blob: f6afe3d76a668154a3131fe55f78bf3de34ed636 [file] [log] [blame]
YOSHIFUJI Hideaki8e87d142007-02-09 23:24:33 +09001/*
Linus Torvalds1da177e2005-04-16 15:20:36 -07002 BlueZ - Bluetooth protocol stack for Linux
3 Copyright (C) 2000-2001 Qualcomm Incorporated
4
5 Written 2000,2001 by Maxim Krasnyansky <maxk@qualcomm.com>
6
7 This program is free software; you can redistribute it and/or modify
8 it under the terms of the GNU General Public License version 2 as
9 published by the Free Software Foundation;
10
11 THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS
12 OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
13 FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT OF THIRD PARTY RIGHTS.
14 IN NO EVENT SHALL THE COPYRIGHT HOLDER(S) AND AUTHOR(S) BE LIABLE FOR ANY
YOSHIFUJI Hideaki8e87d142007-02-09 23:24:33 +090015 CLAIM, OR ANY SPECIAL INDIRECT OR CONSEQUENTIAL DAMAGES, OR ANY DAMAGES
16 WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
17 ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
Linus Torvalds1da177e2005-04-16 15:20:36 -070018 OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
19
YOSHIFUJI Hideaki8e87d142007-02-09 23:24:33 +090020 ALL LIABILITY, INCLUDING LIABILITY FOR INFRINGEMENT OF ANY PATENTS,
21 COPYRIGHTS, TRADEMARKS OR OTHER RIGHTS, RELATING TO USE OF THIS
Linus Torvalds1da177e2005-04-16 15:20:36 -070022 SOFTWARE IS DISCLAIMED.
23*/
24
25/* Bluetooth HCI sockets. */
26
Linus Torvalds1da177e2005-04-16 15:20:36 -070027#include <linux/module.h>
28
29#include <linux/types.h>
Randy Dunlap4fc268d2006-01-11 12:17:47 -080030#include <linux/capability.h>
Linus Torvalds1da177e2005-04-16 15:20:36 -070031#include <linux/errno.h>
32#include <linux/kernel.h>
Linus Torvalds1da177e2005-04-16 15:20:36 -070033#include <linux/slab.h>
34#include <linux/poll.h>
35#include <linux/fcntl.h>
36#include <linux/init.h>
37#include <linux/skbuff.h>
38#include <linux/workqueue.h>
39#include <linux/interrupt.h>
Marcel Holtmann767c5eb2007-09-09 08:39:34 +020040#include <linux/compat.h>
Linus Torvalds1da177e2005-04-16 15:20:36 -070041#include <linux/socket.h>
42#include <linux/ioctl.h>
43#include <net/sock.h>
44
45#include <asm/system.h>
Andrei Emeltchenko70f230202010-12-01 16:58:25 +020046#include <linux/uaccess.h>
Linus Torvalds1da177e2005-04-16 15:20:36 -070047#include <asm/unaligned.h>
48
49#include <net/bluetooth/bluetooth.h>
50#include <net/bluetooth/hci_core.h>
51
Johan Hedberg03811012010-12-08 00:21:06 +020052static int enable_mgmt;
53
Linus Torvalds1da177e2005-04-16 15:20:36 -070054/* ----- HCI socket interface ----- */
55
56static inline int hci_test_bit(int nr, void *addr)
57{
58 return *((__u32 *) addr + (nr >> 5)) & ((__u32) 1 << (nr & 31));
59}
60
61/* Security filter */
62static struct hci_sec_filter hci_sec_filter = {
63 /* Packet types */
64 0x10,
65 /* Events */
Marcel Holtmanndd7f5522005-10-28 19:20:53 +020066 { 0x1000d9fe, 0x0000b00c },
Linus Torvalds1da177e2005-04-16 15:20:36 -070067 /* Commands */
68 {
69 { 0x0 },
70 /* OGF_LINK_CTL */
Marcel Holtmann7c631a62007-09-09 08:39:43 +020071 { 0xbe000006, 0x00000001, 0x00000000, 0x00 },
Linus Torvalds1da177e2005-04-16 15:20:36 -070072 /* OGF_LINK_POLICY */
Marcel Holtmann7c631a62007-09-09 08:39:43 +020073 { 0x00005200, 0x00000000, 0x00000000, 0x00 },
Linus Torvalds1da177e2005-04-16 15:20:36 -070074 /* OGF_HOST_CTL */
Marcel Holtmann7c631a62007-09-09 08:39:43 +020075 { 0xaab00200, 0x2b402aaa, 0x05220154, 0x00 },
