Loading...
1/*
2 RFCOMM implementation for Linux Bluetooth stack (BlueZ).
3 Copyright (C) 2002 Maxim Krasnyansky <maxk@qualcomm.com>
4 Copyright (C) 2002 Marcel Holtmann <marcel@holtmann.org>
5
6 This program is free software; you can redistribute it and/or modify
7 it under the terms of the GNU General Public License version 2 as
8 published by the Free Software Foundation;
9
10 THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS
11 OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
12 FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT OF THIRD PARTY RIGHTS.
13 IN NO EVENT SHALL THE COPYRIGHT HOLDER(S) AND AUTHOR(S) BE LIABLE FOR ANY
14 CLAIM, OR ANY SPECIAL INDIRECT OR CONSEQUENTIAL DAMAGES, OR ANY DAMAGES
15 WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
16 ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
17 OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
18
19 ALL LIABILITY, INCLUDING LIABILITY FOR INFRINGEMENT OF ANY PATENTS,
20 COPYRIGHTS, TRADEMARKS OR OTHER RIGHTS, RELATING TO USE OF THIS
21 SOFTWARE IS DISCLAIMED.
22*/
23
24/*
25 * RFCOMM sockets.
26 */
27#include <linux/compat.h>
28#include <linux/export.h>
29#include <linux/debugfs.h>
30#include <linux/sched/signal.h>
31
32#include <net/bluetooth/bluetooth.h>
33#include <net/bluetooth/hci_core.h>
34#include <net/bluetooth/l2cap.h>
35#include <net/bluetooth/rfcomm.h>
36
37static const struct proto_ops rfcomm_sock_ops;
38
39static struct bt_sock_list rfcomm_sk_list = {
40 .lock = __RW_LOCK_UNLOCKED(rfcomm_sk_list.lock)
41};
42
43static void rfcomm_sock_close(struct sock *sk);
44static void rfcomm_sock_kill(struct sock *sk);
45
46/* ---- DLC callbacks ----
47 *
48 * called under rfcomm_dlc_lock()
49 */
50static void rfcomm_sk_data_ready(struct rfcomm_dlc *d, struct sk_buff *skb)
51{
52 struct sock *sk = d->owner;
53 if (!sk)
54 return;
55
56 atomic_add(skb->len, &sk->sk_rmem_alloc);
57 skb_queue_tail(&sk->sk_receive_queue, skb);
58 sk->sk_data_ready(sk);
59
60 if (atomic_read(&sk->sk_rmem_alloc) >= sk->sk_rcvbuf)
61 rfcomm_dlc_throttle(d);
62}
63
64static void rfcomm_sk_state_change(struct rfcomm_dlc *d, int err)
65{
66 struct sock *sk = d->owner, *parent;
67
68 if (!sk)
69 return;
70
71 BT_DBG("dlc %p state %ld err %d", d, d->state, err);
72
73 lock_sock(sk);
74
75 if (err)
76 sk->sk_err = err;
77
78 sk->sk_state = d->state;
79
80 parent = bt_sk(sk)->parent;
81 if (parent) {
82 if (d->state == BT_CLOSED) {
83 sock_set_flag(sk, SOCK_ZAPPED);
84 bt_accept_unlink(sk);
85 }
86 parent->sk_data_ready(parent);
87 } else {
88 if (d->state == BT_CONNECTED)
89 rfcomm_session_getaddr(d->session,
90 &rfcomm_pi(sk)->src, NULL);
91 sk->sk_state_change(sk);
92 }
93
94 release_sock(sk);
95
96 if (parent && sock_flag(sk, SOCK_ZAPPED)) {
97 /* We have to drop DLC lock here, otherwise
98 * rfcomm_sock_destruct() will dead lock. */
99 rfcomm_dlc_unlock(d);
100 rfcomm_sock_kill(sk);
101 rfcomm_dlc_lock(d);
102 }
103}
104
105/* ---- Socket functions ---- */
106static struct sock *__rfcomm_get_listen_sock_by_addr(u8 channel, bdaddr_t *src)
107{
108 struct sock *sk = NULL;
109
110 sk_for_each(sk, &rfcomm_sk_list.head) {
111 if (rfcomm_pi(sk)->channel != channel)
112 continue;
113
114 if (bacmp(&rfcomm_pi(sk)->src, src))
115 continue;
116
117 if (sk->sk_state == BT_BOUND || sk->sk_state == BT_LISTEN)
118 break;
119 }
120
121 return sk ? sk : NULL;
122}
123
124/* Find socket with channel and source bdaddr.
125 * Returns closest match.
126 */
127static struct sock *rfcomm_get_sock_by_channel(int state, u8 channel, bdaddr_t *src)
128{
129 struct sock *sk = NULL, *sk1 = NULL;
130
131 read_lock(&rfcomm_sk_list.lock);
132
133 sk_for_each(sk, &rfcomm_sk_list.head) {
134 if (state && sk->sk_state != state)
135 continue;
136
137 if (rfcomm_pi(sk)->channel == channel) {
138 /* Exact match. */
139 if (!bacmp(&rfcomm_pi(sk)->src, src))
140 break;
141
142 /* Closest match */
143 if (!bacmp(&rfcomm_pi(sk)->src, BDADDR_ANY))
144 sk1 = sk;
145 }
146 }
147
148 read_unlock(&rfcomm_sk_list.lock);
149
150 return sk ? sk : sk1;
151}
152
153static void rfcomm_sock_destruct(struct sock *sk)
154{
155 struct rfcomm_dlc *d = rfcomm_pi(sk)->dlc;
156
157 BT_DBG("sk %p dlc %p", sk, d);
158
159 skb_queue_purge(&sk->sk_receive_queue);
160 skb_queue_purge(&sk->sk_write_queue);
161
162 rfcomm_dlc_lock(d);
163 rfcomm_pi(sk)->dlc = NULL;
164
165 /* Detach DLC if it's owned by this socket */
166 if (d->owner == sk)
167 d->owner = NULL;
168 rfcomm_dlc_unlock(d);
169
170 rfcomm_dlc_put(d);
171}
172
173static void rfcomm_sock_cleanup_listen(struct sock *parent)
174{
175 struct sock *sk;
176
177 BT_DBG("parent %p", parent);
178
179 /* Close not yet accepted dlcs */
180 while ((sk = bt_accept_dequeue(parent, NULL))) {
181 rfcomm_sock_close(sk);
182 rfcomm_sock_kill(sk);
183 }
184
185 parent->sk_state = BT_CLOSED;
186 sock_set_flag(parent, SOCK_ZAPPED);
187}
188
189/* Kill socket (only if zapped and orphan)
190 * Must be called on unlocked socket.
191 */
192static void rfcomm_sock_kill(struct sock *sk)
193{
194 if (!sock_flag(sk, SOCK_ZAPPED) || sk->sk_socket)
195 return;
196
197 BT_DBG("sk %p state %d refcnt %d", sk, sk->sk_state, refcount_read(&sk->sk_refcnt));
198
199 /* Kill poor orphan */
200 bt_sock_unlink(&rfcomm_sk_list, sk);
201 sock_set_flag(sk, SOCK_DEAD);
202 sock_put(sk);
203}
204
205static void __rfcomm_sock_close(struct sock *sk)
206{
207 struct rfcomm_dlc *d = rfcomm_pi(sk)->dlc;
208
209 BT_DBG("sk %p state %d socket %p", sk, sk->sk_state, sk->sk_socket);
210
211 switch (sk->sk_state) {
212 case BT_LISTEN:
213 rfcomm_sock_cleanup_listen(sk);
214 break;
215
216 case BT_CONNECT:
217 case BT_CONNECT2:
218 case BT_CONFIG:
219 case BT_CONNECTED:
220 rfcomm_dlc_close(d, 0);
221 fallthrough;
222
223 default:
224 sock_set_flag(sk, SOCK_ZAPPED);
225 break;
226 }
227}
228
229/* Close socket.
230 * Must be called on unlocked socket.
