]> git.proxmox.com Git - mirror_ubuntu-bionic-kernel.git/blame - net/bluetooth/hci_core.c
Bluetooth: Add constants for LTK key types
[mirror_ubuntu-bionic-kernel.git] / net / bluetooth / hci_core.c
CommitLineData
8e87d142 1/*
1da177e4
LT
2 BlueZ - Bluetooth protocol stack for Linux
3 Copyright (C) 2000-2001 Qualcomm Incorporated
590051de 4 Copyright (C) 2011 ProFUSION Embedded Systems
1da177e4
LT
5
6 Written 2000,2001 by Maxim Krasnyansky <maxk@qualcomm.com>
7
8 This program is free software; you can redistribute it and/or modify
9 it under the terms of the GNU General Public License version 2 as
10 published by the Free Software Foundation;
11
12 THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS
13 OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
14 FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT OF THIRD PARTY RIGHTS.
15 IN NO EVENT SHALL THE COPYRIGHT HOLDER(S) AND AUTHOR(S) BE LIABLE FOR ANY
8e87d142
YH
16 CLAIM, OR ANY SPECIAL INDIRECT OR CONSEQUENTIAL DAMAGES, OR ANY DAMAGES
17 WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
18 ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
1da177e4
LT
19 OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
20
8e87d142
YH
21 ALL LIABILITY, INCLUDING LIABILITY FOR INFRINGEMENT OF ANY PATENTS,
22 COPYRIGHTS, TRADEMARKS OR OTHER RIGHTS, RELATING TO USE OF THIS
1da177e4
LT
23 SOFTWARE IS DISCLAIMED.
24*/
25
26/* Bluetooth HCI core. */
27
8c520a59 28#include <linux/export.h>
3df92b31 29#include <linux/idr.h>
8c520a59 30#include <linux/rfkill.h>
baf27f6e 31#include <linux/debugfs.h>
47219839 32#include <asm/unaligned.h>
1da177e4
LT
33
34#include <net/bluetooth/bluetooth.h>
35#include <net/bluetooth/hci_core.h>
36
b78752cc 37static void hci_rx_work(struct work_struct *work);
c347b765 38static void hci_cmd_work(struct work_struct *work);
3eff45ea 39static void hci_tx_work(struct work_struct *work);
1da177e4 40
1da177e4
LT
41/* HCI device list */
42LIST_HEAD(hci_dev_list);
43DEFINE_RWLOCK(hci_dev_list_lock);
44
45/* HCI callback list */
46LIST_HEAD(hci_cb_list);
47DEFINE_RWLOCK(hci_cb_list_lock);
48
3df92b31
SL
49/* HCI ID Numbering */
50static DEFINE_IDA(hci_index_ida);
51
1da177e4
LT
52/* ---- HCI notifications ---- */
53
6516455d 54static void hci_notify(struct hci_dev *hdev, int event)
1da177e4 55{
040030ef 56 hci_sock_dev_event(hdev, event);
1da177e4
LT
57}
58
baf27f6e
MH
59/* ---- HCI debugfs entries ---- */
60
4b4148e9
MH
61static ssize_t dut_mode_read(struct file *file, char __user *user_buf,
62 size_t count, loff_t *ppos)
63{
64 struct hci_dev *hdev = file->private_data;
65 char buf[3];
66
67 buf[0] = test_bit(HCI_DUT_MODE, &hdev->dev_flags) ? 'Y': 'N';
68 buf[1] = '\n';
69 buf[2] = '\0';
70 return simple_read_from_buffer(user_buf, count, ppos, buf, 2);
71}
72
73static ssize_t dut_mode_write(struct file *file, const char __user *user_buf,
74 size_t count, loff_t *ppos)
75{
76 struct hci_dev *hdev = file->private_data;
77 struct sk_buff *skb;
78 char buf[32];
79 size_t buf_size = min(count, (sizeof(buf)-1));
80 bool enable;
81 int err;
82
83 if (!test_bit(HCI_UP, &hdev->flags))
84 return -ENETDOWN;
85
86 if (copy_from_user(buf, user_buf, buf_size))
87 return -EFAULT;
88
89 buf[buf_size] = '\0';
90 if (strtobool(buf, &enable))
91 return -EINVAL;
92
93 if (enable == test_bit(HCI_DUT_MODE, &hdev->dev_flags))
94 return -EALREADY;
95
96 hci_req_lock(hdev);
97 if (enable)
98 skb = __hci_cmd_sync(hdev, HCI_OP_ENABLE_DUT_MODE, 0, NULL,
99 HCI_CMD_TIMEOUT);
100 else
101 skb = __hci_cmd_sync(hdev, HCI_OP_RESET, 0, NULL,
102 HCI_CMD_TIMEOUT);
103 hci_req_unlock(hdev);
104
105 if (IS_ERR(skb))
106 return PTR_ERR(skb);
107
108 err = -bt_to_errno(skb->data[0]);
109 kfree_skb(skb);
110
111 if (err < 0)
112 return err;
113
114 change_bit(HCI_DUT_MODE, &hdev->dev_flags);
115
116 return count;
117}
118
119static const struct file_operations dut_mode_fops = {
120 .open = simple_open,
121 .read = dut_mode_read,
122 .write = dut_mode_write,
123 .llseek = default_llseek,
124};
125
dfb826a8
MH
126static int features_show(struct seq_file *f, void *ptr)
127{
128 struct hci_dev *hdev = f->private;
129 u8 p;
130
131 hci_dev_lock(hdev);
132 for (p = 0; p < HCI_MAX_PAGES && p <= hdev->max_page; p++) {
cfbb2b5b 133 seq_printf(f, "%2u: 0x%2.2x 0x%2.2x 0x%2.2x 0x%2.2x "
dfb826a8
MH
134 "0x%2.2x 0x%2.2x 0x%2.2x 0x%2.2x\n", p,
135 hdev->features[p][0], hdev->features[p][1],
136 hdev->features[p][2], hdev->features[p][3],
137 hdev->features[p][4], hdev->features[p][5],
138 hdev->features[p][6], hdev->features[p][7]);
139 }
cfbb2b5b
MH
140 if (lmp_le_capable(hdev))
141 seq_printf(f, "LE: 0x%2.2x 0x%2.2x 0x%2.2x 0x%2.2x "
142 "0x%2.2x 0x%2.2x 0x%2.2x 0x%2.2x\n",
143 hdev->le_features[0], hdev->le_features[1],
144 hdev->le_features[2], hdev->le_features[3],
145 hdev->le_features[4], hdev->le_features[5],
146 hdev->le_features[6], hdev->le_features[7]);
dfb826a8
MH
147 hci_dev_unlock(hdev);
148
149 return 0;
150}
151
152static int features_open(struct inode *inode, struct file *file)
153{
154 return single_open(file, features_show, inode->i_private);
155}
156
157static const struct file_operations features_fops = {
158 .open = features_open,
159 .read = seq_read,
160 .llseek = seq_lseek,
161 .release = single_release,
162};
163
70afe0b8
MH
164static int blacklist_show(struct seq_file *f, void *p)
165{
166 struct hci_dev *hdev = f->private;
167 struct bdaddr_list *b;
168
169 hci_dev_lock(hdev);
170 list_for_each_entry(b, &hdev->blacklist, list)
b25f0785 171 seq_printf(f, "%pMR (type %u)\n", &b->bdaddr, b->bdaddr_type);
70afe0b8
MH
172 hci_dev_unlock(hdev);
173
174 return 0;
175}
176
177static int blacklist_open(struct inode *inode, struct file *file)
178{
179 return single_open(file, blacklist_show, inode->i_private);
180}
181
182static const struct file_operations blacklist_fops = {
183 .open = blacklist_open,
184 .read = seq_read,
185 .llseek = seq_lseek,
186 .release = single_release,
187};
188
47219839
MH
189static int uuids_show(struct seq_file *f, void *p)
190{
191 struct hci_dev *hdev = f->private;
192 struct bt_uuid *uuid;
193
194 hci_dev_lock(hdev);
195 list_for_each_entry(uuid, &hdev->uuids, list) {
58f01aa9
MH
196 u8 i, val[16];
197
198 /* The Bluetooth UUID values are stored in big endian,
199 * but with reversed byte order. So convert them into
200 * the right order for the %pUb modifier.
201 */
202 for (i = 0; i < 16; i++)
203 val[i] = uuid->uuid[15 - i];
204
205 seq_printf(f, "%pUb\n", val);
47219839
MH
206 }
207 hci_dev_unlock(hdev);
208
209 return 0;
210}
211
212static int uuids_open(struct inode *inode, struct file *file)
213{
214 return single_open(file, uuids_show, inode->i_private);
215}
216
217static const struct file_operations uuids_fops = {
218 .open = uuids_open,
219 .read = seq_read,
220 .llseek = seq_lseek,
221 .release = single_release,
222};
223
baf27f6e
MH
224static int inquiry_cache_show(struct seq_file *f, void *p)
225{
226 struct hci_dev *hdev = f->private;
227 struct discovery_state *cache = &hdev->discovery;
228 struct inquiry_entry *e;
229
230 hci_dev_lock(hdev);
231
232 list_for_each_entry(e, &cache->all, all) {
233 struct inquiry_data *data = &e->data;
234 seq_printf(f, "%pMR %d %d %d 0x%.2x%.2x%.2x 0x%.4x %d %d %u\n",
235 &data->bdaddr,
236 data->pscan_rep_mode, data->pscan_period_mode,
237 data->pscan_mode, data->dev_class[2],
238 data->dev_class[1], data->dev_class[0],
239 __le16_to_cpu(data->clock_offset),
240 data->rssi, data->ssp_mode, e->timestamp);
241 }
242
243 hci_dev_unlock(hdev);
244
245 return 0;
246}
247
248static int inquiry_cache_open(struct inode *inode, struct file *file)
249{
250 return single_open(file, inquiry_cache_show, inode->i_private);
251}
252
253static const struct file_operations inquiry_cache_fops = {
254 .open = inquiry_cache_open,
255 .read = seq_read,
256 .llseek = seq_lseek,
257 .release = single_release,
258};
259
02d08d15
MH
260static int link_keys_show(struct seq_file *f, void *ptr)
261{
262 struct hci_dev *hdev = f->private;
263 struct list_head *p, *n;
264
265 hci_dev_lock(hdev);
266 list_for_each_safe(p, n, &hdev->link_keys) {
267 struct link_key *key = list_entry(p, struct link_key, list);
268 seq_printf(f, "%pMR %u %*phN %u\n", &key->bdaddr, key->type,
269 HCI_LINK_KEY_SIZE, key->val, key->pin_len);
270 }
271 hci_dev_unlock(hdev);
272
273 return 0;
274}
275
276static int link_keys_open(struct inode *inode, struct file *file)
277{
278 return single_open(file, link_keys_show, inode->i_private);
279}
280
281static const struct file_operations link_keys_fops = {
282 .open = link_keys_open,
283 .read = seq_read,
284 .llseek = seq_lseek,
285 .release = single_release,
286};
287
babdbb3c
MH
288static int dev_class_show(struct seq_file *f, void *ptr)
289{
290 struct hci_dev *hdev = f->private;
291
292 hci_dev_lock(hdev);
293 seq_printf(f, "0x%.2x%.2x%.2x\n", hdev->dev_class[2],
294 hdev->dev_class[1], hdev->dev_class[0]);
295 hci_dev_unlock(hdev);
296
297 return 0;
298}
299
300static int dev_class_open(struct inode *inode, struct file *file)
301{
302 return single_open(file, dev_class_show, inode->i_private);
303}
304
305static const struct file_operations dev_class_fops = {
306 .open = dev_class_open,
307 .read = seq_read,
308 .llseek = seq_lseek,
309 .release = single_release,
310};
311
041000b9
MH
312static int voice_setting_get(void *data, u64 *val)
313{
314 struct hci_dev *hdev = data;
315
316 hci_dev_lock(hdev);
317 *val = hdev->voice_setting;
318 hci_dev_unlock(hdev);
319
320 return 0;
321}
322
323DEFINE_SIMPLE_ATTRIBUTE(voice_setting_fops, voice_setting_get,
324 NULL, "0x%4.4llx\n");
325
ebd1e33b
MH
326static int auto_accept_delay_set(void *data, u64 val)
327{
328 struct hci_dev *hdev = data;
329
330 hci_dev_lock(hdev);
331 hdev->auto_accept_delay = val;
332 hci_dev_unlock(hdev);
333
334 return 0;
335}
336
337static int auto_accept_delay_get(void *data, u64 *val)
338{
339 struct hci_dev *hdev = data;
340
341 hci_dev_lock(hdev);
342 *val = hdev->auto_accept_delay;
343 hci_dev_unlock(hdev);
344
345 return 0;
346}
347
348DEFINE_SIMPLE_ATTRIBUTE(auto_accept_delay_fops, auto_accept_delay_get,
349 auto_accept_delay_set, "%llu\n");
350
06f5b778
MH
351static int ssp_debug_mode_set(void *data, u64 val)
352{
353 struct hci_dev *hdev = data;
354 struct sk_buff *skb;
355 __u8 mode;
356 int err;
357
358 if (val != 0 && val != 1)
359 return -EINVAL;
360
361 if (!test_bit(HCI_UP, &hdev->flags))
362 return -ENETDOWN;
363
364 hci_req_lock(hdev);
365 mode = val;
366 skb = __hci_cmd_sync(hdev, HCI_OP_WRITE_SSP_DEBUG_MODE, sizeof(mode),
367 &mode, HCI_CMD_TIMEOUT);
368 hci_req_unlock(hdev);
369
370 if (IS_ERR(skb))
371 return PTR_ERR(skb);
372
373 err = -bt_to_errno(skb->data[0]);
374 kfree_skb(skb);
375
376 if (err < 0)
377 return err;
378
379 hci_dev_lock(hdev);
380 hdev->ssp_debug_mode = val;
381 hci_dev_unlock(hdev);
382
383 return 0;
384}
385
386static int ssp_debug_mode_get(void *data, u64 *val)
387{
388 struct hci_dev *hdev = data;
389
390 hci_dev_lock(hdev);
391 *val = hdev->ssp_debug_mode;
392 hci_dev_unlock(hdev);
393
394 return 0;
395}
396
397DEFINE_SIMPLE_ATTRIBUTE(ssp_debug_mode_fops, ssp_debug_mode_get,
398 ssp_debug_mode_set, "%llu\n");
399
5afeac14
MH
400static ssize_t force_sc_support_read(struct file *file, char __user *user_buf,
401 size_t count, loff_t *ppos)
402{
403 struct hci_dev *hdev = file->private_data;
404 char buf[3];
405
406 buf[0] = test_bit(HCI_FORCE_SC, &hdev->dev_flags) ? 'Y': 'N';
407 buf[1] = '\n';
408 buf[2] = '\0';
409 return simple_read_from_buffer(user_buf, count, ppos, buf, 2);
410}
411
412static ssize_t force_sc_support_write(struct file *file,
413 const char __user *user_buf,
414 size_t count, loff_t *ppos)
415{
416 struct hci_dev *hdev = file->private_data;
417 char buf[32];
418 size_t buf_size = min(count, (sizeof(buf)-1));
419 bool enable;
420
421 if (test_bit(HCI_UP, &hdev->flags))
422 return -EBUSY;
423
424 if (copy_from_user(buf, user_buf, buf_size))
425 return -EFAULT;
426
427 buf[buf_size] = '\0';
428 if (strtobool(buf, &enable))
429 return -EINVAL;
430
431 if (enable == test_bit(HCI_FORCE_SC, &hdev->dev_flags))
432 return -EALREADY;
433
434 change_bit(HCI_FORCE_SC, &hdev->dev_flags);
435
436 return count;
437}
438
439static const struct file_operations force_sc_support_fops = {
440 .open = simple_open,
441 .read = force_sc_support_read,
442 .write = force_sc_support_write,
443 .llseek = default_llseek,
444};
445
134c2a89
MH
446static ssize_t sc_only_mode_read(struct file *file, char __user *user_buf,
447 size_t count, loff_t *ppos)
448{
449 struct hci_dev *hdev = file->private_data;
450 char buf[3];
451
452 buf[0] = test_bit(HCI_SC_ONLY, &hdev->dev_flags) ? 'Y': 'N';
453 buf[1] = '\n';
454 buf[2] = '\0';
455 return simple_read_from_buffer(user_buf, count, ppos, buf, 2);
456}
457
458static const struct file_operations sc_only_mode_fops = {
459 .open = simple_open,
460 .read = sc_only_mode_read,
461 .llseek = default_llseek,
462};
463
2bfa3531
MH
464static int idle_timeout_set(void *data, u64 val)
465{
466 struct hci_dev *hdev = data;
467
468 if (val != 0 && (val < 500 || val > 3600000))
469 return -EINVAL;
470
471 hci_dev_lock(hdev);
2be48b65 472 hdev->idle_timeout = val;
2bfa3531
MH
473 hci_dev_unlock(hdev);
474
475 return 0;
476}
477
478static int idle_timeout_get(void *data, u64 *val)
479{
480 struct hci_dev *hdev = data;
481
482 hci_dev_lock(hdev);
483 *val = hdev->idle_timeout;
484 hci_dev_unlock(hdev);
485
486 return 0;
487}
488
489DEFINE_SIMPLE_ATTRIBUTE(idle_timeout_fops, idle_timeout_get,
490 idle_timeout_set, "%llu\n");
491
492static int sniff_min_interval_set(void *data, u64 val)
493{
494 struct hci_dev *hdev = data;
495
496 if (val == 0 || val % 2 || val > hdev->sniff_max_interval)
497 return -EINVAL;
498
499 hci_dev_lock(hdev);
2be48b65 500 hdev->sniff_min_interval = val;
2bfa3531
MH
501 hci_dev_unlock(hdev);
502
503 return 0;
504}
505
506static int sniff_min_interval_get(void *data, u64 *val)
507{
508 struct hci_dev *hdev = data;
509
510 hci_dev_lock(hdev);
511 *val = hdev->sniff_min_interval;
512 hci_dev_unlock(hdev);
513
514 return 0;
515}
516
517DEFINE_SIMPLE_ATTRIBUTE(sniff_min_interval_fops, sniff_min_interval_get,
518 sniff_min_interval_set, "%llu\n");
519
520static int sniff_max_interval_set(void *data, u64 val)
521{
522 struct hci_dev *hdev = data;
523
524 if (val == 0 || val % 2 || val < hdev->sniff_min_interval)
525 return -EINVAL;
526
527 hci_dev_lock(hdev);
2be48b65 528 hdev->sniff_max_interval = val;
2bfa3531
MH
529 hci_dev_unlock(hdev);
530
531 return 0;
532}
533
534static int sniff_max_interval_get(void *data, u64 *val)
535{
536 struct hci_dev *hdev = data;
537
538 hci_dev_lock(hdev);
539 *val = hdev->sniff_max_interval;
540 hci_dev_unlock(hdev);
541
542 return 0;
543}
544
545DEFINE_SIMPLE_ATTRIBUTE(sniff_max_interval_fops, sniff_max_interval_get,
546 sniff_max_interval_set, "%llu\n");
547
e7b8fc92
MH
548static int static_address_show(struct seq_file *f, void *p)
549{
550 struct hci_dev *hdev = f->private;
551
552 hci_dev_lock(hdev);
553 seq_printf(f, "%pMR\n", &hdev->static_addr);
554 hci_dev_unlock(hdev);
555
556 return 0;
557}
558
559static int static_address_open(struct inode *inode, struct file *file)
560{
561 return single_open(file, static_address_show, inode->i_private);
562}
563
564static const struct file_operations static_address_fops = {
565 .open = static_address_open,
566 .read = seq_read,
567 .llseek = seq_lseek,
568 .release = single_release,
569};
570
92202185
MH
571static int own_address_type_set(void *data, u64 val)
572{
573 struct hci_dev *hdev = data;
574
575 if (val != 0 && val != 1)
576 return -EINVAL;
577
578 hci_dev_lock(hdev);
579 hdev->own_addr_type = val;
580 hci_dev_unlock(hdev);
581
582 return 0;
583}
584
585static int own_address_type_get(void *data, u64 *val)
586{
587 struct hci_dev *hdev = data;
588
589 hci_dev_lock(hdev);
590 *val = hdev->own_addr_type;
591 hci_dev_unlock(hdev);
592
593 return 0;
594}
595
596DEFINE_SIMPLE_ATTRIBUTE(own_address_type_fops, own_address_type_get,
597 own_address_type_set, "%llu\n");
598
8f8625cd
MH
599static int long_term_keys_show(struct seq_file *f, void *ptr)
600{
601 struct hci_dev *hdev = f->private;
602 struct list_head *p, *n;
603
604 hci_dev_lock(hdev);
f813f1be 605 list_for_each_safe(p, n, &hdev->long_term_keys) {
8f8625cd 606 struct smp_ltk *ltk = list_entry(p, struct smp_ltk, list);
f813f1be 607 seq_printf(f, "%pMR (type %u) %u 0x%02x %u %.4x %*phN %*phN\n",
8f8625cd
MH
608 &ltk->bdaddr, ltk->bdaddr_type, ltk->authenticated,
609 ltk->type, ltk->enc_size, __le16_to_cpu(ltk->ediv),
610 8, ltk->rand, 16, ltk->val);
611 }
612 hci_dev_unlock(hdev);
613
614 return 0;
615}
616
617static int long_term_keys_open(struct inode *inode, struct file *file)
618{
619 return single_open(file, long_term_keys_show, inode->i_private);
620}
621
622static const struct file_operations long_term_keys_fops = {
623 .open = long_term_keys_open,
624 .read = seq_read,
625 .llseek = seq_lseek,
626 .release = single_release,
627};
628
4e70c7e7
MH
629static int conn_min_interval_set(void *data, u64 val)
630{
631 struct hci_dev *hdev = data;
632
633 if (val < 0x0006 || val > 0x0c80 || val > hdev->le_conn_max_interval)
634 return -EINVAL;
635
636 hci_dev_lock(hdev);
2be48b65 637 hdev->le_conn_min_interval = val;
4e70c7e7
MH
638 hci_dev_unlock(hdev);
639
640 return 0;
641}
642
643static int conn_min_interval_get(void *data, u64 *val)
644{
