xref: /linux/net/bluetooth/l2cap_core.c (revision 6c78a213d9070b610c7f418af2c25b66180b7e37)
1 // SPDX-License-Identifier: GPL-2.0
2 /*
3    BlueZ - Bluetooth protocol stack for Linux
4    Copyright (C) 2000-2001 Qualcomm Incorporated
5    Copyright (C) 2009-2010 Gustavo F. Padovan <gustavo@padovan.org>
6    Copyright (C) 2010 Google Inc.
7    Copyright (C) 2011 ProFUSION Embedded Systems
8    Copyright (c) 2012 Code Aurora Forum.  All rights reserved.
9 
10    Written 2000,2001 by Maxim Krasnyansky <maxk@qualcomm.com>
11 
12    THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS
13    OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
14    FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT OF THIRD PARTY RIGHTS.
15    IN NO EVENT SHALL THE COPYRIGHT HOLDER(S) AND AUTHOR(S) BE LIABLE FOR ANY
16    CLAIM, OR ANY SPECIAL INDIRECT OR CONSEQUENTIAL DAMAGES, OR ANY DAMAGES
17    WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
18    ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
19    OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
20 
21    ALL LIABILITY, INCLUDING LIABILITY FOR INFRINGEMENT OF ANY PATENTS,
22    COPYRIGHTS, TRADEMARKS OR OTHER RIGHTS, RELATING TO USE OF THIS
23    SOFTWARE IS DISCLAIMED.
24 */
25 
26 /* Bluetooth L2CAP core. */
27 
28 #include <linux/module.h>
29 
30 #include <linux/debugfs.h>
31 #include <linux/crc16.h>
32 #include <linux/filter.h>
33 
34 #include <net/bluetooth/bluetooth.h>
35 #include <net/bluetooth/hci_core.h>
36 #include <net/bluetooth/l2cap.h>
37 
38 #include "smp.h"
39 
40 #define LE_FLOWCTL_MAX_CREDITS 65535
41 
42 bool disable_ertm;
43 bool enable_ecred = IS_ENABLED(CONFIG_BT_LE_L2CAP_ECRED);
44 
45 static u32 l2cap_feat_mask = L2CAP_FEAT_FIXED_CHAN | L2CAP_FEAT_UCD;
46 
47 static LIST_HEAD(chan_list);
48 static DEFINE_RWLOCK(chan_list_lock);
49 
50 static struct sk_buff *l2cap_build_cmd(struct l2cap_conn *conn,
51 				       u8 code, u8 ident, u16 dlen, void *data);
52 static void l2cap_send_cmd(struct l2cap_conn *conn, u8 ident, u8 code, u16 len,
53 			   void *data);
54 static int l2cap_build_conf_req(struct l2cap_chan *chan, void *data, size_t data_size);
55 static void l2cap_send_disconn_req(struct l2cap_chan *chan, int err);
56 
57 static void l2cap_tx(struct l2cap_chan *chan, struct l2cap_ctrl *control,
58 		     struct sk_buff_head *skbs, u8 event);
59 static void l2cap_retrans_timeout(struct work_struct *work);
60 static void l2cap_monitor_timeout(struct work_struct *work);
61 static void l2cap_ack_timeout(struct work_struct *work);
62 
63 static inline u8 bdaddr_type(u8 link_type, u8 bdaddr_type)
64 {
65 	if (link_type == LE_LINK) {
66 		if (bdaddr_type == ADDR_LE_DEV_PUBLIC)
67 			return BDADDR_LE_PUBLIC;
68 		else
69 			return BDADDR_LE_RANDOM;
70 	}
71 
72 	return BDADDR_BREDR;
73 }
74 
75 static inline u8 bdaddr_src_type(struct hci_conn *hcon)
76 {
77 	return bdaddr_type(hcon->type, hcon->src_type);
78 }
79 
80 static inline u8 bdaddr_dst_type(struct hci_conn *hcon)
81 {
82 	return bdaddr_type(hcon->type, hcon->dst_type);
83 }
84 
85 /* ---- L2CAP channels ---- */
86 
87 static struct l2cap_chan *__l2cap_get_chan_by_dcid(struct l2cap_conn *conn,
88 						   u16 cid)
89 {
90 	struct l2cap_chan *c;
91 
92 	list_for_each_entry(c, &conn->chan_l, list) {
93 		if (c->dcid == cid)
94 			return c;
95 	}
96 	return NULL;
97 }
98 
99 static struct l2cap_chan *__l2cap_get_chan_by_scid(struct l2cap_conn *conn,
100 						   u16 cid)
101 {
102 	struct l2cap_chan *c;
103 
104 	list_for_each_entry(c, &conn->chan_l, list) {
105 		if (c->scid == cid)
106 			return c;
107 	}
108 	return NULL;
109 }
110 
111 /* Find channel with given SCID.
112  * Returns a reference locked channel.
113  */
114 static struct l2cap_chan *l2cap_get_chan_by_scid(struct l2cap_conn *conn,
115 						 u16 cid)
116 {
117 	struct l2cap_chan *c;
118 
119 	c = __l2cap_get_chan_by_scid(conn, cid);
120 	if (c) {
121 		/* Only lock if chan reference is not 0 */
122 		c = l2cap_chan_hold_unless_zero(c);
123 		if (c)
124 			l2cap_chan_lock(c);
125 	}
126 
127 	return c;
128 }
129 
130 /* Find channel with given DCID.
131  * Returns a reference locked channel.
132  */
133 static struct l2cap_chan *l2cap_get_chan_by_dcid(struct l2cap_conn *conn,
134 						 u16 cid)
135 {
136 	struct l2cap_chan *c;
137 
138 	c = __l2cap_get_chan_by_dcid(conn, cid);
139 	if (c) {
140 		/* Only lock if chan reference is not 0 */
141 		c = l2cap_chan_hold_unless_zero(c);
142 		if (c)
143 			l2cap_chan_lock(c);
144 	}
145 
146 	return c;
147 }
148 
149 static struct l2cap_chan *__l2cap_get_chan_by_ident(struct l2cap_conn *conn,
150 						    u8 ident)
151 {
152 	struct l2cap_chan *c;
153 
154 	list_for_each_entry(c, &conn->chan_l, list) {
155 		if (c->ident == ident)
156 			return c;
157 	}
158 	return NULL;
159 }
160 
161 static struct l2cap_chan *__l2cap_global_chan_by_addr(__le16 psm, bdaddr_t *src,
162 						      u8 src_type)
163 {
164 	struct l2cap_chan *c;
165 
166 	list_for_each_entry(c, &chan_list, global_l) {
167 		if (src_type == BDADDR_BREDR && c->src_type != BDADDR_BREDR)
168 			continue;
169 
170 		if (src_type != BDADDR_BREDR && c->src_type == BDADDR_BREDR)
171 			continue;
172 
173 		if (c->sport == psm && !bacmp(&c->src, src))
174 			return c;
175 	}
176 	return NULL;
177 }
178 
179 int l2cap_add_psm(struct l2cap_chan *chan, bdaddr_t *src, __le16 psm)
180 {
181 	int err;
182 
183 	write_lock(&chan_list_lock);
184 
185 	if (psm && __l2cap_global_chan_by_addr(psm, src, chan->src_type)) {
186 		err = -EADDRINUSE;
187 		goto done;
188 	}
189 
190 	if (psm) {
191 		chan->psm = psm;
192 		chan->sport = psm;
193 		err = 0;
194 	} else {
195 		u16 p, start, end, incr;
196 
197 		if (chan->src_type == BDADDR_BREDR) {
198 			start = L2CAP_PSM_DYN_START;
199 			end = L2CAP_PSM_AUTO_END;
200 			incr = 2;
201 		} else {
202 			start = L2CAP_PSM_LE_DYN_START;
203 			end = L2CAP_PSM_LE_DYN_END;
204 			incr = 1;
205 		}
206 
207 		err = -EINVAL;
208 		for (p = start; p <= end; p += incr)
209 			if (!__l2cap_global_chan_by_addr(cpu_to_le16(p), src,
210 							 chan->src_type)) {
211 				chan->psm   = cpu_to_le16(p);
212 				chan->sport = cpu_to_le16(p);
213 				err = 0;
214 				break;
215 			}
216 	}
217 
218 done:
219 	write_unlock(&chan_list_lock);
220 	return err;
221 }
222 EXPORT_SYMBOL_GPL(l2cap_add_psm);
223 
224 int l2cap_add_scid(struct l2cap_chan *chan,  __u16 scid)
225 {
226 	write_lock(&chan_list_lock);
227 
228 	/* Override the defaults (which are for conn-oriented) */
229 	chan->omtu = L2CAP_DEFAULT_MTU;
230 	chan->chan_type = L2CAP_CHAN_FIXED;
231 
232 	chan->scid = scid;
233 
234 	write_unlock(&chan_list_lock);
235 
236 	return 0;
237 }
238 
239 static u16 l2cap_alloc_cid(struct l2cap_conn *conn)
240 {
241 	u16 cid, dyn_end;
242 
243 	if (conn->hcon->type == LE_LINK)
244 		dyn_end = L2CAP_CID_LE_DYN_END;
245 	else
246 		dyn_end = L2CAP_CID_DYN_END;
247 
248 	for (cid = L2CAP_CID_DYN_START; cid <= dyn_end; cid++) {
249 		if (!__l2cap_get_chan_by_scid(conn, cid))
250 			return cid;
251 	}
252 
253 	return 0;
254 }
255 
256 static void l2cap_state_change(struct l2cap_chan *chan, int state)
257 {
258 	BT_DBG("chan %p %s -> %s", chan, state_to_string(chan->state),
259 	       state_to_string(state));
260 
261 	chan->state = state;
262 	chan->ops->state_change(chan, state, 0);
263 }
264 
265 static inline void l2cap_state_change_and_error(struct l2cap_chan *chan,
266 						int state, int err)
267 {
268 	chan->state = state;
269 	chan->ops->state_change(chan, chan->state, err);
270 }
271 
272 static inline void l2cap_chan_set_err(struct l2cap_chan *chan, int err)
273 {
274 	chan->ops->state_change(chan, chan->state, err);
275 }
276 
277 static void __set_retrans_timer(struct l2cap_chan *chan)
278 {
279 	if (!delayed_work_pending(&chan->monitor_timer) &&
280 	    chan->retrans_timeout) {
281 		l2cap_set_timer(chan, &chan->retrans_timer,
282 				msecs_to_jiffies(chan->retrans_timeout));
283 	}
284 }
285 
286 static void __set_monitor_timer(struct l2cap_chan *chan)
287 {
288 	__clear_retrans_timer(chan);
289 	if (chan->monitor_timeout) {
290 		l2cap_set_timer(chan, &chan->monitor_timer,
291 				msecs_to_jiffies(chan->monitor_timeout));
292 	}
293 }
294 
295 static struct sk_buff *l2cap_ertm_seq_in_queue(struct sk_buff_head *head,
296 					       u16 seq)
297 {
298 	struct sk_buff *skb;
299 
300 	skb_queue_walk(head, skb) {
301 		if (bt_cb(skb)->l2cap.txseq == seq)
302 			return skb;
303 	}
304 
305 	return NULL;
306 }
307 
308 /* ---- L2CAP sequence number lists ---- */
309 
310 /* For ERTM, ordered lists of sequence numbers must be tracked for
311  * SREJ requests that are received and for frames that are to be
312  * retransmitted. These seq_list functions implement a singly-linked
313  * list in an array, where membership in the list can also be checked
314  * in constant time. Items can also be added to the tail of the list
315  * and removed from the head in constant time, without further memory
316  * allocs or frees.
317  */
318 
319 static int l2cap_seq_list_init(struct l2cap_seq_list *seq_list, u16 size)
320 {
321 	size_t alloc_size, i;
322 
323 	/* Allocated size is a power of 2 to map sequence numbers
324 	 * (which may be up to 14 bits) in to a smaller array that is
325 	 * sized for the negotiated ERTM transmit windows.
326 	 */
327 	alloc_size = roundup_pow_of_two(size);
328 
329 	seq_list->list = kmalloc_array(alloc_size, sizeof(u16), GFP_KERNEL);
330 	if (!seq_list->list)
331 		return -ENOMEM;
332 
333 	seq_list->mask = alloc_size - 1;
334 	seq_list->head = L2CAP_SEQ_LIST_CLEAR;
335 	seq_list->tail = L2CAP_SEQ_LIST_CLEAR;
336 	for (i = 0; i < alloc_size; i++)
337 		seq_list->list[i] = L2CAP_SEQ_LIST_CLEAR;
338 
339 	return 0;
340 }
341 
342 static inline void l2cap_seq_list_free(struct l2cap_seq_list *seq_list)
343 {
344 	kfree(seq_list->list);
345 }
346 
347 static inline bool l2cap_seq_list_contains(struct l2cap_seq_list *seq_list,
348 					   u16 seq)
349 {
350 	/* Constant-time check for list membership */
351 	return seq_list->list[seq & seq_list->mask] != L2CAP_SEQ_LIST_CLEAR;
352 }
353 
354 static inline u16 l2cap_seq_list_pop(struct l2cap_seq_list *seq_list)
355 {
356 	u16 seq = seq_list->head;
357 	u16 mask = seq_list->mask;
358 
359 	seq_list->head = seq_list->list[seq & mask];
360 	seq_list->list[seq & mask] = L2CAP_SEQ_LIST_CLEAR;
361 
362 	if (seq_list->head == L2CAP_SEQ_LIST_TAIL) {
363 		seq_list->head = L2CAP_SEQ_LIST_CLEAR;
364 		seq_list->tail = L2CAP_SEQ_LIST_CLEAR;
365 	}
366 
367 	return seq;
368 }
369 
370 static void l2cap_seq_list_clear(struct l2cap_seq_list *seq_list)
371 {
372 	u16 i;
373 
374 	if (seq_list->head == L2CAP_SEQ_LIST_CLEAR)
375 		return;
376 
377 	for (i = 0; i <= seq_list->mask; i++)
378 		seq_list->list[i] = L2CAP_SEQ_LIST_CLEAR;
379 
380 	seq_list->head = L2CAP_SEQ_LIST_CLEAR;
381 	seq_list->tail = L2CAP_SEQ_LIST_CLEAR;
382 }
383 
384 static void l2cap_seq_list_append(struct l2cap_seq_list *seq_list, u16 seq)
385 {
386 	u16 mask = seq_list->mask;
387 
388 	/* All appends happen in constant time */
389 
390 	if (seq_list->list[seq & mask] != L2CAP_SEQ_LIST_CLEAR)
391 		return;
392 
393 	if (seq_list->tail == L2CAP_SEQ_LIST_CLEAR)
394 		seq_list->head = seq;
395 	else
396 		seq_list->list[seq_list->tail & mask] = seq;
397 
398 	seq_list->tail = seq;
399 	seq_list->list[seq & mask] = L2CAP_SEQ_LIST_TAIL;
400 }
401 
402 static void l2cap_chan_timeout(struct work_struct *work)
403 {
404 	struct l2cap_chan *chan = container_of(work, struct l2cap_chan,
405 					       chan_timer.work);
406 	struct l2cap_conn *conn = chan->conn;
407 	int reason;
408 
409 	BT_DBG("chan %p state %s", chan, state_to_string(chan->state));
410 
411 	if (test_bit(FLAG_DEL, &chan->flags)) {
412 		l2cap_chan_put(chan);
413 		return;
414 	}
415 
416 	mutex_lock(&conn->lock);
417 	/* __set_chan_timer() calls l2cap_chan_hold(chan) while scheduling
418 	 * this work. No need to call l2cap_chan_hold(chan) here again.
419 	 */
420 	l2cap_chan_lock(chan);
421 
422 	if (test_bit(FLAG_DEL, &chan->flags))
423 		goto unlock;
424 
425 	if (chan->state == BT_CONNECTED || chan->state == BT_CONFIG)
426 		reason = ECONNREFUSED;
427 	else if (chan->state == BT_CONNECT &&
428 		 chan->sec_level != BT_SECURITY_SDP)
429 		reason = ECONNREFUSED;
430 	else
431 		reason = ETIMEDOUT;
432 
433 	l2cap_chan_close(chan, reason);
434 
435 	chan->ops->close(chan);
436 
437 unlock:
438 	l2cap_chan_unlock(chan);
439 	mutex_unlock(&conn->lock);
440 	l2cap_chan_put(chan);
441 }
442 
443 struct l2cap_chan *l2cap_chan_create(void)
444 {
445 	struct l2cap_chan *chan;
446 
447 	chan = kzalloc_obj(*chan, GFP_ATOMIC);
448 	if (!chan)
449 		return NULL;
450 
451 	skb_queue_head_init(&chan->tx_q);
452 	skb_queue_head_init(&chan->srej_q);
453 	mutex_init(&chan->lock);
454 
455 	/* Set default lock nesting level */
456 	atomic_set(&chan->nesting, L2CAP_NESTING_NORMAL);
457 
458 	/* Available receive buffer space is initially unknown */
459 	chan->rx_avail = -1;
460 
461 	write_lock(&chan_list_lock);
462 	list_add(&chan->global_l, &chan_list);
463 	write_unlock(&chan_list_lock);
464 
465 	INIT_DELAYED_WORK(&chan->chan_timer, l2cap_chan_timeout);
466 	INIT_DELAYED_WORK(&chan->retrans_timer, l2cap_retrans_timeout);
467 	INIT_DELAYED_WORK(&chan->monitor_timer, l2cap_monitor_timeout);
468 	INIT_DELAYED_WORK(&chan->ack_timer, l2cap_ack_timeout);
469 
470 	chan->state = BT_OPEN;
471 
472 	kref_init(&chan->kref);
473 
474 	/* This flag is cleared in l2cap_chan_ready() */
475 	set_bit(CONF_NOT_COMPLETE, &chan->conf_state);
476 
477 	BT_DBG("chan %p", chan);
478 
479 	return chan;
480 }
481 EXPORT_SYMBOL_GPL(l2cap_chan_create);
482 
483 static void l2cap_chan_destroy(struct kref *kref)
484 {
485 	struct l2cap_chan *chan = container_of(kref, struct l2cap_chan, kref);
486 
487 	BT_DBG("chan %p", chan);
488 
489 	write_lock(&chan_list_lock);
490 	list_del(&chan->global_l);
491 	write_unlock(&chan_list_lock);
492 
493 	if (chan->conn)
494 		l2cap_conn_put(chan->conn);
495 
496 	kfree(chan);
497 }
498 
499 void l2cap_chan_hold(struct l2cap_chan *c)
500 {
501 	BT_DBG("chan %p orig refcnt %u", c, kref_read(&c->kref));
502 
503 	kref_get(&c->kref);
504 }
505 EXPORT_SYMBOL_GPL(l2cap_chan_hold);
506 
507 struct l2cap_chan *l2cap_chan_hold_unless_zero(struct l2cap_chan *c)
508 {
509 	BT_DBG("chan %p orig refcnt %u", c, kref_read(&c->kref));
510 
511 	if (!kref_get_unless_zero(&c->kref))
512 		return NULL;
513 
514 	return c;
515 }
516 
517 void l2cap_chan_put(struct l2cap_chan *c)
518 {
519 	BT_DBG("chan %p orig refcnt %u", c, kref_read(&c->kref));
520 
521 	kref_put(&c->kref, l2cap_chan_destroy);
522 }
523 EXPORT_SYMBOL_GPL(l2cap_chan_put);
524 
525 /* Initialise @chan with default values, inheriting from the parent channel
526  * @pchan when it is given.
527  */
528 void l2cap_chan_set_defaults(struct l2cap_chan *chan, struct l2cap_chan *pchan)
529 {
530 	chan->fcs  = L2CAP_FCS_CRC16;
531 	chan->max_tx = L2CAP_DEFAULT_MAX_TX;
532 	chan->tx_win = L2CAP_DEFAULT_TX_WINDOW;
533 	chan->tx_win_max = L2CAP_DEFAULT_TX_WINDOW;
534 	chan->remote_max_tx = chan->max_tx;
535 	chan->remote_tx_win = chan->tx_win;
536 	chan->ack_win = L2CAP_DEFAULT_TX_WINDOW;
537 	chan->sec_level = BT_SECURITY_LOW;
538 	chan->flush_to = L2CAP_DEFAULT_FLUSH_TO;
539 	chan->retrans_timeout = L2CAP_DEFAULT_RETRANS_TO;
540 	chan->monitor_timeout = L2CAP_DEFAULT_MONITOR_TO;
541 
542 	if (pchan) {
543 		BT_DBG("chan %p pchan %p", chan, pchan);
544 
545 		chan->chan_type = pchan->chan_type;
546 		chan->imtu = pchan->imtu;
547 		chan->omtu = pchan->omtu;
548 		chan->mode = pchan->mode;
549 		chan->fcs = pchan->fcs;
550 		chan->max_tx = pchan->max_tx;
551 		chan->tx_win = pchan->tx_win;
552 		chan->tx_win_max = pchan->tx_win_max;
553 		chan->sec_level = pchan->sec_level;
554 		chan->conf_state = pchan->conf_state;
555 		chan->flags = pchan->flags;
556 		chan->tx_credits = pchan->tx_credits;
557 		chan->rx_credits = pchan->rx_credits;
558 
559 		if (chan->chan_type == L2CAP_CHAN_FIXED) {
560 			chan->scid = pchan->scid;
561 			chan->dcid = pchan->scid;
562 		}
563 
564 		return;
565 	}
566 
567 	chan->conf_state = 0;
568 	set_bit(CONF_NOT_COMPLETE, &chan->conf_state);
569 
570 	set_bit(FLAG_FORCE_ACTIVE, &chan->flags);
571 }
572 EXPORT_SYMBOL_GPL(l2cap_chan_set_defaults);
573 
574 static __u16 l2cap_le_rx_credits(struct l2cap_chan *chan)
575 {
576 	size_t sdu_len = chan->sdu ? chan->sdu->len : 0;
577 
578 	if (chan->mps == 0)
579 		return 0;
580 
581 	/* If we don't know the available space in the receiver buffer, give
582 	 * enough credits for a full packet.
583 	 */
584 	if (chan->rx_avail == -1)
585 		return (chan->imtu / chan->mps) + 1;
586 
587 	/* If we know how much space is available in the receive buffer, give
588 	 * out as many credits as would fill the buffer.
589 	 */
590 	if (chan->rx_avail <= sdu_len)
591 		return 0;
592 
593 	return DIV_ROUND_UP(chan->rx_avail - sdu_len, chan->mps);
594 }
595 
596 static void l2cap_le_flowctl_init(struct l2cap_chan *chan, u16 tx_credits)
597 {
598 	chan->sdu = NULL;
599 	chan->sdu_last_frag = NULL;
600 	chan->sdu_len = 0;
601 	chan->tx_credits = tx_credits;
602 	/* Derive MPS from connection MTU to stop HCI fragmentation */
603 	chan->mps = min_t(u16, chan->imtu, chan->conn->mtu - L2CAP_HDR_SIZE);
604 	chan->rx_credits = l2cap_le_rx_credits(chan);
605 
606 	skb_queue_head_init(&chan->tx_q);
607 }
608 
609 static void l2cap_ecred_init(struct l2cap_chan *chan, u16 tx_credits)
610 {
611 	l2cap_le_flowctl_init(chan, tx_credits);
612 
613 	/* L2CAP implementations shall support a minimum MPS of 64 octets */
614 	if (chan->mps < L2CAP_ECRED_MIN_MPS) {
615 		chan->mps = L2CAP_ECRED_MIN_MPS;
616 		chan->rx_credits = l2cap_le_rx_credits(chan);
617 	}
618 }
619 
620 void __l2cap_chan_add(struct l2cap_conn *conn, struct l2cap_chan *chan)
621 {
622 	BT_DBG("conn %p, psm 0x%2.2x, dcid 0x%4.4x", conn,
623 	       __le16_to_cpu(chan->psm), chan->dcid);
624 
625 	conn->disc_reason = HCI_ERROR_REMOTE_USER_TERM;
626 
627 	chan->conn = l2cap_conn_get(conn);
628 
629 	switch (chan->chan_type) {
630 	case L2CAP_CHAN_CONN_ORIENTED:
631 		/* Alloc CID for connection-oriented socket */
632 		chan->scid = l2cap_alloc_cid(conn);
633 		if (conn->hcon->type == ACL_LINK)
634 			chan->omtu = L2CAP_DEFAULT_MTU;
635 		break;
636 
637 	case L2CAP_CHAN_CONN_LESS:
638 		/* Connectionless socket */
639 		chan->scid = L2CAP_CID_CONN_LESS;
640 		chan->dcid = L2CAP_CID_CONN_LESS;
641 		chan->omtu = L2CAP_DEFAULT_MTU;
642 		break;
643 
644 	case L2CAP_CHAN_FIXED:
645 		/* Caller will set CID and CID specific MTU values */
646 		break;
647 
648 	default:
649 		/* Raw socket can send/recv signalling messages only */
650 		chan->scid = L2CAP_CID_SIGNALING;
651 		chan->dcid = L2CAP_CID_SIGNALING;
652 		chan->omtu = L2CAP_DEFAULT_MTU;
653 	}
654 
655 	chan->local_id		= L2CAP_BESTEFFORT_ID;
656 	chan->local_stype	= L2CAP_SERV_BESTEFFORT;
657 	chan->local_msdu	= L2CAP_DEFAULT_MAX_SDU_SIZE;
658 	chan->local_sdu_itime	= L2CAP_DEFAULT_SDU_ITIME;
659 	chan->local_acc_lat	= L2CAP_DEFAULT_ACC_LAT;
660 	chan->local_flush_to	= L2CAP_EFS_DEFAULT_FLUSH_TO;
661 
662 	l2cap_chan_hold(chan);
663 
664 	/* Only keep a reference for fixed channels if they requested it */
665 	if (chan->chan_type != L2CAP_CHAN_FIXED ||
666 	    test_bit(FLAG_HOLD_HCI_CONN, &chan->flags))
667 		hci_conn_hold(conn->hcon);
668 
669 	/* Append to the list since the order matters for ECRED */
670 	list_add_tail(&chan->list, &conn->chan_l);
671 }
672 
673 void l2cap_chan_add(struct l2cap_conn *conn, struct l2cap_chan *chan)
674 {
675 	mutex_lock(&conn->lock);
676 	__l2cap_chan_add(conn, chan);
677 	mutex_unlock(&conn->lock);
678 }
679 
680 void l2cap_chan_del(struct l2cap_chan *chan, int err)
681 {
682 	__clear_chan_timer(chan);
683 
684 	BT_DBG("chan %p, err %d, state %s", chan, err,
685 	       state_to_string(chan->state));
686 
687 	chan->ops->teardown(chan, err);
688 
689 	if (!test_and_set_bit(FLAG_DEL, &chan->flags)) {
690 		/* Delete from channel list */
691 		list_del(&chan->list);
692 
693 		l2cap_chan_put(chan);
694 
695 		/* Reference was only held for non-fixed channels or
696 		 * fixed channels that explicitly requested it using the
697 		 * FLAG_HOLD_HCI_CONN flag.
698 		 */
699 		if (chan->chan_type != L2CAP_CHAN_FIXED ||
700 		    test_bit(FLAG_HOLD_HCI_CONN, &chan->flags))
701 			hci_conn_drop(chan->conn->hcon);
702 	}
703 
704 	if (test_bit(CONF_NOT_COMPLETE, &chan->conf_state))
705 		return;
706 
707 	switch (chan->mode) {
708 	case L2CAP_MODE_BASIC:
709 		break;
710 
711 	case L2CAP_MODE_LE_FLOWCTL:
712 	case L2CAP_MODE_EXT_FLOWCTL:
713 		skb_queue_purge(&chan->tx_q);
714 		break;
715 
716 	case L2CAP_MODE_ERTM:
717 		__clear_retrans_timer(chan);
718 		__clear_monitor_timer(chan);
719 		__clear_ack_timer(chan);
720 
721 		skb_queue_purge(&chan->srej_q);
722 
723 		l2cap_seq_list_free(&chan->srej_list);
724 		l2cap_seq_list_free(&chan->retrans_list);
725 		fallthrough;
726 
727 	case L2CAP_MODE_STREAMING:
728 		skb_queue_purge(&chan->tx_q);
729 		break;
730 	}
731 }
732 EXPORT_SYMBOL_GPL(l2cap_chan_del);
733 
734 static void __l2cap_chan_list_id(struct l2cap_conn *conn, u16 id,
735 				 l2cap_chan_func_t func, void *data)
736 {
737 	struct l2cap_chan *chan, *l;
738 
739 	list_for_each_entry_safe(chan, l, &conn->chan_l, list) {
740 		if (chan->ident == id)
741 			func(chan, data);
742 	}
743 }
744 
745 static void __l2cap_chan_list(struct l2cap_conn *conn, l2cap_chan_func_t func,
746 			      void *data)
747 {
748 	struct l2cap_chan *chan;
749 
750 	list_for_each_entry(chan, &conn->chan_l, list) {
751 		func(chan, data);
752 	}
753 }
754 
755 void l2cap_chan_list(struct l2cap_conn *conn, l2cap_chan_func_t func,
756 		     void *data)
757 {
758 	if (!conn)
759 		return;
760 
761 	mutex_lock(&conn->lock);
762 	__l2cap_chan_list(conn, func, data);
763 	mutex_unlock(&conn->lock);
764 }
765 
766 EXPORT_SYMBOL_GPL(l2cap_chan_list);
767 
768 static void l2cap_conn_update_id_addr(struct work_struct *work)
769 {
770 	struct l2cap_conn *conn = container_of(work, struct l2cap_conn,
771 					       id_addr_timer.work);
772 	struct hci_conn *hcon = conn->hcon;
773 	struct l2cap_chan *chan;
774 
775 	mutex_lock(&conn->lock);
776 
777 	list_for_each_entry(chan, &conn->chan_l, list) {
778 		l2cap_chan_lock(chan);
779 		bacpy(&chan->dst, &hcon->dst);
780 		chan->dst_type = bdaddr_dst_type(hcon);
781 		l2cap_chan_unlock(chan);
782 	}
783 
784 	mutex_unlock(&conn->lock);
785 }
786 
787 static void l2cap_chan_le_connect_reject(struct l2cap_chan *chan)
788 {
789 	struct l2cap_conn *conn = chan->conn;
790 	struct l2cap_le_conn_rsp rsp;
791 	u16 result;
792 
793 	if (test_bit(FLAG_DEFER_SETUP, &chan->flags))
794 		result = L2CAP_CR_LE_AUTHORIZATION;
795 	else
796 		result = L2CAP_CR_LE_BAD_PSM;
797 
798 	l2cap_state_change(chan, BT_DISCONN);
799 
800 	rsp.dcid    = cpu_to_le16(chan->scid);
801 	rsp.mtu     = cpu_to_le16(chan->imtu);
802 	rsp.mps     = cpu_to_le16(chan->mps);
803 	rsp.credits = cpu_to_le16(chan->rx_credits);
804 	rsp.result  = cpu_to_le16(result);
805 
806 	l2cap_send_cmd(conn, chan->ident, L2CAP_LE_CONN_RSP, sizeof(rsp),
807 		       &rsp);
808 }
809 
810 static void l2cap_chan_ecred_connect_reject(struct l2cap_chan *chan)
811 {
812 	l2cap_state_change(chan, BT_DISCONN);
813 
814 	__l2cap_ecred_conn_rsp_defer(chan);
815 }
816 
817 static void l2cap_chan_connect_reject(struct l2cap_chan *chan)
818 {
819 	struct l2cap_conn *conn = chan->conn;
820 	struct l2cap_conn_rsp rsp;
821 	u16 result;
822 
823 	if (test_bit(FLAG_DEFER_SETUP, &chan->flags))
824 		result = L2CAP_CR_SEC_BLOCK;
825 	else
826 		result = L2CAP_CR_BAD_PSM;
827 
828 	l2cap_state_change(chan, BT_DISCONN);
829 
830 	rsp.scid   = cpu_to_le16(chan->dcid);
831 	rsp.dcid   = cpu_to_le16(chan->scid);
832 	rsp.result = cpu_to_le16(result);
833 	rsp.status = cpu_to_le16(L2CAP_CS_NO_INFO);
834 
835 	l2cap_send_cmd(conn, chan->ident, L2CAP_CONN_RSP, sizeof(rsp), &rsp);
836 }
837 
838 void l2cap_chan_close(struct l2cap_chan *chan, int reason)
839 {
840 	struct l2cap_conn *conn = chan->conn;
841 
842 	BT_DBG("chan %p state %s", chan, state_to_string(chan->state));
843 
844 	switch (chan->state) {
845 	case BT_LISTEN:
846 		chan->ops->teardown(chan, 0);
847 		break;
848 
849 	case BT_CONNECTED:
850 	case BT_CONFIG:
851 		if (chan->chan_type == L2CAP_CHAN_CONN_ORIENTED) {
852 			__set_chan_timer(chan, chan->ops->get_sndtimeo(chan));
853 			l2cap_send_disconn_req(chan, reason);
854 		} else
855 			l2cap_chan_del(chan, reason);
856 		break;
857 
858 	case BT_CONNECT2:
859 		if (chan->chan_type == L2CAP_CHAN_CONN_ORIENTED) {
860 			if (conn->hcon->type == ACL_LINK)
861 				l2cap_chan_connect_reject(chan);
862 			else if (conn->hcon->type == LE_LINK) {
863 				switch (chan->mode) {
864 				case L2CAP_MODE_LE_FLOWCTL:
865 					l2cap_chan_le_connect_reject(chan);
866 					break;
867 				case L2CAP_MODE_EXT_FLOWCTL:
868 					l2cap_chan_ecred_connect_reject(chan);
869 					return;
870 				}
871 			}
872 		}
873 
874 		l2cap_chan_del(chan, reason);
875 		break;
876 
877 	case BT_CONNECT:
878 	case BT_DISCONN:
879 		l2cap_chan_del(chan, reason);
880 		break;
881 
882 	default:
883 		chan->ops->teardown(chan, 0);
884 		break;
885 	}
886 }
887 EXPORT_SYMBOL(l2cap_chan_close);
888 
889 static inline u8 l2cap_get_auth_type(struct l2cap_chan *chan)
890 {
891 	switch (chan->chan_type) {
892 	case L2CAP_CHAN_RAW:
893 		switch (chan->sec_level) {
894 		case BT_SECURITY_HIGH:
895 		case BT_SECURITY_FIPS:
896 			return HCI_AT_DEDICATED_BONDING_MITM;
897 		case BT_SECURITY_MEDIUM:
898 			return HCI_AT_DEDICATED_BONDING;
899 		default:
900 			return HCI_AT_NO_BONDING;
901 		}
902 		break;
903 	case L2CAP_CHAN_CONN_LESS:
904 		if (chan->psm == cpu_to_le16(L2CAP_PSM_3DSP)) {
905 			if (chan->sec_level == BT_SECURITY_LOW)
906 				chan->sec_level = BT_SECURITY_SDP;
907 		}
908 		if (chan->sec_level == BT_SECURITY_HIGH ||
909 		    chan->sec_level == BT_SECURITY_FIPS)
910 			return HCI_AT_NO_BONDING_MITM;
911 		else
912 			return HCI_AT_NO_BONDING;
913 		break;
914 	case L2CAP_CHAN_CONN_ORIENTED:
915 		if (chan->psm == cpu_to_le16(L2CAP_PSM_SDP)) {
916 			if (chan->sec_level == BT_SECURITY_LOW)
917 				chan->sec_level = BT_SECURITY_SDP;
918 
919 			if (chan->sec_level == BT_SECURITY_HIGH ||
920 			    chan->sec_level == BT_SECURITY_FIPS)
921 				return HCI_AT_NO_BONDING_MITM;
922 			else
923 				return HCI_AT_NO_BONDING;
924 		}
925 		fallthrough;
926 
927 	default:
928 		switch (chan->sec_level) {
929 		case BT_SECURITY_HIGH:
930 		case BT_SECURITY_FIPS:
931 			return HCI_AT_GENERAL_BONDING_MITM;
932 		case BT_SECURITY_MEDIUM:
933 			return HCI_AT_GENERAL_BONDING;
934 		default:
935 			return HCI_AT_NO_BONDING;
936 		}
937 		break;
938 	}
939 }
940 
941 /* Service level security */
942 int l2cap_chan_check_security(struct l2cap_chan *chan, bool initiator)
943 {
944 	struct l2cap_conn *conn = chan->conn;
945 	__u8 auth_type;
946 
947 	if (conn->hcon->type == LE_LINK)
948 		return smp_conn_security(conn->hcon, chan->sec_level);
949 
950 	auth_type = l2cap_get_auth_type(chan);
951 
952 	return hci_conn_security(conn->hcon, chan->sec_level, auth_type,
953 				 initiator);
954 }
955 
956 static int l2cap_get_ident(struct l2cap_conn *conn)
957 {
958 	u8 max;
959 	int ident;
960 
961 	/* LE link does not support tools like l2ping so use the full range */
962 	if (conn->hcon->type == LE_LINK)
963 		max = 255;
964 	/* Get next available identificator.
965 	 *    1 - 128 are used by kernel.
966 	 *  129 - 199 are reserved.
967 	 *  200 - 254 are used by utilities like l2ping, etc.
968 	 */
969 	else
970 		max = 128;
971 
972 	/* Allocate ident using min as last used + 1 (cyclic) */
973 	ident = ida_alloc_range(&conn->tx_ida, READ_ONCE(conn->tx_ident) + 1,
974 				max, GFP_ATOMIC);
975 	/* Force min 1 to start over */
976 	if (ident <= 0) {
977 		ident = ida_alloc_range(&conn->tx_ida, 1, max, GFP_ATOMIC);
978 		if (ident <= 0) {
979 			/* If all idents are in use, log an error, this is
980 			 * extremely unlikely to happen and would indicate a bug
981 			 * in the code that idents are not being freed properly.
982 			 */
983 			BT_ERR("Unable to allocate ident: %d", ident);
984 			return 0;
985 		}
986 	}
987 
988 	WRITE_ONCE(conn->tx_ident, ident);
989 
990 	return ident;
991 }
992 
993 static void l2cap_send_acl(struct l2cap_conn *conn, struct sk_buff *skb,
994 			   u8 flags)
995 {
996 	/* Check if the hcon still valid before attempting to send */
997 	if (hci_conn_valid(conn->hcon->hdev, conn->hcon))
998 		hci_send_acl(conn->hchan, skb, flags);
999 	else
1000 		kfree_skb(skb);
1001 }
1002 
1003 static void l2cap_send_cmd(struct l2cap_conn *conn, u8 ident, u8 code, u16 len,
1004 			   void *data)
1005 {
1006 	struct sk_buff *skb = l2cap_build_cmd(conn, code, ident, len, data);
1007 	u8 flags;
1008 
1009 	BT_DBG("code 0x%2.2x", code);
1010 
1011 	if (!skb)
1012 		return;
1013 
1014 	/* Use NO_FLUSH if supported or we have an LE link (which does
1015 	 * not support auto-flushing packets) */
1016 	if (lmp_no_flush_capable(conn->hcon->hdev) ||
1017 	    conn->hcon->type == LE_LINK)
1018 		flags = ACL_START_NO_FLUSH;
1019 	else
1020 		flags = ACL_START;
1021 
1022 	bt_cb(skb)->force_active = BT_POWER_FORCE_ACTIVE_ON;
1023 	skb->priority = HCI_PRIO_MAX;
1024 
1025 	l2cap_send_acl(conn, skb, flags);
1026 }
1027 
1028 static void l2cap_do_send(struct l2cap_chan *chan, struct sk_buff *skb)
1029 {
1030 	struct hci_conn *hcon = chan->conn->hcon;
1031 	u16 flags;
1032 
1033 	BT_DBG("chan %p, skb %p len %d priority %u", chan, skb, skb->len,
1034 	       skb->priority);
1035 
1036 	/* Use NO_FLUSH for LE links (where this is the only option) or
1037 	 * if the BR/EDR link supports it and flushing has not been
1038 	 * explicitly requested (through FLAG_FLUSHABLE).
