xref: /linux/net/bluetooth/hci_core.c (revision 848a7a91c7f03675d3bd8db6f7721cbf9cb50e21)
1 // SPDX-License-Identifier: GPL-2.0
2 /*
3    BlueZ - Bluetooth protocol stack for Linux
4    Copyright (C) 2000-2001 Qualcomm Incorporated
5    Copyright (C) 2011 ProFUSION Embedded Systems
6 
7    Written 2000,2001 by Maxim Krasnyansky <maxk@qualcomm.com>
8 
9    THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS
10    OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
11    FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT OF THIRD PARTY RIGHTS.
12    IN NO EVENT SHALL THE COPYRIGHT HOLDER(S) AND AUTHOR(S) BE LIABLE FOR ANY
13    CLAIM, OR ANY SPECIAL INDIRECT OR CONSEQUENTIAL DAMAGES, OR ANY DAMAGES
14    WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
15    ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
16    OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
17 
18    ALL LIABILITY, INCLUDING LIABILITY FOR INFRINGEMENT OF ANY PATENTS,
19    COPYRIGHTS, TRADEMARKS OR OTHER RIGHTS, RELATING TO USE OF THIS
20    SOFTWARE IS DISCLAIMED.
21 */
22 
23 /* Bluetooth HCI core. */
24 
25 #include <linux/export.h>
26 #include <linux/rfkill.h>
27 #include <linux/debugfs.h>
28 #include <linux/crypto.h>
29 #include <linux/kcov.h>
30 #include <linux/property.h>
31 #include <linux/suspend.h>
32 #include <linux/wait.h>
33 #include <linux/unaligned.h>
34 
35 #include <net/bluetooth/bluetooth.h>
36 #include <net/bluetooth/hci_core.h>
37 #include <net/bluetooth/l2cap.h>
38 #include <net/bluetooth/mgmt.h>
39 
40 #include "hci_debugfs.h"
41 #include "smp.h"
42 #include "leds.h"
43 #include "msft.h"
44 #include "aosp.h"
45 #include "hci_codec.h"
46 
47 static void hci_rx_work(struct work_struct *work);
48 static void hci_cmd_work(struct work_struct *work);
49 static void hci_tx_work(struct work_struct *work);
50 
51 /* HCI device list */
52 LIST_HEAD(hci_dev_list);
53 DEFINE_RWLOCK(hci_dev_list_lock);
54 
55 /* HCI callback list */
56 LIST_HEAD(hci_cb_list);
57 DEFINE_MUTEX(hci_cb_list_lock);
58 
59 /* HCI ID Numbering */
60 static DEFINE_IDA(hci_index_ida);
61 
62 /* Get HCI device by index.
63  * Device is held on return. */
64 static struct hci_dev *__hci_dev_get(int index, int *srcu_index)
65 	__context_unsafe(/* conditional locking */)
66 {
67 	struct hci_dev *hdev = NULL, *d;
68 
69 	BT_DBG("%d", index);
70 
71 	if (index < 0)
72 		return NULL;
73 
74 	read_lock(&hci_dev_list_lock);
75 	list_for_each_entry(d, &hci_dev_list, list) {
76 		if (d->id == index) {
77 			hdev = hci_dev_hold(d);
78 			if (srcu_index)
79 				*srcu_index = srcu_read_lock(&d->srcu);
80 			break;
81 		}
82 	}
83 	read_unlock(&hci_dev_list_lock);
84 	return hdev;
85 }
86 
87 struct hci_dev *hci_dev_get(int index)
88 {
89 	return __hci_dev_get(index, NULL);
90 }
91 
92 static struct hci_dev *hci_dev_get_srcu(int index, int *srcu_index)
93 	__context_unsafe(/* conditional locking vs return */)
94 {
95 	return __hci_dev_get(index, srcu_index);
96 }
97 
98 static void hci_dev_put_srcu(struct hci_dev *hdev, int srcu_index)
99 	__context_unsafe(/* conditional locking vs return */)
100 {
101 	srcu_read_unlock(&hdev->srcu, srcu_index);
102 	hci_dev_put(hdev);
103 }
104 
105 /* ---- Inquiry support ---- */
106 
107 bool hci_discovery_active(struct hci_dev *hdev)
108 {
109 	struct discovery_state *discov = &hdev->discovery;
110 
111 	switch (discov->state) {
112 	case DISCOVERY_FINDING:
113 	case DISCOVERY_RESOLVING:
114 		return true;
115 
116 	default:
117 		return false;
118 	}
119 }
120 EXPORT_SYMBOL(hci_discovery_active);
121 
122 void hci_discovery_set_state(struct hci_dev *hdev, int state)
123 {
124 	int old_state = hdev->discovery.state;
125 
126 	if (old_state == state)
127 		return;
128 
129 	hdev->discovery.state = state;
130 
131 	switch (state) {
132 	case DISCOVERY_STOPPED:
133 		hci_update_passive_scan(hdev);
134 
135 		if (old_state != DISCOVERY_STARTING)
136 			mgmt_discovering(hdev, 0);
137 		break;
138 	case DISCOVERY_STARTING:
139 		break;
140 	case DISCOVERY_FINDING:
141 		mgmt_discovering(hdev, 1);
142 		break;
143 	case DISCOVERY_RESOLVING:
144 		break;
145 	case DISCOVERY_STOPPING:
146 		break;
147 	}
148 
149 	bt_dev_dbg(hdev, "state %u -> %u", old_state, state);
150 }
151 
152 void hci_inquiry_cache_flush(struct hci_dev *hdev)
153 {
154 	struct discovery_state *cache = &hdev->discovery;
155 	struct inquiry_entry *p, *n;
156 
157 	list_for_each_entry_safe(p, n, &cache->all, all) {
158 		list_del(&p->all);
159 		kfree(p);
160 	}
161 
162 	INIT_LIST_HEAD(&cache->unknown);
163 	INIT_LIST_HEAD(&cache->resolve);
164 }
165 
166 struct inquiry_entry *hci_inquiry_cache_lookup(struct hci_dev *hdev,
167 					       bdaddr_t *bdaddr)
168 {
169 	struct discovery_state *cache = &hdev->discovery;
170 	struct inquiry_entry *e;
171 
172 	BT_DBG("cache %p, %pMR", cache, bdaddr);
173 
174 	list_for_each_entry(e, &cache->all, all) {
175 		if (!bacmp(&e->data.bdaddr, bdaddr))
176 			return e;
177 	}
178 
179 	return NULL;
180 }
181 
182 struct inquiry_entry *hci_inquiry_cache_lookup_unknown(struct hci_dev *hdev,
183 						       bdaddr_t *bdaddr)
184 {
185 	struct discovery_state *cache = &hdev->discovery;
186 	struct inquiry_entry *e;
187 
188 	BT_DBG("cache %p, %pMR", cache, bdaddr);
189 
190 	list_for_each_entry(e, &cache->unknown, list) {
191 		if (!bacmp(&e->data.bdaddr, bdaddr))
192 			return e;
193 	}
194 
195 	return NULL;
196 }
197 
198 struct inquiry_entry *hci_inquiry_cache_lookup_resolve(struct hci_dev *hdev,
199 						       bdaddr_t *bdaddr,
200 						       int state)
201 {
202 	struct discovery_state *cache = &hdev->discovery;
203 	struct inquiry_entry *e;
204 
205 	BT_DBG("cache %p bdaddr %pMR state %d", cache, bdaddr, state);
206 
207 	list_for_each_entry(e, &cache->resolve, list) {
208 		if (!bacmp(bdaddr, BDADDR_ANY) && e->name_state == state)
209 			return e;
210 		if (!bacmp(&e->data.bdaddr, bdaddr))
211 			return e;
212 	}
213 
214 	return NULL;
215 }
216 
217 void hci_inquiry_cache_update_resolve(struct hci_dev *hdev,
218 				      struct inquiry_entry *ie)
219 {
220 	struct discovery_state *cache = &hdev->discovery;
221 	struct list_head *pos = &cache->resolve;
222 	struct inquiry_entry *p;
223 
224 	list_del(&ie->list);
225 
226 	list_for_each_entry(p, &cache->resolve, list) {
227 		if (p->name_state != NAME_PENDING &&
228 		    abs(p->data.rssi) >= abs(ie->data.rssi))
229 			break;
230 		pos = &p->list;
231 	}
232 
233 	list_add(&ie->list, pos);
234 }
235 
236 u32 hci_inquiry_cache_update(struct hci_dev *hdev, struct inquiry_data *data,
237 			     bool name_known)
238 {
239 	struct discovery_state *cache = &hdev->discovery;
240 	struct inquiry_entry *ie;
241 	u32 flags = 0;
242 
243 	BT_DBG("cache %p, %pMR", cache, &data->bdaddr);
244 
245 	hci_remove_remote_oob_data(hdev, &data->bdaddr, BDADDR_BREDR);
246 
247 	if (!data->ssp_mode)
248 		flags |= MGMT_DEV_FOUND_LEGACY_PAIRING;
249 
250 	ie = hci_inquiry_cache_lookup(hdev, &data->bdaddr);
251 	if (ie) {
252 		if (!ie->data.ssp_mode)
253 			flags |= MGMT_DEV_FOUND_LEGACY_PAIRING;
254 
255 		if (ie->name_state == NAME_NEEDED &&
256 		    data->rssi != ie->data.rssi) {
257 			ie->data.rssi = data->rssi;
258 			hci_inquiry_cache_update_resolve(hdev, ie);
259 		}
260 
261 		goto update;
262 	}
263 
264 	/* Entry not in the cache. Add new one. */
265 	ie = kzalloc_obj(*ie);
266 	if (!ie) {
267 		flags |= MGMT_DEV_FOUND_CONFIRM_NAME;
268 		goto done;
269 	}
270 
271 	list_add(&ie->all, &cache->all);
272 
273 	if (name_known) {
274 		ie->name_state = NAME_KNOWN;
275 	} else {
276 		ie->name_state = NAME_NOT_KNOWN;
277 		list_add(&ie->list, &cache->unknown);
278 	}
279 
280 update:
281 	if (name_known && ie->name_state != NAME_KNOWN &&
282 	    ie->name_state != NAME_PENDING) {
283 		ie->name_state = NAME_KNOWN;
284 		list_del(&ie->list);
285 	}
286 
287 	memcpy(&ie->data, data, sizeof(*data));
288 	ie->timestamp = jiffies;
289 	cache->timestamp = jiffies;
290 
291 	if (ie->name_state == NAME_NOT_KNOWN)
292 		flags |= MGMT_DEV_FOUND_CONFIRM_NAME;
293 
294 done:
295 	return flags;
296 }
297 
298 static int inquiry_cache_dump(struct hci_dev *hdev, int num, __u8 *buf)
299 {
300 	struct discovery_state *cache = &hdev->discovery;
301 	struct inquiry_info *info = (struct inquiry_info *) buf;
302 	struct inquiry_entry *e;
303 	int copied = 0;
304 
305 	list_for_each_entry(e, &cache->all, all) {
306 		struct inquiry_data *data = &e->data;
307 
308 		if (copied >= num)
309 			break;
310 
311 		bacpy(&info->bdaddr, &data->bdaddr);
312 		info->pscan_rep_mode	= data->pscan_rep_mode;
313 		info->pscan_period_mode	= data->pscan_period_mode;
314 		info->pscan_mode	= data->pscan_mode;
315 		memcpy(info->dev_class, data->dev_class, 3);
316 		info->clock_offset	= data->clock_offset;
317 
318 		info++;
319 		copied++;
320 	}
321 
322 	BT_DBG("cache %p, copied %d", cache, copied);
323 	return copied;
324 }
325 
326 int hci_inquiry(void __user *arg)
327 {
328 	__u8 __user *ptr = arg;
329 	struct hci_inquiry_req ir;
330 	struct hci_dev *hdev;
331 	int err = 0, do_inquiry = 0, max_rsp;
332 	__u8 *buf;
333 
334 	if (copy_from_user(&ir, ptr, sizeof(ir)))
335 		return -EFAULT;
336 
337 	hdev = hci_dev_get(ir.dev_id);
338 	if (!hdev)
339 		return -ENODEV;
340 
341 	if (hci_dev_test_flag(hdev, HCI_USER_CHANNEL)) {
342 		err = -EBUSY;
343 		goto done;
344 	}
345 
346 	if (hci_dev_test_flag(hdev, HCI_UNCONFIGURED)) {
347 		err = -EOPNOTSUPP;
348 		goto done;
349 	}
350 
351 	if (!hci_dev_test_flag(hdev, HCI_BREDR_ENABLED)) {
352 		err = -EOPNOTSUPP;
353 		goto done;
354 	}
355 
356 	/* Restrict maximum inquiry length to 60 seconds */
357 	if (ir.length > 60) {
358 		err = -EINVAL;
359 		goto done;
360 	}
361 
362 	hci_dev_lock(hdev);
363 	if (inquiry_cache_age(hdev) > INQUIRY_CACHE_AGE_MAX ||
364 	    inquiry_cache_empty(hdev) || ir.flags & IREQ_CACHE_FLUSH) {
365 		hci_inquiry_cache_flush(hdev);
366 		do_inquiry = 1;
367 	}
368 	hci_dev_unlock(hdev);
369 
370 	if (do_inquiry) {
371 		hci_req_sync_lock(hdev);
372 		err = hci_inquiry_sync(hdev, ir.length, ir.num_rsp);
373 		hci_req_sync_unlock(hdev);
374 
375 		if (err < 0)
376 			goto done;
377 
378 		/* Wait until Inquiry procedure finishes (HCI_INQUIRY flag is
379 		 * cleared). If it is interrupted by a signal, return -EINTR.
380 		 */
381 		if (wait_on_bit(&hdev->flags, HCI_INQUIRY,
382 				TASK_INTERRUPTIBLE)) {
383 			err = -EINTR;
384 			goto done;
385 		}
386 	}
387 
388 	/* for unlimited number of responses we will use buffer with
389 	 * 255 entries
390 	 */
391 	max_rsp = (ir.num_rsp == 0) ? 255 : ir.num_rsp;
392 
393 	/* cache_dump can't sleep. Therefore we allocate temp buffer and then
394 	 * copy it to the user space.
395 	 */
396 	buf = kmalloc_array(max_rsp, sizeof(struct inquiry_info), GFP_KERNEL);
397 	if (!buf) {
398 		err = -ENOMEM;
399 		goto done;
400 	}
401 
402 	hci_dev_lock(hdev);
403 	ir.num_rsp = inquiry_cache_dump(hdev, max_rsp, buf);
404 	hci_dev_unlock(hdev);
405 
406 	BT_DBG("num_rsp %d", ir.num_rsp);
407 
408 	if (!copy_to_user(ptr, &ir, sizeof(ir))) {
409 		ptr += sizeof(ir);
410 		if (copy_to_user(ptr, buf, sizeof(struct inquiry_info) *
411 				 ir.num_rsp))
412 			err = -EFAULT;
413 	} else
414 		err = -EFAULT;
415 
416 	kfree(buf);
417 
418 done:
419 	hci_dev_put(hdev);
420 	return err;
421 }
422 
423 static int hci_dev_do_open(struct hci_dev *hdev)
424 {
425 	int ret = 0;
426 
427 	BT_DBG("%s %p", hdev->name, hdev);
428 
429 	hci_req_sync_lock(hdev);
430 
431 	ret = hci_dev_open_sync(hdev);
432 
433 	hci_req_sync_unlock(hdev);
434 	return ret;
435 }
436 
437 /* ---- HCI ioctl helpers ---- */
438 
439 int hci_dev_open(__u16 dev)
440 {
441 	struct hci_dev *hdev;
442 	int err;
443 
444 	hdev = hci_dev_get(dev);
445 	if (!hdev)
446 		return -ENODEV;
447 
448 	/* Devices that are marked as unconfigured can only be powered
449 	 * up as user channel. Trying to bring them up as normal devices
450 	 * will result into a failure. Only user channel operation is
451 	 * possible.
452 	 *
453 	 * When this function is called for a user channel, the flag
454 	 * HCI_USER_CHANNEL will be set first before attempting to
455 	 * open the device.
456 	 */
457 	if (hci_dev_test_flag(hdev, HCI_UNCONFIGURED) &&
458 	    !hci_dev_test_flag(hdev, HCI_USER_CHANNEL)) {
459 		err = -EOPNOTSUPP;
460 		goto done;
461 	}
462 
463 	/* We need to ensure that no other power on/off work is pending
464 	 * before proceeding to call hci_dev_do_open. This is
465 	 * particularly important if the setup procedure has not yet
466 	 * completed.
467 	 */
468 	if (hci_dev_test_and_clear_flag(hdev, HCI_AUTO_OFF))
469 		cancel_delayed_work(&hdev->power_off);
470 
471 	/* After this call it is guaranteed that the setup procedure
472 	 * has finished. This means that error conditions like RFKILL
473 	 * or no valid public or static random address apply.
474 	 */
475 	flush_workqueue(hdev->req_workqueue);
476 
477 	/* For controllers not using the management interface and that
478 	 * are brought up using legacy ioctl, set the HCI_BONDABLE bit
479 	 * so that pairing works for them. Once the management interface
480 	 * is in use this bit will be cleared again and userspace has
481 	 * to explicitly enable it.
