18c2ecf20Sopenharmony_ci// SPDX-License-Identifier: GPL-2.0-or-later 28c2ecf20Sopenharmony_ci/* 38c2ecf20Sopenharmony_ci * Copyright (C) 2011 Intel Corporation. All rights reserved. 48c2ecf20Sopenharmony_ci * Copyright (C) 2014 Marvell International Ltd. 58c2ecf20Sopenharmony_ci */ 68c2ecf20Sopenharmony_ci 78c2ecf20Sopenharmony_ci#define pr_fmt(fmt) "llcp: %s: " fmt, __func__ 88c2ecf20Sopenharmony_ci 98c2ecf20Sopenharmony_ci#include <linux/init.h> 108c2ecf20Sopenharmony_ci#include <linux/kernel.h> 118c2ecf20Sopenharmony_ci#include <linux/list.h> 128c2ecf20Sopenharmony_ci#include <linux/nfc.h> 138c2ecf20Sopenharmony_ci 148c2ecf20Sopenharmony_ci#include "nfc.h" 158c2ecf20Sopenharmony_ci#include "llcp.h" 168c2ecf20Sopenharmony_ci 178c2ecf20Sopenharmony_cistatic u8 llcp_magic[3] = {0x46, 0x66, 0x6d}; 188c2ecf20Sopenharmony_ci 198c2ecf20Sopenharmony_cistatic LIST_HEAD(llcp_devices); 208c2ecf20Sopenharmony_ci/* Protects llcp_devices list */ 218c2ecf20Sopenharmony_cistatic DEFINE_SPINLOCK(llcp_devices_lock); 228c2ecf20Sopenharmony_ci 238c2ecf20Sopenharmony_cistatic void nfc_llcp_rx_skb(struct nfc_llcp_local *local, struct sk_buff *skb); 248c2ecf20Sopenharmony_ci 258c2ecf20Sopenharmony_civoid nfc_llcp_sock_link(struct llcp_sock_list *l, struct sock *sk) 268c2ecf20Sopenharmony_ci{ 278c2ecf20Sopenharmony_ci write_lock(&l->lock); 288c2ecf20Sopenharmony_ci sk_add_node(sk, &l->head); 298c2ecf20Sopenharmony_ci write_unlock(&l->lock); 308c2ecf20Sopenharmony_ci} 318c2ecf20Sopenharmony_ci 328c2ecf20Sopenharmony_civoid nfc_llcp_sock_unlink(struct llcp_sock_list *l, struct sock *sk) 338c2ecf20Sopenharmony_ci{ 348c2ecf20Sopenharmony_ci write_lock(&l->lock); 358c2ecf20Sopenharmony_ci sk_del_node_init(sk); 368c2ecf20Sopenharmony_ci write_unlock(&l->lock); 378c2ecf20Sopenharmony_ci} 388c2ecf20Sopenharmony_ci 398c2ecf20Sopenharmony_civoid nfc_llcp_socket_remote_param_init(struct nfc_llcp_sock *sock) 408c2ecf20Sopenharmony_ci{ 418c2ecf20Sopenharmony_ci sock->remote_rw = LLCP_DEFAULT_RW; 428c2ecf20Sopenharmony_ci sock->remote_miu = LLCP_MAX_MIU + 1; 438c2ecf20Sopenharmony_ci} 448c2ecf20Sopenharmony_ci 458c2ecf20Sopenharmony_cistatic void nfc_llcp_socket_purge(struct nfc_llcp_sock *sock) 468c2ecf20Sopenharmony_ci{ 478c2ecf20Sopenharmony_ci struct nfc_llcp_local *local = sock->local; 488c2ecf20Sopenharmony_ci struct sk_buff *s, *tmp; 498c2ecf20Sopenharmony_ci 508c2ecf20Sopenharmony_ci pr_debug("%p\n", &sock->sk); 518c2ecf20Sopenharmony_ci 528c2ecf20Sopenharmony_ci skb_queue_purge(&sock->tx_queue); 538c2ecf20Sopenharmony_ci skb_queue_purge(&sock->tx_pending_queue); 548c2ecf20Sopenharmony_ci 558c2ecf20Sopenharmony_ci if (local == NULL) 568c2ecf20Sopenharmony_ci return; 578c2ecf20Sopenharmony_ci 588c2ecf20Sopenharmony_ci /* Search for local pending SKBs that are related to this socket */ 598c2ecf20Sopenharmony_ci skb_queue_walk_safe(&local->tx_queue, s, tmp) { 608c2ecf20Sopenharmony_ci if (s->sk != &sock->sk) 618c2ecf20Sopenharmony_ci continue; 628c2ecf20Sopenharmony_ci 638c2ecf20Sopenharmony_ci skb_unlink(s, &local->tx_queue); 648c2ecf20Sopenharmony_ci kfree_skb(s); 658c2ecf20Sopenharmony_ci } 668c2ecf20Sopenharmony_ci} 678c2ecf20Sopenharmony_ci 688c2ecf20Sopenharmony_cistatic void nfc_llcp_socket_release(struct nfc_llcp_local *local, bool device, 698c2ecf20Sopenharmony_ci int err) 708c2ecf20Sopenharmony_ci{ 718c2ecf20Sopenharmony_ci struct sock *sk; 728c2ecf20Sopenharmony_ci struct hlist_node *tmp; 738c2ecf20Sopenharmony_ci struct nfc_llcp_sock *llcp_sock; 748c2ecf20Sopenharmony_ci 758c2ecf20Sopenharmony_ci skb_queue_purge(&local->tx_queue); 768c2ecf20Sopenharmony_ci 778c2ecf20Sopenharmony_ci write_lock(&local->sockets.lock); 788c2ecf20Sopenharmony_ci 798c2ecf20Sopenharmony_ci sk_for_each_safe(sk, tmp, &local->sockets.head) { 808c2ecf20Sopenharmony_ci llcp_sock = nfc_llcp_sock(sk); 818c2ecf20Sopenharmony_ci 828c2ecf20Sopenharmony_ci bh_lock_sock(sk); 838c2ecf20Sopenharmony_ci 848c2ecf20Sopenharmony_ci nfc_llcp_socket_purge(llcp_sock); 858c2ecf20Sopenharmony_ci 868c2ecf20Sopenharmony_ci if (sk->sk_state == LLCP_CONNECTED) 878c2ecf20Sopenharmony_ci nfc_put_device(llcp_sock->dev); 888c2ecf20Sopenharmony_ci 898c2ecf20Sopenharmony_ci if (sk->sk_state == LLCP_LISTEN) { 908c2ecf20Sopenharmony_ci struct nfc_llcp_sock *lsk, *n; 918c2ecf20Sopenharmony_ci struct sock *accept_sk; 928c2ecf20Sopenharmony_ci 938c2ecf20Sopenharmony_ci list_for_each_entry_safe(lsk, n, 948c2ecf20Sopenharmony_ci &llcp_sock->accept_queue, 958c2ecf20Sopenharmony_ci accept_queue) { 968c2ecf20Sopenharmony_ci accept_sk = &lsk->sk; 978c2ecf20Sopenharmony_ci bh_lock_sock(accept_sk); 988c2ecf20Sopenharmony_ci 998c2ecf20Sopenharmony_ci nfc_llcp_accept_unlink(accept_sk); 1008c2ecf20Sopenharmony_ci 1018c2ecf20Sopenharmony_ci if (err) 1028c2ecf20Sopenharmony_ci accept_sk->sk_err = err; 1038c2ecf20Sopenharmony_ci accept_sk->sk_state = LLCP_CLOSED; 1048c2ecf20Sopenharmony_ci accept_sk->sk_state_change(sk); 1058c2ecf20Sopenharmony_ci 1068c2ecf20Sopenharmony_ci bh_unlock_sock(accept_sk); 1078c2ecf20Sopenharmony_ci } 1088c2ecf20Sopenharmony_ci } 1098c2ecf20Sopenharmony_ci 1108c2ecf20Sopenharmony_ci if (err) 1118c2ecf20Sopenharmony_ci sk->sk_err = err; 1128c2ecf20Sopenharmony_ci sk->sk_state = LLCP_CLOSED; 1138c2ecf20Sopenharmony_ci sk->sk_state_change(sk); 1148c2ecf20Sopenharmony_ci 1158c2ecf20Sopenharmony_ci bh_unlock_sock(sk); 1168c2ecf20Sopenharmony_ci 1178c2ecf20Sopenharmony_ci sk_del_node_init(sk); 1188c2ecf20Sopenharmony_ci } 1198c2ecf20Sopenharmony_ci 1208c2ecf20Sopenharmony_ci write_unlock(&local->sockets.lock); 1218c2ecf20Sopenharmony_ci 1228c2ecf20Sopenharmony_ci /* If we still have a device, we keep the RAW sockets alive */ 1238c2ecf20Sopenharmony_ci if (device == true) 1248c2ecf20Sopenharmony_ci return; 1258c2ecf20Sopenharmony_ci 1268c2ecf20Sopenharmony_ci write_lock(&local->raw_sockets.lock); 1278c2ecf20Sopenharmony_ci 1288c2ecf20Sopenharmony_ci sk_for_each_safe(sk, tmp, &local->raw_sockets.head) { 1298c2ecf20Sopenharmony_ci llcp_sock = nfc_llcp_sock(sk); 1308c2ecf20Sopenharmony_ci 1318c2ecf20Sopenharmony_ci bh_lock_sock(sk); 1328c2ecf20Sopenharmony_ci 1338c2ecf20Sopenharmony_ci nfc_llcp_socket_purge(llcp_sock); 1348c2ecf20Sopenharmony_ci 1358c2ecf20Sopenharmony_ci if (err) 1368c2ecf20Sopenharmony_ci sk->sk_err = err; 1378c2ecf20Sopenharmony_ci sk->sk_state = LLCP_CLOSED; 1388c2ecf20Sopenharmony_ci sk->sk_state_change(sk); 1398c2ecf20Sopenharmony_ci 1408c2ecf20Sopenharmony_ci bh_unlock_sock(sk); 1418c2ecf20Sopenharmony_ci 1428c2ecf20Sopenharmony_ci sk_del_node_init(sk); 1438c2ecf20Sopenharmony_ci } 1448c2ecf20Sopenharmony_ci 1458c2ecf20Sopenharmony_ci write_unlock(&local->raw_sockets.lock); 1468c2ecf20Sopenharmony_ci} 1478c2ecf20Sopenharmony_ci 1488c2ecf20Sopenharmony_cistatic struct nfc_llcp_local *nfc_llcp_local_get(struct nfc_llcp_local *local) 1498c2ecf20Sopenharmony_ci{ 1508c2ecf20Sopenharmony_ci /* Since using nfc_llcp_local may result in usage of nfc_dev, whenever 1518c2ecf20Sopenharmony_ci * we hold a reference to local, we also need to hold a reference to 1528c2ecf20Sopenharmony_ci * the device to avoid UAF. 1538c2ecf20Sopenharmony_ci */ 1548c2ecf20Sopenharmony_ci if (!nfc_get_device(local->dev->idx)) 1558c2ecf20Sopenharmony_ci return NULL; 1568c2ecf20Sopenharmony_ci 1578c2ecf20Sopenharmony_ci kref_get(&local->ref); 1588c2ecf20Sopenharmony_ci 1598c2ecf20Sopenharmony_ci return local; 1608c2ecf20Sopenharmony_ci} 1618c2ecf20Sopenharmony_ci 1628c2ecf20Sopenharmony_cistatic void local_cleanup(struct nfc_llcp_local *local) 1638c2ecf20Sopenharmony_ci{ 1648c2ecf20Sopenharmony_ci nfc_llcp_socket_release(local, false, ENXIO); 1658c2ecf20Sopenharmony_ci del_timer_sync(&local->link_timer); 1668c2ecf20Sopenharmony_ci skb_queue_purge(&local->tx_queue); 1678c2ecf20Sopenharmony_ci cancel_work_sync(&local->tx_work); 1688c2ecf20Sopenharmony_ci cancel_work_sync(&local->rx_work); 1698c2ecf20Sopenharmony_ci cancel_work_sync(&local->timeout_work); 1708c2ecf20Sopenharmony_ci kfree_skb(local->rx_pending); 1718c2ecf20Sopenharmony_ci local->rx_pending = NULL; 1728c2ecf20Sopenharmony_ci del_timer_sync(&local->sdreq_timer); 1738c2ecf20Sopenharmony_ci cancel_work_sync(&local->sdreq_timeout_work); 1748c2ecf20Sopenharmony_ci nfc_llcp_free_sdp_tlv_list(&local->pending_sdreqs); 1758c2ecf20Sopenharmony_ci} 1768c2ecf20Sopenharmony_ci 1778c2ecf20Sopenharmony_cistatic void local_release(struct kref *ref) 1788c2ecf20Sopenharmony_ci{ 1798c2ecf20Sopenharmony_ci struct nfc_llcp_local *local; 1808c2ecf20Sopenharmony_ci 1818c2ecf20Sopenharmony_ci local = container_of(ref, struct nfc_llcp_local, ref); 1828c2ecf20Sopenharmony_ci 1838c2ecf20Sopenharmony_ci local_cleanup(local); 1848c2ecf20Sopenharmony_ci kfree(local); 1858c2ecf20Sopenharmony_ci} 1868c2ecf20Sopenharmony_ci 1878c2ecf20Sopenharmony_ciint nfc_llcp_local_put(struct nfc_llcp_local *local) 1888c2ecf20Sopenharmony_ci{ 1898c2ecf20Sopenharmony_ci struct nfc_dev *dev; 1908c2ecf20Sopenharmony_ci int ret; 1918c2ecf20Sopenharmony_ci 1928c2ecf20Sopenharmony_ci if (local == NULL) 1938c2ecf20Sopenharmony_ci return 0; 1948c2ecf20Sopenharmony_ci 1958c2ecf20Sopenharmony_ci dev = local->dev; 1968c2ecf20Sopenharmony_ci 1978c2ecf20Sopenharmony_ci ret = kref_put(&local->ref, local_release); 1988c2ecf20Sopenharmony_ci nfc_put_device(dev); 1998c2ecf20Sopenharmony_ci 2008c2ecf20Sopenharmony_ci return ret; 2018c2ecf20Sopenharmony_ci} 2028c2ecf20Sopenharmony_ci 2038c2ecf20Sopenharmony_cistatic struct nfc_llcp_sock *nfc_llcp_sock_get(struct nfc_llcp_local *local, 2048c2ecf20Sopenharmony_ci u8 ssap, u8 dsap) 2058c2ecf20Sopenharmony_ci{ 2068c2ecf20Sopenharmony_ci struct sock *sk; 2078c2ecf20Sopenharmony_ci struct nfc_llcp_sock *llcp_sock, *tmp_sock; 2088c2ecf20Sopenharmony_ci 2098c2ecf20Sopenharmony_ci pr_debug("ssap dsap %d %d\n", ssap, dsap); 2108c2ecf20Sopenharmony_ci 2118c2ecf20Sopenharmony_ci if (ssap == 0 && dsap == 0) 2128c2ecf20Sopenharmony_ci return NULL; 2138c2ecf20Sopenharmony_ci 2148c2ecf20Sopenharmony_ci read_lock(&local->sockets.lock); 2158c2ecf20Sopenharmony_ci 2168c2ecf20Sopenharmony_ci llcp_sock = NULL; 