1 // SPDX-License-Identifier: GPL-2.0
2 /*
3 BlueZ - Bluetooth protocol stack for Linux
4 Copyright (C) 2000-2001 Qualcomm Incorporated
5
6 Written 2000,2001 by Maxim Krasnyansky <maxk@qualcomm.com>
7
8 THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS
9 OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
10 FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT OF THIRD PARTY RIGHTS.
11 IN NO EVENT SHALL THE COPYRIGHT HOLDER(S) AND AUTHOR(S) BE LIABLE FOR ANY
12 CLAIM, OR ANY SPECIAL INDIRECT OR CONSEQUENTIAL DAMAGES, OR ANY DAMAGES
13 WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
14 ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
15 OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
16
17 ALL LIABILITY, INCLUDING LIABILITY FOR INFRINGEMENT OF ANY PATENTS,
18 COPYRIGHTS, TRADEMARKS OR OTHER RIGHTS, RELATING TO USE OF THIS
19 SOFTWARE IS DISCLAIMED.
20 */
21
22 /* Bluetooth address family and sockets. */
23
24 #include <linux/module.h>
25 #include <linux/debugfs.h>
26 #include <linux/stringify.h>
27 #include <linux/sched/signal.h>
28
29 #include <asm/ioctls.h>
30
31 #include <net/bluetooth/bluetooth.h>
32 #include <linux/proc_fs.h>
33
34 #include <linux/ethtool.h>
35 #include <linux/sockios.h>
36
37 #include "leds.h"
38 #include "selftest.h"
39
40 /* Bluetooth sockets */
41 #define BT_MAX_PROTO (BTPROTO_LAST + 1)
42 static const struct net_proto_family *bt_proto[BT_MAX_PROTO];
43 static DEFINE_RWLOCK(bt_proto_lock);
44
45 static struct lock_class_key bt_lock_key[BT_MAX_PROTO];
46 static const char *const bt_key_strings[BT_MAX_PROTO] = {
47 "sk_lock-AF_BLUETOOTH-BTPROTO_L2CAP",
48 "sk_lock-AF_BLUETOOTH-BTPROTO_HCI",
49 "sk_lock-AF_BLUETOOTH-BTPROTO_SCO",
50 "sk_lock-AF_BLUETOOTH-BTPROTO_RFCOMM",
51 "sk_lock-AF_BLUETOOTH-BTPROTO_BNEP",
52 "sk_lock-AF_BLUETOOTH-BTPROTO_CMTP",
53 "sk_lock-AF_BLUETOOTH-BTPROTO_HIDP",
54 "sk_lock-AF_BLUETOOTH-BTPROTO_AVDTP",
55 "sk_lock-AF_BLUETOOTH-BTPROTO_ISO",
56 };
57
58 static struct lock_class_key bt_slock_key[BT_MAX_PROTO];
59 static const char *const bt_slock_key_strings[BT_MAX_PROTO] = {
60 "slock-AF_BLUETOOTH-BTPROTO_L2CAP",
61 "slock-AF_BLUETOOTH-BTPROTO_HCI",
62 "slock-AF_BLUETOOTH-BTPROTO_SCO",
63 "slock-AF_BLUETOOTH-BTPROTO_RFCOMM",
64 "slock-AF_BLUETOOTH-BTPROTO_BNEP",
65 "slock-AF_BLUETOOTH-BTPROTO_CMTP",
66 "slock-AF_BLUETOOTH-BTPROTO_HIDP",
67 "slock-AF_BLUETOOTH-BTPROTO_AVDTP",
68 "slock-AF_BLUETOOTH-BTPROTO_ISO",
69 };
70
bt_sock_reclassify_lock(struct sock * sk,int proto)71 void bt_sock_reclassify_lock(struct sock *sk, int proto)
72 {
73 BUG_ON(!sk);
74 BUG_ON(!sock_allow_reclassification(sk));
75
76 sock_lock_init_class_and_name(sk,
77 bt_slock_key_strings[proto], &bt_slock_key[proto],
78 bt_key_strings[proto], &bt_lock_key[proto]);
79 }
80 EXPORT_SYMBOL(bt_sock_reclassify_lock);
81
bt_sock_register(int proto,const struct net_proto_family * ops)82 int bt_sock_register(int proto, const struct net_proto_family *ops)
83 {
84 int err = 0;
85
86 if (proto < 0 || proto >= BT_MAX_PROTO)
87 return -EINVAL;
88
89 write_lock(&bt_proto_lock);
90
91 if (bt_proto[proto])
92 err = -EEXIST;
93 else
94 bt_proto[proto] = ops;
95
96 write_unlock(&bt_proto_lock);
97
98 return err;
99 }
100 EXPORT_SYMBOL(bt_sock_register);
101
bt_sock_unregister(int proto)102 void bt_sock_unregister(int proto)
103 {
104 if (proto < 0 || proto >= BT_MAX_PROTO)
105 return;
106
107 write_lock(&bt_proto_lock);
108 bt_proto[proto] = NULL;