482 	 */
483 	if (!hci_dev_test_flag(hdev, HCI_USER_CHANNEL) &&
484 	    !hci_dev_test_flag(hdev, HCI_MGMT))
485 		hci_dev_set_flag(hdev, HCI_BONDABLE);
486 
487 	err = hci_dev_do_open(hdev);
488 
489 done:
490 	hci_dev_put(hdev);
491 	return err;
492 }
493 
494 int hci_dev_do_close(struct hci_dev *hdev)
495 {
496 	int err;
497 
498 	BT_DBG("%s %p", hdev->name, hdev);
499 
500 	hci_req_sync_lock(hdev);
501 
502 	err = hci_dev_close_sync(hdev);
503 
504 	hci_req_sync_unlock(hdev);
505 
506 	return err;
507 }
508 
509 int hci_dev_close(__u16 dev)
510 {
511 	struct hci_dev *hdev;
512 	int err;
513 
514 	hdev = hci_dev_get(dev);
515 	if (!hdev)
516 		return -ENODEV;
517 
518 	if (hci_dev_test_flag(hdev, HCI_USER_CHANNEL)) {
519 		err = -EBUSY;
520 		goto done;
521 	}
522 
523 	cancel_work_sync(&hdev->power_on);
524 	if (hci_dev_test_and_clear_flag(hdev, HCI_AUTO_OFF))
525 		cancel_delayed_work(&hdev->power_off);
526 
527 	err = hci_dev_do_close(hdev);
528 
529 done:
530 	hci_dev_put(hdev);
531 	return err;
532 }
533 
534 static int hci_dev_do_reset(struct hci_dev *hdev)
535 {
536 	int ret;
537 
538 	BT_DBG("%s %p", hdev->name, hdev);
539 
540 	hci_req_sync_lock(hdev);
541 
542 	ret = hci_dev_close_sync(hdev);
543 	if (!ret)
544 		ret = hci_dev_open_sync(hdev);
545 
546 	hci_req_sync_unlock(hdev);
547 	return ret;
548 }
549 
550 int hci_dev_reset(__u16 dev)
551 {
552 	struct hci_dev *hdev;
553 	int err, srcu_index;
554 
555 	hdev = hci_dev_get_srcu(dev, &srcu_index);
556 	if (!hdev)
557 		return -ENODEV;
558 
559 	if (!test_bit(HCI_UP, &hdev->flags)) {
560 		err = -ENETDOWN;
561 		goto done;
562 	}
563 
564 	if (hci_dev_test_flag(hdev, HCI_USER_CHANNEL)) {
565 		err = -EBUSY;
566 		goto done;
567 	}
568 
569 	if (hci_dev_test_flag(hdev, HCI_UNCONFIGURED)) {
570 		err = -EOPNOTSUPP;
571 		goto done;
572 	}
573 
574 	err = hci_dev_do_reset(hdev);
575 
576 done:
577 	hci_dev_put_srcu(hdev, srcu_index);
578 	return err;
579 }
580 
581 int hci_dev_reset_stat(__u16 dev)
582 {
583 	struct hci_dev *hdev;
584 	int ret = 0;
585 
586 	hdev = hci_dev_get(dev);
587 	if (!hdev)
588 		return -ENODEV;
589 
590 	if (hci_dev_test_flag(hdev, HCI_USER_CHANNEL)) {
591 		ret = -EBUSY;
592 		goto done;
593 	}
594 
595 	if (hci_dev_test_flag(hdev, HCI_UNCONFIGURED)) {
596 		ret = -EOPNOTSUPP;
597 		goto done;
598 	}
599 
600 	memset(&hdev->stat, 0, sizeof(struct hci_dev_stats));
601 
602 done:
603 	hci_dev_put(hdev);
604 	return ret;
605 }
606 
607 static void hci_update_passive_scan_state(struct hci_dev *hdev, u8 scan)
608 {
609 	bool conn_changed, discov_changed;
610 
611 	BT_DBG("%s scan 0x%02x", hdev->name, scan);
612 
613 	if ((scan & SCAN_PAGE))
614 		conn_changed = !hci_dev_test_and_set_flag(hdev,
615 							  HCI_CONNECTABLE);
616 	else
617 		conn_changed = hci_dev_test_and_clear_flag(hdev,
618 							   HCI_CONNECTABLE);
619 
620 	if ((scan & SCAN_INQUIRY)) {
621 		discov_changed = !hci_dev_test_and_set_flag(hdev,
622 							    HCI_DISCOVERABLE);
623 	} else {
624 		hci_dev_clear_flag(hdev, HCI_LIMITED_DISCOVERABLE);
625 		discov_changed = hci_dev_test_and_clear_flag(hdev,
626 							     HCI_DISCOVERABLE);
627 	}
628 
629 	if (!hci_dev_test_flag(hdev, HCI_MGMT))
630 		return;
631 
632 	if (conn_changed || discov_changed) {
633 		/* In case this was disabled through mgmt */
634 		hci_dev_set_flag(hdev, HCI_BREDR_ENABLED);
635 
636 		if (hci_dev_test_flag(hdev, HCI_LE_ENABLED))
637 			hci_update_adv_data(hdev, hdev->cur_adv_instance);
638 
639 		mgmt_new_settings(hdev);
640 	}
641 }
642 
643 int hci_dev_cmd(unsigned int cmd, void __user *arg)
644 {
645 	struct hci_dev *hdev;
646 	struct hci_dev_req dr;
647 	__le16 policy;
648 	int err = 0;
649 
650 	if (copy_from_user(&dr, arg, sizeof(dr)))
651 		return -EFAULT;
652 
653 	hdev = hci_dev_get(dr.dev_id);
654 	if (!hdev)
655 		return -ENODEV;
656 
657 	if (hci_dev_test_flag(hdev, HCI_USER_CHANNEL)) {
658 		err = -EBUSY;
659 		goto done;
660 	}
661 
662 	if (hci_dev_test_flag(hdev, HCI_UNCONFIGURED)) {
663 		err = -EOPNOTSUPP;
664 		goto done;
665 	}
666 
667 	if (!hci_dev_test_flag(hdev, HCI_BREDR_ENABLED)) {
668 		err = -EOPNOTSUPP;
669 		goto done;
670 	}
671 
672 	switch (cmd) {
673 	case HCISETAUTH:
674 		err = hci_cmd_sync_status(hdev, HCI_OP_WRITE_AUTH_ENABLE,
675 					  1, &dr.dev_opt, HCI_CMD_TIMEOUT);
676 		break;
677 
678 	case HCISETENCRYPT:
679 		if (!lmp_encrypt_capable(hdev)) {
680 			err = -EOPNOTSUPP;
681 			break;
682 		}
683 
684 		if (!test_bit(HCI_AUTH, &hdev->flags)) {
685 			/* Auth must be enabled first */
686 			err = hci_cmd_sync_status(hdev,
687 						  HCI_OP_WRITE_AUTH_ENABLE,
688 						  1, &dr.dev_opt,
689 						  HCI_CMD_TIMEOUT);
690 			if (err)
691 				break;
692 		}
693 
694 		err = hci_cmd_sync_status(hdev, HCI_OP_WRITE_ENCRYPT_MODE,
695 					  1, &dr.dev_opt, HCI_CMD_TIMEOUT);
696 		break;
697 
698 	case HCISETSCAN:
699 		err = hci_cmd_sync_status(hdev, HCI_OP_WRITE_SCAN_ENABLE,
700 					  1, &dr.dev_opt, HCI_CMD_TIMEOUT);
701 
702 		/* Ensure that the connectable and discoverable states
703 		 * get correctly modified as this was a non-mgmt change.
704 		 */
705 		if (!err)
706 			hci_update_passive_scan_state(hdev, dr.dev_opt);
707 		break;
708 
709 	case HCISETLINKPOL:
710 		policy = cpu_to_le16(dr.dev_opt);
711 
712 		err = hci_cmd_sync_status(hdev, HCI_OP_WRITE_DEF_LINK_POLICY,
713 					  2, &policy, HCI_CMD_TIMEOUT);
714 		break;
715 
716 	case HCISETLINKMODE:
717 		hdev->link_mode = ((__u16) dr.dev_opt) &
718 					(HCI_LM_MASTER | HCI_LM_ACCEPT);
719 		break;
720 
721 	case HCISETPTYPE:
722 		if (hdev->pkt_type == (__u16) dr.dev_opt)
723 			break;
724 
725 		hdev->pkt_type = (__u16) dr.dev_opt;
726 		mgmt_phy_configuration_changed(hdev, NULL);
727 		break;
728 
729 	case HCISETACLMTU:
730 		hdev->acl_mtu  = *((__u16 *) &dr.dev_opt + 1);
731 		hdev->acl_pkts = *((__u16 *) &dr.dev_opt + 0);
732 		break;
733 
734 	case HCISETSCOMTU:
735 		hdev->sco_mtu  = *((__u16 *) &dr.dev_opt + 1);
736 		hdev->sco_pkts = *((__u16 *) &dr.dev_opt + 0);
737 		break;
738 
739 	default:
740 		err = -EINVAL;
741 		break;
742 	}
743 
744 done:
745 	hci_dev_put(hdev);
746 	return err;
747 }
748 
749 int hci_get_dev_list(void __user *arg)
750 {
751 	struct hci_dev *hdev;
752 	struct hci_dev_list_req *dl;
753 	struct hci_dev_req *dr;
754 	int n = 0, err;
755 	__u16 dev_num;
756 
757 	if (get_user(dev_num, (__u16 __user *) arg))
758 		return -EFAULT;
759 
760 	if (!dev_num || dev_num > (PAGE_SIZE * 2) / sizeof(*dr))
761 		return -EINVAL;
762 
763 	dl = kzalloc_flex(*dl, dev_req, dev_num);
764 	if (!dl)
765 		return -ENOMEM;
766 
767 	dl->dev_num = dev_num;
768 	dr = dl->dev_req;
769 
770 	read_lock(&hci_dev_list_lock);
771 	list_for_each_entry(hdev, &hci_dev_list, list) {
772 		unsigned long flags = hdev->flags;
773 
774 		/* When the auto-off is configured it means the transport
775 		 * is running, but in that case still indicate that the
776 		 * device is actually down.
777 		 */
778 		if (hci_dev_test_flag(hdev, HCI_AUTO_OFF))
779 			flags &= ~BIT(HCI_UP);
780 
781 		dr[n].dev_id  = hdev->id;
782 		dr[n].dev_opt = flags;
783 
784 		if (++n >= dev_num)
785 			break;
786 	}
787 	read_unlock(&hci_dev_list_lock);
788 
789 	dl->dev_num = n;
790 	err = copy_to_user(arg, dl, struct_size(dl, dev_req, n));
791 	kfree(dl);
792 
793 	return err ? -EFAULT : 0;
794 }
795 
796 int hci_get_dev_info(void __user *arg)
797 {
798 	struct hci_dev *hdev;
799 	struct hci_dev_info di;
800 	unsigned long flags;
801 	int err = 0;
802 
803 	if (copy_from_user(&di, arg, sizeof(di)))
804 		return -EFAULT;
805 
806 	hdev = hci_dev_get(di.dev_id);
807 	if (!hdev)
808 		return -ENODEV;
809 
810 	/* When the auto-off is configured it means the transport
811 	 * is running, but in that case still indicate that the
812 	 * device is actually down.
813 	 */
814 	if (hci_dev_test_flag(hdev, HCI_AUTO_OFF))
815 		flags = hdev->flags & ~BIT(HCI_UP);
816 	else
817 		flags = hdev->flags;
818 
819 	strscpy(di.name, hdev->name, sizeof(di.name));
820 	di.bdaddr   = hdev->bdaddr;
821 	di.type     = (hdev->bus & 0x0f);
822 	di.flags    = flags;
823 	di.pkt_type = hdev->pkt_type;
824 	if (lmp_bredr_capable(hdev)) {
825 		di.acl_mtu  = hdev->acl_mtu;
826 		di.acl_pkts = hdev->acl_pkts;
827 		di.sco_mtu  = hdev->sco_mtu;
828 		di.sco_pkts = hdev->sco_pkts;
829 	} else {
830 		di.acl_mtu  = hdev->le_mtu;
831 		di.acl_pkts = hdev->le_pkts;
832 		di.sco_mtu  = 0;
833 		di.sco_pkts = 0;
834 	}
835 	di.link_policy = hdev->link_policy;
836 	di.link_mode   = hdev->link_mode;
837 
838 	memcpy(&di.stat, &hdev->stat, sizeof(di.stat));
839 	memcpy(&di.features, &hdev->features, sizeof(di.features));
840 
841 	if (copy_to_user(arg, &di, sizeof(di)))
842 		err = -EFAULT;
843 
844 	hci_dev_put(hdev);
845 
846 	return err;
847 }
848 
849 /* ---- Interface to HCI drivers ---- */
850 
851 static int hci_dev_do_poweroff(struct hci_dev *hdev)
852 {
853 	int err;
854 
855 	BT_DBG("%s %p", hdev->name, hdev);
856 
857 	hci_req_sync_lock(hdev);
858 
859 	err = hci_set_powered_sync(hdev, false);
860 
861 	hci_req_sync_unlock(hdev);
862 
863 	return err;
864 }
865 
866 static int hci_rfkill_set_block(void *data, bool blocked)
867 {
868 	struct hci_dev *hdev = data;
869 	int err;
870 
871 	BT_DBG("%p name %s blocked %d", hdev, hdev->name, blocked);
872 
873 	if (hci_dev_test_flag(hdev, HCI_USER_CHANNEL))
874 		return -EBUSY;
875 
876 	if (blocked == hci_dev_test_flag(hdev, HCI_RFKILLED))
877 		return 0;
878 
879 	if (blocked) {
880 		hci_dev_set_flag(hdev, HCI_RFKILLED);
881 
882 		if (!hci_dev_test_flag(hdev, HCI_SETUP) &&
883 		    !hci_dev_test_flag(hdev, HCI_CONFIG)) {
884 			err = hci_dev_do_poweroff(hdev);
885 			if (err) {
886 				bt_dev_err(hdev, "Error when powering off device on rfkill (%d)",
887 					   err);
888 
889 				/* Make sure the device is still closed even if
890 				 * anything during power off sequence (eg.
891 				 * disconnecting devices) failed.
892 				 */
893 				hci_dev_do_close(hdev);
894 			}
895 		}
896 	} else {
897 		hci_dev_clear_flag(hdev, HCI_RFKILLED);
898 	}
899 
900 	return 0;
901 }
902 
903 static const struct rfkill_ops hci_rfkill_ops = {
904 	.set_block = hci_rfkill_set_block,
905 };
906 
907 static void hci_power_on(struct work_struct *work)
908 {
909 	struct hci_dev *hdev = container_of(work, struct hci_dev, power_on);
910 	int err;
911 
912 	BT_DBG("%s", hdev->name);
913 
914 	if (test_bit(HCI_UP, &hdev->flags) &&
915 	    hci_dev_test_flag(hdev, HCI_MGMT) &&
916 	    hci_dev_test_and_clear_flag(hdev, HCI_AUTO_OFF)) {
917 		cancel_delayed_work(&hdev->power_off);
918 		err = hci_powered_update_sync(hdev);
919 		mgmt_power_on(hdev, err);
920 		return;
921 	}
922 
923 	err = hci_dev_do_open(hdev);
924 	if (err < 0) {
925 		hci_dev_lock(hdev);
926 		mgmt_set_powered_failed(hdev, err);
927 		hci_dev_unlock(hdev);
928 		return;
929 	}
930 
931 	/* During the HCI setup phase, a few error conditions are
932 	 * ignored and they need to be checked now. If they are still
933 	 * valid, it is important to turn the device back off.
934 	 */
935 	if (hci_dev_test_flag(hdev, HCI_RFKILLED) ||
936 	    hci_dev_test_flag(hdev, HCI_UNCONFIGURED) ||
937 	    (!bacmp(&hdev->bdaddr, BDADDR_ANY) &&
938 	     !bacmp(&hdev->static_addr, BDADDR_ANY))) {
939 		hci_dev_clear_flag(hdev, HCI_AUTO_OFF);
940 		hci_dev_do_close(hdev);
941 	} else if (hci_dev_test_flag(hdev, HCI_AUTO_OFF)) {
942 		queue_delayed_work(hdev->req_workqueue, &hdev->power_off,
943 				   HCI_AUTO_OFF_TIMEOUT);
944 	}
945 
946 	if (hci_dev_test_and_clear_flag(hdev, HCI_SETUP)) {
947 		/* For unconfigured devices, set the HCI_RAW flag
948 		 * so that userspace can easily identify them.
949 		 */
950 		if (hci_dev_test_flag(hdev, HCI_UNCONFIGURED))
951 			set_bit(HCI_RAW, &hdev->flags);
952 
953 		/* For fully configured devices, this will send
954 		 * the Index Added event. For unconfigured devices,
955 		 * it will send Unconfigued Index Added event.
956 		 *
957 		 * Devices with HCI_QUIRK_RAW_DEVICE are ignored
958 		 * and no event will be send.
959 		 */
960 		mgmt_index_added(hdev);
961 	} else if (hci_dev_test_and_clear_flag(hdev, HCI_CONFIG)) {
962 		/* When the controller is now configured, then it
963 		 * is important to clear the HCI_RAW flag.
964 		 */
965 		if (!hci_dev_test_flag(hdev, HCI_UNCONFIGURED))
966 			clear_bit(HCI_RAW, &hdev->flags);
967 
968 		/* Powering on the controller with HCI_CONFIG set only
969 		 * happens with the transition from unconfigured to
970 		 * configured. This will send the Index Added event.
