1 // SPDX-License-Identifier: GPL-2.0 2 /* 3 BlueZ - Bluetooth protocol stack for Linux 4 Copyright (C) 2000-2001 Qualcomm Incorporated 5 Copyright (C) 2011 ProFUSION Embedded Systems 6 7 Written 2000,2001 by Maxim Krasnyansky <maxk@qualcomm.com> 8 9 THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS 10 OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, 11 FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT OF THIRD PARTY RIGHTS. 12 IN NO EVENT SHALL THE COPYRIGHT HOLDER(S) AND AUTHOR(S) BE LIABLE FOR ANY 13 CLAIM, OR ANY SPECIAL INDIRECT OR CONSEQUENTIAL DAMAGES, OR ANY DAMAGES 14 WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN 15 ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF 16 OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. 17 18 ALL LIABILITY, INCLUDING LIABILITY FOR INFRINGEMENT OF ANY PATENTS, 19 COPYRIGHTS, TRADEMARKS OR OTHER RIGHTS, RELATING TO USE OF THIS 20 SOFTWARE IS DISCLAIMED. 21 */ 22 23 /* Bluetooth HCI core. */ 24 25 #include <linux/export.h> 26 #include <linux/rfkill.h> 27 #include <linux/debugfs.h> 28 #include <linux/crypto.h> 29 #include <linux/kcov.h> 30 #include <linux/property.h> 31 #include <linux/suspend.h> 32 #include <linux/wait.h> 33 #include <linux/unaligned.h> 34 35 #include <net/bluetooth/bluetooth.h> 36 #include <net/bluetooth/hci_core.h> 37 #include <net/bluetooth/l2cap.h> 38 #include <net/bluetooth/mgmt.h> 39 40 #include "hci_debugfs.h" 41 #include "smp.h" 42 #include "leds.h" 43 #include "msft.h" 44 #include "aosp.h" 45 #include "hci_codec.h" 46 47 static void hci_rx_work(struct work_struct *work); 48 static void hci_cmd_work(struct work_struct *work); 49 static void hci_tx_work(struct work_struct *work); 50 51 /* HCI device list */ 52 LIST_HEAD(hci_dev_list); 53 DEFINE_RWLOCK(hci_dev_list_lock); 54 55 /* HCI callback list */ 56 LIST_HEAD(hci_cb_list); 57 DEFINE_MUTEX(hci_cb_list_lock); 58 59 /* HCI ID Numbering */ 60 static DEFINE_IDA(hci_index_ida); 61 62 /* Get HCI device by index. 63 * Device is held on return. */ 64 static struct hci_dev *__hci_dev_get(int index, int *srcu_index) 65 __context_unsafe(/* conditional locking */) 66 { 67 struct hci_dev *hdev = NULL, *d; 68 69 BT_DBG("%d", index); 70 71 if (index < 0) 72 return NULL; 73 74 read_lock(&hci_dev_list_lock); 75 list_for_each_entry(d, &hci_dev_list, list) { 76 if (d->id == index) { 77 hdev = hci_dev_hold(d); 78 if (srcu_index) 79 *srcu_index = srcu_read_lock(&d->srcu); 80 break; 81 } 82 } 83 read_unlock(&hci_dev_list_lock); 84 return hdev; 85 } 86 87 struct hci_dev *hci_dev_get(int index) 88 { 89 return __hci_dev_get(index, NULL); 90 } 91 92 static struct hci_dev *hci_dev_get_srcu(int index, int *srcu_index) 93 __context_unsafe(/* conditional locking vs return */) 94 { 95 return __hci_dev_get(index, srcu_index); 96 } 97 98 static void hci_dev_put_srcu(struct hci_dev *hdev, int srcu_index) 99 __context_unsafe(/* conditional locking vs return */) 100 { 101 srcu_read_unlock(&hdev->srcu, srcu_index); 102 hci_dev_put(hdev); 103 } 104 105 /* ---- Inquiry support ---- */ 106 107 bool hci_discovery_active(struct hci_dev *hdev) 108 { 109 struct discovery_state *discov = &hdev->discovery; 110 111 switch (discov->state) { 112 case DISCOVERY_FINDING: 113 case DISCOVERY_RESOLVING: 114 return true; 115 116 default: 117 return false; 118 } 119 } 120 EXPORT_SYMBOL(hci_discovery_active); 121 122 void hci_discovery_set_state(struct hci_dev *hdev, int state) 123 { 124 int old_state = hdev->discovery.state; 125 126 if (old_state == state) 127 return; 128 129 hdev->discovery.state = state; 130 131 switch (state) { 132 case DISCOVERY_STOPPED: 133 hci_update_passive_scan(hdev); 134 135 if (old_state != DISCOVERY_STARTING) 136 mgmt_discovering(hdev, 0); 137 break; 138 case DISCOVERY_STARTING: 139 break; 140 case DISCOVERY_FINDING: 141 mgmt_discovering(hdev, 1); 142 break; 143 case DISCOVERY_RESOLVING: 144 break; 145 case DISCOVERY_STOPPING: 146 break; 147 } 148 149 bt_dev_dbg(hdev, "state %u -> %u", old_state, state); 150 } 151 152 void hci_inquiry_cache_flush(struct hci_dev *hdev) 153 { 154 struct discovery_state *cache = &hdev->discovery; 155 struct inquiry_entry *p, *n; 156 157 list_for_each_entry_safe(p, n, &cache->all, all) { 158 list_del(&p->all); 159 kfree(p); 160 } 161 162 INIT_LIST_HEAD(&cache->unknown); 163 INIT_LIST_HEAD(&cache->resolve); 164 } 165 166 struct inquiry_entry *hci_inquiry_cache_lookup(struct hci_dev *hdev, 167 bdaddr_t *bdaddr) 168 { 169 struct discovery_state *cache = &hdev->discovery; 170 struct inquiry_entry *e; 171 172 BT_DBG("cache %p, %pMR", cache, bdaddr); 173 174 list_for_each_entry(e, &cache->all, all) { 175 if (!bacmp(&e->data.bdaddr, bdaddr)) 176 return e; 177 } 178 179 return NULL; 180 } 181 182 struct inquiry_entry *hci_inquiry_cache_lookup_unknown(struct hci_dev *hdev, 183 bdaddr_t *bdaddr) 184 { 185 struct discovery_state *cache = &hdev->discovery; 186 struct inquiry_entry *e; 187 188 BT_DBG("cache %p, %pMR", cache, bdaddr); 189 190 list_for_each_entry(e, &cache->unknown, list) { 191 if (!bacmp(&e->data.bdaddr, bdaddr)) 192 return e; 193 } 194 195 return NULL; 196 } 197 198 struct inquiry_entry *hci_inquiry_cache_lookup_resolve(struct hci_dev *hdev, 199 bdaddr_t *bdaddr, 200 int state) 201 { 202 struct discovery_state *cache = &hdev->discovery; 203 struct inquiry_entry *e; 204 205 BT_DBG("cache %p bdaddr %pMR state %d", cache, bdaddr, state); 206 207 list_for_each_entry(e, &cache->resolve, list) { 208 if (!bacmp(bdaddr, BDADDR_ANY) && e->name_state == state) 209 return e; 210 if (!bacmp(&e->data.bdaddr, bdaddr)) 211 return e; 212 } 213 214 return NULL; 215 } 216 217 void hci_inquiry_cache_update_resolve(struct hci_dev *hdev, 218 struct inquiry_entry *ie) 219 { 220 struct discovery_state *cache = &hdev->discovery; 221 struct list_head *pos = &cache->resolve; 222 struct inquiry_entry *p; 223 224 list_del(&ie->list); 225 226 list_for_each_entry(p, &cache->resolve, list) { 227 if (p->name_state != NAME_PENDING && 228 abs(p->data.rssi) >= abs(ie->data.rssi)) 229 break; 230 pos = &p->list; 231 } 232 233 list_add(&ie->list, pos); 234 } 235 236 u32 hci_inquiry_cache_update(struct hci_dev *hdev, struct inquiry_data *data, 237 bool name_known) 238 { 239 struct discovery_state *cache = &hdev->discovery; 240 struct inquiry_entry *ie; 241 u32 flags = 0; 242 243 BT_DBG("cache %p, %pMR", cache, &data->bdaddr); 244 245 hci_remove_remote_oob_data(hdev, &data->bdaddr, BDADDR_BREDR); 246 247 if (!data->ssp_mode) 248 flags |= MGMT_DEV_FOUND_LEGACY_PAIRING; 249 250 ie = hci_inquiry_cache_lookup(hdev, &data->bdaddr); 251 if (ie) { 252 if (!ie->data.ssp_mode) 253 flags |= MGMT_DEV_FOUND_LEGACY_PAIRING; 254 255 if (ie->name_state == NAME_NEEDED && 256 data->rssi != ie->data.rssi) { 257 ie->data.rssi = data->rssi; 258 hci_inquiry_cache_update_resolve(hdev, ie); 259 } 260 261 goto update; 262 } 263 264 /* Entry not in the cache. Add new one. */ 265 ie = kzalloc_obj(*ie); 266 if (!ie) { 267 flags |= MGMT_DEV_FOUND_CONFIRM_NAME; 268 goto done; 269 } 270 271 list_add(&ie->all, &cache->all); 272 273 if (name_known) { 274 ie->name_state = NAME_KNOWN; 275 } else { 276 ie->name_state = NAME_NOT_KNOWN; 277 list_add(&ie->list, &cache->unknown); 278 } 279 280 update: 281 if (name_known && ie->name_state != NAME_KNOWN && 282 ie->name_state != NAME_PENDING) { 283 ie->name_state = NAME_KNOWN; 284 list_del(&ie->list); 285 } 286 287 memcpy(&ie->data, data, sizeof(*data)); 288 ie->timestamp = jiffies; 289 cache->timestamp = jiffies; 290 291 if (ie->name_state == NAME_NOT_KNOWN) 292 flags |= MGMT_DEV_FOUND_CONFIRM_NAME; 293 294 done: 295 return flags; 296 } 297 298 static int inquiry_cache_dump(struct hci_dev *hdev, int num, __u8 *buf) 299 { 300 struct discovery_state *cache = &hdev->discovery; 301 struct inquiry_info *info = (struct inquiry_info *) buf; 302 struct inquiry_entry *e; 303 int copied = 0; 304 305 list_for_each_entry(e, &cache->all, all) { 306 struct inquiry_data *data = &e->data; 307 308 if (copied >= num) 309 break; 310 311 bacpy(&info->bdaddr, &data->bdaddr); 312 info->pscan_rep_mode = data->pscan_rep_mode; 313 info->pscan_period_mode = data->pscan_period_mode; 314 info->pscan_mode = data->pscan_mode; 315 memcpy(info->dev_class, data->dev_class, 3); 316 info->clock_offset = data->clock_offset; 317 318 info++; 319 copied++; 320 } 321 322 BT_DBG("cache %p, copied %d", cache, copied); 323 return copied; 324 } 325 326 int hci_inquiry(void __user *arg) 327 { 328 __u8 __user *ptr = arg; 329 struct hci_inquiry_req ir; 330 struct hci_dev *hdev; 331 int err = 0, do_inquiry = 0, max_rsp; 332 __u8 *buf; 333 334 if (copy_from_user(&ir, ptr, sizeof(ir))) 335 return -EFAULT; 336 337 hdev = hci_dev_get(ir.dev_id); 338 if (!hdev) 339 return -ENODEV; 340 341 if (hci_dev_test_flag(hdev, HCI_USER_CHANNEL)) { 342 err = -EBUSY; 343 goto done; 344 } 345 346 if (hci_dev_test_flag(hdev, HCI_UNCONFIGURED)) { 347 err = -EOPNOTSUPP; 348 goto done; 349 } 350 351 if (!hci_dev_test_flag(hdev, HCI_BREDR_ENABLED)) { 352 err = -EOPNOTSUPP; 353 goto done; 354 } 355 356 /* Restrict maximum inquiry length to 60 seconds */ 357 if (ir.length > 60) { 358 err = -EINVAL; 359 goto done; 360 } 361 362 hci_dev_lock(hdev); 363 if (inquiry_cache_age(hdev) > INQUIRY_CACHE_AGE_MAX || 364 inquiry_cache_empty(hdev) || ir.flags & IREQ_CACHE_FLUSH) { 365 hci_inquiry_cache_flush(hdev); 366 do_inquiry = 1; 367 } 368 hci_dev_unlock(hdev); 369 370 if (do_inquiry) { 371 hci_req_sync_lock(hdev); 372 err = hci_inquiry_sync(hdev, ir.length, ir.num_rsp); 373 hci_req_sync_unlock(hdev); 374 375 if (err < 0) 376 goto done; 377 378 /* Wait until Inquiry procedure finishes (HCI_INQUIRY flag is 379 * cleared). If it is interrupted by a signal, return -EINTR. 380 */ 381 if (wait_on_bit(&hdev->flags, HCI_INQUIRY, 382 TASK_INTERRUPTIBLE)) { 383 err = -EINTR; 384 goto done; 385 } 386 } 387 388 /* for unlimited number of responses we will use buffer with 389 * 255 entries 390 */ 391 max_rsp = (ir.num_rsp == 0) ? 255 : ir.num_rsp; 392 393 /* cache_dump can't sleep. Therefore we allocate temp buffer and then 394 * copy it to the user space. 395 */ 396 buf = kmalloc_array(max_rsp, sizeof(struct inquiry_info), GFP_KERNEL); 397 if (!buf) { 398 err = -ENOMEM; 399 goto done; 400 } 401 402 hci_dev_lock(hdev); 403 ir.num_rsp = inquiry_cache_dump(hdev, max_rsp, buf); 404 hci_dev_unlock(hdev); 405 406 BT_DBG("num_rsp %d", ir.num_rsp); 407 408 if (!copy_to_user(ptr, &ir, sizeof(ir))) { 409 ptr += sizeof(ir); 410 if (copy_to_user(ptr, buf, sizeof(struct inquiry_info) * 411 ir.num_rsp)) 412 err = -EFAULT; 413 } else 414 err = -EFAULT; 415 416 kfree(buf); 417 418 done: 419 hci_dev_put(hdev); 420 return err; 421 } 422 423 static int hci_dev_do_open(struct hci_dev *hdev) 424 { 425 int ret = 0; 426 427 BT_DBG("%s %p", hdev->name, hdev); 428 429 hci_req_sync_lock(hdev); 430 431 ret = hci_dev_open_sync(hdev); 432 433 hci_req_sync_unlock(hdev); 434 return ret; 435 } 436 437 /* ---- HCI ioctl helpers ---- */ 438 439 int hci_dev_open(__u16 dev) 440 { 441 struct hci_dev *hdev; 442 int err; 443 444 hdev = hci_dev_get(dev); 445 if (!hdev) 446 return -ENODEV; 447 448 /* Devices that are marked as unconfigured can only be powered 449 * up as user channel. Trying to bring them up as normal devices 450 * will result into a failure. Only user channel operation is 451 * possible. 452 * 453 * When this function is called for a user channel, the flag 454 * HCI_USER_CHANNEL will be set first before attempting to 455 * open the device. 456 */ 457 if (hci_dev_test_flag(hdev, HCI_UNCONFIGURED) && 458 !hci_dev_test_flag(hdev, HCI_USER_CHANNEL)) { 459 err = -EOPNOTSUPP; 460 goto done; 461 } 462 463 /* We need to ensure that no other power on/off work is pending 464 * before proceeding to call hci_dev_do_open. This is 465 * particularly important if the setup procedure has not yet 466 * completed. 467 */ 468 if (hci_dev_test_and_clear_flag(hdev, HCI_AUTO_OFF)) 469 cancel_delayed_work(&hdev->power_off); 470 471 /* After this call it is guaranteed that the setup procedure 472 * has finished. This means that error conditions like RFKILL 473 * or no valid public or static random address apply. 