• Home
  • Line#
  • Scopes#
  • Navigate#
  • Raw
  • Download
1 /*
2  * Copyright (C) 2011  Intel Corporation. All rights reserved.
3  *
4  * This program is free software; you can redistribute it and/or modify
5  * it under the terms of the GNU General Public License as published by
6  * the Free Software Foundation; either version 2 of the License, or
7  * (at your option) any later version.
8  *
9  * This program is distributed in the hope that it will be useful,
10  * but WITHOUT ANY WARRANTY; without even the implied warranty of
11  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
12  * GNU General Public License for more details.
13  *
14  * You should have received a copy of the GNU General Public License
15  * along with this program; if not, see <http://www.gnu.org/licenses/>.
16  */
17 
18 #define pr_fmt(fmt) "llcp: %s: " fmt, __func__
19 
20 #include <linux/init.h>
21 #include <linux/kernel.h>
22 #include <linux/module.h>
23 #include <linux/nfc.h>
24 
25 #include "nfc.h"
26 #include "llcp.h"
27 
sock_wait_state(struct sock * sk,int state,unsigned long timeo)28 static int sock_wait_state(struct sock *sk, int state, unsigned long timeo)
29 {
30 	DECLARE_WAITQUEUE(wait, current);
31 	int err = 0;
32 
33 	pr_debug("sk %p", sk);
34 
35 	add_wait_queue(sk_sleep(sk), &wait);
36 	set_current_state(TASK_INTERRUPTIBLE);
37 
38 	while (sk->sk_state != state) {
39 		if (!timeo) {
40 			err = -EINPROGRESS;
41 			break;
42 		}
43 
44 		if (signal_pending(current)) {
45 			err = sock_intr_errno(timeo);
46 			break;
47 		}
48 
49 		release_sock(sk);
50 		timeo = schedule_timeout(timeo);
51 		lock_sock(sk);
52 		set_current_state(TASK_INTERRUPTIBLE);
53 
54 		err = sock_error(sk);
55 		if (err)
56 			break;
57 	}
58 
59 	__set_current_state(TASK_RUNNING);
60 	remove_wait_queue(sk_sleep(sk), &wait);
61 	return err;
62 }
63 
64 static struct proto llcp_sock_proto = {
65 	.name     = "NFC_LLCP",
66 	.owner    = THIS_MODULE,
67 	.obj_size = sizeof(struct nfc_llcp_sock),
68 };
69 
llcp_sock_bind(struct socket * sock,struct sockaddr * addr,int alen)70 static int llcp_sock_bind(struct socket *sock, struct sockaddr *addr, int alen)
71 {
72 	struct sock *sk = sock->sk;
73 	struct nfc_llcp_sock *llcp_sock = nfc_llcp_sock(sk);
74 	struct nfc_llcp_local *local;
75 	struct nfc_dev *dev;
76 	struct sockaddr_nfc_llcp llcp_addr;
77 	int len, ret = 0;
78 
79 	if (!addr || alen < offsetofend(struct sockaddr, sa_family) ||
80 	    addr->sa_family != AF_NFC)
81 		return -EINVAL;
82 
83 	pr_debug("sk %p addr %p family %d\n", sk, addr, addr->sa_family);
84 
85 	memset(&llcp_addr, 0, sizeof(llcp_addr));
86 	len = min_t(unsigned int, sizeof(llcp_addr), alen);
87 	memcpy(&llcp_addr, addr, len);
88 
89 	/* This is going to be a listening socket, dsap must be 0 */
90 	if (llcp_addr.dsap != 0)
91 		return -EINVAL;
92 
93 	lock_sock(sk);
94 
95 	if (sk->sk_state != LLCP_CLOSED) {
96 		ret = -EBADFD;
97 		goto error;
98 	}
99 
100 	dev = nfc_get_device(llcp_addr.dev_idx);
101 	if (dev == NULL) {
102 		ret = -ENODEV;
103 		goto error;
104 	}
105 
106 	local = nfc_llcp_find_local(dev);
107 	if (local == NULL) {
108 		ret = -ENODEV;
109 		goto put_dev;
110 	}
111 
112 	llcp_sock->dev = dev;
113 	llcp_sock->local = nfc_llcp_local_get(local);
114 	llcp_sock->nfc_protocol = llcp_addr.nfc_protocol;
115 	llcp_sock->service_name_len = min_t(unsigned int,
