nfc: fix potential NULL pointer deref in nfc_genl_dump_ses_done
[platform/kernel/linux-rpi.git] / net / nfc / netlink.c
1 // SPDX-License-Identifier: GPL-2.0-or-later
2 /*
3  * Copyright (C) 2011 Instituto Nokia de Tecnologia
4  *
5  * Authors:
6  *    Lauro Ramos Venancio <lauro.venancio@openbossa.org>
7  *    Aloisio Almeida Jr <aloisio.almeida@openbossa.org>
8  *
9  * Vendor commands implementation based on net/wireless/nl80211.c
10  * which is:
11  *
12  * Copyright 2006-2010  Johannes Berg <johannes@sipsolutions.net>
13  * Copyright 2013-2014  Intel Mobile Communications GmbH
14  */
15
16 #define pr_fmt(fmt) KBUILD_MODNAME ": %s: " fmt, __func__
17
18 #include <net/genetlink.h>
19 #include <linux/nfc.h>
20 #include <linux/slab.h>
21
22 #include "nfc.h"
23 #include "llcp.h"
24
25 static const struct genl_multicast_group nfc_genl_mcgrps[] = {
26         { .name = NFC_GENL_MCAST_EVENT_NAME, },
27 };
28
29 static struct genl_family nfc_genl_family;
30 static const struct nla_policy nfc_genl_policy[NFC_ATTR_MAX + 1] = {
31         [NFC_ATTR_DEVICE_INDEX] = { .type = NLA_U32 },
32         [NFC_ATTR_DEVICE_NAME] = { .type = NLA_STRING,
33                                 .len = NFC_DEVICE_NAME_MAXSIZE },
34         [NFC_ATTR_PROTOCOLS] = { .type = NLA_U32 },
35         [NFC_ATTR_TARGET_INDEX] = { .type = NLA_U32 },
36         [NFC_ATTR_COMM_MODE] = { .type = NLA_U8 },
37         [NFC_ATTR_RF_MODE] = { .type = NLA_U8 },
38         [NFC_ATTR_DEVICE_POWERED] = { .type = NLA_U8 },
39         [NFC_ATTR_IM_PROTOCOLS] = { .type = NLA_U32 },
40         [NFC_ATTR_TM_PROTOCOLS] = { .type = NLA_U32 },
41         [NFC_ATTR_LLC_PARAM_LTO] = { .type = NLA_U8 },
42         [NFC_ATTR_LLC_PARAM_RW] = { .type = NLA_U8 },
43         [NFC_ATTR_LLC_PARAM_MIUX] = { .type = NLA_U16 },
44         [NFC_ATTR_LLC_SDP] = { .type = NLA_NESTED },
45         [NFC_ATTR_FIRMWARE_NAME] = { .type = NLA_STRING,
46                                      .len = NFC_FIRMWARE_NAME_MAXSIZE },
47         [NFC_ATTR_SE_INDEX] = { .type = NLA_U32 },
48         [NFC_ATTR_SE_APDU] = { .type = NLA_BINARY },
49         [NFC_ATTR_VENDOR_ID] = { .type = NLA_U32 },
50         [NFC_ATTR_VENDOR_SUBCMD] = { .type = NLA_U32 },
51         [NFC_ATTR_VENDOR_DATA] = { .type = NLA_BINARY },
52
53 };
54
55 static const struct nla_policy nfc_sdp_genl_policy[NFC_SDP_ATTR_MAX + 1] = {
56         [NFC_SDP_ATTR_URI] = { .type = NLA_STRING,
57                                .len = U8_MAX - 4 },
58         [NFC_SDP_ATTR_SAP] = { .type = NLA_U8 },
59 };
60
61 static int nfc_genl_send_target(struct sk_buff *msg, struct nfc_target *target,
62                                 struct netlink_callback *cb, int flags)
63 {
64         void *hdr;
65
66         hdr = genlmsg_put(msg, NETLINK_CB(cb->skb).portid, cb->nlh->nlmsg_seq,
67                           &nfc_genl_family, flags, NFC_CMD_GET_TARGET);
68         if (!hdr)
69                 return -EMSGSIZE;
70
71         genl_dump_check_consistent(cb, hdr);
72
73         if (nla_put_u32(msg, NFC_ATTR_TARGET_INDEX, target->idx) ||
74             nla_put_u32(msg, NFC_ATTR_PROTOCOLS, target->supported_protocols) ||
75             nla_put_u16(msg, NFC_ATTR_TARGET_SENS_RES, target->sens_res) ||
76             nla_put_u8(msg, NFC_ATTR_TARGET_SEL_RES, target->sel_res))
77                 goto nla_put_failure;
78         if (target->nfcid1_len > 0 &&
79             nla_put(msg, NFC_ATTR_TARGET_NFCID1, target->nfcid1_len,
80                     target->nfcid1))
81                 goto nla_put_failure;
82         if (target->sensb_res_len > 0 &&
83             nla_put(msg, NFC_ATTR_TARGET_SENSB_RES, target->sensb_res_len,
84                     target->sensb_res))
85                 goto nla_put_failure;
86         if (target->sensf_res_len > 0 &&
87             nla_put(msg, NFC_ATTR_TARGET_SENSF_RES, target->sensf_res_len,
88                     target->sensf_res))
89                 goto nla_put_failure;
90
91         if (target->is_iso15693) {
92                 if (nla_put_u8(msg, NFC_ATTR_TARGET_ISO15693_DSFID,
93                                target->iso15693_dsfid) ||
94                     nla_put(msg, NFC_ATTR_TARGET_ISO15693_UID,
95                             sizeof(target->iso15693_uid), target->iso15693_uid))
96                         goto nla_put_failure;
97         }
98
99         genlmsg_end(msg, hdr);
100         return 0;
101
102 nla_put_failure:
103         genlmsg_cancel(msg, hdr);
104         return -EMSGSIZE;
105 }
106
107 static struct nfc_dev *__get_device_from_cb(struct netlink_callback *cb)
108 {
109         const struct genl_dumpit_info *info = genl_dumpit_info(cb);
110         struct nfc_dev *dev;
111         u32 idx;
112
113         if (!info->attrs[NFC_ATTR_DEVICE_INDEX])
114                 return ERR_PTR(-EINVAL);
115
116         idx = nla_get_u32(info->attrs[NFC_ATTR_DEVICE_INDEX]);
117
118         dev = nfc_get_device(idx);
119         if (!dev)
120                 return ERR_PTR(-ENODEV);
121
122         return dev;
123 }
124
125 static int nfc_genl_dump_targets(struct sk_buff *skb,
126                                  struct netlink_callback *cb)
127 {
128         int i = cb->args[0];
129         struct nfc_dev *dev = (struct nfc_dev *) cb->args[1];
130         int rc;
131
132         if (!dev) {
133                 dev = __get_device_from_cb(cb);
134                 if (IS_ERR(dev))
135                         return PTR_ERR(dev);
136
137                 cb->args[1] = (long) dev;
138         }
139
140         device_lock(&dev->dev);
141
142         cb->seq = dev->targets_generation;
143
144         while (i < dev->n_targets) {
145                 rc = nfc_genl_send_target(skb, &dev->targets[i], cb,
146                                           NLM_F_MULTI);
147                 if (rc < 0)
148                         break;
149
150                 i++;
151         }
152
153         device_unlock(&dev->dev);
154
155         cb->args[0] = i;
156
157         return skb->len;
158 }
159
160 static int nfc_genl_dump_targets_done(struct netlink_callback *cb)
161 {
162         struct nfc_dev *dev = (struct nfc_dev *) cb->args[1];
163
164         if (dev)
165                 nfc_put_device(dev);
166
167         return 0;
168 }
169
170 int nfc_genl_targets_found(struct nfc_dev *dev)
171 {
172         struct sk_buff *msg;
173         void *hdr;
174
175         dev->genl_data.poll_req_portid = 0;
176
177         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_ATOMIC);
178         if (!msg)
179                 return -ENOMEM;
180
181         hdr = genlmsg_put(msg, 0, 0, &nfc_genl_family, 0,
182                           NFC_EVENT_TARGETS_FOUND);
183         if (!hdr)
184                 goto free_msg;
185
186         if (nla_put_u32(msg, NFC_ATTR_DEVICE_INDEX, dev->idx))
187                 goto nla_put_failure;
188
189         genlmsg_end(msg, hdr);
190
191         return genlmsg_multicast(&nfc_genl_family, msg, 0, 0, GFP_ATOMIC);
192
193 nla_put_failure:
194 free_msg:
195         nlmsg_free(msg);
196         return -EMSGSIZE;
197 }
198
199 int nfc_genl_target_lost(struct nfc_dev *dev, u32 target_idx)
200 {
201         struct sk_buff *msg;
202         void *hdr;
203
204         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
205         if (!msg)
206                 return -ENOMEM;
207
208         hdr = genlmsg_put(msg, 0, 0, &nfc_genl_family, 0,
209                           NFC_EVENT_TARGET_LOST);
210         if (!hdr)
211                 goto free_msg;
212