971 		 */
972 		mgmt_index_added(hdev);
973 	}
974 }
975 
976 static void hci_power_off(struct work_struct *work)
977 {
978 	struct hci_dev *hdev = container_of(work, struct hci_dev,
979 					    power_off.work);
980 
981 	BT_DBG("%s", hdev->name);
982 
983 	hci_dev_do_close(hdev);
984 }
985 
986 static void hci_error_reset(struct work_struct *work)
987 {
988 	struct hci_dev *hdev = container_of(work, struct hci_dev, error_reset);
989 
990 	hci_dev_hold(hdev);
991 	BT_DBG("%s", hdev->name);
992 
993 	if (hdev->hw_error)
994 		hdev->hw_error(hdev, hdev->hw_error_code);
995 	else
996 		bt_dev_err(hdev, "hardware error 0x%2.2x", hdev->hw_error_code);
997 
998 	if (!hci_dev_do_close(hdev))
999 		hci_dev_do_open(hdev);
1000 
1001 	hci_dev_put(hdev);
1002 }
1003 
1004 void hci_uuids_clear(struct hci_dev *hdev)
1005 {
1006 	struct bt_uuid *uuid, *tmp;
1007 
1008 	list_for_each_entry_safe(uuid, tmp, &hdev->uuids, list) {
1009 		list_del(&uuid->list);
1010 		kfree(uuid);
1011 	}
1012 }
1013 
1014 void hci_link_keys_clear(struct hci_dev *hdev)
1015 {
1016 	struct link_key *key, *tmp;
1017 
1018 	list_for_each_entry_safe(key, tmp, &hdev->link_keys, list) {
1019 		list_del_rcu(&key->list);
1020 		kfree_rcu(key, rcu);
1021 	}
1022 }
1023 
1024 void hci_smp_ltks_clear(struct hci_dev *hdev)
1025 {
1026 	struct smp_ltk *k, *tmp;
1027 
1028 	list_for_each_entry_safe(k, tmp, &hdev->long_term_keys, list) {
1029 		list_del_rcu(&k->list);
1030 		kfree_rcu(k, rcu);
1031 	}
1032 }
1033 
1034 void hci_smp_irks_clear(struct hci_dev *hdev)
1035 {
1036 	struct smp_irk *k, *tmp;
1037 
1038 	list_for_each_entry_safe(k, tmp, &hdev->identity_resolving_keys, list) {
1039 		list_del_rcu(&k->list);
1040 		kfree_rcu(k, rcu);
1041 	}
1042 }
1043 
1044 void hci_blocked_keys_clear(struct hci_dev *hdev)
1045 {
1046 	struct blocked_key *b, *tmp;
1047 
1048 	list_for_each_entry_safe(b, tmp, &hdev->blocked_keys, list) {
1049 		list_del_rcu(&b->list);
1050 		kfree_rcu(b, rcu);
1051 	}
1052 }
1053 
1054 bool hci_is_blocked_key(struct hci_dev *hdev, u8 type, u8 val[16])
1055 {
1056 	bool blocked = false;
1057 	struct blocked_key *b;
1058 
1059 	rcu_read_lock();
1060 	list_for_each_entry_rcu(b, &hdev->blocked_keys, list) {
1061 		if (b->type == type && !memcmp(b->val, val, sizeof(b->val))) {
1062 			blocked = true;
1063 			break;
1064 		}
1065 	}
1066 
1067 	rcu_read_unlock();
1068 	return blocked;
1069 }
1070 
1071 struct link_key *hci_find_link_key(struct hci_dev *hdev, bdaddr_t *bdaddr)
1072 {
1073 	struct link_key *k;
1074 
1075 	rcu_read_lock();
1076 	list_for_each_entry_rcu(k, &hdev->link_keys, list) {
1077 		if (bacmp(bdaddr, &k->bdaddr) == 0) {
1078 			rcu_read_unlock();
1079 
1080 			if (hci_is_blocked_key(hdev,
1081 					       HCI_BLOCKED_KEY_TYPE_LINKKEY,
1082 					       k->val)) {
1083 				bt_dev_warn_ratelimited(hdev,
1084 							"Link key blocked for %pMR",
1085 							&k->bdaddr);
1086 				return NULL;
1087 			}
1088 
1089 			return k;
1090 		}
1091 	}
1092 	rcu_read_unlock();
1093 
1094 	return NULL;
1095 }
1096 
1097 static bool hci_persistent_key(struct hci_dev *hdev, struct hci_conn *conn,
1098 			       u8 key_type, u8 old_key_type)
1099 {
1100 	/* Legacy key */
1101 	if (key_type < 0x03)
1102 		return true;
1103 
1104 	/* Debug keys are insecure so don't store them persistently */
1105 	if (key_type == HCI_LK_DEBUG_COMBINATION)
1106 		return false;
1107 
1108 	/* Changed combination key and there's no previous one */
1109 	if (key_type == HCI_LK_CHANGED_COMBINATION && old_key_type == 0xff)
1110 		return false;
1111 
1112 	/* Security mode 3 case */
1113 	if (!conn)
1114 		return true;
1115 
1116 	/* BR/EDR key derived using SC from an LE link */
1117 	if (conn->type == LE_LINK)
1118 		return true;
1119 
1120 	/* Neither local nor remote side had no-bonding as requirement */
1121 	if (conn->auth_type > 0x01 && conn->remote_auth > 0x01)
1122 		return true;
1123 
1124 	/* Local side had dedicated bonding as requirement */
1125 	if (conn->auth_type == 0x02 || conn->auth_type == 0x03)
1126 		return true;
1127 
1128 	/* Remote side had dedicated bonding as requirement */
1129 	if (conn->remote_auth == 0x02 || conn->remote_auth == 0x03)
1130 		return true;
1131 
1132 	/* If none of the above criteria match, then don't store the key
1133 	 * persistently */
1134 	return false;
1135 }
1136 
1137 static u8 ltk_role(u8 type)
1138 {
1139 	if (type == SMP_LTK)
1140 		return HCI_ROLE_MASTER;
1141 
1142 	return HCI_ROLE_SLAVE;
1143 }
1144 
1145 struct smp_ltk *hci_find_ltk(struct hci_dev *hdev, bdaddr_t *bdaddr,
1146 			     u8 addr_type, u8 role)
1147 {
1148 	struct smp_ltk *k;
1149 
1150 	rcu_read_lock();
1151 	list_for_each_entry_rcu(k, &hdev->long_term_keys, list) {
1152 		if (addr_type != k->bdaddr_type || bacmp(bdaddr, &k->bdaddr))
1153 			continue;
1154 
1155 		if (smp_ltk_is_sc(k) || ltk_role(k->type) == role) {
1156 			rcu_read_unlock();
1157 
1158 			if (hci_is_blocked_key(hdev, HCI_BLOCKED_KEY_TYPE_LTK,
1159 					       k->val)) {
1160 				bt_dev_warn_ratelimited(hdev,
1161 							"LTK blocked for %pMR",
1162 							&k->bdaddr);
1163 				return NULL;
1164 			}
1165 
1166 			return k;
1167 		}
1168 	}
1169 	rcu_read_unlock();
1170 
1171 	return NULL;
1172 }
1173 
1174 struct smp_irk *hci_find_irk_by_rpa(struct hci_dev *hdev, bdaddr_t *rpa)
1175 {
1176 	struct smp_irk *irk_to_return = NULL;
1177 	struct smp_irk *irk;
1178 
1179 	rcu_read_lock();
1180 	list_for_each_entry_rcu(irk, &hdev->identity_resolving_keys, list) {
1181 		if (!bacmp(&irk->rpa, rpa)) {
1182 			irk_to_return = irk;
1183 			goto done;
1184 		}
1185 	}
1186 
1187 	list_for_each_entry_rcu(irk, &hdev->identity_resolving_keys, list) {
1188 		if (smp_irk_matches(hdev, irk->val, rpa)) {
1189 			bacpy(&irk->rpa, rpa);
1190 			irk_to_return = irk;
1191 			goto done;
1192 		}
1193 	}
1194 
1195 done:
1196 	if (irk_to_return && hci_is_blocked_key(hdev, HCI_BLOCKED_KEY_TYPE_IRK,
1197 						irk_to_return->val)) {
1198 		bt_dev_warn_ratelimited(hdev, "Identity key blocked for %pMR",
1199 					&irk_to_return->bdaddr);
1200 		irk_to_return = NULL;
1201 	}
1202 
1203 	rcu_read_unlock();
1204 
1205 	return irk_to_return;
1206 }
1207 
1208 struct smp_irk *hci_find_irk_by_addr(struct hci_dev *hdev, bdaddr_t *bdaddr,
1209 				     u8 addr_type)
1210 {
1211 	struct smp_irk *irk_to_return = NULL;
1212 	struct smp_irk *irk;
1213 
1214 	/* Identity Address must be public or static random */
1215 	if (addr_type == ADDR_LE_DEV_RANDOM && (bdaddr->b[5] & 0xc0) != 0xc0)
1216 		return NULL;
1217 
1218 	rcu_read_lock();
1219 	list_for_each_entry_rcu(irk, &hdev->identity_resolving_keys, list) {
1220 		if (addr_type == irk->addr_type &&
1221 		    bacmp(bdaddr, &irk->bdaddr) == 0) {
1222 			irk_to_return = irk;
1223 			break;
1224 		}
1225 	}
1226 
1227 	if (irk_to_return && hci_is_blocked_key(hdev, HCI_BLOCKED_KEY_TYPE_IRK,
1228 						irk_to_return->val)) {
1229 		bt_dev_warn_ratelimited(hdev, "Identity key blocked for %pMR",
1230 					&irk_to_return->bdaddr);
1231 		irk_to_return = NULL;
1232 	}
1233 
1234 	rcu_read_unlock();
1235 
1236 	return irk_to_return;
1237 }
1238 
1239 struct link_key *hci_add_link_key(struct hci_dev *hdev, struct hci_conn *conn,
1240 				  bdaddr_t *bdaddr, u8 *val, u8 type,
1241 				  u8 pin_len, bool *persistent)
1242 {
1243 	struct link_key *key, *old_key;
1244 	u8 old_key_type;
1245 
1246 	old_key = hci_find_link_key(hdev, bdaddr);
1247 	if (old_key) {
1248 		old_key_type = old_key->type;
1249 		key = old_key;
1250 	} else {
1251 		old_key_type = conn ? conn->key_type : 0xff;
1252 		key = kzalloc_obj(*key);
1253 		if (!key)
1254 			return NULL;
1255 		list_add_rcu(&key->list, &hdev->link_keys);
1256 	}
1257 
1258 	BT_DBG("%s key for %pMR type %u", hdev->name, bdaddr, type);
1259 
1260 	/* Some buggy controller combinations generate a changed
1261 	 * combination key for legacy pairing even when there's no
1262 	 * previous key */
1263 	if (type == HCI_LK_CHANGED_COMBINATION &&
1264 	    (!conn || conn->remote_auth == 0xff) && old_key_type == 0xff) {
1265 		type = HCI_LK_COMBINATION;
1266 		if (conn)
1267 			conn->key_type = type;
1268 	}
1269 
1270 	bacpy(&key->bdaddr, bdaddr);
1271 	memcpy(key->val, val, HCI_LINK_KEY_SIZE);
1272 	key->pin_len = pin_len;
1273 
1274 	if (type == HCI_LK_CHANGED_COMBINATION)
1275 		key->type = old_key_type;
1276 	else
1277 		key->type = type;
1278 
1279 	if (persistent)
1280 		*persistent = hci_persistent_key(hdev, conn, type,
1281 						 old_key_type);
1282 
1283 	return key;
1284 }
1285 
1286 struct smp_ltk *hci_add_ltk(struct hci_dev *hdev, bdaddr_t *bdaddr,
1287 			    u8 addr_type, u8 type, u8 authenticated,
1288 			    u8 tk[16], u8 enc_size, __le16 ediv, __le64 rand)
1289 {
1290 	struct smp_ltk *key, *old_key;
1291 	u8 role = ltk_role(type);
1292 
1293 	old_key = hci_find_ltk(hdev, bdaddr, addr_type, role);
1294 	if (old_key)
1295 		key = old_key;
1296 	else {
1297 		key = kzalloc_obj(*key);
1298 		if (!key)
1299 			return NULL;
1300 		list_add_rcu(&key->list, &hdev->long_term_keys);
1301 	}
1302 
1303 	bacpy(&key->bdaddr, bdaddr);
1304 	key->bdaddr_type = addr_type;
1305 	memcpy(key->val, tk, sizeof(key->val));
1306 	key->authenticated = authenticated;
1307 	key->ediv = ediv;
1308 	key->rand = rand;
1309 	key->enc_size = enc_size;
1310 	key->type = type;
1311 
1312 	return key;
1313 }
1314 
1315 struct smp_irk *hci_add_irk(struct hci_dev *hdev, bdaddr_t *bdaddr,
1316 			    u8 addr_type, u8 val[16], bdaddr_t *rpa)
1317 {
1318 	struct smp_irk *irk;
1319 
1320 	irk = hci_find_irk_by_addr(hdev, bdaddr, addr_type);
1321 	if (!irk) {
1322 		irk = kzalloc_obj(*irk);
1323 		if (!irk)
1324 			return NULL;
1325 
1326 		bacpy(&irk->bdaddr, bdaddr);
1327 		irk->addr_type = addr_type;
1328 
1329 		list_add_rcu(&irk->list, &hdev->identity_resolving_keys);
1330 	}
1331 
1332 	memcpy(irk->val, val, 16);
1333 	bacpy(&irk->rpa, rpa);
1334 
1335 	return irk;
1336 }
1337 
1338 int hci_remove_link_key(struct hci_dev *hdev, bdaddr_t *bdaddr)
1339 {
1340 	struct link_key *key;
1341 
1342 	key = hci_find_link_key(hdev, bdaddr);
1343 	if (!key)
1344 		return -ENOENT;
1345 
1346 	BT_DBG("%s removing %pMR", hdev->name, bdaddr);
1347 
1348 	list_del_rcu(&key->list);
1349 	kfree_rcu(key, rcu);
1350 
1351 	return 0;
1352 }
1353 
1354 int hci_remove_ltk(struct hci_dev *hdev, bdaddr_t *bdaddr, u8 bdaddr_type)
1355 {
1356 	struct smp_ltk *k, *tmp;
1357 	int removed = 0;
1358 
1359 	list_for_each_entry_safe(k, tmp, &hdev->long_term_keys, list) {
1360 		if (bacmp(bdaddr, &k->bdaddr) || k->bdaddr_type != bdaddr_type)
1361 			continue;
1362 
1363 		BT_DBG("%s removing %pMR", hdev->name, bdaddr);
1364 
1365 		list_del_rcu(&k->list);
1366 		kfree_rcu(k, rcu);
1367 		removed++;
1368 	}
1369 
1370 	return removed ? 0 : -ENOENT;
1371 }
1372 
1373 void hci_remove_irk(struct hci_dev *hdev, bdaddr_t *bdaddr, u8 addr_type)
1374 {
1375 	struct smp_irk *k, *tmp;
1376 
1377 	list_for_each_entry_safe(k, tmp, &hdev->identity_resolving_keys, list) {
1378 		if (bacmp(bdaddr, &k->bdaddr) || k->addr_type != addr_type)
1379 			continue;
1380 
1381 		BT_DBG("%s removing %pMR", hdev->name, bdaddr);
1382 
1383 		list_del_rcu(&k->list);
1384 		kfree_rcu(k, rcu);
1385 	}
1386 }
1387 
1388 bool hci_bdaddr_is_paired(struct hci_dev *hdev, bdaddr_t *bdaddr, u8 type)
1389 {
1390 	struct smp_ltk *k;
1391 	struct smp_irk *irk;
1392 	u8 addr_type;
1393 
1394 	if (type == BDADDR_BREDR) {
1395 		if (hci_find_link_key(hdev, bdaddr))
1396 			return true;
1397 		return false;
1398 	}
1399 
1400 	/* Convert to HCI addr type which struct smp_ltk uses */
1401 	if (type == BDADDR_LE_PUBLIC)
1402 		addr_type = ADDR_LE_DEV_PUBLIC;
1403 	else
1404 		addr_type = ADDR_LE_DEV_RANDOM;
1405 
1406 	irk = hci_get_irk(hdev, bdaddr, addr_type);
1407 	if (irk) {
1408 		bdaddr = &irk->bdaddr;
1409 		addr_type = irk->addr_type;
1410 	}
1411 
1412 	rcu_read_lock();
1413 	list_for_each_entry_rcu(k, &hdev->long_term_keys, list) {
1414 		if (k->bdaddr_type == addr_type && !bacmp(bdaddr, &k->bdaddr)) {
1415 			rcu_read_unlock();
1416 			return true;
1417 		}
1418 	}
1419 	rcu_read_unlock();
1420 
1421 	return false;
1422 }
1423 
1424 /* HCI command timer function */
1425 static void hci_cmd_timeout(struct work_struct *work)
1426 {
1427 	struct hci_dev *hdev = container_of(work, struct hci_dev,
1428 					    cmd_timer.work);
1429 
1430 	if (hdev->req_skb) {
1431 		u16 opcode = hci_skb_opcode(hdev->req_skb);
1432 
1433 		bt_dev_err(hdev, "command 0x%4.4x tx timeout", opcode);
1434 
1435 		hci_cmd_sync_cancel_sync(hdev, ETIMEDOUT);
1436 	} else {
1437 		bt_dev_err(hdev, "command tx timeout");
1438 	}
1439 
1440 	if (hdev->reset)
1441 		hdev->reset(hdev);
1442 
1443 	atomic_set(&hdev->cmd_cnt, 1);
1444 	queue_work(hdev->workqueue, &hdev->cmd_work);
1445 }
1446 
1447 /* HCI ncmd timer function */
1448 static void hci_ncmd_timeout(struct work_struct *work)
1449 {
1450 	struct hci_dev *hdev = container_of(work, struct hci_dev,
1451 					    ncmd_timer.work);
1452 
1453 	bt_dev_err(hdev, "Controller not accepting commands anymore: ncmd = 0");
1454 
1455 	/* During HCI_INIT phase no events can be injected if the ncmd timer
1456 	 * triggers since the procedure has its own timeout handling.
1457 	 */
1458 	if (test_bit(HCI_INIT, &hdev->flags))
1459 		return;
1460 
1461 	/* This is an irrecoverable state, inject hardware error event */
1462 	hci_reset_dev(hdev);
1463 }
1464 
1465 struct oob_data *hci_find_remote_oob_data(struct hci_dev *hdev,
1466 					  bdaddr_t *bdaddr, u8 bdaddr_type)
1467 {
1468 	struct oob_data *data;
1469 
1470 	list_for_each_entry(data, &hdev->remote_oob_data, list) {
1471 		if (bacmp(bdaddr, &data->bdaddr) != 0)
1472 			continue;
1473 		if (data->bdaddr_type != bdaddr_type)
1474 			continue;
1475 		return data;
1476 	}
1477 
1478 	return NULL;
1479 }
1480 
1481 int hci_remove_remote_oob_data(struct hci_dev *hdev, bdaddr_t *bdaddr,
1482 			       u8 bdaddr_type)
1483 {
1484 	struct oob_data *data;
1485 
1486 	data = hci_find_remote_oob_data(hdev, bdaddr, bdaddr_type);
1487 	if (!data)
1488 		return -ENOENT;
1489 
1490 	BT_DBG("%s removing %pMR (%u)", hdev->name, bdaddr, bdaddr_type);
1491 
1492 	mutex_lock(&hdev->remote_oob_lock);
1493 	list_del(&data->list);
1494 	kfree(data);
1495 	mutex_unlock(&hdev->remote_oob_lock);
1496 
1497 	return 0;
1498 }
1499 
1500 void hci_remote_oob_data_clear(struct hci_dev *hdev)
1501 {
1502 	struct oob_data *data, *n;
1503 
1504 	mutex_lock(&hdev->remote_oob_lock);
1505 	list_for_each_entry_safe(data, n, &hdev->remote_oob_data, list) {
1506 		list_del(&data->list);
1507 		kfree(data);
1508 	}
1509 	mutex_unlock(&hdev->remote_oob_lock);
1510 }
1511 
1512 int hci_add_remote_oob_data(struct hci_dev *hdev, bdaddr_t *bdaddr,
1513 			    u8 bdaddr_type, u8 *hash192, u8 *rand192,
1514 			    u8 *hash256, u8 *rand256)
1515 {
1516 	struct oob_data *data;
1517 
1518 	mutex_lock(&hdev->remote_oob_lock);
1519 	data = hci_find_remote_oob_data(hdev, bdaddr, bdaddr_type);
1520 	if (!data) {
1521 		data = kmalloc_obj(*data);
1522 		if (!data) {
1523 			mutex_unlock(&hdev->remote_oob_lock);
1524 			return -ENOMEM;
1525 		}
1526 
1527 		bacpy(&data->bdaddr, bdaddr);
1528 		data->bdaddr_type = bdaddr_type;
1529 		list_add(&data->list, &hdev->remote_oob_data);
1530 	}
1531 
1532 	if (hash192 && rand192) {
1533 		memcpy(data->hash192, hash192, sizeof(data->hash192));
1534 		memcpy(data->rand192, rand192, sizeof(data->rand192));
1535 		if (hash256 && rand256)
1536 			data->present = 0x03;
1537 	} else {
1538 		memset(data->hash192, 0, sizeof(data->hash192));
1539 		memset(data->rand192, 0, sizeof(data->rand192));
1540 		if (hash256 && rand256)
1541 			data->present = 0x02;
1542 		else
1543 			data->present = 0x00;
1544 	}
1545 
1546 	if (hash256 && rand256) {
1547 		memcpy(data->hash256, hash256, sizeof(data->hash256));
1548 		memcpy(data->rand256, rand256, sizeof(data->rand256));
1549 	} else {
1550 		memset(data->hash256, 0, sizeof(data->hash256));
1551 		memset(data->rand256, 0, sizeof(data->rand256));
1552 		if (hash192 && rand192)
1553 			data->present = 0x01;
1554 	}
1555 
1556 	BT_DBG("%s for %pMR", hdev->name, bdaddr);
1557 
1558 	mutex_unlock(&hdev->remote_oob_lock);
1559 
1560 	return 0;
1561 }
1562 
1563 /* This function requires the caller holds hdev->lock */
1564 struct adv_info *hci_find_adv_instance(struct hci_dev *hdev, u8 instance)
1565 {
1566 	struct adv_info *adv_instance;
1567 
1568 	list_for_each_entry(adv_instance, &hdev->adv_instances, list) {
1569 		if (adv_instance->instance == instance)
1570 			return adv_instance;
1571 	}
1572 
1573 	return NULL;
1574 }
1575 
1576 /* This function requires the caller holds hdev->lock */
1577 struct adv_info *hci_find_adv_sid(struct hci_dev *hdev, u8 sid)
1578 {
1579 	struct adv_info *adv;
1580 
1581 	list_for_each_entry(adv, &hdev->adv_instances, list) {
1582 		if (adv->sid == sid)
1583 			return adv;
1584 	}
1585 
1586 	return NULL;
1587 }
1588 
1589 /* This function requires the caller holds hdev->lock */
1590 struct adv_info *hci_get_next_instance(struct hci_dev *hdev, u8 instance)
1591 {
1592 	struct adv_info *cur_instance;
1593 
1594 	cur_instance = hci_find_adv_instance(hdev, instance);
1595 	if (!cur_instance)
1596 		return NULL;
1597 
1598 	if (cur_instance == list_last_entry(&hdev->adv_instances,
1599 					    struct adv_info, list))
1600 		return list_first_entry(&hdev->adv_instances,
1601 						 struct adv_info, list);
1602 	else
1603 		return list_next_entry(cur_instance, list);
1604 }
1605 
1606 /* This function requires the caller holds hdev->lock */
1607 int hci_remove_adv_instance(struct hci_dev *hdev, u8 instance)
1608 {
1609 	struct adv_info *adv_instance;
1610 
1611 	adv_instance = hci_find_adv_instance(hdev, instance);
1612 	if (!adv_instance)
1613 		return -ENOENT;
1614 
1615 	BT_DBG("%s removing %dMR", hdev->name, instance);
1616 
1617 	if (hdev->cur_adv_instance == instance) {
1618 		if (hdev->adv_instance_timeout) {
1619 			cancel_delayed_work(&hdev->adv_instance_expire);
1620 			hdev->adv_instance_timeout = 0;
1621 		}
1622 		hdev->cur_adv_instance = 0x00;
1623 	}
1624 
1625 	cancel_delayed_work_sync(&adv_instance->rpa_expired_cb);
1626 
1627 	list_del(&adv_instance->list);
1628 	kfree(adv_instance);
1629 
1630 	hdev->adv_instance_cnt--;
1631 
1632 	return 0;
1633 }
1634 
1635 void hci_adv_instances_set_rpa_expired(struct hci_dev *hdev, bool rpa_expired)
1636 {
1637 	struct adv_info *adv_instance, *n;
1638 
1639 	list_for_each_entry_safe(adv_instance, n, &hdev->adv_instances, list)
1640 		adv_instance->rpa_expired = rpa_expired;
1641 }
1642 
1643 /* This function requires the caller holds hdev->lock */
1644 void hci_adv_instances_clear(struct hci_dev *hdev)
1645 {
1646 	struct adv_info *adv_instance, *n;
1647 
1648 	if (hdev->adv_instance_timeout) {
1649 		disable_delayed_work(&hdev->adv_instance_expire);
1650 		hdev->adv_instance_timeout = 0;
1651 	}
1652 
1653 	list_for_each_entry_safe(adv_instance, n, &hdev->adv_instances, list) {
1654 		disable_delayed_work_sync(&adv_instance->rpa_expired_cb);
1655 		list_del(&adv_instance->list);
1656 		kfree(adv_instance);
1657 	}
1658 
1659 	hdev->adv_instance_cnt = 0;
1660 	hdev->cur_adv_instance = 0x00;
1661 }
1662 
1663 static void adv_instance_rpa_expired(struct work_struct *work)
1664 {
1665 	struct adv_info *adv_instance = container_of(work, struct adv_info,
1666 						     rpa_expired_cb.work);
1667 
1668 	BT_DBG("");
1669 
1670 	adv_instance->rpa_expired = true;
1671 }
1672 
1673 /* This function requires the caller holds hdev->lock */
1674 struct adv_info *hci_add_adv_instance(struct hci_dev *hdev, u8 instance,
1675 				      u32 flags, u16 adv_data_len, u8 *adv_data,
1676 				      u16 scan_rsp_len, u8 *scan_rsp_data,
1677 				      u16 timeout, u16 duration, s8 tx_power,
1678 				      u32 min_interval, u32 max_interval,
1679 				      u8 mesh_handle)
1680 {
1681 	struct adv_info *adv;
1682 
1683 	adv = hci_find_adv_instance(hdev, instance);
1684 	if (adv) {
1685 		memset(adv->adv_data, 0, sizeof(adv->adv_data));
1686 		memset(adv->scan_rsp_data, 0, sizeof(adv->scan_rsp_data));
1687 		memset(adv->per_adv_data, 0, sizeof(adv->per_adv_data));
1688 	} else {
1689 		if (hdev->adv_instance_cnt >= hdev->le_num_of_adv_sets ||
1690 		    instance < 1 || instance > hdev->le_num_of_adv_sets + 1)
1691 			return ERR_PTR(-EOVERFLOW);
1692 
1693 		adv = kzalloc_obj(*adv);
1694 		if (!adv)
1695 			return ERR_PTR(-ENOMEM);
1696 
1697 		adv->pending = true;
1698 		adv->instance = instance;
1699 
1700 		/* If controller support only one set and the instance is set to
1701 		 * 1 then there is no option other than using handle 0x00.