231 */
232static void rfcomm_sock_close(struct sock *sk)
233{
234 lock_sock(sk);
235 __rfcomm_sock_close(sk);
236 release_sock(sk);
237}
238
239static void rfcomm_sock_init(struct sock *sk, struct sock *parent)
240{
241 struct rfcomm_pinfo *pi = rfcomm_pi(sk);
242
243 BT_DBG("sk %p", sk);
244
245 if (parent) {
246 sk->sk_type = parent->sk_type;
247 pi->dlc->defer_setup = test_bit(BT_SK_DEFER_SETUP,
248 &bt_sk(parent)->flags);
249
250 pi->sec_level = rfcomm_pi(parent)->sec_level;
251 pi->role_switch = rfcomm_pi(parent)->role_switch;
252
253 security_sk_clone(parent, sk);
254 } else {
255 pi->dlc->defer_setup = 0;
256
257 pi->sec_level = BT_SECURITY_LOW;
258 pi->role_switch = 0;
259 }
260
261 pi->dlc->sec_level = pi->sec_level;
262 pi->dlc->role_switch = pi->role_switch;
263}
264
265static struct proto rfcomm_proto = {
266 .name = "RFCOMM",
267 .owner = THIS_MODULE,
268 .obj_size = sizeof(struct rfcomm_pinfo)
269};
270
271static struct sock *rfcomm_sock_alloc(struct net *net, struct socket *sock,
272 int proto, gfp_t prio, int kern)
273{
274 struct rfcomm_dlc *d;
275 struct sock *sk;
276
277 sk = bt_sock_alloc(net, sock, &rfcomm_proto, proto, prio, kern);
278 if (!sk)
279 return NULL;
280
281 d = rfcomm_dlc_alloc(prio);
282 if (!d) {
283 sk_free(sk);
284 return NULL;
285 }
286
287 d->data_ready = rfcomm_sk_data_ready;
288 d->state_change = rfcomm_sk_state_change;
289
290 rfcomm_pi(sk)->dlc = d;
291 d->owner = sk;
292
293 sk->sk_destruct = rfcomm_sock_destruct;
294 sk->sk_sndtimeo = RFCOMM_CONN_TIMEOUT;
295
296 sk->sk_sndbuf = RFCOMM_MAX_CREDITS * RFCOMM_DEFAULT_MTU * 10;
297 sk->sk_rcvbuf = RFCOMM_MAX_CREDITS * RFCOMM_DEFAULT_MTU * 10;
298
299 bt_sock_link(&rfcomm_sk_list, sk);
300
301 BT_DBG("sk %p", sk);
302 return sk;
303}
304
305static int rfcomm_sock_create(struct net *net, struct socket *sock,
306 int protocol, int kern)
307{
308 struct sock *sk;
309
310 BT_DBG("sock %p", sock);
311
312 sock->state = SS_UNCONNECTED;
313
314 if (sock->type != SOCK_STREAM && sock->type != SOCK_RAW)
315 return -ESOCKTNOSUPPORT;
316
317 sock->ops = &rfcomm_sock_ops;
318
319 sk = rfcomm_sock_alloc(net, sock, protocol, GFP_ATOMIC, kern);
320 if (!sk)
321 return -ENOMEM;
322
323 rfcomm_sock_init(sk, NULL);
324 return 0;
325}
326
327static int rfcomm_sock_bind(struct socket *sock, struct sockaddr *addr, int addr_len)
328{
329 struct sockaddr_rc sa;
330 struct sock *sk = sock->sk;
331 int len, err = 0;
332
333 if (!addr || addr_len < offsetofend(struct sockaddr, sa_family) ||
334 addr->sa_family != AF_BLUETOOTH)
335 return -EINVAL;
336
337 memset(&sa, 0, sizeof(sa));
338 len = min_t(unsigned int, sizeof(sa), addr_len);
339 memcpy(&sa, addr, len);
340
341 BT_DBG("sk %p %pMR", sk, &sa.rc_bdaddr);
342
343 lock_sock(sk);
344
345 if (sk->sk_state != BT_OPEN) {
346 err = -EBADFD;
347 goto done;
348 }
349
350 if (sk->sk_type != SOCK_STREAM) {
351 err = -EINVAL;
352 goto done;
353 }
354
355 write_lock(&rfcomm_sk_list.lock);
356
357 if (sa.rc_channel &&
358 __rfcomm_get_listen_sock_by_addr(sa.rc_channel, &sa.rc_bdaddr)) {
359 err = -EADDRINUSE;
360 } else {
361 /* Save source address */
362 bacpy(&rfcomm_pi(sk)->src, &sa.rc_bdaddr);
363 rfcomm_pi(sk)->channel = sa.rc_channel;
364 sk->sk_state = BT_BOUND;
365 }
366
367 write_unlock(&rfcomm_sk_list.lock);
368
369done:
370 release_sock(sk);
371 return err;
372}
373
374static int rfcomm_sock_connect(struct socket *sock, struct sockaddr *addr, int alen, int flags)
375{
376 struct sockaddr_rc *sa = (struct sockaddr_rc *) addr;
377 struct sock *sk = sock->sk;
378 struct rfcomm_dlc *d = rfcomm_pi(sk)->dlc;
379 int err = 0;
380
381 BT_DBG("sk %p", sk);
382
383 if (alen < sizeof(struct sockaddr_rc) ||
384 addr->sa_family != AF_BLUETOOTH)
385 return -EINVAL;
386
387 sock_hold(sk);
388 lock_sock(sk);
389
390 if (sk->sk_state != BT_OPEN && sk->sk_state != BT_BOUND) {
391 err = -EBADFD;
392 goto done;
393 }
394
395 if (sk->sk_type != SOCK_STREAM) {
396 err = -EINVAL;
397 goto done;
398 }
399
400 sk->sk_state = BT_CONNECT;
401 bacpy(&rfcomm_pi(sk)->dst, &sa->rc_bdaddr);
402 rfcomm_pi(sk)->channel = sa->rc_channel;
403
404 d->sec_level = rfcomm_pi(sk)->sec_level;
405 d->role_switch = rfcomm_pi(sk)->role_switch;
406
407 /* Drop sock lock to avoid potential deadlock with the RFCOMM lock */
408 release_sock(sk);
409 err = rfcomm_dlc_open(d, &rfcomm_pi(sk)->src, &sa->rc_bdaddr,
410 sa->rc_channel);
411 lock_sock(sk);
412 if (!err && !sock_flag(sk, SOCK_ZAPPED))
413 err = bt_sock_wait_state(sk, BT_CONNECTED,
414 sock_sndtimeo(sk, flags & O_NONBLOCK));
415
416done:
417 release_sock(sk);
418 sock_put(sk);
419 return err;
420}
421
422static int rfcomm_sock_listen(struct socket *sock, int backlog)
423{
424 struct sock *sk = sock->sk;
425 int err = 0;
426
427 BT_DBG("sk %p backlog %d", sk, backlog);
428
429 lock_sock(sk);
430
431 if (sk->sk_state != BT_BOUND) {
432 err = -EBADFD;
433 goto done;
434 }
435
436 if (sk->sk_type != SOCK_STREAM) {
437 err = -EINVAL;
438 goto done;
439 }
440
441 if (!rfcomm_pi(sk)->channel) {
442 bdaddr_t *src = &rfcomm_pi(sk)->src;
443 u8 channel;
444
445 err = -EINVAL;
446
447 write_lock(&rfcomm_sk_list.lock);
448
449 for (channel = 1; channel < 31; channel++)
450 if (!__rfcomm_get_listen_sock_by_addr(channel, src)) {
451 rfcomm_pi(sk)->channel = channel;
452 err = 0;
453 break;
454 }
455
456 write_unlock(&rfcomm_sk_list.lock);
457
458 if (err < 0)
459 goto done;
460 }
461
462 sk->sk_max_ack_backlog = backlog;
463 sk->sk_ack_backlog = 0;
464 sk->sk_state = BT_LISTEN;
465
466done:
467 release_sock(sk);
468 return err;
469}
470
471static int rfcomm_sock_accept(struct socket *sock, struct socket *newsock, int flags,
472 bool kern)
473{
474 DEFINE_WAIT_FUNC(wait, woken_wake_function);
475 struct sock *sk = sock->sk, *nsk;
476 long timeo;
477 int err = 0;
478
479 lock_sock_nested(sk, SINGLE_DEPTH_NESTING);
480
481 if (sk->sk_type != SOCK_STREAM) {
482 err = -EINVAL;
483 goto done;
484 }
485
486 timeo = sock_rcvtimeo(sk, flags & O_NONBLOCK);
487
488 BT_DBG("sk %p timeo %ld", sk, timeo);
489
490 /* Wait for an incoming connection. (wake-one). */
491 add_wait_queue_exclusive(sk_sleep(sk), &wait);
492 while (1) {
493 if (sk->sk_state != BT_LISTEN) {
494 err = -EBADFD;
495 break;
496 }
497
498 nsk = bt_accept_dequeue(sk, newsock);
499 if (nsk)
500 break;
501
502 if (!timeo) {
503 err = -EAGAIN;
504 break;
505 }
506
507 if (signal_pending(current)) {
508 err = sock_intr_errno(timeo);
509 break;
510 }
511
512 release_sock(sk);
513
514 timeo = wait_woken(&wait, TASK_INTERRUPTIBLE, timeo);
515
516 lock_sock_nested(sk, SINGLE_DEPTH_NESTING);
517 }
518 remove_wait_queue(sk_sleep(sk), &wait);
519
520 if (err)
521 goto done;
522
523 newsock->state = SS_CONNECTED;
524
525 BT_DBG("new socket %p", nsk);
526
527done:
528 release_sock(sk);
529 return err;
530}
531
532static int rfcomm_sock_getname(struct socket *sock, struct sockaddr *addr, int peer)
533{
