]> git.proxmox.com Git - mirror_ubuntu-zesty-kernel.git/blob - net/bluetooth/sco.c
Bluetooth: Restrict to one SCO listening socket
[mirror_ubuntu-zesty-kernel.git] / net / bluetooth / sco.c
1 /*
2 BlueZ - Bluetooth protocol stack for Linux
3 Copyright (C) 2000-2001 Qualcomm Incorporated
4
5 Written 2000,2001 by Maxim Krasnyansky <maxk@qualcomm.com>
6
7 This program is free software; you can redistribute it and/or modify
8 it under the terms of the GNU General Public License version 2 as
9 published by the Free Software Foundation;
10
11 THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS
12 OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
13 FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT OF THIRD PARTY RIGHTS.
14 IN NO EVENT SHALL THE COPYRIGHT HOLDER(S) AND AUTHOR(S) BE LIABLE FOR ANY
15 CLAIM, OR ANY SPECIAL INDIRECT OR CONSEQUENTIAL DAMAGES, OR ANY DAMAGES
16 WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
17 ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
18 OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
19
20 ALL LIABILITY, INCLUDING LIABILITY FOR INFRINGEMENT OF ANY PATENTS,
21 COPYRIGHTS, TRADEMARKS OR OTHER RIGHTS, RELATING TO USE OF THIS
22 SOFTWARE IS DISCLAIMED.
23 */
24
25 /* Bluetooth SCO sockets. */
26
27 #include <linux/module.h>
28
29 #include <linux/types.h>
30 #include <linux/errno.h>
31 #include <linux/kernel.h>
32 #include <linux/sched.h>
33 #include <linux/slab.h>
34 #include <linux/poll.h>
35 #include <linux/fcntl.h>
36 #include <linux/init.h>
37 #include <linux/interrupt.h>
38 #include <linux/socket.h>
39 #include <linux/skbuff.h>
40 #include <linux/device.h>
41 #include <linux/debugfs.h>
42 #include <linux/seq_file.h>
43 #include <linux/list.h>
44 #include <linux/security.h>
45 #include <net/sock.h>
46
47 #include <linux/uaccess.h>
48
49 #include <net/bluetooth/bluetooth.h>
50 #include <net/bluetooth/hci_core.h>
51 #include <net/bluetooth/sco.h>
52
53 static bool disable_esco;
54
55 static const struct proto_ops sco_sock_ops;
56
57 static struct bt_sock_list sco_sk_list = {
58 .lock = __RW_LOCK_UNLOCKED(sco_sk_list.lock)
59 };
60
61 static void __sco_chan_add(struct sco_conn *conn, struct sock *sk, struct sock *parent);
62 static void sco_chan_del(struct sock *sk, int err);
63
64 static void sco_sock_close(struct sock *sk);
65 static void sco_sock_kill(struct sock *sk);
66
67 /* ---- SCO timers ---- */
68 static void sco_sock_timeout(unsigned long arg)
69 {
70 struct sock *sk = (struct sock *) arg;
71
72 BT_DBG("sock %p state %d", sk, sk->sk_state);
73
74 bh_lock_sock(sk);
75 sk->sk_err = ETIMEDOUT;
76 sk->sk_state_change(sk);
77 bh_unlock_sock(sk);
78
79 sco_sock_kill(sk);
80 sock_put(sk);
81 }
82
83 static void sco_sock_set_timer(struct sock *sk, long timeout)
84 {
