Bluetooth: Expose current list of long term keys via debugfs
[linux-2.6-block.git] / net / bluetooth / hci_conn.c
CommitLineData
8e87d142 1/*
1da177e4 2 BlueZ - Bluetooth protocol stack for Linux
2d0a0346 3 Copyright (c) 2000-2001, 2010, Code Aurora Forum. All rights reserved.
1da177e4
LT
4
5 Written 2000,2001 by Maxim Krasnyansky <maxk@qualcomm.com>
6
7 This program is free software; you can redistribute it and/or modify
8 it under the terms of the GNU General Public License version 2 as
9 published by the Free Software Foundation;
10
11 THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS
12 OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
13 FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT OF THIRD PARTY RIGHTS.
14 IN NO EVENT SHALL THE COPYRIGHT HOLDER(S) AND AUTHOR(S) BE LIABLE FOR ANY
8e87d142
YH
15 CLAIM, OR ANY SPECIAL INDIRECT OR CONSEQUENTIAL DAMAGES, OR ANY DAMAGES
16 WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
17 ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
1da177e4
LT
18 OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
19
8e87d142
YH
20 ALL LIABILITY, INCLUDING LIABILITY FOR INFRINGEMENT OF ANY PATENTS,
21 COPYRIGHTS, TRADEMARKS OR OTHER RIGHTS, RELATING TO USE OF THIS
1da177e4
LT
22 SOFTWARE IS DISCLAIMED.
23*/
24
25/* Bluetooth HCI connection handling. */
26
8c520a59 27#include <linux/export.h>
1da177e4
LT
28
29#include <net/bluetooth/bluetooth.h>
30#include <net/bluetooth/hci_core.h>
31
ac4b7236 32#include "smp.h"
7024728e
MH
33#include "a2mp.h"
34
2dea632f
FD
35struct sco_param {
36 u16 pkt_type;
37 u16 max_latency;
38};
39
40static const struct sco_param sco_param_cvsd[] = {
41 { EDR_ESCO_MASK & ~ESCO_2EV3, 0x000a }, /* S3 */
42 { EDR_ESCO_MASK & ~ESCO_2EV3, 0x0007 }, /* S2 */
43 { EDR_ESCO_MASK | ESCO_EV3, 0x0007 }, /* S1 */
44 { EDR_ESCO_MASK | ESCO_HV3, 0xffff }, /* D1 */
45 { EDR_ESCO_MASK | ESCO_HV1, 0xffff }, /* D0 */
46};
47
48static const struct sco_param sco_param_wideband[] = {
49 { EDR_ESCO_MASK & ~ESCO_2EV3, 0x000d }, /* T2 */
50 { EDR_ESCO_MASK | ESCO_EV3, 0x0008 }, /* T1 */
51};
52
1aef8669 53static void hci_le_create_connection_cancel(struct hci_conn *conn)
fcd89c09
VT
54{
55 hci_send_cmd(conn->hdev, HCI_OP_LE_CREATE_CONN_CANCEL, 0, NULL);
56}
57
1aef8669 58static void hci_acl_create_connection(struct hci_conn *conn)
1da177e4
LT
59{
60 struct hci_dev *hdev = conn->hdev;
61 struct inquiry_entry *ie;
62 struct hci_cp_create_conn cp;
63
42d2d87c 64 BT_DBG("hcon %p", conn);
1da177e4
LT
65
66 conn->state = BT_CONNECT;
a0c808b3 67 conn->out = true;
a8746417 68
1da177e4
LT
69 conn->link_mode = HCI_LM_MASTER;
70
4c67bc74
MH
71 conn->attempt++;
72
e4e8e37c
MH
73 conn->link_policy = hdev->link_policy;
74
1da177e4
LT
75 memset(&cp, 0, sizeof(cp));
76 bacpy(&cp.bdaddr, &conn->dst);
77 cp.pscan_rep_mode = 0x02;
78
70f23020
AE
79 ie = hci_inquiry_cache_lookup(hdev, &conn->dst);
80 if (ie) {
41a96212
MH
81 if (inquiry_entry_age(ie) <= INQUIRY_ENTRY_AGE_MAX) {
82 cp.pscan_rep_mode = ie->data.pscan_rep_mode;
83 cp.pscan_mode = ie->data.pscan_mode;
84 cp.clock_offset = ie->data.clock_offset |
82781e63 85 __constant_cpu_to_le16(0x8000);
41a96212
MH
86 }
87
1da177e4 88 memcpy(conn->dev_class, ie->data.dev_class, 3);
58a681ef
JH
89 if (ie->data.ssp_mode > 0)
90 set_bit(HCI_CONN_SSP_ENABLED, &conn->flags);
1da177e4
LT
91 }
92
a8746417 93 cp.pkt_type = cpu_to_le16(conn->pkt_type);
1da177e4 94 if (lmp_rswitch_capable(hdev) && !(hdev->link_mode & HCI_LM_MASTER))
b6a0dc82 95 cp.role_switch = 0x01;
1da177e4 96 else
b6a0dc82 97 cp.role_switch = 0x00;
4c67bc74 98
a9de9248 99 hci_send_cmd(hdev, HCI_OP_CREATE_CONN, sizeof(cp), &cp);
1da177e4
LT
100}
101
1aef8669 102static void hci_acl_create_connection_cancel(struct hci_conn *conn)
6ac59344
MH
103{
104 struct hci_cp_create_conn_cancel cp;
105
38b3fef1 106 BT_DBG("hcon %p", conn);
6ac59344 107
d095c1eb 108 if (conn->hdev->hci_ver < BLUETOOTH_VER_1_2)
6ac59344
MH
109 return;
110
111 bacpy(&cp.bdaddr, &conn->dst);
a9de9248 112 hci_send_cmd(conn->hdev, HCI_OP_CREATE_CONN_CANCEL, sizeof(cp), &cp);
6ac59344
MH
113}
114
93796fa6
CT
115static void hci_reject_sco(struct hci_conn *conn)
116{
117 struct hci_cp_reject_sync_conn_req cp;
118
119 cp.reason = HCI_ERROR_REMOTE_USER_TERM;
120 bacpy(&cp.bdaddr, &conn->dst);
121
122 hci_send_cmd(conn->hdev, HCI_OP_REJECT_SYNC_CONN_REQ, sizeof(cp), &cp);
123}
124
bed71748 125void hci_disconnect(struct hci_conn *conn, __u8 reason)
1da177e4
LT
126{
127 struct hci_cp_disconnect cp;
128
38b3fef1 129 BT_DBG("hcon %p", conn);
1da177e4
LT
130
131 conn->state = BT_DISCONN;
132
aca3192c 133 cp.handle = cpu_to_le16(conn->handle);
