xref: /OK3568_Linux_fs/kernel/net/bluetooth/cmtp/core.c (revision 4882a59341e53eb6f0b4789bf948001014eff981)
1*4882a593Smuzhiyun /*
2*4882a593Smuzhiyun    CMTP implementation for Linux Bluetooth stack (BlueZ).
3*4882a593Smuzhiyun    Copyright (C) 2002-2003 Marcel Holtmann <marcel@holtmann.org>
4*4882a593Smuzhiyun 
5*4882a593Smuzhiyun    This program is free software; you can redistribute it and/or modify
6*4882a593Smuzhiyun    it under the terms of the GNU General Public License version 2 as
7*4882a593Smuzhiyun    published by the Free Software Foundation;
8*4882a593Smuzhiyun 
9*4882a593Smuzhiyun    THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS
10*4882a593Smuzhiyun    OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
11*4882a593Smuzhiyun    FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT OF THIRD PARTY RIGHTS.
12*4882a593Smuzhiyun    IN NO EVENT SHALL THE COPYRIGHT HOLDER(S) AND AUTHOR(S) BE LIABLE FOR ANY
13*4882a593Smuzhiyun    CLAIM, OR ANY SPECIAL INDIRECT OR CONSEQUENTIAL DAMAGES, OR ANY DAMAGES
14*4882a593Smuzhiyun    WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
15*4882a593Smuzhiyun    ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
16*4882a593Smuzhiyun    OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
17*4882a593Smuzhiyun 
18*4882a593Smuzhiyun    ALL LIABILITY, INCLUDING LIABILITY FOR INFRINGEMENT OF ANY PATENTS,
19*4882a593Smuzhiyun    COPYRIGHTS, TRADEMARKS OR OTHER RIGHTS, RELATING TO USE OF THIS
20*4882a593Smuzhiyun    SOFTWARE IS DISCLAIMED.
21*4882a593Smuzhiyun */
22*4882a593Smuzhiyun 
23*4882a593Smuzhiyun #include <linux/module.h>
24*4882a593Smuzhiyun 
25*4882a593Smuzhiyun #include <linux/types.h>
26*4882a593Smuzhiyun #include <linux/errno.h>
27*4882a593Smuzhiyun #include <linux/kernel.h>
28*4882a593Smuzhiyun #include <linux/sched.h>
29*4882a593Smuzhiyun #include <linux/slab.h>
30*4882a593Smuzhiyun #include <linux/poll.h>
31*4882a593Smuzhiyun #include <linux/fcntl.h>
32*4882a593Smuzhiyun #include <linux/freezer.h>
33*4882a593Smuzhiyun #include <linux/skbuff.h>
34*4882a593Smuzhiyun #include <linux/socket.h>
35*4882a593Smuzhiyun #include <linux/ioctl.h>
36*4882a593Smuzhiyun #include <linux/file.h>
37*4882a593Smuzhiyun #include <linux/init.h>
38*4882a593Smuzhiyun #include <linux/kthread.h>
39*4882a593Smuzhiyun #include <net/sock.h>
40*4882a593Smuzhiyun 
41*4882a593Smuzhiyun #include <linux/isdn/capilli.h>
42*4882a593Smuzhiyun 
43*4882a593Smuzhiyun #include <net/bluetooth/bluetooth.h>
44*4882a593Smuzhiyun #include <net/bluetooth/l2cap.h>
45*4882a593Smuzhiyun 
46*4882a593Smuzhiyun #include "cmtp.h"
47*4882a593Smuzhiyun 
48*4882a593Smuzhiyun #define VERSION "1.0"
49*4882a593Smuzhiyun 
50*4882a593Smuzhiyun static DECLARE_RWSEM(cmtp_session_sem);
51*4882a593Smuzhiyun static LIST_HEAD(cmtp_session_list);
52*4882a593Smuzhiyun 