Linus Torvalds1da177e2005-04-16 15:20:36 -070076 /* OGF_INFO_PARAM */
Marcel Holtmann7c631a62007-09-09 08:39:43 +020077 { 0x000002be, 0x00000000, 0x00000000, 0x00 },
Linus Torvalds1da177e2005-04-16 15:20:36 -070078 /* OGF_STATUS_PARAM */
Marcel Holtmann7c631a62007-09-09 08:39:43 +020079 { 0x000000ea, 0x00000000, 0x00000000, 0x00 }
Linus Torvalds1da177e2005-04-16 15:20:36 -070080 }
81};
82
83static struct bt_sock_list hci_sk_list = {
Robert P. J. Dayd5fb2962008-03-28 16:17:38 -070084 .lock = __RW_LOCK_UNLOCKED(hci_sk_list.lock)
Linus Torvalds1da177e2005-04-16 15:20:36 -070085};
86
87/* Send frame to RAW socket */
Johan Hedbergeec8d2b2010-12-16 10:17:38 +020088void hci_send_to_sock(struct hci_dev *hdev, struct sk_buff *skb,
89 struct sock *skip_sk)
Linus Torvalds1da177e2005-04-16 15:20:36 -070090{
91 struct sock *sk;
92 struct hlist_node *node;
93
94 BT_DBG("hdev %p len %d", hdev, skb->len);
95
96 read_lock(&hci_sk_list.lock);
97 sk_for_each(sk, node, &hci_sk_list.head) {
98 struct hci_filter *flt;
99 struct sk_buff *nskb;
100
Johan Hedbergeec8d2b2010-12-16 10:17:38 +0200101 if (sk == skip_sk)
102 continue;
103
Linus Torvalds1da177e2005-04-16 15:20:36 -0700104 if (sk->sk_state != BT_BOUND || hci_pi(sk)->hdev != hdev)
105 continue;
106
107 /* Don't send frame to the socket it came from */
108 if (skb->sk == sk)
109 continue;
110
Johan Hedberga40c4062010-12-08 00:21:07 +0200111 if (bt_cb(skb)->channel != hci_pi(sk)->channel)
112 continue;
113
114 if (bt_cb(skb)->channel == HCI_CHANNEL_CONTROL)
115 goto clone;
116
Linus Torvalds1da177e2005-04-16 15:20:36 -0700117 /* Apply filter */
118 flt = &hci_pi(sk)->filter;
119
Marcel Holtmann0d48d932005-08-09 20:30:28 -0700120 if (!test_bit((bt_cb(skb)->pkt_type == HCI_VENDOR_PKT) ?
121 0 : (bt_cb(skb)->pkt_type & HCI_FLT_TYPE_BITS), &flt->type_mask))
Linus Torvalds1da177e2005-04-16 15:20:36 -0700122 continue;
123
Marcel Holtmann0d48d932005-08-09 20:30:28 -0700124 if (bt_cb(skb)->pkt_type == HCI_EVENT_PKT) {
Linus Torvalds1da177e2005-04-16 15:20:36 -0700125 register int evt = (*(__u8 *)skb->data & HCI_FLT_EVENT_BITS);
126
127 if (!hci_test_bit(evt, &flt->event_mask))
128 continue;
129
David S. Miller4498c802006-11-21 16:17:41 -0800130 if (flt->opcode &&
131 ((evt == HCI_EV_CMD_COMPLETE &&
132 flt->opcode !=
Al Viro905f3ed2006-12-13 00:35:01 -0800133 get_unaligned((__le16 *)(skb->data + 3))) ||
David S. Miller4498c802006-11-21 16:17:41 -0800134 (evt == HCI_EV_CMD_STATUS &&
135 flt->opcode !=
Al Viro905f3ed2006-12-13 00:35:01 -0800136 get_unaligned((__le16 *)(skb->data + 4)))))
Linus Torvalds1da177e2005-04-16 15:20:36 -0700137 continue;
138 }
139
Johan Hedberga40c4062010-12-08 00:21:07 +0200140clone:
Andrei Emeltchenko70f230202010-12-01 16:58:25 +0200141 nskb = skb_clone(skb, GFP_ATOMIC);
142 if (!nskb)
Linus Torvalds1da177e2005-04-16 15:20:36 -0700143 continue;
144
145 /* Put type byte before the data */
Johan Hedberga40c4062010-12-08 00:21:07 +0200146 if (bt_cb(skb)->channel == HCI_CHANNEL_RAW)
147 memcpy(skb_push(nskb, 1), &bt_cb(nskb)->pkt_type, 1);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700148
149 if (sock_queue_rcv_skb(sk, nskb))
150 kfree_skb(nskb);
151 }
152 read_unlock(&hci_sk_list.lock);
153}
154
155static int hci_sock_release(struct socket *sock)
156{
157 struct sock *sk = sock->sk;
Marcel Holtmann7b005bd2006-02-13 11:40:03 +0100158 struct hci_dev *hdev;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700159