109 write_unlock(&bt_proto_lock);
110 }
111 EXPORT_SYMBOL(bt_sock_unregister);
112
bt_sock_create(struct net * net,struct socket * sock,int proto,int kern)113 static int bt_sock_create(struct net *net, struct socket *sock, int proto,
114 int kern)
115 {
116 int err;
117
118 if (net != &init_net)
119 return -EAFNOSUPPORT;
120
121 if (proto < 0 || proto >= BT_MAX_PROTO)
122 return -EINVAL;
123
124 if (!bt_proto[proto])
125 request_module("bt-proto-%d", proto);
126
127 err = -EPROTONOSUPPORT;
128
129 read_lock(&bt_proto_lock);
130
131 if (bt_proto[proto] && try_module_get(bt_proto[proto]->owner)) {
132 err = bt_proto[proto]->create(net, sock, proto, kern);
133 if (!err)
134 bt_sock_reclassify_lock(sock->sk, proto);
135 module_put(bt_proto[proto]->owner);
136 }
137
138 read_unlock(&bt_proto_lock);
139
140 return err;
141 }
142
bt_sock_alloc(struct net * net,struct socket * sock,struct proto * prot,int proto,gfp_t prio,int kern)143 struct sock *bt_sock_alloc(struct net *net, struct socket *sock,
144 struct proto *prot, int proto, gfp_t prio, int kern)
145 {
146 struct sock *sk;
147
148 sk = sk_alloc(net, PF_BLUETOOTH, prio, prot, kern);
149 if (!sk)
150 return NULL;
151
152 sock_init_data(sock, sk);
153 INIT_LIST_HEAD(&bt_sk(sk)->accept_q);
154 spin_lock_init(&bt_sk(sk)->accept_q_lock);
155
156 sock_reset_flag(sk, SOCK_ZAPPED);
157
158 sk->sk_protocol = proto;
159 sk->sk_state = BT_OPEN;
160
161 /* Init peer information so it can be properly monitored */
162 if (!kern) {
163 spin_lock(&sk->sk_peer_lock);
164 sk->sk_peer_pid = get_pid(task_tgid(current));
165 sk->sk_peer_cred = get_current_cred();
166 spin_unlock(&sk->sk_peer_lock);
167 }
168
169 return sk;
170 }
171 EXPORT_SYMBOL(bt_sock_alloc);
172
bt_sock_link(struct bt_sock_list * l,struct sock * sk)173 void bt_sock_link(struct bt_sock_list *l, struct sock *sk)
174 {
175 write_lock(&l->lock);
176 sk_add_node(sk, &l->head);
177 write_unlock(&l->lock);
178 }
179 EXPORT_SYMBOL(bt_sock_link);
180
bt_sock_unlink(struct bt_sock_list * l,struct sock * sk)181 void bt_sock_unlink(struct bt_sock_list *l, struct sock *sk)
182 {
183 write_lock(&l->lock);
184 sk_del_node_init(sk);
185 write_unlock(&l->lock);
186 }
187 EXPORT_SYMBOL(bt_sock_unlink);
188
bt_sock_linked(struct bt_sock_list * l,struct sock * s)189 bool bt_sock_linked(struct bt_sock_list *l, struct sock *s)
190 {
191 struct sock *sk;
192
193 if (!l || !s)
194 return false;
195
196 read_lock(&l->lock);
197
198 sk_for_each(sk, &l->head) {
199 if (s == sk) {
200 read_unlock(&l->lock);
201 return true;
202 }
203 }
204
205 read_unlock(&l->lock);
206
207 return false;
208 }
209 EXPORT_SYMBOL(bt_sock_linked);
210
bt_accept_enqueue(struct sock * parent,struct sock * sk,bool bh)211 void bt_accept_enqueue(struct sock *parent, struct sock *sk, bool bh)
212 __context_unsafe(/* conditional locking */)
213 {
214 const struct cred *old_cred;
215 struct pid *old_pid;
216 struct bt_sock *par = bt_sk(parent);
217
218 BT_DBG("parent %p, sk %p", parent, sk);
219
220 sock_hold(sk);
221
222 if (bh)
223 bh_lock_sock_nested(sk);
224 else
225 lock_sock_nested(sk, SINGLE_DEPTH_NESTING);
226
227 bt_sk(sk)->parent = parent;
228
229 spin_lock_bh(&par->accept_q_lock);
230 list_add_tail(&bt_sk(sk)->accept_q, &par->accept_q);
231 sk_acceptq_added(parent);
232 spin_unlock_bh(&par->accept_q_lock);
233
234 /* Copy credentials from parent since for incoming connections the
235 * socket is allocated by the kernel.
