18c2ecf20Sopenharmony_ci// SPDX-License-Identifier: GPL-2.0-only 28c2ecf20Sopenharmony_ci/* 38c2ecf20Sopenharmony_ci Copyright (c) 2011,2012 Intel Corp. 48c2ecf20Sopenharmony_ci 58c2ecf20Sopenharmony_ci*/ 68c2ecf20Sopenharmony_ci 78c2ecf20Sopenharmony_ci#include <net/bluetooth/bluetooth.h> 88c2ecf20Sopenharmony_ci#include <net/bluetooth/hci.h> 98c2ecf20Sopenharmony_ci#include <net/bluetooth/hci_core.h> 108c2ecf20Sopenharmony_ci#include <crypto/hash.h> 118c2ecf20Sopenharmony_ci 128c2ecf20Sopenharmony_ci#include "hci_request.h" 138c2ecf20Sopenharmony_ci#include "a2mp.h" 148c2ecf20Sopenharmony_ci#include "amp.h" 158c2ecf20Sopenharmony_ci 168c2ecf20Sopenharmony_ci/* Remote AMP Controllers interface */ 178c2ecf20Sopenharmony_civoid amp_ctrl_get(struct amp_ctrl *ctrl) 188c2ecf20Sopenharmony_ci{ 198c2ecf20Sopenharmony_ci BT_DBG("ctrl %p orig refcnt %d", ctrl, 208c2ecf20Sopenharmony_ci kref_read(&ctrl->kref)); 218c2ecf20Sopenharmony_ci 228c2ecf20Sopenharmony_ci kref_get(&ctrl->kref); 238c2ecf20Sopenharmony_ci} 248c2ecf20Sopenharmony_ci 258c2ecf20Sopenharmony_cistatic void amp_ctrl_destroy(struct kref *kref) 268c2ecf20Sopenharmony_ci{ 278c2ecf20Sopenharmony_ci struct amp_ctrl *ctrl = container_of(kref, struct amp_ctrl, kref); 288c2ecf20Sopenharmony_ci 298c2ecf20Sopenharmony_ci BT_DBG("ctrl %p", ctrl); 308c2ecf20Sopenharmony_ci 318c2ecf20Sopenharmony_ci kfree(ctrl->assoc); 328c2ecf20Sopenharmony_ci kfree(ctrl); 338c2ecf20Sopenharmony_ci} 348c2ecf20Sopenharmony_ci 358c2ecf20Sopenharmony_ciint amp_ctrl_put(struct amp_ctrl *ctrl) 368c2ecf20Sopenharmony_ci{ 378c2ecf20Sopenharmony_ci BT_DBG("ctrl %p orig refcnt %d", ctrl, 388c2ecf20Sopenharmony_ci kref_read(&ctrl->kref)); 398c2ecf20Sopenharmony_ci 408c2ecf20Sopenharmony_ci return kref_put(&ctrl->kref, &_ctrl_destroy); 418c2ecf20Sopenharmony_ci} 428c2ecf20Sopenharmony_ci 438c2ecf20Sopenharmony_cistruct amp_ctrl *amp_ctrl_add(struct amp_mgr *mgr, u8 id) 448c2ecf20Sopenharmony_ci{ 458c2ecf20Sopenharmony_ci struct amp_ctrl *ctrl; 468c2ecf20Sopenharmony_ci 478c2ecf20Sopenharmony_ci ctrl = kzalloc(sizeof(*ctrl), GFP_KERNEL); 488c2ecf20Sopenharmony_ci if (!ctrl) 498c2ecf20Sopenharmony_ci return NULL; 508c2ecf20Sopenharmony_ci 518c2ecf20Sopenharmony_ci kref_init(&ctrl->kref); 528c2ecf20Sopenharmony_ci ctrl->id = id; 538c2ecf20Sopenharmony_ci 548c2ecf20Sopenharmony_ci mutex_lock(&mgr->amp_ctrls_lock); 558c2ecf20Sopenharmony_ci list_add(&ctrl->list, &mgr->amp_ctrls); 568c2ecf20Sopenharmony_ci mutex_unlock(&mgr->amp_ctrls_lock); 578c2ecf20Sopenharmony_ci 588c2ecf20Sopenharmony_ci BT_DBG("mgr %p ctrl %p", mgr, ctrl); 598c2ecf20Sopenharmony_ci 608c2ecf20Sopenharmony_ci return ctrl; 618c2ecf20Sopenharmony_ci} 628c2ecf20Sopenharmony_ci 638c2ecf20Sopenharmony_civoid amp_ctrl_list_flush(struct amp_mgr *mgr) 648c2ecf20Sopenharmony_ci{ 658c2ecf20Sopenharmony_ci struct amp_ctrl *ctrl, *n; 668c2ecf20Sopenharmony_ci 678c2ecf20Sopenharmony_ci BT_DBG("mgr %p", mgr); 688c2ecf20Sopenharmony_ci 698c2ecf20Sopenharmony_ci mutex_lock(&mgr->amp_ctrls_lock); 708c2ecf20Sopenharmony_ci list_for_each_entry_safe(ctrl, n, &mgr->amp_ctrls, list) { 718c2ecf20Sopenharmony_ci list_del(&ctrl->list); 728c2ecf20Sopenharmony_ci amp_ctrl_put(ctrl); 738c2ecf20Sopenharmony_ci } 748c2ecf20Sopenharmony_ci mutex_unlock(&mgr->amp_ctrls_lock); 758c2ecf20Sopenharmony_ci} 768c2ecf20Sopenharmony_ci 778c2ecf20Sopenharmony_cistruct amp_ctrl *amp_ctrl_lookup(struct amp_mgr *mgr, u8 id) 788c2ecf20Sopenharmony_ci{ 798c2ecf20Sopenharmony_ci struct amp_ctrl *ctrl; 808c2ecf20Sopenharmony_ci 818c2ecf20Sopenharmony_ci BT_DBG("mgr %p id %d", mgr, id); 828c2ecf20Sopenharmony_ci 838c2ecf20Sopenharmony_ci mutex_lock(&mgr->amp_ctrls_lock); 