xref: /linux/net/bluetooth/smp.c (revision 81a2345f1984f0b36d3226571bc196316a01b648)
1 // SPDX-License-Identifier: GPL-2.0
2 /*
3    BlueZ - Bluetooth protocol stack for Linux
4    Copyright (C) 2011 Nokia Corporation and/or its subsidiary(-ies).
5 
6    THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS
7    OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
8    FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT OF THIRD PARTY RIGHTS.
9    IN NO EVENT SHALL THE COPYRIGHT HOLDER(S) AND AUTHOR(S) BE LIABLE FOR ANY
10    CLAIM, OR ANY SPECIAL INDIRECT OR CONSEQUENTIAL DAMAGES, OR ANY DAMAGES
11    WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
12    ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
13    OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
14 
15    ALL LIABILITY, INCLUDING LIABILITY FOR INFRINGEMENT OF ANY PATENTS,
16    COPYRIGHTS, TRADEMARKS OR OTHER RIGHTS, RELATING TO USE OF THIS
17    SOFTWARE IS DISCLAIMED.
18 */
19 
20 #include <linux/debugfs.h>
21 #include <linux/scatterlist.h>
22 #include <crypto/aes-cbc-macs.h>
23 #include <crypto/aes.h>
24 #include <crypto/kpp.h>
25 #include <crypto/utils.h>
26 
27 #include <net/bluetooth/bluetooth.h>
28 #include <net/bluetooth/hci_core.h>
29 #include <net/bluetooth/l2cap.h>
30 #include <net/bluetooth/mgmt.h>
31 
32 #include "ecdh_helper.h"
33 #include "smp.h"
34 
35 #define SMP_DEV(hdev) \
36 	((struct smp_dev *)((struct l2cap_chan *)((hdev)->smp_data))->data)
37 
38 /* Low-level debug macros to be used for stuff that we don't want
39  * accidentally in dmesg, i.e. the values of the various crypto keys
40  * and the inputs & outputs of crypto functions.
41  */
42 #ifdef DEBUG
43 #define SMP_DBG(fmt, ...) printk(KERN_DEBUG "%s: " fmt, __func__, \
44 				 ##__VA_ARGS__)
45 #else
46 #define SMP_DBG(fmt, ...) no_printk(KERN_DEBUG "%s: " fmt, __func__, \
47 				    ##__VA_ARGS__)
48 #endif
49 
50 #define SMP_ALLOW_CMD(smp, code)	set_bit(code, &smp->allow_cmd)
51 
52 /* Keys which are not distributed with Secure Connections */
53 #define SMP_SC_NO_DIST (SMP_DIST_ENC_KEY | SMP_DIST_LINK_KEY)
54 
55 #define SMP_TIMEOUT	secs_to_jiffies(30)
56 
57 #define ID_ADDR_TIMEOUT	msecs_to_jiffies(200)
58 
59 #define AUTH_REQ_MASK(dev)	(hci_dev_test_flag(dev, HCI_SC_ENABLED) ? \
60 				 0x3f : 0x07)
61 #define KEY_DIST_MASK		0x07
62 
63 /* Maximum message length that can be passed to smp_aes_cmac */
64 #define CMAC_MSG_MAX	80
65 
66 enum {
67 	SMP_FLAG_TK_VALID,
68 	SMP_FLAG_CFM_PENDING,
69 	SMP_FLAG_MITM_AUTH,
70 	SMP_FLAG_COMPLETE,
71 	SMP_FLAG_INITIATOR,
72 	SMP_FLAG_SC,
73 	SMP_FLAG_REMOTE_PK,
74 	SMP_FLAG_DEBUG_KEY,
75 	SMP_FLAG_WAIT_USER,
76 	SMP_FLAG_DHKEY_PENDING,
77 	SMP_FLAG_REMOTE_OOB,
78 	SMP_FLAG_LOCAL_OOB,
79 	SMP_FLAG_CT2,
80 };
81 
82 struct smp_dev {
83 	/* Secure Connections OOB data */
84 	bool			local_oob;
85 	u8			local_pk[64];
86 	u8			local_rand[16];
87 	bool			debug_key;
88 
89 	struct crypto_kpp	*tfm_ecdh;
90 };
91 
92 struct smp_chan {
93 	struct l2cap_conn	*conn;
94 	struct delayed_work	security_timer;
95 	unsigned long           allow_cmd; /* Bitmask of allowed commands */
96 
97 	u8		preq[7]; /* SMP Pairing Request */
98 	u8		prsp[7]; /* SMP Pairing Response */
99 	u8		prnd[16]; /* SMP Pairing Random (local) */
100 	u8		rrnd[16]; /* SMP Pairing Random (remote) */
101 	u8		pcnf[16]; /* SMP Pairing Confirm */
102 	u8		tk[16]; /* SMP Temporary Key */
103 	u8		rr[16]; /* Remote OOB ra/rb value */
104 	u8		lr[16]; /* Local OOB ra/rb value */
105 	u8		enc_key_size;
106 	u8		remote_key_dist;
107 	bdaddr_t	id_addr;
108 	u8		id_addr_type;
109 	u8		irk[16];
110 	struct smp_csrk	*csrk;
111 	struct smp_csrk	*responder_csrk;
112 	struct smp_ltk	*ltk;
113 	struct smp_ltk	*responder_ltk;
114 	struct smp_irk	*remote_irk;
115 	u8		*link_key;
116 	unsigned long	flags;
117 	u8		method;
118 	u8		passkey_round;
119 
120 	/* Secure Connections variables */
121 	u8			local_pk[64];
122 	u8			remote_pk[64];
123 	u8			dhkey[32];
124 	u8			mackey[16];
125 
126 	struct crypto_kpp	*tfm_ecdh;
127 };
128 
129 /* These debug key values are defined in the SMP section of the core
130  * specification. debug_pk is the public debug key and debug_sk the
131  * private debug key.
132  */
133 static const u8 debug_pk[64] = {
134 		0xe6, 0x9d, 0x35, 0x0e, 0x48, 0x01, 0x03, 0xcc,
135 		0xdb, 0xfd, 0xf4, 0xac, 0x11, 0x91, 0xf4, 0xef,
136 		0xb9, 0xa5, 0xf9, 0xe9, 0xa7, 0x83, 0x2c, 0x5e,
137 		0x2c, 0xbe, 0x97, 0xf2, 0xd2, 0x03, 0xb0, 0x20,
138 
139 		0x8b, 0xd2, 0x89, 0x15, 0xd0, 0x8e, 0x1c, 0x74,
140 		0x24, 0x30, 0xed, 0x8f, 0xc2, 0x45, 0x63, 0x76,
141 		0x5c, 0x15, 0x52, 0x5a, 0xbf, 0x9a, 0x32, 0x63,
142 		0x6d, 0xeb, 0x2a, 0x65, 0x49, 0x9c, 0x80, 0xdc,
143 };
144 
145 static const u8 debug_sk[32] = {
146 		0xbd, 0x1a, 0x3c, 0xcd, 0xa6, 0xb8, 0x99, 0x58,
147 		0x99, 0xb7, 0x40, 0xeb, 0x7b, 0x60, 0xff, 0x4a,
148 		0x50, 0x3f, 0x10, 0xd2, 0xe3, 0xb3, 0xc9, 0x74,
149 		0x38, 0x5f, 0xc5, 0xa3, 0xd4, 0xf6, 0x49, 0x3f,
150 };
151 
152 static inline void swap_buf(const u8 *src, u8 *dst, size_t len)
153 {
154 	size_t i;
155 
156 	for (i = 0; i < len; i++)
157 		dst[len - 1 - i] = src[i];
158 }
159 
160 /* The following functions map to the LE SC SMP crypto functions
161  * AES-CMAC, f4, f5, f6, g2 and h6.
162  */
163 
164 static int smp_aes_cmac(const u8 k[16], const u8 *m, size_t len, u8 mac[16])
165 {
166 	uint8_t tmp[16], mac_msb[16], msg_msb[CMAC_MSG_MAX];
167 	struct aes_cmac_key key __cleanup(aes_cmac_zeroize_key);
168 	int err;
169 
170 	if (len > CMAC_MSG_MAX)
171 		return -EFBIG;
172 
173 	/* Swap key and message from LSB to MSB */
174 	swap_buf(k, tmp, 16);
175 	swap_buf(m, msg_msb, len);
176 
177 	SMP_DBG("msg (len %zu) %*phN", len, (int) len, m);
178 	SMP_DBG("key %16phN", k);
179 
180 	err = aes_cmac_preparekey(&key, tmp, 16);
181 	memzero_explicit(tmp, sizeof(tmp));
182 	if (WARN_ON_ONCE(err)) /* Should never happen, as 16 is valid keylen */
183 		return err;
184 	aes_cmac(&key, msg_msb, len, mac_msb);
185 
186 	swap_buf(mac_msb, mac, 16);
187 
188 	SMP_DBG("mac %16phN", mac);
189 
190 	return 0;
191 }
192 
193 static int smp_f4(const u8 u[32], const u8 v[32], const u8 x[16], u8 z,
194 		  u8 res[16])
195 {
196 	u8 m[65];
197 	int err;
198 
199 	SMP_DBG("u %32phN", u);
200 	SMP_DBG("v %32phN", v);
201 	SMP_DBG("x %16phN z %02x", x, z);
202 
203 	m[0] = z;
204 	memcpy(m + 1, v, 32);
205 	memcpy(m + 33, u, 32);
206 
207 	err = smp_aes_cmac(x, m, sizeof(m), res);
208 	if (err)
209 		return err;
210 
211 	SMP_DBG("res %16phN", res);
212 
213 	return err;
214 }
215 
216 static int smp_f5(const u8 w[32], const u8 n1[16], const u8 n2[16],
217 		  const u8 a1[7], const u8 a2[7], u8 mackey[16], u8 ltk[16])
218 {
219 	/* The btle, salt and length "magic" values are as defined in
220 	 * the SMP section of the Bluetooth core specification. In ASCII
221 	 * the btle value ends up being 'btle'. The salt is just a
222 	 * random number whereas length is the value 256 in little
223 	 * endian format.
224 	 */
225 	const u8 btle[4] = { 0x65, 0x6c, 0x74, 0x62 };
226 	const u8 salt[16] = { 0xbe, 0x83, 0x60, 0x5a, 0xdb, 0x0b, 0x37, 0x60,
227 			      0x38, 0xa5, 0xf5, 0xaa, 0x91, 0x83, 0x88, 0x6c };
228 	const u8 length[2] = { 0x00, 0x01 };
229 	u8 m[53], t[16];
230 	int err;
231 
232 	SMP_DBG("w %32phN", w);
233 	SMP_DBG("n1 %16phN n2 %16phN", n1, n2);
234 	SMP_DBG("a1 %7phN a2 %7phN", a1, a2);
235 
236 	err = smp_aes_cmac(salt, w, 32, t);
237 	if (err)
238 		return err;
239 
240 	SMP_DBG("t %16phN", t);
241 
242 	memcpy(m, length, 2);
243 	memcpy(m + 2, a2, 7);
244 	memcpy(m + 9, a1, 7);
245 	memcpy(m + 16, n2, 16);
246 	memcpy(m + 32, n1, 16);
247 	memcpy(m + 48, btle, 4);
248 
249 	m[52] = 0; /* Counter */
250 
251 	err = smp_aes_cmac(t, m, sizeof(m), mackey);
252 	if (err)
253 		return err;
254 
255 	SMP_DBG("mackey %16phN", mackey);
256 
257 	m[52] = 1; /* Counter */
258 
259 	err = smp_aes_cmac(t, m, sizeof(m), ltk);
260 	if (err)
261 		return err;
262 
263 	SMP_DBG("ltk %16phN", ltk);
264 
265 	return 0;
266 }
267 
268 static int smp_f6(const u8 w[16], const u8 n1[16], const u8 n2[16],
269 		  const u8 r[16], const u8 io_cap[3], const u8 a1[7],
270 		  const u8 a2[7], u8 res[16])
271 {
272 	u8 m[65];
273 	int err;
274 
275 	SMP_DBG("w %16phN", w);
276 	SMP_DBG("n1 %16phN n2 %16phN", n1, n2);
277 	SMP_DBG("r %16phN io_cap %3phN a1 %7phN a2 %7phN", r, io_cap, a1, a2);
278 
279 	memcpy(m, a2, 7);
280 	memcpy(m + 7, a1, 7);
281 	memcpy(m + 14, io_cap, 3);
282 	memcpy(m + 17, r, 16);
283 	memcpy(m + 33, n2, 16);
284 	memcpy(m + 49, n1, 16);
285 
286 	err = smp_aes_cmac(w, m, sizeof(m), res);
287 	if (err)
288 		return err;
289 
290 	SMP_DBG("res %16phN", res);
291 
292 	return err;
293 }
294 
295 static int smp_g2(const u8 u[32], const u8 v[32], const u8 x[16],
296 		  const u8 y[16], u32 *val)
297 {
298 	u8 m[80], tmp[16];
299 	int err;
300 
301 	SMP_DBG("u %32phN", u);
302 	SMP_DBG("v %32phN", v);
303 	SMP_DBG("x %16phN y %16phN", x, y);
304 
305 	memcpy(m, y, 16);
306 	memcpy(m + 16, v, 32);
307 	memcpy(m + 48, u, 32);
308 
309 	err = smp_aes_cmac(x, m, sizeof(m), tmp);
310 	if (err)
311 		return err;
312 
313 	*val = get_unaligned_le32(tmp);
314 	*val %= 1000000;
315 
316 	SMP_DBG("val %06u", *val);
317 
318 	return 0;
319 }
320 
321 static int smp_h6(const u8 w[16], const u8 key_id[4], u8 res[16])
322 {
323 	int err;
324 
325 	SMP_DBG("w %16phN key_id %4phN", w, key_id);
326 
327 	err = smp_aes_cmac(w, key_id, 4, res);
328 	if (err)
329 		return err;
330 
331 	SMP_DBG("res %16phN", res);
332 
333 	return err;
334 }
335 
336 static int smp_h7(const u8 w[16], const u8 salt[16], u8 res[16])
337 {
338 	int err;
339 
340 	SMP_DBG("w %16phN salt %16phN", w, salt);
341 
342 	err = smp_aes_cmac(salt, w, 16, res);
343 	if (err)
344 		return err;
345 
346 	SMP_DBG("res %16phN", res);
347 
348 	return err;
349 }
350 
351 /* The following functions map to the legacy SMP crypto functions e, c1,
352  * s1 and ah.
353  */
354 
355 static int smp_e(const u8 *k, u8 *r)
356 {
357 	struct aes_enckey aes;
358 	uint8_t tmp[16], data[16];
359 	int err;
360 
361 	SMP_DBG("k %16phN r %16phN", k, r);
362 
363 	/* The most significant octet of key corresponds to k[0] */
364 	swap_buf(k, tmp, 16);
365 
366 	err = aes_prepareenckey(&aes, tmp, 16);
367 	if (err) {
368 		BT_ERR("cipher setkey failed: %d", err);
369 		return err;
370 	}
371 
372 	/* Most significant octet of plaintextData corresponds to data[0] */
373 	swap_buf(r, data, 16);
374 
375 	aes_encrypt(&aes, data, data);
376 
377 	/* Most significant octet of encryptedData corresponds to data[0] */
378 	swap_buf(data, r, 16);
379 
380 	SMP_DBG("r %16phN", r);
381 
382 	memzero_explicit(&aes, sizeof(aes));
383 	return err;
384 }
385 
386 static int smp_c1(const u8 k[16],
387 		  const u8 r[16], const u8 preq[7], const u8 pres[7], u8 _iat,
388 		  const bdaddr_t *ia, u8 _rat, const bdaddr_t *ra, u8 res[16])
389 {
390 	u8 p1[16], p2[16];
391 	int err;
392 
393 	SMP_DBG("k %16phN r %16phN", k, r);
394 	SMP_DBG("iat %u ia %6phN rat %u ra %6phN", _iat, ia, _rat, ra);
395 	SMP_DBG("preq %7phN pres %7phN", preq, pres);
396 
397 	memset(p1, 0, 16);
398 
399 	/* p1 = pres || preq || _rat || _iat */
400 	p1[0] = _iat;
401 	p1[1] = _rat;
402 	memcpy(p1 + 2, preq, 7);
403 	memcpy(p1 + 9, pres, 7);
404 
405 	SMP_DBG("p1 %16phN", p1);
406 
407 	/* res = r XOR p1 */
408 	crypto_xor_cpy(res, r, p1, sizeof(p1));
409 
410 	/* res = e(k, res) */
411 	err = smp_e(k, res);
412 	if (err) {
413 		BT_ERR("Encrypt data error");
414 		return err;
415 	}
416 
417 	/* p2 = padding || ia || ra */
418 	memcpy(p2, ra, 6);
419 	memcpy(p2 + 6, ia, 6);
420 	memset(p2 + 12, 0, 4);
421 
422 	SMP_DBG("p2 %16phN", p2);
423 
424 	/* res = res XOR p2 */
425 	crypto_xor(res, p2, sizeof(p2));
426 
427 	/* res = e(k, res) */
428 	err = smp_e(k, res);
429 	if (err)
430 		BT_ERR("Encrypt data error");
431 
432 	return err;
433 }
434 
435 static int smp_s1(const u8 k[16],
436 		  const u8 r1[16], const u8 r2[16], u8 _r[16])
437 {
438 	int err;
439 
440 	/* Just least significant octets from r1 and r2 are considered */
441 	memcpy(_r, r2, 8);
442 	memcpy(_r + 8, r1, 8);
443 
444 	err = smp_e(k, _r);
445 	if (err)
446 		BT_ERR("Encrypt data error");
447 
448 	return err;
449 }
450 
451 static int smp_ah(const u8 irk[16], const u8 r[3], u8 res[3])
452 {
453 	u8 _res[16];
454 	int err;
455 
456 	/* r' = padding || r */
457 	memcpy(_res, r, 3);
458 	memset(_res + 3, 0, 13);
459 
460 	err = smp_e(irk, _res);
461 	if (err) {
462 		BT_ERR("Encrypt error");
463 		return err;
464 	}
465 
466 	/* The output of the random address function ah is:
467 	 *	ah(k, r) = e(k, r') mod 2^24
468 	 * The output of the security function e is then truncated to 24 bits
469 	 * by taking the least significant 24 bits of the output of e as the
470 	 * result of ah.
471 	 */
472 	memcpy(res, _res, 3);
473 
474 	return 0;
475 }
476 
477 bool smp_irk_matches(struct hci_dev *hdev, const u8 irk[16],
478 		     const bdaddr_t *bdaddr)
479 {
480 	struct l2cap_chan *chan = hdev->smp_data;
481 	u8 hash[3];
482 	int err;
483 
484 	if (!chan || !chan->data)
485 		return false;
486 
487 	bt_dev_dbg(hdev, "RPA %pMR IRK %*phN", bdaddr, 16, irk);
488 
489 	err = smp_ah(irk, &bdaddr->b[3], hash);
490 	if (err)
491 		return false;
492 
493 	return !crypto_memneq(bdaddr->b, hash, 3);
494 }
495 
496 int smp_generate_rpa(struct hci_dev *hdev, const u8 irk[16], bdaddr_t *rpa)
497 {
498 	struct l2cap_chan *chan = hdev->smp_data;
499 	int err;
500 
501 	if (!chan || !chan->data)
502 		return -EOPNOTSUPP;
503 
504 	get_random_bytes(&rpa->b[3], 3);
505 
506 	rpa->b[5] &= 0x3f;	/* Clear two most significant bits */
507 	rpa->b[5] |= 0x40;	/* Set second most significant bit */
508 
509 	err = smp_ah(irk, &rpa->b[3], rpa->b);
510 	if (err < 0)
511 		return err;
512 
513 	bt_dev_dbg(hdev, "RPA %pMR", rpa);
514 
515 	return 0;
516 }
517 
518 int smp_generate_oob(struct hci_dev *hdev, u8 hash[16], u8 rand[16])
519 {
520 	struct l2cap_chan *chan = hdev->smp_data;
521 	struct smp_dev *smp;
522 	int err;
523 
524 	if (!chan || !chan->data)
525 		return -EOPNOTSUPP;
526 
527 	smp = chan->data;
528 
529 	if (hci_dev_test_flag(hdev, HCI_USE_DEBUG_KEYS)) {
530 		bt_dev_dbg(hdev, "Using debug keys");
531 		err = set_ecdh_privkey(smp->tfm_ecdh, debug_sk);
532 		if (err)
533 			return err;
534 		memcpy(smp->local_pk, debug_pk, 64);
535 		smp->debug_key = true;
536 	} else {
537 		while (true) {
538 			/* Generate key pair for Secure Connections */
539 			err = generate_ecdh_keys(smp->tfm_ecdh, smp->local_pk);
540 			if (err)
541 				return err;
542 
543 			/* This is unlikely, but we need to check that
544 			 * we didn't accidentally generate a debug key.