534 struct sockaddr_rc *sa = (struct sockaddr_rc *) addr;
535 struct sock *sk = sock->sk;
536
537 BT_DBG("sock %p, sk %p", sock, sk);
538
539 if (peer && sk->sk_state != BT_CONNECTED &&
540 sk->sk_state != BT_CONNECT && sk->sk_state != BT_CONNECT2)
541 return -ENOTCONN;
542
543 memset(sa, 0, sizeof(*sa));
544 sa->rc_family = AF_BLUETOOTH;
545 sa->rc_channel = rfcomm_pi(sk)->channel;
546 if (peer)
547 bacpy(&sa->rc_bdaddr, &rfcomm_pi(sk)->dst);
548 else
549 bacpy(&sa->rc_bdaddr, &rfcomm_pi(sk)->src);
550
551 return sizeof(struct sockaddr_rc);
552}
553
554static int rfcomm_sock_sendmsg(struct socket *sock, struct msghdr *msg,
555 size_t len)
556{
557 struct sock *sk = sock->sk;
558 struct rfcomm_dlc *d = rfcomm_pi(sk)->dlc;
559 struct sk_buff *skb;
560 int sent;
561
562 if (test_bit(RFCOMM_DEFER_SETUP, &d->flags))
563 return -ENOTCONN;
564
565 if (msg->msg_flags & MSG_OOB)
566 return -EOPNOTSUPP;
567
568 if (sk->sk_shutdown & SEND_SHUTDOWN)
569 return -EPIPE;
570
571 BT_DBG("sock %p, sk %p", sock, sk);
572
573 lock_sock(sk);
574
575 sent = bt_sock_wait_ready(sk, msg->msg_flags);
576
577 release_sock(sk);
578
579 if (sent)
580 return sent;
581
582 skb = bt_skb_sendmmsg(sk, msg, len, d->mtu, RFCOMM_SKB_HEAD_RESERVE,
583 RFCOMM_SKB_TAIL_RESERVE);
584 if (IS_ERR(skb))
585 return PTR_ERR(skb);
586
587 sent = rfcomm_dlc_send(d, skb);
588 if (sent < 0)
589 kfree_skb(skb);
590
591 return sent;
592}
593
594static int rfcomm_sock_recvmsg(struct socket *sock, struct msghdr *msg,
595 size_t size, int flags)
596{
597 struct sock *sk = sock->sk;
598 struct rfcomm_dlc *d = rfcomm_pi(sk)->dlc;
599 int len;
600
601 if (test_and_clear_bit(RFCOMM_DEFER_SETUP, &d->flags)) {
602 rfcomm_dlc_accept(d);
603 return 0;
604 }
605
606 len = bt_sock_stream_recvmsg(sock, msg, size, flags);
607
608 lock_sock(sk);
609 if (!(flags & MSG_PEEK) && len > 0)
610 atomic_sub(len, &sk->sk_rmem_alloc);
611
612 if (atomic_read(&sk->sk_rmem_alloc) <= (sk->sk_rcvbuf >> 2))
613 rfcomm_dlc_unthrottle(rfcomm_pi(sk)->dlc);
614 release_sock(sk);
615
616 return len;
617}
618
619static int rfcomm_sock_setsockopt_old(struct socket *sock, int optname,
620 sockptr_t optval, unsigned int optlen)
621{
622 struct sock *sk = sock->sk;
623 int err = 0;
624 u32 opt;
625
626 BT_DBG("sk %p", sk);
627
628 lock_sock(sk);
629
630 switch (optname) {
631 case RFCOMM_LM:
632 if (copy_from_sockptr(&opt, optval, sizeof(u32))) {
633 err = -EFAULT;
634 break;
635 }
636
637 if (opt & RFCOMM_LM_FIPS) {
638 err = -EINVAL;
639 break;
640 }
641
642 if (opt & RFCOMM_LM_AUTH)
643 rfcomm_pi(sk)->sec_level = BT_SECURITY_LOW;
644 if (opt & RFCOMM_LM_ENCRYPT)
645 rfcomm_pi(sk)->sec_level = BT_SECURITY_MEDIUM;
646 if (opt & RFCOMM_LM_SECURE)
647 rfcomm_pi(sk)->sec_level = BT_SECURITY_HIGH;
648
649 rfcomm_pi(sk)->role_switch = (opt & RFCOMM_LM_MASTER);
650 break;
651
652 default:
653 err = -ENOPROTOOPT;
654 break;
655 }
656
657 release_sock(sk);
658 return err;
659}
660
661static int rfcomm_sock_setsockopt(struct socket *sock, int level, int optname,
662 sockptr_t optval, unsigned int optlen)
663{
664 struct sock *sk = sock->sk;
665 struct bt_security sec;
666 int err = 0;
667 size_t len;
668 u32 opt;
669
670 BT_DBG("sk %p", sk);
671
672 if (level == SOL_RFCOMM)
673 return rfcomm_sock_setsockopt_old(sock, optname, optval, optlen);
674
675 if (level != SOL_BLUETOOTH)
676 return -ENOPROTOOPT;
677
678 lock_sock(sk);
679
680 switch (optname) {
681 case BT_SECURITY:
682 if (sk->sk_type != SOCK_STREAM) {
683 err = -EINVAL;
684 break;
685 }
686
687 sec.level = BT_SECURITY_LOW;
688
689 len = min_t(unsigned int, sizeof(sec), optlen);
690 if (copy_from_sockptr(&sec, optval, len)) {
691 err = -EFAULT;
692 break;
693 }
694
695 if (sec.level > BT_SECURITY_HIGH) {
696 err = -EINVAL;
697 break;
698 }
699
700 rfcomm_pi(sk)->sec_level = sec.level;
701 break;
702
703 case BT_DEFER_SETUP:
704 if (sk->sk_state != BT_BOUND && sk->sk_state != BT_LISTEN) {
705 err = -EINVAL;
706 break;
707 }
708
709 if (copy_from_sockptr(&opt, optval, sizeof(u32))) {
710 err = -EFAULT;
711 break;
712 }
713
714 if (opt)
715 set_bit(BT_SK_DEFER_SETUP, &bt_sk(sk)->flags);
716 else
717 clear_bit(BT_SK_DEFER_SETUP, &bt_sk(sk)->flags);
718
719 break;
720
721 default:
722 err = -ENOPROTOOPT;
723 break;
724 }
725
726 release_sock(sk);
727 return err;
728}
729
730static int rfcomm_sock_getsockopt_old(struct socket *sock, int optname, char __user *optval, int __user *optlen)
731{
732 struct sock *sk = sock->sk;
733 struct sock *l2cap_sk;
734 struct l2cap_conn *conn;
735 struct rfcomm_conninfo cinfo;
736 int len, err = 0;
737 u32 opt;
738
739 BT_DBG("sk %p", sk);
740
741 if (get_user(len, optlen))
742 return -EFAULT;
743
744 lock_sock(sk);
745
746 switch (optname) {
747 case RFCOMM_LM:
748 switch (rfcomm_pi(sk)->sec_level) {
749 case BT_SECURITY_LOW:
750 opt = RFCOMM_LM_AUTH;
751 break;
752 case BT_SECURITY_MEDIUM:
753 opt = RFCOMM_LM_AUTH | RFCOMM_LM_ENCRYPT;
754 break;
755 case BT_SECURITY_HIGH:
756 opt = RFCOMM_LM_AUTH | RFCOMM_LM_ENCRYPT |
757 RFCOMM_LM_SECURE;
758 break;
759 case BT_SECURITY_FIPS:
760 opt = RFCOMM_LM_AUTH | RFCOMM_LM_ENCRYPT |
761 RFCOMM_LM_SECURE | RFCOMM_LM_FIPS;
762 break;
763 default:
764 opt = 0;
765 break;
766 }
767
768 if (rfcomm_pi(sk)->role_switch)
769 opt |= RFCOMM_LM_MASTER;
770
771 if (put_user(opt, (u32 __user *) optval))
772 err = -EFAULT;
773
774 break;
775
776 case RFCOMM_CONNINFO:
777 if (sk->sk_state != BT_CONNECTED &&
778 !rfcomm_pi(sk)->dlc->defer_setup) {
779 err = -ENOTCONN;
780 break;
781 }
782
783 l2cap_sk = rfcomm_pi(sk)->dlc->session->sock->sk;
784 conn = l2cap_pi(l2cap_sk)->chan->conn;
785
786 memset(&cinfo, 0, sizeof(cinfo));
787 cinfo.hci_handle = conn->hcon->handle;
788 memcpy(cinfo.dev_class, conn->hcon->dev_class, 3);
789
790 len = min_t(unsigned int, len, sizeof(cinfo));
791 if (copy_to_user(optval, (char *) &cinfo, len))
792 err = -EFAULT;
793
794 break;
795
796 default:
797 err = -ENOPROTOOPT;
798 break;
799 }
800
801 release_sock(sk);
802 return err;
803}
804
805static int rfcomm_sock_getsockopt(struct socket *sock, int level, int optname, char __user *optval, int __user *optlen)
806{
807 struct sock *sk = sock->sk;
808 struct bt_security sec;
809 int len, err = 0;
810
811 BT_DBG("sk %p", sk);
812
813 if (level == SOL_RFCOMM)
814 return rfcomm_sock_getsockopt_old(sock, optname, optval, optlen);
815
816 if (level != SOL_BLUETOOTH)
817 return -ENOPROTOOPT;
818
819 if (get_user(len, optlen))
820 return -EFAULT;
821
822 lock_sock(sk);
823
824 switch (optname) {
825 case BT_SECURITY:
826 if (sk->sk_type != SOCK_STREAM) {
827 err = -EINVAL;
828 break;
829 }
830
831 sec.level = rfcomm_pi(sk)->sec_level;
832 sec.key_size = 0;
833
834 len = min_t(unsigned int, len, sizeof(sec));
835 if (copy_to_user(optval, (char *) &sec, len))
836 err = -EFAULT;
837
838 break;
839
840 case BT_DEFER_SETUP:
841 if (sk->sk_state != BT_BOUND && sk->sk_state != BT_LISTEN) {
842 err = -EINVAL;
843 break;
844 }