474 */ 475 flush_workqueue(hdev->req_workqueue); 476 477 /* For controllers not using the management interface and that 478 * are brought up using legacy ioctl, set the HCI_BONDABLE bit 479 * so that pairing works for them. Once the management interface 480 * is in use this bit will be cleared again and userspace has 481 * to explicitly enable it. 482 */ 483 if (!hci_dev_test_flag(hdev, HCI_USER_CHANNEL) && 484 !hci_dev_test_flag(hdev, HCI_MGMT)) 485 hci_dev_set_flag(hdev, HCI_BONDABLE); 486 487 err = hci_dev_do_open(hdev); 488 489 done: 490 hci_dev_put(hdev); 491 return err; 492 } 493 494 int hci_dev_do_close(struct hci_dev *hdev) 495 { 496 int err; 497 498 BT_DBG("%s %p", hdev->name, hdev); 499 500 hci_req_sync_lock(hdev); 501 502 err = hci_dev_close_sync(hdev); 503 504 hci_req_sync_unlock(hdev); 505 506 return err; 507 } 508 509 int hci_dev_close(__u16 dev) 510 { 511 struct hci_dev *hdev; 512 int err; 513 514 hdev = hci_dev_get(dev); 515 if (!hdev) 516 return -ENODEV; 517 518 if (hci_dev_test_flag(hdev, HCI_USER_CHANNEL)) { 519 err = -EBUSY; 520 goto done; 521 } 522 523 cancel_work_sync(&hdev->power_on); 524 if (hci_dev_test_and_clear_flag(hdev, HCI_AUTO_OFF)) 525 cancel_delayed_work(&hdev->power_off); 526 527 err = hci_dev_do_close(hdev); 528 529 done: 530 hci_dev_put(hdev); 531 return err; 532 } 533 534 static int hci_dev_do_reset(struct hci_dev *hdev) 535 { 536 int ret; 537 538 BT_DBG("%s %p", hdev->name, hdev); 539 540 hci_req_sync_lock(hdev); 541 542 ret = hci_dev_close_sync(hdev); 543 if (!ret) 544 ret = hci_dev_open_sync(hdev); 545 546 hci_req_sync_unlock(hdev); 547 return ret; 548 } 549 550 int hci_dev_reset(__u16 dev) 551 { 552 struct hci_dev *hdev; 553 int err, srcu_index; 554 555 hdev = hci_dev_get_srcu(dev, &srcu_index); 556 if (!hdev) 557 return -ENODEV; 558 559 if (!test_bit(HCI_UP, &hdev->flags)) { 560 err = -ENETDOWN; 561 goto done; 562 } 563 564 if (hci_dev_test_flag(hdev, HCI_USER_CHANNEL)) { 565 err = -EBUSY; 566 goto done; 567 } 568 569 if (hci_dev_test_flag(hdev, HCI_UNCONFIGURED)) { 570 err = -EOPNOTSUPP; 571 goto done; 572 } 573 574 err = hci_dev_do_reset(hdev); 575 576 done: 577 hci_dev_put_srcu(hdev, srcu_index); 578 return err; 579 } 580 581 int hci_dev_reset_stat(__u16 dev) 582 { 583 struct hci_dev *hdev; 584 int ret = 0; 585 586 hdev = hci_dev_get(dev); 587 if (!hdev) 588 return -ENODEV; 589 590 if (hci_dev_test_flag(hdev, HCI_USER_CHANNEL)) { 591 ret = -EBUSY; 592 goto done; 593 } 594 595 if (hci_dev_test_flag(hdev, HCI_UNCONFIGURED)) { 596 ret = -EOPNOTSUPP; 597 goto done; 598 } 599 600 memset(&hdev->stat, 0, sizeof(struct hci_dev_stats)); 601 602 done: 603 hci_dev_put(hdev); 604 return ret; 605 } 606 607 static void hci_update_passive_scan_state(struct hci_dev *hdev, u8 scan) 608 { 609 bool conn_changed, discov_changed; 610 611 BT_DBG("%s scan 0x%02x", hdev->name, scan); 612 613 if ((scan & SCAN_PAGE)) 614 conn_changed = !hci_dev_test_and_set_flag(hdev, 615 HCI_CONNECTABLE); 616 else 617 conn_changed = hci_dev_test_and_clear_flag(hdev, 618 HCI_CONNECTABLE); 619 620 if ((scan & SCAN_INQUIRY)) { 621 discov_changed = !hci_dev_test_and_set_flag(hdev, 622 HCI_DISCOVERABLE); 623 } else { 624 hci_dev_clear_flag(hdev, HCI_LIMITED_DISCOVERABLE); 625 discov_changed = hci_dev_test_and_clear_flag(hdev, 626 HCI_DISCOVERABLE); 627 } 628 629 if (!hci_dev_test_flag(hdev, HCI_MGMT)) 630 return; 631 632 if (conn_changed || discov_changed) { 633 /* In case this was disabled through mgmt */ 634 hci_dev_set_flag(hdev, HCI_BREDR_ENABLED); 635 636 if (hci_dev_test_flag(hdev, HCI_LE_ENABLED)) 637 hci_update_adv_data(hdev, hdev->cur_adv_instance); 638 639 mgmt_new_settings(hdev); 640 } 641 } 642 643 int hci_dev_cmd(unsigned int cmd, void __user *arg) 644 { 645 struct hci_dev *hdev; 646 struct hci_dev_req dr; 647 __le16 policy; 648 int err = 0; 649 650 if (copy_from_user(&dr, arg, sizeof(dr))) 651 return -EFAULT; 652 653 hdev = hci_dev_get(dr.dev_id); 654 if (!hdev) 655 return -ENODEV; 656 657 if (hci_dev_test_flag(hdev, HCI_USER_CHANNEL)) { 658 err = -EBUSY; 659 goto done; 660 } 661 662 if (hci_dev_test_flag(hdev, HCI_UNCONFIGURED)) { 663 err = -EOPNOTSUPP; 664 goto done; 665 } 666 667 if (!hci_dev_test_flag(hdev, HCI_BREDR_ENABLED)) { 668 err = -EOPNOTSUPP; 669 goto done; 670 } 671 672 switch (cmd) { 673 case HCISETAUTH: 674 err = hci_cmd_sync_status(hdev, HCI_OP_WRITE_AUTH_ENABLE, 675 1, &dr.dev_opt, HCI_CMD_TIMEOUT); 676 break; 677 678 case HCISETENCRYPT: 679 if (!lmp_encrypt_capable(hdev)) { 680 err = -EOPNOTSUPP; 681 break; 682 } 683 684 if (!test_bit(HCI_AUTH, &hdev->flags)) { 685 /* Auth must be enabled first */ 686 err = hci_cmd_sync_status(hdev, 687 HCI_OP_WRITE_AUTH_ENABLE, 688 1, &dr.dev_opt, 689 HCI_CMD_TIMEOUT); 690 if (err) 691 break; 692 } 693 694 err = hci_cmd_sync_status(hdev, HCI_OP_WRITE_ENCRYPT_MODE, 695 1, &dr.dev_opt, HCI_CMD_TIMEOUT); 696 break; 697 698 case HCISETSCAN: 699 err = hci_cmd_sync_status(hdev, HCI_OP_WRITE_SCAN_ENABLE, 700 1, &dr.dev_opt, HCI_CMD_TIMEOUT); 701 702 /* Ensure that the connectable and discoverable states 703 * get correctly modified as this was a non-mgmt change. 704 */ 705 if (!err) 706 hci_update_passive_scan_state(hdev, dr.dev_opt); 707 break; 708 709 case HCISETLINKPOL: 710 policy = cpu_to_le16(dr.dev_opt); 711 712 err = hci_cmd_sync_status(hdev, HCI_OP_WRITE_DEF_LINK_POLICY, 713 2, &policy, HCI_CMD_TIMEOUT); 714 break; 715 716 case HCISETLINKMODE: 717 hdev->link_mode = ((__u16) dr.dev_opt) & 718 (HCI_LM_MASTER | HCI_LM_ACCEPT); 719 break; 720 721 case HCISETPTYPE: 722 if (hdev->pkt_type == (__u16) dr.dev_opt) 723 break; 724 725 hdev->pkt_type = (__u16) dr.dev_opt; 726 mgmt_phy_configuration_changed(hdev, NULL); 727 break; 728 729 case HCISETACLMTU: 730 hdev->acl_mtu = *((__u16 *) &dr.dev_opt + 1); 731 hdev->acl_pkts = *((__u16 *) &dr.dev_opt + 0); 732 break; 733 734 case HCISETSCOMTU: 735 hdev->sco_mtu = *((__u16 *) &dr.dev_opt + 1); 736 hdev->sco_pkts = *((__u16 *) &dr.dev_opt + 0); 737 break; 738 739 default: 740 err = -EINVAL; 741 break; 742 } 743 744 done: 745 hci_dev_put(hdev); 746 return err; 747 } 748 749 int hci_get_dev_list(void __user *arg) 750 { 751 struct hci_dev *hdev; 752 struct hci_dev_list_req *dl; 753 struct hci_dev_req *dr; 754 int n = 0, err; 755 __u16 dev_num; 756 757 if (get_user(dev_num, (__u16 __user *) arg)) 758 return -EFAULT; 759 760 if (!dev_num || dev_num > (PAGE_SIZE * 2) / sizeof(*dr)) 761 return -EINVAL; 762 763 dl = kzalloc_flex(*dl, dev_req, dev_num); 764 if (!dl) 765 return -ENOMEM; 766 767 dl->dev_num = dev_num; 768 dr = dl->dev_req; 769 770 read_lock(&hci_dev_list_lock); 771 list_for_each_entry(hdev, &hci_dev_list, list) { 772 unsigned long flags = hdev->flags; 773 774 /* When the auto-off is configured it means the transport 775 * is running, but in that case still indicate that the 776 * device is actually down. 777 */ 778 if (hci_dev_test_flag(hdev, HCI_AUTO_OFF)) 779 flags &= ~BIT(HCI_UP); 780 781 dr[n].dev_id = hdev->id; 782 dr[n].dev_opt = flags; 783 784 if (++n >= dev_num) 785 break; 786 } 787 read_unlock(&hci_dev_list_lock); 788 789 dl->dev_num = n; 790 err = copy_to_user(arg, dl, struct_size(dl, dev_req, n)); 791 kfree(dl); 792 793 return err ? -EFAULT : 0; 794 } 795 796 int hci_get_dev_info(void __user *arg) 797 { 798 struct hci_dev *hdev; 799 struct hci_dev_info di; 800 unsigned long flags; 801 int err = 0; 802 803 if (copy_from_user(&di, arg, sizeof(di))) 804 return -EFAULT; 805 806 hdev = hci_dev_get(di.dev_id); 807 if (!hdev) 808 return -ENODEV; 809 810 /* When the auto-off is configured it means the transport 811 * is running, but in that case still indicate that the 812 * device is actually down. 813 */ 814 if (hci_dev_test_flag(hdev, HCI_AUTO_OFF)) 815 flags = hdev->flags & ~BIT(HCI_UP); 816 else 817 flags = hdev->flags; 818 819 strscpy(di.name, hdev->name, sizeof(di.name)); 820 di.bdaddr = hdev->bdaddr; 821 di.type = (hdev->bus & 0x0f); 822 di.flags = flags; 823 di.pkt_type = hdev->pkt_type; 824 if (lmp_bredr_capable(hdev)) { 825 di.acl_mtu = hdev->acl_mtu; 826 di.acl_pkts = hdev->acl_pkts; 827 di.sco_mtu = hdev->sco_mtu; 828 di.sco_pkts = hdev->sco_pkts; 829 } else { 830 di.acl_mtu = hdev->le_mtu; 831 di.acl_pkts = hdev->le_pkts; 832 di.sco_mtu = 0; 833 di.sco_pkts = 0; 834 } 835 di.link_policy = hdev->link_policy; 836 di.link_mode = hdev->link_mode; 837 838 memcpy(&di.stat, &hdev->stat, sizeof(di.stat)); 839 memcpy(&di.features, &hdev->features, sizeof(di.features)); 840 841 if (copy_to_user(arg, &di, sizeof(di))) 842 err = -EFAULT; 843 844 hci_dev_put(hdev); 845 846 return err; 847 } 848 849 /* ---- Interface to HCI drivers ---- */ 850 851 static int hci_dev_do_poweroff(struct hci_dev *hdev) 852 { 853 int err; 854 855 BT_DBG("%s %p", hdev->name, hdev); 856 857 hci_req_sync_lock(hdev); 858 859 err = hci_set_powered_sync(hdev, false); 860 861 hci_req_sync_unlock(hdev); 862 863 return err; 864 } 865 866 static int hci_rfkill_set_block(void *data, bool blocked) 867 { 868 struct hci_dev *hdev = data; 869 int err; 870 871 BT_DBG("%p name %s blocked %d", hdev, hdev->name, blocked); 872 873 if (hci_dev_test_flag(hdev, HCI_USER_CHANNEL)) 874 return -EBUSY; 875 876 if (blocked == hci_dev_test_flag(hdev, HCI_RFKILLED)) 877 return 0; 878 879 if (blocked) { 880 hci_dev_set_flag(hdev, HCI_RFKILLED); 881 882 if (!hci_dev_test_flag(hdev, HCI_SETUP) && 883 !hci_dev_test_flag(hdev, HCI_CONFIG)) { 884 err = hci_dev_do_poweroff(hdev); 885 if (err) { 886 bt_dev_err(hdev, "Error when powering off device on rfkill (%d)", 887 err); 888 889 /* Make sure the device is still closed even if 890 * anything during power off sequence (eg. 891 * disconnecting devices) failed. 892 */ 893 hci_dev_do_close(hdev); 894 } 895 } 896 } else { 897 hci_dev_clear_flag(hdev, HCI_RFKILLED); 898 } 899 900 return 0; 901 } 902 903 static const struct rfkill_ops hci_rfkill_ops = { 904 .set_block = hci_rfkill_set_block, 905 }; 906 907 static void hci_power_on(struct work_struct *work) 908 { 909 struct hci_dev *hdev = container_of(work, struct hci_dev, power_on); 910 int err; 911 912 BT_DBG("%s", hdev->name); 913 914 if (test_bit(HCI_UP, &hdev->flags) && 915 hci_dev_test_flag(hdev, HCI_MGMT) && 916 hci_dev_test_and_clear_flag(hdev, HCI_AUTO_OFF)) { 917 cancel_delayed_work(&hdev->power_off); 918 err = hci_powered_update_sync(hdev); 919 mgmt_power_on(hdev, err); 920 return; 921 } 922 923 err = hci_dev_do_open(hdev); 924 if (err < 0) { 925 hci_dev_lock(hdev); 926 mgmt_set_powered_failed(hdev, err); 927 hci_dev_unlock(hdev); 928 return; 929 } 930 931 /* During the HCI setup phase, a few error conditions are 932 * ignored and they need to be checked now. If they are still 933 * valid, it is important to turn the device back off. 934 */ 935 if (hci_dev_test_flag(hdev, HCI_RFKILLED) || 936 hci_dev_test_flag(hdev, HCI_UNCONFIGURED) || 937 (!bacmp(&hdev->bdaddr, BDADDR_ANY) && 938 !bacmp(&hdev->static_addr, BDADDR_ANY))) { 939 hci_dev_clear_flag(hdev, HCI_AUTO_OFF); 940 hci_dev_do_close(hdev); 941 } else if (hci_dev_test_flag(hdev, HCI_AUTO_OFF)) { 942 queue_delayed_work(hdev->req_workqueue, &hdev->power_off, 943 HCI_AUTO_OFF_TIMEOUT); 944 } 945 946 if (hci_dev_test_and_clear_flag(hdev, HCI_SETUP)) { 947 /* For unconfigured devices, set the HCI_RAW flag 948 * so that userspace can easily identify them. 949 */ 950 if (hci_dev_test_flag(hdev, HCI_UNCONFIGURED)) 951 set_bit(HCI_RAW, &hdev->flags); 952 953 /* For fully configured devices, this will send 954 * the Index Added event. For unconfigured devices, 955 * it will send Unconfigued Index Added event. 956 * 957 * Devices with HCI_QUIRK_RAW_DEVICE are ignored 958 * and no event will be send. 959 */ 960 mgmt_index_added(hdev); 961 } else if (hci_dev_test_and_clear_flag(hdev, HCI_CONFIG)) { 962 /* When the controller is now configured, then it 963 * is important to clear the HCI_RAW flag. 964 */ 965 if (!hci_dev_test_flag(hdev, HCI_UNCONFIGURED)) 966 clear_bit(HCI_RAW, &hdev->flags); 967 968 /* Powering on the controller with HCI_CONFIG set only 969 * happens with the transition from unconfigured to 970 * configured. This will send the Index Added event. 971 */ 972 mgmt_index_added(hdev); 973 } 974 } 975 976 static void hci_power_off(struct work_struct *work) 977 { 978 struct hci_dev *hdev = container_of(work, struct hci_dev, 979 power_off.work); 980 981 BT_DBG("%s", hdev->name); 982 983 hci_dev_do_close(hdev); 984 } 985 986 static void hci_error_reset(struct work_struct *work) 987 { 988 struct hci_dev *hdev = container_of(work, struct hci_dev, error_reset); 989 990 hci_dev_hold(hdev); 991 BT_DBG("%s", hdev->name); 992 993 if (hdev->hw_error) 994 hdev->hw_error(hdev, hdev->hw_error_code); 995 else 996 bt_dev_err(hdev, "hardware error 0x%2.2x", hdev->hw_error_code); 997 998 if (!hci_dev_do_close(hdev)) 999 hci_dev_do_open(hdev); 1000 1001 hci_dev_put(hdev); 1002 } 1003 1004 void hci_uuids_clear(struct hci_dev *hdev) 1005 { 1006 struct bt_uuid *uuid, *tmp; 1007 1008 list_for_each_entry_safe(uuid, tmp, &hdev->uuids, list) { 1009 list_del(&uuid->list); 1010 kfree(uuid); 1011 } 1012 } 1013 1014 void hci_link_keys_clear(struct hci_dev *hdev) 1015 { 1016 struct link_key *key, *tmp; 1017 1018 list_for_each_entry_safe(key, tmp, &hdev->link_keys, list) { 1019 list_del_rcu(&key->list); 1020 kfree_rcu(key, rcu); 1021 } 1022 } 1023 1024 void hci_smp_ltks_clear(struct hci_dev *hdev) 1025 { 1026 struct smp_ltk *k, *tmp; 1027 1028 list_for_each_entry_safe(k, tmp, &hdev->long_term_keys, list) { 1029 list_del_rcu(&k->list); 1030 kfree_rcu(k, rcu); 1031 } 1032 } 1033 1034 void hci_smp_irks_clear(struct hci_dev *hdev) 1035 { 1036 struct smp_irk *k, *tmp; 1037 1038 list_for_each_entry_safe(k, tmp, &hdev->identity_resolving_keys, list) { 1039 list_del_rcu(&k->list); 1040 kfree_rcu(k, rcu); 1041 } 1042 } 1043 1044 void hci_blocked_keys_clear(struct hci_dev *hdev) 1045 { 1046 struct blocked_key *b, *tmp; 1047 1048 list_for_each_entry_safe(b, tmp, &hdev->blocked_keys, list) { 1049 list_del_rcu(&b->list); 1050 kfree_rcu(b, rcu); 1051 } 1052 } 1053 1054 bool hci_is_blocked_key(struct hci_dev *hdev, u8 type, u8 val[16]) 1055 { 1056 bool blocked = false; 1057 struct blocked_key *b; 1058 1059 rcu_read_lock(); 1060 list_for_each_entry_rcu(b, &hdev->blocked_keys, list) { 1061 if (b->type == type && !memcmp(b->val, val, sizeof(b->val))) { 1062 blocked = true; 1063 break; 1064 } 1065 } 1066 1067 rcu_read_unlock(); 1068 return blocked; 1069 } 1070 1071 struct link_key *hci_find_link_key(struct hci_dev *hdev, bdaddr_t *bdaddr) 1072 { 1073 struct link_key *k; 1074 1075 rcu_read_lock(); 1076 list_for_each_entry_rcu(k, &hdev->link_keys, list) { 1077 if (bacmp(bdaddr, &k->bdaddr) == 0) { 1078 rcu_read_unlock(); 1079 1080 if (hci_is_blocked_key(hdev, 1081 HCI_BLOCKED_KEY_TYPE_LINKKEY, 1082 k->val)) { 1083 bt_dev_warn_ratelimited(hdev, 1084 "Link key blocked for %pMR", 1085 &k->bdaddr); 1086 return NULL; 1087 } 1088 1089 return k; 1090 } 1091 } 1092 rcu_read_unlock(); 1093 1094 return NULL; 1095 } 1096 1097 static bool hci_persistent_key(struct hci_dev *hdev, struct hci_conn *conn, 1098 u8 key_type, u8 old_key_type) 1099 { 1100 /* Legacy key */ 1101 if (key_type < 0x03) 1102 return true; 1103 1104 /* Debug keys are insecure so don't store them persistently */ 1105 if (key_type == HCI_LK_DEBUG_COMBINATION) 1106 return false; 1107 1108 /* Changed combination key and there's no previous one */ 1109 if (key_type == HCI_LK_CHANGED_COMBINATION && old_key_type == 0xff) 1110 return false; 1111 1112 /* Security mode 3 case */ 1113 if (!conn) 1114 return true; 1115 1116 /* BR/EDR key derived using SC from an LE link */ 1117 if (conn->type == LE_LINK) 1118 return true; 1119 1120 /* Neither local nor remote side had no-bonding as requirement */ 1121 if (conn->auth_type > 0x01 && conn->remote_auth > 0x01) 1122 return true; 1123 1124 /* Local side had dedicated bonding as requirement */ 1125 if (conn->auth_type == 0x02 || conn->auth_type == 0x03) 1126 return true; 1127 1128 /* Remote side had dedicated bonding as requirement */ 1129 if (conn->remote_auth == 0x02 || conn->remote_auth == 0x03) 1130 return true; 1131 1132 /* If none of the above criteria match, then don't store the key 1133 * persistently */ 1134 return false; 1135 } 1136 1137 static u8 ltk_role(u8 type) 1138 { 1139 if (type == SMP_LTK) 1140 return HCI_ROLE_MASTER; 1141 1142 return HCI_ROLE_SLAVE; 1143 } 1144 1145 struct smp_ltk *hci_find_ltk(struct hci_dev *hdev, bdaddr_t *bdaddr, 1146 u8 addr_type, u8 role) 1147 { 1148 struct smp_ltk *k; 1149 1150 rcu_read_lock(); 1151 list_for_each_entry_rcu(k, &hdev->long_term_keys, list) { 1152 if (addr_type != k->bdaddr_type || bacmp(bdaddr, &k->bdaddr)) 1153 continue; 1154 1155 if (smp_ltk_is_sc(k) || ltk_role(k->type) == role) { 1156 rcu_read_unlock(); 1157 1158 if (hci_is_blocked_key(hdev, HCI_BLOCKED_KEY_TYPE_LTK, 1159 k->val)) { 1160 bt_dev_warn_ratelimited(hdev, 1161 "LTK blocked for %pMR", 1162 &k->bdaddr); 1163 return NULL; 1164 } 1165 1166 return k; 1167 } 1168 } 1169 rcu_read_unlock(); 1170 1171 return NULL; 1172 } 1173 1174 struct smp_irk *hci_find_irk_by_rpa(struct hci_dev *hdev, bdaddr_t *rpa) 1175 { 1176 struct smp_irk *irk_to_return = NULL; 1177 struct smp_irk *irk; 1178 1179 rcu_read_lock(); 1180 list_for_each_entry_rcu(irk, &hdev->identity_resolving_keys, list) { 1181 if (!bacmp(&irk->rpa, rpa)) { 1182 irk_to_return = irk; 1183 goto done; 1184 } 1185 } 1186 1187 list_for_each_entry_rcu(irk, &hdev->identity_resolving_keys, list) { 1188 if (smp_irk_matches(hdev, irk->val, rpa)) { 1189 bacpy(&irk->rpa, rpa); 1190 irk_to_return = irk; 1191 goto done; 1192 } 1193 } 1194 1195 done: 1196 if (irk_to_return && hci_is_blocked_key(hdev, HCI_BLOCKED_KEY_TYPE_IRK, 1197 irk_to_return->val)) { 1198 bt_dev_warn_ratelimited(hdev, "Identity key blocked for %pMR", 1199 &irk_to_return->bdaddr); 1200 irk_to_return = NULL; 1201 } 1202 1203 rcu_read_unlock(); 1204 1205 return irk_to_return; 1206 } 1207 1208 struct smp_irk *hci_find_irk_by_addr(struct hci_dev *hdev, bdaddr_t *bdaddr, 1209 u8 addr_type) 1210 { 1211 struct smp_irk *irk_to_return = NULL; 1212 struct smp_irk *irk; 1213 1214 /* Identity Address must be public or static random */ 1215 if (addr_type == ADDR_LE_DEV_RANDOM && (bdaddr->b[5] & 0xc0) != 0xc0) 1216 return NULL; 1217 1218 rcu_read_lock(); 1219 list_for_each_entry_rcu(irk, &hdev->identity_resolving_keys, list) { 1220 if (addr_type == irk->addr_type && 1221 bacmp(bdaddr, &irk->bdaddr) == 0) { 1222 irk_to_return = irk; 1223 break; 1224 } 1225 } 1226 1227 if (irk_to_return && hci_is_blocked_key(hdev, HCI_BLOCKED_KEY_TYPE_IRK, 1228 irk_to_return->val)) { 1229 bt_dev_warn_ratelimited(hdev, "Identity key blocked for %pMR", 1230 &irk_to_return->bdaddr); 1231 irk_to_return = NULL; 1232 } 1233 1234 rcu_read_unlock(); 1235 1236 return irk_to_return; 1237 } 1238 1239 struct link_key *hci_add_link_key(struct hci_dev *hdev, struct hci_conn *conn, 1240 bdaddr_t *bdaddr, u8 *val, u8 type, 1241 u8 pin_len, bool *persistent) 1242 { 1243 struct link_key *key, *old_key; 1244 u8 old_key_type; 1245 1246 old_key = hci_find_link_key(hdev, bdaddr); 1247 if (old_key) { 1248 old_key_type = old_key->type; 1249 key = old_key; 1250 } else { 1251 old_key_type = conn ? conn->key_type : 0xff; 1252 key = kzalloc_obj(*key); 1253 if (!key) 1254 return NULL; 1255 list_add_rcu(&key->list, &hdev->link_keys); 1256 } 1257 1258 BT_DBG("%s key for %pMR type %u", hdev->name, bdaddr, type); 1259 1260 /* Some buggy controller combinations generate a changed 1261 * combination key for legacy pairing even when there's no 1262 * previous key */ 1263 if (type == HCI_LK_CHANGED_COMBINATION && 1264 (!conn || conn->remote_auth == 0xff) && old_key_type == 0xff) { 1265 type = HCI_LK_COMBINATION; 1266 if (conn) 1267 conn->key_type = type; 1268 } 1269 1270 bacpy(&key->bdaddr, bdaddr); 1271 memcpy(key->val, val, HCI_LINK_KEY_SIZE); 1272 key->pin_len = pin_len; 1273 1274 if (type == HCI_LK_CHANGED_COMBINATION) 1275 key->type = old_key_type; 1276 else 1277 key->type = type; 1278 1279 if (persistent) 1280 *persistent = hci_persistent_key(hdev, conn, type, 1281 old_key_type); 1282 1283 return key; 1284 } 1285 1286 struct smp_ltk *hci_add_ltk(struct hci_dev *hdev, bdaddr_t *bdaddr, 1287 u8 addr_type, u8 type, u8 authenticated, 1288 u8 tk[16], u8 enc_size, __le16 ediv, __le64 rand) 1289 { 1290 struct smp_ltk *key, *old_key; 1291 u8 role = ltk_role(type); 1292 1293 old_key = hci_find_ltk(hdev, bdaddr, addr_type, role); 1294 if (old_key) 1295 key = old_key; 1296 else { 1297 key = kzalloc_obj(*key); 1298 if (!key) 1299 return NULL; 1300 list_add_rcu(&key->list, &hdev->long_term_keys); 1301 } 1302 1303 bacpy(&key->bdaddr, bdaddr); 1304 key->bdaddr_type = addr_type; 1305 memcpy(key->val, tk, sizeof(key->val)); 1306 key->authenticated = authenticated; 1307 key->ediv = ediv; 1308 key->rand = rand; 1309 key->enc_size = enc_size; 1310 key->type = type; 1311 1312 return key; 1313 } 1314 1315 struct smp_irk *hci_add_irk(struct hci_dev *hdev, bdaddr_t *bdaddr, 1316 u8 addr_type, u8 val[16], bdaddr_t *rpa) 1317 { 1318 struct smp_irk *irk; 1319 1320 irk = hci_find_irk_by_addr(hdev, bdaddr, addr_type); 1321 if (!irk) { 1322 irk = kzalloc_obj(*irk); 1323 if (!irk) 1324 return NULL; 1325 1326 bacpy(&irk->bdaddr, bdaddr); 1327 irk->addr_type = addr_type; 1328 1329 list_add_rcu(&irk->list, &hdev->identity_resolving_keys); 1330 } 1331 1332 memcpy(irk->val, val, 16); 1333 bacpy(&irk->rpa, rpa); 1334 1335 return irk; 1336 } 1337 1338 int hci_remove_link_key(struct hci_dev *hdev, bdaddr_t *bdaddr) 1339 { 1340 struct link_key *key; 1341 1342 key = hci_find_link_key(hdev, bdaddr); 1343 if (!key) 1344 return -ENOENT; 1345 1346 BT_DBG("%s removing %pMR", hdev->name, bdaddr); 1347 1348 list_del_rcu(&key->list); 1349 kfree_rcu(key, rcu); 1350 1351 return 0; 1352 } 1353 1354 int hci_remove_ltk(struct hci_dev *hdev, bdaddr_t *bdaddr, u8 bdaddr_type) 1355 { 1356 struct smp_ltk *k, *tmp; 1357 int removed = 0; 1358 1359 list_for_each_entry_safe(k, tmp, &hdev->long_term_keys, list) { 1360 if (bacmp(bdaddr, &k->bdaddr) || k->bdaddr_type != bdaddr_type) 1361 continue; 1362 1363 BT_DBG("%s removing %pMR", hdev->name, bdaddr); 1364 1365 list_del_rcu(&k->list); 1366 kfree_rcu(k, rcu); 1367 removed++; 1368 } 1369 1370 return removed ? 0 : -ENOENT; 1371 } 1372 1373 void hci_remove_irk(struct hci_dev *hdev, bdaddr_t *bdaddr, u8 addr_type) 1374 { 1375 struct smp_irk *k, *tmp; 1376 1377 list_for_each_entry_safe(k, tmp, &hdev->identity_resolving_keys, list) { 1378 if (bacmp(bdaddr, &k->bdaddr) || k->addr_type != addr_type) 1379 continue; 1380 1381 BT_DBG("%s removing %pMR", hdev->name, bdaddr); 1382 1383 list_del_rcu(&k->list); 1384 kfree_rcu(k, rcu); 1385 } 1386 } 1387 1388 bool hci_bdaddr_is_paired(struct hci_dev *hdev, bdaddr_t *bdaddr, u8 type) 1389 { 1390 struct smp_ltk *k; 1391 struct smp_irk *irk; 1392 u8 addr_type; 1393 1394 if (type == BDADDR_BREDR) { 1395 if (hci_find_link_key(hdev, bdaddr)) 1396 return true; 1397 return false; 1398 } 1399 1400 /* Convert to HCI addr type which struct smp_ltk uses */ 1401 if (type == BDADDR_LE_PUBLIC) 1402 addr_type = ADDR_LE_DEV_PUBLIC; 1403 else 1404 addr_type = ADDR_LE_DEV_RANDOM; 1405 1406 irk = hci_get_irk(hdev, bdaddr, addr_type); 1407 if (irk) { 1408 bdaddr = &irk->bdaddr; 1409 addr_type = irk->addr_type; 1410 } 1411 1412 rcu_read_lock(); 1413 list_for_each_entry_rcu(k, &hdev->long_term_keys, list) { 1414 if (k->bdaddr_type == addr_type && !bacmp(bdaddr, &k->bdaddr)) { 1415 rcu_read_unlock(); 1416 return true; 1417 } 1418 } 1419 rcu_read_unlock(); 1420 1421 return false; 1422 } 1423 1424 /* HCI command timer function */ 1425 static void hci_cmd_timeout(struct work_struct *work) 1426 { 1427 struct hci_dev *hdev = container_of(work, struct hci_dev, 1428 cmd_timer.work); 1429 1430 if (hdev->req_skb) { 1431 u16 opcode = hci_skb_opcode(hdev->req_skb); 1432 1433 bt_dev_err(hdev, "command 0x%4.4x tx timeout", opcode); 1434 1435 hci_cmd_sync_cancel_sync(hdev, ETIMEDOUT); 1436 } else { 1437 bt_dev_err(hdev, "command tx timeout"); 1438 } 1439 1440 if (hdev->reset) 1441 hdev->reset(hdev); 1442 1443 atomic_set(&hdev->cmd_cnt, 1); 1444 queue_work(hdev->workqueue, &hdev->cmd_work); 1445 } 1446 1447 /* HCI ncmd timer function */ 1448 static void hci_ncmd_timeout(struct work_struct *work) 1449 { 1450 struct hci_dev *hdev = container_of(work, struct hci_dev, 1451 ncmd_timer.work); 1452 1453 bt_dev_err(hdev, "Controller not accepting commands anymore: ncmd = 0"); 1454 1455 /* During HCI_INIT phase no events can be injected if the ncmd timer 1456 * triggers since the procedure has its own timeout handling. 1457 */ 1458 if (test_bit(HCI_INIT, &hdev->flags)) 1459 return; 1460 1461 /* This is an irrecoverable state, inject hardware error event */ 1462 hci_reset_dev(hdev); 1463 } 1464 1465 struct oob_data *hci_find_remote_oob_data(struct hci_dev *hdev, 1466 bdaddr_t *bdaddr, u8 bdaddr_type) 1467 { 1468 struct oob_data *data; 1469 1470 list_for_each_entry(data, &hdev->remote_oob_data, list) { 1471 if (bacmp(bdaddr, &data->bdaddr) != 0) 1472 continue; 1473 if (data->bdaddr_type != bdaddr_type) 1474 continue; 1475 return data; 1476 } 1477 1478 return NULL; 1479 } 1480 1481 int hci_remove_remote_oob_data(struct hci_dev *hdev, bdaddr_t *bdaddr, 1482 u8 bdaddr_type) 1483 { 1484 struct oob_data *data; 1485 1486 data = hci_find_remote_oob_data(hdev, bdaddr, bdaddr_type); 1487 if (!data) 1488 return -ENOENT; 1489 1490 BT_DBG("%s removing %pMR (%u)", hdev->name, bdaddr, bdaddr_type); 1491 1492 mutex_lock(&hdev->remote_oob_lock); 1493 list_del(&data->list); 1494 kfree(data); 1495 mutex_unlock(&hdev->remote_oob_lock); 1496 1497 return 0; 1498 } 1499 1500 void hci_remote_oob_data_clear(struct hci_dev *hdev) 1501 { 1502 struct oob_data *data, *n; 1503 1504 mutex_lock(&hdev->remote_oob_lock); 1505 list_for_each_entry_safe(data, n, &hdev->remote_oob_data, list) { 1506 list_del(&data->list); 1507 kfree(data); 1508 } 1509 mutex_unlock(&hdev->remote_oob_lock); 1510 } 1511 1512 int hci_add_remote_oob_data(struct hci_dev *hdev, bdaddr_t *bdaddr, 1513 u8 bdaddr_type, u8 *hash192, u8 *rand192, 1514 u8 *hash256, u8 *rand256) 1515 { 1516 struct oob_data *data; 1517 1518 mutex_lock(&hdev->remote_oob_lock); 1519 data = hci_find_remote_oob_data(hdev, bdaddr, bdaddr_type); 1520 if (!data) { 1521 data = kmalloc_obj(*data); 1522 if (!data) { 1523 mutex_unlock(&hdev->remote_oob_lock); 1524 return -ENOMEM; 1525 } 1526 1527 bacpy(&data->bdaddr, bdaddr); 1528 data->bdaddr_type = bdaddr_type; 1529 list_add(&data->list, &hdev->remote_oob_data); 1530 } 1531 1532 if (hash192 && rand192) { 1533 memcpy(data->hash192, hash192, sizeof(data->hash192)); 1534 memcpy(data->rand192, rand192, sizeof(data->rand192)); 1535 if (hash256 && rand256) 1536 data->present = 0x03; 1537 } else { 1538 memset(data->hash192, 0, sizeof(data->hash192)); 1539 memset(data->rand192, 0, sizeof(data->rand192)); 1540 if (hash256 && rand256) 1541 data->present = 0x02; 1542 else 1543 data->present = 0x00; 1544 } 1545 1546 if (hash256 && rand256) { 1547 memcpy(data->hash256, hash256, sizeof(data->hash256)); 1548 memcpy(data->rand256, rand256, sizeof(data->rand256)); 1549 } else { 1550 memset(data->hash256, 0, sizeof(data->hash256)); 1551 memset(data->rand256, 0, sizeof(data->rand256)); 1552 if (hash192 && rand192) 1553 data->present = 0x01; 1554 } 1555 1556 BT_DBG("%s for %pMR", hdev->name, bdaddr); 1557 1558 mutex_unlock(&hdev->remote_oob_lock); 1559 1560 return 0; 1561 } 1562 1563 /* This function requires the caller holds hdev->lock */ 1564 struct adv_info *hci_find_adv_instance(struct hci_dev *hdev, u8 instance) 1565 { 1566 struct adv_info *adv_instance; 1567 1568 list_for_each_entry(adv_instance, &hdev->adv_instances, list) { 1569 if (adv_instance->instance == instance) 1570 return adv_instance; 1571 } 1572 1573 return NULL; 1574 } 1575 1576 /* This function requires the caller holds hdev->lock */ 1577 struct adv_info *hci_find_adv_sid(struct hci_dev *hdev, u8 sid) 1578 { 1579 struct adv_info *adv; 1580 1581 list_for_each_entry(adv, &hdev->adv_instances, list) { 1582 if (adv->sid == sid) 1583 return adv; 1584 } 1585 1586 return NULL; 1587 } 1588 1589 /* This function requires the caller holds hdev->lock */ 1590 struct adv_info *hci_get_next_instance(struct hci_dev *hdev, u8 instance) 1591 { 1592 struct adv_info *cur_instance; 1593 1594 cur_instance = hci_find_adv_instance(hdev, instance); 1595 if (!cur_instance) 1596 return NULL; 1597 1598 if (cur_instance == list_last_entry(&hdev->adv_instances, 1599 struct adv_info, list)) 1600 return list_first_entry(&hdev->adv_instances, 1601 struct adv_info, list); 1602 else 1603 return list_next_entry(cur_instance, list); 1604 } 1605 1606 /* This function requires the caller holds hdev->lock */ 1607 int hci_remove_adv_instance(struct hci_dev *hdev, u8 instance) 1608 { 1609 struct adv_info *adv_instance; 1610 1611 adv_instance = hci_find_adv_instance(hdev, instance); 1612 if (!adv_instance) 1613 return -ENOENT; 1614 1615 BT_DBG("%s removing %dMR", hdev->name, instance); 1616 1617 if (hdev->cur_adv_instance == instance) { 1618 if (hdev->adv_instance_timeout) { 1619 cancel_delayed_work(&hdev->adv_instance_expire); 1620 hdev->adv_instance_timeout = 0; 1621 } 1622 hdev->cur_adv_instance = 0x00; 1623 } 1624 1625 cancel_delayed_work_sync(&adv_instance->rpa_expired_cb); 1626 1627 list_del(&adv_instance->list); 1628 kfree(adv_instance); 1629 1630 hdev->adv_instance_cnt--; 1631 1632 return 0; 1633 } 1634 1635 void hci_adv_instances_set_rpa_expired(struct hci_dev *hdev, bool rpa_expired) 1636 { 1637 struct adv_info *adv_instance, *n; 1638 1639 list_for_each_entry_safe(adv_instance, n, &hdev->adv_instances, list) 1640 adv_instance->rpa_expired = rpa_expired; 1641 } 1642 1643 /* This function requires the caller holds hdev->lock */ 1644 void hci_adv_instances_clear(struct hci_dev *hdev) 1645 { 1646 struct adv_info *adv_instance, *n; 1647 1648 if (hdev->adv_instance_timeout) { 1649 disable_delayed_work(&hdev->adv_instance_expire); 1650 hdev->adv_instance_timeout = 0; 1651 } 1652 1653 list_for_each_entry_safe(adv_instance, n, &hdev->adv_instances, list) { 1654 disable_delayed_work_sync(&adv_instance->rpa_expired_cb); 1655 list_del(&adv_instance->list); 1656 kfree(adv_instance); 1657 } 1658 1659 hdev->adv_instance_cnt = 0; 1660 hdev->cur_adv_instance = 0x00; 1661 } 1662 1663 static void adv_instance_rpa_expired(struct work_struct *work) 1664 { 1665 struct adv_info *adv_instance = container_of(work, struct adv_info, 1666 rpa_expired_cb.work); 1667 1668 BT_DBG(""); 1669 1670 adv_instance->rpa_expired = true; 1671 } 1672 1673 /* This function requires the caller holds hdev->lock */ 1674 struct adv_info *hci_add_adv_instance(struct hci_dev *hdev, u8 instance, 1675 u32 flags, u16 adv_data_len, u8 *adv_data, 1676 u16 scan_rsp_len, u8 *scan_rsp_data, 1677 u16 timeout, u16 duration, s8 tx_power, 1678 u32 min_interval, u32 max_interval, 1679 u8 mesh_handle) 1680 { 1681 struct adv_info *adv; 1682 1683 adv = hci_find_adv_instance(hdev, instance); 1684 if (adv) { 1685 memset(adv->adv_data, 0, sizeof(adv->adv_data)); 1686 memset(adv->scan_rsp_data, 0, sizeof(adv->scan_rsp_data)); 1687 memset(adv->per_adv_data, 0, sizeof(adv->per_adv_data)); 1688 } else { 1689 if (hdev->adv_instance_cnt >= hdev->le_num_of_adv_sets || 1690 instance < 1 || instance > hdev->le_num_of_adv_sets + 1) 1691 return ERR_PTR(-EOVERFLOW); 1692 1693 adv = kzalloc_obj(*adv); 1694 if (!adv) 1695 return ERR_PTR(-ENOMEM); 1696 1697 adv->pending = true; 1698 adv->instance = instance; 1699 1700 /* If controller support only one set and the instance is set to 1701 * 1 then there is no option other than using handle 0x00. 