]> git.proxmox.com Git - mirror_ubuntu-bionic-kernel.git/blame - net/bluetooth/hci_core.c
Merge git://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf
[mirror_ubuntu-bionic-kernel.git] / net / bluetooth / hci_core.c
CommitLineData
8e87d142 1/*
1da177e4
LT
2 BlueZ - Bluetooth protocol stack for Linux
3 Copyright (C) 2000-2001 Qualcomm Incorporated
590051de 4 Copyright (C) 2011 ProFUSION Embedded Systems
1da177e4
LT
5
6 Written 2000,2001 by Maxim Krasnyansky <maxk@qualcomm.com>
7
8 This program is free software; you can redistribute it and/or modify
9 it under the terms of the GNU General Public License version 2 as
10 published by the Free Software Foundation;
11
12 THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS
13 OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
14 FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT OF THIRD PARTY RIGHTS.
15 IN NO EVENT SHALL THE COPYRIGHT HOLDER(S) AND AUTHOR(S) BE LIABLE FOR ANY
8e87d142
YH
16 CLAIM, OR ANY SPECIAL INDIRECT OR CONSEQUENTIAL DAMAGES, OR ANY DAMAGES
17 WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
18 ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
1da177e4
LT
19 OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
20
8e87d142
YH
21 ALL LIABILITY, INCLUDING LIABILITY FOR INFRINGEMENT OF ANY PATENTS,
22 COPYRIGHTS, TRADEMARKS OR OTHER RIGHTS, RELATING TO USE OF THIS
1da177e4
LT
23 SOFTWARE IS DISCLAIMED.
24*/
25
26/* Bluetooth HCI core. */
27
8c520a59 28#include <linux/export.h>
3df92b31 29#include <linux/idr.h>
8c520a59 30#include <linux/rfkill.h>
baf27f6e 31#include <linux/debugfs.h>
99780a7b 32#include <linux/crypto.h>
47219839 33#include <asm/unaligned.h>
1da177e4
LT
34
35#include <net/bluetooth/bluetooth.h>
36#include <net/bluetooth/hci_core.h>
4bc58f51 37#include <net/bluetooth/l2cap.h>
af58925c 38#include <net/bluetooth/mgmt.h>
1da177e4 39
0857dd3b 40#include "hci_request.h"
60c5f5fb 41#include "hci_debugfs.h"
970c4e46 42#include "smp.h"
6d5d2ee6 43#include "leds.h"
970c4e46 44
b78752cc 45static void hci_rx_work(struct work_struct *work);
c347b765 46static void hci_cmd_work(struct work_struct *work);
3eff45ea 47static void hci_tx_work(struct work_struct *work);
1da177e4 48
1da177e4
LT
49/* HCI device list */
50LIST_HEAD(hci_dev_list);
51DEFINE_RWLOCK(hci_dev_list_lock);
52
53/* HCI callback list */
54LIST_HEAD(hci_cb_list);
fba7ecf0 55DEFINE_MUTEX(hci_cb_list_lock);
1da177e4 56
3df92b31
SL
57/* HCI ID Numbering */
58static DEFINE_IDA(hci_index_ida);
59
baf27f6e
MH
60/* ---- HCI debugfs entries ---- */
61
4b4148e9
MH
62static ssize_t dut_mode_read(struct file *file, char __user *user_buf,
63 size_t count, loff_t *ppos)
64{
65 struct hci_dev *hdev = file->private_data;
66 char buf[3];
67
74b93e9f 68 buf[0] = hci_dev_test_flag(hdev, HCI_DUT_MODE) ? 'Y' : 'N';
4b4148e9
MH
69 buf[1] = '\n';
70 buf[2] = '\0';
71 return simple_read_from_buffer(user_buf, count, ppos, buf, 2);
72}
73
74static ssize_t dut_mode_write(struct file *file, const char __user *user_buf,
75 size_t count, loff_t *ppos)
76{
77 struct hci_dev *hdev = file->private_data;
78 struct sk_buff *skb;
79 char buf[32];
80 size_t buf_size = min(count, (sizeof(buf)-1));
81 bool enable;
4b4148e9
MH
82
83 if (!test_bit(HCI_UP, &hdev->flags))
84 return -ENETDOWN;
85
86 if (copy_from_user(buf, user_buf, buf_size))
87 return -EFAULT;
88
89 buf[buf_size] = '\0';
90 if (strtobool(buf, &enable))
91 return -EINVAL;
92
b7cb93e5 93 if (enable == hci_dev_test_flag(hdev, HCI_DUT_MODE))
4b4148e9
MH
94 return -EALREADY;
95
b504430c 96 hci_req_sync_lock(hdev);
4b4148e9
MH
97 if (enable)
98 skb = __hci_cmd_sync(hdev, HCI_OP_ENABLE_DUT_MODE, 0, NULL,
99 HCI_CMD_TIMEOUT);
100 else
101 skb = __hci_cmd_sync(hdev, HCI_OP_RESET, 0, NULL,
102 HCI_CMD_TIMEOUT);
b504430c 103 hci_req_sync_unlock(hdev);
4b4148e9
MH
104
105 if (IS_ERR(skb))
106 return PTR_ERR(skb);
107
4b4148e9
MH
108 kfree_skb(skb);
109
b7cb93e5 110 hci_dev_change_flag(hdev, HCI_DUT_MODE);
4b4148e9
MH
111
112 return count;
113}
114
115static const struct file_operations dut_mode_fops = {
116 .open = simple_open,
117 .read = dut_mode_read,
118 .write = dut_mode_write,
119 .llseek = default_llseek,
120};
121
4b4113d6
MH
122static ssize_t vendor_diag_read(struct file *file, char __user *user_buf,
123 size_t count, loff_t *ppos)
124{
125 struct hci_dev *hdev = file->private_data;
126 char buf[3];
127
74b93e9f 128 buf[0] = hci_dev_test_flag(hdev, HCI_VENDOR_DIAG) ? 'Y' : 'N';
4b4113d6
MH
129 buf[1] = '\n';
130 buf[2] = '\0';
131 return simple_read_from_buffer(user_buf, count, ppos, buf, 2);
132}
133
134static ssize_t vendor_diag_write(struct file *file, const char __user *user_buf,
135 size_t count, loff_t *ppos)
136{
137 struct hci_dev *hdev = file->private_data;
138 char buf[32];
139 size_t buf_size = min(count, (sizeof(buf)-1));
140 bool enable;
141 int err;
142
143 if (copy_from_user(buf, user_buf, buf_size))
144 return -EFAULT;
145
146 buf[buf_size] = '\0';
147 if (strtobool(buf, &enable))
148 return -EINVAL;
149
7e995b9e 150 /* When the diagnostic flags are not persistent and the transport
b56c7b25
MH
151 * is not active or in user channel operation, then there is no need
152 * for the vendor callback. Instead just store the desired value and
153 * the setting will be programmed when the controller gets powered on.
7e995b9e
MH
154 */
155 if (test_bit(HCI_QUIRK_NON_PERSISTENT_DIAG, &hdev->quirks) &&
b56c7b25
MH
156 (!test_bit(HCI_RUNNING, &hdev->flags) ||
157 hci_dev_test_flag(hdev, HCI_USER_CHANNEL)))
7e995b9e
MH
158 goto done;
159
b504430c 160 hci_req_sync_lock(hdev);
4b4113d6 161 err = hdev->set_diag(hdev, enable);
b504430c 162 hci_req_sync_unlock(hdev);
4b4113d6
MH
163
164 if (err < 0)
165 return err;
166
7e995b9e 167done:
4b4113d6
MH
168 if (enable)
169 hci_dev_set_flag(hdev, HCI_VENDOR_DIAG);
170 else
171 hci_dev_clear_flag(hdev, HCI_VENDOR_DIAG);
172
173 return count;
174}
175
176static const struct file_operations vendor_diag_fops = {
177 .open = simple_open,
178 .read = vendor_diag_read,
179 .write = vendor_diag_write,
180 .llseek = default_llseek,
181};
182
f640ee98
MH
183static void hci_debugfs_create_basic(struct hci_dev *hdev)
184{
185 debugfs_create_file("dut_mode", 0644, hdev->debugfs, hdev,
186 &dut_mode_fops);
187
188 if (hdev->set_diag)
189 debugfs_create_file("vendor_diag", 0644, hdev->debugfs, hdev,
190 &vendor_diag_fops);
191}
192
a1d01db1 193static int hci_reset_req(struct hci_request *req, unsigned long opt)
1da177e4 194{
42c6b129 195 BT_DBG("%s %ld", req->hdev->name, opt);
1da177e4
LT
196
197 /* Reset device */
42c6b129
JH
198 set_bit(HCI_RESET, &req->hdev->flags);
199 hci_req_add(req, HCI_OP_RESET, 0, NULL);
a1d01db1 200 return 0;
1da177e4
LT
201}
202
42c6b129 203static void bredr_init(struct hci_request *req)
1da177e4 204{
42c6b129 205 req->hdev->flow_ctl_mode = HCI_FLOW_CTL_MODE_PACKET_BASED;
2455a3ea 206
1da177e4 207 /* Read Local Supported Features */
42c6b129 208 hci_req_add(req, HCI_OP_READ_LOCAL_FEATURES, 0, NULL);
1da177e4 209
1143e5a6 210 /* Read Local Version */
42c6b129 211 hci_req_add(req, HCI_OP_READ_LOCAL_VERSION, 0, NULL);
2177bab5
JH
212
213 /* Read BD Address */
42c6b129 214 hci_req_add(req, HCI_OP_READ_BD_ADDR, 0, NULL);
1da177e4
LT
215}
216
0af801b9 217static void amp_init1(struct hci_request *req)
e61ef499 218{
42c6b129 219 req->hdev->flow_ctl_mode = HCI_FLOW_CTL_MODE_BLOCK_BASED;
2455a3ea 220
e61ef499 221 /* Read Local Version */
42c6b129 222 hci_req_add(req, HCI_OP_READ_LOCAL_VERSION, 0, NULL);
6bcbc489 223
f6996cfe
MH
224 /* Read Local Supported Commands */
225 hci_req_add(req, HCI_OP_READ_LOCAL_COMMANDS, 0, NULL);
226
6bcbc489 227 /* Read Local AMP Info */
42c6b129 228 hci_req_add(req, HCI_OP_READ_LOCAL_AMP_INFO, 0, NULL);
e71dfaba
AE
229
230 /* Read Data Blk size */
42c6b129 231 hci_req_add(req, HCI_OP_READ_DATA_BLOCK_SIZE, 0, NULL);
7528ca1c 232
f38ba941
MH
233 /* Read Flow Control Mode */
234 hci_req_add(req, HCI_OP_READ_FLOW_CONTROL_MODE, 0, NULL);
235
7528ca1c
MH
236 /* Read Location Data */
237 hci_req_add(req, HCI_OP_READ_LOCATION_DATA, 0, NULL);
e61ef499
AE
238}
239
a1d01db1 240static int amp_init2(struct hci_request *req)
0af801b9
JH
241{
242 /* Read Local Supported Features. Not all AMP controllers
243 * support this so it's placed conditionally in the second
244 * stage init.
245 */
246 if (req->hdev->commands[14] & 0x20)
247 hci_req_add(req, HCI_OP_READ_LOCAL_FEATURES, 0, NULL);
a1d01db1
JH
248
249 return 0;
0af801b9
JH
250}
251
a1d01db1 252static int hci_init1_req(struct hci_request *req, unsigned long opt)
e61ef499 253{
42c6b129 254 struct hci_dev *hdev = req->hdev;
e61ef499
AE
255
256 BT_DBG("%s %ld", hdev->name, opt);
257
11778716
AE
258 /* Reset */
259 if (!test_bit(HCI_QUIRK_RESET_ON_CLOSE, &hdev->quirks))
42c6b129 260 hci_reset_req(req, 0);
11778716 261
e61ef499 262 switch (hdev->dev_type) {
ca8bee5d 263 case HCI_PRIMARY:
42c6b129 264 bredr_init(req);
e61ef499 265 break;
e61ef499 266 case HCI_AMP:
0af801b9 267 amp_init1(req);
e61ef499 268 break;
e61ef499 269 default:
2064ee33 270 bt_dev_err(hdev, "Unknown device type %d", hdev->dev_type);
e61ef499
AE
271 break;
272 }
a1d01db1
JH
273
274 return 0;
e61ef499
AE
275}
276
42c6b129 277static void bredr_setup(struct hci_request *req)
2177bab5 278{
2177bab5
JH
279 __le16 param;
280 __u8 flt_type;
281
282 /* Read Buffer Size (ACL mtu, max pkt, etc.) */
42c6b129 283 hci_req_add(req, HCI_OP_READ_BUFFER_SIZE, 0, NULL);
2177bab5
JH
284
285 /* Read Class of Device */
42c6b129 286 hci_req_add(req, HCI_OP_READ_CLASS_OF_DEV, 0, NULL);
2177bab5
JH
287
288 /* Read Local Name */
42c6b129 289 hci_req_add(req, HCI_OP_READ_LOCAL_NAME, 0, NULL);
2177bab5
JH
290
291 /* Read Voice Setting */
42c6b129 292 hci_req_add(req, HCI_OP_READ_VOICE_SETTING, 0, NULL);
2177bab5 293
b4cb9fb2
MH
294 /* Read Number of Supported IAC */
295 hci_req_add(req, HCI_OP_READ_NUM_SUPPORTED_IAC, 0, NULL);
296
4b836f39
MH
297 /* Read Current IAC LAP */
298 hci_req_add(req, HCI_OP_READ_CURRENT_IAC_LAP, 0, NULL);
299
2177bab5
JH
300 /* Clear Event Filters */
301 flt_type = HCI_FLT_CLEAR_ALL;
42c6b129 302 hci_req_add(req, HCI_OP_SET_EVENT_FLT, 1, &flt_type);
2177bab5
JH
303
304 /* Connection accept timeout ~20 secs */
dcf4adbf 305 param = cpu_to_le16(0x7d00);
42c6b129 306 hci_req_add(req, HCI_OP_WRITE_CA_TIMEOUT, 2, &param);
2177bab5
JH
307}
308
42c6b129 309static void le_setup(struct hci_request *req)
2177bab5 310{
c73eee91
JH
311 struct hci_dev *hdev = req->hdev;
312
2177bab5 313 /* Read LE Buffer Size */
42c6b129 314 hci_req_add(req, HCI_OP_LE_READ_BUFFER_SIZE, 0, NULL);
2177bab5
JH
315
316 /* Read LE Local Supported Features */
42c6b129 317 hci_req_add(req, HCI_OP_LE_READ_LOCAL_FEATURES, 0, NULL);
2177bab5 318
747d3f03
MH
319 /* Read LE Supported States */
320 hci_req_add(req, HCI_OP_LE_READ_SUPPORTED_STATES, 0, NULL);
321
c73eee91
JH
322 /* LE-only controllers have LE implicitly enabled */
323 if (!lmp_bredr_capable(hdev))
a1536da2 324 hci_dev_set_flag(hdev, HCI_LE_ENABLED);
2177bab5
JH
325}
326
42c6b129 327static void hci_setup_event_mask(struct hci_request *req)
2177bab5 328{
42c6b129
JH
329 struct hci_dev *hdev = req->hdev;
330
2177bab5
JH
331 /* The second byte is 0xff instead of 0x9f (two reserved bits
332 * disabled) since a Broadcom 1.2 dongle doesn't respond to the
333 * command otherwise.
334 */
335 u8 events[8] = { 0xff, 0xff, 0xfb, 0xff, 0x00, 0x00, 0x00, 0x00 };
336
337 /* CSR 1.1 dongles does not accept any bitfield so don't try to set
338 * any event mask for pre 1.2 devices.
339 */
340 if (hdev->hci_ver < BLUETOOTH_VER_1_2)
341 return;
342
343 if (lmp_bredr_capable(hdev)) {
344 events[4] |= 0x01; /* Flow Specification Complete */
c7882cbd
MH
345 } else {
346 /* Use a different default for LE-only devices */
347 memset(events, 0, sizeof(events));
c7882cbd
MH
348 events[1] |= 0x20; /* Command Complete */
349 events[1] |= 0x40; /* Command Status */
350 events[1] |= 0x80; /* Hardware Error */
5c3d3b4c
MH
351
352 /* If the controller supports the Disconnect command, enable
353 * the corresponding event. In addition enable packet flow
354 * control related events.
355 */
356 if (hdev->commands[0] & 0x20) {
357 events[0] |= 0x10; /* Disconnection Complete */
358 events[2] |= 0x04; /* Number of Completed Packets */
359 events[3] |= 0x02; /* Data Buffer Overflow */
360 }
361
362 /* If the controller supports the Read Remote Version
363 * Information command, enable the corresponding event.
364 */
365 if (hdev->commands[2] & 0x80)
366 events[1] |= 0x08; /* Read Remote Version Information
367 * Complete
368 */
0da71f1b
MH
369
370 if (hdev->le_features[0] & HCI_LE_ENCRYPTION) {
371 events[0] |= 0x80; /* Encryption Change */
372 events[5] |= 0x80; /* Encryption Key Refresh Complete */
373 }
2177bab5
JH
374 }
375
9fe759ce
MH
376 if (lmp_inq_rssi_capable(hdev) ||
377 test_bit(HCI_QUIRK_FIXUP_INQUIRY_MODE, &hdev->quirks))
2177bab5
JH
378 events[4] |= 0x02; /* Inquiry Result with RSSI */
379
70f56aa2
MH
380 if (lmp_ext_feat_capable(hdev))
381 events[4] |= 0x04; /* Read Remote Extended Features Complete */
382
383 if (lmp_esco_capable(hdev)) {
384 events[5] |= 0x08; /* Synchronous Connection Complete */
385 events[5] |= 0x10; /* Synchronous Connection Changed */
386 }
387
2177bab5
JH
388 if (lmp_sniffsubr_capable(hdev))
389 events[5] |= 0x20; /* Sniff Subrating */
390
391 if (lmp_pause_enc_capable(hdev))
392 events[5] |= 0x80; /* Encryption Key Refresh Complete */
393
394 if (lmp_ext_inq_capable(hdev))
395 events[5] |= 0x40; /* Extended Inquiry Result */
396
397 if (lmp_no_flush_capable(hdev))
398 events[7] |= 0x01; /* Enhanced Flush Complete */
399
400 if (lmp_lsto_capable(hdev))
401 events[6] |= 0x80; /* Link Supervision Timeout Changed */
402
403 if (lmp_ssp_capable(hdev)) {
404 events[6] |= 0x01; /* IO Capability Request */
405 events[6] |= 0x02; /* IO Capability Response */
406 events[6] |= 0x04; /* User Confirmation Request */
407 events[6] |= 0x08; /* User Passkey Request */
408 events[6] |= 0x10; /* Remote OOB Data Request */
409 events[6] |= 0x20; /* Simple Pairing Complete */
410 events[7] |= 0x04; /* User Passkey Notification */
411 events[7] |= 0x08; /* Keypress Notification */
412 events[7] |= 0x10; /* Remote Host Supported
413 * Features Notification
414 */
415 }
416
417 if (lmp_le_capable(hdev))
418 events[7] |= 0x20; /* LE Meta-Event */
419
42c6b129 420 hci_req_add(req, HCI_OP_SET_EVENT_MASK, sizeof(events), events);
2177bab5
JH
421}
422
a1d01db1 423static int hci_init2_req(struct hci_request *req, unsigned long opt)
2177bab5 424{
42c6b129
JH
425 struct hci_dev *hdev = req->hdev;
426
0af801b9
JH
427 if (hdev->dev_type == HCI_AMP)
428 return amp_init2(req);
429
2177bab5 430 if (lmp_bredr_capable(hdev))
42c6b129 431 bredr_setup(req);
56f87901 432 else
a358dc11 433 hci_dev_clear_flag(hdev, HCI_BREDR_ENABLED);
2177bab5
JH
434
435 if (lmp_le_capable(hdev))
42c6b129 436 le_setup(req);
2177bab5 437
0f3adeae
MH
438 /* All Bluetooth 1.2 and later controllers should support the
439 * HCI command for reading the local supported commands.
440 *
441 * Unfortunately some controllers indicate Bluetooth 1.2 support,
442 * but do not have support for this command. If that is the case,
443 * the driver can quirk the behavior and skip reading the local
444 * supported commands.
3f8e2d75 445 */
0f3adeae
MH
446 if (hdev->hci_ver > BLUETOOTH_VER_1_1 &&
447 !test_bit(HCI_QUIRK_BROKEN_LOCAL_COMMANDS, &hdev->quirks))
42c6b129 448 hci_req_add(req, HCI_OP_READ_LOCAL_COMMANDS, 0, NULL);
2177bab5
JH
449
450 if (lmp_ssp_capable(hdev)) {
57af75a8
MH
451 /* When SSP is available, then the host features page
452 * should also be available as well. However some
453 * controllers list the max_page as 0 as long as SSP
454 * has not been enabled. To achieve proper debugging
455 * output, force the minimum max_page to 1 at least.
456 */
457 hdev->max_page = 0x01;
458
d7a5a11d 459 if (hci_dev_test_flag(hdev, HCI_SSP_ENABLED)) {
2177bab5 460 u8 mode = 0x01;
574ea3c7 461
42c6b129
JH
462 hci_req_add(req, HCI_OP_WRITE_SSP_MODE,
463 sizeof(mode), &mode);
2177bab5
JH
464 } else {
465 struct hci_cp_write_eir cp;
466
467 memset(hdev->eir, 0, sizeof(hdev->eir));
468 memset(&cp, 0, sizeof(cp));
469
42c6b129 470 hci_req_add(req, HCI_OP_WRITE_EIR, sizeof(cp), &cp);
2177bab5
JH
471 }
472 }
473
043ec9bf
MH
474 if (lmp_inq_rssi_capable(hdev) ||
475 test_bit(HCI_QUIRK_FIXUP_INQUIRY_MODE, &hdev->quirks)) {
04422da9
MH
476 u8 mode;
477
478 /* If Extended Inquiry Result events are supported, then
479 * they are clearly preferred over Inquiry Result with RSSI
480 * events.
481 */
482 mode = lmp_ext_inq_capable(hdev) ? 0x02 : 0x01;
483
484 hci_req_add(req, HCI_OP_WRITE_INQUIRY_MODE, 1, &mode);
485 }
2177bab5
JH
486
487 if (lmp_inq_tx_pwr_capable(hdev))
42c6b129 488 hci_req_add(req, HCI_OP_READ_INQ_RSP_TX_POWER, 0, NULL);
2177bab5
JH
489
490 if (lmp_ext_feat_capable(hdev)) {
491 struct hci_cp_read_local_ext_features cp;
492
493 cp.page = 0x01;
42c6b129
JH
494 hci_req_add(req, HCI_OP_READ_LOCAL_EXT_FEATURES,
495 sizeof(cp), &cp);
2177bab5
JH
496 }
497
d7a5a11d 498 if (hci_dev_test_flag(hdev, HCI_LINK_SECURITY)) {
2177bab5 499 u8 enable = 1;
42c6b129
JH
500 hci_req_add(req, HCI_OP_WRITE_AUTH_ENABLE, sizeof(enable),
501 &enable);
2177bab5 502 }
a1d01db1
JH
503
504 return 0;
2177bab5
JH
505}
506
42c6b129 507static void hci_setup_link_policy(struct hci_request *req)
2177bab5 508{
42c6b129 509 struct hci_dev *hdev = req->hdev;
2177bab5
JH
510 struct hci_cp_write_def_link_policy cp;
511 u16 link_policy = 0;
512
513 if (lmp_rswitch_capable(hdev))
514 link_policy |= HCI_LP_RSWITCH;
515 if (lmp_hold_capable(hdev))
516 link_policy |= HCI_LP_HOLD;
517 if (lmp_sniff_capable(hdev))
518 link_policy |= HCI_LP_SNIFF;
519 if (lmp_park_capable(hdev))
520 link_policy |= HCI_LP_PARK;
521
522 cp.policy = cpu_to_le16(link_policy);
42c6b129 523 hci_req_add(req, HCI_OP_WRITE_DEF_LINK_POLICY, sizeof(cp), &cp);
2177bab5
JH
524}
525
42c6b129 526static void hci_set_le_support(struct hci_request *req)
2177bab5 527{
42c6b129 528 struct hci_dev *hdev = req->hdev;
2177bab5
JH
529 struct hci_cp_write_le_host_supported cp;
530
c73eee91
JH
531 /* LE-only devices do not support explicit enablement */
532 if (!lmp_bredr_capable(hdev))
533 return;
534
2177bab5
JH
535 memset(&cp, 0, sizeof(cp));
536
d7a5a11d 537 if (hci_dev_test_flag(hdev, HCI_LE_ENABLED)) {
2177bab5 538 cp.le = 0x01;
32226e4f 539 cp.simul = 0x00;
2177bab5
JH
540 }
541
542 if (cp.le != lmp_host_le_capable(hdev))
42c6b129
JH
543 hci_req_add(req, HCI_OP_WRITE_LE_HOST_SUPPORTED, sizeof(cp),
544 &cp);
2177bab5
JH
545}
546
d62e6d67
JH
547static void hci_set_event_mask_page_2(struct hci_request *req)
548{
549 struct hci_dev *hdev = req->hdev;
550 u8 events[8] = { 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00 };
313f6888 551 bool changed = false;
d62e6d67
JH
552
553 /* If Connectionless Slave Broadcast master role is supported
554 * enable all necessary events for it.