1702 		 */
1703 		if (hdev->le_num_of_adv_sets == 1 && instance == 1)
1704 			adv->handle = 0x00;
1705 		else
1706 			adv->handle = instance;
1707 
1708 		list_add(&adv->list, &hdev->adv_instances);
1709 		hdev->adv_instance_cnt++;
1710 	}
1711 
1712 	adv->flags = flags;
1713 	adv->min_interval = min_interval;
1714 	adv->max_interval = max_interval;
1715 	adv->tx_power = tx_power;
1716 	/* Defining a mesh_handle changes the timing units to ms,
1717 	 * rather than seconds, and ties the instance to the requested
1718 	 * mesh_tx queue.
1719 	 */
1720 	adv->mesh = mesh_handle;
1721 
1722 	hci_set_adv_instance_data(hdev, instance, adv_data_len, adv_data,
1723 				  scan_rsp_len, scan_rsp_data);
1724 
1725 	adv->timeout = timeout;
1726 	adv->remaining_time = timeout;
1727 
1728 	if (duration == 0)
1729 		adv->duration = hdev->def_multi_adv_rotation_duration;
1730 	else
1731 		adv->duration = duration;
1732 
1733 	INIT_DELAYED_WORK(&adv->rpa_expired_cb, adv_instance_rpa_expired);
1734 
1735 	BT_DBG("%s for %dMR", hdev->name, instance);
1736 
1737 	return adv;
1738 }
1739 
1740 /* This function requires the caller holds hdev->lock */
1741 struct adv_info *hci_add_per_instance(struct hci_dev *hdev, u8 instance, u8 sid,
1742 				      u32 flags, u8 data_len, u8 *data,
1743 				      u32 min_interval, u32 max_interval)
1744 {
1745 	struct adv_info *adv;
1746 
1747 	adv = hci_add_adv_instance(hdev, instance, flags, 0, NULL, 0, NULL,
1748 				   0, 0, HCI_ADV_TX_POWER_NO_PREFERENCE,
1749 				   min_interval, max_interval, 0);
1750 	if (IS_ERR(adv))
1751 		return adv;
1752 
1753 	adv->sid = sid;
1754 	adv->periodic = true;
1755 	adv->per_adv_data_len = data_len;
1756 
1757 	if (data)
1758 		memcpy(adv->per_adv_data, data, data_len);
1759 
1760 	return adv;
1761 }
1762 
1763 /* This function requires the caller holds hdev->lock */
1764 int hci_set_adv_instance_data(struct hci_dev *hdev, u8 instance,
1765 			      u16 adv_data_len, u8 *adv_data,
1766 			      u16 scan_rsp_len, u8 *scan_rsp_data)
1767 {
1768 	struct adv_info *adv;
1769 
1770 	adv = hci_find_adv_instance(hdev, instance);
1771 
1772 	/* If advertisement doesn't exist, we can't modify its data */
1773 	if (!adv)
1774 		return -ENOENT;
1775 
1776 	if (adv_data_len && ADV_DATA_CMP(adv, adv_data, adv_data_len)) {
1777 		memset(adv->adv_data, 0, sizeof(adv->adv_data));
1778 		memcpy(adv->adv_data, adv_data, adv_data_len);
1779 		adv->adv_data_len = adv_data_len;
1780 		adv->adv_data_changed = true;
1781 	}
1782 
1783 	if (scan_rsp_len && SCAN_RSP_CMP(adv, scan_rsp_data, scan_rsp_len)) {
1784 		memset(adv->scan_rsp_data, 0, sizeof(adv->scan_rsp_data));
1785 		memcpy(adv->scan_rsp_data, scan_rsp_data, scan_rsp_len);
1786 		adv->scan_rsp_len = scan_rsp_len;
1787 		adv->scan_rsp_changed = true;
1788 	}
1789 
1790 	/* Mark as changed if there are flags which would affect it */
1791 	if (((adv->flags & MGMT_ADV_FLAG_APPEARANCE) && hdev->appearance) ||
1792 	    adv->flags & MGMT_ADV_FLAG_LOCAL_NAME)
1793 		adv->scan_rsp_changed = true;
1794 
1795 	return 0;
1796 }
1797 
1798 /* This function requires the caller holds hdev->lock */
1799 u32 hci_adv_instance_flags(struct hci_dev *hdev, u8 instance)
1800 {
1801 	u32 flags;
1802 	struct adv_info *adv;
1803 
1804 	if (instance == 0x00) {
1805 		/* Instance 0 always manages the "Tx Power" and "Flags"
1806 		 * fields
1807 		 */
1808 		flags = MGMT_ADV_FLAG_TX_POWER | MGMT_ADV_FLAG_MANAGED_FLAGS;
1809 
1810 		/* For instance 0, the HCI_ADVERTISING_CONNECTABLE setting
1811 		 * corresponds to the "connectable" instance flag.
1812 		 */
1813 		if (hci_dev_test_flag(hdev, HCI_ADVERTISING_CONNECTABLE))
1814 			flags |= MGMT_ADV_FLAG_CONNECTABLE;
1815 
1816 		if (hci_dev_test_flag(hdev, HCI_LIMITED_DISCOVERABLE))
1817 			flags |= MGMT_ADV_FLAG_LIMITED_DISCOV;
1818 		else if (hci_dev_test_flag(hdev, HCI_DISCOVERABLE))
1819 			flags |= MGMT_ADV_FLAG_DISCOV;
1820 
1821 		return flags;
1822 	}
1823 
1824 	adv = hci_find_adv_instance(hdev, instance);
1825 
1826 	/* Return 0 when we got an invalid instance identifier. */
1827 	if (!adv)
1828 		return 0;
1829 
1830 	return adv->flags;
1831 }
1832 
1833 bool hci_adv_instance_is_scannable(struct hci_dev *hdev, u8 instance)
1834 {
1835 	struct adv_info *adv;
1836 
1837 	/* Instance 0x00 always set local name */
1838 	if (instance == 0x00)
1839 		return true;
1840 
1841 	adv = hci_find_adv_instance(hdev, instance);
1842 	if (!adv)
1843 		return false;
1844 
1845 	if (adv->flags & MGMT_ADV_FLAG_APPEARANCE ||
1846 	    adv->flags & MGMT_ADV_FLAG_LOCAL_NAME)
1847 		return true;
1848 
1849 	return adv->scan_rsp_len ? true : false;
1850 }
1851 
1852 /* This function requires the caller holds hdev->lock */
1853 void hci_adv_monitors_clear(struct hci_dev *hdev)
1854 {
1855 	struct adv_monitor *monitor;
1856 	int handle;
1857 
1858 	idr_for_each_entry(&hdev->adv_monitors_idr, monitor, handle)
1859 		hci_free_adv_monitor(hdev, monitor);
1860 
1861 	idr_destroy(&hdev->adv_monitors_idr);
1862 }
1863 
1864 /* Frees the monitor structure and do some bookkeepings.
1865  * This function requires the caller holds hdev->lock.
1866  */
1867 void hci_free_adv_monitor(struct hci_dev *hdev, struct adv_monitor *monitor)
1868 {
1869 	struct adv_pattern *pattern;
1870 	struct adv_pattern *tmp;
1871 
1872 	if (!monitor)
1873 		return;
1874 
1875 	list_for_each_entry_safe(pattern, tmp, &monitor->patterns, list) {
1876 		list_del(&pattern->list);
1877 		kfree(pattern);
1878 	}
1879 
1880 	if (monitor->handle)
1881 		idr_remove(&hdev->adv_monitors_idr, monitor->handle);
1882 
1883 	if (monitor->state != ADV_MONITOR_STATE_NOT_REGISTERED)
1884 		hdev->adv_monitors_cnt--;
1885 
1886 	kfree(monitor);
1887 }
1888 
1889 /* Assigns handle to a monitor, and if offloading is supported and power is on,
1890  * also attempts to forward the request to the controller.
1891  * This function requires the caller holds hci_req_sync_lock.
1892  */
1893 int hci_add_adv_monitor(struct hci_dev *hdev, struct adv_monitor *monitor)
1894 {
1895 	int min, max, handle;
1896 	int status = 0;
1897 
1898 	if (!monitor)
1899 		return -EINVAL;
1900 
1901 	hci_dev_lock(hdev);
1902 
1903 	min = HCI_MIN_ADV_MONITOR_HANDLE;
1904 	max = HCI_MIN_ADV_MONITOR_HANDLE + HCI_MAX_ADV_MONITOR_NUM_HANDLES;
1905 	handle = idr_alloc(&hdev->adv_monitors_idr, monitor, min, max,
1906 			   GFP_KERNEL);
1907 
1908 	hci_dev_unlock(hdev);
1909 
1910 	if (handle < 0)
1911 		return handle;
1912 
1913 	monitor->handle = handle;
1914 
1915 	if (!hdev_is_powered(hdev))
1916 		return status;
1917 
1918 	switch (hci_get_adv_monitor_offload_ext(hdev)) {
1919 	case HCI_ADV_MONITOR_EXT_NONE:
1920 		bt_dev_dbg(hdev, "add monitor %d status %d",
1921 			   monitor->handle, status);
1922 		/* Message was not forwarded to controller - not an error */
1923 		break;
1924 
1925 	case HCI_ADV_MONITOR_EXT_MSFT:
1926 		status = msft_add_monitor_pattern(hdev, monitor);
1927 		bt_dev_dbg(hdev, "add monitor %d msft status %d",
1928 			   handle, status);
1929 		break;
1930 	}
1931 
1932 	return status;
1933 }
1934 
1935 /* Attempts to tell the controller and free the monitor. If somehow the
1936  * controller doesn't have a corresponding handle, remove anyway.
1937  * This function requires the caller holds hci_req_sync_lock.
1938  */
1939 static int hci_remove_adv_monitor(struct hci_dev *hdev,
1940 				  struct adv_monitor *monitor)
1941 {
1942 	int status = 0;
1943 	int handle;
1944 
1945 	switch (hci_get_adv_monitor_offload_ext(hdev)) {
1946 	case HCI_ADV_MONITOR_EXT_NONE: /* also goes here when powered off */
1947 		bt_dev_dbg(hdev, "remove monitor %d status %d",
1948 			   monitor->handle, status);
1949 		goto free_monitor;
1950 
1951 	case HCI_ADV_MONITOR_EXT_MSFT:
1952 		handle = monitor->handle;
1953 		status = msft_remove_monitor(hdev, monitor);
1954 		bt_dev_dbg(hdev, "remove monitor %d msft status %d",
1955 			   handle, status);
1956 		break;
1957 	}
1958 
1959 	/* In case no matching handle registered, just free the monitor */
1960 	if (status == -ENOENT)
1961 		goto free_monitor;
1962 
1963 	return status;
1964 
1965 free_monitor:
1966 	if (status == -ENOENT)
1967 		bt_dev_warn(hdev, "Removing monitor with no matching handle %d",
1968 			    monitor->handle);
1969 	hci_free_adv_monitor(hdev, monitor);
1970 
1971 	return status;
1972 }
1973 
1974 /* This function requires the caller holds hci_req_sync_lock */
1975 int hci_remove_single_adv_monitor(struct hci_dev *hdev, u16 handle)
1976 {
1977 	struct adv_monitor *monitor = idr_find(&hdev->adv_monitors_idr, handle);
1978 
1979 	if (!monitor)
1980 		return -EINVAL;
1981 
1982 	return hci_remove_adv_monitor(hdev, monitor);
1983 }
1984 
1985 /* This function requires the caller holds hci_req_sync_lock */
1986 int hci_remove_all_adv_monitor(struct hci_dev *hdev)
1987 {
1988 	struct adv_monitor *monitor;
1989 	int idr_next_id = 0;
1990 	int status = 0;
1991 
1992 	while (1) {
1993 		monitor = idr_get_next(&hdev->adv_monitors_idr, &idr_next_id);
1994 		if (!monitor)
1995 			break;
1996 
1997 		status = hci_remove_adv_monitor(hdev, monitor);
1998 		if (status)
1999 			return status;
2000 
2001 		idr_next_id++;
2002 	}
2003 
2004 	return status;
2005 }
2006 
2007 /* This function requires the caller holds hdev->lock */
2008 bool hci_is_adv_monitoring(struct hci_dev *hdev)
2009 {
2010 	return !idr_is_empty(&hdev->adv_monitors_idr);
2011 }
2012 
2013 int hci_get_adv_monitor_offload_ext(struct hci_dev *hdev)
2014 {
2015 	if (msft_monitor_supported(hdev))
2016 		return HCI_ADV_MONITOR_EXT_MSFT;
2017 
2018 	return HCI_ADV_MONITOR_EXT_NONE;
2019 }
2020 
2021 struct bdaddr_list *hci_bdaddr_list_lookup(struct list_head *bdaddr_list,
2022 					 bdaddr_t *bdaddr, u8 type)
2023 {
2024 	struct bdaddr_list *b;
2025 
2026 	list_for_each_entry(b, bdaddr_list, list) {
2027 		if (!bacmp(&b->bdaddr, bdaddr) && b->bdaddr_type == type)
2028 			return b;
2029 	}
2030 
2031 	return NULL;
2032 }
2033 
2034 struct bdaddr_list_with_irk *hci_bdaddr_list_lookup_with_irk(
2035 				struct list_head *bdaddr_list, bdaddr_t *bdaddr,
2036 				u8 type)
2037 {
2038 	struct bdaddr_list_with_irk *b;
2039 
2040 	list_for_each_entry(b, bdaddr_list, list) {
2041 		if (!bacmp(&b->bdaddr, bdaddr) && b->bdaddr_type == type)
2042 			return b;
2043 	}
2044 
2045 	return NULL;
2046 }
2047 
2048 struct bdaddr_list_with_flags *
2049 hci_bdaddr_list_lookup_with_flags(struct list_head *bdaddr_list,
2050 				  bdaddr_t *bdaddr, u8 type)
2051 {
2052 	struct bdaddr_list_with_flags *b;
2053 
2054 	list_for_each_entry(b, bdaddr_list, list) {
2055 		if (!bacmp(&b->bdaddr, bdaddr) && b->bdaddr_type == type)
2056 			return b;
2057 	}
2058 
2059 	return NULL;
2060 }
2061 
2062 void hci_bdaddr_list_clear(struct list_head *bdaddr_list)
2063 {
2064 	struct bdaddr_list *b, *n;
2065 
2066 	list_for_each_entry_safe(b, n, bdaddr_list, list) {
2067 		list_del(&b->list);
2068 		kfree(b);
2069 	}
2070 }
2071 
2072 int hci_bdaddr_list_add(struct list_head *list, bdaddr_t *bdaddr, u8 type)
2073 {
2074 	struct bdaddr_list *entry;
2075 
2076 	if (!bacmp(bdaddr, BDADDR_ANY))
2077 		return -EBADF;
2078 
2079 	if (hci_bdaddr_list_lookup(list, bdaddr, type))
2080 		return -EEXIST;
2081 
2082 	entry = kzalloc_obj(*entry);
2083 	if (!entry)
2084 		return -ENOMEM;
2085 
2086 	bacpy(&entry->bdaddr, bdaddr);
2087 	entry->bdaddr_type = type;
2088 
2089 	list_add(&entry->list, list);
2090 
2091 	return 0;
2092 }
2093 
2094 int hci_bdaddr_list_add_with_irk(struct list_head *list, bdaddr_t *bdaddr,
2095 					u8 type, u8 *peer_irk, u8 *local_irk)
2096 {
2097 	struct bdaddr_list_with_irk *entry;
2098 
2099 	if (!bacmp(bdaddr, BDADDR_ANY))
2100 		return -EBADF;
2101 
2102 	if (hci_bdaddr_list_lookup(list, bdaddr, type))
2103 		return -EEXIST;
2104 
2105 	entry = kzalloc_obj(*entry);
2106 	if (!entry)
2107 		return -ENOMEM;
2108 
2109 	bacpy(&entry->bdaddr, bdaddr);
2110 	entry->bdaddr_type = type;
2111 
2112 	if (peer_irk)
2113 		memcpy(entry->peer_irk, peer_irk, 16);
2114 
2115 	if (local_irk)
2116 		memcpy(entry->local_irk, local_irk, 16);
2117 
2118 	list_add(&entry->list, list);
2119 
2120 	return 0;
2121 }
2122 
2123 int hci_bdaddr_list_add_with_flags(struct list_head *list, bdaddr_t *bdaddr,
2124 				   u8 type, u32 flags)
2125 {
2126 	struct bdaddr_list_with_flags *entry;
2127 
2128 	if (!bacmp(bdaddr, BDADDR_ANY))
2129 		return -EBADF;
2130 
2131 	if (hci_bdaddr_list_lookup(list, bdaddr, type))
2132 		return -EEXIST;
2133 
2134 	entry = kzalloc_obj(*entry);
2135 	if (!entry)
2136 		return -ENOMEM;
2137 
2138 	bacpy(&entry->bdaddr, bdaddr);
2139 	entry->bdaddr_type = type;
2140 	entry->flags = flags;
2141 
2142 	list_add(&entry->list, list);
2143 
2144 	return 0;
2145 }
2146 
2147 int hci_bdaddr_list_del(struct list_head *list, bdaddr_t *bdaddr, u8 type)
2148 {
2149 	struct bdaddr_list *entry;
2150 
2151 	if (!bacmp(bdaddr, BDADDR_ANY)) {
2152 		hci_bdaddr_list_clear(list);
2153 		return 0;
2154 	}
2155 
2156 	entry = hci_bdaddr_list_lookup(list, bdaddr, type);
2157 	if (!entry)
2158 		return -ENOENT;
2159 
2160 	list_del(&entry->list);
2161 	kfree(entry);
2162 
2163 	return 0;
2164 }
2165 
2166 int hci_bdaddr_list_del_with_irk(struct list_head *list, bdaddr_t *bdaddr,
2167 							u8 type)
2168 {
2169 	struct bdaddr_list_with_irk *entry;
2170 
2171 	if (!bacmp(bdaddr, BDADDR_ANY)) {
2172 		hci_bdaddr_list_clear(list);
2173 		return 0;
2174 	}
2175 
2176 	entry = hci_bdaddr_list_lookup_with_irk(list, bdaddr, type);
2177 	if (!entry)
2178 		return -ENOENT;
2179 
2180 	list_del(&entry->list);
2181 	kfree(entry);
2182 
2183 	return 0;
2184 }
2185 
2186 /* This function requires the caller holds hdev->lock */
2187 struct hci_conn_params *hci_conn_params_lookup(struct hci_dev *hdev,
2188 					       bdaddr_t *addr, u8 addr_type)
2189 {
2190 	struct hci_conn_params *params;
2191 
2192 	list_for_each_entry(params, &hdev->le_conn_params, list) {
2193 		if (bacmp(&params->addr, addr) == 0 &&
2194 		    params->addr_type == addr_type) {
2195 			return params;
2196 		}
2197 	}
2198 
2199 	return NULL;
2200 }
2201 
2202 /* This function requires the caller holds hdev->lock or rcu_read_lock */
2203 struct hci_conn_params *hci_pend_le_action_lookup(struct list_head *list,
2204 						  bdaddr_t *addr, u8 addr_type)
2205 {
2206 	struct hci_conn_params *param;
2207 
2208 	rcu_read_lock();
2209 
2210 	list_for_each_entry_rcu(param, list, action) {
2211 		if (bacmp(&param->addr, addr) == 0 &&
2212 		    param->addr_type == addr_type) {
2213 			rcu_read_unlock();
2214 			return param;
2215 		}
2216 	}
2217 
2218 	rcu_read_unlock();
2219 
2220 	return NULL;
2221 }
2222 
2223 /* This function requires the caller holds hdev->lock */
2224 void hci_pend_le_list_del_init(struct hci_conn_params *param)
2225 {
2226 	if (list_empty(&param->action))
2227 		return;
2228 
2229 	list_del_rcu(&param->action);
2230 	synchronize_rcu();
2231 	INIT_LIST_HEAD(&param->action);
2232 }
2233 
2234 /* This function requires the caller holds hdev->lock */
2235 void hci_pend_le_list_add(struct hci_conn_params *param,
2236 			  struct list_head *list)
2237 {
2238 	list_add_rcu(&param->action, list);
2239 }
2240 
2241 /* This function requires the caller holds hdev->lock */
2242 struct hci_conn_params *hci_conn_params_add(struct hci_dev *hdev,
2243 					    bdaddr_t *addr, u8 addr_type)
2244 {
2245 	struct hci_conn_params *params;
2246 
2247 	params = hci_conn_params_lookup(hdev, addr, addr_type);
2248 	if (params)
2249 		return params;
2250 
2251 	params = kzalloc_obj(*params);
2252 	if (!params) {
2253 		bt_dev_err(hdev, "out of memory");
2254 		return NULL;
2255 	}
2256 
2257 	bacpy(&params->addr, addr);
2258 	params->addr_type = addr_type;
2259 
2260 	list_add(&params->list, &hdev->le_conn_params);
2261 	INIT_LIST_HEAD(&params->action);
2262 
2263 	params->conn_min_interval = hdev->le_conn_min_interval;
2264 	params->conn_max_interval = hdev->le_conn_max_interval;
2265 	params->conn_latency = hdev->le_conn_latency;
2266 	params->supervision_timeout = hdev->le_supv_timeout;
2267 	params->auto_connect = HCI_AUTO_CONN_DISABLED;
2268 
2269 	BT_DBG("addr %pMR (type %u)", addr, addr_type);
2270 
2271 	return params;
2272 }
2273 
2274 void hci_conn_params_free(struct hci_conn_params *params)
2275 {
2276 	hci_pend_le_list_del_init(params);
2277 
2278 	if (params->conn) {
2279 		hci_conn_drop(params->conn);
2280 		hci_conn_put(params->conn);
2281 	}
2282 
2283 	list_del(&params->list);
2284 	kfree(params);
2285 }
2286 
2287 /* This function requires the caller holds hdev->lock */
2288 void hci_conn_params_del(struct hci_dev *hdev, bdaddr_t *addr, u8 addr_type)
2289 {
2290 	struct hci_conn_params *params;
2291 
2292 	params = hci_conn_params_lookup(hdev, addr, addr_type);
2293 	if (!params)
2294 		return;
2295 
2296 	hci_conn_params_free(params);
2297 
2298 	hci_update_passive_scan(hdev);
2299 
2300 	BT_DBG("addr %pMR (type %u)", addr, addr_type);
2301 }
2302 
2303 /* This function requires the caller holds hdev->lock */
2304 void hci_conn_params_clear_disabled(struct hci_dev *hdev)
2305 {
2306 	struct hci_conn_params *params, *tmp;
2307 
2308 	list_for_each_entry_safe(params, tmp, &hdev->le_conn_params, list) {
2309 		if (params->auto_connect != HCI_AUTO_CONN_DISABLED)
2310 			continue;
2311 
2312 		/* If trying to establish one time connection to disabled
2313 		 * device, leave the params, but mark them as just once.
