", ev);
76
77 return data;
78 }
79
80 static void hci_store_wake_reason(struct hci_dev *hdev,
81 const bdaddr_t *bdaddr, u8 addr_type)
82 __must_hold(&hdev->lock);
83
hci_cc_inquiry_cancel(struct hci_dev * hdev,void * data,struct sk_buff * skb)84 static u8 hci_cc_inquiry_cancel(struct hci_dev *hdev, void *data,
85 struct sk_buff *skb)
86 {
87 struct hci_ev_status *rp = data;
88
89 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
90
91 /* It is possible that we receive Inquiry Complete event right
92 * before we receive Inquiry Cancel Command Complete event, in
93 * which case the latter event should have status of Command
94 * Disallowed. This should not be treated as error, since
95 * we actually achieve what Inquiry Cancel wants to achieve,
96 * which is to end the last Inquiry session.
97 */
98 if (rp->status == HCI_ERROR_COMMAND_DISALLOWED && !test_bit(HCI_INQUIRY, &hdev->flags)) {
99 bt_dev_warn(hdev, "Ignoring error of Inquiry Cancel command");
100 rp->status = 0x00;
101 }
102
103 if (rp->status)
104 return rp->status;
105
106 clear_bit(HCI_INQUIRY, &hdev->flags);
107 smp_mb__after_atomic(); /* wake_up_bit advises about this barrier */
108 wake_up_bit(&hdev->flags, HCI_INQUIRY);
109
110 hci_dev_lock(hdev);
111 /* Set discovery state to stopped if we're not doing LE active
112 * scanning.
113 */
114 if (!hci_dev_test_flag(hdev, HCI_LE_SCAN) ||
115 hdev->le_scan_type != LE_SCAN_ACTIVE)
116 hci_discovery_set_state(hdev, DISCOVERY_STOPPED);
117 hci_dev_unlock(hdev);
118
119 return rp->status;
120 }
121
hci_cc_periodic_inq(struct hci_dev * hdev,void * data,struct sk_buff * skb)122 static u8 hci_cc_periodic_inq(struct hci_dev *hdev, void *data,
123 struct sk_buff *skb)
124 {
125 struct hci_ev_status *rp = data;
126
127 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
128
129 if (rp->status)
130 return rp->status;
131
132 hci_dev_set_flag(hdev, HCI_PERIODIC_INQ);
133
134 return rp->status;
135 }
136
hci_cc_exit_periodic_inq(struct hci_dev * hdev,void * data,struct sk_buff * skb)137 static u8 hci_cc_exit_periodic_inq(struct hci_dev *hdev, void *data,
138 struct sk_buff *skb)
139 {
140 struct hci_ev_status *rp = data;
141
142 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
143
144 if (rp->status)
145 return rp->status;
146
147 hci_dev_clear_flag(hdev, HCI_PERIODIC_INQ);
148
149 return rp->status;
150 }
151
hci_cc_remote_name_req_cancel(struct hci_dev * hdev,void * data,struct sk_buff * skb)152 static u8 hci_cc_remote_name_req_cancel(struct hci_dev *hdev, void *data,
153 struct sk_buff *skb)
154 {
155 struct hci_rp_remote_name_req_cancel *rp = data;
156
157 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
158
159 return rp->status;
160 }
161
hci_cc_role_discovery(struct hci_dev * hdev,void * data,struct sk_buff * skb)162 static u8 hci_cc_role_discovery(struct hci_dev *hdev, void *data,
163 struct sk_buff *skb)
164 {
165 struct hci_rp_role_discovery *rp = data;
166 struct hci_conn *conn;
167
168 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
169
170 if (rp->status)
171 return rp->status;
172
173 hci_dev_lock(hdev);
174
175 conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(rp->handle));
176 if (conn)
177 conn->role = rp->role;
178
179 hci_dev_unlock(hdev);
180
181 return rp->status;
182 }
183
hci_cc_read_link_policy(struct hci_dev * hdev,void * data,struct sk_buff * skb)184 static u8 hci_cc_read_link_policy(struct hci_dev *hdev, void *data,
185 struct sk_buff *skb)
186 {
187 struct hci_rp_read_link_policy *rp = data;
188 struct hci_conn *conn;
189
190 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
191
192 if (rp->status)
193 return rp->status;
194
195 hci_dev_lock(hdev);
196
197 conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(rp->handle));
198 if (conn)
199 conn->link_policy = __le16_to_cpu(rp->policy);
200
201 hci_dev_unlock(hdev);
202
203 return rp->status;
204 }
205
hci_cc_write_link_policy(struct hci_dev * hdev,void * data,struct sk_buff * skb)206 static u8 hci_cc_write_link_policy(struct hci_dev *hdev, void *data,
207 struct sk_buff *skb)
208 {
209 struct hci_rp_write_link_policy *rp = data;
210 struct hci_conn *conn;
211 void *sent;
212
213 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
214
215 if (rp->status)
216 return rp->status;
217
218 sent = hci_sent_cmd_data(hdev, HCI_OP_WRITE_LINK_POLICY);
219 if (!sent)
220 return rp->status;
221
222 hci_dev_lock(hdev);
223
224 conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(rp->handle));
225 if (conn)
226 conn->link_policy = get_unaligned_le16(sent + 2);
227
228 hci_dev_unlock(hdev);
229
230 return rp->status;
231 }
232
hci_cc_read_def_link_policy(struct hci_dev * hdev,void * data,struct sk_buff * skb)233 static u8 hci_cc_read_def_link_policy(struct hci_dev *hdev, void *data,
234 struct sk_buff *skb)
235 {
236 struct hci_rp_read_def_link_policy *rp = data;
237
238 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
239
240 if (rp->status)
241 return rp->status;
242
243 hdev->link_policy = __le16_to_cpu(rp->policy);
244
245 return rp->status;
246 }
247
hci_cc_write_def_link_policy(struct hci_dev * hdev,void * data,struct sk_buff * skb)248 static u8 hci_cc_write_def_link_policy(struct hci_dev *hdev, void *data,
249 struct sk_buff *skb)
250 {
251 struct hci_ev_status *rp = data;
252 void *sent;
253
254 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
255
256 if (rp->status)
257 return rp->status;
258
259 sent = hci_sent_cmd_data(hdev, HCI_OP_WRITE_DEF_LINK_POLICY);
260 if (!sent)
261 return rp->status;
262
263 hdev->link_policy = get_unaligned_le16(sent);
264
265 return rp->status;
266 }
267
hci_cc_reset(struct hci_dev * hdev,void * data,struct sk_buff * skb)268 static u8 hci_cc_reset(struct hci_dev *hdev, void *data, struct sk_buff *skb)
269 {
270 struct hci_ev_status *rp = data;
271
272 if (rp->status)
273 bt_dev_err(hdev, "status 0x%2.2x", rp->status);
274 else
275 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
276
277 clear_bit(HCI_RESET, &hdev->flags);
278
279 if (rp->status)
280 return rp->status;
281
282 /* Reset all non-persistent flags */
283 hci_dev_clear_volatile_flags(hdev);
284
285 hci_discovery_set_state(hdev, DISCOVERY_STOPPED);
286
287 hdev->inq_tx_power = HCI_TX_POWER_INVALID;
288 hdev->adv_tx_power = HCI_TX_POWER_INVALID;
289
290 memset(hdev->adv_data, 0, sizeof(hdev->adv_data));
291 hdev->adv_data_len = 0;
292
293 memset(hdev->scan_rsp_data, 0, sizeof(hdev->scan_rsp_data));
294 hdev->scan_rsp_data_len = 0;
295
296 hdev->le_scan_type = LE_SCAN_PASSIVE;
297
298 hdev->ssp_debug_mode = 0;
299
300 hci_dev_lock(hdev);
301 hci_bdaddr_list_clear(&hdev->le_accept_list);
302 hci_bdaddr_list_clear(&hdev->le_resolv_list);
303 hci_dev_unlock(hdev);
304
305 return rp->status;
306 }
307
hci_cc_read_stored_link_key(struct hci_dev * hdev,void * data,struct sk_buff * skb)308 static u8 hci_cc_read_stored_link_key(struct hci_dev *hdev, void *data,
309 struct sk_buff *skb)
310 {
311 struct hci_rp_read_stored_link_key *rp = data;
312 struct hci_cp_read_stored_link_key *sent;
313
314 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
315
316 sent = hci_sent_cmd_data(hdev, HCI_OP_READ_STORED_LINK_KEY);
317 if (!sent)
318 return rp->status;
319
320 if (!rp->status && sent->read_all == 0x01) {
321 hdev->stored_max_keys = le16_to_cpu(rp->max_keys);
322 hdev->stored_num_keys = le16_to_cpu(rp->num_keys);
323 }
324
325 return rp->status;
326 }
327
hci_cc_delete_stored_link_key(struct hci_dev * hdev,void * data,struct sk_buff * skb)328 static u8 hci_cc_delete_stored_link_key(struct hci_dev *hdev, void *data,
329 struct sk_buff *skb)
330 {
331 struct hci_rp_delete_stored_link_key *rp = data;
332 u16 num_keys;
333
334 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
335
336 if (rp->status)
337 return rp->status;
338
339 num_keys = le16_to_cpu(rp->num_keys);
340
341 if (num_keys <= hdev->stored_num_keys)
342 hdev->stored_num_keys -= num_keys;
343 else
344 hdev->stored_num_keys = 0;
345
346 return rp->status;
347 }
348
hci_cc_write_local_name(struct hci_dev * hdev,void * data,struct sk_buff * skb)349 static u8 hci_cc_write_local_name(struct hci_dev *hdev, void *data,
350 struct sk_buff *skb)
351 {
352 struct hci_ev_status *rp = data;
353 void *sent;
354
355 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
356
357 sent = hci_sent_cmd_data(hdev, HCI_OP_WRITE_LOCAL_NAME);
358 if (!sent)
359 return rp->status;
360
361 hci_dev_lock(hdev);
362
363 if (hci_dev_test_flag(hdev, HCI_MGMT))
364 mgmt_set_local_name_complete(hdev, sent, rp->status);
365 else if (!rp->status)
366 memcpy(hdev->dev_name, sent, HCI_MAX_NAME_LENGTH);
367
368 hci_dev_unlock(hdev);
369
370 return rp->status;
371 }
372
hci_cc_read_local_name(struct hci_dev * hdev,void * data,struct sk_buff * skb)373 static u8 hci_cc_read_local_name(struct hci_dev *hdev, void *data,
374 struct sk_buff *skb)
375 {
376 struct hci_rp_read_local_name *rp = data;
377
378 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
379
380 if (rp->status)
381 return rp->status;
382
383 if (hci_dev_test_flag(hdev, HCI_SETUP) ||
384 hci_dev_test_flag(hdev, HCI_CONFIG))
385 memcpy(hdev->dev_name, rp->name, HCI_MAX_NAME_LENGTH);
386
387 return rp->status;
388 }
389
hci_cc_write_auth_enable(struct hci_dev * hdev,void * data,struct sk_buff * skb)390 static u8 hci_cc_write_auth_enable(struct hci_dev *hdev, void *data,
391 struct sk_buff *skb)
392 {
393 struct hci_ev_status *rp = data;
394 void *sent;
395
396 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
397
398 sent = hci_sent_cmd_data(hdev, HCI_OP_WRITE_AUTH_ENABLE);
399 if (!sent)
400 return rp->status;
401
402 hci_dev_lock(hdev);
403
404 if (!rp->status) {
405 __u8 param = *((__u8 *) sent);
406
407 if (param == AUTH_ENABLED)
408 set_bit(HCI_AUTH, &hdev->flags);
409 else
410 clear_bit(HCI_AUTH, &hdev->flags);
411 }
412
413 if (hci_dev_test_flag(hdev, HCI_MGMT))
414 mgmt_auth_enable_complete(hdev, rp->status);
415
416 hci_dev_unlock(hdev);
417
418 return rp->status;
419 }
420
hci_cc_write_encrypt_mode(struct hci_dev * hdev,void * data,struct sk_buff * skb)421 static u8 hci_cc_write_encrypt_mode(struct hci_dev *hdev, void *data,
422 struct sk_buff *skb)
423 {
424 struct hci_ev_status *rp = data;
425 __u8 param;
426 void *sent;
427
428 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
429
430 if (rp->status)
431 return rp->status;
432
433 sent = hci_sent_cmd_data(hdev, HCI_OP_WRITE_ENCRYPT_MODE);
434 if (!sent)
435 return rp->status;
436
437 param = *((__u8 *) sent);
438
439 if (param)
440 set_bit(HCI_ENCRYPT, &hdev->flags);
441 else
442 clear_bit(HCI_ENCRYPT, &hdev->flags);
443
444 return rp->status;
445 }
446
hci_cc_write_scan_enable(struct hci_dev * hdev,void * data,struct sk_buff * skb)447 static u8 hci_cc_write_scan_enable(struct hci_dev *hdev, void *data,
448 struct sk_buff *skb)
449 {
450 struct hci_ev_status *rp = data;
451 __u8 param;
452 void *sent;
453
454 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
455
456 sent = hci_sent_cmd_data(hdev, HCI_OP_WRITE_SCAN_ENABLE);
457 if (!sent)
458 return rp->status;
459
460 param = *((__u8 *) sent);
461
462 hci_dev_lock(hdev);
463
464 if (rp->status) {
465 hdev->discov_timeout = 0;
466 goto done;
467 }
468
469 if (param & SCAN_INQUIRY)
470 set_bit(HCI_ISCAN, &hdev->flags);
471 else
472 clear_bit(HCI_ISCAN, &hdev->flags);
473
474 if (param & SCAN_PAGE)
475 set_bit(HCI_PSCAN, &hdev->flags);
476 else
477 clear_bit(HCI_PSCAN, &hdev->flags);
478
479 done:
480 hci_dev_unlock(hdev);
481
482 return rp->status;
483 }
484
hci_cc_set_event_filter(struct hci_dev * hdev,void * data,struct sk_buff * skb)485 static u8 hci_cc_set_event_filter(struct hci_dev *hdev, void *data,
486 struct sk_buff *skb)
487 {
488 struct hci_ev_status *rp = data;
489 struct hci_cp_set_event_filter *cp;
490 void *sent;
491
492 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
493
494 if (rp->status)
495 return rp->status;
496
497 sent = hci_sent_cmd_data(hdev, HCI_OP_SET_EVENT_FLT);
498 if (!sent)
499 return rp->status;
500
501 cp = (struct hci_cp_set_event_filter *)sent;
502
503 if (cp->flt_type == HCI_FLT_CLEAR_ALL)
504 hci_dev_clear_flag(hdev, HCI_EVENT_FILTER_CONFIGURED);
505 else
506 hci_dev_set_flag(hdev, HCI_EVENT_FILTER_CONFIGURED);
507
508 return rp->status;
509 }
510
hci_cc_read_class_of_dev(struct hci_dev * hdev,void * data,struct sk_buff * skb)511 static u8 hci_cc_read_class_of_dev(struct hci_dev *hdev, void *data,
512 struct sk_buff *skb)
513 {
514 struct hci_rp_read_class_of_dev *rp = data;
515
516 if (WARN_ON(!hdev))
517 return HCI_ERROR_UNSPECIFIED;
518
519 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
520
521 if (rp->status)
522 return rp->status;
523
524 memcpy(hdev->dev_class, rp->dev_class, 3);
525
526 bt_dev_dbg(hdev, "class 0x%.2x%.2x%.2x", hdev->dev_class[2],
527 hdev->dev_class[1], hdev->dev_class[0]);
528
529 return rp->status;
530 }
531
hci_cc_write_class_of_dev(struct hci_dev * hdev,void * data,struct sk_buff * skb)532 static u8 hci_cc_write_class_of_dev(struct hci_dev *hdev, void *data,
533 struct sk_buff *skb)
534 {
535 struct hci_ev_status *rp = data;
536 void *sent;
537
538 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
539
540 sent = hci_sent_cmd_data(hdev, HCI_OP_WRITE_CLASS_OF_DEV);
541 if (!sent)
542 return rp->status;
543
544 hci_dev_lock(hdev);
545
546 if (!rp->status)
547 memcpy(hdev->dev_class, sent, 3);
548
549 if (hci_dev_test_flag(hdev, HCI_MGMT))
550 mgmt_set_class_of_dev_complete(hdev, sent, rp->status);
551
552 hci_dev_unlock(hdev);
553
554 return rp->status;
555 }
556
hci_cc_read_voice_setting(struct hci_dev * hdev,void * data,struct sk_buff * skb)557 static u8 hci_cc_read_voice_setting(struct hci_dev *hdev, void *data,
558 struct sk_buff *skb)
559 {
560 struct hci_rp_read_voice_setting *rp = data;
561 __u16 setting;
562
563 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
564
565 if (rp->status)
566 return rp->status;
567
568 setting = __le16_to_cpu(rp->voice_setting);
569
570 if (hdev->voice_setting == setting)
571 return rp->status;
572
573 hdev->voice_setting = setting;
574
575 bt_dev_dbg(hdev, "voice setting 0x%4.4x", setting);
576
577 if (hdev->notify)
578 hdev->notify(hdev, HCI_NOTIFY_VOICE_SETTING);
579
580 return rp->status;
581 }
582
hci_cc_write_voice_setting(struct hci_dev * hdev,void * data,struct sk_buff * skb)583 static u8 hci_cc_write_voice_setting(struct hci_dev *hdev, void *data,
584 struct sk_buff *skb)
585 {
586 struct hci_ev_status *rp = data;
587 __u16 setting;
588 void *sent;
589
590 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
591
592 if (rp->status)
593 return rp->status;
594
595 sent = hci_sent_cmd_data(hdev, HCI_OP_WRITE_VOICE_SETTING);
596 if (!sent)
597 return rp->status;
598
599 setting = get_unaligned_le16(sent);
600
601 if (hdev->voice_setting == setting)
602 return rp->status;
603
604 hdev->voice_setting = setting;
605
606 bt_dev_dbg(hdev, "voice setting 0x%4.4x", setting);
607
608 if (hdev->notify)
609 hdev->notify(hdev, HCI_NOTIFY_VOICE_SETTING);
610
611 return rp->status;
612 }
613
hci_cc_read_num_supported_iac(struct hci_dev * hdev,void * data,struct sk_buff * skb)614 static u8 hci_cc_read_num_supported_iac(struct hci_dev *hdev, void *data,
615 struct sk_buff *skb)
616 {
617 struct hci_rp_read_num_supported_iac *rp = data;
618
619 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
620
621 if (rp->status)
622 return rp->status;
623
624 hdev->num_iac = rp->num_iac;
625
626 bt_dev_dbg(hdev, "num iac %d", hdev->num_iac);
627
628 return rp->status;
629 }
630
hci_cc_write_ssp_mode(struct hci_dev * hdev,void * data,struct sk_buff * skb)631 static u8 hci_cc_write_ssp_mode(struct hci_dev *hdev, void *data,
632 struct sk_buff *skb)
633 {
634 struct hci_ev_status *rp = data;
635 struct hci_cp_write_ssp_mode *sent;
636
637 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
638
639 sent = hci_sent_cmd_data(hdev, HCI_OP_WRITE_SSP_MODE);
640 if (!sent)
641 return rp->status;
642
643 hci_dev_lock(hdev);
644
645 if (!rp->status) {
646 if (sent->mode)
647 hdev->features[1][0] |= LMP_HOST_SSP;
648 else
649 hdev->features[1][0] &= ~LMP_HOST_SSP;
650 }
651
652 if (!rp->status) {
653 if (sent->mode)
654 hci_dev_set_flag(hdev, HCI_SSP_ENABLED);
655 else
656 hci_dev_clear_flag(hdev, HCI_SSP_ENABLED);
657 }
658
659 hci_dev_unlock(hdev);
660
661 return rp->status;
662 }
663
hci_cc_write_sc_support(struct hci_dev * hdev,void * data,struct sk_buff * skb)664 static u8 hci_cc_write_sc_support(struct hci_dev *hdev, void *data,
665 struct sk_buff *skb)
666 {
667 struct hci_ev_status *rp = data;
668 struct hci_cp_write_sc_support *sent;
669
670 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
671
672 sent = hci_sent_cmd_data(hdev, HCI_OP_WRITE_SC_SUPPORT);
673 if (!sent)
674 return rp->status;
675
676 hci_dev_lock(hdev);
677
678 if (!rp->status) {
679 if (sent->support)
680 hdev->features[1][0] |= LMP_HOST_SC;
681 else
682 hdev->features[1][0] &= ~LMP_HOST_SC;
683 }
684
685 if (!hci_dev_test_flag(hdev, HCI_MGMT) && !rp->status) {
686 if (sent->support)
687 hci_dev_set_flag(hdev, HCI_SC_ENABLED);
688 else
689 hci_dev_clear_flag(hdev, HCI_SC_ENABLED);
690 }
691
692 hci_dev_unlock(hdev);
693
694 return rp->status;
695 }
696
hci_cc_read_local_version(struct hci_dev * hdev,void * data,struct sk_buff * skb)697 static u8 hci_cc_read_local_version(struct hci_dev *hdev, void *data,
698 struct sk_buff *skb)
699 {
700 struct hci_rp_read_local_version *rp = data;
701
702 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
703
704 if (rp->status)
705 return rp->status;
706
707 if (hci_dev_test_flag(hdev, HCI_SETUP) ||
708 hci_dev_test_flag(hdev, HCI_CONFIG)) {
709 hdev->hci_ver = rp->hci_ver;
710 hdev->hci_rev = __le16_to_cpu(rp->hci_rev);
711 hdev->lmp_ver = rp->lmp_ver;
712 hdev->manufacturer = __le16_to_cpu(rp->manufacturer);
713 hdev->lmp_subver = __le16_to_cpu(rp->lmp_subver);
714 }
715
716 return rp->status;
717 }
718
hci_cc_read_enc_key_size(struct hci_dev * hdev,void * data,struct sk_buff * skb)719 static u8 hci_cc_read_enc_key_size(struct hci_dev *hdev, void *data,
720 struct sk_buff *skb)
721 {
722 struct hci_rp_read_enc_key_size *rp = data;
723 struct hci_conn *conn;
724 u16 handle;
725 u8 status = rp->status;
726
727 bt_dev_dbg(hdev, "status 0x%2.2x", status);
728
729 handle = le16_to_cpu(rp->handle);
730
731 hci_dev_lock(hdev);
732
733 conn = hci_conn_hash_lookup_handle(hdev, handle);
734 if (!conn) {
735 status = 0xFF;
736 goto done;
737 }
738
739 /* While unexpected, the read_enc_key_size command may fail. The most
740 * secure approach is to then assume the key size is 0 to force a
741 * disconnection.
742 */
743 if (status) {
744 bt_dev_err(hdev, "failed to read key size for handle %u",
745 handle);
746 conn->enc_key_size = 0;
747 } else {
748 u8 *key_enc_size = hci_conn_key_enc_size(conn);
749
750 conn->enc_key_size = rp->key_size;
751 status = 0;
752
753 /* Attempt to check if the key size is too small or if it has
754 * been downgraded from the last time it was stored as part of
755 * the link_key.
756 */
757 if (conn->enc_key_size < hdev->min_enc_key_size ||
758 (key_enc_size && conn->enc_key_size < *key_enc_size)) {
759 /* As slave role, the conn->state has been set to
760 * BT_CONNECTED and l2cap conn req might not be received
761 * yet, at this moment the l2cap layer almost does
762 * nothing with the non-zero status.
763 * So we also clear encrypt related bits, and then the
764 * handler of l2cap conn req will get the right secure
765 * state at a later time.
766 */
767 status = HCI_ERROR_AUTH_FAILURE;
768 clear_bit(HCI_CONN_ENCRYPT, &conn->flags);
769 clear_bit(HCI_CONN_AES_CCM, &conn->flags);
770 }
771
772 /* Update the key encryption size with the connection one */
773 if (key_enc_size && *key_enc_size != conn->enc_key_size)
774 *key_enc_size = conn->enc_key_size;
775 }
776
777 hci_encrypt_cfm(conn, status);
778
779 done:
780 hci_dev_unlock(hdev);
781
782 return status;
783 }
784
hci_cc_read_local_commands(struct hci_dev * hdev,void * data,struct sk_buff * skb)785 static u8 hci_cc_read_local_commands(struct hci_dev *hdev, void *data,
786 struct sk_buff *skb)
787 {
788 struct hci_rp_read_local_commands *rp = data;
789
790 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
791
792 if (rp->status)
793 return rp->status;
794
795 if (hci_dev_test_flag(hdev, HCI_SETUP) ||
796 hci_dev_test_flag(hdev, HCI_CONFIG))
797 memcpy(hdev->commands, rp->commands, sizeof(hdev->commands));
798
799 return rp->status;
800 }
801
hci_cc_read_auth_payload_timeout(struct hci_dev * hdev,void * data,struct sk_buff * skb)802 static u8 hci_cc_read_auth_payload_timeout(struct hci_dev *hdev, void *data,
803 struct sk_buff *skb)
804 {
805 struct hci_rp_read_auth_payload_to *rp = data;
806 struct hci_conn *conn;
807
808 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
809
810 if (rp->status)
811 return rp->status;
812
813 hci_dev_lock(hdev);
814
815 conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(rp->handle));
816 if (conn)
817 conn->auth_payload_timeout = __le16_to_cpu(rp->timeout);
818
819 hci_dev_unlock(hdev);
820
821 return rp->status;
822 }
823
hci_cc_write_auth_payload_timeout(struct hci_dev * hdev,void * data,struct sk_buff * skb)824 static u8 hci_cc_write_auth_payload_timeout(struct hci_dev *hdev, void *data,
825 struct sk_buff *skb)
826 {
827 struct hci_rp_write_auth_payload_to *rp = data;
828 struct hci_conn *conn;
829 void *sent;
830
831 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
832
833 sent = hci_sent_cmd_data(hdev, HCI_OP_WRITE_AUTH_PAYLOAD_TO);
834 if (!sent)
835 return rp->status;
836
837 hci_dev_lock(hdev);
838
839 conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(rp->handle));
840 if (!conn) {
841 rp->status = 0xff;
842 goto unlock;
843 }
844
845 if (!rp->status)
846 conn->auth_payload_timeout = get_unaligned_le16(sent + 2);
847
848 unlock:
849 hci_dev_unlock(hdev);
850
851 return rp->status;
852 }
853
hci_cc_read_local_features(struct hci_dev * hdev,void * data,struct sk_buff * skb)854 static u8 hci_cc_read_local_features(struct hci_dev *hdev, void *data,
855 struct sk_buff *skb)
856 {
857 struct hci_rp_read_local_features *rp = data;
858
859 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
860
861 if (rp->status)
862 return rp->status;
863
864 memcpy(hdev->features, rp->features, 8);
865
866 /* Adjust default settings according to features
867 * supported by device. */
868
869 if (hdev->features[0][0] & LMP_3SLOT)
870 hdev->pkt_type |= (HCI_DM3 | HCI_DH3);
871
872 if (hdev->features[0][0] & LMP_5SLOT)
873 hdev->pkt_type |= (HCI_DM5 | HCI_DH5);
874
875 if (hdev->features[0][1] & LMP_HV2) {
876 hdev->pkt_type |= (HCI_HV2);
877 hdev->esco_type |= (ESCO_HV2);
878 }
879
880 if (hdev->features[0][1] & LMP_HV3) {
881 hdev->pkt_type |= (HCI_HV3);
882 hdev->esco_type |= (ESCO_HV3);
883 }
884
885 if (lmp_esco_capable(hdev))
886 hdev->esco_type |= (ESCO_EV3);
887
888 if (hdev->features[0][4] & LMP_EV4)
889 hdev->esco_type |= (ESCO_EV4);
890
891 if (hdev->features[0][4] & LMP_EV5)
892 hdev->esco_type |= (ESCO_EV5);
893
894 if (hdev->features[0][5] & LMP_EDR_ESCO_2M)
895 hdev->esco_type |= (ESCO_2EV3);
896
897 if (hdev->features[0][5] & LMP_EDR_ESCO_3M)
898 hdev->esco_type |= (ESCO_3EV3);
899
900 if (hdev->features[0][5] & LMP_EDR_3S_ESCO)
901 hdev->esco_type |= (ESCO_2EV5 | ESCO_3EV5);
902
903 return rp->status;
904 }
905
hci_cc_read_local_ext_features(struct hci_dev * hdev,void * data,struct sk_buff * skb)906 static u8 hci_cc_read_local_ext_features(struct hci_dev *hdev, void *data,
907 struct sk_buff *skb)
908 {
909 struct hci_rp_read_local_ext_features *rp = data;
910
911 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
912
913 if (rp->status)
914 return rp->status;
915
916 if (hdev->max_page < rp->max_page) {
917 if (hci_test_quirk(hdev,
918 HCI_QUIRK_BROKEN_LOCAL_EXT_FEATURES_PAGE_2))
919 bt_dev_warn(hdev, "broken local ext features page 2");
920 else
921 hdev->max_page = rp->max_page;
922 }
923
924 if (rp->page < HCI_MAX_PAGES)
925 memcpy(hdev->features[rp->page], rp->features, 8);
926
927 return rp->status;
928 }
929
hci_cc_read_buffer_size(struct hci_dev * hdev,void * data,struct sk_buff * skb)930 static u8 hci_cc_read_buffer_size(struct hci_dev *hdev, void *data,
931 struct sk_buff *skb)
932 {
933 struct hci_rp_read_buffer_size *rp = data;
934
935 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
936
937 if (rp->status)
938 return rp->status;
939
940 hdev->acl_mtu = __le16_to_cpu(rp->acl_mtu);
941 hdev->sco_mtu = rp->sco_mtu;
942 hdev->acl_pkts = __le16_to_cpu(rp->acl_max_pkt);
943 hdev->sco_pkts = __le16_to_cpu(rp->sco_max_pkt);
944
945 if (hci_test_quirk(hdev, HCI_QUIRK_FIXUP_BUFFER_SIZE)) {
946 hdev->sco_mtu = 64;
947 hdev->sco_pkts = 8;
948 }
949
950 if (!read_voice_setting_capable(hdev))
951 hdev->sco_pkts = 0;
952
953 hdev->acl_cnt = hdev->acl_pkts;
954 hdev->sco_cnt = hdev->sco_pkts;
955
956 BT_DBG("%s acl mtu %d:%d sco mtu %d:%d", hdev->name, hdev->acl_mtu,
957 hdev->acl_pkts, hdev->sco_mtu, hdev->sco_pkts);
958
959 if (!hdev->acl_mtu || !hdev->acl_pkts)
960 return HCI_ERROR_INVALID_PARAMETERS;
961
962 return rp->status;
963 }
964
hci_cc_read_bd_addr(struct hci_dev * hdev,void * data,struct sk_buff * skb)965 static u8 hci_cc_read_bd_addr(struct hci_dev *hdev, void *data,
966 struct sk_buff *skb)
967 {
968 struct hci_rp_read_bd_addr *rp = data;
969
970 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
971
972 if (rp->status)
973 return rp->status;
974
975 if (test_bit(HCI_INIT, &hdev->flags))
976 bacpy(&hdev->bdaddr, &rp->bdaddr);
977
978 if (hci_dev_test_flag(hdev, HCI_SETUP))
979 bacpy(&hdev->setup_addr, &rp->bdaddr);
980
981 return rp->status;
982 }
983
hci_cc_read_local_pairing_opts(struct hci_dev * hdev,void * data,struct sk_buff * skb)984 static u8 hci_cc_read_local_pairing_opts(struct hci_dev *hdev, void *data,
985 struct sk_buff *skb)
986 {
987 struct hci_rp_read_local_pairing_opts *rp = data;
988
989 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
990
991 if (rp->status)
992 return rp->status;
993
994 if (hci_dev_test_flag(hdev, HCI_SETUP) ||
995 hci_dev_test_flag(hdev, HCI_CONFIG)) {
996 hdev->pairing_opts = rp->pairing_opts;
997 hdev->max_enc_key_size = rp->max_key_size;
998 }
999
1000 return rp->status;
1001 }
1002
hci_cc_read_page_scan_activity(struct hci_dev * hdev,void * data,struct sk_buff * skb)1003 static u8 hci_cc_read_page_scan_activity(struct hci_dev *hdev, void *data,
1004 struct sk_buff *skb)
1005 {
1006 struct hci_rp_read_page_scan_activity *rp = data;
1007
1008 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
1009
1010 if (rp->status)
1011 return rp->status;
1012
1013 if (test_bit(HCI_INIT, &hdev->flags)) {
1014 hdev->page_scan_interval = __le16_to_cpu(rp->interval);
1015 hdev->page_scan_window = __le16_to_cpu(rp->window);
1016 }
1017
1018 return rp->status;
1019 }
1020
hci_cc_write_page_scan_activity(struct hci_dev * hdev,void * data,struct sk_buff * skb)1021 static u8 hci_cc_write_page_scan_activity(struct hci_dev *hdev, void *data,
1022 struct sk_buff *skb)
1023 {
1024 struct hci_ev_status *rp = data;
1025 struct hci_cp_write_page_scan_activity *sent;
1026
1027 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
1028
1029 if (rp->status)
1030 return rp->status;
1031
1032 sent = hci_sent_cmd_data(hdev, HCI_OP_WRITE_PAGE_SCAN_ACTIVITY);
1033 if (!sent)
1034 return rp->status;
1035
1036 hdev->page_scan_interval = __le16_to_cpu(sent->interval);
1037 hdev->page_scan_window = __le16_to_cpu(sent->window);
1038
1039 return rp->status;
1040 }
1041
hci_cc_read_page_scan_type(struct hci_dev * hdev,void * data,struct sk_buff * skb)1042 static u8 hci_cc_read_page_scan_type(struct hci_dev *hdev, void *data,
1043 struct sk_buff *skb)
1044 {
1045 struct hci_rp_read_page_scan_type *rp = data;
1046
1047 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
1048
1049 if (rp->status)
1050 return rp->status;
1051
1052 if (test_bit(HCI_INIT, &hdev->flags))
1053 hdev->page_scan_type = rp->type;
1054
1055 return rp->status;
1056 }
1057
hci_cc_write_page_scan_type(struct hci_dev * hdev,void * data,struct sk_buff * skb)1058 static u8 hci_cc_write_page_scan_type(struct hci_dev *hdev, void *data,
1059 struct sk_buff *skb)
1060 {
1061 struct hci_ev_status *rp = data;
1062 u8 *type;
1063
1064 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
1065
1066 if (rp->status)
1067 return rp->status;
1068
1069 type = hci_sent_cmd_data(hdev, HCI_OP_WRITE_PAGE_SCAN_TYPE);
1070 if (type)
1071 hdev->page_scan_type = *type;
1072
1073 return rp->status;
1074 }
1075
hci_cc_read_clock(struct hci_dev * hdev,void * data,struct sk_buff * skb)1076 static u8 hci_cc_read_clock(struct hci_dev *hdev, void *data,
1077 struct sk_buff *skb)
1078 {
1079 struct hci_rp_read_clock *rp = data;
1080 struct hci_cp_read_clock *cp;
1081 struct hci_conn *conn;
1082
1083 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
1084
1085 if (rp->status)
1086 return rp->status;
1087
1088 hci_dev_lock(hdev);
1089
1090 cp = hci_sent_cmd_data(hdev, HCI_OP_READ_CLOCK);
1091 if (!cp)
1092 goto unlock;
1093
1094 if (cp->which == 0x00) {
1095 hdev->clock = le32_to_cpu(rp->clock);
1096 goto unlock;
1097 }
1098
1099 conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(rp->handle));
1100 if (conn) {
1101 conn->clock = le32_to_cpu(rp->clock);
1102 conn->clock_accuracy = le16_to_cpu(rp->accuracy);
1103 }
1104
1105 unlock:
1106 hci_dev_unlock(hdev);
1107 return rp->status;
1108 }
1109
hci_cc_read_inq_rsp_tx_power(struct hci_dev * hdev,void * data,struct sk_buff * skb)1110 static u8 hci_cc_read_inq_rsp_tx_power(struct hci_dev *hdev, void *data,
1111 struct sk_buff *skb)
1112 {
1113 struct hci_rp_read_inq_rsp_tx_power *rp = data;
1114
1115 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
1116
1117 if (rp->status)
1118 return rp->status;
1119
1120 hdev->inq_tx_power = rp->tx_power;
1121
1122 return rp->status;
1123 }
1124
hci_cc_read_def_err_data_reporting(struct hci_dev * hdev,void * data,struct sk_buff * skb)1125 static u8 hci_cc_read_def_err_data_reporting(struct hci_dev *hdev, void *data,
1126 struct sk_buff *skb)
1127 {
1128 struct hci_rp_read_def_err_data_reporting *rp = data;
1129
1130 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
1131
1132 if (rp->status)
1133 return rp->status;
1134
1135 hdev->err_data_reporting = rp->err_data_reporting;
1136
1137 return rp->status;
1138 }
1139
hci_cc_write_def_err_data_reporting(struct hci_dev * hdev,void * data,struct sk_buff * skb)1140 static u8 hci_cc_write_def_err_data_reporting(struct hci_dev *hdev, void *data,
1141 struct sk_buff *skb)
1142 {
1143 struct hci_ev_status *rp = data;
1144 struct hci_cp_write_def_err_data_reporting *cp;
1145
1146 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
1147
1148 if (rp->status)
1149 return rp->status;
1150
1151 cp = hci_sent_cmd_data(hdev, HCI_OP_WRITE_DEF_ERR_DATA_REPORTING);
1152 if (!cp)
1153 return rp->status;
1154
1155 hdev->err_data_reporting = cp->err_data_reporting;
1156
1157 return rp->status;
1158 }
1159
hci_cc_pin_code_reply(struct hci_dev * hdev,void * data,struct sk_buff * skb)1160 static u8 hci_cc_pin_code_reply(struct hci_dev *hdev, void *data,
1161 struct sk_buff *skb)
1162 {
1163 struct hci_rp_pin_code_reply *rp = data;
1164 struct hci_cp_pin_code_reply *cp;
1165 struct hci_conn *conn;
1166
1167 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
1168
1169 hci_dev_lock(hdev);
1170
1171 if (hci_dev_test_flag(hdev, HCI_MGMT))
1172 mgmt_pin_code_reply_complete(hdev, &rp->bdaddr, rp->status);
1173
1174 if (rp->status)
1175 goto unlock;
1176
1177 cp = hci_sent_cmd_data(hdev, HCI_OP_PIN_CODE_REPLY);
1178 if (!cp)
1179 goto unlock;
1180
1181 conn = hci_conn_hash_lookup_ba(hdev, ACL_LINK, &cp->bdaddr);
1182 if (conn)
1183 conn->pin_length = cp->pin_len;
1184
1185 unlock:
1186 hci_dev_unlock(hdev);
1187 return rp->status;
1188 }
1189
hci_cc_pin_code_neg_reply(struct hci_dev * hdev,void * data,struct sk_buff * skb)1190 static u8 hci_cc_pin_code_neg_reply(struct hci_dev *hdev, void *data,
1191 struct sk_buff *skb)
1192 {
1193 struct hci_rp_pin_code_neg_reply *rp = data;
1194
1195 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
1196
1197 hci_dev_lock(hdev);
1198
1199 if (hci_dev_test_flag(hdev, HCI_MGMT))
1200 mgmt_pin_code_neg_reply_complete(hdev, &rp->bdaddr,
1201 rp->status);
1202
1203 hci_dev_unlock(hdev);
1204
1205 return rp->status;
1206 }
1207
hci_cc_le_read_buffer_size(struct hci_dev * hdev,void * data,struct sk_buff * skb)1208 static u8 hci_cc_le_read_buffer_size(struct hci_dev *hdev, void *data,
1209 struct sk_buff *skb)
1210 {
1211 struct hci_rp_le_read_buffer_size *rp = data;
1212
1213 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
1214
1215 if (rp->status)
1216 return rp->status;
1217
1218 hdev->le_mtu = __le16_to_cpu(rp->le_mtu);
1219 hdev->le_pkts = rp->le_max_pkt;
1220
1221 hdev->le_cnt = hdev->le_pkts;
1222
1223 BT_DBG("%s le mtu %d:%d", hdev->name, hdev->le_mtu, hdev->le_pkts);
1224
1225 if (hdev->le_mtu && hdev->le_mtu < HCI_MIN_LE_MTU)
1226 return HCI_ERROR_INVALID_PARAMETERS;
1227
1228 return rp->status;
1229 }
1230
hci_cc_le_read_local_features(struct hci_dev * hdev,void * data,struct sk_buff * skb)1231 static u8 hci_cc_le_read_local_features(struct hci_dev *hdev, void *data,
1232 struct sk_buff *skb)
1233 {
1234 struct hci_rp_le_read_local_features *rp = data;
1235
1236 BT_DBG("%s status 0x%2.2x", hdev->name, rp->status);
1237
1238 if (rp->status)
1239 return rp->status;
1240
1241 memcpy(hdev->le_features, rp->features, 8);
1242
1243 return rp->status;
1244 }
1245
hci_cc_le_read_conn_interval(struct hci_dev * hdev,void * data,struct sk_buff * skb)1246 static u8 hci_cc_le_read_conn_interval(struct hci_dev *hdev, void *data,
1247 struct sk_buff *skb)
1248 {
1249 struct hci_rp_le_read_conn_interval *rp = data;
1250 u16 min_interval = 0;
1251 int i;
1252
1253 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
1254
1255 if (rp->status)
1256 return rp->status;
1257
1258 if (skb->len < flex_array_size(rp, grps, rp->num_grps)) {
1259 bt_dev_err(hdev, "Invalid response length for 0x%4.4x",
1260 HCI_OP_LE_READ_CONN_INTERVAL);
1261 return HCI_ERROR_UNSPECIFIED;
1262 }
1263
1264 /* Store the smallest minimum supported connection interval reported by
1265 * the controller so the default rate parameters can be clamped to it.