2178c2ecf20Sopenharmony_ci 2188c2ecf20Sopenharmony_ci sk_for_each(sk, &local->sockets.head) { 2198c2ecf20Sopenharmony_ci tmp_sock = nfc_llcp_sock(sk); 2208c2ecf20Sopenharmony_ci 2218c2ecf20Sopenharmony_ci if (tmp_sock->ssap == ssap && tmp_sock->dsap == dsap) { 2228c2ecf20Sopenharmony_ci llcp_sock = tmp_sock; 2238c2ecf20Sopenharmony_ci sock_hold(&llcp_sock->sk); 2248c2ecf20Sopenharmony_ci break; 2258c2ecf20Sopenharmony_ci } 2268c2ecf20Sopenharmony_ci } 2278c2ecf20Sopenharmony_ci 2288c2ecf20Sopenharmony_ci read_unlock(&local->sockets.lock); 2298c2ecf20Sopenharmony_ci 2308c2ecf20Sopenharmony_ci return llcp_sock; 2318c2ecf20Sopenharmony_ci} 2328c2ecf20Sopenharmony_ci 2338c2ecf20Sopenharmony_cistatic void nfc_llcp_sock_put(struct nfc_llcp_sock *sock) 2348c2ecf20Sopenharmony_ci{ 2358c2ecf20Sopenharmony_ci sock_put(&sock->sk); 2368c2ecf20Sopenharmony_ci} 2378c2ecf20Sopenharmony_ci 2388c2ecf20Sopenharmony_cistatic void nfc_llcp_timeout_work(struct work_struct *work) 2398c2ecf20Sopenharmony_ci{ 2408c2ecf20Sopenharmony_ci struct nfc_llcp_local *local = container_of(work, struct nfc_llcp_local, 2418c2ecf20Sopenharmony_ci timeout_work); 2428c2ecf20Sopenharmony_ci 2438c2ecf20Sopenharmony_ci nfc_dep_link_down(local->dev); 2448c2ecf20Sopenharmony_ci} 2458c2ecf20Sopenharmony_ci 2468c2ecf20Sopenharmony_cistatic void nfc_llcp_symm_timer(struct timer_list *t) 2478c2ecf20Sopenharmony_ci{ 2488c2ecf20Sopenharmony_ci struct nfc_llcp_local *local = from_timer(local, t, link_timer); 2498c2ecf20Sopenharmony_ci 2508c2ecf20Sopenharmony_ci pr_err("SYMM timeout\n"); 2518c2ecf20Sopenharmony_ci 2528c2ecf20Sopenharmony_ci schedule_work(&local->timeout_work); 2538c2ecf20Sopenharmony_ci} 2548c2ecf20Sopenharmony_ci 2558c2ecf20Sopenharmony_cistatic void nfc_llcp_sdreq_timeout_work(struct work_struct *work) 2568c2ecf20Sopenharmony_ci{ 2578c2ecf20Sopenharmony_ci unsigned long time; 2588c2ecf20Sopenharmony_ci HLIST_HEAD(nl_sdres_list); 2598c2ecf20Sopenharmony_ci struct hlist_node *n; 2608c2ecf20Sopenharmony_ci struct nfc_llcp_sdp_tlv *sdp; 2618c2ecf20Sopenharmony_ci struct nfc_llcp_local *local = container_of(work, struct nfc_llcp_local, 2628c2ecf20Sopenharmony_ci sdreq_timeout_work); 2638c2ecf20Sopenharmony_ci 2648c2ecf20Sopenharmony_ci mutex_lock(&local->sdreq_lock); 2658c2ecf20Sopenharmony_ci 2668c2ecf20Sopenharmony_ci time = jiffies - msecs_to_jiffies(3 * local->remote_lto); 2678c2ecf20Sopenharmony_ci 2688c2ecf20Sopenharmony_ci hlist_for_each_entry_safe(sdp, n, &local->pending_sdreqs, node) { 2698c2ecf20Sopenharmony_ci if (time_after(sdp->time, time)) 2708c2ecf20Sopenharmony_ci continue; 2718c2ecf20Sopenharmony_ci 2728c2ecf20Sopenharmony_ci sdp->sap = LLCP_SDP_UNBOUND; 2738c2ecf20Sopenharmony_ci 2748c2ecf20Sopenharmony_ci hlist_del(&sdp->node); 2758c2ecf20Sopenharmony_ci 2768c2ecf20Sopenharmony_ci hlist_add_head(&sdp->node, &nl_sdres_list); 2778c2ecf20Sopenharmony_ci } 2788c2ecf20Sopenharmony_ci 2798c2ecf20Sopenharmony_ci if (!hlist_empty(&local->pending_sdreqs)) 2808c2ecf20Sopenharmony_ci mod_timer(&local->sdreq_timer, 2818c2ecf20Sopenharmony_ci jiffies + msecs_to_jiffies(3 * local->remote_lto)); 2828c2ecf20Sopenharmony_ci 2838c2ecf20Sopenharmony_ci mutex_unlock(&local->sdreq_lock); 2848c2ecf20Sopenharmony_ci 2858c2ecf20Sopenharmony_ci if (!hlist_empty(&nl_sdres_list)) 2868c2ecf20Sopenharmony_ci nfc_genl_llc_send_sdres(local->dev, &nl_sdres_list); 2878c2ecf20Sopenharmony_ci} 2888c2ecf20Sopenharmony_ci 2898c2ecf20Sopenharmony_cistatic void nfc_llcp_sdreq_timer(struct timer_list *t) 2908c2ecf20Sopenharmony_ci{ 2918c2ecf20Sopenharmony_ci struct nfc_llcp_local *local = from_timer(local, t, sdreq_timer); 2928c2ecf20Sopenharmony_ci 2938c2ecf20Sopenharmony_ci schedule_work(&local->sdreq_timeout_work); 2948c2ecf20Sopenharmony_ci} 2958c2ecf20Sopenharmony_ci 2968c2ecf20Sopenharmony_cistruct nfc_llcp_local *nfc_llcp_find_local(struct nfc_dev *dev) 2978c2ecf20Sopenharmony_ci{ 2988c2ecf20Sopenharmony_ci struct nfc_llcp_local *local; 2998c2ecf20Sopenharmony_ci struct nfc_llcp_local *res = NULL; 3008c2ecf20Sopenharmony_ci 3018c2ecf20Sopenharmony_ci spin_lock(&llcp_devices_lock); 3028c2ecf20Sopenharmony_ci list_for_each_entry(local, &llcp_devices, list) 3038c2ecf20Sopenharmony_ci if (local->dev == dev) { 3048c2ecf20Sopenharmony_ci res = nfc_llcp_local_get(local); 3058c2ecf20Sopenharmony_ci break; 3068c2ecf20Sopenharmony_ci } 3078c2ecf20Sopenharmony_ci spin_unlock(&llcp_devices_lock); 3088c2ecf20Sopenharmony_ci 3098c2ecf20Sopenharmony_ci return res; 3108c2ecf20Sopenharmony_ci} 3118c2ecf20Sopenharmony_ci 3128c2ecf20Sopenharmony_cistatic struct nfc_llcp_local *nfc_llcp_remove_local(struct nfc_dev *dev) 3138c2ecf20Sopenharmony_ci{ 3148c2ecf20Sopenharmony_ci struct nfc_llcp_local *local, *tmp; 3158c2ecf20Sopenharmony_ci 3168c2ecf20Sopenharmony_ci spin_lock(&llcp_devices_lock); 3178c2ecf20Sopenharmony_ci list_for_each_entry_safe(local, tmp, &llcp_devices, list) 3188c2ecf20Sopenharmony_ci if (local->dev == dev) { 3198c2ecf20Sopenharmony_ci list_del(&local->list); 3208c2ecf20Sopenharmony_ci spin_unlock(&llcp_devices_lock); 3218c2ecf20Sopenharmony_ci return local; 3228c2ecf20Sopenharmony_ci } 3238c2ecf20Sopenharmony_ci spin_unlock(&llcp_devices_lock); 3248c2ecf20Sopenharmony_ci 3258c2ecf20Sopenharmony_ci pr_warn("Shutting down device not found\n"); 3268c2ecf20Sopenharmony_ci 3278c2ecf20Sopenharmony_ci return NULL; 3288c2ecf20Sopenharmony_ci} 3298c2ecf20Sopenharmony_ci 3308c2ecf20Sopenharmony_cistatic char *wks[] = { 3318c2ecf20Sopenharmony_ci NULL, 3328c2ecf20Sopenharmony_ci NULL, /* SDP */ 3338c2ecf20Sopenharmony_ci "urn:nfc:sn:ip", 3348c2ecf20Sopenharmony_ci "urn:nfc:sn:obex", 3358c2ecf20Sopenharmony_ci "urn:nfc:sn:snep", 3368c2ecf20Sopenharmony_ci}; 3378c2ecf20Sopenharmony_ci 3388c2ecf20Sopenharmony_cistatic int nfc_llcp_wks_sap(const char *service_name, size_t service_name_len) 3398c2ecf20Sopenharmony_ci{ 3408c2ecf20Sopenharmony_ci int sap, num_wks; 3418c2ecf20Sopenharmony_ci 3428c2ecf20Sopenharmony_ci pr_debug("%s\n", service_name); 3438c2ecf20Sopenharmony_ci 3448c2ecf20Sopenharmony_ci if (service_name == NULL) 3458c2ecf20Sopenharmony_ci return -EINVAL; 3468c2ecf20Sopenharmony_ci 3478c2ecf20Sopenharmony_ci num_wks = ARRAY_SIZE(wks); 3488c2ecf20Sopenharmony_ci 3498c2ecf20Sopenharmony_ci for (sap = 0; sap < num_wks; sap++) { 3508c2ecf20Sopenharmony_ci if (wks[sap] == NULL) 3518c2ecf20Sopenharmony_ci continue; 3528c2ecf20Sopenharmony_ci 3538c2ecf20Sopenharmony_ci if (strncmp(wks[sap], service_name, service_name_len) == 0) 3548c2ecf20Sopenharmony_ci return sap; 3558c2ecf20Sopenharmony_ci } 3568c2ecf20Sopenharmony_ci 3578c2ecf20Sopenharmony_ci return -EINVAL; 3588c2ecf20Sopenharmony_ci} 3598c2ecf20Sopenharmony_ci 3608c2ecf20Sopenharmony_cistatic 3618c2ecf20Sopenharmony_cistruct nfc_llcp_sock *nfc_llcp_sock_from_sn(struct nfc_llcp_local *local, 3628c2ecf20Sopenharmony_ci const u8 *sn, size_t sn_len, 3638c2ecf20Sopenharmony_ci bool needref) 3648c2ecf20Sopenharmony_ci{ 3658c2ecf20Sopenharmony_ci struct sock *sk; 3668c2ecf20Sopenharmony_ci struct nfc_llcp_sock *llcp_sock, *tmp_sock; 3678c2ecf20Sopenharmony_ci 3688c2ecf20Sopenharmony_ci pr_debug("sn %zd %p\n", sn_len, sn); 3698c2ecf20Sopenharmony_ci 3708c2ecf20Sopenharmony_ci if (sn == NULL || sn_len == 0) 3718c2ecf20Sopenharmony_ci return NULL; 3728c2ecf20Sopenharmony_ci 3738c2ecf20Sopenharmony_ci read_lock(&local->sockets.lock); 3748c2ecf20Sopenharmony_ci 3758c2ecf20Sopenharmony_ci llcp_sock = NULL; 3768c2ecf20Sopenharmony_ci 3778c2ecf20Sopenharmony_ci sk_for_each(sk, &local->sockets.head) { 3788c2ecf20Sopenharmony_ci tmp_sock = nfc_llcp_sock(sk); 3798c2ecf20Sopenharmony_ci 3808c2ecf20Sopenharmony_ci pr_debug("llcp sock %p\n", tmp_sock); 3818c2ecf20Sopenharmony_ci 3828c2ecf20Sopenharmony_ci if (tmp_sock->sk.sk_type == SOCK_STREAM && 3838c2ecf20Sopenharmony_ci tmp_sock->sk.sk_state != LLCP_LISTEN) 3848c2ecf20Sopenharmony_ci continue; 3858c2ecf20Sopenharmony_ci 3868c2ecf20Sopenharmony_ci if (tmp_sock->sk.sk_type == SOCK_DGRAM && 3878c2ecf20Sopenharmony_ci tmp_sock->sk.sk_state != LLCP_BOUND) 3888c2ecf20Sopenharmony_ci continue; 3898c2ecf20Sopenharmony_ci 3908c2ecf20Sopenharmony_ci if (tmp_sock->service_name == NULL || 3918c2ecf20Sopenharmony_ci tmp_sock->service_name_len == 0) 3928c2ecf20Sopenharmony_ci continue; 3938c2ecf20Sopenharmony_ci 3948c2ecf20Sopenharmony_ci if (tmp_sock->service_name_len != sn_len) 3958c2ecf20Sopenharmony_ci continue; 3968c2ecf20Sopenharmony_ci 3978c2ecf20Sopenharmony_ci if (memcmp(sn, tmp_sock->service_name, sn_len) == 0) { 3988c2ecf20Sopenharmony_ci llcp_sock = tmp_sock; 3998c2ecf20Sopenharmony_ci if (needref) 4008c2ecf20Sopenharmony_ci sock_hold(&llcp_sock->sk); 4018c2ecf20Sopenharmony_ci break; 4028c2ecf20Sopenharmony_ci } 4038c2ecf20Sopenharmony_ci } 4048c2ecf20Sopenharmony_ci 4058c2ecf20Sopenharmony_ci read_unlock(&local->sockets.lock); 4068c2ecf20Sopenharmony_ci 4078c2ecf20Sopenharmony_ci pr_debug("Found llcp sock %p\n", llcp_sock); 4088c2ecf20Sopenharmony_ci 4098c2ecf20Sopenharmony_ci return llcp_sock; 4108c2ecf20Sopenharmony_ci} 4118c2ecf20Sopenharmony_ci 4128c2ecf20Sopenharmony_ciu8 nfc_llcp_get_sdp_ssap(struct nfc_llcp_local *local, 4138c2ecf20Sopenharmony_ci struct nfc_llcp_sock *sock) 4148c2ecf20Sopenharmony_ci{ 4158c2ecf20Sopenharmony_ci mutex_lock(&local->sdp_lock); 4168c2ecf20Sopenharmony_ci 4178c2ecf20Sopenharmony_ci if (sock->service_name != NULL && sock->service_name_len > 0) { 4188c2ecf20Sopenharmony_ci int ssap = nfc_llcp_wks_sap(sock->service_name, 4198c2ecf20Sopenharmony_ci sock->service_name_len); 4208c2ecf20Sopenharmony_ci 4218c2ecf20Sopenharmony_ci if (ssap > 0) { 4228c2ecf20Sopenharmony_ci pr_debug("WKS %d\n", ssap); 4238c2ecf20Sopenharmony_ci 4248c2ecf20Sopenharmony_ci /* This is a WKS, let's check if it's free */ 4258c2ecf20Sopenharmony_ci if (local->local_wks & BIT(ssap)) { 4268c2ecf20Sopenharmony_ci mutex_unlock(&local->sdp_lock); 4278c2ecf20Sopenharmony_ci 4288c2ecf20Sopenharmony_ci return LLCP_SAP_MAX; 4298c2ecf20Sopenharmony_ci } 4308c2ecf20Sopenharmony_ci 4318c2ecf20Sopenharmony_ci set_bit(ssap, &local->local_wks); 