2314 		 */
2315 		if (params->explicit_connect) {
2316 			params->auto_connect = HCI_AUTO_CONN_EXPLICIT;
2317 			continue;
2318 		}
2319 
2320 		hci_conn_params_free(params);
2321 	}
2322 
2323 	BT_DBG("All LE disabled connection parameters were removed");
2324 }
2325 
2326 /* This function requires the caller holds hdev->lock */
2327 static void hci_conn_params_clear_all(struct hci_dev *hdev)
2328 {
2329 	struct hci_conn_params *params, *tmp;
2330 
2331 	list_for_each_entry_safe(params, tmp, &hdev->le_conn_params, list)
2332 		hci_conn_params_free(params);
2333 
2334 	BT_DBG("All LE connection parameters were removed");
2335 }
2336 
2337 /* Copy the Identity Address of the controller.
2338  *
2339  * If the controller has a public BD_ADDR, then by default use that one.
2340  * If this is a LE only controller without a public address, default to
2341  * the static random address.
2342  *
2343  * For debugging purposes it is possible to force controllers with a
2344  * public address to use the static random address instead.
2345  *
2346  * In case BR/EDR has been disabled on a dual-mode controller and
2347  * userspace has configured a static address, then that address
2348  * becomes the identity address instead of the public BR/EDR address.
2349  */
2350 void hci_copy_identity_address(struct hci_dev *hdev, bdaddr_t *bdaddr,
2351 			       u8 *bdaddr_type)
2352 {
2353 	if (hci_dev_test_flag(hdev, HCI_FORCE_STATIC_ADDR) ||
2354 	    !bacmp(&hdev->bdaddr, BDADDR_ANY) ||
2355 	    (!hci_dev_test_flag(hdev, HCI_BREDR_ENABLED) &&
2356 	     bacmp(&hdev->static_addr, BDADDR_ANY))) {
2357 		bacpy(bdaddr, &hdev->static_addr);
2358 		*bdaddr_type = ADDR_LE_DEV_RANDOM;
2359 	} else {
2360 		bacpy(bdaddr, &hdev->bdaddr);
2361 		*bdaddr_type = ADDR_LE_DEV_PUBLIC;
2362 	}
2363 }
2364 
2365 static void hci_clear_wake_reason(struct hci_dev *hdev)
2366 {
2367 	hci_dev_lock(hdev);
2368 
2369 	hdev->wake_reason = 0;
2370 	bacpy(&hdev->wake_addr, BDADDR_ANY);
2371 	hdev->wake_addr_type = 0;
2372 
2373 	hci_dev_unlock(hdev);
2374 }
2375 
2376 static int hci_suspend_notifier(struct notifier_block *nb, unsigned long action,
2377 				void *data)
2378 {
2379 	struct hci_dev *hdev =
2380 		container_of(nb, struct hci_dev, suspend_notifier);
2381 	int ret = 0;
2382 
2383 	/* Userspace has full control of this device. Do nothing. */
2384 	if (hci_dev_test_flag(hdev, HCI_USER_CHANNEL))
2385 		return NOTIFY_DONE;
2386 
2387 	/* To avoid a potential race with hci_unregister_dev. */
2388 	hci_dev_hold(hdev);
2389 
2390 	switch (action) {
2391 	case PM_HIBERNATION_PREPARE:
2392 	case PM_SUSPEND_PREPARE:
2393 		ret = hci_suspend_dev(hdev);
2394 		break;
2395 	case PM_POST_HIBERNATION:
2396 	case PM_POST_SUSPEND:
2397 		ret = hci_resume_dev(hdev);
2398 		break;
2399 	}
2400 
2401 	if (ret)
2402 		bt_dev_err(hdev, "Suspend notifier action (%lu) failed: %d",
2403 			   action, ret);
2404 
2405 	hci_dev_put(hdev);
2406 	return NOTIFY_DONE;
2407 }
2408 
2409 /* Alloc HCI device */
2410 struct hci_dev *hci_alloc_dev_priv(int sizeof_priv)
2411 {
2412 	struct hci_dev *hdev;
2413 	unsigned int alloc_size;
2414 
2415 	alloc_size = sizeof(*hdev);
2416 	if (sizeof_priv) {
2417 		/* Fixme: May need ALIGN-ment? */
2418 		alloc_size += sizeof_priv;
2419 	}
2420 
2421 	hdev = kzalloc(alloc_size, GFP_KERNEL);
2422 	if (!hdev)
2423 		return NULL;
2424 
2425 	if (init_srcu_struct(&hdev->srcu)) {
2426 		kfree(hdev);
2427 		return NULL;
2428 	}
2429 
2430 	hdev->pkt_type  = (HCI_DM1 | HCI_DH1 | HCI_HV1);
2431 	hdev->esco_type = (ESCO_HV1);
2432 	hdev->link_mode = (HCI_LM_ACCEPT);
2433 	hdev->num_iac = 0x01;		/* One IAC support is mandatory */
2434 	hdev->io_capability = 0x03;	/* No Input No Output */
2435 	hdev->manufacturer = 0xffff;	/* Default to internal use */
2436 	hdev->inq_tx_power = HCI_TX_POWER_INVALID;
2437 	hdev->adv_tx_power = HCI_TX_POWER_INVALID;
2438 	hdev->adv_instance_cnt = 0;
2439 	hdev->cur_adv_instance = 0x00;
2440 	hdev->adv_instance_timeout = 0;
2441 
2442 	hdev->advmon_allowlist_duration = 300;
2443 	hdev->advmon_no_filter_duration = 500;
2444 	hdev->enable_advmon_interleave_scan = 0x00;	/* Default to disable */
2445 
2446 	hdev->sniff_max_interval = 800;
2447 	hdev->sniff_min_interval = 80;
2448 
2449 	hdev->le_adv_channel_map = 0x07;
2450 	hdev->le_adv_min_interval = 0x0800;
2451 	hdev->le_adv_max_interval = 0x0800;
2452 	hdev->le_scan_interval = DISCOV_LE_SCAN_INT_FAST;
2453 	hdev->le_scan_window = DISCOV_LE_SCAN_WIN_FAST;
2454 	hdev->le_scan_int_suspend = DISCOV_LE_SCAN_INT_SLOW1;
2455 	hdev->le_scan_window_suspend = DISCOV_LE_SCAN_WIN_SLOW1;
2456 	hdev->le_scan_int_discovery = DISCOV_LE_SCAN_INT;
2457 	hdev->le_scan_window_discovery = DISCOV_LE_SCAN_WIN;
2458 	hdev->le_scan_int_adv_monitor = DISCOV_LE_SCAN_INT_FAST;
2459 	hdev->le_scan_window_adv_monitor = DISCOV_LE_SCAN_WIN_FAST;
2460 	hdev->le_scan_int_connect = DISCOV_LE_SCAN_INT_CONN;
2461 	hdev->le_scan_window_connect = DISCOV_LE_SCAN_WIN_CONN;
2462 	hdev->le_conn_min_interval = 0x0018;
2463 	hdev->le_conn_max_interval = 0x0028;
2464 	hdev->le_conn_latency = 0x0000;
2465 	hdev->le_supv_timeout = 0x002a;
2466 	hdev->le_def_tx_len = 0x001b;
2467 	hdev->le_def_tx_time = 0x0148;
2468 	hdev->le_max_tx_len = 0x001b;
2469 	hdev->le_max_tx_time = 0x0148;
2470 	hdev->le_max_rx_len = 0x001b;
2471 	hdev->le_max_rx_time = 0x0148;
2472 	hdev->le_max_key_size = SMP_MAX_ENC_KEY_SIZE;
2473 	hdev->le_min_key_size = SMP_MIN_ENC_KEY_SIZE;
2474 	hdev->le_tx_def_phys = HCI_LE_SET_PHY_1M;
2475 	hdev->le_rx_def_phys = HCI_LE_SET_PHY_1M;
2476 	hdev->le_num_of_adv_sets = HCI_MAX_ADV_INSTANCES;
2477 	hdev->def_multi_adv_rotation_duration = HCI_DEFAULT_ADV_DURATION;
2478 	hdev->def_le_autoconnect_timeout = HCI_LE_CONN_TIMEOUT;
2479 	hdev->min_le_tx_power = HCI_TX_POWER_INVALID;
2480 	hdev->max_le_tx_power = HCI_TX_POWER_INVALID;
2481 
2482 	hdev->rpa_timeout = HCI_DEFAULT_RPA_TIMEOUT;
2483 	hdev->discov_interleaved_timeout = DISCOV_INTERLEAVED_TIMEOUT;
2484 	hdev->conn_info_min_age = DEFAULT_CONN_INFO_MIN_AGE;
2485 	hdev->conn_info_max_age = DEFAULT_CONN_INFO_MAX_AGE;
2486 	hdev->auth_payload_timeout = DEFAULT_AUTH_PAYLOAD_TIMEOUT;
2487 	hdev->min_enc_key_size = HCI_MIN_ENC_KEY_SIZE;
2488 
2489 	/* default 1.28 sec page scan */
2490 	hdev->def_page_scan_type = PAGE_SCAN_TYPE_STANDARD;
2491 	hdev->def_page_scan_int = 0x0800;
2492 	hdev->def_page_scan_window = 0x0012;
2493 
2494 	mutex_init(&hdev->lock);
2495 	mutex_init(&hdev->req_lock);
2496 	mutex_init(&hdev->mgmt_pending_lock);
2497 	mutex_init(&hdev->remote_oob_lock);
2498 
2499 	ida_init(&hdev->unset_handle_ida);
2500 
2501 	INIT_LIST_HEAD(&hdev->mesh_pending);
2502 	INIT_LIST_HEAD(&hdev->mgmt_pending);
2503 	INIT_LIST_HEAD(&hdev->reject_list);
2504 	INIT_LIST_HEAD(&hdev->accept_list);
2505 	INIT_LIST_HEAD(&hdev->uuids);
2506 	INIT_LIST_HEAD(&hdev->link_keys);
2507 	INIT_LIST_HEAD(&hdev->long_term_keys);
2508 	INIT_LIST_HEAD(&hdev->identity_resolving_keys);
2509 	INIT_LIST_HEAD(&hdev->remote_oob_data);
2510 	INIT_LIST_HEAD(&hdev->le_accept_list);
2511 	INIT_LIST_HEAD(&hdev->le_resolv_list);
2512 	INIT_LIST_HEAD(&hdev->le_conn_params);
2513 	INIT_LIST_HEAD(&hdev->pend_le_conns);
2514 	INIT_LIST_HEAD(&hdev->pend_le_reports);
2515 	INIT_LIST_HEAD(&hdev->conn_hash.list);
2516 	INIT_LIST_HEAD(&hdev->adv_instances);
2517 	INIT_LIST_HEAD(&hdev->blocked_keys);
2518 	INIT_LIST_HEAD(&hdev->monitored_devices);
2519 
2520 	INIT_LIST_HEAD(&hdev->local_codecs);
2521 	INIT_WORK(&hdev->rx_work, hci_rx_work);
2522 	INIT_WORK(&hdev->cmd_work, hci_cmd_work);
2523 	INIT_WORK(&hdev->tx_work, hci_tx_work);
2524 	INIT_WORK(&hdev->power_on, hci_power_on);
2525 	INIT_WORK(&hdev->error_reset, hci_error_reset);
2526 
2527 	hci_cmd_sync_init(hdev);
2528 
2529 	INIT_DELAYED_WORK(&hdev->power_off, hci_power_off);
2530 
2531 	skb_queue_head_init(&hdev->rx_q);
2532 	skb_queue_head_init(&hdev->cmd_q);
2533 	skb_queue_head_init(&hdev->raw_q);
2534 
2535 	init_waitqueue_head(&hdev->req_wait_q);
2536 
2537 	INIT_DELAYED_WORK(&hdev->cmd_timer, hci_cmd_timeout);
2538 	INIT_DELAYED_WORK(&hdev->ncmd_timer, hci_ncmd_timeout);
2539 
2540 	hci_devcd_setup(hdev);
2541 
2542 	hci_init_sysfs(hdev);
2543 	discovery_init(hdev);
2544 
2545 	return hdev;
2546 }
2547 EXPORT_SYMBOL(hci_alloc_dev_priv);
2548 
2549 /* Free HCI device */
2550 void hci_free_dev(struct hci_dev *hdev)
2551 {
2552 	/* will free via device release */
2553 	put_device(&hdev->dev);
2554 }
2555 EXPORT_SYMBOL(hci_free_dev);
2556 
2557 /* Register HCI device */
2558 int hci_register_dev(struct hci_dev *hdev)
2559 {
2560 	int id, error;
2561 
2562 	if (!hdev->open || !hdev->close || !hdev->send)
2563 		return -EINVAL;
2564 
2565 	id = ida_alloc_max(&hci_index_ida, HCI_MAX_ID - 1, GFP_KERNEL);
2566 	if (id < 0)
2567 		return id;
2568 
2569 	error = dev_set_name(&hdev->dev, "hci%u", id);
2570 	if (error) {
2571 		ida_free(&hci_index_ida, id);
2572 		return error;
2573 	}
2574 
2575 	hdev->name = dev_name(&hdev->dev);
2576 	hdev->id = id;
2577 
2578 	BT_DBG("%p name %s bus %d", hdev, hdev->name, hdev->bus);
2579 
2580 	hdev->workqueue = alloc_ordered_workqueue("%s", WQ_HIGHPRI, hdev->name);
2581 	if (!hdev->workqueue) {
2582 		error = -ENOMEM;
2583 		goto err;
2584 	}
2585 
2586 	hdev->req_workqueue = alloc_ordered_workqueue("%s", WQ_HIGHPRI,
2587 						      hdev->name);
2588 	if (!hdev->req_workqueue) {
2589 		destroy_workqueue(hdev->workqueue);
2590 		error = -ENOMEM;
2591 		goto err;
2592 	}
2593 
2594 	if (!IS_ERR_OR_NULL(bt_debugfs))
2595 		hdev->debugfs = debugfs_create_dir(hdev->name, bt_debugfs);
2596 
2597 	error = device_add(&hdev->dev);
2598 	if (error < 0)
2599 		goto err_wqueue;
2600 
2601 	hci_leds_init(hdev);
2602 
2603 	hdev->rfkill = rfkill_alloc(hdev->name, &hdev->dev,
2604 				    RFKILL_TYPE_BLUETOOTH, &hci_rfkill_ops,
2605 				    hdev);
2606 	if (hdev->rfkill) {
2607 		if (rfkill_register(hdev->rfkill) < 0) {
2608 			rfkill_destroy(hdev->rfkill);
2609 			hdev->rfkill = NULL;
2610 		}
2611 	}
2612 
2613 	if (hdev->rfkill && rfkill_blocked(hdev->rfkill))
2614 		hci_dev_set_flag(hdev, HCI_RFKILLED);
2615 
2616 	hci_dev_set_flag(hdev, HCI_SETUP);
2617 	hci_dev_set_flag(hdev, HCI_AUTO_OFF);
2618 
2619 	/* Assume BR/EDR support until proven otherwise (such as
2620 	 * through reading supported features during init.