160 BT_DBG("sock %p sk %p", sock, sk);
161
162 if (!sk)
163 return 0;
164
Marcel Holtmann7b005bd2006-02-13 11:40:03 +0100165 hdev = hci_pi(sk)->hdev;
166
Linus Torvalds1da177e2005-04-16 15:20:36 -0700167 bt_sock_unlink(&hci_sk_list, sk);
168
169 if (hdev) {
170 atomic_dec(&hdev->promisc);
171 hci_dev_put(hdev);
172 }
173
174 sock_orphan(sk);
175
176 skb_queue_purge(&sk->sk_receive_queue);
177 skb_queue_purge(&sk->sk_write_queue);
178
179 sock_put(sk);
180 return 0;
181}
182
Antti Julkub2a66aa2011-06-15 12:01:14 +0300183static int hci_sock_blacklist_add(struct hci_dev *hdev, void __user *arg)
Johan Hedbergf0358562010-05-18 13:20:32 +0200184{
185 bdaddr_t bdaddr;
Antti Julku5e762442011-08-25 16:48:02 +0300186 int err;
Johan Hedbergf0358562010-05-18 13:20:32 +0200187
188 if (copy_from_user(&bdaddr, arg, sizeof(bdaddr)))
189 return -EFAULT;
190
Antti Julku5e762442011-08-25 16:48:02 +0300191 hci_dev_lock_bh(hdev);
192
193 err = hci_blacklist_add(hdev, &bdaddr);
194
195 hci_dev_unlock_bh(hdev);
196
197 return err;
Johan Hedbergf0358562010-05-18 13:20:32 +0200198}
199
Antti Julkub2a66aa2011-06-15 12:01:14 +0300200static int hci_sock_blacklist_del(struct hci_dev *hdev, void __user *arg)
Johan Hedbergf0358562010-05-18 13:20:32 +0200201{
202 bdaddr_t bdaddr;
Antti Julku5e762442011-08-25 16:48:02 +0300203 int err;
Johan Hedbergf0358562010-05-18 13:20:32 +0200204
205 if (copy_from_user(&bdaddr, arg, sizeof(bdaddr)))
206 return -EFAULT;
207
Antti Julku5e762442011-08-25 16:48:02 +0300208 hci_dev_lock_bh(hdev);
209
210 err = hci_blacklist_del(hdev, &bdaddr);
211
212 hci_dev_unlock_bh(hdev);
213
214 return err;
Johan Hedbergf0358562010-05-18 13:20:32 +0200215}
216
YOSHIFUJI Hideaki8e87d142007-02-09 23:24:33 +0900217/* Ioctls that require bound socket */
Linus Torvalds1da177e2005-04-16 15:20:36 -0700218static inline int hci_sock_bound_ioctl(struct sock *sk, unsigned int cmd, unsigned long arg)
219{
220 struct hci_dev *hdev = hci_pi(sk)->hdev;
221
222 if (!hdev)
223 return -EBADFD;
224
225 switch (cmd) {
226 case HCISETRAW:
227 if (!capable(CAP_NET_ADMIN))
228 return -EACCES;
229
230 if (test_bit(HCI_QUIRK_RAW_DEVICE, &hdev->quirks))
231 return -EPERM;
232
233 if (arg)
234 set_bit(HCI_RAW, &hdev->flags);
235 else
236 clear_bit(HCI_RAW, &hdev->flags);
237
238 return 0;
239
Linus Torvalds1da177e2005-04-16 15:20:36 -0700240 case HCIGETCONNINFO:
Marcel Holtmann40be4922008-07-14 20:13:50 +0200241 return hci_get_conn_info(hdev, (void __user *) arg);
242
243 case HCIGETAUTHINFO:
244 return hci_get_auth_info(hdev, (void __user *) arg);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700245
Johan Hedbergf0358562010-05-18 13:20:32 +0200246 case HCIBLOCKADDR:
247 if (!capable(CAP_NET_ADMIN))
248 return -EACCES;
Antti Julkub2a66aa2011-06-15 12:01:14 +0300249 return hci_sock_blacklist_add(hdev, (void __user *) arg);
Johan Hedbergf0358562010-05-18 13:20:32 +0200250
251 case HCIUNBLOCKADDR:
252 if (!capable(CAP_NET_ADMIN))
253 return -EACCES;
Antti Julkub2a66aa2011-06-15 12:01:14 +0300254 return hci_sock_blacklist_del(hdev, (void __user *) arg);
Johan Hedbergf0358562010-05-18 13:20:32 +0200255
Linus Torvalds1da177e2005-04-16 15:20:36 -0700256 default:
257 if (hdev->ioctl)
258 return hdev->ioctl(hdev, cmd, arg);
259 return -EINVAL;
260 }
261}
262
263static int hci_sock_ioctl(struct socket *sock, unsigned int cmd, unsigned long arg)
264{
265 struct sock *sk = sock->sk;