1039 	 */
1040 	if (hcon->type == LE_LINK ||
1041 	    (!test_bit(FLAG_FLUSHABLE, &chan->flags) &&
1042 	     lmp_no_flush_capable(hcon->hdev)))
1043 		flags = ACL_START_NO_FLUSH;
1044 	else
1045 		flags = ACL_START;
1046 
1047 	bt_cb(skb)->force_active = test_bit(FLAG_FORCE_ACTIVE, &chan->flags);
1048 	hci_send_acl(chan->conn->hchan, skb, flags);
1049 }
1050 
1051 static void __unpack_enhanced_control(u16 enh, struct l2cap_ctrl *control)
1052 {
1053 	control->reqseq = (enh & L2CAP_CTRL_REQSEQ) >> L2CAP_CTRL_REQSEQ_SHIFT;
1054 	control->final = (enh & L2CAP_CTRL_FINAL) >> L2CAP_CTRL_FINAL_SHIFT;
1055 
1056 	if (enh & L2CAP_CTRL_FRAME_TYPE) {
1057 		/* S-Frame */
1058 		control->sframe = 1;
1059 		control->poll = (enh & L2CAP_CTRL_POLL) >> L2CAP_CTRL_POLL_SHIFT;
1060 		control->super = (enh & L2CAP_CTRL_SUPERVISE) >> L2CAP_CTRL_SUPER_SHIFT;
1061 
1062 		control->sar = 0;
1063 		control->txseq = 0;
1064 	} else {
1065 		/* I-Frame */
1066 		control->sframe = 0;
1067 		control->sar = (enh & L2CAP_CTRL_SAR) >> L2CAP_CTRL_SAR_SHIFT;
1068 		control->txseq = (enh & L2CAP_CTRL_TXSEQ) >> L2CAP_CTRL_TXSEQ_SHIFT;
1069 
1070 		control->poll = 0;
1071 		control->super = 0;
1072 	}
1073 }
1074 
1075 static void __unpack_extended_control(u32 ext, struct l2cap_ctrl *control)
1076 {
1077 	control->reqseq = (ext & L2CAP_EXT_CTRL_REQSEQ) >> L2CAP_EXT_CTRL_REQSEQ_SHIFT;
1078 	control->final = (ext & L2CAP_EXT_CTRL_FINAL) >> L2CAP_EXT_CTRL_FINAL_SHIFT;
1079 
1080 	if (ext & L2CAP_EXT_CTRL_FRAME_TYPE) {
1081 		/* S-Frame */
1082 		control->sframe = 1;
1083 		control->poll = (ext & L2CAP_EXT_CTRL_POLL) >> L2CAP_EXT_CTRL_POLL_SHIFT;
1084 		control->super = (ext & L2CAP_EXT_CTRL_SUPERVISE) >> L2CAP_EXT_CTRL_SUPER_SHIFT;
1085 
1086 		control->sar = 0;
1087 		control->txseq = 0;
1088 	} else {
1089 		/* I-Frame */
1090 		control->sframe = 0;
1091 		control->sar = (ext & L2CAP_EXT_CTRL_SAR) >> L2CAP_EXT_CTRL_SAR_SHIFT;
1092 		control->txseq = (ext & L2CAP_EXT_CTRL_TXSEQ) >> L2CAP_EXT_CTRL_TXSEQ_SHIFT;
1093 
1094 		control->poll = 0;
1095 		control->super = 0;
1096 	}
1097 }
1098 
1099 static inline void __unpack_control(struct l2cap_chan *chan,
1100 				    struct sk_buff *skb)
1101 {
1102 	if (test_bit(FLAG_EXT_CTRL, &chan->flags)) {
1103 		__unpack_extended_control(get_unaligned_le32(skb->data),
1104 					  &bt_cb(skb)->l2cap);
1105 		skb_pull(skb, L2CAP_EXT_CTRL_SIZE);
1106 	} else {
1107 		__unpack_enhanced_control(get_unaligned_le16(skb->data),
1108 					  &bt_cb(skb)->l2cap);
1109 		skb_pull(skb, L2CAP_ENH_CTRL_SIZE);
1110 	}
1111 }
1112 
1113 static u32 __pack_extended_control(struct l2cap_ctrl *control)
1114 {
1115 	u32 packed;
1116 
1117 	packed = control->reqseq << L2CAP_EXT_CTRL_REQSEQ_SHIFT;
1118 	packed |= control->final << L2CAP_EXT_CTRL_FINAL_SHIFT;
1119 
1120 	if (control->sframe) {
1121 		packed |= control->poll << L2CAP_EXT_CTRL_POLL_SHIFT;
1122 		packed |= control->super << L2CAP_EXT_CTRL_SUPER_SHIFT;
1123 		packed |= L2CAP_EXT_CTRL_FRAME_TYPE;
1124 	} else {
1125 		packed |= control->sar << L2CAP_EXT_CTRL_SAR_SHIFT;
1126 		packed |= control->txseq << L2CAP_EXT_CTRL_TXSEQ_SHIFT;
1127 	}
1128 
1129 	return packed;
1130 }
1131 
1132 static u16 __pack_enhanced_control(struct l2cap_ctrl *control)
1133 {
1134 	u16 packed;
1135 
1136 	packed = control->reqseq << L2CAP_CTRL_REQSEQ_SHIFT;
1137 	packed |= control->final << L2CAP_CTRL_FINAL_SHIFT;
1138 
1139 	if (control->sframe) {
1140 		packed |= control->poll << L2CAP_CTRL_POLL_SHIFT;
1141 		packed |= control->super << L2CAP_CTRL_SUPER_SHIFT;
1142 		packed |= L2CAP_CTRL_FRAME_TYPE;
1143 	} else {
1144 		packed |= control->sar << L2CAP_CTRL_SAR_SHIFT;
1145 		packed |= control->txseq << L2CAP_CTRL_TXSEQ_SHIFT;
1146 	}
1147 
1148 	return packed;
1149 }
1150 
1151 static inline void __pack_control(struct l2cap_chan *chan,
1152 				  struct l2cap_ctrl *control,
1153 				  struct sk_buff *skb)
1154 {
1155 	if (test_bit(FLAG_EXT_CTRL, &chan->flags)) {
1156 		put_unaligned_le32(__pack_extended_control(control),
1157 				   skb->data + L2CAP_HDR_SIZE);
1158 	} else {
1159 		put_unaligned_le16(__pack_enhanced_control(control),
1160 				   skb->data + L2CAP_HDR_SIZE);
1161 	}
1162 }
1163 
1164 static inline unsigned int __ertm_hdr_size(struct l2cap_chan *chan)
1165 {
1166 	if (test_bit(FLAG_EXT_CTRL, &chan->flags))
1167 		return L2CAP_EXT_HDR_SIZE;
1168 	else
1169 		return L2CAP_ENH_HDR_SIZE;
1170 }
1171 
1172 static struct sk_buff *l2cap_create_sframe_pdu(struct l2cap_chan *chan,
1173 					       u32 control)
1174 {
1175 	struct sk_buff *skb;
1176 	struct l2cap_hdr *lh;
1177 	int hlen = __ertm_hdr_size(chan);
1178 
1179 	if (chan->fcs == L2CAP_FCS_CRC16)
1180 		hlen += L2CAP_FCS_SIZE;
1181 
1182 	skb = bt_skb_alloc(hlen, GFP_KERNEL);
1183 
1184 	if (!skb)
1185 		return ERR_PTR(-ENOMEM);
1186 
1187 	lh = skb_put(skb, L2CAP_HDR_SIZE);
1188 	lh->len = cpu_to_le16(hlen - L2CAP_HDR_SIZE);
1189 	lh->cid = cpu_to_le16(chan->dcid);
1190 
1191 	if (test_bit(FLAG_EXT_CTRL, &chan->flags))
1192 		put_unaligned_le32(control, skb_put(skb, L2CAP_EXT_CTRL_SIZE));
1193 	else
1194 		put_unaligned_le16(control, skb_put(skb, L2CAP_ENH_CTRL_SIZE));
1195 
1196 	if (chan->fcs == L2CAP_FCS_CRC16) {
1197 		u16 fcs = crc16(0, (u8 *)skb->data, skb->len);
1198 		put_unaligned_le16(fcs, skb_put(skb, L2CAP_FCS_SIZE));
1199 	}
1200 
1201 	skb->priority = HCI_PRIO_MAX;
1202 	return skb;
1203 }
1204 
1205 static void l2cap_send_sframe(struct l2cap_chan *chan,
1206 			      struct l2cap_ctrl *control)
1207 {
1208 	struct sk_buff *skb;
1209 	u32 control_field;
1210 
1211 	BT_DBG("chan %p, control %p", chan, control);
1212 
1213 	if (!control->sframe)
1214 		return;
1215 
1216 	if (test_and_clear_bit(CONN_SEND_FBIT, &chan->conn_state) &&
1217 	    !control->poll)
1218 		control->final = 1;
1219 
1220 	if (control->super == L2CAP_SUPER_RR)
1221 		clear_bit(CONN_RNR_SENT, &chan->conn_state);
1222 	else if (control->super == L2CAP_SUPER_RNR)
1223 		set_bit(CONN_RNR_SENT, &chan->conn_state);
1224 
1225 	if (control->super != L2CAP_SUPER_SREJ) {
1226 		chan->last_acked_seq = control->reqseq;
1227 		__clear_ack_timer(chan);
1228 	}
1229 
1230 	BT_DBG("reqseq %d, final %d, poll %d, super %d", control->reqseq,
1231 	       control->final, control->poll, control->super);
1232 
1233 	if (test_bit(FLAG_EXT_CTRL, &chan->flags))
1234 		control_field = __pack_extended_control(control);
1235 	else
1236 		control_field = __pack_enhanced_control(control);
1237 
1238 	skb = l2cap_create_sframe_pdu(chan, control_field);
1239 	if (!IS_ERR(skb))
1240 		l2cap_do_send(chan, skb);
1241 }
1242 
1243 static void l2cap_send_rr_or_rnr(struct l2cap_chan *chan, bool poll)
1244 {
1245 	struct l2cap_ctrl control;
1246 
1247 	BT_DBG("chan %p, poll %d", chan, poll);
1248 
1249 	memset(&control, 0, sizeof(control));
1250 	control.sframe = 1;
1251 	control.poll = poll;
1252 
1253 	if (test_bit(CONN_LOCAL_BUSY, &chan->conn_state))
1254 		control.super = L2CAP_SUPER_RNR;
1255 	else
1256 		control.super = L2CAP_SUPER_RR;
1257 
1258 	control.reqseq = chan->buffer_seq;
1259 	l2cap_send_sframe(chan, &control);
1260 }
1261 
1262 static inline int __l2cap_no_conn_pending(struct l2cap_chan *chan)
1263 {
1264 	if (chan->chan_type != L2CAP_CHAN_CONN_ORIENTED)
1265 		return true;
1266 
1267 	return !test_bit(CONF_CONNECT_PEND, &chan->conf_state);
1268 }
1269 
1270 void l2cap_send_conn_req(struct l2cap_chan *chan)
1271 {
1272 	struct l2cap_conn *conn = chan->conn;
1273 	struct l2cap_conn_req req;
1274 
1275 	req.scid = cpu_to_le16(chan->scid);
1276 	req.psm  = chan->psm;
1277 
1278 	chan->ident = l2cap_get_ident(conn);
1279 
1280 	set_bit(CONF_CONNECT_PEND, &chan->conf_state);
1281 
1282 	l2cap_send_cmd(conn, chan->ident, L2CAP_CONN_REQ, sizeof(req), &req);
1283 }
1284 
1285 static void l2cap_chan_ready(struct l2cap_chan *chan)
1286 {
1287 	/* The channel may have already been flagged as connected in
1288 	 * case of receiving data before the L2CAP info req/rsp
1289 	 * procedure is complete.
1290 	 */
1291 	if (chan->state == BT_CONNECTED)
1292 		return;
1293 
1294 	/* This clears all conf flags, including CONF_NOT_COMPLETE */
1295 	chan->conf_state = 0;
1296 	__clear_chan_timer(chan);
1297 
1298 	switch (chan->mode) {
1299 	case L2CAP_MODE_LE_FLOWCTL:
1300 	case L2CAP_MODE_EXT_FLOWCTL:
1301 		if (!chan->tx_credits)
1302 			chan->ops->suspend(chan);
1303 		break;
1304 	}
1305 
1306 	chan->state = BT_CONNECTED;
1307 
1308 	chan->ops->ready(chan);
1309 }
1310 
1311 static void l2cap_le_connect(struct l2cap_chan *chan)
1312 {
1313 	struct l2cap_conn *conn = chan->conn;
1314 	struct l2cap_le_conn_req req;
1315 
1316 	if (test_and_set_bit(FLAG_LE_CONN_REQ_SENT, &chan->flags))
1317 		return;
1318 
1319 	if (!chan->imtu)
1320 		chan->imtu = chan->conn->mtu;
1321 
1322 	l2cap_le_flowctl_init(chan, 0);
1323 
1324 	memset(&req, 0, sizeof(req));
1325 	req.psm     = chan->psm;
1326 	req.scid    = cpu_to_le16(chan->scid);
1327 	req.mtu     = cpu_to_le16(chan->imtu);
1328 	req.mps     = cpu_to_le16(chan->mps);
1329 	req.credits = cpu_to_le16(chan->rx_credits);
1330 
1331 	chan->ident = l2cap_get_ident(conn);
1332 
1333 	l2cap_send_cmd(conn, chan->ident, L2CAP_LE_CONN_REQ,
1334 		       sizeof(req), &req);
1335 }
1336 
1337 struct l2cap_ecred_conn_data {
1338 	struct {
1339 		struct l2cap_ecred_conn_req_hdr req;
1340 		__le16 scid[L2CAP_ECRED_CONN_SCID_MAX];
1341 	} __packed pdu;
1342 	struct l2cap_chan *chan;
1343 	struct pid *pid;
1344 	int count;
1345 };
1346 
1347 static void l2cap_ecred_defer_connect(struct l2cap_chan *chan, void *data)
1348 {
1349 	struct l2cap_ecred_conn_data *conn = data;
1350 	struct pid *pid;
1351 
1352 	if (chan == conn->chan)
1353 		return;
1354 
1355 	if (!test_bit(FLAG_DEFER_SETUP, &chan->flags))
1356 		return;
1357 
1358 	pid = chan->ops->get_peer_pid(chan);
1359 
1360 	/* Only add deferred channels with the same PID/PSM */
1361 	if (conn->pid != pid || chan->psm != conn->chan->psm || chan->ident ||
1362 	    chan->mode != L2CAP_MODE_EXT_FLOWCTL || chan->state != BT_CONNECT)
1363 		return;
1364 
1365 	if (!test_and_clear_bit(FLAG_DEFER_SETUP, &chan->flags))
1366 		return;
1367 
1368 	if (test_and_set_bit(FLAG_ECRED_CONN_REQ_SENT, &chan->flags))
1369 		return;
1370 
1371 	/* Unreachable, checked in l2cap_connect (+timer drops it if reached) */
1372 	if (WARN_ON_ONCE(conn->count >= ARRAY_SIZE(conn->pdu.scid)))
1373 		return;
1374 
1375 	l2cap_ecred_init(chan, 0);
1376 
1377 	/* Set the same ident so we can match on the rsp */
1378 	chan->ident = conn->chan->ident;
1379 
1380 	/* Include all channels deferred */
1381 	conn->pdu.scid[conn->count] = cpu_to_le16(chan->scid);
1382 
1383 	conn->count++;
1384 }
1385 
1386 static void l2cap_ecred_connect(struct l2cap_chan *chan)
1387 {
1388 	struct l2cap_conn *conn = chan->conn;
1389 	struct l2cap_ecred_conn_data data;
1390 
1391 	if (test_bit(FLAG_DEFER_SETUP, &chan->flags))
1392 		return;
1393 
1394 	if (test_and_set_bit(FLAG_ECRED_CONN_REQ_SENT, &chan->flags))
1395 		return;
1396 
1397 	l2cap_ecred_init(chan, 0);
1398 
1399 	memset(&data, 0, sizeof(data));
1400 	data.pdu.req.psm     = chan->psm;
1401 	data.pdu.req.mtu     = cpu_to_le16(chan->imtu);
1402 	data.pdu.req.mps     = cpu_to_le16(chan->mps);
1403 	data.pdu.req.credits = cpu_to_le16(chan->rx_credits);
1404 	data.pdu.scid[0]     = cpu_to_le16(chan->scid);
1405 
1406 	chan->ident = l2cap_get_ident(conn);
1407 
1408 	data.count = 1;
1409 	data.chan = chan;
1410 	data.pid = chan->ops->get_peer_pid(chan);
1411 
1412 	__l2cap_chan_list(conn, l2cap_ecred_defer_connect, &data);
1413 
1414 	l2cap_send_cmd(conn, chan->ident, L2CAP_ECRED_CONN_REQ,
1415 		       sizeof(data.pdu.req) + data.count * sizeof(__le16),
1416 		       &data.pdu);
1417 }
1418 
1419 static void l2cap_le_start(struct l2cap_chan *chan)
1420 {
1421 	struct l2cap_conn *conn = chan->conn;
1422 
1423 	if (!smp_conn_security(conn->hcon, chan->sec_level))
1424 		return;
1425 
1426 	if (!chan->psm) {
1427 		l2cap_chan_ready(chan);
1428 		return;
1429 	}
1430 
1431 	if (chan->state == BT_CONNECT) {
1432 		if (chan->mode == L2CAP_MODE_EXT_FLOWCTL)
1433 			l2cap_ecred_connect(chan);
1434 		else
1435 			l2cap_le_connect(chan);
1436 	}
1437 }
1438 
1439 static void l2cap_start_connection(struct l2cap_chan *chan)
1440 {
1441 	if (chan->conn->hcon->type == LE_LINK) {
1442 		l2cap_le_start(chan);
1443 	} else {
1444 		l2cap_send_conn_req(chan);
1445 	}
1446 }
1447 
1448 static void l2cap_request_info(struct l2cap_conn *conn)
1449 {
1450 	struct l2cap_info_req req;
1451 
1452 	if (conn->info_state & L2CAP_INFO_FEAT_MASK_REQ_SENT)
1453 		return;
1454 
1455 	req.type = cpu_to_le16(L2CAP_IT_FEAT_MASK);
1456 
1457 	conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_SENT;
1458 	conn->info_ident = l2cap_get_ident(conn);
1459 
1460 	schedule_delayed_work(&conn->info_timer, L2CAP_INFO_TIMEOUT);
1461 
1462 	l2cap_send_cmd(conn, conn->info_ident, L2CAP_INFO_REQ,
1463 		       sizeof(req), &req);
1464 }
1465 
1466 static bool l2cap_check_enc_key_size(struct hci_conn *hcon,
1467 				     struct l2cap_chan *chan)
1468 {
1469 	/* The minimum encryption key size needs to be enforced by the
1470 	 * host stack before establishing any L2CAP connections. The
1471 	 * specification in theory allows a minimum of 1, but to align
1472 	 * BR/EDR and LE transports, a minimum of 7 is chosen.
1473 	 *
1474 	 * This check might also be called for unencrypted connections
1475 	 * that have no key size requirements. Ensure that the link is
1476 	 * actually encrypted before enforcing a key size.
1477 	 */
1478 	int min_key_size = hcon->hdev->min_enc_key_size;
1479 
1480 	/* On FIPS security level, key size must be 16 bytes */
1481 	if (chan->sec_level == BT_SECURITY_FIPS)
1482 		min_key_size = 16;
1483 
1484 	return (!test_bit(HCI_CONN_ENCRYPT, &hcon->flags) ||
1485 		hcon->enc_key_size >= min_key_size);
1486 }
1487 
1488 static void l2cap_do_start(struct l2cap_chan *chan)
1489 {
1490 	struct l2cap_conn *conn = chan->conn;
1491 
1492 	if (conn->hcon->type == LE_LINK) {
1493 		l2cap_le_start(chan);
1494 		return;
1495 	}
1496 
1497 	if (!(conn->info_state & L2CAP_INFO_FEAT_MASK_REQ_SENT)) {
1498 		l2cap_request_info(conn);
1499 		return;
1500 	}
1501 
1502 	if (!(conn->info_state & L2CAP_INFO_FEAT_MASK_REQ_DONE))
1503 		return;
1504 
1505 	if (!l2cap_chan_check_security(chan, true) ||
1506 	    !__l2cap_no_conn_pending(chan))
1507 		return;
1508 
1509 	if (l2cap_check_enc_key_size(conn->hcon, chan))
1510 		l2cap_start_connection(chan);
1511 	else
1512 		__set_chan_timer(chan, L2CAP_DISC_TIMEOUT);
1513 }
1514 
1515 static inline int l2cap_mode_supported(__u8 mode, __u32 feat_mask)
1516 {
1517 	u32 local_feat_mask = l2cap_feat_mask;
1518 	if (!disable_ertm)
1519 		local_feat_mask |= L2CAP_FEAT_ERTM | L2CAP_FEAT_STREAMING;
1520 
1521 	switch (mode) {
1522 	case L2CAP_MODE_ERTM:
1523 		return L2CAP_FEAT_ERTM & feat_mask & local_feat_mask;
1524 	case L2CAP_MODE_STREAMING:
1525 		return L2CAP_FEAT_STREAMING & feat_mask & local_feat_mask;
1526 	default:
1527 		return 0x00;
1528 	}
1529 }
1530 
1531 static void l2cap_send_disconn_req(struct l2cap_chan *chan, int err)
1532 {
1533 	struct l2cap_conn *conn = chan->conn;
1534 	struct l2cap_disconn_req req;
1535 
1536 	if (!conn)
1537 		return;
1538 
1539 	if (chan->mode == L2CAP_MODE_ERTM && chan->state == BT_CONNECTED) {
1540 		__clear_retrans_timer(chan);
1541 		__clear_monitor_timer(chan);
1542 		__clear_ack_timer(chan);
1543 	}
1544 
1545 	req.dcid = cpu_to_le16(chan->dcid);
1546 	req.scid = cpu_to_le16(chan->scid);
1547 	l2cap_send_cmd(conn, l2cap_get_ident(conn), L2CAP_DISCONN_REQ,
1548 		       sizeof(req), &req);
1549 
1550 	l2cap_state_change_and_error(chan, BT_DISCONN, err);
1551 }
1552 
1553 /* ---- L2CAP connections ---- */
1554 static void l2cap_conn_start(struct l2cap_conn *conn)
1555 {
1556 	struct l2cap_chan *chan, *tmp;
1557 
1558 	BT_DBG("conn %p", conn);
1559 
1560 	list_for_each_entry_safe(chan, tmp, &conn->chan_l, list) {
1561 		l2cap_chan_lock(chan);
1562 
1563 		if (chan->chan_type != L2CAP_CHAN_CONN_ORIENTED) {
1564 			l2cap_chan_ready(chan);
1565 			l2cap_chan_unlock(chan);
1566 			continue;
1567 		}
1568 
1569 		if (chan->state == BT_CONNECT) {
1570 			if (!l2cap_chan_check_security(chan, true) ||
1571 			    !__l2cap_no_conn_pending(chan)) {
1572 				l2cap_chan_unlock(chan);
1573 				continue;
1574 			}
1575 
1576 			if (!l2cap_mode_supported(chan->mode, conn->feat_mask)
1577 			    && test_bit(CONF_STATE2_DEVICE,
1578 					&chan->conf_state)) {
1579 				l2cap_chan_close(chan, ECONNRESET);
1580 				l2cap_chan_unlock(chan);
1581 				continue;
1582 			}
1583 
1584 			if (l2cap_check_enc_key_size(conn->hcon, chan))
1585 				l2cap_start_connection(chan);
1586 			else
1587 				l2cap_chan_close(chan, ECONNREFUSED);
1588 
1589 		} else if (chan->state == BT_CONNECT2) {
1590 			struct l2cap_conn_rsp rsp;
1591 			char buf[128];
1592 			rsp.scid = cpu_to_le16(chan->dcid);
1593 			rsp.dcid = cpu_to_le16(chan->scid);
1594 
1595 			if (l2cap_chan_check_security(chan, false)) {
1596 				if (test_bit(FLAG_DEFER_SETUP, &chan->flags)) {
1597 					rsp.result = cpu_to_le16(L2CAP_CR_PEND);
1598 					rsp.status = cpu_to_le16(L2CAP_CS_AUTHOR_PEND);
1599 					chan->ops->defer(chan);
1600 
1601 				} else {
1602 					l2cap_state_change(chan, BT_CONFIG);
1603 					rsp.result = cpu_to_le16(L2CAP_CR_SUCCESS);
1604 					rsp.status = cpu_to_le16(L2CAP_CS_NO_INFO);
1605 				}
1606 			} else {
1607 				rsp.result = cpu_to_le16(L2CAP_CR_PEND);
1608 				rsp.status = cpu_to_le16(L2CAP_CS_AUTHEN_PEND);
1609 			}
1610 
1611 			l2cap_send_cmd(conn, chan->ident, L2CAP_CONN_RSP,
1612 				       sizeof(rsp), &rsp);
1613 
1614 			if (test_bit(CONF_REQ_SENT, &chan->conf_state) ||
1615 			    rsp.result != L2CAP_CR_SUCCESS) {
1616 				l2cap_chan_unlock(chan);
1617 				continue;
1618 			}
1619 
1620 			set_bit(CONF_REQ_SENT, &chan->conf_state);
1621 			l2cap_send_cmd(conn, l2cap_get_ident(conn), L2CAP_CONF_REQ,
1622 				       l2cap_build_conf_req(chan, buf, sizeof(buf)), buf);
1623 			chan->num_conf_req++;
1624 		}
1625 
1626 		l2cap_chan_unlock(chan);
1627 	}
1628 }
1629 
1630 static void l2cap_le_conn_ready(struct l2cap_conn *conn)
1631 {
1632 	struct hci_conn *hcon = conn->hcon;
1633 	struct hci_dev *hdev = hcon->hdev;
1634 
1635 	BT_DBG("%s conn %p", hdev->name, conn);
1636 
1637 	/* For outgoing pairing which doesn't necessarily have an
1638 	 * associated socket (e.g. mgmt_pair_device).
1639 	 */
1640 	if (hcon->out)
1641 		smp_conn_security(hcon, hcon->pending_sec_level);
1642 
1643 	/* For LE peripheral connections, make sure the connection interval
1644 	 * is in the range of the minimum and maximum interval that has
1645 	 * been configured for this connection. If not, then trigger
1646 	 * the connection update procedure.
1647 	 */
1648 	if (hcon->role == HCI_ROLE_SLAVE &&
1649 	    (hcon->le_conn_interval < hcon->le_conn_min_interval ||
1650 	     hcon->le_conn_interval > hcon->le_conn_max_interval)) {
1651 		struct l2cap_conn_param_update_req req;
1652 
1653 		req.min = cpu_to_le16(hcon->le_conn_min_interval);
1654 		req.max = cpu_to_le16(hcon->le_conn_max_interval);
1655 		req.latency = cpu_to_le16(hcon->le_conn_latency);
1656 		req.to_multiplier = cpu_to_le16(hcon->le_supv_timeout);
1657 
1658 		l2cap_send_cmd(conn, l2cap_get_ident(conn),
1659 			       L2CAP_CONN_PARAM_UPDATE_REQ, sizeof(req), &req);
1660 	}
1661 }
1662 
1663 static void l2cap_conn_ready(struct l2cap_conn *conn)
1664 {
1665 	struct l2cap_chan *chan;
1666 	struct hci_conn *hcon = conn->hcon;
1667 
1668 	BT_DBG("conn %p", conn);
1669 
1670 	if (hcon->type == ACL_LINK)
1671 		l2cap_request_info(conn);
1672 
1673 	mutex_lock(&conn->lock);
1674 
1675 	list_for_each_entry(chan, &conn->chan_l, list) {
1676 
1677 		l2cap_chan_lock(chan);
1678 
1679 		if (hcon->type == LE_LINK) {
1680 			l2cap_le_start(chan);
1681 		} else if (chan->chan_type != L2CAP_CHAN_CONN_ORIENTED) {
1682 			if (conn->info_state & L2CAP_INFO_FEAT_MASK_REQ_DONE)
1683 				l2cap_chan_ready(chan);
1684 		} else if (chan->state == BT_CONNECT) {
1685 			l2cap_do_start(chan);
1686 		}
1687 
1688 		l2cap_chan_unlock(chan);
1689 	}
1690 
1691 	mutex_unlock(&conn->lock);
1692 
1693 	if (hcon->type == LE_LINK)
1694 		l2cap_le_conn_ready(conn);
1695 
1696 	queue_work(hcon->hdev->workqueue, &conn->pending_rx_work);
1697 }
1698 
1699 /* Notify sockets that we cannot guaranty reliability anymore */
1700 static void l2cap_conn_unreliable(struct l2cap_conn *conn, int err)
1701 {
1702 	struct l2cap_chan *chan;
1703 
1704 	BT_DBG("conn %p", conn);
1705 
1706 	list_for_each_entry(chan, &conn->chan_l, list) {
1707 		if (test_bit(FLAG_FORCE_RELIABLE, &chan->flags))
1708 			l2cap_chan_set_err(chan, err);
1709 	}
1710 }
1711 
1712 static void l2cap_info_timeout(struct work_struct *work)
1713 {
1714 	struct l2cap_conn *conn = container_of(work, struct l2cap_conn,
1715 					       info_timer.work);
1716 
1717 	conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_DONE;
1718 	conn->info_ident = 0;
1719 
1720 	mutex_lock(&conn->lock);
1721 	l2cap_conn_start(conn);
1722 	mutex_unlock(&conn->lock);
1723 }
1724 
1725 /*
1726  * l2cap_user
1727  * External modules can register l2cap_user objects on l2cap_conn. The ->probe
1728  * callback is called during registration. The ->remove callback is called
1729  * during unregistration.
1730  * An l2cap_user object can either be explicitly unregistered or when the
1731  * underlying l2cap_conn object is deleted. This guarantees that l2cap->hcon,
1732  * l2cap->hchan, .. are valid as long as the remove callback hasn't been called.
1733  * External modules must own a reference to the l2cap_conn object if they intend
1734  * to call l2cap_unregister_user(). The l2cap_conn object might get destroyed at
1735  * any time if they don't.
1736  */
1737 
1738 int l2cap_register_user(struct l2cap_conn *conn, struct l2cap_user *user)
1739 {
1740 	int ret;
1741 
1742 	/* We need to check whether l2cap_conn is registered. If it is not, we
1743 	 * must not register the l2cap_user. l2cap_conn_del() unregisters
1744 	 * l2cap_conn objects under conn->lock, and we use the same lock here
1745 	 * to protect access to conn->users and conn->hchan.
1746 	 */
1747 
1748 	mutex_lock(&conn->lock);
1749 
1750 	if (!list_empty(&user->list)) {
1751 		ret = -EINVAL;
1752 		goto out_unlock;
1753 	}
1754 
1755 	/* conn->hchan is NULL after l2cap_conn_del() was called */
1756 	if (!conn->hchan) {
1757 		ret = -ENODEV;
1758 		goto out_unlock;
1759 	}
1760 
1761 	ret = user->probe(conn, user);
1762 	if (ret)
1763 		goto out_unlock;
1764 
1765 	list_add(&user->list, &conn->users);
1766 	ret = 0;
1767 
1768 out_unlock:
1769 	mutex_unlock(&conn->lock);
1770 	return ret;
1771 }
1772 EXPORT_SYMBOL(l2cap_register_user);
1773 
1774 void l2cap_unregister_user(struct l2cap_conn *conn, struct l2cap_user *user)
1775 {
1776 	mutex_lock(&conn->lock);
1777 
1778 	if (list_empty(&user->list))
1779 		goto out_unlock;
1780 
1781 	list_del_init(&user->list);
1782 	user->remove(conn, user);
1783 
1784 out_unlock:
1785 	mutex_unlock(&conn->lock);
1786 }
1787 EXPORT_SYMBOL(l2cap_unregister_user);
1788 
1789 static void l2cap_unregister_all_users(struct l2cap_conn *conn)
1790 {
1791 	struct l2cap_user *user;
1792 
1793 	while (!list_empty(&conn->users)) {
1794 		user = list_first_entry(&conn->users, struct l2cap_user, list);
1795 		list_del_init(&user->list);
1796 		user->remove(conn, user);
1797 	}
1798 }
1799 
1800 static void l2cap_conn_del(struct hci_conn *hcon, int err)
1801 	__must_hold(&hcon->hdev->lock)
1802 {
1803 	struct l2cap_conn *conn = hcon->l2cap_data;
1804 	struct l2cap_chan *chan, *l;
1805 
1806 	if (!conn)
1807 		return;
1808 
1809 	BT_DBG("hcon %p conn %p, err %d", hcon, conn, err);
1810 
1811 	disable_delayed_work_sync(&conn->info_timer);
1812 	disable_delayed_work_sync(&conn->id_addr_timer);
1813 
1814 	cancel_work_sync(&conn->pending_rx_work);
1815 
1816 	mutex_lock(&conn->lock);
1817 
1818 	kfree_skb(conn->rx_skb);
1819 
1820 	skb_queue_purge(&conn->pending_rx);
1821 	ida_destroy(&conn->tx_ida);
1822 
1823 	l2cap_unregister_all_users(conn);
1824 
1825 	/* Force the connection to be immediately dropped */
1826 	hcon->disc_timeout = 0;
1827 
1828 	/* Kill channels */
1829 	list_for_each_entry_safe(chan, l, &conn->chan_l, list) {
1830 		l2cap_chan_hold(chan);
1831 		l2cap_chan_lock(chan);
1832 
1833 		l2cap_chan_del(chan, err);
1834 
1835 		chan->ops->close(chan);
1836 
1837 		l2cap_chan_unlock(chan);
1838 		l2cap_chan_put(chan);
1839 	}
1840 
1841 	hci_chan_del(conn->hchan);
1842 	conn->hchan = NULL;
1843 
1844 	spin_lock(&hcon->proto_lock);
1845 	hcon->l2cap_data = NULL;
1846 	spin_unlock(&hcon->proto_lock);
1847 
1848 	mutex_unlock(&conn->lock);
1849 	l2cap_conn_put(conn);
1850 }
1851 
1852 static void l2cap_conn_free(struct kref *ref)
1853 {
1854 	struct l2cap_conn *conn = container_of(ref, struct l2cap_conn, ref);
1855 
1856 	hci_conn_put(conn->hcon);
1857 	kfree(conn);
1858 }
1859 
1860 struct l2cap_conn *l2cap_conn_get(struct l2cap_conn *conn)
1861 {
1862 	kref_get(&conn->ref);
1863 	return conn;
1864 }
1865 EXPORT_SYMBOL(l2cap_conn_get);
1866 
1867 void l2cap_conn_put(struct l2cap_conn *conn)
1868 {
1869 	kref_put(&conn->ref, l2cap_conn_free);
1870 }
1871 EXPORT_SYMBOL(l2cap_conn_put);
1872 
1873 /* ---- Socket interface ---- */
1874 
1875 /* Find socket with psm and source / destination bdaddr.
1876  * Returns closest match.
1877  */
1878 static struct l2cap_chan *l2cap_global_chan_by_psm(int state, __le16 psm,
1879 						   bdaddr_t *src,
1880 						   bdaddr_t *dst,
1881 						   u8 link_type)
1882 {
1883 	struct l2cap_chan *c, *tmp, *c1 = NULL;
1884 
1885 	read_lock(&chan_list_lock);
1886 
1887 	list_for_each_entry_safe(c, tmp, &chan_list, global_l) {
1888 		if (state && c->state != state)
1889 			continue;
1890 
1891 		if (link_type == ACL_LINK && c->src_type != BDADDR_BREDR)
1892 			continue;
1893 
1894 		if (link_type == LE_LINK && c->src_type == BDADDR_BREDR)
1895 			continue;
1896 
1897 		if (c->chan_type != L2CAP_CHAN_FIXED && c->psm == psm) {
1898 			int src_match, dst_match;
1899 			int src_any, dst_any;
1900 
1901 			/* Exact match. */
1902 			src_match = !bacmp(&c->src, src);
1903 			dst_match = !bacmp(&c->dst, dst);
1904 			if (src_match && dst_match) {
1905 				if (!l2cap_chan_hold_unless_zero(c))
1906 					continue;
1907 
1908 				read_unlock(&chan_list_lock);
1909 				return c;
1910 			}
1911 
1912 			/* Closest match */
1913 			src_any = !bacmp(&c->src, BDADDR_ANY);
1914 			dst_any = !bacmp(&c->dst, BDADDR_ANY);
1915 			if ((src_match && dst_any) || (src_any && dst_match) ||
1916 			    (src_any && dst_any))
1917 				c1 = c;
1918 		}
1919 	}
1920 
1921 	if (c1)
1922 		c1 = l2cap_chan_hold_unless_zero(c1);
1923 
1924 	read_unlock(&chan_list_lock);
1925 
1926 	return c1;
1927 }
1928 
1929 static void l2cap_monitor_timeout(struct work_struct *work)
1930 {
1931 	struct l2cap_chan *chan = container_of(work, struct l2cap_chan,
1932 					       monitor_timer.work);
1933 
1934 	BT_DBG("chan %p", chan);
1935 
1936 	l2cap_chan_lock(chan);
1937 
1938 	if (test_bit(FLAG_DEL, &chan->flags)) {
1939 		l2cap_chan_unlock(chan);
1940 		l2cap_chan_put(chan);
1941 		return;
1942 	}
1943 
1944 	l2cap_tx(chan, NULL, NULL, L2CAP_EV_MONITOR_TO);
1945 
1946 	l2cap_chan_unlock(chan);
1947 	l2cap_chan_put(chan);
1948 }
1949 
1950 static void l2cap_retrans_timeout(struct work_struct *work)
1951 {
1952 	struct l2cap_chan *chan = container_of(work, struct l2cap_chan,
1953 					       retrans_timer.work);
1954 
1955 	BT_DBG("chan %p", chan);
1956 
1957 	l2cap_chan_lock(chan);
1958 
1959 	if (test_bit(FLAG_DEL, &chan->flags)) {
1960 		l2cap_chan_unlock(chan);
1961 		l2cap_chan_put(chan);
1962 		return;
1963 	}
1964 
1965 	l2cap_tx(chan, NULL, NULL, L2CAP_EV_RETRANS_TO);
1966 	l2cap_chan_unlock(chan);
1967 	l2cap_chan_put(chan);
1968 }
1969 
1970 static void l2cap_streaming_send(struct l2cap_chan *chan,
1971 				 struct sk_buff_head *skbs)
1972 {
1973 	struct sk_buff *skb;
1974 	struct l2cap_ctrl *control;
1975 
1976 	BT_DBG("chan %p, skbs %p", chan, skbs);
1977 
1978 	skb_queue_splice_tail_init(skbs, &chan->tx_q);
1979 
1980 	while (!skb_queue_empty(&chan->tx_q)) {
1981 
1982 		skb = skb_dequeue(&chan->tx_q);
1983 
1984 		bt_cb(skb)->l2cap.retries = 1;
1985 		control = &bt_cb(skb)->l2cap;
1986 
1987 		control->reqseq = 0;
1988 		control->txseq = chan->next_tx_seq;
1989 
1990 		__pack_control(chan, control, skb);
1991 
1992 		if (chan->fcs == L2CAP_FCS_CRC16) {
1993 			u16 fcs = crc16(0, (u8 *) skb->data, skb->len);
1994 			put_unaligned_le16(fcs, skb_put(skb, L2CAP_FCS_SIZE));
1995 		}
1996 
1997 		l2cap_do_send(chan, skb);
1998 
1999 		BT_DBG("Sent txseq %u", control->txseq);
2000 
2001 		chan->next_tx_seq = __next_seq(chan, chan->next_tx_seq);
2002 		chan->frames_sent++;
2003 	}
2004 }
2005 
2006 static int l2cap_ertm_send(struct l2cap_chan *chan)
2007 {
2008 	struct sk_buff *skb, *tx_skb;
2009 	struct l2cap_ctrl *control;
2010 	int sent = 0;
2011 
2012 	BT_DBG("chan %p", chan);
2013 
2014 	if (chan->state != BT_CONNECTED)
2015 		return -ENOTCONN;
2016 
2017 	if (test_bit(CONN_REMOTE_BUSY, &chan->conn_state))
2018 		return 0;
2019 
2020 	while (chan->tx_send_head &&
2021 	       chan->unacked_frames < chan->remote_tx_win &&
2022 	       chan->tx_state == L2CAP_TX_STATE_XMIT) {
2023 
2024 		skb = chan->tx_send_head;
2025 
2026 		bt_cb(skb)->l2cap.retries = 1;
2027 		control = &bt_cb(skb)->l2cap;
2028 
2029 		if (test_and_clear_bit(CONN_SEND_FBIT, &chan->conn_state))
2030 			control->final = 1;
2031 
2032 		control->reqseq = chan->buffer_seq;
2033 		chan->last_acked_seq = chan->buffer_seq;
2034 		control->txseq = chan->next_tx_seq;
2035 
2036 		__pack_control(chan, control, skb);
2037 
2038 		if (chan->fcs == L2CAP_FCS_CRC16) {
2039 			u16 fcs = crc16(0, (u8 *) skb->data, skb->len);
2040 			put_unaligned_le16(fcs, skb_put(skb, L2CAP_FCS_SIZE));
2041 		}
2042 
2043 		/* Clone after data has been modified. Data is assumed to be
2044 		   read-only (for locking purposes) on cloned sk_buffs.