116 					    llcp_addr.service_name_len,
117 					    NFC_LLCP_MAX_SERVICE_NAME);
118 	llcp_sock->service_name = kmemdup(llcp_addr.service_name,
119 					  llcp_sock->service_name_len,
120 					  GFP_KERNEL);
121 
122 	llcp_sock->ssap = nfc_llcp_get_sdp_ssap(local, llcp_sock);
123 	if (llcp_sock->ssap == LLCP_SAP_MAX) {
124 		ret = -EADDRINUSE;
125 		goto put_dev;
126 	}
127 
128 	llcp_sock->reserved_ssap = llcp_sock->ssap;
129 
130 	nfc_llcp_sock_link(&local->sockets, sk);
131 
132 	pr_debug("Socket bound to SAP %d\n", llcp_sock->ssap);
133 
134 	sk->sk_state = LLCP_BOUND;
135 
136 put_dev:
137 	nfc_put_device(dev);
138 
139 error:
140 	release_sock(sk);
141 	return ret;
142 }
143 
llcp_raw_sock_bind(struct socket * sock,struct sockaddr * addr,int alen)144 static int llcp_raw_sock_bind(struct socket *sock, struct sockaddr *addr,
145 			      int alen)
146 {
147 	struct sock *sk = sock->sk;
148 	struct nfc_llcp_sock *llcp_sock = nfc_llcp_sock(sk);
149 	struct nfc_llcp_local *local;
150 	struct nfc_dev *dev;
151 	struct sockaddr_nfc_llcp llcp_addr;
152 	int len, ret = 0;
153 
154 	if (!addr || alen < offsetofend(struct sockaddr, sa_family) ||
155 	    addr->sa_family != AF_NFC)
156 		return -EINVAL;
157 
158 	pr_debug("sk %p addr %p family %d\n", sk, addr, addr->sa_family);
159 
160 	memset(&llcp_addr, 0, sizeof(llcp_addr));
161 	len = min_t(unsigned int, sizeof(llcp_addr), alen);
162 	memcpy(&llcp_addr, addr, len);
163 
164 	lock_sock(sk);
165 
166 	if (sk->sk_state != LLCP_CLOSED) {
167 		ret = -EBADFD;
168 		goto error;
169 	}
170 
171 	dev = nfc_get_device(llcp_addr.dev_idx);
172 	if (dev == NULL) {
173 		ret = -ENODEV;
174 		goto error;
175 	}
176 
177 	local = nfc_llcp_find_local(dev);
178 	if (local == NULL) {
179 		ret = -ENODEV;
180 		goto put_dev;
181 	}
182 
183 	llcp_sock->dev = dev;
184 	llcp_sock->local = nfc_llcp_local_get(local);
185 	llcp_sock->nfc_protocol = llcp_addr.nfc_protocol;
186 
187 	nfc_llcp_sock_link(&local->raw_sockets, sk);
188 
189 	sk->sk_state = LLCP_BOUND;
190 
191 put_dev:
192 	nfc_put_device(dev);
193 
194 error:
195 	release_sock(sk);
196 	return ret;
197 }
198 
llcp_sock_listen(struct socket * sock,int backlog)199 static int llcp_sock_listen(struct socket *sock, int backlog)
200 {
201 	struct sock *sk = sock->sk;
202 	int ret = 0;
203 
204 	pr_debug("sk %p backlog %d\n", sk, backlog);
205 
206 	lock_sock(sk);
207 
208 	if ((sock->type != SOCK_SEQPACKET && sock->type != SOCK_STREAM) ||
209 	    sk->sk_state != LLCP_BOUND) {
210 		ret = -EBADFD;
211 		goto error;
212 	}
213 
214 	sk->sk_max_ack_backlog = backlog;
215 	sk->sk_ack_backlog = 0;
216 
217 	pr_debug("Socket listening\n");
218 	sk->sk_state = LLCP_LISTEN;
219 
220 error:
221 	release_sock(sk);
222 
223 	return ret;
224 }
225 
nfc_llcp_setsockopt(struct socket * sock,int level,int optname,char __user * optval,unsigned int optlen)226 static int nfc_llcp_setsockopt(struct socket *sock, int level, int optname,
227 			       char __user *optval, unsigned int optlen)
228 {
229 	struct sock *sk = sock->sk;
230 	struct nfc_llcp_sock *llcp_sock = nfc_llcp_sock(sk);
231 	u32 opt;
232 	int err = 0;
233 
234 	pr_debug("%p optname %d\n", sk, optname);
235 
236 	if (level != SOL_NFC)
237 		return -ENOPROTOOPT;
238 
239 	lock_sock(sk);
240 
241 	switch (optname) {
242 	case NFC_LLCP_RW:
243 		if (sk->sk_state == LLCP_CONNECTED ||
