]> git.proxmox.com Git - mirror_ubuntu-bionic-kernel.git/blame - net/bluetooth/hci_conn.c
Bluetooth: Permit BT_SECURITY also for L2CAP raw sockets
[mirror_ubuntu-bionic-kernel.git] / net / bluetooth / hci_conn.c
CommitLineData
8e87d142 1/*
1da177e4
LT
2 BlueZ - Bluetooth protocol stack for Linux
3 Copyright (C) 2000-2001 Qualcomm Incorporated
4
5 Written 2000,2001 by Maxim Krasnyansky <maxk@qualcomm.com>
6
7 This program is free software; you can redistribute it and/or modify
8 it under the terms of the GNU General Public License version 2 as
9 published by the Free Software Foundation;
10
11 THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS
12 OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
13 FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT OF THIRD PARTY RIGHTS.
14 IN NO EVENT SHALL THE COPYRIGHT HOLDER(S) AND AUTHOR(S) BE LIABLE FOR ANY
8e87d142
YH
15 CLAIM, OR ANY SPECIAL INDIRECT OR CONSEQUENTIAL DAMAGES, OR ANY DAMAGES
16 WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
17 ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
1da177e4
LT
18 OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
19
8e87d142
YH
20 ALL LIABILITY, INCLUDING LIABILITY FOR INFRINGEMENT OF ANY PATENTS,
21 COPYRIGHTS, TRADEMARKS OR OTHER RIGHTS, RELATING TO USE OF THIS
1da177e4
LT
22 SOFTWARE IS DISCLAIMED.
23*/
24
25/* Bluetooth HCI connection handling. */
26
1da177e4
LT
27#include <linux/module.h>
28
29#include <linux/types.h>
30#include <linux/errno.h>
31#include <linux/kernel.h>
1da177e4
LT
32#include <linux/slab.h>
33#include <linux/poll.h>
34#include <linux/fcntl.h>
35#include <linux/init.h>
36#include <linux/skbuff.h>
37#include <linux/interrupt.h>
38#include <linux/notifier.h>
39#include <net/sock.h>
40
41#include <asm/system.h>
42#include <asm/uaccess.h>
43#include <asm/unaligned.h>
44
45#include <net/bluetooth/bluetooth.h>
46#include <net/bluetooth/hci_core.h>
47
4c67bc74 48void hci_acl_connect(struct hci_conn *conn)
1da177e4
LT
49{
50 struct hci_dev *hdev = conn->hdev;
51 struct inquiry_entry *ie;
52 struct hci_cp_create_conn cp;
53
54 BT_DBG("%p", conn);
55
56 conn->state = BT_CONNECT;
a8746417
MH
57 conn->out = 1;
58
1da177e4
LT
59 conn->link_mode = HCI_LM_MASTER;
60
4c67bc74
MH
61 conn->attempt++;
62
e4e8e37c
MH
63 conn->link_policy = hdev->link_policy;
64
1da177e4
LT
65 memset(&cp, 0, sizeof(cp));
66 bacpy(&cp.bdaddr, &conn->dst);
67 cp.pscan_rep_mode = 0x02;
68
41a96212
MH
69 if ((ie = hci_inquiry_cache_lookup(hdev, &conn->dst))) {
70 if (inquiry_entry_age(ie) <= INQUIRY_ENTRY_AGE_MAX) {
71 cp.pscan_rep_mode = ie->data.pscan_rep_mode;
72 cp.pscan_mode = ie->data.pscan_mode;
73 cp.clock_offset = ie->data.clock_offset |
74 cpu_to_le16(0x8000);
75 }
76
1da177e4 77 memcpy(conn->dev_class, ie->data.dev_class, 3);