845
846 if (put_user(test_bit(BT_SK_DEFER_SETUP, &bt_sk(sk)->flags),
847 (u32 __user *) optval))
848 err = -EFAULT;
849
850 break;
851
852 default:
853 err = -ENOPROTOOPT;
854 break;
855 }
856
857 release_sock(sk);
858 return err;
859}
860
861static int rfcomm_sock_ioctl(struct socket *sock, unsigned int cmd, unsigned long arg)
862{
863 struct sock *sk __maybe_unused = sock->sk;
864 int err;
865
866 BT_DBG("sk %p cmd %x arg %lx", sk, cmd, arg);
867
868 err = bt_sock_ioctl(sock, cmd, arg);
869
870 if (err == -ENOIOCTLCMD) {
871#ifdef CONFIG_BT_RFCOMM_TTY
872 lock_sock(sk);
873 err = rfcomm_dev_ioctl(sk, cmd, (void __user *) arg);
874 release_sock(sk);
875#else
876 err = -EOPNOTSUPP;
877#endif
878 }
879
880 return err;
881}
882
883#ifdef CONFIG_COMPAT
884static int rfcomm_sock_compat_ioctl(struct socket *sock, unsigned int cmd, unsigned long arg)
885{
886 return rfcomm_sock_ioctl(sock, cmd, (unsigned long)compat_ptr(arg));
887}
888#endif
889
890static int rfcomm_sock_shutdown(struct socket *sock, int how)
891{
892 struct sock *sk = sock->sk;
893 int err = 0;
894
895 BT_DBG("sock %p, sk %p", sock, sk);
896
897 if (!sk)
898 return 0;
899
900 lock_sock(sk);
901 if (!sk->sk_shutdown) {
902 sk->sk_shutdown = SHUTDOWN_MASK;
903
904 release_sock(sk);
905 __rfcomm_sock_close(sk);
906 lock_sock(sk);
907
908 if (sock_flag(sk, SOCK_LINGER) && sk->sk_lingertime &&
909 !(current->flags & PF_EXITING))
910 err = bt_sock_wait_state(sk, BT_CLOSED, sk->sk_lingertime);
911 }
912 release_sock(sk);
913 return err;
914}
915
916static int rfcomm_sock_release(struct socket *sock)
917{
918 struct sock *sk = sock->sk;
919 int err;
920
921 BT_DBG("sock %p, sk %p", sock, sk);
922
923 if (!sk)
924 return 0;
925
926 err = rfcomm_sock_shutdown(sock, 2);
927
928 sock_orphan(sk);
929 rfcomm_sock_kill(sk);
930 return err;
931}
932
933/* ---- RFCOMM core layer callbacks ----
934 *
935 * called under rfcomm_lock()
936 */
937int rfcomm_connect_ind(struct rfcomm_session *s, u8 channel, struct rfcomm_dlc **d)
938{
939 struct sock *sk, *parent;
940 bdaddr_t src, dst;
941 int result = 0;
942
943 BT_DBG("session %p channel %d", s, channel);
944
945 rfcomm_session_getaddr(s, &src, &dst);
946
947 /* Check if we have socket listening on channel */
948 parent = rfcomm_get_sock_by_channel(BT_LISTEN, channel, &src);
949 if (!parent)
950 return 0;
951
952 lock_sock(parent);
953
954 /* Check for backlog size */
955 if (sk_acceptq_is_full(parent)) {
956 BT_DBG("backlog full %d", parent->sk_ack_backlog);
957 goto done;
958 }
959
960 sk = rfcomm_sock_alloc(sock_net(parent), NULL, BTPROTO_RFCOMM, GFP_ATOMIC, 0);
961 if (!sk)
962 goto done;
963
964 bt_sock_reclassify_lock(sk, BTPROTO_RFCOMM);
965
966 rfcomm_sock_init(sk, parent);
967 bacpy(&rfcomm_pi(sk)->src, &src);
968 bacpy(&rfcomm_pi(sk)->dst, &dst);
969 rfcomm_pi(sk)->channel = channel;
970
971 sk->sk_state = BT_CONFIG;
972 bt_accept_enqueue(parent, sk, true);
973
974 /* Accept connection and return socket DLC */
975 *d = rfcomm_pi(sk)->dlc;
976 result = 1;
977
978done:
979 release_sock(parent);
980
981 if (test_bit(BT_SK_DEFER_SETUP, &bt_sk(parent)->flags))
982 parent->sk_state_change(parent);
983
984 return result;
985}
986
987static int rfcomm_sock_debugfs_show(struct seq_file *f, void *p)
988{
989 struct sock *sk;
990
991 read_lock(&rfcomm_sk_list.lock);
992
993 sk_for_each(sk, &rfcomm_sk_list.head) {
994 seq_printf(f, "%pMR %pMR %d %d\n",
995 &rfcomm_pi(sk)->src, &rfcomm_pi(sk)->dst,
996 sk->sk_state, rfcomm_pi(sk)->channel);
997 }
998
999 read_unlock(&rfcomm_sk_list.lock);
1000
1001 return 0;
1002}
1003
1004DEFINE_SHOW_ATTRIBUTE(rfcomm_sock_debugfs);
1005
1006static struct dentry *rfcomm_sock_debugfs;
1007
1008static const struct proto_ops rfcomm_sock_ops = {
1009 .family = PF_BLUETOOTH,
1010 .owner = THIS_MODULE,
1011 .release = rfcomm_sock_release,
1012 .bind = rfcomm_sock_bind,
1013 .connect = rfcomm_sock_connect,
1014 .listen = rfcomm_sock_listen,
1015 .accept = rfcomm_sock_accept,
1016 .getname = rfcomm_sock_getname,
1017 .sendmsg = rfcomm_sock_sendmsg,
1018 .recvmsg = rfcomm_sock_recvmsg,
1019 .shutdown = rfcomm_sock_shutdown,
1020 .setsockopt = rfcomm_sock_setsockopt,
1021 .getsockopt = rfcomm_sock_getsockopt,
1022 .ioctl = rfcomm_sock_ioctl,
1023 .gettstamp = sock_gettstamp,
1024 .poll = bt_sock_poll,
1025 .socketpair = sock_no_socketpair,
1026 .mmap = sock_no_mmap,
1027#ifdef CONFIG_COMPAT
1028 .compat_ioctl = rfcomm_sock_compat_ioctl,
1029#endif
1030};
1031
1032static const struct net_proto_family rfcomm_sock_family_ops = {
1033 .family = PF_BLUETOOTH,
1034 .owner = THIS_MODULE,
1035 .create = rfcomm_sock_create
1036};
1037
1038int __init rfcomm_init_sockets(void)
1039{
1040 int err;
1041
1042 BUILD_BUG_ON(sizeof(struct sockaddr_rc) > sizeof(struct sockaddr));
1043
1044 err = proto_register(&rfcomm_proto, 0);
1045 if (err < 0)
1046 return err;
1047
1048 err = bt_sock_register(BTPROTO_RFCOMM, &rfcomm_sock_family_ops);
1049 if (err < 0) {
1050 BT_ERR("RFCOMM socket layer registration failed");
1051 goto error;
1052 }
1053
1054 err = bt_procfs_init(&init_net, "rfcomm", &rfcomm_sk_list, NULL);
1055 if (err < 0) {
1056 BT_ERR("Failed to create RFCOMM proc file");
1057 bt_sock_unregister(BTPROTO_RFCOMM);
1058 goto error;
1059 }
1060
1061 BT_INFO("RFCOMM socket layer initialized");
1062
1063 if (IS_ERR_OR_NULL(bt_debugfs))
1064 return 0;
1065
1066 rfcomm_sock_debugfs = debugfs_create_file("rfcomm", 0444,
1067 bt_debugfs, NULL,
1068 &rfcomm_sock_debugfs_fops);
1069
1070 return 0;
1071
1072error:
1073 proto_unregister(&rfcomm_proto);
1074 return err;
1075}
1076
1077void __exit rfcomm_cleanup_sockets(void)
1078{
1079 bt_procfs_cleanup(&init_net, "rfcomm");
1080
1081 debugfs_remove(rfcomm_sock_debugfs);
1082
1083 bt_sock_unregister(BTPROTO_RFCOMM);
1084
1085 proto_unregister(&rfcomm_proto);
1086}
1/*
2 RFCOMM implementation for Linux Bluetooth stack (BlueZ).
3 Copyright (C) 2002 Maxim Krasnyansky <maxk@qualcomm.com>
4 Copyright (C) 2002 Marcel Holtmann <marcel@holtmann.org>
5
6 This program is free software; you can redistribute it and/or modify
7 it under the terms of the GNU General Public License version 2 as
8 published by the Free Software Foundation;
9
10 THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS
11 OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
12 FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT OF THIRD PARTY RIGHTS.
13 IN NO EVENT SHALL THE COPYRIGHT HOLDER(S) AND AUTHOR(S) BE LIABLE FOR ANY
14 CLAIM, OR ANY SPECIAL INDIRECT OR CONSEQUENTIAL DAMAGES, OR ANY DAMAGES
15 WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
16 ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
17 OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
18
19 ALL LIABILITY, INCLUDING LIABILITY FOR INFRINGEMENT OF ANY PATENTS,
20 COPYRIGHTS, TRADEMARKS OR OTHER RIGHTS, RELATING TO USE OF THIS
21 SOFTWARE IS DISCLAIMED.
22*/
23
24/*
25 * RFCOMM sockets.