1da177e4 134 cp.reason = reason;
a9de9248 135 hci_send_cmd(conn->hdev, HCI_OP_DISCONNECT, sizeof(cp), &cp);
1da177e4
LT
136}
137
53502d69
AE
138static void hci_amp_disconn(struct hci_conn *conn, __u8 reason)
139{
140 struct hci_cp_disconn_phy_link cp;
141
142 BT_DBG("hcon %p", conn);
143
144 conn->state = BT_DISCONN;
145
146 cp.phy_handle = HCI_PHY_HANDLE(conn->handle);
147 cp.reason = reason;
148 hci_send_cmd(conn->hdev, HCI_OP_DISCONN_PHY_LINK,
149 sizeof(cp), &cp);
150}
151
57f5d0d1 152static void hci_add_sco(struct hci_conn *conn, __u16 handle)
1da177e4
LT
153{
154 struct hci_dev *hdev = conn->hdev;
155 struct hci_cp_add_sco cp;
156
38b3fef1 157 BT_DBG("hcon %p", conn);
1da177e4
LT
158
159 conn->state = BT_CONNECT;
a0c808b3 160 conn->out = true;
1da177e4 161
efc7688b
MH
162 conn->attempt++;
163
aca3192c 164 cp.handle = cpu_to_le16(handle);
a8746417 165 cp.pkt_type = cpu_to_le16(conn->pkt_type);
1da177e4 166
a9de9248 167 hci_send_cmd(hdev, HCI_OP_ADD_SCO, sizeof(cp), &cp);
1da177e4
LT
168}
169
2dea632f 170bool hci_setup_sync(struct hci_conn *conn, __u16 handle)
b6a0dc82
MH
171{
172 struct hci_dev *hdev = conn->hdev;
173 struct hci_cp_setup_sync_conn cp;
2dea632f 174 const struct sco_param *param;
b6a0dc82 175
38b3fef1 176 BT_DBG("hcon %p", conn);
b6a0dc82
MH
177
178 conn->state = BT_CONNECT;
a0c808b3 179 conn->out = true;
b6a0dc82 180
efc7688b
MH
181 conn->attempt++;
182
b6a0dc82 183 cp.handle = cpu_to_le16(handle);
b6a0dc82 184
82781e63
AE
185 cp.tx_bandwidth = __constant_cpu_to_le32(0x00001f40);
186 cp.rx_bandwidth = __constant_cpu_to_le32(0x00001f40);
10c62ddc
FD
187 cp.voice_setting = cpu_to_le16(conn->setting);
188
189 switch (conn->setting & SCO_AIRMODE_MASK) {
190 case SCO_AIRMODE_TRANSP:
2dea632f
FD
191 if (conn->attempt > ARRAY_SIZE(sco_param_wideband))
192 return false;
10c62ddc 193 cp.retrans_effort = 0x02;
2dea632f 194 param = &sco_param_wideband[conn->attempt - 1];
10c62ddc
FD
195 break;
196 case SCO_AIRMODE_CVSD:
2dea632f
FD
197 if (conn->attempt > ARRAY_SIZE(sco_param_cvsd))
198 return false;
199 cp.retrans_effort = 0x01;
200 param = &sco_param_cvsd[conn->attempt - 1];
10c62ddc 201 break;
2dea632f
FD
202 default:
203 return false;
10c62ddc 204 }
b6a0dc82 205
2dea632f
FD
206 cp.pkt_type = __cpu_to_le16(param->pkt_type);
207 cp.max_latency = __cpu_to_le16(param->max_latency);
208
209 if (hci_send_cmd(hdev, HCI_OP_SETUP_SYNC_CONN, sizeof(cp), &cp) < 0)
210 return false;
211
212 return true;
b6a0dc82
MH
213}
214
2ce603eb 215void hci_le_conn_update(struct hci_conn *conn, u16 min, u16 max,
5974e4c4 216 u16 latency, u16 to_multiplier)
2ce603eb
CT
217{
218 struct hci_cp_le_conn_update cp;
219 struct hci_dev *hdev = conn->hdev;
220
221 memset(&cp, 0, sizeof(cp));
222
223 cp.handle = cpu_to_le16(conn->handle);
224 cp.conn_interval_min = cpu_to_le16(min);
225 cp.conn_interval_max = cpu_to_le16(max);
226 cp.conn_latency = cpu_to_le16(latency);
227 cp.supervision_timeout = cpu_to_le16(to_multiplier);
82781e63
AE
228 cp.min_ce_len = __constant_cpu_to_le16(0x0001);
229 cp.max_ce_len = __constant_cpu_to_le16(0x0001);
2ce603eb
CT
230
231 hci_send_cmd(hdev, HCI_OP_LE_CONN_UPDATE, sizeof(cp), &cp);
232}
2ce603eb 233
a7a595f6 234void hci_le_start_enc(struct hci_conn *conn, __le16 ediv, __u8 rand[8],
5974e4c4 235 __u8 ltk[16])
a7a595f6
VCG
236{
237 struct hci_dev *hdev = conn->hdev;
238 struct hci_cp_le_start_enc cp;
239
38b3fef1 240 BT_DBG("hcon %p", conn);
a7a595f6
VCG
241
242 memset(&cp, 0, sizeof(cp));
243
244 cp.handle = cpu_to_le16(conn->handle);
245 memcpy(cp.ltk, ltk, sizeof(cp.ltk));
246 cp.ediv = ediv;
51beabdf 247 memcpy(cp.rand, rand, sizeof(cp.rand));
a7a595f6
VCG
248
249 hci_send_cmd(hdev, HCI_OP_LE_START_ENC, sizeof(cp), &cp);
250}
a7a595f6 251
e73439d8
MH
252/* Device _must_ be locked */
253void hci_sco_setup(struct hci_conn *conn, __u8 status)
254{
255 struct hci_conn *sco = conn->link;
256
e73439d8
MH
257 if (!sco)
258 return;
259
38b3fef1
AE
260 BT_DBG("hcon %p", conn);
261
e73439d8
MH
262 if (!status) {
263 if (lmp_esco_capable(conn->hdev))
264 hci_setup_sync(sco, conn->handle);
265 else
266 hci_add_sco(sco, conn->handle);
267 } else {
268 hci_proto_connect_cfm(sco, status);
269 hci_conn_del(sco);
270 }
271}
272
53502d69
AE
273static void hci_conn_disconnect(struct hci_conn *conn)
274{
275 __u8 reason = hci_proto_disconn_ind(conn);
276
277 switch (conn->type) {
53502d69
AE
278 case AMP_LINK:
279 hci_amp_disconn(conn, reason);
280 break;
4c02e2d4 281 default:
bed71748 282 hci_disconnect(conn, reason);
4c02e2d4 283 break;
53502d69
AE
284 }
285}
286
19c40e3b 287static void hci_conn_timeout(struct work_struct *work)
1da177e4 288{