41a96212 78 conn->ssp_mode = ie->data.ssp_mode;
1da177e4
LT
79 }
80
a8746417 81 cp.pkt_type = cpu_to_le16(conn->pkt_type);
1da177e4 82 if (lmp_rswitch_capable(hdev) && !(hdev->link_mode & HCI_LM_MASTER))
b6a0dc82 83 cp.role_switch = 0x01;
1da177e4 84 else
b6a0dc82 85 cp.role_switch = 0x00;
4c67bc74 86
a9de9248 87 hci_send_cmd(hdev, HCI_OP_CREATE_CONN, sizeof(cp), &cp);
1da177e4
LT
88}
89
6ac59344
MH
90static void hci_acl_connect_cancel(struct hci_conn *conn)
91{
92 struct hci_cp_create_conn_cancel cp;
93
94 BT_DBG("%p", conn);
95
96 if (conn->hdev->hci_ver < 2)
97 return;
98
99 bacpy(&cp.bdaddr, &conn->dst);
a9de9248 100 hci_send_cmd(conn->hdev, HCI_OP_CREATE_CONN_CANCEL, sizeof(cp), &cp);
6ac59344
MH
101}
102
1da177e4
LT
103void hci_acl_disconn(struct hci_conn *conn, __u8 reason)
104{
105 struct hci_cp_disconnect cp;
106
107 BT_DBG("%p", conn);
108
109 conn->state = BT_DISCONN;
110
aca3192c 111 cp.handle = cpu_to_le16(conn->handle);
1da177e4 112 cp.reason = reason;
a9de9248 113 hci_send_cmd(conn->hdev, HCI_OP_DISCONNECT, sizeof(cp), &cp);
1da177e4
LT
114}
115
116void hci_add_sco(struct hci_conn *conn, __u16 handle)
117{
118 struct hci_dev *hdev = conn->hdev;
119 struct hci_cp_add_sco cp;
120
121 BT_DBG("%p", conn);
122
123 conn->state = BT_CONNECT;
124 conn->out = 1;
125
efc7688b
MH
126 conn->attempt++;
127
aca3192c 128 cp.handle = cpu_to_le16(handle);
a8746417 129 cp.pkt_type = cpu_to_le16(conn->pkt_type);
1da177e4 130
a9de9248 131 hci_send_cmd(hdev, HCI_OP_ADD_SCO, sizeof(cp), &cp);
1da177e4
LT
132}
133
b6a0dc82
MH
134void hci_setup_sync(struct hci_conn *conn, __u16 handle)
135{
136 struct hci_dev *hdev = conn->hdev;
137 struct hci_cp_setup_sync_conn cp;
138
139 BT_DBG("%p", conn);
140
141 conn->state = BT_CONNECT;
142 conn->out = 1;
143
efc7688b
MH
144 conn->attempt++;
145
b6a0dc82 146 cp.handle = cpu_to_le16(handle);
a8746417 147 cp.pkt_type = cpu_to_le16(conn->pkt_type);
b6a0dc82
MH
148
149 cp.tx_bandwidth = cpu_to_le32(0x00001f40);
150 cp.rx_bandwidth = cpu_to_le32(0x00001f40);
151 cp.max_latency = cpu_to_le16(0xffff);
152 cp.voice_setting = cpu_to_le16(hdev->voice_setting);
153 cp.retrans_effort = 0xff;
154
155 hci_send_cmd(hdev, HCI_OP_SETUP_SYNC_CONN, sizeof(cp), &cp);
156}
157
1da177e4
LT
158static void hci_conn_timeout(unsigned long arg)
159{
04837f64
MH
160 struct hci_conn *conn = (void *) arg;
161 struct hci_dev *hdev = conn->hdev;
2950f21a 162 __u8 reason;
1da177e4
LT
163
164 BT_DBG("conn %p state %d", conn, conn->state);
165
166 if (atomic_read(&conn->refcnt))
167 return;
168
169 hci_dev_lock(hdev);
6ac59344
MH
170
171 switch (conn->state) {
172 case BT_CONNECT:
769be974 173 case BT_CONNECT2:
b6a0dc82
MH
174 if (conn->type == ACL_LINK)
175 hci_acl_connect_cancel(conn);
176 else
177 hci_acl_disconn(conn, 0x13);