4328c2ecf20Sopenharmony_ci mutex_unlock(&local->sdp_lock); 4338c2ecf20Sopenharmony_ci 4348c2ecf20Sopenharmony_ci return ssap; 4358c2ecf20Sopenharmony_ci } 4368c2ecf20Sopenharmony_ci 4378c2ecf20Sopenharmony_ci /* 4388c2ecf20Sopenharmony_ci * Check if there already is a non WKS socket bound 4398c2ecf20Sopenharmony_ci * to this service name. 4408c2ecf20Sopenharmony_ci */ 4418c2ecf20Sopenharmony_ci if (nfc_llcp_sock_from_sn(local, sock->service_name, 4428c2ecf20Sopenharmony_ci sock->service_name_len, 4438c2ecf20Sopenharmony_ci false) != NULL) { 4448c2ecf20Sopenharmony_ci mutex_unlock(&local->sdp_lock); 4458c2ecf20Sopenharmony_ci 4468c2ecf20Sopenharmony_ci return LLCP_SAP_MAX; 4478c2ecf20Sopenharmony_ci } 4488c2ecf20Sopenharmony_ci 4498c2ecf20Sopenharmony_ci mutex_unlock(&local->sdp_lock); 4508c2ecf20Sopenharmony_ci 4518c2ecf20Sopenharmony_ci return LLCP_SDP_UNBOUND; 4528c2ecf20Sopenharmony_ci 4538c2ecf20Sopenharmony_ci } else if (sock->ssap != 0 && sock->ssap < LLCP_WKS_NUM_SAP) { 4548c2ecf20Sopenharmony_ci if (!test_bit(sock->ssap, &local->local_wks)) { 4558c2ecf20Sopenharmony_ci set_bit(sock->ssap, &local->local_wks); 4568c2ecf20Sopenharmony_ci mutex_unlock(&local->sdp_lock); 4578c2ecf20Sopenharmony_ci 4588c2ecf20Sopenharmony_ci return sock->ssap; 4598c2ecf20Sopenharmony_ci } 4608c2ecf20Sopenharmony_ci } 4618c2ecf20Sopenharmony_ci 4628c2ecf20Sopenharmony_ci mutex_unlock(&local->sdp_lock); 4638c2ecf20Sopenharmony_ci 4648c2ecf20Sopenharmony_ci return LLCP_SAP_MAX; 4658c2ecf20Sopenharmony_ci} 4668c2ecf20Sopenharmony_ci 4678c2ecf20Sopenharmony_ciu8 nfc_llcp_get_local_ssap(struct nfc_llcp_local *local) 4688c2ecf20Sopenharmony_ci{ 4698c2ecf20Sopenharmony_ci u8 local_ssap; 4708c2ecf20Sopenharmony_ci 4718c2ecf20Sopenharmony_ci mutex_lock(&local->sdp_lock); 4728c2ecf20Sopenharmony_ci 4738c2ecf20Sopenharmony_ci local_ssap = find_first_zero_bit(&local->local_sap, LLCP_LOCAL_NUM_SAP); 4748c2ecf20Sopenharmony_ci if (local_ssap == LLCP_LOCAL_NUM_SAP) { 4758c2ecf20Sopenharmony_ci mutex_unlock(&local->sdp_lock); 4768c2ecf20Sopenharmony_ci return LLCP_SAP_MAX; 4778c2ecf20Sopenharmony_ci } 4788c2ecf20Sopenharmony_ci 4798c2ecf20Sopenharmony_ci set_bit(local_ssap, &local->local_sap); 4808c2ecf20Sopenharmony_ci 4818c2ecf20Sopenharmony_ci mutex_unlock(&local->sdp_lock); 4828c2ecf20Sopenharmony_ci 4838c2ecf20Sopenharmony_ci return local_ssap + LLCP_LOCAL_SAP_OFFSET; 4848c2ecf20Sopenharmony_ci} 4858c2ecf20Sopenharmony_ci 4868c2ecf20Sopenharmony_civoid nfc_llcp_put_ssap(struct nfc_llcp_local *local, u8 ssap) 4878c2ecf20Sopenharmony_ci{ 4888c2ecf20Sopenharmony_ci u8 local_ssap; 4898c2ecf20Sopenharmony_ci unsigned long *sdp; 4908c2ecf20Sopenharmony_ci 4918c2ecf20Sopenharmony_ci if (ssap < LLCP_WKS_NUM_SAP) { 4928c2ecf20Sopenharmony_ci local_ssap = ssap; 4938c2ecf20Sopenharmony_ci sdp = &local->local_wks; 4948c2ecf20Sopenharmony_ci } else if (ssap < LLCP_LOCAL_NUM_SAP) { 4958c2ecf20Sopenharmony_ci atomic_t *client_cnt; 4968c2ecf20Sopenharmony_ci 4978c2ecf20Sopenharmony_ci local_ssap = ssap - LLCP_WKS_NUM_SAP; 4988c2ecf20Sopenharmony_ci sdp = &local->local_sdp; 4998c2ecf20Sopenharmony_ci client_cnt = &local->local_sdp_cnt[local_ssap]; 5008c2ecf20Sopenharmony_ci 5018c2ecf20Sopenharmony_ci pr_debug("%d clients\n", atomic_read(client_cnt)); 5028c2ecf20Sopenharmony_ci 5038c2ecf20Sopenharmony_ci mutex_lock(&local->sdp_lock); 5048c2ecf20Sopenharmony_ci 5058c2ecf20Sopenharmony_ci if (atomic_dec_and_test(client_cnt)) { 5068c2ecf20Sopenharmony_ci struct nfc_llcp_sock *l_sock; 5078c2ecf20Sopenharmony_ci 5088c2ecf20Sopenharmony_ci pr_debug("No more clients for SAP %d\n", ssap); 5098c2ecf20Sopenharmony_ci 5108c2ecf20Sopenharmony_ci clear_bit(local_ssap, sdp); 5118c2ecf20Sopenharmony_ci 5128c2ecf20Sopenharmony_ci /* Find the listening sock and set it back to UNBOUND */ 5138c2ecf20Sopenharmony_ci l_sock = nfc_llcp_sock_get(local, ssap, LLCP_SAP_SDP); 5148c2ecf20Sopenharmony_ci if (l_sock) { 5158c2ecf20Sopenharmony_ci l_sock->ssap = LLCP_SDP_UNBOUND; 5168c2ecf20Sopenharmony_ci nfc_llcp_sock_put(l_sock); 5178c2ecf20Sopenharmony_ci } 5188c2ecf20Sopenharmony_ci } 5198c2ecf20Sopenharmony_ci 5208c2ecf20Sopenharmony_ci mutex_unlock(&local->sdp_lock); 5218c2ecf20Sopenharmony_ci 5228c2ecf20Sopenharmony_ci return; 5238c2ecf20Sopenharmony_ci } else if (ssap < LLCP_MAX_SAP) { 5248c2ecf20Sopenharmony_ci local_ssap = ssap - LLCP_LOCAL_NUM_SAP; 5258c2ecf20Sopenharmony_ci sdp = &local->local_sap; 5268c2ecf20Sopenharmony_ci } else { 5278c2ecf20Sopenharmony_ci return; 5288c2ecf20Sopenharmony_ci } 5298c2ecf20Sopenharmony_ci 5308c2ecf20Sopenharmony_ci mutex_lock(&local->sdp_lock); 5318c2ecf20Sopenharmony_ci 5328c2ecf20Sopenharmony_ci clear_bit(local_ssap, sdp); 5338c2ecf20Sopenharmony_ci 5348c2ecf20Sopenharmony_ci mutex_unlock(&local->sdp_lock); 5358c2ecf20Sopenharmony_ci} 5368c2ecf20Sopenharmony_ci 5378c2ecf20Sopenharmony_cistatic u8 nfc_llcp_reserve_sdp_ssap(struct nfc_llcp_local *local) 5388c2ecf20Sopenharmony_ci{ 5398c2ecf20Sopenharmony_ci u8 ssap; 5408c2ecf20Sopenharmony_ci 5418c2ecf20Sopenharmony_ci mutex_lock(&local->sdp_lock); 5428c2ecf20Sopenharmony_ci 5438c2ecf20Sopenharmony_ci ssap = find_first_zero_bit(&local->local_sdp, LLCP_SDP_NUM_SAP); 5448c2ecf20Sopenharmony_ci if (ssap == LLCP_SDP_NUM_SAP) { 5458c2ecf20Sopenharmony_ci mutex_unlock(&local->sdp_lock); 5468c2ecf20Sopenharmony_ci 5478c2ecf20Sopenharmony_ci return LLCP_SAP_MAX; 5488c2ecf20Sopenharmony_ci } 5498c2ecf20Sopenharmony_ci 5508c2ecf20Sopenharmony_ci pr_debug("SDP ssap %d\n", LLCP_WKS_NUM_SAP + ssap); 5518c2ecf20Sopenharmony_ci 5528c2ecf20Sopenharmony_ci set_bit(ssap, &local->local_sdp); 5538c2ecf20Sopenharmony_ci 5548c2ecf20Sopenharmony_ci mutex_unlock(&local->sdp_lock); 5558c2ecf20Sopenharmony_ci 5568c2ecf20Sopenharmony_ci return LLCP_WKS_NUM_SAP + ssap; 5578c2ecf20Sopenharmony_ci} 5588c2ecf20Sopenharmony_ci 5598c2ecf20Sopenharmony_cistatic int nfc_llcp_build_gb(struct nfc_llcp_local *local) 5608c2ecf20Sopenharmony_ci{ 5618c2ecf20Sopenharmony_ci u8 *gb_cur, version, version_length; 5628c2ecf20Sopenharmony_ci u8 lto_length, wks_length, miux_length; 5638c2ecf20Sopenharmony_ci const u8 *version_tlv = NULL, *lto_tlv = NULL, 5648c2ecf20Sopenharmony_ci *wks_tlv = NULL, *miux_tlv = NULL; 5658c2ecf20Sopenharmony_ci __be16 wks = cpu_to_be16(local->local_wks); 5668c2ecf20Sopenharmony_ci u8 gb_len = 0; 5678c2ecf20Sopenharmony_ci int ret = 0; 5688c2ecf20Sopenharmony_ci 5698c2ecf20Sopenharmony_ci version = LLCP_VERSION_11; 5708c2ecf20Sopenharmony_ci version_tlv = nfc_llcp_build_tlv(LLCP_TLV_VERSION, &version, 5718c2ecf20Sopenharmony_ci 1, &version_length); 5728c2ecf20Sopenharmony_ci if (!version_tlv) { 5738c2ecf20Sopenharmony_ci ret = -ENOMEM; 5748c2ecf20Sopenharmony_ci goto out; 5758c2ecf20Sopenharmony_ci } 5768c2ecf20Sopenharmony_ci gb_len += version_length; 5778c2ecf20Sopenharmony_ci 5788c2ecf20Sopenharmony_ci lto_tlv = nfc_llcp_build_tlv(LLCP_TLV_LTO, &local->lto, 1, <o_length); 5798c2ecf20Sopenharmony_ci if (!lto_tlv) { 5808c2ecf20Sopenharmony_ci ret = -ENOMEM; 5818c2ecf20Sopenharmony_ci goto out; 5828c2ecf20Sopenharmony_ci } 5838c2ecf20Sopenharmony_ci gb_len += lto_length; 5848c2ecf20Sopenharmony_ci 5858c2ecf20Sopenharmony_ci pr_debug("Local wks 0x%lx\n", local->local_wks); 5868c2ecf20Sopenharmony_ci wks_tlv = nfc_llcp_build_tlv(LLCP_TLV_WKS, (u8 *)&wks, 2, &wks_length); 5878c2ecf20Sopenharmony_ci if (!wks_tlv) { 5888c2ecf20Sopenharmony_ci ret = -ENOMEM; 5898c2ecf20Sopenharmony_ci goto out; 5908c2ecf20Sopenharmony_ci } 5918c2ecf20Sopenharmony_ci gb_len += wks_length; 5928c2ecf20Sopenharmony_ci 5938c2ecf20Sopenharmony_ci miux_tlv = nfc_llcp_build_tlv(LLCP_TLV_MIUX, (u8 *)&local->miux, 0, 5948c2ecf20Sopenharmony_ci &miux_length); 5958c2ecf20Sopenharmony_ci if (!miux_tlv) { 5968c2ecf20Sopenharmony_ci ret = -ENOMEM; 5978c2ecf20Sopenharmony_ci goto out; 5988c2ecf20Sopenharmony_ci } 5998c2ecf20Sopenharmony_ci gb_len += miux_length; 6008c2ecf20Sopenharmony_ci 6018c2ecf20Sopenharmony_ci gb_len += ARRAY_SIZE(llcp_magic); 6028c2ecf20Sopenharmony_ci 6038c2ecf20Sopenharmony_ci if (gb_len > NFC_MAX_GT_LEN) { 6048c2ecf20Sopenharmony_ci ret = -EINVAL; 6058c2ecf20Sopenharmony_ci goto out; 6068c2ecf20Sopenharmony_ci } 6078c2ecf20Sopenharmony_ci 6088c2ecf20Sopenharmony_ci gb_cur = local->gb; 6098c2ecf20Sopenharmony_ci 6108c2ecf20Sopenharmony_ci memcpy(gb_cur, llcp_magic, ARRAY_SIZE(llcp_magic)); 6118c2ecf20Sopenharmony_ci gb_cur += ARRAY_SIZE(llcp_magic); 6128c2ecf20Sopenharmony_ci 6138c2ecf20Sopenharmony_ci memcpy(gb_cur, version_tlv, version_length); 6148c2ecf20Sopenharmony_ci gb_cur += version_length; 6158c2ecf20Sopenharmony_ci 6168c2ecf20Sopenharmony_ci memcpy(gb_cur, lto_tlv, lto_length); 6178c2ecf20Sopenharmony_ci gb_cur += lto_length; 6188c2ecf20Sopenharmony_ci 6198c2ecf20Sopenharmony_ci memcpy(gb_cur, wks_tlv, wks_length); 6208c2ecf20Sopenharmony_ci gb_cur += wks_length; 6218c2ecf20Sopenharmony_ci 6228c2ecf20Sopenharmony_ci memcpy(gb_cur, miux_tlv, miux_length); 6238c2ecf20Sopenharmony_ci gb_cur += miux_length; 6248c2ecf20Sopenharmony_ci 6258c2ecf20Sopenharmony_ci local->gb_len = gb_len; 6268c2ecf20Sopenharmony_ci 6278c2ecf20Sopenharmony_ciout: 6288c2ecf20Sopenharmony_ci kfree(version_tlv); 6298c2ecf20Sopenharmony_ci kfree(lto_tlv); 6308c2ecf20Sopenharmony_ci kfree(wks_tlv); 6318c2ecf20Sopenharmony_ci kfree(miux_tlv); 6328c2ecf20Sopenharmony_ci 6338c2ecf20Sopenharmony_ci return ret; 6348c2ecf20Sopenharmony_ci} 6358c2ecf20Sopenharmony_ci 6368c2ecf20Sopenharmony_ciu8 *nfc_llcp_general_bytes(struct nfc_dev *dev, size_t *general_bytes_len) 6378c2ecf20Sopenharmony_ci{ 6388c2ecf20Sopenharmony_ci struct nfc_llcp_local *local; 6398c2ecf20Sopenharmony_ci 6408c2ecf20Sopenharmony_ci local = nfc_llcp_find_local(dev); 6418c2ecf20Sopenharmony_ci if (local == NULL) { 6428c2ecf20Sopenharmony_ci *general_bytes_len = 0; 6438c2ecf20Sopenharmony_ci return NULL; 6448c2ecf20Sopenharmony_ci } 6458c2ecf20Sopenharmony_ci 6468c2ecf20Sopenharmony_ci nfc_llcp_build_gb(local); 6478c2ecf20Sopenharmony_ci 6488c2ecf20Sopenharmony_ci *general_bytes_len = local->gb_len; 6498c2ecf20Sopenharmony_ci 