162306a36Sopenharmony_ci// SPDX-License-Identifier: GPL-2.0-or-later 262306a36Sopenharmony_ci/* 362306a36Sopenharmony_ci * Copyright (C) 2011 Intel Corporation. All rights reserved. 462306a36Sopenharmony_ci * Copyright (C) 2014 Marvell International Ltd. 562306a36Sopenharmony_ci */ 662306a36Sopenharmony_ci 762306a36Sopenharmony_ci#define pr_fmt(fmt) "llcp: %s: " fmt, __func__ 862306a36Sopenharmony_ci 962306a36Sopenharmony_ci#include <linux/init.h> 1062306a36Sopenharmony_ci#include <linux/kernel.h> 1162306a36Sopenharmony_ci#include <linux/list.h> 1262306a36Sopenharmony_ci#include <linux/nfc.h> 1362306a36Sopenharmony_ci 1462306a36Sopenharmony_ci#include "nfc.h" 1562306a36Sopenharmony_ci#include "llcp.h" 1662306a36Sopenharmony_ci 1762306a36Sopenharmony_cistatic u8 llcp_magic[3] = {0x46, 0x66, 0x6d}; 1862306a36Sopenharmony_ci 1962306a36Sopenharmony_cistatic LIST_HEAD(llcp_devices); 2062306a36Sopenharmony_ci/* Protects llcp_devices list */ 2162306a36Sopenharmony_cistatic DEFINE_SPINLOCK(llcp_devices_lock); 2262306a36Sopenharmony_ci 2362306a36Sopenharmony_cistatic void nfc_llcp_rx_skb(struct nfc_llcp_local *local, struct sk_buff *skb); 2462306a36Sopenharmony_ci 2562306a36Sopenharmony_civoid nfc_llcp_sock_link(struct llcp_sock_list *l, struct sock *sk) 2662306a36Sopenharmony_ci{ 2762306a36Sopenharmony_ci write_lock(&l->lock); 2862306a36Sopenharmony_ci sk_add_node(sk, &l->head); 2962306a36Sopenharmony_ci write_unlock(&l->lock); 3062306a36Sopenharmony_ci} 3162306a36Sopenharmony_ci 3262306a36Sopenharmony_civoid nfc_llcp_sock_unlink(struct llcp_sock_list *l, struct sock *sk) 3362306a36Sopenharmony_ci{ 3462306a36Sopenharmony_ci write_lock(&l->lock); 3562306a36Sopenharmony_ci sk_del_node_init(sk); 3662306a36Sopenharmony_ci write_unlock(&l->lock); 3762306a36Sopenharmony_ci} 3862306a36Sopenharmony_ci 3962306a36Sopenharmony_civoid nfc_llcp_socket_remote_param_init(struct nfc_llcp_sock *sock) 4062306a36Sopenharmony_ci{ 4162306a36Sopenharmony_ci sock->remote_rw = LLCP_DEFAULT_RW; 4262306a36Sopenharmony_ci sock->remote_miu = LLCP_MAX_MIU + 1; 4362306a36Sopenharmony_ci} 4462306a36Sopenharmony_ci 4562306a36Sopenharmony_cistatic void nfc_llcp_socket_purge(struct nfc_llcp_sock *sock) 4662306a36Sopenharmony_ci{ 4762306a36Sopenharmony_ci struct nfc_llcp_local *local = sock->local; 4862306a36Sopenharmony_ci struct sk_buff *s, *tmp; 4962306a36Sopenharmony_ci 5062306a36Sopenharmony_ci skb_queue_purge(&sock->tx_queue); 5162306a36Sopenharmony_ci skb_queue_purge(&sock->tx_pending_queue); 5262306a36Sopenharmony_ci 5362306a36Sopenharmony_ci if (local == NULL) 5462306a36Sopenharmony_ci return; 5562306a36Sopenharmony_ci 5662306a36Sopenharmony_ci /* Search for local pending SKBs that are related to this socket */ 5762306a36Sopenharmony_ci skb_queue_walk_safe(&local->tx_queue, s, tmp) { 5862306a36Sopenharmony_ci if (s->sk != &sock->sk) 5962306a36Sopenharmony_ci continue; 6062306a36Sopenharmony_ci 6162306a36Sopenharmony_ci skb_unlink(s, &local->tx_queue); 6262306a36Sopenharmony_ci kfree_skb(s); 6362306a36Sopenharmony_ci } 6462306a36Sopenharmony_ci} 6562306a36Sopenharmony_ci 6662306a36Sopenharmony_cistatic void nfc_llcp_socket_release(struct nfc_llcp_local *local, bool device, 6762306a36Sopenharmony_ci int err) 6862306a36Sopenharmony_ci{ 6962306a36Sopenharmony_ci struct sock *sk; 7062306a36Sopenharmony_ci struct hlist_node *tmp; 7162306a36Sopenharmony_ci struct nfc_llcp_sock *llcp_sock; 7262306a36Sopenharmony_ci 7362306a36Sopenharmony_ci skb_queue_purge(&local->tx_queue); 7462306a36Sopenharmony_ci 7562306a36Sopenharmony_ci write_lock(&local->sockets.lock); 7662306a36Sopenharmony_ci 7762306a36Sopenharmony_ci sk_for_each_safe(sk, tmp, &local->sockets.head) { 7862306a36Sopenharmony_ci llcp_sock = nfc_llcp_sock(sk); 7962306a36Sopenharmony_ci 8062306a36Sopenharmony_ci bh_lock_sock(sk); 8162306a36Sopenharmony_ci 8262306a36Sopenharmony_ci nfc_llcp_socket_purge(llcp_sock); 8362306a36Sopenharmony_ci 8462306a36Sopenharmony_ci if (sk->sk_state == LLCP_CONNECTED) 8562306a36Sopenharmony_ci nfc_put_device(llcp_sock->dev); 8662306a36Sopenharmony_ci 8762306a36Sopenharmony_ci if (sk->sk_state == LLCP_LISTEN) { 8862306a36Sopenharmony_ci struct nfc_llcp_sock *lsk, *n; 8962306a36Sopenharmony_ci struct sock *accept_sk; 9062306a36Sopenharmony_ci 9162306a36Sopenharmony_ci list_for_each_entry_safe(lsk, n, 9262306a36Sopenharmony_ci &llcp_sock->accept_queue, 9362306a36Sopenharmony_ci accept_queue) { 9462306a36Sopenharmony_ci accept_sk = &lsk->sk; 9562306a36Sopenharmony_ci bh_lock_sock(accept_sk); 9662306a36Sopenharmony_ci 9762306a36Sopenharmony_ci nfc_llcp_accept_unlink(accept_sk); 9862306a36Sopenharmony_ci 9962306a36Sopenharmony_ci if (err) 10062306a36Sopenharmony_ci accept_sk->sk_err = err; 10162306a36Sopenharmony_ci accept_sk->sk_state = LLCP_CLOSED; 10262306a36Sopenharmony_ci accept_sk->sk_state_change(sk); 10362306a36Sopenharmony_ci 10462306a36Sopenharmony_ci bh_unlock_sock(accept_sk); 10562306a36Sopenharmony_ci } 10662306a36Sopenharmony_ci } 10762306a36Sopenharmony_ci 10862306a36Sopenharmony_ci if (err) 10962306a36Sopenharmony_ci sk->sk_err = err; 11062306a36Sopenharmony_ci sk->sk_state = LLCP_CLOSED; 11162306a36Sopenharmony_ci sk->sk_state_change(sk); 11262306a36Sopenharmony_ci 11362306a36Sopenharmony_ci bh_unlock_sock(sk); 11462306a36Sopenharmony_ci 11562306a36Sopenharmony_ci sk_del_node_init(sk); 11662306a36Sopenharmony_ci } 11762306a36Sopenharmony_ci 11862306a36Sopenharmony_ci write_unlock(&local->sockets.lock); 11962306a36Sopenharmony_ci 12062306a36Sopenharmony_ci /* If we still have a device, we keep the RAW sockets alive */ 12162306a36Sopenharmony_ci if (device == true) 12262306a36Sopenharmony_ci return; 12362306a36Sopenharmony_ci 12462306a36Sopenharmony_ci write_lock(&local->raw_sockets.lock); 12562306a36Sopenharmony_ci 12662306a36Sopenharmony_ci sk_for_each_safe(sk, tmp, &local->raw_sockets.head) { 12762306a36Sopenharmony_ci llcp_sock = nfc_llcp_sock(sk); 12862306a36Sopenharmony_ci 12962306a36Sopenharmony_ci bh_lock_sock(sk); 13062306a36Sopenharmony_ci 13162306a36Sopenharmony_ci nfc_llcp_socket_purge(llcp_sock); 13262306a36Sopenharmony_ci 13362306a36Sopenharmony_ci if (err) 13462306a36Sopenharmony_ci sk->sk_err = err; 13562306a36Sopenharmony_ci sk->sk_state = LLCP_CLOSED; 13662306a36Sopenharmony_ci sk->sk_state_change(sk); 13762306a36Sopenharmony_ci 13862306a36Sopenharmony_ci bh_unlock_sock(sk); 13962306a36Sopenharmony_ci 14062306a36Sopenharmony_ci sk_del_node_init(sk); 14162306a36Sopenharmony_ci } 14262306a36Sopenharmony_ci 14362306a36Sopenharmony_ci write_unlock(&local->raw_sockets.lock); 14462306a36Sopenharmony_ci} 14562306a36Sopenharmony_ci 14662306a36Sopenharmony_cistatic struct nfc_llcp_local *nfc_llcp_local_get(struct nfc_llcp_local *local) 14762306a36Sopenharmony_ci{ 14862306a36Sopenharmony_ci /* Since using nfc_llcp_local may result in usage of nfc_dev, whenever 14962306a36Sopenharmony_ci * we hold a reference to local, we also need to hold a reference to 15062306a36Sopenharmony_ci * the device to avoid UAF. 15162306a36Sopenharmony_ci */ 15262306a36Sopenharmony_ci if (!nfc_get_device(local->dev->idx)) 15362306a36Sopenharmony_ci return NULL; 15462306a36Sopenharmony_ci 15562306a36Sopenharmony_ci kref_get(&local->ref); 15662306a36Sopenharmony_ci 15762306a36Sopenharmony_ci return local; 15862306a36Sopenharmony_ci} 15962306a36Sopenharmony_ci 16062306a36Sopenharmony_cistatic void local_cleanup(struct nfc_llcp_local *local) 16162306a36Sopenharmony_ci{ 16262306a36Sopenharmony_ci nfc_llcp_socket_release(local, false, ENXIO); 16362306a36Sopenharmony_ci del_timer_sync(&local->link_timer); 16462306a36Sopenharmony_ci skb_queue_purge(&local->tx_queue); 16562306a36Sopenharmony_ci cancel_work_sync(&local->tx_work); 16662306a36Sopenharmony_ci cancel_work_sync(&local->rx_work); 16762306a36Sopenharmony_ci cancel_work_sync(&local->timeout_work); 16862306a36Sopenharmony_ci kfree_skb(local->rx_pending); 16962306a36Sopenharmony_ci local->rx_pending = NULL; 17062306a36Sopenharmony_ci del_timer_sync(&local->sdreq_timer); 17162306a36Sopenharmony_ci cancel_work_sync(&local->sdreq_timeout_work); 17262306a36Sopenharmony_ci nfc_llcp_free_sdp_tlv_list(&local->pending_sdreqs); 17362306a36Sopenharmony_ci} 17462306a36Sopenharmony_ci 17562306a36Sopenharmony_cistatic void local_release(struct kref *ref) 17662306a36Sopenharmony_ci{ 17762306a36Sopenharmony_ci struct nfc_llcp_local *local; 17862306a36Sopenharmony_ci 17962306a36Sopenharmony_ci local = container_of(ref, struct nfc_llcp_local, ref); 18062306a36Sopenharmony_ci 18162306a36Sopenharmony_ci local_cleanup(local); 18262306a36Sopenharmony_ci kfree(local); 18362306a36Sopenharmony_ci} 18462306a36Sopenharmony_ci 18562306a36Sopenharmony_ciint nfc_llcp_local_put(struct nfc_llcp_local *local) 18662306a36Sopenharmony_ci{ 18762306a36Sopenharmony_ci struct nfc_dev *dev; 18862306a36Sopenharmony_ci int ret; 18962306a36Sopenharmony_ci 19062306a36Sopenharmony_ci if (local == NULL) 19162306a36Sopenharmony_ci return 0; 19262306a36Sopenharmony_ci 19362306a36Sopenharmony_ci dev = local->dev; 19462306a36Sopenharmony_ci 19562306a36Sopenharmony_ci ret = kref_put(&local->ref, local_release); 19662306a36Sopenharmony_ci nfc_put_device(dev); 19762306a36Sopenharmony_ci 19862306a36Sopenharmony_ci return ret; 19962306a36Sopenharmony_ci} 20062306a36Sopenharmony_ci 20162306a36Sopenharmony_cistatic struct nfc_llcp_sock *nfc_llcp_sock_get(struct nfc_llcp_local *local, 20262306a36Sopenharmony_ci u8 ssap, u8 dsap) 20362306a36Sopenharmony_ci{ 20462306a36Sopenharmony_ci struct sock *sk; 20562306a36Sopenharmony_ci struct nfc_llcp_sock *llcp_sock, *tmp_sock; 20662306a36Sopenharmony_ci 20762306a36Sopenharmony_ci pr_debug("ssap dsap %d %d\n", ssap, dsap); 20862306a36Sopenharmony_ci 20962306a36Sopenharmony_ci if (ssap == 0 && dsap == 0) 21062306a36Sopenharmony_ci return NULL; 21162306a36Sopenharmony_ci 21262306a36Sopenharmony_ci read_lock(&local->sockets.lock); 21362306a36Sopenharmony_ci 21462306a36Sopenharmony_ci llcp_sock = NULL; 21562306a36Sopenharmony_ci 