Marcel Holtmann40be4922008-07-14 20:13:50 +0200266 void __user *argp = (void __user *) arg;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700267 int err;
268
269 BT_DBG("cmd %x arg %lx", cmd, arg);
270
271 switch (cmd) {
272 case HCIGETDEVLIST:
273 return hci_get_dev_list(argp);
274
275 case HCIGETDEVINFO:
276 return hci_get_dev_info(argp);
277
278 case HCIGETCONNLIST:
279 return hci_get_conn_list(argp);
280
281 case HCIDEVUP:
282 if (!capable(CAP_NET_ADMIN))
283 return -EACCES;
284 return hci_dev_open(arg);
285
286 case HCIDEVDOWN:
287 if (!capable(CAP_NET_ADMIN))
288 return -EACCES;
289 return hci_dev_close(arg);
290
291 case HCIDEVRESET:
292 if (!capable(CAP_NET_ADMIN))
293 return -EACCES;
294 return hci_dev_reset(arg);
295
296 case HCIDEVRESTAT:
297 if (!capable(CAP_NET_ADMIN))
298 return -EACCES;
299 return hci_dev_reset_stat(arg);
300
301 case HCISETSCAN:
302 case HCISETAUTH:
303 case HCISETENCRYPT:
304 case HCISETPTYPE:
305 case HCISETLINKPOL:
306 case HCISETLINKMODE:
307 case HCISETACLMTU:
308 case HCISETSCOMTU:
309 if (!capable(CAP_NET_ADMIN))
310 return -EACCES;
311 return hci_dev_cmd(cmd, argp);
312
313 case HCIINQUIRY:
314 return hci_inquiry(argp);
315
316 default:
317 lock_sock(sk);
318 err = hci_sock_bound_ioctl(sk, cmd, arg);
319 release_sock(sk);
320 return err;
321 }
322}
323
324static int hci_sock_bind(struct socket *sock, struct sockaddr *addr, int addr_len)
325{
Johan Hedberg03811012010-12-08 00:21:06 +0200326 struct sockaddr_hci haddr;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700327 struct sock *sk = sock->sk;
328 struct hci_dev *hdev = NULL;
Johan Hedberg03811012010-12-08 00:21:06 +0200329 int len, err = 0;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700330
331 BT_DBG("sock %p sk %p", sock, sk);
332
Johan Hedberg03811012010-12-08 00:21:06 +0200333 if (!addr)
334 return -EINVAL;
335
336 memset(&haddr, 0, sizeof(haddr));
337 len = min_t(unsigned int, sizeof(haddr), addr_len);
338 memcpy(&haddr, addr, len);
339
340 if (haddr.hci_family != AF_BLUETOOTH)
341 return -EINVAL;
342
Gustavo F. Padovan17f9cc32010-12-22 23:00:34 -0200343 if (haddr.hci_channel > HCI_CHANNEL_CONTROL)
344 return -EINVAL;
345
346 if (haddr.hci_channel == HCI_CHANNEL_CONTROL && !enable_mgmt)
Linus Torvalds1da177e2005-04-16 15:20:36 -0700347 return -EINVAL;
348
349 lock_sock(sk);
350
Johan Hedberg03811012010-12-08 00:21:06 +0200351 if (sk->sk_state == BT_BOUND || hci_pi(sk)->hdev) {
Linus Torvalds1da177e2005-04-16 15:20:36 -0700352 err = -EALREADY;
353 goto done;
354 }
355
Johan Hedberg03811012010-12-08 00:21:06 +0200356 if (haddr.hci_dev != HCI_DEV_NONE) {
357 hdev = hci_dev_get(haddr.hci_dev);
Andrei Emeltchenko70f230202010-12-01 16:58:25 +0200358 if (!hdev) {
Linus Torvalds1da177e2005-04-16 15:20:36 -0700359 err = -ENODEV;
360 goto done;
361 }
362
363 atomic_inc(&hdev->promisc);
364 }
365
Johan Hedberg03811012010-12-08 00:21:06 +0200366 hci_pi(sk)->channel = haddr.hci_channel;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700367 hci_pi(sk)->hdev = hdev;
368 sk->sk_state = BT_BOUND;
369
370done:
371 release_sock(sk);
372 return err;
373}
374
375static int hci_sock_getname(struct socket *sock, struct sockaddr *addr, int *addr_len, int peer)
376{
377 struct sockaddr_hci *haddr = (struct sockaddr_hci *) addr;
378 struct sock *sk = sock->sk;
Marcel Holtmann7b005bd2006-02-13 11:40:03 +0100379 struct hci_dev *hdev = hci_pi(sk)->hdev;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700380
381 BT_DBG("sock %p sk %p", sock, sk);