__cmtp_get_session(bdaddr_t * bdaddr)53*4882a593Smuzhiyun static struct cmtp_session *__cmtp_get_session(bdaddr_t *bdaddr)
54*4882a593Smuzhiyun {
55*4882a593Smuzhiyun 	struct cmtp_session *session;
56*4882a593Smuzhiyun 
57*4882a593Smuzhiyun 	BT_DBG("");
58*4882a593Smuzhiyun 
59*4882a593Smuzhiyun 	list_for_each_entry(session, &cmtp_session_list, list)
60*4882a593Smuzhiyun 		if (!bacmp(bdaddr, &session->bdaddr))
61*4882a593Smuzhiyun 			return session;
62*4882a593Smuzhiyun 
63*4882a593Smuzhiyun 	return NULL;
64*4882a593Smuzhiyun }
65*4882a593Smuzhiyun 
__cmtp_link_session(struct cmtp_session * session)66*4882a593Smuzhiyun static void __cmtp_link_session(struct cmtp_session *session)
67*4882a593Smuzhiyun {
68*4882a593Smuzhiyun 	list_add(&session->list, &cmtp_session_list);
69*4882a593Smuzhiyun }
70*4882a593Smuzhiyun 
__cmtp_unlink_session(struct cmtp_session * session)71*4882a593Smuzhiyun static void __cmtp_unlink_session(struct cmtp_session *session)
72*4882a593Smuzhiyun {
73*4882a593Smuzhiyun 	list_del(&session->list);
74*4882a593Smuzhiyun }
75*4882a593Smuzhiyun 
__cmtp_copy_session(struct cmtp_session * session,struct cmtp_conninfo * ci)76*4882a593Smuzhiyun static void __cmtp_copy_session(struct cmtp_session *session, struct cmtp_conninfo *ci)
77*4882a593Smuzhiyun {
78*4882a593Smuzhiyun 	u32 valid_flags = BIT(CMTP_LOOPBACK);
79*4882a593Smuzhiyun 	memset(ci, 0, sizeof(*ci));
80*4882a593Smuzhiyun 	bacpy(&ci->bdaddr, &session->bdaddr);
81*4882a593Smuzhiyun 
82*4882a593Smuzhiyun 	ci->flags = session->flags & valid_flags;
83*4882a593Smuzhiyun 	ci->state = session->state;
84*4882a593Smuzhiyun 
85*4882a593Smuzhiyun 	ci->num = session->num;
86*4882a593Smuzhiyun }
87*4882a593Smuzhiyun 
88*4882a593Smuzhiyun 
cmtp_alloc_block_id(struct cmtp_session * session)89*4882a593Smuzhiyun static inline int cmtp_alloc_block_id(struct cmtp_session *session)
90*4882a593Smuzhiyun {
91*4882a593Smuzhiyun 	int i, id = -1;
92*4882a593Smuzhiyun 
93*4882a593Smuzhiyun 	for (i = 0; i < 16; i++)
94*4882a593Smuzhiyun 		if (!test_and_set_bit(i, &session->blockids)) {
95*4882a593Smuzhiyun 			id = i;
96*4882a593Smuzhiyun 			break;
97*4882a593Smuzhiyun 		}
98*4882a593Smuzhiyun 
99*4882a593Smuzhiyun 	return id;
100*4882a593Smuzhiyun }
101*4882a593Smuzhiyun 
cmtp_free_block_id(struct cmtp_session * session,int id)102*4882a593Smuzhiyun static inline void cmtp_free_block_id(struct cmtp_session *session, int id)
103*4882a593Smuzhiyun {
104*4882a593Smuzhiyun 	clear_bit(id, &session->blockids);
105*4882a593Smuzhiyun }
106*4882a593Smuzhiyun 
cmtp_add_msgpart(struct cmtp_session * session,int id,const unsigned char * buf,int count)107*4882a593Smuzhiyun static inline void cmtp_add_msgpart(struct cmtp_session *session, int id, const unsigned char *buf, int count)
108*4882a593Smuzhiyun {
109*4882a593Smuzhiyun 	struct sk_buff *skb = session->reassembly[id], *nskb;
110*4882a593Smuzhiyun 	int size;
111*4882a593Smuzhiyun 