555 */
53b834d2 556 if (lmp_csb_master_capable(hdev)) {
d62e6d67
JH
557 events[1] |= 0x40; /* Triggered Clock Capture */
558 events[1] |= 0x80; /* Synchronization Train Complete */
559 events[2] |= 0x10; /* Slave Page Response Timeout */
560 events[2] |= 0x20; /* CSB Channel Map Change */
313f6888 561 changed = true;
d62e6d67
JH
562 }
563
564 /* If Connectionless Slave Broadcast slave role is supported
565 * enable all necessary events for it.
566 */
53b834d2 567 if (lmp_csb_slave_capable(hdev)) {
d62e6d67
JH
568 events[2] |= 0x01; /* Synchronization Train Received */
569 events[2] |= 0x02; /* CSB Receive */
570 events[2] |= 0x04; /* CSB Timeout */
571 events[2] |= 0x08; /* Truncated Page Complete */
313f6888 572 changed = true;
d62e6d67
JH
573 }
574
40c59fcb 575 /* Enable Authenticated Payload Timeout Expired event if supported */
313f6888 576 if (lmp_ping_capable(hdev) || hdev->le_features[0] & HCI_LE_PING) {
40c59fcb 577 events[2] |= 0x80;
313f6888
MH
578 changed = true;
579 }
40c59fcb 580
313f6888
MH
581 /* Some Broadcom based controllers indicate support for Set Event
582 * Mask Page 2 command, but then actually do not support it. Since
583 * the default value is all bits set to zero, the command is only
584 * required if the event mask has to be changed. In case no change
585 * to the event mask is needed, skip this command.
586 */
587 if (changed)
588 hci_req_add(req, HCI_OP_SET_EVENT_MASK_PAGE_2,
589 sizeof(events), events);
d62e6d67
JH
590}
591
a1d01db1 592static int hci_init3_req(struct hci_request *req, unsigned long opt)
2177bab5 593{
42c6b129 594 struct hci_dev *hdev = req->hdev;
d2c5d77f 595 u8 p;
42c6b129 596
0da71f1b
MH
597 hci_setup_event_mask(req);
598
e81be90b
JH
599 if (hdev->commands[6] & 0x20 &&
600 !test_bit(HCI_QUIRK_BROKEN_STORED_LINK_KEY, &hdev->quirks)) {
48ce62c4
MH
601 struct hci_cp_read_stored_link_key cp;
602
603 bacpy(&cp.bdaddr, BDADDR_ANY);
604 cp.read_all = 0x01;
605 hci_req_add(req, HCI_OP_READ_STORED_LINK_KEY, sizeof(cp), &cp);
606 }
607
2177bab5 608 if (hdev->commands[5] & 0x10)
42c6b129 609 hci_setup_link_policy(req);
2177bab5 610
417287de
MH
611 if (hdev->commands[8] & 0x01)
612 hci_req_add(req, HCI_OP_READ_PAGE_SCAN_ACTIVITY, 0, NULL);
613
614 /* Some older Broadcom based Bluetooth 1.2 controllers do not
615 * support the Read Page Scan Type command. Check support for
616 * this command in the bit mask of supported commands.
617 */
618 if (hdev->commands[13] & 0x01)
619 hci_req_add(req, HCI_OP_READ_PAGE_SCAN_TYPE, 0, NULL);
620
9193c6e8
AG
621 if (lmp_le_capable(hdev)) {
622 u8 events[8];
623
624 memset(events, 0, sizeof(events));
4d6c705b
MH
625
626 if (hdev->le_features[0] & HCI_LE_ENCRYPTION)
627 events[0] |= 0x10; /* LE Long Term Key Request */
662bc2e6
AG
628
629 /* If controller supports the Connection Parameters Request
630 * Link Layer Procedure, enable the corresponding event.
631 */
632 if (hdev->le_features[0] & HCI_LE_CONN_PARAM_REQ_PROC)
633 events[0] |= 0x20; /* LE Remote Connection
634 * Parameter Request
635 */
636
a9f6068e
MH
637 /* If the controller supports the Data Length Extension
638 * feature, enable the corresponding event.
639 */
640 if (hdev->le_features[0] & HCI_LE_DATA_LEN_EXT)
641 events[0] |= 0x40; /* LE Data Length Change */
642
4b71bba4
MH
643 /* If the controller supports Extended Scanner Filter
644 * Policies, enable the correspondig event.
645 */
646 if (hdev->le_features[0] & HCI_LE_EXT_SCAN_POLICY)
647 events[1] |= 0x04; /* LE Direct Advertising
648 * Report
649 */
650
9756d33b
MH
651 /* If the controller supports Channel Selection Algorithm #2
652 * feature, enable the corresponding event.
653 */
654 if (hdev->le_features[1] & HCI_LE_CHAN_SEL_ALG2)
655 events[2] |= 0x08; /* LE Channel Selection
656 * Algorithm
657 */
658
7d26f5c4
MH
659 /* If the controller supports the LE Set Scan Enable command,
660 * enable the corresponding advertising report event.
661 */
662 if (hdev->commands[26] & 0x08)
663 events[0] |= 0x02; /* LE Advertising Report */
664
665 /* If the controller supports the LE Create Connection
666 * command, enable the corresponding event.
667 */
668 if (hdev->commands[26] & 0x10)
669 events[0] |= 0x01; /* LE Connection Complete */
670
671 /* If the controller supports the LE Connection Update
672 * command, enable the corresponding event.
673 */
674 if (hdev->commands[27] & 0x04)
675 events[0] |= 0x04; /* LE Connection Update
676 * Complete
677 */
678
679 /* If the controller supports the LE Read Remote Used Features
680 * command, enable the corresponding event.
681 */
682 if (hdev->commands[27] & 0x20)
683 events[0] |= 0x08; /* LE Read Remote Used
684 * Features Complete
685 */
686
5a34bd5f
MH
687 /* If the controller supports the LE Read Local P-256
688 * Public Key command, enable the corresponding event.
689 */
690 if (hdev->commands[34] & 0x02)
691 events[0] |= 0x80; /* LE Read Local P-256
692 * Public Key Complete
693 */
694
695 /* If the controller supports the LE Generate DHKey
696 * command, enable the corresponding event.
697 */
698 if (hdev->commands[34] & 0x04)
699 events[1] |= 0x01; /* LE Generate DHKey Complete */
700
27bbca44
MH
701 /* If the controller supports the LE Set Default PHY or
702 * LE Set PHY commands, enable the corresponding event.
703 */
704 if (hdev->commands[35] & (0x20 | 0x40))
705 events[1] |= 0x08; /* LE PHY Update Complete */
706
9193c6e8
AG
707 hci_req_add(req, HCI_OP_LE_SET_EVENT_MASK, sizeof(events),
708 events);
709
15a49cca
MH
710 if (hdev->commands[25] & 0x40) {
711 /* Read LE Advertising Channel TX Power */
712 hci_req_add(req, HCI_OP_LE_READ_ADV_TX_POWER, 0, NULL);
713 }
714
2ab216a7
MH
715 if (hdev->commands[26] & 0x40) {
716 /* Read LE White List Size */
717 hci_req_add(req, HCI_OP_LE_READ_WHITE_LIST_SIZE,
718 0, NULL);
719 }
720
721 if (hdev->commands[26] & 0x80) {
722 /* Clear LE White List */
723 hci_req_add(req, HCI_OP_LE_CLEAR_WHITE_LIST, 0, NULL);
724 }
725
a9f6068e
MH
726 if (hdev->le_features[0] & HCI_LE_DATA_LEN_EXT) {
727 /* Read LE Maximum Data Length */
728 hci_req_add(req, HCI_OP_LE_READ_MAX_DATA_LEN, 0, NULL);
729
730 /* Read LE Suggested Default Data Length */
731 hci_req_add(req, HCI_OP_LE_READ_DEF_DATA_LEN, 0, NULL);
732 }
733
42c6b129 734 hci_set_le_support(req);
9193c6e8 735 }
d2c5d77f
JH
736
737 /* Read features beyond page 1 if available */
738 for (p = 2; p < HCI_MAX_PAGES && p <= hdev->max_page; p++) {
739 struct hci_cp_read_local_ext_features cp;
740
741 cp.page = p;
742 hci_req_add(req, HCI_OP_READ_LOCAL_EXT_FEATURES,
743 sizeof(cp), &cp);
744 }
a1d01db1
JH
745
746 return 0;
2177bab5
JH
747}
748
a1d01db1 749static int hci_init4_req(struct hci_request *req, unsigned long opt)
5d4e7e8d
JH
750{
751 struct hci_dev *hdev = req->hdev;
752
36f260ce
MH
753 /* Some Broadcom based Bluetooth controllers do not support the
754 * Delete Stored Link Key command. They are clearly indicating its
755 * absence in the bit mask of supported commands.
756 *
757 * Check the supported commands and only if the the command is marked
758 * as supported send it. If not supported assume that the controller
759 * does not have actual support for stored link keys which makes this
760 * command redundant anyway.
761 *
762 * Some controllers indicate that they support handling deleting
763 * stored link keys, but they don't. The quirk lets a driver
764 * just disable this command.
765 */
766 if (hdev->commands[6] & 0x80 &&
767 !test_bit(HCI_QUIRK_BROKEN_STORED_LINK_KEY, &hdev->quirks)) {
768 struct hci_cp_delete_stored_link_key cp;
769
770 bacpy(&cp.bdaddr, BDADDR_ANY);
771 cp.delete_all = 0x01;
772 hci_req_add(req, HCI_OP_DELETE_STORED_LINK_KEY,
773 sizeof(cp), &cp);
774 }
775
d62e6d67
JH
776 /* Set event mask page 2 if the HCI command for it is supported */
777 if (hdev->commands[22] & 0x04)
778 hci_set_event_mask_page_2(req);
779
109e3191
MH
780 /* Read local codec list if the HCI command is supported */
781 if (hdev->commands[29] & 0x20)
782 hci_req_add(req, HCI_OP_READ_LOCAL_CODECS, 0, NULL);
783
f4fe73ed
MH
784 /* Get MWS transport configuration if the HCI command is supported */
785 if (hdev->commands[30] & 0x08)
786 hci_req_add(req, HCI_OP_GET_MWS_TRANSPORT_CONFIG, 0, NULL);
787
5d4e7e8d 788 /* Check for Synchronization Train support */
53b834d2 789 if (lmp_sync_train_capable(hdev))
5d4e7e8d 790 hci_req_add(req, HCI_OP_READ_SYNC_TRAIN_PARAMS, 0, NULL);
a6d0d690
MH
791
792 /* Enable Secure Connections if supported and configured */
d7a5a11d 793 if (hci_dev_test_flag(hdev, HCI_SSP_ENABLED) &&
574ea3c7 794 bredr_sc_enabled(hdev)) {
a6d0d690 795 u8 support = 0x01;
574ea3c7 796
a6d0d690
MH
797 hci_req_add(req, HCI_OP_WRITE_SC_SUPPORT,
798 sizeof(support), &support);
799 }
a1d01db1 800
12204875
MH
801 /* Set Suggested Default Data Length to maximum if supported */
802 if (hdev->le_features[0] & HCI_LE_DATA_LEN_EXT) {
803 struct hci_cp_le_write_def_data_len cp;
804
805 cp.tx_len = hdev->le_max_tx_len;
806 cp.tx_time = hdev->le_max_tx_time;
807 hci_req_add(req, HCI_OP_LE_WRITE_DEF_DATA_LEN, sizeof(cp), &cp);
808 }
809
de2ba303
MH
810 /* Set Default PHY parameters if command is supported */
811 if (hdev->commands[35] & 0x20) {
812 struct hci_cp_le_set_default_phy cp;
813
814 /* No transmitter PHY or receiver PHY preferences */
815 cp.all_phys = 0x03;
816 cp.tx_phys = 0;
817 cp.rx_phys = 0;
818
819 hci_req_add(req, HCI_OP_LE_SET_DEFAULT_PHY, sizeof(cp), &cp);
820 }
821
a1d01db1 822 return 0;
5d4e7e8d
JH
823}
824
2177bab5
JH
825static int __hci_init(struct hci_dev *hdev)
826{
827 int err;
828
4ebeee2d 829 err = __hci_req_sync(hdev, hci_init1_req, 0, HCI_INIT_TIMEOUT, NULL);
2177bab5
JH
830 if (err < 0)
831 return err;
832
f640ee98
MH
833 if (hci_dev_test_flag(hdev, HCI_SETUP))
834 hci_debugfs_create_basic(hdev);
4b4148e9 835
4ebeee2d 836 err = __hci_req_sync(hdev, hci_init2_req, 0, HCI_INIT_TIMEOUT, NULL);
0af801b9
JH
837 if (err < 0)
838 return err;
839
ca8bee5d 840 /* HCI_PRIMARY covers both single-mode LE, BR/EDR and dual-mode
2177bab5 841 * BR/EDR/LE type controllers. AMP controllers only need the
0af801b9 842 * first two stages of init.
2177bab5 843 */
ca8bee5d 844 if (hdev->dev_type != HCI_PRIMARY)
2177bab5
JH
845 return 0;
846
4ebeee2d 847 err = __hci_req_sync(hdev, hci_init3_req, 0, HCI_INIT_TIMEOUT, NULL);
5d4e7e8d
JH
848 if (err < 0)
849 return err;
850
4ebeee2d 851 err = __hci_req_sync(hdev, hci_init4_req, 0, HCI_INIT_TIMEOUT, NULL);
baf27f6e
MH
852 if (err < 0)
853 return err;
854
ec6cef9c
MH
855 /* This function is only called when the controller is actually in
856 * configured state. When the controller is marked as unconfigured,
857 * this initialization procedure is not run.
858 *
859 * It means that it is possible that a controller runs through its
860 * setup phase and then discovers missing settings. If that is the
861 * case, then this function will not be called. It then will only
862 * be called during the config phase.
863 *
864 * So only when in setup phase or config phase, create the debugfs
865 * entries and register the SMP channels.
baf27f6e 866 */
d7a5a11d
MH
867 if (!hci_dev_test_flag(hdev, HCI_SETUP) &&
868 !hci_dev_test_flag(hdev, HCI_CONFIG))
baf27f6e
MH
869 return 0;
870
60c5f5fb
MH
871 hci_debugfs_create_common(hdev);
872
71c3b60e 873 if (lmp_bredr_capable(hdev))
60c5f5fb 874 hci_debugfs_create_bredr(hdev);
2bfa3531 875
162a3bac 876 if (lmp_le_capable(hdev))
60c5f5fb 877 hci_debugfs_create_le(hdev);
e7b8fc92 878
baf27f6e 879 return 0;
2177bab5
JH
880}
881
a1d01db1 882static int hci_init0_req(struct hci_request *req, unsigned long opt)
0ebca7d6
MH
883{
884 struct hci_dev *hdev = req->hdev;
885
886 BT_DBG("%s %ld", hdev->name, opt);
887
888 /* Reset */
889 if (!test_bit(HCI_QUIRK_RESET_ON_CLOSE, &hdev->quirks))
890 hci_reset_req(req, 0);
891
892 /* Read Local Version */
893 hci_req_add(req, HCI_OP_READ_LOCAL_VERSION, 0, NULL);
894
895 /* Read BD Address */
896 if (hdev->set_bdaddr)
897 hci_req_add(req, HCI_OP_READ_BD_ADDR, 0, NULL);
a1d01db1
JH
898
899 return 0;
0ebca7d6
MH
900}
901
902static int __hci_unconf_init(struct hci_dev *hdev)
903{
904 int err;
905
cc78b44b
MH
906 if (test_bit(HCI_QUIRK_RAW_DEVICE, &hdev->quirks))
907 return 0;
908
4ebeee2d 909 err = __hci_req_sync(hdev, hci_init0_req, 0, HCI_INIT_TIMEOUT, NULL);
0ebca7d6
MH
910 if (err < 0)
911 return err;
912
f640ee98
MH
913 if (hci_dev_test_flag(hdev, HCI_SETUP))
914 hci_debugfs_create_basic(hdev);
915
0ebca7d6
MH
916 return 0;
917}
918
a1d01db1 919static int hci_scan_req(struct hci_request *req, unsigned long opt)
1da177e4
LT
920{
921 __u8 scan = opt;
922
42c6b129 923 BT_DBG("%s %x", req->hdev->name, scan);
1da177e4
LT
924
925 /* Inquiry and Page scans */
42c6b129 926 hci_req_add(req, HCI_OP_WRITE_SCAN_ENABLE, 1, &scan);
a1d01db1 927 return 0;
1da177e4
LT
928}
929
a1d01db1 930static int hci_auth_req(struct hci_request *req, unsigned long opt)
1da177e4
LT
931{
932 __u8 auth = opt;
933
42c6b129 934 BT_DBG("%s %x", req->hdev->name, auth);
1da177e4
LT
935
936 /* Authentication */
42c6b129 937 hci_req_add(req, HCI_OP_WRITE_AUTH_ENABLE, 1, &auth);
a1d01db1 938 return 0;
1da177e4
LT
939}
940
a1d01db1 941static int hci_encrypt_req(struct hci_request *req, unsigned long opt)
1da177e4
LT
942{
943 __u8 encrypt = opt;
944
42c6b129 945 BT_DBG("%s %x", req->hdev->name, encrypt);
1da177e4 946
e4e8e37c 947 /* Encryption */
42c6b129 948 hci_req_add(req, HCI_OP_WRITE_ENCRYPT_MODE, 1, &encrypt);
a1d01db1 949 return 0;
1da177e4
LT
950}
951
a1d01db1 952static int hci_linkpol_req(struct hci_request *req, unsigned long opt)
e4e8e37c
MH
953{
954 __le16 policy = cpu_to_le16(opt);
955
42c6b129 956 BT_DBG("%s %x", req->hdev->name, policy);
e4e8e37c
MH
957
958 /* Default link policy */
42c6b129 959 hci_req_add(req, HCI_OP_WRITE_DEF_LINK_POLICY, 2, &policy);
a1d01db1 960 return 0;
e4e8e37c
MH
961}
962
8e87d142 963/* Get HCI device by index.
