2 BlueZ - Bluetooth protocol stack for Linux
3 Copyright (c) 2000-2001, 2010, Code Aurora Forum. All rights reserved.
5 Written 2000,2001 by Maxim Krasnyansky <maxk@qualcomm.com>
7 This program is free software; you can redistribute it and/or modify
8 it under the terms of the GNU General Public License version 2 as
9 published by the Free Software Foundation;
11 THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS
12 OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
13 FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT OF THIRD PARTY RIGHTS.
14 IN NO EVENT SHALL THE COPYRIGHT HOLDER(S) AND AUTHOR(S) BE LIABLE FOR ANY
15 CLAIM, OR ANY SPECIAL INDIRECT OR CONSEQUENTIAL DAMAGES, OR ANY DAMAGES
16 WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
17 ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
18 OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
20 ALL LIABILITY, INCLUDING LIABILITY FOR INFRINGEMENT OF ANY PATENTS,
21 COPYRIGHTS, TRADEMARKS OR OTHER RIGHTS, RELATING TO USE OF THIS
22 SOFTWARE IS DISCLAIMED.
25 /* Bluetooth HCI event handling. */
27 #include <linux/export.h>
28 #include <asm/unaligned.h>
30 #include <net/bluetooth/bluetooth.h>
31 #include <net/bluetooth/hci_core.h>
33 /* Handle HCI Event packets */
35 static void hci_cc_inquiry_cancel(struct hci_dev *hdev, struct sk_buff *skb)
37 __u8 status = *((__u8 *) skb->data);
39 BT_DBG("%s status 0x%2.2x", hdev->name, status);
43 mgmt_stop_discovery_failed(hdev, status);
48 clear_bit(HCI_INQUIRY, &hdev->flags);
51 hci_discovery_set_state(hdev, DISCOVERY_STOPPED);
54 hci_req_complete(hdev, HCI_OP_INQUIRY_CANCEL, status);
56 hci_conn_check_pending(hdev);
59 static void hci_cc_periodic_inq(struct hci_dev *hdev, struct sk_buff *skb)
61 __u8 status = *((__u8 *) skb->data);
63 BT_DBG("%s status 0x%2.2x", hdev->name, status);
68 set_bit(HCI_PERIODIC_INQ, &hdev->dev_flags);
71 static void hci_cc_exit_periodic_inq(struct hci_dev *hdev, struct sk_buff *skb)
73 __u8 status = *((__u8 *) skb->data);
75 BT_DBG("%s status 0x%2.2x", hdev->name, status);
80 clear_bit(HCI_PERIODIC_INQ, &hdev->dev_flags);
82 hci_conn_check_pending(hdev);
85 static void hci_cc_remote_name_req_cancel(struct hci_dev *hdev,
88 BT_DBG("%s", hdev->name);
91 static void hci_cc_role_discovery(struct hci_dev *hdev, struct sk_buff *skb)
93 struct hci_rp_role_discovery *rp = (void *) skb->data;
94 struct hci_conn *conn;
96 BT_DBG("%s status 0x%2.2x", hdev->name, rp->status);
103 conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(rp->handle));
106 conn->link_mode &= ~HCI_LM_MASTER;
108 conn->link_mode |= HCI_LM_MASTER;
111 hci_dev_unlock(hdev);
114 static void hci_cc_read_link_policy(struct hci_dev *hdev, struct sk_buff *skb)
116 struct hci_rp_read_link_policy *rp = (void *) skb->data;
117 struct hci_conn *conn;
119 BT_DBG("%s status 0x%2.2x", hdev->name, rp->status);
126 conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(rp->handle));
128 conn->link_policy = __le16_to_cpu(rp->policy);
130 hci_dev_unlock(hdev);
133 static void hci_cc_write_link_policy(struct hci_dev *hdev, struct sk_buff *skb)
135 struct hci_rp_write_link_policy *rp = (void *) skb->data;
136 struct hci_conn *conn;
139 BT_DBG("%s status 0x%2.2x", hdev->name, rp->status);
144 sent = hci_sent_cmd_data(hdev, HCI_OP_WRITE_LINK_POLICY);
150 conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(rp->handle));
152 conn->link_policy = get_unaligned_le16(sent + 2);
154 hci_dev_unlock(hdev);
157 static void hci_cc_read_def_link_policy(struct hci_dev *hdev,
160 struct hci_rp_read_def_link_policy *rp = (void *) skb->data;
162 BT_DBG("%s status 0x%2.2x", hdev->name, rp->status);
167 hdev->link_policy = __le16_to_cpu(rp->policy);
170 static void hci_cc_write_def_link_policy(struct hci_dev *hdev,
173 __u8 status = *((__u8 *) skb->data);
176 BT_DBG("%s status 0x%2.2x", hdev->name, status);
178 sent = hci_sent_cmd_data(hdev, HCI_OP_WRITE_DEF_LINK_POLICY);
183 hdev->link_policy = get_unaligned_le16(sent);
185 hci_req_complete(hdev, HCI_OP_WRITE_DEF_LINK_POLICY, status);
188 static void hci_cc_reset(struct hci_dev *hdev, struct sk_buff *skb)
190 __u8 status = *((__u8 *) skb->data);
192 BT_DBG("%s status 0x%2.2x", hdev->name, status);
194 clear_bit(HCI_RESET, &hdev->flags);
196 hci_req_complete(hdev, HCI_OP_RESET, status);
198 /* Reset all non-persistent flags */
199 hdev->dev_flags &= ~(BIT(HCI_LE_SCAN) | BIT(HCI_PENDING_CLASS) |
200 BIT(HCI_PERIODIC_INQ));
202 hdev->discovery.state = DISCOVERY_STOPPED;
205 static void hci_cc_write_local_name(struct hci_dev *hdev, struct sk_buff *skb)
207 __u8 status = *((__u8 *) skb->data);
210 BT_DBG("%s status 0x%2.2x", hdev->name, status);
212 sent = hci_sent_cmd_data(hdev, HCI_OP_WRITE_LOCAL_NAME);
218 if (test_bit(HCI_MGMT, &hdev->dev_flags))
219 mgmt_set_local_name_complete(hdev, sent, status);
221 memcpy(hdev->dev_name, sent, HCI_MAX_NAME_LENGTH);
223 hci_dev_unlock(hdev);
225 hci_req_complete(hdev, HCI_OP_WRITE_LOCAL_NAME, status);
228 static void hci_cc_read_local_name(struct hci_dev *hdev, struct sk_buff *skb)
230 struct hci_rp_read_local_name *rp = (void *) skb->data;
232 BT_DBG("%s status 0x%2.2x", hdev->name, rp->status);
237 if (test_bit(HCI_SETUP, &hdev->dev_flags))
238 memcpy(hdev->dev_name, rp->name, HCI_MAX_NAME_LENGTH);
241 static void hci_cc_write_auth_enable(struct hci_dev *hdev, struct sk_buff *skb)
243 __u8 status = *((__u8 *) skb->data);
246 BT_DBG("%s status 0x%2.2x", hdev->name, status);
248 sent = hci_sent_cmd_data(hdev, HCI_OP_WRITE_AUTH_ENABLE);
253 __u8 param = *((__u8 *) sent);
255 if (param == AUTH_ENABLED)
256 set_bit(HCI_AUTH, &hdev->flags);
258 clear_bit(HCI_AUTH, &hdev->flags);
261 if (test_bit(HCI_MGMT, &hdev->dev_flags))
262 mgmt_auth_enable_complete(hdev, status);
264 hci_req_complete(hdev, HCI_OP_WRITE_AUTH_ENABLE, status);
267 static void hci_cc_write_encrypt_mode(struct hci_dev *hdev, struct sk_buff *skb)
269 __u8 status = *((__u8 *) skb->data);
272 BT_DBG("%s status 0x%2.2x", hdev->name, status);
274 sent = hci_sent_cmd_data(hdev, HCI_OP_WRITE_ENCRYPT_MODE);
279 __u8 param = *((__u8 *) sent);
282 set_bit(HCI_ENCRYPT, &hdev->flags);
284 clear_bit(HCI_ENCRYPT, &hdev->flags);
287 hci_req_complete(hdev, HCI_OP_WRITE_ENCRYPT_MODE, status);
290 static void hci_cc_write_scan_enable(struct hci_dev *hdev, struct sk_buff *skb)
292 __u8 param, status = *((__u8 *) skb->data);
293 int old_pscan, old_iscan;
296 BT_DBG("%s status 0x%2.2x", hdev->name, status);
298 sent = hci_sent_cmd_data(hdev, HCI_OP_WRITE_SCAN_ENABLE);
302 param = *((__u8 *) sent);
307 mgmt_write_scan_failed(hdev, param, status);
308 hdev->discov_timeout = 0;
312 old_pscan = test_and_clear_bit(HCI_PSCAN, &hdev->flags);
313 old_iscan = test_and_clear_bit(HCI_ISCAN, &hdev->flags);
315 if (param & SCAN_INQUIRY) {
316 set_bit(HCI_ISCAN, &hdev->flags);
318 mgmt_discoverable(hdev, 1);
319 if (hdev->discov_timeout > 0) {
320 int to = msecs_to_jiffies(hdev->discov_timeout * 1000);
321 queue_delayed_work(hdev->workqueue, &hdev->discov_off,
324 } else if (old_iscan)
325 mgmt_discoverable(hdev, 0);
327 if (param & SCAN_PAGE) {
328 set_bit(HCI_PSCAN, &hdev->flags);
330 mgmt_connectable(hdev, 1);
331 } else if (old_pscan)
332 mgmt_connectable(hdev, 0);
335 hci_dev_unlock(hdev);
336 hci_req_complete(hdev, HCI_OP_WRITE_SCAN_ENABLE, status);
339 static void hci_cc_read_class_of_dev(struct hci_dev *hdev, struct sk_buff *skb)
341 struct hci_rp_read_class_of_dev *rp = (void *) skb->data;
343 BT_DBG("%s status 0x%2.2x", hdev->name, rp->status);
348 memcpy(hdev->dev_class, rp->dev_class, 3);
350 BT_DBG("%s class 0x%.2x%.2x%.2x", hdev->name,
351 hdev->dev_class[2], hdev->dev_class[1], hdev->dev_class[0]);
354 static void hci_cc_write_class_of_dev(struct hci_dev *hdev, struct sk_buff *skb)
356 __u8 status = *((__u8 *) skb->data);
359 BT_DBG("%s status 0x%2.2x", hdev->name, status);
361 sent = hci_sent_cmd_data(hdev, HCI_OP_WRITE_CLASS_OF_DEV);
368 memcpy(hdev->dev_class, sent, 3);
370 if (test_bit(HCI_MGMT, &hdev->dev_flags))
371 mgmt_set_class_of_dev_complete(hdev, sent, status);
373 hci_dev_unlock(hdev);
376 static void hci_cc_read_voice_setting(struct hci_dev *hdev, struct sk_buff *skb)
378 struct hci_rp_read_voice_setting *rp = (void *) skb->data;
381 BT_DBG("%s status 0x%2.2x", hdev->name, rp->status);
386 setting = __le16_to_cpu(rp->voice_setting);
388 if (hdev->voice_setting == setting)
391 hdev->voice_setting = setting;
393 BT_DBG("%s voice setting 0x%4.4x", hdev->name, setting);
396 hdev->notify(hdev, HCI_NOTIFY_VOICE_SETTING);
399 static void hci_cc_write_voice_setting(struct hci_dev *hdev,
402 __u8 status = *((__u8 *) skb->data);
406 BT_DBG("%s status 0x%2.2x", hdev->name, status);
411 sent = hci_sent_cmd_data(hdev, HCI_OP_WRITE_VOICE_SETTING);
415 setting = get_unaligned_le16(sent);
417 if (hdev->voice_setting == setting)
420 hdev->voice_setting = setting;
422 BT_DBG("%s voice setting 0x%4.4x", hdev->name, setting);
425 hdev->notify(hdev, HCI_NOTIFY_VOICE_SETTING);
428 static void hci_cc_host_buffer_size(struct hci_dev *hdev, struct sk_buff *skb)
430 __u8 status = *((__u8 *) skb->data);
432 BT_DBG("%s status 0x%2.2x", hdev->name, status);
434 hci_req_complete(hdev, HCI_OP_HOST_BUFFER_SIZE, status);
437 static void hci_cc_write_ssp_mode(struct hci_dev *hdev, struct sk_buff *skb)
439 __u8 status = *((__u8 *) skb->data);
442 BT_DBG("%s status 0x%2.2x", hdev->name, status);
444 sent = hci_sent_cmd_data(hdev, HCI_OP_WRITE_SSP_MODE);
448 if (test_bit(HCI_MGMT, &hdev->dev_flags))
449 mgmt_ssp_enable_complete(hdev, *((u8 *) sent), status);
452 set_bit(HCI_SSP_ENABLED, &hdev->dev_flags);
454 clear_bit(HCI_SSP_ENABLED, &hdev->dev_flags);
458 static u8 hci_get_inquiry_mode(struct hci_dev *hdev)
460 if (hdev->features[6] & LMP_EXT_INQ)
463 if (hdev->features[3] & LMP_RSSI_INQ)
466 if (hdev->manufacturer == 11 && hdev->hci_rev == 0x00 &&
467 hdev->lmp_subver == 0x0757)
