]> git.proxmox.com Git - mirror_ubuntu-kernels.git/blame - net/bluetooth/hci_conn.c
[Bluetooth] Enforce correct authentication requirements
[mirror_ubuntu-kernels.git] / net / bluetooth / hci_conn.c
CommitLineData
8e87d142 1/*
1da177e4
LT
2 BlueZ - Bluetooth protocol stack for Linux
3 Copyright (C) 2000-2001 Qualcomm Incorporated
4
5 Written 2000,2001 by Maxim Krasnyansky <maxk@qualcomm.com>
6
7 This program is free software; you can redistribute it and/or modify
8 it under the terms of the GNU General Public License version 2 as
9 published by the Free Software Foundation;
10
11 THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS
12 OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
13 FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT OF THIRD PARTY RIGHTS.
14 IN NO EVENT SHALL THE COPYRIGHT HOLDER(S) AND AUTHOR(S) BE LIABLE FOR ANY
8e87d142
YH
15 CLAIM, OR ANY SPECIAL INDIRECT OR CONSEQUENTIAL DAMAGES, OR ANY DAMAGES
16 WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
17 ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
1da177e4
LT
18 OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
19
8e87d142
YH
20 ALL LIABILITY, INCLUDING LIABILITY FOR INFRINGEMENT OF ANY PATENTS,
21 COPYRIGHTS, TRADEMARKS OR OTHER RIGHTS, RELATING TO USE OF THIS
1da177e4
LT
22 SOFTWARE IS DISCLAIMED.
23*/
24
25/* Bluetooth HCI connection handling. */
26
1da177e4
LT
27#include <linux/module.h>
28
29#include <linux/types.h>
30#include <linux/errno.h>
31#include <linux/kernel.h>
1da177e4
LT
32#include <linux/slab.h>
33#include <linux/poll.h>
34#include <linux/fcntl.h>
35#include <linux/init.h>
36#include <linux/skbuff.h>
37#include <linux/interrupt.h>
38#include <linux/notifier.h>
39#include <net/sock.h>
40
41#include <asm/system.h>
42#include <asm/uaccess.h>
43#include <asm/unaligned.h>
44
45#include <net/bluetooth/bluetooth.h>
46#include <net/bluetooth/hci_core.h>
47
48#ifndef CONFIG_BT_HCI_CORE_DEBUG
49#undef BT_DBG
50#define BT_DBG(D...)
51#endif
52
4c67bc74 53void hci_acl_connect(struct hci_conn *conn)
1da177e4
LT
54{
55 struct hci_dev *hdev = conn->hdev;
56 struct inquiry_entry *ie;
57 struct hci_cp_create_conn cp;
58
59 BT_DBG("%p", conn);
60
61 conn->state = BT_CONNECT;
a8746417
MH
62 conn->out = 1;
63
1da177e4
LT
64 conn->link_mode = HCI_LM_MASTER;
65
4c67bc74
MH
66 conn->attempt++;
67
e4e8e37c
MH
68 conn->link_policy = hdev->link_policy;
69
1da177e4
LT
70 memset(&cp, 0, sizeof(cp));
71 bacpy(&cp.bdaddr, &conn->dst);
72 cp.pscan_rep_mode = 0x02;
73
41a96212
MH
74 if ((ie = hci_inquiry_cache_lookup(hdev, &conn->dst))) {
75 if (inquiry_entry_age(ie) <= INQUIRY_ENTRY_AGE_MAX) {
76 cp.pscan_rep_mode = ie->data.pscan_rep_mode;
77 cp.pscan_mode = ie->data.pscan_mode;
78 cp.clock_offset = ie->data.clock_offset |
79 cpu_to_le16(0x8000);
80 }
81
1da177e4 82 memcpy(conn->dev_class, ie->data.dev_class, 3);
41a96212 83 conn->ssp_mode = ie->data.ssp_mode;
1da177e4
LT
84 }
85
a8746417 86 cp.pkt_type = cpu_to_le16(conn->pkt_type);
1da177e4 87 if (lmp_rswitch_capable(hdev) && !(hdev->link_mode & HCI_LM_MASTER))
b6a0dc82 88 cp.role_switch = 0x01;
1da177e4 89 else