85 BT_DBG("sock %p state %d timeout %ld", sk, sk->sk_state, timeout);
86 sk_reset_timer(sk, &sk->sk_timer, jiffies + timeout);
87 }
88
89 static void sco_sock_clear_timer(struct sock *sk)
90 {
91 BT_DBG("sock %p state %d", sk, sk->sk_state);
92 sk_stop_timer(sk, &sk->sk_timer);
93 }
94
95 /* ---- SCO connections ---- */
96 static struct sco_conn *sco_conn_add(struct hci_conn *hcon)
97 {
98 struct hci_dev *hdev = hcon->hdev;
99 struct sco_conn *conn = hcon->sco_data;
100
101 if (conn)
102 return conn;
103
104 conn = kzalloc(sizeof(struct sco_conn), GFP_ATOMIC);
105 if (!conn)
106 return NULL;
107
108 spin_lock_init(&conn->lock);
109
110 hcon->sco_data = conn;
111 conn->hcon = hcon;
112
113 conn->src = &hdev->bdaddr;
114 conn->dst = &hcon->dst;
115
116 if (hdev->sco_mtu > 0)
117 conn->mtu = hdev->sco_mtu;
118 else
119 conn->mtu = 60;
120
121 BT_DBG("hcon %p conn %p", hcon, conn);
122
123 return conn;
124 }
125
126 static inline struct sock *sco_chan_get(struct sco_conn *conn)
127 {
128 struct sock *sk = NULL;
129 sco_conn_lock(conn);
130 sk = conn->sk;
131 sco_conn_unlock(conn);
132 return sk;
133 }
134
135 static int sco_conn_del(struct hci_conn *hcon, int err)
136 {
137 struct sco_conn *conn = hcon->sco_data;
138 struct sock *sk;
139
140 if (!conn)
141 return 0;
142
143 BT_DBG("hcon %p conn %p, err %d", hcon, conn, err);
144
145 /* Kill socket */
146 sk = sco_chan_get(conn);
147 if (sk) {
148 bh_lock_sock(sk);
149 sco_sock_clear_timer(sk);
150 sco_chan_del(sk, err);
151 bh_unlock_sock(sk);
152 sco_sock_kill(sk);
153 }
154
155 hcon->sco_data = NULL;
156 kfree(conn);
157 return 0;
158 }
159
160 static inline int sco_chan_add(struct sco_conn *conn, struct sock *sk, struct sock *parent)
161 {
162 int err = 0;
163
164 sco_conn_lock(conn);
165 if (conn->sk)
166 err = -EBUSY;
167 else
168 __sco_chan_add(conn, sk, parent);
169
170 sco_conn_unlock(conn);
171 return err;
172 }
173
174 static int sco_connect(struct sock *sk)
175 {
176 bdaddr_t *src = &bt_sk(sk)->src;
177 bdaddr_t *dst = &bt_sk(sk)->dst;
178 struct sco_conn *conn;
179 struct hci_conn *hcon;
180 struct hci_dev *hdev;
181 int err, type;
182
183 BT_DBG("%s -> %s", batostr(src), batostr(dst));
184
185 hdev = hci_get_route(dst, src);
186 if (!hdev)
187 return -EHOSTUNREACH;
188
189 hci_dev_lock(hdev);
190
191 if (lmp_esco_capable(hdev) && !disable_esco)
192 type = ESCO_LINK;
193 else
194 type = SCO_LINK;
195
196 hcon = hci_connect(hdev, type, dst, BT_SECURITY_LOW, HCI_AT_NO_BONDING);
197 if (IS_ERR(hcon)) {
198 err = PTR_ERR(hcon);
199 goto done;
200 }
201
202 conn = sco_conn_add(hcon);
203 if (!conn) {
204 hci_conn_put(hcon);
205 err = -ENOMEM;
206 goto done;
207 }
208
209 /* Update source addr of the socket */
210 bacpy(src, conn->src);
211
212 err = sco_chan_add(conn, sk, NULL);
213 if (err)
214 goto done;
215
216 if (hcon->state == BT_CONNECTED) {
