162306a36Sopenharmony_ci/*
262306a36Sopenharmony_ci   CMTP implementation for Linux Bluetooth stack (BlueZ).
362306a36Sopenharmony_ci   Copyright (C) 2002-2003 Marcel Holtmann <marcel@holtmann.org>
462306a36Sopenharmony_ci
562306a36Sopenharmony_ci   This program is free software; you can redistribute it and/or modify
662306a36Sopenharmony_ci   it under the terms of the GNU General Public License version 2 as
762306a36Sopenharmony_ci   published by the Free Software Foundation;
862306a36Sopenharmony_ci
962306a36Sopenharmony_ci   THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS
1062306a36Sopenharmony_ci   OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
1162306a36Sopenharmony_ci   FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT OF THIRD PARTY RIGHTS.
1262306a36Sopenharmony_ci   IN NO EVENT SHALL THE COPYRIGHT HOLDER(S) AND AUTHOR(S) BE LIABLE FOR ANY
1362306a36Sopenharmony_ci   CLAIM, OR ANY SPECIAL INDIRECT OR CONSEQUENTIAL DAMAGES, OR ANY DAMAGES
1462306a36Sopenharmony_ci   WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
1562306a36Sopenharmony_ci   ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
1662306a36Sopenharmony_ci   OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
1762306a36Sopenharmony_ci
1862306a36Sopenharmony_ci   ALL LIABILITY, INCLUDING LIABILITY FOR INFRINGEMENT OF ANY PATENTS,
1962306a36Sopenharmony_ci   COPYRIGHTS, TRADEMARKS OR OTHER RIGHTS, RELATING TO USE OF THIS
2062306a36Sopenharmony_ci   SOFTWARE IS DISCLAIMED.
2162306a36Sopenharmony_ci*/
2262306a36Sopenharmony_ci
2362306a36Sopenharmony_ci#include <linux/module.h>
2462306a36Sopenharmony_ci
2562306a36Sopenharmony_ci#include <linux/types.h>
2662306a36Sopenharmony_ci#include <linux/errno.h>
2762306a36Sopenharmony_ci#include <linux/kernel.h>
2862306a36Sopenharmony_ci#include <linux/sched.h>
2962306a36Sopenharmony_ci#include <linux/slab.h>
3062306a36Sopenharmony_ci#include <linux/poll.h>
3162306a36Sopenharmony_ci#include <linux/fcntl.h>
3262306a36Sopenharmony_ci#include <linux/freezer.h>
3362306a36Sopenharmony_ci#include <linux/skbuff.h>
3462306a36Sopenharmony_ci#include <linux/socket.h>
3562306a36Sopenharmony_ci#include <linux/ioctl.h>
3662306a36Sopenharmony_ci#include <linux/file.h>
3762306a36Sopenharmony_ci#include <linux/init.h>
3862306a36Sopenharmony_ci#include <linux/kthread.h>
3962306a36Sopenharmony_ci#include <net/sock.h>
4062306a36Sopenharmony_ci
4162306a36Sopenharmony_ci#include <linux/isdn/capilli.h>
4262306a36Sopenharmony_ci
4362306a36Sopenharmony_ci#include <net/bluetooth/bluetooth.h>
4462306a36Sopenharmony_ci#include <net/bluetooth/l2cap.h>
4562306a36Sopenharmony_ci
4662306a36Sopenharmony_ci#include "cmtp.h"
4762306a36Sopenharmony_ci
4862306a36Sopenharmony_ci#define VERSION "1.0"
4962306a36Sopenharmony_ci
5062306a36Sopenharmony_cistatic DECLARE_RWSEM(cmtp_session_sem);
5162306a36Sopenharmony_cistatic LIST_HEAD(cmtp_session_list);
5262306a36Sopenharmony_ci
5362306a36Sopenharmony_cistatic struct cmtp_session *__cmtp_get_session(bdaddr_t *bdaddr)