382
Marcel Holtmann7b005bd2006-02-13 11:40:03 +0100383 if (!hdev)
384 return -EBADFD;
385
Linus Torvalds1da177e2005-04-16 15:20:36 -0700386 lock_sock(sk);
387
388 *addr_len = sizeof(*haddr);
389 haddr->hci_family = AF_BLUETOOTH;
Marcel Holtmann7b005bd2006-02-13 11:40:03 +0100390 haddr->hci_dev = hdev->id;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700391
392 release_sock(sk);
393 return 0;
394}
395
396static inline void hci_sock_cmsg(struct sock *sk, struct msghdr *msg, struct sk_buff *skb)
397{
398 __u32 mask = hci_pi(sk)->cmsg_mask;
399
Marcel Holtmann0d48d932005-08-09 20:30:28 -0700400 if (mask & HCI_CMSG_DIR) {
401 int incoming = bt_cb(skb)->incoming;
402 put_cmsg(msg, SOL_HCI, HCI_CMSG_DIR, sizeof(incoming), &incoming);
403 }
Linus Torvalds1da177e2005-04-16 15:20:36 -0700404
Patrick McHardya61bbcf2005-08-14 17:24:31 -0700405 if (mask & HCI_CMSG_TSTAMP) {
Johann Felix Sodenf6e623a2010-02-15 22:23:48 +0100406#ifdef CONFIG_COMPAT
407 struct compat_timeval ctv;
408#endif
Patrick McHardya61bbcf2005-08-14 17:24:31 -0700409 struct timeval tv;
Marcel Holtmann767c5eb2007-09-09 08:39:34 +0200410 void *data;
411 int len;
Patrick McHardya61bbcf2005-08-14 17:24:31 -0700412
413 skb_get_timestamp(skb, &tv);
Marcel Holtmann767c5eb2007-09-09 08:39:34 +0200414
David S. Miller1da97f82007-09-12 14:10:58 +0200415 data = &tv;
416 len = sizeof(tv);
417#ifdef CONFIG_COMPAT
Marcel Holtmann767c5eb2007-09-09 08:39:34 +0200418 if (msg->msg_flags & MSG_CMSG_COMPAT) {
Marcel Holtmann767c5eb2007-09-09 08:39:34 +0200419 ctv.tv_sec = tv.tv_sec;
420 ctv.tv_usec = tv.tv_usec;
421 data = &ctv;
422 len = sizeof(ctv);
Marcel Holtmann767c5eb2007-09-09 08:39:34 +0200423 }
David S. Miller1da97f82007-09-12 14:10:58 +0200424#endif
Marcel Holtmann767c5eb2007-09-09 08:39:34 +0200425
426 put_cmsg(msg, SOL_HCI, HCI_CMSG_TSTAMP, len, data);
Patrick McHardya61bbcf2005-08-14 17:24:31 -0700427 }
Linus Torvalds1da177e2005-04-16 15:20:36 -0700428}
YOSHIFUJI Hideaki8e87d142007-02-09 23:24:33 +0900429
430static int hci_sock_recvmsg(struct kiocb *iocb, struct socket *sock,
Linus Torvalds1da177e2005-04-16 15:20:36 -0700431 struct msghdr *msg, size_t len, int flags)
432{
433 int noblock = flags & MSG_DONTWAIT;
434 struct sock *sk = sock->sk;
435 struct sk_buff *skb;
436 int copied, err;
437
438 BT_DBG("sock %p, sk %p", sock, sk);
439
440 if (flags & (MSG_OOB))
441 return -EOPNOTSUPP;
442
443 if (sk->sk_state == BT_CLOSED)
444 return 0;
445
Andrei Emeltchenko70f230202010-12-01 16:58:25 +0200446 skb = skb_recv_datagram(sk, flags, noblock, &err);
447 if (!skb)
Linus Torvalds1da177e2005-04-16 15:20:36 -0700448 return err;
449
450 msg->msg_namelen = 0;
451
452 copied = skb->len;
453 if (len < copied) {
454 msg->msg_flags |= MSG_TRUNC;
455 copied = len;
456 }
457
Arnaldo Carvalho de Melobadff6d2007-03-13 13:06:52 -0300458 skb_reset_transport_header(skb);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700459 err = skb_copy_datagram_iovec(skb, 0, msg->msg_iov, copied);
460
461 hci_sock_cmsg(sk, msg, skb);
462
463 skb_free_datagram(sk, skb);
464
465 return err ? : copied;
466}
467
YOSHIFUJI Hideaki8e87d142007-02-09 23:24:33 +0900468static int hci_sock_sendmsg(struct kiocb *iocb, struct socket *sock,
Linus Torvalds1da177e2005-04-16 15:20:36 -0700469 struct msghdr *msg, size_t len)
470{
471 struct sock *sk = sock->sk;
472 struct hci_dev *hdev;
473 struct sk_buff *skb;
474 int err;
475
476 BT_DBG("sock %p sk %p", sock, sk);
477