217 sco_sock_clear_timer(sk);
218 sk->sk_state = BT_CONNECTED;
219 } else {
220 sk->sk_state = BT_CONNECT;
221 sco_sock_set_timer(sk, sk->sk_sndtimeo);
222 }
223
224 done:
225 hci_dev_unlock(hdev);
226 hci_dev_put(hdev);
227 return err;
228 }
229
230 static inline int sco_send_frame(struct sock *sk, struct msghdr *msg, int len)
231 {
232 struct sco_conn *conn = sco_pi(sk)->conn;
233 struct sk_buff *skb;
234 int err;
235
236 /* Check outgoing MTU */
237 if (len > conn->mtu)
238 return -EINVAL;
239
240 BT_DBG("sk %p len %d", sk, len);
241
242 skb = bt_skb_send_alloc(sk, len, msg->msg_flags & MSG_DONTWAIT, &err);
243 if (!skb)
244 return err;
245
246 if (memcpy_fromiovec(skb_put(skb, len), msg->msg_iov, len)) {
247 kfree_skb(skb);
248 return -EFAULT;
249 }
250
251 hci_send_sco(conn->hcon, skb);
252
253 return len;
254 }
255
256 static inline void sco_recv_frame(struct sco_conn *conn, struct sk_buff *skb)
257 {
258 struct sock *sk = sco_chan_get(conn);
259
260 if (!sk)
261 goto drop;
262
263 BT_DBG("sk %p len %d", sk, skb->len);
264
265 if (sk->sk_state != BT_CONNECTED)
266 goto drop;
267
268 if (!sock_queue_rcv_skb(sk, skb))
269 return;
270
271 drop:
272 kfree_skb(skb);
273 }
274
275 /* -------- Socket interface ---------- */
276 static struct sock *__sco_get_sock_listen_by_addr(bdaddr_t *ba)
277 {
278 struct hlist_node *node;
279 struct sock *sk;
280
281 sk_for_each(sk, node, &sco_sk_list.head) {
282 if (sk->sk_state != BT_LISTEN)
283 continue;
284
285 if (!bacmp(&bt_sk(sk)->src, ba))
286 return sk;
287 }
288
289 return NULL;
290 }
291
292 /* Find socket listening on source bdaddr.
293 * Returns closest match.
294 */
295 static struct sock *sco_get_sock_listen(bdaddr_t *src)
296 {
297 struct sock *sk = NULL, *sk1 = NULL;
298 struct hlist_node *node;
299
300 read_lock(&sco_sk_list.lock);
301
302 sk_for_each(sk, node, &sco_sk_list.head) {
303 if (sk->sk_state != BT_LISTEN)
304 continue;
305
306 /* Exact match. */
307 if (!bacmp(&bt_sk(sk)->src, src))
308 break;
309
310 /* Closest match */
311 if (!bacmp(&bt_sk(sk)->src, BDADDR_ANY))
312 sk1 = sk;
313 }
314
315 read_unlock(&sco_sk_list.lock);
316
317 return node ? sk : sk1;
318 }
319
320 static void sco_sock_destruct(struct sock *sk)
321 {
322 BT_DBG("sk %p", sk);
323
324 skb_queue_purge(&sk->sk_receive_queue);
325 skb_queue_purge(&sk->sk_write_queue);
326 }
327
328 static void sco_sock_cleanup_listen(struct sock *parent)
329 {
330 struct sock *sk;
331
332 BT_DBG("parent %p", parent);
333
334 /* Close not yet accepted channels */
335 while ((sk = bt_accept_dequeue(parent, NULL))) {
336 sco_sock_close(sk);
337 sco_sock_kill(sk);
338 }
339
340 parent->sk_state = BT_CLOSED;
341 sock_set_flag(parent, SOCK_ZAPPED);
342 }
343
344 /* Kill socket (only if zapped and orphan)
345 * Must be called on unlocked socket.