848c2ecf20Sopenharmony_ci list_for_each_entry(ctrl, &mgr->amp_ctrls, list) { 858c2ecf20Sopenharmony_ci if (ctrl->id == id) { 868c2ecf20Sopenharmony_ci amp_ctrl_get(ctrl); 878c2ecf20Sopenharmony_ci mutex_unlock(&mgr->amp_ctrls_lock); 888c2ecf20Sopenharmony_ci return ctrl; 898c2ecf20Sopenharmony_ci } 908c2ecf20Sopenharmony_ci } 918c2ecf20Sopenharmony_ci mutex_unlock(&mgr->amp_ctrls_lock); 928c2ecf20Sopenharmony_ci 938c2ecf20Sopenharmony_ci return NULL; 948c2ecf20Sopenharmony_ci} 958c2ecf20Sopenharmony_ci 968c2ecf20Sopenharmony_ci/* Physical Link interface */ 978c2ecf20Sopenharmony_cistatic u8 __next_handle(struct amp_mgr *mgr) 988c2ecf20Sopenharmony_ci{ 998c2ecf20Sopenharmony_ci if (++mgr->handle == 0) 1008c2ecf20Sopenharmony_ci mgr->handle = 1; 1018c2ecf20Sopenharmony_ci 1028c2ecf20Sopenharmony_ci return mgr->handle; 1038c2ecf20Sopenharmony_ci} 1048c2ecf20Sopenharmony_ci 1058c2ecf20Sopenharmony_cistruct hci_conn *phylink_add(struct hci_dev *hdev, struct amp_mgr *mgr, 1068c2ecf20Sopenharmony_ci u8 remote_id, bool out) 1078c2ecf20Sopenharmony_ci{ 1088c2ecf20Sopenharmony_ci bdaddr_t *dst = &mgr->l2cap_conn->hcon->dst; 1098c2ecf20Sopenharmony_ci struct hci_conn *hcon; 1108c2ecf20Sopenharmony_ci u8 role = out ? HCI_ROLE_MASTER : HCI_ROLE_SLAVE; 1118c2ecf20Sopenharmony_ci 1128c2ecf20Sopenharmony_ci hcon = hci_conn_add(hdev, AMP_LINK, dst, role); 1138c2ecf20Sopenharmony_ci if (!hcon) 1148c2ecf20Sopenharmony_ci return NULL; 1158c2ecf20Sopenharmony_ci 1168c2ecf20Sopenharmony_ci BT_DBG("hcon %p dst %pMR", hcon, dst); 1178c2ecf20Sopenharmony_ci 1188c2ecf20Sopenharmony_ci hcon->state = BT_CONNECT; 1198c2ecf20Sopenharmony_ci hcon->attempt++; 1208c2ecf20Sopenharmony_ci hcon->handle = __next_handle(mgr); 1218c2ecf20Sopenharmony_ci hcon->remote_id = remote_id; 1228c2ecf20Sopenharmony_ci hcon->amp_mgr = amp_mgr_get(mgr); 1238c2ecf20Sopenharmony_ci 1248c2ecf20Sopenharmony_ci return hcon; 1258c2ecf20Sopenharmony_ci} 1268c2ecf20Sopenharmony_ci 1278c2ecf20Sopenharmony_ci/* AMP crypto key generation interface */ 1288c2ecf20Sopenharmony_cistatic int hmac_sha256(u8 *key, u8 ksize, char *plaintext, u8 psize, u8 *output) 1298c2ecf20Sopenharmony_ci{ 1308c2ecf20Sopenharmony_ci struct crypto_shash *tfm; 1318c2ecf20Sopenharmony_ci struct shash_desc *shash; 1328c2ecf20Sopenharmony_ci int ret; 1338c2ecf20Sopenharmony_ci 1348c2ecf20Sopenharmony_ci if (!ksize) 1358c2ecf20Sopenharmony_ci return -EINVAL; 1368c2ecf20Sopenharmony_ci 1378c2ecf20Sopenharmony_ci tfm = crypto_alloc_shash("hmac(sha256)", 0, 0); 1388c2ecf20Sopenharmony_ci if (IS_ERR(tfm)) { 1398c2ecf20Sopenharmony_ci BT_DBG("crypto_alloc_ahash failed: err %ld", PTR_ERR(tfm)); 1408c2ecf20Sopenharmony_ci return PTR_ERR(tfm); 1418c2ecf20Sopenharmony_ci } 1428c2ecf20Sopenharmony_ci 1438c2ecf20Sopenharmony_ci ret = crypto_shash_setkey(tfm, key, ksize); 1448c2ecf20Sopenharmony_ci if (ret) { 1458c2ecf20Sopenharmony_ci BT_DBG("crypto_ahash_setkey failed: err %d", ret); 1468c2ecf20Sopenharmony_ci goto failed; 1478c2ecf20Sopenharmony_ci } 1488c2ecf20Sopenharmony_ci 1498c2ecf20Sopenharmony_ci shash = kzalloc(sizeof(*shash) + crypto_shash_descsize(tfm), 1508c2ecf20Sopenharmony_ci GFP_KERNEL); 1518c2ecf20Sopenharmony_ci if (!shash) { 1528c2ecf20Sopenharmony_ci ret = -ENOMEM; 1538c2ecf20Sopenharmony_ci goto failed; 1548c2ecf20Sopenharmony_ci } 1558c2ecf20Sopenharmony_ci 1568c2ecf20Sopenharmony_ci shash->tfm = tfm; 1578c2ecf20Sopenharmony_ci 1588c2ecf20Sopenharmony_ci ret = crypto_shash_digest(shash, plaintext, psize, output); 1598c2ecf20Sopenharmony_ci 1608c2ecf20Sopenharmony_ci kfree(shash); 1618c2ecf20Sopenharmony_ci 1628c2ecf20Sopenharmony_cifailed: 