19c40e3b 289 struct hci_conn *conn = container_of(work, struct hci_conn,
5974e4c4 290 disc_work.work);
1da177e4 291
38b3fef1 292 BT_DBG("hcon %p state %s", conn, state_to_string(conn->state));
1da177e4
LT
293
294 if (atomic_read(&conn->refcnt))
295 return;
296
6ac59344
MH
297 switch (conn->state) {
298 case BT_CONNECT:
769be974 299 case BT_CONNECT2:
fcd89c09
VT
300 if (conn->out) {
301 if (conn->type == ACL_LINK)
1aef8669 302 hci_acl_create_connection_cancel(conn);
fcd89c09 303 else if (conn->type == LE_LINK)
1aef8669 304 hci_le_create_connection_cancel(conn);
93796fa6
CT
305 } else if (conn->type == SCO_LINK || conn->type == ESCO_LINK) {
306 hci_reject_sco(conn);
fcd89c09 307 }
6ac59344 308 break;
769be974 309 case BT_CONFIG:
8e87d142 310 case BT_CONNECTED:
53502d69 311 hci_conn_disconnect(conn);
6ac59344
MH
312 break;
313 default:
1da177e4 314 conn->state = BT_CLOSED;
6ac59344
MH
315 break;
316 }
1da177e4
LT
317}
318
416dc94b 319/* Enter sniff mode */
a74a84f6 320static void hci_conn_idle(struct work_struct *work)
416dc94b 321{
a74a84f6
JH
322 struct hci_conn *conn = container_of(work, struct hci_conn,
323 idle_work.work);
416dc94b
GP
324 struct hci_dev *hdev = conn->hdev;
325
38b3fef1 326 BT_DBG("hcon %p mode %d", conn, conn->mode);
416dc94b
GP
327
328 if (test_bit(HCI_RAW, &hdev->flags))
329 return;
330
331 if (!lmp_sniff_capable(hdev) || !lmp_sniff_capable(conn))
332 return;
333
334 if (conn->mode != HCI_CM_ACTIVE || !(conn->link_policy & HCI_LP_SNIFF))
335 return;
336
337 if (lmp_sniffsubr_capable(hdev) && lmp_sniffsubr_capable(conn)) {
338 struct hci_cp_sniff_subrate cp;
339 cp.handle = cpu_to_le16(conn->handle);
82781e63
AE
340 cp.max_latency = __constant_cpu_to_le16(0);
341 cp.min_remote_timeout = __constant_cpu_to_le16(0);
342 cp.min_local_timeout = __constant_cpu_to_le16(0);
416dc94b
GP
343 hci_send_cmd(hdev, HCI_OP_SNIFF_SUBRATE, sizeof(cp), &cp);
344 }
345
51a8efd7 346 if (!test_and_set_bit(HCI_CONN_MODE_CHANGE_PEND, &conn->flags)) {
416dc94b
GP
347 struct hci_cp_sniff_mode cp;
348 cp.handle = cpu_to_le16(conn->handle);
349 cp.max_interval = cpu_to_le16(hdev->sniff_max_interval);
350 cp.min_interval = cpu_to_le16(hdev->sniff_min_interval);
82781e63
AE
351 cp.attempt = __constant_cpu_to_le16(4);
352 cp.timeout = __constant_cpu_to_le16(1);
416dc94b
GP
353 hci_send_cmd(hdev, HCI_OP_SNIFF_MODE, sizeof(cp), &cp);
354 }
355}
356
7bc18d9d 357static void hci_conn_auto_accept(struct work_struct *work)
9f61656a 358{
7bc18d9d
JH
359 struct hci_conn *conn = container_of(work, struct hci_conn,
360 auto_accept_work.work);
9f61656a 361
7bc18d9d 362 hci_send_cmd(conn->hdev, HCI_OP_USER_CONFIRM_REPLY, sizeof(conn->dst),
5974e4c4 363 &conn->dst);
9f61656a
JH
364}
365
1da177e4
LT
366struct hci_conn *hci_conn_add(struct hci_dev *hdev, int type, bdaddr_t *dst)
367{
368 struct hci_conn *conn;
369
6ed93dc6 370 BT_DBG("%s dst %pMR", hdev->name, dst);
1da177e4 371
cb601d7e 372 conn = kzalloc(sizeof(struct hci_conn), GFP_KERNEL);
04837f64 373 if (!conn)
1da177e4 374 return NULL;
1da177e4
LT
375
376 bacpy(&conn->dst, dst);
662e8820 377 bacpy(&conn->src, &hdev->bdaddr);
a8746417
MH
378 conn->hdev = hdev;
379 conn->type = type;
380 conn->mode = HCI_CM_ACTIVE;
381 conn->state = BT_OPEN;
93f19c9f 382 conn->auth_type = HCI_AT_GENERAL_BONDING;
17fa4b9d 383 conn->io_capability = hdev->io_capability;
a9583556 384 conn->remote_auth = 0xff;
13d39315 385 conn->key_type = 0xff;
1da177e4 386
58a681ef 387 set_bit(HCI_CONN_POWER_SAVE, &conn->flags);
052b30b0 388 conn->disc_timeout = HCI_DISCONN_TIMEOUT;
04837f64 389
a8746417
MH
390 switch (type) {
391 case ACL_LINK:
392 conn->pkt_type = hdev->pkt_type & ACL_PTYPE_MASK;
393 break;
394 case SCO_LINK:
395 if (lmp_esco_capable(hdev))
efc7688b
MH
396 conn->pkt_type = (hdev->esco_type & SCO_ESCO_MASK) |
397 (hdev->esco_type & EDR_ESCO_MASK);
a8746417
MH
398 else
399 conn->pkt_type = hdev->pkt_type & SCO_PTYPE_MASK;
400 break;
401 case ESCO_LINK:
efc7688b 402 conn->pkt_type = hdev->esco_type & ~EDR_ESCO_MASK;
a8746417
MH
403 break;
404 }
405
1da177e4 406 skb_queue_head_init(&conn->data_q);
04837f64 407
70c1f20b 408 INIT_LIST_HEAD(&conn->chan_list);
73d80deb 409
19c40e3b 410 INIT_DELAYED_WORK(&conn->disc_work, hci_conn_timeout);
7bc18d9d 411 INIT_DELAYED_WORK(&conn->auto_accept_work, hci_conn_auto_accept);
a74a84f6 412 INIT_DELAYED_WORK(&conn->idle_work, hci_conn_idle);
1da177e4
LT
413
414 atomic_set(&conn->refcnt, 0);
415
416 hci_dev_hold(hdev);
417
1da177e4 418 hci_conn_hash_add(hdev, conn);
3c54711c 419 if (hdev->notify)
1da177e4
LT
420 hdev->notify(hdev, HCI_NOTIFY_CONN_ADD);
421
a67e899c
MH
422 hci_conn_init_sysfs(conn);
423
1da177e4
LT
424 return conn;
425}
426