545 			 */
546 			if (crypto_memneq(smp->local_pk, debug_pk, 64))
547 				break;
548 		}
549 		smp->debug_key = false;
550 	}
551 
552 	SMP_DBG("OOB Public Key X: %32phN", smp->local_pk);
553 	SMP_DBG("OOB Public Key Y: %32phN", smp->local_pk + 32);
554 
555 	get_random_bytes(smp->local_rand, 16);
556 
557 	err = smp_f4(smp->local_pk, smp->local_pk, smp->local_rand, 0, hash);
558 	if (err < 0)
559 		return err;
560 
561 	memcpy(rand, smp->local_rand, 16);
562 
563 	smp->local_oob = true;
564 
565 	return 0;
566 }
567 
568 static void smp_send_cmd(struct l2cap_conn *conn, u8 code, u16 len, void *data)
569 {
570 	struct l2cap_chan *chan = conn->smp;
571 	struct smp_chan *smp;
572 	struct kvec iv[2];
573 	struct msghdr msg;
574 
575 	if (!chan)
576 		return;
577 
578 	bt_dev_dbg(conn->hcon->hdev, "code 0x%2.2x", code);
579 
580 	iv[0].iov_base = &code;
581 	iv[0].iov_len = 1;
582 
583 	iv[1].iov_base = data;
584 	iv[1].iov_len = len;
585 
586 	memset(&msg, 0, sizeof(msg));
587 
588 	iov_iter_kvec(&msg.msg_iter, ITER_SOURCE, iv, 2, 1 + len);
589 
590 	l2cap_chan_send(chan, &msg, 1 + len, NULL);
591 
592 	if (!chan->data)
593 		return;
594 
595 	smp = chan->data;
596 
597 	cancel_delayed_work_sync(&smp->security_timer);
598 	schedule_delayed_work(&smp->security_timer, SMP_TIMEOUT);
599 }
600 
601 static u8 authreq_to_seclevel(u8 authreq)
602 {
603 	if (authreq & SMP_AUTH_MITM) {
604 		if (authreq & SMP_AUTH_SC)
605 			return BT_SECURITY_FIPS;
606 		else
607 			return BT_SECURITY_HIGH;
608 	} else {
609 		return BT_SECURITY_MEDIUM;
610 	}
611 }
612 
613 static __u8 seclevel_to_authreq(__u8 sec_level)
614 {
615 	switch (sec_level) {
616 	case BT_SECURITY_FIPS:
617 	case BT_SECURITY_HIGH:
618 		return SMP_AUTH_MITM | SMP_AUTH_BONDING;
619 	case BT_SECURITY_MEDIUM:
620 		return SMP_AUTH_BONDING;
621 	default:
622 		return SMP_AUTH_NONE;
623 	}
624 }
625 
626 static void build_pairing_cmd(struct l2cap_conn *conn,
627 			      struct smp_cmd_pairing *req,
628 			      struct smp_cmd_pairing *rsp, __u8 authreq)
629 {
630 	struct l2cap_chan *chan = conn->smp;
631 	struct smp_chan *smp = chan->data;
632 	struct hci_conn *hcon = conn->hcon;
633 	struct hci_dev *hdev = hcon->hdev;
634 	u8 local_dist = 0, remote_dist = 0, oob_flag = SMP_OOB_NOT_PRESENT;
635 
636 	if (hci_dev_test_flag(hdev, HCI_BONDABLE)) {
637 		local_dist = SMP_DIST_ENC_KEY | SMP_DIST_SIGN;
638 		remote_dist = SMP_DIST_ENC_KEY | SMP_DIST_SIGN;
639 		authreq |= SMP_AUTH_BONDING;
640 	} else {
641 		authreq &= ~SMP_AUTH_BONDING;
642 	}
643 
644 	if (hci_dev_test_flag(hdev, HCI_RPA_RESOLVING))
645 		remote_dist |= SMP_DIST_ID_KEY;
646 
647 	if (hci_dev_test_flag(hdev, HCI_PRIVACY))
648 		local_dist |= SMP_DIST_ID_KEY;
649 
650 	if (hci_dev_test_flag(hdev, HCI_SC_ENABLED) &&
651 	    (authreq & SMP_AUTH_SC)) {
652 		struct oob_data *oob_data;
653 		u8 bdaddr_type;
654 
655 		if (hci_dev_test_flag(hdev, HCI_SSP_ENABLED)) {
656 			local_dist |= SMP_DIST_LINK_KEY;
657 			remote_dist |= SMP_DIST_LINK_KEY;
658 		}
659 
660 		if (hcon->dst_type == ADDR_LE_DEV_PUBLIC)
661 			bdaddr_type = BDADDR_LE_PUBLIC;
662 		else
663 			bdaddr_type = BDADDR_LE_RANDOM;
664 
665 		mutex_lock(&hdev->remote_oob_lock);
666 		oob_data = hci_find_remote_oob_data(hdev, &hcon->dst,
667 						    bdaddr_type);
668 		if (oob_data && oob_data->present) {
669 			set_bit(SMP_FLAG_REMOTE_OOB, &smp->flags);
670 			oob_flag = SMP_OOB_PRESENT;
671 			memcpy(smp->rr, oob_data->rand256, 16);
672 			memcpy(smp->pcnf, oob_data->hash256, 16);
673 			SMP_DBG("OOB Remote Confirmation: %16phN", smp->pcnf);
674 			SMP_DBG("OOB Remote Random: %16phN", smp->rr);
675 		}
676 		mutex_unlock(&hdev->remote_oob_lock);
677 
678 	} else {
679 		authreq &= ~SMP_AUTH_SC;
680 	}
681 
682 	if (rsp == NULL) {
683 		req->io_capability = conn->hcon->io_capability;
684 		req->oob_flag = oob_flag;
685 		req->max_key_size = hdev->le_max_key_size;
686 		req->init_key_dist = local_dist;
687 		req->resp_key_dist = remote_dist;
688 		req->auth_req = (authreq & AUTH_REQ_MASK(hdev));
689 
690 		smp->remote_key_dist = remote_dist;
691 		return;
692 	}
693 
694 	rsp->io_capability = conn->hcon->io_capability;
695 	rsp->oob_flag = oob_flag;
696 	rsp->max_key_size = hdev->le_max_key_size;
697 	rsp->init_key_dist = req->init_key_dist & remote_dist;
698 	rsp->resp_key_dist = req->resp_key_dist & local_dist;
699 	rsp->auth_req = (authreq & AUTH_REQ_MASK(hdev));
700 
701 	smp->remote_key_dist = rsp->init_key_dist;
702 }
703 
704 static u8 check_enc_key_size(struct l2cap_conn *conn, __u8 max_key_size)
705 {
706 	struct l2cap_chan *chan = conn->smp;
707 	struct hci_dev *hdev = conn->hcon->hdev;
708 	struct smp_chan *smp = chan->data;
709 
710 	if (conn->hcon->pending_sec_level == BT_SECURITY_FIPS &&
711 	    max_key_size != SMP_MAX_ENC_KEY_SIZE)
712 		return SMP_ENC_KEY_SIZE;
713 
714 	if (max_key_size > hdev->le_max_key_size ||
715 	    max_key_size < SMP_MIN_ENC_KEY_SIZE)
716 		return SMP_ENC_KEY_SIZE;
717 
718 	smp->enc_key_size = max_key_size;
719 
720 	return 0;
721 }
722 
723 static void smp_chan_destroy(struct l2cap_conn *conn)
724 {
725 	struct l2cap_chan *chan = conn->smp;
726 	struct smp_chan *smp = chan->data;
727 	struct hci_conn *hcon = conn->hcon;
728 	bool complete;
729 
730 	BUG_ON(!smp);
731 
732 	cancel_delayed_work_sync(&smp->security_timer);
733 
734 	complete = test_bit(SMP_FLAG_COMPLETE, &smp->flags);
735 	mgmt_smp_complete(hcon, complete);
736 
737 	kfree_sensitive(smp->csrk);
738 	kfree_sensitive(smp->responder_csrk);
739 	kfree_sensitive(smp->link_key);
740 
741 	crypto_free_kpp(smp->tfm_ecdh);
742 
743 	/* Ensure that we don't leave any debug key around if debug key
744 	 * support hasn't been explicitly enabled.
745 	 */
746 	if (smp->ltk && smp->ltk->type == SMP_LTK_P256_DEBUG &&
747 	    !hci_dev_test_flag(hcon->hdev, HCI_KEEP_DEBUG_KEYS)) {
748 		list_del_rcu(&smp->ltk->list);
749 		kfree_rcu(smp->ltk, rcu);
750 		smp->ltk = NULL;
751 	}
752 
753 	/* If pairing failed clean up any keys we might have */
754 	if (!complete) {
755 		if (smp->ltk) {
756 			list_del_rcu(&smp->ltk->list);
757 			kfree_rcu(smp->ltk, rcu);
758 		}
759 
760 		if (smp->responder_ltk) {
761 			list_del_rcu(&smp->responder_ltk->list);
762 			kfree_rcu(smp->responder_ltk, rcu);
763 		}
764 
765 		if (smp->remote_irk) {
766 			list_del_rcu(&smp->remote_irk->list);
767 			kfree_rcu(smp->remote_irk, rcu);
768 		}
769 	}
770 
771 	chan->data = NULL;
772 	kfree_sensitive(smp);
773 	hci_conn_drop(hcon);
774 }
775 
776 static void smp_failure(struct l2cap_conn *conn, u8 reason)
777 {
778 	struct hci_conn *hcon = conn->hcon;
779 	struct l2cap_chan *chan = conn->smp;
780 
781 	if (reason)
782 		smp_send_cmd(conn, SMP_CMD_PAIRING_FAIL, sizeof(reason),
783 			     &reason);
784 
785 	mgmt_auth_failed(hcon, HCI_ERROR_AUTH_FAILURE);
786 
787 	if (chan->data)
788 		smp_chan_destroy(conn);
789 }
790 
791 #define JUST_WORKS	0x00
792 #define JUST_CFM	0x01
793 #define REQ_PASSKEY	0x02
794 #define CFM_PASSKEY	0x03
795 #define REQ_OOB		0x04
796 #define DSP_PASSKEY	0x05
797 #define OVERLAP		0xFF
798 
799 static const u8 gen_method[5][5] = {
800 	{ JUST_WORKS,  JUST_CFM,    REQ_PASSKEY, JUST_WORKS, REQ_PASSKEY },
801 	{ JUST_WORKS,  JUST_CFM,    REQ_PASSKEY, JUST_WORKS, REQ_PASSKEY },
802 	{ CFM_PASSKEY, CFM_PASSKEY, REQ_PASSKEY, JUST_WORKS, CFM_PASSKEY },
803 	{ JUST_WORKS,  JUST_CFM,    JUST_WORKS,  JUST_WORKS, JUST_CFM    },
804 	{ CFM_PASSKEY, CFM_PASSKEY, REQ_PASSKEY, JUST_WORKS, OVERLAP     },
805 };
806 
807 static const u8 sc_method[5][5] = {
808 	{ JUST_WORKS,  JUST_CFM,    REQ_PASSKEY, JUST_WORKS, REQ_PASSKEY },
809 	{ JUST_WORKS,  CFM_PASSKEY, REQ_PASSKEY, JUST_WORKS, CFM_PASSKEY },
810 	{ DSP_PASSKEY, DSP_PASSKEY, REQ_PASSKEY, JUST_WORKS, DSP_PASSKEY },
811 	{ JUST_WORKS,  JUST_CFM,    JUST_WORKS,  JUST_WORKS, JUST_CFM    },
812 	{ DSP_PASSKEY, CFM_PASSKEY, REQ_PASSKEY, JUST_WORKS, CFM_PASSKEY },
813 };
814 
815 static u8 get_auth_method(struct smp_chan *smp, u8 local_io, u8 remote_io)
816 {
817 	/* If either side has unknown io_caps, use JUST_CFM (which gets
818 	 * converted later to JUST_WORKS if we're initiators.
819 	 */
820 	if (local_io > SMP_IO_KEYBOARD_DISPLAY ||
821 	    remote_io > SMP_IO_KEYBOARD_DISPLAY)
822 		return JUST_CFM;
823 
824 	if (test_bit(SMP_FLAG_SC, &smp->flags))
825 		return sc_method[remote_io][local_io];
826 
827 	return gen_method[remote_io][local_io];
828 }
829 
830 static int tk_request(struct l2cap_conn *conn, u8 remote_oob, u8 auth,
831 						u8 local_io, u8 remote_io)
832 {
833 	struct hci_conn *hcon = conn->hcon;
834 	struct l2cap_chan *chan = conn->smp;
835 	struct smp_chan *smp = chan->data;
836 	u32 passkey = 0;
837 	int ret;
838 
839 	/* Initialize key for JUST WORKS */
840 	memset(smp->tk, 0, sizeof(smp->tk));
841 	clear_bit(SMP_FLAG_TK_VALID, &smp->flags);
842 
843 	bt_dev_dbg(hcon->hdev, "auth:%u lcl:%u rem:%u", auth, local_io,
844 		   remote_io);
845 
846 	/* If neither side wants MITM, either "just" confirm an incoming
847 	 * request or use just-works for outgoing ones. The JUST_CFM
848 	 * will be converted to JUST_WORKS if necessary later in this
849 	 * function. If either side has MITM look up the method from the
850 	 * table.
851 	 */
852 	if (!(auth & SMP_AUTH_MITM))
853 		smp->method = JUST_CFM;
854 	else
855 		smp->method = get_auth_method(smp, local_io, remote_io);
856 
857 	/* Don't confirm locally initiated pairing attempts */
858 	if (smp->method == JUST_CFM && test_bit(SMP_FLAG_INITIATOR,
859 						&smp->flags))
860 		smp->method = JUST_WORKS;
861 
862 	/* Don't bother user space with no IO capabilities */
863 	if (smp->method == JUST_CFM &&
864 	    hcon->io_capability == HCI_IO_NO_INPUT_OUTPUT)
865 		smp->method = JUST_WORKS;
866 
867 	/* If Just Works, Continue with Zero TK and ask user-space for
868 	 * confirmation */
869 	if (smp->method == JUST_WORKS) {
870 		ret = mgmt_user_confirm_request(hcon->hdev, &hcon->dst,
871 						hcon->type,
872 						hcon->dst_type,
873 						passkey, 1);
874 		if (ret)
875 			return ret;
876 		set_bit(SMP_FLAG_WAIT_USER, &smp->flags);
877 		return 0;
878 	}
879 
880 	/* If this function is used for SC -> legacy fallback we
881 	 * can only recover the just-works case.
882 	 */
883 	if (test_bit(SMP_FLAG_SC, &smp->flags))
884 		return -EINVAL;
885 
886 	/* Not Just Works/Confirm results in MITM Authentication */
887 	if (smp->method != JUST_CFM) {
888 		set_bit(SMP_FLAG_MITM_AUTH, &smp->flags);
889 		if (hcon->pending_sec_level < BT_SECURITY_HIGH)
890 			hcon->pending_sec_level = BT_SECURITY_HIGH;
891 	}
892 
893 	/* If both devices have Keyboard-Display I/O, the initiator
894 	 * Confirms and the responder Enters the passkey.
895 	 */
896 	if (smp->method == OVERLAP) {
897 		if (test_bit(SMP_FLAG_INITIATOR, &smp->flags))
898 			smp->method = CFM_PASSKEY;
899 		else
900 			smp->method = REQ_PASSKEY;
901 	}
902 
903 	/* Generate random passkey. */
904 	if (smp->method == CFM_PASSKEY) {
905 		memset(smp->tk, 0, sizeof(smp->tk));
906 		get_random_bytes(&passkey, sizeof(passkey));
907 		passkey %= 1000000;
908 		put_unaligned_le32(passkey, smp->tk);
909 		bt_dev_dbg(hcon->hdev, "PassKey: %u", passkey);
910 		set_bit(SMP_FLAG_TK_VALID, &smp->flags);
911 	}
912 
913 	if (smp->method == REQ_PASSKEY)
914 		ret = mgmt_user_passkey_request(hcon->hdev, &hcon->dst,
915 						hcon->type, hcon->dst_type);
916 	else if (smp->method == JUST_CFM)
917 		ret = mgmt_user_confirm_request(hcon->hdev, &hcon->dst,
918 						hcon->type, hcon->dst_type,
919 						passkey, 1);
920 	else
921 		ret = mgmt_user_passkey_notify(hcon->hdev, &hcon->dst,
922 						hcon->type, hcon->dst_type,
923 						passkey, 0);
924 
925 	return ret;
926 }
927 
928 static u8 smp_confirm(struct smp_chan *smp)
929 {
930 	struct l2cap_conn *conn = smp->conn;
931 	struct smp_cmd_pairing_confirm cp;
932 	int ret;
933 
934 	bt_dev_dbg(conn->hcon->hdev, "conn %p", conn);
935 
936 	ret = smp_c1(smp->tk, smp->prnd, smp->preq, smp->prsp,
937 		     conn->hcon->init_addr_type, &conn->hcon->init_addr,
938 		     conn->hcon->resp_addr_type, &conn->hcon->resp_addr,
939 		     cp.confirm_val);
940 	if (ret)
941 		return SMP_UNSPECIFIED;
942 
943 	clear_bit(SMP_FLAG_CFM_PENDING, &smp->flags);
944 
945 	smp_send_cmd(smp->conn, SMP_CMD_PAIRING_CONFIRM, sizeof(cp), &cp);
946 
947 	if (test_bit(SMP_FLAG_INITIATOR, &smp->flags))
948 		SMP_ALLOW_CMD(smp, SMP_CMD_PAIRING_CONFIRM);
949 	else
950 		SMP_ALLOW_CMD(smp, SMP_CMD_PAIRING_RANDOM);
951 
952 	return 0;
953 }
954 
955 static u8 smp_random(struct smp_chan *smp)
956 {
957 	struct l2cap_conn *conn = smp->conn;
958 	struct hci_conn *hcon = conn->hcon;
959 	u8 confirm[16];
960 	int ret;
961 
962 	bt_dev_dbg(conn->hcon->hdev, "conn %p %s", conn,
963 		   test_bit(SMP_FLAG_INITIATOR, &smp->flags) ? "initiator" :
964 		   "responder");
965 
966 	ret = smp_c1(smp->tk, smp->rrnd, smp->preq, smp->prsp,
967 		     hcon->init_addr_type, &hcon->init_addr,
968 		     hcon->resp_addr_type, &hcon->resp_addr, confirm);
969 	if (ret)
970 		return SMP_UNSPECIFIED;
971 
972 	if (crypto_memneq(smp->pcnf, confirm, sizeof(smp->pcnf))) {
973 		bt_dev_err(hcon->hdev, "pairing failed "
974 			   "(confirmation values mismatch)");
975 		return SMP_CONFIRM_FAILED;
976 	}
977 
978 	if (test_bit(SMP_FLAG_INITIATOR, &smp->flags)) {
979 		u8 stk[16];
980 		__le64 rand = 0;
981 		__le16 ediv = 0;
982 
983 		smp_s1(smp->tk, smp->rrnd, smp->prnd, stk);
984 
985 		if (test_and_set_bit(HCI_CONN_ENCRYPT_PEND, &hcon->flags))
986 			return SMP_UNSPECIFIED;
987 
988 		hci_le_start_enc(hcon, ediv, rand, stk, smp->enc_key_size);
989 		hcon->enc_key_size = smp->enc_key_size;
990 		set_bit(HCI_CONN_STK_ENCRYPT, &hcon->flags);
991 	} else {
992 		u8 stk[16], auth;
993 		__le64 rand = 0;
994 		__le16 ediv = 0;
995 
996 		smp_send_cmd(conn, SMP_CMD_PAIRING_RANDOM, sizeof(smp->prnd),
997 			     smp->prnd);
998 
999 		smp_s1(smp->tk, smp->prnd, smp->rrnd, stk);
1000 
1001 		auth = test_bit(SMP_FLAG_MITM_AUTH, &smp->flags) ? 1 : 0;
1002 
1003 		/* Even though there's no _RESPONDER suffix this is the
1004 		 * responder STK we're adding for later lookup (the initiator
1005 		 * STK never needs to be stored).