1638c2ecf20Sopenharmony_ci crypto_free_shash(tfm); 1648c2ecf20Sopenharmony_ci return ret; 1658c2ecf20Sopenharmony_ci} 1668c2ecf20Sopenharmony_ci 1678c2ecf20Sopenharmony_ciint phylink_gen_key(struct hci_conn *conn, u8 *data, u8 *len, u8 *type) 1688c2ecf20Sopenharmony_ci{ 1698c2ecf20Sopenharmony_ci struct hci_dev *hdev = conn->hdev; 1708c2ecf20Sopenharmony_ci struct link_key *key; 1718c2ecf20Sopenharmony_ci u8 keybuf[HCI_AMP_LINK_KEY_SIZE]; 1728c2ecf20Sopenharmony_ci u8 gamp_key[HCI_AMP_LINK_KEY_SIZE]; 1738c2ecf20Sopenharmony_ci int err; 1748c2ecf20Sopenharmony_ci 1758c2ecf20Sopenharmony_ci if (!hci_conn_check_link_mode(conn)) 1768c2ecf20Sopenharmony_ci return -EACCES; 1778c2ecf20Sopenharmony_ci 1788c2ecf20Sopenharmony_ci BT_DBG("conn %p key_type %d", conn, conn->key_type); 1798c2ecf20Sopenharmony_ci 1808c2ecf20Sopenharmony_ci /* Legacy key */ 1818c2ecf20Sopenharmony_ci if (conn->key_type < 3) { 1828c2ecf20Sopenharmony_ci bt_dev_err(hdev, "legacy key type %d", conn->key_type); 1838c2ecf20Sopenharmony_ci return -EACCES; 1848c2ecf20Sopenharmony_ci } 1858c2ecf20Sopenharmony_ci 1868c2ecf20Sopenharmony_ci *type = conn->key_type; 1878c2ecf20Sopenharmony_ci *len = HCI_AMP_LINK_KEY_SIZE; 1888c2ecf20Sopenharmony_ci 1898c2ecf20Sopenharmony_ci key = hci_find_link_key(hdev, &conn->dst); 1908c2ecf20Sopenharmony_ci if (!key) { 1918c2ecf20Sopenharmony_ci BT_DBG("No Link key for conn %p dst %pMR", conn, &conn->dst); 1928c2ecf20Sopenharmony_ci return -EACCES; 1938c2ecf20Sopenharmony_ci } 1948c2ecf20Sopenharmony_ci 1958c2ecf20Sopenharmony_ci /* BR/EDR Link Key concatenated together with itself */ 1968c2ecf20Sopenharmony_ci memcpy(&keybuf[0], key->val, HCI_LINK_KEY_SIZE); 1978c2ecf20Sopenharmony_ci memcpy(&keybuf[HCI_LINK_KEY_SIZE], key->val, HCI_LINK_KEY_SIZE); 1988c2ecf20Sopenharmony_ci 1998c2ecf20Sopenharmony_ci /* Derive Generic AMP Link Key (gamp) */ 2008c2ecf20Sopenharmony_ci err = hmac_sha256(keybuf, HCI_AMP_LINK_KEY_SIZE, "gamp", 4, gamp_key); 2018c2ecf20Sopenharmony_ci if (err) { 2028c2ecf20Sopenharmony_ci bt_dev_err(hdev, "could not derive Generic AMP Key: err %d", err); 2038c2ecf20Sopenharmony_ci return err; 2048c2ecf20Sopenharmony_ci } 2058c2ecf20Sopenharmony_ci 2068c2ecf20Sopenharmony_ci if (conn->key_type == HCI_LK_DEBUG_COMBINATION) { 2078c2ecf20Sopenharmony_ci BT_DBG("Use Generic AMP Key (gamp)"); 2088c2ecf20Sopenharmony_ci memcpy(data, gamp_key, HCI_AMP_LINK_KEY_SIZE); 2098c2ecf20Sopenharmony_ci return err; 2108c2ecf20Sopenharmony_ci } 2118c2ecf20Sopenharmony_ci 2128c2ecf20Sopenharmony_ci /* Derive Dedicated AMP Link Key: "802b" is 802.11 PAL keyID */ 2138c2ecf20Sopenharmony_ci return hmac_sha256(gamp_key, HCI_AMP_LINK_KEY_SIZE, "802b", 4, data); 2148c2ecf20Sopenharmony_ci} 2158c2ecf20Sopenharmony_ci 2168c2ecf20Sopenharmony_cistatic void read_local_amp_assoc_complete(struct hci_dev *hdev, u8 status, 2178c2ecf20Sopenharmony_ci u16 opcode, struct sk_buff *skb) 2188c2ecf20Sopenharmony_ci{ 2198c2ecf20Sopenharmony_ci struct hci_rp_read_local_amp_assoc *rp = (void *)skb->data; 2208c2ecf20Sopenharmony_ci struct amp_assoc *assoc = &hdev->loc_assoc; 2218c2ecf20Sopenharmony_ci size_t rem_len, frag_len; 2228c2ecf20Sopenharmony_ci 2238c2ecf20Sopenharmony_ci BT_DBG("%s status 0x%2.2x", hdev->name, rp->status); 2248c2ecf20Sopenharmony_ci 2258c2ecf20Sopenharmony_ci if (rp->status) 2268c2ecf20Sopenharmony_ci goto send_rsp; 2278c2ecf20Sopenharmony_ci 2288c2ecf20Sopenharmony_ci frag_len = skb->len - sizeof(*rp); 2298c2ecf20Sopenharmony_ci rem_len = __le16_to_cpu(rp->rem_len); 2308c2ecf20Sopenharmony_ci 2318c2ecf20Sopenharmony_ci if (rem_len > frag_len) { 2328c2ecf20Sopenharmony_ci BT_DBG("frag_len %zu rem_len %zu", frag_len, rem_len); 