427int hci_conn_del(struct hci_conn *conn)
428{
429 struct hci_dev *hdev = conn->hdev;
430
38b3fef1 431 BT_DBG("%s hcon %p handle %d", hdev->name, conn, conn->handle);
1da177e4 432
19c40e3b 433 cancel_delayed_work_sync(&conn->disc_work);
7bc18d9d 434 cancel_delayed_work_sync(&conn->auto_accept_work);
a74a84f6 435 cancel_delayed_work_sync(&conn->idle_work);
9f61656a 436
5b7f9909 437 if (conn->type == ACL_LINK) {
1da177e4
LT
438 struct hci_conn *sco = conn->link;
439 if (sco)
440 sco->link = NULL;
441
442 /* Unacked frames */
443 hdev->acl_cnt += conn->sent;
6ed58ec5
VT
444 } else if (conn->type == LE_LINK) {
445 if (hdev->le_pkts)
446 hdev->le_cnt += conn->sent;
447 else
448 hdev->acl_cnt += conn->sent;
5b7f9909
MH
449 } else {
450 struct hci_conn *acl = conn->link;
451 if (acl) {
452 acl->link = NULL;
76a68ba0 453 hci_conn_drop(acl);
5b7f9909 454 }
1da177e4
LT
455 }
456
2c33c06a 457 hci_chan_list_flush(conn);
73d80deb 458
9740e49d
AE
459 if (conn->amp_mgr)
460 amp_mgr_put(conn->amp_mgr);
461
1da177e4 462 hci_conn_hash_del(hdev, conn);
3c54711c 463 if (hdev->notify)
1da177e4 464 hdev->notify(hdev, HCI_NOTIFY_CONN_DEL);
7d0db0a3 465
1da177e4 466 skb_queue_purge(&conn->data_q);
1da177e4 467
fc225c3f 468 hci_conn_del_sysfs(conn);
2ae9a6be 469
384943ec
MH
470 hci_dev_put(hdev);
471
8d12356f 472 hci_conn_put(conn);
163f4dab 473
1da177e4
LT
474 return 0;
475}
476
477struct hci_dev *hci_get_route(bdaddr_t *dst, bdaddr_t *src)
478{
479 int use_src = bacmp(src, BDADDR_ANY);
8035ded4 480 struct hci_dev *hdev = NULL, *d;
1da177e4 481
6ed93dc6 482 BT_DBG("%pMR -> %pMR", src, dst);
1da177e4 483
f20d09d5 484 read_lock(&hci_dev_list_lock);
1da177e4 485
8035ded4 486 list_for_each_entry(d, &hci_dev_list, list) {
8fc9ced3 487 if (!test_bit(HCI_UP, &d->flags) ||
d300fa9b 488 test_bit(HCI_RAW, &d->flags) ||
af750e94 489 test_bit(HCI_USER_CHANNEL, &d->dev_flags) ||
d300fa9b 490 d->dev_type != HCI_BREDR)
1da177e4
LT
491 continue;
492
8e87d142 493 /* Simple routing:
1da177e4
LT
494 * No source address - find interface with bdaddr != dst
495 * Source address - find interface with bdaddr == src
496 */
497
498 if (use_src) {
499 if (!bacmp(&d->bdaddr, src)) {
500 hdev = d; break;
501 }
502 } else {
503 if (bacmp(&d->bdaddr, dst)) {
504 hdev = d; break;
505 }
506 }
507 }
508
509 if (hdev)
510 hdev = hci_dev_hold(hdev);
511
f20d09d5 512 read_unlock(&hci_dev_list_lock);
1da177e4
LT
513 return hdev;
514}
515EXPORT_SYMBOL(hci_get_route);
516
1d399ae5
AG
517static void create_le_conn_complete(struct hci_dev *hdev, u8 status)
518{
519 struct hci_conn *conn;
520
521 if (status == 0)
522 return;
523
524 BT_ERR("HCI request failed to create LE connection: status 0x%2.2x",
525 status);
526
527 hci_dev_lock(hdev);
528
529 conn = hci_conn_hash_lookup_state(hdev, LE_LINK, BT_CONNECT);
530 if (!conn)
531 goto done;
532
533 conn->state = BT_CLOSED;
534
535 mgmt_connect_failed(hdev, &conn->dst, conn->type, conn->dst_type,
536 status);
537
538 hci_proto_connect_cfm(conn, status);
539
540 hci_conn_del(conn);
541
542done:
543 hci_dev_unlock(hdev);
544}
545
546static int hci_create_le_conn(struct hci_conn *conn)
547{
548 struct hci_dev *hdev = conn->hdev;
549 struct hci_cp_le_create_conn cp;
550 struct hci_request req;
551 int err;
552
553 hci_req_init(&req, hdev);
554
555 memset(&cp, 0, sizeof(cp));
bef64738
MH
556 cp.scan_interval = cpu_to_le16(hdev->le_scan_interval);
557 cp.scan_window = cpu_to_le16(hdev->le_scan_window);
1d399ae5
AG
558 bacpy(&cp.peer_addr, &conn->dst);
559 cp.peer_addr_type = conn->dst_type;
e7c4096e 560 cp.own_address_type = conn->src_type;
1d399ae5
AG
561 cp.conn_interval_min = __constant_cpu_to_le16(0x0028);
562 cp.conn_interval_max = __constant_cpu_to_le16(0x0038);
563 cp.supervision_timeout = __constant_cpu_to_le16(0x002a);
564 cp.min_ce_len = __constant_cpu_to_le16(0x0000);
565 cp.max_ce_len = __constant_cpu_to_le16(0x0000);
566 hci_req_add(&req, HCI_OP_LE_CREATE_CONN, sizeof(cp), &cp);
567
568 err = hci_req_run(&req, create_le_conn_complete);
569 if (err) {
570 hci_conn_del(conn);
571 return err;
572 }
573
574 return 0;
575}
576
d04aef4c
VCG
577static struct hci_conn *hci_connect_le(struct hci_dev *hdev, bdaddr_t *dst,
578 u8 dst_type, u8 sec_level, u8 auth_type)
1da177e4 579{
f1e5d547 580 struct hci_conn *conn;
1d399ae5 581 int err;
1da177e4 582
f3d3444a 583 if (test_bit(HCI_ADVERTISING, &hdev->flags))
f1550478
JH
584 return ERR_PTR(-ENOTSUPP);
585
620ad521
AG
586 /* Some devices send ATT messages as soon as the physical link is
587 * established. To be able to handle these ATT messages, the user-
588 * space first establishes the connection and then starts the pairing
589 * process.