645 struct hci_dev *hdev = data;
646
647 hci_dev_lock(hdev);
648 *val = hdev->le_conn_min_interval;
649 hci_dev_unlock(hdev);
650
651 return 0;
652}
653
654DEFINE_SIMPLE_ATTRIBUTE(conn_min_interval_fops, conn_min_interval_get,
655 conn_min_interval_set, "%llu\n");
656
657static int conn_max_interval_set(void *data, u64 val)
658{
659 struct hci_dev *hdev = data;
660
661 if (val < 0x0006 || val > 0x0c80 || val < hdev->le_conn_min_interval)
662 return -EINVAL;
663
664 hci_dev_lock(hdev);
2be48b65 665 hdev->le_conn_max_interval = val;
4e70c7e7
MH
666 hci_dev_unlock(hdev);
667
668 return 0;
669}
670
671static int conn_max_interval_get(void *data, u64 *val)
672{
673 struct hci_dev *hdev = data;
674
675 hci_dev_lock(hdev);
676 *val = hdev->le_conn_max_interval;
677 hci_dev_unlock(hdev);
678
679 return 0;
680}
681
682DEFINE_SIMPLE_ATTRIBUTE(conn_max_interval_fops, conn_max_interval_get,
683 conn_max_interval_set, "%llu\n");
684
89863109
JR
685static ssize_t lowpan_read(struct file *file, char __user *user_buf,
686 size_t count, loff_t *ppos)
687{
688 struct hci_dev *hdev = file->private_data;
689 char buf[3];
690
691 buf[0] = test_bit(HCI_6LOWPAN_ENABLED, &hdev->dev_flags) ? 'Y' : 'N';
692 buf[1] = '\n';
693 buf[2] = '\0';
694 return simple_read_from_buffer(user_buf, count, ppos, buf, 2);
695}
696
697static ssize_t lowpan_write(struct file *fp, const char __user *user_buffer,
698 size_t count, loff_t *position)
699{
700 struct hci_dev *hdev = fp->private_data;
701 bool enable;
702 char buf[32];
703 size_t buf_size = min(count, (sizeof(buf)-1));
704
705 if (copy_from_user(buf, user_buffer, buf_size))
706 return -EFAULT;
707
708 buf[buf_size] = '\0';
709
710 if (strtobool(buf, &enable) < 0)
711 return -EINVAL;
712
713 if (enable == test_bit(HCI_6LOWPAN_ENABLED, &hdev->dev_flags))
714 return -EALREADY;
715
716 change_bit(HCI_6LOWPAN_ENABLED, &hdev->dev_flags);
717
718 return count;
719}
720
721static const struct file_operations lowpan_debugfs_fops = {
722 .open = simple_open,
723 .read = lowpan_read,
724 .write = lowpan_write,
725 .llseek = default_llseek,
726};
727
1da177e4
LT
728/* ---- HCI requests ---- */
729
42c6b129 730static void hci_req_sync_complete(struct hci_dev *hdev, u8 result)
1da177e4 731{
42c6b129 732 BT_DBG("%s result 0x%2.2x", hdev->name, result);
1da177e4
LT
733
734 if (hdev->req_status == HCI_REQ_PEND) {
735 hdev->req_result = result;
736 hdev->req_status = HCI_REQ_DONE;
737 wake_up_interruptible(&hdev->req_wait_q);
738 }
739}
740
741static void hci_req_cancel(struct hci_dev *hdev, int err)
742{
743 BT_DBG("%s err 0x%2.2x", hdev->name, err);
744
745 if (hdev->req_status == HCI_REQ_PEND) {
746 hdev->req_result = err;
747 hdev->req_status = HCI_REQ_CANCELED;
748 wake_up_interruptible(&hdev->req_wait_q);
749 }
750}
751
77a63e0a
FW
752static struct sk_buff *hci_get_cmd_complete(struct hci_dev *hdev, u16 opcode,
753 u8 event)
75e84b7c
JH
754{
755 struct hci_ev_cmd_complete *ev;
756 struct hci_event_hdr *hdr;
757 struct sk_buff *skb;
758
759 hci_dev_lock(hdev);
760
761 skb = hdev->recv_evt;
762 hdev->recv_evt = NULL;
763
764 hci_dev_unlock(hdev);
765
766 if (!skb)
767 return ERR_PTR(-ENODATA);
768
769 if (skb->len < sizeof(*hdr)) {
770 BT_ERR("Too short HCI event");
771 goto failed;
772 }
773
774 hdr = (void *) skb->data;
775 skb_pull(skb, HCI_EVENT_HDR_SIZE);
776
7b1abbbe
JH
777 if (event) {
778 if (hdr->evt != event)
779 goto failed;
780 return skb;
781 }
782
75e84b7c
JH
783 if (hdr->evt != HCI_EV_CMD_COMPLETE) {
784 BT_DBG("Last event is not cmd complete (0x%2.2x)", hdr->evt);
785 goto failed;
786 }
787
788 if (skb->len < sizeof(*ev)) {
789 BT_ERR("Too short cmd_complete event");
790 goto failed;
791 }
792
793 ev = (void *) skb->data;
794 skb_pull(skb, sizeof(*ev));
795
796 if (opcode == __le16_to_cpu(ev->opcode))
797 return skb;
798
799 BT_DBG("opcode doesn't match (0x%2.2x != 0x%2.2x)", opcode,
800 __le16_to_cpu(ev->opcode));
801
802failed:
803 kfree_skb(skb);
804 return ERR_PTR(-ENODATA);
805}
806
7b1abbbe 807struct sk_buff *__hci_cmd_sync_ev(struct hci_dev *hdev, u16 opcode, u32 plen,
07dc93dd 808 const void *param, u8 event, u32 timeout)
75e84b7c
JH
809{
810 DECLARE_WAITQUEUE(wait, current);
811 struct hci_request req;
812 int err = 0;
813
814 BT_DBG("%s", hdev->name);
815
816 hci_req_init(&req, hdev);
817
7b1abbbe 818 hci_req_add_ev(&req, opcode, plen, param, event);
75e84b7c
JH
819
820 hdev->req_status = HCI_REQ_PEND;
821
822 err = hci_req_run(&req, hci_req_sync_complete);
823 if (err < 0)
824 return ERR_PTR(err);
825
826 add_wait_queue(&hdev->req_wait_q, &wait);
827 set_current_state(TASK_INTERRUPTIBLE);
828
829 schedule_timeout(timeout);
830
831 remove_wait_queue(&hdev->req_wait_q, &wait);
832
833 if (signal_pending(current))
834 return ERR_PTR(-EINTR);
835
836 switch (hdev->req_status) {
837 case HCI_REQ_DONE:
838 err = -bt_to_errno(hdev->req_result);
839 break;
840
841 case HCI_REQ_CANCELED:
842 err = -hdev->req_result;
843 break;
844
845 default:
846 err = -ETIMEDOUT;
847 break;
848 }
849
850 hdev->req_status = hdev->req_result = 0;
851
852 BT_DBG("%s end: err %d", hdev->name, err);
853
854 if (err < 0)
855 return ERR_PTR(err);
856
7b1abbbe
JH
857 return hci_get_cmd_complete(hdev, opcode, event);
858}
859EXPORT_SYMBOL(__hci_cmd_sync_ev);
860
861struct sk_buff *__hci_cmd_sync(struct hci_dev *hdev, u16 opcode, u32 plen,
07dc93dd 862 const void *param, u32 timeout)
7b1abbbe
JH
863{
864 return __hci_cmd_sync_ev(hdev, opcode, plen, param, 0, timeout);
75e84b7c
JH
865}
866EXPORT_SYMBOL(__hci_cmd_sync);
867
1da177e4 868/* Execute request and wait for completion. */
01178cd4 869static int __hci_req_sync(struct hci_dev *hdev,
42c6b129
JH
870 void (*func)(struct hci_request *req,
871 unsigned long opt),
01178cd4 872 unsigned long opt, __u32 timeout)
1da177e4 873{
42c6b129 874 struct hci_request req;
1da177e4
LT
875 DECLARE_WAITQUEUE(wait, current);
876 int err = 0;
877
878 BT_DBG("%s start", hdev->name);
879
42c6b129
JH
880 hci_req_init(&req, hdev);
881
1da177e4
LT
882 hdev->req_status = HCI_REQ_PEND;
883
42c6b129 884 func(&req, opt);
53cce22d 885
42c6b129
JH
886 err = hci_req_run(&req, hci_req_sync_complete);
887 if (err < 0) {
53cce22d 888 hdev->req_status = 0;
920c8300
AG
889
890 /* ENODATA means the HCI request command queue is empty.
891 * This can happen when a request with conditionals doesn't
892 * trigger any commands to be sent. This is normal behavior
893 * and should not trigger an error return.
42c6b129 894 */
920c8300
AG
895 if (err == -ENODATA)
896 return 0;
897
898 return err;
53cce22d
JH
899 }
900
bc4445c7
AG
901 add_wait_queue(&hdev->req_wait_q, &wait);
902 set_current_state(TASK_INTERRUPTIBLE);
903
1da177e4
LT
904 schedule_timeout(timeout);
905
906 remove_wait_queue(&hdev->req_wait_q, &wait);
907
908 if (signal_pending(current))
909 return -EINTR;
910
911 switch (hdev->req_status) {
912 case HCI_REQ_DONE:
e175072f 913 err = -bt_to_errno(hdev->req_result);
1da177e4
LT
914 break;
915
916 case HCI_REQ_CANCELED:
917 err = -hdev->req_result;
918 break;
919
920 default:
921 err = -ETIMEDOUT;
922 break;
3ff50b79 923 }
1da177e4 924
a5040efa 925 hdev->req_status = hdev->req_result = 0;
1da177e4
LT
926
927 BT_DBG("%s end: err %d", hdev->name, err);
928
929 return err;
930}
931
01178cd4 932static int hci_req_sync(struct hci_dev *hdev,
42c6b129
JH
933 void (*req)(struct hci_request *req,
934 unsigned long opt),
01178cd4 935 unsigned long opt, __u32 timeout)
1da177e4
LT
936{
937 int ret;
938
7c6a329e
MH
939 if (!test_bit(HCI_UP, &hdev->flags))
940 return -ENETDOWN;
941
1da177e4
LT
942 /* Serialize all requests */
943 hci_req_lock(hdev);
01178cd4 944 ret = __hci_req_sync(hdev, req, opt, timeout);
1da177e4
LT
945 hci_req_unlock(hdev);
946
947 return ret;
948}
949
42c6b129 950static void hci_reset_req(struct hci_request *req, unsigned long opt)
1da177e4 951{
42c6b129 952 BT_DBG("%s %ld", req->hdev->name, opt);
1da177e4
LT
953
954 /* Reset device */
42c6b129
JH
955 set_bit(HCI_RESET, &req->hdev->flags);
956 hci_req_add(req, HCI_OP_RESET, 0, NULL);
1da177e4
LT
957}
958
42c6b129 959static void bredr_init(struct hci_request *req)
1da177e4 960{
42c6b129 961 req->hdev->flow_ctl_mode = HCI_FLOW_CTL_MODE_PACKET_BASED;
2455a3ea 962
1da177e4 963 /* Read Local Supported Features */
42c6b129 964 hci_req_add(req, HCI_OP_READ_LOCAL_FEATURES, 0, NULL);
1da177e4 965
1143e5a6 966 /* Read Local Version */
42c6b129 967 hci_req_add(req, HCI_OP_READ_LOCAL_VERSION, 0, NULL);
2177bab5
JH
968
969 /* Read BD Address */
42c6b129 970 hci_req_add(req, HCI_OP_READ_BD_ADDR, 0, NULL);
1da177e4
LT
971}
972
42c6b129 973static void amp_init(struct hci_request *req)
e61ef499 974{
42c6b129 975 req->hdev->flow_ctl_mode = HCI_FLOW_CTL_MODE_BLOCK_BASED;
2455a3ea 976
e61ef499 977 /* Read Local Version */
42c6b129 978 hci_req_add(req, HCI_OP_READ_LOCAL_VERSION, 0, NULL);
6bcbc489 979
f6996cfe
MH
980 /* Read Local Supported Commands */
981 hci_req_add(req, HCI_OP_READ_LOCAL_COMMANDS, 0, NULL);
982
983 /* Read Local Supported Features */
984 hci_req_add(req, HCI_OP_READ_LOCAL_FEATURES, 0, NULL);
985
6bcbc489 986 /* Read Local AMP Info */
42c6b129 987 hci_req_add(req, HCI_OP_READ_LOCAL_AMP_INFO, 0, NULL);
e71dfaba
AE
988
989 /* Read Data Blk size */
42c6b129 990 hci_req_add(req, HCI_OP_READ_DATA_BLOCK_SIZE, 0, NULL);
7528ca1c 991
f38ba941
MH
992 /* Read Flow Control Mode */
993 hci_req_add(req, HCI_OP_READ_FLOW_CONTROL_MODE, 0, NULL);
994
7528ca1c
MH
995 /* Read Location Data */
996 hci_req_add(req, HCI_OP_READ_LOCATION_DATA, 0, NULL);
e61ef499
AE
997}
998
42c6b129 999static void hci_init1_req(struct hci_request *req, unsigned long opt)
e61ef499 1000{
42c6b129 1001 struct hci_dev *hdev = req->hdev;
e61ef499
AE
1002
1003 BT_DBG("%s %ld", hdev->name, opt);
1004
11778716
AE
1005 /* Reset */
1006 if (!test_bit(HCI_QUIRK_RESET_ON_CLOSE, &hdev->quirks))
42c6b129 1007 hci_reset_req(req, 0);
11778716 1008
e61ef499
AE
1009 switch (hdev->dev_type) {
1010 case HCI_BREDR:
42c6b129 1011 bredr_init(req);
e61ef499
AE
1012 break;
1013
1014 case HCI_AMP:
42c6b129 1015 amp_init(req);
e61ef499
AE
1016 break;
1017
1018 default:
1019 BT_ERR("Unknown device type %d", hdev->dev_type);
1020 break;
1021 }
e61ef499
AE
1022}
1023
42c6b129 1024static void bredr_setup(struct hci_request *req)
2177bab5 1025{
4ca048e3
MH
1026 struct hci_dev *hdev = req->hdev;
1027
2177bab5
JH
1028 __le16 param;
1029 __u8 flt_type;
1030
1031 /* Read Buffer Size (ACL mtu, max pkt, etc.) */
42c6b129 1032 hci_req_add(req, HCI_OP_READ_BUFFER_SIZE, 0, NULL);
2177bab5
JH
1033
1034 /* Read Class of Device */
42c6b129 1035 hci_req_add(req, HCI_OP_READ_CLASS_OF_DEV, 0, NULL);
2177bab5
JH
1036
1037 /* Read Local Name */
42c6b129 1038 hci_req_add(req, HCI_OP_READ_LOCAL_NAME, 0, NULL);
2177bab5
JH
1039
1040 /* Read Voice Setting */
42c6b129 1041 hci_req_add(req, HCI_OP_READ_VOICE_SETTING, 0, NULL);
2177bab5 1042
b4cb9fb2
MH
1043 /* Read Number of Supported IAC */
1044 hci_req_add(req, HCI_OP_READ_NUM_SUPPORTED_IAC, 0, NULL);
1045
4b836f39
MH
1046 /* Read Current IAC LAP */
1047 hci_req_add(req, HCI_OP_READ_CURRENT_IAC_LAP, 0, NULL);
1048
2177bab5
JH
1049 /* Clear Event Filters */
1050 flt_type = HCI_FLT_CLEAR_ALL;
42c6b129 1051 hci_req_add(req, HCI_OP_SET_EVENT_FLT, 1, &flt_type);
2177bab5
JH
1052
1053 /* Connection accept timeout ~20 secs */
1054 param = __constant_cpu_to_le16(0x7d00);
42c6b129 1055 hci_req_add(req, HCI_OP_WRITE_CA_TIMEOUT, 2, &param);
2177bab5 1056
4ca048e3
MH
1057 /* AVM Berlin (31), aka "BlueFRITZ!", reports version 1.2,
1058 * but it does not support page scan related HCI commands.
1059 */
1060 if (hdev->manufacturer != 31 && hdev->hci_ver > BLUETOOTH_VER_1_1) {
f332ec66
JH
1061 hci_req_add(req, HCI_OP_READ_PAGE_SCAN_ACTIVITY, 0, NULL);
1062 hci_req_add(req, HCI_OP_READ_PAGE_SCAN_TYPE, 0, NULL);
1063 }
2177bab5
JH
1064}
1065
42c6b129 1066static void le_setup(struct hci_request *req)
2177bab5 1067{
c73eee91
JH
1068 struct hci_dev *hdev = req->hdev;
1069
2177bab5 1070 /* Read LE Buffer Size */
42c6b129 1071 hci_req_add(req, HCI_OP_LE_READ_BUFFER_SIZE, 0, NULL);
2177bab5
JH
1072
1073 /* Read LE Local Supported Features */
42c6b129 1074 hci_req_add(req, HCI_OP_LE_READ_LOCAL_FEATURES, 0, NULL);
2177bab5
JH
1075
1076 /* Read LE Advertising Channel TX Power */
42c6b129 1077 hci_req_add(req, HCI_OP_LE_READ_ADV_TX_POWER, 0, NULL);
2177bab5
JH
1078
1079 /* Read LE White List Size */
42c6b129 1080 hci_req_add(req, HCI_OP_LE_READ_WHITE_LIST_SIZE, 0, NULL);
2177bab5
JH
1081
1082 /* Read LE Supported States */
42c6b129 1083 hci_req_add(req, HCI_OP_LE_READ_SUPPORTED_STATES, 0, NULL);
c73eee91
JH
1084
1085 /* LE-only controllers have LE implicitly enabled */
1086 if (!lmp_bredr_capable(hdev))
1087 set_bit(HCI_LE_ENABLED, &hdev->dev_flags);
2177bab5
JH
1088}
1089
1090static u8 hci_get_inquiry_mode(struct hci_dev *hdev)
1091{
1092 if (lmp_ext_inq_capable(hdev))
1093 return 0x02;
1094
1095 if (lmp_inq_rssi_capable(hdev))
1096 return 0x01;
1097
1098 if (hdev->manufacturer == 11 && hdev->hci_rev == 0x00 &&
1099 hdev->lmp_subver == 0x0757)
1100 return 0x01;
1101
1102 if (hdev->manufacturer == 15) {
1103 if (hdev->hci_rev == 0x03 && hdev->lmp_subver == 0x6963)
1104 return 0x01;
1105 if (hdev->hci_rev == 0x09 && hdev->lmp_subver == 0x6963)
1106 return 0x01;
1107 if (hdev->hci_rev == 0x00 && hdev->lmp_subver == 0x6965)
1108 return 0x01;
1109 }
1110
1111 if (hdev->manufacturer == 31 && hdev->hci_rev == 0x2005 &&
1112 hdev->lmp_subver == 0x1805)
1113 return 0x01;
1114
1115 return 0x00;
1116}
1117
42c6b129 1118static void hci_setup_inquiry_mode(struct hci_request *req)
2177bab5
JH
1119{
1120 u8 mode;
1121
42c6b129 1122 mode = hci_get_inquiry_mode(req->hdev);
2177bab5 1123
42c6b129 1124 hci_req_add(req, HCI_OP_WRITE_INQUIRY_MODE, 1, &mode);
2177bab5
JH
1125}
1126
42c6b129 1127static void hci_setup_event_mask(struct hci_request *req)
2177bab5 1128{
42c6b129
JH
1129 struct hci_dev *hdev = req->hdev;
1130
2177bab5
JH
1131 /* The second byte is 0xff instead of 0x9f (two reserved bits
1132 * disabled) since a Broadcom 1.2 dongle doesn't respond to the
1133 * command otherwise.
1134 */
1135 u8 events[8] = { 0xff, 0xff, 0xfb, 0xff, 0x00, 0x00, 0x00, 0x00 };
1136
1137 /* CSR 1.1 dongles does not accept any bitfield so don't try to set
1138 * any event mask for pre 1.2 devices.
1139 */
1140 if (hdev->hci_ver < BLUETOOTH_VER_1_2)
1141 return;
1142
1143 if (lmp_bredr_capable(hdev)) {
1144 events[4] |= 0x01; /* Flow Specification Complete */
1145 events[4] |= 0x02; /* Inquiry Result with RSSI */
1146 events[4] |= 0x04; /* Read Remote Extended Features Complete */
1147 events[5] |= 0x08; /* Synchronous Connection Complete */
1148 events[5] |= 0x10; /* Synchronous Connection Changed */
c7882cbd
MH
1149 } else {
1150 /* Use a different default for LE-only devices */
1151 memset(events, 0, sizeof(events));
1152 events[0] |= 0x10; /* Disconnection Complete */
1153 events[0] |= 0x80; /* Encryption Change */
1154 events[1] |= 0x08; /* Read Remote Version Information Complete */
1155 events[1] |= 0x20; /* Command Complete */
1156 events[1] |= 0x40; /* Command Status */
1157 events[1] |= 0x80; /* Hardware Error */
1158 events[2] |= 0x04; /* Number of Completed Packets */
1159 events[3] |= 0x02; /* Data Buffer Overflow */
1160 events[5] |= 0x80; /* Encryption Key Refresh Complete */
2177bab5
JH
1161 }
1162
1163 if (lmp_inq_rssi_capable(hdev))
1164 events[4] |= 0x02; /* Inquiry Result with RSSI */
1165
1166 if (lmp_sniffsubr_capable(hdev))
1167 events[5] |= 0x20; /* Sniff Subrating */
1168
1169 if (lmp_pause_enc_capable(hdev))
1170 events[5] |= 0x80; /* Encryption Key Refresh Complete */
1171
1172 if (lmp_ext_inq_capable(hdev))
1173 events[5] |= 0x40; /* Extended Inquiry Result */
1174
1175 if (lmp_no_flush_capable(hdev))
1176 events[7] |= 0x01; /* Enhanced Flush Complete */
1177
1178 if (lmp_lsto_capable(hdev))
1179 events[6] |= 0x80; /* Link Supervision Timeout Changed */
1180
1181 if (lmp_ssp_capable(hdev)) {
1182 events[6] |= 0x01; /* IO Capability Request */
1183 events[6] |= 0x02; /* IO Capability Response */
1184 events[6] |= 0x04; /* User Confirmation Request */
1185 events[6] |= 0x08; /* User Passkey Request */
1186 events[6] |= 0x10; /* Remote OOB Data Request */
1187 events[6] |= 0x20; /* Simple Pairing Complete */
1188 events[7] |= 0x04; /* User Passkey Notification */
1189 events[7] |= 0x08; /* Keypress Notification */
1190 events[7] |= 0x10; /* Remote Host Supported
1191 * Features Notification
1192 */
1193 }
1194
1195 if (lmp_le_capable(hdev))
1196 events[7] |= 0x20; /* LE Meta-Event */
1197
42c6b129 1198 hci_req_add(req, HCI_OP_SET_EVENT_MASK, sizeof(events), events);
2177bab5
JH
1199
1200 if (lmp_le_capable(hdev)) {
1201 memset(events, 0, sizeof(events));
1202 events[0] = 0x1f;
42c6b129
JH
1203 hci_req_add(req, HCI_OP_LE_SET_EVENT_MASK,
1204 sizeof(events), events);
2177bab5
JH
1205 }
1206}
1207
42c6b129 1208static void hci_init2_req(struct hci_request *req, unsigned long opt)
2177bab5 1209{
42c6b129
JH
1210 struct hci_dev *hdev = req->hdev;
1211
2177bab5 1212 if (lmp_bredr_capable(hdev))
42c6b129 1213 bredr_setup(req);
56f87901
JH
1214 else
1215 clear_bit(HCI_BREDR_ENABLED, &hdev->dev_flags);
2177bab5
JH
1216
1217 if (lmp_le_capable(hdev))
42c6b129 1218 le_setup(req);
2177bab5 1219
42c6b129 1220 hci_setup_event_mask(req);
2177bab5 1221
3f8e2d75
JH
1222 /* AVM Berlin (31), aka "BlueFRITZ!", doesn't support the read
1223 * local supported commands HCI command.