1266 */
1267 for (i = 0; i < rp->num_grps; i++) {
1268 u16 min = le16_to_cpu(rp->grps[i].min);
1269
1270 if (!min_interval || min < min_interval)
1271 min_interval = min;
1272 }
1273
1274 hdev->le_min_rate_interval = min_interval;
1275
1276 return rp->status;
1277 }
1278
hci_cc_le_read_adv_tx_power(struct hci_dev * hdev,void * data,struct sk_buff * skb)1279 static u8 hci_cc_le_read_adv_tx_power(struct hci_dev *hdev, void *data,
1280 struct sk_buff *skb)
1281 {
1282 struct hci_rp_le_read_adv_tx_power *rp = data;
1283
1284 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
1285
1286 if (rp->status)
1287 return rp->status;
1288
1289 hdev->adv_tx_power = rp->tx_power;
1290
1291 return rp->status;
1292 }
1293
hci_cc_user_confirm_reply(struct hci_dev * hdev,void * data,struct sk_buff * skb)1294 static u8 hci_cc_user_confirm_reply(struct hci_dev *hdev, void *data,
1295 struct sk_buff *skb)
1296 {
1297 struct hci_rp_user_confirm_reply *rp = data;
1298
1299 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
1300
1301 hci_dev_lock(hdev);
1302
1303 if (hci_dev_test_flag(hdev, HCI_MGMT))
1304 mgmt_user_confirm_reply_complete(hdev, &rp->bdaddr, ACL_LINK, 0,
1305 rp->status);
1306
1307 hci_dev_unlock(hdev);
1308
1309 return rp->status;
1310 }
1311
hci_cc_user_confirm_neg_reply(struct hci_dev * hdev,void * data,struct sk_buff * skb)1312 static u8 hci_cc_user_confirm_neg_reply(struct hci_dev *hdev, void *data,
1313 struct sk_buff *skb)
1314 {
1315 struct hci_rp_user_confirm_reply *rp = data;
1316
1317 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
1318
1319 hci_dev_lock(hdev);
1320
1321 if (hci_dev_test_flag(hdev, HCI_MGMT))
1322 mgmt_user_confirm_neg_reply_complete(hdev, &rp->bdaddr,
1323 ACL_LINK, 0, rp->status);
1324
1325 hci_dev_unlock(hdev);
1326
1327 return rp->status;
1328 }
1329
hci_cc_user_passkey_reply(struct hci_dev * hdev,void * data,struct sk_buff * skb)1330 static u8 hci_cc_user_passkey_reply(struct hci_dev *hdev, void *data,
1331 struct sk_buff *skb)
1332 {
1333 struct hci_rp_user_confirm_reply *rp = data;
1334
1335 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
1336
1337 hci_dev_lock(hdev);
1338
1339 if (hci_dev_test_flag(hdev, HCI_MGMT))
1340 mgmt_user_passkey_reply_complete(hdev, &rp->bdaddr, ACL_LINK,
1341 0, rp->status);
1342
1343 hci_dev_unlock(hdev);
1344
1345 return rp->status;
1346 }
1347
hci_cc_user_passkey_neg_reply(struct hci_dev * hdev,void * data,struct sk_buff * skb)1348 static u8 hci_cc_user_passkey_neg_reply(struct hci_dev *hdev, void *data,
1349 struct sk_buff *skb)
1350 {
1351 struct hci_rp_user_confirm_reply *rp = data;
1352
1353 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
1354
1355 hci_dev_lock(hdev);
1356
1357 if (hci_dev_test_flag(hdev, HCI_MGMT))
1358 mgmt_user_passkey_neg_reply_complete(hdev, &rp->bdaddr,
1359 ACL_LINK, 0, rp->status);
1360
1361 hci_dev_unlock(hdev);
1362
1363 return rp->status;
1364 }
1365
hci_cc_read_local_oob_data(struct hci_dev * hdev,void * data,struct sk_buff * skb)1366 static u8 hci_cc_read_local_oob_data(struct hci_dev *hdev, void *data,
1367 struct sk_buff *skb)
1368 {
1369 struct hci_rp_read_local_oob_data *rp = data;
1370
1371 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
1372
1373 return rp->status;
1374 }
1375
hci_cc_read_local_oob_ext_data(struct hci_dev * hdev,void * data,struct sk_buff * skb)1376 static u8 hci_cc_read_local_oob_ext_data(struct hci_dev *hdev, void *data,
1377 struct sk_buff *skb)
1378 {
1379 struct hci_rp_read_local_oob_ext_data *rp = data;
1380
1381 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
1382
1383 return rp->status;
1384 }
1385
hci_cc_le_set_random_addr(struct hci_dev * hdev,void * data,struct sk_buff * skb)1386 static u8 hci_cc_le_set_random_addr(struct hci_dev *hdev, void *data,
1387 struct sk_buff *skb)
1388 {
1389 struct hci_ev_status *rp = data;
1390 bdaddr_t *sent;
1391
1392 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
1393
1394 if (rp->status)
1395 return rp->status;
1396
1397 sent = hci_sent_cmd_data(hdev, HCI_OP_LE_SET_RANDOM_ADDR);
1398 if (!sent)
1399 return rp->status;
1400
1401 hci_dev_lock(hdev);
1402
1403 bacpy(&hdev->random_addr, sent);
1404
1405 if (!bacmp(&hdev->rpa, sent)) {
1406 hci_dev_clear_flag(hdev, HCI_RPA_EXPIRED);
1407 queue_delayed_work(hdev->workqueue, &hdev->rpa_expired,
1408 secs_to_jiffies(hdev->rpa_timeout));
1409 }
1410
1411 hci_dev_unlock(hdev);
1412
1413 return rp->status;
1414 }
1415
hci_cc_le_set_default_phy(struct hci_dev * hdev,void * data,struct sk_buff * skb)1416 static u8 hci_cc_le_set_default_phy(struct hci_dev *hdev, void *data,
1417 struct sk_buff *skb)
1418 {
1419 struct hci_ev_status *rp = data;
1420 struct hci_cp_le_set_default_phy *cp;
1421
1422 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
1423
1424 if (rp->status)
1425 return rp->status;
1426
1427 cp = hci_sent_cmd_data(hdev, HCI_OP_LE_SET_DEFAULT_PHY);
1428 if (!cp)
1429 return rp->status;
1430
1431 hci_dev_lock(hdev);
1432
1433 hdev->le_tx_def_phys = cp->tx_phys;
1434 hdev->le_rx_def_phys = cp->rx_phys;
1435
1436 hci_dev_unlock(hdev);
1437
1438 return rp->status;
1439 }
1440
hci_cc_le_set_adv_set_random_addr(struct hci_dev * hdev,void * data,struct sk_buff * skb)1441 static u8 hci_cc_le_set_adv_set_random_addr(struct hci_dev *hdev, void *data,
1442 struct sk_buff *skb)
1443 {
1444 struct hci_ev_status *rp = data;
1445 struct hci_cp_le_set_adv_set_rand_addr *cp;
1446 struct adv_info *adv;
1447
1448 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
1449
1450 if (rp->status)
1451 return rp->status;
1452
1453 cp = hci_sent_cmd_data(hdev, HCI_OP_LE_SET_ADV_SET_RAND_ADDR);
1454 /* Update only in case the adv instance since handle 0x00 shall be using
1455 * HCI_OP_LE_SET_RANDOM_ADDR since that allows both extended and
1456 * non-extended adverting.
1457 */
1458 if (!cp || !cp->handle)
1459 return rp->status;
1460
1461 hci_dev_lock(hdev);
1462
1463 adv = hci_find_adv_instance(hdev, cp->handle);
1464 if (adv) {
1465 bacpy(&adv->random_addr, &cp->bdaddr);
1466 if (!bacmp(&hdev->rpa, &cp->bdaddr)) {
1467 adv->rpa_expired = false;
1468 queue_delayed_work(hdev->workqueue,
1469 &adv->rpa_expired_cb,
1470 secs_to_jiffies(hdev->rpa_timeout));
1471 }
1472 }
1473
1474 hci_dev_unlock(hdev);
1475
1476 return rp->status;
1477 }
1478
hci_cc_le_remove_adv_set(struct hci_dev * hdev,void * data,struct sk_buff * skb)1479 static u8 hci_cc_le_remove_adv_set(struct hci_dev *hdev, void *data,
1480 struct sk_buff *skb)
1481 {
1482 struct hci_ev_status *rp = data;
1483 u8 *instance;
1484 int err;
1485
1486 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
1487
1488 if (rp->status)
1489 return rp->status;
1490
1491 instance = hci_sent_cmd_data(hdev, HCI_OP_LE_REMOVE_ADV_SET);
1492 if (!instance)
1493 return rp->status;
1494
1495 hci_dev_lock(hdev);
1496
1497 err = hci_remove_adv_instance(hdev, *instance);
1498 if (!err)
1499 mgmt_advertising_removed(hci_skb_sk(hdev->sent_cmd), hdev,
1500 *instance);
1501
1502 hci_dev_unlock(hdev);
1503
1504 return rp->status;
1505 }
1506
hci_cc_le_clear_adv_sets(struct hci_dev * hdev,void * data,struct sk_buff * skb)1507 static u8 hci_cc_le_clear_adv_sets(struct hci_dev *hdev, void *data,
1508 struct sk_buff *skb)
1509 {
1510 struct hci_ev_status *rp = data;
1511 struct adv_info *adv, *n;
1512 int err;
1513
1514 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
1515
1516 if (rp->status)
1517 return rp->status;
1518
1519 if (!hci_sent_cmd_data(hdev, HCI_OP_LE_CLEAR_ADV_SETS))
1520 return rp->status;
1521
1522 hci_dev_lock(hdev);
1523
1524 list_for_each_entry_safe(adv, n, &hdev->adv_instances, list) {
1525 u8 instance = adv->instance;
1526
1527 err = hci_remove_adv_instance(hdev, instance);
1528 if (!err)
1529 mgmt_advertising_removed(hci_skb_sk(hdev->sent_cmd),
1530 hdev, instance);
1531 }
1532
1533 hci_dev_unlock(hdev);
1534
1535 return rp->status;
1536 }
1537
hci_cc_le_read_transmit_power(struct hci_dev * hdev,void * data,struct sk_buff * skb)1538 static u8 hci_cc_le_read_transmit_power(struct hci_dev *hdev, void *data,
1539 struct sk_buff *skb)
1540 {
1541 struct hci_rp_le_read_transmit_power *rp = data;
1542
1543 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
1544
1545 if (rp->status)
1546 return rp->status;
1547
1548 hdev->min_le_tx_power = rp->min_le_tx_power;
1549 hdev->max_le_tx_power = rp->max_le_tx_power;
1550
1551 return rp->status;
1552 }
1553
hci_cc_le_set_privacy_mode(struct hci_dev * hdev,void * data,struct sk_buff * skb)1554 static u8 hci_cc_le_set_privacy_mode(struct hci_dev *hdev, void *data,
1555 struct sk_buff *skb)
1556 {
1557 struct hci_ev_status *rp = data;
1558 struct hci_cp_le_set_privacy_mode *cp;
1559 struct hci_conn_params *params;
1560
1561 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
1562
1563 if (rp->status)
1564 return rp->status;
1565
1566 cp = hci_sent_cmd_data(hdev, HCI_OP_LE_SET_PRIVACY_MODE);
1567 if (!cp)
1568 return rp->status;
1569
1570 hci_dev_lock(hdev);
1571
1572 params = hci_conn_params_lookup(hdev, &cp->bdaddr, cp->bdaddr_type);
1573 if (params)
1574 WRITE_ONCE(params->privacy_mode, cp->mode);
1575
1576 hci_dev_unlock(hdev);
1577
1578 return rp->status;
1579 }
1580
hci_cc_le_set_adv_enable(struct hci_dev * hdev,void * data,struct sk_buff * skb)1581 static u8 hci_cc_le_set_adv_enable(struct hci_dev *hdev, void *data,
1582 struct sk_buff *skb)
1583 {
1584 struct hci_ev_status *rp = data;
1585 __u8 *sent;
1586
1587 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
1588
1589 if (rp->status)
1590 return rp->status;
1591
1592 sent = hci_sent_cmd_data(hdev, HCI_OP_LE_SET_ADV_ENABLE);
1593 if (!sent)
1594 return rp->status;
1595
1596 hci_dev_lock(hdev);
1597
1598 /* If we're doing connection initiation as peripheral. Set a
1599 * timeout in case something goes wrong.
1600 */
1601 if (*sent) {
1602 struct hci_conn *conn;
1603
1604 hci_dev_set_flag(hdev, HCI_LE_ADV);
1605
1606 conn = hci_lookup_le_connect(hdev);
1607 if (conn)
1608 queue_delayed_work(hdev->workqueue,
1609 &conn->le_conn_timeout,
1610 conn->conn_timeout);
1611 } else {
1612 hci_dev_clear_flag(hdev, HCI_LE_ADV);
1613 }
1614
1615 hci_dev_unlock(hdev);
1616
1617 return rp->status;
1618 }
1619
hci_cc_le_set_ext_adv_enable(struct hci_dev * hdev,void * data,struct sk_buff * skb)1620 static u8 hci_cc_le_set_ext_adv_enable(struct hci_dev *hdev, void *data,
1621 struct sk_buff *skb)
1622 {
1623 struct hci_cp_le_set_ext_adv_enable *cp;
1624 struct hci_cp_ext_adv_set *set;
1625 struct adv_info *adv = NULL, *n;
1626 struct hci_ev_status *rp = data;
1627
1628 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
1629
1630 if (rp->status)
1631 return rp->status;
1632
1633 cp = hci_sent_cmd_data(hdev, HCI_OP_LE_SET_EXT_ADV_ENABLE);
1634 if (!cp)
1635 return rp->status;
1636
1637 set = (void *)cp->data;
1638
1639 hci_dev_lock(hdev);
1640
1641 if (cp->num_of_sets)
1642 adv = hci_find_adv_instance(hdev, set->handle);
1643
1644 if (cp->enable) {
1645 struct hci_conn *conn;
1646
1647 hci_dev_set_flag(hdev, HCI_LE_ADV);
1648
1649 if (adv)
1650 adv->enabled = true;
1651 else if (!set->handle)
1652 hci_dev_set_flag(hdev, HCI_LE_ADV_0);
1653
1654 conn = hci_lookup_le_connect(hdev);
1655 if (conn)
1656 queue_delayed_work(hdev->workqueue,
1657 &conn->le_conn_timeout,
1658 conn->conn_timeout);
1659 } else {
1660 if (cp->num_of_sets) {
1661 if (adv)
1662 adv->enabled = false;
1663 else if (!set->handle)
1664 hci_dev_clear_flag(hdev, HCI_LE_ADV_0);
1665
1666 /* If just one instance was disabled check if there are
1667 * any other instance enabled before clearing HCI_LE_ADV
1668 */
1669 list_for_each_entry_safe(adv, n, &hdev->adv_instances,
1670 list) {
1671 if (adv->enabled)
1672 goto unlock;
1673 }
1674 } else {
1675 /* All instances shall be considered disabled */
1676 list_for_each_entry_safe(adv, n, &hdev->adv_instances,
1677 list)
1678 adv->enabled = false;
1679 }
1680
1681 hci_dev_clear_flag(hdev, HCI_LE_ADV);
1682 }
1683
1684 unlock:
1685 hci_dev_unlock(hdev);
1686 return rp->status;
1687 }
1688
hci_cc_le_set_scan_param(struct hci_dev * hdev,void * data,struct sk_buff * skb)1689 static u8 hci_cc_le_set_scan_param(struct hci_dev *hdev, void *data,
1690 struct sk_buff *skb)
1691 {
1692 struct hci_cp_le_set_scan_param *cp;
1693 struct hci_ev_status *rp = data;
1694
1695 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
1696
1697 if (rp->status)
1698 return rp->status;
1699
1700 cp = hci_sent_cmd_data(hdev, HCI_OP_LE_SET_SCAN_PARAM);
1701 if (!cp)
1702 return rp->status;
1703
1704 hci_dev_lock(hdev);
1705
1706 hdev->le_scan_type = cp->type;
1707
1708 hci_dev_unlock(hdev);
1709
1710 return rp->status;
1711 }
1712
hci_cc_le_set_ext_scan_param(struct hci_dev * hdev,void * data,struct sk_buff * skb)1713 static u8 hci_cc_le_set_ext_scan_param(struct hci_dev *hdev, void *data,
1714 struct sk_buff *skb)
1715 {
1716 struct hci_cp_le_set_ext_scan_params *cp;
1717 struct hci_ev_status *rp = data;
1718 struct hci_cp_le_scan_phy_params *phy_param;
1719
1720 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
1721
1722 if (rp->status)
1723 return rp->status;
1724
1725 cp = hci_sent_cmd_data(hdev, HCI_OP_LE_SET_EXT_SCAN_PARAMS);
1726 if (!cp)
1727 return rp->status;
1728
1729 phy_param = (void *)cp->data;
1730
1731 hci_dev_lock(hdev);
1732
1733 hdev->le_scan_type = phy_param->type;
1734
1735 hci_dev_unlock(hdev);
1736
1737 return rp->status;
1738 }
1739
has_pending_adv_report(struct hci_dev * hdev)1740 static bool has_pending_adv_report(struct hci_dev *hdev)
1741 {
1742 struct discovery_state *d = &hdev->discovery;
1743
1744 return bacmp(&d->last_adv_addr, BDADDR_ANY);
1745 }
1746
clear_pending_adv_report(struct hci_dev * hdev)1747 static void clear_pending_adv_report(struct hci_dev *hdev)
1748 {
1749 struct discovery_state *d = &hdev->discovery;
1750
1751 bacpy(&d->last_adv_addr, BDADDR_ANY);
1752 d->last_adv_data_len = 0;
1753 }
1754
store_pending_adv_report(struct hci_dev * hdev,bdaddr_t * bdaddr,u8 bdaddr_type,s8 rssi,u32 flags,u8 * data,u8 len)1755 static void store_pending_adv_report(struct hci_dev *hdev, bdaddr_t *bdaddr,
1756 u8 bdaddr_type, s8 rssi, u32 flags,
1757 u8 *data, u8 len)
1758 {
1759 struct discovery_state *d = &hdev->discovery;
1760
1761 if (len > max_adv_len(hdev))
1762 return;
1763
1764 bacpy(&d->last_adv_addr, bdaddr);
1765 d->last_adv_addr_type = bdaddr_type;
1766 d->last_adv_rssi = rssi;
1767 d->last_adv_flags = flags;
1768 memcpy(d->last_adv_data, data, len);
1769 d->last_adv_data_len = len;
1770 }
1771
le_set_scan_enable_complete(struct hci_dev * hdev,u8 enable)1772 static void le_set_scan_enable_complete(struct hci_dev *hdev, u8 enable)
1773 {
1774 hci_dev_lock(hdev);
1775
1776 switch (enable) {
1777 case LE_SCAN_ENABLE:
1778 hci_dev_set_flag(hdev, HCI_LE_SCAN);
1779 if (hdev->le_scan_type == LE_SCAN_ACTIVE) {
1780 clear_pending_adv_report(hdev);
1781 hci_discovery_set_state(hdev, DISCOVERY_FINDING);
1782 }
1783 break;
1784
1785 case LE_SCAN_DISABLE:
1786 /* We do this here instead of when setting DISCOVERY_STOPPED
1787 * since the latter would potentially require waiting for
1788 * inquiry to stop too.
1789 */
1790 if (has_pending_adv_report(hdev)) {
1791 struct discovery_state *d = &hdev->discovery;
1792
1793 mgmt_device_found(hdev, &d->last_adv_addr, LE_LINK,
1794 d->last_adv_addr_type, NULL,
1795 d->last_adv_rssi, d->last_adv_flags,
1796 d->last_adv_data,
1797 d->last_adv_data_len, NULL, 0, 0);
1798 }
1799
1800 /* Cancel this timer so that we don't try to disable scanning
1801 * when it's already disabled.
1802 */
1803 cancel_delayed_work(&hdev->le_scan_disable);
1804
1805 hci_dev_clear_flag(hdev, HCI_LE_SCAN);
1806
1807 if (hdev->discovery.type == DISCOV_TYPE_INTERLEAVED &&
1808 hci_test_quirk(hdev, HCI_QUIRK_SIMULTANEOUS_DISCOVERY) &&
1809 !test_bit(HCI_INQUIRY, &hdev->flags) &&
1810 hdev->discovery.state == DISCOVERY_FINDING) {
1811 hci_discovery_set_state(hdev, DISCOVERY_STOPPED);
1812 }
1813
1814 /* The HCI_LE_SCAN_INTERRUPTED flag indicates that we
1815 * interrupted scanning due to a connect request. Mark
1816 * therefore discovery as stopped.
1817 */
1818 if (hci_dev_test_and_clear_flag(hdev, HCI_LE_SCAN_INTERRUPTED))
1819 hci_discovery_set_state(hdev, DISCOVERY_STOPPED);
1820 else if (!hci_dev_test_flag(hdev, HCI_LE_ADV) &&
1821 hdev->discovery.state == DISCOVERY_FINDING)
1822 queue_work(hdev->workqueue, &hdev->reenable_adv_work);
1823
1824 break;
1825
1826 default:
1827 bt_dev_err(hdev, "use of reserved LE_Scan_Enable param %d",
1828 enable);
1829 break;
1830 }
1831
1832 hci_dev_unlock(hdev);
1833 }
1834
hci_cc_le_set_scan_enable(struct hci_dev * hdev,void * data,struct sk_buff * skb)1835 static u8 hci_cc_le_set_scan_enable(struct hci_dev *hdev, void *data,
1836 struct sk_buff *skb)
1837 {
1838 struct hci_cp_le_set_scan_enable *cp;
1839 struct hci_ev_status *rp = data;
1840
1841 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
1842
1843 if (rp->status)
1844 return rp->status;
1845
1846 cp = hci_sent_cmd_data(hdev, HCI_OP_LE_SET_SCAN_ENABLE);
1847 if (!cp)
1848 return rp->status;
1849
1850 le_set_scan_enable_complete(hdev, cp->enable);
1851
1852 return rp->status;
1853 }
1854
hci_cc_le_set_ext_scan_enable(struct hci_dev * hdev,void * data,struct sk_buff * skb)1855 static u8 hci_cc_le_set_ext_scan_enable(struct hci_dev *hdev, void *data,
1856 struct sk_buff *skb)
1857 {
1858 struct hci_cp_le_set_ext_scan_enable *cp;
1859 struct hci_ev_status *rp = data;
1860
1861 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
1862
1863 if (rp->status)
1864 return rp->status;
1865
1866 cp = hci_sent_cmd_data(hdev, HCI_OP_LE_SET_EXT_SCAN_ENABLE);
1867 if (!cp)
1868 return rp->status;
1869
1870 le_set_scan_enable_complete(hdev, cp->enable);
1871
1872 return rp->status;
1873 }
1874
hci_cc_le_read_num_adv_sets(struct hci_dev * hdev,void * data,struct sk_buff * skb)1875 static u8 hci_cc_le_read_num_adv_sets(struct hci_dev *hdev, void *data,
1876 struct sk_buff *skb)
1877 {
1878 struct hci_rp_le_read_num_supported_adv_sets *rp = data;
1879
1880 bt_dev_dbg(hdev, "status 0x%2.2x No of Adv sets %u", rp->status,
1881 rp->num_of_sets);
1882
1883 if (rp->status)
1884 return rp->status;
1885
1886 hdev->le_num_of_adv_sets = rp->num_of_sets;
1887
1888 return rp->status;
1889 }
1890
hci_cc_le_read_accept_list_size(struct hci_dev * hdev,void * data,struct sk_buff * skb)1891 static u8 hci_cc_le_read_accept_list_size(struct hci_dev *hdev, void *data,
1892 struct sk_buff *skb)
1893 {
1894 struct hci_rp_le_read_accept_list_size *rp = data;
1895
1896 bt_dev_dbg(hdev, "status 0x%2.2x size %u", rp->status, rp->size);
1897
1898 if (rp->status)
1899 return rp->status;
1900
1901 hdev->le_accept_list_size = rp->size;
1902
1903 return rp->status;
1904 }
1905
hci_cc_le_clear_accept_list(struct hci_dev * hdev,void * data,struct sk_buff * skb)1906 static u8 hci_cc_le_clear_accept_list(struct hci_dev *hdev, void *data,
1907 struct sk_buff *skb)
1908 {
1909 struct hci_ev_status *rp = data;
1910
1911 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
1912
1913 if (rp->status)
1914 return rp->status;
1915
1916 hci_dev_lock(hdev);
1917 hci_bdaddr_list_clear(&hdev->le_accept_list);
1918 hci_dev_unlock(hdev);
1919
1920 return rp->status;
1921 }
1922
hci_cc_le_add_to_accept_list(struct hci_dev * hdev,void * data,struct sk_buff * skb)1923 static u8 hci_cc_le_add_to_accept_list(struct hci_dev *hdev, void *data,
1924 struct sk_buff *skb)
1925 {
1926 struct hci_cp_le_add_to_accept_list *sent;
1927 struct hci_ev_status *rp = data;
1928
1929 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
1930
1931 if (rp->status)
1932 return rp->status;
1933
1934 sent = hci_sent_cmd_data(hdev, HCI_OP_LE_ADD_TO_ACCEPT_LIST);
1935 if (!sent)
1936 return rp->status;
1937
1938 hci_dev_lock(hdev);
1939 hci_bdaddr_list_add(&hdev->le_accept_list, &sent->bdaddr,
1940 sent->bdaddr_type);
1941 hci_dev_unlock(hdev);
1942
1943 return rp->status;
1944 }
1945
hci_cc_le_del_from_accept_list(struct hci_dev * hdev,void * data,struct sk_buff * skb)1946 static u8 hci_cc_le_del_from_accept_list(struct hci_dev *hdev, void *data,
1947 struct sk_buff *skb)
1948 {
1949 struct hci_cp_le_del_from_accept_list *sent;
1950 struct hci_ev_status *rp = data;
1951
1952 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
1953
1954 if (rp->status)
1955 return rp->status;
1956
1957 sent = hci_sent_cmd_data(hdev, HCI_OP_LE_DEL_FROM_ACCEPT_LIST);
1958 if (!sent)
1959 return rp->status;
1960
1961 hci_dev_lock(hdev);
1962 hci_bdaddr_list_del(&hdev->le_accept_list, &sent->bdaddr,
1963 sent->bdaddr_type);
1964 hci_dev_unlock(hdev);
1965
1966 return rp->status;
1967 }
1968
hci_cc_le_read_supported_states(struct hci_dev * hdev,void * data,struct sk_buff * skb)1969 static u8 hci_cc_le_read_supported_states(struct hci_dev *hdev, void *data,
1970 struct sk_buff *skb)
1971 {
1972 struct hci_rp_le_read_supported_states *rp = data;
1973
1974 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
1975
1976 if (rp->status)
1977 return rp->status;
1978
1979 memcpy(hdev->le_states, rp->le_states, 8);
1980
1981 return rp->status;
1982 }
1983
hci_cc_le_read_def_data_len(struct hci_dev * hdev,void * data,struct sk_buff * skb)1984 static u8 hci_cc_le_read_def_data_len(struct hci_dev *hdev, void *data,
1985 struct sk_buff *skb)
1986 {
1987 struct hci_rp_le_read_def_data_len *rp = data;
1988
1989 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
1990
1991 if (rp->status)
1992 return rp->status;
1993
1994 hdev->le_def_tx_len = le16_to_cpu(rp->tx_len);
1995 hdev->le_def_tx_time = le16_to_cpu(rp->tx_time);
1996
1997 return rp->status;
1998 }
1999
hci_cc_le_write_def_data_len(struct hci_dev * hdev,void * data,struct sk_buff * skb)2000 static u8 hci_cc_le_write_def_data_len(struct hci_dev *hdev, void *data,
2001 struct sk_buff *skb)
2002 {
2003 struct hci_cp_le_write_def_data_len *sent;
2004 struct hci_ev_status *rp = data;
2005
2006 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
2007
2008 if (rp->status)
2009 return rp->status;
2010
2011 sent = hci_sent_cmd_data(hdev, HCI_OP_LE_WRITE_DEF_DATA_LEN);
2012 if (!sent)
2013 return rp->status;
2014
2015 hdev->le_def_tx_len = le16_to_cpu(sent->tx_len);
2016 hdev->le_def_tx_time = le16_to_cpu(sent->tx_time);
2017
2018 return rp->status;
2019 }
2020
hci_cc_le_add_to_resolv_list(struct hci_dev * hdev,void * data,struct sk_buff * skb)2021 static u8 hci_cc_le_add_to_resolv_list(struct hci_dev *hdev, void *data,
2022 struct sk_buff *skb)
2023 {
2024 struct hci_cp_le_add_to_resolv_list *sent;
2025 struct hci_ev_status *rp = data;
2026
2027 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
2028
2029 if (rp->status)
2030 return rp->status;
2031
2032 sent = hci_sent_cmd_data(hdev, HCI_OP_LE_ADD_TO_RESOLV_LIST);
2033 if (!sent)
2034 return rp->status;
2035
2036 hci_dev_lock(hdev);
2037 hci_bdaddr_list_add_with_irk(&hdev->le_resolv_list, &sent->bdaddr,
2038 sent->bdaddr_type, sent->peer_irk,
2039 sent->local_irk);
2040 hci_dev_unlock(hdev);
2041
2042 return rp->status;
2043 }
2044
hci_cc_le_del_from_resolv_list(struct hci_dev * hdev,void * data,struct sk_buff * skb)2045 static u8 hci_cc_le_del_from_resolv_list(struct hci_dev *hdev, void *data,
2046 struct sk_buff *skb)
2047 {
2048 struct hci_cp_le_del_from_resolv_list *sent;
2049 struct hci_ev_status *rp = data;
2050
2051 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
2052
2053 if (rp->status)
2054 return rp->status;
2055
2056 sent = hci_sent_cmd_data(hdev, HCI_OP_LE_DEL_FROM_RESOLV_LIST);
2057 if (!sent)
2058 return rp->status;
2059
2060 hci_dev_lock(hdev);
2061 hci_bdaddr_list_del_with_irk(&hdev->le_resolv_list, &sent->bdaddr,
2062 sent->bdaddr_type);
2063 hci_dev_unlock(hdev);
2064
2065 return rp->status;
2066 }
2067
hci_cc_le_clear_resolv_list(struct hci_dev * hdev,void * data,struct sk_buff * skb)2068 static u8 hci_cc_le_clear_resolv_list(struct hci_dev *hdev, void *data,
2069 struct sk_buff *skb)
2070 {
2071 struct hci_ev_status *rp = data;
2072
2073 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
2074
2075 if (rp->status)
2076 return rp->status;
2077
2078 hci_dev_lock(hdev);
2079 hci_bdaddr_list_clear(&hdev->le_resolv_list);
2080 hci_dev_unlock(hdev);
2081
2082 return rp->status;
2083 }
2084
hci_cc_le_read_resolv_list_size(struct hci_dev * hdev,void * data,struct sk_buff * skb)2085 static u8 hci_cc_le_read_resolv_list_size(struct hci_dev *hdev, void *data,
2086 struct sk_buff *skb)
2087 {
2088 struct hci_rp_le_read_resolv_list_size *rp = data;
2089
2090 bt_dev_dbg(hdev, "status 0x%2.2x size %u", rp->status, rp->size);
2091
2092 if (rp->status)
2093 return rp->status;
2094
2095 hdev->le_resolv_list_size = rp->size;
2096
2097 return rp->status;
2098 }
2099
hci_cc_le_set_addr_resolution_enable(struct hci_dev * hdev,void * data,struct sk_buff * skb)2100 static u8 hci_cc_le_set_addr_resolution_enable(struct hci_dev *hdev, void *data,
2101 struct sk_buff *skb)
2102 {
2103 struct hci_ev_status *rp = data;
2104 __u8 *sent;
2105
2106 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
2107
2108 if (rp->status)
2109 return rp->status;
2110
2111 sent = hci_sent_cmd_data(hdev, HCI_OP_LE_SET_ADDR_RESOLV_ENABLE);
2112 if (!sent)
2113 return rp->status;
2114
2115 hci_dev_lock(hdev);
2116
2117 if (*sent)
2118 hci_dev_set_flag(hdev, HCI_LL_RPA_RESOLUTION);
2119 else
2120 hci_dev_clear_flag(hdev, HCI_LL_RPA_RESOLUTION);
2121
2122 hci_dev_unlock(hdev);
2123
2124 return rp->status;
2125 }
2126
hci_cc_le_read_max_data_len(struct hci_dev * hdev,void * data,struct sk_buff * skb)2127 static u8 hci_cc_le_read_max_data_len(struct hci_dev *hdev, void *data,
2128 struct sk_buff *skb)
2129 {
2130 struct hci_rp_le_read_max_data_len *rp = data;
2131
2132 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
2133
2134 if (rp->status)
2135 return rp->status;
2136
2137 hdev->le_max_tx_len = le16_to_cpu(rp->tx_len);
2138 hdev->le_max_tx_time = le16_to_cpu(rp->tx_time);
2139 hdev->le_max_rx_len = le16_to_cpu(rp->rx_len);
2140 hdev->le_max_rx_time = le16_to_cpu(rp->rx_time);
2141
2142 return rp->status;
2143 }
2144
hci_cc_write_le_host_supported(struct hci_dev * hdev,void * data,struct sk_buff * skb)2145 static u8 hci_cc_write_le_host_supported(struct hci_dev *hdev, void *data,
2146 struct sk_buff *skb)
2147 {
2148 struct hci_cp_write_le_host_supported *sent;
2149 struct hci_ev_status *rp = data;
2150
2151 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
2152
2153 if (rp->status)
2154 return rp->status;
2155
2156 sent = hci_sent_cmd_data(hdev, HCI_OP_WRITE_LE_HOST_SUPPORTED);
2157 if (!sent)
2158 return rp->status;
2159
2160 hci_dev_lock(hdev);
2161
2162 if (sent->le) {
2163 hdev->features[1][0] |= LMP_HOST_LE;
2164 hci_dev_set_flag(hdev, HCI_LE_ENABLED);
2165 } else {
2166 hdev->features[1][0] &= ~LMP_HOST_LE;
2167 hci_dev_clear_flag(hdev, HCI_LE_ENABLED);
2168 hci_dev_clear_flag(hdev, HCI_ADVERTISING);
2169 }
2170
2171 if (sent->simul)
2172 hdev->features[1][0] |= LMP_HOST_LE_BREDR;
2173 else
2174 hdev->features[1][0] &= ~LMP_HOST_LE_BREDR;
2175
2176 hci_dev_unlock(hdev);
2177
2178 return rp->status;
2179 }
2180
hci_cc_set_adv_param(struct hci_dev * hdev,void * data,struct sk_buff * skb)2181 static u8 hci_cc_set_adv_param(struct hci_dev *hdev, void *data,
2182 struct sk_buff *skb)
2183 {
2184 struct hci_cp_le_set_adv_param *cp;
2185 struct hci_ev_status *rp = data;
2186
2187 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
2188
2189 if (rp->status)
2190 return rp->status;
2191
2192 cp = hci_sent_cmd_data(hdev, HCI_OP_LE_SET_ADV_PARAM);
2193 if (!cp)
2194 return rp->status;
2195
2196 hci_dev_lock(hdev);
2197 hdev->adv_addr_type = cp->own_address_type;
2198 hci_dev_unlock(hdev);
2199
2200 return rp->status;
2201 }
2202
hci_cc_read_rssi(struct hci_dev * hdev,void * data,struct sk_buff * skb)2203 static u8 hci_cc_read_rssi(struct hci_dev *hdev, void *data,
2204 struct sk_buff *skb)
2205 {
2206 struct hci_rp_read_rssi *rp = data;
2207 struct hci_conn *conn;
2208
2209 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
2210
2211 if (rp->status)
2212 return rp->status;
2213
2214 hci_dev_lock(hdev);
2215
2216 conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(rp->handle));
2217 if (conn)
2218 conn->rssi = rp->rssi;
2219
2220 hci_dev_unlock(hdev);
2221
2222 return rp->status;
2223 }
2224
hci_cc_read_tx_power(struct hci_dev * hdev,void * data,struct sk_buff * skb)2225 static u8 hci_cc_read_tx_power(struct hci_dev *hdev, void *data,
2226 struct sk_buff *skb)
2227 {
2228 struct hci_cp_read_tx_power *sent;
2229 struct hci_rp_read_tx_power *rp = data;
2230 struct hci_conn *conn;
2231
2232 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
2233
2234 if (rp->status)
2235 return rp->status;
2236
2237 sent = hci_sent_cmd_data(hdev, HCI_OP_READ_TX_POWER);
2238 if (!sent)
2239 return rp->status;
2240
2241 hci_dev_lock(hdev);
2242
2243 conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(rp->handle));
2244 if (!conn)
2245 goto unlock;
2246
2247 switch (sent->type) {
2248 case 0x00:
2249 conn->tx_power = rp->tx_power;
2250 break;
2251 case 0x01:
2252 conn->max_tx_power = rp->tx_power;
2253 break;
2254 }
2255
2256 unlock:
2257 hci_dev_unlock(hdev);
2258 return rp->status;
2259 }
2260
hci_cc_write_ssp_debug_mode(struct hci_dev * hdev,void * data,struct sk_buff * skb)2261 static u8 hci_cc_write_ssp_debug_mode(struct hci_dev *hdev, void *data,
2262 struct sk_buff *skb)
2263 {
2264 struct hci_ev_status *rp = data;
2265 u8 *mode;
2266
2267 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
2268
2269 if (rp->status)
2270 return rp->status;
2271
2272 mode = hci_sent_cmd_data(hdev, HCI_OP_WRITE_SSP_DEBUG_MODE);
2273 if (mode)
2274 hdev->ssp_debug_mode = *mode;
2275
2276 return rp->status;
2277 }
2278
hci_cs_inquiry(struct hci_dev * hdev,__u8 status)2279 static void hci_cs_inquiry(struct hci_dev *hdev, __u8 status)
2280 {
2281 bt_dev_dbg(hdev, "status 0x%2.2x", status);
2282
2283 if (status)
2284 return;
2285
2286 if (hci_sent_cmd_data(hdev, HCI_OP_INQUIRY))
2287 set_bit(HCI_INQUIRY, &hdev->flags);
2288 }
2289
hci_cs_create_conn(struct hci_dev * hdev,__u8 status)2290 static void hci_cs_create_conn(struct hci_dev *hdev, __u8 status)
2291 {
2292 struct hci_cp_create_conn *cp;
2293 struct hci_conn *conn;
2294
2295 bt_dev_dbg(hdev, "status 0x%2.2x", status);
2296
2297 cp = hci_sent_cmd_data(hdev, HCI_OP_CREATE_CONN);
2298 if (!cp)
2299 return;
2300
2301 hci_dev_lock(hdev);
2302
2303 conn = hci_conn_hash_lookup_ba(hdev, ACL_LINK, &cp->bdaddr);
2304
2305 bt_dev_dbg(hdev, "bdaddr %pMR hcon %p", &cp->bdaddr, conn);
2306
2307 if (status) {
2308 if (conn && conn->state == BT_CONNECT) {
2309 conn->state = BT_CLOSED;
2310 hci_connect_cfm(conn, status);
2311 hci_conn_del(conn);
2312 }
2313 } else {
2314 if (!conn) {
2315 conn = hci_conn_add_unset(hdev, ACL_LINK, &cp->bdaddr,
2316 0, HCI_ROLE_MASTER);
2317 if (IS_ERR(conn))
2318 bt_dev_err(hdev, "connection err: %ld", PTR_ERR(conn));
2319 }
2320 }
2321
2322 hci_dev_unlock(hdev);
2323 }
2324
hci_cs_add_sco(struct hci_dev * hdev,__u8 status)2325 static void hci_cs_add_sco(struct hci_dev *hdev, __u8 status)
2326 {
2327 struct hci_cp_add_sco *cp;
2328 struct hci_conn *acl;
2329 struct hci_link *link;
2330 __u16 handle;
2331
2332 bt_dev_dbg(hdev, "status 0x%2.2x", status);
2333
2334 if (!status)
2335 return;
2336
2337 cp = hci_sent_cmd_data(hdev, HCI_OP_ADD_SCO);
2338 if (!cp)
2339 return;
2340
2341 handle = __le16_to_cpu(cp->handle);
2342
2343 bt_dev_dbg(hdev, "handle 0x%4.4x", handle);
2344
2345 hci_dev_lock(hdev);
2346
2347 acl = hci_conn_hash_lookup_handle(hdev, handle);
2348 if (acl) {
2349 link = list_first_entry_or_null(&acl->link_list,
2350 struct hci_link, list);
2351 if (link && link->conn) {
2352 link->conn->state = BT_CLOSED;
2353
2354 hci_connect_cfm(link->conn, status);
2355 hci_conn_del(link->conn);
2356 }
2357 }
2358
2359 hci_dev_unlock(hdev);
2360 }
2361
hci_cs_auth_requested(struct hci_dev * hdev,__u8 status)2362 static void hci_cs_auth_requested(struct hci_dev *hdev, __u8 status)
2363 {
2364 struct hci_cp_auth_requested *cp;
2365 struct hci_conn *conn;
2366
2367 bt_dev_dbg(hdev, "status 0x%2.2x", status);
2368
2369 if (!status)
2370 return;
2371
2372 cp = hci_sent_cmd_data(hdev, HCI_OP_AUTH_REQUESTED);
2373 if (!cp)
2374 return;
2375
2376 hci_dev_lock(hdev);
2377
2378 conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(cp->handle));
2379 if (conn) {
2380 if (conn->state == BT_CONFIG) {
2381 hci_connect_cfm(conn, status);
2382 hci_conn_drop(conn);
2383 }
2384 }
2385
2386 hci_dev_unlock(hdev);
2387 }
2388
hci_cs_set_conn_encrypt(struct hci_dev * hdev,__u8 status)2389 static void hci_cs_set_conn_encrypt(struct hci_dev *hdev, __u8 status)
2390 {
2391 struct hci_cp_set_conn_encrypt *cp;
2392 struct hci_conn *conn;
2393
2394 bt_dev_dbg(hdev, "status 0x%2.2x", status);
2395
2396 if (!status)
2397 return;
2398
2399 cp = hci_sent_cmd_data(hdev, HCI_OP_SET_CONN_ENCRYPT);
2400 if (!cp)
2401 return;
2402
2403 hci_dev_lock(hdev);
2404
2405 conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(cp->handle));
2406 if (conn) {
2407 if (conn->state == BT_CONFIG) {
2408 hci_connect_cfm(conn, status);
2409 hci_conn_drop(conn);
2410 }
2411 }
2412
2413 hci_dev_unlock(hdev);
2414 }
2415
hci_outgoing_auth_needed(struct hci_dev * hdev,struct hci_conn * conn)2416 static int hci_outgoing_auth_needed(struct hci_dev *hdev,
2417 struct hci_conn *conn)
2418 {
2419 if (conn->state != BT_CONFIG || !conn->out)
2420 return 0;
2421
2422 if (conn->pending_sec_level == BT_SECURITY_SDP)
2423 return 0;
2424
2425 /* Only request authentication for SSP connections or non-SSP
2426 * devices with sec_level MEDIUM or HIGH or if MITM protection
2427 * is requested.