b6a0dc82 90 cp.role_switch = 0x00;
4c67bc74 91
a9de9248 92 hci_send_cmd(hdev, HCI_OP_CREATE_CONN, sizeof(cp), &cp);
1da177e4
LT
93}
94
6ac59344
MH
95static void hci_acl_connect_cancel(struct hci_conn *conn)
96{
97 struct hci_cp_create_conn_cancel cp;
98
99 BT_DBG("%p", conn);
100
101 if (conn->hdev->hci_ver < 2)
102 return;
103
104 bacpy(&cp.bdaddr, &conn->dst);
a9de9248 105 hci_send_cmd(conn->hdev, HCI_OP_CREATE_CONN_CANCEL, sizeof(cp), &cp);
6ac59344
MH
106}
107
1da177e4
LT
108void hci_acl_disconn(struct hci_conn *conn, __u8 reason)
109{
110 struct hci_cp_disconnect cp;
111
112 BT_DBG("%p", conn);
113
114 conn->state = BT_DISCONN;
115
aca3192c 116 cp.handle = cpu_to_le16(conn->handle);
1da177e4 117 cp.reason = reason;
a9de9248 118 hci_send_cmd(conn->hdev, HCI_OP_DISCONNECT, sizeof(cp), &cp);
1da177e4
LT
119}
120
121void hci_add_sco(struct hci_conn *conn, __u16 handle)
122{
123 struct hci_dev *hdev = conn->hdev;
124 struct hci_cp_add_sco cp;
125
126 BT_DBG("%p", conn);
127
128 conn->state = BT_CONNECT;
129 conn->out = 1;
130
aca3192c 131 cp.handle = cpu_to_le16(handle);
a8746417 132 cp.pkt_type = cpu_to_le16(conn->pkt_type);
1da177e4 133
a9de9248 134 hci_send_cmd(hdev, HCI_OP_ADD_SCO, sizeof(cp), &cp);
1da177e4
LT
135}
136
b6a0dc82
MH
137void hci_setup_sync(struct hci_conn *conn, __u16 handle)
138{
139 struct hci_dev *hdev = conn->hdev;
140 struct hci_cp_setup_sync_conn cp;
141
142 BT_DBG("%p", conn);
143
144 conn->state = BT_CONNECT;
145 conn->out = 1;
146
147 cp.handle = cpu_to_le16(handle);
a8746417 148 cp.pkt_type = cpu_to_le16(conn->pkt_type);
b6a0dc82
MH
149
150 cp.tx_bandwidth = cpu_to_le32(0x00001f40);
151 cp.rx_bandwidth = cpu_to_le32(0x00001f40);
152 cp.max_latency = cpu_to_le16(0xffff);
153 cp.voice_setting = cpu_to_le16(hdev->voice_setting);
154 cp.retrans_effort = 0xff;
155
156 hci_send_cmd(hdev, HCI_OP_SETUP_SYNC_CONN, sizeof(cp), &cp);
157}
158
1da177e4
LT
159static void hci_conn_timeout(unsigned long arg)
160{
04837f64
MH
161 struct hci_conn *conn = (void *) arg;
162 struct hci_dev *hdev = conn->hdev;
1da177e4
LT
163
164 BT_DBG("conn %p state %d", conn, conn->state);
165
166 if (atomic_read(&conn->refcnt))
167 return;
168
169 hci_dev_lock(hdev);
6ac59344
MH
170
171 switch (conn->state) {
172 case BT_CONNECT:
769be974 173 case BT_CONNECT2:
b6a0dc82
MH
174 if (conn->type == ACL_LINK)
175 hci_acl_connect_cancel(conn);
176 else
177 hci_acl_disconn(conn, 0x13);
6ac59344 178 break;
769be974 179 case BT_CONFIG:
8e87d142 180 case BT_CONNECTED:
1da177e4 181 hci_acl_disconn(conn, 0x13);
6ac59344
MH
182 break;
183 default:
1da177e4 184 conn->state = BT_CLOSED;
6ac59344
MH
185 break;
186 }
187
1da177e4 188 hci_dev_unlock(hdev);
1da177e4
LT
189}
190
04837f64 191static void hci_conn_idle(unsigned long arg)
1da177e4 192{
04837f64
MH
193 struct hci_conn *conn = (void *) arg;
194
195 BT_DBG("conn %p mode %d", conn, conn->mode);
196
197 hci_conn_enter_sniff_mode(conn);
1da177e4
LT
198}
199
200struct hci_conn *hci_conn_add(struct hci_dev *hdev, int type, bdaddr_t *dst)
201{
202 struct hci_conn *conn;
203
204 BT_DBG("%s dst %s", hdev->name, batostr(dst));
205
04837f64
MH