1224 */
1225 if (hdev->manufacturer != 31 && hdev->hci_ver > BLUETOOTH_VER_1_1)
42c6b129 1226 hci_req_add(req, HCI_OP_READ_LOCAL_COMMANDS, 0, NULL);
2177bab5
JH
1227
1228 if (lmp_ssp_capable(hdev)) {
57af75a8
MH
1229 /* When SSP is available, then the host features page
1230 * should also be available as well. However some
1231 * controllers list the max_page as 0 as long as SSP
1232 * has not been enabled. To achieve proper debugging
1233 * output, force the minimum max_page to 1 at least.
1234 */
1235 hdev->max_page = 0x01;
1236
2177bab5
JH
1237 if (test_bit(HCI_SSP_ENABLED, &hdev->dev_flags)) {
1238 u8 mode = 0x01;
42c6b129
JH
1239 hci_req_add(req, HCI_OP_WRITE_SSP_MODE,
1240 sizeof(mode), &mode);
2177bab5
JH
1241 } else {
1242 struct hci_cp_write_eir cp;
1243
1244 memset(hdev->eir, 0, sizeof(hdev->eir));
1245 memset(&cp, 0, sizeof(cp));
1246
42c6b129 1247 hci_req_add(req, HCI_OP_WRITE_EIR, sizeof(cp), &cp);
2177bab5
JH
1248 }
1249 }
1250
1251 if (lmp_inq_rssi_capable(hdev))
42c6b129 1252 hci_setup_inquiry_mode(req);
2177bab5
JH
1253
1254 if (lmp_inq_tx_pwr_capable(hdev))
42c6b129 1255 hci_req_add(req, HCI_OP_READ_INQ_RSP_TX_POWER, 0, NULL);
2177bab5
JH
1256
1257 if (lmp_ext_feat_capable(hdev)) {
1258 struct hci_cp_read_local_ext_features cp;
1259
1260 cp.page = 0x01;
42c6b129
JH
1261 hci_req_add(req, HCI_OP_READ_LOCAL_EXT_FEATURES,
1262 sizeof(cp), &cp);
2177bab5
JH
1263 }
1264
1265 if (test_bit(HCI_LINK_SECURITY, &hdev->dev_flags)) {
1266 u8 enable = 1;
42c6b129
JH
1267 hci_req_add(req, HCI_OP_WRITE_AUTH_ENABLE, sizeof(enable),
1268 &enable);
2177bab5
JH
1269 }
1270}
1271
42c6b129 1272static void hci_setup_link_policy(struct hci_request *req)
2177bab5 1273{
42c6b129 1274 struct hci_dev *hdev = req->hdev;
2177bab5
JH
1275 struct hci_cp_write_def_link_policy cp;
1276 u16 link_policy = 0;
1277
1278 if (lmp_rswitch_capable(hdev))
1279 link_policy |= HCI_LP_RSWITCH;
1280 if (lmp_hold_capable(hdev))
1281 link_policy |= HCI_LP_HOLD;
1282 if (lmp_sniff_capable(hdev))
1283 link_policy |= HCI_LP_SNIFF;
1284 if (lmp_park_capable(hdev))
1285 link_policy |= HCI_LP_PARK;
1286
1287 cp.policy = cpu_to_le16(link_policy);
42c6b129 1288 hci_req_add(req, HCI_OP_WRITE_DEF_LINK_POLICY, sizeof(cp), &cp);
2177bab5
JH
1289}
1290
42c6b129 1291static void hci_set_le_support(struct hci_request *req)
2177bab5 1292{
42c6b129 1293 struct hci_dev *hdev = req->hdev;
2177bab5
JH
1294 struct hci_cp_write_le_host_supported cp;
1295
c73eee91
JH
1296 /* LE-only devices do not support explicit enablement */
1297 if (!lmp_bredr_capable(hdev))
1298 return;
1299
2177bab5
JH
1300 memset(&cp, 0, sizeof(cp));
1301
1302 if (test_bit(HCI_LE_ENABLED, &hdev->dev_flags)) {
1303 cp.le = 0x01;
1304 cp.simul = lmp_le_br_capable(hdev);
1305 }
1306
1307 if (cp.le != lmp_host_le_capable(hdev))
42c6b129
JH
1308 hci_req_add(req, HCI_OP_WRITE_LE_HOST_SUPPORTED, sizeof(cp),
1309 &cp);
2177bab5
JH
1310}
1311
d62e6d67
JH
1312static void hci_set_event_mask_page_2(struct hci_request *req)
1313{
1314 struct hci_dev *hdev = req->hdev;
1315 u8 events[8] = { 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00 };
1316
1317 /* If Connectionless Slave Broadcast master role is supported
1318 * enable all necessary events for it.
1319 */
53b834d2 1320 if (lmp_csb_master_capable(hdev)) {
d62e6d67
JH
1321 events[1] |= 0x40; /* Triggered Clock Capture */
1322 events[1] |= 0x80; /* Synchronization Train Complete */
1323 events[2] |= 0x10; /* Slave Page Response Timeout */
1324 events[2] |= 0x20; /* CSB Channel Map Change */
1325 }
1326
1327 /* If Connectionless Slave Broadcast slave role is supported
1328 * enable all necessary events for it.
1329 */
53b834d2 1330 if (lmp_csb_slave_capable(hdev)) {
d62e6d67
JH
1331 events[2] |= 0x01; /* Synchronization Train Received */
1332 events[2] |= 0x02; /* CSB Receive */
1333 events[2] |= 0x04; /* CSB Timeout */
1334 events[2] |= 0x08; /* Truncated Page Complete */
1335 }
1336
40c59fcb
MH
1337 /* Enable Authenticated Payload Timeout Expired event if supported */
1338 if (lmp_ping_capable(hdev))
1339 events[2] |= 0x80;
1340
d62e6d67
JH
1341 hci_req_add(req, HCI_OP_SET_EVENT_MASK_PAGE_2, sizeof(events), events);
1342}
1343
42c6b129 1344static void hci_init3_req(struct hci_request *req, unsigned long opt)
2177bab5 1345{
42c6b129 1346 struct hci_dev *hdev = req->hdev;
d2c5d77f 1347 u8 p;
42c6b129 1348
b8f4e068
GP
1349 /* Some Broadcom based Bluetooth controllers do not support the
1350 * Delete Stored Link Key command. They are clearly indicating its
1351 * absence in the bit mask of supported commands.
1352 *
1353 * Check the supported commands and only if the the command is marked
1354 * as supported send it. If not supported assume that the controller
1355 * does not have actual support for stored link keys which makes this
1356 * command redundant anyway.
f9f462fa
MH
1357 *
1358 * Some controllers indicate that they support handling deleting
1359 * stored link keys, but they don't. The quirk lets a driver
1360 * just disable this command.
637b4cae 1361 */
f9f462fa
MH
1362 if (hdev->commands[6] & 0x80 &&
1363 !test_bit(HCI_QUIRK_BROKEN_STORED_LINK_KEY, &hdev->quirks)) {
59f45d57
JH
1364 struct hci_cp_delete_stored_link_key cp;
1365
1366 bacpy(&cp.bdaddr, BDADDR_ANY);
1367 cp.delete_all = 0x01;
1368 hci_req_add(req, HCI_OP_DELETE_STORED_LINK_KEY,
1369 sizeof(cp), &cp);
1370 }
1371
2177bab5 1372 if (hdev->commands[5] & 0x10)
42c6b129 1373 hci_setup_link_policy(req);
2177bab5 1374
79830f66 1375 if (lmp_le_capable(hdev)) {
bef34c0a
MH
1376 if (test_bit(HCI_SETUP, &hdev->dev_flags)) {
1377 /* If the controller has a public BD_ADDR, then
1378 * by default use that one. If this is a LE only
1379 * controller without a public address, default
1380 * to the random address.
1381 */
1382 if (bacmp(&hdev->bdaddr, BDADDR_ANY))
1383 hdev->own_addr_type = ADDR_LE_DEV_PUBLIC;
1384 else
1385 hdev->own_addr_type = ADDR_LE_DEV_RANDOM;
1386 }
79830f66 1387
42c6b129 1388 hci_set_le_support(req);
79830f66 1389 }
d2c5d77f
JH
1390
1391 /* Read features beyond page 1 if available */
1392 for (p = 2; p < HCI_MAX_PAGES && p <= hdev->max_page; p++) {
1393 struct hci_cp_read_local_ext_features cp;
1394
1395 cp.page = p;
1396 hci_req_add(req, HCI_OP_READ_LOCAL_EXT_FEATURES,
1397 sizeof(cp), &cp);
1398 }
2177bab5
JH
1399}
1400
5d4e7e8d
JH
1401static void hci_init4_req(struct hci_request *req, unsigned long opt)
1402{
1403 struct hci_dev *hdev = req->hdev;
1404
d62e6d67
JH
1405 /* Set event mask page 2 if the HCI command for it is supported */
1406 if (hdev->commands[22] & 0x04)
1407 hci_set_event_mask_page_2(req);
1408
5d4e7e8d 1409 /* Check for Synchronization Train support */
53b834d2 1410 if (lmp_sync_train_capable(hdev))
5d4e7e8d 1411 hci_req_add(req, HCI_OP_READ_SYNC_TRAIN_PARAMS, 0, NULL);
a6d0d690
MH
1412
1413 /* Enable Secure Connections if supported and configured */
5afeac14
MH
1414 if ((lmp_sc_capable(hdev) ||
1415 test_bit(HCI_FORCE_SC, &hdev->dev_flags)) &&
a6d0d690
MH
1416 test_bit(HCI_SC_ENABLED, &hdev->dev_flags)) {
1417 u8 support = 0x01;
1418 hci_req_add(req, HCI_OP_WRITE_SC_SUPPORT,
1419 sizeof(support), &support);
1420 }
5d4e7e8d
JH
1421}
1422
2177bab5
JH
1423static int __hci_init(struct hci_dev *hdev)
1424{
1425 int err;
1426
1427 err = __hci_req_sync(hdev, hci_init1_req, 0, HCI_INIT_TIMEOUT);
1428 if (err < 0)
1429 return err;
1430
4b4148e9
MH
1431 /* The Device Under Test (DUT) mode is special and available for
1432 * all controller types. So just create it early on.
1433 */
1434 if (test_bit(HCI_SETUP, &hdev->dev_flags)) {
1435 debugfs_create_file("dut_mode", 0644, hdev->debugfs, hdev,
1436 &dut_mode_fops);
1437 }
1438
2177bab5
JH
1439 /* HCI_BREDR covers both single-mode LE, BR/EDR and dual-mode
1440 * BR/EDR/LE type controllers. AMP controllers only need the
1441 * first stage init.
1442 */
1443 if (hdev->dev_type != HCI_BREDR)
1444 return 0;
1445
1446 err = __hci_req_sync(hdev, hci_init2_req, 0, HCI_INIT_TIMEOUT);
1447 if (err < 0)
1448 return err;
1449
5d4e7e8d
JH
1450 err = __hci_req_sync(hdev, hci_init3_req, 0, HCI_INIT_TIMEOUT);
1451 if (err < 0)
1452 return err;
1453
baf27f6e
MH
1454 err = __hci_req_sync(hdev, hci_init4_req, 0, HCI_INIT_TIMEOUT);
1455 if (err < 0)
1456 return err;
1457
1458 /* Only create debugfs entries during the initial setup
1459 * phase and not every time the controller gets powered on.
1460 */
1461 if (!test_bit(HCI_SETUP, &hdev->dev_flags))
1462 return 0;
1463
dfb826a8
MH
1464 debugfs_create_file("features", 0444, hdev->debugfs, hdev,
1465 &features_fops);
ceeb3bc0
MH
1466 debugfs_create_u16("manufacturer", 0444, hdev->debugfs,
1467 &hdev->manufacturer);
1468 debugfs_create_u8("hci_version", 0444, hdev->debugfs, &hdev->hci_ver);
1469 debugfs_create_u16("hci_revision", 0444, hdev->debugfs, &hdev->hci_rev);
70afe0b8
MH
1470 debugfs_create_file("blacklist", 0444, hdev->debugfs, hdev,
1471 &blacklist_fops);
47219839
MH
1472 debugfs_create_file("uuids", 0444, hdev->debugfs, hdev, &uuids_fops);
1473
baf27f6e
MH
1474 if (lmp_bredr_capable(hdev)) {
1475 debugfs_create_file("inquiry_cache", 0444, hdev->debugfs,
1476 hdev, &inquiry_cache_fops);
02d08d15
MH
1477 debugfs_create_file("link_keys", 0400, hdev->debugfs,
1478 hdev, &link_keys_fops);
babdbb3c
MH
1479 debugfs_create_file("dev_class", 0444, hdev->debugfs,
1480 hdev, &dev_class_fops);
041000b9
MH
1481 debugfs_create_file("voice_setting", 0444, hdev->debugfs,
1482 hdev, &voice_setting_fops);
baf27f6e
MH
1483 }
1484
06f5b778 1485 if (lmp_ssp_capable(hdev)) {
ebd1e33b
MH
1486 debugfs_create_file("auto_accept_delay", 0644, hdev->debugfs,
1487 hdev, &auto_accept_delay_fops);
06f5b778
MH
1488 debugfs_create_file("ssp_debug_mode", 0644, hdev->debugfs,
1489 hdev, &ssp_debug_mode_fops);
5afeac14
MH
1490 debugfs_create_file("force_sc_support", 0644, hdev->debugfs,
1491 hdev, &force_sc_support_fops);
134c2a89
MH
1492 debugfs_create_file("sc_only_mode", 0444, hdev->debugfs,
1493 hdev, &sc_only_mode_fops);
06f5b778 1494 }
ebd1e33b 1495
2bfa3531
MH
1496 if (lmp_sniff_capable(hdev)) {
1497 debugfs_create_file("idle_timeout", 0644, hdev->debugfs,
1498 hdev, &idle_timeout_fops);
1499 debugfs_create_file("sniff_min_interval", 0644, hdev->debugfs,
1500 hdev, &sniff_min_interval_fops);
1501 debugfs_create_file("sniff_max_interval", 0644, hdev->debugfs,
1502 hdev, &sniff_max_interval_fops);
1503 }
1504
d0f729b8
MH
1505 if (lmp_le_capable(hdev)) {
1506 debugfs_create_u8("white_list_size", 0444, hdev->debugfs,
1507 &hdev->le_white_list_size);
e7b8fc92
MH
1508 debugfs_create_file("static_address", 0444, hdev->debugfs,
1509 hdev, &static_address_fops);
92202185
MH
1510 debugfs_create_file("own_address_type", 0644, hdev->debugfs,
1511 hdev, &own_address_type_fops);
8f8625cd
MH
1512 debugfs_create_file("long_term_keys", 0400, hdev->debugfs,
1513 hdev, &long_term_keys_fops);
4e70c7e7
MH
1514 debugfs_create_file("conn_min_interval", 0644, hdev->debugfs,
1515 hdev, &conn_min_interval_fops);
1516 debugfs_create_file("conn_max_interval", 0644, hdev->debugfs,
1517 hdev, &conn_max_interval_fops);
89863109
JR
1518 debugfs_create_file("6lowpan", 0644, hdev->debugfs, hdev,
1519 &lowpan_debugfs_fops);
d0f729b8 1520 }
e7b8fc92 1521
baf27f6e 1522 return 0;
2177bab5
JH
1523}
1524
42c6b129 1525static void hci_scan_req(struct hci_request *req, unsigned long opt)
1da177e4
LT
1526{
1527 __u8 scan = opt;
1528
42c6b129 1529 BT_DBG("%s %x", req->hdev->name, scan);
1da177e4
LT
1530
1531 /* Inquiry and Page scans */
42c6b129 1532 hci_req_add(req, HCI_OP_WRITE_SCAN_ENABLE, 1, &scan);
1da177e4
LT
1533}
1534
42c6b129 1535static void hci_auth_req(struct hci_request *req, unsigned long opt)
1da177e4
LT
1536{
1537 __u8 auth = opt;
1538
42c6b129 1539 BT_DBG("%s %x", req->hdev->name, auth);
1da177e4
LT
1540
1541 /* Authentication */
42c6b129 1542 hci_req_add(req, HCI_OP_WRITE_AUTH_ENABLE, 1, &auth);
1da177e4
LT
1543}
1544
42c6b129 1545static void hci_encrypt_req(struct hci_request *req, unsigned long opt)
1da177e4
LT
1546{
1547 __u8 encrypt = opt;
1548
42c6b129 1549 BT_DBG("%s %x", req->hdev->name, encrypt);
1da177e4 1550
e4e8e37c 1551 /* Encryption */
42c6b129 1552 hci_req_add(req, HCI_OP_WRITE_ENCRYPT_MODE, 1, &encrypt);
1da177e4
LT
1553}
1554
42c6b129 1555static void hci_linkpol_req(struct hci_request *req, unsigned long opt)
e4e8e37c
MH
1556{
1557 __le16 policy = cpu_to_le16(opt);
1558
42c6b129 1559 BT_DBG("%s %x", req->hdev->name, policy);
e4e8e37c
MH
1560
1561 /* Default link policy */
42c6b129 1562 hci_req_add(req, HCI_OP_WRITE_DEF_LINK_POLICY, 2, &policy);
e4e8e37c
MH
1563}
1564
8e87d142 1565/* Get HCI device by index.