21662306a36Sopenharmony_ci sk_for_each(sk, &local->sockets.head) { 21762306a36Sopenharmony_ci tmp_sock = nfc_llcp_sock(sk); 21862306a36Sopenharmony_ci 21962306a36Sopenharmony_ci if (tmp_sock->ssap == ssap && tmp_sock->dsap == dsap) { 22062306a36Sopenharmony_ci llcp_sock = tmp_sock; 22162306a36Sopenharmony_ci sock_hold(&llcp_sock->sk); 22262306a36Sopenharmony_ci break; 22362306a36Sopenharmony_ci } 22462306a36Sopenharmony_ci } 22562306a36Sopenharmony_ci 22662306a36Sopenharmony_ci read_unlock(&local->sockets.lock); 22762306a36Sopenharmony_ci 22862306a36Sopenharmony_ci return llcp_sock; 22962306a36Sopenharmony_ci} 23062306a36Sopenharmony_ci 23162306a36Sopenharmony_cistatic void nfc_llcp_sock_put(struct nfc_llcp_sock *sock) 23262306a36Sopenharmony_ci{ 23362306a36Sopenharmony_ci sock_put(&sock->sk); 23462306a36Sopenharmony_ci} 23562306a36Sopenharmony_ci 23662306a36Sopenharmony_cistatic void nfc_llcp_timeout_work(struct work_struct *work) 23762306a36Sopenharmony_ci{ 23862306a36Sopenharmony_ci struct nfc_llcp_local *local = container_of(work, struct nfc_llcp_local, 23962306a36Sopenharmony_ci timeout_work); 24062306a36Sopenharmony_ci 24162306a36Sopenharmony_ci nfc_dep_link_down(local->dev); 24262306a36Sopenharmony_ci} 24362306a36Sopenharmony_ci 24462306a36Sopenharmony_cistatic void nfc_llcp_symm_timer(struct timer_list *t) 24562306a36Sopenharmony_ci{ 24662306a36Sopenharmony_ci struct nfc_llcp_local *local = from_timer(local, t, link_timer); 24762306a36Sopenharmony_ci 24862306a36Sopenharmony_ci pr_err("SYMM timeout\n"); 24962306a36Sopenharmony_ci 25062306a36Sopenharmony_ci schedule_work(&local->timeout_work); 25162306a36Sopenharmony_ci} 25262306a36Sopenharmony_ci 25362306a36Sopenharmony_cistatic void nfc_llcp_sdreq_timeout_work(struct work_struct *work) 25462306a36Sopenharmony_ci{ 25562306a36Sopenharmony_ci unsigned long time; 25662306a36Sopenharmony_ci HLIST_HEAD(nl_sdres_list); 25762306a36Sopenharmony_ci struct hlist_node *n; 25862306a36Sopenharmony_ci struct nfc_llcp_sdp_tlv *sdp; 25962306a36Sopenharmony_ci struct nfc_llcp_local *local = container_of(work, struct nfc_llcp_local, 26062306a36Sopenharmony_ci sdreq_timeout_work); 26162306a36Sopenharmony_ci 26262306a36Sopenharmony_ci mutex_lock(&local->sdreq_lock); 26362306a36Sopenharmony_ci 26462306a36Sopenharmony_ci time = jiffies - msecs_to_jiffies(3 * local->remote_lto); 26562306a36Sopenharmony_ci 26662306a36Sopenharmony_ci hlist_for_each_entry_safe(sdp, n, &local->pending_sdreqs, node) { 26762306a36Sopenharmony_ci if (time_after(sdp->time, time)) 26862306a36Sopenharmony_ci continue; 26962306a36Sopenharmony_ci 27062306a36Sopenharmony_ci sdp->sap = LLCP_SDP_UNBOUND; 27162306a36Sopenharmony_ci 27262306a36Sopenharmony_ci hlist_del(&sdp->node); 27362306a36Sopenharmony_ci 27462306a36Sopenharmony_ci hlist_add_head(&sdp->node, &nl_sdres_list); 27562306a36Sopenharmony_ci } 27662306a36Sopenharmony_ci 27762306a36Sopenharmony_ci if (!hlist_empty(&local->pending_sdreqs)) 27862306a36Sopenharmony_ci mod_timer(&local->sdreq_timer, 27962306a36Sopenharmony_ci jiffies + msecs_to_jiffies(3 * local->remote_lto)); 28062306a36Sopenharmony_ci 28162306a36Sopenharmony_ci mutex_unlock(&local->sdreq_lock); 28262306a36Sopenharmony_ci 28362306a36Sopenharmony_ci if (!hlist_empty(&nl_sdres_list)) 28462306a36Sopenharmony_ci nfc_genl_llc_send_sdres(local->dev, &nl_sdres_list); 28562306a36Sopenharmony_ci} 28662306a36Sopenharmony_ci 28762306a36Sopenharmony_cistatic void nfc_llcp_sdreq_timer(struct timer_list *t) 28862306a36Sopenharmony_ci{ 28962306a36Sopenharmony_ci struct nfc_llcp_local *local = from_timer(local, t, sdreq_timer); 29062306a36Sopenharmony_ci 29162306a36Sopenharmony_ci schedule_work(&local->sdreq_timeout_work); 29262306a36Sopenharmony_ci} 29362306a36Sopenharmony_ci 29462306a36Sopenharmony_cistruct nfc_llcp_local *nfc_llcp_find_local(struct nfc_dev *dev) 29562306a36Sopenharmony_ci{ 29662306a36Sopenharmony_ci struct nfc_llcp_local *local; 29762306a36Sopenharmony_ci struct nfc_llcp_local *res = NULL; 29862306a36Sopenharmony_ci 29962306a36Sopenharmony_ci spin_lock(&llcp_devices_lock); 30062306a36Sopenharmony_ci list_for_each_entry(local, &llcp_devices, list) 30162306a36Sopenharmony_ci if (local->dev == dev) { 30262306a36Sopenharmony_ci res = nfc_llcp_local_get(local); 30362306a36Sopenharmony_ci break; 30462306a36Sopenharmony_ci } 30562306a36Sopenharmony_ci spin_unlock(&llcp_devices_lock); 30662306a36Sopenharmony_ci 30762306a36Sopenharmony_ci return res; 30862306a36Sopenharmony_ci} 30962306a36Sopenharmony_ci 31062306a36Sopenharmony_cistatic struct nfc_llcp_local *nfc_llcp_remove_local(struct nfc_dev *dev) 31162306a36Sopenharmony_ci{ 31262306a36Sopenharmony_ci struct nfc_llcp_local *local, *tmp; 31362306a36Sopenharmony_ci 31462306a36Sopenharmony_ci spin_lock(&llcp_devices_lock); 31562306a36Sopenharmony_ci list_for_each_entry_safe(local, tmp, &llcp_devices, list) 31662306a36Sopenharmony_ci if (local->dev == dev) { 31762306a36Sopenharmony_ci list_del(&local->list); 31862306a36Sopenharmony_ci spin_unlock(&llcp_devices_lock); 31962306a36Sopenharmony_ci return local; 32062306a36Sopenharmony_ci } 32162306a36Sopenharmony_ci spin_unlock(&llcp_devices_lock); 32262306a36Sopenharmony_ci 32362306a36Sopenharmony_ci pr_warn("Shutting down device not found\n"); 32462306a36Sopenharmony_ci 32562306a36Sopenharmony_ci return NULL; 32662306a36Sopenharmony_ci} 32762306a36Sopenharmony_ci 32862306a36Sopenharmony_cistatic char *wks[] = { 32962306a36Sopenharmony_ci NULL, 33062306a36Sopenharmony_ci NULL, /* SDP */ 33162306a36Sopenharmony_ci "urn:nfc:sn:ip", 33262306a36Sopenharmony_ci "urn:nfc:sn:obex", 33362306a36Sopenharmony_ci "urn:nfc:sn:snep", 33462306a36Sopenharmony_ci}; 33562306a36Sopenharmony_ci 33662306a36Sopenharmony_cistatic int nfc_llcp_wks_sap(const char *service_name, size_t service_name_len) 33762306a36Sopenharmony_ci{ 33862306a36Sopenharmony_ci int sap, num_wks; 33962306a36Sopenharmony_ci 34062306a36Sopenharmony_ci pr_debug("%s\n", service_name); 34162306a36Sopenharmony_ci 34262306a36Sopenharmony_ci if (service_name == NULL) 34362306a36Sopenharmony_ci return -EINVAL; 34462306a36Sopenharmony_ci 34562306a36Sopenharmony_ci num_wks = ARRAY_SIZE(wks); 34662306a36Sopenharmony_ci 34762306a36Sopenharmony_ci for (sap = 0; sap < num_wks; sap++) { 34862306a36Sopenharmony_ci if (wks[sap] == NULL) 34962306a36Sopenharmony_ci continue; 35062306a36Sopenharmony_ci 35162306a36Sopenharmony_ci if (strncmp(wks[sap], service_name, service_name_len) == 0) 35262306a36Sopenharmony_ci return sap; 35362306a36Sopenharmony_ci } 35462306a36Sopenharmony_ci 35562306a36Sopenharmony_ci return -EINVAL; 35662306a36Sopenharmony_ci} 35762306a36Sopenharmony_ci 35862306a36Sopenharmony_cistatic 35962306a36Sopenharmony_cistruct nfc_llcp_sock *nfc_llcp_sock_from_sn(struct nfc_llcp_local *local, 36062306a36Sopenharmony_ci const u8 *sn, size_t sn_len, 36162306a36Sopenharmony_ci bool needref) 36262306a36Sopenharmony_ci{ 36362306a36Sopenharmony_ci struct sock *sk; 36462306a36Sopenharmony_ci struct nfc_llcp_sock *llcp_sock, *tmp_sock; 36562306a36Sopenharmony_ci 36662306a36Sopenharmony_ci pr_debug("sn %zd %p\n", sn_len, sn); 36762306a36Sopenharmony_ci 36862306a36Sopenharmony_ci if (sn == NULL || sn_len == 0) 36962306a36Sopenharmony_ci return NULL; 37062306a36Sopenharmony_ci 37162306a36Sopenharmony_ci read_lock(&local->sockets.lock); 37262306a36Sopenharmony_ci 37362306a36Sopenharmony_ci llcp_sock = NULL; 37462306a36Sopenharmony_ci 37562306a36Sopenharmony_ci sk_for_each(sk, &local->sockets.head) { 37662306a36Sopenharmony_ci tmp_sock = nfc_llcp_sock(sk); 37762306a36Sopenharmony_ci 37862306a36Sopenharmony_ci pr_debug("llcp sock %p\n", tmp_sock); 37962306a36Sopenharmony_ci 38062306a36Sopenharmony_ci if (tmp_sock->sk.sk_type == SOCK_STREAM && 38162306a36Sopenharmony_ci tmp_sock->sk.sk_state != LLCP_LISTEN) 38262306a36Sopenharmony_ci continue; 38362306a36Sopenharmony_ci 38462306a36Sopenharmony_ci if (tmp_sock->sk.sk_type == SOCK_DGRAM && 38562306a36Sopenharmony_ci tmp_sock->sk.sk_state != LLCP_BOUND) 38662306a36Sopenharmony_ci continue; 38762306a36Sopenharmony_ci 38862306a36Sopenharmony_ci if (tmp_sock->service_name == NULL || 38962306a36Sopenharmony_ci tmp_sock->service_name_len == 0) 39062306a36Sopenharmony_ci continue; 39162306a36Sopenharmony_ci 39262306a36Sopenharmony_ci if (tmp_sock->service_name_len != sn_len) 39362306a36Sopenharmony_ci continue; 39462306a36Sopenharmony_ci 39562306a36Sopenharmony_ci if (memcmp(sn, tmp_sock->service_name, sn_len) == 0) { 39662306a36Sopenharmony_ci llcp_sock = tmp_sock; 39762306a36Sopenharmony_ci if (needref) 39862306a36Sopenharmony_ci sock_hold(&llcp_sock->sk); 39962306a36Sopenharmony_ci break; 40062306a36Sopenharmony_ci } 40162306a36Sopenharmony_ci } 40262306a36Sopenharmony_ci 40362306a36Sopenharmony_ci read_unlock(&local->sockets.lock); 40462306a36Sopenharmony_ci 40562306a36Sopenharmony_ci pr_debug("Found llcp sock %p\n", llcp_sock); 40662306a36Sopenharmony_ci 40762306a36Sopenharmony_ci return llcp_sock; 40862306a36Sopenharmony_ci} 40962306a36Sopenharmony_ci 41062306a36Sopenharmony_ciu8 nfc_llcp_get_sdp_ssap(struct nfc_llcp_local *local, 41162306a36Sopenharmony_ci struct nfc_llcp_sock *sock) 41262306a36Sopenharmony_ci{ 41362306a36Sopenharmony_ci mutex_lock(&local->sdp_lock); 41462306a36Sopenharmony_ci 41562306a36Sopenharmony_ci if (sock->service_name != NULL && sock->service_name_len > 0) { 41662306a36Sopenharmony_ci int ssap = nfc_llcp_wks_sap(sock->service_name, 41762306a36Sopenharmony_ci sock->service_name_len); 41862306a36Sopenharmony_ci 41962306a36Sopenharmony_ci if (ssap > 0) { 42062306a36Sopenharmony_ci pr_debug("WKS %d\n", ssap); 42162306a36Sopenharmony_ci 42262306a36Sopenharmony_ci /* This is a WKS, let's check if it's free */ 42362306a36Sopenharmony_ci if (test_bit(ssap, &local->local_wks)) { 42462306a36Sopenharmony_ci mutex_unlock(&local->sdp_lock); 42562306a36Sopenharmony_ci 42662306a36Sopenharmony_ci return LLCP_SAP_MAX; 42762306a36Sopenharmony_ci } 42862306a36Sopenharmony_ci 42962306a36Sopenharmony_ci