6ac59344 178 break;
769be974 179 case BT_CONFIG:
8e87d142 180 case BT_CONNECTED:
2950f21a
MH
181 reason = hci_proto_disconn_ind(conn);
182 hci_acl_disconn(conn, reason);
6ac59344
MH
183 break;
184 default:
1da177e4 185 conn->state = BT_CLOSED;
6ac59344
MH
186 break;
187 }
188
1da177e4 189 hci_dev_unlock(hdev);
1da177e4
LT
190}
191
04837f64 192static void hci_conn_idle(unsigned long arg)
1da177e4 193{
04837f64
MH
194 struct hci_conn *conn = (void *) arg;
195
196 BT_DBG("conn %p mode %d", conn, conn->mode);
197
198 hci_conn_enter_sniff_mode(conn);
1da177e4
LT
199}
200
201struct hci_conn *hci_conn_add(struct hci_dev *hdev, int type, bdaddr_t *dst)
202{
203 struct hci_conn *conn;
204
205 BT_DBG("%s dst %s", hdev->name, batostr(dst));
206
04837f64
MH
207 conn = kzalloc(sizeof(struct hci_conn), GFP_ATOMIC);
208 if (!conn)
1da177e4 209 return NULL;
1da177e4
LT
210
211 bacpy(&conn->dst, dst);
a8746417
MH
212 conn->hdev = hdev;
213 conn->type = type;
214 conn->mode = HCI_CM_ACTIVE;
215 conn->state = BT_OPEN;
1da177e4 216
04837f64
MH
217 conn->power_save = 1;
218
a8746417
MH
219 switch (type) {
220 case ACL_LINK:
221 conn->pkt_type = hdev->pkt_type & ACL_PTYPE_MASK;
222 break;
223 case SCO_LINK:
224 if (lmp_esco_capable(hdev))
efc7688b
MH
225 conn->pkt_type = (hdev->esco_type & SCO_ESCO_MASK) |
226 (hdev->esco_type & EDR_ESCO_MASK);
a8746417
MH
227 else
228 conn->pkt_type = hdev->pkt_type & SCO_PTYPE_MASK;
229 break;
230 case ESCO_LINK:
efc7688b 231 conn->pkt_type = hdev->esco_type & ~EDR_ESCO_MASK;
a8746417
MH
232 break;
233 }
234
1da177e4 235 skb_queue_head_init(&conn->data_q);
04837f64 236
b24b8a24
PE
237 setup_timer(&conn->disc_timer, hci_conn_timeout, (unsigned long)conn);
238 setup_timer(&conn->idle_timer, hci_conn_idle, (unsigned long)conn);
1da177e4
LT
239
240 atomic_set(&conn->refcnt, 0);
241
242 hci_dev_hold(hdev);
243
244 tasklet_disable(&hdev->tx_task);
245
246 hci_conn_hash_add(hdev, conn);
247 if (hdev->notify)
248 hdev->notify(hdev, HCI_NOTIFY_CONN_ADD);
249
250 tasklet_enable(&hdev->tx_task);
251
252 return conn;
253}
254
255int hci_conn_del(struct hci_conn *conn)
256{
257 struct hci_dev *hdev = conn->hdev;
258
259 BT_DBG("%s conn %p handle %d", hdev->name, conn, conn->handle);
260
04837f64
MH
261 del_timer(&conn->idle_timer);
262
263 del_timer(&conn->disc_timer);
1da177e4 264
5b7f9909 265 if (conn->type == ACL_LINK) {
1da177e4
LT
266 struct hci_conn *sco = conn->link;
267 if (sco)
268 sco->link = NULL;
269
270 /* Unacked frames */
271 hdev->acl_cnt += conn->sent;
5b7f9909
MH
272 } else {
273 struct hci_conn *acl = conn->link;
274 if (acl) {
275 acl->link = NULL;
276 hci_conn_put(acl);
277 }
1da177e4
LT
278 }
279
280 tasklet_disable(&hdev->tx_task);
7d0db0a3 281
1da177e4
LT
282 hci_conn_hash_del(hdev, conn);