213         if (nla_put_string(msg, NFC_ATTR_DEVICE_NAME, nfc_device_name(dev)) ||
214             nla_put_u32(msg, NFC_ATTR_TARGET_INDEX, target_idx))
215                 goto nla_put_failure;
216
217         genlmsg_end(msg, hdr);
218
219         genlmsg_multicast(&nfc_genl_family, msg, 0, 0, GFP_KERNEL);
220
221         return 0;
222
223 nla_put_failure:
224 free_msg:
225         nlmsg_free(msg);
226         return -EMSGSIZE;
227 }
228
229 int nfc_genl_tm_activated(struct nfc_dev *dev, u32 protocol)
230 {
231         struct sk_buff *msg;
232         void *hdr;
233
234         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
235         if (!msg)
236                 return -ENOMEM;
237
238         hdr = genlmsg_put(msg, 0, 0, &nfc_genl_family, 0,
239                           NFC_EVENT_TM_ACTIVATED);
240         if (!hdr)
241                 goto free_msg;
242
243         if (nla_put_u32(msg, NFC_ATTR_DEVICE_INDEX, dev->idx))
244                 goto nla_put_failure;
245         if (nla_put_u32(msg, NFC_ATTR_TM_PROTOCOLS, protocol))
246                 goto nla_put_failure;
247
248         genlmsg_end(msg, hdr);
249
250         genlmsg_multicast(&nfc_genl_family, msg, 0, 0, GFP_KERNEL);
251
252         return 0;
253
254 nla_put_failure:
255 free_msg:
256         nlmsg_free(msg);
257         return -EMSGSIZE;
258 }
259
260 int nfc_genl_tm_deactivated(struct nfc_dev *dev)
261 {
262         struct sk_buff *msg;
263         void *hdr;
264
265         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
266         if (!msg)
267                 return -ENOMEM;
268
269         hdr = genlmsg_put(msg, 0, 0, &nfc_genl_family, 0,
270                           NFC_EVENT_TM_DEACTIVATED);
271         if (!hdr)
272                 goto free_msg;
273
274         if (nla_put_u32(msg, NFC_ATTR_DEVICE_INDEX, dev->idx))
275                 goto nla_put_failure;
276
277         genlmsg_end(msg, hdr);
278
279         genlmsg_multicast(&nfc_genl_family, msg, 0, 0, GFP_KERNEL);
280
281         return 0;
282
283 nla_put_failure:
284 free_msg:
285         nlmsg_free(msg);
286         return -EMSGSIZE;
287 }
288
289 static int nfc_genl_setup_device_added(struct nfc_dev *dev, struct sk_buff *msg)
290 {
291         if (nla_put_string(msg, NFC_ATTR_DEVICE_NAME, nfc_device_name(dev)) ||
292             nla_put_u32(msg, NFC_ATTR_DEVICE_INDEX, dev->idx) ||
293             nla_put_u32(msg, NFC_ATTR_PROTOCOLS, dev->supported_protocols) ||
294             nla_put_u8(msg, NFC_ATTR_DEVICE_POWERED, dev->dev_up) ||
295             nla_put_u8(msg, NFC_ATTR_RF_MODE, dev->rf_mode))
296                 return -1;
297         return 0;
298 }
299
300 int nfc_genl_device_added(struct nfc_dev *dev)
301 {
302         struct sk_buff *msg;
303         void *hdr;
304
305         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
306         if (!msg)
307                 return -ENOMEM;
308
309         hdr = genlmsg_put(msg, 0, 0, &nfc_genl_family, 0,
310                           NFC_EVENT_DEVICE_ADDED);
311         if (!hdr)
312                 goto free_msg;
313
314         if (nfc_genl_setup_device_added(dev, msg))
315                 goto nla_put_failure;
316
317         genlmsg_end(msg, hdr);
318
319         genlmsg_multicast(&nfc_genl_family, msg, 0, 0, GFP_KERNEL);
320
321         return 0;
322
323 nla_put_failure:
324 free_msg:
325         nlmsg_free(msg);
326         return -EMSGSIZE;
327 }
328
329 int nfc_genl_device_removed(struct nfc_dev *dev)
330 {
331         struct sk_buff *msg;
332         void *hdr;
333
334         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
335         if (!msg)
336                 return -ENOMEM;
337
338         hdr = genlmsg_put(msg, 0, 0, &nfc_genl_family, 0,
339                           NFC_EVENT_DEVICE_REMOVED);
340         if (!hdr)
341                 goto free_msg;
342
343         if (nla_put_u32(msg, NFC_ATTR_DEVICE_INDEX, dev->idx))
344                 goto nla_put_failure;
345
346         genlmsg_end(msg, hdr);
347
348         genlmsg_multicast(&nfc_genl_family, msg, 0, 0, GFP_KERNEL);
349
350         return 0;
351
352 nla_put_failure:
353 free_msg:
354         nlmsg_free(msg);
355         return -EMSGSIZE;
356 }
357
358 int nfc_genl_llc_send_sdres(struct nfc_dev *dev, struct hlist_head *sdres_list)
359 {
360         struct sk_buff *msg;
361         struct nlattr *sdp_attr, *uri_attr;
362         struct nfc_llcp_sdp_tlv *sdres;
363         struct hlist_node *n;
364         void *hdr;
365         int rc = -EMSGSIZE;
366         int i;
367
368         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
369         if (!msg)
370                 return -ENOMEM;
371
372         hdr = genlmsg_put(msg, 0, 0, &nfc_genl_family, 0,
373                           NFC_EVENT_LLC_SDRES);
374         if (!hdr)
375                 goto free_msg;
376
377         if (nla_put_u32(msg, NFC_ATTR_DEVICE_INDEX, dev->idx))
378                 goto nla_put_failure;
379
380         sdp_attr = nla_nest_start_noflag(msg, NFC_ATTR_LLC_SDP);
381         if (sdp_attr == NULL) {
382                 rc = -ENOMEM;
383                 goto nla_put_failure;
384         }
385
386         i = 1;
387         hlist_for_each_entry_safe(sdres, n, sdres_list, node) {
388                 pr_debug("uri: %s, sap: %d\n", sdres->uri, sdres->sap);
389
390                 uri_attr = nla_nest_start_noflag(msg, i++);
391                 if (uri_attr == NULL) {
392                         rc = -ENOMEM;
393                         goto nla_put_failure;
394                 }
395
396                 if (nla_put_u8(msg, NFC_SDP_ATTR_SAP, sdres->sap))
397                         goto nla_put_failure;
398
399                 if (nla_put_string(msg, NFC_SDP_ATTR_URI, sdres->uri))
400                         goto nla_put_failure;
401
402                 nla_nest_end(msg, uri_attr);
403
404                 hlist_del(&sdres->node);
405
406                 nfc_llcp_free_sdp_tlv(sdres);
407         }
408
409         nla_nest_end(msg, sdp_attr);
410
411         genlmsg_end(msg, hdr);
412
413         return genlmsg_multicast(&nfc_genl_family, msg, 0, 0, GFP_ATOMIC);
414
415 nla_put_failure:
416 free_msg:
417         nlmsg_free(msg);
418
419         nfc_llcp_free_sdp_tlv_list(sdres_list);
420
421         return rc;
422 }
423
424 int nfc_genl_se_added(struct nfc_dev *dev, u32 se_idx, u16 type)
425 {
426         struct sk_buff *msg;
427         void *hdr;
428
429         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
430         if (!msg)
431                 return -ENOMEM;
432
433         hdr = genlmsg_put(msg, 0, 0, &nfc_genl_family, 0,
434                           NFC_EVENT_SE_ADDED);
435         if (!hdr)
436                 goto free_msg;
437
438         if (nla_put_u32(msg, NFC_ATTR_DEVICE_INDEX, dev->idx) ||
439             nla_put_u32(msg, NFC_ATTR_SE_INDEX, se_idx) ||
440             nla_put_u8(msg, NFC_ATTR_SE_TYPE, type))
441                 goto nla_put_failure;
442
443         genlmsg_end(msg, hdr);
444
445         genlmsg_multicast(&nfc_genl_family, msg, 0, 0, GFP_KERNEL);
446
447         return 0;
448
449 nla_put_failure:
450 free_msg:
451         nlmsg_free(msg);
452         return -EMSGSIZE;
453 }
454
455 int nfc_genl_se_removed(struct nfc_dev *dev, u32 se_idx)
456 {
457         struct sk_buff *msg;
458         void *hdr;
459
460         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
461         if (!msg)
462                 return -ENOMEM;
463
464         hdr = genlmsg_put(msg, 0, 0, &nfc_genl_family, 0,
465                           NFC_EVENT_SE_REMOVED);
