2 BlueZ - Bluetooth protocol stack for Linux
3 Copyright (C) 2000-2001 Qualcomm Incorporated
5 Written 2000,2001 by Maxim Krasnyansky <maxk@qualcomm.com>
7 This program is free software; you can redistribute it and/or modify
8 it under the terms of the GNU General Public License version 2 as
9 published by the Free Software Foundation;
11 THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS
12 OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
13 FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT OF THIRD PARTY RIGHTS.
14 IN NO EVENT SHALL THE COPYRIGHT HOLDER(S) AND AUTHOR(S) BE LIABLE FOR ANY
15 CLAIM, OR ANY SPECIAL INDIRECT OR CONSEQUENTIAL DAMAGES, OR ANY DAMAGES
16 WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
17 ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
18 OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
20 ALL LIABILITY, INCLUDING LIABILITY FOR INFRINGEMENT OF ANY PATENTS,
21 COPYRIGHTS, TRADEMARKS OR OTHER RIGHTS, RELATING TO USE OF THIS
22 SOFTWARE IS DISCLAIMED.
25 /* Bluetooth HCI sockets. */
27 #include <linux/module.h>
29 #include <linux/types.h>
30 #include <linux/capability.h>
31 #include <linux/errno.h>
32 #include <linux/kernel.h>
33 #include <linux/slab.h>
34 #include <linux/poll.h>
35 #include <linux/fcntl.h>
36 #include <linux/init.h>
37 #include <linux/skbuff.h>
38 #include <linux/workqueue.h>
39 #include <linux/interrupt.h>
40 #include <linux/compat.h>
41 #include <linux/socket.h>
42 #include <linux/ioctl.h>
45 #include <asm/system.h>
46 #include <asm/uaccess.h>
47 #include <asm/unaligned.h>
49 #include <net/bluetooth/bluetooth.h>
50 #include <net/bluetooth/hci_core.h>
52 #ifndef CONFIG_BT_HCI_SOCK_DEBUG
57 /* ----- HCI socket interface ----- */
59 static inline int hci_test_bit(int nr, void *addr)
61 return *((__u32 *) addr + (nr >> 5)) & ((__u32) 1 << (nr & 31));
65 static struct hci_sec_filter hci_sec_filter = {
69 { 0x1000d9fe, 0x0000b00c },
74 { 0xbe000006, 0x00000001, 0x00000000, 0x00 },
76 { 0x00005200, 0x00000000, 0x00000000, 0x00 },
78 { 0xaab00200, 0x2b402aaa, 0x05220154, 0x00 },
80 { 0x000002be, 0x00000000, 0x00000000, 0x00 },
81 /* OGF_STATUS_PARAM */
82 { 0x000000ea, 0x00000000, 0x00000000, 0x00 }
86 static struct bt_sock_list hci_sk_list = {
87 .lock = RW_LOCK_UNLOCKED
90 /* Send frame to RAW socket */
91 void hci_send_to_sock(struct hci_dev *hdev, struct sk_buff *skb)
94 struct hlist_node *node;
96 BT_DBG("hdev %p len %d", hdev, skb->len);
98 read_lock(&hci_sk_list.lock);
99 sk_for_each(sk, node, &hci_sk_list.head) {
100 struct hci_filter *flt;
101 struct sk_buff *nskb;
103 if (sk->sk_state != BT_BOUND || hci_pi(sk)->hdev != hdev)
106 /* Don't send frame to the socket it came from */
111 flt = &hci_pi(sk)->filter;
113 if (!test_bit((bt_cb(skb)->pkt_type == HCI_VENDOR_PKT) ?