206 conn = kzalloc(sizeof(struct hci_conn), GFP_ATOMIC);
207 if (!conn)
1da177e4 208 return NULL;
1da177e4
LT
209
210 bacpy(&conn->dst, dst);
a8746417
MH
211 conn->hdev = hdev;
212 conn->type = type;
213 conn->mode = HCI_CM_ACTIVE;
214 conn->state = BT_OPEN;
1da177e4 215
04837f64
MH
216 conn->power_save = 1;
217
a8746417
MH
218 switch (type) {
219 case ACL_LINK:
220 conn->pkt_type = hdev->pkt_type & ACL_PTYPE_MASK;
221 break;
222 case SCO_LINK:
223 if (lmp_esco_capable(hdev))
224 conn->pkt_type = hdev->esco_type & SCO_ESCO_MASK;
225 else
226 conn->pkt_type = hdev->pkt_type & SCO_PTYPE_MASK;
227 break;
228 case ESCO_LINK:
229 conn->pkt_type = hdev->esco_type;
230 break;
231 }
232
1da177e4 233 skb_queue_head_init(&conn->data_q);
04837f64 234
b24b8a24
PE
235 setup_timer(&conn->disc_timer, hci_conn_timeout, (unsigned long)conn);
236 setup_timer(&conn->idle_timer, hci_conn_idle, (unsigned long)conn);
1da177e4
LT
237
238 atomic_set(&conn->refcnt, 0);
239
240 hci_dev_hold(hdev);
241
242 tasklet_disable(&hdev->tx_task);
243
244 hci_conn_hash_add(hdev, conn);
245 if (hdev->notify)
246 hdev->notify(hdev, HCI_NOTIFY_CONN_ADD);
247
248 tasklet_enable(&hdev->tx_task);
249
250 return conn;
251}
252
253int hci_conn_del(struct hci_conn *conn)
254{
255 struct hci_dev *hdev = conn->hdev;
256
257 BT_DBG("%s conn %p handle %d", hdev->name, conn, conn->handle);
258
04837f64
MH
259 del_timer(&conn->idle_timer);
260
261 del_timer(&conn->disc_timer);
1da177e4 262
5b7f9909 263 if (conn->type == ACL_LINK) {
1da177e4
LT
264 struct hci_conn *sco = conn->link;
265 if (sco)
266 sco->link = NULL;
267
268 /* Unacked frames */
269 hdev->acl_cnt += conn->sent;
5b7f9909
MH
270 } else {
271 struct hci_conn *acl = conn->link;
272 if (acl) {
273 acl->link = NULL;
274 hci_conn_put(acl);
275 }
1da177e4
LT
276 }
277
278 tasklet_disable(&hdev->tx_task);
7d0db0a3 279
1da177e4
LT
280 hci_conn_hash_del(hdev, conn);
281 if (hdev->notify)
282 hdev->notify(hdev, HCI_NOTIFY_CONN_DEL);
7d0db0a3 283
1da177e4 284 tasklet_enable(&hdev->tx_task);
7d0db0a3 285
1da177e4 286 skb_queue_purge(&conn->data_q);
1da177e4 287
1da177e4
LT
288 return 0;
289}
290
291struct hci_dev *hci_get_route(bdaddr_t *dst, bdaddr_t *src)
292{
293 int use_src = bacmp(src, BDADDR_ANY);
294 struct hci_dev *hdev = NULL;
295 struct list_head *p;
296
297 BT_DBG("%s -> %s", batostr(src), batostr(dst));
298
299 read_lock_bh(&hci_dev_list_lock);
300
301 list_for_each(p, &hci_dev_list) {
302 struct hci_dev *d = list_entry(p, struct hci_dev, list);
303
304 if (!test_bit(HCI_UP, &d->flags) || test_bit(HCI_RAW, &d->flags))
305 continue;
306
8e87d142 307 /* Simple routing:
1da177e4
LT
308 * No source address - find interface with bdaddr != dst
309 * Source address - find interface with bdaddr == src
310 */
311
312 if (use_src) {
313 if (!bacmp(&d->bdaddr, src)) {
314 hdev = d; break;
315 }
316 } else {
317 if (bacmp(&d->bdaddr, dst)) {
318 hdev = d; break;
319 }
320 }
321 }
322
323 if (hdev)
324 hdev = hci_dev_hold(hdev);
325
326 read_unlock_bh(&hci_dev_list_lock);
327 return hdev;
328}
329EXPORT_SYMBOL(hci_get_route);
330
331/* Create SCO or ACL connection.