283 if (hdev->notify)
284 hdev->notify(hdev, HCI_NOTIFY_CONN_DEL);
7d0db0a3 285
1da177e4 286 tasklet_enable(&hdev->tx_task);
7d0db0a3 287
1da177e4 288 skb_queue_purge(&conn->data_q);
1da177e4 289
1da177e4
LT
290 return 0;
291}
292
293struct hci_dev *hci_get_route(bdaddr_t *dst, bdaddr_t *src)
294{
295 int use_src = bacmp(src, BDADDR_ANY);
296 struct hci_dev *hdev = NULL;
297 struct list_head *p;
298
299 BT_DBG("%s -> %s", batostr(src), batostr(dst));
300
301 read_lock_bh(&hci_dev_list_lock);
302
303 list_for_each(p, &hci_dev_list) {
304 struct hci_dev *d = list_entry(p, struct hci_dev, list);
305
306 if (!test_bit(HCI_UP, &d->flags) || test_bit(HCI_RAW, &d->flags))
307 continue;
308
8e87d142 309 /* Simple routing:
1da177e4
LT
310 * No source address - find interface with bdaddr != dst
311 * Source address - find interface with bdaddr == src
312 */
313
314 if (use_src) {
315 if (!bacmp(&d->bdaddr, src)) {
316 hdev = d; break;
317 }
318 } else {
319 if (bacmp(&d->bdaddr, dst)) {
320 hdev = d; break;
321 }
322 }
323 }
324
325 if (hdev)
326 hdev = hci_dev_hold(hdev);
327
328 read_unlock_bh(&hci_dev_list_lock);
329 return hdev;
330}
331EXPORT_SYMBOL(hci_get_route);
332
333/* Create SCO or ACL connection.
334 * Device _must_ be locked */
8c1b2355 335struct hci_conn *hci_connect(struct hci_dev *hdev, int type, bdaddr_t *dst, __u8 sec_level, __u8 auth_type)
1da177e4
LT
336{
337 struct hci_conn *acl;
5b7f9909 338 struct hci_conn *sco;
1da177e4
LT
339
340 BT_DBG("%s dst %s", hdev->name, batostr(dst));
341
342 if (!(acl = hci_conn_hash_lookup_ba(hdev, ACL_LINK, dst))) {
343 if (!(acl = hci_conn_add(hdev, ACL_LINK, dst)))
344 return NULL;
345 }
346
347 hci_conn_hold(acl);
348
09ab6f4c 349 if (acl->state == BT_OPEN || acl->state == BT_CLOSED) {
8c1b2355 350 acl->sec_level = sec_level;
09ab6f4c 351 acl->auth_type = auth_type;
1da177e4 352 hci_acl_connect(acl);
09ab6f4c 353 }
1da177e4 354
5b7f9909
MH
355 if (type == ACL_LINK)
356 return acl;
1da177e4 357
5b7f9909
MH
358 if (!(sco = hci_conn_hash_lookup_ba(hdev, type, dst))) {
359 if (!(sco = hci_conn_add(hdev, type, dst))) {
360 hci_conn_put(acl);
361 return NULL;
1da177e4 362 }
5b7f9909 363 }
1da177e4 364
5b7f9909
MH
365 acl->link = sco;
366 sco->link = acl;
1da177e4 367
5b7f9909 368 hci_conn_hold(sco);
1da177e4 369
5b7f9909 370 if (acl->state == BT_CONNECTED &&
b6a0dc82
MH
371 (sco->state == BT_OPEN || sco->state == BT_CLOSED)) {
372 if (lmp_esco_capable(hdev))
373 hci_setup_sync(sco, acl->handle);
374 else
375 hci_add_sco(sco, acl->handle);
376 }
5b7f9909
MH
377
378 return sco;
1da177e4
LT
379}
380EXPORT_SYMBOL(hci_connect);
381
e7c29cb1
MH
382/* Check link security requirement */
383int hci_conn_check_link_mode(struct hci_conn *conn)
384{
385 BT_DBG("conn %p", conn);
386