2428 */
2429 if (!hci_conn_ssp_enabled(conn) && !(conn->auth_type & 0x01) &&
2430 conn->pending_sec_level != BT_SECURITY_FIPS &&
2431 conn->pending_sec_level != BT_SECURITY_HIGH &&
2432 conn->pending_sec_level != BT_SECURITY_MEDIUM)
2433 return 0;
2434
2435 return 1;
2436 }
2437
hci_resolve_name(struct hci_dev * hdev,struct inquiry_entry * e)2438 static int hci_resolve_name(struct hci_dev *hdev,
2439 struct inquiry_entry *e)
2440 {
2441 struct hci_cp_remote_name_req cp;
2442
2443 memset(&cp, 0, sizeof(cp));
2444
2445 bacpy(&cp.bdaddr, &e->data.bdaddr);
2446 cp.pscan_rep_mode = e->data.pscan_rep_mode;
2447 cp.pscan_mode = e->data.pscan_mode;
2448 cp.clock_offset = e->data.clock_offset;
2449
2450 return hci_send_cmd(hdev, HCI_OP_REMOTE_NAME_REQ, sizeof(cp), &cp);
2451 }
2452
hci_resolve_next_name(struct hci_dev * hdev)2453 static bool hci_resolve_next_name(struct hci_dev *hdev)
2454 {
2455 struct discovery_state *discov = &hdev->discovery;
2456 struct inquiry_entry *e;
2457
2458 if (list_empty(&discov->resolve))
2459 return false;
2460
2461 /* We should stop if we already spent too much time resolving names. */
2462 if (time_after(jiffies, discov->name_resolve_timeout)) {
2463 bt_dev_warn_ratelimited(hdev, "Name resolve takes too long.");
2464 return false;
2465 }
2466
2467 e = hci_inquiry_cache_lookup_resolve(hdev, BDADDR_ANY, NAME_NEEDED);
2468 if (!e)
2469 return false;
2470
2471 if (hci_resolve_name(hdev, e) == 0) {
2472 e->name_state = NAME_PENDING;
2473 return true;
2474 }
2475
2476 return false;
2477 }
2478
hci_check_pending_name(struct hci_dev * hdev,struct hci_conn * conn,bdaddr_t * bdaddr,u8 * name,u8 name_len)2479 static void hci_check_pending_name(struct hci_dev *hdev, struct hci_conn *conn,
2480 bdaddr_t *bdaddr, u8 *name, u8 name_len)
2481 {
2482 struct discovery_state *discov = &hdev->discovery;
2483 struct inquiry_entry *e;
2484
2485 /* Update the mgmt connected state if necessary. Be careful with
2486 * conn objects that exist but are not (yet) connected however.
2487 * Only those in BT_CONFIG or BT_CONNECTED states can be
2488 * considered connected.
2489 */
2490 if (conn && (conn->state == BT_CONFIG || conn->state == BT_CONNECTED))
2491 mgmt_device_connected(hdev, conn, name, name_len);
2492
2493 if (discov->state == DISCOVERY_STOPPED)
2494 return;
2495
2496 if (discov->state == DISCOVERY_STOPPING)
2497 goto discov_complete;
2498
2499 if (discov->state != DISCOVERY_RESOLVING)
2500 return;
2501
2502 e = hci_inquiry_cache_lookup_resolve(hdev, bdaddr, NAME_PENDING);
2503 /* If the device was not found in a list of found devices names of which
2504 * are pending. there is no need to continue resolving a next name as it
2505 * will be done upon receiving another Remote Name Request Complete
2506 * Event */
2507 if (!e)
2508 return;
2509
2510 list_del(&e->list);
2511
2512 e->name_state = name ? NAME_KNOWN : NAME_NOT_KNOWN;
2513 mgmt_remote_name(hdev, bdaddr, ACL_LINK, 0x00, e->data.rssi,
2514 name, name_len);
2515
2516 if (hci_resolve_next_name(hdev))
2517 return;
2518
2519 discov_complete:
2520 hci_discovery_set_state(hdev, DISCOVERY_STOPPED);
2521 }
2522
hci_cs_remote_name_req(struct hci_dev * hdev,__u8 status)2523 static void hci_cs_remote_name_req(struct hci_dev *hdev, __u8 status)
2524 {
2525 struct hci_cp_remote_name_req *cp;
2526 struct hci_conn *conn;
2527
2528 bt_dev_dbg(hdev, "status 0x%2.2x", status);
2529
2530 /* If successful wait for the name req complete event before
2531 * checking for the need to do authentication */
2532 if (!status)
2533 return;
2534
2535 cp = hci_sent_cmd_data(hdev, HCI_OP_REMOTE_NAME_REQ);
2536 if (!cp)
2537 return;
2538
2539 hci_dev_lock(hdev);
2540
2541 conn = hci_conn_hash_lookup_ba(hdev, ACL_LINK, &cp->bdaddr);
2542
2543 if (hci_dev_test_flag(hdev, HCI_MGMT))
2544 hci_check_pending_name(hdev, conn, &cp->bdaddr, NULL, 0);
2545
2546 if (!conn)
2547 goto unlock;
2548
2549 if (!hci_outgoing_auth_needed(hdev, conn))
2550 goto unlock;
2551
2552 if (!test_and_set_bit(HCI_CONN_AUTH_PEND, &conn->flags)) {
2553 struct hci_cp_auth_requested auth_cp;
2554
2555 set_bit(HCI_CONN_AUTH_INITIATOR, &conn->flags);
2556
2557 auth_cp.handle = __cpu_to_le16(conn->handle);
2558 hci_send_cmd(hdev, HCI_OP_AUTH_REQUESTED,
2559 sizeof(auth_cp), &auth_cp);
2560 }
2561
2562 unlock:
2563 hci_dev_unlock(hdev);
2564 }
2565
hci_cs_read_remote_features(struct hci_dev * hdev,__u8 status)2566 static void hci_cs_read_remote_features(struct hci_dev *hdev, __u8 status)
2567 {
2568 struct hci_cp_read_remote_features *cp;
2569 struct hci_conn *conn;
2570
2571 bt_dev_dbg(hdev, "status 0x%2.2x", status);
2572
2573 if (!status)
2574 return;
2575
2576 cp = hci_sent_cmd_data(hdev, HCI_OP_READ_REMOTE_FEATURES);
2577 if (!cp)
2578 return;
2579
2580 hci_dev_lock(hdev);
2581
2582 conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(cp->handle));
2583 if (conn) {
2584 if (conn->state == BT_CONFIG) {
2585 hci_connect_cfm(conn, status);
2586 hci_conn_drop(conn);
2587 }
2588 }
2589
2590 hci_dev_unlock(hdev);
2591 }
2592
hci_cs_read_remote_ext_features(struct hci_dev * hdev,__u8 status)2593 static void hci_cs_read_remote_ext_features(struct hci_dev *hdev, __u8 status)
2594 {
2595 struct hci_cp_read_remote_ext_features *cp;
2596 struct hci_conn *conn;
2597
2598 bt_dev_dbg(hdev, "status 0x%2.2x", status);
2599
2600 if (!status)
2601 return;
2602
2603 cp = hci_sent_cmd_data(hdev, HCI_OP_READ_REMOTE_EXT_FEATURES);
2604 if (!cp)
2605 return;
2606
2607 hci_dev_lock(hdev);
2608
2609 conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(cp->handle));
2610 if (conn) {
2611 if (conn->state == BT_CONFIG) {
2612 hci_connect_cfm(conn, status);
2613 hci_conn_drop(conn);
2614 }
2615 }
2616
2617 hci_dev_unlock(hdev);
2618 }
2619
hci_setup_sync_conn_status(struct hci_dev * hdev,__u16 handle,__u8 status)2620 static void hci_setup_sync_conn_status(struct hci_dev *hdev, __u16 handle,
2621 __u8 status)
2622 {
2623 struct hci_conn *acl;
2624 struct hci_link *link;
2625
2626 bt_dev_dbg(hdev, "handle 0x%4.4x status 0x%2.2x", handle, status);
2627
2628 hci_dev_lock(hdev);
2629
2630 acl = hci_conn_hash_lookup_handle(hdev, handle);
2631 if (acl) {
2632 link = list_first_entry_or_null(&acl->link_list,
2633 struct hci_link, list);
2634 if (link && link->conn) {
2635 link->conn->state = BT_CLOSED;
2636
2637 hci_connect_cfm(link->conn, status);
2638 hci_conn_del(link->conn);
2639 }
2640 }
2641
2642 hci_dev_unlock(hdev);
2643 }
2644
hci_cs_setup_sync_conn(struct hci_dev * hdev,__u8 status)2645 static void hci_cs_setup_sync_conn(struct hci_dev *hdev, __u8 status)
2646 {
2647 struct hci_cp_setup_sync_conn *cp;
2648
2649 bt_dev_dbg(hdev, "status 0x%2.2x", status);
2650
2651 if (!status)
2652 return;
2653
2654 cp = hci_sent_cmd_data(hdev, HCI_OP_SETUP_SYNC_CONN);
2655 if (!cp)
2656 return;
2657
2658 hci_setup_sync_conn_status(hdev, __le16_to_cpu(cp->handle), status);
2659 }
2660
hci_cs_enhanced_setup_sync_conn(struct hci_dev * hdev,__u8 status)2661 static void hci_cs_enhanced_setup_sync_conn(struct hci_dev *hdev, __u8 status)
2662 {
2663 struct hci_cp_enhanced_setup_sync_conn *cp;
2664
2665 bt_dev_dbg(hdev, "status 0x%2.2x", status);
2666
2667 if (!status)
2668 return;
2669
2670 cp = hci_sent_cmd_data(hdev, HCI_OP_ENHANCED_SETUP_SYNC_CONN);
2671 if (!cp)
2672 return;
2673
2674 hci_setup_sync_conn_status(hdev, __le16_to_cpu(cp->handle), status);
2675 }
2676
hci_cs_sniff_mode(struct hci_dev * hdev,__u8 status)2677 static void hci_cs_sniff_mode(struct hci_dev *hdev, __u8 status)
2678 {
2679 struct hci_cp_sniff_mode *cp;
2680 struct hci_conn *conn;
2681
2682 bt_dev_dbg(hdev, "status 0x%2.2x", status);
2683
2684 if (!status)
2685 return;
2686
2687 cp = hci_sent_cmd_data(hdev, HCI_OP_SNIFF_MODE);
2688 if (!cp)
2689 return;
2690
2691 hci_dev_lock(hdev);
2692
2693 conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(cp->handle));
2694 if (conn) {
2695 clear_bit(HCI_CONN_MODE_CHANGE_PEND, &conn->flags);
2696
2697 if (test_and_clear_bit(HCI_CONN_SCO_SETUP_PEND, &conn->flags))
2698 hci_sco_setup(conn, status);
2699 }
2700
2701 hci_dev_unlock(hdev);
2702 }
2703
hci_cs_exit_sniff_mode(struct hci_dev * hdev,__u8 status)2704 static void hci_cs_exit_sniff_mode(struct hci_dev *hdev, __u8 status)
2705 {
2706 struct hci_cp_exit_sniff_mode *cp;
2707 struct hci_conn *conn;
2708
2709 bt_dev_dbg(hdev, "status 0x%2.2x", status);
2710
2711 if (!status)
2712 return;
2713
2714 cp = hci_sent_cmd_data(hdev, HCI_OP_EXIT_SNIFF_MODE);
2715 if (!cp)
2716 return;
2717
2718 hci_dev_lock(hdev);
2719
2720 conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(cp->handle));
2721 if (conn) {
2722 clear_bit(HCI_CONN_MODE_CHANGE_PEND, &conn->flags);
2723
2724 if (test_and_clear_bit(HCI_CONN_SCO_SETUP_PEND, &conn->flags))
2725 hci_sco_setup(conn, status);
2726 }
2727
2728 hci_dev_unlock(hdev);
2729 }
2730
hci_cs_disconnect(struct hci_dev * hdev,u8 status)2731 static void hci_cs_disconnect(struct hci_dev *hdev, u8 status)
2732 {
2733 struct hci_cp_disconnect *cp;
2734 struct hci_conn_params *params;
2735 struct hci_conn *conn;
2736 bool mgmt_conn;
2737
2738 bt_dev_dbg(hdev, "status 0x%2.2x", status);
2739
2740 /* Wait for HCI_EV_DISCONN_COMPLETE if status 0x00 and not suspended
2741 * otherwise cleanup the connection immediately.
2742 */
2743 if (!status && !hdev->suspended)
2744 return;
2745
2746 cp = hci_sent_cmd_data(hdev, HCI_OP_DISCONNECT);
2747 if (!cp)
2748 return;
2749
2750 hci_dev_lock(hdev);
2751
2752 conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(cp->handle));
2753 if (!conn)
2754 goto unlock;
2755
2756 if (status && status != HCI_ERROR_UNKNOWN_CONN_ID) {
2757 mgmt_disconnect_failed(hdev, &conn->dst, conn->type,
2758 conn->dst_type, status);
2759
2760 if (conn->type == LE_LINK && conn->role == HCI_ROLE_SLAVE) {
2761 hdev->cur_adv_instance = conn->adv_instance;
2762 hci_enable_advertising(hdev);
2763 }
2764
2765 /* Inform sockets conn is gone before we delete it */
2766 hci_disconn_cfm(conn, HCI_ERROR_UNSPECIFIED);
2767
2768 goto done;
2769 }
2770
2771 /* During suspend, mark connection as closed immediately
2772 * since we might not receive HCI_EV_DISCONN_COMPLETE
2773 */
2774 if (hdev->suspended)
2775 conn->state = BT_CLOSED;
2776
2777 mgmt_conn = test_and_clear_bit(HCI_CONN_MGMT_CONNECTED, &conn->flags);
2778
2779 if (conn->type == ACL_LINK) {
2780 if (test_and_clear_bit(HCI_CONN_FLUSH_KEY, &conn->flags))
2781 hci_remove_link_key(hdev, &conn->dst);
2782 }
2783
2784 params = hci_conn_params_lookup(hdev, &conn->dst, conn->dst_type);
2785 if (params) {
2786 switch (params->auto_connect) {
2787 case HCI_AUTO_CONN_LINK_LOSS:
2788 if (cp->reason != HCI_ERROR_CONNECTION_TIMEOUT)
2789 break;
2790 fallthrough;
2791
2792 case HCI_AUTO_CONN_DIRECT:
2793 case HCI_AUTO_CONN_ALWAYS:
2794 hci_pend_le_list_del_init(params);
2795 hci_pend_le_list_add(params, &hdev->pend_le_conns);
2796 break;
2797
2798 default:
2799 break;
2800 }
2801 }
2802
2803 mgmt_device_disconnected(hdev, &conn->dst, conn->type, conn->dst_type,
2804 hci_to_mgmt_reason(cp->reason), mgmt_conn);
2805
2806 hci_disconn_cfm(conn, cp->reason);
2807
2808 done:
2809 /* If the disconnection failed for any reason, the upper layer
2810 * does not retry to disconnect in current implementation.
2811 * Hence, we need to do some basic cleanup here and re-enable
2812 * advertising if necessary.
2813 */
2814 hci_conn_del(conn);
2815 unlock:
2816 hci_dev_unlock(hdev);
2817 }
2818
ev_bdaddr_type(struct hci_dev * hdev,u8 type,bool * resolved)2819 static u8 ev_bdaddr_type(struct hci_dev *hdev, u8 type, bool *resolved)
2820 {
2821 /* When using controller based address resolution, then the new
2822 * address types 0x02 and 0x03 are used. These types need to be
2823 * converted back into either public address or random address type
2824 */
2825 switch (type) {
2826 case ADDR_LE_DEV_PUBLIC_RESOLVED:
2827 if (resolved)
2828 *resolved = true;
2829 return ADDR_LE_DEV_PUBLIC;
2830 case ADDR_LE_DEV_RANDOM_RESOLVED:
2831 if (resolved)
2832 *resolved = true;
2833 return ADDR_LE_DEV_RANDOM;
2834 }
2835
2836 if (resolved)
2837 *resolved = false;
2838 return type;
2839 }
2840
cs_le_create_conn(struct hci_dev * hdev,bdaddr_t * peer_addr,u8 peer_addr_type,u8 own_address_type,u8 filter_policy)2841 static void cs_le_create_conn(struct hci_dev *hdev, bdaddr_t *peer_addr,
2842 u8 peer_addr_type, u8 own_address_type,
2843 u8 filter_policy)
2844 {
2845 struct hci_conn *conn;
2846
2847 conn = hci_conn_hash_lookup_le(hdev, peer_addr,
2848 peer_addr_type);
2849 if (!conn)
2850 return;
2851
2852 own_address_type = ev_bdaddr_type(hdev, own_address_type, NULL);
2853
2854 /* Store the initiator and responder address information which
2855 * is needed for SMP. These values will not change during the
2856 * lifetime of the connection.
2857 */
2858 conn->init_addr_type = own_address_type;
2859 if (own_address_type == ADDR_LE_DEV_RANDOM)
2860 bacpy(&conn->init_addr, &hdev->random_addr);
2861 else
2862 bacpy(&conn->init_addr, &hdev->bdaddr);
2863
2864 conn->resp_addr_type = peer_addr_type;
2865 bacpy(&conn->resp_addr, peer_addr);
2866 }
2867
hci_cs_le_create_conn(struct hci_dev * hdev,u8 status)2868 static void hci_cs_le_create_conn(struct hci_dev *hdev, u8 status)
2869 {
2870 struct hci_cp_le_create_conn *cp;
2871
2872 bt_dev_dbg(hdev, "status 0x%2.2x", status);
2873
2874 /* All connection failure handling is taken care of by the
2875 * hci_conn_failed function which is triggered by the HCI
2876 * request completion callbacks used for connecting.
2877 */
2878 if (status)
2879 return;
2880
2881 cp = hci_sent_cmd_data(hdev, HCI_OP_LE_CREATE_CONN);
2882 if (!cp)
2883 return;
2884
2885 hci_dev_lock(hdev);
2886
2887 cs_le_create_conn(hdev, &cp->peer_addr, cp->peer_addr_type,
2888 cp->own_address_type, cp->filter_policy);
2889
2890 hci_dev_unlock(hdev);
2891 }
2892
hci_cs_le_ext_create_conn(struct hci_dev * hdev,u8 status)2893 static void hci_cs_le_ext_create_conn(struct hci_dev *hdev, u8 status)
2894 {
2895 struct hci_cp_le_ext_create_conn *cp;
2896
2897 bt_dev_dbg(hdev, "status 0x%2.2x", status);
2898
2899 /* All connection failure handling is taken care of by the
2900 * hci_conn_failed function which is triggered by the HCI
2901 * request completion callbacks used for connecting.
2902 */
2903 if (status)
2904 return;
2905
2906 cp = hci_sent_cmd_data(hdev, HCI_OP_LE_EXT_CREATE_CONN);
2907 if (!cp)
2908 return;
2909
2910 hci_dev_lock(hdev);
2911
2912 cs_le_create_conn(hdev, &cp->peer_addr, cp->peer_addr_type,
2913 cp->own_addr_type, cp->filter_policy);
2914
2915 hci_dev_unlock(hdev);
2916 }
2917
hci_cs_le_set_phy(struct hci_dev * hdev,u8 status)2918 static void hci_cs_le_set_phy(struct hci_dev *hdev, u8 status)
2919 {
2920 struct hci_cp_le_set_phy *cp;
2921 struct hci_conn *conn;
2922
2923 bt_dev_dbg(hdev, "status 0x%2.2x", status);
2924
2925 if (status)
2926 return;
2927
2928 cp = hci_sent_cmd_data(hdev, HCI_OP_LE_SET_PHY);
2929 if (!cp)
2930 return;
2931
2932 hci_dev_lock(hdev);
2933
2934 conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(cp->handle));
2935 if (conn) {
2936 conn->le_tx_def_phys = cp->tx_phys;
2937 conn->le_rx_def_phys = cp->rx_phys;
2938 }
2939
2940 hci_dev_unlock(hdev);
2941 }
2942
hci_cs_le_read_remote_features(struct hci_dev * hdev,u8 status)2943 static void hci_cs_le_read_remote_features(struct hci_dev *hdev, u8 status)
2944 {
2945 struct hci_cp_le_read_remote_features *cp;
2946 struct hci_conn *conn;
2947
2948 bt_dev_dbg(hdev, "status 0x%2.2x", status);
2949
2950 if (!status)
2951 return;
2952
2953 cp = hci_sent_cmd_data(hdev, HCI_OP_LE_READ_REMOTE_FEATURES);
2954 if (!cp)
2955 return;
2956
2957 hci_dev_lock(hdev);
2958
2959 conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(cp->handle));
2960 if (conn && conn->state == BT_CONFIG)
2961 hci_connect_cfm(conn, status);
2962
2963 hci_dev_unlock(hdev);
2964 }
2965
hci_cs_le_start_enc(struct hci_dev * hdev,u8 status)2966 static void hci_cs_le_start_enc(struct hci_dev *hdev, u8 status)
2967 {
2968 struct hci_cp_le_start_enc *cp;
2969 struct hci_conn *conn;
2970
2971 bt_dev_dbg(hdev, "status 0x%2.2x", status);
2972
2973 if (!status)
2974 return;
2975
2976 hci_dev_lock(hdev);
2977
2978 cp = hci_sent_cmd_data(hdev, HCI_OP_LE_START_ENC);
2979 if (!cp)
2980 goto unlock;
2981
2982 conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(cp->handle));
2983 if (!conn)
2984 goto unlock;
2985
2986 if (conn->state != BT_CONNECTED)
2987 goto unlock;
2988
2989 hci_disconnect(conn, HCI_ERROR_AUTH_FAILURE);
2990 hci_conn_drop(conn);
2991
2992 unlock:
2993 hci_dev_unlock(hdev);
2994 }
2995
hci_cs_switch_role(struct hci_dev * hdev,u8 status)2996 static void hci_cs_switch_role(struct hci_dev *hdev, u8 status)
2997 {
2998 struct hci_cp_switch_role *cp;
2999 struct hci_conn *conn;
3000
3001 BT_DBG("%s status 0x%2.2x", hdev->name, status);
3002
3003 if (!status)
3004 return;
3005
3006 cp = hci_sent_cmd_data(hdev, HCI_OP_SWITCH_ROLE);
3007 if (!cp)
3008 return;
3009
3010 hci_dev_lock(hdev);
3011
3012 conn = hci_conn_hash_lookup_ba(hdev, ACL_LINK, &cp->bdaddr);
3013 if (conn)
3014 clear_bit(HCI_CONN_RSWITCH_PEND, &conn->flags);
3015
3016 hci_dev_unlock(hdev);
3017 }
3018
hci_inquiry_complete_evt(struct hci_dev * hdev,void * data,struct sk_buff * skb)3019 static void hci_inquiry_complete_evt(struct hci_dev *hdev, void *data,
3020 struct sk_buff *skb)
3021 {
3022 struct hci_ev_status *ev = data;
3023 struct discovery_state *discov = &hdev->discovery;
3024 struct inquiry_entry *e;
3025
3026 bt_dev_dbg(hdev, "status 0x%2.2x", ev->status);
3027
3028 if (!test_and_clear_bit(HCI_INQUIRY, &hdev->flags))
3029 return;
3030
3031 smp_mb__after_atomic(); /* wake_up_bit advises about this barrier */
3032 wake_up_bit(&hdev->flags, HCI_INQUIRY);
3033
3034 if (!hci_dev_test_flag(hdev, HCI_MGMT))
3035 return;
3036
3037 hci_dev_lock(hdev);
3038
3039 if (discov->state != DISCOVERY_FINDING)
3040 goto unlock;
3041
3042 if (list_empty(&discov->resolve)) {
3043 /* When BR/EDR inquiry is active and no LE scanning is in
3044 * progress, then change discovery state to indicate completion.
3045 *
3046 * When running LE scanning and BR/EDR inquiry simultaneously
3047 * and the LE scan already finished, then change the discovery
3048 * state to indicate completion.
3049 */
3050 if (!hci_dev_test_flag(hdev, HCI_LE_SCAN) ||
3051 !hci_test_quirk(hdev, HCI_QUIRK_SIMULTANEOUS_DISCOVERY))
3052 hci_discovery_set_state(hdev, DISCOVERY_STOPPED);
3053 goto unlock;
3054 }
3055
3056 e = hci_inquiry_cache_lookup_resolve(hdev, BDADDR_ANY, NAME_NEEDED);
3057 if (e && hci_resolve_name(hdev, e) == 0) {
3058 e->name_state = NAME_PENDING;
3059 hci_discovery_set_state(hdev, DISCOVERY_RESOLVING);
3060 discov->name_resolve_timeout = jiffies + NAME_RESOLVE_DURATION;
3061 } else {
3062 /* When BR/EDR inquiry is active and no LE scanning is in
3063 * progress, then change discovery state to indicate completion.
3064 *
3065 * When running LE scanning and BR/EDR inquiry simultaneously
3066 * and the LE scan already finished, then change the discovery
3067 * state to indicate completion.
3068 */
3069 if (!hci_dev_test_flag(hdev, HCI_LE_SCAN) ||
3070 !hci_test_quirk(hdev, HCI_QUIRK_SIMULTANEOUS_DISCOVERY))
3071 hci_discovery_set_state(hdev, DISCOVERY_STOPPED);
3072 }
3073
3074 unlock:
3075 hci_dev_unlock(hdev);
3076 }
3077
hci_inquiry_result_evt(struct hci_dev * hdev,void * edata,struct sk_buff * skb)3078 static void hci_inquiry_result_evt(struct hci_dev *hdev, void *edata,
3079 struct sk_buff *skb)
3080 {
3081 struct hci_ev_inquiry_result *ev = edata;
3082 struct inquiry_data data;
3083 int i;
3084
3085 if (!hci_ev_skb_pull(hdev, skb, HCI_EV_INQUIRY_RESULT,
3086 flex_array_size(ev, info, ev->num)))
3087 return;
3088
3089 bt_dev_dbg(hdev, "num %d", ev->num);
3090
3091 if (!ev->num)
3092 return;
3093
3094 if (hci_dev_test_flag(hdev, HCI_PERIODIC_INQ))
3095 return;
3096
3097 hci_dev_lock(hdev);
3098
3099 for (i = 0; i < ev->num; i++) {
3100 struct inquiry_info *info = &ev->info[i];
3101 u32 flags;
3102
3103 bacpy(&data.bdaddr, &info->bdaddr);
3104 data.pscan_rep_mode = info->pscan_rep_mode;
3105 data.pscan_period_mode = info->pscan_period_mode;
3106 data.pscan_mode = info->pscan_mode;
3107 memcpy(data.dev_class, info->dev_class, 3);
3108 data.clock_offset = info->clock_offset;
3109 data.rssi = HCI_RSSI_INVALID;
3110 data.ssp_mode = 0x00;
3111
3112 flags = hci_inquiry_cache_update(hdev, &data, false);
3113
3114 mgmt_device_found(hdev, &info->bdaddr, ACL_LINK, 0x00,
3115 info->dev_class, HCI_RSSI_INVALID,
3116 flags, NULL, 0, NULL, 0, 0);
3117 }
3118
3119 hci_dev_unlock(hdev);
3120 }
3121
hci_read_enc_key_size(struct hci_dev * hdev,struct hci_conn * conn)3122 static int hci_read_enc_key_size(struct hci_dev *hdev, struct hci_conn *conn)
3123 {
3124 struct hci_cp_read_enc_key_size cp;
3125 u8 *key_enc_size = hci_conn_key_enc_size(conn);
3126
3127 if (!read_key_size_capable(hdev)) {
3128 conn->enc_key_size = HCI_LINK_KEY_SIZE;
3129 return -EOPNOTSUPP;
3130 }
3131
3132 bt_dev_dbg(hdev, "hcon %p", conn);
3133
3134 memset(&cp, 0, sizeof(cp));
3135 cp.handle = cpu_to_le16(conn->handle);
3136
3137 /* If the key enc_size is already known, use it as conn->enc_key_size,
3138 * otherwise use hdev->min_enc_key_size so the likes of
3139 * l2cap_check_enc_key_size don't fail while waiting for
3140 * HCI_OP_READ_ENC_KEY_SIZE response.
3141 */
3142 if (key_enc_size && *key_enc_size)
3143 conn->enc_key_size = *key_enc_size;
3144 else
3145 conn->enc_key_size = hdev->min_enc_key_size;
3146
3147 return hci_send_cmd(hdev, HCI_OP_READ_ENC_KEY_SIZE, sizeof(cp), &cp);
3148 }
3149
hci_conn_complete_evt(struct hci_dev * hdev,void * data,struct sk_buff * skb)3150 static void hci_conn_complete_evt(struct hci_dev *hdev, void *data,
3151 struct sk_buff *skb)
3152 {
3153 struct hci_ev_conn_complete *ev = data;
3154 struct hci_conn *conn;
3155 u8 status = ev->status;
3156
3157 bt_dev_dbg(hdev, "status 0x%2.2x", status);
3158
3159 hci_dev_lock(hdev);
3160 hci_store_wake_reason(hdev, &ev->bdaddr, BDADDR_BREDR);
3161
3162 /* Check for existing connection:
3163 *
3164 * 1. If it doesn't exist then it must be receiver/slave role.
3165 * 2. If it does exist confirm that it is connecting/BT_CONNECT in case
3166 * of initiator/master role since there could be a collision where
3167 * either side is attempting to connect or something like a fuzzing
3168 * testing is trying to play tricks to destroy the hcon object before
3169 * it even attempts to connect (e.g. hcon->state == BT_OPEN).
3170 */
3171 conn = hci_conn_hash_lookup_ba(hdev, ev->link_type, &ev->bdaddr);
3172 if (!conn ||
3173 (conn->role == HCI_ROLE_MASTER && conn->state != BT_CONNECT)) {
3174 /* In case of error status and there is no connection pending
3175 * just unlock as there is nothing to cleanup.
3176 */
3177 if (ev->status)
3178 goto unlock;
3179
3180 /* Connection may not exist if auto-connected. Check the bredr
3181 * allowlist to see if this device is allowed to auto connect.
3182 * If link is an ACL type, create a connection class
3183 * automatically.
3184 *
3185 * Auto-connect will only occur if the event filter is
3186 * programmed with a given address. Right now, event filter is
3187 * only used during suspend.
3188 */
3189 if (ev->link_type == ACL_LINK &&
3190 hci_bdaddr_list_lookup_with_flags(&hdev->accept_list,
3191 &ev->bdaddr,
3192 BDADDR_BREDR)) {
3193 conn = hci_conn_add_unset(hdev, ev->link_type,
3194 &ev->bdaddr, 0,
3195 HCI_ROLE_SLAVE);
3196 if (IS_ERR(conn)) {
3197 bt_dev_err(hdev, "connection err: %ld", PTR_ERR(conn));
3198 goto unlock;
3199 }
3200 } else {
3201 if (ev->link_type != SCO_LINK)
3202 goto unlock;
3203
3204 conn = hci_conn_hash_lookup_ba(hdev, ESCO_LINK,
3205 &ev->bdaddr);
3206 if (!conn)
3207 goto unlock;
3208
3209 conn->type = SCO_LINK;
3210 }
3211 }
3212
3213 /* The HCI_Connection_Complete event is only sent once per connection.
3214 * Processing it more than once per connection can corrupt kernel memory.
3215 *
3216 * As the connection handle is set here for the first time, it indicates
3217 * whether the connection is already set up.
3218 */
3219 if (!HCI_CONN_HANDLE_UNSET(conn->handle)) {
3220 bt_dev_err(hdev, "Ignoring HCI_Connection_Complete for existing connection");
3221 goto unlock;
3222 }
3223
3224 if (!status) {
3225 status = hci_conn_set_handle(conn, __le16_to_cpu(ev->handle));
3226 if (status)
3227 goto done;
3228
3229 if (conn->type == ACL_LINK) {
3230 conn->state = BT_CONFIG;
3231 hci_conn_hold(conn);
3232
3233 if (!conn->out && !hci_conn_ssp_enabled(conn) &&
3234 !hci_find_link_key(hdev, &ev->bdaddr))
3235 conn->disc_timeout = HCI_PAIRING_TIMEOUT;
3236 else
3237 conn->disc_timeout = HCI_DISCONN_TIMEOUT;
3238 } else
3239 conn->state = BT_CONNECTED;
3240
3241 hci_debugfs_create_conn(conn);
3242 hci_conn_add_sysfs(conn);
3243
3244 if (test_bit(HCI_AUTH, &hdev->flags))
3245 set_bit(HCI_CONN_AUTH, &conn->flags);
3246
3247 if (test_bit(HCI_ENCRYPT, &hdev->flags))
3248 set_bit(HCI_CONN_ENCRYPT, &conn->flags);
3249
3250 /* "Link key request" completed ahead of "connect request" completes */
3251 if (ev->encr_mode == 1 && !test_bit(HCI_CONN_ENCRYPT, &conn->flags) &&
3252 ev->link_type == ACL_LINK) {
3253 struct link_key *key;
3254
3255 key = hci_find_link_key(hdev, &ev->bdaddr);
3256 if (key) {
3257 set_bit(HCI_CONN_ENCRYPT, &conn->flags);
3258 hci_read_enc_key_size(hdev, conn);
3259 hci_encrypt_cfm(conn, ev->status);
3260 }
3261 }
3262
3263 /* Get remote features */
3264 if (conn->type == ACL_LINK) {
3265 struct hci_cp_read_remote_features cp;
3266 cp.handle = ev->handle;
3267 hci_send_cmd(hdev, HCI_OP_READ_REMOTE_FEATURES,
3268 sizeof(cp), &cp);
3269
3270 hci_update_scan(hdev);
3271 }
3272
3273 /* Set packet type for incoming connection */
3274 if (!conn->out && hdev->hci_ver < BLUETOOTH_VER_2_0) {
3275 struct hci_cp_change_conn_ptype cp;
3276 cp.handle = ev->handle;
3277 cp.pkt_type = cpu_to_le16(conn->pkt_type);
3278 hci_send_cmd(hdev, HCI_OP_CHANGE_CONN_PTYPE, sizeof(cp),
3279 &cp);
3280 }
3281 }
3282
3283 if (conn->type == ACL_LINK)
3284 hci_sco_setup(conn, ev->status);
3285
3286 done:
3287 if (status) {
3288 hci_conn_failed(conn, status);
3289 } else if (ev->link_type == SCO_LINK) {
3290 switch (conn->setting & SCO_AIRMODE_MASK) {
3291 case SCO_AIRMODE_CVSD:
3292 if (hdev->notify)
3293 hdev->notify(hdev, HCI_NOTIFY_ENABLE_SCO_CVSD);
3294 break;
3295 }
3296
3297 hci_connect_cfm(conn, status);
3298 }
3299
3300 unlock:
3301 hci_dev_unlock(hdev);
3302 }
3303
hci_reject_conn(struct hci_dev * hdev,bdaddr_t * bdaddr)3304 static void hci_reject_conn(struct hci_dev *hdev, bdaddr_t *bdaddr)
3305 {
3306 struct hci_cp_reject_conn_req cp;
3307
3308 bacpy(&cp.bdaddr, bdaddr);
3309 cp.reason = HCI_ERROR_REJ_BAD_ADDR;
3310 hci_send_cmd(hdev, HCI_OP_REJECT_CONN_REQ, sizeof(cp), &cp);
3311 }
3312
hci_conn_request_evt(struct hci_dev * hdev,void * data,struct sk_buff * skb)3313 static void hci_conn_request_evt(struct hci_dev *hdev, void *data,
3314 struct sk_buff *skb)
3315 {
3316 struct hci_ev_conn_request *ev = data;
3317 int mask = hdev->link_mode;
3318 struct inquiry_entry *ie;
3319 struct hci_conn *conn;
3320 __u8 flags = 0;
3321
3322 bt_dev_dbg(hdev, "bdaddr %pMR type 0x%x", &ev->bdaddr, ev->link_type);
3323
3324 hci_dev_lock(hdev);
3325 hci_store_wake_reason(hdev, &ev->bdaddr, BDADDR_BREDR);
3326 hci_dev_unlock(hdev);
3327
3328 /* Reject incoming connection from device with same BD ADDR against
3329 * CVE-2020-26555
3330 */
3331 if (hdev && !bacmp(&hdev->bdaddr, &ev->bdaddr)) {
3332 bt_dev_dbg(hdev, "Reject connection with same BD_ADDR %pMR\n",
3333 &ev->bdaddr);
3334 hci_reject_conn(hdev, &ev->bdaddr);
3335 return;
3336 }
3337
3338 mask |= hci_proto_connect_ind(hdev, &ev->bdaddr, ev->link_type,
3339 &flags);
3340
3341 if (!(mask & HCI_LM_ACCEPT)) {
3342 hci_reject_conn(hdev, &ev->bdaddr);
3343 return;
3344 }
3345
3346 hci_dev_lock(hdev);
3347
3348 if (hci_bdaddr_list_lookup(&hdev->reject_list, &ev->bdaddr,
3349 BDADDR_BREDR)) {
3350 hci_reject_conn(hdev, &ev->bdaddr);
3351 goto unlock;
3352 }
3353
3354 /* Require HCI_CONNECTABLE or an accept list entry to accept the
3355 * connection. These features are only touched through mgmt so
3356 * only do the checks if HCI_MGMT is set.