1da177e4
LT
1566 * Device is held on return. */
1567struct hci_dev *hci_dev_get(int index)
1568{
8035ded4 1569 struct hci_dev *hdev = NULL, *d;
1da177e4
LT
1570
1571 BT_DBG("%d", index);
1572
1573 if (index < 0)
1574 return NULL;
1575
1576 read_lock(&hci_dev_list_lock);
8035ded4 1577 list_for_each_entry(d, &hci_dev_list, list) {
1da177e4
LT
1578 if (d->id == index) {
1579 hdev = hci_dev_hold(d);
1580 break;
1581 }
1582 }
1583 read_unlock(&hci_dev_list_lock);
1584 return hdev;
1585}
1da177e4
LT
1586
1587/* ---- Inquiry support ---- */
ff9ef578 1588
30dc78e1
JH
1589bool hci_discovery_active(struct hci_dev *hdev)
1590{
1591 struct discovery_state *discov = &hdev->discovery;
1592
6fbe195d 1593 switch (discov->state) {
343f935b 1594 case DISCOVERY_FINDING:
6fbe195d 1595 case DISCOVERY_RESOLVING:
30dc78e1
JH
1596 return true;
1597
6fbe195d
AG
1598 default:
1599 return false;
1600 }
30dc78e1
JH
1601}
1602
ff9ef578
JH
1603void hci_discovery_set_state(struct hci_dev *hdev, int state)
1604{
1605 BT_DBG("%s state %u -> %u", hdev->name, hdev->discovery.state, state);
1606
1607 if (hdev->discovery.state == state)
1608 return;
1609
1610 switch (state) {
1611 case DISCOVERY_STOPPED:
7b99b659
AG
1612 if (hdev->discovery.state != DISCOVERY_STARTING)
1613 mgmt_discovering(hdev, 0);
ff9ef578
JH
1614 break;
1615 case DISCOVERY_STARTING:
1616 break;
343f935b 1617 case DISCOVERY_FINDING:
ff9ef578
JH
1618 mgmt_discovering(hdev, 1);
1619 break;
30dc78e1
JH
1620 case DISCOVERY_RESOLVING:
1621 break;
ff9ef578
JH
1622 case DISCOVERY_STOPPING:
1623 break;
1624 }
1625
1626 hdev->discovery.state = state;
1627}
1628
1f9b9a5d 1629void hci_inquiry_cache_flush(struct hci_dev *hdev)
1da177e4 1630{
30883512 1631 struct discovery_state *cache = &hdev->discovery;
b57c1a56 1632 struct inquiry_entry *p, *n;
1da177e4 1633
561aafbc
JH
1634 list_for_each_entry_safe(p, n, &cache->all, all) {
1635 list_del(&p->all);
b57c1a56 1636 kfree(p);
1da177e4 1637 }
561aafbc
JH
1638
1639 INIT_LIST_HEAD(&cache->unknown);
1640 INIT_LIST_HEAD(&cache->resolve);
1da177e4
LT
1641}
1642
a8c5fb1a
GP
1643struct inquiry_entry *hci_inquiry_cache_lookup(struct hci_dev *hdev,
1644 bdaddr_t *bdaddr)
1da177e4 1645{
30883512 1646 struct discovery_state *cache = &hdev->discovery;
1da177e4
LT
1647 struct inquiry_entry *e;
1648
6ed93dc6 1649 BT_DBG("cache %p, %pMR", cache, bdaddr);
1da177e4 1650
561aafbc
JH
1651 list_for_each_entry(e, &cache->all, all) {
1652 if (!bacmp(&e->data.bdaddr, bdaddr))
1653 return e;
1654 }
1655
1656 return NULL;
1657}
1658
1659struct inquiry_entry *hci_inquiry_cache_lookup_unknown(struct hci_dev *hdev,
04124681 1660 bdaddr_t *bdaddr)
561aafbc 1661{
30883512 1662 struct discovery_state *cache = &hdev->discovery;
561aafbc
JH
1663 struct inquiry_entry *e;
1664
6ed93dc6 1665 BT_DBG("cache %p, %pMR", cache, bdaddr);
561aafbc
JH
1666
1667 list_for_each_entry(e, &cache->unknown, list) {
1da177e4 1668 if (!bacmp(&e->data.bdaddr, bdaddr))
b57c1a56
JH
1669 return e;
1670 }
1671
1672 return NULL;
1da177e4
LT
1673}
1674
30dc78e1 1675struct inquiry_entry *hci_inquiry_cache_lookup_resolve(struct hci_dev *hdev,
04124681
GP
1676 bdaddr_t *bdaddr,
1677 int state)
30dc78e1
JH
1678{
1679 struct discovery_state *cache = &hdev->discovery;
1680 struct inquiry_entry *e;
1681
6ed93dc6 1682 BT_DBG("cache %p bdaddr %pMR state %d", cache, bdaddr, state);
30dc78e1
JH
1683
1684 list_for_each_entry(e, &cache->resolve, list) {
1685 if (!bacmp(bdaddr, BDADDR_ANY) && e->name_state == state)
1686 return e;
1687 if (!bacmp(&e->data.bdaddr, bdaddr))
1688 return e;
1689 }
1690
1691 return NULL;
1692}
1693
a3d4e20a 1694void hci_inquiry_cache_update_resolve(struct hci_dev *hdev,
04124681 1695 struct inquiry_entry *ie)
a3d4e20a
JH
1696{
1697 struct discovery_state *cache = &hdev->discovery;
1698 struct list_head *pos = &cache->resolve;
1699 struct inquiry_entry *p;
1700
1701 list_del(&ie->list);
1702
1703 list_for_each_entry(p, &cache->resolve, list) {
1704 if (p->name_state != NAME_PENDING &&
a8c5fb1a 1705 abs(p->data.rssi) >= abs(ie->data.rssi))
a3d4e20a
JH
1706 break;
1707 pos = &p->list;
1708 }
1709
1710 list_add(&ie->list, pos);
1711}
1712
3175405b 1713bool hci_inquiry_cache_update(struct hci_dev *hdev, struct inquiry_data *data,
04124681 1714 bool name_known, bool *ssp)
1da177e4 1715{
30883512 1716 struct discovery_state *cache = &hdev->discovery;
70f23020 1717 struct inquiry_entry *ie;
1da177e4 1718
6ed93dc6 1719 BT_DBG("cache %p, %pMR", cache, &data->bdaddr);
1da177e4 1720
2b2fec4d
SJ
1721 hci_remove_remote_oob_data(hdev, &data->bdaddr);
1722
388fc8fa
JH
1723 if (ssp)
1724 *ssp = data->ssp_mode;
1725
70f23020 1726 ie = hci_inquiry_cache_lookup(hdev, &data->bdaddr);
a3d4e20a 1727 if (ie) {
388fc8fa
JH
1728 if (ie->data.ssp_mode && ssp)
1729 *ssp = true;
1730
a3d4e20a 1731 if (ie->name_state == NAME_NEEDED &&
a8c5fb1a 1732 data->rssi != ie->data.rssi) {
a3d4e20a
JH
1733 ie->data.rssi = data->rssi;
1734 hci_inquiry_cache_update_resolve(hdev, ie);
1735 }
1736
561aafbc 1737 goto update;
a3d4e20a 1738 }
561aafbc
JH
1739
1740 /* Entry not in the cache. Add new one. */
1741 ie = kzalloc(sizeof(struct inquiry_entry), GFP_ATOMIC);
1742 if (!ie)
3175405b 1743 return false;
561aafbc
JH
1744
1745 list_add(&ie->all, &cache->all);
1746
1747 if (name_known) {
1748 ie->name_state = NAME_KNOWN;
1749 } else {
1750 ie->name_state = NAME_NOT_KNOWN;
1751 list_add(&ie->list, &cache->unknown);
1752 }
70f23020 1753
561aafbc
JH
1754update:
1755 if (name_known && ie->name_state != NAME_KNOWN &&
a8c5fb1a 1756 ie->name_state != NAME_PENDING) {
561aafbc
JH
1757 ie->name_state = NAME_KNOWN;
1758 list_del(&ie->list);
1da177e4
LT
1759 }
1760
70f23020
AE
1761 memcpy(&ie->data, data, sizeof(*data));
1762 ie->timestamp = jiffies;
1da177e4 1763 cache->timestamp = jiffies;
3175405b
JH
1764
1765 if (ie->name_state == NAME_NOT_KNOWN)
1766 return false;
1767
1768 return true;
1da177e4
LT
1769}
1770
1771static int inquiry_cache_dump(struct hci_dev *hdev, int num, __u8 *buf)
1772{
30883512 1773 struct discovery_state *cache = &hdev->discovery;
1da177e4
LT
1774 struct inquiry_info *info = (struct inquiry_info *) buf;
1775 struct inquiry_entry *e;
1776 int copied = 0;
1777
561aafbc 1778 list_for_each_entry(e, &cache->all, all) {
1da177e4 1779 struct inquiry_data *data = &e->data;
b57c1a56
JH
1780
1781 if (copied >= num)
1782 break;
1783
1da177e4
LT
1784 bacpy(&info->bdaddr, &data->bdaddr);
1785 info->pscan_rep_mode = data->pscan_rep_mode;
1786 info->pscan_period_mode = data->pscan_period_mode;
1787 info->pscan_mode = data->pscan_mode;
1788 memcpy(info->dev_class, data->dev_class, 3);
1789 info->clock_offset = data->clock_offset;
b57c1a56 1790
1da177e4 1791 info++;
b57c1a56 1792 copied++;
1da177e4
LT
1793 }
1794
1795 BT_DBG("cache %p, copied %d", cache, copied);
1796 return copied;
1797}
1798
42c6b129 1799static void hci_inq_req(struct hci_request *req, unsigned long opt)
1da177e4
LT
1800{
1801 struct hci_inquiry_req *ir = (struct hci_inquiry_req *) opt;
42c6b129 1802 struct hci_dev *hdev = req->hdev;
1da177e4
LT
1803 struct hci_cp_inquiry cp;
1804
1805 BT_DBG("%s", hdev->name);
1806
1807 if (test_bit(HCI_INQUIRY, &hdev->flags))
1808 return;
1809
1810 /* Start Inquiry */
1811 memcpy(&cp.lap, &ir->lap, 3);
1812 cp.length = ir->length;
1813 cp.num_rsp = ir->num_rsp;
42c6b129 1814 hci_req_add(req, HCI_OP_INQUIRY, sizeof(cp), &cp);
1da177e4
LT
1815}
1816
3e13fa1e
AG
1817static int wait_inquiry(void *word)
1818{
1819 schedule();
1820 return signal_pending(current);
1821}
1822
1da177e4
LT
1823int hci_inquiry(void __user *arg)
1824{
1825 __u8 __user *ptr = arg;
1826 struct hci_inquiry_req ir;
1827 struct hci_dev *hdev;
1828 int err = 0, do_inquiry = 0, max_rsp;
1829 long timeo;
1830 __u8 *buf;
1831
1832 if (copy_from_user(&ir, ptr, sizeof(ir)))
1833 return -EFAULT;
1834
5a08ecce
AE
1835 hdev = hci_dev_get(ir.dev_id);
1836 if (!hdev)
1da177e4
LT
1837 return -ENODEV;
1838
0736cfa8
MH
1839 if (test_bit(HCI_USER_CHANNEL, &hdev->dev_flags)) {
1840 err = -EBUSY;
1841 goto done;
1842 }
1843
5b69bef5
MH
1844 if (hdev->dev_type != HCI_BREDR) {
1845 err = -EOPNOTSUPP;
1846 goto done;
1847 }
1848
56f87901
JH
1849 if (!test_bit(HCI_BREDR_ENABLED, &hdev->dev_flags)) {
1850 err = -EOPNOTSUPP;
1851 goto done;
1852 }
1853
09fd0de5 1854 hci_dev_lock(hdev);
8e87d142 1855 if (inquiry_cache_age(hdev) > INQUIRY_CACHE_AGE_MAX ||
a8c5fb1a 1856 inquiry_cache_empty(hdev) || ir.flags & IREQ_CACHE_FLUSH) {
1f9b9a5d 1857 hci_inquiry_cache_flush(hdev);
1da177e4
LT
1858 do_inquiry = 1;
1859 }
09fd0de5 1860 hci_dev_unlock(hdev);
1da177e4 1861
04837f64 1862 timeo = ir.length * msecs_to_jiffies(2000);
70f23020
AE
1863
1864 if (do_inquiry) {
01178cd4
JH
1865 err = hci_req_sync(hdev, hci_inq_req, (unsigned long) &ir,
1866 timeo);
70f23020
AE
1867 if (err < 0)
1868 goto done;
3e13fa1e
AG
1869
1870 /* Wait until Inquiry procedure finishes (HCI_INQUIRY flag is
1871 * cleared). If it is interrupted by a signal, return -EINTR.
1872 */
1873 if (wait_on_bit(&hdev->flags, HCI_INQUIRY, wait_inquiry,
1874 TASK_INTERRUPTIBLE))
1875 return -EINTR;
70f23020 1876 }
1da177e4 1877
8fc9ced3
GP
1878 /* for unlimited number of responses we will use buffer with
1879 * 255 entries
1880 */
1da177e4
LT
1881 max_rsp = (ir.num_rsp == 0) ? 255 : ir.num_rsp;
1882
1883 /* cache_dump can't sleep. Therefore we allocate temp buffer and then
1884 * copy it to the user space.
1885 */
01df8c31 1886 buf = kmalloc(sizeof(struct inquiry_info) * max_rsp, GFP_KERNEL);
70f23020 1887 if (!buf) {
1da177e4
LT
1888 err = -ENOMEM;
1889 goto done;
1890 }
1891
09fd0de5 1892 hci_dev_lock(hdev);
1da177e4 1893 ir.num_rsp = inquiry_cache_dump(hdev, max_rsp, buf);
09fd0de5 1894 hci_dev_unlock(hdev);
1da177e4
LT
1895
1896 BT_DBG("num_rsp %d", ir.num_rsp);
1897
1898 if (!copy_to_user(ptr, &ir, sizeof(ir))) {
1899 ptr += sizeof(ir);
1900 if (copy_to_user(ptr, buf, sizeof(struct inquiry_info) *
a8c5fb1a 1901 ir.num_rsp))
1da177e4 1902 err = -EFAULT;
8e87d142 1903 } else
1da177e4
LT
1904 err = -EFAULT;
1905
1906 kfree(buf);
1907
1908done:
1909 hci_dev_put(hdev);
1910 return err;
1911}
1912
cbed0ca1 1913static int hci_dev_do_open(struct hci_dev *hdev)
1da177e4 1914{
1da177e4
LT
1915 int ret = 0;
1916
1da177e4
LT
1917 BT_DBG("%s %p", hdev->name, hdev);
1918
1919 hci_req_lock(hdev);
1920
94324962
JH
1921 if (test_bit(HCI_UNREGISTER, &hdev->dev_flags)) {
1922 ret = -ENODEV;
1923 goto done;
1924 }
1925
a5c8f270
MH
1926 if (!test_bit(HCI_SETUP, &hdev->dev_flags)) {
1927 /* Check for rfkill but allow the HCI setup stage to
1928 * proceed (which in itself doesn't cause any RF activity).
1929 */
1930 if (test_bit(HCI_RFKILLED, &hdev->dev_flags)) {
1931 ret = -ERFKILL;
1932 goto done;
1933 }
1934
1935 /* Check for valid public address or a configured static
1936 * random adddress, but let the HCI setup proceed to
1937 * be able to determine if there is a public address
1938 * or not.
1939 *
1940 * This check is only valid for BR/EDR controllers
1941 * since AMP controllers do not have an address.
1942 */
1943 if (hdev->dev_type == HCI_BREDR &&
1944 !bacmp(&hdev->bdaddr, BDADDR_ANY) &&
1945 !bacmp(&hdev->static_addr, BDADDR_ANY)) {
1946 ret = -EADDRNOTAVAIL;
1947 goto done;
1948 }
611b30f7
MH
1949 }
1950
1da177e4
LT
1951 if (test_bit(HCI_UP, &hdev->flags)) {
1952 ret = -EALREADY;
1953 goto done;
1954 }
1955
1da177e4
LT
1956 if (hdev->open(hdev)) {
1957 ret = -EIO;
1958 goto done;
1959 }
1960
f41c70c4
MH
1961 atomic_set(&hdev->cmd_cnt, 1);
1962 set_bit(HCI_INIT, &hdev->flags);
1963
1964 if (hdev->setup && test_bit(HCI_SETUP, &hdev->dev_flags))
1965 ret = hdev->setup(hdev);
1966
1967 if (!ret) {
f41c70c4
MH
1968 if (test_bit(HCI_QUIRK_RAW_DEVICE, &hdev->quirks))
1969 set_bit(HCI_RAW, &hdev->flags);
1970
0736cfa8
MH
1971 if (!test_bit(HCI_RAW, &hdev->flags) &&
1972 !test_bit(HCI_USER_CHANNEL, &hdev->dev_flags))
f41c70c4 1973 ret = __hci_init(hdev);
1da177e4
LT
1974 }
1975
f41c70c4
MH
1976 clear_bit(HCI_INIT, &hdev->flags);
1977
1da177e4
LT
1978 if (!ret) {
1979 hci_dev_hold(hdev);
1980 set_bit(HCI_UP, &hdev->flags);
1981 hci_notify(hdev, HCI_DEV_UP);
bb4b2a9a 1982 if (!test_bit(HCI_SETUP, &hdev->dev_flags) &&
0736cfa8 1983 !test_bit(HCI_USER_CHANNEL, &hdev->dev_flags) &&
1514b892 1984 hdev->dev_type == HCI_BREDR) {
09fd0de5 1985 hci_dev_lock(hdev);
744cf19e 1986 mgmt_powered(hdev, 1);
09fd0de5 1987 hci_dev_unlock(hdev);
56e5cb86 1988 }
8e87d142 1989 } else {
1da177e4 1990 /* Init failed, cleanup */
3eff45ea 1991 flush_work(&hdev->tx_work);
c347b765 1992 flush_work(&hdev->cmd_work);
b78752cc 1993 flush_work(&hdev->rx_work);
1da177e4
LT
1994
1995 skb_queue_purge(&hdev->cmd_q);
1996 skb_queue_purge(&hdev->rx_q);
1997
1998 if (hdev->flush)
1999 hdev->flush(hdev);
2000
2001 if (hdev->sent_cmd) {
2002 kfree_skb(hdev->sent_cmd);
2003 hdev->sent_cmd = NULL;
2004 }
2005
2006 hdev->close(hdev);
2007 hdev->flags = 0;
2008 }
2009
2010done:
2011 hci_req_unlock(hdev);
1da177e4
LT
2012 return ret;
2013}
2014
cbed0ca1
JH
2015/* ---- HCI ioctl helpers ---- */
2016
2017int hci_dev_open(__u16 dev)
2018{
2019 struct hci_dev *hdev;
2020 int err;
2021
2022 hdev = hci_dev_get(dev);
2023 if (!hdev)
2024 return -ENODEV;
2025
e1d08f40
JH
2026 /* We need to ensure that no other power on/off work is pending
2027 * before proceeding to call hci_dev_do_open. This is
2028 * particularly important if the setup procedure has not yet
2029 * completed.
2030 */
2031 if (test_and_clear_bit(HCI_AUTO_OFF, &hdev->dev_flags))
2032 cancel_delayed_work(&hdev->power_off);
2033
a5c8f270
MH
2034 /* After this call it is guaranteed that the setup procedure
2035 * has finished. This means that error conditions like RFKILL
2036 * or no valid public or static random address apply.
2037 */
e1d08f40
JH
2038 flush_workqueue(hdev->req_workqueue);
2039
cbed0ca1
JH
2040 err = hci_dev_do_open(hdev);
2041
2042 hci_dev_put(hdev);
2043
2044 return err;
2045}
2046
1da177e4
LT
2047static int hci_dev_do_close(struct hci_dev *hdev)
2048{
2049 BT_DBG("%s %p", hdev->name, hdev);
2050
78c04c0b
VCG
2051 cancel_delayed_work(&hdev->power_off);
2052
1da177e4
LT
2053 hci_req_cancel(hdev, ENODEV);
2054 hci_req_lock(hdev);
2055
2056 if (!test_and_clear_bit(HCI_UP, &hdev->flags)) {
b79f44c1 2057 del_timer_sync(&hdev->cmd_timer);
1da177e4
LT
2058 hci_req_unlock(hdev);
2059 return 0;
2060 }
2061
3eff45ea
GP
2062 /* Flush RX and TX works */
2063 flush_work(&hdev->tx_work);
b78752cc 2064 flush_work(&hdev->rx_work);
1da177e4 2065
16ab91ab 2066 if (hdev->discov_timeout > 0) {
e0f9309f 2067 cancel_delayed_work(&hdev->discov_off);
16ab91ab 2068 hdev->discov_timeout = 0;
5e5282bb 2069 clear_bit(HCI_DISCOVERABLE, &hdev->dev_flags);
310a3d48 2070 clear_bit(HCI_LIMITED_DISCOVERABLE, &hdev->dev_flags);
16ab91ab
JH
2071 }
2072
a8b2d5c2 2073 if (test_and_clear_bit(HCI_SERVICE_CACHE, &hdev->dev_flags))
7d78525d
JH
2074 cancel_delayed_work(&hdev->service_cache);
2075
7ba8b4be
AG
2076 cancel_delayed_work_sync(&hdev->le_scan_disable);
2077
09fd0de5 2078 hci_dev_lock(hdev);
1f9b9a5d 2079 hci_inquiry_cache_flush(hdev);
1da177e4 2080 hci_conn_hash_flush(hdev);
09fd0de5 2081 hci_dev_unlock(hdev);
1da177e4
LT
2082
2083 hci_notify(hdev, HCI_DEV_DOWN);
2084
2085 if (hdev->flush)
2086 hdev->flush(hdev);
2087
2088 /* Reset device */
2089 skb_queue_purge(&hdev->cmd_q);
2090 atomic_set(&hdev->cmd_cnt, 1);
8af59467 2091 if (!test_bit(HCI_RAW, &hdev->flags) &&
3a6afbd2 2092 !test_bit(HCI_AUTO_OFF, &hdev->dev_flags) &&
a6c511c6 2093 test_bit(HCI_QUIRK_RESET_ON_CLOSE, &hdev->quirks)) {
1da177e4 2094 set_bit(HCI_INIT, &hdev->flags);
01178cd4 2095 __hci_req_sync(hdev, hci_reset_req, 0, HCI_CMD_TIMEOUT);
1da177e4
LT
2096 clear_bit(HCI_INIT, &hdev->flags);
2097 }
2098
c347b765
GP
2099 /* flush cmd work */
2100 flush_work(&hdev->cmd_work);
1da177e4
LT
2101
2102 /* Drop queues */
2103 skb_queue_purge(&hdev->rx_q);
2104 skb_queue_purge(&hdev->cmd_q);
2105 skb_queue_purge(&hdev->raw_q);
2106
2107 /* Drop last sent command */
2108 if (hdev->sent_cmd) {
b79f44c1 2109 del_timer_sync(&hdev->cmd_timer);
1da177e4
LT
2110 kfree_skb(hdev->sent_cmd);
2111 hdev->sent_cmd = NULL;
2112 }
2113
b6ddb638
JH
2114 kfree_skb(hdev->recv_evt);
2115 hdev->recv_evt = NULL;
2116
1da177e4
LT
2117 /* After this point our queues are empty
2118 * and no tasks are scheduled. */
2119 hdev->close(hdev);
2120
35b973c9
JH
2121 /* Clear flags */
2122 hdev->flags = 0;
2123 hdev->dev_flags &= ~HCI_PERSISTENT_MASK;
2124
93c311a0
MH
2125 if (!test_and_clear_bit(HCI_AUTO_OFF, &hdev->dev_flags)) {
2126 if (hdev->dev_type == HCI_BREDR) {
2127 hci_dev_lock(hdev);
2128 mgmt_powered(hdev, 0);
2129 hci_dev_unlock(hdev);
2130 }
8ee56540 2131 }
5add6af8 2132
ced5c338 2133 /* Controller radio is available but is currently powered down */
536619e8 2134 hdev->amp_status = AMP_STATUS_POWERED_DOWN;
ced5c338 2135
e59fda8d 2136 memset(hdev->eir, 0, sizeof(hdev->eir));
09b3c3fb 2137 memset(hdev->dev_class, 0, sizeof(hdev->dev_class));
e59fda8d 2138
1da177e4
LT
2139 hci_req_unlock(hdev);
2140
2141 hci_dev_put(hdev);
2142 return 0;
2143}
2144
2145int hci_dev_close(__u16 dev)
2146{
2147 struct hci_dev *hdev;
2148 int err;
2149
70f23020
AE
2150 hdev = hci_dev_get(dev);
2151 if (!hdev)
1da177e4 2152 return -ENODEV;
8ee56540 2153
0736cfa8
MH
2154 if (test_bit(HCI_USER_CHANNEL, &hdev->dev_flags)) {
2155 err = -EBUSY;
2156 goto done;
2157 }
2158
8ee56540
MH
2159 if (test_and_clear_bit(HCI_AUTO_OFF, &hdev->dev_flags))
2160 cancel_delayed_work(&hdev->power_off);
2161
1da177e4 2162 err = hci_dev_do_close(hdev);
8ee56540 2163
0736cfa8 2164done:
1da177e4
LT
2165 hci_dev_put(hdev);
2166 return err;
2167}
2168
2169int hci_dev_reset(__u16 dev)
2170{
2171 struct hci_dev *hdev;
2172 int ret = 0;
2173
70f23020
AE
2174 hdev = hci_dev_get(dev);
2175 if (!hdev)
1da177e4
LT
2176 return -ENODEV;
2177
2178 hci_req_lock(hdev);
1da177e4 2179
808a049e
MH
2180 if (!test_bit(HCI_UP, &hdev->flags)) {
2181 ret = -ENETDOWN;
1da177e4 2182 goto done;
808a049e 2183 }
1da177e4 2184
0736cfa8
MH
2185 if (test_bit(HCI_USER_CHANNEL, &hdev->dev_flags)) {
2186 ret = -EBUSY;
2187 goto done;
2188 }
2189
1da177e4
LT
2190 /* Drop queues */
2191 skb_queue_purge(&hdev->rx_q);
2192 skb_queue_purge(&hdev->cmd_q);
2193
09fd0de5 2194 hci_dev_lock(hdev);
1f9b9a5d 2195 hci_inquiry_cache_flush(hdev);
1da177e4 2196 hci_conn_hash_flush(hdev);
09fd0de5 2197 hci_dev_unlock(hdev);
1da177e4
LT
2198
2199 if (hdev->flush)
2200 hdev->flush(hdev);
2201
8e87d142 2202 atomic_set(&hdev->cmd_cnt, 1);
6ed58ec5 2203 hdev->acl_cnt = 0; hdev->sco_cnt = 0; hdev->le_cnt = 0;
1da177e4
LT
2204
2205 if (!test_bit(HCI_RAW, &hdev->flags))
01178cd4 2206 ret = __hci_req_sync(hdev, hci_reset_req, 0, HCI_INIT_TIMEOUT);
1da177e4
LT