346 */
347 static void sco_sock_kill(struct sock *sk)
348 {
349 if (!sock_flag(sk, SOCK_ZAPPED) || sk->sk_socket)
350 return;
351
352 BT_DBG("sk %p state %d", sk, sk->sk_state);
353
354 /* Kill poor orphan */
355 bt_sock_unlink(&sco_sk_list, sk);
356 sock_set_flag(sk, SOCK_DEAD);
357 sock_put(sk);
358 }
359
360 static void __sco_sock_close(struct sock *sk)
361 {
362 BT_DBG("sk %p state %d socket %p", sk, sk->sk_state, sk->sk_socket);
363
364 switch (sk->sk_state) {
365 case BT_LISTEN:
366 sco_sock_cleanup_listen(sk);
367 break;
368
369 case BT_CONNECTED:
370 case BT_CONFIG:
371 if (sco_pi(sk)->conn) {
372 sk->sk_state = BT_DISCONN;
373 sco_sock_set_timer(sk, SCO_DISCONN_TIMEOUT);
374 hci_conn_put(sco_pi(sk)->conn->hcon);
375 sco_pi(sk)->conn->hcon = NULL;
376 } else
377 sco_chan_del(sk, ECONNRESET);
378 break;
379
380 case BT_CONNECT:
381 case BT_DISCONN:
382 sco_chan_del(sk, ECONNRESET);
383 break;
384
385 default:
386 sock_set_flag(sk, SOCK_ZAPPED);
387 break;
388 }
389 }
390
391 /* Must be called on unlocked socket. */
392 static void sco_sock_close(struct sock *sk)
393 {
394 sco_sock_clear_timer(sk);
395 lock_sock(sk);
396 __sco_sock_close(sk);
397 release_sock(sk);
398 sco_sock_kill(sk);
399 }
400
401 static void sco_sock_init(struct sock *sk, struct sock *parent)
402 {
403 BT_DBG("sk %p", sk);
404
405 if (parent) {
406 sk->sk_type = parent->sk_type;
407 security_sk_clone(parent, sk);
408 }
409 }
410
411 static struct proto sco_proto = {
412 .name = "SCO",
413 .owner = THIS_MODULE,
414 .obj_size = sizeof(struct sco_pinfo)
415 };
416
417 static struct sock *sco_sock_alloc(struct net *net, struct socket *sock, int proto, gfp_t prio)
418 {
419 struct sock *sk;
420
421 sk = sk_alloc(net, PF_BLUETOOTH, prio, &sco_proto);
422 if (!sk)
423 return NULL;
424
425 sock_init_data(sock, sk);
426 INIT_LIST_HEAD(&bt_sk(sk)->accept_q);
427
428 sk->sk_destruct = sco_sock_destruct;
429 sk->sk_sndtimeo = SCO_CONN_TIMEOUT;
430
431 sock_reset_flag(sk, SOCK_ZAPPED);
432
433 sk->sk_protocol = proto;
434 sk->sk_state = BT_OPEN;
435
436 setup_timer(&sk->sk_timer, sco_sock_timeout, (unsigned long)sk);
437
438 bt_sock_link(&sco_sk_list, sk);
439 return sk;
440 }
441
442 static int sco_sock_create(struct net *net, struct socket *sock, int protocol,
443 int kern)
444 {
445 struct sock *sk;
446
447 BT_DBG("sock %p", sock);
448
449 sock->state = SS_UNCONNECTED;
450
451 if (sock->type != SOCK_SEQPACKET)
452 return -ESOCKTNOSUPPORT;
453
454 sock->ops = &sco_sock_ops;
455
456 sk = sco_sock_alloc(net, sock, protocol, GFP_ATOMIC);
457 if (!sk)
458 return -ENOMEM;
459
460 sco_sock_init(sk, NULL);
461 return 0;
462 }
463
464 static int sco_sock_bind(struct socket *sock, struct sockaddr *addr, int addr_len)
465 {
466 struct sockaddr_sco *sa = (struct sockaddr_sco *) addr;
467 struct sock *sk = sock->sk;
468 int err = 0;
469
470 BT_DBG("sk %p %s", sk, batostr(&sa->sco_bdaddr));
471
472 if (!addr || addr->sa_family != AF_BLUETOOTH)
473 return -EINVAL;
474
475 lock_sock(sk);
476
477 if (sk->sk_state != BT_OPEN) {
478 err = -EBADFD;
479 goto done;
480 }
481
482 if (sk->sk_type != SOCK_SEQPACKET) {
483 err = -EINVAL;
484 goto done;
485 }
486
487 bacpy(&bt_sk(sk)->src, &sa->sco_bdaddr);
488
489 sk->sk_state = BT_BOUND;
490
491 done:
492 release_sock(sk);
493 return err;
494 }
495
496 static int sco_sock_connect(struct socket *sock, struct sockaddr *addr, int alen, int flags)
497 {
498 struct sockaddr_sco *sa = (struct sockaddr_sco *) addr;