114 0 : (bt_cb(skb)->pkt_type & HCI_FLT_TYPE_BITS), &flt->type_mask))
117 if (bt_cb(skb)->pkt_type == HCI_EVENT_PKT) {
118 register int evt = (*(__u8 *)skb->data & HCI_FLT_EVENT_BITS);
120 if (!hci_test_bit(evt, &flt->event_mask))
124 ((evt == HCI_EV_CMD_COMPLETE &&
126 get_unaligned((__le16 *)(skb->data + 3))) ||
127 (evt == HCI_EV_CMD_STATUS &&
129 get_unaligned((__le16 *)(skb->data + 4)))))
133 if (!(nskb = skb_clone(skb, GFP_ATOMIC)))
136 /* Put type byte before the data */
137 memcpy(skb_push(nskb, 1), &bt_cb(nskb)->pkt_type, 1);
139 if (sock_queue_rcv_skb(sk, nskb))
142 read_unlock(&hci_sk_list.lock);
145 static int hci_sock_release(struct socket *sock)
147 struct sock *sk = sock->sk;
148 struct hci_dev *hdev;
150 BT_DBG("sock %p sk %p", sock, sk);
155 hdev = hci_pi(sk)->hdev;
157 bt_sock_unlink(&hci_sk_list, sk);
160 atomic_dec(&hdev->promisc);
166 skb_queue_purge(&sk->sk_receive_queue);
167 skb_queue_purge(&sk->sk_write_queue);
173 /* Ioctls that require bound socket */
174 static inline int hci_sock_bound_ioctl(struct sock *sk, unsigned int cmd, unsigned long arg)
176 struct hci_dev *hdev = hci_pi(sk)->hdev;
183 if (!capable(CAP_NET_ADMIN))
186 if (test_bit(HCI_QUIRK_RAW_DEVICE, &hdev->quirks))
190 set_bit(HCI_RAW, &hdev->flags);
192 clear_bit(HCI_RAW, &hdev->flags);
197 if (!capable(CAP_NET_ADMIN))
201 set_bit(HCI_SECMGR, &hdev->flags);
203 clear_bit(HCI_SECMGR, &hdev->flags);
208 return hci_get_conn_info(hdev, (void __user *)arg);
212 return hdev->ioctl(hdev, cmd, arg);
217 static int hci_sock_ioctl(struct socket *sock, unsigned int cmd, unsigned long arg)
219 struct sock *sk = sock->sk;
220 void __user *argp = (void __user *)arg;
223 BT_DBG("cmd %x arg %lx", cmd, arg);
227 return hci_get_dev_list(argp);
230 return hci_get_dev_info(argp);
233 return hci_get_conn_list(argp);
236 if (!capable(CAP_NET_ADMIN))
238 return hci_dev_open(arg);
241 if (!capable(CAP_NET_ADMIN))
243 return hci_dev_close(arg);
246 if (!capable(CAP_NET_ADMIN))
248 return hci_dev_reset(arg);
251 if (!capable(CAP_NET_ADMIN))
253 return hci_dev_reset_stat(arg);
263 if (!capable(CAP_NET_ADMIN))
265 return hci_dev_cmd(cmd, argp);
268 return hci_inquiry(argp);
272 err = hci_sock_bound_ioctl(sk, cmd, arg);
278 static int hci_sock_bind(struct socket *sock, struct sockaddr *addr, int addr_len)
280 struct sockaddr_hci *haddr = (struct sockaddr_hci *) addr;
281 struct sock *sk = sock->sk;
282 struct hci_dev *hdev = NULL;
285 BT_DBG("sock %p sk %p", sock, sk);
287 if (!haddr || haddr->hci_family != AF_BLUETOOTH)
292 if (hci_pi(sk)->hdev) {
297 if (haddr->hci_dev != HCI_DEV_NONE) {
298 if (!(hdev = hci_dev_get(haddr->hci_dev))) {
303 atomic_inc(&hdev->promisc);
306 hci_pi(sk)->hdev = hdev;
307 sk->sk_state = BT_BOUND;
314 static int hci_sock_getname(struct socket *sock, struct sockaddr *addr, int *addr_len, int peer)
316 struct sockaddr_hci *haddr = (struct sockaddr_hci *) addr;
317 struct sock *sk = sock->sk;
318 struct hci_dev *hdev = hci_pi(sk)->hdev;
320 BT_DBG("sock %p sk %p", sock, sk);
327 *addr_len = sizeof(*haddr);
328 haddr->hci_family = AF_BLUETOOTH;
329 haddr->hci_dev = hdev->id;
335 static inline void hci_sock_cmsg(struct sock *sk, struct msghdr *msg, struct sk_buff *skb)
337 __u32 mask = hci_pi(sk)->cmsg_mask;
339 if (mask & HCI_CMSG_DIR) {
340 int incoming = bt_cb(skb)->incoming;