1da177e4
LT
964 * Device is held on return. */
965struct hci_dev *hci_dev_get(int index)
966{
8035ded4 967 struct hci_dev *hdev = NULL, *d;
1da177e4
LT
968
969 BT_DBG("%d", index);
970
971 if (index < 0)
972 return NULL;
973
974 read_lock(&hci_dev_list_lock);
8035ded4 975 list_for_each_entry(d, &hci_dev_list, list) {
1da177e4
LT
976 if (d->id == index) {
977 hdev = hci_dev_hold(d);
978 break;
979 }
980 }
981 read_unlock(&hci_dev_list_lock);
982 return hdev;
983}
1da177e4
LT
984
985/* ---- Inquiry support ---- */
ff9ef578 986
30dc78e1
JH
987bool hci_discovery_active(struct hci_dev *hdev)
988{
989 struct discovery_state *discov = &hdev->discovery;
990
6fbe195d 991 switch (discov->state) {
343f935b 992 case DISCOVERY_FINDING:
6fbe195d 993 case DISCOVERY_RESOLVING:
30dc78e1
JH
994 return true;
995
6fbe195d
AG
996 default:
997 return false;
998 }
30dc78e1
JH
999}
1000
ff9ef578
JH
1001void hci_discovery_set_state(struct hci_dev *hdev, int state)
1002{
bb3e0a33
JH
1003 int old_state = hdev->discovery.state;
1004
ff9ef578
JH
1005 BT_DBG("%s state %u -> %u", hdev->name, hdev->discovery.state, state);
1006
bb3e0a33 1007 if (old_state == state)
ff9ef578
JH
1008 return;
1009
bb3e0a33
JH
1010 hdev->discovery.state = state;
1011
ff9ef578
JH
1012 switch (state) {
1013 case DISCOVERY_STOPPED:
c54c3860
AG
1014 hci_update_background_scan(hdev);
1015
bb3e0a33 1016 if (old_state != DISCOVERY_STARTING)
7b99b659 1017 mgmt_discovering(hdev, 0);
ff9ef578
JH
1018 break;
1019 case DISCOVERY_STARTING:
1020 break;
343f935b 1021 case DISCOVERY_FINDING:
ff9ef578
JH
1022 mgmt_discovering(hdev, 1);
1023 break;
30dc78e1
JH
1024 case DISCOVERY_RESOLVING:
1025 break;
ff9ef578
JH
1026 case DISCOVERY_STOPPING:
1027 break;
1028 }
ff9ef578
JH
1029}
1030
1f9b9a5d 1031void hci_inquiry_cache_flush(struct hci_dev *hdev)
1da177e4 1032{
30883512 1033 struct discovery_state *cache = &hdev->discovery;
b57c1a56 1034 struct inquiry_entry *p, *n;
1da177e4 1035
561aafbc
JH
1036 list_for_each_entry_safe(p, n, &cache->all, all) {
1037 list_del(&p->all);
b57c1a56 1038 kfree(p);
1da177e4 1039 }
561aafbc
JH
1040
1041 INIT_LIST_HEAD(&cache->unknown);
1042 INIT_LIST_HEAD(&cache->resolve);
1da177e4
LT
1043}
1044
a8c5fb1a
GP
1045struct inquiry_entry *hci_inquiry_cache_lookup(struct hci_dev *hdev,
1046 bdaddr_t *bdaddr)
1da177e4 1047{
30883512 1048 struct discovery_state *cache = &hdev->discovery;
1da177e4
LT
1049 struct inquiry_entry *e;
1050
6ed93dc6 1051 BT_DBG("cache %p, %pMR", cache, bdaddr);
1da177e4 1052
561aafbc
JH
1053 list_for_each_entry(e, &cache->all, all) {
1054 if (!bacmp(&e->data.bdaddr, bdaddr))
1055 return e;
1056 }
1057
1058 return NULL;
1059}
1060
1061struct inquiry_entry *hci_inquiry_cache_lookup_unknown(struct hci_dev *hdev,
04124681 1062 bdaddr_t *bdaddr)
561aafbc 1063{
30883512 1064 struct discovery_state *cache = &hdev->discovery;
561aafbc
JH
1065 struct inquiry_entry *e;
1066
6ed93dc6 1067 BT_DBG("cache %p, %pMR", cache, bdaddr);
561aafbc
JH
1068
1069 list_for_each_entry(e, &cache->unknown, list) {
1da177e4 1070 if (!bacmp(&e->data.bdaddr, bdaddr))
b57c1a56
JH
1071 return e;
1072 }
1073
1074 return NULL;
1da177e4
LT
1075}
1076
30dc78e1 1077struct inquiry_entry *hci_inquiry_cache_lookup_resolve(struct hci_dev *hdev,
04124681
GP
1078 bdaddr_t *bdaddr,
1079 int state)
30dc78e1
JH
1080{
1081 struct discovery_state *cache = &hdev->discovery;
1082 struct inquiry_entry *e;
1083
6ed93dc6 1084 BT_DBG("cache %p bdaddr %pMR state %d", cache, bdaddr, state);
30dc78e1
JH
1085
1086 list_for_each_entry(e, &cache->resolve, list) {
1087 if (!bacmp(bdaddr, BDADDR_ANY) && e->name_state == state)
1088 return e;
1089 if (!bacmp(&e->data.bdaddr, bdaddr))
1090 return e;
1091 }
1092
1093 return NULL;
1094}
1095
a3d4e20a 1096void hci_inquiry_cache_update_resolve(struct hci_dev *hdev,
04124681 1097 struct inquiry_entry *ie)
a3d4e20a
JH
1098{
1099 struct discovery_state *cache = &hdev->discovery;
1100 struct list_head *pos = &cache->resolve;
1101 struct inquiry_entry *p;
1102
1103 list_del(&ie->list);
1104
1105 list_for_each_entry(p, &cache->resolve, list) {
1106 if (p->name_state != NAME_PENDING &&
a8c5fb1a 1107 abs(p->data.rssi) >= abs(ie->data.rssi))
a3d4e20a
JH
1108 break;
1109 pos = &p->list;
1110 }
1111
1112 list_add(&ie->list, pos);
1113}
1114
af58925c
MH
1115u32 hci_inquiry_cache_update(struct hci_dev *hdev, struct inquiry_data *data,
1116 bool name_known)
1da177e4 1117{
30883512 1118 struct discovery_state *cache = &hdev->discovery;
70f23020 1119 struct inquiry_entry *ie;
af58925c 1120 u32 flags = 0;
1da177e4 1121
6ed93dc6 1122 BT_DBG("cache %p, %pMR", cache, &data->bdaddr);
1da177e4 1123
6928a924 1124 hci_remove_remote_oob_data(hdev, &data->bdaddr, BDADDR_BREDR);
2b2fec4d 1125
af58925c
MH
1126 if (!data->ssp_mode)
1127 flags |= MGMT_DEV_FOUND_LEGACY_PAIRING;
388fc8fa 1128
70f23020 1129 ie = hci_inquiry_cache_lookup(hdev, &data->bdaddr);
a3d4e20a 1130 if (ie) {
af58925c
MH
1131 if (!ie->data.ssp_mode)
1132 flags |= MGMT_DEV_FOUND_LEGACY_PAIRING;
388fc8fa 1133
a3d4e20a 1134 if (ie->name_state == NAME_NEEDED &&
a8c5fb1a 1135 data->rssi != ie->data.rssi) {
a3d4e20a
JH
1136 ie->data.rssi = data->rssi;
1137 hci_inquiry_cache_update_resolve(hdev, ie);
1138 }
1139
561aafbc 1140 goto update;
a3d4e20a 1141 }
561aafbc
JH
1142
1143 /* Entry not in the cache. Add new one. */
27f70f3e 1144 ie = kzalloc(sizeof(*ie), GFP_KERNEL);
af58925c
MH
1145 if (!ie) {
1146 flags |= MGMT_DEV_FOUND_CONFIRM_NAME;
1147 goto done;
1148 }
561aafbc
JH
1149
1150 list_add(&ie->all, &cache->all);
1151
1152 if (name_known) {
1153 ie->name_state = NAME_KNOWN;
1154 } else {
1155 ie->name_state = NAME_NOT_KNOWN;
1156 list_add(&ie->list, &cache->unknown);
1157 }
70f23020 1158
561aafbc
JH
1159update:
1160 if (name_known && ie->name_state != NAME_KNOWN &&
a8c5fb1a 1161 ie->name_state != NAME_PENDING) {
561aafbc
JH
1162 ie->name_state = NAME_KNOWN;
1163 list_del(&ie->list);
1da177e4
LT
1164 }
1165
70f23020
AE
1166 memcpy(&ie->data, data, sizeof(*data));
1167 ie->timestamp = jiffies;
1da177e4 1168 cache->timestamp = jiffies;
3175405b
JH
1169
1170 if (ie->name_state == NAME_NOT_KNOWN)
af58925c 1171 flags |= MGMT_DEV_FOUND_CONFIRM_NAME;
3175405b 1172
af58925c
MH
1173done:
1174 return flags;
1da177e4
LT
1175}
1176
1177static int inquiry_cache_dump(struct hci_dev *hdev, int num, __u8 *buf)
1178{
30883512 1179 struct discovery_state *cache = &hdev->discovery;
1da177e4
LT
1180 struct inquiry_info *info = (struct inquiry_info *) buf;
1181 struct inquiry_entry *e;
1182 int copied = 0;
1183
561aafbc 1184 list_for_each_entry(e, &cache->all, all) {
1da177e4 1185 struct inquiry_data *data = &e->data;
b57c1a56
JH
1186
1187 if (copied >= num)
1188 break;
1189
1da177e4
LT
1190 bacpy(&info->bdaddr, &data->bdaddr);
1191 info->pscan_rep_mode = data->pscan_rep_mode;
1192 info->pscan_period_mode = data->pscan_period_mode;
1193 info->pscan_mode = data->pscan_mode;
1194 memcpy(info->dev_class, data->dev_class, 3);
1195 info->clock_offset = data->clock_offset;
b57c1a56 1196
1da177e4 1197 info++;
b57c1a56 1198 copied++;
1da177e4
LT
1199 }
1200
1201 BT_DBG("cache %p, copied %d", cache, copied);
1202 return copied;
1203}
1204
a1d01db1 1205static int hci_inq_req(struct hci_request *req, unsigned long opt)
1da177e4
LT
1206{
1207 struct hci_inquiry_req *ir = (struct hci_inquiry_req *) opt;
42c6b129 1208 struct hci_dev *hdev = req->hdev;
1da177e4
LT
1209 struct hci_cp_inquiry cp;
1210
1211 BT_DBG("%s", hdev->name);
1212
1213 if (test_bit(HCI_INQUIRY, &hdev->flags))
a1d01db1 1214 return 0;
1da177e4
LT
1215
1216 /* Start Inquiry */
1217 memcpy(&cp.lap, &ir->lap, 3);
1218 cp.length = ir->length;
1219 cp.num_rsp = ir->num_rsp;
42c6b129 1220 hci_req_add(req, HCI_OP_INQUIRY, sizeof(cp), &cp);
a1d01db1
JH
1221
1222 return 0;
1da177e4
LT
1223}
1224
1225int hci_inquiry(void __user *arg)
1226{
1227 __u8 __user *ptr = arg;
1228 struct hci_inquiry_req ir;
1229 struct hci_dev *hdev;
1230 int err = 0, do_inquiry = 0, max_rsp;
1231 long timeo;
1232 __u8 *buf;
1233
1234 if (copy_from_user(&ir, ptr, sizeof(ir)))
1235 return -EFAULT;
1236
5a08ecce
AE
1237 hdev = hci_dev_get(ir.dev_id);
1238 if (!hdev)
1da177e4
LT
1239 return -ENODEV;
1240
d7a5a11d 1241 if (hci_dev_test_flag(hdev, HCI_USER_CHANNEL)) {
0736cfa8
MH
1242 err = -EBUSY;
1243 goto done;
1244 }
1245
d7a5a11d 1246 if (hci_dev_test_flag(hdev, HCI_UNCONFIGURED)) {
fee746b0
MH
1247 err = -EOPNOTSUPP;
1248 goto done;
1249 }
1250
ca8bee5d 1251 if (hdev->dev_type != HCI_PRIMARY) {
5b69bef5
MH
1252 err = -EOPNOTSUPP;
1253 goto done;
1254 }
1255
d7a5a11d 1256 if (!hci_dev_test_flag(hdev, HCI_BREDR_ENABLED)) {
56f87901
JH
1257 err = -EOPNOTSUPP;
1258 goto done;
1259 }
1260
09fd0de5 1261 hci_dev_lock(hdev);
8e87d142 1262 if (inquiry_cache_age(hdev) > INQUIRY_CACHE_AGE_MAX ||
a8c5fb1a 1263 inquiry_cache_empty(hdev) || ir.flags & IREQ_CACHE_FLUSH) {
1f9b9a5d 1264 hci_inquiry_cache_flush(hdev);
1da177e4
LT
1265 do_inquiry = 1;
1266 }
09fd0de5 1267 hci_dev_unlock(hdev);
1da177e4 1268
04837f64 1269 timeo = ir.length * msecs_to_jiffies(2000);
70f23020
AE
1270
1271 if (do_inquiry) {
01178cd4 1272 err = hci_req_sync(hdev, hci_inq_req, (unsigned long) &ir,
4ebeee2d 1273 timeo, NULL);
70f23020
AE
1274 if (err < 0)
1275 goto done;
3e13fa1e
AG
1276
1277 /* Wait until Inquiry procedure finishes (HCI_INQUIRY flag is
1278 * cleared). If it is interrupted by a signal, return -EINTR.
1279 */
74316201 1280 if (wait_on_bit(&hdev->flags, HCI_INQUIRY,
3e13fa1e
AG
1281 TASK_INTERRUPTIBLE))
1282 return -EINTR;
70f23020 1283 }
1da177e4 1284
8fc9ced3
GP
1285 /* for unlimited number of responses we will use buffer with
1286 * 255 entries
1287 */
1da177e4
LT
1288 max_rsp = (ir.num_rsp == 0) ? 255 : ir.num_rsp;
1289
1290 /* cache_dump can't sleep. Therefore we allocate temp buffer and then
1291 * copy it to the user space.
1292 */
01df8c31 1293 buf = kmalloc(sizeof(struct inquiry_info) * max_rsp, GFP_KERNEL);
70f23020 1294 if (!buf) {
1da177e4
LT
1295 err = -ENOMEM;
1296 goto done;
1297 }
1298
09fd0de5 1299 hci_dev_lock(hdev);
1da177e4 1300 ir.num_rsp = inquiry_cache_dump(hdev, max_rsp, buf);
09fd0de5 1301 hci_dev_unlock(hdev);
1da177e4
LT
1302
1303 BT_DBG("num_rsp %d", ir.num_rsp);
1304
1305 if (!copy_to_user(ptr, &ir, sizeof(ir))) {
1306 ptr += sizeof(ir);
1307 if (copy_to_user(ptr, buf, sizeof(struct inquiry_info) *
a8c5fb1a 1308 ir.num_rsp))
1da177e4 1309 err = -EFAULT;
8e87d142 1310 } else
1da177e4
LT
1311 err = -EFAULT;
1312
1313 kfree(buf);
1314
1315done:
1316 hci_dev_put(hdev);
1317 return err;
1318}
1319
cbed0ca1 1320static int hci_dev_do_open(struct hci_dev *hdev)
1da177e4 1321{
1da177e4
LT
1322 int ret = 0;
1323
1da177e4
LT
1324 BT_DBG("%s %p", hdev->name, hdev);
1325
b504430c 1326 hci_req_sync_lock(hdev);
1da177e4 1327
d7a5a11d 1328 if (hci_dev_test_flag(hdev, HCI_UNREGISTER)) {
94324962
JH
1329 ret = -ENODEV;
1330 goto done;
1331 }
1332
d7a5a11d
MH
1333 if (!hci_dev_test_flag(hdev, HCI_SETUP) &&
1334 !hci_dev_test_flag(hdev, HCI_CONFIG)) {
a5c8f270
MH
1335 /* Check for rfkill but allow the HCI setup stage to
1336 * proceed (which in itself doesn't cause any RF activity).
1337 */
d7a5a11d 1338 if (hci_dev_test_flag(hdev, HCI_RFKILLED)) {
a5c8f270
MH
1339 ret = -ERFKILL;
1340 goto done;
1341 }
1342
1343 /* Check for valid public address or a configured static
1344 * random adddress, but let the HCI setup proceed to
1345 * be able to determine if there is a public address
1346 * or not.
1347 *
c6beca0e
MH
1348 * In case of user channel usage, it is not important
1349 * if a public address or static random address is
1350 * available.
1351 *
a5c8f270
MH
1352 * This check is only valid for BR/EDR controllers
1353 * since AMP controllers do not have an address.
1354 */
d7a5a11d 1355 if (!hci_dev_test_flag(hdev, HCI_USER_CHANNEL) &&
ca8bee5d 1356 hdev->dev_type == HCI_PRIMARY &&
a5c8f270
MH
1357 !bacmp(&hdev->bdaddr, BDADDR_ANY) &&
1358 !bacmp(&hdev->static_addr, BDADDR_ANY)) {
1359 ret = -EADDRNOTAVAIL;
1360 goto done;
1361 }
611b30f7
MH
1362 }
1363
1da177e4
LT
1364 if (test_bit(HCI_UP, &hdev->flags)) {
1365 ret = -EALREADY;
1366 goto done;
1367 }
1368
1da177e4
LT
1369 if (hdev->open(hdev)) {
1370 ret = -EIO;
1371 goto done;
1372 }
1373
e9ca8bf1 1374 set_bit(HCI_RUNNING, &hdev->flags);
05fcd4c4 1375 hci_sock_dev_event(hdev, HCI_DEV_OPEN);
4a3f95b7 1376
f41c70c4
MH
1377 atomic_set(&hdev->cmd_cnt, 1);
1378 set_bit(HCI_INIT, &hdev->flags);
1379
d7a5a11d 1380 if (hci_dev_test_flag(hdev, HCI_SETUP)) {
e131d74a
MH
1381 hci_sock_dev_event(hdev, HCI_DEV_SETUP);
1382
af202f84
MH
1383 if (hdev->setup)
1384 ret = hdev->setup(hdev);
f41c70c4 1385
af202f84
MH
1386 /* The transport driver can set these quirks before
1387 * creating the HCI device or in its setup callback.
1388 *
1389 * In case any of them is set, the controller has to
1390 * start up as unconfigured.
1391 */
eb1904f4
MH
1392 if (test_bit(HCI_QUIRK_EXTERNAL_CONFIG, &hdev->quirks) ||
1393 test_bit(HCI_QUIRK_INVALID_BDADDR, &hdev->quirks))
a1536da2 1394 hci_dev_set_flag(hdev, HCI_UNCONFIGURED);
f41c70c4 1395
0ebca7d6
MH
1396 /* For an unconfigured controller it is required to
1397 * read at least the version information provided by
1398 * the Read Local Version Information command.
1399 *
1400 * If the set_bdaddr driver callback is provided, then
1401 * also the original Bluetooth public device address
1402 * will be read using the Read BD Address command.
1403 */
d7a5a11d 1404 if (hci_dev_test_flag(hdev, HCI_UNCONFIGURED))
0ebca7d6 1405 ret = __hci_unconf_init(hdev);
89bc22d2
MH
1406 }
1407
d7a5a11d 1408 if (hci_dev_test_flag(hdev, HCI_CONFIG)) {
9713c17b
MH
1409 /* If public address change is configured, ensure that
1410 * the address gets programmed. If the driver does not
1411 * support changing the public address, fail the power
1412 * on procedure.
1413 */
1414 if (bacmp(&hdev->public_addr, BDADDR_ANY) &&
1415 hdev->set_bdaddr)
24c457e2
MH
1416 ret = hdev->set_bdaddr(hdev, &hdev->public_addr);
1417 else
1418 ret = -EADDRNOTAVAIL;
1419 }
1420
f41c70c4 1421 if (!ret) {
d7a5a11d 1422 if (!hci_dev_test_flag(hdev, HCI_UNCONFIGURED) &&
98a63aaf 1423 !hci_dev_test_flag(hdev, HCI_USER_CHANNEL)) {
f41c70c4 1424 ret = __hci_init(hdev);
98a63aaf
MH
1425 if (!ret && hdev->post_init)
1426 ret = hdev->post_init(hdev);
1427 }
1da177e4
LT
1428 }
1429
7e995b9e
MH
1430 /* If the HCI Reset command is clearing all diagnostic settings,
1431 * then they need to be reprogrammed after the init procedure
1432 * completed.
1433 */
1434 if (test_bit(HCI_QUIRK_NON_PERSISTENT_DIAG, &hdev->quirks) &&
b56c7b25 1435 !hci_dev_test_flag(hdev, HCI_USER_CHANNEL) &&
7e995b9e
MH
1436 hci_dev_test_flag(hdev, HCI_VENDOR_DIAG) && hdev->set_diag)
1437 ret = hdev->set_diag(hdev, true);
1438
f41c70c4
MH
1439 clear_bit(HCI_INIT, &hdev->flags);
1440
1da177e4
LT
1441 if (!ret) {
1442 hci_dev_hold(hdev);
a1536da2 1443 hci_dev_set_flag(hdev, HCI_RPA_EXPIRED);
1da177e4 1444 set_bit(HCI_UP, &hdev->flags);
05fcd4c4 1445 hci_sock_dev_event(hdev, HCI_DEV_UP);
6d5d2ee6 1446 hci_leds_update_powered(hdev, true);
d7a5a11d
MH
1447 if (!hci_dev_test_flag(hdev, HCI_SETUP) &&
1448 !hci_dev_test_flag(hdev, HCI_CONFIG) &&
1449 !hci_dev_test_flag(hdev, HCI_UNCONFIGURED) &&
1450 !hci_dev_test_flag(hdev, HCI_USER_CHANNEL) &&
2ff13894 1451 hci_dev_test_flag(hdev, HCI_MGMT) &&
ca8bee5d 1452 hdev->dev_type == HCI_PRIMARY) {
2ff13894
JH
1453 ret = __hci_req_hci_power_on(hdev);
1454 mgmt_power_on(hdev, ret);
56e5cb86 1455 }
8e87d142 1456 } else {
1da177e4 1457 /* Init failed, cleanup */
3eff45ea 1458 flush_work(&hdev->tx_work);
c347b765 1459 flush_work(&hdev->cmd_work);
b78752cc 1460 flush_work(&hdev->rx_work);
1da177e4
LT
1461
1462 skb_queue_purge(&hdev->cmd_q);
1463 skb_queue_purge(&hdev->rx_q);
1464
1465 if (hdev->flush)
1466 hdev->flush(hdev);
1467
1468 if (hdev->sent_cmd) {
1469 kfree_skb(hdev->sent_cmd);
1470 hdev->sent_cmd = NULL;
1471 }
1472
e9ca8bf1 1473 clear_bit(HCI_RUNNING, &hdev->flags);
05fcd4c4 1474 hci_sock_dev_event(hdev, HCI_DEV_CLOSE);
4a3f95b7 1475
1da177e4 1476 hdev->close(hdev);
fee746b0 1477 hdev->flags &= BIT(HCI_RAW);
1da177e4
LT
1478 }
1479
1480done:
b504430c 1481 hci_req_sync_unlock(hdev);
1da177e4
LT
1482 return ret;
1483}
1484
cbed0ca1
JH
1485/* ---- HCI ioctl helpers ---- */
1486
1487int hci_dev_open(__u16 dev)
1488{
1489 struct hci_dev *hdev;
1490 int err;
1491
1492 hdev = hci_dev_get(dev);
1493 if (!hdev)
1494 return -ENODEV;
1495
4a964404 1496 /* Devices that are marked as unconfigured can only be powered
fee746b0
MH
1497 * up as user channel. Trying to bring them up as normal devices
1498 * will result into a failure. Only user channel operation is
1499 * possible.
1500 *
1501 * When this function is called for a user channel, the flag
1502 * HCI_USER_CHANNEL will be set first before attempting to
1503 * open the device.
1504 */
d7a5a11d
MH
1505 if (hci_dev_test_flag(hdev, HCI_UNCONFIGURED) &&
1506 !hci_dev_test_flag(hdev, HCI_USER_CHANNEL)) {
fee746b0
MH
1507 err = -EOPNOTSUPP;
1508 goto done;
1509 }
1510
e1d08f40
JH
1511 /* We need to ensure that no other power on/off work is pending
1512 * before proceeding to call hci_dev_do_open. This is
1513 * particularly important if the setup procedure has not yet
1514 * completed.
1515 */
a69d8927 1516 if (hci_dev_test_and_clear_flag(hdev, HCI_AUTO_OFF))
e1d08f40
JH
1517 cancel_delayed_work(&hdev->power_off);
1518
a5c8f270
MH
1519 /* After this call it is guaranteed that the setup procedure
1520 * has finished. This means that error conditions like RFKILL
1521 * or no valid public or static random address apply.
1522 */
e1d08f40
JH
1523 flush_workqueue(hdev->req_workqueue);
1524
12aa4f0a 1525 /* For controllers not using the management interface and that
b6ae8457 1526 * are brought up using legacy ioctl, set the HCI_BONDABLE bit
12aa4f0a
MH
1527 * so that pairing works for them. Once the management interface
1528 * is in use this bit will be cleared again and userspace has
1529 * to explicitly enable it.
1530 */
d7a5a11d
MH
1531 if (!hci_dev_test_flag(hdev, HCI_USER_CHANNEL) &&
1532 !hci_dev_test_flag(hdev, HCI_MGMT))
a1536da2 1533 hci_dev_set_flag(hdev, HCI_BONDABLE);
12aa4f0a 1534
cbed0ca1
JH
1535 err = hci_dev_do_open(hdev);
1536
fee746b0 1537done:
cbed0ca1 1538 hci_dev_put(hdev);
cbed0ca1
JH
1539 return err;
1540}
1541
d7347f3c
JH
1542/* This function requires the caller holds hdev->lock */
1543static void hci_pend_le_actions_clear(struct hci_dev *hdev)
1544{
1545 struct hci_conn_params *p;
1546
f161dd41
JH
1547 list_for_each_entry(p, &hdev->le_conn_params, list) {
1548 if (p->conn) {
1549 hci_conn_drop(p->conn);
f8aaf9b6 1550 hci_conn_put(p->conn);
f161dd41
JH
1551 p->conn = NULL;
1552 }
d7347f3c 1553 list_del_init(&p->action);
f161dd41 1554 }
d7347f3c
JH
1555
1556 BT_DBG("All LE pending actions cleared");
1557}
1558
6b3cc1db 1559int hci_dev_do_close(struct hci_dev *hdev)
1da177e4 1560{
acc649c6
MH
1561 bool auto_off;
1562
1da177e4
LT
1563 BT_DBG("%s %p", hdev->name, hdev);
1564
d24d8144 1565 if (!hci_dev_test_flag(hdev, HCI_UNREGISTER) &&
867146a0 1566 !hci_dev_test_flag(hdev, HCI_USER_CHANNEL) &&
d24d8144 1567 test_bit(HCI_UP, &hdev->flags)) {
a44fecbd
THJA
1568 /* Execute vendor specific shutdown routine */
1569 if (hdev->shutdown)
1570 hdev->shutdown(hdev);
1571 }
1572
78c04c0b
VCG
1573 cancel_delayed_work(&hdev->power_off);
1574
7df0f73e 1575 hci_request_cancel_all(hdev);
b504430c 1576 hci_req_sync_lock(hdev);
1da177e4
LT
1577
1578 if (!test_and_clear_bit(HCI_UP, &hdev->flags)) {
65cc2b49 1579 cancel_delayed_work_sync(&hdev->cmd_timer);
b504430c 1580 hci_req_sync_unlock(hdev);
1da177e4
LT
1581 return 0;
1582 }
1583
6d5d2ee6
HK
1584 hci_leds_update_powered(hdev, false);
1585
3eff45ea
GP
1586 /* Flush RX and TX works */
1587 flush_work(&hdev->tx_work);
b78752cc 1588 flush_work(&hdev->rx_work);
1da177e4 1589
16ab91ab 1590 if (hdev->discov_timeout > 0) {
16ab91ab 1591 hdev->discov_timeout = 0;
a358dc11
MH
1592 hci_dev_clear_flag(hdev, HCI_DISCOVERABLE);
1593 hci_dev_clear_flag(hdev, HCI_LIMITED_DISCOVERABLE);
16ab91ab
JH
1594 }
1595
a69d8927 1596 if (hci_dev_test_and_clear_flag(hdev, HCI_SERVICE_CACHE))
7d78525d
JH
1597 cancel_delayed_work(&hdev->service_cache);
1598
d7a5a11d 1599 if (hci_dev_test_flag(hdev, HCI_MGMT))
4518bb0f 1600 cancel_delayed_work_sync(&hdev->rpa_expired);
7ba8b4be 1601
76727c02
JH
1602 /* Avoid potential lockdep warnings from the *_flush() calls by
1603 * ensuring the workqueue is empty up front.