6508c2ecf20Sopenharmony_ci nfc_llcp_local_put(local); 6518c2ecf20Sopenharmony_ci 6528c2ecf20Sopenharmony_ci return local->gb; 6538c2ecf20Sopenharmony_ci} 6548c2ecf20Sopenharmony_ci 6558c2ecf20Sopenharmony_ciint nfc_llcp_set_remote_gb(struct nfc_dev *dev, const u8 *gb, u8 gb_len) 6568c2ecf20Sopenharmony_ci{ 6578c2ecf20Sopenharmony_ci struct nfc_llcp_local *local; 6588c2ecf20Sopenharmony_ci int err; 6598c2ecf20Sopenharmony_ci 6608c2ecf20Sopenharmony_ci if (gb_len < 3 || gb_len > NFC_MAX_GT_LEN) 6618c2ecf20Sopenharmony_ci return -EINVAL; 6628c2ecf20Sopenharmony_ci 6638c2ecf20Sopenharmony_ci local = nfc_llcp_find_local(dev); 6648c2ecf20Sopenharmony_ci if (local == NULL) { 6658c2ecf20Sopenharmony_ci pr_err("No LLCP device\n"); 6668c2ecf20Sopenharmony_ci return -ENODEV; 6678c2ecf20Sopenharmony_ci } 6688c2ecf20Sopenharmony_ci 6698c2ecf20Sopenharmony_ci memset(local->remote_gb, 0, NFC_MAX_GT_LEN); 6708c2ecf20Sopenharmony_ci memcpy(local->remote_gb, gb, gb_len); 6718c2ecf20Sopenharmony_ci local->remote_gb_len = gb_len; 6728c2ecf20Sopenharmony_ci 6738c2ecf20Sopenharmony_ci if (memcmp(local->remote_gb, llcp_magic, 3)) { 6748c2ecf20Sopenharmony_ci pr_err("MAC does not support LLCP\n"); 6758c2ecf20Sopenharmony_ci err = -EINVAL; 6768c2ecf20Sopenharmony_ci goto out; 6778c2ecf20Sopenharmony_ci } 6788c2ecf20Sopenharmony_ci 6798c2ecf20Sopenharmony_ci err = nfc_llcp_parse_gb_tlv(local, 6808c2ecf20Sopenharmony_ci &local->remote_gb[3], 6818c2ecf20Sopenharmony_ci local->remote_gb_len - 3); 6828c2ecf20Sopenharmony_ciout: 6838c2ecf20Sopenharmony_ci nfc_llcp_local_put(local); 6848c2ecf20Sopenharmony_ci return err; 6858c2ecf20Sopenharmony_ci} 6868c2ecf20Sopenharmony_ci 6878c2ecf20Sopenharmony_cistatic u8 nfc_llcp_dsap(const struct sk_buff *pdu) 6888c2ecf20Sopenharmony_ci{ 6898c2ecf20Sopenharmony_ci return (pdu->data[0] & 0xfc) >> 2; 6908c2ecf20Sopenharmony_ci} 6918c2ecf20Sopenharmony_ci 6928c2ecf20Sopenharmony_cistatic u8 nfc_llcp_ptype(const struct sk_buff *pdu) 6938c2ecf20Sopenharmony_ci{ 6948c2ecf20Sopenharmony_ci return ((pdu->data[0] & 0x03) << 2) | ((pdu->data[1] & 0xc0) >> 6); 6958c2ecf20Sopenharmony_ci} 6968c2ecf20Sopenharmony_ci 6978c2ecf20Sopenharmony_cistatic u8 nfc_llcp_ssap(const struct sk_buff *pdu) 6988c2ecf20Sopenharmony_ci{ 6998c2ecf20Sopenharmony_ci return pdu->data[1] & 0x3f; 7008c2ecf20Sopenharmony_ci} 7018c2ecf20Sopenharmony_ci 7028c2ecf20Sopenharmony_cistatic u8 nfc_llcp_ns(const struct sk_buff *pdu) 7038c2ecf20Sopenharmony_ci{ 7048c2ecf20Sopenharmony_ci return pdu->data[2] >> 4; 7058c2ecf20Sopenharmony_ci} 7068c2ecf20Sopenharmony_ci 7078c2ecf20Sopenharmony_cistatic u8 nfc_llcp_nr(const struct sk_buff *pdu) 7088c2ecf20Sopenharmony_ci{ 7098c2ecf20Sopenharmony_ci return pdu->data[2] & 0xf; 7108c2ecf20Sopenharmony_ci} 7118c2ecf20Sopenharmony_ci 7128c2ecf20Sopenharmony_cistatic void nfc_llcp_set_nrns(struct nfc_llcp_sock *sock, struct sk_buff *pdu) 7138c2ecf20Sopenharmony_ci{ 7148c2ecf20Sopenharmony_ci pdu->data[2] = (sock->send_n << 4) | (sock->recv_n); 7158c2ecf20Sopenharmony_ci sock->send_n = (sock->send_n + 1) % 16; 7168c2ecf20Sopenharmony_ci sock->recv_ack_n = (sock->recv_n - 1) % 16; 7178c2ecf20Sopenharmony_ci} 7188c2ecf20Sopenharmony_ci 7198c2ecf20Sopenharmony_civoid nfc_llcp_send_to_raw_sock(struct nfc_llcp_local *local, 7208c2ecf20Sopenharmony_ci struct sk_buff *skb, u8 direction) 7218c2ecf20Sopenharmony_ci{ 7228c2ecf20Sopenharmony_ci struct sk_buff *skb_copy = NULL, *nskb; 7238c2ecf20Sopenharmony_ci struct sock *sk; 7248c2ecf20Sopenharmony_ci u8 *data; 7258c2ecf20Sopenharmony_ci 7268c2ecf20Sopenharmony_ci read_lock(&local->raw_sockets.lock); 7278c2ecf20Sopenharmony_ci 7288c2ecf20Sopenharmony_ci sk_for_each(sk, &local->raw_sockets.head) { 7298c2ecf20Sopenharmony_ci if (sk->sk_state != LLCP_BOUND) 7308c2ecf20Sopenharmony_ci continue; 7318c2ecf20Sopenharmony_ci 7328c2ecf20Sopenharmony_ci if (skb_copy == NULL) { 7338c2ecf20Sopenharmony_ci skb_copy = __pskb_copy_fclone(skb, NFC_RAW_HEADER_SIZE, 7348c2ecf20Sopenharmony_ci GFP_ATOMIC, true); 7358c2ecf20Sopenharmony_ci 7368c2ecf20Sopenharmony_ci if (skb_copy == NULL) 7378c2ecf20Sopenharmony_ci continue; 7388c2ecf20Sopenharmony_ci 7398c2ecf20Sopenharmony_ci data = skb_push(skb_copy, NFC_RAW_HEADER_SIZE); 7408c2ecf20Sopenharmony_ci 7418c2ecf20Sopenharmony_ci data[0] = local->dev ? local->dev->idx : 0xFF; 7428c2ecf20Sopenharmony_ci data[1] = direction & 0x01; 7438c2ecf20Sopenharmony_ci data[1] |= (RAW_PAYLOAD_LLCP << 1); 7448c2ecf20Sopenharmony_ci } 7458c2ecf20Sopenharmony_ci 7468c2ecf20Sopenharmony_ci nskb = skb_clone(skb_copy, GFP_ATOMIC); 7478c2ecf20Sopenharmony_ci if (!nskb) 7488c2ecf20Sopenharmony_ci continue; 7498c2ecf20Sopenharmony_ci 7508c2ecf20Sopenharmony_ci if (sock_queue_rcv_skb(sk, nskb)) 7518c2ecf20Sopenharmony_ci kfree_skb(nskb); 7528c2ecf20Sopenharmony_ci } 7538c2ecf20Sopenharmony_ci 7548c2ecf20Sopenharmony_ci read_unlock(&local->raw_sockets.lock); 7558c2ecf20Sopenharmony_ci 7568c2ecf20Sopenharmony_ci kfree_skb(skb_copy); 7578c2ecf20Sopenharmony_ci} 7588c2ecf20Sopenharmony_ci 7598c2ecf20Sopenharmony_cistatic void nfc_llcp_tx_work(struct work_struct *work) 7608c2ecf20Sopenharmony_ci{ 7618c2ecf20Sopenharmony_ci struct nfc_llcp_local *local = container_of(work, struct nfc_llcp_local, 7628c2ecf20Sopenharmony_ci tx_work); 7638c2ecf20Sopenharmony_ci struct sk_buff *skb; 7648c2ecf20Sopenharmony_ci struct sock *sk; 7658c2ecf20Sopenharmony_ci struct nfc_llcp_sock *llcp_sock; 7668c2ecf20Sopenharmony_ci 7678c2ecf20Sopenharmony_ci skb = skb_dequeue(&local->tx_queue); 7688c2ecf20Sopenharmony_ci if (skb != NULL) { 7698c2ecf20Sopenharmony_ci sk = skb->sk; 7708c2ecf20Sopenharmony_ci llcp_sock = nfc_llcp_sock(sk); 7718c2ecf20Sopenharmony_ci 7728c2ecf20Sopenharmony_ci if (llcp_sock == NULL && nfc_llcp_ptype(skb) == LLCP_PDU_I) { 7738c2ecf20Sopenharmony_ci kfree_skb(skb); 7748c2ecf20Sopenharmony_ci nfc_llcp_send_symm(local->dev); 7758c2ecf20Sopenharmony_ci } else if (llcp_sock && !llcp_sock->remote_ready) { 7768c2ecf20Sopenharmony_ci skb_queue_head(&local->tx_queue, skb); 7778c2ecf20Sopenharmony_ci nfc_llcp_send_symm(local->dev); 7788c2ecf20Sopenharmony_ci } else { 7798c2ecf20Sopenharmony_ci struct sk_buff *copy_skb = NULL; 7808c2ecf20Sopenharmony_ci u8 ptype = nfc_llcp_ptype(skb); 7818c2ecf20Sopenharmony_ci int ret; 7828c2ecf20Sopenharmony_ci 7838c2ecf20Sopenharmony_ci pr_debug("Sending pending skb\n"); 7848c2ecf20Sopenharmony_ci print_hex_dump_debug("LLCP Tx: ", DUMP_PREFIX_OFFSET, 7858c2ecf20Sopenharmony_ci 16, 1, skb->data, skb->len, true); 7868c2ecf20Sopenharmony_ci 7878c2ecf20Sopenharmony_ci if (ptype == LLCP_PDU_DISC && sk != NULL && 7888c2ecf20Sopenharmony_ci sk->sk_state == LLCP_DISCONNECTING) { 7898c2ecf20Sopenharmony_ci nfc_llcp_sock_unlink(&local->sockets, sk); 7908c2ecf20Sopenharmony_ci sock_orphan(sk); 7918c2ecf20Sopenharmony_ci sock_put(sk); 7928c2ecf20Sopenharmony_ci } 7938c2ecf20Sopenharmony_ci 7948c2ecf20Sopenharmony_ci if (ptype == LLCP_PDU_I) 7958c2ecf20Sopenharmony_ci copy_skb = skb_copy(skb, GFP_ATOMIC); 7968c2ecf20Sopenharmony_ci 7978c2ecf20Sopenharmony_ci __net_timestamp(skb); 7988c2ecf20Sopenharmony_ci 7998c2ecf20Sopenharmony_ci nfc_llcp_send_to_raw_sock(local, skb, 8008c2ecf20Sopenharmony_ci NFC_DIRECTION_TX); 8018c2ecf20Sopenharmony_ci 8028c2ecf20Sopenharmony_ci ret = nfc_data_exchange(local->dev, local->target_idx, 8038c2ecf20Sopenharmony_ci skb, nfc_llcp_recv, local); 8048c2ecf20Sopenharmony_ci 8058c2ecf20Sopenharmony_ci if (ret) { 8068c2ecf20Sopenharmony_ci kfree_skb(copy_skb); 8078c2ecf20Sopenharmony_ci goto out; 8088c2ecf20Sopenharmony_ci } 8098c2ecf20Sopenharmony_ci 8108c2ecf20Sopenharmony_ci if (ptype == LLCP_PDU_I && copy_skb) 8118c2ecf20Sopenharmony_ci skb_queue_tail(&llcp_sock->tx_pending_queue, 8128c2ecf20Sopenharmony_ci copy_skb); 8138c2ecf20Sopenharmony_ci } 8148c2ecf20Sopenharmony_ci } else { 8158c2ecf20Sopenharmony_ci nfc_llcp_send_symm(local->dev); 8168c2ecf20Sopenharmony_ci } 8178c2ecf20Sopenharmony_ci 8188c2ecf20Sopenharmony_ciout: 8198c2ecf20Sopenharmony_ci mod_timer(&local->link_timer, 8208c2ecf20Sopenharmony_ci jiffies + msecs_to_jiffies(2 * local->remote_lto)); 8218c2ecf20Sopenharmony_ci} 8228c2ecf20Sopenharmony_ci 8238c2ecf20Sopenharmony_cistatic struct nfc_llcp_sock *nfc_llcp_connecting_sock_get(struct nfc_llcp_local *local, 8248c2ecf20Sopenharmony_ci u8 ssap) 8258c2ecf20Sopenharmony_ci{ 8268c2ecf20Sopenharmony_ci struct sock *sk; 8278c2ecf20Sopenharmony_ci struct nfc_llcp_sock *llcp_sock; 8288c2ecf20Sopenharmony_ci 8298c2ecf20Sopenharmony_ci read_lock(&local->connecting_sockets.lock); 8308c2ecf20Sopenharmony_ci 8318c2ecf20Sopenharmony_ci sk_for_each(sk, &local->connecting_sockets.head) { 8328c2ecf20Sopenharmony_ci llcp_sock = nfc_llcp_sock(sk); 8338c2ecf20Sopenharmony_ci 8348c2ecf20Sopenharmony_ci if (llcp_sock->ssap == ssap) { 8358c2ecf20Sopenharmony_ci sock_hold(&llcp_sock->sk); 8368c2ecf20Sopenharmony_ci goto out; 8378c2ecf20Sopenharmony_ci } 8388c2ecf20Sopenharmony_ci } 8398c2ecf20Sopenharmony_ci 8408c2ecf20Sopenharmony_ci llcp_sock = NULL; 8418c2ecf20Sopenharmony_ci 8428c2ecf20Sopenharmony_ciout: 8438c2ecf20Sopenharmony_ci read_unlock(&local->connecting_sockets.lock); 8448c2ecf20Sopenharmony_ci 8458c2ecf20Sopenharmony_ci return llcp_sock; 8468c2ecf20Sopenharmony_ci} 8478c2ecf20Sopenharmony_ci 8488c2ecf20Sopenharmony_cistatic struct nfc_llcp_sock *nfc_llcp_sock_get_sn(struct nfc_llcp_local *local, 8498c2ecf20Sopenharmony_ci const u8 *sn, size_t sn_len) 8508c2ecf20Sopenharmony_ci{ 8518c2ecf20Sopenharmony_ci return nfc_llcp_sock_from_sn(local, sn, sn_len, true); 8528c2ecf20Sopenharmony_ci} 8538c2ecf20Sopenharmony_ci 8548c2ecf20Sopenharmony_cistatic const u8 *nfc_llcp_connect_sn(const struct sk_buff *skb, size_t *sn_len) 8558c2ecf20Sopenharmony_ci{ 8568c2ecf20Sopenharmony_ci u8 type, length; 8578c2ecf20Sopenharmony_ci const u8 *tlv = &skb->data[2]; 8588c2ecf20Sopenharmony_ci size_t tlv_array_len = skb->len - LLCP_HEADER_SIZE, offset = 0; 8598c2ecf20Sopenharmony_ci 8608c2ecf20Sopenharmony_ci while (offset < tlv_array_len) { 8618c2ecf20Sopenharmony_ci type = tlv[0]; 