set_bit(ssap, &local->local_wks); 43062306a36Sopenharmony_ci mutex_unlock(&local->sdp_lock); 43162306a36Sopenharmony_ci 43262306a36Sopenharmony_ci return ssap; 43362306a36Sopenharmony_ci } 43462306a36Sopenharmony_ci 43562306a36Sopenharmony_ci /* 43662306a36Sopenharmony_ci * Check if there already is a non WKS socket bound 43762306a36Sopenharmony_ci * to this service name. 43862306a36Sopenharmony_ci */ 43962306a36Sopenharmony_ci if (nfc_llcp_sock_from_sn(local, sock->service_name, 44062306a36Sopenharmony_ci sock->service_name_len, 44162306a36Sopenharmony_ci false) != NULL) { 44262306a36Sopenharmony_ci mutex_unlock(&local->sdp_lock); 44362306a36Sopenharmony_ci 44462306a36Sopenharmony_ci return LLCP_SAP_MAX; 44562306a36Sopenharmony_ci } 44662306a36Sopenharmony_ci 44762306a36Sopenharmony_ci mutex_unlock(&local->sdp_lock); 44862306a36Sopenharmony_ci 44962306a36Sopenharmony_ci return LLCP_SDP_UNBOUND; 45062306a36Sopenharmony_ci 45162306a36Sopenharmony_ci } else if (sock->ssap != 0 && sock->ssap < LLCP_WKS_NUM_SAP) { 45262306a36Sopenharmony_ci if (!test_bit(sock->ssap, &local->local_wks)) { 45362306a36Sopenharmony_ci set_bit(sock->ssap, &local->local_wks); 45462306a36Sopenharmony_ci mutex_unlock(&local->sdp_lock); 45562306a36Sopenharmony_ci 45662306a36Sopenharmony_ci return sock->ssap; 45762306a36Sopenharmony_ci } 45862306a36Sopenharmony_ci } 45962306a36Sopenharmony_ci 46062306a36Sopenharmony_ci mutex_unlock(&local->sdp_lock); 46162306a36Sopenharmony_ci 46262306a36Sopenharmony_ci return LLCP_SAP_MAX; 46362306a36Sopenharmony_ci} 46462306a36Sopenharmony_ci 46562306a36Sopenharmony_ciu8 nfc_llcp_get_local_ssap(struct nfc_llcp_local *local) 46662306a36Sopenharmony_ci{ 46762306a36Sopenharmony_ci u8 local_ssap; 46862306a36Sopenharmony_ci 46962306a36Sopenharmony_ci mutex_lock(&local->sdp_lock); 47062306a36Sopenharmony_ci 47162306a36Sopenharmony_ci local_ssap = find_first_zero_bit(&local->local_sap, LLCP_LOCAL_NUM_SAP); 47262306a36Sopenharmony_ci if (local_ssap == LLCP_LOCAL_NUM_SAP) { 47362306a36Sopenharmony_ci mutex_unlock(&local->sdp_lock); 47462306a36Sopenharmony_ci return LLCP_SAP_MAX; 47562306a36Sopenharmony_ci } 47662306a36Sopenharmony_ci 47762306a36Sopenharmony_ci set_bit(local_ssap, &local->local_sap); 47862306a36Sopenharmony_ci 47962306a36Sopenharmony_ci mutex_unlock(&local->sdp_lock); 48062306a36Sopenharmony_ci 48162306a36Sopenharmony_ci return local_ssap + LLCP_LOCAL_SAP_OFFSET; 48262306a36Sopenharmony_ci} 48362306a36Sopenharmony_ci 48462306a36Sopenharmony_civoid nfc_llcp_put_ssap(struct nfc_llcp_local *local, u8 ssap) 48562306a36Sopenharmony_ci{ 48662306a36Sopenharmony_ci u8 local_ssap; 48762306a36Sopenharmony_ci unsigned long *sdp; 48862306a36Sopenharmony_ci 48962306a36Sopenharmony_ci if (ssap < LLCP_WKS_NUM_SAP) { 49062306a36Sopenharmony_ci local_ssap = ssap; 49162306a36Sopenharmony_ci sdp = &local->local_wks; 49262306a36Sopenharmony_ci } else if (ssap < LLCP_LOCAL_NUM_SAP) { 49362306a36Sopenharmony_ci atomic_t *client_cnt; 49462306a36Sopenharmony_ci 49562306a36Sopenharmony_ci local_ssap = ssap - LLCP_WKS_NUM_SAP; 49662306a36Sopenharmony_ci sdp = &local->local_sdp; 49762306a36Sopenharmony_ci client_cnt = &local->local_sdp_cnt[local_ssap]; 49862306a36Sopenharmony_ci 49962306a36Sopenharmony_ci pr_debug("%d clients\n", atomic_read(client_cnt)); 50062306a36Sopenharmony_ci 50162306a36Sopenharmony_ci mutex_lock(&local->sdp_lock); 50262306a36Sopenharmony_ci 50362306a36Sopenharmony_ci if (atomic_dec_and_test(client_cnt)) { 50462306a36Sopenharmony_ci struct nfc_llcp_sock *l_sock; 50562306a36Sopenharmony_ci 50662306a36Sopenharmony_ci pr_debug("No more clients for SAP %d\n", ssap); 50762306a36Sopenharmony_ci 50862306a36Sopenharmony_ci clear_bit(local_ssap, sdp); 50962306a36Sopenharmony_ci 51062306a36Sopenharmony_ci /* Find the listening sock and set it back to UNBOUND */ 51162306a36Sopenharmony_ci l_sock = nfc_llcp_sock_get(local, ssap, LLCP_SAP_SDP); 51262306a36Sopenharmony_ci if (l_sock) { 51362306a36Sopenharmony_ci l_sock->ssap = LLCP_SDP_UNBOUND; 51462306a36Sopenharmony_ci nfc_llcp_sock_put(l_sock); 51562306a36Sopenharmony_ci } 51662306a36Sopenharmony_ci } 51762306a36Sopenharmony_ci 51862306a36Sopenharmony_ci mutex_unlock(&local->sdp_lock); 51962306a36Sopenharmony_ci 52062306a36Sopenharmony_ci return; 52162306a36Sopenharmony_ci } else if (ssap < LLCP_MAX_SAP) { 52262306a36Sopenharmony_ci local_ssap = ssap - LLCP_LOCAL_NUM_SAP; 52362306a36Sopenharmony_ci sdp = &local->local_sap; 52462306a36Sopenharmony_ci } else { 52562306a36Sopenharmony_ci return; 52662306a36Sopenharmony_ci } 52762306a36Sopenharmony_ci 52862306a36Sopenharmony_ci mutex_lock(&local->sdp_lock); 52962306a36Sopenharmony_ci 53062306a36Sopenharmony_ci clear_bit(local_ssap, sdp); 53162306a36Sopenharmony_ci 53262306a36Sopenharmony_ci mutex_unlock(&local->sdp_lock); 53362306a36Sopenharmony_ci} 53462306a36Sopenharmony_ci 53562306a36Sopenharmony_cistatic u8 nfc_llcp_reserve_sdp_ssap(struct nfc_llcp_local *local) 53662306a36Sopenharmony_ci{ 53762306a36Sopenharmony_ci u8 ssap; 53862306a36Sopenharmony_ci 53962306a36Sopenharmony_ci mutex_lock(&local->sdp_lock); 54062306a36Sopenharmony_ci 54162306a36Sopenharmony_ci ssap = find_first_zero_bit(&local->local_sdp, LLCP_SDP_NUM_SAP); 54262306a36Sopenharmony_ci if (ssap == LLCP_SDP_NUM_SAP) { 54362306a36Sopenharmony_ci mutex_unlock(&local->sdp_lock); 54462306a36Sopenharmony_ci 54562306a36Sopenharmony_ci return LLCP_SAP_MAX; 54662306a36Sopenharmony_ci } 54762306a36Sopenharmony_ci 54862306a36Sopenharmony_ci pr_debug("SDP ssap %d\n", LLCP_WKS_NUM_SAP + ssap); 54962306a36Sopenharmony_ci 55062306a36Sopenharmony_ci set_bit(ssap, &local->local_sdp); 55162306a36Sopenharmony_ci 55262306a36Sopenharmony_ci mutex_unlock(&local->sdp_lock); 55362306a36Sopenharmony_ci 55462306a36Sopenharmony_ci return LLCP_WKS_NUM_SAP + ssap; 55562306a36Sopenharmony_ci} 55662306a36Sopenharmony_ci 55762306a36Sopenharmony_cistatic int nfc_llcp_build_gb(struct nfc_llcp_local *local) 55862306a36Sopenharmony_ci{ 55962306a36Sopenharmony_ci u8 *gb_cur, version, version_length; 56062306a36Sopenharmony_ci u8 lto_length, wks_length, miux_length; 56162306a36Sopenharmony_ci const u8 *version_tlv = NULL, *lto_tlv = NULL, 56262306a36Sopenharmony_ci *wks_tlv = NULL, *miux_tlv = NULL; 56362306a36Sopenharmony_ci __be16 wks = cpu_to_be16(local->local_wks); 56462306a36Sopenharmony_ci u8 gb_len = 0; 56562306a36Sopenharmony_ci int ret = 0; 56662306a36Sopenharmony_ci 56762306a36Sopenharmony_ci version = LLCP_VERSION_11; 56862306a36Sopenharmony_ci version_tlv = nfc_llcp_build_tlv(LLCP_TLV_VERSION, &version, 56962306a36Sopenharmony_ci 1, &version_length); 57062306a36Sopenharmony_ci if (!version_tlv) { 57162306a36Sopenharmony_ci ret = -ENOMEM; 57262306a36Sopenharmony_ci goto out; 57362306a36Sopenharmony_ci } 57462306a36Sopenharmony_ci gb_len += version_length; 57562306a36Sopenharmony_ci 57662306a36Sopenharmony_ci lto_tlv = nfc_llcp_build_tlv(LLCP_TLV_LTO, &local->lto, 1, <o_length); 57762306a36Sopenharmony_ci if (!lto_tlv) { 57862306a36Sopenharmony_ci ret = -ENOMEM; 57962306a36Sopenharmony_ci goto out; 58062306a36Sopenharmony_ci } 58162306a36Sopenharmony_ci gb_len += lto_length; 58262306a36Sopenharmony_ci 58362306a36Sopenharmony_ci pr_debug("Local wks 0x%lx\n", local->local_wks); 58462306a36Sopenharmony_ci wks_tlv = nfc_llcp_build_tlv(LLCP_TLV_WKS, (u8 *)&wks, 2, &wks_length); 58562306a36Sopenharmony_ci if (!wks_tlv) { 58662306a36Sopenharmony_ci ret = -ENOMEM; 58762306a36Sopenharmony_ci goto out; 58862306a36Sopenharmony_ci } 58962306a36Sopenharmony_ci gb_len += wks_length; 59062306a36Sopenharmony_ci 59162306a36Sopenharmony_ci miux_tlv = nfc_llcp_build_tlv(LLCP_TLV_MIUX, (u8 *)&local->miux, 0, 59262306a36Sopenharmony_ci &miux_length); 59362306a36Sopenharmony_ci if (!miux_tlv) { 59462306a36Sopenharmony_ci ret = -ENOMEM; 59562306a36Sopenharmony_ci goto out; 59662306a36Sopenharmony_ci } 59762306a36Sopenharmony_ci gb_len += miux_length; 59862306a36Sopenharmony_ci 59962306a36Sopenharmony_ci gb_len += ARRAY_SIZE(llcp_magic); 60062306a36Sopenharmony_ci 60162306a36Sopenharmony_ci if (gb_len > NFC_MAX_GT_LEN) { 60262306a36Sopenharmony_ci ret = -EINVAL; 60362306a36Sopenharmony_ci goto out; 60462306a36Sopenharmony_ci } 60562306a36Sopenharmony_ci 60662306a36Sopenharmony_ci gb_cur = local->gb; 60762306a36Sopenharmony_ci 60862306a36Sopenharmony_ci memcpy(gb_cur, llcp_magic, ARRAY_SIZE(llcp_magic)); 60962306a36Sopenharmony_ci gb_cur += ARRAY_SIZE(llcp_magic); 61062306a36Sopenharmony_ci 61162306a36Sopenharmony_ci memcpy(gb_cur, version_tlv, version_length); 61262306a36Sopenharmony_ci gb_cur += version_length; 61362306a36Sopenharmony_ci 61462306a36Sopenharmony_ci memcpy(gb_cur, lto_tlv, lto_length); 61562306a36Sopenharmony_ci gb_cur += lto_length; 61662306a36Sopenharmony_ci 61762306a36Sopenharmony_ci memcpy(gb_cur, wks_tlv, wks_length); 61862306a36Sopenharmony_ci gb_cur += wks_length; 61962306a36Sopenharmony_ci 62062306a36Sopenharmony_ci memcpy(gb_cur, miux_tlv, miux_length); 62162306a36Sopenharmony_ci gb_cur += miux_length; 62262306a36Sopenharmony_ci 62362306a36Sopenharmony_ci local->gb_len = gb_len; 62462306a36Sopenharmony_ci 62562306a36Sopenharmony_ciout: 62662306a36Sopenharmony_ci kfree(version_tlv); 62762306a36Sopenharmony_ci kfree(lto_tlv); 62862306a36Sopenharmony_ci kfree(wks_tlv); 62962306a36Sopenharmony_ci kfree(miux_tlv); 63062306a36Sopenharmony_ci 63162306a36Sopenharmony_ci return ret; 63262306a36Sopenharmony_ci} 63362306a36Sopenharmony_ci 63462306a36Sopenharmony_ciu8 *nfc_llcp_general_bytes(struct nfc_dev *dev, size_t *general_bytes_len) 63562306a36Sopenharmony_ci{ 63662306a36Sopenharmony_ci struct nfc_llcp_local *local; 63762306a36Sopenharmony_ci 63862306a36Sopenharmony_ci local = nfc_llcp_find_local(dev); 63962306a36Sopenharmony_ci if (local == NULL) { 64062306a36Sopenharmony_ci *general_bytes_len = 0; 64162306a36Sopenharmony_ci return NULL; 64262306a36Sopenharmony_ci } 64362306a36Sopenharmony_ci 64462306a36Sopenharmony_ci nfc_llcp_build_gb(local); 