3357 */
3358 if (hci_dev_test_flag(hdev, HCI_MGMT) &&
3359 !hci_dev_test_flag(hdev, HCI_CONNECTABLE) &&
3360 !hci_bdaddr_list_lookup_with_flags(&hdev->accept_list, &ev->bdaddr,
3361 BDADDR_BREDR)) {
3362 hci_reject_conn(hdev, &ev->bdaddr);
3363 goto unlock;
3364 }
3365
3366 /* Connection accepted */
3367
3368 ie = hci_inquiry_cache_lookup(hdev, &ev->bdaddr);
3369 if (ie)
3370 memcpy(ie->data.dev_class, ev->dev_class, 3);
3371
3372 conn = hci_conn_hash_lookup_ba(hdev, ev->link_type,
3373 &ev->bdaddr);
3374 if (!conn) {
3375 conn = hci_conn_add_unset(hdev, ev->link_type, &ev->bdaddr, 0,
3376 HCI_ROLE_SLAVE);
3377 if (IS_ERR(conn)) {
3378 bt_dev_err(hdev, "connection err: %ld", PTR_ERR(conn));
3379 goto unlock;
3380 }
3381 }
3382
3383 memcpy(conn->dev_class, ev->dev_class, 3);
3384
3385 if (ev->link_type == ACL_LINK ||
3386 (!(flags & HCI_PROTO_DEFER) && !lmp_esco_capable(hdev))) {
3387 struct hci_cp_accept_conn_req cp;
3388 conn->state = BT_CONNECT;
3389
3390 bacpy(&cp.bdaddr, &ev->bdaddr);
3391
3392 if (lmp_rswitch_capable(hdev) && (mask & HCI_LM_MASTER))
3393 cp.role = 0x00; /* Become central */
3394 else
3395 cp.role = 0x01; /* Remain peripheral */
3396
3397 hci_send_cmd(hdev, HCI_OP_ACCEPT_CONN_REQ, sizeof(cp), &cp);
3398 } else if (!(flags & HCI_PROTO_DEFER)) {
3399 struct hci_cp_accept_sync_conn_req cp;
3400 conn->state = BT_CONNECT;
3401
3402 bacpy(&cp.bdaddr, &ev->bdaddr);
3403 cp.pkt_type = cpu_to_le16(conn->pkt_type);
3404
3405 cp.tx_bandwidth = cpu_to_le32(0x00001f40);
3406 cp.rx_bandwidth = cpu_to_le32(0x00001f40);
3407 cp.max_latency = cpu_to_le16(0xffff);
3408 cp.content_format = cpu_to_le16(hdev->voice_setting);
3409 cp.retrans_effort = 0xff;
3410
3411 hci_send_cmd(hdev, HCI_OP_ACCEPT_SYNC_CONN_REQ, sizeof(cp),
3412 &cp);
3413 } else {
3414 conn->state = BT_CONNECT2;
3415 hci_connect_cfm(conn, 0);
3416 }
3417
3418 unlock:
3419 hci_dev_unlock(hdev);
3420 }
3421
hci_disconn_complete_evt(struct hci_dev * hdev,void * data,struct sk_buff * skb)3422 static void hci_disconn_complete_evt(struct hci_dev *hdev, void *data,
3423 struct sk_buff *skb)
3424 {
3425 struct hci_ev_disconn_complete *ev = data;
3426 u8 reason;
3427 struct hci_conn_params *params;
3428 struct hci_conn *conn;
3429 bool mgmt_connected;
3430
3431 bt_dev_dbg(hdev, "status 0x%2.2x", ev->status);
3432
3433 hci_dev_lock(hdev);
3434
3435 conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(ev->handle));
3436 if (!conn)
3437 goto unlock;
3438
3439 if (ev->status) {
3440 mgmt_disconnect_failed(hdev, &conn->dst, conn->type,
3441 conn->dst_type, ev->status);
3442 goto unlock;
3443 }
3444
3445 conn->state = BT_CLOSED;
3446
3447 mgmt_connected = test_and_clear_bit(HCI_CONN_MGMT_CONNECTED, &conn->flags);
3448
3449 if (test_bit(HCI_CONN_AUTH_FAILURE, &conn->flags))
3450 reason = MGMT_DEV_DISCONN_AUTH_FAILURE;
3451 else
3452 reason = hci_to_mgmt_reason(ev->reason);
3453
3454 mgmt_device_disconnected(hdev, &conn->dst, conn->type, conn->dst_type,
3455 reason, mgmt_connected);
3456
3457 if (conn->type == ACL_LINK) {
3458 if (test_and_clear_bit(HCI_CONN_FLUSH_KEY, &conn->flags))
3459 hci_remove_link_key(hdev, &conn->dst);
3460
3461 hci_update_scan(hdev);
3462 }
3463
3464 /* Re-enable passive scanning if disconnected device is marked
3465 * as auto-connectable.
3466 */
3467 if (conn->type == LE_LINK) {
3468 params = hci_conn_params_lookup(hdev, &conn->dst,
3469 conn->dst_type);
3470 if (params) {
3471 switch (params->auto_connect) {
3472 case HCI_AUTO_CONN_LINK_LOSS:
3473 if (ev->reason != HCI_ERROR_CONNECTION_TIMEOUT)
3474 break;
3475 fallthrough;
3476
3477 case HCI_AUTO_CONN_DIRECT:
3478 case HCI_AUTO_CONN_ALWAYS:
3479 hci_pend_le_list_del_init(params);
3480 hci_pend_le_list_add(params,
3481 &hdev->pend_le_conns);
3482 hci_update_passive_scan(hdev);
3483 break;
3484
3485 default:
3486 break;
3487 }
3488 }
3489 }
3490
3491 hci_disconn_cfm(conn, ev->reason);
3492
3493 /* Re-enable advertising if necessary, since it might
3494 * have been disabled by the connection. From the
3495 * HCI_LE_Set_Advertise_Enable command description in
3496 * the core specification (v4.0):
3497 * "The Controller shall continue advertising until the Host
3498 * issues an LE_Set_Advertise_Enable command with
3499 * Advertising_Enable set to 0x00 (Advertising is disabled)
3500 * or until a connection is created or until the Advertising
3501 * is timed out due to Directed Advertising."
3502 */
3503 if (conn->type == LE_LINK && conn->role == HCI_ROLE_SLAVE) {
3504 hdev->cur_adv_instance = conn->adv_instance;
3505 hci_enable_advertising(hdev);
3506 }
3507
3508 hci_conn_del(conn);
3509
3510 unlock:
3511 hci_dev_unlock(hdev);
3512 }
3513
hci_auth_complete_evt(struct hci_dev * hdev,void * data,struct sk_buff * skb)3514 static void hci_auth_complete_evt(struct hci_dev *hdev, void *data,
3515 struct sk_buff *skb)
3516 {
3517 struct hci_ev_auth_complete *ev = data;
3518 struct hci_conn *conn;
3519
3520 bt_dev_dbg(hdev, "status 0x%2.2x", ev->status);
3521
3522 hci_dev_lock(hdev);
3523
3524 conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(ev->handle));
3525 if (!conn)
3526 goto unlock;
3527
3528 if (!ev->status) {
3529 clear_bit(HCI_CONN_AUTH_FAILURE, &conn->flags);
3530 set_bit(HCI_CONN_AUTH, &conn->flags);
3531 conn->sec_level = conn->pending_sec_level;
3532 } else {
3533 if (ev->status == HCI_ERROR_PIN_OR_KEY_MISSING)
3534 set_bit(HCI_CONN_AUTH_FAILURE, &conn->flags);
3535
3536 mgmt_auth_failed(conn, ev->status);
3537 }
3538
3539 clear_bit(HCI_CONN_AUTH_PEND, &conn->flags);
3540
3541 if (conn->state == BT_CONFIG) {
3542 if (!ev->status && hci_conn_ssp_enabled(conn)) {
3543 struct hci_cp_set_conn_encrypt cp;
3544 cp.handle = ev->handle;
3545 cp.encrypt = 0x01;
3546 hci_send_cmd(hdev, HCI_OP_SET_CONN_ENCRYPT, sizeof(cp),
3547 &cp);
3548 } else {
3549 conn->state = BT_CONNECTED;
3550 hci_connect_cfm(conn, ev->status);
3551 hci_conn_drop(conn);
3552 }
3553 } else {
3554 hci_auth_cfm(conn, ev->status);
3555
3556 hci_conn_hold(conn);
3557 conn->disc_timeout = HCI_DISCONN_TIMEOUT;
3558 hci_conn_drop(conn);
3559 }
3560
3561 if (test_bit(HCI_CONN_ENCRYPT_PEND, &conn->flags)) {
3562 if (!ev->status) {
3563 struct hci_cp_set_conn_encrypt cp;
3564 cp.handle = ev->handle;
3565 cp.encrypt = 0x01;
3566 hci_send_cmd(hdev, HCI_OP_SET_CONN_ENCRYPT, sizeof(cp),
3567 &cp);
3568 } else {
3569 clear_bit(HCI_CONN_ENCRYPT_PEND, &conn->flags);
3570 hci_encrypt_cfm(conn, ev->status);
3571 }
3572 }
3573
3574 unlock:
3575 hci_dev_unlock(hdev);
3576 }
3577
hci_remote_name_evt(struct hci_dev * hdev,void * data,struct sk_buff * skb)3578 static void hci_remote_name_evt(struct hci_dev *hdev, void *data,
3579 struct sk_buff *skb)
3580 {
3581 struct hci_ev_remote_name *ev = data;
3582 struct hci_conn *conn;
3583
3584 bt_dev_dbg(hdev, "status 0x%2.2x", ev->status);
3585
3586 hci_dev_lock(hdev);
3587
3588 conn = hci_conn_hash_lookup_ba(hdev, ACL_LINK, &ev->bdaddr);
3589
3590 if (!hci_dev_test_flag(hdev, HCI_MGMT))
3591 goto check_auth;
3592
3593 if (ev->status == 0)
3594 hci_check_pending_name(hdev, conn, &ev->bdaddr, ev->name,
3595 strnlen(ev->name, HCI_MAX_NAME_LENGTH));
3596 else
3597 hci_check_pending_name(hdev, conn, &ev->bdaddr, NULL, 0);
3598
3599 check_auth:
3600 if (!conn)
3601 goto unlock;
3602
3603 if (!hci_outgoing_auth_needed(hdev, conn))
3604 goto unlock;
3605
3606 if (!test_and_set_bit(HCI_CONN_AUTH_PEND, &conn->flags)) {
3607 struct hci_cp_auth_requested cp;
3608
3609 set_bit(HCI_CONN_AUTH_INITIATOR, &conn->flags);
3610
3611 cp.handle = __cpu_to_le16(conn->handle);
3612 hci_send_cmd(hdev, HCI_OP_AUTH_REQUESTED, sizeof(cp), &cp);
3613 }
3614
3615 unlock:
3616 hci_dev_unlock(hdev);
3617 }
3618
hci_encrypt_change_evt(struct hci_dev * hdev,void * data,struct sk_buff * skb)3619 static void hci_encrypt_change_evt(struct hci_dev *hdev, void *data,
3620 struct sk_buff *skb)
3621 {
3622 struct hci_ev_encrypt_change *ev = data;
3623 struct hci_conn *conn;
3624
3625 bt_dev_dbg(hdev, "status 0x%2.2x", ev->status);
3626
3627 hci_dev_lock(hdev);
3628
3629 conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(ev->handle));
3630 if (!conn)
3631 goto unlock;
3632
3633 if (!ev->status) {
3634 if (ev->encrypt) {
3635 /* Encryption implies authentication */
3636 set_bit(HCI_CONN_AUTH, &conn->flags);
3637 set_bit(HCI_CONN_ENCRYPT, &conn->flags);
3638 conn->sec_level = conn->pending_sec_level;
3639
3640 /* P-256 authentication key implies FIPS */
3641 if (conn->key_type == HCI_LK_AUTH_COMBINATION_P256)
3642 set_bit(HCI_CONN_FIPS, &conn->flags);
3643
3644 if ((conn->type == ACL_LINK && ev->encrypt == 0x02) ||
3645 conn->type == LE_LINK)
3646 set_bit(HCI_CONN_AES_CCM, &conn->flags);
3647 } else {
3648 clear_bit(HCI_CONN_ENCRYPT, &conn->flags);
3649 clear_bit(HCI_CONN_AES_CCM, &conn->flags);
3650 }
3651 }
3652
3653 /* We should disregard the current RPA and generate a new one
3654 * whenever the encryption procedure fails.
3655 */
3656 if (ev->status && conn->type == LE_LINK) {
3657 hci_dev_set_flag(hdev, HCI_RPA_EXPIRED);
3658 hci_adv_instances_set_rpa_expired(hdev, true);
3659 }
3660
3661 clear_bit(HCI_CONN_ENCRYPT_PEND, &conn->flags);
3662
3663 /* Check link security requirements are met */
3664 if (!hci_conn_check_link_mode(conn))
3665 ev->status = HCI_ERROR_AUTH_FAILURE;
3666
3667 if (ev->status && conn->state == BT_CONNECTED) {
3668 if (ev->status == HCI_ERROR_PIN_OR_KEY_MISSING)
3669 set_bit(HCI_CONN_AUTH_FAILURE, &conn->flags);
3670
3671 /* Notify upper layers so they can cleanup before
3672 * disconnecting.
3673 */
3674 hci_encrypt_cfm(conn, ev->status);
3675 hci_disconnect(conn, HCI_ERROR_AUTH_FAILURE);
3676 hci_conn_drop(conn);
3677 goto unlock;
3678 }
3679
3680 /* Try reading the encryption key size for encrypted ACL links */
3681 if (!ev->status && ev->encrypt && conn->type == ACL_LINK) {
3682 if (hci_read_enc_key_size(hdev, conn))
3683 goto notify;
3684
3685 goto unlock;
3686 }
3687
3688 /* We skip the WRITE_AUTH_PAYLOAD_TIMEOUT for ATS2851 based controllers
3689 * to avoid unexpected SMP command errors when pairing.
3690 */
3691 if (hci_test_quirk(hdev, HCI_QUIRK_BROKEN_WRITE_AUTH_PAYLOAD_TIMEOUT))
3692 goto notify;
3693
3694 /* Set the default Authenticated Payload Timeout after
3695 * an LE Link is established. As per Core Spec v5.0, Vol 2, Part B
3696 * Section 3.3, the HCI command WRITE_AUTH_PAYLOAD_TIMEOUT should be
3697 * sent when the link is active and Encryption is enabled, the conn
3698 * type can be either LE or ACL and controller must support LMP Ping.
3699 * Ensure for AES-CCM encryption as well.
3700 */
3701 if (test_bit(HCI_CONN_ENCRYPT, &conn->flags) &&
3702 test_bit(HCI_CONN_AES_CCM, &conn->flags) &&
3703 ((conn->type == ACL_LINK && lmp_ping_capable(hdev)) ||
3704 (conn->type == LE_LINK && (hdev->le_features[0] & HCI_LE_PING)))) {
3705 struct hci_cp_write_auth_payload_to cp;
3706
3707 cp.handle = cpu_to_le16(conn->handle);
3708 cp.timeout = cpu_to_le16(hdev->auth_payload_timeout);
3709 if (hci_send_cmd(conn->hdev, HCI_OP_WRITE_AUTH_PAYLOAD_TO,
3710 sizeof(cp), &cp))
3711 bt_dev_err(hdev, "write auth payload timeout failed");
3712 }
3713
3714 notify:
3715 hci_encrypt_cfm(conn, ev->status);
3716
3717 unlock:
3718 hci_dev_unlock(hdev);
3719 }
3720
hci_change_link_key_complete_evt(struct hci_dev * hdev,void * data,struct sk_buff * skb)3721 static void hci_change_link_key_complete_evt(struct hci_dev *hdev, void *data,
3722 struct sk_buff *skb)
3723 {
3724 struct hci_ev_change_link_key_complete *ev = data;
3725 struct hci_conn *conn;
3726
3727 bt_dev_dbg(hdev, "status 0x%2.2x", ev->status);
3728
3729 hci_dev_lock(hdev);
3730
3731 conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(ev->handle));
3732 if (conn) {
3733 if (!ev->status)
3734 set_bit(HCI_CONN_SECURE, &conn->flags);
3735
3736 clear_bit(HCI_CONN_AUTH_PEND, &conn->flags);
3737
3738 hci_key_change_cfm(conn, ev->status);
3739 }
3740
3741 hci_dev_unlock(hdev);
3742 }
3743
hci_remote_features_evt(struct hci_dev * hdev,void * data,struct sk_buff * skb)3744 static void hci_remote_features_evt(struct hci_dev *hdev, void *data,
3745 struct sk_buff *skb)
3746 {
3747 struct hci_ev_remote_features *ev = data;
3748 struct hci_conn *conn;
3749
3750 bt_dev_dbg(hdev, "status 0x%2.2x", ev->status);
3751
3752 hci_dev_lock(hdev);
3753
3754 conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(ev->handle));
3755 if (!conn)
3756 goto unlock;
3757
3758 if (!ev->status)
3759 memcpy(conn->features[0], ev->features, 8);
3760
3761 if (conn->state != BT_CONFIG)
3762 goto unlock;
3763
3764 if (!ev->status && lmp_ext_feat_capable(hdev) &&
3765 lmp_ext_feat_capable(conn)) {
3766 struct hci_cp_read_remote_ext_features cp;
3767 cp.handle = ev->handle;
3768 cp.page = 0x01;
3769 hci_send_cmd(hdev, HCI_OP_READ_REMOTE_EXT_FEATURES,
3770 sizeof(cp), &cp);
3771 goto unlock;
3772 }
3773
3774 if (!ev->status) {
3775 struct hci_cp_remote_name_req cp;
3776 memset(&cp, 0, sizeof(cp));
3777 bacpy(&cp.bdaddr, &conn->dst);
3778 cp.pscan_rep_mode = 0x02;
3779 hci_send_cmd(hdev, HCI_OP_REMOTE_NAME_REQ, sizeof(cp), &cp);
3780 } else {
3781 mgmt_device_connected(hdev, conn, NULL, 0);
3782 }
3783
3784 if (!hci_outgoing_auth_needed(hdev, conn)) {
3785 conn->state = BT_CONNECTED;
3786 hci_connect_cfm(conn, ev->status);
3787 hci_conn_drop(conn);
3788 }
3789
3790 unlock:
3791 hci_dev_unlock(hdev);
3792 }
3793
handle_cmd_cnt_and_timer(struct hci_dev * hdev,u8 ncmd)3794 static inline void handle_cmd_cnt_and_timer(struct hci_dev *hdev, u8 ncmd)
3795 {
3796 cancel_delayed_work(&hdev->cmd_timer);
3797
3798 rcu_read_lock();
3799 if (!test_bit(HCI_RESET, &hdev->flags)) {
3800 if (ncmd) {
3801 cancel_delayed_work(&hdev->ncmd_timer);
3802 atomic_set(&hdev->cmd_cnt, 1);
3803 } else {
3804 if (!hci_dev_test_flag(hdev, HCI_CMD_DRAIN_WORKQUEUE))
3805 queue_delayed_work(hdev->workqueue, &hdev->ncmd_timer,
3806 HCI_NCMD_TIMEOUT);
3807 }
3808 }
3809 rcu_read_unlock();
3810 }
3811
hci_cc_le_read_buffer_size_v2(struct hci_dev * hdev,void * data,struct sk_buff * skb)3812 static u8 hci_cc_le_read_buffer_size_v2(struct hci_dev *hdev, void *data,
3813 struct sk_buff *skb)
3814 {
3815 struct hci_rp_le_read_buffer_size_v2 *rp = data;
3816
3817 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
3818
3819 if (rp->status)
3820 return rp->status;
3821
3822 hdev->le_mtu = __le16_to_cpu(rp->acl_mtu);
3823 hdev->le_pkts = rp->acl_max_pkt;
3824 hdev->iso_mtu = __le16_to_cpu(rp->iso_mtu);
3825 hdev->iso_pkts = rp->iso_max_pkt;
3826
3827 hdev->le_cnt = hdev->le_pkts;
3828 hdev->iso_cnt = hdev->iso_pkts;
3829
3830 BT_DBG("%s acl mtu %d:%d iso mtu %d:%d", hdev->name, hdev->acl_mtu,
3831 hdev->acl_pkts, hdev->iso_mtu, hdev->iso_pkts);
3832
3833 if (hdev->le_mtu && hdev->le_mtu < HCI_MIN_LE_MTU)
3834 return HCI_ERROR_INVALID_PARAMETERS;
3835
3836 return rp->status;
3837 }
3838
hci_unbound_cis_failed(struct hci_dev * hdev,u8 cig,u8 status)3839 static void hci_unbound_cis_failed(struct hci_dev *hdev, u8 cig, u8 status)
3840 {
3841 struct hci_conn *conn, *tmp;
3842
3843 lockdep_assert_held(&hdev->lock);
3844
3845 list_for_each_entry_safe(conn, tmp, &hdev->conn_hash.list, list) {
3846 if (conn->type != CIS_LINK ||
3847 conn->state == BT_OPEN || conn->iso_qos.ucast.cig != cig)
3848 continue;
3849
3850 if (HCI_CONN_HANDLE_UNSET(conn->handle))
3851 hci_conn_failed(conn, status);
3852 }
3853 }
3854
hci_cc_le_set_cig_params(struct hci_dev * hdev,void * data,struct sk_buff * skb)3855 static u8 hci_cc_le_set_cig_params(struct hci_dev *hdev, void *data,
3856 struct sk_buff *skb)
3857 {
3858 struct hci_rp_le_set_cig_params *rp = data;
3859 struct hci_cp_le_set_cig_params *cp;
3860 struct hci_conn *conn;
3861 u8 status = rp->status;
3862 bool pending = false;
3863 int i;
3864
3865 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
3866
3867 cp = hci_sent_cmd_data(hdev, HCI_OP_LE_SET_CIG_PARAMS);
3868 if (!rp->status &&
3869 (!cp || rp->num_handles != cp->num_cis ||
3870 rp->cig_id != cp->cig_id ||
3871 skb->len < array_size(rp->num_handles, sizeof(*rp->handle)))) {
3872 bt_dev_err(hdev, "unexpected Set CIG Parameters response data");
3873 status = HCI_ERROR_UNSPECIFIED;
3874 }
3875
3876 hci_dev_lock(hdev);
3877
3878 /* BLUETOOTH CORE SPECIFICATION Version 5.4 | Vol 4, Part E page 2554
3879 *
3880 * If the Status return parameter is non-zero, then the state of the CIG
3881 * and its CIS configurations shall not be changed by the command. If
3882 * the CIG did not already exist, it shall not be created.
3883 */
3884 if (status) {
3885 /* Keep current configuration, fail only the unbound CIS */
3886 hci_unbound_cis_failed(hdev, rp->cig_id, status);
3887 goto unlock;
3888 }
3889
3890 /* BLUETOOTH CORE SPECIFICATION Version 5.3 | Vol 4, Part E page 2553
3891 *
3892 * If the Status return parameter is zero, then the Controller shall
3893 * set the Connection_Handle arrayed return parameter to the connection
3894 * handle(s) corresponding to the CIS configurations specified in
3895 * the CIS_IDs command parameter, in the same order.
3896 */
3897 for (i = 0; i < rp->num_handles; ++i) {
3898 conn = hci_conn_hash_lookup_cis(hdev, NULL, 0, rp->cig_id,
3899 cp->cis[i].cis_id);
3900 if (!conn || !bacmp(&conn->dst, BDADDR_ANY))
3901 continue;
3902
3903 if (conn->state != BT_BOUND && conn->state != BT_CONNECT)
3904 continue;
3905
3906 if (hci_conn_set_handle(conn, __le16_to_cpu(rp->handle[i])))
3907 continue;
3908
3909 if (conn->state == BT_CONNECT)
3910 pending = true;
3911 }
3912
3913 unlock:
3914 if (pending)
3915 hci_le_create_cis_pending(hdev);
3916
3917 hci_dev_unlock(hdev);
3918
3919 return rp->status;
3920 }
3921
hci_cc_le_setup_iso_path(struct hci_dev * hdev,void * data,struct sk_buff * skb)3922 static u8 hci_cc_le_setup_iso_path(struct hci_dev *hdev, void *data,
3923 struct sk_buff *skb)
3924 {
3925 struct hci_rp_le_setup_iso_path *rp = data;
3926 struct hci_cp_le_setup_iso_path *cp;
3927 struct hci_conn *conn;
3928
3929 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
3930
3931 cp = hci_sent_cmd_data(hdev, HCI_OP_LE_SETUP_ISO_PATH);
3932 if (!cp)
3933 return rp->status;
3934
3935 hci_dev_lock(hdev);
3936
3937 conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(cp->handle));
3938 if (!conn)
3939 goto unlock;
3940
3941 if (rp->status) {
3942 hci_connect_cfm(conn, rp->status);
3943 hci_conn_del(conn);
3944 goto unlock;
3945 }
3946
3947 switch (cp->direction) {
3948 /* Input (Host to Controller) */
3949 case 0x00:
3950 /* Only confirm connection if output only */
3951 if (conn->iso_qos.ucast.out.sdu && !conn->iso_qos.ucast.in.sdu)
3952 hci_connect_cfm(conn, rp->status);
3953 break;
3954 /* Output (Controller to Host) */
3955 case 0x01:
3956 /* Confirm connection since conn->iso_qos is always configured
3957 * last.
3958 */
3959 hci_connect_cfm(conn, rp->status);
3960
3961 /* Notify device connected in case it is a BIG Sync */
3962 if (!rp->status && test_bit(HCI_CONN_BIG_SYNC, &conn->flags))
3963 mgmt_device_connected(hdev, conn, NULL, 0);
3964
3965 break;
3966 }
3967
3968 unlock:
3969 hci_dev_unlock(hdev);
3970 return rp->status;
3971 }
3972
hci_cc_le_read_all_local_features(struct hci_dev * hdev,void * data,struct sk_buff * skb)3973 static u8 hci_cc_le_read_all_local_features(struct hci_dev *hdev, void *data,
3974 struct sk_buff *skb)
3975 {
3976 struct hci_rp_le_read_all_local_features *rp = data;
3977
3978 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
3979
3980 if (rp->status)
3981 return rp->status;
3982
3983 memcpy(hdev->le_features, rp->features, 248);
3984
3985 return rp->status;
3986 }
3987
hci_cs_le_create_big(struct hci_dev * hdev,u8 status)3988 static void hci_cs_le_create_big(struct hci_dev *hdev, u8 status)
3989 {
3990 bt_dev_dbg(hdev, "status 0x%2.2x", status);
3991 }
3992
hci_cs_le_read_all_remote_features(struct hci_dev * hdev,u8 status)3993 static void hci_cs_le_read_all_remote_features(struct hci_dev *hdev, u8 status)
3994 {
3995 struct hci_cp_le_read_remote_features *cp;
3996 struct hci_conn *conn;
3997
3998 bt_dev_dbg(hdev, "status 0x%2.2x", status);
3999
4000 if (!status)
4001 return;
4002
4003 cp = hci_sent_cmd_data(hdev, HCI_OP_LE_READ_ALL_REMOTE_FEATURES);
4004 if (!cp)
4005 return;
4006
4007 hci_dev_lock(hdev);
4008
4009 conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(cp->handle));
4010 if (conn && conn->state == BT_CONFIG)
4011 hci_connect_cfm(conn, status);
4012
4013 hci_dev_unlock(hdev);
4014 }
4015
hci_cc_set_per_adv_param(struct hci_dev * hdev,void * data,struct sk_buff * skb)4016 static u8 hci_cc_set_per_adv_param(struct hci_dev *hdev, void *data,
4017 struct sk_buff *skb)
4018 {
4019 struct hci_ev_status *rp = data;
4020 struct hci_cp_le_set_per_adv_params *cp;
4021
4022 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
4023
4024 if (rp->status)
4025 return rp->status;
4026
4027 cp = hci_sent_cmd_data(hdev, HCI_OP_LE_SET_PER_ADV_PARAMS);
4028 if (!cp)
4029 return rp->status;
4030
4031 /* TODO: set the conn state */
4032 return rp->status;
4033 }
4034
hci_cc_le_set_per_adv_enable(struct hci_dev * hdev,void * data,struct sk_buff * skb)4035 static u8 hci_cc_le_set_per_adv_enable(struct hci_dev *hdev, void *data,
4036 struct sk_buff *skb)
4037 {
4038 struct hci_ev_status *rp = data;
4039 struct hci_cp_le_set_per_adv_enable *cp;
4040 struct adv_info *adv = NULL, *n;
4041 u8 per_adv_cnt = 0;
4042
4043 bt_dev_dbg(hdev, "status 0x%2.2x", rp->status);
4044
4045 if (rp->status)
4046 return rp->status;
4047
4048 cp = hci_sent_cmd_data(hdev, HCI_OP_LE_SET_PER_ADV_ENABLE);
4049 if (!cp)
4050 return rp->status;
4051
4052 hci_dev_lock(hdev);
4053
4054 adv = hci_find_adv_instance(hdev, cp->handle);
4055
4056 if (cp->enable) {
4057 hci_dev_set_flag(hdev, HCI_LE_PER_ADV);
4058
4059 if (adv)
4060 adv->periodic_enabled = true;
4061 } else {
4062 if (adv)
4063 adv->periodic_enabled = false;
4064
4065 /* If just one instance was disabled check if there are
4066 * any other instance enabled before clearing HCI_LE_PER_ADV.
4067 * The current periodic adv instance will be marked as
4068 * disabled once extended advertising is also disabled.
4069 */
4070 list_for_each_entry_safe(adv, n, &hdev->adv_instances,
4071 list) {
4072 if (adv->periodic && adv->enabled)
4073 per_adv_cnt++;
4074 }
4075
4076 if (per_adv_cnt > 1)
4077 goto unlock;
4078
4079 hci_dev_clear_flag(hdev, HCI_LE_PER_ADV);
4080 }
4081
4082 unlock:
4083 hci_dev_unlock(hdev);
4084
4085 return rp->status;
4086 }
4087
4088 #define HCI_CC_VL(_op, _func, _min, _max) \
4089 { \
4090 .op = _op, \
4091 .func = _func, \
4092 .min_len = _min, \
4093 .max_len = _max, \
4094 }
4095
4096 #define HCI_CC(_op, _func, _len) \
4097 HCI_CC_VL(_op, _func, _len, _len)
4098
4099 #define HCI_CC_STATUS(_op, _func) \
4100 HCI_CC(_op, _func, sizeof(struct hci_ev_status))
4101
4102 static const struct hci_cc {
4103 u16 op;
4104 u8 (*func)(struct hci_dev *hdev, void *data, struct sk_buff *skb);
4105 u16 min_len;
4106 u16 max_len;
4107 } hci_cc_table[] = {
4108 HCI_CC_STATUS(HCI_OP_INQUIRY_CANCEL, hci_cc_inquiry_cancel),
4109 HCI_CC_STATUS(HCI_OP_PERIODIC_INQ, hci_cc_periodic_inq),
4110 HCI_CC_STATUS(HCI_OP_EXIT_PERIODIC_INQ, hci_cc_exit_periodic_inq),
4111 HCI_CC(HCI_OP_REMOTE_NAME_REQ_CANCEL, hci_cc_remote_name_req_cancel,
4112 sizeof(struct hci_rp_remote_name_req_cancel)),
4113 HCI_CC(HCI_OP_ROLE_DISCOVERY, hci_cc_role_discovery,
4114 sizeof(struct hci_rp_role_discovery)),
4115 HCI_CC(HCI_OP_READ_LINK_POLICY, hci_cc_read_link_policy,
4116 sizeof(struct hci_rp_read_link_policy)),
4117 HCI_CC(HCI_OP_WRITE_LINK_POLICY, hci_cc_write_link_policy,
4118 sizeof(struct hci_rp_write_link_policy)),
4119 HCI_CC(HCI_OP_READ_DEF_LINK_POLICY, hci_cc_read_def_link_policy,
4120 sizeof(struct hci_rp_read_def_link_policy)),
4121 HCI_CC_STATUS(HCI_OP_WRITE_DEF_LINK_POLICY,
4122 hci_cc_write_def_link_policy),
4123 HCI_CC_STATUS(HCI_OP_RESET, hci_cc_reset),
4124 HCI_CC(HCI_OP_READ_STORED_LINK_KEY, hci_cc_read_stored_link_key,
4125 sizeof(struct hci_rp_read_stored_link_key)),
4126 HCI_CC(HCI_OP_DELETE_STORED_LINK_KEY, hci_cc_delete_stored_link_key,
4127 sizeof(struct hci_rp_delete_stored_link_key)),
4128 HCI_CC_STATUS(HCI_OP_WRITE_LOCAL_NAME, hci_cc_write_local_name),
4129 HCI_CC(HCI_OP_READ_LOCAL_NAME, hci_cc_read_local_name,
4130 sizeof(struct hci_rp_read_local_name)),
4131 HCI_CC_STATUS(HCI_OP_WRITE_AUTH_ENABLE, hci_cc_write_auth_enable),
4132 HCI_CC_STATUS(HCI_OP_WRITE_ENCRYPT_MODE, hci_cc_write_encrypt_mode),
4133 HCI_CC_STATUS(HCI_OP_WRITE_SCAN_ENABLE, hci_cc_write_scan_enable),
4134 HCI_CC_STATUS(HCI_OP_SET_EVENT_FLT, hci_cc_set_event_filter),
4135 HCI_CC(HCI_OP_READ_CLASS_OF_DEV, hci_cc_read_class_of_dev,
4136 sizeof(struct hci_rp_read_class_of_dev)),
4137 HCI_CC_STATUS(HCI_OP_WRITE_CLASS_OF_DEV, hci_cc_write_class_of_dev),
4138 HCI_CC(HCI_OP_READ_VOICE_SETTING, hci_cc_read_voice_setting,
4139 sizeof(struct hci_rp_read_voice_setting)),
4140 HCI_CC_STATUS(HCI_OP_WRITE_VOICE_SETTING, hci_cc_write_voice_setting),
4141 HCI_CC(HCI_OP_READ_NUM_SUPPORTED_IAC, hci_cc_read_num_supported_iac,
4142 sizeof(struct hci_rp_read_num_supported_iac)),
4143 HCI_CC_STATUS(HCI_OP_WRITE_SSP_MODE, hci_cc_write_ssp_mode),
4144 HCI_CC_STATUS(HCI_OP_WRITE_SC_SUPPORT, hci_cc_write_sc_support),
4145 HCI_CC(HCI_OP_READ_AUTH_PAYLOAD_TO, hci_cc_read_auth_payload_timeout,
4146 sizeof(struct hci_rp_read_auth_payload_to)),
4147 HCI_CC(HCI_OP_WRITE_AUTH_PAYLOAD_TO, hci_cc_write_auth_payload_timeout,
4148 sizeof(struct hci_rp_write_auth_payload_to)),
4149 HCI_CC(HCI_OP_READ_LOCAL_VERSION, hci_cc_read_local_version,
4150 sizeof(struct hci_rp_read_local_version)),
4151 HCI_CC(HCI_OP_READ_LOCAL_COMMANDS, hci_cc_read_local_commands,
4152 sizeof(struct hci_rp_read_local_commands)),
4153 HCI_CC(HCI_OP_READ_LOCAL_FEATURES, hci_cc_read_local_features,
4154 sizeof(struct hci_rp_read_local_features)),
4155 HCI_CC(HCI_OP_READ_LOCAL_EXT_FEATURES, hci_cc_read_local_ext_features,
4156 sizeof(struct hci_rp_read_local_ext_features)),
4157 HCI_CC(HCI_OP_READ_BUFFER_SIZE, hci_cc_read_buffer_size,
4158 sizeof(struct hci_rp_read_buffer_size)),
4159 HCI_CC(HCI_OP_READ_BD_ADDR, hci_cc_read_bd_addr,
4160 sizeof(struct hci_rp_read_bd_addr)),
4161 HCI_CC(HCI_OP_READ_LOCAL_PAIRING_OPTS, hci_cc_read_local_pairing_opts,
4162 sizeof(struct hci_rp_read_local_pairing_opts)),
4163 HCI_CC(HCI_OP_READ_PAGE_SCAN_ACTIVITY, hci_cc_read_page_scan_activity,
4164 sizeof(struct hci_rp_read_page_scan_activity)),
4165 HCI_CC_STATUS(HCI_OP_WRITE_PAGE_SCAN_ACTIVITY,
4166 hci_cc_write_page_scan_activity),
4167 HCI_CC(HCI_OP_READ_PAGE_SCAN_TYPE, hci_cc_read_page_scan_type,
4168 sizeof(struct hci_rp_read_page_scan_type)),
4169 HCI_CC_STATUS(HCI_OP_WRITE_PAGE_SCAN_TYPE, hci_cc_write_page_scan_type),
4170 HCI_CC(HCI_OP_READ_CLOCK, hci_cc_read_clock,
4171 sizeof(struct hci_rp_read_clock)),
4172 HCI_CC(HCI_OP_READ_ENC_KEY_SIZE, hci_cc_read_enc_key_size,
4173 sizeof(struct hci_rp_read_enc_key_size)),
4174 HCI_CC(HCI_OP_READ_INQ_RSP_TX_POWER, hci_cc_read_inq_rsp_tx_power,
4175 sizeof(struct hci_rp_read_inq_rsp_tx_power)),
4176 HCI_CC(HCI_OP_READ_DEF_ERR_DATA_REPORTING,
4177 hci_cc_read_def_err_data_reporting,
4178 sizeof(struct hci_rp_read_def_err_data_reporting)),
4179 HCI_CC_STATUS(HCI_OP_WRITE_DEF_ERR_DATA_REPORTING,
4180 hci_cc_write_def_err_data_reporting),
4181 HCI_CC(HCI_OP_PIN_CODE_REPLY, hci_cc_pin_code_reply,
4182 sizeof(struct hci_rp_pin_code_reply)),
4183 HCI_CC(HCI_OP_PIN_CODE_NEG_REPLY, hci_cc_pin_code_neg_reply,
4184 sizeof(struct hci_rp_pin_code_neg_reply)),
4185 HCI_CC(HCI_OP_READ_LOCAL_OOB_DATA, hci_cc_read_local_oob_data,
4186 sizeof(struct hci_rp_read_local_oob_data)),
4187 HCI_CC(HCI_OP_READ_LOCAL_OOB_EXT_DATA, hci_cc_read_local_oob_ext_data,
4188 sizeof(struct hci_rp_read_local_oob_ext_data)),
4189 HCI_CC(HCI_OP_LE_READ_BUFFER_SIZE, hci_cc_le_read_buffer_size,
4190 sizeof(struct hci_rp_le_read_buffer_size)),
4191 HCI_CC(HCI_OP_LE_READ_LOCAL_FEATURES, hci_cc_le_read_local_features,
4192 sizeof(struct hci_rp_le_read_local_features)),
4193 HCI_CC_VL(HCI_OP_LE_READ_CONN_INTERVAL, hci_cc_le_read_conn_interval,
4194 sizeof(struct hci_rp_le_read_conn_interval),
4195 HCI_MAX_EVENT_SIZE),
4196 HCI_CC(HCI_OP_LE_READ_ADV_TX_POWER, hci_cc_le_read_adv_tx_power,
4197 sizeof(struct hci_rp_le_read_adv_tx_power)),
4198 HCI_CC(HCI_OP_USER_CONFIRM_REPLY, hci_cc_user_confirm_reply,
4199 sizeof(struct hci_rp_user_confirm_reply)),
4200 HCI_CC(HCI_OP_USER_CONFIRM_NEG_REPLY, hci_cc_user_confirm_neg_reply,
4201 sizeof(struct hci_rp_user_confirm_reply)),
4202 HCI_CC(HCI_OP_USER_PASSKEY_REPLY, hci_cc_user_passkey_reply,
4203 sizeof(struct hci_rp_user_confirm_reply)),
4204 HCI_CC(HCI_OP_USER_PASSKEY_NEG_REPLY, hci_cc_user_passkey_neg_reply,
4205 sizeof(struct hci_rp_user_confirm_reply)),
4206 HCI_CC_STATUS(HCI_OP_LE_SET_RANDOM_ADDR, hci_cc_le_set_random_addr),
4207 HCI_CC_STATUS(HCI_OP_LE_SET_ADV_ENABLE, hci_cc_le_set_adv_enable),
4208 HCI_CC_STATUS(HCI_OP_LE_SET_SCAN_PARAM, hci_cc_le_set_scan_param),
4209 HCI_CC_STATUS(HCI_OP_LE_SET_SCAN_ENABLE, hci_cc_le_set_scan_enable),
4210 HCI_CC(HCI_OP_LE_READ_ACCEPT_LIST_SIZE,
4211 hci_cc_le_read_accept_list_size,
4212 sizeof(struct hci_rp_le_read_accept_list_size)),
4213 HCI_CC_STATUS(HCI_OP_LE_CLEAR_ACCEPT_LIST, hci_cc_le_clear_accept_list),
4214 HCI_CC_STATUS(HCI_OP_LE_ADD_TO_ACCEPT_LIST,
4215 hci_cc_le_add_to_accept_list),
4216 HCI_CC_STATUS(HCI_OP_LE_DEL_FROM_ACCEPT_LIST,
4217 hci_cc_le_del_from_accept_list),
4218 HCI_CC(HCI_OP_LE_READ_SUPPORTED_STATES, hci_cc_le_read_supported_states,
4219 sizeof(struct hci_rp_le_read_supported_states)),
4220 HCI_CC(HCI_OP_LE_READ_DEF_DATA_LEN, hci_cc_le_read_def_data_len,
4221 sizeof(struct hci_rp_le_read_def_data_len)),
4222 HCI_CC_STATUS(HCI_OP_LE_WRITE_DEF_DATA_LEN,
4223 hci_cc_le_write_def_data_len),
4224 HCI_CC_STATUS(HCI_OP_LE_ADD_TO_RESOLV_LIST,
4225 hci_cc_le_add_to_resolv_list),
4226 HCI_CC_STATUS(HCI_OP_LE_DEL_FROM_RESOLV_LIST,
4227 hci_cc_le_del_from_resolv_list),
4228 HCI_CC_STATUS(HCI_OP_LE_CLEAR_RESOLV_LIST,
4229 hci_cc_le_clear_resolv_list),
4230 HCI_CC(HCI_OP_LE_READ_RESOLV_LIST_SIZE, hci_cc_le_read_resolv_list_size,
4231 sizeof(struct hci_rp_le_read_resolv_list_size)),
4232 HCI_CC_STATUS(HCI_OP_LE_SET_ADDR_RESOLV_ENABLE,
4233 hci_cc_le_set_addr_resolution_enable),
4234 HCI_CC(HCI_OP_LE_READ_MAX_DATA_LEN, hci_cc_le_read_max_data_len,
4235 sizeof(struct hci_rp_le_read_max_data_len)),
4236 HCI_CC_STATUS(HCI_OP_WRITE_LE_HOST_SUPPORTED,
4237 hci_cc_write_le_host_supported),
4238 HCI_CC_STATUS(HCI_OP_LE_SET_ADV_PARAM, hci_cc_set_adv_param),
4239 HCI_CC(HCI_OP_READ_RSSI, hci_cc_read_rssi,
4240 sizeof(struct hci_rp_read_rssi)),
4241 HCI_CC(HCI_OP_READ_TX_POWER, hci_cc_read_tx_power,
4242 sizeof(struct hci_rp_read_tx_power)),
4243 HCI_CC_STATUS(HCI_OP_WRITE_SSP_DEBUG_MODE, hci_cc_write_ssp_debug_mode),
4244 HCI_CC_STATUS(HCI_OP_LE_SET_EXT_SCAN_PARAMS,
4245 hci_cc_le_set_ext_scan_param),
4246 HCI_CC_STATUS(HCI_OP_LE_SET_EXT_SCAN_ENABLE,
4247 hci_cc_le_set_ext_scan_enable),
4248 HCI_CC_STATUS(HCI_OP_LE_SET_DEFAULT_PHY, hci_cc_le_set_default_phy),
4249 HCI_CC(HCI_OP_LE_READ_NUM_SUPPORTED_ADV_SETS,
4250 hci_cc_le_read_num_adv_sets,
4251 sizeof(struct hci_rp_le_read_num_supported_adv_sets)),
4252 HCI_CC_STATUS(HCI_OP_LE_SET_EXT_ADV_ENABLE,
4253 hci_cc_le_set_ext_adv_enable),
4254 HCI_CC_STATUS(HCI_OP_LE_SET_ADV_SET_RAND_ADDR,
4255 hci_cc_le_set_adv_set_random_addr),
4256 HCI_CC_STATUS(HCI_OP_LE_REMOVE_ADV_SET, hci_cc_le_remove_adv_set),
4257 HCI_CC_STATUS(HCI_OP_LE_CLEAR_ADV_SETS, hci_cc_le_clear_adv_sets),
4258 HCI_CC_STATUS(HCI_OP_LE_SET_PER_ADV_PARAMS, hci_cc_set_per_adv_param),
4259 HCI_CC_STATUS(HCI_OP_LE_SET_PER_ADV_ENABLE,
4260 hci_cc_le_set_per_adv_enable),
4261 HCI_CC(HCI_OP_LE_READ_TRANSMIT_POWER, hci_cc_le_read_transmit_power,
4262 sizeof(struct hci_rp_le_read_transmit_power)),
4263 HCI_CC_STATUS(HCI_OP_LE_SET_PRIVACY_MODE, hci_cc_le_set_privacy_mode),
4264 HCI_CC(HCI_OP_LE_READ_BUFFER_SIZE_V2, hci_cc_le_read_buffer_size_v2,
4265 sizeof(struct hci_rp_le_read_buffer_size_v2)),
4266 HCI_CC_VL(HCI_OP_LE_SET_CIG_PARAMS, hci_cc_le_set_cig_params,
4267 sizeof(struct hci_rp_le_set_cig_params), HCI_MAX_EVENT_SIZE),
4268 HCI_CC(HCI_OP_LE_SETUP_ISO_PATH, hci_cc_le_setup_iso_path,
4269 sizeof(struct hci_rp_le_setup_iso_path)),
4270 HCI_CC(HCI_OP_LE_READ_ALL_LOCAL_FEATURES,
4271 hci_cc_le_read_all_local_features,
4272 sizeof(struct hci_rp_le_read_all_local_features)),
4273 };
4274
hci_cc_func(struct hci_dev * hdev,const struct hci_cc * cc,struct sk_buff * skb)4275 static u8 hci_cc_func(struct hci_dev *hdev, const struct hci_cc *cc,
4276 struct sk_buff *skb)
4277 {
4278 void *data;
4279
4280 if (skb->len < cc->min_len) {
4281 bt_dev_err(hdev, "unexpected cc 0x%4.4x length: %u < %u",
4282 cc->op, skb->len, cc->min_len);
4283 return HCI_ERROR_UNSPECIFIED;
4284 }
4285
4286 /* Just warn if the length is over max_len size it still be possible to
4287 * partially parse the cc so leave to callback to decide if that is
4288 * acceptable.