2338c2ecf20Sopenharmony_ci 2348c2ecf20Sopenharmony_ci memcpy(assoc->data + assoc->offset, rp->frag, frag_len); 2358c2ecf20Sopenharmony_ci assoc->offset += frag_len; 2368c2ecf20Sopenharmony_ci 2378c2ecf20Sopenharmony_ci /* Read other fragments */ 2388c2ecf20Sopenharmony_ci amp_read_loc_assoc_frag(hdev, rp->phy_handle); 2398c2ecf20Sopenharmony_ci 2408c2ecf20Sopenharmony_ci return; 2418c2ecf20Sopenharmony_ci } 2428c2ecf20Sopenharmony_ci 2438c2ecf20Sopenharmony_ci memcpy(assoc->data + assoc->offset, rp->frag, rem_len); 2448c2ecf20Sopenharmony_ci assoc->len = assoc->offset + rem_len; 2458c2ecf20Sopenharmony_ci assoc->offset = 0; 2468c2ecf20Sopenharmony_ci 2478c2ecf20Sopenharmony_cisend_rsp: 2488c2ecf20Sopenharmony_ci /* Send A2MP Rsp when all fragments are received */ 2498c2ecf20Sopenharmony_ci a2mp_send_getampassoc_rsp(hdev, rp->status); 2508c2ecf20Sopenharmony_ci a2mp_send_create_phy_link_req(hdev, rp->status); 2518c2ecf20Sopenharmony_ci} 2528c2ecf20Sopenharmony_ci 2538c2ecf20Sopenharmony_civoid amp_read_loc_assoc_frag(struct hci_dev *hdev, u8 phy_handle) 2548c2ecf20Sopenharmony_ci{ 2558c2ecf20Sopenharmony_ci struct hci_cp_read_local_amp_assoc cp; 2568c2ecf20Sopenharmony_ci struct amp_assoc *loc_assoc = &hdev->loc_assoc; 2578c2ecf20Sopenharmony_ci struct hci_request req; 2588c2ecf20Sopenharmony_ci int err; 2598c2ecf20Sopenharmony_ci 2608c2ecf20Sopenharmony_ci BT_DBG("%s handle %d", hdev->name, phy_handle); 2618c2ecf20Sopenharmony_ci 2628c2ecf20Sopenharmony_ci cp.phy_handle = phy_handle; 2638c2ecf20Sopenharmony_ci cp.max_len = cpu_to_le16(hdev->amp_assoc_size); 2648c2ecf20Sopenharmony_ci cp.len_so_far = cpu_to_le16(loc_assoc->offset); 2658c2ecf20Sopenharmony_ci 2668c2ecf20Sopenharmony_ci hci_req_init(&req, hdev); 2678c2ecf20Sopenharmony_ci hci_req_add(&req, HCI_OP_READ_LOCAL_AMP_ASSOC, sizeof(cp), &cp); 2688c2ecf20Sopenharmony_ci err = hci_req_run_skb(&req, read_local_amp_assoc_complete); 2698c2ecf20Sopenharmony_ci if (err < 0) 2708c2ecf20Sopenharmony_ci a2mp_send_getampassoc_rsp(hdev, A2MP_STATUS_INVALID_CTRL_ID); 2718c2ecf20Sopenharmony_ci} 2728c2ecf20Sopenharmony_ci 2738c2ecf20Sopenharmony_civoid amp_read_loc_assoc(struct hci_dev *hdev, struct amp_mgr *mgr) 2748c2ecf20Sopenharmony_ci{ 2758c2ecf20Sopenharmony_ci struct hci_cp_read_local_amp_assoc cp; 2768c2ecf20Sopenharmony_ci struct hci_request req; 2778c2ecf20Sopenharmony_ci int err; 2788c2ecf20Sopenharmony_ci 2798c2ecf20Sopenharmony_ci memset(&hdev->loc_assoc, 0, sizeof(struct amp_assoc)); 2808c2ecf20Sopenharmony_ci memset(&cp, 0, sizeof(cp)); 2818c2ecf20Sopenharmony_ci 2828c2ecf20Sopenharmony_ci cp.max_len = cpu_to_le16(hdev->amp_assoc_size); 2838c2ecf20Sopenharmony_ci 2848c2ecf20Sopenharmony_ci set_bit(READ_LOC_AMP_ASSOC, &mgr->state); 2858c2ecf20Sopenharmony_ci hci_req_init(&req, hdev); 2868c2ecf20Sopenharmony_ci hci_req_add(&req, HCI_OP_READ_LOCAL_AMP_ASSOC, sizeof(cp), &cp); 2878c2ecf20Sopenharmony_ci err = hci_req_run_skb(&req, read_local_amp_assoc_complete); 2888c2ecf20Sopenharmony_ci if (err < 0) 2898c2ecf20Sopenharmony_ci a2mp_send_getampassoc_rsp(hdev, A2MP_STATUS_INVALID_CTRL_ID); 2908c2ecf20Sopenharmony_ci} 2918c2ecf20Sopenharmony_ci 2928c2ecf20Sopenharmony_civoid amp_read_loc_assoc_final_data(struct hci_dev *hdev, 2938c2ecf20Sopenharmony_ci struct hci_conn *hcon) 2948c2ecf20Sopenharmony_ci{ 2958c2ecf20Sopenharmony_ci struct hci_cp_read_local_amp_assoc cp; 2968c2ecf20Sopenharmony_ci struct amp_mgr *mgr = hcon->amp_mgr; 2978c2ecf20Sopenharmony_ci struct hci_request req; 2988c2ecf20Sopenharmony_ci int err; 2998c2ecf20Sopenharmony_ci 3008c2ecf20Sopenharmony_ci if (!mgr) 3018c2ecf20Sopenharmony_ci return; 3028c2ecf20Sopenharmony_ci 