2045 		 */
2046 		tx_skb = skb_clone(skb, GFP_KERNEL);
2047 
2048 		if (!tx_skb)
2049 			break;
2050 
2051 		__set_retrans_timer(chan);
2052 
2053 		chan->next_tx_seq = __next_seq(chan, chan->next_tx_seq);
2054 		chan->unacked_frames++;
2055 		chan->frames_sent++;
2056 		sent++;
2057 
2058 		if (skb_queue_is_last(&chan->tx_q, skb))
2059 			chan->tx_send_head = NULL;
2060 		else
2061 			chan->tx_send_head = skb_queue_next(&chan->tx_q, skb);
2062 
2063 		l2cap_do_send(chan, tx_skb);
2064 		BT_DBG("Sent txseq %u", control->txseq);
2065 	}
2066 
2067 	BT_DBG("Sent %d, %u unacked, %u in ERTM queue", sent,
2068 	       chan->unacked_frames, skb_queue_len(&chan->tx_q));
2069 
2070 	return sent;
2071 }
2072 
2073 static void l2cap_ertm_resend(struct l2cap_chan *chan)
2074 {
2075 	struct l2cap_ctrl control;
2076 	struct sk_buff *skb;
2077 	struct sk_buff *tx_skb;
2078 	u16 seq;
2079 
2080 	BT_DBG("chan %p", chan);
2081 
2082 	if (test_bit(CONN_REMOTE_BUSY, &chan->conn_state))
2083 		return;
2084 
2085 	while (chan->retrans_list.head != L2CAP_SEQ_LIST_CLEAR) {
2086 		seq = l2cap_seq_list_pop(&chan->retrans_list);
2087 
2088 		skb = l2cap_ertm_seq_in_queue(&chan->tx_q, seq);
2089 		if (!skb) {
2090 			BT_DBG("Error: Can't retransmit seq %d, frame missing",
2091 			       seq);
2092 			continue;
2093 		}
2094 
2095 		bt_cb(skb)->l2cap.retries++;
2096 		control = bt_cb(skb)->l2cap;
2097 
2098 		if (chan->max_tx != 0 &&
2099 		    bt_cb(skb)->l2cap.retries > chan->max_tx) {
2100 			BT_DBG("Retry limit exceeded (%d)", chan->max_tx);
2101 			l2cap_send_disconn_req(chan, ECONNRESET);
2102 			l2cap_seq_list_clear(&chan->retrans_list);
2103 			break;
2104 		}
2105 
2106 		control.reqseq = chan->buffer_seq;
2107 		if (test_and_clear_bit(CONN_SEND_FBIT, &chan->conn_state))
2108 			control.final = 1;
2109 		else
2110 			control.final = 0;
2111 
2112 		if (skb_cloned(skb)) {
2113 			/* Cloned sk_buffs are read-only, so we need a
2114 			 * writeable copy
2115 			 */
2116 			tx_skb = skb_copy(skb, GFP_KERNEL);
2117 		} else {
2118 			tx_skb = skb_clone(skb, GFP_KERNEL);
2119 		}
2120 
2121 		if (!tx_skb) {
2122 			l2cap_seq_list_clear(&chan->retrans_list);
2123 			break;
2124 		}
2125 
2126 		/* Update skb contents */
2127 		if (test_bit(FLAG_EXT_CTRL, &chan->flags)) {
2128 			put_unaligned_le32(__pack_extended_control(&control),
2129 					   tx_skb->data + L2CAP_HDR_SIZE);
2130 		} else {
2131 			put_unaligned_le16(__pack_enhanced_control(&control),
2132 					   tx_skb->data + L2CAP_HDR_SIZE);
2133 		}
2134 
2135 		/* Update FCS */
2136 		if (chan->fcs == L2CAP_FCS_CRC16) {
2137 			u16 fcs = crc16(0, (u8 *) tx_skb->data,
2138 					tx_skb->len - L2CAP_FCS_SIZE);
2139 			put_unaligned_le16(fcs, skb_tail_pointer(tx_skb) -
2140 						L2CAP_FCS_SIZE);
2141 		}
2142 
2143 		l2cap_do_send(chan, tx_skb);
2144 
2145 		BT_DBG("Resent txseq %d", control.txseq);
2146 
2147 		chan->last_acked_seq = chan->buffer_seq;
2148 	}
2149 }
2150 
2151 static void l2cap_retransmit(struct l2cap_chan *chan,
2152 			     struct l2cap_ctrl *control)
2153 {
2154 	BT_DBG("chan %p, control %p", chan, control);
2155 
2156 	l2cap_seq_list_append(&chan->retrans_list, control->reqseq);
2157 	l2cap_ertm_resend(chan);
2158 }
2159 
2160 static void l2cap_retransmit_all(struct l2cap_chan *chan,
2161 				 struct l2cap_ctrl *control)
2162 {
2163 	struct sk_buff *skb;
2164 
2165 	BT_DBG("chan %p, control %p", chan, control);
2166 
2167 	if (control->poll)
2168 		set_bit(CONN_SEND_FBIT, &chan->conn_state);
2169 
2170 	l2cap_seq_list_clear(&chan->retrans_list);
2171 
2172 	if (test_bit(CONN_REMOTE_BUSY, &chan->conn_state))
2173 		return;
2174 
2175 	if (chan->unacked_frames) {
2176 		skb_queue_walk(&chan->tx_q, skb) {
2177 			if (bt_cb(skb)->l2cap.txseq == control->reqseq ||
2178 			    skb == chan->tx_send_head)
2179 				break;
2180 		}
2181 
2182 		skb_queue_walk_from(&chan->tx_q, skb) {
2183 			if (skb == chan->tx_send_head)
2184 				break;
2185 
2186 			l2cap_seq_list_append(&chan->retrans_list,
2187 					      bt_cb(skb)->l2cap.txseq);
2188 		}
2189 
2190 		l2cap_ertm_resend(chan);
2191 	}
2192 }
2193 
2194 static void l2cap_send_ack(struct l2cap_chan *chan)
2195 {
2196 	struct l2cap_ctrl control;
2197 	u16 frames_to_ack = __seq_offset(chan, chan->buffer_seq,
2198 					 chan->last_acked_seq);
2199 	int threshold;
2200 
2201 	BT_DBG("chan %p last_acked_seq %d buffer_seq %d",
2202 	       chan, chan->last_acked_seq, chan->buffer_seq);
2203 
2204 	memset(&control, 0, sizeof(control));
2205 	control.sframe = 1;
2206 
2207 	if (test_bit(CONN_LOCAL_BUSY, &chan->conn_state) &&
2208 	    chan->rx_state == L2CAP_RX_STATE_RECV) {
2209 		__clear_ack_timer(chan);
2210 		control.super = L2CAP_SUPER_RNR;
2211 		control.reqseq = chan->buffer_seq;
2212 		l2cap_send_sframe(chan, &control);
2213 	} else {
2214 		if (!test_bit(CONN_REMOTE_BUSY, &chan->conn_state)) {
2215 			l2cap_ertm_send(chan);
2216 			/* If any i-frames were sent, they included an ack */
2217 			if (chan->buffer_seq == chan->last_acked_seq)
2218 				frames_to_ack = 0;
2219 		}
2220 
2221 		/* Ack now if the window is 3/4ths full.
2222 		 * Calculate without mul or div
2223 		 */
2224 		threshold = chan->ack_win;
2225 		threshold += threshold << 1;
2226 		threshold >>= 2;
2227 
2228 		BT_DBG("frames_to_ack %u, threshold %d", frames_to_ack,
2229 		       threshold);
2230 
2231 		if (frames_to_ack >= threshold) {
2232 			__clear_ack_timer(chan);
2233 			control.super = L2CAP_SUPER_RR;
2234 			control.reqseq = chan->buffer_seq;
2235 			l2cap_send_sframe(chan, &control);
2236 			frames_to_ack = 0;
2237 		}
2238 
2239 		if (frames_to_ack)
2240 			__set_ack_timer(chan);
2241 	}
2242 }
2243 
2244 static inline int l2cap_skbuff_fromiovec(struct l2cap_chan *chan,
2245 					 struct msghdr *msg, int len,
2246 					 int count, struct sk_buff *skb)
2247 {
2248 	struct l2cap_conn *conn = chan->conn;
2249 	struct sk_buff **frag;
2250 	int sent = 0;
2251 
2252 	if (!copy_from_iter_full(skb_put(skb, count), count, &msg->msg_iter))
2253 		return -EFAULT;
2254 
2255 	sent += count;
2256 	len  -= count;
2257 
2258 	/* Continuation fragments (no L2CAP header) */
2259 	frag = &skb_shinfo(skb)->frag_list;
2260 	while (len) {
2261 		struct sk_buff *tmp;
2262 
2263 		count = min_t(unsigned int, conn->mtu, len);
2264 
2265 		tmp = chan->ops->alloc_skb(chan, 0, count,
2266 					   msg->msg_flags & MSG_DONTWAIT);
2267 		if (IS_ERR(tmp))
2268 			return PTR_ERR(tmp);
2269 
2270 		*frag = tmp;
2271 
2272 		if (!copy_from_iter_full(skb_put(*frag, count), count,
2273 				   &msg->msg_iter))
2274 			return -EFAULT;
2275 
2276 		sent += count;
2277 		len  -= count;
2278 
2279 		skb->len += (*frag)->len;
2280 		skb->data_len += (*frag)->len;
2281 
2282 		frag = &(*frag)->next;
2283 	}
2284 
2285 	return sent;
2286 }
2287 
2288 static struct sk_buff *l2cap_create_connless_pdu(struct l2cap_chan *chan,
2289 						 struct msghdr *msg, size_t len)
2290 {
2291 	struct l2cap_conn *conn = chan->conn;
2292 	struct sk_buff *skb;
2293 	int err, count, hlen = L2CAP_HDR_SIZE + L2CAP_PSMLEN_SIZE;
2294 	struct l2cap_hdr *lh;
2295 
2296 	BT_DBG("chan %p psm 0x%2.2x len %zu", chan,
2297 	       __le16_to_cpu(chan->psm), len);
2298 
2299 	count = min_t(unsigned int, (conn->mtu - hlen), len);
2300 
2301 	skb = chan->ops->alloc_skb(chan, hlen, count,
2302 				   msg->msg_flags & MSG_DONTWAIT);
2303 	if (IS_ERR(skb))
2304 		return skb;
2305 
2306 	/* Create L2CAP header */
2307 	lh = skb_put(skb, L2CAP_HDR_SIZE);
2308 	lh->cid = cpu_to_le16(chan->dcid);
2309 	lh->len = cpu_to_le16(len + L2CAP_PSMLEN_SIZE);
2310 	put_unaligned(chan->psm, (__le16 *) skb_put(skb, L2CAP_PSMLEN_SIZE));
2311 
2312 	err = l2cap_skbuff_fromiovec(chan, msg, len, count, skb);
2313 	if (unlikely(err < 0)) {
2314 		kfree_skb(skb);
2315 		return ERR_PTR(err);
2316 	}
2317 	return skb;
2318 }
2319 
2320 static struct sk_buff *l2cap_create_basic_pdu(struct l2cap_chan *chan,
2321 					      struct msghdr *msg, size_t len)
2322 {
2323 	struct l2cap_conn *conn = chan->conn;
2324 	struct sk_buff *skb;
2325 	int err, count;
2326 	struct l2cap_hdr *lh;
2327 
2328 	BT_DBG("chan %p len %zu", chan, len);
2329 
2330 	count = min_t(unsigned int, (conn->mtu - L2CAP_HDR_SIZE), len);
2331 
2332 	skb = chan->ops->alloc_skb(chan, L2CAP_HDR_SIZE, count,
2333 				   msg->msg_flags & MSG_DONTWAIT);
2334 	if (IS_ERR(skb))
2335 		return skb;
2336 
2337 	/* Create L2CAP header */
2338 	lh = skb_put(skb, L2CAP_HDR_SIZE);
2339 	lh->cid = cpu_to_le16(chan->dcid);
2340 	lh->len = cpu_to_le16(len);
2341 
2342 	err = l2cap_skbuff_fromiovec(chan, msg, len, count, skb);
2343 	if (unlikely(err < 0)) {
2344 		kfree_skb(skb);
2345 		return ERR_PTR(err);
2346 	}
2347 	return skb;
2348 }
2349 
2350 static struct sk_buff *l2cap_create_iframe_pdu(struct l2cap_chan *chan,
2351 					       struct msghdr *msg, size_t len,
2352 					       u16 sdulen)
2353 {
2354 	struct l2cap_conn *conn = chan->conn;
2355 	struct sk_buff *skb;
2356 	int err, count, hlen;
2357 	struct l2cap_hdr *lh;
2358 
2359 	BT_DBG("chan %p len %zu", chan, len);
2360 
2361 	if (!conn)
2362 		return ERR_PTR(-ENOTCONN);
2363 
2364 	hlen = __ertm_hdr_size(chan);
2365 
2366 	if (sdulen)
2367 		hlen += L2CAP_SDULEN_SIZE;
2368 
2369 	if (chan->fcs == L2CAP_FCS_CRC16)
2370 		hlen += L2CAP_FCS_SIZE;
2371 
2372 	count = min_t(unsigned int, (conn->mtu - hlen), len);
2373 
2374 	skb = chan->ops->alloc_skb(chan, hlen, count,
2375 				   msg->msg_flags & MSG_DONTWAIT);
2376 	if (IS_ERR(skb))
2377 		return skb;
2378 
2379 	/* Create L2CAP header */
2380 	lh = skb_put(skb, L2CAP_HDR_SIZE);
2381 	lh->cid = cpu_to_le16(chan->dcid);
2382 	lh->len = cpu_to_le16(len + (hlen - L2CAP_HDR_SIZE));
2383 
2384 	/* Control header is populated later */
2385 	if (test_bit(FLAG_EXT_CTRL, &chan->flags))
2386 		put_unaligned_le32(0, skb_put(skb, L2CAP_EXT_CTRL_SIZE));
2387 	else
2388 		put_unaligned_le16(0, skb_put(skb, L2CAP_ENH_CTRL_SIZE));
2389 
2390 	if (sdulen)
2391 		put_unaligned_le16(sdulen, skb_put(skb, L2CAP_SDULEN_SIZE));
2392 
2393 	err = l2cap_skbuff_fromiovec(chan, msg, len, count, skb);
2394 	if (unlikely(err < 0)) {
2395 		kfree_skb(skb);
2396 		return ERR_PTR(err);
2397 	}
2398 
2399 	bt_cb(skb)->l2cap.fcs = chan->fcs;
2400 	bt_cb(skb)->l2cap.retries = 0;
2401 	return skb;
2402 }
2403 
2404 static int l2cap_segment_sdu(struct l2cap_chan *chan,
2405 			     struct sk_buff_head *seg_queue,
2406 			     struct msghdr *msg, size_t len)
2407 {
2408 	struct sk_buff *skb;
2409 	u16 sdu_len;
2410 	size_t pdu_len;
2411 	u8 sar;
2412 
2413 	BT_DBG("chan %p, msg %p, len %zu", chan, msg, len);
2414 
2415 	/* It is critical that ERTM PDUs fit in a single HCI fragment,
2416 	 * so fragmented skbs are not used.  The HCI layer's handling
2417 	 * of fragmented skbs is not compatible with ERTM's queueing.
2418 	 */
2419 
2420 	/* PDU size is derived from the HCI MTU */
2421 	pdu_len = chan->conn->mtu;
2422 
2423 	/* Constrain PDU size for BR/EDR connections */
2424 	pdu_len = min_t(size_t, pdu_len, L2CAP_BREDR_MAX_PAYLOAD);
2425 
2426 	/* Adjust for largest possible L2CAP overhead. */
2427 	if (chan->fcs)
2428 		pdu_len -= L2CAP_FCS_SIZE;
2429 
2430 	pdu_len -= __ertm_hdr_size(chan);
2431 
2432 	/* Remote device may have requested smaller PDUs */
2433 	pdu_len = min_t(size_t, pdu_len, chan->remote_mps);
2434 
2435 	if (!pdu_len)
2436 		return -EINVAL;
2437 
2438 	if (len <= pdu_len) {
2439 		sar = L2CAP_SAR_UNSEGMENTED;
2440 		sdu_len = 0;
2441 		pdu_len = len;
2442 	} else {
2443 		sar = L2CAP_SAR_START;
2444 		sdu_len = len;
2445 	}
2446 
2447 	while (len > 0) {
2448 		skb = l2cap_create_iframe_pdu(chan, msg, pdu_len, sdu_len);
2449 
2450 		if (IS_ERR(skb)) {
2451 			__skb_queue_purge(seg_queue);
2452 			return PTR_ERR(skb);
2453 		}
2454 
2455 		bt_cb(skb)->l2cap.sar = sar;
2456 		__skb_queue_tail(seg_queue, skb);
2457 
2458 		len -= pdu_len;
2459 		if (sdu_len)
2460 			sdu_len = 0;
2461 
2462 		if (len <= pdu_len) {
2463 			sar = L2CAP_SAR_END;
2464 			pdu_len = len;
2465 		} else {
2466 			sar = L2CAP_SAR_CONTINUE;
2467 		}
2468 	}
2469 
2470 	return 0;
2471 }
2472 
2473 static struct sk_buff *l2cap_create_le_flowctl_pdu(struct l2cap_chan *chan,
2474 						   struct msghdr *msg,
2475 						   size_t len, u16 sdulen)
2476 {
2477 	struct l2cap_conn *conn = chan->conn;
2478 	struct sk_buff *skb;
2479 	int err, count, hlen;
2480 	struct l2cap_hdr *lh;
2481 
2482 	BT_DBG("chan %p len %zu", chan, len);
2483 
2484 	if (!conn)
2485 		return ERR_PTR(-ENOTCONN);
2486 
2487 	hlen = L2CAP_HDR_SIZE;
2488 
2489 	if (sdulen)
2490 		hlen += L2CAP_SDULEN_SIZE;
2491 
2492 	count = min_t(unsigned int, (conn->mtu - hlen), len);
2493 
2494 	skb = chan->ops->alloc_skb(chan, hlen, count,
2495 				   msg->msg_flags & MSG_DONTWAIT);
2496 	if (IS_ERR(skb))
2497 		return skb;
2498 
2499 	/* Create L2CAP header */
2500 	lh = skb_put(skb, L2CAP_HDR_SIZE);
2501 	lh->cid = cpu_to_le16(chan->dcid);
2502 	lh->len = cpu_to_le16(len + (hlen - L2CAP_HDR_SIZE));
2503 
2504 	if (sdulen)
2505 		put_unaligned_le16(sdulen, skb_put(skb, L2CAP_SDULEN_SIZE));
2506 
2507 	err = l2cap_skbuff_fromiovec(chan, msg, len, count, skb);
2508 	if (unlikely(err < 0)) {
2509 		kfree_skb(skb);
2510 		return ERR_PTR(err);
2511 	}
2512 
2513 	return skb;
2514 }
2515 
2516 static int l2cap_segment_le_sdu(struct l2cap_chan *chan,
2517 				struct sk_buff_head *seg_queue,
2518 				struct msghdr *msg, size_t len)
2519 {
2520 	struct sk_buff *skb;
2521 	size_t pdu_len;
2522 	u16 sdu_len;
2523 
2524 	BT_DBG("chan %p, msg %p, len %zu", chan, msg, len);
2525 
2526 	sdu_len = len;
2527 	pdu_len = chan->remote_mps - L2CAP_SDULEN_SIZE;
2528 
2529 	while (len > 0) {
2530 		if (len <= pdu_len)
2531 			pdu_len = len;
2532 
2533 		skb = l2cap_create_le_flowctl_pdu(chan, msg, pdu_len, sdu_len);
2534 		if (IS_ERR(skb)) {
2535 			__skb_queue_purge(seg_queue);
2536 			return PTR_ERR(skb);
2537 		}
2538 
2539 		__skb_queue_tail(seg_queue, skb);
2540 
2541 		len -= pdu_len;
2542 
2543 		if (sdu_len) {
2544 			sdu_len = 0;
2545 			pdu_len += L2CAP_SDULEN_SIZE;
2546 		}
2547 	}
2548 
2549 	return 0;
2550 }
2551 
2552 static void l2cap_le_flowctl_send(struct l2cap_chan *chan)
2553 {
2554 	int sent = 0;
2555 
2556 	BT_DBG("chan %p", chan);
2557 
2558 	while (chan->tx_credits && !skb_queue_empty(&chan->tx_q)) {
2559 		l2cap_do_send(chan, skb_dequeue(&chan->tx_q));
2560 		chan->tx_credits--;
2561 		sent++;
2562 	}
2563 
2564 	BT_DBG("Sent %d credits %u queued %u", sent, chan->tx_credits,
2565 	       skb_queue_len(&chan->tx_q));
2566 }
2567 
2568 static void l2cap_tx_timestamp(struct sk_buff *skb,
2569 			       const struct sockcm_cookie *sockc,
2570 			       size_t len)
2571 {
2572 	struct sock *sk = skb ? skb->sk : NULL;
2573 
2574 	if (sk && sk->sk_type == SOCK_STREAM)
2575 		hci_setup_tx_timestamp(skb, len, sockc);
2576 	else
2577 		hci_setup_tx_timestamp(skb, 1, sockc);
2578 }
2579 
2580 static void l2cap_tx_timestamp_seg(struct sk_buff_head *queue,
2581 				   const struct sockcm_cookie *sockc,
2582 				   size_t len)
2583 {
2584 	struct sk_buff *skb = skb_peek(queue);
2585 	struct sock *sk = skb ? skb->sk : NULL;
2586 
2587 	if (sk && sk->sk_type == SOCK_STREAM)
2588 		l2cap_tx_timestamp(skb_peek_tail(queue), sockc, len);
2589 	else
2590 		l2cap_tx_timestamp(skb, sockc, len);
2591 }
2592 
2593 int l2cap_chan_send(struct l2cap_chan *chan, struct msghdr *msg, size_t len,
2594 		    const struct sockcm_cookie *sockc)
2595 {
2596 	struct sk_buff *skb;
2597 	int err;
2598 	struct sk_buff_head seg_queue;
2599 
2600 	if (test_bit(FLAG_DEL, &chan->flags))
2601 		return -ENOTCONN;
2602 
2603 	/* Connectionless channel */
2604 	if (chan->chan_type == L2CAP_CHAN_CONN_LESS) {
2605 		skb = l2cap_create_connless_pdu(chan, msg, len);
2606 		if (IS_ERR(skb))
2607 			return PTR_ERR(skb);
2608 
2609 		l2cap_tx_timestamp(skb, sockc, len);
2610 
2611 		l2cap_do_send(chan, skb);
2612 		return len;
2613 	}
2614 
2615 	switch (chan->mode) {
2616 	case L2CAP_MODE_LE_FLOWCTL:
2617 	case L2CAP_MODE_EXT_FLOWCTL:
2618 		/* Check outgoing MTU */
2619 		if (len > chan->omtu)
2620 			return -EMSGSIZE;
2621 
2622 		__skb_queue_head_init(&seg_queue);
2623 
2624 		err = l2cap_segment_le_sdu(chan, &seg_queue, msg, len);
2625 
2626 		if (chan->state != BT_CONNECTED) {
2627 			__skb_queue_purge(&seg_queue);
2628 			err = -ENOTCONN;
2629 		}
2630 
2631 		if (err)
2632 			return err;
2633 
2634 		l2cap_tx_timestamp_seg(&seg_queue, sockc, len);
2635 
2636 		skb_queue_splice_tail_init(&seg_queue, &chan->tx_q);
2637 
2638 		l2cap_le_flowctl_send(chan);
2639 
2640 		if (!chan->tx_credits)
2641 			chan->ops->suspend(chan);
2642 
2643 		err = len;
2644 
2645 		break;
2646 
2647 	case L2CAP_MODE_BASIC:
2648 		/* Check outgoing MTU */
2649 		if (len > chan->omtu)
2650 			return -EMSGSIZE;
2651 
2652 		/* Create a basic PDU */
2653 		skb = l2cap_create_basic_pdu(chan, msg, len);
2654 		if (IS_ERR(skb))
2655 			return PTR_ERR(skb);
2656 
2657 		l2cap_tx_timestamp(skb, sockc, len);
2658 
2659 		l2cap_do_send(chan, skb);
2660 		err = len;
2661 		break;
2662 
2663 	case L2CAP_MODE_ERTM:
2664 	case L2CAP_MODE_STREAMING:
2665 		/* Check outgoing MTU */
2666 		if (len > chan->omtu) {
2667 			err = -EMSGSIZE;
2668 			break;
2669 		}
2670 
2671 		__skb_queue_head_init(&seg_queue);
2672 
2673 		/* Do segmentation before calling in to the state machine,
2674 		 * since it's possible to block while waiting for memory
2675 		 * allocation.
2676 		 */
2677 		err = l2cap_segment_sdu(chan, &seg_queue, msg, len);
2678 
2679 		if (err)
2680 			break;
2681 
2682 		if (chan->mode == L2CAP_MODE_ERTM) {
2683 			/* TODO: ERTM mode timestamping */
2684 			l2cap_tx(chan, NULL, &seg_queue, L2CAP_EV_DATA_REQUEST);
2685 		} else {
2686 			l2cap_tx_timestamp_seg(&seg_queue, sockc, len);
2687 			l2cap_streaming_send(chan, &seg_queue);
2688 		}
2689 
2690 		err = len;
2691 
2692 		/* If the skbs were not queued for sending, they'll still be in
2693 		 * seg_queue and need to be purged.
2694 		 */
2695 		__skb_queue_purge(&seg_queue);
2696 		break;
2697 
2698 	default:
2699 		BT_DBG("bad state %1.1x", chan->mode);
2700 		err = -EBADFD;
2701 	}
2702 
2703 	return err;
2704 }
2705 EXPORT_SYMBOL_GPL(l2cap_chan_send);
2706 
2707 static void l2cap_send_srej(struct l2cap_chan *chan, u16 txseq)
2708 {
2709 	struct l2cap_ctrl control;
2710 	u16 seq;
2711 
2712 	BT_DBG("chan %p, txseq %u", chan, txseq);
2713 
2714 	memset(&control, 0, sizeof(control));
2715 	control.sframe = 1;
2716 	control.super = L2CAP_SUPER_SREJ;
2717 
2718 	for (seq = chan->expected_tx_seq; seq != txseq;
2719 	     seq = __next_seq(chan, seq)) {
2720 		if (!l2cap_ertm_seq_in_queue(&chan->srej_q, seq)) {
2721 			control.reqseq = seq;
2722 			l2cap_send_sframe(chan, &control);
2723 			l2cap_seq_list_append(&chan->srej_list, seq);
2724 		}
2725 	}
2726 
2727 	chan->expected_tx_seq = __next_seq(chan, txseq);
2728 }
2729 
2730 static void l2cap_send_srej_tail(struct l2cap_chan *chan)
2731 {
2732 	struct l2cap_ctrl control;
2733 
2734 	BT_DBG("chan %p", chan);
2735 
2736 	if (chan->srej_list.tail == L2CAP_SEQ_LIST_CLEAR)
2737 		return;
2738 
2739 	memset(&control, 0, sizeof(control));
2740 	control.sframe = 1;
2741 	control.super = L2CAP_SUPER_SREJ;
2742 	control.reqseq = chan->srej_list.tail;
2743 	l2cap_send_sframe(chan, &control);
2744 }
2745 
2746 static void l2cap_send_srej_list(struct l2cap_chan *chan, u16 txseq)
2747 {
2748 	struct l2cap_ctrl control;
2749 	u16 initial_head;
2750 	u16 seq;
2751 
2752 	BT_DBG("chan %p, txseq %u", chan, txseq);
2753 
2754 	memset(&control, 0, sizeof(control));
2755 	control.sframe = 1;
2756 	control.super = L2CAP_SUPER_SREJ;
2757 
2758 	/* Capture initial list head to allow only one pass through the list. */
2759 	initial_head = chan->srej_list.head;
2760 
2761 	do {
2762 		seq = l2cap_seq_list_pop(&chan->srej_list);
2763 		if (seq == txseq || seq == L2CAP_SEQ_LIST_CLEAR)
2764 			break;
2765 
2766 		control.reqseq = seq;
2767 		l2cap_send_sframe(chan, &control);
2768 		l2cap_seq_list_append(&chan->srej_list, seq);
2769 	} while (chan->srej_list.head != initial_head);
2770 }
2771 
2772 static void l2cap_process_reqseq(struct l2cap_chan *chan, u16 reqseq)
2773 {
2774 	struct sk_buff *acked_skb;
2775 	u16 ackseq;
2776 
2777 	BT_DBG("chan %p, reqseq %u", chan, reqseq);
2778 
2779 	if (chan->unacked_frames == 0 || reqseq == chan->expected_ack_seq)
2780 		return;
2781 
2782 	BT_DBG("expected_ack_seq %u, unacked_frames %u",
2783 	       chan->expected_ack_seq, chan->unacked_frames);
2784 
2785 	for (ackseq = chan->expected_ack_seq; ackseq != reqseq;
2786 	     ackseq = __next_seq(chan, ackseq)) {
2787 
2788 		acked_skb = l2cap_ertm_seq_in_queue(&chan->tx_q, ackseq);
2789 		if (acked_skb) {
2790 			skb_unlink(acked_skb, &chan->tx_q);
2791 			kfree_skb(acked_skb);
2792 			chan->unacked_frames--;
2793 		}
2794 	}
2795 
2796 	chan->expected_ack_seq = reqseq;
2797 
2798 	if (chan->unacked_frames == 0)
2799 		__clear_retrans_timer(chan);
2800 
2801 	BT_DBG("unacked_frames %u", chan->unacked_frames);
2802 }
2803 
2804 static void l2cap_abort_rx_srej_sent(struct l2cap_chan *chan)
2805 {
2806 	BT_DBG("chan %p", chan);
2807 
2808 	chan->expected_tx_seq = chan->buffer_seq;
2809 	l2cap_seq_list_clear(&chan->srej_list);
2810 	skb_queue_purge(&chan->srej_q);
2811 	chan->rx_state = L2CAP_RX_STATE_RECV;
2812 }
2813 
2814 static void l2cap_tx_state_xmit(struct l2cap_chan *chan,
2815 				struct l2cap_ctrl *control,
2816 				struct sk_buff_head *skbs, u8 event)
2817 {
2818 	BT_DBG("chan %p, control %p, skbs %p, event %d", chan, control, skbs,
2819 	       event);
2820 
2821 	switch (event) {
2822 	case L2CAP_EV_DATA_REQUEST:
2823 		if (chan->tx_send_head == NULL)
2824 			chan->tx_send_head = skb_peek(skbs);
2825 
2826 		skb_queue_splice_tail_init(skbs, &chan->tx_q);
2827 		l2cap_ertm_send(chan);
2828 		break;
2829 	case L2CAP_EV_LOCAL_BUSY_DETECTED:
2830 		BT_DBG("Enter LOCAL_BUSY");
2831 		set_bit(CONN_LOCAL_BUSY, &chan->conn_state);
2832 
2833 		if (chan->rx_state == L2CAP_RX_STATE_SREJ_SENT) {
2834 			/* The SREJ_SENT state must be aborted if we are to
2835 			 * enter the LOCAL_BUSY state.
2836 			 */
2837 			l2cap_abort_rx_srej_sent(chan);
2838 		}
2839 
2840 		l2cap_send_ack(chan);
2841 
2842 		break;
2843 	case L2CAP_EV_LOCAL_BUSY_CLEAR:
2844 		BT_DBG("Exit LOCAL_BUSY");
2845 		clear_bit(CONN_LOCAL_BUSY, &chan->conn_state);
2846 
2847 		if (test_bit(CONN_RNR_SENT, &chan->conn_state)) {
2848 			struct l2cap_ctrl local_control;
2849 
2850 			memset(&local_control, 0, sizeof(local_control));
2851 			local_control.sframe = 1;
2852 			local_control.super = L2CAP_SUPER_RR;
2853 			local_control.poll = 1;
2854 			local_control.reqseq = chan->buffer_seq;
2855 			l2cap_send_sframe(chan, &local_control);
2856 
2857 			chan->retry_count = 1;
2858 			__set_monitor_timer(chan);
2859 			chan->tx_state = L2CAP_TX_STATE_WAIT_F;
2860 		}
2861 		break;
2862 	case L2CAP_EV_RECV_REQSEQ_AND_FBIT:
2863 		l2cap_process_reqseq(chan, control->reqseq);
2864 		break;
2865 	case L2CAP_EV_EXPLICIT_POLL:
2866 		l2cap_send_rr_or_rnr(chan, 1);
2867 		chan->retry_count = 1;
2868 		__set_monitor_timer(chan);
2869 		__clear_ack_timer(chan);
2870 		chan->tx_state = L2CAP_TX_STATE_WAIT_F;
2871 		break;
2872 	case L2CAP_EV_RETRANS_TO:
2873 		l2cap_send_rr_or_rnr(chan, 1);
2874 		chan->retry_count = 1;
2875 		__set_monitor_timer(chan);
2876 		chan->tx_state = L2CAP_TX_STATE_WAIT_F;
2877 		break;
2878 	case L2CAP_EV_RECV_FBIT:
2879 		/* Nothing to process */
2880 		break;
2881 	default:
2882 		break;
2883 	}
2884 }
2885 
2886 static void l2cap_tx_state_wait_f(struct l2cap_chan *chan,
2887 				  struct l2cap_ctrl *control,
2888 				  struct sk_buff_head *skbs, u8 event)
2889 {
2890 	BT_DBG("chan %p, control %p, skbs %p, event %d", chan, control, skbs,
2891 	       event);
2892 
2893 	switch (event) {
2894 	case L2CAP_EV_DATA_REQUEST:
2895 		if (chan->tx_send_head == NULL)
2896 			chan->tx_send_head = skb_peek(skbs);
2897 		/* Queue data, but don't send. */
2898 		skb_queue_splice_tail_init(skbs, &chan->tx_q);
2899 		break;
2900 	case L2CAP_EV_LOCAL_BUSY_DETECTED:
2901 		BT_DBG("Enter LOCAL_BUSY");
2902 		set_bit(CONN_LOCAL_BUSY, &chan->conn_state);
2903 
2904 		if (chan->rx_state == L2CAP_RX_STATE_SREJ_SENT) {
2905 			/* The SREJ_SENT state must be aborted if we are to
2906 			 * enter the LOCAL_BUSY state.
2907 			 */
2908 			l2cap_abort_rx_srej_sent(chan);
2909 		}
2910 
2911 		l2cap_send_ack(chan);
2912 
2913 		break;
2914 	case L2CAP_EV_LOCAL_BUSY_CLEAR:
2915 		BT_DBG("Exit LOCAL_BUSY");
2916 		clear_bit(CONN_LOCAL_BUSY, &chan->conn_state);
2917 
2918 		if (test_bit(CONN_RNR_SENT, &chan->conn_state)) {
2919 			struct l2cap_ctrl local_control;
2920 			memset(&local_control, 0, sizeof(local_control));
2921 			local_control.sframe = 1;
2922 			local_control.super = L2CAP_SUPER_RR;
2923 			local_control.poll = 1;
2924 			local_control.reqseq = chan->buffer_seq;
2925 			l2cap_send_sframe(chan, &local_control);
2926 
2927 			chan->retry_count = 1;
2928 			__set_monitor_timer(chan);
2929 			chan->tx_state = L2CAP_TX_STATE_WAIT_F;
2930 		}
2931 		break;
2932 	case L2CAP_EV_RECV_REQSEQ_AND_FBIT:
2933 		l2cap_process_reqseq(chan, control->reqseq);
2934 		fallthrough;
2935 
2936 	case L2CAP_EV_RECV_FBIT:
2937 		if (control && control->final) {
2938 			__clear_monitor_timer(chan);
2939 			if (chan->unacked_frames > 0)
2940 				__set_retrans_timer(chan);
2941 			chan->retry_count = 0;
2942 			chan->tx_state = L2CAP_TX_STATE_XMIT;
2943 			BT_DBG("recv fbit tx_state 0x2.2%x", chan->tx_state);
2944 		}
2945 		break;
2946 	case L2CAP_EV_EXPLICIT_POLL:
2947 		/* Ignore */
2948 		break;
2949 	case L2CAP_EV_MONITOR_TO:
2950 		if (chan->max_tx == 0 || chan->retry_count < chan->max_tx) {
2951 			l2cap_send_rr_or_rnr(chan, 1);
2952 			__set_monitor_timer(chan);
2953 			chan->retry_count++;
2954 		} else {
2955 			l2cap_send_disconn_req(chan, ECONNABORTED);
2956 		}
2957 		break;
2958 	default:
2959 		break;
2960 	}
2961 }
2962 
2963 static void l2cap_tx(struct l2cap_chan *chan, struct l2cap_ctrl *control,
2964 		     struct sk_buff_head *skbs, u8 event)
2965 {
2966 	BT_DBG("chan %p, control %p, skbs %p, event %d, state %d",
2967 	       chan, control, skbs, event, chan->tx_state);
2968 
2969 	switch (chan->tx_state) {
2970 	case L2CAP_TX_STATE_XMIT:
2971 		l2cap_tx_state_xmit(chan, control, skbs, event);
2972 		break;
2973 	case L2CAP_TX_STATE_WAIT_F:
2974 		l2cap_tx_state_wait_f(chan, control, skbs, event);
2975 		break;
2976 	default:
2977 		/* Ignore event */
2978 		break;
2979 	}
2980 }
2981 
2982 static void l2cap_pass_to_tx(struct l2cap_chan *chan,
2983 			     struct l2cap_ctrl *control)
2984 {
2985 	BT_DBG("chan %p, control %p", chan, control);
2986 	l2cap_tx(chan, control, NULL, L2CAP_EV_RECV_REQSEQ_AND_FBIT);
2987 }
2988 
2989 static void l2cap_pass_to_tx_fbit(struct l2cap_chan *chan,
2990 				  struct l2cap_ctrl *control)
2991 {
2992 	BT_DBG("chan %p, control %p", chan, control);
2993 	l2cap_tx(chan, control, NULL, L2CAP_EV_RECV_FBIT);
2994 }
2995 
2996 /* Copy frame to all raw sockets on that connection */
2997 static void l2cap_raw_recv(struct l2cap_conn *conn, struct sk_buff *skb)
2998 {
2999 	struct sk_buff *nskb;
3000 	struct l2cap_chan *chan;
3001 
3002 	BT_DBG("conn %p", conn);
3003 
3004 	list_for_each_entry(chan, &conn->chan_l, list) {
3005 		if (chan->chan_type != L2CAP_CHAN_RAW)
3006 			continue;
3007 
3008 		/* Don't send frame to the channel it came from */
3009 		if (bt_cb(skb)->l2cap.chan == chan)
3010 			continue;
3011 
3012 		nskb = skb_clone(skb, GFP_KERNEL);
3013 		if (!nskb)
3014 			continue;
3015 		if (chan->ops->recv(chan, nskb))
3016 			kfree_skb(nskb);
3017 	}
3018 }
3019 
3020 /* ---- L2CAP signalling commands ---- */
3021 static struct sk_buff *l2cap_build_cmd(struct l2cap_conn *conn, u8 code,
3022 				       u8 ident, u16 dlen, void *data)
3023 {
3024 	struct sk_buff *skb, **frag;
3025 	struct l2cap_cmd_hdr *cmd;
3026 	struct l2cap_hdr *lh;
3027 	int len, count;
3028 
3029 	BT_DBG("conn %p, code 0x%2.2x, ident 0x%2.2x, len %u",
3030 	       conn, code, ident, dlen);
3031 
3032 	if (conn->mtu < L2CAP_HDR_SIZE + L2CAP_CMD_HDR_SIZE)
3033 		return NULL;
3034 
3035 	len = L2CAP_HDR_SIZE + L2CAP_CMD_HDR_SIZE + dlen;
3036 	count = min_t(unsigned int, conn->mtu, len);
3037 
3038 	skb = bt_skb_alloc(count, GFP_KERNEL);
3039 	if (!skb)
3040 		return NULL;
3041 
3042 	lh = skb_put(skb, L2CAP_HDR_SIZE);
3043 	lh->len = cpu_to_le16(L2CAP_CMD_HDR_SIZE + dlen);
3044 
3045 	if (conn->hcon->type == LE_LINK)
3046 		lh->cid = cpu_to_le16(L2CAP_CID_LE_SIGNALING);
3047 	else
3048 		lh->cid = cpu_to_le16(L2CAP_CID_SIGNALING);
3049 
3050 	cmd = skb_put(skb, L2CAP_CMD_HDR_SIZE);
3051 	cmd->code  = code;
3052 	cmd->ident = ident;
3053 	cmd->len   = cpu_to_le16(dlen);
3054 
3055 	if (dlen) {
3056 		count -= L2CAP_HDR_SIZE + L2CAP_CMD_HDR_SIZE;
3057 		skb_put_data(skb, data, count);
3058 		data += count;
3059 	}
3060 
3061 	len -= skb->len;
3062 
3063 	/* Continuation fragments (no L2CAP header) */
3064 	frag = &skb_shinfo(skb)->frag_list;
3065 	while (len) {
3066 		count = min_t(unsigned int, conn->mtu, len);
3067 
3068 		*frag = bt_skb_alloc(count, GFP_KERNEL);
3069 		if (!*frag)
3070 			goto fail;
3071 
3072 		skb_put_data(*frag, data, count);
3073 
3074 		len  -= count;
3075 		data += count;
3076 
3077 		frag = &(*frag)->next;
3078 	}
3079 
3080 	return skb;
3081 
3082 fail:
3083 	kfree_skb(skb);
3084 	return NULL;
3085 }
3086 
3087 static inline int l2cap_get_conf_opt(void **ptr, void *end, int *type,
3088 				     int *olen, unsigned long *val)
3089 {
3090 	struct l2cap_conf_opt *opt = *ptr;
3091 	int len;
3092 
3093 	/* opt->len is attacker-controlled. Validate that the full option
3094 	 * (header + value) actually fits in the buffer before touching
3095 	 * opt->val, otherwise the switch below reads past the end of the
3096 	 * caller's buffer.