236 */
237 spin_lock(&sk->sk_peer_lock);
238 old_pid = sk->sk_peer_pid;
239 old_cred = sk->sk_peer_cred;
240 sk->sk_peer_pid = get_pid(parent->sk_peer_pid);
241 sk->sk_peer_cred = get_cred(parent->sk_peer_cred);
242 spin_unlock(&sk->sk_peer_lock);
243
244 put_pid(old_pid);
245 put_cred(old_cred);
246
247 if (bh)
248 bh_unlock_sock(sk);
249 else
250 release_sock(sk);
251 }
252 EXPORT_SYMBOL(bt_accept_enqueue);
253
254 /* Calling function must hold the sk lock.
255 * bt_sk(sk)->parent must be non-NULL meaning sk is in the parent list.
256 */
bt_accept_unlink(struct sock * sk)257 void bt_accept_unlink(struct sock *sk)
258 {
259 struct sock *parent = bt_sk(sk)->parent;
260
261 BT_DBG("sk %p state %d", sk, sk->sk_state);
262
263 spin_lock_bh(&bt_sk(parent)->accept_q_lock);
264 list_del_init(&bt_sk(sk)->accept_q);
265 sk_acceptq_removed(parent);
266 spin_unlock_bh(&bt_sk(parent)->accept_q_lock);
267 bt_sk(sk)->parent = NULL;
268 sock_put(sk);
269 }
270 EXPORT_SYMBOL(bt_accept_unlink);
271
bt_accept_get(struct sock * parent,struct sock * sk)272 static struct sock *bt_accept_get(struct sock *parent, struct sock *sk)
273 {
274 struct bt_sock *bt = bt_sk(parent);
275 struct sock *next = NULL;
276
277 /* accept_q is modified from child teardown paths too, so take a
278 * temporary reference before dropping the queue lock.
279 */
280 spin_lock_bh(&bt->accept_q_lock);
281
282 if (sk) {
283 if (bt_sk(sk)->parent != parent)
284 goto out;
285
286 if (!list_is_last(&bt_sk(sk)->accept_q, &bt->accept_q)) {
287 next = &list_next_entry(bt_sk(sk), accept_q)->sk;
288 sock_hold(next);
289 }
290 } else if (!list_empty(&bt->accept_q)) {
291 next = &list_first_entry(&bt->accept_q,
292 struct bt_sock, accept_q)->sk;
293 sock_hold(next);
294 }
295
296 out:
297 spin_unlock_bh(&bt->accept_q_lock);
298 return next;
299 }
300
bt_accept_dequeue(struct sock * parent,struct socket * newsock)301 struct sock *bt_accept_dequeue(struct sock *parent, struct socket *newsock)
302 {
303 struct sock *sk, *next;
304
305 BT_DBG("parent %p", parent);
306
307 restart:
308 for (sk = bt_accept_get(parent, NULL); sk; sk = next) {
309 /* The reference from bt_accept_get() keeps sk alive. */
310 lock_sock(sk);
311
312 /* Check sk has not already been unlinked via
313 * bt_accept_unlink() due to serialisation caused by sk locking
314 */
315 if (bt_sk(sk)->parent != parent) {
316 BT_DBG("sk %p, already unlinked", sk);
317 release_sock(sk);
318 sock_put(sk);
319
320 goto restart;
321 }
322
323 next = bt_accept_get(parent, sk);
324
325 /* FIXME: Is this check still needed */
326 if (sk->sk_state == BT_CLOSED) {
327 bt_accept_unlink(sk);
328 release_sock(sk);
329 sock_put(sk);
330 continue;
331 }
332
333 if (sk->sk_state == BT_CONNECTED || !newsock ||
334 test_bit(BT_SK_DEFER_SETUP, &bt_sk(parent)->flags)) {
335 bt_accept_unlink(sk);
336 if (newsock)
337 sock_graft(sk, newsock);
338
339 release_sock(sk);
340 if (next)
341 sock_put(next);
342 return sk;
343 }
344
345 release_sock(sk);
346 sock_put(sk);
347 }
348
349 return NULL;
350 }
351 EXPORT_SYMBOL(bt_accept_dequeue);
352
bt_sock_recvmsg(struct socket * sock,struct msghdr * msg,size_t len,int flags)353 int bt_sock_recvmsg(struct socket *sock, struct msghdr *msg, size_t len,
354 int flags)
355 {
356 struct sock *sk = sock->sk;