5462306a36Sopenharmony_ci{
5562306a36Sopenharmony_ci	struct cmtp_session *session;
5662306a36Sopenharmony_ci
5762306a36Sopenharmony_ci	BT_DBG("");
5862306a36Sopenharmony_ci
5962306a36Sopenharmony_ci	list_for_each_entry(session, &cmtp_session_list, list)
6062306a36Sopenharmony_ci		if (!bacmp(bdaddr, &session->bdaddr))
6162306a36Sopenharmony_ci			return session;
6262306a36Sopenharmony_ci
6362306a36Sopenharmony_ci	return NULL;
6462306a36Sopenharmony_ci}
6562306a36Sopenharmony_ci
6662306a36Sopenharmony_cistatic void __cmtp_link_session(struct cmtp_session *session)
6762306a36Sopenharmony_ci{
6862306a36Sopenharmony_ci	list_add(&session->list, &cmtp_session_list);
6962306a36Sopenharmony_ci}
7062306a36Sopenharmony_ci
7162306a36Sopenharmony_cistatic void __cmtp_unlink_session(struct cmtp_session *session)
7262306a36Sopenharmony_ci{
7362306a36Sopenharmony_ci	list_del(&session->list);
7462306a36Sopenharmony_ci}
7562306a36Sopenharmony_ci
7662306a36Sopenharmony_cistatic void __cmtp_copy_session(struct cmtp_session *session, struct cmtp_conninfo *ci)
7762306a36Sopenharmony_ci{
7862306a36Sopenharmony_ci	u32 valid_flags = BIT(CMTP_LOOPBACK);
7962306a36Sopenharmony_ci	memset(ci, 0, sizeof(*ci));
8062306a36Sopenharmony_ci	bacpy(&ci->bdaddr, &session->bdaddr);
8162306a36Sopenharmony_ci
8262306a36Sopenharmony_ci	ci->flags = session->flags & valid_flags;
8362306a36Sopenharmony_ci	ci->state = session->state;
8462306a36Sopenharmony_ci
8562306a36Sopenharmony_ci	ci->num = session->num;
8662306a36Sopenharmony_ci}
8762306a36Sopenharmony_ci
8862306a36Sopenharmony_ci
8962306a36Sopenharmony_cistatic inline int cmtp_alloc_block_id(struct cmtp_session *session)
9062306a36Sopenharmony_ci{
9162306a36Sopenharmony_ci	int i, id = -1;
9262306a36Sopenharmony_ci
9362306a36Sopenharmony_ci	for (i = 0; i < 16; i++)
9462306a36Sopenharmony_ci		if (!test_and_set_bit(i, &session->blockids)) {
9562306a36Sopenharmony_ci			id = i;
9662306a36Sopenharmony_ci			break;
9762306a36Sopenharmony_ci		}
9862306a36Sopenharmony_ci
9962306a36Sopenharmony_ci	return id;
10062306a36Sopenharmony_ci}
10162306a36Sopenharmony_ci
10262306a36Sopenharmony_cistatic inline void cmtp_free_block_id(struct cmtp_session *session, int id)
10362306a36Sopenharmony_ci{
10462306a36Sopenharmony_ci	clear_bit(id, &session->blockids);
10562306a36Sopenharmony_ci}
10662306a36Sopenharmony_ci
10762306a36Sopenharmony_cistatic inline void cmtp_add_msgpart(struct cmtp_session *session, int id, const unsigned char *buf, int count)
10862306a36Sopenharmony_ci{
10962306a36Sopenharmony_ci	struct sk_buff *skb = session->reassembly[id], *nskb;
11062306a36Sopenharmony_ci	int size;
11162306a36Sopenharmony_ci
11262306a36Sopenharmony_ci	BT_DBG("session %p buf %p count %d", session, buf, count);
11362306a36Sopenharmony_ci
11462306a36Sopenharmony_ci	size = (skb) ? skb->len + count : count;
11562306a36Sopenharmony_ci
11662306a36Sopenharmony_ci	nskb = alloc_skb(size, GFP_ATOMIC);
11762306a36Sopenharmony_ci	if (!nskb) {