26 */
27
28#include <linux/export.h>
29#include <linux/debugfs.h>
30
31#include <net/bluetooth/bluetooth.h>
32#include <net/bluetooth/hci_core.h>
33#include <net/bluetooth/l2cap.h>
34#include <net/bluetooth/rfcomm.h>
35
36static const struct proto_ops rfcomm_sock_ops;
37
38static struct bt_sock_list rfcomm_sk_list = {
39 .lock = __RW_LOCK_UNLOCKED(rfcomm_sk_list.lock)
40};
41
42static void rfcomm_sock_close(struct sock *sk);
43static void rfcomm_sock_kill(struct sock *sk);
44
45/* ---- DLC callbacks ----
46 *
47 * called under rfcomm_dlc_lock()
48 */
49static void rfcomm_sk_data_ready(struct rfcomm_dlc *d, struct sk_buff *skb)
50{
51 struct sock *sk = d->owner;
52 if (!sk)
53 return;
54
55 atomic_add(skb->len, &sk->sk_rmem_alloc);
56 skb_queue_tail(&sk->sk_receive_queue, skb);
57 sk->sk_data_ready(sk);
58
59 if (atomic_read(&sk->sk_rmem_alloc) >= sk->sk_rcvbuf)
60 rfcomm_dlc_throttle(d);
61}
62
63static void rfcomm_sk_state_change(struct rfcomm_dlc *d, int err)
64{
65 struct sock *sk = d->owner, *parent;
66 unsigned long flags;
67
68 if (!sk)
69 return;
70
71 BT_DBG("dlc %p state %ld err %d", d, d->state, err);
72
73 local_irq_save(flags);
74 bh_lock_sock(sk);
75
76 if (err)
77 sk->sk_err = err;
78
79 sk->sk_state = d->state;
80
81 parent = bt_sk(sk)->parent;
82 if (parent) {
83 if (d->state == BT_CLOSED) {
84 sock_set_flag(sk, SOCK_ZAPPED);
85 bt_accept_unlink(sk);
86 }
87 parent->sk_data_ready(parent);
88 } else {
89 if (d->state == BT_CONNECTED)
90 rfcomm_session_getaddr(d->session,
91 &rfcomm_pi(sk)->src, NULL);
92 sk->sk_state_change(sk);
93 }
94
95 bh_unlock_sock(sk);
96 local_irq_restore(flags);
97
98 if (parent && sock_flag(sk, SOCK_ZAPPED)) {
99 /* We have to drop DLC lock here, otherwise
100 * rfcomm_sock_destruct() will dead lock. */
101 rfcomm_dlc_unlock(d);
102 rfcomm_sock_kill(sk);
103 rfcomm_dlc_lock(d);
104 }
105}
106
107/* ---- Socket functions ---- */
108static struct sock *__rfcomm_get_listen_sock_by_addr(u8 channel, bdaddr_t *src)
109{
110 struct sock *sk = NULL;
111
112 sk_for_each(sk, &rfcomm_sk_list.head) {
113 if (rfcomm_pi(sk)->channel != channel)
114 continue;
115
116 if (bacmp(&rfcomm_pi(sk)->src, src))
117 continue;
118
119 if (sk->sk_state == BT_BOUND || sk->sk_state == BT_LISTEN)
120 break;
121 }
122
123 return sk ? sk : NULL;
124}
125
126/* Find socket with channel and source bdaddr.
127 * Returns closest match.
128 */
129static struct sock *rfcomm_get_sock_by_channel(int state, u8 channel, bdaddr_t *src)
130{
131 struct sock *sk = NULL, *sk1 = NULL;
132
133 read_lock(&rfcomm_sk_list.lock);
134
135 sk_for_each(sk, &rfcomm_sk_list.head) {
136 if (state && sk->sk_state != state)
137 continue;
138
139 if (rfcomm_pi(sk)->channel == channel) {
140 /* Exact match. */
141 if (!bacmp(&rfcomm_pi(sk)->src, src))
142 break;
143
144 /* Closest match */
145 if (!bacmp(&rfcomm_pi(sk)->src, BDADDR_ANY))
146 sk1 = sk;
147 }
148 }
149
150 read_unlock(&rfcomm_sk_list.lock);
151
152 return sk ? sk : sk1;
153}
154
155static void rfcomm_sock_destruct(struct sock *sk)
156{
157 struct rfcomm_dlc *d = rfcomm_pi(sk)->dlc;
158
159 BT_DBG("sk %p dlc %p", sk, d);
160
161 skb_queue_purge(&sk->sk_receive_queue);
162 skb_queue_purge(&sk->sk_write_queue);
163
164 rfcomm_dlc_lock(d);
165 rfcomm_pi(sk)->dlc = NULL;
166
167 /* Detach DLC if it's owned by this socket */
168 if (d->owner == sk)
169 d->owner = NULL;
170 rfcomm_dlc_unlock(d);
171
172 rfcomm_dlc_put(d);
173}
174
175static void rfcomm_sock_cleanup_listen(struct sock *parent)
176{
177 struct sock *sk;
178
179 BT_DBG("parent %p", parent);
180
181 /* Close not yet accepted dlcs */
182 while ((sk = bt_accept_dequeue(parent, NULL))) {
183 rfcomm_sock_close(sk);
184 rfcomm_sock_kill(sk);
185 }
186
187 parent->sk_state = BT_CLOSED;
188 sock_set_flag(parent, SOCK_ZAPPED);
189}
190
191/* Kill socket (only if zapped and orphan)
192 * Must be called on unlocked socket.
193 */
194static void rfcomm_sock_kill(struct sock *sk)
195{
196 if (!sock_flag(sk, SOCK_ZAPPED) || sk->sk_socket)
197 return;
198
199 BT_DBG("sk %p state %d refcnt %d", sk, sk->sk_state, atomic_read(&sk->sk_refcnt));
200
201 /* Kill poor orphan */
202 bt_sock_unlink(&rfcomm_sk_list, sk);
203 sock_set_flag(sk, SOCK_DEAD);
204 sock_put(sk);
205}
206
207static void __rfcomm_sock_close(struct sock *sk)
208{
209 struct rfcomm_dlc *d = rfcomm_pi(sk)->dlc;
210
211 BT_DBG("sk %p state %d socket %p", sk, sk->sk_state, sk->sk_socket);
212
213 switch (sk->sk_state) {
214 case BT_LISTEN:
215 rfcomm_sock_cleanup_listen(sk);
216 break;
217
218 case BT_CONNECT:
219 case BT_CONNECT2:
220 case BT_CONFIG:
221 case BT_CONNECTED:
222 rfcomm_dlc_close(d, 0);
223
224 default:
225 sock_set_flag(sk, SOCK_ZAPPED);
226 break;
227 }
228}
229
230/* Close socket.
231 * Must be called on unlocked socket.