478 if (msg->msg_flags & MSG_OOB)
479 return -EOPNOTSUPP;
480
481 if (msg->msg_flags & ~(MSG_DONTWAIT|MSG_NOSIGNAL|MSG_ERRQUEUE))
482 return -EINVAL;
483
484 if (len < 4 || len > HCI_MAX_FRAME_SIZE)
485 return -EINVAL;
486
487 lock_sock(sk);
488
Johan Hedberg03811012010-12-08 00:21:06 +0200489 switch (hci_pi(sk)->channel) {
490 case HCI_CHANNEL_RAW:
491 break;
492 case HCI_CHANNEL_CONTROL:
493 err = mgmt_control(sk, msg, len);
494 goto done;
495 default:
496 err = -EINVAL;
497 goto done;
498 }
499
Andrei Emeltchenko70f230202010-12-01 16:58:25 +0200500 hdev = hci_pi(sk)->hdev;
501 if (!hdev) {
Linus Torvalds1da177e2005-04-16 15:20:36 -0700502 err = -EBADFD;
503 goto done;
504 }
505
Marcel Holtmann7e21add2009-11-18 01:05:00 +0100506 if (!test_bit(HCI_UP, &hdev->flags)) {
507 err = -ENETDOWN;
508 goto done;
509 }
510
Andrei Emeltchenko70f230202010-12-01 16:58:25 +0200511 skb = bt_skb_send_alloc(sk, len, msg->msg_flags & MSG_DONTWAIT, &err);
512 if (!skb)
Linus Torvalds1da177e2005-04-16 15:20:36 -0700513 goto done;
514
515 if (memcpy_fromiovec(skb_put(skb, len), msg->msg_iov, len)) {
516 err = -EFAULT;
517 goto drop;
518 }
519
Marcel Holtmann0d48d932005-08-09 20:30:28 -0700520 bt_cb(skb)->pkt_type = *((unsigned char *) skb->data);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700521 skb_pull(skb, 1);
522 skb->dev = (void *) hdev;
523
Marcel Holtmann0d48d932005-08-09 20:30:28 -0700524 if (bt_cb(skb)->pkt_type == HCI_COMMAND_PKT) {
Harvey Harrison83985312008-05-02 16:25:46 -0700525 u16 opcode = get_unaligned_le16(skb->data);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700526 u16 ogf = hci_opcode_ogf(opcode);
527 u16 ocf = hci_opcode_ocf(opcode);
528
529 if (((ogf > HCI_SFLT_MAX_OGF) ||
530 !hci_test_bit(ocf & HCI_FLT_OCF_BITS, &hci_sec_filter.ocf_mask[ogf])) &&
531 !capable(CAP_NET_RAW)) {
532 err = -EPERM;
533 goto drop;
534 }
535
Marcel Holtmanna9de9242007-10-20 13:33:56 +0200536 if (test_bit(HCI_RAW, &hdev->flags) || (ogf == 0x3f)) {
Linus Torvalds1da177e2005-04-16 15:20:36 -0700537 skb_queue_tail(&hdev->raw_q, skb);
Marcel Holtmannc78ae282009-11-18 01:02:54 +0100538 tasklet_schedule(&hdev->tx_task);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700539 } else {
540 skb_queue_tail(&hdev->cmd_q, skb);
Marcel Holtmannc78ae282009-11-18 01:02:54 +0100541 tasklet_schedule(&hdev->cmd_task);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700542 }
543 } else {
544 if (!capable(CAP_NET_RAW)) {
545 err = -EPERM;
546 goto drop;
547 }
548
549 skb_queue_tail(&hdev->raw_q, skb);
Marcel Holtmannc78ae282009-11-18 01:02:54 +0100550 tasklet_schedule(&hdev->tx_task);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700551 }
552
553 err = len;
554
555done:
556 release_sock(sk);
557 return err;
558
559drop:
560 kfree_skb(skb);
561 goto done;
562}
563
David S. Millerb7058842009-09-30 16:12:20 -0700564static int hci_sock_setsockopt(struct socket *sock, int level, int optname, char __user *optval, unsigned int len)
Linus Torvalds1da177e2005-04-16 15:20:36 -0700565{
566 struct hci_ufilter uf = { .opcode = 0 };
567 struct sock *sk = sock->sk;
568 int err = 0, opt = 0;
569
570 BT_DBG("sk %p, opt %d", sk, optname);
571
572 lock_sock(sk);
573
574 switch (optname) {
575 case HCI_DATA_DIR:
576 if (get_user(opt, (int __user *)optval)) {
577 err = -EFAULT;
578 break;
579 }
580
581 if (opt)
582 hci_pi(sk)->cmsg_mask |= HCI_CMSG_DIR;
583 else
584 hci_pi(sk)->cmsg_mask &= ~HCI_CMSG_DIR;
585 break;
586