357 struct sk_buff *skb;
358 size_t copied;
359 size_t skblen;
360 int err;
361
362 BT_DBG("sock %p sk %p len %zu", sock, sk, len);
363
364 if (flags & MSG_OOB)
365 return -EOPNOTSUPP;
366
367 skb = skb_recv_datagram(sk, flags, &err);
368 if (!skb) {
369 if (sk->sk_shutdown & RCV_SHUTDOWN)
370 err = 0;
371
372 return err;
373 }
374
375 skblen = skb->len;
376 copied = skb->len;
377 if (len < copied) {
378 msg->msg_flags |= MSG_TRUNC;
379 copied = len;
380 }
381
382 skb_reset_transport_header(skb);
383 err = skb_copy_datagram_msg(skb, 0, msg, copied);
384 if (err == 0) {
385 sock_recv_cmsgs(msg, sk, skb);
386
387 if (msg->msg_name && bt_sk(sk)->skb_msg_name)
388 bt_sk(sk)->skb_msg_name(skb, msg->msg_name,
389 &msg->msg_namelen);
390
391 if (test_bit(BT_SK_PKT_STATUS, &bt_sk(sk)->flags)) {
392 u8 pkt_status = hci_skb_pkt_status(skb);
393
394 put_cmsg(msg, SOL_BLUETOOTH, BT_SCM_PKT_STATUS,
395 sizeof(pkt_status), &pkt_status);
396 }
397
398 if (test_bit(BT_SK_PKT_SEQNUM, &bt_sk(sk)->flags)) {
399 u16 pkt_seqnum = hci_skb_pkt_seqnum(skb);
400
401 put_cmsg(msg, SOL_BLUETOOTH, BT_SCM_PKT_SEQNUM,
402 sizeof(pkt_seqnum), &pkt_seqnum);
403 }
404 }
405
406 skb_free_datagram(sk, skb);
407
408 if (flags & MSG_TRUNC)
409 copied = skblen;
410
411 return err ? : copied;
412 }
413 EXPORT_SYMBOL(bt_sock_recvmsg);
414
bt_sock_data_wait(struct sock * sk,long timeo)415 static long bt_sock_data_wait(struct sock *sk, long timeo)
416 {
417 DECLARE_WAITQUEUE(wait, current);
418
419 add_wait_queue(sk_sleep(sk), &wait);
420 for (;;) {
421 set_current_state(TASK_INTERRUPTIBLE);
422
423 if (!skb_queue_empty(&sk->sk_receive_queue))
424 break;
425
426 if (sk->sk_err || (sk->sk_shutdown & RCV_SHUTDOWN))
427 break;
428
429 if (signal_pending(current) || !timeo)
430 break;
431
432 sk_set_bit(SOCKWQ_ASYNC_WAITDATA, sk);
433 release_sock(sk);
434 timeo = schedule_timeout(timeo);
435 lock_sock(sk);
436 sk_clear_bit(SOCKWQ_ASYNC_WAITDATA, sk);
437 }
438
439 __set_current_state(TASK_RUNNING);
440 remove_wait_queue(sk_sleep(sk), &wait);
441 return timeo;
442 }
443
bt_sock_stream_recvmsg(struct socket * sock,struct msghdr * msg,size_t size,int flags)444 int bt_sock_stream_recvmsg(struct socket *sock, struct msghdr *msg,
445 size_t size, int flags)
446 {
447 struct sock *sk = sock->sk;
448 int err = 0;
449 size_t target, copied = 0;
450 long timeo;
451
452 if (flags & MSG_OOB)
453 return -EOPNOTSUPP;
454
455 BT_DBG("sk %p size %zu", sk, size);
456
457 lock_sock(sk);
458
459 target = sock_rcvlowat(sk, flags & MSG_WAITALL, size);
460 timeo = sock_rcvtimeo(sk, flags & MSG_DONTWAIT);
461
462 do {
463 struct sk_buff *skb;
464 int chunk;
465
466 skb = skb_dequeue(&sk->sk_receive_queue);
467 if (!skb) {
468 if (copied >= target)
469 break;
470
471 err = sock_error(sk);
472 if (err)
473 break;
474 if (sk->sk_shutdown & RCV_SHUTDOWN)
475 break;
476
477 err = -EAGAIN;
478 if (!timeo)
479 break;
480
481 timeo = bt_sock_data_wait(sk, timeo);
482
483 if (signal_pending(current)) {
484 err = sock_intr_errno(timeo);
485 goto out;
486 }
487 continue;
488 }
489
490 chunk = min_t(unsigned int, skb->len, size);
491 if (skb_copy_datagram_msg(skb, 0, msg, chunk)) {
492 skb_queue_head(&sk->sk_receive_queue, skb);
493 if (!copied)
494 copied = -EFAULT;
495 break;
496 }