11862306a36Sopenharmony_ci		BT_ERR("Can't allocate memory for CAPI message");
11962306a36Sopenharmony_ci		return;
12062306a36Sopenharmony_ci	}
12162306a36Sopenharmony_ci
12262306a36Sopenharmony_ci	if (skb && (skb->len > 0))
12362306a36Sopenharmony_ci		skb_copy_from_linear_data(skb, skb_put(nskb, skb->len), skb->len);
12462306a36Sopenharmony_ci
12562306a36Sopenharmony_ci	skb_put_data(nskb, buf, count);
12662306a36Sopenharmony_ci
12762306a36Sopenharmony_ci	session->reassembly[id] = nskb;
12862306a36Sopenharmony_ci
12962306a36Sopenharmony_ci	kfree_skb(skb);
13062306a36Sopenharmony_ci}
13162306a36Sopenharmony_ci
13262306a36Sopenharmony_cistatic inline int cmtp_recv_frame(struct cmtp_session *session, struct sk_buff *skb)
13362306a36Sopenharmony_ci{
13462306a36Sopenharmony_ci	__u8 hdr, hdrlen, id;
13562306a36Sopenharmony_ci	__u16 len;
13662306a36Sopenharmony_ci
13762306a36Sopenharmony_ci	BT_DBG("session %p skb %p len %d", session, skb, skb->len);
13862306a36Sopenharmony_ci
13962306a36Sopenharmony_ci	while (skb->len > 0) {
14062306a36Sopenharmony_ci		hdr = skb->data[0];
14162306a36Sopenharmony_ci
14262306a36Sopenharmony_ci		switch (hdr & 0xc0) {
14362306a36Sopenharmony_ci		case 0x40:
14462306a36Sopenharmony_ci			hdrlen = 2;
14562306a36Sopenharmony_ci			len = skb->data[1];
14662306a36Sopenharmony_ci			break;
14762306a36Sopenharmony_ci		case 0x80:
14862306a36Sopenharmony_ci			hdrlen = 3;
14962306a36Sopenharmony_ci			len = skb->data[1] | (skb->data[2] << 8);
15062306a36Sopenharmony_ci			break;
15162306a36Sopenharmony_ci		default:
15262306a36Sopenharmony_ci			hdrlen = 1;
15362306a36Sopenharmony_ci			len = 0;
15462306a36Sopenharmony_ci			break;
15562306a36Sopenharmony_ci		}
15662306a36Sopenharmony_ci
15762306a36Sopenharmony_ci		id = (hdr & 0x3c) >> 2;
15862306a36Sopenharmony_ci
15962306a36Sopenharmony_ci		BT_DBG("hdr 0x%02x hdrlen %d len %d id %d", hdr, hdrlen, len, id);
16062306a36Sopenharmony_ci
16162306a36Sopenharmony_ci		if (hdrlen + len > skb->len) {
16262306a36Sopenharmony_ci			BT_ERR("Wrong size or header information in CMTP frame");
16362306a36Sopenharmony_ci			break;
16462306a36Sopenharmony_ci		}
16562306a36Sopenharmony_ci
16662306a36Sopenharmony_ci		if (len == 0) {
16762306a36Sopenharmony_ci			skb_pull(skb, hdrlen);
16862306a36Sopenharmony_ci			continue;
16962306a36Sopenharmony_ci		}
17062306a36Sopenharmony_ci
17162306a36Sopenharmony_ci		switch (hdr & 0x03) {
17262306a36Sopenharmony_ci		case 0x00:
17362306a36Sopenharmony_ci			cmtp_add_msgpart(session, id, skb->data + hdrlen, len);
17462306a36Sopenharmony_ci			cmtp_recv_capimsg(session, session->reassembly[id]);
17562306a36Sopenharmony_ci			session->reassembly[id] = NULL;
17662306a36Sopenharmony_ci			break;
17762306a36Sopenharmony_ci		case 0x01:
17862306a36Sopenharmony_ci			cmtp_add_msgpart(session, id, skb->data + hdrlen, len);
17962306a36Sopenharmony_ci			break;
18062306a36Sopenharmony_ci		default:
18162306a36Sopenharmony_ci			kfree_skb(session->reassembly[id]);