2207
2208done:
1da177e4
LT
2209 hci_req_unlock(hdev);
2210 hci_dev_put(hdev);
2211 return ret;
2212}
2213
2214int hci_dev_reset_stat(__u16 dev)
2215{
2216 struct hci_dev *hdev;
2217 int ret = 0;
2218
70f23020
AE
2219 hdev = hci_dev_get(dev);
2220 if (!hdev)
1da177e4
LT
2221 return -ENODEV;
2222
0736cfa8
MH
2223 if (test_bit(HCI_USER_CHANNEL, &hdev->dev_flags)) {
2224 ret = -EBUSY;
2225 goto done;
2226 }
2227
1da177e4
LT
2228 memset(&hdev->stat, 0, sizeof(struct hci_dev_stats));
2229
0736cfa8 2230done:
1da177e4 2231 hci_dev_put(hdev);
1da177e4
LT
2232 return ret;
2233}
2234
2235int hci_dev_cmd(unsigned int cmd, void __user *arg)
2236{
2237 struct hci_dev *hdev;
2238 struct hci_dev_req dr;
2239 int err = 0;
2240
2241 if (copy_from_user(&dr, arg, sizeof(dr)))
2242 return -EFAULT;
2243
70f23020
AE
2244 hdev = hci_dev_get(dr.dev_id);
2245 if (!hdev)
1da177e4
LT
2246 return -ENODEV;
2247
0736cfa8
MH
2248 if (test_bit(HCI_USER_CHANNEL, &hdev->dev_flags)) {
2249 err = -EBUSY;
2250 goto done;
2251 }
2252
5b69bef5
MH
2253 if (hdev->dev_type != HCI_BREDR) {
2254 err = -EOPNOTSUPP;
2255 goto done;
2256 }
2257
56f87901
JH
2258 if (!test_bit(HCI_BREDR_ENABLED, &hdev->dev_flags)) {
2259 err = -EOPNOTSUPP;
2260 goto done;
2261 }
2262
1da177e4
LT
2263 switch (cmd) {
2264 case HCISETAUTH:
01178cd4
JH
2265 err = hci_req_sync(hdev, hci_auth_req, dr.dev_opt,
2266 HCI_INIT_TIMEOUT);
1da177e4
LT
2267 break;
2268
2269 case HCISETENCRYPT:
2270 if (!lmp_encrypt_capable(hdev)) {
2271 err = -EOPNOTSUPP;
2272 break;
2273 }
2274
2275 if (!test_bit(HCI_AUTH, &hdev->flags)) {
2276 /* Auth must be enabled first */
01178cd4
JH
2277 err = hci_req_sync(hdev, hci_auth_req, dr.dev_opt,
2278 HCI_INIT_TIMEOUT);
1da177e4
LT
2279 if (err)
2280 break;
2281 }
2282
01178cd4
JH
2283 err = hci_req_sync(hdev, hci_encrypt_req, dr.dev_opt,
2284 HCI_INIT_TIMEOUT);
1da177e4
LT
2285 break;
2286
2287 case HCISETSCAN:
01178cd4
JH
2288 err = hci_req_sync(hdev, hci_scan_req, dr.dev_opt,
2289 HCI_INIT_TIMEOUT);
1da177e4
LT
2290 break;
2291
1da177e4 2292 case HCISETLINKPOL:
01178cd4
JH
2293 err = hci_req_sync(hdev, hci_linkpol_req, dr.dev_opt,
2294 HCI_INIT_TIMEOUT);
1da177e4
LT
2295 break;
2296
2297 case HCISETLINKMODE:
e4e8e37c
MH
2298 hdev->link_mode = ((__u16) dr.dev_opt) &
2299 (HCI_LM_MASTER | HCI_LM_ACCEPT);
2300 break;
2301
2302 case HCISETPTYPE:
2303 hdev->pkt_type = (__u16) dr.dev_opt;
1da177e4
LT
2304 break;
2305
2306 case HCISETACLMTU:
e4e8e37c
MH
2307 hdev->acl_mtu = *((__u16 *) &dr.dev_opt + 1);
2308 hdev->acl_pkts = *((__u16 *) &dr.dev_opt + 0);
1da177e4
LT
2309 break;
2310
2311 case HCISETSCOMTU:
e4e8e37c
MH
2312 hdev->sco_mtu = *((__u16 *) &dr.dev_opt + 1);
2313 hdev->sco_pkts = *((__u16 *) &dr.dev_opt + 0);
1da177e4
LT
2314 break;
2315
2316 default:
2317 err = -EINVAL;
2318 break;
2319 }
e4e8e37c 2320
0736cfa8 2321done:
1da177e4
LT
2322 hci_dev_put(hdev);
2323 return err;
2324}
2325
2326int hci_get_dev_list(void __user *arg)
2327{
8035ded4 2328 struct hci_dev *hdev;
1da177e4
LT
2329 struct hci_dev_list_req *dl;
2330 struct hci_dev_req *dr;
1da177e4
LT
2331 int n = 0, size, err;
2332 __u16 dev_num;
2333
2334 if (get_user(dev_num, (__u16 __user *) arg))
2335 return -EFAULT;
2336
2337 if (!dev_num || dev_num > (PAGE_SIZE * 2) / sizeof(*dr))
2338 return -EINVAL;
2339
2340 size = sizeof(*dl) + dev_num * sizeof(*dr);
2341
70f23020
AE
2342 dl = kzalloc(size, GFP_KERNEL);
2343 if (!dl)
1da177e4
LT
2344 return -ENOMEM;
2345
2346 dr = dl->dev_req;
2347
f20d09d5 2348 read_lock(&hci_dev_list_lock);
8035ded4 2349 list_for_each_entry(hdev, &hci_dev_list, list) {
a8b2d5c2 2350 if (test_and_clear_bit(HCI_AUTO_OFF, &hdev->dev_flags))
e0f9309f 2351 cancel_delayed_work(&hdev->power_off);
c542a06c 2352
a8b2d5c2
JH
2353 if (!test_bit(HCI_MGMT, &hdev->dev_flags))
2354 set_bit(HCI_PAIRABLE, &hdev->dev_flags);
c542a06c 2355
1da177e4
LT
2356 (dr + n)->dev_id = hdev->id;
2357 (dr + n)->dev_opt = hdev->flags;
c542a06c 2358
1da177e4
LT
2359 if (++n >= dev_num)
2360 break;
2361 }
f20d09d5 2362 read_unlock(&hci_dev_list_lock);
1da177e4
LT
2363
2364 dl->dev_num = n;
2365 size = sizeof(*dl) + n * sizeof(*dr);
2366
2367 err = copy_to_user(arg, dl, size);
2368 kfree(dl);
2369
2370 return err ? -EFAULT : 0;
2371}
2372
2373int hci_get_dev_info(void __user *arg)
2374{
2375 struct hci_dev *hdev;
2376 struct hci_dev_info di;
2377 int err = 0;
2378
2379 if (copy_from_user(&di, arg, sizeof(di)))
2380 return -EFAULT;
2381
70f23020
AE
2382 hdev = hci_dev_get(di.dev_id);
2383 if (!hdev)
1da177e4
LT
2384 return -ENODEV;
2385
a8b2d5c2 2386 if (test_and_clear_bit(HCI_AUTO_OFF, &hdev->dev_flags))
3243553f 2387 cancel_delayed_work_sync(&hdev->power_off);
ab81cbf9 2388
a8b2d5c2
JH
2389 if (!test_bit(HCI_MGMT, &hdev->dev_flags))
2390 set_bit(HCI_PAIRABLE, &hdev->dev_flags);
c542a06c 2391
1da177e4
LT
2392 strcpy(di.name, hdev->name);
2393 di.bdaddr = hdev->bdaddr;
60f2a3ed 2394 di.type = (hdev->bus & 0x0f) | ((hdev->dev_type & 0x03) << 4);
1da177e4
LT
2395 di.flags = hdev->flags;
2396 di.pkt_type = hdev->pkt_type;
572c7f84
JH
2397 if (lmp_bredr_capable(hdev)) {
2398 di.acl_mtu = hdev->acl_mtu;
2399 di.acl_pkts = hdev->acl_pkts;
2400 di.sco_mtu = hdev->sco_mtu;
2401 di.sco_pkts = hdev->sco_pkts;
2402 } else {
2403 di.acl_mtu = hdev->le_mtu;
2404 di.acl_pkts = hdev->le_pkts;
2405 di.sco_mtu = 0;
2406 di.sco_pkts = 0;
2407 }
1da177e4
LT
2408 di.link_policy = hdev->link_policy;
2409 di.link_mode = hdev->link_mode;
2410
2411 memcpy(&di.stat, &hdev->stat, sizeof(di.stat));
2412 memcpy(&di.features, &hdev->features, sizeof(di.features));
2413
2414 if (copy_to_user(arg, &di, sizeof(di)))
2415 err = -EFAULT;
2416
2417 hci_dev_put(hdev);
2418
2419 return err;
2420}
2421
2422/* ---- Interface to HCI drivers ---- */
2423
611b30f7
MH
2424static int hci_rfkill_set_block(void *data, bool blocked)
2425{
2426 struct hci_dev *hdev = data;
2427
2428 BT_DBG("%p name %s blocked %d", hdev, hdev->name, blocked);
2429
0736cfa8
MH
2430 if (test_bit(HCI_USER_CHANNEL, &hdev->dev_flags))
2431 return -EBUSY;
2432
5e130367
JH
2433 if (blocked) {
2434 set_bit(HCI_RFKILLED, &hdev->dev_flags);
bf543036
JH
2435 if (!test_bit(HCI_SETUP, &hdev->dev_flags))
2436 hci_dev_do_close(hdev);
5e130367
JH
2437 } else {
2438 clear_bit(HCI_RFKILLED, &hdev->dev_flags);
1025c04c 2439 }
611b30f7
MH
2440
2441 return 0;
2442}
2443
2444static const struct rfkill_ops hci_rfkill_ops = {
2445 .set_block = hci_rfkill_set_block,
2446};
2447
ab81cbf9
JH
2448static void hci_power_on(struct work_struct *work)
2449{
2450 struct hci_dev *hdev = container_of(work, struct hci_dev, power_on);
96570ffc 2451 int err;
ab81cbf9
JH
2452
2453 BT_DBG("%s", hdev->name);
2454
cbed0ca1 2455 err = hci_dev_do_open(hdev);
96570ffc
JH
2456 if (err < 0) {
2457 mgmt_set_powered_failed(hdev, err);
ab81cbf9 2458 return;
96570ffc 2459 }
ab81cbf9 2460
a5c8f270
MH
2461 /* During the HCI setup phase, a few error conditions are
2462 * ignored and they need to be checked now. If they are still
2463 * valid, it is important to turn the device back off.
2464 */
2465 if (test_bit(HCI_RFKILLED, &hdev->dev_flags) ||
2466 (hdev->dev_type == HCI_BREDR &&
2467 !bacmp(&hdev->bdaddr, BDADDR_ANY) &&
2468 !bacmp(&hdev->static_addr, BDADDR_ANY))) {
bf543036
JH
2469 clear_bit(HCI_AUTO_OFF, &hdev->dev_flags);
2470 hci_dev_do_close(hdev);
2471 } else if (test_bit(HCI_AUTO_OFF, &hdev->dev_flags)) {
19202573
JH
2472 queue_delayed_work(hdev->req_workqueue, &hdev->power_off,
2473 HCI_AUTO_OFF_TIMEOUT);
bf543036 2474 }
ab81cbf9 2475
a8b2d5c2 2476 if (test_and_clear_bit(HCI_SETUP, &hdev->dev_flags))
744cf19e 2477 mgmt_index_added(hdev);
ab81cbf9
JH
2478}
2479
2480static void hci_power_off(struct work_struct *work)
2481{
3243553f 2482 struct hci_dev *hdev = container_of(work, struct hci_dev,
a8c5fb1a 2483 power_off.work);
ab81cbf9
JH
2484
2485 BT_DBG("%s", hdev->name);
2486
8ee56540 2487 hci_dev_do_close(hdev);
ab81cbf9
JH
2488}
2489
16ab91ab
JH
2490static void hci_discov_off(struct work_struct *work)
2491{
2492 struct hci_dev *hdev;
16ab91ab
JH
2493
2494 hdev = container_of(work, struct hci_dev, discov_off.work);
2495
2496 BT_DBG("%s", hdev->name);
2497
d1967ff8 2498 mgmt_discoverable_timeout(hdev);
16ab91ab
JH
2499}
2500
2aeb9a1a
JH
2501int hci_uuids_clear(struct hci_dev *hdev)
2502{
4821002c 2503 struct bt_uuid *uuid, *tmp;
2aeb9a1a 2504
4821002c
JH
2505 list_for_each_entry_safe(uuid, tmp, &hdev->uuids, list) {
2506 list_del(&uuid->list);
2aeb9a1a
JH
2507 kfree(uuid);
2508 }
2509
2510 return 0;
2511}
2512
55ed8ca1
JH
2513int hci_link_keys_clear(struct hci_dev *hdev)
2514{
2515 struct list_head *p, *n;
2516
2517 list_for_each_safe(p, n, &hdev->link_keys) {
2518 struct link_key *key;
2519
2520 key = list_entry(p, struct link_key, list);
2521
2522 list_del(p);
2523 kfree(key);
2524 }
2525
2526 return 0;
2527}
2528
b899efaf
VCG
2529int hci_smp_ltks_clear(struct hci_dev *hdev)
2530{
2531 struct smp_ltk *k, *tmp;
2532
2533 list_for_each_entry_safe(k, tmp, &hdev->long_term_keys, list) {
2534 list_del(&k->list);
2535 kfree(k);
2536 }
2537
2538 return 0;
2539}
2540
55ed8ca1
JH
2541struct link_key *hci_find_link_key(struct hci_dev *hdev, bdaddr_t *bdaddr)
2542{
8035ded4 2543 struct link_key *k;
55ed8ca1 2544
8035ded4 2545 list_for_each_entry(k, &hdev->link_keys, list)
55ed8ca1
JH
2546 if (bacmp(bdaddr, &k->bdaddr) == 0)
2547 return k;
55ed8ca1
JH
2548
2549 return NULL;
2550}
2551
745c0ce3 2552static bool hci_persistent_key(struct hci_dev *hdev, struct hci_conn *conn,
a8c5fb1a 2553 u8 key_type, u8 old_key_type)
d25e28ab
JH
2554{
2555 /* Legacy key */
2556 if (key_type < 0x03)
745c0ce3 2557 return true;
d25e28ab
JH
2558
2559 /* Debug keys are insecure so don't store them persistently */
2560 if (key_type == HCI_LK_DEBUG_COMBINATION)
745c0ce3 2561 return false;
d25e28ab
JH
2562
2563 /* Changed combination key and there's no previous one */
2564 if (key_type == HCI_LK_CHANGED_COMBINATION && old_key_type == 0xff)
745c0ce3 2565 return false;
d25e28ab
JH
2566
2567 /* Security mode 3 case */
2568 if (!conn)
745c0ce3 2569 return true;
d25e28ab
JH
2570
2571 /* Neither local nor remote side had no-bonding as requirement */
2572 if (conn->auth_type > 0x01 && conn->remote_auth > 0x01)
745c0ce3 2573 return true;
d25e28ab
JH
2574
2575 /* Local side had dedicated bonding as requirement */
2576 if (conn->auth_type == 0x02 || conn->auth_type == 0x03)
745c0ce3 2577 return true;
d25e28ab
JH
2578
2579 /* Remote side had dedicated bonding as requirement */
2580 if (conn->remote_auth == 0x02 || conn->remote_auth == 0x03)
745c0ce3 2581 return true;
d25e28ab
JH
2582
2583 /* If none of the above criteria match, then don't store the key
2584 * persistently */
745c0ce3 2585 return false;
d25e28ab
JH
2586}
2587
98a0b845
JH
2588static bool ltk_type_master(u8 type)
2589{
2590 if (type == HCI_SMP_STK || type == HCI_SMP_LTK)
2591 return true;
2592
2593 return false;
2594}
2595
2596struct smp_ltk *hci_find_ltk(struct hci_dev *hdev, __le16 ediv, u8 rand[8],
2597 bool master)
75d262c2 2598{
c9839a11 2599 struct smp_ltk *k;
75d262c2 2600
c9839a11
VCG
2601 list_for_each_entry(k, &hdev->long_term_keys, list) {
2602 if (k->ediv != ediv ||
a8c5fb1a 2603 memcmp(rand, k->rand, sizeof(k->rand)))
75d262c2
VCG
2604 continue;
2605
98a0b845
JH
2606 if (ltk_type_master(k->type) != master)
2607 continue;
2608
c9839a11 2609 return k;
75d262c2
VCG
2610 }
2611
2612 return NULL;
2613}
75d262c2 2614
c9839a11 2615struct smp_ltk *hci_find_ltk_by_addr(struct hci_dev *hdev, bdaddr_t *bdaddr,
98a0b845 2616 u8 addr_type, bool master)
75d262c2 2617{
c9839a11 2618 struct smp_ltk *k;
75d262c2 2619
c9839a11
VCG
2620 list_for_each_entry(k, &hdev->long_term_keys, list)
2621 if (addr_type == k->bdaddr_type &&
98a0b845
JH
2622 bacmp(bdaddr, &k->bdaddr) == 0 &&
2623 ltk_type_master(k->type) == master)
75d262c2
VCG
2624 return k;
2625
2626 return NULL;
2627}
75d262c2 2628
d25e28ab 2629int hci_add_link_key(struct hci_dev *hdev, struct hci_conn *conn, int new_key,
04124681 2630 bdaddr_t *bdaddr, u8 *val, u8 type, u8 pin_len)
55ed8ca1
JH
2631{
2632 struct link_key *key, *old_key;
745c0ce3
VA
2633 u8 old_key_type;
2634 bool persistent;
55ed8ca1
JH
2635
2636 old_key = hci_find_link_key(hdev, bdaddr);
2637 if (old_key) {
2638 old_key_type = old_key->type;
2639 key = old_key;
2640 } else {
12adcf3a 2641 old_key_type = conn ? conn->key_type : 0xff;
55ed8ca1
JH
2642 key = kzalloc(sizeof(*key), GFP_ATOMIC);
2643 if (!key)
2644 return -ENOMEM;
2645 list_add(&key->list, &hdev->link_keys);
2646 }
2647
6ed93dc6 2648 BT_DBG("%s key for %pMR type %u", hdev->name, bdaddr, type);
55ed8ca1 2649
d25e28ab
JH
2650 /* Some buggy controller combinations generate a changed
2651 * combination key for legacy pairing even when there's no
2652 * previous key */
2653 if (type == HCI_LK_CHANGED_COMBINATION &&
a8c5fb1a 2654 (!conn || conn->remote_auth == 0xff) && old_key_type == 0xff) {
d25e28ab 2655 type = HCI_LK_COMBINATION;
655fe6ec
JH
2656 if (conn)
2657 conn->key_type = type;
2658 }
d25e28ab 2659
55ed8ca1 2660 bacpy(&key->bdaddr, bdaddr);
9b3b4460 2661 memcpy(key->val, val, HCI_LINK_KEY_SIZE);
55ed8ca1
JH
2662 key->pin_len = pin_len;
2663
b6020ba0 2664 if (type == HCI_LK_CHANGED_COMBINATION)
55ed8ca1 2665 key->type = old_key_type;
4748fed2
JH
2666 else
2667 key->type = type;
2668
4df378a1
JH
2669 if (!new_key)
2670 return 0;
2671
2672 persistent = hci_persistent_key(hdev, conn, type, old_key_type);
2673
744cf19e 2674 mgmt_new_link_key(hdev, key, persistent);
4df378a1 2675
6ec5bcad
VA
2676 if (conn)
2677 conn->flush_key = !persistent;
55ed8ca1
JH
2678
2679 return 0;
2680}
2681
c9839a11 2682int hci_add_ltk(struct hci_dev *hdev, bdaddr_t *bdaddr, u8 addr_type, u8 type,
9a006657 2683 int new_key, u8 authenticated, u8 tk[16], u8 enc_size, __le16
04124681 2684 ediv, u8 rand[8])
75d262c2 2685{
c9839a11 2686 struct smp_ltk *key, *old_key;
98a0b845 2687 bool master = ltk_type_master(type);
75d262c2 2688
98a0b845 2689 old_key = hci_find_ltk_by_addr(hdev, bdaddr, addr_type, master);
c9839a11 2690 if (old_key)
75d262c2 2691 key = old_key;
c9839a11
VCG
2692 else {
2693 key = kzalloc(sizeof(*key), GFP_ATOMIC);
75d262c2
VCG
2694 if (!key)
2695 return -ENOMEM;
c9839a11 2696 list_add(&key->list, &hdev->long_term_keys);
75d262c2
VCG
2697 }
2698
75d262c2 2699 bacpy(&key->bdaddr, bdaddr);
c9839a11
VCG
2700 key->bdaddr_type = addr_type;
2701 memcpy(key->val, tk, sizeof(key->val));
2702 key->authenticated = authenticated;
2703 key->ediv = ediv;
2704 key->enc_size = enc_size;
2705 key->type = type;
2706 memcpy(key->rand, rand, sizeof(key->rand));
75d262c2 2707
c9839a11
VCG
2708 if (!new_key)
2709 return 0;
75d262c2 2710
21b93b75 2711 if (type == HCI_SMP_LTK || type == HCI_SMP_LTK_SLAVE)
261cc5aa
VCG
2712 mgmt_new_ltk(hdev, key, 1);
2713
75d262c2
VCG
2714 return 0;
2715}
2716
55ed8ca1
JH
2717int hci_remove_link_key(struct hci_dev *hdev, bdaddr_t *bdaddr)
2718{
2719 struct link_key *key;
2720
2721 key = hci_find_link_key(hdev, bdaddr);
2722 if (!key)
2723 return -ENOENT;
2724
6ed93dc6 2725 BT_DBG("%s removing %pMR", hdev->name, bdaddr);
55ed8ca1
JH
2726
2727 list_del(&key->list);
2728 kfree(key);
2729
2730 return 0;
2731}
2732
b899efaf
VCG
2733int hci_remove_ltk(struct hci_dev *hdev, bdaddr_t *bdaddr)
2734{
2735 struct smp_ltk *k, *tmp;
2736
2737 list_for_each_entry_safe(k, tmp, &hdev->long_term_keys, list) {
2738 if (bacmp(bdaddr, &k->bdaddr))
2739 continue;
2740
6ed93dc6 2741 BT_DBG("%s removing %pMR", hdev->name, bdaddr);
b899efaf
VCG
2742
2743 list_del(&k->list);
2744 kfree(k);
2745 }
2746
2747 return 0;
2748}
2749
6bd32326 2750/* HCI command timer function */
bda4f23a 2751static void hci_cmd_timeout(unsigned long arg)
6bd32326
VT
2752{
2753 struct hci_dev *hdev = (void *) arg;
2754
bda4f23a
AE
2755 if (hdev->sent_cmd) {
2756 struct hci_command_hdr *sent = (void *) hdev->sent_cmd->data;
2757 u16 opcode = __le16_to_cpu(sent->opcode);
2758
2759 BT_ERR("%s command 0x%4.4x tx timeout", hdev->name, opcode);
2760 } else {
2761 BT_ERR("%s command tx timeout", hdev->name);
2762 }
2763
6bd32326 2764 atomic_set(&hdev->cmd_cnt, 1);
c347b765 2765 queue_work(hdev->workqueue, &hdev->cmd_work);
6bd32326
VT
2766}
2767
2763eda6 2768struct oob_data *hci_find_remote_oob_data(struct hci_dev *hdev,
04124681 2769 bdaddr_t *bdaddr)
2763eda6
SJ
2770{
2771 struct oob_data *data;
2772
2773 list_for_each_entry(data, &hdev->remote_oob_data, list)
2774 if (bacmp(bdaddr, &data->bdaddr) == 0)
2775 return data;
2776
2777 return NULL;
2778}
2779
2780int hci_remove_remote_oob_data(struct hci_dev *hdev, bdaddr_t *bdaddr)
2781{
2782 struct oob_data *data;
2783
2784 data = hci_find_remote_oob_data(hdev, bdaddr);
2785 if (!data)
2786 return -ENOENT;
2787
6ed93dc6 2788 BT_DBG("%s removing %pMR", hdev->name, bdaddr);
2763eda6
SJ
2789
2790 list_del(&data->list);
2791 kfree(data);
2792
2793 return 0;
2794}
2795
2796int hci_remote_oob_data_clear(struct hci_dev *hdev)
2797{
2798 struct oob_data *data, *n;
2799
2800 list_for_each_entry_safe(data, n, &hdev->remote_oob_data, list) {
2801 list_del(&data->list);
2802 kfree(data);
2803 }
2804
2805 return 0;
2806}
2807
0798872e
MH
2808int hci_add_remote_oob_data(struct hci_dev *hdev, bdaddr_t *bdaddr,
2809 u8 *hash, u8 *randomizer)
2763eda6
SJ
2810{
2811 struct oob_data *data;
2812
2813 data = hci_find_remote_oob_data(hdev, bdaddr);
2763eda6 2814 if (!data) {
0798872e 2815 data = kmalloc(sizeof(*data), GFP_ATOMIC);
2763eda6
SJ
2816 if (!data)
2817 return -ENOMEM;
2818
2819 bacpy(&data->bdaddr, bdaddr);
2820 list_add(&data->list, &hdev->remote_oob_data);
2821 }
2822
519ca9d0
MH
2823 memcpy(data->hash192, hash, sizeof(data->hash192));
2824 memcpy(data->randomizer192, randomizer, sizeof(data->randomizer192));
2763eda6 2825
0798872e
MH
2826 memset(data->hash256, 0, sizeof(data->hash256));
2827 memset(data->randomizer256, 0, sizeof(data->randomizer256));
2828
2829 BT_DBG("%s for %pMR", hdev->name, bdaddr);
2830
2831 return 0;
2832}
2833
2834int hci_add_remote_oob_ext_data(struct hci_dev *hdev, bdaddr_t *bdaddr,
2835 u8 *hash192, u8 *randomizer192,
2836 u8 *hash256, u8 *randomizer256)
2837{
2838 struct oob_data *data;
2839
2840 data = hci_find_remote_oob_data(hdev, bdaddr);
2841 if (!data) {
2842 data = kmalloc(sizeof(*data), GFP_ATOMIC);
2843 if (!data)
2844 return -ENOMEM;
2845
2846 bacpy(&data->bdaddr, bdaddr);
2847 list_add(&data->list, &hdev->remote_oob_data);
2848 }
2849
2850 memcpy(data->hash192, hash192, sizeof(data->hash192));
2851 memcpy(data->randomizer192, randomizer192, sizeof(data->randomizer192));
2852
2853 memcpy(data->hash256, hash256, sizeof(data->hash256));
2854 memcpy(data->randomizer256, randomizer256, sizeof(data->randomizer256));
2855