244 		    sk->sk_state == LLCP_BOUND ||
245 		    sk->sk_state == LLCP_LISTEN) {
246 			err = -EINVAL;
247 			break;
248 		}
249 
250 		if (get_user(opt, (u32 __user *) optval)) {
251 			err = -EFAULT;
252 			break;
253 		}
254 
255 		if (opt > LLCP_MAX_RW) {
256 			err = -EINVAL;
257 			break;
258 		}
259 
260 		llcp_sock->rw = (u8) opt;
261 
262 		break;
263 
264 	case NFC_LLCP_MIUX:
265 		if (sk->sk_state == LLCP_CONNECTED ||
266 		    sk->sk_state == LLCP_BOUND ||
267 		    sk->sk_state == LLCP_LISTEN) {
268 			err = -EINVAL;
269 			break;
270 		}
271 
272 		if (get_user(opt, (u32 __user *) optval)) {
273 			err = -EFAULT;
274 			break;
275 		}
276 
277 		if (opt > LLCP_MAX_MIUX) {
278 			err = -EINVAL;
279 			break;
280 		}
281 
282 		llcp_sock->miux = cpu_to_be16((u16) opt);
283 
284 		break;
285 
286 	default:
287 		err = -ENOPROTOOPT;
288 		break;
289 	}
290 
291 	release_sock(sk);
292 
293 	pr_debug("%p rw %d miux %d\n", llcp_sock,
294 		 llcp_sock->rw, llcp_sock->miux);
295 
296 	return err;
297 }
298 
nfc_llcp_getsockopt(struct socket * sock,int level,int optname,char __user * optval,int __user * optlen)299 static int nfc_llcp_getsockopt(struct socket *sock, int level, int optname,
300 			       char __user *optval, int __user *optlen)
301 {
302 	struct nfc_llcp_local *local;
303 	struct sock *sk = sock->sk;
304 	struct nfc_llcp_sock *llcp_sock = nfc_llcp_sock(sk);
305 	int len, err = 0;
306 	u16 miux, remote_miu;
307 	u8 rw;
308 
309 	pr_debug("%p optname %d\n", sk, optname);
310 
311 	if (level != SOL_NFC)
312 		return -ENOPROTOOPT;
313 
314 	if (get_user(len, optlen))
315 		return -EFAULT;
316 
317 	local = llcp_sock->local;
318 	if (!local)
319 		return -ENODEV;
320 
321 	len = min_t(u32, len, sizeof(u32));
322 
323 	lock_sock(sk);
324 
325 	switch (optname) {
326 	case NFC_LLCP_RW:
327 		rw = llcp_sock->rw > LLCP_MAX_RW ? local->rw : llcp_sock->rw;
328 		if (put_user(rw, (u32 __user *) optval))
329 			err = -EFAULT;
330 
331 		break;
332 
333 	case NFC_LLCP_MIUX:
334 		miux = be16_to_cpu(llcp_sock->miux) > LLCP_MAX_MIUX ?
335 			be16_to_cpu(local->miux) : be16_to_cpu(llcp_sock->miux);
336 
337 		if (put_user(miux, (u32 __user *) optval))
338 			err = -EFAULT;
339 
340 		break;
341 
342 	case NFC_LLCP_REMOTE_MIU:
343 		remote_miu = llcp_sock->remote_miu > LLCP_MAX_MIU ?
344 				local->remote_miu : llcp_sock->remote_miu;
345 
346 		if (put_user(remote_miu, (u32 __user *) optval))
347 			err = -EFAULT;
348 
349 		break;
350 
351 	case NFC_LLCP_REMOTE_LTO:
352 		if (put_user(local->remote_lto / 10, (u32 __user *) optval))
353 			err = -EFAULT;
354 
355 		break;
356 
357 	case NFC_LLCP_REMOTE_RW:
358 		if (put_user(llcp_sock->remote_rw, (u32 __user *) optval))
359 			err = -EFAULT;
360 
361 		break;
362 
363 	default:
364 		err = -ENOPROTOOPT;
365 		break;
366 	}
367 
368 	release_sock(sk);
369 
370 	if (put_user(len, optlen))
371 		return -EFAULT;
372 
373 	return err;
374 }
375 
nfc_llcp_accept_unlink(struct sock * sk)376 void nfc_llcp_accept_unlink(struct sock *sk)
377 {
378 	struct nfc_llcp_sock *llcp_sock = nfc_llcp_sock(sk);
379 
380 	pr_debug("state %d\n", sk->sk_state);
381 
382 	list_del_init(&llcp_sock->accept_queue);
383 	sk_acceptq_removed(llcp_sock->parent);
384 	llcp_sock->parent = NULL;
385 
386 	sock_put(sk);
387 }
388 
nfc_llcp_accept_enqueue(struct sock * parent,struct sock * sk)389 void nfc_llcp_accept_enqueue(struct sock *parent, struct sock *sk)