590 *
591 * So if a hci_conn object already exists for the following connection
592 * attempt, we simply update pending_sec_level and auth_type fields
593 * and return the object found.
594 */
f1e5d547 595 conn = hci_conn_hash_lookup_ba(hdev, LE_LINK, dst);
620ad521
AG
596 if (conn) {
597 conn->pending_sec_level = sec_level;
598 conn->auth_type = auth_type;
599 goto done;
600 }
dfc94dbd 601
620ad521
AG
602 /* Since the controller supports only one LE connection attempt at a
603 * time, we return -EBUSY if there is any connection attempt running.
604 */
605 conn = hci_conn_hash_lookup_state(hdev, LE_LINK, BT_CONNECT);
606 if (conn)
607 return ERR_PTR(-EBUSY);
46a190cb 608
620ad521
AG
609 conn = hci_conn_add(hdev, LE_LINK, dst);
610 if (!conn)
611 return ERR_PTR(-ENOMEM);
9f0caeb1 612
79d95a19
MH
613 if (dst_type == BDADDR_LE_PUBLIC)
614 conn->dst_type = ADDR_LE_DEV_PUBLIC;
615 else
616 conn->dst_type = ADDR_LE_DEV_RANDOM;
e7c4096e 617
662e8820 618 if (bacmp(&conn->src, BDADDR_ANY)) {
e7c4096e 619 conn->src_type = ADDR_LE_DEV_PUBLIC;
662e8820
MH
620 } else {
621 bacpy(&conn->src, &hdev->static_addr);
e7c4096e 622 conn->src_type = ADDR_LE_DEV_RANDOM;
662e8820 623 }
e7c4096e 624
620ad521
AG
625 conn->state = BT_CONNECT;
626 conn->out = true;
627 conn->link_mode |= HCI_LM_MASTER;
628 conn->sec_level = BT_SECURITY_LOW;
f1e5d547
AG
629 conn->pending_sec_level = sec_level;
630 conn->auth_type = auth_type;
eda42b50 631
620ad521
AG
632 err = hci_create_le_conn(conn);
633 if (err)
634 return ERR_PTR(err);
fcd89c09 635
620ad521
AG
636done:
637 hci_conn_hold(conn);
f1e5d547 638 return conn;
d04aef4c 639}
fcd89c09 640
db474275
VCG
641static struct hci_conn *hci_connect_acl(struct hci_dev *hdev, bdaddr_t *dst,
642 u8 sec_level, u8 auth_type)
1da177e4
LT
643{
644 struct hci_conn *acl;
fcd89c09 645
56f87901
JH
646 if (!test_bit(HCI_BREDR_ENABLED, &hdev->dev_flags))
647 return ERR_PTR(-ENOTSUPP);
648
70f23020
AE
649 acl = hci_conn_hash_lookup_ba(hdev, ACL_LINK, dst);
650 if (!acl) {
651 acl = hci_conn_add(hdev, ACL_LINK, dst);
652 if (!acl)
48c7aba9 653 return ERR_PTR(-ENOMEM);
1da177e4
LT
654 }
655
656 hci_conn_hold(acl);
657
09ab6f4c 658 if (acl->state == BT_OPEN || acl->state == BT_CLOSED) {
765c2a96
JH
659 acl->sec_level = BT_SECURITY_LOW;
660 acl->pending_sec_level = sec_level;
09ab6f4c 661 acl->auth_type = auth_type;
1aef8669 662 hci_acl_create_connection(acl);
09ab6f4c 663 }
1da177e4 664
db474275
VCG
665 return acl;
666}
667
10c62ddc
FD
668struct hci_conn *hci_connect_sco(struct hci_dev *hdev, int type, bdaddr_t *dst,
669 __u16 setting)
db474275
VCG
670{
671 struct hci_conn *acl;
672 struct hci_conn *sco;
673
e660ed6c 674 acl = hci_connect_acl(hdev, dst, BT_SECURITY_LOW, HCI_AT_NO_BONDING);
db474275 675 if (IS_ERR(acl))
5b7f9909 676 return acl;
1da177e4 677
70f23020
AE
678 sco = hci_conn_hash_lookup_ba(hdev, type, dst);
679 if (!sco) {
680 sco = hci_conn_add(hdev, type, dst);
681 if (!sco) {
76a68ba0 682 hci_conn_drop(acl);
48c7aba9 683 return ERR_PTR(-ENOMEM);
1da177e4 684 }
5b7f9909 685 }
1da177e4 686
5b7f9909
MH
687 acl->link = sco;
688 sco->link = acl;
1da177e4 689
5b7f9909 690 hci_conn_hold(sco);
1da177e4 691
10c62ddc
FD
692 sco->setting = setting;
693
5b7f9909 694 if (acl->state == BT_CONNECTED &&
5974e4c4 695 (sco->state == BT_OPEN || sco->state == BT_CLOSED)) {
58a681ef 696 set_bit(HCI_CONN_POWER_SAVE, &acl->flags);
14b12d0b 697 hci_conn_enter_active_mode(acl, BT_POWER_FORCE_ACTIVE_ON);
c390216b 698
51a8efd7 699 if (test_bit(HCI_CONN_MODE_CHANGE_PEND, &acl->flags)) {
e73439d8 700 /* defer SCO setup until mode change completed */
51a8efd7 701 set_bit(HCI_CONN_SCO_SETUP_PEND, &acl->flags);
e73439d8
MH
702 return sco;
703 }
704
705 hci_sco_setup(acl, 0x00);
b6a0dc82 706 }
5b7f9909
MH
707
708 return sco;
1da177e4 709}
1da177e4 710
b7d839bf
VCG
711/* Create SCO, ACL or LE connection. */