6ed93dc6 2856 BT_DBG("%s for %pMR", hdev->name, bdaddr);
2763eda6
SJ
2857
2858 return 0;
2859}
2860
b9ee0a78
MH
2861struct bdaddr_list *hci_blacklist_lookup(struct hci_dev *hdev,
2862 bdaddr_t *bdaddr, u8 type)
b2a66aad 2863{
8035ded4 2864 struct bdaddr_list *b;
b2a66aad 2865
b9ee0a78
MH
2866 list_for_each_entry(b, &hdev->blacklist, list) {
2867 if (!bacmp(&b->bdaddr, bdaddr) && b->bdaddr_type == type)
b2a66aad 2868 return b;
b9ee0a78 2869 }
b2a66aad
AJ
2870
2871 return NULL;
2872}
2873
2874int hci_blacklist_clear(struct hci_dev *hdev)
2875{
2876 struct list_head *p, *n;
2877
2878 list_for_each_safe(p, n, &hdev->blacklist) {
b9ee0a78 2879 struct bdaddr_list *b = list_entry(p, struct bdaddr_list, list);
b2a66aad
AJ
2880
2881 list_del(p);
2882 kfree(b);
2883 }
2884
2885 return 0;
2886}
2887
88c1fe4b 2888int hci_blacklist_add(struct hci_dev *hdev, bdaddr_t *bdaddr, u8 type)
b2a66aad
AJ
2889{
2890 struct bdaddr_list *entry;
b2a66aad 2891
b9ee0a78 2892 if (!bacmp(bdaddr, BDADDR_ANY))
b2a66aad
AJ
2893 return -EBADF;
2894
b9ee0a78 2895 if (hci_blacklist_lookup(hdev, bdaddr, type))
5e762444 2896 return -EEXIST;
b2a66aad
AJ
2897
2898 entry = kzalloc(sizeof(struct bdaddr_list), GFP_KERNEL);
5e762444
AJ
2899 if (!entry)
2900 return -ENOMEM;
b2a66aad
AJ
2901
2902 bacpy(&entry->bdaddr, bdaddr);
b9ee0a78 2903 entry->bdaddr_type = type;
b2a66aad
AJ
2904
2905 list_add(&entry->list, &hdev->blacklist);
2906
88c1fe4b 2907 return mgmt_device_blocked(hdev, bdaddr, type);
b2a66aad
AJ
2908}
2909
88c1fe4b 2910int hci_blacklist_del(struct hci_dev *hdev, bdaddr_t *bdaddr, u8 type)
b2a66aad
AJ
2911{
2912 struct bdaddr_list *entry;
b2a66aad 2913
b9ee0a78 2914 if (!bacmp(bdaddr, BDADDR_ANY))
5e762444 2915 return hci_blacklist_clear(hdev);
b2a66aad 2916
b9ee0a78 2917 entry = hci_blacklist_lookup(hdev, bdaddr, type);
1ec918ce 2918 if (!entry)
5e762444 2919 return -ENOENT;
b2a66aad
AJ
2920
2921 list_del(&entry->list);
2922 kfree(entry);
2923
88c1fe4b 2924 return mgmt_device_unblocked(hdev, bdaddr, type);
b2a66aad
AJ
2925}
2926
4c87eaab 2927static void inquiry_complete(struct hci_dev *hdev, u8 status)
7ba8b4be 2928{
4c87eaab
AG
2929 if (status) {
2930 BT_ERR("Failed to start inquiry: status %d", status);
7ba8b4be 2931
4c87eaab
AG
2932 hci_dev_lock(hdev);
2933 hci_discovery_set_state(hdev, DISCOVERY_STOPPED);
2934 hci_dev_unlock(hdev);
2935 return;
2936 }
7ba8b4be
AG
2937}
2938
4c87eaab 2939static void le_scan_disable_work_complete(struct hci_dev *hdev, u8 status)
7ba8b4be 2940{
4c87eaab
AG
2941 /* General inquiry access code (GIAC) */
2942 u8 lap[3] = { 0x33, 0x8b, 0x9e };
2943 struct hci_request req;
2944 struct hci_cp_inquiry cp;
7ba8b4be
AG
2945 int err;
2946
4c87eaab
AG
2947 if (status) {
2948 BT_ERR("Failed to disable LE scanning: status %d", status);
2949 return;
2950 }
7ba8b4be 2951
4c87eaab
AG
2952 switch (hdev->discovery.type) {
2953 case DISCOV_TYPE_LE:
2954 hci_dev_lock(hdev);
2955 hci_discovery_set_state(hdev, DISCOVERY_STOPPED);
2956 hci_dev_unlock(hdev);
2957 break;
7ba8b4be 2958
4c87eaab
AG
2959 case DISCOV_TYPE_INTERLEAVED:
2960 hci_req_init(&req, hdev);
7ba8b4be 2961
4c87eaab
AG
2962 memset(&cp, 0, sizeof(cp));
2963 memcpy(&cp.lap, lap, sizeof(cp.lap));
2964 cp.length = DISCOV_INTERLEAVED_INQUIRY_LEN;
2965 hci_req_add(&req, HCI_OP_INQUIRY, sizeof(cp), &cp);
7ba8b4be 2966
4c87eaab 2967 hci_dev_lock(hdev);
7dbfac1d 2968
4c87eaab 2969 hci_inquiry_cache_flush(hdev);
7dbfac1d 2970
4c87eaab
AG
2971 err = hci_req_run(&req, inquiry_complete);
2972 if (err) {
2973 BT_ERR("Inquiry request failed: err %d", err);
2974 hci_discovery_set_state(hdev, DISCOVERY_STOPPED);
2975 }
7dbfac1d 2976
4c87eaab
AG
2977 hci_dev_unlock(hdev);
2978 break;
7dbfac1d 2979 }
7dbfac1d
AG
2980}
2981
7ba8b4be
AG
2982static void le_scan_disable_work(struct work_struct *work)
2983{
2984 struct hci_dev *hdev = container_of(work, struct hci_dev,
04124681 2985 le_scan_disable.work);
7ba8b4be 2986 struct hci_cp_le_set_scan_enable cp;
4c87eaab
AG
2987 struct hci_request req;
2988 int err;
7ba8b4be
AG
2989
2990 BT_DBG("%s", hdev->name);
2991
4c87eaab 2992 hci_req_init(&req, hdev);
28b75a89 2993
7ba8b4be 2994 memset(&cp, 0, sizeof(cp));
4c87eaab
AG
2995 cp.enable = LE_SCAN_DISABLE;
2996 hci_req_add(&req, HCI_OP_LE_SET_SCAN_ENABLE, sizeof(cp), &cp);
28b75a89 2997
4c87eaab
AG
2998 err = hci_req_run(&req, le_scan_disable_work_complete);
2999 if (err)
3000 BT_ERR("Disable LE scanning request failed: err %d", err);
28b75a89
AG
3001}
3002
9be0dab7
DH
3003/* Alloc HCI device */
3004struct hci_dev *hci_alloc_dev(void)
3005{
3006 struct hci_dev *hdev;
3007
3008 hdev = kzalloc(sizeof(struct hci_dev), GFP_KERNEL);
3009 if (!hdev)
3010 return NULL;
3011
b1b813d4
DH
3012 hdev->pkt_type = (HCI_DM1 | HCI_DH1 | HCI_HV1);
3013 hdev->esco_type = (ESCO_HV1);
3014 hdev->link_mode = (HCI_LM_ACCEPT);
b4cb9fb2
MH
3015 hdev->num_iac = 0x01; /* One IAC support is mandatory */
3016 hdev->io_capability = 0x03; /* No Input No Output */
bbaf444a
JH
3017 hdev->inq_tx_power = HCI_TX_POWER_INVALID;
3018 hdev->adv_tx_power = HCI_TX_POWER_INVALID;
b1b813d4 3019
b1b813d4
DH
3020 hdev->sniff_max_interval = 800;
3021 hdev->sniff_min_interval = 80;
3022
bef64738
MH
3023 hdev->le_scan_interval = 0x0060;
3024 hdev->le_scan_window = 0x0030;
4e70c7e7
MH
3025 hdev->le_conn_min_interval = 0x0028;
3026 hdev->le_conn_max_interval = 0x0038;
bef64738 3027
b1b813d4
DH
3028 mutex_init(&hdev->lock);
3029 mutex_init(&hdev->req_lock);
3030
3031 INIT_LIST_HEAD(&hdev->mgmt_pending);
3032 INIT_LIST_HEAD(&hdev->blacklist);
3033 INIT_LIST_HEAD(&hdev->uuids);
3034 INIT_LIST_HEAD(&hdev->link_keys);
3035 INIT_LIST_HEAD(&hdev->long_term_keys);
3036 INIT_LIST_HEAD(&hdev->remote_oob_data);
6b536b5e 3037 INIT_LIST_HEAD(&hdev->conn_hash.list);
b1b813d4
DH
3038
3039 INIT_WORK(&hdev->rx_work, hci_rx_work);
3040 INIT_WORK(&hdev->cmd_work, hci_cmd_work);
3041 INIT_WORK(&hdev->tx_work, hci_tx_work);
3042 INIT_WORK(&hdev->power_on, hci_power_on);
b1b813d4 3043
b1b813d4
DH
3044 INIT_DELAYED_WORK(&hdev->power_off, hci_power_off);
3045 INIT_DELAYED_WORK(&hdev->discov_off, hci_discov_off);
3046 INIT_DELAYED_WORK(&hdev->le_scan_disable, le_scan_disable_work);
3047
b1b813d4
DH
3048 skb_queue_head_init(&hdev->rx_q);
3049 skb_queue_head_init(&hdev->cmd_q);
3050 skb_queue_head_init(&hdev->raw_q);
3051
3052 init_waitqueue_head(&hdev->req_wait_q);
3053
bda4f23a 3054 setup_timer(&hdev->cmd_timer, hci_cmd_timeout, (unsigned long) hdev);
b1b813d4 3055
b1b813d4
DH
3056 hci_init_sysfs(hdev);
3057 discovery_init(hdev);
9be0dab7
DH
3058
3059 return hdev;
3060}
3061EXPORT_SYMBOL(hci_alloc_dev);
3062
3063/* Free HCI device */
3064void hci_free_dev(struct hci_dev *hdev)
3065{
9be0dab7
DH
3066 /* will free via device release */
3067 put_device(&hdev->dev);
3068}
3069EXPORT_SYMBOL(hci_free_dev);
3070
1da177e4
LT
3071/* Register HCI device */
3072int hci_register_dev(struct hci_dev *hdev)
3073{
b1b813d4 3074 int id, error;
1da177e4 3075
010666a1 3076 if (!hdev->open || !hdev->close)
1da177e4
LT
3077 return -EINVAL;
3078
08add513
MM
3079 /* Do not allow HCI_AMP devices to register at index 0,
3080 * so the index can be used as the AMP controller ID.
3081 */
3df92b31
SL
3082 switch (hdev->dev_type) {
3083 case HCI_BREDR:
3084 id = ida_simple_get(&hci_index_ida, 0, 0, GFP_KERNEL);
3085 break;
3086 case HCI_AMP:
3087 id = ida_simple_get(&hci_index_ida, 1, 0, GFP_KERNEL);
3088 break;
3089 default:
3090 return -EINVAL;
1da177e4 3091 }
8e87d142 3092
3df92b31
SL
3093 if (id < 0)
3094 return id;
3095
1da177e4
LT
3096 sprintf(hdev->name, "hci%d", id);
3097 hdev->id = id;
2d8b3a11
AE
3098
3099 BT_DBG("%p name %s bus %d", hdev, hdev->name, hdev->bus);
3100
d8537548
KC
3101 hdev->workqueue = alloc_workqueue("%s", WQ_HIGHPRI | WQ_UNBOUND |
3102 WQ_MEM_RECLAIM, 1, hdev->name);
33ca954d
DH
3103 if (!hdev->workqueue) {
3104 error = -ENOMEM;
3105 goto err;
3106 }
f48fd9c8 3107
d8537548
KC
3108 hdev->req_workqueue = alloc_workqueue("%s", WQ_HIGHPRI | WQ_UNBOUND |
3109 WQ_MEM_RECLAIM, 1, hdev->name);
6ead1bbc
JH
3110 if (!hdev->req_workqueue) {
3111 destroy_workqueue(hdev->workqueue);
3112 error = -ENOMEM;
3113 goto err;
3114 }
3115
0153e2ec
MH
3116 if (!IS_ERR_OR_NULL(bt_debugfs))
3117 hdev->debugfs = debugfs_create_dir(hdev->name, bt_debugfs);
3118
bdc3e0f1
MH
3119 dev_set_name(&hdev->dev, "%s", hdev->name);
3120
3121 error = device_add(&hdev->dev);
33ca954d
DH
3122 if (error < 0)
3123 goto err_wqueue;
1da177e4 3124
611b30f7 3125 hdev->rfkill = rfkill_alloc(hdev->name, &hdev->dev,
a8c5fb1a
GP
3126 RFKILL_TYPE_BLUETOOTH, &hci_rfkill_ops,
3127 hdev);
611b30f7
MH
3128 if (hdev->rfkill) {
3129 if (rfkill_register(hdev->rfkill) < 0) {
3130 rfkill_destroy(hdev->rfkill);
3131 hdev->rfkill = NULL;
3132 }
3133 }
3134
5e130367
JH
3135 if (hdev->rfkill && rfkill_blocked(hdev->rfkill))
3136 set_bit(HCI_RFKILLED, &hdev->dev_flags);
3137
a8b2d5c2 3138 set_bit(HCI_SETUP, &hdev->dev_flags);
004b0258 3139 set_bit(HCI_AUTO_OFF, &hdev->dev_flags);
ce2be9ac 3140
01cd3404 3141 if (hdev->dev_type == HCI_BREDR) {
56f87901
JH
3142 /* Assume BR/EDR support until proven otherwise (such as
3143 * through reading supported features during init.
3144 */
3145 set_bit(HCI_BREDR_ENABLED, &hdev->dev_flags);
3146 }
ce2be9ac 3147
fcee3377
GP
3148 write_lock(&hci_dev_list_lock);
3149 list_add(&hdev->list, &hci_dev_list);
3150 write_unlock(&hci_dev_list_lock);
3151
1da177e4 3152 hci_notify(hdev, HCI_DEV_REG);
dc946bd8 3153 hci_dev_hold(hdev);
1da177e4 3154
19202573 3155 queue_work(hdev->req_workqueue, &hdev->power_on);
fbe96d6f 3156
1da177e4 3157 return id;
f48fd9c8 3158
33ca954d
DH
3159err_wqueue:
3160 destroy_workqueue(hdev->workqueue);
6ead1bbc 3161 destroy_workqueue(hdev->req_workqueue);
33ca954d 3162err:
3df92b31 3163 ida_simple_remove(&hci_index_ida, hdev->id);
f48fd9c8 3164
33ca954d 3165 return error;
1da177e4
LT
3166}
3167EXPORT_SYMBOL(hci_register_dev);
3168
3169/* Unregister HCI device */
59735631 3170void hci_unregister_dev(struct hci_dev *hdev)
1da177e4 3171{
3df92b31 3172 int i, id;
ef222013 3173
c13854ce 3174 BT_DBG("%p name %s bus %d", hdev, hdev->name, hdev->bus);
1da177e4 3175
94324962
JH
3176 set_bit(HCI_UNREGISTER, &hdev->dev_flags);
3177
3df92b31
SL
3178 id = hdev->id;
3179
f20d09d5 3180 write_lock(&hci_dev_list_lock);
1da177e4 3181 list_del(&hdev->list);
f20d09d5 3182 write_unlock(&hci_dev_list_lock);
1da177e4
LT
3183
3184 hci_dev_do_close(hdev);
3185
cd4c5391 3186 for (i = 0; i < NUM_REASSEMBLY; i++)
ef222013
MH
3187 kfree_skb(hdev->reassembly[i]);
3188
b9b5ef18
GP
3189 cancel_work_sync(&hdev->power_on);
3190
ab81cbf9 3191 if (!test_bit(HCI_INIT, &hdev->flags) &&
a8c5fb1a 3192 !test_bit(HCI_SETUP, &hdev->dev_flags)) {
09fd0de5 3193 hci_dev_lock(hdev);
744cf19e 3194 mgmt_index_removed(hdev);
09fd0de5 3195 hci_dev_unlock(hdev);
56e5cb86 3196 }
ab81cbf9 3197
2e58ef3e
JH
3198 /* mgmt_index_removed should take care of emptying the
3199 * pending list */
3200 BUG_ON(!list_empty(&hdev->mgmt_pending));
3201
1da177e4
LT
3202 hci_notify(hdev, HCI_DEV_UNREG);
3203
611b30f7
MH
3204 if (hdev->rfkill) {
3205 rfkill_unregister(hdev->rfkill);
3206 rfkill_destroy(hdev->rfkill);
3207 }
3208
bdc3e0f1 3209 device_del(&hdev->dev);
147e2d59 3210
0153e2ec
MH
3211 debugfs_remove_recursive(hdev->debugfs);
3212
f48fd9c8 3213 destroy_workqueue(hdev->workqueue);
6ead1bbc 3214 destroy_workqueue(hdev->req_workqueue);
f48fd9c8 3215
09fd0de5 3216 hci_dev_lock(hdev);
e2e0cacb 3217 hci_blacklist_clear(hdev);
2aeb9a1a 3218 hci_uuids_clear(hdev);
55ed8ca1 3219 hci_link_keys_clear(hdev);
b899efaf 3220 hci_smp_ltks_clear(hdev);
2763eda6 3221 hci_remote_oob_data_clear(hdev);
09fd0de5 3222 hci_dev_unlock(hdev);
e2e0cacb 3223
dc946bd8 3224 hci_dev_put(hdev);
3df92b31
SL
3225
3226 ida_simple_remove(&hci_index_ida, id);
1da177e4
LT
3227}
3228EXPORT_SYMBOL(hci_unregister_dev);
3229
3230/* Suspend HCI device */
3231int hci_suspend_dev(struct hci_dev *hdev)
3232{
3233 hci_notify(hdev, HCI_DEV_SUSPEND);
3234 return 0;
3235}
3236EXPORT_SYMBOL(hci_suspend_dev);
3237
3238/* Resume HCI device */
3239int hci_resume_dev(struct hci_dev *hdev)
3240{
3241 hci_notify(hdev, HCI_DEV_RESUME);
3242 return 0;
3243}
3244EXPORT_SYMBOL(hci_resume_dev);
3245
76bca880 3246/* Receive frame from HCI drivers */
e1a26170 3247int hci_recv_frame(struct hci_dev *hdev, struct sk_buff *skb)
76bca880 3248{
76bca880 3249 if (!hdev || (!test_bit(HCI_UP, &hdev->flags)
a8c5fb1a 3250 && !test_bit(HCI_INIT, &hdev->flags))) {
76bca880
MH
3251 kfree_skb(skb);
3252 return -ENXIO;
3253 }
3254
d82603c6 3255 /* Incoming skb */
76bca880
MH
3256 bt_cb(skb)->incoming = 1;
3257
3258 /* Time stamp */
3259 __net_timestamp(skb);
3260
76bca880 3261 skb_queue_tail(&hdev->rx_q, skb);
b78752cc 3262 queue_work(hdev->workqueue, &hdev->rx_work);
c78ae283 3263
76bca880
MH
3264 return 0;
3265}
3266EXPORT_SYMBOL(hci_recv_frame);
3267
33e882a5 3268static int hci_reassembly(struct hci_dev *hdev, int type, void *data,
a8c5fb1a 3269 int count, __u8 index)
33e882a5
SS
3270{
3271 int len = 0;
3272 int hlen = 0;
3273 int remain = count;
3274 struct sk_buff *skb;
3275 struct bt_skb_cb *scb;
3276
3277 if ((type < HCI_ACLDATA_PKT || type > HCI_EVENT_PKT) ||
a8c5fb1a 3278 index >= NUM_REASSEMBLY)
33e882a5
SS
3279 return -EILSEQ;
3280
3281 skb = hdev->reassembly[index];
3282
3283 if (!skb) {
3284 switch (type) {
3285 case HCI_ACLDATA_PKT:
3286 len = HCI_MAX_FRAME_SIZE;
3287 hlen = HCI_ACL_HDR_SIZE;
3288 break;
3289 case HCI_EVENT_PKT:
3290 len = HCI_MAX_EVENT_SIZE;
3291 hlen = HCI_EVENT_HDR_SIZE;
3292 break;
3293 case HCI_SCODATA_PKT:
3294 len = HCI_MAX_SCO_SIZE;
3295 hlen = HCI_SCO_HDR_SIZE;
3296 break;
3297 }
3298
1e429f38 3299 skb = bt_skb_alloc(len, GFP_ATOMIC);
33e882a5
SS
3300 if (!skb)
3301 return -ENOMEM;
3302
3303 scb = (void *) skb->cb;
3304 scb->expect = hlen;
3305 scb->pkt_type = type;
3306
33e882a5
SS
3307 hdev->reassembly[index] = skb;
3308 }
3309
3310 while (count) {
3311 scb = (void *) skb->cb;
89bb46d0 3312 len = min_t(uint, scb->expect, count);
33e882a5
SS
3313
3314 memcpy(skb_put(skb, len), data, len);
3315
3316 count -= len;
3317 data += len;
3318 scb->expect -= len;
3319 remain = count;
3320
3321 switch (type) {
3322 case HCI_EVENT_PKT:
3323 if (skb->len == HCI_EVENT_HDR_SIZE) {
3324 struct hci_event_hdr *h = hci_event_hdr(skb);
3325 scb->expect = h->plen;
3326
3327 if (skb_tailroom(skb) < scb->expect) {
3328 kfree_skb(skb);
3329 hdev->reassembly[index] = NULL;
3330 return -ENOMEM;
3331 }
3332 }
3333 break;
3334
3335 case HCI_ACLDATA_PKT:
3336 if (skb->len == HCI_ACL_HDR_SIZE) {
3337 struct hci_acl_hdr *h = hci_acl_hdr(skb);
3338 scb->expect = __le16_to_cpu(h->dlen);
3339
3340 if (skb_tailroom(skb) < scb->expect) {
3341 kfree_skb(skb);
3342 hdev->reassembly[index] = NULL;
3343 return -ENOMEM;
3344 }
3345 }
3346 break;
3347
3348 case HCI_SCODATA_PKT:
3349 if (skb->len == HCI_SCO_HDR_SIZE) {
3350 struct hci_sco_hdr *h = hci_sco_hdr(skb);
3351 scb->expect = h->dlen;
3352
3353 if (skb_tailroom(skb) < scb->expect) {
3354 kfree_skb(skb);
3355 hdev->reassembly[index] = NULL;
3356 return -ENOMEM;
3357 }
3358 }
3359 break;
3360 }
3361
3362 if (scb->expect == 0) {
3363 /* Complete frame */
3364
3365 bt_cb(skb)->pkt_type = type;
e1a26170 3366 hci_recv_frame(hdev, skb);
33e882a5
SS
3367
3368 hdev->reassembly[index] = NULL;
3369 return remain;
3370 }
3371 }
3372
3373 return remain;
3374}
3375
ef222013
MH
3376int hci_recv_fragment(struct hci_dev *hdev, int type, void *data, int count)
3377{
f39a3c06
SS
3378 int rem = 0;
3379
ef222013
MH
3380 if (type < HCI_ACLDATA_PKT || type > HCI_EVENT_PKT)
3381 return -EILSEQ;
3382
da5f6c37 3383 while (count) {
1e429f38 3384 rem = hci_reassembly(hdev, type, data, count, type - 1);
f39a3c06
SS
3385 if (rem < 0)
3386 return rem;
ef222013 3387
f39a3c06
SS
3388 data += (count - rem);
3389 count = rem;
f81c6224 3390 }
ef222013 3391
f39a3c06 3392 return rem;
ef222013
MH
3393}
3394EXPORT_SYMBOL(hci_recv_fragment);
3395
99811510
SS
3396#define STREAM_REASSEMBLY 0
3397
3398int hci_recv_stream_fragment(struct hci_dev *hdev, void *data, int count)
3399{
3400 int type;
3401 int rem = 0;
3402
da5f6c37 3403 while (count) {
99811510
SS
3404 struct sk_buff *skb = hdev->reassembly[STREAM_REASSEMBLY];
3405
3406 if (!skb) {
3407 struct { char type; } *pkt;
3408
3409 /* Start of the frame */
3410 pkt = data;
3411 type = pkt->type;
3412
3413 data++;
3414 count--;
3415 } else
3416 type = bt_cb(skb)->pkt_type;
3417
1e429f38 3418 rem = hci_reassembly(hdev, type, data, count,
a8c5fb1a 3419 STREAM_REASSEMBLY);
99811510
SS
3420 if (rem < 0)
3421 return rem;
3422
3423 data += (count - rem);
3424 count = rem;
f81c6224 3425 }
99811510
SS
3426
3427 return rem;
3428}
3429EXPORT_SYMBOL(hci_recv_stream_fragment);
3430
1da177e4
LT
3431/* ---- Interface to upper protocols ---- */
3432
1da177e4
LT
3433int hci_register_cb(struct hci_cb *cb)
3434{
3435 BT_DBG("%p name %s", cb, cb->name);
3436
f20d09d5 3437 write_lock(&hci_cb_list_lock);
1da177e4 3438 list_add(&cb->list, &hci_cb_list);
f20d09d5 3439 write_unlock(&hci_cb_list_lock);
1da177e4
LT
3440
3441 return 0;
3442}
3443EXPORT_SYMBOL(hci_register_cb);
3444
3445int hci_unregister_cb(struct hci_cb *cb)
3446{
3447 BT_DBG("%p name %s", cb, cb->name);
3448
f20d09d5 3449 write_lock(&hci_cb_list_lock);
1da177e4 3450 list_del(&cb->list);
f20d09d5 3451 write_unlock(&hci_cb_list_lock);
1da177e4
LT
3452
3453 return 0;
3454}
3455EXPORT_SYMBOL(hci_unregister_cb);
3456
51086991 3457static void hci_send_frame(struct hci_dev *hdev, struct sk_buff *skb)
1da177e4 3458{
0d48d939 3459 BT_DBG("%s type %d len %d", hdev->name, bt_cb(skb)->pkt_type, skb->len);
1da177e4 3460
cd82e61c
MH
3461 /* Time stamp */
3462 __net_timestamp(skb);
1da177e4 3463
cd82e61c
MH
3464 /* Send copy to monitor */
3465 hci_send_to_monitor(hdev, skb);
3466
3467 if (atomic_read(&hdev->promisc)) {
3468 /* Send copy to the sockets */
470fe1b5 3469 hci_send_to_sock(hdev, skb);
1da177e4
LT
3470 }
3471
3472 /* Get rid of skb owner, prior to sending to the driver. */
3473 skb_orphan(skb);
3474
7bd8f09f 3475 if (hdev->send(hdev, skb) < 0)
51086991 3476 BT_ERR("%s sending frame failed", hdev->name);
1da177e4
LT
3477}
3478
3119ae95
JH
3479void hci_req_init(struct hci_request *req, struct hci_dev *hdev)
3480{
3481 skb_queue_head_init(&req->cmd_q);
3482 req->hdev = hdev;
5d73e034 3483 req->err = 0;
3119ae95
JH
3484}
3485
3486int hci_req_run(struct hci_request *req, hci_req_complete_t complete)
3487{
3488 struct hci_dev *hdev = req->hdev;
3489 struct sk_buff *skb;
3490 unsigned long flags;
3491
3492 BT_DBG("length %u", skb_queue_len(&req->cmd_q));
3493
5d73e034
AG
3494 /* If an error occured during request building, remove all HCI
3495 * commands queued on the HCI request queue.