390 {
391 	struct nfc_llcp_sock *llcp_sock = nfc_llcp_sock(sk);
392 	struct nfc_llcp_sock *llcp_sock_parent = nfc_llcp_sock(parent);
393 
394 	/* Lock will be free from unlink */
395 	sock_hold(sk);
396 
397 	list_add_tail(&llcp_sock->accept_queue,
398 		      &llcp_sock_parent->accept_queue);
399 	llcp_sock->parent = parent;
400 	sk_acceptq_added(parent);
401 }
402 
nfc_llcp_accept_dequeue(struct sock * parent,struct socket * newsock)403 struct sock *nfc_llcp_accept_dequeue(struct sock *parent,
404 				     struct socket *newsock)
405 {
406 	struct nfc_llcp_sock *lsk, *n, *llcp_parent;
407 	struct sock *sk;
408 
409 	llcp_parent = nfc_llcp_sock(parent);
410 
411 	list_for_each_entry_safe(lsk, n, &llcp_parent->accept_queue,
412 				 accept_queue) {
413 		sk = &lsk->sk;
414 		lock_sock(sk);
415 
416 		if (sk->sk_state == LLCP_CLOSED) {
417 			release_sock(sk);
418 			nfc_llcp_accept_unlink(sk);
419 			continue;
420 		}
421 
422 		if (sk->sk_state == LLCP_CONNECTED || !newsock) {
423 			list_del_init(&lsk->accept_queue);
424 			sock_put(sk);
425 
426 			if (newsock)
427 				sock_graft(sk, newsock);
428 
429 			release_sock(sk);
430 
431 			pr_debug("Returning sk state %d\n", sk->sk_state);
432 
433 			sk_acceptq_removed(parent);
434 
435 			return sk;
436 		}
437 
438 		release_sock(sk);
439 	}
440 
441 	return NULL;
442 }
443 
llcp_sock_accept(struct socket * sock,struct socket * newsock,int flags)444 static int llcp_sock_accept(struct socket *sock, struct socket *newsock,
445 			    int flags)
446 {
447 	DECLARE_WAITQUEUE(wait, current);
448 	struct sock *sk = sock->sk, *new_sk;
449 	long timeo;
450 	int ret = 0;
451 
452 	pr_debug("parent %p\n", sk);
453 
454 	lock_sock_nested(sk, SINGLE_DEPTH_NESTING);
455 
456 	if (sk->sk_state != LLCP_LISTEN) {
457 		ret = -EBADFD;
458 		goto error;
459 	}
460 
461 	timeo = sock_rcvtimeo(sk, flags & O_NONBLOCK);
462 
463 	/* Wait for an incoming connection. */
464 	add_wait_queue_exclusive(sk_sleep(sk), &wait);
465 	while (!(new_sk = nfc_llcp_accept_dequeue(sk, newsock))) {
466 		set_current_state(TASK_INTERRUPTIBLE);
467 
468 		if (!timeo) {
469 			ret = -EAGAIN;
470 			break;
471 		}
472 
473 		if (signal_pending(current)) {
474 			ret = sock_intr_errno(timeo);
475 			break;
476 		}
477 
478 		release_sock(sk);
479 		timeo = schedule_timeout(timeo);
480 		lock_sock_nested(sk, SINGLE_DEPTH_NESTING);
481 	}
482 	__set_current_state(TASK_RUNNING);
483 	remove_wait_queue(sk_sleep(sk), &wait);
484 
485 	if (ret)
486 		goto error;
487 
488 	newsock->state = SS_CONNECTED;
489 
490 	pr_debug("new socket %p\n", new_sk);
491 
492 error:
493 	release_sock(sk);
494 
495 	return ret;
496 }
497 
llcp_sock_getname(struct socket * sock,struct sockaddr * uaddr,int * len,int peer)498 static int llcp_sock_getname(struct socket *sock, struct sockaddr *uaddr,
499 			     int *len, int peer)
500 {
501 	struct sock *sk = sock->sk;
502 	struct nfc_llcp_sock *llcp_sock = nfc_llcp_sock(sk);
503 	DECLARE_SOCKADDR(struct sockaddr_nfc_llcp *, llcp_addr, uaddr);
504 
505 	if (llcp_sock == NULL || llcp_sock->dev == NULL)
506 		return -EBADFD;
507 
508 	pr_debug("%p %d %d %d\n", sk, llcp_sock->target_idx,
509 		 llcp_sock->dsap, llcp_sock->ssap);
510 
511 	memset(llcp_addr, 0, sizeof(*llcp_addr));
512 	*len = sizeof(struct sockaddr_nfc_llcp);
513 
514 	llcp_addr->sa_family = AF_NFC;