332 * Device _must_ be locked */
09ab6f4c 333struct hci_conn *hci_connect(struct hci_dev *hdev, int type, bdaddr_t *dst, __u8 auth_type)
1da177e4
LT
334{
335 struct hci_conn *acl;
5b7f9909 336 struct hci_conn *sco;
1da177e4
LT
337
338 BT_DBG("%s dst %s", hdev->name, batostr(dst));
339
340 if (!(acl = hci_conn_hash_lookup_ba(hdev, ACL_LINK, dst))) {
341 if (!(acl = hci_conn_add(hdev, ACL_LINK, dst)))
342 return NULL;
343 }
344
345 hci_conn_hold(acl);
346
09ab6f4c
MH
347 if (acl->state == BT_OPEN || acl->state == BT_CLOSED) {
348 acl->auth_type = auth_type;
1da177e4 349 hci_acl_connect(acl);
09ab6f4c 350 }
1da177e4 351
5b7f9909
MH
352 if (type == ACL_LINK)
353 return acl;
1da177e4 354
5b7f9909
MH
355 if (!(sco = hci_conn_hash_lookup_ba(hdev, type, dst))) {
356 if (!(sco = hci_conn_add(hdev, type, dst))) {
357 hci_conn_put(acl);
358 return NULL;
1da177e4 359 }
5b7f9909 360 }
1da177e4 361
5b7f9909
MH
362 acl->link = sco;
363 sco->link = acl;
1da177e4 364
5b7f9909 365 hci_conn_hold(sco);
1da177e4 366
5b7f9909 367 if (acl->state == BT_CONNECTED &&
b6a0dc82
MH
368 (sco->state == BT_OPEN || sco->state == BT_CLOSED)) {
369 if (lmp_esco_capable(hdev))
370 hci_setup_sync(sco, acl->handle);
371 else
372 hci_add_sco(sco, acl->handle);
373 }
5b7f9909
MH
374
375 return sco;
1da177e4
LT
376}
377EXPORT_SYMBOL(hci_connect);
378
379/* Authenticate remote device */
380int hci_conn_auth(struct hci_conn *conn)
381{
382 BT_DBG("conn %p", conn);
383
40be492f
MH
384 if (conn->ssp_mode > 0 && conn->hdev->ssp_mode > 0) {
385 if (!(conn->auth_type & 0x01)) {
09ab6f4c 386 conn->auth_type |= 0x01;
40be492f
MH
387 conn->link_mode &= ~HCI_LM_AUTH;
388 }
389 }
390
1da177e4
LT
391 if (conn->link_mode & HCI_LM_AUTH)
392 return 1;
393
394 if (!test_and_set_bit(HCI_CONN_AUTH_PEND, &conn->pend)) {
395 struct hci_cp_auth_requested cp;
aca3192c 396 cp.handle = cpu_to_le16(conn->handle);
40be492f
MH
397 hci_send_cmd(conn->hdev, HCI_OP_AUTH_REQUESTED,
398 sizeof(cp), &cp);
1da177e4
LT
399 }
400 return 0;
401}
402EXPORT_SYMBOL(hci_conn_auth);
403
404/* Enable encryption */
405int hci_conn_encrypt(struct hci_conn *conn)
406{
407 BT_DBG("conn %p", conn);
408
409 if (conn->link_mode & HCI_LM_ENCRYPT)
40be492f 410 return hci_conn_auth(conn);
1da177e4
LT
411
412 if (test_and_set_bit(HCI_CONN_ENCRYPT_PEND, &conn->pend))
413 return 0;
414
415 if (hci_conn_auth(conn)) {
416 struct hci_cp_set_conn_encrypt cp;
aca3192c 417 cp.handle = cpu_to_le16(conn->handle);
8e87d142 418 cp.encrypt = 1;
40be492f
MH
419 hci_send_cmd(conn->hdev, HCI_OP_SET_CONN_ENCRYPT,
420 sizeof(cp), &cp);
1da177e4
LT
421 }
422 return 0;
423}
424EXPORT_SYMBOL(hci_conn_encrypt);
425
426/* Change link key */
427int hci_conn_change_link_key(struct hci_conn *conn)
428{
429 BT_DBG("conn %p", conn);
430
431 if (!test_and_set_bit(HCI_CONN_AUTH_PEND, &conn->pend)) {
432 struct hci_cp_change_conn_link_key cp;
aca3192c 433 cp.handle = cpu_to_le16(conn->handle);
40be492f
MH
434 hci_send_cmd(conn->hdev, HCI_OP_CHANGE_CONN_LINK_KEY,