499 struct sock *sk = sock->sk;
500 int err = 0;
501
502
503 BT_DBG("sk %p", sk);
504
505 if (alen < sizeof(struct sockaddr_sco) ||
506 addr->sa_family != AF_BLUETOOTH)
507 return -EINVAL;
508
509 if (sk->sk_state != BT_OPEN && sk->sk_state != BT_BOUND)
510 return -EBADFD;
511
512 if (sk->sk_type != SOCK_SEQPACKET)
513 return -EINVAL;
514
515 lock_sock(sk);
516
517 /* Set destination address and psm */
518 bacpy(&bt_sk(sk)->dst, &sa->sco_bdaddr);
519
520 err = sco_connect(sk);
521 if (err)
522 goto done;
523
524 err = bt_sock_wait_state(sk, BT_CONNECTED,
525 sock_sndtimeo(sk, flags & O_NONBLOCK));
526
527 done:
528 release_sock(sk);
529 return err;
530 }
531
532 static int sco_sock_listen(struct socket *sock, int backlog)
533 {
534 struct sock *sk = sock->sk;
535 bdaddr_t *src = &bt_sk(sk)->src;
536 int err = 0;
537
538 BT_DBG("sk %p backlog %d", sk, backlog);
539
540 lock_sock(sk);
541
542 if (sk->sk_state != BT_BOUND) {
543 err = -EBADFD;
544 goto done;
545 }
546
547 if (sk->sk_type != SOCK_SEQPACKET) {
548 err = -EINVAL;
549 goto done;
550 }
551
552 write_lock(&sco_sk_list.lock);
553
554 if (__sco_get_sock_listen_by_addr(src)) {
555 err = -EADDRINUSE;
556 goto unlock;
557 }
558
559 sk->sk_max_ack_backlog = backlog;
560 sk->sk_ack_backlog = 0;
561
562 sk->sk_state = BT_LISTEN;
563
564 unlock:
565 write_unlock(&sco_sk_list.lock);
566
567 done:
568 release_sock(sk);
569 return err;
570 }
571
572 static int sco_sock_accept(struct socket *sock, struct socket *newsock, int flags)
573 {
574 DECLARE_WAITQUEUE(wait, current);
575 struct sock *sk = sock->sk, *ch;
576 long timeo;
577 int err = 0;
578
579 lock_sock(sk);
580
581 timeo = sock_rcvtimeo(sk, flags & O_NONBLOCK);
582
583 BT_DBG("sk %p timeo %ld", sk, timeo);
584
585 /* Wait for an incoming connection. (wake-one). */
586 add_wait_queue_exclusive(sk_sleep(sk), &wait);
587 while (1) {
588 set_current_state(TASK_INTERRUPTIBLE);
589
590 if (sk->sk_state != BT_LISTEN) {
591 err = -EBADFD;
592 break;
593 }
594
595 ch = bt_accept_dequeue(sk, newsock);
596 if (ch)
597 break;
598
599 if (!timeo) {
600 err = -EAGAIN;
601 break;
602 }
603
604 if (signal_pending(current)) {
605 err = sock_intr_errno(timeo);
606 break;
607 }
608
609 release_sock(sk);
610 timeo = schedule_timeout(timeo);
611 lock_sock(sk);
612 }
613 __set_current_state(TASK_RUNNING);
614 remove_wait_queue(sk_sleep(sk), &wait);
615
616 if (err)
617 goto done;
618
619 newsock->state = SS_CONNECTED;
620
621 BT_DBG("new socket %p", ch);
622
623 done:
624 release_sock(sk);
625 return err;
626 }
627
628 static int sco_sock_getname(struct socket *sock, struct sockaddr *addr, int *len, int peer)
629 {
630 struct sockaddr_sco *sa = (struct sockaddr_sco *) addr;
631 struct sock *sk = sock->sk;
632
633 BT_DBG("sock %p, sk %p", sock, sk);
634
635 addr->sa_family = AF_BLUETOOTH;
636 *len = sizeof(struct sockaddr_sco);
637
638 if (peer)
639 bacpy(&sa->sco_bdaddr, &bt_sk(sk)->dst);
640 else
641 bacpy(&sa->sco_bdaddr, &bt_sk(sk)->src);
642
643 return 0;
644 }
645
646 static int sco_sock_sendmsg(struct kiocb *iocb, struct socket *sock,
647 struct msghdr *msg, size_t len)
648 {
649 struct sock *sk = sock->sk;
650 int err;
651
652 BT_DBG("sock %p, sk %p", sock, sk);
653
654 err = sock_error(sk);
655 if (err)
656 return err;
657
658 if (msg->msg_flags & MSG_OOB)
659 return -EOPNOTSUPP;
660
661 lock_sock(sk);
662
663 if (sk->sk_state == BT_CONNECTED)