515 	llcp_addr->dev_idx = llcp_sock->dev->idx;
516 	llcp_addr->target_idx = llcp_sock->target_idx;
517 	llcp_addr->nfc_protocol = llcp_sock->nfc_protocol;
518 	llcp_addr->dsap = llcp_sock->dsap;
519 	llcp_addr->ssap = llcp_sock->ssap;
520 	llcp_addr->service_name_len = llcp_sock->service_name_len;
521 	memcpy(llcp_addr->service_name, llcp_sock->service_name,
522 	       llcp_addr->service_name_len);
523 
524 	return 0;
525 }
526 
llcp_accept_poll(struct sock * parent)527 static inline unsigned int llcp_accept_poll(struct sock *parent)
528 {
529 	struct nfc_llcp_sock *llcp_sock, *n, *parent_sock;
530 	struct sock *sk;
531 
532 	parent_sock = nfc_llcp_sock(parent);
533 
534 	list_for_each_entry_safe(llcp_sock, n, &parent_sock->accept_queue,
535 				 accept_queue) {
536 		sk = &llcp_sock->sk;
537 
538 		if (sk->sk_state == LLCP_CONNECTED)
539 			return POLLIN | POLLRDNORM;
540 	}
541 
542 	return 0;
543 }
544 
llcp_sock_poll(struct file * file,struct socket * sock,poll_table * wait)545 static unsigned int llcp_sock_poll(struct file *file, struct socket *sock,
546 				   poll_table *wait)
547 {
548 	struct sock *sk = sock->sk;
549 	unsigned int mask = 0;
550 
551 	pr_debug("%p\n", sk);
552 
553 	sock_poll_wait(file, sk_sleep(sk), wait);
554 
555 	if (sk->sk_state == LLCP_LISTEN)
556 		return llcp_accept_poll(sk);
557 
558 	if (sk->sk_err || !skb_queue_empty(&sk->sk_error_queue))
559 		mask |= POLLERR |
560 			(sock_flag(sk, SOCK_SELECT_ERR_QUEUE) ? POLLPRI : 0);
561 
562 	if (!skb_queue_empty(&sk->sk_receive_queue))
563 		mask |= POLLIN | POLLRDNORM;
564 
565 	if (sk->sk_state == LLCP_CLOSED)
566 		mask |= POLLHUP;
567 
568 	if (sk->sk_shutdown & RCV_SHUTDOWN)
569 		mask |= POLLRDHUP | POLLIN | POLLRDNORM;
570 
571 	if (sk->sk_shutdown == SHUTDOWN_MASK)
572 		mask |= POLLHUP;
573 
574 	if (sock_writeable(sk) && sk->sk_state == LLCP_CONNECTED)
575 		mask |= POLLOUT | POLLWRNORM | POLLWRBAND;
576 	else
577 		set_bit(SOCK_ASYNC_NOSPACE, &sk->sk_socket->flags);
578 
579 	pr_debug("mask 0x%x\n", mask);
580 
581 	return mask;
582 }
583 
llcp_sock_release(struct socket * sock)584 static int llcp_sock_release(struct socket *sock)
585 {
586 	struct sock *sk = sock->sk;
587 	struct nfc_llcp_local *local;
588 	struct nfc_llcp_sock *llcp_sock = nfc_llcp_sock(sk);
589 	int err = 0;
590 
591 	if (!sk)
592 		return 0;
593 
594 	pr_debug("%p\n", sk);
595 
596 	local = llcp_sock->local;
597 	if (local == NULL) {
598 		err = -ENODEV;
599 		goto out;
600 	}
601 
602 	lock_sock(sk);
603 
604 	/* Send a DISC */
605 	if (sk->sk_state == LLCP_CONNECTED)
606 		nfc_llcp_send_disconnect(llcp_sock);
607 
608 	if (sk->sk_state == LLCP_LISTEN) {
609 		struct nfc_llcp_sock *lsk, *n;
610 		struct sock *accept_sk;
611 
612 		list_for_each_entry_safe(lsk, n, &llcp_sock->accept_queue,
613 					 accept_queue) {
614 			accept_sk = &lsk->sk;
615 			lock_sock(accept_sk);
616 
617 			nfc_llcp_send_disconnect(lsk);
618 			nfc_llcp_accept_unlink(accept_sk);
619 
620 			release_sock(accept_sk);
621 		}
622 	}
623 
624 	if (llcp_sock->reserved_ssap < LLCP_SAP_MAX)
625 		nfc_llcp_put_ssap(llcp_sock->local, llcp_sock->ssap);
626 
627 	release_sock(sk);
628 
629 	/* Keep this sock alive and therefore do not remove it from the sockets
630 	 * list until the DISC PDU has been actually sent. Otherwise we would
631 	 * reply with DM PDUs before sending the DISC one.