1604 */
1605 drain_workqueue(hdev->workqueue);
1606
09fd0de5 1607 hci_dev_lock(hdev);
1aeb9c65 1608
8f502f84
JH
1609 hci_discovery_set_state(hdev, DISCOVERY_STOPPED);
1610
acc649c6
MH
1611 auto_off = hci_dev_test_and_clear_flag(hdev, HCI_AUTO_OFF);
1612
ca8bee5d 1613 if (!auto_off && hdev->dev_type == HCI_PRIMARY &&
baab7932 1614 !hci_dev_test_flag(hdev, HCI_USER_CHANNEL) &&
2ff13894
JH
1615 hci_dev_test_flag(hdev, HCI_MGMT))
1616 __mgmt_power_off(hdev);
1aeb9c65 1617
1f9b9a5d 1618 hci_inquiry_cache_flush(hdev);
d7347f3c 1619 hci_pend_le_actions_clear(hdev);
f161dd41 1620 hci_conn_hash_flush(hdev);
09fd0de5 1621 hci_dev_unlock(hdev);
1da177e4 1622
64dae967
MH
1623 smp_unregister(hdev);
1624
05fcd4c4 1625 hci_sock_dev_event(hdev, HCI_DEV_DOWN);
1da177e4
LT
1626
1627 if (hdev->flush)
1628 hdev->flush(hdev);
1629
1630 /* Reset device */
1631 skb_queue_purge(&hdev->cmd_q);
1632 atomic_set(&hdev->cmd_cnt, 1);
acc649c6
MH
1633 if (test_bit(HCI_QUIRK_RESET_ON_CLOSE, &hdev->quirks) &&
1634 !auto_off && !hci_dev_test_flag(hdev, HCI_UNCONFIGURED)) {
1da177e4 1635 set_bit(HCI_INIT, &hdev->flags);
4ebeee2d 1636 __hci_req_sync(hdev, hci_reset_req, 0, HCI_CMD_TIMEOUT, NULL);
1da177e4
LT
1637 clear_bit(HCI_INIT, &hdev->flags);
1638 }
1639
c347b765
GP
1640 /* flush cmd work */
1641 flush_work(&hdev->cmd_work);
1da177e4
LT
1642
1643 /* Drop queues */
1644 skb_queue_purge(&hdev->rx_q);
1645 skb_queue_purge(&hdev->cmd_q);
1646 skb_queue_purge(&hdev->raw_q);
1647
1648 /* Drop last sent command */
1649 if (hdev->sent_cmd) {
65cc2b49 1650 cancel_delayed_work_sync(&hdev->cmd_timer);
1da177e4
LT
1651 kfree_skb(hdev->sent_cmd);
1652 hdev->sent_cmd = NULL;
1653 }
1654
e9ca8bf1 1655 clear_bit(HCI_RUNNING, &hdev->flags);
05fcd4c4 1656 hci_sock_dev_event(hdev, HCI_DEV_CLOSE);
4a3f95b7 1657
1da177e4
LT
1658 /* After this point our queues are empty
1659 * and no tasks are scheduled. */
1660 hdev->close(hdev);
1661
35b973c9 1662 /* Clear flags */
fee746b0 1663 hdev->flags &= BIT(HCI_RAW);
eacb44df 1664 hci_dev_clear_volatile_flags(hdev);
35b973c9 1665
ced5c338 1666 /* Controller radio is available but is currently powered down */
536619e8 1667 hdev->amp_status = AMP_STATUS_POWERED_DOWN;
ced5c338 1668
e59fda8d 1669 memset(hdev->eir, 0, sizeof(hdev->eir));
09b3c3fb 1670 memset(hdev->dev_class, 0, sizeof(hdev->dev_class));
7a4cd51d 1671 bacpy(&hdev->random_addr, BDADDR_ANY);
e59fda8d 1672
b504430c 1673 hci_req_sync_unlock(hdev);
1da177e4
LT
1674
1675 hci_dev_put(hdev);
1676 return 0;
1677}
1678
1679int hci_dev_close(__u16 dev)
1680{
1681 struct hci_dev *hdev;
1682 int err;
1683
70f23020
AE
1684 hdev = hci_dev_get(dev);
1685 if (!hdev)
1da177e4 1686 return -ENODEV;
8ee56540 1687
d7a5a11d 1688 if (hci_dev_test_flag(hdev, HCI_USER_CHANNEL)) {
0736cfa8
MH
1689 err = -EBUSY;
1690 goto done;
1691 }
1692
a69d8927 1693 if (hci_dev_test_and_clear_flag(hdev, HCI_AUTO_OFF))
8ee56540
MH
1694 cancel_delayed_work(&hdev->power_off);
1695
1da177e4 1696 err = hci_dev_do_close(hdev);
8ee56540 1697
0736cfa8 1698done:
1da177e4
LT
1699 hci_dev_put(hdev);
1700 return err;
1701}
1702
5c912495 1703static int hci_dev_do_reset(struct hci_dev *hdev)
1da177e4 1704{
5c912495 1705 int ret;
1da177e4 1706
5c912495 1707 BT_DBG("%s %p", hdev->name, hdev);
1da177e4 1708
b504430c 1709 hci_req_sync_lock(hdev);
1da177e4 1710
1da177e4
LT
1711 /* Drop queues */
1712 skb_queue_purge(&hdev->rx_q);
1713 skb_queue_purge(&hdev->cmd_q);
1714
76727c02
JH
1715 /* Avoid potential lockdep warnings from the *_flush() calls by
1716 * ensuring the workqueue is empty up front.
1717 */
1718 drain_workqueue(hdev->workqueue);
1719
09fd0de5 1720 hci_dev_lock(hdev);
1f9b9a5d 1721 hci_inquiry_cache_flush(hdev);
1da177e4 1722 hci_conn_hash_flush(hdev);
09fd0de5 1723 hci_dev_unlock(hdev);
1da177e4
LT
1724
1725 if (hdev->flush)
1726 hdev->flush(hdev);
1727
8e87d142 1728 atomic_set(&hdev->cmd_cnt, 1);
6ed58ec5 1729 hdev->acl_cnt = 0; hdev->sco_cnt = 0; hdev->le_cnt = 0;
1da177e4 1730
4ebeee2d 1731 ret = __hci_req_sync(hdev, hci_reset_req, 0, HCI_INIT_TIMEOUT, NULL);
1da177e4 1732
b504430c 1733 hci_req_sync_unlock(hdev);
1da177e4
LT
1734 return ret;
1735}
1736
5c912495
MH
1737int hci_dev_reset(__u16 dev)
1738{
1739 struct hci_dev *hdev;
1740 int err;
1741
1742 hdev = hci_dev_get(dev);
1743 if (!hdev)
1744 return -ENODEV;
1745
1746 if (!test_bit(HCI_UP, &hdev->flags)) {
1747 err = -ENETDOWN;
1748 goto done;
1749 }
1750
d7a5a11d 1751 if (hci_dev_test_flag(hdev, HCI_USER_CHANNEL)) {
5c912495
MH
1752 err = -EBUSY;
1753 goto done;
1754 }
1755
d7a5a11d 1756 if (hci_dev_test_flag(hdev, HCI_UNCONFIGURED)) {
5c912495
MH
1757 err = -EOPNOTSUPP;
1758 goto done;
1759 }
1760
1761 err = hci_dev_do_reset(hdev);
1762
1763done:
1764 hci_dev_put(hdev);
1765 return err;
1766}
1767
1da177e4
LT
1768int hci_dev_reset_stat(__u16 dev)
1769{
1770 struct hci_dev *hdev;
1771 int ret = 0;
1772
70f23020
AE
1773 hdev = hci_dev_get(dev);
1774 if (!hdev)
1da177e4
LT
1775 return -ENODEV;
1776
d7a5a11d 1777 if (hci_dev_test_flag(hdev, HCI_USER_CHANNEL)) {
0736cfa8
MH
1778 ret = -EBUSY;
1779 goto done;
1780 }
1781
d7a5a11d 1782 if (hci_dev_test_flag(hdev, HCI_UNCONFIGURED)) {
fee746b0
MH
1783 ret = -EOPNOTSUPP;
1784 goto done;
1785 }
1786
1da177e4
LT
1787 memset(&hdev->stat, 0, sizeof(struct hci_dev_stats));
1788
0736cfa8 1789done:
1da177e4 1790 hci_dev_put(hdev);
1da177e4
LT
1791 return ret;
1792}
1793
123abc08
JH
1794static void hci_update_scan_state(struct hci_dev *hdev, u8 scan)
1795{
bc6d2d04 1796 bool conn_changed, discov_changed;
123abc08
JH
1797
1798 BT_DBG("%s scan 0x%02x", hdev->name, scan);
1799
1800 if ((scan & SCAN_PAGE))
238be788
MH
1801 conn_changed = !hci_dev_test_and_set_flag(hdev,
1802 HCI_CONNECTABLE);
123abc08 1803 else
a69d8927
MH
1804 conn_changed = hci_dev_test_and_clear_flag(hdev,
1805 HCI_CONNECTABLE);
123abc08 1806
bc6d2d04 1807 if ((scan & SCAN_INQUIRY)) {
238be788
MH
1808 discov_changed = !hci_dev_test_and_set_flag(hdev,
1809 HCI_DISCOVERABLE);
bc6d2d04 1810 } else {
a358dc11 1811 hci_dev_clear_flag(hdev, HCI_LIMITED_DISCOVERABLE);
a69d8927
MH
1812 discov_changed = hci_dev_test_and_clear_flag(hdev,
1813 HCI_DISCOVERABLE);
bc6d2d04
JH
1814 }
1815
d7a5a11d 1816 if (!hci_dev_test_flag(hdev, HCI_MGMT))
123abc08
JH
1817 return;
1818
bc6d2d04
JH
1819 if (conn_changed || discov_changed) {
1820 /* In case this was disabled through mgmt */
a1536da2 1821 hci_dev_set_flag(hdev, HCI_BREDR_ENABLED);
bc6d2d04 1822
d7a5a11d 1823 if (hci_dev_test_flag(hdev, HCI_LE_ENABLED))
cab054ab 1824 hci_req_update_adv_data(hdev, hdev->cur_adv_instance);
bc6d2d04 1825
123abc08 1826 mgmt_new_settings(hdev);
bc6d2d04 1827 }
123abc08
JH
1828}
1829
1da177e4
LT
1830int hci_dev_cmd(unsigned int cmd, void __user *arg)
1831{
1832 struct hci_dev *hdev;
1833 struct hci_dev_req dr;
1834 int err = 0;
1835
1836 if (copy_from_user(&dr, arg, sizeof(dr)))
1837 return -EFAULT;
1838
70f23020
AE
1839 hdev = hci_dev_get(dr.dev_id);
1840 if (!hdev)
1da177e4
LT
1841 return -ENODEV;
1842
d7a5a11d 1843 if (hci_dev_test_flag(hdev, HCI_USER_CHANNEL)) {
0736cfa8
MH
1844 err = -EBUSY;
1845 goto done;
1846 }
1847
d7a5a11d 1848 if (hci_dev_test_flag(hdev, HCI_UNCONFIGURED)) {
fee746b0
MH
1849 err = -EOPNOTSUPP;
1850 goto done;
1851 }
1852
ca8bee5d 1853 if (hdev->dev_type != HCI_PRIMARY) {
5b69bef5
MH
1854 err = -EOPNOTSUPP;
1855 goto done;
1856 }
1857
d7a5a11d 1858 if (!hci_dev_test_flag(hdev, HCI_BREDR_ENABLED)) {
56f87901
JH
1859 err = -EOPNOTSUPP;
1860 goto done;
1861 }
1862
1da177e4
LT
1863 switch (cmd) {
1864 case HCISETAUTH:
01178cd4 1865 err = hci_req_sync(hdev, hci_auth_req, dr.dev_opt,
4ebeee2d 1866 HCI_INIT_TIMEOUT, NULL);
1da177e4
LT
1867 break;
1868
1869 case HCISETENCRYPT:
1870 if (!lmp_encrypt_capable(hdev)) {
1871 err = -EOPNOTSUPP;
1872 break;
1873 }
1874
1875 if (!test_bit(HCI_AUTH, &hdev->flags)) {
1876 /* Auth must be enabled first */
01178cd4 1877 err = hci_req_sync(hdev, hci_auth_req, dr.dev_opt,
4ebeee2d 1878 HCI_INIT_TIMEOUT, NULL);
1da177e4
LT
1879 if (err)
1880 break;
1881 }
1882
01178cd4 1883 err = hci_req_sync(hdev, hci_encrypt_req, dr.dev_opt,
4ebeee2d 1884 HCI_INIT_TIMEOUT, NULL);
1da177e4
LT
1885 break;
1886
1887 case HCISETSCAN:
01178cd4 1888 err = hci_req_sync(hdev, hci_scan_req, dr.dev_opt,
4ebeee2d 1889 HCI_INIT_TIMEOUT, NULL);
91a668b0 1890
bc6d2d04
JH
1891 /* Ensure that the connectable and discoverable states
1892 * get correctly modified as this was a non-mgmt change.
91a668b0 1893 */
123abc08
JH
1894 if (!err)
1895 hci_update_scan_state(hdev, dr.dev_opt);
1da177e4
LT
1896 break;
1897
1da177e4 1898 case HCISETLINKPOL:
01178cd4 1899 err = hci_req_sync(hdev, hci_linkpol_req, dr.dev_opt,
4ebeee2d 1900 HCI_INIT_TIMEOUT, NULL);
1da177e4
LT
1901 break;
1902
1903 case HCISETLINKMODE:
e4e8e37c
MH
1904 hdev->link_mode = ((__u16) dr.dev_opt) &
1905 (HCI_LM_MASTER | HCI_LM_ACCEPT);
1906 break;
1907
1908 case HCISETPTYPE:
1909 hdev->pkt_type = (__u16) dr.dev_opt;
1da177e4
LT
1910 break;
1911
1912 case HCISETACLMTU:
e4e8e37c
MH
1913 hdev->acl_mtu = *((__u16 *) &dr.dev_opt + 1);
1914 hdev->acl_pkts = *((__u16 *) &dr.dev_opt + 0);
1da177e4
LT
1915 break;
1916
1917 case HCISETSCOMTU:
e4e8e37c
MH
1918 hdev->sco_mtu = *((__u16 *) &dr.dev_opt + 1);
1919 hdev->sco_pkts = *((__u16 *) &dr.dev_opt + 0);
1da177e4
LT
1920 break;
1921
1922 default:
1923 err = -EINVAL;
1924 break;
1925 }
e4e8e37c 1926
0736cfa8 1927done:
1da177e4
LT
1928 hci_dev_put(hdev);
1929 return err;
1930}
1931
1932int hci_get_dev_list(void __user *arg)
1933{
8035ded4 1934 struct hci_dev *hdev;
1da177e4
LT
1935 struct hci_dev_list_req *dl;
1936 struct hci_dev_req *dr;
1da177e4
LT
1937 int n = 0, size, err;
1938 __u16 dev_num;
1939
1940 if (get_user(dev_num, (__u16 __user *) arg))
1941 return -EFAULT;
1942
1943 if (!dev_num || dev_num > (PAGE_SIZE * 2) / sizeof(*dr))
1944 return -EINVAL;
1945
1946 size = sizeof(*dl) + dev_num * sizeof(*dr);
1947
70f23020
AE
1948 dl = kzalloc(size, GFP_KERNEL);
1949 if (!dl)
1da177e4
LT
1950 return -ENOMEM;
1951
1952 dr = dl->dev_req;
1953
f20d09d5 1954 read_lock(&hci_dev_list_lock);
8035ded4 1955 list_for_each_entry(hdev, &hci_dev_list, list) {
2e84d8db 1956 unsigned long flags = hdev->flags;
c542a06c 1957
2e84d8db
MH
1958 /* When the auto-off is configured it means the transport
1959 * is running, but in that case still indicate that the
1960 * device is actually down.
1961 */
d7a5a11d 1962 if (hci_dev_test_flag(hdev, HCI_AUTO_OFF))
2e84d8db 1963 flags &= ~BIT(HCI_UP);
c542a06c 1964
1da177e4 1965 (dr + n)->dev_id = hdev->id;
2e84d8db 1966 (dr + n)->dev_opt = flags;
c542a06c 1967
1da177e4
LT
1968 if (++n >= dev_num)
1969 break;
1970 }
f20d09d5 1971 read_unlock(&hci_dev_list_lock);
1da177e4
LT
1972
1973 dl->dev_num = n;
1974 size = sizeof(*dl) + n * sizeof(*dr);
1975
1976 err = copy_to_user(arg, dl, size);
1977 kfree(dl);
1978
1979 return err ? -EFAULT : 0;
1980}
1981
1982int hci_get_dev_info(void __user *arg)
1983{
1984 struct hci_dev *hdev;
1985 struct hci_dev_info di;
2e84d8db 1986 unsigned long flags;
1da177e4
LT
1987 int err = 0;
1988
1989 if (copy_from_user(&di, arg, sizeof(di)))
1990 return -EFAULT;
1991
70f23020
AE
1992 hdev = hci_dev_get(di.dev_id);
1993 if (!hdev)
1da177e4
LT
1994 return -ENODEV;
1995
2e84d8db
MH
1996 /* When the auto-off is configured it means the transport
1997 * is running, but in that case still indicate that the
1998 * device is actually down.
1999 */
d7a5a11d 2000 if (hci_dev_test_flag(hdev, HCI_AUTO_OFF))
2e84d8db
MH
2001 flags = hdev->flags & ~BIT(HCI_UP);
2002 else
2003 flags = hdev->flags;
c542a06c 2004
1da177e4
LT
2005 strcpy(di.name, hdev->name);
2006 di.bdaddr = hdev->bdaddr;
60f2a3ed 2007 di.type = (hdev->bus & 0x0f) | ((hdev->dev_type & 0x03) << 4);
2e84d8db 2008 di.flags = flags;
1da177e4 2009 di.pkt_type = hdev->pkt_type;
572c7f84
JH
2010 if (lmp_bredr_capable(hdev)) {
2011 di.acl_mtu = hdev->acl_mtu;
2012 di.acl_pkts = hdev->acl_pkts;
2013 di.sco_mtu = hdev->sco_mtu;
2014 di.sco_pkts = hdev->sco_pkts;
2015 } else {
2016 di.acl_mtu = hdev->le_mtu;
2017 di.acl_pkts = hdev->le_pkts;
2018 di.sco_mtu = 0;
2019 di.sco_pkts = 0;
2020 }
1da177e4
LT
2021 di.link_policy = hdev->link_policy;
2022 di.link_mode = hdev->link_mode;
2023
2024 memcpy(&di.stat, &hdev->stat, sizeof(di.stat));
2025 memcpy(&di.features, &hdev->features, sizeof(di.features));
2026
2027 if (copy_to_user(arg, &di, sizeof(di)))
2028 err = -EFAULT;
2029
2030 hci_dev_put(hdev);
2031
2032 return err;
2033}
2034
2035/* ---- Interface to HCI drivers ---- */
2036
611b30f7
MH
2037static int hci_rfkill_set_block(void *data, bool blocked)
2038{
2039 struct hci_dev *hdev = data;
2040
2041 BT_DBG("%p name %s blocked %d", hdev, hdev->name, blocked);
2042
d7a5a11d 2043 if (hci_dev_test_flag(hdev, HCI_USER_CHANNEL))
0736cfa8
MH
2044 return -EBUSY;
2045
5e130367 2046 if (blocked) {
a1536da2 2047 hci_dev_set_flag(hdev, HCI_RFKILLED);
d7a5a11d
MH
2048 if (!hci_dev_test_flag(hdev, HCI_SETUP) &&
2049 !hci_dev_test_flag(hdev, HCI_CONFIG))
bf543036 2050 hci_dev_do_close(hdev);
5e130367 2051 } else {
a358dc11 2052 hci_dev_clear_flag(hdev, HCI_RFKILLED);
1025c04c 2053 }
611b30f7
MH
2054
2055 return 0;
2056}
2057
2058static const struct rfkill_ops hci_rfkill_ops = {
2059 .set_block = hci_rfkill_set_block,
2060};
2061
ab81cbf9
JH
2062static void hci_power_on(struct work_struct *work)
2063{
2064 struct hci_dev *hdev = container_of(work, struct hci_dev, power_on);
96570ffc 2065 int err;
ab81cbf9
JH
2066
2067 BT_DBG("%s", hdev->name);
2068
2ff13894
JH
2069 if (test_bit(HCI_UP, &hdev->flags) &&
2070 hci_dev_test_flag(hdev, HCI_MGMT) &&
2071 hci_dev_test_and_clear_flag(hdev, HCI_AUTO_OFF)) {
d82142a8 2072 cancel_delayed_work(&hdev->power_off);
2ff13894
JH
2073 hci_req_sync_lock(hdev);
2074 err = __hci_req_hci_power_on(hdev);
2075 hci_req_sync_unlock(hdev);
2076 mgmt_power_on(hdev, err);
2077 return;
2078 }
2079
cbed0ca1 2080 err = hci_dev_do_open(hdev);
96570ffc 2081 if (err < 0) {
3ad67582 2082 hci_dev_lock(hdev);
96570ffc 2083 mgmt_set_powered_failed(hdev, err);
3ad67582 2084 hci_dev_unlock(hdev);
ab81cbf9 2085 return;
96570ffc 2086 }
ab81cbf9 2087
a5c8f270
MH
2088 /* During the HCI setup phase, a few error conditions are
2089 * ignored and they need to be checked now. If they are still
2090 * valid, it is important to turn the device back off.
2091 */
d7a5a11d
MH
2092 if (hci_dev_test_flag(hdev, HCI_RFKILLED) ||
2093 hci_dev_test_flag(hdev, HCI_UNCONFIGURED) ||
ca8bee5d 2094 (hdev->dev_type == HCI_PRIMARY &&
a5c8f270
MH
2095 !bacmp(&hdev->bdaddr, BDADDR_ANY) &&
2096 !bacmp(&hdev->static_addr, BDADDR_ANY))) {
a358dc11 2097 hci_dev_clear_flag(hdev, HCI_AUTO_OFF);
bf543036 2098 hci_dev_do_close(hdev);
d7a5a11d 2099 } else if (hci_dev_test_flag(hdev, HCI_AUTO_OFF)) {
19202573
JH
2100 queue_delayed_work(hdev->req_workqueue, &hdev->power_off,
2101 HCI_AUTO_OFF_TIMEOUT);
bf543036 2102 }
ab81cbf9 2103
a69d8927 2104 if (hci_dev_test_and_clear_flag(hdev, HCI_SETUP)) {
4a964404
MH
2105 /* For unconfigured devices, set the HCI_RAW flag
2106 * so that userspace can easily identify them.
4a964404 2107 */
d7a5a11d 2108 if (hci_dev_test_flag(hdev, HCI_UNCONFIGURED))
4a964404 2109 set_bit(HCI_RAW, &hdev->flags);
0602a8ad
MH
2110
2111 /* For fully configured devices, this will send
2112 * the Index Added event. For unconfigured devices,
2113 * it will send Unconfigued Index Added event.
2114 *
2115 * Devices with HCI_QUIRK_RAW_DEVICE are ignored
2116 * and no event will be send.