470 if (hdev->manufacturer == 15) {
471 if (hdev->hci_rev == 0x03 && hdev->lmp_subver == 0x6963)
473 if (hdev->hci_rev == 0x09 && hdev->lmp_subver == 0x6963)
475 if (hdev->hci_rev == 0x00 && hdev->lmp_subver == 0x6965)
479 if (hdev->manufacturer == 31 && hdev->hci_rev == 0x2005 &&
480 hdev->lmp_subver == 0x1805)
486 static void hci_setup_inquiry_mode(struct hci_dev *hdev)
490 mode = hci_get_inquiry_mode(hdev);
492 hci_send_cmd(hdev, HCI_OP_WRITE_INQUIRY_MODE, 1, &mode);
495 static void hci_setup_event_mask(struct hci_dev *hdev)
497 /* The second byte is 0xff instead of 0x9f (two reserved bits
498 * disabled) since a Broadcom 1.2 dongle doesn't respond to the
499 * command otherwise */
500 u8 events[8] = { 0xff, 0xff, 0xfb, 0xff, 0x00, 0x00, 0x00, 0x00 };
502 /* CSR 1.1 dongles does not accept any bitfield so don't try to set
503 * any event mask for pre 1.2 devices */
504 if (hdev->hci_ver < BLUETOOTH_VER_1_2)
507 events[4] |= 0x01; /* Flow Specification Complete */
508 events[4] |= 0x02; /* Inquiry Result with RSSI */
509 events[4] |= 0x04; /* Read Remote Extended Features Complete */
510 events[5] |= 0x08; /* Synchronous Connection Complete */
511 events[5] |= 0x10; /* Synchronous Connection Changed */
513 if (hdev->features[3] & LMP_RSSI_INQ)
514 events[4] |= 0x02; /* Inquiry Result with RSSI */
516 if (hdev->features[5] & LMP_SNIFF_SUBR)
517 events[5] |= 0x20; /* Sniff Subrating */
519 if (hdev->features[5] & LMP_PAUSE_ENC)
520 events[5] |= 0x80; /* Encryption Key Refresh Complete */
522 if (hdev->features[6] & LMP_EXT_INQ)
523 events[5] |= 0x40; /* Extended Inquiry Result */
525 if (hdev->features[6] & LMP_NO_FLUSH)
526 events[7] |= 0x01; /* Enhanced Flush Complete */
528 if (hdev->features[7] & LMP_LSTO)
529 events[6] |= 0x80; /* Link Supervision Timeout Changed */
531 if (hdev->features[6] & LMP_SIMPLE_PAIR) {
532 events[6] |= 0x01; /* IO Capability Request */
533 events[6] |= 0x02; /* IO Capability Response */
534 events[6] |= 0x04; /* User Confirmation Request */
535 events[6] |= 0x08; /* User Passkey Request */
536 events[6] |= 0x10; /* Remote OOB Data Request */
537 events[6] |= 0x20; /* Simple Pairing Complete */
538 events[7] |= 0x04; /* User Passkey Notification */
539 events[7] |= 0x08; /* Keypress Notification */
540 events[7] |= 0x10; /* Remote Host Supported
541 * Features Notification */
544 if (hdev->features[4] & LMP_LE)
545 events[7] |= 0x20; /* LE Meta-Event */
547 hci_send_cmd(hdev, HCI_OP_SET_EVENT_MASK, sizeof(events), events);
550 static void hci_setup(struct hci_dev *hdev)
552 if (hdev->dev_type != HCI_BREDR)
555 hci_setup_event_mask(hdev);
557 if (hdev->hci_ver > BLUETOOTH_VER_1_1)
558 hci_send_cmd(hdev, HCI_OP_READ_LOCAL_COMMANDS, 0, NULL);
560 if (lmp_ssp_capable(hdev)) {
561 if (test_bit(HCI_SSP_ENABLED, &hdev->dev_flags)) {
563 hci_send_cmd(hdev, HCI_OP_WRITE_SSP_MODE,
564 sizeof(mode), &mode);
566 struct hci_cp_write_eir cp;
568 memset(hdev->eir, 0, sizeof(hdev->eir));
569 memset(&cp, 0, sizeof(cp));
571 hci_send_cmd(hdev, HCI_OP_WRITE_EIR, sizeof(cp), &cp);
575 if (hdev->features[3] & LMP_RSSI_INQ)
576 hci_setup_inquiry_mode(hdev);
578 if (hdev->features[7] & LMP_INQ_TX_PWR)
579 hci_send_cmd(hdev, HCI_OP_READ_INQ_RSP_TX_POWER, 0, NULL);
581 if (hdev->features[7] & LMP_EXTFEATURES) {
582 struct hci_cp_read_local_ext_features cp;
585 hci_send_cmd(hdev, HCI_OP_READ_LOCAL_EXT_FEATURES, sizeof(cp),
589 if (test_bit(HCI_LINK_SECURITY, &hdev->dev_flags)) {
591 hci_send_cmd(hdev, HCI_OP_WRITE_AUTH_ENABLE, sizeof(enable),
596 static void hci_cc_read_local_version(struct hci_dev *hdev, struct sk_buff *skb)
598 struct hci_rp_read_local_version *rp = (void *) skb->data;
600 BT_DBG("%s status 0x%2.2x", hdev->name, rp->status);
605 hdev->hci_ver = rp->hci_ver;
606 hdev->hci_rev = __le16_to_cpu(rp->hci_rev);
607 hdev->lmp_ver = rp->lmp_ver;
608 hdev->manufacturer = __le16_to_cpu(rp->manufacturer);
609 hdev->lmp_subver = __le16_to_cpu(rp->lmp_subver);
611 BT_DBG("%s manufacturer 0x%4.4x hci ver %d:%d", hdev->name,
612 hdev->manufacturer, hdev->hci_ver, hdev->hci_rev);
614 if (test_bit(HCI_INIT, &hdev->flags))
618 hci_req_complete(hdev, HCI_OP_READ_LOCAL_VERSION, rp->status);
621 static void hci_setup_link_policy(struct hci_dev *hdev)
623 struct hci_cp_write_def_link_policy cp;
626 if (hdev->features[0] & LMP_RSWITCH)
627 link_policy |= HCI_LP_RSWITCH;
628 if (hdev->features[0] & LMP_HOLD)
629 link_policy |= HCI_LP_HOLD;
630 if (hdev->features[0] & LMP_SNIFF)
631 link_policy |= HCI_LP_SNIFF;
632 if (hdev->features[1] & LMP_PARK)
633 link_policy |= HCI_LP_PARK;
635 cp.policy = cpu_to_le16(link_policy);
636 hci_send_cmd(hdev, HCI_OP_WRITE_DEF_LINK_POLICY, sizeof(cp), &cp);
639 static void hci_cc_read_local_commands(struct hci_dev *hdev,
642 struct hci_rp_read_local_commands *rp = (void *) skb->data;
644 BT_DBG("%s status 0x%2.2x", hdev->name, rp->status);
649 memcpy(hdev->commands, rp->commands, sizeof(hdev->commands));
651 if (test_bit(HCI_INIT, &hdev->flags) && (hdev->commands[5] & 0x10))
652 hci_setup_link_policy(hdev);
655 hci_req_complete(hdev, HCI_OP_READ_LOCAL_COMMANDS, rp->status);
658 static void hci_cc_read_local_features(struct hci_dev *hdev,
661 struct hci_rp_read_local_features *rp = (void *) skb->data;
663 BT_DBG("%s status 0x%2.2x", hdev->name, rp->status);
668 memcpy(hdev->features, rp->features, 8);
670 /* Adjust default settings according to features
671 * supported by device. */
673 if (hdev->features[0] & LMP_3SLOT)
674 hdev->pkt_type |= (HCI_DM3 | HCI_DH3);
676 if (hdev->features[0] & LMP_5SLOT)
677 hdev->pkt_type |= (HCI_DM5 | HCI_DH5);
679 if (hdev->features[1] & LMP_HV2) {
680 hdev->pkt_type |= (HCI_HV2);
681 hdev->esco_type |= (ESCO_HV2);
684 if (hdev->features[1] & LMP_HV3) {
685 hdev->pkt_type |= (HCI_HV3);
686 hdev->esco_type |= (ESCO_HV3);
689 if (hdev->features[3] & LMP_ESCO)
690 hdev->esco_type |= (ESCO_EV3);
692 if (hdev->features[4] & LMP_EV4)
693 hdev->esco_type |= (ESCO_EV4);
695 if (hdev->features[4] & LMP_EV5)
696 hdev->esco_type |= (ESCO_EV5);
698 if (hdev->features[5] & LMP_EDR_ESCO_2M)
699 hdev->esco_type |= (ESCO_2EV3);
701 if (hdev->features[5] & LMP_EDR_ESCO_3M)
702 hdev->esco_type |= (ESCO_3EV3);
704 if (hdev->features[5] & LMP_EDR_3S_ESCO)
705 hdev->esco_type |= (ESCO_2EV5 | ESCO_3EV5);
707 BT_DBG("%s features 0x%.2x%.2x%.2x%.2x%.2x%.2x%.2x%.2x", hdev->name,
708 hdev->features[0], hdev->features[1],
709 hdev->features[2], hdev->features[3],
710 hdev->features[4], hdev->features[5],
711 hdev->features[6], hdev->features[7]);
714 static void hci_set_le_support(struct hci_dev *hdev)
716 struct hci_cp_write_le_host_supported cp;
718 memset(&cp, 0, sizeof(cp));
720 if (test_bit(HCI_LE_ENABLED, &hdev->dev_flags)) {
722 cp.simul = !!(hdev->features[6] & LMP_SIMUL_LE_BR);
725 if (cp.le != !!(hdev->host_features[0] & LMP_HOST_LE))
726 hci_send_cmd(hdev, HCI_OP_WRITE_LE_HOST_SUPPORTED, sizeof(cp),
730 static void hci_cc_read_local_ext_features(struct hci_dev *hdev,
733 struct hci_rp_read_local_ext_features *rp = (void *) skb->data;
735 BT_DBG("%s status 0x%2.2x", hdev->name, rp->status);
742 memcpy(hdev->features, rp->features, 8);
745 memcpy(hdev->host_features, rp->features, 8);
749 if (test_bit(HCI_INIT, &hdev->flags) && hdev->features[4] & LMP_LE)
750 hci_set_le_support(hdev);
753 hci_req_complete(hdev, HCI_OP_READ_LOCAL_EXT_FEATURES, rp->status);
756 static void hci_cc_read_flow_control_mode(struct hci_dev *hdev,
759 struct hci_rp_read_flow_control_mode *rp = (void *) skb->data;
761 BT_DBG("%s status 0x%2.2x", hdev->name, rp->status);
766 hdev->flow_ctl_mode = rp->mode;
768 hci_req_complete(hdev, HCI_OP_READ_FLOW_CONTROL_MODE, rp->status);
771 static void hci_cc_read_buffer_size(struct hci_dev *hdev, struct sk_buff *skb)
773 struct hci_rp_read_buffer_size *rp = (void *) skb->data;
775 BT_DBG("%s status 0x%2.2x", hdev->name, rp->status);
780 hdev->acl_mtu = __le16_to_cpu(rp->acl_mtu);
781 hdev->sco_mtu = rp->sco_mtu;
782 hdev->acl_pkts = __le16_to_cpu(rp->acl_max_pkt);
783 hdev->sco_pkts = __le16_to_cpu(rp->sco_max_pkt);
785 if (test_bit(HCI_QUIRK_FIXUP_BUFFER_SIZE, &hdev->quirks)) {
790 hdev->acl_cnt = hdev->acl_pkts;
791 hdev->sco_cnt = hdev->sco_pkts;
793 BT_DBG("%s acl mtu %d:%d sco mtu %d:%d", hdev->name, hdev->acl_mtu,
794 hdev->acl_pkts, hdev->sco_mtu, hdev->sco_pkts);
797 static void hci_cc_read_bd_addr(struct hci_dev *hdev, struct sk_buff *skb)
799 struct hci_rp_read_bd_addr *rp = (void *) skb->data;
801 BT_DBG("%s status 0x%2.2x", hdev->name, rp->status);
804 bacpy(&hdev->bdaddr, &rp->bdaddr);
806 hci_req_complete(hdev, HCI_OP_READ_BD_ADDR, rp->status);
809 static void hci_cc_read_data_block_size(struct hci_dev *hdev,
812 struct hci_rp_read_data_block_size *rp = (void *) skb->data;
814 BT_DBG("%s status 0x%2.2x", hdev->name, rp->status);
819 hdev->block_mtu = __le16_to_cpu(rp->max_acl_len);
820 hdev->block_len = __le16_to_cpu(rp->block_len);
821 hdev->num_blocks = __le16_to_cpu(rp->num_blocks);
823 hdev->block_cnt = hdev->num_blocks;
825 BT_DBG("%s blk mtu %d cnt %d len %d", hdev->name, hdev->block_mtu,
826 hdev->block_cnt, hdev->block_len);
828 hci_req_complete(hdev, HCI_OP_READ_DATA_BLOCK_SIZE, rp->status);
831 static void hci_cc_write_ca_timeout(struct hci_dev *hdev, struct sk_buff *skb)
833 __u8 status = *((__u8 *) skb->data);
835 BT_DBG("%s status 0x%2.2x", hdev->name, status);
837 hci_req_complete(hdev, HCI_OP_WRITE_CA_TIMEOUT, status);
840 static void hci_cc_read_local_amp_info(struct hci_dev *hdev,
843 struct hci_rp_read_local_amp_info *rp = (void *) skb->data;
845 BT_DBG("%s status 0x%2.2x", hdev->name, rp->status);
850 hdev->amp_status = rp->amp_status;
851 hdev->amp_total_bw = __le32_to_cpu(rp->total_bw);
852 hdev->amp_max_bw = __le32_to_cpu(rp->max_bw);
853 hdev->amp_min_latency = __le32_to_cpu(rp->min_latency);
854 hdev->amp_max_pdu = __le32_to_cpu(rp->max_pdu);
855 hdev->amp_type = rp->amp_type;