1702 */ 1703 if (hdev->le_num_of_adv_sets == 1 && instance == 1) 1704 adv->handle = 0x00; 1705 else 1706 adv->handle = instance; 1707 1708 list_add(&adv->list, &hdev->adv_instances); 1709 hdev->adv_instance_cnt++; 1710 } 1711 1712 adv->flags = flags; 1713 adv->min_interval = min_interval; 1714 adv->max_interval = max_interval; 1715 adv->tx_power = tx_power; 1716 /* Defining a mesh_handle changes the timing units to ms, 1717 * rather than seconds, and ties the instance to the requested 1718 * mesh_tx queue. 1719 */ 1720 adv->mesh = mesh_handle; 1721 1722 hci_set_adv_instance_data(hdev, instance, adv_data_len, adv_data, 1723 scan_rsp_len, scan_rsp_data); 1724 1725 adv->timeout = timeout; 1726 adv->remaining_time = timeout; 1727 1728 if (duration == 0) 1729 adv->duration = hdev->def_multi_adv_rotation_duration; 1730 else 1731 adv->duration = duration; 1732 1733 INIT_DELAYED_WORK(&adv->rpa_expired_cb, adv_instance_rpa_expired); 1734 1735 BT_DBG("%s for %dMR", hdev->name, instance); 1736 1737 return adv; 1738 } 1739 1740 /* This function requires the caller holds hdev->lock */ 1741 struct adv_info *hci_add_per_instance(struct hci_dev *hdev, u8 instance, u8 sid, 1742 u32 flags, u8 data_len, u8 *data, 1743 u32 min_interval, u32 max_interval) 1744 { 1745 struct adv_info *adv; 1746 1747 adv = hci_add_adv_instance(hdev, instance, flags, 0, NULL, 0, NULL, 1748 0, 0, HCI_ADV_TX_POWER_NO_PREFERENCE, 1749 min_interval, max_interval, 0); 1750 if (IS_ERR(adv)) 1751 return adv; 1752 1753 adv->sid = sid; 1754 adv->periodic = true; 1755 adv->per_adv_data_len = data_len; 1756 1757 if (data) 1758 memcpy(adv->per_adv_data, data, data_len); 1759 1760 return adv; 1761 } 1762 1763 /* This function requires the caller holds hdev->lock */ 1764 int hci_set_adv_instance_data(struct hci_dev *hdev, u8 instance, 1765 u16 adv_data_len, u8 *adv_data, 1766 u16 scan_rsp_len, u8 *scan_rsp_data) 1767 { 1768 struct adv_info *adv; 1769 1770 adv = hci_find_adv_instance(hdev, instance); 1771 1772 /* If advertisement doesn't exist, we can't modify its data */ 1773 if (!adv) 1774 return -ENOENT; 1775 1776 if (adv_data_len && ADV_DATA_CMP(adv, adv_data, adv_data_len)) { 1777 memset(adv->adv_data, 0, sizeof(adv->adv_data)); 1778 memcpy(adv->adv_data, adv_data, adv_data_len); 1779 adv->adv_data_len = adv_data_len; 1780 adv->adv_data_changed = true; 1781 } 1782 1783 if (scan_rsp_len && SCAN_RSP_CMP(adv, scan_rsp_data, scan_rsp_len)) { 1784 memset(adv->scan_rsp_data, 0, sizeof(adv->scan_rsp_data)); 1785 memcpy(adv->scan_rsp_data, scan_rsp_data, scan_rsp_len); 1786 adv->scan_rsp_len = scan_rsp_len; 1787 adv->scan_rsp_changed = true; 1788 } 1789 1790 /* Mark as changed if there are flags which would affect it */ 1791 if (((adv->flags & MGMT_ADV_FLAG_APPEARANCE) && hdev->appearance) || 1792 adv->flags & MGMT_ADV_FLAG_LOCAL_NAME) 1793 adv->scan_rsp_changed = true; 1794 1795 return 0; 1796 } 1797 1798 /* This function requires the caller holds hdev->lock */ 1799 u32 hci_adv_instance_flags(struct hci_dev *hdev, u8 instance) 1800 { 1801 u32 flags; 1802 struct adv_info *adv; 1803 1804 if (instance == 0x00) { 1805 /* Instance 0 always manages the "Tx Power" and "Flags" 1806 * fields 1807 */ 1808 flags = MGMT_ADV_FLAG_TX_POWER | MGMT_ADV_FLAG_MANAGED_FLAGS; 1809 1810 /* For instance 0, the HCI_ADVERTISING_CONNECTABLE setting 1811 * corresponds to the "connectable" instance flag. 1812 */ 1813 if (hci_dev_test_flag(hdev, HCI_ADVERTISING_CONNECTABLE)) 1814 flags |= MGMT_ADV_FLAG_CONNECTABLE; 1815 1816 if (hci_dev_test_flag(hdev, HCI_LIMITED_DISCOVERABLE)) 1817 flags |= MGMT_ADV_FLAG_LIMITED_DISCOV; 1818 else if (hci_dev_test_flag(hdev, HCI_DISCOVERABLE)) 1819 flags |= MGMT_ADV_FLAG_DISCOV; 1820 1821 return flags; 1822 } 1823 1824 adv = hci_find_adv_instance(hdev, instance); 1825 1826 /* Return 0 when we got an invalid instance identifier. */ 1827 if (!adv) 1828 return 0; 1829 1830 return adv->flags; 1831 } 1832 1833 bool hci_adv_instance_is_scannable(struct hci_dev *hdev, u8 instance) 1834 { 1835 struct adv_info *adv; 1836 1837 /* Instance 0x00 always set local name */ 1838 if (instance == 0x00) 1839 return true; 1840 1841 adv = hci_find_adv_instance(hdev, instance); 1842 if (!adv) 1843 return false; 1844 1845 if (adv->flags & MGMT_ADV_FLAG_APPEARANCE || 1846 adv->flags & MGMT_ADV_FLAG_LOCAL_NAME) 1847 return true; 1848 1849 return adv->scan_rsp_len ? true : false; 1850 } 1851 1852 /* This function requires the caller holds hdev->lock */ 1853 void hci_adv_monitors_clear(struct hci_dev *hdev) 1854 { 1855 struct adv_monitor *monitor; 1856 int handle; 1857 1858 idr_for_each_entry(&hdev->adv_monitors_idr, monitor, handle) 1859 hci_free_adv_monitor(hdev, monitor); 1860 1861 idr_destroy(&hdev->adv_monitors_idr); 1862 } 1863 1864 /* Frees the monitor structure and do some bookkeepings. 1865 * This function requires the caller holds hdev->lock. 1866 */ 1867 void hci_free_adv_monitor(struct hci_dev *hdev, struct adv_monitor *monitor) 1868 { 1869 struct adv_pattern *pattern; 1870 struct adv_pattern *tmp; 1871 1872 if (!monitor) 1873 return; 1874 1875 list_for_each_entry_safe(pattern, tmp, &monitor->patterns, list) { 1876 list_del(&pattern->list); 1877 kfree(pattern); 1878 } 1879 1880 if (monitor->handle) 1881 idr_remove(&hdev->adv_monitors_idr, monitor->handle); 1882 1883 if (monitor->state != ADV_MONITOR_STATE_NOT_REGISTERED) 1884 hdev->adv_monitors_cnt--; 1885 1886 kfree(monitor); 1887 } 1888 1889 /* Assigns handle to a monitor, and if offloading is supported and power is on, 1890 * also attempts to forward the request to the controller. 1891 * This function requires the caller holds hci_req_sync_lock. 1892 */ 1893 int hci_add_adv_monitor(struct hci_dev *hdev, struct adv_monitor *monitor) 1894 { 1895 int min, max, handle; 1896 int status = 0; 1897 1898 if (!monitor) 1899 return -EINVAL; 1900 1901 hci_dev_lock(hdev); 1902 1903 min = HCI_MIN_ADV_MONITOR_HANDLE; 1904 max = HCI_MIN_ADV_MONITOR_HANDLE + HCI_MAX_ADV_MONITOR_NUM_HANDLES; 1905 handle = idr_alloc(&hdev->adv_monitors_idr, monitor, min, max, 1906 GFP_KERNEL); 1907 1908 hci_dev_unlock(hdev); 1909 1910 if (handle < 0) 1911 return handle; 1912 1913 monitor->handle = handle; 1914 1915 if (!hdev_is_powered(hdev)) 1916 return status; 1917 1918 switch (hci_get_adv_monitor_offload_ext(hdev)) { 1919 case HCI_ADV_MONITOR_EXT_NONE: 1920 bt_dev_dbg(hdev, "add monitor %d status %d", 1921 monitor->handle, status); 1922 /* Message was not forwarded to controller - not an error */ 1923 break; 1924 1925 case HCI_ADV_MONITOR_EXT_MSFT: 1926 status = msft_add_monitor_pattern(hdev, monitor); 1927 bt_dev_dbg(hdev, "add monitor %d msft status %d", 1928 handle, status); 1929 break; 1930 } 1931 1932 return status; 1933 } 1934 1935 /* Attempts to tell the controller and free the monitor. If somehow the 1936 * controller doesn't have a corresponding handle, remove anyway. 1937 * This function requires the caller holds hci_req_sync_lock. 1938 */ 1939 static int hci_remove_adv_monitor(struct hci_dev *hdev, 1940 struct adv_monitor *monitor) 1941 { 1942 int status = 0; 1943 int handle; 1944 1945 switch (hci_get_adv_monitor_offload_ext(hdev)) { 1946 case HCI_ADV_MONITOR_EXT_NONE: /* also goes here when powered off */ 1947 bt_dev_dbg(hdev, "remove monitor %d status %d", 1948 monitor->handle, status); 1949 goto free_monitor; 1950 1951 case HCI_ADV_MONITOR_EXT_MSFT: 1952 handle = monitor->handle; 1953 status = msft_remove_monitor(hdev, monitor); 1954 bt_dev_dbg(hdev, "remove monitor %d msft status %d", 1955 handle, status); 1956 break; 1957 } 1958 1959 /* In case no matching handle registered, just free the monitor */ 1960 if (status == -ENOENT) 1961 goto free_monitor; 1962 1963 return status; 1964 1965 free_monitor: 1966 if (status == -ENOENT) 1967 bt_dev_warn(hdev, "Removing monitor with no matching handle %d", 1968 monitor->handle); 1969 hci_free_adv_monitor(hdev, monitor); 1970 1971 return status; 1972 } 1973 1974 /* This function requires the caller holds hci_req_sync_lock */ 1975 int hci_remove_single_adv_monitor(struct hci_dev *hdev, u16 handle) 1976 { 1977 struct adv_monitor *monitor = idr_find(&hdev->adv_monitors_idr, handle); 1978 1979 if (!monitor) 1980 return -EINVAL; 1981 1982 return hci_remove_adv_monitor(hdev, monitor); 1983 } 1984 1985 /* This function requires the caller holds hci_req_sync_lock */ 1986 int hci_remove_all_adv_monitor(struct hci_dev *hdev) 1987 { 1988 struct adv_monitor *monitor; 1989 int idr_next_id = 0; 1990 int status = 0; 1991 1992 while (1) { 1993 monitor = idr_get_next(&hdev->adv_monitors_idr, &idr_next_id); 1994 if (!monitor) 1995 break; 1996 1997 status = hci_remove_adv_monitor(hdev, monitor); 1998 if (status) 1999 return status; 2000 2001 idr_next_id++; 2002 } 2003 2004 return status; 2005 } 2006 2007 /* This function requires the caller holds hdev->lock */ 2008 bool hci_is_adv_monitoring(struct hci_dev *hdev) 2009 { 2010 return !idr_is_empty(&hdev->adv_monitors_idr); 2011 } 2012 2013 int hci_get_adv_monitor_offload_ext(struct hci_dev *hdev) 2014 { 2015 if (msft_monitor_supported(hdev)) 2016 return HCI_ADV_MONITOR_EXT_MSFT; 2017 2018 return HCI_ADV_MONITOR_EXT_NONE; 2019 } 2020 2021 struct bdaddr_list *hci_bdaddr_list_lookup(struct list_head *bdaddr_list, 2022 bdaddr_t *bdaddr, u8 type) 2023 { 2024 struct bdaddr_list *b; 2025 2026 list_for_each_entry(b, bdaddr_list, list) { 2027 if (!bacmp(&b->bdaddr, bdaddr) && b->bdaddr_type == type) 2028 return b; 2029 } 2030 2031 return NULL; 2032 } 2033 2034 struct bdaddr_list_with_irk *hci_bdaddr_list_lookup_with_irk( 2035 struct list_head *bdaddr_list, bdaddr_t *bdaddr, 2036 u8 type) 2037 { 2038 struct bdaddr_list_with_irk *b; 2039 2040 list_for_each_entry(b, bdaddr_list, list) { 2041 if (!bacmp(&b->bdaddr, bdaddr) && b->bdaddr_type == type) 2042 return b; 2043 } 2044 2045 return NULL; 2046 } 2047 2048 struct bdaddr_list_with_flags * 2049 hci_bdaddr_list_lookup_with_flags(struct list_head *bdaddr_list, 2050 bdaddr_t *bdaddr, u8 type) 2051 { 2052 struct bdaddr_list_with_flags *b; 2053 2054 list_for_each_entry(b, bdaddr_list, list) { 2055 if (!bacmp(&b->bdaddr, bdaddr) && b->bdaddr_type == type) 2056 return b; 2057 } 2058 2059 return NULL; 2060 } 2061 2062 void hci_bdaddr_list_clear(struct list_head *bdaddr_list) 2063 { 2064 struct bdaddr_list *b, *n; 2065 2066 list_for_each_entry_safe(b, n, bdaddr_list, list) { 2067 list_del(&b->list); 2068 kfree(b); 2069 } 2070 } 2071 2072 int hci_bdaddr_list_add(struct list_head *list, bdaddr_t *bdaddr, u8 type) 2073 { 2074 struct bdaddr_list *entry; 2075 2076 if (!bacmp(bdaddr, BDADDR_ANY)) 2077 return -EBADF; 2078 2079 if (hci_bdaddr_list_lookup(list, bdaddr, type)) 2080 return -EEXIST; 2081 2082 entry = kzalloc_obj(*entry); 2083 if (!entry) 2084 return -ENOMEM; 2085 2086 bacpy(&entry->bdaddr, bdaddr); 2087 entry->bdaddr_type = type; 2088 2089 list_add(&entry->list, list); 2090 2091 return 0; 2092 } 2093 2094 int hci_bdaddr_list_add_with_irk(struct list_head *list, bdaddr_t *bdaddr, 2095 u8 type, u8 *peer_irk, u8 *local_irk) 2096 { 2097 struct bdaddr_list_with_irk *entry; 2098 2099 if (!bacmp(bdaddr, BDADDR_ANY)) 2100 return -EBADF; 2101 2102 if (hci_bdaddr_list_lookup(list, bdaddr, type)) 2103 return -EEXIST; 2104 2105 entry = kzalloc_obj(*entry); 2106 if (!entry) 2107 return -ENOMEM; 2108 2109 bacpy(&entry->bdaddr, bdaddr); 2110 entry->bdaddr_type = type; 2111 2112 if (peer_irk) 2113 memcpy(entry->peer_irk, peer_irk, 16); 2114 2115 if (local_irk) 2116 memcpy(entry->local_irk, local_irk, 16); 2117 2118 list_add(&entry->list, list); 2119 2120 return 0; 2121 } 2122 2123 int hci_bdaddr_list_add_with_flags(struct list_head *list, bdaddr_t *bdaddr, 2124 u8 type, u32 flags) 2125 { 2126 struct bdaddr_list_with_flags *entry; 2127 2128 if (!bacmp(bdaddr, BDADDR_ANY)) 2129 return -EBADF; 2130 2131 if (hci_bdaddr_list_lookup(list, bdaddr, type)) 2132 return -EEXIST; 2133 2134 entry = kzalloc_obj(*entry); 2135 if (!entry) 2136 return -ENOMEM; 2137 2138 bacpy(&entry->bdaddr, bdaddr); 