632 	 */
633 	if (sk->sk_state == LLCP_DISCONNECTING)
634 		return err;
635 
636 	if (sock->type == SOCK_RAW)
637 		nfc_llcp_sock_unlink(&local->raw_sockets, sk);
638 	else
639 		nfc_llcp_sock_unlink(&local->sockets, sk);
640 
641 out:
642 	sock_orphan(sk);
643 	sock_put(sk);
644 
645 	return err;
646 }
647 
llcp_sock_connect(struct socket * sock,struct sockaddr * _addr,int len,int flags)648 static int llcp_sock_connect(struct socket *sock, struct sockaddr *_addr,
649 			     int len, int flags)
650 {
651 	struct sock *sk = sock->sk;
652 	struct nfc_llcp_sock *llcp_sock = nfc_llcp_sock(sk);
653 	struct sockaddr_nfc_llcp *addr = (struct sockaddr_nfc_llcp *)_addr;
654 	struct nfc_dev *dev;
655 	struct nfc_llcp_local *local;
656 	int ret = 0;
657 
658 	pr_debug("sock %p sk %p flags 0x%x\n", sock, sk, flags);
659 
660 	if (!addr || len < sizeof(*addr) || addr->sa_family != AF_NFC)
661 		return -EINVAL;
662 
663 	if (addr->service_name_len == 0 && addr->dsap == 0)
664 		return -EINVAL;
665 
666 	pr_debug("addr dev_idx=%u target_idx=%u protocol=%u\n", addr->dev_idx,
667 		 addr->target_idx, addr->nfc_protocol);
668 
669 	lock_sock(sk);
670 
671 	if (sk->sk_state == LLCP_CONNECTED) {
672 		ret = -EISCONN;
673 		goto error;
674 	}
675 
676 	dev = nfc_get_device(addr->dev_idx);
677 	if (dev == NULL) {
678 		ret = -ENODEV;
679 		goto error;
680 	}
681 
682 	local = nfc_llcp_find_local(dev);
683 	if (local == NULL) {
684 		ret = -ENODEV;
685 		goto put_dev;
686 	}
687 
688 	device_lock(&dev->dev);
689 	if (dev->dep_link_up == false) {
690 		ret = -ENOLINK;
691 		device_unlock(&dev->dev);
692 		goto put_dev;
693 	}
694 	device_unlock(&dev->dev);
695 
696 	if (local->rf_mode == NFC_RF_INITIATOR &&
697 	    addr->target_idx != local->target_idx) {
698 		ret = -ENOLINK;
699 		goto put_dev;
700 	}
701 
702 	llcp_sock->dev = dev;
703 	llcp_sock->local = nfc_llcp_local_get(local);
704 	llcp_sock->ssap = nfc_llcp_get_local_ssap(local);
705 	if (llcp_sock->ssap == LLCP_SAP_MAX) {
706 		ret = -ENOMEM;
707 		goto put_dev;
708 	}
709 
710 	llcp_sock->reserved_ssap = llcp_sock->ssap;
711 
712 	if (addr->service_name_len == 0)
713 		llcp_sock->dsap = addr->dsap;
714 	else
715 		llcp_sock->dsap = LLCP_SAP_SDP;
716 	llcp_sock->nfc_protocol = addr->nfc_protocol;
717 	llcp_sock->service_name_len = min_t(unsigned int,
718 					    addr->service_name_len,
719 					    NFC_LLCP_MAX_SERVICE_NAME);
720 	llcp_sock->service_name = kmemdup(addr->service_name,
721 					  llcp_sock->service_name_len,
722 					  GFP_KERNEL);
723 
724 	nfc_llcp_sock_link(&local->connecting_sockets, sk);
725 
726 	ret = nfc_llcp_send_connect(llcp_sock);
727 	if (ret)
728 		goto sock_unlink;
729 
730 	sk->sk_state = LLCP_CONNECTING;
731 
732 	ret = sock_wait_state(sk, LLCP_CONNECTED,
733 			      sock_sndtimeo(sk, flags & O_NONBLOCK));
734 	if (ret && ret != -EINPROGRESS)
735 		goto sock_unlink;
736 
737 	release_sock(sk);
738 
739 	return ret;
740 
741 sock_unlink:
742 	nfc_llcp_put_ssap(local, llcp_sock->ssap);
743 
744 	nfc_llcp_sock_unlink(&local->connecting_sockets, sk);
745 
746 put_dev:
747 	nfc_put_device(dev);
748 
749 error:
750 	release_sock(sk);
751 	return ret;
752 }
753 
llcp_sock_sendmsg(struct kiocb * iocb,struct socket * sock,struct msghdr * msg,size_t len)754 static int llcp_sock_sendmsg(struct kiocb *iocb, struct socket *sock,
755 			     struct msghdr *msg, size_t len)
756 {
757 	struct sock *sk = sock->sk;
758 	struct nfc_llcp_sock *llcp_sock = nfc_llcp_sock(sk);
759 	int ret;
760 
761 	pr_debug("sock %p sk %p", sock, sk);
762 
763 	ret = sock_error(sk);
764 	if (ret)
765 		return ret;
766 
767 	if (msg->msg_flags & MSG_OOB)
768 		return -EOPNOTSUPP;
769 
770 	lock_sock(sk);
771 
772 	if (sk->sk_type == SOCK_DGRAM) {
773 		DECLARE_SOCKADDR(struct sockaddr_nfc_llcp *, addr,
774 				 msg->msg_name);
775 