112*4882a593Smuzhiyun 	BT_DBG("session %p buf %p count %d", session, buf, count);
113*4882a593Smuzhiyun 
114*4882a593Smuzhiyun 	size = (skb) ? skb->len + count : count;
115*4882a593Smuzhiyun 
116*4882a593Smuzhiyun 	nskb = alloc_skb(size, GFP_ATOMIC);
117*4882a593Smuzhiyun 	if (!nskb) {
118*4882a593Smuzhiyun 		BT_ERR("Can't allocate memory for CAPI message");
119*4882a593Smuzhiyun 		return;
120*4882a593Smuzhiyun 	}
121*4882a593Smuzhiyun 
122*4882a593Smuzhiyun 	if (skb && (skb->len > 0))
123*4882a593Smuzhiyun 		skb_copy_from_linear_data(skb, skb_put(nskb, skb->len), skb->len);
124*4882a593Smuzhiyun 
125*4882a593Smuzhiyun 	skb_put_data(nskb, buf, count);
126*4882a593Smuzhiyun 
127*4882a593Smuzhiyun 	session->reassembly[id] = nskb;
128*4882a593Smuzhiyun 
129*4882a593Smuzhiyun 	kfree_skb(skb);
130*4882a593Smuzhiyun }
131*4882a593Smuzhiyun 
cmtp_recv_frame(struct cmtp_session * session,struct sk_buff * skb)132*4882a593Smuzhiyun static inline int cmtp_recv_frame(struct cmtp_session *session, struct sk_buff *skb)
133*4882a593Smuzhiyun {
134*4882a593Smuzhiyun 	__u8 hdr, hdrlen, id;
135*4882a593Smuzhiyun 	__u16 len;
136*4882a593Smuzhiyun 
137*4882a593Smuzhiyun 	BT_DBG("session %p skb %p len %d", session, skb, skb->len);
138*4882a593Smuzhiyun 
139*4882a593Smuzhiyun 	while (skb->len > 0) {
140*4882a593Smuzhiyun 		hdr = skb->data[0];
141*4882a593Smuzhiyun 
142*4882a593Smuzhiyun 		switch (hdr & 0xc0) {
143*4882a593Smuzhiyun 		case 0x40:
144*4882a593Smuzhiyun 			hdrlen = 2;
145*4882a593Smuzhiyun 			len = skb->data[1];
146*4882a593Smuzhiyun 			break;
147*4882a593Smuzhiyun 		case 0x80:
148*4882a593Smuzhiyun 			hdrlen = 3;
149*4882a593Smuzhiyun 			len = skb->data[1] | (skb->data[2] << 8);
150*4882a593Smuzhiyun 			break;
151*4882a593Smuzhiyun 		default:
152*4882a593Smuzhiyun 			hdrlen = 1;
153*4882a593Smuzhiyun 			len = 0;
154*4882a593Smuzhiyun 			break;
155*4882a593Smuzhiyun 		}
156*4882a593Smuzhiyun 
157*4882a593Smuzhiyun 		id = (hdr & 0x3c) >> 2;
158*4882a593Smuzhiyun 
159*4882a593Smuzhiyun 		BT_DBG("hdr 0x%02x hdrlen %d len %d id %d", hdr, hdrlen, len, id);
160*4882a593Smuzhiyun 
161*4882a593Smuzhiyun 		if (hdrlen + len > skb->len) {
162*4882a593Smuzhiyun 			BT_ERR("Wrong size or header information in CMTP frame");
163*4882a593Smuzhiyun 			break;
164*4882a593Smuzhiyun 		}
165*4882a593Smuzhiyun 
166*4882a593Smuzhiyun 		if (len == 0) {
167*4882a593Smuzhiyun 			skb_pull(skb, hdrlen);
168*4882a593Smuzhiyun 			continue;
169*4882a593Smuzhiyun 		}
170*4882a593Smuzhiyun 
171*4882a593Smuzhiyun 		switch (hdr & 0x03) {
172*4882a593Smuzhiyun 		case 0x00:
173*4882a593Smuzhiyun 			cmtp_add_msgpart(session, id, skb->data + hdrlen, len);
174*4882a593Smuzhiyun 			cmtp_recv_capimsg(session, session->reassembly[id]);
175*4882a593Smuzhiyun 			session->reassembly[id] = NULL;
176*4882a593Smuzhiyun 			break;
177*4882a593Smuzhiyun 		case 0x01:
178*4882a593Smuzhiyun 			cmtp_add_msgpart(session, id, skb->data + hdrlen, len);