2139 entry->bdaddr_type = type; 2140 entry->flags = flags; 2141 2142 list_add(&entry->list, list); 2143 2144 return 0; 2145 } 2146 2147 int hci_bdaddr_list_del(struct list_head *list, bdaddr_t *bdaddr, u8 type) 2148 { 2149 struct bdaddr_list *entry; 2150 2151 if (!bacmp(bdaddr, BDADDR_ANY)) { 2152 hci_bdaddr_list_clear(list); 2153 return 0; 2154 } 2155 2156 entry = hci_bdaddr_list_lookup(list, bdaddr, type); 2157 if (!entry) 2158 return -ENOENT; 2159 2160 list_del(&entry->list); 2161 kfree(entry); 2162 2163 return 0; 2164 } 2165 2166 int hci_bdaddr_list_del_with_irk(struct list_head *list, bdaddr_t *bdaddr, 2167 u8 type) 2168 { 2169 struct bdaddr_list_with_irk *entry; 2170 2171 if (!bacmp(bdaddr, BDADDR_ANY)) { 2172 hci_bdaddr_list_clear(list); 2173 return 0; 2174 } 2175 2176 entry = hci_bdaddr_list_lookup_with_irk(list, bdaddr, type); 2177 if (!entry) 2178 return -ENOENT; 2179 2180 list_del(&entry->list); 2181 kfree(entry); 2182 2183 return 0; 2184 } 2185 2186 /* This function requires the caller holds hdev->lock */ 2187 struct hci_conn_params *hci_conn_params_lookup(struct hci_dev *hdev, 2188 bdaddr_t *addr, u8 addr_type) 2189 { 2190 struct hci_conn_params *params; 2191 2192 list_for_each_entry(params, &hdev->le_conn_params, list) { 2193 if (bacmp(¶ms->addr, addr) == 0 && 2194 params->addr_type == addr_type) { 2195 return params; 2196 } 2197 } 2198 2199 return NULL; 2200 } 2201 2202 /* This function requires the caller holds hdev->lock or rcu_read_lock */ 2203 struct hci_conn_params *hci_pend_le_action_lookup(struct list_head *list, 2204 bdaddr_t *addr, u8 addr_type) 2205 { 2206 struct hci_conn_params *param; 2207 2208 rcu_read_lock(); 2209 2210 list_for_each_entry_rcu(param, list, action) { 2211 if (bacmp(¶m->addr, addr) == 0 && 2212 param->addr_type == addr_type) { 2213 rcu_read_unlock(); 2214 return param; 2215 } 2216 } 2217 2218 rcu_read_unlock(); 2219 2220 return NULL; 2221 } 2222 2223 /* This function requires the caller holds hdev->lock */ 2224 void hci_pend_le_list_del_init(struct hci_conn_params *param) 2225 { 2226 if (list_empty(¶m->action)) 2227 return; 2228 2229 list_del_rcu(¶m->action); 2230 synchronize_rcu(); 2231 INIT_LIST_HEAD(¶m->action); 2232 } 2233 2234 /* This function requires the caller holds hdev->lock */ 2235 void hci_pend_le_list_add(struct hci_conn_params *param, 2236 struct list_head *list) 2237 { 2238 list_add_rcu(¶m->action, list); 2239 } 2240 2241 /* This function requires the caller holds hdev->lock */ 2242 struct hci_conn_params *hci_conn_params_add(struct hci_dev *hdev, 2243 bdaddr_t *addr, u8 addr_type) 2244 { 2245 struct hci_conn_params *params; 2246 2247 params = hci_conn_params_lookup(hdev, addr, addr_type); 2248 if (params) 2249 return params; 2250 2251 params = kzalloc_obj(*params); 2252 if (!params) { 2253 bt_dev_err(hdev, "out of memory"); 2254 return NULL; 2255 } 2256 2257 bacpy(¶ms->addr, addr); 2258 params->addr_type = addr_type; 2259 2260 list_add(¶ms->list, &hdev->le_conn_params); 2261 INIT_LIST_HEAD(¶ms->action); 2262 2263 params->conn_min_interval = hdev->le_conn_min_interval; 2264 params->conn_max_interval = hdev->le_conn_max_interval; 2265 params->conn_latency = hdev->le_conn_latency; 2266 params->supervision_timeout = hdev->le_supv_timeout; 2267 params->auto_connect = HCI_AUTO_CONN_DISABLED; 2268 2269 BT_DBG("addr %pMR (type %u)", addr, addr_type); 2270 2271 return params; 2272 } 2273 2274 void hci_conn_params_free(struct hci_conn_params *params) 2275 { 2276 hci_pend_le_list_del_init(params); 2277 2278 if (params->conn) { 2279 hci_conn_drop(params->conn); 2280 hci_conn_put(params->conn); 2281 } 2282 2283 list_del(¶ms->list); 2284 kfree(params); 2285 } 2286 2287 /* This function requires the caller holds hdev->lock */ 2288 void hci_conn_params_del(struct hci_dev *hdev, bdaddr_t *addr, u8 addr_type) 2289 { 2290 struct hci_conn_params *params; 2291 2292 params = hci_conn_params_lookup(hdev, addr, addr_type); 2293 if (!params) 2294 return; 2295 2296 hci_conn_params_free(params); 2297 2298 hci_update_passive_scan(hdev); 2299 2300 BT_DBG("addr %pMR (type %u)", addr, addr_type); 2301 } 2302 2303 /* This function requires the caller holds hdev->lock */ 2304 void hci_conn_params_clear_disabled(struct hci_dev *hdev) 2305 { 2306 struct hci_conn_params *params, *tmp; 2307 2308 list_for_each_entry_safe(params, tmp, &hdev->le_conn_params, list) { 2309 if (params->auto_connect != HCI_AUTO_CONN_DISABLED) 2310 continue; 2311 2312 /* If trying to establish one time connection to disabled 2313 * device, leave the params, but mark them as just once. 2314 */ 2315 if (params->explicit_connect) { 2316 params->auto_connect = HCI_AUTO_CONN_EXPLICIT; 2317 continue; 2318 } 2319 2320 hci_conn_params_free(params); 2321 } 2322 2323 BT_DBG("All LE disabled connection parameters were removed"); 2324 } 2325 2326 /* This function requires the caller holds hdev->lock */ 2327 static void hci_conn_params_clear_all(struct hci_dev *hdev) 2328 { 2329 struct hci_conn_params *params, *tmp; 2330 2331 list_for_each_entry_safe(params, tmp, &hdev->le_conn_params, list) 2332 hci_conn_params_free(params); 2333 2334 BT_DBG("All LE connection parameters were removed"); 2335 } 2336 2337 /* Copy the Identity Address of the controller. 2338 * 2339 * If the controller has a public BD_ADDR, then by default use that one. 2340 * If this is a LE only controller without a public address, default to 2341 * the static random address. 2342 * 2343 * For debugging purposes it is possible to force controllers with a 2344 * public address to use the static random address instead. 2345 * 2346 * In case BR/EDR has been disabled on a dual-mode controller and 2347 * userspace has configured a static address, then that address 2348 * becomes the identity address instead of the public BR/EDR address. 2349 */ 2350 void hci_copy_identity_address(struct hci_dev *hdev, bdaddr_t *bdaddr, 2351 u8 *bdaddr_type) 2352 { 2353 if (hci_dev_test_flag(hdev, HCI_FORCE_STATIC_ADDR) || 2354 !bacmp(&hdev->bdaddr, BDADDR_ANY) || 2355 (!hci_dev_test_flag(hdev, HCI_BREDR_ENABLED) && 2356 bacmp(&hdev->static_addr, BDADDR_ANY))) { 2357 bacpy(bdaddr, &hdev->static_addr); 2358 *bdaddr_type = ADDR_LE_DEV_RANDOM; 2359 } else { 2360 bacpy(bdaddr, &hdev->bdaddr); 2361 *bdaddr_type = ADDR_LE_DEV_PUBLIC; 2362 } 2363 } 2364 2365 static void hci_clear_wake_reason(struct hci_dev *hdev) 2366 { 2367 hci_dev_lock(hdev); 2368 2369 hdev->wake_reason = 0; 2370 bacpy(&hdev->wake_addr, BDADDR_ANY); 2371 hdev->wake_addr_type = 0; 2372 2373 hci_dev_unlock(hdev); 2374 } 2375 2376 static int hci_suspend_notifier(struct notifier_block *nb, unsigned long action, 2377 void *data) 2378 { 2379 struct hci_dev *hdev = 2380 container_of(nb, struct hci_dev, suspend_notifier); 2381 int ret = 0; 2382 2383 /* Userspace has full control of this device. Do nothing. */ 2384 if (hci_dev_test_flag(hdev, HCI_USER_CHANNEL)) 2385 return NOTIFY_DONE; 2386 2387 /* To avoid a potential race with hci_unregister_dev. */ 2388 hci_dev_hold(hdev); 2389 2390 switch (action) { 2391 case PM_HIBERNATION_PREPARE: 2392 case PM_SUSPEND_PREPARE: 2393 ret = hci_suspend_dev(hdev); 2394 break; 2395 case PM_POST_HIBERNATION: 2396 case PM_POST_SUSPEND: 2397 ret = hci_resume_dev(hdev); 2398 break; 2399 } 2400 2401 if (ret) 2402 bt_dev_err(hdev, "Suspend notifier action (%lu) failed: %d", 2403 action, ret); 2404 2405 hci_dev_put(hdev); 2406 return NOTIFY_DONE; 2407 } 2408 2409 /* Alloc HCI device */ 2410 struct hci_dev *hci_alloc_dev_priv(int sizeof_priv) 2411 { 2412 struct hci_dev *hdev; 2413 unsigned int alloc_size; 2414 2415 alloc_size = sizeof(*hdev); 2416 if (sizeof_priv) { 2417 /* Fixme: May need ALIGN-ment? */ 2418 alloc_size += sizeof_priv; 2419 } 2420 2421 hdev = kzalloc(alloc_size, GFP_KERNEL); 2422 if (!hdev) 2423 return NULL; 2424 2425 if (init_srcu_struct(&hdev->srcu)) { 2426 kfree(hdev); 2427 return NULL; 2428 } 2429 2430 hdev->pkt_type = (HCI_DM1 | HCI_DH1 | HCI_HV1); 2431 hdev->esco_type = (ESCO_HV1); 2432 hdev->link_mode = (HCI_LM_ACCEPT); 2433 hdev->num_iac = 0x01; /* One IAC support is mandatory */ 2434 hdev->io_capability = 0x03; /* No Input No Output */ 2435 hdev->manufacturer = 0xffff; /* Default to internal use */ 2436 hdev->inq_tx_power = HCI_TX_POWER_INVALID; 2437 hdev->adv_tx_power = HCI_TX_POWER_INVALID; 2438 hdev->adv_instance_cnt = 0; 2439 hdev->cur_adv_instance = 0x00; 2440 hdev->adv_instance_timeout = 0; 2441 2442 hdev->advmon_allowlist_duration = 300; 2443 hdev->advmon_no_filter_duration = 500; 2444 hdev->enable_advmon_interleave_scan = 0x00; /* Default to disable */ 2445 2446 hdev->sniff_max_interval = 800; 2447 hdev->sniff_min_interval = 80; 2448 2449 hdev->le_adv_channel_map = 0x07; 2450 hdev->le_adv_min_interval = 0x0800; 2451 hdev->le_adv_max_interval = 0x0800; 2452 hdev->le_scan_interval = DISCOV_LE_SCAN_INT_FAST; 2453 hdev->le_scan_window = DISCOV_LE_SCAN_WIN_FAST; 2454 hdev->le_scan_int_suspend = DISCOV_LE_SCAN_INT_SLOW1; 2455 hdev->le_scan_window_suspend = DISCOV_LE_SCAN_WIN_SLOW1; 2456 hdev->le_scan_int_discovery = DISCOV_LE_SCAN_INT; 2457 hdev->le_scan_window_discovery = DISCOV_LE_SCAN_WIN; 2458 hdev->le_scan_int_adv_monitor = DISCOV_LE_SCAN_INT_FAST; 2459 hdev->le_scan_window_adv_monitor = DISCOV_LE_SCAN_WIN_FAST; 2460 hdev->le_scan_int_connect = DISCOV_LE_SCAN_INT_CONN; 2461 hdev->le_scan_window_connect = DISCOV_LE_SCAN_WIN_CONN; 2462 hdev->le_conn_min_interval = 0x0018; 2463 hdev->le_conn_max_interval = 0x0028; 2464 hdev->le_conn_latency = 0x0000; 2465 hdev->le_supv_timeout = 0x002a; 2466 hdev->le_def_tx_len = 0x001b; 2467 hdev->le_def_tx_time = 0x0148; 2468 hdev->le_max_tx_len = 0x001b; 2469 hdev->le_max_tx_time = 0x0148; 2470 hdev->le_max_rx_len = 0x001b; 2471 hdev->le_max_rx_time = 0x0148; 2472 hdev->le_max_key_size = SMP_MAX_ENC_KEY_SIZE; 2473 hdev->le_min_key_size = SMP_MIN_ENC_KEY_SIZE; 2474 hdev->le_tx_def_phys = HCI_LE_SET_PHY_1M; 2475 hdev->le_rx_def_phys = HCI_LE_SET_PHY_1M; 2476 hdev->le_num_of_adv_sets = HCI_MAX_ADV_INSTANCES; 2477 hdev->def_multi_adv_rotation_duration = HCI_DEFAULT_ADV_DURATION; 2478 hdev->def_le_autoconnect_timeout = HCI_LE_CONN_TIMEOUT; 2479 hdev->min_le_tx_power = HCI_TX_POWER_INVALID; 2480 hdev->max_le_tx_power = HCI_TX_POWER_INVALID; 2481 2482 hdev->rpa_timeout = HCI_DEFAULT_RPA_TIMEOUT; 2483 hdev->discov_interleaved_timeout = DISCOV_INTERLEAVED_TIMEOUT; 2484 hdev->conn_info_min_age = DEFAULT_CONN_INFO_MIN_AGE; 2485 hdev->conn_info_max_age = DEFAULT_CONN_INFO_MAX_AGE; 2486 hdev->auth_payload_timeout = DEFAULT_AUTH_PAYLOAD_TIMEOUT; 2487 hdev->min_enc_key_size = HCI_MIN_ENC_KEY_SIZE; 2488 2489 /* default 1.28 sec page scan */ 2490 hdev->def_page_scan_type = PAGE_SCAN_TYPE_STANDARD; 2491 hdev->def_page_scan_int = 0x0800; 2492 hdev->def_page_scan_window = 0x0012; 2493 2494 mutex_init(&hdev->lock); 2495 mutex_init(&hdev->req_lock); 2496 mutex_init(&hdev->mgmt_pending_lock); 2497 mutex_init(&hdev->remote_oob_lock); 2498 2499 ida_init(&hdev->unset_handle_ida); 2500 2501 INIT_LIST_HEAD(&hdev->mesh_pending); 2502 INIT_LIST_HEAD(&hdev->mgmt_pending); 2503 INIT_LIST_HEAD(&hdev->reject_list); 2504 INIT_LIST_HEAD(&hdev->accept_list); 2505 INIT_LIST_HEAD(&hdev->uuids); 2506 INIT_LIST_HEAD(&hdev->link_keys); 2507 INIT_LIST_HEAD(&hdev->long_term_keys); 2508 INIT_LIST_HEAD(&hdev->identity_resolving_keys); 2509 INIT_LIST_HEAD(&hdev->remote_oob_data); 2510 INIT_LIST_HEAD(&hdev->le_accept_list); 2511 INIT_LIST_HEAD(&hdev->le_resolv_list); 2512 INIT_LIST_HEAD(&hdev->le_conn_params); 2513 INIT_LIST_HEAD(&hdev->pend_le_conns); 2514 INIT_LIST_HEAD(&hdev->pend_le_reports); 2515 INIT_LIST_HEAD(&hdev->conn_hash.list); 2516 INIT_LIST_HEAD(&hdev->adv_instances); 2517 INIT_LIST_HEAD(&hdev->blocked_keys); 2518 INIT_LIST_HEAD(&hdev->monitored_devices); 2519 2520 INIT_LIST_HEAD(&hdev->local_codecs); 2521 INIT_WORK(&hdev->rx_work, hci_rx_work); 2522 INIT_WORK(&hdev->cmd_work, hci_cmd_work); 2523 INIT_WORK(&hdev->tx_work, hci_tx_work); 2524 INIT_WORK(&hdev->power_on, hci_power_on); 2525 INIT_WORK(&hdev->error_reset, hci_error_reset); 2526 2527 hci_cmd_sync_init(hdev); 2528 2529 INIT_DELAYED_WORK(&hdev->power_off, hci_power_off); 2530 2531 skb_queue_head_init(&hdev->rx_q); 2532 skb_queue_head_init(&hdev->cmd_q); 2533 skb_queue_head_init(&hdev->raw_q); 2534 2535 init_waitqueue_head(&hdev->req_wait_q); 2536 2537 INIT_DELAYED_WORK(&hdev->cmd_timer, hci_cmd_timeout); 2538 INIT_DELAYED_WORK(&hdev->ncmd_timer, hci_ncmd_timeout); 2539 2540 hci_devcd_setup(hdev); 2541 2542 hci_init_sysfs(hdev); 2543 discovery_init(hdev); 2544 2545 return hdev; 2546 } 2547 EXPORT_SYMBOL(hci_alloc_dev_priv); 2548 2549 /* Free HCI device */ 2550 void hci_free_dev(struct hci_dev *hdev) 2551 { 2552 /* will free via device release */ 2553 put_device(&hdev->dev); 2554 } 2555 EXPORT_SYMBOL(hci_free_dev); 2556 2557 /* Register HCI device */ 2558 int hci_register_dev(struct hci_dev *hdev) 2559 { 2560 int id, error; 2561 2562 if (!hdev->open || !hdev->close || !hdev->send) 2563 return -EINVAL; 2564 2565 id = ida_alloc_max(&hci_index_ida, HCI_MAX_ID - 1, GFP_KERNEL); 2566 if (id < 0) 2567 return id; 2568 2569 error = dev_set_name(&hdev->dev, "hci%u", id); 2570 if (error) { 2571 ida_free(&hci_index_ida, id); 2572 return error; 2573 } 2574 2575 hdev->name = dev_name(&hdev->dev); 2576 hdev->id = id; 2577 2578 BT_DBG("%p name %s bus %d", hdev, hdev->name, hdev->bus); 2579 2580 hdev->workqueue = alloc_ordered_workqueue("%s", WQ_HIGHPRI, hdev->name); 2581 if (!hdev->workqueue) { 2582 error = -ENOMEM; 2583 goto err; 2584 } 2585 2586 hdev->req_workqueue = alloc_ordered_workqueue("%s", WQ_HIGHPRI, 2587 hdev->name); 2588 if (!hdev->req_workqueue) { 2589 destroy_workqueue(hdev->workqueue); 2590 error = -ENOMEM; 2591 goto err; 2592 } 2593 2594 if (!IS_ERR_OR_NULL(bt_debugfs)) 2595 hdev->debugfs = debugfs_create_dir(hdev->name, bt_debugfs); 2596 2597 error = device_add(&hdev->dev); 2598 if (error < 0) 2599 goto err_wqueue; 2600 2601 hci_leds_init(hdev); 2602 2603 hdev->rfkill = rfkill_alloc(hdev->name, &hdev->dev, 2604 RFKILL_TYPE_BLUETOOTH, &hci_rfkill_ops, 2605 hdev); 2606 if (hdev->rfkill) { 2607 if (rfkill_register(hdev->rfkill) < 0) { 2608 rfkill_destroy(hdev->rfkill); 2609 hdev->rfkill = NULL; 2610 } 2611 } 2612 2613 if (hdev->rfkill && rfkill_blocked(hdev->rfkill)) 2614 hci_dev_set_flag(hdev, HCI_RFKILLED); 2615 2616 hci_dev_set_flag(hdev, HCI_SETUP); 2617 hci_dev_set_flag(hdev, HCI_AUTO_OFF); 2618 2619 /* Assume BR/EDR support until proven otherwise (such as 2620 * through reading supported features during init. 2621 */ 2622 hci_dev_set_flag(hdev, HCI_BREDR_ENABLED); 2623 2624 write_lock(&hci_dev_list_lock); 2625 list_add(&hdev->list, &hci_dev_list); 2626 write_unlock(&hci_dev_list_lock); 2627 2628 /* Devices that are marked for raw-only usage are unconfigured 2629 * and should not be included in normal operation. 