2117 */
2118 mgmt_index_added(hdev);
a69d8927 2119 } else if (hci_dev_test_and_clear_flag(hdev, HCI_CONFIG)) {
5ea234d3
MH
2120 /* When the controller is now configured, then it
2121 * is important to clear the HCI_RAW flag.
2122 */
d7a5a11d 2123 if (!hci_dev_test_flag(hdev, HCI_UNCONFIGURED))
5ea234d3
MH
2124 clear_bit(HCI_RAW, &hdev->flags);
2125
d603b76b
MH
2126 /* Powering on the controller with HCI_CONFIG set only
2127 * happens with the transition from unconfigured to
2128 * configured. This will send the Index Added event.
2129 */
744cf19e 2130 mgmt_index_added(hdev);
fee746b0 2131 }
ab81cbf9
JH
2132}
2133
2134static void hci_power_off(struct work_struct *work)
2135{
3243553f 2136 struct hci_dev *hdev = container_of(work, struct hci_dev,
a8c5fb1a 2137 power_off.work);
ab81cbf9
JH
2138
2139 BT_DBG("%s", hdev->name);
2140
8ee56540 2141 hci_dev_do_close(hdev);
ab81cbf9
JH
2142}
2143
c7741d16
MH
2144static void hci_error_reset(struct work_struct *work)
2145{
2146 struct hci_dev *hdev = container_of(work, struct hci_dev, error_reset);
2147
2148 BT_DBG("%s", hdev->name);
2149
2150 if (hdev->hw_error)
2151 hdev->hw_error(hdev, hdev->hw_error_code);
2152 else
2064ee33 2153 bt_dev_err(hdev, "hardware error 0x%2.2x", hdev->hw_error_code);
c7741d16
MH
2154
2155 if (hci_dev_do_close(hdev))
2156 return;
2157
c7741d16
MH
2158 hci_dev_do_open(hdev);
2159}
2160
35f7498a 2161void hci_uuids_clear(struct hci_dev *hdev)
2aeb9a1a 2162{
4821002c 2163 struct bt_uuid *uuid, *tmp;
2aeb9a1a 2164
4821002c
JH
2165 list_for_each_entry_safe(uuid, tmp, &hdev->uuids, list) {
2166 list_del(&uuid->list);
2aeb9a1a
JH
2167 kfree(uuid);
2168 }
2aeb9a1a
JH
2169}
2170
35f7498a 2171void hci_link_keys_clear(struct hci_dev *hdev)
55ed8ca1 2172{
0378b597 2173 struct link_key *key;
55ed8ca1 2174
0378b597
JH
2175 list_for_each_entry_rcu(key, &hdev->link_keys, list) {
2176 list_del_rcu(&key->list);
2177 kfree_rcu(key, rcu);
55ed8ca1 2178 }
55ed8ca1
JH
2179}
2180
35f7498a 2181void hci_smp_ltks_clear(struct hci_dev *hdev)
b899efaf 2182{
970d0f1b 2183 struct smp_ltk *k;
b899efaf 2184
970d0f1b
JH
2185 list_for_each_entry_rcu(k, &hdev->long_term_keys, list) {
2186 list_del_rcu(&k->list);
2187 kfree_rcu(k, rcu);
b899efaf 2188 }
b899efaf
VCG
2189}
2190
970c4e46
JH
2191void hci_smp_irks_clear(struct hci_dev *hdev)
2192{
adae20cb 2193 struct smp_irk *k;
970c4e46 2194
adae20cb
JH
2195 list_for_each_entry_rcu(k, &hdev->identity_resolving_keys, list) {
2196 list_del_rcu(&k->list);
2197 kfree_rcu(k, rcu);
970c4e46
JH
2198 }
2199}
2200
55ed8ca1
JH
2201struct link_key *hci_find_link_key(struct hci_dev *hdev, bdaddr_t *bdaddr)
2202{
8035ded4 2203 struct link_key *k;
55ed8ca1 2204
0378b597
JH
2205 rcu_read_lock();
2206 list_for_each_entry_rcu(k, &hdev->link_keys, list) {
2207 if (bacmp(bdaddr, &k->bdaddr) == 0) {
2208 rcu_read_unlock();
55ed8ca1 2209 return k;
0378b597
JH
2210 }
2211 }
2212 rcu_read_unlock();
55ed8ca1
JH
2213
2214 return NULL;
2215}
2216
745c0ce3 2217static bool hci_persistent_key(struct hci_dev *hdev, struct hci_conn *conn,
a8c5fb1a 2218 u8 key_type, u8 old_key_type)
d25e28ab
JH
2219{
2220 /* Legacy key */
2221 if (key_type < 0x03)
745c0ce3 2222 return true;
d25e28ab
JH
2223
2224 /* Debug keys are insecure so don't store them persistently */
2225 if (key_type == HCI_LK_DEBUG_COMBINATION)
745c0ce3 2226 return false;
d25e28ab
JH
2227
2228 /* Changed combination key and there's no previous one */
2229 if (key_type == HCI_LK_CHANGED_COMBINATION && old_key_type == 0xff)
745c0ce3 2230 return false;
d25e28ab
JH
2231
2232 /* Security mode 3 case */
2233 if (!conn)
745c0ce3 2234 return true;
d25e28ab 2235
e3befab9
JH
2236 /* BR/EDR key derived using SC from an LE link */
2237 if (conn->type == LE_LINK)
2238 return true;
2239
d25e28ab
JH
2240 /* Neither local nor remote side had no-bonding as requirement */
2241 if (conn->auth_type > 0x01 && conn->remote_auth > 0x01)
745c0ce3 2242 return true;
d25e28ab
JH
2243
2244 /* Local side had dedicated bonding as requirement */
2245 if (conn->auth_type == 0x02 || conn->auth_type == 0x03)
745c0ce3 2246 return true;
d25e28ab
JH
2247
2248 /* Remote side had dedicated bonding as requirement */
2249 if (conn->remote_auth == 0x02 || conn->remote_auth == 0x03)
745c0ce3 2250 return true;
d25e28ab
JH
2251
2252 /* If none of the above criteria match, then don't store the key
2253 * persistently */
745c0ce3 2254 return false;
d25e28ab
JH
2255}
2256
e804d25d 2257static u8 ltk_role(u8 type)
98a0b845 2258{
e804d25d
JH
2259 if (type == SMP_LTK)
2260 return HCI_ROLE_MASTER;
98a0b845 2261
e804d25d 2262 return HCI_ROLE_SLAVE;
98a0b845
JH
2263}
2264
f3a73d97
JH
2265struct smp_ltk *hci_find_ltk(struct hci_dev *hdev, bdaddr_t *bdaddr,
2266 u8 addr_type, u8 role)
75d262c2 2267{
c9839a11 2268 struct smp_ltk *k;
75d262c2 2269
970d0f1b
JH
2270 rcu_read_lock();
2271 list_for_each_entry_rcu(k, &hdev->long_term_keys, list) {
5378bc56
JH
2272 if (addr_type != k->bdaddr_type || bacmp(bdaddr, &k->bdaddr))
2273 continue;
2274
923e2414 2275 if (smp_ltk_is_sc(k) || ltk_role(k->type) == role) {
970d0f1b 2276 rcu_read_unlock();
75d262c2 2277 return k;
970d0f1b
JH
2278 }
2279 }
2280 rcu_read_unlock();
75d262c2
VCG
2281
2282 return NULL;
2283}
75d262c2 2284
970c4e46
JH
2285struct smp_irk *hci_find_irk_by_rpa(struct hci_dev *hdev, bdaddr_t *rpa)
2286{
2287 struct smp_irk *irk;
2288
adae20cb
JH
2289 rcu_read_lock();
2290 list_for_each_entry_rcu(irk, &hdev->identity_resolving_keys, list) {
2291 if (!bacmp(&irk->rpa, rpa)) {
2292 rcu_read_unlock();
970c4e46 2293 return irk;
adae20cb 2294 }
970c4e46
JH
2295 }
2296
adae20cb 2297 list_for_each_entry_rcu(irk, &hdev->identity_resolving_keys, list) {
defce9e8 2298 if (smp_irk_matches(hdev, irk->val, rpa)) {
970c4e46 2299 bacpy(&irk->rpa, rpa);
adae20cb 2300 rcu_read_unlock();
970c4e46
JH
2301 return irk;
2302 }
2303 }
adae20cb 2304 rcu_read_unlock();
970c4e46
JH
2305
2306 return NULL;
2307}
2308
2309struct smp_irk *hci_find_irk_by_addr(struct hci_dev *hdev, bdaddr_t *bdaddr,
2310 u8 addr_type)
2311{
2312 struct smp_irk *irk;
2313
6cfc9988
JH
2314 /* Identity Address must be public or static random */
2315 if (addr_type == ADDR_LE_DEV_RANDOM && (bdaddr->b[5] & 0xc0) != 0xc0)
2316 return NULL;
2317
adae20cb
JH
2318 rcu_read_lock();
2319 list_for_each_entry_rcu(irk, &hdev->identity_resolving_keys, list) {
970c4e46 2320 if (addr_type == irk->addr_type &&
adae20cb
JH
2321 bacmp(bdaddr, &irk->bdaddr) == 0) {
2322 rcu_read_unlock();
970c4e46 2323 return irk;
adae20cb 2324 }
970c4e46 2325 }
adae20cb 2326 rcu_read_unlock();
970c4e46
JH
2327
2328 return NULL;
2329}
2330
567fa2aa 2331struct link_key *hci_add_link_key(struct hci_dev *hdev, struct hci_conn *conn,
7652ff6a
JH
2332 bdaddr_t *bdaddr, u8 *val, u8 type,
2333 u8 pin_len, bool *persistent)
55ed8ca1
JH
2334{
2335 struct link_key *key, *old_key;
745c0ce3 2336 u8 old_key_type;
55ed8ca1
JH
2337
2338 old_key = hci_find_link_key(hdev, bdaddr);
2339 if (old_key) {
2340 old_key_type = old_key->type;
2341 key = old_key;
2342 } else {
12adcf3a 2343 old_key_type = conn ? conn->key_type : 0xff;
0a14ab41 2344 key = kzalloc(sizeof(*key), GFP_KERNEL);
55ed8ca1 2345 if (!key)
567fa2aa 2346 return NULL;
0378b597 2347 list_add_rcu(&key->list, &hdev->link_keys);
55ed8ca1
JH
2348 }
2349
6ed93dc6 2350 BT_DBG("%s key for %pMR type %u", hdev->name, bdaddr, type);
55ed8ca1 2351
d25e28ab
JH
2352 /* Some buggy controller combinations generate a changed
2353 * combination key for legacy pairing even when there's no
2354 * previous key */
2355 if (type == HCI_LK_CHANGED_COMBINATION &&
a8c5fb1a 2356 (!conn || conn->remote_auth == 0xff) && old_key_type == 0xff) {
d25e28ab 2357 type = HCI_LK_COMBINATION;
655fe6ec
JH
2358 if (conn)
2359 conn->key_type = type;
2360 }
d25e28ab 2361
55ed8ca1 2362 bacpy(&key->bdaddr, bdaddr);
9b3b4460 2363 memcpy(key->val, val, HCI_LINK_KEY_SIZE);
55ed8ca1
JH
2364 key->pin_len = pin_len;
2365
b6020ba0 2366 if (type == HCI_LK_CHANGED_COMBINATION)
55ed8ca1 2367 key->type = old_key_type;
4748fed2
JH
2368 else
2369 key->type = type;
2370
7652ff6a
JH
2371 if (persistent)
2372 *persistent = hci_persistent_key(hdev, conn, type,
2373 old_key_type);
4df378a1 2374
567fa2aa 2375 return key;
55ed8ca1
JH
2376}
2377
ca9142b8 2378struct smp_ltk *hci_add_ltk(struct hci_dev *hdev, bdaddr_t *bdaddr,
35d70271 2379 u8 addr_type, u8 type, u8 authenticated,
fe39c7b2 2380 u8 tk[16], u8 enc_size, __le16 ediv, __le64 rand)
75d262c2 2381{
c9839a11 2382 struct smp_ltk *key, *old_key;
e804d25d 2383 u8 role = ltk_role(type);
75d262c2 2384
f3a73d97 2385 old_key = hci_find_ltk(hdev, bdaddr, addr_type, role);
c9839a11 2386 if (old_key)
75d262c2 2387 key = old_key;
c9839a11 2388 else {
0a14ab41 2389 key = kzalloc(sizeof(*key), GFP_KERNEL);
75d262c2 2390 if (!key)
ca9142b8 2391 return NULL;
970d0f1b 2392 list_add_rcu(&key->list, &hdev->long_term_keys);
75d262c2
VCG
2393 }
2394
75d262c2 2395 bacpy(&key->bdaddr, bdaddr);
c9839a11
VCG
2396 key->bdaddr_type = addr_type;
2397 memcpy(key->val, tk, sizeof(key->val));
2398 key->authenticated = authenticated;
2399 key->ediv = ediv;
fe39c7b2 2400 key->rand = rand;
c9839a11
VCG
2401 key->enc_size = enc_size;
2402 key->type = type;
75d262c2 2403
ca9142b8 2404 return key;
75d262c2
VCG
2405}
2406
ca9142b8
JH
2407struct smp_irk *hci_add_irk(struct hci_dev *hdev, bdaddr_t *bdaddr,
2408 u8 addr_type, u8 val[16], bdaddr_t *rpa)
970c4e46
JH
2409{
2410 struct smp_irk *irk;
2411
2412 irk = hci_find_irk_by_addr(hdev, bdaddr, addr_type);
2413 if (!irk) {
2414 irk = kzalloc(sizeof(*irk), GFP_KERNEL);
2415 if (!irk)
ca9142b8 2416 return NULL;
970c4e46
JH
2417
2418 bacpy(&irk->bdaddr, bdaddr);
2419 irk->addr_type = addr_type;
2420
adae20cb 2421 list_add_rcu(&irk->list, &hdev->identity_resolving_keys);
970c4e46
JH
2422 }
2423
2424 memcpy(irk->val, val, 16);
2425 bacpy(&irk->rpa, rpa);
2426
ca9142b8 2427 return irk;
970c4e46
JH
2428}
2429
55ed8ca1
JH
2430int hci_remove_link_key(struct hci_dev *hdev, bdaddr_t *bdaddr)
2431{
2432 struct link_key *key;
2433
2434 key = hci_find_link_key(hdev, bdaddr);
2435 if (!key)
2436 return -ENOENT;
2437
6ed93dc6 2438 BT_DBG("%s removing %pMR", hdev->name, bdaddr);
55ed8ca1 2439
0378b597
JH
2440 list_del_rcu(&key->list);
2441 kfree_rcu(key, rcu);
55ed8ca1
JH
2442
2443 return 0;
2444}
2445
e0b2b27e 2446int hci_remove_ltk(struct hci_dev *hdev, bdaddr_t *bdaddr, u8 bdaddr_type)
b899efaf 2447{
970d0f1b 2448 struct smp_ltk *k;
c51ffa0b 2449 int removed = 0;
b899efaf 2450
970d0f1b 2451 list_for_each_entry_rcu(k, &hdev->long_term_keys, list) {
e0b2b27e 2452 if (bacmp(bdaddr, &k->bdaddr) || k->bdaddr_type != bdaddr_type)
b899efaf
VCG
2453 continue;
2454
6ed93dc6 2455 BT_DBG("%s removing %pMR", hdev->name, bdaddr);
b899efaf 2456
970d0f1b
JH
2457 list_del_rcu(&k->list);
2458 kfree_rcu(k, rcu);
c51ffa0b 2459 removed++;
b899efaf
VCG
2460 }
2461
c51ffa0b 2462 return removed ? 0 : -ENOENT;
b899efaf
VCG
2463}
2464
a7ec7338
JH
2465void hci_remove_irk(struct hci_dev *hdev, bdaddr_t *bdaddr, u8 addr_type)
2466{
adae20cb 2467 struct smp_irk *k;
a7ec7338 2468
adae20cb 2469 list_for_each_entry_rcu(k, &hdev->identity_resolving_keys, list) {
a7ec7338
JH
2470 if (bacmp(bdaddr, &k->bdaddr) || k->addr_type != addr_type)
2471 continue;
2472
2473 BT_DBG("%s removing %pMR", hdev->name, bdaddr);
2474
adae20cb
JH
2475 list_del_rcu(&k->list);
2476 kfree_rcu(k, rcu);
a7ec7338
JH
2477 }
2478}
2479
55e76b38
JH
2480bool hci_bdaddr_is_paired(struct hci_dev *hdev, bdaddr_t *bdaddr, u8 type)
2481{
2482 struct smp_ltk *k;
4ba9faf3 2483 struct smp_irk *irk;
55e76b38
JH
2484 u8 addr_type;
2485
2486 if (type == BDADDR_BREDR) {
2487 if (hci_find_link_key(hdev, bdaddr))
2488 return true;
2489 return false;
2490 }
2491
2492 /* Convert to HCI addr type which struct smp_ltk uses */
2493 if (type == BDADDR_LE_PUBLIC)
2494 addr_type = ADDR_LE_DEV_PUBLIC;
2495 else
2496 addr_type = ADDR_LE_DEV_RANDOM;
2497
4ba9faf3
JH
2498 irk = hci_get_irk(hdev, bdaddr, addr_type);
2499 if (irk) {
2500 bdaddr = &irk->bdaddr;
2501 addr_type = irk->addr_type;
2502 }
2503
55e76b38
JH
2504 rcu_read_lock();
2505 list_for_each_entry_rcu(k, &hdev->long_term_keys, list) {
87c8b28d
JH
2506 if (k->bdaddr_type == addr_type && !bacmp(bdaddr, &k->bdaddr)) {
2507 rcu_read_unlock();
55e76b38 2508 return true;
87c8b28d 2509 }
55e76b38
JH
2510 }
2511 rcu_read_unlock();
2512
2513 return false;
2514}
2515
6bd32326 2516/* HCI command timer function */
65cc2b49 2517static void hci_cmd_timeout(struct work_struct *work)
6bd32326 2518{
65cc2b49
MH
2519 struct hci_dev *hdev = container_of(work, struct hci_dev,
2520 cmd_timer.work);
6bd32326 2521
bda4f23a
AE
2522 if (hdev->sent_cmd) {
2523 struct hci_command_hdr *sent = (void *) hdev->sent_cmd->data;
2524 u16 opcode = __le16_to_cpu(sent->opcode);
2525
2064ee33 2526 bt_dev_err(hdev, "command 0x%4.4x tx timeout", opcode);
bda4f23a 2527 } else {
2064ee33 2528 bt_dev_err(hdev, "command tx timeout");
bda4f23a
AE
2529 }
2530
6bd32326 2531 atomic_set(&hdev->cmd_cnt, 1);
c347b765 2532 queue_work(hdev->workqueue, &hdev->cmd_work);
6bd32326
VT
2533}
2534
2763eda6 2535struct oob_data *hci_find_remote_oob_data(struct hci_dev *hdev,
6928a924 2536 bdaddr_t *bdaddr, u8 bdaddr_type)
2763eda6
SJ
2537{
2538 struct oob_data *data;
2539
6928a924
JH
2540 list_for_each_entry(data, &hdev->remote_oob_data, list) {
2541 if (bacmp(bdaddr, &data->bdaddr) != 0)
2542 continue;
2543 if (data->bdaddr_type != bdaddr_type)
2544 continue;
2545 return data;
2546 }
2763eda6
SJ
2547
2548 return NULL;
2549}
2550
6928a924
JH
2551int hci_remove_remote_oob_data(struct hci_dev *hdev, bdaddr_t *bdaddr,
2552 u8 bdaddr_type)
2763eda6
SJ
2553{
2554 struct oob_data *data;
2555
6928a924 2556 data = hci_find_remote_oob_data(hdev, bdaddr, bdaddr_type);
2763eda6
SJ
2557 if (!data)
2558 return -ENOENT;
2559
6928a924 2560 BT_DBG("%s removing %pMR (%u)", hdev->name, bdaddr, bdaddr_type);
2763eda6
SJ
2561
2562 list_del(&data->list);
2563 kfree(data);
2564
2565 return 0;
2566}
2567
35f7498a 2568void hci_remote_oob_data_clear(struct hci_dev *hdev)
2763eda6
SJ
2569{
2570 struct oob_data *data, *n;
2571
2572 list_for_each_entry_safe(data, n, &hdev->remote_oob_data, list) {
2573 list_del(&data->list);
2574 kfree(data);
2575 }
2763eda6
SJ
2576}
2577
0798872e 2578int hci_add_remote_oob_data(struct hci_dev *hdev, bdaddr_t *bdaddr,
6928a924 2579 u8 bdaddr_type, u8 *hash192, u8 *rand192,
81328d5c 2580 u8 *hash256, u8 *rand256)
2763eda6
SJ
2581{
2582 struct oob_data *data;
2583
6928a924 2584 data = hci_find_remote_oob_data(hdev, bdaddr, bdaddr_type);
2763eda6 2585 if (!data) {
0a14ab41 2586 data = kmalloc(sizeof(*data), GFP_KERNEL);
2763eda6
SJ
2587 if (!data)
2588 return -ENOMEM;
2589
2590 bacpy(&data->bdaddr, bdaddr);
6928a924 2591 data->bdaddr_type = bdaddr_type;
2763eda6
SJ
2592 list_add(&data->list, &hdev->remote_oob_data);
2593 }
2594
81328d5c
JH
2595 if (hash192 && rand192) {
2596 memcpy(data->hash192, hash192, sizeof(data->hash192));
2597 memcpy(data->rand192, rand192, sizeof(data->rand192));
f7697b16
MH
2598 if (hash256 && rand256)
2599 data->present = 0x03;
81328d5c
JH
2600 } else {
2601 memset(data->hash192, 0, sizeof(data->hash192));
2602 memset(data->rand192, 0, sizeof(data->rand192));
f7697b16
MH
2603 if (hash256 && rand256)
2604 data->present = 0x02;
2605 else
2606 data->present = 0x00;
0798872e
MH
2607 }
2608
81328d5c
JH
2609 if (hash256 && rand256) {
2610 memcpy(data->hash256, hash256, sizeof(data->hash256));
2611 memcpy(data->rand256, rand256, sizeof(data->rand256));
2612 } else {
2613 memset(data->hash256, 0, sizeof(data->hash256));
2614 memset(data->rand256, 0, sizeof(data->rand256));
f7697b16
MH
2615 if (hash192 && rand192)
2616 data->present = 0x01;
81328d5c 2617 }
0798872e 2618
6ed93dc6 2619 BT_DBG("%s for %pMR", hdev->name, bdaddr);
2763eda6
SJ
2620
2621 return 0;
2622}
2623
d2609b34
FG
2624/* This function requires the caller holds hdev->lock */
2625struct adv_info *hci_find_adv_instance(struct hci_dev *hdev, u8 instance)
2626{
2627 struct adv_info *adv_instance;
2628
2629 list_for_each_entry(adv_instance, &hdev->adv_instances, list) {
2630 if (adv_instance->instance == instance)
2631 return adv_instance;
2632 }
2633
2634 return NULL;
2635}
2636
2637/* This function requires the caller holds hdev->lock */
74b93e9f
PK
2638struct adv_info *hci_get_next_instance(struct hci_dev *hdev, u8 instance)
2639{
d2609b34
FG
2640 struct adv_info *cur_instance;
2641
2642 cur_instance = hci_find_adv_instance(hdev, instance);
2643 if (!cur_instance)
2644 return NULL;
2645