497 copied += chunk;
498 size -= chunk;
499
500 sock_recv_cmsgs(msg, sk, skb);
501
502 if (!(flags & MSG_PEEK)) {
503 int skb_len = skb_headlen(skb);
504
505 if (chunk <= skb_len) {
506 __skb_pull(skb, chunk);
507 } else {
508 struct sk_buff *frag;
509
510 __skb_pull(skb, skb_len);
511 chunk -= skb_len;
512
513 skb_walk_frags(skb, frag) {
514 if (chunk <= frag->len) {
515 /* Pulling partial data */
516 skb->len -= chunk;
517 skb->data_len -= chunk;
518 __skb_pull(frag, chunk);
519 break;
520 } else if (frag->len) {
521 /* Pulling all frag data */
522 chunk -= frag->len;
523 skb->len -= frag->len;
524 skb->data_len -= frag->len;
525 __skb_pull(frag, frag->len);
526 }
527 }
528 }
529
530 if (skb->len) {
531 skb_queue_head(&sk->sk_receive_queue, skb);
532 break;
533 }
534 kfree_skb(skb);
535
536 } else {
537 /* put message back and return */
538 skb_queue_head(&sk->sk_receive_queue, skb);
539 break;
540 }
541 } while (size);
542
543 out:
544 release_sock(sk);
545 return copied ? : err;
546 }
547 EXPORT_SYMBOL(bt_sock_stream_recvmsg);
548
bt_accept_poll(struct sock * parent)549 static inline __poll_t bt_accept_poll(struct sock *parent)
550 {
551 struct bt_sock *bt = bt_sk(parent);
552 struct bt_sock *s;
553 struct sock *sk;
554 __poll_t mask = 0;
555
556 spin_lock_bh(&bt->accept_q_lock);
557 list_for_each_entry(s, &bt->accept_q, accept_q) {
558 int state;
559
560 sk = (struct sock *)s;
561 state = READ_ONCE(sk->sk_state);
562
563 if (state == BT_CONNECTED ||
564 (test_bit(BT_SK_DEFER_SETUP, &bt->flags) &&
565 state == BT_CONNECT2)) {
566 mask = EPOLLIN | EPOLLRDNORM;
567 break;
568 }
569 }
570 spin_unlock_bh(&bt->accept_q_lock);
571
572 return mask;
573 }
574
bt_sock_poll(struct file * file,struct socket * sock,poll_table * wait)575 __poll_t bt_sock_poll(struct file *file, struct socket *sock,
576 poll_table *wait)
577 {
578 struct sock *sk = sock->sk;
579 __poll_t mask = 0;
580
581 poll_wait(file, sk_sleep(sk), wait);
582
583 if (sk->sk_state == BT_LISTEN)
584 return bt_accept_poll(sk);
585
586 if (sk->sk_err || !skb_queue_empty_lockless(&sk->sk_error_queue))
587 mask |= EPOLLERR |
588 (sock_flag(sk, SOCK_SELECT_ERR_QUEUE) ? EPOLLPRI : 0);
589
590 if (sk->sk_shutdown & RCV_SHUTDOWN)
591 mask |= EPOLLRDHUP | EPOLLIN | EPOLLRDNORM;
592
593 if (sk->sk_shutdown == SHUTDOWN_MASK)
594 mask |= EPOLLHUP;
595
596 if (!skb_queue_empty_lockless(&sk->sk_receive_queue))
597 mask |= EPOLLIN | EPOLLRDNORM;
598
599 if (sk->sk_state == BT_CLOSED)
600 mask |= EPOLLHUP;
601
602 if (sk->sk_state == BT_CONNECT ||
603 sk->sk_state == BT_CONNECT2 ||
604 sk->sk_state == BT_CONFIG)
605 return mask;
606
607 if (!test_bit(BT_SK_SUSPEND, &bt_sk(sk)->flags) && sock_writeable(sk))
608 mask |= EPOLLOUT | EPOLLWRNORM | EPOLLWRBAND;
609 else
610 sk_set_bit(SOCKWQ_ASYNC_NOSPACE, sk);
611
612 return mask;
613 }
614 EXPORT_SYMBOL(bt_sock_poll);
615
bt_ethtool_get_ts_info(struct sock * sk,unsigned int index,void __user * useraddr)616 static int bt_ethtool_get_ts_info(struct sock *sk, unsigned int index,
617 void __user *useraddr)
618 {
619 struct ethtool_ts_info info;
620 struct kernel_ethtool_ts_info ts_info = {};
621 int ret;
622
623 ret = hci_ethtool_ts_info(index, sk->sk_protocol, &ts_info);
624 if (ret == -ENODEV)
625 return ret;
626 else if (ret < 0)