4289 */
4290 if (skb->len > cc->max_len)
4291 bt_dev_warn(hdev, "unexpected cc 0x%4.4x length: %u > %u",
4292 cc->op, skb->len, cc->max_len);
4293
4294 data = hci_cc_skb_pull(hdev, skb, cc->op, cc->min_len);
4295 if (!data)
4296 return HCI_ERROR_UNSPECIFIED;
4297
4298 return cc->func(hdev, data, skb);
4299 }
4300
hci_cmd_complete_evt(struct hci_dev * hdev,void * data,struct sk_buff * skb,u16 * opcode,u8 * status,hci_req_complete_t * req_complete,hci_req_complete_skb_t * req_complete_skb)4301 static void hci_cmd_complete_evt(struct hci_dev *hdev, void *data,
4302 struct sk_buff *skb, u16 *opcode, u8 *status,
4303 hci_req_complete_t *req_complete,
4304 hci_req_complete_skb_t *req_complete_skb)
4305 {
4306 struct hci_ev_cmd_complete *ev = data;
4307 int i;
4308
4309 *opcode = __le16_to_cpu(ev->opcode);
4310
4311 bt_dev_dbg(hdev, "opcode 0x%4.4x", *opcode);
4312
4313 for (i = 0; i < ARRAY_SIZE(hci_cc_table); i++) {
4314 if (hci_cc_table[i].op == *opcode) {
4315 *status = hci_cc_func(hdev, &hci_cc_table[i], skb);
4316 break;
4317 }
4318 }
4319
4320 if (i == ARRAY_SIZE(hci_cc_table)) {
4321 if (!skb->len) {
4322 bt_dev_err(hdev, "Unexpected cc 0x%4.4x with no status",
4323 *opcode);
4324 *status = HCI_ERROR_UNSPECIFIED;
4325 return;
4326 }
4327
4328 /* Unknown opcode, assume byte 0 contains the status, so
4329 * that e.g. __hci_cmd_sync() properly returns errors
4330 * for vendor specific commands send by HCI drivers.
4331 * If a vendor doesn't actually follow this convention we may
4332 * need to introduce a vendor CC table in order to properly set
4333 * the status.
4334 */
4335 *status = skb->data[0];
4336 }
4337
4338 handle_cmd_cnt_and_timer(hdev, ev->ncmd);
4339
4340 hci_req_cmd_complete(hdev, *opcode, *status, req_complete,
4341 req_complete_skb);
4342
4343 if (hci_dev_test_flag(hdev, HCI_CMD_PENDING)) {
4344 bt_dev_err(hdev,
4345 "unexpected event for opcode 0x%4.4x", *opcode);
4346 return;
4347 }
4348
4349 if (atomic_read(&hdev->cmd_cnt) && !skb_queue_empty(&hdev->cmd_q))
4350 queue_work(hdev->workqueue, &hdev->cmd_work);
4351 }
4352
hci_cs_le_create_cis(struct hci_dev * hdev,u8 status)4353 static void hci_cs_le_create_cis(struct hci_dev *hdev, u8 status)
4354 {
4355 struct hci_cp_le_create_cis *cp;
4356 bool pending = false;
4357 int i;
4358
4359 bt_dev_dbg(hdev, "status 0x%2.2x", status);
4360
4361 if (!status)
4362 return;
4363
4364 cp = hci_sent_cmd_data(hdev, HCI_OP_LE_CREATE_CIS);
4365 if (!cp)
4366 return;
4367
4368 hci_dev_lock(hdev);
4369
4370 /* Remove connection if command failed */
4371 for (i = 0; i < cp->num_cis; i++) {
4372 struct hci_conn *conn;
4373 u16 handle;
4374
4375 handle = __le16_to_cpu(cp->cis[i].cis_handle);
4376
4377 conn = hci_conn_hash_lookup_handle(hdev, handle);
4378 if (conn) {
4379 if (test_and_clear_bit(HCI_CONN_CREATE_CIS,
4380 &conn->flags))
4381 pending = true;
4382 conn->state = BT_CLOSED;
4383 hci_connect_cfm(conn, status);
4384 hci_conn_del(conn);
4385 }
4386 }
4387 cp->num_cis = 0;
4388
4389 if (pending)
4390 hci_le_create_cis_pending(hdev);
4391
4392 hci_dev_unlock(hdev);
4393 }
4394
4395 #define HCI_CS(_op, _func) \
4396 { \
4397 .op = _op, \
4398 .func = _func, \
4399 }
4400
4401 static const struct hci_cs {
4402 u16 op;
4403 void (*func)(struct hci_dev *hdev, __u8 status);
4404 } hci_cs_table[] = {
4405 HCI_CS(HCI_OP_INQUIRY, hci_cs_inquiry),
4406 HCI_CS(HCI_OP_CREATE_CONN, hci_cs_create_conn),
4407 HCI_CS(HCI_OP_DISCONNECT, hci_cs_disconnect),
4408 HCI_CS(HCI_OP_ADD_SCO, hci_cs_add_sco),
4409 HCI_CS(HCI_OP_AUTH_REQUESTED, hci_cs_auth_requested),
4410 HCI_CS(HCI_OP_SET_CONN_ENCRYPT, hci_cs_set_conn_encrypt),
4411 HCI_CS(HCI_OP_REMOTE_NAME_REQ, hci_cs_remote_name_req),
4412 HCI_CS(HCI_OP_READ_REMOTE_FEATURES, hci_cs_read_remote_features),
4413 HCI_CS(HCI_OP_READ_REMOTE_EXT_FEATURES,
4414 hci_cs_read_remote_ext_features),
4415 HCI_CS(HCI_OP_SETUP_SYNC_CONN, hci_cs_setup_sync_conn),
4416 HCI_CS(HCI_OP_ENHANCED_SETUP_SYNC_CONN,
4417 hci_cs_enhanced_setup_sync_conn),
4418 HCI_CS(HCI_OP_SNIFF_MODE, hci_cs_sniff_mode),
4419 HCI_CS(HCI_OP_EXIT_SNIFF_MODE, hci_cs_exit_sniff_mode),
4420 HCI_CS(HCI_OP_SWITCH_ROLE, hci_cs_switch_role),
4421 HCI_CS(HCI_OP_LE_CREATE_CONN, hci_cs_le_create_conn),
4422 HCI_CS(HCI_OP_LE_READ_REMOTE_FEATURES, hci_cs_le_read_remote_features),
4423 HCI_CS(HCI_OP_LE_START_ENC, hci_cs_le_start_enc),
4424 HCI_CS(HCI_OP_LE_SET_PHY, hci_cs_le_set_phy),
4425 HCI_CS(HCI_OP_LE_EXT_CREATE_CONN, hci_cs_le_ext_create_conn),
4426 HCI_CS(HCI_OP_LE_CREATE_CIS, hci_cs_le_create_cis),
4427 HCI_CS(HCI_OP_LE_CREATE_BIG, hci_cs_le_create_big),
4428 HCI_CS(HCI_OP_LE_READ_ALL_REMOTE_FEATURES,
4429 hci_cs_le_read_all_remote_features),
4430 };
4431
hci_cmd_status_evt(struct hci_dev * hdev,void * data,struct sk_buff * skb,u16 * opcode,u8 * status,hci_req_complete_t * req_complete,hci_req_complete_skb_t * req_complete_skb)4432 static void hci_cmd_status_evt(struct hci_dev *hdev, void *data,
4433 struct sk_buff *skb, u16 *opcode, u8 *status,
4434 hci_req_complete_t *req_complete,
4435 hci_req_complete_skb_t *req_complete_skb)
4436 {
4437 struct hci_ev_cmd_status *ev = data;
4438 int i;
4439
4440 *opcode = __le16_to_cpu(ev->opcode);
4441 *status = ev->status;
4442
4443 bt_dev_dbg(hdev, "opcode 0x%4.4x", *opcode);
4444
4445 for (i = 0; i < ARRAY_SIZE(hci_cs_table); i++) {
4446 if (hci_cs_table[i].op == *opcode) {
4447 hci_cs_table[i].func(hdev, ev->status);
4448 break;
4449 }
4450 }
4451
4452 handle_cmd_cnt_and_timer(hdev, ev->ncmd);
4453
4454 /* Indicate request completion if the command failed. Also, if
4455 * we're not waiting for a special event and we get a success
4456 * command status we should try to flag the request as completed
4457 * (since for this kind of commands there will not be a command
4458 * complete event).
4459 */
4460 if (ev->status || (hdev->req_skb && !hci_skb_event(hdev->req_skb))) {
4461 hci_req_cmd_complete(hdev, *opcode, ev->status, req_complete,
4462 req_complete_skb);
4463 if (hci_dev_test_flag(hdev, HCI_CMD_PENDING)) {
4464 bt_dev_err(hdev, "unexpected event for opcode 0x%4.4x",
4465 *opcode);
4466 return;
4467 }
4468 }
4469
4470 if (atomic_read(&hdev->cmd_cnt) && !skb_queue_empty(&hdev->cmd_q))
4471 queue_work(hdev->workqueue, &hdev->cmd_work);
4472 }
4473
hci_hardware_error_evt(struct hci_dev * hdev,void * data,struct sk_buff * skb)4474 static void hci_hardware_error_evt(struct hci_dev *hdev, void *data,
4475 struct sk_buff *skb)
4476 {
4477 struct hci_ev_hardware_error *ev = data;
4478
4479 bt_dev_dbg(hdev, "code 0x%2.2x", ev->code);
4480
4481 hdev->hw_error_code = ev->code;
4482
4483 queue_work(hdev->req_workqueue, &hdev->error_reset);
4484 }
4485
hci_role_change_evt(struct hci_dev * hdev,void * data,struct sk_buff * skb)4486 static void hci_role_change_evt(struct hci_dev *hdev, void *data,
4487 struct sk_buff *skb)
4488 {
4489 struct hci_ev_role_change *ev = data;
4490 struct hci_conn *conn;
4491
4492 bt_dev_dbg(hdev, "status 0x%2.2x", ev->status);
4493
4494 hci_dev_lock(hdev);
4495
4496 conn = hci_conn_hash_lookup_ba(hdev, ACL_LINK, &ev->bdaddr);
4497 if (conn) {
4498 if (!ev->status)
4499 conn->role = ev->role;
4500
4501 clear_bit(HCI_CONN_RSWITCH_PEND, &conn->flags);
4502
4503 hci_role_switch_cfm(conn, ev->status, ev->role);
4504 }
4505
4506 hci_dev_unlock(hdev);
4507 }
4508
hci_num_comp_pkts_evt(struct hci_dev * hdev,void * data,struct sk_buff * skb)4509 static void hci_num_comp_pkts_evt(struct hci_dev *hdev, void *data,
4510 struct sk_buff *skb)
4511 {
4512 struct hci_ev_num_comp_pkts *ev = data;
4513 int i;
4514
4515 if (!hci_ev_skb_pull(hdev, skb, HCI_EV_NUM_COMP_PKTS,
4516 flex_array_size(ev, handles, ev->num)))
4517 return;
4518
4519 bt_dev_dbg(hdev, "num %d", ev->num);
4520
4521 hci_dev_lock(hdev);
4522
4523 for (i = 0; i < ev->num; i++) {
4524 struct hci_comp_pkts_info *info = &ev->handles[i];
4525 struct hci_conn *conn;
4526 __u16 handle, count;
4527 unsigned int i;
4528
4529 handle = __le16_to_cpu(info->handle);
4530 count = __le16_to_cpu(info->count);
4531
4532 conn = hci_conn_hash_lookup_handle(hdev, handle);
4533 if (!conn)
4534 continue;
4535
4536 /* Check if there is really enough packets outstanding before
4537 * attempting to decrease the sent counter otherwise it could
4538 * underflow..
4539 */
4540 if (conn->sent >= count) {
4541 conn->sent -= count;
4542 } else {
4543 bt_dev_warn(hdev, "hcon %p sent %u < count %u",
4544 conn, conn->sent, count);
4545 conn->sent = 0;
4546 }
4547
4548 for (i = 0; i < count; ++i)
4549 hci_conn_tx_dequeue(conn);
4550
4551 switch (conn->type) {
4552 case ACL_LINK:
4553 hdev->acl_cnt += count;
4554 if (hdev->acl_cnt > hdev->acl_pkts)
4555 hdev->acl_cnt = hdev->acl_pkts;
4556 break;
4557
4558 case LE_LINK:
4559 if (hdev->le_pkts) {
4560 hdev->le_cnt += count;
4561 if (hdev->le_cnt > hdev->le_pkts)
4562 hdev->le_cnt = hdev->le_pkts;
4563 } else {
4564 hdev->acl_cnt += count;
4565 if (hdev->acl_cnt > hdev->acl_pkts)
4566 hdev->acl_cnt = hdev->acl_pkts;
4567 }
4568 break;
4569
4570 case SCO_LINK:
4571 case ESCO_LINK:
4572 hdev->sco_cnt += count;
4573 if (hdev->sco_cnt > hdev->sco_pkts)
4574 hdev->sco_cnt = hdev->sco_pkts;
4575
4576 break;
4577
4578 case CIS_LINK:
4579 case BIS_LINK:
4580 case PA_LINK:
4581 hdev->iso_cnt += count;
4582 if (hdev->iso_cnt > hdev->iso_pkts)
4583 hdev->iso_cnt = hdev->iso_pkts;
4584 break;
4585
4586 default:
4587 bt_dev_err(hdev, "unknown type %d conn %p",
4588 conn->type, conn);
4589 break;
4590 }
4591 }
4592
4593 queue_work(hdev->workqueue, &hdev->tx_work);
4594
4595 hci_dev_unlock(hdev);
4596 }
4597
hci_mode_change_evt(struct hci_dev * hdev,void * data,struct sk_buff * skb)4598 static void hci_mode_change_evt(struct hci_dev *hdev, void *data,
4599 struct sk_buff *skb)
4600 {
4601 struct hci_ev_mode_change *ev = data;
4602 struct hci_conn *conn;
4603
4604 bt_dev_dbg(hdev, "status 0x%2.2x", ev->status);
4605
4606 hci_dev_lock(hdev);
4607
4608 conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(ev->handle));
4609 if (conn) {
4610 conn->mode = ev->mode;
4611
4612 if (!test_and_clear_bit(HCI_CONN_MODE_CHANGE_PEND,
4613 &conn->flags)) {
4614 if (conn->mode == HCI_CM_ACTIVE)
4615 set_bit(HCI_CONN_POWER_SAVE, &conn->flags);
4616 else
4617 clear_bit(HCI_CONN_POWER_SAVE, &conn->flags);
4618 }
4619
4620 if (test_and_clear_bit(HCI_CONN_SCO_SETUP_PEND, &conn->flags))
4621 hci_sco_setup(conn, ev->status);
4622 }
4623
4624 hci_dev_unlock(hdev);
4625 }
4626
hci_pin_code_request_evt(struct hci_dev * hdev,void * data,struct sk_buff * skb)4627 static void hci_pin_code_request_evt(struct hci_dev *hdev, void *data,
4628 struct sk_buff *skb)
4629 {
4630 struct hci_ev_pin_code_req *ev = data;
4631 struct hci_conn *conn;
4632
4633 bt_dev_dbg(hdev, "");
4634
4635 hci_dev_lock(hdev);
4636
4637 conn = hci_conn_hash_lookup_ba(hdev, ACL_LINK, &ev->bdaddr);
4638 if (!conn)
4639 goto unlock;
4640
4641 if (conn->state == BT_CONNECTED) {
4642 hci_conn_hold(conn);
4643 conn->disc_timeout = HCI_PAIRING_TIMEOUT;
4644 hci_conn_drop(conn);
4645 }
4646
4647 if (!hci_dev_test_flag(hdev, HCI_BONDABLE) &&
4648 !test_bit(HCI_CONN_AUTH_INITIATOR, &conn->flags)) {
4649 hci_send_cmd(hdev, HCI_OP_PIN_CODE_NEG_REPLY,
4650 sizeof(ev->bdaddr), &ev->bdaddr);
4651 } else if (hci_dev_test_flag(hdev, HCI_MGMT)) {
4652 u8 secure;
4653
4654 if (conn->pending_sec_level == BT_SECURITY_HIGH)
4655 secure = 1;
4656 else
4657 secure = 0;
4658
4659 mgmt_pin_code_request(hdev, &ev->bdaddr, secure);
4660 }
4661
4662 unlock:
4663 hci_dev_unlock(hdev);
4664 }
4665
conn_set_key(struct hci_conn * conn,u8 key_type,u8 pin_len)4666 static void conn_set_key(struct hci_conn *conn, u8 key_type, u8 pin_len)
4667 {
4668 if (key_type == HCI_LK_CHANGED_COMBINATION)
4669 return;
4670
4671 conn->pin_length = pin_len;
4672 conn->key_type = key_type;
4673
4674 switch (key_type) {
4675 case HCI_LK_LOCAL_UNIT:
4676 case HCI_LK_REMOTE_UNIT:
4677 case HCI_LK_DEBUG_COMBINATION:
4678 return;
4679 case HCI_LK_COMBINATION:
4680 if (pin_len == 16)
4681 conn->pending_sec_level = BT_SECURITY_HIGH;
4682 else
4683 conn->pending_sec_level = BT_SECURITY_MEDIUM;
4684 break;
4685 case HCI_LK_UNAUTH_COMBINATION_P192:
4686 case HCI_LK_UNAUTH_COMBINATION_P256:
4687 conn->pending_sec_level = BT_SECURITY_MEDIUM;
4688 break;
4689 case HCI_LK_AUTH_COMBINATION_P192:
4690 conn->pending_sec_level = BT_SECURITY_HIGH;
4691 break;
4692 case HCI_LK_AUTH_COMBINATION_P256:
4693 conn->pending_sec_level = BT_SECURITY_FIPS;
4694 break;
4695 }
4696 }
4697
hci_link_key_request_evt(struct hci_dev * hdev,void * data,struct sk_buff * skb)4698 static void hci_link_key_request_evt(struct hci_dev *hdev, void *data,
4699 struct sk_buff *skb)
4700 {
4701 struct hci_ev_link_key_req *ev = data;
4702 struct hci_cp_link_key_reply cp;
4703 struct hci_conn *conn;
4704 struct link_key *key;
4705
4706 bt_dev_dbg(hdev, "");
4707
4708 if (!hci_dev_test_flag(hdev, HCI_MGMT))
4709 return;
4710
4711 hci_dev_lock(hdev);
4712
4713 key = hci_find_link_key(hdev, &ev->bdaddr);
4714 if (!key) {
4715 bt_dev_dbg(hdev, "link key not found for %pMR", &ev->bdaddr);
4716 goto not_found;
4717 }
4718
4719 bt_dev_dbg(hdev, "found key type %u for %pMR", key->type, &ev->bdaddr);
4720
4721 conn = hci_conn_hash_lookup_ba(hdev, ACL_LINK, &ev->bdaddr);
4722 if (conn) {
4723 clear_bit(HCI_CONN_NEW_LINK_KEY, &conn->flags);
4724
4725 if ((key->type == HCI_LK_UNAUTH_COMBINATION_P192 ||
4726 key->type == HCI_LK_UNAUTH_COMBINATION_P256) &&
4727 conn->auth_type != 0xff && (conn->auth_type & 0x01)) {
4728 bt_dev_dbg(hdev, "ignoring unauthenticated key");
4729 goto not_found;
4730 }
4731
4732 if (key->type == HCI_LK_COMBINATION && key->pin_len < 16 &&
4733 (conn->pending_sec_level == BT_SECURITY_HIGH ||
4734 conn->pending_sec_level == BT_SECURITY_FIPS)) {
4735 bt_dev_dbg(hdev, "ignoring key unauthenticated for high security");
4736 goto not_found;
4737 }
4738
4739 conn_set_key(conn, key->type, key->pin_len);
4740 }
4741
4742 bacpy(&cp.bdaddr, &ev->bdaddr);
4743 memcpy(cp.link_key, key->val, HCI_LINK_KEY_SIZE);
4744
4745 hci_send_cmd(hdev, HCI_OP_LINK_KEY_REPLY, sizeof(cp), &cp);
4746
4747 hci_dev_unlock(hdev);
4748
4749 return;
4750
4751 not_found:
4752 hci_send_cmd(hdev, HCI_OP_LINK_KEY_NEG_REPLY, 6, &ev->bdaddr);
4753 hci_dev_unlock(hdev);
4754 }
4755
hci_link_key_notify_evt(struct hci_dev * hdev,void * data,struct sk_buff * skb)4756 static void hci_link_key_notify_evt(struct hci_dev *hdev, void *data,
4757 struct sk_buff *skb)
4758 {
4759 struct hci_ev_link_key_notify *ev = data;
4760 struct hci_conn *conn;
4761 struct link_key *key;
4762 bool persistent;
4763 u8 pin_len = 0;
4764
4765 bt_dev_dbg(hdev, "");
4766
4767 hci_dev_lock(hdev);
4768
4769 conn = hci_conn_hash_lookup_ba(hdev, ACL_LINK, &ev->bdaddr);
4770 if (!conn)
4771 goto unlock;
4772
4773 /* Ignore NULL link key against CVE-2020-26555 */
4774 if (!crypto_memneq(ev->link_key, ZERO_KEY, HCI_LINK_KEY_SIZE)) {
4775 bt_dev_dbg(hdev, "Ignore NULL link key (ZERO KEY) for %pMR",
4776 &ev->bdaddr);
4777 hci_disconnect(conn, HCI_ERROR_AUTH_FAILURE);
4778 hci_conn_drop(conn);
4779 goto unlock;
4780 }
4781
4782 hci_conn_hold(conn);
4783 conn->disc_timeout = HCI_DISCONN_TIMEOUT;
4784 hci_conn_drop(conn);
4785
4786 set_bit(HCI_CONN_NEW_LINK_KEY, &conn->flags);
4787 conn_set_key(conn, ev->key_type, conn->pin_length);
4788
4789 if (!hci_dev_test_flag(hdev, HCI_MGMT))
4790 goto unlock;
4791
4792 key = hci_add_link_key(hdev, conn, &ev->bdaddr, ev->link_key,
4793 ev->key_type, pin_len, &persistent);
4794 if (!key)
4795 goto unlock;
4796
4797 /* Update connection information since adding the key will have
4798 * fixed up the type in the case of changed combination keys.
4799 */
4800 if (ev->key_type == HCI_LK_CHANGED_COMBINATION)
4801 conn_set_key(conn, key->type, key->pin_len);
4802
4803 mgmt_new_link_key(hdev, key, persistent);
4804
4805 /* Keep debug keys around only if the HCI_KEEP_DEBUG_KEYS flag
4806 * is set. If it's not set simply remove the key from the kernel
4807 * list (we've still notified user space about it but with
4808 * store_hint being 0).
4809 */
4810 if (key->type == HCI_LK_DEBUG_COMBINATION &&
4811 !hci_dev_test_flag(hdev, HCI_KEEP_DEBUG_KEYS)) {
4812 list_del_rcu(&key->list);
4813 kfree_rcu(key, rcu);
4814 goto unlock;
4815 }
4816
4817 if (persistent)
4818 clear_bit(HCI_CONN_FLUSH_KEY, &conn->flags);
4819 else
4820 set_bit(HCI_CONN_FLUSH_KEY, &conn->flags);
4821
4822 unlock:
4823 hci_dev_unlock(hdev);
4824 }
4825
hci_clock_offset_evt(struct hci_dev * hdev,void * data,struct sk_buff * skb)4826 static void hci_clock_offset_evt(struct hci_dev *hdev, void *data,
4827 struct sk_buff *skb)
4828 {
4829 struct hci_ev_clock_offset *ev = data;
4830 struct hci_conn *conn;
4831
4832 bt_dev_dbg(hdev, "status 0x%2.2x", ev->status);
4833
4834 hci_dev_lock(hdev);
4835
4836 conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(ev->handle));
4837 if (conn && !ev->status) {
4838 struct inquiry_entry *ie;
4839
4840 ie = hci_inquiry_cache_lookup(hdev, &conn->dst);
4841 if (ie) {
4842 ie->data.clock_offset = ev->clock_offset;
4843 ie->timestamp = jiffies;
4844 }
4845 }
4846
4847 hci_dev_unlock(hdev);
4848 }
4849
hci_pkt_type_change_evt(struct hci_dev * hdev,void * data,struct sk_buff * skb)4850 static void hci_pkt_type_change_evt(struct hci_dev *hdev, void *data,
4851 struct sk_buff *skb)
4852 {
4853 struct hci_ev_pkt_type_change *ev = data;
4854 struct hci_conn *conn;
4855
4856 bt_dev_dbg(hdev, "status 0x%2.2x", ev->status);
4857
4858 hci_dev_lock(hdev);
4859
4860 conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(ev->handle));
4861 if (conn && !ev->status)
4862 conn->pkt_type = __le16_to_cpu(ev->pkt_type);
4863
4864 hci_dev_unlock(hdev);
4865 }
4866
hci_pscan_rep_mode_evt(struct hci_dev * hdev,void * data,struct sk_buff * skb)4867 static void hci_pscan_rep_mode_evt(struct hci_dev *hdev, void *data,
4868 struct sk_buff *skb)
4869 {
4870 struct hci_ev_pscan_rep_mode *ev = data;
4871 struct inquiry_entry *ie;
4872
4873 bt_dev_dbg(hdev, "");
4874
4875 hci_dev_lock(hdev);
4876
4877 ie = hci_inquiry_cache_lookup(hdev, &ev->bdaddr);
4878 if (ie) {
4879 ie->data.pscan_rep_mode = ev->pscan_rep_mode;
4880 ie->timestamp = jiffies;
4881 }
4882
4883 hci_dev_unlock(hdev);
4884 }
4885
hci_inquiry_result_with_rssi_evt(struct hci_dev * hdev,void * edata,struct sk_buff * skb)4886 static void hci_inquiry_result_with_rssi_evt(struct hci_dev *hdev, void *edata,
4887 struct sk_buff *skb)
4888 {
4889 struct hci_ev_inquiry_result_rssi *ev = edata;
4890 struct inquiry_data data;
4891 int i;
4892
4893 bt_dev_dbg(hdev, "num_rsp %d", ev->num);
4894
4895 if (!ev->num)
4896 return;
4897
4898 if (hci_dev_test_flag(hdev, HCI_PERIODIC_INQ))
4899 return;
4900
4901 hci_dev_lock(hdev);
4902
4903 if (skb->len == array_size(ev->num,
4904 sizeof(struct inquiry_info_rssi_pscan))) {
4905 struct inquiry_info_rssi_pscan *info;
4906
4907 for (i = 0; i < ev->num; i++) {
4908 u32 flags;
4909
4910 info = hci_ev_skb_pull(hdev, skb,
4911 HCI_EV_INQUIRY_RESULT_WITH_RSSI,
4912 sizeof(*info));
4913 if (!info) {
4914 bt_dev_err(hdev, "Malformed HCI Event: 0x%2.2x",
4915 HCI_EV_INQUIRY_RESULT_WITH_RSSI);
4916 goto unlock;
4917 }
4918
4919 bacpy(&data.bdaddr, &info->bdaddr);
4920 data.pscan_rep_mode = info->pscan_rep_mode;
4921 data.pscan_period_mode = info->pscan_period_mode;
4922 data.pscan_mode = info->pscan_mode;
4923 memcpy(data.dev_class, info->dev_class, 3);
4924 data.clock_offset = info->clock_offset;
4925 data.rssi = info->rssi;
4926 data.ssp_mode = 0x00;
4927
4928 flags = hci_inquiry_cache_update(hdev, &data, false);
4929
4930 mgmt_device_found(hdev, &info->bdaddr, ACL_LINK, 0x00,
4931 info->dev_class, info->rssi,
4932 flags, NULL, 0, NULL, 0, 0);
4933 }
4934 } else if (skb->len == array_size(ev->num,
4935 sizeof(struct inquiry_info_rssi))) {
4936 struct inquiry_info_rssi *info;
4937
4938 for (i = 0; i < ev->num; i++) {
4939 u32 flags;
4940
4941 info = hci_ev_skb_pull(hdev, skb,
4942 HCI_EV_INQUIRY_RESULT_WITH_RSSI,
4943 sizeof(*info));
4944 if (!info) {
4945 bt_dev_err(hdev, "Malformed HCI Event: 0x%2.2x",
4946 HCI_EV_INQUIRY_RESULT_WITH_RSSI);
4947 goto unlock;
4948 }
4949
4950 bacpy(&data.bdaddr, &info->bdaddr);
4951 data.pscan_rep_mode = info->pscan_rep_mode;
4952 data.pscan_period_mode = info->pscan_period_mode;
4953 data.pscan_mode = 0x00;
4954 memcpy(data.dev_class, info->dev_class, 3);
4955 data.clock_offset = info->clock_offset;
4956 data.rssi = info->rssi;
4957 data.ssp_mode = 0x00;
4958
4959 flags = hci_inquiry_cache_update(hdev, &data, false);
4960
4961 mgmt_device_found(hdev, &info->bdaddr, ACL_LINK, 0x00,
4962 info->dev_class, info->rssi,
4963 flags, NULL, 0, NULL, 0, 0);
4964 }
4965 } else {
4966 bt_dev_err(hdev, "Malformed HCI Event: 0x%2.2x",
4967 HCI_EV_INQUIRY_RESULT_WITH_RSSI);
4968 }
4969 unlock:
4970 hci_dev_unlock(hdev);
4971 }
4972
hci_remote_ext_features_evt(struct hci_dev * hdev,void * data,struct sk_buff * skb)4973 static void hci_remote_ext_features_evt(struct hci_dev *hdev, void *data,
4974 struct sk_buff *skb)
4975 {
4976 struct hci_ev_remote_ext_features *ev = data;
4977 struct hci_conn *conn;
4978
4979 bt_dev_dbg(hdev, "status 0x%2.2x", ev->status);
4980
4981 hci_dev_lock(hdev);
4982
4983 conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(ev->handle));
4984 if (!conn)
4985 goto unlock;
4986
4987 if (ev->page < HCI_MAX_PAGES)
4988 memcpy(conn->features[ev->page], ev->features, 8);
4989
4990 if (!ev->status && ev->page == 0x01) {
4991 struct inquiry_entry *ie;
4992
4993 ie = hci_inquiry_cache_lookup(hdev, &conn->dst);
4994 if (ie)
4995 ie->data.ssp_mode = (ev->features[0] & LMP_HOST_SSP);
4996
4997 if (ev->features[0] & LMP_HOST_SSP) {
4998 set_bit(HCI_CONN_SSP_ENABLED, &conn->flags);
4999 } else {
5000 /* It is mandatory by the Bluetooth specification that
5001 * Extended Inquiry Results are only used when Secure
5002 * Simple Pairing is enabled, but some devices violate
5003 * this.
5004 *
5005 * To make these devices work, the internal SSP
5006 * enabled flag needs to be cleared if the remote host
5007 * features do not indicate SSP support */
5008 clear_bit(HCI_CONN_SSP_ENABLED, &conn->flags);
5009 }
5010
5011 if (ev->features[0] & LMP_HOST_SC)
5012 set_bit(HCI_CONN_SC_ENABLED, &conn->flags);
5013 }
5014
5015 if (conn->state != BT_CONFIG)
5016 goto unlock;
5017
5018 if (!ev->status && !test_bit(HCI_CONN_MGMT_CONNECTED, &conn->flags)) {
5019 struct hci_cp_remote_name_req cp;
5020 memset(&cp, 0, sizeof(cp));
5021 bacpy(&cp.bdaddr, &conn->dst);
5022 cp.pscan_rep_mode = 0x02;
5023 hci_send_cmd(hdev, HCI_OP_REMOTE_NAME_REQ, sizeof(cp), &cp);
5024 } else {
5025 mgmt_device_connected(hdev, conn, NULL, 0);
5026 }
5027
5028 if (!hci_outgoing_auth_needed(hdev, conn)) {
5029 conn->state = BT_CONNECTED;
5030 hci_connect_cfm(conn, ev->status);
5031 hci_conn_drop(conn);
5032 }
5033
5034 unlock:
5035 hci_dev_unlock(hdev);
5036 }
5037
hci_sync_conn_complete_evt(struct hci_dev * hdev,void * data,struct sk_buff * skb)5038 static void hci_sync_conn_complete_evt(struct hci_dev *hdev, void *data,
5039 struct sk_buff *skb)
5040 {
5041 struct hci_ev_sync_conn_complete *ev = data;
5042 struct hci_conn *conn;
5043 u8 status = ev->status;
5044
5045 switch (ev->link_type) {
5046 case SCO_LINK:
5047 case ESCO_LINK:
5048 break;
5049 default:
5050 /* As per Core 5.3 Vol 4 Part E 7.7.35 (p.2219), Link_Type
5051 * for HCI_Synchronous_Connection_Complete is limited to
5052 * either SCO or eSCO
5053 */
5054 bt_dev_err(hdev, "Ignoring connect complete event for invalid link type");
5055 return;
5056 }
5057
5058 bt_dev_dbg(hdev, "status 0x%2.2x", status);
5059
5060 hci_dev_lock(hdev);
5061 hci_store_wake_reason(hdev, &ev->bdaddr, BDADDR_BREDR);
5062
5063 conn = hci_conn_hash_lookup_ba(hdev, ev->link_type, &ev->bdaddr);
5064 if (!conn) {
5065 if (ev->link_type == ESCO_LINK)
5066 goto unlock;
5067
5068 /* When the link type in the event indicates SCO connection
5069 * and lookup of the connection object fails, then check
5070 * if an eSCO connection object exists.
5071 *
5072 * The core limits the synchronous connections to either
5073 * SCO or eSCO. The eSCO connection is preferred and tried
5074 * to be setup first and until successfully established,
5075 * the link type will be hinted as eSCO.
5076 */
5077 conn = hci_conn_hash_lookup_ba(hdev, ESCO_LINK, &ev->bdaddr);
5078 if (!conn)
5079 goto unlock;
5080 }
5081
5082 /* The HCI_Synchronous_Connection_Complete event is only sent once per connection.
5083 * Processing it more than once per connection can corrupt kernel memory.
5084 *
5085 * As the connection handle is set here for the first time, it indicates
5086 * whether the connection is already set up.
5087 */
5088 if (!HCI_CONN_HANDLE_UNSET(conn->handle)) {
5089 bt_dev_err(hdev, "Ignoring HCI_Sync_Conn_Complete event for existing connection");
5090 goto unlock;
5091 }
5092
5093 switch (status) {
5094 case 0x00:
5095 status = hci_conn_set_handle(conn, __le16_to_cpu(ev->handle));
5096 if (status) {
5097 conn->state = BT_CLOSED;
5098 break;
5099 }
5100
5101 conn->state = BT_CONNECTED;
5102 conn->type = ev->link_type;
5103
5104 hci_debugfs_create_conn(conn);
5105 hci_conn_add_sysfs(conn);
5106 break;
5107
5108 case 0x10: /* Connection Accept Timeout */
5109 case 0x0d: /* Connection Rejected due to Limited Resources */
5110 case 0x11: /* Unsupported Feature or Parameter Value */
5111 case 0x1c: /* SCO interval rejected */
5112 case 0x1a: /* Unsupported Remote Feature */
5113 case 0x1e: /* Invalid LMP Parameters */
5114 case 0x1f: /* Unspecified error */
5115 case 0x20: /* Unsupported LMP Parameter value */
5116 if (conn->out) {
5117 conn->pkt_type = (hdev->esco_type & SCO_ESCO_MASK) |
5118 (hdev->esco_type & EDR_ESCO_MASK);
5119 if (hci_setup_sync(conn, conn->parent->handle))
5120 goto unlock;
5121 }
5122 fallthrough;
5123
5124 default:
5125 conn->state = BT_CLOSED;
5126 break;
5127 }
5128
5129 bt_dev_dbg(hdev, "SCO connected with air mode: %02x", ev->air_mode);
5130 /* Notify only in case of SCO over HCI transport data path which
5131 * is zero and non-zero value shall be non-HCI transport data path
5132 */
5133 if (conn->codec.data_path == 0 && hdev->notify) {
5134 switch (ev->air_mode) {
5135 case 0x02:
5136 hdev->notify(hdev, HCI_NOTIFY_ENABLE_SCO_CVSD);
5137 break;
5138 case 0x03:
5139 hdev->notify(hdev, HCI_NOTIFY_ENABLE_SCO_TRANSP);
5140 break;
5141 }
5142 }
5143
5144 hci_connect_cfm(conn, status);
5145 if (status)
5146 hci_conn_del(conn);
5147
5148 unlock:
5149 hci_dev_unlock(hdev);
5150 }
5151
eir_get_length(u8 * eir,size_t eir_len)5152 static inline size_t eir_get_length(u8 *eir, size_t eir_len)
5153 {
5154 size_t parsed = 0;
5155
5156 while (parsed < eir_len) {
5157 u8 field_len = eir[0];
5158
5159 if (field_len == 0)
5160 return parsed;
5161
5162 parsed += field_len + 1;
5163 eir += field_len + 1;
5164 }
5165
5166 return eir_len;
5167 }
5168
hci_extended_inquiry_result_evt(struct hci_dev * hdev,void * edata,struct sk_buff * skb)5169 static void hci_extended_inquiry_result_evt(struct hci_dev *hdev, void *edata,
5170 struct sk_buff *skb)
5171 {
5172 struct hci_ev_ext_inquiry_result *ev = edata;
5173 struct inquiry_data data;
5174 size_t eir_len;
5175 int i;
5176
5177 if (!hci_ev_skb_pull(hdev, skb, HCI_EV_EXTENDED_INQUIRY_RESULT,
5178 flex_array_size(ev, info, ev->num)))
5179 return;
5180
5181 bt_dev_dbg(hdev, "num %d", ev->num);
5182
5183 if (!ev->num)
5184 return;
5185
5186 if (hci_dev_test_flag(hdev, HCI_PERIODIC_INQ))
5187 return;
5188
5189 hci_dev_lock(hdev);
5190
5191 for (i = 0; i < ev->num; i++) {
5192 struct extended_inquiry_info *info = &ev->info[i];
5193 u32 flags;
5194 bool name_known;
5195
5196 bacpy(&data.bdaddr, &info->bdaddr);
5197 data.pscan_rep_mode = info->pscan_rep_mode;
5198 data.pscan_period_mode = info->pscan_period_mode;
5199 data.pscan_mode = 0x00;
5200 memcpy(data.dev_class, info->dev_class, 3);
5201 data.clock_offset = info->clock_offset;
5202 data.rssi = info->rssi;
5203 data.ssp_mode = 0x01;
5204
5205 if (hci_dev_test_flag(hdev, HCI_MGMT))
5206 name_known = eir_get_data(info->data,
5207 sizeof(info->data),
5208 EIR_NAME_COMPLETE, NULL);
5209 else
5210 name_known = true;
5211
5212 flags = hci_inquiry_cache_update(hdev, &data, name_known);
5213
5214 eir_len = eir_get_length(info->data, sizeof(info->data));
5215
5216 mgmt_device_found(hdev, &info->bdaddr, ACL_LINK, 0x00,
5217 info->dev_class, info->rssi,
5218 flags, info->data, eir_len, NULL, 0, 0);
5219 }
5220
5221 hci_dev_unlock(hdev);
5222 }
5223
hci_key_refresh_complete_evt(struct hci_dev * hdev,void * data,struct sk_buff * skb)5224 static void hci_key_refresh_complete_evt(struct hci_dev *hdev, void *data,
5225 struct sk_buff *skb)
5226 {
5227 struct hci_ev_key_refresh_complete *ev = data;
5228 struct hci_conn *conn;
5229
5230 bt_dev_dbg(hdev, "status 0x%2.2x handle 0x%4.4x", ev->status,
5231 __le16_to_cpu(ev->handle));
5232
5233 hci_dev_lock(hdev);
5234
5235 conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(ev->handle));
5236 if (!conn)
5237 goto unlock;
5238
5239 /* For BR/EDR the necessary steps are taken through the
5240 * auth_complete event.