1006 		 */
1007 		hci_add_ltk(hcon->hdev, &hcon->dst, hcon->dst_type,
1008 			    SMP_STK, auth, stk, smp->enc_key_size, ediv, rand);
1009 	}
1010 
1011 	return 0;
1012 }
1013 
1014 static void smp_notify_keys(struct l2cap_conn *conn)
1015 {
1016 	struct l2cap_chan *chan = conn->smp;
1017 	struct smp_chan *smp = chan->data;
1018 	struct hci_conn *hcon = conn->hcon;
1019 	struct hci_dev *hdev = hcon->hdev;
1020 	struct smp_cmd_pairing *req = (void *) &smp->preq[1];
1021 	struct smp_cmd_pairing *rsp = (void *) &smp->prsp[1];
1022 	bool persistent;
1023 
1024 	if (hcon->type == ACL_LINK) {
1025 		if (hcon->key_type == HCI_LK_DEBUG_COMBINATION)
1026 			persistent = false;
1027 		else
1028 			persistent = !test_bit(HCI_CONN_FLUSH_KEY,
1029 					       &hcon->flags);
1030 	} else {
1031 		/* The LTKs, IRKs and CSRKs should be persistent only if
1032 		 * both sides had the bonding bit set in their
1033 		 * authentication requests.
1034 		 */
1035 		persistent = !!((req->auth_req & rsp->auth_req) &
1036 				SMP_AUTH_BONDING);
1037 	}
1038 
1039 	if (smp->remote_irk) {
1040 		mgmt_new_irk(hdev, smp->remote_irk, persistent);
1041 
1042 		/* Now that user space can be considered to know the
1043 		 * identity address track the connection based on it
1044 		 * from now on (assuming this is an LE link).
1045 		 */
1046 		if (hcon->type == LE_LINK) {
1047 			bacpy(&hcon->dst, &smp->remote_irk->bdaddr);
1048 			hcon->dst_type = smp->remote_irk->addr_type;
1049 			/* Use a short delay to make sure the new address is
1050 			 * propagated _before_ the channels.
1051 			 */
1052 			queue_delayed_work(hdev->workqueue,
1053 					   &conn->id_addr_timer,
1054 					   ID_ADDR_TIMEOUT);
1055 		}
1056 	}
1057 
1058 	if (smp->csrk) {
1059 		smp->csrk->bdaddr_type = hcon->dst_type;
1060 		bacpy(&smp->csrk->bdaddr, &hcon->dst);
1061 		mgmt_new_csrk(hdev, smp->csrk, persistent);
1062 	}
1063 
1064 	if (smp->responder_csrk) {
1065 		smp->responder_csrk->bdaddr_type = hcon->dst_type;
1066 		bacpy(&smp->responder_csrk->bdaddr, &hcon->dst);
1067 		mgmt_new_csrk(hdev, smp->responder_csrk, persistent);
1068 	}
1069 
1070 	if (smp->ltk) {
1071 		smp->ltk->bdaddr_type = hcon->dst_type;
1072 		bacpy(&smp->ltk->bdaddr, &hcon->dst);
1073 		mgmt_new_ltk(hdev, smp->ltk, persistent);
1074 	}
1075 
1076 	if (smp->responder_ltk) {
1077 		smp->responder_ltk->bdaddr_type = hcon->dst_type;
1078 		bacpy(&smp->responder_ltk->bdaddr, &hcon->dst);
1079 		mgmt_new_ltk(hdev, smp->responder_ltk, persistent);
1080 	}
1081 
1082 	if (smp->link_key) {
1083 		struct link_key *key;
1084 		u8 type;
1085 
1086 		if (test_bit(SMP_FLAG_DEBUG_KEY, &smp->flags))
1087 			type = HCI_LK_DEBUG_COMBINATION;
1088 		else if (hcon->sec_level == BT_SECURITY_FIPS)
1089 			type = HCI_LK_AUTH_COMBINATION_P256;
1090 		else
1091 			type = HCI_LK_UNAUTH_COMBINATION_P256;
1092 
1093 		key = hci_add_link_key(hdev, smp->conn->hcon, &hcon->dst,
1094 				       smp->link_key, type, 0, &persistent);
1095 		if (key) {
1096 			mgmt_new_link_key(hdev, key, persistent);
1097 
1098 			/* Don't keep debug keys around if the relevant
1099 			 * flag is not set.
1100 			 */
1101 			if (!hci_dev_test_flag(hdev, HCI_KEEP_DEBUG_KEYS) &&
1102 			    key->type == HCI_LK_DEBUG_COMBINATION) {
1103 				list_del_rcu(&key->list);
1104 				kfree_rcu(key, rcu);
1105 			}
1106 		}
1107 	}
1108 }
1109 
1110 static void sc_add_ltk(struct smp_chan *smp)
1111 {
1112 	struct hci_conn *hcon = smp->conn->hcon;
1113 	u8 key_type, auth;
1114 
1115 	if (test_bit(SMP_FLAG_DEBUG_KEY, &smp->flags))
1116 		key_type = SMP_LTK_P256_DEBUG;
1117 	else
1118 		key_type = SMP_LTK_P256;
1119 
1120 	if (hcon->pending_sec_level == BT_SECURITY_FIPS)
1121 		auth = 1;
1122 	else
1123 		auth = 0;
1124 
1125 	smp->ltk = hci_add_ltk(hcon->hdev, &hcon->dst, hcon->dst_type,
1126 			       key_type, auth, smp->tk, smp->enc_key_size,
1127 			       0, 0);
1128 }
1129 
1130 static void sc_generate_link_key(struct smp_chan *smp)
1131 {
1132 	/* From core spec. Spells out in ASCII as 'lebr'. */
1133 	const u8 lebr[4] = { 0x72, 0x62, 0x65, 0x6c };
1134 
1135 	smp->link_key = kzalloc(16, GFP_KERNEL);
1136 	if (!smp->link_key)
1137 		return;
1138 
1139 	if (test_bit(SMP_FLAG_CT2, &smp->flags)) {
1140 		/* SALT = 0x000000000000000000000000746D7031 */
1141 		const u8 salt[16] = { 0x31, 0x70, 0x6d, 0x74 };
1142 
1143 		if (smp_h7(smp->tk, salt, smp->link_key)) {
1144 			kfree_sensitive(smp->link_key);
1145 			smp->link_key = NULL;
1146 			return;
1147 		}
1148 	} else {
1149 		/* From core spec. Spells out in ASCII as 'tmp1'. */
1150 		const u8 tmp1[4] = { 0x31, 0x70, 0x6d, 0x74 };
1151 
1152 		if (smp_h6(smp->tk, tmp1, smp->link_key)) {
1153 			kfree_sensitive(smp->link_key);
1154 			smp->link_key = NULL;
1155 			return;
1156 		}
1157 	}
1158 
1159 	if (smp_h6(smp->link_key, lebr, smp->link_key)) {
1160 		kfree_sensitive(smp->link_key);
1161 		smp->link_key = NULL;
1162 		return;
1163 	}
1164 }
1165 
1166 static void smp_allow_key_dist(struct smp_chan *smp)
1167 {
1168 	/* Allow the first expected phase 3 PDU. The rest of the PDUs
1169 	 * will be allowed in each PDU handler to ensure we receive
1170 	 * them in the correct order.
1171 	 */
1172 	if (smp->remote_key_dist & SMP_DIST_ENC_KEY)
1173 		SMP_ALLOW_CMD(smp, SMP_CMD_ENCRYPT_INFO);
1174 	else if (smp->remote_key_dist & SMP_DIST_ID_KEY)
1175 		SMP_ALLOW_CMD(smp, SMP_CMD_IDENT_INFO);
1176 	else if (smp->remote_key_dist & SMP_DIST_SIGN)
1177 		SMP_ALLOW_CMD(smp, SMP_CMD_SIGN_INFO);
1178 }
1179 
1180 static void sc_generate_ltk(struct smp_chan *smp)
1181 {
1182 	/* From core spec. Spells out in ASCII as 'brle'. */
1183 	const u8 brle[4] = { 0x65, 0x6c, 0x72, 0x62 };
1184 	struct hci_conn *hcon = smp->conn->hcon;
1185 	struct hci_dev *hdev = hcon->hdev;
1186 	struct link_key *key;
1187 
1188 	key = hci_find_link_key(hdev, &hcon->dst);
1189 	if (!key) {
1190 		bt_dev_err(hdev, "no Link Key found to generate LTK");
1191 		return;
1192 	}
1193 
1194 	if (key->type == HCI_LK_DEBUG_COMBINATION)
1195 		set_bit(SMP_FLAG_DEBUG_KEY, &smp->flags);
1196 
1197 	if (test_bit(SMP_FLAG_CT2, &smp->flags)) {
1198 		/* SALT = 0x000000000000000000000000746D7032 */
1199 		const u8 salt[16] = { 0x32, 0x70, 0x6d, 0x74 };
1200 
1201 		if (smp_h7(key->val, salt, smp->tk))
1202 			return;
1203 	} else {
1204 		/* From core spec. Spells out in ASCII as 'tmp2'. */
1205 		const u8 tmp2[4] = { 0x32, 0x70, 0x6d, 0x74 };
1206 
1207 		if (smp_h6(key->val, tmp2, smp->tk))
1208 			return;
1209 	}
1210 
1211 	if (smp_h6(smp->tk, brle, smp->tk))
1212 		return;
1213 
1214 	sc_add_ltk(smp);
1215 }
1216 
1217 static void smp_distribute_keys(struct smp_chan *smp)
1218 {
1219 	struct smp_cmd_pairing *req, *rsp;
1220 	struct l2cap_conn *conn = smp->conn;
1221 	struct hci_conn *hcon = conn->hcon;
1222 	struct hci_dev *hdev = hcon->hdev;
1223 	__u8 *keydist;
1224 
1225 	bt_dev_dbg(hdev, "conn %p", conn);
1226 
1227 	rsp = (void *) &smp->prsp[1];
1228 
1229 	/* The responder sends its keys first */
1230 	if (test_bit(SMP_FLAG_INITIATOR, &smp->flags) &&
1231 	    (smp->remote_key_dist & KEY_DIST_MASK)) {
1232 		smp_allow_key_dist(smp);
1233 		return;
1234 	}
1235 
1236 	req = (void *) &smp->preq[1];
1237 
1238 	if (test_bit(SMP_FLAG_INITIATOR, &smp->flags)) {
1239 		keydist = &rsp->init_key_dist;
1240 		*keydist &= req->init_key_dist;
1241 	} else {
1242 		keydist = &rsp->resp_key_dist;
1243 		*keydist &= req->resp_key_dist;
1244 	}
1245 
1246 	if (test_bit(SMP_FLAG_SC, &smp->flags)) {
1247 		if (hcon->type == LE_LINK && (*keydist & SMP_DIST_LINK_KEY))
1248 			sc_generate_link_key(smp);
1249 		if (hcon->type == ACL_LINK && (*keydist & SMP_DIST_ENC_KEY))
1250 			sc_generate_ltk(smp);
1251 
1252 		/* Clear the keys which are generated but not distributed */
1253 		*keydist &= ~SMP_SC_NO_DIST;
1254 	}
1255 
1256 	bt_dev_dbg(hdev, "keydist 0x%x", *keydist);
1257 
1258 	if (*keydist & SMP_DIST_ENC_KEY) {
1259 		struct smp_cmd_encrypt_info enc;
1260 		struct smp_cmd_initiator_ident ident;
1261 		struct smp_ltk *ltk;
1262 		u8 authenticated;
1263 		__le16 ediv;
1264 		__le64 rand;
1265 
1266 		/* Make sure we generate only the significant amount of
1267 		 * bytes based on the encryption key size, and set the rest
1268 		 * of the value to zeroes.
1269 		 */
1270 		get_random_bytes(enc.ltk, smp->enc_key_size);
1271 		memset(enc.ltk + smp->enc_key_size, 0,
1272 		       sizeof(enc.ltk) - smp->enc_key_size);
1273 
1274 		get_random_bytes(&ediv, sizeof(ediv));
1275 		get_random_bytes(&rand, sizeof(rand));
1276 
1277 		smp_send_cmd(conn, SMP_CMD_ENCRYPT_INFO, sizeof(enc), &enc);
1278 
1279 		authenticated = hcon->sec_level == BT_SECURITY_HIGH;
1280 		ltk = hci_add_ltk(hdev, &hcon->dst, hcon->dst_type,
1281 				  SMP_LTK_RESPONDER, authenticated, enc.ltk,
1282 				  smp->enc_key_size, ediv, rand);
1283 		smp->responder_ltk = ltk;
1284 
1285 		ident.ediv = ediv;
1286 		ident.rand = rand;
1287 
1288 		smp_send_cmd(conn, SMP_CMD_INITIATOR_IDENT, sizeof(ident),
1289 			     &ident);
1290 
1291 		*keydist &= ~SMP_DIST_ENC_KEY;
1292 	}
1293 
1294 	if (*keydist & SMP_DIST_ID_KEY) {
1295 		struct smp_cmd_ident_addr_info addrinfo;
1296 		struct smp_cmd_ident_info idinfo;
1297 
1298 		memcpy(idinfo.irk, hdev->irk, sizeof(idinfo.irk));
1299 
1300 		smp_send_cmd(conn, SMP_CMD_IDENT_INFO, sizeof(idinfo), &idinfo);
1301 
1302 		/* The hci_conn contains the local identity address
1303 		 * after the connection has been established.
1304 		 *
1305 		 * This is true even when the connection has been
1306 		 * established using a resolvable random address.
1307 		 */
1308 		bacpy(&addrinfo.bdaddr, &hcon->src);
1309 		addrinfo.addr_type = hcon->src_type;
1310 
1311 		smp_send_cmd(conn, SMP_CMD_IDENT_ADDR_INFO, sizeof(addrinfo),
1312 			     &addrinfo);
1313 
1314 		*keydist &= ~SMP_DIST_ID_KEY;
1315 	}
1316 
1317 	if (*keydist & SMP_DIST_SIGN) {
1318 		struct smp_cmd_sign_info sign;
1319 		struct smp_csrk *csrk;
1320 
1321 		/* Generate a new random key */
1322 		get_random_bytes(sign.csrk, sizeof(sign.csrk));
1323 
1324 		csrk = kzalloc_obj(*csrk);
1325 		if (csrk) {
1326 			if (hcon->sec_level > BT_SECURITY_MEDIUM)
1327 				csrk->type = MGMT_CSRK_LOCAL_AUTHENTICATED;
1328 			else
1329 				csrk->type = MGMT_CSRK_LOCAL_UNAUTHENTICATED;
1330 			memcpy(csrk->val, sign.csrk, sizeof(csrk->val));
1331 		}
1332 		smp->responder_csrk = csrk;
1333 
1334 		smp_send_cmd(conn, SMP_CMD_SIGN_INFO, sizeof(sign), &sign);
1335 
1336 		*keydist &= ~SMP_DIST_SIGN;
1337 	}
1338 
1339 	/* If there are still keys to be received wait for them */
1340 	if (smp->remote_key_dist & KEY_DIST_MASK) {
1341 		smp_allow_key_dist(smp);
1342 		return;
1343 	}
1344 
1345 	set_bit(SMP_FLAG_COMPLETE, &smp->flags);
1346 	smp_notify_keys(conn);
1347 
1348 	smp_chan_destroy(conn);
1349 }
1350 
1351 static void smp_timeout(struct work_struct *work)
1352 {
1353 	struct smp_chan *smp = container_of(work, struct smp_chan,
1354 					    security_timer.work);
1355 	struct l2cap_conn *conn = smp->conn;
1356 
1357 	bt_dev_dbg(conn->hcon->hdev, "conn %p", conn);
1358 
1359 	hci_disconnect(conn->hcon, HCI_ERROR_AUTH_FAILURE);
1360 }
1361 
1362 static struct smp_chan *smp_chan_create(struct l2cap_conn *conn)
1363 {
1364 	struct hci_conn *hcon = conn->hcon;
1365 	struct l2cap_chan *chan = conn->smp;
1366 	struct smp_chan *smp;
1367 
1368 	smp = kzalloc_obj(*smp, GFP_ATOMIC);
1369 	if (!smp)
1370 		return NULL;
1371 
1372 	smp->tfm_ecdh = crypto_alloc_kpp("ecdh-nist-p256", 0, 0);
1373 	if (IS_ERR(smp->tfm_ecdh)) {
1374 		bt_dev_err(hcon->hdev, "Unable to create ECDH crypto context");
1375 		goto zfree_smp;
1376 	}
1377 
1378 	smp->conn = conn;
1379 	chan->data = smp;
1380 
1381 	SMP_ALLOW_CMD(smp, SMP_CMD_PAIRING_FAIL);
1382 
1383 	INIT_DELAYED_WORK(&smp->security_timer, smp_timeout);
1384 
1385 	hci_conn_hold(hcon);
1386 
1387 	return smp;
1388 
1389 zfree_smp:
1390 	kfree_sensitive(smp);
1391 	return NULL;
1392 }
1393 
1394 static int sc_mackey_and_ltk(struct smp_chan *smp, u8 mackey[16], u8 ltk[16])
1395 {
1396 	struct hci_conn *hcon = smp->conn->hcon;
1397 	u8 *na, *nb, a[7], b[7];
1398 
1399 	if (test_bit(SMP_FLAG_INITIATOR, &smp->flags)) {
1400 		na   = smp->prnd;
1401 		nb   = smp->rrnd;
1402 	} else {
1403 		na   = smp->rrnd;
1404 		nb   = smp->prnd;
1405 	}
1406 
1407 	memcpy(a, &hcon->init_addr, 6);
1408 	memcpy(b, &hcon->resp_addr, 6);
1409 	a[6] = hcon->init_addr_type;
1410 	b[6] = hcon->resp_addr_type;
1411 
1412 	return smp_f5(smp->dhkey, na, nb, a, b, mackey, ltk);
1413 }
1414 
1415 static void sc_dhkey_check(struct smp_chan *smp)
1416 {
1417 	struct hci_conn *hcon = smp->conn->hcon;
1418 	struct smp_cmd_dhkey_check check;
1419 	u8 a[7], b[7], *local_addr, *remote_addr;
1420 	u8 io_cap[3], r[16];
1421 
1422 	memcpy(a, &hcon->init_addr, 6);
1423 	memcpy(b, &hcon->resp_addr, 6);
1424 	a[6] = hcon->init_addr_type;
1425 	b[6] = hcon->resp_addr_type;
1426 
1427 	if (test_bit(SMP_FLAG_INITIATOR, &smp->flags)) {
1428 		local_addr = a;
1429 		remote_addr = b;
1430 		memcpy(io_cap, &smp->preq[1], 3);
1431 	} else {
1432 		local_addr = b;
1433 		remote_addr = a;
1434 		memcpy(io_cap, &smp->prsp[1], 3);
1435 	}
1436 
1437 	memset(r, 0, sizeof(r));
1438 
1439 	if (smp->method == REQ_PASSKEY || smp->method == DSP_PASSKEY)
1440 		put_unaligned_le32(hcon->passkey_notify, r);
1441 
1442 	if (smp->method == REQ_OOB)
1443 		memcpy(r, smp->rr, 16);
1444 
1445 	smp_f6(smp->mackey, smp->prnd, smp->rrnd, r, io_cap, local_addr,
1446 	       remote_addr, check.e);
1447 
1448 	smp_send_cmd(smp->conn, SMP_CMD_DHKEY_CHECK, sizeof(check), &check);
1449 }
1450 
1451 static u8 sc_passkey_send_confirm(struct smp_chan *smp)
1452 {
1453 	struct l2cap_conn *conn = smp->conn;
1454 	struct hci_conn *hcon = conn->hcon;
1455 	struct smp_cmd_pairing_confirm cfm;
1456 	u8 r;
1457 
1458 	r = ((hcon->passkey_notify >> smp->passkey_round) & 0x01);
1459 	r |= 0x80;
1460 
1461 	get_random_bytes(smp->prnd, sizeof(smp->prnd));
1462 
1463 	if (smp_f4(smp->local_pk, smp->remote_pk, smp->prnd, r,
1464 		   cfm.confirm_val))
1465 		return SMP_UNSPECIFIED;
1466 
1467 	smp_send_cmd(conn, SMP_CMD_PAIRING_CONFIRM, sizeof(cfm), &cfm);
1468 
1469 	return 0;
1470 }
1471 
1472 static u8 sc_passkey_round(struct smp_chan *smp, u8 smp_op)
1473 {
1474 	struct l2cap_conn *conn = smp->conn;
1475 	struct hci_conn *hcon = conn->hcon;
1476 	struct hci_dev *hdev = hcon->hdev;
1477 	u8 cfm[16], r;
1478 
1479 	/* Ignore the PDU if we've already done 20 rounds (0 - 19) */
1480 	if (smp->passkey_round >= 20)
1481 		return 0;
1482 
1483 	switch (smp_op) {
1484 	case SMP_CMD_PAIRING_RANDOM:
1485 		r = ((hcon->passkey_notify >> smp->passkey_round) & 0x01);
1486 		r |= 0x80;
1487 
1488 		if (smp_f4(smp->remote_pk, smp->local_pk, smp->rrnd, r, cfm))
1489 			return SMP_UNSPECIFIED;
1490 
1491 		if (crypto_memneq(smp->pcnf, cfm, 16))
1492 			return SMP_CONFIRM_FAILED;
1493 
1494 		smp->passkey_round++;
1495 
1496 		if (smp->passkey_round == 20) {
1497 			/* Generate MacKey and LTK */
1498 			if (sc_mackey_and_ltk(smp, smp->mackey, smp->tk))
1499 				return SMP_UNSPECIFIED;
1500 		}
1501 
1502 		/* The round is only complete when the initiator
1503 		 * receives pairing random.