627 return -EIO;
628
629 memset(&info, 0, sizeof(info));
630
631 info.cmd = ETHTOOL_GET_TS_INFO;
632 info.so_timestamping = ts_info.so_timestamping;
633 info.phc_index = ts_info.phc_index;
634 info.tx_types = ts_info.tx_types;
635 info.rx_filters = ts_info.rx_filters;
636
637 if (copy_to_user(useraddr, &info, sizeof(info)))
638 return -EFAULT;
639
640 return 0;
641 }
642
bt_ethtool(struct sock * sk,const struct ifreq * ifr,void __user * useraddr)643 static int bt_ethtool(struct sock *sk, const struct ifreq *ifr,
644 void __user *useraddr)
645 {
646 unsigned int index;
647 u32 ethcmd;
648 int n;
649
650 if (copy_from_user(ðcmd, useraddr, sizeof(ethcmd)))
651 return -EFAULT;
652
653 if (sscanf(ifr->ifr_name, "hci%u%n", &index, &n) != 1 ||
654 n != strlen(ifr->ifr_name))
655 return -ENODEV;
656
657 switch (ethcmd) {
658 case ETHTOOL_GET_TS_INFO:
659 return bt_ethtool_get_ts_info(sk, index, useraddr);
660 }
661
662 return -EOPNOTSUPP;
663 }
664
bt_dev_ioctl(struct socket * sock,unsigned int cmd,void __user * arg)665 static int bt_dev_ioctl(struct socket *sock, unsigned int cmd, void __user *arg)
666 {
667 struct sock *sk = sock->sk;
668 struct ifreq ifr = {};
669 void __user *data;
670 char *colon;
671 int ret = -ENOIOCTLCMD;
672
673 if (get_user_ifreq(&ifr, &data, arg))
674 return -EFAULT;
675
676 ifr.ifr_name[IFNAMSIZ - 1] = 0;
677 colon = strchr(ifr.ifr_name, ':');
678 if (colon)
679 *colon = 0;
680
681 switch (cmd) {
682 case SIOCETHTOOL:
683 ret = bt_ethtool(sk, &ifr, data);
684 break;
685 }
686
687 if (colon)
688 *colon = ':';
689
690 if (put_user_ifreq(&ifr, arg))
691 return -EFAULT;
692
693 return ret;
694 }
695
bt_sock_ioctl(struct socket * sock,unsigned int cmd,unsigned long arg)696 int bt_sock_ioctl(struct socket *sock, unsigned int cmd, unsigned long arg)
697 {
698 struct sock *sk = sock->sk;
699 struct sk_buff *skb;
700 long amount;
701 int err;
702
703 BT_DBG("sk %p cmd %x arg %lx", sk, cmd, arg);
704
705 switch (cmd) {
706 case TIOCOUTQ:
707 if (sk->sk_state == BT_LISTEN)
708 return -EINVAL;
709
710 amount = sk->sk_sndbuf - sk_wmem_alloc_get(sk);
711 if (amount < 0)
712 amount = 0;
713 err = put_user(amount, (int __user *)arg);
714 break;
715
716 case TIOCINQ:
717 if (sk->sk_state == BT_LISTEN)
718 return -EINVAL;
719
720 spin_lock(&sk->sk_receive_queue.lock);
721 skb = skb_peek(&sk->sk_receive_queue);
722 amount = skb ? skb->len : 0;
723 spin_unlock(&sk->sk_receive_queue.lock);
724
725 err = put_user(amount, (int __user *)arg);
726 break;
727
728 case SIOCETHTOOL:
729 err = bt_dev_ioctl(sock, cmd, (void __user *)arg);
730 break;
731
732 default:
733 err = -ENOIOCTLCMD;
734 break;
735 }
736
737 return err;
738 }
739 EXPORT_SYMBOL(bt_sock_ioctl);
740
741 /* This function expects the sk lock to be held when called */
bt_sock_wait_state(struct sock * sk,int state,unsigned long timeo)742 int bt_sock_wait_state(struct sock *sk, int state, unsigned long timeo)
743 {
744 DECLARE_WAITQUEUE(wait, current);
745 int err = 0;
746
747 BT_DBG("sk %p", sk);
748
749 add_wait_queue(sk_sleep(sk), &wait);
750 set_current_state(TASK_INTERRUPTIBLE);
751 while (sk->sk_state != state) {
752 if (!timeo) {
753 err = -EINPROGRESS;
754 break;
755 }
756
757 if (signal_pending(current)) {
758 err = sock_intr_errno(timeo);
759 break;
760 }