18262306a36Sopenharmony_ci			session->reassembly[id] = NULL;
18362306a36Sopenharmony_ci			break;
18462306a36Sopenharmony_ci		}
18562306a36Sopenharmony_ci
18662306a36Sopenharmony_ci		skb_pull(skb, hdrlen + len);
18762306a36Sopenharmony_ci	}
18862306a36Sopenharmony_ci
18962306a36Sopenharmony_ci	kfree_skb(skb);
19062306a36Sopenharmony_ci	return 0;
19162306a36Sopenharmony_ci}
19262306a36Sopenharmony_ci
19362306a36Sopenharmony_cistatic int cmtp_send_frame(struct cmtp_session *session, unsigned char *data, int len)
19462306a36Sopenharmony_ci{
19562306a36Sopenharmony_ci	struct socket *sock = session->sock;
19662306a36Sopenharmony_ci	struct kvec iv = { data, len };
19762306a36Sopenharmony_ci	struct msghdr msg;
19862306a36Sopenharmony_ci
19962306a36Sopenharmony_ci	BT_DBG("session %p data %p len %d", session, data, len);
20062306a36Sopenharmony_ci
20162306a36Sopenharmony_ci	if (!len)
20262306a36Sopenharmony_ci		return 0;
20362306a36Sopenharmony_ci
20462306a36Sopenharmony_ci	memset(&msg, 0, sizeof(msg));
20562306a36Sopenharmony_ci
20662306a36Sopenharmony_ci	return kernel_sendmsg(sock, &msg, &iv, 1, len);
20762306a36Sopenharmony_ci}
20862306a36Sopenharmony_ci
20962306a36Sopenharmony_cistatic void cmtp_process_transmit(struct cmtp_session *session)
21062306a36Sopenharmony_ci{
21162306a36Sopenharmony_ci	struct sk_buff *skb, *nskb;
21262306a36Sopenharmony_ci	unsigned char *hdr;
21362306a36Sopenharmony_ci	unsigned int size, tail;
21462306a36Sopenharmony_ci
21562306a36Sopenharmony_ci	BT_DBG("session %p", session);
21662306a36Sopenharmony_ci
21762306a36Sopenharmony_ci	nskb = alloc_skb(session->mtu, GFP_ATOMIC);
21862306a36Sopenharmony_ci	if (!nskb) {
21962306a36Sopenharmony_ci		BT_ERR("Can't allocate memory for new frame");
22062306a36Sopenharmony_ci		return;
22162306a36Sopenharmony_ci	}
22262306a36Sopenharmony_ci
22362306a36Sopenharmony_ci	while ((skb = skb_dequeue(&session->transmit))) {
22462306a36Sopenharmony_ci		struct cmtp_scb *scb = (void *) skb->cb;
22562306a36Sopenharmony_ci
22662306a36Sopenharmony_ci		tail = session->mtu - nskb->len;
22762306a36Sopenharmony_ci		if (tail < 5) {
22862306a36Sopenharmony_ci			cmtp_send_frame(session, nskb->data, nskb->len);
22962306a36Sopenharmony_ci			skb_trim(nskb, 0);
23062306a36Sopenharmony_ci			tail = session->mtu;
23162306a36Sopenharmony_ci		}
23262306a36Sopenharmony_ci
23362306a36Sopenharmony_ci		size = min_t(uint, ((tail < 258) ? (tail - 2) : (tail - 3)), skb->len);
23462306a36Sopenharmony_ci
23562306a36Sopenharmony_ci		if (scb->id < 0) {
23662306a36Sopenharmony_ci			scb->id = cmtp_alloc_block_id(session);
23762306a36Sopenharmony_ci			if (scb->id < 0) {
23862306a36Sopenharmony_ci				skb_queue_head(&session->transmit, skb);
23962306a36Sopenharmony_ci				break;
24062306a36Sopenharmony_ci			}
24162306a36Sopenharmony_ci		}
24262306a36Sopenharmony_ci
24362306a36Sopenharmony_ci		if (size < 256) {
24462306a36Sopenharmony_ci			hdr = skb_put(nskb, 2);
24562306a36Sopenharmony_ci			hdr[0] = 0x40
24662306a36Sopenharmony_ci				| ((scb->id << 2) & 0x3c)