856 hdev->amp_pal_cap = __le16_to_cpu(rp->pal_cap);
857 hdev->amp_assoc_size = __le16_to_cpu(rp->max_assoc_size);
858 hdev->amp_be_flush_to = __le32_to_cpu(rp->be_flush_to);
859 hdev->amp_max_flush_to = __le32_to_cpu(rp->max_flush_to);
861 hci_req_complete(hdev, HCI_OP_READ_LOCAL_AMP_INFO, rp->status);
864 static void hci_cc_delete_stored_link_key(struct hci_dev *hdev,
867 __u8 status = *((__u8 *) skb->data);
869 BT_DBG("%s status 0x%2.2x", hdev->name, status);
871 hci_req_complete(hdev, HCI_OP_DELETE_STORED_LINK_KEY, status);
874 static void hci_cc_set_event_mask(struct hci_dev *hdev, struct sk_buff *skb)
876 __u8 status = *((__u8 *) skb->data);
878 BT_DBG("%s status 0x%2.2x", hdev->name, status);
880 hci_req_complete(hdev, HCI_OP_SET_EVENT_MASK, status);
883 static void hci_cc_write_inquiry_mode(struct hci_dev *hdev,
886 __u8 status = *((__u8 *) skb->data);
888 BT_DBG("%s status 0x%2.2x", hdev->name, status);
890 hci_req_complete(hdev, HCI_OP_WRITE_INQUIRY_MODE, status);
893 static void hci_cc_read_inq_rsp_tx_power(struct hci_dev *hdev,
896 struct hci_rp_read_inq_rsp_tx_power *rp = (void *) skb->data;
898 BT_DBG("%s status 0x%2.2x", hdev->name, rp->status);
901 hdev->inq_tx_power = rp->tx_power;
903 hci_req_complete(hdev, HCI_OP_READ_INQ_RSP_TX_POWER, rp->status);
906 static void hci_cc_set_event_flt(struct hci_dev *hdev, struct sk_buff *skb)
908 __u8 status = *((__u8 *) skb->data);
910 BT_DBG("%s status 0x%2.2x", hdev->name, status);
912 hci_req_complete(hdev, HCI_OP_SET_EVENT_FLT, status);
915 static void hci_cc_pin_code_reply(struct hci_dev *hdev, struct sk_buff *skb)
917 struct hci_rp_pin_code_reply *rp = (void *) skb->data;
918 struct hci_cp_pin_code_reply *cp;
919 struct hci_conn *conn;
921 BT_DBG("%s status 0x%2.2x", hdev->name, rp->status);
925 if (test_bit(HCI_MGMT, &hdev->dev_flags))
926 mgmt_pin_code_reply_complete(hdev, &rp->bdaddr, rp->status);
931 cp = hci_sent_cmd_data(hdev, HCI_OP_PIN_CODE_REPLY);
935 conn = hci_conn_hash_lookup_ba(hdev, ACL_LINK, &cp->bdaddr);
937 conn->pin_length = cp->pin_len;
940 hci_dev_unlock(hdev);
943 static void hci_cc_pin_code_neg_reply(struct hci_dev *hdev, struct sk_buff *skb)
945 struct hci_rp_pin_code_neg_reply *rp = (void *) skb->data;
947 BT_DBG("%s status 0x%2.2x", hdev->name, rp->status);
951 if (test_bit(HCI_MGMT, &hdev->dev_flags))
952 mgmt_pin_code_neg_reply_complete(hdev, &rp->bdaddr,
955 hci_dev_unlock(hdev);
958 static void hci_cc_le_read_buffer_size(struct hci_dev *hdev,
961 struct hci_rp_le_read_buffer_size *rp = (void *) skb->data;
963 BT_DBG("%s status 0x%2.2x", hdev->name, rp->status);
968 hdev->le_mtu = __le16_to_cpu(rp->le_mtu);
969 hdev->le_pkts = rp->le_max_pkt;
971 hdev->le_cnt = hdev->le_pkts;
973 BT_DBG("%s le mtu %d:%d", hdev->name, hdev->le_mtu, hdev->le_pkts);
975 hci_req_complete(hdev, HCI_OP_LE_READ_BUFFER_SIZE, rp->status);
978 static void hci_cc_user_confirm_reply(struct hci_dev *hdev, struct sk_buff *skb)
980 struct hci_rp_user_confirm_reply *rp = (void *) skb->data;
982 BT_DBG("%s status 0x%2.2x", hdev->name, rp->status);
986 if (test_bit(HCI_MGMT, &hdev->dev_flags))
987 mgmt_user_confirm_reply_complete(hdev, &rp->bdaddr, ACL_LINK, 0,
990 hci_dev_unlock(hdev);
993 static void hci_cc_user_confirm_neg_reply(struct hci_dev *hdev,
996 struct hci_rp_user_confirm_reply *rp = (void *) skb->data;
998 BT_DBG("%s status 0x%2.2x", hdev->name, rp->status);
1002 if (test_bit(HCI_MGMT, &hdev->dev_flags))
1003 mgmt_user_confirm_neg_reply_complete(hdev, &rp->bdaddr,
1004 ACL_LINK, 0, rp->status);
1006 hci_dev_unlock(hdev);
1009 static void hci_cc_user_passkey_reply(struct hci_dev *hdev, struct sk_buff *skb)
1011 struct hci_rp_user_confirm_reply *rp = (void *) skb->data;
1013 BT_DBG("%s status 0x%2.2x", hdev->name, rp->status);
1017 if (test_bit(HCI_MGMT, &hdev->dev_flags))
1018 mgmt_user_passkey_reply_complete(hdev, &rp->bdaddr, ACL_LINK,
1021 hci_dev_unlock(hdev);
1024 static void hci_cc_user_passkey_neg_reply(struct hci_dev *hdev,
1025 struct sk_buff *skb)
1027 struct hci_rp_user_confirm_reply *rp = (void *) skb->data;
1029 BT_DBG("%s status 0x%2.2x", hdev->name, rp->status);
1033 if (test_bit(HCI_MGMT, &hdev->dev_flags))
1034 mgmt_user_passkey_neg_reply_complete(hdev, &rp->bdaddr,
1035 ACL_LINK, 0, rp->status);
1037 hci_dev_unlock(hdev);
1040 static void hci_cc_read_local_oob_data_reply(struct hci_dev *hdev,
1041 struct sk_buff *skb)
1043 struct hci_rp_read_local_oob_data *rp = (void *) skb->data;
1045 BT_DBG("%s status 0x%2.2x", hdev->name, rp->status);
1048 mgmt_read_local_oob_data_reply_complete(hdev, rp->hash,
1049 rp->randomizer, rp->status);
1050 hci_dev_unlock(hdev);
1053 static void hci_cc_le_set_scan_param(struct hci_dev *hdev, struct sk_buff *skb)
1055 __u8 status = *((__u8 *) skb->data);
1057 BT_DBG("%s status 0x%2.2x", hdev->name, status);
1059 hci_req_complete(hdev, HCI_OP_LE_SET_SCAN_PARAM, status);
1063 mgmt_start_discovery_failed(hdev, status);
1064 hci_dev_unlock(hdev);
1069 static void hci_cc_le_set_scan_enable(struct hci_dev *hdev,
1070 struct sk_buff *skb)
1072 struct hci_cp_le_set_scan_enable *cp;
1073 __u8 status = *((__u8 *) skb->data);
1075 BT_DBG("%s status 0x%2.2x", hdev->name, status);
1077 cp = hci_sent_cmd_data(hdev, HCI_OP_LE_SET_SCAN_ENABLE);
1081 switch (cp->enable) {
1082 case LE_SCANNING_ENABLED:
1083 hci_req_complete(hdev, HCI_OP_LE_SET_SCAN_ENABLE, status);
1087 mgmt_start_discovery_failed(hdev, status);
1088 hci_dev_unlock(hdev);
1092 set_bit(HCI_LE_SCAN, &hdev->dev_flags);
1095 hci_discovery_set_state(hdev, DISCOVERY_FINDING);
1096 hci_dev_unlock(hdev);
1099 case LE_SCANNING_DISABLED:
1102 mgmt_stop_discovery_failed(hdev, status);
1103 hci_dev_unlock(hdev);
1107 clear_bit(HCI_LE_SCAN, &hdev->dev_flags);
1109 if (hdev->discovery.type == DISCOV_TYPE_INTERLEAVED &&
1110 hdev->discovery.state == DISCOVERY_FINDING) {
1111 mgmt_interleaved_discovery(hdev);
1114 hci_discovery_set_state(hdev, DISCOVERY_STOPPED);
1115 hci_dev_unlock(hdev);
1121 BT_ERR("Used reserved LE_Scan_Enable param %d", cp->enable);
1126 static void hci_cc_le_ltk_reply(struct hci_dev *hdev, struct sk_buff *skb)
1128 struct hci_rp_le_ltk_reply *rp = (void *) skb->data;
1130 BT_DBG("%s status 0x%2.2x", hdev->name, rp->status);
1135 hci_req_complete(hdev, HCI_OP_LE_LTK_REPLY, rp->status);
1138 static void hci_cc_le_ltk_neg_reply(struct hci_dev *hdev, struct sk_buff *skb)
1140 struct hci_rp_le_ltk_neg_reply *rp = (void *) skb->data;
1142 BT_DBG("%s status 0x%2.2x", hdev->name, rp->status);
1147 hci_req_complete(hdev, HCI_OP_LE_LTK_NEG_REPLY, rp->status);
1150 static void hci_cc_write_le_host_supported(struct hci_dev *hdev,
1151 struct sk_buff *skb)
1153 struct hci_cp_write_le_host_supported *sent;
1154 __u8 status = *((__u8 *) skb->data);
1156 BT_DBG("%s status 0x%2.2x", hdev->name, status);
1158 sent = hci_sent_cmd_data(hdev, HCI_OP_WRITE_LE_HOST_SUPPORTED);
1164 hdev->host_features[0] |= LMP_HOST_LE;
1166 hdev->host_features[0] &= ~LMP_HOST_LE;
1169 if (test_bit(HCI_MGMT, &hdev->dev_flags) &&
1170 !test_bit(HCI_INIT, &hdev->flags))
1171 mgmt_le_enable_complete(hdev, sent->le, status);
1173 hci_req_complete(hdev, HCI_OP_WRITE_LE_HOST_SUPPORTED, status);
1176 static void hci_cs_inquiry(struct hci_dev *hdev, __u8 status)
1178 BT_DBG("%s status 0x%2.2x", hdev->name, status);
1181 hci_req_complete(hdev, HCI_OP_INQUIRY, status);
1182 hci_conn_check_pending(hdev);
1184 if (test_bit(HCI_MGMT, &hdev->dev_flags))
1185 mgmt_start_discovery_failed(hdev, status);
1186 hci_dev_unlock(hdev);
1190 set_bit(HCI_INQUIRY, &hdev->flags);
1193 hci_discovery_set_state(hdev, DISCOVERY_FINDING);
1194 hci_dev_unlock(hdev);
1197 static void hci_cs_create_conn(struct hci_dev *hdev, __u8 status)
1199 struct hci_cp_create_conn *cp;
1200 struct hci_conn *conn;
1202 BT_DBG("%s status 0x%2.2x", hdev->name, status);
1204 cp = hci_sent_cmd_data(hdev, HCI_OP_CREATE_CONN);
1210 conn = hci_conn_hash_lookup_ba(hdev, ACL_LINK, &cp->bdaddr);
1212 BT_DBG("%s bdaddr %s hcon %p", hdev->name, batostr(&cp->bdaddr), conn);
1215 if (conn && conn->state == BT_CONNECT) {
1216 if (status != 0x0c || conn->attempt > 2) {
1217 conn->state = BT_CLOSED;
1218 hci_proto_connect_cfm(conn, status);
1221 conn->state = BT_CONNECT2;
1225 conn = hci_conn_add(hdev, ACL_LINK, &cp->bdaddr);
1228 conn->link_mode |= HCI_LM_MASTER;
1230 BT_ERR("No memory for new connection");
1234 hci_dev_unlock(hdev);
1237 static void hci_cs_add_sco(struct hci_dev *hdev, __u8 status)
1239 struct hci_cp_add_sco *cp;
1240 struct hci_conn *acl, *sco;
1243 BT_DBG("%s status 0x%2.2x", hdev->name, status);
1248 cp = hci_sent_cmd_data(hdev, HCI_OP_ADD_SCO);
1252 handle = __le16_to_cpu(cp->handle);
1254 BT_DBG("%s handle 0x%4.4x", hdev->name, handle);
1258 acl = hci_conn_hash_lookup_handle(hdev, handle);
1262 sco->state = BT_CLOSED;
1264 hci_proto_connect_cfm(sco, status);
1269 hci_dev_unlock(hdev);
1272 static void hci_cs_auth_requested(struct hci_dev *hdev, __u8 status)
1274 struct hci_cp_auth_requested *cp;
1275 struct hci_conn *conn;
1277 BT_DBG("%s status 0x%2.2x", hdev->name, status);
1282 cp = hci_sent_cmd_data(hdev, HCI_OP_AUTH_REQUESTED);
1288 conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(cp->handle));
1290 if (conn->state == BT_CONFIG) {
1291 hci_proto_connect_cfm(conn, status);
1296 hci_dev_unlock(hdev);
1299 static void hci_cs_set_conn_encrypt(struct hci_dev *hdev, __u8 status)
1301 struct hci_cp_set_conn_encrypt *cp;
1302 struct hci_conn *conn;
1304 BT_DBG("%s status 0x%2.2x", hdev->name, status);
1309 cp = hci_sent_cmd_data(hdev, HCI_OP_SET_CONN_ENCRYPT);
1315 conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(cp->handle));
1317 if (conn->state == BT_CONFIG) {
1318 hci_proto_connect_cfm(conn, status);
1323 hci_dev_unlock(hdev);
1326 static int hci_outgoing_auth_needed(struct hci_dev *hdev,
1327 struct hci_conn *conn)
1329 if (conn->state != BT_CONFIG || !conn->out)
1332 if (conn->pending_sec_level == BT_SECURITY_SDP)