5241 */
5242 if (conn->type != LE_LINK)
5243 goto unlock;
5244
5245 if (!ev->status)
5246 conn->sec_level = conn->pending_sec_level;
5247
5248 clear_bit(HCI_CONN_ENCRYPT_PEND, &conn->flags);
5249
5250 if (ev->status && conn->state == BT_CONNECTED) {
5251 hci_disconnect(conn, HCI_ERROR_AUTH_FAILURE);
5252 hci_conn_drop(conn);
5253 goto unlock;
5254 }
5255
5256 if (conn->state == BT_CONFIG) {
5257 if (!ev->status)
5258 conn->state = BT_CONNECTED;
5259
5260 hci_connect_cfm(conn, ev->status);
5261 hci_conn_drop(conn);
5262 } else {
5263 hci_auth_cfm(conn, ev->status);
5264
5265 hci_conn_hold(conn);
5266 conn->disc_timeout = HCI_DISCONN_TIMEOUT;
5267 hci_conn_drop(conn);
5268 }
5269
5270 unlock:
5271 hci_dev_unlock(hdev);
5272 }
5273
hci_get_auth_req(struct hci_conn * conn)5274 static u8 hci_get_auth_req(struct hci_conn *conn)
5275 {
5276 /* If remote requests no-bonding follow that lead */
5277 if (conn->remote_auth == HCI_AT_NO_BONDING ||
5278 conn->remote_auth == HCI_AT_NO_BONDING_MITM)
5279 return conn->remote_auth | (conn->auth_type & 0x01);
5280
5281 /* If both remote and local have enough IO capabilities, require
5282 * MITM protection
5283 */
5284 if (conn->remote_cap != HCI_IO_NO_INPUT_OUTPUT &&
5285 conn->io_capability != HCI_IO_NO_INPUT_OUTPUT)
5286 return conn->remote_auth | 0x01;
5287
5288 /* No MITM protection possible so ignore remote requirement */
5289 return (conn->remote_auth & ~0x01) | (conn->auth_type & 0x01);
5290 }
5291
bredr_oob_data_present(struct hci_conn * conn)5292 static u8 bredr_oob_data_present(struct hci_conn *conn)
5293 {
5294 struct hci_dev *hdev = conn->hdev;
5295 struct oob_data *data;
5296
5297 data = hci_find_remote_oob_data(hdev, &conn->dst, BDADDR_BREDR);
5298 if (!data)
5299 return 0x00;
5300
5301 if (bredr_sc_enabled(hdev)) {
5302 /* When Secure Connections is enabled, then just
5303 * return the present value stored with the OOB
5304 * data. The stored value contains the right present
5305 * information. However it can only be trusted when
5306 * not in Secure Connection Only mode.
5307 */
5308 if (!hci_dev_test_flag(hdev, HCI_SC_ONLY))
5309 return data->present;
5310
5311 /* When Secure Connections Only mode is enabled, then
5312 * the P-256 values are required. If they are not
5313 * available, then do not declare that OOB data is
5314 * present.
5315 */
5316 if (!crypto_memneq(data->rand256, ZERO_KEY, 16) ||
5317 !crypto_memneq(data->hash256, ZERO_KEY, 16))
5318 return 0x00;
5319
5320 return 0x02;
5321 }
5322
5323 /* When Secure Connections is not enabled or actually
5324 * not supported by the hardware, then check that if
5325 * P-192 data values are present.
5326 */
5327 if (!crypto_memneq(data->rand192, ZERO_KEY, 16) ||
5328 !crypto_memneq(data->hash192, ZERO_KEY, 16))
5329 return 0x00;
5330
5331 return 0x01;
5332 }
5333
hci_io_capa_request_evt(struct hci_dev * hdev,void * data,struct sk_buff * skb)5334 static void hci_io_capa_request_evt(struct hci_dev *hdev, void *data,
5335 struct sk_buff *skb)
5336 {
5337 struct hci_ev_io_capa_request *ev = data;
5338 struct hci_conn *conn;
5339
5340 bt_dev_dbg(hdev, "");
5341
5342 hci_dev_lock(hdev);
5343
5344 conn = hci_conn_hash_lookup_ba(hdev, ACL_LINK, &ev->bdaddr);
5345 if (!conn || !hci_dev_test_flag(hdev, HCI_SSP_ENABLED))
5346 goto unlock;
5347
5348 /* Assume remote supports SSP since it has triggered this event */
5349 set_bit(HCI_CONN_SSP_ENABLED, &conn->flags);
5350
5351 hci_conn_hold(conn);
5352
5353 if (!hci_dev_test_flag(hdev, HCI_MGMT))
5354 goto unlock;
5355
5356 /* Allow pairing if we're pairable, the initiators of the
5357 * pairing or if the remote is not requesting bonding.
5358 */
5359 if (hci_dev_test_flag(hdev, HCI_BONDABLE) ||
5360 test_bit(HCI_CONN_AUTH_INITIATOR, &conn->flags) ||
5361 (conn->remote_auth & ~0x01) == HCI_AT_NO_BONDING) {
5362 struct hci_cp_io_capability_reply cp;
5363
5364 bacpy(&cp.bdaddr, &ev->bdaddr);
5365 /* Change the IO capability from KeyboardDisplay
5366 * to DisplayYesNo as it is not supported by BT spec. */
5367 cp.capability = (conn->io_capability == 0x04) ?
5368 HCI_IO_DISPLAY_YESNO : conn->io_capability;
5369
5370 /* If we are initiators, there is no remote information yet */
5371 if (conn->remote_auth == 0xff) {
5372 /* Request MITM protection if our IO caps allow it
5373 * except for the no-bonding case.
5374 */
5375 if (conn->io_capability != HCI_IO_NO_INPUT_OUTPUT &&
5376 conn->auth_type != HCI_AT_NO_BONDING)
5377 conn->auth_type |= 0x01;
5378 } else {
5379 conn->auth_type = hci_get_auth_req(conn);
5380 }
5381
5382 /* If we're not bondable, force one of the non-bondable
5383 * authentication requirement values.
5384 */
5385 if (!hci_dev_test_flag(hdev, HCI_BONDABLE))
5386 conn->auth_type &= HCI_AT_NO_BONDING_MITM;
5387
5388 cp.authentication = conn->auth_type;
5389 cp.oob_data = bredr_oob_data_present(conn);
5390
5391 hci_send_cmd(hdev, HCI_OP_IO_CAPABILITY_REPLY,
5392 sizeof(cp), &cp);
5393 } else {
5394 struct hci_cp_io_capability_neg_reply cp;
5395
5396 bacpy(&cp.bdaddr, &ev->bdaddr);
5397 cp.reason = HCI_ERROR_PAIRING_NOT_ALLOWED;
5398
5399 hci_send_cmd(hdev, HCI_OP_IO_CAPABILITY_NEG_REPLY,
5400 sizeof(cp), &cp);
5401 }
5402
5403 unlock:
5404 hci_dev_unlock(hdev);
5405 }
5406
hci_io_capa_reply_evt(struct hci_dev * hdev,void * data,struct sk_buff * skb)5407 static void hci_io_capa_reply_evt(struct hci_dev *hdev, void *data,
5408 struct sk_buff *skb)
5409 {
5410 struct hci_ev_io_capa_reply *ev = data;
5411 struct hci_conn *conn;
5412
5413 bt_dev_dbg(hdev, "");
5414
5415 hci_dev_lock(hdev);
5416
5417 conn = hci_conn_hash_lookup_ba(hdev, ACL_LINK, &ev->bdaddr);
5418 if (!conn)
5419 goto unlock;
5420
5421 conn->remote_cap = ev->capability;
5422 conn->remote_auth = ev->authentication;
5423
5424 unlock:
5425 hci_dev_unlock(hdev);
5426 }
5427
hci_user_confirm_request_evt(struct hci_dev * hdev,void * data,struct sk_buff * skb)5428 static void hci_user_confirm_request_evt(struct hci_dev *hdev, void *data,
5429 struct sk_buff *skb)
5430 {
5431 struct hci_ev_user_confirm_req *ev = data;
5432 int loc_mitm, rem_mitm, confirm_hint = 0;
5433 struct hci_conn *conn;
5434
5435 bt_dev_dbg(hdev, "");
5436
5437 hci_dev_lock(hdev);
5438
5439 if (!hci_dev_test_flag(hdev, HCI_MGMT))
5440 goto unlock;
5441
5442 conn = hci_conn_hash_lookup_ba(hdev, ACL_LINK, &ev->bdaddr);
5443 if (!conn)
5444 goto unlock;
5445
5446 loc_mitm = (conn->auth_type & 0x01);
5447 rem_mitm = (conn->remote_auth & 0x01);
5448
5449 /* If we require MITM but the remote device can't provide that
5450 * (it has NoInputNoOutput) then reject the confirmation
5451 * request. We check the security level here since it doesn't
5452 * necessarily match conn->auth_type.
5453 */
5454 if (conn->pending_sec_level > BT_SECURITY_MEDIUM &&
5455 conn->remote_cap == HCI_IO_NO_INPUT_OUTPUT) {
5456 bt_dev_dbg(hdev, "Rejecting request: remote device can't provide MITM");
5457 hci_send_cmd(hdev, HCI_OP_USER_CONFIRM_NEG_REPLY,
5458 sizeof(ev->bdaddr), &ev->bdaddr);
5459 goto unlock;
5460 }
5461
5462 /* If no side requires MITM protection; use JUST_CFM method */
5463 if ((!loc_mitm || conn->remote_cap == HCI_IO_NO_INPUT_OUTPUT) &&
5464 (!rem_mitm || conn->io_capability == HCI_IO_NO_INPUT_OUTPUT)) {
5465
5466 /* If we're not the initiator of request authorization and the
5467 * local IO capability is not NoInputNoOutput, use JUST_WORKS
5468 * method (mgmt_user_confirm with confirm_hint set to 1).
5469 */
5470 if (!test_bit(HCI_CONN_AUTH_PEND, &conn->flags) &&
5471 conn->io_capability != HCI_IO_NO_INPUT_OUTPUT) {
5472 bt_dev_dbg(hdev, "Confirming auto-accept as acceptor");
5473 confirm_hint = 1;
5474 goto confirm;
5475 }
5476
5477 /* If there already exists link key in local host, leave the
5478 * decision to user space since the remote device could be
5479 * legitimate or malicious.
5480 */
5481 if (hci_find_link_key(hdev, &ev->bdaddr)) {
5482 bt_dev_dbg(hdev, "Local host already has link key");
5483 confirm_hint = 1;
5484 goto confirm;
5485 }
5486
5487 BT_DBG("Auto-accept of user confirmation with %ums delay",
5488 hdev->auto_accept_delay);
5489
5490 if (hdev->auto_accept_delay > 0) {
5491 int delay = msecs_to_jiffies(hdev->auto_accept_delay);
5492 queue_delayed_work(conn->hdev->workqueue,
5493 &conn->auto_accept_work, delay);
5494 goto unlock;
5495 }
5496
5497 hci_send_cmd(hdev, HCI_OP_USER_CONFIRM_REPLY,
5498 sizeof(ev->bdaddr), &ev->bdaddr);
5499 goto unlock;
5500 }
5501
5502 confirm:
5503 mgmt_user_confirm_request(hdev, &ev->bdaddr, ACL_LINK, 0,
5504 le32_to_cpu(ev->passkey), confirm_hint);
5505
5506 unlock:
5507 hci_dev_unlock(hdev);
5508 }
5509
hci_user_passkey_request_evt(struct hci_dev * hdev,void * data,struct sk_buff * skb)5510 static void hci_user_passkey_request_evt(struct hci_dev *hdev, void *data,
5511 struct sk_buff *skb)
5512 {
5513 struct hci_ev_user_passkey_req *ev = data;
5514
5515 bt_dev_dbg(hdev, "");
5516
5517 if (hci_dev_test_flag(hdev, HCI_MGMT))
5518 mgmt_user_passkey_request(hdev, &ev->bdaddr, ACL_LINK, 0);
5519 }
5520
hci_user_passkey_notify_evt(struct hci_dev * hdev,void * data,struct sk_buff * skb)5521 static void hci_user_passkey_notify_evt(struct hci_dev *hdev, void *data,
5522 struct sk_buff *skb)
5523 {
5524 struct hci_ev_user_passkey_notify *ev = data;
5525 struct hci_conn *conn;
5526
5527 bt_dev_dbg(hdev, "");
5528
5529 hci_dev_lock(hdev);
5530
5531 conn = hci_conn_hash_lookup_ba(hdev, ACL_LINK, &ev->bdaddr);
5532 if (!conn)
5533 goto unlock;
5534
5535 conn->passkey_notify = __le32_to_cpu(ev->passkey);
5536 conn->passkey_entered = 0;
5537
5538 if (hci_dev_test_flag(hdev, HCI_MGMT))
5539 mgmt_user_passkey_notify(hdev, &conn->dst, conn->type,
5540 conn->dst_type, conn->passkey_notify,
5541 conn->passkey_entered);
5542
5543 unlock:
5544 hci_dev_unlock(hdev);
5545 }
5546
hci_keypress_notify_evt(struct hci_dev * hdev,void * data,struct sk_buff * skb)5547 static void hci_keypress_notify_evt(struct hci_dev *hdev, void *data,
5548 struct sk_buff *skb)
5549 {
5550 struct hci_ev_keypress_notify *ev = data;
5551 struct hci_conn *conn;
5552
5553 bt_dev_dbg(hdev, "");
5554
5555 hci_dev_lock(hdev);
5556
5557 conn = hci_conn_hash_lookup_ba(hdev, ACL_LINK, &ev->bdaddr);
5558 if (!conn)
5559 goto unlock;
5560
5561 switch (ev->type) {
5562 case HCI_KEYPRESS_STARTED:
5563 conn->passkey_entered = 0;
5564 goto unlock;
5565
5566 case HCI_KEYPRESS_ENTERED:
5567 conn->passkey_entered++;
5568 break;
5569
5570 case HCI_KEYPRESS_ERASED:
5571 conn->passkey_entered--;
5572 break;
5573
5574 case HCI_KEYPRESS_CLEARED:
5575 conn->passkey_entered = 0;
5576 break;
5577
5578 case HCI_KEYPRESS_COMPLETED:
5579 goto unlock;
5580 }
5581
5582 if (hci_dev_test_flag(hdev, HCI_MGMT))
5583 mgmt_user_passkey_notify(hdev, &conn->dst, conn->type,
5584 conn->dst_type, conn->passkey_notify,
5585 conn->passkey_entered);
5586
5587 unlock:
5588 hci_dev_unlock(hdev);
5589 }
5590
hci_simple_pair_complete_evt(struct hci_dev * hdev,void * data,struct sk_buff * skb)5591 static void hci_simple_pair_complete_evt(struct hci_dev *hdev, void *data,
5592 struct sk_buff *skb)
5593 {
5594 struct hci_ev_simple_pair_complete *ev = data;
5595 struct hci_conn *conn;
5596
5597 bt_dev_dbg(hdev, "");
5598
5599 hci_dev_lock(hdev);
5600
5601 conn = hci_conn_hash_lookup_ba(hdev, ACL_LINK, &ev->bdaddr);
5602 if (!conn || !hci_conn_ssp_enabled(conn))
5603 goto unlock;
5604
5605 /* Reset the authentication requirement to unknown */
5606 conn->remote_auth = 0xff;
5607
5608 /* To avoid duplicate auth_failed events to user space we check
5609 * the HCI_CONN_AUTH_PEND flag which will be set if we
5610 * initiated the authentication. A traditional auth_complete
5611 * event gets always produced as initiator and is also mapped to
5612 * the mgmt_auth_failed event */
5613 if (!test_bit(HCI_CONN_AUTH_PEND, &conn->flags) && ev->status)
5614 mgmt_auth_failed(conn, ev->status);
5615
5616 hci_conn_drop(conn);
5617
5618 unlock:
5619 hci_dev_unlock(hdev);
5620 }
5621
hci_remote_host_features_evt(struct hci_dev * hdev,void * data,struct sk_buff * skb)5622 static void hci_remote_host_features_evt(struct hci_dev *hdev, void *data,
5623 struct sk_buff *skb)
5624 {
5625 struct hci_ev_remote_host_features *ev = data;
5626 struct inquiry_entry *ie;
5627 struct hci_conn *conn;
5628
5629 bt_dev_dbg(hdev, "");
5630
5631 hci_dev_lock(hdev);
5632
5633 conn = hci_conn_hash_lookup_ba(hdev, ACL_LINK, &ev->bdaddr);
5634 if (conn)
5635 memcpy(conn->features[1], ev->features, 8);
5636
5637 ie = hci_inquiry_cache_lookup(hdev, &ev->bdaddr);
5638 if (ie)
5639 ie->data.ssp_mode = (ev->features[0] & LMP_HOST_SSP);
5640
5641 hci_dev_unlock(hdev);
5642 }
5643
hci_remote_oob_data_request_evt(struct hci_dev * hdev,void * edata,struct sk_buff * skb)5644 static void hci_remote_oob_data_request_evt(struct hci_dev *hdev, void *edata,
5645 struct sk_buff *skb)
5646 {
5647 struct hci_ev_remote_oob_data_request *ev = edata;
5648 struct oob_data *data;
5649
5650 bt_dev_dbg(hdev, "");
5651
5652 hci_dev_lock(hdev);
5653
5654 if (!hci_dev_test_flag(hdev, HCI_MGMT))
5655 goto unlock;
5656
5657 data = hci_find_remote_oob_data(hdev, &ev->bdaddr, BDADDR_BREDR);
5658 if (!data) {
5659 struct hci_cp_remote_oob_data_neg_reply cp;
5660
5661 bacpy(&cp.bdaddr, &ev->bdaddr);
5662 hci_send_cmd(hdev, HCI_OP_REMOTE_OOB_DATA_NEG_REPLY,
5663 sizeof(cp), &cp);
5664 goto unlock;
5665 }
5666
5667 if (bredr_sc_enabled(hdev)) {
5668 struct hci_cp_remote_oob_ext_data_reply cp;
5669
5670 bacpy(&cp.bdaddr, &ev->bdaddr);
5671 if (hci_dev_test_flag(hdev, HCI_SC_ONLY)) {
5672 memset(cp.hash192, 0, sizeof(cp.hash192));
5673 memset(cp.rand192, 0, sizeof(cp.rand192));
5674 } else {
5675 memcpy(cp.hash192, data->hash192, sizeof(cp.hash192));
5676 memcpy(cp.rand192, data->rand192, sizeof(cp.rand192));
5677 }
5678 memcpy(cp.hash256, data->hash256, sizeof(cp.hash256));
5679 memcpy(cp.rand256, data->rand256, sizeof(cp.rand256));
5680
5681 hci_send_cmd(hdev, HCI_OP_REMOTE_OOB_EXT_DATA_REPLY,
5682 sizeof(cp), &cp);
5683 } else {
5684 struct hci_cp_remote_oob_data_reply cp;
5685
5686 bacpy(&cp.bdaddr, &ev->bdaddr);
5687 memcpy(cp.hash, data->hash192, sizeof(cp.hash));
5688 memcpy(cp.rand, data->rand192, sizeof(cp.rand));
5689
5690 hci_send_cmd(hdev, HCI_OP_REMOTE_OOB_DATA_REPLY,
5691 sizeof(cp), &cp);
5692 }
5693
5694 unlock:
5695 hci_dev_unlock(hdev);
5696 }
5697
le_conn_update_addr(struct hci_conn * conn,bdaddr_t * bdaddr,u8 bdaddr_type,bdaddr_t * local_rpa)5698 static void le_conn_update_addr(struct hci_conn *conn, bdaddr_t *bdaddr,
5699 u8 bdaddr_type, bdaddr_t *local_rpa)
5700 {
5701 if (conn->out) {
5702 conn->dst_type = bdaddr_type;
5703 conn->resp_addr_type = bdaddr_type;
5704 bacpy(&conn->resp_addr, bdaddr);
5705
5706 /* Check if the controller has set a Local RPA then it must be
5707 * used instead or hdev->rpa.
5708 */
5709 if (local_rpa && bacmp(local_rpa, BDADDR_ANY)) {
5710 conn->init_addr_type = ADDR_LE_DEV_RANDOM;
5711 bacpy(&conn->init_addr, local_rpa);
5712 } else if (hci_dev_test_flag(conn->hdev, HCI_PRIVACY)) {
5713 conn->init_addr_type = ADDR_LE_DEV_RANDOM;
5714 bacpy(&conn->init_addr, &conn->hdev->rpa);
5715 } else {
5716 hci_copy_identity_address(conn->hdev, &conn->init_addr,
5717 &conn->init_addr_type);
5718 }
5719 } else {
5720 conn->resp_addr_type = conn->hdev->adv_addr_type;
5721 /* Check if the controller has set a Local RPA then it must be
5722 * used instead or hdev->rpa.
5723 */
5724 if (local_rpa && bacmp(local_rpa, BDADDR_ANY)) {
5725 conn->resp_addr_type = ADDR_LE_DEV_RANDOM;
5726 bacpy(&conn->resp_addr, local_rpa);
5727 } else if (conn->hdev->adv_addr_type == ADDR_LE_DEV_RANDOM) {
5728 /* In case of ext adv, resp_addr will be updated in
5729 * Adv Terminated event.
5730 */
5731 if (!ext_adv_capable(conn->hdev))
5732 bacpy(&conn->resp_addr,
5733 &conn->hdev->random_addr);
5734 } else {
5735 bacpy(&conn->resp_addr, &conn->hdev->bdaddr);
5736 }
5737
5738 conn->init_addr_type = bdaddr_type;
5739 bacpy(&conn->init_addr, bdaddr);
5740
5741 /* For incoming connections, set the default minimum
5742 * and maximum connection interval. They will be used
5743 * to check if the parameters are in range and if not
5744 * trigger the connection update procedure.
5745 */
5746 conn->le_conn_min_interval = conn->hdev->le_conn_min_interval;
5747 conn->le_conn_max_interval = conn->hdev->le_conn_max_interval;
5748 }
5749 }
5750
le_conn_complete_evt(struct hci_dev * hdev,u8 status,bdaddr_t * bdaddr,u8 bdaddr_type,bdaddr_t * local_rpa,u8 role,u16 handle,u16 interval,u16 latency,u16 supervision_timeout)5751 static void le_conn_complete_evt(struct hci_dev *hdev, u8 status,
5752 bdaddr_t *bdaddr, u8 bdaddr_type,
5753 bdaddr_t *local_rpa, u8 role, u16 handle,
5754 u16 interval, u16 latency,
5755 u16 supervision_timeout)
5756 {
5757 struct hci_conn_params *params;
5758 struct hci_conn *conn;
5759 struct smp_irk *irk;
5760 u8 addr_type;
5761 int err;
5762
5763 hci_dev_lock(hdev);
5764 hci_store_wake_reason(hdev, bdaddr, bdaddr_type);
5765
5766 /* Advertising stops when a connection is created. On a failed
5767 * connection it keeps running, so leave the state bit alone.
5768 */
5769 if (!status)
5770 hci_dev_clear_flag(hdev, HCI_LE_ADV);
5771
5772 /* Check for existing connection:
5773 *
5774 * 1. If it doesn't exist then use the role to create a new object.
5775 * 2. If it does exist confirm that it is connecting/BT_CONNECT in case
5776 * of initiator/master role since there could be a collision where
5777 * either side is attempting to connect or something like a fuzzing
5778 * testing is trying to play tricks to destroy the hcon object before
5779 * it even attempts to connect (e.g. hcon->state == BT_OPEN).
5780 */
5781 conn = hci_conn_hash_lookup_role(hdev, LE_LINK, role, bdaddr);
5782 if (!conn ||
5783 (conn->role == HCI_ROLE_MASTER && conn->state != BT_CONNECT)) {
5784 /* In case of error status and there is no connection pending
5785 * just unlock as there is nothing to cleanup.
5786 */
5787 if (status)
5788 goto unlock;
5789
5790 conn = hci_conn_add_unset(hdev, LE_LINK, bdaddr, bdaddr_type,
5791 role);
5792 if (IS_ERR(conn)) {
5793 bt_dev_err(hdev, "connection err: %ld", PTR_ERR(conn));
5794 goto unlock;
5795 }
5796
5797 /* If we didn't have a hci_conn object previously
5798 * but we're in central role this must be something
5799 * initiated using an accept list. Since accept list based
5800 * connections are not "first class citizens" we don't
5801 * have full tracking of them. Therefore, we go ahead
5802 * with a "best effort" approach of determining the
5803 * initiator address based on the HCI_PRIVACY flag.
5804 */
5805 if (conn->out) {
5806 conn->resp_addr_type = bdaddr_type;
5807 bacpy(&conn->resp_addr, bdaddr);
5808 if (hci_dev_test_flag(hdev, HCI_PRIVACY)) {
5809 conn->init_addr_type = ADDR_LE_DEV_RANDOM;
5810 bacpy(&conn->init_addr, &hdev->rpa);
5811 } else {
5812 hci_copy_identity_address(hdev,
5813 &conn->init_addr,
5814 &conn->init_addr_type);
5815 }
5816 }
5817 } else {
5818 cancel_delayed_work(&conn->le_conn_timeout);
5819 }
5820
5821 /* The HCI_LE_Connection_Complete event is only sent once per connection.
5822 * Processing it more than once per connection can corrupt kernel memory.
5823 *
5824 * As the connection handle is set here for the first time, it indicates
5825 * whether the connection is already set up.
5826 */
5827 if (!HCI_CONN_HANDLE_UNSET(conn->handle)) {
5828 bt_dev_err(hdev, "Ignoring HCI_Connection_Complete for existing connection");
5829 goto unlock;
5830 }
5831
5832 le_conn_update_addr(conn, bdaddr, bdaddr_type, local_rpa);
5833
5834 /* Lookup the identity address from the stored connection
5835 * address and address type.
5836 *
5837 * When establishing connections to an identity address, the
5838 * connection procedure will store the resolvable random
5839 * address first. Now if it can be converted back into the
5840 * identity address, start using the identity address from
5841 * now on.
5842 */
5843 irk = hci_get_irk(hdev, &conn->dst, conn->dst_type);
5844 if (irk) {
5845 bacpy(&conn->dst, &irk->bdaddr);
5846 conn->dst_type = irk->addr_type;
5847 }
5848
5849 conn->dst_type = ev_bdaddr_type(hdev, conn->dst_type, NULL);
5850
5851 /* All connection failure handling is taken care of by the
5852 * hci_conn_failed function which is triggered by the HCI
5853 * request completion callbacks used for connecting.
5854 */
5855 if (status || hci_conn_set_handle(conn, handle))
5856 goto unlock;
5857
5858 /* Drop the connection if it has been aborted */
5859 if (test_bit(HCI_CONN_CANCEL, &conn->flags)) {
5860 hci_conn_drop(conn);
5861 goto unlock;
5862 }
5863
5864 if (conn->dst_type == ADDR_LE_DEV_PUBLIC)
5865 addr_type = BDADDR_LE_PUBLIC;
5866 else
5867 addr_type = BDADDR_LE_RANDOM;
5868
5869 /* Drop the connection if the device is blocked */
5870 if (hci_bdaddr_list_lookup(&hdev->reject_list, &conn->dst, addr_type)) {
5871 hci_conn_drop(conn);
5872 goto unlock;
5873 }
5874
5875 mgmt_device_connected(hdev, conn, NULL, 0);
5876
5877 conn->sec_level = BT_SECURITY_LOW;
5878 conn->state = BT_CONFIG;
5879
5880 /* Store current advertising instance as connection advertising instance
5881 * when software rotation is in use so it can be re-enabled when
5882 * disconnected.
5883 */
5884 if (!ext_adv_capable(hdev))
5885 conn->adv_instance = hdev->cur_adv_instance;
5886
5887 conn->le_conn_interval = interval;
5888 conn->le_conn_latency = latency;
5889 conn->le_supv_timeout = supervision_timeout;
5890
5891 hci_debugfs_create_conn(conn);
5892 hci_conn_add_sysfs(conn);
5893
5894 err = hci_le_read_remote_features(conn);
5895 if (err) {
5896 conn->state = BT_CONNECTED;
5897 hci_connect_cfm(conn, status);
5898 }
5899
5900 params = hci_pend_le_action_lookup(&hdev->pend_le_conns, &conn->dst,
5901 conn->dst_type);
5902 if (params) {
5903 hci_pend_le_list_del_init(params);
5904 if (params->conn) {
5905 hci_conn_drop(params->conn);
5906 hci_conn_put(params->conn);
5907 params->conn = NULL;
5908 }
5909 }
5910
5911 /* If we are central and have subrate parameters stored, queue a
5912 * connection rate request to apply them.
5913 */
5914 if (conn->role == HCI_ROLE_MASTER && le_sci_capable(hdev)) {
5915 struct hci_conn_params *p;
5916
5917 p = hci_conn_params_lookup(hdev, &conn->dst, conn->dst_type);
5918 if (p && p->subrate_max)
5919 hci_le_conn_rate_request(hdev, conn);
5920 }
5921
5922 unlock:
5923 hci_update_passive_scan(hdev);
5924 hci_dev_unlock(hdev);
5925 }
5926
hci_le_conn_complete_evt(struct hci_dev * hdev,void * data,struct sk_buff * skb)5927 static void hci_le_conn_complete_evt(struct hci_dev *hdev, void *data,
5928 struct sk_buff *skb)
5929 {
5930 struct hci_ev_le_conn_complete *ev = data;
5931
5932 bt_dev_dbg(hdev, "status 0x%2.2x", ev->status);
5933
5934 le_conn_complete_evt(hdev, ev->status, &ev->bdaddr, ev->bdaddr_type,
5935 NULL, ev->role, le16_to_cpu(ev->handle),
5936 le16_to_cpu(ev->interval),
5937 le16_to_cpu(ev->latency),
5938 le16_to_cpu(ev->supervision_timeout));
5939 }
5940
hci_le_enh_conn_complete_evt(struct hci_dev * hdev,void * data,struct sk_buff * skb)5941 static void hci_le_enh_conn_complete_evt(struct hci_dev *hdev, void *data,
5942 struct sk_buff *skb)
5943 {
5944 struct hci_ev_le_enh_conn_complete *ev = data;
5945
5946 bt_dev_dbg(hdev, "status 0x%2.2x", ev->status);
5947
5948 le_conn_complete_evt(hdev, ev->status, &ev->bdaddr, ev->bdaddr_type,
5949 &ev->local_rpa, ev->role, le16_to_cpu(ev->handle),
5950 le16_to_cpu(ev->interval),
5951 le16_to_cpu(ev->latency),
5952 le16_to_cpu(ev->supervision_timeout));
5953 }
5954
hci_le_pa_sync_lost_evt(struct hci_dev * hdev,void * data,struct sk_buff * skb)5955 static void hci_le_pa_sync_lost_evt(struct hci_dev *hdev, void *data,
5956 struct sk_buff *skb)
5957 {
5958 struct hci_ev_le_pa_sync_lost *ev = data;
5959 u16 handle = le16_to_cpu(ev->handle);
5960 struct hci_conn *conn;
5961
5962 bt_dev_dbg(hdev, "sync handle 0x%4.4x", handle);
5963
5964 hci_dev_lock(hdev);
5965
5966 /* Delete the pa sync connection */
5967 conn = hci_conn_hash_lookup_pa_sync_handle(hdev, handle);
5968 if (conn) {
5969 clear_bit(HCI_CONN_BIG_SYNC, &conn->flags);
5970 clear_bit(HCI_CONN_PA_SYNC, &conn->flags);
5971 hci_disconn_cfm(conn, HCI_ERROR_REMOTE_USER_TERM);
5972 hci_conn_del(conn);
5973 }
5974
5975 hci_dev_unlock(hdev);
5976 }
5977
hci_le_ext_adv_term_evt(struct hci_dev * hdev,void * data,struct sk_buff * skb)5978 static void hci_le_ext_adv_term_evt(struct hci_dev *hdev, void *data,
5979 struct sk_buff *skb)
5980 {
5981 struct hci_evt_le_ext_adv_set_term *ev = data;
5982 struct hci_conn *conn;
5983 struct adv_info *adv, *n;
5984
5985 bt_dev_dbg(hdev, "status 0x%2.2x", ev->status);
5986
5987 /* The Bluetooth Core 5.3 specification clearly states that this event
5988 * shall not be sent when the Host disables the advertising set. So in
5989 * case of HCI_ERROR_CANCELLED_BY_HOST, just ignore the event.
5990 *
5991 * When the Host disables an advertising set, all cleanup is done via
5992 * its command callback and not needed to be duplicated here.
5993 */
5994 if (ev->status == HCI_ERROR_CANCELLED_BY_HOST) {
5995 bt_dev_warn_ratelimited(hdev, "Unexpected advertising set terminated event");
5996 return;
5997 }
5998
5999 hci_dev_lock(hdev);
6000
6001 adv = hci_find_adv_instance(hdev, ev->handle);
6002
6003 if (ev->status) {
6004 if (!adv)
6005 goto unlock;
6006
6007 /* Remove advertising as it has been terminated */
6008 hci_remove_adv_instance(hdev, ev->handle);
6009 mgmt_advertising_removed(NULL, hdev, ev->handle);
6010
6011 list_for_each_entry_safe(adv, n, &hdev->adv_instances, list) {
6012 if (adv->enabled)
6013 goto unlock;
6014 }
6015
6016 /* We are no longer advertising, clear HCI_LE_ADV */
6017 hci_dev_clear_flag(hdev, HCI_LE_ADV);
6018 goto unlock;
6019 }
6020
6021 if (adv)
6022 adv->enabled = false;
6023
6024 conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(ev->conn_handle));
6025 if (conn) {
6026 /* Store handle in the connection so the correct advertising
6027 * instance can be re-enabled when disconnected.
6028 */
6029 conn->adv_instance = ev->handle;
6030
6031 if (hdev->adv_addr_type != ADDR_LE_DEV_RANDOM ||
6032 bacmp(&conn->resp_addr, BDADDR_ANY))
6033 goto unlock;
6034
6035 if (!ev->handle) {
6036 bacpy(&conn->resp_addr, &hdev->random_addr);
6037 goto unlock;
6038 }
6039
6040 if (adv)
6041 bacpy(&conn->resp_addr, &adv->random_addr);
6042 }
6043
6044 unlock:
6045 hci_dev_unlock(hdev);
6046 }
6047
hci_le_pa_term_sync(struct hci_dev * hdev,__le16 handle)6048 static int hci_le_pa_term_sync(struct hci_dev *hdev, __le16 handle)
6049 {
6050 struct hci_cp_le_pa_term_sync cp;
6051
6052 memset(&cp, 0, sizeof(cp));
6053 cp.handle = handle;
6054
6055 return hci_send_cmd(hdev, HCI_OP_LE_PA_TERM_SYNC, sizeof(cp), &cp);
6056 }
6057
hci_le_past_received_evt(struct hci_dev * hdev,void * data,struct sk_buff * skb)6058 static void hci_le_past_received_evt(struct hci_dev *hdev, void *data,
6059 struct sk_buff *skb)
6060 {
6061 struct hci_ev_le_past_received *ev = data;
6062 int mask = hdev->link_mode;
6063 __u8 flags = 0;
6064 struct hci_conn *pa_sync, *conn;
6065
6066 bt_dev_dbg(hdev, "status 0x%2.2x", ev->status);
6067
6068 hci_dev_lock(hdev);
6069 hci_store_wake_reason(hdev, &ev->bdaddr, ev->bdaddr_type);
6070
6071 hci_dev_clear_flag(hdev, HCI_PA_SYNC);
6072
6073 conn = hci_conn_hash_lookup_create_pa_sync(hdev);
6074 if (!conn) {
6075 bt_dev_err(hdev,
6076 "Unable to find connection for dst %pMR sid 0x%2.2x",
6077 &ev->bdaddr, ev->sid);
6078 goto unlock;
6079 }
6080
6081 conn->sync_handle = le16_to_cpu(ev->sync_handle);
6082 conn->sid = HCI_SID_INVALID;
6083
6084 mask |= hci_proto_connect_ind(hdev, &ev->bdaddr, PA_LINK,
6085 &flags);
6086 if (!(mask & HCI_LM_ACCEPT)) {
6087 hci_le_pa_term_sync(hdev, ev->sync_handle);
6088 goto unlock;
6089 }
6090
6091 if (!(flags & HCI_PROTO_DEFER))
6092 goto unlock;
6093
6094 /* Add connection to indicate PA sync event */
6095 pa_sync = hci_conn_add_unset(hdev, PA_LINK, BDADDR_ANY, 0,
6096 HCI_ROLE_SLAVE);
6097
6098 if (IS_ERR(pa_sync))
6099 goto unlock;
6100
6101 pa_sync->sync_handle = le16_to_cpu(ev->sync_handle);
6102
6103 if (ev->status) {
6104 set_bit(HCI_CONN_PA_SYNC_FAILED, &pa_sync->flags);
6105
6106 /* Notify iso layer */
6107 hci_connect_cfm(pa_sync, ev->status);
6108 }
6109
6110 unlock:
6111 hci_dev_unlock(hdev);
6112 }
6113
hci_le_conn_update_complete_evt(struct hci_dev * hdev,void * data,struct sk_buff * skb)6114 static void hci_le_conn_update_complete_evt(struct hci_dev *hdev, void *data,
6115 struct sk_buff *skb)
6116 {
6117 struct hci_ev_le_conn_update_complete *ev = data;
6118 struct hci_conn *conn;
6119
6120 bt_dev_dbg(hdev, "status 0x%2.2x", ev->status);
6121
6122 if (ev->status)
6123 return;
6124
6125 hci_dev_lock(hdev);
6126
6127 conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(ev->handle));
6128 if (conn) {
6129 conn->le_conn_interval = le16_to_cpu(ev->interval);
6130 conn->le_conn_latency = le16_to_cpu(ev->latency);
6131 conn->le_supv_timeout = le16_to_cpu(ev->supervision_timeout);
6132 }
6133
6134 hci_dev_unlock(hdev);
6135 }
6136
6137 /* This function requires the caller holds hdev->lock */
check_pending_le_conn(struct hci_dev * hdev,bdaddr_t * addr,u8 addr_type,bool addr_resolved,u8 adv_type,u8 phy,u8 sec_phy)6138 static struct hci_conn *check_pending_le_conn(struct hci_dev *hdev,
6139 bdaddr_t *addr,
6140 u8 addr_type, bool addr_resolved,
6141 u8 adv_type, u8 phy, u8 sec_phy)
6142 {
6143 struct hci_conn *conn;
6144 struct hci_conn_params *params;
6145
6146 /* If the event is not connectable don't proceed further */
6147 if (adv_type != LE_ADV_IND && adv_type != LE_ADV_DIRECT_IND)
6148 return NULL;
6149
6150 /* Ignore if the device is blocked or hdev is suspended */
6151 if (hci_bdaddr_list_lookup(&hdev->reject_list, addr, addr_type) ||
6152 hdev->suspended)
6153 return NULL;
6154
6155 /* Most controller will fail if we try to create new connections
6156 * while we have an existing one in peripheral role.
6157 */
6158 if (hdev->conn_hash.le_num_peripheral > 0 &&
6159 (hci_test_quirk(hdev, HCI_QUIRK_BROKEN_LE_STATES) ||
6160 !(hdev->le_states[3] & 0x10)))
6161 return NULL;
6162
6163 /* If we're not connectable only connect devices that we have in
6164 * our pend_le_conns list.
6165 */
6166 params = hci_pend_le_action_lookup(&hdev->pend_le_conns, addr,
6167 addr_type);
6168 if (!params)
6169 return NULL;
6170
6171 if (!params->explicit_connect) {
6172 switch (params->auto_connect) {
6173 case HCI_AUTO_CONN_DIRECT:
6174 /* Only devices advertising with ADV_DIRECT_IND are
6175 * triggering a connection attempt. This is allowing
6176 * incoming connections from peripheral devices.