232 */
233static void rfcomm_sock_close(struct sock *sk)
234{
235 lock_sock(sk);
236 __rfcomm_sock_close(sk);
237 release_sock(sk);
238}
239
240static void rfcomm_sock_init(struct sock *sk, struct sock *parent)
241{
242 struct rfcomm_pinfo *pi = rfcomm_pi(sk);
243
244 BT_DBG("sk %p", sk);
245
246 if (parent) {
247 sk->sk_type = parent->sk_type;
248 pi->dlc->defer_setup = test_bit(BT_SK_DEFER_SETUP,
249 &bt_sk(parent)->flags);
250
251 pi->sec_level = rfcomm_pi(parent)->sec_level;
252 pi->role_switch = rfcomm_pi(parent)->role_switch;
253
254 security_sk_clone(parent, sk);
255 } else {
256 pi->dlc->defer_setup = 0;
257
258 pi->sec_level = BT_SECURITY_LOW;
259 pi->role_switch = 0;
260 }
261
262 pi->dlc->sec_level = pi->sec_level;
263 pi->dlc->role_switch = pi->role_switch;
264}
265
266static struct proto rfcomm_proto = {
267 .name = "RFCOMM",
268 .owner = THIS_MODULE,
269 .obj_size = sizeof(struct rfcomm_pinfo)
270};
271
272static struct sock *rfcomm_sock_alloc(struct net *net, struct socket *sock, int proto, gfp_t prio)
273{
274 struct rfcomm_dlc *d;
275 struct sock *sk;
276
277 sk = sk_alloc(net, PF_BLUETOOTH, prio, &rfcomm_proto);
278 if (!sk)
279 return NULL;
280
281 sock_init_data(sock, sk);
282 INIT_LIST_HEAD(&bt_sk(sk)->accept_q);
283
284 d = rfcomm_dlc_alloc(prio);
285 if (!d) {
286 sk_free(sk);
287 return NULL;
288 }
289
290 d->data_ready = rfcomm_sk_data_ready;
291 d->state_change = rfcomm_sk_state_change;
292
293 rfcomm_pi(sk)->dlc = d;
294 d->owner = sk;
295
296 sk->sk_destruct = rfcomm_sock_destruct;
297 sk->sk_sndtimeo = RFCOMM_CONN_TIMEOUT;
298
299 sk->sk_sndbuf = RFCOMM_MAX_CREDITS * RFCOMM_DEFAULT_MTU * 10;
300 sk->sk_rcvbuf = RFCOMM_MAX_CREDITS * RFCOMM_DEFAULT_MTU * 10;
301
302 sock_reset_flag(sk, SOCK_ZAPPED);
303
304 sk->sk_protocol = proto;
305 sk->sk_state = BT_OPEN;
306
307 bt_sock_link(&rfcomm_sk_list, sk);
308
309 BT_DBG("sk %p", sk);
310 return sk;
311}
312
313static int rfcomm_sock_create(struct net *net, struct socket *sock,
314 int protocol, int kern)
315{
316 struct sock *sk;
317
318 BT_DBG("sock %p", sock);
319
320 sock->state = SS_UNCONNECTED;
321
322 if (sock->type != SOCK_STREAM && sock->type != SOCK_RAW)
323 return -ESOCKTNOSUPPORT;
324
325 sock->ops = &rfcomm_sock_ops;
326
327 sk = rfcomm_sock_alloc(net, sock, protocol, GFP_ATOMIC);
328 if (!sk)
329 return -ENOMEM;
330
331 rfcomm_sock_init(sk, NULL);
332 return 0;
333}
334
335static int rfcomm_sock_bind(struct socket *sock, struct sockaddr *addr, int addr_len)
336{
337 struct sockaddr_rc *sa = (struct sockaddr_rc *) addr;
338 struct sock *sk = sock->sk;
339 int chan = sa->rc_channel;
340 int err = 0;
341
342 BT_DBG("sk %p %pMR", sk, &sa->rc_bdaddr);
343
344 if (!addr || addr->sa_family != AF_BLUETOOTH)
345 return -EINVAL;
346
347 lock_sock(sk);
348
349 if (sk->sk_state != BT_OPEN) {
350 err = -EBADFD;
351 goto done;
352 }
353
354 if (sk->sk_type != SOCK_STREAM) {
355 err = -EINVAL;
356 goto done;
357 }
358
359 write_lock(&rfcomm_sk_list.lock);
360
361 if (chan && __rfcomm_get_listen_sock_by_addr(chan, &sa->rc_bdaddr)) {
362 err = -EADDRINUSE;
363 } else {
364 /* Save source address */
365 bacpy(&rfcomm_pi(sk)->src, &sa->rc_bdaddr);
366 rfcomm_pi(sk)->channel = chan;
367 sk->sk_state = BT_BOUND;
368 }
369
370 write_unlock(&rfcomm_sk_list.lock);
371
372done:
373 release_sock(sk);
374 return err;
375}
376
377static int rfcomm_sock_connect(struct socket *sock, struct sockaddr *addr, int alen, int flags)
378{
379 struct sockaddr_rc *sa = (struct sockaddr_rc *) addr;
380 struct sock *sk = sock->sk;
381 struct rfcomm_dlc *d = rfcomm_pi(sk)->dlc;
382 int err = 0;
383
384 BT_DBG("sk %p", sk);
385
386 if (alen < sizeof(struct sockaddr_rc) ||
387 addr->sa_family != AF_BLUETOOTH)
388 return -EINVAL;
389
390 lock_sock(sk);
391
392 if (sk->sk_state != BT_OPEN && sk->sk_state != BT_BOUND) {
393 err = -EBADFD;
394 goto done;
395 }
396
397 if (sk->sk_type != SOCK_STREAM) {
398 err = -EINVAL;
399 goto done;
400 }
401
402 sk->sk_state = BT_CONNECT;
403 bacpy(&rfcomm_pi(sk)->dst, &sa->rc_bdaddr);
404 rfcomm_pi(sk)->channel = sa->rc_channel;
405
406 d->sec_level = rfcomm_pi(sk)->sec_level;
407 d->role_switch = rfcomm_pi(sk)->role_switch;
408
409 err = rfcomm_dlc_open(d, &rfcomm_pi(sk)->src, &sa->rc_bdaddr,
410 sa->rc_channel);
411 if (!err)
412 err = bt_sock_wait_state(sk, BT_CONNECTED,
413 sock_sndtimeo(sk, flags & O_NONBLOCK));
414
415done:
416 release_sock(sk);
417 return err;
418}
419
420static int rfcomm_sock_listen(struct socket *sock, int backlog)
421{
422 struct sock *sk = sock->sk;
423 int err = 0;
424
425 BT_DBG("sk %p backlog %d", sk, backlog);
426
427 lock_sock(sk);
428
429 if (sk->sk_state != BT_BOUND) {
430 err = -EBADFD;
431 goto done;
432 }
433
434 if (sk->sk_type != SOCK_STREAM) {
435 err = -EINVAL;
436 goto done;
437 }
438
439 if (!rfcomm_pi(sk)->channel) {
440 bdaddr_t *src = &rfcomm_pi(sk)->src;
441 u8 channel;
442
443 err = -EINVAL;
444
445 write_lock(&rfcomm_sk_list.lock);
446
447 for (channel = 1; channel < 31; channel++)
448 if (!__rfcomm_get_listen_sock_by_addr(channel, src)) {
449 rfcomm_pi(sk)->channel = channel;
450 err = 0;
451 break;
452 }
453
454 write_unlock(&rfcomm_sk_list.lock);
455
456 if (err < 0)
457 goto done;
458 }
459
460 sk->sk_max_ack_backlog = backlog;
461 sk->sk_ack_backlog = 0;
462 sk->sk_state = BT_LISTEN;
463
464done:
465 release_sock(sk);
466 return err;
467}
468
469static int rfcomm_sock_accept(struct socket *sock, struct socket *newsock, int flags)
470{
471 DECLARE_WAITQUEUE(wait, current);
472 struct sock *sk = sock->sk, *nsk;
473 long timeo;
474 int err = 0;
475
476 lock_sock_nested(sk, SINGLE_DEPTH_NESTING);
477
478 if (sk->sk_type != SOCK_STREAM) {
479 err = -EINVAL;
480 goto done;
481 }
482
483 timeo = sock_rcvtimeo(sk, flags & O_NONBLOCK);
484
485 BT_DBG("sk %p timeo %ld", sk, timeo);
486
487 /* Wait for an incoming connection. (wake-one). */
488 add_wait_queue_exclusive(sk_sleep(sk), &wait);
489 while (1) {
490 set_current_state(TASK_INTERRUPTIBLE);
491
492 if (sk->sk_state != BT_LISTEN) {
493 err = -EBADFD;
494 break;
495 }
496
497 nsk = bt_accept_dequeue(sk, newsock);
498 if (nsk)
499 break;
500
501 if (!timeo) {
502 err = -EAGAIN;
503 break;
504 }
505
506 if (signal_pending(current)) {
507 err = sock_intr_errno(timeo);
508 break;
509 }
510
511 release_sock(sk);
512 timeo = schedule_timeout(timeo);
513 lock_sock_nested(sk, SINGLE_DEPTH_NESTING);
514 }
515 __set_current_state(TASK_RUNNING);
516 remove_wait_queue(sk_sleep(sk), &wait);
517
518 if (err)
519 goto done;
520
521 newsock->state = SS_CONNECTED;
522
523 BT_DBG("new socket %p", nsk);
524
525done:
526 release_sock(sk);
527 return err;
528}
529
530static int rfcomm_sock_getname(struct socket *sock, struct sockaddr *addr, int *len, int peer)
531{
532 struct sockaddr_rc *sa = (struct sockaddr_rc *) addr;
533 struct sock *sk = sock->sk;
534
535 BT_DBG("sock %p, sk %p", sock, sk);
536
537 if (peer && sk->sk_state != BT_CONNECTED &&
538 sk->sk_state != BT_CONNECT && sk->sk_state != BT_CONNECT2)
539 return -ENOTCONN;
540
541 memset(sa, 0, sizeof(*sa));
542 sa->rc_family = AF_BLUETOOTH;
543 sa->rc_channel = rfcomm_pi(sk)->channel;
544 if (peer)
545 bacpy(&sa->rc_bdaddr, &rfcomm_pi(sk)->dst);
546 else
547 bacpy(&sa->rc_bdaddr, &rfcomm_pi(sk)->src);
548
549 *len = sizeof(struct sockaddr_rc);
550 return 0;
551}
552
553static int rfcomm_sock_sendmsg(struct kiocb *iocb, struct socket *sock,
554 struct msghdr *msg, size_t len)
555{
556 struct sock *sk = sock->sk;
557 struct rfcomm_dlc *d = rfcomm_pi(sk)->dlc;
558 struct sk_buff *skb;
559 int sent;
560
561 if (test_bit(RFCOMM_DEFER_SETUP, &d->flags))
562 return -ENOTCONN;
563
564 if (msg->msg_flags & MSG_OOB)
565 return -EOPNOTSUPP;
566
567 if (sk->sk_shutdown & SEND_SHUTDOWN)
568 return -EPIPE;
569
570 BT_DBG("sock %p, sk %p", sock, sk);
571
572 lock_sock(sk);
573
574 sent = bt_sock_wait_ready(sk, msg->msg_flags);
575 if (sent)
576 goto done;
577
578 while (len) {
579 size_t size = min_t(size_t, len, d->mtu);
580 int err;
581
582 skb = sock_alloc_send_skb(sk, size + RFCOMM_SKB_RESERVE,
583 msg->msg_flags & MSG_DONTWAIT, &err);
584 if (!skb) {
585 if (sent == 0)
586 sent = err;
587 break;
588 }
589 skb_reserve(skb, RFCOMM_SKB_HEAD_RESERVE);
590
591 err = memcpy_fromiovec(skb_put(skb, size), msg->msg_iov, size);
592 if (err) {
593 kfree_skb(skb);
594 if (sent == 0)
595 sent = err;
596 break;
597 }
598
599 skb->priority = sk->sk_priority;
600
601 err = rfcomm_dlc_send(d, skb);
602 if (err < 0) {
603 kfree_skb(skb);
604 if (sent == 0)
605 sent = err;
606 break;
607 }
608
609 sent += size;
610 len -= size;
611 }
612
613done:
614 release_sock(sk);
615
616 return sent;
617}
618
619static int rfcomm_sock_recvmsg(struct kiocb *iocb, struct socket *sock,
620 struct msghdr *msg, size_t size, int flags)
621{
622 struct sock *sk = sock->sk;
623 struct rfcomm_dlc *d = rfcomm_pi(sk)->dlc;
624 int len;
625
626 if (test_and_clear_bit(RFCOMM_DEFER_SETUP, &d->flags)) {
627 rfcomm_dlc_accept(d);
628 return 0;
629 }
630
631 len = bt_sock_stream_recvmsg(iocb, sock, msg, size, flags);
632
633 lock_sock(sk);
634 if (!(flags & MSG_PEEK) && len > 0)
635 atomic_sub(len, &sk->sk_rmem_alloc);
636
637 if (atomic_read(&sk->sk_rmem_alloc) <= (sk->sk_rcvbuf >> 2))
638 rfcomm_dlc_unthrottle(rfcomm_pi(sk)->dlc);
639 release_sock(sk);
640
641 return len;
642}
643
644static int rfcomm_sock_setsockopt_old(struct socket *sock, int optname, char __user *optval, unsigned int optlen)
645{
646 struct sock *sk = sock->sk;
647 int err = 0;
648 u32 opt;
649
650 BT_DBG("sk %p", sk);
651
652 lock_sock(sk);
653
654 switch (optname) {
655 case RFCOMM_LM:
656 if (get_user(opt, (u32 __user *) optval)) {
657 err = -EFAULT;
658 break;
659 }
660
661 if (opt & RFCOMM_LM_FIPS) {
662 err = -EINVAL;
663 break;
664 }
665
666 if (opt & RFCOMM_LM_AUTH)
667 rfcomm_pi(sk)->sec_level = BT_SECURITY_LOW;
668 if (opt & RFCOMM_LM_ENCRYPT)
669 rfcomm_pi(sk)->sec_level = BT_SECURITY_MEDIUM;
670 if (opt & RFCOMM_LM_SECURE)
671 rfcomm_pi(sk)->sec_level = BT_SECURITY_HIGH;
672
673 rfcomm_pi(sk)->role_switch = (opt & RFCOMM_LM_MASTER);
674 break;
675
676 default:
677 err = -ENOPROTOOPT;
678 break;
679 }
680
681 release_sock(sk);
682 return err;
683}
684
685static int rfcomm_sock_setsockopt(struct socket *sock, int level, int optname, char __user *optval, unsigned int optlen)
686{
687 struct sock *sk = sock->sk;
688 struct bt_security sec;
689 int err = 0;
690 size_t len;
691 u32 opt;
692
693 BT_DBG("sk %p", sk);
694
695 if (level == SOL_RFCOMM)
696 return rfcomm_sock_setsockopt_old(sock, optname, optval, optlen);
697
698 if (level != SOL_BLUETOOTH)
699 return -ENOPROTOOPT;
700
701 lock_sock(sk);
702
703 switch (optname) {
704 case BT_SECURITY:
705 if (sk->sk_type != SOCK_STREAM) {
706 err = -EINVAL;
707 break;
708 }
709
710 sec.level = BT_SECURITY_LOW;
711
712 len = min_t(unsigned int, sizeof(sec), optlen);
713 if (copy_from_user((char *) &sec, optval, len)) {
714 err = -EFAULT;
715 break;
716 }
717
718 if (sec.level > BT_SECURITY_HIGH) {
719 err = -EINVAL;
720 break;
721 }
722
723 rfcomm_pi(sk)->sec_level = sec.level;
724 break;
725
726 case BT_DEFER_SETUP:
727 if (sk->sk_state != BT_BOUND && sk->sk_state != BT_LISTEN) {
728 err = -EINVAL;
729 break;
730 }
731
732 if (get_user(opt, (u32 __user *) optval)) {
733 err = -EFAULT;
734 break;
735 }
736
737 if (opt)
738 set_bit(BT_SK_DEFER_SETUP, &bt_sk(sk)->flags);
739 else
740 clear_bit(BT_SK_DEFER_SETUP, &bt_sk(sk)->flags);
741
742 break;
743
744 default:
745 err = -ENOPROTOOPT;
746 break;
747 }
748
749 release_sock(sk);
750 return err;
751}
752
753static int rfcomm_sock_getsockopt_old(struct socket *sock, int optname, char __user *optval, int __user *optlen)
754{
755 struct sock *sk = sock->sk;
756 struct sock *l2cap_sk;
757 struct l2cap_conn *conn;
758 struct rfcomm_conninfo cinfo;
759 int len, err = 0;
760 u32 opt;
761
762 BT_DBG("sk %p", sk);
763
764 if (get_user(len, optlen))
765 return -EFAULT;
766
767 lock_sock(sk);
768
769 switch (optname) {
770 case RFCOMM_LM:
771 switch (rfcomm_pi(sk)->sec_level) {
772 case BT_SECURITY_LOW:
773 opt = RFCOMM_LM_AUTH;
774 break;
775 case BT_SECURITY_MEDIUM:
776 opt = RFCOMM_LM_AUTH | RFCOMM_LM_ENCRYPT;
777 break;
778 case BT_SECURITY_HIGH:
779 opt = RFCOMM_LM_AUTH | RFCOMM_LM_ENCRYPT |
780 RFCOMM_LM_SECURE;
781 break;
782 case BT_SECURITY_FIPS:
783 opt = RFCOMM_LM_AUTH | RFCOMM_LM_ENCRYPT |
784 RFCOMM_LM_SECURE | RFCOMM_LM_FIPS;
785 break;
786 default:
787 opt = 0;
788 break;
789 }
790
791 if (rfcomm_pi(sk)->role_switch)
792 opt |= RFCOMM_LM_MASTER;
793
794 if (put_user(opt, (u32 __user *) optval))
795 err = -EFAULT;
796
797 break;
798
799 case RFCOMM_CONNINFO:
800 if (sk->sk_state != BT_CONNECTED &&
801 !rfcomm_pi(sk)->dlc->defer_setup) {
802 err = -ENOTCONN;
803 break;
804 }
805
806 l2cap_sk = rfcomm_pi(sk)->dlc->session->sock->sk;
807 conn = l2cap_pi(l2cap_sk)->chan->conn;
808
809 memset(&cinfo, 0, sizeof(cinfo));
810 cinfo.hci_handle = conn->hcon->handle;
811 memcpy(cinfo.dev_class, conn->hcon->dev_class, 3);
812
813 len = min_t(unsigned int, len, sizeof(cinfo));
814 if (copy_to_user(optval, (char *) &cinfo, len))
815 err = -EFAULT;
816
817 break;
818
819 default:
820 err = -ENOPROTOOPT;
821 break;
822 }
823
824 release_sock(sk);