664 err = sco_send_frame(sk, msg, len);
665 else
666 err = -ENOTCONN;
667
668 release_sock(sk);
669 return err;
670 }
671
672 static int sco_sock_setsockopt(struct socket *sock, int level, int optname, char __user *optval, unsigned int optlen)
673 {
674 struct sock *sk = sock->sk;
675 int err = 0;
676
677 BT_DBG("sk %p", sk);
678
679 lock_sock(sk);
680
681 switch (optname) {
682 default:
683 err = -ENOPROTOOPT;
684 break;
685 }
686
687 release_sock(sk);
688 return err;
689 }
690
691 static int sco_sock_getsockopt_old(struct socket *sock, int optname, char __user *optval, int __user *optlen)
692 {
693 struct sock *sk = sock->sk;
694 struct sco_options opts;
695 struct sco_conninfo cinfo;
696 int len, err = 0;
697
698 BT_DBG("sk %p", sk);
699
700 if (get_user(len, optlen))
701 return -EFAULT;
702
703 lock_sock(sk);
704
705 switch (optname) {
706 case SCO_OPTIONS:
707 if (sk->sk_state != BT_CONNECTED) {
708 err = -ENOTCONN;
709 break;
710 }
711
712 opts.mtu = sco_pi(sk)->conn->mtu;
713
714 BT_DBG("mtu %d", opts.mtu);
715
716 len = min_t(unsigned int, len, sizeof(opts));
717 if (copy_to_user(optval, (char *)&opts, len))
718 err = -EFAULT;
719
720 break;
721
722 case SCO_CONNINFO:
723 if (sk->sk_state != BT_CONNECTED) {
724 err = -ENOTCONN;
725 break;
726 }
727
728 memset(&cinfo, 0, sizeof(cinfo));
729 cinfo.hci_handle = sco_pi(sk)->conn->hcon->handle;
730 memcpy(cinfo.dev_class, sco_pi(sk)->conn->hcon->dev_class, 3);
731
732 len = min_t(unsigned int, len, sizeof(cinfo));
733 if (copy_to_user(optval, (char *)&cinfo, len))
734 err = -EFAULT;
735
736 break;
737
738 default:
739 err = -ENOPROTOOPT;
740 break;
741 }
742
743 release_sock(sk);
744 return err;
745 }
746
747 static int sco_sock_getsockopt(struct socket *sock, int level, int optname, char __user *optval, int __user *optlen)
748 {
749 struct sock *sk = sock->sk;
750 int len, err = 0;
751
752 BT_DBG("sk %p", sk);
753
754 if (level == SOL_SCO)
755 return sco_sock_getsockopt_old(sock, optname, optval, optlen);
756
757 if (get_user(len, optlen))
758 return -EFAULT;
759
760 lock_sock(sk);
761
762 switch (optname) {
763 default:
764 err = -ENOPROTOOPT;
765 break;
766 }
767
768 release_sock(sk);
769 return err;
770 }
771
772 static int sco_sock_shutdown(struct socket *sock, int how)
773 {
774 struct sock *sk = sock->sk;
775 int err = 0;
776
777 BT_DBG("sock %p, sk %p", sock, sk);
778
779 if (!sk)
780 return 0;
781
782 lock_sock(sk);
783 if (!sk->sk_shutdown) {
784 sk->sk_shutdown = SHUTDOWN_MASK;
785 sco_sock_clear_timer(sk);
786 __sco_sock_close(sk);
787
788 if (sock_flag(sk, SOCK_LINGER) && sk->sk_lingertime)
789 err = bt_sock_wait_state(sk, BT_CLOSED,
790 sk->sk_lingertime);
791 }
792 release_sock(sk);
793 return err;
794 }
795
796 static int sco_sock_release(struct socket *sock)
797 {
798 struct sock *sk = sock->sk;
799 int err = 0;
800
801 BT_DBG("sock %p, sk %p", sock, sk);
802
803 if (!sk)
804 return 0;
805
806 sco_sock_close(sk);
807
808 if (sock_flag(sk, SOCK_LINGER) && sk->sk_lingertime) {
809 lock_sock(sk);
810 err = bt_sock_wait_state(sk, BT_CLOSED, sk->sk_lingertime);
811 release_sock(sk);
812 }
813
814 sock_orphan(sk);
815 sco_sock_kill(sk);
816 return err;
817 }
818
819 static void __sco_chan_add(struct sco_conn *conn, struct sock *sk, struct sock *parent)
820 {
821 BT_DBG("conn %p", conn);
822
823 sco_pi(sk)->conn = conn;
824 conn->sk = sk;
825
826 if (parent)
827 bt_accept_enqueue(parent, sk);
828 }
829
830 /* Delete channel.