64562306a36Sopenharmony_ci 64662306a36Sopenharmony_ci *general_bytes_len = local->gb_len; 64762306a36Sopenharmony_ci 64862306a36Sopenharmony_ci nfc_llcp_local_put(local); 64962306a36Sopenharmony_ci 65062306a36Sopenharmony_ci return local->gb; 65162306a36Sopenharmony_ci} 65262306a36Sopenharmony_ci 65362306a36Sopenharmony_ciint nfc_llcp_set_remote_gb(struct nfc_dev *dev, const u8 *gb, u8 gb_len) 65462306a36Sopenharmony_ci{ 65562306a36Sopenharmony_ci struct nfc_llcp_local *local; 65662306a36Sopenharmony_ci int err; 65762306a36Sopenharmony_ci 65862306a36Sopenharmony_ci if (gb_len < 3 || gb_len > NFC_MAX_GT_LEN) 65962306a36Sopenharmony_ci return -EINVAL; 66062306a36Sopenharmony_ci 66162306a36Sopenharmony_ci local = nfc_llcp_find_local(dev); 66262306a36Sopenharmony_ci if (local == NULL) { 66362306a36Sopenharmony_ci pr_err("No LLCP device\n"); 66462306a36Sopenharmony_ci return -ENODEV; 66562306a36Sopenharmony_ci } 66662306a36Sopenharmony_ci 66762306a36Sopenharmony_ci memset(local->remote_gb, 0, NFC_MAX_GT_LEN); 66862306a36Sopenharmony_ci memcpy(local->remote_gb, gb, gb_len); 66962306a36Sopenharmony_ci local->remote_gb_len = gb_len; 67062306a36Sopenharmony_ci 67162306a36Sopenharmony_ci if (memcmp(local->remote_gb, llcp_magic, 3)) { 67262306a36Sopenharmony_ci pr_err("MAC does not support LLCP\n"); 67362306a36Sopenharmony_ci err = -EINVAL; 67462306a36Sopenharmony_ci goto out; 67562306a36Sopenharmony_ci } 67662306a36Sopenharmony_ci 67762306a36Sopenharmony_ci err = nfc_llcp_parse_gb_tlv(local, 67862306a36Sopenharmony_ci &local->remote_gb[3], 67962306a36Sopenharmony_ci local->remote_gb_len - 3); 68062306a36Sopenharmony_ciout: 68162306a36Sopenharmony_ci nfc_llcp_local_put(local); 68262306a36Sopenharmony_ci return err; 68362306a36Sopenharmony_ci} 68462306a36Sopenharmony_ci 68562306a36Sopenharmony_cistatic u8 nfc_llcp_dsap(const struct sk_buff *pdu) 68662306a36Sopenharmony_ci{ 68762306a36Sopenharmony_ci return (pdu->data[0] & 0xfc) >> 2; 68862306a36Sopenharmony_ci} 68962306a36Sopenharmony_ci 69062306a36Sopenharmony_cistatic u8 nfc_llcp_ptype(const struct sk_buff *pdu) 69162306a36Sopenharmony_ci{ 69262306a36Sopenharmony_ci return ((pdu->data[0] & 0x03) << 2) | ((pdu->data[1] & 0xc0) >> 6); 69362306a36Sopenharmony_ci} 69462306a36Sopenharmony_ci 69562306a36Sopenharmony_cistatic u8 nfc_llcp_ssap(const struct sk_buff *pdu) 69662306a36Sopenharmony_ci{ 69762306a36Sopenharmony_ci return pdu->data[1] & 0x3f; 69862306a36Sopenharmony_ci} 69962306a36Sopenharmony_ci 70062306a36Sopenharmony_cistatic u8 nfc_llcp_ns(const struct sk_buff *pdu) 70162306a36Sopenharmony_ci{ 70262306a36Sopenharmony_ci return pdu->data[2] >> 4; 70362306a36Sopenharmony_ci} 70462306a36Sopenharmony_ci 70562306a36Sopenharmony_cistatic u8 nfc_llcp_nr(const struct sk_buff *pdu) 70662306a36Sopenharmony_ci{ 70762306a36Sopenharmony_ci return pdu->data[2] & 0xf; 70862306a36Sopenharmony_ci} 70962306a36Sopenharmony_ci 71062306a36Sopenharmony_cistatic void nfc_llcp_set_nrns(struct nfc_llcp_sock *sock, struct sk_buff *pdu) 71162306a36Sopenharmony_ci{ 71262306a36Sopenharmony_ci pdu->data[2] = (sock->send_n << 4) | (sock->recv_n); 71362306a36Sopenharmony_ci sock->send_n = (sock->send_n + 1) % 16; 71462306a36Sopenharmony_ci sock->recv_ack_n = (sock->recv_n - 1) % 16; 71562306a36Sopenharmony_ci} 71662306a36Sopenharmony_ci 71762306a36Sopenharmony_civoid nfc_llcp_send_to_raw_sock(struct nfc_llcp_local *local, 71862306a36Sopenharmony_ci struct sk_buff *skb, u8 direction) 71962306a36Sopenharmony_ci{ 72062306a36Sopenharmony_ci struct sk_buff *skb_copy = NULL, *nskb; 72162306a36Sopenharmony_ci struct sock *sk; 72262306a36Sopenharmony_ci u8 *data; 72362306a36Sopenharmony_ci 72462306a36Sopenharmony_ci read_lock(&local->raw_sockets.lock); 72562306a36Sopenharmony_ci 72662306a36Sopenharmony_ci sk_for_each(sk, &local->raw_sockets.head) { 72762306a36Sopenharmony_ci if (sk->sk_state != LLCP_BOUND) 72862306a36Sopenharmony_ci continue; 72962306a36Sopenharmony_ci 73062306a36Sopenharmony_ci if (skb_copy == NULL) { 73162306a36Sopenharmony_ci skb_copy = __pskb_copy_fclone(skb, NFC_RAW_HEADER_SIZE, 73262306a36Sopenharmony_ci GFP_ATOMIC, true); 73362306a36Sopenharmony_ci 73462306a36Sopenharmony_ci if (skb_copy == NULL) 73562306a36Sopenharmony_ci continue; 73662306a36Sopenharmony_ci 73762306a36Sopenharmony_ci data = skb_push(skb_copy, NFC_RAW_HEADER_SIZE); 73862306a36Sopenharmony_ci 73962306a36Sopenharmony_ci data[0] = local->dev ? local->dev->idx : 0xFF; 74062306a36Sopenharmony_ci data[1] = direction & 0x01; 74162306a36Sopenharmony_ci data[1] |= (RAW_PAYLOAD_LLCP << 1); 74262306a36Sopenharmony_ci } 74362306a36Sopenharmony_ci 74462306a36Sopenharmony_ci nskb = skb_clone(skb_copy, GFP_ATOMIC); 74562306a36Sopenharmony_ci if (!nskb) 74662306a36Sopenharmony_ci continue; 74762306a36Sopenharmony_ci 74862306a36Sopenharmony_ci if (sock_queue_rcv_skb(sk, nskb)) 74962306a36Sopenharmony_ci kfree_skb(nskb); 75062306a36Sopenharmony_ci } 75162306a36Sopenharmony_ci 75262306a36Sopenharmony_ci read_unlock(&local->raw_sockets.lock); 75362306a36Sopenharmony_ci 75462306a36Sopenharmony_ci kfree_skb(skb_copy); 75562306a36Sopenharmony_ci} 75662306a36Sopenharmony_ci 75762306a36Sopenharmony_cistatic void nfc_llcp_tx_work(struct work_struct *work) 75862306a36Sopenharmony_ci{ 75962306a36Sopenharmony_ci struct nfc_llcp_local *local = container_of(work, struct nfc_llcp_local, 76062306a36Sopenharmony_ci tx_work); 76162306a36Sopenharmony_ci struct sk_buff *skb; 76262306a36Sopenharmony_ci struct sock *sk; 76362306a36Sopenharmony_ci struct nfc_llcp_sock *llcp_sock; 76462306a36Sopenharmony_ci 76562306a36Sopenharmony_ci skb = skb_dequeue(&local->tx_queue); 76662306a36Sopenharmony_ci if (skb != NULL) { 76762306a36Sopenharmony_ci sk = skb->sk; 76862306a36Sopenharmony_ci llcp_sock = nfc_llcp_sock(sk); 76962306a36Sopenharmony_ci 77062306a36Sopenharmony_ci if (llcp_sock == NULL && nfc_llcp_ptype(skb) == LLCP_PDU_I) { 77162306a36Sopenharmony_ci kfree_skb(skb); 77262306a36Sopenharmony_ci nfc_llcp_send_symm(local->dev); 77362306a36Sopenharmony_ci } else if (llcp_sock && !llcp_sock->remote_ready) { 77462306a36Sopenharmony_ci skb_queue_head(&local->tx_queue, skb); 77562306a36Sopenharmony_ci nfc_llcp_send_symm(local->dev); 77662306a36Sopenharmony_ci } else { 77762306a36Sopenharmony_ci struct sk_buff *copy_skb = NULL; 77862306a36Sopenharmony_ci u8 ptype = nfc_llcp_ptype(skb); 77962306a36Sopenharmony_ci int ret; 78062306a36Sopenharmony_ci 78162306a36Sopenharmony_ci pr_debug("Sending pending skb\n"); 78262306a36Sopenharmony_ci print_hex_dump_debug("LLCP Tx: ", DUMP_PREFIX_OFFSET, 78362306a36Sopenharmony_ci 16, 1, skb->data, skb->len, true); 78462306a36Sopenharmony_ci 78562306a36Sopenharmony_ci if (ptype == LLCP_PDU_I) 78662306a36Sopenharmony_ci copy_skb = skb_copy(skb, GFP_ATOMIC); 78762306a36Sopenharmony_ci 78862306a36Sopenharmony_ci __net_timestamp(skb); 78962306a36Sopenharmony_ci 79062306a36Sopenharmony_ci nfc_llcp_send_to_raw_sock(local, skb, 79162306a36Sopenharmony_ci NFC_DIRECTION_TX); 79262306a36Sopenharmony_ci 79362306a36Sopenharmony_ci ret = nfc_data_exchange(local->dev, local->target_idx, 79462306a36Sopenharmony_ci skb, nfc_llcp_recv, local); 79562306a36Sopenharmony_ci 79662306a36Sopenharmony_ci if (ret) { 79762306a36Sopenharmony_ci kfree_skb(copy_skb); 79862306a36Sopenharmony_ci goto out; 79962306a36Sopenharmony_ci } 80062306a36Sopenharmony_ci 80162306a36Sopenharmony_ci if (ptype == LLCP_PDU_I && copy_skb) 80262306a36Sopenharmony_ci skb_queue_tail(&llcp_sock->tx_pending_queue, 80362306a36Sopenharmony_ci copy_skb); 80462306a36Sopenharmony_ci } 80562306a36Sopenharmony_ci } else { 80662306a36Sopenharmony_ci nfc_llcp_send_symm(local->dev); 80762306a36Sopenharmony_ci } 80862306a36Sopenharmony_ci 80962306a36Sopenharmony_ciout: 81062306a36Sopenharmony_ci mod_timer(&local->link_timer, 81162306a36Sopenharmony_ci jiffies + msecs_to_jiffies(2 * local->remote_lto)); 81262306a36Sopenharmony_ci} 81362306a36Sopenharmony_ci 81462306a36Sopenharmony_cistatic struct nfc_llcp_sock *nfc_llcp_connecting_sock_get(struct nfc_llcp_local *local, 81562306a36Sopenharmony_ci u8 ssap) 81662306a36Sopenharmony_ci{ 81762306a36Sopenharmony_ci struct sock *sk; 81862306a36Sopenharmony_ci struct nfc_llcp_sock *llcp_sock; 81962306a36Sopenharmony_ci 82062306a36Sopenharmony_ci read_lock(&local->connecting_sockets.lock); 82162306a36Sopenharmony_ci 82262306a36Sopenharmony_ci sk_for_each(sk, &local->connecting_sockets.head) { 82362306a36Sopenharmony_ci llcp_sock = nfc_llcp_sock(sk); 82462306a36Sopenharmony_ci 82562306a36Sopenharmony_ci if (llcp_sock->ssap == ssap) { 82662306a36Sopenharmony_ci sock_hold(&llcp_sock->sk); 82762306a36Sopenharmony_ci goto out; 82862306a36Sopenharmony_ci } 82962306a36Sopenharmony_ci } 83062306a36Sopenharmony_ci 83162306a36Sopenharmony_ci llcp_sock = NULL; 83262306a36Sopenharmony_ci 83362306a36Sopenharmony_ciout: 83462306a36Sopenharmony_ci read_unlock(&local->connecting_sockets.lock); 83562306a36Sopenharmony_ci 83662306a36Sopenharmony_ci return llcp_sock; 83762306a36Sopenharmony_ci} 83862306a36Sopenharmony_ci 83962306a36Sopenharmony_cistatic struct nfc_llcp_sock *nfc_llcp_sock_get_sn(struct nfc_llcp_local *local, 84062306a36Sopenharmony_ci const u8 *sn, size_t sn_len) 84162306a36Sopenharmony_ci{ 84262306a36Sopenharmony_ci return nfc_llcp_sock_from_sn(local, sn, sn_len, true); 84362306a36Sopenharmony_ci} 84462306a36Sopenharmony_ci 84562306a36Sopenharmony_cistatic const u8 *nfc_llcp_connect_sn(const struct sk_buff *skb, size_t *sn_len) 84662306a36Sopenharmony_ci{ 84762306a36Sopenharmony_ci u8 type, length; 84862306a36Sopenharmony_ci const u8 *tlv = &skb->data[2]; 84962306a36Sopenharmony_ci size_t tlv_array_len = skb->len - LLCP_HEADER_SIZE, offset = 0; 85062306a36Sopenharmony_ci 85162306a36Sopenharmony_ci while (offset < tlv_array_len) { 85262306a36Sopenharmony_ci type = tlv[0]; 85362306a36Sopenharmony_ci length = tlv[1]; 85462306a36Sopenharmony_ci 85562306a36Sopenharmony_ci pr_debug("type 0x%x length %d\n", type, length); 85662306a36Sopenharmony_ci 