1335 /* Only request authentication for SSP connections or non-SSP
1336 * devices with sec_level HIGH or if MITM protection is requested */
1337 if (!hci_conn_ssp_enabled(conn) && !(conn->auth_type & 0x01) &&
1338 conn->pending_sec_level != BT_SECURITY_HIGH)
1344 static int hci_resolve_name(struct hci_dev *hdev,
1345 struct inquiry_entry *e)
1347 struct hci_cp_remote_name_req cp;
1349 memset(&cp, 0, sizeof(cp));
1351 bacpy(&cp.bdaddr, &e->data.bdaddr);
1352 cp.pscan_rep_mode = e->data.pscan_rep_mode;
1353 cp.pscan_mode = e->data.pscan_mode;
1354 cp.clock_offset = e->data.clock_offset;
1356 return hci_send_cmd(hdev, HCI_OP_REMOTE_NAME_REQ, sizeof(cp), &cp);
1359 static bool hci_resolve_next_name(struct hci_dev *hdev)
1361 struct discovery_state *discov = &hdev->discovery;
1362 struct inquiry_entry *e;
1364 if (list_empty(&discov->resolve))
1367 e = hci_inquiry_cache_lookup_resolve(hdev, BDADDR_ANY, NAME_NEEDED);
1371 if (hci_resolve_name(hdev, e) == 0) {
1372 e->name_state = NAME_PENDING;
1379 static void hci_check_pending_name(struct hci_dev *hdev, struct hci_conn *conn,
1380 bdaddr_t *bdaddr, u8 *name, u8 name_len)
1382 struct discovery_state *discov = &hdev->discovery;
1383 struct inquiry_entry *e;
1385 if (conn && !test_and_set_bit(HCI_CONN_MGMT_CONNECTED, &conn->flags))
1386 mgmt_device_connected(hdev, bdaddr, ACL_LINK, 0x00, 0, name,
1387 name_len, conn->dev_class);
1389 if (discov->state == DISCOVERY_STOPPED)
1392 if (discov->state == DISCOVERY_STOPPING)
1393 goto discov_complete;
1395 if (discov->state != DISCOVERY_RESOLVING)
1398 e = hci_inquiry_cache_lookup_resolve(hdev, bdaddr, NAME_PENDING);
1399 /* If the device was not found in a list of found devices names of which
1400 * are pending. there is no need to continue resolving a next name as it
1401 * will be done upon receiving another Remote Name Request Complete
1408 e->name_state = NAME_KNOWN;
1409 mgmt_remote_name(hdev, bdaddr, ACL_LINK, 0x00,
1410 e->data.rssi, name, name_len);
1412 e->name_state = NAME_NOT_KNOWN;
1415 if (hci_resolve_next_name(hdev))
1419 hci_discovery_set_state(hdev, DISCOVERY_STOPPED);
1422 static void hci_cs_remote_name_req(struct hci_dev *hdev, __u8 status)
1424 struct hci_cp_remote_name_req *cp;
1425 struct hci_conn *conn;
1427 BT_DBG("%s status 0x%2.2x", hdev->name, status);
1429 /* If successful wait for the name req complete event before
1430 * checking for the need to do authentication */
1434 cp = hci_sent_cmd_data(hdev, HCI_OP_REMOTE_NAME_REQ);
1440 conn = hci_conn_hash_lookup_ba(hdev, ACL_LINK, &cp->bdaddr);
1442 if (test_bit(HCI_MGMT, &hdev->dev_flags))
1443 hci_check_pending_name(hdev, conn, &cp->bdaddr, NULL, 0);
1448 if (!hci_outgoing_auth_needed(hdev, conn))
1451 if (!test_and_set_bit(HCI_CONN_AUTH_PEND, &conn->flags)) {
1452 struct hci_cp_auth_requested cp;
1453 cp.handle = __cpu_to_le16(conn->handle);
1454 hci_send_cmd(hdev, HCI_OP_AUTH_REQUESTED, sizeof(cp), &cp);
1458 hci_dev_unlock(hdev);
1461 static void hci_cs_read_remote_features(struct hci_dev *hdev, __u8 status)
1463 struct hci_cp_read_remote_features *cp;
1464 struct hci_conn *conn;
1466 BT_DBG("%s status 0x%2.2x", hdev->name, status);
1471 cp = hci_sent_cmd_data(hdev, HCI_OP_READ_REMOTE_FEATURES);
1477 conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(cp->handle));
1479 if (conn->state == BT_CONFIG) {
1480 hci_proto_connect_cfm(conn, status);
1485 hci_dev_unlock(hdev);
1488 static void hci_cs_read_remote_ext_features(struct hci_dev *hdev, __u8 status)
1490 struct hci_cp_read_remote_ext_features *cp;
1491 struct hci_conn *conn;
1493 BT_DBG("%s status 0x%2.2x", hdev->name, status);
1498 cp = hci_sent_cmd_data(hdev, HCI_OP_READ_REMOTE_EXT_FEATURES);
1504 conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(cp->handle));
1506 if (conn->state == BT_CONFIG) {
1507 hci_proto_connect_cfm(conn, status);
1512 hci_dev_unlock(hdev);
1515 static void hci_cs_setup_sync_conn(struct hci_dev *hdev, __u8 status)
1517 struct hci_cp_setup_sync_conn *cp;
1518 struct hci_conn *acl, *sco;
1521 BT_DBG("%s status 0x%2.2x", hdev->name, status);
1526 cp = hci_sent_cmd_data(hdev, HCI_OP_SETUP_SYNC_CONN);
1530 handle = __le16_to_cpu(cp->handle);
1532 BT_DBG("%s handle 0x%4.4x", hdev->name, handle);
1536 acl = hci_conn_hash_lookup_handle(hdev, handle);
1540 sco->state = BT_CLOSED;
1542 hci_proto_connect_cfm(sco, status);
1547 hci_dev_unlock(hdev);
1550 static void hci_cs_sniff_mode(struct hci_dev *hdev, __u8 status)
1552 struct hci_cp_sniff_mode *cp;
1553 struct hci_conn *conn;
1555 BT_DBG("%s status 0x%2.2x", hdev->name, status);
1560 cp = hci_sent_cmd_data(hdev, HCI_OP_SNIFF_MODE);
1566 conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(cp->handle));
1568 clear_bit(HCI_CONN_MODE_CHANGE_PEND, &conn->flags);
1570 if (test_and_clear_bit(HCI_CONN_SCO_SETUP_PEND, &conn->flags))
1571 hci_sco_setup(conn, status);
1574 hci_dev_unlock(hdev);
1577 static void hci_cs_exit_sniff_mode(struct hci_dev *hdev, __u8 status)
1579 struct hci_cp_exit_sniff_mode *cp;
1580 struct hci_conn *conn;
1582 BT_DBG("%s status 0x%2.2x", hdev->name, status);
1587 cp = hci_sent_cmd_data(hdev, HCI_OP_EXIT_SNIFF_MODE);
1593 conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(cp->handle));
1595 clear_bit(HCI_CONN_MODE_CHANGE_PEND, &conn->flags);
1597 if (test_and_clear_bit(HCI_CONN_SCO_SETUP_PEND, &conn->flags))
1598 hci_sco_setup(conn, status);
1601 hci_dev_unlock(hdev);
1604 static void hci_cs_disconnect(struct hci_dev *hdev, u8 status)
1606 struct hci_cp_disconnect *cp;
1607 struct hci_conn *conn;
1612 cp = hci_sent_cmd_data(hdev, HCI_OP_DISCONNECT);
1618 conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(cp->handle));
1620 mgmt_disconnect_failed(hdev, &conn->dst, conn->type,
1621 conn->dst_type, status);
1623 hci_dev_unlock(hdev);
1626 static void hci_cs_le_create_conn(struct hci_dev *hdev, __u8 status)
1628 struct hci_cp_le_create_conn *cp;
1629 struct hci_conn *conn;
1631 BT_DBG("%s status 0x%2.2x", hdev->name, status);
1633 cp = hci_sent_cmd_data(hdev, HCI_OP_LE_CREATE_CONN);
1639 conn = hci_conn_hash_lookup_ba(hdev, LE_LINK, &cp->peer_addr);
1641 BT_DBG("%s bdaddr %s conn %p", hdev->name, batostr(&cp->peer_addr),
1645 if (conn && conn->state == BT_CONNECT) {
1646 conn->state = BT_CLOSED;
1647 mgmt_connect_failed(hdev, &cp->peer_addr, conn->type,
1648 conn->dst_type, status);
1649 hci_proto_connect_cfm(conn, status);
1654 conn = hci_conn_add(hdev, LE_LINK, &cp->peer_addr);
1656 conn->dst_type = cp->peer_addr_type;
1659 BT_ERR("No memory for new connection");
1664 hci_dev_unlock(hdev);
1667 static void hci_cs_le_start_enc(struct hci_dev *hdev, u8 status)
1669 BT_DBG("%s status 0x%2.2x", hdev->name, status);
1672 static void hci_inquiry_complete_evt(struct hci_dev *hdev, struct sk_buff *skb)
1674 __u8 status = *((__u8 *) skb->data);
1675 struct discovery_state *discov = &hdev->discovery;
1676 struct inquiry_entry *e;
1678 BT_DBG("%s status 0x%2.2x", hdev->name, status);
1680 hci_req_complete(hdev, HCI_OP_INQUIRY, status);
1682 hci_conn_check_pending(hdev);
1684 if (!test_and_clear_bit(HCI_INQUIRY, &hdev->flags))
1687 if (!test_bit(HCI_MGMT, &hdev->dev_flags))
1692 if (discov->state != DISCOVERY_FINDING)
1695 if (list_empty(&discov->resolve)) {
1696 hci_discovery_set_state(hdev, DISCOVERY_STOPPED);
1700 e = hci_inquiry_cache_lookup_resolve(hdev, BDADDR_ANY, NAME_NEEDED);
1701 if (e && hci_resolve_name(hdev, e) == 0) {
1702 e->name_state = NAME_PENDING;
1703 hci_discovery_set_state(hdev, DISCOVERY_RESOLVING);
1705 hci_discovery_set_state(hdev, DISCOVERY_STOPPED);
1709 hci_dev_unlock(hdev);
1712 static void hci_inquiry_result_evt(struct hci_dev *hdev, struct sk_buff *skb)
1714 struct inquiry_data data;
1715 struct inquiry_info *info = (void *) (skb->data + 1);
1716 int num_rsp = *((__u8 *) skb->data);
1718 BT_DBG("%s num_rsp %d", hdev->name, num_rsp);
1723 if (test_bit(HCI_PERIODIC_INQ, &hdev->dev_flags))
1728 for (; num_rsp; num_rsp--, info++) {
1729 bool name_known, ssp;
1731 bacpy(&data.bdaddr, &info->bdaddr);
1732 data.pscan_rep_mode = info->pscan_rep_mode;
1733 data.pscan_period_mode = info->pscan_period_mode;
1734 data.pscan_mode = info->pscan_mode;
1735 memcpy(data.dev_class, info->dev_class, 3);
1736 data.clock_offset = info->clock_offset;
1738 data.ssp_mode = 0x00;
1740 name_known = hci_inquiry_cache_update(hdev, &data, false, &ssp);
1741 mgmt_device_found(hdev, &info->bdaddr, ACL_LINK, 0x00,
1742 info->dev_class, 0, !name_known, ssp, NULL,
1746 hci_dev_unlock(hdev);
1749 static void hci_conn_complete_evt(struct hci_dev *hdev, struct sk_buff *skb)
1751 struct hci_ev_conn_complete *ev = (void *) skb->data;
1752 struct hci_conn *conn;
1754 BT_DBG("%s", hdev->name);
1758 conn = hci_conn_hash_lookup_ba(hdev, ev->link_type, &ev->bdaddr);
1760 if (ev->link_type != SCO_LINK)
1763 conn = hci_conn_hash_lookup_ba(hdev, ESCO_LINK, &ev->bdaddr);
1767 conn->type = SCO_LINK;
1771 conn->handle = __le16_to_cpu(ev->handle);
1773 if (conn->type == ACL_LINK) {
1774 conn->state = BT_CONFIG;
1775 hci_conn_hold(conn);
1777 if (!conn->out && !hci_conn_ssp_enabled(conn) &&
1778 !hci_find_link_key(hdev, &ev->bdaddr))
1779 conn->disc_timeout = HCI_PAIRING_TIMEOUT;
1781 conn->disc_timeout = HCI_DISCONN_TIMEOUT;
1783 conn->state = BT_CONNECTED;
1785 hci_conn_hold_device(conn);
1786 hci_conn_add_sysfs(conn);
1788 if (test_bit(HCI_AUTH, &hdev->flags))
1789 conn->link_mode |= HCI_LM_AUTH;
1791 if (test_bit(HCI_ENCRYPT, &hdev->flags))
1792 conn->link_mode |= HCI_LM_ENCRYPT;
1794 /* Get remote features */
1795 if (conn->type == ACL_LINK) {
1796 struct hci_cp_read_remote_features cp;
1797 cp.handle = ev->handle;
1798 hci_send_cmd(hdev, HCI_OP_READ_REMOTE_FEATURES,
1802 /* Set packet type for incoming connection */
1803 if (!conn->out && hdev->hci_ver < BLUETOOTH_VER_2_0) {
1804 struct hci_cp_change_conn_ptype cp;
1805 cp.handle = ev->handle;