6177 */
6178 if (adv_type != LE_ADV_DIRECT_IND)
6179 return NULL;
6180 break;
6181 case HCI_AUTO_CONN_ALWAYS:
6182 /* Devices advertising with ADV_IND or ADV_DIRECT_IND
6183 * are triggering a connection attempt. This means
6184 * that incoming connections from peripheral device are
6185 * accepted and also outgoing connections to peripheral
6186 * devices are established when found.
6187 */
6188 break;
6189 default:
6190 return NULL;
6191 }
6192 }
6193
6194 conn = hci_connect_le(hdev, addr, addr_type, addr_resolved,
6195 BT_SECURITY_LOW, hdev->def_le_autoconnect_timeout,
6196 HCI_ROLE_MASTER, phy, sec_phy);
6197 if (!IS_ERR(conn)) {
6198 /* If HCI_AUTO_CONN_EXPLICIT is set, conn is already owned
6199 * by higher layer that tried to connect, if no then
6200 * store the pointer since we don't really have any
6201 * other owner of the object besides the params that
6202 * triggered it. This way we can abort the connection if
6203 * the parameters get removed and keep the reference
6204 * count consistent once the connection is established.
6205 */
6206
6207 if (!params->explicit_connect)
6208 params->conn = hci_conn_get(conn);
6209
6210 return conn;
6211 }
6212
6213 switch (PTR_ERR(conn)) {
6214 case -EBUSY:
6215 /* If hci_connect() returns -EBUSY it means there is already
6216 * an LE connection attempt going on. Since controllers don't
6217 * support more than one connection attempt at the time, we
6218 * don't consider this an error case.
6219 */
6220 break;
6221 default:
6222 BT_DBG("Failed to connect: err %ld", PTR_ERR(conn));
6223 return NULL;
6224 }
6225
6226 return NULL;
6227 }
6228
process_adv_report(struct hci_dev * hdev,u8 type,bdaddr_t * bdaddr,u8 bdaddr_type,bdaddr_t * direct_addr,u8 direct_addr_type,u8 phy,u8 sec_phy,s8 rssi,u8 * data,u8 len,bool ext_adv,bool ctl_time,u64 instant)6229 static void process_adv_report(struct hci_dev *hdev, u8 type, bdaddr_t *bdaddr,
6230 u8 bdaddr_type, bdaddr_t *direct_addr,
6231 u8 direct_addr_type, u8 phy, u8 sec_phy, s8 rssi,
6232 u8 *data, u8 len, bool ext_adv, bool ctl_time,
6233 u64 instant)
6234 {
6235 struct discovery_state *d = &hdev->discovery;
6236 struct smp_irk *irk;
6237 struct hci_conn *conn;
6238 bool match, bdaddr_resolved;
6239 u32 flags;
6240 u8 *ptr;
6241
6242 switch (type) {
6243 case LE_ADV_IND:
6244 case LE_ADV_DIRECT_IND:
6245 case LE_ADV_SCAN_IND:
6246 case LE_ADV_NONCONN_IND:
6247 case LE_ADV_SCAN_RSP:
6248 break;
6249 default:
6250 bt_dev_err_ratelimited(hdev, "unknown advertising packet "
6251 "type: 0x%02x", type);
6252 return;
6253 }
6254
6255 if (len > max_adv_len(hdev)) {
6256 bt_dev_err_ratelimited(hdev,
6257 "adv larger than maximum supported");
6258 return;
6259 }
6260
6261 /* Find the end of the data in case the report contains padded zero
6262 * bytes at the end causing an invalid length value.
6263 *
6264 * When data is NULL, len is 0 so there is no need for extra ptr
6265 * check as 'ptr < data + 0' is already false in such case.
6266 */
6267 for (ptr = data; ptr < data + len && *ptr; ptr += *ptr + 1) {
6268 if (ptr + 1 + *ptr > data + len)
6269 break;
6270 }
6271
6272 /* Adjust for actual length. This handles the case when remote
6273 * device is advertising with incorrect data length.
6274 */
6275 len = ptr - data;
6276
6277 /* If the direct address is present, then this report is from
6278 * a LE Direct Advertising Report event. In that case it is
6279 * important to see if the address is matching the local
6280 * controller address.
6281 *
6282 * If local privacy is not enable the controller shall not be
6283 * generating such event since according to its documentation it is only
6284 * valid for filter_policy 0x02 and 0x03, but the fact that it did
6285 * generate LE Direct Advertising Report means it is probably broken and
6286 * won't generate any other event which can potentially break
6287 * auto-connect logic so in case local privacy is not enable this
6288 * ignores the direct_addr so it works as a regular report.
6289 */
6290 if (!hci_dev_test_flag(hdev, HCI_MESH) && direct_addr &&
6291 hci_dev_test_flag(hdev, HCI_PRIVACY)) {
6292 direct_addr_type = ev_bdaddr_type(hdev, direct_addr_type,
6293 &bdaddr_resolved);
6294
6295 /* Only resolvable random addresses are valid for these
6296 * kind of reports and others can be ignored.
6297 */
6298 if (!hci_bdaddr_is_rpa(direct_addr, direct_addr_type))
6299 return;
6300
6301 /* If the local IRK of the controller does not match
6302 * with the resolvable random address provided, then
6303 * this report can be ignored.
6304 */
6305 if (!smp_irk_matches(hdev, hdev->irk, direct_addr))
6306 return;
6307 }
6308
6309 /* Check if we need to convert to identity address */
6310 irk = hci_get_irk(hdev, bdaddr, bdaddr_type);
6311 if (irk) {
6312 bdaddr = &irk->bdaddr;
6313 bdaddr_type = irk->addr_type;
6314 }
6315
6316 bdaddr_type = ev_bdaddr_type(hdev, bdaddr_type, &bdaddr_resolved);
6317
6318 /* Check if we have been requested to connect to this device.
6319 *
6320 * direct_addr is set only for directed advertising reports (it is NULL
6321 * for advertising reports) and is already verified to be RPA above.
6322 */
6323 conn = check_pending_le_conn(hdev, bdaddr, bdaddr_type, bdaddr_resolved,
6324 type, phy, sec_phy);
6325 if (!ext_adv && conn && type == LE_ADV_IND &&
6326 len <= max_adv_len(hdev)) {
6327 /* Store report for later inclusion by
6328 * mgmt_device_connected
6329 */
6330 memcpy(conn->le_adv_data, data, len);
6331 conn->le_adv_data_len = len;
6332 }
6333
6334 if (type == LE_ADV_NONCONN_IND || type == LE_ADV_SCAN_IND)
6335 flags = MGMT_DEV_FOUND_NOT_CONNECTABLE;
6336 else
6337 flags = 0;
6338
6339 /* All scan results should be sent up for Mesh systems */
6340 if (hci_dev_test_flag(hdev, HCI_MESH)) {
6341 mgmt_device_found(hdev, bdaddr, LE_LINK, bdaddr_type, NULL,
6342 rssi, flags, data, len, NULL, 0, instant);
6343 return;
6344 }
6345
6346 /* Passive scanning shouldn't trigger any device found events,
6347 * except for devices marked as CONN_REPORT for which we do send
6348 * device found events, or advertisement monitoring requested.
6349 */
6350 if (hdev->le_scan_type == LE_SCAN_PASSIVE) {
6351 if (type == LE_ADV_DIRECT_IND)
6352 return;
6353
6354 if (!hci_pend_le_action_lookup(&hdev->pend_le_reports,
6355 bdaddr, bdaddr_type) &&
6356 idr_is_empty(&hdev->adv_monitors_idr))
6357 return;
6358
6359 mgmt_device_found(hdev, bdaddr, LE_LINK, bdaddr_type, NULL,
6360 rssi, flags, data, len, NULL, 0, 0);
6361 return;
6362 }
6363
6364 /* When receiving a scan response, then there is no way to
6365 * know if the remote device is connectable or not. However
6366 * since scan responses are merged with a previously seen
6367 * advertising report, the flags field from that report
6368 * will be used.
6369 *
6370 * In the unlikely case that a controller just sends a scan
6371 * response event that doesn't match the pending report, then
6372 * it is marked as a standalone SCAN_RSP.
6373 */
6374 if (type == LE_ADV_SCAN_RSP)
6375 flags = MGMT_DEV_FOUND_SCAN_RSP;
6376
6377 /* If there's nothing pending either store the data from this
6378 * event or send an immediate device found event if the data
6379 * should not be stored for later.
6380 */
6381 if (!has_pending_adv_report(hdev)) {
6382 /* If the report will trigger a SCAN_REQ store it for
6383 * later merging.
6384 */
6385 if (!ext_adv && (type == LE_ADV_IND ||
6386 type == LE_ADV_SCAN_IND)) {
6387 store_pending_adv_report(hdev, bdaddr, bdaddr_type,
6388 rssi, flags, data, len);
6389 return;
6390 }
6391
6392 mgmt_device_found(hdev, bdaddr, LE_LINK, bdaddr_type, NULL,
6393 rssi, flags, data, len, NULL, 0, 0);
6394 return;
6395 }
6396
6397 /* Check if the pending report is for the same device as the new one */
6398 match = (!bacmp(bdaddr, &d->last_adv_addr) &&
6399 bdaddr_type == d->last_adv_addr_type);
6400
6401 /* If the pending data doesn't match this report or this isn't a
6402 * scan response (e.g. we got a duplicate ADV_IND) then force
6403 * sending of the pending data.
6404 */
6405 if (type != LE_ADV_SCAN_RSP || !match) {
6406 /* Send out whatever is in the cache, but skip duplicates */
6407 if (!match)
6408 mgmt_device_found(hdev, &d->last_adv_addr, LE_LINK,
6409 d->last_adv_addr_type, NULL,
6410 d->last_adv_rssi, d->last_adv_flags,
6411 d->last_adv_data,
6412 d->last_adv_data_len, NULL, 0, 0);
6413
6414 /* If the new report will trigger a SCAN_REQ store it for
6415 * later merging.
6416 */
6417 if (!ext_adv && (type == LE_ADV_IND ||
6418 type == LE_ADV_SCAN_IND)) {
6419 store_pending_adv_report(hdev, bdaddr, bdaddr_type,
6420 rssi, flags, data, len);
6421 return;
6422 }
6423
6424 /* The advertising reports cannot be merged, so clear
6425 * the pending report and send out a device found event.
6426 */
6427 clear_pending_adv_report(hdev);
6428 mgmt_device_found(hdev, bdaddr, LE_LINK, bdaddr_type, NULL,
6429 rssi, flags, data, len, NULL, 0, 0);
6430 return;
6431 }
6432
6433 /* If we get here we've got a pending ADV_IND or ADV_SCAN_IND and
6434 * the new event is a SCAN_RSP. We can therefore proceed with
6435 * sending a merged device found event.
6436 */
6437 mgmt_device_found(hdev, &d->last_adv_addr, LE_LINK,
6438 d->last_adv_addr_type, NULL, rssi, d->last_adv_flags,
6439 d->last_adv_data, d->last_adv_data_len, data, len, 0);
6440 clear_pending_adv_report(hdev);
6441 }
6442
hci_le_adv_report_evt(struct hci_dev * hdev,void * data,struct sk_buff * skb)6443 static void hci_le_adv_report_evt(struct hci_dev *hdev, void *data,
6444 struct sk_buff *skb)
6445 {
6446 struct hci_ev_le_advertising_report *ev = data;
6447 u64 instant = jiffies;
6448
6449 if (!ev->num)
6450 return;
6451
6452 hci_dev_lock(hdev);
6453
6454 while (ev->num--) {
6455 struct hci_ev_le_advertising_info *info;
6456 s8 rssi;
6457
6458 info = hci_le_ev_skb_pull(hdev, skb,
6459 HCI_EV_LE_ADVERTISING_REPORT,
6460 sizeof(*info));
6461 if (!info)
6462 break;
6463
6464 if (!hci_le_ev_skb_pull(hdev, skb, HCI_EV_LE_ADVERTISING_REPORT,
6465 info->length + 1))
6466 break;
6467
6468 hci_store_wake_reason(hdev, &info->bdaddr, info->bdaddr_type);
6469
6470 if (info->length <= max_adv_len(hdev)) {
6471 rssi = info->data[info->length];
6472 process_adv_report(hdev, info->type, &info->bdaddr,
6473 info->bdaddr_type, NULL, 0,
6474 HCI_ADV_PHY_1M, 0, rssi,
6475 info->data, info->length, false,
6476 false, instant);
6477 } else {
6478 bt_dev_err(hdev, "Dropping invalid advertising data");
6479 }
6480 }
6481
6482 hci_dev_unlock(hdev);
6483 }
6484
ext_evt_type_to_legacy(struct hci_dev * hdev,u16 evt_type)6485 static u8 ext_evt_type_to_legacy(struct hci_dev *hdev, u16 evt_type)
6486 {
6487 u16 pdu_type = evt_type & ~LE_EXT_ADV_DATA_STATUS_MASK;
6488
6489 if (!pdu_type)
6490 return LE_ADV_NONCONN_IND;
6491
6492 if (evt_type & LE_EXT_ADV_LEGACY_PDU) {
6493 switch (evt_type) {
6494 case LE_LEGACY_ADV_IND:
6495 return LE_ADV_IND;
6496 case LE_LEGACY_ADV_DIRECT_IND:
6497 return LE_ADV_DIRECT_IND;
6498 case LE_LEGACY_ADV_SCAN_IND:
6499 return LE_ADV_SCAN_IND;
6500 case LE_LEGACY_NONCONN_IND:
6501 return LE_ADV_NONCONN_IND;
6502 case LE_LEGACY_SCAN_RSP_ADV:
6503 case LE_LEGACY_SCAN_RSP_ADV_SCAN:
6504 return LE_ADV_SCAN_RSP;
6505 }
6506
6507 goto invalid;
6508 }
6509
6510 if (evt_type & LE_EXT_ADV_CONN_IND) {
6511 if (evt_type & LE_EXT_ADV_DIRECT_IND)
6512 return LE_ADV_DIRECT_IND;
6513
6514 return LE_ADV_IND;
6515 }
6516
6517 if (evt_type & LE_EXT_ADV_SCAN_RSP)
6518 return LE_ADV_SCAN_RSP;
6519
6520 if (evt_type & LE_EXT_ADV_SCAN_IND)
6521 return LE_ADV_SCAN_IND;
6522
6523 if (evt_type & LE_EXT_ADV_DIRECT_IND)
6524 return LE_ADV_NONCONN_IND;
6525
6526 invalid:
6527 bt_dev_err_ratelimited(hdev, "Unknown advertising packet type: 0x%02x",
6528 evt_type);
6529
6530 return LE_ADV_INVALID;
6531 }
6532
hci_le_ext_adv_report_evt(struct hci_dev * hdev,void * data,struct sk_buff * skb)6533 static void hci_le_ext_adv_report_evt(struct hci_dev *hdev, void *data,
6534 struct sk_buff *skb)
6535 {
6536 struct hci_ev_le_ext_adv_report *ev = data;
6537 u64 instant = jiffies;
6538
6539 if (!ev->num)
6540 return;
6541
6542 hci_dev_lock(hdev);
6543
6544 while (ev->num--) {
6545 struct hci_ev_le_ext_adv_info *info;
6546 u8 legacy_evt_type;
6547 u16 evt_type;
6548
6549 info = hci_le_ev_skb_pull(hdev, skb, HCI_EV_LE_EXT_ADV_REPORT,
6550 sizeof(*info));
6551 if (!info)
6552 break;
6553
6554 if (!hci_le_ev_skb_pull(hdev, skb, HCI_EV_LE_EXT_ADV_REPORT,
6555 info->length))
6556 break;
6557
6558 hci_store_wake_reason(hdev, &info->bdaddr, info->bdaddr_type);
6559
6560 evt_type = __le16_to_cpu(info->type) & LE_EXT_ADV_EVT_TYPE_MASK;
6561 legacy_evt_type = ext_evt_type_to_legacy(hdev, evt_type);
6562
6563 if (hci_test_quirk(hdev,
6564 HCI_QUIRK_FIXUP_LE_EXT_ADV_REPORT_PHY)) {
6565 info->primary_phy &= 0x1f;
6566 info->secondary_phy &= 0x1f;
6567 }
6568
6569 /* Check if PA Sync is pending and if the hci_conn SID has not
6570 * been set update it.
6571 */
6572 if (hci_dev_test_flag(hdev, HCI_PA_SYNC)) {
6573 struct hci_conn *conn;
6574
6575 conn = hci_conn_hash_lookup_create_pa_sync(hdev);
6576 if (conn && conn->sid == HCI_SID_INVALID)
6577 conn->sid = info->sid;
6578 }
6579
6580 if (legacy_evt_type != LE_ADV_INVALID) {
6581 process_adv_report(hdev, legacy_evt_type, &info->bdaddr,
6582 info->bdaddr_type, NULL, 0,
6583 info->primary_phy,
6584 info->secondary_phy,
6585 info->rssi, info->data, info->length,
6586 !(evt_type & LE_EXT_ADV_LEGACY_PDU),
6587 false, instant);
6588 }
6589 }
6590
6591 hci_dev_unlock(hdev);
6592 }
6593
hci_le_pa_sync_established_evt(struct hci_dev * hdev,void * data,struct sk_buff * skb)6594 static void hci_le_pa_sync_established_evt(struct hci_dev *hdev, void *data,
6595 struct sk_buff *skb)
6596 {
6597 struct hci_ev_le_pa_sync_established *ev = data;
6598 int mask = hdev->link_mode;
6599 __u8 flags = 0;
6600 struct hci_conn *pa_sync, *conn;
6601
6602 bt_dev_dbg(hdev, "status 0x%2.2x", ev->status);
6603
6604 hci_dev_lock(hdev);
6605 hci_store_wake_reason(hdev, &ev->bdaddr, ev->bdaddr_type);
6606
6607 hci_dev_clear_flag(hdev, HCI_PA_SYNC);
6608
6609 conn = hci_conn_hash_lookup_create_pa_sync(hdev);
6610 if (!conn) {
6611 bt_dev_err(hdev,
6612 "Unable to find connection for dst %pMR sid 0x%2.2x",
6613 &ev->bdaddr, ev->sid);
6614 goto unlock;
6615 }
6616
6617 clear_bit(HCI_CONN_CREATE_PA_SYNC, &conn->flags);
6618
6619 conn->sync_handle = le16_to_cpu(ev->handle);
6620 conn->sid = HCI_SID_INVALID;
6621
6622 mask |= hci_proto_connect_ind(hdev, &ev->bdaddr, PA_LINK,
6623 &flags);
6624 if (!(mask & HCI_LM_ACCEPT)) {
6625 hci_le_pa_term_sync(hdev, ev->handle);
6626 goto unlock;
6627 }
6628
6629 if (!(flags & HCI_PROTO_DEFER))
6630 goto unlock;
6631
6632 /* Add connection to indicate PA sync event */
6633 pa_sync = hci_conn_add_unset(hdev, PA_LINK, BDADDR_ANY, 0,
6634 HCI_ROLE_SLAVE);
6635
6636 if (IS_ERR(pa_sync))
6637 goto unlock;
6638
6639 pa_sync->sync_handle = le16_to_cpu(ev->handle);
6640
6641 if (ev->status) {
6642 set_bit(HCI_CONN_PA_SYNC_FAILED, &pa_sync->flags);
6643
6644 /* Notify iso layer */
6645 hci_connect_cfm(pa_sync, ev->status);
6646 }
6647
6648 unlock:
6649 hci_dev_unlock(hdev);
6650 }
6651
hci_le_per_adv_report_evt(struct hci_dev * hdev,void * data,struct sk_buff * skb)6652 static void hci_le_per_adv_report_evt(struct hci_dev *hdev, void *data,
6653 struct sk_buff *skb)
6654 {
6655 struct hci_ev_le_per_adv_report *ev = data;
6656 int mask = hdev->link_mode;
6657 __u8 flags = 0;
6658 struct hci_conn *pa_sync;
6659
6660 bt_dev_dbg(hdev, "sync_handle 0x%4.4x", le16_to_cpu(ev->sync_handle));
6661
6662 /* The reassembly in iso_connect_ind() copies ev->length bytes from the
6663 * stored event, so make sure the event actually carries that many data
6664 * bytes before it is consumed.
6665 */
6666 if (!hci_le_ev_skb_pull(hdev, skb, HCI_EV_LE_PER_ADV_REPORT, ev->length))
6667 return;
6668
6669 hci_dev_lock(hdev);
6670
6671 mask |= hci_proto_connect_ind(hdev, BDADDR_ANY, PA_LINK, &flags);
6672 if (!(mask & HCI_LM_ACCEPT))
6673 goto unlock;
6674
6675 if (!(flags & HCI_PROTO_DEFER))
6676 goto unlock;
6677
6678 pa_sync = hci_conn_hash_lookup_pa_sync_handle
6679 (hdev,
6680 le16_to_cpu(ev->sync_handle));
6681
6682 if (!pa_sync)
6683 goto unlock;
6684
6685 if (ev->data_status == LE_PA_DATA_COMPLETE &&
6686 !test_and_set_bit(HCI_CONN_PA_SYNC, &pa_sync->flags)) {
6687 /* Notify iso layer */
6688 hci_connect_cfm(pa_sync, 0);
6689
6690 /* Notify MGMT layer */
6691 mgmt_device_connected(hdev, pa_sync, NULL, 0);
6692 }
6693
6694 unlock:
6695 hci_dev_unlock(hdev);
6696 }
6697
hci_le_remote_feat_complete_evt(struct hci_dev * hdev,void * data,struct sk_buff * skb)6698 static void hci_le_remote_feat_complete_evt(struct hci_dev *hdev, void *data,
6699 struct sk_buff *skb)
6700 {
6701 struct hci_ev_le_remote_feat_complete *ev = data;
6702 struct hci_conn *conn;
6703
6704 bt_dev_dbg(hdev, "status 0x%2.2x", ev->status);
6705
6706 hci_dev_lock(hdev);
6707
6708 conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(ev->handle));
6709 if (conn) {
6710 if (!ev->status) {
6711 memcpy(conn->le_features, ev->features, 8);
6712
6713 /* Update supported PHYs */
6714 if (!(conn->le_features[1] & HCI_LE_PHY_2M)) {
6715 conn->le_tx_def_phys &= ~HCI_LE_SET_PHY_2M;
6716 conn->le_rx_def_phys &= ~HCI_LE_SET_PHY_2M;
6717 }
6718
6719 if (!(conn->le_features[1] & HCI_LE_PHY_CODED)) {
6720 conn->le_tx_def_phys &= ~HCI_LE_SET_PHY_CODED;
6721 conn->le_rx_def_phys &= ~HCI_LE_SET_PHY_CODED;
6722 }
6723 }
6724
6725 if (conn->state == BT_CONFIG) {
6726 __u8 status;
6727
6728 /* If the local controller supports peripheral-initiated
6729 * features exchange, but the remote controller does
6730 * not, then it is possible that the error code 0x1a
6731 * for unsupported remote feature gets returned.
6732 *
6733 * In this specific case, allow the connection to
6734 * transition into connected state and mark it as
6735 * successful.
6736 */
6737 if (!conn->out && ev->status == HCI_ERROR_UNSUPPORTED_REMOTE_FEATURE &&
6738 (hdev->le_features[0] & HCI_LE_PERIPHERAL_FEATURES))
6739 status = 0x00;
6740 else
6741 status = ev->status;
6742
6743 conn->state = BT_CONNECTED;
6744 hci_connect_cfm(conn, status);
6745 }
6746 }
6747
6748 hci_dev_unlock(hdev);
6749 }
6750
hci_le_ltk_request_evt(struct hci_dev * hdev,void * data,struct sk_buff * skb)6751 static void hci_le_ltk_request_evt(struct hci_dev *hdev, void *data,
6752 struct sk_buff *skb)
6753 {
6754 struct hci_ev_le_ltk_req *ev = data;
6755 struct hci_cp_le_ltk_reply cp;
6756 struct hci_cp_le_ltk_neg_reply neg;
6757 struct hci_conn *conn;
6758 struct smp_ltk *ltk;
6759
6760 bt_dev_dbg(hdev, "handle 0x%4.4x", __le16_to_cpu(ev->handle));
6761
6762 hci_dev_lock(hdev);
6763
6764 conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(ev->handle));
6765 if (conn == NULL)
6766 goto not_found;
6767
6768 ltk = hci_find_ltk(hdev, &conn->dst, conn->dst_type, conn->role);
6769 if (!ltk)
6770 goto not_found;
6771
6772 if (smp_ltk_is_sc(ltk)) {
6773 /* With SC both EDiv and Rand are set to zero */
6774 if (ev->ediv || ev->rand)
6775 goto not_found;
6776 } else {
6777 /* For non-SC keys check that EDiv and Rand match */
6778 if (ev->ediv != ltk->ediv || ev->rand != ltk->rand)
6779 goto not_found;
6780 }
6781
6782 memcpy(cp.ltk, ltk->val, ltk->enc_size);
6783 memset(cp.ltk + ltk->enc_size, 0, sizeof(cp.ltk) - ltk->enc_size);
6784 cp.handle = cpu_to_le16(conn->handle);
6785
6786 conn->pending_sec_level = smp_ltk_sec_level(ltk);
6787
6788 conn->enc_key_size = ltk->enc_size;
6789
6790 hci_send_cmd(hdev, HCI_OP_LE_LTK_REPLY, sizeof(cp), &cp);
6791
6792 /* Ref. Bluetooth Core SPEC pages 1975 and 2004. STK is a
6793 * temporary key used to encrypt a connection following
6794 * pairing. It is used during the Encrypted Session Setup to
6795 * distribute the keys. Later, security can be re-established
6796 * using a distributed LTK.
6797 */
6798 if (ltk->type == SMP_STK) {
6799 set_bit(HCI_CONN_STK_ENCRYPT, &conn->flags);
6800 list_del_rcu(<k->list);
6801 kfree_rcu(ltk, rcu);
6802 } else {
6803 clear_bit(HCI_CONN_STK_ENCRYPT, &conn->flags);
6804 }
6805
6806 hci_dev_unlock(hdev);
6807
6808 return;
6809
6810 not_found:
6811 neg.handle = ev->handle;
6812 hci_send_cmd(hdev, HCI_OP_LE_LTK_NEG_REPLY, sizeof(neg), &neg);
6813 hci_dev_unlock(hdev);
6814 }
6815
send_conn_param_neg_reply(struct hci_dev * hdev,u16 handle,u8 reason)6816 static void send_conn_param_neg_reply(struct hci_dev *hdev, u16 handle,
6817 u8 reason)
6818 {
6819 struct hci_cp_le_conn_param_req_neg_reply cp;
6820
6821 cp.handle = cpu_to_le16(handle);
6822 cp.reason = reason;
6823
6824 hci_send_cmd(hdev, HCI_OP_LE_CONN_PARAM_REQ_NEG_REPLY, sizeof(cp),
6825 &cp);
6826 }
6827
hci_le_remote_conn_param_req_evt(struct hci_dev * hdev,void * data,struct sk_buff * skb)6828 static void hci_le_remote_conn_param_req_evt(struct hci_dev *hdev, void *data,
6829 struct sk_buff *skb)
6830 {
6831 struct hci_ev_le_remote_conn_param_req *ev = data;
6832 struct hci_cp_le_conn_param_req_reply cp;
6833 struct hci_conn *hcon;
6834 u16 handle, min, max, latency, timeout;
6835
6836 bt_dev_dbg(hdev, "handle 0x%4.4x", __le16_to_cpu(ev->handle));
6837
6838 handle = le16_to_cpu(ev->handle);
6839 min = le16_to_cpu(ev->interval_min);
6840 max = le16_to_cpu(ev->interval_max);
6841 latency = le16_to_cpu(ev->latency);
6842 timeout = le16_to_cpu(ev->timeout);
6843
6844 hci_dev_lock(hdev);
6845
6846 hcon = hci_conn_hash_lookup_handle(hdev, handle);
6847 if (!hcon || hcon->state != BT_CONNECTED) {
6848 send_conn_param_neg_reply(hdev, handle,
6849 HCI_ERROR_UNKNOWN_CONN_ID);
6850 goto unlock;
6851 }
6852
6853 if (max > hcon->le_conn_max_interval) {
6854 send_conn_param_neg_reply(hdev, handle,
6855 HCI_ERROR_INVALID_LL_PARAMS);
6856 goto unlock;
6857 }
6858
6859 if (hci_check_conn_params(min, max, latency, timeout)) {
6860 send_conn_param_neg_reply(hdev, handle,
6861 HCI_ERROR_INVALID_LL_PARAMS);
6862 goto unlock;
6863 }
6864
6865 if (hcon->role == HCI_ROLE_MASTER) {
6866 struct hci_conn_params *params;
6867 u8 store_hint;
6868
6869 params = hci_conn_params_lookup(hdev, &hcon->dst,
6870 hcon->dst_type);
6871 if (params) {
6872 params->conn_min_interval = min;
6873 params->conn_max_interval = max;
6874 params->conn_latency = latency;
6875 params->supervision_timeout = timeout;
6876 store_hint = 0x01;
6877 } else {
6878 store_hint = 0x00;
6879 }
6880
6881 mgmt_new_conn_param(hdev, &hcon->dst, hcon->dst_type,
6882 store_hint, min, max, latency, timeout);
6883 }
6884
6885 cp.handle = ev->handle;
6886 cp.interval_min = ev->interval_min;
6887 cp.interval_max = ev->interval_max;
6888 cp.latency = ev->latency;
6889 cp.timeout = ev->timeout;
6890 cp.min_ce_len = 0;
6891 cp.max_ce_len = 0;
6892
6893 hci_send_cmd(hdev, HCI_OP_LE_CONN_PARAM_REQ_REPLY, sizeof(cp), &cp);
6894
6895 unlock:
6896 hci_dev_unlock(hdev);
6897 }
6898
hci_le_direct_adv_report_evt(struct hci_dev * hdev,void * data,struct sk_buff * skb)6899 static void hci_le_direct_adv_report_evt(struct hci_dev *hdev, void *data,
6900 struct sk_buff *skb)
6901 {
6902 struct hci_ev_le_direct_adv_report *ev = data;
6903 u64 instant = jiffies;
6904 int i;
6905
6906 if (!hci_le_ev_skb_pull(hdev, skb, HCI_EV_LE_DIRECT_ADV_REPORT,
6907 flex_array_size(ev, info, ev->num)))
6908 return;
6909
6910 if (!ev->num)
6911 return;
6912
6913 hci_dev_lock(hdev);
6914
6915 for (i = 0; i < ev->num; i++) {
6916 struct hci_ev_le_direct_adv_info *info = &ev->info[i];
6917
6918 hci_store_wake_reason(hdev, &info->bdaddr, info->bdaddr_type);
6919
6920 process_adv_report(hdev, info->type, &info->bdaddr,
6921 info->bdaddr_type, &info->direct_addr,
6922 info->direct_addr_type, HCI_ADV_PHY_1M, 0,
6923 info->rssi, NULL, 0, false, false, instant);
6924 }
6925
6926 hci_dev_unlock(hdev);
6927 }
6928
hci_le_phy_update_evt(struct hci_dev * hdev,void * data,struct sk_buff * skb)6929 static void hci_le_phy_update_evt(struct hci_dev *hdev, void *data,
6930 struct sk_buff *skb)
6931 {
6932 struct hci_ev_le_phy_update_complete *ev = data;
6933 struct hci_conn *conn;
6934
6935 bt_dev_dbg(hdev, "status 0x%2.2x", ev->status);
6936
6937 if (ev->status)
6938 return;
6939
6940 hci_dev_lock(hdev);
6941
6942 conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(ev->handle));
6943 if (!conn)
6944 goto unlock;
6945
6946 conn->le_tx_phy = ev->tx_phy;
6947 conn->le_rx_phy = ev->rx_phy;
6948
6949 unlock:
6950 hci_dev_unlock(hdev);
6951 }
6952
6953 /* Convert LE PHY to QoS PHYs */
le_phy_qos(u8 phy)6954 static u8 le_phy_qos(u8 phy)
6955 {
6956 switch (phy) {
6957 case 0x01:
6958 return HCI_LE_SET_PHY_1M;
6959 case 0x02:
6960 return HCI_LE_SET_PHY_2M;
6961 case 0x03:
6962 return HCI_LE_SET_PHY_CODED;
6963 }
6964
6965 return 0;
6966 }
6967
hci_le_cis_established_evt(struct hci_dev * hdev,void * data,struct sk_buff * skb)6968 static void hci_le_cis_established_evt(struct hci_dev *hdev, void *data,
6969 struct sk_buff *skb)
6970 {
6971 struct hci_evt_le_cis_established *ev = data;
6972 struct hci_conn *conn;
6973 struct bt_iso_qos *qos;
6974 bool pending = false;
6975 u16 handle = __le16_to_cpu(ev->handle);
6976 u32 c_sdu_interval, p_sdu_interval;
6977
6978 bt_dev_dbg(hdev, "status 0x%2.2x", ev->status);
6979
6980 hci_dev_lock(hdev);
6981
6982 conn = hci_conn_hash_lookup_handle(hdev, handle);
6983 if (!conn) {
6984 bt_dev_err(hdev,
6985 "Unable to find connection with handle 0x%4.4x",
6986 handle);
6987 goto unlock;
6988 }
6989
6990 if (conn->type != CIS_LINK) {
6991 bt_dev_err(hdev,
6992 "Invalid connection link type handle 0x%4.4x",
6993 handle);
6994 goto unlock;
6995 }
6996
6997 qos = &conn->iso_qos;
6998
6999 pending = test_and_clear_bit(HCI_CONN_CREATE_CIS, &conn->flags);
7000
7001 /* BLUETOOTH CORE SPECIFICATION Version 5.4 | Vol 6, Part G
7002 * page 3075:
7003 * Transport_Latency_C_To_P = CIG_Sync_Delay + (FT_C_To_P) ×
7004 * ISO_Interval + SDU_Interval_C_To_P
7005 * ...
7006 * SDU_Interval = (CIG_Sync_Delay + (FT) x ISO_Interval) -
7007 * Transport_Latency
7008 */
7009 c_sdu_interval = (get_unaligned_le24(ev->cig_sync_delay) +
7010 (ev->c_ft * le16_to_cpu(ev->interval) * 1250)) -
7011 get_unaligned_le24(ev->c_latency);
7012 p_sdu_interval = (get_unaligned_le24(ev->cig_sync_delay) +
7013 (ev->p_ft * le16_to_cpu(ev->interval) * 1250)) -
7014 get_unaligned_le24(ev->p_latency);
7015
7016 switch (conn->role) {
7017 case HCI_ROLE_SLAVE:
7018 qos->ucast.in.interval = c_sdu_interval;
7019 qos->ucast.out.interval = p_sdu_interval;
7020 /* Convert Transport Latency (us) to Latency (msec) */
7021 qos->ucast.in.latency =
7022 DIV_ROUND_CLOSEST(get_unaligned_le24(ev->c_latency),
7023 1000);
7024 qos->ucast.out.latency =
7025 DIV_ROUND_CLOSEST(get_unaligned_le24(ev->p_latency),
7026 1000);
7027 qos->ucast.in.sdu = ev->c_bn ? le16_to_cpu(ev->c_mtu) : 0;
7028 qos->ucast.out.sdu = ev->p_bn ? le16_to_cpu(ev->p_mtu) : 0;
7029 qos->ucast.in.phys = le_phy_qos(ev->c_phy);
7030 qos->ucast.out.phys = le_phy_qos(ev->p_phy);
7031 break;
7032 case HCI_ROLE_MASTER:
7033 qos->ucast.in.interval = p_sdu_interval;
7034 qos->ucast.out.interval = c_sdu_interval;
7035 /* Convert Transport Latency (us) to Latency (msec) */
7036 qos->ucast.out.latency =
7037 DIV_ROUND_CLOSEST(get_unaligned_le24(ev->c_latency),
7038 1000);
7039 qos->ucast.in.latency =
7040 DIV_ROUND_CLOSEST(get_unaligned_le24(ev->p_latency),
7041 1000);
7042 qos->ucast.out.sdu = ev->c_bn ? le16_to_cpu(ev->c_mtu) : 0;
7043 qos->ucast.in.sdu = ev->p_bn ? le16_to_cpu(ev->p_mtu) : 0;
7044 qos->ucast.out.phys = le_phy_qos(ev->c_phy);
7045 qos->ucast.in.phys = le_phy_qos(ev->p_phy);
7046 break;
7047 }
7048
7049 if (!ev->status) {
7050 conn->state = BT_CONNECTED;
7051 hci_debugfs_create_conn(conn);
7052 hci_conn_add_sysfs(conn);
7053 hci_iso_setup_path(conn);
7054 goto unlock;
7055 }
7056
7057 conn->state = BT_CLOSED;
7058 hci_connect_cfm(conn, ev->status);
7059 hci_conn_del(conn);
7060
7061 unlock:
7062 if (pending)
7063 hci_le_create_cis_pending(hdev);
7064
7065 hci_dev_unlock(hdev);
7066 }
7067
hci_le_reject_cis(struct hci_dev * hdev,__le16 handle)7068 static void hci_le_reject_cis(struct hci_dev *hdev, __le16 handle)
7069 {
7070 struct hci_cp_le_reject_cis cp;
7071
7072 memset(&cp, 0, sizeof(cp));
7073 cp.handle = handle;
7074 cp.reason = HCI_ERROR_REJ_BAD_ADDR;
7075 hci_send_cmd(hdev, HCI_OP_LE_REJECT_CIS, sizeof(cp), &cp);
7076 }
7077
hci_le_accept_cis(struct hci_dev * hdev,__le16 handle)7078 static void hci_le_accept_cis(struct hci_dev *hdev, __le16 handle)
7079 {
7080 struct hci_cp_le_accept_cis cp;
7081
7082 memset(&cp, 0, sizeof(cp));
7083 cp.handle = handle;
7084 hci_send_cmd(hdev, HCI_OP_LE_ACCEPT_CIS, sizeof(cp), &cp);
7085 }
7086
hci_le_cis_req_evt(struct hci_dev * hdev,void * data,struct sk_buff * skb)7087 static void hci_le_cis_req_evt(struct hci_dev *hdev, void *data,
7088 struct sk_buff *skb)
7089 {
7090 struct hci_evt_le_cis_req *ev = data;
7091 u16 acl_handle, cis_handle;
7092 struct hci_conn *acl, *cis;
7093 int mask;
7094 __u8 flags = 0;
7095
7096 acl_handle = __le16_to_cpu(ev->acl_handle);
7097 cis_handle = __le16_to_cpu(ev->cis_handle);
7098
7099 bt_dev_dbg(hdev, "acl 0x%4.4x handle 0x%4.4x cig 0x%2.2x cis 0x%2.2x",
7100 acl_handle, cis_handle, ev->cig_id, ev->cis_id);
7101
7102 hci_dev_lock(hdev);
7103
7104 acl = hci_conn_hash_lookup_handle(hdev, acl_handle);
7105 if (!acl)
7106 goto unlock;
7107
7108 mask = hci_proto_connect_ind(hdev, &acl->dst, CIS_LINK, &flags);
7109 if (!(mask & HCI_LM_ACCEPT)) {
7110 hci_le_reject_cis(hdev, ev->cis_handle);
7111 goto unlock;
7112 }
7113
7114 cis = hci_conn_hash_lookup_handle(hdev, cis_handle);
7115 if (!cis) {
7116 cis = hci_conn_add(hdev, CIS_LINK, &acl->dst, acl->dst_type,
7117 HCI_ROLE_SLAVE, cis_handle);
7118 if (IS_ERR(cis)) {
7119 hci_le_reject_cis(hdev, ev->cis_handle);
7120 goto unlock;
7121 }
7122 }
7123
7124 cis->iso_qos.ucast.cig = ev->cig_id;
7125 cis->iso_qos.ucast.cis = ev->cis_id;
7126
7127 if (!(flags & HCI_PROTO_DEFER)) {
7128 hci_le_accept_cis(hdev, ev->cis_handle);
7129 } else {
7130 cis->state = BT_CONNECT2;
7131 hci_connect_cfm(cis, 0);
7132 }
7133
7134 unlock:
7135 hci_dev_unlock(hdev);
7136 }
7137
hci_iso_term_big_sync(struct hci_dev * hdev,void * data)7138 static int hci_iso_term_big_sync(struct hci_dev *hdev, void *data)
7139 {
7140 u8 handle = PTR_UINT(data);
7141
7142 return hci_le_terminate_big_sync(hdev, handle,
7143 HCI_ERROR_LOCAL_HOST_TERM);
7144 }
7145
hci_le_create_big_complete_evt(struct hci_dev * hdev,void * data,struct sk_buff * skb)7146 static void hci_le_create_big_complete_evt(struct hci_dev *hdev, void *data,
7147 struct sk_buff *skb)
7148 {
7149 struct hci_evt_le_create_big_complete *ev = data;
7150 struct hci_conn *conn;
7151 __u8 i = 0;
7152
7153 BT_DBG("%s status 0x%2.2x", hdev->name, ev->status);
7154
7155 if (!hci_le_ev_skb_pull(hdev, skb, HCI_EVT_LE_CREATE_BIG_COMPLETE,
7156 flex_array_size(ev, bis_handle, ev->num_bis)))
7157 return;
7158
7159 hci_dev_lock(hdev);
7160
7161 /* Connect all BISes that are bound to the BIG */
7162 while ((conn = hci_conn_hash_lookup_big_state(hdev, ev->handle,
7163 BT_BOUND,
7164 HCI_ROLE_MASTER))) {
7165 if (ev->status) {
7166 hci_connect_cfm(conn, ev->status);
7167 hci_conn_del(conn);
7168 continue;
7169 }
7170
7171 if (ev->num_bis <= i) {
7172 bt_dev_err(hdev,
7173 "Not enough BIS handles for BIG 0x%2.2x",
7174 ev->handle);
7175 ev->status = HCI_ERROR_UNSPECIFIED;
7176 hci_connect_cfm(conn, ev->status);
7177 hci_conn_del(conn);
7178 continue;
7179 }
7180
7181 if (hci_conn_set_handle(conn,
7182 __le16_to_cpu(ev->bis_handle[i++]))) {
7183 bt_dev_err(hdev,
7184 "Failed to set BIS handle for BIG 0x%2.2x",
7185 ev->handle);
7186 /* Force error so BIG gets terminated as not all BIS
7187 * could be connected.