8628c2ecf20Sopenharmony_ci length = tlv[1]; 8638c2ecf20Sopenharmony_ci 8648c2ecf20Sopenharmony_ci pr_debug("type 0x%x length %d\n", type, length); 8658c2ecf20Sopenharmony_ci 8668c2ecf20Sopenharmony_ci if (type == LLCP_TLV_SN) { 8678c2ecf20Sopenharmony_ci *sn_len = length; 8688c2ecf20Sopenharmony_ci return &tlv[2]; 8698c2ecf20Sopenharmony_ci } 8708c2ecf20Sopenharmony_ci 8718c2ecf20Sopenharmony_ci offset += length + 2; 8728c2ecf20Sopenharmony_ci tlv += length + 2; 8738c2ecf20Sopenharmony_ci } 8748c2ecf20Sopenharmony_ci 8758c2ecf20Sopenharmony_ci return NULL; 8768c2ecf20Sopenharmony_ci} 8778c2ecf20Sopenharmony_ci 8788c2ecf20Sopenharmony_cistatic void nfc_llcp_recv_ui(struct nfc_llcp_local *local, 8798c2ecf20Sopenharmony_ci struct sk_buff *skb) 8808c2ecf20Sopenharmony_ci{ 8818c2ecf20Sopenharmony_ci struct nfc_llcp_sock *llcp_sock; 8828c2ecf20Sopenharmony_ci struct nfc_llcp_ui_cb *ui_cb; 8838c2ecf20Sopenharmony_ci u8 dsap, ssap; 8848c2ecf20Sopenharmony_ci 8858c2ecf20Sopenharmony_ci dsap = nfc_llcp_dsap(skb); 8868c2ecf20Sopenharmony_ci ssap = nfc_llcp_ssap(skb); 8878c2ecf20Sopenharmony_ci 8888c2ecf20Sopenharmony_ci ui_cb = nfc_llcp_ui_skb_cb(skb); 8898c2ecf20Sopenharmony_ci ui_cb->dsap = dsap; 8908c2ecf20Sopenharmony_ci ui_cb->ssap = ssap; 8918c2ecf20Sopenharmony_ci 8928c2ecf20Sopenharmony_ci pr_debug("%d %d\n", dsap, ssap); 8938c2ecf20Sopenharmony_ci 8948c2ecf20Sopenharmony_ci /* We're looking for a bound socket, not a client one */ 8958c2ecf20Sopenharmony_ci llcp_sock = nfc_llcp_sock_get(local, dsap, LLCP_SAP_SDP); 8968c2ecf20Sopenharmony_ci if (llcp_sock == NULL || llcp_sock->sk.sk_type != SOCK_DGRAM) 8978c2ecf20Sopenharmony_ci return; 8988c2ecf20Sopenharmony_ci 8998c2ecf20Sopenharmony_ci /* There is no sequence with UI frames */ 9008c2ecf20Sopenharmony_ci skb_pull(skb, LLCP_HEADER_SIZE); 9018c2ecf20Sopenharmony_ci if (!sock_queue_rcv_skb(&llcp_sock->sk, skb)) { 9028c2ecf20Sopenharmony_ci /* 9038c2ecf20Sopenharmony_ci * UI frames will be freed from the socket layer, so we 9048c2ecf20Sopenharmony_ci * need to keep them alive until someone receives them. 9058c2ecf20Sopenharmony_ci */ 9068c2ecf20Sopenharmony_ci skb_get(skb); 9078c2ecf20Sopenharmony_ci } else { 9088c2ecf20Sopenharmony_ci pr_err("Receive queue is full\n"); 9098c2ecf20Sopenharmony_ci } 9108c2ecf20Sopenharmony_ci 9118c2ecf20Sopenharmony_ci nfc_llcp_sock_put(llcp_sock); 9128c2ecf20Sopenharmony_ci} 9138c2ecf20Sopenharmony_ci 9148c2ecf20Sopenharmony_cistatic void nfc_llcp_recv_connect(struct nfc_llcp_local *local, 9158c2ecf20Sopenharmony_ci const struct sk_buff *skb) 9168c2ecf20Sopenharmony_ci{ 9178c2ecf20Sopenharmony_ci struct sock *new_sk, *parent; 9188c2ecf20Sopenharmony_ci struct nfc_llcp_sock *sock, *new_sock; 9198c2ecf20Sopenharmony_ci u8 dsap, ssap, reason; 9208c2ecf20Sopenharmony_ci 9218c2ecf20Sopenharmony_ci dsap = nfc_llcp_dsap(skb); 9228c2ecf20Sopenharmony_ci ssap = nfc_llcp_ssap(skb); 9238c2ecf20Sopenharmony_ci 9248c2ecf20Sopenharmony_ci pr_debug("%d %d\n", dsap, ssap); 9258c2ecf20Sopenharmony_ci 9268c2ecf20Sopenharmony_ci if (dsap != LLCP_SAP_SDP) { 9278c2ecf20Sopenharmony_ci sock = nfc_llcp_sock_get(local, dsap, LLCP_SAP_SDP); 9288c2ecf20Sopenharmony_ci if (sock == NULL || sock->sk.sk_state != LLCP_LISTEN) { 9298c2ecf20Sopenharmony_ci reason = LLCP_DM_NOBOUND; 9308c2ecf20Sopenharmony_ci goto fail; 9318c2ecf20Sopenharmony_ci } 9328c2ecf20Sopenharmony_ci } else { 9338c2ecf20Sopenharmony_ci const u8 *sn; 9348c2ecf20Sopenharmony_ci size_t sn_len; 9358c2ecf20Sopenharmony_ci 9368c2ecf20Sopenharmony_ci sn = nfc_llcp_connect_sn(skb, &sn_len); 9378c2ecf20Sopenharmony_ci if (sn == NULL) { 9388c2ecf20Sopenharmony_ci reason = LLCP_DM_NOBOUND; 9398c2ecf20Sopenharmony_ci goto fail; 9408c2ecf20Sopenharmony_ci } 9418c2ecf20Sopenharmony_ci 9428c2ecf20Sopenharmony_ci pr_debug("Service name length %zu\n", sn_len); 9438c2ecf20Sopenharmony_ci 9448c2ecf20Sopenharmony_ci sock = nfc_llcp_sock_get_sn(local, sn, sn_len); 9458c2ecf20Sopenharmony_ci if (sock == NULL) { 9468c2ecf20Sopenharmony_ci reason = LLCP_DM_NOBOUND; 9478c2ecf20Sopenharmony_ci goto fail; 9488c2ecf20Sopenharmony_ci } 9498c2ecf20Sopenharmony_ci } 9508c2ecf20Sopenharmony_ci 9518c2ecf20Sopenharmony_ci lock_sock(&sock->sk); 9528c2ecf20Sopenharmony_ci 9538c2ecf20Sopenharmony_ci parent = &sock->sk; 9548c2ecf20Sopenharmony_ci 9558c2ecf20Sopenharmony_ci if (sk_acceptq_is_full(parent)) { 9568c2ecf20Sopenharmony_ci reason = LLCP_DM_REJ; 9578c2ecf20Sopenharmony_ci release_sock(&sock->sk); 9588c2ecf20Sopenharmony_ci sock_put(&sock->sk); 9598c2ecf20Sopenharmony_ci goto fail; 9608c2ecf20Sopenharmony_ci } 9618c2ecf20Sopenharmony_ci 9628c2ecf20Sopenharmony_ci if (sock->ssap == LLCP_SDP_UNBOUND) { 9638c2ecf20Sopenharmony_ci u8 ssap = nfc_llcp_reserve_sdp_ssap(local); 9648c2ecf20Sopenharmony_ci 9658c2ecf20Sopenharmony_ci pr_debug("First client, reserving %d\n", ssap); 9668c2ecf20Sopenharmony_ci 9678c2ecf20Sopenharmony_ci if (ssap == LLCP_SAP_MAX) { 9688c2ecf20Sopenharmony_ci reason = LLCP_DM_REJ; 9698c2ecf20Sopenharmony_ci release_sock(&sock->sk); 9708c2ecf20Sopenharmony_ci sock_put(&sock->sk); 9718c2ecf20Sopenharmony_ci goto fail; 9728c2ecf20Sopenharmony_ci } 9738c2ecf20Sopenharmony_ci 9748c2ecf20Sopenharmony_ci sock->ssap = ssap; 9758c2ecf20Sopenharmony_ci } 9768c2ecf20Sopenharmony_ci 9778c2ecf20Sopenharmony_ci new_sk = nfc_llcp_sock_alloc(NULL, parent->sk_type, GFP_ATOMIC, 0); 9788c2ecf20Sopenharmony_ci if (new_sk == NULL) { 9798c2ecf20Sopenharmony_ci reason = LLCP_DM_REJ; 9808c2ecf20Sopenharmony_ci release_sock(&sock->sk); 9818c2ecf20Sopenharmony_ci sock_put(&sock->sk); 9828c2ecf20Sopenharmony_ci goto fail; 9838c2ecf20Sopenharmony_ci } 9848c2ecf20Sopenharmony_ci 9858c2ecf20Sopenharmony_ci new_sock = nfc_llcp_sock(new_sk); 9868c2ecf20Sopenharmony_ci 9878c2ecf20Sopenharmony_ci new_sock->local = nfc_llcp_local_get(local); 9888c2ecf20Sopenharmony_ci if (!new_sock->local) { 9898c2ecf20Sopenharmony_ci reason = LLCP_DM_REJ; 9908c2ecf20Sopenharmony_ci sock_put(&new_sock->sk); 9918c2ecf20Sopenharmony_ci release_sock(&sock->sk); 9928c2ecf20Sopenharmony_ci sock_put(&sock->sk); 9938c2ecf20Sopenharmony_ci goto fail; 9948c2ecf20Sopenharmony_ci } 9958c2ecf20Sopenharmony_ci 9968c2ecf20Sopenharmony_ci new_sock->dev = local->dev; 9978c2ecf20Sopenharmony_ci new_sock->rw = sock->rw; 9988c2ecf20Sopenharmony_ci new_sock->miux = sock->miux; 9998c2ecf20Sopenharmony_ci new_sock->nfc_protocol = sock->nfc_protocol; 10008c2ecf20Sopenharmony_ci new_sock->dsap = ssap; 10018c2ecf20Sopenharmony_ci new_sock->target_idx = local->target_idx; 10028c2ecf20Sopenharmony_ci new_sock->parent = parent; 10038c2ecf20Sopenharmony_ci new_sock->ssap = sock->ssap; 10048c2ecf20Sopenharmony_ci if (sock->ssap < LLCP_LOCAL_NUM_SAP && sock->ssap >= LLCP_WKS_NUM_SAP) { 10058c2ecf20Sopenharmony_ci atomic_t *client_count; 10068c2ecf20Sopenharmony_ci 10078c2ecf20Sopenharmony_ci pr_debug("reserved_ssap %d for %p\n", sock->ssap, new_sock); 10088c2ecf20Sopenharmony_ci 10098c2ecf20Sopenharmony_ci client_count = 10108c2ecf20Sopenharmony_ci &local->local_sdp_cnt[sock->ssap - LLCP_WKS_NUM_SAP]; 10118c2ecf20Sopenharmony_ci 10128c2ecf20Sopenharmony_ci atomic_inc(client_count); 10138c2ecf20Sopenharmony_ci new_sock->reserved_ssap = sock->ssap; 10148c2ecf20Sopenharmony_ci } 10158c2ecf20Sopenharmony_ci 10168c2ecf20Sopenharmony_ci nfc_llcp_parse_connection_tlv(new_sock, &skb->data[LLCP_HEADER_SIZE], 10178c2ecf20Sopenharmony_ci skb->len - LLCP_HEADER_SIZE); 10188c2ecf20Sopenharmony_ci 10198c2ecf20Sopenharmony_ci pr_debug("new sock %p sk %p\n", new_sock, &new_sock->sk); 10208c2ecf20Sopenharmony_ci 10218c2ecf20Sopenharmony_ci nfc_llcp_sock_link(&local->sockets, new_sk); 10228c2ecf20Sopenharmony_ci 10238c2ecf20Sopenharmony_ci nfc_llcp_accept_enqueue(&sock->sk, new_sk); 10248c2ecf20Sopenharmony_ci 10258c2ecf20Sopenharmony_ci nfc_get_device(local->dev->idx); 10268c2ecf20Sopenharmony_ci 10278c2ecf20Sopenharmony_ci new_sk->sk_state = LLCP_CONNECTED; 10288c2ecf20Sopenharmony_ci 10298c2ecf20Sopenharmony_ci /* Wake the listening processes */ 10308c2ecf20Sopenharmony_ci parent->sk_data_ready(parent); 10318c2ecf20Sopenharmony_ci 10328c2ecf20Sopenharmony_ci /* Send CC */ 10338c2ecf20Sopenharmony_ci nfc_llcp_send_cc(new_sock); 10348c2ecf20Sopenharmony_ci 10358c2ecf20Sopenharmony_ci release_sock(&sock->sk); 10368c2ecf20Sopenharmony_ci sock_put(&sock->sk); 10378c2ecf20Sopenharmony_ci 10388c2ecf20Sopenharmony_ci return; 10398c2ecf20Sopenharmony_ci 10408c2ecf20Sopenharmony_cifail: 10418c2ecf20Sopenharmony_ci /* Send DM */ 10428c2ecf20Sopenharmony_ci nfc_llcp_send_dm(local, dsap, ssap, reason); 10438c2ecf20Sopenharmony_ci} 10448c2ecf20Sopenharmony_ci 10458c2ecf20Sopenharmony_ciint nfc_llcp_queue_i_frames(struct nfc_llcp_sock *sock) 10468c2ecf20Sopenharmony_ci{ 10478c2ecf20Sopenharmony_ci int nr_frames = 0; 10488c2ecf20Sopenharmony_ci struct nfc_llcp_local *local = sock->local; 10498c2ecf20Sopenharmony_ci 10508c2ecf20Sopenharmony_ci pr_debug("Remote ready %d tx queue len %d remote rw %d", 10518c2ecf20Sopenharmony_ci sock->remote_ready, skb_queue_len(&sock->tx_pending_queue), 10528c2ecf20Sopenharmony_ci sock->remote_rw); 10538c2ecf20Sopenharmony_ci 10548c2ecf20Sopenharmony_ci /* Try to queue some I frames for transmission */ 10558c2ecf20Sopenharmony_ci while (sock->remote_ready && 10568c2ecf20Sopenharmony_ci skb_queue_len(&sock->tx_pending_queue) < sock->remote_rw) { 10578c2ecf20Sopenharmony_ci struct sk_buff *pdu; 10588c2ecf20Sopenharmony_ci 10598c2ecf20Sopenharmony_ci pdu = skb_dequeue(&sock->tx_queue); 10608c2ecf20Sopenharmony_ci if (pdu == NULL) 10618c2ecf20Sopenharmony_ci break; 10628c2ecf20Sopenharmony_ci 10638c2ecf20Sopenharmony_ci /* Update N(S)/N(R) */ 10648c2ecf20Sopenharmony_ci nfc_llcp_set_nrns(sock, pdu); 10658c2ecf20Sopenharmony_ci 10668c2ecf20Sopenharmony_ci skb_queue_tail(&local->tx_queue, pdu); 10678c2ecf20Sopenharmony_ci nr_frames++; 10688c2ecf20Sopenharmony_ci } 10698c2ecf20Sopenharmony_ci 10708c2ecf20Sopenharmony_ci return nr_frames; 10718c2ecf20Sopenharmony_ci} 10728c2ecf20Sopenharmony_ci 10738c2ecf20Sopenharmony_cistatic void