3496 */
3497 if (req->err) {
3498 skb_queue_purge(&req->cmd_q);
3499 return req->err;
3500 }
3501
3119ae95
JH
3502 /* Do not allow empty requests */
3503 if (skb_queue_empty(&req->cmd_q))
382b0c39 3504 return -ENODATA;
3119ae95
JH
3505
3506 skb = skb_peek_tail(&req->cmd_q);
3507 bt_cb(skb)->req.complete = complete;
3508
3509 spin_lock_irqsave(&hdev->cmd_q.lock, flags);
3510 skb_queue_splice_tail(&req->cmd_q, &hdev->cmd_q);
3511 spin_unlock_irqrestore(&hdev->cmd_q.lock, flags);
3512
3513 queue_work(hdev->workqueue, &hdev->cmd_work);
3514
3515 return 0;
3516}
3517
1ca3a9d0 3518static struct sk_buff *hci_prepare_cmd(struct hci_dev *hdev, u16 opcode,
07dc93dd 3519 u32 plen, const void *param)
1da177e4
LT
3520{
3521 int len = HCI_COMMAND_HDR_SIZE + plen;
3522 struct hci_command_hdr *hdr;
3523 struct sk_buff *skb;
3524
1da177e4 3525 skb = bt_skb_alloc(len, GFP_ATOMIC);
1ca3a9d0
JH
3526 if (!skb)
3527 return NULL;
1da177e4
LT
3528
3529 hdr = (struct hci_command_hdr *) skb_put(skb, HCI_COMMAND_HDR_SIZE);
a9de9248 3530 hdr->opcode = cpu_to_le16(opcode);
1da177e4
LT
3531 hdr->plen = plen;
3532
3533 if (plen)
3534 memcpy(skb_put(skb, plen), param, plen);
3535
3536 BT_DBG("skb len %d", skb->len);
3537
0d48d939 3538 bt_cb(skb)->pkt_type = HCI_COMMAND_PKT;
c78ae283 3539
1ca3a9d0
JH
3540 return skb;
3541}
3542
3543/* Send HCI command */
07dc93dd
JH
3544int hci_send_cmd(struct hci_dev *hdev, __u16 opcode, __u32 plen,
3545 const void *param)
1ca3a9d0
JH
3546{
3547 struct sk_buff *skb;
3548
3549 BT_DBG("%s opcode 0x%4.4x plen %d", hdev->name, opcode, plen);
3550
3551 skb = hci_prepare_cmd(hdev, opcode, plen, param);
3552 if (!skb) {
3553 BT_ERR("%s no memory for command", hdev->name);
3554 return -ENOMEM;
3555 }
3556
11714b3d
JH
3557 /* Stand-alone HCI commands must be flaged as
3558 * single-command requests.
3559 */
3560 bt_cb(skb)->req.start = true;
3561
1da177e4 3562 skb_queue_tail(&hdev->cmd_q, skb);
c347b765 3563 queue_work(hdev->workqueue, &hdev->cmd_work);
1da177e4
LT
3564
3565 return 0;
3566}
1da177e4 3567
71c76a17 3568/* Queue a command to an asynchronous HCI request */
07dc93dd
JH
3569void hci_req_add_ev(struct hci_request *req, u16 opcode, u32 plen,
3570 const void *param, u8 event)
71c76a17
JH
3571{
3572 struct hci_dev *hdev = req->hdev;
3573 struct sk_buff *skb;
3574
3575 BT_DBG("%s opcode 0x%4.4x plen %d", hdev->name, opcode, plen);
3576
34739c1e
AG
3577 /* If an error occured during request building, there is no point in
3578 * queueing the HCI command. We can simply return.
3579 */
3580 if (req->err)
3581 return;
3582
71c76a17
JH
3583 skb = hci_prepare_cmd(hdev, opcode, plen, param);
3584 if (!skb) {
5d73e034
AG
3585 BT_ERR("%s no memory for command (opcode 0x%4.4x)",
3586 hdev->name, opcode);
3587 req->err = -ENOMEM;
e348fe6b 3588 return;
71c76a17
JH
3589 }
3590
3591 if (skb_queue_empty(&req->cmd_q))
3592 bt_cb(skb)->req.start = true;
3593
02350a72
JH
3594 bt_cb(skb)->req.event = event;
3595
71c76a17 3596 skb_queue_tail(&req->cmd_q, skb);
71c76a17
JH
3597}
3598
07dc93dd
JH
3599void hci_req_add(struct hci_request *req, u16 opcode, u32 plen,
3600 const void *param)
02350a72
JH
3601{
3602 hci_req_add_ev(req, opcode, plen, param, 0);
3603}
3604
1da177e4 3605/* Get data from the previously sent command */
a9de9248 3606void *hci_sent_cmd_data(struct hci_dev *hdev, __u16 opcode)
1da177e4
LT
3607{
3608 struct hci_command_hdr *hdr;
3609
3610 if (!hdev->sent_cmd)
3611 return NULL;
3612
3613 hdr = (void *) hdev->sent_cmd->data;
3614
a9de9248 3615 if (hdr->opcode != cpu_to_le16(opcode))
1da177e4
LT
3616 return NULL;
3617
f0e09510 3618 BT_DBG("%s opcode 0x%4.4x", hdev->name, opcode);
1da177e4
LT
3619
3620 return hdev->sent_cmd->data + HCI_COMMAND_HDR_SIZE;
3621}
3622
3623/* Send ACL data */
3624static void hci_add_acl_hdr(struct sk_buff *skb, __u16 handle, __u16 flags)
3625{
3626 struct hci_acl_hdr *hdr;
3627 int len = skb->len;
3628
badff6d0
ACM
3629 skb_push(skb, HCI_ACL_HDR_SIZE);
3630 skb_reset_transport_header(skb);
9c70220b 3631 hdr = (struct hci_acl_hdr *)skb_transport_header(skb);
aca3192c
YH
3632 hdr->handle = cpu_to_le16(hci_handle_pack(handle, flags));
3633 hdr->dlen = cpu_to_le16(len);
1da177e4
LT
3634}
3635
ee22be7e 3636static void hci_queue_acl(struct hci_chan *chan, struct sk_buff_head *queue,
a8c5fb1a 3637 struct sk_buff *skb, __u16 flags)
1da177e4 3638{
ee22be7e 3639 struct hci_conn *conn = chan->conn;
1da177e4
LT
3640 struct hci_dev *hdev = conn->hdev;
3641 struct sk_buff *list;
3642
087bfd99
GP
3643 skb->len = skb_headlen(skb);
3644 skb->data_len = 0;
3645
3646 bt_cb(skb)->pkt_type = HCI_ACLDATA_PKT;
204a6e54
AE
3647
3648 switch (hdev->dev_type) {
3649 case HCI_BREDR:
3650 hci_add_acl_hdr(skb, conn->handle, flags);
3651 break;
3652 case HCI_AMP:
3653 hci_add_acl_hdr(skb, chan->handle, flags);
3654 break;
3655 default:
3656 BT_ERR("%s unknown dev_type %d", hdev->name, hdev->dev_type);
3657 return;
3658 }
087bfd99 3659
70f23020
AE
3660 list = skb_shinfo(skb)->frag_list;
3661 if (!list) {
1da177e4
LT
3662 /* Non fragmented */
3663 BT_DBG("%s nonfrag skb %p len %d", hdev->name, skb, skb->len);
3664
73d80deb 3665 skb_queue_tail(queue, skb);
1da177e4
LT
3666 } else {
3667 /* Fragmented */
3668 BT_DBG("%s frag %p len %d", hdev->name, skb, skb->len);
3669
3670 skb_shinfo(skb)->frag_list = NULL;
3671
3672 /* Queue all fragments atomically */
af3e6359 3673 spin_lock(&queue->lock);
1da177e4 3674
73d80deb 3675 __skb_queue_tail(queue, skb);
e702112f
AE
3676
3677 flags &= ~ACL_START;
3678 flags |= ACL_CONT;
1da177e4
LT
3679 do {
3680 skb = list; list = list->next;
8e87d142 3681
0d48d939 3682 bt_cb(skb)->pkt_type = HCI_ACLDATA_PKT;
e702112f 3683 hci_add_acl_hdr(skb, conn->handle, flags);
1da177e4
LT
3684
3685 BT_DBG("%s frag %p len %d", hdev->name, skb, skb->len);
3686
73d80deb 3687 __skb_queue_tail(queue, skb);
1da177e4
LT
3688 } while (list);
3689
af3e6359 3690 spin_unlock(&queue->lock);
1da177e4 3691 }
73d80deb
LAD
3692}
3693
3694void hci_send_acl(struct hci_chan *chan, struct sk_buff *skb, __u16 flags)
3695{
ee22be7e 3696 struct hci_dev *hdev = chan->conn->hdev;
73d80deb 3697
f0e09510 3698 BT_DBG("%s chan %p flags 0x%4.4x", hdev->name, chan, flags);
73d80deb 3699
ee22be7e 3700 hci_queue_acl(chan, &chan->data_q, skb, flags);
1da177e4 3701
3eff45ea 3702 queue_work(hdev->workqueue, &hdev->tx_work);
1da177e4 3703}
1da177e4
LT
3704
3705/* Send SCO data */
0d861d8b 3706void hci_send_sco(struct hci_conn *conn, struct sk_buff *skb)
1da177e4
LT
3707{
3708 struct hci_dev *hdev = conn->hdev;
3709 struct hci_sco_hdr hdr;
3710
3711 BT_DBG("%s len %d", hdev->name, skb->len);
3712
aca3192c 3713 hdr.handle = cpu_to_le16(conn->handle);
1da177e4
LT
3714 hdr.dlen = skb->len;
3715
badff6d0
ACM
3716 skb_push(skb, HCI_SCO_HDR_SIZE);
3717 skb_reset_transport_header(skb);
9c70220b 3718 memcpy(skb_transport_header(skb), &hdr, HCI_SCO_HDR_SIZE);
1da177e4 3719
0d48d939 3720 bt_cb(skb)->pkt_type = HCI_SCODATA_PKT;
c78ae283 3721
1da177e4 3722 skb_queue_tail(&conn->data_q, skb);
3eff45ea 3723 queue_work(hdev->workqueue, &hdev->tx_work);
1da177e4 3724}
1da177e4
LT
3725
3726/* ---- HCI TX task (outgoing data) ---- */
3727
3728/* HCI Connection scheduler */
6039aa73
GP
3729static struct hci_conn *hci_low_sent(struct hci_dev *hdev, __u8 type,
3730 int *quote)
1da177e4
LT
3731{
3732 struct hci_conn_hash *h = &hdev->conn_hash;
8035ded4 3733 struct hci_conn *conn = NULL, *c;
abc5de8f 3734 unsigned int num = 0, min = ~0;
1da177e4 3735
8e87d142 3736 /* We don't have to lock device here. Connections are always
1da177e4 3737 * added and removed with TX task disabled. */
bf4c6325
GP
3738
3739 rcu_read_lock();
3740
3741 list_for_each_entry_rcu(c, &h->list, list) {
769be974 3742 if (c->type != type || skb_queue_empty(&c->data_q))
1da177e4 3743 continue;
769be974
MH
3744
3745 if (c->state != BT_CONNECTED && c->state != BT_CONFIG)
3746 continue;
3747
1da177e4
LT
3748 num++;
3749
3750 if (c->sent < min) {
3751 min = c->sent;
3752 conn = c;
3753 }
52087a79
LAD
3754
3755 if (hci_conn_num(hdev, type) == num)
3756 break;
1da177e4
LT
3757 }
3758
bf4c6325
GP
3759 rcu_read_unlock();
3760
1da177e4 3761 if (conn) {
6ed58ec5
VT
3762 int cnt, q;
3763
3764 switch (conn->type) {
3765 case ACL_LINK:
3766 cnt = hdev->acl_cnt;
3767 break;
3768 case SCO_LINK:
3769 case ESCO_LINK:
3770 cnt = hdev->sco_cnt;
3771 break;
3772 case LE_LINK:
3773 cnt = hdev->le_mtu ? hdev->le_cnt : hdev->acl_cnt;
3774 break;
3775 default:
3776 cnt = 0;
3777 BT_ERR("Unknown link type");
3778 }
3779
3780 q = cnt / num;
1da177e4
LT
3781 *quote = q ? q : 1;
3782 } else
3783 *quote = 0;
3784
3785 BT_DBG("conn %p quote %d", conn, *quote);
3786 return conn;
3787}
3788
6039aa73 3789static void hci_link_tx_to(struct hci_dev *hdev, __u8 type)
1da177e4
LT
3790{
3791 struct hci_conn_hash *h = &hdev->conn_hash;
8035ded4 3792 struct hci_conn *c;
1da177e4 3793
bae1f5d9 3794 BT_ERR("%s link tx timeout", hdev->name);
1da177e4 3795
bf4c6325
GP
3796 rcu_read_lock();
3797
1da177e4 3798 /* Kill stalled connections */
bf4c6325 3799 list_for_each_entry_rcu(c, &h->list, list) {
bae1f5d9 3800 if (c->type == type && c->sent) {
6ed93dc6
AE
3801 BT_ERR("%s killing stalled connection %pMR",
3802 hdev->name, &c->dst);
bed71748 3803 hci_disconnect(c, HCI_ERROR_REMOTE_USER_TERM);
1da177e4
LT
3804 }
3805 }
bf4c6325
GP
3806
3807 rcu_read_unlock();
1da177e4
LT
3808}
3809
6039aa73
GP
3810static struct hci_chan *hci_chan_sent(struct hci_dev *hdev, __u8 type,
3811 int *quote)
1da177e4 3812{
73d80deb
LAD
3813 struct hci_conn_hash *h = &hdev->conn_hash;
3814 struct hci_chan *chan = NULL;
abc5de8f 3815 unsigned int num = 0, min = ~0, cur_prio = 0;
1da177e4 3816 struct hci_conn *conn;
73d80deb
LAD
3817 int cnt, q, conn_num = 0;
3818
3819 BT_DBG("%s", hdev->name);
3820
bf4c6325
GP
3821 rcu_read_lock();
3822
3823 list_for_each_entry_rcu(conn, &h->list, list) {
73d80deb
LAD
3824 struct hci_chan *tmp;
3825
3826 if (conn->type != type)
3827 continue;
3828
3829 if (conn->state != BT_CONNECTED && conn->state != BT_CONFIG)
3830 continue;
3831
3832 conn_num++;
3833
8192edef 3834 list_for_each_entry_rcu(tmp, &conn->chan_list, list) {
73d80deb
LAD
3835 struct sk_buff *skb;
3836
3837 if (skb_queue_empty(&tmp->data_q))
3838 continue;
3839
3840 skb = skb_peek(&tmp->data_q);
3841 if (skb->priority < cur_prio)
3842 continue;
3843
3844 if (skb->priority > cur_prio) {
3845 num = 0;
3846 min = ~0;
3847 cur_prio = skb->priority;
3848 }
3849
3850 num++;
3851
3852 if (conn->sent < min) {
3853 min = conn->sent;
3854 chan = tmp;
3855 }
3856 }
3857
3858 if (hci_conn_num(hdev, type) == conn_num)
3859 break;
3860 }
3861
bf4c6325
GP
3862 rcu_read_unlock();
3863
73d80deb
LAD
3864 if (!chan)
3865 return NULL;
3866
3867 switch (chan->conn->type) {
3868 case ACL_LINK:
3869 cnt = hdev->acl_cnt;
3870 break;
bd1eb66b
AE
3871 case AMP_LINK:
3872 cnt = hdev->block_cnt;
3873 break;
73d80deb
LAD
3874 case SCO_LINK:
3875 case ESCO_LINK:
3876 cnt = hdev->sco_cnt;
3877 break;
3878 case LE_LINK:
3879 cnt = hdev->le_mtu ? hdev->le_cnt : hdev->acl_cnt;
3880 break;
3881 default:
3882 cnt = 0;
3883 BT_ERR("Unknown link type");
3884 }
3885
3886 q = cnt / num;
3887 *quote = q ? q : 1;
3888 BT_DBG("chan %p quote %d", chan, *quote);
3889 return chan;
3890}
3891
02b20f0b
LAD
3892static void hci_prio_recalculate(struct hci_dev *hdev, __u8 type)
3893{
3894 struct hci_conn_hash *h = &hdev->conn_hash;
3895 struct hci_conn *conn;
3896 int num = 0;
3897
3898 BT_DBG("%s", hdev->name);
3899
bf4c6325
GP
3900 rcu_read_lock();
3901
3902 list_for_each_entry_rcu(conn, &h->list, list) {
02b20f0b
LAD
3903 struct hci_chan *chan;
3904
3905 if (conn->type != type)
3906 continue;
3907
3908 if (conn->state != BT_CONNECTED && conn->state != BT_CONFIG)
3909 continue;
3910
3911 num++;
3912
8192edef 3913 list_for_each_entry_rcu(chan, &conn->chan_list, list) {
02b20f0b
LAD
3914 struct sk_buff *skb;
3915
3916 if (chan->sent) {
3917 chan->sent = 0;
3918 continue;
3919 }
3920
3921 if (skb_queue_empty(&chan->data_q))
3922 continue;
3923
3924 skb = skb_peek(&chan->data_q);
3925 if (skb->priority >= HCI_PRIO_MAX - 1)
3926 continue;
3927
3928 skb->priority = HCI_PRIO_MAX - 1;
3929
3930 BT_DBG("chan %p skb %p promoted to %d", chan, skb,
a8c5fb1a 3931 skb->priority);
02b20f0b
LAD
3932 }
3933
3934 if (hci_conn_num(hdev, type) == num)
3935 break;
3936 }
bf4c6325
GP
3937
3938 rcu_read_unlock();
3939
02b20f0b
LAD
3940}
3941
b71d385a
AE
3942static inline int __get_blocks(struct hci_dev *hdev, struct sk_buff *skb)
3943{
3944 /* Calculate count of blocks used by this packet */
3945 return DIV_ROUND_UP(skb->len - HCI_ACL_HDR_SIZE, hdev->block_len);
3946}
3947
6039aa73 3948static void __check_timeout(struct hci_dev *hdev, unsigned int cnt)
73d80deb 3949{
1da177e4
LT
3950 if (!test_bit(HCI_RAW, &hdev->flags)) {
3951 /* ACL tx timeout must be longer than maximum
3952 * link supervision timeout (40.9 seconds) */
63d2bc1b 3953 if (!cnt && time_after(jiffies, hdev->acl_last_tx +
5f246e89 3954 HCI_ACL_TX_TIMEOUT))
bae1f5d9 3955 hci_link_tx_to(hdev, ACL_LINK);
1da177e4 3956 }
63d2bc1b 3957}
1da177e4 3958
6039aa73 3959static void hci_sched_acl_pkt(struct hci_dev *hdev)
63d2bc1b
AE
3960{
3961 unsigned int cnt = hdev->acl_cnt;
3962 struct hci_chan *chan;
3963 struct sk_buff *skb;
3964 int quote;
3965
3966 __check_timeout(hdev, cnt);
04837f64 3967
73d80deb 3968 while (hdev->acl_cnt &&
a8c5fb1a 3969 (chan = hci_chan_sent(hdev, ACL_LINK, &quote))) {
ec1cce24
LAD
3970 u32 priority = (skb_peek(&chan->data_q))->priority;
3971 while (quote-- && (skb = skb_peek(&chan->data_q))) {
73d80deb 3972 BT_DBG("chan %p skb %p len %d priority %u", chan, skb,
a8c5fb1a 3973 skb->len, skb->priority);
73d80deb 3974
ec1cce24
LAD
3975 /* Stop if priority has changed */
3976 if (skb->priority < priority)
3977 break;
3978