1504 		 */
1505 		if (!test_bit(SMP_FLAG_INITIATOR, &smp->flags)) {
1506 			smp_send_cmd(conn, SMP_CMD_PAIRING_RANDOM,
1507 				     sizeof(smp->prnd), smp->prnd);
1508 			if (smp->passkey_round == 20)
1509 				SMP_ALLOW_CMD(smp, SMP_CMD_DHKEY_CHECK);
1510 			else
1511 				SMP_ALLOW_CMD(smp, SMP_CMD_PAIRING_CONFIRM);
1512 			return 0;
1513 		}
1514 
1515 		/* Start the next round */
1516 		if (smp->passkey_round != 20)
1517 			return sc_passkey_round(smp, 0);
1518 
1519 		/* Passkey rounds are complete - start DHKey Check */
1520 		sc_dhkey_check(smp);
1521 		SMP_ALLOW_CMD(smp, SMP_CMD_DHKEY_CHECK);
1522 
1523 		break;
1524 
1525 	case SMP_CMD_PAIRING_CONFIRM:
1526 		if (test_bit(SMP_FLAG_WAIT_USER, &smp->flags)) {
1527 			set_bit(SMP_FLAG_CFM_PENDING, &smp->flags);
1528 			return 0;
1529 		}
1530 
1531 		SMP_ALLOW_CMD(smp, SMP_CMD_PAIRING_RANDOM);
1532 
1533 		if (test_bit(SMP_FLAG_INITIATOR, &smp->flags)) {
1534 			smp_send_cmd(conn, SMP_CMD_PAIRING_RANDOM,
1535 				     sizeof(smp->prnd), smp->prnd);
1536 			return 0;
1537 		}
1538 
1539 		return sc_passkey_send_confirm(smp);
1540 
1541 	case SMP_CMD_PUBLIC_KEY:
1542 	default:
1543 		/* Initiating device starts the round */
1544 		if (!test_bit(SMP_FLAG_INITIATOR, &smp->flags))
1545 			return 0;
1546 
1547 		bt_dev_dbg(hdev, "Starting passkey round %u",
1548 			   smp->passkey_round + 1);
1549 
1550 		SMP_ALLOW_CMD(smp, SMP_CMD_PAIRING_CONFIRM);
1551 
1552 		return sc_passkey_send_confirm(smp);
1553 	}
1554 
1555 	return 0;
1556 }
1557 
1558 static int sc_user_reply(struct smp_chan *smp, u16 mgmt_op, __le32 passkey)
1559 {
1560 	struct l2cap_conn *conn = smp->conn;
1561 	struct hci_conn *hcon = conn->hcon;
1562 	u8 smp_op;
1563 
1564 	clear_bit(SMP_FLAG_WAIT_USER, &smp->flags);
1565 
1566 	switch (mgmt_op) {
1567 	case MGMT_OP_USER_PASSKEY_NEG_REPLY:
1568 		smp_failure(smp->conn, SMP_PASSKEY_ENTRY_FAILED);
1569 		return 0;
1570 	case MGMT_OP_USER_CONFIRM_NEG_REPLY:
1571 		smp_failure(smp->conn, SMP_NUMERIC_COMP_FAILED);
1572 		return 0;
1573 	case MGMT_OP_USER_PASSKEY_REPLY:
1574 		hcon->passkey_notify = le32_to_cpu(passkey);
1575 		smp->passkey_round = 0;
1576 
1577 		if (test_and_clear_bit(SMP_FLAG_CFM_PENDING, &smp->flags))
1578 			smp_op = SMP_CMD_PAIRING_CONFIRM;
1579 		else
1580 			smp_op = 0;
1581 
1582 		if (sc_passkey_round(smp, smp_op))
1583 			return -EIO;
1584 
1585 		return 0;
1586 	}
1587 
1588 	/* Initiator sends DHKey check first */
1589 	if (test_bit(SMP_FLAG_INITIATOR, &smp->flags)) {
1590 		sc_dhkey_check(smp);
1591 		SMP_ALLOW_CMD(smp, SMP_CMD_DHKEY_CHECK);
1592 	} else if (test_and_clear_bit(SMP_FLAG_DHKEY_PENDING, &smp->flags)) {
1593 		sc_dhkey_check(smp);
1594 		sc_add_ltk(smp);
1595 	}
1596 
1597 	return 0;
1598 }
1599 
1600 int smp_user_confirm_reply(struct hci_conn *hcon, u16 mgmt_op, __le32 passkey)
1601 {
1602 	struct l2cap_conn *conn = hcon->l2cap_data;
1603 	struct l2cap_chan *chan;
1604 	struct smp_chan *smp;
1605 	u32 value;
1606 	int err;
1607 
1608 	if (!conn)
1609 		return -ENOTCONN;
1610 
1611 	bt_dev_dbg(conn->hcon->hdev, "");
1612 
1613 	chan = conn->smp;
1614 	if (!chan)
1615 		return -ENOTCONN;
1616 
1617 	l2cap_chan_lock(chan);
1618 	if (!chan->data) {
1619 		err = -ENOTCONN;
1620 		goto unlock;
1621 	}
1622 
1623 	smp = chan->data;
1624 
1625 	if (test_bit(SMP_FLAG_SC, &smp->flags)) {
1626 		err = sc_user_reply(smp, mgmt_op, passkey);
1627 		goto unlock;
1628 	}
1629 
1630 	switch (mgmt_op) {
1631 	case MGMT_OP_USER_PASSKEY_REPLY:
1632 		value = le32_to_cpu(passkey);
1633 		memset(smp->tk, 0, sizeof(smp->tk));
1634 		bt_dev_dbg(conn->hcon->hdev, "PassKey: %u", value);
1635 		put_unaligned_le32(value, smp->tk);
1636 		fallthrough;
1637 	case MGMT_OP_USER_CONFIRM_REPLY:
1638 		set_bit(SMP_FLAG_TK_VALID, &smp->flags);
1639 		break;
1640 	case MGMT_OP_USER_PASSKEY_NEG_REPLY:
1641 	case MGMT_OP_USER_CONFIRM_NEG_REPLY:
1642 		smp_failure(conn, SMP_PASSKEY_ENTRY_FAILED);
1643 		err = 0;
1644 		goto unlock;
1645 	default:
1646 		smp_failure(conn, SMP_PASSKEY_ENTRY_FAILED);
1647 		err = -EOPNOTSUPP;
1648 		goto unlock;
1649 	}
1650 
1651 	err = 0;
1652 
1653 	/* If it is our turn to send Pairing Confirm, do so now */
1654 	if (test_bit(SMP_FLAG_CFM_PENDING, &smp->flags)) {
1655 		u8 rsp = smp_confirm(smp);
1656 		if (rsp)
1657 			smp_failure(conn, rsp);
1658 	}
1659 
1660 unlock:
1661 	l2cap_chan_unlock(chan);
1662 	return err;
1663 }
1664 
1665 static void build_bredr_pairing_cmd(struct smp_chan *smp,
1666 				    struct smp_cmd_pairing *req,
1667 				    struct smp_cmd_pairing *rsp)
1668 {
1669 	struct l2cap_conn *conn = smp->conn;
1670 	struct hci_dev *hdev = conn->hcon->hdev;
1671 	u8 local_dist = 0, remote_dist = 0;
1672 
1673 	if (hci_dev_test_flag(hdev, HCI_BONDABLE)) {
1674 		local_dist = SMP_DIST_ENC_KEY | SMP_DIST_SIGN;
1675 		remote_dist = SMP_DIST_ENC_KEY | SMP_DIST_SIGN;
1676 	}
1677 
1678 	if (hci_dev_test_flag(hdev, HCI_RPA_RESOLVING))
1679 		remote_dist |= SMP_DIST_ID_KEY;
1680 
1681 	if (hci_dev_test_flag(hdev, HCI_PRIVACY))
1682 		local_dist |= SMP_DIST_ID_KEY;
1683 
1684 	if (!rsp) {
1685 		memset(req, 0, sizeof(*req));
1686 
1687 		req->auth_req        = SMP_AUTH_CT2;
1688 		req->init_key_dist   = local_dist;
1689 		req->resp_key_dist   = remote_dist;
1690 		req->max_key_size    = conn->hcon->enc_key_size;
1691 
1692 		smp->remote_key_dist = remote_dist;
1693 
1694 		return;
1695 	}
1696 
1697 	memset(rsp, 0, sizeof(*rsp));
1698 
1699 	rsp->auth_req        = SMP_AUTH_CT2;
1700 	rsp->max_key_size    = conn->hcon->enc_key_size;
1701 	rsp->init_key_dist   = req->init_key_dist & remote_dist;
1702 	rsp->resp_key_dist   = req->resp_key_dist & local_dist;
1703 
1704 	smp->remote_key_dist = rsp->init_key_dist;
1705 }
1706 
1707 static u8 smp_cmd_pairing_req(struct l2cap_conn *conn, struct sk_buff *skb)
1708 {
1709 	struct smp_cmd_pairing rsp, *req = (void *) skb->data;
1710 	struct l2cap_chan *chan = conn->smp;
1711 	struct hci_dev *hdev = conn->hcon->hdev;
1712 	struct smp_chan *smp = chan->data;
1713 	u8 key_size, auth, sec_level;
1714 	int ret;
1715 
1716 	bt_dev_dbg(hdev, "conn %p", conn);
1717 
1718 	if (skb->len < sizeof(*req))
1719 		return SMP_INVALID_PARAMS;
1720 
1721 	if (smp && test_bit(SMP_FLAG_INITIATOR, &smp->flags))
1722 		return SMP_CMD_NOTSUPP;
1723 
1724 	if (!smp) {
1725 		smp = smp_chan_create(conn);
1726 		if (!smp)
1727 			return SMP_UNSPECIFIED;
1728 	}
1729 
1730 	/* We didn't start the pairing, so match remote */
1731 	auth = req->auth_req & AUTH_REQ_MASK(hdev);
1732 
1733 	if (!hci_dev_test_flag(hdev, HCI_BONDABLE) &&
1734 	    (auth & SMP_AUTH_BONDING))
1735 		return SMP_PAIRING_NOTSUPP;
1736 
1737 	if (hci_dev_test_flag(hdev, HCI_SC_ONLY) && !(auth & SMP_AUTH_SC))
1738 		return SMP_AUTH_REQUIREMENTS;
1739 
1740 	smp->preq[0] = SMP_CMD_PAIRING_REQ;
1741 	memcpy(&smp->preq[1], req, sizeof(*req));
1742 	skb_pull(skb, sizeof(*req));
1743 
1744 	/* If the remote side's OOB flag is set it means it has
1745 	 * successfully received our local OOB data - therefore set the
1746 	 * flag to indicate that local OOB is in use.
1747 	 */
1748 	if (req->oob_flag == SMP_OOB_PRESENT && SMP_DEV(hdev)->local_oob)
1749 		set_bit(SMP_FLAG_LOCAL_OOB, &smp->flags);
1750 
1751 	/* SMP over BR/EDR requires special treatment */
1752 	if (conn->hcon->type == ACL_LINK) {
1753 		/* We must have a BR/EDR SC link */
1754 		if (!test_bit(HCI_CONN_AES_CCM, &conn->hcon->flags) &&
1755 		    !hci_dev_test_flag(hdev, HCI_FORCE_BREDR_SMP))
1756 			return SMP_CROSS_TRANSP_NOT_ALLOWED;
1757 
1758 		set_bit(SMP_FLAG_SC, &smp->flags);
1759 
1760 		build_bredr_pairing_cmd(smp, req, &rsp);
1761 
1762 		if (req->auth_req & SMP_AUTH_CT2)
1763 			set_bit(SMP_FLAG_CT2, &smp->flags);
1764 
1765 		key_size = min(req->max_key_size, rsp.max_key_size);
1766 		if (check_enc_key_size(conn, key_size))
1767 			return SMP_ENC_KEY_SIZE;
1768 
1769 		/* Clear bits which are generated but not distributed */
1770 		smp->remote_key_dist &= ~SMP_SC_NO_DIST;
1771 
1772 		smp->prsp[0] = SMP_CMD_PAIRING_RSP;
1773 		memcpy(&smp->prsp[1], &rsp, sizeof(rsp));
1774 		smp_send_cmd(conn, SMP_CMD_PAIRING_RSP, sizeof(rsp), &rsp);
1775 
1776 		smp_distribute_keys(smp);
1777 		return 0;
1778 	}
1779 
1780 	build_pairing_cmd(conn, req, &rsp, auth);
1781 
1782 	if (rsp.auth_req & SMP_AUTH_SC) {
1783 		set_bit(SMP_FLAG_SC, &smp->flags);
1784 
1785 		if (rsp.auth_req & SMP_AUTH_CT2)
1786 			set_bit(SMP_FLAG_CT2, &smp->flags);
1787 	}
1788 
1789 	if (conn->hcon->io_capability == HCI_IO_NO_INPUT_OUTPUT)
1790 		sec_level = BT_SECURITY_MEDIUM;
1791 	else
1792 		sec_level = authreq_to_seclevel(auth);
1793 
1794 	if (sec_level > conn->hcon->pending_sec_level)
1795 		conn->hcon->pending_sec_level = sec_level;
1796 
1797 	/* If we need MITM check that it can be achieved. */
1798 	if (conn->hcon->pending_sec_level >= BT_SECURITY_HIGH) {
1799 		u8 method;
1800 
1801 		method = get_auth_method(smp, conn->hcon->io_capability,
1802 					 req->io_capability);
1803 		if (method == JUST_WORKS || method == JUST_CFM)
1804 			return SMP_AUTH_REQUIREMENTS;
1805 
1806 		/* Force MITM bit if it isn't set by the initiator. */
1807 		auth |= SMP_AUTH_MITM;
1808 		rsp.auth_req |= SMP_AUTH_MITM;
1809 	}
1810 
1811 	key_size = min(req->max_key_size, rsp.max_key_size);
1812 	if (check_enc_key_size(conn, key_size))
1813 		return SMP_ENC_KEY_SIZE;
1814 
1815 	get_random_bytes(smp->prnd, sizeof(smp->prnd));
1816 
1817 	smp->prsp[0] = SMP_CMD_PAIRING_RSP;
1818 	memcpy(&smp->prsp[1], &rsp, sizeof(rsp));
1819 
1820 	smp_send_cmd(conn, SMP_CMD_PAIRING_RSP, sizeof(rsp), &rsp);
1821 
1822 	clear_bit(SMP_FLAG_INITIATOR, &smp->flags);
1823 
1824 	/* Strictly speaking we shouldn't allow Pairing Confirm for the
1825 	 * SC case, however some implementations incorrectly copy RFU auth
1826 	 * req bits from our security request, which may create a false
1827 	 * positive SC enablement.
1828 	 */
1829 	SMP_ALLOW_CMD(smp, SMP_CMD_PAIRING_CONFIRM);
1830 
1831 	if (test_bit(SMP_FLAG_SC, &smp->flags)) {
1832 		SMP_ALLOW_CMD(smp, SMP_CMD_PUBLIC_KEY);
1833 		/* Clear bits which are generated but not distributed */
1834 		smp->remote_key_dist &= ~SMP_SC_NO_DIST;
1835 		/* Wait for Public Key from Initiating Device */
1836 		return 0;
1837 	}
1838 
1839 	/* Request setup of TK */
1840 	ret = tk_request(conn, 0, auth, rsp.io_capability, req->io_capability);
1841 	if (ret)
1842 		return SMP_UNSPECIFIED;
1843 
1844 	return 0;
1845 }
1846 
1847 static u8 sc_send_public_key(struct smp_chan *smp)
1848 {
1849 	struct hci_dev *hdev = smp->conn->hcon->hdev;
1850 
1851 	bt_dev_dbg(hdev, "");
1852 
1853 	if (test_bit(SMP_FLAG_LOCAL_OOB, &smp->flags)) {
1854 		struct l2cap_chan *chan = hdev->smp_data;
1855 		struct smp_dev *smp_dev;
1856 
1857 		if (!chan || !chan->data)
1858 			return SMP_UNSPECIFIED;
1859 
1860 		smp_dev = chan->data;
1861 
1862 		memcpy(smp->local_pk, smp_dev->local_pk, 64);
1863 		memcpy(smp->lr, smp_dev->local_rand, 16);
1864 
1865 		if (smp_dev->debug_key)
1866 			set_bit(SMP_FLAG_DEBUG_KEY, &smp->flags);
1867 
1868 		goto done;
1869 	}
1870 
1871 	if (hci_dev_test_flag(hdev, HCI_USE_DEBUG_KEYS)) {
1872 		bt_dev_dbg(hdev, "Using debug keys");
1873 		if (set_ecdh_privkey(smp->tfm_ecdh, debug_sk))
1874 			return SMP_UNSPECIFIED;
1875 		memcpy(smp->local_pk, debug_pk, 64);
1876 		set_bit(SMP_FLAG_DEBUG_KEY, &smp->flags);
1877 	} else {
1878 		while (true) {
1879 			/* Generate key pair for Secure Connections */
1880 			if (generate_ecdh_keys(smp->tfm_ecdh, smp->local_pk))
1881 				return SMP_UNSPECIFIED;
1882 
1883 			/* This is unlikely, but we need to check that
1884 			 * we didn't accidentally generate a debug key.
1885 			 */
1886 			if (crypto_memneq(smp->local_pk, debug_pk, 64))
1887 				break;
1888 		}
1889 	}
1890 
1891 done:
1892 	SMP_DBG("Local Public Key X: %32phN", smp->local_pk);
1893 	SMP_DBG("Local Public Key Y: %32phN", smp->local_pk + 32);
1894 
1895 	smp_send_cmd(smp->conn, SMP_CMD_PUBLIC_KEY, 64, smp->local_pk);
1896 
1897 	return 0;
1898 }
1899 
1900 static u8 smp_cmd_pairing_rsp(struct l2cap_conn *conn, struct sk_buff *skb)
1901 {
1902 	struct smp_cmd_pairing *req, *rsp = (void *) skb->data;
1903 	struct l2cap_chan *chan = conn->smp;
1904 	struct smp_chan *smp = chan->data;
1905 	struct hci_dev *hdev = conn->hcon->hdev;
1906 	u8 key_size, auth;
1907 	int ret;
1908 
1909 	bt_dev_dbg(hdev, "conn %p", conn);
1910 
1911 	if (skb->len < sizeof(*rsp))
1912 		return SMP_INVALID_PARAMS;
1913 
1914 	if (!test_bit(SMP_FLAG_INITIATOR, &smp->flags))
1915 		return SMP_CMD_NOTSUPP;
1916 
1917 	skb_pull(skb, sizeof(*rsp));
1918 
1919 	req = (void *) &smp->preq[1];
1920 
1921 	key_size = min(req->max_key_size, rsp->max_key_size);
1922 	if (check_enc_key_size(conn, key_size))
1923 		return SMP_ENC_KEY_SIZE;
1924 
1925 	auth = rsp->auth_req & AUTH_REQ_MASK(hdev);
1926 
1927 	if (hci_dev_test_flag(hdev, HCI_SC_ONLY) && !(auth & SMP_AUTH_SC))
1928 		return SMP_AUTH_REQUIREMENTS;
1929 
1930 	/* If the remote side's OOB flag is set it means it has
1931 	 * successfully received our local OOB data - therefore set the
1932 	 * flag to indicate that local OOB is in use.