nfc_llcp_recv_hdlc(struct nfc_llcp_local *local, 10748c2ecf20Sopenharmony_ci struct sk_buff *skb) 10758c2ecf20Sopenharmony_ci{ 10768c2ecf20Sopenharmony_ci struct nfc_llcp_sock *llcp_sock; 10778c2ecf20Sopenharmony_ci struct sock *sk; 10788c2ecf20Sopenharmony_ci u8 dsap, ssap, ptype, ns, nr; 10798c2ecf20Sopenharmony_ci 10808c2ecf20Sopenharmony_ci ptype = nfc_llcp_ptype(skb); 10818c2ecf20Sopenharmony_ci dsap = nfc_llcp_dsap(skb); 10828c2ecf20Sopenharmony_ci ssap = nfc_llcp_ssap(skb); 10838c2ecf20Sopenharmony_ci ns = nfc_llcp_ns(skb); 10848c2ecf20Sopenharmony_ci nr = nfc_llcp_nr(skb); 10858c2ecf20Sopenharmony_ci 10868c2ecf20Sopenharmony_ci pr_debug("%d %d R %d S %d\n", dsap, ssap, nr, ns); 10878c2ecf20Sopenharmony_ci 10888c2ecf20Sopenharmony_ci llcp_sock = nfc_llcp_sock_get(local, dsap, ssap); 10898c2ecf20Sopenharmony_ci if (llcp_sock == NULL) { 10908c2ecf20Sopenharmony_ci nfc_llcp_send_dm(local, dsap, ssap, LLCP_DM_NOCONN); 10918c2ecf20Sopenharmony_ci return; 10928c2ecf20Sopenharmony_ci } 10938c2ecf20Sopenharmony_ci 10948c2ecf20Sopenharmony_ci sk = &llcp_sock->sk; 10958c2ecf20Sopenharmony_ci lock_sock(sk); 10968c2ecf20Sopenharmony_ci if (sk->sk_state == LLCP_CLOSED) { 10978c2ecf20Sopenharmony_ci release_sock(sk); 10988c2ecf20Sopenharmony_ci nfc_llcp_sock_put(llcp_sock); 10998c2ecf20Sopenharmony_ci } 11008c2ecf20Sopenharmony_ci 11018c2ecf20Sopenharmony_ci /* Pass the payload upstream */ 11028c2ecf20Sopenharmony_ci if (ptype == LLCP_PDU_I) { 11038c2ecf20Sopenharmony_ci pr_debug("I frame, queueing on %p\n", &llcp_sock->sk); 11048c2ecf20Sopenharmony_ci 11058c2ecf20Sopenharmony_ci if (ns == llcp_sock->recv_n) 11068c2ecf20Sopenharmony_ci llcp_sock->recv_n = (llcp_sock->recv_n + 1) % 16; 11078c2ecf20Sopenharmony_ci else 11088c2ecf20Sopenharmony_ci pr_err("Received out of sequence I PDU\n"); 11098c2ecf20Sopenharmony_ci 11108c2ecf20Sopenharmony_ci skb_pull(skb, LLCP_HEADER_SIZE + LLCP_SEQUENCE_SIZE); 11118c2ecf20Sopenharmony_ci if (!sock_queue_rcv_skb(&llcp_sock->sk, skb)) { 11128c2ecf20Sopenharmony_ci /* 11138c2ecf20Sopenharmony_ci * I frames will be freed from the socket layer, so we 11148c2ecf20Sopenharmony_ci * need to keep them alive until someone receives them. 11158c2ecf20Sopenharmony_ci */ 11168c2ecf20Sopenharmony_ci skb_get(skb); 11178c2ecf20Sopenharmony_ci } else { 11188c2ecf20Sopenharmony_ci pr_err("Receive queue is full\n"); 11198c2ecf20Sopenharmony_ci } 11208c2ecf20Sopenharmony_ci } 11218c2ecf20Sopenharmony_ci 11228c2ecf20Sopenharmony_ci /* Remove skbs from the pending queue */ 11238c2ecf20Sopenharmony_ci if (llcp_sock->send_ack_n != nr) { 11248c2ecf20Sopenharmony_ci struct sk_buff *s, *tmp; 11258c2ecf20Sopenharmony_ci u8 n; 11268c2ecf20Sopenharmony_ci 11278c2ecf20Sopenharmony_ci llcp_sock->send_ack_n = nr; 11288c2ecf20Sopenharmony_ci 11298c2ecf20Sopenharmony_ci /* Remove and free all skbs until ns == nr */ 11308c2ecf20Sopenharmony_ci skb_queue_walk_safe(&llcp_sock->tx_pending_queue, s, tmp) { 11318c2ecf20Sopenharmony_ci n = nfc_llcp_ns(s); 11328c2ecf20Sopenharmony_ci 11338c2ecf20Sopenharmony_ci skb_unlink(s, &llcp_sock->tx_pending_queue); 11348c2ecf20Sopenharmony_ci kfree_skb(s); 11358c2ecf20Sopenharmony_ci 11368c2ecf20Sopenharmony_ci if (n == nr) 11378c2ecf20Sopenharmony_ci break; 11388c2ecf20Sopenharmony_ci } 11398c2ecf20Sopenharmony_ci 11408c2ecf20Sopenharmony_ci /* Re-queue the remaining skbs for transmission */ 11418c2ecf20Sopenharmony_ci skb_queue_reverse_walk_safe(&llcp_sock->tx_pending_queue, 11428c2ecf20Sopenharmony_ci s, tmp) { 11438c2ecf20Sopenharmony_ci skb_unlink(s, &llcp_sock->tx_pending_queue); 11448c2ecf20Sopenharmony_ci skb_queue_head(&local->tx_queue, s); 11458c2ecf20Sopenharmony_ci } 11468c2ecf20Sopenharmony_ci } 11478c2ecf20Sopenharmony_ci 11488c2ecf20Sopenharmony_ci if (ptype == LLCP_PDU_RR) 11498c2ecf20Sopenharmony_ci llcp_sock->remote_ready = true; 11508c2ecf20Sopenharmony_ci else if (ptype == LLCP_PDU_RNR) 11518c2ecf20Sopenharmony_ci llcp_sock->remote_ready = false; 11528c2ecf20Sopenharmony_ci 11538c2ecf20Sopenharmony_ci if (nfc_llcp_queue_i_frames(llcp_sock) == 0 && ptype == LLCP_PDU_I) 11548c2ecf20Sopenharmony_ci nfc_llcp_send_rr(llcp_sock); 11558c2ecf20Sopenharmony_ci 11568c2ecf20Sopenharmony_ci release_sock(sk); 11578c2ecf20Sopenharmony_ci nfc_llcp_sock_put(llcp_sock); 11588c2ecf20Sopenharmony_ci} 11598c2ecf20Sopenharmony_ci 11608c2ecf20Sopenharmony_cistatic void nfc_llcp_recv_disc(struct nfc_llcp_local *local, 11618c2ecf20Sopenharmony_ci const struct sk_buff *skb) 11628c2ecf20Sopenharmony_ci{ 11638c2ecf20Sopenharmony_ci struct nfc_llcp_sock *llcp_sock; 11648c2ecf20Sopenharmony_ci struct sock *sk; 11658c2ecf20Sopenharmony_ci u8 dsap, ssap; 11668c2ecf20Sopenharmony_ci 11678c2ecf20Sopenharmony_ci dsap = nfc_llcp_dsap(skb); 11688c2ecf20Sopenharmony_ci ssap = nfc_llcp_ssap(skb); 11698c2ecf20Sopenharmony_ci 11708c2ecf20Sopenharmony_ci if ((dsap == 0) && (ssap == 0)) { 11718c2ecf20Sopenharmony_ci pr_debug("Connection termination"); 11728c2ecf20Sopenharmony_ci nfc_dep_link_down(local->dev); 11738c2ecf20Sopenharmony_ci return; 11748c2ecf20Sopenharmony_ci } 11758c2ecf20Sopenharmony_ci 11768c2ecf20Sopenharmony_ci llcp_sock = nfc_llcp_sock_get(local, dsap, ssap); 11778c2ecf20Sopenharmony_ci if (llcp_sock == NULL) { 11788c2ecf20Sopenharmony_ci nfc_llcp_send_dm(local, dsap, ssap, LLCP_DM_NOCONN); 11798c2ecf20Sopenharmony_ci return; 11808c2ecf20Sopenharmony_ci } 11818c2ecf20Sopenharmony_ci 11828c2ecf20Sopenharmony_ci sk = &llcp_sock->sk; 11838c2ecf20Sopenharmony_ci lock_sock(sk); 11848c2ecf20Sopenharmony_ci 11858c2ecf20Sopenharmony_ci nfc_llcp_socket_purge(llcp_sock); 11868c2ecf20Sopenharmony_ci 11878c2ecf20Sopenharmony_ci if (sk->sk_state == LLCP_CLOSED) { 11888c2ecf20Sopenharmony_ci release_sock(sk); 11898c2ecf20Sopenharmony_ci nfc_llcp_sock_put(llcp_sock); 11908c2ecf20Sopenharmony_ci } 11918c2ecf20Sopenharmony_ci 11928c2ecf20Sopenharmony_ci if (sk->sk_state == LLCP_CONNECTED) { 11938c2ecf20Sopenharmony_ci nfc_put_device(local->dev); 11948c2ecf20Sopenharmony_ci sk->sk_state = LLCP_CLOSED; 11958c2ecf20Sopenharmony_ci sk->sk_state_change(sk); 11968c2ecf20Sopenharmony_ci } 11978c2ecf20Sopenharmony_ci 11988c2ecf20Sopenharmony_ci nfc_llcp_send_dm(local, dsap, ssap, LLCP_DM_DISC); 11998c2ecf20Sopenharmony_ci 12008c2ecf20Sopenharmony_ci release_sock(sk); 12018c2ecf20Sopenharmony_ci nfc_llcp_sock_put(llcp_sock); 12028c2ecf20Sopenharmony_ci} 12038c2ecf20Sopenharmony_ci 12048c2ecf20Sopenharmony_cistatic void nfc_llcp_recv_cc(struct nfc_llcp_local *local, 12058c2ecf20Sopenharmony_ci const struct sk_buff *skb) 12068c2ecf20Sopenharmony_ci{ 12078c2ecf20Sopenharmony_ci struct nfc_llcp_sock *llcp_sock; 12088c2ecf20Sopenharmony_ci struct sock *sk; 12098c2ecf20Sopenharmony_ci u8 dsap, ssap; 12108c2ecf20Sopenharmony_ci 12118c2ecf20Sopenharmony_ci dsap = nfc_llcp_dsap(skb); 12128c2ecf20Sopenharmony_ci ssap = nfc_llcp_ssap(skb); 12138c2ecf20Sopenharmony_ci 12148c2ecf20Sopenharmony_ci llcp_sock = nfc_llcp_connecting_sock_get(local, dsap); 12158c2ecf20Sopenharmony_ci if (llcp_sock == NULL) { 12168c2ecf20Sopenharmony_ci pr_err("Invalid CC\n"); 12178c2ecf20Sopenharmony_ci nfc_llcp_send_dm(local, dsap, ssap, LLCP_DM_NOCONN); 12188c2ecf20Sopenharmony_ci 12198c2ecf20Sopenharmony_ci return; 12208c2ecf20Sopenharmony_ci } 12218c2ecf20Sopenharmony_ci 12228c2ecf20Sopenharmony_ci sk = &llcp_sock->sk; 12238c2ecf20Sopenharmony_ci 12248c2ecf20Sopenharmony_ci /* Unlink from connecting and link to the client array */ 12258c2ecf20Sopenharmony_ci nfc_llcp_sock_unlink(&local->connecting_sockets, sk); 12268c2ecf20Sopenharmony_ci nfc_llcp_sock_link(&local->sockets, sk); 12278c2ecf20Sopenharmony_ci llcp_sock->dsap = ssap; 12288c2ecf20Sopenharmony_ci 12298c2ecf20Sopenharmony_ci nfc_llcp_parse_connection_tlv(llcp_sock, &skb->data[LLCP_HEADER_SIZE], 12308c2ecf20Sopenharmony_ci skb->len - LLCP_HEADER_SIZE); 12318c2ecf20Sopenharmony_ci 12328c2ecf20Sopenharmony_ci sk->sk_state = LLCP_CONNECTED; 12338c2ecf20Sopenharmony_ci sk->sk_state_change(sk); 12348c2ecf20Sopenharmony_ci 12358c2ecf20Sopenharmony_ci nfc_llcp_sock_put(llcp_sock); 12368c2ecf20Sopenharmony_ci} 12378c2ecf20Sopenharmony_ci 12388c2ecf20Sopenharmony_cistatic void nfc_llcp_recv_dm(struct nfc_llcp_local *local, 12398c2ecf20Sopenharmony_ci const struct sk_buff *skb) 12408c2ecf20Sopenharmony_ci{ 12418c2ecf20Sopenharmony_ci struct nfc_llcp_sock *llcp_sock; 12428c2ecf20Sopenharmony_ci struct sock *sk; 12438c2ecf20Sopenharmony_ci u8 dsap, ssap, reason; 12448c2ecf20Sopenharmony_ci 12458c2ecf20Sopenharmony_ci dsap = nfc_llcp_dsap(skb); 12468c2ecf20Sopenharmony_ci ssap = nfc_llcp_ssap(skb); 12478c2ecf20Sopenharmony_ci reason = skb->data[2]; 12488c2ecf20Sopenharmony_ci 12498c2ecf20Sopenharmony_ci pr_debug("%d %d reason %d\n", ssap, dsap, reason); 12508c2ecf20Sopenharmony_ci 12518c2ecf20Sopenharmony_ci switch (reason) { 12528c2ecf20Sopenharmony_ci case LLCP_DM_NOBOUND: 12538c2ecf20Sopenharmony_ci case LLCP_DM_REJ: 12548c2ecf20Sopenharmony_ci llcp_sock = nfc_llcp_connecting_sock_get(local, dsap); 12558c2ecf20Sopenharmony_ci break; 12568c2ecf20Sopenharmony_ci 12578c2ecf20Sopenharmony_ci default: 12588c2ecf20Sopenharmony_ci llcp_sock = nfc_llcp_sock_get(local, dsap, ssap); 12598c2ecf20Sopenharmony_ci break; 12608c2ecf20Sopenharmony_ci } 12618c2ecf20Sopenharmony_ci 12628c2ecf20Sopenharmony_ci if (llcp_sock == NULL) { 12638c2ecf20Sopenharmony_ci pr_debug("Already closed\n"); 12648c2ecf20Sopenharmony_ci return; 12658c2ecf20Sopenharmony_ci } 12668c2ecf20Sopenharmony_ci 12678c2ecf20Sopenharmony_ci sk = &llcp_sock->sk; 12688c2ecf20Sopenharmony_ci 12698c2ecf20Sopenharmony_ci sk->sk_err = ENXIO; 12708c2ecf20Sopenharmony_ci sk->sk_state = LLCP_CLOSED; 12718c2ecf20Sopenharmony_ci sk->sk_state_change(sk); 12728c2ecf20Sopenharmony_ci 12738c2ecf20Sopenharmony_ci nfc_llcp_sock_put(llcp_sock); 12748c2ecf20Sopenharmony_ci} 12758c2ecf20Sopenharmony_ci 12768c2ecf20Sopenharmony_cistatic void nfc_llcp_recv_snl(struct nfc_llcp_local *local, 12778c2ecf20Sopenharmony_ci const struct sk_buff *skb) 12788c2ecf20Sopenharmony_ci{ 12798c2ecf20Sopenharmony_ci struct