85762306a36Sopenharmony_ci if (type == LLCP_TLV_SN) { 85862306a36Sopenharmony_ci *sn_len = length; 85962306a36Sopenharmony_ci return &tlv[2]; 86062306a36Sopenharmony_ci } 86162306a36Sopenharmony_ci 86262306a36Sopenharmony_ci offset += length + 2; 86362306a36Sopenharmony_ci tlv += length + 2; 86462306a36Sopenharmony_ci } 86562306a36Sopenharmony_ci 86662306a36Sopenharmony_ci return NULL; 86762306a36Sopenharmony_ci} 86862306a36Sopenharmony_ci 86962306a36Sopenharmony_cistatic void nfc_llcp_recv_ui(struct nfc_llcp_local *local, 87062306a36Sopenharmony_ci struct sk_buff *skb) 87162306a36Sopenharmony_ci{ 87262306a36Sopenharmony_ci struct nfc_llcp_sock *llcp_sock; 87362306a36Sopenharmony_ci struct nfc_llcp_ui_cb *ui_cb; 87462306a36Sopenharmony_ci u8 dsap, ssap; 87562306a36Sopenharmony_ci 87662306a36Sopenharmony_ci dsap = nfc_llcp_dsap(skb); 87762306a36Sopenharmony_ci ssap = nfc_llcp_ssap(skb); 87862306a36Sopenharmony_ci 87962306a36Sopenharmony_ci ui_cb = nfc_llcp_ui_skb_cb(skb); 88062306a36Sopenharmony_ci ui_cb->dsap = dsap; 88162306a36Sopenharmony_ci ui_cb->ssap = ssap; 88262306a36Sopenharmony_ci 88362306a36Sopenharmony_ci pr_debug("%d %d\n", dsap, ssap); 88462306a36Sopenharmony_ci 88562306a36Sopenharmony_ci /* We're looking for a bound socket, not a client one */ 88662306a36Sopenharmony_ci llcp_sock = nfc_llcp_sock_get(local, dsap, LLCP_SAP_SDP); 88762306a36Sopenharmony_ci if (llcp_sock == NULL || llcp_sock->sk.sk_type != SOCK_DGRAM) 88862306a36Sopenharmony_ci return; 88962306a36Sopenharmony_ci 89062306a36Sopenharmony_ci /* There is no sequence with UI frames */ 89162306a36Sopenharmony_ci skb_pull(skb, LLCP_HEADER_SIZE); 89262306a36Sopenharmony_ci if (!sock_queue_rcv_skb(&llcp_sock->sk, skb)) { 89362306a36Sopenharmony_ci /* 89462306a36Sopenharmony_ci * UI frames will be freed from the socket layer, so we 89562306a36Sopenharmony_ci * need to keep them alive until someone receives them. 89662306a36Sopenharmony_ci */ 89762306a36Sopenharmony_ci skb_get(skb); 89862306a36Sopenharmony_ci } else { 89962306a36Sopenharmony_ci pr_err("Receive queue is full\n"); 90062306a36Sopenharmony_ci } 90162306a36Sopenharmony_ci 90262306a36Sopenharmony_ci nfc_llcp_sock_put(llcp_sock); 90362306a36Sopenharmony_ci} 90462306a36Sopenharmony_ci 90562306a36Sopenharmony_cistatic void nfc_llcp_recv_connect(struct nfc_llcp_local *local, 90662306a36Sopenharmony_ci const struct sk_buff *skb) 90762306a36Sopenharmony_ci{ 90862306a36Sopenharmony_ci struct sock *new_sk, *parent; 90962306a36Sopenharmony_ci struct nfc_llcp_sock *sock, *new_sock; 91062306a36Sopenharmony_ci u8 dsap, ssap, reason; 91162306a36Sopenharmony_ci 91262306a36Sopenharmony_ci dsap = nfc_llcp_dsap(skb); 91362306a36Sopenharmony_ci ssap = nfc_llcp_ssap(skb); 91462306a36Sopenharmony_ci 91562306a36Sopenharmony_ci pr_debug("%d %d\n", dsap, ssap); 91662306a36Sopenharmony_ci 91762306a36Sopenharmony_ci if (dsap != LLCP_SAP_SDP) { 91862306a36Sopenharmony_ci sock = nfc_llcp_sock_get(local, dsap, LLCP_SAP_SDP); 91962306a36Sopenharmony_ci if (sock == NULL || sock->sk.sk_state != LLCP_LISTEN) { 92062306a36Sopenharmony_ci reason = LLCP_DM_NOBOUND; 92162306a36Sopenharmony_ci goto fail; 92262306a36Sopenharmony_ci } 92362306a36Sopenharmony_ci } else { 92462306a36Sopenharmony_ci const u8 *sn; 92562306a36Sopenharmony_ci size_t sn_len; 92662306a36Sopenharmony_ci 92762306a36Sopenharmony_ci sn = nfc_llcp_connect_sn(skb, &sn_len); 92862306a36Sopenharmony_ci if (sn == NULL) { 92962306a36Sopenharmony_ci reason = LLCP_DM_NOBOUND; 93062306a36Sopenharmony_ci goto fail; 93162306a36Sopenharmony_ci } 93262306a36Sopenharmony_ci 93362306a36Sopenharmony_ci pr_debug("Service name length %zu\n", sn_len); 93462306a36Sopenharmony_ci 93562306a36Sopenharmony_ci sock = nfc_llcp_sock_get_sn(local, sn, sn_len); 93662306a36Sopenharmony_ci if (sock == NULL) { 93762306a36Sopenharmony_ci reason = LLCP_DM_NOBOUND; 93862306a36Sopenharmony_ci goto fail; 93962306a36Sopenharmony_ci } 94062306a36Sopenharmony_ci } 94162306a36Sopenharmony_ci 94262306a36Sopenharmony_ci lock_sock(&sock->sk); 94362306a36Sopenharmony_ci 94462306a36Sopenharmony_ci parent = &sock->sk; 94562306a36Sopenharmony_ci 94662306a36Sopenharmony_ci if (sk_acceptq_is_full(parent)) { 94762306a36Sopenharmony_ci reason = LLCP_DM_REJ; 94862306a36Sopenharmony_ci release_sock(&sock->sk); 94962306a36Sopenharmony_ci sock_put(&sock->sk); 95062306a36Sopenharmony_ci goto fail; 95162306a36Sopenharmony_ci } 95262306a36Sopenharmony_ci 95362306a36Sopenharmony_ci if (sock->ssap == LLCP_SDP_UNBOUND) { 95462306a36Sopenharmony_ci u8 ssap = nfc_llcp_reserve_sdp_ssap(local); 95562306a36Sopenharmony_ci 95662306a36Sopenharmony_ci pr_debug("First client, reserving %d\n", ssap); 95762306a36Sopenharmony_ci 95862306a36Sopenharmony_ci if (ssap == LLCP_SAP_MAX) { 95962306a36Sopenharmony_ci reason = LLCP_DM_REJ; 96062306a36Sopenharmony_ci release_sock(&sock->sk); 96162306a36Sopenharmony_ci sock_put(&sock->sk); 96262306a36Sopenharmony_ci goto fail; 96362306a36Sopenharmony_ci } 96462306a36Sopenharmony_ci 96562306a36Sopenharmony_ci sock->ssap = ssap; 96662306a36Sopenharmony_ci } 96762306a36Sopenharmony_ci 96862306a36Sopenharmony_ci new_sk = nfc_llcp_sock_alloc(NULL, parent->sk_type, GFP_ATOMIC, 0); 96962306a36Sopenharmony_ci if (new_sk == NULL) { 97062306a36Sopenharmony_ci reason = LLCP_DM_REJ; 97162306a36Sopenharmony_ci release_sock(&sock->sk); 97262306a36Sopenharmony_ci sock_put(&sock->sk); 97362306a36Sopenharmony_ci goto fail; 97462306a36Sopenharmony_ci } 97562306a36Sopenharmony_ci 97662306a36Sopenharmony_ci new_sock = nfc_llcp_sock(new_sk); 97762306a36Sopenharmony_ci 97862306a36Sopenharmony_ci new_sock->local = nfc_llcp_local_get(local); 97962306a36Sopenharmony_ci if (!new_sock->local) { 98062306a36Sopenharmony_ci reason = LLCP_DM_REJ; 98162306a36Sopenharmony_ci sock_put(&new_sock->sk); 98262306a36Sopenharmony_ci release_sock(&sock->sk); 98362306a36Sopenharmony_ci sock_put(&sock->sk); 98462306a36Sopenharmony_ci goto fail; 98562306a36Sopenharmony_ci } 98662306a36Sopenharmony_ci 98762306a36Sopenharmony_ci new_sock->dev = local->dev; 98862306a36Sopenharmony_ci new_sock->rw = sock->rw; 98962306a36Sopenharmony_ci new_sock->miux = sock->miux; 99062306a36Sopenharmony_ci new_sock->nfc_protocol = sock->nfc_protocol; 99162306a36Sopenharmony_ci new_sock->dsap = ssap; 99262306a36Sopenharmony_ci new_sock->target_idx = local->target_idx; 99362306a36Sopenharmony_ci new_sock->parent = parent; 99462306a36Sopenharmony_ci new_sock->ssap = sock->ssap; 99562306a36Sopenharmony_ci if (sock->ssap < LLCP_LOCAL_NUM_SAP && sock->ssap >= LLCP_WKS_NUM_SAP) { 99662306a36Sopenharmony_ci atomic_t *client_count; 99762306a36Sopenharmony_ci 99862306a36Sopenharmony_ci pr_debug("reserved_ssap %d for %p\n", sock->ssap, new_sock); 99962306a36Sopenharmony_ci 100062306a36Sopenharmony_ci client_count = 100162306a36Sopenharmony_ci &local->local_sdp_cnt[sock->ssap - LLCP_WKS_NUM_SAP]; 100262306a36Sopenharmony_ci 100362306a36Sopenharmony_ci atomic_inc(client_count); 100462306a36Sopenharmony_ci new_sock->reserved_ssap = sock->ssap; 100562306a36Sopenharmony_ci } 100662306a36Sopenharmony_ci 100762306a36Sopenharmony_ci nfc_llcp_parse_connection_tlv(new_sock, &skb->data[LLCP_HEADER_SIZE], 100862306a36Sopenharmony_ci skb->len - LLCP_HEADER_SIZE); 100962306a36Sopenharmony_ci 101062306a36Sopenharmony_ci pr_debug("new sock %p sk %p\n", new_sock, &new_sock->sk); 101162306a36Sopenharmony_ci 101262306a36Sopenharmony_ci nfc_llcp_sock_link(&local->sockets, new_sk); 101362306a36Sopenharmony_ci 101462306a36Sopenharmony_ci nfc_llcp_accept_enqueue(&sock->sk, new_sk); 101562306a36Sopenharmony_ci 101662306a36Sopenharmony_ci nfc_get_device(local->dev->idx); 101762306a36Sopenharmony_ci 101862306a36Sopenharmony_ci new_sk->sk_state = LLCP_CONNECTED; 101962306a36Sopenharmony_ci 102062306a36Sopenharmony_ci /* Wake the listening processes */ 102162306a36Sopenharmony_ci parent->sk_data_ready(parent); 102262306a36Sopenharmony_ci 102362306a36Sopenharmony_ci /* Send CC */ 102462306a36Sopenharmony_ci nfc_llcp_send_cc(new_sock); 102562306a36Sopenharmony_ci 102662306a36Sopenharmony_ci release_sock(&sock->sk); 102762306a36Sopenharmony_ci sock_put(&sock->sk); 102862306a36Sopenharmony_ci 102962306a36Sopenharmony_ci return; 103062306a36Sopenharmony_ci 103162306a36Sopenharmony_cifail: 103262306a36Sopenharmony_ci /* Send DM */ 103362306a36Sopenharmony_ci nfc_llcp_send_dm(local, dsap, ssap, reason); 103462306a36Sopenharmony_ci} 103562306a36Sopenharmony_ci 103662306a36Sopenharmony_ciint nfc_llcp_queue_i_frames(struct nfc_llcp_sock *sock) 103762306a36Sopenharmony_ci{ 103862306a36Sopenharmony_ci int nr_frames = 0; 103962306a36Sopenharmony_ci struct nfc_llcp_local *local = sock->local; 104062306a36Sopenharmony_ci 104162306a36Sopenharmony_ci pr_debug("Remote ready %d tx queue len %d remote rw %d", 104262306a36Sopenharmony_ci sock->remote_ready, skb_queue_len(&sock->tx_pending_queue), 104362306a36Sopenharmony_ci sock->remote_rw); 104462306a36Sopenharmony_ci 104562306a36Sopenharmony_ci /* Try to queue some I frames for transmission */ 104662306a36Sopenharmony_ci while (sock->remote_ready && 104762306a36Sopenharmony_ci skb_queue_len(&sock->tx_pending_queue) < sock->remote_rw) { 104862306a36Sopenharmony_ci struct sk_buff *pdu; 104962306a36Sopenharmony_ci 105062306a36Sopenharmony_ci pdu = skb_dequeue(&sock->tx_queue); 105162306a36Sopenharmony_ci if (pdu == NULL) 105262306a36Sopenharmony_ci break; 105362306a36Sopenharmony_ci 105462306a36Sopenharmony_ci /* Update N(S)/N(R) */ 105562306a36Sopenharmony_ci nfc_llcp_set_nrns(sock, pdu); 105662306a36Sopenharmony_ci 105762306a36Sopenharmony_ci skb_queue_tail(&local->tx_queue, pdu); 105862306a36Sopenharmony_ci nr_frames++; 105962306a36Sopenharmony_ci } 106062306a36Sopenharmony_ci 106162306a36Sopenharmony_ci return nr_frames; 106262306a36Sopenharmony_ci} 106362306a36Sopenharmony_ci 106462306a36Sopenharmony_cistatic void nfc_llcp_recv_hdlc(struct nfc_llcp_local *local, 106562306a36Sopenharmony_ci struct sk_buff *skb) 106662306a36Sopenharmony_ci{ 