466         if (!hdr)
467                 goto free_msg;
468
469         if (nla_put_u32(msg, NFC_ATTR_DEVICE_INDEX, dev->idx) ||
470             nla_put_u32(msg, NFC_ATTR_SE_INDEX, se_idx))
471                 goto nla_put_failure;
472
473         genlmsg_end(msg, hdr);
474
475         genlmsg_multicast(&nfc_genl_family, msg, 0, 0, GFP_KERNEL);
476
477         return 0;
478
479 nla_put_failure:
480 free_msg:
481         nlmsg_free(msg);
482         return -EMSGSIZE;
483 }
484
485 int nfc_genl_se_transaction(struct nfc_dev *dev, u8 se_idx,
486                             struct nfc_evt_transaction *evt_transaction)
487 {
488         struct nfc_se *se;
489         struct sk_buff *msg;
490         void *hdr;
491
492         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
493         if (!msg)
494                 return -ENOMEM;
495
496         hdr = genlmsg_put(msg, 0, 0, &nfc_genl_family, 0,
497                           NFC_EVENT_SE_TRANSACTION);
498         if (!hdr)
499                 goto free_msg;
500
501         se = nfc_find_se(dev, se_idx);
502         if (!se)
503                 goto free_msg;
504
505         if (nla_put_u32(msg, NFC_ATTR_DEVICE_INDEX, dev->idx) ||
506             nla_put_u32(msg, NFC_ATTR_SE_INDEX, se_idx) ||
507             nla_put_u8(msg, NFC_ATTR_SE_TYPE, se->type) ||
508             nla_put(msg, NFC_ATTR_SE_AID, evt_transaction->aid_len,
509                     evt_transaction->aid) ||
510             nla_put(msg, NFC_ATTR_SE_PARAMS, evt_transaction->params_len,
511                     evt_transaction->params))
512                 goto nla_put_failure;
513
514         /* evt_transaction is no more used */
515         devm_kfree(&dev->dev, evt_transaction);
516
517         genlmsg_end(msg, hdr);
518
519         genlmsg_multicast(&nfc_genl_family, msg, 0, 0, GFP_KERNEL);
520
521         return 0;
522
523 nla_put_failure:
524 free_msg:
525         /* evt_transaction is no more used */
526         devm_kfree(&dev->dev, evt_transaction);
527         nlmsg_free(msg);
528         return -EMSGSIZE;
529 }
530
531 int nfc_genl_se_connectivity(struct nfc_dev *dev, u8 se_idx)
532 {
533         const struct nfc_se *se;
534         struct sk_buff *msg;
535         void *hdr;
536
537         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
538         if (!msg)
539                 return -ENOMEM;
540
541         hdr = genlmsg_put(msg, 0, 0, &nfc_genl_family, 0,
542                           NFC_EVENT_SE_CONNECTIVITY);
543         if (!hdr)
544                 goto free_msg;
545
546         se = nfc_find_se(dev, se_idx);
547         if (!se)
548                 goto free_msg;
549
550         if (nla_put_u32(msg, NFC_ATTR_DEVICE_INDEX, dev->idx) ||
551             nla_put_u32(msg, NFC_ATTR_SE_INDEX, se_idx) ||
552             nla_put_u8(msg, NFC_ATTR_SE_TYPE, se->type))
553                 goto nla_put_failure;
554
555         genlmsg_end(msg, hdr);
556
557         genlmsg_multicast(&nfc_genl_family, msg, 0, 0, GFP_KERNEL);
558
559         return 0;
560
561 nla_put_failure:
562 free_msg:
563         nlmsg_free(msg);
564         return -EMSGSIZE;
565 }
566
567 static int nfc_genl_send_device(struct sk_buff *msg, struct nfc_dev *dev,
568                                 u32 portid, u32 seq,
569                                 struct netlink_callback *cb,
570                                 int flags)
571 {
572         void *hdr;
573
574         hdr = genlmsg_put(msg, portid, seq, &nfc_genl_family, flags,
575                           NFC_CMD_GET_DEVICE);
576         if (!hdr)
577                 return -EMSGSIZE;
578
579         if (cb)
580                 genl_dump_check_consistent(cb, hdr);
581
582         if (nfc_genl_setup_device_added(dev, msg))
583                 goto nla_put_failure;
584
585         genlmsg_end(msg, hdr);
586         return 0;
587
588 nla_put_failure:
589         genlmsg_cancel(msg, hdr);
590         return -EMSGSIZE;
591 }
592
593 static int nfc_genl_dump_devices(struct sk_buff *skb,
594                                  struct netlink_callback *cb)
595 {
596         struct class_dev_iter *iter = (struct class_dev_iter *) cb->args[0];
597         struct nfc_dev *dev = (struct nfc_dev *) cb->args[1];
598         bool first_call = false;
599
600         if (!iter) {
601                 first_call = true;
602                 iter = kmalloc(sizeof(struct class_dev_iter), GFP_KERNEL);
603                 if (!iter)
604                         return -ENOMEM;
605                 cb->args[0] = (long) iter;
606         }
607
608         mutex_lock(&nfc_devlist_mutex);
609
610         cb->seq = nfc_devlist_generation;
611
612         if (first_call) {
613                 nfc_device_iter_init(iter);
614                 dev = nfc_device_iter_next(iter);
615         }
616
617         while (dev) {
618                 int rc;
619
620                 rc = nfc_genl_send_device(skb, dev, NETLINK_CB(cb->skb).portid,
621                                           cb->nlh->nlmsg_seq, cb, NLM_F_MULTI);
622                 if (rc < 0)
623                         break;
624
625                 dev = nfc_device_iter_next(iter);
626         }
627
628         mutex_unlock(&nfc_devlist_mutex);
629
630         cb->args[1] = (long) dev;
631
632         return skb->len;
633 }
634
635 static int nfc_genl_dump_devices_done(struct netlink_callback *cb)
636 {
637         struct class_dev_iter *iter = (struct class_dev_iter *) cb->args[0];
638
639         nfc_device_iter_exit(iter);
640         kfree(iter);
641
642         return 0;
643 }
644
645 int nfc_genl_dep_link_up_event(struct nfc_dev *dev, u32 target_idx,
646                                u8 comm_mode, u8 rf_mode)
647 {
648         struct sk_buff *msg;
649         void *hdr;
650
651         pr_debug("DEP link is up\n");
652
653         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_ATOMIC);
654         if (!msg)
655                 return -ENOMEM;
656
657         hdr = genlmsg_put(msg, 0, 0, &nfc_genl_family, 0, NFC_CMD_DEP_LINK_UP);
658         if (!hdr)
659                 goto free_msg;
660
661         if (nla_put_u32(msg, NFC_ATTR_DEVICE_INDEX, dev->idx))
662                 goto nla_put_failure;
663         if (rf_mode == NFC_RF_INITIATOR &&
664             nla_put_u32(msg, NFC_ATTR_TARGET_INDEX, target_idx))
665                 goto nla_put_failure;
666         if (nla_put_u8(msg, NFC_ATTR_COMM_MODE, comm_mode) ||
667             nla_put_u8(msg, NFC_ATTR_RF_MODE, rf_mode))
668                 goto nla_put_failure;
669
670         genlmsg_end(msg, hdr);
671
672         dev->dep_link_up = true;
673
674         genlmsg_multicast(&nfc_genl_family, msg, 0, 0, GFP_ATOMIC);
675
676         return 0;
677
678 nla_put_failure:
679 free_msg:
680         nlmsg_free(msg);
681         return -EMSGSIZE;
682 }
683
684 int nfc_genl_dep_link_down_event(struct nfc_dev *dev)
685 {
686         struct sk_buff *msg;
687         void *hdr;
688
689         pr_debug("DEP link is down\n");
690
691         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_ATOMIC);
692         if (!msg)
693                 return -ENOMEM;
694
695         hdr = genlmsg_put(msg, 0, 0, &nfc_genl_family, 0,
696                           NFC_CMD_DEP_LINK_DOWN);
697         if (!hdr)
698                 goto free_msg;
699
700         if (nla_put_u32(msg, NFC_ATTR_DEVICE_INDEX, dev->idx))
701                 goto nla_put_failure;
702
703         genlmsg_end(msg, hdr);
704
705         genlmsg_multicast(&nfc_genl_family, msg, 0, 0, GFP_ATOMIC);
706
707         return 0;