nfc_llcp_sock *llcp_sock; 12808c2ecf20Sopenharmony_ci u8 dsap, ssap, type, length, tid, sap; 12818c2ecf20Sopenharmony_ci const u8 *tlv; 12828c2ecf20Sopenharmony_ci u16 tlv_len, offset; 12838c2ecf20Sopenharmony_ci const char *service_name; 12848c2ecf20Sopenharmony_ci size_t service_name_len; 12858c2ecf20Sopenharmony_ci struct nfc_llcp_sdp_tlv *sdp; 12868c2ecf20Sopenharmony_ci HLIST_HEAD(llc_sdres_list); 12878c2ecf20Sopenharmony_ci size_t sdres_tlvs_len; 12888c2ecf20Sopenharmony_ci HLIST_HEAD(nl_sdres_list); 12898c2ecf20Sopenharmony_ci 12908c2ecf20Sopenharmony_ci dsap = nfc_llcp_dsap(skb); 12918c2ecf20Sopenharmony_ci ssap = nfc_llcp_ssap(skb); 12928c2ecf20Sopenharmony_ci 12938c2ecf20Sopenharmony_ci pr_debug("%d %d\n", dsap, ssap); 12948c2ecf20Sopenharmony_ci 12958c2ecf20Sopenharmony_ci if (dsap != LLCP_SAP_SDP || ssap != LLCP_SAP_SDP) { 12968c2ecf20Sopenharmony_ci pr_err("Wrong SNL SAP\n"); 12978c2ecf20Sopenharmony_ci return; 12988c2ecf20Sopenharmony_ci } 12998c2ecf20Sopenharmony_ci 13008c2ecf20Sopenharmony_ci tlv = &skb->data[LLCP_HEADER_SIZE]; 13018c2ecf20Sopenharmony_ci tlv_len = skb->len - LLCP_HEADER_SIZE; 13028c2ecf20Sopenharmony_ci offset = 0; 13038c2ecf20Sopenharmony_ci sdres_tlvs_len = 0; 13048c2ecf20Sopenharmony_ci 13058c2ecf20Sopenharmony_ci while (offset < tlv_len) { 13068c2ecf20Sopenharmony_ci type = tlv[0]; 13078c2ecf20Sopenharmony_ci length = tlv[1]; 13088c2ecf20Sopenharmony_ci 13098c2ecf20Sopenharmony_ci switch (type) { 13108c2ecf20Sopenharmony_ci case LLCP_TLV_SDREQ: 13118c2ecf20Sopenharmony_ci tid = tlv[2]; 13128c2ecf20Sopenharmony_ci service_name = (char *) &tlv[3]; 13138c2ecf20Sopenharmony_ci service_name_len = length - 1; 13148c2ecf20Sopenharmony_ci 13158c2ecf20Sopenharmony_ci pr_debug("Looking for %.16s\n", service_name); 13168c2ecf20Sopenharmony_ci 13178c2ecf20Sopenharmony_ci if (service_name_len == strlen("urn:nfc:sn:sdp") && 13188c2ecf20Sopenharmony_ci !strncmp(service_name, "urn:nfc:sn:sdp", 13198c2ecf20Sopenharmony_ci service_name_len)) { 13208c2ecf20Sopenharmony_ci sap = 1; 13218c2ecf20Sopenharmony_ci goto add_snl; 13228c2ecf20Sopenharmony_ci } 13238c2ecf20Sopenharmony_ci 13248c2ecf20Sopenharmony_ci llcp_sock = nfc_llcp_sock_from_sn(local, service_name, 13258c2ecf20Sopenharmony_ci service_name_len, 13268c2ecf20Sopenharmony_ci true); 13278c2ecf20Sopenharmony_ci if (!llcp_sock) { 13288c2ecf20Sopenharmony_ci sap = 0; 13298c2ecf20Sopenharmony_ci goto add_snl; 13308c2ecf20Sopenharmony_ci } 13318c2ecf20Sopenharmony_ci 13328c2ecf20Sopenharmony_ci /* 13338c2ecf20Sopenharmony_ci * We found a socket but its ssap has not been reserved 13348c2ecf20Sopenharmony_ci * yet. We need to assign it for good and send a reply. 13358c2ecf20Sopenharmony_ci * The ssap will be freed when the socket is closed. 13368c2ecf20Sopenharmony_ci */ 13378c2ecf20Sopenharmony_ci if (llcp_sock->ssap == LLCP_SDP_UNBOUND) { 13388c2ecf20Sopenharmony_ci atomic_t *client_count; 13398c2ecf20Sopenharmony_ci 13408c2ecf20Sopenharmony_ci sap = nfc_llcp_reserve_sdp_ssap(local); 13418c2ecf20Sopenharmony_ci 13428c2ecf20Sopenharmony_ci pr_debug("Reserving %d\n", sap); 13438c2ecf20Sopenharmony_ci 13448c2ecf20Sopenharmony_ci if (sap == LLCP_SAP_MAX) { 13458c2ecf20Sopenharmony_ci sap = 0; 13468c2ecf20Sopenharmony_ci nfc_llcp_sock_put(llcp_sock); 13478c2ecf20Sopenharmony_ci goto add_snl; 13488c2ecf20Sopenharmony_ci } 13498c2ecf20Sopenharmony_ci 13508c2ecf20Sopenharmony_ci client_count = 13518c2ecf20Sopenharmony_ci &local->local_sdp_cnt[sap - 13528c2ecf20Sopenharmony_ci LLCP_WKS_NUM_SAP]; 13538c2ecf20Sopenharmony_ci 13548c2ecf20Sopenharmony_ci atomic_inc(client_count); 13558c2ecf20Sopenharmony_ci 13568c2ecf20Sopenharmony_ci llcp_sock->ssap = sap; 13578c2ecf20Sopenharmony_ci llcp_sock->reserved_ssap = sap; 13588c2ecf20Sopenharmony_ci } else { 13598c2ecf20Sopenharmony_ci sap = llcp_sock->ssap; 13608c2ecf20Sopenharmony_ci } 13618c2ecf20Sopenharmony_ci 13628c2ecf20Sopenharmony_ci pr_debug("%p %d\n", llcp_sock, sap); 13638c2ecf20Sopenharmony_ci 13648c2ecf20Sopenharmony_ci nfc_llcp_sock_put(llcp_sock); 13658c2ecf20Sopenharmony_ciadd_snl: 13668c2ecf20Sopenharmony_ci sdp = nfc_llcp_build_sdres_tlv(tid, sap); 13678c2ecf20Sopenharmony_ci if (sdp == NULL) 13688c2ecf20Sopenharmony_ci goto exit; 13698c2ecf20Sopenharmony_ci 13708c2ecf20Sopenharmony_ci sdres_tlvs_len += sdp->tlv_len; 13718c2ecf20Sopenharmony_ci hlist_add_head(&sdp->node, &llc_sdres_list); 13728c2ecf20Sopenharmony_ci break; 13738c2ecf20Sopenharmony_ci 13748c2ecf20Sopenharmony_ci case LLCP_TLV_SDRES: 13758c2ecf20Sopenharmony_ci mutex_lock(&local->sdreq_lock); 13768c2ecf20Sopenharmony_ci 13778c2ecf20Sopenharmony_ci pr_debug("LLCP_TLV_SDRES: searching tid %d\n", tlv[2]); 13788c2ecf20Sopenharmony_ci 13798c2ecf20Sopenharmony_ci hlist_for_each_entry(sdp, &local->pending_sdreqs, node) { 13808c2ecf20Sopenharmony_ci if (sdp->tid != tlv[2]) 13818c2ecf20Sopenharmony_ci continue; 13828c2ecf20Sopenharmony_ci 13838c2ecf20Sopenharmony_ci sdp->sap = tlv[3]; 13848c2ecf20Sopenharmony_ci 13858c2ecf20Sopenharmony_ci pr_debug("Found: uri=%s, sap=%d\n", 13868c2ecf20Sopenharmony_ci sdp->uri, sdp->sap); 13878c2ecf20Sopenharmony_ci 13888c2ecf20Sopenharmony_ci hlist_del(&sdp->node); 13898c2ecf20Sopenharmony_ci 13908c2ecf20Sopenharmony_ci hlist_add_head(&sdp->node, &nl_sdres_list); 13918c2ecf20Sopenharmony_ci 13928c2ecf20Sopenharmony_ci break; 13938c2ecf20Sopenharmony_ci } 13948c2ecf20Sopenharmony_ci 13958c2ecf20Sopenharmony_ci mutex_unlock(&local->sdreq_lock); 13968c2ecf20Sopenharmony_ci break; 13978c2ecf20Sopenharmony_ci 13988c2ecf20Sopenharmony_ci default: 13998c2ecf20Sopenharmony_ci pr_err("Invalid SNL tlv value 0x%x\n", type); 14008c2ecf20Sopenharmony_ci break; 14018c2ecf20Sopenharmony_ci } 14028c2ecf20Sopenharmony_ci 14038c2ecf20Sopenharmony_ci offset += length + 2; 14048c2ecf20Sopenharmony_ci tlv += length + 2; 14058c2ecf20Sopenharmony_ci } 14068c2ecf20Sopenharmony_ci 14078c2ecf20Sopenharmony_ciexit: 14088c2ecf20Sopenharmony_ci if (!hlist_empty(&nl_sdres_list)) 14098c2ecf20Sopenharmony_ci nfc_genl_llc_send_sdres(local->dev, &nl_sdres_list); 14108c2ecf20Sopenharmony_ci 14118c2ecf20Sopenharmony_ci if (!hlist_empty(&llc_sdres_list)) 14128c2ecf20Sopenharmony_ci nfc_llcp_send_snl_sdres(local, &llc_sdres_list, sdres_tlvs_len); 14138c2ecf20Sopenharmony_ci} 14148c2ecf20Sopenharmony_ci 14158c2ecf20Sopenharmony_cistatic void nfc_llcp_recv_agf(struct nfc_llcp_local *local, struct sk_buff *skb) 14168c2ecf20Sopenharmony_ci{ 14178c2ecf20Sopenharmony_ci u8 ptype; 14188c2ecf20Sopenharmony_ci u16 pdu_len; 14198c2ecf20Sopenharmony_ci struct sk_buff *new_skb; 14208c2ecf20Sopenharmony_ci 14218c2ecf20Sopenharmony_ci if (skb->len <= LLCP_HEADER_SIZE) { 14228c2ecf20Sopenharmony_ci pr_err("Malformed AGF PDU\n"); 14238c2ecf20Sopenharmony_ci return; 14248c2ecf20Sopenharmony_ci } 14258c2ecf20Sopenharmony_ci 14268c2ecf20Sopenharmony_ci skb_pull(skb, LLCP_HEADER_SIZE); 14278c2ecf20Sopenharmony_ci 14288c2ecf20Sopenharmony_ci while (skb->len > LLCP_AGF_PDU_HEADER_SIZE) { 14298c2ecf20Sopenharmony_ci pdu_len = skb->data[0] << 8 | skb->data[1]; 14308c2ecf20Sopenharmony_ci 14318c2ecf20Sopenharmony_ci skb_pull(skb, LLCP_AGF_PDU_HEADER_SIZE); 14328c2ecf20Sopenharmony_ci 14338c2ecf20Sopenharmony_ci if (pdu_len < LLCP_HEADER_SIZE || pdu_len > skb->len) { 14348c2ecf20Sopenharmony_ci pr_err("Malformed AGF PDU\n"); 14358c2ecf20Sopenharmony_ci return; 14368c2ecf20Sopenharmony_ci } 14378c2ecf20Sopenharmony_ci 14388c2ecf20Sopenharmony_ci ptype = nfc_llcp_ptype(skb); 14398c2ecf20Sopenharmony_ci 14408c2ecf20Sopenharmony_ci if (ptype == LLCP_PDU_SYMM || ptype == LLCP_PDU_AGF) 14418c2ecf20Sopenharmony_ci goto next; 14428c2ecf20Sopenharmony_ci 14438c2ecf20Sopenharmony_ci new_skb = nfc_alloc_recv_skb(pdu_len, GFP_KERNEL); 14448c2ecf20Sopenharmony_ci if (new_skb == NULL) { 14458c2ecf20Sopenharmony_ci pr_err("Could not allocate PDU\n"); 14468c2ecf20Sopenharmony_ci return; 14478c2ecf20Sopenharmony_ci } 14488c2ecf20Sopenharmony_ci 14498c2ecf20Sopenharmony_ci skb_put_data(new_skb, skb->data, pdu_len); 14508c2ecf20Sopenharmony_ci 14518c2ecf20Sopenharmony_ci nfc_llcp_rx_skb(local, new_skb); 14528c2ecf20Sopenharmony_ci 14538c2ecf20Sopenharmony_ci kfree_skb(new_skb); 14548c2ecf20Sopenharmony_cinext: 14558c2ecf20Sopenharmony_ci skb_pull(skb, pdu_len); 14568c2ecf20Sopenharmony_ci } 14578c2ecf20Sopenharmony_ci} 14588c2ecf20Sopenharmony_ci 14598c2ecf20Sopenharmony_cistatic void nfc_llcp_rx_skb(struct nfc_llcp_local *local, struct sk_buff *skb) 14608c2ecf20Sopenharmony_ci{ 14618c2ecf20Sopenharmony_ci u8 dsap, ssap, ptype; 14628c2ecf20Sopenharmony_ci 14638c2ecf20Sopenharmony_ci ptype = nfc_llcp_ptype(skb); 14648c2ecf20Sopenharmony_ci dsap = nfc_llcp_dsap(skb); 14658c2ecf20Sopenharmony_ci ssap = nfc_llcp_ssap(skb); 14668c2ecf20Sopenharmony_ci 14678c2ecf20Sopenharmony_ci pr_debug("ptype 0x%x dsap 0x%x ssap 0x%x\n", ptype, dsap, ssap); 14688c2ecf20Sopenharmony_ci 14698c2ecf20Sopenharmony_ci if (ptype != LLCP_PDU_SYMM) 14708c2ecf20Sopenharmony_ci print_hex_dump_debug("LLCP Rx: ", DUMP_PREFIX_OFFSET, 16, 1, 14718c2ecf20Sopenharmony_ci skb->data, skb->len, true); 14728c2ecf20Sopenharmony_ci 14738c2ecf20Sopenharmony_ci switch (ptype) { 14748c2ecf20Sopenharmony_ci case LLCP_PDU_SYMM: 14758c2ecf20Sopenharmony_ci pr_debug("SYMM\n"); 14768c2ecf20Sopenharmony_ci break; 14778c2ecf20Sopenharmony_ci 14788c2ecf20Sopenharmony_ci case LLCP_PDU_UI: 14798c2ecf20Sopenharmony_ci pr_debug("UI\n"); 14808c2ecf20Sopenharmony_ci nfc_llcp_recv_ui(local, skb); 14818c2ecf20Sopenharmony_ci break; 14828c2ecf20Sopenharmony_ci 14838c2ecf20Sopenharmony_ci case LLCP_PDU_CONNECT: 14848c2ecf20Sopenharmony_ci pr_debug("CONNECT\n"); 14858c2ecf20Sopenharmony_ci nfc_llcp_recv_connect(local, skb); 14868c2ecf20Sopenharmony_ci break; 14878c2ecf20Sopenharmony_ci 14888c2ecf20Sopenharmony_ci case LLCP_PDU_DISC: 14898c2ecf20Sopenharmony_ci pr_debug("DISC\n"); 14908c2ecf20Sopenharmony_ci nfc_llcp_recv_disc(local, skb); 14918c2ecf20Sopenharmony_ci break; 14928c2ecf20Sopenharmony_ci 14938c2ecf20Sopenharmony_ci case LLCP_PDU_CC: 14948c2ecf20Sopenharmony_ci pr_debug("CC\n"); 