2646 if (cur_instance == list_last_entry(&hdev->adv_instances,
2647 struct adv_info, list))
2648 return list_first_entry(&hdev->adv_instances,
2649 struct adv_info, list);
2650 else
2651 return list_next_entry(cur_instance, list);
2652}
2653
2654/* This function requires the caller holds hdev->lock */
2655int hci_remove_adv_instance(struct hci_dev *hdev, u8 instance)
2656{
2657 struct adv_info *adv_instance;
2658
2659 adv_instance = hci_find_adv_instance(hdev, instance);
2660 if (!adv_instance)
2661 return -ENOENT;
2662
2663 BT_DBG("%s removing %dMR", hdev->name, instance);
2664
cab054ab
JH
2665 if (hdev->cur_adv_instance == instance) {
2666 if (hdev->adv_instance_timeout) {
2667 cancel_delayed_work(&hdev->adv_instance_expire);
2668 hdev->adv_instance_timeout = 0;
2669 }
2670 hdev->cur_adv_instance = 0x00;
5d900e46
FG
2671 }
2672
d2609b34
FG
2673 list_del(&adv_instance->list);
2674 kfree(adv_instance);
2675
2676 hdev->adv_instance_cnt--;
2677
2678 return 0;
2679}
2680
2681/* This function requires the caller holds hdev->lock */
2682void hci_adv_instances_clear(struct hci_dev *hdev)
2683{
2684 struct adv_info *adv_instance, *n;
2685
5d900e46
FG
2686 if (hdev->adv_instance_timeout) {
2687 cancel_delayed_work(&hdev->adv_instance_expire);
2688 hdev->adv_instance_timeout = 0;
2689 }
2690
d2609b34
FG
2691 list_for_each_entry_safe(adv_instance, n, &hdev->adv_instances, list) {
2692 list_del(&adv_instance->list);
2693 kfree(adv_instance);
2694 }
2695
2696 hdev->adv_instance_cnt = 0;
cab054ab 2697 hdev->cur_adv_instance = 0x00;
d2609b34
FG
2698}
2699
2700/* This function requires the caller holds hdev->lock */
2701int hci_add_adv_instance(struct hci_dev *hdev, u8 instance, u32 flags,
2702 u16 adv_data_len, u8 *adv_data,
2703 u16 scan_rsp_len, u8 *scan_rsp_data,
2704 u16 timeout, u16 duration)
2705{
2706 struct adv_info *adv_instance;
2707
2708 adv_instance = hci_find_adv_instance(hdev, instance);
2709 if (adv_instance) {
2710 memset(adv_instance->adv_data, 0,
2711 sizeof(adv_instance->adv_data));
2712 memset(adv_instance->scan_rsp_data, 0,
2713 sizeof(adv_instance->scan_rsp_data));
2714 } else {
2715 if (hdev->adv_instance_cnt >= HCI_MAX_ADV_INSTANCES ||
2716 instance < 1 || instance > HCI_MAX_ADV_INSTANCES)
2717 return -EOVERFLOW;
2718
39ecfad6 2719 adv_instance = kzalloc(sizeof(*adv_instance), GFP_KERNEL);
d2609b34
FG
2720 if (!adv_instance)
2721 return -ENOMEM;
2722
fffd38bc 2723 adv_instance->pending = true;
d2609b34
FG
2724 adv_instance->instance = instance;
2725 list_add(&adv_instance->list, &hdev->adv_instances);
2726 hdev->adv_instance_cnt++;
2727 }
2728
2729 adv_instance->flags = flags;
2730 adv_instance->adv_data_len = adv_data_len;
2731 adv_instance->scan_rsp_len = scan_rsp_len;
2732
2733 if (adv_data_len)
2734 memcpy(adv_instance->adv_data, adv_data, adv_data_len);
2735
2736 if (scan_rsp_len)
2737 memcpy(adv_instance->scan_rsp_data,
2738 scan_rsp_data, scan_rsp_len);
2739
2740 adv_instance->timeout = timeout;
5d900e46 2741 adv_instance->remaining_time = timeout;
d2609b34
FG
2742
2743 if (duration == 0)
2744 adv_instance->duration = HCI_DEFAULT_ADV_DURATION;
2745 else
2746 adv_instance->duration = duration;
2747
2748 BT_DBG("%s for %dMR", hdev->name, instance);
2749
2750 return 0;
2751}
2752
dcc36c16 2753struct bdaddr_list *hci_bdaddr_list_lookup(struct list_head *bdaddr_list,
b9ee0a78 2754 bdaddr_t *bdaddr, u8 type)
b2a66aad 2755{
8035ded4 2756 struct bdaddr_list *b;
b2a66aad 2757
dcc36c16 2758 list_for_each_entry(b, bdaddr_list, list) {
b9ee0a78 2759 if (!bacmp(&b->bdaddr, bdaddr) && b->bdaddr_type == type)
b2a66aad 2760 return b;
b9ee0a78 2761 }
b2a66aad
AJ
2762
2763 return NULL;
2764}
2765
dcc36c16 2766void hci_bdaddr_list_clear(struct list_head *bdaddr_list)
b2a66aad 2767{
7eb7404f 2768 struct bdaddr_list *b, *n;
b2a66aad 2769
7eb7404f
GT
2770 list_for_each_entry_safe(b, n, bdaddr_list, list) {
2771 list_del(&b->list);
b2a66aad
AJ
2772 kfree(b);
2773 }
b2a66aad
AJ
2774}
2775
dcc36c16 2776int hci_bdaddr_list_add(struct list_head *list, bdaddr_t *bdaddr, u8 type)
b2a66aad
AJ
2777{
2778 struct bdaddr_list *entry;
b2a66aad 2779
b9ee0a78 2780 if (!bacmp(bdaddr, BDADDR_ANY))
b2a66aad
AJ
2781 return -EBADF;
2782
dcc36c16 2783 if (hci_bdaddr_list_lookup(list, bdaddr, type))
5e762444 2784 return -EEXIST;
b2a66aad 2785
27f70f3e 2786 entry = kzalloc(sizeof(*entry), GFP_KERNEL);
5e762444
AJ
2787 if (!entry)
2788 return -ENOMEM;
b2a66aad
AJ
2789
2790 bacpy(&entry->bdaddr, bdaddr);
b9ee0a78 2791 entry->bdaddr_type = type;
b2a66aad 2792
dcc36c16 2793 list_add(&entry->list, list);
b2a66aad 2794
2a8357f2 2795 return 0;
b2a66aad
AJ
2796}
2797
dcc36c16 2798int hci_bdaddr_list_del(struct list_head *list, bdaddr_t *bdaddr, u8 type)
b2a66aad
AJ
2799{
2800 struct bdaddr_list *entry;
b2a66aad 2801
35f7498a 2802 if (!bacmp(bdaddr, BDADDR_ANY)) {
dcc36c16 2803 hci_bdaddr_list_clear(list);
35f7498a
JH
2804 return 0;
2805 }
b2a66aad 2806
dcc36c16 2807 entry = hci_bdaddr_list_lookup(list, bdaddr, type);
d2ab0ac1
MH
2808 if (!entry)
2809 return -ENOENT;
2810
2811 list_del(&entry->list);
2812 kfree(entry);
2813
2814 return 0;
2815}
2816
15819a70
AG
2817/* This function requires the caller holds hdev->lock */
2818struct hci_conn_params *hci_conn_params_lookup(struct hci_dev *hdev,
2819 bdaddr_t *addr, u8 addr_type)
2820{
2821 struct hci_conn_params *params;
2822
2823 list_for_each_entry(params, &hdev->le_conn_params, list) {
2824 if (bacmp(&params->addr, addr) == 0 &&
2825 params->addr_type == addr_type) {
2826 return params;
2827 }
2828 }
2829
2830 return NULL;
2831}
2832
4b10966f 2833/* This function requires the caller holds hdev->lock */
501f8827
JH
2834struct hci_conn_params *hci_pend_le_action_lookup(struct list_head *list,
2835 bdaddr_t *addr, u8 addr_type)
a9b0a04c 2836{
912b42ef 2837 struct hci_conn_params *param;
a9b0a04c 2838
501f8827 2839 list_for_each_entry(param, list, action) {
912b42ef
JH
2840 if (bacmp(&param->addr, addr) == 0 &&
2841 param->addr_type == addr_type)
2842 return param;
4b10966f
MH
2843 }
2844
2845 return NULL;
a9b0a04c
AG
2846}
2847
15819a70 2848/* This function requires the caller holds hdev->lock */
51d167c0
MH
2849struct hci_conn_params *hci_conn_params_add(struct hci_dev *hdev,
2850 bdaddr_t *addr, u8 addr_type)
15819a70
AG
2851{
2852 struct hci_conn_params *params;
2853
2854 params = hci_conn_params_lookup(hdev, addr, addr_type);
cef952ce 2855 if (params)
51d167c0 2856 return params;
15819a70
AG
2857
2858 params = kzalloc(sizeof(*params), GFP_KERNEL);
2859 if (!params) {
2064ee33 2860 bt_dev_err(hdev, "out of memory");
51d167c0 2861 return NULL;
15819a70
AG
2862 }
2863
2864 bacpy(&params->addr, addr);
2865 params->addr_type = addr_type;
cef952ce
AG
2866
2867 list_add(&params->list, &hdev->le_conn_params);
93450c75 2868 INIT_LIST_HEAD(&params->action);
cef952ce 2869
bf5b3c8b
MH
2870 params->conn_min_interval = hdev->le_conn_min_interval;
2871 params->conn_max_interval = hdev->le_conn_max_interval;
2872 params->conn_latency = hdev->le_conn_latency;
2873 params->supervision_timeout = hdev->le_supv_timeout;
2874 params->auto_connect = HCI_AUTO_CONN_DISABLED;
2875
2876 BT_DBG("addr %pMR (type %u)", addr, addr_type);
2877
51d167c0 2878 return params;
bf5b3c8b
MH
2879}
2880
f6c63249 2881static void hci_conn_params_free(struct hci_conn_params *params)
15819a70 2882{
f8aaf9b6 2883 if (params->conn) {
f161dd41 2884 hci_conn_drop(params->conn);
f8aaf9b6
JH
2885 hci_conn_put(params->conn);
2886 }
f161dd41 2887
95305baa 2888 list_del(&params->action);
15819a70
AG
2889 list_del(&params->list);
2890 kfree(params);
f6c63249
JH
2891}
2892
2893/* This function requires the caller holds hdev->lock */
2894void hci_conn_params_del(struct hci_dev *hdev, bdaddr_t *addr, u8 addr_type)
2895{
2896 struct hci_conn_params *params;
2897
2898 params = hci_conn_params_lookup(hdev, addr, addr_type);
2899 if (!params)
2900 return;
2901
2902 hci_conn_params_free(params);
15819a70 2903
95305baa
JH
2904 hci_update_background_scan(hdev);
2905
15819a70
AG
2906 BT_DBG("addr %pMR (type %u)", addr, addr_type);
2907}
2908
2909/* This function requires the caller holds hdev->lock */
55af49a8 2910void hci_conn_params_clear_disabled(struct hci_dev *hdev)
15819a70
AG
2911{
2912 struct hci_conn_params *params, *tmp;
2913
2914 list_for_each_entry_safe(params, tmp, &hdev->le_conn_params, list) {
55af49a8
JH
2915 if (params->auto_connect != HCI_AUTO_CONN_DISABLED)
2916 continue;
f75113a2
JP
2917
2918 /* If trying to estabilish one time connection to disabled
2919 * device, leave the params, but mark them as just once.
2920 */
2921 if (params->explicit_connect) {
2922 params->auto_connect = HCI_AUTO_CONN_EXPLICIT;
2923 continue;
2924 }
2925
15819a70
AG
2926 list_del(&params->list);
2927 kfree(params);
2928 }
2929
55af49a8 2930 BT_DBG("All LE disabled connection parameters were removed");
77a77a30
AG
2931}
2932
2933/* This function requires the caller holds hdev->lock */
030e7f81 2934static void hci_conn_params_clear_all(struct hci_dev *hdev)
77a77a30 2935{
15819a70 2936 struct hci_conn_params *params, *tmp;
77a77a30 2937
f6c63249
JH
2938 list_for_each_entry_safe(params, tmp, &hdev->le_conn_params, list)
2939 hci_conn_params_free(params);
77a77a30 2940
15819a70 2941 BT_DBG("All LE connection parameters were removed");
77a77a30
AG
2942}
2943
a1f4c318
JH
2944/* Copy the Identity Address of the controller.
2945 *
2946 * If the controller has a public BD_ADDR, then by default use that one.
2947 * If this is a LE only controller without a public address, default to
2948 * the static random address.
2949 *
2950 * For debugging purposes it is possible to force controllers with a
2951 * public address to use the static random address instead.
50b5b952
MH
2952 *
2953 * In case BR/EDR has been disabled on a dual-mode controller and
2954 * userspace has configured a static address, then that address
2955 * becomes the identity address instead of the public BR/EDR address.
a1f4c318
JH
2956 */
2957void hci_copy_identity_address(struct hci_dev *hdev, bdaddr_t *bdaddr,
2958 u8 *bdaddr_type)
2959{
b7cb93e5 2960 if (hci_dev_test_flag(hdev, HCI_FORCE_STATIC_ADDR) ||
50b5b952 2961 !bacmp(&hdev->bdaddr, BDADDR_ANY) ||
d7a5a11d 2962 (!hci_dev_test_flag(hdev, HCI_BREDR_ENABLED) &&
50b5b952 2963 bacmp(&hdev->static_addr, BDADDR_ANY))) {
a1f4c318
JH
2964 bacpy(bdaddr, &hdev->static_addr);
2965 *bdaddr_type = ADDR_LE_DEV_RANDOM;
2966 } else {
2967 bacpy(bdaddr, &hdev->bdaddr);
2968 *bdaddr_type = ADDR_LE_DEV_PUBLIC;
2969 }
2970}
2971
9be0dab7
DH
2972/* Alloc HCI device */
2973struct hci_dev *hci_alloc_dev(void)
2974{
2975 struct hci_dev *hdev;
2976
27f70f3e 2977 hdev = kzalloc(sizeof(*hdev), GFP_KERNEL);
9be0dab7
DH
2978 if (!hdev)
2979 return NULL;
2980
b1b813d4
DH
2981 hdev->pkt_type = (HCI_DM1 | HCI_DH1 | HCI_HV1);
2982 hdev->esco_type = (ESCO_HV1);
2983 hdev->link_mode = (HCI_LM_ACCEPT);
b4cb9fb2
MH
2984 hdev->num_iac = 0x01; /* One IAC support is mandatory */
2985 hdev->io_capability = 0x03; /* No Input No Output */
96c2103a 2986 hdev->manufacturer = 0xffff; /* Default to internal use */
bbaf444a
JH
2987 hdev->inq_tx_power = HCI_TX_POWER_INVALID;
2988 hdev->adv_tx_power = HCI_TX_POWER_INVALID;
d2609b34
FG
2989 hdev->adv_instance_cnt = 0;
2990 hdev->cur_adv_instance = 0x00;
5d900e46 2991 hdev->adv_instance_timeout = 0;
b1b813d4 2992
b1b813d4
DH
2993 hdev->sniff_max_interval = 800;
2994 hdev->sniff_min_interval = 80;
2995
3f959d46 2996 hdev->le_adv_channel_map = 0x07;
628531c9
GL
2997 hdev->le_adv_min_interval = 0x0800;
2998 hdev->le_adv_max_interval = 0x0800;
bef64738
MH
2999 hdev->le_scan_interval = 0x0060;
3000 hdev->le_scan_window = 0x0030;
b48c3b59
JH
3001 hdev->le_conn_min_interval = 0x0018;
3002 hdev->le_conn_max_interval = 0x0028;
04fb7d90
MH
3003 hdev->le_conn_latency = 0x0000;
3004 hdev->le_supv_timeout = 0x002a;
a8e1bfaa
MH
3005 hdev->le_def_tx_len = 0x001b;
3006 hdev->le_def_tx_time = 0x0148;
3007 hdev->le_max_tx_len = 0x001b;
3008 hdev->le_max_tx_time = 0x0148;
3009 hdev->le_max_rx_len = 0x001b;
3010 hdev->le_max_rx_time = 0x0148;
bef64738 3011
d6bfd59c 3012 hdev->rpa_timeout = HCI_DEFAULT_RPA_TIMEOUT;
b9a7a61e 3013 hdev->discov_interleaved_timeout = DISCOV_INTERLEAVED_TIMEOUT;
31ad1691
AK
3014 hdev->conn_info_min_age = DEFAULT_CONN_INFO_MIN_AGE;
3015 hdev->conn_info_max_age = DEFAULT_CONN_INFO_MAX_AGE;
d6bfd59c 3016
b1b813d4
DH
3017 mutex_init(&hdev->lock);
3018 mutex_init(&hdev->req_lock);
3019
3020 INIT_LIST_HEAD(&hdev->mgmt_pending);
3021 INIT_LIST_HEAD(&hdev->blacklist);
6659358e 3022 INIT_LIST_HEAD(&hdev->whitelist);
b1b813d4
DH
3023 INIT_LIST_HEAD(&hdev->uuids);
3024 INIT_LIST_HEAD(&hdev->link_keys);
3025 INIT_LIST_HEAD(&hdev->long_term_keys);
970c4e46 3026 INIT_LIST_HEAD(&hdev->identity_resolving_keys);
b1b813d4 3027 INIT_LIST_HEAD(&hdev->remote_oob_data);
d2ab0ac1 3028 INIT_LIST_HEAD(&hdev->le_white_list);
15819a70 3029 INIT_LIST_HEAD(&hdev->le_conn_params);
77a77a30 3030 INIT_LIST_HEAD(&hdev->pend_le_conns);
66f8455a 3031 INIT_LIST_HEAD(&hdev->pend_le_reports);
6b536b5e 3032 INIT_LIST_HEAD(&hdev->conn_hash.list);
d2609b34 3033 INIT_LIST_HEAD(&hdev->adv_instances);
b1b813d4
DH
3034
3035 INIT_WORK(&hdev->rx_work, hci_rx_work);
3036 INIT_WORK(&hdev->cmd_work, hci_cmd_work);
3037 INIT_WORK(&hdev->tx_work, hci_tx_work);
3038 INIT_WORK(&hdev->power_on, hci_power_on);
c7741d16 3039 INIT_WORK(&hdev->error_reset, hci_error_reset);
b1b813d4 3040
b1b813d4 3041 INIT_DELAYED_WORK(&hdev->power_off, hci_power_off);
b1b813d4 3042
b1b813d4
DH
3043 skb_queue_head_init(&hdev->rx_q);
3044 skb_queue_head_init(&hdev->cmd_q);
3045 skb_queue_head_init(&hdev->raw_q);
3046
3047 init_waitqueue_head(&hdev->req_wait_q);
3048
65cc2b49 3049 INIT_DELAYED_WORK(&hdev->cmd_timer, hci_cmd_timeout);
b1b813d4 3050
5fc16cc4
JH
3051 hci_request_setup(hdev);
3052
b1b813d4
DH
3053 hci_init_sysfs(hdev);
3054 discovery_init(hdev);
9be0dab7
DH
3055
3056 return hdev;
3057}
3058EXPORT_SYMBOL(hci_alloc_dev);
3059
3060/* Free HCI device */
3061void hci_free_dev(struct hci_dev *hdev)
3062{
9be0dab7
DH
3063 /* will free via device release */
3064 put_device(&hdev->dev);
3065}
3066EXPORT_SYMBOL(hci_free_dev);
3067
1da177e4
LT
3068/* Register HCI device */
3069int hci_register_dev(struct hci_dev *hdev)
3070{
b1b813d4 3071 int id, error;
1da177e4 3072
74292d5a 3073 if (!hdev->open || !hdev->close || !hdev->send)
1da177e4
LT
3074 return -EINVAL;
3075
08add513
MM
3076 /* Do not allow HCI_AMP devices to register at index 0,
3077 * so the index can be used as the AMP controller ID.
3078 */
3df92b31 3079 switch (hdev->dev_type) {
ca8bee5d 3080 case HCI_PRIMARY:
3df92b31
SL
3081 id = ida_simple_get(&hci_index_ida, 0, 0, GFP_KERNEL);
3082 break;
3083 case HCI_AMP:
3084 id = ida_simple_get(&hci_index_ida, 1, 0, GFP_KERNEL);
3085 break;
3086 default:
3087 return -EINVAL;
1da177e4 3088 }
8e87d142 3089
3df92b31
SL
3090 if (id < 0)
3091 return id;
3092
1da177e4
LT
3093 sprintf(hdev->name, "hci%d", id);
3094 hdev->id = id;
2d8b3a11
AE
3095
3096 BT_DBG("%p name %s bus %d", hdev, hdev->name, hdev->bus);
3097
29e2dd0d 3098 hdev->workqueue = alloc_ordered_workqueue("%s", WQ_HIGHPRI, hdev->name);
33ca954d
DH
3099 if (!hdev->workqueue) {
3100 error = -ENOMEM;
3101 goto err;
3102 }
f48fd9c8 3103
29e2dd0d
TH
3104 hdev->req_workqueue = alloc_ordered_workqueue("%s", WQ_HIGHPRI,
3105 hdev->name);
6ead1bbc
JH
3106 if (!hdev->req_workqueue) {
3107 destroy_workqueue(hdev->workqueue);
3108 error = -ENOMEM;
3109 goto err;
3110 }
3111
0153e2ec
MH
3112 if (!IS_ERR_OR_NULL(bt_debugfs))
3113 hdev->debugfs = debugfs_create_dir(hdev->name, bt_debugfs);
3114
bdc3e0f1
MH
3115 dev_set_name(&hdev->dev, "%s", hdev->name);
3116
3117 error = device_add(&hdev->dev);
33ca954d 3118 if (error < 0)
54506918 3119 goto err_wqueue;
1da177e4 3120
6d5d2ee6
HK
3121 hci_leds_init(hdev);
3122
611b30f7 3123 hdev->rfkill = rfkill_alloc(hdev->name, &hdev->dev,
a8c5fb1a
GP
3124 RFKILL_TYPE_BLUETOOTH, &hci_rfkill_ops,
3125 hdev);
611b30f7
MH
3126 if (hdev->rfkill) {
3127 if (rfkill_register(hdev->rfkill) < 0) {
3128 rfkill_destroy(hdev->rfkill);
3129 hdev->rfkill = NULL;
3130 }
3131 }
3132
5e130367 3133 if (hdev->rfkill && rfkill_blocked(hdev->rfkill))
a1536da2 3134 hci_dev_set_flag(hdev, HCI_RFKILLED);
5e130367 3135
a1536da2
MH
3136 hci_dev_set_flag(hdev, HCI_SETUP);
3137 hci_dev_set_flag(hdev, HCI_AUTO_OFF);
ce2be9ac 3138
ca8bee5d 3139 if (hdev->dev_type == HCI_PRIMARY) {
56f87901
JH
3140 /* Assume BR/EDR support until proven otherwise (such as
3141 * through reading supported features during init.