776 		if (msg->msg_namelen < sizeof(*addr)) {
777 			release_sock(sk);
778 			return -EINVAL;
779 		}
780 
781 		release_sock(sk);
782 
783 		return nfc_llcp_send_ui_frame(llcp_sock, addr->dsap, addr->ssap,
784 					      msg, len);
785 	}
786 
787 	if (sk->sk_state != LLCP_CONNECTED) {
788 		release_sock(sk);
789 		return -ENOTCONN;
790 	}
791 
792 	release_sock(sk);
793 
794 	return nfc_llcp_send_i_frame(llcp_sock, msg, len);
795 }
796 
llcp_sock_recvmsg(struct kiocb * iocb,struct socket * sock,struct msghdr * msg,size_t len,int flags)797 static int llcp_sock_recvmsg(struct kiocb *iocb, struct socket *sock,
798 			     struct msghdr *msg, size_t len, int flags)
799 {
800 	int noblock = flags & MSG_DONTWAIT;
801 	struct sock *sk = sock->sk;
802 	unsigned int copied, rlen;
803 	struct sk_buff *skb, *cskb;
804 	int err = 0;
805 
806 	pr_debug("%p %zu\n", sk, len);
807 
808 	lock_sock(sk);
809 
810 	if (sk->sk_state == LLCP_CLOSED &&
811 	    skb_queue_empty(&sk->sk_receive_queue)) {
812 		release_sock(sk);
813 		return 0;
814 	}
815 
816 	release_sock(sk);
817 
818 	if (flags & (MSG_OOB))
819 		return -EOPNOTSUPP;
820 
821 	skb = skb_recv_datagram(sk, flags, noblock, &err);
822 	if (!skb) {
823 		pr_err("Recv datagram failed state %d %d %d",
824 		       sk->sk_state, err, sock_error(sk));
825 
826 		if (sk->sk_shutdown & RCV_SHUTDOWN)
827 			return 0;
828 
829 		return err;
830 	}
831 
832 	rlen = skb->len;		/* real length of skb */
833 	copied = min_t(unsigned int, rlen, len);
834 
835 	cskb = skb;
836 	if (skb_copy_datagram_iovec(cskb, 0, msg->msg_iov, copied)) {
837 		if (!(flags & MSG_PEEK))
838 			skb_queue_head(&sk->sk_receive_queue, skb);
839 		return -EFAULT;
840 	}
841 
842 	sock_recv_timestamp(msg, sk, skb);
843 
844 	if (sk->sk_type == SOCK_DGRAM && msg->msg_name) {
845 		struct nfc_llcp_ui_cb *ui_cb = nfc_llcp_ui_skb_cb(skb);
846 		DECLARE_SOCKADDR(struct sockaddr_nfc_llcp *, sockaddr,
847 				 msg->msg_name);
848 
849 		msg->msg_namelen = sizeof(struct sockaddr_nfc_llcp);
850 
851 		pr_debug("Datagram socket %d %d\n", ui_cb->dsap, ui_cb->ssap);
852 
853 		memset(sockaddr, 0, sizeof(*sockaddr));
854 		sockaddr->sa_family = AF_NFC;
855 		sockaddr->nfc_protocol = NFC_PROTO_NFC_DEP;
856 		sockaddr->dsap = ui_cb->dsap;
857 		sockaddr->ssap = ui_cb->ssap;
858 	}
859 
860 	/* Mark read part of skb as used */
861 	if (!(flags & MSG_PEEK)) {
862 
863 		/* SOCK_STREAM: re-queue skb if it contains unreceived data */
864 		if (sk->sk_type == SOCK_STREAM ||
865 		    sk->sk_type == SOCK_DGRAM ||
866 		    sk->sk_type == SOCK_RAW) {
867 			skb_pull(skb, copied);
868 			if (skb->len) {
869 				skb_queue_head(&sk->sk_receive_queue, skb);
870 				goto done;
871 			}
872 		}
873 
874 		kfree_skb(skb);
875 	}
876 
877 	/* XXX Queue backlogged skbs */
878 
879 done:
880 	/* SOCK_SEQPACKET: return real length if MSG_TRUNC is set */
881 	if (sk->sk_type == SOCK_SEQPACKET && (flags & MSG_TRUNC))
882 		copied = rlen;
883 
884 	return copied;
885 }
886 
887 static const struct proto_ops llcp_sock_ops = {
888 	.family         = PF_NFC,
889 	.owner          = THIS_MODULE,
890 	.bind           = llcp_sock_bind,
891 	.connect        = llcp_sock_connect,
892 	.release        = llcp_sock_release,
893 	.socketpair     = sock_no_socketpair,
894 	.accept         = llcp_sock_accept,
895 	.getname        = llcp_sock_getname,
896 	.poll           = llcp_sock_poll,
897 	.ioctl          = sock_no_ioctl,
898 	.listen         = llcp_sock_listen,
899 	.shutdown       = sock_no_shutdown,
900 	.setsockopt     = nfc_llcp_setsockopt,
901 	.getsockopt     = nfc_llcp_getsockopt,
902 	.sendmsg        = llcp_sock_sendmsg,
903 	.recvmsg        = llcp_sock_recvmsg,
904 	.mmap           = sock_no_mmap,
905 };
906 
907 static const struct proto_ops llcp_rawsock_ops = {
908 	.family         = PF_NFC,