2630 */ 2631 if (hci_test_quirk(hdev, HCI_QUIRK_RAW_DEVICE)) 2632 hci_dev_set_flag(hdev, HCI_UNCONFIGURED); 2633 2634 /* Mark Remote Wakeup connection flag as supported if driver has wakeup 2635 * callback. 2636 */ 2637 if (hdev->wakeup) 2638 hdev->conn_flags |= HCI_CONN_FLAG_REMOTE_WAKEUP; 2639 2640 hci_sock_dev_event(hdev, HCI_DEV_REG); 2641 hci_dev_hold(hdev); 2642 2643 error = hci_register_suspend_notifier(hdev); 2644 if (error) 2645 BT_WARN("register suspend notifier failed error:%d\n", error); 2646 2647 idr_init(&hdev->adv_monitors_idr); 2648 msft_register(hdev); 2649 2650 queue_work(hdev->req_workqueue, &hdev->power_on); 2651 2652 return id; 2653 2654 err_wqueue: 2655 debugfs_remove_recursive(hdev->debugfs); 2656 destroy_workqueue(hdev->workqueue); 2657 destroy_workqueue(hdev->req_workqueue); 2658 err: 2659 ida_free(&hci_index_ida, hdev->id); 2660 2661 return error; 2662 } 2663 EXPORT_SYMBOL(hci_register_dev); 2664 2665 /* Unregister HCI device */ 2666 void hci_unregister_dev(struct hci_dev *hdev) 2667 { 2668 BT_DBG("%p name %s bus %d", hdev, hdev->name, hdev->bus); 2669 2670 mutex_lock(&hdev->unregister_lock); 2671 hci_dev_set_flag(hdev, HCI_UNREGISTER); 2672 mutex_unlock(&hdev->unregister_lock); 2673 2674 write_lock(&hci_dev_list_lock); 2675 list_del(&hdev->list); 2676 write_unlock(&hci_dev_list_lock); 2677 2678 synchronize_srcu(&hdev->srcu); 2679 cleanup_srcu_struct(&hdev->srcu); 2680 2681 disable_work_sync(&hdev->rx_work); 2682 disable_work_sync(&hdev->cmd_work); 2683 disable_work_sync(&hdev->tx_work); 2684 disable_work_sync(&hdev->power_on); 2685 disable_work_sync(&hdev->error_reset); 2686 disable_delayed_work_sync(&hdev->cmd_timer); 2687 disable_delayed_work_sync(&hdev->ncmd_timer); 2688 hci_devcd_shutdown(hdev); 2689 2690 hci_cmd_sync_clear(hdev); 2691 2692 hci_unregister_suspend_notifier(hdev); 2693 2694 hci_dev_do_close(hdev); 2695 2696 if (!test_bit(HCI_INIT, &hdev->flags) && 2697 !hci_dev_test_flag(hdev, HCI_SETUP) && 2698 !hci_dev_test_flag(hdev, HCI_CONFIG)) { 2699 hci_dev_lock(hdev); 2700 mgmt_index_removed(hdev); 2701 hci_dev_unlock(hdev); 2702 } 2703 2704 /* mgmt_index_removed should take care of emptying the 2705 * pending list */ 2706 BUG_ON(!list_empty(&hdev->mgmt_pending)); 2707 2708 hci_sock_dev_event(hdev, HCI_DEV_UNREG); 2709 2710 if (hdev->rfkill) { 2711 rfkill_unregister(hdev->rfkill); 2712 rfkill_destroy(hdev->rfkill); 2713 } 2714 2715 device_del(&hdev->dev); 2716 /* Actual cleanup is deferred until hci_release_dev(). */ 2717 hci_dev_put(hdev); 2718 } 2719 EXPORT_SYMBOL(hci_unregister_dev); 2720 2721 /* Release HCI device */ 2722 void hci_release_dev(struct hci_dev *hdev) 2723 { 2724 debugfs_remove_recursive(hdev->debugfs); 2725 kfree_const(hdev->hw_info); 2726 kfree_const(hdev->fw_info); 2727 2728 destroy_workqueue(hdev->workqueue); 2729 destroy_workqueue(hdev->req_workqueue); 2730 2731 hci_dev_lock(hdev); 2732 hci_bdaddr_list_clear(&hdev->reject_list); 2733 hci_bdaddr_list_clear(&hdev->accept_list); 2734 hci_uuids_clear(hdev); 2735 hci_link_keys_clear(hdev); 2736 hci_smp_ltks_clear(hdev); 2737 hci_smp_irks_clear(hdev); 2738 hci_remote_oob_data_clear(hdev); 2739 hci_adv_instances_clear(hdev); 2740 hci_adv_monitors_clear(hdev); 2741 hci_bdaddr_list_clear(&hdev->le_accept_list); 2742 hci_bdaddr_list_clear(&hdev->le_resolv_list); 2743 hci_conn_params_clear_all(hdev); 2744 hci_discovery_filter_clear(hdev); 2745 hci_blocked_keys_clear(hdev); 2746 hci_codec_list_clear(&hdev->local_codecs); 2747 msft_release(hdev); 2748 hci_dev_unlock(hdev); 2749 2750 ida_destroy(&hdev->unset_handle_ida); 2751 ida_free(&hci_index_ida, hdev->id); 2752 kfree_skb(hdev->sent_cmd); 2753 kfree_skb(hdev->req_skb); 2754 kfree_skb(hdev->recv_event); 2755 kfree(hdev); 2756 } 2757 EXPORT_SYMBOL(hci_release_dev); 2758 2759 int hci_register_suspend_notifier(struct hci_dev *hdev) 2760 { 2761 int ret = 0; 2762 2763 if (!hdev->suspend_notifier.notifier_call && 2764 !hci_test_quirk(hdev, HCI_QUIRK_NO_SUSPEND_NOTIFIER)) { 2765 hdev->suspend_notifier.notifier_call = hci_suspend_notifier; 2766 ret = register_pm_notifier(&hdev->suspend_notifier); 2767 } 2768 2769 return ret; 2770 } 2771 2772 int hci_unregister_suspend_notifier(struct hci_dev *hdev) 2773 { 2774 int ret = 0; 2775 2776 if (hdev->suspend_notifier.notifier_call) { 2777 ret = unregister_pm_notifier(&hdev->suspend_notifier); 2778 if (!ret) 2779 hdev->suspend_notifier.notifier_call = NULL; 2780 } 2781 2782 return ret; 2783 } 2784 2785 /* Cancel ongoing command synchronously: 2786 * 2787 * - Cancel command timer 2788 * - Reset command counter 2789 * - Cancel command request 2790 */ 2791 static void hci_cancel_cmd_sync(struct hci_dev *hdev, int err) 2792 { 2793 bt_dev_dbg(hdev, "err 0x%2.2x", err); 2794 2795 if (hci_dev_test_flag(hdev, HCI_UNREGISTER)) { 2796 disable_delayed_work_sync(&hdev->cmd_timer); 2797 disable_delayed_work_sync(&hdev->ncmd_timer); 2798 } else { 2799 cancel_delayed_work_sync(&hdev->cmd_timer); 2800 cancel_delayed_work_sync(&hdev->ncmd_timer); 2801 } 2802 2803 atomic_set(&hdev->cmd_cnt, 1); 2804 2805 hci_cmd_sync_cancel_sync(hdev, err); 2806 } 2807 2808 /* Suspend HCI device */ 2809 int hci_suspend_dev(struct hci_dev *hdev) 2810 { 2811 int ret; 2812 2813 bt_dev_dbg(hdev, ""); 2814 2815 /* Suspend should only act on when powered. */ 2816 if (!hdev_is_powered(hdev) || 2817 hci_dev_test_flag(hdev, HCI_UNREGISTER)) 2818 return 0; 2819 2820 /* If powering down don't attempt to suspend */ 2821 if (mgmt_powering_down(hdev)) 2822 return 0; 2823 2824 /* Cancel potentially blocking sync operation before suspend */ 2825 hci_cancel_cmd_sync(hdev, EHOSTDOWN); 2826 2827 hci_req_sync_lock(hdev); 2828 ret = hci_suspend_sync(hdev); 2829 hci_req_sync_unlock(hdev); 2830 2831 hci_clear_wake_reason(hdev); 2832 mgmt_suspending(hdev, hdev->suspend_state); 2833 2834 hci_sock_dev_event(hdev, HCI_DEV_SUSPEND); 2835 return ret; 2836 } 2837 EXPORT_SYMBOL(hci_suspend_dev); 2838 2839 /* Resume HCI device */ 2840 int hci_resume_dev(struct hci_dev *hdev) 2841 { 2842 int ret; 2843 2844 bt_dev_dbg(hdev, ""); 2845 2846 /* Resume should only act on when powered. */ 2847 if (!hdev_is_powered(hdev) || 2848 hci_dev_test_flag(hdev, HCI_UNREGISTER)) 2849 return 0; 2850 2851 /* If powering down don't attempt to resume */ 2852 if (mgmt_powering_down(hdev)) 2853 return 0; 2854 2855 hci_req_sync_lock(hdev); 2856 ret = hci_resume_sync(hdev); 2857 hci_req_sync_unlock(hdev); 2858 2859 mgmt_resuming(hdev, hdev->wake_reason, &hdev->wake_addr, 2860 hdev->wake_addr_type); 2861 2862 hci_sock_dev_event(hdev, HCI_DEV_RESUME); 2863 return ret; 2864 } 2865 EXPORT_SYMBOL(hci_resume_dev); 2866 2867 /* Reset HCI device */ 2868 int __hci_reset_dev(struct hci_dev *hdev, u8 hw_err_code) 2869 { 2870 const u8 hw_err[] = { HCI_EV_HARDWARE_ERROR, 0x01, hw_err_code }; 2871 struct sk_buff *skb; 2872 2873 skb = bt_skb_alloc(3, GFP_ATOMIC); 2874 if (!skb) 2875 return -ENOMEM; 2876 2877 hci_skb_pkt_type(skb) = HCI_EVENT_PKT; 2878 skb_put_data(skb, hw_err, 3); 2879 2880 bt_dev_err(hdev, "Injecting HCI hardware error event"); 2881 2882 /* Send Hardware Error to upper stack */ 2883 return hci_recv_frame(hdev, skb); 2884 } 2885 EXPORT_SYMBOL(__hci_reset_dev); 2886 2887 static u8 hci_dev_classify_pkt_type(struct hci_dev *hdev, struct sk_buff *skb) 2888 { 2889 if (hdev->classify_pkt_type) 2890 return hdev->classify_pkt_type(hdev, skb); 2891 2892 return hci_skb_pkt_type(skb); 2893 } 2894 2895 /* Receive frame from HCI drivers */ 2896 int hci_recv_frame(struct hci_dev *hdev, struct sk_buff *skb) 2897 { 2898 u8 dev_pkt_type; 2899 2900 if (!hdev || (!test_bit(HCI_UP, &hdev->flags) 2901 && !test_bit(HCI_INIT, &hdev->flags))) { 2902 kfree_skb(skb); 2903 return -ENXIO; 2904 } 2905 2906 /* Check if the driver agree with packet type classification */ 2907 dev_pkt_type = hci_dev_classify_pkt_type(hdev, skb); 2908 if (hci_skb_pkt_type(skb) != dev_pkt_type) { 2909 hci_skb_pkt_type(skb) = dev_pkt_type; 2910 } 2911 2912 switch (hci_skb_pkt_type(skb)) { 2913 case HCI_EVENT_PKT: 2914 break; 2915 case HCI_ACLDATA_PKT: 2916 /* Detect if ISO packet has been sent as ACL */ 2917 if (hci_conn_num(hdev, CIS_LINK) || 2918 hci_conn_num(hdev, BIS_LINK) || 2919 hci_conn_num(hdev, PA_LINK)) { 2920 __u8 type; 2921 2922 type = hci_conn_lookup_type(hdev, hci_acl_handle(skb)); 2923 if (type == CIS_LINK || type == BIS_LINK || 2924 type == PA_LINK) 2925 hci_skb_pkt_type(skb) = HCI_ISODATA_PKT; 2926 } 2927 break; 2928 case HCI_SCODATA_PKT: 2929 break; 2930 case HCI_ISODATA_PKT: 2931 break; 2932 case HCI_DRV_PKT: 2933 break; 2934 default: 2935 kfree_skb(skb); 2936 return -EINVAL; 2937 } 2938 2939 /* Incoming skb */ 2940 bt_cb(skb)->incoming = 1; 2941 2942 /* Time stamp */ 2943 __net_timestamp(skb); 2944 2945 skb_queue_tail(&hdev->rx_q, skb); 2946 queue_work(hdev->workqueue, &hdev->rx_work); 2947 2948 return 0; 2949 } 2950 EXPORT_SYMBOL(hci_recv_frame); 2951 2952 /* Receive diagnostic message from HCI drivers */ 2953 int hci_recv_diag(struct hci_dev *hdev, struct sk_buff *skb) 2954 { 2955 /* Mark as diagnostic packet */ 2956 hci_skb_pkt_type(skb) = HCI_DIAG_PKT; 2957 2958 /* Time stamp */ 2959 __net_timestamp(skb); 2960 2961 skb_queue_tail(&hdev->rx_q, skb); 2962 queue_work(hdev->workqueue, &hdev->rx_work); 2963 2964 return 0; 2965 } 2966 EXPORT_SYMBOL(hci_recv_diag); 2967 2968 void hci_set_hw_info(struct hci_dev *hdev, const char *fmt, ...) 2969 { 2970 va_list vargs; 2971 2972 va_start(vargs, fmt); 2973 kfree_const(hdev->hw_info); 2974 hdev->hw_info = kvasprintf_const(GFP_KERNEL, fmt, vargs); 2975 va_end(vargs); 2976 } 2977 EXPORT_SYMBOL(hci_set_hw_info); 2978 2979 void hci_set_fw_info(struct hci_dev *hdev, const char *fmt, ...) 2980 { 2981 va_list vargs; 2982 2983 va_start(vargs, fmt); 2984 kfree_const(hdev->fw_info); 2985 hdev->fw_info = kvasprintf_const(GFP_KERNEL, fmt, vargs); 2986 va_end(vargs); 2987 } 2988 EXPORT_SYMBOL(hci_set_fw_info); 2989 2990 /* ---- Interface to upper protocols ---- */ 2991 2992 int hci_register_cb(struct hci_cb *cb) 2993 { 2994 BT_DBG("%p name %s", cb, cb->name); 2995 2996 mutex_lock(&hci_cb_list_lock); 2997 list_add_tail(&cb->list, &hci_cb_list); 2998 mutex_unlock(&hci_cb_list_lock); 2999 3000 return 0; 3001 } 3002 EXPORT_SYMBOL(hci_register_cb); 3003 3004 int hci_unregister_cb(struct hci_cb *cb) 3005 { 3006 BT_DBG("%p name %s", cb, cb->name); 3007 3008 mutex_lock(&hci_cb_list_lock); 3009 list_del(&cb->list); 3010 mutex_unlock(&hci_cb_list_lock); 3011 3012 return 0; 3013 } 3014 EXPORT_SYMBOL(hci_unregister_cb); 3015 3016 static int hci_send_frame(struct hci_dev *hdev, struct sk_buff *skb) 3017 { 3018 int err; 3019 3020 BT_DBG("%s type %d len %d", hdev->name, hci_skb_pkt_type(skb), 3021 skb->len); 3022 3023 /* Time stamp */ 3024 __net_timestamp(skb); 3025 3026 /* Send copy to monitor */ 3027 hci_send_to_monitor(hdev, skb); 3028 3029 if (atomic_read(&hdev->promisc)) { 3030 /* Send copy to the sockets */ 3031 hci_send_to_sock(hdev, skb); 3032 } 3033 3034 /* Get rid of skb owner, prior to sending to the driver. */ 3035 skb_orphan(skb); 3036 3037 if (!test_bit(HCI_RUNNING, &hdev->flags)) { 3038 kfree_skb(skb); 3039 return -EINVAL; 3040 } 3041 3042 if (hci_skb_pkt_type(skb) == HCI_DRV_PKT) { 3043 /* Intercept HCI Drv packet here and don't go with hdev->send 3044 * callback. 3045 */ 3046 err = hci_drv_process_cmd(hdev, skb); 3047 kfree_skb(skb); 3048 return err; 3049 } 3050 3051 err = hdev->send(hdev, skb); 3052 if (err < 0) { 3053 bt_dev_err(hdev, "sending frame failed (%d)", err); 3054 kfree_skb(skb); 3055 return err; 3056 } 3057 3058 return 0; 3059 } 3060 3061 static int hci_send_conn_frame(struct hci_dev *hdev, struct hci_conn *conn, 3062 struct sk_buff *skb) 3063 { 3064 hci_conn_tx_queue(conn, skb); 3065 return hci_send_frame(hdev, skb); 3066 } 3067 3068 /* Send HCI command */ 3069 int hci_send_cmd(struct hci_dev *hdev, __u16 opcode, __u32 plen, 3070 const void *param) 3071 { 3072 struct sk_buff *skb; 3073 3074 BT_DBG("%s opcode 0x%4.4x plen %d", hdev->name, opcode, plen); 3075 3076 skb = hci_cmd_sync_alloc(hdev, opcode, plen, param, NULL); 3077 if (!skb) { 3078 bt_dev_err(hdev, "no memory for command"); 3079 return -ENOMEM; 3080 } 3081 3082 /* Stand-alone HCI commands must be flagged as 3083 * single-command requests. 3084 */ 3085 bt_cb(skb)->hci.req_flags |= HCI_REQ_START; 3086 3087 skb_queue_tail(&hdev->cmd_q, skb); 3088 queue_work(hdev->workqueue, &hdev->cmd_work); 3089 3090 return 0; 3091 } 3092 3093 int __hci_cmd_send(struct hci_dev *hdev, u16 opcode, u32 plen, 3094 const void *param) 3095 { 3096 struct sk_buff *skb; 3097 3098 if (hci_opcode_ogf(opcode) != 0x3f) { 3099 /* A controller receiving a command shall respond with either 3100 * a Command Status Event or a Command Complete Event. 3101 * Therefore, all standard HCI commands must be sent via the 3102 * standard API, using hci_send_cmd or hci_cmd_sync helpers. 