3097 	 */
3098 	if (end - *ptr < L2CAP_CONF_OPT_SIZE)
3099 		return -EINVAL;
3100 
3101 	len = L2CAP_CONF_OPT_SIZE + opt->len;
3102 	if (end - *ptr < len)
3103 		return -EINVAL;
3104 
3105 	*ptr += len;
3106 
3107 	*type = opt->type;
3108 	*olen = opt->len;
3109 
3110 	switch (opt->len) {
3111 	case 1:
3112 		*val = *((u8 *) opt->val);
3113 		break;
3114 
3115 	case 2:
3116 		*val = get_unaligned_le16(opt->val);
3117 		break;
3118 
3119 	case 4:
3120 		*val = get_unaligned_le32(opt->val);
3121 		break;
3122 
3123 	default:
3124 		*val = (unsigned long) opt->val;
3125 		break;
3126 	}
3127 
3128 	BT_DBG("type 0x%2.2x len %u val 0x%lx", *type, opt->len, *val);
3129 	return len;
3130 }
3131 
3132 static void l2cap_add_conf_opt(void **ptr, u8 type, u8 len, unsigned long val, size_t size)
3133 {
3134 	struct l2cap_conf_opt *opt = *ptr;
3135 
3136 	BT_DBG("type 0x%2.2x len %u val 0x%lx", type, len, val);
3137 
3138 	if (size < L2CAP_CONF_OPT_SIZE + len)
3139 		return;
3140 
3141 	opt->type = type;
3142 	opt->len  = len;
3143 
3144 	switch (len) {
3145 	case 1:
3146 		*((u8 *) opt->val)  = val;
3147 		break;
3148 
3149 	case 2:
3150 		put_unaligned_le16(val, opt->val);
3151 		break;
3152 
3153 	case 4:
3154 		put_unaligned_le32(val, opt->val);
3155 		break;
3156 
3157 	default:
3158 		memcpy(opt->val, (void *) val, len);
3159 		break;
3160 	}
3161 
3162 	*ptr += L2CAP_CONF_OPT_SIZE + len;
3163 }
3164 
3165 static void l2cap_add_opt_efs(void **ptr, struct l2cap_chan *chan, size_t size)
3166 {
3167 	struct l2cap_conf_efs efs;
3168 
3169 	switch (chan->mode) {
3170 	case L2CAP_MODE_ERTM:
3171 		efs.id		= chan->local_id;
3172 		efs.stype	= chan->local_stype;
3173 		efs.msdu	= cpu_to_le16(chan->local_msdu);
3174 		efs.sdu_itime	= cpu_to_le32(chan->local_sdu_itime);
3175 		efs.acc_lat	= cpu_to_le32(L2CAP_DEFAULT_ACC_LAT);
3176 		efs.flush_to	= cpu_to_le32(L2CAP_EFS_DEFAULT_FLUSH_TO);
3177 		break;
3178 
3179 	case L2CAP_MODE_STREAMING:
3180 		efs.id		= 1;
3181 		efs.stype	= L2CAP_SERV_BESTEFFORT;
3182 		efs.msdu	= cpu_to_le16(chan->local_msdu);
3183 		efs.sdu_itime	= cpu_to_le32(chan->local_sdu_itime);
3184 		efs.acc_lat	= 0;
3185 		efs.flush_to	= 0;
3186 		break;
3187 
3188 	default:
3189 		return;
3190 	}
3191 
3192 	l2cap_add_conf_opt(ptr, L2CAP_CONF_EFS, sizeof(efs),
3193 			   (unsigned long) &efs, size);
3194 }
3195 
3196 static void l2cap_ack_timeout(struct work_struct *work)
3197 {
3198 	struct l2cap_chan *chan = container_of(work, struct l2cap_chan,
3199 					       ack_timer.work);
3200 	u16 frames_to_ack;
3201 
3202 	BT_DBG("chan %p", chan);
3203 
3204 	l2cap_chan_lock(chan);
3205 
3206 	if (test_bit(FLAG_DEL, &chan->flags))
3207 		goto unlock;
3208 
3209 	frames_to_ack = __seq_offset(chan, chan->buffer_seq,
3210 				     chan->last_acked_seq);
3211 
3212 	if (frames_to_ack)
3213 		l2cap_send_rr_or_rnr(chan, 0);
3214 
3215 unlock:
3216 	l2cap_chan_unlock(chan);
3217 	l2cap_chan_put(chan);
3218 }
3219 
3220 int l2cap_ertm_init(struct l2cap_chan *chan)
3221 {
3222 	int err;
3223 
3224 	chan->next_tx_seq = 0;
3225 	chan->expected_tx_seq = 0;
3226 	chan->expected_ack_seq = 0;
3227 	chan->unacked_frames = 0;
3228 	chan->buffer_seq = 0;
3229 	chan->frames_sent = 0;
3230 	chan->last_acked_seq = 0;
3231 	chan->sdu = NULL;
3232 	chan->sdu_last_frag = NULL;
3233 	chan->sdu_len = 0;
3234 
3235 	skb_queue_head_init(&chan->tx_q);
3236 
3237 	if (chan->mode != L2CAP_MODE_ERTM)
3238 		return 0;
3239 
3240 	chan->rx_state = L2CAP_RX_STATE_RECV;
3241 	chan->tx_state = L2CAP_TX_STATE_XMIT;
3242 
3243 	skb_queue_head_init(&chan->srej_q);
3244 
3245 	err = l2cap_seq_list_init(&chan->srej_list, chan->tx_win);
3246 	if (err < 0)
3247 		return err;
3248 
3249 	err = l2cap_seq_list_init(&chan->retrans_list, chan->remote_tx_win);
3250 	if (err < 0)
3251 		l2cap_seq_list_free(&chan->srej_list);
3252 
3253 	return err;
3254 }
3255 
3256 static inline __u8 l2cap_select_mode(__u8 mode, __u16 remote_feat_mask)
3257 {
3258 	switch (mode) {
3259 	case L2CAP_MODE_STREAMING:
3260 	case L2CAP_MODE_ERTM:
3261 		if (l2cap_mode_supported(mode, remote_feat_mask))
3262 			return mode;
3263 		fallthrough;
3264 	default:
3265 		return L2CAP_MODE_BASIC;
3266 	}
3267 }
3268 
3269 static inline bool __l2cap_ews_supported(struct l2cap_conn *conn)
3270 {
3271 	return (conn->feat_mask & L2CAP_FEAT_EXT_WINDOW);
3272 }
3273 
3274 static inline bool __l2cap_efs_supported(struct l2cap_conn *conn)
3275 {
3276 	return (conn->feat_mask & L2CAP_FEAT_EXT_FLOW);
3277 }
3278 
3279 static void __l2cap_set_ertm_timeouts(struct l2cap_chan *chan,
3280 				      struct l2cap_conf_rfc *rfc)
3281 {
3282 	rfc->retrans_timeout = cpu_to_le16(L2CAP_DEFAULT_RETRANS_TO);
3283 	rfc->monitor_timeout = cpu_to_le16(L2CAP_DEFAULT_MONITOR_TO);
3284 }
3285 
3286 static inline void l2cap_txwin_setup(struct l2cap_chan *chan)
3287 {
3288 	if (chan->tx_win > L2CAP_DEFAULT_TX_WINDOW &&
3289 	    __l2cap_ews_supported(chan->conn)) {
3290 		/* use extended control field */
3291 		set_bit(FLAG_EXT_CTRL, &chan->flags);
3292 		chan->tx_win_max = L2CAP_DEFAULT_EXT_WINDOW;
3293 	} else {
3294 		chan->tx_win = min_t(u16, chan->tx_win,
3295 				     L2CAP_DEFAULT_TX_WINDOW);
3296 		chan->tx_win_max = L2CAP_DEFAULT_TX_WINDOW;
3297 	}
3298 	chan->ack_win = chan->tx_win;
3299 }
3300 
3301 static void l2cap_mtu_auto(struct l2cap_chan *chan)
3302 {
3303 	struct hci_conn *conn = chan->conn->hcon;
3304 
3305 	chan->imtu = L2CAP_DEFAULT_MIN_MTU;
3306 
3307 	/* The 2-DH1 packet has between 2 and 56 information bytes
3308 	 * (including the 2-byte payload header)
3309 	 */
3310 	if (!(conn->pkt_type & HCI_2DH1))
3311 		chan->imtu = 54;
3312 
3313 	/* The 3-DH1 packet has between 2 and 85 information bytes
3314 	 * (including the 2-byte payload header)
3315 	 */
3316 	if (!(conn->pkt_type & HCI_3DH1))
3317 		chan->imtu = 83;
3318 
3319 	/* The 2-DH3 packet has between 2 and 369 information bytes
3320 	 * (including the 2-byte payload header)
3321 	 */
3322 	if (!(conn->pkt_type & HCI_2DH3))
3323 		chan->imtu = 367;
3324 
3325 	/* The 3-DH3 packet has between 2 and 554 information bytes
3326 	 * (including the 2-byte payload header)
3327 	 */
3328 	if (!(conn->pkt_type & HCI_3DH3))
3329 		chan->imtu = 552;
3330 
3331 	/* The 2-DH5 packet has between 2 and 681 information bytes
3332 	 * (including the 2-byte payload header)
3333 	 */
3334 	if (!(conn->pkt_type & HCI_2DH5))
3335 		chan->imtu = 679;
3336 
3337 	/* The 3-DH5 packet has between 2 and 1023 information bytes
3338 	 * (including the 2-byte payload header)
3339 	 */
3340 	if (!(conn->pkt_type & HCI_3DH5))
3341 		chan->imtu = 1021;
3342 }
3343 
3344 static int l2cap_build_conf_req(struct l2cap_chan *chan, void *data, size_t data_size)
3345 {
3346 	struct l2cap_conf_req *req = data;
3347 	struct l2cap_conf_rfc rfc = { .mode = chan->mode };
3348 	void *ptr = req->data;
3349 	void *endptr = data + data_size;
3350 	u16 size;
3351 
3352 	BT_DBG("chan %p", chan);
3353 
3354 	if (chan->num_conf_req || chan->num_conf_rsp)
3355 		goto done;
3356 
3357 	switch (chan->mode) {
3358 	case L2CAP_MODE_STREAMING:
3359 	case L2CAP_MODE_ERTM:
3360 		if (test_bit(CONF_STATE2_DEVICE, &chan->conf_state))
3361 			break;
3362 
3363 		if (__l2cap_efs_supported(chan->conn))
3364 			set_bit(FLAG_EFS_ENABLE, &chan->flags);
3365 
3366 		fallthrough;
3367 	default:
3368 		chan->mode = l2cap_select_mode(rfc.mode, chan->conn->feat_mask);
3369 		break;
3370 	}
3371 
3372 done:
3373 	if (chan->imtu != L2CAP_DEFAULT_MTU) {
3374 		if (!chan->imtu)
3375 			l2cap_mtu_auto(chan);
3376 		l2cap_add_conf_opt(&ptr, L2CAP_CONF_MTU, 2, chan->imtu,
3377 				   endptr - ptr);
3378 	}
3379 
3380 	switch (chan->mode) {
3381 	case L2CAP_MODE_BASIC:
3382 		if (disable_ertm)
3383 			break;
3384 
3385 		if (!(chan->conn->feat_mask & L2CAP_FEAT_ERTM) &&
3386 		    !(chan->conn->feat_mask & L2CAP_FEAT_STREAMING))
3387 			break;
3388 
3389 		rfc.mode            = L2CAP_MODE_BASIC;
3390 		rfc.txwin_size      = 0;
3391 		rfc.max_transmit    = 0;
3392 		rfc.retrans_timeout = 0;
3393 		rfc.monitor_timeout = 0;
3394 		rfc.max_pdu_size    = 0;
3395 
3396 		l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC, sizeof(rfc),
3397 				   (unsigned long) &rfc, endptr - ptr);
3398 		break;
3399 
3400 	case L2CAP_MODE_ERTM:
3401 		rfc.mode            = L2CAP_MODE_ERTM;
3402 		rfc.max_transmit    = chan->max_tx;
3403 
3404 		__l2cap_set_ertm_timeouts(chan, &rfc);
3405 
3406 		size = min_t(u16, L2CAP_DEFAULT_MAX_PDU_SIZE, chan->conn->mtu -
3407 			     L2CAP_EXT_HDR_SIZE - L2CAP_SDULEN_SIZE -
3408 			     L2CAP_FCS_SIZE);
3409 		rfc.max_pdu_size = cpu_to_le16(size);
3410 
3411 		l2cap_txwin_setup(chan);
3412 
3413 		rfc.txwin_size = min_t(u16, chan->tx_win,
3414 				       L2CAP_DEFAULT_TX_WINDOW);
3415 
3416 		l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC, sizeof(rfc),
3417 				   (unsigned long) &rfc, endptr - ptr);
3418 
3419 		if (test_bit(FLAG_EFS_ENABLE, &chan->flags))
3420 			l2cap_add_opt_efs(&ptr, chan, endptr - ptr);
3421 
3422 		if (test_bit(FLAG_EXT_CTRL, &chan->flags))
3423 			l2cap_add_conf_opt(&ptr, L2CAP_CONF_EWS, 2,
3424 					   chan->tx_win, endptr - ptr);
3425 
3426 		if (chan->conn->feat_mask & L2CAP_FEAT_FCS)
3427 			if (chan->fcs == L2CAP_FCS_NONE ||
3428 			    test_bit(CONF_RECV_NO_FCS, &chan->conf_state)) {
3429 				chan->fcs = L2CAP_FCS_NONE;
3430 				l2cap_add_conf_opt(&ptr, L2CAP_CONF_FCS, 1,
3431 						   chan->fcs, endptr - ptr);
3432 			}
3433 		break;
3434 
3435 	case L2CAP_MODE_STREAMING:
3436 		l2cap_txwin_setup(chan);
3437 		rfc.mode            = L2CAP_MODE_STREAMING;
3438 		rfc.txwin_size      = 0;
3439 		rfc.max_transmit    = 0;
3440 		rfc.retrans_timeout = 0;
3441 		rfc.monitor_timeout = 0;
3442 
3443 		size = min_t(u16, L2CAP_DEFAULT_MAX_PDU_SIZE, chan->conn->mtu -
3444 			     L2CAP_EXT_HDR_SIZE - L2CAP_SDULEN_SIZE -
3445 			     L2CAP_FCS_SIZE);
3446 		rfc.max_pdu_size = cpu_to_le16(size);
3447 
3448 		l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC, sizeof(rfc),
3449 				   (unsigned long) &rfc, endptr - ptr);
3450 
3451 		if (test_bit(FLAG_EFS_ENABLE, &chan->flags))
3452 			l2cap_add_opt_efs(&ptr, chan, endptr - ptr);
3453 
3454 		if (chan->conn->feat_mask & L2CAP_FEAT_FCS)
3455 			if (chan->fcs == L2CAP_FCS_NONE ||
3456 			    test_bit(CONF_RECV_NO_FCS, &chan->conf_state)) {
3457 				chan->fcs = L2CAP_FCS_NONE;
3458 				l2cap_add_conf_opt(&ptr, L2CAP_CONF_FCS, 1,
3459 						   chan->fcs, endptr - ptr);
3460 			}
3461 		break;
3462 	}
3463 
3464 	req->dcid  = cpu_to_le16(chan->dcid);
3465 	req->flags = cpu_to_le16(0);
3466 
3467 	return ptr - data;
3468 }
3469 
3470 static int l2cap_parse_conf_req(struct l2cap_chan *chan, void *data, size_t data_size)
3471 {
3472 	struct l2cap_conf_rsp *rsp = data;
3473 	void *ptr = rsp->data;
3474 	void *endptr = data + data_size;
3475 	void *req = chan->conf_req;
3476 	void *req_end = req + chan->conf_len;
3477 	int len = chan->conf_len;
3478 	int type, hint, olen;
3479 	unsigned long val;
3480 	struct l2cap_conf_rfc rfc = { .mode = L2CAP_MODE_BASIC };
3481 	struct l2cap_conf_efs efs;
3482 	u8 remote_efs = 0;
3483 	u16 mtu = 0;
3484 	u16 result = L2CAP_CONF_SUCCESS;
3485 	u16 size;
3486 
3487 	BT_DBG("chan %p", chan);
3488 
3489 	while (len >= L2CAP_CONF_OPT_SIZE) {
3490 		int ret = l2cap_get_conf_opt(&req, req_end, &type, &olen, &val);
3491 
3492 		if (ret < 0)
3493 			break;
3494 		len -= ret;
3495 
3496 		hint  = type & L2CAP_CONF_HINT;
3497 		type &= L2CAP_CONF_MASK;
3498 
3499 		switch (type) {
3500 		case L2CAP_CONF_MTU:
3501 			if (olen != 2)
3502 				break;
3503 			mtu = val;
3504 			break;
3505 
3506 		case L2CAP_CONF_FLUSH_TO:
3507 			if (olen != 2)
3508 				break;
3509 			chan->flush_to = val;
3510 			break;
3511 
3512 		case L2CAP_CONF_QOS:
3513 			break;
3514 
3515 		case L2CAP_CONF_RFC:
3516 			if (olen != sizeof(rfc))
3517 				break;
3518 			memcpy(&rfc, (void *) val, olen);
3519 			break;
3520 
3521 		case L2CAP_CONF_FCS:
3522 			if (olen != 1)
3523 				break;
3524 			if (val == L2CAP_FCS_NONE)
3525 				set_bit(CONF_RECV_NO_FCS, &chan->conf_state);
3526 			break;
3527 
3528 		case L2CAP_CONF_EFS:
3529 			if (olen != sizeof(efs))
3530 				break;
3531 			remote_efs = 1;
3532 			memcpy(&efs, (void *) val, olen);
3533 			break;
3534 
3535 		case L2CAP_CONF_EWS:
3536 			if (olen != 2)
3537 				break;
3538 			return -ECONNREFUSED;
3539 
3540 		default:
3541 			if (hint)
3542 				break;
3543 			result = L2CAP_CONF_UNKNOWN;
3544 			l2cap_add_conf_opt(&ptr, (u8)type, sizeof(u8), type, endptr - ptr);
3545 			break;
3546 		}
3547 	}
3548 
3549 	if (chan->num_conf_rsp || chan->num_conf_req > 1)
3550 		goto done;
3551 
3552 	switch (chan->mode) {
3553 	case L2CAP_MODE_STREAMING:
3554 	case L2CAP_MODE_ERTM:
3555 		if (!test_bit(CONF_STATE2_DEVICE, &chan->conf_state)) {
3556 			chan->mode = l2cap_select_mode(rfc.mode,
3557 						       chan->conn->feat_mask);
3558 			break;
3559 		}
3560 
3561 		if (remote_efs) {
3562 			if (__l2cap_efs_supported(chan->conn))
3563 				set_bit(FLAG_EFS_ENABLE, &chan->flags);
3564 			else
3565 				return -ECONNREFUSED;
3566 		}
3567 
3568 		if (chan->mode != rfc.mode)
3569 			return -ECONNREFUSED;
3570 
3571 		break;
3572 	}
3573 
3574 done:
3575 	if (chan->mode != rfc.mode) {
3576 		result = L2CAP_CONF_UNACCEPT;
3577 		rfc.mode = chan->mode;
3578 
3579 		if (chan->num_conf_rsp == 1)
3580 			return -ECONNREFUSED;
3581 
3582 		l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC, sizeof(rfc),
3583 				   (unsigned long) &rfc, endptr - ptr);
3584 	}
3585 
3586 	if (result == L2CAP_CONF_SUCCESS) {
3587 		/* Configure output options and let the other side know
3588 		 * which ones we don't like. */
3589 
3590 		/* If MTU is not provided in configure request, try adjusting it
3591 		 * to the current output MTU if it has been set
3592 		 *
3593 		 * Bluetooth Core 6.1, Vol 3, Part A, Section 4.5
3594 		 *
3595 		 * Each configuration parameter value (if any is present) in an
3596 		 * L2CAP_CONFIGURATION_RSP packet reflects an ‘adjustment’ to a
3597 		 * configuration parameter value that has been sent (or, in case
3598 		 * of default values, implied) in the corresponding
3599 		 * L2CAP_CONFIGURATION_REQ packet.
3600 		 */
3601 		if (!mtu) {
3602 			/* Only adjust for ERTM channels as for older modes the
3603 			 * remote stack may not be able to detect that the
3604 			 * adjustment causing it to silently drop packets.
3605 			 */
3606 			if (chan->mode == L2CAP_MODE_ERTM &&
3607 			    chan->omtu && chan->omtu != L2CAP_DEFAULT_MTU)
3608 				mtu = chan->omtu;
3609 			else
3610 				mtu = L2CAP_DEFAULT_MTU;
3611 		}
3612 
3613 		if (mtu < L2CAP_DEFAULT_MIN_MTU)
3614 			result = L2CAP_CONF_UNACCEPT;
3615 		else {
3616 			chan->omtu = mtu;
3617 			set_bit(CONF_MTU_DONE, &chan->conf_state);
3618 		}
3619 		l2cap_add_conf_opt(&ptr, L2CAP_CONF_MTU, 2, chan->omtu, endptr - ptr);
3620 
3621 		if (remote_efs) {
3622 			if (chan->local_stype != L2CAP_SERV_NOTRAFIC &&
3623 			    efs.stype != L2CAP_SERV_NOTRAFIC &&
3624 			    efs.stype != chan->local_stype) {
3625 
3626 				result = L2CAP_CONF_UNACCEPT;
3627 
3628 				if (chan->num_conf_req >= 1)
3629 					return -ECONNREFUSED;
3630 
3631 				l2cap_add_conf_opt(&ptr, L2CAP_CONF_EFS,
3632 						   sizeof(efs),
3633 						   (unsigned long) &efs, endptr - ptr);
3634 			} else {
3635 				/* Send PENDING Conf Rsp */
3636 				result = L2CAP_CONF_PENDING;
3637 				set_bit(CONF_LOC_CONF_PEND, &chan->conf_state);
3638 			}
3639 		}
3640 
3641 		switch (rfc.mode) {
3642 		case L2CAP_MODE_BASIC:
3643 			chan->fcs = L2CAP_FCS_NONE;
3644 			set_bit(CONF_MODE_DONE, &chan->conf_state);
3645 			break;
3646 
3647 		case L2CAP_MODE_ERTM:
3648 			if (!test_bit(CONF_EWS_RECV, &chan->conf_state))
3649 				chan->remote_tx_win = rfc.txwin_size;
3650 			else
3651 				rfc.txwin_size = L2CAP_DEFAULT_TX_WINDOW;
3652 
3653 			chan->remote_max_tx = rfc.max_transmit;
3654 
3655 			size = min_t(u16, le16_to_cpu(rfc.max_pdu_size),
3656 				     chan->conn->mtu - L2CAP_EXT_HDR_SIZE -
3657 				     L2CAP_SDULEN_SIZE - L2CAP_FCS_SIZE);
3658 			rfc.max_pdu_size = cpu_to_le16(size);
3659 			chan->remote_mps = size;
3660 
3661 			__l2cap_set_ertm_timeouts(chan, &rfc);
3662 
3663 			set_bit(CONF_MODE_DONE, &chan->conf_state);
3664 
3665 			l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC,
3666 					   sizeof(rfc), (unsigned long) &rfc, endptr - ptr);
3667 
3668 			if (remote_efs &&
3669 			    test_bit(FLAG_EFS_ENABLE, &chan->flags)) {
3670 				chan->remote_id = efs.id;
3671 				chan->remote_stype = efs.stype;
3672 				chan->remote_msdu = le16_to_cpu(efs.msdu);
3673 				chan->remote_flush_to =
3674 					le32_to_cpu(efs.flush_to);
3675 				chan->remote_acc_lat =
3676 					le32_to_cpu(efs.acc_lat);
3677 				chan->remote_sdu_itime =
3678 					le32_to_cpu(efs.sdu_itime);
3679 				l2cap_add_conf_opt(&ptr, L2CAP_CONF_EFS,
3680 						   sizeof(efs),
3681 						   (unsigned long) &efs, endptr - ptr);
3682 			}
3683 			break;
3684 
3685 		case L2CAP_MODE_STREAMING:
3686 			size = min_t(u16, le16_to_cpu(rfc.max_pdu_size),
3687 				     chan->conn->mtu - L2CAP_EXT_HDR_SIZE -
3688 				     L2CAP_SDULEN_SIZE - L2CAP_FCS_SIZE);
3689 			rfc.max_pdu_size = cpu_to_le16(size);
3690 			chan->remote_mps = size;
3691 
3692 			set_bit(CONF_MODE_DONE, &chan->conf_state);
3693 
3694 			l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC, sizeof(rfc),
3695 					   (unsigned long) &rfc, endptr - ptr);
3696 
3697 			break;
3698 
3699 		default:
3700 			result = L2CAP_CONF_UNACCEPT;
3701 
3702 			memset(&rfc, 0, sizeof(rfc));
3703 			rfc.mode = chan->mode;
3704 		}
3705 
3706 		if (result == L2CAP_CONF_SUCCESS)
3707 			set_bit(CONF_OUTPUT_DONE, &chan->conf_state);
3708 	}
3709 	rsp->scid   = cpu_to_le16(chan->dcid);
3710 	rsp->result = cpu_to_le16(result);
3711 	rsp->flags  = cpu_to_le16(0);
3712 
3713 	return ptr - data;
3714 }
3715 
3716 static int l2cap_parse_conf_rsp(struct l2cap_chan *chan, void *rsp, int len,
3717 				void *data, size_t size, u16 *result)
3718 {
3719 	struct l2cap_conf_req *req = data;
3720 	void *ptr = req->data;
3721 	void *endptr = data + size;
3722 	void *rsp_end = rsp + len;
3723 	int type, olen;
3724 	unsigned long val;
3725 	struct l2cap_conf_rfc rfc = { .mode = L2CAP_MODE_BASIC };
3726 	struct l2cap_conf_efs efs;
3727 
3728 	BT_DBG("chan %p, rsp %p, len %d, req %p", chan, rsp, len, data);
3729 
3730 	while (len >= L2CAP_CONF_OPT_SIZE) {
3731 		int ret = l2cap_get_conf_opt(&rsp, rsp_end, &type, &olen, &val);
3732 
3733 		if (ret < 0)
3734 			break;
3735 		len -= ret;
3736 
3737 		switch (type) {
3738 		case L2CAP_CONF_MTU:
3739 			if (olen != 2)
3740 				break;
3741 			if (val < L2CAP_DEFAULT_MIN_MTU) {
3742 				*result = L2CAP_CONF_UNACCEPT;
3743 				chan->imtu = L2CAP_DEFAULT_MIN_MTU;
3744 			} else
3745 				chan->imtu = val;
3746 			l2cap_add_conf_opt(&ptr, L2CAP_CONF_MTU, 2, chan->imtu,
3747 					   endptr - ptr);
3748 			break;
3749 
3750 		case L2CAP_CONF_FLUSH_TO:
3751 			if (olen != 2)
3752 				break;
3753 			chan->flush_to = val;
3754 			l2cap_add_conf_opt(&ptr, L2CAP_CONF_FLUSH_TO, 2,
3755 					   chan->flush_to, endptr - ptr);
3756 			break;
3757 
3758 		case L2CAP_CONF_RFC:
3759 			if (olen != sizeof(rfc))
3760 				break;
3761 			memcpy(&rfc, (void *)val, olen);
3762 			if (test_bit(CONF_STATE2_DEVICE, &chan->conf_state) &&
3763 			    rfc.mode != chan->mode)
3764 				return -ECONNREFUSED;
3765 			chan->fcs = 0;
3766 			l2cap_add_conf_opt(&ptr, L2CAP_CONF_RFC, sizeof(rfc),
3767 					   (unsigned long) &rfc, endptr - ptr);
3768 			break;
3769 
3770 		case L2CAP_CONF_EWS:
3771 			if (olen != 2)
3772 				break;
3773 			chan->ack_win = min_t(u16, val, chan->ack_win);
3774 			l2cap_add_conf_opt(&ptr, L2CAP_CONF_EWS, 2,
3775 					   chan->tx_win, endptr - ptr);
3776 			break;
3777 
3778 		case L2CAP_CONF_EFS:
3779 			if (olen != sizeof(efs))
3780 				break;
3781 			memcpy(&efs, (void *)val, olen);
3782 			if (chan->local_stype != L2CAP_SERV_NOTRAFIC &&
3783 			    efs.stype != L2CAP_SERV_NOTRAFIC &&
3784 			    efs.stype != chan->local_stype)
3785 				return -ECONNREFUSED;
3786 			l2cap_add_conf_opt(&ptr, L2CAP_CONF_EFS, sizeof(efs),
3787 					   (unsigned long) &efs, endptr - ptr);
3788 			break;
3789 
3790 		case L2CAP_CONF_FCS:
3791 			if (olen != 1)
3792 				break;
3793 			if (*result == L2CAP_CONF_PENDING)
3794 				if (val == L2CAP_FCS_NONE)
3795 					set_bit(CONF_RECV_NO_FCS,
3796 						&chan->conf_state);
3797 			break;
3798 		}
3799 	}
3800 
3801 	if (chan->mode == L2CAP_MODE_BASIC && chan->mode != rfc.mode)
3802 		return -ECONNREFUSED;
3803 
3804 	chan->mode = rfc.mode;
3805 
3806 	if (*result == L2CAP_CONF_SUCCESS || *result == L2CAP_CONF_PENDING) {
3807 		switch (rfc.mode) {
3808 		case L2CAP_MODE_ERTM:
3809 			chan->retrans_timeout = le16_to_cpu(rfc.retrans_timeout);
3810 			chan->monitor_timeout = le16_to_cpu(rfc.monitor_timeout);
3811 			chan->mps    = le16_to_cpu(rfc.max_pdu_size);
3812 			if (!test_bit(FLAG_EXT_CTRL, &chan->flags))
3813 				chan->ack_win = min_t(u16, chan->ack_win,
3814 						      rfc.txwin_size);
3815 
3816 			if (test_bit(FLAG_EFS_ENABLE, &chan->flags)) {
3817 				chan->local_msdu = le16_to_cpu(efs.msdu);
3818 				chan->local_sdu_itime =
3819 					le32_to_cpu(efs.sdu_itime);
3820 				chan->local_acc_lat = le32_to_cpu(efs.acc_lat);
3821 				chan->local_flush_to =
3822 					le32_to_cpu(efs.flush_to);
3823 			}
3824 			break;
3825 
3826 		case L2CAP_MODE_STREAMING:
3827 			chan->mps    = le16_to_cpu(rfc.max_pdu_size);
3828 		}
3829 	}
3830 
3831 	req->dcid   = cpu_to_le16(chan->dcid);
3832 	req->flags  = cpu_to_le16(0);
3833 
3834 	return ptr - data;
3835 }
3836 
3837 static int l2cap_build_conf_rsp(struct l2cap_chan *chan, void *data,
3838 				u16 result, u16 flags)
3839 {
3840 	struct l2cap_conf_rsp *rsp = data;
3841 	void *ptr = rsp->data;
3842 
3843 	BT_DBG("chan %p", chan);
3844 
3845 	rsp->scid   = cpu_to_le16(chan->dcid);
3846 	rsp->result = cpu_to_le16(result);
3847 	rsp->flags  = cpu_to_le16(flags);
3848 
3849 	return ptr - data;
3850 }
3851 
3852 void __l2cap_le_connect_rsp_defer(struct l2cap_chan *chan)
3853 {
3854 	struct l2cap_le_conn_rsp rsp;
3855 	struct l2cap_conn *conn = chan->conn;
3856 
3857 	BT_DBG("chan %p", chan);
3858 
3859 	rsp.dcid    = cpu_to_le16(chan->scid);
3860 	rsp.mtu     = cpu_to_le16(chan->imtu);
3861 	rsp.mps     = cpu_to_le16(chan->mps);
3862 	rsp.credits = cpu_to_le16(chan->rx_credits);
3863 	rsp.result  = cpu_to_le16(L2CAP_CR_LE_SUCCESS);
3864 
3865 	l2cap_send_cmd(conn, chan->ident, L2CAP_LE_CONN_RSP, sizeof(rsp),
3866 		       &rsp);
3867 }
3868 
3869 static void l2cap_ecred_list_defer(struct l2cap_chan *chan, void *data)
3870 {
3871 	int *result = data;
3872 
3873 	if (*result || test_bit(FLAG_ECRED_CONN_REQ_SENT, &chan->flags))
3874 		return;
3875 
3876 	switch (chan->state) {
3877 	case BT_CONNECT2:
3878 		/* If channel still pending accept add to result */
3879 		(*result)++;
3880 		return;
3881 	case BT_CONNECTED:
3882 		return;
3883 	default:
3884 		/* If not connected or pending accept it has been refused */
3885 		*result = -ECONNREFUSED;
3886 		return;
3887 	}
3888 }
3889 
3890 struct l2cap_ecred_rsp_data {
3891 	struct {
3892 		struct l2cap_ecred_conn_rsp_hdr rsp;
3893 		__le16 scid[L2CAP_ECRED_MAX_CID];
3894 	} __packed pdu;
3895 	int count;
3896 };
3897 
3898 static void l2cap_ecred_rsp_defer(struct l2cap_chan *chan, void *data)
3899 {
3900 	struct l2cap_ecred_rsp_data *rsp = data;
3901 	struct l2cap_ecred_conn_rsp *rsp_flex =
3902 		container_of(&rsp->pdu.rsp, struct l2cap_ecred_conn_rsp, hdr);
3903 
3904 	if (chan->mode != L2CAP_MODE_EXT_FLOWCTL)
3905 		return;
3906 
3907 	/* Check if channel for outgoing connection or if it wasn't deferred
3908 	 * since in those cases it must be skipped.
3909 	 */
3910 	if (test_bit(FLAG_ECRED_CONN_REQ_SENT, &chan->flags) ||
3911 	    !test_and_clear_bit(FLAG_DEFER_SETUP, &chan->flags))
3912 		return;
3913 
3914 	/* Reset ident so only one response is sent */
3915 	chan->ident = 0;
3916 
3917 	/* Unreachable, check in l2cap_ecred_conn_req. If reached, drop rest */
3918 	if (WARN_ON_ONCE(rsp->count >= ARRAY_SIZE(rsp->pdu.scid)))
3919 		rsp->pdu.rsp.result = cpu_to_le16(L2CAP_CR_LE_NO_MEM);
3920 
3921 	/* Include all channels pending with the same ident */
3922 	if (!rsp->pdu.rsp.result)
3923 		rsp_flex->dcid[rsp->count++] = cpu_to_le16(chan->scid);
3924 	else
3925 		l2cap_chan_del(chan, ECONNRESET);
3926 }
3927 
3928 void __l2cap_ecred_conn_rsp_defer(struct l2cap_chan *chan)
3929 {
3930 	struct l2cap_conn *conn = chan->conn;
3931 	struct l2cap_ecred_rsp_data data;
3932 	u16 id = chan->ident;
3933 	int result = 0;
3934 
3935 	if (!id)
3936 		return;
3937 
3938 	BT_DBG("chan %p id %d", chan, id);
3939 
3940 	memset(&data, 0, sizeof(data));
3941 
3942 	data.pdu.rsp.mtu     = cpu_to_le16(chan->imtu);
3943 	data.pdu.rsp.mps     = cpu_to_le16(chan->mps);
3944 	data.pdu.rsp.credits = cpu_to_le16(chan->rx_credits);
3945 	data.pdu.rsp.result  = cpu_to_le16(L2CAP_CR_LE_SUCCESS);
3946 
3947 	/* Verify that all channels are ready */
3948 	__l2cap_chan_list_id(conn, id, l2cap_ecred_list_defer, &result);
3949 
3950 	if (result > 0)
3951 		return;
3952 
3953 	if (result < 0)
3954 		data.pdu.rsp.result = cpu_to_le16(L2CAP_CR_LE_AUTHORIZATION);
3955 
3956 	/* Build response */
3957 	__l2cap_chan_list_id(conn, id, l2cap_ecred_rsp_defer, &data);
3958 
3959 	l2cap_send_cmd(conn, id, L2CAP_ECRED_CONN_RSP,
3960 		       sizeof(data.pdu.rsp) + (data.count * sizeof(__le16)),
3961 		       &data.pdu);
3962 }
3963 
3964 void __l2cap_connect_rsp_defer(struct l2cap_chan *chan)
3965 {
3966 	struct l2cap_conn_rsp rsp;
3967 	struct l2cap_conn *conn = chan->conn;
3968 	u8 buf[128];
3969 	u8 rsp_code;
3970 
3971 	rsp.scid   = cpu_to_le16(chan->dcid);
3972 	rsp.dcid   = cpu_to_le16(chan->scid);
3973 	rsp.result = cpu_to_le16(L2CAP_CR_SUCCESS);
3974 	rsp.status = cpu_to_le16(L2CAP_CS_NO_INFO);
3975 	rsp_code = L2CAP_CONN_RSP;
3976 
3977 	BT_DBG("chan %p rsp_code %u", chan, rsp_code);
3978 
3979 	l2cap_send_cmd(conn, chan->ident, rsp_code, sizeof(rsp), &rsp);
3980 
3981 	if (test_and_set_bit(CONF_REQ_SENT, &chan->conf_state))
3982 		return;
3983 
3984 	l2cap_send_cmd(conn, l2cap_get_ident(conn), L2CAP_CONF_REQ,
3985 		       l2cap_build_conf_req(chan, buf, sizeof(buf)), buf);
3986 	chan->num_conf_req++;
3987 }
3988 
3989 static void l2cap_conf_rfc_get(struct l2cap_chan *chan, void *rsp, int len)
3990 {
3991 	int type, olen;
3992 	unsigned long val;
3993 	void *rsp_end = rsp + len;
3994 	/* Use sane default values in case a misbehaving remote device
3995 	 * did not send an RFC or extended window size option.