435 sizeof(cp), &cp);
1da177e4
LT
436 }
437 return 0;
438}
439EXPORT_SYMBOL(hci_conn_change_link_key);
440
441/* Switch role */
442int hci_conn_switch_role(struct hci_conn *conn, uint8_t role)
443{
444 BT_DBG("conn %p", conn);
445
446 if (!role && conn->link_mode & HCI_LM_MASTER)
447 return 1;
448
449 if (!test_and_set_bit(HCI_CONN_RSWITCH_PEND, &conn->pend)) {
450 struct hci_cp_switch_role cp;
451 bacpy(&cp.bdaddr, &conn->dst);
452 cp.role = role;
a9de9248 453 hci_send_cmd(conn->hdev, HCI_OP_SWITCH_ROLE, sizeof(cp), &cp);
1da177e4
LT
454 }
455 return 0;
456}
457EXPORT_SYMBOL(hci_conn_switch_role);
458
04837f64
MH
459/* Enter active mode */
460void hci_conn_enter_active_mode(struct hci_conn *conn)
461{
462 struct hci_dev *hdev = conn->hdev;
463
464 BT_DBG("conn %p mode %d", conn, conn->mode);
465
466 if (test_bit(HCI_RAW, &hdev->flags))
467 return;
468
469 if (conn->mode != HCI_CM_SNIFF || !conn->power_save)
470 goto timer;
471
472 if (!test_and_set_bit(HCI_CONN_MODE_CHANGE_PEND, &conn->pend)) {
473 struct hci_cp_exit_sniff_mode cp;
aca3192c 474 cp.handle = cpu_to_le16(conn->handle);
a9de9248 475 hci_send_cmd(hdev, HCI_OP_EXIT_SNIFF_MODE, sizeof(cp), &cp);
04837f64
MH
476 }
477
478timer:
479 if (hdev->idle_timeout > 0)
480 mod_timer(&conn->idle_timer,
481 jiffies + msecs_to_jiffies(hdev->idle_timeout));
482}
483
484/* Enter sniff mode */
485void hci_conn_enter_sniff_mode(struct hci_conn *conn)
486{
487 struct hci_dev *hdev = conn->hdev;
488
489 BT_DBG("conn %p mode %d", conn, conn->mode);
490
491 if (test_bit(HCI_RAW, &hdev->flags))
492 return;
493
494 if (!lmp_sniff_capable(hdev) || !lmp_sniff_capable(conn))
495 return;
496
497 if (conn->mode != HCI_CM_ACTIVE || !(conn->link_policy & HCI_LP_SNIFF))
498 return;
499
500 if (lmp_sniffsubr_capable(hdev) && lmp_sniffsubr_capable(conn)) {
501 struct hci_cp_sniff_subrate cp;
aca3192c
YH
502 cp.handle = cpu_to_le16(conn->handle);
503 cp.max_latency = cpu_to_le16(0);
504 cp.min_remote_timeout = cpu_to_le16(0);
505 cp.min_local_timeout = cpu_to_le16(0);
a9de9248 506 hci_send_cmd(hdev, HCI_OP_SNIFF_SUBRATE, sizeof(cp), &cp);
04837f64
MH
507 }
508
509 if (!test_and_set_bit(HCI_CONN_MODE_CHANGE_PEND, &conn->pend)) {
510 struct hci_cp_sniff_mode cp;
aca3192c
YH
511 cp.handle = cpu_to_le16(conn->handle);
512 cp.max_interval = cpu_to_le16(hdev->sniff_max_interval);
513 cp.min_interval = cpu_to_le16(hdev->sniff_min_interval);
514 cp.attempt = cpu_to_le16(4);
515 cp.timeout = cpu_to_le16(1);
a9de9248 516 hci_send_cmd(hdev, HCI_OP_SNIFF_MODE, sizeof(cp), &cp);
04837f64
MH
517 }
518}
519
1da177e4
LT
520/* Drop all connection on the device */
521void hci_conn_hash_flush(struct hci_dev *hdev)
522{
523 struct hci_conn_hash *h = &hdev->conn_hash;
524 struct list_head *p;
525
526 BT_DBG("hdev %s", hdev->name);
527
528 p = h->list.next;
529 while (p != &h->list) {
530 struct hci_conn *c;
531
532 c = list_entry(p, struct hci_conn, list);
533 p = p->next;
534
535 c->state = BT_CLOSED;
536
7d0db0a3