3103 * Some vendors do not comply with this rule for vendor-specific 3104 * commands and do not return any event. We want to support 3105 * unresponded commands for such cases only. 3106 */ 3107 bt_dev_err(hdev, "unresponded command not supported"); 3108 return -EINVAL; 3109 } 3110 3111 skb = hci_cmd_sync_alloc(hdev, opcode, plen, param, NULL); 3112 if (!skb) { 3113 bt_dev_err(hdev, "no memory for command (opcode 0x%4.4x)", 3114 opcode); 3115 return -ENOMEM; 3116 } 3117 3118 hci_send_frame(hdev, skb); 3119 3120 return 0; 3121 } 3122 EXPORT_SYMBOL(__hci_cmd_send); 3123 3124 /* Get data from the previously sent command */ 3125 static void *hci_cmd_data(struct sk_buff *skb, __u16 opcode) 3126 { 3127 struct hci_command_hdr *hdr; 3128 3129 if (!skb || skb->len < HCI_COMMAND_HDR_SIZE) 3130 return NULL; 3131 3132 hdr = (void *)skb->data; 3133 3134 if (hdr->opcode != cpu_to_le16(opcode)) 3135 return NULL; 3136 3137 return skb->data + HCI_COMMAND_HDR_SIZE; 3138 } 3139 3140 /* Get data from the previously sent command */ 3141 void *hci_sent_cmd_data(struct hci_dev *hdev, __u16 opcode) 3142 { 3143 void *data; 3144 3145 /* Check if opcode matches last sent command */ 3146 data = hci_cmd_data(hdev->sent_cmd, opcode); 3147 if (!data) 3148 /* Check if opcode matches last request */ 3149 data = hci_cmd_data(hdev->req_skb, opcode); 3150 3151 return data; 3152 } 3153 3154 /* Get data from last received event */ 3155 void *hci_recv_event_data(struct hci_dev *hdev, __u8 event) 3156 { 3157 struct hci_event_hdr *hdr; 3158 int offset; 3159 3160 if (!hdev->recv_event) 3161 return NULL; 3162 3163 hdr = (void *)hdev->recv_event->data; 3164 offset = sizeof(*hdr); 3165 3166 if (hdr->evt != event) { 3167 /* In case of LE metaevent check the subevent match */ 3168 if (hdr->evt == HCI_EV_LE_META) { 3169 struct hci_ev_le_meta *ev; 3170 3171 ev = (void *)hdev->recv_event->data + offset; 3172 offset += sizeof(*ev); 3173 if (ev->subevent == event) 3174 goto found; 3175 } 3176 return NULL; 3177 } 3178 3179 found: 3180 bt_dev_dbg(hdev, "event 0x%2.2x", event); 3181 3182 return hdev->recv_event->data + offset; 3183 } 3184 3185 /* Send ACL data */ 3186 static void hci_add_acl_hdr(struct sk_buff *skb, __u16 handle, __u16 flags) 3187 { 3188 struct hci_acl_hdr *hdr; 3189 int len = skb->len; 3190 3191 skb_push(skb, HCI_ACL_HDR_SIZE); 3192 skb_reset_transport_header(skb); 3193 hdr = (struct hci_acl_hdr *)skb_transport_header(skb); 3194 hdr->handle = cpu_to_le16(hci_handle_pack(handle, flags)); 3195 hdr->dlen = cpu_to_le16(len); 3196 } 3197 3198 static void hci_queue_acl(struct hci_chan *chan, struct sk_buff_head *queue, 3199 struct sk_buff *skb, __u16 flags) 3200 { 3201 struct hci_conn *conn = chan->conn; 3202 struct hci_dev *hdev = conn->hdev; 3203 struct sk_buff *list; 3204 3205 skb->len = skb_headlen(skb); 3206 skb->data_len = 0; 3207 3208 hci_skb_pkt_type(skb) = HCI_ACLDATA_PKT; 3209 3210 hci_add_acl_hdr(skb, conn->handle, flags); 3211 3212 list = skb_shinfo(skb)->frag_list; 3213 if (!list) { 3214 /* Non fragmented */ 3215 BT_DBG("%s nonfrag skb %p len %d", hdev->name, skb, skb->len); 3216 3217 skb_queue_tail(queue, skb); 3218 } else { 3219 /* Fragmented */ 3220 BT_DBG("%s frag %p len %d", hdev->name, skb, skb->len); 3221 3222 skb_shinfo(skb)->frag_list = NULL; 3223 3224 /* Queue all fragments atomically. We need to use spin_lock_bh 3225 * here because of 6LoWPAN links, as there this function is 3226 * called from softirq and using normal spin lock could cause 3227 * deadlocks. 3228 */ 3229 spin_lock_bh(&queue->lock); 3230 3231 __skb_queue_tail(queue, skb); 3232 3233 flags &= ~ACL_START; 3234 flags |= ACL_CONT; 3235 do { 3236 skb = list; list = list->next; 3237 3238 hci_skb_pkt_type(skb) = HCI_ACLDATA_PKT; 3239 hci_add_acl_hdr(skb, conn->handle, flags); 3240 3241 BT_DBG("%s frag %p len %d", hdev->name, skb, skb->len); 3242 3243 __skb_queue_tail(queue, skb); 3244 } while (list); 3245 3246 spin_unlock_bh(&queue->lock); 3247 } 3248 3249 bt_dev_dbg(hdev, "chan %p queued %d", chan, skb_queue_len(queue)); 3250 } 3251 3252 /* Queue hdev->tx_work, unless hdev->workqueue is being drained by 3253 * hci_dev_close_sync(), which would otherwise WARN and drop the work. 3254 */ 3255 static void hci_sched_tx(struct hci_dev *hdev) 3256 { 3257 rcu_read_lock(); 3258 if (!hci_dev_test_flag(hdev, HCI_CMD_DRAIN_WORKQUEUE)) 3259 queue_work(hdev->workqueue, &hdev->tx_work); 3260 rcu_read_unlock(); 3261 } 3262 3263 void hci_send_acl(struct hci_chan *chan, struct sk_buff *skb, __u16 flags) 3264 { 3265 struct hci_dev *hdev = chan->conn->hdev; 3266 3267 BT_DBG("%s chan %p flags 0x%4.4x", hdev->name, chan, flags); 3268 3269 hci_queue_acl(chan, &chan->data_q, skb, flags); 3270 3271 hci_sched_tx(hdev); 3272 } 3273 3274 /* Send SCO data */ 3275 void hci_send_sco(struct hci_conn *conn, struct sk_buff *skb) 3276 { 3277 struct hci_dev *hdev = conn->hdev; 3278 struct hci_sco_hdr hdr; 3279 3280 BT_DBG("%s len %d", hdev->name, skb->len); 3281 3282 hdr.handle = cpu_to_le16(conn->handle); 3283 hdr.dlen = skb->len; 3284 3285 skb_push(skb, HCI_SCO_HDR_SIZE); 3286 skb_reset_transport_header(skb); 3287 memcpy(skb_transport_header(skb), &hdr, HCI_SCO_HDR_SIZE); 3288 3289 hci_skb_pkt_type(skb) = HCI_SCODATA_PKT; 3290 3291 skb_queue_tail(&conn->data_q, skb); 3292 3293 bt_dev_dbg(hdev, "hcon %p queued %d", conn, 3294 skb_queue_len(&conn->data_q)); 3295 3296 hci_sched_tx(hdev); 3297 } 3298 3299 /* Send ISO data */ 3300 static void hci_add_iso_hdr(struct sk_buff *skb, __u16 handle, __u8 flags) 3301 { 3302 struct hci_iso_hdr *hdr; 3303 int len = skb->len; 3304 3305 skb_push(skb, HCI_ISO_HDR_SIZE); 3306 skb_reset_transport_header(skb); 3307 hdr = (struct hci_iso_hdr *)skb_transport_header(skb); 3308 hdr->handle = cpu_to_le16(hci_handle_pack(handle, flags)); 3309 hdr->dlen = cpu_to_le16(len); 3310 } 3311 3312 static void hci_queue_iso(struct hci_conn *conn, struct sk_buff_head *queue, 3313 struct sk_buff *skb) 3314 { 3315 struct hci_dev *hdev = conn->hdev; 3316 struct sk_buff *list; 3317 __u16 flags; 3318 3319 skb->len = skb_headlen(skb); 3320 skb->data_len = 0; 3321 3322 hci_skb_pkt_type(skb) = HCI_ISODATA_PKT; 3323 3324 list = skb_shinfo(skb)->frag_list; 3325 3326 flags = hci_iso_flags_pack(list ? ISO_START : ISO_SINGLE, 0x00); 3327 hci_add_iso_hdr(skb, conn->handle, flags); 3328 3329 if (!list) { 3330 /* Non fragmented */ 3331 BT_DBG("%s nonfrag skb %p len %d", hdev->name, skb, skb->len); 3332 3333 skb_queue_tail(queue, skb); 3334 } else { 3335 /* Fragmented */ 3336 BT_DBG("%s frag %p len %d", hdev->name, skb, skb->len); 3337 3338 skb_shinfo(skb)->frag_list = NULL; 3339 3340 spin_lock_bh(&queue->lock); 3341 3342 __skb_queue_tail(queue, skb); 3343 3344 do { 3345 skb = list; list = list->next; 3346 3347 hci_skb_pkt_type(skb) = HCI_ISODATA_PKT; 3348 flags = hci_iso_flags_pack(list ? ISO_CONT : ISO_END, 3349 0x00); 3350 hci_add_iso_hdr(skb, conn->handle, flags); 3351 3352 BT_DBG("%s frag %p len %d", hdev->name, skb, skb->len); 3353 3354 __skb_queue_tail(queue, skb); 3355 } while (list); 3356 3357 spin_unlock_bh(&queue->lock); 3358 } 3359 3360 bt_dev_dbg(hdev, "hcon %p queued %d", conn, skb_queue_len(queue)); 3361 } 3362 3363 void hci_send_iso(struct hci_conn *conn, struct sk_buff *skb) 3364 { 3365 struct hci_dev *hdev = conn->hdev; 3366 3367 BT_DBG("%s len %d", hdev->name, skb->len); 3368 3369 hci_queue_iso(conn, &conn->data_q, skb); 3370 3371 hci_sched_tx(hdev); 3372 } 3373 3374 /* ---- HCI TX task (outgoing data) ---- */ 3375 3376 /* HCI Connection scheduler */ 3377 static inline void hci_quote_sent(struct hci_conn *conn, int num, int *quote) 3378 { 3379 struct hci_dev *hdev; 3380 int cnt, q; 3381 3382 if (!conn) { 3383 *quote = 0; 3384 return; 3385 } 3386 3387 hdev = conn->hdev; 3388 3389 switch (conn->type) { 3390 case ACL_LINK: 3391 cnt = hdev->acl_cnt; 3392 break; 3393 case SCO_LINK: 3394 case ESCO_LINK: 3395 cnt = hdev->sco_cnt; 3396 break; 3397 case LE_LINK: 3398 cnt = hdev->le_mtu ? hdev->le_cnt : hdev->acl_cnt; 3399 break; 3400 case CIS_LINK: 3401 case BIS_LINK: 3402 case PA_LINK: 3403 cnt = hdev->iso_cnt; 3404 break; 3405 default: 3406 cnt = 0; 3407 bt_dev_err(hdev, "unknown link type %d", conn->type); 3408 } 3409 3410 q = cnt / num; 3411 *quote = q ? q : 1; 3412 } 3413 3414 static struct hci_conn *hci_low_sent(struct hci_dev *hdev, __u8 type, 3415 int *quote) 3416 { 3417 struct hci_conn_hash *h = &hdev->conn_hash; 3418 struct hci_conn *conn = NULL, *c; 3419 unsigned int num = 0, min = ~0; 3420 3421 rcu_read_lock(); 3422 3423 list_for_each_entry_rcu(c, &h->list, list) { 3424 if (c->type != type || 3425 skb_queue_empty(&c->data_q)) 3426 continue; 3427 3428 bt_dev_dbg(hdev, "hcon %p state %s queued %d", c, 3429 state_to_string(c->state), 3430 skb_queue_len(&c->data_q)); 3431 3432 if (c->state != BT_CONNECTED && c->state != BT_CONFIG) 3433 continue; 3434 3435 num++; 3436 3437 if (c->sent < min) { 3438 min = c->sent; 3439 conn = c; 3440 } 3441 3442 if (hci_conn_num(hdev, type) == num) 3443 break; 3444 } 3445 3446 rcu_read_unlock(); 3447 3448 hci_quote_sent(conn, num, quote); 3449 3450 BT_DBG("conn %p quote %d", conn, *quote); 3451 return conn; 3452 } 3453 3454 static void hci_link_tx_to(struct hci_dev *hdev, __u8 type) 3455 { 3456 struct hci_conn_hash *h = &hdev->conn_hash; 3457 struct hci_conn *c; 3458 3459 bt_dev_err(hdev, "link tx timeout"); 3460 3461 hci_dev_lock(hdev); 3462 3463 /* Kill stalled connections */ 3464 list_for_each_entry(c, &h->list, list) { 3465 if (c->type == type && c->sent) { 3466 bt_dev_err(hdev, "killing stalled connection %pMR", 3467 &c->dst); 3468 hci_disconnect(c, HCI_ERROR_REMOTE_USER_TERM); 3469 } 3470 } 3471 3472 hci_dev_unlock(hdev); 3473 } 3474 3475 static struct hci_chan *hci_chan_sent(struct hci_dev *hdev, __u8 type, 3476 int *quote) 3477 { 3478 struct hci_conn_hash *h = &hdev->conn_hash; 3479 struct hci_chan *chan = NULL; 3480 unsigned int num = 0, min = ~0, cur_prio = 0; 3481 struct hci_conn *conn; 3482 int conn_num = 0; 3483 3484 BT_DBG("%s", hdev->name); 3485 3486 rcu_read_lock(); 3487 3488 list_for_each_entry_rcu(conn, &h->list, list) { 3489 struct hci_chan *tmp; 3490 3491 if (conn->type != type) 3492 continue; 3493 3494 if (conn->state != BT_CONNECTED && conn->state != BT_CONFIG) 3495 continue; 3496 3497 conn_num++; 3498 3499 list_for_each_entry_rcu(tmp, &conn->chan_list, list) { 3500 struct sk_buff *skb; 3501 3502 if (skb_queue_empty(&tmp->data_q)) 3503 continue; 3504 3505 skb = skb_peek(&tmp->data_q); 3506 if (skb->priority < cur_prio) 3507 continue; 3508 3509 if (skb->priority > cur_prio) { 3510 num = 0; 3511 min = ~0; 3512 cur_prio = skb->priority; 3513 } 3514 3515 num++; 3516 3517 if (conn->sent < min) { 3518 min = conn->sent; 3519 chan = tmp; 3520 } 3521 } 3522 3523 if (hci_conn_num(hdev, type) == conn_num) 3524 break; 3525 } 3526 3527 rcu_read_unlock(); 3528 3529 if (!chan) 3530 return NULL; 3531 3532 hci_quote_sent(chan->conn, num, quote); 3533 3534 BT_DBG("chan %p quote %d", chan, *quote); 3535 return chan; 3536 } 3537 3538 static void hci_prio_recalculate(struct hci_dev *hdev, __u8 type) 3539 { 3540 struct hci_conn_hash *h = &hdev->conn_hash; 3541 struct hci_conn *conn; 3542 int num = 0; 3543 3544 BT_DBG("%s", hdev->name); 3545 3546 rcu_read_lock(); 3547 3548 list_for_each_entry_rcu(conn, &h->list, list) { 3549 struct hci_chan *chan; 3550 3551 if (conn->type != type) 3552 continue; 3553 3554 if (conn->state != BT_CONNECTED && conn->state != BT_CONFIG) 3555 continue; 3556 3557 num++; 3558 3559 list_for_each_entry_rcu(chan, &conn->chan_list, list) { 3560 struct sk_buff *skb; 3561 3562 if (chan->sent) { 3563 chan->sent = 0; 3564 continue; 3565 } 3566 3567 if (skb_queue_empty(&chan->data_q)) 3568 continue; 3569 3570 skb = skb_peek(&chan->data_q); 3571 if (skb->priority >= HCI_PRIO_MAX - 1) 3572 continue; 3573 3574 skb->priority = HCI_PRIO_MAX - 1; 3575 3576 BT_DBG("chan %p skb %p promoted to %d", chan, skb, 3577 skb->priority); 3578 } 3579 3580 if (hci_conn_num(hdev, type) == num) 3581 break; 3582 } 3583 3584 rcu_read_unlock(); 3585 3586 } 3587 3588 static void __check_timeout(struct hci_dev *hdev, unsigned int cnt, u8 type) 3589 { 3590 unsigned long timeout; 3591 3592 if (hci_dev_test_flag(hdev, HCI_UNCONFIGURED)) 3593 return; 3594 3595 switch (type) { 3596 case ACL_LINK: 3597 /* tx timeout must be longer than maximum link supervision 3598 * timeout (40.9 seconds) 3599 */ 3600 timeout = hdev->acl_last_tx + HCI_ACL_TX_TIMEOUT; 3601 break; 3602 case LE_LINK: 3603 /* tx timeout must be longer than maximum link supervision 3604 * timeout (40.9 seconds) 3605 */ 3606 timeout = hdev->le_last_tx + HCI_ACL_TX_TIMEOUT; 3607 break; 3608 case CIS_LINK: 3609 case BIS_LINK: 3610 case PA_LINK: 3611 /* tx timeout must be longer than the maximum transport latency 3612 * (8.388607 seconds) 3613 */ 3614 timeout = hdev->iso_last_tx + HCI_ISO_TX_TIMEOUT; 3615 break; 3616 default: 3617 return; 3618 } 3619 3620 if (!cnt && time_after(jiffies, timeout)) 3621 hci_link_tx_to(hdev, type); 3622 } 3623 3624 /* Schedule SCO */ 3625 static void __hci_sched_sco(struct hci_dev *hdev, __u8 type) 3626 { 3627 struct hci_conn *conn; 3628 struct sk_buff *skb; 3629 int quote, *cnt; 3630 unsigned int pkts = hdev->sco_pkts; 3631 3632 lockdep_assert_held(&hdev->lock); 3633 3634 bt_dev_dbg(hdev, "type %u", type); 3635 3636 if (!hci_conn_num(hdev, type) || !pkts) 3637 return; 3638 3639 /* Use sco_pkts if flow control has not been enabled which will limit 3640 * the amount of buffer sent in a row. 3641 */ 3642 if (!hci_dev_test_flag(hdev, HCI_SCO_FLOWCTL)) 3643 cnt = &pkts; 3644 else 3645 cnt = &hdev->sco_cnt; 3646 3647 while (*cnt && (conn = hci_low_sent(hdev, type, "e))) { 3648 while (quote-- && (skb = skb_dequeue(&conn->data_q))) { 3649 BT_DBG("skb %p len %d", skb, skb->len); 3650 hci_send_conn_frame(hdev, conn, skb); 3651 3652 conn->sent++; 3653 if (conn->sent == ~0) 3654 conn->sent = 0; 3655 (*cnt)--; 3656 } 3657 } 3658 3659 /* Rescheduled if all packets were sent and flow control is not enabled 3660 * as there could be more packets queued that could not be sent and 3661 * since no HCI_EV_NUM_COMP_PKTS event will be generated the reschedule 3662 * needs to be forced. 