3996 	 */
3997 	u16 txwin_ext = chan->ack_win;
3998 	struct l2cap_conf_rfc rfc = {
3999 		.mode = chan->mode,
4000 		.retrans_timeout = cpu_to_le16(L2CAP_DEFAULT_RETRANS_TO),
4001 		.monitor_timeout = cpu_to_le16(L2CAP_DEFAULT_MONITOR_TO),
4002 		.max_pdu_size = cpu_to_le16(chan->imtu),
4003 		.txwin_size = min_t(u16, chan->ack_win, L2CAP_DEFAULT_TX_WINDOW),
4004 	};
4005 
4006 	BT_DBG("chan %p, rsp %p, len %d", chan, rsp, len);
4007 
4008 	if ((chan->mode != L2CAP_MODE_ERTM) && (chan->mode != L2CAP_MODE_STREAMING))
4009 		return;
4010 
4011 	while (len >= L2CAP_CONF_OPT_SIZE) {
4012 		int ret = l2cap_get_conf_opt(&rsp, rsp_end, &type, &olen, &val);
4013 
4014 		if (ret < 0)
4015 			break;
4016 		len -= ret;
4017 
4018 		switch (type) {
4019 		case L2CAP_CONF_RFC:
4020 			if (olen != sizeof(rfc))
4021 				break;
4022 			memcpy(&rfc, (void *)val, olen);
4023 			break;
4024 		case L2CAP_CONF_EWS:
4025 			if (olen != 2)
4026 				break;
4027 			txwin_ext = val;
4028 			break;
4029 		}
4030 	}
4031 
4032 	switch (rfc.mode) {
4033 	case L2CAP_MODE_ERTM:
4034 		chan->retrans_timeout = le16_to_cpu(rfc.retrans_timeout);
4035 		chan->monitor_timeout = le16_to_cpu(rfc.monitor_timeout);
4036 		chan->mps = le16_to_cpu(rfc.max_pdu_size);
4037 		if (test_bit(FLAG_EXT_CTRL, &chan->flags))
4038 			chan->ack_win = min_t(u16, chan->ack_win, txwin_ext);
4039 		else
4040 			chan->ack_win = min_t(u16, chan->ack_win,
4041 					      rfc.txwin_size);
4042 		break;
4043 	case L2CAP_MODE_STREAMING:
4044 		chan->mps    = le16_to_cpu(rfc.max_pdu_size);
4045 	}
4046 }
4047 
4048 static inline int l2cap_command_rej(struct l2cap_conn *conn,
4049 				    struct l2cap_cmd_hdr *cmd, u16 cmd_len,
4050 				    u8 *data)
4051 {
4052 	struct l2cap_cmd_rej_unk *rej = (struct l2cap_cmd_rej_unk *) data;
4053 
4054 	if (cmd_len < sizeof(*rej))
4055 		return -EPROTO;
4056 
4057 	if (rej->reason != L2CAP_REJ_NOT_UNDERSTOOD)
4058 		return 0;
4059 
4060 	if ((conn->info_state & L2CAP_INFO_FEAT_MASK_REQ_SENT) &&
4061 	    cmd->ident == conn->info_ident) {
4062 		cancel_delayed_work(&conn->info_timer);
4063 
4064 		conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_DONE;
4065 		conn->info_ident = 0;
4066 
4067 		l2cap_conn_start(conn);
4068 	}
4069 
4070 	return 0;
4071 }
4072 
4073 /* Allocate and initialise a channel for an incoming connection.
4074  *
4075  * The channel inherits its configuration from @pchan and is linked into @conn
4076  * before ->new_connection() runs, so the conn list reference keeps it alive if
4077  * the callback exposes it (e.g. via the socket accept queue) before this
4078  * returns. The l2cap_chan_create() reference is taken over by the subsystem on
4079  * success and dropped here on failure.
4080  */
4081 static struct l2cap_chan *l2cap_new_connection(struct l2cap_conn *conn,
4082 					       struct l2cap_chan *pchan)
4083 {
4084 	struct l2cap_chan *chan;
4085 
4086 	chan = l2cap_chan_create();
4087 	if (!chan)
4088 		return NULL;
4089 
4090 	l2cap_chan_set_defaults(chan, pchan);
4091 	chan->ops = pchan->ops;
4092 
4093 	__l2cap_chan_add(conn, chan);
4094 
4095 	if (pchan->ops->new_connection &&
4096 	    pchan->ops->new_connection(pchan, chan) < 0) {
4097 		l2cap_chan_del(chan, 0);
4098 		l2cap_chan_put(chan);
4099 		return NULL;
4100 	}
4101 
4102 	return chan;
4103 }
4104 
4105 static void l2cap_connect(struct l2cap_conn *conn, struct l2cap_cmd_hdr *cmd,
4106 			  u8 *data, u8 rsp_code)
4107 {
4108 	struct l2cap_conn_req *req = (struct l2cap_conn_req *) data;
4109 	struct l2cap_conn_rsp rsp;
4110 	struct l2cap_chan *chan = NULL, *pchan = NULL;
4111 	int result, status = L2CAP_CS_NO_INFO;
4112 
4113 	u16 dcid = 0, scid = __le16_to_cpu(req->scid);
4114 	__le16 psm = req->psm;
4115 
4116 	BT_DBG("psm 0x%2.2x scid 0x%4.4x", __le16_to_cpu(psm), scid);
4117 
4118 	/* Check if we have socket listening on psm */
4119 	pchan = l2cap_global_chan_by_psm(BT_LISTEN, psm, &conn->hcon->src,
4120 					 &conn->hcon->dst, ACL_LINK);
4121 	if (!pchan) {
4122 		result = L2CAP_CR_BAD_PSM;
4123 		goto response;
4124 	}
4125 
4126 	l2cap_chan_lock(pchan);
4127 
4128 	/* Check if the ACL is secure enough (if not SDP) */
4129 	if (psm != cpu_to_le16(L2CAP_PSM_SDP) &&
4130 	    (!hci_conn_check_link_mode(conn->hcon) ||
4131 	    !l2cap_check_enc_key_size(conn->hcon, pchan))) {
4132 		conn->disc_reason = HCI_ERROR_AUTH_FAILURE;
4133 		result = L2CAP_CR_SEC_BLOCK;
4134 		goto response;
4135 	}
4136 
4137 	result = L2CAP_CR_NO_MEM;
4138 
4139 	/* Check for valid dynamic CID range (as per Erratum 3253) */
4140 	if (scid < L2CAP_CID_DYN_START || scid > L2CAP_CID_DYN_END) {
4141 		result = L2CAP_CR_INVALID_SCID;
4142 		goto response;
4143 	}
4144 
4145 	/* Check if we already have channel with that dcid */
4146 	if (__l2cap_get_chan_by_dcid(conn, scid)) {
4147 		result = L2CAP_CR_SCID_IN_USE;
4148 		goto response;
4149 	}
4150 
4151 	chan = l2cap_new_connection(conn, pchan);
4152 	if (!chan)
4153 		goto response;
4154 
4155 	/* For certain devices (ex: HID mouse), support for authentication,
4156 	 * pairing and bonding is optional. For such devices, inorder to avoid
4157 	 * the ACL alive for too long after L2CAP disconnection, reset the ACL
4158 	 * disc_timeout back to HCI_DISCONN_TIMEOUT during L2CAP connect.
4159 	 */
4160 	conn->hcon->disc_timeout = HCI_DISCONN_TIMEOUT;
4161 
4162 	bacpy(&chan->src, &conn->hcon->src);
4163 	bacpy(&chan->dst, &conn->hcon->dst);
4164 	chan->src_type = bdaddr_src_type(conn->hcon);
4165 	chan->dst_type = bdaddr_dst_type(conn->hcon);
4166 	chan->psm  = psm;
4167 	chan->dcid = scid;
4168 
4169 	dcid = chan->scid;
4170 
4171 	__set_chan_timer(chan, chan->ops->get_sndtimeo(chan));
4172 
4173 	chan->ident = cmd->ident;
4174 
4175 	if (conn->info_state & L2CAP_INFO_FEAT_MASK_REQ_DONE) {
4176 		if (l2cap_chan_check_security(chan, false)) {
4177 			if (test_bit(FLAG_DEFER_SETUP, &chan->flags)) {
4178 				l2cap_state_change(chan, BT_CONNECT2);
4179 				result = L2CAP_CR_PEND;
4180 				status = L2CAP_CS_AUTHOR_PEND;
4181 				chan->ops->defer(chan);
4182 			} else {
4183 				l2cap_state_change(chan, BT_CONFIG);
4184 				result = L2CAP_CR_SUCCESS;
4185 				status = L2CAP_CS_NO_INFO;
4186 			}
4187 		} else {
4188 			l2cap_state_change(chan, BT_CONNECT2);
4189 			result = L2CAP_CR_PEND;
4190 			status = L2CAP_CS_AUTHEN_PEND;
4191 		}
4192 	} else {
4193 		l2cap_state_change(chan, BT_CONNECT2);
4194 		result = L2CAP_CR_PEND;
4195 		status = L2CAP_CS_NO_INFO;
4196 	}
4197 
4198 response:
4199 	rsp.scid   = cpu_to_le16(scid);
4200 	rsp.dcid   = cpu_to_le16(dcid);
4201 	rsp.result = cpu_to_le16(result);
4202 	rsp.status = cpu_to_le16(status);
4203 	l2cap_send_cmd(conn, cmd->ident, rsp_code, sizeof(rsp), &rsp);
4204 
4205 	if (!pchan)
4206 		return;
4207 
4208 	if (result == L2CAP_CR_PEND && status == L2CAP_CS_NO_INFO) {
4209 		struct l2cap_info_req info;
4210 		info.type = cpu_to_le16(L2CAP_IT_FEAT_MASK);
4211 
4212 		conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_SENT;
4213 		conn->info_ident = l2cap_get_ident(conn);
4214 
4215 		schedule_delayed_work(&conn->info_timer, L2CAP_INFO_TIMEOUT);
4216 
4217 		l2cap_send_cmd(conn, conn->info_ident, L2CAP_INFO_REQ,
4218 			       sizeof(info), &info);
4219 	}
4220 
4221 	if (chan && !test_bit(CONF_REQ_SENT, &chan->conf_state) &&
4222 	    result == L2CAP_CR_SUCCESS) {
4223 		u8 buf[128];
4224 		set_bit(CONF_REQ_SENT, &chan->conf_state);
4225 		l2cap_send_cmd(conn, l2cap_get_ident(conn), L2CAP_CONF_REQ,
4226 			       l2cap_build_conf_req(chan, buf, sizeof(buf)), buf);
4227 		chan->num_conf_req++;
4228 	}
4229 
4230 	l2cap_chan_unlock(pchan);
4231 	l2cap_chan_put(pchan);
4232 }
4233 
4234 static int l2cap_connect_req(struct l2cap_conn *conn,
4235 			     struct l2cap_cmd_hdr *cmd, u16 cmd_len, u8 *data)
4236 {
4237 	if (cmd_len < sizeof(struct l2cap_conn_req))
4238 		return -EPROTO;
4239 
4240 	l2cap_connect(conn, cmd, data, L2CAP_CONN_RSP);
4241 	return 0;
4242 }
4243 
4244 static int l2cap_connect_create_rsp(struct l2cap_conn *conn,
4245 				    struct l2cap_cmd_hdr *cmd, u16 cmd_len,
4246 				    u8 *data)
4247 {
4248 	struct l2cap_conn_rsp *rsp = (struct l2cap_conn_rsp *) data;
4249 	u16 scid, dcid, result, status;
4250 	struct l2cap_chan *chan;
4251 	u8 req[128];
4252 	int err;
4253 
4254 	if (cmd_len < sizeof(*rsp))
4255 		return -EPROTO;
4256 
4257 	scid   = __le16_to_cpu(rsp->scid);
4258 	dcid   = __le16_to_cpu(rsp->dcid);
4259 	result = __le16_to_cpu(rsp->result);
4260 	status = __le16_to_cpu(rsp->status);
4261 
4262 	if (result == L2CAP_CR_SUCCESS && (dcid < L2CAP_CID_DYN_START ||
4263 					   dcid > L2CAP_CID_DYN_END))
4264 		return -EPROTO;
4265 
4266 	BT_DBG("dcid 0x%4.4x scid 0x%4.4x result 0x%2.2x status 0x%2.2x",
4267 	       dcid, scid, result, status);
4268 
4269 	if (scid) {
4270 		chan = __l2cap_get_chan_by_scid(conn, scid);
4271 		if (!chan)
4272 			return -EBADSLT;
4273 	} else {
4274 		chan = __l2cap_get_chan_by_ident(conn, cmd->ident);
4275 		if (!chan)
4276 			return -EBADSLT;
4277 	}
4278 
4279 	chan = l2cap_chan_hold_unless_zero(chan);
4280 	if (!chan)
4281 		return -EBADSLT;
4282 
4283 	err = 0;
4284 
4285 	l2cap_chan_lock(chan);
4286 
4287 	switch (result) {
4288 	case L2CAP_CR_SUCCESS:
4289 		if (__l2cap_get_chan_by_dcid(conn, dcid)) {
4290 			err = -EBADSLT;
4291 			break;
4292 		}
4293 
4294 		l2cap_state_change(chan, BT_CONFIG);
4295 		chan->ident = 0;
4296 		chan->dcid = dcid;
4297 		clear_bit(CONF_CONNECT_PEND, &chan->conf_state);
4298 
4299 		if (test_and_set_bit(CONF_REQ_SENT, &chan->conf_state))
4300 			break;
4301 
4302 		l2cap_send_cmd(conn, l2cap_get_ident(conn), L2CAP_CONF_REQ,
4303 			       l2cap_build_conf_req(chan, req, sizeof(req)), req);
4304 		chan->num_conf_req++;
4305 		break;
4306 
4307 	case L2CAP_CR_PEND:
4308 		set_bit(CONF_CONNECT_PEND, &chan->conf_state);
4309 		break;
4310 
4311 	default:
4312 		l2cap_chan_del(chan, ECONNREFUSED);
4313 		break;
4314 	}
4315 
4316 	l2cap_chan_unlock(chan);
4317 	l2cap_chan_put(chan);
4318 
4319 	return err;
4320 }
4321 
4322 static inline void set_default_fcs(struct l2cap_chan *chan)
4323 {
4324 	/* FCS is enabled only in ERTM or streaming mode, if one or both
4325 	 * sides request it.
4326 	 */
4327 	if (chan->mode != L2CAP_MODE_ERTM && chan->mode != L2CAP_MODE_STREAMING)
4328 		chan->fcs = L2CAP_FCS_NONE;
4329 	else if (!test_bit(CONF_RECV_NO_FCS, &chan->conf_state))
4330 		chan->fcs = L2CAP_FCS_CRC16;
4331 }
4332 
4333 static void l2cap_send_efs_conf_rsp(struct l2cap_chan *chan, void *data,
4334 				    u8 ident, u16 flags)
4335 {
4336 	struct l2cap_conn *conn = chan->conn;
4337 
4338 	BT_DBG("conn %p chan %p ident %d flags 0x%4.4x", conn, chan, ident,
4339 	       flags);
4340 
4341 	clear_bit(CONF_LOC_CONF_PEND, &chan->conf_state);
4342 	set_bit(CONF_OUTPUT_DONE, &chan->conf_state);
4343 
4344 	l2cap_send_cmd(conn, ident, L2CAP_CONF_RSP,
4345 		       l2cap_build_conf_rsp(chan, data,
4346 					    L2CAP_CONF_SUCCESS, flags), data);
4347 }
4348 
4349 static void cmd_reject_invalid_cid(struct l2cap_conn *conn, u8 ident,
4350 				   u16 scid, u16 dcid)
4351 {
4352 	struct l2cap_cmd_rej_cid rej;
4353 
4354 	rej.reason = cpu_to_le16(L2CAP_REJ_INVALID_CID);
4355 	rej.scid = __cpu_to_le16(scid);
4356 	rej.dcid = __cpu_to_le16(dcid);
4357 
4358 	l2cap_send_cmd(conn, ident, L2CAP_COMMAND_REJ, sizeof(rej), &rej);
4359 }
4360 
4361 static inline int l2cap_config_req(struct l2cap_conn *conn,
4362 				   struct l2cap_cmd_hdr *cmd, u16 cmd_len,
4363 				   u8 *data)
4364 {
4365 	struct l2cap_conf_req *req = (struct l2cap_conf_req *) data;
4366 	u16 dcid, flags;
4367 	u8 rsp[64];
4368 	struct l2cap_chan *chan;
4369 	int len, err = 0;
4370 
4371 	if (cmd_len < sizeof(*req))
4372 		return -EPROTO;
4373 
4374 	dcid  = __le16_to_cpu(req->dcid);
4375 	flags = __le16_to_cpu(req->flags);
4376 
4377 	BT_DBG("dcid 0x%4.4x flags 0x%2.2x", dcid, flags);
4378 
4379 	chan = l2cap_get_chan_by_scid(conn, dcid);
4380 	if (!chan) {
4381 		cmd_reject_invalid_cid(conn, cmd->ident, dcid, 0);
4382 		return 0;
4383 	}
4384 
4385 	if (chan->state != BT_CONFIG && chan->state != BT_CONNECT2 &&
4386 	    chan->state != BT_CONNECTED) {
4387 		cmd_reject_invalid_cid(conn, cmd->ident, chan->scid,
4388 				       chan->dcid);
4389 		goto unlock;
4390 	}
4391 
4392 	/* Reject if config buffer is too small. */
4393 	len = cmd_len - sizeof(*req);
4394 	if (chan->conf_len + len > sizeof(chan->conf_req)) {
4395 		l2cap_send_cmd(conn, cmd->ident, L2CAP_CONF_RSP,
4396 			       l2cap_build_conf_rsp(chan, rsp,
4397 			       L2CAP_CONF_REJECT, flags), rsp);
4398 		goto unlock;
4399 	}
4400 
4401 	/* Store config. */
4402 	memcpy(chan->conf_req + chan->conf_len, req->data, len);
4403 	chan->conf_len += len;
4404 
4405 	if (flags & L2CAP_CONF_FLAG_CONTINUATION) {
4406 		/* Incomplete config. Send empty response. */
4407 		l2cap_send_cmd(conn, cmd->ident, L2CAP_CONF_RSP,
4408 			       l2cap_build_conf_rsp(chan, rsp,
4409 			       L2CAP_CONF_SUCCESS, flags), rsp);
4410 		goto unlock;
4411 	}
4412 
4413 	/* Complete config. */
4414 	len = l2cap_parse_conf_req(chan, rsp, sizeof(rsp));
4415 	if (len < 0) {
4416 		l2cap_send_disconn_req(chan, ECONNRESET);
4417 		goto unlock;
4418 	}
4419 
4420 	chan->ident = cmd->ident;
4421 	l2cap_send_cmd(conn, cmd->ident, L2CAP_CONF_RSP, len, rsp);
4422 	if (chan->num_conf_rsp < L2CAP_CONF_MAX_CONF_RSP)
4423 		chan->num_conf_rsp++;
4424 
4425 	/* Reset config buffer. */
4426 	chan->conf_len = 0;
4427 
4428 	if (!test_bit(CONF_OUTPUT_DONE, &chan->conf_state))
4429 		goto unlock;
4430 
4431 	if (test_bit(CONF_INPUT_DONE, &chan->conf_state)) {
4432 		set_default_fcs(chan);
4433 
4434 		if (chan->state != BT_CONNECTED) {
4435 			if (chan->mode == L2CAP_MODE_ERTM ||
4436 			    chan->mode == L2CAP_MODE_STREAMING)
4437 				err = l2cap_ertm_init(chan);
4438 
4439 			if (err < 0)
4440 				l2cap_send_disconn_req(chan, -err);
4441 			else
4442 				l2cap_chan_ready(chan);
4443 		}
4444 
4445 		goto unlock;
4446 	}
4447 
4448 	if (!test_and_set_bit(CONF_REQ_SENT, &chan->conf_state)) {
4449 		u8 buf[64];
4450 		l2cap_send_cmd(conn, l2cap_get_ident(conn), L2CAP_CONF_REQ,
4451 			       l2cap_build_conf_req(chan, buf, sizeof(buf)), buf);
4452 		chan->num_conf_req++;
4453 	}
4454 
4455 	/* Got Conf Rsp PENDING from remote side and assume we sent
4456 	   Conf Rsp PENDING in the code above */
4457 	if (test_bit(CONF_REM_CONF_PEND, &chan->conf_state) &&
4458 	    test_bit(CONF_LOC_CONF_PEND, &chan->conf_state)) {
4459 
4460 		/* check compatibility */
4461 
4462 		/* Send rsp for BR/EDR channel */
4463 		l2cap_send_efs_conf_rsp(chan, rsp, cmd->ident, flags);
4464 	}
4465 
4466 unlock:
4467 	l2cap_chan_unlock(chan);
4468 	l2cap_chan_put(chan);
4469 	return err;
4470 }
4471 
4472 static inline int l2cap_config_rsp(struct l2cap_conn *conn,
4473 				   struct l2cap_cmd_hdr *cmd, u16 cmd_len,
4474 				   u8 *data)
4475 {
4476 	struct l2cap_conf_rsp *rsp = (struct l2cap_conf_rsp *)data;
4477 	u16 scid, flags, result;
4478 	struct l2cap_chan *chan;
4479 	int len = cmd_len - sizeof(*rsp);
4480 	int err = 0;
4481 
4482 	if (cmd_len < sizeof(*rsp))
4483 		return -EPROTO;
4484 
4485 	scid   = __le16_to_cpu(rsp->scid);
4486 	flags  = __le16_to_cpu(rsp->flags);
4487 	result = __le16_to_cpu(rsp->result);
4488 
4489 	BT_DBG("scid 0x%4.4x flags 0x%2.2x result 0x%2.2x len %d", scid, flags,
4490 	       result, len);
4491 
4492 	chan = l2cap_get_chan_by_scid(conn, scid);
4493 	if (!chan)
4494 		return 0;
4495 
4496 	switch (result) {
4497 	case L2CAP_CONF_SUCCESS:
4498 		l2cap_conf_rfc_get(chan, rsp->data, len);
4499 		clear_bit(CONF_REM_CONF_PEND, &chan->conf_state);
4500 		break;
4501 
4502 	case L2CAP_CONF_PENDING:
4503 		set_bit(CONF_REM_CONF_PEND, &chan->conf_state);
4504 
4505 		if (test_bit(CONF_LOC_CONF_PEND, &chan->conf_state)) {
4506 			char buf[64];
4507 
4508 			len = l2cap_parse_conf_rsp(chan, rsp->data, len,
4509 						   buf, sizeof(buf), &result);
4510 			if (len < 0) {
4511 				l2cap_send_disconn_req(chan, ECONNRESET);
4512 				goto done;
4513 			}
4514 
4515 			l2cap_send_efs_conf_rsp(chan, buf, cmd->ident, 0);
4516 		}
4517 		goto done;
4518 
4519 	case L2CAP_CONF_UNKNOWN:
4520 	case L2CAP_CONF_UNACCEPT:
4521 		if (chan->num_conf_rsp <= L2CAP_CONF_MAX_CONF_RSP) {
4522 			char req[64];
4523 
4524 			if (len > sizeof(req) - sizeof(struct l2cap_conf_req)) {
4525 				l2cap_send_disconn_req(chan, ECONNRESET);
4526 				goto done;
4527 			}
4528 
4529 			/* throw out any old stored conf requests */
4530 			result = L2CAP_CONF_SUCCESS;
4531 			len = l2cap_parse_conf_rsp(chan, rsp->data, len,
4532 						   req, sizeof(req), &result);
4533 			if (len < 0) {
4534 				l2cap_send_disconn_req(chan, ECONNRESET);
4535 				goto done;
4536 			}
4537 
4538 			l2cap_send_cmd(conn, l2cap_get_ident(conn),
4539 				       L2CAP_CONF_REQ, len, req);
4540 			chan->num_conf_req++;
4541 			if (result != L2CAP_CONF_SUCCESS)
4542 				goto done;
4543 			break;
4544 		}
4545 		fallthrough;
4546 
4547 	default:
4548 		l2cap_chan_set_err(chan, ECONNRESET);
4549 
4550 		__set_chan_timer(chan, L2CAP_DISC_REJ_TIMEOUT);
4551 		l2cap_send_disconn_req(chan, ECONNRESET);
4552 		goto done;
4553 	}
4554 
4555 	if (flags & L2CAP_CONF_FLAG_CONTINUATION)
4556 		goto done;
4557 
4558 	set_bit(CONF_INPUT_DONE, &chan->conf_state);
4559 
4560 	if (test_bit(CONF_OUTPUT_DONE, &chan->conf_state)) {
4561 		set_default_fcs(chan);
4562 
4563 		if (chan->mode == L2CAP_MODE_ERTM ||
4564 		    chan->mode == L2CAP_MODE_STREAMING)
4565 			err = l2cap_ertm_init(chan);
4566 
4567 		if (err < 0)
4568 			l2cap_send_disconn_req(chan, -err);
4569 		else
4570 			l2cap_chan_ready(chan);
4571 	}
4572 
4573 done:
4574 	l2cap_chan_unlock(chan);
4575 	l2cap_chan_put(chan);
4576 	return err;
4577 }
4578 
4579 static inline int l2cap_disconnect_req(struct l2cap_conn *conn,
4580 				       struct l2cap_cmd_hdr *cmd, u16 cmd_len,
4581 				       u8 *data)
4582 {
4583 	struct l2cap_disconn_req *req = (struct l2cap_disconn_req *) data;
4584 	struct l2cap_disconn_rsp rsp;
4585 	u16 dcid, scid;
4586 	struct l2cap_chan *chan;
4587 
4588 	if (cmd_len != sizeof(*req))
4589 		return -EPROTO;
4590 
4591 	scid = __le16_to_cpu(req->scid);
4592 	dcid = __le16_to_cpu(req->dcid);
4593 
4594 	BT_DBG("scid 0x%4.4x dcid 0x%4.4x", scid, dcid);
4595 
4596 	chan = l2cap_get_chan_by_scid(conn, dcid);
4597 	if (!chan) {
4598 		cmd_reject_invalid_cid(conn, cmd->ident, dcid, scid);
4599 		return 0;
4600 	}
4601 
4602 	rsp.dcid = cpu_to_le16(chan->scid);
4603 	rsp.scid = cpu_to_le16(chan->dcid);
4604 	l2cap_send_cmd(conn, cmd->ident, L2CAP_DISCONN_RSP, sizeof(rsp), &rsp);
4605 
4606 	chan->ops->set_shutdown(chan);
4607 
4608 	l2cap_chan_del(chan, ECONNRESET);
4609 
4610 	chan->ops->close(chan);
4611 
4612 	l2cap_chan_unlock(chan);
4613 	l2cap_chan_put(chan);
4614 
4615 	return 0;
4616 }
4617 
4618 static inline int l2cap_disconnect_rsp(struct l2cap_conn *conn,
4619 				       struct l2cap_cmd_hdr *cmd, u16 cmd_len,
4620 				       u8 *data)
4621 {
4622 	struct l2cap_disconn_rsp *rsp = (struct l2cap_disconn_rsp *) data;
4623 	u16 dcid, scid;
4624 	struct l2cap_chan *chan;
4625 
4626 	if (cmd_len != sizeof(*rsp))
4627 		return -EPROTO;
4628 
4629 	scid = __le16_to_cpu(rsp->scid);
4630 	dcid = __le16_to_cpu(rsp->dcid);
4631 
4632 	BT_DBG("dcid 0x%4.4x scid 0x%4.4x", dcid, scid);
4633 
4634 	chan = l2cap_get_chan_by_scid(conn, scid);
4635 	if (!chan) {
4636 		return 0;
4637 	}
4638 
4639 	if (chan->state != BT_DISCONN) {
4640 		l2cap_chan_unlock(chan);
4641 		l2cap_chan_put(chan);
4642 		return 0;
4643 	}
4644 
4645 	l2cap_chan_del(chan, 0);
4646 
4647 	chan->ops->close(chan);
4648 
4649 	l2cap_chan_unlock(chan);
4650 	l2cap_chan_put(chan);
4651 
4652 	return 0;
4653 }
4654 
4655 static inline int l2cap_information_req(struct l2cap_conn *conn,
4656 					struct l2cap_cmd_hdr *cmd, u16 cmd_len,
4657 					u8 *data)
4658 {
4659 	struct l2cap_info_req *req = (struct l2cap_info_req *) data;
4660 	u16 type;
4661 
4662 	if (cmd_len != sizeof(*req))
4663 		return -EPROTO;
4664 
4665 	type = __le16_to_cpu(req->type);
4666 
4667 	BT_DBG("type 0x%4.4x", type);
4668 
4669 	if (type == L2CAP_IT_FEAT_MASK) {
4670 		u8 buf[8];
4671 		u32 feat_mask = l2cap_feat_mask;
4672 		struct l2cap_info_rsp *rsp = (struct l2cap_info_rsp *) buf;
4673 		rsp->type   = cpu_to_le16(L2CAP_IT_FEAT_MASK);
4674 		rsp->result = cpu_to_le16(L2CAP_IR_SUCCESS);
4675 		if (!disable_ertm)
4676 			feat_mask |= L2CAP_FEAT_ERTM | L2CAP_FEAT_STREAMING
4677 				| L2CAP_FEAT_FCS;
4678 
4679 		put_unaligned_le32(feat_mask, rsp->data);
4680 		l2cap_send_cmd(conn, cmd->ident, L2CAP_INFO_RSP, sizeof(buf),
4681 			       buf);
4682 	} else if (type == L2CAP_IT_FIXED_CHAN) {
4683 		u8 buf[12];
4684 		struct l2cap_info_rsp *rsp = (struct l2cap_info_rsp *) buf;
4685 
4686 		rsp->type   = cpu_to_le16(L2CAP_IT_FIXED_CHAN);
4687 		rsp->result = cpu_to_le16(L2CAP_IR_SUCCESS);
4688 		rsp->data[0] = conn->local_fixed_chan;
4689 		memset(rsp->data + 1, 0, 7);
4690 		l2cap_send_cmd(conn, cmd->ident, L2CAP_INFO_RSP, sizeof(buf),
4691 			       buf);
4692 	} else {
4693 		struct l2cap_info_rsp rsp;
4694 		rsp.type   = cpu_to_le16(type);
4695 		rsp.result = cpu_to_le16(L2CAP_IR_NOTSUPP);
4696 		l2cap_send_cmd(conn, cmd->ident, L2CAP_INFO_RSP, sizeof(rsp),
4697 			       &rsp);
4698 	}
4699 
4700 	return 0;
4701 }
4702 
4703 static inline int l2cap_information_rsp(struct l2cap_conn *conn,
4704 					struct l2cap_cmd_hdr *cmd, u16 cmd_len,
4705 					u8 *data)
4706 {
4707 	struct l2cap_info_rsp *rsp = (struct l2cap_info_rsp *) data;
4708 	u16 type, result;
4709 
4710 	if (cmd_len < sizeof(*rsp))
4711 		return -EPROTO;
4712 
4713 	type   = __le16_to_cpu(rsp->type);
4714 	result = __le16_to_cpu(rsp->result);
4715 
4716 	BT_DBG("type 0x%4.4x result 0x%2.2x", type, result);
4717 
4718 	/* L2CAP Info req/rsp are unbound to channels, add extra checks */
4719 	if (cmd->ident != conn->info_ident ||
4720 	    conn->info_state & L2CAP_INFO_FEAT_MASK_REQ_DONE)
4721 		return 0;
4722 
4723 	cancel_delayed_work(&conn->info_timer);
4724 
4725 	if (result != L2CAP_IR_SUCCESS) {
4726 		conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_DONE;
4727 		conn->info_ident = 0;
4728 
4729 		l2cap_conn_start(conn);
4730 
4731 		return 0;
4732 	}
4733 
4734 	switch (type) {
4735 	case L2CAP_IT_FEAT_MASK:
4736 		if (cmd_len >= sizeof(*rsp) + sizeof(u32))
4737 			conn->feat_mask = get_unaligned_le32(rsp->data);
4738 
4739 		if (conn->feat_mask & L2CAP_FEAT_FIXED_CHAN) {
4740 			struct l2cap_info_req req;
4741 			req.type = cpu_to_le16(L2CAP_IT_FIXED_CHAN);
4742 
4743 			conn->info_ident = l2cap_get_ident(conn);
4744 
4745 			l2cap_send_cmd(conn, conn->info_ident,
4746 				       L2CAP_INFO_REQ, sizeof(req), &req);
4747 		} else {
4748 			conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_DONE;
4749 			conn->info_ident = 0;
4750 
4751 			l2cap_conn_start(conn);
4752 		}
4753 		break;
4754 
4755 	case L2CAP_IT_FIXED_CHAN:
4756 		if (cmd_len >= sizeof(*rsp) + sizeof(rsp->data[0]))
4757 			conn->remote_fixed_chan = rsp->data[0];
4758 		conn->info_state |= L2CAP_INFO_FEAT_MASK_REQ_DONE;
4759 		conn->info_ident = 0;
4760 
4761 		l2cap_conn_start(conn);
4762 		break;
4763 	}
4764 
4765 	return 0;
4766 }
4767 
4768 static inline int l2cap_conn_param_update_req(struct l2cap_conn *conn,
4769 					      struct l2cap_cmd_hdr *cmd,
4770 					      u16 cmd_len, u8 *data)
4771 {
4772 	struct hci_conn *hcon = conn->hcon;
4773 	struct l2cap_conn_param_update_req *req;
4774 	struct l2cap_conn_param_update_rsp rsp;
4775 	u16 min, max, latency, to_multiplier;
4776 	int err;
4777 
4778 	if (hcon->role != HCI_ROLE_MASTER)
4779 		return -EINVAL;
4780 
4781 	if (cmd_len != sizeof(struct l2cap_conn_param_update_req))
4782 		return -EPROTO;
4783 
4784 	req = (struct l2cap_conn_param_update_req *) data;
4785 	min		= __le16_to_cpu(req->min);
4786 	max		= __le16_to_cpu(req->max);
4787 	latency		= __le16_to_cpu(req->latency);
4788 	to_multiplier	= __le16_to_cpu(req->to_multiplier);
4789 
4790 	BT_DBG("min 0x%4.4x max 0x%4.4x latency: 0x%4.4x Timeout: 0x%4.4x",
4791 	       min, max, latency, to_multiplier);
4792 
4793 	memset(&rsp, 0, sizeof(rsp));
4794 
4795 	err = hci_check_conn_params(min, max, latency, to_multiplier);
4796 	if (err)
4797 		rsp.result = cpu_to_le16(L2CAP_CONN_PARAM_REJECTED);
4798 	else
4799 		rsp.result = cpu_to_le16(L2CAP_CONN_PARAM_ACCEPTED);
4800 
4801 	l2cap_send_cmd(conn, cmd->ident, L2CAP_CONN_PARAM_UPDATE_RSP,
4802 		       sizeof(rsp), &rsp);
4803 
4804 	if (!err)
4805 		hci_le_conn_update(hcon, min, max, latency, to_multiplier);
4806 
4807 	return 0;
4808 }
4809 
4810 static int l2cap_le_connect_rsp(struct l2cap_conn *conn,
4811 				struct l2cap_cmd_hdr *cmd, u16 cmd_len,
4812 				u8 *data)
4813 {
4814 	struct l2cap_le_conn_rsp *rsp = (struct l2cap_le_conn_rsp *) data;
4815 	struct hci_conn *hcon = conn->hcon;
4816 	u16 dcid, mtu, mps, credits, result;
4817 	struct l2cap_chan *chan;
4818 	int err, sec_level;
4819 
4820 	if (cmd_len < sizeof(*rsp))
4821 		return -EPROTO;
4822 
4823 	dcid    = __le16_to_cpu(rsp->dcid);
4824 	mtu     = __le16_to_cpu(rsp->mtu);
4825 	mps     = __le16_to_cpu(rsp->mps);
4826 	credits = __le16_to_cpu(rsp->credits);
4827 	result  = __le16_to_cpu(rsp->result);
4828 
4829 	if (result == L2CAP_CR_LE_SUCCESS && (mtu < 23 || mps < 23 ||
4830 					   dcid < L2CAP_CID_DYN_START ||
4831 					   dcid > L2CAP_CID_LE_DYN_END))
4832 		return -EPROTO;
4833 
4834 	BT_DBG("dcid 0x%4.4x mtu %u mps %u credits %u result 0x%2.2x",
4835 	       dcid, mtu, mps, credits, result);
4836 
4837 	chan = __l2cap_get_chan_by_ident(conn, cmd->ident);
4838 	if (!chan)
4839 		return -EBADSLT;
4840 
4841 	chan = l2cap_chan_hold_unless_zero(chan);
4842 	if (!chan)
4843 		return -EBADSLT;
4844 
4845 	err = 0;
4846 
4847 	l2cap_chan_lock(chan);
4848 
4849 	switch (result) {
4850 	case L2CAP_CR_LE_SUCCESS:
4851 		if (__l2cap_get_chan_by_dcid(conn, dcid)) {
4852 			err = -EBADSLT;
4853 			break;
4854 		}
4855 
4856 		chan->ident = 0;
4857 		chan->dcid = dcid;
4858 		chan->omtu = mtu;
4859 		chan->remote_mps = mps;
4860 		chan->tx_credits = credits;
4861 		l2cap_chan_ready(chan);
4862 		break;
4863 
4864 	case L2CAP_CR_LE_AUTHENTICATION:
4865 	case L2CAP_CR_LE_ENCRYPTION:
4866 		/* If we already have MITM protection we can't do
4867 		 * anything.
4868 		 */
4869 		if (hcon->sec_level > BT_SECURITY_MEDIUM) {
4870 			l2cap_chan_del(chan, ECONNREFUSED);
4871 			break;
4872 		}
4873 
4874 		sec_level = hcon->sec_level + 1;
4875 		if (chan->sec_level < sec_level)
4876 			chan->sec_level = sec_level;
4877 
4878 		/* We'll need to send a new Connect Request */
4879 		clear_bit(FLAG_LE_CONN_REQ_SENT, &chan->flags);
4880 
4881 		smp_conn_security(hcon, chan->sec_level);
4882 		break;
4883 
4884 	default:
4885 		l2cap_chan_del(chan, ECONNREFUSED);
4886 		break;
4887 	}
4888 
4889 	l2cap_chan_unlock(chan);
4890 	l2cap_chan_put(chan);
4891 
4892 	return err;
4893 }
4894 
4895 static void l2cap_put_ident(struct l2cap_conn *conn, u8 code, u8 id)
4896 {
4897 	switch (code) {
4898 	case L2CAP_COMMAND_REJ:
4899 	case L2CAP_CONN_RSP:
4900 	case L2CAP_CONF_RSP:
4901 	case L2CAP_DISCONN_RSP:
4902 	case L2CAP_ECHO_RSP:
4903 	case L2CAP_INFO_RSP:
4904 	case L2CAP_CONN_PARAM_UPDATE_RSP:
4905 	case L2CAP_LE_CONN_RSP:
4906 	case L2CAP_ECRED_CONN_RSP:
4907 	case L2CAP_ECRED_RECONF_RSP:
4908 		/* First do a lookup since the remote may send bogus ids that
4909 		 * would make ida_free to generate warnings.
4910 		 */
4911 		if (ida_find_first_range(&conn->tx_ida, id, id) >= 0)
4912 			ida_free(&conn->tx_ida, id);
4913 	}
4914 }
4915 
4916 static inline int l2cap_bredr_sig_cmd(struct l2cap_conn *conn,
4917 				      struct l2cap_cmd_hdr *cmd, u16 cmd_len,
4918 				      u8 *data)
4919 {
4920 	int err = 0;
4921 
4922 	l2cap_put_ident(conn, cmd->code, cmd->ident);
4923 
4924 	switch (cmd->code) {
4925 	case L2CAP_COMMAND_REJ:
4926 		l2cap_command_rej(conn, cmd, cmd_len, data);
4927 		break;
4928 
4929 	case L2CAP_CONN_REQ:
4930 		err = l2cap_connect_req(conn, cmd, cmd_len, data);
4931 		break;
4932 
4933 	case L2CAP_CONN_RSP:
4934 		l2cap_connect_create_rsp(conn, cmd, cmd_len, data);
4935 		break;
4936 
4937 	case L2CAP_CONF_REQ:
4938 		err = l2cap_config_req(conn, cmd, cmd_len, data);
4939 		break;
4940 
4941 	case L2CAP_CONF_RSP:
4942 		l2cap_config_rsp(conn, cmd, cmd_len, data);
4943 		break;
4944 
4945 	case L2CAP_DISCONN_REQ:
4946 		err = l2cap_disconnect_req(conn, cmd, cmd_len, data);
4947 		break;
4948 
4949 	case L2CAP_DISCONN_RSP:
4950 		l2cap_disconnect_rsp(conn, cmd, cmd_len, data);
4951 		break;
4952 
4953 	case L2CAP_ECHO_REQ:
4954 		l2cap_send_cmd(conn, cmd->ident, L2CAP_ECHO_RSP, cmd_len, data);
4955 		break;
4956 
4957 	case L2CAP_ECHO_RSP:
4958 		break;
4959 
4960 	case L2CAP_INFO_REQ:
4961 		err = l2cap_information_req(conn, cmd, cmd_len, data);
4962 		break;
4963 
4964 	case L2CAP_INFO_RSP:
4965 		l2cap_information_rsp(conn, cmd, cmd_len, data);
4966 		break;
4967 
4968 	default:
4969 		BT_ERR("Unknown BR/EDR signaling command 0x%2.2x", cmd->code);
4970 		err = -EINVAL;
4971 		break;
4972 	}
4973 
4974 	return err;
4975 }
4976 
4977 static int l2cap_le_connect_req(struct l2cap_conn *conn,
4978 				struct l2cap_cmd_hdr *cmd, u16 cmd_len,
4979 				u8 *data)
4980 {
4981 	struct l2cap_le_conn_req *req = (struct l2cap_le_conn_req *) data;
4982 	struct l2cap_le_conn_rsp rsp;
4983 	struct l2cap_chan *chan, *pchan;
4984 	u16 dcid, scid, credits, mtu, mps;
4985 	__le16 psm;
4986 	u8 result;
4987 
4988 	if (cmd_len != sizeof(*req))
4989 		return -EPROTO;
4990 
4991 	scid = __le16_to_cpu(req->scid);
4992 	mtu  = __le16_to_cpu(req->mtu);
4993 	mps  = __le16_to_cpu(req->mps);
4994 	psm  = req->psm;
4995 	dcid = 0;
4996 	credits = 0;
4997 
4998 	if (mtu < 23 || mps < 23)
4999 		return -EPROTO;
5000 
5001 	BT_DBG("psm 0x%2.2x scid 0x%4.4x mtu %u mps %u", __le16_to_cpu(psm),
5002 	       scid, mtu, mps);
5003 
5004 	/* BLUETOOTH CORE SPECIFICATION Version 5.3 | Vol 3, Part A
5005 	 * page 1059:
5006 	 *
5007 	 * Valid range: 0x0001-0x00ff
5008 	 *
5009 	 * Table 4.15: L2CAP_LE_CREDIT_BASED_CONNECTION_REQ SPSM ranges
5010 	 */
5011 	if (!psm || __le16_to_cpu(psm) > L2CAP_PSM_LE_DYN_END) {
5012 		result = L2CAP_CR_LE_BAD_PSM;
5013 		chan = NULL;
5014 		goto response;
5015 	}
5016 
5017 	/* Check if we have socket listening on psm */
5018 	pchan = l2cap_global_chan_by_psm(BT_LISTEN, psm, &conn->hcon->src,
5019 					 &conn->hcon->dst, LE_LINK);
5020 	if (!pchan) {
5021 		result = L2CAP_CR_LE_BAD_PSM;
5022 		chan = NULL;
5023 		goto response;
5024 	}
5025 
5026 	l2cap_chan_lock(pchan);
5027 
5028 	if (!smp_sufficient_security(conn->hcon, pchan->sec_level,
5029 				     SMP_ALLOW_STK)) {
5030 		result = pchan->sec_level == BT_SECURITY_MEDIUM ?