712struct hci_conn *hci_connect(struct hci_dev *hdev, int type, bdaddr_t *dst,
713 __u8 dst_type, __u8 sec_level, __u8 auth_type)
714{
6ed93dc6 715 BT_DBG("%s dst %pMR type 0x%x", hdev->name, dst, type);
b7d839bf 716
4cd2d983
VCG
717 switch (type) {
718 case LE_LINK:
b7d839bf 719 return hci_connect_le(hdev, dst, dst_type, sec_level, auth_type);
4cd2d983 720 case ACL_LINK:
b7d839bf 721 return hci_connect_acl(hdev, dst, sec_level, auth_type);
4cd2d983 722 }
b7d839bf 723
4cd2d983 724 return ERR_PTR(-EINVAL);
b7d839bf
VCG
725}
726
e7c29cb1
MH
727/* Check link security requirement */
728int hci_conn_check_link_mode(struct hci_conn *conn)
729{
38b3fef1 730 BT_DBG("hcon %p", conn);
e7c29cb1 731
aa64a8b5 732 if (hci_conn_ssp_enabled(conn) && !(conn->link_mode & HCI_LM_ENCRYPT))
e7c29cb1
MH
733 return 0;
734
735 return 1;
736}
e7c29cb1 737
1da177e4 738/* Authenticate remote device */
0684e5f9 739static int hci_conn_auth(struct hci_conn *conn, __u8 sec_level, __u8 auth_type)
1da177e4 740{
38b3fef1 741 BT_DBG("hcon %p", conn);
1da177e4 742
765c2a96
JH
743 if (conn->pending_sec_level > sec_level)
744 sec_level = conn->pending_sec_level;
745
96a31833 746 if (sec_level > conn->sec_level)
765c2a96 747 conn->pending_sec_level = sec_level;
96a31833 748 else if (conn->link_mode & HCI_LM_AUTH)
1da177e4
LT
749 return 1;
750
65cf686e
JH
751 /* Make sure we preserve an existing MITM requirement*/
752 auth_type |= (conn->auth_type & 0x01);
753
96a31833
MH
754 conn->auth_type = auth_type;
755
51a8efd7 756 if (!test_and_set_bit(HCI_CONN_AUTH_PEND, &conn->flags)) {
1da177e4 757 struct hci_cp_auth_requested cp;
b7d05bad
PH
758
759 /* encrypt must be pending if auth is also pending */
760 set_bit(HCI_CONN_ENCRYPT_PEND, &conn->flags);
761
aca3192c 762 cp.handle = cpu_to_le16(conn->handle);
40be492f 763 hci_send_cmd(conn->hdev, HCI_OP_AUTH_REQUESTED,
5974e4c4 764 sizeof(cp), &cp);
19f8def0 765 if (conn->key_type != 0xff)
51a8efd7 766 set_bit(HCI_CONN_REAUTH_PEND, &conn->flags);
1da177e4 767 }
8c1b2355 768
1da177e4
LT
769 return 0;
770}
1da177e4 771
13d39315
WR
772/* Encrypt the the link */
773static void hci_conn_encrypt(struct hci_conn *conn)
774{
38b3fef1 775 BT_DBG("hcon %p", conn);
13d39315 776
51a8efd7 777 if (!test_and_set_bit(HCI_CONN_ENCRYPT_PEND, &conn->flags)) {
13d39315
WR
778 struct hci_cp_set_conn_encrypt cp;
779 cp.handle = cpu_to_le16(conn->handle);
780 cp.encrypt = 0x01;
781 hci_send_cmd(conn->hdev, HCI_OP_SET_CONN_ENCRYPT, sizeof(cp),
5974e4c4 782 &cp);
13d39315
WR
783 }
784}
785
8c1b2355 786/* Enable security */
0684e5f9 787int hci_conn_security(struct hci_conn *conn, __u8 sec_level, __u8 auth_type)
1da177e4 788{
38b3fef1 789 BT_DBG("hcon %p", conn);
1da177e4 790
d8343f12
VCG
791 if (conn->type == LE_LINK)
792 return smp_conn_security(conn, sec_level);
793
13d39315 794 /* For sdp we don't need the link key. */
8c1b2355
MH
795 if (sec_level == BT_SECURITY_SDP)
796 return 1;
797
13d39315
WR
798 /* For non 2.1 devices and low security level we don't need the link
799 key. */
aa64a8b5 800 if (sec_level == BT_SECURITY_LOW && !hci_conn_ssp_enabled(conn))
3fdca1e1 801 return 1;
8c1b2355 802
13d39315
WR
803 /* For other security levels we need the link key. */
804 if (!(conn->link_mode & HCI_LM_AUTH))
805 goto auth;
806
807 /* An authenticated combination key has sufficient security for any
808 security level. */
809 if (conn->key_type == HCI_LK_AUTH_COMBINATION)
810 goto encrypt;
811
812 /* An unauthenticated combination key has sufficient security for
813 security level 1 and 2. */
814 if (conn->key_type == HCI_LK_UNAUTH_COMBINATION &&
5974e4c4 815 (sec_level == BT_SECURITY_MEDIUM || sec_level == BT_SECURITY_LOW))
13d39315
WR
816 goto encrypt;
817
818 /* A combination key has always sufficient security for the security
819 levels 1 or 2. High security level requires the combination key
820 is generated using maximum PIN code length (16).