708
709 nla_put_failure:
710 free_msg:
711         nlmsg_free(msg);
712         return -EMSGSIZE;
713 }
714
715 static int nfc_genl_get_device(struct sk_buff *skb, struct genl_info *info)
716 {
717         struct sk_buff *msg;
718         struct nfc_dev *dev;
719         u32 idx;
720         int rc = -ENOBUFS;
721
722         if (!info->attrs[NFC_ATTR_DEVICE_INDEX])
723                 return -EINVAL;
724
725         idx = nla_get_u32(info->attrs[NFC_ATTR_DEVICE_INDEX]);
726
727         dev = nfc_get_device(idx);
728         if (!dev)
729                 return -ENODEV;
730
731         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
732         if (!msg) {
733                 rc = -ENOMEM;
734                 goto out_putdev;
735         }
736
737         rc = nfc_genl_send_device(msg, dev, info->snd_portid, info->snd_seq,
738                                   NULL, 0);
739         if (rc < 0)
740                 goto out_free;
741
742         nfc_put_device(dev);
743
744         return genlmsg_reply(msg, info);
745
746 out_free:
747         nlmsg_free(msg);
748 out_putdev:
749         nfc_put_device(dev);
750         return rc;
751 }
752
753 static int nfc_genl_dev_up(struct sk_buff *skb, struct genl_info *info)
754 {
755         struct nfc_dev *dev;
756         int rc;
757         u32 idx;
758
759         if (!info->attrs[NFC_ATTR_DEVICE_INDEX])
760                 return -EINVAL;
761
762         idx = nla_get_u32(info->attrs[NFC_ATTR_DEVICE_INDEX]);
763
764         dev = nfc_get_device(idx);
765         if (!dev)
766                 return -ENODEV;
767
768         rc = nfc_dev_up(dev);
769
770         nfc_put_device(dev);
771         return rc;
772 }
773
774 static int nfc_genl_dev_down(struct sk_buff *skb, struct genl_info *info)
775 {
776         struct nfc_dev *dev;
777         int rc;
778         u32 idx;
779
780         if (!info->attrs[NFC_ATTR_DEVICE_INDEX])
781                 return -EINVAL;
782
783         idx = nla_get_u32(info->attrs[NFC_ATTR_DEVICE_INDEX]);
784
785         dev = nfc_get_device(idx);
786         if (!dev)
787                 return -ENODEV;
788
789         rc = nfc_dev_down(dev);
790
791         nfc_put_device(dev);
792         return rc;
793 }
794
795 static int nfc_genl_start_poll(struct sk_buff *skb, struct genl_info *info)
796 {
797         struct nfc_dev *dev;
798         int rc;
799         u32 idx;
800         u32 im_protocols = 0, tm_protocols = 0;
801
802         pr_debug("Poll start\n");
803
804         if (!info->attrs[NFC_ATTR_DEVICE_INDEX] ||
805             ((!info->attrs[NFC_ATTR_IM_PROTOCOLS] &&
806               !info->attrs[NFC_ATTR_PROTOCOLS]) &&
807               !info->attrs[NFC_ATTR_TM_PROTOCOLS]))
808                 return -EINVAL;
809
810         idx = nla_get_u32(info->attrs[NFC_ATTR_DEVICE_INDEX]);
811
812         if (info->attrs[NFC_ATTR_TM_PROTOCOLS])
813                 tm_protocols = nla_get_u32(info->attrs[NFC_ATTR_TM_PROTOCOLS]);
814
815         if (info->attrs[NFC_ATTR_IM_PROTOCOLS])
816                 im_protocols = nla_get_u32(info->attrs[NFC_ATTR_IM_PROTOCOLS]);
817         else if (info->attrs[NFC_ATTR_PROTOCOLS])
818                 im_protocols = nla_get_u32(info->attrs[NFC_ATTR_PROTOCOLS]);
819
820         dev = nfc_get_device(idx);
821         if (!dev)
822                 return -ENODEV;
823
824         mutex_lock(&dev->genl_data.genl_data_mutex);
825
826         rc = nfc_start_poll(dev, im_protocols, tm_protocols);
827         if (!rc)
828                 dev->genl_data.poll_req_portid = info->snd_portid;
829
830         mutex_unlock(&dev->genl_data.genl_data_mutex);
831
832         nfc_put_device(dev);
833         return rc;
834 }
835
836 static int nfc_genl_stop_poll(struct sk_buff *skb, struct genl_info *info)
837 {
838         struct nfc_dev *dev;
839         int rc;
840         u32 idx;
841
842         if (!info->attrs[NFC_ATTR_DEVICE_INDEX])
843                 return -EINVAL;
844
845         idx = nla_get_u32(info->attrs[NFC_ATTR_DEVICE_INDEX]);
846
847         dev = nfc_get_device(idx);
848         if (!dev)
849                 return -ENODEV;
850
851         device_lock(&dev->dev);
852
853         if (!dev->polling) {
854                 device_unlock(&dev->dev);
855                 nfc_put_device(dev);
856                 return -EINVAL;
857         }
858
859         device_unlock(&dev->dev);
860
861         mutex_lock(&dev->genl_data.genl_data_mutex);
862
863         if (dev->genl_data.poll_req_portid != info->snd_portid) {
864                 rc = -EBUSY;
865                 goto out;
866         }
867
868         rc = nfc_stop_poll(dev);
869         dev->genl_data.poll_req_portid = 0;
870
871 out:
872         mutex_unlock(&dev->genl_data.genl_data_mutex);
873         nfc_put_device(dev);
874         return rc;
875 }
876
877 static int nfc_genl_activate_target(struct sk_buff *skb, struct genl_info *info)
878 {
879         struct nfc_dev *dev;
880         u32 device_idx, target_idx, protocol;
881         int rc;
882
883         if (!info->attrs[NFC_ATTR_DEVICE_INDEX] ||
884             !info->attrs[NFC_ATTR_TARGET_INDEX] ||
885             !info->attrs[NFC_ATTR_PROTOCOLS])
886                 return -EINVAL;
887
888         device_idx = nla_get_u32(info->attrs[NFC_ATTR_DEVICE_INDEX]);
889
890         dev = nfc_get_device(device_idx);
891         if (!dev)
892                 return -ENODEV;
893
894         target_idx = nla_get_u32(info->attrs[NFC_ATTR_TARGET_INDEX]);
895         protocol = nla_get_u32(info->attrs[NFC_ATTR_PROTOCOLS]);
896
897         nfc_deactivate_target(dev, target_idx, NFC_TARGET_MODE_SLEEP);
898         rc = nfc_activate_target(dev, target_idx, protocol);
899
900         nfc_put_device(dev);
901         return rc;
902 }
903
904 static int nfc_genl_deactivate_target(struct sk_buff *skb,
905                                       struct genl_info *info)
906 {
907         struct nfc_dev *dev;
908         u32 device_idx, target_idx;
909         int rc;
910
911         if (!info->attrs[NFC_ATTR_DEVICE_INDEX] ||
912             !info->attrs[NFC_ATTR_TARGET_INDEX])
913                 return -EINVAL;
914
915         device_idx = nla_get_u32(info->attrs[NFC_ATTR_DEVICE_INDEX]);
916
917         dev = nfc_get_device(device_idx);
918         if (!dev)
919                 return -ENODEV;
920
921         target_idx = nla_get_u32(info->attrs[NFC_ATTR_TARGET_INDEX]);
922
923         rc = nfc_deactivate_target(dev, target_idx, NFC_TARGET_MODE_SLEEP);
924
925         nfc_put_device(dev);
926         return rc;
927 }
928
929 static int nfc_genl_dep_link_up(struct sk_buff *skb, struct genl_info *info)
930 {
931         struct nfc_dev *dev;
932         int rc, tgt_idx;
933         u32 idx;
934         u8 comm;
935
936         pr_debug("DEP link up\n");
937
938         if (!info->attrs[NFC_ATTR_DEVICE_INDEX] ||
939             !info->attrs[NFC_ATTR_COMM_MODE])
940                 return -EINVAL;
941
942         idx = nla_get_u32(info->attrs[NFC_ATTR_DEVICE_INDEX]);
943         if (!info->attrs[NFC_ATTR_TARGET_INDEX])
944                 tgt_idx = NFC_TARGET_IDX_ANY;
945         else
946                 tgt_idx = nla_get_u32(info->attrs[NFC_ATTR_TARGET_INDEX]);
947
948         comm = nla_get_u8(info->attrs[NFC_ATTR_COMM_MODE]);
949
950         if (comm != NFC_COMM_ACTIVE && comm != NFC_COMM_PASSIVE)
951                 return -EINVAL;
952
953         dev = nfc_get_device(idx);
954         if (!dev)
955                 return -ENODEV;
956
957         rc = nfc_dep_link_up(dev, tgt_idx, comm);
958