3038c2ecf20Sopenharmony_ci cp.phy_handle = hcon->handle; 3048c2ecf20Sopenharmony_ci cp.len_so_far = cpu_to_le16(0); 3058c2ecf20Sopenharmony_ci cp.max_len = cpu_to_le16(hdev->amp_assoc_size); 3068c2ecf20Sopenharmony_ci 3078c2ecf20Sopenharmony_ci set_bit(READ_LOC_AMP_ASSOC_FINAL, &mgr->state); 3088c2ecf20Sopenharmony_ci 3098c2ecf20Sopenharmony_ci /* Read Local AMP Assoc final link information data */ 3108c2ecf20Sopenharmony_ci hci_req_init(&req, hdev); 3118c2ecf20Sopenharmony_ci hci_req_add(&req, HCI_OP_READ_LOCAL_AMP_ASSOC, sizeof(cp), &cp); 3128c2ecf20Sopenharmony_ci err = hci_req_run_skb(&req, read_local_amp_assoc_complete); 3138c2ecf20Sopenharmony_ci if (err < 0) 3148c2ecf20Sopenharmony_ci a2mp_send_getampassoc_rsp(hdev, A2MP_STATUS_INVALID_CTRL_ID); 3158c2ecf20Sopenharmony_ci} 3168c2ecf20Sopenharmony_ci 3178c2ecf20Sopenharmony_cistatic void write_remote_amp_assoc_complete(struct hci_dev *hdev, u8 status, 3188c2ecf20Sopenharmony_ci u16 opcode, struct sk_buff *skb) 3198c2ecf20Sopenharmony_ci{ 3208c2ecf20Sopenharmony_ci struct hci_rp_write_remote_amp_assoc *rp = (void *)skb->data; 3218c2ecf20Sopenharmony_ci 3228c2ecf20Sopenharmony_ci BT_DBG("%s status 0x%2.2x phy_handle 0x%2.2x", 3238c2ecf20Sopenharmony_ci hdev->name, rp->status, rp->phy_handle); 3248c2ecf20Sopenharmony_ci 3258c2ecf20Sopenharmony_ci if (rp->status) 3268c2ecf20Sopenharmony_ci return; 3278c2ecf20Sopenharmony_ci 3288c2ecf20Sopenharmony_ci amp_write_rem_assoc_continue(hdev, rp->phy_handle); 3298c2ecf20Sopenharmony_ci} 3308c2ecf20Sopenharmony_ci 3318c2ecf20Sopenharmony_ci/* Write AMP Assoc data fragments, returns true with last fragment written*/ 3328c2ecf20Sopenharmony_cistatic bool amp_write_rem_assoc_frag(struct hci_dev *hdev, 3338c2ecf20Sopenharmony_ci struct hci_conn *hcon) 3348c2ecf20Sopenharmony_ci{ 3358c2ecf20Sopenharmony_ci struct hci_cp_write_remote_amp_assoc *cp; 3368c2ecf20Sopenharmony_ci struct amp_mgr *mgr = hcon->amp_mgr; 3378c2ecf20Sopenharmony_ci struct amp_ctrl *ctrl; 3388c2ecf20Sopenharmony_ci struct hci_request req; 3398c2ecf20Sopenharmony_ci u16 frag_len, len; 3408c2ecf20Sopenharmony_ci 3418c2ecf20Sopenharmony_ci ctrl = amp_ctrl_lookup(mgr, hcon->remote_id); 3428c2ecf20Sopenharmony_ci if (!ctrl) 3438c2ecf20Sopenharmony_ci return false; 3448c2ecf20Sopenharmony_ci 3458c2ecf20Sopenharmony_ci if (!ctrl->assoc_rem_len) { 3468c2ecf20Sopenharmony_ci BT_DBG("all fragments are written"); 3478c2ecf20Sopenharmony_ci ctrl->assoc_rem_len = ctrl->assoc_len; 3488c2ecf20Sopenharmony_ci ctrl->assoc_len_so_far = 0; 3498c2ecf20Sopenharmony_ci 3508c2ecf20Sopenharmony_ci amp_ctrl_put(ctrl); 3518c2ecf20Sopenharmony_ci return true; 3528c2ecf20Sopenharmony_ci } 3538c2ecf20Sopenharmony_ci 3548c2ecf20Sopenharmony_ci frag_len = min_t(u16, 248, ctrl->assoc_rem_len); 3558c2ecf20Sopenharmony_ci len = frag_len + sizeof(*cp); 3568c2ecf20Sopenharmony_ci 3578c2ecf20Sopenharmony_ci cp = kzalloc(len, GFP_KERNEL); 3588c2ecf20Sopenharmony_ci if (!cp) { 3598c2ecf20Sopenharmony_ci amp_ctrl_put(ctrl); 3608c2ecf20Sopenharmony_ci return false; 3618c2ecf20Sopenharmony_ci } 3628c2ecf20Sopenharmony_ci 3638c2ecf20Sopenharmony_ci BT_DBG("hcon %p ctrl %p frag_len %u assoc_len %u rem_len %u", 3648c2ecf20Sopenharmony_ci hcon, ctrl, frag_len, ctrl->assoc_len, ctrl->assoc_rem_len); 3658c2ecf20Sopenharmony_ci 3668c2ecf20Sopenharmony_ci cp->phy_handle = hcon->handle; 3678c2ecf20Sopenharmony_ci cp->len_so_far = cpu_to_le16(ctrl->assoc_len_so_far); 3688c2ecf20Sopenharmony_ci cp->rem_len = cpu_to_le16(ctrl->assoc_rem_len); 3698c2ecf20Sopenharmony_ci memcpy(cp->frag, ctrl->assoc, frag_len); 3708c2ecf20Sopenharmony_ci 3718c2ecf20Sopenharmony_ci