761
762 release_sock(sk);
763 timeo = schedule_timeout(timeo);
764 lock_sock(sk);
765 set_current_state(TASK_INTERRUPTIBLE);
766
767 err = sock_error(sk);
768 if (err)
769 break;
770 }
771 __set_current_state(TASK_RUNNING);
772 remove_wait_queue(sk_sleep(sk), &wait);
773 return err;
774 }
775 EXPORT_SYMBOL(bt_sock_wait_state);
776
777 /* This function expects the sk lock to be held when called */
bt_sock_wait_ready(struct sock * sk,unsigned int msg_flags)778 int bt_sock_wait_ready(struct sock *sk, unsigned int msg_flags)
779 {
780 DECLARE_WAITQUEUE(wait, current);
781 unsigned long timeo;
782 int err = 0;
783
784 BT_DBG("sk %p", sk);
785
786 timeo = sock_sndtimeo(sk, !!(msg_flags & MSG_DONTWAIT));
787
788 add_wait_queue(sk_sleep(sk), &wait);
789 set_current_state(TASK_INTERRUPTIBLE);
790 while (test_bit(BT_SK_SUSPEND, &bt_sk(sk)->flags)) {
791 if (!timeo) {
792 err = -EAGAIN;
793 break;
794 }
795
796 if (signal_pending(current)) {
797 err = sock_intr_errno(timeo);
798 break;
799 }
800
801 release_sock(sk);
802 timeo = schedule_timeout(timeo);
803 lock_sock(sk);
804 set_current_state(TASK_INTERRUPTIBLE);
805
806 err = sock_error(sk);
807 if (err)
808 break;
809 }
810 __set_current_state(TASK_RUNNING);
811 remove_wait_queue(sk_sleep(sk), &wait);
812
813 return err;
814 }
815 EXPORT_SYMBOL(bt_sock_wait_ready);
816
817 #ifdef CONFIG_PROC_FS
bt_seq_start(struct seq_file * seq,loff_t * pos)818 static void *bt_seq_start(struct seq_file *seq, loff_t *pos)
819 __acquires_shared(&((struct bt_sock_list *)
820 pde_data(file_inode(seq->file)))->lock)
821 {
822 struct bt_sock_list *l = pde_data(file_inode(seq->file));
823
824 read_lock(&l->lock);
825 return seq_hlist_start_head(&l->head, *pos);
826 }
827
bt_seq_next(struct seq_file * seq,void * v,loff_t * pos)828 static void *bt_seq_next(struct seq_file *seq, void *v, loff_t *pos)
829 {
830 struct bt_sock_list *l = pde_data(file_inode(seq->file));
831
832 return seq_hlist_next(v, &l->head, pos);
833 }
834
bt_seq_stop(struct seq_file * seq,void * v)835 static void bt_seq_stop(struct seq_file *seq, void *v)
836 __releases_shared(&((struct bt_sock_list *)
837 pde_data(file_inode(seq->file)))->lock)
838 {
839 struct bt_sock_list *l = pde_data(file_inode(seq->file));
840
841 read_unlock(&l->lock);
842 }
843
bt_seq_show(struct seq_file * seq,void * v)844 static int bt_seq_show(struct seq_file *seq, void *v)
845 {
846 struct bt_sock_list *l = pde_data(file_inode(seq->file));
847
848 if (v == SEQ_START_TOKEN) {
849 seq_puts(seq, "sk RefCnt Rmem Wmem User Inode Parent");
850
851 if (l->custom_seq_show) {
852 seq_putc(seq, ' ');
853 l->custom_seq_show(seq, v);
854 }
855
856 seq_putc(seq, '\n');
857 } else {
858 struct sock *sk = sk_entry(v);
859 struct bt_sock *bt = bt_sk(sk);
860
861 seq_printf(seq,
862 "%pK %-6d %-6u %-6u %-6u %-6llu %-6llu",
863 sk,
864 refcount_read(&sk->sk_refcnt),
865 sk_rmem_alloc_get(sk),
866 sk_wmem_alloc_get(sk),
867 from_kuid(seq_user_ns(seq), sk_uid(sk)),
868 sock_i_ino(sk),
869 bt->parent ? sock_i_ino(bt->parent) : 0ULL);
870
871 if (l->custom_seq_show) {
872 seq_putc(seq, ' ');
873 l->custom_seq_show(seq, v);
874 }
875
876 seq_putc(seq, '\n');
877 }
878 return 0;
879 }
880
881 static const struct seq_operations bt_seq_ops = {
882 .start = bt_seq_start,