821 For pre 2.1 units. */
822 if (conn->key_type == HCI_LK_COMBINATION &&
5974e4c4 823 (sec_level != BT_SECURITY_HIGH || conn->pin_length == 16))
13d39315
WR
824 goto encrypt;
825
826auth:
51a8efd7 827 if (test_bit(HCI_CONN_ENCRYPT_PEND, &conn->flags))
1da177e4
LT
828 return 0;
829
6fdf658c
LAD
830 if (!hci_conn_auth(conn, sec_level, auth_type))
831 return 0;
13d39315
WR
832
833encrypt:
834 if (conn->link_mode & HCI_LM_ENCRYPT)
835 return 1;
8c1b2355 836
13d39315 837 hci_conn_encrypt(conn);
1da177e4
LT
838 return 0;
839}
8c1b2355 840EXPORT_SYMBOL(hci_conn_security);
1da177e4 841
b3b1b061
WR
842/* Check secure link requirement */
843int hci_conn_check_secure(struct hci_conn *conn, __u8 sec_level)
844{
38b3fef1 845 BT_DBG("hcon %p", conn);
b3b1b061
WR
846
847 if (sec_level != BT_SECURITY_HIGH)
848 return 1; /* Accept if non-secure is required */
849
ef4177e2 850 if (conn->sec_level == BT_SECURITY_HIGH)
b3b1b061
WR
851 return 1;
852
853 return 0; /* Reject not secure link */
854}
855EXPORT_SYMBOL(hci_conn_check_secure);
856
1da177e4
LT
857/* Change link key */
858int hci_conn_change_link_key(struct hci_conn *conn)
859{
38b3fef1 860 BT_DBG("hcon %p", conn);
1da177e4 861
51a8efd7 862 if (!test_and_set_bit(HCI_CONN_AUTH_PEND, &conn->flags)) {
1da177e4 863 struct hci_cp_change_conn_link_key cp;
aca3192c 864 cp.handle = cpu_to_le16(conn->handle);
40be492f 865 hci_send_cmd(conn->hdev, HCI_OP_CHANGE_CONN_LINK_KEY,
5974e4c4 866 sizeof(cp), &cp);
1da177e4 867 }
8c1b2355 868
1da177e4
LT
869 return 0;
870}
1da177e4
LT
871
872/* Switch role */
8c1b2355 873int hci_conn_switch_role(struct hci_conn *conn, __u8 role)
1da177e4 874{
38b3fef1 875 BT_DBG("hcon %p", conn);
1da177e4
LT
876
877 if (!role && conn->link_mode & HCI_LM_MASTER)
878 return 1;
879
51a8efd7 880 if (!test_and_set_bit(HCI_CONN_RSWITCH_PEND, &conn->flags)) {
1da177e4
LT
881 struct hci_cp_switch_role cp;
882 bacpy(&cp.bdaddr, &conn->dst);
883 cp.role = role;
a9de9248 884 hci_send_cmd(conn->hdev, HCI_OP_SWITCH_ROLE, sizeof(cp), &cp);
1da177e4 885 }
8c1b2355 886
1da177e4
LT
887 return 0;
888}
889EXPORT_SYMBOL(hci_conn_switch_role);
890
04837f64 891/* Enter active mode */
14b12d0b 892void hci_conn_enter_active_mode(struct hci_conn *conn, __u8 force_active)
04837f64
MH
893{
894 struct hci_dev *hdev = conn->hdev;
895
38b3fef1 896 BT_DBG("hcon %p mode %d", conn, conn->mode);
04837f64
MH
897
898 if (test_bit(HCI_RAW, &hdev->flags))
899 return;
900
14b12d0b
JG
901 if (conn->mode != HCI_CM_SNIFF)
902 goto timer;
903
58a681ef 904 if (!test_bit(HCI_CONN_POWER_SAVE, &conn->flags) && !force_active)
04837f64
MH
905 goto timer;
906
51a8efd7 907 if (!test_and_set_bit(HCI_CONN_MODE_CHANGE_PEND, &conn->flags)) {
04837f64 908 struct hci_cp_exit_sniff_mode cp;
aca3192c 909 cp.handle = cpu_to_le16(conn->handle);
a9de9248 910 hci_send_cmd(hdev, HCI_OP_EXIT_SNIFF_MODE, sizeof(cp), &cp);
04837f64
MH
911 }
912
913timer:
914 if (hdev->idle_timeout > 0)
a74a84f6
JH
915 queue_delayed_work(hdev->workqueue, &conn->idle_work,
916 msecs_to_jiffies(hdev->idle_timeout));
04837f64
MH
917}
918
1da177e4
LT
919/* Drop all connection on the device */
920void hci_conn_hash_flush(struct hci_dev *hdev)
921{
922 struct hci_conn_hash *h = &hdev->conn_hash;
3c4e0df0 923 struct hci_conn *c, *n;
1da177e4
LT
924
925 BT_DBG("hdev %s", hdev->name);
926
3c4e0df0 927 list_for_each_entry_safe(c, n, &h->list, list) {
1da177e4
LT
928 c->state = BT_CLOSED;
929
9f5a0d7b 930 hci_proto_disconn_cfm(c, HCI_ERROR_LOCAL_HOST_TERM);
1da177e4
LT
931 hci_conn_del(c);
932 }
933}
934
a9de9248
MH
935/* Check pending connect attempts */
936void hci_conn_check_pending(struct hci_dev *hdev)
937{
938 struct hci_conn *conn;
939
940 BT_DBG("hdev %s", hdev->name);
941
942 hci_dev_lock(hdev);
943
944 conn = hci_conn_hash_lookup_state(hdev, ACL_LINK, BT_CONNECT2);
945 if (conn)
1aef8669 946 hci_acl_create_connection(conn);
a9de9248
MH
947
948 hci_dev_unlock(hdev);
949}
950
1da177e4
LT
951int hci_get_conn_list(void __user *arg)
952{
fc5fef61 953 struct hci_conn *c;
1da177e4
LT
954 struct hci_conn_list_req req, *cl;
955 struct hci_conn_info *ci;
956 struct hci_dev *hdev;
1da177e4
LT
957 int n = 0, size, err;
958
959 if (copy_from_user(&req, arg, sizeof(req)))
960 return -EFAULT;
961
962 if (!req.conn_num || req.conn_num > (PAGE_SIZE * 2) / sizeof(*ci))
963 return -EINVAL;
964