2621 	 */
2622 	hci_dev_set_flag(hdev, HCI_BREDR_ENABLED);
2623 
2624 	write_lock(&hci_dev_list_lock);
2625 	list_add(&hdev->list, &hci_dev_list);
2626 	write_unlock(&hci_dev_list_lock);
2627 
2628 	/* Devices that are marked for raw-only usage are unconfigured
2629 	 * and should not be included in normal operation.
2630 	 */
2631 	if (hci_test_quirk(hdev, HCI_QUIRK_RAW_DEVICE))
2632 		hci_dev_set_flag(hdev, HCI_UNCONFIGURED);
2633 
2634 	/* Mark Remote Wakeup connection flag as supported if driver has wakeup
2635 	 * callback.
2636 	 */
2637 	if (hdev->wakeup)
2638 		hdev->conn_flags |= HCI_CONN_FLAG_REMOTE_WAKEUP;
2639 
2640 	hci_sock_dev_event(hdev, HCI_DEV_REG);
2641 	hci_dev_hold(hdev);
2642 
2643 	error = hci_register_suspend_notifier(hdev);
2644 	if (error)
2645 		BT_WARN("register suspend notifier failed error:%d\n", error);
2646 
2647 	idr_init(&hdev->adv_monitors_idr);
2648 	msft_register(hdev);
2649 
2650 	queue_work(hdev->req_workqueue, &hdev->power_on);
2651 
2652 	return id;
2653 
2654 err_wqueue:
2655 	debugfs_remove_recursive(hdev->debugfs);
2656 	destroy_workqueue(hdev->workqueue);
2657 	destroy_workqueue(hdev->req_workqueue);
2658 err:
2659 	ida_free(&hci_index_ida, hdev->id);
2660 
2661 	return error;
2662 }
2663 EXPORT_SYMBOL(hci_register_dev);
2664 
2665 /* Unregister HCI device */
2666 void hci_unregister_dev(struct hci_dev *hdev)
2667 {
2668 	BT_DBG("%p name %s bus %d", hdev, hdev->name, hdev->bus);
2669 
2670 	mutex_lock(&hdev->unregister_lock);
2671 	hci_dev_set_flag(hdev, HCI_UNREGISTER);
2672 	mutex_unlock(&hdev->unregister_lock);
2673 
2674 	write_lock(&hci_dev_list_lock);
2675 	list_del(&hdev->list);
2676 	write_unlock(&hci_dev_list_lock);
2677 
2678 	synchronize_srcu(&hdev->srcu);
2679 	cleanup_srcu_struct(&hdev->srcu);
2680 
2681 	disable_work_sync(&hdev->rx_work);
2682 	disable_work_sync(&hdev->cmd_work);
2683 	disable_work_sync(&hdev->tx_work);
2684 	disable_work_sync(&hdev->power_on);
2685 	disable_work_sync(&hdev->error_reset);
2686 	disable_delayed_work_sync(&hdev->cmd_timer);
2687 	disable_delayed_work_sync(&hdev->ncmd_timer);
2688 	hci_devcd_shutdown(hdev);
2689 
2690 	hci_cmd_sync_clear(hdev);
2691 
2692 	hci_unregister_suspend_notifier(hdev);
2693 
2694 	hci_dev_do_close(hdev);
2695 
2696 	if (!test_bit(HCI_INIT, &hdev->flags) &&
2697 	    !hci_dev_test_flag(hdev, HCI_SETUP) &&
2698 	    !hci_dev_test_flag(hdev, HCI_CONFIG)) {
2699 		hci_dev_lock(hdev);
2700 		mgmt_index_removed(hdev);
2701 		hci_dev_unlock(hdev);
2702 	}
2703 
2704 	/* mgmt_index_removed should take care of emptying the
2705 	 * pending list */
2706 	BUG_ON(!list_empty(&hdev->mgmt_pending));
2707 
2708 	hci_sock_dev_event(hdev, HCI_DEV_UNREG);
2709 
2710 	if (hdev->rfkill) {
2711 		rfkill_unregister(hdev->rfkill);
2712 		rfkill_destroy(hdev->rfkill);
2713 	}
2714 
2715 	device_del(&hdev->dev);
2716 	/* Actual cleanup is deferred until hci_release_dev(). */
2717 	hci_dev_put(hdev);
2718 }
2719 EXPORT_SYMBOL(hci_unregister_dev);
2720 
2721 /* Release HCI device */
2722 void hci_release_dev(struct hci_dev *hdev)
2723 {
2724 	debugfs_remove_recursive(hdev->debugfs);
2725 	kfree_const(hdev->hw_info);
2726 	kfree_const(hdev->fw_info);
2727 
2728 	destroy_workqueue(hdev->workqueue);
2729 	destroy_workqueue(hdev->req_workqueue);
2730 
2731 	hci_dev_lock(hdev);
2732 	hci_bdaddr_list_clear(&hdev->reject_list);
2733 	hci_bdaddr_list_clear(&hdev->accept_list);
2734 	hci_uuids_clear(hdev);
2735 	hci_link_keys_clear(hdev);
2736 	hci_smp_ltks_clear(hdev);
2737 	hci_smp_irks_clear(hdev);
2738 	hci_remote_oob_data_clear(hdev);
2739 	hci_adv_instances_clear(hdev);
2740 	hci_adv_monitors_clear(hdev);
2741 	hci_bdaddr_list_clear(&hdev->le_accept_list);
2742 	hci_bdaddr_list_clear(&hdev->le_resolv_list);
2743 	hci_conn_params_clear_all(hdev);
2744 	hci_discovery_filter_clear(hdev);
2745 	hci_blocked_keys_clear(hdev);
2746 	hci_codec_list_clear(&hdev->local_codecs);
2747 	msft_release(hdev);
2748 	hci_dev_unlock(hdev);
2749 
2750 	ida_destroy(&hdev->unset_handle_ida);
2751 	ida_free(&hci_index_ida, hdev->id);
2752 	kfree_skb(hdev->sent_cmd);
2753 	kfree_skb(hdev->req_skb);
2754 	kfree_skb(hdev->recv_event);
2755 	kfree(hdev);
2756 }
2757 EXPORT_SYMBOL(hci_release_dev);
2758 
2759 int hci_register_suspend_notifier(struct hci_dev *hdev)
2760 {
2761 	int ret = 0;
2762 
2763 	if (!hdev->suspend_notifier.notifier_call &&
2764 	    !hci_test_quirk(hdev, HCI_QUIRK_NO_SUSPEND_NOTIFIER)) {
2765 		hdev->suspend_notifier.notifier_call = hci_suspend_notifier;
2766 		ret = register_pm_notifier(&hdev->suspend_notifier);
2767 	}
2768 
2769 	return ret;
2770 }
2771 
2772 int hci_unregister_suspend_notifier(struct hci_dev *hdev)
2773 {
2774 	int ret = 0;
2775 
2776 	if (hdev->suspend_notifier.notifier_call) {
2777 		ret = unregister_pm_notifier(&hdev->suspend_notifier);
2778 		if (!ret)
2779 			hdev->suspend_notifier.notifier_call = NULL;
2780 	}
2781 
2782 	return ret;
2783 }
2784 
2785 /* Cancel ongoing command synchronously:
2786  *
2787  * - Cancel command timer
2788  * - Reset command counter
2789  * - Cancel command request
2790  */
2791 static void hci_cancel_cmd_sync(struct hci_dev *hdev, int err)
2792 {
2793 	bt_dev_dbg(hdev, "err 0x%2.2x", err);
2794 
2795 	if (hci_dev_test_flag(hdev, HCI_UNREGISTER)) {
2796 		disable_delayed_work_sync(&hdev->cmd_timer);
2797 		disable_delayed_work_sync(&hdev->ncmd_timer);
2798 	} else  {
2799 		cancel_delayed_work_sync(&hdev->cmd_timer);
2800 		cancel_delayed_work_sync(&hdev->ncmd_timer);
2801 	}
2802 
2803 	atomic_set(&hdev->cmd_cnt, 1);
2804 
2805 	hci_cmd_sync_cancel_sync(hdev, err);
2806 }
2807 
2808 /* Suspend HCI device */
2809 int hci_suspend_dev(struct hci_dev *hdev)
2810 {
2811 	int ret;
2812 
2813 	bt_dev_dbg(hdev, "");
2814 
2815 	/* Suspend should only act on when powered. */
2816 	if (!hdev_is_powered(hdev) ||
2817 	    hci_dev_test_flag(hdev, HCI_UNREGISTER))
2818 		return 0;
2819 
2820 	/* If powering down don't attempt to suspend */
2821 	if (mgmt_powering_down(hdev))
2822 		return 0;
2823 
2824 	/* Cancel potentially blocking sync operation before suspend */
2825 	hci_cancel_cmd_sync(hdev, EHOSTDOWN);
2826 
2827 	hci_req_sync_lock(hdev);
2828 	ret = hci_suspend_sync(hdev);
2829 	hci_req_sync_unlock(hdev);
2830 
2831 	hci_clear_wake_reason(hdev);
2832 	mgmt_suspending(hdev, hdev->suspend_state);
2833 
2834 	hci_sock_dev_event(hdev, HCI_DEV_SUSPEND);
2835 	return ret;
2836 }
2837 EXPORT_SYMBOL(hci_suspend_dev);
2838 
2839 /* Resume HCI device */
2840 int hci_resume_dev(struct hci_dev *hdev)
2841 {
2842 	int ret;
2843 
2844 	bt_dev_dbg(hdev, "");
2845 
2846 	/* Resume should only act on when powered. */
2847 	if (!hdev_is_powered(hdev) ||
2848 	    hci_dev_test_flag(hdev, HCI_UNREGISTER))
2849 		return 0;
2850 
2851 	/* If powering down don't attempt to resume */
2852 	if (mgmt_powering_down(hdev))
2853 		return 0;
2854 
2855 	hci_req_sync_lock(hdev);
2856 	ret = hci_resume_sync(hdev);
2857 	hci_req_sync_unlock(hdev);
2858 
2859 	mgmt_resuming(hdev, hdev->wake_reason, &hdev->wake_addr,
2860 		      hdev->wake_addr_type);
2861 
2862 	hci_sock_dev_event(hdev, HCI_DEV_RESUME);
2863 	return ret;
2864 }
2865 EXPORT_SYMBOL(hci_resume_dev);
2866 
2867 /* Reset HCI device */
2868 int __hci_reset_dev(struct hci_dev *hdev, u8 hw_err_code)
2869 {
2870 	const u8 hw_err[] = { HCI_EV_HARDWARE_ERROR, 0x01, hw_err_code };
2871 	struct sk_buff *skb;
2872 
2873 	skb = bt_skb_alloc(3, GFP_ATOMIC);
2874 	if (!skb)
2875 		return -ENOMEM;
2876 
2877 	hci_skb_pkt_type(skb) = HCI_EVENT_PKT;
2878 	skb_put_data(skb, hw_err, 3);
2879 
2880 	bt_dev_err(hdev, "Injecting HCI hardware error event");
2881 
2882 	/* Send Hardware Error to upper stack */
2883 	return hci_recv_frame(hdev, skb);
2884 }
2885 EXPORT_SYMBOL(__hci_reset_dev);
2886 
2887 static u8 hci_dev_classify_pkt_type(struct hci_dev *hdev, struct sk_buff *skb)
2888 {
2889 	if (hdev->classify_pkt_type)
2890 		return hdev->classify_pkt_type(hdev, skb);
2891 
2892 	return hci_skb_pkt_type(skb);
2893 }
2894 
2895 /* Receive frame from HCI drivers */
2896 int hci_recv_frame(struct hci_dev *hdev, struct sk_buff *skb)
2897 {
2898 	u8 dev_pkt_type;
2899 
2900 	if (!hdev || (!test_bit(HCI_UP, &hdev->flags)
2901 		      && !test_bit(HCI_INIT, &hdev->flags))) {
2902 		kfree_skb(skb);
2903 		return -ENXIO;
2904 	}
2905 
2906 	/* Check if the driver agree with packet type classification */
2907 	dev_pkt_type = hci_dev_classify_pkt_type(hdev, skb);
2908 	if (hci_skb_pkt_type(skb) != dev_pkt_type) {
2909 		hci_skb_pkt_type(skb) = dev_pkt_type;
2910 	}
2911 
2912 	switch (hci_skb_pkt_type(skb)) {
2913 	case HCI_EVENT_PKT:
2914 		break;
2915 	case HCI_ACLDATA_PKT:
2916 		/* Detect if ISO packet has been sent as ACL */
2917 		if (hci_conn_num(hdev, CIS_LINK) ||
2918 		    hci_conn_num(hdev, BIS_LINK) ||
2919 			hci_conn_num(hdev, PA_LINK)) {
2920 			__u8 type;
2921 
2922 			type = hci_conn_lookup_type(hdev, hci_acl_handle(skb));
2923 			if (type == CIS_LINK || type == BIS_LINK ||
2924 			    type == PA_LINK)
2925 				hci_skb_pkt_type(skb) = HCI_ISODATA_PKT;
2926 		}
2927 		break;
2928 	case HCI_SCODATA_PKT:
2929 		break;
2930 	case HCI_ISODATA_PKT:
2931 		break;
2932 	case HCI_DRV_PKT:
2933 		break;
2934 	default:
2935 		kfree_skb(skb);
2936 		return -EINVAL;
2937 	}
2938 
2939 	/* Incoming skb */
2940 	bt_cb(skb)->incoming = 1;
2941 
2942 	/* Time stamp */
2943 	__net_timestamp(skb);
2944 
2945 	skb_queue_tail(&hdev->rx_q, skb);
2946 	queue_work(hdev->workqueue, &hdev->rx_work);
2947 
2948 	return 0;
2949 }
2950 EXPORT_SYMBOL(hci_recv_frame);
2951 
2952 /* Receive diagnostic message from HCI drivers */
2953 int hci_recv_diag(struct hci_dev *hdev, struct sk_buff *skb)
2954 {
2955 	/* Mark as diagnostic packet */
2956 	hci_skb_pkt_type(skb) = HCI_DIAG_PKT;
2957 
2958 	/* Time stamp */
2959 	__net_timestamp(skb);
2960 
2961 	skb_queue_tail(&hdev->rx_q, skb);
2962 	queue_work(hdev->workqueue, &hdev->rx_work);
2963 
2964 	return 0;
2965 }
2966 EXPORT_SYMBOL(hci_recv_diag);
2967 
2968 void hci_set_hw_info(struct hci_dev *hdev, const char *fmt, ...)
2969 {
2970 	va_list vargs;
2971 
2972 	va_start(vargs, fmt);
2973 	kfree_const(hdev->hw_info);
2974 	hdev->hw_info = kvasprintf_const(GFP_KERNEL, fmt, vargs);
2975 	va_end(vargs);
2976 }
2977 EXPORT_SYMBOL(hci_set_hw_info);
2978 
2979 void hci_set_fw_info(struct hci_dev *hdev, const char *fmt, ...)
2980 {
2981 	va_list vargs;
2982 
2983 	va_start(vargs, fmt);
2984 	kfree_const(hdev->fw_info);
2985 	hdev->fw_info = kvasprintf_const(GFP_KERNEL, fmt, vargs);
2986 	va_end(vargs);
2987 }
2988 EXPORT_SYMBOL(hci_set_fw_info);
2989 
2990 /* ---- Interface to upper protocols ---- */
2991 
2992 int hci_register_cb(struct hci_cb *cb)
2993 {
2994 	BT_DBG("%p name %s", cb, cb->name);
2995 
2996 	mutex_lock(&hci_cb_list_lock);
2997 	list_add_tail(&cb->list, &hci_cb_list);
2998 	mutex_unlock(&hci_cb_list_lock);
2999 
3000 	return 0;
3001 }
3002 EXPORT_SYMBOL(hci_register_cb);
3003 
3004 int hci_unregister_cb(struct hci_cb *cb)
3005 {
3006 	BT_DBG("%p name %s", cb, cb->name);
3007 
3008 	mutex_lock(&hci_cb_list_lock);
3009 	list_del(&cb->list);
3010 	mutex_unlock(&hci_cb_list_lock);
3011 
3012 	return 0;
3013 }
3014 EXPORT_SYMBOL(hci_unregister_cb);
3015 
3016 static int hci_send_frame(struct hci_dev *hdev, struct sk_buff *skb)
3017 {
3018 	int err;
3019 
3020 	BT_DBG("%s type %d len %d", hdev->name, hci_skb_pkt_type(skb),
3021 	       skb->len);
3022 
3023 	/* Time stamp */
3024 	__net_timestamp(skb);
3025 
3026 	/* Send copy to monitor */
3027 	hci_send_to_monitor(hdev, skb);
3028 
3029 	if (atomic_read(&hdev->promisc)) {
3030 		/* Send copy to the sockets */
3031 		hci_send_to_sock(hdev, skb);
3032 	}
3033 
3034 	/* Get rid of skb owner, prior to sending to the driver. */
3035 	skb_orphan(skb);
3036 
3037 	if (!test_bit(HCI_RUNNING, &hdev->flags)) {
3038 		kfree_skb(skb);
3039 		return -EINVAL;
3040 	}
3041 
3042 	if (hci_skb_pkt_type(skb) == HCI_DRV_PKT) {
3043 		/* Intercept HCI Drv packet here and don't go with hdev->send
3044 		 * callback.
3045 		 */
3046 		err = hci_drv_process_cmd(hdev, skb);
3047 		kfree_skb(skb);
3048 		return err;
3049 	}
3050 
3051 	err = hdev->send(hdev, skb);
3052 	if (err < 0) {
3053 		bt_dev_err(hdev, "sending frame failed (%d)", err);
3054 		kfree_skb(skb);
3055 		return err;
3056 	}
3057 
3058 	return 0;
3059 }
3060 
3061 static int hci_send_conn_frame(struct hci_dev *hdev, struct hci_conn *conn,
3062 			       struct sk_buff *skb)
3063 {
3064 	hci_conn_tx_queue(conn, skb);
3065 	return hci_send_frame(hdev, skb);
3066 }
3067 
3068 /* Send HCI command */
3069 int hci_send_cmd(struct hci_dev *hdev, __u16 opcode, __u32 plen,
3070 		 const void *param)
3071 {
3072 	struct sk_buff *skb;
3073 
3074 	BT_DBG("%s opcode 0x%4.4x plen %d", hdev->name, opcode, plen);
3075 
3076 	skb = hci_cmd_sync_alloc(hdev, opcode, plen, param, NULL);
3077 	if (!skb) {
3078 		bt_dev_err(hdev, "no memory for command");
3079 		return -ENOMEM;
3080 	}
3081 
3082 	/* Stand-alone HCI commands must be flagged as
3083 	 * single-command requests.
3084 	 */
3085 	bt_cb(skb)->hci.req_flags |= HCI_REQ_START;
3086 
3087 	skb_queue_tail(&hdev->cmd_q, skb);
3088 	queue_work(hdev->workqueue, &hdev->cmd_work);
3089 
3090 	return 0;
3091 }
3092 
3093 int __hci_cmd_send(struct hci_dev *hdev, u16 opcode, u32 plen,
3094 		   const void *param)
3095 {
3096 	struct sk_buff *skb;
3097 
3098 	if (hci_opcode_ogf(opcode) != 0x3f) {
3099 		/* A controller receiving a command shall respond with either
3100 		 * a Command Status Event or a Command Complete Event.
3101 		 * Therefore, all standard HCI commands must be sent via the
3102 		 * standard API, using hci_send_cmd or hci_cmd_sync helpers.
3103 		 * Some vendors do not comply with this rule for vendor-specific
3104 		 * commands and do not return any event. We want to support
3105 		 * unresponded commands for such cases only.