14958c2ecf20Sopenharmony_ci nfc_llcp_recv_cc(local, skb); 14968c2ecf20Sopenharmony_ci break; 14978c2ecf20Sopenharmony_ci 14988c2ecf20Sopenharmony_ci case LLCP_PDU_DM: 14998c2ecf20Sopenharmony_ci pr_debug("DM\n"); 15008c2ecf20Sopenharmony_ci nfc_llcp_recv_dm(local, skb); 15018c2ecf20Sopenharmony_ci break; 15028c2ecf20Sopenharmony_ci 15038c2ecf20Sopenharmony_ci case LLCP_PDU_SNL: 15048c2ecf20Sopenharmony_ci pr_debug("SNL\n"); 15058c2ecf20Sopenharmony_ci nfc_llcp_recv_snl(local, skb); 15068c2ecf20Sopenharmony_ci break; 15078c2ecf20Sopenharmony_ci 15088c2ecf20Sopenharmony_ci case LLCP_PDU_I: 15098c2ecf20Sopenharmony_ci case LLCP_PDU_RR: 15108c2ecf20Sopenharmony_ci case LLCP_PDU_RNR: 15118c2ecf20Sopenharmony_ci pr_debug("I frame\n"); 15128c2ecf20Sopenharmony_ci nfc_llcp_recv_hdlc(local, skb); 15138c2ecf20Sopenharmony_ci break; 15148c2ecf20Sopenharmony_ci 15158c2ecf20Sopenharmony_ci case LLCP_PDU_AGF: 15168c2ecf20Sopenharmony_ci pr_debug("AGF frame\n"); 15178c2ecf20Sopenharmony_ci nfc_llcp_recv_agf(local, skb); 15188c2ecf20Sopenharmony_ci break; 15198c2ecf20Sopenharmony_ci } 15208c2ecf20Sopenharmony_ci} 15218c2ecf20Sopenharmony_ci 15228c2ecf20Sopenharmony_cistatic void nfc_llcp_rx_work(struct work_struct *work) 15238c2ecf20Sopenharmony_ci{ 15248c2ecf20Sopenharmony_ci struct nfc_llcp_local *local = container_of(work, struct nfc_llcp_local, 15258c2ecf20Sopenharmony_ci rx_work); 15268c2ecf20Sopenharmony_ci struct sk_buff *skb; 15278c2ecf20Sopenharmony_ci 15288c2ecf20Sopenharmony_ci skb = local->rx_pending; 15298c2ecf20Sopenharmony_ci if (skb == NULL) { 15308c2ecf20Sopenharmony_ci pr_debug("No pending SKB\n"); 15318c2ecf20Sopenharmony_ci return; 15328c2ecf20Sopenharmony_ci } 15338c2ecf20Sopenharmony_ci 15348c2ecf20Sopenharmony_ci __net_timestamp(skb); 15358c2ecf20Sopenharmony_ci 15368c2ecf20Sopenharmony_ci nfc_llcp_send_to_raw_sock(local, skb, NFC_DIRECTION_RX); 15378c2ecf20Sopenharmony_ci 15388c2ecf20Sopenharmony_ci nfc_llcp_rx_skb(local, skb); 15398c2ecf20Sopenharmony_ci 15408c2ecf20Sopenharmony_ci schedule_work(&local->tx_work); 15418c2ecf20Sopenharmony_ci kfree_skb(local->rx_pending); 15428c2ecf20Sopenharmony_ci local->rx_pending = NULL; 15438c2ecf20Sopenharmony_ci} 15448c2ecf20Sopenharmony_ci 15458c2ecf20Sopenharmony_cistatic void __nfc_llcp_recv(struct nfc_llcp_local *local, struct sk_buff *skb) 15468c2ecf20Sopenharmony_ci{ 15478c2ecf20Sopenharmony_ci local->rx_pending = skb; 15488c2ecf20Sopenharmony_ci del_timer(&local->link_timer); 15498c2ecf20Sopenharmony_ci schedule_work(&local->rx_work); 15508c2ecf20Sopenharmony_ci} 15518c2ecf20Sopenharmony_ci 15528c2ecf20Sopenharmony_civoid nfc_llcp_recv(void *data, struct sk_buff *skb, int err) 15538c2ecf20Sopenharmony_ci{ 15548c2ecf20Sopenharmony_ci struct nfc_llcp_local *local = (struct nfc_llcp_local *) data; 15558c2ecf20Sopenharmony_ci 15568c2ecf20Sopenharmony_ci pr_debug("Received an LLCP PDU\n"); 15578c2ecf20Sopenharmony_ci if (err < 0) { 15588c2ecf20Sopenharmony_ci pr_err("err %d\n", err); 15598c2ecf20Sopenharmony_ci return; 15608c2ecf20Sopenharmony_ci } 15618c2ecf20Sopenharmony_ci 15628c2ecf20Sopenharmony_ci __nfc_llcp_recv(local, skb); 15638c2ecf20Sopenharmony_ci} 15648c2ecf20Sopenharmony_ci 15658c2ecf20Sopenharmony_ciint nfc_llcp_data_received(struct nfc_dev *dev, struct sk_buff *skb) 15668c2ecf20Sopenharmony_ci{ 15678c2ecf20Sopenharmony_ci struct nfc_llcp_local *local; 15688c2ecf20Sopenharmony_ci 15698c2ecf20Sopenharmony_ci local = nfc_llcp_find_local(dev); 15708c2ecf20Sopenharmony_ci if (local == NULL) { 15718c2ecf20Sopenharmony_ci kfree_skb(skb); 15728c2ecf20Sopenharmony_ci return -ENODEV; 15738c2ecf20Sopenharmony_ci } 15748c2ecf20Sopenharmony_ci 15758c2ecf20Sopenharmony_ci __nfc_llcp_recv(local, skb); 15768c2ecf20Sopenharmony_ci 15778c2ecf20Sopenharmony_ci nfc_llcp_local_put(local); 15788c2ecf20Sopenharmony_ci 15798c2ecf20Sopenharmony_ci return 0; 15808c2ecf20Sopenharmony_ci} 15818c2ecf20Sopenharmony_ci 15828c2ecf20Sopenharmony_civoid nfc_llcp_mac_is_down(struct nfc_dev *dev) 15838c2ecf20Sopenharmony_ci{ 15848c2ecf20Sopenharmony_ci struct nfc_llcp_local *local; 15858c2ecf20Sopenharmony_ci 15868c2ecf20Sopenharmony_ci local = nfc_llcp_find_local(dev); 15878c2ecf20Sopenharmony_ci if (local == NULL) 15888c2ecf20Sopenharmony_ci return; 15898c2ecf20Sopenharmony_ci 15908c2ecf20Sopenharmony_ci local->remote_miu = LLCP_DEFAULT_MIU; 15918c2ecf20Sopenharmony_ci local->remote_lto = LLCP_DEFAULT_LTO; 15928c2ecf20Sopenharmony_ci 15938c2ecf20Sopenharmony_ci /* Close and purge all existing sockets */ 15948c2ecf20Sopenharmony_ci nfc_llcp_socket_release(local, true, 0); 15958c2ecf20Sopenharmony_ci 15968c2ecf20Sopenharmony_ci nfc_llcp_local_put(local); 15978c2ecf20Sopenharmony_ci} 15988c2ecf20Sopenharmony_ci 15998c2ecf20Sopenharmony_civoid nfc_llcp_mac_is_up(struct nfc_dev *dev, u32 target_idx, 16008c2ecf20Sopenharmony_ci u8 comm_mode, u8 rf_mode) 16018c2ecf20Sopenharmony_ci{ 16028c2ecf20Sopenharmony_ci struct nfc_llcp_local *local; 16038c2ecf20Sopenharmony_ci 16048c2ecf20Sopenharmony_ci pr_debug("rf mode %d\n", rf_mode); 16058c2ecf20Sopenharmony_ci 16068c2ecf20Sopenharmony_ci local = nfc_llcp_find_local(dev); 16078c2ecf20Sopenharmony_ci if (local == NULL) 16088c2ecf20Sopenharmony_ci return; 16098c2ecf20Sopenharmony_ci 16108c2ecf20Sopenharmony_ci local->target_idx = target_idx; 16118c2ecf20Sopenharmony_ci local->comm_mode = comm_mode; 16128c2ecf20Sopenharmony_ci local->rf_mode = rf_mode; 16138c2ecf20Sopenharmony_ci 16148c2ecf20Sopenharmony_ci if (rf_mode == NFC_RF_INITIATOR) { 16158c2ecf20Sopenharmony_ci pr_debug("Queueing Tx work\n"); 16168c2ecf20Sopenharmony_ci 16178c2ecf20Sopenharmony_ci schedule_work(&local->tx_work); 16188c2ecf20Sopenharmony_ci } else { 16198c2ecf20Sopenharmony_ci mod_timer(&local->link_timer, 16208c2ecf20Sopenharmony_ci jiffies + msecs_to_jiffies(local->remote_lto)); 16218c2ecf20Sopenharmony_ci } 16228c2ecf20Sopenharmony_ci 16238c2ecf20Sopenharmony_ci nfc_llcp_local_put(local); 16248c2ecf20Sopenharmony_ci} 16258c2ecf20Sopenharmony_ci 16268c2ecf20Sopenharmony_ciint nfc_llcp_register_device(struct nfc_dev *ndev) 16278c2ecf20Sopenharmony_ci{ 16288c2ecf20Sopenharmony_ci struct nfc_llcp_local *local; 16298c2ecf20Sopenharmony_ci 16308c2ecf20Sopenharmony_ci local = kzalloc(sizeof(struct nfc_llcp_local), GFP_KERNEL); 16318c2ecf20Sopenharmony_ci if (local == NULL) 16328c2ecf20Sopenharmony_ci return -ENOMEM; 16338c2ecf20Sopenharmony_ci 16348c2ecf20Sopenharmony_ci /* As we are going to initialize local's refcount, we need to get the 16358c2ecf20Sopenharmony_ci * nfc_dev to avoid UAF, otherwise there is no point in continuing. 16368c2ecf20Sopenharmony_ci * See nfc_llcp_local_get(). 16378c2ecf20Sopenharmony_ci */ 16388c2ecf20Sopenharmony_ci local->dev = nfc_get_device(ndev->idx); 16398c2ecf20Sopenharmony_ci if (!local->dev) { 16408c2ecf20Sopenharmony_ci kfree(local); 16418c2ecf20Sopenharmony_ci return -ENODEV; 16428c2ecf20Sopenharmony_ci } 16438c2ecf20Sopenharmony_ci 16448c2ecf20Sopenharmony_ci INIT_LIST_HEAD(&local->list); 16458c2ecf20Sopenharmony_ci kref_init(&local->ref); 16468c2ecf20Sopenharmony_ci mutex_init(&local->sdp_lock); 16478c2ecf20Sopenharmony_ci timer_setup(&local->link_timer, nfc_llcp_symm_timer, 0); 16488c2ecf20Sopenharmony_ci 16498c2ecf20Sopenharmony_ci skb_queue_head_init(&local->tx_queue); 16508c2ecf20Sopenharmony_ci INIT_WORK(&local->tx_work, nfc_llcp_tx_work); 16518c2ecf20Sopenharmony_ci 16528c2ecf20Sopenharmony_ci local->rx_pending = NULL; 16538c2ecf20Sopenharmony_ci INIT_WORK(&local->rx_work, nfc_llcp_rx_work); 16548c2ecf20Sopenharmony_ci 16558c2ecf20Sopenharmony_ci INIT_WORK(&local->timeout_work, nfc_llcp_timeout_work); 16568c2ecf20Sopenharmony_ci 16578c2ecf20Sopenharmony_ci rwlock_init(&local->sockets.lock); 16588c2ecf20Sopenharmony_ci rwlock_init(&local->connecting_sockets.lock); 16598c2ecf20Sopenharmony_ci rwlock_init(&local->raw_sockets.lock); 16608c2ecf20Sopenharmony_ci 16618c2ecf20Sopenharmony_ci local->lto = 150; /* 1500 ms */ 16628c2ecf20Sopenharmony_ci local->rw = LLCP_MAX_RW; 16638c2ecf20Sopenharmony_ci local->miux = cpu_to_be16(LLCP_MAX_MIUX); 16648c2ecf20Sopenharmony_ci local->local_wks = 0x1; /* LLC Link Management */ 16658c2ecf20Sopenharmony_ci 16668c2ecf20Sopenharmony_ci nfc_llcp_build_gb(local); 16678c2ecf20Sopenharmony_ci 16688c2ecf20Sopenharmony_ci local->remote_miu = LLCP_DEFAULT_MIU; 16698c2ecf20Sopenharmony_ci local->remote_lto = LLCP_DEFAULT_LTO; 16708c2ecf20Sopenharmony_ci 16718c2ecf20Sopenharmony_ci mutex_init(&local->sdreq_lock); 16728c2ecf20Sopenharmony_ci INIT_HLIST_HEAD(&local->pending_sdreqs); 16738c2ecf20Sopenharmony_ci timer_setup(&local->sdreq_timer, nfc_llcp_sdreq_timer, 0); 16748c2ecf20Sopenharmony_ci INIT_WORK(&local->sdreq_timeout_work, nfc_llcp_sdreq_timeout_work); 16758c2ecf20Sopenharmony_ci 16768c2ecf20Sopenharmony_ci spin_lock(&llcp_devices_lock); 16778c2ecf20Sopenharmony_ci list_add(&local->list, &llcp_devices); 16788c2ecf20Sopenharmony_ci spin_unlock(&llcp_devices_lock); 16798c2ecf20Sopenharmony_ci 16808c2ecf20Sopenharmony_ci return 0; 16818c2ecf20Sopenharmony_ci} 16828c2ecf20Sopenharmony_ci 16838c2ecf20Sopenharmony_civoid nfc_llcp_unregister_device(struct nfc_dev *dev) 16848c2ecf20Sopenharmony_ci{ 16858c2ecf20Sopenharmony_ci struct nfc_llcp_local *local = nfc_llcp_remove_local(dev); 16868c2ecf20Sopenharmony_ci 16878c2ecf20Sopenharmony_ci if (local == NULL) { 16888c2ecf20Sopenharmony_ci pr_debug("No such device\n"); 16898c2ecf20Sopenharmony_ci return; 16908c2ecf20Sopenharmony_ci } 16918c2ecf20Sopenharmony_ci 16928c2ecf20Sopenharmony_ci local_cleanup(local); 16938c2ecf20Sopenharmony_ci 16948c2ecf20Sopenharmony_ci nfc_llcp_local_put(local); 16958c2ecf20Sopenharmony_ci} 16968c2ecf20Sopenharmony_ci 16978c2ecf20Sopenharmony_ciint __init nfc_llcp_init(void) 16988c2ecf20Sopenharmony_ci{ 16998c2ecf20Sopenharmony_ci return nfc_llcp_sock_init(); 17008c2ecf20Sopenharmony_ci} 17018c2ecf20Sopenharmony_ci 17028c2ecf20Sopenharmony_civoid nfc_llcp_exit(void) 17038c2ecf20Sopenharmony_ci{ 17048c2ecf20Sopenharmony_ci nfc_llcp_sock_exit(); 17058c2ecf20Sopenharmony_ci} 1706