ctrl->assoc_len_so_far += frag_len; 3728c2ecf20Sopenharmony_ci ctrl->assoc_rem_len -= frag_len; 3738c2ecf20Sopenharmony_ci 3748c2ecf20Sopenharmony_ci amp_ctrl_put(ctrl); 3758c2ecf20Sopenharmony_ci 3768c2ecf20Sopenharmony_ci hci_req_init(&req, hdev); 3778c2ecf20Sopenharmony_ci hci_req_add(&req, HCI_OP_WRITE_REMOTE_AMP_ASSOC, len, cp); 3788c2ecf20Sopenharmony_ci hci_req_run_skb(&req, write_remote_amp_assoc_complete); 3798c2ecf20Sopenharmony_ci 3808c2ecf20Sopenharmony_ci kfree(cp); 3818c2ecf20Sopenharmony_ci 3828c2ecf20Sopenharmony_ci return false; 3838c2ecf20Sopenharmony_ci} 3848c2ecf20Sopenharmony_ci 3858c2ecf20Sopenharmony_civoid amp_write_rem_assoc_continue(struct hci_dev *hdev, u8 handle) 3868c2ecf20Sopenharmony_ci{ 3878c2ecf20Sopenharmony_ci struct hci_conn *hcon; 3888c2ecf20Sopenharmony_ci 3898c2ecf20Sopenharmony_ci BT_DBG("%s phy handle 0x%2.2x", hdev->name, handle); 3908c2ecf20Sopenharmony_ci 3918c2ecf20Sopenharmony_ci hcon = hci_conn_hash_lookup_handle(hdev, handle); 3928c2ecf20Sopenharmony_ci if (!hcon) 3938c2ecf20Sopenharmony_ci return; 3948c2ecf20Sopenharmony_ci 3958c2ecf20Sopenharmony_ci /* Send A2MP create phylink rsp when all fragments are written */ 3968c2ecf20Sopenharmony_ci if (amp_write_rem_assoc_frag(hdev, hcon)) 3978c2ecf20Sopenharmony_ci a2mp_send_create_phy_link_rsp(hdev, 0); 3988c2ecf20Sopenharmony_ci} 3998c2ecf20Sopenharmony_ci 4008c2ecf20Sopenharmony_civoid amp_write_remote_assoc(struct hci_dev *hdev, u8 handle) 4018c2ecf20Sopenharmony_ci{ 4028c2ecf20Sopenharmony_ci struct hci_conn *hcon; 4038c2ecf20Sopenharmony_ci 4048c2ecf20Sopenharmony_ci BT_DBG("%s phy handle 0x%2.2x", hdev->name, handle); 4058c2ecf20Sopenharmony_ci 4068c2ecf20Sopenharmony_ci hcon = hci_conn_hash_lookup_handle(hdev, handle); 4078c2ecf20Sopenharmony_ci if (!hcon) 4088c2ecf20Sopenharmony_ci return; 4098c2ecf20Sopenharmony_ci 4108c2ecf20Sopenharmony_ci BT_DBG("%s phy handle 0x%2.2x hcon %p", hdev->name, handle, hcon); 4118c2ecf20Sopenharmony_ci 4128c2ecf20Sopenharmony_ci amp_write_rem_assoc_frag(hdev, hcon); 4138c2ecf20Sopenharmony_ci} 4148c2ecf20Sopenharmony_ci 4158c2ecf20Sopenharmony_cistatic void create_phylink_complete(struct hci_dev *hdev, u8 status, 4168c2ecf20Sopenharmony_ci u16 opcode) 4178c2ecf20Sopenharmony_ci{ 4188c2ecf20Sopenharmony_ci struct hci_cp_create_phy_link *cp; 4198c2ecf20Sopenharmony_ci 4208c2ecf20Sopenharmony_ci BT_DBG("%s status 0x%2.2x", hdev->name, status); 4218c2ecf20Sopenharmony_ci 4228c2ecf20Sopenharmony_ci cp = hci_sent_cmd_data(hdev, HCI_OP_CREATE_PHY_LINK); 4238c2ecf20Sopenharmony_ci if (!cp) 4248c2ecf20Sopenharmony_ci return; 4258c2ecf20Sopenharmony_ci 4268c2ecf20Sopenharmony_ci hci_dev_lock(hdev); 4278c2ecf20Sopenharmony_ci 4288c2ecf20Sopenharmony_ci if (status) { 4298c2ecf20Sopenharmony_ci struct hci_conn *hcon; 4308c2ecf20Sopenharmony_ci 4318c2ecf20Sopenharmony_ci hcon = hci_conn_hash_lookup_handle(hdev, cp->phy_handle); 4328c2ecf20Sopenharmony_ci if (hcon) 4338c2ecf20Sopenharmony_ci hci_conn_del(hcon); 4348c2ecf20Sopenharmony_ci } else { 4358c2ecf20Sopenharmony_ci amp_write_remote_assoc(hdev, cp->phy_handle); 4368c2ecf20Sopenharmony_ci } 4378c2ecf20Sopenharmony_ci 4388c2ecf20Sopenharmony_ci hci_dev_unlock(hdev); 4398c2ecf20Sopenharmony_ci} 4408c2ecf20Sopenharmony_ci 4418c2ecf20Sopenharmony_civoid amp_create_phylink(struct hci_dev *hdev, struct amp_mgr *mgr, 4428c2ecf20Sopenharmony_ci struct hci_conn *hcon) 4438c2ecf20Sopenharmony_ci{ 4448c2ecf20Sopenharmony_ci struct hci_cp_create_phy_link cp; 4458c2ecf20Sopenharmony_ci struct hci_request req; 4468c2ecf20Sopenharmony_ci 4478c2ecf20Sopenharmony_ci cp.phy_handle = hcon->handle; 4488c2ecf20Sopenharmony_ci 4498c2ecf20Sopenharmony_ci