3142 */
a1536da2 3143 hci_dev_set_flag(hdev, HCI_BREDR_ENABLED);
56f87901 3144 }
ce2be9ac 3145
fcee3377
GP
3146 write_lock(&hci_dev_list_lock);
3147 list_add(&hdev->list, &hci_dev_list);
3148 write_unlock(&hci_dev_list_lock);
3149
4a964404
MH
3150 /* Devices that are marked for raw-only usage are unconfigured
3151 * and should not be included in normal operation.
fee746b0
MH
3152 */
3153 if (test_bit(HCI_QUIRK_RAW_DEVICE, &hdev->quirks))
a1536da2 3154 hci_dev_set_flag(hdev, HCI_UNCONFIGURED);
fee746b0 3155
05fcd4c4 3156 hci_sock_dev_event(hdev, HCI_DEV_REG);
dc946bd8 3157 hci_dev_hold(hdev);
1da177e4 3158
19202573 3159 queue_work(hdev->req_workqueue, &hdev->power_on);
fbe96d6f 3160
1da177e4 3161 return id;
f48fd9c8 3162
33ca954d
DH
3163err_wqueue:
3164 destroy_workqueue(hdev->workqueue);
6ead1bbc 3165 destroy_workqueue(hdev->req_workqueue);
33ca954d 3166err:
3df92b31 3167 ida_simple_remove(&hci_index_ida, hdev->id);
f48fd9c8 3168
33ca954d 3169 return error;
1da177e4
LT
3170}
3171EXPORT_SYMBOL(hci_register_dev);
3172
3173/* Unregister HCI device */
59735631 3174void hci_unregister_dev(struct hci_dev *hdev)
1da177e4 3175{
2d7cc19e 3176 int id;
ef222013 3177
c13854ce 3178 BT_DBG("%p name %s bus %d", hdev, hdev->name, hdev->bus);
1da177e4 3179
a1536da2 3180 hci_dev_set_flag(hdev, HCI_UNREGISTER);
94324962 3181
3df92b31
SL
3182 id = hdev->id;
3183
f20d09d5 3184 write_lock(&hci_dev_list_lock);
1da177e4 3185 list_del(&hdev->list);
f20d09d5 3186 write_unlock(&hci_dev_list_lock);
1da177e4 3187
b9b5ef18
GP
3188 cancel_work_sync(&hdev->power_on);
3189
bf389cab
JS
3190 hci_dev_do_close(hdev);
3191
ab81cbf9 3192 if (!test_bit(HCI_INIT, &hdev->flags) &&
d7a5a11d
MH
3193 !hci_dev_test_flag(hdev, HCI_SETUP) &&
3194 !hci_dev_test_flag(hdev, HCI_CONFIG)) {
09fd0de5 3195 hci_dev_lock(hdev);
744cf19e 3196 mgmt_index_removed(hdev);
09fd0de5 3197 hci_dev_unlock(hdev);
56e5cb86 3198 }
ab81cbf9 3199
2e58ef3e
JH
3200 /* mgmt_index_removed should take care of emptying the
3201 * pending list */
3202 BUG_ON(!list_empty(&hdev->mgmt_pending));
3203
05fcd4c4 3204 hci_sock_dev_event(hdev, HCI_DEV_UNREG);
1da177e4 3205
611b30f7
MH
3206 if (hdev->rfkill) {
3207 rfkill_unregister(hdev->rfkill);
3208 rfkill_destroy(hdev->rfkill);
3209 }
3210
bdc3e0f1 3211 device_del(&hdev->dev);
147e2d59 3212
0153e2ec 3213 debugfs_remove_recursive(hdev->debugfs);
5177a838
MH
3214 kfree_const(hdev->hw_info);
3215 kfree_const(hdev->fw_info);
0153e2ec 3216
f48fd9c8 3217 destroy_workqueue(hdev->workqueue);
6ead1bbc 3218 destroy_workqueue(hdev->req_workqueue);
f48fd9c8 3219
09fd0de5 3220 hci_dev_lock(hdev);
dcc36c16 3221 hci_bdaddr_list_clear(&hdev->blacklist);
6659358e 3222 hci_bdaddr_list_clear(&hdev->whitelist);
2aeb9a1a 3223 hci_uuids_clear(hdev);
55ed8ca1 3224 hci_link_keys_clear(hdev);
b899efaf 3225 hci_smp_ltks_clear(hdev);
970c4e46 3226 hci_smp_irks_clear(hdev);
2763eda6 3227 hci_remote_oob_data_clear(hdev);
d2609b34 3228 hci_adv_instances_clear(hdev);
dcc36c16 3229 hci_bdaddr_list_clear(&hdev->le_white_list);
373110c5 3230 hci_conn_params_clear_all(hdev);
22078800 3231 hci_discovery_filter_clear(hdev);
09fd0de5 3232 hci_dev_unlock(hdev);
e2e0cacb 3233
dc946bd8 3234 hci_dev_put(hdev);
3df92b31
SL
3235
3236 ida_simple_remove(&hci_index_ida, id);
1da177e4
LT
3237}
3238EXPORT_SYMBOL(hci_unregister_dev);
3239
3240/* Suspend HCI device */
3241int hci_suspend_dev(struct hci_dev *hdev)
3242{
05fcd4c4 3243 hci_sock_dev_event(hdev, HCI_DEV_SUSPEND);
1da177e4
LT
3244 return 0;
3245}
3246EXPORT_SYMBOL(hci_suspend_dev);
3247
3248/* Resume HCI device */
3249int hci_resume_dev(struct hci_dev *hdev)
3250{
05fcd4c4 3251 hci_sock_dev_event(hdev, HCI_DEV_RESUME);
1da177e4
LT
3252 return 0;
3253}
3254EXPORT_SYMBOL(hci_resume_dev);
3255
75e0569f
MH
3256/* Reset HCI device */
3257int hci_reset_dev(struct hci_dev *hdev)
3258{
3259 const u8 hw_err[] = { HCI_EV_HARDWARE_ERROR, 0x01, 0x00 };
3260 struct sk_buff *skb;
3261
3262 skb = bt_skb_alloc(3, GFP_ATOMIC);
3263 if (!skb)
3264 return -ENOMEM;
3265
d79f34e3 3266 hci_skb_pkt_type(skb) = HCI_EVENT_PKT;
59ae1d12 3267 skb_put_data(skb, hw_err, 3);
75e0569f
MH
3268
3269 /* Send Hardware Error to upper stack */
3270 return hci_recv_frame(hdev, skb);
3271}
3272EXPORT_SYMBOL(hci_reset_dev);
3273
76bca880 3274/* Receive frame from HCI drivers */
e1a26170 3275int hci_recv_frame(struct hci_dev *hdev, struct sk_buff *skb)
76bca880 3276{
76bca880 3277 if (!hdev || (!test_bit(HCI_UP, &hdev->flags)
a8c5fb1a 3278 && !test_bit(HCI_INIT, &hdev->flags))) {
76bca880
MH
3279 kfree_skb(skb);
3280 return -ENXIO;
3281 }
3282
d79f34e3
MH
3283 if (hci_skb_pkt_type(skb) != HCI_EVENT_PKT &&
3284 hci_skb_pkt_type(skb) != HCI_ACLDATA_PKT &&
3285 hci_skb_pkt_type(skb) != HCI_SCODATA_PKT) {
fe806dce
MH
3286 kfree_skb(skb);
3287 return -EINVAL;
3288 }
3289
d82603c6 3290 /* Incoming skb */
76bca880
MH
3291 bt_cb(skb)->incoming = 1;
3292
3293 /* Time stamp */
3294 __net_timestamp(skb);
3295
76bca880 3296 skb_queue_tail(&hdev->rx_q, skb);
b78752cc 3297 queue_work(hdev->workqueue, &hdev->rx_work);
c78ae283 3298
76bca880
MH
3299 return 0;
3300}
3301EXPORT_SYMBOL(hci_recv_frame);
3302
e875ff84
MH
3303/* Receive diagnostic message from HCI drivers */
3304int hci_recv_diag(struct hci_dev *hdev, struct sk_buff *skb)
3305{
581d6fd6 3306 /* Mark as diagnostic packet */
d79f34e3 3307 hci_skb_pkt_type(skb) = HCI_DIAG_PKT;
581d6fd6 3308
e875ff84
MH
3309 /* Time stamp */
3310 __net_timestamp(skb);
3311
581d6fd6
MH
3312 skb_queue_tail(&hdev->rx_q, skb);
3313 queue_work(hdev->workqueue, &hdev->rx_work);
e875ff84 3314
e875ff84
MH
3315 return 0;
3316}
3317EXPORT_SYMBOL(hci_recv_diag);
3318
5177a838
MH
3319void hci_set_hw_info(struct hci_dev *hdev, const char *fmt, ...)
3320{
3321 va_list vargs;
3322
3323 va_start(vargs, fmt);
3324 kfree_const(hdev->hw_info);
3325 hdev->hw_info = kvasprintf_const(GFP_KERNEL, fmt, vargs);
3326 va_end(vargs);
3327}
3328EXPORT_SYMBOL(hci_set_hw_info);
3329
3330void hci_set_fw_info(struct hci_dev *hdev, const char *fmt, ...)
3331{
3332 va_list vargs;
3333
3334 va_start(vargs, fmt);
3335 kfree_const(hdev->fw_info);
3336 hdev->fw_info = kvasprintf_const(GFP_KERNEL, fmt, vargs);
3337 va_end(vargs);
3338}
3339EXPORT_SYMBOL(hci_set_fw_info);
3340
1da177e4
LT
3341/* ---- Interface to upper protocols ---- */
3342
1da177e4
LT
3343int hci_register_cb(struct hci_cb *cb)
3344{
3345 BT_DBG("%p name %s", cb, cb->name);
3346
fba7ecf0 3347 mutex_lock(&hci_cb_list_lock);
00629e0f 3348 list_add_tail(&cb->list, &hci_cb_list);
fba7ecf0 3349 mutex_unlock(&hci_cb_list_lock);
1da177e4
LT
3350
3351 return 0;
3352}
3353EXPORT_SYMBOL(hci_register_cb);
3354
3355int hci_unregister_cb(struct hci_cb *cb)
3356{
3357 BT_DBG("%p name %s", cb, cb->name);
3358
fba7ecf0 3359 mutex_lock(&hci_cb_list_lock);
1da177e4 3360 list_del(&cb->list);
fba7ecf0 3361 mutex_unlock(&hci_cb_list_lock);
1da177e4
LT
3362
3363 return 0;
3364}
3365EXPORT_SYMBOL(hci_unregister_cb);
3366
51086991 3367static void hci_send_frame(struct hci_dev *hdev, struct sk_buff *skb)
1da177e4 3368{
cdc52faa
MH
3369 int err;
3370
d79f34e3
MH
3371 BT_DBG("%s type %d len %d", hdev->name, hci_skb_pkt_type(skb),
3372 skb->len);
1da177e4 3373
cd82e61c
MH
3374 /* Time stamp */
3375 __net_timestamp(skb);
1da177e4 3376
cd82e61c
MH
3377 /* Send copy to monitor */
3378 hci_send_to_monitor(hdev, skb);
3379
3380 if (atomic_read(&hdev->promisc)) {
3381 /* Send copy to the sockets */
470fe1b5 3382 hci_send_to_sock(hdev, skb);
1da177e4
LT
3383 }
3384
3385 /* Get rid of skb owner, prior to sending to the driver. */
3386 skb_orphan(skb);
3387
73d0d3c8
MH
3388 if (!test_bit(HCI_RUNNING, &hdev->flags)) {
3389 kfree_skb(skb);
3390 return;
3391 }
3392
cdc52faa
MH
3393 err = hdev->send(hdev, skb);
3394 if (err < 0) {
2064ee33 3395 bt_dev_err(hdev, "sending frame failed (%d)", err);
cdc52faa
MH
3396 kfree_skb(skb);
3397 }
1da177e4
LT
3398}
3399
1ca3a9d0 3400/* Send HCI command */
07dc93dd
JH
3401int hci_send_cmd(struct hci_dev *hdev, __u16 opcode, __u32 plen,
3402 const void *param)
1ca3a9d0
JH
3403{
3404 struct sk_buff *skb;
3405
3406 BT_DBG("%s opcode 0x%4.4x plen %d", hdev->name, opcode, plen);
3407
3408 skb = hci_prepare_cmd(hdev, opcode, plen, param);
3409 if (!skb) {
2064ee33 3410 bt_dev_err(hdev, "no memory for command");
1ca3a9d0
JH
3411 return -ENOMEM;
3412 }
3413
49c922bb 3414 /* Stand-alone HCI commands must be flagged as
11714b3d
JH
3415 * single-command requests.
3416 */
44d27137 3417 bt_cb(skb)->hci.req_flags |= HCI_REQ_START;
11714b3d 3418
1da177e4 3419 skb_queue_tail(&hdev->cmd_q, skb);
c347b765 3420 queue_work(hdev->workqueue, &hdev->cmd_work);
1da177e4
LT
3421
3422 return 0;
3423}
1da177e4
LT
3424
3425/* Get data from the previously sent command */
a9de9248 3426void *hci_sent_cmd_data(struct hci_dev *hdev, __u16 opcode)
1da177e4
LT
3427{
3428 struct hci_command_hdr *hdr;
3429
3430 if (!hdev->sent_cmd)
3431 return NULL;
3432
3433 hdr = (void *) hdev->sent_cmd->data;
3434
a9de9248 3435 if (hdr->opcode != cpu_to_le16(opcode))
1da177e4
LT
3436 return NULL;
3437
f0e09510 3438 BT_DBG("%s opcode 0x%4.4x", hdev->name, opcode);
1da177e4
LT
3439
3440 return hdev->sent_cmd->data + HCI_COMMAND_HDR_SIZE;
3441}
3442
fbef168f
LP
3443/* Send HCI command and wait for command commplete event */
3444struct sk_buff *hci_cmd_sync(struct hci_dev *hdev, u16 opcode, u32 plen,
3445 const void *param, u32 timeout)
3446{
3447 struct sk_buff *skb;
3448
3449 if (!test_bit(HCI_UP, &hdev->flags))
3450 return ERR_PTR(-ENETDOWN);
3451
3452 bt_dev_dbg(hdev, "opcode 0x%4.4x plen %d", opcode, plen);
3453
b504430c 3454 hci_req_sync_lock(hdev);
fbef168f 3455 skb = __hci_cmd_sync(hdev, opcode, plen, param, timeout);
b504430c 3456 hci_req_sync_unlock(hdev);
fbef168f
LP
3457
3458 return skb;
3459}
3460EXPORT_SYMBOL(hci_cmd_sync);
3461
1da177e4
LT
3462/* Send ACL data */
3463static void hci_add_acl_hdr(struct sk_buff *skb, __u16 handle, __u16 flags)
3464{
3465 struct hci_acl_hdr *hdr;
3466 int len = skb->len;
3467
badff6d0
ACM
3468 skb_push(skb, HCI_ACL_HDR_SIZE);
3469 skb_reset_transport_header(skb);
9c70220b 3470 hdr = (struct hci_acl_hdr *)skb_transport_header(skb);
aca3192c
YH
3471 hdr->handle = cpu_to_le16(hci_handle_pack(handle, flags));
3472 hdr->dlen = cpu_to_le16(len);
1da177e4
LT
3473}
3474
ee22be7e 3475static void hci_queue_acl(struct hci_chan *chan, struct sk_buff_head *queue,
a8c5fb1a 3476 struct sk_buff *skb, __u16 flags)
1da177e4 3477{
ee22be7e 3478 struct hci_conn *conn = chan->conn;
1da177e4
LT
3479 struct hci_dev *hdev = conn->hdev;
3480 struct sk_buff *list;
3481
087bfd99
GP
3482 skb->len = skb_headlen(skb);
3483 skb->data_len = 0;
3484
d79f34e3 3485 hci_skb_pkt_type(skb) = HCI_ACLDATA_PKT;
204a6e54
AE
3486
3487 switch (hdev->dev_type) {
ca8bee5d 3488 case HCI_PRIMARY:
204a6e54
AE
3489 hci_add_acl_hdr(skb, conn->handle, flags);
3490 break;
3491 case HCI_AMP:
3492 hci_add_acl_hdr(skb, chan->handle, flags);
3493 break;
3494 default:
2064ee33 3495 bt_dev_err(hdev, "unknown dev_type %d", hdev->dev_type);
204a6e54
AE
3496 return;
3497 }
087bfd99 3498
70f23020
AE
3499 list = skb_shinfo(skb)->frag_list;
3500 if (!list) {
1da177e4
LT
3501 /* Non fragmented */
3502 BT_DBG("%s nonfrag skb %p len %d", hdev->name, skb, skb->len);
3503
73d80deb 3504 skb_queue_tail(queue, skb);
1da177e4
LT
3505 } else {
3506 /* Fragmented */
3507 BT_DBG("%s frag %p len %d", hdev->name, skb, skb->len);
3508
3509 skb_shinfo(skb)->frag_list = NULL;
3510
9cfd5a23
JR
3511 /* Queue all fragments atomically. We need to use spin_lock_bh
3512 * here because of 6LoWPAN links, as there this function is
3513 * called from softirq and using normal spin lock could cause
3514 * deadlocks.
3515 */
3516 spin_lock_bh(&queue->lock);
1da177e4 3517
73d80deb 3518 __skb_queue_tail(queue, skb);
e702112f
AE
3519
3520 flags &= ~ACL_START;
3521 flags |= ACL_CONT;
1da177e4
LT
3522 do {
3523 skb = list; list = list->next;
8e87d142 3524
d79f34e3 3525 hci_skb_pkt_type(skb) = HCI_ACLDATA_PKT;
e702112f 3526 hci_add_acl_hdr(skb, conn->handle, flags);
1da177e4
LT
3527
3528 BT_DBG("%s frag %p len %d", hdev->name, skb, skb->len);
3529
73d80deb 3530 __skb_queue_tail(queue, skb);
1da177e4
LT
3531 } while (list);
3532
9cfd5a23 3533 spin_unlock_bh(&queue->lock);
1da177e4 3534 }
73d80deb
LAD
3535}
3536
3537void hci_send_acl(struct hci_chan *chan, struct sk_buff *skb, __u16 flags)
3538{
ee22be7e 3539 struct hci_dev *hdev = chan->conn->hdev;
73d80deb 3540
f0e09510 3541 BT_DBG("%s chan %p flags 0x%4.4x", hdev->name, chan, flags);
73d80deb 3542
ee22be7e 3543 hci_queue_acl(chan, &chan->data_q, skb, flags);
1da177e4 3544
3eff45ea 3545 queue_work(hdev->workqueue, &hdev->tx_work);
1da177e4 3546}
1da177e4
LT
3547
3548/* Send SCO data */
0d861d8b 3549void hci_send_sco(struct hci_conn *conn, struct sk_buff *skb)
1da177e4
LT
3550{
3551 struct hci_dev *hdev = conn->hdev;
3552 struct hci_sco_hdr hdr;
3553
3554 BT_DBG("%s len %d", hdev->name, skb->len);
3555
aca3192c 3556 hdr.handle = cpu_to_le16(conn->handle);
1da177e4
LT
3557 hdr.dlen = skb->len;
3558
badff6d0
ACM
3559 skb_push(skb, HCI_SCO_HDR_SIZE);
3560 skb_reset_transport_header(skb);
9c70220b 3561 memcpy(skb_transport_header(skb), &hdr, HCI_SCO_HDR_SIZE);
1da177e4 3562
d79f34e3 3563 hci_skb_pkt_type(skb) = HCI_SCODATA_PKT;
c78ae283 3564
1da177e4 3565 skb_queue_tail(&conn->data_q, skb);
3eff45ea 3566 queue_work(hdev->workqueue, &hdev->tx_work);
1da177e4 3567}
1da177e4
LT
3568
3569/* ---- HCI TX task (outgoing data) ---- */
3570
3571/* HCI Connection scheduler */
6039aa73
GP
3572static struct hci_conn *hci_low_sent(struct hci_dev *hdev, __u8 type,
3573 int *quote)
1da177e4
LT
3574{
3575 struct hci_conn_hash *h = &hdev->conn_hash;
8035ded4 3576 struct hci_conn *conn = NULL, *c;
abc5de8f 3577 unsigned int num = 0, min = ~0;
1da177e4 3578
8e87d142 3579 /* We don't have to lock device here. Connections are always
1da177e4 3580 * added and removed with TX task disabled. */
bf4c6325
GP
3581
3582 rcu_read_lock();
3583
3584 list_for_each_entry_rcu(c, &h->list, list) {
769be974 3585 if (c->type != type || skb_queue_empty(&c->data_q))
1da177e4 3586 continue;
769be974
MH
3587
3588 if (c->state != BT_CONNECTED && c->state != BT_CONFIG)
3589 continue;
3590
1da177e4
LT
3591 num++;
3592
3593 if (c->sent < min) {
3594 min = c->sent;
3595 conn = c;
3596 }
52087a79
LAD
3597
3598 if (hci_conn_num(hdev, type) == num)
3599 break;
1da177e4
LT
3600 }
3601
bf4c6325
GP
3602 rcu_read_unlock();
3603
1da177e4 3604 if (conn) {
6ed58ec5
VT
3605 int cnt, q;
3606
3607 switch (conn->type) {
3608 case ACL_LINK:
3609 cnt = hdev->acl_cnt;
3610 break;
3611 case SCO_LINK:
3612 case ESCO_LINK:
3613 cnt = hdev->sco_cnt;
3614 break;
3615 case LE_LINK:
3616 cnt = hdev->le_mtu ? hdev->le_cnt : hdev->acl_cnt;
3617 break;
3618 default:
3619 cnt = 0;
2064ee33 3620 bt_dev_err(hdev, "unknown link type %d", conn->type);
6ed58ec5
VT
3621 }
3622
3623 q = cnt / num;
1da177e4
LT
3624 *quote = q ? q : 1;
3625 } else
3626 *quote = 0;
3627
3628 BT_DBG("conn %p quote %d", conn, *quote);
3629 return conn;
3630}
3631
6039aa73 3632static void hci_link_tx_to(struct hci_dev *hdev, __u8 type)
1da177e4
LT
3633{
3634 struct hci_conn_hash *h = &hdev->conn_hash;
8035ded4 3635 struct hci_conn *c;
1da177e4 3636
2064ee33 3637 bt_dev_err(hdev, "link tx timeout");
1da177e4 3638
bf4c6325
GP
3639 rcu_read_lock();
3640
1da177e4 3641 /* Kill stalled connections */
bf4c6325 3642 list_for_each_entry_rcu(c, &h->list, list) {
bae1f5d9 3643 if (c->type == type && c->sent) {
2064ee33
MH
3644 bt_dev_err(hdev, "killing stalled connection %pMR",
3645 &c->dst);
bed71748 3646 hci_disconnect(c, HCI_ERROR_REMOTE_USER_TERM);
1da177e4
LT
3647 }
3648 }
bf4c6325
GP
3649
3650 rcu_read_unlock();
1da177e4
LT
3651}
3652
6039aa73
GP
3653static struct hci_chan *hci_chan_sent(struct hci_dev *hdev, __u8 type,
3654 int *quote)
1da177e4 3655{
73d80deb
LAD
3656 struct hci_conn_hash *h = &hdev->conn_hash;
3657 struct hci_chan *chan = NULL;
abc5de8f 3658 unsigned int num = 0, min = ~0, cur_prio = 0;
1da177e4 3659 struct hci_conn *conn;
73d80deb
LAD
3660 int cnt, q, conn_num = 0;
3661
3662 BT_DBG("%s", hdev->name);
3663
bf4c6325
GP
3664 rcu_read_lock();
3665
3666 list_for_each_entry_rcu(conn, &h->list, list) {
73d80deb
LAD
3667 struct hci_chan *tmp;
3668
3669 if (conn->type != type)
3670 continue;
3671
3672 if (conn->state != BT_CONNECTED && conn->state != BT_CONFIG)
3673 continue;
3674
3675 conn_num++;
3676
8192edef 3677 list_for_each_entry_rcu(tmp, &conn->chan_list, list) {
73d80deb
LAD
3678 struct sk_buff *skb;
3679
3680 if (skb_queue_empty(&tmp->data_q))
3681 continue;
3682
3683 skb = skb_peek(&tmp->data_q);
3684 if (skb->priority < cur_prio)
3685 continue;
3686
3687 if (skb->priority > cur_prio) {
3688 num = 0;
3689 min = ~0;
3690 cur_prio = skb->priority;
3691 }
3692
3693 num++;
3694
3695 if (conn->sent < min) {
3696 min = conn->sent;
3697 chan = tmp;
3698 }
3699 }
3700
3701 if (hci_conn_num(hdev, type) == conn_num)
3702 break;
3703 }
3704
bf4c6325
GP
3705 rcu_read_unlock();
3706
73d80deb
LAD
3707 if (!chan)
3708 return NULL;
3709
3710 switch (chan->conn->type) {
3711 case ACL_LINK:
3712 cnt = hdev->acl_cnt;
3713 break;
bd1eb66b
AE
3714 case AMP_LINK:
3715 cnt = hdev->block_cnt;
3716 break;
73d80deb
LAD
3717 case SCO_LINK:
3718 case ESCO_LINK:
3719 cnt = hdev->sco_cnt;
3720 break;
3721 case LE_LINK:
3722 cnt = hdev->le_mtu ? hdev->le_cnt : hdev->acl_cnt;
3723 break;
3724 default:
3725 cnt = 0;
2064ee33 3726 bt_dev_err(hdev, "unknown link type %d", chan->conn->type);
73d80deb
LAD
3727 }
3728
3729 q = cnt / num;
3730 *quote = q ? q : 1;
3731 BT_DBG("chan %p quote %d", chan, *quote);
3732 return chan;
3733}
3734
02b20f0b
LAD
3735static void hci_prio_recalculate(struct hci_dev *hdev, __u8 type)
3736{
3737 struct hci_conn_hash *h = &hdev->conn_hash;
3738 struct hci_conn *conn;
3739 int num = 0;
3740
3741 BT_DBG("%s", hdev->name);
3742
bf4c6325
GP
3743 rcu_read_lock();
3744
3745 list_for_each_entry_rcu(conn, &h->list, list) {
02b20f0b
LAD
3746 struct hci_chan *chan;
3747
3748 if (conn->type != type)
3749 continue;
3750
3751 if (conn->state != BT_CONNECTED && conn->state != BT_CONFIG)
3752 continue;
3753
3754 num++;
3755
8192edef 3756 list_for_each_entry_rcu(chan, &conn->chan_list, list) {
02b20f0b
LAD
3757 struct sk_buff *skb;
3758
3759 if (chan->sent) {
3760 chan->sent = 0;
3761 continue;
3762 }
3763
3764 if (skb_queue_empty(&chan->data_q))
3765 continue;
3766
3767 skb = skb_peek(&chan->data_q);
3768 if (skb->priority >= HCI_PRIO_MAX - 1)
3769 continue;
3770
3771 skb->priority = HCI_PRIO_MAX - 1;
3772
3773 BT_DBG("chan %p skb %p promoted to %d", chan, skb,
a8c5fb1a 3774 skb->priority);
02b20f0b
LAD
3775 }
3776
3777 if (hci_conn_num(hdev, type) == num)
3778 break;
3779 }
bf4c6325
GP
3780
3781 rcu_read_unlock();
3782
02b20f0b
LAD
3783}
3784
b71d385a
AE
3785static inline int __get_blocks(struct hci_dev *hdev, struct sk_buff *skb)
3786{
3787 /* Calculate count of blocks used by this packet */
3788 return DIV_ROUND_UP(skb->len - HCI_ACL_HDR_SIZE, hdev->block_len);
3789}
3790
6039aa73 3791static void __check_timeout(struct hci_dev *hdev, unsigned int cnt)
73d80deb 3792{
d7a5a11d 3793 if (!hci_dev_test_flag(hdev, HCI_UNCONFIGURED)) {
1da177e4
LT
3794 /* ACL tx timeout must be longer than maximum
3795 * link supervision timeout (40.9 seconds) */
63d2bc1b 3796 if (!cnt && time_after(jiffies, hdev->acl_last_tx +
5f246e89 3797 HCI_ACL_TX_TIMEOUT))
bae1f5d9 3798 hci_link_tx_to(hdev, ACL_LINK);
1da177e4 3799 }
63d2bc1b 3800}
1da177e4 3801
6039aa73 3802static void hci_sched_acl_pkt(struct hci_dev *hdev)
63d2bc1b
AE
3803{
3804 unsigned int cnt = hdev->acl_cnt;
3805 struct hci_chan *chan;
3806 struct sk_buff *skb;
3807 int quote;
3808
3809 __check_timeout(hdev, cnt);
04837f64 3810
73d80deb 3811 while (hdev->acl_cnt &&
a8c5fb1a 3812 (chan = hci_chan_sent(hdev, ACL_LINK, &quote))) {
ec1cce24
LAD
3813 u32 priority = (skb_peek(&chan->data_q))->priority;
3814 while (quote-- && (skb = skb_peek(&chan->data_q))) {
73d80deb 3815 BT_DBG("chan %p skb %p len %d priority %u", chan, skb,
a8c5fb1a 3816 skb->len, skb->priority);
73d80deb 3817
ec1cce24
LAD
3818 /* Stop if priority has changed */
3819 if (skb->priority < priority)
3820 break;
3821
3822 skb = skb_dequeue(&chan->data_q);
3823
73d80deb 3824 hci_conn_enter_active_mode(chan->conn,
04124681 3825 bt_cb(skb)->force_active);
04837f64 3826
57d17d70 3827 hci_send_frame(hdev, skb);
1da177e4
LT
3828 hdev->acl_last_tx = jiffies;
3829
3830 hdev->acl_cnt--;
73d80deb
LAD
3831 chan->sent++;
3832 chan->conn->sent++;
1da177e4
LT
3833 }
3834 }
02b20f0b
LAD
3835
3836 if (cnt != hdev->acl_cnt)
3837 hci_prio_recalculate(hdev, ACL_LINK);
1da177e4
LT
3838}
3839
6039aa73 3840static void hci_sched_acl_blk(struct hci_dev *hdev)
b71d385a 3841{
63d2bc1b 3842 unsigned int cnt = hdev->block_cnt;
b71d385a
AE
3843 struct hci_chan *chan;
3844 struct sk_buff *skb;
3845 int quote;
bd1eb66b 3846 u8 type;
b71d385a 3847
63d2bc1b 3848 __check_timeout(hdev, cnt);
b71d385a 3849
bd1eb66b
AE
3850 BT_DBG("%s", hdev->name);
3851
3852 if (hdev->dev_type == HCI_AMP)
3853 type = AMP_LINK;
3854 else
3855 type = ACL_LINK;
3856
b71d385a 3857 while (hdev->block_cnt > 0 &&
bd1eb66b 3858 (chan = hci_chan_sent(hdev, type, &quote))) {
b71d385a
AE
3859 u32 priority = (skb_peek(&chan->data_q))->priority;
3860 while (quote > 0 && (skb = skb_peek(&chan->data_q))) {
3861 int blocks;
3862
3863 BT_DBG("chan %p skb %p len %d priority %u", chan, skb,
a8c5fb1a 3864 skb->len, skb->priority);
b71d385a
AE
3865
3866 /* Stop if priority has changed */
3867 if (skb->priority < priority)
3868 break;
3869
3870 skb = skb_dequeue(&chan->data_q);
3871
3872 blocks = __get_blocks(hdev, skb);
3873 if (blocks > hdev->block_cnt)
3874 return;
3875
3876 hci_conn_enter_active_mode(chan->conn,
a8c5fb1a 3877 bt_cb(skb)->force_active);
b71d385a 3878
57d17d70 3879 hci_send_frame(hdev, skb);
b71d385a
AE
3880 hdev->acl_last_tx = jiffies;
3881
3882 hdev->block_cnt -= blocks;
3883 quote -= blocks;
3884
3885 chan->sent += blocks;
3886 chan->conn->sent += blocks;
3887 }
3888 }
3889
3890 if (cnt != hdev->block_cnt)
bd1eb66b 3891 hci_prio_recalculate(hdev, type);
b71d385a
AE
3892}
3893
6039aa73 3894static void hci_sched_acl(struct hci_dev *hdev)
b71d385a
AE
3895{
3896 BT_DBG("%s", hdev->name);
3897
bd1eb66b 3898 /* No ACL link over BR/EDR controller */
ca8bee5d 3899 if (!hci_conn_num(hdev, ACL_LINK) && hdev->dev_type == HCI_PRIMARY)
bd1eb66b
AE
3900 return;
3901
3902 /* No AMP link over AMP controller */
3903 if (!hci_conn_num(hdev, AMP_LINK) && hdev->dev_type == HCI_AMP)
b71d385a
AE
3904 return;
3905
3906 switch (hdev->flow_ctl_mode) {
3907 case HCI_FLOW_CTL_MODE_PACKET_BASED:
3908 hci_sched_acl_pkt(hdev);
3909 break;
3910
3911 case HCI_FLOW_CTL_MODE_BLOCK_BASED:
3912 hci_sched_acl_blk(hdev);
3913 break;
3914 }
3915}
3916
1da177e4 3917/* Schedule SCO */
6039aa73 3918static void hci_sched_sco(struct hci_dev *hdev)
1da177e4
LT
3919{
3920 struct hci_conn *conn;
3921 struct sk_buff *skb;
3922 int quote;
3923
3924 BT_DBG("%s", hdev->name);
3925
52087a79
LAD
3926 if (!hci_conn_num(hdev, SCO_LINK))
3927 return;
3928
1da177e4
LT
3929 while (hdev->sco_cnt && (conn = hci_low_sent(hdev, SCO_LINK, &quote))) {
3930 while (quote-- && (skb = skb_dequeue(&conn->data_q))) {
3931 BT_DBG("skb %p len %d", skb, skb->len);
57d17d70 3932 hci_send_frame(hdev, skb);
1da177e4
LT
3933
3934 conn->sent++;
3935 if (conn->sent == ~0)
3936 conn->sent = 0;
3937 }
3938 }
3939}
3940
6039aa73 3941static void hci_sched_esco(struct hci_dev *hdev)
b6a0dc82
MH
3942{
3943 struct hci_conn *conn;
3944 struct sk_buff *skb;
3945 int quote;
3946
3947 BT_DBG("%s", hdev->name);
3948
52087a79
LAD
3949 if (!hci_conn_num(hdev, ESCO_LINK))
3950 return;
3951
8fc9ced3
GP
3952 while (hdev->sco_cnt && (conn = hci_low_sent(hdev, ESCO_LINK,
3953 &quote))) {
b6a0dc82
MH
3954 while (quote-- && (skb = skb_dequeue(&conn->data_q))) {
3955 BT_DBG("skb %p len %d", skb, skb->len);
57d17d70 3956 hci_send_frame(hdev, skb);
b6a0dc82
MH
3957
3958 conn->sent++;
3959 if (conn->sent == ~0)
3960 conn->sent = 0;
3961 }
3962 }
3963}
3964
6039aa73 3965static void hci_sched_le(struct hci_dev *hdev)
6ed58ec5 3966{
73d80deb 3967 struct hci_chan *chan;
6ed58ec5 3968 struct sk_buff *skb;
02b20f0b 3969 int quote, cnt, tmp;
6ed58ec5
VT
3970
3971 BT_DBG("%s", hdev->name);
3972
52087a79
LAD
3973 if (!hci_conn_num(hdev, LE_LINK))
3974 return;
3975
d7a5a11d 3976 if (!hci_dev_test_flag(hdev, HCI_UNCONFIGURED)) {
6ed58ec5
VT
3977 /* LE tx timeout must be longer than maximum
3978 * link supervision timeout (40.9 seconds) */
bae1f5d9 3979 if (!hdev->le_cnt && hdev->le_pkts &&
a8c5fb1a 3980 time_after(jiffies, hdev->le_last_tx + HZ * 45))
bae1f5d9 3981 hci_link_tx_to(hdev, LE_LINK);
6ed58ec5
VT
3982 }
3983
3984 cnt = hdev->le_pkts ? hdev->le_cnt : hdev->acl_cnt;
02b20f0b 3985 tmp = cnt;
73d80deb 3986 while (cnt && (chan = hci_chan_sent(hdev, LE_LINK, &quote))) {
ec1cce24
LAD
3987 u32 priority = (skb_peek(&chan->data_q))->priority;
3988 while (quote-- && (skb = skb_peek(&chan->data_q))) {
73d80deb 3989 BT_DBG("chan %p skb %p len %d priority %u", chan, skb,
a8c5fb1a 3990 skb->len, skb->priority);
6ed58ec5 3991
ec1cce24
LAD
3992 /* Stop if priority has changed */
3993 if (skb->priority < priority)
3994 break;
3995
3996 skb = skb_dequeue(&chan->data_q);
3997
57d17d70 3998 hci_send_frame(hdev, skb);
6ed58ec5
VT
3999 hdev->le_last_tx = jiffies;
4000
4001 cnt--;
73d80deb
LAD
4002 chan->sent++;
4003 chan->conn->sent++;
6ed58ec5
VT
4004 }
4005 }
73d80deb 4006
6ed58ec5
VT
4007 if (hdev->le_pkts)
4008 hdev->le_cnt = cnt;
4009 else
4010 hdev->acl_cnt = cnt;
02b20f0b
LAD
4011
4012 if (cnt != tmp)
4013 hci_prio_recalculate(hdev, LE_LINK);
6ed58ec5
VT
4014}
4015
3eff45ea 4016static void hci_tx_work(struct work_struct *work)
1da177e4 4017{
3eff45ea 4018 struct hci_dev *hdev = container_of(work, struct hci_dev, tx_work);
1da177e4
LT
4019 struct sk_buff *skb;
4020
6ed58ec5 4021 BT_DBG("%s acl %d sco %d le %d", hdev->name, hdev->acl_cnt,
a8c5fb1a 4022 hdev->sco_cnt, hdev->le_cnt);
1da177e4 4023
d7a5a11d 4024 if (!hci_dev_test_flag(hdev, HCI_USER_CHANNEL)) {
52de599e
MH
4025 /* Schedule queues and send stuff to HCI driver */
4026 hci_sched_acl(hdev);
4027 hci_sched_sco(hdev);
4028 hci_sched_esco(hdev);
4029 hci_sched_le(hdev);
4030 }
6ed58ec5 4031
1da177e4
LT
4032 /* Send next queued raw (unknown type) packet */
4033 while ((skb = skb_dequeue(&hdev->raw_q)))
57d17d70 4034 hci_send_frame(hdev, skb);
1da177e4
LT
4035}
4036
25985edc 4037/* ----- HCI RX task (incoming data processing) ----- */
1da177e4
LT
4038
4039/* ACL data packet */
6039aa73 4040static void hci_acldata_packet(struct hci_dev *hdev, struct sk_buff *skb)
1da177e4
LT
4041{
4042 struct hci_acl_hdr *hdr = (void *) skb->data;
4043 struct hci_conn *conn;
4044 __u16 handle, flags;
4045
4046 skb_pull(skb, HCI_ACL_HDR_SIZE);
4047
4048 handle = __le16_to_cpu(hdr->handle);
4049 flags = hci_flags(handle);
4050 handle = hci_handle(handle);
4051
f0e09510 4052 BT_DBG("%s len %d handle 0x%4.4x flags 0x%4.4x", hdev->name, skb->len,
a8c5fb1a 4053 handle, flags);
1da177e4
LT
4054
4055 hdev->stat.acl_rx++;
4056
4057 hci_dev_lock(hdev);
4058 conn = hci_conn_hash_lookup_handle(hdev, handle);
4059 hci_dev_unlock(hdev);
8e87d142 4060
1da177e4 4061 if (conn) {
65983fc7 4062 hci_conn_enter_active_mode(conn, BT_POWER_FORCE_ACTIVE_OFF);
04837f64 4063
1da177e4 4064 /* Send to upper protocol */
686ebf28
UF
4065 l2cap_recv_acldata(conn, skb, flags);
4066 return;
1da177e4 4067 } else {
2064ee33
MH
4068 bt_dev_err(hdev, "ACL packet for unknown connection handle %d",
4069 handle);
1da177e4
LT
4070 }
4071
4072 kfree_skb(skb);
4073}
4074
4075/* SCO data packet */
6039aa73 4076static void hci_scodata_packet(struct hci_dev *hdev, struct sk_buff *skb)
1da177e4
LT
4077{
4078 struct hci_sco_hdr *hdr = (void *) skb->data;
4079 struct hci_conn *conn;
4080 __u16 handle;
4081
4082 skb_pull(skb, HCI_SCO_HDR_SIZE);
4083
4084 handle = __le16_to_cpu(hdr->handle);
4085
f0e09510 4086 BT_DBG("%s len %d handle 0x%4.4x", hdev->name, skb->len, handle);
1da177e4
LT
4087
4088 hdev->stat.sco_rx++;
4089
4090 hci_dev_lock(hdev);
4091 conn = hci_conn_hash_lookup_handle(hdev, handle);
4092 hci_dev_unlock(hdev);
4093
4094 if (conn) {
1da177e4 4095 /* Send to upper protocol */
686ebf28
UF
4096 sco_recv_scodata(conn, skb);
4097 return;
1da177e4 4098 } else {
2064ee33
MH
4099 bt_dev_err(hdev, "SCO packet for unknown connection handle %d",
4100 handle);
1da177e4
LT
4101 }
4102
4103 kfree_skb(skb);
4104}
4105
9238f36a
JH
4106static bool hci_req_is_complete(struct hci_dev *hdev)
4107{
4108 struct sk_buff *skb;
4109
4110 skb = skb_peek(&hdev->cmd_q);
4111 if (!skb)
4112 return true;
4113
44d27137 4114 return (bt_cb(skb)->hci.req_flags & HCI_REQ_START);
9238f36a
JH
4115}
4116
42c6b129
JH
4117static void hci_resend_last(struct hci_dev *hdev)
4118{
4119 struct hci_command_hdr *sent;
4120 struct sk_buff *skb;
4121 u16 opcode;
4122
4123 if (!hdev->sent_cmd)
4124 return;
4125
4126 sent = (void *) hdev->sent_cmd->data;
4127 opcode = __le16_to_cpu(sent->opcode);
4128 if (opcode == HCI_OP_RESET)
4129 return;
4130
4131 skb = skb_clone(hdev->sent_cmd, GFP_KERNEL);
4132 if (!skb)
4133 return;
4134
4135 skb_queue_head(&hdev->cmd_q, skb);
4136 queue_work(hdev->workqueue, &hdev->cmd_work);
4137}
4138
e6214487
JH
4139void hci_req_cmd_complete(struct hci_dev *hdev, u16 opcode, u8 status,
4140 hci_req_complete_t *req_complete,
4141 hci_req_complete_skb_t *req_complete_skb)
9238f36a 4142{
9238f36a
JH
4143 struct sk_buff *skb;
4144 unsigned long flags;
4145
4146 BT_DBG("opcode 0x%04x status 0x%02x", opcode, status);
4147
42c6b129
JH
4148 /* If the completed command doesn't match the last one that was
4149 * sent we need to do special handling of it.
9238f36a 4150 */
42c6b129
JH
4151 if (!hci_sent_cmd_data(hdev, opcode)) {
4152 /* Some CSR based controllers generate a spontaneous
4153 * reset complete event during init and any pending
4154 * command will never be completed. In such a case we
4155 * need to resend whatever was the last sent
4156 * command.
4157 */
4158 if (test_bit(HCI_INIT, &hdev->flags) && opcode == HCI_OP_RESET)
4159 hci_resend_last(hdev);
4160
9238f36a 4161 return;
42c6b129 4162 }
9238f36a
JH
4163
4164 /* If the command succeeded and there's still more commands in
4165 * this request the request is not yet complete.
4166 */
4167 if (!status && !hci_req_is_complete(hdev))
4168 return;
4169
4170 /* If this was the last command in a request the complete
4171 * callback would be found in hdev->sent_cmd instead of the
4172 * command queue (hdev->cmd_q).
4173 */
44d27137
JH
4174 if (bt_cb(hdev->sent_cmd)->hci.req_flags & HCI_REQ_SKB) {
4175 *req_complete_skb = bt_cb(hdev->sent_cmd)->hci.req_complete_skb;
e6214487
JH
4176 return;
4177 }
53e21fbc 4178
44d27137
JH
4179 if (bt_cb(hdev->sent_cmd)->hci.req_complete) {
4180 *req_complete = bt_cb(hdev->sent_cmd)->hci.req_complete;
e6214487 4181 return;
9238f36a
JH
4182 }
4183
4184 /* Remove all pending commands belonging to this request */
4185 spin_lock_irqsave(&hdev->cmd_q.lock, flags);
4186 while ((skb = __skb_dequeue(&hdev->cmd_q))) {
44d27137 4187 if (bt_cb(skb)->hci.req_flags & HCI_REQ_START) {
9238f36a
JH
4188 __skb_queue_head(&hdev->cmd_q, skb);
4189 break;
4190 }
4191
3bd7594e
DA
4192 if (bt_cb(skb)->hci.req_flags & HCI_REQ_SKB)
4193 *req_complete_skb = bt_cb(skb)->hci.req_complete_skb;
4194 else
4195 *req_complete = bt_cb(skb)->hci.req_complete;
9238f36a
JH
4196 kfree_skb(skb);
4197 }
4198 spin_unlock_irqrestore(&hdev->cmd_q.lock, flags);
9238f36a
JH
4199}
4200
b78752cc 4201static void hci_rx_work(struct work_struct *work)
1da177e4 4202{
b78752cc 4203 struct hci_dev *hdev = container_of(work, struct hci_dev, rx_work);
1da177e4
LT
4204 struct sk_buff *skb;
4205
4206 BT_DBG("%s", hdev->name);
4207
1da177e4 4208 while ((skb = skb_dequeue(&hdev->rx_q))) {
cd82e61c
MH
4209 /* Send copy to monitor */
4210 hci_send_to_monitor(hdev, skb);
4211
1da177e4
LT
4212 if (atomic_read(&hdev->promisc)) {
4213 /* Send copy to the sockets */
470fe1b5 4214 hci_send_to_sock(hdev, skb);
1da177e4
LT
4215 }
4216
d7a5a11d 4217 if (hci_dev_test_flag(hdev, HCI_USER_CHANNEL)) {
1da177e4
LT
4218 kfree_skb(skb);
4219 continue;
4220 }
4221
4222 if (test_bit(HCI_INIT, &hdev->flags)) {
4223 /* Don't process data packets in this states. */
d79f34e3 4224 switch (hci_skb_pkt_type(skb)) {
1da177e4
LT
4225 case HCI_ACLDATA_PKT:
4226 case HCI_SCODATA_PKT:
4227 kfree_skb(skb);
4228 continue;
3ff50b79 4229 }
1da177e4
LT
4230 }
4231
4232 /* Process frame */
d79f34e3 4233 switch (hci_skb_pkt_type(skb)) {
1da177e4 4234 case HCI_EVENT_PKT:
b78752cc 4235 BT_DBG("%s Event packet", hdev->name);
1da177e4
LT
4236 hci_event_packet(hdev, skb);
4237 break;
4238
4239 case HCI_ACLDATA_PKT:
4240 BT_DBG("%s ACL data packet", hdev->name);
4241 hci_acldata_packet(hdev, skb);
4242 break;
4243
4244 case HCI_SCODATA_PKT:
4245 BT_DBG("%s SCO data packet", hdev->name);
4246 hci_scodata_packet(hdev, skb);
4247 break;
4248
4249 default:
4250 kfree_skb(skb);
4251 break;
4252 }
4253 }
1da177e4
LT
4254}
4255
c347b765 4256static void hci_cmd_work(struct work_struct *work)
1da177e4 4257{
c347b765 4258 struct hci_dev *hdev = container_of(work, struct hci_dev, cmd_work);
1da177e4
LT
4259 struct sk_buff *skb;
4260
2104786b
AE
4261 BT_DBG("%s cmd_cnt %d cmd queued %d", hdev->name,
4262 atomic_read(&hdev->cmd_cnt), skb_queue_len(&hdev->cmd_q));
1da177e4 4263
1da177e4 4264 /* Send queued commands */
5a08ecce
AE
4265 if (atomic_read(&hdev->cmd_cnt)) {
4266 skb = skb_dequeue(&hdev->cmd_q);
4267 if (!skb)
4268 return;
4269
7585b97a 4270 kfree_skb(hdev->sent_cmd);
1da177e4 4271
a675d7f1 4272 hdev->sent_cmd = skb_clone(skb, GFP_KERNEL);
70f23020 4273 if (hdev->sent_cmd) {
1da177e4 4274 atomic_dec(&hdev->cmd_cnt);
57d17d70 4275 hci_send_frame(hdev, skb);
7bdb8a5c 4276 if (test_bit(HCI_RESET, &hdev->flags))
65cc2b49 4277 cancel_delayed_work(&hdev->cmd_timer);
7bdb8a5c 4278 else
65cc2b49
MH
4279 schedule_delayed_work(&hdev->cmd_timer,
4280 HCI_CMD_TIMEOUT);
1da177e4
LT
4281 } else {
4282 skb_queue_head(&hdev->cmd_q, skb);
c347b765 4283 queue_work(hdev->workqueue, &hdev->cmd_work);
1da177e4
LT
4284 }
4285 }
4286}