106762306a36Sopenharmony_ci struct nfc_llcp_sock *llcp_sock; 106862306a36Sopenharmony_ci struct sock *sk; 106962306a36Sopenharmony_ci u8 dsap, ssap, ptype, ns, nr; 107062306a36Sopenharmony_ci 107162306a36Sopenharmony_ci ptype = nfc_llcp_ptype(skb); 107262306a36Sopenharmony_ci dsap = nfc_llcp_dsap(skb); 107362306a36Sopenharmony_ci ssap = nfc_llcp_ssap(skb); 107462306a36Sopenharmony_ci ns = nfc_llcp_ns(skb); 107562306a36Sopenharmony_ci nr = nfc_llcp_nr(skb); 107662306a36Sopenharmony_ci 107762306a36Sopenharmony_ci pr_debug("%d %d R %d S %d\n", dsap, ssap, nr, ns); 107862306a36Sopenharmony_ci 107962306a36Sopenharmony_ci llcp_sock = nfc_llcp_sock_get(local, dsap, ssap); 108062306a36Sopenharmony_ci if (llcp_sock == NULL) { 108162306a36Sopenharmony_ci nfc_llcp_send_dm(local, dsap, ssap, LLCP_DM_NOCONN); 108262306a36Sopenharmony_ci return; 108362306a36Sopenharmony_ci } 108462306a36Sopenharmony_ci 108562306a36Sopenharmony_ci sk = &llcp_sock->sk; 108662306a36Sopenharmony_ci lock_sock(sk); 108762306a36Sopenharmony_ci if (sk->sk_state == LLCP_CLOSED) { 108862306a36Sopenharmony_ci release_sock(sk); 108962306a36Sopenharmony_ci nfc_llcp_sock_put(llcp_sock); 109062306a36Sopenharmony_ci } 109162306a36Sopenharmony_ci 109262306a36Sopenharmony_ci /* Pass the payload upstream */ 109362306a36Sopenharmony_ci if (ptype == LLCP_PDU_I) { 109462306a36Sopenharmony_ci pr_debug("I frame, queueing on %p\n", &llcp_sock->sk); 109562306a36Sopenharmony_ci 109662306a36Sopenharmony_ci if (ns == llcp_sock->recv_n) 109762306a36Sopenharmony_ci llcp_sock->recv_n = (llcp_sock->recv_n + 1) % 16; 109862306a36Sopenharmony_ci else 109962306a36Sopenharmony_ci pr_err("Received out of sequence I PDU\n"); 110062306a36Sopenharmony_ci 110162306a36Sopenharmony_ci skb_pull(skb, LLCP_HEADER_SIZE + LLCP_SEQUENCE_SIZE); 110262306a36Sopenharmony_ci if (!sock_queue_rcv_skb(&llcp_sock->sk, skb)) { 110362306a36Sopenharmony_ci /* 110462306a36Sopenharmony_ci * I frames will be freed from the socket layer, so we 110562306a36Sopenharmony_ci * need to keep them alive until someone receives them. 110662306a36Sopenharmony_ci */ 110762306a36Sopenharmony_ci skb_get(skb); 110862306a36Sopenharmony_ci } else { 110962306a36Sopenharmony_ci pr_err("Receive queue is full\n"); 111062306a36Sopenharmony_ci } 111162306a36Sopenharmony_ci } 111262306a36Sopenharmony_ci 111362306a36Sopenharmony_ci /* Remove skbs from the pending queue */ 111462306a36Sopenharmony_ci if (llcp_sock->send_ack_n != nr) { 111562306a36Sopenharmony_ci struct sk_buff *s, *tmp; 111662306a36Sopenharmony_ci u8 n; 111762306a36Sopenharmony_ci 111862306a36Sopenharmony_ci llcp_sock->send_ack_n = nr; 111962306a36Sopenharmony_ci 112062306a36Sopenharmony_ci /* Remove and free all skbs until ns == nr */ 112162306a36Sopenharmony_ci skb_queue_walk_safe(&llcp_sock->tx_pending_queue, s, tmp) { 112262306a36Sopenharmony_ci n = nfc_llcp_ns(s); 112362306a36Sopenharmony_ci 112462306a36Sopenharmony_ci skb_unlink(s, &llcp_sock->tx_pending_queue); 112562306a36Sopenharmony_ci kfree_skb(s); 112662306a36Sopenharmony_ci 112762306a36Sopenharmony_ci if (n == nr) 112862306a36Sopenharmony_ci break; 112962306a36Sopenharmony_ci } 113062306a36Sopenharmony_ci 113162306a36Sopenharmony_ci /* Re-queue the remaining skbs for transmission */ 113262306a36Sopenharmony_ci skb_queue_reverse_walk_safe(&llcp_sock->tx_pending_queue, 113362306a36Sopenharmony_ci s, tmp) { 113462306a36Sopenharmony_ci skb_unlink(s, &llcp_sock->tx_pending_queue); 113562306a36Sopenharmony_ci skb_queue_head(&local->tx_queue, s); 113662306a36Sopenharmony_ci } 113762306a36Sopenharmony_ci } 113862306a36Sopenharmony_ci 113962306a36Sopenharmony_ci if (ptype == LLCP_PDU_RR) 114062306a36Sopenharmony_ci llcp_sock->remote_ready = true; 114162306a36Sopenharmony_ci else if (ptype == LLCP_PDU_RNR) 114262306a36Sopenharmony_ci llcp_sock->remote_ready = false; 114362306a36Sopenharmony_ci 114462306a36Sopenharmony_ci if (nfc_llcp_queue_i_frames(llcp_sock) == 0 && ptype == LLCP_PDU_I) 114562306a36Sopenharmony_ci nfc_llcp_send_rr(llcp_sock); 114662306a36Sopenharmony_ci 114762306a36Sopenharmony_ci release_sock(sk); 114862306a36Sopenharmony_ci nfc_llcp_sock_put(llcp_sock); 114962306a36Sopenharmony_ci} 115062306a36Sopenharmony_ci 115162306a36Sopenharmony_cistatic void nfc_llcp_recv_disc(struct nfc_llcp_local *local, 115262306a36Sopenharmony_ci const struct sk_buff *skb) 115362306a36Sopenharmony_ci{ 115462306a36Sopenharmony_ci struct nfc_llcp_sock *llcp_sock; 115562306a36Sopenharmony_ci struct sock *sk; 115662306a36Sopenharmony_ci u8 dsap, ssap; 115762306a36Sopenharmony_ci 115862306a36Sopenharmony_ci dsap = nfc_llcp_dsap(skb); 115962306a36Sopenharmony_ci ssap = nfc_llcp_ssap(skb); 116062306a36Sopenharmony_ci 116162306a36Sopenharmony_ci if ((dsap == 0) && (ssap == 0)) { 116262306a36Sopenharmony_ci pr_debug("Connection termination"); 116362306a36Sopenharmony_ci nfc_dep_link_down(local->dev); 116462306a36Sopenharmony_ci return; 116562306a36Sopenharmony_ci } 116662306a36Sopenharmony_ci 116762306a36Sopenharmony_ci llcp_sock = nfc_llcp_sock_get(local, dsap, ssap); 116862306a36Sopenharmony_ci if (llcp_sock == NULL) { 116962306a36Sopenharmony_ci nfc_llcp_send_dm(local, dsap, ssap, LLCP_DM_NOCONN); 117062306a36Sopenharmony_ci return; 117162306a36Sopenharmony_ci } 117262306a36Sopenharmony_ci 117362306a36Sopenharmony_ci sk = &llcp_sock->sk; 117462306a36Sopenharmony_ci lock_sock(sk); 117562306a36Sopenharmony_ci 117662306a36Sopenharmony_ci nfc_llcp_socket_purge(llcp_sock); 117762306a36Sopenharmony_ci 117862306a36Sopenharmony_ci if (sk->sk_state == LLCP_CLOSED) { 117962306a36Sopenharmony_ci release_sock(sk); 118062306a36Sopenharmony_ci nfc_llcp_sock_put(llcp_sock); 118162306a36Sopenharmony_ci } 118262306a36Sopenharmony_ci 118362306a36Sopenharmony_ci if (sk->sk_state == LLCP_CONNECTED) { 118462306a36Sopenharmony_ci nfc_put_device(local->dev); 118562306a36Sopenharmony_ci sk->sk_state = LLCP_CLOSED; 118662306a36Sopenharmony_ci sk->sk_state_change(sk); 118762306a36Sopenharmony_ci } 118862306a36Sopenharmony_ci 118962306a36Sopenharmony_ci nfc_llcp_send_dm(local, dsap, ssap, LLCP_DM_DISC); 119062306a36Sopenharmony_ci 119162306a36Sopenharmony_ci release_sock(sk); 119262306a36Sopenharmony_ci nfc_llcp_sock_put(llcp_sock); 119362306a36Sopenharmony_ci} 119462306a36Sopenharmony_ci 119562306a36Sopenharmony_cistatic void nfc_llcp_recv_cc(struct nfc_llcp_local *local, 119662306a36Sopenharmony_ci const struct sk_buff *skb) 119762306a36Sopenharmony_ci{ 119862306a36Sopenharmony_ci struct nfc_llcp_sock *llcp_sock; 119962306a36Sopenharmony_ci struct sock *sk; 120062306a36Sopenharmony_ci u8 dsap, ssap; 120162306a36Sopenharmony_ci 120262306a36Sopenharmony_ci dsap = nfc_llcp_dsap(skb); 120362306a36Sopenharmony_ci ssap = nfc_llcp_ssap(skb); 120462306a36Sopenharmony_ci 120562306a36Sopenharmony_ci llcp_sock = nfc_llcp_connecting_sock_get(local, dsap); 120662306a36Sopenharmony_ci if (llcp_sock == NULL) { 120762306a36Sopenharmony_ci pr_err("Invalid CC\n"); 120862306a36Sopenharmony_ci nfc_llcp_send_dm(local, dsap, ssap, LLCP_DM_NOCONN); 120962306a36Sopenharmony_ci 121062306a36Sopenharmony_ci return; 121162306a36Sopenharmony_ci } 121262306a36Sopenharmony_ci 121362306a36Sopenharmony_ci sk = &llcp_sock->sk; 121462306a36Sopenharmony_ci 121562306a36Sopenharmony_ci /* Unlink from connecting and link to the client array */ 121662306a36Sopenharmony_ci nfc_llcp_sock_unlink(&local->connecting_sockets, sk); 121762306a36Sopenharmony_ci nfc_llcp_sock_link(&local->sockets, sk); 121862306a36Sopenharmony_ci llcp_sock->dsap = ssap; 121962306a36Sopenharmony_ci 122062306a36Sopenharmony_ci nfc_llcp_parse_connection_tlv(llcp_sock, &skb->data[LLCP_HEADER_SIZE], 122162306a36Sopenharmony_ci skb->len - LLCP_HEADER_SIZE); 122262306a36Sopenharmony_ci 122362306a36Sopenharmony_ci sk->sk_state = LLCP_CONNECTED; 122462306a36Sopenharmony_ci sk->sk_state_change(sk); 122562306a36Sopenharmony_ci 122662306a36Sopenharmony_ci nfc_llcp_sock_put(llcp_sock); 122762306a36Sopenharmony_ci} 122862306a36Sopenharmony_ci 122962306a36Sopenharmony_cistatic void nfc_llcp_recv_dm(struct nfc_llcp_local *local, 123062306a36Sopenharmony_ci const struct sk_buff *skb) 123162306a36Sopenharmony_ci{ 123262306a36Sopenharmony_ci struct nfc_llcp_sock *llcp_sock; 123362306a36Sopenharmony_ci struct sock *sk; 123462306a36Sopenharmony_ci u8 dsap, ssap, reason; 123562306a36Sopenharmony_ci 123662306a36Sopenharmony_ci dsap = nfc_llcp_dsap(skb); 123762306a36Sopenharmony_ci ssap = nfc_llcp_ssap(skb); 123862306a36Sopenharmony_ci reason = skb->data[2]; 123962306a36Sopenharmony_ci 124062306a36Sopenharmony_ci pr_debug("%d %d reason %d\n", ssap, dsap, reason); 124162306a36Sopenharmony_ci 124262306a36Sopenharmony_ci switch (reason) { 124362306a36Sopenharmony_ci case LLCP_DM_NOBOUND: 124462306a36Sopenharmony_ci case LLCP_DM_REJ: 124562306a36Sopenharmony_ci llcp_sock = nfc_llcp_connecting_sock_get(local, dsap); 124662306a36Sopenharmony_ci break; 124762306a36Sopenharmony_ci 124862306a36Sopenharmony_ci default: 124962306a36Sopenharmony_ci llcp_sock = nfc_llcp_sock_get(local, dsap, ssap); 125062306a36Sopenharmony_ci break; 125162306a36Sopenharmony_ci } 125262306a36Sopenharmony_ci 125362306a36Sopenharmony_ci if (llcp_sock == NULL) { 125462306a36Sopenharmony_ci pr_debug("Already closed\n"); 125562306a36Sopenharmony_ci return; 125662306a36Sopenharmony_ci } 125762306a36Sopenharmony_ci 125862306a36Sopenharmony_ci sk = &llcp_sock->sk; 125962306a36Sopenharmony_ci 126062306a36Sopenharmony_ci sk->sk_err = ENXIO; 126162306a36Sopenharmony_ci sk->sk_state = LLCP_CLOSED; 126262306a36Sopenharmony_ci sk->sk_state_change(sk); 126362306a36Sopenharmony_ci 126462306a36Sopenharmony_ci nfc_llcp_sock_put(llcp_sock); 126562306a36Sopenharmony_ci} 126662306a36Sopenharmony_ci 126762306a36Sopenharmony_cistatic void nfc_llcp_recv_snl(struct nfc_llcp_local *local, 126862306a36Sopenharmony_ci const struct sk_buff *skb) 126962306a36Sopenharmony_ci{ 127062306a36Sopenharmony_ci struct nfc_llcp_sock *llcp_sock; 127162306a36Sopenharmony_ci u8 dsap, ssap, type, length, tid, sap; 