831 * Must be called on the locked socket. */
832 static void sco_chan_del(struct sock *sk, int err)
833 {
834 struct sco_conn *conn;
835
836 conn = sco_pi(sk)->conn;
837
838 BT_DBG("sk %p, conn %p, err %d", sk, conn, err);
839
840 if (conn) {
841 sco_conn_lock(conn);
842 conn->sk = NULL;
843 sco_pi(sk)->conn = NULL;
844 sco_conn_unlock(conn);
845
846 if (conn->hcon)
847 hci_conn_put(conn->hcon);
848 }
849
850 sk->sk_state = BT_CLOSED;
851 sk->sk_err = err;
852 sk->sk_state_change(sk);
853
854 sock_set_flag(sk, SOCK_ZAPPED);
855 }
856
857 static void sco_conn_ready(struct sco_conn *conn)
858 {
859 struct sock *parent;
860 struct sock *sk = conn->sk;
861
862 BT_DBG("conn %p", conn);
863
864 sco_conn_lock(conn);
865
866 if (sk) {
867 sco_sock_clear_timer(sk);
868 bh_lock_sock(sk);
869 sk->sk_state = BT_CONNECTED;
870 sk->sk_state_change(sk);
871 bh_unlock_sock(sk);
872 } else {
873 parent = sco_get_sock_listen(conn->src);
874 if (!parent)
875 goto done;
876
877 bh_lock_sock(parent);
878
879 sk = sco_sock_alloc(sock_net(parent), NULL,
880 BTPROTO_SCO, GFP_ATOMIC);
881 if (!sk) {
882 bh_unlock_sock(parent);
883 goto done;
884 }
885
886 sco_sock_init(sk, parent);
887
888 bacpy(&bt_sk(sk)->src, conn->src);
889 bacpy(&bt_sk(sk)->dst, conn->dst);
890
891 hci_conn_hold(conn->hcon);
892 __sco_chan_add(conn, sk, parent);
893
894 sk->sk_state = BT_CONNECTED;
895
896 /* Wake up parent */
897 parent->sk_data_ready(parent, 1);
898
899 bh_unlock_sock(parent);
900 }
901
902 done:
903 sco_conn_unlock(conn);
904 }
905
906 /* ----- SCO interface with lower layer (HCI) ----- */
907 int sco_connect_ind(struct hci_dev *hdev, bdaddr_t *bdaddr)
908 {
909 register struct sock *sk;
910 struct hlist_node *node;
911 int lm = 0;
912
913 BT_DBG("hdev %s, bdaddr %s", hdev->name, batostr(bdaddr));
914
915 /* Find listening sockets */
916 read_lock(&sco_sk_list.lock);
917 sk_for_each(sk, node, &sco_sk_list.head) {
918 if (sk->sk_state != BT_LISTEN)
919 continue;
920
921 if (!bacmp(&bt_sk(sk)->src, &hdev->bdaddr) ||
922 !bacmp(&bt_sk(sk)->src, BDADDR_ANY)) {
923 lm |= HCI_LM_ACCEPT;
924 break;
925 }
926 }
927 read_unlock(&sco_sk_list.lock);
928
929 return lm;
930 }
931
932 int sco_connect_cfm(struct hci_conn *hcon, __u8 status)
933 {
934 BT_DBG("hcon %p bdaddr %s status %d", hcon, batostr(&hcon->dst), status);
935 if (!status) {
936 struct sco_conn *conn;
937
938 conn = sco_conn_add(hcon);
939 if (conn)
940 sco_conn_ready(conn);
941 } else
942 sco_conn_del(hcon, bt_to_errno(status));
943
944 return 0;
945 }
946
947 int sco_disconn_cfm(struct hci_conn *hcon, __u8 reason)
948 {
949 BT_DBG("hcon %p reason %d", hcon, reason);
950
951 sco_conn_del(hcon, bt_to_errno(reason));
952 return 0;
953 }
954
955 int sco_recv_scodata(struct hci_conn *hcon, struct sk_buff *skb)
956 {