5031 			L2CAP_CR_LE_ENCRYPTION : L2CAP_CR_LE_AUTHENTICATION;
5032 		chan = NULL;
5033 		goto response_unlock;
5034 	}
5035 
5036 	/* Check if Key Size is sufficient for the security level */
5037 	if (!l2cap_check_enc_key_size(conn->hcon, pchan)) {
5038 		result = L2CAP_CR_LE_BAD_KEY_SIZE;
5039 		chan = NULL;
5040 		goto response_unlock;
5041 	}
5042 
5043 	/* Check for valid dynamic CID range */
5044 	if (scid < L2CAP_CID_DYN_START || scid > L2CAP_CID_LE_DYN_END) {
5045 		result = L2CAP_CR_LE_INVALID_SCID;
5046 		chan = NULL;
5047 		goto response_unlock;
5048 	}
5049 
5050 	/* Check if we already have channel with that dcid */
5051 	if (__l2cap_get_chan_by_dcid(conn, scid)) {
5052 		result = L2CAP_CR_LE_SCID_IN_USE;
5053 		chan = NULL;
5054 		goto response_unlock;
5055 	}
5056 
5057 	chan = l2cap_new_connection(conn, pchan);
5058 	if (!chan) {
5059 		result = L2CAP_CR_LE_NO_MEM;
5060 		goto response_unlock;
5061 	}
5062 
5063 	bacpy(&chan->src, &conn->hcon->src);
5064 	bacpy(&chan->dst, &conn->hcon->dst);
5065 	chan->src_type = bdaddr_src_type(conn->hcon);
5066 	chan->dst_type = bdaddr_dst_type(conn->hcon);
5067 	chan->psm  = psm;
5068 	chan->dcid = scid;
5069 	chan->omtu = mtu;
5070 	chan->remote_mps = mps;
5071 
5072 	l2cap_le_flowctl_init(chan, __le16_to_cpu(req->credits));
5073 
5074 	dcid = chan->scid;
5075 	credits = chan->rx_credits;
5076 
5077 	__set_chan_timer(chan, chan->ops->get_sndtimeo(chan));
5078 
5079 	chan->ident = cmd->ident;
5080 	chan->mode = L2CAP_MODE_LE_FLOWCTL;
5081 
5082 	if (test_bit(FLAG_DEFER_SETUP, &chan->flags)) {
5083 		l2cap_state_change(chan, BT_CONNECT2);
5084 		/* The following result value is actually not defined
5085 		 * for LE CoC but we use it to let the function know
5086 		 * that it should bail out after doing its cleanup
5087 		 * instead of sending a response.
5088 		 */
5089 		result = L2CAP_CR_PEND;
5090 		chan->ops->defer(chan);
5091 	} else {
5092 		l2cap_chan_ready(chan);
5093 		result = L2CAP_CR_LE_SUCCESS;
5094 	}
5095 
5096 response_unlock:
5097 	l2cap_chan_unlock(pchan);
5098 	l2cap_chan_put(pchan);
5099 
5100 	if (result == L2CAP_CR_PEND)
5101 		return 0;
5102 
5103 response:
5104 	if (chan) {
5105 		rsp.mtu = cpu_to_le16(chan->imtu);
5106 		rsp.mps = cpu_to_le16(chan->mps);
5107 	} else {
5108 		rsp.mtu = 0;
5109 		rsp.mps = 0;
5110 	}
5111 
5112 	rsp.dcid    = cpu_to_le16(dcid);
5113 	rsp.credits = cpu_to_le16(credits);
5114 	rsp.result  = cpu_to_le16(result);
5115 
5116 	l2cap_send_cmd(conn, cmd->ident, L2CAP_LE_CONN_RSP, sizeof(rsp), &rsp);
5117 
5118 	return 0;
5119 }
5120 
5121 static inline int l2cap_le_credits(struct l2cap_conn *conn,
5122 				   struct l2cap_cmd_hdr *cmd, u16 cmd_len,
5123 				   u8 *data)
5124 {
5125 	struct l2cap_le_credits *pkt;
5126 	struct l2cap_chan *chan;
5127 	u16 cid, credits, max_credits;
5128 
5129 	if (cmd_len != sizeof(*pkt))
5130 		return -EPROTO;
5131 
5132 	pkt = (struct l2cap_le_credits *) data;
5133 	cid	= __le16_to_cpu(pkt->cid);
5134 	credits	= __le16_to_cpu(pkt->credits);
5135 
5136 	BT_DBG("cid 0x%4.4x credits 0x%4.4x", cid, credits);
5137 
5138 	chan = l2cap_get_chan_by_dcid(conn, cid);
5139 	if (!chan)
5140 		return -EBADSLT;
5141 
5142 	max_credits = LE_FLOWCTL_MAX_CREDITS - chan->tx_credits;
5143 	if (credits > max_credits) {
5144 		BT_ERR("LE credits overflow");
5145 		l2cap_send_disconn_req(chan, ECONNRESET);
5146 
5147 		/* Return 0 so that we don't trigger an unnecessary
5148 		 * command reject packet.
5149 		 */
5150 		goto unlock;
5151 	}
5152 
5153 	chan->tx_credits += credits;
5154 
5155 	/* Resume sending */
5156 	l2cap_le_flowctl_send(chan);
5157 
5158 	if (chan->tx_credits)
5159 		chan->ops->resume(chan);
5160 
5161 unlock:
5162 	l2cap_chan_unlock(chan);
5163 	l2cap_chan_put(chan);
5164 
5165 	return 0;
5166 }
5167 
5168 static inline int l2cap_ecred_conn_req(struct l2cap_conn *conn,
5169 				       struct l2cap_cmd_hdr *cmd, u16 cmd_len,
5170 				       u8 *data)
5171 {
5172 	struct l2cap_ecred_conn_req *req = (void *) data;
5173 	DEFINE_RAW_FLEX(struct l2cap_ecred_conn_rsp, pdu, dcid, L2CAP_ECRED_MAX_CID);
5174 	struct l2cap_chan *chan, *pchan;
5175 	u16 mtu, mps;
5176 	__le16 psm;
5177 	u8 result, rsp_len = 0;
5178 	int i, num_scid = 0;
5179 	bool defer = false;
5180 
5181 	if (!enable_ecred)
5182 		return -EINVAL;
5183 
5184 	memset(pdu, 0, sizeof(*pdu));
5185 
5186 	if (cmd_len < sizeof(*req) || (cmd_len - sizeof(*req)) % sizeof(u16)) {
5187 		result = L2CAP_CR_LE_INVALID_PARAMS;
5188 		goto response;
5189 	}
5190 
5191 	/* Check if there are no pending channels with the same ident */
5192 	__l2cap_chan_list_id(conn, cmd->ident, l2cap_ecred_list_defer,
5193 			     &num_scid);
5194 	if (num_scid) {
5195 		result = L2CAP_CR_LE_INVALID_PARAMS;
5196 		goto response;
5197 	}
5198 
5199 	cmd_len -= sizeof(*req);
5200 	num_scid = cmd_len / sizeof(u16);
5201 
5202 	if (num_scid > L2CAP_ECRED_MAX_CID) {
5203 		result = L2CAP_CR_LE_INVALID_PARAMS;
5204 		goto response;
5205 	}
5206 
5207 	/* Always respond with the same number of scids as in the request */
5208 	rsp_len = cmd_len;
5209 
5210 	mtu  = __le16_to_cpu(req->mtu);
5211 	mps  = __le16_to_cpu(req->mps);
5212 
5213 	if (mtu < L2CAP_ECRED_MIN_MTU || mps < L2CAP_ECRED_MIN_MPS) {
5214 		result = L2CAP_CR_LE_INVALID_PARAMS;
5215 		goto response;
5216 	}
5217 
5218 	psm  = req->psm;
5219 
5220 	/* BLUETOOTH CORE SPECIFICATION Version 5.3 | Vol 3, Part A
5221 	 * page 1059:
5222 	 *
5223 	 * Valid range: 0x0001-0x00ff
5224 	 *
5225 	 * Table 4.15: L2CAP_LE_CREDIT_BASED_CONNECTION_REQ SPSM ranges
5226 	 */
5227 	if (!psm || __le16_to_cpu(psm) > L2CAP_PSM_LE_DYN_END) {
5228 		result = L2CAP_CR_LE_BAD_PSM;
5229 		goto response;
5230 	}
5231 
5232 	BT_DBG("psm 0x%2.2x mtu %u mps %u", __le16_to_cpu(psm), mtu, mps);
5233 
5234 	/* Check if we have socket listening on psm */
5235 	pchan = l2cap_global_chan_by_psm(BT_LISTEN, psm, &conn->hcon->src,
5236 					 &conn->hcon->dst, LE_LINK);
5237 	if (!pchan) {
5238 		result = L2CAP_CR_LE_BAD_PSM;
5239 		goto response;
5240 	}
5241 
5242 	l2cap_chan_lock(pchan);
5243 
5244 	if (!smp_sufficient_security(conn->hcon, pchan->sec_level,
5245 				     SMP_ALLOW_STK)) {
5246 		result = pchan->sec_level == BT_SECURITY_MEDIUM ?
5247 			L2CAP_CR_LE_ENCRYPTION : L2CAP_CR_LE_AUTHENTICATION;
5248 		goto unlock;
5249 	}
5250 
5251 	/* Check if the listening channel has set an output MTU then the
5252 	 * requested MTU shall be less than or equal to that value.
5253 	 */
5254 	if (pchan->omtu && mtu < pchan->omtu) {
5255 		result = L2CAP_CR_LE_UNACCEPT_PARAMS;
5256 		goto unlock;
5257 	}
5258 
5259 	result = L2CAP_CR_LE_SUCCESS;
5260 
5261 	for (i = 0; i < num_scid; i++) {
5262 		u16 scid = __le16_to_cpu(req->scid[i]);
5263 
5264 		BT_DBG("scid[%d] 0x%4.4x", i, scid);
5265 
5266 		pdu->dcid[i] = 0x0000;
5267 
5268 		/* Check for valid dynamic CID range */
5269 		if (scid < L2CAP_CID_DYN_START || scid > L2CAP_CID_LE_DYN_END) {
5270 			result = L2CAP_CR_LE_INVALID_SCID;
5271 			continue;
5272 		}
5273 
5274 		/* Check if we already have channel with that dcid */
5275 		if (__l2cap_get_chan_by_dcid(conn, scid)) {
5276 			result = L2CAP_CR_LE_SCID_IN_USE;
5277 			continue;
5278 		}
5279 
5280 		chan = l2cap_new_connection(conn, pchan);
5281 		if (!chan) {
5282 			result = L2CAP_CR_LE_NO_MEM;
5283 			continue;
5284 		}
5285 
5286 		bacpy(&chan->src, &conn->hcon->src);
5287 		bacpy(&chan->dst, &conn->hcon->dst);
5288 		chan->src_type = bdaddr_src_type(conn->hcon);
5289 		chan->dst_type = bdaddr_dst_type(conn->hcon);
5290 		chan->psm  = psm;
5291 		chan->dcid = scid;
5292 		chan->omtu = mtu;
5293 		chan->remote_mps = mps;
5294 
5295 		l2cap_ecred_init(chan, __le16_to_cpu(req->credits));
5296 
5297 		/* Init response */
5298 		if (!pdu->credits) {
5299 			pdu->mtu = cpu_to_le16(chan->imtu);
5300 			pdu->mps = cpu_to_le16(chan->mps);
5301 			pdu->credits = cpu_to_le16(chan->rx_credits);
5302 		}
5303 
5304 		pdu->dcid[i] = cpu_to_le16(chan->scid);
5305 
5306 		__set_chan_timer(chan, chan->ops->get_sndtimeo(chan));
5307 
5308 		chan->ident = cmd->ident;
5309 		chan->mode = L2CAP_MODE_EXT_FLOWCTL;
5310 
5311 		if (test_bit(FLAG_DEFER_SETUP, &chan->flags)) {
5312 			l2cap_state_change(chan, BT_CONNECT2);
5313 			defer = true;
5314 			chan->ops->defer(chan);
5315 		} else {
5316 			l2cap_chan_ready(chan);
5317 		}
5318 	}
5319 
5320 unlock:
5321 	l2cap_chan_unlock(pchan);
5322 	l2cap_chan_put(pchan);
5323 
5324 response:
5325 	pdu->result = cpu_to_le16(result);
5326 
5327 	if (defer)
5328 		return 0;
5329 
5330 	l2cap_send_cmd(conn, cmd->ident, L2CAP_ECRED_CONN_RSP,
5331 		       sizeof(*pdu) + rsp_len, pdu);
5332 
5333 	return 0;
5334 }
5335 
5336 static inline int l2cap_ecred_conn_rsp(struct l2cap_conn *conn,
5337 				       struct l2cap_cmd_hdr *cmd, u16 cmd_len,
5338 				       u8 *data)
5339 {
5340 	struct l2cap_ecred_conn_rsp *rsp = (void *) data;
5341 	struct hci_conn *hcon = conn->hcon;
5342 	u16 mtu, mps, credits, result;
5343 	struct l2cap_chan *chan, *tmp;
5344 	int err = 0, sec_level;
5345 	int i = 0;
5346 
5347 	if (cmd_len < sizeof(*rsp))
5348 		return -EPROTO;
5349 
5350 	mtu     = __le16_to_cpu(rsp->mtu);
5351 	mps     = __le16_to_cpu(rsp->mps);
5352 	credits = __le16_to_cpu(rsp->credits);
5353 	result  = __le16_to_cpu(rsp->result);
5354 
5355 	BT_DBG("mtu %u mps %u credits %u result 0x%4.4x", mtu, mps, credits,
5356 	       result);
5357 
5358 	cmd_len -= sizeof(*rsp);
5359 
5360 	list_for_each_entry_safe(chan, tmp, &conn->chan_l, list) {
5361 		struct l2cap_chan *orig;
5362 		u16 dcid;
5363 
5364 		if (chan->ident != cmd->ident ||
5365 		    chan->mode != L2CAP_MODE_EXT_FLOWCTL ||
5366 		    chan->state == BT_CONNECTED)
5367 			continue;
5368 
5369 		l2cap_chan_lock(chan);
5370 
5371 		/* Check that there is a dcid for each pending channel */
5372 		if (cmd_len < sizeof(dcid)) {
5373 			l2cap_chan_del(chan, ECONNREFUSED);
5374 			l2cap_chan_unlock(chan);
5375 			continue;
5376 		}
5377 
5378 		dcid = __le16_to_cpu(rsp->dcid[i++]);
5379 		cmd_len -= sizeof(u16);
5380 
5381 		BT_DBG("dcid[%d] 0x%4.4x", i, dcid);
5382 
5383 		orig = __l2cap_get_chan_by_dcid(conn, dcid);
5384 
5385 		/* Check if dcid is already in use */
5386 		if (dcid && orig) {
5387 			/* If a device receives a
5388 			 * L2CAP_CREDIT_BASED_CONNECTION_RSP packet with an
5389 			 * already-assigned Destination CID, then both the
5390 			 * original channel and the new channel shall be
5391 			 * immediately discarded and not used.
5392 			 */
5393 			l2cap_chan_del(chan, ECONNREFUSED);
5394 			l2cap_chan_unlock(chan);
5395 
5396 			/* Check that the dcid channel mode is
5397 			 * L2CAP_MODE_EXT_FLOWCTL since this procedure is only
5398 			 * valid for that mode and shouldn't disconnect a dcid
5399 			 * in other modes.
5400 			 */
5401 			if (orig->mode == L2CAP_MODE_EXT_FLOWCTL) {
5402 				l2cap_chan_lock(orig);
5403 				/* Disconnect the original channel as it may be
5404 				 * considered connected since dcid has already
5405 				 * been assigned; don't call l2cap_chan_close
5406 				 * directly since that could lead to
5407 				 * l2cap_chan_del and then removing the channel
5408 				 * from the list while we're iterating over it.
5409 				 */
5410 				__set_chan_timer(orig, 0);
5411 				l2cap_chan_unlock(orig);
5412 			}
5413 			continue;
5414 		}
5415 
5416 		switch (result) {
5417 		case L2CAP_CR_LE_AUTHENTICATION:
5418 		case L2CAP_CR_LE_ENCRYPTION:
5419 			/* If we already have MITM protection we can't do
5420 			 * anything.
5421 			 */
5422 			if (hcon->sec_level > BT_SECURITY_MEDIUM) {
5423 				l2cap_chan_del(chan, ECONNREFUSED);
5424 				break;
5425 			}
5426 
5427 			sec_level = hcon->sec_level + 1;
5428 			if (chan->sec_level < sec_level)
5429 				chan->sec_level = sec_level;
5430 
5431 			/* We'll need to send a new Connect Request */
5432 			clear_bit(FLAG_ECRED_CONN_REQ_SENT, &chan->flags);
5433 
5434 			smp_conn_security(hcon, chan->sec_level);
5435 			break;
5436 
5437 		case L2CAP_CR_LE_BAD_PSM:
5438 			l2cap_chan_del(chan, ECONNREFUSED);
5439 			break;
5440 
5441 		default:
5442 			/* If dcid was not set it means channels was refused */
5443 			if (!dcid) {
5444 				l2cap_chan_del(chan, ECONNREFUSED);
5445 				break;
5446 			}
5447 
5448 			chan->ident = 0;
5449 			chan->dcid = dcid;
5450 			chan->omtu = mtu;
5451 			chan->remote_mps = mps;
5452 			chan->tx_credits = credits;
5453 			l2cap_chan_ready(chan);
5454 			break;
5455 		}
5456 
5457 		l2cap_chan_unlock(chan);
5458 	}
5459 
5460 	return err;
5461 }
5462 
5463 static inline int l2cap_ecred_reconf_req(struct l2cap_conn *conn,
5464 					 struct l2cap_cmd_hdr *cmd, u16 cmd_len,
5465 					 u8 *data)
5466 {
5467 	struct l2cap_ecred_reconf_req *req = (void *) data;
5468 	struct l2cap_ecred_reconf_rsp rsp;
5469 	u16 mtu, mps, result;
5470 	struct l2cap_chan *chan[L2CAP_ECRED_MAX_CID] = {};
5471 	int i, num_scid;
5472 
5473 	if (!enable_ecred)
5474 		return -EINVAL;
5475 
5476 	if (cmd_len < sizeof(*req) || (cmd_len - sizeof(*req)) % sizeof(u16)) {
5477 		result = L2CAP_RECONF_INVALID_CID;
5478 		goto respond;
5479 	}
5480 
5481 	mtu = __le16_to_cpu(req->mtu);
5482 	mps = __le16_to_cpu(req->mps);
5483 
5484 	BT_DBG("mtu %u mps %u", mtu, mps);
5485 
5486 	if (mtu < L2CAP_ECRED_MIN_MTU) {
5487 		result = L2CAP_RECONF_INVALID_PARAMS;
5488 		goto respond;
5489 	}
5490 
5491 	if (mps < L2CAP_ECRED_MIN_MPS) {
5492 		result = L2CAP_RECONF_INVALID_PARAMS;
5493 		goto respond;
5494 	}
5495 
5496 	cmd_len -= sizeof(*req);
5497 	num_scid = cmd_len / sizeof(u16);
5498 
5499 	if (num_scid > L2CAP_ECRED_MAX_CID) {
5500 		result = L2CAP_RECONF_INVALID_PARAMS;
5501 		goto respond;
5502 	}
5503 
5504 	result = L2CAP_RECONF_SUCCESS;
5505 
5506 	/* Check if each SCID, MTU and MPS are valid */
5507 	for (i = 0; i < num_scid; i++) {
5508 		u16 scid;
5509 
5510 		scid = __le16_to_cpu(req->scid[i]);
5511 		if (!scid) {
5512 			result = L2CAP_RECONF_INVALID_CID;
5513 			goto respond;
5514 		}
5515 
5516 		chan[i] = __l2cap_get_chan_by_dcid(conn, scid);
5517 		if (!chan[i]) {
5518 			result = L2CAP_RECONF_INVALID_CID;
5519 			goto respond;
5520 		}
5521 
5522 		/* The MTU field shall be greater than or equal to the greatest
5523 		 * current MTU size of these channels.
5524 		 */
5525 		if (chan[i]->omtu > mtu) {
5526 			BT_ERR("chan %p decreased MTU %u -> %u", chan[i],
5527 			       chan[i]->omtu, mtu);
5528 			result = L2CAP_RECONF_INVALID_MTU;
5529 			goto respond;
5530 		}
5531 
5532 		/* If more than one channel is being configured, the MPS field
5533 		 * shall be greater than or equal to the current MPS size of
5534 		 * each of these channels. If only one channel is being
5535 		 * configured, the MPS field may be less than the current MPS
5536 		 * of that channel.
5537 		 */
5538 		if (chan[i]->remote_mps > mps && num_scid > 1) {
5539 			BT_ERR("chan %p decreased MPS %u -> %u", chan[i],
5540 			       chan[i]->remote_mps, mps);
5541 			result = L2CAP_RECONF_INVALID_MPS;
5542 			goto respond;
5543 		}
5544 	}
5545 
5546 	/* Commit the new MTU and MPS values after checking they are valid */
5547 	for (i = 0; i < num_scid; i++) {
5548 		chan[i]->omtu = mtu;
5549 		chan[i]->remote_mps = mps;
5550 	}
5551 
5552 respond:
5553 	rsp.result = cpu_to_le16(result);
5554 
5555 	l2cap_send_cmd(conn, cmd->ident, L2CAP_ECRED_RECONF_RSP, sizeof(rsp),
5556 		       &rsp);
5557 
5558 	return 0;
5559 }
5560 
5561 static inline int l2cap_ecred_reconf_rsp(struct l2cap_conn *conn,
5562 					 struct l2cap_cmd_hdr *cmd, u16 cmd_len,
5563 					 u8 *data)
5564 {
5565 	struct l2cap_chan *chan, *tmp;
5566 	struct l2cap_ecred_reconf_rsp *rsp = (void *)data;
5567 	u16 result;
5568 
5569 	if (cmd_len < sizeof(*rsp))
5570 		return -EPROTO;
5571 
5572 	result = __le16_to_cpu(rsp->result);
5573 
5574 	BT_DBG("result 0x%4.4x", result);
5575 
5576 	if (!result) {
5577 		list_for_each_entry(chan, &conn->chan_l, list) {
5578 			if (chan->ident == cmd->ident)
5579 				chan->ident = 0;
5580 		}
5581 		return 0;
5582 	}
5583 
5584 	list_for_each_entry_safe(chan, tmp, &conn->chan_l, list) {
5585 		if (chan->ident != cmd->ident)
5586 			continue;
5587 
5588 		if (!l2cap_chan_hold_unless_zero(chan))
5589 			continue;
5590 		l2cap_chan_lock(chan);
5591 
5592 		l2cap_chan_del(chan, ECONNRESET);
5593 
5594 		l2cap_chan_unlock(chan);
5595 		l2cap_chan_put(chan);
5596 	}
5597 
5598 	return 0;
5599 }
5600 
5601 static inline int l2cap_le_command_rej(struct l2cap_conn *conn,
5602 				       struct l2cap_cmd_hdr *cmd, u16 cmd_len,
5603 				       u8 *data)
5604 {
5605 	struct l2cap_cmd_rej_unk *rej = (struct l2cap_cmd_rej_unk *) data;
5606 	struct l2cap_chan *chan;
5607 
5608 	if (cmd_len < sizeof(*rej))
5609 		return -EPROTO;
5610 
5611 	chan = __l2cap_get_chan_by_ident(conn, cmd->ident);
5612 	if (!chan)
5613 		goto done;
5614 
5615 	chan = l2cap_chan_hold_unless_zero(chan);
5616 	if (!chan)
5617 		goto done;
5618 
5619 	l2cap_chan_lock(chan);
5620 	l2cap_chan_del(chan, ECONNREFUSED);
5621 	l2cap_chan_unlock(chan);
5622 	l2cap_chan_put(chan);
5623 
5624 done:
5625 	return 0;
5626 }
5627 
5628 static inline int l2cap_le_sig_cmd(struct l2cap_conn *conn,
5629 				   struct l2cap_cmd_hdr *cmd, u16 cmd_len,
5630 				   u8 *data)
5631 {
5632 	int err = 0;
5633 
5634 	l2cap_put_ident(conn, cmd->code, cmd->ident);
5635 
5636 	switch (cmd->code) {
5637 	case L2CAP_COMMAND_REJ:
5638 		l2cap_le_command_rej(conn, cmd, cmd_len, data);
5639 		break;
5640 
5641 	case L2CAP_CONN_PARAM_UPDATE_REQ:
5642 		err = l2cap_conn_param_update_req(conn, cmd, cmd_len, data);
5643 		break;
5644 
5645 	case L2CAP_CONN_PARAM_UPDATE_RSP:
5646 		break;
5647 
5648 	case L2CAP_LE_CONN_RSP:
5649 		l2cap_le_connect_rsp(conn, cmd, cmd_len, data);
5650 		break;
5651 
5652 	case L2CAP_LE_CONN_REQ:
5653 		err = l2cap_le_connect_req(conn, cmd, cmd_len, data);
5654 		break;
5655 
5656 	case L2CAP_LE_CREDITS:
5657 		err = l2cap_le_credits(conn, cmd, cmd_len, data);
5658 		break;
5659 
5660 	case L2CAP_ECRED_CONN_REQ:
5661 		err = l2cap_ecred_conn_req(conn, cmd, cmd_len, data);
5662 		break;
5663 
5664 	case L2CAP_ECRED_CONN_RSP:
5665 		err = l2cap_ecred_conn_rsp(conn, cmd, cmd_len, data);
5666 		break;
5667 
5668 	case L2CAP_ECRED_RECONF_REQ:
5669 		err = l2cap_ecred_reconf_req(conn, cmd, cmd_len, data);
5670 		break;
5671 
5672 	case L2CAP_ECRED_RECONF_RSP:
5673 		err = l2cap_ecred_reconf_rsp(conn, cmd, cmd_len, data);
5674 		break;
5675 
5676 	case L2CAP_DISCONN_REQ:
5677 		err = l2cap_disconnect_req(conn, cmd, cmd_len, data);
5678 		break;
5679 
5680 	case L2CAP_DISCONN_RSP:
5681 		l2cap_disconnect_rsp(conn, cmd, cmd_len, data);
5682 		break;
5683 
5684 	default:
5685 		BT_ERR("Unknown LE signaling command 0x%2.2x", cmd->code);
5686 		err = -EINVAL;
5687 		break;
5688 	}
5689 
5690 	return err;
5691 }
5692 
5693 static inline void l2cap_le_sig_channel(struct l2cap_conn *conn,
5694 					struct sk_buff *skb)
5695 {
5696 	struct hci_conn *hcon = conn->hcon;
5697 	struct l2cap_cmd_hdr *cmd;
5698 	u16 len;
5699 	int err;
5700 
5701 	if (hcon->type != LE_LINK)
5702 		goto drop;
5703 
5704 	if (skb->len < L2CAP_CMD_HDR_SIZE)
5705 		goto drop;
5706 
5707 	cmd = (void *) skb->data;
5708 	skb_pull(skb, L2CAP_CMD_HDR_SIZE);
5709 
5710 	len = le16_to_cpu(cmd->len);
5711 
5712 	BT_DBG("code 0x%2.2x len %d id 0x%2.2x", cmd->code, len, cmd->ident);
5713 
5714 	if (len != skb->len || !cmd->ident) {
5715 		BT_DBG("corrupted command");
5716 		goto drop;
5717 	}
5718 
5719 	err = l2cap_le_sig_cmd(conn, cmd, len, skb->data);
5720 	if (err) {
5721 		struct l2cap_cmd_rej_unk rej;
5722 
5723 		BT_ERR("Wrong link type (%d)", err);
5724 
5725 		rej.reason = cpu_to_le16(L2CAP_REJ_NOT_UNDERSTOOD);
5726 		l2cap_send_cmd(conn, cmd->ident, L2CAP_COMMAND_REJ,
5727 			       sizeof(rej), &rej);
5728 	}
5729 
5730 drop:
5731 	kfree_skb(skb);
5732 }
5733 
5734 static inline void l2cap_sig_send_rej(struct l2cap_conn *conn, u16 ident)
5735 {
5736 	struct l2cap_cmd_rej_unk rej;
5737 
5738 	rej.reason = cpu_to_le16(L2CAP_REJ_NOT_UNDERSTOOD);
5739 	l2cap_send_cmd(conn, ident, L2CAP_COMMAND_REJ, sizeof(rej), &rej);
5740 }
5741 
5742 static inline void l2cap_sig_send_mtu_rej(struct l2cap_conn *conn, u8 ident)
5743 {
5744 	struct l2cap_cmd_rej_mtu rej;
5745 
5746 	rej.reason = cpu_to_le16(L2CAP_REJ_MTU_EXCEEDED);
5747 	rej.max_mtu = cpu_to_le16(L2CAP_SIG_MTU);
5748 	l2cap_send_cmd(conn, ident, L2CAP_COMMAND_REJ, sizeof(rej), &rej);
5749 }
5750 
5751 static inline void l2cap_sig_channel(struct l2cap_conn *conn,
5752 				     struct sk_buff *skb)
5753 {
5754 	struct hci_conn *hcon = conn->hcon;
5755 	struct l2cap_cmd_hdr *cmd;
5756 	int err;
5757 
5758 	l2cap_raw_recv(conn, skb);
5759 
5760 	if (hcon->type != ACL_LINK)
5761 		goto drop;
5762 
5763 	/*
5764 	 * Bluetooth Core v5.4, Vol 3, Part A, Section 4: the BR/EDR
5765 	 * signaling channel has a fixed signaling MTU (MTUsig) whose
5766 	 * minimum and default is 48 octets.  Section 4.1 says that on
5767 	 * an MTUExceeded command reject the identifier "shall match
5768 	 * the first request command in the L2CAP packet" and that
5769 	 * packets containing only response commands "shall be
5770 	 * silently discarded".
5771 	 *
5772 	 * Linux intentionally deviates from that prescription:
5773 	 *
5774 	 *   1. Silently discarding desynchronizes the peer.  The
5775 	 *      remote stack never learns its responses were dropped,
5776 	 *      so any state machine waiting on a paired response
5777 	 *      stalls until its own timer fires.
5778 	 *
5779 	 *   2. Locating "the first request command" requires walking
5780 	 *      command headers past MTUsig, i.e. processing bytes
5781 	 *      from a packet we have already decided is too large to
5782 	 *      process.
5783 	 *
5784 	 * Reject every over-MTUsig signaling packet with one
5785 	 * L2CAP_REJ_MTU_EXCEEDED command reject.  The reject's
5786 	 * reason field is what tells the peer that the whole packet
5787 	 * was discarded; the identifier value is informational, so
5788 	 * we use the identifier from the first command header, a
5789 	 * single fixed-offset byte read.
5790 	 */
5791 	if (skb->len > L2CAP_SIG_MTU) {
5792 		u8 ident = skb->data[1];
5793 
5794 		BT_DBG("signaling packet exceeds MTU: %u > %u",
5795 		       skb->len, L2CAP_SIG_MTU);
5796 		l2cap_sig_send_mtu_rej(conn, ident);
5797 		goto drop;
5798 	}
5799 
5800 	while (skb->len >= L2CAP_CMD_HDR_SIZE) {
5801 		u16 len;
5802 
5803 		cmd = (void *) skb->data;
5804 		skb_pull(skb, L2CAP_CMD_HDR_SIZE);
5805 
5806 		len = le16_to_cpu(cmd->len);
5807 
5808 		BT_DBG("code 0x%2.2x len %d id 0x%2.2x", cmd->code, len,
5809 		       cmd->ident);
5810 
5811 		if (len > skb->len || !cmd->ident) {
5812 			BT_DBG("corrupted command");
5813 			l2cap_sig_send_rej(conn, cmd->ident);
5814 			skb_pull(skb, len > skb->len ? skb->len : len);
5815 			continue;
5816 		}
5817 
5818 		err = l2cap_bredr_sig_cmd(conn, cmd, len, skb->data);
5819 		if (err) {
5820 			BT_ERR("Wrong link type (%d)", err);
5821 			l2cap_sig_send_rej(conn, cmd->ident);
5822 		}
5823 
5824 		skb_pull(skb, len);
5825 	}
5826 
5827 	if (skb->len > 0) {
5828 		BT_DBG("corrupted command");
5829 		l2cap_sig_send_rej(conn, 0);
5830 	}
5831 
5832 drop:
5833 	kfree_skb(skb);
5834 }
5835 
5836 static int l2cap_check_fcs(struct l2cap_chan *chan,  struct sk_buff *skb)
5837 {
5838 	u16 our_fcs, rcv_fcs;
5839 	int hdr_size;
5840 
5841 	if (test_bit(FLAG_EXT_CTRL, &chan->flags))
5842 		hdr_size = L2CAP_EXT_HDR_SIZE;
5843 	else
5844 		hdr_size = L2CAP_ENH_HDR_SIZE;
5845 
5846 	if (chan->fcs == L2CAP_FCS_CRC16) {
5847 		skb_trim(skb, skb->len - L2CAP_FCS_SIZE);
5848 		rcv_fcs = get_unaligned_le16(skb->data + skb->len);
5849 		our_fcs = crc16(0, skb->data - hdr_size, skb->len + hdr_size);
5850 
5851 		if (our_fcs != rcv_fcs)
5852 			return -EBADMSG;
5853 	}
5854 	return 0;
5855 }
5856 
5857 static void l2cap_send_i_or_rr_or_rnr(struct l2cap_chan *chan)
5858 {
5859 	struct l2cap_ctrl control;
5860 
5861 	BT_DBG("chan %p", chan);
5862 
5863 	memset(&control, 0, sizeof(control));
5864 	control.sframe = 1;
5865 	control.final = 1;
5866 	control.reqseq = chan->buffer_seq;
5867 	set_bit(CONN_SEND_FBIT, &chan->conn_state);
5868 
5869 	if (test_bit(CONN_LOCAL_BUSY, &chan->conn_state)) {
5870 		control.super = L2CAP_SUPER_RNR;
5871 		l2cap_send_sframe(chan, &control);
5872 	}
5873 
5874 	if (test_and_clear_bit(CONN_REMOTE_BUSY, &chan->conn_state) &&
5875 	    chan->unacked_frames > 0)
5876 		__set_retrans_timer(chan);
5877 
5878 	/* Send pending iframes */
5879 	l2cap_ertm_send(chan);
5880 
5881 	if (!test_bit(CONN_LOCAL_BUSY, &chan->conn_state) &&
5882 	    test_bit(CONN_SEND_FBIT, &chan->conn_state)) {
5883 		/* F-bit wasn't sent in an s-frame or i-frame yet, so
5884 		 * send it now.
5885 		 */
5886 		control.super = L2CAP_SUPER_RR;
5887 		l2cap_send_sframe(chan, &control);
5888 	}
5889 }
5890 
5891 static void append_skb_frag(struct sk_buff *skb, struct sk_buff *new_frag,
5892 			    struct sk_buff **last_frag)
5893 {
5894 	/* skb->len reflects data in skb as well as all fragments
5895 	 * skb->data_len reflects only data in fragments
5896 	 */
5897 	if (!skb_has_frag_list(skb))
5898 		skb_shinfo(skb)->frag_list = new_frag;
5899 
5900 	new_frag->next = NULL;
5901 
5902 	(*last_frag)->next = new_frag;
5903 	*last_frag = new_frag;
5904 
5905 	skb->len += new_frag->len;
5906 	skb->data_len += new_frag->len;
5907 	skb->truesize += new_frag->truesize;
5908 }
5909 
5910 static int l2cap_reassemble_sdu(struct l2cap_chan *chan, struct sk_buff *skb,
5911 				struct l2cap_ctrl *control)
5912 {
5913 	int err = -EINVAL;
5914 
5915 	switch (control->sar) {
5916 	case L2CAP_SAR_UNSEGMENTED:
5917 		if (chan->sdu)
5918 			break;
5919 
5920 		err = chan->ops->recv(chan, skb);
5921 		break;
5922 
5923 	case L2CAP_SAR_START:
5924 		if (chan->sdu)
5925 			break;
5926 
5927 		if (!pskb_may_pull(skb, L2CAP_SDULEN_SIZE))
5928 			break;
5929 
5930 		chan->sdu_len = get_unaligned_le16(skb->data);
5931 		skb_pull(skb, L2CAP_SDULEN_SIZE);
5932 
5933 		if (chan->sdu_len > chan->imtu) {
5934 			err = -EMSGSIZE;
5935 			break;
5936 		}
5937 
5938 		if (skb->len >= chan->sdu_len)
5939 			break;
5940 
5941 		chan->sdu = skb;
5942 		chan->sdu_last_frag = skb;
5943 
5944 		skb = NULL;
5945 		err = 0;
5946 		break;
5947 
5948 	case L2CAP_SAR_CONTINUE:
5949 		if (!chan->sdu)
5950 			break;
5951 
5952 		append_skb_frag(chan->sdu, skb,
5953 				&chan->sdu_last_frag);
5954 		skb = NULL;
5955 
5956 		if (chan->sdu->len >= chan->sdu_len)
5957 			break;
5958 
5959 		err = 0;
5960 		break;
5961 
5962 	case L2CAP_SAR_END:
5963 		if (!chan->sdu)
5964 			break;
5965 
5966 		append_skb_frag(chan->sdu, skb,
5967 				&chan->sdu_last_frag);
5968 		skb = NULL;
5969 
5970 		if (chan->sdu->len != chan->sdu_len)
5971 			break;
5972 
5973 		err = chan->ops->recv(chan, chan->sdu);
5974 
5975 		if (!err) {
5976 			/* Reassembly complete */
5977 			chan->sdu = NULL;
5978 			chan->sdu_last_frag = NULL;
5979 			chan->sdu_len = 0;
5980 		}
5981 		break;
5982 	}
5983 
5984 	if (err) {
5985 		kfree_skb(skb);
5986 		kfree_skb(chan->sdu);
5987 		chan->sdu = NULL;
5988 		chan->sdu_last_frag = NULL;
5989 		chan->sdu_len = 0;
5990 	}
5991 
5992 	return err;
5993 }
5994 
5995 static int l2cap_resegment(struct l2cap_chan *chan)
5996 {
5997 	/* Placeholder */
5998 	return 0;
5999 }
6000 
6001 void l2cap_chan_busy(struct l2cap_chan *chan, int busy)
6002 {
6003 	u8 event;
6004 
6005 	if (chan->mode != L2CAP_MODE_ERTM)
6006 		return;
6007 
6008 	event = busy ? L2CAP_EV_LOCAL_BUSY_DETECTED : L2CAP_EV_LOCAL_BUSY_CLEAR;
6009 	l2cap_tx(chan, NULL, NULL, event);
6010 }
6011 
6012 static int l2cap_rx_queued_iframes(struct l2cap_chan *chan)
6013 {
6014 	int err = 0;
6015 	/* Pass sequential frames to l2cap_reassemble_sdu()
6016 	 * until a gap is encountered.