959         nfc_put_device(dev);
960
961         return rc;
962 }
963
964 static int nfc_genl_dep_link_down(struct sk_buff *skb, struct genl_info *info)
965 {
966         struct nfc_dev *dev;
967         int rc;
968         u32 idx;
969
970         if (!info->attrs[NFC_ATTR_DEVICE_INDEX] ||
971             !info->attrs[NFC_ATTR_TARGET_INDEX])
972                 return -EINVAL;
973
974         idx = nla_get_u32(info->attrs[NFC_ATTR_DEVICE_INDEX]);
975
976         dev = nfc_get_device(idx);
977         if (!dev)
978                 return -ENODEV;
979
980         rc = nfc_dep_link_down(dev);
981
982         nfc_put_device(dev);
983         return rc;
984 }
985
986 static int nfc_genl_send_params(struct sk_buff *msg,
987                                 struct nfc_llcp_local *local,
988                                 u32 portid, u32 seq)
989 {
990         void *hdr;
991
992         hdr = genlmsg_put(msg, portid, seq, &nfc_genl_family, 0,
993                           NFC_CMD_LLC_GET_PARAMS);
994         if (!hdr)
995                 return -EMSGSIZE;
996
997         if (nla_put_u32(msg, NFC_ATTR_DEVICE_INDEX, local->dev->idx) ||
998             nla_put_u8(msg, NFC_ATTR_LLC_PARAM_LTO, local->lto) ||
999             nla_put_u8(msg, NFC_ATTR_LLC_PARAM_RW, local->rw) ||
1000             nla_put_u16(msg, NFC_ATTR_LLC_PARAM_MIUX, be16_to_cpu(local->miux)))
1001                 goto nla_put_failure;
1002
1003         genlmsg_end(msg, hdr);
1004         return 0;
1005
1006 nla_put_failure:
1007         genlmsg_cancel(msg, hdr);
1008         return -EMSGSIZE;
1009 }
1010
1011 static int nfc_genl_llc_get_params(struct sk_buff *skb, struct genl_info *info)
1012 {
1013         struct nfc_dev *dev;
1014         struct nfc_llcp_local *local;
1015         int rc = 0;
1016         struct sk_buff *msg = NULL;
1017         u32 idx;
1018
1019         if (!info->attrs[NFC_ATTR_DEVICE_INDEX] ||
1020             !info->attrs[NFC_ATTR_FIRMWARE_NAME])
1021                 return -EINVAL;
1022
1023         idx = nla_get_u32(info->attrs[NFC_ATTR_DEVICE_INDEX]);
1024
1025         dev = nfc_get_device(idx);
1026         if (!dev)
1027                 return -ENODEV;
1028
1029         device_lock(&dev->dev);
1030
1031         local = nfc_llcp_find_local(dev);
1032         if (!local) {
1033                 rc = -ENODEV;
1034                 goto exit;
1035         }
1036
1037         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
1038         if (!msg) {
1039                 rc = -ENOMEM;
1040                 goto exit;
1041         }
1042
1043         rc = nfc_genl_send_params(msg, local, info->snd_portid, info->snd_seq);
1044
1045 exit:
1046         device_unlock(&dev->dev);
1047
1048         nfc_put_device(dev);
1049
1050         if (rc < 0) {
1051                 if (msg)
1052                         nlmsg_free(msg);
1053
1054                 return rc;
1055         }
1056
1057         return genlmsg_reply(msg, info);
1058 }
1059
1060 static int nfc_genl_llc_set_params(struct sk_buff *skb, struct genl_info *info)
1061 {
1062         struct nfc_dev *dev;
1063         struct nfc_llcp_local *local;
1064         u8 rw = 0;
1065         u16 miux = 0;
1066         u32 idx;
1067         int rc = 0;
1068
1069         if (!info->attrs[NFC_ATTR_DEVICE_INDEX] ||
1070             (!info->attrs[NFC_ATTR_LLC_PARAM_LTO] &&
1071              !info->attrs[NFC_ATTR_LLC_PARAM_RW] &&
1072              !info->attrs[NFC_ATTR_LLC_PARAM_MIUX]))
1073                 return -EINVAL;
1074
1075         if (info->attrs[NFC_ATTR_LLC_PARAM_RW]) {
1076                 rw = nla_get_u8(info->attrs[NFC_ATTR_LLC_PARAM_RW]);
1077
1078                 if (rw > LLCP_MAX_RW)
1079                         return -EINVAL;
1080         }
1081
1082         if (info->attrs[NFC_ATTR_LLC_PARAM_MIUX]) {
1083                 miux = nla_get_u16(info->attrs[NFC_ATTR_LLC_PARAM_MIUX]);
1084
1085                 if (miux > LLCP_MAX_MIUX)
1086                         return -EINVAL;
1087         }
1088
1089         idx = nla_get_u32(info->attrs[NFC_ATTR_DEVICE_INDEX]);
1090
1091         dev = nfc_get_device(idx);
1092         if (!dev)
1093                 return -ENODEV;
1094
1095         device_lock(&dev->dev);
1096
1097         local = nfc_llcp_find_local(dev);
1098         if (!local) {
1099                 rc = -ENODEV;
1100                 goto exit;
1101         }
1102
1103         if (info->attrs[NFC_ATTR_LLC_PARAM_LTO]) {
1104                 if (dev->dep_link_up) {
1105                         rc = -EINPROGRESS;
1106                         goto exit;
1107                 }
1108
1109                 local->lto = nla_get_u8(info->attrs[NFC_ATTR_LLC_PARAM_LTO]);
1110         }
1111
1112         if (info->attrs[NFC_ATTR_LLC_PARAM_RW])
1113                 local->rw = rw;
1114
1115         if (info->attrs[NFC_ATTR_LLC_PARAM_MIUX])
1116                 local->miux = cpu_to_be16(miux);
1117
1118 exit:
1119         device_unlock(&dev->dev);
1120
1121         nfc_put_device(dev);
1122
1123         return rc;
1124 }
1125
1126 static int nfc_genl_llc_sdreq(struct sk_buff *skb, struct genl_info *info)
1127 {
1128         struct nfc_dev *dev;
1129         struct nfc_llcp_local *local;
1130         struct nlattr *attr, *sdp_attrs[NFC_SDP_ATTR_MAX+1];
1131         u32 idx;
1132         u8 tid;
1133         char *uri;
1134         int rc = 0, rem;
1135         size_t uri_len, tlvs_len;
1136         struct hlist_head sdreq_list;
1137         struct nfc_llcp_sdp_tlv *sdreq;
1138
1139         if (!info->attrs[NFC_ATTR_DEVICE_INDEX] ||
1140             !info->attrs[NFC_ATTR_LLC_SDP])
1141                 return -EINVAL;
1142
1143         idx = nla_get_u32(info->attrs[NFC_ATTR_DEVICE_INDEX]);
1144
1145         dev = nfc_get_device(idx);
1146         if (!dev)
1147                 return -ENODEV;
1148
1149         device_lock(&dev->dev);
1150
1151         if (dev->dep_link_up == false) {
1152                 rc = -ENOLINK;
1153                 goto exit;
1154         }
1155
1156         local = nfc_llcp_find_local(dev);
1157         if (!local) {
1158                 rc = -ENODEV;
1159                 goto exit;
1160         }
1161
1162         INIT_HLIST_HEAD(&sdreq_list);
1163
1164         tlvs_len = 0;
1165
1166         nla_for_each_nested(attr, info->attrs[NFC_ATTR_LLC_SDP], rem) {
1167                 rc = nla_parse_nested_deprecated(sdp_attrs, NFC_SDP_ATTR_MAX,
1168                                                  attr, nfc_sdp_genl_policy,
1169                                                  info->extack);
1170
1171                 if (rc != 0) {
1172                         rc = -EINVAL;
1173                         goto exit;
1174                 }
1175
1176                 if (!sdp_attrs[NFC_SDP_ATTR_URI])
1177                         continue;
1178
1179                 uri_len = nla_len(sdp_attrs[NFC_SDP_ATTR_URI]);
1180                 if (uri_len == 0)
1181                         continue;
1182
1183                 uri = nla_data(sdp_attrs[NFC_SDP_ATTR_URI]);
1184                 if (uri == NULL || *uri == 0)
1185                         continue;
1186
1187                 tid = local->sdreq_next_tid++;
1188
1189                 sdreq = nfc_llcp_build_sdreq_tlv(tid, uri, uri_len);
1190                 if (sdreq == NULL) {
1191                         rc = -ENOMEM;
1192                         goto exit;
1193                 }
1194
1195                 tlvs_len += sdreq->tlv_len;
1196
1197                 hlist_add_head(&sdreq->node, &sdreq_list);
1198         }
1199