909 	.owner          = THIS_MODULE,
910 	.bind           = llcp_raw_sock_bind,
911 	.connect        = sock_no_connect,
912 	.release        = llcp_sock_release,
913 	.socketpair     = sock_no_socketpair,
914 	.accept         = sock_no_accept,
915 	.getname        = llcp_sock_getname,
916 	.poll           = llcp_sock_poll,
917 	.ioctl          = sock_no_ioctl,
918 	.listen         = sock_no_listen,
919 	.shutdown       = sock_no_shutdown,
920 	.setsockopt     = sock_no_setsockopt,
921 	.getsockopt     = sock_no_getsockopt,
922 	.sendmsg        = sock_no_sendmsg,
923 	.recvmsg        = llcp_sock_recvmsg,
924 	.mmap           = sock_no_mmap,
925 };
926 
llcp_sock_destruct(struct sock * sk)927 static void llcp_sock_destruct(struct sock *sk)
928 {
929 	struct nfc_llcp_sock *llcp_sock = nfc_llcp_sock(sk);
930 
931 	pr_debug("%p\n", sk);
932 
933 	if (sk->sk_state == LLCP_CONNECTED)
934 		nfc_put_device(llcp_sock->dev);
935 
936 	skb_queue_purge(&sk->sk_receive_queue);
937 
938 	nfc_llcp_sock_free(llcp_sock);
939 
940 	if (!sock_flag(sk, SOCK_DEAD)) {
941 		pr_err("Freeing alive NFC LLCP socket %p\n", sk);
942 		return;
943 	}
944 }
945 
nfc_llcp_sock_alloc(struct socket * sock,int type,gfp_t gfp)946 struct sock *nfc_llcp_sock_alloc(struct socket *sock, int type, gfp_t gfp)
947 {
948 	struct sock *sk;
949 	struct nfc_llcp_sock *llcp_sock;
950 
951 	sk = sk_alloc(&init_net, PF_NFC, gfp, &llcp_sock_proto);
952 	if (!sk)
953 		return NULL;
954 
955 	llcp_sock = nfc_llcp_sock(sk);
956 
957 	sock_init_data(sock, sk);
958 	sk->sk_state = LLCP_CLOSED;
959 	sk->sk_protocol = NFC_SOCKPROTO_LLCP;
960 	sk->sk_type = type;
961 	sk->sk_destruct = llcp_sock_destruct;
962 
963 	llcp_sock->ssap = 0;
964 	llcp_sock->dsap = LLCP_SAP_SDP;
965 	llcp_sock->rw = LLCP_MAX_RW + 1;
966 	llcp_sock->miux = cpu_to_be16(LLCP_MAX_MIUX + 1);
967 	llcp_sock->send_n = llcp_sock->send_ack_n = 0;
968 	llcp_sock->recv_n = llcp_sock->recv_ack_n = 0;
969 	llcp_sock->remote_ready = 1;
970 	llcp_sock->reserved_ssap = LLCP_SAP_MAX;
971 	nfc_llcp_socket_remote_param_init(llcp_sock);
972 	skb_queue_head_init(&llcp_sock->tx_queue);
973 	skb_queue_head_init(&llcp_sock->tx_pending_queue);
974 	INIT_LIST_HEAD(&llcp_sock->accept_queue);
975 
976 	if (sock != NULL)
977 		sock->state = SS_UNCONNECTED;
978 
979 	return sk;
980 }
981 
nfc_llcp_sock_free(struct nfc_llcp_sock * sock)982 void nfc_llcp_sock_free(struct nfc_llcp_sock *sock)
983 {
984 	kfree(sock->service_name);
985 
986 	skb_queue_purge(&sock->tx_queue);
987 	skb_queue_purge(&sock->tx_pending_queue);
988 
989 	list_del_init(&sock->accept_queue);
990 
991 	sock->parent = NULL;
992 
993 	nfc_llcp_local_put(sock->local);
994 }
995 
llcp_sock_create(struct net * net,struct socket * sock,const struct nfc_protocol * nfc_proto)996 static int llcp_sock_create(struct net *net, struct socket *sock,
997 			    const struct nfc_protocol *nfc_proto)
998 {
999 	struct sock *sk;
1000 
1001 	pr_debug("%p\n", sock);
1002 
1003 	if (sock->type != SOCK_STREAM &&
1004 	    sock->type != SOCK_DGRAM &&
1005 	    sock->type != SOCK_RAW)
1006 		return -ESOCKTNOSUPPORT;
1007 
1008 	if (sock->type == SOCK_RAW)
1009 		sock->ops = &llcp_rawsock_ops;
1010 	else
1011 		sock->ops = &llcp_sock_ops;
1012 
1013 	sk = nfc_llcp_sock_alloc(sock, sock->type, GFP_ATOMIC);
1014 	if (sk == NULL)
1015 		return -ENOMEM;
1016 
1017 	return 0;
1018 }
1019 
1020 static const struct nfc_protocol llcp_nfc_proto = {
1021 	.id	  = NFC_SOCKPROTO_LLCP,
1022 	.proto    = &llcp_sock_proto,
1023 	.owner    = THIS_MODULE,
1024 	.create   = llcp_sock_create
1025 };
1026 
nfc_llcp_sock_init(void)1027 int __init nfc_llcp_sock_init(void)
1028 {
1029 	return nfc_proto_register(&llcp_nfc_proto);
1030 }
1031 
nfc_llcp_sock_exit(void)1032 void nfc_llcp_sock_exit(void)
1033 {
1034 	nfc_proto_unregister(&llcp_nfc_proto);
1035 }
1036