24762306a36Sopenharmony_ci				| ((skb->len == size) ? 0x00 : 0x01);
24862306a36Sopenharmony_ci			hdr[1] = size;
24962306a36Sopenharmony_ci		} else {
25062306a36Sopenharmony_ci			hdr = skb_put(nskb, 3);
25162306a36Sopenharmony_ci			hdr[0] = 0x80
25262306a36Sopenharmony_ci				| ((scb->id << 2) & 0x3c)
25362306a36Sopenharmony_ci				| ((skb->len == size) ? 0x00 : 0x01);
25462306a36Sopenharmony_ci			hdr[1] = size & 0xff;
25562306a36Sopenharmony_ci			hdr[2] = size >> 8;
25662306a36Sopenharmony_ci		}
25762306a36Sopenharmony_ci
25862306a36Sopenharmony_ci		skb_copy_from_linear_data(skb, skb_put(nskb, size), size);
25962306a36Sopenharmony_ci		skb_pull(skb, size);
26062306a36Sopenharmony_ci
26162306a36Sopenharmony_ci		if (skb->len > 0) {
26262306a36Sopenharmony_ci			skb_queue_head(&session->transmit, skb);
26362306a36Sopenharmony_ci		} else {
26462306a36Sopenharmony_ci			cmtp_free_block_id(session, scb->id);
26562306a36Sopenharmony_ci			if (scb->data) {
26662306a36Sopenharmony_ci				cmtp_send_frame(session, nskb->data, nskb->len);
26762306a36Sopenharmony_ci				skb_trim(nskb, 0);
26862306a36Sopenharmony_ci			}
26962306a36Sopenharmony_ci			kfree_skb(skb);
27062306a36Sopenharmony_ci		}
27162306a36Sopenharmony_ci	}
27262306a36Sopenharmony_ci
27362306a36Sopenharmony_ci	cmtp_send_frame(session, nskb->data, nskb->len);
27462306a36Sopenharmony_ci
27562306a36Sopenharmony_ci	kfree_skb(nskb);
27662306a36Sopenharmony_ci}
27762306a36Sopenharmony_ci
27862306a36Sopenharmony_cistatic int cmtp_session(void *arg)
27962306a36Sopenharmony_ci{
28062306a36Sopenharmony_ci	struct cmtp_session *session = arg;
28162306a36Sopenharmony_ci	struct sock *sk = session->sock->sk;
28262306a36Sopenharmony_ci	struct sk_buff *skb;
28362306a36Sopenharmony_ci	DEFINE_WAIT_FUNC(wait, woken_wake_function);
28462306a36Sopenharmony_ci
28562306a36Sopenharmony_ci	BT_DBG("session %p", session);
28662306a36Sopenharmony_ci
28762306a36Sopenharmony_ci	set_user_nice(current, -15);
28862306a36Sopenharmony_ci
28962306a36Sopenharmony_ci	add_wait_queue(sk_sleep(sk), &wait);
29062306a36Sopenharmony_ci	while (1) {
29162306a36Sopenharmony_ci		if (atomic_read(&session->terminate))
29262306a36Sopenharmony_ci			break;
29362306a36Sopenharmony_ci		if (sk->sk_state != BT_CONNECTED)
29462306a36Sopenharmony_ci			break;
29562306a36Sopenharmony_ci
29662306a36Sopenharmony_ci		while ((skb = skb_dequeue(&sk->sk_receive_queue))) {
29762306a36Sopenharmony_ci			skb_orphan(skb);
29862306a36Sopenharmony_ci			if (!skb_linearize(skb))
29962306a36Sopenharmony_ci				cmtp_recv_frame(session, skb);
30062306a36Sopenharmony_ci			else
30162306a36Sopenharmony_ci				kfree_skb(skb);
30262306a36Sopenharmony_ci		}
30362306a36Sopenharmony_ci
30462306a36Sopenharmony_ci		cmtp_process_transmit(session);
30562306a36Sopenharmony_ci
30662306a36Sopenharmony_ci		/*
30762306a36Sopenharmony_ci		 * wait_woken() performs the necessary memory barriers
30862306a36Sopenharmony_ci		 * for us; see the header comment for this primitive.