3106 		 */
3107 		bt_dev_err(hdev, "unresponded command not supported");
3108 		return -EINVAL;
3109 	}
3110 
3111 	skb = hci_cmd_sync_alloc(hdev, opcode, plen, param, NULL);
3112 	if (!skb) {
3113 		bt_dev_err(hdev, "no memory for command (opcode 0x%4.4x)",
3114 			   opcode);
3115 		return -ENOMEM;
3116 	}
3117 
3118 	hci_send_frame(hdev, skb);
3119 
3120 	return 0;
3121 }
3122 EXPORT_SYMBOL(__hci_cmd_send);
3123 
3124 /* Get data from the previously sent command */
3125 static void *hci_cmd_data(struct sk_buff *skb, __u16 opcode)
3126 {
3127 	struct hci_command_hdr *hdr;
3128 
3129 	if (!skb || skb->len < HCI_COMMAND_HDR_SIZE)
3130 		return NULL;
3131 
3132 	hdr = (void *)skb->data;
3133 
3134 	if (hdr->opcode != cpu_to_le16(opcode))
3135 		return NULL;
3136 
3137 	return skb->data + HCI_COMMAND_HDR_SIZE;
3138 }
3139 
3140 /* Get data from the previously sent command */
3141 void *hci_sent_cmd_data(struct hci_dev *hdev, __u16 opcode)
3142 {
3143 	void *data;
3144 
3145 	/* Check if opcode matches last sent command */
3146 	data = hci_cmd_data(hdev->sent_cmd, opcode);
3147 	if (!data)
3148 		/* Check if opcode matches last request */
3149 		data = hci_cmd_data(hdev->req_skb, opcode);
3150 
3151 	return data;
3152 }
3153 
3154 /* Get data from last received event */
3155 void *hci_recv_event_data(struct hci_dev *hdev, __u8 event)
3156 {
3157 	struct hci_event_hdr *hdr;
3158 	int offset;
3159 
3160 	if (!hdev->recv_event)
3161 		return NULL;
3162 
3163 	hdr = (void *)hdev->recv_event->data;
3164 	offset = sizeof(*hdr);
3165 
3166 	if (hdr->evt != event) {
3167 		/* In case of LE metaevent check the subevent match */
3168 		if (hdr->evt == HCI_EV_LE_META) {
3169 			struct hci_ev_le_meta *ev;
3170 
3171 			ev = (void *)hdev->recv_event->data + offset;
3172 			offset += sizeof(*ev);
3173 			if (ev->subevent == event)
3174 				goto found;
3175 		}
3176 		return NULL;
3177 	}
3178 
3179 found:
3180 	bt_dev_dbg(hdev, "event 0x%2.2x", event);
3181 
3182 	return hdev->recv_event->data + offset;
3183 }
3184 
3185 /* Send ACL data */
3186 static void hci_add_acl_hdr(struct sk_buff *skb, __u16 handle, __u16 flags)
3187 {
3188 	struct hci_acl_hdr *hdr;
3189 	int len = skb->len;
3190 
3191 	skb_push(skb, HCI_ACL_HDR_SIZE);
3192 	skb_reset_transport_header(skb);
3193 	hdr = (struct hci_acl_hdr *)skb_transport_header(skb);
3194 	hdr->handle = cpu_to_le16(hci_handle_pack(handle, flags));
3195 	hdr->dlen   = cpu_to_le16(len);
3196 }
3197 
3198 static void hci_queue_acl(struct hci_chan *chan, struct sk_buff_head *queue,
3199 			  struct sk_buff *skb, __u16 flags)
3200 {
3201 	struct hci_conn *conn = chan->conn;
3202 	struct hci_dev *hdev = conn->hdev;
3203 	struct sk_buff *list;
3204 
3205 	skb->len = skb_headlen(skb);
3206 	skb->data_len = 0;
3207 
3208 	hci_skb_pkt_type(skb) = HCI_ACLDATA_PKT;
3209 
3210 	hci_add_acl_hdr(skb, conn->handle, flags);
3211 
3212 	list = skb_shinfo(skb)->frag_list;
3213 	if (!list) {
3214 		/* Non fragmented */
3215 		BT_DBG("%s nonfrag skb %p len %d", hdev->name, skb, skb->len);
3216 
3217 		skb_queue_tail(queue, skb);
3218 	} else {
3219 		/* Fragmented */
3220 		BT_DBG("%s frag %p len %d", hdev->name, skb, skb->len);
3221 
3222 		skb_shinfo(skb)->frag_list = NULL;
3223 
3224 		/* Queue all fragments atomically. We need to use spin_lock_bh
3225 		 * here because of 6LoWPAN links, as there this function is
3226 		 * called from softirq and using normal spin lock could cause
3227 		 * deadlocks.
3228 		 */
3229 		spin_lock_bh(&queue->lock);
3230 
3231 		__skb_queue_tail(queue, skb);
3232 
3233 		flags &= ~ACL_START;
3234 		flags |= ACL_CONT;
3235 		do {
3236 			skb = list; list = list->next;
3237 
3238 			hci_skb_pkt_type(skb) = HCI_ACLDATA_PKT;
3239 			hci_add_acl_hdr(skb, conn->handle, flags);
3240 
3241 			BT_DBG("%s frag %p len %d", hdev->name, skb, skb->len);
3242 
3243 			__skb_queue_tail(queue, skb);
3244 		} while (list);
3245 
3246 		spin_unlock_bh(&queue->lock);
3247 	}
3248 
3249 	bt_dev_dbg(hdev, "chan %p queued %d", chan, skb_queue_len(queue));
3250 }
3251 
3252 /* Queue hdev->tx_work, unless hdev->workqueue is being drained by
3253  * hci_dev_close_sync(), which would otherwise WARN and drop the work.
3254  */
3255 static void hci_sched_tx(struct hci_dev *hdev)
3256 {
3257 	rcu_read_lock();
3258 	if (!hci_dev_test_flag(hdev, HCI_CMD_DRAIN_WORKQUEUE))
3259 		queue_work(hdev->workqueue, &hdev->tx_work);
3260 	rcu_read_unlock();
3261 }
3262 
3263 void hci_send_acl(struct hci_chan *chan, struct sk_buff *skb, __u16 flags)
3264 {
3265 	struct hci_dev *hdev = chan->conn->hdev;
3266 
3267 	BT_DBG("%s chan %p flags 0x%4.4x", hdev->name, chan, flags);
3268 
3269 	hci_queue_acl(chan, &chan->data_q, skb, flags);
3270 
3271 	hci_sched_tx(hdev);
3272 }
3273 
3274 /* Send SCO data */
3275 void hci_send_sco(struct hci_conn *conn, struct sk_buff *skb)
3276 {
3277 	struct hci_dev *hdev = conn->hdev;
3278 	struct hci_sco_hdr hdr;
3279 
3280 	BT_DBG("%s len %d", hdev->name, skb->len);
3281 
3282 	hdr.handle = cpu_to_le16(conn->handle);
3283 	hdr.dlen   = skb->len;
3284 
3285 	skb_push(skb, HCI_SCO_HDR_SIZE);
3286 	skb_reset_transport_header(skb);
3287 	memcpy(skb_transport_header(skb), &hdr, HCI_SCO_HDR_SIZE);
3288 
3289 	hci_skb_pkt_type(skb) = HCI_SCODATA_PKT;
3290 
3291 	skb_queue_tail(&conn->data_q, skb);
3292 
3293 	bt_dev_dbg(hdev, "hcon %p queued %d", conn,
3294 		   skb_queue_len(&conn->data_q));
3295 
3296 	hci_sched_tx(hdev);
3297 }
3298 
3299 /* Send ISO data */
3300 static void hci_add_iso_hdr(struct sk_buff *skb, __u16 handle, __u8 flags)
3301 {
3302 	struct hci_iso_hdr *hdr;
3303 	int len = skb->len;
3304 
3305 	skb_push(skb, HCI_ISO_HDR_SIZE);
3306 	skb_reset_transport_header(skb);
3307 	hdr = (struct hci_iso_hdr *)skb_transport_header(skb);
3308 	hdr->handle = cpu_to_le16(hci_handle_pack(handle, flags));
3309 	hdr->dlen   = cpu_to_le16(len);
3310 }
3311 
3312 static void hci_queue_iso(struct hci_conn *conn, struct sk_buff_head *queue,
3313 			  struct sk_buff *skb)
3314 {
3315 	struct hci_dev *hdev = conn->hdev;
3316 	struct sk_buff *list;
3317 	__u16 flags;
3318 
3319 	skb->len = skb_headlen(skb);
3320 	skb->data_len = 0;
3321 
3322 	hci_skb_pkt_type(skb) = HCI_ISODATA_PKT;
3323 
3324 	list = skb_shinfo(skb)->frag_list;
3325 
3326 	flags = hci_iso_flags_pack(list ? ISO_START : ISO_SINGLE, 0x00);
3327 	hci_add_iso_hdr(skb, conn->handle, flags);
3328 
3329 	if (!list) {
3330 		/* Non fragmented */
3331 		BT_DBG("%s nonfrag skb %p len %d", hdev->name, skb, skb->len);
3332 
3333 		skb_queue_tail(queue, skb);
3334 	} else {
3335 		/* Fragmented */
3336 		BT_DBG("%s frag %p len %d", hdev->name, skb, skb->len);
3337 
3338 		skb_shinfo(skb)->frag_list = NULL;
3339 
3340 		spin_lock_bh(&queue->lock);
3341 
3342 		__skb_queue_tail(queue, skb);
3343 
3344 		do {
3345 			skb = list; list = list->next;
3346 
3347 			hci_skb_pkt_type(skb) = HCI_ISODATA_PKT;
3348 			flags = hci_iso_flags_pack(list ? ISO_CONT : ISO_END,
3349 						   0x00);
3350 			hci_add_iso_hdr(skb, conn->handle, flags);
3351 
3352 			BT_DBG("%s frag %p len %d", hdev->name, skb, skb->len);
3353 
3354 			__skb_queue_tail(queue, skb);
3355 		} while (list);
3356 
3357 		spin_unlock_bh(&queue->lock);
3358 	}
3359 
3360 	bt_dev_dbg(hdev, "hcon %p queued %d", conn, skb_queue_len(queue));
3361 }
3362 
3363 void hci_send_iso(struct hci_conn *conn, struct sk_buff *skb)
3364 {
3365 	struct hci_dev *hdev = conn->hdev;
3366 
3367 	BT_DBG("%s len %d", hdev->name, skb->len);
3368 
3369 	hci_queue_iso(conn, &conn->data_q, skb);
3370 
3371 	hci_sched_tx(hdev);
3372 }
3373 
3374 /* ---- HCI TX task (outgoing data) ---- */
3375 
3376 /* HCI Connection scheduler */
3377 static inline void hci_quote_sent(struct hci_conn *conn, int num, int *quote)
3378 {
3379 	struct hci_dev *hdev;
3380 	int cnt, q;
3381 
3382 	if (!conn) {
3383 		*quote = 0;
3384 		return;
3385 	}
3386 
3387 	hdev = conn->hdev;
3388 
3389 	switch (conn->type) {
3390 	case ACL_LINK:
3391 		cnt = hdev->acl_cnt;
3392 		break;
3393 	case SCO_LINK:
3394 	case ESCO_LINK:
3395 		cnt = hdev->sco_cnt;
3396 		break;
3397 	case LE_LINK:
3398 		cnt = hdev->le_mtu ? hdev->le_cnt : hdev->acl_cnt;
3399 		break;
3400 	case CIS_LINK:
3401 	case BIS_LINK:
3402 	case PA_LINK:
3403 		cnt = hdev->iso_cnt;
3404 		break;
3405 	default:
3406 		cnt = 0;
3407 		bt_dev_err(hdev, "unknown link type %d", conn->type);
3408 	}
3409 
3410 	q = cnt / num;
3411 	*quote = q ? q : 1;
3412 }
3413 
3414 static struct hci_conn *hci_low_sent(struct hci_dev *hdev, __u8 type,
3415 				     int *quote)
3416 {
3417 	struct hci_conn_hash *h = &hdev->conn_hash;
3418 	struct hci_conn *conn = NULL, *c;
3419 	unsigned int num = 0, min = ~0;
3420 
3421 	rcu_read_lock();
3422 
3423 	list_for_each_entry_rcu(c, &h->list, list) {
3424 		if (c->type != type ||
3425 		    skb_queue_empty(&c->data_q))
3426 			continue;
3427 
3428 		bt_dev_dbg(hdev, "hcon %p state %s queued %d", c,
3429 			   state_to_string(c->state),
3430 			   skb_queue_len(&c->data_q));
3431 
3432 		if (c->state != BT_CONNECTED && c->state != BT_CONFIG)
3433 			continue;
3434 
3435 		num++;
3436 
3437 		if (c->sent < min) {
3438 			min  = c->sent;
3439 			conn = c;
3440 		}
3441 
3442 		if (hci_conn_num(hdev, type) == num)
3443 			break;
3444 	}
3445 
3446 	rcu_read_unlock();
3447 
3448 	hci_quote_sent(conn, num, quote);
3449 
3450 	BT_DBG("conn %p quote %d", conn, *quote);
3451 	return conn;
3452 }
3453 
3454 static void hci_link_tx_to(struct hci_dev *hdev, __u8 type)
3455 {
3456 	struct hci_conn_hash *h = &hdev->conn_hash;
3457 	struct hci_conn *c;
3458 
3459 	bt_dev_err(hdev, "link tx timeout");
3460 
3461 	hci_dev_lock(hdev);
3462 
3463 	/* Kill stalled connections */
3464 	list_for_each_entry(c, &h->list, list) {
3465 		if (c->type == type && c->sent) {
3466 			bt_dev_err(hdev, "killing stalled connection %pMR",
3467 				   &c->dst);
3468 			hci_disconnect(c, HCI_ERROR_REMOTE_USER_TERM);
3469 		}
3470 	}
3471 
3472 	hci_dev_unlock(hdev);
3473 }
3474 
3475 static struct hci_chan *hci_chan_sent(struct hci_dev *hdev, __u8 type,
3476 				      int *quote)
3477 {
3478 	struct hci_conn_hash *h = &hdev->conn_hash;
3479 	struct hci_chan *chan = NULL;
3480 	unsigned int num = 0, min = ~0, cur_prio = 0;
3481 	struct hci_conn *conn;
3482 	int conn_num = 0;
3483 
3484 	BT_DBG("%s", hdev->name);
3485 
3486 	rcu_read_lock();
3487 
3488 	list_for_each_entry_rcu(conn, &h->list, list) {
3489 		struct hci_chan *tmp;
3490 
3491 		if (conn->type != type)
3492 			continue;
3493 
3494 		if (conn->state != BT_CONNECTED && conn->state != BT_CONFIG)
3495 			continue;
3496 
3497 		conn_num++;
3498 
3499 		list_for_each_entry_rcu(tmp, &conn->chan_list, list) {
3500 			struct sk_buff *skb;
3501 
3502 			if (skb_queue_empty(&tmp->data_q))
3503 				continue;
3504 
3505 			skb = skb_peek(&tmp->data_q);
3506 			if (skb->priority < cur_prio)
3507 				continue;
3508 
3509 			if (skb->priority > cur_prio) {
3510 				num = 0;
3511 				min = ~0;
3512 				cur_prio = skb->priority;
3513 			}
3514 
3515 			num++;
3516 
3517 			if (conn->sent < min) {
3518 				min  = conn->sent;
3519 				chan = tmp;
3520 			}
3521 		}
3522 
3523 		if (hci_conn_num(hdev, type) == conn_num)
3524 			break;
3525 	}
3526 
3527 	rcu_read_unlock();
3528 
3529 	if (!chan)
3530 		return NULL;
3531 
3532 	hci_quote_sent(chan->conn, num, quote);
3533 
3534 	BT_DBG("chan %p quote %d", chan, *quote);
3535 	return chan;
3536 }
3537 
3538 static void hci_prio_recalculate(struct hci_dev *hdev, __u8 type)
3539 {
3540 	struct hci_conn_hash *h = &hdev->conn_hash;
3541 	struct hci_conn *conn;
3542 	int num = 0;
3543 
3544 	BT_DBG("%s", hdev->name);
3545 
3546 	rcu_read_lock();
3547 
3548 	list_for_each_entry_rcu(conn, &h->list, list) {
3549 		struct hci_chan *chan;
3550 
3551 		if (conn->type != type)
3552 			continue;
3553 
3554 		if (conn->state != BT_CONNECTED && conn->state != BT_CONFIG)
3555 			continue;
3556 
3557 		num++;
3558 
3559 		list_for_each_entry_rcu(chan, &conn->chan_list, list) {
3560 			struct sk_buff *skb;
3561 
3562 			if (chan->sent) {
3563 				chan->sent = 0;
3564 				continue;
3565 			}
3566 
3567 			if (skb_queue_empty(&chan->data_q))
3568 				continue;
3569 
3570 			skb = skb_peek(&chan->data_q);
3571 			if (skb->priority >= HCI_PRIO_MAX - 1)
3572 				continue;
3573 
3574 			skb->priority = HCI_PRIO_MAX - 1;
3575 
3576 			BT_DBG("chan %p skb %p promoted to %d", chan, skb,
3577 			       skb->priority);
3578 		}
3579 
3580 		if (hci_conn_num(hdev, type) == num)
3581 			break;
3582 	}
3583 
3584 	rcu_read_unlock();
3585 
3586 }
3587 
3588 static void __check_timeout(struct hci_dev *hdev, unsigned int cnt, u8 type)
3589 {
3590 	unsigned long timeout;
3591 
3592 	if (hci_dev_test_flag(hdev, HCI_UNCONFIGURED))
3593 		return;
3594 
3595 	switch (type) {
3596 	case ACL_LINK:
3597 		/* tx timeout must be longer than maximum link supervision
3598 		 * timeout (40.9 seconds)
3599 		 */
3600 		timeout = hdev->acl_last_tx + HCI_ACL_TX_TIMEOUT;
3601 		break;
3602 	case LE_LINK:
3603 		/* tx timeout must be longer than maximum link supervision
3604 		 * timeout (40.9 seconds)
3605 		 */
3606 		timeout = hdev->le_last_tx + HCI_ACL_TX_TIMEOUT;
3607 		break;
3608 	case CIS_LINK:
3609 	case BIS_LINK:
3610 	case PA_LINK:
3611 		/* tx timeout must be longer than the maximum transport latency
3612 		 * (8.388607 seconds)
3613 		 */
3614 		timeout = hdev->iso_last_tx + HCI_ISO_TX_TIMEOUT;
3615 		break;
3616 	default:
3617 		return;
3618 	}
3619 
3620 	if (!cnt && time_after(jiffies, timeout))
3621 		hci_link_tx_to(hdev, type);
3622 }
3623 
3624 /* Schedule SCO */
3625 static void __hci_sched_sco(struct hci_dev *hdev, __u8 type)
3626 {
3627 	struct hci_conn *conn;
3628 	struct sk_buff *skb;
3629 	int quote, *cnt;
3630 	unsigned int pkts = hdev->sco_pkts;
3631 
3632 	lockdep_assert_held(&hdev->lock);
3633 
3634 	bt_dev_dbg(hdev, "type %u", type);
3635 
3636 	if (!hci_conn_num(hdev, type) || !pkts)
3637 		return;
3638 
3639 	/* Use sco_pkts if flow control has not been enabled which will limit
3640 	 * the amount of buffer sent in a row.
3641 	 */
3642 	if (!hci_dev_test_flag(hdev, HCI_SCO_FLOWCTL))
3643 		cnt = &pkts;
3644 	else
3645 		cnt = &hdev->sco_cnt;
3646 
3647 	while (*cnt && (conn = hci_low_sent(hdev, type, &quote))) {
3648 		while (quote-- && (skb = skb_dequeue(&conn->data_q))) {
3649 			BT_DBG("skb %p len %d", skb, skb->len);
3650 			hci_send_conn_frame(hdev, conn, skb);
3651 
3652 			conn->sent++;
3653 			if (conn->sent == ~0)
3654 				conn->sent = 0;
3655 			(*cnt)--;
3656 		}
3657 	}
3658 
3659 	/* Rescheduled if all packets were sent and flow control is not enabled
3660 	 * as there could be more packets queued that could not be sent and
3661 	 * since no HCI_EV_NUM_COMP_PKTS event will be generated the reschedule
3662 	 * needs to be forced.