179*4882a593Smuzhiyun 			break;
180*4882a593Smuzhiyun 		default:
181*4882a593Smuzhiyun 			kfree_skb(session->reassembly[id]);
182*4882a593Smuzhiyun 			session->reassembly[id] = NULL;
183*4882a593Smuzhiyun 			break;
184*4882a593Smuzhiyun 		}
185*4882a593Smuzhiyun 
186*4882a593Smuzhiyun 		skb_pull(skb, hdrlen + len);
187*4882a593Smuzhiyun 	}
188*4882a593Smuzhiyun 
189*4882a593Smuzhiyun 	kfree_skb(skb);
190*4882a593Smuzhiyun 	return 0;
191*4882a593Smuzhiyun }
192*4882a593Smuzhiyun 
cmtp_send_frame(struct cmtp_session * session,unsigned char * data,int len)193*4882a593Smuzhiyun static int cmtp_send_frame(struct cmtp_session *session, unsigned char *data, int len)
194*4882a593Smuzhiyun {
195*4882a593Smuzhiyun 	struct socket *sock = session->sock;
196*4882a593Smuzhiyun 	struct kvec iv = { data, len };
197*4882a593Smuzhiyun 	struct msghdr msg;
198*4882a593Smuzhiyun 
199*4882a593Smuzhiyun 	BT_DBG("session %p data %p len %d", session, data, len);
200*4882a593Smuzhiyun 
201*4882a593Smuzhiyun 	if (!len)
202*4882a593Smuzhiyun 		return 0;
203*4882a593Smuzhiyun 
204*4882a593Smuzhiyun 	memset(&msg, 0, sizeof(msg));
205*4882a593Smuzhiyun 
206*4882a593Smuzhiyun 	return kernel_sendmsg(sock, &msg, &iv, 1, len);
207*4882a593Smuzhiyun }
208*4882a593Smuzhiyun 
cmtp_process_transmit(struct cmtp_session * session)209*4882a593Smuzhiyun static void cmtp_process_transmit(struct cmtp_session *session)
210*4882a593Smuzhiyun {
211*4882a593Smuzhiyun 	struct sk_buff *skb, *nskb;
212*4882a593Smuzhiyun 	unsigned char *hdr;
213*4882a593Smuzhiyun 	unsigned int size, tail;
214*4882a593Smuzhiyun 
215*4882a593Smuzhiyun 	BT_DBG("session %p", session);
216*4882a593Smuzhiyun 
217*4882a593Smuzhiyun 	nskb = alloc_skb(session->mtu, GFP_ATOMIC);
218*4882a593Smuzhiyun 	if (!nskb) {
219*4882a593Smuzhiyun 		BT_ERR("Can't allocate memory for new frame");
220*4882a593Smuzhiyun 		return;
221*4882a593Smuzhiyun 	}
222*4882a593Smuzhiyun 
223*4882a593Smuzhiyun 	while ((skb = skb_dequeue(&session->transmit))) {
224*4882a593Smuzhiyun 		struct cmtp_scb *scb = (void *) skb->cb;
225*4882a593Smuzhiyun 
226*4882a593Smuzhiyun 		tail = session->mtu - nskb->len;
227*4882a593Smuzhiyun 		if (tail < 5) {
228*4882a593Smuzhiyun 			cmtp_send_frame(session, nskb->data, nskb->len);
229*4882a593Smuzhiyun 			skb_trim(nskb, 0);
230*4882a593Smuzhiyun 			tail = session->mtu;
231*4882a593Smuzhiyun 		}
232*4882a593Smuzhiyun 
233*4882a593Smuzhiyun 		size = min_t(uint, ((tail < 258) ? (tail - 2) : (tail - 3)), skb->len);
234*4882a593Smuzhiyun 
235*4882a593Smuzhiyun 		if (scb->id < 0) {
236*4882a593Smuzhiyun 			scb->id = cmtp_alloc_block_id(session);
237*4882a593Smuzhiyun 			if (scb->id < 0) {
238*4882a593Smuzhiyun 				skb_queue_head(&session->transmit, skb);
239*4882a593Smuzhiyun 				break;
240*4882a593Smuzhiyun 			}
241*4882a593Smuzhiyun 		}
242*4882a593Smuzhiyun 
243*4882a593Smuzhiyun 		if (size < 256) {