1806 cp.pkt_type = cpu_to_le16(conn->pkt_type);
1807 hci_send_cmd(hdev, HCI_OP_CHANGE_CONN_PTYPE, sizeof(cp),
1811 conn->state = BT_CLOSED;
1812 if (conn->type == ACL_LINK)
1813 mgmt_connect_failed(hdev, &ev->bdaddr, conn->type,
1814 conn->dst_type, ev->status);
1817 if (conn->type == ACL_LINK)
1818 hci_sco_setup(conn, ev->status);
1821 hci_proto_connect_cfm(conn, ev->status);
1823 } else if (ev->link_type != ACL_LINK)
1824 hci_proto_connect_cfm(conn, ev->status);
1827 hci_dev_unlock(hdev);
1829 hci_conn_check_pending(hdev);
1832 static void hci_conn_request_evt(struct hci_dev *hdev, struct sk_buff *skb)
1834 struct hci_ev_conn_request *ev = (void *) skb->data;
1835 int mask = hdev->link_mode;
1837 BT_DBG("%s bdaddr %s type 0x%x", hdev->name, batostr(&ev->bdaddr),
1840 mask |= hci_proto_connect_ind(hdev, &ev->bdaddr, ev->link_type);
1842 if ((mask & HCI_LM_ACCEPT) &&
1843 !hci_blacklist_lookup(hdev, &ev->bdaddr)) {
1844 /* Connection accepted */
1845 struct inquiry_entry *ie;
1846 struct hci_conn *conn;
1850 ie = hci_inquiry_cache_lookup(hdev, &ev->bdaddr);
1852 memcpy(ie->data.dev_class, ev->dev_class, 3);
1854 conn = hci_conn_hash_lookup_ba(hdev, ev->link_type,
1857 conn = hci_conn_add(hdev, ev->link_type, &ev->bdaddr);
1859 BT_ERR("No memory for new connection");
1860 hci_dev_unlock(hdev);
1865 memcpy(conn->dev_class, ev->dev_class, 3);
1866 conn->state = BT_CONNECT;
1868 hci_dev_unlock(hdev);
1870 if (ev->link_type == ACL_LINK || !lmp_esco_capable(hdev)) {
1871 struct hci_cp_accept_conn_req cp;
1873 bacpy(&cp.bdaddr, &ev->bdaddr);
1875 if (lmp_rswitch_capable(hdev) && (mask & HCI_LM_MASTER))
1876 cp.role = 0x00; /* Become master */
1878 cp.role = 0x01; /* Remain slave */
1880 hci_send_cmd(hdev, HCI_OP_ACCEPT_CONN_REQ, sizeof(cp),
1883 struct hci_cp_accept_sync_conn_req cp;
1885 bacpy(&cp.bdaddr, &ev->bdaddr);
1886 cp.pkt_type = cpu_to_le16(conn->pkt_type);
1888 cp.tx_bandwidth = __constant_cpu_to_le32(0x00001f40);
1889 cp.rx_bandwidth = __constant_cpu_to_le32(0x00001f40);
1890 cp.max_latency = __constant_cpu_to_le16(0xffff);
1891 cp.content_format = cpu_to_le16(hdev->voice_setting);
1892 cp.retrans_effort = 0xff;
1894 hci_send_cmd(hdev, HCI_OP_ACCEPT_SYNC_CONN_REQ,
1898 /* Connection rejected */
1899 struct hci_cp_reject_conn_req cp;
1901 bacpy(&cp.bdaddr, &ev->bdaddr);
1902 cp.reason = HCI_ERROR_REJ_BAD_ADDR;
1903 hci_send_cmd(hdev, HCI_OP_REJECT_CONN_REQ, sizeof(cp), &cp);
1907 static void hci_disconn_complete_evt(struct hci_dev *hdev, struct sk_buff *skb)
1909 struct hci_ev_disconn_complete *ev = (void *) skb->data;
1910 struct hci_conn *conn;
1912 BT_DBG("%s status 0x%2.2x", hdev->name, ev->status);
1916 conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(ev->handle));
1920 if (ev->status == 0)
1921 conn->state = BT_CLOSED;
1923 if (test_and_clear_bit(HCI_CONN_MGMT_CONNECTED, &conn->flags) &&
1924 (conn->type == ACL_LINK || conn->type == LE_LINK)) {
1925 if (ev->status != 0)
1926 mgmt_disconnect_failed(hdev, &conn->dst, conn->type,
1927 conn->dst_type, ev->status);
1929 mgmt_device_disconnected(hdev, &conn->dst, conn->type,
1933 if (ev->status == 0) {
1934 if (conn->type == ACL_LINK && conn->flush_key)
1935 hci_remove_link_key(hdev, &conn->dst);
1936 hci_proto_disconn_cfm(conn, ev->reason);
1941 hci_dev_unlock(hdev);
1944 static void hci_auth_complete_evt(struct hci_dev *hdev, struct sk_buff *skb)
1946 struct hci_ev_auth_complete *ev = (void *) skb->data;
1947 struct hci_conn *conn;
1949 BT_DBG("%s status 0x%2.2x", hdev->name, ev->status);
1953 conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(ev->handle));
1958 if (!hci_conn_ssp_enabled(conn) &&
1959 test_bit(HCI_CONN_REAUTH_PEND, &conn->flags)) {
1960 BT_INFO("re-auth of legacy device is not possible.");
1962 conn->link_mode |= HCI_LM_AUTH;
1963 conn->sec_level = conn->pending_sec_level;
1966 mgmt_auth_failed(hdev, &conn->dst, conn->type, conn->dst_type,
1970 clear_bit(HCI_CONN_AUTH_PEND, &conn->flags);
1971 clear_bit(HCI_CONN_REAUTH_PEND, &conn->flags);
1973 if (conn->state == BT_CONFIG) {
1974 if (!ev->status && hci_conn_ssp_enabled(conn)) {
1975 struct hci_cp_set_conn_encrypt cp;
1976 cp.handle = ev->handle;
1978 hci_send_cmd(hdev, HCI_OP_SET_CONN_ENCRYPT, sizeof(cp),
1981 conn->state = BT_CONNECTED;
1982 hci_proto_connect_cfm(conn, ev->status);
1986 hci_auth_cfm(conn, ev->status);
1988 hci_conn_hold(conn);
1989 conn->disc_timeout = HCI_DISCONN_TIMEOUT;
1993 if (test_bit(HCI_CONN_ENCRYPT_PEND, &conn->flags)) {
1995 struct hci_cp_set_conn_encrypt cp;
1996 cp.handle = ev->handle;
1998 hci_send_cmd(hdev, HCI_OP_SET_CONN_ENCRYPT, sizeof(cp),
2001 clear_bit(HCI_CONN_ENCRYPT_PEND, &conn->flags);
2002 hci_encrypt_cfm(conn, ev->status, 0x00);
2007 hci_dev_unlock(hdev);
2010 static void hci_remote_name_evt(struct hci_dev *hdev, struct sk_buff *skb)
2012 struct hci_ev_remote_name *ev = (void *) skb->data;
2013 struct hci_conn *conn;
2015 BT_DBG("%s", hdev->name);
2017 hci_conn_check_pending(hdev);
2021 conn = hci_conn_hash_lookup_ba(hdev, ACL_LINK, &ev->bdaddr);
2023 if (!test_bit(HCI_MGMT, &hdev->dev_flags))
2026 if (ev->status == 0)
2027 hci_check_pending_name(hdev, conn, &ev->bdaddr, ev->name,
2028 strnlen(ev->name, HCI_MAX_NAME_LENGTH));
2030 hci_check_pending_name(hdev, conn, &ev->bdaddr, NULL, 0);
2036 if (!hci_outgoing_auth_needed(hdev, conn))
2039 if (!test_and_set_bit(HCI_CONN_AUTH_PEND, &conn->flags)) {
2040 struct hci_cp_auth_requested cp;
2041 cp.handle = __cpu_to_le16(conn->handle);
2042 hci_send_cmd(hdev, HCI_OP_AUTH_REQUESTED, sizeof(cp), &cp);
2046 hci_dev_unlock(hdev);
2049 static void hci_encrypt_change_evt(struct hci_dev *hdev, struct sk_buff *skb)
2051 struct hci_ev_encrypt_change *ev = (void *) skb->data;
2052 struct hci_conn *conn;
2054 BT_DBG("%s status 0x%2.2x", hdev->name, ev->status);
2058 conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(ev->handle));
2062 /* Encryption implies authentication */
2063 conn->link_mode |= HCI_LM_AUTH;
2064 conn->link_mode |= HCI_LM_ENCRYPT;
2065 conn->sec_level = conn->pending_sec_level;
2067 conn->link_mode &= ~HCI_LM_ENCRYPT;
2070 clear_bit(HCI_CONN_ENCRYPT_PEND, &conn->flags);
2072 if (ev->status && conn->state == BT_CONNECTED) {
2073 hci_acl_disconn(conn, HCI_ERROR_AUTH_FAILURE);
2078 if (conn->state == BT_CONFIG) {
2080 conn->state = BT_CONNECTED;
2082 hci_proto_connect_cfm(conn, ev->status);
2085 hci_encrypt_cfm(conn, ev->status, ev->encrypt);
2089 hci_dev_unlock(hdev);
2092 static void hci_change_link_key_complete_evt(struct hci_dev *hdev,
2093 struct sk_buff *skb)
2095 struct hci_ev_change_link_key_complete *ev = (void *) skb->data;
2096 struct hci_conn *conn;
2098 BT_DBG("%s status 0x%2.2x", hdev->name, ev->status);
2102 conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(ev->handle));
2105 conn->link_mode |= HCI_LM_SECURE;
2107 clear_bit(HCI_CONN_AUTH_PEND, &conn->flags);
2109 hci_key_change_cfm(conn, ev->status);
2112 hci_dev_unlock(hdev);
2115 static void hci_remote_features_evt(struct hci_dev *hdev,
2116 struct sk_buff *skb)
2118 struct hci_ev_remote_features *ev = (void *) skb->data;
2119 struct hci_conn *conn;
2121 BT_DBG("%s status 0x%2.2x", hdev->name, ev->status);
2125 conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(ev->handle));
2130 memcpy(conn->features, ev->features, 8);
2132 if (conn->state != BT_CONFIG)
2135 if (!ev->status && lmp_ssp_capable(hdev) && lmp_ssp_capable(conn)) {
2136 struct hci_cp_read_remote_ext_features cp;
2137 cp.handle = ev->handle;
2139 hci_send_cmd(hdev, HCI_OP_READ_REMOTE_EXT_FEATURES,
2144 if (!ev->status && !test_bit(HCI_CONN_MGMT_CONNECTED, &conn->flags)) {
2145 struct hci_cp_remote_name_req cp;
2146 memset(&cp, 0, sizeof(cp));
2147 bacpy(&cp.bdaddr, &conn->dst);
2148 cp.pscan_rep_mode = 0x02;
2149 hci_send_cmd(hdev, HCI_OP_REMOTE_NAME_REQ, sizeof(cp), &cp);
2150 } else if (!test_and_set_bit(HCI_CONN_MGMT_CONNECTED, &conn->flags))
2151 mgmt_device_connected(hdev, &conn->dst, conn->type,
2152 conn->dst_type, 0, NULL, 0,
2155 if (!hci_outgoing_auth_needed(hdev, conn)) {
2156 conn->state = BT_CONNECTED;
2157 hci_proto_connect_cfm(conn, ev->status);
2162 hci_dev_unlock(hdev);
2165 static void hci_remote_version_evt(struct hci_dev *hdev, struct sk_buff *skb)
2167 BT_DBG("%s", hdev->name);
2170 static void hci_qos_setup_complete_evt(struct hci_dev *hdev,
2171 struct sk_buff *skb)
2173 BT_DBG("%s", hdev->name);
2176 static void hci_cmd_complete_evt(struct hci_dev *hdev, struct sk_buff *skb)
2178 struct hci_ev_cmd_complete *ev = (void *) skb->data;
2181 skb_pull(skb, sizeof(*ev));
2183 opcode = __le16_to_cpu(ev->opcode);
2186 case HCI_OP_INQUIRY_CANCEL:
2187 hci_cc_inquiry_cancel(hdev, skb);
2190 case HCI_OP_PERIODIC_INQ:
2191 hci_cc_periodic_inq(hdev, skb);
2194 case HCI_OP_EXIT_PERIODIC_INQ:
2195 hci_cc_exit_periodic_inq(hdev, skb);
2198 case HCI_OP_REMOTE_NAME_REQ_CANCEL:
2199 hci_cc_remote_name_req_cancel(hdev, skb);
2202 case HCI_OP_ROLE_DISCOVERY:
2203 hci_cc_role_discovery(hdev, skb);
2206 case HCI_OP_READ_LINK_POLICY:
2207 hci_cc_read_link_policy(hdev, skb);
2210 case HCI_OP_WRITE_LINK_POLICY:
2211 hci_cc_write_link_policy(hdev, skb);
2214 case HCI_OP_READ_DEF_LINK_POLICY:
2215 hci_cc_read_def_link_policy(hdev, skb);
2218 case HCI_OP_WRITE_DEF_LINK_POLICY:
2219 hci_cc_write_def_link_policy(hdev, skb);
2223 hci_cc_reset(hdev, skb);
2226 case HCI_OP_WRITE_LOCAL_NAME:
2227 hci_cc_write_local_name(hdev, skb);
2230 case HCI_OP_READ_LOCAL_NAME:
2231 hci_cc_read_local_name(hdev, skb);
2234 case HCI_OP_WRITE_AUTH_ENABLE:
2235 hci_cc_write_auth_enable(hdev, skb);
2238 case HCI_OP_WRITE_ENCRYPT_MODE:
2239 hci_cc_write_encrypt_mode(hdev, skb);
2242 case HCI_OP_WRITE_SCAN_ENABLE:
2243 hci_cc_write_scan_enable(hdev, skb);
2246 case HCI_OP_READ_CLASS_OF_DEV:
2247 hci_cc_read_class_of_dev(hdev, skb);
2250 case HCI_OP_WRITE_CLASS_OF_DEV:
2251 hci_cc_write_class_of_dev(hdev, skb);
2254 case HCI_OP_READ_VOICE_SETTING:
2255 hci_cc_read_voice_setting(hdev, skb);
2258 case HCI_OP_WRITE_VOICE_SETTING:
2259 hci_cc_write_voice_setting(hdev, skb);
2262 case HCI_OP_HOST_BUFFER_SIZE:
2263 hci_cc_host_buffer_size(hdev, skb);
2266 case HCI_OP_WRITE_SSP_MODE:
2267 hci_cc_write_ssp_mode(hdev, skb);
2270 case HCI_OP_READ_LOCAL_VERSION:
2271 hci_cc_read_local_version(hdev, skb);
2274 case HCI_OP_READ_LOCAL_COMMANDS:
2275 hci_cc_read_local_commands(hdev, skb);
2278 case HCI_OP_READ_LOCAL_FEATURES:
2279 hci_cc_read_local_features(hdev, skb);
2282 case HCI_OP_READ_LOCAL_EXT_FEATURES:
2283 hci_cc_read_local_ext_features(hdev, skb);
2286 case HCI_OP_READ_BUFFER_SIZE:
2287 hci_cc_read_buffer_size(hdev, skb);
2290 case HCI_OP_READ_BD_ADDR:
2291 hci_cc_read_bd_addr(hdev, skb);
2294 case HCI_OP_READ_DATA_BLOCK_SIZE:
2295 hci_cc_read_data_block_size(hdev, skb);
2298 case HCI_OP_WRITE_CA_TIMEOUT:
2299 hci_cc_write_ca_timeout(hdev, skb);
2302 case HCI_OP_READ_FLOW_CONTROL_MODE:
2303 hci_cc_read_flow_control_mode(hdev, skb);
2306 case HCI_OP_READ_LOCAL_AMP_INFO:
2307 hci_cc_read_local_amp_info(hdev, skb);
2310 case HCI_OP_DELETE_STORED_LINK_KEY:
2311 hci_cc_delete_stored_link_key(hdev, skb);
2314 case HCI_OP_SET_EVENT_MASK:
2315 hci_cc_set_event_mask(hdev, skb);
2318 case HCI_OP_WRITE_INQUIRY_MODE:
2319 hci_cc_write_inquiry_mode(hdev, skb);
2322 case HCI_OP_READ_INQ_RSP_TX_POWER:
2323 hci_cc_read_inq_rsp_tx_power(hdev, skb);
2326 case HCI_OP_SET_EVENT_FLT:
2327 hci_cc_set_event_flt(hdev, skb);
2330 case HCI_OP_PIN_CODE_REPLY:
2331 hci_cc_pin_code_reply(hdev, skb);
2334 case HCI_OP_PIN_CODE_NEG_REPLY:
2335 hci_cc_pin_code_neg_reply(hdev, skb);
2338 case HCI_OP_READ_LOCAL_OOB_DATA:
2339 hci_cc_read_local_oob_data_reply(hdev, skb);
2342 case HCI_OP_LE_READ_BUFFER_SIZE:
2343 hci_cc_le_read_buffer_size(hdev, skb);
2346 case HCI_OP_USER_CONFIRM_REPLY:
2347 hci_cc_user_confirm_reply(hdev, skb);
2350 case HCI_OP_USER_CONFIRM_NEG_REPLY:
2351 hci_cc_user_confirm_neg_reply(hdev, skb);
2354 case HCI_OP_USER_PASSKEY_REPLY:
2355 hci_cc_user_passkey_reply(hdev, skb);
2358 case HCI_OP_USER_PASSKEY_NEG_REPLY:
2359 hci_cc_user_passkey_neg_reply(hdev, skb);
2362 case HCI_OP_LE_SET_SCAN_PARAM:
2363 hci_cc_le_set_scan_param(hdev, skb);
2366 case HCI_OP_LE_SET_SCAN_ENABLE:
2367 hci_cc_le_set_scan_enable(hdev, skb);
2370 case HCI_OP_LE_LTK_REPLY:
2371 hci_cc_le_ltk_reply(hdev, skb);
2374 case HCI_OP_LE_LTK_NEG_REPLY:
2375 hci_cc_le_ltk_neg_reply(hdev, skb);
2378 case HCI_OP_WRITE_LE_HOST_SUPPORTED:
2379 hci_cc_write_le_host_supported(hdev, skb);
2383 BT_DBG("%s opcode 0x%4.4x", hdev->name, opcode);
2387 if (ev->opcode != HCI_OP_NOP)
2388 del_timer(&hdev->cmd_timer);
2391 atomic_set(&hdev->cmd_cnt, 1);
2392 if (!skb_queue_empty(&hdev->cmd_q))
2393 queue_work(hdev->workqueue, &hdev->cmd_work);
2397 static void hci_cmd_status_evt(struct hci_dev *hdev, struct sk_buff *skb)
2399 struct hci_ev_cmd_status *ev = (void *) skb->data;
2402 skb_pull(skb, sizeof(*ev));
2404 opcode = __le16_to_cpu(ev->opcode);
2407 case HCI_OP_INQUIRY:
2408 hci_cs_inquiry(hdev, ev->status);
2411 case HCI_OP_CREATE_CONN:
2412 hci_cs_create_conn(hdev, ev->status);
2415 case HCI_OP_ADD_SCO:
2416 hci_cs_add_sco(hdev, ev->status);
2419 case HCI_OP_AUTH_REQUESTED:
2420 hci_cs_auth_requested(hdev, ev->status);
2423 case HCI_OP_SET_CONN_ENCRYPT:
2424 hci_cs_set_conn_encrypt(hdev, ev->status);
2427 case HCI_OP_REMOTE_NAME_REQ:
2428 hci_cs_remote_name_req(hdev, ev->status);
2431 case HCI_OP_READ_REMOTE_FEATURES:
2432 hci_cs_read_remote_features(hdev, ev->status);
2435 case HCI_OP_READ_REMOTE_EXT_FEATURES:
2436 hci_cs_read_remote_ext_features(hdev, ev->status);
2439 case HCI_OP_SETUP_SYNC_CONN:
2440 hci_cs_setup_sync_conn(hdev, ev->status);
2443 case HCI_OP_SNIFF_MODE:
2444 hci_cs_sniff_mode(hdev, ev->status);
2447 case HCI_OP_EXIT_SNIFF_MODE:
2448 hci_cs_exit_sniff_mode(hdev, ev->status);
2451 case HCI_OP_DISCONNECT:
2452 hci_cs_disconnect(hdev, ev->status);
2455 case HCI_OP_LE_CREATE_CONN:
2456 hci_cs_le_create_conn(hdev, ev->status);
2459 case HCI_OP_LE_START_ENC:
2460 hci_cs_le_start_enc(hdev, ev->status);
2464 BT_DBG("%s opcode 0x%4.4x", hdev->name, opcode);
2468 if (ev->opcode != HCI_OP_NOP)
2469 del_timer(&hdev->cmd_timer);
2471 if (ev->ncmd && !test_bit(HCI_RESET, &hdev->flags)) {
2472 atomic_set(&hdev->cmd_cnt, 1);
2473 if (!skb_queue_empty(&hdev->cmd_q))
2474 queue_work(hdev->workqueue, &hdev->cmd_work);
2478 static void hci_role_change_evt(struct hci_dev *hdev, struct sk_buff *skb)
2480 struct hci_ev_role_change *ev = (void *) skb->data;
2481 struct hci_conn *conn;
2483 BT_DBG("%s status 0x%2.2x", hdev->name, ev->status);
2487 conn = hci_conn_hash_lookup_ba(hdev, ACL_LINK, &ev->bdaddr);
2491 conn->link_mode &= ~HCI_LM_MASTER;
2493 conn->link_mode |= HCI_LM_MASTER;
2496 clear_bit(HCI_CONN_RSWITCH_PEND, &conn->flags);
2498 hci_role_switch_cfm(conn, ev->status, ev->role);
2501 hci_dev_unlock(hdev);
2504 static void hci_num_comp_pkts_evt(struct hci_dev *hdev, struct sk_buff *skb)
2506 struct hci_ev_num_comp_pkts *ev = (void *) skb->data;
2509 if (hdev->flow_ctl_mode != HCI_FLOW_CTL_MODE_PACKET_BASED) {
2510 BT_ERR("Wrong event for mode %d", hdev->flow_ctl_mode);
2514 if (skb->len < sizeof(*ev) || skb->len < sizeof(*ev) +
2515 ev->num_hndl * sizeof(struct hci_comp_pkts_info)) {
2516 BT_DBG("%s bad parameters", hdev->name);
2520 BT_DBG("%s num_hndl %d", hdev->name, ev->num_hndl);
2522 for (i = 0; i < ev->num_hndl; i++) {
2523 struct hci_comp_pkts_info *info = &ev->handles[i];
2524 struct hci_conn *conn;
2525 __u16 handle, count;
2527 handle = __le16_to_cpu(info->handle);
2528 count = __le16_to_cpu(info->count);
2530 conn = hci_conn_hash_lookup_handle(hdev, handle);
2534 conn->sent -= count;
2536 switch (conn->type) {
2538 hdev->acl_cnt += count;
2539 if (hdev->acl_cnt > hdev->acl_pkts)
2540 hdev->acl_cnt = hdev->acl_pkts;
2544 if (hdev->le_pkts) {
2545 hdev->le_cnt += count;
2546 if (hdev->le_cnt > hdev->le_pkts)
2547 hdev->le_cnt = hdev->le_pkts;
2549 hdev->acl_cnt += count;
2550 if (hdev->acl_cnt > hdev->acl_pkts)
2551 hdev->acl_cnt = hdev->acl_pkts;
2556 hdev->sco_cnt += count;
2557 if (hdev->sco_cnt > hdev->sco_pkts)
2558 hdev->sco_cnt = hdev->sco_pkts;
2562 BT_ERR("Unknown type %d conn %p", conn->type, conn);
2567 queue_work(hdev->workqueue, &hdev->tx_work);
2570 static void hci_num_comp_blocks_evt(struct hci_dev *hdev, struct sk_buff *skb)
2572 struct hci_ev_num_comp_blocks *ev = (void *) skb->data;
2575 if (hdev->flow_ctl_mode != HCI_FLOW_CTL_MODE_BLOCK_BASED) {
2576 BT_ERR("Wrong event for mode %d", hdev->flow_ctl_mode);
2580 if (skb->len < sizeof(*ev) || skb->len < sizeof(*ev) +
2581 ev->num_hndl * sizeof(struct hci_comp_blocks_info)) {
2582 BT_DBG("%s bad parameters", hdev->name);
2586 BT_DBG("%s num_blocks %d num_hndl %d", hdev->name, ev->num_blocks,
2589 for (i = 0; i < ev->num_hndl; i++) {
2590 struct hci_comp_blocks_info *info = &ev->handles[i];
2591 struct hci_conn *conn;
2592 __u16 handle, block_count;
2594 handle = __le16_to_cpu(info->handle);
2595 block_count = __le16_to_cpu(info->blocks);
2597 conn = hci_conn_hash_lookup_handle(hdev, handle);
2601 conn->sent -= block_count;
2603 switch (conn->type) {
2605 hdev->block_cnt += block_count;
2606 if (hdev->block_cnt > hdev->num_blocks)
2607 hdev->block_cnt = hdev->num_blocks;
2611 BT_ERR("Unknown type %d conn %p", conn->type, conn);
2616 queue_work(hdev->workqueue, &hdev->tx_work);
2619 static void hci_mode_change_evt(struct hci_dev *hdev, struct sk_buff *skb)
2621 struct hci_ev_mode_change *ev = (void *) skb->data;
2622 struct hci_conn *conn;
2624 BT_DBG("%s status 0x%2.2x", hdev->name, ev->status);
2628 conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(ev->handle));
2630 conn->mode = ev->mode;
2631 conn->interval = __le16_to_cpu(ev->interval);
2633 if (!test_and_clear_bit(HCI_CONN_MODE_CHANGE_PEND,
2635 if (conn->mode == HCI_CM_ACTIVE)
2636 set_bit(HCI_CONN_POWER_SAVE, &conn->flags);
2638 clear_bit(HCI_CONN_POWER_SAVE, &conn->flags);
2641 if (test_and_clear_bit(HCI_CONN_SCO_SETUP_PEND, &conn->flags))
2642 hci_sco_setup(conn, ev->status);
2645 hci_dev_unlock(hdev);
2648 static void hci_pin_code_request_evt(struct hci_dev *hdev, struct sk_buff *skb)
2650 struct hci_ev_pin_code_req *ev = (void *) skb->data;
2651 struct hci_conn *conn;
2653 BT_DBG("%s", hdev->name);
2657 conn = hci_conn_hash_lookup_ba(hdev, ACL_LINK, &ev->bdaddr);
2661 if (conn->state == BT_CONNECTED) {
2662 hci_conn_hold(conn);
2663 conn->disc_timeout = HCI_PAIRING_TIMEOUT;
2667 if (!test_bit(HCI_PAIRABLE, &hdev->dev_flags))
2668 hci_send_cmd(hdev, HCI_OP_PIN_CODE_NEG_REPLY,
2669 sizeof(ev->bdaddr), &ev->bdaddr);
2670 else if (test_bit(HCI_MGMT, &hdev->dev_flags)) {
2673 if (conn->pending_sec_level == BT_SECURITY_HIGH)
2678 mgmt_pin_code_request(hdev, &ev->bdaddr, secure);
2682 hci_dev_unlock(hdev);
2685 static void hci_link_key_request_evt(struct hci_dev *hdev, struct sk_buff *skb)
2687 struct hci_ev_link_key_req *ev = (void *) skb->data;
2688 struct hci_cp_link_key_reply cp;
2689 struct hci_conn *conn;
2690 struct link_key *key;
2692 BT_DBG("%s", hdev->name);
2694 if (!test_bit(HCI_LINK_KEYS, &hdev->dev_flags))
2699 key = hci_find_link_key(hdev, &ev->bdaddr);
2701 BT_DBG("%s link key not found for %s", hdev->name,
2702 batostr(&ev->bdaddr));
2706 BT_DBG("%s found key type %u for %s", hdev->name, key->type,
2707 batostr(&ev->bdaddr));
2709 if (!test_bit(HCI_DEBUG_KEYS, &hdev->dev_flags) &&
2710 key->type == HCI_LK_DEBUG_COMBINATION) {
2711 BT_DBG("%s ignoring debug key", hdev->name);
2715 conn = hci_conn_hash_lookup_ba(hdev, ACL_LINK, &ev->bdaddr);
2717 if (key->type == HCI_LK_UNAUTH_COMBINATION &&
2718 conn->auth_type != 0xff && (conn->auth_type & 0x01)) {
2719 BT_DBG("%s ignoring unauthenticated key", hdev->name);
2723 if (key->type == HCI_LK_COMBINATION && key->pin_len < 16 &&
2724 conn->pending_sec_level == BT_SECURITY_HIGH) {