883 .next = bt_seq_next,
884 .stop = bt_seq_stop,
885 .show = bt_seq_show,
886 };
887
bt_procfs_init(struct net * net,const char * name,struct bt_sock_list * sk_list,int (* seq_show)(struct seq_file *,void *))888 int bt_procfs_init(struct net *net, const char *name,
889 struct bt_sock_list *sk_list,
890 int (*seq_show)(struct seq_file *, void *))
891 {
892 sk_list->custom_seq_show = seq_show;
893
894 if (!proc_create_seq_data(name, 0, net->proc_net, &bt_seq_ops, sk_list))
895 return -ENOMEM;
896 return 0;
897 }
898
bt_procfs_cleanup(struct net * net,const char * name)899 void bt_procfs_cleanup(struct net *net, const char *name)
900 {
901 remove_proc_entry(name, net->proc_net);
902 }
903 #else
bt_procfs_init(struct net * net,const char * name,struct bt_sock_list * sk_list,int (* seq_show)(struct seq_file *,void *))904 int bt_procfs_init(struct net *net, const char *name,
905 struct bt_sock_list *sk_list,
906 int (*seq_show)(struct seq_file *, void *))
907 {
908 return 0;
909 }
910
bt_procfs_cleanup(struct net * net,const char * name)911 void bt_procfs_cleanup(struct net *net, const char *name)
912 {
913 }
914 #endif
915 EXPORT_SYMBOL(bt_procfs_init);
916 EXPORT_SYMBOL(bt_procfs_cleanup);
917
918 static const struct net_proto_family bt_sock_family_ops = {
919 .owner = THIS_MODULE,
920 .family = PF_BLUETOOTH,
921 .create = bt_sock_create,
922 };
923
924 struct dentry *bt_debugfs;
925 EXPORT_SYMBOL_GPL(bt_debugfs);
926
927 #define VERSION __stringify(BT_SUBSYS_VERSION) "." \
928 __stringify(BT_SUBSYS_REVISION)
929
bt_init(void)930 static int __init bt_init(void)
931 {
932 int err;
933
934 sock_skb_cb_check_size(sizeof(struct bt_skb_cb));
935
936 BT_INFO("Core ver %s", VERSION);
937
938 err = bt_selftest();
939 if (err < 0)
940 return err;
941
942 bt_debugfs = debugfs_create_dir("bluetooth", NULL);
943
944 bt_leds_init();
945
946 err = bt_sysfs_init();
947 if (err < 0)
948 goto cleanup_led;
949
950 err = sock_register(&bt_sock_family_ops);
951 if (err)
952 goto cleanup_sysfs;
953
954 BT_INFO("HCI device and connection manager initialized");
955
956 err = hci_sock_init();
957 if (err)
958 goto unregister_socket;
959
960 err = l2cap_init();
961 if (err)
962 goto cleanup_socket;
963
964 err = sco_init();
965 if (err)
966 goto cleanup_cap;
967
968 err = mgmt_init();
969 if (err)
970 goto cleanup_sco;
971
972 return 0;
973
974 cleanup_sco:
975 sco_exit();
976 cleanup_cap:
977 l2cap_exit();
978 cleanup_socket:
979 hci_sock_cleanup();
980 unregister_socket:
981 sock_unregister(PF_BLUETOOTH);
982 cleanup_sysfs:
983 bt_sysfs_cleanup();
984 cleanup_led:
985 bt_leds_cleanup();
986 debugfs_remove_recursive(bt_debugfs);
987 return err;
988 }
989
bt_exit(void)990 static void __exit bt_exit(void)
991 {
992 iso_exit();
993
994 mgmt_exit();
995
996 sco_exit();
997
998 l2cap_exit();
999
1000 hci_sock_cleanup();
1001
1002 sock_unregister(PF_BLUETOOTH);
1003
1004 bt_sysfs_cleanup();
1005
1006 bt_leds_cleanup();
1007
1008 debugfs_remove_recursive(bt_debugfs);
1009 }
1010
1011 subsys_initcall(bt_init);
1012 module_exit(bt_exit);
1013
1014 MODULE_AUTHOR("Marcel Holtmann <marcel@holtmann.org>");
1015 MODULE_DESCRIPTION("Bluetooth Core ver " VERSION);
1016 MODULE_VERSION(VERSION);
1017 MODULE_LICENSE("GPL");
1018 MODULE_ALIAS_NETPROTO(PF_BLUETOOTH);
1019