1200         if (hlist_empty(&sdreq_list)) {
1201                 rc = -EINVAL;
1202                 goto exit;
1203         }
1204
1205         rc = nfc_llcp_send_snl_sdreq(local, &sdreq_list, tlvs_len);
1206 exit:
1207         device_unlock(&dev->dev);
1208
1209         nfc_put_device(dev);
1210
1211         return rc;
1212 }
1213
1214 static int nfc_genl_fw_download(struct sk_buff *skb, struct genl_info *info)
1215 {
1216         struct nfc_dev *dev;
1217         int rc;
1218         u32 idx;
1219         char firmware_name[NFC_FIRMWARE_NAME_MAXSIZE + 1];
1220
1221         if (!info->attrs[NFC_ATTR_DEVICE_INDEX] || !info->attrs[NFC_ATTR_FIRMWARE_NAME])
1222                 return -EINVAL;
1223
1224         idx = nla_get_u32(info->attrs[NFC_ATTR_DEVICE_INDEX]);
1225
1226         dev = nfc_get_device(idx);
1227         if (!dev)
1228                 return -ENODEV;
1229
1230         nla_strscpy(firmware_name, info->attrs[NFC_ATTR_FIRMWARE_NAME],
1231                     sizeof(firmware_name));
1232
1233         rc = nfc_fw_download(dev, firmware_name);
1234
1235         nfc_put_device(dev);
1236         return rc;
1237 }
1238
1239 int nfc_genl_fw_download_done(struct nfc_dev *dev, const char *firmware_name,
1240                               u32 result)
1241 {
1242         struct sk_buff *msg;
1243         void *hdr;
1244
1245         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
1246         if (!msg)
1247                 return -ENOMEM;
1248
1249         hdr = genlmsg_put(msg, 0, 0, &nfc_genl_family, 0,
1250                           NFC_CMD_FW_DOWNLOAD);
1251         if (!hdr)
1252                 goto free_msg;
1253
1254         if (nla_put_string(msg, NFC_ATTR_FIRMWARE_NAME, firmware_name) ||
1255             nla_put_u32(msg, NFC_ATTR_FIRMWARE_DOWNLOAD_STATUS, result) ||
1256             nla_put_u32(msg, NFC_ATTR_DEVICE_INDEX, dev->idx))
1257                 goto nla_put_failure;
1258
1259         genlmsg_end(msg, hdr);
1260
1261         genlmsg_multicast(&nfc_genl_family, msg, 0, 0, GFP_KERNEL);
1262
1263         return 0;
1264
1265 nla_put_failure:
1266 free_msg:
1267         nlmsg_free(msg);
1268         return -EMSGSIZE;
1269 }
1270
1271 static int nfc_genl_enable_se(struct sk_buff *skb, struct genl_info *info)
1272 {
1273         struct nfc_dev *dev;
1274         int rc;
1275         u32 idx, se_idx;
1276
1277         if (!info->attrs[NFC_ATTR_DEVICE_INDEX] ||
1278             !info->attrs[NFC_ATTR_SE_INDEX])
1279                 return -EINVAL;
1280
1281         idx = nla_get_u32(info->attrs[NFC_ATTR_DEVICE_INDEX]);
1282         se_idx = nla_get_u32(info->attrs[NFC_ATTR_SE_INDEX]);
1283
1284         dev = nfc_get_device(idx);
1285         if (!dev)
1286                 return -ENODEV;
1287
1288         rc = nfc_enable_se(dev, se_idx);
1289
1290         nfc_put_device(dev);
1291         return rc;
1292 }
1293
1294 static int nfc_genl_disable_se(struct sk_buff *skb, struct genl_info *info)
1295 {
1296         struct nfc_dev *dev;
1297         int rc;
1298         u32 idx, se_idx;
1299
1300         if (!info->attrs[NFC_ATTR_DEVICE_INDEX] ||
1301             !info->attrs[NFC_ATTR_SE_INDEX])
1302                 return -EINVAL;
1303
1304         idx = nla_get_u32(info->attrs[NFC_ATTR_DEVICE_INDEX]);
1305         se_idx = nla_get_u32(info->attrs[NFC_ATTR_SE_INDEX]);
1306
1307         dev = nfc_get_device(idx);
1308         if (!dev)
1309                 return -ENODEV;
1310
1311         rc = nfc_disable_se(dev, se_idx);
1312
1313         nfc_put_device(dev);
1314         return rc;
1315 }
1316
1317 static int nfc_genl_send_se(struct sk_buff *msg, struct nfc_dev *dev,
1318                                 u32 portid, u32 seq,
1319                                 struct netlink_callback *cb,
1320                                 int flags)
1321 {
1322         void *hdr;
1323         struct nfc_se *se, *n;
1324
1325         list_for_each_entry_safe(se, n, &dev->secure_elements, list) {
1326                 hdr = genlmsg_put(msg, portid, seq, &nfc_genl_family, flags,
1327                                   NFC_CMD_GET_SE);
1328                 if (!hdr)
1329                         goto nla_put_failure;
1330
1331                 if (cb)
1332                         genl_dump_check_consistent(cb, hdr);
1333
1334                 if (nla_put_u32(msg, NFC_ATTR_DEVICE_INDEX, dev->idx) ||
1335                     nla_put_u32(msg, NFC_ATTR_SE_INDEX, se->idx) ||
1336                     nla_put_u8(msg, NFC_ATTR_SE_TYPE, se->type))
1337                         goto nla_put_failure;
1338
1339                 genlmsg_end(msg, hdr);
1340         }
1341
1342         return 0;
1343
1344 nla_put_failure:
1345         genlmsg_cancel(msg, hdr);
1346         return -EMSGSIZE;
1347 }
1348
1349 static int nfc_genl_dump_ses(struct sk_buff *skb,
1350                                  struct netlink_callback *cb)
1351 {
1352         struct class_dev_iter *iter = (struct class_dev_iter *) cb->args[0];
1353         struct nfc_dev *dev = (struct nfc_dev *) cb->args[1];
1354         bool first_call = false;
1355
1356         if (!iter) {
1357                 first_call = true;
1358                 iter = kmalloc(sizeof(struct class_dev_iter), GFP_KERNEL);
1359                 if (!iter)
1360                         return -ENOMEM;
1361                 cb->args[0] = (long) iter;
1362         }
1363
1364         mutex_lock(&nfc_devlist_mutex);
1365
1366         cb->seq = nfc_devlist_generation;
1367
1368         if (first_call) {
1369                 nfc_device_iter_init(iter);
1370                 dev = nfc_device_iter_next(iter);
1371         }
1372
1373         while (dev) {
1374                 int rc;
1375
1376                 rc = nfc_genl_send_se(skb, dev, NETLINK_CB(cb->skb).portid,
1377                                           cb->nlh->nlmsg_seq, cb, NLM_F_MULTI);
1378                 if (rc < 0)
1379                         break;
1380
1381                 dev = nfc_device_iter_next(iter);
1382         }
1383
1384         mutex_unlock(&nfc_devlist_mutex);
1385
1386         cb->args[1] = (long) dev;
1387
1388         return skb->len;
1389 }
1390
1391 static int nfc_genl_dump_ses_done(struct netlink_callback *cb)
1392 {
1393         struct class_dev_iter *iter = (struct class_dev_iter *) cb->args[0];
1394
1395         if (iter) {
1396                 nfc_device_iter_exit(iter);
1397                 kfree(iter);
1398         }
1399
1400         return 0;
1401 }
1402
1403 static int nfc_se_io(struct nfc_dev *dev, u32 se_idx,
1404                      u8 *apdu, size_t apdu_length,
1405                      se_io_cb_t cb, void *cb_context)
1406 {
1407         struct nfc_se *se;
1408         int rc;
1409
1410         pr_debug("%s se index %d\n", dev_name(&dev->dev), se_idx);
1411
1412         device_lock(&dev->dev);
1413
1414         if (!device_is_registered(&dev->dev)) {
1415                 rc = -ENODEV;
1416                 goto error;
1417         }
1418
1419         if (!dev->dev_up) {
1420                 rc = -ENODEV;
1421                 goto error;
1422         }
1423
1424         if (!dev->ops->se_io) {
1425                 rc = -EOPNOTSUPP;
1426                 goto error;
1427         }
1428
1429         se = nfc_find_se(dev, se_idx);
1430         if (!se) {
1431                 rc = -EINVAL;
1432                 goto error;
1433         }
1434
1435         if (se->state != NFC_SE_ENABLED) {
1436                 rc = -ENODEV;
1437                 goto error;
1438         }
1439
1440         rc = dev->ops->se_io(dev, se_idx, apdu,