30962306a36Sopenharmony_ci		 */
31062306a36Sopenharmony_ci		wait_woken(&wait, TASK_INTERRUPTIBLE, MAX_SCHEDULE_TIMEOUT);
31162306a36Sopenharmony_ci	}
31262306a36Sopenharmony_ci	remove_wait_queue(sk_sleep(sk), &wait);
31362306a36Sopenharmony_ci
31462306a36Sopenharmony_ci	down_write(&cmtp_session_sem);
31562306a36Sopenharmony_ci
31662306a36Sopenharmony_ci	if (!(session->flags & BIT(CMTP_LOOPBACK)))
31762306a36Sopenharmony_ci		cmtp_detach_device(session);
31862306a36Sopenharmony_ci
31962306a36Sopenharmony_ci	fput(session->sock->file);
32062306a36Sopenharmony_ci
32162306a36Sopenharmony_ci	__cmtp_unlink_session(session);
32262306a36Sopenharmony_ci
32362306a36Sopenharmony_ci	up_write(&cmtp_session_sem);
32462306a36Sopenharmony_ci
32562306a36Sopenharmony_ci	kfree(session);
32662306a36Sopenharmony_ci	module_put_and_kthread_exit(0);
32762306a36Sopenharmony_ci	return 0;
32862306a36Sopenharmony_ci}
32962306a36Sopenharmony_ci
33062306a36Sopenharmony_ciint cmtp_add_connection(struct cmtp_connadd_req *req, struct socket *sock)
33162306a36Sopenharmony_ci{
33262306a36Sopenharmony_ci	u32 valid_flags = BIT(CMTP_LOOPBACK);
33362306a36Sopenharmony_ci	struct cmtp_session *session, *s;
33462306a36Sopenharmony_ci	int i, err;
33562306a36Sopenharmony_ci
33662306a36Sopenharmony_ci	BT_DBG("");
33762306a36Sopenharmony_ci
33862306a36Sopenharmony_ci	if (!l2cap_is_socket(sock))
33962306a36Sopenharmony_ci		return -EBADFD;
34062306a36Sopenharmony_ci
34162306a36Sopenharmony_ci	if (req->flags & ~valid_flags)
34262306a36Sopenharmony_ci		return -EINVAL;
34362306a36Sopenharmony_ci
34462306a36Sopenharmony_ci	session = kzalloc(sizeof(struct cmtp_session), GFP_KERNEL);
34562306a36Sopenharmony_ci	if (!session)
34662306a36Sopenharmony_ci		return -ENOMEM;
34762306a36Sopenharmony_ci
34862306a36Sopenharmony_ci	down_write(&cmtp_session_sem);
34962306a36Sopenharmony_ci
35062306a36Sopenharmony_ci	s = __cmtp_get_session(&l2cap_pi(sock->sk)->chan->dst);
35162306a36Sopenharmony_ci	if (s && s->state == BT_CONNECTED) {
35262306a36Sopenharmony_ci		err = -EEXIST;
35362306a36Sopenharmony_ci		goto failed;
35462306a36Sopenharmony_ci	}
35562306a36Sopenharmony_ci
35662306a36Sopenharmony_ci	bacpy(&session->bdaddr, &l2cap_pi(sock->sk)->chan->dst);
35762306a36Sopenharmony_ci
35862306a36Sopenharmony_ci	session->mtu = min_t(uint, l2cap_pi(sock->sk)->chan->omtu,
35962306a36Sopenharmony_ci					l2cap_pi(sock->sk)->chan->imtu);
36062306a36Sopenharmony_ci
36162306a36Sopenharmony_ci	BT_DBG("mtu %d", session->mtu);
36262306a36Sopenharmony_ci
36362306a36Sopenharmony_ci	sprintf(session->name, "%pMR", &session->bdaddr);
36462306a36Sopenharmony_ci
36562306a36Sopenharmony_ci	session->sock  = sock;
36662306a36Sopenharmony_ci	session->state = BT_CONFIG;
36762306a36Sopenharmony_ci
36862306a36Sopenharmony_ci	init_waitqueue_head(&session->wait);
36962306a36Sopenharmony_ci
37062306a36Sopenharmony_ci	session->msgnum = CMTP_INITIAL_MSGNUM;
37162306a36Sopenharmony_ci
37262306a36Sopenharmony_ci	INIT_LIST_HEAD(&session->applications);
37362306a36Sopenharmony_ci
37462306a36Sopenharmony_ci	skb_queue_head_init(&session->transmit);
37562306a36Sopenharmony_ci
37662306a36Sopenharmony_ci	for (i = 0; i < 16; i++)
37762306a36Sopenharmony_ci		session->reassembly[i] = NULL;
37862306a36Sopenharmony_ci
37962306a36Sopenharmony_ci	session->flags = req->flags;
38062306a36Sopenharmony_ci
38162306a36Sopenharmony_ci	__cmtp_link_session(session);
38262306a36Sopenharmony_ci
38362306a36Sopenharmony_ci	__module_get(THIS_MODULE);
38462306a36Sopenharmony_ci	session->task = kthread_run(cmtp_session, session, "kcmtpd_ctr_%d",
38562306a36Sopenharmony_ci								session->num);
38662306a36Sopenharmony_ci	if (IS_ERR(session->task)) {
38762306a36Sopenharmony_ci		module_put(THIS_MODULE);
38862306a36Sopenharmony_ci		err = PTR_ERR(session->task);
38962306a36Sopenharmony_ci		goto unlink;
39062306a36Sopenharmony_ci	}
39162306a36Sopenharmony_ci
39262306a36Sopenharmony_ci	if (!(session->flags & BIT(CMTP_LOOPBACK))) {
39362306a36Sopenharmony_ci		err = cmtp_attach_device(session);
39462306a36Sopenharmony_ci		if (err < 0) {
39562306a36Sopenharmony_ci			/* Caller will call fput in case of failure, and so
39662306a36Sopenharmony_ci			 * will cmtp_session kthread.