341 put_cmsg(msg, SOL_HCI, HCI_CMSG_DIR, sizeof(incoming), &incoming);
344 if (mask & HCI_CMSG_TSTAMP) {
349 skb_get_timestamp(skb, &tv);
351 if (msg->msg_flags & MSG_CMSG_COMPAT) {
352 struct compat_timeval ctv;
353 ctv.tv_sec = tv.tv_sec;
354 ctv.tv_usec = tv.tv_usec;
362 put_cmsg(msg, SOL_HCI, HCI_CMSG_TSTAMP, len, data);
366 static int hci_sock_recvmsg(struct kiocb *iocb, struct socket *sock,
367 struct msghdr *msg, size_t len, int flags)
369 int noblock = flags & MSG_DONTWAIT;
370 struct sock *sk = sock->sk;
374 BT_DBG("sock %p, sk %p", sock, sk);
376 if (flags & (MSG_OOB))
379 if (sk->sk_state == BT_CLOSED)
382 if (!(skb = skb_recv_datagram(sk, flags, noblock, &err)))
385 msg->msg_namelen = 0;
389 msg->msg_flags |= MSG_TRUNC;
393 skb_reset_transport_header(skb);
394 err = skb_copy_datagram_iovec(skb, 0, msg->msg_iov, copied);
396 hci_sock_cmsg(sk, msg, skb);
398 skb_free_datagram(sk, skb);
400 return err ? : copied;
403 static int hci_sock_sendmsg(struct kiocb *iocb, struct socket *sock,
404 struct msghdr *msg, size_t len)
406 struct sock *sk = sock->sk;
407 struct hci_dev *hdev;
411 BT_DBG("sock %p sk %p", sock, sk);
413 if (msg->msg_flags & MSG_OOB)
416 if (msg->msg_flags & ~(MSG_DONTWAIT|MSG_NOSIGNAL|MSG_ERRQUEUE))
419 if (len < 4 || len > HCI_MAX_FRAME_SIZE)
424 if (!(hdev = hci_pi(sk)->hdev)) {
429 if (!(skb = bt_skb_send_alloc(sk, len, msg->msg_flags & MSG_DONTWAIT, &err)))
432 if (memcpy_fromiovec(skb_put(skb, len), msg->msg_iov, len)) {
437 bt_cb(skb)->pkt_type = *((unsigned char *) skb->data);
439 skb->dev = (void *) hdev;
441 if (bt_cb(skb)->pkt_type == HCI_COMMAND_PKT) {
442 u16 opcode = __le16_to_cpu(get_unaligned((__le16 *) skb->data));
443 u16 ogf = hci_opcode_ogf(opcode);
444 u16 ocf = hci_opcode_ocf(opcode);
446 if (((ogf > HCI_SFLT_MAX_OGF) ||
447 !hci_test_bit(ocf & HCI_FLT_OCF_BITS, &hci_sec_filter.ocf_mask[ogf])) &&
448 !capable(CAP_NET_RAW)) {
453 if (test_bit(HCI_RAW, &hdev->flags) || (ogf == OGF_VENDOR_CMD)) {
454 skb_queue_tail(&hdev->raw_q, skb);
457 skb_queue_tail(&hdev->cmd_q, skb);
461 if (!capable(CAP_NET_RAW)) {
466 skb_queue_tail(&hdev->raw_q, skb);
481 static int hci_sock_setsockopt(struct socket *sock, int level, int optname, char __user *optval, int len)
483 struct hci_ufilter uf = { .opcode = 0 };
484 struct sock *sk = sock->sk;
485 int err = 0, opt = 0;
487 BT_DBG("sk %p, opt %d", sk, optname);
493 if (get_user(opt, (int __user *)optval)) {
499 hci_pi(sk)->cmsg_mask |= HCI_CMSG_DIR;
501 hci_pi(sk)->cmsg_mask &= ~HCI_CMSG_DIR;
505 if (get_user(opt, (int __user *)optval)) {
511 hci_pi(sk)->cmsg_mask |= HCI_CMSG_TSTAMP;
513 hci_pi(sk)->cmsg_mask &= ~HCI_CMSG_TSTAMP;
518 struct hci_filter *f = &hci_pi(sk)->filter;
520 uf.type_mask = f->type_mask;
521 uf.opcode = f->opcode;
522 uf.event_mask[0] = *((u32 *) f->event_mask + 0);
523 uf.event_mask[1] = *((u32 *) f->event_mask + 1);
526 len = min_t(unsigned int, len, sizeof(uf));
527 if (copy_from_user(&uf, optval, len)) {
532 if (!capable(CAP_NET_RAW)) {
533 uf.type_mask &= hci_sec_filter.type_mask;
534 uf.event_mask[0] &= *((u32 *) hci_sec_filter.event_mask + 0);
535 uf.event_mask[1] &= *((u32 *) hci_sec_filter.event_mask + 1);
539 struct hci_filter *f = &hci_pi(sk)->filter;
541 f->type_mask = uf.type_mask;
542 f->opcode = uf.opcode;
543 *((u32 *) f->event_mask + 0) = uf.event_mask[0];