3979 skb = skb_dequeue(&chan->data_q);
3980
73d80deb 3981 hci_conn_enter_active_mode(chan->conn,
04124681 3982 bt_cb(skb)->force_active);
04837f64 3983
57d17d70 3984 hci_send_frame(hdev, skb);
1da177e4
LT
3985 hdev->acl_last_tx = jiffies;
3986
3987 hdev->acl_cnt--;
73d80deb
LAD
3988 chan->sent++;
3989 chan->conn->sent++;
1da177e4
LT
3990 }
3991 }
02b20f0b
LAD
3992
3993 if (cnt != hdev->acl_cnt)
3994 hci_prio_recalculate(hdev, ACL_LINK);
1da177e4
LT
3995}
3996
6039aa73 3997static void hci_sched_acl_blk(struct hci_dev *hdev)
b71d385a 3998{
63d2bc1b 3999 unsigned int cnt = hdev->block_cnt;
b71d385a
AE
4000 struct hci_chan *chan;
4001 struct sk_buff *skb;
4002 int quote;
bd1eb66b 4003 u8 type;
b71d385a 4004
63d2bc1b 4005 __check_timeout(hdev, cnt);
b71d385a 4006
bd1eb66b
AE
4007 BT_DBG("%s", hdev->name);
4008
4009 if (hdev->dev_type == HCI_AMP)
4010 type = AMP_LINK;
4011 else
4012 type = ACL_LINK;
4013
b71d385a 4014 while (hdev->block_cnt > 0 &&
bd1eb66b 4015 (chan = hci_chan_sent(hdev, type, &quote))) {
b71d385a
AE
4016 u32 priority = (skb_peek(&chan->data_q))->priority;
4017 while (quote > 0 && (skb = skb_peek(&chan->data_q))) {
4018 int blocks;
4019
4020 BT_DBG("chan %p skb %p len %d priority %u", chan, skb,
a8c5fb1a 4021 skb->len, skb->priority);
b71d385a
AE
4022
4023 /* Stop if priority has changed */
4024 if (skb->priority < priority)
4025 break;
4026
4027 skb = skb_dequeue(&chan->data_q);
4028
4029 blocks = __get_blocks(hdev, skb);
4030 if (blocks > hdev->block_cnt)
4031 return;
4032
4033 hci_conn_enter_active_mode(chan->conn,
a8c5fb1a 4034 bt_cb(skb)->force_active);
b71d385a 4035
57d17d70 4036 hci_send_frame(hdev, skb);
b71d385a
AE
4037 hdev->acl_last_tx = jiffies;
4038
4039 hdev->block_cnt -= blocks;
4040 quote -= blocks;
4041
4042 chan->sent += blocks;
4043 chan->conn->sent += blocks;
4044 }
4045 }
4046
4047 if (cnt != hdev->block_cnt)
bd1eb66b 4048 hci_prio_recalculate(hdev, type);
b71d385a
AE
4049}
4050
6039aa73 4051static void hci_sched_acl(struct hci_dev *hdev)
b71d385a
AE
4052{
4053 BT_DBG("%s", hdev->name);
4054
bd1eb66b
AE
4055 /* No ACL link over BR/EDR controller */
4056 if (!hci_conn_num(hdev, ACL_LINK) && hdev->dev_type == HCI_BREDR)
4057 return;
4058
4059 /* No AMP link over AMP controller */
4060 if (!hci_conn_num(hdev, AMP_LINK) && hdev->dev_type == HCI_AMP)
b71d385a
AE
4061 return;
4062
4063 switch (hdev->flow_ctl_mode) {
4064 case HCI_FLOW_CTL_MODE_PACKET_BASED:
4065 hci_sched_acl_pkt(hdev);
4066 break;
4067
4068 case HCI_FLOW_CTL_MODE_BLOCK_BASED:
4069 hci_sched_acl_blk(hdev);
4070 break;
4071 }
4072}
4073
1da177e4 4074/* Schedule SCO */
6039aa73 4075static void hci_sched_sco(struct hci_dev *hdev)
1da177e4
LT
4076{
4077 struct hci_conn *conn;
4078 struct sk_buff *skb;
4079 int quote;
4080
4081 BT_DBG("%s", hdev->name);
4082
52087a79
LAD
4083 if (!hci_conn_num(hdev, SCO_LINK))
4084 return;
4085
1da177e4
LT
4086 while (hdev->sco_cnt && (conn = hci_low_sent(hdev, SCO_LINK, &quote))) {
4087 while (quote-- && (skb = skb_dequeue(&conn->data_q))) {
4088 BT_DBG("skb %p len %d", skb, skb->len);
57d17d70 4089 hci_send_frame(hdev, skb);
1da177e4
LT
4090
4091 conn->sent++;
4092 if (conn->sent == ~0)
4093 conn->sent = 0;
4094 }
4095 }
4096}
4097
6039aa73 4098static void hci_sched_esco(struct hci_dev *hdev)
b6a0dc82
MH
4099{
4100 struct hci_conn *conn;
4101 struct sk_buff *skb;
4102 int quote;
4103
4104 BT_DBG("%s", hdev->name);
4105
52087a79
LAD
4106 if (!hci_conn_num(hdev, ESCO_LINK))
4107 return;
4108
8fc9ced3
GP
4109 while (hdev->sco_cnt && (conn = hci_low_sent(hdev, ESCO_LINK,
4110 &quote))) {
b6a0dc82
MH
4111 while (quote-- && (skb = skb_dequeue(&conn->data_q))) {
4112 BT_DBG("skb %p len %d", skb, skb->len);
57d17d70 4113 hci_send_frame(hdev, skb);
b6a0dc82
MH
4114
4115 conn->sent++;
4116 if (conn->sent == ~0)
4117 conn->sent = 0;
4118 }
4119 }
4120}
4121
6039aa73 4122static void hci_sched_le(struct hci_dev *hdev)
6ed58ec5 4123{
73d80deb 4124 struct hci_chan *chan;
6ed58ec5 4125 struct sk_buff *skb;
02b20f0b 4126 int quote, cnt, tmp;
6ed58ec5
VT
4127
4128 BT_DBG("%s", hdev->name);
4129
52087a79
LAD
4130 if (!hci_conn_num(hdev, LE_LINK))
4131 return;
4132
6ed58ec5
VT
4133 if (!test_bit(HCI_RAW, &hdev->flags)) {
4134 /* LE tx timeout must be longer than maximum
4135 * link supervision timeout (40.9 seconds) */
bae1f5d9 4136 if (!hdev->le_cnt && hdev->le_pkts &&
a8c5fb1a 4137 time_after(jiffies, hdev->le_last_tx + HZ * 45))
bae1f5d9 4138 hci_link_tx_to(hdev, LE_LINK);
6ed58ec5
VT
4139 }
4140
4141 cnt = hdev->le_pkts ? hdev->le_cnt : hdev->acl_cnt;
02b20f0b 4142 tmp = cnt;
73d80deb 4143 while (cnt && (chan = hci_chan_sent(hdev, LE_LINK, &quote))) {
ec1cce24
LAD
4144 u32 priority = (skb_peek(&chan->data_q))->priority;
4145 while (quote-- && (skb = skb_peek(&chan->data_q))) {
73d80deb 4146 BT_DBG("chan %p skb %p len %d priority %u", chan, skb,
a8c5fb1a 4147 skb->len, skb->priority);
6ed58ec5 4148
ec1cce24
LAD
4149 /* Stop if priority has changed */
4150 if (skb->priority < priority)
4151 break;
4152
4153 skb = skb_dequeue(&chan->data_q);
4154
57d17d70 4155 hci_send_frame(hdev, skb);
6ed58ec5
VT
4156 hdev->le_last_tx = jiffies;
4157
4158 cnt--;
73d80deb
LAD
4159 chan->sent++;
4160 chan->conn->sent++;
6ed58ec5
VT
4161 }
4162 }
73d80deb 4163
6ed58ec5
VT
4164 if (hdev->le_pkts)
4165 hdev->le_cnt = cnt;
4166 else
4167 hdev->acl_cnt = cnt;
02b20f0b
LAD
4168
4169 if (cnt != tmp)
4170 hci_prio_recalculate(hdev, LE_LINK);
6ed58ec5
VT
4171}
4172
3eff45ea 4173static void hci_tx_work(struct work_struct *work)
1da177e4 4174{
3eff45ea 4175 struct hci_dev *hdev = container_of(work, struct hci_dev, tx_work);
1da177e4
LT
4176 struct sk_buff *skb;
4177
6ed58ec5 4178 BT_DBG("%s acl %d sco %d le %d", hdev->name, hdev->acl_cnt,
a8c5fb1a 4179 hdev->sco_cnt, hdev->le_cnt);
1da177e4 4180
52de599e
MH
4181 if (!test_bit(HCI_USER_CHANNEL, &hdev->dev_flags)) {
4182 /* Schedule queues and send stuff to HCI driver */
4183 hci_sched_acl(hdev);
4184 hci_sched_sco(hdev);
4185 hci_sched_esco(hdev);
4186 hci_sched_le(hdev);
4187 }
6ed58ec5 4188
1da177e4
LT
4189 /* Send next queued raw (unknown type) packet */
4190 while ((skb = skb_dequeue(&hdev->raw_q)))
57d17d70 4191 hci_send_frame(hdev, skb);
1da177e4
LT
4192}
4193
25985edc 4194/* ----- HCI RX task (incoming data processing) ----- */
1da177e4
LT
4195
4196/* ACL data packet */
6039aa73 4197static void hci_acldata_packet(struct hci_dev *hdev, struct sk_buff *skb)
1da177e4
LT
4198{
4199 struct hci_acl_hdr *hdr = (void *) skb->data;
4200 struct hci_conn *conn;
4201 __u16 handle, flags;
4202
4203 skb_pull(skb, HCI_ACL_HDR_SIZE);
4204
4205 handle = __le16_to_cpu(hdr->handle);
4206 flags = hci_flags(handle);
4207 handle = hci_handle(handle);
4208
f0e09510 4209 BT_DBG("%s len %d handle 0x%4.4x flags 0x%4.4x", hdev->name, skb->len,
a8c5fb1a 4210 handle, flags);
1da177e4
LT
4211
4212 hdev->stat.acl_rx++;
4213
4214 hci_dev_lock(hdev);
4215 conn = hci_conn_hash_lookup_handle(hdev, handle);
4216 hci_dev_unlock(hdev);
8e87d142 4217
1da177e4 4218 if (conn) {
65983fc7 4219 hci_conn_enter_active_mode(conn, BT_POWER_FORCE_ACTIVE_OFF);
04837f64 4220
1da177e4 4221 /* Send to upper protocol */
686ebf28
UF
4222 l2cap_recv_acldata(conn, skb, flags);
4223 return;
1da177e4 4224 } else {
8e87d142 4225 BT_ERR("%s ACL packet for unknown connection handle %d",
a8c5fb1a 4226 hdev->name, handle);
1da177e4
LT
4227 }
4228
4229 kfree_skb(skb);
4230}
4231
4232/* SCO data packet */
6039aa73 4233static void hci_scodata_packet(struct hci_dev *hdev, struct sk_buff *skb)
1da177e4
LT
4234{
4235 struct hci_sco_hdr *hdr = (void *) skb->data;
4236 struct hci_conn *conn;
4237 __u16 handle;
4238
4239 skb_pull(skb, HCI_SCO_HDR_SIZE);
4240
4241 handle = __le16_to_cpu(hdr->handle);
4242
f0e09510 4243 BT_DBG("%s len %d handle 0x%4.4x", hdev->name, skb->len, handle);
1da177e4
LT
4244
4245 hdev->stat.sco_rx++;
4246
4247 hci_dev_lock(hdev);
4248 conn = hci_conn_hash_lookup_handle(hdev, handle);
4249 hci_dev_unlock(hdev);
4250
4251 if (conn) {
1da177e4 4252 /* Send to upper protocol */
686ebf28
UF
4253 sco_recv_scodata(conn, skb);
4254 return;
1da177e4 4255 } else {
8e87d142 4256 BT_ERR("%s SCO packet for unknown connection handle %d",
a8c5fb1a 4257 hdev->name, handle);
1da177e4
LT
4258 }
4259
4260 kfree_skb(skb);
4261}
4262
9238f36a
JH
4263static bool hci_req_is_complete(struct hci_dev *hdev)
4264{
4265 struct sk_buff *skb;
4266
4267 skb = skb_peek(&hdev->cmd_q);
4268 if (!skb)
4269 return true;
4270
4271 return bt_cb(skb)->req.start;
4272}
4273
42c6b129
JH
4274static void hci_resend_last(struct hci_dev *hdev)
4275{
4276 struct hci_command_hdr *sent;
4277 struct sk_buff *skb;
4278 u16 opcode;
4279
4280 if (!hdev->sent_cmd)
4281 return;
4282
4283 sent = (void *) hdev->sent_cmd->data;
4284 opcode = __le16_to_cpu(sent->opcode);
4285 if (opcode == HCI_OP_RESET)
4286 return;
4287
4288 skb = skb_clone(hdev->sent_cmd, GFP_KERNEL);
4289 if (!skb)
4290 return;
4291
4292 skb_queue_head(&hdev->cmd_q, skb);
4293 queue_work(hdev->workqueue, &hdev->cmd_work);
4294}
4295
9238f36a
JH
4296void hci_req_cmd_complete(struct hci_dev *hdev, u16 opcode, u8 status)
4297{
4298 hci_req_complete_t req_complete = NULL;
4299 struct sk_buff *skb;
4300 unsigned long flags;
4301
4302 BT_DBG("opcode 0x%04x status 0x%02x", opcode, status);
4303
42c6b129
JH
4304 /* If the completed command doesn't match the last one that was
4305 * sent we need to do special handling of it.
9238f36a 4306 */
42c6b129
JH
4307 if (!hci_sent_cmd_data(hdev, opcode)) {
4308 /* Some CSR based controllers generate a spontaneous
4309 * reset complete event during init and any pending
4310 * command will never be completed. In such a case we
4311 * need to resend whatever was the last sent
4312 * command.
4313 */
4314 if (test_bit(HCI_INIT, &hdev->flags) && opcode == HCI_OP_RESET)
4315 hci_resend_last(hdev);
4316
9238f36a 4317 return;
42c6b129 4318 }
9238f36a
JH
4319
4320 /* If the command succeeded and there's still more commands in
4321 * this request the request is not yet complete.
4322 */
4323 if (!status && !hci_req_is_complete(hdev))
4324 return;
4325
4326 /* If this was the last command in a request the complete
4327 * callback would be found in hdev->sent_cmd instead of the
4328 * command queue (hdev->cmd_q).
4329 */
4330 if (hdev->sent_cmd) {
4331 req_complete = bt_cb(hdev->sent_cmd)->req.complete;
53e21fbc
JH
4332
4333 if (req_complete) {
4334 /* We must set the complete callback to NULL to
4335 * avoid calling the callback more than once if
4336 * this function gets called again.
4337 */
4338 bt_cb(hdev->sent_cmd)->req.complete = NULL;
4339
9238f36a 4340 goto call_complete;
53e21fbc 4341 }
9238f36a
JH
4342 }
4343
4344 /* Remove all pending commands belonging to this request */
4345 spin_lock_irqsave(&hdev->cmd_q.lock, flags);
4346 while ((skb = __skb_dequeue(&hdev->cmd_q))) {
4347 if (bt_cb(skb)->req.start) {
4348 __skb_queue_head(&hdev->cmd_q, skb);
4349 break;
4350 }
4351
4352 req_complete = bt_cb(skb)->req.complete;
4353 kfree_skb(skb);
4354 }
4355 spin_unlock_irqrestore(&hdev->cmd_q.lock, flags);
4356
4357call_complete:
4358 if (req_complete)
4359 req_complete(hdev, status);
4360}
4361
b78752cc 4362static void hci_rx_work(struct work_struct *work)
1da177e4 4363{
b78752cc 4364 struct hci_dev *hdev = container_of(work, struct hci_dev, rx_work);
1da177e4
LT
4365 struct sk_buff *skb;
4366
4367 BT_DBG("%s", hdev->name);
4368
1da177e4 4369 while ((skb = skb_dequeue(&hdev->rx_q))) {
cd82e61c
MH
4370 /* Send copy to monitor */
4371 hci_send_to_monitor(hdev, skb);
4372
1da177e4
LT
4373 if (atomic_read(&hdev->promisc)) {
4374 /* Send copy to the sockets */
470fe1b5 4375 hci_send_to_sock(hdev, skb);
1da177e4
LT
4376 }
4377
0736cfa8
MH
4378 if (test_bit(HCI_RAW, &hdev->flags) ||
4379 test_bit(HCI_USER_CHANNEL, &hdev->dev_flags)) {
1da177e4
LT
4380 kfree_skb(skb);
4381 continue;
4382 }
4383
4384 if (test_bit(HCI_INIT, &hdev->flags)) {
4385 /* Don't process data packets in this states. */
0d48d939 4386 switch (bt_cb(skb)->pkt_type) {
1da177e4
LT
4387 case HCI_ACLDATA_PKT:
4388 case HCI_SCODATA_PKT:
4389 kfree_skb(skb);
4390 continue;
3ff50b79 4391 }
1da177e4
LT
4392 }
4393
4394 /* Process frame */
0d48d939 4395 switch (bt_cb(skb)->pkt_type) {
1da177e4 4396 case HCI_EVENT_PKT:
b78752cc 4397 BT_DBG("%s Event packet", hdev->name);
1da177e4
LT
4398 hci_event_packet(hdev, skb);
4399 break;
4400
4401 case HCI_ACLDATA_PKT:
4402 BT_DBG("%s ACL data packet", hdev->name);
4403 hci_acldata_packet(hdev, skb);
4404 break;
4405
4406 case HCI_SCODATA_PKT:
4407 BT_DBG("%s SCO data packet", hdev->name);
4408 hci_scodata_packet(hdev, skb);
4409 break;
4410
4411 default:
4412 kfree_skb(skb);
4413 break;
4414 }
4415 }
1da177e4
LT
4416}
4417
c347b765 4418static void hci_cmd_work(struct work_struct *work)
1da177e4 4419{
c347b765 4420 struct hci_dev *hdev = container_of(work, struct hci_dev, cmd_work);
1da177e4
LT
4421 struct sk_buff *skb;
4422
2104786b
AE
4423 BT_DBG("%s cmd_cnt %d cmd queued %d", hdev->name,
4424 atomic_read(&hdev->cmd_cnt), skb_queue_len(&hdev->cmd_q));
1da177e4 4425
1da177e4 4426 /* Send queued commands */
5a08ecce
AE
4427 if (atomic_read(&hdev->cmd_cnt)) {
4428 skb = skb_dequeue(&hdev->cmd_q);
4429 if (!skb)
4430 return;
4431
7585b97a 4432 kfree_skb(hdev->sent_cmd);
1da177e4 4433
a675d7f1 4434 hdev->sent_cmd = skb_clone(skb, GFP_KERNEL);
70f23020 4435 if (hdev->sent_cmd) {
1da177e4 4436 atomic_dec(&hdev->cmd_cnt);
57d17d70 4437 hci_send_frame(hdev, skb);
7bdb8a5c
SJ
4438 if (test_bit(HCI_RESET, &hdev->flags))
4439 del_timer(&hdev->cmd_timer);
4440 else
4441 mod_timer(&hdev->cmd_timer,
5f246e89 4442 jiffies + HCI_CMD_TIMEOUT);
1da177e4
LT
4443 } else {
4444 skb_queue_head(&hdev->cmd_q, skb);
c347b765 4445 queue_work(hdev->workqueue, &hdev->cmd_work);
1da177e4
LT
4446 }
4447 }
4448}