244*4882a593Smuzhiyun 			hdr = skb_put(nskb, 2);
245*4882a593Smuzhiyun 			hdr[0] = 0x40
246*4882a593Smuzhiyun 				| ((scb->id << 2) & 0x3c)
247*4882a593Smuzhiyun 				| ((skb->len == size) ? 0x00 : 0x01);
248*4882a593Smuzhiyun 			hdr[1] = size;
249*4882a593Smuzhiyun 		} else {
250*4882a593Smuzhiyun 			hdr = skb_put(nskb, 3);
251*4882a593Smuzhiyun 			hdr[0] = 0x80
252*4882a593Smuzhiyun 				| ((scb->id << 2) & 0x3c)
253*4882a593Smuzhiyun 				| ((skb->len == size) ? 0x00 : 0x01);
254*4882a593Smuzhiyun 			hdr[1] = size & 0xff;
255*4882a593Smuzhiyun 			hdr[2] = size >> 8;
256*4882a593Smuzhiyun 		}
257*4882a593Smuzhiyun 
258*4882a593Smuzhiyun 		skb_copy_from_linear_data(skb, skb_put(nskb, size), size);
259*4882a593Smuzhiyun 		skb_pull(skb, size);
260*4882a593Smuzhiyun 
261*4882a593Smuzhiyun 		if (skb->len > 0) {
262*4882a593Smuzhiyun 			skb_queue_head(&session->transmit, skb);
263*4882a593Smuzhiyun 		} else {
264*4882a593Smuzhiyun 			cmtp_free_block_id(session, scb->id);
265*4882a593Smuzhiyun 			if (scb->data) {
266*4882a593Smuzhiyun 				cmtp_send_frame(session, nskb->data, nskb->len);
267*4882a593Smuzhiyun 				skb_trim(nskb, 0);
268*4882a593Smuzhiyun 			}
269*4882a593Smuzhiyun 			kfree_skb(skb);
270*4882a593Smuzhiyun 		}
271*4882a593Smuzhiyun 	}
272*4882a593Smuzhiyun 
273*4882a593Smuzhiyun 	cmtp_send_frame(session, nskb->data, nskb->len);
274*4882a593Smuzhiyun 
275*4882a593Smuzhiyun 	kfree_skb(nskb);
276*4882a593Smuzhiyun }
277*4882a593Smuzhiyun 
cmtp_session(void * arg)278*4882a593Smuzhiyun static int cmtp_session(void *arg)
279*4882a593Smuzhiyun {
280*4882a593Smuzhiyun 	struct cmtp_session *session = arg;
281*4882a593Smuzhiyun 	struct sock *sk = session->sock->sk;
282*4882a593Smuzhiyun 	struct sk_buff *skb;
283*4882a593Smuzhiyun 	DEFINE_WAIT_FUNC(wait, woken_wake_function);
284*4882a593Smuzhiyun 
285*4882a593Smuzhiyun 	BT_DBG("session %p", session);
286*4882a593Smuzhiyun 
287*4882a593Smuzhiyun 	set_user_nice(current, -15);
288*4882a593Smuzhiyun 
289*4882a593Smuzhiyun 	add_wait_queue(sk_sleep(sk), &wait);
290*4882a593Smuzhiyun 	while (1) {
291*4882a593Smuzhiyun 		if (atomic_read(&session->terminate))
292*4882a593Smuzhiyun 			break;
293*4882a593Smuzhiyun 		if (sk->sk_state != BT_CONNECTED)
294*4882a593Smuzhiyun 			break;
295*4882a593Smuzhiyun 
296*4882a593Smuzhiyun 		while ((skb = skb_dequeue(&sk->sk_receive_queue))) {
297*4882a593Smuzhiyun 			skb_orphan(skb);
298*4882a593Smuzhiyun 			if (!skb_linearize(skb))
299*4882a593Smuzhiyun 				cmtp_recv_frame(session, skb);
300*4882a593Smuzhiyun 			else
301*4882a593Smuzhiyun 				kfree_skb(skb);
302*4882a593Smuzhiyun 		}
303*4882a593Smuzhiyun 
304*4882a593Smuzhiyun 		cmtp_process_transmit(session);
305*4882a593Smuzhiyun 
306*4882a593Smuzhiyun 		/*
307*4882a593Smuzhiyun 		 * wait_woken() performs the necessary memory barriers
308*4882a593Smuzhiyun 		 * for us; see the header comment for this primitive.