6017 	 */
6018 
6019 	BT_DBG("chan %p", chan);
6020 
6021 	while (!test_bit(CONN_LOCAL_BUSY, &chan->conn_state)) {
6022 		struct sk_buff *skb;
6023 		BT_DBG("Searching for skb with txseq %d (queue len %d)",
6024 		       chan->buffer_seq, skb_queue_len(&chan->srej_q));
6025 
6026 		skb = l2cap_ertm_seq_in_queue(&chan->srej_q, chan->buffer_seq);
6027 
6028 		if (!skb)
6029 			break;
6030 
6031 		skb_unlink(skb, &chan->srej_q);
6032 		chan->buffer_seq = __next_seq(chan, chan->buffer_seq);
6033 		err = l2cap_reassemble_sdu(chan, skb, &bt_cb(skb)->l2cap);
6034 		if (err)
6035 			break;
6036 	}
6037 
6038 	if (skb_queue_empty(&chan->srej_q)) {
6039 		chan->rx_state = L2CAP_RX_STATE_RECV;
6040 		l2cap_send_ack(chan);
6041 	}
6042 
6043 	return err;
6044 }
6045 
6046 static void l2cap_handle_srej(struct l2cap_chan *chan,
6047 			      struct l2cap_ctrl *control)
6048 {
6049 	struct sk_buff *skb;
6050 
6051 	BT_DBG("chan %p, control %p", chan, control);
6052 
6053 	if (control->reqseq == chan->next_tx_seq) {
6054 		BT_DBG("Invalid reqseq %d, disconnecting", control->reqseq);
6055 		l2cap_send_disconn_req(chan, ECONNRESET);
6056 		return;
6057 	}
6058 
6059 	skb = l2cap_ertm_seq_in_queue(&chan->tx_q, control->reqseq);
6060 
6061 	if (skb == NULL) {
6062 		BT_DBG("Seq %d not available for retransmission",
6063 		       control->reqseq);
6064 		return;
6065 	}
6066 
6067 	if (chan->max_tx != 0 && bt_cb(skb)->l2cap.retries >= chan->max_tx) {
6068 		BT_DBG("Retry limit exceeded (%d)", chan->max_tx);
6069 		l2cap_send_disconn_req(chan, ECONNRESET);
6070 		return;
6071 	}
6072 
6073 	clear_bit(CONN_REMOTE_BUSY, &chan->conn_state);
6074 
6075 	if (control->poll) {
6076 		l2cap_pass_to_tx(chan, control);
6077 
6078 		set_bit(CONN_SEND_FBIT, &chan->conn_state);
6079 		l2cap_retransmit(chan, control);
6080 		l2cap_ertm_send(chan);
6081 
6082 		if (chan->tx_state == L2CAP_TX_STATE_WAIT_F) {
6083 			set_bit(CONN_SREJ_ACT, &chan->conn_state);
6084 			chan->srej_save_reqseq = control->reqseq;
6085 		}
6086 	} else {
6087 		l2cap_pass_to_tx_fbit(chan, control);
6088 
6089 		if (control->final) {
6090 			if (chan->srej_save_reqseq != control->reqseq ||
6091 			    !test_and_clear_bit(CONN_SREJ_ACT,
6092 						&chan->conn_state))
6093 				l2cap_retransmit(chan, control);
6094 		} else {
6095 			l2cap_retransmit(chan, control);
6096 			if (chan->tx_state == L2CAP_TX_STATE_WAIT_F) {
6097 				set_bit(CONN_SREJ_ACT, &chan->conn_state);
6098 				chan->srej_save_reqseq = control->reqseq;
6099 			}
6100 		}
6101 	}
6102 }
6103 
6104 static void l2cap_handle_rej(struct l2cap_chan *chan,
6105 			     struct l2cap_ctrl *control)
6106 {
6107 	struct sk_buff *skb;
6108 
6109 	BT_DBG("chan %p, control %p", chan, control);
6110 
6111 	if (control->reqseq == chan->next_tx_seq) {
6112 		BT_DBG("Invalid reqseq %d, disconnecting", control->reqseq);
6113 		l2cap_send_disconn_req(chan, ECONNRESET);
6114 		return;
6115 	}
6116 
6117 	skb = l2cap_ertm_seq_in_queue(&chan->tx_q, control->reqseq);
6118 
6119 	if (chan->max_tx && skb &&
6120 	    bt_cb(skb)->l2cap.retries >= chan->max_tx) {
6121 		BT_DBG("Retry limit exceeded (%d)", chan->max_tx);
6122 		l2cap_send_disconn_req(chan, ECONNRESET);
6123 		return;
6124 	}
6125 
6126 	clear_bit(CONN_REMOTE_BUSY, &chan->conn_state);
6127 
6128 	l2cap_pass_to_tx(chan, control);
6129 
6130 	if (control->final) {
6131 		if (!test_and_clear_bit(CONN_REJ_ACT, &chan->conn_state))
6132 			l2cap_retransmit_all(chan, control);
6133 	} else {
6134 		l2cap_retransmit_all(chan, control);
6135 		l2cap_ertm_send(chan);
6136 		if (chan->tx_state == L2CAP_TX_STATE_WAIT_F)
6137 			set_bit(CONN_REJ_ACT, &chan->conn_state);
6138 	}
6139 }
6140 
6141 static u8 l2cap_classify_txseq(struct l2cap_chan *chan, u16 txseq)
6142 {
6143 	BT_DBG("chan %p, txseq %d", chan, txseq);
6144 
6145 	BT_DBG("last_acked_seq %d, expected_tx_seq %d", chan->last_acked_seq,
6146 	       chan->expected_tx_seq);
6147 
6148 	if (chan->rx_state == L2CAP_RX_STATE_SREJ_SENT) {
6149 		if (__seq_offset(chan, txseq, chan->last_acked_seq) >=
6150 		    chan->tx_win) {
6151 			/* See notes below regarding "double poll" and
6152 			 * invalid packets.
6153 			 */
6154 			if (chan->tx_win <= ((chan->tx_win_max + 1) >> 1)) {
6155 				BT_DBG("Invalid/Ignore - after SREJ");
6156 				return L2CAP_TXSEQ_INVALID_IGNORE;
6157 			} else {
6158 				BT_DBG("Invalid - in window after SREJ sent");
6159 				return L2CAP_TXSEQ_INVALID;
6160 			}
6161 		}
6162 
6163 		if (chan->srej_list.head == txseq) {
6164 			BT_DBG("Expected SREJ");
6165 			return L2CAP_TXSEQ_EXPECTED_SREJ;
6166 		}
6167 
6168 		if (l2cap_ertm_seq_in_queue(&chan->srej_q, txseq)) {
6169 			BT_DBG("Duplicate SREJ - txseq already stored");
6170 			return L2CAP_TXSEQ_DUPLICATE_SREJ;
6171 		}
6172 
6173 		if (l2cap_seq_list_contains(&chan->srej_list, txseq)) {
6174 			BT_DBG("Unexpected SREJ - not requested");
6175 			return L2CAP_TXSEQ_UNEXPECTED_SREJ;
6176 		}
6177 	}
6178 
6179 	if (chan->expected_tx_seq == txseq) {
6180 		if (__seq_offset(chan, txseq, chan->last_acked_seq) >=
6181 		    chan->tx_win) {
6182 			BT_DBG("Invalid - txseq outside tx window");
6183 			return L2CAP_TXSEQ_INVALID;
6184 		} else {
6185 			BT_DBG("Expected");
6186 			return L2CAP_TXSEQ_EXPECTED;
6187 		}
6188 	}
6189 
6190 	if (__seq_offset(chan, txseq, chan->last_acked_seq) <
6191 	    __seq_offset(chan, chan->expected_tx_seq, chan->last_acked_seq)) {
6192 		BT_DBG("Duplicate - expected_tx_seq later than txseq");
6193 		return L2CAP_TXSEQ_DUPLICATE;
6194 	}
6195 
6196 	if (__seq_offset(chan, txseq, chan->last_acked_seq) >= chan->tx_win) {
6197 		/* A source of invalid packets is a "double poll" condition,
6198 		 * where delays cause us to send multiple poll packets.  If
6199 		 * the remote stack receives and processes both polls,
6200 		 * sequence numbers can wrap around in such a way that a
6201 		 * resent frame has a sequence number that looks like new data
6202 		 * with a sequence gap.  This would trigger an erroneous SREJ
6203 		 * request.
6204 		 *
6205 		 * Fortunately, this is impossible with a tx window that's
6206 		 * less than half of the maximum sequence number, which allows
6207 		 * invalid frames to be safely ignored.
6208 		 *
6209 		 * With tx window sizes greater than half of the tx window
6210 		 * maximum, the frame is invalid and cannot be ignored.  This
6211 		 * causes a disconnect.
6212 		 */
6213 
6214 		if (chan->tx_win <= ((chan->tx_win_max + 1) >> 1)) {
6215 			BT_DBG("Invalid/Ignore - txseq outside tx window");
6216 			return L2CAP_TXSEQ_INVALID_IGNORE;
6217 		} else {
6218 			BT_DBG("Invalid - txseq outside tx window");
6219 			return L2CAP_TXSEQ_INVALID;
6220 		}
6221 	} else {
6222 		BT_DBG("Unexpected - txseq indicates missing frames");
6223 		return L2CAP_TXSEQ_UNEXPECTED;
6224 	}
6225 }
6226 
6227 static int l2cap_rx_state_recv(struct l2cap_chan *chan,
6228 			       struct l2cap_ctrl *control,
6229 			       struct sk_buff *skb, u8 event)
6230 {
6231 	struct l2cap_ctrl local_control;
6232 	int err = 0;
6233 	bool skb_in_use = false;
6234 
6235 	BT_DBG("chan %p, control %p, skb %p, event %d", chan, control, skb,
6236 	       event);
6237 
6238 	switch (event) {
6239 	case L2CAP_EV_RECV_IFRAME:
6240 		switch (l2cap_classify_txseq(chan, control->txseq)) {
6241 		case L2CAP_TXSEQ_EXPECTED:
6242 			l2cap_pass_to_tx(chan, control);
6243 
6244 			if (test_bit(CONN_LOCAL_BUSY, &chan->conn_state)) {
6245 				BT_DBG("Busy, discarding expected seq %d",
6246 				       control->txseq);
6247 				break;
6248 			}
6249 
6250 			chan->expected_tx_seq = __next_seq(chan,
6251 							   control->txseq);
6252 
6253 			chan->buffer_seq = chan->expected_tx_seq;
6254 			skb_in_use = true;
6255 
6256 			/* l2cap_reassemble_sdu may free skb, hence invalidate
6257 			 * control, so make a copy in advance to use it after
6258 			 * l2cap_reassemble_sdu returns and to avoid the race
6259 			 * condition, for example:
6260 			 *
6261 			 * The current thread calls:
6262 			 *   l2cap_reassemble_sdu
6263 			 *     chan->ops->recv == l2cap_sock_recv_cb
6264 			 *       __sock_queue_rcv_skb
6265 			 * Another thread calls:
6266 			 *   bt_sock_recvmsg
6267 			 *     skb_recv_datagram
6268 			 *     skb_free_datagram
6269 			 * Then the current thread tries to access control, but
6270 			 * it was freed by skb_free_datagram.
6271 			 */
6272 			local_control = *control;
6273 			err = l2cap_reassemble_sdu(chan, skb, control);
6274 			if (err)
6275 				break;
6276 
6277 			if (local_control.final) {
6278 				if (!test_and_clear_bit(CONN_REJ_ACT,
6279 							&chan->conn_state)) {
6280 					local_control.final = 0;
6281 					l2cap_retransmit_all(chan, &local_control);
6282 					l2cap_ertm_send(chan);
6283 				}
6284 			}
6285 
6286 			if (!test_bit(CONN_LOCAL_BUSY, &chan->conn_state))
6287 				l2cap_send_ack(chan);
6288 			break;
6289 		case L2CAP_TXSEQ_UNEXPECTED:
6290 			l2cap_pass_to_tx(chan, control);
6291 
6292 			/* Can't issue SREJ frames in the local busy state.
6293 			 * Drop this frame, it will be seen as missing
6294 			 * when local busy is exited.
6295 			 */
6296 			if (test_bit(CONN_LOCAL_BUSY, &chan->conn_state)) {
6297 				BT_DBG("Busy, discarding unexpected seq %d",
6298 				       control->txseq);
6299 				break;
6300 			}
6301 
6302 			/* There was a gap in the sequence, so an SREJ
6303 			 * must be sent for each missing frame.  The
6304 			 * current frame is stored for later use.
6305 			 */
6306 			skb_queue_tail(&chan->srej_q, skb);
6307 			skb_in_use = true;
6308 			BT_DBG("Queued %p (queue len %d)", skb,
6309 			       skb_queue_len(&chan->srej_q));
6310 
6311 			clear_bit(CONN_SREJ_ACT, &chan->conn_state);
6312 			l2cap_seq_list_clear(&chan->srej_list);
6313 			l2cap_send_srej(chan, control->txseq);
6314 
6315 			chan->rx_state = L2CAP_RX_STATE_SREJ_SENT;
6316 			break;
6317 		case L2CAP_TXSEQ_DUPLICATE:
6318 			l2cap_pass_to_tx(chan, control);
6319 			break;
6320 		case L2CAP_TXSEQ_INVALID_IGNORE:
6321 			break;
6322 		case L2CAP_TXSEQ_INVALID:
6323 		default:
6324 			l2cap_send_disconn_req(chan, ECONNRESET);
6325 			break;
6326 		}
6327 		break;
6328 	case L2CAP_EV_RECV_RR:
6329 		l2cap_pass_to_tx(chan, control);
6330 		if (control->final) {
6331 			clear_bit(CONN_REMOTE_BUSY, &chan->conn_state);
6332 
6333 			if (!test_and_clear_bit(CONN_REJ_ACT,
6334 						&chan->conn_state)) {
6335 				control->final = 0;
6336 				l2cap_retransmit_all(chan, control);
6337 			}
6338 
6339 			l2cap_ertm_send(chan);
6340 		} else if (control->poll) {
6341 			l2cap_send_i_or_rr_or_rnr(chan);
6342 		} else {
6343 			if (test_and_clear_bit(CONN_REMOTE_BUSY,
6344 					       &chan->conn_state) &&
6345 			    chan->unacked_frames)
6346 				__set_retrans_timer(chan);
6347 
6348 			l2cap_ertm_send(chan);
6349 		}
6350 		break;
6351 	case L2CAP_EV_RECV_RNR:
6352 		set_bit(CONN_REMOTE_BUSY, &chan->conn_state);
6353 		l2cap_pass_to_tx(chan, control);
6354 		if (control && control->poll) {
6355 			set_bit(CONN_SEND_FBIT, &chan->conn_state);
6356 			l2cap_send_rr_or_rnr(chan, 0);
6357 		}
6358 		__clear_retrans_timer(chan);
6359 		l2cap_seq_list_clear(&chan->retrans_list);
6360 		break;
6361 	case L2CAP_EV_RECV_REJ:
6362 		l2cap_handle_rej(chan, control);
6363 		break;
6364 	case L2CAP_EV_RECV_SREJ:
6365 		l2cap_handle_srej(chan, control);
6366 		break;
6367 	default:
6368 		break;
6369 	}
6370 
6371 	if (skb && !skb_in_use) {
6372 		BT_DBG("Freeing %p", skb);
6373 		kfree_skb(skb);
6374 	}
6375 
6376 	return err;
6377 }
6378 
6379 static int l2cap_rx_state_srej_sent(struct l2cap_chan *chan,
6380 				    struct l2cap_ctrl *control,
6381 				    struct sk_buff *skb, u8 event)
6382 {
6383 	int err = 0;
6384 	u16 txseq = control->txseq;
6385 	bool skb_in_use = false;
6386 
6387 	BT_DBG("chan %p, control %p, skb %p, event %d", chan, control, skb,
6388 	       event);
6389 
6390 	switch (event) {
6391 	case L2CAP_EV_RECV_IFRAME:
6392 		switch (l2cap_classify_txseq(chan, txseq)) {
6393 		case L2CAP_TXSEQ_EXPECTED:
6394 			/* Keep frame for reassembly later */
6395 			l2cap_pass_to_tx(chan, control);
6396 			skb_queue_tail(&chan->srej_q, skb);
6397 			skb_in_use = true;
6398 			BT_DBG("Queued %p (queue len %d)", skb,
6399 			       skb_queue_len(&chan->srej_q));
6400 
6401 			chan->expected_tx_seq = __next_seq(chan, txseq);
6402 			break;
6403 		case L2CAP_TXSEQ_EXPECTED_SREJ:
6404 			l2cap_seq_list_pop(&chan->srej_list);
6405 
6406 			l2cap_pass_to_tx(chan, control);
6407 			skb_queue_tail(&chan->srej_q, skb);
6408 			skb_in_use = true;
6409 			BT_DBG("Queued %p (queue len %d)", skb,
6410 			       skb_queue_len(&chan->srej_q));
6411 
6412 			err = l2cap_rx_queued_iframes(chan);
6413 			if (err)
6414 				break;
6415 
6416 			break;
6417 		case L2CAP_TXSEQ_UNEXPECTED:
6418 			/* Got a frame that can't be reassembled yet.
6419 			 * Save it for later, and send SREJs to cover
6420 			 * the missing frames.
6421 			 */
6422 			skb_queue_tail(&chan->srej_q, skb);
6423 			skb_in_use = true;
6424 			BT_DBG("Queued %p (queue len %d)", skb,
6425 			       skb_queue_len(&chan->srej_q));
6426 
6427 			l2cap_pass_to_tx(chan, control);
6428 			l2cap_send_srej(chan, control->txseq);
6429 			break;
6430 		case L2CAP_TXSEQ_UNEXPECTED_SREJ:
6431 			/* This frame was requested with an SREJ, but
6432 			 * some expected retransmitted frames are
6433 			 * missing.  Request retransmission of missing
6434 			 * SREJ'd frames.
6435 			 */
6436 			skb_queue_tail(&chan->srej_q, skb);
6437 			skb_in_use = true;
6438 			BT_DBG("Queued %p (queue len %d)", skb,
6439 			       skb_queue_len(&chan->srej_q));
6440 
6441 			l2cap_pass_to_tx(chan, control);
6442 			l2cap_send_srej_list(chan, control->txseq);
6443 			break;
6444 		case L2CAP_TXSEQ_DUPLICATE_SREJ:
6445 			/* We've already queued this frame.  Drop this copy. */
6446 			l2cap_pass_to_tx(chan, control);
6447 			break;
6448 		case L2CAP_TXSEQ_DUPLICATE:
6449 			/* Expecting a later sequence number, so this frame
6450 			 * was already received.  Ignore it completely.
6451 			 */
6452 			break;
6453 		case L2CAP_TXSEQ_INVALID_IGNORE:
6454 			break;
6455 		case L2CAP_TXSEQ_INVALID:
6456 		default:
6457 			l2cap_send_disconn_req(chan, ECONNRESET);
6458 			break;
6459 		}
6460 		break;
6461 	case L2CAP_EV_RECV_RR:
6462 		l2cap_pass_to_tx(chan, control);
6463 		if (control->final) {
6464 			clear_bit(CONN_REMOTE_BUSY, &chan->conn_state);
6465 
6466 			if (!test_and_clear_bit(CONN_REJ_ACT,
6467 						&chan->conn_state)) {
6468 				control->final = 0;
6469 				l2cap_retransmit_all(chan, control);
6470 			}
6471 
6472 			l2cap_ertm_send(chan);
6473 		} else if (control->poll) {
6474 			if (test_and_clear_bit(CONN_REMOTE_BUSY,
6475 					       &chan->conn_state) &&
6476 			    chan->unacked_frames) {
6477 				__set_retrans_timer(chan);
6478 			}
6479 
6480 			set_bit(CONN_SEND_FBIT, &chan->conn_state);
6481 			l2cap_send_srej_tail(chan);
6482 		} else {
6483 			if (test_and_clear_bit(CONN_REMOTE_BUSY,
6484 					       &chan->conn_state) &&
6485 			    chan->unacked_frames)
6486 				__set_retrans_timer(chan);
6487 
6488 			l2cap_send_ack(chan);
6489 		}
6490 		break;
6491 	case L2CAP_EV_RECV_RNR:
6492 		set_bit(CONN_REMOTE_BUSY, &chan->conn_state);
6493 		l2cap_pass_to_tx(chan, control);
6494 		if (control->poll) {
6495 			l2cap_send_srej_tail(chan);
6496 		} else {
6497 			struct l2cap_ctrl rr_control;
6498 			memset(&rr_control, 0, sizeof(rr_control));
6499 			rr_control.sframe = 1;
6500 			rr_control.super = L2CAP_SUPER_RR;
6501 			rr_control.reqseq = chan->buffer_seq;
6502 			l2cap_send_sframe(chan, &rr_control);
6503 		}
6504 
6505 		break;
6506 	case L2CAP_EV_RECV_REJ:
6507 		l2cap_handle_rej(chan, control);
6508 		break;
6509 	case L2CAP_EV_RECV_SREJ:
6510 		l2cap_handle_srej(chan, control);
6511 		break;
6512 	}
6513 
6514 	if (skb && !skb_in_use) {
6515 		BT_DBG("Freeing %p", skb);
6516 		kfree_skb(skb);
6517 	}
6518 
6519 	return err;
6520 }
6521 
6522 static int l2cap_finish_move(struct l2cap_chan *chan)
6523 {
6524 	BT_DBG("chan %p", chan);
6525 
6526 	chan->rx_state = L2CAP_RX_STATE_RECV;
6527 	chan->conn->mtu = chan->conn->hcon->mtu;
6528 
6529 	return l2cap_resegment(chan);
6530 }
6531 
6532 static int l2cap_rx_state_wait_p(struct l2cap_chan *chan,
6533 				 struct l2cap_ctrl *control,
6534 				 struct sk_buff *skb, u8 event)
6535 {
6536 	int err;
6537 
6538 	BT_DBG("chan %p, control %p, skb %p, event %d", chan, control, skb,
6539 	       event);
6540 
6541 	if (!control->poll)
6542 		return -EPROTO;
6543 
6544 	l2cap_process_reqseq(chan, control->reqseq);
6545 
6546 	if (!skb_queue_empty(&chan->tx_q))
6547 		chan->tx_send_head = skb_peek(&chan->tx_q);
6548 	else
6549 		chan->tx_send_head = NULL;
6550 
6551 	/* Rewind next_tx_seq to the point expected
6552 	 * by the receiver.
6553 	 */
6554 	chan->next_tx_seq = control->reqseq;
6555 	chan->unacked_frames = 0;
6556 
6557 	err = l2cap_finish_move(chan);
6558 	if (err)
6559 		return err;
6560 
6561 	set_bit(CONN_SEND_FBIT, &chan->conn_state);
6562 	l2cap_send_i_or_rr_or_rnr(chan);
6563 
6564 	if (event == L2CAP_EV_RECV_IFRAME)
6565 		return -EPROTO;
6566 
6567 	return l2cap_rx_state_recv(chan, control, NULL, event);
6568 }
6569 
6570 static int l2cap_rx_state_wait_f(struct l2cap_chan *chan,
6571 				 struct l2cap_ctrl *control,
6572 				 struct sk_buff *skb, u8 event)
6573 {
6574 	int err;
6575 
6576 	if (!control->final)
6577 		return -EPROTO;
6578 
6579 	clear_bit(CONN_REMOTE_BUSY, &chan->conn_state);
6580 
6581 	chan->rx_state = L2CAP_RX_STATE_RECV;
6582 	l2cap_process_reqseq(chan, control->reqseq);
6583 
6584 	if (!skb_queue_empty(&chan->tx_q))
6585 		chan->tx_send_head = skb_peek(&chan->tx_q);
6586 	else
6587 		chan->tx_send_head = NULL;
6588 
6589 	/* Rewind next_tx_seq to the point expected
6590 	 * by the receiver.
6591 	 */
6592 	chan->next_tx_seq = control->reqseq;
6593 	chan->unacked_frames = 0;
6594 	chan->conn->mtu = chan->conn->hcon->mtu;
6595 
6596 	err = l2cap_resegment(chan);
6597 
6598 	if (!err)
6599 		err = l2cap_rx_state_recv(chan, control, skb, event);
6600 
6601 	return err;
6602 }
6603 
6604 static bool __valid_reqseq(struct l2cap_chan *chan, u16 reqseq)
6605 {
6606 	/* Make sure reqseq is for a packet that has been sent but not acked */
6607 	u16 unacked;
6608 
6609 	unacked = __seq_offset(chan, chan->next_tx_seq, chan->expected_ack_seq);
6610 	return __seq_offset(chan, chan->next_tx_seq, reqseq) <= unacked;
6611 }
6612 
6613 static int l2cap_rx(struct l2cap_chan *chan, struct l2cap_ctrl *control,
6614 		    struct sk_buff *skb, u8 event)
6615 {
6616 	int err = 0;
6617 
6618 	BT_DBG("chan %p, control %p, skb %p, event %d, state %d", chan,
6619 	       control, skb, event, chan->rx_state);
6620 
6621 	if (__valid_reqseq(chan, control->reqseq)) {
6622 		switch (chan->rx_state) {
6623 		case L2CAP_RX_STATE_RECV:
6624 			err = l2cap_rx_state_recv(chan, control, skb, event);
6625 			break;
6626 		case L2CAP_RX_STATE_SREJ_SENT:
6627 			err = l2cap_rx_state_srej_sent(chan, control, skb,
6628 						       event);
6629 			break;
6630 		case L2CAP_RX_STATE_WAIT_P:
6631 			err = l2cap_rx_state_wait_p(chan, control, skb, event);
6632 			break;
6633 		case L2CAP_RX_STATE_WAIT_F:
6634 			err = l2cap_rx_state_wait_f(chan, control, skb, event);
6635 			break;
6636 		default:
6637 			/* shut it down */
6638 			break;
6639 		}
6640 	} else {
6641 		BT_DBG("Invalid reqseq %d (next_tx_seq %d, expected_ack_seq %d",
6642 		       control->reqseq, chan->next_tx_seq,
6643 		       chan->expected_ack_seq);
6644 		l2cap_send_disconn_req(chan, ECONNRESET);
6645 	}
6646 
6647 	return err;
6648 }
6649 
6650 static int l2cap_stream_rx(struct l2cap_chan *chan, struct l2cap_ctrl *control,
6651 			   struct sk_buff *skb)
6652 {
6653 	/* l2cap_reassemble_sdu may free skb, hence invalidate control, so store
6654 	 * the txseq field in advance to use it after l2cap_reassemble_sdu
6655 	 * returns and to avoid the race condition, for example:
6656 	 *
6657 	 * The current thread calls:
6658 	 *   l2cap_reassemble_sdu
6659 	 *     chan->ops->recv == l2cap_sock_recv_cb
6660 	 *       __sock_queue_rcv_skb
6661 	 * Another thread calls:
6662 	 *   bt_sock_recvmsg
6663 	 *     skb_recv_datagram
6664 	 *     skb_free_datagram
6665 	 * Then the current thread tries to access control, but it was freed by
6666 	 * skb_free_datagram.
6667 	 */
6668 	u16 txseq = control->txseq;
6669 
6670 	BT_DBG("chan %p, control %p, skb %p, state %d", chan, control, skb,
6671 	       chan->rx_state);
6672 
6673 	if (l2cap_classify_txseq(chan, txseq) == L2CAP_TXSEQ_EXPECTED) {
6674 		l2cap_pass_to_tx(chan, control);
6675 
6676 		BT_DBG("buffer_seq %u->%u", chan->buffer_seq,
6677 		       __next_seq(chan, chan->buffer_seq));
6678 
6679 		chan->buffer_seq = __next_seq(chan, chan->buffer_seq);
6680 
6681 		l2cap_reassemble_sdu(chan, skb, control);
6682 	} else {
6683 		if (chan->sdu) {
6684 			kfree_skb(chan->sdu);
6685 			chan->sdu = NULL;
6686 		}
6687 		chan->sdu_last_frag = NULL;
6688 		chan->sdu_len = 0;
6689 
6690 		if (skb) {
6691 			BT_DBG("Freeing %p", skb);
6692 			kfree_skb(skb);
6693 		}
6694 	}
6695 
6696 	chan->last_acked_seq = txseq;
6697 	chan->expected_tx_seq = __next_seq(chan, txseq);
6698 
6699 	return 0;
6700 }
6701 
6702 static int l2cap_data_rcv(struct l2cap_chan *chan, struct sk_buff *skb)
6703 {
6704 	struct l2cap_ctrl *control = &bt_cb(skb)->l2cap;
6705 	u16 len, min_len;
6706 	u8 event;
6707 
6708 	min_len = test_bit(FLAG_EXT_CTRL, &chan->flags) ?
6709 		  L2CAP_EXT_CTRL_SIZE : L2CAP_ENH_CTRL_SIZE;
6710 	if (chan->fcs == L2CAP_FCS_CRC16)
6711 		min_len += L2CAP_FCS_SIZE;
6712 
6713 	if (skb->len < min_len)
6714 		goto drop;
6715 
6716 	__unpack_control(chan, skb);
6717 
6718 	len = skb->len;
6719 
6720 	/*
6721 	 * We can just drop the corrupted I-frame here.
6722 	 * Receiver will miss it and start proper recovery
6723 	 * procedures and ask for retransmission.
6724 	 */
6725 	if (l2cap_check_fcs(chan, skb))
6726 		goto drop;
6727 
6728 	if (!control->sframe && control->sar == L2CAP_SAR_START)
6729 		len -= L2CAP_SDULEN_SIZE;
6730 
6731 	if (chan->fcs == L2CAP_FCS_CRC16)
6732 		len -= L2CAP_FCS_SIZE;
6733 
6734 	if (len > chan->mps) {
6735 		l2cap_send_disconn_req(chan, ECONNRESET);
6736 		goto drop;
6737 	}
6738 
6739 	if (chan->ops->filter) {
6740 		if (chan->ops->filter(chan, skb))
6741 			goto drop;
6742 	}
6743 
6744 	if (!control->sframe) {
6745 		int err;
6746 
6747 		BT_DBG("iframe sar %d, reqseq %d, final %d, txseq %d",
6748 		       control->sar, control->reqseq, control->final,
6749 		       control->txseq);
6750 
6751 		/* Validate F-bit - F=0 always valid, F=1 only
6752 		 * valid in TX WAIT_F
6753 		 */
6754 		if (control->final && chan->tx_state != L2CAP_TX_STATE_WAIT_F)
6755 			goto drop;
6756 
6757 		if (chan->mode != L2CAP_MODE_STREAMING) {
6758 			event = L2CAP_EV_RECV_IFRAME;
6759 			err = l2cap_rx(chan, control, skb, event);
6760 		} else {
6761 			err = l2cap_stream_rx(chan, control, skb);
6762 		}
6763 
6764 		if (err)
6765 			l2cap_send_disconn_req(chan, ECONNRESET);
6766 	} else {
6767 		const u8 rx_func_to_event[4] = {
6768 			L2CAP_EV_RECV_RR, L2CAP_EV_RECV_REJ,
6769 			L2CAP_EV_RECV_RNR, L2CAP_EV_RECV_SREJ
6770 		};
6771 
6772 		/* Only I-frames are expected in streaming mode */
6773 		if (chan->mode == L2CAP_MODE_STREAMING)
6774 			goto drop;
6775 
6776 		BT_DBG("sframe reqseq %d, final %d, poll %d, super %d",
6777 		       control->reqseq, control->final, control->poll,
6778 		       control->super);
6779 
6780 		if (len != 0) {
6781 			BT_ERR("Trailing bytes: %d in sframe", len);
6782 			l2cap_send_disconn_req(chan, ECONNRESET);
6783 			goto drop;
6784 		}
6785 
6786 		/* Validate F and P bits */
6787 		if (control->final && (control->poll ||
6788 				       chan->tx_state != L2CAP_TX_STATE_WAIT_F))
6789 			goto drop;
6790 
6791 		event = rx_func_to_event[control->super];
6792 		if (l2cap_rx(chan, control, skb, event))
6793 			l2cap_send_disconn_req(chan, ECONNRESET);
6794 	}
6795 
6796 	return 0;
6797 
6798 drop:
6799 	kfree_skb(skb);
6800 	return 0;
6801 }
6802 
6803 static void l2cap_chan_le_send_credits(struct l2cap_chan *chan)
6804 {
6805 	struct l2cap_conn *conn = chan->conn;
6806 	struct l2cap_le_credits pkt;
6807 	u16 return_credits = l2cap_le_rx_credits(chan);
6808 	int ident;
6809 
6810 	if (chan->mode != L2CAP_MODE_LE_FLOWCTL &&
6811 	    chan->mode != L2CAP_MODE_EXT_FLOWCTL)
6812 		return;
6813 
6814 	if (chan->rx_credits >= return_credits)
6815 		return;
6816 
6817 	return_credits -= chan->rx_credits;
6818 
6819 	BT_DBG("chan %p returning %u credits to sender", chan, return_credits);
6820 
6821 	chan->rx_credits += return_credits;
6822 
6823 	pkt.cid     = cpu_to_le16(chan->scid);
6824 	pkt.credits = cpu_to_le16(return_credits);
6825 
6826 	ident = l2cap_get_ident(conn);
6827 
6828 	l2cap_send_cmd(conn, ident, L2CAP_LE_CREDITS, sizeof(pkt), &pkt);
6829 
6830 	/* L2CAP_LE_CREDITS has no response so the ident is never released by
6831 	 * l2cap_put_ident() - release it right away, otherwise the tx_ida
6832 	 * range is exhausted after 254 packets and from then on credits are
6833 	 * sent with the invalid ident 0, which some remote stacks ignore,
6834 	 * stalling the channel.
6835 	 */
6836 	if (ident > 0)
6837 		ida_free(&conn->tx_ida, ident);
6838 }
6839 
6840 void l2cap_chan_rx_avail(struct l2cap_chan *chan, ssize_t rx_avail)
6841 {
6842 	if (chan->rx_avail == rx_avail)
6843 		return;
6844 
6845 	BT_DBG("chan %p has %zd bytes avail for rx", chan, rx_avail);
6846 
6847 	chan->rx_avail = rx_avail;
6848 
6849 	if (chan->state == BT_CONNECTED)
6850 		l2cap_chan_le_send_credits(chan);
6851 }
6852 
6853 static int l2cap_ecred_recv(struct l2cap_chan *chan, struct sk_buff *skb)
6854 {
6855 	int err;
6856 
6857 	BT_DBG("SDU reassemble complete: chan %p skb->len %u", chan, skb->len);
6858 
6859 	/* Wait recv to confirm reception before updating the credits */
6860 	err = chan->ops->recv(chan, skb);
6861 
6862 	if (err < 0 && chan->rx_avail != -1) {
6863 		BT_ERR("Queueing received LE L2CAP data failed");
6864 		l2cap_send_disconn_req(chan, ECONNRESET);
6865 		return err;
6866 	}
6867 
6868 	/* Update credits whenever an SDU is received */
6869 	l2cap_chan_le_send_credits(chan);
6870 
6871 	return err;
6872 }
6873 
6874 static int l2cap_ecred_data_rcv(struct l2cap_chan *chan, struct sk_buff *skb)
6875 {
6876 	int err;
6877 
6878 	if (!chan->rx_credits) {
6879 		BT_ERR("No credits to receive LE L2CAP data");
6880 		l2cap_send_disconn_req(chan, ECONNRESET);
6881 		return -ENOBUFS;
6882 	}
6883 
6884 	if (skb->len > chan->imtu) {
6885 		BT_ERR("Too big LE L2CAP PDU: len %u > %u", skb->len,
6886 		       chan->imtu);
6887 		l2cap_send_disconn_req(chan, ECONNRESET);
6888 		return -ENOBUFS;
6889 	}
6890 
6891 	if (skb->len > chan->mps) {
6892 		BT_ERR("Too big LE L2CAP MPS: len %u > %u", skb->len,
6893 		       chan->mps);
6894 		l2cap_send_disconn_req(chan, ECONNRESET);
6895 		return -ENOBUFS;
6896 	}
6897 
6898 	chan->rx_credits--;
6899 	BT_DBG("chan %p: rx_credits %u -> %u",
6900 	       chan, chan->rx_credits + 1, chan->rx_credits);
6901 
6902 	/* Update if remote had run out of credits, this should only happens
6903 	 * if the remote is not using the entire MPS.
6904 	 */
6905 	if (!chan->rx_credits)
6906 		l2cap_chan_le_send_credits(chan);
6907 
6908 	err = 0;
6909 
6910 	if (!chan->sdu) {
6911 		u16 sdu_len;
6912 
6913 		if (!pskb_may_pull(skb, L2CAP_SDULEN_SIZE)) {
6914 			err = -EINVAL;
6915 			goto failed;
6916 		}
6917 
6918 		sdu_len = get_unaligned_le16(skb->data);
6919 		skb_pull(skb, L2CAP_SDULEN_SIZE);
6920 
6921 		BT_DBG("Start of new SDU. sdu_len %u skb->len %u imtu %u",
6922 		       sdu_len, skb->len, chan->imtu);
6923 
6924 		if (sdu_len > chan->imtu) {
6925 			BT_ERR("Too big LE L2CAP SDU length: len %u > %u",
6926 			       sdu_len, chan->imtu);
6927 			l2cap_send_disconn_req(chan, ECONNRESET);
6928 			err = -EMSGSIZE;
6929 			goto failed;
6930 		}
6931 
6932 		if (skb->len > sdu_len) {
6933 			BT_ERR("Too much LE L2CAP data received");
6934 			err = -EINVAL;
6935 			goto failed;
6936 		}
6937 
6938 		if (skb->len == sdu_len)
6939 			return l2cap_ecred_recv(chan, skb);
6940 
6941 		chan->sdu = skb;
6942 		chan->sdu_len = sdu_len;
6943 		chan->sdu_last_frag = skb;
6944 
6945 		/* Detect if remote is not able to use the selected MPS */
6946 		if (skb->len + L2CAP_SDULEN_SIZE < chan->mps) {
6947 			u16 mps_len = skb->len + L2CAP_SDULEN_SIZE;
6948 
6949 			/* Adjust the number of credits */
6950 			BT_DBG("chan->mps %u -> %u", chan->mps, mps_len);
6951 			chan->mps = mps_len;
6952 			l2cap_chan_le_send_credits(chan);
6953 		}
6954 
6955 		return 0;
6956 	}
6957 
6958 	BT_DBG("SDU fragment. chan->sdu->len %u skb->len %u chan->sdu_len %u",
6959 	       chan->sdu->len, skb->len, chan->sdu_len);
6960 
6961 	if (chan->sdu->len + skb->len > chan->sdu_len) {
6962 		BT_ERR("Too much LE L2CAP data received");
6963 		l2cap_send_disconn_req(chan, ECONNRESET);
6964 		err = -EINVAL;
6965 		goto failed;
6966 	}
6967 
6968 	append_skb_frag(chan->sdu, skb, &chan->sdu_last_frag);
6969 	skb = NULL;
6970 
6971 	if (chan->sdu->len == chan->sdu_len) {
6972 		err = l2cap_ecred_recv(chan, chan->sdu);
6973 		if (!err) {
6974 			chan->sdu = NULL;
6975 			chan->sdu_last_frag = NULL;
6976 			chan->sdu_len = 0;
6977 		}
6978 	}
6979 
6980 failed:
6981 	if (err) {
6982 		kfree_skb(skb);
6983 		kfree_skb(chan->sdu);
6984 		chan->sdu = NULL;
6985 		chan->sdu_last_frag = NULL;
6986 		chan->sdu_len = 0;
6987 	}
6988 
6989 	/* We can't return an error here since we took care of the skb
6990 	 * freeing internally. An error return would cause the caller to
6991 	 * do a double-free of the skb.