1441                         apdu_length, cb, cb_context);
1442
1443 error:
1444         device_unlock(&dev->dev);
1445         return rc;
1446 }
1447
1448 struct se_io_ctx {
1449         u32 dev_idx;
1450         u32 se_idx;
1451 };
1452
1453 static void se_io_cb(void *context, u8 *apdu, size_t apdu_len, int err)
1454 {
1455         struct se_io_ctx *ctx = context;
1456         struct sk_buff *msg;
1457         void *hdr;
1458
1459         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
1460         if (!msg) {
1461                 kfree(ctx);
1462                 return;
1463         }
1464
1465         hdr = genlmsg_put(msg, 0, 0, &nfc_genl_family, 0,
1466                           NFC_CMD_SE_IO);
1467         if (!hdr)
1468                 goto free_msg;
1469
1470         if (nla_put_u32(msg, NFC_ATTR_DEVICE_INDEX, ctx->dev_idx) ||
1471             nla_put_u32(msg, NFC_ATTR_SE_INDEX, ctx->se_idx) ||
1472             nla_put(msg, NFC_ATTR_SE_APDU, apdu_len, apdu))
1473                 goto nla_put_failure;
1474
1475         genlmsg_end(msg, hdr);
1476
1477         genlmsg_multicast(&nfc_genl_family, msg, 0, 0, GFP_KERNEL);
1478
1479         kfree(ctx);
1480
1481         return;
1482
1483 nla_put_failure:
1484 free_msg:
1485         nlmsg_free(msg);
1486         kfree(ctx);
1487
1488         return;
1489 }
1490
1491 static int nfc_genl_se_io(struct sk_buff *skb, struct genl_info *info)
1492 {
1493         struct nfc_dev *dev;
1494         struct se_io_ctx *ctx;
1495         u32 dev_idx, se_idx;
1496         u8 *apdu;
1497         size_t apdu_len;
1498
1499         if (!info->attrs[NFC_ATTR_DEVICE_INDEX] ||
1500             !info->attrs[NFC_ATTR_SE_INDEX] ||
1501             !info->attrs[NFC_ATTR_SE_APDU])
1502                 return -EINVAL;
1503
1504         dev_idx = nla_get_u32(info->attrs[NFC_ATTR_DEVICE_INDEX]);
1505         se_idx = nla_get_u32(info->attrs[NFC_ATTR_SE_INDEX]);
1506
1507         dev = nfc_get_device(dev_idx);
1508         if (!dev)
1509                 return -ENODEV;
1510
1511         if (!dev->ops || !dev->ops->se_io)
1512                 return -ENOTSUPP;
1513
1514         apdu_len = nla_len(info->attrs[NFC_ATTR_SE_APDU]);
1515         if (apdu_len == 0)
1516                 return -EINVAL;
1517
1518         apdu = nla_data(info->attrs[NFC_ATTR_SE_APDU]);
1519         if (!apdu)
1520                 return -EINVAL;
1521
1522         ctx = kzalloc(sizeof(struct se_io_ctx), GFP_KERNEL);
1523         if (!ctx)
1524                 return -ENOMEM;
1525
1526         ctx->dev_idx = dev_idx;
1527         ctx->se_idx = se_idx;
1528
1529         return nfc_se_io(dev, se_idx, apdu, apdu_len, se_io_cb, ctx);
1530 }
1531
1532 static int nfc_genl_vendor_cmd(struct sk_buff *skb,
1533                                struct genl_info *info)
1534 {
1535         struct nfc_dev *dev;
1536         const struct nfc_vendor_cmd *cmd;
1537         u32 dev_idx, vid, subcmd;
1538         u8 *data;
1539         size_t data_len;
1540         int i, err;
1541
1542         if (!info->attrs[NFC_ATTR_DEVICE_INDEX] ||
1543             !info->attrs[NFC_ATTR_VENDOR_ID] ||
1544             !info->attrs[NFC_ATTR_VENDOR_SUBCMD])
1545                 return -EINVAL;
1546
1547         dev_idx = nla_get_u32(info->attrs[NFC_ATTR_DEVICE_INDEX]);
1548         vid = nla_get_u32(info->attrs[NFC_ATTR_VENDOR_ID]);
1549         subcmd = nla_get_u32(info->attrs[NFC_ATTR_VENDOR_SUBCMD]);
1550
1551         dev = nfc_get_device(dev_idx);
1552         if (!dev || !dev->vendor_cmds || !dev->n_vendor_cmds)
1553                 return -ENODEV;
1554
1555         if (info->attrs[NFC_ATTR_VENDOR_DATA]) {
1556                 data = nla_data(info->attrs[NFC_ATTR_VENDOR_DATA]);
1557                 data_len = nla_len(info->attrs[NFC_ATTR_VENDOR_DATA]);
1558                 if (data_len == 0)
1559                         return -EINVAL;
1560         } else {
1561                 data = NULL;
1562                 data_len = 0;
1563         }
1564
1565         for (i = 0; i < dev->n_vendor_cmds; i++) {
1566                 cmd = &dev->vendor_cmds[i];
1567
1568                 if (cmd->vendor_id != vid || cmd->subcmd != subcmd)
1569                         continue;
1570
1571                 dev->cur_cmd_info = info;
1572                 err = cmd->doit(dev, data, data_len);
1573                 dev->cur_cmd_info = NULL;
1574                 return err;
1575         }
1576
1577         return -EOPNOTSUPP;
1578 }
1579
1580 /* message building helper */
1581 static inline void *nfc_hdr_put(struct sk_buff *skb, u32 portid, u32 seq,
1582                                 int flags, u8 cmd)
1583 {
1584         /* since there is no private header just add the generic one */
1585         return genlmsg_put(skb, portid, seq, &nfc_genl_family, flags, cmd);
1586 }
1587
1588 static struct sk_buff *
1589 __nfc_alloc_vendor_cmd_skb(struct nfc_dev *dev, int approxlen,
1590                            u32 portid, u32 seq,
1591                            enum nfc_attrs attr,
1592                            u32 oui, u32 subcmd, gfp_t gfp)
1593 {
1594         struct sk_buff *skb;
1595         void *hdr;
1596
1597         skb = nlmsg_new(approxlen + 100, gfp);
1598         if (!skb)
1599                 return NULL;
1600
1601         hdr = nfc_hdr_put(skb, portid, seq, 0, NFC_CMD_VENDOR);
1602         if (!hdr) {
1603                 kfree_skb(skb);
1604                 return NULL;
1605         }
1606
1607         if (nla_put_u32(skb, NFC_ATTR_DEVICE_INDEX, dev->idx))
1608                 goto nla_put_failure;
1609         if (nla_put_u32(skb, NFC_ATTR_VENDOR_ID, oui))
1610                 goto nla_put_failure;
1611         if (nla_put_u32(skb, NFC_ATTR_VENDOR_SUBCMD, subcmd))
1612                 goto nla_put_failure;
1613
1614         ((void **)skb->cb)[0] = dev;
1615         ((void **)skb->cb)[1] = hdr;
1616
1617         return skb;
1618
1619 nla_put_failure:
1620         kfree_skb(skb);
1621         return NULL;
1622 }
1623
1624 struct sk_buff *__nfc_alloc_vendor_cmd_reply_skb(struct nfc_dev *dev,
1625                                                  enum nfc_attrs attr,
1626                                                  u32 oui, u32 subcmd,
1627                                                  int approxlen)
1628 {
1629         if (WARN_ON(!dev->cur_cmd_info))
1630                 return NULL;
1631
1632         return __nfc_alloc_vendor_cmd_skb(dev, approxlen,
1633                                           dev->cur_cmd_info->snd_portid,
1634                                           dev->cur_cmd_info->snd_seq, attr,
1635                                           oui, subcmd, GFP_KERNEL);
1636 }
1637 EXPORT_SYMBOL(__nfc_alloc_vendor_cmd_reply_skb);
1638
1639 int nfc_vendor_cmd_reply(struct sk_buff *skb)
1640 {
1641         struct nfc_dev *dev = ((void **)skb->cb)[0];
1642         void *hdr = ((void **)skb->cb)[1];
1643
1644         /* clear CB data for netlink core to own from now on */
1645         memset(skb->cb, 0, sizeof(skb->cb));
1646
1647         if (WARN_ON(!dev->cur_cmd_info)) {
1648                 kfree_skb(skb);
1649                 return -EINVAL;
1650         }
1651
1652         genlmsg_end(skb, hdr);
1653         return genlmsg_reply(skb, dev->cur_cmd_info);
1654 }
1655 EXPORT_SYMBOL(nfc_vendor_cmd_reply);
1656
1657 static const struct genl_ops nfc_genl_ops[] = {
1658         {
1659                 .cmd = NFC_CMD_GET_DEVICE,
1660                 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