3663 */ 3664 if (!pkts && !hci_dev_test_flag(hdev, HCI_SCO_FLOWCTL)) 3665 queue_work(hdev->workqueue, &hdev->tx_work); 3666 } 3667 3668 static void hci_sched_sco(struct hci_dev *hdev, __u8 type) 3669 { 3670 hci_dev_lock(hdev); 3671 __hci_sched_sco(hdev, type); 3672 hci_dev_unlock(hdev); 3673 } 3674 3675 static void hci_sched_acl_pkt(struct hci_dev *hdev) 3676 { 3677 unsigned int cnt = hdev->acl_cnt; 3678 struct hci_chan *chan; 3679 struct sk_buff *skb; 3680 int quote; 3681 3682 __check_timeout(hdev, cnt, ACL_LINK); 3683 3684 hci_dev_lock(hdev); 3685 3686 while (hdev->acl_cnt && 3687 (chan = hci_chan_sent(hdev, ACL_LINK, "e))) { 3688 u32 priority = (skb_peek(&chan->data_q))->priority; 3689 while (quote-- && (skb = skb_peek(&chan->data_q))) { 3690 BT_DBG("chan %p skb %p len %d priority %u", chan, skb, 3691 skb->len, skb->priority); 3692 3693 /* Stop if priority has changed */ 3694 if (skb->priority < priority) 3695 break; 3696 3697 skb = skb_dequeue(&chan->data_q); 3698 3699 hci_conn_enter_active_mode(chan->conn, 3700 bt_cb(skb)->force_active); 3701 3702 hci_send_conn_frame(hdev, chan->conn, skb); 3703 hdev->acl_last_tx = jiffies; 3704 3705 hdev->acl_cnt--; 3706 chan->sent++; 3707 chan->conn->sent++; 3708 3709 /* Send pending SCO packets right away */ 3710 __hci_sched_sco(hdev, SCO_LINK); 3711 __hci_sched_sco(hdev, ESCO_LINK); 3712 } 3713 } 3714 3715 if (cnt != hdev->acl_cnt) 3716 hci_prio_recalculate(hdev, ACL_LINK); 3717 3718 hci_dev_unlock(hdev); 3719 } 3720 3721 static void hci_sched_acl(struct hci_dev *hdev) 3722 { 3723 BT_DBG("%s", hdev->name); 3724 3725 /* No ACL link over BR/EDR controller */ 3726 if (!hci_conn_num(hdev, ACL_LINK)) 3727 return; 3728 3729 hci_sched_acl_pkt(hdev); 3730 } 3731 3732 static void hci_sched_le(struct hci_dev *hdev) 3733 { 3734 struct hci_chan *chan; 3735 struct sk_buff *skb; 3736 int quote, *cnt, tmp; 3737 3738 BT_DBG("%s", hdev->name); 3739 3740 if (!hci_conn_num(hdev, LE_LINK)) 3741 return; 3742 3743 cnt = hdev->le_pkts ? &hdev->le_cnt : &hdev->acl_cnt; 3744 3745 __check_timeout(hdev, *cnt, LE_LINK); 3746 3747 hci_dev_lock(hdev); 3748 3749 tmp = *cnt; 3750 while (*cnt && (chan = hci_chan_sent(hdev, LE_LINK, "e))) { 3751 u32 priority = (skb_peek(&chan->data_q))->priority; 3752 while (quote-- && (skb = skb_peek(&chan->data_q))) { 3753 BT_DBG("chan %p skb %p len %d priority %u", chan, skb, 3754 skb->len, skb->priority); 3755 3756 /* Stop if priority has changed */ 3757 if (skb->priority < priority) 3758 break; 3759 3760 skb = skb_dequeue(&chan->data_q); 3761 3762 hci_send_conn_frame(hdev, chan->conn, skb); 3763 hdev->le_last_tx = jiffies; 3764 3765 (*cnt)--; 3766 chan->sent++; 3767 chan->conn->sent++; 3768 3769 /* Send pending SCO packets right away */ 3770 __hci_sched_sco(hdev, SCO_LINK); 3771 __hci_sched_sco(hdev, ESCO_LINK); 3772 } 3773 } 3774 3775 if (*cnt != tmp) 3776 hci_prio_recalculate(hdev, LE_LINK); 3777 3778 hci_dev_unlock(hdev); 3779 } 3780 3781 /* Schedule iso */ 3782 static void hci_sched_iso(struct hci_dev *hdev, __u8 type) 3783 { 3784 struct hci_conn *conn; 3785 struct sk_buff *skb; 3786 int quote, *cnt; 3787 3788 BT_DBG("%s", hdev->name); 3789 3790 if (!hci_conn_num(hdev, type)) 3791 return; 3792 3793 cnt = &hdev->iso_cnt; 3794 3795 __check_timeout(hdev, *cnt, type); 3796 3797 hci_dev_lock(hdev); 3798 3799 while (*cnt && (conn = hci_low_sent(hdev, type, "e))) { 3800 while (quote-- && (skb = skb_dequeue(&conn->data_q))) { 3801 BT_DBG("skb %p len %d", skb, skb->len); 3802 3803 hci_send_conn_frame(hdev, conn, skb); 3804 hdev->iso_last_tx = jiffies; 3805 3806 conn->sent++; 3807 if (conn->sent == ~0) 3808 conn->sent = 0; 3809 (*cnt)--; 3810 } 3811 } 3812 3813 hci_dev_unlock(hdev); 3814 } 3815 3816 static void hci_tx_work(struct work_struct *work) 3817 { 3818 struct hci_dev *hdev = container_of(work, struct hci_dev, tx_work); 3819 struct sk_buff *skb; 3820 3821 BT_DBG("%s acl %d sco %d le %d iso %d", hdev->name, hdev->acl_cnt, 3822 hdev->sco_cnt, hdev->le_cnt, hdev->iso_cnt); 3823 3824 if (!hci_dev_test_flag(hdev, HCI_USER_CHANNEL)) { 3825 /* Schedule queues and send stuff to HCI driver */ 3826 hci_sched_sco(hdev, SCO_LINK); 3827 hci_sched_sco(hdev, ESCO_LINK); 3828 hci_sched_iso(hdev, CIS_LINK); 3829 hci_sched_iso(hdev, BIS_LINK); 3830 hci_sched_iso(hdev, PA_LINK); 3831 hci_sched_acl(hdev); 3832 hci_sched_le(hdev); 3833 } 3834 3835 /* Send next queued raw (unknown type) packet */ 3836 while ((skb = skb_dequeue(&hdev->raw_q))) 3837 hci_send_frame(hdev, skb); 3838 } 3839 3840 /* ----- HCI RX task (incoming data processing) ----- */ 3841 3842 /* ACL data packet */ 3843 static void hci_acldata_packet(struct hci_dev *hdev, struct sk_buff *skb) 3844 { 3845 struct hci_acl_hdr *hdr; 3846 __u16 handle, flags; 3847 int err; 3848 3849 hdr = skb_pull_data(skb, sizeof(*hdr)); 3850 if (!hdr) { 3851 bt_dev_err(hdev, "ACL packet too small"); 3852 kfree_skb(skb); 3853 return; 3854 } 3855 3856 handle = __le16_to_cpu(hdr->handle); 3857 flags = hci_flags(handle); 3858 handle = hci_handle(handle); 3859 3860 bt_dev_dbg(hdev, "len %d handle 0x%4.4x flags 0x%4.4x", skb->len, 3861 handle, flags); 3862 3863 hdev->stat.acl_rx++; 3864 3865 err = l2cap_recv_acldata(hdev, handle, skb, flags); 3866 if (err == -ENOENT) 3867 bt_dev_err(hdev, "ACL packet for unknown connection handle %d", 3868 handle); 3869 else if (err) 3870 bt_dev_dbg(hdev, "ACL packet recv for handle %d failed: %d", 3871 handle, err); 3872 } 3873 3874 /* SCO data packet */ 3875 static void hci_scodata_packet(struct hci_dev *hdev, struct sk_buff *skb) 3876 { 3877 struct hci_sco_hdr *hdr; 3878 __u16 handle, flags; 3879 int err; 3880 3881 hdr = skb_pull_data(skb, sizeof(*hdr)); 3882 if (!hdr) { 3883 bt_dev_err(hdev, "SCO packet too small"); 3884 kfree_skb(skb); 3885 return; 3886 } 3887 3888 handle = __le16_to_cpu(hdr->handle); 3889 flags = hci_flags(handle); 3890 handle = hci_handle(handle); 3891 3892 bt_dev_dbg(hdev, "len %d handle 0x%4.4x flags 0x%4.4x", skb->len, 3893 handle, flags); 3894 3895 hdev->stat.sco_rx++; 3896 3897 hci_skb_pkt_status(skb) = flags & 0x03; 3898 3899 err = sco_recv_scodata(hdev, handle, skb); 3900 if (err == -ENOENT) 3901 bt_dev_err_ratelimited(hdev, "SCO packet for unknown connection handle %d", 3902 handle); 3903 else if (err) 3904 bt_dev_dbg(hdev, "SCO packet recv for handle %d failed: %d", 3905 handle, err); 3906 } 3907 3908 static void hci_isodata_packet(struct hci_dev *hdev, struct sk_buff *skb) 3909 { 3910 struct hci_iso_hdr *hdr; 3911 __u16 handle, flags; 3912 int err; 3913 3914 hdr = skb_pull_data(skb, sizeof(*hdr)); 3915 if (!hdr) { 3916 bt_dev_err(hdev, "ISO packet too small"); 3917 kfree_skb(skb); 3918 return; 3919 } 3920 3921 handle = __le16_to_cpu(hdr->handle); 3922 flags = hci_flags(handle); 3923 handle = hci_handle(handle); 3924 3925 bt_dev_dbg(hdev, "len %d handle 0x%4.4x flags 0x%4.4x", skb->len, 3926 handle, flags); 3927 3928 err = iso_recv(hdev, handle, skb, flags); 3929 if (err == -ENOENT) 3930 bt_dev_err_ratelimited(hdev, "ISO packet for unknown connection handle %d", 3931 handle); 3932 else if (err) 3933 bt_dev_dbg(hdev, "ISO packet recv for handle %d failed: %d", 3934 handle, err); 3935 } 3936 3937 static bool hci_req_is_complete(struct hci_dev *hdev) 3938 { 3939 struct sk_buff *skb; 3940 3941 skb = skb_peek(&hdev->cmd_q); 3942 if (!skb) 3943 return true; 3944 3945 return (bt_cb(skb)->hci.req_flags & HCI_REQ_START); 3946 } 3947 3948 static void hci_resend_last(struct hci_dev *hdev) 3949 { 3950 struct hci_command_hdr *sent; 3951 struct sk_buff *skb; 3952 u16 opcode; 3953 3954 if (!hdev->sent_cmd) 3955 return; 3956 3957 sent = (void *) hdev->sent_cmd->data; 3958 opcode = __le16_to_cpu(sent->opcode); 3959 if (opcode == HCI_OP_RESET) 3960 return; 3961 3962 skb = skb_clone(hdev->sent_cmd, GFP_KERNEL); 3963 if (!skb) 3964 return; 3965 3966 skb_queue_head(&hdev->cmd_q, skb); 3967 queue_work(hdev->workqueue, &hdev->cmd_work); 3968 } 3969 3970 void hci_req_cmd_complete(struct hci_dev *hdev, u16 opcode, u8 status, 3971 hci_req_complete_t *req_complete, 3972 hci_req_complete_skb_t *req_complete_skb) 3973 { 3974 struct sk_buff *skb; 3975 unsigned long flags; 3976 3977 BT_DBG("opcode 0x%04x status 0x%02x", opcode, status); 3978 3979 /* If the completed command doesn't match the last one that was 3980 * sent we need to do special handling of it. 3981 */ 3982 if (!hci_sent_cmd_data(hdev, opcode)) { 3983 /* Some CSR based controllers generate a spontaneous 3984 * reset complete event during init and any pending 3985 * command will never be completed. In such a case we 3986 * need to resend whatever was the last sent 3987 * command. 3988 */ 3989 if (test_bit(HCI_INIT, &hdev->flags) && opcode == HCI_OP_RESET) 3990 hci_resend_last(hdev); 3991 3992 return; 3993 } 3994 3995 /* If we reach this point this event matches the last command sent */ 3996 hci_dev_clear_flag(hdev, HCI_CMD_PENDING); 3997 3998 /* If the command succeeded and there's still more commands in 3999 * this request the request is not yet complete. 4000 */ 4001 if (!status && !hci_req_is_complete(hdev)) 4002 return; 4003 4004 skb = hdev->req_skb; 4005 4006 /* If this was the last command in a request the complete 4007 * callback would be found in hdev->req_skb instead of the 4008 * command queue (hdev->cmd_q). 4009 */ 4010 if (skb && bt_cb(skb)->hci.req_flags & HCI_REQ_SKB) { 4011 *req_complete_skb = bt_cb(skb)->hci.req_complete_skb; 4012 return; 4013 } 4014 4015 if (skb && bt_cb(skb)->hci.req_complete) { 4016 *req_complete = bt_cb(skb)->hci.req_complete; 4017 return; 4018 } 4019 4020 /* Remove all pending commands belonging to this request */ 4021 spin_lock_irqsave(&hdev->cmd_q.lock, flags); 4022 while ((skb = __skb_dequeue(&hdev->cmd_q))) { 4023 if (bt_cb(skb)->hci.req_flags & HCI_REQ_START) { 4024 __skb_queue_head(&hdev->cmd_q, skb); 4025 break; 4026 } 4027 4028 if (bt_cb(skb)->hci.req_flags & HCI_REQ_SKB) 4029 *req_complete_skb = bt_cb(skb)->hci.req_complete_skb; 4030 else 4031 *req_complete = bt_cb(skb)->hci.req_complete; 4032 dev_kfree_skb_irq(skb); 4033 } 4034 spin_unlock_irqrestore(&hdev->cmd_q.lock, flags); 4035 } 4036 4037 static void hci_rx_work(struct work_struct *work) 4038 { 4039 struct hci_dev *hdev = container_of(work, struct hci_dev, rx_work); 4040 struct sk_buff *skb; 4041 4042 BT_DBG("%s", hdev->name); 4043 4044 /* The kcov_remote functions used for collecting packet parsing 4045 * coverage information from this background thread and associate 4046 * the coverage with the syscall's thread which originally injected 4047 * the packet. This helps fuzzing the kernel. 4048 */ 4049 for (; (skb = skb_dequeue(&hdev->rx_q)); kcov_remote_stop()) { 4050 kcov_remote_start_common(skb_get_kcov_handle(skb)); 4051 4052 /* Send copy to monitor */ 4053 hci_send_to_monitor(hdev, skb); 4054 4055 if (atomic_read(&hdev->promisc)) { 4056 /* Send copy to the sockets */ 4057 hci_send_to_sock(hdev, skb); 4058 } 4059 4060 /* If the device has been opened in HCI_USER_CHANNEL, 4061 * the userspace has exclusive access to device. 4062 * When device is HCI_INIT, we still need to process 4063 * the data packets to the driver in order 4064 * to complete its setup(). 4065 */ 4066 if (hci_dev_test_flag(hdev, HCI_USER_CHANNEL) && 4067 !test_bit(HCI_INIT, &hdev->flags)) { 4068 kfree_skb(skb); 4069 continue; 4070 } 4071 4072 if (test_bit(HCI_INIT, &hdev->flags)) { 4073 /* Don't process data packets in this states. */ 4074 switch (hci_skb_pkt_type(skb)) { 4075 case HCI_ACLDATA_PKT: 4076 case HCI_SCODATA_PKT: 4077 case HCI_ISODATA_PKT: 4078 kfree_skb(skb); 4079 continue; 4080 } 4081 } 4082 4083 /* Process frame */ 4084 switch (hci_skb_pkt_type(skb)) { 4085 case HCI_EVENT_PKT: 4086 BT_DBG("%s Event packet", hdev->name); 4087 hci_event_packet(hdev, skb); 4088 break; 4089 4090 case HCI_ACLDATA_PKT: 4091 BT_DBG("%s ACL data packet", hdev->name); 4092 hci_acldata_packet(hdev, skb); 4093 break; 4094 4095 case HCI_SCODATA_PKT: 4096 BT_DBG("%s SCO data packet", hdev->name); 4097 hci_scodata_packet(hdev, skb); 4098 break; 4099 4100 case HCI_ISODATA_PKT: 4101 BT_DBG("%s ISO data packet", hdev->name); 4102 hci_isodata_packet(hdev, skb); 4103 break; 4104 4105 default: 4106 kfree_skb(skb); 4107 break; 4108 } 4109 } 4110 } 4111 4112 static int hci_send_cmd_sync(struct hci_dev *hdev, struct sk_buff *skb) 4113 { 4114 int err; 4115 4116 bt_dev_dbg(hdev, "skb %p", skb); 4117 4118 kfree_skb(hdev->sent_cmd); 4119 4120 hdev->sent_cmd = skb_clone(skb, GFP_KERNEL); 4121 if (!hdev->sent_cmd) { 4122 skb_queue_head(&hdev->cmd_q, skb); 4123 queue_work(hdev->workqueue, &hdev->cmd_work); 4124 return -EINVAL; 4125 } 4126 4127 if (hci_skb_opcode(skb) != HCI_OP_NOP) { 4128 err = hci_send_frame(hdev, skb); 4129 if (err < 0) { 4130 hci_cmd_sync_cancel_sync(hdev, -err); 4131 return err; 4132 } 4133 atomic_dec(&hdev->cmd_cnt); 4134 } else { 4135 err = -ENODATA; 4136 kfree_skb(skb); 4137 } 4138 4139 if (READ_ONCE(hdev->req_status) == HCI_REQ_PEND && 4140 !hci_dev_test_and_set_flag(hdev, HCI_CMD_PENDING)) { 4141 kfree_skb(hdev->req_skb); 4142 hdev->req_skb = skb_get(hdev->sent_cmd); 4143 } 4144 4145 return err; 4146 } 4147 4148 static void hci_cmd_work(struct work_struct *work) 4149 { 4150 struct hci_dev *hdev = container_of(work, struct hci_dev, cmd_work); 4151 struct sk_buff *skb; 4152 int err; 4153 4154 BT_DBG("%s cmd_cnt %d cmd queued %d", hdev->name, 4155 atomic_read(&hdev->cmd_cnt), skb_queue_len(&hdev->cmd_q)); 4156 4157 /* Send queued commands */ 4158 if (atomic_read(&hdev->cmd_cnt)) { 4159 skb = skb_dequeue(&hdev->cmd_q); 4160 if (!skb) 4161 return; 4162 4163 err = hci_send_cmd_sync(hdev, skb); 4164 if (err) 4165 return; 4166 4167 rcu_read_lock(); 4168 if (test_bit(HCI_RESET, &hdev->flags) || 4169 hci_dev_test_flag(hdev, HCI_CMD_DRAIN_WORKQUEUE)) 4170 cancel_delayed_work(&hdev->cmd_timer); 4171 else 4172 queue_delayed_work(hdev->workqueue, &hdev->cmd_timer, 4173 HCI_CMD_TIMEOUT); 4174 rcu_read_unlock(); 4175 } 4176 } 4177