BT_DBG("%s hcon %p phy handle 0x%2.2x", hdev->name, hcon, 4508c2ecf20Sopenharmony_ci hcon->handle); 4518c2ecf20Sopenharmony_ci 4528c2ecf20Sopenharmony_ci if (phylink_gen_key(mgr->l2cap_conn->hcon, cp.key, &cp.key_len, 4538c2ecf20Sopenharmony_ci &cp.key_type)) { 4548c2ecf20Sopenharmony_ci BT_DBG("Cannot create link key"); 4558c2ecf20Sopenharmony_ci return; 4568c2ecf20Sopenharmony_ci } 4578c2ecf20Sopenharmony_ci 4588c2ecf20Sopenharmony_ci hci_req_init(&req, hdev); 4598c2ecf20Sopenharmony_ci hci_req_add(&req, HCI_OP_CREATE_PHY_LINK, sizeof(cp), &cp); 4608c2ecf20Sopenharmony_ci hci_req_run(&req, create_phylink_complete); 4618c2ecf20Sopenharmony_ci} 4628c2ecf20Sopenharmony_ci 4638c2ecf20Sopenharmony_cistatic void accept_phylink_complete(struct hci_dev *hdev, u8 status, 4648c2ecf20Sopenharmony_ci u16 opcode) 4658c2ecf20Sopenharmony_ci{ 4668c2ecf20Sopenharmony_ci struct hci_cp_accept_phy_link *cp; 4678c2ecf20Sopenharmony_ci 4688c2ecf20Sopenharmony_ci BT_DBG("%s status 0x%2.2x", hdev->name, status); 4698c2ecf20Sopenharmony_ci 4708c2ecf20Sopenharmony_ci if (status) 4718c2ecf20Sopenharmony_ci return; 4728c2ecf20Sopenharmony_ci 4738c2ecf20Sopenharmony_ci cp = hci_sent_cmd_data(hdev, HCI_OP_ACCEPT_PHY_LINK); 4748c2ecf20Sopenharmony_ci if (!cp) 4758c2ecf20Sopenharmony_ci return; 4768c2ecf20Sopenharmony_ci 4778c2ecf20Sopenharmony_ci amp_write_remote_assoc(hdev, cp->phy_handle); 4788c2ecf20Sopenharmony_ci} 4798c2ecf20Sopenharmony_ci 4808c2ecf20Sopenharmony_civoid amp_accept_phylink(struct hci_dev *hdev, struct amp_mgr *mgr, 4818c2ecf20Sopenharmony_ci struct hci_conn *hcon) 4828c2ecf20Sopenharmony_ci{ 4838c2ecf20Sopenharmony_ci struct hci_cp_accept_phy_link cp; 4848c2ecf20Sopenharmony_ci struct hci_request req; 4858c2ecf20Sopenharmony_ci 4868c2ecf20Sopenharmony_ci cp.phy_handle = hcon->handle; 4878c2ecf20Sopenharmony_ci 4888c2ecf20Sopenharmony_ci BT_DBG("%s hcon %p phy handle 0x%2.2x", hdev->name, hcon, 4898c2ecf20Sopenharmony_ci hcon->handle); 4908c2ecf20Sopenharmony_ci 4918c2ecf20Sopenharmony_ci if (phylink_gen_key(mgr->l2cap_conn->hcon, cp.key, &cp.key_len, 4928c2ecf20Sopenharmony_ci &cp.key_type)) { 4938c2ecf20Sopenharmony_ci BT_DBG("Cannot create link key"); 4948c2ecf20Sopenharmony_ci return; 4958c2ecf20Sopenharmony_ci } 4968c2ecf20Sopenharmony_ci 4978c2ecf20Sopenharmony_ci hci_req_init(&req, hdev); 4988c2ecf20Sopenharmony_ci hci_req_add(&req, HCI_OP_ACCEPT_PHY_LINK, sizeof(cp), &cp); 4998c2ecf20Sopenharmony_ci hci_req_run(&req, accept_phylink_complete); 5008c2ecf20Sopenharmony_ci} 5018c2ecf20Sopenharmony_ci 5028c2ecf20Sopenharmony_civoid amp_physical_cfm(struct hci_conn *bredr_hcon, struct hci_conn *hs_hcon) 5038c2ecf20Sopenharmony_ci{ 5048c2ecf20Sopenharmony_ci struct hci_dev *bredr_hdev = hci_dev_hold(bredr_hcon->hdev); 5058c2ecf20Sopenharmony_ci struct amp_mgr *mgr = hs_hcon->amp_mgr; 5068c2ecf20Sopenharmony_ci struct l2cap_chan *bredr_chan; 5078c2ecf20Sopenharmony_ci 5088c2ecf20Sopenharmony_ci BT_DBG("bredr_hcon %p hs_hcon %p mgr %p", bredr_hcon, hs_hcon, mgr); 5098c2ecf20Sopenharmony_ci 5108c2ecf20Sopenharmony_ci if (!bredr_hdev || !mgr || !mgr->bredr_chan) 5118c2ecf20Sopenharmony_ci return; 5128c2ecf20Sopenharmony_ci 5138c2ecf20Sopenharmony_ci bredr_chan = mgr->bredr_chan; 5148c2ecf20Sopenharmony_ci 5158c2ecf20Sopenharmony_ci l2cap_chan_lock(bredr_chan); 5168c2ecf20Sopenharmony_ci 5178c2ecf20Sopenharmony_ci set_bit(FLAG_EFS_ENABLE, &bredr_chan->flags); 5188c2ecf20Sopenharmony_ci bredr_chan->remote_amp_id = hs_hcon->remote_id; 5198c2ecf20Sopenharmony_ci bredr_chan->local_amp_id = hs_hcon->hdev->id; 5208c2ecf20Sopenharmony_ci bredr_chan->hs_hcon = hs_hcon; 5218c2ecf20Sopenharmony_ci