544 *((u32 *) f->event_mask + 1) = uf.event_mask[1];
557 static int hci_sock_getsockopt(struct socket *sock, int level, int optname, char __user *optval, int __user *optlen)
559 struct hci_ufilter uf;
560 struct sock *sk = sock->sk;
563 if (get_user(len, optlen))
568 if (hci_pi(sk)->cmsg_mask & HCI_CMSG_DIR)
573 if (put_user(opt, optval))
578 if (hci_pi(sk)->cmsg_mask & HCI_CMSG_TSTAMP)
583 if (put_user(opt, optval))
589 struct hci_filter *f = &hci_pi(sk)->filter;
591 uf.type_mask = f->type_mask;
592 uf.opcode = f->opcode;
593 uf.event_mask[0] = *((u32 *) f->event_mask + 0);
594 uf.event_mask[1] = *((u32 *) f->event_mask + 1);
597 len = min_t(unsigned int, len, sizeof(uf));
598 if (copy_to_user(optval, &uf, len))
610 static const struct proto_ops hci_sock_ops = {
611 .family = PF_BLUETOOTH,
612 .owner = THIS_MODULE,
613 .release = hci_sock_release,
614 .bind = hci_sock_bind,
615 .getname = hci_sock_getname,
616 .sendmsg = hci_sock_sendmsg,
617 .recvmsg = hci_sock_recvmsg,
618 .ioctl = hci_sock_ioctl,
619 .poll = datagram_poll,
620 .listen = sock_no_listen,
621 .shutdown = sock_no_shutdown,
622 .setsockopt = hci_sock_setsockopt,
623 .getsockopt = hci_sock_getsockopt,
624 .connect = sock_no_connect,
625 .socketpair = sock_no_socketpair,
626 .accept = sock_no_accept,
630 static struct proto hci_sk_proto = {
632 .owner = THIS_MODULE,
633 .obj_size = sizeof(struct hci_pinfo)
636 static int hci_sock_create(struct socket *sock, int protocol)
640 BT_DBG("sock %p", sock);
642 if (sock->type != SOCK_RAW)
643 return -ESOCKTNOSUPPORT;
645 sock->ops = &hci_sock_ops;
647 sk = sk_alloc(PF_BLUETOOTH, GFP_ATOMIC, &hci_sk_proto, 1);
651 sock_init_data(sock, sk);
653 sock_reset_flag(sk, SOCK_ZAPPED);
655 sk->sk_protocol = protocol;
657 sock->state = SS_UNCONNECTED;
658 sk->sk_state = BT_OPEN;
660 bt_sock_link(&hci_sk_list, sk);
664 static int hci_sock_dev_event(struct notifier_block *this, unsigned long event, void *ptr)
666 struct hci_dev *hdev = (struct hci_dev *) ptr;
667 struct hci_ev_si_device ev;
669 BT_DBG("hdev %s event %ld", hdev->name, event);
671 /* Send event to sockets */
673 ev.dev_id = hdev->id;
674 hci_si_event(NULL, HCI_EV_SI_DEVICE, sizeof(ev), &ev);
676 if (event == HCI_DEV_UNREG) {
678 struct hlist_node *node;
680 /* Detach sockets from device */
681 read_lock(&hci_sk_list.lock);
682 sk_for_each(sk, node, &hci_sk_list.head) {
684 bh_lock_sock_nested(sk);
685 if (hci_pi(sk)->hdev == hdev) {
686 hci_pi(sk)->hdev = NULL;
688 sk->sk_state = BT_OPEN;
689 sk->sk_state_change(sk);
696 read_unlock(&hci_sk_list.lock);
702 static struct net_proto_family hci_sock_family_ops = {
703 .family = PF_BLUETOOTH,
704 .owner = THIS_MODULE,
705 .create = hci_sock_create,
708 static struct notifier_block hci_sock_nblock = {
709 .notifier_call = hci_sock_dev_event
712 int __init hci_sock_init(void)
716 err = proto_register(&hci_sk_proto, 0);
720 err = bt_sock_register(BTPROTO_HCI, &hci_sock_family_ops);
724 hci_register_notifier(&hci_sock_nblock);
726 BT_INFO("HCI socket layer initialized");
731 BT_ERR("HCI socket registration failed");
732 proto_unregister(&hci_sk_proto);
736 int __exit hci_sock_cleanup(void)
738 if (bt_sock_unregister(BTPROTO_HCI) < 0)
739 BT_ERR("HCI socket unregistration failed");
741 hci_unregister_notifier(&hci_sock_nblock);
743 proto_unregister(&hci_sk_proto);