1933 	 */
1934 	if (rsp->oob_flag == SMP_OOB_PRESENT && SMP_DEV(hdev)->local_oob)
1935 		set_bit(SMP_FLAG_LOCAL_OOB, &smp->flags);
1936 
1937 	smp->prsp[0] = SMP_CMD_PAIRING_RSP;
1938 	memcpy(&smp->prsp[1], rsp, sizeof(*rsp));
1939 
1940 	/* Update remote key distribution in case the remote cleared
1941 	 * some bits that we had enabled in our request.
1942 	 */
1943 	smp->remote_key_dist &= rsp->resp_key_dist;
1944 
1945 	if ((req->auth_req & SMP_AUTH_CT2) && (auth & SMP_AUTH_CT2))
1946 		set_bit(SMP_FLAG_CT2, &smp->flags);
1947 
1948 	/* For BR/EDR this means we're done and can start phase 3 */
1949 	if (conn->hcon->type == ACL_LINK) {
1950 		/* Clear bits which are generated but not distributed */
1951 		smp->remote_key_dist &= ~SMP_SC_NO_DIST;
1952 		smp_distribute_keys(smp);
1953 		return 0;
1954 	}
1955 
1956 	if ((req->auth_req & SMP_AUTH_SC) && (auth & SMP_AUTH_SC))
1957 		set_bit(SMP_FLAG_SC, &smp->flags);
1958 	else if (conn->hcon->pending_sec_level > BT_SECURITY_HIGH)
1959 		conn->hcon->pending_sec_level = BT_SECURITY_HIGH;
1960 
1961 	/* If we need MITM check that it can be achieved */
1962 	if (conn->hcon->pending_sec_level >= BT_SECURITY_HIGH) {
1963 		u8 method;
1964 
1965 		method = get_auth_method(smp, req->io_capability,
1966 					 rsp->io_capability);
1967 		if (method == JUST_WORKS || method == JUST_CFM)
1968 			return SMP_AUTH_REQUIREMENTS;
1969 	}
1970 
1971 	get_random_bytes(smp->prnd, sizeof(smp->prnd));
1972 
1973 	/* Update remote key distribution in case the remote cleared
1974 	 * some bits that we had enabled in our request.
1975 	 */
1976 	smp->remote_key_dist &= rsp->resp_key_dist;
1977 
1978 	if (test_bit(SMP_FLAG_SC, &smp->flags)) {
1979 		/* Clear bits which are generated but not distributed */
1980 		smp->remote_key_dist &= ~SMP_SC_NO_DIST;
1981 		SMP_ALLOW_CMD(smp, SMP_CMD_PUBLIC_KEY);
1982 		return sc_send_public_key(smp);
1983 	}
1984 
1985 	auth |= req->auth_req;
1986 
1987 	ret = tk_request(conn, 0, auth, req->io_capability, rsp->io_capability);
1988 	if (ret)
1989 		return SMP_UNSPECIFIED;
1990 
1991 	set_bit(SMP_FLAG_CFM_PENDING, &smp->flags);
1992 
1993 	/* Can't compose response until we have been confirmed */
1994 	if (test_bit(SMP_FLAG_TK_VALID, &smp->flags))
1995 		return smp_confirm(smp);
1996 
1997 	return 0;
1998 }
1999 
2000 static u8 sc_check_confirm(struct smp_chan *smp)
2001 {
2002 	struct l2cap_conn *conn = smp->conn;
2003 
2004 	bt_dev_dbg(conn->hcon->hdev, "");
2005 
2006 	if (smp->method == REQ_PASSKEY || smp->method == DSP_PASSKEY)
2007 		return sc_passkey_round(smp, SMP_CMD_PAIRING_CONFIRM);
2008 
2009 	if (test_bit(SMP_FLAG_INITIATOR, &smp->flags)) {
2010 		smp_send_cmd(conn, SMP_CMD_PAIRING_RANDOM, sizeof(smp->prnd),
2011 			     smp->prnd);
2012 		SMP_ALLOW_CMD(smp, SMP_CMD_PAIRING_RANDOM);
2013 	}
2014 
2015 	return 0;
2016 }
2017 
2018 /* Work-around for some implementations that incorrectly copy RFU bits
2019  * from our security request and thereby create the impression that
2020  * we're doing SC when in fact the remote doesn't support it.
2021  */
2022 static int fixup_sc_false_positive(struct smp_chan *smp)
2023 {
2024 	struct l2cap_conn *conn = smp->conn;
2025 	struct hci_conn *hcon = conn->hcon;
2026 	struct hci_dev *hdev = hcon->hdev;
2027 	struct smp_cmd_pairing *req, *rsp;
2028 	u8 auth;
2029 
2030 	/* The issue is only observed when we're in responder role */
2031 	if (test_bit(SMP_FLAG_INITIATOR, &smp->flags))
2032 		return SMP_UNSPECIFIED;
2033 
2034 	if (hci_dev_test_flag(hdev, HCI_SC_ONLY)) {
2035 		bt_dev_err(hdev, "refusing legacy fallback in SC-only mode");
2036 		return SMP_UNSPECIFIED;
2037 	}
2038 
2039 	bt_dev_err(hdev, "trying to fall back to legacy SMP");
2040 
2041 	req = (void *) &smp->preq[1];
2042 	rsp = (void *) &smp->prsp[1];
2043 
2044 	/* Rebuild key dist flags which may have been cleared for SC */
2045 	smp->remote_key_dist = (req->init_key_dist & rsp->resp_key_dist);
2046 
2047 	auth = req->auth_req & AUTH_REQ_MASK(hdev);
2048 
2049 	if (tk_request(conn, 0, auth, rsp->io_capability, req->io_capability)) {
2050 		bt_dev_err(hdev, "failed to fall back to legacy SMP");
2051 		return SMP_UNSPECIFIED;
2052 	}
2053 
2054 	clear_bit(SMP_FLAG_SC, &smp->flags);
2055 
2056 	return 0;
2057 }
2058 
2059 static u8 smp_cmd_pairing_confirm(struct l2cap_conn *conn, struct sk_buff *skb)
2060 {
2061 	struct l2cap_chan *chan = conn->smp;
2062 	struct smp_chan *smp = chan->data;
2063 	struct hci_conn *hcon = conn->hcon;
2064 	struct hci_dev *hdev = hcon->hdev;
2065 
2066 	bt_dev_dbg(hdev, "conn %p %s", conn,
2067 		   test_bit(SMP_FLAG_INITIATOR, &smp->flags) ? "initiator" :
2068 		   "responder");
2069 
2070 	if (skb->len < sizeof(smp->pcnf))
2071 		return SMP_INVALID_PARAMS;
2072 
2073 	memcpy(smp->pcnf, skb->data, sizeof(smp->pcnf));
2074 	skb_pull(skb, sizeof(smp->pcnf));
2075 
2076 	if (test_bit(SMP_FLAG_SC, &smp->flags)) {
2077 		int ret;
2078 
2079 		/* Public Key exchange must happen before any other steps */
2080 		if (test_bit(SMP_FLAG_REMOTE_PK, &smp->flags))
2081 			return sc_check_confirm(smp);
2082 
2083 		bt_dev_err(hdev, "Unexpected SMP Pairing Confirm");
2084 
2085 		ret = fixup_sc_false_positive(smp);
2086 		if (ret)
2087 			return ret;
2088 	}
2089 
2090 	if (test_bit(SMP_FLAG_INITIATOR, &smp->flags)) {
2091 		smp_send_cmd(conn, SMP_CMD_PAIRING_RANDOM, sizeof(smp->prnd),
2092 			     smp->prnd);
2093 		SMP_ALLOW_CMD(smp, SMP_CMD_PAIRING_RANDOM);
2094 		return 0;
2095 	}
2096 
2097 	if (test_bit(SMP_FLAG_TK_VALID, &smp->flags))
2098 		return smp_confirm(smp);
2099 
2100 	set_bit(SMP_FLAG_CFM_PENDING, &smp->flags);
2101 
2102 	return 0;
2103 }
2104 
2105 static u8 smp_cmd_pairing_random(struct l2cap_conn *conn, struct sk_buff *skb)
2106 {
2107 	struct l2cap_chan *chan = conn->smp;
2108 	struct smp_chan *smp = chan->data;
2109 	struct hci_conn *hcon = conn->hcon;
2110 	u8 *pkax, *pkbx, *na, *nb, confirm_hint;
2111 	u32 passkey = 0;
2112 	int err;
2113 
2114 	bt_dev_dbg(hcon->hdev, "conn %p", conn);
2115 
2116 	if (skb->len < sizeof(smp->rrnd))
2117 		return SMP_INVALID_PARAMS;
2118 
2119 	memcpy(smp->rrnd, skb->data, sizeof(smp->rrnd));
2120 	skb_pull(skb, sizeof(smp->rrnd));
2121 
2122 	if (!test_bit(SMP_FLAG_SC, &smp->flags))
2123 		return smp_random(smp);
2124 
2125 	if (test_bit(SMP_FLAG_INITIATOR, &smp->flags)) {
2126 		pkax = smp->local_pk;
2127 		pkbx = smp->remote_pk;
2128 		na   = smp->prnd;
2129 		nb   = smp->rrnd;
2130 	} else {
2131 		pkax = smp->remote_pk;
2132 		pkbx = smp->local_pk;
2133 		na   = smp->rrnd;
2134 		nb   = smp->prnd;
2135 	}
2136 
2137 	if (smp->method == REQ_OOB) {
2138 		if (!test_bit(SMP_FLAG_INITIATOR, &smp->flags))
2139 			smp_send_cmd(conn, SMP_CMD_PAIRING_RANDOM,
2140 				     sizeof(smp->prnd), smp->prnd);
2141 		SMP_ALLOW_CMD(smp, SMP_CMD_DHKEY_CHECK);
2142 		goto mackey_and_ltk;
2143 	}
2144 
2145 	/* Passkey entry has special treatment */
2146 	if (smp->method == REQ_PASSKEY || smp->method == DSP_PASSKEY)
2147 		return sc_passkey_round(smp, SMP_CMD_PAIRING_RANDOM);
2148 
2149 	if (test_bit(SMP_FLAG_INITIATOR, &smp->flags)) {
2150 		u8 cfm[16];
2151 
2152 		err = smp_f4(smp->remote_pk, smp->local_pk, smp->rrnd, 0, cfm);
2153 		if (err)
2154 			return SMP_UNSPECIFIED;
2155 
2156 		if (crypto_memneq(smp->pcnf, cfm, 16))
2157 			return SMP_CONFIRM_FAILED;
2158 	} else {
2159 		smp_send_cmd(conn, SMP_CMD_PAIRING_RANDOM, sizeof(smp->prnd),
2160 			     smp->prnd);
2161 		SMP_ALLOW_CMD(smp, SMP_CMD_DHKEY_CHECK);
2162 	}
2163 
2164 mackey_and_ltk:
2165 	/* Generate MacKey and LTK */
2166 	err = sc_mackey_and_ltk(smp, smp->mackey, smp->tk);
2167 	if (err)
2168 		return SMP_UNSPECIFIED;
2169 
2170 	if (smp->method == REQ_OOB) {
2171 		if (test_bit(SMP_FLAG_INITIATOR, &smp->flags)) {
2172 			sc_dhkey_check(smp);
2173 			SMP_ALLOW_CMD(smp, SMP_CMD_DHKEY_CHECK);
2174 		}
2175 		return 0;
2176 	}
2177 
2178 	err = smp_g2(pkax, pkbx, na, nb, &passkey);
2179 	if (err)
2180 		return SMP_UNSPECIFIED;
2181 
2182 	/* Always require user confirmation for Just-Works pairing to prevent
2183 	 * impersonation attacks, or in case of a legitimate device that is
2184 	 * repairing use the confirmation as acknowledgment to proceed with the
2185 	 * creation of new keys.
2186 	 */
2187 	confirm_hint = smp->method == JUST_WORKS ? 1 : 0;
2188 
2189 	err = mgmt_user_confirm_request(hcon->hdev, &hcon->dst, hcon->type,
2190 					hcon->dst_type, passkey, confirm_hint);
2191 	if (err)
2192 		return SMP_UNSPECIFIED;
2193 
2194 	set_bit(SMP_FLAG_WAIT_USER, &smp->flags);
2195 
2196 	return 0;
2197 }
2198 
2199 static bool smp_ltk_encrypt(struct l2cap_conn *conn, u8 sec_level)
2200 {
2201 	struct smp_ltk *key;
2202 	struct hci_conn *hcon = conn->hcon;
2203 
2204 	key = hci_find_ltk(hcon->hdev, &hcon->dst, hcon->dst_type, hcon->role);
2205 	if (!key)
2206 		return false;
2207 
2208 	if (smp_ltk_sec_level(key) < sec_level)
2209 		return false;
2210 
2211 	if (test_and_set_bit(HCI_CONN_ENCRYPT_PEND, &hcon->flags))
2212 		return true;
2213 
2214 	hci_le_start_enc(hcon, key->ediv, key->rand, key->val, key->enc_size);
2215 	hcon->enc_key_size = key->enc_size;
2216 
2217 	/* We never store STKs for initiator role, so clear this flag */
2218 	clear_bit(HCI_CONN_STK_ENCRYPT, &hcon->flags);
2219 
2220 	return true;
2221 }
2222 
2223 bool smp_sufficient_security(struct hci_conn *hcon, u8 sec_level,
2224 			     enum smp_key_pref key_pref)
2225 {
2226 	if (sec_level == BT_SECURITY_LOW)
2227 		return true;
2228 
2229 	/* If we're encrypted with an STK but the caller prefers using
2230 	 * LTK claim insufficient security. This way we allow the
2231 	 * connection to be re-encrypted with an LTK, even if the LTK
2232 	 * provides the same level of security. Only exception is if we
2233 	 * don't have an LTK (e.g. because of key distribution bits).
2234 	 */
2235 	if (key_pref == SMP_USE_LTK &&
2236 	    test_bit(HCI_CONN_STK_ENCRYPT, &hcon->flags) &&
2237 	    hci_find_ltk(hcon->hdev, &hcon->dst, hcon->dst_type, hcon->role))
2238 		return false;
2239 
2240 	if (hcon->sec_level >= sec_level)
2241 		return true;
2242 
2243 	return false;
2244 }
2245 
2246 static void smp_send_pairing_req(struct smp_chan *smp, __u8 auth)
2247 {
2248 	struct smp_cmd_pairing cp;
2249 
2250 	if (smp->conn->hcon->type == ACL_LINK)
2251 		build_bredr_pairing_cmd(smp, &cp, NULL);
2252 	else
2253 		build_pairing_cmd(smp->conn, &cp, NULL, auth);
2254 
2255 	smp->preq[0] = SMP_CMD_PAIRING_REQ;
2256 	memcpy(&smp->preq[1], &cp, sizeof(cp));
2257 
2258 	smp_send_cmd(smp->conn, SMP_CMD_PAIRING_REQ, sizeof(cp), &cp);
2259 	SMP_ALLOW_CMD(smp, SMP_CMD_PAIRING_RSP);
2260 
2261 	set_bit(SMP_FLAG_INITIATOR, &smp->flags);
2262 }
2263 
2264 static u8 smp_cmd_security_req(struct l2cap_conn *conn, struct sk_buff *skb)
2265 {
2266 	struct smp_cmd_security_req *rp = (void *) skb->data;
2267 	struct hci_conn *hcon = conn->hcon;
2268 	struct hci_dev *hdev = hcon->hdev;
2269 	struct smp_chan *smp;
2270 	u8 sec_level, auth;
2271 
2272 	bt_dev_dbg(hdev, "conn %p", conn);
2273 
2274 	/* SMP over BR/EDR only covers cross-transport key derivation; the
2275 	 * Security Request procedure has no BR/EDR counterpart. Reject it
2276 	 * here, otherwise smp_ltk_encrypt() finds the peer's LE LTK
2277 	 * (ADDR_LE_DEV_PUBLIC and BDADDR_BREDR are both 0) and issues
2278 	 * HCI_OP_LE_START_ENC on the ACL handle, which the controller
2279 	 * rejects and hci_cs_le_start_enc() turns into a disconnect. Reply
2280 	 * without smp_failure(): this is not an authentication failure, and
2281 	 * MGMT_EV_AUTH_FAILED would make bluetoothd drop the device.
2282 	 */
2283 	if (hcon->type != LE_LINK) {
2284 		u8 reason = SMP_CMD_NOTSUPP;
2285 
2286 		smp_send_cmd(conn, SMP_CMD_PAIRING_FAIL, sizeof(reason),
2287 			     &reason);
2288 		return 0;
2289 	}
2290 
2291 	if (skb->len < sizeof(*rp))
2292 		return SMP_INVALID_PARAMS;
2293 
2294 	if (hcon->role != HCI_ROLE_MASTER)
2295 		return SMP_CMD_NOTSUPP;
2296 
2297 	auth = rp->auth_req & AUTH_REQ_MASK(hdev);
2298 
2299 	if (hci_dev_test_flag(hdev, HCI_SC_ONLY) && !(auth & SMP_AUTH_SC))
2300 		return SMP_AUTH_REQUIREMENTS;
2301 
2302 	if (hcon->io_capability == HCI_IO_NO_INPUT_OUTPUT)
2303 		sec_level = BT_SECURITY_MEDIUM;
2304 	else
2305 		sec_level = authreq_to_seclevel(auth);
2306 
2307 	if (smp_sufficient_security(hcon, sec_level, SMP_USE_LTK)) {
2308 		/* If link is already encrypted with sufficient security we
2309 		 * still need refresh encryption as per Core Spec 5.0 Vol 3,
2310 		 * Part H 2.4.6
2311 		 */
2312 		smp_ltk_encrypt(conn, hcon->sec_level);
2313 		return 0;
2314 	}
2315 
2316 	if (sec_level > hcon->pending_sec_level)
2317 		hcon->pending_sec_level = sec_level;
2318 
2319 	if (smp_ltk_encrypt(conn, hcon->pending_sec_level))
2320 		return 0;
2321 
2322 	smp = smp_chan_create(conn);
2323 	if (!smp)
2324 		return SMP_UNSPECIFIED;
2325 
2326 	if (!hci_dev_test_flag(hdev, HCI_BONDABLE) &&
2327 	    (auth & SMP_AUTH_BONDING))
2328 		return SMP_PAIRING_NOTSUPP;
2329 
2330 	skb_pull(skb, sizeof(*rp));
2331 
2332 	smp_send_pairing_req(smp, auth);
2333 
2334 	return 0;
2335 }
2336 
2337 static void smp_send_security_req(struct smp_chan *smp, __u8 auth)
2338 {
2339 	struct smp_cmd_security_req cp;
2340 
2341 	cp.auth_req = auth;
2342 	smp_send_cmd(smp->conn, SMP_CMD_SECURITY_REQ, sizeof(cp), &cp);
2343 	SMP_ALLOW_CMD(smp, SMP_CMD_PAIRING_REQ);
2344 
2345 	clear_bit(SMP_FLAG_INITIATOR, &smp->flags);
2346 }
2347 
2348 int smp_conn_security(struct hci_conn *hcon, __u8 sec_level)
2349 {
2350 	struct l2cap_conn *conn;
2351 	struct l2cap_chan *chan;
2352 	struct smp_chan *smp;
2353 	__u8 authreq;
2354 	int ret;
2355 
2356 	/* Caller shall ensure there can be no race with l2cap_conn_del() */
2357 	conn = context_unsafe(hcon->l2cap_data);
2358 
2359 	bt_dev_dbg(hcon->hdev, "conn %p hcon %p level 0x%2.2x", conn, hcon,
2360 		   sec_level);
2361 
2362 	/* This may be NULL if there's an unexpected disconnection */
2363 	if (!conn)
2364 		return 1;
2365 
2366 	if (!hci_dev_test_flag(hcon->hdev, HCI_LE_ENABLED))
2367 		return 1;
2368 
2369 	if (smp_sufficient_security(hcon, sec_level, SMP_USE_LTK))
2370 		return 1;
2371 
2372 	if (sec_level > hcon->pending_sec_level)
2373 		hcon->pending_sec_level = sec_level;
2374 
2375 	if (hcon->role == HCI_ROLE_MASTER)
2376 		if (smp_ltk_encrypt(conn, hcon->pending_sec_level))
2377 			return 0;
2378 
2379 	chan = conn->smp;
2380 	if (!chan) {
2381 		bt_dev_err(hcon->hdev, "security requested but not available");
2382 		return 1;
2383 	}
2384 
2385 	l2cap_chan_lock(chan);
2386 
2387 	/* If SMP is already in progress ignore this request */
2388 	if (chan->data) {
2389 		ret = 0;
2390 		goto unlock;
2391 	}
2392 
2393 	smp = smp_chan_create(conn);
2394 	if (!smp) {
2395 		ret = 1;
2396 		goto unlock;
2397 	}
2398 
2399 	authreq = seclevel_to_authreq(sec_level);
2400 
2401 	if (hci_dev_test_flag(hcon->hdev, HCI_SC_ENABLED)) {
2402 		authreq |= SMP_AUTH_SC;
2403 		if (hci_dev_test_flag(hcon->hdev, HCI_SSP_ENABLED))
2404 			authreq |= SMP_AUTH_CT2;
2405 	}
2406 
2407 	/* Don't attempt to set MITM if setting is overridden by debugfs
2408 	 * Needed to pass certification test SM/MAS/PKE/BV-01-C
2409 	 */
2410 	if (!hci_dev_test_flag(hcon->hdev, HCI_FORCE_NO_MITM)) {
2411 		/* Require MITM if IO Capability allows or the security level
2412 		 * requires it.