387 if (conn->ssp_mode > 0 && conn->hdev->ssp_mode > 0 &&
388 !(conn->link_mode & HCI_LM_ENCRYPT))
389 return 0;
390
391 return 1;
392}
393EXPORT_SYMBOL(hci_conn_check_link_mode);
394
1da177e4 395/* Authenticate remote device */
0684e5f9 396static int hci_conn_auth(struct hci_conn *conn, __u8 sec_level, __u8 auth_type)
1da177e4
LT
397{
398 BT_DBG("conn %p", conn);
399
96a31833 400 if (sec_level > conn->sec_level)
0684e5f9 401 conn->sec_level = sec_level;
96a31833 402 else if (conn->link_mode & HCI_LM_AUTH)
1da177e4
LT
403 return 1;
404
96a31833
MH
405 conn->auth_type = auth_type;
406
1da177e4
LT
407 if (!test_and_set_bit(HCI_CONN_AUTH_PEND, &conn->pend)) {
408 struct hci_cp_auth_requested cp;
aca3192c 409 cp.handle = cpu_to_le16(conn->handle);
40be492f
MH
410 hci_send_cmd(conn->hdev, HCI_OP_AUTH_REQUESTED,
411 sizeof(cp), &cp);
1da177e4 412 }
8c1b2355 413
1da177e4
LT
414 return 0;
415}
1da177e4 416
8c1b2355 417/* Enable security */
0684e5f9 418int hci_conn_security(struct hci_conn *conn, __u8 sec_level, __u8 auth_type)
1da177e4
LT
419{
420 BT_DBG("conn %p", conn);
421
8c1b2355
MH
422 if (sec_level == BT_SECURITY_SDP)
423 return 1;
424
425 if (sec_level == BT_SECURITY_LOW) {
426 if (conn->ssp_mode > 0 && conn->hdev->ssp_mode > 0)
0684e5f9 427 return hci_conn_auth(conn, sec_level, auth_type);
8c1b2355
MH
428 else
429 return 1;
430 }
431
1da177e4 432 if (conn->link_mode & HCI_LM_ENCRYPT)
0684e5f9 433 return hci_conn_auth(conn, sec_level, auth_type);
1da177e4
LT
434
435 if (test_and_set_bit(HCI_CONN_ENCRYPT_PEND, &conn->pend))
436 return 0;
437
0684e5f9 438 if (hci_conn_auth(conn, sec_level, auth_type)) {
1da177e4 439 struct hci_cp_set_conn_encrypt cp;
aca3192c 440 cp.handle = cpu_to_le16(conn->handle);
8e87d142 441 cp.encrypt = 1;
40be492f
MH
442 hci_send_cmd(conn->hdev, HCI_OP_SET_CONN_ENCRYPT,
443 sizeof(cp), &cp);
1da177e4 444 }
8c1b2355 445
1da177e4
LT
446 return 0;
447}
8c1b2355 448EXPORT_SYMBOL(hci_conn_security);
1da177e4
LT
449
450/* Change link key */
451int hci_conn_change_link_key(struct hci_conn *conn)
452{
453 BT_DBG("conn %p", conn);
454
455 if (!test_and_set_bit(HCI_CONN_AUTH_PEND, &conn->pend)) {
456 struct hci_cp_change_conn_link_key cp;
aca3192c 457 cp.handle = cpu_to_le16(conn->handle);
40be492f
MH
458 hci_send_cmd(conn->hdev, HCI_OP_CHANGE_CONN_LINK_KEY,
459 sizeof(cp), &cp);
1da177e4 460 }
8c1b2355 461
1da177e4
LT
462 return 0;
463}
464EXPORT_SYMBOL(hci_conn_change_link_key);
465
466/* Switch role */
8c1b2355 467int hci_conn_switch_role(struct hci_conn *conn, __u8 role)
1da177e4
LT
468{
469 BT_DBG("conn %p", conn);
470
471 if (!role && conn->link_mode & HCI_LM_MASTER)
472 return 1;
473
474 if (!test_and_set_bit(HCI_CONN_RSWITCH_PEND, &conn->pend)) {
475 struct hci_cp_switch_role cp;
476 bacpy(&cp.bdaddr, &conn->dst);