127262306a36Sopenharmony_ci const u8 *tlv; 127362306a36Sopenharmony_ci u16 tlv_len, offset; 127462306a36Sopenharmony_ci const char *service_name; 127562306a36Sopenharmony_ci size_t service_name_len; 127662306a36Sopenharmony_ci struct nfc_llcp_sdp_tlv *sdp; 127762306a36Sopenharmony_ci HLIST_HEAD(llc_sdres_list); 127862306a36Sopenharmony_ci size_t sdres_tlvs_len; 127962306a36Sopenharmony_ci HLIST_HEAD(nl_sdres_list); 128062306a36Sopenharmony_ci 128162306a36Sopenharmony_ci dsap = nfc_llcp_dsap(skb); 128262306a36Sopenharmony_ci ssap = nfc_llcp_ssap(skb); 128362306a36Sopenharmony_ci 128462306a36Sopenharmony_ci pr_debug("%d %d\n", dsap, ssap); 128562306a36Sopenharmony_ci 128662306a36Sopenharmony_ci if (dsap != LLCP_SAP_SDP || ssap != LLCP_SAP_SDP) { 128762306a36Sopenharmony_ci pr_err("Wrong SNL SAP\n"); 128862306a36Sopenharmony_ci return; 128962306a36Sopenharmony_ci } 129062306a36Sopenharmony_ci 129162306a36Sopenharmony_ci tlv = &skb->data[LLCP_HEADER_SIZE]; 129262306a36Sopenharmony_ci tlv_len = skb->len - LLCP_HEADER_SIZE; 129362306a36Sopenharmony_ci offset = 0; 129462306a36Sopenharmony_ci sdres_tlvs_len = 0; 129562306a36Sopenharmony_ci 129662306a36Sopenharmony_ci while (offset < tlv_len) { 129762306a36Sopenharmony_ci type = tlv[0]; 129862306a36Sopenharmony_ci length = tlv[1]; 129962306a36Sopenharmony_ci 130062306a36Sopenharmony_ci switch (type) { 130162306a36Sopenharmony_ci case LLCP_TLV_SDREQ: 130262306a36Sopenharmony_ci tid = tlv[2]; 130362306a36Sopenharmony_ci service_name = (char *) &tlv[3]; 130462306a36Sopenharmony_ci service_name_len = length - 1; 130562306a36Sopenharmony_ci 130662306a36Sopenharmony_ci pr_debug("Looking for %.16s\n", service_name); 130762306a36Sopenharmony_ci 130862306a36Sopenharmony_ci if (service_name_len == strlen("urn:nfc:sn:sdp") && 130962306a36Sopenharmony_ci !strncmp(service_name, "urn:nfc:sn:sdp", 131062306a36Sopenharmony_ci service_name_len)) { 131162306a36Sopenharmony_ci sap = 1; 131262306a36Sopenharmony_ci goto add_snl; 131362306a36Sopenharmony_ci } 131462306a36Sopenharmony_ci 131562306a36Sopenharmony_ci llcp_sock = nfc_llcp_sock_from_sn(local, service_name, 131662306a36Sopenharmony_ci service_name_len, 131762306a36Sopenharmony_ci true); 131862306a36Sopenharmony_ci if (!llcp_sock) { 131962306a36Sopenharmony_ci sap = 0; 132062306a36Sopenharmony_ci goto add_snl; 132162306a36Sopenharmony_ci } 132262306a36Sopenharmony_ci 132362306a36Sopenharmony_ci /* 132462306a36Sopenharmony_ci * We found a socket but its ssap has not been reserved 132562306a36Sopenharmony_ci * yet. We need to assign it for good and send a reply. 132662306a36Sopenharmony_ci * The ssap will be freed when the socket is closed. 132762306a36Sopenharmony_ci */ 132862306a36Sopenharmony_ci if (llcp_sock->ssap == LLCP_SDP_UNBOUND) { 132962306a36Sopenharmony_ci atomic_t *client_count; 133062306a36Sopenharmony_ci 133162306a36Sopenharmony_ci sap = nfc_llcp_reserve_sdp_ssap(local); 133262306a36Sopenharmony_ci 133362306a36Sopenharmony_ci pr_debug("Reserving %d\n", sap); 133462306a36Sopenharmony_ci 133562306a36Sopenharmony_ci if (sap == LLCP_SAP_MAX) { 133662306a36Sopenharmony_ci sap = 0; 133762306a36Sopenharmony_ci nfc_llcp_sock_put(llcp_sock); 133862306a36Sopenharmony_ci goto add_snl; 133962306a36Sopenharmony_ci } 134062306a36Sopenharmony_ci 134162306a36Sopenharmony_ci client_count = 134262306a36Sopenharmony_ci &local->local_sdp_cnt[sap - 134362306a36Sopenharmony_ci LLCP_WKS_NUM_SAP]; 134462306a36Sopenharmony_ci 134562306a36Sopenharmony_ci atomic_inc(client_count); 134662306a36Sopenharmony_ci 134762306a36Sopenharmony_ci llcp_sock->ssap = sap; 134862306a36Sopenharmony_ci llcp_sock->reserved_ssap = sap; 134962306a36Sopenharmony_ci } else { 135062306a36Sopenharmony_ci sap = llcp_sock->ssap; 135162306a36Sopenharmony_ci } 135262306a36Sopenharmony_ci 135362306a36Sopenharmony_ci pr_debug("%p %d\n", llcp_sock, sap); 135462306a36Sopenharmony_ci 135562306a36Sopenharmony_ci nfc_llcp_sock_put(llcp_sock); 135662306a36Sopenharmony_ciadd_snl: 135762306a36Sopenharmony_ci sdp = nfc_llcp_build_sdres_tlv(tid, sap); 135862306a36Sopenharmony_ci if (sdp == NULL) 135962306a36Sopenharmony_ci goto exit; 136062306a36Sopenharmony_ci 136162306a36Sopenharmony_ci sdres_tlvs_len += sdp->tlv_len; 136262306a36Sopenharmony_ci hlist_add_head(&sdp->node, &llc_sdres_list); 136362306a36Sopenharmony_ci break; 136462306a36Sopenharmony_ci 136562306a36Sopenharmony_ci case LLCP_TLV_SDRES: 136662306a36Sopenharmony_ci mutex_lock(&local->sdreq_lock); 136762306a36Sopenharmony_ci 136862306a36Sopenharmony_ci pr_debug("LLCP_TLV_SDRES: searching tid %d\n", tlv[2]); 136962306a36Sopenharmony_ci 137062306a36Sopenharmony_ci hlist_for_each_entry(sdp, &local->pending_sdreqs, node) { 137162306a36Sopenharmony_ci if (sdp->tid != tlv[2]) 137262306a36Sopenharmony_ci continue; 137362306a36Sopenharmony_ci 137462306a36Sopenharmony_ci sdp->sap = tlv[3]; 137562306a36Sopenharmony_ci 137662306a36Sopenharmony_ci pr_debug("Found: uri=%s, sap=%d\n", 137762306a36Sopenharmony_ci sdp->uri, sdp->sap); 137862306a36Sopenharmony_ci 137962306a36Sopenharmony_ci hlist_del(&sdp->node); 138062306a36Sopenharmony_ci 138162306a36Sopenharmony_ci hlist_add_head(&sdp->node, &nl_sdres_list); 138262306a36Sopenharmony_ci 138362306a36Sopenharmony_ci break; 138462306a36Sopenharmony_ci } 138562306a36Sopenharmony_ci 138662306a36Sopenharmony_ci mutex_unlock(&local->sdreq_lock); 138762306a36Sopenharmony_ci break; 138862306a36Sopenharmony_ci 138962306a36Sopenharmony_ci default: 139062306a36Sopenharmony_ci pr_err("Invalid SNL tlv value 0x%x\n", type); 139162306a36Sopenharmony_ci break; 139262306a36Sopenharmony_ci } 139362306a36Sopenharmony_ci 139462306a36Sopenharmony_ci offset += length + 2; 139562306a36Sopenharmony_ci tlv += length + 2; 139662306a36Sopenharmony_ci } 139762306a36Sopenharmony_ci 139862306a36Sopenharmony_ciexit: 139962306a36Sopenharmony_ci if (!hlist_empty(&nl_sdres_list)) 140062306a36Sopenharmony_ci nfc_genl_llc_send_sdres(local->dev, &nl_sdres_list); 140162306a36Sopenharmony_ci 140262306a36Sopenharmony_ci if (!hlist_empty(&llc_sdres_list)) 140362306a36Sopenharmony_ci nfc_llcp_send_snl_sdres(local, &llc_sdres_list, sdres_tlvs_len); 140462306a36Sopenharmony_ci} 140562306a36Sopenharmony_ci 140662306a36Sopenharmony_cistatic void nfc_llcp_recv_agf(struct nfc_llcp_local *local, struct sk_buff *skb) 140762306a36Sopenharmony_ci{ 140862306a36Sopenharmony_ci u8 ptype; 140962306a36Sopenharmony_ci u16 pdu_len; 141062306a36Sopenharmony_ci struct sk_buff *new_skb; 141162306a36Sopenharmony_ci 141262306a36Sopenharmony_ci if (skb->len <= LLCP_HEADER_SIZE) { 141362306a36Sopenharmony_ci pr_err("Malformed AGF PDU\n"); 141462306a36Sopenharmony_ci return; 141562306a36Sopenharmony_ci } 141662306a36Sopenharmony_ci 141762306a36Sopenharmony_ci skb_pull(skb, LLCP_HEADER_SIZE); 141862306a36Sopenharmony_ci 141962306a36Sopenharmony_ci while (skb->len > LLCP_AGF_PDU_HEADER_SIZE) { 142062306a36Sopenharmony_ci pdu_len = skb->data[0] << 8 | skb->data[1]; 142162306a36Sopenharmony_ci 142262306a36Sopenharmony_ci skb_pull(skb, LLCP_AGF_PDU_HEADER_SIZE); 142362306a36Sopenharmony_ci 142462306a36Sopenharmony_ci if (pdu_len < LLCP_HEADER_SIZE || pdu_len > skb->len) { 142562306a36Sopenharmony_ci pr_err("Malformed AGF PDU\n"); 142662306a36Sopenharmony_ci return; 142762306a36Sopenharmony_ci } 142862306a36Sopenharmony_ci 142962306a36Sopenharmony_ci ptype = nfc_llcp_ptype(skb); 143062306a36Sopenharmony_ci 143162306a36Sopenharmony_ci if (ptype == LLCP_PDU_SYMM || ptype == LLCP_PDU_AGF) 143262306a36Sopenharmony_ci goto next; 143362306a36Sopenharmony_ci 143462306a36Sopenharmony_ci new_skb = nfc_alloc_recv_skb(pdu_len, GFP_KERNEL); 143562306a36Sopenharmony_ci if (new_skb == NULL) { 143662306a36Sopenharmony_ci pr_err("Could not allocate PDU\n"); 143762306a36Sopenharmony_ci return; 143862306a36Sopenharmony_ci } 143962306a36Sopenharmony_ci 144062306a36Sopenharmony_ci skb_put_data(new_skb, skb->data, pdu_len); 144162306a36Sopenharmony_ci 144262306a36Sopenharmony_ci nfc_llcp_rx_skb(local, new_skb); 144362306a36Sopenharmony_ci 144462306a36Sopenharmony_ci kfree_skb(new_skb); 144562306a36Sopenharmony_cinext: 144662306a36Sopenharmony_ci skb_pull(skb, pdu_len); 144762306a36Sopenharmony_ci } 144862306a36Sopenharmony_ci} 144962306a36Sopenharmony_ci 145062306a36Sopenharmony_cistatic void nfc_llcp_rx_skb(struct nfc_llcp_local *local, struct sk_buff *skb) 145162306a36Sopenharmony_ci{ 145262306a36Sopenharmony_ci u8 dsap, ssap, ptype; 145362306a36Sopenharmony_ci 145462306a36Sopenharmony_ci ptype = nfc_llcp_ptype(skb); 145562306a36Sopenharmony_ci dsap = nfc_llcp_dsap(skb); 145662306a36Sopenharmony_ci ssap = nfc_llcp_ssap(skb); 145762306a36Sopenharmony_ci 145862306a36Sopenharmony_ci pr_debug("ptype 0x%x dsap 0x%x ssap 0x%x\n", ptype, dsap, ssap); 145962306a36Sopenharmony_ci 146062306a36Sopenharmony_ci if (ptype != LLCP_PDU_SYMM) 146162306a36Sopenharmony_ci print_hex_dump_debug("LLCP Rx: ", DUMP_PREFIX_OFFSET, 16, 1, 146262306a36Sopenharmony_ci skb->data, skb->len, true); 146362306a36Sopenharmony_ci 146462306a36Sopenharmony_ci switch (ptype) { 146562306a36Sopenharmony_ci case LLCP_PDU_SYMM: 146662306a36Sopenharmony_ci pr_debug("SYMM\n"); 146762306a36Sopenharmony_ci break; 146862306a36Sopenharmony_ci 146962306a36Sopenharmony_ci case LLCP_PDU_UI: 147062306a36Sopenharmony_ci pr_debug("UI\n"); 147162306a36Sopenharmony_ci nfc_llcp_recv_ui(local, skb); 147262306a36Sopenharmony_ci break; 147362306a36Sopenharmony_ci 147462306a36Sopenharmony_ci case LLCP_PDU_CONNECT: 147562306a36Sopenharmony_ci pr_debug("CONNECT\n"); 147662306a36Sopenharmony_ci nfc_llcp_recv_connect(local, skb); 147762306a36Sopenharmony_ci break; 147862306a36Sopenharmony_ci 147962306a36Sopenharmony_ci case LLCP_PDU_DISC: 148062306a36Sopenharmony_ci pr_debug("DISC\n"); 148162306a36Sopenharmony_ci nfc_llcp_recv_disc(local, skb); 148262306a36Sopenharmony_ci break; 148362306a36Sopenharmony_ci 148462306a36Sopenharmony_ci case LLCP_PDU_CC: 148562306a36Sopenharmony_ci pr_debug("CC\n"); 148662306a36Sopenharmony_ci