2413 		 */
2414 		if (hcon->io_capability != HCI_IO_NO_INPUT_OUTPUT ||
2415 		    hcon->pending_sec_level > BT_SECURITY_MEDIUM)
2416 			authreq |= SMP_AUTH_MITM;
2417 	}
2418 
2419 	if (hcon->role == HCI_ROLE_MASTER)
2420 		smp_send_pairing_req(smp, authreq);
2421 	else
2422 		smp_send_security_req(smp, authreq);
2423 
2424 	ret = 0;
2425 
2426 unlock:
2427 	l2cap_chan_unlock(chan);
2428 	return ret;
2429 }
2430 
2431 int smp_cancel_and_remove_pairing(struct hci_dev *hdev, bdaddr_t *bdaddr,
2432 				  u8 addr_type)
2433 {
2434 	struct hci_conn *hcon;
2435 	struct l2cap_conn *conn;
2436 	struct l2cap_chan *chan;
2437 	struct smp_chan *smp;
2438 	int err;
2439 
2440 	err = hci_remove_ltk(hdev, bdaddr, addr_type);
2441 	hci_remove_irk(hdev, bdaddr, addr_type);
2442 
2443 	hcon = hci_conn_hash_lookup_le(hdev, bdaddr, addr_type);
2444 	if (!hcon)
2445 		goto done;
2446 
2447 	lockdep_assert_held(&hcon->hdev->lock);
2448 
2449 	conn = hcon->l2cap_data;
2450 	if (!conn)
2451 		goto done;
2452 
2453 	chan = conn->smp;
2454 	if (!chan)
2455 		goto done;
2456 
2457 	l2cap_chan_lock(chan);
2458 
2459 	smp = chan->data;
2460 	if (smp) {
2461 		/* Set keys to NULL to make sure smp_failure() does not try to
2462 		 * remove and free already invalidated rcu list entries. */
2463 		smp->ltk = NULL;
2464 		smp->responder_ltk = NULL;
2465 		smp->remote_irk = NULL;
2466 
2467 		if (test_bit(SMP_FLAG_COMPLETE, &smp->flags))
2468 			smp_failure(conn, 0);
2469 		else
2470 			smp_failure(conn, SMP_UNSPECIFIED);
2471 		err = 0;
2472 	}
2473 
2474 	l2cap_chan_unlock(chan);
2475 
2476 done:
2477 	return err;
2478 }
2479 
2480 static int smp_cmd_encrypt_info(struct l2cap_conn *conn, struct sk_buff *skb)
2481 {
2482 	struct smp_cmd_encrypt_info *rp = (void *) skb->data;
2483 	struct l2cap_chan *chan = conn->smp;
2484 	struct smp_chan *smp = chan->data;
2485 
2486 	bt_dev_dbg(conn->hcon->hdev, "conn %p", conn);
2487 
2488 	if (skb->len < sizeof(*rp))
2489 		return SMP_INVALID_PARAMS;
2490 
2491 	/* Pairing is aborted if any blocked keys are distributed */
2492 	if (hci_is_blocked_key(conn->hcon->hdev, HCI_BLOCKED_KEY_TYPE_LTK,
2493 			       rp->ltk)) {
2494 		bt_dev_warn_ratelimited(conn->hcon->hdev,
2495 					"LTK blocked for %pMR",
2496 					&conn->hcon->dst);
2497 		return SMP_INVALID_PARAMS;
2498 	}
2499 
2500 	SMP_ALLOW_CMD(smp, SMP_CMD_INITIATOR_IDENT);
2501 
2502 	skb_pull(skb, sizeof(*rp));
2503 
2504 	memcpy(smp->tk, rp->ltk, sizeof(smp->tk));
2505 
2506 	return 0;
2507 }
2508 
2509 static int smp_cmd_initiator_ident(struct l2cap_conn *conn, struct sk_buff *skb)
2510 {
2511 	struct smp_cmd_initiator_ident *rp = (void *)skb->data;
2512 	struct l2cap_chan *chan = conn->smp;
2513 	struct smp_chan *smp = chan->data;
2514 	struct hci_dev *hdev = conn->hcon->hdev;
2515 	struct hci_conn *hcon = conn->hcon;
2516 	struct smp_ltk *ltk;
2517 	u8 authenticated;
2518 
2519 	bt_dev_dbg(hdev, "conn %p", conn);
2520 
2521 	if (skb->len < sizeof(*rp))
2522 		return SMP_INVALID_PARAMS;
2523 
2524 	/* Mark the information as received */
2525 	smp->remote_key_dist &= ~SMP_DIST_ENC_KEY;
2526 
2527 	if (smp->remote_key_dist & SMP_DIST_ID_KEY)
2528 		SMP_ALLOW_CMD(smp, SMP_CMD_IDENT_INFO);
2529 	else if (smp->remote_key_dist & SMP_DIST_SIGN)
2530 		SMP_ALLOW_CMD(smp, SMP_CMD_SIGN_INFO);
2531 
2532 	skb_pull(skb, sizeof(*rp));
2533 
2534 	authenticated = (hcon->sec_level == BT_SECURITY_HIGH);
2535 	ltk = hci_add_ltk(hdev, &hcon->dst, hcon->dst_type, SMP_LTK,
2536 			  authenticated, smp->tk, smp->enc_key_size,
2537 			  rp->ediv, rp->rand);
2538 	smp->ltk = ltk;
2539 	if (!(smp->remote_key_dist & KEY_DIST_MASK))
2540 		smp_distribute_keys(smp);
2541 
2542 	return 0;
2543 }
2544 
2545 static int smp_cmd_ident_info(struct l2cap_conn *conn, struct sk_buff *skb)
2546 {
2547 	struct smp_cmd_ident_info *info = (void *) skb->data;
2548 	struct l2cap_chan *chan = conn->smp;
2549 	struct smp_chan *smp = chan->data;
2550 
2551 	bt_dev_dbg(conn->hcon->hdev, "");
2552 
2553 	if (skb->len < sizeof(*info))
2554 		return SMP_INVALID_PARAMS;
2555 
2556 	/* Pairing is aborted if any blocked keys are distributed */
2557 	if (hci_is_blocked_key(conn->hcon->hdev, HCI_BLOCKED_KEY_TYPE_IRK,
2558 			       info->irk)) {
2559 		bt_dev_warn_ratelimited(conn->hcon->hdev,
2560 					"Identity key blocked for %pMR",
2561 					&conn->hcon->dst);
2562 		return SMP_INVALID_PARAMS;
2563 	}
2564 
2565 	SMP_ALLOW_CMD(smp, SMP_CMD_IDENT_ADDR_INFO);
2566 
2567 	skb_pull(skb, sizeof(*info));
2568 
2569 	memcpy(smp->irk, info->irk, 16);
2570 
2571 	return 0;
2572 }
2573 
2574 static int smp_cmd_ident_addr_info(struct l2cap_conn *conn,
2575 				   struct sk_buff *skb)
2576 {
2577 	struct smp_cmd_ident_addr_info *info = (void *) skb->data;
2578 	struct l2cap_chan *chan = conn->smp;
2579 	struct smp_chan *smp = chan->data;
2580 	struct hci_conn *hcon = conn->hcon;
2581 	bdaddr_t rpa;
2582 
2583 	bt_dev_dbg(hcon->hdev, "");
2584 
2585 	if (skb->len < sizeof(*info))
2586 		return SMP_INVALID_PARAMS;
2587 
2588 	/* Mark the information as received */
2589 	smp->remote_key_dist &= ~SMP_DIST_ID_KEY;
2590 
2591 	if (smp->remote_key_dist & SMP_DIST_SIGN)
2592 		SMP_ALLOW_CMD(smp, SMP_CMD_SIGN_INFO);
2593 
2594 	skb_pull(skb, sizeof(*info));
2595 
2596 	/* Strictly speaking the Core Specification (4.1) allows sending
2597 	 * an empty address which would force us to rely on just the IRK
2598 	 * as "identity information". However, since such
2599 	 * implementations are not known of and in order to not over
2600 	 * complicate our implementation, simply pretend that we never
2601 	 * received an IRK for such a device.
2602 	 *
2603 	 * The Identity Address must also be a Static Random or Public
2604 	 * Address, which hci_is_identity_address() checks for.
2605 	 */
2606 	if (!bacmp(&info->bdaddr, BDADDR_ANY) ||
2607 	    !hci_is_identity_address(&info->bdaddr, info->addr_type)) {
2608 		bt_dev_err(hcon->hdev, "ignoring IRK with no identity address");
2609 		goto distribute;
2610 	}
2611 
2612 	/* Drop IRK if peer is using identity address during pairing but is
2613 	 * providing different address as identity information.
2614 	 *
2615 	 * Microsoft Surface Precision Mouse is known to have this bug.
2616 	 */
2617 	if (hci_is_identity_address(&hcon->dst, hcon->dst_type) &&
2618 	    (bacmp(&info->bdaddr, &hcon->dst) ||
2619 	     info->addr_type != hcon->dst_type)) {
2620 		bt_dev_err(hcon->hdev,
2621 			   "ignoring IRK with invalid identity address");
2622 		goto distribute;
2623 	}
2624 
2625 	bacpy(&smp->id_addr, &info->bdaddr);
2626 	smp->id_addr_type = info->addr_type;
2627 
2628 	if (hci_bdaddr_is_rpa(&hcon->dst, hcon->dst_type))
2629 		bacpy(&rpa, &hcon->dst);
2630 	else
2631 		bacpy(&rpa, BDADDR_ANY);
2632 
2633 	smp->remote_irk = hci_add_irk(conn->hcon->hdev, &smp->id_addr,
2634 				      smp->id_addr_type, smp->irk, &rpa);
2635 
2636 distribute:
2637 	if (!(smp->remote_key_dist & KEY_DIST_MASK))
2638 		smp_distribute_keys(smp);
2639 
2640 	return 0;
2641 }
2642 
2643 static int smp_cmd_sign_info(struct l2cap_conn *conn, struct sk_buff *skb)
2644 {
2645 	struct smp_cmd_sign_info *rp = (void *) skb->data;
2646 	struct l2cap_chan *chan = conn->smp;
2647 	struct smp_chan *smp = chan->data;
2648 	struct smp_csrk *csrk;
2649 
2650 	bt_dev_dbg(conn->hcon->hdev, "conn %p", conn);
2651 
2652 	if (skb->len < sizeof(*rp))
2653 		return SMP_INVALID_PARAMS;
2654 
2655 	/* Mark the information as received */
2656 	smp->remote_key_dist &= ~SMP_DIST_SIGN;
2657 
2658 	skb_pull(skb, sizeof(*rp));
2659 
2660 	csrk = kzalloc_obj(*csrk);
2661 	if (csrk) {
2662 		if (conn->hcon->sec_level > BT_SECURITY_MEDIUM)
2663 			csrk->type = MGMT_CSRK_REMOTE_AUTHENTICATED;
2664 		else
2665 			csrk->type = MGMT_CSRK_REMOTE_UNAUTHENTICATED;
2666 		memcpy(csrk->val, rp->csrk, sizeof(csrk->val));
2667 	}
2668 	smp->csrk = csrk;
2669 	smp_distribute_keys(smp);
2670 
2671 	return 0;
2672 }
2673 
2674 static u8 sc_select_method(struct smp_chan *smp)
2675 {
2676 	struct smp_cmd_pairing *local, *remote;
2677 	u8 local_mitm, remote_mitm, local_io, remote_io, method;
2678 
2679 	if (test_bit(SMP_FLAG_REMOTE_OOB, &smp->flags) ||
2680 	    test_bit(SMP_FLAG_LOCAL_OOB, &smp->flags))
2681 		return REQ_OOB;
2682 
2683 	/* The preq/prsp contain the raw Pairing Request/Response PDUs
2684 	 * which are needed as inputs to some crypto functions. To get
2685 	 * the "struct smp_cmd_pairing" from them we need to skip the
2686 	 * first byte which contains the opcode.
2687 	 */
2688 	if (test_bit(SMP_FLAG_INITIATOR, &smp->flags)) {
2689 		local = (void *) &smp->preq[1];
2690 		remote = (void *) &smp->prsp[1];
2691 	} else {
2692 		local = (void *) &smp->prsp[1];
2693 		remote = (void *) &smp->preq[1];
2694 	}
2695 
2696 	local_io = local->io_capability;
2697 	remote_io = remote->io_capability;
2698 
2699 	local_mitm = (local->auth_req & SMP_AUTH_MITM);
2700 	remote_mitm = (remote->auth_req & SMP_AUTH_MITM);
2701 
2702 	/* If either side wants MITM, look up the method from the table,
2703 	 * otherwise use JUST WORKS.
2704 	 */
2705 	if (local_mitm || remote_mitm)
2706 		method = get_auth_method(smp, local_io, remote_io);
2707 	else
2708 		method = JUST_WORKS;
2709 
2710 	/* Don't confirm locally initiated pairing attempts */
2711 	if (method == JUST_CFM && test_bit(SMP_FLAG_INITIATOR, &smp->flags))
2712 		method = JUST_WORKS;
2713 
2714 	return method;
2715 }
2716 
2717 static int smp_cmd_public_key(struct l2cap_conn *conn, struct sk_buff *skb)
2718 {
2719 	struct smp_cmd_public_key *key = (void *) skb->data;
2720 	struct hci_conn *hcon = conn->hcon;
2721 	struct l2cap_chan *chan = conn->smp;
2722 	struct smp_chan *smp = chan->data;
2723 	struct hci_dev *hdev = hcon->hdev;
2724 	struct crypto_kpp *tfm_ecdh;
2725 	struct smp_cmd_pairing_confirm cfm;
2726 	int err;
2727 
2728 	bt_dev_dbg(hdev, "conn %p", conn);
2729 
2730 	if (skb->len < sizeof(*key))
2731 		return SMP_INVALID_PARAMS;
2732 
2733 	/* Check if remote and local public keys are the same and debug key is
2734 	 * not in use.
2735 	 */
2736 	if (!test_bit(SMP_FLAG_DEBUG_KEY, &smp->flags) &&
2737 	    !crypto_memneq(key, smp->local_pk, 64)) {
2738 		bt_dev_err(hdev, "Remote and local public keys are identical");
2739 		return SMP_DHKEY_CHECK_FAILED;
2740 	}
2741 
2742 	memcpy(smp->remote_pk, key, 64);
2743 
2744 	if (test_bit(SMP_FLAG_REMOTE_OOB, &smp->flags)) {
2745 		err = smp_f4(smp->remote_pk, smp->remote_pk, smp->rr, 0,
2746 			     cfm.confirm_val);
2747 		if (err)
2748 			return SMP_UNSPECIFIED;
2749 
2750 		if (crypto_memneq(cfm.confirm_val, smp->pcnf, 16))
2751 			return SMP_CONFIRM_FAILED;
2752 	}
2753 
2754 	/* Non-initiating device sends its public key after receiving
2755 	 * the key from the initiating device.
2756 	 */
2757 	if (!test_bit(SMP_FLAG_INITIATOR, &smp->flags)) {
2758 		err = sc_send_public_key(smp);
2759 		if (err)
2760 			return err;
2761 	}
2762 
2763 	SMP_DBG("Remote Public Key X: %32phN", smp->remote_pk);
2764 	SMP_DBG("Remote Public Key Y: %32phN", smp->remote_pk + 32);
2765 
2766 	/* Compute the shared secret on the same crypto tfm on which the private
2767 	 * key was set/generated.
2768 	 */
2769 	if (test_bit(SMP_FLAG_LOCAL_OOB, &smp->flags)) {
2770 		struct l2cap_chan *hchan = hdev->smp_data;
2771 		struct smp_dev *smp_dev;
2772 
2773 		if (!hchan || !hchan->data)
2774 			return SMP_UNSPECIFIED;
2775 
2776 		smp_dev = hchan->data;
2777 
2778 		tfm_ecdh = smp_dev->tfm_ecdh;
2779 	} else {
2780 		tfm_ecdh = smp->tfm_ecdh;
2781 	}
2782 
2783 	if (compute_ecdh_secret(tfm_ecdh, smp->remote_pk, smp->dhkey))
2784 		return SMP_UNSPECIFIED;
2785 
2786 	SMP_DBG("DHKey %32phN", smp->dhkey);
2787 
2788 	set_bit(SMP_FLAG_REMOTE_PK, &smp->flags);
2789 
2790 	smp->method = sc_select_method(smp);
2791 
2792 	bt_dev_dbg(hdev, "selected method 0x%02x", smp->method);
2793 
2794 	/* JUST_WORKS and JUST_CFM result in an unauthenticated key */
2795 	if (smp->method == JUST_WORKS || smp->method == JUST_CFM)
2796 		hcon->pending_sec_level = BT_SECURITY_MEDIUM;
2797 	else
2798 		hcon->pending_sec_level = BT_SECURITY_FIPS;
2799 
2800 	if (!crypto_memneq(debug_pk, smp->remote_pk, 64))
2801 		set_bit(SMP_FLAG_DEBUG_KEY, &smp->flags);
2802 
2803 	if (smp->method == DSP_PASSKEY) {
2804 		get_random_bytes(&hcon->passkey_notify,
2805 				 sizeof(hcon->passkey_notify));
2806 		hcon->passkey_notify %= 1000000;
2807 		hcon->passkey_entered = 0;
2808 		smp->passkey_round = 0;
2809 		if (mgmt_user_passkey_notify(hdev, &hcon->dst, hcon->type,
2810 					     hcon->dst_type,
2811 					     hcon->passkey_notify,
2812 					     hcon->passkey_entered))
2813 			return SMP_UNSPECIFIED;
2814 		SMP_ALLOW_CMD(smp, SMP_CMD_PAIRING_CONFIRM);
2815 		return sc_passkey_round(smp, SMP_CMD_PUBLIC_KEY);
2816 	}
2817 
2818 	if (smp->method == REQ_OOB) {
2819 		if (test_bit(SMP_FLAG_INITIATOR, &smp->flags))
2820 			smp_send_cmd(conn, SMP_CMD_PAIRING_RANDOM,
2821 				     sizeof(smp->prnd), smp->prnd);
2822 
2823 		SMP_ALLOW_CMD(smp, SMP_CMD_PAIRING_RANDOM);
2824 
2825 		return 0;
2826 	}
2827 
2828 	if (test_bit(SMP_FLAG_INITIATOR, &smp->flags))
2829 		SMP_ALLOW_CMD(smp, SMP_CMD_PAIRING_CONFIRM);
2830 
2831 	if (smp->method == REQ_PASSKEY) {
2832 		if (mgmt_user_passkey_request(hdev, &hcon->dst, hcon->type,
2833 					      hcon->dst_type))
2834 			return SMP_UNSPECIFIED;
2835 		SMP_ALLOW_CMD(smp, SMP_CMD_PAIRING_CONFIRM);
2836 		set_bit(SMP_FLAG_WAIT_USER, &smp->flags);
2837 		return 0;
2838 	}
2839 
2840 	/* The Initiating device waits for the non-initiating device to
2841 	 * send the confirm value.