309*4882a593Smuzhiyun 		 */
310*4882a593Smuzhiyun 		wait_woken(&wait, TASK_INTERRUPTIBLE, MAX_SCHEDULE_TIMEOUT);
311*4882a593Smuzhiyun 	}
312*4882a593Smuzhiyun 	remove_wait_queue(sk_sleep(sk), &wait);
313*4882a593Smuzhiyun 
314*4882a593Smuzhiyun 	down_write(&cmtp_session_sem);
315*4882a593Smuzhiyun 
316*4882a593Smuzhiyun 	if (!(session->flags & BIT(CMTP_LOOPBACK)))
317*4882a593Smuzhiyun 		cmtp_detach_device(session);
318*4882a593Smuzhiyun 
319*4882a593Smuzhiyun 	fput(session->sock->file);
320*4882a593Smuzhiyun 
321*4882a593Smuzhiyun 	__cmtp_unlink_session(session);
322*4882a593Smuzhiyun 
323*4882a593Smuzhiyun 	up_write(&cmtp_session_sem);
324*4882a593Smuzhiyun 
325*4882a593Smuzhiyun 	kfree(session);
326*4882a593Smuzhiyun 	module_put_and_exit(0);
327*4882a593Smuzhiyun 	return 0;
328*4882a593Smuzhiyun }
329*4882a593Smuzhiyun 
cmtp_add_connection(struct cmtp_connadd_req * req,struct socket * sock)330*4882a593Smuzhiyun int cmtp_add_connection(struct cmtp_connadd_req *req, struct socket *sock)
331*4882a593Smuzhiyun {
332*4882a593Smuzhiyun 	u32 valid_flags = BIT(CMTP_LOOPBACK);
333*4882a593Smuzhiyun 	struct cmtp_session *session, *s;
334*4882a593Smuzhiyun 	int i, err;
335*4882a593Smuzhiyun 
336*4882a593Smuzhiyun 	BT_DBG("");
337*4882a593Smuzhiyun 
338*4882a593Smuzhiyun 	if (!l2cap_is_socket(sock))
339*4882a593Smuzhiyun 		return -EBADFD;
340*4882a593Smuzhiyun 
341*4882a593Smuzhiyun 	if (req->flags & ~valid_flags)
342*4882a593Smuzhiyun 		return -EINVAL;
343*4882a593Smuzhiyun 
344*4882a593Smuzhiyun 	session = kzalloc(sizeof(struct cmtp_session), GFP_KERNEL);
345*4882a593Smuzhiyun 	if (!session)
346*4882a593Smuzhiyun 		return -ENOMEM;
347*4882a593Smuzhiyun 
348*4882a593Smuzhiyun 	down_write(&cmtp_session_sem);
349*4882a593Smuzhiyun 
350*4882a593Smuzhiyun 	s = __cmtp_get_session(&l2cap_pi(sock->sk)->chan->dst);
351*4882a593Smuzhiyun 	if (s && s->state == BT_CONNECTED) {
352*4882a593Smuzhiyun 		err = -EEXIST;
353*4882a593Smuzhiyun 		goto failed;
354*4882a593Smuzhiyun 	}
355*4882a593Smuzhiyun 
356*4882a593Smuzhiyun 	bacpy(&session->bdaddr, &l2cap_pi(sock->sk)->chan->dst);
357*4882a593Smuzhiyun 
358*4882a593Smuzhiyun 	session->mtu = min_t(uint, l2cap_pi(sock->sk)->chan->omtu,
359*4882a593Smuzhiyun 					l2cap_pi(sock->sk)->chan->imtu);
360*4882a593Smuzhiyun 
361*4882a593Smuzhiyun 	BT_DBG("mtu %d", session->mtu);
362*4882a593Smuzhiyun 
363*4882a593Smuzhiyun 	sprintf(session->name, "%pMR", &session->bdaddr);
364*4882a593Smuzhiyun 
365*4882a593Smuzhiyun 	session->sock  = sock;
366*4882a593Smuzhiyun 	session->state = BT_CONFIG;
367*4882a593Smuzhiyun 
368*4882a593Smuzhiyun 	init_waitqueue_head(&session->wait);
369*4882a593Smuzhiyun 
370*4882a593Smuzhiyun 	session->msgnum = CMTP_INITIAL_MSGNUM;
371*4882a593Smuzhiyun 
372*4882a593Smuzhiyun 	INIT_LIST_HEAD(&session->applications);
373*4882a593Smuzhiyun 
374*4882a593Smuzhiyun 	skb_queue_head_init(&session->transmit);
375*4882a593Smuzhiyun 
376*4882a593Smuzhiyun 	for (i = 0; i < 16; i++)
377*4882a593Smuzhiyun 		session->reassembly[i] = NULL;
378*4882a593Smuzhiyun 
379*4882a593Smuzhiyun 	session->flags = req->flags;
380*4882a593Smuzhiyun 
381*4882a593Smuzhiyun 	__cmtp_link_session(session);
382*4882a593Smuzhiyun 
383*4882a593Smuzhiyun 	__module_get(THIS_MODULE);
384*4882a593Smuzhiyun 	session->task = kthread_run(cmtp_session, session, "kcmtpd_ctr_%d",
385*4882a593Smuzhiyun 								session->num);
386*4882a593Smuzhiyun 	if (IS_ERR(session->task)) {
387*4882a593Smuzhiyun 		module_put(THIS_MODULE);
388*4882a593Smuzhiyun 		err = PTR_ERR(session->task);
389*4882a593Smuzhiyun 		goto unlink;
390*4882a593Smuzhiyun 	}
391*4882a593Smuzhiyun 
392*4882a593Smuzhiyun 	if (!(session->flags & BIT(CMTP_LOOPBACK))) {
393*4882a593Smuzhiyun 		err = cmtp_attach_device(session);
394*4882a593Smuzhiyun 		if (err < 0) {
395*4882a593Smuzhiyun 			/* Caller will call fput in case of failure, and so
396*4882a593Smuzhiyun 			 * will cmtp_session kthread.