587 case HCI_TIME_STAMP:
588 if (get_user(opt, (int __user *)optval)) {
589 err = -EFAULT;
590 break;
591 }
592
593 if (opt)
594 hci_pi(sk)->cmsg_mask |= HCI_CMSG_TSTAMP;
595 else
596 hci_pi(sk)->cmsg_mask &= ~HCI_CMSG_TSTAMP;
597 break;
598
599 case HCI_FILTER:
Marcel Holtmann0878b662007-05-05 00:35:59 +0200600 {
601 struct hci_filter *f = &hci_pi(sk)->filter;
602
603 uf.type_mask = f->type_mask;
604 uf.opcode = f->opcode;
605 uf.event_mask[0] = *((u32 *) f->event_mask + 0);
606 uf.event_mask[1] = *((u32 *) f->event_mask + 1);
607 }
608
Linus Torvalds1da177e2005-04-16 15:20:36 -0700609 len = min_t(unsigned int, len, sizeof(uf));
610 if (copy_from_user(&uf, optval, len)) {
611 err = -EFAULT;
612 break;
613 }
614
615 if (!capable(CAP_NET_RAW)) {
616 uf.type_mask &= hci_sec_filter.type_mask;
617 uf.event_mask[0] &= *((u32 *) hci_sec_filter.event_mask + 0);
618 uf.event_mask[1] &= *((u32 *) hci_sec_filter.event_mask + 1);
619 }
620
621 {
622 struct hci_filter *f = &hci_pi(sk)->filter;
623
624 f->type_mask = uf.type_mask;
625 f->opcode = uf.opcode;
626 *((u32 *) f->event_mask + 0) = uf.event_mask[0];
627 *((u32 *) f->event_mask + 1) = uf.event_mask[1];
628 }
YOSHIFUJI Hideaki8e87d142007-02-09 23:24:33 +0900629 break;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700630
631 default:
632 err = -ENOPROTOOPT;
633 break;
634 }
635
636 release_sock(sk);
637 return err;
638}
639
640static int hci_sock_getsockopt(struct socket *sock, int level, int optname, char __user *optval, int __user *optlen)
641{
642 struct hci_ufilter uf;
643 struct sock *sk = sock->sk;
YOSHIFUJI Hideaki8e87d142007-02-09 23:24:33 +0900644 int len, opt;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700645
646 if (get_user(len, optlen))
647 return -EFAULT;
648
649 switch (optname) {
650 case HCI_DATA_DIR:
651 if (hci_pi(sk)->cmsg_mask & HCI_CMSG_DIR)
652 opt = 1;
YOSHIFUJI Hideaki8e87d142007-02-09 23:24:33 +0900653 else
Linus Torvalds1da177e2005-04-16 15:20:36 -0700654 opt = 0;
655
656 if (put_user(opt, optval))
657 return -EFAULT;
658 break;
659
660 case HCI_TIME_STAMP:
661 if (hci_pi(sk)->cmsg_mask & HCI_CMSG_TSTAMP)
662 opt = 1;
YOSHIFUJI Hideaki8e87d142007-02-09 23:24:33 +0900663 else
Linus Torvalds1da177e2005-04-16 15:20:36 -0700664 opt = 0;
665
666 if (put_user(opt, optval))
667 return -EFAULT;
668 break;
669
670 case HCI_FILTER:
671 {
672 struct hci_filter *f = &hci_pi(sk)->filter;
673
674 uf.type_mask = f->type_mask;
675 uf.opcode = f->opcode;
676 uf.event_mask[0] = *((u32 *) f->event_mask + 0);
677 uf.event_mask[1] = *((u32 *) f->event_mask + 1);
678 }
679
680 len = min_t(unsigned int, len, sizeof(uf));
681 if (copy_to_user(optval, &uf, len))
682 return -EFAULT;
683 break;
684
685 default:
686 return -ENOPROTOOPT;
687 break;
688 }
689
690 return 0;
691}
692
Eric Dumazet90ddc4f2005-12-22 12:49:22 -0800693static const struct proto_ops hci_sock_ops = {
Linus Torvalds1da177e2005-04-16 15:20:36 -0700694 .family = PF_BLUETOOTH,
695 .owner = THIS_MODULE,
696 .release = hci_sock_release,
697 .bind = hci_sock_bind,
698 .getname = hci_sock_getname,
699 .sendmsg = hci_sock_sendmsg,
700 .recvmsg = hci_sock_recvmsg,
701 .ioctl = hci_sock_ioctl,
702 .poll = datagram_poll,
703 .listen = sock_no_listen,
704 .shutdown = sock_no_shutdown,
705 .setsockopt = hci_sock_setsockopt,
706 .getsockopt = hci_sock_getsockopt,
707 .connect = sock_no_connect,
708 .socketpair = sock_no_socketpair,
709 .accept = sock_no_accept,