965 size = sizeof(req) + req.conn_num * sizeof(*ci);
966
70f23020
AE
967 cl = kmalloc(size, GFP_KERNEL);
968 if (!cl)
1da177e4
LT
969 return -ENOMEM;
970
70f23020
AE
971 hdev = hci_dev_get(req.dev_id);
972 if (!hdev) {
1da177e4
LT
973 kfree(cl);
974 return -ENODEV;
975 }
976
977 ci = cl->conn_info;
978
09fd0de5 979 hci_dev_lock(hdev);
8035ded4 980 list_for_each_entry(c, &hdev->conn_hash.list, list) {
1da177e4
LT
981 bacpy(&(ci + n)->bdaddr, &c->dst);
982 (ci + n)->handle = c->handle;
983 (ci + n)->type = c->type;
984 (ci + n)->out = c->out;
985 (ci + n)->state = c->state;
986 (ci + n)->link_mode = c->link_mode;
987 if (++n >= req.conn_num)
988 break;
989 }
09fd0de5 990 hci_dev_unlock(hdev);
1da177e4
LT
991
992 cl->dev_id = hdev->id;
993 cl->conn_num = n;
994 size = sizeof(req) + n * sizeof(*ci);
995
996 hci_dev_put(hdev);
997
998 err = copy_to_user(arg, cl, size);
999 kfree(cl);
1000
1001 return err ? -EFAULT : 0;
1002}
1003
1004int hci_get_conn_info(struct hci_dev *hdev, void __user *arg)
1005{
1006 struct hci_conn_info_req req;
1007 struct hci_conn_info ci;
1008 struct hci_conn *conn;
1009 char __user *ptr = arg + sizeof(req);
1010
1011 if (copy_from_user(&req, arg, sizeof(req)))
1012 return -EFAULT;
1013
09fd0de5 1014 hci_dev_lock(hdev);
1da177e4
LT
1015 conn = hci_conn_hash_lookup_ba(hdev, req.type, &req.bdaddr);
1016 if (conn) {
1017 bacpy(&ci.bdaddr, &conn->dst);
1018 ci.handle = conn->handle;
1019 ci.type = conn->type;
1020 ci.out = conn->out;
1021 ci.state = conn->state;
1022 ci.link_mode = conn->link_mode;
1023 }
09fd0de5 1024 hci_dev_unlock(hdev);
1da177e4
LT
1025
1026 if (!conn)
1027 return -ENOENT;
1028
1029 return copy_to_user(ptr, &ci, sizeof(ci)) ? -EFAULT : 0;
1030}
40be492f
MH
1031
1032int hci_get_auth_info(struct hci_dev *hdev, void __user *arg)
1033{
1034 struct hci_auth_info_req req;
1035 struct hci_conn *conn;
1036
1037 if (copy_from_user(&req, arg, sizeof(req)))
1038 return -EFAULT;
1039
09fd0de5 1040 hci_dev_lock(hdev);
40be492f
MH
1041 conn = hci_conn_hash_lookup_ba(hdev, ACL_LINK, &req.bdaddr);
1042 if (conn)
1043 req.type = conn->auth_type;
09fd0de5 1044 hci_dev_unlock(hdev);
40be492f
MH
1045
1046 if (!conn)
1047 return -ENOENT;
1048
1049 return copy_to_user(arg, &req, sizeof(req)) ? -EFAULT : 0;
1050}
73d80deb
LAD
1051
1052struct hci_chan *hci_chan_create(struct hci_conn *conn)
1053{
1054 struct hci_dev *hdev = conn->hdev;
1055 struct hci_chan *chan;
1056
38b3fef1 1057 BT_DBG("%s hcon %p", hdev->name, conn);
73d80deb 1058
75d7735c 1059 chan = kzalloc(sizeof(struct hci_chan), GFP_KERNEL);
73d80deb
LAD
1060 if (!chan)
1061 return NULL;
1062
1063 chan->conn = conn;
1064 skb_queue_head_init(&chan->data_q);
168df8e5 1065 chan->state = BT_CONNECTED;
73d80deb 1066
8192edef 1067 list_add_rcu(&chan->list, &conn->chan_list);
73d80deb
LAD
1068
1069 return chan;
1070}
1071
9472007c 1072void hci_chan_del(struct hci_chan *chan)
73d80deb
LAD
1073{
1074 struct hci_conn *conn = chan->conn;
1075 struct hci_dev *hdev = conn->hdev;
1076
38b3fef1 1077 BT_DBG("%s hcon %p chan %p", hdev->name, conn, chan);
73d80deb 1078
8192edef
GP
1079 list_del_rcu(&chan->list);
1080
1081 synchronize_rcu();
73d80deb 1082
76a68ba0 1083 hci_conn_drop(conn);
e9b02748 1084
73d80deb
LAD
1085 skb_queue_purge(&chan->data_q);
1086 kfree(chan);
73d80deb
LAD
1087}
1088
2c33c06a 1089void hci_chan_list_flush(struct hci_conn *conn)
73d80deb 1090{
2a5a5ec6 1091 struct hci_chan *chan, *n;
73d80deb 1092
38b3fef1 1093 BT_DBG("hcon %p", conn);
73d80deb 1094
2a5a5ec6 1095 list_for_each_entry_safe(chan, n, &conn->chan_list, list)
73d80deb
LAD
1096 hci_chan_del(chan);
1097}
42c4e53e
AE
1098
1099static struct hci_chan *__hci_chan_lookup_handle(struct hci_conn *hcon,
1100 __u16 handle)
1101{
1102 struct hci_chan *hchan;
1103
1104 list_for_each_entry(hchan, &hcon->chan_list, list) {
1105 if (hchan->handle == handle)
1106 return hchan;
1107 }
1108
1109 return NULL;
1110}
1111
1112struct hci_chan *hci_chan_lookup_handle(struct hci_dev *hdev, __u16 handle)
1113{
1114 struct hci_conn_hash *h = &hdev->conn_hash;
1115 struct hci_conn *hcon;
1116 struct hci_chan *hchan = NULL;
1117
1118 rcu_read_lock();
1119
1120 list_for_each_entry_rcu(hcon, &h->list, list) {
1121 hchan = __hci_chan_lookup_handle(hcon, handle);
1122 if (hchan)
1123 break;
1124 }
1125
1126 rcu_read_unlock();
1127
1128 return hchan;
1129}