397*4882a593Smuzhiyun 			 */
398*4882a593Smuzhiyun 			get_file(session->sock->file);
399*4882a593Smuzhiyun 
400*4882a593Smuzhiyun 			atomic_inc(&session->terminate);
401*4882a593Smuzhiyun 			wake_up_interruptible(sk_sleep(session->sock->sk));
402*4882a593Smuzhiyun 			up_write(&cmtp_session_sem);
403*4882a593Smuzhiyun 			return err;
404*4882a593Smuzhiyun 		}
405*4882a593Smuzhiyun 	}
406*4882a593Smuzhiyun 
407*4882a593Smuzhiyun 	up_write(&cmtp_session_sem);
408*4882a593Smuzhiyun 	return 0;
409*4882a593Smuzhiyun 
410*4882a593Smuzhiyun unlink:
411*4882a593Smuzhiyun 	__cmtp_unlink_session(session);
412*4882a593Smuzhiyun 
413*4882a593Smuzhiyun failed:
414*4882a593Smuzhiyun 	up_write(&cmtp_session_sem);
415*4882a593Smuzhiyun 	kfree(session);
416*4882a593Smuzhiyun 	return err;
417*4882a593Smuzhiyun }
418*4882a593Smuzhiyun 
cmtp_del_connection(struct cmtp_conndel_req * req)419*4882a593Smuzhiyun int cmtp_del_connection(struct cmtp_conndel_req *req)
420*4882a593Smuzhiyun {
421*4882a593Smuzhiyun 	u32 valid_flags = 0;
422*4882a593Smuzhiyun 	struct cmtp_session *session;
423*4882a593Smuzhiyun 	int err = 0;
424*4882a593Smuzhiyun 
425*4882a593Smuzhiyun 	BT_DBG("");
426*4882a593Smuzhiyun 
427*4882a593Smuzhiyun 	if (req->flags & ~valid_flags)
428*4882a593Smuzhiyun 		return -EINVAL;
429*4882a593Smuzhiyun 
430*4882a593Smuzhiyun 	down_read(&cmtp_session_sem);
431*4882a593Smuzhiyun 
432*4882a593Smuzhiyun 	session = __cmtp_get_session(&req->bdaddr);
433*4882a593Smuzhiyun 	if (session) {
434*4882a593Smuzhiyun 		/* Flush the transmit queue */
435*4882a593Smuzhiyun 		skb_queue_purge(&session->transmit);
436*4882a593Smuzhiyun 
437*4882a593Smuzhiyun 		/* Stop session thread */
438*4882a593Smuzhiyun 		atomic_inc(&session->terminate);
439*4882a593Smuzhiyun 
440*4882a593Smuzhiyun 		/*
441*4882a593Smuzhiyun 		 * See the comment preceding the call to wait_woken()
442*4882a593Smuzhiyun 		 * in cmtp_session().