bredr_chan->conn->mtu = hs_hcon->hdev->block_mtu; 5228c2ecf20Sopenharmony_ci 5238c2ecf20Sopenharmony_ci __l2cap_physical_cfm(bredr_chan, 0); 5248c2ecf20Sopenharmony_ci 5258c2ecf20Sopenharmony_ci l2cap_chan_unlock(bredr_chan); 5268c2ecf20Sopenharmony_ci 5278c2ecf20Sopenharmony_ci hci_dev_put(bredr_hdev); 5288c2ecf20Sopenharmony_ci} 5298c2ecf20Sopenharmony_ci 5308c2ecf20Sopenharmony_civoid amp_create_logical_link(struct l2cap_chan *chan) 5318c2ecf20Sopenharmony_ci{ 5328c2ecf20Sopenharmony_ci struct hci_conn *hs_hcon = chan->hs_hcon; 5338c2ecf20Sopenharmony_ci struct hci_cp_create_accept_logical_link cp; 5348c2ecf20Sopenharmony_ci struct hci_dev *hdev; 5358c2ecf20Sopenharmony_ci 5368c2ecf20Sopenharmony_ci BT_DBG("chan %p hs_hcon %p dst %pMR", chan, hs_hcon, 5378c2ecf20Sopenharmony_ci &chan->conn->hcon->dst); 5388c2ecf20Sopenharmony_ci 5398c2ecf20Sopenharmony_ci if (!hs_hcon) 5408c2ecf20Sopenharmony_ci return; 5418c2ecf20Sopenharmony_ci 5428c2ecf20Sopenharmony_ci hdev = hci_dev_hold(chan->hs_hcon->hdev); 5438c2ecf20Sopenharmony_ci if (!hdev) 5448c2ecf20Sopenharmony_ci return; 5458c2ecf20Sopenharmony_ci 5468c2ecf20Sopenharmony_ci cp.phy_handle = hs_hcon->handle; 5478c2ecf20Sopenharmony_ci 5488c2ecf20Sopenharmony_ci cp.tx_flow_spec.id = chan->local_id; 5498c2ecf20Sopenharmony_ci cp.tx_flow_spec.stype = chan->local_stype; 5508c2ecf20Sopenharmony_ci cp.tx_flow_spec.msdu = cpu_to_le16(chan->local_msdu); 5518c2ecf20Sopenharmony_ci cp.tx_flow_spec.sdu_itime = cpu_to_le32(chan->local_sdu_itime); 5528c2ecf20Sopenharmony_ci cp.tx_flow_spec.acc_lat = cpu_to_le32(chan->local_acc_lat); 5538c2ecf20Sopenharmony_ci cp.tx_flow_spec.flush_to = cpu_to_le32(chan->local_flush_to); 5548c2ecf20Sopenharmony_ci 5558c2ecf20Sopenharmony_ci cp.rx_flow_spec.id = chan->remote_id; 5568c2ecf20Sopenharmony_ci cp.rx_flow_spec.stype = chan->remote_stype; 5578c2ecf20Sopenharmony_ci cp.rx_flow_spec.msdu = cpu_to_le16(chan->remote_msdu); 5588c2ecf20Sopenharmony_ci cp.rx_flow_spec.sdu_itime = cpu_to_le32(chan->remote_sdu_itime); 5598c2ecf20Sopenharmony_ci cp.rx_flow_spec.acc_lat = cpu_to_le32(chan->remote_acc_lat); 5608c2ecf20Sopenharmony_ci cp.rx_flow_spec.flush_to = cpu_to_le32(chan->remote_flush_to); 5618c2ecf20Sopenharmony_ci 5628c2ecf20Sopenharmony_ci if (hs_hcon->out) 5638c2ecf20Sopenharmony_ci hci_send_cmd(hdev, HCI_OP_CREATE_LOGICAL_LINK, sizeof(cp), 5648c2ecf20Sopenharmony_ci &cp); 5658c2ecf20Sopenharmony_ci else 5668c2ecf20Sopenharmony_ci hci_send_cmd(hdev, HCI_OP_ACCEPT_LOGICAL_LINK, sizeof(cp), 5678c2ecf20Sopenharmony_ci &cp); 5688c2ecf20Sopenharmony_ci 5698c2ecf20Sopenharmony_ci hci_dev_put(hdev); 5708c2ecf20Sopenharmony_ci} 5718c2ecf20Sopenharmony_ci 5728c2ecf20Sopenharmony_civoid amp_disconnect_logical_link(struct hci_chan *hchan) 5738c2ecf20Sopenharmony_ci{ 5748c2ecf20Sopenharmony_ci struct hci_conn *hcon = hchan->conn; 5758c2ecf20Sopenharmony_ci struct hci_cp_disconn_logical_link cp; 5768c2ecf20Sopenharmony_ci 5778c2ecf20Sopenharmony_ci if (hcon->state != BT_CONNECTED) { 5788c2ecf20Sopenharmony_ci BT_DBG("hchan %p not connected", hchan); 5798c2ecf20Sopenharmony_ci return; 5808c2ecf20Sopenharmony_ci } 5818c2ecf20Sopenharmony_ci 5828c2ecf20Sopenharmony_ci cp.log_handle = cpu_to_le16(hchan->handle); 5838c2ecf20Sopenharmony_ci hci_send_cmd(hcon->hdev, HCI_OP_DISCONN_LOGICAL_LINK, sizeof(cp), &cp); 5848c2ecf20Sopenharmony_ci} 5858c2ecf20Sopenharmony_ci 5868c2ecf20Sopenharmony_civoid amp_destroy_logical_link(struct hci_chan *hchan, u8 reason) 5878c2ecf20Sopenharmony_ci{ 5888c2ecf20Sopenharmony_ci BT_DBG("hchan %p", hchan); 5898c2ecf20Sopenharmony_ci 5908c2ecf20Sopenharmony_ci hci_chan_del(hchan); 5918c2ecf20Sopenharmony_ci} 592