2725 BT_DBG("%s ignoring key unauthenticated for high security",
2730 conn->key_type = key->type;
2731 conn->pin_length = key->pin_len;
2734 bacpy(&cp.bdaddr, &ev->bdaddr);
2735 memcpy(cp.link_key, key->val, HCI_LINK_KEY_SIZE);
2737 hci_send_cmd(hdev, HCI_OP_LINK_KEY_REPLY, sizeof(cp), &cp);
2739 hci_dev_unlock(hdev);
2744 hci_send_cmd(hdev, HCI_OP_LINK_KEY_NEG_REPLY, 6, &ev->bdaddr);
2745 hci_dev_unlock(hdev);
2748 static void hci_link_key_notify_evt(struct hci_dev *hdev, struct sk_buff *skb)
2750 struct hci_ev_link_key_notify *ev = (void *) skb->data;
2751 struct hci_conn *conn;
2754 BT_DBG("%s", hdev->name);
2758 conn = hci_conn_hash_lookup_ba(hdev, ACL_LINK, &ev->bdaddr);
2760 hci_conn_hold(conn);
2761 conn->disc_timeout = HCI_DISCONN_TIMEOUT;
2762 pin_len = conn->pin_length;
2764 if (ev->key_type != HCI_LK_CHANGED_COMBINATION)
2765 conn->key_type = ev->key_type;
2770 if (test_bit(HCI_LINK_KEYS, &hdev->dev_flags))
2771 hci_add_link_key(hdev, conn, 1, &ev->bdaddr, ev->link_key,
2772 ev->key_type, pin_len);
2774 hci_dev_unlock(hdev);
2777 static void hci_clock_offset_evt(struct hci_dev *hdev, struct sk_buff *skb)
2779 struct hci_ev_clock_offset *ev = (void *) skb->data;
2780 struct hci_conn *conn;
2782 BT_DBG("%s status 0x%2.2x", hdev->name, ev->status);
2786 conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(ev->handle));
2787 if (conn && !ev->status) {
2788 struct inquiry_entry *ie;
2790 ie = hci_inquiry_cache_lookup(hdev, &conn->dst);
2792 ie->data.clock_offset = ev->clock_offset;
2793 ie->timestamp = jiffies;
2797 hci_dev_unlock(hdev);
2800 static void hci_pkt_type_change_evt(struct hci_dev *hdev, struct sk_buff *skb)
2802 struct hci_ev_pkt_type_change *ev = (void *) skb->data;
2803 struct hci_conn *conn;
2805 BT_DBG("%s status 0x%2.2x", hdev->name, ev->status);
2809 conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(ev->handle));
2810 if (conn && !ev->status)
2811 conn->pkt_type = __le16_to_cpu(ev->pkt_type);
2813 hci_dev_unlock(hdev);
2816 static void hci_pscan_rep_mode_evt(struct hci_dev *hdev, struct sk_buff *skb)
2818 struct hci_ev_pscan_rep_mode *ev = (void *) skb->data;
2819 struct inquiry_entry *ie;
2821 BT_DBG("%s", hdev->name);
2825 ie = hci_inquiry_cache_lookup(hdev, &ev->bdaddr);
2827 ie->data.pscan_rep_mode = ev->pscan_rep_mode;
2828 ie->timestamp = jiffies;
2831 hci_dev_unlock(hdev);
2834 static void hci_inquiry_result_with_rssi_evt(struct hci_dev *hdev,
2835 struct sk_buff *skb)
2837 struct inquiry_data data;
2838 int num_rsp = *((__u8 *) skb->data);
2839 bool name_known, ssp;
2841 BT_DBG("%s num_rsp %d", hdev->name, num_rsp);
2846 if (test_bit(HCI_PERIODIC_INQ, &hdev->dev_flags))
2851 if ((skb->len - 1) / num_rsp != sizeof(struct inquiry_info_with_rssi)) {
2852 struct inquiry_info_with_rssi_and_pscan_mode *info;
2853 info = (void *) (skb->data + 1);
2855 for (; num_rsp; num_rsp--, info++) {
2856 bacpy(&data.bdaddr, &info->bdaddr);
2857 data.pscan_rep_mode = info->pscan_rep_mode;
2858 data.pscan_period_mode = info->pscan_period_mode;
2859 data.pscan_mode = info->pscan_mode;
2860 memcpy(data.dev_class, info->dev_class, 3);
2861 data.clock_offset = info->clock_offset;
2862 data.rssi = info->rssi;
2863 data.ssp_mode = 0x00;
2865 name_known = hci_inquiry_cache_update(hdev, &data,
2867 mgmt_device_found(hdev, &info->bdaddr, ACL_LINK, 0x00,
2868 info->dev_class, info->rssi,
2869 !name_known, ssp, NULL, 0);
2872 struct inquiry_info_with_rssi *info = (void *) (skb->data + 1);
2874 for (; num_rsp; num_rsp--, info++) {
2875 bacpy(&data.bdaddr, &info->bdaddr);
2876 data.pscan_rep_mode = info->pscan_rep_mode;
2877 data.pscan_period_mode = info->pscan_period_mode;
2878 data.pscan_mode = 0x00;
2879 memcpy(data.dev_class, info->dev_class, 3);
2880 data.clock_offset = info->clock_offset;
2881 data.rssi = info->rssi;
2882 data.ssp_mode = 0x00;
2883 name_known = hci_inquiry_cache_update(hdev, &data,
2885 mgmt_device_found(hdev, &info->bdaddr, ACL_LINK, 0x00,
2886 info->dev_class, info->rssi,
2887 !name_known, ssp, NULL, 0);
2891 hci_dev_unlock(hdev);
2894 static void hci_remote_ext_features_evt(struct hci_dev *hdev,
2895 struct sk_buff *skb)
2897 struct hci_ev_remote_ext_features *ev = (void *) skb->data;
2898 struct hci_conn *conn;
2900 BT_DBG("%s", hdev->name);
2904 conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(ev->handle));
2908 if (!ev->status && ev->page == 0x01) {
2909 struct inquiry_entry *ie;
2911 ie = hci_inquiry_cache_lookup(hdev, &conn->dst);
2913 ie->data.ssp_mode = (ev->features[0] & LMP_HOST_SSP);
2915 if (ev->features[0] & LMP_HOST_SSP)
2916 set_bit(HCI_CONN_SSP_ENABLED, &conn->flags);
2919 if (conn->state != BT_CONFIG)
2922 if (!ev->status && !test_bit(HCI_CONN_MGMT_CONNECTED, &conn->flags)) {
2923 struct hci_cp_remote_name_req cp;
2924 memset(&cp, 0, sizeof(cp));
2925 bacpy(&cp.bdaddr, &conn->dst);
2926 cp.pscan_rep_mode = 0x02;
2927 hci_send_cmd(hdev, HCI_OP_REMOTE_NAME_REQ, sizeof(cp), &cp);
2928 } else if (!test_and_set_bit(HCI_CONN_MGMT_CONNECTED, &conn->flags))
2929 mgmt_device_connected(hdev, &conn->dst, conn->type,
2930 conn->dst_type, 0, NULL, 0,
2933 if (!hci_outgoing_auth_needed(hdev, conn)) {
2934 conn->state = BT_CONNECTED;
2935 hci_proto_connect_cfm(conn, ev->status);
2940 hci_dev_unlock(hdev);
2943 static void hci_sync_conn_complete_evt(struct hci_dev *hdev,
2944 struct sk_buff *skb)
2946 struct hci_ev_sync_conn_complete *ev = (void *) skb->data;
2947 struct hci_conn *conn;
2949 BT_DBG("%s status 0x%2.2x", hdev->name, ev->status);
2953 conn = hci_conn_hash_lookup_ba(hdev, ev->link_type, &ev->bdaddr);
2955 if (ev->link_type == ESCO_LINK)
2958 conn = hci_conn_hash_lookup_ba(hdev, ESCO_LINK, &ev->bdaddr);
2962 conn->type = SCO_LINK;
2965 switch (ev->status) {
2967 conn->handle = __le16_to_cpu(ev->handle);
2968 conn->state = BT_CONNECTED;
2970 hci_conn_hold_device(conn);
2971 hci_conn_add_sysfs(conn);
2974 case 0x11: /* Unsupported Feature or Parameter Value */
2975 case 0x1c: /* SCO interval rejected */
2976 case 0x1a: /* Unsupported Remote Feature */
2977 case 0x1f: /* Unspecified error */
2978 if (conn->out && conn->attempt < 2) {
2979 conn->pkt_type = (hdev->esco_type & SCO_ESCO_MASK) |
2980 (hdev->esco_type & EDR_ESCO_MASK);
2981 hci_setup_sync(conn, conn->link->handle);
2987 conn->state = BT_CLOSED;
2991 hci_proto_connect_cfm(conn, ev->status);
2996 hci_dev_unlock(hdev);
2999 static void hci_sync_conn_changed_evt(struct hci_dev *hdev, struct sk_buff *skb)
3001 BT_DBG("%s", hdev->name);
3004 static void hci_sniff_subrate_evt(struct hci_dev *hdev, struct sk_buff *skb)
3006 struct hci_ev_sniff_subrate *ev = (void *) skb->data;
3008 BT_DBG("%s status 0x%2.2x", hdev->name, ev->status);
3011 static void hci_extended_inquiry_result_evt(struct hci_dev *hdev,
3012 struct sk_buff *skb)
3014 struct inquiry_data data;
3015 struct extended_inquiry_info *info = (void *) (skb->data + 1);
3016 int num_rsp = *((__u8 *) skb->data);
3019 BT_DBG("%s num_rsp %d", hdev->name, num_rsp);
3024 if (test_bit(HCI_PERIODIC_INQ, &hdev->dev_flags))
3029 for (; num_rsp; num_rsp--, info++) {
3030 bool name_known, ssp;
3032 bacpy(&data.bdaddr, &info->bdaddr);
3033 data.pscan_rep_mode = info->pscan_rep_mode;
3034 data.pscan_period_mode = info->pscan_period_mode;
3035 data.pscan_mode = 0x00;
3036 memcpy(data.dev_class, info->dev_class, 3);
3037 data.clock_offset = info->clock_offset;
3038 data.rssi = info->rssi;
3039 data.ssp_mode = 0x01;
3041 if (test_bit(HCI_MGMT, &hdev->dev_flags))
3042 name_known = eir_has_data_type(info->data,
3048 name_known = hci_inquiry_cache_update(hdev, &data, name_known,
3050 eir_len = eir_get_length(info->data, sizeof(info->data));
3051 mgmt_device_found(hdev, &info->bdaddr, ACL_LINK, 0x00,
3052 info->dev_class, info->rssi, !name_known,
3053 ssp, info->data, eir_len);
3056 hci_dev_unlock(hdev);
3059 static void hci_key_refresh_complete_evt(struct hci_dev *hdev,
3060 struct sk_buff *skb)
3062 struct hci_ev_key_refresh_complete *ev = (void *) skb->data;
3063 struct hci_conn *conn;
3065 BT_DBG("%s status 0x%2.2x handle 0x%4.4x", hdev->name, ev->status,
3066 __le16_to_cpu(ev->handle));
3070 conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(ev->handle));
3075 conn->sec_level = conn->pending_sec_level;
3077 clear_bit(HCI_CONN_ENCRYPT_PEND, &conn->flags);
3079 if (ev->status && conn->state == BT_CONNECTED) {
3080 hci_acl_disconn(conn, HCI_ERROR_AUTH_FAILURE);
3085 if (conn->state == BT_CONFIG) {
3087 conn->state = BT_CONNECTED;
3089 hci_proto_connect_cfm(conn, ev->status);
3092 hci_auth_cfm(conn, ev->status);
3094 hci_conn_hold(conn);
3095 conn->disc_timeout = HCI_DISCONN_TIMEOUT;
3100 hci_dev_unlock(hdev);
3103 static u8 hci_get_auth_req(struct hci_conn *conn)
3105 /* If remote requests dedicated bonding follow that lead */
3106 if (conn->remote_auth == 0x02 || conn->remote_auth == 0x03) {
3107 /* If both remote and local IO capabilities allow MITM
3108 * protection then require it, otherwise don't */
3109 if (conn->remote_cap == 0x03 || conn->io_capability == 0x03)
3115 /* If remote requests no-bonding follow that lead */
3116 if (conn->remote_auth == 0x00 || conn->remote_auth == 0x01)
3117 return conn->remote_auth | (conn->auth_type & 0x01);
3119 return conn->auth_type;
3122 static void hci_io_capa_request_evt(struct hci_dev *hdev, struct sk_buff *skb)
3124 struct hci_ev_io_capa_request *ev = (void *) skb->data;
3125 struct hci_conn *conn;
3127 BT_DBG("%s", hdev->name);
3131 conn = hci_conn_hash_lookup_ba(hdev, ACL_LINK, &ev->bdaddr);
3135 hci_conn_hold(conn);
3137 if (!test_bit(HCI_MGMT, &hdev->dev_flags))
3140 if (test_bit(HCI_PAIRABLE, &hdev->dev_flags) ||
3141 (conn->remote_auth & ~0x01) == HCI_AT_NO_BONDING) {
3142 struct hci_cp_io_capability_reply cp;
3144 bacpy(&cp.bdaddr, &ev->bdaddr);
3145 /* Change the IO capability from KeyboardDisplay
3146 * to DisplayYesNo as it is not supported by BT spec. */
3147 cp.capability = (conn->io_capability == 0x04) ?