39762306a36Sopenharmony_ci			 */
39862306a36Sopenharmony_ci			get_file(session->sock->file);
39962306a36Sopenharmony_ci
40062306a36Sopenharmony_ci			atomic_inc(&session->terminate);
40162306a36Sopenharmony_ci			wake_up_interruptible(sk_sleep(session->sock->sk));
40262306a36Sopenharmony_ci			up_write(&cmtp_session_sem);
40362306a36Sopenharmony_ci			return err;
40462306a36Sopenharmony_ci		}
40562306a36Sopenharmony_ci	}
40662306a36Sopenharmony_ci
40762306a36Sopenharmony_ci	up_write(&cmtp_session_sem);
40862306a36Sopenharmony_ci	return 0;
40962306a36Sopenharmony_ci
41062306a36Sopenharmony_ciunlink:
41162306a36Sopenharmony_ci	__cmtp_unlink_session(session);
41262306a36Sopenharmony_ci
41362306a36Sopenharmony_cifailed:
41462306a36Sopenharmony_ci	up_write(&cmtp_session_sem);
41562306a36Sopenharmony_ci	kfree(session);
41662306a36Sopenharmony_ci	return err;
41762306a36Sopenharmony_ci}
41862306a36Sopenharmony_ci
41962306a36Sopenharmony_ciint cmtp_del_connection(struct cmtp_conndel_req *req)
42062306a36Sopenharmony_ci{
42162306a36Sopenharmony_ci	u32 valid_flags = 0;
42262306a36Sopenharmony_ci	struct cmtp_session *session;
42362306a36Sopenharmony_ci	int err = 0;
42462306a36Sopenharmony_ci
42562306a36Sopenharmony_ci	BT_DBG("");
42662306a36Sopenharmony_ci
42762306a36Sopenharmony_ci	if (req->flags & ~valid_flags)
42862306a36Sopenharmony_ci		return -EINVAL;
42962306a36Sopenharmony_ci
43062306a36Sopenharmony_ci	down_read(&cmtp_session_sem);
43162306a36Sopenharmony_ci
43262306a36Sopenharmony_ci	session = __cmtp_get_session(&req->bdaddr);
43362306a36Sopenharmony_ci	if (session) {
43462306a36Sopenharmony_ci		/* Flush the transmit queue */
43562306a36Sopenharmony_ci		skb_queue_purge(&session->transmit);
43662306a36Sopenharmony_ci
43762306a36Sopenharmony_ci		/* Stop session thread */
43862306a36Sopenharmony_ci		atomic_inc(&session->terminate);
43962306a36Sopenharmony_ci
44062306a36Sopenharmony_ci		/*
44162306a36Sopenharmony_ci		 * See the comment preceding the call to wait_woken()
44262306a36Sopenharmony_ci		 * in cmtp_session().