nfc_llcp_recv_cc(local, skb); 148762306a36Sopenharmony_ci break; 148862306a36Sopenharmony_ci 148962306a36Sopenharmony_ci case LLCP_PDU_DM: 149062306a36Sopenharmony_ci pr_debug("DM\n"); 149162306a36Sopenharmony_ci nfc_llcp_recv_dm(local, skb); 149262306a36Sopenharmony_ci break; 149362306a36Sopenharmony_ci 149462306a36Sopenharmony_ci case LLCP_PDU_SNL: 149562306a36Sopenharmony_ci pr_debug("SNL\n"); 149662306a36Sopenharmony_ci nfc_llcp_recv_snl(local, skb); 149762306a36Sopenharmony_ci break; 149862306a36Sopenharmony_ci 149962306a36Sopenharmony_ci case LLCP_PDU_I: 150062306a36Sopenharmony_ci case LLCP_PDU_RR: 150162306a36Sopenharmony_ci case LLCP_PDU_RNR: 150262306a36Sopenharmony_ci pr_debug("I frame\n"); 150362306a36Sopenharmony_ci nfc_llcp_recv_hdlc(local, skb); 150462306a36Sopenharmony_ci break; 150562306a36Sopenharmony_ci 150662306a36Sopenharmony_ci case LLCP_PDU_AGF: 150762306a36Sopenharmony_ci pr_debug("AGF frame\n"); 150862306a36Sopenharmony_ci nfc_llcp_recv_agf(local, skb); 150962306a36Sopenharmony_ci break; 151062306a36Sopenharmony_ci } 151162306a36Sopenharmony_ci} 151262306a36Sopenharmony_ci 151362306a36Sopenharmony_cistatic void nfc_llcp_rx_work(struct work_struct *work) 151462306a36Sopenharmony_ci{ 151562306a36Sopenharmony_ci struct nfc_llcp_local *local = container_of(work, struct nfc_llcp_local, 151662306a36Sopenharmony_ci rx_work); 151762306a36Sopenharmony_ci struct sk_buff *skb; 151862306a36Sopenharmony_ci 151962306a36Sopenharmony_ci skb = local->rx_pending; 152062306a36Sopenharmony_ci if (skb == NULL) { 152162306a36Sopenharmony_ci pr_debug("No pending SKB\n"); 152262306a36Sopenharmony_ci return; 152362306a36Sopenharmony_ci } 152462306a36Sopenharmony_ci 152562306a36Sopenharmony_ci __net_timestamp(skb); 152662306a36Sopenharmony_ci 152762306a36Sopenharmony_ci nfc_llcp_send_to_raw_sock(local, skb, NFC_DIRECTION_RX); 152862306a36Sopenharmony_ci 152962306a36Sopenharmony_ci nfc_llcp_rx_skb(local, skb); 153062306a36Sopenharmony_ci 153162306a36Sopenharmony_ci schedule_work(&local->tx_work); 153262306a36Sopenharmony_ci kfree_skb(local->rx_pending); 153362306a36Sopenharmony_ci local->rx_pending = NULL; 153462306a36Sopenharmony_ci} 153562306a36Sopenharmony_ci 153662306a36Sopenharmony_cistatic void __nfc_llcp_recv(struct nfc_llcp_local *local, struct sk_buff *skb) 153762306a36Sopenharmony_ci{ 153862306a36Sopenharmony_ci local->rx_pending = skb; 153962306a36Sopenharmony_ci del_timer(&local->link_timer); 154062306a36Sopenharmony_ci schedule_work(&local->rx_work); 154162306a36Sopenharmony_ci} 154262306a36Sopenharmony_ci 154362306a36Sopenharmony_civoid nfc_llcp_recv(void *data, struct sk_buff *skb, int err) 154462306a36Sopenharmony_ci{ 154562306a36Sopenharmony_ci struct nfc_llcp_local *local = (struct nfc_llcp_local *) data; 154662306a36Sopenharmony_ci 154762306a36Sopenharmony_ci if (err < 0) { 154862306a36Sopenharmony_ci pr_err("LLCP PDU receive err %d\n", err); 154962306a36Sopenharmony_ci return; 155062306a36Sopenharmony_ci } 155162306a36Sopenharmony_ci 155262306a36Sopenharmony_ci __nfc_llcp_recv(local, skb); 155362306a36Sopenharmony_ci} 155462306a36Sopenharmony_ci 155562306a36Sopenharmony_ciint nfc_llcp_data_received(struct nfc_dev *dev, struct sk_buff *skb) 155662306a36Sopenharmony_ci{ 155762306a36Sopenharmony_ci struct nfc_llcp_local *local; 155862306a36Sopenharmony_ci 155962306a36Sopenharmony_ci local = nfc_llcp_find_local(dev); 156062306a36Sopenharmony_ci if (local == NULL) { 156162306a36Sopenharmony_ci kfree_skb(skb); 156262306a36Sopenharmony_ci return -ENODEV; 156362306a36Sopenharmony_ci } 156462306a36Sopenharmony_ci 156562306a36Sopenharmony_ci __nfc_llcp_recv(local, skb); 156662306a36Sopenharmony_ci 156762306a36Sopenharmony_ci nfc_llcp_local_put(local); 156862306a36Sopenharmony_ci 156962306a36Sopenharmony_ci return 0; 157062306a36Sopenharmony_ci} 157162306a36Sopenharmony_ci 157262306a36Sopenharmony_civoid nfc_llcp_mac_is_down(struct nfc_dev *dev) 157362306a36Sopenharmony_ci{ 157462306a36Sopenharmony_ci struct nfc_llcp_local *local; 157562306a36Sopenharmony_ci 157662306a36Sopenharmony_ci local = nfc_llcp_find_local(dev); 157762306a36Sopenharmony_ci if (local == NULL) 157862306a36Sopenharmony_ci return; 157962306a36Sopenharmony_ci 158062306a36Sopenharmony_ci local->remote_miu = LLCP_DEFAULT_MIU; 158162306a36Sopenharmony_ci local->remote_lto = LLCP_DEFAULT_LTO; 158262306a36Sopenharmony_ci 158362306a36Sopenharmony_ci /* Close and purge all existing sockets */ 158462306a36Sopenharmony_ci nfc_llcp_socket_release(local, true, 0); 158562306a36Sopenharmony_ci 158662306a36Sopenharmony_ci nfc_llcp_local_put(local); 158762306a36Sopenharmony_ci} 158862306a36Sopenharmony_ci 158962306a36Sopenharmony_civoid nfc_llcp_mac_is_up(struct nfc_dev *dev, u32 target_idx, 159062306a36Sopenharmony_ci u8 comm_mode, u8 rf_mode) 159162306a36Sopenharmony_ci{ 159262306a36Sopenharmony_ci struct nfc_llcp_local *local; 159362306a36Sopenharmony_ci 159462306a36Sopenharmony_ci pr_debug("rf mode %d\n", rf_mode); 159562306a36Sopenharmony_ci 159662306a36Sopenharmony_ci local = nfc_llcp_find_local(dev); 159762306a36Sopenharmony_ci if (local == NULL) 159862306a36Sopenharmony_ci return; 159962306a36Sopenharmony_ci 160062306a36Sopenharmony_ci local->target_idx = target_idx; 160162306a36Sopenharmony_ci local->comm_mode = comm_mode; 160262306a36Sopenharmony_ci local->rf_mode = rf_mode; 160362306a36Sopenharmony_ci 160462306a36Sopenharmony_ci if (rf_mode == NFC_RF_INITIATOR) { 160562306a36Sopenharmony_ci pr_debug("Queueing Tx work\n"); 160662306a36Sopenharmony_ci 160762306a36Sopenharmony_ci schedule_work(&local->tx_work); 160862306a36Sopenharmony_ci } else { 160962306a36Sopenharmony_ci mod_timer(&local->link_timer, 161062306a36Sopenharmony_ci jiffies + msecs_to_jiffies(local->remote_lto)); 161162306a36Sopenharmony_ci } 161262306a36Sopenharmony_ci 161362306a36Sopenharmony_ci nfc_llcp_local_put(local); 161462306a36Sopenharmony_ci} 161562306a36Sopenharmony_ci 161662306a36Sopenharmony_ciint nfc_llcp_register_device(struct nfc_dev *ndev) 161762306a36Sopenharmony_ci{ 161862306a36Sopenharmony_ci struct nfc_llcp_local *local; 161962306a36Sopenharmony_ci 162062306a36Sopenharmony_ci local = kzalloc(sizeof(struct nfc_llcp_local), GFP_KERNEL); 162162306a36Sopenharmony_ci if (local == NULL) 162262306a36Sopenharmony_ci return -ENOMEM; 162362306a36Sopenharmony_ci 162462306a36Sopenharmony_ci /* As we are going to initialize local's refcount, we need to get the 162562306a36Sopenharmony_ci * nfc_dev to avoid UAF, otherwise there is no point in continuing. 162662306a36Sopenharmony_ci * See nfc_llcp_local_get(). 162762306a36Sopenharmony_ci */ 162862306a36Sopenharmony_ci local->dev = nfc_get_device(ndev->idx); 162962306a36Sopenharmony_ci if (!local->dev) { 163062306a36Sopenharmony_ci kfree(local); 163162306a36Sopenharmony_ci return -ENODEV; 163262306a36Sopenharmony_ci } 163362306a36Sopenharmony_ci 163462306a36Sopenharmony_ci INIT_LIST_HEAD(&local->list); 163562306a36Sopenharmony_ci kref_init(&local->ref); 163662306a36Sopenharmony_ci mutex_init(&local->sdp_lock); 163762306a36Sopenharmony_ci timer_setup(&local->link_timer, nfc_llcp_symm_timer, 0); 163862306a36Sopenharmony_ci 163962306a36Sopenharmony_ci skb_queue_head_init(&local->tx_queue); 164062306a36Sopenharmony_ci INIT_WORK(&local->tx_work, nfc_llcp_tx_work); 164162306a36Sopenharmony_ci 164262306a36Sopenharmony_ci local->rx_pending = NULL; 164362306a36Sopenharmony_ci INIT_WORK(&local->rx_work, nfc_llcp_rx_work); 164462306a36Sopenharmony_ci 164562306a36Sopenharmony_ci INIT_WORK(&local->timeout_work, nfc_llcp_timeout_work); 164662306a36Sopenharmony_ci 164762306a36Sopenharmony_ci rwlock_init(&local->sockets.lock); 164862306a36Sopenharmony_ci rwlock_init(&local->connecting_sockets.lock); 164962306a36Sopenharmony_ci rwlock_init(&local->raw_sockets.lock); 165062306a36Sopenharmony_ci 165162306a36Sopenharmony_ci local->lto = 150; /* 1500 ms */ 165262306a36Sopenharmony_ci local->rw = LLCP_MAX_RW; 165362306a36Sopenharmony_ci local->miux = cpu_to_be16(LLCP_MAX_MIUX); 165462306a36Sopenharmony_ci local->local_wks = 0x1; /* LLC Link Management */ 165562306a36Sopenharmony_ci 165662306a36Sopenharmony_ci nfc_llcp_build_gb(local); 165762306a36Sopenharmony_ci 165862306a36Sopenharmony_ci local->remote_miu = LLCP_DEFAULT_MIU; 165962306a36Sopenharmony_ci local->remote_lto = LLCP_DEFAULT_LTO; 166062306a36Sopenharmony_ci 166162306a36Sopenharmony_ci mutex_init(&local->sdreq_lock); 166262306a36Sopenharmony_ci INIT_HLIST_HEAD(&local->pending_sdreqs); 166362306a36Sopenharmony_ci timer_setup(&local->sdreq_timer, nfc_llcp_sdreq_timer, 0); 166462306a36Sopenharmony_ci INIT_WORK(&local->sdreq_timeout_work, nfc_llcp_sdreq_timeout_work); 166562306a36Sopenharmony_ci 166662306a36Sopenharmony_ci spin_lock(&llcp_devices_lock); 166762306a36Sopenharmony_ci list_add(&local->list, &llcp_devices); 166862306a36Sopenharmony_ci spin_unlock(&llcp_devices_lock); 166962306a36Sopenharmony_ci 167062306a36Sopenharmony_ci return 0; 167162306a36Sopenharmony_ci} 167262306a36Sopenharmony_ci 167362306a36Sopenharmony_civoid nfc_llcp_unregister_device(struct nfc_dev *dev) 167462306a36Sopenharmony_ci{ 167562306a36Sopenharmony_ci struct nfc_llcp_local *local = nfc_llcp_remove_local(dev); 167662306a36Sopenharmony_ci 167762306a36Sopenharmony_ci if (local == NULL) { 167862306a36Sopenharmony_ci pr_debug("No such device\n"); 167962306a36Sopenharmony_ci return; 168062306a36Sopenharmony_ci } 168162306a36Sopenharmony_ci 168262306a36Sopenharmony_ci local_cleanup(local); 168362306a36Sopenharmony_ci 168462306a36Sopenharmony_ci nfc_llcp_local_put(local); 168562306a36Sopenharmony_ci} 168662306a36Sopenharmony_ci 168762306a36Sopenharmony_ciint __init nfc_llcp_init(void) 168862306a36Sopenharmony_ci{ 168962306a36Sopenharmony_ci return nfc_llcp_sock_init(); 169062306a36Sopenharmony_ci} 169162306a36Sopenharmony_ci 169262306a36Sopenharmony_civoid nfc_llcp_exit(void) 169362306a36Sopenharmony_ci{ 169462306a36Sopenharmony_ci nfc_llcp_sock_exit(); 169562306a36Sopenharmony_ci} 1696