477 cp.role = role;
a9de9248 478 hci_send_cmd(conn->hdev, HCI_OP_SWITCH_ROLE, sizeof(cp), &cp);
1da177e4 479 }
8c1b2355 480
1da177e4
LT
481 return 0;
482}
483EXPORT_SYMBOL(hci_conn_switch_role);
484
04837f64
MH
485/* Enter active mode */
486void hci_conn_enter_active_mode(struct hci_conn *conn)
487{
488 struct hci_dev *hdev = conn->hdev;
489
490 BT_DBG("conn %p mode %d", conn, conn->mode);
491
492 if (test_bit(HCI_RAW, &hdev->flags))
493 return;
494
495 if (conn->mode != HCI_CM_SNIFF || !conn->power_save)
496 goto timer;
497
498 if (!test_and_set_bit(HCI_CONN_MODE_CHANGE_PEND, &conn->pend)) {
499 struct hci_cp_exit_sniff_mode cp;
aca3192c 500 cp.handle = cpu_to_le16(conn->handle);
a9de9248 501 hci_send_cmd(hdev, HCI_OP_EXIT_SNIFF_MODE, sizeof(cp), &cp);
04837f64
MH
502 }
503
504timer:
505 if (hdev->idle_timeout > 0)
506 mod_timer(&conn->idle_timer,
507 jiffies + msecs_to_jiffies(hdev->idle_timeout));
508}
509
510/* Enter sniff mode */
511void hci_conn_enter_sniff_mode(struct hci_conn *conn)
512{
513 struct hci_dev *hdev = conn->hdev;
514
515 BT_DBG("conn %p mode %d", conn, conn->mode);
516
517 if (test_bit(HCI_RAW, &hdev->flags))
518 return;
519
520 if (!lmp_sniff_capable(hdev) || !lmp_sniff_capable(conn))
521 return;
522
523 if (conn->mode != HCI_CM_ACTIVE || !(conn->link_policy & HCI_LP_SNIFF))
524 return;
525
526 if (lmp_sniffsubr_capable(hdev) && lmp_sniffsubr_capable(conn)) {
527 struct hci_cp_sniff_subrate cp;
aca3192c
YH
528 cp.handle = cpu_to_le16(conn->handle);
529 cp.max_latency = cpu_to_le16(0);
530 cp.min_remote_timeout = cpu_to_le16(0);
531 cp.min_local_timeout = cpu_to_le16(0);
a9de9248 532 hci_send_cmd(hdev, HCI_OP_SNIFF_SUBRATE, sizeof(cp), &cp);
04837f64
MH
533 }
534
535 if (!test_and_set_bit(HCI_CONN_MODE_CHANGE_PEND, &conn->pend)) {
536 struct hci_cp_sniff_mode cp;
aca3192c
YH
537 cp.handle = cpu_to_le16(conn->handle);
538 cp.max_interval = cpu_to_le16(hdev->sniff_max_interval);
539 cp.min_interval = cpu_to_le16(hdev->sniff_min_interval);
540 cp.attempt = cpu_to_le16(4);
541 cp.timeout = cpu_to_le16(1);
a9de9248 542 hci_send_cmd(hdev, HCI_OP_SNIFF_MODE, sizeof(cp), &cp);
04837f64
MH
543 }
544}
545
1da177e4
LT
546/* Drop all connection on the device */
547void hci_conn_hash_flush(struct hci_dev *hdev)
548{
549 struct hci_conn_hash *h = &hdev->conn_hash;
550 struct list_head *p;
551
552 BT_DBG("hdev %s", hdev->name);
553
554 p = h->list.next;
555 while (p != &h->list) {
556 struct hci_conn *c;
557
558 c = list_entry(p, struct hci_conn, list);
559 p = p->next;
560
561 c->state = BT_CLOSED;
562
7d0db0a3
MH
563 hci_conn_del_sysfs(c);
564
2950f21a 565 hci_proto_disconn_cfm(c, 0x16);
1da177e4
LT
566 hci_conn_del(c);
567 }
568}
569
a9de9248
MH
570/* Check pending connect attempts */
571void hci_conn_check_pending(struct hci_dev *hdev)