2842 	 */
2843 	if (test_bit(SMP_FLAG_INITIATOR, &smp->flags))
2844 		return 0;
2845 
2846 	err = smp_f4(smp->local_pk, smp->remote_pk, smp->prnd, 0,
2847 		     cfm.confirm_val);
2848 	if (err)
2849 		return SMP_UNSPECIFIED;
2850 
2851 	smp_send_cmd(conn, SMP_CMD_PAIRING_CONFIRM, sizeof(cfm), &cfm);
2852 	SMP_ALLOW_CMD(smp, SMP_CMD_PAIRING_RANDOM);
2853 
2854 	return 0;
2855 }
2856 
2857 static int smp_cmd_dhkey_check(struct l2cap_conn *conn, struct sk_buff *skb)
2858 {
2859 	struct smp_cmd_dhkey_check *check = (void *) skb->data;
2860 	struct l2cap_chan *chan = conn->smp;
2861 	struct hci_conn *hcon = conn->hcon;
2862 	struct smp_chan *smp = chan->data;
2863 	u8 a[7], b[7], *local_addr, *remote_addr;
2864 	u8 io_cap[3], r[16], e[16];
2865 	int err;
2866 
2867 	bt_dev_dbg(hcon->hdev, "conn %p", conn);
2868 
2869 	if (skb->len < sizeof(*check))
2870 		return SMP_INVALID_PARAMS;
2871 
2872 	memcpy(a, &hcon->init_addr, 6);
2873 	memcpy(b, &hcon->resp_addr, 6);
2874 	a[6] = hcon->init_addr_type;
2875 	b[6] = hcon->resp_addr_type;
2876 
2877 	if (test_bit(SMP_FLAG_INITIATOR, &smp->flags)) {
2878 		local_addr = a;
2879 		remote_addr = b;
2880 		memcpy(io_cap, &smp->prsp[1], 3);
2881 	} else {
2882 		local_addr = b;
2883 		remote_addr = a;
2884 		memcpy(io_cap, &smp->preq[1], 3);
2885 	}
2886 
2887 	memset(r, 0, sizeof(r));
2888 
2889 	if (smp->method == REQ_PASSKEY || smp->method == DSP_PASSKEY)
2890 		put_unaligned_le32(hcon->passkey_notify, r);
2891 	else if (smp->method == REQ_OOB)
2892 		memcpy(r, smp->lr, 16);
2893 
2894 	err = smp_f6(smp->mackey, smp->rrnd, smp->prnd, r, io_cap, remote_addr,
2895 		     local_addr, e);
2896 	if (err)
2897 		return SMP_UNSPECIFIED;
2898 
2899 	if (crypto_memneq(check->e, e, 16))
2900 		return SMP_DHKEY_CHECK_FAILED;
2901 
2902 	if (!test_bit(SMP_FLAG_INITIATOR, &smp->flags)) {
2903 		if (test_bit(SMP_FLAG_WAIT_USER, &smp->flags)) {
2904 			set_bit(SMP_FLAG_DHKEY_PENDING, &smp->flags);
2905 			return 0;
2906 		}
2907 
2908 		/* Responder sends DHKey check as response to initiator */
2909 		sc_dhkey_check(smp);
2910 	}
2911 
2912 	sc_add_ltk(smp);
2913 
2914 	if (test_bit(SMP_FLAG_INITIATOR, &smp->flags)) {
2915 		hci_le_start_enc(hcon, 0, 0, smp->tk, smp->enc_key_size);
2916 		hcon->enc_key_size = smp->enc_key_size;
2917 	}
2918 
2919 	return 0;
2920 }
2921 
2922 static int smp_cmd_keypress_notify(struct l2cap_conn *conn,
2923 				   struct sk_buff *skb)
2924 {
2925 	struct smp_cmd_keypress_notify *kp = (void *) skb->data;
2926 
2927 	bt_dev_dbg(conn->hcon->hdev, "value 0x%02x", kp->value);
2928 
2929 	return 0;
2930 }
2931 
2932 static int smp_sig_channel(struct l2cap_chan *chan, struct sk_buff *skb)
2933 {
2934 	struct l2cap_conn *conn = chan->conn;
2935 	struct hci_conn *hcon = conn->hcon;
2936 	struct smp_chan *smp;
2937 	__u8 code, reason;
2938 	int err = 0;
2939 
2940 	if (skb->len < 1)
2941 		return -EILSEQ;
2942 
2943 	if (!hci_dev_test_flag(hcon->hdev, HCI_LE_ENABLED)) {
2944 		reason = SMP_PAIRING_NOTSUPP;
2945 		goto done;
2946 	}
2947 
2948 	code = skb->data[0];
2949 	skb_pull(skb, sizeof(code));
2950 
2951 	smp = chan->data;
2952 
2953 	if (code > SMP_CMD_MAX)
2954 		goto drop;
2955 
2956 	if (smp && !test_and_clear_bit(code, &smp->allow_cmd)) {
2957 		/* If there is a context and the command is not allowed consider
2958 		 * it a failure so the session is cleanup properly.
2959 		 */
2960 		switch (code) {
2961 		case SMP_CMD_IDENT_INFO:
2962 		case SMP_CMD_IDENT_ADDR_INFO:
2963 		case SMP_CMD_SIGN_INFO:
2964 			/* 3.6.1. Key distribution and generation
2965 			 *
2966 			 * A device may reject a distributed key by sending the
2967 			 * Pairing Failed command with the reason set to
2968 			 * "Key Rejected".
2969 			 */
2970 			smp_failure(conn, SMP_KEY_REJECTED);
2971 			break;
2972 		}
2973 		goto drop;
2974 	}
2975 
2976 	/* If we don't have a context the only allowed commands are
2977 	 * pairing request and security request.
2978 	 */
2979 	if (!smp && code != SMP_CMD_PAIRING_REQ && code != SMP_CMD_SECURITY_REQ)
2980 		goto drop;
2981 
2982 	switch (code) {
2983 	case SMP_CMD_PAIRING_REQ:
2984 		reason = smp_cmd_pairing_req(conn, skb);
2985 		break;
2986 
2987 	case SMP_CMD_PAIRING_FAIL:
2988 		smp_failure(conn, 0);
2989 		err = -EPERM;
2990 		break;
2991 
2992 	case SMP_CMD_PAIRING_RSP:
2993 		reason = smp_cmd_pairing_rsp(conn, skb);
2994 		break;
2995 
2996 	case SMP_CMD_SECURITY_REQ:
2997 		reason = smp_cmd_security_req(conn, skb);
2998 		break;
2999 
3000 	case SMP_CMD_PAIRING_CONFIRM:
3001 		reason = smp_cmd_pairing_confirm(conn, skb);
3002 		break;
3003 
3004 	case SMP_CMD_PAIRING_RANDOM:
3005 		reason = smp_cmd_pairing_random(conn, skb);
3006 		break;
3007 
3008 	case SMP_CMD_ENCRYPT_INFO:
3009 		reason = smp_cmd_encrypt_info(conn, skb);
3010 		break;
3011 
3012 	case SMP_CMD_INITIATOR_IDENT:
3013 		reason = smp_cmd_initiator_ident(conn, skb);
3014 		break;
3015 
3016 	case SMP_CMD_IDENT_INFO:
3017 		reason = smp_cmd_ident_info(conn, skb);
3018 		break;
3019 
3020 	case SMP_CMD_IDENT_ADDR_INFO:
3021 		reason = smp_cmd_ident_addr_info(conn, skb);
3022 		break;
3023 
3024 	case SMP_CMD_SIGN_INFO:
3025 		reason = smp_cmd_sign_info(conn, skb);
3026 		break;
3027 
3028 	case SMP_CMD_PUBLIC_KEY:
3029 		reason = smp_cmd_public_key(conn, skb);
3030 		break;
3031 
3032 	case SMP_CMD_DHKEY_CHECK:
3033 		reason = smp_cmd_dhkey_check(conn, skb);
3034 		break;
3035 
3036 	case SMP_CMD_KEYPRESS_NOTIFY:
3037 		reason = smp_cmd_keypress_notify(conn, skb);
3038 		break;
3039 
3040 	default:
3041 		bt_dev_dbg(hcon->hdev, "Unknown command code 0x%2.2x", code);
3042 		reason = SMP_CMD_NOTSUPP;
3043 		goto done;
3044 	}
3045 
3046 done:
3047 	if (!err) {
3048 		if (reason)
3049 			smp_failure(conn, reason);
3050 		kfree_skb(skb);
3051 	}
3052 
3053 	return err;
3054 
3055 drop:
3056 	bt_dev_err(hcon->hdev, "unexpected SMP command 0x%02x from %pMR",
3057 		   code, &hcon->dst);
3058 	kfree_skb(skb);
3059 	return 0;
3060 }
3061 
3062 static void smp_teardown_cb(struct l2cap_chan *chan, int err)
3063 {
3064 	struct l2cap_conn *conn = chan->conn;
3065 
3066 	bt_dev_dbg(conn->hcon->hdev, "chan %p", chan);
3067 
3068 	if (chan->data)
3069 		smp_chan_destroy(conn);
3070 
3071 	conn->smp = NULL;
3072 	l2cap_chan_put(chan);
3073 }
3074 
3075 static void bredr_pairing(struct l2cap_chan *chan)
3076 {
3077 	struct l2cap_conn *conn = chan->conn;
3078 	struct hci_conn *hcon = conn->hcon;
3079 	struct hci_dev *hdev = hcon->hdev;
3080 	struct smp_chan *smp;
3081 
3082 	bt_dev_dbg(hdev, "chan %p", chan);
3083 
3084 	/* Only new pairings are interesting */
3085 	if (!test_bit(HCI_CONN_NEW_LINK_KEY, &hcon->flags))
3086 		return;
3087 
3088 	/* Don't bother if we're not encrypted */
3089 	if (!test_bit(HCI_CONN_ENCRYPT, &hcon->flags))
3090 		return;
3091 
3092 	/* Only initiator may initiate SMP over BR/EDR */
3093 	if (hcon->role != HCI_ROLE_MASTER)
3094 		return;
3095 
3096 	/* Secure Connections support must be enabled */
3097 	if (!hci_dev_test_flag(hdev, HCI_SC_ENABLED))
3098 		return;
3099 
3100 	/* BR/EDR must use Secure Connections for SMP */
3101 	if (!test_bit(HCI_CONN_AES_CCM, &hcon->flags) &&
3102 	    !hci_dev_test_flag(hdev, HCI_FORCE_BREDR_SMP))
3103 		return;
3104 
3105 	/* If our LE support is not enabled don't do anything */
3106 	if (!hci_dev_test_flag(hdev, HCI_LE_ENABLED))
3107 		return;
3108 
3109 	/* Don't bother if remote LE support is not enabled */
3110 	if (!lmp_host_le_capable(hcon))
3111 		return;
3112 
3113 	/* Remote must support SMP fixed chan for BR/EDR */
3114 	if (!(conn->remote_fixed_chan & L2CAP_FC_SMP_BREDR))
3115 		return;
3116 
3117 	/* Don't bother if SMP is already ongoing */
3118 	if (chan->data)
3119 		return;
3120 
3121 	smp = smp_chan_create(conn);
3122 	if (!smp) {
3123 		bt_dev_err(hdev, "unable to create SMP context for BR/EDR");
3124 		return;
3125 	}
3126 
3127 	set_bit(SMP_FLAG_SC, &smp->flags);
3128 
3129 	bt_dev_dbg(hdev, "starting SMP over BR/EDR");
3130 
3131 	smp_send_pairing_req(smp, 0x00);
3132 }
3133 
3134 static void smp_resume_cb(struct l2cap_chan *chan)
3135 {
3136 	struct smp_chan *smp = chan->data;
3137 	struct l2cap_conn *conn = chan->conn;
3138 	struct hci_conn *hcon = conn->hcon;
3139 
3140 	bt_dev_dbg(hcon->hdev, "chan %p", chan);
3141 
3142 	if (hcon->type == ACL_LINK) {
3143 		bredr_pairing(chan);
3144 		return;
3145 	}
3146 
3147 	if (!smp)
3148 		return;
3149 
3150 	if (!test_bit(HCI_CONN_ENCRYPT, &hcon->flags))
3151 		return;
3152 
3153 	cancel_delayed_work(&smp->security_timer);
3154 
3155 	smp_distribute_keys(smp);
3156 }
3157 
3158 static void smp_ready_cb(struct l2cap_chan *chan)
3159 {
3160 	struct l2cap_conn *conn = chan->conn;
3161 	struct hci_conn *hcon = conn->hcon;
3162 
3163 	bt_dev_dbg(hcon->hdev, "chan %p", chan);
3164 
3165 	/* No need to call l2cap_chan_hold() here since we already own
3166 	 * the reference taken in smp_new_conn_cb(). This is just the
3167 	 * first time that we tie it to a specific pointer. The code in
3168 	 * l2cap_core.c ensures that there's no risk this function won't
3169 	 * get called if smp_new_conn_cb was previously called.
3170 	 */
3171 	conn->smp = chan;
3172 
3173 	if (hcon->type == ACL_LINK && test_bit(HCI_CONN_ENCRYPT, &hcon->flags))
3174 		bredr_pairing(chan);
3175 }
3176 
3177 static int smp_recv_cb(struct l2cap_chan *chan, struct sk_buff *skb)
3178 {
3179 	int err;
3180 
3181 	bt_dev_dbg(chan->conn->hcon->hdev, "chan %p", chan);
3182 
3183 	err = smp_sig_channel(chan, skb);
3184 	if (err) {
3185 		struct smp_chan *smp = chan->data;
3186 
3187 		if (smp)
3188 			cancel_delayed_work_sync(&smp->security_timer);
3189 
3190 		hci_disconnect(chan->conn->hcon, HCI_ERROR_AUTH_FAILURE);
3191 	}
3192 
3193 	return err;
3194 }
3195 
3196 static struct sk_buff *smp_alloc_skb_cb(struct l2cap_chan *chan,
3197 					unsigned long hdr_len,
3198 					unsigned long len, int nb)
3199 {
3200 	struct sk_buff *skb;
3201 
3202 	skb = bt_skb_alloc(hdr_len + len, GFP_KERNEL);
3203 	if (!skb)
3204 		return ERR_PTR(-ENOMEM);
3205 
3206 	skb->priority = HCI_PRIO_MAX;
3207 	bt_cb(skb)->l2cap.chan = chan;
3208 
3209 	return skb;
3210 }
3211 
3212 static const struct l2cap_ops smp_chan_ops = {
3213 	.name			= "Security Manager",
3214 	.ready			= smp_ready_cb,
3215 	.recv			= smp_recv_cb,
3216 	.alloc_skb		= smp_alloc_skb_cb,
3217 	.teardown		= smp_teardown_cb,
3218 	.resume			= smp_resume_cb,
3219 
3220 	.new_connection		= l2cap_chan_no_new_connection,
3221 	.state_change		= l2cap_chan_no_state_change,
3222 	.close			= l2cap_chan_no_close,
3223 	.defer			= l2cap_chan_no_defer,
3224 	.suspend		= l2cap_chan_no_suspend,
3225 	.set_shutdown		= l2cap_chan_no_set_shutdown,
3226 	.get_sndtimeo		= l2cap_chan_no_get_sndtimeo,
3227 };
3228 
3229 static inline int smp_new_conn_cb(struct l2cap_chan *chan,
3230 				  struct l2cap_chan *new_chan)
3231 {
3232 	new_chan->ops = &smp_chan_ops;
3233 
3234 	/* Other L2CAP channels may request SMP routines in order to
3235 	 * change the security level. This means that the SMP channel
3236 	 * lock must be considered in its own category to avoid lockdep
3237 	 * warnings.
3238 	 */
3239 	atomic_set(&new_chan->nesting, L2CAP_NESTING_SMP);
3240 
3241 	return 0;
3242 }
3243 
3244 static const struct l2cap_ops smp_root_chan_ops = {
3245 	.name			= "Security Manager Root",
3246 	.new_connection		= smp_new_conn_cb,
3247 
3248 	/* None of these are implemented for the root channel */
3249 	.close			= l2cap_chan_no_close,
3250 	.alloc_skb		= l2cap_chan_no_alloc_skb,
3251 	.recv			= l2cap_chan_no_recv,
3252 	.state_change		= l2cap_chan_no_state_change,
3253 	.teardown		= l2cap_chan_no_teardown,
3254 	.ready			= l2cap_chan_no_ready,
3255 	.defer			= l2cap_chan_no_defer,
3256 	.suspend		= l2cap_chan_no_suspend,
3257 	.resume			= l2cap_chan_no_resume,
3258 	.set_shutdown		= l2cap_chan_no_set_shutdown,
3259 	.get_sndtimeo		= l2cap_chan_no_get_sndtimeo,
3260 };
3261 
3262 static struct l2cap_chan *smp_add_cid(struct hci_dev *hdev, u16 cid)
3263 {
3264 	struct l2cap_chan *chan;
3265 	struct smp_dev *smp;
3266 	struct crypto_kpp *tfm_ecdh;
3267 
3268 	if (cid == L2CAP_CID_SMP_BREDR) {
3269 		smp = NULL;
3270 		goto create_chan;
3271 	}
3272 
3273 	smp = kzalloc_obj(*smp);
3274 	if (!smp)
3275 		return ERR_PTR(-ENOMEM);
3276 
3277 	tfm_ecdh = crypto_alloc_kpp("ecdh-nist-p256", 0, 0);
3278 	if (IS_ERR(tfm_ecdh)) {
3279 		bt_dev_err(hdev, "Unable to create ECDH crypto context");
3280 		kfree_sensitive(smp);
3281 		return ERR_CAST(tfm_ecdh);
3282 	}
3283 
3284 	smp->local_oob = false;
3285 	smp->tfm_ecdh = tfm_ecdh;
3286 
3287 create_chan:
3288 	chan = l2cap_chan_create();
3289 	if (!chan) {
3290 		if (smp) {
3291 			crypto_free_kpp(smp->tfm_ecdh);
3292 			kfree_sensitive(smp);
3293 		}
3294 		return ERR_PTR(-ENOMEM);
3295 	}
3296 
3297 	chan->data = smp;
3298 
3299 	l2cap_add_scid(chan, cid);
3300 
3301 	l2cap_chan_set_defaults(chan, NULL);
3302 
3303 	if (cid == L2CAP_CID_SMP) {
3304 		u8 bdaddr_type;
3305 
3306 		hci_copy_identity_address(hdev, &chan->src, &bdaddr_type);
3307 
3308 		if (bdaddr_type == ADDR_LE_DEV_PUBLIC)
3309 			chan->src_type = BDADDR_LE_PUBLIC;
3310 		else
3311 			chan->src_type = BDADDR_LE_RANDOM;
3312 	} else {
3313 		bacpy(&chan->src, &hdev->bdaddr);
3314 		chan->src_type = BDADDR_BREDR;
3315 	}
3316 
3317 	chan->state = BT_LISTEN;
3318 	chan->mode = L2CAP_MODE_BASIC;
3319 	chan->imtu = L2CAP_DEFAULT_MTU;
3320 	chan->ops = &smp_root_chan_ops;
3321 
3322 	/* Set correct nesting level for a parent/listening channel */
3323 	atomic_set(&chan->nesting, L2CAP_NESTING_PARENT);
3324 
3325 	return chan;
3326 }
3327 
3328 static void smp_del_chan(struct l2cap_chan *chan)
3329 {
3330 	struct smp_dev *smp;
3331 
3332 	BT_DBG("chan %p", chan);
3333 
3334 	smp = chan->data;
3335 	if (smp) {
3336 		chan->data = NULL;
3337 		crypto_free_kpp(smp->tfm_ecdh);
3338 		kfree_sensitive(smp);
3339 	}
3340 
3341 	l2cap_chan_put(chan);
3342 }
3343 
3344 int smp_force_bredr(struct hci_dev *hdev, bool enable)
3345 {
3346 	if (enable == hci_dev_test_flag(hdev, HCI_FORCE_BREDR_SMP))
3347 		return -EALREADY;
3348 
3349 	if (enable) {
3350 		struct l2cap_chan *chan;
3351 
3352 		chan = smp_add_cid(hdev, L2CAP_CID_SMP_BREDR);
3353 		if (IS_ERR(chan))
3354 			return PTR_ERR(chan);
3355 
3356 		hdev->smp_bredr_data = chan;
3357 	} else {
3358 		struct l2cap_chan *chan;
3359 
3360 		chan = hdev->smp_bredr_data;
3361 		hdev->smp_bredr_data = NULL;
3362 		smp_del_chan(chan);
3363 	}
3364 
3365 	hci_dev_change_flag(hdev, HCI_FORCE_BREDR_SMP);
3366 
3367 	return 0;
3368 }
3369 
3370 int smp_register(struct hci_dev *hdev)
3371 {
3372 	struct l2cap_chan *chan;
3373 
3374 	bt_dev_dbg(hdev, "");
3375 
3376 	/* If the controller does not support Low Energy operation, then
3377 	 * there is also no need to register any SMP channel.