710 .mmap = sock_no_mmap
711};
712
713static struct proto hci_sk_proto = {
714 .name = "HCI",
715 .owner = THIS_MODULE,
716 .obj_size = sizeof(struct hci_pinfo)
717};
718
Eric Paris3f378b62009-11-05 22:18:14 -0800719static int hci_sock_create(struct net *net, struct socket *sock, int protocol,
720 int kern)
Linus Torvalds1da177e2005-04-16 15:20:36 -0700721{
722 struct sock *sk;
723
724 BT_DBG("sock %p", sock);
725
726 if (sock->type != SOCK_RAW)
727 return -ESOCKTNOSUPPORT;
728
729 sock->ops = &hci_sock_ops;
730
Pavel Emelyanov6257ff22007-11-01 00:39:31 -0700731 sk = sk_alloc(net, PF_BLUETOOTH, GFP_ATOMIC, &hci_sk_proto);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700732 if (!sk)
733 return -ENOMEM;
734
735 sock_init_data(sock, sk);
736
737 sock_reset_flag(sk, SOCK_ZAPPED);
738
739 sk->sk_protocol = protocol;
740
741 sock->state = SS_UNCONNECTED;
742 sk->sk_state = BT_OPEN;
743
744 bt_sock_link(&hci_sk_list, sk);
745 return 0;
746}
747
748static int hci_sock_dev_event(struct notifier_block *this, unsigned long event, void *ptr)
749{
750 struct hci_dev *hdev = (struct hci_dev *) ptr;
751 struct hci_ev_si_device ev;
752
753 BT_DBG("hdev %s event %ld", hdev->name, event);
754
755 /* Send event to sockets */
756 ev.event = event;
757 ev.dev_id = hdev->id;
758 hci_si_event(NULL, HCI_EV_SI_DEVICE, sizeof(ev), &ev);
759
760 if (event == HCI_DEV_UNREG) {
761 struct sock *sk;
762 struct hlist_node *node;
763
764 /* Detach sockets from device */
765 read_lock(&hci_sk_list.lock);
766 sk_for_each(sk, node, &hci_sk_list.head) {
Satyam Sharma4ce61d12007-05-16 23:50:16 -0700767 local_bh_disable();
768 bh_lock_sock_nested(sk);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700769 if (hci_pi(sk)->hdev == hdev) {
770 hci_pi(sk)->hdev = NULL;
771 sk->sk_err = EPIPE;
772 sk->sk_state = BT_OPEN;
773 sk->sk_state_change(sk);
774
775 hci_dev_put(hdev);
776 }
Satyam Sharma4ce61d12007-05-16 23:50:16 -0700777 bh_unlock_sock(sk);
778 local_bh_enable();
Linus Torvalds1da177e2005-04-16 15:20:36 -0700779 }
780 read_unlock(&hci_sk_list.lock);
781 }
782
783 return NOTIFY_DONE;
784}
785
Stephen Hemmingerec1b4cf2009-10-05 05:58:39 +0000786static const struct net_proto_family hci_sock_family_ops = {
Linus Torvalds1da177e2005-04-16 15:20:36 -0700787 .family = PF_BLUETOOTH,
788 .owner = THIS_MODULE,
789 .create = hci_sock_create,
790};
791
792static struct notifier_block hci_sock_nblock = {
793 .notifier_call = hci_sock_dev_event
794};
795
796int __init hci_sock_init(void)
797{
798 int err;
799
800 err = proto_register(&hci_sk_proto, 0);
801 if (err < 0)
802 return err;
803
804 err = bt_sock_register(BTPROTO_HCI, &hci_sock_family_ops);
805 if (err < 0)
806 goto error;
807
808 hci_register_notifier(&hci_sock_nblock);
809
810 BT_INFO("HCI socket layer initialized");
811
812 return 0;
813
814error:
815 BT_ERR("HCI socket registration failed");
816 proto_unregister(&hci_sk_proto);
817 return err;
818}
819
Anand Gadiyarb7440a142011-02-22 12:43:09 +0530820void hci_sock_cleanup(void)
Linus Torvalds1da177e2005-04-16 15:20:36 -0700821{
822 if (bt_sock_unregister(BTPROTO_HCI) < 0)
823 BT_ERR("HCI socket unregistration failed");
824
825 hci_unregister_notifier(&hci_sock_nblock);
826
827 proto_unregister(&hci_sk_proto);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700828}
Johan Hedberg03811012010-12-08 00:21:06 +0200829
830module_param(enable_mgmt, bool, 0644);
831MODULE_PARM_DESC(enable_mgmt, "Enable Management interface");