3148 0x01 : conn->io_capability;
3149 conn->auth_type = hci_get_auth_req(conn);
3150 cp.authentication = conn->auth_type;
3152 if (hci_find_remote_oob_data(hdev, &conn->dst) &&
3153 (conn->out || test_bit(HCI_CONN_REMOTE_OOB, &conn->flags)))
3158 hci_send_cmd(hdev, HCI_OP_IO_CAPABILITY_REPLY,
3161 struct hci_cp_io_capability_neg_reply cp;
3163 bacpy(&cp.bdaddr, &ev->bdaddr);
3164 cp.reason = HCI_ERROR_PAIRING_NOT_ALLOWED;
3166 hci_send_cmd(hdev, HCI_OP_IO_CAPABILITY_NEG_REPLY,
3171 hci_dev_unlock(hdev);
3174 static void hci_io_capa_reply_evt(struct hci_dev *hdev, struct sk_buff *skb)
3176 struct hci_ev_io_capa_reply *ev = (void *) skb->data;
3177 struct hci_conn *conn;
3179 BT_DBG("%s", hdev->name);
3183 conn = hci_conn_hash_lookup_ba(hdev, ACL_LINK, &ev->bdaddr);
3187 conn->remote_cap = ev->capability;
3188 conn->remote_auth = ev->authentication;
3190 set_bit(HCI_CONN_REMOTE_OOB, &conn->flags);
3193 hci_dev_unlock(hdev);
3196 static void hci_user_confirm_request_evt(struct hci_dev *hdev,
3197 struct sk_buff *skb)
3199 struct hci_ev_user_confirm_req *ev = (void *) skb->data;
3200 int loc_mitm, rem_mitm, confirm_hint = 0;
3201 struct hci_conn *conn;
3203 BT_DBG("%s", hdev->name);
3207 if (!test_bit(HCI_MGMT, &hdev->dev_flags))
3210 conn = hci_conn_hash_lookup_ba(hdev, ACL_LINK, &ev->bdaddr);
3214 loc_mitm = (conn->auth_type & 0x01);
3215 rem_mitm = (conn->remote_auth & 0x01);
3217 /* If we require MITM but the remote device can't provide that
3218 * (it has NoInputNoOutput) then reject the confirmation
3219 * request. The only exception is when we're dedicated bonding
3220 * initiators (connect_cfm_cb set) since then we always have the MITM
3222 if (!conn->connect_cfm_cb && loc_mitm && conn->remote_cap == 0x03) {
3223 BT_DBG("Rejecting request: remote device can't provide MITM");
3224 hci_send_cmd(hdev, HCI_OP_USER_CONFIRM_NEG_REPLY,
3225 sizeof(ev->bdaddr), &ev->bdaddr);
3229 /* If no side requires MITM protection; auto-accept */
3230 if ((!loc_mitm || conn->remote_cap == 0x03) &&
3231 (!rem_mitm || conn->io_capability == 0x03)) {
3233 /* If we're not the initiators request authorization to
3234 * proceed from user space (mgmt_user_confirm with
3235 * confirm_hint set to 1). */
3236 if (!test_bit(HCI_CONN_AUTH_PEND, &conn->flags)) {
3237 BT_DBG("Confirming auto-accept as acceptor");
3242 BT_DBG("Auto-accept of user confirmation with %ums delay",
3243 hdev->auto_accept_delay);
3245 if (hdev->auto_accept_delay > 0) {
3246 int delay = msecs_to_jiffies(hdev->auto_accept_delay);
3247 mod_timer(&conn->auto_accept_timer, jiffies + delay);
3251 hci_send_cmd(hdev, HCI_OP_USER_CONFIRM_REPLY,
3252 sizeof(ev->bdaddr), &ev->bdaddr);
3257 mgmt_user_confirm_request(hdev, &ev->bdaddr, ACL_LINK, 0, ev->passkey,
3261 hci_dev_unlock(hdev);
3264 static void hci_user_passkey_request_evt(struct hci_dev *hdev,
3265 struct sk_buff *skb)
3267 struct hci_ev_user_passkey_req *ev = (void *) skb->data;
3269 BT_DBG("%s", hdev->name);
3273 if (test_bit(HCI_MGMT, &hdev->dev_flags))
3274 mgmt_user_passkey_request(hdev, &ev->bdaddr, ACL_LINK, 0);
3276 hci_dev_unlock(hdev);
3279 static void hci_simple_pair_complete_evt(struct hci_dev *hdev,
3280 struct sk_buff *skb)
3282 struct hci_ev_simple_pair_complete *ev = (void *) skb->data;
3283 struct hci_conn *conn;
3285 BT_DBG("%s", hdev->name);
3289 conn = hci_conn_hash_lookup_ba(hdev, ACL_LINK, &ev->bdaddr);
3293 /* To avoid duplicate auth_failed events to user space we check
3294 * the HCI_CONN_AUTH_PEND flag which will be set if we
3295 * initiated the authentication. A traditional auth_complete
3296 * event gets always produced as initiator and is also mapped to
3297 * the mgmt_auth_failed event */
3298 if (!test_bit(HCI_CONN_AUTH_PEND, &conn->flags) && ev->status != 0)
3299 mgmt_auth_failed(hdev, &conn->dst, conn->type, conn->dst_type,
3305 hci_dev_unlock(hdev);
3308 static void hci_remote_host_features_evt(struct hci_dev *hdev,
3309 struct sk_buff *skb)
3311 struct hci_ev_remote_host_features *ev = (void *) skb->data;
3312 struct inquiry_entry *ie;
3314 BT_DBG("%s", hdev->name);
3318 ie = hci_inquiry_cache_lookup(hdev, &ev->bdaddr);
3320 ie->data.ssp_mode = (ev->features[0] & LMP_HOST_SSP);
3322 hci_dev_unlock(hdev);
3325 static void hci_remote_oob_data_request_evt(struct hci_dev *hdev,
3326 struct sk_buff *skb)
3328 struct hci_ev_remote_oob_data_request *ev = (void *) skb->data;
3329 struct oob_data *data;
3331 BT_DBG("%s", hdev->name);
3335 if (!test_bit(HCI_MGMT, &hdev->dev_flags))
3338 data = hci_find_remote_oob_data(hdev, &ev->bdaddr);
3340 struct hci_cp_remote_oob_data_reply cp;
3342 bacpy(&cp.bdaddr, &ev->bdaddr);
3343 memcpy(cp.hash, data->hash, sizeof(cp.hash));
3344 memcpy(cp.randomizer, data->randomizer, sizeof(cp.randomizer));
3346 hci_send_cmd(hdev, HCI_OP_REMOTE_OOB_DATA_REPLY, sizeof(cp),
3349 struct hci_cp_remote_oob_data_neg_reply cp;
3351 bacpy(&cp.bdaddr, &ev->bdaddr);
3352 hci_send_cmd(hdev, HCI_OP_REMOTE_OOB_DATA_NEG_REPLY, sizeof(cp),
3357 hci_dev_unlock(hdev);
3360 static void hci_le_conn_complete_evt(struct hci_dev *hdev, struct sk_buff *skb)
3362 struct hci_ev_le_conn_complete *ev = (void *) skb->data;
3363 struct hci_conn *conn;
3365 BT_DBG("%s status 0x%2.2x", hdev->name, ev->status);
3370 conn = hci_conn_hash_lookup_state(hdev, LE_LINK, BT_CONNECT);
3374 mgmt_connect_failed(hdev, &conn->dst, conn->type,
3375 conn->dst_type, ev->status);
3376 hci_proto_connect_cfm(conn, ev->status);
3377 conn->state = BT_CLOSED;
3382 conn = hci_conn_hash_lookup_ba(hdev, LE_LINK, &ev->bdaddr);
3384 conn = hci_conn_add(hdev, LE_LINK, &ev->bdaddr);
3386 BT_ERR("No memory for new connection");
3387 hci_dev_unlock(hdev);
3391 conn->dst_type = ev->bdaddr_type;
3394 if (!test_and_set_bit(HCI_CONN_MGMT_CONNECTED, &conn->flags))
3395 mgmt_device_connected(hdev, &ev->bdaddr, conn->type,
3396 conn->dst_type, 0, NULL, 0, NULL);
3398 conn->sec_level = BT_SECURITY_LOW;
3399 conn->handle = __le16_to_cpu(ev->handle);
3400 conn->state = BT_CONNECTED;
3402 hci_conn_hold_device(conn);
3403 hci_conn_add_sysfs(conn);
3405 hci_proto_connect_cfm(conn, ev->status);
3408 hci_dev_unlock(hdev);
3411 static void hci_le_adv_report_evt(struct hci_dev *hdev, struct sk_buff *skb)
3413 u8 num_reports = skb->data[0];
3414 void *ptr = &skb->data[1];
3419 while (num_reports--) {
3420 struct hci_ev_le_advertising_info *ev = ptr;
3422 rssi = ev->data[ev->length];
3423 mgmt_device_found(hdev, &ev->bdaddr, LE_LINK, ev->bdaddr_type,
3424 NULL, rssi, 0, 1, ev->data, ev->length);
3426 ptr += sizeof(*ev) + ev->length + 1;
3429 hci_dev_unlock(hdev);
3432 static void hci_le_ltk_request_evt(struct hci_dev *hdev, struct sk_buff *skb)
3434 struct hci_ev_le_ltk_req *ev = (void *) skb->data;
3435 struct hci_cp_le_ltk_reply cp;
3436 struct hci_cp_le_ltk_neg_reply neg;
3437 struct hci_conn *conn;
3438 struct smp_ltk *ltk;
3440 BT_DBG("%s handle 0x%4.4x", hdev->name, __le16_to_cpu(ev->handle));
3444 conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(ev->handle));
3448 ltk = hci_find_ltk(hdev, ev->ediv, ev->random);
3452 memcpy(cp.ltk, ltk->val, sizeof(ltk->val));
3453 cp.handle = cpu_to_le16(conn->handle);
3455 if (ltk->authenticated)
3456 conn->sec_level = BT_SECURITY_HIGH;
3458 hci_send_cmd(hdev, HCI_OP_LE_LTK_REPLY, sizeof(cp), &cp);
3460 if (ltk->type & HCI_SMP_STK) {
3461 list_del(<k->list);
3465 hci_dev_unlock(hdev);
3470 neg.handle = ev->handle;
3471 hci_send_cmd(hdev, HCI_OP_LE_LTK_NEG_REPLY, sizeof(neg), &neg);
3472 hci_dev_unlock(hdev);
3475 static void hci_le_meta_evt(struct hci_dev *hdev, struct sk_buff *skb)
3477 struct hci_ev_le_meta *le_ev = (void *) skb->data;
3479 skb_pull(skb, sizeof(*le_ev));
3481 switch (le_ev->subevent) {
3482 case HCI_EV_LE_CONN_COMPLETE:
3483 hci_le_conn_complete_evt(hdev, skb);
3486 case HCI_EV_LE_ADVERTISING_REPORT:
3487 hci_le_adv_report_evt(hdev, skb);
3490 case HCI_EV_LE_LTK_REQ:
3491 hci_le_ltk_request_evt(hdev, skb);
3499 void hci_event_packet(struct hci_dev *hdev, struct sk_buff *skb)
3501 struct hci_event_hdr *hdr = (void *) skb->data;
3502 __u8 event = hdr->evt;
3504 skb_pull(skb, HCI_EVENT_HDR_SIZE);
3507 case HCI_EV_INQUIRY_COMPLETE:
3508 hci_inquiry_complete_evt(hdev, skb);
3511 case HCI_EV_INQUIRY_RESULT:
3512 hci_inquiry_result_evt(hdev, skb);
3515 case HCI_EV_CONN_COMPLETE:
3516 hci_conn_complete_evt(hdev, skb);
3519 case HCI_EV_CONN_REQUEST:
3520 hci_conn_request_evt(hdev, skb);
3523 case HCI_EV_DISCONN_COMPLETE:
3524 hci_disconn_complete_evt(hdev, skb);
3527 case HCI_EV_AUTH_COMPLETE:
3528 hci_auth_complete_evt(hdev, skb);
3531 case HCI_EV_REMOTE_NAME:
3532 hci_remote_name_evt(hdev, skb);
3535 case HCI_EV_ENCRYPT_CHANGE:
3536 hci_encrypt_change_evt(hdev, skb);
3539 case HCI_EV_CHANGE_LINK_KEY_COMPLETE:
3540 hci_change_link_key_complete_evt(hdev, skb);
3543 case HCI_EV_REMOTE_FEATURES:
3544 hci_remote_features_evt(hdev, skb);
3547 case HCI_EV_REMOTE_VERSION:
3548 hci_remote_version_evt(hdev, skb);
3551 case HCI_EV_QOS_SETUP_COMPLETE:
3552 hci_qos_setup_complete_evt(hdev, skb);
3555 case HCI_EV_CMD_COMPLETE:
3556 hci_cmd_complete_evt(hdev, skb);
3559 case HCI_EV_CMD_STATUS:
3560 hci_cmd_status_evt(hdev, skb);
3563 case HCI_EV_ROLE_CHANGE:
3564 hci_role_change_evt(hdev, skb);
3567 case HCI_EV_NUM_COMP_PKTS:
3568 hci_num_comp_pkts_evt(hdev, skb);
3571 case HCI_EV_MODE_CHANGE:
3572 hci_mode_change_evt(hdev, skb);
3575 case HCI_EV_PIN_CODE_REQ:
3576 hci_pin_code_request_evt(hdev, skb);
3579 case HCI_EV_LINK_KEY_REQ:
3580 hci_link_key_request_evt(hdev, skb);
3583 case HCI_EV_LINK_KEY_NOTIFY:
3584 hci_link_key_notify_evt(hdev, skb);
3587 case HCI_EV_CLOCK_OFFSET:
3588 hci_clock_offset_evt(hdev, skb);
3591 case HCI_EV_PKT_TYPE_CHANGE:
3592 hci_pkt_type_change_evt(hdev, skb);
3595 case HCI_EV_PSCAN_REP_MODE:
3596 hci_pscan_rep_mode_evt(hdev, skb);
3599 case HCI_EV_INQUIRY_RESULT_WITH_RSSI:
3600 hci_inquiry_result_with_rssi_evt(hdev, skb);
3603 case HCI_EV_REMOTE_EXT_FEATURES:
3604 hci_remote_ext_features_evt(hdev, skb);
3607 case HCI_EV_SYNC_CONN_COMPLETE:
3608 hci_sync_conn_complete_evt(hdev, skb);
3611 case HCI_EV_SYNC_CONN_CHANGED:
3612 hci_sync_conn_changed_evt(hdev, skb);
3615 case HCI_EV_SNIFF_SUBRATE:
3616 hci_sniff_subrate_evt(hdev, skb);
3619 case HCI_EV_EXTENDED_INQUIRY_RESULT:
3620 hci_extended_inquiry_result_evt(hdev, skb);
3623 case HCI_EV_KEY_REFRESH_COMPLETE:
3624 hci_key_refresh_complete_evt(hdev, skb);
3627 case HCI_EV_IO_CAPA_REQUEST:
3628 hci_io_capa_request_evt(hdev, skb);
3631 case HCI_EV_IO_CAPA_REPLY:
3632 hci_io_capa_reply_evt(hdev, skb);
3635 case HCI_EV_USER_CONFIRM_REQUEST:
3636 hci_user_confirm_request_evt(hdev, skb);
3639 case HCI_EV_USER_PASSKEY_REQUEST:
3640 hci_user_passkey_request_evt(hdev, skb);
3643 case HCI_EV_SIMPLE_PAIR_COMPLETE:
3644 hci_simple_pair_complete_evt(hdev, skb);
3647 case HCI_EV_REMOTE_HOST_FEATURES:
3648 hci_remote_host_features_evt(hdev, skb);
3651 case HCI_EV_LE_META:
3652 hci_le_meta_evt(hdev, skb);
3655 case HCI_EV_REMOTE_OOB_DATA_REQUEST:
3656 hci_remote_oob_data_request_evt(hdev, skb);
3659 case HCI_EV_NUM_COMP_BLOCKS:
3660 hci_num_comp_blocks_evt(hdev, skb);
3664 BT_DBG("%s event 0x%2.2x", hdev->name, event);
3669 hdev->stat.evt_rx++;