825 return err;
826}
827
828static int rfcomm_sock_getsockopt(struct socket *sock, int level, int optname, char __user *optval, int __user *optlen)
829{
830 struct sock *sk = sock->sk;
831 struct bt_security sec;
832 int len, err = 0;
833
834 BT_DBG("sk %p", sk);
835
836 if (level == SOL_RFCOMM)
837 return rfcomm_sock_getsockopt_old(sock, optname, optval, optlen);
838
839 if (level != SOL_BLUETOOTH)
840 return -ENOPROTOOPT;
841
842 if (get_user(len, optlen))
843 return -EFAULT;
844
845 lock_sock(sk);
846
847 switch (optname) {
848 case BT_SECURITY:
849 if (sk->sk_type != SOCK_STREAM) {
850 err = -EINVAL;
851 break;
852 }
853
854 sec.level = rfcomm_pi(sk)->sec_level;
855 sec.key_size = 0;
856
857 len = min_t(unsigned int, len, sizeof(sec));
858 if (copy_to_user(optval, (char *) &sec, len))
859 err = -EFAULT;
860
861 break;
862
863 case BT_DEFER_SETUP:
864 if (sk->sk_state != BT_BOUND && sk->sk_state != BT_LISTEN) {
865 err = -EINVAL;
866 break;
867 }
868
869 if (put_user(test_bit(BT_SK_DEFER_SETUP, &bt_sk(sk)->flags),
870 (u32 __user *) optval))
871 err = -EFAULT;
872
873 break;
874
875 default:
876 err = -ENOPROTOOPT;
877 break;
878 }
879
880 release_sock(sk);
881 return err;
882}
883
884static int rfcomm_sock_ioctl(struct socket *sock, unsigned int cmd, unsigned long arg)
885{
886 struct sock *sk __maybe_unused = sock->sk;
887 int err;
888
889 BT_DBG("sk %p cmd %x arg %lx", sk, cmd, arg);
890
891 err = bt_sock_ioctl(sock, cmd, arg);
892
893 if (err == -ENOIOCTLCMD) {
894#ifdef CONFIG_BT_RFCOMM_TTY
895 lock_sock(sk);
896 err = rfcomm_dev_ioctl(sk, cmd, (void __user *) arg);
897 release_sock(sk);
898#else
899 err = -EOPNOTSUPP;
900#endif
901 }
902
903 return err;
904}
905
906static int rfcomm_sock_shutdown(struct socket *sock, int how)
907{
908 struct sock *sk = sock->sk;
909 int err = 0;
910
911 BT_DBG("sock %p, sk %p", sock, sk);
912
913 if (!sk)
914 return 0;
915
916 lock_sock(sk);
917 if (!sk->sk_shutdown) {
918 sk->sk_shutdown = SHUTDOWN_MASK;
919 __rfcomm_sock_close(sk);
920
921 if (sock_flag(sk, SOCK_LINGER) && sk->sk_lingertime)
922 err = bt_sock_wait_state(sk, BT_CLOSED, sk->sk_lingertime);
923 }
924 release_sock(sk);
925 return err;
926}
927
928static int rfcomm_sock_release(struct socket *sock)
929{
930 struct sock *sk = sock->sk;
931 int err;
932
933 BT_DBG("sock %p, sk %p", sock, sk);
934
935 if (!sk)
936 return 0;
937
938 err = rfcomm_sock_shutdown(sock, 2);
939
940 sock_orphan(sk);
941 rfcomm_sock_kill(sk);
942 return err;
943}
944
945/* ---- RFCOMM core layer callbacks ----
946 *
947 * called under rfcomm_lock()
948 */
949int rfcomm_connect_ind(struct rfcomm_session *s, u8 channel, struct rfcomm_dlc **d)
950{
951 struct sock *sk, *parent;
952 bdaddr_t src, dst;
953 int result = 0;
954
955 BT_DBG("session %p channel %d", s, channel);
956
957 rfcomm_session_getaddr(s, &src, &dst);
958
959 /* Check if we have socket listening on channel */
960 parent = rfcomm_get_sock_by_channel(BT_LISTEN, channel, &src);
961 if (!parent)
962 return 0;
963
964 bh_lock_sock(parent);
965
966 /* Check for backlog size */
967 if (sk_acceptq_is_full(parent)) {
968 BT_DBG("backlog full %d", parent->sk_ack_backlog);
969 goto done;
970 }
971
972 sk = rfcomm_sock_alloc(sock_net(parent), NULL, BTPROTO_RFCOMM, GFP_ATOMIC);
973 if (!sk)
974 goto done;
975
976 bt_sock_reclassify_lock(sk, BTPROTO_RFCOMM);
977
978 rfcomm_sock_init(sk, parent);
979 bacpy(&rfcomm_pi(sk)->src, &src);
980 bacpy(&rfcomm_pi(sk)->dst, &dst);
981 rfcomm_pi(sk)->channel = channel;
982
983 sk->sk_state = BT_CONFIG;
984 bt_accept_enqueue(parent, sk);
985
986 /* Accept connection and return socket DLC */
987 *d = rfcomm_pi(sk)->dlc;
988 result = 1;
989
990done:
991 bh_unlock_sock(parent);
992
993 if (test_bit(BT_SK_DEFER_SETUP, &bt_sk(parent)->flags))
994 parent->sk_state_change(parent);
995
996 return result;
997}
998
999static int rfcomm_sock_debugfs_show(struct seq_file *f, void *p)
1000{
1001 struct sock *sk;
1002
1003 read_lock(&rfcomm_sk_list.lock);
1004
1005 sk_for_each(sk, &rfcomm_sk_list.head) {
1006 seq_printf(f, "%pMR %pMR %d %d\n",
1007 &rfcomm_pi(sk)->src, &rfcomm_pi(sk)->dst,
1008 sk->sk_state, rfcomm_pi(sk)->channel);
1009 }
1010
1011 read_unlock(&rfcomm_sk_list.lock);
1012
1013 return 0;
1014}
1015
1016static int rfcomm_sock_debugfs_open(struct inode *inode, struct file *file)
1017{
1018 return single_open(file, rfcomm_sock_debugfs_show, inode->i_private);
1019}
1020
1021static const struct file_operations rfcomm_sock_debugfs_fops = {
1022 .open = rfcomm_sock_debugfs_open,
1023 .read = seq_read,
1024 .llseek = seq_lseek,
1025 .release = single_release,
1026};
1027
1028static struct dentry *rfcomm_sock_debugfs;
1029
1030static const struct proto_ops rfcomm_sock_ops = {
1031 .family = PF_BLUETOOTH,
1032 .owner = THIS_MODULE,
1033 .release = rfcomm_sock_release,
1034 .bind = rfcomm_sock_bind,
1035 .connect = rfcomm_sock_connect,
1036 .listen = rfcomm_sock_listen,
1037 .accept = rfcomm_sock_accept,
1038 .getname = rfcomm_sock_getname,
1039 .sendmsg = rfcomm_sock_sendmsg,
1040 .recvmsg = rfcomm_sock_recvmsg,
1041 .shutdown = rfcomm_sock_shutdown,
1042 .setsockopt = rfcomm_sock_setsockopt,
1043 .getsockopt = rfcomm_sock_getsockopt,
1044 .ioctl = rfcomm_sock_ioctl,
1045 .poll = bt_sock_poll,
1046 .socketpair = sock_no_socketpair,
1047 .mmap = sock_no_mmap
1048};
1049
1050static const struct net_proto_family rfcomm_sock_family_ops = {
1051 .family = PF_BLUETOOTH,
1052 .owner = THIS_MODULE,
1053 .create = rfcomm_sock_create
1054};
1055
1056int __init rfcomm_init_sockets(void)
1057{
1058 int err;
1059
1060 err = proto_register(&rfcomm_proto, 0);
1061 if (err < 0)
1062 return err;
1063
1064 err = bt_sock_register(BTPROTO_RFCOMM, &rfcomm_sock_family_ops);
1065 if (err < 0) {
1066 BT_ERR("RFCOMM socket layer registration failed");
1067 goto error;
1068 }
1069
1070 err = bt_procfs_init(&init_net, "rfcomm", &rfcomm_sk_list, NULL);
1071 if (err < 0) {
1072 BT_ERR("Failed to create RFCOMM proc file");
1073 bt_sock_unregister(BTPROTO_RFCOMM);
1074 goto error;
1075 }
1076
1077 BT_INFO("RFCOMM socket layer initialized");
1078
1079 if (IS_ERR_OR_NULL(bt_debugfs))
1080 return 0;
1081
1082 rfcomm_sock_debugfs = debugfs_create_file("rfcomm", 0444,
1083 bt_debugfs, NULL,
1084 &rfcomm_sock_debugfs_fops);
1085
1086 return 0;
1087
1088error:
1089 proto_unregister(&rfcomm_proto);
1090 return err;
1091}
1092
1093void __exit rfcomm_cleanup_sockets(void)
1094{
1095 bt_procfs_cleanup(&init_net, "rfcomm");
1096
1097 debugfs_remove(rfcomm_sock_debugfs);
1098
1099 bt_sock_unregister(BTPROTO_RFCOMM);
1100
1101 proto_unregister(&rfcomm_proto);
1102}