957 struct sco_conn *conn = hcon->sco_data;
958
959 if (!conn)
960 goto drop;
961
962 BT_DBG("conn %p len %d", conn, skb->len);
963
964 if (skb->len) {
965 sco_recv_frame(conn, skb);
966 return 0;
967 }
968
969 drop:
970 kfree_skb(skb);
971 return 0;
972 }
973
974 static int sco_debugfs_show(struct seq_file *f, void *p)
975 {
976 struct sock *sk;
977 struct hlist_node *node;
978
979 read_lock(&sco_sk_list.lock);
980
981 sk_for_each(sk, node, &sco_sk_list.head) {
982 seq_printf(f, "%s %s %d\n", batostr(&bt_sk(sk)->src),
983 batostr(&bt_sk(sk)->dst), sk->sk_state);
984 }
985
986 read_unlock(&sco_sk_list.lock);
987
988 return 0;
989 }
990
991 static int sco_debugfs_open(struct inode *inode, struct file *file)
992 {
993 return single_open(file, sco_debugfs_show, inode->i_private);
994 }
995
996 static const struct file_operations sco_debugfs_fops = {
997 .open = sco_debugfs_open,
998 .read = seq_read,
999 .llseek = seq_lseek,
1000 .release = single_release,
1001 };
1002
1003 static struct dentry *sco_debugfs;
1004
1005 static const struct proto_ops sco_sock_ops = {
1006 .family = PF_BLUETOOTH,
1007 .owner = THIS_MODULE,
1008 .release = sco_sock_release,
1009 .bind = sco_sock_bind,
1010 .connect = sco_sock_connect,
1011 .listen = sco_sock_listen,
1012 .accept = sco_sock_accept,
1013 .getname = sco_sock_getname,
1014 .sendmsg = sco_sock_sendmsg,
1015 .recvmsg = bt_sock_recvmsg,
1016 .poll = bt_sock_poll,
1017 .ioctl = bt_sock_ioctl,
1018 .mmap = sock_no_mmap,
1019 .socketpair = sock_no_socketpair,
1020 .shutdown = sco_sock_shutdown,
1021 .setsockopt = sco_sock_setsockopt,
1022 .getsockopt = sco_sock_getsockopt
1023 };
1024
1025 static const struct net_proto_family sco_sock_family_ops = {
1026 .family = PF_BLUETOOTH,
1027 .owner = THIS_MODULE,
1028 .create = sco_sock_create,
1029 };
1030
1031 int __init sco_init(void)
1032 {
1033 int err;
1034
1035 err = proto_register(&sco_proto, 0);
1036 if (err < 0)
1037 return err;
1038
1039 err = bt_sock_register(BTPROTO_SCO, &sco_sock_family_ops);
1040 if (err < 0) {
1041 BT_ERR("SCO socket registration failed");
1042 goto error;
1043 }
1044
1045 if (bt_debugfs) {
1046 sco_debugfs = debugfs_create_file("sco", 0444,
1047 bt_debugfs, NULL, &sco_debugfs_fops);
1048 if (!sco_debugfs)
1049 BT_ERR("Failed to create SCO debug file");
1050 }
1051
1052 BT_INFO("SCO socket layer initialized");
1053
1054 return 0;
1055
1056 error:
1057 proto_unregister(&sco_proto);
1058 return err;
1059 }
1060
1061 void __exit sco_exit(void)
1062 {
1063 debugfs_remove(sco_debugfs);
1064
1065 if (bt_sock_unregister(BTPROTO_SCO) < 0)
1066 BT_ERR("SCO socket unregistration failed");
1067
1068 proto_unregister(&sco_proto);
1069 }
1070
1071 module_param(disable_esco, bool, 0644);
1072 MODULE_PARM_DESC(disable_esco, "Disable eSCO connection creation");