44362306a36Sopenharmony_ci		 */
44462306a36Sopenharmony_ci		wake_up_interruptible(sk_sleep(session->sock->sk));
44562306a36Sopenharmony_ci	} else
44662306a36Sopenharmony_ci		err = -ENOENT;
44762306a36Sopenharmony_ci
44862306a36Sopenharmony_ci	up_read(&cmtp_session_sem);
44962306a36Sopenharmony_ci	return err;
45062306a36Sopenharmony_ci}
45162306a36Sopenharmony_ci
45262306a36Sopenharmony_ciint cmtp_get_connlist(struct cmtp_connlist_req *req)
45362306a36Sopenharmony_ci{
45462306a36Sopenharmony_ci	struct cmtp_session *session;
45562306a36Sopenharmony_ci	int err = 0, n = 0;
45662306a36Sopenharmony_ci
45762306a36Sopenharmony_ci	BT_DBG("");
45862306a36Sopenharmony_ci
45962306a36Sopenharmony_ci	down_read(&cmtp_session_sem);
46062306a36Sopenharmony_ci
46162306a36Sopenharmony_ci	list_for_each_entry(session, &cmtp_session_list, list) {
46262306a36Sopenharmony_ci		struct cmtp_conninfo ci;
46362306a36Sopenharmony_ci
46462306a36Sopenharmony_ci		__cmtp_copy_session(session, &ci);
46562306a36Sopenharmony_ci
46662306a36Sopenharmony_ci		if (copy_to_user(req->ci, &ci, sizeof(ci))) {
46762306a36Sopenharmony_ci			err = -EFAULT;
46862306a36Sopenharmony_ci			break;
46962306a36Sopenharmony_ci		}
47062306a36Sopenharmony_ci
47162306a36Sopenharmony_ci		if (++n >= req->cnum)
47262306a36Sopenharmony_ci			break;
47362306a36Sopenharmony_ci
47462306a36Sopenharmony_ci		req->ci++;
47562306a36Sopenharmony_ci	}
47662306a36Sopenharmony_ci	req->cnum = n;
47762306a36Sopenharmony_ci
47862306a36Sopenharmony_ci	up_read(&cmtp_session_sem);
47962306a36Sopenharmony_ci	return err;
48062306a36Sopenharmony_ci}
48162306a36Sopenharmony_ci
48262306a36Sopenharmony_ciint cmtp_get_conninfo(struct cmtp_conninfo *ci)
48362306a36Sopenharmony_ci{
48462306a36Sopenharmony_ci	struct cmtp_session *session;
48562306a36Sopenharmony_ci	int err = 0;
48662306a36Sopenharmony_ci
48762306a36Sopenharmony_ci	down_read(&cmtp_session_sem);
48862306a36Sopenharmony_ci
48962306a36Sopenharmony_ci	session = __cmtp_get_session(&ci->bdaddr);
49062306a36Sopenharmony_ci	if (session)
49162306a36Sopenharmony_ci		__cmtp_copy_session(session, ci);
49262306a36Sopenharmony_ci	else
49362306a36Sopenharmony_ci		err = -ENOENT;
49462306a36Sopenharmony_ci
49562306a36Sopenharmony_ci	up_read(&cmtp_session_sem);
49662306a36Sopenharmony_ci	return err;
49762306a36Sopenharmony_ci}
49862306a36Sopenharmony_ci
49962306a36Sopenharmony_ci
50062306a36Sopenharmony_cistatic int __init cmtp_init(void)
50162306a36Sopenharmony_ci{
50262306a36Sopenharmony_ci	BT_INFO("CMTP (CAPI Emulation) ver %s", VERSION);
50362306a36Sopenharmony_ci
50462306a36Sopenharmony_ci	return cmtp_init_sockets();
50562306a36Sopenharmony_ci}
50662306a36Sopenharmony_ci
50762306a36Sopenharmony_cistatic void __exit cmtp_exit(void)
50862306a36Sopenharmony_ci{
50962306a36Sopenharmony_ci	cmtp_cleanup_sockets();
51062306a36Sopenharmony_ci}
51162306a36Sopenharmony_ci
51262306a36Sopenharmony_cimodule_init(cmtp_init);
51362306a36Sopenharmony_cimodule_exit(cmtp_exit);
51462306a36Sopenharmony_ci
51562306a36Sopenharmony_ciMODULE_AUTHOR("Marcel Holtmann <marcel@holtmann.org>");
51662306a36Sopenharmony_ciMODULE_DESCRIPTION("Bluetooth CMTP ver " VERSION);
51762306a36Sopenharmony_ciMODULE_VERSION(VERSION);
51862306a36Sopenharmony_ciMODULE_LICENSE("GPL");
51962306a36Sopenharmony_ciMODULE_ALIAS("bt-proto-5");
520