7188 */
7189 ev->status = HCI_ERROR_UNSPECIFIED;
7190 hci_connect_cfm(conn, ev->status);
7191 hci_conn_del(conn);
7192 continue;
7193 }
7194
7195 conn->state = BT_CONNECTED;
7196 set_bit(HCI_CONN_BIG_CREATED, &conn->flags);
7197 hci_debugfs_create_conn(conn);
7198 hci_conn_add_sysfs(conn);
7199 hci_iso_setup_path(conn);
7200 }
7201
7202 /* If there is an unexpected error or if no BISes have been connected
7203 * for the BIG, terminate it.
7204 */
7205 if (ev->status == HCI_ERROR_UNSPECIFIED || (!ev->status && !i))
7206 /* If no BISes have been connected for the BIG,
7207 * terminate. This is in case all bound connections
7208 * have been closed before the BIG creation
7209 * has completed.
7210 */
7211 hci_cmd_sync_queue(hdev, hci_iso_term_big_sync,
7212 UINT_PTR(ev->handle), NULL);
7213
7214 hci_dev_unlock(hdev);
7215 }
7216
hci_le_big_sync_established_evt(struct hci_dev * hdev,void * data,struct sk_buff * skb)7217 static void hci_le_big_sync_established_evt(struct hci_dev *hdev, void *data,
7218 struct sk_buff *skb)
7219 {
7220 struct hci_evt_le_big_sync_established *ev = data;
7221 struct hci_conn *bis, *conn;
7222 int i;
7223
7224 bt_dev_dbg(hdev, "status 0x%2.2x", ev->status);
7225
7226 if (!hci_le_ev_skb_pull(hdev, skb, HCI_EVT_LE_BIG_SYNC_ESTABLISHED,
7227 flex_array_size(ev, bis, ev->num_bis)))
7228 return;
7229
7230 hci_dev_lock(hdev);
7231
7232 conn = hci_conn_hash_lookup_big_sync_pend(hdev, ev->handle,
7233 ev->num_bis);
7234 if (!conn) {
7235 bt_dev_err(hdev,
7236 "Unable to find connection for big 0x%2.2x",
7237 ev->handle);
7238 goto unlock;
7239 }
7240
7241 clear_bit(HCI_CONN_CREATE_BIG_SYNC, &conn->flags);
7242
7243 conn->num_bis = 0;
7244 memset(conn->bis, 0, sizeof(conn->bis));
7245
7246 for (i = 0; i < ev->num_bis; i++) {
7247 u16 handle = le16_to_cpu(ev->bis[i]);
7248 __le32 interval;
7249
7250 bis = hci_conn_hash_lookup_handle(hdev, handle);
7251 if (!bis) {
7252 if (handle > HCI_CONN_HANDLE_MAX) {
7253 bt_dev_dbg(hdev, "ignore too large handle %u", handle);
7254 continue;
7255 }
7256 bis = hci_conn_add(hdev, BIS_LINK, BDADDR_ANY, 0,
7257 HCI_ROLE_SLAVE, handle);
7258 if (IS_ERR(bis))
7259 continue;
7260 }
7261
7262 if (ev->status != 0x42)
7263 /* Mark PA sync as established */
7264 set_bit(HCI_CONN_PA_SYNC, &bis->flags);
7265
7266 bis->sync_handle = conn->sync_handle;
7267 bis->iso_qos.bcast.big = ev->handle;
7268 memset(&interval, 0, sizeof(interval));
7269 memcpy(&interval, ev->latency, sizeof(ev->latency));
7270 bis->iso_qos.bcast.in.interval = le32_to_cpu(interval);
7271 /* Convert ISO Interval (1.25 ms slots) to latency (ms) */
7272 bis->iso_qos.bcast.in.latency = le16_to_cpu(ev->interval) * 125 / 100;
7273 bis->iso_qos.bcast.in.sdu = le16_to_cpu(ev->max_pdu);
7274
7275 if (!ev->status) {
7276 bis->state = BT_CONNECTED;
7277 set_bit(HCI_CONN_BIG_SYNC, &bis->flags);
7278 hci_debugfs_create_conn(bis);
7279 hci_conn_add_sysfs(bis);
7280 hci_iso_setup_path(bis);
7281 }
7282 }
7283
7284 /* In case BIG sync failed, notify each failed connection to
7285 * the user after all hci connections have been added
7286 */
7287 if (ev->status)
7288 for (i = 0; i < ev->num_bis; i++) {
7289 u16 handle = le16_to_cpu(ev->bis[i]);
7290
7291 bis = hci_conn_hash_lookup_handle(hdev, handle);
7292 if (!bis)
7293 continue;
7294
7295 set_bit(HCI_CONN_BIG_SYNC_FAILED, &bis->flags);
7296 hci_connect_cfm(bis, ev->status);
7297 }
7298
7299 unlock:
7300 hci_dev_unlock(hdev);
7301 }
7302
hci_le_big_sync_lost_evt(struct hci_dev * hdev,void * data,struct sk_buff * skb)7303 static void hci_le_big_sync_lost_evt(struct hci_dev *hdev, void *data,
7304 struct sk_buff *skb)
7305 {
7306 struct hci_evt_le_big_sync_lost *ev = data;
7307 struct hci_conn *bis;
7308 bool mgmt_conn = false;
7309
7310 bt_dev_dbg(hdev, "big handle 0x%2.2x", ev->handle);
7311
7312 hci_dev_lock(hdev);
7313
7314 /* Delete each bis connection */
7315 while ((bis = hci_conn_hash_lookup_big_state(hdev, ev->handle,
7316 BT_CONNECTED,
7317 HCI_ROLE_SLAVE))) {
7318 if (!mgmt_conn) {
7319 mgmt_conn = test_and_clear_bit(HCI_CONN_MGMT_CONNECTED,
7320 &bis->flags);
7321 mgmt_device_disconnected(hdev, &bis->dst, bis->type,
7322 bis->dst_type, ev->reason,
7323 mgmt_conn);
7324 }
7325
7326 clear_bit(HCI_CONN_BIG_SYNC, &bis->flags);
7327 hci_disconn_cfm(bis, ev->reason);
7328 hci_conn_del(bis);
7329 }
7330
7331 hci_dev_unlock(hdev);
7332 }
7333
hci_le_big_info_adv_report_evt(struct hci_dev * hdev,void * data,struct sk_buff * skb)7334 static void hci_le_big_info_adv_report_evt(struct hci_dev *hdev, void *data,
7335 struct sk_buff *skb)
7336 {
7337 struct hci_evt_le_big_info_adv_report *ev = data;
7338 int mask = hdev->link_mode;
7339 __u8 flags = 0;
7340 struct hci_conn *pa_sync;
7341
7342 bt_dev_dbg(hdev, "sync_handle 0x%4.4x", le16_to_cpu(ev->sync_handle));
7343
7344 hci_dev_lock(hdev);
7345
7346 mask |= hci_proto_connect_ind(hdev, BDADDR_ANY, BIS_LINK, &flags);
7347 if (!(mask & HCI_LM_ACCEPT))
7348 goto unlock;
7349
7350 if (!(flags & HCI_PROTO_DEFER))
7351 goto unlock;
7352
7353 pa_sync = hci_conn_hash_lookup_pa_sync_handle
7354 (hdev,
7355 le16_to_cpu(ev->sync_handle));
7356
7357 if (!pa_sync)
7358 goto unlock;
7359
7360 pa_sync->iso_qos.bcast.encryption = ev->encryption;
7361
7362 /* Notify iso layer */
7363 hci_connect_cfm(pa_sync, 0);
7364
7365 unlock:
7366 hci_dev_unlock(hdev);
7367 }
7368
hci_le_read_all_remote_features_evt(struct hci_dev * hdev,void * data,struct sk_buff * skb)7369 static void hci_le_read_all_remote_features_evt(struct hci_dev *hdev,
7370 void *data, struct sk_buff *skb)
7371 {
7372 struct hci_evt_le_read_all_remote_features_complete *ev = data;
7373 struct hci_conn *conn;
7374
7375 bt_dev_dbg(hdev, "status 0x%2.2x", ev->status);
7376
7377 hci_dev_lock(hdev);
7378
7379 conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(ev->handle));
7380 if (!conn)
7381 goto unlock;
7382
7383 if (!ev->status) {
7384 memcpy(conn->le_features, ev->features, 248);
7385
7386 /* Update supported PHYs */
7387 if (!(conn->le_features[1] & HCI_LE_PHY_2M)) {
7388 conn->le_tx_def_phys &= ~HCI_LE_SET_PHY_2M;
7389 conn->le_rx_def_phys &= ~HCI_LE_SET_PHY_2M;
7390 }
7391
7392 if (!(conn->le_features[1] & HCI_LE_PHY_CODED)) {
7393 conn->le_tx_def_phys &= ~HCI_LE_SET_PHY_CODED;
7394 conn->le_rx_def_phys &= ~HCI_LE_SET_PHY_CODED;
7395 }
7396 }
7397
7398 if (conn->state == BT_CONFIG) {
7399 __u8 status;
7400
7401 /* If the local controller supports peripheral-initiated
7402 * features exchange, but the remote controller does
7403 * not, then it is possible that the error code 0x1a
7404 * for unsupported remote feature gets returned.
7405 *
7406 * In this specific case, allow the connection to
7407 * transition into connected state and mark it as
7408 * successful.
7409 */
7410 if (!conn->out &&
7411 ev->status == HCI_ERROR_UNSUPPORTED_REMOTE_FEATURE &&
7412 (hdev->le_features[0] & HCI_LE_PERIPHERAL_FEATURES))
7413 status = 0x00;
7414 else
7415 status = ev->status;
7416
7417 conn->state = BT_CONNECTED;
7418 hci_connect_cfm(conn, status);
7419 }
7420
7421 unlock:
7422 hci_dev_unlock(hdev);
7423 }
7424
hci_le_conn_rate_change_evt(struct hci_dev * hdev,void * data,struct sk_buff * skb)7425 static void hci_le_conn_rate_change_evt(struct hci_dev *hdev, void *data,
7426 struct sk_buff *skb)
7427 {
7428 struct hci_evt_le_conn_rate_change *ev = data;
7429 struct hci_conn *conn;
7430
7431 bt_dev_dbg(hdev, "status 0x%2.2x", ev->status);
7432
7433 hci_dev_lock(hdev);
7434
7435 conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(ev->handle));
7436 if (conn) {
7437 /* Only update the stored rate parameters on success; on
7438 * failure the values in the event are not valid. Userspace is
7439 * notified either way.
7440 */
7441 if (!ev->status) {
7442 conn->le_rate_interval = le16_to_cpu(ev->interval);
7443 conn->le_subrate = le16_to_cpu(ev->subrate);
7444 conn->le_rate_latency = le16_to_cpu(ev->latency);
7445 conn->le_cont_num = le16_to_cpu(ev->cont_number);
7446 conn->le_rate_supv_timeout =
7447 le16_to_cpu(ev->supv_timeout);
7448 }
7449 mgmt_conn_subrate_notify(hdev, conn, ev->status);
7450 }
7451
7452 hci_dev_unlock(hdev);
7453 }
7454
7455 #define HCI_LE_EV_VL(_op, _func, _min_len, _max_len) \
7456 [_op] = { \
7457 .func = _func, \
7458 .min_len = _min_len, \
7459 .max_len = _max_len, \
7460 }
7461
7462 #define HCI_LE_EV(_op, _func, _len) \
7463 HCI_LE_EV_VL(_op, _func, _len, _len)
7464
7465 #define HCI_LE_EV_STATUS(_op, _func) \
7466 HCI_LE_EV(_op, _func, sizeof(struct hci_ev_status))
7467
7468 /* Entries in this table shall have their position according to the subevent
7469 * opcode they handle so the use of the macros above is recommend since it does
7470 * attempt to initialize at its proper index using Designated Initializers that
7471 * way events without a callback function can be omitted.
7472 */
7473 static const struct hci_le_ev {
7474 void (*func)(struct hci_dev *hdev, void *data, struct sk_buff *skb);
7475 u16 min_len;
7476 u16 max_len;
7477 } hci_le_ev_table[U8_MAX + 1] = {
7478 /* [0x01 = HCI_EV_LE_CONN_COMPLETE] */
7479 HCI_LE_EV(HCI_EV_LE_CONN_COMPLETE, hci_le_conn_complete_evt,
7480 sizeof(struct hci_ev_le_conn_complete)),
7481 /* [0x02 = HCI_EV_LE_ADVERTISING_REPORT] */
7482 HCI_LE_EV_VL(HCI_EV_LE_ADVERTISING_REPORT, hci_le_adv_report_evt,
7483 sizeof(struct hci_ev_le_advertising_report),
7484 HCI_MAX_EVENT_SIZE),
7485 /* [0x03 = HCI_EV_LE_CONN_UPDATE_COMPLETE] */
7486 HCI_LE_EV(HCI_EV_LE_CONN_UPDATE_COMPLETE,
7487 hci_le_conn_update_complete_evt,
7488 sizeof(struct hci_ev_le_conn_update_complete)),
7489 /* [0x04 = HCI_EV_LE_REMOTE_FEAT_COMPLETE] */
7490 HCI_LE_EV(HCI_EV_LE_REMOTE_FEAT_COMPLETE,
7491 hci_le_remote_feat_complete_evt,
7492 sizeof(struct hci_ev_le_remote_feat_complete)),
7493 /* [0x05 = HCI_EV_LE_LTK_REQ] */
7494 HCI_LE_EV(HCI_EV_LE_LTK_REQ, hci_le_ltk_request_evt,
7495 sizeof(struct hci_ev_le_ltk_req)),
7496 /* [0x06 = HCI_EV_LE_REMOTE_CONN_PARAM_REQ] */
7497 HCI_LE_EV(HCI_EV_LE_REMOTE_CONN_PARAM_REQ,
7498 hci_le_remote_conn_param_req_evt,
7499 sizeof(struct hci_ev_le_remote_conn_param_req)),
7500 /* [0x0a = HCI_EV_LE_ENHANCED_CONN_COMPLETE] */
7501 HCI_LE_EV(HCI_EV_LE_ENHANCED_CONN_COMPLETE,
7502 hci_le_enh_conn_complete_evt,
7503 sizeof(struct hci_ev_le_enh_conn_complete)),
7504 /* [0x0b = HCI_EV_LE_DIRECT_ADV_REPORT] */
7505 HCI_LE_EV_VL(HCI_EV_LE_DIRECT_ADV_REPORT, hci_le_direct_adv_report_evt,
7506 sizeof(struct hci_ev_le_direct_adv_report),
7507 HCI_MAX_EVENT_SIZE),
7508 /* [0x0c = HCI_EV_LE_PHY_UPDATE_COMPLETE] */
7509 HCI_LE_EV(HCI_EV_LE_PHY_UPDATE_COMPLETE, hci_le_phy_update_evt,
7510 sizeof(struct hci_ev_le_phy_update_complete)),
7511 /* [0x0d = HCI_EV_LE_EXT_ADV_REPORT] */
7512 HCI_LE_EV_VL(HCI_EV_LE_EXT_ADV_REPORT, hci_le_ext_adv_report_evt,
7513 sizeof(struct hci_ev_le_ext_adv_report),
7514 HCI_MAX_EVENT_SIZE),
7515 /* [0x0e = HCI_EV_LE_PA_SYNC_ESTABLISHED] */
7516 HCI_LE_EV(HCI_EV_LE_PA_SYNC_ESTABLISHED,
7517 hci_le_pa_sync_established_evt,
7518 sizeof(struct hci_ev_le_pa_sync_established)),
7519 /* [0x0f = HCI_EV_LE_PER_ADV_REPORT] */
7520 HCI_LE_EV_VL(HCI_EV_LE_PER_ADV_REPORT,
7521 hci_le_per_adv_report_evt,
7522 sizeof(struct hci_ev_le_per_adv_report),
7523 HCI_MAX_EVENT_SIZE),
7524 /* [0x10 = HCI_EV_LE_PA_SYNC_LOST] */
7525 HCI_LE_EV(HCI_EV_LE_PA_SYNC_LOST, hci_le_pa_sync_lost_evt,
7526 sizeof(struct hci_ev_le_pa_sync_lost)),
7527 /* [0x12 = HCI_EV_LE_EXT_ADV_SET_TERM] */
7528 HCI_LE_EV(HCI_EV_LE_EXT_ADV_SET_TERM, hci_le_ext_adv_term_evt,
7529 sizeof(struct hci_evt_le_ext_adv_set_term)),
7530 /* [0x18 = HCI_EVT_LE_PAST_RECEIVED] */
7531 HCI_LE_EV(HCI_EV_LE_PAST_RECEIVED,
7532 hci_le_past_received_evt,
7533 sizeof(struct hci_ev_le_past_received)),
7534 /* [0x19 = HCI_EVT_LE_CIS_ESTABLISHED] */
7535 HCI_LE_EV(HCI_EVT_LE_CIS_ESTABLISHED, hci_le_cis_established_evt,
7536 sizeof(struct hci_evt_le_cis_established)),
7537 /* [0x1a = HCI_EVT_LE_CIS_REQ] */
7538 HCI_LE_EV(HCI_EVT_LE_CIS_REQ, hci_le_cis_req_evt,
7539 sizeof(struct hci_evt_le_cis_req)),
7540 /* [0x1b = HCI_EVT_LE_CREATE_BIG_COMPLETE] */
7541 HCI_LE_EV_VL(HCI_EVT_LE_CREATE_BIG_COMPLETE,
7542 hci_le_create_big_complete_evt,
7543 sizeof(struct hci_evt_le_create_big_complete),
7544 HCI_MAX_EVENT_SIZE),
7545 /* [0x1d = HCI_EV_LE_BIG_SYNC_ESTABLISHED] */
7546 HCI_LE_EV_VL(HCI_EVT_LE_BIG_SYNC_ESTABLISHED,
7547 hci_le_big_sync_established_evt,
7548 sizeof(struct hci_evt_le_big_sync_established),
7549 HCI_MAX_EVENT_SIZE),
7550 /* [0x1e = HCI_EVT_LE_BIG_SYNC_LOST] */
7551 HCI_LE_EV_VL(HCI_EVT_LE_BIG_SYNC_LOST,
7552 hci_le_big_sync_lost_evt,
7553 sizeof(struct hci_evt_le_big_sync_lost),
7554 HCI_MAX_EVENT_SIZE),
7555 /* [0x22 = HCI_EVT_LE_BIG_INFO_ADV_REPORT] */
7556 HCI_LE_EV_VL(HCI_EVT_LE_BIG_INFO_ADV_REPORT,
7557 hci_le_big_info_adv_report_evt,
7558 sizeof(struct hci_evt_le_big_info_adv_report),
7559 HCI_MAX_EVENT_SIZE),
7560 /* [0x2b = HCI_EVT_LE_ALL_REMOTE_FEATURES_COMPLETE] */
7561 HCI_LE_EV_VL(HCI_EVT_LE_ALL_REMOTE_FEATURES_COMPLETE,
7562 hci_le_read_all_remote_features_evt,
7563 sizeof(struct
7564 hci_evt_le_read_all_remote_features_complete),
7565 HCI_MAX_EVENT_SIZE),
7566 /* [0x37 = HCI_EVT_LE_CONN_RATE_CHANGE] */
7567 HCI_LE_EV(HCI_EVT_LE_CONN_RATE_CHANGE, hci_le_conn_rate_change_evt,
7568 sizeof(struct hci_evt_le_conn_rate_change)),
7569 };
7570
hci_le_meta_evt(struct hci_dev * hdev,void * data,struct sk_buff * skb,u16 * opcode,u8 * status,hci_req_complete_t * req_complete,hci_req_complete_skb_t * req_complete_skb)7571 static void hci_le_meta_evt(struct hci_dev *hdev, void *data,
7572 struct sk_buff *skb, u16 *opcode, u8 *status,
7573 hci_req_complete_t *req_complete,
7574 hci_req_complete_skb_t *req_complete_skb)
7575 {
7576 struct hci_ev_le_meta *ev = data;
7577 const struct hci_le_ev *subev;
7578
7579 bt_dev_dbg(hdev, "subevent 0x%2.2x", ev->subevent);
7580
7581 /* Only match event if command OGF is for LE */
7582 if (hdev->req_skb &&
7583 (hci_opcode_ogf(hci_skb_opcode(hdev->req_skb)) == 0x08 ||
7584 hci_skb_opcode(hdev->req_skb) == HCI_OP_NOP) &&
7585 hci_skb_event(hdev->req_skb) == ev->subevent) {
7586 *opcode = hci_skb_opcode(hdev->req_skb);
7587 hci_req_cmd_complete(hdev, *opcode, 0x00, req_complete,
7588 req_complete_skb);
7589 }
7590
7591 subev = &hci_le_ev_table[ev->subevent];
7592 if (!subev->func)
7593 return;
7594
7595 if (skb->len < subev->min_len) {
7596 bt_dev_err(hdev, "unexpected subevent 0x%2.2x length: %u < %u",
7597 ev->subevent, skb->len, subev->min_len);
7598 return;
7599 }
7600
7601 /* Just warn if the length is over max_len size it still be
7602 * possible to partially parse the event so leave to callback to
7603 * decide if that is acceptable.
7604 */
7605 if (skb->len > subev->max_len)
7606 bt_dev_warn(hdev, "unexpected subevent 0x%2.2x length: %u > %u",
7607 ev->subevent, skb->len, subev->max_len);
7608 data = hci_le_ev_skb_pull(hdev, skb, ev->subevent, subev->min_len);
7609 if (!data)
7610 return;
7611
7612 subev->func(hdev, data, skb);
7613 }
7614
hci_vendor_evt(struct hci_dev * hdev,void * data,struct sk_buff * skb)7615 static void hci_vendor_evt(struct hci_dev *hdev, void *data, struct sk_buff *skb)
7616 {
7617 if (hdev->handle_ev_vendor && hdev->handle_ev_vendor(hdev, skb))
7618 return;
7619
7620 msft_vendor_evt(hdev, data, skb);
7621 }
7622
hci_get_cmd_complete(struct hci_dev * hdev,u16 opcode,u8 event,struct sk_buff * skb)7623 static bool hci_get_cmd_complete(struct hci_dev *hdev, u16 opcode,
7624 u8 event, struct sk_buff *skb)
7625 {
7626 struct hci_ev_cmd_complete *ev;
7627 struct hci_event_hdr *hdr;
7628
7629 if (!skb)
7630 return false;
7631
7632 hdr = hci_ev_skb_pull(hdev, skb, event, sizeof(*hdr));
7633 if (!hdr)
7634 return false;
7635
7636 if (event) {
7637 if (hdr->evt != event)
7638 return false;
7639 return true;
7640 }
7641
7642 /* Check if request ended in Command Status - no way to retrieve
7643 * any extra parameters in this case.
7644 */
7645 if (hdr->evt == HCI_EV_CMD_STATUS)
7646 return false;
7647
7648 if (hdr->evt != HCI_EV_CMD_COMPLETE) {
7649 bt_dev_err(hdev, "last event is not cmd complete (0x%2.2x)",
7650 hdr->evt);
7651 return false;
7652 }
7653
7654 ev = hci_cc_skb_pull(hdev, skb, opcode, sizeof(*ev));
7655 if (!ev)
7656 return false;
7657
7658 if (opcode != __le16_to_cpu(ev->opcode)) {
7659 BT_DBG("opcode doesn't match (0x%2.2x != 0x%2.2x)", opcode,
7660 __le16_to_cpu(ev->opcode));
7661 return false;
7662 }
7663
7664 return true;
7665 }
7666
hci_store_wake_reason(struct hci_dev * hdev,const bdaddr_t * bdaddr,u8 addr_type)7667 static void hci_store_wake_reason(struct hci_dev *hdev,
7668 const bdaddr_t *bdaddr, u8 addr_type)
7669 __must_hold(&hdev->lock)
7670 {
7671 lockdep_assert_held(&hdev->lock);
7672
7673 /* If we are currently suspended and this is the first BT event seen,
7674 * save the wake reason associated with the event.
7675 */
7676 if (!hdev->suspended || hdev->wake_reason)
7677 return;
7678
7679 if (!bdaddr) {
7680 hdev->wake_reason = MGMT_WAKE_REASON_UNEXPECTED;
7681 return;
7682 }
7683
7684 /* Default to remote wake. Values for wake_reason are documented in the
7685 * Bluez mgmt api docs.
7686 */
7687 hdev->wake_reason = MGMT_WAKE_REASON_REMOTE_WAKE;
7688 bacpy(&hdev->wake_addr, bdaddr);
7689 hdev->wake_addr_type = addr_type;
7690 }
7691
7692 #define HCI_EV_VL(_op, _func, _min_len, _max_len) \
7693 [_op] = { \
7694 .req = false, \
7695 .func = _func, \
7696 .min_len = _min_len, \
7697 .max_len = _max_len, \
7698 }
7699
7700 #define HCI_EV(_op, _func, _len) \
7701 HCI_EV_VL(_op, _func, _len, _len)
7702
7703 #define HCI_EV_STATUS(_op, _func) \
7704 HCI_EV(_op, _func, sizeof(struct hci_ev_status))
7705
7706 #define HCI_EV_REQ_VL(_op, _func, _min_len, _max_len) \
7707 [_op] = { \
7708 .req = true, \
7709 .func_req = _func, \
7710 .min_len = _min_len, \
7711 .max_len = _max_len, \
7712 }
7713
7714 #define HCI_EV_REQ(_op, _func, _len) \
7715 HCI_EV_REQ_VL(_op, _func, _len, _len)
7716
7717 /* Entries in this table shall have their position according to the event opcode
7718 * they handle so the use of the macros above is recommend since it does attempt
7719 * to initialize at its proper index using Designated Initializers that way
7720 * events without a callback function don't have entered.
7721 */
7722 static const struct hci_ev {
7723 bool req;
7724 union {
7725 void (*func)(struct hci_dev *hdev, void *data,
7726 struct sk_buff *skb);
7727 void (*func_req)(struct hci_dev *hdev, void *data,
7728 struct sk_buff *skb, u16 *opcode, u8 *status,
7729 hci_req_complete_t *req_complete,
7730 hci_req_complete_skb_t *req_complete_skb);
7731 };
7732 u16 min_len;
7733 u16 max_len;
7734 } hci_ev_table[U8_MAX + 1] = {
7735 /* [0x01 = HCI_EV_INQUIRY_COMPLETE] */
7736 HCI_EV_STATUS(HCI_EV_INQUIRY_COMPLETE, hci_inquiry_complete_evt),
7737 /* [0x02 = HCI_EV_INQUIRY_RESULT] */
7738 HCI_EV_VL(HCI_EV_INQUIRY_RESULT, hci_inquiry_result_evt,
7739 sizeof(struct hci_ev_inquiry_result), HCI_MAX_EVENT_PLEN),
7740 /* [0x03 = HCI_EV_CONN_COMPLETE] */
7741 HCI_EV(HCI_EV_CONN_COMPLETE, hci_conn_complete_evt,
7742 sizeof(struct hci_ev_conn_complete)),
7743 /* [0x04 = HCI_EV_CONN_REQUEST] */
7744 HCI_EV(HCI_EV_CONN_REQUEST, hci_conn_request_evt,
7745 sizeof(struct hci_ev_conn_request)),
7746 /* [0x05 = HCI_EV_DISCONN_COMPLETE] */
7747 HCI_EV(HCI_EV_DISCONN_COMPLETE, hci_disconn_complete_evt,
7748 sizeof(struct hci_ev_disconn_complete)),
7749 /* [0x06 = HCI_EV_AUTH_COMPLETE] */
7750 HCI_EV(HCI_EV_AUTH_COMPLETE, hci_auth_complete_evt,
7751 sizeof(struct hci_ev_auth_complete)),
7752 /* [0x07 = HCI_EV_REMOTE_NAME] */
7753 HCI_EV(HCI_EV_REMOTE_NAME, hci_remote_name_evt,
7754 sizeof(struct hci_ev_remote_name)),
7755 /* [0x08 = HCI_EV_ENCRYPT_CHANGE] */
7756 HCI_EV(HCI_EV_ENCRYPT_CHANGE, hci_encrypt_change_evt,
7757 sizeof(struct hci_ev_encrypt_change)),
7758 /* [0x09 = HCI_EV_CHANGE_LINK_KEY_COMPLETE] */
7759 HCI_EV(HCI_EV_CHANGE_LINK_KEY_COMPLETE,
7760 hci_change_link_key_complete_evt,
7761 sizeof(struct hci_ev_change_link_key_complete)),
7762 /* [0x0b = HCI_EV_REMOTE_FEATURES] */
7763 HCI_EV(HCI_EV_REMOTE_FEATURES, hci_remote_features_evt,
7764 sizeof(struct hci_ev_remote_features)),
7765 /* [0x0e = HCI_EV_CMD_COMPLETE] */
7766 HCI_EV_REQ_VL(HCI_EV_CMD_COMPLETE, hci_cmd_complete_evt,
7767 sizeof(struct hci_ev_cmd_complete), HCI_MAX_EVENT_PLEN),
7768 /* [0x0f = HCI_EV_CMD_STATUS] */
7769 HCI_EV_REQ(HCI_EV_CMD_STATUS, hci_cmd_status_evt,
7770 sizeof(struct hci_ev_cmd_status)),
7771 /* [0x10 = HCI_EV_CMD_STATUS] */
7772 HCI_EV(HCI_EV_HARDWARE_ERROR, hci_hardware_error_evt,
7773 sizeof(struct hci_ev_hardware_error)),
7774 /* [0x12 = HCI_EV_ROLE_CHANGE] */
7775 HCI_EV(HCI_EV_ROLE_CHANGE, hci_role_change_evt,
7776 sizeof(struct hci_ev_role_change)),
7777 /* [0x13 = HCI_EV_NUM_COMP_PKTS] */
7778 HCI_EV_VL(HCI_EV_NUM_COMP_PKTS, hci_num_comp_pkts_evt,
7779 sizeof(struct hci_ev_num_comp_pkts), HCI_MAX_EVENT_PLEN),
7780 /* [0x14 = HCI_EV_MODE_CHANGE] */
7781 HCI_EV(HCI_EV_MODE_CHANGE, hci_mode_change_evt,
7782 sizeof(struct hci_ev_mode_change)),
7783 /* [0x16 = HCI_EV_PIN_CODE_REQ] */
7784 HCI_EV(HCI_EV_PIN_CODE_REQ, hci_pin_code_request_evt,
7785 sizeof(struct hci_ev_pin_code_req)),
7786 /* [0x17 = HCI_EV_LINK_KEY_REQ] */
7787 HCI_EV(HCI_EV_LINK_KEY_REQ, hci_link_key_request_evt,
7788 sizeof(struct hci_ev_link_key_req)),
7789 /* [0x18 = HCI_EV_LINK_KEY_NOTIFY] */
7790 HCI_EV(HCI_EV_LINK_KEY_NOTIFY, hci_link_key_notify_evt,
7791 sizeof(struct hci_ev_link_key_notify)),
7792 /* [0x1c = HCI_EV_CLOCK_OFFSET] */
7793 HCI_EV(HCI_EV_CLOCK_OFFSET, hci_clock_offset_evt,
7794 sizeof(struct hci_ev_clock_offset)),
7795 /* [0x1d = HCI_EV_PKT_TYPE_CHANGE] */
7796 HCI_EV(HCI_EV_PKT_TYPE_CHANGE, hci_pkt_type_change_evt,
7797 sizeof(struct hci_ev_pkt_type_change)),
7798 /* [0x20 = HCI_EV_PSCAN_REP_MODE] */
7799 HCI_EV(HCI_EV_PSCAN_REP_MODE, hci_pscan_rep_mode_evt,
7800 sizeof(struct hci_ev_pscan_rep_mode)),
7801 /* [0x22 = HCI_EV_INQUIRY_RESULT_WITH_RSSI] */
7802 HCI_EV_VL(HCI_EV_INQUIRY_RESULT_WITH_RSSI,
7803 hci_inquiry_result_with_rssi_evt,
7804 sizeof(struct hci_ev_inquiry_result_rssi),
7805 HCI_MAX_EVENT_PLEN),
7806 /* [0x23 = HCI_EV_REMOTE_EXT_FEATURES] */
7807 HCI_EV(HCI_EV_REMOTE_EXT_FEATURES, hci_remote_ext_features_evt,
7808 sizeof(struct hci_ev_remote_ext_features)),
7809 /* [0x2c = HCI_EV_SYNC_CONN_COMPLETE] */
7810 HCI_EV(HCI_EV_SYNC_CONN_COMPLETE, hci_sync_conn_complete_evt,
7811 sizeof(struct hci_ev_sync_conn_complete)),
7812 /* [0x2f = HCI_EV_EXTENDED_INQUIRY_RESULT] */
7813 HCI_EV_VL(HCI_EV_EXTENDED_INQUIRY_RESULT,
7814 hci_extended_inquiry_result_evt,
7815 sizeof(struct hci_ev_ext_inquiry_result), HCI_MAX_EVENT_PLEN),
7816 /* [0x30 = HCI_EV_KEY_REFRESH_COMPLETE] */
7817 HCI_EV(HCI_EV_KEY_REFRESH_COMPLETE, hci_key_refresh_complete_evt,
7818 sizeof(struct hci_ev_key_refresh_complete)),
7819 /* [0x31 = HCI_EV_IO_CAPA_REQUEST] */
7820 HCI_EV(HCI_EV_IO_CAPA_REQUEST, hci_io_capa_request_evt,
7821 sizeof(struct hci_ev_io_capa_request)),
7822 /* [0x32 = HCI_EV_IO_CAPA_REPLY] */
7823 HCI_EV(HCI_EV_IO_CAPA_REPLY, hci_io_capa_reply_evt,
7824 sizeof(struct hci_ev_io_capa_reply)),
7825 /* [0x33 = HCI_EV_USER_CONFIRM_REQUEST] */
7826 HCI_EV(HCI_EV_USER_CONFIRM_REQUEST, hci_user_confirm_request_evt,
7827 sizeof(struct hci_ev_user_confirm_req)),
7828 /* [0x34 = HCI_EV_USER_PASSKEY_REQUEST] */
7829 HCI_EV(HCI_EV_USER_PASSKEY_REQUEST, hci_user_passkey_request_evt,
7830 sizeof(struct hci_ev_user_passkey_req)),
7831 /* [0x35 = HCI_EV_REMOTE_OOB_DATA_REQUEST] */
7832 HCI_EV(HCI_EV_REMOTE_OOB_DATA_REQUEST, hci_remote_oob_data_request_evt,
7833 sizeof(struct hci_ev_remote_oob_data_request)),
7834 /* [0x36 = HCI_EV_SIMPLE_PAIR_COMPLETE] */
7835 HCI_EV(HCI_EV_SIMPLE_PAIR_COMPLETE, hci_simple_pair_complete_evt,
7836 sizeof(struct hci_ev_simple_pair_complete)),
7837 /* [0x3b = HCI_EV_USER_PASSKEY_NOTIFY] */
7838 HCI_EV(HCI_EV_USER_PASSKEY_NOTIFY, hci_user_passkey_notify_evt,
7839 sizeof(struct hci_ev_user_passkey_notify)),
7840 /* [0x3c = HCI_EV_KEYPRESS_NOTIFY] */
7841 HCI_EV(HCI_EV_KEYPRESS_NOTIFY, hci_keypress_notify_evt,
7842 sizeof(struct hci_ev_keypress_notify)),
7843 /* [0x3d = HCI_EV_REMOTE_HOST_FEATURES] */
7844 HCI_EV(HCI_EV_REMOTE_HOST_FEATURES, hci_remote_host_features_evt,
7845 sizeof(struct hci_ev_remote_host_features)),
7846 /* [0x3e = HCI_EV_LE_META] */
7847 HCI_EV_REQ_VL(HCI_EV_LE_META, hci_le_meta_evt,
7848 sizeof(struct hci_ev_le_meta), HCI_MAX_EVENT_PLEN),
7849 /* [0xff = HCI_EV_VENDOR] */
7850 HCI_EV_VL(HCI_EV_VENDOR, hci_vendor_evt, 0, HCI_MAX_EVENT_PLEN),
7851 };
7852
hci_event_func(struct hci_dev * hdev,u8 event,struct sk_buff * skb,u16 * opcode,u8 * status,hci_req_complete_t * req_complete,hci_req_complete_skb_t * req_complete_skb)7853 static void hci_event_func(struct hci_dev *hdev, u8 event, struct sk_buff *skb,
7854 u16 *opcode, u8 *status,
7855 hci_req_complete_t *req_complete,
7856 hci_req_complete_skb_t *req_complete_skb)
7857 {
7858 const struct hci_ev *ev = &hci_ev_table[event];
7859 void *data;
7860
7861 if (!ev->func)
7862 return;
7863
7864 if (skb->len < ev->min_len) {
7865 bt_dev_err(hdev, "unexpected event 0x%2.2x length: %u < %u",
7866 event, skb->len, ev->min_len);
7867 return;
7868 }
7869
7870 /* Just warn if the length is over max_len size it still be
7871 * possible to partially parse the event so leave to callback to
7872 * decide if that is acceptable.
7873 */
7874 if (skb->len > ev->max_len)
7875 bt_dev_warn_ratelimited(hdev,
7876 "unexpected event 0x%2.2x length: %u > %u",
7877 event, skb->len, ev->max_len);
7878
7879 data = hci_ev_skb_pull(hdev, skb, event, ev->min_len);
7880 if (!data)
7881 return;
7882
7883 if (ev->req)
7884 ev->func_req(hdev, data, skb, opcode, status, req_complete,
7885 req_complete_skb);
7886 else
7887 ev->func(hdev, data, skb);
7888 }
7889
hci_event_packet(struct hci_dev * hdev,struct sk_buff * skb)7890 void hci_event_packet(struct hci_dev *hdev, struct sk_buff *skb)
7891 {
7892 struct hci_event_hdr *hdr = (void *) skb->data;
7893 hci_req_complete_t req_complete = NULL;
7894 hci_req_complete_skb_t req_complete_skb = NULL;
7895 struct sk_buff *orig_skb = NULL;
7896 u8 status = 0, event, req_evt = 0;
7897 u16 opcode = HCI_OP_NOP;
7898
7899 if (skb->len < sizeof(*hdr)) {
7900 bt_dev_err(hdev, "Malformed HCI Event");
7901 goto done;
7902 }
7903
7904 hci_dev_lock(hdev);
7905 kfree_skb(hdev->recv_event);
7906 hdev->recv_event = skb_clone(skb, GFP_KERNEL);
7907 hci_dev_unlock(hdev);
7908
7909 event = hdr->evt;
7910 if (!event) {
7911 bt_dev_warn(hdev, "Received unexpected HCI Event 0x%2.2x",
7912 event);
7913 goto done;
7914 }
7915
7916 /* Only match event if command OGF is not for LE */
7917 if (hdev->req_skb &&
7918 hci_opcode_ogf(hci_skb_opcode(hdev->req_skb)) != 0x08 &&
7919 hci_skb_event(hdev->req_skb) == event) {
7920 hci_req_cmd_complete(hdev, hci_skb_opcode(hdev->req_skb),
7921 status, &req_complete, &req_complete_skb);
7922 req_evt = event;
7923 }
7924
7925 /* If it looks like we might end up having to call
7926 * req_complete_skb, store a pristine copy of the skb since the
7927 * various handlers may modify the original one through
7928 * skb_pull() calls, etc.
7929 */
7930 if (req_complete_skb || event == HCI_EV_CMD_STATUS ||
7931 event == HCI_EV_CMD_COMPLETE)
7932 orig_skb = skb_clone(skb, GFP_KERNEL);
7933
7934 skb_pull(skb, HCI_EVENT_HDR_SIZE);
7935
7936 bt_dev_dbg(hdev, "event 0x%2.2x", event);
7937
7938 hci_event_func(hdev, event, skb, &opcode, &status, &req_complete,
7939 &req_complete_skb);
7940
7941 hci_dev_lock(hdev);
7942 hci_store_wake_reason(hdev, NULL, 0);
7943 hci_dev_unlock(hdev);
7944
7945 if (req_complete) {
7946 req_complete(hdev, status, opcode);
7947 } else if (req_complete_skb) {
7948 if (!hci_get_cmd_complete(hdev, opcode, req_evt, orig_skb)) {
7949 kfree_skb(orig_skb);
7950 orig_skb = NULL;
7951 }
7952 req_complete_skb(hdev, status, opcode, orig_skb);
7953 }
7954
7955 done:
7956 kfree_skb(orig_skb);
7957 kfree_skb(skb);
7958 hdev->stat.evt_rx++;
7959 }
7960