3378 	 */
3379 	if (!lmp_le_capable(hdev))
3380 		return 0;
3381 
3382 	if (WARN_ON(hdev->smp_data)) {
3383 		chan = hdev->smp_data;
3384 		hdev->smp_data = NULL;
3385 		smp_del_chan(chan);
3386 	}
3387 
3388 	chan = smp_add_cid(hdev, L2CAP_CID_SMP);
3389 	if (IS_ERR(chan))
3390 		return PTR_ERR(chan);
3391 
3392 	hdev->smp_data = chan;
3393 
3394 	if (!lmp_sc_capable(hdev)) {
3395 		/* Flag can be already set here (due to power toggle) */
3396 		if (!hci_dev_test_flag(hdev, HCI_FORCE_BREDR_SMP))
3397 			return 0;
3398 	}
3399 
3400 	if (WARN_ON(hdev->smp_bredr_data)) {
3401 		chan = hdev->smp_bredr_data;
3402 		hdev->smp_bredr_data = NULL;
3403 		smp_del_chan(chan);
3404 	}
3405 
3406 	chan = smp_add_cid(hdev, L2CAP_CID_SMP_BREDR);
3407 	if (IS_ERR(chan)) {
3408 		int err = PTR_ERR(chan);
3409 		chan = hdev->smp_data;
3410 		hdev->smp_data = NULL;
3411 		smp_del_chan(chan);
3412 		return err;
3413 	}
3414 
3415 	hdev->smp_bredr_data = chan;
3416 
3417 	return 0;
3418 }
3419 
3420 void smp_unregister(struct hci_dev *hdev)
3421 {
3422 	struct l2cap_chan *chan;
3423 
3424 	if (hdev->smp_bredr_data) {
3425 		chan = hdev->smp_bredr_data;
3426 		hdev->smp_bredr_data = NULL;
3427 		smp_del_chan(chan);
3428 	}
3429 
3430 	if (hdev->smp_data) {
3431 		chan = hdev->smp_data;
3432 		hdev->smp_data = NULL;
3433 		smp_del_chan(chan);
3434 	}
3435 }
3436 
3437 #if IS_ENABLED(CONFIG_BT_SELFTEST_SMP)
3438 
3439 static int __init test_debug_key(struct crypto_kpp *tfm_ecdh)
3440 {
3441 	u8 pk[64];
3442 	int err;
3443 
3444 	err = set_ecdh_privkey(tfm_ecdh, debug_sk);
3445 	if (err)
3446 		return err;
3447 
3448 	err = generate_ecdh_public_key(tfm_ecdh, pk);
3449 	if (err)
3450 		return err;
3451 
3452 	if (crypto_memneq(pk, debug_pk, 64))
3453 		return -EINVAL;
3454 
3455 	return 0;
3456 }
3457 
3458 static int __init test_ah(void)
3459 {
3460 	const u8 irk[16] = {
3461 			0x9b, 0x7d, 0x39, 0x0a, 0xa6, 0x10, 0x10, 0x34,
3462 			0x05, 0xad, 0xc8, 0x57, 0xa3, 0x34, 0x02, 0xec };
3463 	const u8 r[3] = { 0x94, 0x81, 0x70 };
3464 	const u8 exp[3] = { 0xaa, 0xfb, 0x0d };
3465 	u8 res[3];
3466 	int err;
3467 
3468 	err = smp_ah(irk, r, res);
3469 	if (err)
3470 		return err;
3471 
3472 	if (crypto_memneq(res, exp, 3))
3473 		return -EINVAL;
3474 
3475 	return 0;
3476 }
3477 
3478 static int __init test_c1(void)
3479 {
3480 	const u8 k[16] = {
3481 			0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
3482 			0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00 };
3483 	const u8 r[16] = {
3484 			0xe0, 0x2e, 0x70, 0xc6, 0x4e, 0x27, 0x88, 0x63,
3485 			0x0e, 0x6f, 0xad, 0x56, 0x21, 0xd5, 0x83, 0x57 };
3486 	const u8 preq[7] = { 0x01, 0x01, 0x00, 0x00, 0x10, 0x07, 0x07 };
3487 	const u8 pres[7] = { 0x02, 0x03, 0x00, 0x00, 0x08, 0x00, 0x05 };
3488 	const u8 _iat = 0x01;
3489 	const u8 _rat = 0x00;
3490 	const bdaddr_t ra = { { 0xb6, 0xb5, 0xb4, 0xb3, 0xb2, 0xb1 } };
3491 	const bdaddr_t ia = { { 0xa6, 0xa5, 0xa4, 0xa3, 0xa2, 0xa1 } };
3492 	const u8 exp[16] = {
3493 			0x86, 0x3b, 0xf1, 0xbe, 0xc5, 0x4d, 0xa7, 0xd2,
3494 			0xea, 0x88, 0x89, 0x87, 0xef, 0x3f, 0x1e, 0x1e };
3495 	u8 res[16];
3496 	int err;
3497 
3498 	err = smp_c1(k, r, preq, pres, _iat, &ia, _rat, &ra, res);
3499 	if (err)
3500 		return err;
3501 
3502 	if (crypto_memneq(res, exp, 16))
3503 		return -EINVAL;
3504 
3505 	return 0;
3506 }
3507 
3508 static int __init test_s1(void)
3509 {
3510 	const u8 k[16] = {
3511 			0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
3512 			0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00 };
3513 	const u8 r1[16] = {
3514 			0x88, 0x77, 0x66, 0x55, 0x44, 0x33, 0x22, 0x11 };
3515 	const u8 r2[16] = {
3516 			0x00, 0xff, 0xee, 0xdd, 0xcc, 0xbb, 0xaa, 0x99 };
3517 	const u8 exp[16] = {
3518 			0x62, 0xa0, 0x6d, 0x79, 0xae, 0x16, 0x42, 0x5b,
3519 			0x9b, 0xf4, 0xb0, 0xe8, 0xf0, 0xe1, 0x1f, 0x9a };
3520 	u8 res[16];
3521 	int err;
3522 
3523 	err = smp_s1(k, r1, r2, res);
3524 	if (err)
3525 		return err;
3526 
3527 	if (crypto_memneq(res, exp, 16))
3528 		return -EINVAL;
3529 
3530 	return 0;
3531 }
3532 
3533 static int __init test_f4(void)
3534 {
3535 	const u8 u[32] = {
3536 			0xe6, 0x9d, 0x35, 0x0e, 0x48, 0x01, 0x03, 0xcc,
3537 			0xdb, 0xfd, 0xf4, 0xac, 0x11, 0x91, 0xf4, 0xef,
3538 			0xb9, 0xa5, 0xf9, 0xe9, 0xa7, 0x83, 0x2c, 0x5e,
3539 			0x2c, 0xbe, 0x97, 0xf2, 0xd2, 0x03, 0xb0, 0x20 };
3540 	const u8 v[32] = {
3541 			0xfd, 0xc5, 0x7f, 0xf4, 0x49, 0xdd, 0x4f, 0x6b,
3542 			0xfb, 0x7c, 0x9d, 0xf1, 0xc2, 0x9a, 0xcb, 0x59,
3543 			0x2a, 0xe7, 0xd4, 0xee, 0xfb, 0xfc, 0x0a, 0x90,
3544 			0x9a, 0xbb, 0xf6, 0x32, 0x3d, 0x8b, 0x18, 0x55 };
3545 	const u8 x[16] = {
3546 			0xab, 0xae, 0x2b, 0x71, 0xec, 0xb2, 0xff, 0xff,
3547 			0x3e, 0x73, 0x77, 0xd1, 0x54, 0x84, 0xcb, 0xd5 };
3548 	const u8 z = 0x00;
3549 	const u8 exp[16] = {
3550 			0x2d, 0x87, 0x74, 0xa9, 0xbe, 0xa1, 0xed, 0xf1,
3551 			0x1c, 0xbd, 0xa9, 0x07, 0xf1, 0x16, 0xc9, 0xf2 };
3552 	u8 res[16];
3553 	int err;
3554 
3555 	err = smp_f4(u, v, x, z, res);
3556 	if (err)
3557 		return err;
3558 
3559 	if (crypto_memneq(res, exp, 16))
3560 		return -EINVAL;
3561 
3562 	return 0;
3563 }
3564 
3565 static int __init test_f5(void)
3566 {
3567 	const u8 w[32] = {
3568 			0x98, 0xa6, 0xbf, 0x73, 0xf3, 0x34, 0x8d, 0x86,
3569 			0xf1, 0x66, 0xf8, 0xb4, 0x13, 0x6b, 0x79, 0x99,
3570 			0x9b, 0x7d, 0x39, 0x0a, 0xa6, 0x10, 0x10, 0x34,
3571 			0x05, 0xad, 0xc8, 0x57, 0xa3, 0x34, 0x02, 0xec };
3572 	const u8 n1[16] = {
3573 			0xab, 0xae, 0x2b, 0x71, 0xec, 0xb2, 0xff, 0xff,
3574 			0x3e, 0x73, 0x77, 0xd1, 0x54, 0x84, 0xcb, 0xd5 };
3575 	const u8 n2[16] = {
3576 			0xcf, 0xc4, 0x3d, 0xff, 0xf7, 0x83, 0x65, 0x21,
3577 			0x6e, 0x5f, 0xa7, 0x25, 0xcc, 0xe7, 0xe8, 0xa6 };
3578 	const u8 a1[7] = { 0xce, 0xbf, 0x37, 0x37, 0x12, 0x56, 0x00 };
3579 	const u8 a2[7] = { 0xc1, 0xcf, 0x2d, 0x70, 0x13, 0xa7, 0x00 };
3580 	const u8 exp_ltk[16] = {
3581 			0x38, 0x0a, 0x75, 0x94, 0xb5, 0x22, 0x05, 0x98,
3582 			0x23, 0xcd, 0xd7, 0x69, 0x11, 0x79, 0x86, 0x69 };
3583 	const u8 exp_mackey[16] = {
3584 			0x20, 0x6e, 0x63, 0xce, 0x20, 0x6a, 0x3f, 0xfd,
3585 			0x02, 0x4a, 0x08, 0xa1, 0x76, 0xf1, 0x65, 0x29 };
3586 	u8 mackey[16], ltk[16];
3587 	int err;
3588 
3589 	err = smp_f5(w, n1, n2, a1, a2, mackey, ltk);
3590 	if (err)
3591 		return err;
3592 
3593 	if (crypto_memneq(mackey, exp_mackey, 16))
3594 		return -EINVAL;
3595 
3596 	if (crypto_memneq(ltk, exp_ltk, 16))
3597 		return -EINVAL;
3598 
3599 	return 0;
3600 }
3601 
3602 static int __init test_f6(void)
3603 {
3604 	const u8 w[16] = {
3605 			0x20, 0x6e, 0x63, 0xce, 0x20, 0x6a, 0x3f, 0xfd,
3606 			0x02, 0x4a, 0x08, 0xa1, 0x76, 0xf1, 0x65, 0x29 };
3607 	const u8 n1[16] = {
3608 			0xab, 0xae, 0x2b, 0x71, 0xec, 0xb2, 0xff, 0xff,
3609 			0x3e, 0x73, 0x77, 0xd1, 0x54, 0x84, 0xcb, 0xd5 };
3610 	const u8 n2[16] = {
3611 			0xcf, 0xc4, 0x3d, 0xff, 0xf7, 0x83, 0x65, 0x21,
3612 			0x6e, 0x5f, 0xa7, 0x25, 0xcc, 0xe7, 0xe8, 0xa6 };
3613 	const u8 r[16] = {
3614 			0xc8, 0x0f, 0x2d, 0x0c, 0xd2, 0x42, 0xda, 0x08,
3615 			0x54, 0xbb, 0x53, 0xb4, 0x3b, 0x34, 0xa3, 0x12 };
3616 	const u8 io_cap[3] = { 0x02, 0x01, 0x01 };
3617 	const u8 a1[7] = { 0xce, 0xbf, 0x37, 0x37, 0x12, 0x56, 0x00 };
3618 	const u8 a2[7] = { 0xc1, 0xcf, 0x2d, 0x70, 0x13, 0xa7, 0x00 };
3619 	const u8 exp[16] = {
3620 			0x61, 0x8f, 0x95, 0xda, 0x09, 0x0b, 0x6c, 0xd2,
3621 			0xc5, 0xe8, 0xd0, 0x9c, 0x98, 0x73, 0xc4, 0xe3 };
3622 	u8 res[16];
3623 	int err;
3624 
3625 	err = smp_f6(w, n1, n2, r, io_cap, a1, a2, res);
3626 	if (err)
3627 		return err;
3628 
3629 	if (crypto_memneq(res, exp, 16))
3630 		return -EINVAL;
3631 
3632 	return 0;
3633 }
3634 
3635 static int __init test_g2(void)
3636 {
3637 	const u8 u[32] = {
3638 			0xe6, 0x9d, 0x35, 0x0e, 0x48, 0x01, 0x03, 0xcc,
3639 			0xdb, 0xfd, 0xf4, 0xac, 0x11, 0x91, 0xf4, 0xef,
3640 			0xb9, 0xa5, 0xf9, 0xe9, 0xa7, 0x83, 0x2c, 0x5e,
3641 			0x2c, 0xbe, 0x97, 0xf2, 0xd2, 0x03, 0xb0, 0x20 };
3642 	const u8 v[32] = {
3643 			0xfd, 0xc5, 0x7f, 0xf4, 0x49, 0xdd, 0x4f, 0x6b,
3644 			0xfb, 0x7c, 0x9d, 0xf1, 0xc2, 0x9a, 0xcb, 0x59,
3645 			0x2a, 0xe7, 0xd4, 0xee, 0xfb, 0xfc, 0x0a, 0x90,
3646 			0x9a, 0xbb, 0xf6, 0x32, 0x3d, 0x8b, 0x18, 0x55 };
3647 	const u8 x[16] = {
3648 			0xab, 0xae, 0x2b, 0x71, 0xec, 0xb2, 0xff, 0xff,
3649 			0x3e, 0x73, 0x77, 0xd1, 0x54, 0x84, 0xcb, 0xd5 };
3650 	const u8 y[16] = {
3651 			0xcf, 0xc4, 0x3d, 0xff, 0xf7, 0x83, 0x65, 0x21,
3652 			0x6e, 0x5f, 0xa7, 0x25, 0xcc, 0xe7, 0xe8, 0xa6 };
3653 	const u32 exp_val = 0x2f9ed5ba % 1000000;
3654 	u32 val;
3655 	int err;
3656 
3657 	err = smp_g2(u, v, x, y, &val);
3658 	if (err)
3659 		return err;
3660 
3661 	if (val != exp_val)
3662 		return -EINVAL;
3663 
3664 	return 0;
3665 }
3666 
3667 static int __init test_h6(void)
3668 {
3669 	const u8 w[16] = {
3670 			0x9b, 0x7d, 0x39, 0x0a, 0xa6, 0x10, 0x10, 0x34,
3671 			0x05, 0xad, 0xc8, 0x57, 0xa3, 0x34, 0x02, 0xec };
3672 	const u8 key_id[4] = { 0x72, 0x62, 0x65, 0x6c };
3673 	const u8 exp[16] = {
3674 			0x99, 0x63, 0xb1, 0x80, 0xe2, 0xa9, 0xd3, 0xe8,
3675 			0x1c, 0xc9, 0x6d, 0xe7, 0x02, 0xe1, 0x9a, 0x2d };
3676 	u8 res[16];
3677 	int err;
3678 
3679 	err = smp_h6(w, key_id, res);
3680 	if (err)
3681 		return err;
3682 
3683 	if (crypto_memneq(res, exp, 16))
3684 		return -EINVAL;
3685 
3686 	return 0;
3687 }
3688 
3689 static char test_smp_buffer[32];
3690 
3691 static ssize_t test_smp_read(struct file *file, char __user *user_buf,
3692 			     size_t count, loff_t *ppos)
3693 {
3694 	return simple_read_from_buffer(user_buf, count, ppos, test_smp_buffer,
3695 				       strlen(test_smp_buffer));
3696 }
3697 
3698 static const struct file_operations test_smp_fops = {
3699 	.open		= simple_open,
3700 	.read		= test_smp_read,
3701 	.llseek		= default_llseek,
3702 };
3703 
3704 static int __init run_selftests(struct crypto_kpp *tfm_ecdh)
3705 {
3706 	ktime_t calltime, delta, rettime;
3707 	unsigned long long duration;
3708 	int err;
3709 
3710 	calltime = ktime_get();
3711 
3712 	err = test_debug_key(tfm_ecdh);
3713 	if (err) {
3714 		BT_ERR("debug_key test failed");
3715 		goto done;
3716 	}
3717 
3718 	err = test_ah();
3719 	if (err) {
3720 		BT_ERR("smp_ah test failed");
3721 		goto done;
3722 	}
3723 
3724 	err = test_c1();
3725 	if (err) {
3726 		BT_ERR("smp_c1 test failed");
3727 		goto done;
3728 	}
3729 
3730 	err = test_s1();
3731 	if (err) {
3732 		BT_ERR("smp_s1 test failed");
3733 		goto done;
3734 	}
3735 
3736 	err = test_f4();
3737 	if (err) {
3738 		BT_ERR("smp_f4 test failed");
3739 		goto done;
3740 	}
3741 
3742 	err = test_f5();
3743 	if (err) {
3744 		BT_ERR("smp_f5 test failed");
3745 		goto done;
3746 	}
3747 
3748 	err = test_f6();
3749 	if (err) {
3750 		BT_ERR("smp_f6 test failed");
3751 		goto done;
3752 	}
3753 
3754 	err = test_g2();
3755 	if (err) {
3756 		BT_ERR("smp_g2 test failed");
3757 		goto done;
3758 	}
3759 
3760 	err = test_h6();
3761 	if (err) {
3762 		BT_ERR("smp_h6 test failed");
3763 		goto done;
3764 	}
3765 
3766 	rettime = ktime_get();
3767 	delta = ktime_sub(rettime, calltime);
3768 	duration = (unsigned long long) ktime_to_ns(delta) >> 10;
3769 
3770 	BT_INFO("SMP test passed in %llu usecs", duration);
3771 
3772 done:
3773 	if (!err)
3774 		snprintf(test_smp_buffer, sizeof(test_smp_buffer),
3775 			 "PASS (%llu usecs)\n", duration);
3776 	else
3777 		snprintf(test_smp_buffer, sizeof(test_smp_buffer), "FAIL\n");
3778 
3779 	debugfs_create_file("selftest_smp", 0444, bt_debugfs, NULL,
3780 			    &test_smp_fops);
3781 
3782 	return err;
3783 }
3784 
3785 int __init bt_selftest_smp(void)
3786 {
3787 	struct crypto_kpp *tfm_ecdh;
3788 	int err;
3789 
3790 	tfm_ecdh = crypto_alloc_kpp("ecdh-nist-p256", 0, 0);
3791 	if (IS_ERR(tfm_ecdh)) {
3792 		BT_ERR("Unable to create ECDH crypto context");
3793 		return PTR_ERR(tfm_ecdh);
3794 	}
3795 
3796 	err = run_selftests(tfm_ecdh);
3797 
3798 	crypto_free_kpp(tfm_ecdh);
3799 
3800 	return err;
3801 }
3802 
3803 #endif
3804