6992 	 */
6993 	return 0;
6994 }
6995 
6996 static void l2cap_data_channel(struct l2cap_conn *conn, u16 cid,
6997 			       struct sk_buff *skb)
6998 {
6999 	struct l2cap_chan *chan;
7000 
7001 	chan = l2cap_get_chan_by_scid(conn, cid);
7002 	if (!chan) {
7003 		BT_DBG("unknown cid 0x%4.4x", cid);
7004 		/* Drop packet and return */
7005 		kfree_skb(skb);
7006 		return;
7007 	}
7008 
7009 	BT_DBG("chan %p, len %d", chan, skb->len);
7010 
7011 	/* If we receive data on a fixed channel before the info req/rsp
7012 	 * procedure is done simply assume that the channel is supported
7013 	 * and mark it as ready.
7014 	 */
7015 	if (chan->chan_type == L2CAP_CHAN_FIXED)
7016 		l2cap_chan_ready(chan);
7017 
7018 	if (chan->state != BT_CONNECTED)
7019 		goto drop;
7020 
7021 	switch (chan->mode) {
7022 	case L2CAP_MODE_LE_FLOWCTL:
7023 	case L2CAP_MODE_EXT_FLOWCTL:
7024 		if (l2cap_ecred_data_rcv(chan, skb) < 0)
7025 			goto drop;
7026 
7027 		goto done;
7028 
7029 	case L2CAP_MODE_BASIC:
7030 		/* If socket recv buffers overflows we drop data here
7031 		 * which is *bad* because L2CAP has to be reliable.
7032 		 * But we don't have any other choice. L2CAP doesn't
7033 		 * provide flow control mechanism. */
7034 
7035 		if (chan->imtu < skb->len) {
7036 			BT_ERR("Dropping L2CAP data: receive buffer overflow");
7037 			goto drop;
7038 		}
7039 
7040 		if (!chan->ops->recv(chan, skb))
7041 			goto done;
7042 		break;
7043 
7044 	case L2CAP_MODE_ERTM:
7045 	case L2CAP_MODE_STREAMING:
7046 		l2cap_data_rcv(chan, skb);
7047 		goto done;
7048 
7049 	default:
7050 		BT_DBG("chan %p: bad mode 0x%2.2x", chan, chan->mode);
7051 		break;
7052 	}
7053 
7054 drop:
7055 	kfree_skb(skb);
7056 
7057 done:
7058 	l2cap_chan_unlock(chan);
7059 	l2cap_chan_put(chan);
7060 }
7061 
7062 static void l2cap_conless_channel(struct l2cap_conn *conn, __le16 psm,
7063 				  struct sk_buff *skb)
7064 {
7065 	struct hci_conn *hcon = conn->hcon;
7066 	struct l2cap_chan *chan;
7067 
7068 	if (hcon->type != ACL_LINK)
7069 		goto free_skb;
7070 
7071 	chan = l2cap_global_chan_by_psm(0, psm, &hcon->src, &hcon->dst,
7072 					ACL_LINK);
7073 	if (!chan)
7074 		goto free_skb;
7075 
7076 	BT_DBG("chan %p, len %d", chan, skb->len);
7077 
7078 	l2cap_chan_lock(chan);
7079 
7080 	if (chan->state != BT_BOUND && chan->state != BT_CONNECTED)
7081 		goto drop;
7082 
7083 	if (chan->imtu < skb->len)
7084 		goto drop;
7085 
7086 	/* Store remote BD_ADDR and PSM for msg_name */
7087 	bacpy(&bt_cb(skb)->l2cap.bdaddr, &hcon->dst);
7088 	bt_cb(skb)->l2cap.psm = psm;
7089 
7090 	if (!chan->ops->recv(chan, skb)) {
7091 		l2cap_chan_unlock(chan);
7092 		l2cap_chan_put(chan);
7093 		return;
7094 	}
7095 
7096 drop:
7097 	l2cap_chan_unlock(chan);
7098 	l2cap_chan_put(chan);
7099 free_skb:
7100 	kfree_skb(skb);
7101 }
7102 
7103 static void l2cap_recv_frame(struct l2cap_conn *conn, struct sk_buff *skb)
7104 {
7105 	struct l2cap_hdr *lh = (void *) skb->data;
7106 	struct hci_conn *hcon = conn->hcon;
7107 	u16 cid, len;
7108 	__le16 psm;
7109 
7110 	if (hcon->state != BT_CONNECTED) {
7111 		BT_DBG("queueing pending rx skb");
7112 		skb_queue_tail(&conn->pending_rx, skb);
7113 		return;
7114 	}
7115 
7116 	skb_pull(skb, L2CAP_HDR_SIZE);
7117 	cid = __le16_to_cpu(lh->cid);
7118 	len = __le16_to_cpu(lh->len);
7119 
7120 	if (len != skb->len) {
7121 		kfree_skb(skb);
7122 		return;
7123 	}
7124 
7125 	/* Since we can't actively block incoming LE connections we must
7126 	 * at least ensure that we ignore incoming data from them.
7127 	 */
7128 	if (hcon->type == LE_LINK &&
7129 	    hci_bdaddr_list_lookup(&hcon->hdev->reject_list, &hcon->dst,
7130 				   bdaddr_dst_type(hcon))) {
7131 		kfree_skb(skb);
7132 		return;
7133 	}
7134 
7135 	BT_DBG("len %d, cid 0x%4.4x", len, cid);
7136 
7137 	switch (cid) {
7138 	case L2CAP_CID_SIGNALING:
7139 		l2cap_sig_channel(conn, skb);
7140 		break;
7141 
7142 	case L2CAP_CID_CONN_LESS:
7143 		if (skb->len < L2CAP_PSMLEN_SIZE) {
7144 			kfree_skb(skb);
7145 			break;
7146 		}
7147 
7148 		psm = get_unaligned((__le16 *) skb->data);
7149 		skb_pull(skb, L2CAP_PSMLEN_SIZE);
7150 		l2cap_conless_channel(conn, psm, skb);
7151 		break;
7152 
7153 	case L2CAP_CID_LE_SIGNALING:
7154 		l2cap_le_sig_channel(conn, skb);
7155 		break;
7156 
7157 	default:
7158 		l2cap_data_channel(conn, cid, skb);
7159 		break;
7160 	}
7161 }
7162 
7163 static void process_pending_rx(struct work_struct *work)
7164 {
7165 	struct l2cap_conn *conn = container_of(work, struct l2cap_conn,
7166 					       pending_rx_work);
7167 	struct sk_buff *skb;
7168 
7169 	BT_DBG("");
7170 
7171 	mutex_lock(&conn->lock);
7172 
7173 	while ((skb = skb_dequeue(&conn->pending_rx)))
7174 		l2cap_recv_frame(conn, skb);
7175 
7176 	mutex_unlock(&conn->lock);
7177 }
7178 
7179 static struct l2cap_conn *l2cap_conn_add(struct hci_conn *hcon)
7180 	__must_hold(&hcon->hdev->lock)
7181 {
7182 	struct l2cap_conn *conn = hcon->l2cap_data;
7183 	struct hci_chan *hchan;
7184 
7185 	if (conn)
7186 		return conn;
7187 
7188 	hchan = hci_chan_create(hcon);
7189 	if (!hchan)
7190 		return NULL;
7191 
7192 	conn = kzalloc_obj(*conn);
7193 	if (!conn) {
7194 		hci_chan_del(hchan);
7195 		return NULL;
7196 	}
7197 
7198 	kref_init(&conn->ref);
7199 	conn->hchan = hchan;
7200 
7201 	BT_DBG("hcon %p conn %p hchan %p", hcon, conn, hchan);
7202 
7203 	conn->mtu = hcon->mtu;
7204 	conn->feat_mask = 0;
7205 
7206 	conn->local_fixed_chan = L2CAP_FC_SIG_BREDR | L2CAP_FC_CONNLESS;
7207 
7208 	if (hci_dev_test_flag(hcon->hdev, HCI_LE_ENABLED) &&
7209 	    (bredr_sc_enabled(hcon->hdev) ||
7210 	     hci_dev_test_flag(hcon->hdev, HCI_FORCE_BREDR_SMP)))
7211 		conn->local_fixed_chan |= L2CAP_FC_SMP_BREDR;
7212 
7213 	mutex_init(&conn->lock);
7214 
7215 	INIT_LIST_HEAD(&conn->chan_l);
7216 	INIT_LIST_HEAD(&conn->users);
7217 
7218 	INIT_DELAYED_WORK(&conn->info_timer, l2cap_info_timeout);
7219 	ida_init(&conn->tx_ida);
7220 
7221 	skb_queue_head_init(&conn->pending_rx);
7222 	INIT_WORK(&conn->pending_rx_work, process_pending_rx);
7223 	INIT_DELAYED_WORK(&conn->id_addr_timer, l2cap_conn_update_id_addr);
7224 
7225 	conn->disc_reason = HCI_ERROR_REMOTE_USER_TERM;
7226 
7227 	spin_lock(&hcon->proto_lock);
7228 	conn->hcon = hci_conn_get(hcon);
7229 	hcon->l2cap_data = conn;
7230 	spin_unlock(&hcon->proto_lock);
7231 
7232 	return conn;
7233 }
7234 
7235 static bool is_valid_psm(u16 psm, u8 dst_type)
7236 {
7237 	if (!psm)
7238 		return false;
7239 
7240 	if (bdaddr_type_is_le(dst_type))
7241 		return (psm <= 0x00ff);
7242 
7243 	/* PSM must be odd and lsb of upper byte must be 0 */
7244 	return ((psm & 0x0101) == 0x0001);
7245 }
7246 
7247 struct l2cap_chan_data {
7248 	struct l2cap_chan *chan;
7249 	struct pid *pid;
7250 	int count;
7251 };
7252 
7253 static void l2cap_chan_by_pid(struct l2cap_chan *chan, void *data)
7254 {
7255 	struct l2cap_chan_data *d = data;
7256 	struct pid *pid;
7257 
7258 	if (chan == d->chan)
7259 		return;
7260 
7261 	if (!test_bit(FLAG_DEFER_SETUP, &chan->flags))
7262 		return;
7263 
7264 	pid = chan->ops->get_peer_pid(chan);
7265 
7266 	/* Only count deferred channels with the same PID/PSM */
7267 	if (d->pid != pid || chan->psm != d->chan->psm || chan->ident ||
7268 	    chan->mode != L2CAP_MODE_EXT_FLOWCTL || chan->state != BT_CONNECT)
7269 		return;
7270 
7271 	d->count++;
7272 }
7273 
7274 int l2cap_chan_connect(struct l2cap_chan *chan, __le16 psm, u16 cid,
7275 		       bdaddr_t *dst, u8 dst_type, u16 timeout)
7276 {
7277 	struct l2cap_conn *conn;
7278 	struct hci_conn *hcon;
7279 	struct hci_dev *hdev;
7280 	int err;
7281 
7282 	BT_DBG("%pMR -> %pMR (type %u) psm 0x%4.4x mode 0x%2.2x", &chan->src,
7283 	       dst, dst_type, __le16_to_cpu(psm), chan->mode);
7284 
7285 	hdev = hci_get_route(dst, &chan->src, chan->src_type);
7286 	if (!hdev)
7287 		return -EHOSTUNREACH;
7288 
7289 	hci_dev_lock(hdev);
7290 
7291 	if (!is_valid_psm(__le16_to_cpu(psm), dst_type) && !cid &&
7292 	    chan->chan_type != L2CAP_CHAN_RAW) {
7293 		err = -EINVAL;
7294 		goto done;
7295 	}
7296 
7297 	if (chan->chan_type == L2CAP_CHAN_CONN_ORIENTED && !psm) {
7298 		err = -EINVAL;
7299 		goto done;
7300 	}
7301 
7302 	if (chan->chan_type == L2CAP_CHAN_FIXED && !cid) {
7303 		err = -EINVAL;
7304 		goto done;
7305 	}
7306 
7307 	switch (chan->mode) {
7308 	case L2CAP_MODE_BASIC:
7309 		break;
7310 	case L2CAP_MODE_LE_FLOWCTL:
7311 		break;
7312 	case L2CAP_MODE_EXT_FLOWCTL:
7313 		if (!enable_ecred) {
7314 			err = -EOPNOTSUPP;
7315 			goto done;
7316 		}
7317 		break;
7318 	case L2CAP_MODE_ERTM:
7319 	case L2CAP_MODE_STREAMING:
7320 		if (!disable_ertm)
7321 			break;
7322 		fallthrough;
7323 	default:
7324 		err = -EOPNOTSUPP;
7325 		goto done;
7326 	}
7327 
7328 	switch (chan->state) {
7329 	case BT_CONNECT:
7330 	case BT_CONNECT2:
7331 	case BT_CONFIG:
7332 		/* Already connecting */
7333 		err = 0;
7334 		goto done;
7335 
7336 	case BT_CONNECTED:
7337 		/* Already connected */
7338 		err = -EISCONN;
7339 		goto done;
7340 
7341 	case BT_OPEN:
7342 	case BT_BOUND:
7343 		/* Can connect */
7344 		break;
7345 
7346 	default:
7347 		err = -EBADFD;
7348 		goto done;
7349 	}
7350 
7351 	/* Set destination address and psm */
7352 	bacpy(&chan->dst, dst);
7353 	chan->dst_type = dst_type;
7354 
7355 	chan->psm = psm;
7356 	chan->dcid = cid;
7357 
7358 	if (bdaddr_type_is_le(dst_type)) {
7359 		/* Convert from L2CAP channel address type to HCI address type
7360 		 */
7361 		if (dst_type == BDADDR_LE_PUBLIC)
7362 			dst_type = ADDR_LE_DEV_PUBLIC;
7363 		else
7364 			dst_type = ADDR_LE_DEV_RANDOM;
7365 
7366 		if (hci_dev_test_flag(hdev, HCI_ADVERTISING))
7367 			hcon = hci_connect_le(hdev, dst, dst_type, false,
7368 					      chan->sec_level, timeout,
7369 					      HCI_ROLE_SLAVE, 0, 0);
7370 		else
7371 			hcon = hci_connect_le_scan(hdev, dst, dst_type,
7372 						   chan->sec_level, timeout,
7373 						   CONN_REASON_L2CAP_CHAN);
7374 
7375 	} else {
7376 		u8 auth_type = l2cap_get_auth_type(chan);
7377 		hcon = hci_connect_acl(hdev, dst, chan->sec_level, auth_type,
7378 				       CONN_REASON_L2CAP_CHAN, timeout);
7379 	}
7380 
7381 	if (IS_ERR(hcon)) {
7382 		err = PTR_ERR(hcon);
7383 		goto done;
7384 	}
7385 
7386 	lockdep_assert_held(&hcon->hdev->lock);
7387 
7388 	conn = l2cap_conn_add(hcon);
7389 	if (!conn) {
7390 		hci_conn_drop(hcon);
7391 		err = -ENOMEM;
7392 		goto done;
7393 	}
7394 
7395 	mutex_lock(&conn->lock);
7396 	l2cap_chan_lock(chan);
7397 
7398 	if (chan->mode == L2CAP_MODE_EXT_FLOWCTL) {
7399 		struct l2cap_chan_data data;
7400 
7401 		data.chan = chan;
7402 		data.pid = chan->ops->get_peer_pid(chan);
7403 		data.count = 1;
7404 
7405 		__l2cap_chan_list(conn, l2cap_chan_by_pid, &data);
7406 
7407 		/* Leave room for non-deferred channel that ends the group. */
7408 		if (test_bit(FLAG_DEFER_SETUP, &chan->flags))
7409 			data.count += 1;
7410 
7411 		/* Check if there isn't too many channels being connected */
7412 		if (data.count > L2CAP_ECRED_CONN_SCID_MAX) {
7413 			hci_conn_drop(hcon);
7414 			err = -EPROTO;
7415 			goto chan_unlock;
7416 		}
7417 	}
7418 
7419 	if (cid && __l2cap_get_chan_by_dcid(conn, cid)) {
7420 		hci_conn_drop(hcon);
7421 		err = -EBUSY;
7422 		goto chan_unlock;
7423 	}
7424 
7425 	/* Update source addr of the socket */
7426 	bacpy(&chan->src, &hcon->src);
7427 	chan->src_type = bdaddr_src_type(hcon);
7428 
7429 	__l2cap_chan_add(conn, chan);
7430 
7431 	/* l2cap_chan_add takes its own ref so we can drop this one */
7432 	hci_conn_drop(hcon);
7433 
7434 	l2cap_state_change(chan, BT_CONNECT);
7435 	__set_chan_timer(chan, chan->ops->get_sndtimeo(chan));
7436 
7437 	/* Release chan->sport so that it can be reused by other
7438 	 * sockets (as it's only used for listening sockets).
7439 	 */
7440 	write_lock(&chan_list_lock);
7441 	chan->sport = 0;
7442 	write_unlock(&chan_list_lock);
7443 
7444 	if (hcon->state == BT_CONNECTED) {
7445 		if (chan->chan_type != L2CAP_CHAN_CONN_ORIENTED) {
7446 			__clear_chan_timer(chan);
7447 			if (l2cap_chan_check_security(chan, true))
7448 				l2cap_state_change(chan, BT_CONNECTED);
7449 		} else
7450 			l2cap_do_start(chan);
7451 	}
7452 
7453 	err = 0;
7454 
7455 chan_unlock:
7456 	l2cap_chan_unlock(chan);
7457 	mutex_unlock(&conn->lock);
7458 done:
7459 	hci_dev_unlock(hdev);
7460 	hci_dev_put(hdev);
7461 	return err;
7462 }
7463 EXPORT_SYMBOL_GPL(l2cap_chan_connect);
7464 
7465 static void l2cap_ecred_reconfigure(struct l2cap_chan *chan)
7466 {
7467 	struct l2cap_conn *conn = chan->conn;
7468 	DEFINE_RAW_FLEX(struct l2cap_ecred_reconf_req, pdu, scid, 1);
7469 
7470 	pdu->mtu = cpu_to_le16(chan->imtu);
7471 	pdu->mps = cpu_to_le16(chan->mps);
7472 	pdu->scid[0] = cpu_to_le16(chan->scid);
7473 
7474 	chan->ident = l2cap_get_ident(conn);
7475 
7476 	l2cap_send_cmd(conn, chan->ident, L2CAP_ECRED_RECONF_REQ,
7477 		       struct_size(pdu, scid, 1), pdu);
7478 }
7479 
7480 int l2cap_chan_reconfigure(struct l2cap_chan *chan, __u16 mtu)
7481 {
7482 	if (chan->imtu > mtu)
7483 		return -EINVAL;
7484 
7485 	BT_DBG("chan %p mtu 0x%4.4x", chan, mtu);
7486 
7487 	chan->imtu = mtu;
7488 
7489 	l2cap_ecred_reconfigure(chan);
7490 
7491 	return 0;
7492 }
7493 
7494 /* ---- L2CAP interface with lower layer (HCI) ---- */
7495 
7496 int l2cap_connect_ind(struct hci_dev *hdev, bdaddr_t *bdaddr)
7497 {
7498 	int exact = 0, lm1 = 0, lm2 = 0;
7499 	struct l2cap_chan *c;
7500 
7501 	BT_DBG("hdev %s, bdaddr %pMR", hdev->name, bdaddr);
7502 
7503 	/* Find listening sockets and check their link_mode */
7504 	read_lock(&chan_list_lock);
7505 	list_for_each_entry(c, &chan_list, global_l) {
7506 		if (c->state != BT_LISTEN)
7507 			continue;
7508 
7509 		if (!bacmp(&c->src, &hdev->bdaddr)) {
7510 			lm1 |= HCI_LM_ACCEPT;
7511 			if (test_bit(FLAG_ROLE_SWITCH, &c->flags))
7512 				lm1 |= HCI_LM_MASTER;
7513 			exact++;
7514 		} else if (!bacmp(&c->src, BDADDR_ANY)) {
7515 			lm2 |= HCI_LM_ACCEPT;
7516 			if (test_bit(FLAG_ROLE_SWITCH, &c->flags))
7517 				lm2 |= HCI_LM_MASTER;
7518 		}
7519 	}
7520 	read_unlock(&chan_list_lock);
7521 
7522 	return exact ? lm1 : lm2;
7523 }
7524 
7525 /* Find the next fixed channel in BT_LISTEN state, continue iteration
7526  * from an existing channel in the list or from the beginning of the
7527  * global list (by passing NULL as first parameter).
7528  */
7529 static struct l2cap_chan *l2cap_global_fixed_chan(struct l2cap_chan *c,
7530 						  struct hci_conn *hcon)
7531 {
7532 	u8 src_type = bdaddr_src_type(hcon);
7533 
7534 	read_lock(&chan_list_lock);
7535 
7536 	if (c)
7537 		c = list_next_entry(c, global_l);
7538 	else
7539 		c = list_entry(chan_list.next, typeof(*c), global_l);
7540 
7541 	list_for_each_entry_from(c, &chan_list, global_l) {
7542 		if (c->chan_type != L2CAP_CHAN_FIXED)
7543 			continue;
7544 		if (c->state != BT_LISTEN)
7545 			continue;
7546 		if (bacmp(&c->src, &hcon->src) && bacmp(&c->src, BDADDR_ANY))
7547 			continue;
7548 		if (src_type != c->src_type)
7549 			continue;
7550 
7551 		c = l2cap_chan_hold_unless_zero(c);
7552 		read_unlock(&chan_list_lock);
7553 		return c;
7554 	}
7555 
7556 	read_unlock(&chan_list_lock);
7557 
7558 	return NULL;
7559 }
7560 
7561 static void l2cap_connect_cfm(struct hci_conn *hcon, u8 status)
7562 	__must_hold(&hcon->hdev->lock)
7563 {
7564 	struct hci_dev *hdev = hcon->hdev;
7565 	struct l2cap_conn *conn;
7566 	struct l2cap_chan *pchan;
7567 	u8 dst_type;
7568 
7569 	if (hcon->type != ACL_LINK && hcon->type != LE_LINK)
7570 		return;
7571 
7572 	BT_DBG("hcon %p bdaddr %pMR status %d", hcon, &hcon->dst, status);
7573 
7574 	if (status) {
7575 		l2cap_conn_del(hcon, bt_to_errno(status));
7576 		return;
7577 	}
7578 
7579 	conn = l2cap_conn_add(hcon);
7580 	if (!conn)
7581 		return;
7582 
7583 	dst_type = bdaddr_dst_type(hcon);
7584 
7585 	/* If device is blocked, do not create channels for it */
7586 	if (hci_bdaddr_list_lookup(&hdev->reject_list, &hcon->dst, dst_type))
7587 		return;
7588 
7589 	/* Find fixed channels and notify them of the new connection. We
7590 	 * use multiple individual lookups, continuing each time where
7591 	 * we left off, because the list lock would prevent calling the
7592 	 * potentially sleeping l2cap_chan_lock() function.
7593 	 */
7594 	pchan = l2cap_global_fixed_chan(NULL, hcon);
7595 	while (pchan) {
7596 		struct l2cap_chan *chan, *next;
7597 
7598 		/* Client fixed channels should override server ones */
7599 		if (__l2cap_get_chan_by_dcid(conn, pchan->scid))
7600 			goto next;
7601 
7602 		l2cap_chan_lock(pchan);
7603 		chan = l2cap_new_connection(conn, pchan);
7604 		if (chan) {
7605 			bacpy(&chan->src, &hcon->src);
7606 			bacpy(&chan->dst, &hcon->dst);
7607 			chan->src_type = bdaddr_src_type(hcon);
7608 			chan->dst_type = dst_type;
7609 		}
7610 
7611 		l2cap_chan_unlock(pchan);
7612 next:
7613 		next = l2cap_global_fixed_chan(pchan, hcon);
7614 		l2cap_chan_put(pchan);
7615 		pchan = next;
7616 	}
7617 
7618 	l2cap_conn_ready(conn);
7619 }
7620 
7621 int l2cap_disconn_ind(struct hci_conn *hcon)
7622 {
7623 	struct l2cap_conn *conn;
7624 	int ret = HCI_ERROR_REMOTE_USER_TERM;
7625 
7626 	BT_DBG("hcon %p", hcon);
7627 
7628 	spin_lock(&hcon->proto_lock);
7629 	conn = hcon->l2cap_data;
7630 	if (conn)
7631 		ret = conn->disc_reason;
7632 	spin_unlock(&hcon->proto_lock);
7633 
7634 	return ret;
7635 }
7636 
7637 static void l2cap_disconn_cfm(struct hci_conn *hcon, u8 reason)
7638 	__must_hold(&hcon->hdev->lock)
7639 {
7640 	if (hcon->type != ACL_LINK && hcon->type != LE_LINK)
7641 		return;
7642 
7643 	BT_DBG("hcon %p reason %d", hcon, reason);
7644 
7645 	l2cap_conn_del(hcon, bt_to_errno(reason));
7646 }
7647 
7648 static inline void l2cap_check_encryption(struct l2cap_chan *chan, u8 encrypt)
7649 {
7650 	if (chan->chan_type != L2CAP_CHAN_CONN_ORIENTED)
7651 		return;
7652 
7653 	if (encrypt == 0x00) {
7654 		if (chan->sec_level == BT_SECURITY_MEDIUM) {
7655 			__set_chan_timer(chan, L2CAP_ENC_TIMEOUT);
7656 		} else if (chan->sec_level == BT_SECURITY_HIGH ||
7657 			   chan->sec_level == BT_SECURITY_FIPS)
7658 			l2cap_chan_close(chan, ECONNREFUSED);
7659 	} else {
7660 		if (chan->sec_level == BT_SECURITY_MEDIUM)
7661 			__clear_chan_timer(chan);
7662 	}
7663 }
7664 
7665 static void l2cap_security_cfm(struct hci_conn *hcon, u8 status, u8 encrypt)
7666 	__must_hold(&hcon->hdev->lock)
7667 {
7668 	struct l2cap_conn *conn = hcon->l2cap_data;
7669 	struct l2cap_chan *chan;
7670 
7671 	if (!conn)
7672 		return;
7673 
7674 	BT_DBG("conn %p status 0x%2.2x encrypt %u", conn, status, encrypt);
7675 
7676 	mutex_lock(&conn->lock);
7677 
7678 	list_for_each_entry(chan, &conn->chan_l, list) {
7679 		l2cap_chan_lock(chan);
7680 
7681 		BT_DBG("chan %p scid 0x%4.4x state %s", chan, chan->scid,
7682 		       state_to_string(chan->state));
7683 
7684 		if (!status && encrypt)
7685 			chan->sec_level = hcon->sec_level;
7686 
7687 		if (!__l2cap_no_conn_pending(chan)) {
7688 			l2cap_chan_unlock(chan);
7689 			continue;
7690 		}
7691 
7692 		if (!status && (chan->state == BT_CONNECTED ||
7693 				chan->state == BT_CONFIG)) {
7694 			chan->ops->resume(chan);
7695 			l2cap_check_encryption(chan, encrypt);
7696 			l2cap_chan_unlock(chan);
7697 			continue;
7698 		}
7699 
7700 		if (chan->state == BT_CONNECT) {
7701 			if (!status && l2cap_check_enc_key_size(hcon, chan))
7702 				l2cap_start_connection(chan);
7703 			else
7704 				__set_chan_timer(chan, L2CAP_DISC_TIMEOUT);
7705 		} else if (chan->state == BT_CONNECT2 &&
7706 			   !(chan->mode == L2CAP_MODE_EXT_FLOWCTL ||
7707 			     chan->mode == L2CAP_MODE_LE_FLOWCTL)) {
7708 			struct l2cap_conn_rsp rsp;
7709 			__u16 res, stat;
7710 
7711 			if (!status && l2cap_check_enc_key_size(hcon, chan)) {
7712 				if (test_bit(FLAG_DEFER_SETUP, &chan->flags)) {
7713 					res = L2CAP_CR_PEND;
7714 					stat = L2CAP_CS_AUTHOR_PEND;
7715 					chan->ops->defer(chan);
7716 				} else {
7717 					l2cap_state_change(chan, BT_CONFIG);
7718 					res = L2CAP_CR_SUCCESS;
7719 					stat = L2CAP_CS_NO_INFO;
7720 				}
7721 			} else {
7722 				l2cap_state_change(chan, BT_DISCONN);
7723 				__set_chan_timer(chan, L2CAP_DISC_TIMEOUT);
7724 				res = L2CAP_CR_SEC_BLOCK;
7725 				stat = L2CAP_CS_NO_INFO;
7726 			}
7727 
7728 			rsp.scid   = cpu_to_le16(chan->dcid);
7729 			rsp.dcid   = cpu_to_le16(chan->scid);
7730 			rsp.result = cpu_to_le16(res);
7731 			rsp.status = cpu_to_le16(stat);
7732 			l2cap_send_cmd(conn, chan->ident, L2CAP_CONN_RSP,
7733 				       sizeof(rsp), &rsp);
7734 
7735 			if (!test_bit(CONF_REQ_SENT, &chan->conf_state) &&
7736 			    res == L2CAP_CR_SUCCESS) {
7737 				char buf[128];
7738 				set_bit(CONF_REQ_SENT, &chan->conf_state);
7739 				l2cap_send_cmd(conn, l2cap_get_ident(conn),
7740 					       L2CAP_CONF_REQ,
7741 					       l2cap_build_conf_req(chan, buf, sizeof(buf)),
7742 					       buf);
7743 				chan->num_conf_req++;
7744 			}
7745 		}
7746 
7747 		l2cap_chan_unlock(chan);
7748 	}
7749 
7750 	mutex_unlock(&conn->lock);
7751 }
7752 
7753 /* Append fragment into frame respecting the maximum len of rx_skb */
7754 static int l2cap_recv_frag(struct l2cap_conn *conn, struct sk_buff *skb,
7755 			   u16 len)
7756 {
7757 	if (!conn->rx_skb) {
7758 		/* Allocate skb for the complete frame (with header) */
7759 		conn->rx_skb = bt_skb_alloc(len, GFP_KERNEL);
7760 		if (!conn->rx_skb)
7761 			return -ENOMEM;
7762 		/* Init rx_len */
7763 		conn->rx_len = len;
7764 
7765 		skb_set_delivery_time(conn->rx_skb, skb->tstamp,
7766 				      skb->tstamp_type);
7767 	}
7768 
7769 	/* Copy as much as the rx_skb can hold */
7770 	len = min_t(u16, len, skb->len);
7771 	skb_copy_from_linear_data(skb, skb_put(conn->rx_skb, len), len);
7772 	skb_pull(skb, len);
7773 	conn->rx_len -= len;
7774 
7775 	return len;
7776 }
7777 
7778 static int l2cap_recv_len(struct l2cap_conn *conn, struct sk_buff *skb)
7779 {
7780 	struct sk_buff *rx_skb;
7781 	int len;
7782 
7783 	/* Append just enough to complete the header */
7784 	len = l2cap_recv_frag(conn, skb, L2CAP_LEN_SIZE - conn->rx_skb->len);
7785 
7786 	/* If header could not be read just continue */
7787 	if (len < 0 || conn->rx_skb->len < L2CAP_LEN_SIZE)
7788 		return len;
7789 
7790 	rx_skb = conn->rx_skb;
7791 	len = get_unaligned_le16(rx_skb->data);
7792 
7793 	/* Check if rx_skb has enough space to received all fragments */
7794 	if (len + (L2CAP_HDR_SIZE - L2CAP_LEN_SIZE) <= skb_tailroom(rx_skb)) {
7795 		/* Update expected len */
7796 		conn->rx_len = len + (L2CAP_HDR_SIZE - L2CAP_LEN_SIZE);
7797 		return L2CAP_LEN_SIZE;
7798 	}
7799 
7800 	/* Reset conn->rx_skb since it will need to be reallocated in order to
7801 	 * fit all fragments.
7802 	 */
7803 	conn->rx_skb = NULL;
7804 
7805 	/* Reallocates rx_skb using the exact expected length */
7806 	len = l2cap_recv_frag(conn, rx_skb,
7807 			      len + (L2CAP_HDR_SIZE - L2CAP_LEN_SIZE));
7808 	kfree_skb(rx_skb);
7809 
7810 	return len;
7811 }
7812 
7813 static void l2cap_recv_reset(struct l2cap_conn *conn)
7814 {
7815 	kfree_skb(conn->rx_skb);
7816 	conn->rx_skb = NULL;
7817 	conn->rx_len = 0;
7818 }
7819 
7820 struct l2cap_conn *l2cap_conn_hold_unless_zero(struct l2cap_conn *c)
7821 {
7822 	if (!c)
7823 		return NULL;
7824 
7825 	BT_DBG("conn %p orig refcnt %u", c, kref_read(&c->ref));
7826 
7827 	if (!kref_get_unless_zero(&c->ref))
7828 		return NULL;
7829 
7830 	return c;
7831 }
7832 EXPORT_SYMBOL(l2cap_conn_hold_unless_zero);
7833 
7834 int l2cap_recv_acldata(struct hci_dev *hdev, u16 handle,
7835 		       struct sk_buff *skb, u16 flags)
7836 {
7837 	struct hci_conn *hcon;
7838 	struct l2cap_conn *conn;
7839 	int len;
7840 
7841 	/* Lock hdev for hci_conn, and race on l2cap_data vs. l2cap_conn_del */
7842 	hci_dev_lock(hdev);
7843 
7844 	hcon = hci_conn_hash_lookup_handle(hdev, handle);
7845 	if (!hcon) {
7846 		hci_dev_unlock(hdev);
7847 		kfree_skb(skb);
7848 		return -ENOENT;
7849 	}
7850 
7851 	lockdep_assert_held(&hcon->hdev->lock);
7852 
7853 	hci_conn_enter_active_mode(hcon, BT_POWER_FORCE_ACTIVE_OFF);
7854 
7855 	conn = hcon->l2cap_data;
7856 
7857 	if (!conn)
7858 		conn = l2cap_conn_add(hcon);
7859 
7860 	conn = l2cap_conn_hold_unless_zero(conn);
7861 	hcon = NULL;
7862 
7863 	hci_dev_unlock(hdev);
7864 
7865 	if (!conn) {
7866 		kfree_skb(skb);
7867 		return -EINVAL;
7868 	}
7869 
7870 	BT_DBG("conn %p len %u flags 0x%x", conn, skb->len, flags);
7871 
7872 	mutex_lock(&conn->lock);
7873 
7874 	switch (flags) {
7875 	case ACL_START:
7876 	case ACL_START_NO_FLUSH:
7877 	case ACL_COMPLETE:
7878 		if (conn->rx_skb) {
7879 			BT_ERR("Unexpected start frame (len %d)", skb->len);
7880 			l2cap_recv_reset(conn);
7881 			l2cap_conn_unreliable(conn, ECOMM);
7882 		}
7883 
7884 		/* Start fragment may not contain the L2CAP length so just
7885 		 * copy the initial byte when that happens and use conn->mtu as
7886 		 * expected length.
7887 		 */
7888 		if (skb->len < L2CAP_LEN_SIZE) {
7889 			l2cap_recv_frag(conn, skb, conn->mtu);
7890 			break;
7891 		}
7892 
7893 		len = get_unaligned_le16(skb->data) + L2CAP_HDR_SIZE;
7894 
7895 		if (len == skb->len) {
7896 			/* Complete frame received */
7897 			l2cap_recv_frame(conn, skb);
7898 			goto unlock;
7899 		}
7900 
7901 		BT_DBG("Start: total len %d, frag len %u", len, skb->len);
7902 
7903 		if (skb->len > len) {
7904 			BT_ERR("Frame is too long (len %u, expected len %d)",
7905 			       skb->len, len);
7906 			/* PTS test cases L2CAP/COS/CED/BI-14-C and BI-15-C
7907 			 * (Multiple Signaling Command in one PDU, Data
7908 			 * Truncated, BR/EDR) send a C-frame to the IUT with
7909 			 * PDU Length set to 8 and Channel ID set to the
7910 			 * correct signaling channel for the logical link.
7911 			 * The Information payload contains one L2CAP_ECHO_REQ
7912 			 * packet with Data Length set to 0 with 0 octets of
7913 			 * echo data and one invalid command packet due to
7914 			 * data truncated in PDU but present in HCI packet.
7915 			 *
7916 			 * Shorter the socket buffer to the PDU length to
7917 			 * allow to process valid commands from the PDU before
7918 			 * setting the socket unreliable.
7919 			 */
7920 			skb->len = len;
7921 			l2cap_recv_frame(conn, skb);
7922 			l2cap_conn_unreliable(conn, ECOMM);
7923 			goto unlock;
7924 		}
7925 
7926 		/* Append fragment into frame (with header) */
7927 		if (l2cap_recv_frag(conn, skb, len) < 0)
7928 			goto drop;
7929 
7930 		break;
7931 
7932 	case ACL_CONT:
7933 		BT_DBG("Cont: frag len %u (expecting %u)", skb->len, conn->rx_len);
7934 
7935 		if (!conn->rx_skb) {
7936 			BT_ERR("Unexpected continuation frame (len %d)", skb->len);
7937 			l2cap_conn_unreliable(conn, ECOMM);
7938 			goto drop;
7939 		}
7940 
7941 		/* Complete the L2CAP length if it has not been read */
7942 		if (conn->rx_skb->len < L2CAP_LEN_SIZE) {
7943 			if (l2cap_recv_len(conn, skb) < 0) {
7944 				l2cap_conn_unreliable(conn, ECOMM);
7945 				goto drop;
7946 			}
7947 
7948 			/* Header still could not be read just continue */
7949 			if (conn->rx_skb->len < L2CAP_LEN_SIZE)
7950 				break;
7951 		}
7952 
7953 		if (skb->len > conn->rx_len) {
7954 			BT_ERR("Fragment is too long (len %u, expected %u)",
7955 			       skb->len, conn->rx_len);
7956 			l2cap_recv_reset(conn);
7957 			l2cap_conn_unreliable(conn, ECOMM);
7958 			goto drop;
7959 		}
7960 
7961 		/* Append fragment into frame (with header) */
7962 		l2cap_recv_frag(conn, skb, skb->len);
7963 
7964 		if (!conn->rx_len) {
7965 			/* Complete frame received. l2cap_recv_frame
7966 			 * takes ownership of the skb so set the global
7967 			 * rx_skb pointer to NULL first.
7968 			 */
7969 			struct sk_buff *rx_skb = conn->rx_skb;
7970 			conn->rx_skb = NULL;
7971 			l2cap_recv_frame(conn, rx_skb);
7972 		}
7973 		break;
7974 	}
7975 
7976 drop:
7977 	kfree_skb(skb);
7978 unlock:
7979 	mutex_unlock(&conn->lock);
7980 	l2cap_conn_put(conn);
7981 	return 0;
7982 }
7983 
7984 static struct hci_cb l2cap_cb = {
7985 	.name		= "L2CAP",
7986 	.connect_cfm	= l2cap_connect_cfm,
7987 	.disconn_cfm	= l2cap_disconn_cfm,
7988 	.security_cfm	= l2cap_security_cfm,
7989 };
7990 
7991 static int l2cap_debugfs_show(struct seq_file *f, void *p)
7992 {
7993 	struct l2cap_chan *c;
7994 
7995 	read_lock(&chan_list_lock);
7996 
7997 	list_for_each_entry(c, &chan_list, global_l) {
7998 		seq_printf(f, "%pMR (%u) %pMR (%u) %d %d 0x%4.4x 0x%4.4x %d %d %d %d\n",
7999 			   &c->src, c->src_type, &c->dst, c->dst_type,
8000 			   c->state, __le16_to_cpu(c->psm),
8001 			   c->scid, c->dcid, c->imtu, c->omtu,
8002 			   c->sec_level, c->mode);
8003 	}
8004 
8005 	read_unlock(&chan_list_lock);
8006 
8007 	return 0;
8008 }
8009 
8010 DEFINE_SHOW_ATTRIBUTE(l2cap_debugfs);
8011 
8012 static struct dentry *l2cap_debugfs;
8013 
8014 int __init l2cap_init(void)
8015 {
8016 	int err;
8017 
8018 	err = l2cap_init_sockets();
8019 	if (err < 0)
8020 		return err;
8021 
8022 	hci_register_cb(&l2cap_cb);
8023 
8024 	if (IS_ERR_OR_NULL(bt_debugfs))
8025 		return 0;
8026 
8027 	l2cap_debugfs = debugfs_create_file("l2cap", 0444, bt_debugfs,
8028 					    NULL, &l2cap_debugfs_fops);
8029 
8030 	return 0;
8031 }
8032 
8033 void l2cap_exit(void)
8034 {
8035 	debugfs_remove(l2cap_debugfs);
8036 	hci_unregister_cb(&l2cap_cb);
8037 	l2cap_cleanup_sockets();
8038 }
8039 
8040 module_param(disable_ertm, bool, 0644);
8041 MODULE_PARM_DESC(disable_ertm, "Disable enhanced retransmission mode");
8042 
8043 module_param(enable_ecred, bool, 0644);
8044 MODULE_PARM_DESC(enable_ecred, "Enable enhanced credit flow control mode");
8045