1661                 .doit = nfc_genl_get_device,
1662                 .dumpit = nfc_genl_dump_devices,
1663                 .done = nfc_genl_dump_devices_done,
1664         },
1665         {
1666                 .cmd = NFC_CMD_DEV_UP,
1667                 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
1668                 .doit = nfc_genl_dev_up,
1669         },
1670         {
1671                 .cmd = NFC_CMD_DEV_DOWN,
1672                 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
1673                 .doit = nfc_genl_dev_down,
1674         },
1675         {
1676                 .cmd = NFC_CMD_START_POLL,
1677                 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
1678                 .doit = nfc_genl_start_poll,
1679         },
1680         {
1681                 .cmd = NFC_CMD_STOP_POLL,
1682                 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
1683                 .doit = nfc_genl_stop_poll,
1684         },
1685         {
1686                 .cmd = NFC_CMD_DEP_LINK_UP,
1687                 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
1688                 .doit = nfc_genl_dep_link_up,
1689         },
1690         {
1691                 .cmd = NFC_CMD_DEP_LINK_DOWN,
1692                 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
1693                 .doit = nfc_genl_dep_link_down,
1694         },
1695         {
1696                 .cmd = NFC_CMD_GET_TARGET,
1697                 .validate = GENL_DONT_VALIDATE_STRICT |
1698                             GENL_DONT_VALIDATE_DUMP_STRICT,
1699                 .dumpit = nfc_genl_dump_targets,
1700                 .done = nfc_genl_dump_targets_done,
1701         },
1702         {
1703                 .cmd = NFC_CMD_LLC_GET_PARAMS,
1704                 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
1705                 .doit = nfc_genl_llc_get_params,
1706         },
1707         {
1708                 .cmd = NFC_CMD_LLC_SET_PARAMS,
1709                 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
1710                 .doit = nfc_genl_llc_set_params,
1711         },
1712         {
1713                 .cmd = NFC_CMD_LLC_SDREQ,
1714                 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
1715                 .doit = nfc_genl_llc_sdreq,
1716         },
1717         {
1718                 .cmd = NFC_CMD_FW_DOWNLOAD,
1719                 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
1720                 .doit = nfc_genl_fw_download,
1721         },
1722         {
1723                 .cmd = NFC_CMD_ENABLE_SE,
1724                 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
1725                 .doit = nfc_genl_enable_se,
1726         },
1727         {
1728                 .cmd = NFC_CMD_DISABLE_SE,
1729                 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
1730                 .doit = nfc_genl_disable_se,
1731         },
1732         {
1733                 .cmd = NFC_CMD_GET_SE,
1734                 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
1735                 .dumpit = nfc_genl_dump_ses,
1736                 .done = nfc_genl_dump_ses_done,
1737         },
1738         {
1739                 .cmd = NFC_CMD_SE_IO,
1740                 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
1741                 .doit = nfc_genl_se_io,
1742         },
1743         {
1744                 .cmd = NFC_CMD_ACTIVATE_TARGET,
1745                 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
1746                 .doit = nfc_genl_activate_target,
1747         },
1748         {
1749                 .cmd = NFC_CMD_VENDOR,
1750                 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
1751                 .doit = nfc_genl_vendor_cmd,
1752         },
1753         {
1754                 .cmd = NFC_CMD_DEACTIVATE_TARGET,
1755                 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
1756                 .doit = nfc_genl_deactivate_target,
1757         },
1758 };
1759
1760 static struct genl_family nfc_genl_family __ro_after_init = {
1761         .hdrsize = 0,
1762         .name = NFC_GENL_NAME,
1763         .version = NFC_GENL_VERSION,
1764         .maxattr = NFC_ATTR_MAX,
1765         .policy = nfc_genl_policy,
1766         .module = THIS_MODULE,
1767         .ops = nfc_genl_ops,
1768         .n_ops = ARRAY_SIZE(nfc_genl_ops),
1769         .mcgrps = nfc_genl_mcgrps,
1770         .n_mcgrps = ARRAY_SIZE(nfc_genl_mcgrps),
1771 };
1772
1773
1774 struct urelease_work {
1775         struct  work_struct w;
1776         u32     portid;
1777 };
1778
1779 static void nfc_urelease_event_work(struct work_struct *work)
1780 {
1781         struct urelease_work *w = container_of(work, struct urelease_work, w);
1782         struct class_dev_iter iter;
1783         struct nfc_dev *dev;
1784
1785         pr_debug("portid %d\n", w->portid);
1786
1787         mutex_lock(&nfc_devlist_mutex);
1788
1789         nfc_device_iter_init(&iter);
1790         dev = nfc_device_iter_next(&iter);
1791
1792         while (dev) {
1793                 mutex_lock(&dev->genl_data.genl_data_mutex);
1794
1795                 if (dev->genl_data.poll_req_portid == w->portid) {
1796                         nfc_stop_poll(dev);
1797                         dev->genl_data.poll_req_portid = 0;
1798                 }
1799
1800                 mutex_unlock(&dev->genl_data.genl_data_mutex);
1801
1802                 dev = nfc_device_iter_next(&iter);
1803         }
1804
1805         nfc_device_iter_exit(&iter);
1806
1807         mutex_unlock(&nfc_devlist_mutex);
1808
1809         kfree(w);
1810 }
1811
1812 static int nfc_genl_rcv_nl_event(struct notifier_block *this,
1813                                  unsigned long event, void *ptr)
1814 {
1815         struct netlink_notify *n = ptr;
1816         struct urelease_work *w;
1817
1818         if (event != NETLINK_URELEASE || n->protocol != NETLINK_GENERIC)
1819                 goto out;
1820
1821         pr_debug("NETLINK_URELEASE event from id %d\n", n->portid);
1822
1823         w = kmalloc(sizeof(*w), GFP_ATOMIC);
1824         if (w) {
1825                 INIT_WORK(&w->w, nfc_urelease_event_work);
1826                 w->portid = n->portid;
1827                 schedule_work(&w->w);
1828         }
1829
1830 out:
1831         return NOTIFY_DONE;
1832 }
1833
1834 void nfc_genl_data_init(struct nfc_genl_data *genl_data)
1835 {
1836         genl_data->poll_req_portid = 0;
1837         mutex_init(&genl_data->genl_data_mutex);
1838 }
1839
1840 void nfc_genl_data_exit(struct nfc_genl_data *genl_data)
1841 {
1842         mutex_destroy(&genl_data->genl_data_mutex);
1843 }
1844
1845 static struct notifier_block nl_notifier = {
1846         .notifier_call  = nfc_genl_rcv_nl_event,
1847 };
1848
1849 /**
1850  * nfc_genl_init() - Initialize netlink interface
1851  *
1852  * This initialization function registers the nfc netlink family.
1853  */
1854 int __init nfc_genl_init(void)
1855 {
1856         int rc;
1857
1858         rc = genl_register_family(&nfc_genl_family);
1859         if (rc)
1860                 return rc;
1861
1862         netlink_register_notifier(&nl_notifier);
1863
1864         return 0;
1865 }
1866
1867 /**
1868  * nfc_genl_exit() - Deinitialize netlink interface
1869  *
1870  * This exit function unregisters the nfc netlink family.
1871  */
1872 void nfc_genl_exit(void)
1873 {
1874         netlink_unregister_notifier(&nl_notifier);
1875         genl_unregister_family(&nfc_genl_family);
1876 }