443*4882a593Smuzhiyun 		 */
444*4882a593Smuzhiyun 		wake_up_interruptible(sk_sleep(session->sock->sk));
445*4882a593Smuzhiyun 	} else
446*4882a593Smuzhiyun 		err = -ENOENT;
447*4882a593Smuzhiyun 
448*4882a593Smuzhiyun 	up_read(&cmtp_session_sem);
449*4882a593Smuzhiyun 	return err;
450*4882a593Smuzhiyun }
451*4882a593Smuzhiyun 
cmtp_get_connlist(struct cmtp_connlist_req * req)452*4882a593Smuzhiyun int cmtp_get_connlist(struct cmtp_connlist_req *req)
453*4882a593Smuzhiyun {
454*4882a593Smuzhiyun 	struct cmtp_session *session;
455*4882a593Smuzhiyun 	int err = 0, n = 0;
456*4882a593Smuzhiyun 
457*4882a593Smuzhiyun 	BT_DBG("");
458*4882a593Smuzhiyun 
459*4882a593Smuzhiyun 	down_read(&cmtp_session_sem);
460*4882a593Smuzhiyun 
461*4882a593Smuzhiyun 	list_for_each_entry(session, &cmtp_session_list, list) {
462*4882a593Smuzhiyun 		struct cmtp_conninfo ci;
463*4882a593Smuzhiyun 
464*4882a593Smuzhiyun 		__cmtp_copy_session(session, &ci);
465*4882a593Smuzhiyun 
466*4882a593Smuzhiyun 		if (copy_to_user(req->ci, &ci, sizeof(ci))) {
467*4882a593Smuzhiyun 			err = -EFAULT;
468*4882a593Smuzhiyun 			break;
469*4882a593Smuzhiyun 		}
470*4882a593Smuzhiyun 
471*4882a593Smuzhiyun 		if (++n >= req->cnum)
472*4882a593Smuzhiyun 			break;
473*4882a593Smuzhiyun 
474*4882a593Smuzhiyun 		req->ci++;
475*4882a593Smuzhiyun 	}
476*4882a593Smuzhiyun 	req->cnum = n;
477*4882a593Smuzhiyun 
478*4882a593Smuzhiyun 	up_read(&cmtp_session_sem);
479*4882a593Smuzhiyun 	return err;
480*4882a593Smuzhiyun }
481*4882a593Smuzhiyun 
cmtp_get_conninfo(struct cmtp_conninfo * ci)482*4882a593Smuzhiyun int cmtp_get_conninfo(struct cmtp_conninfo *ci)
483*4882a593Smuzhiyun {
484*4882a593Smuzhiyun 	struct cmtp_session *session;
485*4882a593Smuzhiyun 	int err = 0;
486*4882a593Smuzhiyun 
487*4882a593Smuzhiyun 	down_read(&cmtp_session_sem);
488*4882a593Smuzhiyun 
489*4882a593Smuzhiyun 	session = __cmtp_get_session(&ci->bdaddr);
490*4882a593Smuzhiyun 	if (session)
491*4882a593Smuzhiyun 		__cmtp_copy_session(session, ci);
492*4882a593Smuzhiyun 	else
493*4882a593Smuzhiyun 		err = -ENOENT;
494*4882a593Smuzhiyun 
495*4882a593Smuzhiyun 	up_read(&cmtp_session_sem);
496*4882a593Smuzhiyun 	return err;
497*4882a593Smuzhiyun }
498*4882a593Smuzhiyun 
499*4882a593Smuzhiyun 
cmtp_init(void)500*4882a593Smuzhiyun static int __init cmtp_init(void)
501*4882a593Smuzhiyun {
502*4882a593Smuzhiyun 	BT_INFO("CMTP (CAPI Emulation) ver %s", VERSION);
503*4882a593Smuzhiyun 
504*4882a593Smuzhiyun 	return cmtp_init_sockets();
505*4882a593Smuzhiyun }
506*4882a593Smuzhiyun 
cmtp_exit(void)507*4882a593Smuzhiyun static void __exit cmtp_exit(void)
508*4882a593Smuzhiyun {
509*4882a593Smuzhiyun 	cmtp_cleanup_sockets();
510*4882a593Smuzhiyun }
511*4882a593Smuzhiyun 
512*4882a593Smuzhiyun module_init(cmtp_init);
513*4882a593Smuzhiyun module_exit(cmtp_exit);
514*4882a593Smuzhiyun 
515*4882a593Smuzhiyun MODULE_AUTHOR("Marcel Holtmann <marcel@holtmann.org>");
516*4882a593Smuzhiyun MODULE_DESCRIPTION("Bluetooth CMTP ver " VERSION);
517*4882a593Smuzhiyun MODULE_VERSION(VERSION);
518*4882a593Smuzhiyun MODULE_LICENSE("GPL");
519*4882a593Smuzhiyun MODULE_ALIAS("bt-proto-5");
520