MH
537 hci_conn_del_sysfs(c);
538
1da177e4
LT
539 hci_proto_disconn_ind(c, 0x16);
540 hci_conn_del(c);
541 }
542}
543
a9de9248
MH
544/* Check pending connect attempts */
545void hci_conn_check_pending(struct hci_dev *hdev)
546{
547 struct hci_conn *conn;
548
549 BT_DBG("hdev %s", hdev->name);
550
551 hci_dev_lock(hdev);
552
553 conn = hci_conn_hash_lookup_state(hdev, ACL_LINK, BT_CONNECT2);
554 if (conn)
555 hci_acl_connect(conn);
556
557 hci_dev_unlock(hdev);
558}
559
1da177e4
LT
560int hci_get_conn_list(void __user *arg)
561{
562 struct hci_conn_list_req req, *cl;
563 struct hci_conn_info *ci;
564 struct hci_dev *hdev;
565 struct list_head *p;
566 int n = 0, size, err;
567
568 if (copy_from_user(&req, arg, sizeof(req)))
569 return -EFAULT;
570
571 if (!req.conn_num || req.conn_num > (PAGE_SIZE * 2) / sizeof(*ci))
572 return -EINVAL;
573
574 size = sizeof(req) + req.conn_num * sizeof(*ci);
575
12fe2c58 576 if (!(cl = kmalloc(size, GFP_KERNEL)))
1da177e4
LT
577 return -ENOMEM;
578
579 if (!(hdev = hci_dev_get(req.dev_id))) {
580 kfree(cl);
581 return -ENODEV;
582 }
583
584 ci = cl->conn_info;
585
586 hci_dev_lock_bh(hdev);
587 list_for_each(p, &hdev->conn_hash.list) {
588 register struct hci_conn *c;
589 c = list_entry(p, struct hci_conn, list);
590
591 bacpy(&(ci + n)->bdaddr, &c->dst);
592 (ci + n)->handle = c->handle;
593 (ci + n)->type = c->type;
594 (ci + n)->out = c->out;
595 (ci + n)->state = c->state;
596 (ci + n)->link_mode = c->link_mode;
597 if (++n >= req.conn_num)
598 break;
599 }
600 hci_dev_unlock_bh(hdev);
601
602 cl->dev_id = hdev->id;
603 cl->conn_num = n;
604 size = sizeof(req) + n * sizeof(*ci);
605
606 hci_dev_put(hdev);
607
608 err = copy_to_user(arg, cl, size);
609 kfree(cl);
610
611 return err ? -EFAULT : 0;
612}
613
614int hci_get_conn_info(struct hci_dev *hdev, void __user *arg)
615{
616 struct hci_conn_info_req req;
617 struct hci_conn_info ci;
618 struct hci_conn *conn;
619 char __user *ptr = arg + sizeof(req);
620
621 if (copy_from_user(&req, arg, sizeof(req)))
622 return -EFAULT;
623
624 hci_dev_lock_bh(hdev);
625 conn = hci_conn_hash_lookup_ba(hdev, req.type, &req.bdaddr);
626 if (conn) {
627 bacpy(&ci.bdaddr, &conn->dst);
628 ci.handle = conn->handle;
629 ci.type = conn->type;
630 ci.out = conn->out;
631 ci.state = conn->state;
632 ci.link_mode = conn->link_mode;
633 }
634 hci_dev_unlock_bh(hdev);
635
636 if (!conn)
637 return -ENOENT;
638
639 return copy_to_user(ptr, &ci, sizeof(ci)) ? -EFAULT : 0;
640}
40be492f
MH
641
642int hci_get_auth_info(struct hci_dev *hdev, void __user *arg)
643{
644 struct hci_auth_info_req req;
645 struct hci_conn *conn;
646
647 if (copy_from_user(&req, arg, sizeof(req)))
648 return -EFAULT;
649
650 hci_dev_lock_bh(hdev);
651 conn = hci_conn_hash_lookup_ba(hdev, ACL_LINK, &req.bdaddr);
652 if (conn)
653 req.type = conn->auth_type;
654 hci_dev_unlock_bh(hdev);
655
656 if (!conn)
657 return -ENOENT;
658
659 return copy_to_user(arg, &req, sizeof(req)) ? -EFAULT : 0;
660}