572{
573 struct hci_conn *conn;
574
575 BT_DBG("hdev %s", hdev->name);
576
577 hci_dev_lock(hdev);
578
579 conn = hci_conn_hash_lookup_state(hdev, ACL_LINK, BT_CONNECT2);
580 if (conn)
581 hci_acl_connect(conn);
582
583 hci_dev_unlock(hdev);
584}
585
1da177e4
LT
586int hci_get_conn_list(void __user *arg)
587{
588 struct hci_conn_list_req req, *cl;
589 struct hci_conn_info *ci;
590 struct hci_dev *hdev;
591 struct list_head *p;
592 int n = 0, size, err;
593
594 if (copy_from_user(&req, arg, sizeof(req)))
595 return -EFAULT;
596
597 if (!req.conn_num || req.conn_num > (PAGE_SIZE * 2) / sizeof(*ci))
598 return -EINVAL;
599
600 size = sizeof(req) + req.conn_num * sizeof(*ci);
601
12fe2c58 602 if (!(cl = kmalloc(size, GFP_KERNEL)))
1da177e4
LT
603 return -ENOMEM;
604
605 if (!(hdev = hci_dev_get(req.dev_id))) {
606 kfree(cl);
607 return -ENODEV;
608 }
609
610 ci = cl->conn_info;
611
612 hci_dev_lock_bh(hdev);
613 list_for_each(p, &hdev->conn_hash.list) {
614 register struct hci_conn *c;
615 c = list_entry(p, struct hci_conn, list);
616
617 bacpy(&(ci + n)->bdaddr, &c->dst);
618 (ci + n)->handle = c->handle;
619 (ci + n)->type = c->type;
620 (ci + n)->out = c->out;
621 (ci + n)->state = c->state;
622 (ci + n)->link_mode = c->link_mode;
623 if (++n >= req.conn_num)
624 break;
625 }
626 hci_dev_unlock_bh(hdev);
627
628 cl->dev_id = hdev->id;
629 cl->conn_num = n;
630 size = sizeof(req) + n * sizeof(*ci);
631
632 hci_dev_put(hdev);
633
634 err = copy_to_user(arg, cl, size);
635 kfree(cl);
636
637 return err ? -EFAULT : 0;
638}
639
640int hci_get_conn_info(struct hci_dev *hdev, void __user *arg)
641{
642 struct hci_conn_info_req req;
643 struct hci_conn_info ci;
644 struct hci_conn *conn;
645 char __user *ptr = arg + sizeof(req);
646
647 if (copy_from_user(&req, arg, sizeof(req)))
648 return -EFAULT;
649
650 hci_dev_lock_bh(hdev);
651 conn = hci_conn_hash_lookup_ba(hdev, req.type, &req.bdaddr);
652 if (conn) {
653 bacpy(&ci.bdaddr, &conn->dst);
654 ci.handle = conn->handle;
655 ci.type = conn->type;
656 ci.out = conn->out;
657 ci.state = conn->state;
658 ci.link_mode = conn->link_mode;
659 }
660 hci_dev_unlock_bh(hdev);
661
662 if (!conn)
663 return -ENOENT;
664
665 return copy_to_user(ptr, &ci, sizeof(ci)) ? -EFAULT : 0;
666}
40be492f
MH
667
668int hci_get_auth_info(struct hci_dev *hdev, void __user *arg)
669{
670 struct hci_auth_info_req req;
671 struct hci_conn *conn;
672
673 if (copy_from_user(&req, arg, sizeof(req)))
674 return -EFAULT;
675
676 hci_dev_lock_bh(hdev);
677 conn = hci_conn_hash_lookup_ba(hdev, ACL_LINK, &req.bdaddr);
678 if (conn)
679 req.type = conn->auth_type;
680 hci_dev_unlock_bh(hdev);
681
682 if (!conn)
683 return -ENOENT;
684
685 return copy_to_user(arg, &req, sizeof(req)) ? -EFAULT : 0;
686}