3663 	 */
3664 	if (!pkts && !hci_dev_test_flag(hdev, HCI_SCO_FLOWCTL))
3665 		queue_work(hdev->workqueue, &hdev->tx_work);
3666 }
3667 
3668 static void hci_sched_sco(struct hci_dev *hdev, __u8 type)
3669 {
3670 	hci_dev_lock(hdev);
3671 	__hci_sched_sco(hdev, type);
3672 	hci_dev_unlock(hdev);
3673 }
3674 
3675 static void hci_sched_acl_pkt(struct hci_dev *hdev)
3676 {
3677 	unsigned int cnt = hdev->acl_cnt;
3678 	struct hci_chan *chan;
3679 	struct sk_buff *skb;
3680 	int quote;
3681 
3682 	__check_timeout(hdev, cnt, ACL_LINK);
3683 
3684 	hci_dev_lock(hdev);
3685 
3686 	while (hdev->acl_cnt &&
3687 	       (chan = hci_chan_sent(hdev, ACL_LINK, &quote))) {
3688 		u32 priority = (skb_peek(&chan->data_q))->priority;
3689 		while (quote-- && (skb = skb_peek(&chan->data_q))) {
3690 			BT_DBG("chan %p skb %p len %d priority %u", chan, skb,
3691 			       skb->len, skb->priority);
3692 
3693 			/* Stop if priority has changed */
3694 			if (skb->priority < priority)
3695 				break;
3696 
3697 			skb = skb_dequeue(&chan->data_q);
3698 
3699 			hci_conn_enter_active_mode(chan->conn,
3700 						   bt_cb(skb)->force_active);
3701 
3702 			hci_send_conn_frame(hdev, chan->conn, skb);
3703 			hdev->acl_last_tx = jiffies;
3704 
3705 			hdev->acl_cnt--;
3706 			chan->sent++;
3707 			chan->conn->sent++;
3708 
3709 			/* Send pending SCO packets right away */
3710 			__hci_sched_sco(hdev, SCO_LINK);
3711 			__hci_sched_sco(hdev, ESCO_LINK);
3712 		}
3713 	}
3714 
3715 	if (cnt != hdev->acl_cnt)
3716 		hci_prio_recalculate(hdev, ACL_LINK);
3717 
3718 	hci_dev_unlock(hdev);
3719 }
3720 
3721 static void hci_sched_acl(struct hci_dev *hdev)
3722 {
3723 	BT_DBG("%s", hdev->name);
3724 
3725 	/* No ACL link over BR/EDR controller */
3726 	if (!hci_conn_num(hdev, ACL_LINK))
3727 		return;
3728 
3729 	hci_sched_acl_pkt(hdev);
3730 }
3731 
3732 static void hci_sched_le(struct hci_dev *hdev)
3733 {
3734 	struct hci_chan *chan;
3735 	struct sk_buff *skb;
3736 	int quote, *cnt, tmp;
3737 
3738 	BT_DBG("%s", hdev->name);
3739 
3740 	if (!hci_conn_num(hdev, LE_LINK))
3741 		return;
3742 
3743 	cnt = hdev->le_pkts ? &hdev->le_cnt : &hdev->acl_cnt;
3744 
3745 	__check_timeout(hdev, *cnt, LE_LINK);
3746 
3747 	hci_dev_lock(hdev);
3748 
3749 	tmp = *cnt;
3750 	while (*cnt && (chan = hci_chan_sent(hdev, LE_LINK, &quote))) {
3751 		u32 priority = (skb_peek(&chan->data_q))->priority;
3752 		while (quote-- && (skb = skb_peek(&chan->data_q))) {
3753 			BT_DBG("chan %p skb %p len %d priority %u", chan, skb,
3754 			       skb->len, skb->priority);
3755 
3756 			/* Stop if priority has changed */
3757 			if (skb->priority < priority)
3758 				break;
3759 
3760 			skb = skb_dequeue(&chan->data_q);
3761 
3762 			hci_send_conn_frame(hdev, chan->conn, skb);
3763 			hdev->le_last_tx = jiffies;
3764 
3765 			(*cnt)--;
3766 			chan->sent++;
3767 			chan->conn->sent++;
3768 
3769 			/* Send pending SCO packets right away */
3770 			__hci_sched_sco(hdev, SCO_LINK);
3771 			__hci_sched_sco(hdev, ESCO_LINK);
3772 		}
3773 	}
3774 
3775 	if (*cnt != tmp)
3776 		hci_prio_recalculate(hdev, LE_LINK);
3777 
3778 	hci_dev_unlock(hdev);
3779 }
3780 
3781 /* Schedule iso */
3782 static void hci_sched_iso(struct hci_dev *hdev, __u8 type)
3783 {
3784 	struct hci_conn *conn;
3785 	struct sk_buff *skb;
3786 	int quote, *cnt;
3787 
3788 	BT_DBG("%s", hdev->name);
3789 
3790 	if (!hci_conn_num(hdev, type))
3791 		return;
3792 
3793 	cnt = &hdev->iso_cnt;
3794 
3795 	__check_timeout(hdev, *cnt, type);
3796 
3797 	hci_dev_lock(hdev);
3798 
3799 	while (*cnt && (conn = hci_low_sent(hdev, type, &quote))) {
3800 		while (quote-- && (skb = skb_dequeue(&conn->data_q))) {
3801 			BT_DBG("skb %p len %d", skb, skb->len);
3802 
3803 			hci_send_conn_frame(hdev, conn, skb);
3804 			hdev->iso_last_tx = jiffies;
3805 
3806 			conn->sent++;
3807 			if (conn->sent == ~0)
3808 				conn->sent = 0;
3809 			(*cnt)--;
3810 		}
3811 	}
3812 
3813 	hci_dev_unlock(hdev);
3814 }
3815 
3816 static void hci_tx_work(struct work_struct *work)
3817 {
3818 	struct hci_dev *hdev = container_of(work, struct hci_dev, tx_work);
3819 	struct sk_buff *skb;
3820 
3821 	BT_DBG("%s acl %d sco %d le %d iso %d", hdev->name, hdev->acl_cnt,
3822 	       hdev->sco_cnt, hdev->le_cnt, hdev->iso_cnt);
3823 
3824 	if (!hci_dev_test_flag(hdev, HCI_USER_CHANNEL)) {
3825 		/* Schedule queues and send stuff to HCI driver */
3826 		hci_sched_sco(hdev, SCO_LINK);
3827 		hci_sched_sco(hdev, ESCO_LINK);
3828 		hci_sched_iso(hdev, CIS_LINK);
3829 		hci_sched_iso(hdev, BIS_LINK);
3830 		hci_sched_iso(hdev, PA_LINK);
3831 		hci_sched_acl(hdev);
3832 		hci_sched_le(hdev);
3833 	}
3834 
3835 	/* Send next queued raw (unknown type) packet */
3836 	while ((skb = skb_dequeue(&hdev->raw_q)))
3837 		hci_send_frame(hdev, skb);
3838 }
3839 
3840 /* ----- HCI RX task (incoming data processing) ----- */
3841 
3842 /* ACL data packet */
3843 static void hci_acldata_packet(struct hci_dev *hdev, struct sk_buff *skb)
3844 {
3845 	struct hci_acl_hdr *hdr;
3846 	__u16 handle, flags;
3847 	int err;
3848 
3849 	hdr = skb_pull_data(skb, sizeof(*hdr));
3850 	if (!hdr) {
3851 		bt_dev_err(hdev, "ACL packet too small");
3852 		kfree_skb(skb);
3853 		return;
3854 	}
3855 
3856 	handle = __le16_to_cpu(hdr->handle);
3857 	flags  = hci_flags(handle);
3858 	handle = hci_handle(handle);
3859 
3860 	bt_dev_dbg(hdev, "len %d handle 0x%4.4x flags 0x%4.4x", skb->len,
3861 		   handle, flags);
3862 
3863 	hdev->stat.acl_rx++;
3864 
3865 	err = l2cap_recv_acldata(hdev, handle, skb, flags);
3866 	if (err == -ENOENT)
3867 		bt_dev_err(hdev, "ACL packet for unknown connection handle %d",
3868 			   handle);
3869 	else if (err)
3870 		bt_dev_dbg(hdev, "ACL packet recv for handle %d failed: %d",
3871 			   handle, err);
3872 }
3873 
3874 /* SCO data packet */
3875 static void hci_scodata_packet(struct hci_dev *hdev, struct sk_buff *skb)
3876 {
3877 	struct hci_sco_hdr *hdr;
3878 	__u16 handle, flags;
3879 	int err;
3880 
3881 	hdr = skb_pull_data(skb, sizeof(*hdr));
3882 	if (!hdr) {
3883 		bt_dev_err(hdev, "SCO packet too small");
3884 		kfree_skb(skb);
3885 		return;
3886 	}
3887 
3888 	handle = __le16_to_cpu(hdr->handle);
3889 	flags  = hci_flags(handle);
3890 	handle = hci_handle(handle);
3891 
3892 	bt_dev_dbg(hdev, "len %d handle 0x%4.4x flags 0x%4.4x", skb->len,
3893 		   handle, flags);
3894 
3895 	hdev->stat.sco_rx++;
3896 
3897 	hci_skb_pkt_status(skb) = flags & 0x03;
3898 
3899 	err = sco_recv_scodata(hdev, handle, skb);
3900 	if (err == -ENOENT)
3901 		bt_dev_err_ratelimited(hdev, "SCO packet for unknown connection handle %d",
3902 				       handle);
3903 	else if (err)
3904 		bt_dev_dbg(hdev, "SCO packet recv for handle %d failed: %d",
3905 			   handle, err);
3906 }
3907 
3908 static void hci_isodata_packet(struct hci_dev *hdev, struct sk_buff *skb)
3909 {
3910 	struct hci_iso_hdr *hdr;
3911 	__u16 handle, flags;
3912 	int err;
3913 
3914 	hdr = skb_pull_data(skb, sizeof(*hdr));
3915 	if (!hdr) {
3916 		bt_dev_err(hdev, "ISO packet too small");
3917 		kfree_skb(skb);
3918 		return;
3919 	}
3920 
3921 	handle = __le16_to_cpu(hdr->handle);
3922 	flags  = hci_flags(handle);
3923 	handle = hci_handle(handle);
3924 
3925 	bt_dev_dbg(hdev, "len %d handle 0x%4.4x flags 0x%4.4x", skb->len,
3926 		   handle, flags);
3927 
3928 	err = iso_recv(hdev, handle, skb, flags);
3929 	if (err == -ENOENT)
3930 		bt_dev_err_ratelimited(hdev, "ISO packet for unknown connection handle %d",
3931 				       handle);
3932 	else if (err)
3933 		bt_dev_dbg(hdev, "ISO packet recv for handle %d failed: %d",
3934 			   handle, err);
3935 }
3936 
3937 static bool hci_req_is_complete(struct hci_dev *hdev)
3938 {
3939 	struct sk_buff *skb;
3940 
3941 	skb = skb_peek(&hdev->cmd_q);
3942 	if (!skb)
3943 		return true;
3944 
3945 	return (bt_cb(skb)->hci.req_flags & HCI_REQ_START);
3946 }
3947 
3948 static void hci_resend_last(struct hci_dev *hdev)
3949 {
3950 	struct hci_command_hdr *sent;
3951 	struct sk_buff *skb;
3952 	u16 opcode;
3953 
3954 	if (!hdev->sent_cmd)
3955 		return;
3956 
3957 	sent = (void *) hdev->sent_cmd->data;
3958 	opcode = __le16_to_cpu(sent->opcode);
3959 	if (opcode == HCI_OP_RESET)
3960 		return;
3961 
3962 	skb = skb_clone(hdev->sent_cmd, GFP_KERNEL);
3963 	if (!skb)
3964 		return;
3965 
3966 	skb_queue_head(&hdev->cmd_q, skb);
3967 	queue_work(hdev->workqueue, &hdev->cmd_work);
3968 }
3969 
3970 void hci_req_cmd_complete(struct hci_dev *hdev, u16 opcode, u8 status,
3971 			  hci_req_complete_t *req_complete,
3972 			  hci_req_complete_skb_t *req_complete_skb)
3973 {
3974 	struct sk_buff *skb;
3975 	unsigned long flags;
3976 
3977 	BT_DBG("opcode 0x%04x status 0x%02x", opcode, status);
3978 
3979 	/* If the completed command doesn't match the last one that was
3980 	 * sent we need to do special handling of it.
3981 	 */
3982 	if (!hci_sent_cmd_data(hdev, opcode)) {
3983 		/* Some CSR based controllers generate a spontaneous
3984 		 * reset complete event during init and any pending
3985 		 * command will never be completed. In such a case we
3986 		 * need to resend whatever was the last sent
3987 		 * command.
3988 		 */
3989 		if (test_bit(HCI_INIT, &hdev->flags) && opcode == HCI_OP_RESET)
3990 			hci_resend_last(hdev);
3991 
3992 		return;
3993 	}
3994 
3995 	/* If we reach this point this event matches the last command sent */
3996 	hci_dev_clear_flag(hdev, HCI_CMD_PENDING);
3997 
3998 	/* If the command succeeded and there's still more commands in
3999 	 * this request the request is not yet complete.
4000 	 */
4001 	if (!status && !hci_req_is_complete(hdev))
4002 		return;
4003 
4004 	skb = hdev->req_skb;
4005 
4006 	/* If this was the last command in a request the complete
4007 	 * callback would be found in hdev->req_skb instead of the
4008 	 * command queue (hdev->cmd_q).
4009 	 */
4010 	if (skb && bt_cb(skb)->hci.req_flags & HCI_REQ_SKB) {
4011 		*req_complete_skb = bt_cb(skb)->hci.req_complete_skb;
4012 		return;
4013 	}
4014 
4015 	if (skb && bt_cb(skb)->hci.req_complete) {
4016 		*req_complete = bt_cb(skb)->hci.req_complete;
4017 		return;
4018 	}
4019 
4020 	/* Remove all pending commands belonging to this request */
4021 	spin_lock_irqsave(&hdev->cmd_q.lock, flags);
4022 	while ((skb = __skb_dequeue(&hdev->cmd_q))) {
4023 		if (bt_cb(skb)->hci.req_flags & HCI_REQ_START) {
4024 			__skb_queue_head(&hdev->cmd_q, skb);
4025 			break;
4026 		}
4027 
4028 		if (bt_cb(skb)->hci.req_flags & HCI_REQ_SKB)
4029 			*req_complete_skb = bt_cb(skb)->hci.req_complete_skb;
4030 		else
4031 			*req_complete = bt_cb(skb)->hci.req_complete;
4032 		dev_kfree_skb_irq(skb);
4033 	}
4034 	spin_unlock_irqrestore(&hdev->cmd_q.lock, flags);
4035 }
4036 
4037 static void hci_rx_work(struct work_struct *work)
4038 {
4039 	struct hci_dev *hdev = container_of(work, struct hci_dev, rx_work);
4040 	struct sk_buff *skb;
4041 
4042 	BT_DBG("%s", hdev->name);
4043 
4044 	/* The kcov_remote functions used for collecting packet parsing
4045 	 * coverage information from this background thread and associate
4046 	 * the coverage with the syscall's thread which originally injected
4047 	 * the packet. This helps fuzzing the kernel.
4048 	 */
4049 	for (; (skb = skb_dequeue(&hdev->rx_q)); kcov_remote_stop()) {
4050 		kcov_remote_start_common(skb_get_kcov_handle(skb));
4051 
4052 		/* Send copy to monitor */
4053 		hci_send_to_monitor(hdev, skb);
4054 
4055 		if (atomic_read(&hdev->promisc)) {
4056 			/* Send copy to the sockets */
4057 			hci_send_to_sock(hdev, skb);
4058 		}
4059 
4060 		/* If the device has been opened in HCI_USER_CHANNEL,
4061 		 * the userspace has exclusive access to device.
4062 		 * When device is HCI_INIT, we still need to process
4063 		 * the data packets to the driver in order
4064 		 * to complete its setup().
4065 		 */
4066 		if (hci_dev_test_flag(hdev, HCI_USER_CHANNEL) &&
4067 		    !test_bit(HCI_INIT, &hdev->flags)) {
4068 			kfree_skb(skb);
4069 			continue;
4070 		}
4071 
4072 		if (test_bit(HCI_INIT, &hdev->flags)) {
4073 			/* Don't process data packets in this states. */
4074 			switch (hci_skb_pkt_type(skb)) {
4075 			case HCI_ACLDATA_PKT:
4076 			case HCI_SCODATA_PKT:
4077 			case HCI_ISODATA_PKT:
4078 				kfree_skb(skb);
4079 				continue;
4080 			}
4081 		}
4082 
4083 		/* Process frame */
4084 		switch (hci_skb_pkt_type(skb)) {
4085 		case HCI_EVENT_PKT:
4086 			BT_DBG("%s Event packet", hdev->name);
4087 			hci_event_packet(hdev, skb);
4088 			break;
4089 
4090 		case HCI_ACLDATA_PKT:
4091 			BT_DBG("%s ACL data packet", hdev->name);
4092 			hci_acldata_packet(hdev, skb);
4093 			break;
4094 
4095 		case HCI_SCODATA_PKT:
4096 			BT_DBG("%s SCO data packet", hdev->name);
4097 			hci_scodata_packet(hdev, skb);
4098 			break;
4099 
4100 		case HCI_ISODATA_PKT:
4101 			BT_DBG("%s ISO data packet", hdev->name);
4102 			hci_isodata_packet(hdev, skb);
4103 			break;
4104 
4105 		default:
4106 			kfree_skb(skb);
4107 			break;
4108 		}
4109 	}
4110 }
4111 
4112 static int hci_send_cmd_sync(struct hci_dev *hdev, struct sk_buff *skb)
4113 {
4114 	int err;
4115 
4116 	bt_dev_dbg(hdev, "skb %p", skb);
4117 
4118 	kfree_skb(hdev->sent_cmd);
4119 
4120 	hdev->sent_cmd = skb_clone(skb, GFP_KERNEL);
4121 	if (!hdev->sent_cmd) {
4122 		skb_queue_head(&hdev->cmd_q, skb);
4123 		queue_work(hdev->workqueue, &hdev->cmd_work);
4124 		return -EINVAL;
4125 	}
4126 
4127 	if (hci_skb_opcode(skb) != HCI_OP_NOP) {
4128 		err = hci_send_frame(hdev, skb);
4129 		if (err < 0) {
4130 			hci_cmd_sync_cancel_sync(hdev, -err);
4131 			return err;
4132 		}
4133 		atomic_dec(&hdev->cmd_cnt);
4134 	} else {
4135 		err = -ENODATA;
4136 		kfree_skb(skb);
4137 	}
4138 
4139 	if (READ_ONCE(hdev->req_status) == HCI_REQ_PEND &&
4140 	    !hci_dev_test_and_set_flag(hdev, HCI_CMD_PENDING)) {
4141 		kfree_skb(hdev->req_skb);
4142 		hdev->req_skb = skb_get(hdev->sent_cmd);
4143 	}
4144 
4145 	return err;
4146 }
4147 
4148 static void hci_cmd_work(struct work_struct *work)
4149 {
4150 	struct hci_dev *hdev = container_of(work, struct hci_dev, cmd_work);
4151 	struct sk_buff *skb;
4152 	int err;
4153 
4154 	BT_DBG("%s cmd_cnt %d cmd queued %d", hdev->name,
4155 	       atomic_read(&hdev->cmd_cnt), skb_queue_len(&hdev->cmd_q));
4156 
4157 	/* Send queued commands */
4158 	if (atomic_read(&hdev->cmd_cnt)) {
4159 		skb = skb_dequeue(&hdev->cmd_q);
4160 		if (!skb)
4161 			return;
4162 
4163 		err = hci_send_cmd_sync(hdev, skb);
4164 		if (err)
4165 			return;
4166 
4167 		rcu_read_lock();
4168 		if (test_bit(HCI_RESET, &hdev->flags) ||
4169 		    hci_dev_test_flag(hdev, HCI_CMD_DRAIN_WORKQUEUE))
4170 			cancel_delayed_work(&hdev->cmd_timer);
4171 		else
4172 			queue_delayed_work(hdev->workqueue, &hdev->cmd_timer,
4173 					   HCI_CMD_TIMEOUT);
4174 		rcu_read_unlock();
4175 	}
4176 }
4177